Robert68
Participant
Nombre d'articles : 8

Bonjour,

Merci déjà pour votre réponse rapide.
Que voulez-vous dire avec j’avais quelques cochonneries? dois-je désinstaller des programmes?

Voici encore le nouveau rapport. ( durant l’execution j’ai eu des messages de ^Kaspersky)

J’espère que c’est ok pour vous.

Spoiler for 3mdd2kaz

~ Rapport de ZHPDiag v2014.5.19.69 – Nicolas Coolman (19.05.2014)
~ Lancé par Robert (20.05.2014 07:16:35)
~ Adresse du Site Web http://nicolascoolman.webs.com” onclick=”window.open(this.href);return false;
~ Blog d'analyse software : http://nicolascoolman.byethost7.com” onclick=”window.open(this.href);return false;
~ Forums gratuits d'Assistance à la désinfection : http://nicolascoolman.webs.com/apps/links/” onclick=”window.open(this.href);return false;
~ Traduit par Nicolas Coolman
~ Etat de la version :
~ Liste blanche : Activée par le programme
~ Elévation des Privilèges : OK
~ User Account Control (UAC): Deactivate by program

—\ Navigateurs Internet
MSIE: Internet Explorer v11.0.9600.17107 (Defaut)
GCIE: Google Chrome v34.0.1847.137

—\ Informations sur les produits Windows
~ Langage: Français
Windows 7 Ultimate, 64-bit Service Pack 1 (Build 7601)
Windows Server License Manager Script : OK
~ Windows Operating System – Windows(R) 7, OEM_COA_NSLP channel
Windows ID Activation : OK
~ Windows Partial Key : BPF2C
Windows License : OK
~ Windows Remaining Initializations Number : 4
Software Protection Service (Protection logicielle) : OK
Windows Automatic Updates : OK
Windows Activation Technologies : OK

—\ Logiciels de protection du système
Kaspersky PURE 3.0 v13.0.2.558
Malwarebytes Anti-Malware version 1.75.0.1300
Windows Defender W7

—\ Logiciels d'optimisation du système

—\ Logiciels de partage PeerToPeer

—\ Surveillance de Logiciels
Adobe Flash Player 13 ActiveX
Java 7 Update 55
Java 7 Update 55

—\ Informations sur le système
~ Processor: Intel64 Family 6 Model 26 Stepping 5, GenuineIntel
~ Operating System: 64 Bits
Boot mode: Normal (Normal boot)
Total RAM: 6135.1 MB (70% free)
System Restore: Désactivé (Disabled)
System drive C: has 46 GB (38%) free of 119 GB

—\ Mode de connexion au système
~ Computer Name: ROBERT-PC
~ User Name: Robert
~ All Users Names: Robert, HomeGroupUser$, Administrateur,
~ Unselected Option: None
Logged in as Administrator

—\ Variables d'environnement
~ System Unit : C:
~ %AppZHP% : C:UsersRobertAppDataRoamingZHP
~ %AppData% : C:UsersRobertAppDataRoaming
~ %Desktop% : C:UsersRobertDesktop
~ %Favorites% : C:UsersRobertFavorites
~ %LocalAppData% : C:UsersRobertAppDataLocal
~ %StartMenu% : C:UsersRobertAppDataRoamingMicrosoftWindowsStart Menu
~ %Windir% : C:Windows
~ %System% : C:WindowsSystem32

—\ Enumération des unités disques
C: Hard drive, Flash drive, Thumb drive (Free 46 Go of 119 Go)
D: Hard drive, Flash drive, Thumb drive (Free 596 Go of 1397 Go)
E: Hard drive, Flash drive, Thumb drive (Free 1395 Go of 1397 Go)
F: CD-ROM drive (Not Inserted)
G: CD-ROM drive (Not Inserted)
H: Floppy drive, Flash card reader, USB Key (Not Inserted)

—\ Etat du Centre de Sécurité Windows
[HKLMSOFTWAREMicrosoftWindowsCurrentVersionPoliciesExplorer] NoActiveDesktopChanges: Modified
~ Security Center: 49 Legitimates Filtered in 00mn 00s

—\ Recherche particulière de fichiers génériques
[MD5.332FEAB1435662FC6C672E25BEB37BE3] – (.Microsoft Corporation – Explorateur Windows.) (.25.02.2011 – 07:19:30.) — C:WindowsExplorer.exe [2871808]
[MD5.94355C28C1970635A31B3FE52EB7CEBA] – (.Microsoft Corporation – Application de démarrage de Windows.) (.14.07.2009 – 02:39:52.) — C:WindowsSystem32Wininit.exe [129024]
[MD5.F220BA78AB542C70211D73AE4729B2CD] – (.Microsoft Corporation – Extensions Internet pour Win32.) (.06.03.2014 – 07:22:40.) — C:WindowsSystem32wininet.dll [2260480]
[MD5.88AB9B72B4BF3963A0DE0820B4B0B06C] – (.Microsoft Corporation – Application d’ouverture de session Windows.) (.04.03.2014 – 10:43:50.) — C:WindowsSystem32Winlogon.exe [455168]
[MD5.067FA52BFB59A56110A12312EF9AF243] – (.Microsoft Corporation – Bibliothèque de licences.) (.20.11.2010 – 14:27:26.) — C:WindowsSystem32sppcomapi.dll [232448]
[MD5.79059559E89D06E8B80CE2944BE20228] – (.Microsoft Corporation – Ancillary Function Driver for WinSock.) (.28.09.2013 – 02:09:10.) — C:Windowssystem32DriversAFD.sys [497152]
[MD5.02062C0B390B7729EDC9E69C680A6F3C] – (.Microsoft Corporation – ATAPI IDE Miniport Driver.) (.14.07.2009 – 02:52:21.) — C:Windowssystem32Driversatapi.sys [24128]
[MD5.B8BD2BB284668C84865658C77574381A] – (.Microsoft Corporation – CD-ROM File System Driver.) (.14.07.2009 – 00:19:47.) — C:Windowssystem32DriversCdfs.sys [92160]
[MD5.F036CE71586E93D94DAB220D7BDF4416] – (.Microsoft Corporation – SCSI CD-ROM Driver.) (.20.11.2010 – 10:19:21.) — C:Windowssystem32DriversCdrom.sys [147456]
[MD5.9BB2EF44EAA163B29C4A4587887A0FE4] – (.Microsoft Corporation – DFS Namespace Client Driver.) (.20.11.2010 – 10:26:32.) — C:Windowssystem32DriversDfsC.sys [102400]
[MD5.97BFED39B6B79EB12CDDBFEED51F56BB] – (.Microsoft Corporation – High Definition Audio Bus Driver.) (.20.11.2010 – 11:43:43.) — C:Windowssystem32DriversHDAudBus.sys [122368]
[MD5.FA55C73D4AFFA7EE23AC4BE53B4592D3] – (.Microsoft Corporation – Pilote de port i8042.) (.14.07.2009 – 00:19:57.) — C:Windowssystem32Driversi8042prt.sys [105472]
[MD5.AF9B39A7E7B6CAA203B3862582E9F2D0] – (.Microsoft Corporation – IP Network Address Translator.) (.14.07.2009 – 01:10:03.) — C:Windowssystem32DriversIpNat.sys [116224]
[MD5.A5D9106A73DC88564C825D317CAC68AC] – (.Microsoft Corporation – Windows NT SMB Minirdr.) (.27.04.2011 – 03:40:40.) — C:Windowssystem32DriversMRxSmb.sys [158208]
[MD5.09594D1089C523423B32A4229263F068] – (.Microsoft Corporation – MBT Transport driver.) (.20.11.2010 – 10:23:20.) — C:Windowssystem32DriversnetBT.sys [261632]
[MD5.1A29A59A4C5BA6F8C85062A613B7E2B2] – (.Microsoft Corporation – Pilote du système de fichiers NT.) (.24.01.2014 – 03:37:55.) — C:Windowssystem32Driversntfs.sys [1684928]
[MD5.0086431C29C35BE1DBC43F52CC273887] – (.Microsoft Corporation – Pilote de port parallèle.) (.14.07.2009 – 01:00:41.) — C:Windowssystem32DriversParport.sys [97280]
[MD5.471815800AE33E6F1C32FB1B97C490CA] – (.Microsoft Corporation – RAS L2TP mini-port/call-manager driver.) (.20.11.2010 – 11:52:35.) — C:Windowssystem32DriversRasl2tp.sys [129536]
[MD5.1B6163C503398B23FF8B939C67747683] – (.Microsoft Corporation – Microsoft RDP Device redirector.) (.20.11.2010 – 12:06:41.) — C:Windowssystem32Driversrdpdr.sys [165888]
[MD5.548260A7B8654E024DC30BF8A7C5BAA4] – (.Microsoft Corporation – SMB Transport driver.) (.14.07.2009 – 01:09:09.) — C:Windowssystem32Driverssmb.sys [93184]
[MD5.DDAD5A7AB24D8B65F8D724F5C20FD806] – (.Microsoft Corporation – TDI Translation Driver.) (.20.11.2010 – 10:21:56.) — C:Windowssystem32Driverstdx.sys [119296]
[MD5.0D08D2F3B3FF84E433346669B5E0F639] – (.Microsoft Corporation – Pilote de cliché instantané du volume.) (.20.11.2010 – 14:34:02.) — C:Windowssystem32Driversvolsnap.sys [295808]
~ Generic Processes: Scanned in 00mn 00s

—\ Etat des fichiers cachés (Caché/Total)
~ Mes musiques (My Musics) : 1/248
~ Mes Videos (My Videos) : 1/2
~ Mes Favoris (My Favorites) : 1/40
~ Mes Documents (My Documents) : 1/15
~ Mon Bureau (My Desktop) : 1/63
~ Menu demarrer (Programs) : 1/31
~ Hidden Files: Scanned in 00mn 00s

—\ Processus lancés
[MD5.08EFC4E112F3B26AC331AAFE17E49376] – (.SlySoft, Inc. – AnyDVD Application.) — C:Program Files (x86)SlySoftAnyDVDAnyDVDtray.exe [8088488] [PID.5012]
[MD5.95EA648ACEF2E5CF88A4E28302E1CCF8] – (.NETGEAR Inc. – NETGEAR Genie.) — C:Program Files (x86)NETGEAR GeniebinNETGEARGenie.exe [602880] [PID.5024]
[MD5.BF456A0CAFB2876583982E74F450D647] – (.Dropbox, Inc. – Dropbox.) — C:UsersRobertAppDataRoamingDropboxbinDropbox.exe [32668056] [PID.5084]
[MD5.7E91655B4947EC1B18B3BC1645839145] – (.Kaspersky Lab ZAO – Kaspersky Anti-Virus.) — C:Program Files (x86)Kaspersky LabKaspersky PURE 3.0avp.exe [356128] [PID.1688]
[MD5.CADE2638A7C3A4E15CE99F8D4FFC5A88] – (…) — C:Program Files (x86)NETGEAR Geniebingenie2_tray.exe [105216] [PID.5616]
[MD5.145AD71E3A05A558FEF9705B5EA6E2D1] – (.Kaspersky Lab – Kaspersky Password Manager.) — C:Program Files (x86)Kaspersky LabKaspersky PURE 3.0Kaspersky Password Managerstpass.exe [16317248] [PID.7016]
[MD5.D9FAA5EFEB27DDBE99C720B9069A451E] – (.Apple Inc. – iTunesHelper.) — C:Program Files (x86)iTunesiTunesHelper.exe [152392] [PID.8148]
[MD5.0667ED9F8E905E1F73DB60ACCEDCBCA7] – (.Microsoft Corporation – Internet Explorer.) — C:Program Files (x86)Internet ExplorerIEXPLORE.exe [811728] [PID.4432]
[MD5.322522D6FF36A539CAD732D182FA6D18] – (.Nicolas Coolman – ZHPDiag.) — C:Program Files (x86)ZHPDiagZHPDiag.exe [7878656] [PID.7568]
[MD5.B362181ED3771DC03B4141927C80F801] – (.Adobe Systems Incorporated – Adobe Acrobat Update Service.) — C:Program Files (x86)Common FilesAdobeARM1.0armsvc.exe [65432] [PID.1568]
[MD5.BC8A3EC1BAE3D18256C09DDE1082D0F3] – (.Samsung – AllShareFrameworkDMS.) — C:Program FilesSamsungAllShare Framework DMS1.3.23AllShareFrameworkDMS.exe [755080] [PID.1612]
[MD5.0F9FE82E229C039F0AC1996E44059653] – (.Infowatch – InfoWatch CryptoStorage Protected objects c.) — C:Program Files (x86)Common FilesInfoWatchCryptoStorageProtectedObjectsSrv.exe [819040] [PID.1796]
[MD5.782748F6CAE6A360AD8F60CFC88F4B01] – (…) — C:Program Files (x86)HoneywellEZConfig-Scanning v4HPAHSMPeripherals.exe [11776] [PID.1868]
[MD5.65085456FD9A74D7F1A999520C299ECB] – (.Malwarebytes Corporation – Malwarebytes Anti-Malware.) — C:Program Files (x86)Malwarebytes' Anti-Malwarembamscheduler.exe [418376] [PID.1900]
[MD5.ACE36C27A1F93797EC2B29A1A2B0FCD3] – (.TODO: – TODO: .) — C:Program Files (x86)HoneywellEZConfig-Scanning v4HPAHPA.exe [4078080] [PID.1908]
[MD5.543A4EF0923BF70D126625B034EF25AF] – (.Protexis Inc. – PsiService PsiService.) — c:Program Files (x86)Common FilesProtexisLicense ServicePsiService_2.exe [189728] [PID.2100]
[MD5.934BB0D23A25C8C136570800A5A149B6] – (.Nero AG – NeroUpdate.) — C:Program Files (x86)NeroUpdateNASvc.exe [687400] [PID.7632]
[MD5.221564CC7BE37611FE15EACF443E1BF6] – (.Apple Inc. – YSLoader.exe.) — C:Program Files (x86)Common FilesAppleMobile Device SupportAppleMobileDeviceService.exe [43336] [PID.6748]
~ Processes Running: Scanned in 00mn 00s

—\ Google Chrome, Démarrage,Recherche,Extensions (G0,G1,G2)
C:UsersRobertAppDataLocalGoogleChromeUser DataDefaultPreferences
G0 – GCSP: Preference [User DataDefault][HomePage] http://www.bluewin.ch” onclick=”window.open(this.href);return false;
G2 – GCE: Preference [User DataDefault] [apdfllckaahabafndbhieahigkjlhalf] Google Drive v.6.3 (Activé)
G2 – GCE: Preference [User DataDefault] [dhdnahjkclbpahfnjmpcbacidgllghba] Password Manager plugin v.7.0.3.11 (Activé)
G2 – GCE: Preference [User DataDefault] [edmenbbkdinanecgnpphpfdbdlnfobnb] Télévision v.1.0.0 (Activé)
G2 – GCE: Preference [User DataDefault] [hghkgaeecgjhjkannahfamoehjmkjail] Content Blocker v.13.0.2.614 (Désactivé)
G2 – GCE: Preference [User DataDefault] [jagncdcchgajhfhijbbhecadmaiegcmh] Virtual Keyboard v.13.0.2.614 (Désactivé)
G2 – GCE: Preference [User DataDefault] [neajdppkdcdipfabeoofebfddakdcjhd] Google Network Speech v.1.0 (Activé)
G2 – GCE: Preference [User DataDefault] [nkeimhogjdpnpccoofpliimaahmaaome] Hangout Services v.1.0 (Activé)
G2 – GCE: Preference [User DataDefault] [nmmhkkegccagdldgiimedpiccmgmieda] Google Wallet v.0.0.6.1 (Activé)

—\ Liste des dossiers d'extension Google Chrome
~ Google Lines Browser: 26 Legitimates Filtered in 00mn 02s

—\ Internet Explorer, Démarrage,Recherche,URLSearchHook, Phishing (R0,R1,R3,R4)
R0 – HKCUSOFTWAREMicrosoftInternet ExplorerMain,Start Page = http://www.bluewin.ch” onclick=”window.open(this.href);return false;
~ IE Browser: 17 Legitimates Filtered in 00mn 00s

—\ Internet Explorer, Proxy Management (R5)
R5 – HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings,ProxyOverride = *.local
R5 – HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings,ProxyServer = no key
R5 – HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings,ProxyEnable = 0
R5 – HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings,MigrateProxy = 1
R5 – HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings,EnableHttp1_1 = 1
R5 – HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings,AutoConfigProxy = wininet.dll
~ Proxy management: Scanned in 00mn 00s

—\ Analyse des lignes F0, F1, F2, F3 – IniFiles, Autoloading programs
F2 – REG:system.ini: USERINIT=C:Windowssystem32userinit.exe,
F2 – REG:system.ini: Shell=C:Windowsexplorer.exe
F2 – REG:system.ini: VMApplet=C:WindowsSystem32SystemPropertiesPerformance.exe
~ Keys: Scanned in 00mn 00s

—\ Hosts file redirection (O1)
~ Le fichier hosts est sain (The hosts file is clean).
~ Hosts File: Scanned in 00mn 00s
~ Nombre de lignes (Lines number): 25

—\ Internet Explorer Toolbars (O3)
O3 – Toolbar: Adobe Acrobat Create PDF Toolbar – [HKLM]{47833539-D0C5-4125-9FA8-0819E2EAAC93} . (.Adobe Systems Incorporated – Adobe PDF Toolbar for Internet Explorer.) — C:Program Files (x86)Common FilesAdobeAcrobatWCIEActiveXx64AcroIEFavClient.dll
O3 – Toolbar: Google Toolbar – [HKLM]{2318C2B1-4965-11d4-9B18-009027A5CD4F} . (.Google Inc. – Google Toolbar.) — C:Program Files (x86)GoogleGoogle ToolbarGoogleToolbar_64.dll =>Toolbar.Google
O3 – ToolbarWebBrowser: (no name) – [HKCU]{47833539-D0C5-4125-9FA8-0819E2EAAC93} Clé orpheline
~ Toolbar: Scanned in 00mn 00s

—\ Applications lancées au démarrage du système (O4)
O4 – HKLM..Run: [EvtMgr6] . (.Logitech, Inc. – Logitech SetPoint Event Manager (UNICODE).) — C:Program FilesLogitechSetPointPSetPoint.exe
O4 – HKLM..Run: [Samsung Link] . (.Copyright 2013 SAMSUNG – Samsung Link Tray Agent.) — D:DocumentsSamsung LinkSamsung Link Tray Agent.exe
O4 – HKCU..Run: [Sidebar] . (.Microsoft Corporation – Gadgets du Bureau Windows.) — C:Program FilesWindows Sidebarsidebar.exe =>.Microsoft Corporation
O4 – HKCU..Run: [AnyDVD] . (.SlySoft, Inc. – AnyDVD Application.) — C:Program Files (x86)SlySoftAnyDVDAnyDVD.exe
O4 – HKCU..Run: [NETGEARGenie] . (.NETGEAR Inc. – NETGEAR Genie.) — C:Program Files (x86)NETGEAR GeniebinNETGEARGenie.exe
O4 – HKLM..Wow6432NodeRun: [AVP] . (.Kaspersky Lab ZAO – Kaspersky Anti-Virus.) — C:Program Files (x86)Kaspersky LabKaspersky PURE 3.0avp.exe
O4 – HKLM..Wow6432NodeRun: [APSDaemon] . (.Apple Inc. – Apple Push.) — C:Program Files (x86)Common FilesAppleApple Application SupportAPSDaemon.exe
O4 – HKLM..Wow6432NodeRun: [iTunesHelper] . (.Apple Inc. – iTunesHelper.) — C:Program Files (x86)iTunesiTunesHelper.exe
O4 – HKUSS-1-5-19..Run: [Sidebar] . (.Microsoft Corporation – Gadgets du Bureau Windows.) — C:Program Files (x86)Windows SidebarSidebar.exe =>.Microsoft Corporation
O4 – HKUSS-1-5-20..Run: [Sidebar] . (.Microsoft Corporation – Gadgets du Bureau Windows.) — C:Program Files (x86)Windows SidebarSidebar.exe =>.Microsoft Corporation
O4 – HKUS.DEFAULT..RunOnce: [SPReview] . (.Microsoft Corporation – SP Reviewer.) — C:WindowsSystem32SPReviewSPReview.exe =>.Microsoft Corporation
O4 – HKUSS-1-5-18..RunOnce: [SPReview] . (.Microsoft Corporation – SP Reviewer.) — C:WindowsSystem32SPReviewSPReview.exe =>.Microsoft Corporation
O4 – HKUSS-1-5-19..RunOnce: [mctadmin] . (.Microsoft Corporation – MCTAdmin.) — C:WindowsSystem32mctadmin.exe =>.Microsoft Corporation
O4 – HKUSS-1-5-20..RunOnce: [mctadmin] . (.Microsoft Corporation – MCTAdmin.) — C:WindowsSystem32mctadmin.exe =>.Microsoft Corporation
O4 – HKUSS-1-5-21-1734556912-3800310981-1539476678-1001..Run: [Sidebar] . (.Microsoft Corporation – Gadgets du Bureau Windows.) — C:Program FilesWindows Sidebarsidebar.exe =>.Microsoft Corporation
O4 – HKUSS-1-5-21-1734556912-3800310981-1539476678-1001..Run: [AnyDVD] . (.SlySoft, Inc. – AnyDVD Application.) — C:Program Files (x86)SlySoftAnyDVDAnyDVD.exe
O4 – HKUSS-1-5-21-1734556912-3800310981-1539476678-1001..Run: [NETGEARGenie] . (.NETGEAR Inc. – NETGEAR Genie.) — C:Program Files (x86)NETGEAR GeniebinNETGEARGenie.exe
~ Application: Scanned in 00mn 00s

—\ Boutons situés sur la barre d'outils principale d'Internet Explorer (O9)
O9 – Extra button: Clavier virtuel [64Bits] – {0C4CC089-D306-440D-9772-464E226F6539} . (…) — C:Program Files (x86)Kaspersky LabKaspersky PURE 3.0kbrd.ico
O9 – Extra button: Se&nd to OneNote [64Bits] – {2670000A-7350-4f3c-8081-5663EE0C6C49} . (.Microsoft Corporation – Microsoft OneNote Internet Explorer Add-in.) — C:Program FilesMicrosoft Office 15rootOffice15ONBttnIE.dll =>.Microsoft Corporation
O9 – Extra button: Lync Click to Call [64Bits] – {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} . (.Microsoft Corporation – Microsoft Lync.) — C:Program FilesMicrosoft Office 15rootOffice15lync.exe
O9 – Extra button: OneNote Lin&ked Notes [64Bits] – {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} . (.Microsoft Corporation – Microsoft OneNote Internet Explorer Add-in.) — C:Program FilesMicrosoft Office 15rootOffice15ONBttnIELinkedNotes.dll =>.Microsoft Corporation
O9 – Extra button: Analyse des liens [64Bits] – {CCF151D8-D089-449F-A5A4-D9909053F20F} . (…) — C:Program Files (x86)Kaspersky LabKaspersky PURE 3.0logo.ico
~ IE Extra Buttons: Scanned in 00mn 00s

—\ Modification Domaine/Adresses DNS (O17)
O17 – HKLMSystemCCSServicesTcpip..{0EC83504-AB3B-4D84-ACAD-BC817F533604}: DhcpNameServer = 192.168.1.1
O17 – HKLMSystemCS1ServicesTcpip..{0EC83504-AB3B-4D84-ACAD-BC817F533604}: DhcpNameServer = 192.168.1.1
O17 – HKLMSystemCS2ServicesTcpip..{0EC83504-AB3B-4D84-ACAD-BC817F533604}: DhcpNameServer = 192.168.1.1
O17 – HKLMSystemCCSServicesTcpipParameters: DhcpNameServer = 192.168.1.1
~ Domain: Scanned in 00mn 00s

—\ Protocole additionnel (O18)
O18 – Handler: vbscript [64Bits] – {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation – Visionneuse HTML Microsoft (R).) — C:WindowsSystem32mshtml.dll =>.Microsoft Corporation
O18 – Filter: application/x-msdownload [64Bits] – {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation – Microsoft .NET Runtime Execution Engine.) — C:WindowsSystem32mscoree.dll =>.Microsoft Corporation
~ Protocole Additionnel: Scanned in 00mn 00s

—\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (autorun) (O20)
O20 – Winlogon Notify: LBTWlgn . (.Logitech, Inc. – Logitech Bluetooth Service.) — c:program filescommon fileslogishrdbluetoothLBTWlgn.dll
~ Winlogon: Scanned in 00mn 00s

—\ Liste des services NT non Microsoft et non désactivés (O23)
O23 – Service: HSM Peripherals (HSMPeripherals) . (…) – C:Program Files (x86)HoneywellEZConfig-Scanning v4HPAHSMPeripherals.exe
~ Services: 16 Legitimates Filtered in 00mn 06s

—\ Tâches planifiées en automatique (O39)
O39 – APT: – (..) — C:WindowsSystem32TasksAdobe Flash Player Updater [1002]
O39 – APT: – (..) — C:WindowsSystem32TasksGoogleUpdateTaskMachineCore [1064]
O39 – APT: – (..) — C:WindowsSystem32TasksGoogleUpdateTaskMachineUA [1068]
~ Scheduled Task: 12 Legitimates Filtered in 00mn 01s

—\ Logiciels installés (O42)
O42 – Logiciel: EZConfig-Scanning v4 – (.Honeywell.) [HKLM][64Bits] — {2938956D-9C7D-4D19-B625-F35FA2347560}
O42 – Logiciel: UseNeXT by Tangysoft – (.Tangysoft Ltd..) [HKLM][64Bits] — UseNeXT by Tangysoft_is1
~ Logic: 5 Legitimates Filtered in 00mn 00s

—\ HKCU & HKLM Software Keys
[HKCUSoftwareHoneywell]
[HKCUSoftwareMetrologic Instruments]
[HKCUSoftwarePando Networks]
[HKLMSoftwareWow6432NodeHoneywell]
[HKLMSoftwareWow6432NodePando Networks]
[HKLMSoftwareWow6432NodeUE BOOM]
~ Key Software: 258 Legitimates Filtered in 00mn 00s

—\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43)
O43 – CFD: 21.04.2014 – 17:49:33 – [] —-D C:Program Files (x86)Assistant de mise à jour de UE BOOM 1.2.38
O43 – CFD: 22.03.2014 – 15:58:42 – [] —-D C:Program Files (x86)Honeywell
O43 – CFD: 12.02.2014 – 22:32:35 – [] —-D C:Program Files (x86)Pando Networks
O43 – CFD: 20.03.2014 – 18:45:24 – [] —-D C:Program Files (x86)UseNeXT
O43 – CFD: 22.03.2014 – 15:39:54 – [] —-D C:Program Files (x86)Common FilesMetrologic
O43 – CFD: 14.02.2014 – 21:07:12 – [0] -SH-D C:ProgramData{FE8D473A-6F06-4F99-B5F4-BED72B2A038C}
O43 – CFD: 19.05.2014 – 21:05:21 – [] —-D C:UsersRobertAppDataRoamingUseNeXT
O43 – CFD: 12.02.2014 – 22:32:32 – [] —-D C:UsersRobertAppDataLocalPando_Temp
O43 – CFD: 21.04.2014 – 17:49:49 – [] —-D C:UsersRobertAppDataLocalUE BOOM
~ Program Folder: 167 Legitimates Filtered in 00mn 00s

—\ Derniers fichiers modifiés ou crées sous Windows et System32 (O44)
O44 – LFC:[MD5.1FBA28374B19570249ED4A4CBB6E1FDF] – 17.05.2014 – 07:16:07 —A- . (…) — C:Windowsntbtlog.txt [1034468]
~ Files: 65 Legitimates Filtered in 00mn 11s

—\ Enumération des clés de registre PoliciesSystem (MWPS) (O55)
O55 – MWPS:[HKLM…PoliciesSystem] – “EnableUIADesktopToggle”=0
O55 – MWPS:[HKLM…PoliciesSystem] – “FilterAdministratorToken”=0
O55 – MWPS:[HKLM…PoliciesSystem] – “EnableLinkedConnections”=1
~ MWPS: 19 Legitimates Filtered in 00mn 00s

—\ Enumération des clés de registre PoliciesExplorer (MWPE) (O56)
O56 – MWPE:[HKLM…policiesExplorer] – “NoActiveDesktopChanges”=1
~ MWPE Keys: 4 Legitimates Filtered in 00mn 00s

—\ Liste des pilotes du système (SDL) (O58)
O58 – SDL:29.03.2005 – 01:30:38 —A- . (.Pas de propriétaire – ATK0110 ACPI Utility.) — C:WindowsSystem32DriversASACPI.sys [8192]
~ Drivers: 21 Legitimates Filtered in 00mn 00s

—\ Derniers fichiers modifiés ou crées (Utilisateur) (O61)
O61 – LFC: 17.05.2014 – 07:17:16 —A- . (…) — C:UsersRobertDownloadsSetupAnyDVD7470.exe [10952784]
O61 – LFC: 17.05.2014 – 07:17:16 —A- . (.Inekman.) — C:UsersRobertDownloadsXtremsplit.exe [305664]
O61 – LFC: 19.05.2014 – 07:17:15 —A- . (…) — C:UsersRobertAppDataLocalGoogleChromeUser Datanacl_validation_cache.bin [128]
O61 – LFC: 19.05.2014 – 07:17:15 —A- . (…) — C:UsersRobertDesktopadwcleaner_3.209.exe [1328723]
~ 180 Fichiers temporaires (Temporary files)
~ 727 Fichiers cookies (Cookies files)
~ Files: 14 Legitimates Filtered in 00mn 02s

—\ Liste des outils de désinfection (LATC) (O63)
O63 – Logiciel: ZHPDiag 2014 – (.Nicolas Coolman.) [HKLM] — ZHPDiag_is1 =>.Nicolas Coolman
~ ADS: Scanned in 00mn 00s

—\ Menu de démarrage Internet (SMI) (O68)
O68 – StartMenuInternet: [HKLM..ShellopenCommand] (.Google Inc. – Google Chrome.) — C:Program Files (x86)GoogleChromeApplicationchrome.exe
O68 – StartMenuInternet: [HKLM..ShellopenCommand] (.Microsoft Corporation – Internet Explorer.) — C:Program FilesInternet Exploreriexplore.exe
~ Keys: Scanned in 00mn 00s

—\ Recherche d'infection sur les navigateurs internet (SBI) (O69)
O69 – SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} – (Bing) – http://www.bing.com” onclick=”window.open(this.href);return false;
O69 – SBI: SearchScopes [HKCU] {784DFDEE-A63A-475A-8D66-AFDE13BC36C2} [DefaultScope] – (Google) – http://www.google.com” onclick=”window.open(this.href);return false;
~ Keys: Scanned in 00mn 00s

—\ Enumère les fichiers Crack & Keygen (CKF) (O82)
C:UsersRobertDownloadsCorel DRAW X5 keygen.rar =>.Crack,Keygen
C:UsersRobertDownloadsCorel DRAW X5 keygen.rar =>.Crack,Keygen
D:DocumentsPinnacle Studio 17CrackKeygen.exe =>.Crack,Keygen
D:TelechargementCrackme1.zip =>.Crack,Keygen
D:Telechargementnaodiga.com_X5.Keygen.zip =>.Crack,Keygen
~ Files: Scanned in 00mn 41s

—\ Recherche particulière à la racine du système (SPRF) (O84)
[MD5.5272726DBB7A409A2F4E55356E335128] [SPRF][19.05.2014] (…) — C:UsersRobertDesktopadwcleaner_3.209.exe [1328723]
~ Files: 3 Legitimates Filtered in 00mn 00s

—\ Recherche des packages WindowsInstaller (WIS) (O93) (NTFS)
[MD5.F0331DC93B0E29C97541425F4BDA60EE] [WIS][26.04.2014] (.Google Inc. – Google Toolbar for Internet Explorer.) — C:WindowsInstaller4d1f4.msi [28672] =>Toolbar.Google
~ WIS: 1 Legitimates Filtered in 00mn 00s

—\ Recherche de clés de registre Tracing (O100)
HKLMSOFTWAREWow6432NodeMicrosoftTracingGoogleToolbarNotifier_RASAPI32 =>Toolbar.Google
~ BTK: 67 Legitimates Filtered in 00mn 00s

—\ Recherche de clés de registre CLSID (O101)
[HKCRCLSID{2318C2B1-4965-11d4-9B18-009027A5CD4F}] (Google Toolbar) =>Toolbar.Google
[HKCRCLSID{AA58ED58-01DD-4d91-8333-CF10577473F7}] (Google Toolbar Helper) =>Toolbar.Google
~ BCK: 5358 Legitimates Filtered in 00mn 05s

—\ Etat général des services non Microsoft (EGS) (SR=Running, SS=Stopped)
SS – | Demand 13.05.2014 257712 | (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) – C:WindowsSysWOW64MacromedFlashFlashPlayerUpdateService.exe
SS – | Auto 15.02.2014 116648 | (gupdate) . (.Google Inc..) – C:Program Files (x86)GoogleUpdateGoogleUpdate.exe
SS – | Demand 15.02.2014 116648 | (gupdatem) . (.Google Inc..) – C:Program Files (x86)GoogleUpdateGoogleUpdate.exe
SS – | Demand 26.04.2014 194032 | (gusvc) . (.Google.) – C:Program Files (x86)GoogleCommonGoogle UpdaterGoogleUpdaterService.exe
SS – | Demand 13.06.2013 357144 | (LBTServ) . (.Logitech, Inc..) – C:Program FilesCommon FilesLogiShrdBluetoothlbtserv.exe
SS – | Disabled 04.03.2011 73728 | (LightScribeService) . (.Hewlett-Packard Company.) – C:Program Files (x86)Common FilesLightScribeLSSrvc.exe
SS – | Auto 04.04.2013 701512 | (MBAMService) . (.Malwarebytes Corporation.) – C:Program Files (x86)Malwarebytes' Anti-Malwarembamservice.exe
SR – | Auto 21.12.2013 65432 | (AdobeARMservice) . (.Adobe Systems Incorporated.) – C:Program Files (x86)Common FilesAdobeARM1.0armsvc.exe
SR – | Auto 21.12.2013 404360 | (AllShare Framework DMS) . (.Samsung.) – C:Program FilesSamsungAllShare Framework DMS1.3.23AllShareFrameworkManagerDMS.exe
SR – | Auto 18.08.2009 203264 | (AMD External Events Utility) . (.AMD.) – C:WindowsSystem32atiesrxx.exe
SR – | Auto 12.02.2014 43336 | (Apple Mobile Device) . (.Apple Inc..) – C:Program Files (x86)Common FilesAppleMobile Device SupportAppleMobileDeviceService.exe
SR – | Auto 15.02.2014 356128 | (AVP) . (.Kaspersky Lab ZAO.) – C:Program Files (x86)Kaspersky LabKaspersky PURE 3.0avp.exe
SR – | Auto 30.08.2011 462184 | (Bonjour Service) . (.Apple Inc..) – C:Program FilesBonjourmDNSResponder.exe
SR – | Auto 21.12.2012 819040 | (CSObjectsSrv) . (.Infowatch.) – C:Program Files (x86)Common FilesInfoWatchCryptoStorageProtectedObjectsSrv.exe
SR – | Auto 31.01.2014 11776 | (HSMPeripherals) . (…) – C:Program Files (x86)HoneywellEZConfig-Scanning v4HPAHSMPeripherals.exe
SR – | Demand 15.05.2014 641352 | (iPod Service) . (.Apple Inc..) – C:Program FilesiPodbiniPodService.exe
SR – | Auto 04.04.2013 418376 | (MBAMScheduler) . (.Malwarebytes Corporation.) – C:Program Files (x86)Malwarebytes' Anti-Malwarembamscheduler.exe
SR – | Auto 25.11.2011 687400 | (NAUpdate) . (.Nero AG.) – C:Program Files (x86)NeroUpdateNASvc.exe
SR – | Auto 14.11.2013 232192 | (NETGEARGenieDaemon) . (.NETGEAR.) – C:Program Files (x86)NETGEAR GeniebinNETGEARGenieDaemon64.exe
SR – | Auto 10.03.2010 189728 | (PSI_SVC_2) . (.Protexis Inc..) – c:Program Files (x86)Common FilesProtexisLicense ServicePsiService_2.exe
SR – | Auto 19.05.2014 604512 | (Samsung Link Service) . (.Copyright 2013 SAMSUNG.) – D:DocumentsSamsung LinkSamsung Link.exe
SR – | Auto 15.04.2014 2140984 | (TuneUp.UtilitiesSvc) . (.TuneUp Software.) – C:Program Files (x86)TuneUp Utilities 2014TuneUpUtilitiesService64.exe
SR – | Auto 14.07.2009 27136 | C:WindowsSystem32uxtuneup.dll (UxTuneUp) . (.TuneUp Software.) – C:WindowsSystem32svchost.exe
SR – | Auto 14.07.2009 27136 | C:Program Files (x86)Windows Defendermpsvc.dll (WinDefend) . (.Microsoft Corporation.) – C:WindowsSystem32svchost.exe
SR – | Auto 10.07.1658 0 | (WMPNetworkSvc) . (…) – C:Program Files (x86)Windows Media Playerwmpnetwk.exe =>.Microsoft Corporation
SR – | Auto 14.07.2009 27136 | C:WindowsSystem32wuaueng.dll (wuauserv) . (.Microsoft Corporation.) – C:WindowsSystem32svchost.exe
~ Services: Scanned in 00mn 05s

—\ Recherche d'infection sur le Master Boot Record (MBR)(O80)
Run by Robert at 20.05.2014 07:18:08
~ OS 64 not supported by MBR tool
~ MBR: 0 Legitimates Filtered in 00mn 00s

—\ Recherche d'infection sur le Master Boot Record (MBRCheck)(O80)
Written by ad13, http://ad13.geekstog” onclick=”window.open(this.href);return false;
Run by Robert at 20.05.2014 07:18:10
********* Dump file Name *********
C:PhysicalDisk0_MBR.bin
~ MBR: Scanned in 00mn 02s

—\ Scan Additionnel (O88)
Database Version : 13029 – (19.05.2014)
Clés trouvées (Keys found) : 0
Valeurs trouvées (Values found) : 1
Dossiers trouvés (Folders found) : 0
Fichiers trouvés (Files found) : 3

[HKLMSoftwareMicrosoftInternet ExplorerToolbar]:{2318C2B1-4965-11d4-9B18-009027A5CD4F} =>Toolbar.Google^
C:WindowsInstaller4d1f4.msi =>Toolbar.Google^
[HKCRCLSID{2318C2B1-4965-11d4-9B18-009027A5CD4F}] (Google Toolbar) =>Toolbar.Google^
[HKCRCLSID{AA58ED58-01DD-4d91-8333-CF10577473F7}] (Google Toolbar Helper) =>Toolbar.Google^
~ Additionnel Scan: 390349 Items scanned in 00mn 14s

—\ Récapitulatif des détections trouvées sur votre station
~ MSI: 0 link(s) detected in 00mn 00s

~ 820 Legitimates filtered by white list
End of the scan (463 lines in 01mn 49s)(5)[/spoiler:3mdd2kaz]

Bonne journée