Gabriel,
Voici la seconde partie du rapport de Zhpdiag.
---\\ Derniers fichiers modifiés ou crées sous Windows et System32 (O44)
O44 - LFC:[MD5.76293EF1A6BFCCBD901107E514E48624] - 04/02/2015 - 03:49:50 ---A- . (.Microsoft Corporation - Application Experience Program Inventory Co.) -- C:\Windows\System32\aeinv.dll [886784]
O44 - LFC:[MD5.0389CAF21A50D13A90D2699750D499B5] - 04/02/2015 - 03:53:36 ---A- . (.Microsoft Corporation - Application Experience Program Cache.) -- C:\Windows\System32\aepic.dll [159744]
O44 - LFC:[MD5.EE0759179FC7EB0012AF1A69C8AAE185] - 04/02/2015 - 03:53:36 ---A- . (.Microsoft Corporation - Mise à jour des données de compatibilité de.) -- C:\Windows\System32\aepdu.dll [202752]
O44 - LFC:[MD5.48D5B4FC2235E069A444C105B65D40BD] - 04/02/2015 - 03:53:37 ---A- . (.Microsoft Corporation - Compatibility Appraiser.) -- C:\Windows\System32\appraiser.dll [767488]
O44 - LFC:[MD5.048FD5432E4C2B42EE39FD9F54ED162F] - 04/02/2015 - 03:53:39 ---A- . (.Microsoft Corporation - Device Inventory Library.) -- C:\Windows\System32\devinv.dll [325632]
O44 - LFC:[MD5.1C562DF669A412EF40A9871C8856AEE4] - 04/02/2015 - 03:53:44 ---A- . (.Microsoft Corporation - Program Compatibility Data Updater.) -- C:\Windows\System32\invagent.dll [621056]
O44 - LFC:[MD5.EEA1C649DBE9628150207BC563DA77F2] - 04/02/2015 - 03:54:02 ---A- . (.Microsoft Corporation - General Telemetry.) -- C:\Windows\System32\generaltel.dll [482304]
O44 - LFC:[MD5.8B2E310154ECCBB572B7BB3FAC2327A7] - 10/02/2015 - 14:45:07 ---A- . (...) -- C:\Windows\System32\PerfStringBackup.INI [1669656]
O44 - LFC:[MD5.AB95293A9627EFA54766384163AF0D6F] - 10/02/2015 - 14:45:07 ---A- . (...) -- C:\Windows\System32\perfc009.dat [122352]
O44 - LFC:[MD5.808724C7EC2802C0495B688B1277981F] - 10/02/2015 - 14:45:07 ---A- . (...) -- C:\Windows\System32\perfc00C.dat [150402]
O44 - LFC:[MD5.952DB43C194F3993191479EB8EA2DC6B] - 10/02/2015 - 14:45:07 ---A- . (...) -- C:\Windows\System32\perfh009.dat [654480]
O44 - LFC:[MD5.8665BB21BECF7D270018DDA164434930] - 10/02/2015 - 14:45:07 ---A- . (...) -- C:\Windows\System32\perfh00C.dat [747910]
O44 - LFC:[MD5.793F6658ED65839FDB2957A4884CB63C] - 11/02/2015 - 09:46:29 ---A- . (.Microsoft Corporation - Microsoft Windows Codecs Library.) -- C:\Windows\System32\WindowsCodecs.dll [1230336]
O44 - LFC:[MD5.B3BC38B886CA53C92D52EF724A9F0D45] - 11/02/2015 - 09:46:41 ---A- . (.Microsoft Corporation - Moteur de l’Éditeur de configuration de séc.) -- C:\Windows\System32\scesrv.dll [308224]
O44 - LFC:[MD5.0C96A745A76C7DD75C5503E86D968E49] - 11/02/2015 - 09:46:49 ---A- . (.Microsoft Corporation - Crypto API32.) -- C:\Windows\System32\crypt32.dll [1174528]
O44 - LFC:[MD5.E365C7B3EBB96451D3C9DF6B6B6900C2] - 11/02/2015 - 09:46:49 ---A- . (.Microsoft Corporation - Microsoft Trust Verification APIs.) -- C:\Windows\System32\wintrust.dll [179200]
O44 - LFC:[MD5.623E143F2DF17C0106A9988F5D7DC878] - 11/02/2015 - 09:46:49 ---A- . (.Microsoft Corporation - Services de chiffrement.) -- C:\Windows\System32\cryptsvc.dll [143872]
O44 - LFC:[MD5.3BB446DE24501FEA5FDB9A9DB23A22AE] - 11/02/2015 - 09:52:19 ---A- . (.Microsoft Corporation - Bibliothèque de chiffrement Windows.) -- C:\Windows\System32\ncrypt.dll [221184]
O44 - LFC:[MD5.C256EFD3655EC782F8094E96094E8F9E] - 11/02/2015 - 09:52:19 ---A- . (.Microsoft Corporation - Credential Delegation Security Package.) -- C:\Windows\System32\credssp.dll [17408]
O44 - LFC:[MD5.7D94A9161E8432B8521E60E064B1D737] - 11/02/2015 - 09:52:19 ---A- . (.Microsoft Corporation - Microsoft Authentication Package v1.0.) -- C:\Windows\System32\msv1_0.dll [259584]
O44 - LFC:[MD5.A12D64A94EC57079C2D96A741CB4FF53] - 11/02/2015 - 09:52:19 ---A- . (.Microsoft Corporation - Microsoft Digest Access.) -- C:\Windows\System32\wdigest.dll [172032]
O44 - LFC:[MD5.F3F6BE20A03215209B61CA85B4A83E1F] - 11/02/2015 - 09:52:19 ---A- . (.Microsoft Corporation - Web Service Security Package.) -- C:\Windows\System32\TSpkg.dll [65536]
O44 - LFC:[MD5.B63A6FF4339C9B701A93D3973C7FB6D2] - 11/02/2015 - 09:52:20 ---A- . (.Microsoft Corporation - Package de sécurité Kerberos.) -- C:\Windows\System32\kerberos.dll [550912]
O44 - LFC:[MD5.7C893DBA0A58855A99DA68B751FD223B] - 11/02/2015 - 09:52:20 ---A- . (.Microsoft Corporation - TLS / SSL Security Provider.) -- C:\Windows\System32\schannel.dll [248832]
O44 - LFC:[MD5.F57E1D225AE5C2C8F475A99BFDF018F4] - 11/02/2015 - 09:52:26 ---A- . (.Microsoft Corporation - Application Impact Telemetry Static Analyze.) -- C:\Windows\System32\aitstatic.exe [1167520]
O44 - LFC:[MD5.A208DAC2932649CFF82A6A684D8BB1F6] - 11/02/2015 - 09:52:29 ---A- . (.Microsoft Corporation - Pas de description.) -- C:\Windows\System32\oleaut32.dll [571904]
O44 - LFC:[MD5.B3AC14EA18DD0EE517703A86963AED18] - 11/02/2015 - 09:52:32 ---A- . (.Microsoft Corporation - Client avec accès à distance.) -- C:\Windows\System32\aaclient.dll [131584]
O44 - LFC:[MD5.F5142E9A99F44F9CC19A8AF31761F7F9] - 11/02/2015 - 09:52:33 ---A- . (.Microsoft Corporation - Client ActiveX des services Bureau à distan.) -- C:\Windows\System32\mstscax.dll [3221504]
O44 - LFC:[MD5.62C93E47A424A8EC79F3CF1719A2DCC6] - 11/02/2015 - 09:52:45 ---A- . (.Microsoft Corporation - NT Kernel & System.) -- C:\Windows\System32\ntkrnlpa.exe [3972544]
O44 - LFC:[MD5.6D227897A458DA8A9518DACDC88F1947] - 11/02/2015 - 09:52:45 ---A- . (.Microsoft Corporation - NT Kernel & System.) -- C:\Windows\System32\ntoskrnl.exe [3917760]
O44 - LFC:[MD5.36F152AE2F64B12771A44EA77124332B] - 11/02/2015 - 09:53:17 ---A- . (.Microsoft Corporation - DLL des événements d’audit de la sécurité.) -- C:\Windows\System32\msaudite.dll [146432]
O44 - LFC:[MD5.ACF312F6CCFC9249F739BF439DD4B80C] - 11/02/2015 - 09:53:17 ---A- . (.Microsoft Corporation - LSA SSPI RPC interface DLL.) -- C:\Windows\System32\sspisrv.dll [15872]
O44 - LFC:[MD5.BF08DE8E4FA1F143D41B3241F7FCE5F6] - 11/02/2015 - 09:53:17 ---A- . (.Microsoft Corporation - Local Security Authority Process.) -- C:\Windows\System32\lsass.exe [22528]
O44 - LFC:[MD5.43791D2F736C4E9BE9FE0B33A1E92A5D] - 11/02/2015 - 09:53:17 ---A- . (.Microsoft Corporation - Nom d’audit des objets système.) -- C:\Windows\System32\msobjs.dll [60416]
O44 - LFC:[MD5.4E6934926B4C923CC0FF61C6D77814EF] - 11/02/2015 - 09:53:17 ---A- . (.Microsoft Corporation - Programme de stratégie d’audit.) -- C:\Windows\System32\auditpol.exe [50176]
O44 - LFC:[MD5.F29BC66CE4A5507A49FB20744A056E61] - 11/02/2015 - 09:53:17 ---A- . (.Microsoft Corporation - Security Support Provider Interface.) -- C:\Windows\System32\secur32.dll [22016]
O44 - LFC:[MD5.CEFE50761B7681715C66AE3488363985] - 11/02/2015 - 09:53:17 ---A- . (.Microsoft Corporation - Security Support Provider Interface.) -- C:\Windows\System32\sspicli.dll [100352]
O44 - LFC:[MD5.F2A743912D404A8866362836CFE7A648] - 11/02/2015 - 09:53:18 ---A- . (.Microsoft Corporation - DLL du schéma d’audit de sécurité.) -- C:\Windows\System32\adtschema.dll [686080]
O44 - LFC:[MD5.4775E1A0E15BF148098C35A19135F881] - 11/02/2015 - 09:53:18 ---A- . (.Microsoft Corporation - DLL serveur LSA.) -- C:\Windows\System32\lsasrv.dll [1061376]
O44 - LFC:[MD5.F516F1167EFBBC5ABC90687C94497869] - 11/02/2015 - 09:53:18 ---A- . (.Microsoft Corporation - Kernel Cryptography, Next Generation.) -- C:\Windows\System32\Drivers\cng.sys [369968]
O44 - LFC:[MD5.EF88BAC2B489D9C46F4E41ACF0219CD0] - 11/02/2015 - 09:53:18 ---A- . (.Microsoft Corporation - Kernel Security Support Provider Interface.) -- C:\Windows\System32\Drivers\ksecdd.sys [67520]
O44 - LFC:[MD5.49D70660EE8266988C1F99A0297A1430] - 11/02/2015 - 09:53:18 ---A- . (.Microsoft Corporation - Kernel Security Support Provider Interface.) -- C:\Windows\System32\Drivers\ksecpkg.sys [136640]
O44 - LFC:[MD5.15E13FB1C22A47A128965287194D1906] - 11/02/2015 - 09:53:22 ---A- . (.Microsoft Corporation - Pilote Win32 multi-utilisateurs.) -- C:\Windows\System32\win32k.sys [2380288]
O44 - LFC:[MD5.180C599C9D5E15475EFEF3994067D739] - 11/02/2015 - 09:54:21 ---A- . (.Microsoft Corporation - Microsoft (R) JScript.) -- C:\Windows\System32\jscript9.dll [4300800]
O44 - LFC:[MD5.9DEE691C8FDBC2DE6957F1AE873C78FC] - 11/02/2015 - 09:54:22 ---A- . (.Microsoft Corporation - Microsoft ® VBScript.) -- C:\Windows\System32\vbscript.dll [503296]
O44 - LFC:[MD5.61C74D794C14E9FC94D93F5F0F72A3F9] - 11/02/2015 - 09:54:23 ---A- . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll [19740160]
O44 - LFC:[MD5.3B9EF1B8E154D202D32A7765E2F33554] - 11/02/2015 - 09:54:24 ---A- . (.Microsoft Corporation - DAC for Trident DOM.) -- C:\Windows\System32\MshtmlDac.dll [64000]
O44 - LFC:[MD5.9A91F9B5035F54C2D0BA92CF9B16EE34] - 11/02/2015 - 09:54:24 ---A- . (.Microsoft Corporation - Run time utility for Internet Explorer.) -- C:\Windows\System32\iertutil.dll [2277888]
O44 - LFC:[MD5.180168942E4A133C55E7BBF17DA3C142] - 11/02/2015 - 09:54:25 ---A- . (.Microsoft Corporation - Microsoft (R) HTML Media DLL.) -- C:\Windows\System32\mshtmlmedia.dll [1155072]
O44 - LFC:[MD5.D87759889FE7BCAE4461439139E62BAA] - 11/02/2015 - 09:54:25 ---A- . (.Microsoft Corporation - Microsoft® HTML Editing Component.) -- C:\Windows\System32\mshtmled.dll [76288]
O44 - LFC:[MD5.994E7459260D315573DD72783D1B78A7] - 11/02/2015 - 09:54:27 ---A- . (.Microsoft Corporation - Moteur de l’interface utilisateur d’Interne.) -- C:\Windows\System32\ieui.dll [478208]
O44 - LFC:[MD5.78A1A938D51D4F83A772123B93EE1612] - 11/02/2015 - 09:54:27 ---A- . (.Microsoft Corporation - Navigateur Internet.) -- C:\Windows\System32\ieframe.dll [12829184]
O44 - LFC:[MD5.F285D499EC42969D963CA49EADA63218] - 11/02/2015 - 09:54:29 ---A- . (.Microsoft Corporation - Extensions Internet pour Win32.) -- C:\Windows\System32\wininet.dll [1888256]
O44 - LFC:[MD5.44791AA90DF93DD79E63ED3A38657964] - 11/02/2015 - 09:54:29 ---A- . (.Microsoft Corporation - IE ETW Collector Service Resources.) -- C:\Windows\System32\ieetwcollectorres.dll [4096]
O44 - LFC:[MD5.5FB7E9786F70F4072663746072C9E6CE] - 11/02/2015 - 09:54:29 ---A- . (.Microsoft Corporation - IOD Version Map.) -- C:\Windows\System32\iesetup.dll [62464]
O44 - LFC:[MD5.6F10743069DFFC56DEE079204960844E] - 11/02/2015 - 09:54:30 ---A- . (.Microsoft Corporation - DLL de gestion d'utilisateur local et de co.) -- C:\Windows\System32\msrating.dll [168960]
O44 - LFC:[MD5.AD3F5926EC2C1F21FB45D1CDED6E2A47] - 11/02/2015 - 09:54:30 ---A- . (.Microsoft Corporation - Panneau de configuration Internet.) -- C:\Windows\System32\inetcpl.cpl [2052608]
O44 - LFC:[MD5.8FBC9680719ACDA9351B67D906C682F4] - 11/02/2015 - 09:54:31 ---A- . (.Microsoft Corporation - Microsoft Feeds Manager.) -- C:\Windows\System32\msfeeds.dll [688640]
O44 - LFC:[MD5.47B26D89EF9973E2DD586D0C827F61A9] - 11/02/2015 - 09:54:31 ---A- . (.Microsoft Corporation - Microsoft® MSHTML Typelib.) -- C:\Windows\System32\mshtml.tlb [2724864]
O44 - LFC:[MD5.8E8137569741D3693F88DDF94CC38C20] - 11/02/2015 - 09:54:32 ---A- . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\System32\urlmon.dll [1307136]
O44 - LFC:[MD5.55A84600EAAF8F1D3F0E6206E2EF6D48] - 11/02/2015 - 09:54:32 ---A- . (.Microsoft Corporation - JScript Proxy Auto-Configuration.) -- C:\Windows\System32\jsproxy.dll [47104]
O44 - LFC:[MD5.FD6AF61AF029B9BC2CF4EFF57CDD5821] - 11/02/2015 - 09:54:32 ---A- . (.Microsoft Corporation - Microsoft SmartScreen Filter.) -- C:\Windows\System32\ieapfltr.dll [710144]
O44 - LFC:[MD5.2575170E9ACE5924716D34E7761B1F11] - 11/02/2015 - 09:54:32 ---A- . (.Microsoft Corporation - Microsoft ® JScript Diagnostics.) -- C:\Windows\System32\jscript9diag.dll [620032]
O44 - LFC:[MD5.28B2D3CB1B4306D476200D80AF7D87AD] - 11/02/2015 - 09:54:32 ---A- . (.Microsoft Corporation - Outil d’installation sans assistance d’IE 7.) -- C:\Windows\System32\ieUnatt.exe [115712]
O44 - LFC:[MD5.74EA6C792F57E453261DA210C1BCEB53] - 11/02/2015 - 09:54:32 ---A- . (.Microsoft Corporation - Personnalisation d’IEAK.) -- C:\Windows\System32\iedkcs32.dll [342712]
O44 - LFC:[MD5.B0F7BD3492C2D60A70F15AEADCE1E2A6] - 11/02/2015 - 09:54:33 ---A- . (.Microsoft Corporation - IE ETW Collector Proxy Stub Resources.) -- C:\Windows\System32\ieetwproxystub.dll [47616]
O44 - LFC:[MD5.71189E2787179666BDCD1374AE92BF62] - 11/02/2015 - 09:54:33 ---A- . (.Microsoft Corporation - IE ETW Collector Service.) -- C:\Windows\System32\ieetwcollector.exe [102912]
O44 - LFC:[MD5.C4F2424A0671907FD3AC44EBE43C3C66] - 11/02/2015 - 09:54:33 ---A- . (.Microsoft Corporation - Microsoft Spell Checking Facility.) -- C:\Windows\System32\MsSpellCheckingFacility.exe [667648]
O44 - LFC:[MD5.E1A4D24281526DDFEA418F729CDA9DC6] - 11/02/2015 - 09:54:33 ---A- . (.Microsoft Corporation - Traitement de RunOnce complet avec interfac.) -- C:\Windows\System32\iernonce.dll [30720]
O44 - LFC:[MD5.73AFBF165241EB4502CD15107AA12CBA] - 11/02/2015 - 09:54:33 ---A- . (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Expl.) -- C:\Windows\System32\ie4uinit.exe [684544]
O44 - LFC:[MD5.94B1F7CE1AAA5542923E0AD63C4D0050] - 11/02/2015 - 09:54:34 ---A- . (.Microsoft Corporation - JavaScript Performance Collection Agent.) -- C:\Windows\System32\JavaScriptCollectionAgent.dll [60416]
O44 - LFC:[MD5.E185BDA84E5F03F4E1D8DCA30E209277] - 11/02/2015 - 10:57:16 ---A- . (...) -- C:\Windows\epplauncher.mif [1912]
O44 - LFC:[MD5.79CD788F17C0D836180BD89730DB8F87] - 11/02/2015 - 11:02:37 ---A- . (.Microsoft Corporation - Outil de suppression de logiciels malveilla.) -- C:\Windows\System32\MRT.exe [113756392]
O44 - LFC:[MD5.DC4B3E09E51A8F257312BA326908BA9E] - 11/02/2015 - 15:33:55 ---A- . (...) -- C:\Windows\System32\FNTCACHE.DAT [337600]
O44 - LFC:[MD5.E51B539FEC6A6485289F650E5E7D5156] - 11/02/2015 - 16:14:25 ---A- . (.Adobe Systems Incorporated - Adobe Flash Player Control Panel Applet.) -- C:\Windows\System32\FlashPlayerApp.exe [701616]
O44 - LFC:[MD5.4713ED2510365E9102172816D2CFB832] - 11/02/2015 - 16:14:25 ---A- . (.Adobe Systems Incorporated - Adobe Flash Player Control Panel Applet.) -- C:\Windows\System32\FlashPlayerCPLApp.cpl [71344]
O44 - LFC:[MD5.FB100366159B4A4E08029C053F14A6A0] - 12/02/2015 - 13:29:09 -S-A- . (...) -- C:\Windows\bootstat.dat [67584]
O44 - LFC:[MD5.1DF37DBD2F911BFE1902008A689466FB] - 12/02/2015 - 13:42:44 ----- . (...) -- C:\Windows\WindowsUpdate.log [1988789]
~ Files: 80 Scanned in 01mn 34s
---\\ Déni du service (Local Security Authority) (O48)
O48 - LSA:Local Security Authority Authentication Packages . (.Microsoft Corporation - Microsoft Authentication Package v1.0.) -- C:\Windows\System32\msv1_0.dll
O48 - LSA:Local Security Authority Notification Packages . (.Microsoft Corporation - Moteur du client de l’Éditeur de configuration de sécurité Windows.) -- C:\Windows\System32\scecli.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Package de sécurité Kerberos.) -- C:\Windows\System32\kerberos.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Microsoft Authentication Package v1.0.) -- C:\Windows\System32\msv1_0.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - TLS / SSL Security Provider.) -- C:\Windows\System32\schannel.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Microsoft Digest Access.) -- C:\Windows\System32\wdigest.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Web Service Security Package.) -- C:\Windows\System32\tspkg.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Pku2u Security Package.) -- C:\Windows\System32\pku2u.dll
O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corp. - LiveSSP.) -- C:\Windows\System32\livessp.dll
~ LSA: 9 Scanned in 00mn 00s
---\\ Contrôle du Safe Boot (CSB) (O49)
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\sermouse.sys . (.Microsoft Corporation - Pilote de filtre souris série.) -- C:\Windows\System32\Drivers\sermouse.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\vga.sys . (.Microsoft Corporation - VGA/Super VGA Video Driver.) -- C:\Windows\System32\Drivers\vga.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\vgasave.sys . (...) -- C:\Windows\System32\Drivers\vgasave.sys (.not file.)
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\volmgr.sys . (.Microsoft Corporation - Volume Manager Driver.) -- C:\Windows\System32\Drivers\volmgr.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\volmgrx.sys . (.Microsoft Corporation - Pilote d’extension du gestionnaire de volumes.) -- C:\Windows\System32\Drivers\volmgrx.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\ipnat.sys . (.Microsoft Corporation - IP Network Address Translator.) -- C:\Windows\System32\Drivers\ipnat.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\nsiproxy.sys . (.Microsoft Corporation - NSI Proxy.) -- C:\Windows\System32\Drivers\nsiproxy.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\rdpencdd.sys . (.Microsoft Corporation - RDP Encoder Miniport.) -- C:\Windows\System32\Drivers\rdpencdd.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\sermouse.sys . (.Microsoft Corporation - Pilote de filtre souris série.) -- C:\Windows\System32\Drivers\sermouse.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\vga.sys . (.Microsoft Corporation - VGA/Super VGA Video Driver.) -- C:\Windows\System32\Drivers\vga.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\vgasave.sys . (...) -- C:\Windows\System32\Drivers\vgasave.sys (.not file.)
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\volmgr.sys . (.Microsoft Corporation - Volume Manager Driver.) -- C:\Windows\System32\Drivers\volmgr.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\volmgrx.sys . (.Microsoft Corporation - Pilote d’extension du gestionnaire de volumes.) -- C:\Windows\System32\Drivers\volmgrx.sys
~ CSB: 13 Scanned in 00mn 00s
---\\ Clé de registre Shell MountPoints2 (MPSK) (O51)
O51 - MPSK:{206b211e-acae-11e1-b440-806e6f6e6963}\AutoRun\command. (...) -- D:\setup.exe (.not file.)
O51 - MPSK:{2b3009fa-a5e8-11e2-81ba-00238b2e1abf}\AutoRun\command. (...) -- E:\MicroLauncher.exe (.not file.)
O51 - MPSK:{616020f1-af22-11e1-a344-00238b2e1abf}\AutoRun\command. (...) -- E:\AutoRun.exe (.not file.)
O51 - MPSK:{616020fc-af22-11e1-a344-00238b2e1abf}\AutoRun\command. (...) -- D:\AutoRun.exe (.not file.)
O51 - MPSK:{d3ec5f52-865d-11e2-8813-00238b2e1abf}\AutoRun\command. (...) -- E:\WD SmartWare.exe (.not file.)
~ Keys: Scanned in 00mn 00s
---\\ Recherche d'infection sur les pilotes (HKLM)(TDSD) (O52)
O52 - TDSD: \Drivers32\"msacm.l3acm"="C:\Windows\System32\l3codeca.acm" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Layer-3 Audio Codec for MSACM.) -- C:\Windows\System32\l3codeca.acm
O52 - TDSD: \Drivers32\"vidc.cvid"="iccvid.dll" . (.Radius Inc. - Codec Cinepak®.) -- C:\Windows\System32\iccvid.dll
O52 - TDSD: \Drivers32\"VIDC.CFHD"="CFHD.DLL" . (.CineForm Inc. - CineForm VFW CODEC.) -- C:\Windows\System32\CFHD.dll
O52 - TDSD: \Drivers32\"vidc.iv50"="ir50_32.dll" . (.Intel Corporation - Intel Indeo® video 5.10.) -- C:\Windows\System32\ir50_32.dll
O52 - TDSD: \Drivers32\"vidc.iv41"="ir41_32.ax" . (.Intel Corporation - Intel Indeo® Video 4.5.) -- C:\Windows\System32\ir41_32.ax
O52 - TDSD: \Drivers32\"vidc.iv32"="ir32_32.dll" . (.Intel(R) Corporation - Pas de description.) -- C:\Windows\System32\ir32_32.dll
O52 - TDSD: \Drivers32\"vidc.iv31"="ir32_32.dll" . (.Intel(R) Corporation - Pas de description.) -- C:\Windows\System32\ir32_32.dll
O52 - TDSD: \Drivers32\"msacm.iac2"="C:\Windows\system32\iac25_32.ax" . (.Intel Corporation - Indeo® audio software.) -- C:\Windows\system32\iac25_32.ax
O52 - TDSD: \drivers.desc\"C:\Windows\System32\l3codeca.acm"="Fraunhofer IIS MPEG Layer-3 Codec" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Layer-3 Audio Codec for MSACM.) -- C:\Windows\System32\l3codeca.acm
O52 - TDSD: \drivers.desc\"CFHD.dll"="CineForm HD VFW Codec" . (.CineForm Inc. - CineForm VFW CODEC.) -- C:\Windows\System32\CFHD.dll
O52 - TDSD: \drivers.desc\"C:\Windows\system32\iac25_32.ax"="Indeo® audio software" . (.Intel Corporation - Indeo® audio software.) -- C:\Windows\system32\iac25_32.ax
~ TDSD: 11 Scanned in 00mn 00s
---\\ Enumération des clés de registre StartupReg (SMSR) (O53)
O53 - SMSR:HKLM\...\startupreg\Adobe ARM [Key] . (.Adobe Systems Incorporated - Adobe Reader and Acrobat Manager.) -- C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe =>.Adobe Systems Incorporated
O53 - SMSR:HKLM\...\startupreg\Google Update [Key] . (.Google Inc. - Programme d'installation de Google.) -- C:\Users\christophe\AppData\Local\Google\Update\GoogleUpdate.exe =>.Google Inc
~ SMSR Keys: 2 Scanned in 00mn 00s
---\\ Enumération des clés de registre SecurityProviders (MCSP) (O54)
O54 - MCSP:[HKLM\...\CurrentControlSet\Control] - (SecurityProviders) - (.Microsoft Corporation - Credential Delegation Security Package.) -- C:\Windows\System32\credssp.dll
O54 - MCSP:[HKLM\...\ControlSet001\Control] - (SecurityProviders) - (.Microsoft Corporation - Credential Delegation Security Package.) -- C:\Windows\System32\credssp.dll
~ MSCP: 2 Scanned in 00mn 00s
---\\ Enumération des clés de registre PoliciesSystem (MWPS) (O55)
O55 - MWPS:[HKLM\...\Policies\System] - "ConsentPromptBehaviorAdmin"=0
O55 - MWPS:[HKLM\...\Policies\System] - "ConsentPromptBehaviorUser"=3
O55 - MWPS:[HKLM\...\Policies\System] - "EnableInstallerDetection"=1
O55 - MWPS:[HKLM\...\Policies\System] - "EnableLUA"=0
O55 - MWPS:[HKLM\...\Policies\System] - "EnableSecureUIAPaths"=1
O55 - MWPS:[HKLM\...\Policies\System] - "EnableUIADesktopToggle"=0
O55 - MWPS:[HKLM\...\Policies\System] - "EnableVirtualization"=1
O55 - MWPS:[HKLM\...\Policies\System] - "PromptOnSecureDesktop"=0
O55 - MWPS:[HKLM\...\Policies\System] - "ValidateAdminCodeSignatures"=0
O55 - MWPS:[HKLM\...\Policies\System] - "dontdisplaylastusername"=0
O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticecaption"=0
O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticetext"=0
O55 - MWPS:[HKLM\...\Policies\System] - "scforceoption"=0
O55 - MWPS:[HKLM\...\Policies\System] - "shutdownwithoutlogon"=1
O55 - MWPS:[HKLM\...\Policies\System] - "undockwithoutlogon"=1
O55 - MWPS:[HKLM\...\Policies\System] - "FilterAdministratorToken"=0
~ MWPS: 16 Scanned in 00mn 00s
---\\ Enumération des clés de registre PoliciesExplorer (MWPE) (O56)
O56 - MWPE:[HKCU\...\policies\Explorer] - "NoDriveTypeAutoRun"=145
~ MWPE Keys: 1 Scanned in 00mn 00s
---\\ Liste des pilotes du système (SDL) (O58)
O58 - SDL:14/07/2009 - 02:26:15 ---A- . (.Adaptec, Inc. - Adaptec Windows SAS/SATA Storport Driver.) -- C:\Windows\System32\Drivers\adp94xx.sys [422976]
O58 - SDL:14/07/2009 - 02:26:17 ---A- . (.Adaptec, Inc. - Adaptec Windows SATA Storport Driver.) -- C:\Windows\System32\Drivers\adpahci.sys [297552]
O58 - SDL:14/07/2009 - 02:26:15 ---A- . (.Adaptec, Inc. - Adaptec StorPort Ultra320 SCSI Driver.) -- C:\Windows\System32\Drivers\adpu320.sys [146512]
O58 - SDL:01/05/2013 - 12:09:52 ---A- . (.Oak Technology Inc. - Audio File System.) -- C:\Windows\System32\Drivers\AFS.SYS [77004]
O58 - SDL:14/07/2009 - 02:26:15 ---A- . (.Acer Laboratories Inc. - ALi mini IDE Driver.) -- C:\Windows\System32\Drivers\aliide.sys [14400]
O58 - SDL:11/03/2011 - 06:38:37 ---A- . (.Advanced Micro Devices - AHCI 1.2 Device Driver.) -- C:\Windows\System32\Drivers\amdsata.sys [80256]
O58 - SDL:14/07/2009 - 02:26:15 ---A- . (.AMD Technologies Inc. - AMD Technology AHCI Compatible Controller Driver for Windows fa.) -- C:\Windows\System32\Drivers\amdsbs.sys [159312]
O58 - SDL:11/03/2011 - 06:38:37 ---A- . (.Advanced Micro Devices - Storage Filter Driver.) -- C:\Windows\System32\Drivers\amdxata.sys [22400]
O58 - SDL:14/07/2009 - 02:26:15 ---A- . (.Adaptec, Inc. - Adaptec RAID Storport Driver.) -- C:\Windows\System32\Drivers\arc.sys [76368]
O58 - SDL:14/07/2009 - 02:26:15 ---A- . (.Adaptec, Inc. - Adaptec SAS RAID WS03 Driver.) -- C:\Windows\System32\Drivers\arcsas.sys [86608]
O58 - SDL:14/09/2009 - 09:31:54 ---A- . (.AuthenTec, Inc. - AuthenTec Swipe Sensor WDF USB Driver.) -- C:\Windows\System32\Drivers\ATSwpWDF.sys [659328]
O58 - SDL:13/07/2009 - 23:02:49 ---A- . (.Broadcom Corporation - Pilote unifié NDIS6.x Broadcom NetXtreme Gigabit Ethernet..) -- C:\Windows\System32\Drivers\b57nd60x.sys [229888]
O58 - SDL:13/07/2009 - 23:53:28 ---A- . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Lower Filter Driver.) -- C:\Windows\System32\Drivers\BrFiltLo.sys [13568]
O58 - SDL:13/07/2009 - 23:53:28 ---A- . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Upper Filter Driver.) -- C:\Windows\System32\Drivers\BrFiltUp.sys [5248]
O58 - SDL:14/07/2009 - 01:57:25 ---A- . (.Brother Industries Ltd. - Pilote Brother Série I/F (WDM).) -- C:\Windows\System32\Drivers\BrSerId.sys [272128]
O58 - SDL:13/07/2009 - 23:53:32 ---A- . (.Brother Industries Ltd. - Brother Serial driver (WDM version).) -- C:\Windows\System32\Drivers\BrSerWdm.sys [62336]
O58 - SDL:13/07/2009 - 23:53:33 ---A- . (.Brother Industries Ltd. - Brother USB MDM Driver.) -- C:\Windows\System32\Drivers\BrUsbMdm.sys [12160]
O58 - SDL:13/07/2009 - 23:53:33 ---A- . (.Brother Industries Ltd. - Brother USB Serial Driver.) -- C:\Windows\System32\Drivers\BrUsbSer.sys [11904]
O58 - SDL:13/07/2009 - 23:02:48 ---A- . (.Broadcom Corporation - Broadcom NetXtreme II GigE VBD.) -- C:\Windows\System32\Drivers\bxvbdx.sys [430080]
O58 - SDL:14/07/2009 - 02:26:21 ---A- . (.CMD Technology, Inc. - CMD PCI IDE Bus Driver.) -- C:\Windows\System32\Drivers\cmdide.sys [15952]
O58 - SDL:14/07/2009 - 02:20:28 ---A- . (.Adaptec, Inc. - Adaptec Ultra SCSI miniport.) -- C:\Windows\System32\Drivers\djsvs.sys [70720]
O58 - SDL:14/07/2009 - 02:20:28 ---A- . (.Emulex - Storport Miniport Driver for LightPulse HBAs.) -- C:\Windows\System32\Drivers\elxstor.sys [453712]
O58 - SDL:13/07/2009 - 23:02:48 ---A- . (.Broadcom Corporation - Broadcom NetXtreme II 10 GigE VBD.) -- C:\Windows\System32\Drivers\evbdx.sys [3100160]
O58 - SDL:18/01/2010 - 17:48:42 ---A- . (.Huawei Tech. Co., Ltd. - HUAWEI USB Smart Card Driver.) -- C:\Windows\System32\Drivers\ewdcsc.sys [27136]
O58 - SDL:25/03/2010 - 09:08:38 ---A- . (.Huawei Technologies Co., Ltd. - USB Modem/Serial Device Driver.) -- C:\Windows\System32\Drivers\ewusbmdm.sys [105984]
O58 - SDL:30/04/2010 - 15:52:06 ---A- . (.Huawei Technologies Co., Ltd. - USB NDIS Miniport Driver.) -- C:\Windows\System32\Drivers\ewusbnet.sys [206336]
O58 - SDL:20/03/2010 - 10:56:04 ---A- . (.Huawei Technologies Co., Ltd. - USB Modem/Serial Device Driver.) -- C:\Windows\System32\Drivers\ew_hwusbdev.sys [101504]
O58 - SDL:22/05/2010 - 13:48:20 ---A- . (.Huawei Technologies Co., Ltd. - ew_jubusenum Driver.) -- C:\Windows\System32\Drivers\ew_jubusenum.sys [70656]
O58 - SDL:22/05/2010 - 13:48:20 ---A- . (.Huawei Technologies Co., Ltd. - ew_jucdcacm Driver.) -- C:\Windows\System32\Drivers\ew_jucdcacm.sys [69632]
O58 - SDL:22/05/2010 - 13:48:20 ---A- . (.Huawei Technologies Co., Ltd. - ew_jucdcecm Driver.) -- C:\Windows\System32\Drivers\ew_jucdcecm.sys [51584]
O58 - SDL:22/05/2010 - 13:48:22 ---A- . (.Huawei Technologies Co., Ltd. - ew_juextctrl Driver.) -- C:\Windows\System32\Drivers\ew_juextctrl.sys [26880]
O58 - SDL:22/05/2010 - 13:48:56 ---A- . (.Huawei Technologies Co., Ltd. - ew_jucdcecm Driver.) -- C:\Windows\System32\Drivers\ew_juwwanecm.sys [167936]
O58 - SDL:20/03/2010 - 11:06:58 ---A- . (.Huawei Technologies Co., Ltd. - Filter Driver.) -- C:\Windows\System32\Drivers\ew_usbenumfilter.sys [11136]
O58 - SDL:21/08/2012 - 13:01:22 ---A- . (.GEAR Software Inc. - CD DVD Filter.) -- C:\Windows\System32\Drivers\GEARAspiWDM.sys [26840]
O58 - SDL:13/07/2009 - 23:54:14 ---A- . (.Hauppauge Computer Works, Inc. - Hauppauge WinTV 885 Consumer IR Driver for eHome.) -- C:\Windows\System32\Drivers\hcw85cir.sys [26624]
O58 - SDL:14/07/2009 - 02:20:28 ---A- . (.Hewlett-Packard Company - Smart Array SAS/SATA Controller Media Driver.) -- C:\Windows\System32\Drivers\HpSAMD.sys [67152]
O58 - SDL:21/10/2005 - 18:58:52 ---A- . (.HP - IEEE-1284.4-1999 Driver (Windows 2000).) -- C:\Windows\System32\Drivers\HPZid412.sys [49920]
O58 - SDL:21/10/2005 - 18:58:58 ---A- . (.HP - IEEE-1284.4-1999 Print Class Driver.) -- C:\Windows\System32\Drivers\HPZipr12.sys [16496]
O58 - SDL:09/03/2003 - 05:31:02 ---A- . (.HP - 1284.4<->Usb Datalink Driver (Windows 2000).) -- C:\Windows\System32\Drivers\HPZius12.sys [21456]
O58 - SDL:11/03/2011 - 06:38:51 ---A- . (.Intel Corporation - Intel Matrix Storage Manager driver - ia32.) -- C:\Windows\System32\Drivers\iaStorV.sys [332160]
O58 - SDL:10/06/2009 - 22:19:30 ---A- . (.Intel Corporation - Intel Graphics Kernel Mode Driver.) -- C:\Windows\System32\Drivers\igdkmd32.sys [4756480]
O58 - SDL:14/07/2009 - 02:20:36 ---A- . (.Intel Corp./ICP vortex GmbH - Intel/ICP Raid Storport Driver.) -- C:\Windows\System32\Drivers\iirsp.sys [41040]
O58 - SDL:14/07/2009 - 02:20:36 ---A- . (.LSI Corporation - LSI Fusion-MPT FC Driver (StorPort).) -- C:\Windows\System32\Drivers\lsi_fc.sys [95824]
O58 - SDL:14/07/2009 - 02:20:37 ---A- . (.LSI Corporation - LSI Fusion-MPT SAS Driver (StorPort).) -- C:\Windows\System32\Drivers\lsi_sas.sys [89168]
O58 - SDL:14/07/2009 - 02:20:36 ---A- . (.LSI Corporation - LSI SAS Gen2 Driver (StorPort).) -- C:\Windows\System32\Drivers\lsi_sas2.sys [54864]
O58 - SDL:14/07/2009 - 02:20:36 ---A- . (.LSI Corporation - LSI Fusion-MPT SCSI Driver (StorPort).) -- C:\Windows\System32\Drivers\lsi_scsi.sys [96848]
O58 - SDL:14/07/2009 - 02:20:36 ---A- . (.LSI Corporation - MEGASAS RAID Controller Driver for Windows 7 for x86.) -- C:\Windows\System32\Drivers\megasas.sys [30800]
O58 - SDL:14/07/2009 - 02:20:36 ---A- . (.LSI Corporation, Inc. - LSI MegaRAID Software RAID Driver.) -- C:\Windows\System32\Drivers\MegaSR.sys [235584]
O58 - SDL:26/03/2012 - 13:50:12 ---A- . (.Apple Inc. - Apple Mobile Device Ethernet.) -- C:\Windows\System32\Drivers\netaapl.sys [18432]
O58 - SDL:13/01/2010 - 15:36:40 ---A- . (.Intel Corporation - Intel® Wireless WiFi Link Driver.) -- C:\Windows\System32\Drivers\NETw5s32.sys [6755840]
O58 - SDL:13/07/2009 - 23:02:51 ---A- . (.Intel Corporation - Intel® Wireless WiFi Link Driver.) -- C:\Windows\System32\Drivers\netw5v32.sys [4231168]
O58 - SDL:14/07/2009 - 02:20:44 ---A- . (.IBM Corporation - IBM ServeRAID Controller Driver.) -- C:\Windows\System32\Drivers\nfrd960.sys [44624]
O58 - SDL:11/03/2011 - 06:39:00 ---A- . (.NVIDIA Corporation - NVIDIA® nForce(TM) RAID Driver.) -- C:\Windows\System32\Drivers\nvraid.sys [117120]
O58 - SDL:11/03/2011 - 06:39:00 ---A- . (.NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver.) -- C:\Windows\System32\Drivers\nvstor.sys [143744]
O58 - SDL:04/03/2008 - 08:12:06 ---A- . (.O2Micro - o2media.) -- C:\Windows\System32\Drivers\o2media.sys [48600]
O58 - SDL:14/07/2009 - 02:19:04 ---A- . (.QLogic Corporation - QLogic Fibre Channel Stor Miniport Driver.) -- C:\Windows\System32\Drivers\ql2300.sys [1383488]
O58 - SDL:14/07/2009 - 02:19:04 ---A- . (.QLogic Corporation - QLogic iSCSI Storport Miniport Driver.) -- C:\Windows\System32\Drivers\ql40xx.sys [106064]
O58 - SDL:20/07/2011 - 13:13:16 ---A- . (.Research in Motion Ltd - RIM Virtual Serial Driver.) -- C:\Windows\System32\Drivers\RimSerial.sys [35328]
O58 - SDL:25/07/2011 - 16:53:48 ---A- . (.Research In Motion Limited - BlackBerry Device Driver.) -- C:\Windows\System32\Drivers\RimUsb.sys [64512]
O58 - SDL:13/07/2009 - 21:50:20 ---A- . (.Macrovision Corporation, Macrovision Europe - Macrovision SECURITY Driver.) -- C:\Windows\System32\Drivers\secdrv.sys [20480]
O58 - SDL:14/07/2009 - 02:19:04 ---A- . (.Silicon Integrated Systems Corp. - SiS RAID Stor Miniport Driver.) -- C:\Windows\System32\Drivers\sisraid2.sys [40016]
O58 - SDL:14/07/2009 - 02:19:04 ---A- . (.Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver.) -- C:\Windows\System32\Drivers\sisraid4.sys [77888]
O58 - SDL:14/07/2009 - 02:19:04 ---A- . (.Promise Technology - Promise SuperTrak EX Series Driver for Windows.) -- C:\Windows\System32\Drivers\stexstor.sys [21072]
O58 - SDL:25/03/2008 - 12:54:02 ---A- . (.TOSHIBA Corporation - TOSHIBA Bluetooth Port Emulation Driver.) -- C:\Windows\System32\Drivers\tosporte.sys [41472]
O58 - SDL:06/10/2008 - 16:56:38 ---A- . (.TOSHIBA CORPORATION - Bluetooth RF Bus Driver.) -- C:\Windows\System32\Drivers\tosrfbd.sys [137984]
O58 - SDL:03/03/2009 - 14:42:56 ---A- . (.TOSHIBA Corporation - Bluetooth RFBNEP Driver.) -- C:\Windows\System32\Drivers\tosrfbnp.sys [36864]
O58 - SDL:19/02/2009 - 15:20:10 ---A- . (.TOSHIBA Corporation - Bluetooth RFCOMM Driver.) -- C:\Windows\System32\Drivers\tosrfcom.sys [63872]
O58 - SDL:23/10/2006 - 15:32:20 ---A- . (.TOSHIBA Corporation - TOSHIBA Bluetooth EC Driver.) -- C:\Windows\System32\Drivers\tosrfec.sys [9216]
O58 - SDL:05/03/2009 - 10:03:16 ---A- . (.TOSHIBA Corporation. - Bluetooth HID Driver from TOSHIBA.) -- C:\Windows\System32\Drivers\Tosrfhid.sys [74368]
O58 - SDL:12/03/2009 - 10:33:08 ---A- . (.TOSHIBA Corporation. - Bluetooth BNEP Driver.) -- C:\Windows\System32\Drivers\tosrfnds.sys [16128]
O58 - SDL:23/03/2009 - 16:28:24 ---A- . (.TOSHIBA Corporation - Bluetooth Audio Driver (WDM).) -- C:\Windows\System32\Drivers\TosRfSnd.sys [54272]
O58 - SDL:19/03/2009 - 13:07:32 ---A- . (.TOSHIBA CORPORATION - Bluetooth USB Miniport Driver.) -- C:\Windows\System32\Drivers\tosrfusb.sys [43264]
O58 - SDL:09/11/2007 - 04:00:52 ---A- . (.TOSHIBA Corporation - TOSHIBA ACPI-Based Value Added Logical and General Purpose Devi.) -- C:\Windows\System32\Drivers\TVALZ_O.SYS [23640]
O58 - SDL:28/09/2012 - 10:32:56 ---A- . (.Apple, Inc. - Apple Mobile Device USB Driver.) -- C:\Windows\System32\Drivers\usbaapl.sys [44544]
O58 - SDL:14/07/2009 - 02:19:10 ---A- . (.VIA Technologies, Inc. - VIA Generic PCI IDE Bus Driver.) -- C:\Windows\System32\Drivers\viaide.sys [16976]
O58 - SDL:17/12/2009 - 23:18:50 ---A- . (.Cisco Systems, Inc. - Cisco AnyConnect VPN Client Virtual Miniport Adapter for Window.) -- C:\Windows\System32\Drivers\vpnva.sys [20152]
O58 - SDL:14/07/2009 - 02:19:11 ---A- . (.VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR AMD-X86-64.) -- C:\Windows\System32\Drivers\vsmraid.sys [141904]
O58 - SDL:13/07/2009 - 23:13:45 ---A- . (.Conexant Systems, Inc. - HSF_HWAZL WDM driver.) -- C:\Windows\System32\Drivers\VSTAZL3.SYS [207360]
O58 - SDL:13/07/2009 - 23:13:45 ---A- . (.Conexant Systems, Inc. - HSF_CNXT driver.) -- C:\Windows\System32\Drivers\VSTCNXT3.SYS [661504]
O58 - SDL:13/07/2009 - 23:13:46 ---A- . (.Conexant Systems, Inc. - HSF_DP driver.) -- C:\Windows\System32\Drivers\VSTDPV3.SYS [980992]
O58 - SDL:13/07/2009 - 23:02:53 ---A- . (.Marvell - Pilote Miniport pour contrôleur Ethernet Marvell Yukon..) -- C:\Windows\System32\Drivers\yk62x86.sys [311296]
O58 - SDL:13/07/2009 - 22:40:41 ---A- . (...) -- C:\Windows\System32\ANSI.SYS [9029]
O58 - SDL:13/07/2009 - 22:40:44 ---A- . (...) -- C:\Windows\System32\country.sys [27097]
O58 - SDL:13/07/2009 - 22:40:40 ---A- . (...) -- C:\Windows\System32\HIMEM.SYS [4768]
O58 - SDL:13/07/2009 - 22:40:43 ---A- . (...) -- C:\Windows\System32\KEY01.SYS [42809]
O58 - SDL:13/07/2009 - 22:40:43 ---A- . (...) -- C:\Windows\System32\KEYBOARD.SYS [42537]
O58 - SDL:13/07/2009 - 22:40:23 ---A- . (...) -- C:\Windows\System32\NTDOS.SYS [27866]
O58 - SDL:13/07/2009 - 22:40:31 ---A- . (...) -- C:\Windows\System32\NTDOS404.SYS [29146]
O58 - SDL:13/07/2009 - 22:40:35 ---A- . (...) -- C:\Windows\System32\NTDOS411.SYS [29370]
O58 - SDL:13/07/2009 - 22:40:39 ---A- . (...) -- C:\Windows\System32\NTDOS412.SYS [29274]
O58 - SDL:13/07/2009 - 22:40:27 ---A- . (...) -- C:\Windows\System32\NTDOS804.SYS [29146]
O58 - SDL:13/07/2009 - 22:40:11 ---A- . (...) -- C:\Windows\System32\NTIO.SYS [33952]
O58 - SDL:13/07/2009 - 22:40:15 ---A- . (...) -- C:\Windows\System32\NTIO404.SYS [34672]
O58 - SDL:13/07/2009 - 22:40:17 ---A- . (...) -- C:\Windows\System32\NTIO411.SYS [35776]
O58 - SDL:13/07/2009 - 22:40:19 ---A- . (...) -- C:\Windows\System32\NTIO412.SYS [35536]
O58 - SDL:13/07/2009 - 22:40:13 ---A- . (...) -- C:\Windows\System32\NTIO804.SYS [34672]
~ Drivers: 96 Scanned in 00mn 24s
---\\ Derniers fichiers modifiés ou crées (Utilisateur) (O61)
O61 - LFC: 05/02/2015 - 13:47:33 ---A- . (...) -- C:\Users\christophe\AppData\Local\Google\Update\Download\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}\40.0.2214.111\40.0.2214.111_40.0.2214.94_chrome_updater.exe [1043024]
O61 - LFC: 07/02/2015 - 13:47:29 ---A- . (.Google Inc..) -- C:\Users\christophe\AppData\Local\Google\Chrome\Application\40.0.2214.111\Installer\setup.exe [1086280]
O61 - LFC: 10/02/2015 - 13:47:30 ---A- . (...) -- C:\Users\christophe\AppData\Local\Google\Update\1.3.26.9\GoogleUpdateComRegisterShell64.exe [115528]
O61 - LFC: 10/02/2015 - 13:47:30 ---A- . (.Google Inc..) -- C:\Users\christophe\AppData\Local\Google\Update\1.3.26.9\GoogleCrashHandler.exe [232264]
O61 - LFC: 10/02/2015 - 13:47:30 ---A- . (.Google Inc..) -- C:\Users\christophe\AppData\Local\Google\Update\1.3.26.9\GoogleCrashHandler64.exe [287048]
O61 - LFC: 10/02/2015 - 13:47:30 ---A- . (.Google Inc..) -- C:\Users\christophe\AppData\Local\Google\Update\1.3.26.9\GoogleUpdate.exe [107848]
O61 - LFC: 10/02/2015 - 13:47:30 ---A- . (.Google Inc..) -- C:\Users\christophe\AppData\Local\Google\Update\1.3.26.9\GoogleUpdateBroker.exe [52040]
O61 - LFC: 10/02/2015 - 13:47:30 ---A- . (.Google Inc..) -- C:\Users\christophe\AppData\Local\Google\Update\1.3.26.9\GoogleUpdateOnDemand.exe [52040]
O61 - LFC: 10/02/2015 - 13:47:30 ---A- . (.Google Inc..) -- C:\Users\christophe\AppData\Local\Google\Update\1.3.26.9\GoogleUpdateWebPlugin.exe [52040]
O61 - LFC: 10/02/2015 - 13:47:30 ---A- . (.Google Inc..) -- C:\Users\christophe\AppData\Local\Google\Update\1.3.26.9\goopdate.dll [1683272]
O61 - LFC: 10/02/2015 - 13:47:31 ---A- . (.Google Inc..) -- C:\Users\christophe\AppData\Local\Google\Update\1.3.26.9\goopdateres_am.dll [37704]
O61 - LFC: 10/02/2015 - 13:47:31 ---A- . (.Google Inc..) -- C:\Users\christophe\AppData\Local\Google\Update\1.3.26.9\goopdateres_ar.dll [36680]
O61 - LFC: 10/02/2015 - 13:47:31 ---A- . (.Google Inc..) -- C:\Users\christophe\AppData\Local\Google\Update\1.3.26.9\goopdateres_bg.dll [39752]
O61 - LFC: 10/02/2015 - 13:47:31 ---A- . (.Google Inc..) -- C:\Users\christophe\AppData\Local\Google\Update\1.3.26.9\goopdateres_bn.dll [39752]
O61 - LFC: 10/02/2015 - 13:47:31 ---A- . (.Google Inc..) -- C:\Users\christophe\AppData\Local\Google\Update\1.3.26.9\goopdateres_ca.dll [39752]
O61 - LFC: 10/02/2015 - 13:47:31 ---A- . (.Google Inc..) -- C:\Users\christophe\AppData\Local\Google\Update\1.3.26.9\goopdateres_cs.dll [38728]
O61 - LFC: 10/02/2015 - 13:47:31 ---A- . (.Google Inc..) -- C:\Users\christophe\AppData\Local\Google\Update\1.3.26.9\goopdateres_da.dll [38728]
O61 - LFC: 10/02/2015 - 13:47:31 ---A- . (.Google Inc..) -- C:\Users\christophe\AppData\Local\Google\Update\1.3.26.9\goopdateres_de.dll [40776]
O61 - LFC: 10/02/2015 - 13:47:31 ---A- . (.Google Inc..) -- C:\Users\christophe\AppData\Local\Google\Update\1.3.26.9\goopdateres_el.dll [40264]
O61 - LFC: 10/02/2015 - 13:47:31 ---A- . (.Google Inc..) -- C:\Users\christophe\AppData\Local\Google\Update\1.3.26.9\goopdateres_en-GB.dll [37704]
O61 - LFC: 10/02/2015 - 13:47:31 ---A- . (.Google Inc..) -- C:\Users\christophe\AppData\Local\Google\Update\1.3.26.9\goopdateres_en.dll [37704]
O61 - LFC: 10/02/2015 - 13:47:31 ---A- . (.Google Inc..) -- C:\Users\christophe\AppData\Local\Google\Update\1.3.26.9\goopdateres_es-419.dll [39240]
O61 - LFC: 10/02/2015 - 13:47:31 ---A- . (.Google Inc..) -- C:\Users\christophe\AppData\Local\Google\Update\1.3.26.9\goopdateres_es.dll [40776]
O61 - LFC: 10/02/2015 - 13:47:31 ---A- . (.Google Inc..) -- C:\Users\christophe\AppData\Local\Google\Update\1.3.26.9\goopdateres_et.dll [38216]
O61 - LFC: 10/02/2015 - 13:47:31 ---A- . (.Google Inc..) -- C:\Users\christophe\AppData\Local\Google\Update\1.3.26.9\goopdateres_fa.dll [37704]
O61 - LFC: 10/02/2015 - 13:47:31 ---A- . (.Google Inc..) -- C:\Users\christophe\AppData\Local\Google\Update\1.3.26.9\goopdateres_fi.dll [38728]
O61 - LFC: 10/02/2015 - 13:47:31 ---A- . (.Google Inc..) -- C:\Users\christophe\AppData\Local\Google\Update\1.3.26.9\goopdateres_fil.dll [39752]
O61 - LFC: 10/02/2015 - 13:47:31 ---A- . (.Google Inc..) -- C:\Users\christophe\AppData\Local\Google\Update\1.3.26.9\goopdateres_fr.dll [40264]
O61 - LFC: 10/02/2015 - 13:47:31 ---A- . (.Google Inc..) -- C:\Users\christophe\AppData\Local\Google\Update\1.3.26.9\goopdateres_gu.dll [40264]
O61 - LFC: 10/02/2015 - 13:47:31 ---A- . (.Google Inc..) -- C:\Users\christophe\AppData\Local\Google\Update\1.3.26.9\goopdateres_hi.dll [38728]
O61 - LFC: 10/02/2015 - 13:47:31 ---A- . (.Google Inc..) -- C:\Users\christophe\AppData\Local\Google\Update\1.3.26.9\goopdateres_hr.dll [39240]
O61 - LFC: 10/02/2015 - 13:47:32 ---A- . (.Google Inc.) -- C:\Users\christophe\AppData\Local\Google\Update\1.3.26.9\goopdateres_ko.dll [34632]
O61 - LFC: 10/02/2015 - 13:47:32 ---A- . (.Google Inc..) -- C:\Users\christophe\AppData\Local\Google\Update\1.3.26.9\goopdateres_hu.dll [39240]
O61 - LFC: 10/02/2015 - 13:47:32 ---A- . (.Google Inc..) -- C:\Users\christophe\AppData\Local\Google\Update\1.3.26.9\goopdateres_id.dll [38216]
O61 - LFC: 10/02/2015 - 13:47:32 ---A- . (.Google Inc..) -- C:\Users\christophe\AppData\Local\Google\Update\1.3.26.9\goopdateres_is.dll [38728]
O61 - LFC: 10/02/2015 - 13:47:32 ---A- . (.Google Inc..) -- C:\Users\christophe\AppData\Local\Google\Update\1.3.26.9\goopdateres_it.dll [40264]
O61 - LFC: 10/02/2015 - 13:47:32 ---A- . (.Google Inc..) -- C:\Users\christophe\AppData\Local\Google\Update\1.3.26.9\goopdateres_iw.dll [36168]
O61 - LFC: 10/02/2015 - 13:47:32 ---A- . (.Google Inc..) -- C:\Users\christophe\AppData\Local\Google\Update\1.3.26.9\goopdateres_ja.dll [35144]
O61 - LFC: 10/02/2015 - 13:47:32 ---A- . (.Google Inc..) -- C:\Users\christophe\AppData\Local\Google\Update\1.3.26.9\goopdateres_kn.dll [40264]
O61 - LFC: 10/02/2015 - 13:47:32 ---A- . (.Google Inc..) -- C:\Users\christophe\AppData\Local\Google\Update\1.3.26.9\goopdateres_lv.dll [39240]
O61 - LFC: 10/02/2015 - 13:47:32 ---A- . (.Google Inc..) -- C:\Users\christophe\AppData\Local\Google\Update\1.3.26.9\goopdateres_ml.dll [41800]
O61 - LFC: 10/02/2015 - 13:47:32 ---A- . (.Google Inc..) -- C:\Users\christophe\AppData\Local\Google\Update\1.3.26.9\goopdateres_mr.dll [39752]
O61 - LFC: 10/02/2015 - 13:47:32 ---A- . (.Google Inc..) -- C:\Users\christophe\AppData\Local\Google\Update\1.3.26.9\goopdateres_ms.dll [38216]
O61 - LFC: 10/02/2015 - 13:47:32 ---A- . (.Google Inc..) -- C:\Users\christophe\AppData\Local\Google\Update\1.3.26.9\goopdateres_nl.dll [39752]
O61 - LFC: 10/02/2015 - 13:47:32 ---A- . (.Google Inc..) -- C:\Users\christophe\AppData\Local\Google\Update\1.3.26.9\goopdateres_no.dll [38728]
O61 - LFC: 10/02/2015 - 13:47:32 ---A- . (.Google Inc..) -- C:\Users\christophe\AppData\Local\Google\Update\1.3.26.9\goopdateres_pl.dll [39240]
O61 - LFC: 10/02/2015 - 13:47:32 ---A- . (.Google Inc..) -- C:\Users\christophe\AppData\Local\Google\Update\1.3.26.9\goopdateres_pt-BR.dll [38728]
O61 - LFC: 10/02/2015 - 13:47:32 ---A- . (.Google Inc..) -- C:\Users\christophe\AppData\Local\Google\Update\1.3.26.9\goopdateres_pt-PT.dll [39240]
O61 - LFC: 10/02/2015 - 13:47:32 ---A- . (.Google Inc..) -- C:\Users\christophe\AppData\Local\Google\Update\1.3.26.9\goopdateres_ro.dll [39240]
O61 - LFC: 10/02/2015 - 13:47:32 ---A- . (.Google Inc..) -- C:\Users\christophe\AppData\Local\Google\Update\1.3.26.9\goopdateres_ru.dll [38216]
O61 - LFC: 10/02/2015 - 13:47:32 ---A- . (.Google Inc..) -- C:\Users\christophe\AppData\Local\Google\Update\1.3.26.9\goopdateres_sk.dll [38728]
O61 - LFC: 10/02/2015 - 13:47:32 ---A- . (.Google Inc..) -- C:\Users\christophe\AppData\Local\Google\Update\1.3.26.9\goopdateres_sl.dll [39240]
O61 - LFC: 10/02/2015 - 13:47:32 ---A- . (.Google Inc..) -- C:\Users\christophe\AppData\Local\Google\Update\1.3.26.9\goopdateres_sr.dll [38728]
O61 - LFC: 10/02/2015 - 13:47:32 ---A- . (.Google Inc..) -- C:\Users\christophe\AppData\Local\Google\Update\1.3.26.9\goopdateres_sv.dll [38728]
O61 - LFC: 10/02/2015 - 13:47:32 ---A- . (.Google Inc..) -- C:\Users\christophe\AppData\Local\Google\Update\1.3.26.9\goopdateres_sw.dll [40264]
O61 - LFC: 10/02/2015 - 13:47:32 ---A- . (.„Google Inc.“.) -- C:\Users\christophe\AppData\Local\Google\Update\1.3.26.9\goopdateres_lt.dll [38216]
O61 - LFC: 10/02/2015 - 13:47:33 ---A- . (.Google Inc..) -- C:\Users\christophe\AppData\Local\Google\Update\1.3.26.9\goopdateres_ta.dll [40776]
O61 - LFC: 10/02/2015 - 13:47:33 ---A- . (.Google Inc..) -- C:\Users\christophe\AppData\Local\Google\Update\1.3.26.9\goopdateres_te.dll [40264]
O61 - LFC: 10/02/2015 - 13:47:33 ---A- . (.Google Inc..) -- C:\Users\christophe\AppData\Local\Google\Update\1.3.26.9\goopdateres_th.dll [37704]
O61 - LFC: 10/02/2015 - 13:47:33 ---A- . (.Google Inc..) -- C:\Users\christophe\AppData\Local\Google\Update\1.3.26.9\goopdateres_tr.dll [38728]
O61 - LFC: 10/02/2015 - 13:47:33 ---A- . (.Google Inc..) -- C:\Users\christophe\AppData\Local\Google\Update\1.3.26.9\goopdateres_uk.dll [38728]
O61 - LFC: 10/02/2015 - 13:47:33 ---A- . (.Google Inc..) -- C:\Users\christophe\AppData\Local\Google\Update\1.3.26.9\goopdateres_ur.dll [38728]
O61 - LFC: 10/02/2015 - 13:47:33 ---A- . (.Google Inc..) -- C:\Users\christophe\AppData\Local\Google\Update\1.3.26.9\goopdateres_vi.dll [38216]
O61 - LFC: 10/02/2015 - 13:47:33 ---A- . (.Google Inc..) -- C:\Users\christophe\AppData\Local\Google\Update\1.3.26.9\goopdateres_zh-CN.dll [32584]
O61 - LFC: 10/02/2015 - 13:47:33 ---A- . (.Google Inc..) -- C:\Users\christophe\AppData\Local\Google\Update\1.3.26.9\goopdateres_zh-TW.dll [32584]
O61 - LFC: 10/02/2015 - 13:47:33 ---A- . (.Google Inc..) -- C:\Users\christophe\AppData\Local\Google\Update\1.3.26.9\npGoogleUpdate3.dll [599368]
O61 - LFC: 10/02/2015 - 13:47:33 ---A- . (.Google Inc..) -- C:\Users\christophe\AppData\Local\Google\Update\1.3.26.9\psmachine.dll [165704]
O61 - LFC: 10/02/2015 - 13:47:33 ---A- . (.Google Inc..) -- C:\Users\christophe\AppData\Local\Google\Update\1.3.26.9\psmachine_64.dll [188232]
O61 - LFC: 10/02/2015 - 13:47:33 ---A- . (.Google Inc..) -- C:\Users\christophe\AppData\Local\Google\Update\1.3.26.9\psuser.dll [165704]
O61 - LFC: 10/02/2015 - 13:47:33 ---A- . (.Google Inc..) -- C:\Users\christophe\AppData\Local\Google\Update\1.3.26.9\psuser_64.dll [188232]
O61 - LFC: 11/02/2015 - 13:51:20 ---A- . (.Piriform Ltd.) -- C:\Users\christophe\Downloads\ccsetup502.exe [5325208]
O61 - LFC: 12/02/2015 - 13:50:59 ---A- . (...) -- C:\Users\christophe\Downloads\AdwCleaner-4.110.exe [2112512]
O61 - LFC: 12/02/2015 - 13:51:45 ---A- . (.Nicolas Coolman.) -- C:\Users\christophe\Downloads\ZHPDiag2.exe [6874603] =>.Nicolas Coolman
~ 4 Fichiers temporaires (Temporary files)
~ 29 Fichiers cookies (Cookies files)
~ Files: 73 Scanned in 04mn 25s
---\\ Liste des outils de désinfection (LATC) (O63)
O63 - Logiciel: ZHPDiag 2015 - (.Nicolas Coolman.) [HKLM] -- ZHPDiag_is1 =>.Nicolas Coolman
~ ADS: Scanned in 00mn 00s
---\\ Liste les services legacy du registre (LALS) (O64)
O64 - Services: CurCS - 01/05/2013 - C:\Windows\System32\Drivers\AFS.sys (AFS) .(.Oak Technology Inc. - Audio File System.) - LEGACY_AFS
O64 - Services: CurCS - 13/07/2009 - C:\Windows\System32\Drivers\secdrv.sys (secdrv) .(.Macrovision Corporation, Macrovision Europe - Macrovision SECURITY Driver.) - LEGACY_SECDRV
~ Legacy: 86 Scanned in 00mn 00s
---\\ Associations Shell Spawning (O67)
O67 - Shell Spawning: <.bat> <batfile>[HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.cpl> <cplfile>[HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe =>.Microsoft Corporation
O67 - Shell Spawning: <.cmd> <cmdfile>[HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.com> <comfile>[HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.evt> <evtfile>[HKLM\..\open\Command] (.Microsoft Corporation - Lanceur du composant logiciel enfichable Observateur d’événements.) -- C:\Windows\System32\eventvwr.exe
O67 - Shell Spawning: <.exe> <exefile>[HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.html> <htmlfile>[HKLM\..\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe
O67 - Shell Spawning: <.js> <JSFile>[HKLM\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\Windows\System32\WScript.exe
O67 - Shell Spawning: <.reg> <regfile>[HKLM\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\Windows\regedit.exe
O67 - Shell Spawning: <.scr> <scrfile>[HKLM\..\open\Command] (...) -- "%1" /S
O67 - Shell Spawning: <.html> <ChromeHTML>[HKCU\..\open\Command] (.Not Key.)
~ FASS Keys: 11 Scanned in 00mn 00s
---\\ Menu de démarrage Internet (SMI) (O68)
O68 - StartMenuInternet: <FIREFOX.EXE> <Mozilla Firefox>[HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe
O68 - StartMenuInternet: <Google Chrome> <Google Chrome>[HKLM\..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- C:\Users\christophe\AppData\Local\Google\Chrome\Application\chrome.exe
O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer>[HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe
~ Keys: Scanned in 00mn 00s
---\\ Recherche d'infection sur les navigateurs internet (SBI) (O69)
O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (Bing) -
http://www.bing.com
O69 - SBI: SearchScopes [HKCU] {32AF96C1-817A-4C8F-95BC-CA72E9B08FC8} - (Google) -
http://www.google.com
O69 - SBI: SearchScopes [HKCU] {6A1806CD-94D4-4689-BA73-E35EA1EA9990} - (Bing) -
http://www.bing.com
~ Keys: Scanned in 00mn 00s
---\\ Enumère les service demarrés par Svchost (SSS) (O83)
O83 - Search Svchost Services: AeLookupSvc (AeLookupSvc) . (.Microsoft Corporation - Service Expérience d’application.) -- C:\Windows\System32\aelupsvc.dll [62464]
O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Service de propagation de certificats de cartes à puce Microsoft.) -- C:\Windows\System32\certprop.dll [67584]
O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Service de propagation de certificats de cartes à puce Microsoft.) -- C:\Windows\System32\certprop.dll [67584]
O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - DLL du service Serveur.) -- C:\Windows\System32\srvsvc.dll [168960]
O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Client de stratégie de groupe.) -- C:\Windows\System32\gpsvc.dll [593408]
O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - Extension IKE.) -- C:\Windows\System32\ikeext.dll [679424]
O83 - Search Svchost Services: AudioSrv (AudioSrv) . (.Microsoft Corporation - Service Audio Windows.) -- C:\Windows\System32\Audiosrv.dll [475136]
O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Gestionnaire de numérotation automatique d’accès distant.) -- C:\Windows\System32\rasauto.dll [90624]
O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Gestionnaire de connexions d’accès distant.) -- C:\Windows\System32\rasmans.dll [286208]
O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Gestionnaire d’interface dynamique.) -- C:\Windows\System32\mprdim.dll [75264]
O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - Service de notification d’événements système (SENS).) -- C:\Windows\System32\sens.dll [49664]
O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Composants de l’application d’assistance à Microsoft NAT.) -- C:\Windows\System32\ipnathlp.dll [300544]
O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Serveur de téléphonie Microsoft® Windows(TM).) -- C:\Windows\System32\tapisrv.dll [242176]
O83 - Search Svchost Services: TermService (TermService) . (.Microsoft Corporation - Gestionnaire des connexions distantes du serveur hôte de session Burea.) -- C:\Windows\System32\termsrv.dll [523776]
O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Agent de mise à jour automatique Windows Update.) -- C:\Windows\System32\wuaueng.dll [1973728]
O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Service de transfert intelligent en arrière-plan.) -- C:\Windows\System32\qmgr.dll [585728]
O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Dll des services Windows Shell.) -- C:\Windows\System32\shsvcs.dll [328192]
O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Service offrant une connectivité IPv6 sur un réseau IPv4..) -- C:\Windows\System32\iphlpsvc.dll [499712]
O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - DLL de service d’ouverture de session secondaire.) -- C:\Windows\system32\seclogon.dll [21504]
O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Service Informations d’application.) -- C:\Windows\System32\appinfo.dll [47104]
O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - Service de découverte iSCSI.) -- C:\Windows\System32\iscsiexe.dll [114688]
O83 - Search Svchost Services: MMCSS (MMCSS) . (.Microsoft Corporation - Service Planificateur de classes multimédias.) -- C:\Windows\System32\mmcss.dll [49664]
O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - Rapports et solutions aux problèmes.) -- C:\Windows\System32\wercplsupport.dll [61440]
O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Service EAPHost Microsoft.) -- C:\Windows\System32\eapsvc.dll [98304]
O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) -- C:\Windows\System32\profsvc.dll [164864]
O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - Service du Planificateur de tâches.) -- C:\Windows\System32\schedsvc.dll [750592]
O83 - Search Svchost Services: hkmsvc (hkmsvc) . (.Microsoft Corporation - Service Gestion des clés.) -- C:\Windows\System32\kmsvc.dll [71168]
O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - Service Configuration des services Bureau à distance.) -- C:\Windows\System32\sessenv.dll [113664]
O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\Windows\System32\wbem\WMIsvc.dll [168960]
O83 - Search Svchost Services: browser (browser) . (.Microsoft Corporation - DLL du service Explorateur d’ordinateurs.) -- C:\Windows\System32\browser.dll [102912]
O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - DLL du service des thèmes Windows Shell.) -- C:\Windows\System32\themeservice.dll [37376]
O83 - Search Svchost Services: BDESVC (BDESVC) . (.Microsoft Corporation - Service BDE.) -- C:\Windows\System32\bdesvc.dll [76800]
~ Services: 32 Scanned in 00mn 01s
---\\ Enumère les données de la clé NameSpace (MNS) (O92)
O92 - MNS: Flux de photos - {F0D63F85-37EC-4097-B30D-61B4A8917118}
~ MNS: 1 Scanned in 00mn 00s
---\\ Recherche des packages WindowsInstaller (WIS) (O93) (NTFS)
[MD5.EDD21B7C504C7E3F36DE766B31BD3178] [WIS][04/10/2012] (.SweetIM Technologies Ltd. - SweetPacks Toolbar for Internet Explorer 4.0.) -- C:\Windows\Installer\5afaa0.msi [3304960] =>PUP.SweetIM
[MD5.3CD19859CD377AD00B30E4BEE49D374E] [WIS][04/10/2012] (.SweetIM Technologies Ltd. - Sweetpacks Communicator 1.1.) -- C:\Windows\Installer\5afaa6.msi [2997248] =>PUP.SweetIM
~ WIS: 2 Scanned in 00mn 05s
---\\ Recherche de clés de registre CLSID (O101)
[HKCR\CLSID\{c585d593-e7f4-4852-a200-561686ee02e4}] (TheSeaApp) =>Adware.TheSeaApp
~ BCK: 5442 Scanned in 00mn 23s
---\\ Etat général des services non Microsoft (EGS) (SR=Running, SS=Stopped)
SS - | Demand 11/02/2015 267440 | (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
SS - | Auto 19/08/2012 116648 | (gupdate) . (.Google Inc..) - C:\Program Files\Google\Update\GoogleUpdate.exe
SS - | Demand 19/08/2012 116648 | (gupdatem) . (.Google Inc..) - C:\Program Files\Google\Update\GoogleUpdate.exe
SS - | Demand 03/04/2005 69632 | (IDriverT) . (.Macrovision Corporation.) - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
SS - | Demand 12/12/2012 553440 | (iPod Service) . (.Apple Inc..) - C:\Program Files\iPod\bin\iPodService.exe
SS - | Demand 06/11/2014 114288 | (MozillaMaintenance) . (.Mozilla Foundation.) - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
SS - | Demand 16/07/2012 2673064 | (TeamViewer7) . (.TeamViewer GmbH.) - C:\Program Files\TeamViewer\Version7\TeamViewer_Service.exe
SS - | Demand 14/07/2009 20992 | C:\Program Files\Windows Defender\mpsvc.dll (WinDefend) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe
SR - | Auto 19/12/2014 81088 | (AdobeARMservice) . (.Adobe Systems Incorporated.) - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
SR - | Auto 11/08/2012 55184 | (Apple Mobile Device) . (.Apple Inc..) - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
SR - | Auto 11/09/2009 1811704 | (ATService) . (.AuthenTec, Inc..) - C:\Program Files\Fingerprint Sensor\AtService.exe
SR - | Auto 30/08/2011 390504 | (Bonjour Service) . (.Apple Inc..) - C:\Program Files\Bonjour\mDNSResponder.exe
SR - | Auto 10/08/2009 185712 | (cfWiMAXService) . (.TOSHIBA CORPORATION.) - C:\Program Files\TOSHIBA\ConfigFree\CFIWmxSvcs.exe
SR - | Auto 10/03/2009 46448 | (ConfigFree Service) . (.TOSHIBA CORPORATION.) - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
SR - | Auto 30/01/2015 22184 | (MsMpSvc) . (.Microsoft Corporation.) - c:\Program Files\Microsoft Security Client\MsMpEng.exe
SR - | Auto 12/02/2007 65536 | (O2FLASH) . (.O2Micro International.) - C:\Program Files\O2Micro Flash Memory Card Driver\o2flash.exe
SR - | Auto 17/03/2009 144752 | (TOSHIBA Bluetooth Service) . (.TOSHIBA CORPORATION.) - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
SR - | Auto 17/12/2009 497856 | (vpnagent) . (.Cisco Systems, Inc..) - C:\Program Files\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe
SR - | Auto 14/07/2009 20992 | C:\Windows\System32\wuaueng.dll (wuauserv) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe
~ Services: Scanned in 00mn 26s
---\\ Recherche d'infection sur le Master Boot Record (MBR)(O80)
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer,
http://www.gmer.net
Run by christophe at 12/02/2015 13:53:07
device: opened successfully
user: error reading MBR
Disk trace:
error: Read Descripteur non valide
kernel: error reading MBR
~ MBR: 9 Scanned in 00mn 02s
---\\ Recherche d'infection sur le Master Boot Record (MBRCheck)(O80)
Written by ad13,
http://ad13.geekstog
Run by christophe at 12/02/2015 13:53:09
********* Dump file Name *********
C:\PhysicalDisk0_MBR.bin
~ MBR: Scanned in 00mn 04s
---\\ Scan Additionnel (O88)
Database Version : 13008 - (11/02/2015)
Clés trouvées (Keys found) : 2
Valeurs trouvées (Values found) : 0
Dossiers trouvés (Folders found) : 1
Fichiers trouvés (Files found) : 5
[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\The Sea App] =>Adware.TheSeaApp^
[HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110411361110}] =>PUP.CrossRider
C:\Program Files\The Sea App (Internet Explorer) =>Adware.TheSeaApp^
[HKCU\Software\The Sea App] =>Adware.TheSeaApp^
C:\Windows\Installer\5afaa0.msi =>PUP.SweetIM^
C:\Windows\Installer\5afaa6.msi =>PUP.SweetIM^
[HKCR\CLSID\{c585d593-e7f4-4852-a200-561686ee02e4}] (TheSeaApp) =>Adware.TheSeaApp^
C:\Users\christophe\Downloads\cacaoweb.exe =>PUP.CacaoWeb
~ Additionnel Scan: 293900 Items scanned in 00mn 57s
---\\ Informations complémentaires sur les modules
~
http://nicolascoolman.fr/g2-google-chrome-extensions/ =>.Google Chrome, Démarrage,Recherche,Extensions (G0,G1,G2)
~
http://nicolascoolman.fr/r5-internet-ex ... ment-iepm/ =>.Internet Explorer, Proxy Management (R5)
~
http://nicolascoolman.fr/o2-browser-hel ... avigateur/ =>.Browser Helper Objects de navigateur (O2)
~
http://nicolascoolman.fr/o3-internet-explorer-toolbars/ =>.Internet Explorer Toolbars (O3)
~
http://nicolascoolman.fr/o4-application ... -registre/ =>.Applications lancées au démarrage du système (O4)
~
http://nicolascoolman.fr/o51-mountpoint ... -key-mpsk/ =>.Clé de registre Shell MountPoints2 (MPSK) (O51)
~ AMI: 6 Scanned in 00mn 00s
---\\ Récapitulatif des détections trouvées sur votre station
http://nicolascoolman.fr/32592770-adware-theseaapp =>Adware.TheSeaApp
http://nicolascoolman.fr/pup-sweetim =>PUP.SweetIM
http://nicolascoolman.fr/pup-crossrider =>PUP.CrossRider
http://nicolascoolman.fr/pup-cacaoweb =>PUP.CacaoWeb
~ MSI: 4 link(s) detected in 00mn 00s
End of the scan (1316 lines in 11mn 41s)(0.10)
J'attends les consignes
Merci d'avance
Christophe