bonsoir
voici le 2eme rapport
Rapport de ZHPDiag v2013.3.30.114 par Nicolas Coolman, Update du 30/03/2013
Run by lara at 01/04/2013 20:42:22
State : Nouvelle version disponible
High Elevated Privileges : OK
UAC : Activate by user
---\\ Web Browser
MSIE: Internet Explorer v10.0.9200.16521
GCIE: Google Chrome v26.0.1410.43 (Defaut)
---\\ Windows Product Information
~ Langage: Français
Windows 7 Home Premium Edition, 32-bit Service Pack 1 (Build 7601)
Windows Server License Manager Script : OK
~ Windows(R) 7, OEM_COA_NSLP channel
Windows ID Activation : OK
~ Windows Partial Key : 2FVV8
Windows License : OK
~ Windows Remaining Initializations Number : 5
Software Protection Service (Protection logicielle) : OK
Windows Automatic Updates : OK
Windows Activation Technologies : OK
---\\ System Information
~ Processor: x86 Family 6 Model 23 Stepping 10, GenuineIntel
~ Operating System: 32 Bits
Boot mode: Normal (Normal boot)
Total RAM: 3066 MB (57% free)
System Restore: Activé (Enable)
System drive C: has 81 GB (54%) free of 149 GB
---\\ Logged in mode
~ Computer Name: PC-DE-LARA
~ User Name: lara
~ All Users Names: lara, HomeGroupUser$, Administrateur,
~ Unselected Option: None
Logged in as Administrator
---\\ Environnement Variables
~ System Unit : C:\
~ %AppData% : C:\Users\lara\AppData\Roaming\
~ %Desktop% : C:\Users\lara\Desktop\
~ %Favorites% : C:\Users\lara\Favorites\
~ %LocalAppData% : C:\Users\lara\AppData\Local\
~ %StartMenu% : C:\Users\lara\AppData\Roaming\Microsoft\Windows\Start Menu\
~ %Windir% : C:\Windows\
~ %System% : C:\Windows\System32\
---\\ DOS/Devices
C:\ Hard drive, Flash drive, Thumb drive (Free 81 Go of 149 Go)
D:\ Floppy drive, Flash card reader, USB Key (Free 12 Go of 15 Go)
E:\ Hard drive, Flash drive, Thumb drive (Free 130 Go of 148 Go)
F:\ CD-ROM drive (Not Inserted)
G:\ CD-ROM drive (Not Inserted)
---\\ Security Center Tools Informations
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiSpywareOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallOverride: OK
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System] DisableTaskMgr: OK
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System] DisableRegistryTools: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK
[HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] Load: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install] LastSuccessTime : OK
~ Security Center: Scanned in 00mn 00s
---\\ Recherche particulière de fichiers génériques
[MD5.8B88EBBB05A0E56B7DCC708498C02B3E] - (.Microsoft Corporation - Explorateur Windows.) (.25/02/2011 - 06:30:54.) -- C:\Windows\Explorer.exe [2616320]
[MD5.B5C5DCAD3899512020D135600129D665] - (.Microsoft Corporation - Application de démarrage de Windows.) (.14/07/2009 - 02:14:45.) -- C:\Windows\System32\Wininit.exe [96256]
[MD5.BA15504FA59A8DC304F1CBAEBA6252A1] - (.Microsoft Corporation - Extensions Internet pour Win32.) (.30/03/2013 - 02:58:31.) -- C:\Windows\System32\wininet.dll [1766912]
[MD5.6D13E1406F50C66E2A95D97F22C47560] - (.Microsoft Corporation - Application d’ouverture de session Windows.) (.20/11/2010 - 13:17:54.) -- C:\Windows\System32\Winlogon.exe [286720]
[MD5.E3AE23569749DE12D45BA3B489A036AE] - (.Microsoft Corporation - Bibliothèque de licences.) (.20/11/2010 - 13:21:24.) -- C:\Windows\System32\sppcomapi.dll [193536]
[MD5.9EBBBA55060F786F0FCAA3893BFA2806] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) (.25/04/2011 - 03:18:03.) -- C:\Windows\system32\Drivers\AFD.sys [338944]
[MD5.338C86357871C167A96AB976519BF59E] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.14/07/2009 - 02:26:15.) -- C:\Windows\system32\Drivers\atapi.sys [21584]
[MD5.77EA11B065E0A8AB902D78145CA51E10] - (.Microsoft Corporation - CD-ROM File System Driver.) (.14/07/2009 - 00:11:15.) -- C:\Windows\system32\Drivers\Cdfs.sys [70656]
[MD5.BE167ED0FDB9C1FA1133953C18D5A6C9] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.20/11/2010 - 09:38:10.) -- C:\Windows\system32\Drivers\Cdrom.sys [108544]
[MD5.F024449C97EC1E464AAFFDA18593DB88] - (.Microsoft Corporation - DFS Namespace Client Driver.) (.20/11/2010 - 09:42:32.) -- C:\Windows\system32\Drivers\DfsC.sys [78336]
[MD5.9036377B8A6C15DC2EEC53E489D159B5] - (.Microsoft Corporation - High Definition Audio Bus Driver.) (.20/11/2010 - 10:59:29.) -- C:\Windows\system32\Drivers\HDAudBus.sys [108544]
[MD5.F151F0BDC47F4A28B1B20A0818EA36D6] - (.Microsoft Corporation - Pilote de port i8042.) (.14/07/2009 - 00:11:24.) -- C:\Windows\system32\Drivers\i8042prt.sys [80896]
[MD5.A5FA468D67ABCDAA36264E463A7BB0CD] - (.Microsoft Corporation - IP Network Address Translator.) (.14/07/2009 - 00:54:29.) -- C:\Windows\system32\Drivers\IpNat.sys [101888]
[MD5.5D16C921E3671636C0EBA3BBAAC5FD25] - (.Microsoft Corporation - Windows NT SMB Minirdr.) (.27/04/2011 - 03:17:22.) -- C:\Windows\system32\Drivers\MRxSmb.sys [123904]
[MD5.280122DDCF04B378EDD1AD54D71C1E54] - (.Microsoft Corporation - MBT Transport driver.) (.20/11/2010 - 09:39:44.) -- C:\Windows\system32\Drivers\netBT.sys [187904]
[MD5.0D87503986BB3DFED58E343FE39DDE13] - (.Microsoft Corporation - Pilote du système de fichiers NT.) (.31/08/2012 - 18:18:09.) -- C:\Windows\system32\Drivers\ntfs.sys [1211760]
[MD5.2EA877ED5DD9713C5AC74E8EA7348D14] - (.Microsoft Corporation - Pilote de port parallèle.) (.14/07/2009 - 00:45:35.) -- C:\Windows\system32\Drivers\Parport.sys [79360]
[MD5.D9F91EAFEC2815365CBE6D167E4E332A] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.14/07/2009 - 00:54:34.) -- C:\Windows\system32\Drivers\Rasl2tp.sys [78848]
[MD5.3E21C083B8A01CB70BA1F09303010FCE] - (.Microsoft Corporation - SMB Transport driver.) (.14/07/2009 - 00:53:41.) -- C:\Windows\system32\Drivers\smb.sys [71168]
[MD5.B459575348C20E8121D6039DA063C704] - (.Microsoft Corporation - TDI Translation Driver.) (.20/11/2010 - 09:39:17.) -- C:\Windows\system32\Drivers\tdx.sys [74752]
[MD5.F497F67932C6FA693D7DE2780631CFE7] - (.Microsoft Corporation - Pilote de cliché instantané du volume.) (.20/11/2010 - 13:30:16.) -- C:\Windows\system32\Drivers\volsnap.sys [245632]
~ Generic Processes: Scanned in 00mn 00s
---\\ Etat des fichiers cachés (Caché/Total)
~ Mes images (My Pictures) : 2/725
~ Mes musiques (My Musics) : 15/1039
~ Mes Videos (My Videos) : 1/5
~ Mes Favoris (My Favorites) : 1/47
~ Mes Documents (My Documents) : 1/288
~ Mon Bureau (My Desktop) : 1/36
~ Menu demarrer (Programs) : 1/29
~ Hidden Files: Scanned in 00mn 01s
---\\ Processus lancés
[MD5.0066227730319A9702D485BEB32EE4D9] - (.Bitdefender - Bitdefender Antivirus Free Edition.) -- C:\Program Files\Bitdefender\Antivirus Free Edition\gziface.exe [235728] [PID.3492]
[MD5.7853D2AB445C10F97610B2B05FA4CF0A] - (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe [512360] [PID.3696]
[MD5.51138BEEA3E2C21EC44D0932C71762A8] - (...) -- ystem32\rundll32.exe [0] [PID.2756]
[MD5.A4A14FADDE82F30A4BDAFE5C65CB8ABC] - (.Alps Electric Co., Ltd. - Alps Pointing-device Driver.) -- C:\Program Files\Apoint2K\Apoint.exe [184320] [PID.3664]
[MD5.979AA9F9DED2EEC68ED57F3706CEC5F0] - (.Realtek Semiconductor - Gestionnaire audio HD Realtek.) -- C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [7719456] [PID.3796]
[MD5.B77F5392B4E8899D4EF1E2326EEB33EA] - (.TOSHIBA Corporation - TOSHIBA Flash Cards.) -- C:\Program Files\Toshiba\FlashCards\TCrdMain.exe [727608] [PID.3988]
[MD5.FCA31AECDA34437178A58A4B4EF2EBDC] - (.TOSHIBA Corporation. - HDMICtrlMan.exe.) -- C:\Program Files\Toshiba\HDMICtrlMan\HDMICtrlMan.exe [716800] [PID.884]
[MD5.99E45FCB96AC7A8F437C9EF7F4BC36E8] - (.Alps Electric Co., Ltd. - ApMsgFwd.) -- C:\Program Files\Apoint2K\ApMsgFwd.exe [50472] [PID.3892]
[MD5.AFD400AEBCAB252C99E60991FF00D9D2] - (.Pas de propriétaire - KeNotify MFC Application.) -- C:\Program Files\Toshiba\Utilities\KeNotify.exe [34352] [PID.1508]
[MD5.D140C5FDFD1924E3CC173CF8376B5E22] - (.TOSHIBA Corporation - SmoothView.) -- C:\Program Files\Toshiba\SmoothView\SmoothView.exe [509816] [PID.3956]
[MD5.E1FAAF7915BC07352CCF1DFF37058414] - (.TOSHIBA - TOSHIBA Online Product Information.) -- C:\Program Files\Toshiba\Toshiba Online Product Information\TOPI.exe [581632] [PID.3672]
[MD5.3DC23E3E5E78FF5A428E405D16D8ED82] - (.TOSHIBA Corporation - TOSHIBA Power Saver.) -- C:\Program Files\Toshiba\Power Saver\TPwrMain.exe [431456] [PID.3368]
[MD5.FB0C8699B87F7140BB6201BE7B4B6778] - (.Pas de propriétaire - CameraMonitor Application.) -- C:\Windows\vsnpstd3.exe [827392] [PID.1228]
[MD5.FB642F641AB3C7A973CCB9B07350486D] - (.Chicony - traybar.) -- C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe [417792] [PID.3580]
[MD5.359937EFD1763DF9F8B8D166BD4CC022] - (.Alps Electric Co., Ltd. - Alps Pointing-device Driver for Windows NT/.) -- C:\Program Files\Apoint2K\Apntex.exe [49152] [PID.3592]
[MD5.2E35CE78141C99D2E0E88DCCDE89FB99] - (.Pas de propriétaire - Printer Device Monitor.) -- C:\Program Files\Lexmark 2600 Series\lxdnmon.exe [660136] [PID.1252]
[MD5.50131BFA7FD0C6029E611DBA35AA7E4D] - (.Lexmark International Inc. - Lexmark Fast Pics Application.) -- C:\Program Files\Lexmark 2600 Series\ezprint.exe [107176] [PID.2416]
[MD5.12916E0642E92561C98B18A2A2D01B14] - (.Sun Microsystems, Inc. - Java(TM) Update Scheduler.) -- C:\Program Files\Common Files\Java\Java Update\jusched.exe [252848] [PID.3116]
[MD5.799D3B219B84CA5AB76CB13619389A73] - (.Pas de propriétaire - HTC UPCT Loader.) -- C:\Program Files\HTC\HTC Sync 3.0\htcUPCTLoader.exe [651264] [PID.3856]
[MD5.8513BF8D7C4C1F1A0365E9FBFDE458D5] - (.TOSHIBA - CD/DVD Drive Acoustic Silencer.) -- C:\Program Files\Toshiba\TOSCDSPD\TOSCDSPD.exe [430080] [PID.3560]
[MD5.F34E7705751BB413283434697BF8E55D] - (.DT Soft Ltd - DAEMON Tools Lite.) -- C:\Program Files\DAEMON Tools Lite\DTLite.exe [357696] [PID.3908]
[MD5.805DA17E1C417223E77474A686739306] - (.TOSHIBA Corporation. - SoundChanger.exe.) -- C:\Program Files\Toshiba\HDMICtrlMan\HCMSoundChanger.exe [667648] [PID.3656]
[MD5.B0BF698030DB6561393AE753C6D3F936] - (.Google Inc. - Google Chrome.) -- C:\Users\lara\AppData\Local\Google\Chrome\Application\chrome.exe [1312720] [PID.1996]
[MD5.0051240D50ABE7922727B1E3385DF512] - (.Nicolas Coolman - ZHPDiag.) -- C:\Program Files\ZHPDiag\ZHPDiag.exe [6264832] [PID.2692]
~ Processes Running: Scanned in 00mn 00s
---\\ Google Chrome, Démarrage,Recherche,Extensions (G0,G1,G2)
C:\Users\lara\AppData\Local\Google\Chrome\User Data\Default\Preferences
G1 - GCS: Preference [User Data\Default]
http://www.bing.com
~ Google Browser: Scanned in 00mn 00s
---\\ Mozilla Firefox, Plugins,Demarrage,Recherche,Extensions (P2,M0,M1,M2,M3)
P2 - FPN: [HKLM] [@google.com/npPicasa3,version=3.0.0] - (.Google, Inc. - Picasa plugin.) -- C:\Program Files\Google\Picasa3\npPicasa3.dll
P2 - FPN: [HKLM] [@java.com/DTPlugin,version=10.7.2] - (.Oracle Corporation - NPRuntime Script Plug-in Library for Java(TM) Deploy.) -- C:\Windows\system32\npDeployJava1.dll
P2 - FPN: [HKLM] [@java.com/JavaPlugin,version=10.7.2] - (.Oracle Corporation - Next Generation Java Plug-in 10.7.2 for Mozilla browsers.) -- C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll
P2 - FPN: [HKLM] [@Microsoft.com/NpCtrl,version=1.0] - (. Microsoft Corporation - 5.1.20125.0.) -- C:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll
P2 - FPN: [HKLM] [@microsoft.com/OfficeLive,version=1.5] - (.Microsoft Corp. - Office Live Update v1.5.) -- C:\Program Files\Microsoft\Office Live\npOLW.dll
P2 - FPN: [HKLM] [@microsoft.com/WLPG,version=15.4.3502.0922] - (.Microsoft Corporation - NPWLPG.) -- C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
P2 - FPN: [HKLM] [@microsoft.com/WLPG,version=15.4.3508.1109] - (.Microsoft Corporation - NPWLPG.) -- C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
P2 - FPN: [HKLM] [@microsoft.com/WLPG,version=15.4.3538.0513] - (.Microsoft Corporation - NPWLPG.) -- C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
P2 - FPN: [HKLM] [@microsoft.com/WPF,version=3.5] - (.Microsoft Corporation - Windows Presentation Foundation (WPF) plug-in for Mozilla browsers.) -- C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
P2 - FPN: [HKLM] [@tools.google.com/Google Update;version=3] - (.Google Inc. - Google Update.) -- C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll
P2 - FPN: [HKLM] [@tools.google.com/Google Update;version=9] - (.Google Inc. - Google Update.) -- C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll
P2 - FPN: [HKCU] [@tools.google.com/Google Update;version=3] - (.Google Inc. - Google Update.) -- C:\Users\lara\AppData\Local\Google\Update\1.3.21.135\npGoogleUpdate3.dll
P2 - FPN: [HKCU] [@tools.google.com/Google Update;version=9] - (.Google Inc. - Google Update.) -- C:\Users\lara\AppData\Local\Google\Update\1.3.21.135\npGoogleUpdate3.dll
~ Firefox Browser: Scanned in 00mn 00s
---\\ Internet Explorer, Démarrage,Recherche,URLSearchHook, Phishing (R0,R1,R3,R4)
R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.fr
R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.google.com
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = aboutnoadd-ons
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = aboutsecurityrisk
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
http://www.google.com
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch =
http://www.google.com
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
http://www.google.com
R3 - URLSearchHook: Microsoft Url Search Hook - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} . (.Google Inc. - Google Update.) (No version) -- (.not file.)
R4 - HKLM\SOFTWARE\Microsoft\Internet Explorer\PhishingFilter,EnabledV8 = 1
~ IE Browser: Scanned in 00mn 00s
---\\ Internet Explorer, Proxy Management (R5)
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll
~ Proxy management: Scanned in 00mn 00s
---\\ Analyse des lignes F0, F1, F2, F3 - IniFiles, Autoloading programs
F2 - REG:system.ini: USERINIT=C:\Windows\system32\userinit.exe,
F2 - REG:system.ini: Shell=C:\Windows\explorer.exe
F2 - REG:system.ini: VMApplet=C:\Windows\System32\SystemPropertiesPerformance.exe
~ Keys: Scanned in 00mn 00s
---\\ Redirection du fichier Hosts (O1)
~ Le fichier hosts est sain (The hosts file is clean).
~ Hosts File: Scanned in 00mn 00s
~ Nombre de lignes (Lines number): 20
---\\ Browser Helper Objects de navigateur (O2)
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} . (.Adobe Systems Incorporated - Adobe PDF Helper for Internet Explorer.) -- C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} . (.Oracle Corporation - Java(TM) Platform SE binary.) -- C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} . (.Microsoft Corp. - Microsoft® Windows Live ID Login Helper.) -- C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} . (.Google Inc. - Google Toolbar.) -- C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} . (.Google Inc. - GoogleToolbarNotifier.) -- C:\Program Files\Google\GoogleToolbarNotifier\5.7.8313.1002\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} . (.Oracle Corporation - Java(TM) Platform SE binary.) -- C:\Program Files\Java\jre7\bin\jp2ssv.dll
~ BHO: Scanned in 00mn 00s
---\\ Internet Explorer Toolbars (O3)
O3 - Toolbar: (no name) - [HKLM]{0BF43445-2F28-4351-9252-17FE6E806AA0} Clé orpheline
O3 - Toolbar: (no name) - [HKLM]{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} Clé orpheline
O3 - Toolbar: Google Toolbar - [HKLM]{2318C2B1-4965-11d4-9B18-009027A5CD4F} . (.Google Inc. - Google Toolbar.) -- C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
~ Toolbar: Scanned in 00mn 00s
---\\ Applications démarrées par registre par dossier (O4)
O4 - HKLM\..\Run: [Apoint] . (.Alps Electric Co., Ltd. - Alps Pointing-device Driver.) -- C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [RtHDVCpl] . (.Realtek Semiconductor - Gestionnaire audio HD Realtek.) -- C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
O4 - HKLM\..\Run: [00TCrdMain] . (.TOSHIBA Corporation - TOSHIBA Flash Cards.) -- C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] . (.Adobe Systems Incorporated - Adobe Acrobat SpeedLauncher.) -- C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
O4 - HKLM\..\Run: [Google EULA Launcher] . (...) -- c:\Program Files\Google\Google EULA\GoogleEULALauncher.exe
O4 - HKLM\..\Run: [HDMICtrlMan] . (.TOSHIBA Corporation. - HDMICtrlMan.exe.) -- C:\Program Files\TOSHIBA\HDMICtrlMan\HDMICtrlMan.exe
O4 - HKLM\..\Run: [HSON] . (.TOSHIBA Corporation - HotStartOn.) -- C:\Program Files\TOSHIBA\TBS\HSON.exe
O4 - HKLM\..\Run: [HWSetup] . (.TOSHIBA Electronics, Inc. - HWSetup.) -- C:\Program Files\TOSHIBA\Utilities\HWSetup.exe
O4 - HKLM\..\Run: [KeNotify] . (.Pas de propriétaire - KeNotify MFC Application.) -- C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
O4 - HKLM\..\Run: [SmoothView] . (.TOSHIBA Corporation - SmoothView.) -- C:\Program Files\Toshiba\SmoothView\SmoothView.exe
O4 - HKLM\..\Run: [SVPWUTIL] . (.TOSHIBA - SVPWUTIL Application.) -- C:\Program Files\TOSHIBA\Utilities\SVPWUTIL.exe
O4 - HKLM\..\Run: [topi] . (.TOSHIBA - TOSHIBA Online Product Information.) -- C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe
O4 - HKLM\..\Run: [TPwrMain] . (.TOSHIBA Corporation - TOSHIBA Power Saver.) -- C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
O4 - HKLM\..\Run: [snpstd3] . (.Pas de propriétaire - CameraMonitor Application.) -- C:\Windows\vsnpstd3.exe
O4 - HKLM\..\Run: [ATICustomerCare] . (.Advanced Micro Devices, Inc. - ATI Customer Care.) -- C:\Program Files\ATI\ATICustomerCare\ATICustomerCare.exe
O4 - HKLM\..\Run: [Camera Assistant Software] . (.Chicony - traybar.) -- C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe
O4 - HKLM\..\Run: [lxdnmon.exe] . (.Pas de propriétaire - Printer Device Monitor.) -- C:\Program Files\Lexmark 2600 Series\lxdnmon.exe
O4 - HKLM\..\Run: [EzPrint] . (.Lexmark International Inc. - Lexmark Fast Pics Application.) -- C:\Program Files\Lexmark 2600 Series\ezprint.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] . (.Sun Microsystems, Inc. - Java(TM) Update Scheduler.) -- C:\Program Files\Common Files\Java\Java Update\jusched.exe
O4 - HKLM\..\Run: [HTC Sync Loader] . (.Pas de propriétaire - HTC UPCT Loader.) -- C:\Program Files\HTC\HTC Sync 3.0\htcUPCTLoader.exe
O4 - HKCU\..\Run: [TOSCDSPD] . (.TOSHIBA - CD/DVD Drive Acoustic Silencer.) -- C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
O4 - HKCU\..\Run: [Google Update] . (.Google Inc. - Programme d'installation de Google.) -- C:\Users\lara\AppData\Local\Google\Update\GoogleUpdate.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] . (.DT Soft Ltd - DAEMON Tools Lite.) -- C:\Program Files\DAEMON Tools Lite\DTLite.exe
O4 - HKCU\..\Run: [swg] . (.Google Inc. - GoogleToolbarNotifier.) -- C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files\Windows Sidebar\Sidebar.exe
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files\Windows Sidebar\Sidebar.exe
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe
O4 - HKUS\S-1-5-21-3074221200-4178445646-789309326-1000\..\Run: [TOSCDSPD] . (.TOSHIBA - CD/DVD Drive Acoustic Silencer.) -- C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
O4 - HKUS\S-1-5-21-3074221200-4178445646-789309326-1000\..\Run: [Google Update] . (.Google Inc. - Programme d'installation de Google.) -- C:\Users\lara\AppData\Local\Google\Update\GoogleUpdate.exe
O4 - HKUS\S-1-5-21-3074221200-4178445646-789309326-1000\..\Run: [DAEMON Tools Lite] . (.DT Soft Ltd - DAEMON Tools Lite.) -- C:\Program Files\DAEMON Tools Lite\DTLite.exe
O4 - HKUS\S-1-5-21-3074221200-4178445646-789309326-1000\..\Run: [swg] . (.Google Inc. - GoogleToolbarNotifier.) -- C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
~ Application: Scanned in 00mn 00s
---\\ Autres liens utilisateurs (O4)
O4 - GS\TaskBar: Google Chrome.lnk . (.Google Inc. - Google Chrome.) -- C:\Users\lara\AppData\Local\Google\Chrome\Application\chrome.exe
O4 - GS\TaskBar: Windows Explorer.lnk . (.Microsoft Corporation - Explorateur Windows.) -- C:\Windows\explorer.exe
O4 - GS\TaskBar: Windows Media Player.lnk . (.Microsoft Corporation - Lecteur Windows Media.) -- C:\Program Files\Windows Media Player\wmplayer.exe
O4 - GS\Programs: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe
O4 - GS\QuickLaunch: Launch Internet Explorer Browser.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe
O4 - GS\Accessories: Internet Explorer (No Add-ons).lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe
O4 - GS\Accessories: Private Character Editor.lnk . (.Microsoft Corporation - Éditeur de caractères privés.) -- C:\Windows\system32\eudcedit.exe
O4 - GS\SendTo: Fax Recipient.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) -- C:\Windows\system32\WFS.exe
O4 - GS\SendTo: Skype.lnk . (.Skype Technologies S.A. - Skype.) -- C:\Program Files\Skype\Phone\Skype.exe
O4 - GS\Desktop: Fichiers d’installation Norton.lnk . (...) -- C:\Users\Public\Downloads\Norton\{NAV19113-SHPD-FSD21017}
O4 - GS\Desktop: Google Chrome.lnk . (.Google Inc. - Google Chrome.) -- C:\Users\lara\AppData\Local\Google\Chrome\Application\chrome.exe
O4 - GS\Desktop: photos - Raccourci.lnk . (...) -- E:\photos
O4 - GS\Desktop: Skype.lnk . (.Skype Technologies S.A. - Skype.) -- C:\Program Files\Skype\Phone\Skype.exe
~ Global Startup: Scanned in 00mn 00s
---\\ Invisibilité de l'icône d'options IE dans le panneau de Configuration (O5)
~ IE Control Panel: 1 Legitimates Scanned in 00mn 00s
---\\ Boutons situés sur la barre d'outils principale d'Internet Explorer (O9)
O9 - Extra button: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -- Clé orpheline
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} . (.Microsoft Corporation - Windows Live Writer Blog This Extension.) -- C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} . (.Microsoft Corporation - Microsoft Office OneNote Internet Explorer Add-in.) -- C:\Program Files\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: eBay - Achetez, Vendez - {76577871-04EC-495E-A12B-91F7C3600AFA} . (...) -- c:\toshiba\Webshops\ebay.ico
O9 - Extra button: Amazon.fr - {8A918C1D-E123-4E36-B562-5C1519E434CE} . (...) -- c:\toshiba\Webshops\amazon.ico
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} . (...) -- C:\Program Files\Microsoft Office\Office12\REFBARH.ICO
~ IE Extra Buttons: Scanned in 00mn 00s
---\\ Winsock hijacker (Layered Service Provider) (O10)
~ Winsock: 9 Legitimates Scanned in 00mn 00s
---\\ Modification Domaine/Adresses DNS (O17)
O17 - HKLM\System\CCS\Services\Tcpip\..\{DED64794-ED60-43EF-A971-18E7C7E1440D}: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\..\{DED64794-ED60-43EF-A971-18E7C7E1440D}: DhcpDomain = lan
O17 - HKLM\System\CCS\Services\Tcpip\..\{F4BF8A9C-9E4C-4CF6-84F3-7E91B678B4F4}: DhcpDomain = lan
O17 - HKLM\System\CS1\Services\Tcpip\..\{DED64794-ED60-43EF-A971-18E7C7E1440D}: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CS1\Services\Tcpip\..\{DED64794-ED60-43EF-A971-18E7C7E1440D}: DhcpDomain = lan
O17 - HKLM\System\CS1\Services\Tcpip\..\{F4BF8A9C-9E4C-4CF6-84F3-7E91B678B4F4}: DhcpDomain = lan
O17 - HKLM\System\CS2\Services\Tcpip\..\{DED64794-ED60-43EF-A971-18E7C7E1440D}: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CS2\Services\Tcpip\..\{DED64794-ED60-43EF-A971-18E7C7E1440D}: DhcpDomain = lan
O17 - HKLM\System\CS2\Services\Tcpip\..\{F4BF8A9C-9E4C-4CF6-84F3-7E91B678B4F4}: DhcpDomain = lan
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
~ Domain: Scanned in 00mn 00s
---\\ Protocole additionnel (O18)
O18 - Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} . (.Microsoft Corporation - Windows Live Album Download Protocol Handle.) -- C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} . (.Microsoft Corporation - Microsoft Office XML MIME Filter.) -- C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.dll
~ Protocole Additionnel: Scanned in 00mn 00s
---\\ Clé de Registre autorun ShellServiceObjectDelayLoad (SSO/SSODL) (O21)
~ SSODL: 1 Legitimates Scanned in 00mn 00s
---\\ Liste des services NT non Microsoft et non désactivés (O23)
O23 - Service: Bitdefender Antivirus Free Edition (gzserv) . (.Bitdefender - Bitdefender Antivirus Free Edition.) - C:\Program Files\Bitdefender\Antivirus Free Edition\gzserv.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) . (.Ulead Systems, Inc. - ULCDRSvr.) - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
~ Services: 16 Legitimates Scanned in 00mn 07s
---\\ Enumération Active Desktop MHTML Editor (O24)
~ Desktop Component: 1 Legitimates Scanned in 00mn 00s
---\\ BootExecute (O34)
~ BEX: 1 Legitimates Scanned in 00mn 00s
---\\ Tâches planifiées en automatique (O39)
[MD5.00000000000000000000000000000000] [APT] [EPUpdater] (...) -- C:\Users\lara\AppData\Roaming\BABSOL~1\Shared\BabMaint.exe (.not file.) [0]
[MD5.50131BFA7FD0C6029E611DBA35AA7E4D] [APT] [Installation App Launcher] (.Lexmark International Inc..) -- C:\Program Files\Lexmark 2600 Series\ezprint.exe [107176]
[MD5.00000000000000000000000000000000] [APT] [RunAsStdUser] (...) -- C:\Program Files\Desk 365\desk365.exe (.not file.) [0]
[MD5.F920FBB43C1CDB905044C91B9A3FD516] [APT] [{00199D78-A132-4BE3-9F2D-FBEC7C95E7B4}] (.Skype Technologies S.A..) -- C:\Program Files\Skype\Phone\Skype.exe [18643560]
[MD5.00000000000000000000000000000000] [APT] [{23D8F00A-8209-495C-A3DC-2092B97D3480}] (...) -- F:\LGInstaller.exe (.not file.) [0]
[MD5.7B764BDD14F87149E69B5F5B8FD80837] [APT] [{30634782-3F9D-4112-A1F3-77636227DFDC}] (.Internet Scrabble Club.) -- C:\Program Files\WordBiz\WordBiz.exe [12824064]
[MD5.00000000000000000000000000000000] [APT] [{4975043A-3073-45C7-8059-AAF17D0FDDD9}] (...) -- C:\Program Files\NETGEAR\WN111v2\WN111v2.exe (.not file.) [0]
[MD5.432E4B9B1F6C42D6305F684E0BE022E4] [APT] [{59AA1C9E-7234-445B-85BE-F583B1862262}] (...) -- C:\Program Files\Lexmark 2600 Series\Install\x86\Uninst.exe [3523240]
[MD5.00000000000000000000000000000000] [APT] [{9EB01ED6-7E7C-4589-B961-3471CA31C4BA}] (...) -- C:\Program Files\Norton Internet Security\Engine\17.1.0.19\uiStub.exe (.not file.) [0]
[MD5.7B764BDD14F87149E69B5F5B8FD80837] [APT] [{FE83934C-0139-4563-87D6-3B810484AC4A}] (.Internet Scrabble Club.) -- C:\Program Files\WordBiz\WordBiz.exe [12824064]
[MD5.00000000000000000000000000000000] [APT] [Norton Error Analyzer 18.6.0.29] (...) -- C:\Program Files\Norton AntiVirus\Engine\18.6.0.29\SymErr.exe (.not file.) [0]
[MD5.00000000000000000000000000000000] [APT] [Norton Error Processor 18.6.0.29] (...) -- C:\Program Files\Norton AntiVirus\Engine\18.6.0.29\SymErr.exe (.not file.) [0]
~ Scheduled Task: 24 Legitimates Scanned in 00mn 02s
---\\ Composants installés (ActiveSetup Installed Components) (O40)
~ Active Setup: 11 Legitimates Scanned in 00mn 00s
---\\ Pilotes lancés au démarrage (O41)
O41 - Driver: (bdfwfpf) . (.BitDefender LLC - BitDefender Firewall WFP Filter Driver.) - C:\Program Files\Bitdefender\Antivirus Free Edition\bdfwfpf.sys
O41 - Driver: (bdselfpr) . (.BitDefender LLC - BitDefender Self Protection Driver.) - C:\Program Files\Bitdefender\Antivirus Free Edition\bdselfpr.sys
O41 - Driver: (ccHP) . (.Symantec Corporation - Common Client Hash Provider Driver.) - C:\Windows\system32\drivers\NIS\1101000.013\ccHPx86.sys
O41 - Driver: (gzflt) . (.BitDefender LLC - BitDefender Gonzales FileSystem Driver.) - C:\Windows\System32\DRIVERS\gzflt.sys
O41 - Driver: C:\Windows\System32\drivers\netbt.sys (NetBT) . (.Microsoft Corporation - MBT Transport driver.) - C:\Windows\System32\DRIVERS\netbt.sys
~ Drivers: 72 Legitimates Scanned in 00mn 00s
---\\ Logiciels installés (O42)
O42 - Logiciel: Adobe Flash Player 10 ActiveX - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player ActiveX
O42 - Logiciel: Adobe Reader 8.1.2 - Français - (.Adobe Systems Incorporated.) [HKLM] -- {AC76BA86-7AD7-1036-7B44-A81200000003}
O42 - Logiciel: Adobe Reader 8.1.2 Security Update 1 (KB403742) - (...) [HKLM] -- {AC76BA86-7AD7-1036-7B44-A81200000003}_Adobe Reader 8.1.2 - Français
O42 - Logiciel: Java 7 Update 7 - (.Oracle.) [HKLM] -- {26A24AE4-039D-4CA4-87B4-2F83217007FF}
O42 - Logiciel: Java(TM) 6 Update 6 - (.Sun Microsystems, Inc..) [HKLM] -- {3248F0A8-6813-11D6-A77B-00B0D0160060}
O42 - Logiciel: Rosetta Stone Version 3 - (.Rosetta Stone Ltd..) [HKLM] -- {99011A6E-5200-11DE-BDB8-7ACD56D89593}
O42 - Logiciel: TRDCReminder - (.TOSHIBA.) [HKLM] -- InstallShield_{773970F1-5EBA-4474-ADEE-1EA3B0A59492}
O42 - Logiciel: Traitement de texte Atlantis - (...) [HKLM] -- Atlantis Word Processor
O42 - Logiciel: WordBiz 1.8.6 - (...) [HKLM] -- WordBiz_0
~ Logic: 103 Legitimates Scanned in 00mn 00s
---\\ HKCU HKLM Software Keys
[HKCU\Software\EBIo]
[HKCU\Software\PerformerSoft LLC]
[HKCU\Software\Rising Sun Solutions, Inc.]
[HKLM\Software\AVC3]
[HKLM\Software\afplanet]
[HKLM\Software\deskSvc]
[HKLM\Software\index+]
~ Key Software: 182 Legitimates Scanned in 00mn 00s
---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43)
O43 - CFD: 28/06/2010 - 23:31:10 - [7,128] ----D C:\Program Files\Atlantis
O43 - CFD: 30/11/2010 - 22:40:29 - [18,037] ----D C:\Program Files\quickmov
O43 - CFD: 31/03/2013 - 21:15:50 - [4,370] ----D C:\Program Files\Spybot - Search Destroy
O43 - CFD: 03/11/2012 - 14:22:39 - [65,664] ----D C:\Program Files\WordBiz
O43 - CFD: 24/03/2013 - 20:05:18 - [28,816] ----D C:\Program Files\Common Files\337
O43 - CFD: 30/10/2012 - 15:28:20 - [0] ----D C:\ProgramData\BDLogging
O43 - CFD: 24/03/2013 - 14:13:52 - [4,944] ----D C:\ProgramData\BrowserProtect
O43 - CFD: 16/09/2010 - 22:51:00 - [0] ----D C:\ProgramData\eMule
O43 - CFD: 04/11/2012 - 16:39:24 - [400,439] ----D C:\ProgramData\Rosetta Stone
O43 - CFD: 31/03/2013 - 20:49:39 - [0,092] ----D C:\ProgramData\Spybot - Search Destroy
O43 - CFD: 02/01/2010 - 19:13:06 - [0] ----D C:\Users\lara\AppData\Roaming\CrystalSpace
O43 - CFD: 24/03/2013 - 14:13:20 - [0,076] ----D C:\Users\lara\AppData\Roaming\SpeedanAlysis
O43 - CFD: 15/04/2011 - 15:53:16 - [1,643] ----D C:\Users\lara\AppData\Roaming\uTorrent
O43 - CFD: 29/11/2010 - 20:10:26 - [0,079] ----D C:\Users\lara\AppData\Local\PCM4Everio
O43 - CFD: 30/11/2010 - 22:40:06 - [0,002] ----D C:\Users\lara\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Editions Atlas
~ 251 Dossiers CLSID vides (CLSID Empty Folders)
~ Program Folder: 499 Legitimates Scanned in 00mn 02s
---\\ Derniers fichiers modifiés ou crées sous Windows et System32 (O44)
O44 - LFC:[MD5.8CF2B639F0324328B9902120198FF4AA] - 31/03/2013 - 20:14:40 ---A- . (...) -- C:\Windows\DeleteOnReboot.bat [97]
O44 - LFC:[MD5.FE50D71BF1DCA42C36555CA3BCA5036E] - 31/03/2013 - 20:14:39 ---A- . (...) -- C:\AdwCleaner[S2].txt [41171]
O44 - LFC:[MD5.6DED69696691BCF8C1EE65AA7A342A86] - 31/03/2013 - 20:00:33 ---A- . (...) -- C:\AdwCleaner[S1].txt [501]
O44 - LFC:[MD5.B3F3A2A5183A7C2EEB1FE30E61DD64E3] - 31/03/2013 - 20:00:22 ---A- . (...) -- C:\AdwCleaner[R3].txt [42074]
O44 - LFC:[MD5.534CD6A2EE827AEC167B6381AF5CC030] - 31/03/2013 - 19:52:06 ---A- . (...) -- C:\AdwCleaner[R2].txt [42081]
O44 - LFC:[MD5.7456A13AA96093D071505ADA3F2CAD78] - 31/03/2013 - 19:51:20 ---A- . (...) -- C:\AdwCleaner[R1].txt [42020]
O44 - LFC:[MD5.1FF56AC32B38A94C3C88497BD6E00C96] - 30/03/2013 - 02:58:30 ---A- . (...) -- C:\Windows\System32\ieuinit.inf [25185]
O44 - LFC:[MD5.9AD5AA947569DB289CE81B1B1D47BA00] - 24/03/2013 - 19:19:16 ---A- . (.BitDefender - Active Virus Control filter driver.) -- C:\Windows\System32\Drivers\avc3.sys [622616]
O44 - LFC:[MD5.7281D1F4D015064DA967AA492CD8093C] - 24/03/2013 - 19:12:10 ---A- . (.BitDefender - BitDefender AntiVirus Active Virus Control.) -- C:\Windows\System32\Drivers\avchv.sys [241992]
O44 - LFC:[MD5.129673E6E216517EF31944C1514E53C9] - 24/03/2013 - 19:10:52 ---A- . (...) -- C:\Windows\System32\lic2.xml24078 [2842]
O44 - LFC:[MD5.2BCE314A25E71298ADD6794BFBD66266] - 24/03/2013 - 19:09:57 ---A- . (.BitDefender - Active Virus Control Kernel Filtering drive.) -- C:\Windows\System32\Drivers\avckf.sys [447208]
O44 - LFC:[MD5.9C1E3F5A672EDB0831AAF3E36B6876A6] - 24/03/2013 - 19:08:19 ---A- . (.BitDefender LLC - BitDefender Gonzales FileSystem Driver.) -- C:\Windows\System32\Drivers\gzflt.sys [162976]
O44 - LFC:[MD5.F2AEE22231046CAD8D2F94D2C0F9BEFB] - 24/03/2013 - 19:08:19 ---A- . (.BitDefender S.R.L. - Trufos Kernel Module.) -- C:\Windows\System32\Drivers\trufos.sys [343456]
O44 - LFC:[MD5.4CA0EF0E3C5BABD9670E2CF18B29ADE0] - 24/03/2013 - 19:05:54 ---A- . (...) -- C:\Windows\System32\InstallUtil.InstallLog [661]
O44 - LFC:[MD5.1153AC6E133AA849853DFD407B086B80] - 30/11/2012 - 00:17:39 ---A- . (...) -- C:\Windows\System32\locale.nls [420064]
~ Files: 171 Legitimates Scanned in 00mn 02s
---\\ Derniers fichiers créés dans Windows Prefetcher (O45)
O45 - LFCP:[MD5.7F59C00A725329CD6DE211F2E93362EE] - 01/04/2013 - 16:18:41 ---A- - C:\Windows\Prefetch\GRPCONV.EXE-B823222B.pf
~ Prefetcher: 57 Legitimates Scanned in 00mn 00s
---\\ Déni du service (Local Security Authority) (O48)
~ LSA: 9 Legitimates Scanned in 00mn 00s
---\\ Contrôle du Safe Boot (CSB) (O49)
~ CBS: 13 Legitimates Scanned in 00mn 00s
---\\ Trojan Driver Search Data (HKLM) (O52)
~ TDSD: 3 Legitimates Scanned in 00mn 00s
---\\ Microsoft Control Security Providers (O54)
~ MSCP: 2 Legitimates Scanned in 00mn 00s
---\\ Microsoft Windows Policies System (O55)
O55 - MWPS:[HKLM\...\Policies\System] - "EnableUIADesktopToggle"=0
O55 - MWPS:[HKLM\...\Policies\System] - "FilterAdministratorToken"=0
O55 - MWPS:[HKLM\...\Policies\System] - "DisableStatusMessages"=0
~ MWPS: 20 Legitimates Scanned in 00mn 00s
---\\ Microsoft Windows Policies Explorer (O56)
O56 - MWPE:[HKCU\...\policies\Explorer] - "NoDriveTypeAutoRun"=149
O56 - MWPE:[HKCU\...\policies\Explorer] - "NoDriveAutoRun"=0
~ Keys: Scanned in 00mn 00s
---\\ Liste des Drivers Système (O58)
O58 - SDL:[MD5.21E785EBD7DC90A06391141AAC7892FB] - 14/07/2009 - 02:26:15 ---A- . (.Adaptec, Inc. - Adaptec Windows SAS/SATA Storport Driver.) -- C:\Windows\System32\Drivers\adp94xx.sys [422976]
O58 - SDL:[MD5.8AAD333C876590293F72B315E162BCC7] - 13/07/2009 - 22:40:41 ---A- . (...) -- C:\Windows\System32\ANSI.SYS [9029]
~ Drivers: Scanned in 00mn 00s
---\\ Derniers fichiers modifiés ou crées (Utilisateur) (O61)
O61 - LFC: 01/04/2013 - 00:14:53 --HA- C:\Users\lara\AppData\Local\IconCache.db [6059466]
O61 - LFC: 01/04/2013 - 16:09:21 ---A- C:\Users\lara\AppData\Roaming\HTC\Local Store\config\uiconfig.xml [262]
O61 - LFC: 01/04/2013 - 16:09:24 ---A- C:\Users\lara\AppData\Roaming\HTC\Local Store\xml\detecteddevice.xml [59]
O61 - LFC: 01/04/2013 - 16:09:27 ---A- C:\Users\lara\AppData\Roaming\HTC\Local Store\xml\htcsystem_resp.xml [185]
O61 - LFC: 01/04/2013 - 16:09:32 ---A- C:\Users\lara\AppData\Local\Htc\ROUTE66UIPreferences.xml [4013]
O61 - LFC: 01/04/2013 - 16:09:34 ---A- C:\Users\lara\AppData\Local\Htc\CommunicationProtocol.xml [283]
O61 - LFC: 01/04/2013 - 16:16:54 ---A- C:\Users\lara\AppData\Local\Google\Chrome\User Data\Certificate Revocation Lists [271257]
O61 - LFC: 01/04/2013 - 16:19:58 ---A- C:\Users\lara\AppData\Roaming\Microsoft\Spelling\fr-FR\default.acl [2]
O61 - LFC: 01/04/2013 - 16:19:58 ---A- C:\Users\lara\AppData\Roaming\Microsoft\Spelling\fr-FR\default.dic [2]
O61 - LFC: 01/04/2013 - 16:19:58 ---A- C:\Users\lara\AppData\Roaming\Microsoft\Spelling\fr-FR\default.exc [2]
O61 - LFC: 01/04/2013 - 16:23:50 ---A- C:\Users\lara\AppData\Local\Google\Chrome\Application\Dictionaries\fr-FR-3-0.bdic [1074744]
O61 - LFC: 01/04/2013 - 17:09:10 ---A- C:\Users\lara\AppData\Roaming\HTC\Local Store\xml\detecteddevice_resp.xml [59]
O61 - LFC: 01/04/2013 - 19:42:36 ---A- C:\Users\lara\AppData\Local\Google\Chrome\User Data\Local State [36874]
O61 - LFC: 29/03/2013 - 12:03:03 ---A- C:\Users\lara\AppData\Local\Htc\ROUTE66Engine.log.0003 [4882]
O61 - LFC: 30/03/2013 - 12:38:44 ---A- C:\Users\lara\AppData\Local\Htc\ROUTE66Engine.log.0002 [4898]
O61 - LFC: 30/03/2013 - 21:32:24 ---A- C:\Users\lara\Downloads\CV LARA.pdf [92518]
O61 - LFC: 30/03/2013 - 21:40:25 ---A- C:\Users\lara\Downloads\WorksConv.exe [1483808]
O61 - LFC: 30/03/2013 - 21:46:39 ---A- C:\Users\lara\AppData\Roaming\wklnhst.dat [1012]
O61 - LFC: 30/03/2013 - 22:00:12 ---A- C:\Users\lara\Downloads\SpyHunter-Installer.exe [726464]
O61 - LFC: 31/03/2013 - 18:04:27 ---A- C:\Users\lara\AppData\Local\Htc\ROUTE66Engine.log.0001 [4890]
O61 - LFC: 31/03/2013 - 18:25:22 ---A- C:\Users\lara\AppData\Local\Google\Toolbar Cache\7.4.3607.2246\fr\translate_languages.json.content [1505]
O61 - LFC: 31/03/2013 - 18:25:23 ---A- C:\Users\lara\AppData\Local\Google\Toolbar Cache\7.4.3607.2246\fr\translate_element.js.content [2337]
O61 - LFC: 31/03/2013 - 19:05:56 ---A- C:\Users\lara\AppData\Roaming\Google\Local Search History\google%2Eweb.w [88]
O61 - LFC: 31/03/2013 - 19:12:49 ---A- C:\Users\lara\Downloads\ZHPDiag2.exe [5494111]
O61 - LFC: 31/03/2013 - 19:14:03 ---A- C:\Users\lara\Downloads\ZHPDiag2 (1).exe [5494111]
O61 - LFC: 31/03/2013 - 20:00:07 ---A- C:\Users\lara\Downloads\adwcleaner.exe [609993]
O61 - LFC: 31/03/2013 - 20:19:00 ---A- C:\Users\lara\AppData\Local\Htc\ROUTE66Engine.log.0000 [4890]
O61 - LFC: 31/03/2013 - 21:01:05 ---A- C:\Users\lara\Downloads\mbam-setup-1.61.0.1400.exe [10063000]
O61 - LFC: 31/03/2013 - 23:48:30 ---A- C:\Users\lara\AppData\Local\Google\Chrome\Application\26.0.1410.43\Installer\setup.exe [1642448]
O61 - LFC: 31/03/2013 - 23:48:43 R--A- C:\Users\lara\AppData\Local\Google\Chrome\Application\26.0.1410.43\Installer\chrome.7z [122395900]
O61 - LFC: 31/03/2013 - 23:48:54 ---A- C:\Users\lara\AppData\Local\Google\Chrome\Application\VisualElementsManifest.xml [396]
~ 12 Fichiers temporaires (Temporary files)
~ Files: 172 Legitimates Scanned in 00mn 10s
---\\ Liste des outils de nettoyage (O63)
O63 - Logiciel: ZHPDiag 2013 - (.Nicolas Coolman.) [HKLM] -- ZHPDiag_is1
~ ADS: Scanned in 00mn 00s
---\\ Liste des services Legacy (O64)
O64 - Services: CurCS - 27/01/2010 - C:\Windows\System32\DRIVERS\atksgt.sys - atksgt (atksgt) .(...) - LEGACY_ATKSGT
O64 - Services: CurCS - 24/03/2013 - C:\Windows\System32\DRIVERS\avc3.sys (avc3) .(.BitDefender - Active Virus Control filter driver.) - LEGACY_AVC3
O64 - Services: CurCS - 29/10/2012 - C:\Program Files\Bitdefender\Antivirus Free Edition\bdfwfpf.sys (bdfwfpf) .(.BitDefender LLC - BitDefender Firewall WFP Filter Driver.) - LEGACY_BDFWFPF
O64 - Services: CurCS - 02/10/2012 - C:\Program Files\Bitdefender\Antivirus Free Edition\bdselfpr.sys (bdselfpr) .(.BitDefender LLC - BitDefender Self Protection Driver.) - LEGACY_BDSELFPR
O64 - Services: CurCS - 04/10/2012 - C:\Windows\System32\DRIVERS\gzflt.sys (gzflt) .(.BitDefender LLC - BitDefender Gonzales FileSystem Driver.) - LEGACY_GZFLT
O64 - Services: CurCS - 23/06/2010 - C:\Windows\System32\DRIVERS\htcnprot.sys (htcnprot) .(.Windows (R) Win 7 DDK provider - RawPacket NDIS Protocol Driver.) - LEGACY_HTCNPROT
O64 - Services: CurCS - 27/01/2010 - C:\Windows\System32\DRIVERS\lirsgt.sys - lirsgt (lirsgt) .(...) - LEGACY_LIRSGT
O64 - Services: CurCS - 31/10/2012 - C:\Windows\System32\DRIVERS\trufos.sys (trufos) .(.BitDefender S.R.L. - Trufos Kernel Module.) - LEGACY_TRUFOS
~ Legacy: 91 Legitimates Scanned in 00mn 00s
---\\ File Associations Shell Spawning (O67)
O67 - Shell Spawning: [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: [HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe
O67 - Shell Spawning: [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: [HKLM\..\open\Command] (.Microsoft Corporation - Lanceur du composant logiciel enfichable Observateur d’événements.) -- C:\Windows\System32\eventvwr.exe
O67 - Shell Spawning: [HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: [HKLM\..\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe
O67 - Shell Spawning: [HKLM\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\Windows\System32\WScript.exe
O67 - Shell Spawning: [HKLM\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\Windows\regedit.exe
O67 - Shell Spawning: [HKCU\..\open\Command] (.Google Inc. - Google Chrome.) -- C:\Users\lara\AppData\Local\Google\Chrome\Application\chrome.exe
O67 - Shell Spawning: [HKCR\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: [HKCR\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe
O67 - Shell Spawning: [HKCR\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: [HKCR\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: [HKCR\..\open\Command] (.Microsoft Corporation - Lanceur du composant logiciel enfichable Observateur d’événements.) -- C:\Windows\System32\eventvwr.exe
O67 - Shell Spawning: [HKCR\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: [HKCR\..\open\Command] (.Google Inc. - Google Chrome.) -- C:\Users\lara\AppData\Local\Google\Chrome\Application\chrome.exe
O67 - Shell Spawning: [HKCR\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\Windows\System32\WScript.exe
O67 - Shell Spawning: [HKCR\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\Windows\regedit.exe
~ Keys: Scanned in 00mn 00s
---\\ Start Menu Internet (O68)
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (...) -- C:\Users\lara\AppData\Local\Google\Chrome\Application\chrome.exe"
http://www.22find.com
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (...) -- C:\Program Files\Internet Explorer\iexplore.exe
http://www.22find.com
~ Keys: Scanned in 00mn 00s
---\\ Search Browser Infection (O69)
O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} - (Bing) -
http://www.bing.com
O69 - SBI: SearchScopes [HKCU] {6A1806CD-94D4-4689-BA73-E35EA1EA9990} [DefaultScope] - (@ieframe.dll,-12512) -
http://www.bing.com
O69 - SBI: SearchScopes [HKCU] {8FAD2B92-1B27-4CF8-A2FA-530203895245} - (Google) -
http://www.google.fr
O69 - SBI: SearchScopes [HKCU] {902AD390-8A00-453D-9376-4D441D0B15F3} - (Google) -
http://www.google.fr
~ Keys: Scanned in 00mn 00s
---\\ Recherche des services démarrés par Svchost (O83)
~ Services: 32 Legitimates Scanned in 00mn 00s
---\\ Recherche particuliere à la racine de certains dossiers (O84)
[MD5.C72F1F7546D98613B0182F47A1ACEFF5] [SPRF][30/10/2012] (...) -- C:\ProgramData\1351603472.bdinstall.bin [439601]
[MD5.A25B0D99CAFCF679C8A82C01FB6D9F21] [SPRF][24/03/2013] (...) -- C:\ProgramData\1364136599.1920.bin [3535]
[MD5.E67514A7089AEF89C4A467000ABF0C0B] [SPRF][24/03/2013] (...) -- C:\ProgramData\1364136599.3760.bin [89246]
[MD5.29DBC0CF76BF06B313850C2A01A52F64] [SPRF][24/03/2013] (...) -- C:\ProgramData\1364136599.5072.bin [3073]
[MD5.204B0E71328D5760C1EF3EADC622E437] [SPRF][24/03/2013] (...) -- C:\ProgramData\1364136599.5564.bin [36179]
[MD5.92F13EEBB0D15269E6C53D6D101B071A] [SPRF][24/03/2013] (...) -- C:\ProgramData\1364147388.bdinstall.bin [216367]
[MD5.B09AEAD5967D8D4DDE35AB7AD84F0A05] [SPRF][24/03/2013] (...) -- C:\ProgramData\1364148329.bdinstall.bin [32111]
[MD5.32391CA74A5DCB553431756FE2816BF3] [SPRF][24/03/2013] (...) -- C:\ProgramData\1364148408.bdinstall.bin [32027]
[MD5.DC00B50E49C8FB159288D7A7AD06A020] [SPRF][24/03/2013] (...) -- C:\ProgramData\1364148460.bdinstall.bin [157959]
[MD5.F2C3537D6192F986BA83F3D4C7B45786] [SPRF][24/03/2013] (...) -- C:\ProgramData\1364148633.bdinstall.bin [22488]
[MD5.A1208DE90DBBF050FE08B38D969A1968] [SPRF][24/03/2013] (...) -- C:\ProgramData\1364148638.bdinstall.bin [142281]
[MD5.05E85C35B8F003FBAD8317FC8C18C723] [SPRF][24/03/2013] (...) -- C:\ProgramData\1364149222.bdinstall.bin [22419]
[MD5.4314F1738460BDD893586D0D77E426E0] [SPRF][24/03/2013] (...) -- C:\ProgramData\1364149226.bdinstall.bin [26433]
[MD5.3A60DC2E3DA2F4D6ABFD86A388EEB1D7] [SPRF][24/03/2013] (...) -- C:\ProgramData\1364149306.bdinstall.bin [22419]
[MD5.FE4331DF357156CEF7380599F6DFF18E] [SPRF][24/03/2013] (...) -- C:\ProgramData\1364149309.bdinstall.bin [24829]
[MD5.6046DD9F1A603992F48C03EE5A5B3801] [SPRF][06/01/2010] (...) -- C:\ProgramData\ezsidmv.dat [56]
[MD5.C90FFA4142A3E94EEC74FE8EB26BF794] [SPRF][30/03/2013] (...) -- C:\Users\lara\AppData\Local\Temp\SHSetup.exe [44853328]
[MD5.C80CA1C94FB864F6C609C0AF08935B62] [SPRF][30/03/2013] (...) -- C:\Users\lara\AppData\Roaming\wklnhst.dat [1012]
[MD5.DE1F74C3471F2C9A8C0B3969E692F7B2] [SPRF][24/03/2013] (...) -- C:\Users\lara\Desktop\Antivirus_Free_Edition.exe [162208]
[MD5.1E5579B02CFF71F4E0432A0F5A5CC8CF] [SPRF][24/03/2013] (...) -- C:\Users\lara\Desktop\Antivirus_Free_Edition_x86.exe [8649848]
~ Files: Scanned in 00mn 00s
---\\ Firewall Active Exception List (FirewallRules) (O87)
O87 - FAEL: "{79C08C19-8E19-41FA-9CDE-8F7FA9810DB7}" | In - None - P17 - TRUE | .(.Multidmedia Limited - My Flash Application.) -- E:\Program Files\Rosetta Stone\Rosetta Stone Version 3\RosettaStoneVersion3.exe
O87 - FAEL: "{9F493CB5-22E4-4EDE-895E-A8FC2A0EF623}" | Out - None - P6 - TRUE | .(.Multidmedia Limited - My Flash Application.) -- E:\Program Files\Rosetta Stone\Rosetta Stone Version 3\RosettaStoneVersion3.exe
O87 - FAEL: "{DA4F7B5B-7FCD-47FF-92D0-05DDE001CEC2}" | In - None - P6 - TRUE | .(.Rosetta Stone Ltd. - Rosetta Stone Ltd. executable.) -- E:\Program Files\Rosetta Stone\Rosetta Stone Version 3\support\bin\win\RosettaStoneLtdServices.exe
O87 - FAEL: "{3DD64A66-C634-4980-ADD0-059A9D13EF7A}" | Out - None - P6 - TRUE | .(.Rosetta Stone Ltd. - Rosetta Stone Ltd. executable.) -- E:\Program Files\Rosetta Stone\Rosetta Stone Version 3\support\bin\win\RosettaStoneLtdServices.exe
O87 - FAEL: "TCP Query User{8DF5B815-4754-4308-96E8-77A35D296D50}C:\windows\system32\spool\drivers\w32x86\3\lxdnpswx.exe" | In - Private - P6 - TRUE | .(...) -- C:\windows\system32\spool\drivers\w32x86\3\lxdnpswx.exe
O87 - FAEL: "UDP Query User{DA9DABA9-9509-4187-820C-B90D4C4FEC06}C:\windows\system32\spool\drivers\w32x86\3\lxdnpswx.exe" | In - Private - P17 - TRUE | .(...) -- C:\windows\system32\spool\drivers\w32x86\3\lxdnpswx.exe
O87 - FAEL: "{C0C2A287-BC6B-4FDB-86BE-347DECD63E05}" | In - Private - P6 - TRUE | .(.Pas de propriétaire - Printer Device Monitor.) -- C:\Program Files\Lexmark 2600 Series\lxdnmon.exe
O87 - FAEL: "{B0B93A24-8CCF-4ADE-B56B-82684EE8319E}" | In - Private - P17 - TRUE | .(.Pas de propriétaire - Printer Device Monitor.) -- C:\Program Files\Lexmark 2600 Series\lxdnmon.exe
O87 - FAEL: "TCP Query User{256CE690-5C07-4309-A085-4A720361732F}C:\program files\lexmark 2600 series\lxdnmon.exe" | In - Public - P6 - TRUE | .(.Pas de propriétaire - Printer Device Monitor.) -- C:\program files\lexmark 2600 series\lxdnmon.exe
O87 - FAEL: "UDP Query User{7D1A4913-C9F1-4784-90AA-2E04C72B40D2}C:\program files\lexmark 2600 series\lxdnmon.exe" | In - Public - P17 - TRUE | .(.Pas de propriétaire - Printer Device Monitor.) -- C:\program files\lexmark 2600 series\lxdnmon.exe
O87 - FAEL: "{A5A53D54-AFD5-47EF-A770-9C57D9CC00CC}" |In - None - P17 - TRUE | .(...) -- C:\Program Files\Iminent\Iminent.exe (.not file.)
O87 - FAEL: "{8A2FA976-209A-42F6-847D-2453B31E1ACE}" |In - None - P17 - TRUE | .(...) -- C:\Program Files\Iminent\Iminent.Messengers.exe (.not file.)
~ Firewall: 214 Legitimates Scanned in 00mn 00s
---\\ Scan Additionnel (O88)
Database Version : v2.11349 - (30/03/2013)
Clés trouvées (Keys found) : 8
Valeurs trouvées (Values found) : 0
Dossiers trouvés (Folders found) : 1
Fichiers trouvés (Files found) : 0
[HKLM\Software\Microsoft\Tracing\offerbox_RASAPI32] =PUP.OfferBox
[HKLM\Software\Microsoft\Tracing\offerbox_RASMANCS] =PUP.OfferBox
[HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}] =Toolbar.Bing
[HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}] =Toolbar.Bing
[HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\desksvc] =Hijacker.22find
[HKLM\Software\Classes\Installer\Features\9EC6D81181F59F2459A84176A626F9ED] =Adware.IMBooster
[HKLM\Software\Classes\Installer\Products\9EC6D81181F59F2459A84176A626F9ED] =Adware.IMBooster
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9EC6D81181F59F2459A84176A626F9ED] =Adware.IMBooster
C:\Program Files\Common Files\337 =Hijacker.22find
~ Additionnel: Scanned in 00mn 34s
---\\ Product Upgrade Codes (O90)
O90 - PUC: "1F079377ABE54744DAEEE13A0B5A4929" . (.TRDCReminder.) -- c:\Windows\Installer\{773970F1-5EBA-4474-ADEE-1EA3B0A59492}\ARPPRODUCTICON.exe
O90 - PUC: "9EC6D81181F59F2459A84176A626F9ED" . (.Iminent.) -- C:\Windows\Installer\{118D6CE9-5F18-42F9-958A-14676A629FDE}\imbooster.ico
O90 - PUC: "E6A110990025ED11DB8BA7DC658D5939" . (.Rosetta Stone Version 3.) -- C:\Windows\Installer\{99011A6E-5200-11DE-BDB8-7ACD56D89593}\StoneyIcon.exe
~ Update Products: 131 Legitimates Scanned in 00mn 00s
---\\ Etat général des services non Microsoft (EGS) (SR=Running, SS=Stopped)
SR - | Auto 18/08/2009 176128 | (AMD External Events Utility) . (.AMD.) - C:\Windows\System32\atiesrxx.exe
SR - | Auto 18/02/2011 37664 | (Apple Mobile Device) . (.Apple Inc..) - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
SR - | Auto 06/04/2011 349472 | (Bonjour Service) . (.Apple Inc..) - C:\Program Files\Bonjour\mDNSResponder.exe
SR - | Auto 24/03/2013 969280 | (eSafeSvc) . (.eSafe Security Co., Ltd..) - C:\ProgramData\eSafe\eGdpSvc.exe
SS - | Demand 02/03/2011 655624 | (FLEXnet Licensing Service) . (.Acresso Software Inc..) - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
SS - | Auto 07/02/2010 135664 | (gupdate) . (.Google Inc..) - C:\Program Files\Google\Update\GoogleUpdate.exe
SS - | Demand 07/02/2010 135664 | (gupdatem) . (.Google Inc..) - C:\Program Files\Google\Update\GoogleUpdate.exe
SS - | Demand 15/10/2012 194032 | (gusvc) . (.Google.) - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
SR - | Auto 08/02/2013 27136 | (gzserv) . (.Bitdefender.) - C:\Program Files\Bitdefender\Antivirus Free Edition\gzserv.exe
SS - | Demand 04/04/2005 69632 | (IDriverT) . (.Macrovision Corporation.) - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
SR - | Auto 589824 | (lxdn_device) . (...) - C:\Windows\system32\lxdncoms.exe
SR - | Auto 14/12/2012 398184 | (MBAMScheduler) . (.Malwarebytes Corporation.) - C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
SR - | Auto 14/12/2012 682344 | (MBAMService) . (.Malwarebytes Corporation.) - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
SR - | Auto 87040 | (PassThru Service) . (...) - C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe
SS - | Auto 01/03/2013 161384 | (SkypeUpdate) . (.Skype Technologies.) - C:\Program Files\Skype\Updater\Updater.exe
SR - | Demand 25/08/2008 77824 | (SmartFaceVWatchSrv) . (.Toshiba.) - C:\Program Files\Toshiba\SmartFaceV\SmartFaceVWatchSrv.exe
SR - | Auto 19/08/2008 83312 | (TNaviSrv) . (.TOSHIBA Corporation.) - C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe
SR - | Auto 21/11/2007 129632 | (TODDSrv) . (.TOSHIBA Corporation.) - C:\Windows\system32\TODDSrv.exe
SR - | Auto 18/08/2008 431456 | (TosCoSrv) . (.TOSHIBA Corporation.) - C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe
SR - | Auto 15/07/2008 106496 | (TOSHIBA SMART Log Service) . (.TOSHIBA Corporation.) - C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe
SR - | Auto 23/08/2006 49152 | (UleadBurningHelper) . (.Ulead Systems, Inc..) - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
SS - | Demand 14/07/2009 20992 | C:\Program Files\Windows Defender\mpsvc.dll (WinDefend) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe
SR - | Auto 14/07/2009 20992 | C:\Windows\System32\wuaueng.dll (wuauserv) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe
~ Services: Scanned in 00mn 00s
---\\ Recherche Master Boot Record Infection (MBR)(O80)
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer,
http://www.gmer.net
Run by lara at 01/04/2013 20:44:55
device: opened successfully
user: MBR read successfully
Disk trace:
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys iaStor.sys spca.sys halmacpi.dll UNKNOWN [0x85F5A938]C:\Windows\system32\DRIVERS\iaStor.sys Intel Corporation Intel Matrix Storage Manager driver
System32\Drivers\spca.sys
1 ntkrnlpa!IofCallDriver[0x8347BBAA] = \Device\Harddisk0\DR0[0x877AC8D8]
kernel: MBR read successfully
user kernel MBR OK
~ MBR: 14 Legitimates Scanned in 00mn 02s
---\\ Recherche Master Boot Record Infection (MBRCheck)(O80)
Written by ad13,
http://ad13.geekstog
Run by lara at 01/04/2013 20:44:57
********* Dump file Name *********
C:\PhysicalDisk0_MBR.bin
~ MBR: Scanned in 00mn 04s
End of the scan (722 lines in 02mn 35s)(0)