Rapport de ZHPDiag v2013.7.1.1 par Nicolas Coolman, Update du 01/07/2013
Run by Mickael at 04/07/2013 17:24:09
WebSite:
http://nicolascoolman.webs.com
State : Problème connexion internet
WhiteList : Enable
High Elevated Privileges : OK
UAC : Activate by user
---\\ Web Browser
MSIE: Internet Explorer v9.0.8112.16421
GCIE: Google Chrome v27.0.1453.116 (Defaut)
---\\ Windows Product Information
~ Langage: Français
Windows Vista Home Premium Edition, 64-bit Service Pack 2 (Build 6002)
Windows Server License Manager Script : OK
Windows Automatic Updates : OK
---\\ System Protection
Malwarebytes Anti-Malware version 1.75.0.1300
Microsoft Security Client v4.2.0223.1
McAfee Security Scan Plus v3.0.318.3
---\\ System Optimizer
---\\ Peer To Peer (P2P)
eMule
---\\ Software Update
Adobe Flash Player 11 Plugin
Adobe Reader XI
Java 7 Update 25
---\\ System Information
~ Processor: Intel64 Family 6 Model 23 Stepping 10, GenuineIntel
~ Operating System: 64 Bits
Boot mode: Sans échec (Fail-safe boot)
Total RAM: 4094 MB (83% free)
System Restore: Activé (Enable)
System drive C: has 150 GB (43%) free of 342 GB
---\\ Logged in mode
~ Computer Name: PC-DE-MICKAEL
~ User Name: Mickael
~ All Users Names: UpdatusUser, Mickael 2, Mickael, Administrateur,
~ Unselected Option: None
Logged in as Administrator
---\\ Environnement Variables
~ System Unit : C:\
~ %AppData% : C:\Users\Mickael\AppData\Roaming\
~ %Desktop% : C:\Users\Mickael\Desktop\
~ %Favorites% : C:\Users\Mickael\Favorites\
~ %LocalAppData% : C:\Users\Mickael\AppData\Local\
~ %StartMenu% : C:\Users\Mickael\AppData\Roaming\Microsoft\Windows\Start Menu\
~ %Windir% : C:\Windows\
~ %System% : C:\Windows\System32\
---\\ DOS/Devices
C:\ Hard drive, Flash drive, Thumb drive (Free 150 Go of 342 Go)
D:\ Hard drive, Flash drive, Thumb drive (Free 242 Go of 342 Go)
E:\ CD-ROM drive (Not Inserted)
F:\ CD-ROM drive (Not Inserted)
G:\ Floppy drive, Flash card reader, USB Key (Not Inserted)
H:\ Floppy drive, Flash card reader, USB Key (Not Inserted)
I:\ Floppy drive, Flash card reader, USB Key (Not Inserted)
J:\ Floppy drive, Flash card reader, USB Key (Not Inserted)
K:\ CD-ROM drive (Not Inserted)
L:\ Floppy drive, Flash card reader, USB Key (Free 0 Go of 0 Go)
---\\ Security Center Tools Informations
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install] LastSuccessTime : Out Of Date
~ Security Center: 37 Legitimates Filtered in 00mn 00s
---\\ Recherche particulière de fichiers génériques
[MD5.6B08E54A451B3F95E4109DBA7E594270] - (.Microsoft Corporation - Explorateur Windows.) (.11/04/2009 - 08:10:17.) -- C:\Windows\Explorer.exe [3079168]
[MD5.117EA87DF785CA1B9D821F6F213DCE07] - (.Microsoft Corporation - Application de démarrage de Windows.) (.21/01/2008 - 03:50:23.) -- C:\Windows\System32\Wininit.exe [123904]
[MD5.4FBE96D97A1E070A06F76F67255C756D] - (.Microsoft Corporation - Extensions Internet pour Win32.) (.17/05/2013 - 04:02:29.) -- C:\Windows\System32\wininet.dll [1392128]
[MD5.6D0773A3A65D28B663F334C90441D01A] - (.Microsoft Corporation - Application d'ouverture de session Windows.) (.11/04/2009 - 08:11:08.) -- C:\Windows\System32\Winlogon.exe [405504]
[MD5.C4F6CE6087760AD70960C9EB130E7943] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) (.03/01/2012 - 15:25:21.) -- C:\Windows\system32\Drivers\AFD.sys [404992]
[MD5.1898FAE8E07D97F2F6C2D5326C633FAC] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.21/01/2008 - 03:46:50.) -- C:\Windows\system32\Drivers\atapi.sys [22584]
[MD5.B4D787DB8D30793A4D4DF9FEED18F136] - (.Microsoft Corporation - CD-ROM File System Driver.) (.21/01/2008 - 03:50:39.) -- C:\Windows\system32\Drivers\Cdfs.sys [90624]
[MD5.C025AA69BE3D0D25C7A2E746EF6F94FC] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.11/04/2009 - 06:34:39.) -- C:\Windows\system32\Drivers\Cdrom.sys [79872]
[MD5.8B722BA35205C71E7951CDC4CDBADE19] - (.Microsoft Corporation - DFS Namespace Client Driver.) (.14/04/2011 - 16:14:19.) -- C:\Windows\system32\Drivers\DfsC.sys [97792]
[MD5.F942C5820205F2FB453243EDFEC82A3D] - (.Microsoft Corporation - High Definition Audio Bus Driver.) (.11/04/2009 - 06:39:41.) -- C:\Windows\system32\Drivers\HDAudBus.sys [948736]
[MD5.CBB597659A2713CE0C9CC20C88C7591F] - (.Microsoft Corporation - Pilote de port i8042.) (.21/01/2008 - 03:47:27.) -- C:\Windows\system32\Drivers\i8042prt.sys [64000]
[MD5.B7E6212F581EA5F6AB0C3A6CEEEB89BE] - (.Microsoft Corporation - IP Network Address Translator.) (.21/01/2008 - 03:48:45.) -- C:\Windows\system32\Drivers\IpNat.sys [115712]
[MD5.1485811B320FF8C7EDAD1CAEBB1C6C2B] - (.Microsoft Corporation - Windows NT SMB Minirdr.) (.29/04/2011 - 14:39:34.) -- C:\Windows\system32\Drivers\MRxSmb.sys [135680]
[MD5.FC2C792EBDDC8E28DF939D6A92C83D61] - (.Microsoft Corporation - MBT Transport driver.) (.11/04/2009 - 06:42:33.) -- C:\Windows\system32\Drivers\netBT.sys [248320]
[MD5.2ACCAA3C3C55370A32F17B3595E1A217] - (.Microsoft Corporation - Pilote du système de fichiers NT.) (.03/03/2013 - 20:13:14.) -- C:\Windows\system32\Drivers\ntfs.sys [1513320]
[MD5.AECD57F94C887F58919F307C35498EA0] - (.Microsoft Corporation - Pilote de port parallèle.) (.02/11/2006 - 10:37:57.) -- C:\Windows\system32\Drivers\Parport.sys [96768]
[MD5.AC7BC4D42A7E558718DFDEC599BBFC2C] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.11/04/2009 - 06:43:38.) -- C:\Windows\system32\Drivers\Rasl2tp.sys [124928]
[MD5.C045D1FB111C28DF0D1BE8D4BDA22C06] - (.Microsoft Corporation - Microsoft RDP Device redirector.) (.21/01/2008 - 03:46:51.) -- C:\Windows\system32\Drivers\rdpdr.sys [314368]
[MD5.290B6F6A0EC4FCDFC90F5CB6D7020473] - (.Microsoft Corporation - SMB Transport driver.) (.11/04/2009 - 06:42:19.) -- C:\Windows\system32\Drivers\smb.sys [88064]
[MD5.458919C8C42E398DC4802178D5FFEE27] - (.Microsoft Corporation - TDI Translation Driver.) (.11/04/2009 - 06:43:00.) -- C:\Windows\system32\Drivers\tdx.sys [94720]
[MD5.582F710097B46140F5A89A19A6573D4B] - (.Microsoft Corporation - Pilote de cliché instantané du volume.) (.21/08/2012 - 12:50:57.) -- C:\Windows\system32\Drivers\volsnap.sys [267648]
~ Generic Processes: Scanned in 00mn 00s
---\\ Etat des fichiers cachés (Caché/Total)
~ Mes images (My Pictures) : 2/4197
~ Mes musiques (My Musics) : 51/630
~ Mes Videos (My Videos) : 1/4
~ Mes Favoris (My Favorites) : 1/116
~ Mes Documents (My Documents) : 1/13696
~ Mon Bureau (My Desktop) : 1/5347
~ Menu demarrer (Programs) : 1/57
~ Hidden Files: Scanned in 00mn 50s
---\\ Processus lancés
[MD5.C04549F211179A3C3DF1EFFF19DE041A] - (.Nicolas Coolman - ZHPDiag.) -- C:\Program Files (x86)\ZHPDiag\ZHPDiag.exe [7629824] [PID.300]
[MD5.6080A176D09435FC8E6E800996656E18] - (.Microsoft Corporation - Console IME.) -- C:\Windows\SysWOW64\conime.exe [69120] [PID.1404]
~ Processes Running: Scanned in 00mn 00s
---\\ Google Chrome, Démarrage,Recherche,Extensions (G0,G1,G2)
C:\Users\Mickael\AppData\Local\Google\Chrome\User Data\Default\Preferences
G2 - GCE: Preference [User Data\Default] [golfgdoojafiippacodpnlfkmclpdgmo] winnie the pooh v.1 (Activé)
G2 - GCE: Preference [User Data\Default] [hlddcjcfgdjclmkhhddocoendieiooag] Lyrics Plus v.1.116 (Désactivé)
~ Google Browser: 20 Legitimates Filtered in 00mn 14s
---\\ Mozilla Firefox, Plugins,Demarrage,Recherche,Extensions (P2,M0,M1,M2,M3)
C:\Users\Mickael\AppData\Roaming\Mozilla\Firefox\Profiles\qhs3gljn.default\prefs.js
M2 - MFEP: prefs.js [Mickael - qhs3gljn.default\
e180d6e8-52cd-41d9-9002-9e43f22d4c91@7466a5f3-05bd-4c4d-a0e9-9442a8ea8a0e.com] [] Plus-HD-1.5 v (..) =Adware.PlusHD
M2 - MFEP: prefs.js [Mickael - qhs3gljn.default\{3112ca9c-de6d-4884-a869-9855de68056c}] [] Google Toolbar for Firefox v7.1.20110316W (..)
M2 - MFEP: prefs.js [Mickael - qhs3gljn.default\{c21ca2bf-7f85-4713-9b57-809b6c4c7f4e}] [] Messenger Plus! Community Smartbar v7.1.20110316W (..) =Hijacker.SmartBar
P2 - FPN: [HKCU] [vitzo.com/VDownloader] - (.Vitzo - VDownloader browser plug-in.) -- C:\Program Files\VDownloader\Addons\npVDownloader.dll
~ Firefox Browser: 32 Legitimates Filtered in 00mn 00s
---\\ Internet Explorer, Proxy Management (R5)
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll
~ Proxy management: Scanned in 00mn 00s
---\\ Analyse des lignes F0, F1, F2, F3 - IniFiles, Autoloading programs
F2 - REG:system.ini: USERINIT=C:\Windows\system32\userinit.exe,
F2 - REG:system.ini: Shell=C:\Windows\explorer.exe
F2 - REG:system.ini: VMApplet=rundll32 shell32,Control_RunDLL "sysdm.cpl"
~ Keys: Scanned in 00mn 00s
---\\ Redirection du fichier Hosts (O1)
~ Le fichier hosts est sain (The hosts file is clean).
~ Hosts File: Scanned in 00mn 00s
~ Nombre de lignes (Lines number): 20
---\\ Applications démarrées par registre par dossier (O4)
O4 - HKLM\..\Run: [Windows Defender] C:\Program Files (x86)\Windows Defender\MSASCui.exe (.not file.)
O4 - HKLM\..\Run: [IAAnotif] . (.Intel Corporation - Event Monitor User Notification Tool.) -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [RtHDVCpl] . (.Realtek Semiconductor - HD Audio Control Panel.) -- C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
O4 - HKLM\..\Run: [Skytel] . (.Realtek Semiconductor Corp. - Realtek Voice Manager.) -- C:\Program Files\Realtek\Audio\HDA\Skytel.exe
O4 - HKLM\..\Run: [FijiKeyboard] . (.Packard Bell BV - Activboard Application.) -- c:\Acer\Preload\Autorun\DRV\FIJI Keyboard\ABoard.exe
O4 - HKLM\..\Run: [Monitor] . (.PixArt Imaging Incorporation - Registry Monitor.) -- C:\Windows\PixArt\PAC207\Monitor.exe
O4 - HKLM\..\Run: [MSC] . (.Microsoft Corporation - Microsoft Security Client User Interface.) -- C:\Program Files\Microsoft Security Client\msseces.exe
O4 - HKLM\..\Run: [Nvtmru] . (.NVIDIA Corporation - NVIDIA NvTmru Application.) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe
O4 - HKCU\..\Run: [SmpcSys] . (.Acer Incorporated - SMP Systray.) -- C:\Program Files (x86)\Packard Bell\SetUpMyPC\SmpSys.exe
O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] . (.Nero AG - Nero Home.) -- C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexStoreSvr.exe
O4 - HKCU\..\Run: [EPSON Stylus DX6000 Series] . (.SEIKO EPSON CORPORATION - EPSON Status Monitor 3.) -- C:\Windows\system32\spool\DRIVERS\x64\3\E_FATIBIE.exe
O4 - HKCU\..\Run: [Neuf Media Center] . (.SFR - Media Center.) -- C:\Program Files (x86)\SFR\Media Center\MediaCenter.exe
O4 - HKCU\..\Run: [RocketDock] . (...) -- C:\Program Files (x86)\RocketDock\RocketDock.exe
O4 - HKCU\..\Run: [Connexion SFR 9props.exe] . (.SFR - Propriétés de la connexion SFR.) -- C:\Program Files (x86)\SFR\Kit\9props.exe
O4 - HKCU\..\Run: [Facebook Update] . (.Facebook Inc. - Programme d'installation de Facebook.) -- C:\Users\Mickael\AppData\Local\Facebook\Update\FacebookUpdate.exe
O4 - HKCU\..\Run: [Skype] . (.Skype Technologies S.A. - Skype.) -- C:\Program Files (x86)\Skype\Phone\Skype.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe (.not file.)
O4 - HKCU\..\Run: [DAEMON Tools Lite] . (.Disc Soft Ltd - DAEMON Tools Lite.) -- C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
O4 - HKCU\..\Run: [Google Update] . (.Google Inc. - Programme d'installation de Google.) -- C:\Users\Mickael\AppData\Local\Google\Update\GoogleUpdate.exe
O4 - HKLM\..\Wow6432Node\Run: [PlusService] . (.Yuna Software - Messenger Plus! 6.) -- C:\Program Files (x86)\Yuna Software\Messenger Plus!\PlusService.exe
O4 - HKLM\..\Wow6432Node\Run: [APSDaemon] . (.Apple Inc. - Apple Push.) -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
O4 - HKLM\..\Wow6432Node\Run: [VMonitorVMUVC] . (.Vimicro Corporation - Monitor SnapShot Button.) -- C:\Program Files (x86)\Vimicro Corporation\VMUVC\VMonitor.exe
O4 - HKLM\..\Wow6432Node\Run: [InstaLAN] . (.Affinegy, Inc. - Pas de description.) -- C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinRouterMonitor.exe
O4 - HKLM\..\Wow6432Node\Run: [DivXMediaServer] . (.DivX, LLC - DivX DLNA Media Server.) -- C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe
O4 - HKLM\..\Wow6432Node\Run: [MessengerPlusForSkypeService] . (.Yuna Software - Service - Messenger Plus! for Skype.) -- C:\Program Files (x86)\Yuna Software\Messenger Plus! for Skype\MsgPlusForSkypeService.exe
O4 - HKLM\..\Wow6432Node\Run: [DivXUpdate] . (.Pas de propriétaire - DivX Update.) -- C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
O4 - HKLM\..\Wow6432Node\Run: [Adobe ARM] . (.Adobe Systems Incorporated - Adobe Reader and Acrobat Manager.) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
O4 - HKLM\..\Wow6432Node\Run: [QuickTime Task] . (.Apple Inc. - QuickTime Task.) -- C:\Program Files (x86)\QuickTime\QTTask.exe
O4 - HKLM\..\Wow6432Node\Run: [iTunesHelper] . (.Apple Inc. - iTunesHelper.) -- C:\Program Files (x86)\iTunes\iTunesHelper.exe
O4 - HKLM\..\Wow6432Node\Run: [SunJavaUpdateSched] . (.Oracle Corporation - Java(TM) Update Scheduler.) -- C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] . (.Microsoft Corporation - Volet Windows.) -- C:\Program Files (x86)\Windows Sidebar\Sidebar.exe
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] oobefldr.dll
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] . (.Microsoft Corporation - Volet Windows.) -- C:\Program Files (x86)\Windows Sidebar\Sidebar.exe
O4 - HKUS\S-1-5-20\..\Run: [WindowsWelcomeCenter] oobefldr.dll
O4 - HKUS\S-1-5-21-3055793546-3695696052-210246096-1000\..\Run: [SmpcSys] . (.Acer Incorporated - SMP Systray.) -- C:\Program Files (x86)\Packard Bell\SetUpMyPC\SmpSys.exe
O4 - HKUS\S-1-5-21-3055793546-3695696052-210246096-1000\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] . (.Nero AG - Nero Home.) -- C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexStoreSvr.exe
O4 - HKUS\S-1-5-21-3055793546-3695696052-210246096-1000\..\Run: [EPSON Stylus DX6000 Series] . (.SEIKO EPSON CORPORATION - EPSON Status Monitor 3.) -- C:\Windows\system32\spool\DRIVERS\x64\3\E_FATIBIE.exe
O4 - HKUS\S-1-5-21-3055793546-3695696052-210246096-1000\..\Run: [Neuf Media Center] . (.SFR - Media Center.) -- C:\Program Files (x86)\SFR\Media Center\MediaCenter.exe
O4 - HKUS\S-1-5-21-3055793546-3695696052-210246096-1000\..\Run: [RocketDock] . (...) -- C:\Program Files (x86)\RocketDock\RocketDock.exe
O4 - HKUS\S-1-5-21-3055793546-3695696052-210246096-1000\..\Run: [Connexion SFR 9props.exe] . (.SFR - Propriétés de la connexion SFR.) -- C:\Program Files (x86)\SFR\Kit\9props.exe
O4 - HKUS\S-1-5-21-3055793546-3695696052-210246096-1000\..\Run: [Facebook Update] . (.Facebook Inc. - Programme d'installation de Facebook.) -- C:\Users\Mickael\AppData\Local\Facebook\Update\FacebookUpdate.exe
O4 - HKUS\S-1-5-21-3055793546-3695696052-210246096-1000\..\Run: [Skype] . (.Skype Technologies S.A. - Skype.) -- C:\Program Files (x86)\Skype\Phone\Skype.exe
O4 - HKUS\S-1-5-21-3055793546-3695696052-210246096-1000\..\Run: [WMPNSCFG] C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe (.not file.)
O4 - HKUS\S-1-5-21-3055793546-3695696052-210246096-1000\..\Run: [DAEMON Tools Lite] . (.Disc Soft Ltd - DAEMON Tools Lite.) -- C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
O4 - HKUS\S-1-5-21-3055793546-3695696052-210246096-1000\..\Run: [Google Update] . (.Google Inc. - Programme d'installation de Google.) -- C:\Users\Mickael\AppData\Local\Google\Update\GoogleUpdate.exe
~ Application: Scanned in 00mn 00s
---\\ Autres liens utilisateurs (O4)
O4 - GS\Desktop: AlerteGPS G300.lnk . (...) -- C:\Program Files (x86)\AlerteGPS\G300\G300-V1.exe
O4 - GS\Desktop: SpeedFan.lnk . (.Almico Software (
http://www.almico.com) - Pas de description.) -- C:\Program Files (x86)\SpeedFan\speedfan.exe
O4 - GS\Programs: Internet Explorer (64-bit).lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
O4 - GS\Programs: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
O4 - GS\Programs: Windows Mail.lnk . (.Microsoft Corporation - Windows Mail.) -- C:\Program Files (x86)\Windows Mail\WinMail.exe
O4 - GS\Programs: Windows Media Player.lnk . (.Microsoft Corporation - Windows Media Player.) -- C:\Program Files (x86)\Windows Media Player\wmplayer.exe
O4 - GS\QuickLaunch: Launch Internet Explorer Browser.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
O4 - GS\Accessories: Internet Explorer (No Add-ons).lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
O4 - GS\SendTo: Assistant Transfert de fichiers Bluetooth.LNK . (.Microsoft Corporation - Pas de description.) -- C:\Windows\System32\fsquirt.exe
O4 - GS\QuickLaunch: Anti Doublons 2010.lnk . (...) -- C:\Adp\adp.exe
O4 - GS\QuickLaunch: Apple Safari.lnk . (...) -- C:\Windows\Installer\{C779648B-410E-4BBA-B75B-5815BCEFE71D}\SafariIco.exe
O4 - GS\QuickLaunch: Cartes de visite Edition Spéciale.lnk . (...) -- C:\Program Files (x86)\Micro Application\Cartes de visite Edition Spéciale\draw7053.exe
O4 - GS\QuickLaunch: ConvertXtoDVD 4.lnk . (.VSO Software SARL - ConvertXToDVD transcoder.) -- C:\Program Files (x86)\VSO\ConvertX\4\ConvertXtoDvd.exe
O4 - GS\QuickLaunch: CyberLink PowerDVD 9.lnk . (.CyberLink Corp. - PDVDLaunchPolicy Application.) -- C:\Program Files (x86)\CyberLink\PowerDVD9\PDVDLaunchPolicy.exe
O4 - GS\QuickLaunch: DAEMON Tools Lite.lnk . (.Disc Soft Ltd - DAEMON Tools Lite.) -- C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
O4 - GS\QuickLaunch: DivX Plus Player.lnk . (...) -- C:\Program Files (x86)\DivX\DivX Plus Player\DivX Plus Player.exe
O4 - GS\QuickLaunch: DVD Decrypter.lnk . (.LIGHTNING UK! - DVD Decrypter - The Ultimate DVD Ripper!.) -- C:\Program Files (x86)\DVD Decrypter\DVDDecrypter.exe
O4 - GS\QuickLaunch: DVD Shrink 3.2.lnk . (.DVD Shrink - DVD Shrink 3.2.) -- C:\Program Files (x86)\DVD Shrink\DVD Shrink 3.2.exe
O4 - GS\QuickLaunch: DVDFab 8.lnk . (.Fengtao Software Inc. - DVDFab is the all-in-one software package f.) -- C:\Program Files (x86)\DVDFab 8\DVDFab.exe
O4 - GS\QuickLaunch: Démarrer la détection.lnk . (...) -- C:\Program Files (x86)\ma-config.com\StartDetection.html
O4 - GS\QuickLaunch: eBay.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
http://go.packardbell.com
O4 - GS\QuickLaunch: eMule.lnk . (.
http://www.emule-project.net - eMule.) -- C:\Program Files (x86)\eMule\emule.exe
O4 - GS\QuickLaunch: Enregistrement Packard Bell.lnk . (.Acer Incorporated - Packard Bell Customer Registration.) -- C:\Program Files (x86)\Packard Bell\Packard Bell Customer Registration\PBCReg.exe
O4 - GS\QuickLaunch: Google Chrome.lnk . (.Google Inc. - Google Chrome.) -- C:\Users\Mickael\AppData\Local\Google\Chrome\Application\chrome.exe
O4 - GS\QuickLaunch: Google Earth.lnk . (.Google - Google Earth.) -- C:\Program Files (x86)\Google\Google Earth\client\googleearth.exe
O4 - GS\QuickLaunch: Guide de l'utilisateur (Packard Bell InfoCenter).lnk . (.Acer Incorporated - Packard Bell InfoCentre.) -- C:\Program Files (x86)\Packard Bell\InfoCentre\InfoCtr.exe
O4 - GS\QuickLaunch: ImgBurn.lnk . (.LIGHTNING UK! - ImgBurn - Le Logiciel de Gravure d'Image Ul.) -- C:\Program Files (x86)\ImgBurn\ImgBurn.exe
O4 - GS\QuickLaunch: iTunes.lnk . (.Apple Inc. - iTunes.) -- C:\Program Files (x86)\iTunes\iTunes.exe
O4 - GS\QuickLaunch: Lancer QuickCam de Logitech.lnk . (.Logitech Inc. - QuickCam Application.) -- C:\Program Files (x86)\Logitech\QuickCam\QuickCam.exe
O4 - GS\QuickLaunch: Malwarebytes Anti-Malware.lnk . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe
O4 - GS\QuickLaunch: MBRCheck.lnk . (...) -- C:\Program Files (x86)\ZHPDiag\mbrcheck.exe
O4 - GS\QuickLaunch: McAfee Security Scan Plus.lnk . (...) -- C:\Program Files (x86)\McAfee Security Scan\2.0.181\McUICnt.exe (.not file.)
O4 - GS\QuickLaunch: Media Impression 2.lnk . (.ArcSoft, Inc. - MediaImpression.) -- C:\Program Files (x86)\ArcSoft\MediaImpression 2\MediaImpression.exe
O4 - GS\QuickLaunch: Microsoft Works.lnk . (.Microsoft® Corporation - Microsoft® Works.) -- C:\Program Files (x86)\Microsoft Works\MSWorks.exe
O4 - GS\QuickLaunch: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
O4 - GS\QuickLaunch: Mozilla Thunderbird.lnk . (.Mozilla Corporation - Thunderbird.) -- C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe
O4 - GS\QuickLaunch: Nero StartSmart.lnk . (.Nero AG - Nero StartSmart 9 Application.) -- C:\Program Files (x86)\Nero\Nero 9\Nero StartSmart\NeroStartSmart.exe
O4 - GS\QuickLaunch: ObjectDock.lnk . (.Stardock - ObjectDock.) -- C:\Program Files (x86)\Stardock\ObjectDock\ObjectDock.exe
O4 - GS\QuickLaunch: PC Inspector File Recovery.lnk . (...) -- C:\Program Files (x86)\Convar\PC Inspector File Recovery\Filerecovery.exe
O4 - GS\QuickLaunch: PhotoScape.lnk . (...) -- C:\Program Files (x86)\PhotoScape\PhotoScape.exe
O4 - GS\QuickLaunch: Quick Media Converter.lnk . (.Cocoon Software - Quick Media Converter Next Generation HD.) -- C:\Program Files\QuickMediaConverter\QuickMediaConverter.exe
O4 - GS\QuickLaunch: QuickTime Player.lnk . (.Apple Inc. - QuickTime Player.) -- C:\Program Files (x86)\QuickTime\QuickTimePlayer.exe
O4 - GS\QuickLaunch: Recuva.lnk . (.Piriform Ltd - Recuva.) -- C:\Program Files\Recuva\Recuva64.exe
O4 - GS\QuickLaunch: Revo Uninstaller.lnk . (.VS Revo Group - Revo Uninstaller.) -- C:\Program Files (x86)\VS Revo Group\Revo Uninstaller\Revouninstaller.exe
O4 - GS\QuickLaunch: VDownloader.lnk . (.Vitzo - VDownloader.) -- C:\Program Files\VDownloader\VDownloader.exe
O4 - GS\QuickLaunch: VLC media player.lnk . (...) -- C:\Program Files (x86)\VideoLAN\VLC\vlc.exe
O4 - GS\QuickLaunch: Windows Media Player.lnk . (.Microsoft Corporation - Windows Media Player.) -- C:\Program Files (x86)\Windows Media Player\wmplayer.exe
O4 - GS\QuickLaunch: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) -- C:\Program Files (x86)\ZHPDiag\ZHPDiag.exe
O4 - GS\QuickLaunch: ZHPFix.lnk . (...) -- C:\Program Files (x86)\ZHPDiag\ZHPFix.exe (.not file.)
O4 - GS\SendTo: Skype.lnk . (.Skype Technologies S.A. - Skype.) -- C:\Program Files (x86)\Skype\Phone\Skype.exe
O4 - GS\Desktop: Google Chrome.lnk . (.Google Inc. - Google Chrome.) -- C:\Users\Mickael\AppData\Local\Google\Chrome\Application\chrome.exe
O4 - GS\Desktop: INFORAD MANAGER 3.9.lnk . (.Inforad Ltd. - INFORAD Manager 3.9 Daemon.) -- C:\Users\Mickael\AppData\Local\IFM39\ifdmon.exe
O4 - GS\Desktop: Radiomanager.lnk . (...) -- C:\Users\Mickael\AppData\Roaming\Microsoft\Installer\{4AF68616-7251-41A0-A458-86EAFE31D063}\_41066CA997838B67554B25.exe
~ Global Startup: Scanned in 00mn 01s
---\\ Boutons situés sur la barre d'outils principale d'Internet Explorer (O9)
O9 - Extra button: Skype Click to Call [64Bits] - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} . (...) -- c:\program files (x86)\skype\toolbars\internet explorer x64\icon.ico
~ IE Extra Buttons: Scanned in 00mn 00s
---\\ Objets ActiveX (Downloaded Program Files)(O16)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} ((no name)) -
http://fpdownload2.macromedia.com/get/s ... wflash.cab
~ Objets ActiveX Scanned in 00mn 00s
---\\ Modification Domaine/Adresses DNS (O17)
O17 - HKLM\System\CCS\Services\Tcpip\..\{7F41A451-E673-4695-8EFB-1C3F0D5CDAD1}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{7F41A451-E673-4695-8EFB-1C3F0D5CDAD1}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{7F41A451-E673-4695-8EFB-1C3F0D5CDAD1}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
~ Domain: Scanned in 00mn 00s
---\\ Protocole additionnel (O18)
O18 - Handler: wlpg [64Bits] - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} . (...) --
O18 - Filter: text/xml [64Bits] - {807563E5-5146-11D5-A672-00B0D022E945} . (.Microsoft Corporation - Microsoft Office XML MIME Filter.) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.dll
~ Protocole Additionnel: Scanned in 00mn 00s
---\\ Clé de Registre autorun SharedTaskScheduler (STS) (O22)
O22 - SharedTaskScheduler: Component Categories cache daemon [64Bits] - {8C7461EF-2B13-11d2-BE35-3078302C2030} . (.Microsoft Corporation - Bibliothèque de l'interface utilisateur du.) -- C:\Windows\System32\browseui.dll
~ STS/SSO: Scanned in 00mn 00s
---\\ Liste des services NT non Microsoft et non désactivés (O23)
O23 - Service: AffinegyService (AffinegyService) . (.Affinegy, Inc. - BelkinService.) - C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinService.exe
O23 - Service: Norton Internet Security (Norton Internet Security) . (...) - C:\Program Files (x86)\Norton Internet Security\Engine\16.0.0.125\ccSvcHst.exe (.not file.)
O23 - Service: Power Control [2011/08/24 18:48:04] ({B154377D-700F-42cc-9474-23858FBDF4BD}) . (.CyberLink Corp. - Pas de description.) - C:\Program Files (x86)\CyberLink\PowerDVD9\000.fcl
~ Services: 16 Legitimates Filtered in 00mn 04s
---\\ Tâches planifiées en automatique (O39)
O39 - APT:Automatic Planified Task - C:\Windows\Tasks\Lyrics Plus Update.job [388]
O39 - APT:Automatic Planified Task - C:\Windows\Tasks\NeroLiveEpgUpdate-PC-de-Mickael_Mickael.job [398]
O39 - APT:Automatic Planified Task - C:\Windows\Tasks\Plus-HD-1.5-chromeinstaller.job [1894] =Adware.PlusHD
O39 - APT:Automatic Planified Task - C:\Windows\Tasks\Plus-HD-1.5-codedownloader.job [1186] =Adware.PlusHD
O39 - APT:Automatic Planified Task - C:\Windows\Tasks\Plus-HD-1.5-enabler.job [1086] =Adware.PlusHD
O39 - APT:Automatic Planified Task - C:\Windows\Tasks\Plus-HD-1.5-firefoxinstaller.job [1818] =Adware.PlusHD
O39 - APT:Automatic Planified Task - C:\Windows\Tasks\Plus-HD-1.5-updater.job [1174] =Adware.PlusHD
~ Scheduled Task: 14 Legitimates Filtered in 00mn 00s
---\\ Pilotes lancés au démarrage (O41)
O41 - Driver: (SRTSP) . (. - .) - C:\Windows\system32\drivers\NISx64\1000000.07D\SRTSP64.sys (.not file.)
O41 - Driver: (SRTSPX) . (. - .) - C:\Windows\system32\drivers\NISx64\1000000.07D\SRTSPX64.sys (.not file.)
~ Drivers: 69 Legitimates Filtered in 00mn 00s
---\\ Logiciels installés (O42)
O42 - Logiciel: Agriculture Simulator 2012 - (...) [HKLM][64Bits] -- Agrar Simulator 2012
O42 - Logiciel: Cascade Crossing - (...) [HKLM][64Bits] -- Cascade Crossing
O42 - Logiciel: Forklift Truck Simulator 2009 - (.Astragon.) [HKLM][64Bits] -- {AF805B23-DCB3-44D5-A9A8-B44C7A80C8D7}_is1
O42 - Logiciel: Lyrics Plus - (.Plus Add-on Software.) [HKLM][64Bits] --
lyrics@lyricsplus.net
O42 - Logiciel: Plus-HD-1.5 - (.Plus HD.) [HKLM][64Bits] -- Plus-HD-1.5 =Adware.PlusHD
O42 - Logiciel: Programme d'installation et utilitaire de surveillance - (...) [HKLM][64Bits] -- Programme d'installation et utilitaire de surveillance_is1
O42 - Logiciel: WinSesame - (...) [HKLM][64Bits] -- WinSesame
O42 - Logiciel: Woodcutter Simulator 2011 - (...) [HKLM][64Bits] -- Woodcutter Simulator 2011
~ Logic: 216 Legitimates Filtered in 00mn 00s
---\\ HKCU HKLM Software Keys
[HKCU\Software\AppDataLow\Software\LyricsPlus]
[HKCU\Software\AppDataLow\Software\Plus-HD-1.5] =Adware.PlusHD
[HKCU\Software\Blabbers ] =PUP.Blabbers
[HKCU\Software\IncrediMail]
[HKCU\Software\KoroSoft]
[HKCU\Software\SweetIM] =PUP.SweetIM
[HKLM\Software\SearchCore for Browsers] =Adware.SearchCore
[HKLM\Software\WNLT] =Adware.IncrediBar
[HKLM\Software\Wow6432Node\SweetIM] =PUP.SweetIM
~ Key Software: 341 Legitimates Filtered in 00mn 00s
---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43)
O43 - CFD: 25/08/2012 - 11:31:13 - [266,983] ----D C:\Program Files (x86)\Agrar Simulator 2012
O43 - CFD: 01/09/2012 - 14:16:38 - [260,316] ----D C:\Program Files (x86)\Forklift Truck Simulator 2009
O43 - CFD: 21/06/2013 - 17:32:28 - [1,172] ----D C:\Program Files (x86)\LyricsPlus
O43 - CFD: 23/05/2013 - 16:37:48 - [7,156] ----D C:\Program Files (x86)\Plus-HD-1.5 =Adware.PlusHD
O43 - CFD: 02/07/2013 - 18:19:08 - [0,359] ----D C:\Program Files (x86)\sweetpacks bundle uninstaller =PUP.SweetIM
O43 - CFD: 05/05/2013 - 17:11:21 - [623,937] ----D C:\Program Files (x86)\Woodcutter Simulator 2011
O43 - CFD: 23/02/2013 - 16:35:17 - [0] ----D C:\ProgramData\Ask
O43 - CFD: 25/03/2012 - 18:47:05 - [0] ----D C:\Users\Mickael\AppData\Roaming\WinSesame
O43 - CFD: 18/12/2012 - 18:44:56 - [0,301] ----D C:\Users\Mickael\AppData\Local\GIANTS Editor 4.1.7
O43 - CFD: 02/01/2013 - 18:47:02 - [0,103] ----D C:\Users\Mickael\AppData\Local\GIANTS Editor 5.0.1
O43 - CFD: 13/10/2012 - 14:16:47 - [0] ----D C:\Users\Mickael\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Cascade Crossing
O43 - CFD: 25/03/2012 - 18:59:11 - [0,001] ----D C:\Users\Mickael\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinSauvegarde
O43 - CFD: 25/03/2012 - 18:47:13 - [0,001] ----D C:\Users\Mickael\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinSesame
~ 593 Dossiers CLSID vides (CLSID Empty Folders)
~ Program Folder: 976 Legitimates Filtered in 01mn 41s
---\\ Derniers fichiers modifiés ou crées sous Windows et System32 (O44)
O44 - LFC:[MD5.9A1747930277828227F81533191F4E4E] - 04/07/2013 - 16:23:08 ---A- . (...) -- C:\Windows\ntbtlog.txt [475066]
O44 - LFC:[MD5.1FF6F80FC476BF9B189BF23A3FA487C8] - 04/07/2013 - 16:20:01 --HA- . (...) -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 [3216]
O44 - LFC:[MD5.1FF6F80FC476BF9B189BF23A3FA487C8] - 04/07/2013 - 16:20:01 --HA- . (...) -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 [3216]
O44 - LFC:[MD5.1FF6F80FC476BF9B189BF23A3FA487C8] - 04/07/2013 - 16:20:01 RSHAD . (...) -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 [3216]
O44 - LFC:[MD5.1FF6F80FC476BF9B189BF23A3FA487C8] - 04/07/2013 - 16:20:01 RSHAD . (...) -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 [3216]
O44 - LFC:[MD5.C4421484DB2B8C461F64C2634A0E3639] - 03/07/2013 - 16:45:38 ---A- . (...) -- C:\Windows\DeleteOnReboot.bat [4325]
O44 - LFC:[MD5.08E6745B20457ED6913D321EB0B35351] - 02/07/2013 - 17:19:10 ---A- . (...) -- C:\Windows\SysNative\dmwu.exe [1277744]
O44 - LFC:[MD5.695946F7F4CEEAF05394D763A45C6CC5] - 02/07/2013 - 17:19:10 ---A- . (.IncrediMail, Ltd. - IMHttpCo Dynamic Link Library.) -- C:\Windows\SysNative\ImHttpComm.dll [35328]
O44 - LFC:[MD5.08E6745B20457ED6913D321EB0B35351] - 02/07/2013 - 17:19:10 RSHAD . (...) -- C:\Windows\System32\dmwu.exe [1277744]
O44 - LFC:[MD5.695946F7F4CEEAF05394D763A45C6CC5] - 02/07/2013 - 17:19:10 RSHAD . (.IncrediMail, Ltd. - IMHttpCo Dynamic Link Library.) -- C:\Windows\System32\ImHttpComm.dll [35328]
O44 - LFC:[MD5.EB74A80456BFFCE997E16F4C366AB5EF] - 21/06/2013 - 13:06:36 ---A- . (...) -- C:\Windows\SysNative\nvinfo.pb [21578]
O44 - LFC:[MD5.EB74A80456BFFCE997E16F4C366AB5EF] - 21/06/2013 - 13:06:36 RSHAD . (...) -- C:\Windows\System32\nvinfo.pb [21578]
~ Files: 64 Legitimates Filtered in 00mn 04s
---\\ Derniers fichiers créés dans Windows Prefetcher (O45)
O45 - LFCP:[MD5.9E23209642F152AC1E60BB5DAFC5C9FE] - 04/07/2013 - 16:14:34 ---A- - C:\Windows\Prefetch\HTTPD.EXE-DC628125.pf
O45 - LFCP:[MD5.AF4E2D0825607B6BEB9659B8CF6FE580] - 23/06/2013 - 10:12:57 ---A- - C:\Windows\Prefetch\FARMINGSIMULATOR2013GAME.EXE-D44F8D3F.pf
O45 - LFCP:[MD5.9F036D4D26F1B1F4D77E79B48E3D0687] - 23/06/2013 - 10:13:00 ---A- - C:\Windows\Prefetch\FARMINGSIMULATOR2013.EXE-E2CFD1FD.pf
~ Prefetcher: 92 Legitimates Filtered in 00mn 00s
---\\ MountPoints2 Shell Key (O51)
O51 - MPSK:{08c29269-cf3b-11e0-b56f-001f16f2fbdf}\AutoRun\command. (...) -- M:\setup.exe (.not file.)
O51 - MPSK:{2058233b-4de6-11e2-aa99-001f16f2fbdf}\AutoRun\command. (...) -- K:\start.exe (.not file.)
O51 - MPSK:{6314da06-caad-11e2-a535-001f16f2fbdf}\AutoRun\command. (...) -- K:\cdstart.exe (.not file.)
O51 - MPSK:{6517a7a6-e532-11e1-9f16-001f16f2fbdf}\AutoRun\command. (...) -- M:\cdstart.exe (.not file.)
O51 - MPSK:{be10f806-b954-11e1-8b91-001f16f2fbdf}\AutoRun\command. (...) -- L:\cdstart.exe (.not file.)
O51 - MPSK:{e87d0fb5-ba56-11e2-890a-001f16f2fbdf}\AutoRun\command. (...) -- O:\iLinker.exe (.not file.)
~ Keys: Scanned in 00mn 00s
---\\ Trojan Driver Search Data (HKLM) (O52)
O52 - TDSD: \Drivers32\"msacm.ac3filter"="ac3filter64.acm" . (...) -- C:\Windows\System32\ac3filter64.acm
~ TDSD: 3 Legitimates Filtered in 00mn 00s
---\\ Microsoft Windows Policies System (O55)
O55 - MWPS:[HKLM\...\Policies\System] - "FilterAdministratorToken"=0
O55 - MWPS:[HKLM\...\Policies\System] - "EnableUIADesktopToggle"=0
~ MWPS: 20 Legitimates Filtered in 00mn 00s
---\\ Microsoft Windows Policies Explorer (O56)
O56 - MWPE:[HKCU\...\policies\Explorer] - "NoLogoff"=0
O56 - MWPE:[HKCU\...\policies\Explorer] - "NoClose"=0
~ MWPE Keys: 6 Legitimates Filtered in 00mn 00s
---\\ Liste des Drivers Système (O58)
O58 - SDL:[MD5.F14215E37CF124104575073F782111D2] - 21/01/2008 - 03:46:53 ---A- . (.Adaptec, Inc. - Adaptec Windows SAS/SATA Storport Driver.) -- C:\Windows\System32\Drivers\adp94xx.sys [486456]
O58 - SDL:[MD5.ACD35A46247CC066E24AD1E97183151B] - 11/11/2003 - 09:44:00 ---A- . (.Creative Technology Ltd - Creative DVD-Audio Device Driver (WDM).) -- C:\Windows\SysWOW64\drivers\ctdvda2k.sys [333600]
O58 - SDL:[MD5.12583AF6CBE0050651EAF2723B3AD7B3] - 18/03/2011 - 17:08:56 ---A- . (.Almico Software - SpeedFan x64 Driver.) -- C:\Windows\SysWOW64\speedfan.sys [29592]
~ Drivers: Scanned in 00mn 00s
---\\ Derniers fichiers modifiés ou crées (Utilisateur) (O61)
O61 - LFC: 02/07/2013 - 17:11:22 ---A- C:\Users\Mickael\AppData\Local\Google\firefox-toolbar.xml [171]
O61 - LFC: 02/07/2013 - 17:12:02 ---A- C:\Users\Mickael\Downloads\google-chrome_27-0-1453-116_fr_257658.exe [739856]
O61 - LFC: 02/07/2013 - 17:12:11 ---A- C:\Users\Mickael\AppData\Local\Google\Update\GoogleUpdate.exe [116648]
O61 - LFC: 02/07/2013 - 17:17:26 ---A- C:\Users\Mickael\AppData\Local\Google\Update\1.3.21.145\GoogleCrashHandler.exe [216968]
O61 - LFC: 02/07/2013 - 17:17:26 ---A- C:\Users\Mickael\AppData\Local\Google\Update\1.3.21.145\GoogleCrashHandler64.exe [287624]
O61 - LFC: 02/07/2013 - 17:17:26 ---A- C:\Users\Mickael\AppData\Local\Google\Update\1.3.21.145\GoogleUpdate.exe [116648]
O61 - LFC: 02/07/2013 - 17:17:26 ---A- C:\Users\Mickael\AppData\Local\Google\Update\1.3.21.145\GoogleUpdateBroker.exe [59784]
O61 - LFC: 02/07/2013 - 17:17:26 ---A- C:\Users\Mickael\AppData\Local\Google\Update\1.3.21.145\GoogleUpdateOnDemand.exe [59784]
O61 - LFC: 02/07/2013 - 17:17:26 ---A- C:\Users\Mickael\AppData\Local\Google\Update\1.3.21.145\goopdate.dll [848776]
O61 - LFC: 02/07/2013 - 17:17:26 ---A- C:\Users\Mickael\AppData\Local\Google\Update\1.3.21.145\goopdateres_am.dll [25480]
O61 - LFC: 02/07/2013 - 17:17:26 ---A- C:\Users\Mickael\AppData\Local\Google\Update\1.3.21.145\goopdateres_ar.dll [27016]
O61 - LFC: 02/07/2013 - 17:17:26 ---A- C:\Users\Mickael\AppData\Local\Google\Update\1.3.21.145\goopdateres_bg.dll [30600]
O61 - LFC: 02/07/2013 - 17:17:26 ---A- C:\Users\Mickael\AppData\Local\Google\Update\1.3.21.145\goopdateres_bn.dll [29064]
O61 - LFC: 02/07/2013 - 17:17:26 ---A- C:\Users\Mickael\AppData\Local\Google\Update\1.3.21.145\goopdateres_ca.dll [30088]
O61 - LFC: 02/07/2013 - 17:17:26 ---A- C:\Users\Mickael\AppData\Local\Google\Update\1.3.21.145\goopdateres_cs.dll [29064]
O61 - LFC: 02/07/2013 - 17:17:26 ---A- C:\Users\Mickael\AppData\Local\Google\Update\1.3.21.145\goopdateres_da.dll [29576]
O61 - LFC: 02/07/2013 - 17:17:26 ---A- C:\Users\Mickael\AppData\Local\Google\Update\1.3.21.145\goopdateres_de.dll [31624]
O61 - LFC: 02/07/2013 - 17:17:26 ---A- C:\Users\Mickael\AppData\Local\Google\Update\1.3.21.145\goopdateres_el.dll [31112]
O61 - LFC: 02/07/2013 - 17:17:26 ---A- C:\Users\Mickael\AppData\Local\Google\Update\1.3.21.145\goopdateres_en-GB.dll [28552]
O61 - LFC: 02/07/2013 - 17:17:26 ---A- C:\Users\Mickael\AppData\Local\Google\Update\1.3.21.145\goopdateres_en.dll [28040]
O61 - LFC: 02/07/2013 - 17:17:26 ---A- C:\Users\Mickael\AppData\Local\Google\Update\1.3.21.145\goopdateres_es-419.dll [29576]
O61 - LFC: 02/07/2013 - 17:17:26 ---A- C:\Users\Mickael\AppData\Local\Google\Update\1.3.21.145\goopdateres_es.dll [31624]
O61 - LFC: 02/07/2013 - 17:17:26 ---A- C:\Users\Mickael\AppData\Local\Google\Update\1.3.21.145\goopdateres_et.dll [28552]
O61 - LFC: 02/07/2013 - 17:17:26 ---A- C:\Users\Mickael\AppData\Local\Google\Update\1.3.21.145\goopdateres_fa.dll [28040]
O61 - LFC: 02/07/2013 - 17:17:26 ---A- C:\Users\Mickael\AppData\Local\Google\Update\1.3.21.145\npGoogleUpdate3.dll [585608]
O61 - LFC: 02/07/2013 - 17:17:26 ---A- C:\Users\Mickael\AppData\Local\Google\Update\1.3.21.145\psmachine.dll [162184]
O61 - LFC: 02/07/2013 - 17:17:26 ---A- C:\Users\Mickael\AppData\Local\Google\Update\1.3.21.145\psuser.dll [162184]
O61 - LFC: 02/07/2013 - 17:17:27 ---A- C:\Users\Mickael\AppData\Local\Google\Update\1.3.21.145\goopdateres_fi.dll [29576]
O61 - LFC: 02/07/2013 - 17:17:27 ---A- C:\Users\Mickael\AppData\Local\Google\Update\1.3.21.145\goopdateres_fil.dll [30600]
O61 - LFC: 02/07/2013 - 17:17:27 ---A- C:\Users\Mickael\AppData\Local\Google\Update\1.3.21.145\goopdateres_fr.dll [31112]
O61 - LFC: 02/07/2013 - 17:17:27 ---A- C:\Users\Mickael\AppData\Local\Google\Update\1.3.21.145\goopdateres_gu.dll [29064]
O61 - LFC: 02/07/2013 - 17:17:27 ---A- C:\Users\Mickael\AppData\Local\Google\Update\1.3.21.145\goopdateres_hi.dll [29576]
O61 - LFC: 02/07/2013 - 17:17:27 ---A- C:\Users\Mickael\AppData\Local\Google\Update\1.3.21.145\goopdateres_hr.dll [30088]
O61 - LFC: 02/07/2013 - 17:17:27 ---A- C:\Users\Mickael\AppData\Local\Google\Update\1.3.21.145\goopdateres_hu.dll [30088]
O61 - LFC: 02/07/2013 - 17:17:27 ---A- C:\Users\Mickael\AppData\Local\Google\Update\1.3.21.145\goopdateres_id.dll [28552]
O61 - LFC: 02/07/2013 - 17:17:27 ---A- C:\Users\Mickael\AppData\Local\Google\Update\1.3.21.145\goopdateres_is.dll [29064]
O61 - LFC: 02/07/2013 - 17:17:27 ---A- C:\Users\Mickael\AppData\Local\Google\Update\1.3.21.145\goopdateres_it.dll [31112]
O61 - LFC: 02/07/2013 - 17:17:27 ---A- C:\Users\Mickael\AppData\Local\Google\Update\1.3.21.145\goopdateres_iw.dll [26504]
O61 - LFC: 02/07/2013 - 17:17:27 ---A- C:\Users\Mickael\AppData\Local\Google\Update\1.3.21.145\goopdateres_ja.dll [24968]
O61 - LFC: 02/07/2013 - 17:17:27 ---A- C:\Users\Mickael\AppData\Local\Google\Update\1.3.21.145\goopdateres_kn.dll [30088]
O61 - LFC: 02/07/2013 - 17:17:27 ---A- C:\Users\Mickael\AppData\Local\Google\Update\1.3.21.145\goopdateres_ko.dll [23944]
O61 - LFC: 02/07/2013 - 17:17:27 ---A- C:\Users\Mickael\AppData\Local\Google\Update\1.3.21.145\goopdateres_lt.dll [28552]
O61 - LFC: 02/07/2013 - 17:17:27 ---A- C:\Users\Mickael\AppData\Local\Google\Update\1.3.21.145\goopdateres_lv.dll [30600]
O61 - LFC: 02/07/2013 - 17:17:27 ---A- C:\Users\Mickael\AppData\Local\Google\Update\1.3.21.145\goopdateres_ml.dll [32136]
O61 - LFC: 02/07/2013 - 17:17:27 ---A- C:\Users\Mickael\AppData\Local\Google\Update\1.3.21.145\goopdateres_mr.dll [29064]
O61 - LFC: 02/07/2013 - 17:17:27 ---A- C:\Users\Mickael\AppData\Local\Google\Update\1.3.21.145\goopdateres_ms.dll [28552]
O61 - LFC: 02/07/2013 - 17:17:27 ---A- C:\Users\Mickael\AppData\Local\Google\Update\1.3.21.145\goopdateres_nl.dll [30600]
O61 - LFC: 02/07/2013 - 17:17:27 ---A- C:\Users\Mickael\AppData\Local\Google\Update\1.3.21.145\goopdateres_no.dll [29576]
O61 - LFC: 02/07/2013 - 17:17:27 ---A- C:\Users\Mickael\AppData\Local\Google\Update\1.3.21.145\goopdateres_pl.dll [30600]
O61 - LFC: 02/07/2013 - 17:17:27 ---A- C:\Users\Mickael\AppData\Local\Google\Update\1.3.21.145\goopdateres_pt-BR.dll [29576]
O61 - LFC: 02/07/2013 - 17:17:27 ---A- C:\Users\Mickael\AppData\Local\Google\Update\1.3.21.145\goopdateres_pt-PT.dll [29576]
O61 - LFC: 02/07/2013 - 17:17:27 ---A- C:\Users\Mickael\AppData\Local\Google\Update\1.3.21.145\goopdateres_ro.dll [30088]
O61 - LFC: 02/07/2013 - 17:17:27 ---A- C:\Users\Mickael\AppData\Local\Google\Update\1.3.21.145\goopdateres_ru.dll [29064]
O61 - LFC: 02/07/2013 - 17:17:27 ---A- C:\Users\Mickael\AppData\Local\Google\Update\1.3.21.145\goopdateres_sk.dll [30088]
O61 - LFC: 02/07/2013 - 17:17:27 ---A- C:\Users\Mickael\AppData\Local\Google\Update\1.3.21.145\goopdateres_sl.dll [30088]
O61 - LFC: 02/07/2013 - 17:17:27 ---A- C:\Users\Mickael\AppData\Local\Google\Update\1.3.21.145\goopdateres_sr.dll [29576]
O61 - LFC: 02/07/2013 - 17:17:27 ---A- C:\Users\Mickael\AppData\Local\Google\Update\1.3.21.145\goopdateres_sv.dll [29576]
O61 - LFC: 02/07/2013 - 17:17:27 ---A- C:\Users\Mickael\AppData\Local\Google\Update\1.3.21.145\goopdateres_sw.dll [29576]
O61 - LFC: 02/07/2013 - 17:17:27 ---A- C:\Users\Mickael\AppData\Local\Google\Update\1.3.21.145\goopdateres_ta.dll [30600]
O61 - LFC: 02/07/2013 - 17:17:27 ---A- C:\Users\Mickael\AppData\Local\Google\Update\1.3.21.145\goopdateres_te.dll [29576]
O61 - LFC: 02/07/2013 - 17:17:27 ---A- C:\Users\Mickael\AppData\Local\Google\Update\1.3.21.145\goopdateres_th.dll [28040]
O61 - LFC: 02/07/2013 - 17:17:27 ---A- C:\Users\Mickael\AppData\Local\Google\Update\1.3.21.145\goopdateres_tr.dll [29576]
O61 - LFC: 02/07/2013 - 17:17:27 ---A- C:\Users\Mickael\AppData\Local\Google\Update\1.3.21.145\goopdateres_uk.dll [29064]
O61 - LFC: 02/07/2013 - 17:17:27 ---A- C:\Users\Mickael\AppData\Local\Google\Update\1.3.21.145\goopdateres_ur.dll [29064]
O61 - LFC: 02/07/2013 - 17:17:27 ---A- C:\Users\Mickael\AppData\Local\Google\Update\1.3.21.145\goopdateres_vi.dll [28552]
O61 - LFC: 02/07/2013 - 17:17:27 ---A- C:\Users\Mickael\AppData\Local\Google\Update\1.3.21.145\goopdateres_zh-CN.dll [22408]
O61 - LFC: 02/07/2013 - 17:17:27 ---A- C:\Users\Mickael\AppData\Local\Google\Update\1.3.21.145\goopdateres_zh-TW.dll [22408]
O61 - LFC: 02/07/2013 - 17:18:20 ---A- C:\Users\Mickael\Downloads\VLCMediaPlayerSetup-8T1Anmw.exe [167544]
O61 - LFC: 03/07/2013 - 16:39:26 ---A- C:\Users\Mickael\Downloads\adwcleaner (1).exe [650027]
O61 - LFC: 03/07/2013 - 16:39:45 ---A- C:\Users\Mickael\Downloads\adwcleaner (2).exe [650027]
O61 - LFC: 03/07/2013 - 17:29:53 ---A- C:\Users\Mickael\Downloads\mbam-setup-1.75.0.1300.exe [10285040]
O61 - LFC: 04/07/2013 - 16:04:28 ---A- C:\Users\Mickael\AppData\Local\Google\Chrome\User Data\Certificate Revocation Lists [266225]
O61 - LFC: 04/07/2013 - 16:14:27 ---A- C:\Users\Mickael\AppData\Local\Google\Chrome\User Data\Local State [37899]
O61 - LFC: 04/07/2013 - 16:14:27 ---A- C:\Users\Mickael\AppData\Local\Google\Chrome\User Data\chrome_shutdown_ms.txt [4]
~ 17 Fichiers temporaires (Temporary files)
~ Files: 660 Legitimates Filtered in 00mn 16s
---\\ Liste des outils de nettoyage (O63)
O63 - Logiciel: ZHPDiag 2013 - (.Nicolas Coolman.) [HKLM] -- ZHPDiag_is1
~ ADS: Scanned in 00mn 00s
---\\ Liste des services Legacy (O64)
O64 - Services: CurCS - ??\??\???? - Pas de propriétaire (SRTSP) .(...) - LEGACY_SRTSP
O64 - Services: CurCS - ??\??\???? - Pas de propriétaire (SRTSPX) .(...) - LEGACY_SRTSPX
~ Legacy: 71 Legitimates Filtered in 00mn 24s
---\\ Start Menu Internet (O68)
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
~ Keys: Scanned in 00mn 00s
---\\ Search Browser Infection (O69)
O69 - SBI: prefs.js [Mickael - qhs3gljn.default] user_pref("extensions.crossrider.bic", "13fa02618ea020fb198df263c16676cb"); =PUP.CrossRider
O69 - SBI: prefs.js [Mickael - qhs3gljn.default] user_pref("extensions.helperbar.DockingPositionDown", false);
O69 - SBI: prefs.js [Mickael - qhs3gljn.default] user_pref("extensions.helperbar.Visibility", false);
O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} - (Bing) -
http://www.bing.com
O69 - SBI: SearchScopes [HKCU] {BAFC0267-B29F-4420-A651-45FB83A5C15C} - (Ask Search) -
http://websearch.ask.com
~ Keys: Scanned in 00mn 00s
---\\ Crack Keygen Files (O82)
C:\Users\Mickael\Documents\Petits Logiciel\PhotoFiltre Studio Full 9.2.2 keygen Share Accelerator.zip
C:\Users\Mickael\Documents\Petits Logiciel\Photofiltre Studio v9.0.0 Fr Crack (Keygen) By Seven.zip
C:\Users\Mickael\Documents\Petits Logiciel\Reallusion Crazy Talk PRO v6.0 +bonus-Hedy80\BONUS\Facial Expression Clips Vol.1\CT_Effect_FacialExpressionClipsV1(cracked).rar
C:\Users\Mickael\Documents\Petits Logiciel\Reallusion Crazy Talk PRO v6.0 +bonus-Hedy80\BONUS\Facial Expression Clips Vol.2\CT_Effect_FacialExpressionClipsVo2(cracked).rar
C:\Users\Mickael\Documents\Petits Logiciel\Win Dvd7 Platinium Keygen.rar
C:\Users\Mickael\Documents\Petits Logiciel\windvd7 platinium+keygen\WinDVD7.exe
C:\Users\Mickael\Documents\Petits Logiciel\windvd7 platinium+keygen\windvd7kgn.rar
C:\Users\Mickael\Documents\Petits Logiciel\PhotoFiltre Studio Full 9.2.2 keygen Share Accelerator.zip
C:\Users\Mickael\Documents\Petits Logiciel\Photofiltre Studio v9.0.0 Fr Crack (Keygen) By Seven.zip
C:\Users\Mickael\Documents\Petits Logiciel\Reallusion Crazy Talk PRO v6.0 +bonus-Hedy80\BONUS\Facial Expression Clips Vol.1\CT_Effect_FacialExpressionClipsV1(cracked).rar
C:\Users\Mickael\Documents\Petits Logiciel\Reallusion Crazy Talk PRO v6.0 +bonus-Hedy80\BONUS\Facial Expression Clips Vol.2\CT_Effect_FacialExpressionClipsVo2(cracked).rar
C:\Users\Mickael\Documents\Petits Logiciel\Win Dvd7 Platinium Keygen.rar
C:\Users\Mickael\Documents\Petits Logiciel\windvd7 platinium+keygen\WinDVD7.exe
C:\Users\Mickael\Documents\Petits Logiciel\windvd7 platinium+keygen\windvd7kgn.rar
D:\InterVideo.WinDVD.Platinum.6.0.6.42.ITA.+.KEYGEN.by.PEPPE.rar
D:\Jeux DS OK\Jeux DS pas essayer\[NDS]Michael Jackson-The Experience[CRACKED][M5].rar
D:\Les sims 2\(Jeu Pc) - Les Sims 2 Au Fil Des Saisons (Keygen Crack) Fr.zip
D:\Les sims 2\(Jeu PC) - Les Sims 2 Quartier libre (Keygen + Crack) Fr.zip
D:\Les sims 2\Les Sims 2 Quartier Libre keygen.exe
L:\Clé Office 2010\(Incl Keygen) Microsoft Office 2010 Crack Serial.exe
~ Files: Scanned in 01mn 27s
---\\ Recherche particuliere à la racine de certains dossiers (O84)
[MD5.002791CEF3A8E81EEE80F38D59DDA57E] [SPRF][10/12/2011] (...) -- C:\Users\Mickael\AppData\Local\d3d9caps.dat [680]
[MD5.E8F591D698233F0D06EFC291A2840D26] [SPRF][02/07/2013] (.SweetIM Technologies Ltd. - SweetIM Installer by SweetPacks.) -- C:\Users\Mickael\AppData\Local\Temp\bundlesweetimsetup.exe [7464720] =PUP.SweetIM
[MD5.CBEA94357CF0600E9096A1AD20C4F48A] [SPRF][02/07/2013] (.TODO: - TODO: .) -- C:\Users\Mickael\AppData\Local\Temp\GenericUninstall.exe [123904]
[MD5.8A4AF3B0695F29186AD02E2FD766FA3B] [SPRF][02/07/2013] (.SweetIM Technologies Ltd. - SQLite DLL.) -- C:\Users\Mickael\AppData\Local\Temp\mgsqlite3.dll [393016] =PUP.SweetIM
[MD5.E990FC354E1A08AC8C7B544FB1A32ABA] [SPRF][02/07/2013] (.TODO: - TODO: .) -- C:\Users\Mickael\AppData\Local\Temp\uninstaller.exe [376832]
[MD5.83087F025194693DFF3A0F22E6A4AE96] [SPRF][02/07/2013] (.Somoto Ltd. - FilesFrog Update Checker.) -- C:\Users\Mickael\AppData\Local\Temp\UpdateCheckerSetup.exe [196376] =Adware.MegaSearch
[MD5.69D2894206516657B7A06EEEA5B917E5] [SPRF][02/07/2013] (...) -- C:\Users\Mickael\AppData\Local\Temp\vlc-2.0.2-win32.exe [22630361]
[MD5.C79EF333384F37CDEB10C1BC57326F0D] [SPRF][02/07/2013] (...) -- C:\Users\Mickael\AppData\Local\Temp\WSSetup.exe [3243944]
[MD5.55B47223BCA8056BA5E91CBFF0928BDB] [SPRF][15/03/2013] (...) -- C:\Users\Mickael\AppData\Roaming\wklnhst.dat [224]
[MD5.812B893CE1F1EA87C98EE9499D2B7645] [SPRF][24/05/2013] (.NVIDIA Corporation - NVIDIA Package Launcher.) -- C:\Users\Mickael\Desktop\320.18-desktop-win8-win7-winvista-64bit-international-whql.exe [228075456]
[MD5.3FEA9D2EDF23B0283C7A66C8DEA380BD] [SPRF][25/07/2002] (.InstallShield Software Corporation - InstallShield Update Service Setup Player Module.) -- C:\Windows\Downloaded Program Files\dwusplay.dll [24576]
[MD5.CDBE35EA59BC9223E4F800BD1DB82D27] [SPRF][25/07/2002] (.InstallShield Software Corporation - InstallShield Update Service Setup Player.) -- C:\Windows\Downloaded Program Files\dwusplay.exe [196608]
[MD5.0C78701C6F42345DFF2B2B6C3C3D01EF] [SPRF][25/07/2002] (.InstallShield Software Corporation - InstallShield Update Service Web Agent.) -- C:\Windows\Downloaded Program Files\isusweb.dll [172032]
~ Files: Scanned in 00mn 16s
---\\ Firewall Active Exception List (FirewallRules) (O87)
O87 - FAEL: "{F239C736-E98E-41CF-893A-1498DE2D92BF}" |In - Private - P6 - TRUE | .(...) -- C:\Program Files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\dtUser.exe (.not file.) =PUP.Datamngr
O87 - FAEL: "{4A944A4D-2A84-4D90-88D8-C5F562054457}" |In - Private - P17 - TRUE | .(...) -- C:\Program Files (x86)\Windows Searchqu Toolbar\Datamngr\ToolBar\dtUser.exe (.not file.) =PUP.Datamngr
O87 - FAEL: "TCP Query User{41AC4A90-B1C1-4768-B5B2-E3DDF0EEE1DB}C:\program files (x86)\radionomy\radiomanager\radiomanager.exe" | In - Private - P6 - TRUE | .(.Radionomy s.a..) -- C:\program files (x86)\radionomy\radiomanager\radiomanager.exe
O87 - FAEL: "UDP Query User{0DE233AD-6283-43D2-AECB-EE7D7AC54123}C:\program files (x86)\radionomy\radiomanager\radiomanager.exe" | In - Private - P17 - TRUE | .(.Radionomy s.a..) -- C:\program files (x86)\radionomy\radiomanager\radiomanager.exe
O87 - FAEL: "{232C044B-B972-4D98-8F94-CEF8A3A5635A}" | In - Domain - P6 - TRUE | .(.Affinegy, Inc. - Belkin Setup / Router Monitor Application.) -- C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinSetup.exe
O87 - FAEL: "{91EE7A33-23A0-47EA-8F95-A00E09445BEA}" | In - Domain - P17 - TRUE | .(.Affinegy, Inc. - Belkin Setup / Router Monitor Application.) -- C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinSetup.exe
O87 - FAEL: "{A5F12003-E575-43F1-BE1A-1B0BF22864B4}" | In - Private - P6 - TRUE | .(.Affinegy, Inc. - Belkin Setup / Router Monitor Application.) -- C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinSetup.exe
O87 - FAEL: "{B4EB5391-6D5B-4932-9F8F-C61E06700EDF}" | In - Private - P17 - TRUE | .(.Affinegy, Inc. - Belkin Setup / Router Monitor Application.) -- C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinSetup.exe
O87 - FAEL: "{05DD30E4-3841-445E-BF24-A17AECD6EBD8}" | In - None - P17 - TRUE | .(.Affinegy, Inc. - Belkin Setup / Router Monitor Application.) -- C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinSetup.exe
O87 - FAEL: "TCP Query User{32DD7101-1ACD-42A9-B93E-4C39F2933581}C:\program files (x86)\gigatribe\gigatribe.exe" |In - Public - P6 - TRUE | .(...) -- C:\program files (x86)\gigatribe\gigatribe.exe (.not file.)
O87 - FAEL: "UDP Query User{F5297904-69AF-43A9-8472-EA763E2B9364}C:\program files (x86)\gigatribe\gigatribe.exe" |In - Public - P17 - TRUE | .(...) -- C:\program files (x86)\gigatribe\gigatribe.exe (.not file.)
O87 - FAEL: "{672A6C0A-EB6A-43B2-B0E1-5D844AA241BF}" |In - Private - P6 - TRUE | .(...) -- C:\Program Files (x86)\GigaTribe\gigatribe.exe (.not file.)
O87 - FAEL: "{5B1C04FE-E0CA-4A0C-B1B2-1F785886C334}" |In - Private - P17 - TRUE | .(...) -- C:\Program Files (x86)\GigaTribe\gigatribe.exe (.not file.)
O87 - FAEL: "{45D65925-7946-4B86-8A9F-5EF61B0657B8}" | In - Private - P6 - TRUE | .(.ActaLogic - auto update.) -- C:\Program Files (x86)\Woodcutter Simulator 2011\iupdate.dll
O87 - FAEL: "{F4426F6C-5CFE-47BA-9896-B2FF345192F3}" | In - Private - P17 - TRUE | .(.ActaLogic - auto update.) -- C:\Program Files (x86)\Woodcutter Simulator 2011\iupdate.dll
O87 - FAEL: "{68614C0E-71CC-41CE-A527-5066834AB805}" | In - Private - P6 - TRUE | .(.ActaLogic - Woodcutter Simulator 2011.) -- C:\Program Files (x86)\Woodcutter Simulator 2011\woodcutter2011.dll
O87 - FAEL: "{D8BF414A-CB59-470E-BA8F-45D069F4B80E}" | In - Private - P17 - TRUE | .(.ActaLogic - Woodcutter Simulator 2011.) -- C:\Program Files (x86)\Woodcutter Simulator 2011\woodcutter2011.dll
O87 - FAEL: "{6BBE2453-8F9D-45AF-AA2C-C8FADE865931}" | In - Private - P6 - TRUE | .(...) -- C:\Windows\System32\dmwu.exe
O87 - FAEL: "{99AF1206-ECF6-4D14-A77E-F9AAACFCB819}" | In - Private - P17 - TRUE | .(...) -- C:\Windows\System32\dmwu.exe
O87 - FAEL: "{B82F6FC8-8FE8-40A8-8732-1D886DFEA856}" | In - Public - P6 - TRUE | .(...) -- C:\Windows\System32\dmwu.exe
O87 - FAEL: "{4350E106-A7C7-43D1-A76F-CA1B72877BB9}" | In - Public - P17 - TRUE | .(...) -- C:\Windows\System32\dmwu.exe
~ Firewall: 254 Legitimates Filtered in 00mn 01s
---\\ Scan Additionnel (O88)
Database Version : v2.12631 - (01/07/2013)
Clés trouvées (Keys found) : 21
Valeurs trouvées (Values found) : 0
Dossiers trouvés (Folders found) : 1
Fichiers trouvés (Files found) : 7
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0F6E720A-1A6B-40E1-A294-1D4D19F156C8}] =Toolbar.Agent
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{0F6E720A-1A6B-40E1-A294-1D4D19F156C8}] =Toolbar.Agent
[HKLM\Software\Classes\CLSID\{0F6E720A-1A6B-40E1-A294-1D4D19F156C8}] =Toolbar.Agent
[HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0F6E720A-1A6B-40E1-A294-1D4D19F156C8}] =Toolbar.Agent
[HKLM\Software\Classes\CLSID\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}] =Toolbar.Skype
[HKLM\Software\Microsoft\Internet Explorer\extensions\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}] =Toolbar.Skype
[HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\extensions\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}] =Toolbar.Skype
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}] =Toolbar.Skype
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}] =Toolbar.Skype
[HKLM\Software\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}] =Toolbar.Skype
[HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}] =Toolbar.Skype
[HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}] =Toolbar.Skype
[HKLM\Software\Classes\Installer\Features\90C64EA18BA25EE488BF80DCF07F2FFD] =Toolbar.Agent
[HKLM\Software\Classes\Installer\Products\90C64EA18BA25EE488BF80DCF07F2FFD] =Toolbar.Agent
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\90C64EA18BA25EE488BF80DCF07F2FFD] =Toolbar.Agent
[HKCU\Software\BlabbersToolbar] =PUP.Blabbers
[HKCU\Software\SweetIM] =PUP.SweetIM
[HKLM\Software\Wow6432Node\SweetIM] =PUP.SweetIM
[HKLM\Software\WNLT] =Adware.IncrediBar
[HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{1AE46C09-2AB8-4EE5-88FB-08CD0FF7F2DF}] =Toolbar.Agent
[HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\daemon tools toolbar] =Toolbar.Agent
C:\Program Files (x86)\XingHaoLyrics =Adware.ShopperReports
C:\Users\Mickael\AppData\Local\Temp\bundlesweetimsetup.exe =PUP.SweetIM
C:\Users\Mickael\AppData\Local\Temp\GoogleToolbarInstaller1.log =Toolbar.Babylon
C:\Users\Mickael\AppData\Local\Temp\mgsqlite3.dll =PUP.SweetIM
C:\Users\Mickael\AppData\Local\Temp\UpdateCheckerSetup.exe =Adware.MegaSearch
~ Additionnel Scan: 446791 Items scanned in 00mn 24s
---\\ Product Upgrade Codes (O90)
O90 - PUC: "90C64EA18BA25EE488BF80DCF07F2FFD" . (.Bing Bar.) -- C:\Windows\Installer\{1AE46C09-2AB8-4EE5-88FB-08CD0FF7F2DF}\icon_installer_ico
~ Update Products: 200 Legitimates Filtered in 00mn 00s
---\\ Etat général des services non Microsoft (EGS) (SR=Running, SS=Stopped)
SS - | Auto 124832 | (AdobeActiveFileMonitor6.0) . (...) - C:\Program Files (x86)\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
SS - | Auto 11/05/2013 65640 | (AdobeARMservice) . (.Adobe Systems Incorporated.) - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
SS - | Demand 20/06/2013 256904 | (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
SS - | Auto 14/09/2010 571288 | (AffinegyService) . (.Affinegy, Inc..) - C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinService.exe
SS - | Auto 21/12/2012 57008 | (Apple Mobile Device) . (.Apple Inc..) - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
SS - | Auto 11/06/2012 193616 | (BBSvc) . (.Microsoft Corporation..) - C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BBSvc.exe
SS - | Demand 11/06/2012 240208 | (BBUpdate) . (.Microsoft Corporation..) - C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\SeaPort.exe
SS - | Auto 30/08/2011 462184 | (Bonjour Service) . (.Apple Inc..) - C:\Program Files\Bonjour\mDNSResponder.exe
SS - | Auto 21/01/2008 27648 | C:\Windows\System32\ezsvc7.dll (ezSharedSvc) . (.EasyBits Sofware AS.) - C:\Windows\System32\svchost.exe
SS - | Demand 13/05/2009 654848 | (FLEXnet Licensing Service) . (.Macrovision Europe Ltd..) - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
SS - | Auto 29/05/2008 83264 | (GenericHidService) . (.Packard Bell Services.) - C:\Windows\System32\HidService.exe
SS - | Auto 09/08/2011 135664 | (gupdate) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
SS - | Demand 09/08/2011 135664 | (gupdatem) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
SS - | Auto 12/09/2008 354840 | (IAANTMON) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
SS - | Demand 31/05/2013 641352 | (iPod Service) . (.Apple Inc..) - C:\Program Files\iPod\bin\iPodService.exe
SS - | Demand 08/08/2011 311928 | (maconfservice) . (.CybelSoft.) - C:\Program Files (x86)\ma-config.com\maconfservice.exe
SS - | Demand 05/02/2013 235216 | (McComponentHostService) . (.McAfee, Inc..) - C:\Program Files (x86)\McAfee Security Scan\3.0.318\McCHSvc.exe
SS - | Demand 17/11/2012 115168 | (MozillaMaintenance) . (.Mozilla Foundation.) - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
SS - | Auto 07/05/2013 128000 | (MsgPlusService) . (.Yuna Software.) - C:\Program Files (x86)\Yuna Software\Messenger Plus! for Skype\MsgPlusForSkypeService.exe
SS - | Auto 03/12/2007 869672 | (Nero BackItUp Scheduler 3) . (.Nero AG.) - C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBService.exe
SS - | Auto 24/09/2008 935208 | (Nero BackItUp Scheduler 4.0) . (.Nero AG.) - C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
SS - | Demand 13/12/2007 447784 | (NMIndexingService) . (.Nero AG.) - C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexingService.exe
SS - | Auto 0 | (Norton Internet Security) . (...) - C:\Program Files (x86)\Norton Internet Security\Engine\16.0.0.125\ccSvcHst.exe
SS - | Auto 21/06/2013 884512 | (nvsvc) . (.NVIDIA Corporation.) - C:\Windows\system32\nvvsvc.exe
SS - | Auto 16/05/2013 1826592 | (nvUpdatusService) . (.NVIDIA Corporation.) - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
SS - | Auto 02/10/2012 3064000 | (Skype C2C Service) . (.Skype Technologies S.A..) - C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
SS - | Auto 03/06/2013 162408 | (SkypeUpdate) . (.Skype Technologies.) - C:\Program Files (x86)\Skype\Updater\Updater.exe
SS - | Auto 21/01/2008 27648 | C:\Program Files (x86)\Windows Defender\mpsvc.dll (WinDefend) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe
SS - | Auto 0 | (WMPNetworkSvc) . (...) - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe
SS - | Auto 21/01/2008 27648 | C:\Windows\System32\wuaueng.dll (wuauserv) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe
SS - | Auto 30/03/2009 146928 | ({B154377D-700F-42cc-9474-23858FBDF4BD}) . (.CyberLink Corp..) - C:\Program Files (x86)\CyberLink\PowerDVD9\000.fcl
~ Services: Scanned in 00mn 01s
---\\ Recherche Master Boot Record Infection (MBR)(O80)
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer,
http://www.gmer.net
Run by Mickael at 04/07/2013 17:30:17
device: opened successfully
user: error reading MBR
Disk trace:
error: Read Descripteur non valide
kernel: error reading MBR
~ MBR: 9 Legitimates Filtered in 00mn 02s
---\\ Recherche Master Boot Record Infection (MBRCheck)(O80)
Written by ad13,
http://ad13.geekstog
Run by Mickael at 04/07/2013 17:30:19
********* Dump file Name *********
C:\PhysicalDisk0_MBR.bin
~ MBR: Scanned in 00mn 04s
---\\ Malicius Software Information
~
http://nicolascoolman.webs.com/apps/blo ... are-plushd =Adware.PlusHD
~
http://nicolascoolman.webs.com/apps/blo ... r-smartbar =Hijacker.SmartBar
~
http://nicolascoolman.webs.com/apps/blo ... p-blabbers =PUP.Blabbers
~
http://nicolascoolman.webs.com/apps/blo ... up-sweetim =PUP.SweetIM
~
http://nicolascoolman.webs.com/apps/blo ... searchcore =Adware.SearchCore
~
http://nicolascoolman.webs.com/apps/blo ... incredibar =Adware.Incredibar
~
http://nicolascoolman.webs.com/apps/blo ... crossrider =PUP.CrossRider
~
http://nicolascoolman.webs.com/apps/blo ... megasearch =Adware.MegaSearch
~
http://nicolascoolman.webs.com/apps/blo ... p-datamngr =PUP.Datamngr
~
http://nicolascoolman.webs.com/apps/blo ... ar-babylon =Toolbar.Babylon
~ MSI: 10 link(s) detected in 00mn 04s
~ 2977 Legitimates filtered by white list
End of the scan (744 lines in 06mn 11s)(20)