Bonsoir,
Je te poste comme prévu les différents résultats des opérations que tu m'as demandé de faire:
1- Rapport de Ad-remover: Ad-report-CLEAN.txt
2- Rapport MalwareBytes
3- rapport de zhpDiag
Encore merci pour ton aide précieuse
Bien cordialement
Gilles
1- Rapport de Ad-remover: Ad-report-CLEAN.txt
======= RAPPORT D'AD-REMOVER 2.0.0.2,G | UNIQUEMENT XP/VISTA/7 =======
Mis à jour par TeamXscript le 12/04/11
Contact: AdRemover[DOT]contact[AT]gmail[DOT]com
Site web:
http://www.sosvirus.net
C:\Program Files (x86)\Ad-Remover\main.exe (CLEAN [1]) - Lancé à 20:31:40 le 22/07/2013, Mode normal
Microsoft Windows 7 Édition Familiale Premium (X64)
Gilles@GILLES-PC (Acer Aspire 1830T)
============== ACTION(S) ==============
(!) -- Fichiers temporaires supprimés.
Clé supprimée: HKLM\Software\Classes\Interface\{05A83F00-1BEF-4750-A03C-C2060765DF43}
Clé supprimée: HKLM\Software\Classes\TypeLib\{3357BB1E-0DDB-4573-A010-811E8E11DAD7}
Clé supprimée: HKU\.DEFAULT\Software\Ask.com
Clé supprimée: HKU\.DEFAULT\Software\AskToolbar
============== SCAN ADDITIONNEL ==============
**** Mozilla Firefox Version [22.0 (fr)] ****
HKLM_MozillaPlugins\Adobe Reader (x)
HKCU_Extensions|{86D92CB0-3EB2-4979-AD43-DF0341807D7F} - C:\Program Files (x86)\Copernic Desktop Search - Home\FirefoxToolbar\
HKCU_Extensions|{96D26B34-35E1-4ed2-AB54-138830AC8268} - C:\Program Files (x86)\Cordial\Macros\Mozilla\correctionFirefox
-- C:\Users\Gilles\AppData\Roaming\Mozilla\FireFox\Profiles\ddyodmla.default --
Extensions\.BackupManager (?)
Extensions\
printPages2Pdf@reinhold.ripper (Print pages to PDF)
Extensions\
zotero@chnm.gmu.edu (Zotero)
Extensions\{E0B8C461-F8FB-49b4-8373-FE32E9252800} (Evernote Web Clipper)
Prefs.js - browser.search.defaulturl, hxxp://
www.bing.com/search?FORM=WLETDFPC=WLEMq=
Prefs.js - browser.startup.homepage, hxxp://
www.google.fr/
Prefs.js - browser.startup.homepage_override.buildID, 20130618035212
Prefs.js - browser.startup.homepage_override.mstone, 22.0
========================================
**** Internet Explorer Version [8.0.7600.16385] ****
HKCU_Main|Default_Page_URL - hxxp://
www.microsoft.com/isapi/redir.dll?prd=i ... ar=msnhome
HKCU_Main|Default_Search_URL - hxxp://
www.microsoft.com/isapi/redir.dll?prd=iear=iesearch
HKCU_Main|Search bar - hxxp://go.microsoft.com/fwlink/?linkid=54896
HKCU_Main|Start Page - hxxp://fr.msn.com/
HKLM_Main|Default_Page_URL - hxxp://go.microsoft.com/fwlink/?LinkId=54896
HKLM_Main|Default_Search_URL - hxxp://
www.microsoft.com/isapi/redir.dll?prd=iear=iesearch
HKLM_Main|Search bar - hxxp://search.msn.com/spbasic.htm
HKLM_Main|Search Page - hxxp://
www.microsoft.com/isapi/redir.dll?prd=iear=iesearch
HKLM_Main|Start Page - hxxp://fr.msn.com/
HKCU_SearchScopes\{483830EE-A4CD-4b71-B0A3-3D82E62A6909} - "?" (?)
HKCU_SearchScopes\{6BE66562-E53D-4F84-BDA9-B7DE7CFF65F3} - "Copernic" (hxxp://search.copernic.com/query21/?q={SearchTerms}c=webl=FRAe=CDS2cpn=b=30...)
HKCU_SearchScopes\{7821C050-1991-49AE-97DA-B82716DA0ED4} - "Search" (hxxp://start.funmoods.com/results.php?f=4a=downq={searchTerms})
HKCU_Toolbar\WebBrowser|{968631B6-4729-440D-9BF4-251F5593EC9A} (C:\Program Files (x86)\Copernic Desktop Search - Home\DesktopSearchBand300000074.dll)
HKCU_Toolbar\WebBrowser|{47833539-D0C5-4125-9FA8-0819E2EAAC93} (C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll)
HKLM_Toolbar|{968631B6-4729-440D-9BF4-251F5593EC9A} (C:\Program Files (x86)\Copernic Desktop Search - Home\DesktopSearchBand300000074.dll)
HKLM_Toolbar|{47833539-D0C5-4125-9FA8-0819E2EAAC93} (C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll)
HKCU_ElevationPolicy\{57C4642F-0237-4443-9E53-02E249C3AD5E} - C:\Program Files (x86)\Copernic Desktop Search - Home\DesktopSearch.exe (Copernic Inc.)
HKLM_ElevationPolicy\{07d873dc-b9b9-44f5-af0b-fb59fa54fb7a} - C:\Windows\SysWOW64\wpcer.exe (x)
HKLM_ElevationPolicy\{0a402d70-1f10-4ae7-bec9-286a98240695} - C:\Windows\SysWOW64\winfxdocobj.exe (x)
HKLM_ElevationPolicy\{70f641fd-9ffc-4d5b-a4dc-962af4ed7999} - C:\Program Files (x86)\Internet Explorer\iedw.exe (x)
HKLM_ElevationPolicy\{A6E2003F-95C5-4591-BA9A-0093080FDB5C} - C:\Program Files (x86)\Common Files\Oberon Media\OberonBroker\1.0.0.63\OberonBroker.exe (?)
HKLM_ElevationPolicy\{B43A0C1E-B63F-4691-B68F-CD807A45DA01} - C:\Windows\system32\TSWbPrxy.exe (x)
HKLM_Extensions\{CCA281CA-C863-46ef-9331-5C8D4460577F} - "Envoyer à Bluetooth" (C:\Program Files\WIDCOMM\Bluetooth Software\bt_cold_icon.ico)
========================================
C:\Program Files (x86)\Ad-Remover\Quarantine: 0 Fichier(s)
C:\Program Files (x86)\Ad-Remover\Backup: 16 Fichier(s)
C:\Ad-Report-CLEAN[1].txt - 22/07/2013 20:31:49 (4441 Octet(s))
C:\Ad-Report-SCAN[1].txt - 18/07/2013 23:15:21 (4626 Octet(s))
Fin à: 20:33:38, 22/07/2013
============== E.O.F ==============
2- Rapport MalwareBytes
Rapport Malwarebytes
Malwarebytes Anti-Malware 1.75.0.1300
http://www.malwarebytes.org
Version de la base de données: v2013.07.22.08
Windows 7 x64 NTFS
Internet Explorer 8.0.7600.16385
Gilles :: GILLES-PC [administrateur]
22/07/2013 23:08:47
mbam-log-2013-07-22 (23-08-47).txt
Type d'examen: Examen complet (C:\|D:\|E:\|F:\|G:\|)
Options d'examen activées: Mémoire | Démarrage | Registre | Système de fichiers | Heuristique/Extra | Heuristique/Shuriken | PUP | PUM
Options d'examen désactivées: P2P
Elément(s) analysé(s): 1532638
Temps écoulé: 16 heure(s), 38 minute(s), 57 seconde(s)
Processus mémoire détecté(s): 0
(Aucun élément nuisible détecté)
Module(s) mémoire détecté(s): 0
(Aucun élément nuisible détecté)
Clé(s) du Registre détectée(s): 0
(Aucun élément nuisible détecté)
Valeur(s) du Registre détectée(s): 0
(Aucun élément nuisible détecté)
Elément(s) de données du Registre détecté(s): 0
(Aucun élément nuisible détecté)
Dossier(s) détecté(s): 0
(Aucun élément nuisible détecté)
Fichier(s) détecté(s): 3
F:\$RECYCLE.BIN\S-1-5-21-978868575-3469318854-3647737991-1001\$RX8OLGR\cubase-4-1-0-en-win.exe (PUP.AdBundler) - Mis en quarantaine et supprimé avec succès.
F:\$RECYCLE.BIN\S-1-5-21-978868575-3469318854-3647737991-1001\$RX8OLGR\unlocker1.8.7.exe (Adware.Clicker) - Mis en quarantaine et supprimé avec succès.
F:\$RECYCLE.BIN\S-1-5-21-978868575-3469318854-3647737991-1001\$RX8OLGR\H4 recorder\cubase-4-1-0-en-win.exe (PUP.AdBundler) - Mis en quarantaine et supprimé avec succès.
(fin)
3- rapport de zhpDiag
Rapport de ZHPDiag v2013.7.22.36 par Nicolas Coolman, Update du 22/07/2013
Run by Gilles at 23/07/2013 21:29:10
WebSite:
http://nicolascoolman.webs.com
State : Version à jour.
WhiteList : Enable
High Elevated Privileges : OK
UAC : Deactivate by user
---\\ Web Browser
MSIE: Internet Explorer v8.0.7600.16385
MFIE: Mozilla Firefox 22.0 (Defaut)
GCIE: Google Chrome v28.0.1500.72
---\\ Windows Product Information
~ Langage: Français
Windows 7 Home Premium Edition, 64-bit (Build 7600)
Windows Server License Manager Script : OK
~ Windows(R) 7, OEM_SLP channel
System Locked Preinstallation (OEM_SLP) : OK
Windows ID Activation : OK
~ Windows Partial Key : 7QJB7
Windows License : OK
~ Windows Remaining Initializations Number : 1
Software Protection Service (Protection logicielle) : OK
Windows Automatic Updates : OK
Windows Activation Technologies : OK
---\\ System Protection
Avira Free Antivirus v13.0.0.3884
Malwarebytes Anti-Malware version 1.75.0.1300
Windows Defender W7
---\\ System Optimizer
CCleaner v3.17 =Piriform Ltd
---\\ Peer To Peer (P2P)
---\\ Software Update
Adobe Flash Player 11 Plugin
Adobe Reader X
---\\ System Information
~ Processor: Intel64 Family 6 Model 37 Stepping 5, GenuineIntel
~ Operating System: 64 Bits
Boot mode: Normal (Normal boot)
Total RAM: 3765 MB (63% free)
System Restore: Activé (Enable)
System drive C: has 61 GB (26%) free of 228 GB
---\\ Logged in mode
~ Computer Name: GILLES-PC
~ User Name: Gilles
~ All Users Names: HomeGroupUser$, Gilles, Administrateur,
~ Unselected Option: None
Logged in as Administrator
---\\ Environnement Variables
~ System Unit : C:\
~ %AppData% : C:\Users\Gilles\AppData\Roaming\
~ %Desktop% : C:\Users\Gilles\Desktop\
~ %Favorites% : C:\Users\Gilles\Favorites\
~ %LocalAppData% : C:\Users\Gilles\AppData\Local\
~ %StartMenu% : C:\Users\Gilles\AppData\Roaming\Microsoft\Windows\Start Menu\
~ %Windir% : C:\Windows\
~ %System% : C:\Windows\System32\
---\\ DOS/Devices
C:\ Hard drive, Flash drive, Thumb drive (Free 61 Go of 228 Go)
D:\ Hard drive, Flash drive, Thumb drive (Free 85 Go of 225 Go)
E:\ CD-ROM drive (Not Inserted)
F:\ Hard drive, Flash drive, Thumb drive (Free 54 Go of 466 Go)
G:\ Hard drive, Flash drive, Thumb drive (Free 786 Go of 1863 Go)
H:\ Floppy drive, Flash card reader, USB Key (Free 1 Go of 2 Go)
---\\ Security Center Tools Informations
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: Modified
~ Security Center: 35 Legitimates Filtered in 00mn 00s
---\\ Recherche particulière de fichiers génériques
[MD5.0862495E0C825893DB75EF44FAEA8E93] - (.Microsoft Corporation - Explorateur Windows.) (.26/02/2011 - 07:23:14.) -- C:\Windows\Explorer.exe [2870272]
[MD5.94355C28C1970635A31B3FE52EB7CEBA] - (.Microsoft Corporation - Application de démarrage de Windows.) (.14/07/2009 - 02:39:52.) -- C:\Windows\System32\Wininit.exe [129024]
[MD5.8523338F749AC8C5300C125BC4B08275] - (.Microsoft Corporation - Extensions Internet pour Win32.) (.02/03/2013 - 06:49:19.) -- C:\Windows\System32\wininet.dll [1198080]
[MD5.DA3E2A6FA9660CC75B471530CE88453A] - (.Microsoft Corporation - Application d’ouverture de session Windows.) (.17/05/2010 - 08:35:14.) -- C:\Windows\System32\Winlogon.exe [389632]
[MD5.75341574F21E766748732BDF530C74BD] - (.Microsoft Corporation - Bibliothèque de licences.) (.14/07/2009 - 02:41:54.) -- C:\Windows\System32\sppcomapi.dll [231936]
[MD5.DB9D6C6B2CD95A9CA414D045B627422E] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) (.28/12/2011 - 04:59:11.) -- C:\Windows\system32\Drivers\AFD.sys [499200]
[MD5.02062C0B390B7729EDC9E69C680A6F3C] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.14/07/2009 - 02:52:21.) -- C:\Windows\system32\Drivers\atapi.sys [24128]
[MD5.B8BD2BB284668C84865658C77574381A] - (.Microsoft Corporation - CD-ROM File System Driver.) (.14/07/2009 - 00:19:47.) -- C:\Windows\system32\Drivers\Cdfs.sys [92160]
[MD5.83D2D75E1EFB81B3450C18131443F7DB] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.14/07/2009 - 00:19:54.) -- C:\Windows\system32\Drivers\Cdrom.sys [147456]
[MD5.9C253CE7311CA60FC11C774692A13208] - (.Microsoft Corporation - DFS Namespace Client Driver.) (.27/04/2011 - 03:57:40.) -- C:\Windows\system32\Drivers\DfsC.sys [102400]
[MD5.0A49913402747A0B67DE940FB42CBDBB] - (.Microsoft Corporation - High Definition Audio Bus Driver.) (.14/07/2009 - 01:06:13.) -- C:\Windows\system32\Drivers\HDAudBus.sys [122368]
[MD5.FA55C73D4AFFA7EE23AC4BE53B4592D3] - (.Microsoft Corporation - Pilote de port i8042.) (.14/07/2009 - 00:19:57.) -- C:\Windows\system32\Drivers\i8042prt.sys [105472]
[MD5.AF9B39A7E7B6CAA203B3862582E9F2D0] - (.Microsoft Corporation - IP Network Address Translator.) (.14/07/2009 - 01:10:03.) -- C:\Windows\system32\Drivers\IpNat.sys [116224]
[MD5.040D62A9D8AD28922632137ACDD984F2] - (.Microsoft Corporation - Windows NT SMB Minirdr.) (.04/05/2011 - 03:51:08.) -- C:\Windows\system32\Drivers\MRxSmb.sys [157696]
[MD5.9162B273A44AB9DCE5B44362731D062A] - (.Microsoft Corporation - MBT Transport driver.) (.14/07/2009 - 00:21:29.) -- C:\Windows\system32\Drivers\netBT.sys [259072]
[MD5.9A6089B056EA1B83B36424FC9D0A300E] - (.Microsoft Corporation - Pilote du système de fichiers NT.) (.12/04/2013 - 15:36:37.) -- C:\Windows\system32\Drivers\ntfs.sys [1653096]
[MD5.0086431C29C35BE1DBC43F52CC273887] - (.Microsoft Corporation - Pilote de port parallèle.) (.14/07/2009 - 01:00:41.) -- C:\Windows\system32\Drivers\Parport.sys [97280]
[MD5.87A6E852A22991580D6D39ADC4790463] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.14/07/2009 - 01:10:12.) -- C:\Windows\system32\Drivers\Rasl2tp.sys [130048]
[MD5.548260A7B8654E024DC30BF8A7C5BAA4] - (.Microsoft Corporation - SMB Transport driver.) (.14/07/2009 - 01:09:09.) -- C:\Windows\system32\Drivers\smb.sys [93184]
[MD5.079125C4B17B01FCAEEBCE0BCB290C0F] - (.Microsoft Corporation - TDI Translation Driver.) (.14/07/2009 - 00:21:15.) -- C:\Windows\system32\Drivers\tdx.sys [99840]
[MD5.9E425AC5C9A5A973273D169F43B4F5E1] - (.Microsoft Corporation - Pilote de cliché instantané du volume.) (.06/09/2012 - 18:38:18.) -- C:\Windows\system32\Drivers\volsnap.sys [295792]
~ Generic Processes: Scanned in 00mn 06s
---\\ Etat des fichiers cachés (Caché/Total)
~ Mes images (My Pictures) : 1/19819
~ Mes musiques (My Musics) : 1/211
~ Mes Favoris (My Favorites) : 1/37
~ Mes Documents (My Documents) : 1/640
~ Mon Bureau (My Desktop) : 1/944
~ Menu demarrer (Programs) : 1/36
~ Hidden Files: Scanned in 01mn 45s
---\\ Processus lancés
[MD5.30CCA31D938B70FB98343EB857F02945] - (.Pas de propriétaire - DefaultSettingEXE MFC Application.) -- C:\Windows\PLFSetI.exe [206208] [PID.2516]
[MD5.BAE10A613F31AE098B67F764A4969945] - (.Copernic Inc. - Copernic Desktop Search Service.) -- C:\Program Files (x86)\Copernic Desktop Search - Home\DesktopSearchService.exe [1520640] [PID.2544]
[MD5.E6DEED311D830678E1A0B4889F3C2F0E] - (.UASSOFT.COM - DRIVER AUTORUN.) -- C:\Program Files (x86)\Keyboard Driver\StartAutorun.exe [212992] [PID.2968]
[MD5.CDE07257FC2802001D930ADD1F25127C] - (.UASSOFT.COM - USB Keyboard And PS/2 Keyboard Driver.) -- C:\Program Files (x86)\Keyboard Driver\KMConfig.exe [397312] [PID.2916]
[MD5.D722AA885336EDBA2AC0EB4D8E15D050] - (.SPAMfighter ApS - FIGHTERtools Update Manager.) -- C:\Program Files (x86)\Fighters\Tray\FightersTray.exe [1405544] [PID.2912]
[MD5.AE94B9E946239BF390AA8918CADFCE40] - (.SPAMfighter ApS - SPAMfighter Agent.) -- C:\Program Files (x86)\Fighters\SPAMfighter\sfagent.exe [1460768] [PID.2900]
[MD5.59B7D79AF2159D1C784054D8C0D99EA0] - (.UASSOFT.COM - Keyboard And Mouse Processing.) -- C:\Program Files (x86)\Keyboard Driver\KMProcess.exe [339456] [PID.3136]
[MD5.F7E1CCBAD109329203AACB1E87BE614C] - (.Dropbox, Inc. - Dropbox.) -- C:\Users\Gilles\AppData\Roaming\Dropbox\bin\Dropbox.exe [27776968] [PID.3160]
[MD5.4631FF0EE2964CCDC646AF807CB778F5] - (.Avira Operations GmbH Co. KG - Avira System Tray Tool.) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [345144] [PID.3208]
[MD5.51138BEEA3E2C21EC44D0932C71762A8] - (...) -- ysWOW64\RunDll32.exe [0] [PID.3284]
[MD5.C07BA1F5673D7097F667530187E3EA14] - (.Nicolas Coolman - ZHPDiag.) -- C:\Program Files (x86)\ZHPDiag\ZHPDiag.exe [7748096] [PID.3740]
[MD5.C866F8C29508363A09FAC5C235855D56] - (.Microsoft Corporation - Microsoft Word.) -- C:\Program Files (x86)\Microsoft Office\Office14\WINWORD.exe [1422912] [PID.4152]
[MD5.C8D28F8B498CADBB9445AC4545BD41B7] - (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe [920472] [PID.4112]
[MD5.99387251353598C939592FAF40DF8AA9] - (.Avira Operations GmbH Co. KG - Avira Scheduler.) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [84024] [PID.1400]
[MD5.3927397AC60D943DAF8808AFFED582B7] - (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [65192] [PID.1564]
[MD5.8491FDA93507F2F27FFBA11372764086] - (.Avira Operations GmbH Co. KG - Avira On-Access Service.) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [108088] [PID.1640]
[MD5.F2060A34C8A75BC24A9222EB4F8C07BD] - (.Apple Inc. - Bonjour Service.) -- C:\Program Files (x86)\Bonjour\mDNSResponder.exe [349472] [PID.1660]
[MD5.E2B2853A0210D6EDAB2261870BD80C1A] - (.Dritek System Inc. - Dritek WMI Service.) -- C:\Program Files (x86)\Launch Manager\dsiwmis.exe [312400] [PID.1748]
[MD5.0191DEE9B9EB7902AF2CF4F67301095D] - (.Acer Incorporated - Global Registration Service.) -- C:\Program Files (x86)\Acer\Registration\GREGsvc.exe [23584] [PID.1796]
[MD5.C845BAD94BB9AB52806E1402FC04AD89] - (.UASSOFT.COM - Keyboard And Mouse Communication Service.) -- C:\Program Files (x86)\Keyboard Driver\KMWDSrv.exe [1821184] [PID.1864]
[MD5.23DE5B62B0445A6F874BE633C95B483E] - (.Intel Corporation - Local Manageability Service.) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [268824] [PID.1904]
[MD5.5B3CE960C62DBE864BE9A0BD043A3E30] - (.NewTech Infosystems, Inc. - Backup Manager Module.) -- C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe [250368] [PID.1048]
[MD5.DE43E582B80C4DF7D6425A42BCABB90A] - (.SPAMfighter ApS - Fighter Suite Service.) -- C:\Program Files (x86)\Fighters\FighterSuiteService.exe [1270376] [PID.1492]
[MD5.F9EC9ACD504D823D9B9CA98A4F8D3CA2] - (.Acer Group - Updater Service.) -- C:\Program Files\Acer\Acer Updater\UpdaterService.exe [243232] [PID.1912]
[MD5.B5B84712111414DD1B14C2346E9868BE] - (.Western Digital - WD Drive Service.) -- C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe [248248] [PID.1984]
[MD5.A578AE45097ACAD346C86C96F1C0D5A7] - (.Western Digital - WD Rules Engine.) -- C:\Program Files (x86)\Western Digital\WD SmartWare\WDRulesEngine.exe [1177536] [PID.2080]
[MD5.D634CFE93E0CD001499D0D6D68890C9E] - (.Western Digital - WD Backup Engine.) -- C:\Program Files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe [1151424] [PID.2248]
[MD5.696EB1F22EC71262BB8188639DBEED3E] - (.Avira Operations GmbH Co. KG - Avira WebGuard Service.) -- C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.exe [589368] [PID.3916]
[MD5.CC3775100ABA633984F73DFAE1F55CAE] - (.Intel Corporation - User Notification Service.) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2320920] [PID.828]
~ Processes Running: Scanned in 00mn 10s
---\\ Google Chrome, Démarrage,Recherche,Extensions (G0,G1,G2)
C:\Users\Gilles\AppData\Local\Google\Chrome\User Data\Default\Preferences
~ Google Browser: 1 Legitimates Filtered in 00mn 01s
---\\ Mozilla Firefox, Plugins,Demarrage,Recherche,Extensions (P2,M0,M1,M2,M3)
C:\Users\Gilles\AppData\Roaming\Mozilla\Firefox\Profiles\.BackupManager\prefs.js
C:\Users\Gilles\AppData\Roaming\Mozilla\Firefox\Profiles\ddyodmla.default\prefs.js
M2 - MFEP: prefs.js [Gilles - ddyodmla.default\
printPages2Pdf@reinhold.ripper] [] Print pages to PDF v0.1.9.0 (..)
M2 - MFEP: prefs.js [Gilles - ddyodmla.default\
zotero@chnm.gmu.edu] [] Zotero v3.0.11 (..)
~ Firefox Browser: 25 Legitimates Filtered in 00mn 04s
---\\ Internet Explorer, Proxy Management (R5)
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;127.0.0.1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll
~ Proxy management: Scanned in 00mn 00s
---\\ Analyse des lignes F0, F1, F2, F3 - IniFiles, Autoloading programs
F2 - REG:system.ini: USERINIT=C:\Windows\system32\userinit.exe,
F2 - REG:system.ini: Shell=C:\Windows\explorer.exe
F2 - REG:system.ini: VMApplet=C:\Windows\System32\SystemPropertiesPerformance.exe
~ Keys: Scanned in 00mn 00s
---\\ Redirection du fichier Hosts (O1)
~ Le fichier hosts est sain (The hosts file is clean).
~ Hosts File: Scanned in 00mn 00s
~ Nombre de lignes (Lines number): 21
---\\ Internet Explorer Toolbars (O3)
O3 - Toolbar\WebBrowser: (no name) [64Bits] - [HKCU]{2318C2B1-4965-11D4-9B18-009027A5CD4F} Clé orpheline
O3 - Toolbar\WebBrowser: (no name) [64Bits] - [HKCU]{968631B6-4729-440D-9BF4-251F5593EC9A} Clé orpheline
O3 - Toolbar\WebBrowser: (no name) [64Bits] - [HKCU]{47833539-D0C5-4125-9FA8-0819E2EAAC93} Clé orpheline
~ Toolbar: Scanned in 00mn 00s
---\\ Applications démarrées par registre par dossier (O4)
O4 - HKLM\..\Run: [Persistence] . (.Intel Corporation - persistence Module.) -- C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [RtHDVCpl] . (.Realtek Semiconductor - Gestionnaire audio HD Realtek.) -- C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
O4 - HKLM\..\Run: [PLFSetI] . (.Pas de propriétaire - DefaultSettingEXE MFC Application.) -- C:\Windows\PLFSetI.exe
O4 - HKLM\..\Run: [Apoint] . (.Alps Electric Co., Ltd. - Alps Pointing-device Driver.) -- C:\Program Files\Apoint2K\Apoint.exe
O4 - HKCU\..\Run: [Copernic Desktop Search - Home] . (.Copernic Inc. - Copernic Desktop Search Service.) -- C:\Program Files (x86)\Copernic Desktop Search - Home\DesktopSearchService.exe
O4 - HKLM\..\Wow6432Node\Run: [SuiteTray] . (.Egis Technology Inc. - SuiteTray.) -- C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe
O4 - HKLM\..\Wow6432Node\Run: [zBrowser Launcher] . (.Logitech Inc. - iTouch Application.) -- C:\Program Files (x86)\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Wow6432Node\Run: [KMCONFIG] . (.UASSOFT.COM - DRIVER AUTORUN.) -- C:\Program Files (x86)\Keyboard Driver\StartAutorun.exe
O4 - HKLM\..\Wow6432Node\Run: [CommonToolkitTray] . (.SPAMfighter ApS - FIGHTERtools Update Manager.) -- C:\Program Files (x86)\Fighters\Tray\FightersTray.exe
O4 - HKLM\..\Wow6432Node\Run: [sfagent] . (.SPAMfighter ApS - SPAMfighter Agent.) -- C:\Program Files (x86)\Fighters\SPAMfighter\sfagent.exe
O4 - HKLM\..\Wow6432Node\Run: [avgnt] . (.Avira Operations GmbH Co. KG - Avira System Tray Tool.) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files (x86)\Windows Sidebar\Sidebar.exe
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files (x86)\Windows Sidebar\Sidebar.exe
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe
O4 - HKUS\S-1-5-21-978868575-3469318854-3647737991-1001\..\Run: [Copernic Desktop Search - Home] . (.Copernic Inc. - Copernic Desktop Search Service.) -- C:\Program Files (x86)\Copernic Desktop Search - Home\DesktopSearchService.exe
~ Application: Scanned in 00mn 01s
---\\ Autres liens utilisateurs (O4)
O4 - GS\TaskBar: CCleaner.lnk . (.Piriform Ltd - CCleaner.) -- C:\Program Files\CCleaner\CCleaner64.exe =Piriform Ltd
O4 - GS\TaskBar: Cordial 2012 Application.lnk . (.Synapse Développement - Pas de description.) -- C:\Program Files (x86)\Cordial\CordialPro.exe
O4 - GS\Programs: Internet Explorer (64-bit).lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
O4 - GS\Programs: Microsoft Money.lnk . (.Microsoft Corporation - Microsoft Money.) -- C:\Program Files (x86)\Microsoft Money\System\msmoney.exe
O4 - GS\QuickLaunch: e-Carte Bleue Banque Populaire.lnk . (.Orbiscom Ltd. All rights reserved. - ECBL Client.) -- C:\Program Files (x86)\e-Carte Bleue Banque Populaire\ecbl-nxbp.exe
O4 - GS\QuickLaunch: Google Chrome.lnk . (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
O4 - GS\QuickLaunch: Inkscape.lnk . (.inkscape.org - Inkscape.) -- C:\Program Files (x86)\Inkscape\inkscape.exe
O4 - GS\QuickLaunch: Launch Internet Explorer Browser.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
O4 - GS\QuickLaunch: MegaCloud.lnk . (...) -- C:\Users\Gilles\AppData\Roaming\MegaCloud\MegaCloud.exe
O4 - GS\QuickLaunch: Microsoft Outlook.lnk . (.Microsoft Corporation - Microsoft Outlook.) -- C:\Program Files (x86)\Microsoft Office\Office14\OUTLOOK.exe
O4 - GS\QuickLaunch: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
O4 - GS\QuickLaunch: Mozilla Thunderbird.lnk . (.Mozilla Corporation - Thunderbird.) -- C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe
O4 - GS\QuickLaunch: Samsung Kies (Lite).lnk . (...) -- C:\Program Files (x86)\SAMSUNG\Kies\KiesAgent.exe
O4 - GS\QuickLaunch: Samsung Kies.lnk . (...) -- C:\Program Files (x86)\SAMSUNG\Kies\KiesAgent.exe
O4 - GS\Accessories: Internet Explorer (No Add-ons).lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
O4 - GS\Accessories: Private Character Editor.lnk . (.Microsoft Corporation - Éditeur de caractères privés.) -- C:\Windows\system32\eudcedit.exe
O4 - GS\SendTo: Fax Recipient.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) -- C:\Windows\system32\WFS.exe
O4 - GS\Desktop: AD-R.lnk . (...) -- C:\Program Files (x86)\Ad-Remover\main.exe
O4 - GS\Desktop: Audiograbber.lnk . (...) -- C:\audiograbber\audiograbber.exe
O4 - GS\Desktop: Cordial 2012 Application.lnk . (.Synapse Développement - Pas de description.) -- C:\Program Files (x86)\Cordial\CordialPro.exe
O4 - GS\Desktop: Dropbox.lnk . (.Dropbox, Inc. - Dropbox.) -- C:\Users\Gilles\AppData\Roaming\Dropbox\bin\Dropbox.exe
O4 - GS\Desktop: EndNote Program.lnk . (...) -- C:\Windows\Installer\{86B3F2D6-AC2B-0015-8AE1-F2F77F781B0C}\Icon002B1E90.exe
O4 - GS\Desktop: Eudora.lnk . (...) -- C:\Users\Gilles\AppData\Roaming\Qualcomm\Eudora
O4 - GS\Desktop: Images - Raccourci.lnk . (...) -- C:\Users\Gilles\AppData\Roaming\Microsoft\Windows\Libraries\Pictures.library-ms
O4 - GS\Desktop: MegaCloud Backup.lnk . (...) -- C:\Users\Gilles\AppData\Roaming\MegaCloudBackup\MegaCloudBackup.exe
O4 - GS\Desktop: MegaCloud.lnk . (...) -- C:\Users\Gilles\AppData\Roaming\MegaCloud\MegaCloud.exe
O4 - GS\Desktop: Mes documents.lnk . (...) -- C:\Users\Gilles\Documents
O4 - GS\Desktop: Microsoft Excel 2010.lnk . (...) -- C:\Windows\Installer\{90140000-0011-0000-0000-0000000FF1CE}\xlicons.exe
O4 - GS\Desktop: Microsoft Money.lnk . (.Microsoft Corporation - Microsoft Money.) -- C:\Program Files (x86)\Microsoft Money\System\msmoney.exe
O4 - GS\Desktop: Microsoft Word 2010.lnk . (...) -- C:\Windows\Installer\{90140000-0011-0000-0000-0000000FF1CE}\wordicon.exe
O4 - GS\Desktop: PhotoFiltre.lnk . (.Antonio Da Cruz - PhotoFiltre.) -- C:\Program Files (x86)\PhotoFiltre\photofiltre.exe
O4 - GS\Desktop: Podcasts.lnk . (...) -- C:\Users\Gilles\Music\iTunes\iTunes Media\Podcasts
O4 - GS\Desktop: RecentPlaces.lnk - Clé orpheline
O4 - GS\Desktop: Samsung SCX-3200 Series - Raccourci.lnk - Clé orpheline
O4 - GS\Desktop: Thunderbind_Local Folders.lnk . (...) -- C:\Users\Gilles\AppData\Roaming\Thunderbird\Profiles\v8p23y8u.default\Mail\Local Folders
O4 - GS\Desktop: Téléchargements 2.lnk . (...) -- C:\Users\Gilles\Documents\Téléchargements
O4 - GS\Desktop: Téléchargements1.lnk . (...) -- C:\Users\Gilles\Downloads
~ Global Startup: Scanned in 00mn 17s
---\\ Boutons situés sur la barre d'outils principale d'Internet Explorer (O9)
O9 - Extra button: Envoyer à OneNote [64Bits] - {2670000A-7350-4f3c-8081-5663EE0C6C49} -- C:\Program Files (x86)\MICROS~2\Office14\ONBttnIE.dll (.not file.)
O9 - Extra button: Notes liées OneNote [64Bits] - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} -- C:\Program Files (x86)\MICROS~2\Office14\ONBTTN~1.dll (.not file.)
O9 - Extra button: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 [64Bits] - {CCA281CA-C863-46ef-9331-5C8D4460577F} . (...) -- C:\Program Files\WIDCOMM\Bluetooth Software\bt_hot_icon.ico
~ IE Extra Buttons: Scanned in 00mn 00s
---\\ Modification Domaine/Adresses DNS (O17)
O17 - HKLM\System\CCS\Services\Tcpip\..\{B145864E-6F7E-423D-A1FC-71E803ADFBC2}: DhcpNameServer = 212.27.40.241 212.27.40.240
O17 - HKLM\System\CS1\Services\Tcpip\..\{B145864E-6F7E-423D-A1FC-71E803ADFBC2}: DhcpNameServer = 212.27.40.241 212.27.40.240
O17 - HKLM\System\CS2\Services\Tcpip\..\{B145864E-6F7E-423D-A1FC-71E803ADFBC2}: DhcpNameServer = 212.27.40.241 212.27.40.240
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 212.27.40.241 212.27.40.240
~ Domain: Scanned in 00mn 00s
---\\ Protocole additionnel (O18)
O18 - Handler: wlpg [64Bits] - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} . (...) --
O18 - Filter: text/xml [64Bits] - {807573E5-5146-11D5-A672-00B0D022E945} . (.Microsoft Corporation - Microsoft Office XML MIME Filter.) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.dll
~ Protocole Additionnel: Scanned in 00mn 00s
---\\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (autorun) (O20)
O20 - Winlogon Notify: igfxcui . (.Intel Corporation - igfxdev Module.) -- C:\Windows\System32\igfxdev.dll
~ Winlogon: Scanned in 00mn 00s
---\\ Liste des services NT non Microsoft et non désactivés (O23)
O23 - Service: Keyboard And Mouse Communication Service (KMWDSERVICE) . (.UASSOFT.COM - Keyboard And Mouse Communication Service.) - C:\Program Files (x86)\Keyboard Driver\KMWDSrv.exe
O23 - Service: lxcj_device (lxcj_device) . (...) - C:\Windows\system32\lxcjcoms.exe (.not file.)
O23 - Service: WD Rules (WDRulesService) . (.Western Digital - WD Rules Engine.) - C:\Program Files (x86)\Western Digital\WD SmartWare\WDRulesEngine.exe
~ Services: 18 Legitimates Filtered in 00mn 09s
---\\ Tâches planifiées en automatique (O39)
[MD5.7E1624E6C85FFC1EE98AE472B71D5781] [APT] [{20D85ACF-0BAE-4AA4-9034-1CCD5B92DE7F}] (...) -- C:\Program Files (x86)\LexmarkX83\RemoveX83.exe [549448]
[MD5.46D6CA92D98D73277F35AF2F558BA351] [APT] [{3F695F73-0BCB-4C4C-BEF8-4FC5E0E4DD5F}] (...) -- D:\26 Informatique\Protection de son ordinateur\spampal.exe [805947]
[MD5.BA53F6566EDC6DDD1E2D2734B2E1C007] [APT] [{62036ADF-5EDC-4F97-8651-4A0CEF20E4B4}] (...) -- D:\27 Fichiers programmes informatiques\Lexmark X83_programmes scanner et photo\Scan\ENGLISH\SETUP.exe [11556655]
[MD5.00000000000000000000000000000000] [APT] [{6371153C-EE2A-45B6-AC8F-FB11016D3CA2}] (...) -- F:\setup.exe (.not file.) [0]
[MD5.83F0582EA262E2542AB067EE4787BA22] [APT] [{6FE14151-381A-4D71-957D-AE86810891FA}] (.Logitech.) -- D:\27 Fichiers programmes informatiques\Logitech sans fil\iTouche2.22fra.exe [4474271]
[MD5.65F83F4BE6D76D32B90B1957FAD1ED35] [APT] [{73B15FA6-9BE9-4487-8A00-C2010A507127}] (...) -- D:\27 Fichiers programmes informatiques\audiograbber setup.exe [1665325]
[MD5.00000000000000000000000000000000] [APT] [{996A6CD5-86FD-4B72-945C-82443D74E2A5}] (...) -- C:\Users\Gilles\Downloads\20070128180408375_ML-1200_GDI_Vista.exe (.not file.) [0]
[MD5.D03570460025C8D321E223C70112B5A3] [APT] [{9AFF2768-2111-49D3-99D2-3B22E9D402A9}] (...) -- D:\03-1 Vie Pratique\Achats\Achats\Appareil photo Nikon Coolpix P7000\Coolpix P7000_Firmware1.2 Update\F-P7000-V12W.exe [9564656]
[MD5.00000000000000000000000000000000] [APT] [{F4701B66-7E34-4402-B816-27DD62154B7D}] (...) -- E:\27 Fichiers programmes informatiques\Lexmark X83_programmes scanner et photo\setup.exe (.not file.) [0]
~ Scheduled Task: 16 Legitimates Filtered in 01mn 09s
---\\ Logiciels installés (O42)
O42 - Logiciel: Eudora - (...) [HKLM][64Bits] -- {64510A28-ED00-484C-AF50-7F9A1FE45C23}
O42 - Logiciel: Keyboard Driver - (.Driver Builder.) [HKLM][64Bits] -- InstallShield_{DFCDD1CE-6D49-49B8-BFB7-93391D22776B}
O42 - Logiciel: Keyboard Driver - (.Driver Builder.) [HKLM][64Bits] -- {DFCDD1CE-6D49-49B8-BFB7-93391D22776B}
O42 - Logiciel: ML-1200 Series - (...) [HKLM][64Bits] -- {8C19F391-A225-4F32-8681-EDB8AFE6E436}
O42 - Logiciel: Trust R-Series Keyboard - (.Driver Builder.) [HKLM][64Bits] -- InstallShield_{1935D11C-DD19-4D4A-B033-401086EED63C}
~ Logic: 125 Legitimates Filtered in 00mn 01s
---\\ HKCU HKLM Software Keys
[HKLM\Software\Wow6432Node\SPYWAREFIGHTER]
~ Key Software: 230 Legitimates Filtered in 00mn 01s
---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43)
O43 - CFD: 30/03/2011 - 12:02:18 - [91,937] ----D C:\Program Files (x86)\Cardiris 4 Limited Edition
O43 - CFD: 16/05/2011 - 12:35:42 - [6,188] ----D C:\Program Files (x86)\Keyboard Driver
O43 - CFD: 11/07/2012 - 18:14:51 - [0] ----D C:\Program Files (x86)\SpamPal
O43 - CFD: 25/01/2013 - 12:11:13 - [0,006] ----D C:\Program Files (x86)\tuto4pc_fr_23 =PUP.Eorezo
O43 - CFD: 16/05/2011 - 12:25:15 - [1,597] ----D C:\ProgramData\{60727955-924B-4A9F-9506-5104848B6673}
O43 - CFD: 11/07/2012 - 18:11:06 - [0,139] ----D C:\Users\Gilles\AppData\Roaming\SpamPal
O43 - CFD: 25/01/2013 - 12:11:06 - [0,002] ----D C:\Users\Gilles\AppData\Local\tuto4pc_fr_23 =PUP.Eorezo
O43 - CFD: 14/02/2011 - 13:48:43 - [0] ----D C:\Users\Gilles\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Audiograbber
~ 51 Dossiers CLSID vides (CLSID Empty Folders)
~ Program Folder: 280 Legitimates Filtered in 05mn 49s
---\\ Derniers fichiers modifiés ou crées sous Windows et System32 (O44)
O44 - LFC:[MD5.BF80325DE95FA526F223BE140EB33D38] - 23/07/2013 - 20:34:25 --HA- . (...) -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [22896]
O44 - LFC:[MD5.BF80325DE95FA526F223BE140EB33D38] - 23/07/2013 - 20:34:25 --HA- . (...) -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [22896]
O44 - LFC:[MD5.BF80325DE95FA526F223BE140EB33D38] - 23/07/2013 - 20:34:25 RSHAD . (...) -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [22896]
O44 - LFC:[MD5.BF80325DE95FA526F223BE140EB33D38] - 23/07/2013 - 20:34:25 RSHAD . (...) -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [22896]
O44 - LFC:[MD5.4DD41851A91356359A9F1FCD35C845D1] - 23/07/2013 - 20:24:34 ---A- . (...) -- C:\Windows\iTouch.ini [32]
O44 - LFC:[MD5.B391BFFA4DC9384721528EDEE0E39F00] - 22/07/2013 - 19:33:38 ---A- . (...) -- C:\Ad-Report-CLEAN[1].txt [4645]
O44 - LFC:[MD5.A86CC0D5669AA3AD7A5086EC3F8C8E87] - 18/07/2013 - 22:17:00 ---A- . (...) -- C:\Ad-Report-SCAN[1].txt [4626]
~ Files: 25 Legitimates Filtered in 04mn 04s
---\\ Derniers fichiers créés dans Windows Prefetcher (O45)
O45 - LFCP:[MD5.3868125BB07F669637239BAECF0E26F8] - 04/07/2013 - 17:23:14 ---A- - C:\Windows\Prefetch\WDSMARTWARE.EXE-1EC63CDF.pf
O45 - LFCP:[MD5.47D52CC458EF7BEE04EFCEA9DB576751] - 09/07/2013 - 10:48:32 ---A- - C:\Windows\Prefetch\ECBL-NXBP.EXE-3CE79B1C.pf
O45 - LFCP:[MD5.EBCEDC2A21E5D2AAFE7CAE30AB4FF744] - 11/07/2013 - 15:11:02 ---A- - C:\Windows\Prefetch\OMNIPAGE18.EXE-D5F6924E.pf
O45 - LFCP:[MD5.6BF6059DC4AAA4E0D4FE62516B034C64] - 11/07/2013 - 17:40:31 ---A- - C:\Windows\Prefetch\TWAINCLIENTU.EXE-F78BAB7C.pf
O45 - LFCP:[MD5.C5F48CEC2535C367FC42556D6CE6BCA9] - 22/07/2013 - 14:22:18 ---A- - C:\Windows\Prefetch\PLFSETI.EXE-D9D6FD5A.pf
O45 - LFCP:[MD5.93D8E3608948E7273A61FFF13DEE2675] - 22/07/2013 - 14:23:11 ---A- - C:\Windows\Prefetch\STARTAUTORUN.EXE-4E3C0D4B.pf
O45 - LFCP:[MD5.268589B3F775629909244B96D40E35F5] - 22/07/2013 - 14:23:19 ---A- - C:\Windows\Prefetch\SUITETRAY.EXE-42757614.pf
O45 - LFCP:[MD5.9F4DBBE634C04F0D5BC8D1451BAF9412] - 22/07/2013 - 14:23:34 ---A- - C:\Windows\Prefetch\ITOUCH.EXE-1BEF4FCD.pf
O45 - LFCP:[MD5.29F9FA372276EAEAE37406DD3105EA46] - 22/07/2013 - 14:23:39 ---A- - C:\Windows\Prefetch\MSGSYS.EXE-CE2EB8DC.pf
O45 - LFCP:[MD5.175D074918EDB94D03DACE41CBAFB45F] - 22/07/2013 - 14:23:40 ---A- - C:\Windows\Prefetch\FIGHTERSTRAY.EXE-661AD7B2.pf
O45 - LFCP:[MD5.946BB3719B19C44133153FFA95CD3347] - 22/07/2013 - 14:23:48 ---A- - C:\Windows\Prefetch\KMCONFIG.EXE-182D97B5.pf
O45 - LFCP:[MD5.C07E989065B2097FDDF94C5EC55154F9] - 22/07/2013 - 14:23:49 ---A- - C:\Windows\Prefetch\KMPROCESS.EXE-E4ABC39A.pf
O45 - LFCP:[MD5.0122F4CBC6EEFB3F4FE8208F6B33D5F2] - 22/07/2013 - 14:47:01 ---A- - C:\Windows\Prefetch\READIRIS.EXE-D85E35FE.pf
O45 - LFCP:[MD5.0C98DAA0B8EC02CBD57D973CAC5456B8] - 22/07/2013 - 18:49:32 ---A- - C:\Windows\Prefetch\OMNIPAGE.EXE-0FCD1E19.pf
O45 - LFCP:[MD5.FD2B32733DD9B3BADC45B69CF092F494] - 23/07/2013 - 20:20:48 ---A- - C:\Windows\Prefetch\WDLOCKEDFILES.EXE-EE26236A.pf
~ Prefetcher: 124 Legitimates Filtered in 00mn 02s
---\\ Opérations et fonctions au démarrage de Windows Explorer (O46)
O46 - SEH:ShellExecuteHooks - Groove GFS Stub Execution Hook [64Bits] - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~2\MICROS~4\Office14\GROOVEEX.DLL
~ ShellExecuteHooks: Scanned in 00mn 00s
---\\ MountPoints2 Shell Key (O51)
O51 - MPSK:{264aa37a-da1c-11e0-a375-78e400734643}\AutoRun\command. (...) -- E:\WD SmartWare.exe (.not file.)
O51 - MPSK:{8ee582f6-9063-11e2-b0bf-00262dab8b8e}\AutoRun\command. (...) -- F:\LaunchU3.exe (.not file.)
~ Keys: Scanned in 00mn 00s
---\\ ShareTools MSconfig StartupReg (O53)
O53 - SMSR:HKLM\...\startupreg\BabylonToolbar [Key] . (...) -- C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.4.19.19\BabylonToolbarsrv.exe (.not file.) =Toolbar.Babylon
O53 - SMSR:HKLM\...\startupreg\Copernic Desktop Search - Home [Key] . (.Copernic Inc. - Copernic Desktop Search Service.) -- C:\Program Files (x86)\Copernic Desktop Search - Home\DesktopSearchService.exe
O53 - SMSR:HKLM\...\startupreg\SearchSettings [Key] . (...) -- C:\Program Files (x86)\Common Files\Spigot\Search Settings\SearchSettings.exe (.not file.) =Adware.SearchSettings
O53 - SMSR:HKLM\...\startupreg\WD Drive Unlocker [Key] . (.Western Digital - WD Drive Auto Unlock.) -- C:\Program Files (x86)\Western Digital\WD Security\WDDriveAutoUnlock.exe
O53 - SMSR:HKLM\...\startupreg\WD Quick View [Key] . (.Western Digital Technologies, Inc. - WD Quick View.) -- C:\Program Files (x86)\Western Digital\WD Quick View\WDDMStatus.exe
~ SMSR Keys: 38 Legitimates Filtered in 00mn 03s
---\\ Microsoft Windows Policies System (O55)
O55 - MWPS:[HKLM\...\Policies\System] - "EnableUIADesktopToggle"=0
O55 - MWPS:[HKLM\...\Policies\System] - "PromptOnSecureDesktop"=0
O55 - MWPS:[HKLM\...\Policies\System] - "FilterAdministratorToken"=0
O55 - MWPS:[HKLM\...\Policies\System] - "EnableLUA"=0
~ MWPS: 16 Legitimates Filtered in 00mn 00s
---\\ Microsoft Windows Policies Explorer (O56)
O56 - MWPE:[HKLM\...\policies\Explorer] - "NoActiveDesktopChanges"=1
~ MWPE Keys: 4 Legitimates Filtered in 00mn 00s
---\\ Liste des Drivers Système (O58)
O58 - SDL:[MD5.2F6B34B83843F0C5118B63AC634F5BF4] - 14/07/2009 - 02:52:21 ---A- . (.Adaptec, Inc. - Adaptec Windows SAS/SATA Storport Driver.) -- C:\Windows\System32\Drivers\adp94xx.sys [491088]
O58 - SDL:[MD5.F9BF3459F5B6F0C497FE481D0449E040] - 02/06/2005 - 10:20:12 R--A- . (.Prolific Technology Inc. - USB IDE Bridge Controller WDM Driver.) -- C:\Windows\SysWOW64\drivers\IBUMSS.sys [19368]
~ Drivers: Scanned in 00mn 00s
---\\ Derniers fichiers modifiés ou crées (Utilisateur) (O61)
O61 - LFC: 22/07/2013 - 14:54:39 ---A- C:\Users\Gilles\Documents\Readiris.DUS [173807]
O61 - LFC: 22/07/2013 - 15:01:33 ---A- C:\Users\Gilles\Documents\Readiris\defboot.ibt [111302]
O61 - LFC: 23/07/2013 - 20:12:47 ---A- C:\Users\Gilles\AppData\Local\Copernic\DesktopSearch2\Queue\MainChunk\IndexingQueueEl.dat [296768]
O61 - LFC: 23/07/2013 - 20:12:47 ---A- C:\Users\Gilles\AppData\Local\Copernic\DesktopSearch2\Queue\MainChunk\IndexingQueueIf.dat [0]
O61 - LFC: 23/07/2013 - 20:24:41 ---A- C:\Users\Gilles\AppData\Local\Copernic\DesktopSearch2\Queue\MainChunk\IndexingQueueV.dat [8]
O61 - LFC: 23/07/2013 - 20:24:45 ---A- C:\Users\Gilles\AppData\Local\Copernic\DesktopSearch2\Index\MainChunk\ChunkV.dat [8]
O61 - LFC: 23/07/2013 - 20:24:53 ---A- C:\Users\Gilles\AppData\Local\Copernic\DesktopSearch2\Index\MainChunk\DocumentsDI.dat [100004]
O61 - LFC: 23/07/2013 - 20:24:53 ---A- C:\Users\Gilles\AppData\Local\Copernic\DesktopSearch2\Index\MainChunk\DocumentsI.dat [8]
O61 - LFC: 23/07/2013 - 20:24:54 ---A- C:\Users\Gilles\AppData\Local\Copernic\DesktopSearch2\Index\MainChunk\ChunkFD.dat [2630]
O61 - LFC: 23/07/2013 - 20:24:54 ---A- C:\Users\Gilles\AppData\Local\Copernic\DesktopSearch2\Index\MainChunk\ChunkI.dat [0]
O61 - LFC: 23/07/2013 - 20:24:54 ---A- C:\Users\Gilles\AppData\Local\Copernic\DesktopSearch2\Index\MainChunk\ChunkSCSF.dat [508]
O61 - LFC: 23/07/2013 - 20:24:54 ---A- C:\Users\Gilles\AppData\Local\Copernic\DesktopSearch2\Index\MainChunk\KeywordsI.dat [0]
O61 - LFC: 23/07/2013 - 20:24:54 ---A- C:\Users\Gilles\AppData\Local\Copernic\DesktopSearch2\RefreshQueue.dat [414877]
O61 - LFC: 23/07/2013 - 20:26:59 ---A- C:\Users\Gilles\AppData\Roaming\Thunderbird\sfagent.port.txt [37]
~ 36 Fichiers temporaires (Temporary files)
~ 1 Fichiers cookies (Cookies files)
~ Files: 267 Legitimates Filtered in 10mn 46s
---\\ Liste des outils de nettoyage (O63)
O63 - Logiciel: Ad-Remover par C_XX - (.C_XX.) [HKLM] -- Ad-Remover
O63 - Logiciel: ZHPDiag 2013 - (.Nicolas Coolman.) [HKLM] -- ZHPDiag_is1
~ ADS: Scanned in 00mn 00s
---\\ Start Menu Internet (O68)
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
~ Keys: Scanned in 00mn 00s
---\\ Search Browser Infection (O69)
O69 - SBI: prefs.js [Gilles - ddyodmla.default] user_pref("extensions.enabledItems", "
ffxtlbr@babylon.com:1.1.3,
pdfforge@mybrowserbar.com:4.3,
wtxpcom@mybrowserbar.com:4.3,{972ce4[...] =Toolbar.Babylon
O69 - SBI: SearchScopes [HKCU] ${searchCLSID} [DefaultScope] - (@ieframe.dll,-12512) -
http://search.live.com
O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} - (Bing) -
http://www.bing.com
O69 - SBI: SearchScopes [HKCU] {67A2568C-7A0A-4EED-AECC-B5405DE63B64} - (Google) -
http://www.google.com
O69 - SBI: SearchScopes [HKCU] {6A1806CD-94D4-4689-BA73-E35EA1EA9990} - (Google) -
http://www.google.com
O69 - SBI: SearchScopes [HKCU] {6BE66562-E53D-4F84-BDA9-B7DE7CFF65F3} - (Copernic) -
http://search.copernic.com
O69 - SBI: SearchScopes [HKCU] {7821C050-1991-49AE-97DA-B82716DA0ED4} - (Search) -
http://start.funmoods.com =PUP.Funmoods
O69 - SBI: SearchScopes [HKCU] {98F0BEEA-51A9-4D1B-99B8-AD5083E1CC1B} - (Yahoo! Search) -
http://fr.search.yahoo.com =Toolbar.Yahoo
~ Keys: Scanned in 00mn 00s
---\\ Recherche particuliere à la racine de certains dossiers (O84)
[MD5.6ACBD475647D7A160657CB3E460F0F35] [SPRF][27/01/2010] (...) -- C:\ProgramData\FullRemove.exe [131472]
[MD5.CBF470B77B2DB2F25C56E05CE391F18A] [SPRF][25/02/2011] (.Avanquest Software - IElevator Class Container.) -- C:\ProgramData\hpe4309.dll [148736]
~ Files: Scanned in 00mn 00s
---\\ Product Upgrade Codes (O90)
O90 - PUC: "00EBBF16988FA90478AF72480ED07122" . (.Cardiris 4 Limited Edition.) -- C:\Windows\Installer\{61FBBE00-F889-409A-87FA-2784E00D1722}\ARPPRODUCTICON.exe
O90 - PUC: "8383A4BB1F038CD4F9D20D62738C80D5" . (.CordialHunspell.) -- C:\Windows\Installer\{BB4A3838-30F1-4DC8-9F2D-D02637C8085D}\ARPPRODUCTICON.exe
O90 - PUC: "EC1DDCFD94D68B94FB7B3993D12277B6" . (.Keyboard Driver.) -- C:\Windows\Installer\{DFCDD1CE-6D49-49B8-BFB7-93391D22776B}\ARPPRODUCTICON.exe
~ Update Products: 112 Legitimates Filtered in 00mn 00s
---\\ Etat général des services non Microsoft (EGS) (SR=Running, SS=Stopped)
SR - | Auto 18/12/2012 65192 | (AdobeARMservice) . (.Adobe Systems Incorporated.) - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
SR - | Auto 05/07/2013 84024 | (AntiVirSchedulerService) . (.Avira Operations GmbH Co. KG.) - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
SR - | Auto 05/07/2013 108088 | (AntiVirService) . (.Avira Operations GmbH Co. KG.) - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
SR - | Auto 05/07/2013 589368 | (AntiVirWebService) . (.Avira Operations GmbH Co. KG.) - C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.exe
SS - | Disabled 25/05/2011 37664 | (Apple Mobile Device) . (.Apple Inc..) - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
SR - | Auto 06/04/2011 349472 | (Bonjour Service) . (.Apple Inc..) - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
SR - | Auto 26/03/2010 920352 | (btwdins) . (.Broadcom Corporation..) - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
SR - | Auto 08/04/2010 312400 | (DsiWMIService) . (.Dritek System Inc..) - C:\Program Files (x86)\Launch Manager\dsiwmis.exe
SS - | Disabled 23/04/2010 867360 | (ePowerSvc) . (.Acer Incorporated.) - C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
SS - | Demand 26/04/2012 651720 | (FLEXnet Licensing Service) . (.Macrovision Europe Ltd..) - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
SR - | Auto 08/01/2010 23584 | (GREGService) . (.Acer Incorporated.) - C:\Program Files (x86)\Acer\Registration\GREGsvc.exe
SS - | Auto 23/12/2010 135664 | (gupdate) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
SS - | Demand 23/12/2010 135664 | (gupdatem) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
SS - | Demand 14/11/2005 69632 | (IDriverT) . (.Macrovision Corporation.) - C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
SS - | Disabled 07/06/2011 934176 | (iPod Service) . (.Apple Inc..) - C:\Program Files\iPod\bin\iPodService.exe
SR - | Auto 31/08/2009 1821184 | (KMWDSERVICE) . (.UASSOFT.COM.) - C:\Program Files (x86)\Keyboard Driver\KMWDSrv.exe
SR - | Auto 03/03/2010 268824 | (LMS) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
SS - | Auto 0 | (lxcj_device) . (...) - C:\Windows\system32\lxcjcoms.exe
SS - | Demand 04/07/2013 117144 | (MozillaMaintenance) . (.Mozilla Foundation.) - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
SS - | Demand 01/02/2010 305520 | (MWLService) . (.Egis Technology Inc..) - C:\Program Files (x86)\EgisTec MyWinLocker\x86\MWLService.exe
SR - | Auto 09/03/2010 250368 | (NTI IScheduleSvc) . (.NewTech Infosystems, Inc..) - C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe
SS - | Disabled 90112 | (OMSI download service) . (...) - C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe
SS - | Disabled 15/01/2013 216608 | (SPAMfighter Update Service) . (.SPAMfighter ApS.) - C:\Program Files (x86)\Fighters\SPAMfighter\sfus.exe
SR - | Auto 12/11/2012 1270376 | (Suite Service) . (.SPAMfighter ApS.) - C:\Program Files (x86)\Fighters\FighterSuiteService.exe
SR - | Auto 03/03/2010 2320920 | (UNS) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
SR - | Auto 29/01/2010 243232 | (Updater Service) . (.Acer Group.) - C:\Program Files\Acer\Acer Updater\UpdaterService.exe
SR - | Auto 14/06/2012 1151424 | (WDBackup) . (.Western Digital.) - C:\Program Files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe
SR - | Auto 06/09/2012 248248 | (WDDriveService) . (.Western Digital.) - C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe
SR - | Auto 14/06/2012 1177536 | (WDRulesService) . (.Western Digital.) - C:\Program Files (x86)\Western Digital\WD SmartWare\WDRulesEngine.exe
SR - | Auto 14/07/2009 27136 | C:\Program Files (x86)\Windows Defender\mpsvc.dll (WinDefend) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe
SR - | Auto 0 | (WMPNetworkSvc) . (...) - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe
SR - | Auto 14/07/2009 27136 | C:\Windows\System32\wuaueng.dll (wuauserv) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe
~ Services: Scanned in 00mn 03s
---\\ Recherche Master Boot Record Infection (MBR)(O80)
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer,
http://www.gmer.net
~ MBR: 1 Legitimates Filtered in 00mn 02s
---\\ Recherche Master Boot Record Infection (MBRCheck)(O80)
Written by ad13,
http://ad13.geekstog
Run by Gilles at 23/07/2013 23:26:08
********* Dump file Name *********
C:\PhysicalDisk0_MBR.bin
~ MBR: Scanned in 00mn 04s
---\\ Scan Additionnel (O88)
Database Version : v2.12804 - (22/07/2013)
Clés trouvées (Keys found) : 18
Valeurs trouvées (Values found) : 0
Dossiers trouvés (Folders found) : 2
Fichiers trouvés (Files found) : 0
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\261F213D1F55267499B1F87D0CC3BCF7] =Toolbar.Ask
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\741B4ADF27276464790022C965AB6DA8] =Toolbar.Ask
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7DE196B10195F5647A2B21B761F3DE01] =Toolbar.Ask
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9D4F5849367142E4685ED8C25E44C5ED] =Toolbar.Ask
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A5875B04372C19545BEB90D4D606C472] =Toolbar.Ask
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A876D9E80B896EC44A8620248CC79296] =Toolbar.Ask
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B66FFAB725B92594C986DE826A867888] =Toolbar.Ask
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\F928123A039649549966D4C29D35B1C9] =Adware.MyWebSearch
[HKLM\Software\Microsoft\Shared Tools\MSConfig\startupreg\BabylonToolbar] =Toolbar.Babylon
[HKLM\Software\Microsoft\Shared Tools\MSConfig\startupreg\SearchSettings] =PUP.Dealio
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0CFE535C35F99574E8340BFA75BF92C2] =Toolbar.Ask
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\00E944CB89111313EAF35A0553F547F9] =PUP.Dealio
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\53F55AF3F4049ED3FA6EA6F88E414E24] =PUP.Dealio
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\68E4BF4B11615E03C97732FD581AB607] =PUP.Dealio
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8CE3DDAB2D152683FBCEB4866BCD2B0F] =PUP.Dealio
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AF6CE16AFEA5C9A39B766468A8B35C21] =PUP.Dealio
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FB1E44269B58F433A8C8E671E37CFDCF] =PUP.Dealio
[HKLM\Software\Wow6432Node\Google\Chrome\Extensions\aaaaabfjnbeinlpljodiajipidiompfl] =Toolbar.Avira
C:\Program Files (x86)\tuto4pc_fr_23 =PUP.Eorezo^
C:\Users\Gilles\AppData\Local\tuto4pc_fr_23 =PUP.Eorezo^
~ Additionnel Scan: 348244 Items scanned in 00mn 38s
---\\ Malicius Software Information
~
http://nicolascoolman.webs.com/apps/blo ... pup-eorezo =PUP.EoRezo
~
http://nicolascoolman.webs.com/apps/blo ... ar-babylon =Toolbar.Babylon
~
http://nicolascoolman.webs.com/apps/blo ... chsettings =Adware.SearchSettings
~
http://nicolascoolman.webs.com/apps/blo ... p-funmoods =PUP.Funmoods
~
http://nicolascoolman.webs.com/apps/blo ... lbar-yahoo =Toolbar.Yahoo
~
http://nicolascoolman.webs.com/apps/blo ... oolbar-ask =Toolbar.Ask
~
http://nicolascoolman.webs.com/apps/blo ... ywebsearch =Adware.MyWebSearch
~
http://nicolascoolman.webs.com/apps/blo ... pup-dealio =PUP.Dealio
~ MSI: 8 link(s) detected in 00mn 38s
~ 1705 Legitimates filtered by white list
End of the scan (588 lines in 57mn 37s)(0)