cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

~ Rapport de ZHPDiag v2013.12.10.20 - Nicolas Coolman (10/12/2013)
~ Lancé par Sarah (12/12/2013 22:30:19)
~ Adresse du Site Web http://nicolascoolman.webs.com
~ Forums gratuits d'Assistance à la désinfection : http://nicolascoolman.webs.com/apps/links/
~ Traduit par Nicolas Coolman
~ Etat de la version :
~ Liste blanche : Activée par le programme
~ Elévation des Privilèges : OK
~ User Account Control (UAC): Activate by user


---\\ Navigateurs Internet
MSIE: Internet Explorer v10.0.9200.16736
GCIE: Google Chrome v13.0.782.112 (Defaut)
OBIE: Wacom WebTabletPlugin for Internet Explorer and Netscape v2.1.0.2

---\\ Informations sur les produits Windows
~ Langage: Français
Windows 7 Home Premium, 64-bit Service Pack 1 (Build 7601)
Windows Server License Manager Script : OK
~ Windows(R) 7, OEM_SLP channel
System Locked Preinstallation (OEM_SLP) : OK
Windows ID Activation : OK
~ Windows Partial Key : 9YQTR
Windows License : OK
~ Windows Remaining Initializations Number : 2
Software Protection Service (Protection logicielle) : OK
Windows Automatic Updates : OK
Windows Activation Technologies : OK

---\\ Logiciels de protection du système
avast! Free Antivirus v7.0.1474.0
Spybot - Search & Destroy v1.6.2
Windows Defender W7

---\\ Logiciels d'optimisation du système
CCleaner v3.13 =>Piriform Ltd

---\\ Logiciels de partage PeerToPeer
µTorrent v3.2.0 =>P2P.µTorrent

---\\ Surveillance de Logiciels
Adobe Flash Player 11 Plugin
Adobe Reader X
Java 7 Update 17

---\\ Informations sur le système
~ Processor: Intel64 Family 6 Model 37 Stepping 5, GenuineIntel
~ Operating System: 64 Bits
Boot mode: Normal (Normal boot)
Total RAM: 3948 MB (38% free)
System Restore: Activé (Enable)
System drive C: has 40 GB (20%) free of 198 GB

---\\ Mode de connexion au système
~ Computer Name: SARAH-PC
~ User Name: Sarah
~ All Users Names: Sarah, HomeGroupUser$, Administrateur,
~ Unselected Option: O45,O61,O62,O65,O66,O80,O82,O89
Logged in as Administrator

---\\ Variables d'environnement
~ System Unit : C:\
~ %AppZHP% : C:\Users\Sarah\AppData\Roaming\ZHP\
~ %AppData% : C:\Users\Sarah\AppData\Roaming\
~ %Desktop% : C:\Users\Sarah\Desktop\
~ %Favorites% : C:\Users\Sarah\Favorites\
~ %LocalAppData% : C:\Users\Sarah\AppData\Local\
~ %StartMenu% : C:\Users\Sarah\AppData\Roaming\Microsoft\Windows\Start Menu\
~ %Windir% : C:\Windows\
~ %System% : C:\Windows\System32\

---\\ Enumération des unités disques
C: Hard drive, Flash drive, Thumb drive (Free 40 Go of 198 Go)
D: Hard drive, Flash drive, Thumb drive (Free 243 Go of 243 Go)
E: CD-ROM drive (Not Inserted)
F: CD-ROM drive (Not Inserted)



---\\ Etat du Centre de Sécurité Windows
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified
~ Security Center: 41 Legitimates Filtered in 00mn 00s



---\\ Recherche particulière de fichiers génériques
[MD5.332FEAB1435662FC6C672E25BEB37BE3] - (.Microsoft Corporation - Explorateur Windows.) (.25/02/2011 - 07:19:30.) -- C:\Windows\Explorer.exe [2871808]
[MD5.94355C28C1970635A31B3FE52EB7CEBA] - (.Microsoft Corporation - Application de démarrage de Windows.) (.14/07/2009 - 02:39:52.) -- C:\Windows\System32\Wininit.exe [129024]
[MD5.9706C99DAEBE3FEAC811B239617E98C4] - (.Microsoft Corporation - Extensions Internet pour Win32.) (.12/10/2013 - 09:45:20.) -- C:\Windows\System32\wininet.dll [2241536]
[MD5.1151B1BAA6F350B1DB6598E0FEA7C457] - (.Microsoft Corporation - Application d’ouverture de session Windows.) (.20/11/2010 - 14:25:30.) -- C:\Windows\System32\Winlogon.exe [390656]
[MD5.067FA52BFB59A56110A12312EF9AF243] - (.Microsoft Corporation - Bibliothèque de licences.) (.20/11/2010 - 14:27:26.) -- C:\Windows\System32\sppcomapi.dll [232448]
[MD5.79059559E89D06E8B80CE2944BE20228] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) (.28/09/2013 - 02:09:10.) -- C:\Windows\system32\Drivers\AFD.sys [497152]
[MD5.02062C0B390B7729EDC9E69C680A6F3C] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.14/07/2009 - 02:52:21.) -- C:\Windows\system32\Drivers\atapi.sys [24128]
[MD5.B8BD2BB284668C84865658C77574381A] - (.Microsoft Corporation - CD-ROM File System Driver.) (.14/07/2009 - 00:19:47.) -- C:\Windows\system32\Drivers\Cdfs.sys [92160]
[MD5.F036CE71586E93D94DAB220D7BDF4416] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.20/11/2010 - 10:19:21.) -- C:\Windows\system32\Drivers\Cdrom.sys [147456]
[MD5.9BB2EF44EAA163B29C4A4587887A0FE4] - (.Microsoft Corporation - DFS Namespace Client Driver.) (.20/11/2010 - 10:26:32.) -- C:\Windows\system32\Drivers\DfsC.sys [102400]
[MD5.97BFED39B6B79EB12CDDBFEED51F56BB] - (.Microsoft Corporation - High Definition Audio Bus Driver.) (.20/11/2010 - 11:43:43.) -- C:\Windows\system32\Drivers\HDAudBus.sys [122368]
[MD5.FA55C73D4AFFA7EE23AC4BE53B4592D3] - (.Microsoft Corporation - Pilote de port i8042.) (.14/07/2009 - 00:19:57.) -- C:\Windows\system32\Drivers\i8042prt.sys [105472]
[MD5.AF9B39A7E7B6CAA203B3862582E9F2D0] - (.Microsoft Corporation - IP Network Address Translator.) (.14/07/2009 - 01:10:03.) -- C:\Windows\system32\Drivers\IpNat.sys [116224]
[MD5.A5D9106A73DC88564C825D317CAC68AC] - (.Microsoft Corporation - Windows NT SMB Minirdr.) (.27/04/2011 - 03:40:40.) -- C:\Windows\system32\Drivers\MRxSmb.sys [158208]
[MD5.09594D1089C523423B32A4229263F068] - (.Microsoft Corporation - MBT Transport driver.) (.20/11/2010 - 10:23:20.) -- C:\Windows\system32\Drivers\netBT.sys [261632]
[MD5.B98F8C6E31CD07B2E6F71F7F648E38C0] - (.Microsoft Corporation - Pilote du système de fichiers NT.) (.12/04/2013 - 15:45:08.) -- C:\Windows\system32\Drivers\ntfs.sys [1656680]
[MD5.0086431C29C35BE1DBC43F52CC273887] - (.Microsoft Corporation - Pilote de port parallèle.) (.14/07/2009 - 01:00:41.) -- C:\Windows\system32\Drivers\Parport.sys [97280]
[MD5.471815800AE33E6F1C32FB1B97C490CA] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.20/11/2010 - 11:52:35.) -- C:\Windows\system32\Drivers\Rasl2tp.sys [129536]
[MD5.548260A7B8654E024DC30BF8A7C5BAA4] - (.Microsoft Corporation - SMB Transport driver.) (.14/07/2009 - 01:09:09.) -- C:\Windows\system32\Drivers\smb.sys [93184]
[MD5.DDAD5A7AB24D8B65F8D724F5C20FD806] - (.Microsoft Corporation - TDI Translation Driver.) (.20/11/2010 - 10:21:56.) -- C:\Windows\system32\Drivers\tdx.sys [119296]
[MD5.0D08D2F3B3FF84E433346669B5E0F639] - (.Microsoft Corporation - Pilote de cliché instantané du volume.) (.20/11/2010 - 14:34:02.) -- C:\Windows\system32\Drivers\volsnap.sys [295808]
~ Generic Processes: Scanned in 00mn 01s



---\\ Etat des fichiers cachés (Caché/Total)
~ Mes images (My Pictures) : 1/35
~ Mes musiques (My Musics) : 16/69
~ Mes Favoris (My Favorites) : 1/20
~ Mes Documents (My Documents) : 5/9986
~ Mon Bureau (My Desktop) : 6/1342
~ Menu demarrer (Programs) : 1/53
~ Hidden Files: Scanned in 00mn 22s



---\\ Processus lancés
[MD5.5BB1F77C8AF725A15EC9366498D275BB] - (.ASUS - ATKOSD2.) -- C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [5732992] [PID.2248]
[MD5.5C396DDE6AAFFB64ABC0E0FD88F53553] - (.ASUS - AsScrPro.) -- C:\Windows\AsScrPro.exe [3054136] [PID.2452]
[MD5.F4DCD4912B185C3AAEB92A7040832AD1] - (.Pas de propriétaire - ALU.) -- C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe [51768] [PID.2496]
[MD5.57B4D34232852BFE4453BE571DF90D21] - (.CyberLink - CyberLink MediaLibray Service.) -- C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe [103720] [PID.2624]
[MD5.896A1DB9A972AD2339C2E8569EC926D1] - (.Safer Networking Limited - System settings protector.) -- C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe [2144088] [PID.3228]
[MD5.D98BC64645C2DAEDC1E79B4CCCCBBC8E] - (.ASUS - ATK Media.) -- C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [170624] [PID.3308]
[MD5.5AEBF6FA9805C9101220AA4FB4FA17E7] - (.ASUS - HControlUser.) -- C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [105016] [PID.3320]
[MD5.F477F57732AFFC5460FCC5302DC08394] - (.Pas de propriétaire - Wireless Console 3.) -- C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [1597440] [PID.3448]
[MD5.083649EF692A066880C9326020915AFE] - (.AVAST Software - avast! Antivirus.) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe [4297136] [PID.3688]
[MD5.F7E1CCBAD109329203AACB1E87BE614C] - (.Dropbox, Inc. - Dropbox.) -- C:\Users\Sarah\AppData\Roaming\Dropbox\bin\Dropbox.exe [27776968] [PID.6704]
[MD5.376A9B411BF8B77D5BF84B24D0C7DACD] - (.Google Inc. - Google Chrome.) -- C:\Users\Sarah\AppData\Local\Google\Chrome\Application\chrome.exe [863184] [PID.6580]
[MD5.CBCC1D0C253EC31D94F5CDBE60866F7B] - (.Nicolas Coolman - ZHPDiag.) -- C:\Program Files (x86)\ZHPDiag\ZHPDiag.exe [8291840] [PID.6816]
[MD5.18E5C2F937F9DEB8C282DF66A3761925] - (.ASUS - ASLDR Service.) -- C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe [84536] [PID.1416]
[MD5.7910158929571214A959D5A6D16DD9C0] - (.ASUS - GFNEXSrv.) -- C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe [96896] [PID.1504]
[MD5.8FA553E9AE69808D99C164733A0F9590] - (.AVAST Software - avast! Service.) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe [44808] [PID.1528]
[MD5.ADDA5E1951B90D3D23C56D3CF0622ADC] - (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [65640] [PID.1600]
[MD5.5DC84FEF6A9050019678C30B1D01C8E8] - (...) -- C:\Program Files (x86)\HDD Health\HDDHealthService.exe [17760] [PID.1868]
[MD5.A1C148801B4AF64847AEB9F3AD9594EF] - (.Intel Corporation - Local Manageability Service.) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [262144] [PID.1056]
[MD5.C0BF554D2277F7A4C735D475ADE2E3B2] - (.ASUSTek Computer Inc. - ADSMSrv.) -- C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMSrv.exe [225280] [PID.3076]
[MD5.19E0B5B6202CE85796EA6C0EBB7334DF] - (.Wacom Technology - Wacom Load Agent.) -- C:\Program Files\Tablet\Pen\WacomHost.exe [39808] [PID.4424]
[MD5.41118D920B2B268C0ADC36421248CDCF] - (.Intel Corporation - User Notification Service.) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2314240] [PID.4820]
~ Processes Running: Scanned in 00mn 02s



---\\ Google Chrome, Démarrage,Recherche,Extensions (G0,G1,G2)
C:\Users\Sarah\AppData\Local\Google\Chrome\User Data\Default\Preferences
~ Google Browser: 19 Legitimates Filtered in 00mn 09s



---\\ Mozilla Firefox, Plugins,Demarrage,Recherche,Extensions (P2,M0,M1,M2,M3)
C:\Users\Sarah\AppData\Roaming\Mozilla\Firefox\Profiles\931rstx7.default\prefs.js
C:\Users\Sarah\AppData\Roaming\Mozilla\Firefox\Profiles\931rstx7.default\user.js
M3 - MFPP: Plugins - [Sarah] -- C:\Users\Sarah\AppData\Roaming\Mozilla\Firefox\Profiles\931rstx7.default\searchplugins\askcom.xml
M3 - MFPP: Plugins - [Sarah] -- C:\Users\Sarah\AppData\Roaming\Mozilla\Firefox\Profiles\931rstx7.default\searchplugins\Web Search.xml =>Parasite.Pugi
M0 - MFSP: prefs.js [Sarah - 931rstx7.default] http://feed.snap.do =>Hijacker.SmartBar
M2 - MFEP: prefs.js [Sarah - 931rstx7.default\{ef79f67a-6ad7-4715-a0f8-932fca442023}] [] BittorrentBar_FR Community Toolbar v3.10.0.1 (..) =>P2P.BitTorrent
~ Firefox Browser: 18 Legitimates Filtered in 00mn 00s



---\\ Internet Explorer, Démarrage,Recherche,URLSearchHook, Phishing (R0,R1,R3,R4)
R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.amazon.fr
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://feed.snap.do =>Hijacker.SmartBar
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://feed.snap.do =>Hijacker.SmartBar
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://feed.snap.do =>Hijacker.SmartBar
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://feed.snap.do =>Hijacker.SmartBar
~ IE Browser: 22 Legitimates Filtered in 00mn 00s



---\\ Internet Explorer, Proxy Management (R5)
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.eau.cgeaux.fr:
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll
~ Proxy management: Scanned in 00mn 00s



---\\ Analyse des lignes F0, F1, F2, F3 - IniFiles, Autoloading programs
F2 - REG:system.ini: USERINIT=C:\Windows\system32\userinit.exe,
F2 - REG:system.ini: Shell=C:\Windows\explorer.exe
F2 - REG:system.ini: VMApplet=C:\Windows\System32\SystemPropertiesPerformance.exe
~ Keys: Scanned in 00mn 00s



---\\ Hosts file redirection (O1)
~ Le fichier hosts est sain (The hosts file is clean).
~ Hosts File: Scanned in 00mn 00s
~ Nombre de lignes (Lines number): 21



---\\ Internet Explorer Toolbars (O3)
O3 - Toolbar: (no name) [64Bits] - [HKLM]{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} Clé orpheline
O3 - Toolbar: (no name) [64Bits] - [HKLM]{ae07101b-46d4-4a98-af68-0333ea26e113} Clé orpheline
O3 - Toolbar\WebBrowser: (no name) [64Bits] - [HKCU]{EF79F67A-6AD7-4715-A0F8-932FCA442023} Clé orpheline
~ Toolbar: Scanned in 00mn 00s



---\\ Autres liens utilisateurs (O4)
O4 - GS\Desktop [Public]: Bamboo Dock.lnk . (...) -- C:\Program Files (x86)\Bamboo Dock\Bamboo Dock\Bamboo Dock.exe
O4 - GS\Desktop [Public]: GanttProject.lnk . (...) -- C:\Program Files (x86)\GanttProject-2.6\ganttproject.exe
O4 - GS\Desktop [Public]: µTorrent.lnk . (.BitTorrent, Inc. - µTorrent.) -- C:\Program Files (x86)\uTorrent\uTorrent.exe =>P2P.BitTorrent
O4 - GS\Program [Public]: Prezi Desktop.lnk . (...) -- C:\Program Files (x86)\Prezi Desktop 4\Prezi Desktop.exe
O4 - GS\QuickLaunch [Sarah]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) -- C:\Users\Sarah\AppData\Local\Google\Chrome\Application\chrome.exe
O4 - GS\QuickLaunch [Sarah]: Launch Internet Explorer Browser.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
O4 - GS\QuickLaunch [Sarah]: Spybot - Search & Destroy.lnk . (.Safer Networking Limited - Spybot - Search & Destroy.) -- C:\Program Files (x86)\Spybot - Search & Destroy\SpybotSD.exe
O4 - GS\TaskBar [Sarah]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) -- C:\Users\Sarah\AppData\Local\Google\Chrome\Application\chrome.exe
O4 - GS\Program [Sarah]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
O4 - GS\SystemTools [Sarah]: Internet Explorer (No Add-ons).lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
O4 - GS\Desktop [Sarah]: Data (D) - Raccourci.lnk . (...) -- D:\
O4 - GS\Desktop [Sarah]: Prezi Desktop.lnk . (...) -- C:\Program Files (x86)\Prezi Desktop 4\Prezi Desktop.exe
~ Global Startup: 73 Legitimates Filtered in 00mn 04s



---\\ Applications lancées au démarrage du sytème (O4)
O4 - GS\Startup [Public]: AsusVibeLauncher.lnk . (...) -- C:\Program Files (x86)\ASUS\AsusVibe\AsusVibeLauncher.exe
O4 - HKLM\..\Run: [SmartAudio] . (.Conexant systems, Inc. - SmartAudio Control Panel application.) -- C:\Program Files\CONEXANT\SAII\SAIICpl.exe
O4 - HKLM\..\Run: [ETDWare] C:\Program Files (x86)\Elantech\ETDCtrl.exe (.not file.)
O4 - HKCU\..\Run: [SpybotSD TeaTimer] . (.Safer Networking Limited - System settings protector.) -- C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files\Windows Sidebar\sidebar.exe =>.Microsoft Corporation
O4 - HKLM\..\Wow6432Node\Run: [ATKMEDIA] . (.ASUS - ATK Media.) -- C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
O4 - HKLM\..\Wow6432Node\Run: [HControlUser] . (.ASUS - HControlUser.) -- C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
O4 - HKLM\..\Wow6432Node\Run: [Wireless Console 3] . (.Pas de propriétaire - Wireless Console 3.) -- C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
O4 - HKLM\..\Wow6432Node\Run: [avast] . (.AVAST Software - avast! Antivirus.) -- C:\Program Files\AVAST Software\Avast\avastUI.exe
O4 - HKLM\..\Wow6432Node\Run: [SwitchBoard] . (.Adobe Systems Incorporated - SwitchBoard Server (32 bit).) -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files (x86)\Windows Sidebar\Sidebar.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files (x86)\Windows Sidebar\Sidebar.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-21-3624994208-2833534946-3749945262-1000\..\Run: [SpybotSD TeaTimer] . (.Safer Networking Limited - System settings protector.) -- C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-21-3624994208-2833534946-3749945262-1000\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files\Windows Sidebar\sidebar.exe =>.Microsoft Corporation
~ Application: Scanned in 00mn 00s



---\\ Boutons situés sur la barre d'outils principale d'Internet Explorer (O9)
O9 - Extra button: &Envoyer à OneNote [64Bits] - {2670000A-7350-4f3c-8081-5663EE0C6C49} -- C:\Program Files (x86)\MICROS~2\Office15\ONBttnIE.dll (.not file.)
O9 - Extra button: Cliquer pour appeler Lync [64Bits] - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} . (.Microsoft Corporation - Microsoft Lync.) -- C:\Program Files\Microsoft Office\Office15\lync.exe
O9 - Extra button: Notes &liées OneNote [64Bits] - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} -- C:\Program Files (x86)\MICROS~2\Office15\ONBTTN~1.dll (.not file.)
~ IE Extra Buttons: Scanned in 00mn 00s



---\\ Modification Domaine/Adresses DNS (O17)
O17 - HKLM\System\CCS\Services\Tcpip\..\{2CC2FB31-9584-48F0-8A21-534B24DA0438}: DhcpNameServer = 192.168.1.1 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{FDDB7CF7-E69C-4D6C-AB5E-1834BFF08BAD}: DhcpNameServer = 192.168.0.97 192.168.0.98
O17 - HKLM\System\CCS\Services\Tcpip\..\{FDDB7CF7-E69C-4D6C-AB5E-1834BFF08BAD}: DhcpDomain = girus.com
O17 - HKLM\System\CS1\Services\Tcpip\..\{2CC2FB31-9584-48F0-8A21-534B24DA0438}: DhcpNameServer = 192.168.1.1 192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{FDDB7CF7-E69C-4D6C-AB5E-1834BFF08BAD}: DhcpNameServer = 192.168.0.97 192.168.0.98
O17 - HKLM\System\CS1\Services\Tcpip\..\{FDDB7CF7-E69C-4D6C-AB5E-1834BFF08BAD}: DhcpDomain = girus.com
O17 - HKLM\System\CS2\Services\Tcpip\..\{2CC2FB31-9584-48F0-8A21-534B24DA0438}: DhcpNameServer = 192.168.1.1 192.168.1.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{FDDB7CF7-E69C-4D6C-AB5E-1834BFF08BAD}: DhcpNameServer = 192.168.0.97 192.168.0.98
O17 - HKLM\System\CS2\Services\Tcpip\..\{FDDB7CF7-E69C-4D6C-AB5E-1834BFF08BAD}: DhcpDomain = girus.com
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 192.168.1.1
~ Domain: Scanned in 00mn 00s



---\\ Protocole additionnel (O18)
O18 - Handler: wlpg [64Bits] - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} . (...) --
O18 - Filter: text/xml [64Bits] - {807583E5-5146-11D5-A672-00B0D022E945} . (.Microsoft Corporation - Microsoft Office XML MIME Filter.) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.dll =>.Microsoft Corporation
~ Protocole Additionnel: Scanned in 00mn 00s



---\\ Liste des services NT non Microsoft et non désactivés (O23)
O23 - Service: HDDHealth (HDDHealth) . (...) - C:\Program Files (x86)\HDD Health\HDDHealthService.exe
O23 - Service: Wacom Consumer Service (WTabletServiceCon) . (.Wacom Technology, Corp. - Tablet Service.) - C:\Program Files\Tablet\Pen\WTabletServiceCon.exe
~ Services: 13 Legitimates Filtered in 00mn 12s



---\\ Tâches planifiées en automatique (O39)
O39 - APT:Automatic Planified Task - C:\Windows\Tasks\AutoKMS.job [200]
[MD5.0ED398A4D031B9CFB10E3FEDF97AD836] [APT] [AutoKMS] (...) -- C:\Windows\AutoKMS.exe [614400] =>Trojan.Keygen
[MD5.4A240DC60337CECED5D5DBC4F375CA16] [APT] [{ACBD2AA5-299F-4F61-A95E-5C1FFBA3282F}] (.Irfan Skiljan.) -- C:\Users\Sarah\Downloads\irfanview_plugins_435_setup.exe [10328776]
~ Scheduled Task: 31 Legitimates Filtered in 00mn 10s



---\\ Logiciels installés (O42)
O42 - Logiciel: Les Sims™ 2 Au fil des saisons - (...) [HKLM][64Bits] -- {DFEF49D9-FC95-4301-99B9-2FB91C6ABA06}
~ Logic: 22 Legitimates Filtered in 00mn 01s



---\\ HKCU & HKLM Software Keys
[HKLM\Software\Wow6432Node\Conduit] =>Toolbar.Conduit
~ Key Software: 334 Legitimates Filtered in 00mn 01s



---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43)
O43 - CFD: 25/09/2011 - 14:03:27 - [0,609] ----D C:\Program Files (x86)\Conduit
O43 - CFD: 11/09/2012 - 16:52:12 - [-1755,267] ----D C:\Program Files (x86)\GW2
O43 - CFD: 20/02/2013 - 14:11:08 - [0] ----D C:\ProgramData\Ask
O43 - CFD: 11/09/2012 - 13:17:21 - [0] ----D C:\ProgramData\Babylon =>PUP.Babylon
O43 - CFD: 18/10/2011 - 19:47:09 - [0,001] ----D C:\ProgramData\Partner
O43 - CFD: 20/10/2013 - 18:50:05 - [0] -SH-D C:\ProgramData\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C}
O43 - CFD: 11/09/2012 - 13:17:21 - [0,003] ----D C:\Users\Sarah\AppData\Roaming\Babylon =>PUP.Babylon
O43 - CFD: 23/01/2013 - 21:40:02 - [25,424] ----D C:\Users\Sarah\AppData\Roaming\OpenCandy =>Adware.OpenCandy
O43 - CFD: 11/09/2012 - 13:17:24 - [5,565] ----D C:\Users\Sarah\AppData\Local\Babylon =>PUP.Babylon
O43 - CFD: 21/10/2011 - 20:51:17 - [0] ----D C:\Users\Sarah\AppData\Local\Conduit
~ 213 Dossiers CLSID vides (CLSID Empty Folders)
~ Program Folder: 436 Legitimates Filtered in 02mn 06s



---\\ Derniers fichiers modifiés ou crées sous Windows et System32 (O44)
O44 - LFC:[MD5.377E9FBB56234DE91CD82AA77EEB30CC] - 06/12/2013 - 20:49:42 ---A- . (...) -- C:\Windows\System32\AutoRunFilter.ini [2632]
O44 - LFC:[MD5.62FFE9015B5FCA53AC48EF5612C040EB] - 06/12/2013 - 20:50:35 ---A- . (...) -- C:\Windows\System32\ServiceFilter.ini [1413]
O44 - LFC:[MD5.B3B9295385F4E74D023181E5A24F4D83] - 07/12/2013 - 11:34:18 ----- . (...) -- C:\Windows\KMSEmulator.exe [77824]
O44 - LFC:[MD5.33886C8E1A2DA8FF63211BEC5C84BDDF] - 07/12/2013 - 11:34:45 ---A- . (...) -- C:\Windows\AutoKMS.log [484]
~ Files: 14 Legitimates Filtered in 00mn 08s



---\\ Clé de registre Shell MountPoints2 (MPKS) (O51)
O51 - MPSK:{84af4d43-dbf2-11e0-bece-f46d04894410}\AutoRun\command. (...) -- F:\Autorun.exe (.not file.)
O51 - MPSK:{b4e0271e-25c4-11e1-b608-f46d04894410}\AutoRun\command. (...) -- G:\LaunchU3.exe (.not file.)
O51 - MPSK:{cfccc0b1-2f22-11e2-b299-f46d04894410}\AutoRun\command. (...) -- F:\SETUP.exe (.not file.)
~ Keys: Scanned in 00mn 00s



---\\ Enumération des clés de registre StartupReg (SMSR) (O53)
O53 - SMSR:HKLM\...\startupreg\BambooCore [Key] . (.Pas de propriétaire - BambooDock back-end application.) -- C:\Program Files (x86)\Bamboo Dock\BambooCore.exe
~ SMSR Keys: 18 Legitimates Filtered in 00mn 01s



---\\ Enumération des clés de registre PoliciesSystem (MWPS) (O55)
O55 - MWPS:[HKLM\...\Policies\System] - "EnableUIADesktopToggle"=0
O55 - MWPS:[HKLM\...\Policies\System] - "FilterAdministratorToken"=0
~ MWPS: 16 Legitimates Filtered in 00mn 00s



---\\ Enumération des clés de registre PoliciesExplorer (MWPE) (O56)
O56 - MWPE:[HKLM\...\policies\Explorer] - "NoActiveDesktopChanges"=1
~ MWPE Keys: 3 Legitimates Filtered in 00mn 00s



---\\ Liste des pilotes du système (SDL) (O58)
O58 - SDL:[MD5.46571ED73AE84469DCA53081D33CF3C8] - 15/11/2012 - 13:56:27 ---A- . (.DT Soft Ltd - DAEMON Tools Virtual Bus Driver.) -- C:\Windows\System32\Drivers\dtsoftbus01.sys [283200]
O58 - SDL:[MD5.0E5DA5369A0FCAEA12456DD852545184] - 14/07/2009 - 02:47:48 ---A- . (.Emulex - Storport Miniport Driver for LightPulse HBAs.) -- C:\Windows\System32\Drivers\elxstor.sys [530496]
O58 - SDL:[MD5.0975BF32399A24117E317B5BF1D5D0AA] - 13/04/2010 - 11:15:04 ---A- . (.ELAN Microelectronic Corp. - ETD Control Center.) -- C:\Windows\System32\Drivers\ETD.sys [135560]
O58 - SDL:[MD5.F2523EF6460FC42405B12248338AB2F0] - 10/06/2009 - 21:31:59 ---A- . (.Hauppauge Computer Works, Inc. - Hauppauge WinTV 885 Consumer IR Driver for eHome.) -- C:\Windows\System32\Drivers\hcw85cir.sys [31232]
O58 - SDL:[MD5.46BBE8EA221461A65F18A078528F4B2C] - 03/12/2012 - 15:36:34 ---A- . (.Windows (R) Win 7 DDK provider - Filter Driver for HID-KMDF Interface.) -- C:\Windows\System32\Drivers\hidkmdf.sys [13728]
O58 - SDL:[MD5.E63EF8C3271D014F14E2469CE75FECB4] - 20/07/2009 - 10:29:40 ---A- . (.Pas de propriétaire - Keyboard Filter Driver.) -- C:\Windows\System32\Drivers\kbfiltr.sys [15416]
O58 - SDL:[MD5.1CDADE078F46F10919F21E08E22D227D] - 29/12/2008 - 10:14:28 ---A- . (.Pas de propriétaire - USBCAMD for Sonix UVC.) -- C:\Windows\System32\Drivers\sncduvc.sys [35456]
O58 - SDL:[MD5.2114518E55B380A3ACC28B2C27FD499A] - 20/08/2009 - 03:41:38 ---A- . (.Pas de propriétaire - UVC Camera Streaming Driver.) -- C:\Windows\System32\Drivers\snp2uvc.sys [1800192]
O58 - SDL:[MD5.41AC348DBD378F618CB4FDEE54270692] - 06/02/2013 - 06:42:08 ---A- . (.DEVGURU Co., LTD.(www.devguru.co.kr) - SAMSUNG USB Composite Device Driver (MSS Ver.3).) -- C:\Windows\System32\Drivers\ssudbus.sys [102936]
O58 - SDL:[MD5.EA8F41484CCC5BA6A1455C2AD3D1BE3C] - 04/06/2013 - 08:15:00 ---A- . (.DEVGURU Co., LTD.(www.devguru.co.kr) - SAMSUNG Android Modem Device Driver (MSS Ver.3).) -- C:\Windows\System32\Drivers\ssudmdm.sys [203672]
O58 - SDL:[MD5.F3817967ED533D08327DC73BC4D5542A] - 14/07/2009 - 02:45:55 ---A- . (.Promise Technology - Promise SuperTrak EX Series Driver for Windows.) -- C:\Windows\System32\Drivers\stexstor.sys [24656]
O58 - SDL:[MD5.C45A3E051C65106A28982CAED125F855] - 06/08/2009 - 22:17:34 ---A- . (...) -- C:\Windows\System32\Drivers\TurboB.sys [13784]
~ Drivers: 16 Legitimates Filtered in 00mn 20s



---\\ Liste des outils de désinfection (LATC) (O63)
O63 - Logiciel: ZHPDiag 2013 - (.Nicolas Coolman.) [HKLM] -- ZHPDiag_is1 =>.Nicolas Coolman
~ ADS: Scanned in 00mn 00s



---\\ Menu de démarrage Internet (SMI) (O68)
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- C:\Users\Sarah\AppData\Local\Google\Chrome\Application\chrome.exe
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe
~ Keys: Scanned in 00mn 00s



---\\ Recherche d'infection sur les navigateurs internet (SBI) (O69)
O69 - SBI: C:\Users\Sarah\AppData\Roaming\Mozilla\Firefox\Profiles\931rstx7.default\searchplugins\askcom.xml
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852..clientLogIsEnabled", true);
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852..clientLogServiceUrl", "http://clientlog.users.conduit.com/ClientDiagnostics.asmx/ReportDiagnosticsEvent");
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852..uninstallLogServiceUrl", "http://uninstall.users.conduit.com/Uninstall.asmx/RegisterToolbarUninstallation");
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.AboutPrivacyUrl", "http://www.conduit.com/privacy/Default.aspx");
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.AppTrackingLastCheckTime", "Tue Oct 11 2011 12:56:01 GMT+0200");
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.CTID", "CT2849852");
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.CurrentServerDate", "24-10-2011");
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.DSInstall", true);
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.DialogsAlignMode", "LTR");
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.DialogsGetterLastCheckTime", "Sun Oct 23 2011 15:31:16 GMT+0200");
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.DownloadReferralCookieData", "");
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.EMailNotifierPollDate", "Sun Oct 23 2011 20:49:18 GMT+0200");
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.FeedLastCount129349795937781608", 485);
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.FeedPollDate129313974171006416", "Fri Oct 21 2011 21:41:39 GMT+0200");
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.FeedPollDate129313975698350231", "Fri Oct 21 2011 21:41:39 GMT+0200");
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.FeedPollDate129313976370850190", "Fri Oct 21 2011 21:41:39 GMT+0200");
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.FeedPollDate129313976648818968", "Fri Oct 21 2011 21:41:40 GMT+0200");
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.FeedPollDate129313977444757117", "Fri Oct 21 2011 21:41:40 GMT+0200");
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.FeedPollDate129313980389131455", "Fri Oct 21 2011 21:41:40 GMT+0200");
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.FeedPollDate129313980655381977", "Fri Oct 21 2011 21:41:40 GMT+0200");
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.FeedPollDate129313980886163259", "Fri Oct 21 2011 21:41:40 GMT+0200");
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.FeedPollDate129313981234756535", "Fri Oct 21 2011 21:41:40 GMT+0200");
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.FeedPollDate129313983226631720", "Fri Oct 21 2011 21:41:40 GMT+0200");
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.FeedPollDate129313983607725691", "Fri Oct 21 2011 21:41:40 GMT+0200");
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.FeedTTL129313974171006416", 10);
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.FeedTTL129313977444757117", 15);
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.FeedTTL129313980655381977", 5);
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.FeedTTL129313981234756535", 5);
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.FirstServerDate", "26-9-2011");
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.FirstTime", true);
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.FirstTimeFF3", true);
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.FixPageNotFoundErrors", false);
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.GroupingServerCheckInterval", 1440);
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.GroupingServiceUrl", "http://grouping.services.conduit.com/");
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.HPInstall", false);
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.HasUserGlobalKeys", true);
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.HomePageProtectorEnabled", false);
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.HomepageBeforeUnload", "chrome://branding/locale/browserconfig.properties");
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.Initialize", true);
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.InitializeCommonPrefs", true);
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.InstallationAndCookieDataSentCount", 3);
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.InstallationType", "UnknownIntegration");
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.InstalledDate", "Mon Sep 26 2011 18:37:01 GMT+0200");
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.IsAlertDBUpdated", true);
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.IsGrouping", false);
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.IsInitSetupIni", true);
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.IsMulticommunity", false);
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.IsOpenThankYouPage", true);
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.IsOpenUninstallPage", false);
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.LanguagePackLastCheckTime", "Mon Oct 24 2011 14:45:09 GMT+0200");
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.LanguagePackReloadIntervalMM", 1440);
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.LanguagePackServiceUrl", "http://translation.users.conduit.com/Translation.ashx");
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.LastLogin_3.7.0.6", "Mon Oct 24 2011 21:18:36 GMT+0200");
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.LatestVersion", "3.7.0.6");
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.Locale", "fr");
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.MCDetectTooltipHeight", "83");
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.MCDetectTooltipShow", false);
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.MCDetectTooltipUrl", "http://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.MCDetectTooltipWidth", "295");
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.MyStuffEnabledAtInstallation", true);
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.OriginalFirstVersion", "3.7.0.6");
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.RadioShrinked", "shrinked");
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.RadioShrinkedFromSetup", true);
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.SHRINK_TOOLBAR", 0);
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.SearchBoxWidth", 372);
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.SearchCaption", "BittorrentBar_FR Customized Web Search"); =>P2P.BitTorrent
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.SearchEngineBeforeUnload", "chrome://browser-region/locale/region.properties");
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.SearchFromAddressBarIsInit", true);
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.SearchFromAddressBarUrl", "http://search.conduit.com/ResultsExt.aspx?ctid=CT2849852&q=");
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.SearchInNewTabEnabled", true);
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.SearchInNewTabIntervalMM", 1440);
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.SearchInNewTabLastCheckTime", "Mon Oct 24 2011 15:55:02 GMT+0200");
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.SearchInNewTabServiceUrl", "http://newtab.conduit-hosting.com/newtab/?ctid=EB_TOOLBAR_ID"); =>Toolbar.Conduit
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.SearchInNewTabUsageUrl", "http://usage.hosting.toolbar.conduit-services.com/usage.ashx?ctid=EB_TOOLBAR_ID"); =>Toolbar.Conduit
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.SearchProtectorEnabled", false); =>Toolbar.Conduit
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.SearchProtectorToolbarDisabled", false); =>Toolbar.Conduit
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.SendProtectorDataViaLogin", true);
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.ServiceMapLastCheckTime", "Mon Oct 24 2011 14:45:08 GMT+0200");
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.SettingsLastCheckTime", "Mon Oct 24 2011 21:18:35 GMT+0200");
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.SettingsLastUpdate", "1313478220");
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.TBHomePageUrl", "http://search.conduit.com/?ctid=CT2849852&SearchSource=13");
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.ThirdPartyComponentsInterval", 504);
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.ThirdPartyComponentsLastCheck", "Mon Oct 17 2011 20:44:11 GMT+0200");
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.ThirdPartyComponentsLastUpdate", "1255344667");
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.ToolbarShrinkedFromSetup", true);
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.TrusteLinkUrl", "http://trust.conduit.com/CT2849852");
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.TrustedApiDomains", "conduit.com,conduit-hosting.com,conduit-services.com,client.conduit-storage.com,OurToolb[...] =>Toolbar.Conduit
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.UserID", "UN24921316252349684");
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.ValidationData_Search", 1);
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.ValidationData_Toolbar", 2);
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.WeatherNetwork", "");
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.WeatherPollDate", "Sun Oct 23 2011 20:32:19 GMT+0200");
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.WeatherUnit", "C");
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.alertChannelId", "1241893");
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.approveUntrustedApps", false);
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.backendstorage.cbfirsttime", "5765642053657020323820323031312030393A33393A313320474D542B30323030");
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.backendstorage.pairingkey", "46343834353533304235334136324143303239353530464533393742464130393735314341384437[...]
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.backendstorage.scriptsource", "687474703A2F2F3132372E302E302E313A31303030302F6775692F");
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.backendstorage.url_history", "687474703A2F2F7777772E73747265616D697A2E636F6D2F696E6465782E706870");
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.backendstorage.url_history_time", "31333139323236363030333930");
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.backendstorage.uttorrents", "7B226275696C64223A32353638312C226C6162656C223A5B5D2C22746F7272656E7473223A5B5B22[...]
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.components.1000034", false);
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.components.1000234", false);
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.components.129349795936062815", false);
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.components.129349795936375318", false);
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.components.129349795937781608", false);
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.components.129349795937937859", false);
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.components.129349795937937860", false);
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.components.129431554657187564", false);
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.components.129544672056371179", false);
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.generalConfigFromLogin", "{\"ApiMaxAlerts\":\"12\",\"SocialDomains\":\"social.conduit.com;apps.conduit.com;se[...]
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.globalFirstTimeInfoLastCheckTime", "Mon Oct 24 2011 21:18:36 GMT+0200");
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.homepageProtectorEnableByLogin", true);
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.initDone", true);
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.isAppTrackingManagerOn", true);
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.isFirstRadioInstallation", false);
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.myStuffEnabled", true);
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.myStuffPublihserMinWidth", 400);
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.myStuffSearchUrl", "http://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOrigin=29&ctid=EB_TOOLBAR_ID&oct[...]
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.myStuffServiceIntervalMM", 1440);
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.myStuffServiceUrl", "http://mystuff.conduit-services.com/MyStuffService.ashx?ComponentId=EB_MY_STUFF_INSTANCE[...] =>Toolbar.Conduit
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.oldAppsList", "129349795935594062,129349795935906563,111,1000234,129349795936062815,1000034,12943155465718756[...]
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.revertSettingsEnabled", true);
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.searchProtectorDialogDelayInSec", 10); =>Toolbar.Conduit
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.searchProtectorEnableByLogin", true); =>Toolbar.Conduit
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.testingCtid", "");
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.toolbarAppMetaDataLastCheckTime", "Mon Oct 24 2011 15:55:02 GMT+0200");
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.toolbarContextMenuLastCheckTime", "Mon Oct 24 2011 21:18:36 GMT+0200");
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CT2849852.usagesFlag", 2);
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CommunityToolbar.ETag.http://alerts.conduit-services.com/root/1241893/1237566/FR", "\"0\""); =>Toolbar.Conduit
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CommunityToolbar.ETag.http://appsmetadata.toolbar.conduit-services.com/?ctid=CT2849852", "\"0\""); =>Toolbar.Conduit
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CommunityToolbar.ETag.http://contextmenu.toolbar.conduit-services.com/?name=GottenApps&locale=fr", "kLE3EoupXhh+3ayzzXG[...] =>Toolbar.Conduit
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CommunityToolbar.ETag.http://contextmenu.toolbar.conduit-services.com/?name=OtherApps&locale=fr", "TA2mKqdBHssHhc1ui1OG[...] =>Toolbar.Conduit
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CommunityToolbar.ETag.http://contextmenu.toolbar.conduit-services.com/?name=SharedApps&locale=fr", "ev2KSD8BFMMs2dxsoAq[...] =>Toolbar.Conduit
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CommunityToolbar.ETag.http://contextmenu.toolbar.conduit-services.com/?name=Toolbar&locale=fr", "hOlcV9OHcX1OR8Faic1Xmg[...] =>Toolbar.Conduit
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CommunityToolbar.ETag.http://dynamicdialogs.alert.conduit-services.com/alert/dlg.pkg", "\"07879643d3acc1:0\""); =>Toolbar.Conduit
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CommunityToolbar.ETag.http://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.7.0.6", "\"0ee90707f77cc1:0\""); =>Toolbar.Conduit
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CommunityToolbar.ETag.http://servicemap.conduit-services.com/Toolbar/?ownerId=CT2849852", "\"634531597989330000\""); =>Toolbar.Conduit
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CommunityToolbar.ETag.http://settings.toolbar.conduit-services.com/?ctid=CT2849852&octid=CT2849852", "\"1313478220\""); =>Toolbar.Conduit
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CommunityToolbar.ETag.http://translation.toolbar.conduit-services.com/?locale=EB_LOCALE", "\"199de7c4c12c1450eed0bd9bf6[...] =>Toolbar.Conduit
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CommunityToolbar.ETag.http://translation.toolbar.conduit-services.com/?locale=fr", "\"864b96cefc08a4496f11285e75305e25\[...] =>Toolbar.Conduit
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CommunityToolbar.LatestLibsPath", "file:///C:\\Users\\Sarah\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\931rstx7.def[...]
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CommunityToolbar.LatestToolbarVersionInstalled", "3.7.0.6");
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "");
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CommunityToolbar.ToolbarsList", "CT2849852");
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CommunityToolbar.ToolbarsList2", "CT2849852");
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CommunityToolbar.ToolbarsList4", "CT2849852");
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CommunityToolbar.facebook.settingsLastCheckTime", "Sun Oct 23 2011 14:06:19 GMT+0200");
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CommunityToolbar.globalUserId", "dae20a29-f298-4e5e-b3ed-15fd39a6dfca");
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true);
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true);
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CommunityToolbar.notifications.alertDialogsGetterLastCheckTime", "Mon Oct 24 2011 21:18:36 GMT+0200");
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CommunityToolbar.notifications.alertInfoInterval", 1440);
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CommunityToolbar.notifications.alertInfoLastCheckTime", "Mon Oct 24 2011 14:45:17 GMT+0200");
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CommunityToolbar.notifications.clientsServerUrl", "http://alert.client.conduit.com");
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CommunityToolbar.notifications.locale", "en");
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CommunityToolbar.notifications.loginIntervalMin", 1440);
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CommunityToolbar.notifications.loginLastCheckTime", "Mon Oct 24 2011 15:55:02 GMT+0200");
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CommunityToolbar.notifications.loginLastUpdateTime", "1313487611");
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CommunityToolbar.notifications.messageShowTimeSec", 20);
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CommunityToolbar.notifications.servicesServerUrl", "http://alert.services.conduit.com");
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CommunityToolbar.notifications.showTrayIcon", false);
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CommunityToolbar.notifications.userCloseIntervalMin", 300);
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CommunityToolbar.notifications.userId", "fc4ada3f-448c-4096-817a-53e7956fcf03");
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CommunityToolbar.originalHomepage", "chrome://branding/locale/browserconfig.properties");
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("CommunityToolbar.originalSearchEngine", "chrome://browser-region/locale/region.properties");
O69 - SBI: prefs.js [Sarah - 931rstx7.default] user_pref("extensions.asktb.ff-original-keyword-url", "http://feed.snap.do/?publisher=SnapdoOpenCandy&dpid=SnapdoOpenCandy&co=FR&u[...] =>Adware.OpenCandy
O69 - SBI: SearchScopes [HKCU] {006ee092-9658-4fd6-bd8e-a21a348e59f5} - (Web Search) - http://feed.snap.do =>Hijacker.SmartBar
O69 - SBI: SearchScopes [HKCU] {00D6C074-C7C1-4118-93A3-8F1D5FF6C94F} - (Ask Search) - http://websearch.ask.com =>Toolbar.Ask
O69 - SBI: SearchScopes [HKCU] {afdbddaa-5d3f-42ee-b79c-185a7020515b} - (BittorrentBar_FR Customized Web Search) - http://search.conduit.com =>P2P.BitTorrent
O69 - SBI: SearchScopes [HKCU] {B3B3A6AC-74EC-BD56-BCDB-EFA4799FB9DF} [DefaultScope] - (Amazon) - http://www.amazon.frch
~ Keys: Scanned in 00mn 00s



---\\ Recherche particulière à la racine du système (SPRF) (O84)
[MD5.90E1D86D979B92738A47D7072CB22DA8] [SPRF][07/07/2010] (...) -- C:\ProgramData\FullRemove.exe [131472]
[MD5.4272BB1D2B577D5917DA0AD9954C4A97] [SPRF][06/12/2013] (.Spotify Ltd - Spotify.) -- C:\Users\Sarah\AppData\Local\Temp\SpotifyUninstall.exe [5951488]
~ Files: 6 Legitimates Filtered in 00mn 00s



---\\ Etat général des services non Microsoft (EGS) (SR=Running, SS=Stopped)
SS - | Demand 11/12/2013 257416 | (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
SS - | Demand 05/05/2013 1045256 | (FLEXnet Licensing Service) . (.Acresso Software Inc..) - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
SS - | Auto 12/01/2011 135664 | (gupdate) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
SS - | Demand 12/01/2011 135664 | (gupdatem) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
SS - | Demand 12/01/2011 182768 | (gusvc) . (.Google.) - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
SS - | Disabled 04/10/2013 2542416 | (MaConfigAgent) . (.CybelSoft.) - C:\Program Files\ma-config.com\MaConfigAgent.exe
SS - | Auto 14/07/2009 27136 | C:\Windows\system32\HPZinw12.dll (Net Driver HPZ12) . (.Hewlett-Packard.) - C:\Windows\System32\svchost.exe
SS - | Auto 14/07/2009 27136 | C:\Windows\system32\HPZipm12.dll (Pml Driver HPZ12) . (.Hewlett-Packard.) - C:\Windows\System32\svchost.exe
SS - | Auto 26/01/2009 1153368 | (SBSDWSCService) . (.Safer Networking Ltd..) - C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
SS - | Auto 08/01/2013 161536 | (SkypeUpdate) . (.Skype Technologies.) - C:\Program Files (x86)\Skype\Updater\Updater.exe
SS - | Demand 19/02/2010 517096 | (SwitchBoard) . (.Adobe Systems Incorporated.) - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
SS - | Demand 06/08/2009 118672 | (TurboBoost) . (.Intel(R) Corporation.) - C:\Program Files\Intel\TurboBoost\TurboBoost.exe

SR - | Auto 10/05/2013 65640 | (AdobeARMservice) . (.Adobe Systems Incorporated.) - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
SR - | Demand 31/03/2008 225280 | (ADSMService) . (.ASUSTek Computer Inc..) - C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMSrv.exe
SR - | Auto 30/11/2010 379520 | (AFBAgent) . (.ASUSTeK Computer Inc..) - C:\Windows\system32\FBAgent.exe
SR - | Auto 09/03/2011 203776 | (AMD External Events Utility) . (.AMD.) - C:\Windows\System32\atiesrxx.exe
SR - | Auto 16/06/2009 84536 | (ASLDRService) . (.ASUS.) - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
SR - | Auto 15/12/2009 96896 | (ATKGFNEXSrv) . (.ASUS.) - C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
SR - | Auto 30/10/2012 44808 | (avast! Antivirus) . (.AVAST Software.) - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
SR - | Auto 08/03/2013 17760 | (HDDHealth) . (...) - C:\Program Files (x86)\HDD Health\HDDHealthService.exe
SR - | Auto 01/10/2009 262144 | (LMS) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
SR - | Auto 01/10/2009 2314240 | (UNS) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
SR - | Auto 14/07/2009 27136 | C:\Program Files (x86)\Windows Defender\mpsvc.dll (WinDefend) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe
SR - | Auto 10/07/1658 0 | (WMPNetworkSvc) . (...) - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe =>.Microsoft Corporation
SR - | Auto 11/12/2012 619904 | (WTabletServiceCon) . (.Wacom Technology, Corp..) - C:\Program Files\Tablet\Pen\WTabletServiceCon.exe
SR - | Auto 14/07/2009 27136 | C:\Windows\System32\wuaueng.dll (wuauserv) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe

~ Services: Scanned in 01mn 00s



---\\ Scan Additionnel (O88)
Database Version : 13013 - (10/12/2013)
Clés trouvées (Keys found) : 19
Valeurs trouvées (Values found) : 1
Dossiers trouvés (Folders found) : 10
Fichiers trouvés (Files found) : 3

[HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}] =>Hijacker.SmartBar
[HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}] =>Hijacker.SmartBar
[HKLM\Software\Wow6432Node\Microsoft\Tracing\SnapDo_RASAPI32] =>Hijacker.SmartBar
[HKLM\Software\Wow6432Node\Microsoft\Tracing\SnapDo_RASMANCS] =>Hijacker.SmartBar
[HKLM\Software\Classes\CLSID\{ae07101b-46d4-4a98-af68-0333ea26e113}] =>Adware.Agent
[HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}] =>Toolbar.Conduit
[HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}] =>Toolbar.Conduit
[HKLM\Software\Wow6432Node\Google\Chrome\Extensions\elhjaoldnkkbifioodjndkijecdeinld] =>Toolbar.Conduit
[HKCU\Software\AppDataLow\Software\PriceGong] =>Adware.PriceGong
[HKLM\Software\Classes\Prod.cap] =>PUP.Babylon
[HKLM\Software\Classes\esri3DAnalystUI.DeltaXYZSketch3DMenuItem] =>Toolbar.DeltaSearch
[HKLM\Software\Classes\esri3DAnalystUI.DeltaXYZSketch3DMenuItem.1] =>Toolbar.DeltaSearch
[HKLM\Software\Classes\esriCadastralUI.DeltaXYConstructionMenuItem] =>Toolbar.DeltaSearch
[HKLM\Software\Classes\esriCadastralUI.DeltaXYConstructionMenuItem.1] =>Toolbar.DeltaSearch
[HKLM\Software\Wow6432Node\Classes\esri3DAnalystUI.DeltaXYZSketch3DMenuItem] =>Toolbar.DeltaSearch
[HKLM\Software\Wow6432Node\Classes\esri3DAnalystUI.DeltaXYZSketch3DMenuItem.1] =>Toolbar.DeltaSearch
[HKLM\Software\Wow6432Node\Classes\esriCadastralUI.DeltaXYConstructionMenuItem] =>Toolbar.DeltaSearch
[HKLM\Software\Wow6432Node\Classes\esriCadastralUI.DeltaXYConstructionMenuItem.1] =>Toolbar.DeltaSearch
[HKLM\Software\Wow6432Node\Classes\CLSID\{3c471948-f874-49f5-b338-4f214a2ee0b1}] =>Toolbar.Conduit^
C:\Users\Sarah\AppData\Roaming\Mozilla\Firefox\Profiles\931rstx7.default\extensions\{ef79f67a-6ad7-4715-a0f8-932fca442023} =>P2P.BitTorrent^
C:\ProgramData\Babylon =>PUP.Babylon^
C:\Users\Sarah\AppData\Roaming\Babylon =>PUP.Babylon^
C:\Users\Sarah\AppData\Roaming\OpenCandy =>Adware.OpenCandy^
C:\Users\Sarah\AppData\Local\Babylon =>PUP.Babylon^
C:\Program Files (x86)\Conduit =>Toolbar.Conduit
C:\ProgramData\Partner =>Spyware.Partner
C:\Users\Sarah\AppData\Local\Conduit =>Toolbar.Conduit
C:\Users\Sarah\AppData\LocalLow\Conduit =>Toolbar.Conduit
C:\Users\Sarah\AppData\LocalLow\PriceGong =>Adware.PriceGong
C:\Windows\AutoKMS.exe =>Trojan.Keygen^
[HKLM\Software\Wow6432Node\Conduit] =>Toolbar.Conduit^
C:\Windows\KMSEmulator.exe =>Hijacker.Windows
~ Additionnel Scan: 470193 Items scanned in 01mn 02s



---\\ Récapitulatif des détections trouvées sur votre station
~ http://nicolascoolman.webs.com/apps/blog/show/26632288-parasite-pugi =>Parasite.Pugi
~ http://nicolascoolman.webs.com/apps/blog/show/26990375-hijacker-smartbar =>Hijacker.SmartBar
~ http://nicolascoolman.webs.com/apps/blog/show/29507721-toolbar-conduit =>Toolbar.Conduit
~ http://nicolascoolman.webs.com/apps/blog/show/26627369-toolbar-babylon =>PUP.Babylon
~ http://nicolascoolman.webs.com/apps/blog/show/26770694-adware-opencandy =>Adware.OpenCandy
~ http://nicolascoolman.webs.com/apps/blog/show/28927746-toolbar-ask =>Toolbar.Ask
~ http://nicolascoolman.webs.com/apps/blog/show/26666995-adware-pricegong =>Adware.PriceGong
~ http://nicolascoolman.webs.com/apps/blog/show/27875657-toolbar-deltasearch =>Toolbar.DeltaSearch
~ http://nicolascoolman.webs.com/apps/blog/show/28193283-spyware-partner =>Spyware.Partner
~ MSI: 9 link(s) detected in 01mn 02s



~ 1636 Legitimates filtered by white list
End of the scan (661 lines in 06mn 31s)(0)

Publicité


Signaler le contenu de ce document

Publicité