Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Rapport de ZHPDiag v2013.8.10.15 par Nicolas Coolman, Update du 2013-08-10
- Run by jimmy at 2013-08-12 17:09:20
- WebSite: http://nicolascoolman.webs.com
- State :
- WhiteList : Enable
- High Elevated Privileges : OK
- UAC : Activate by user
- ---\\ Web Browser
- MSIE: Internet Explorer v10.0.9200.16635
- MFIE: Mozilla Firefox 22.0 (Defaut)
- ---\\ Windows Product Information
- ~ Langage: Français
- Windows 8 Business Edition, 64-bit (Build 9200)
- Windows Server License Manager Script : OK
- ~ ion : Windows(R) Operating System, RETAIL channel
- Windows ID Activation : OK
- ~ Windows Partial Key : MDR9V
- Windows License : OK
- ~ Windows Remaining Initializations Number : 1000
- Software Protection Service (Protection logicielle) : OK
- Windows Automatic Updates : OK
- Windows Activation Technologies : OK
- ---\\ System Protection
- Kaspersky Internet Security 2013 v13.0.1.4190
- Windows Defender W8
- ---\\ System Optimizer
- CCleaner v4.02 =>Piriform Ltd
- ---\\ Peer To Peer (P2P)
- µTorrent v2.2.1 =>P2P.µTorrent
- ---\\ Software Update
- Adobe Flash Player 11 Plugin
- Java 7 Update 21
- Java 7 Update 25
- ---\\ System Information
- ~ Processor: Intel64 Family 6 Model 58 Stepping 9, GenuineIntel
- ~ Operating System: 64 Bits
- Boot mode: Normal (Normal boot)
- Total RAM: 8150 MB (40% free)
- System Restore: Activé (Enable)
- System drive C: has 70 GB (29%) free of 238 GB
- ---\\ Logged in mode
- ~ Computer Name: TOUR-JIMMY
- ~ User Name: jimmy
- ~ All Users Names: UpdatusUser, jimmy, Administrateur,
- ~ Unselected Option: O45,O61,O62,O65,O66,O80,O82,O89
- Logged in as Administrator
- ---\\ Environnement Variables
- ~ System Unit : C:\
- ~ %AppData% : C:\Users\jimmy\AppData\Roaming\
- ~ %Desktop% : A:\Users\jimmy\Desktop\
- ~ %Favorites% : C:\Users\jimmy\Favorites\
- ~ %LocalAppData% : C:\Users\jimmy\AppData\Local\
- ~ %StartMenu% : C:\Users\jimmy\AppData\Roaming\Microsoft\Windows\Start Menu\
- ~ %Windir% : C:\Windows\
- ~ %System% : C:\Windows\System32\
- ---\\ DOS/Devices
- A:\ Hard drive, Flash drive, Thumb drive (Free 1804 Go of 1863 Go)
- C:\ Hard drive, Flash drive, Thumb drive (Free 70 Go of 238 Go)
- D:\ Hard drive, Flash drive, Thumb drive (Free 546 Go of 932 Go)
- E:\ CD-ROM drive (Not Inserted)
- F:\ CD-ROM drive (Free 0 Go of 0 Go)
- ---\\ Security Center & Tools Informations
- [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified
- ~ Security Center: 29 Legitimates Filtered in 00mn 00s
- ---\\ Recherche particulière de fichiers génériques
- [MD5.0E8E6463F81C80AFBED533E0F1F8895D] - (.Microsoft Corporation - Explorateur Windows.) (.2013-06-01 - 06:34:21.) -- C:\Windows\Explorer.exe [2391280]
- [MD5.FE9AB232B56A12224E8A3F3F9878C9A3] - (.Microsoft Corporation - Application de démarrage de Windows.) (.2012-07-25 - 22:08:50.) -- C:\Windows\System32\Wininit.exe [132608]
- [MD5.FAF6EC2460AD5FBBD38D8E1AE28B0D77] - (.Microsoft Corporation - Extensions Internet pour Win32.) (.2013-06-11 - 18:26:20.) -- C:\Windows\System32\wininet.dll [2241024]
- [MD5.BCF2036A0DD579E47C008C133550283E] - (.Microsoft Corporation - Application d’ouverture de session Windows.) (.2012-10-11 - 00:46:58.) -- C:\Windows\System32\Winlogon.exe [517120]
- [MD5.9448F5740A037EC0C18F0E9177232DD0] - (.Microsoft Corporation - Bibliothèque de licences.) (.2012-07-25 - 22:07:20.) -- C:\Windows\System32\sppcomapi.dll [273408]
- [MD5.36D6A3201721558A8AFBCC09C2DA4C2C] - (.Microsoft Corporation - Pilote de fonction connexe pour WinSock.) (.2012-11-05 - 22:53:44.) -- C:\Windows\system32\Drivers\AFD.sys [560640]
- [MD5.A721FF570C2387E383BDDEA9632863C9] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.2012-07-26 - 00:00:48.) -- C:\Windows\system32\Drivers\atapi.sys [25840]
- [MD5.990B1BABE6E81FB18E65A87EBEFB1772] - (.Microsoft Corporation - CD-ROM File System Driver.) (.2012-07-25 - 21:30:10.) -- C:\Windows\system32\Drivers\Cdfs.sys [108544]
- [MD5.339BFF85D788268752DA8C9644B188EE] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.2012-07-25 - 21:26:36.) -- C:\Windows\system32\Drivers\Cdrom.sys [174080]
- [MD5.09D9EB9E7898F8E6561473A20CC808B9] - (.Microsoft Corporation - DFS Namespace Client Driver.) (.2012-07-25 - 21:26:53.) -- C:\Windows\system32\Drivers\DfsC.sys [118784]
- [MD5.7D87B5B6C7188D553E11B59DC7F0B111] - (.Microsoft Corporation - High Definition Audio Bus Driver.) (.2012-09-20 - 01:08:44.) -- C:\Windows\system32\Drivers\HDAudBus.sys [71168]
- [MD5.C9E9CBF73AFFBFE3E801EFB516787BA3] - (.Microsoft Corporation - Pilote de port i8042.) (.2012-07-25 - 21:28:51.) -- C:\Windows\system32\Drivers\i8042prt.sys [112640]
- [MD5.3969B9C218DD3FAA9F4ED2FFC3651C02] - (.Microsoft Corporation - IP Network Address Translator.) (.2012-07-25 - 21:23:01.) -- C:\Windows\system32\Drivers\IpNat.sys [145920]
- [MD5.93179D48066918323628CB016D8C94DC] - (.Microsoft Corporation - Minirdr SMB Windows NT.) (.2013-02-05 - 17:29:09.) -- C:\Windows\system32\Drivers\MRxSmb.sys [370688]
- [MD5.7CEC25C682D319D484630B3952C31A11] - (.Microsoft Corporation - MBT Transport driver.) (.2012-07-25 - 21:24:28.) -- C:\Windows\system32\Drivers\netBT.sys [331776]
- [MD5.76929F4A69E425911A63B407E26C2589] - (.Microsoft Corporation - Pilote du système de fichiers NT.) (.2013-02-02 - 05:54:54.) -- C:\Windows\system32\Drivers\ntfs.sys [1933544]
- [MD5.4563DAF8C6A740AD7F501E219BD10766] - (.Microsoft Corporation - Pilote de port parallèle.) (.2012-07-25 - 21:29:53.) -- C:\Windows\system32\Drivers\Parport.sys [105984]
- [MD5.A14D625C5AEE5FFE0F47D1A1D419FAAE] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.2012-07-25 - 21:23:17.) -- C:\Windows\system32\Drivers\Rasl2tp.sys [124928]
- [MD5.B2A3AD74FF2E2FFA73AF2567108231B3] - (.Microsoft Corporation - Redirecteur de périphérique de Microsoft RDP.) (.2012-07-25 - 21:25:18.) -- C:\Windows\system32\Drivers\rdpdr.sys [179712]
- [MD5.73DC722CE5DF26D7638CE2446F2655C7] - (.Microsoft Corporation - TDI Translation Driver.) (.2012-07-26 - 00:26:47.) -- C:\Windows\system32\Drivers\tdx.sys [117248]
- [MD5.78A5BBA3819FFFC62FFEC3E2220D102D] - (.Microsoft Corporation - Pilote de cliché instantané du volume.) (.2013-06-01 - 06:26:33.) -- C:\Windows\system32\Drivers\volsnap.sys [327936]
- ~ Generic Processes: Scanned in 00mn 00s
- ---\\ Etat des fichiers cachés (Caché/Total)
- ~ Mes images (My Pictures) : 1/2
- ~ Mes musiques (My Musics) : 1/10
- ~ Mes Favoris (My Favorites) : 1/5
- ~ Mes Documents (My Documents) : 1/819
- ~ Mon Bureau (My Desktop) : 3/1806
- ~ Menu demarrer (Programs) : 1/36
- ~ Hidden Files: Scanned in 00mn 00s
- ---\\ Processus lancés
- [MD5.85206BFDD3388883F49CF4E3A68B7507] - (.Stardock - ObjectDock.) -- C:\Program Files (x86)\Stardock\ObjectDockPlus2\ObjectDock.exe [4142448] [PID.8544]
- [MD5.587EFD6A3A30A35A27904D21AE1FB882] - (.Kaspersky Lab ZAO - Kaspersky Anti-Virus.) -- C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe [356376] [PID.6864]
- [MD5.E0D50B1D0FB4B71D7DE0ECE999C69028] - (...) -- C:\Users\jimmy\AppData\Roaming\cacaoweb\cacaoweb.exe [452608] [PID.4892] =>PUP.CacaoWeb
- [MD5.6B412FCE75E2B1462C71D17B6E5C1484] - (.NVIDIA Corporation - NVIDIA Update COM object.) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\ComUpdatus.exe [1209120] [PID.2388]
- [MD5.F9B37EE9DEAE9A9F8F7DB35A93643829] - (...) -- C:\ProgramData\BOINC\projects\einstein.phys.uwm.edu\einstein_S6CasA_1.05_windows_intelx86__SSE2.exe [27028617] [PID.8056]
- [MD5.C8D28F8B498CADBB9445AC4545BD41B7] - (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe [920472] [PID.7624]
- [MD5.E9349A03FD81B4806714A16796B5E20A] - (.Mozilla Corporation - Plugin Container for Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe [17304] [PID.1044]
- [MD5.D8425B8D6DC2AA8D871363B0775BCF18] - (.Adobe Systems, Inc. - Adobe Flash Player 11.8 r800.) -- C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe [1861512] [PID.1420]
- [MD5.B141F8F8B0FF37FFC51F9B71EE7A641B] - (.Skype Technologies S.A. - Skype.) -- C:\Program Files (x86)\Skype\Phone\Skype.exe [19875432] [PID.4264]
- [MD5.2254B9BE2F6F2C9F3CE326051AF65425] - (.Microsoft Corporation - Microsoft Visual C++ 2010 Express.) -- C:\Program Files (x86)\Microsoft Visual Studio 10.0\Common7\IDE\VCExpress.exe [583504] [PID.4176]
- [MD5.BF516883A362948A6E81886ED24796B5] - (.Microsoft Corporation - MSBuild.exe.) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe [267176] [PID.7888]
- [MD5.DEF9F717FC22E899D5109A031D236E52] - (.Microsoft Corporation - Microsoft® Program Database.) -- C:\Program Files (x86)\Microsoft Visual Studio 10.0\Common7\ide\mspdbsrv.exe [116048] [PID.4480]
- [MD5.E1FE1E146C24CE2E70824937807D59F0] - (...) -- C:\ProgramData\BOINC\projects\einstein.phys.uwm.edu\einsteinbinary_BRP5_1.39_windows_intelx86__BRP5-cuda32-nv301.exe [15909382] [PID.7792]
- [MD5.8266B91AD9900AF3CEA7F1D7DD26CED8] - (.Microsoft Corporation - Microsoft (R) Visual C++ Package Server.) -- C:\Program Files (x86)\Microsoft Visual Studio 10.0\VC\vcpackages\VCPkgSrv.exe [100176] [PID.3996]
- [MD5.D8DBE084F97536D7FDE2EE9B4574FB23] - (.Nicolas Coolman - ZHPDiag.) -- C:\Program Files (x86)\ZHPDiag\ZHPDiag.exe [7691264] [PID.8244]
- ~ Processes Running: Scanned in 00mn 01s
- ---\\ Mozilla Firefox, Plugins,Demarrage,Recherche,Extensions (P2,M0,M1,M2,M3)
- M2 - MFEP: prefs.js [jimmy - 8ljgm7it.default\[email protected]] [] cacaoweb v1.0.30 (..) =>PUP.CacaoWeb
- ~ Firefox Browser: 12 Legitimates Filtered in 00mn 00s
- ---\\ Internet Explorer, Proxy Management (R5)
- R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
- R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key
- R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
- R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
- R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
- R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll
- ~ Proxy management: Scanned in 00mn 00s
- ---\\ Analyse des lignes F0, F1, F2, F3 - IniFiles, Autoloading programs
- F2 - REG:system.ini: USERINIT=C:\Windows\system32\userinit.exe,
- F2 - REG:system.ini: Shell=C:\Windows\explorer.exe
- F2 - REG:system.ini: VMApplet=C:\Windows\System32\SystemPropertiesPerformance.exe
- ~ Keys: Scanned in 00mn 00s
- ---\\ Redirection du fichier Hosts (O1)
- ~ Le fichier hosts est sain (The hosts file is clean).
- ~ Hosts File: Scanned in 00mn 00s
- ~ Nombre de lignes (Lines number): 14
- ---\\ Applications démarrées par registre & par dossier (O4)
- O4 - HKLM\..\Run: [Launch LCore] . (.Logitech Inc. - Logitech Gaming Framework.) -- C:\Program Files\Logitech Gaming Software\LCore.exe
- O4 - HKLM\..\Run: [AdobeAAMUpdater-1.0] . (.Adobe Systems Incorporated - Adobe Updater Startup Utility.) -- C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe
- O4 - HKLM\..\Run: [BCSSync] . (.Microsoft Corporation - Microsoft Office 2010 component.) -- C:\Program Files\Microsoft Office\Office14\BCSSync.exe
- O4 - HKLM\..\Run: [XboxStat] . (.Microsoft Corporation - XBoxStat.exe.) -- C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe
- O4 - HKLM\..\Run: [Nvtmru] . (.NVIDIA Corporation - NVIDIA NvTmru Application.) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe
- O4 - HKLM\..\Run: [AgentAntidote32] . (.Druide informatique inc. - AgentAntidote.) -- C:\Program Files (x86)\Druide\Antidote 8\Programmes32\AgentAntidote.exe
- O4 - HKLM\..\Run: [AgentAntidote64] . (.Druide informatique inc. - AgentAntidote.) -- C:\Program Files (x86)\Druide\Antidote 8\Programmes64\AgentAntidote.exe
- O4 - HKLM\..\Run: [boincmgr] . (.Space Sciences Laboratory - BOINC Manager for Windows.) -- C:\Program Files\BOINC\boincmgr.exe
- O4 - HKLM\..\Run: [boinctray] . (.Space Sciences Laboratory - BOINC System Tray for Windows.) -- C:\Program Files\BOINC\boinctray.exe
- O4 - HKCU\..\Run: [Steam] . (.Valve Corporation - Steam Client Bootstrapper (buildbot_winslav.) -- C:\Program Files (x86)\Steam\steam.exe
- O4 - HKCU\..\Run: [Skype] . (.Skype Technologies S.A. - Skype.) -- C:\Program Files (x86)\Skype\Phone\Skype.exe
- O4 - HKCU\..\Run: [cacaoweb] . (...) -- C:\Users\jimmy\AppData\Roaming\cacaoweb\cacaoweb.exe =>PUP.CacaoWeb
- O4 - HKLM\..\Wow6432Node\Run: [AVP] . (.Kaspersky Lab ZAO - Kaspersky Anti-Virus.) -- C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\runner_avp.exe
- O4 - HKLM\..\Wow6432Node\Run: [AdobeCS5.5ServiceManager] . (.Adobe Systems Incorporated - Adobe CS5.5 Service Manager.) -- C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe
- O4 - HKLM\..\Wow6432Node\Run: [SwitchBoard] . (.Adobe Systems Incorporated - SwitchBoard Server (32 bit).) -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
- O4 - HKLM\..\Wow6432Node\Run: [APSDaemon] . (.Apple Inc. - Apple Push.) -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
- O4 - HKLM\..\Wow6432Node\Run: [iTunesHelper] . (.Apple Inc. - iTunesHelper.) -- C:\Program Files (x86)\iTunes\iTunesHelper.exe
- O4 - HKLM\..\Wow6432Node\Run: [SunJavaUpdateSched] . (.Oracle Corporation - Java(TM) Update Scheduler.) -- C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
- O4 - HKLM\..\Wow6432Node\Run: [LogMeIn Hamachi Ui] . (.LogMeIn Inc. - Hamachi Client Application.) -- C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
- O4 - HKLM\..\Wow6432Node\Run: [QuickTime Task] . (.Apple Inc. - QuickTime Task.) -- C:\Program Files (x86)\QuickTime\QTTask.exe
- ~ Application: Scanned in 00mn 00s
- ---\\ Autres liens utilisateurs (O4)
- O4 - GS\Desktop: Cain.lnk . (...) -- C:\Program Files (x86)\Cain\Cain.exe (.not file.)
- O4 - GS\Desktop: mdcrackGUI.lnk . (...) -- C:\Program Files (x86)\mdcrackGUI\mdcrackGUI.exe (.not file.)
- O4 - GS\Desktop: SpeedFan.lnk . (...) -- C:\Program Files (x86)\SpeedFan\speedfan.exe (.not file.)
- ~ Global Startup: Scanned in 00mn 00s
- ---\\ Boutons situés sur la barre d'outils principale d'Internet Explorer (O9)
- O9 - Extra button: Virtual Keyboard [64Bits] - {0C4CC089-D306-440D-9772-464E226F6539} . (...) -- C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\kbrd.ico
- O9 - Extra button: URLs check [64Bits] - {CCF151D8-D089-449F-A5A4-D9909053F20F} . (...) -- C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\logo.ico
- ~ IE Extra Buttons: Scanned in 00mn 00s
- ---\\ Site dans la Zone de confiance d'Internet Explorer (O15)
- O15 - Trusted Zone: [HKCU\...\Domains] http.ma-config.com
- O15 - Trusted Zone: [HKCU\...\Domains] http.touslesdrivers.com
- ~ IE Zone Confiance: Scanned in 00mn 00s
- ---\\ Modification Domaine/Adresses DNS (O17)
- O17 - HKLM\System\CCS\Services\Tcpip\..\{135AB9A2-C27F-41BB-9647-FE7C3AE198E0}: DhcpNameServer = 192.168.42.129
- O17 - HKLM\System\CCS\Services\Tcpip\..\{49BEF726-8AE6-4FCF-B068-66C9BB4B4F23}: DhcpNameServer = 192.168.0.1
- O17 - HKLM\System\CCS\Services\Tcpip\..\{B164C310-6330-43D7-A18B-A52FB62F5D76}: DhcpNameServer = 216.228.208.2 209.169.131.66
- O17 - HKLM\System\CS1\Services\Tcpip\..\{135AB9A2-C27F-41BB-9647-FE7C3AE198E0}: DhcpNameServer = 192.168.42.129
- O17 - HKLM\System\CS1\Services\Tcpip\..\{49BEF726-8AE6-4FCF-B068-66C9BB4B4F23}: DhcpNameServer = 192.168.0.1
- O17 - HKLM\System\CS1\Services\Tcpip\..\{B164C310-6330-43D7-A18B-A52FB62F5D76}: DhcpNameServer = 216.228.208.2 209.169.131.66
- O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 216.228.208.2 209.169.131.66
- ~ Domain: Scanned in 00mn 00s
- ---\\ Protocole additionnel (O18)
- O18 - Handler: vbscript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\System32\mshtml.dll
- O18 - Filter: text/xml [64Bits] - {807573E5-5146-11D5-A672-00B0D022E945} . (.Microsoft Corporation - Microsoft Office XML MIME Filter.) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.dll
- ~ Protocole Additionnel: Scanned in 00mn 00s
- ---\\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (autorun) (O20)
- O20 - AppInit_DLLs: . (...) - C:\PROGRA~2\NVIDIA~1\3DVISI~1\NVSTIN~1.dll (.not file.)
- ~ AppInit DLL: Scanned in 00mn 00s
- ---\\ Clé de Registre autorun SharedTaskScheduler (STS) (O22)
- O22 - SharedTaskScheduler: (no name) [64Bits] - {1984D045-52CF-49cd-DB77-08F378FEA4DB} - (.not file.)
- ~ STS/SSO: Scanned in 00mn 00s
- ---\\ Tâches planifiées en automatique (O39)
- O39 - APT:Automatic Planified Task - C:\Windows\Tasks\AutoKMS.job [222]
- [MD5.0ED398A4D031B9CFB10E3FEDF97AD836] [APT] [AutoKMS] (...) -- C:\WINDOWS\AutoKMS.exe [614400] =>Trojan.Keygen
- [MD5.AE022945810805E64C94E08106801566] [APT] [Hybrid] (...) -- C:\IORRT\IORRT.bat [855]
- [MD5.AE022945810805E64C94E08106801566] [APT] [IORRT] (...) -- C:\IORRT\IORRT.bat [855]
- ~ Scheduled Task: 8 Legitimates Filtered in 00mn 02s
- ---\\ Pilotes lancés au démarrage (O41)
- O41 - Driver: (lmimirr) . (. - .) - C:\Windows\system32\DRIVERS\lmimirr.sys (.not file.)
- ~ Drivers: 46 Legitimates Filtered in 00mn 00s
- ---\\ Logiciels installés (O42)
- O42 - Logiciel: Dragon Nest Europe - (...) [HKLM][64Bits] -- Dragon Nest Europe
- O42 - Logiciel: Qubicle Constructor Basic Edition version 1.6 - (.Minddesk.) [HKLM][64Bits] -- {6B693F37-43D8-448C-8FEA-688AC8778203}_is1
- ~ Logic: 148 Legitimates Filtered in 00mn 00s
- ---\\ HKCU & HKLM Software Keys
- [HKCU\Software\Apricorn]
- [HKCU\Software\DefaultCompany]
- [HKCU\Software\Eric Haines]
- [HKCU\Software\MT2Float]
- [HKCU\Software\VCMP]
- [HKCU\Software\cacaoweb] =>PUP.CacaoWeb
- [HKCU\Software\xcd]
- [HKLM\Software\Wow6432Node\InstallIQ]
- ~ Key Software: 252 Legitimates Filtered in 00mn 00s
- ---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43)
- O43 - CFD: 2013-07-03 - 21:25:17 - [0,151] ----D C:\Program Files (x86)\1-click run
- O43 - CFD: 2013-03-25 - 11:03:45 - [42,192] ----D C:\Program Files (x86)\Jts
- O43 - CFD: 2013-07-03 - 21:26:00 - [1368,899] ----D C:\Program Files (x86)\Kerbal Space Program 0.20.2
- O43 - CFD: 2013-06-08 - 16:12:45 - [8,921] ----D C:\Program Files (x86)\Qubicle Constructor Basic Edition
- O43 - CFD: 2013-07-13 - 14:24:27 - [0] ----D C:\ProgramData\APN
- O43 - CFD: 2013-07-04 - 10:30:49 - [0] ----D C:\ProgramData\Picroma
- O43 - CFD: 2013-05-05 - 14:10:51 - [0] ----D C:\ProgramData\tools4meta
- O43 - CFD: 2013-06-08 - 16:20:30 - [57,316] ----D C:\Users\jimmy\AppData\Roaming\.FriendlyCube
- O43 - CFD: 2013-06-30 - 11:54:37 - [0,000] ----D C:\Users\jimmy\AppData\Roaming\.StarMade =>Toolbar.Tarma
- O43 - CFD: 2013-08-12 - 05:54:48 - [0,432] ----D C:\Users\jimmy\AppData\Roaming\cacaoweb =>PUP.CacaoWeb
- O43 - CFD: 2013-08-10 - 10:25:48 - [0,002] ----D C:\Users\jimmy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\1-click run
- ~ Program Folder: 205 Legitimates Filtered in 00mn 02s
- ---\\ Derniers fichiers modifiés ou crées sous Windows et System32 (O44)
- O44 - LFC:[MD5.85F6CF34209CFE9FDE2337F08FAE09F9] - 2013-08-10 - 19:49:59 ---A- . (...) -- C:\Windows\AutoKMS.log [2537]
- O44 - LFC:[MD5.FBD5FF1BB12E5497C3E7170BA0D8B905] - 2013-08-10 - 19:56:53 ---A- . (...) -- C:\Windows\DirectX.log [1054]
- O44 - LFC:[MD5.9C0458C93226459B4880F4E358913B6A] - 2013-08-12 - 09:58:43 ---A- . (...) -- C:\Windows\ntbtlog.txt [173194]
- ~ Files: 20 Legitimates Filtered in 00mn 16s
- ---\\ MountPoints2 Shell Key (O51)
- O51 - MPSK:{1af3c95d-ca12-11e2-bee2-fccd7fd14889}\AutoRun\command. (.HTC - HTC Sync Manager.) -- F:\HTC_Sync_Manager_PC.exe
- O51 - MPSK:{24428d8b-d54d-11e2-bee8-902b343e70bb}\AutoRun\command. (.HTC - HTC Sync Manager.) -- F:\HTC_Sync_Manager_PC.exe
- ~ Keys: Scanned in 00mn 00s
- ---\\ Microsoft Windows Policies System (O55)
- O55 - MWPS:[HKLM\...\Policies\System] - "EnableUIADesktopToggle"=0
- O55 - MWPS:[HKLM\...\Policies\System] - "FilterAdministratorToken"=0
- O55 - MWPS:[HKLM\...\Policies\System] - "EnableLinkedConnections"=1
- ~ MWPS: 18 Legitimates Filtered in 00mn 00s
- ---\\ Microsoft Windows Policies Explorer (O56)
- O56 - MWPE:[HKLM\...\policies\Explorer] - "NoActiveDesktopChanges"=1
- ~ MWPE Keys: 3 Legitimates Filtered in 00mn 00s
- ---\\ Liste des Drivers Système (O58)
- O58 - SDL:[MD5.4F18D4C7EA14F11A7211F60D553C03DB] - 2012-07-26 - 00:00:49 ---A- . (.LSI - LSI 3ware SCSI Storport Driver.) -- C:\Windows\System32\Drivers\3ware.sys [106736]
- O58 - SDL:[MD5.1E6438D4EA6E1174A3B3B1EDC4DE660B] - 2009-03-18 - 17:35:42 --HA- . (.LogMeIn, Inc. - Hamachi Virtual Network Interface Driver.) -- C:\Windows\System32\hamachi.sys [33856]
- ~ Drivers: Scanned in 00mn 00s
- ---\\ Liste des outils de nettoyage (O63)
- O63 - Logiciel: ZHPDiag 2013 - (.Nicolas Coolman.) [HKLM] -- ZHPDiag_is1
- ~ ADS: Scanned in 00mn 00s
- ---\\ Start Menu Internet (O68)
- O68 - StartMenuInternet: <FIREFOX.EXE> <Mozilla Firefox>[HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
- O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer>[HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe
- ~ Keys: Scanned in 00mn 00s
- ---\\ Search Browser Infection (O69)
- O69 - SBI: prefs.js [jimmy - 8ljgm7it.default] user_pref("weboftrust.search.ask.display", "Ask.com Web Search");
- O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} [DefaultScope] - (Bing) - http://www.bing.com
- ~ Keys: Scanned in 00mn 00s
- ---\\ Recherche particuliere à la racine de certains dossiers (O84)
- [MD5.48C8BA301BAD0C4A23AB3DCBA2A29F69] [SPRF][2013-06-21] (.NVIDIA Corporation - NVIDIA 3D Vision plugin.) -- C:\Users\jimmy\AppData\Local\Temp\nv3DVStreaming.dll [575984]
- [MD5.C6A168DEAA5C3090A8399E16CE0EA592] [SPRF][2013-06-21] (.NVIDIA Corporation - NVIDIA 3D Vision Control Panel API.) -- C:\Users\jimmy\AppData\Local\Temp\nvSCPAPI.dll [1154832]
- [MD5.F356B874D7C6C20FFF08B2CA923811DF] [SPRF][2013-06-21] (.NVIDIA Corporation - NVIDIA 3D Vision Control Panel 64bit API.) -- C:\Users\jimmy\AppData\Local\Temp\nvSCPAPI64.dll [1330968]
- [MD5.2222073BE0232E70A397B8302293AA9D] [SPRF][2013-06-21] (.NVIDIA Corporation - Stereo Vision Control Panel API Server.) -- C:\Users\jimmy\AppData\Local\Temp\nvSCPAPISvr.exe [413472]
- [MD5.A6876FDC7216B1FAEE1335E4AA361240] [SPRF][2013-06-21] (.NVIDIA Corporation - NVIDIA API 3D Vision extention.) -- C:\Users\jimmy\AppData\Local\Temp\nvStereoApiI.dll [361744]
- [MD5.359F134350EA329A7C14E97D649EB1FA] [SPRF][2013-06-21] (.NVIDIA Corporation - Stereoscpic 3D driver Installer API.) -- C:\Users\jimmy\AppData\Local\Temp\nvStInst.exe [787232]
- [MD5.7E7EB7AFF595774E5E500B34058CC1A7] [SPRF][2013-07-18] (...) -- C:\Users\jimmy\AppData\Local\Temp\sfamcc00001.dll [192512]
- [MD5.F0E142B1EF4006222863D4E4A0B952B7] [SPRF][2012-12-16] (...) -- C:\Users\jimmy\AppData\Local\Temp\sfextra.dll [55296]
- [MD5.1B1D86A574E842946E5D5317892B45C5] [SPRF][2013-08-05] (.Skype Technologies S.A. - Skype.) -- C:\Users\jimmy\AppData\Local\Temp\SkypeSetup.exe [31954536]
- [MD5.06D5E5E952C61923C9D24C83E7FE1F45] [SPRF][2013-08-10] (...) -- C:\Users\jimmy\AppData\Local\Temp\vlc-2.0.7-win32.exe [22937227]
- [MD5.6C269C7F629DEED724ED32F931E384A1] [SPRF][2013-05-08] (...) -- A:\Users\jimmy\Desktop\FriendlyCubeLauncher-v2.1.exe [328941]
- [MD5.501E26080BFF03563B4A691C3B39A007] [SPRF][2013-07-16] (.techPowerUp (www.techpowerup.com) - GPU-Z - Video card Information Utility.) -- A:\Users\jimmy\Desktop\GPU-Z.0.7.2.exe [1344480]
- [MD5.0F1931E26C21219DB1C90E90037F11F6] [SPRF][2011-07-14] (...) -- A:\Users\jimmy\Desktop\Minecraft.exe [270142]
- [MD5.EEC8A9F1E71D8D66B4DE0DAAB316E75F] [SPRF][2013-01-16] (.Nattyware - The ultimate colour picker.) -- A:\Users\jimmy\Desktop\pixie.exe [11776]
- [MD5.26CEEF9B9FE30A2430266B0E085A6EDE] [SPRF][2013-06-30] (...) -- A:\Users\jimmy\Desktop\StarMade-starter.exe [1148298] =>Toolbar.Tarma
- ~ Files: Scanned in 00mn 06s
- ---\\ Firewall Active Exception List (FirewallRules) (O87)
- O87 - FAEL: "{796B0D27-A252-4D3E-B603-1D489A160B06}" | In - Public - P6 - TRUE | .(...) -- C:\Program Files (x86)\eFusion\Dragon Nest Europe\DragonNest.exe
- O87 - FAEL: "{7EDE3E0A-7679-4A01-B081-93F4D64B4C30}" | In - Public - P17 - TRUE | .(...) -- C:\Program Files (x86)\eFusion\Dragon Nest Europe\DragonNest.exe
- ~ Firewall: 287 Legitimates Filtered in 00mn 19s
- ---\\ Windows Installer Scan (O93) (NTFS)
- [MD5.73122534D527893BDEFD1F707FFB34F6] [WIS][2013-08-05] (.Skype Technologies S.A. - Skype.) -- C:\Windows\Installer\13e85d.msi [21803008]
- [MD5.99E620B9DFC24F35B33865BAA98DAE54] [WIS][2013-07-10] (.Space Sciences Laboratory, U.C. Berkeley - BOINC.) -- C:\Windows\Installer\145d892.msi [9222656]
- [MD5.9314BD51CD2E85ED6B8B0DDE55F2DD62] [WIS][2013-06-04] (.HTC Corporation - HTC Driver.) -- C:\Windows\Installer\168fc579.msi [17349888]
- [MD5.96E6D181192A995214493A6828E4287D] [WIS][2012-12-07] (.HTC - .) -- C:\Windows\Installer\168fc57f.msi [576512]
- [MD5.2BFD52D320118466A39949B797D9C4AD] [WIS][2012-09-12] (.Kaspersky Lab - Kaspersky Internet Security 2013.) -- C:\Windows\Installer\2f4f7e4.msi [2789376]
- [MD5.3BEA739AF7E8189D713E28A0100E0DFA] [WIS][2013-07-03] (.LogMeIn, Inc. - LogMeIn Hamachi Installer.) -- C:\Windows\Installer\3eb2.msi [4296704]
- [MD5.71E8D3D1679A9D803302FF2923406DEF] [WIS][2013-05-05] (.Pete Shinners, Rene Dudfield, Marcus von Ap - Python 3.2 pygame-1.9.2a0.) -- C:\Windows\Installer\4be168c.msi [6422528]
- [MD5.075AFFBDFC36C956D9C2176B215F7F16] [WIS][2009-09-30] (.Microsoft - Microsoft Xbox 360 Accessories.) -- C:\Windows\Installer\7dd0209.msi [1219584]
- [MD5.5102694E49576312C0AF6E1CDB85D3F3] [WIS][2013-07-06] (.GIGABYTE Technology Co.,Ltd. - GIGABYTE OC_GURU II.) -- C:\Windows\Installer\c134268.msi [12881920]
- [MD5.73792BA1B556400D5DF1444853235DB7] [WIS][2013-01-30] (.Logitech Inc - Logitech Gaming Software.) -- C:\Windows\Installer\c301dd9.msi [188928]
- ~ WIS: 109 Legitimates Filtered in 00mn 09s
- ---\\ Etat général des services non Microsoft (EGS) (SR=Running, SS=Stopped)
- SS - | Demand 2013-07-18 257416 | (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
- SR - | Auto 2012-12-02 240640 | (AMD External Events Utility) . (.AMD.) - C:\Windows\System32\atiesrxx.exe
- SR - | Auto 2012-12-21 57008 | (Apple Mobile Device) . (.Apple Inc..) - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
- SR - | Auto 2012-11-21 356376 | (AVP) . (.Kaspersky Lab ZAO.) - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe
- SR - | Auto 2011-08-30 462184 | (Bonjour Service) . (.Apple Inc..) - C:\Program Files\Bonjour\mDNSResponder.exe
- SR - | Auto 2013-06-28 2470736 | (Hamachi2Svc) . (.LogMeIn Inc..) - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
- SS - | Demand 2005-11-14 69632 | (IDriverT) . (.Macrovision Corporation.) - C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
- SR - | Auto 2012-07-27 636952 | (Intel(R) Capability Licensing Service Interface) . (.Intel(R) Corporation.) - C:\Program Files\Intel\iCLS Client\HeciServer.exe
- SS - | Demand 2013-05-31 641352 | (iPod Service) . (.Apple Inc..) - C:\Program Files\iPod\bin\iPodService.exe
- SR - | Auto 2012-08-09 166720 | (jhi_service) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
- SR - | Auto 2012-08-09 277824 | (LMS) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
- SR - | Auto 2013-08-04 2650960 | (MaConfigAgent) . (.CybelSoft.) - C:\Program Files\ma-config.com\MaConfigAgent.exe
- SS - | Demand 2013-07-02 117144 | (MozillaMaintenance) . (.Mozilla Foundation.) - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
- SR - | Auto 2013-07-27 14984480 | (NvStreamSvc) . (.NVIDIA Corporation.) - C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
- SR - | Auto 2013-06-21 884512 | (nvsvc) . (.NVIDIA Corporation.) - C:\WINDOWS\system32\nvvsvc.exe
- SR - | Auto 2013-07-27 1889568 | (nvUpdatusService) . (.NVIDIA Corporation.) - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
- SR - | Auto 167424 | (PassThru Service) . (...) - C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe
- SR - | Auto 0 | (PnkBstrA) . (...) - C:\WINDOWS\system32\PnkBstrA.exe
- SS - | Auto 2013-06-21 162408 | (SkypeUpdate) . (.Skype Technologies.) - C:\Program Files (x86)\Skype\Updater\Updater.exe
- SS - | Demand 2013-07-26 563624 | (Steam Client Service) . (.Valve Corporation.) - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
- SS - | Demand 2010-02-19 517096 | (SwitchBoard) . (.Adobe Systems Incorporated.) - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
- SR - | Auto 2012-08-09 365376 | (UNS) . (.Intel Corporation.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
- SS - | Auto 0 | (WMPNetworkSvc) . (...) - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe
- SS - | Demand 2012-09-20 29696 | C:\Windows\System32\wuaueng.dll (wuauserv) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe
- ~ Services: Scanned in 00mn 09s
- ---\\ Scan Additionnel (O88)
- Database Version : v2.12849 - (2013-08-10)
- Clés trouvées (Keys found) : 2
- Valeurs trouvées (Values found) : 1
- Dossiers trouvés (Folders found) : 4
- Fichiers trouvés (Files found) : 4
- [HKCU\Software\cacaoweb] =>PUP.CacaoWeb
- [HKLM\Software\Wow6432Node\InstallIQ] =>Toolbar.Agent
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]:cacaoweb =>PUP.CacaoWeb^
- C:\Users\jimmy\AppData\Roaming\Mozilla\Firefox\Profiles\8ljgm7it.default\[email protected] =>PUP.CacaoWeb^
- C:\Users\jimmy\AppData\Roaming\.StarMade =>Toolbar.Tarma^
- C:\Users\jimmy\AppData\Roaming\cacaoweb =>PUP.CacaoWeb^
- C:\Users\jimmy\AppData\Roaming\Mozilla\Firefox\Profiles\8ljgm7it.default\Extensions\[email protected] =>PUP.CacaoWeb
- C:\Users\jimmy\AppData\Roaming\cacaoweb\cacaoweb.exe =>PUP.CacaoWeb^
- C:\WINDOWS\AutoKMS.exe =>Trojan.Keygen^
- A:\Users\jimmy\Desktop\StarMade-starter.exe =>Toolbar.Tarma^
- C:\Windows\AutoKMS.exe =>Trojan.Keygen
- ~ Additionnel Scan: 515406 Items scanned in 00mn 21s
- ---\\ Récapitulatif des détections trouvées sur votre station
- ~ http://nicolascoolman.webs.com/apps/blog/show/27566847-pup-cacaoweb =>PUP.CacaoWeb
- ~ http://nicolascoolman.webs.com/apps/blog/show/29637859-toolbar-tarma =>Toolbar.Tarma
- ~ MSI: 2 link(s) detected in 00mn 21s
- ~ 1136 Legitimates filtered by white list
- End of the scan (456 lines in 01mn 38s)(0)
Advertisement
Add Comment
Please, Sign In to add comment