Voila le ZHPdiag:
[spoiler]—\ Processus lancés
[MD5.DD231039B13EC2ABDE315D76E658EF0E] - (.Avira Operations GmbH & Co. KG - Antivirus System Tray Tool (Desktop).) – C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [684600] [PID.2788]
[MD5.5EBBA07CFE002FF3DB1B0AAC33689913] - (.Glarysoft Ltd - Glary Utilities 4.) – C:\Program Files (x86)\Glary Utilities 4\Integrator.exe [780064] [PID.716]
[MD5.D9184C5FF3FD526761D518A95ABA74A3] - (.Mozilla Corporation - Firefox.) – C:\Program Files (x86)\Mozilla Firefox\firefox.exe [275568] [PID.2776]
[MD5.86E69581356CA45167EA6986B6E29087] - (.TOSHIBA CORPORATION - ConfigFree Task Tray Menu.) – C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe [304560] [PID.956]
[MD5.FF409C974A9AD58B82374DEEF6B44CBB] - (.Mozilla Corporation - Plugin Container for Firefox.) – C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe [18544] [PID.3248]
[MD5.0642800E69522E29B93EF4C6BE00D13E] - (.Adobe Systems, Inc. - Adobe Flash Player 12.0 r0.) – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_12_0_0_70.exe [1863560] [PID.3284]
[MD5.8A07221789D46B2EA7DFCA2BC807572A] - (.TOSHIBA CORPORATION - ConfigFree Switch Manager Process.) – C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSwMgr.exe [62848] [PID.3508]
[MD5.48820A316D73677FE0FC39CC72EE3906] - (.Don HO don.h@free.fr - Notepad++ : a free (GNU) source code editor.) – C:\Program Files (x86)\Notepad++\notepad++.exe [1802240] [PID.3136]
[MD5.B34E6256D75CF56369147487AF5BF16F] - (.Nicolas Coolman - ZHPDiag.) – C:\Program Files (x86)\ZHPDiag\ZHPDiag.exe [8352256] [PID.3192]
[MD5.D004558CE39AA4F01F207627EECF4CFB] - (.TeamViewer GmbH - TeamViewer 9.) – C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe [12493152] [PID.4568]
[MD5.FE79366FECD444A16CCA9979134DBEA8] - (.Avira Operations GmbH & Co. KG - Antivirus Host Framework Service.) – C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440376] [PID.1480]
[MD5.FDE9C7030FB1E9E2715E113EE6A10F90] - (.Avira Operations GmbH & Co. KG - Antivirus Host Framework Service.) – C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440376] [PID.1692]
~ Processes Running: Scanned in 00mn 01s
—\ Analyse des lignes F0, F1, F2, F3 - IniFiles, Autoloading programs
F2 - REG:system.ini: USERINIT=C:\Windows\system32\userinit.exe,
F2 - REG:system.ini: Shell=C:\Windows\explorer.exe
F2 - REG:system.ini: VMApplet=C:\Windows\System32\SystemPropertiesPerformance.exe
~ Keys: Scanned in 00mn 00s
—\ Applications lancées au démarrage du sytème (O4)
O4 - HKLM…\Run: [RtHDVCpl] . (.Realtek Semiconductor - Gestionnaire audio HD Realtek.) – C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe =>.Realtek Semiconductor Corp
O4 - HKLM…\Run: [TosVolRegulator] . (.TOSHIBA Corporation - Toshiba Volume Regulator.) – C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe =>.Toshiba Corporation
O4 - HKLM…\Run: [Teco] C:\Program Files (x86)\TOSHIBA\TECO\Teco.exe (.not file.)
O4 - HKCU…\Run: [GUDelayStartup] . (.Glarysoft Ltd - StartupManager.) – C:\Program Files (x86)\Glary Utilities 4\StartupManager.exe
O4 - HKLM…\Wow6432Node\Run: [AMD AVT] . (.Microsoft Corporation - Interpréteur de commandes Windows.) – C:\Windows\System32\Cmd.exe =>.Microsoft Corporation
O4 - HKLM…\Wow6432Node\Run: [HWSetup] . (.TOSHIBA Electronics, Inc. - HWSetup.) – C:\Program Files\TOSHIBA\Utilities\HWSetup.exe
O4 - HKLM…\Wow6432Node\Run: [avgnt] . (.Avira Operations GmbH & Co. KG - Antivirus System Tray Tool (Desktop).) – C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
O4 - HKUS\S-1-5-19…\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) – C:\Program Files (x86)\Windows Sidebar\Sidebar.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-20…\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) – C:\Program Files (x86)\Windows Sidebar\Sidebar.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-19…\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) – C:\Windows\System32\mctadmin.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-20…\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) – C:\Windows\System32\mctadmin.exe =>.Microsoft Corporation
O4 - HKUS\S-1-5-21-712965392-342034552-4204572026-1000…\Run: [GUDelayStartup] . (.Glarysoft Ltd - StartupManager.) – C:\Program Files (x86)\Glary Utilities 4\StartupManager.exe
~ Application: Scanned in 00mn 00s
—\ Tâches planifiées en automatique (O39)
[MD5.140237BA8BD1AAC665893A4A456ABDD9] [APT] [AutoKMS] (…) – C:\Windows\AutoKMS\AutoKMS.exe [3732480] =>Trojan.Trojan.Keygen
~ Scheduled Task: 7 Legitimates Filtered in 00mn 06s
—\ Etat général des services non Microsoft (EGS) (SR=Running, SS=Stopped)
SS - | Disabled 30/08/2011 462184 | (Bonjour Service) . (.Apple Inc…) - C:\Program Files\Bonjour\mDNSResponder.exe
SS - | Disabled 28/01/2010 249200 | (cfWiMAXService) . (.TOSHIBA CORPORATION.) - C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe
SS - | Disabled 10/03/2009 46448 | (ConfigFree Service) . (.TOSHIBA CORPORATION.) - C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe
SS - | Disabled 09/03/2014 1044816 | (FLEXnet Licensing Service) . (.Flexera Software, Inc…) - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
SS - | Disabled 09/03/2014 1431888 | (FLEXnet Licensing Service 64) . (.Flexera Software, Inc…) - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
SS - | Demand 13/02/2014 118896 | (MozillaMaintenance) . (.Mozilla Foundation.) - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
SS - | Disabled 09/03/2014 79360 | (SolidWorks Licensing Service) . (.SolidWorks.) - C:\Program Files (x86)\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe
SS - | Disabled 17/02/2014 4915040 | (TeamViewer9) . (.TeamViewer GmbH.) - C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
SS - | Demand 05/02/2010 137560 | (TOSHIBA HDD SSD Alert Service) . (.TOSHIBA Corporation.) - C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
SS - | Demand 23/02/2010 835952 | (TPCHSrv) . (.TOSHIBA Corporation.) - C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
SS - | Demand 14/07/2009 27136 | C:\Program Files (x86)\Windows Defender\mpsvc.dll (WinDefend) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe
SR - | Auto 30/04/2013 238080 | (AMD External Events Utility) . (.AMD.) - C:\Windows\System32\atiesrxx.exe
SR - | Auto 29/04/2013 361984 | (AMD FUEL Service) . (.Advanced Micro Devices, Inc…) - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
SR - | Auto 13/12/2013 440376 | (AntiVirSchedulerService) . (.Avira Operations GmbH & Co. KG.) - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
SR - | Auto 13/12/2013 440376 | (AntiVirService) . (.Avira Operations GmbH & Co. KG.) - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
SR - | Auto 24/02/2014 2818888 | (MaConfigAgent) . (.CybelSoft.) - C:\Program Files\ma-config.com\MaConfigAgent.exe
SR - | Auto 16/10/2013 289496 | (RtkAudioService) . (.Realtek Semiconductor.) - C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
SR - | Demand 06/10/2009 51512 | (TMachInfo) . (.TOSHIBA Corporation.) - C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe =>.Toshiba Corporation
SR - | Auto 06/04/2010 258928 | (TOSHIBA eco Utility Service) . (.TOSHIBA Corporation.) - C:\Program Files\TOSHIBA\TECO\TecoService.exe =>.Toshiba Corporation
SR - | Demand 10/07/1658 0 | (WMPNetworkSvc) . (…) - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe =>.Microsoft Corporation
SR - | Auto 14/07/2009 27136 | C:\Windows\System32\wuaueng.dll (wuauserv) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe
~ Services: Scanned in 00mn 24s
[/spoiler]
Je me permet de rajouter les catégorie qui on mis longtemps a etre annalysés:
[spoiler]
—\ Scan Additionnel (O88)
Database Version : 13031 - (10/03/2014)
Clés trouvées (Keys found) : 0
Valeurs trouvées (Values found) : 1
Dossiers trouvés (Folders found) : 0
Fichiers trouvés (Files found) : 1
C:\Windows\AutoKMS\AutoKMS.exe =>Trojan.Trojan.Keygen^
~ Additionnel Scan: 228006 Items scanned in 01mn 01s
~ 1425 Legitimates filtered by white list
End of the scan (343 lines in 03mn 38s)(0)
—\ Récapitulatif des détections trouvées sur votre station
~ MSI: 0 link(s) detected in 01mn 01s
—\ Derniers fichiers modifiés ou crées sous Windows et System32 (O44)
O44 - LFC:[MD5.F862CD08F1AD4EE39BD506853F3C6103] - 01/03/2014 - 19:19:48 —A- . (…) – C:\Windows\System32\ieuinit.inf [16284]
O44 - LFC:[MD5.5A2953154F7B7E59F87A28F774D6EB3D] - 05/03/2014 - 17:17:28 —A- . (.Windows ® Win 7 DDK provider - HerculesClass-Installer DLL.) – C:\Windows\System32\HerculesDJDevices.dll [78848]
O44 - LFC:[MD5.ADAD7E1C22C0858A761746A98664BB12] - 05/03/2014 - 17:17:33 —A- . (.Windows ® Win 7 DDK provider - Hercules DJ USB Audio Class-Installer DLL.) – C:\Windows\System32\HerculesDJUSBAudioDevices_x64.dll [79872]
O44 - LFC:[MD5.7C7EC6003CD65B8BA1ECB801F860FF1D] - 05/03/2014 - 17:17:49 R–A- . (…) – C:\Windows\System32\HDJcustom.ini [365]
O44 - LFC:[MD5.C8C7EAD8098EA7468D651F3459657240] - 25/02/2014 - 11:28:45 —A- . (…) – C:\Windows\System32\Drivers\RTAIODAT.DAT [681905]
O44 - LFC:[MD5.D41D8CD98F00B204E9800998ECF8427E] - 25/02/2014 - 11:35:35 —A- . (…) – C:\Windows\ativpsrm.bin [0]
~ Files: 469 Legitimates Filtered in 01mn 04s
[/spoiler]
Comment je me débarrasse de “C:\Windows\AutoKMS\AutoKMS.exe =>Trojan.Trojan.Keygen^”
Le probleme vient il de là?