Probleme ccleaner

Résolu
noya83000 Messages postés 19 Statut Membre -  
Patdam73 Messages postés 271 Statut Membre -
bonjour a tous , voila mon probleme : en utilisant ccleaner :programmes qui démarre en même temps que Windows et qui ralentisse fortement le système, certain programme sont nécessaire ou plus pratique d'être démarré comme l'antivirus, ou ceux que vous utilisez quotidiennement (emule, adobe reader...)

je vous conseille de racourcir cette liste le plus possible, VOICI LA LISTE QUI S AFFICHE ET JE NE SAIS PAS QUOI EFFACER : Oui HKCU:Run NVIEW rundll32.exe nview.dll,nViewLoadHook
Oui HKCU:Run ctfmon.exe C:\WINDOWS\system32\ctfmon.exe
Oui HKCU:Run Acme.PCHButton C:\PROGRA~1\PRESAR~1\Presario\XPHWWRP4\plugin\bin\PCHButton.exe
Oui HKCU:Run msnmsgr "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
Oui HKLM:Run hpsysdrv c:\windows\system\hpsysdrv.exe
Oui HKLM:Run HotKeysCmds C:\WINDOWS\System32\hkcmd.exe
Oui HKLM:Run HPHmon05 C:\WINDOWS\System32\hphmon05.exe
Oui HKLM:Run Recguard C:\WINDOWS\SMINST\RECGUARD.EXE
Oui HKLM:Run TkBellExe "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
Oui HKLM:Run iTunesHelper "C:\Program Files\iTunes\iTunesHelper.exe"
Oui HKLM:Run avgnt "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
Oui HKLM:Run SunJavaUpdateSched "C:\Program Files\Fichiers communs\Java\Java Update\jusched.exe"
Oui HKLM:Run Adobe Reader Speed Launcher "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
Oui HKLM:Run Adobe ARM "C:\Program Files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe"
Oui HKLM:Run installer C:\Program Files\Installer\lnetworker.exe
MERCI D AVANCE

28 réponses

  • 1
  • 2
  1. Patdam73 Messages postés 271 Statut Membre 13
     
    Bonsoir

    Je te propose d'utiliser un autre outil que ccleaner pour optimiser ton pc.

    De plus avant de l'optimiser il faut déjà mettre à jour ton adobe reader car un programme non a jour comporte des failles de sécurité qui peuvent être exploité.

    Si tu veux en savoir plus tu peux consulter cet article :

    https://forum.malekal.com/viewtopic.php?t=3452&start=

    On va analyser ta config :

    ZHPDiag

    [*] Télécharge zhpdiag
    https://www.zebulon.fr/telechargements/securite/systeme/zhpdiag.html (de Nicolas Coolman) sur ton bureau.

    [*] Double clique sur ZHPDiag.exe pour lancer l'installation.

    Note :
    Pour Vista et Windows 7 faites un clic droit sur l'icône et sélectionnez Exécuter en tant qu'administrateur.

    [*] Laisse toi guider pour l'installation et coche bien la case proposant la création d'un raccourci sur le bureau.
    Note :
    2 nouvelles icônes sont maintenant sur ton bureau : ZHPDiag et ZHPFix.

    [*] Double clique sur ZHPDiag pour lancer l'exécution.
    Note :
    Pour Vista et Windows 7 faites un clic droit sur l'icône et sélectionnez Exécuter en tant qu'administrateur.

    [*] Clique sur la loupe pour lancer l'analyse et patiente jusqu'à la fin de celle ci.

    [*] Le rapport a été crée sur ton bureau (ZHPDiag.txt)
    [b]Note :
    Le rapport étant trop long pour le forum, héberge le sur http://www.cijoint.fr

    [*] Copie et colle le lien dans ta prochaine réponse.

    @+
    0
  2. noya83000 Messages postés 19 Statut Membre
     
    bonsoir desole du retard : voici le rapport :http://www.cijoint.fr/cjlink.php?file=cj201101/cijVea2hRc.txt
    0
  3. Patdam73 Messages postés 271 Statut Membre 13
     
    RE

    Pas de souci, tu as tout ton temps ;-)

    Bien effectivement on peut optimiser ton pc car tu as pas mal de programmes qui se lancent au démarrage.

    Mais au paravent tu as plusieurs infection, donc on va commencer par cela :

    Tu es victime d'une infection Navipromo (aussi appelée Magic.control, Instant Access...)
    Elle provoque l'ouverture de fenêtres publicitaires qui t'incitent, entre autre, à télécharger des logiciels sois disant de sécurité mais qui sont en fait des malwares. Cette infection est en général proposée avec des logiciels gratuits. En voici une liste non exhaustive :

    go-astro - Instant Access - InternetGameBox - GoRecord - HotTVPlayer - Live Player - MailSkinner - Messenger Skinner - sudoplanet - Webmediaplayer- Funky Emoticons - Game Attack - Official Emule (Version d'Emule modifiée) -
    Original Solitaire - SuperSexPlayer - Speed Downloading...

    Suppression de ce malware :

    Télécharger Navilog1(de il-Mafioso) sur le bureau

    http://il.mafioso.pagesperso-orange.fr/Navifix/Navilog1.exe

    /!\ Désactive tes protections résidentes : antivirus, antispyware, parefeu ... /!\

    Double clique sur Navilog1.exe pour le lancer.

    Note :
    Pour Vista et Windows 7 faites un clic droit sur l'icône et sélectionnez Exécuter en tant qu'administrateur.

    [*]Choisi la langue 1 (Français) puis appuie sur "Entrée"
    [*]Appuie sur une touche après chaque avertissement.
    [*]Au menu principal, choisis 1 (Recherche / Désinfection automatique) et valide. Ne fais pas le choix 2.

    [*] Si aucune infection n'est détectée:
    [*]Lorsque cela te sera demandé, appuie sur une touche.
    [*]Le bloc-note va s'ouvrir, sauvegarde le rapport sur le bureau et ferme-le.
    Sinon, il se trouve ici : C:\cleannavi.txt
    [*]Poste-le dans ta prochaine réponse.

    Si une infection est détectée, la procédure se poursuit :
    [*]Lorsque cela te sera demandé, appuie sur une touche.
    [*]Le pc va redémarrer, laisse-le faire (s'il ne le fait pas automatiquement, redémarre manuellement)
    [*]Au démarrage lance ta session habituelle.
    [*]Le bureau restera vide, c'est normal, patiente jusqu'à avoir le message nettoyage terminée le ...
    [*]Le bloc-note va s'ouvrir, sauvegarde le rapport sur le bureau et ferme-le.
    Sinon, il se trouve ici : C:\cleannavi.txt
    [*]Poste-le dans ta prochaine réponse

    (PS : Si le bureau ne réapparait pas, relance le processus explorer via le gestionnaire des tâches : Fichier -> nouvelle tâche -> explorer )

    /!\ N'oublie pas de réactiver tes protections résidentes /!\

    Tu trouveras une aide en images sur le lien ci dessous

    http://il.mafioso.pagesperso-orange.fr/Navifix/presentation.htm

    ========

    Ensuite :

    Ad-Remover : Scan

    Télécharge Ad Remover sur ton Bureau. (Merci à C_XX)

    http://www.teamxscript.org/too/AD-R.exe

    /!\ Ferme toutes applications en cours /!\

    /!\ Désactive provisoirement et seulement le temps de l'utilisation de AD-Remover, la protection en temps réel de ton Antivirus et de tes Antispywares, qui peuvent gêner fortement la procédure de recherche et de nettoyage de l'outil.

    - Double-clique sur l'icône Ad-remover située sur ton Bureau.
    - Sur la page, clique sur le bouton « Scanner »
    - Confirme lancement du scan
    - Laisse travailler l'outil.
    - Poste le rapport qui apparaît à la fin.

    (Le rapport est sauvegardé aussi sousC:\Ad-reportScan.Txt)

    (CTRL+A pour tout sélectionner, CTRL+C pour copier et CTRL+V pour coller)

    ========

    Et enfin il y a de grande chance que tu es aussi une infection usb :

    USBFix : Recherche

    Télécharge USBFix sur ton Bureau. (Merci à C_XX)

    http://www.teamxscript.org/too/UsbFix.exe

    /!\ Déconnecte-toi et ferme toutes les applications en cours /!\
    /!\ Branche tous tes périphériques ayant pu être infectés (clés usb, disque dur externe, etc ...) /!\

    [*] Double-clique sur UsbFix pour lancer le programme
    Note :
    Pour Vista et Windows 7 faites un clic droit sur l'icône et sélectionnez Exécuter en tant qu'administrateur.

    [*]Clique sur Rechercher et valide
    [*]Laisse travailler l'outil
    [*]A la fin, un rapport apparaitra (sinon, il est situé ici C:\Usbfix.txt).

    Poste-le dans ta prochaine réponse

    =========

    Voilà, j'attends donc tes 3 rapports pour poursuivre

    Bonne soirée
    0
  4. noya83000 Messages postés 19 Statut Membre
     
    rebonsoir voici les 3 rapports :Fix Navipromo version 4.0.9 commencé le 13/01/2011 22:26:35,29

    !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
    !!! Postez ce rapport sur le forum pour le faire analyser !!!

    Outil exécuté depuis C:\navilog1

    Mise à jour le 24.11.2010 à 16h00 par IL-MAFIOSO

    Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 3
    X86-based PC ( Uniprocessor Free : Intel(R) Celeron(R) CPU 2.50GHz )
    BIOS : Phoenix - AwardBIOS v6.00PG
    USER : Propriétaire ( Administrator )
    BOOT : Normal boot

    Antivirus : AntiVir Desktop 9.0.1.32 (Not Activated)

    A:\ (USB)
    C:\ (Local Disk) - NTFS - Total:70 Go (Free:47 Go)
    D:\ (Local Disk) - FAT32 - Total:4 Go (Free:0 Go)
    E:\ (CD or DVD)
    F:\ (CD or DVD)

    Recherche executée en mode normal

    [b]Aucune Infection Navipromo/Egdaccess trouvée/b

    *** Scan terminé 13/01/2011 22:26:56,96 ***
    ======= RAPPORT D'AD-REMOVER 2.0.0.2,D | UNIQUEMENT XP/VISTA/7 =======

    Mis à jour par TeamXscript le 12/01/11 à 19:00
    Contact: AdRemover[DOT]contact[AT]gmail[DOT]com
    Site web: http://www.teamxscript.org

    C:\Program Files\Ad-Remover\main.exe (SCAN [1]) -> Lancé à 22:30:23 le 13/01/2011, Mode normal

    Microsoft Windows XP Édition familiale Service Pack 3 (X86)
    Propriétaire@MARSEILLAIS ( )

    ============== RECHERCHE ==============

    Service: "sdmBackupIP" Présent

    Dossier trouvé: C:\Program Files\Installer
    Fichier trouvé: C:\Program Files\Mozilla FireFox\Components\AskSearch.js
    Fichier trouvé: C:\WINDOWS\system32\Utils.dll
    Dossier trouvé: C:\WINDOWS\BackupIP
    Fichier trouvé: C:\Documents and Settings\Propriétaire\Application Data\Mozilla\FireFox\Profiles\8vneijw1.default\searchplugins\fast-browser-search.xml
    Fichier trouvé: C:\Documents and Settings\Propriétaire\Application Data\Mozilla\FireFox\Profiles\8vneijw1.default\searchplugins\web-search.xml
    Dossier trouvé: C:\Documents and Settings\Propriétaire\Local Settings\Application Data\networker

    -- Fichier ouvert: C:\Documents and Settings\Propriétaire\Application Data\Mozilla\FireFox\Profiles\8vneijw1.default\Prefs.js --
    Ligne trouvée: user_pref("browser.search.defaultenginename", "Fast Browser Search");
    Ligne trouvée: user_pref("browser.search.defaultthis.engineName", "Fast Browser Search");
    Ligne trouvée: user_pref("browser.search.defaulturl", "hxxp://www.fastbrowsersearch.com/results/results.aspx?s=DEF&...
    Ligne trouvée: user_pref("browser.search.order.1", "Fast Browser Search");
    Ligne trouvée: user_pref("browser.search.selectedEngine", "Fast Browser Search");
    Ligne trouvée: user_pref("extensions.snipit.askTbInstalled", true);
    Ligne trouvée: user_pref("extensions.snipit.chromeURL", "hxxp://toolbar.ask.com/toolbarv/askRedirect?o=13925&gct=&g...
    Ligne trouvée: user_pref("keyword.URL", "hxxp://www.fastbrowsersearch.com/results/results.aspx?s=NAUS&v=19&tid={DE8...
    -- Fichier Fermé --

    Clé trouvée: HKLM\Software\Classes\CLSID\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}
    Clé trouvée: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}
    Clé trouvée: HKLM\Software\Classes\Interface\{06784C15-B640-40F8-AEE8-3C1A3C7A899C}
    Clé trouvée: HKLM\Software\Classes\Interface\{1D5DF418-73EA-4B20-B0D1-5F9C6C949CB0}
    Clé trouvée: HKLM\Software\Classes\Interface\{30022029-2C17-4A99-87D2-A382C674A19D}
    Clé trouvée: HKLM\Software\Classes\Interface\{3A6691EA-C844-46F2-9237-1386A85CE119}
    Clé trouvée: HKLM\Software\Classes\Interface\{3D2E7662-85FB-4CC1-875C-A624B1AA5D96}
    Clé trouvée: HKLM\Software\Classes\Interface\{5D16197A-1EAA-45AF-B29A-69F1AA055E87}
    Clé trouvée: HKLM\Software\Classes\Interface\{72FEEB09-BB27-46D3-A06D-930D4D544227}
    Clé trouvée: HKLM\Software\Classes\Interface\{736918FE-2349-4230-BA9A-1F23649E32AD}
    Clé trouvée: HKLM\Software\Classes\Interface\{89D36231-6BD9-4E20-BBA0-FD28C3A83C40}
    Clé trouvée: HKLM\Software\Classes\Interface\{972BC913-312C-44B7-AA91-4AE3EC2E264B}
    Clé trouvée: HKLM\Software\Classes\Interface\{A0BA9F0F-BCEF-49CF-8A8E-D87E19E066F3}
    Clé trouvée: HKLM\Software\Classes\Interface\{A53762B6-30F7-469F-BA92-13D63CF09A93}
    Clé trouvée: HKLM\Software\Classes\Interface\{B24FF4F6-D327-4208-8840-68CCEF7D6125}
    Clé trouvée: HKLM\Software\Classes\Interface\{BD31DF26-7178-41F4-88DD-F16B82D827CA}
    Clé trouvée: HKLM\Software\Classes\Interface\{C4DB76D5-B430-4652-8599-7CD2C8FE6CC6}
    Clé trouvée: HKLM\Software\Classes\Interface\{E4662B0A-DA6B-4408-A73B-5A2BBB2B0CC8}
    Clé trouvée: HKLM\Software\Classes\Interface\{E977DE7C-34EA-4876-B333-207C4504589E}
    Clé trouvée: HKLM\Software\Classes\Interface\{F5FC30C3-68AD-451B-8BC1-8ABD98F2C69A}
    Clé trouvée: HKLM\Software\Classes\TypeLib\{3088C799-9630-4719-A471-4544D7CABC2D}
    Clé trouvée: HKLM\Software\Classes\TypeLib\{4509D3CC-B642-4745-B030-645B79522C6D}
    Clé trouvée: HKLM\Software\Classes\TypeLib\{77AA25E8-6083-4949-A831-9CB11861DC10}
    Clé trouvée: HKLM\Software\Classes\BHO.PSHelper
    Clé trouvée: HKLM\Software\Classes\BHO.PSHelper.1
    Clé trouvée: HKLM\Software\Classes\AppID\BHO.dll
    Clé trouvée: HKLM\Software\Classes\AppID\{055069F3-F78B-4BD1-A277-FE66648D3300}
    Clé trouvée: HKLM\Software\Install Pedia Limited
    Clé trouvée: HKLM\Software\Live-Player
    Clé trouvée: HKCU\Software\FBSearch
    Clé trouvée: HKCU\Software\Live-Player
    Clé trouvée: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{19F2B849-4ADE-4d4b-85F9-C31C643DBDE9}
    Clé trouvée: HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BEA9079D-A05D-40f3-B3F1-581C611A9B63}

    Valeur trouvée: HKCU\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing\Trust Database\0|goicfboogidikkejccmclpieicihhlpo jimddp
    Valeur trouvée: HKCU\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing\Trust Database\0|goicfboogidikkejccmclpieicihhlpo hpfanicgkffmccehnpkikogcffaepkfp
    Valeur trouvée: HKCU\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing\Trust Database\0|goicfboogidikkejccmclpieicihhlpo dgnckdmmolaijpbbakmplfhlfpdhglgc
    Valeur trouvée: HKLM\Software\Microsoft\Windows\CurrentVersion\Run|installer
    Valeur trouvée: HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser|{1BB22D38-A411-4B13-A746-C2A4F4EC7344}

    ============== SCAN ADDITIONNEL ==============

    ** Mozilla Firefox Version [3.6.13 (fr)] **

    -- C:\Documents and Settings\Propriétaire\Application Data\Mozilla\FireFox\Profiles\8vneijw1.default\Prefs.js --
    browser.download.lastDir, C:\\Documents and Settings\\Propriétaire\\Bureau
    browser.search.defaultenginename, Fast Browser Search
    browser.search.defaulturl, hxxp://www.fastbrowsersearch.com/results/results.aspx?s=DEF&v=19&q=
    browser.search.selectedEngine, Fast Browser Search
    browser.startup.homepage, hxxp://www.sfr.fr/communiquer/messagerie/sfr-messagerie/authentification/index.jsp?domain=webm...
    browser.startup.homepage_override.mstone, rv:1.9.2.13
    keyword.URL, hxxp://www.fastbrowsersearch.com/results/results.aspx?s=NAUS&v=19&tid={DE816129-E39D-35D5-B696-9255364FA11E...
    privacy.popups.showBrowserMessage, false

    ========================================

    ** Internet Explorer Version [8.0.6001.18702] **

    [HKCU\Software\Microsoft\Internet Explorer\Main]
    AutoHide: yes
    Default_Page_URL: hxxp://go.microsoft.com/fwlink/?LinkId=69157
    Do404Search: 0x01000000
    Enable Browser Extensions: yes
    Local Page: C:\WINDOWS\system32\blank.htm
    Search Page: hxxp://search.live.com
    Show_ToolBar: yes
    Start Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
    Use Search Asst: no

    [HKLM\Software\Microsoft\Internet Explorer\Main]
    Default_Page_URL: hxxp://go.microsoft.com/fwlink/?LinkId=69157
    Default_Search_URL: hxxp://go.microsoft.com/fwlink/?LinkId=54896
    Delete_Temp_Files_On_Exit: yes
    Local Page: C:\WINDOWS\system32\blank.htm
    Search bar: hxxp://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
    Search Page: hxxp://go.microsoft.com/fwlink/?LinkId=54896
    Start Page: hxxp://go.microsoft.com/fwlink/?LinkId=69157

    [HKLM\Software\Microsoft\Internet Explorer\ABOUTURLS]
    Tabs: res://ieframe.dll/tabswelcome.htm
    Blank: res://mshtml.dll/blank.htm

    ========================================

    C:\Program Files\Ad-Remover\Quarantine: 0 Fichier(s)
    C:\Program Files\Ad-Remover\Backup: 1 Fichier(s)

    C:\Ad-Report-SCAN[1].txt - 13/01/2011 (5455 Octet(s))

    Fin à: 22:33:35, 13/01/2011

    ============== E.O.F ==============
    Fix Navipromo version 4.0.9 commencé le 13/01/2011 22:26:35,29

    !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
    !!! Postez ce rapport sur le forum pour le faire analyser !!!

    Outil exécuté depuis C:\navilog1

    Mise à jour le 24.11.2010 à 16h00 par IL-MAFIOSO

    Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 3
    X86-based PC ( Uniprocessor Free : Intel(R) Celeron(R) CPU 2.50GHz )
    BIOS : Phoenix - AwardBIOS v6.00PG
    USER : Propriétaire ( Administrator )
    BOOT : Normal boot

    Antivirus : AntiVir Desktop 9.0.1.32 (Not Activated)

    A:\ (USB)
    C:\ (Local Disk) - NTFS - Total:70 Go (Free:47 Go)
    D:\ (Local Disk) - FAT32 - Total:4 Go (Free:0 Go)
    E:\ (CD or DVD)
    F:\ (CD or DVD)

    Recherche executée en mode normal

    [b]Aucune Infection Navipromo/Egdaccess trouvée/b

    *** Scan terminé 13/01/2011 22:26:56,96 ***Fix Navipromo version 4.0.9 commencé le 13/01/2011 22:26:35,29

    !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
    !!! Postez ce rapport sur le forum pour le faire analyser !!!

    Outil exécuté depuis C:\navilog1

    Mise à jour le 24.11.2010 à 16h00 par IL-MAFIOSO

    Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 3
    X86-based PC ( Uniprocessor Free : Intel(R) Celeron(R) CPU 2.50GHz )
    BIOS : Phoenix - AwardBIOS v6.00PG
    USER : Propriétaire ( Administrator )
    BOOT : Normal boot

    Antivirus : AntiVir Desktop 9.0.1.32 (Not Activated)

    A:\ (USB)
    C:\ (Local Disk) - NTFS - Total:70 Go (Free:47 Go)
    D:\ (Local Disk) - FAT32 - Total:4 Go (Free:0 Go)
    E:\ (CD or DVD)
    F:\ (CD or DVD)

    Recherche executée en mode normal

    [b]Aucune Infection Navipromo/Egdaccess trouvée/b

    *** Scan terminé 13/01/2011 22:26:56,96 ***

    ############################## | UsbFix 7.037 | [Recherche]

    Utilisateur: Propriétaire (Administrateur) # MARSEILLAIS [ ]
    Mis à jour le 10/01/2011 par El Desaparecido / C_XX
    Lancé à 22:35:51 | 13/01/2011
    Site Web: http://www.teamxscript.org
    Contact: eldesaparecido@teamxscript.org

    CPU: Intel(R) Celeron(R) CPU 2.50GHz
    Microsoft Windows XP Édition familiale (5.1.2600 32-Bit) # Service Pack 3
    Internet Explorer 8.0.6001.18702

    Pare-feu Windows: Activé
    Antivirus: AntiVir Desktop 9.0.1.32 [(!) Disabled | Updated]
    RAM -> 511 Mo
    C:\ (%systemdrive%) -> Disque fixe # 70 Go (48 Go libre(s) - 68%) [PRESARIO] # NTFS
    D:\ -> Disque fixe # 4 Go (561 Mo libre(s) - 13%) [PRESARIO_RP] # FAT32
    E:\ -> CD-ROM
    F:\ -> CD-ROM

    ################## | Éléments infectieux |

    ################## | Registre |

    ################## | Mountpoints2 |

    HKCU\.\.\.\.\Explorer\MountPoints2\{d2992242-9fae-11df-9d04-0011679a6a10}
    Shell\AutoRun\Command = G:\Startme.exe

    ################## | Vaccin |

    (!) Cet ordinateur n'est pas vacciné!

    ################## | E.O.F |
    0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. Patdam73 Messages postés 271 Statut Membre 13
     
    Bonjour

    on continue ;-)

    Ad-Remover : Suppression

    Relance Ad-remover.exe, par un double-clique sur l'icône Ad-remover située sur ton Bureau.
    Sur la page, clique sur le bouton Nettoyer
    Laisse travailler l'outil
    Poste le rapport qui apparait à la fin
    (Le rapport est sauvegardé aussi sous C:\Ad-reportClean.Txt)

    (CTRL+A pour tout sélectionner, CTRL+C pour copier et CTRL+V pour coller)

    ==========

    USBFIX : Suppression

    /!\ Déconnecte-toi et ferme toutes les applications en cours /!\
    /!\ Branche tous tes périphériques ayant pu être infectés (clés usb, disque dur externe, etc ...) /!\

    [*] Double-clique sur UsbFix pour lancer le programme
    Note :
    Pour Vista et Windows 7 faites un clic droit sur l'icône et sélectionnez Exécuter en tant qu'administrateur.

    [*]Clique sur Suppression et valide
    [*]Accepte le redémarrage du pc puis laisse travailler l'outil
    [*]A la fin, un rapport apparaitra (sinon, il est situé ici C:\Usbfix.txt).

    Poste-le dans ta prochaine réponse.

    ==========

    Télécharge MalwareByte's Anti-Malware sur ton bureau.

    https://www.commentcamarche.net/telecharger/securite/14361-malwarebytes-anti-malware/

    [*]Installe le programme
    [*]Lance-le et mets à jour la base de définition en allant dans l'onglet "mise à jour" puis "Recherche de mise à jour".
    [*]Choisis Exécuter un examen rapide puis Rechercher
    [*]Laisse l'analyse se faire (cela peut durer longtemps).
    Une fois le scan terminé, clique sur Afficher les résultats, vérifie que les éléments trouvés soient cochés puis clique sur Supprimer la sélection en bas.
    [*]Un redémarrage peut être nécessaire.
    Un rapport va s'afficher, enregistre-le sur ton bureau. Sinon, après le démarrage, il se trouvera dans l'onglet Rapports/logs de Malwarebyte.
    Poste le rapport svp

    =========

    Refais un nouveau scan avec zhpdiag

    pour résumer, il me faut donc

    ton rapport ad remover
    ton rapport usbfix
    ton rapport mbam
    et ton rapport zhpdiag

    @+
    0
  7. noya83000 Messages postés 19 Statut Membre
     
    BONSOIR voici ce que tu m a demandé : ======= RAPPORT D'AD-REMOVER 2.0.0.2,D | UNIQUEMENT XP/VISTA/7 =======

    Mis à jour par TeamXscript le 12/01/11 à 19:00
    Contact: AdRemover[DOT]contact[AT]gmail[DOT]com
    Site web: http://www.teamxscript.org

    C:\Program Files\Ad-Remover\main.exe (CLEAN [2]) -> Lancé à 15:24:17 le 14/01/2011, Mode normal

    Microsoft Windows XP Édition familiale Service Pack 3 (X86)
    Propriétaire@MARSEILLAIS ( )

    ============== ACTION(S) ==============

    (!) -- Fichiers temporaires supprimés.

    ============== SCAN ADDITIONNEL ==============

    ** Mozilla Firefox Version [3.6.13 (fr)] **

    -- C:\Documents and Settings\Propriétaire\Application Data\Mozilla\FireFox\Profiles\8vneijw1.default\Prefs.js --
    browser.download.lastDir, C:\\Documents and Settings\\Propriétaire\\Bureau
    browser.startup.homepage, hxxp://www.sfr.fr/communiquer/messagerie/sfr-messagerie/authentification/index.jsp?domain=webm...
    browser.startup.homepage_override.mstone, rv:1.9.2.13
    privacy.popups.showBrowserMessage, false

    ========================================

    ** Internet Explorer Version [8.0.6001.18702] **

    [HKCU\Software\Microsoft\Internet Explorer\Main]
    AutoHide: yes
    Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
    Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
    Do404Search: 0x01000000
    Enable Browser Extensions: yes
    Local Page: C:\WINDOWS\system32\blank.htm
    Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
    Show_ToolBar: yes
    Start Page: hxxp://fr.msn.com/
    Use Search Asst: no

    [HKLM\Software\Microsoft\Internet Explorer\Main]
    Default_Page_URL: hxxp://go.microsoft.com/fwlink/?LinkId=54896
    Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
    Delete_Temp_Files_On_Exit: yes
    Local Page: C:\WINDOWS\system32\blank.htm
    Search bar: hxxp://search.msn.com/spbasic.htm
    Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
    Start Page: hxxp://fr.msn.com/

    [HKLM\Software\Microsoft\Internet Explorer\ABOUTURLS]
    Tabs: res://ieframe.dll/tabswelcome.htm
    Blank: res://mshtml.dll/blank.htm

    ========================================

    C:\Program Files\Ad-Remover\Quarantine: 13 Fichier(s)
    C:\Program Files\Ad-Remover\Backup: 15 Fichier(s)

    C:\Ad-Report-CLEAN[1].txt - 14/01/2011 (7475 Octet(s))
    C:\Ad-Report-CLEAN[2].txt - 14/01/2011 (596 Octet(s))

    Fin à: 15:25:36, 14/01/2011

    ============== E.O.F ==============
    ############################## | UsbFix 7.037 | [Suppression]

    Utilisateur: Propriétaire (Administrateur) # MARSEILLAIS [ ]
    Mis à jour le 10/01/2011 par El Desaparecido / C_XX
    Lancé à 15:31:12 | 14/01/2011
    Site Web: http://www.teamxscript.org
    Contact: eldesaparecido@teamxscript.org

    CPU: Intel(R) Celeron(R) CPU 2.50GHz
    Microsoft Windows XP Édition familiale (5.1.2600 32-Bit) # Service Pack 3
    Internet Explorer 8.0.6001.18702

    Pare-feu Windows: Activé
    Antivirus: AntiVir Desktop 9.0.1.32 [(!) Disabled | Updated]
    RAM -> 511 Mo
    C:\ (%systemdrive%) -> Disque fixe # 70 Go (48 Go libre(s) - 68%) [PRESARIO] # NTFS
    D:\ -> Disque fixe # 4 Go (561 Mo libre(s) - 13%) [PRESARIO_RP] # FAT32
    E:\ -> CD-ROM
    F:\ -> CD-ROM
    G:\ -> Disque amovible # 4 Go (4 Go libre(s) - 94%) [KINGSTON] # FAT32

    ################## | Éléments infectieux |

    Supprimé! C:\Recycler\S-1-5-21-3959529750-497367016-2629840051-1003

    ################## | Registre |

    ################## | Mountpoints2 |

    Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{d2992242-9fae-11df-9d04-0011679a6a10}

    ################## | Listing |

    [15/08/2009 - 07:44:13 | D ] C:\52353c8e279c7c69775a8d
    [15/08/2009 - 19:33:27 | D ] C:\5a015879084f6ea35ff3b8
    [15/08/2009 - 07:44:07 | D ] C:\614e0e9f57fc66d62edf
    [28/11/2006 - 17:10:15 | D ] C:\9db95885eeb86695ab8682fa4bef
    [14/01/2011 - 15:20:54 | | 7475] C:\Ad-Report-CLEAN[1].txt
    [14/01/2011 - 15:25:36 | | 2470] C:\Ad-Report-CLEAN[2].txt
    [30/12/2008 - 07:31:15 | D ] C:\assembly
    [01/01/2003 - 22:11:10 | | 0] C:\AUTOEXEC.BAT
    [11/02/2010 - 18:36:03 | RASHD ] C:\autorun.inf
    [24/12/2010 - 13:45:57 | D ] C:\BJPrinter
    [20/03/2005 - 19:44:55 | | 196] C:\BOOT.BAK
    [01/04/2008 - 18:31:12 | | 291] C:\boot.ini
    [20/09/2003 - 20:08:00 | | 4952] C:\Bootfont.bin
    [12/10/2010 - 13:52:56 | D ] C:\CanonMP
    [13/01/2011 - 22:27:11 | | 902] C:\cleannavi.txt
    [20/03/2005 - 19:53:21 | D ] C:\cmdcons
    [20/09/2003 - 18:38:00 | N | 249136] C:\cmldr
    [01/01/2003 - 22:11:10 | | 0] C:\CONFIG.SYS
    [08/12/2006 - 19:28:35 | D ] C:\d4a402ea74453679f798a3f6ad
    [30/09/2005 - 20:51:24 | D ] C:\DBBackup
    [28/07/2009 - 11:29:07 | D ] C:\Documents and Settings
    [16/12/2009 - 08:46:36 | | 12660] C:\drwtsn32.log
    [21/03/2005 - 03:37:08 | D ] C:\hp
    [21/03/2005 - 03:37:07 | D ] C:\I386
    [01/01/2003 - 22:11:10 | | 0] C:\IO.SYS
    [18/01/2008 - 19:45:56 | | 258] C:\IPH.PH
    [24/12/2008 - 19:05:12 | | 485] C:\LOG8.log
    [24/12/2008 - 19:05:12 | | 0] C:\LOG8.tmp
    [21/08/2008 - 12:53:49 | | 485] C:\LOGF.log
    [01/01/2003 - 22:11:10 | | 0] C:\MSDOS.SYS
    [13/12/2009 - 09:17:15 | | 16384] C:\mtwb.dat
    [15/08/2006 - 19:15:42 | D ] C:\My Shared Folder
    [13/01/2011 - 22:26:56 | D ] C:\Navilog1
    [17/01/2007 - 23:50:03 | N | 47564] C:\NTDETECT.COM
    [05/11/2008 - 16:02:05 | N | 252240] C:\ntldr
    [29/02/2004 - 16:44:34 | | 52576] C:\orange.bmp
    [14/01/2011 - 15:22:08 | ASH | 390070272] C:\pagefile.sys
    [14/01/2011 - 15:20:26 | D ] C:\Program Files
    [21/07/2005 - 01:57:55 | D ] C:\Python22
    [14/01/2011 - 15:36:39 | SHD ] C:\RECYCLER
    [12/02/2010 - 03:43:29 | SHD ] C:\System Volume Information
    [01/10/2008 - 19:35:21 | D ] C:\temp
    [14/01/2011 - 15:36:39 | D ] C:\UsbFix
    [14/01/2011 - 15:36:40 | A | 962] C:\UsbFix.txt
    [14/01/2011 - 15:23:26 | D ] C:\WINDOWS
    [17/01/2007 - 09:45:48 | | 274425064] C:\WindowsXP-KB835935-SP2-FRA.exe
    [11/02/2010 - 16:53:10 | | 13918] C:\ZHPExportRegistry-11-02-2010-16-53-09.txt
    [27/07/2001 - 21:07:38 | N | 0] D:\AUTOEXEC.BAT
    [11/02/2010 - 18:36:04 | RASHD ] D:\autorun.inf
    [09/01/2002 - 10:52:30 | N | 244] D:\BOOT.INI
    [03/10/2003 - 12:56:26 | D ] D:\cmdcons
    [17/08/2001 - 00:26:26 | N | 237728] D:\CMLDR
    [27/07/2001 - 21:07:38 | N | 0] D:\CONFIG.SYS
    [09/09/2002 - 14:14:14 | SH | 100] D:\Desktop.ini
    [10/09/2002 - 08:21:08 | N | 7850] D:\Folder.htt
    [30/04/2001 - 11:16:46 | N | 14] D:\GRAPH
    [25/01/2002 - 09:21:24 | N | 0] D:\GRAPH16
    [10/09/2002 - 12:54:58 | N | 40960] D:\Info.exe
    [27/07/2001 - 21:07:38 | N | 0] D:\IO.SYS
    [03/10/2003 - 12:50:42 | D ] D:\MiniNT
    [27/07/2001 - 21:07:38 | N | 0] D:\MSDOS.SYS
    [25/07/2001 - 13:00:00 | N | 45124] D:\NTDETECT.COM
    [17/08/2001 - 06:32:24 | N | 0] D:\NTFS
    [25/07/2001 - 13:00:00 | N | 222880] D:\NTLDR
    [11/11/2003 - 10:02:44 | D ] D:\PRELOAD
    [03/03/2003 - 05:46:06 | N | 111377] D:\protect.ed
    [11/11/2003 - 02:44:08 | N | 36] D:\SAVEFILE.DIR
    [30/04/2001 - 11:16:46 | N | 14] D:\SVGA
    [03/03/2003 - 12:41:48 | N | 88038] D:\warning.BMP
    [15/12/2003 - 13:01:06 | N | 498] D:\BATCH.OLD
    [11/11/2003 - 03:02:40 | N | 11] D:\BLOCK.RIN
    [04/01/2003 - 18:00:26 | D ] D:\I386
    [11/11/2003 - 03:08:08 | N | 848] D:\MASTER.LOG
    [04/01/2003 - 18:19:06 | D ] D:\TOOLS
    [18/08/2001 - 06:00:00 | N | 10] D:\WIN51
    [22/01/2001 - 06:00:00 | N | 11] D:\WIN51.B2
    [25/07/2001 - 06:00:00 | N | 11] D:\WIN51.RC1
    [25/07/2001 - 11:47:04 | N | 11] D:\WIN51.RC2
    [18/08/2001 - 06:00:00 | N | 10] D:\WIN51IC
    [20/03/2001 - 06:00:00 | N | 11] D:\WIN51IC.B2
    [25/07/2001 - 06:00:00 | N | 11] D:\WIN51IC.RC1
    [25/07/2001 - 06:00:00 | N | 11] D:\WIN51IC.RC2
    [17/08/2001 - 06:00:00 | N | 10] D:\WIN51IP
    [22/01/2001 - 06:00:00 | N | 11] D:\WIN51IP.B2
    [25/07/2001 - 11:47:04 | N | 11] D:\WIN51IP.RC2
    [17/08/2001 - 04:17:02 | N | 184] D:\WINBOM.INI
    [04/01/2003 - 18:19:54 | D ] D:\hp
    [04/01/2003 - 18:19:56 | D ] D:\Réinstallation Système
    [11/11/2003 - 03:08:08 | N | 848] D:\USER
    [20/01/2004 - 21:21:48 | N | 1552] D:\BATCH.LOG
    [24/10/2008 - 19:47:00 | D ] D:\TW
    [18/02/2004 - 09:53:24 | SHD ] D:\Recycled
    [18/02/2004 - 09:53:24 | SHD ] D:\System Volume Information
    [24/10/2008 - 19:47:04 | N | 2632] D:\Uninst.isu
    [24/10/2008 - 19:47:00 | D ] D:\PRC
    [22/12/2006 - 17:41:50 | D ] D:\PhotoImpression
    [09/01/2011 - 20:03:30 | D ] G:\4 ans amelle
    [09/01/2011 - 20:10:28 | D ] G:\2006-01-31 001

    ################## | Vaccin |

    C:\Autorun.inf -> Dossier créé par UsbFix (El Desaparecido & C_XX)
    D:\Autorun.inf -> Dossier créé par UsbFix (El Desaparecido & C_XX)
    G:\Autorun.inf -> Dossier créé par UsbFix (El Desaparecido & C_XX)

    ################## | Upload |

    Veuillez envoyer le fichier: C:\UsbFix_Upload_Me_MARSEILLAIS.zip
    http://www.teamxscript.org/Upload.php
    Merci de votre contribution.

    ################## | E.O.F |
    Malwarebytes' Anti-Malware 1.50.1.1100
    www.malwarebytes.org

    Version de la base de données: 5519

    Windows 5.1.2600 Service Pack 3
    Internet Explorer 8.0.6001.18702

    14/01/2011 16:01:07
    mbam-log-2011-01-14 (16-01-07).txt

    Type d'examen: Examen rapide
    Elément(s) analysé(s): 143949
    Temps écoulé: 14 minute(s), 6 seconde(s)

    Processus mémoire infecté(s): 0
    Module(s) mémoire infecté(s): 0
    Clé(s) du Registre infectée(s): 0
    Valeur(s) du Registre infectée(s): 0
    Elément(s) de données du Registre infecté(s): 0
    Dossier(s) infecté(s): 0
    Fichier(s) infecté(s): 0

    Processus mémoire infecté(s):
    (Aucun élément nuisible détecté)

    Module(s) mémoire infecté(s):
    (Aucun élément nuisible détecté)

    Clé(s) du Registre infectée(s):
    (Aucun élément nuisible détecté)

    Valeur(s) du Registre infectée(s):
    (Aucun élément nuisible détecté)

    Elément(s) de données du Registre infecté(s):
    (Aucun élément nuisible détecté)

    Dossier(s) infecté(s):
    (Aucun élément nuisible détecté)

    Fichier(s) infecté(s):
    (Aucun élément nuisible détecté)
    et enfin le dernier :http://www.cijoint.fr/cjlink.php?file=cj201101/cijLXJrOUk.txt merci
    0
  8. Patdam73 Messages postés 271 Statut Membre 13
     
    Bonjour

    Peux tu envoyer le fichier que usbfix te demande stp ?

    C'est très simple, connecte toi sur le lien ci dessous :

    http://www.teamxscript.org/Upload.php

    Clique sur le bouton parcourir, et sélectionne le fichier

    UsbFix_Upload_Me_MARSEILLAIS.zip

    situé directement sur C:

    Merci pour ta contribution.

    Bon on continu :

    Attention deux logiciels vont être désinstallés, il se peut qu'au cours de ces désinstallation une boite de dialogue te demande de redémarrer le pc.
    Ne le fais pas. Cela stopperai le travail de zhpfix.
    De même si ton navigateur s'ouvre pendant la désinstallation, ferme le.

    ZHPFix

    [*] Ferme toutes tes applications en cours.

    [*] Double clique sur l'icône ZHPFix sur ton bureau
    Note :
    Pour Vista et Windows 7 faites un clic droit sur l'icône et sélectionnez Exécuter en tant qu'administrateur.

    [*] Copie les lignes ci dessous :

    R3 - URLSearchHook: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} Clé orpheline
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} Clé orpheline
    O2 - BHO: (no name) - {3049C3E9-B461-4BC5-8870-4C09146192CA} Clé orpheline
    O3 - Toolbar: (no name) - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} . (.Pas de propriétaire - Pas de description.) --  (.not file.)
    O8 - Extra context menu item: Easy-WebPrint Ajouter à la liste d'impressions - (.not file.) - C:\Program Files\Canon\Easy-WebPrint\Resource.dll
    O8 - Extra context menu item: Easy-WebPrint Impression rapide - (.not file.) - C:\Program Files\Canon\Easy-WebPrint\Resource.dll
    O8 - Extra context menu item: Easy-WebPrint Imprimer - (.not file.) - C:\Program Files\Canon\Easy-WebPrint\Resource.dll
    O8 - Extra context menu item: Easy-WebPrint Prévisualiser - (.not file.) - C:\Program Files\Canon\Easy-WebPrint\Resource.dll
    O8 - Extra context menu item: Google Sidewiki... - (.not file.) - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_950DF09FAB501E03.dll
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} . (.not file.) - (.not file.)
    O42 - Logiciel: Java(TM) 6 Update 18 - (.Sun Microsystems, Inc..) [HKLM] -- {26A24AE4-039D-4CA4-87B4-2F83216018F0}
    O42 - Logiciel: Fast Browser Search (My Tattoons) - (.Make The Web Better, LLC.) [HKLM] -- TBSB07183.TBSB07183Toolbar
    [HKCU\Software\YahooPartnerToolbar]
    [HKCU\Software\sponsoradulto]
    [HKLM\Software\McAfee.com]
    [HKLM\Software\Symantec]
    O43 - CFD: 01/01/2003 - 22:11:12 ----D- C:\Documents and Settings\Propriétaire\Application Data\Symantec
    O64 - Services: CurCS - (.not file.) - avast! Asynchronous Virus Monitor (Aavmker4)  .(.Pas de propriétaire - Pas de description.) - LEGACY_AAVMKER4
    O64 - Services: CurCS - (.not file.) - aswFsBlk (aswFsBlk)  .(.Pas de propriétaire - Pas de description.) - LEGACY_ASWFSBLK
    O64 - Services: CurCS - (.not file.) - avast! Standard Shield Support (aswMon2)  .(.Pas de propriétaire - Pas de description.) - LEGACY_ASWMON2
    O64 - Services: CurCS - (.not file.) - aswRdr (aswRdr)  .(.Pas de propriétaire - Pas de description.) - LEGACY_ASWRDR
    O64 - Services: CurCS - (.not file.) - avast! Self Protection (aswSP)  .(.Pas de propriétaire - Pas de description.) - LEGACY_ASWSP
    O64 - Services: CurCS - (.not file.) - avast! Network Shield Support (aswTdi)  .(.Pas de propriétaire - Pas de description.) - LEGACY_ASWTDI
    O64 - Services: CurCS - (.not file.) - avast! Antivirus (avast! Antivirus)  .(.Pas de propriétaire - Pas de description.) - LEGACY_AVAST!_ANTIVIRUS
    O64 - Services: CurCS - (.not file.) - AVG7 Wrap Driver (Avg7RsW)  .(.Pas de propriétaire - Pas de description.) - LEGACY_AVG7RSW
    O64 - Services: CurCS - (.not file.) - AVG Anti-Spyware Clean Driver (AvgAsCln)  .(.Pas de propriétaire - Pas de description.) - LEGACY_AVGASCLN
    O64 - Services: CurCS - (.not file.) - SymEvent (SymEvent)  .(.Pas de propriétaire - Pas de description.) - LEGACY_SYMEVENT
    O64 - Services: CurCS - (.not file.) - SYMTDI (SYMTDI)  .(.Pas de propriétaire - Pas de description.) - LEGACY_SYMTDI
    O69 - SBI: SearchScopes [HKCU] {88d29ed6-740e-4bc6-b63b-8790e04cf92e} - (Wibeez) - https://www.hugedomains.com/domain_profile.cfm?d=wibeez&e=com{searchTerms}
    
    


    [*] Clique sur le bouton H pour coller ces lignes

    [*] Clique sur le bouton OK.

    [*] Clique sur le bouton Tous pour les sélectionner.

    [*] Clique sur le bouton Nettoyer afin de les supprimer

    [*] Accepte la désinstallation des programmes si proposé, mais refuse le redémarrage de ton pc si également proposé, car cela stopperai ZHPFix.

    [*] Ton navigateur risque de s'ouvrir pendant la désinstallation des toolbars, pas de panique c'est normal, ferme les fenêtres tout simplement.

    [*] Redémarre le pc, copie et colle le rapport ZHPFix.txt qui s'affiche.
    Note : le rapport est enregistré sous C:\Program Files\ZHPDiag\ZHPFixReport.txt

    =======

    Dis moi si ton problème est toujours la.

    Et refais un nouveau scan zhpdiag

    Bon week
    0
  9. noya83000 Messages postés 19 Statut Membre
     
    bonjour apres l execution sur quoi je dois appuyer pour afficher les lignes ? merci
    0
  10. Patdam73 Messages postés 271 Statut Membre 13
     
    Tu copies le rapport ZHPFix.txt qui se trouve sur ton burreau et tu le colle dans ta prochaine réponse
    0
  11. noya83000 Messages postés 19 Statut Membre
     
    bonsoir ca y est j ai copié les lines et j ai supprimé comme demandé voici le rapport :Rapport de ZHPFix 1.12.3227 par Nicolas Coolman, Update du 16/12/2010
    Fichier d'export Registre : C:\ZHPExportRegistry-15-01-2011-21-31-12.txt
    Run by Propriétaire at 15/01/2011 21:31:12
    Windows XP Home Edition Service Pack 3 (Build 2600)
    Web site : http://www.premiumorange.com/zeb-help-process/zhpfix.html
    Contact : nicolascoolman@yahoo.fr

    ========== Clé(s) du Registre ==========
    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\TBSB07183.TBSB07183Toolbar] => Clé supprimée avec succès
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} Clé orpheline => Clé supprimée avec succès
    O2 - BHO: (no name) - {3049C3E9-B461-4BC5-8870-4C09146192CA} Clé orpheline => Clé supprimée avec succès
    O8 - Extra context menu item: Easy-WebPrint Ajouter à la liste d'impressions - (.not file.) - C:\Program Files\Canon\Easy-WebPrint\Resource.dll => Clé supprimée avec succès
    O8 - Extra context menu item: Easy-WebPrint Impression rapide - (.not file.) - C:\Program Files\Canon\Easy-WebPrint\Resource.dll => Clé supprimée avec succès
    O8 - Extra context menu item: Easy-WebPrint Imprimer - (.not file.) - C:\Program Files\Canon\Easy-WebPrint\Resource.dll => Clé supprimée avec succès
    O8 - Extra context menu item: Easy-WebPrint Prévisualiser - (.not file.) - C:\Program Files\Canon\Easy-WebPrint\Resource.dll => Clé supprimée avec succès
    O8 - Extra context menu item: Google Sidewiki... - (.not file.) - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_950DF09FAB501E03.dll => Clé supprimée avec succès
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} . (.not file.) - (.not file.) => Clé absente
    HKCU\Software\YahooPartnerToolbar => Clé supprimée avec succès
    HKCU\Software\sponsoradulto => Clé supprimée avec succès
    HKLM\Software\McAfee.com => Clé supprimée avec succès
    HKLM\Software\Symantec => Clé supprimée avec succès
    O64 - Services: CurCS - (.not file.) - avast! Asynchronous Virus Monitor (Aavmker4) .(.Pas de propriétaire - Pas de description.) - LEGACY_AAVMKER4 => Clé supprimée avec succès
    O64 - Services: CurCS - (.not file.) - aswFsBlk (aswFsBlk) .(.Pas de propriétaire - Pas de description.) - LEGACY_ASWFSBLK => Clé supprimée avec succès
    O64 - Services: CurCS - (.not file.) - avast! Standard Shield Support (aswMon2) .(.Pas de propriétaire - Pas de description.) - LEGACY_ASWMON2 => Clé supprimée avec succès
    O64 - Services: CurCS - (.not file.) - aswRdr (aswRdr) .(.Pas de propriétaire - Pas de description.) - LEGACY_ASWRDR => Clé supprimée avec succès
    O64 - Services: CurCS - (.not file.) - avast! Self Protection (aswSP) .(.Pas de propriétaire - Pas de description.) - LEGACY_ASWSP => Clé supprimée avec succès
    O64 - Services: CurCS - (.not file.) - avast! Network Shield Support (aswTdi) .(.Pas de propriétaire - Pas de description.) - LEGACY_ASWTDI => Clé supprimée avec succès
    O64 - Services: CurCS - (.not file.) - avast! Antivirus (avast! Antivirus) .(.Pas de propriétaire - Pas de description.) - LEGACY_AVAST!_ANTIVIRUS => Clé supprimée avec succès
    O64 - Services: CurCS - (.not file.) - AVG7 Wrap Driver (Avg7RsW) .(.Pas de propriétaire - Pas de description.) - LEGACY_AVG7RSW => Clé supprimée avec succès
    O64 - Services: CurCS - (.not file.) - AVG Anti-Spyware Clean Driver (AvgAsCln) .(.Pas de propriétaire - Pas de description.) - LEGACY_AVGASCLN => Clé supprimée avec succès
    O64 - Services: CurCS - (.not file.) - SymEvent (SymEvent) .(.Pas de propriétaire - Pas de description.) - LEGACY_SYMEVENT => Clé supprimée avec succès
    O64 - Services: CurCS - (.not file.) - SYMTDI (SYMTDI) .(.Pas de propriétaire - Pas de description.) - LEGACY_SYMTDI => Clé supprimée avec succès

    ========== Valeur(s) du Registre ==========
    R3 - URLSearchHook: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} Clé orpheline => Valeur supprimée avec succès
    O3 - Toolbar: (no name) - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} . (.Pas de propriétaire - Pas de description.) -- (.not file.) => Valeur supprimée avec succès

    ========== Elément(s) de donnée du Registre ==========
    O69 - SBI: SearchScopes [HKCU] {88d29ed6-740e-4bc6-b63b-8790e04cf92e} - (Wibeez) - https://www.hugedomains.com/domain_profile.cfm?d=wibeez&e=com{searchTerms} => Donnée remplacée avec succès

    ========== Dossier(s) ==========
    C:\Documents and Settings\Propriétaire\Application Data\Symantec => Supprimé et mis en quarantaine

    ========== Fichier(s) ==========
    c:\program files\canon\easy-webprint\resource.dll () => Fichier absent
    c:\program files\google\google toolbar\component\googletoolbardynamic_mui_en_950df09fab501e03.dll () => Fichier absent

    ========== Logiciel(s) ==========
    O42 - Logiciel: Java(TM) 6 Update 18 - (.Sun Microsystems, Inc..) [HKLM] -- {26A24AE4-039D-4CA4-87B4-2F83216018F0} => Logiciel supprimé avec succès
    O42 - Logiciel: Fast Browser Search (My Tattoons) - (.Make The Web Better, LLC.) [HKLM] -- TBSB07183.TBSB07183Toolbar => Logiciel supprimé avec succès

    ========== Récapitulatif ==========
    24 : Clé(s) du Registre
    2 : Valeur(s) du Registre
    1 : Elément(s) de donnée du Registre
    1 : Dossier(s)
    2 : Fichier(s)
    2 : Logiciel(s)

    End of the scan
    0
  12. Patdam73 Messages postés 271 Statut Membre 13
     
    Très bien, maintenant refait un nouveau scan avec zhpdiag et poste son rapport sur cijoint.fr comme précédemment

    @+
    0
  13. noya83000 Messages postés 19 Statut Membre
     
    le voici :http://www.cijoint.fr/cjlink.php?file=cj201101/cij4wBKLAf.txt
    0
  14. Patdam73 Messages postés 271 Statut Membre 13
     
    RE

    OneClick2RestorePoint :

    Télécharge Oneclick2RP de Laddy sur ton Bureau

    https://app.box.com/s/cqcsz5m0oz

    [*] Conserve-le tout au long de la désinfection et de l'optimisation.
    [*] Double clic dessus pour l'exécuter (Sous Vista/Seven, fais un clic droit et choisir Exécuter en tant qu'administrateur)
    [*] Entre la description suivante : Fin de désinfection
    [*] Clic sur le bouton Créer, puis sur le bouton OK.

    ========

    ZHPFix

    [*] Ferme toutes tes applications en cours.

    [*] Double clique sur l'icône ZHPFix sur ton bureau
    Note :
    Pour Vista et Windows 7 faites un clic droit sur l'icône et sélectionnez Exécuter en tant qu'administrateur.

    [*] Copie les lignes ci dessous :

    [HKCU\Software\TBSB07183]   
    O64 - Services: CurCS - (.not file.) - Gestionnaire de mise à jour Winsudate (WinSvc)  .(.Pas de propriétaire - Pas de description.) - LEGACY_WINSVC    
    [HKCU\Software\ALWIL Software]
    [HKLM\Software\ALWIL Software]
    O47 - AAKE:Key Export SP - "C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe" [Enabled] .(.Pas de propriétaire - Pas de description.) (.not file.) -- 
    O47 - AAKE:Key Export SP - "C:\temp\CI_HITACHI\MAJ_Hitachi.exe" [Enabled] .(.Pas de propriétaire - Pas de description.) (.not file.) -- 
    O47 - AAKE:Key Export SP - "C:\WINDOWS\system32\sessmgr.exe" [Disabled] .(.Microsoft Corporation - Gestionnaire de session de l'aide sur le Bureau à distance de Microsoft®.) (.not file.) -- C:\WINDOWS\system32\sessmgr.exe
    O47 - AAKE:Key Export SP - "D:\PPMate\ppmnet.exe" [Disabled] .(.Pas de propriétaire - Pas de description.) (.not file.) -- 
    O47 - AAKE:Key Export SP - "D:\PPMate\ppmate.exe" [Enabled] .(.Pas de propriétaire - Pas de description.) (.not file.) -- 
    O47 - AAKE:Key Export SP - "C:\Program Files\PPStream\PPStream.exe" [Disabled] .(.Pas de propriétaire - Pas de description.) (.not file.) -- 
    O47 - AAKE:Key Export SP - "C:\Documents and Settings\Propriétaire\Application Data\SopCast\adv\SopAdver.exe" [Disabled] .(.Pas de propriétaire - Pas de description.) (.not file.) -- 
    O47 - AAKE:Key Export SP - "C:\Program Files\SopCast\SopCast.exe" [Disabled] .(.Pas de propriétaire - Pas de description.) (.not file.) -- 
    O47 - AAKE:Key Export SP - "C:\Program Files\Internet Explorer\iexplore.exe" [Enabled] .(.Pas de propriétaire - Pas de description.) (.not file.) -- 
    O47 - AAKE:Key Export SP - "C:\Program Files\Messenger\msmsgs.exe" [Enabled] .(.Pas de propriétaire - Pas de description.) (.not file.) -- 
    O47 - AAKE:Key Export SP - "D:\VLC\vlc.exe" [Disabled] .(.Pas de propriétaire - Pas de description.) (.not file.) -- 
    O47 - AAKE:Key Export SP - "C:\Documents and Settings\Propriétaire\Bureau\sopcast\adv\SopAdver.exe" [Disabled] .(.Pas de propriétaire - Pas de description.) (.not file.) -- 
    O47 - AAKE:Key Export SP - "C:\Documents and Settings\Propriétaire\Bureau\sopcast\SopCast.exe" [Disabled] .(.Pas de propriétaire - Pas de description.) (.not file.) -- 
    O47 - AAKE:Key Export SP - "C:\Program Files\eMule\emule.exe" [Disabled] .(.Pas de propriétaire - Pas de description.) (.not file.) -- 
    O47 - AAKE:Key Export SP - "C:\Documents and Settings\Propriétaire\Bureau\eMule\emule.exe" [Disabled] .(.Pas de propriétaire - Pas de description.) (.not file.) -- 
    O47 - AAKE:Key Export SP - "%windir%\Network Diagnostic\xpnetdiag.exe" [Enabled] .(.Microsoft Corporation - Network Diagnostic for Windows XP.) (.not file.) -- C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O47 - AAKE:Key Export SP - "C:\Program Files\TVAnts\Tvants.exe" [Disabled] .(.Pas de propriétaire - Pas de description.) (.not file.) -- 
    O47 - AAKE:Key Export SP - "C:\Program Files\Real\RealPlayer\realplay.exe" [Enabled] .(.Pas de propriétaire - Pas de description.) (.not file.) -- 
    O47 - AAKE:Key Export SP - "C:\Program Files\Nokia\Nokia Home Media Server\Media Server\twonkymedia.exe" [Enabled] .(.Pas de propriétaire - Pas de description.) (.not file.) -- 
    O47 - AAKE:Key Export SP - "C:\Program Files\Nokia\Nokia Home Media Server\Media Server\twonkymediaserver.exe" [Enabled] .(.Pas de propriétaire - Pas de description.) (.not file.) -- 
    O47 - AAKE:Key Export SP - "C:\Program Files\TVUPlayer\TVUPlayer.exe" [Disabled] .(.Pas de propriétaire - Pas de description.) (.not file.) -- 
    O47 - AAKE:Key Export SP - "C:\Program Files\Bonjour\mDNSResponder.exe" [Enabled] .(.Pas de propriétaire - Pas de description.) (.not file.) -- 
    O47 - AAKE:Key Export SP - "C:\Program Files\iTunes\iTunes.exe" [Enabled] .(.Pas de propriétaire - Pas de description.) (.not file.) -- 
    O47 - AAKE:Key Export SP - "C:\Documents and Settings\Propriétaire\Mes documents\PROGRAMME\eMule\emule.exe" [Disabled] .(.Pas de propriétaire - Pas de description.) (.not file.) -- 
    O47 - AAKE:Key Export SP - "C:\Documents and Settings\Propriétaire\Mes documents\U96.exe" [Enabled] .(.Pas de propriétaire - Pas de description.) (.not file.) -- 
    O47 - AAKE:Key Export SP - "C:\Program Files\Yahoo!\Messenger\YServer.exe" [Enabled] .(.Pas de propriétaire - Pas de description.) (.not file.) -- 
    O47 - AAKE:Key Export SP - "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [Enabled] .(.Pas de propriétaire - Pas de description.) (.not file.) -- 
    O47 - AAKE:Key Export SP - "C:\Documents and Settings\Propriétaire\Bureau\U98.exe" [Disabled] .(.Pas de propriétaire - Pas de description.) (.not file.) -- 
    O47 - AAKE:Key Export SP - "C:\Documents and Settings\Propriétaire\Bureau\U99.exe" [Enabled] .(.Pas de propriétaire - Pas de description.) (.not file.) -- 
    O47 - AAKE:Key Export SP - "C:\Documents and Settings\Propriétaire\Mes documents\U99.exe" [Disabled] .(.Pas de propriétaire - Pas de description.) (.not file.) -- 
    O47 - AAKE:Key Export SP - "C:\Program Files\Windows Live\Messenger\wlcsdk.exe" [Enabled] .(.Pas de propriétaire - Pas de description.) (.not file.) -- 
    O47 - AAKE:Key Export SP - "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [Enabled] .(.Pas de propriétaire - Pas de description.) (.not file.) -- 
    O47 - AAKE:Key Export SP - "C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe" [Enabled] .(.Pas de propriétaire - Pas de description.) (.not file.) -- 
    O47 - AAKE:Key Export SP - "C:\Documents and Settings\Propriétaire\Bureau\BlueSoleil 6.4.240.2WithMobile\Crack\BlueSoleilCS.exe" [Enabled] .(.Pas de propriétaire - Pas de description.) (.not file.) -- 
    O47 - AAKE:Key Export SP - "C:\Program Files\Mozilla Firefox\firefox.exe" [Enabled] .(.Pas de propriétaire - Pas de description.) (.not file.) -- 
    047 - AAKE:Key Export DP - "C:\Program Files\Windows Live\Messenger\wlcsdk.exe" [Enabled] .(.Pas de propriétaire - Pas de description.) (.not file.) -- 
    O47 - AAKE:Key Export DP - "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [Enabled] .(.Pas de propriétaire - Pas de description.) (.not file.) -- 
    O47 - AAKE:Key Export DP - "C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe" [Enabled] .(.Pas de propriétaire - Pas de description.) (.not file.) -- 
    
    


    [*] Clique sur le bouton H pour coller ces lignes

    [*] Clique sur le bouton OK.

    [*] Clique sur le bouton Tous pour les sélectionner.

    [*] Clique sur le bouton Nettoyer afin de les supprimer

    [*] Accepte la désinstallation des programmes si proposé, mais refuse le redémarrage de ton pc si également proposé, car cela stopperai ZHPFix.

    [*] Ton navigateur risque de s'ouvrir pendant la désinstallation des toolbars, pas de panique c'est normal, ferme les fenêtres tout simplement.

    [*] Redémarre le pc, copie et colle le rapport ZHPFix.txt qui s'affiche.
    Note : le rapport est enregistré sous C:\Program Files\ZHPDiag\ZHPFixReport.txt

    =========

    Tu as des programmes qui ne sont pas à jour et donc comportent des failles de sécurité :

    Mise à jour Adobe Reader

    Connectes toi sur le site :

    https://get2.adobe.com/fr/reader/otherversions/

    Télécharges la dernière version de ce programme ,

    /!\ fais bien attention de décocher le sponsor McAffe associé avant le téléchargement
    .
    Installes la nouvelle version et vérifies s'il n'y a pas de mises à jour = lance le programme => cliques sur aide puis "rechercher les mises à jour". Laisse toi guider au besoin par le programme.

    ======

    Mise à jour Java

    La version de java qui est installée sur ton ordinateur n'est pas du tout à jour, c'est encore une faille de sécurité importante. Rends toi sur ce site :

    https://www.java.com/fr/download/uninstalltool.jsp

    cliques sur "vérifier la version de java" et laisses toi guider par le programme.

    Attention Une barre d'outil ou un moteur de recherche peut être proposé au cours de l'installation, pense à bien décocher la ou les cases devant son nom.

    ======

    Refais ensuite un nouveau scan zhpdiag

    @+
    0
  15. noya83000 Messages postés 19 Statut Membre
     
    bonjour voila :Rapport de ZHPFix 1.12.3227 par Nicolas Coolman, Update du 16/12/2010
    Fichier d'export Registre :
    Run by Propriétaire at 16/01/2011 07:24:20
    Windows XP Home Edition Service Pack 3 (Build 2600)
    Web site : http://www.premiumorange.com/zeb-help-process/zhpfix.html
    Contact : nicolascoolman@yahoo.fr

    ========== Clé(s) du Registre ==========
    HKCU\Software\TBSB07183 => Clé supprimée avec succès
    O64 - Services: CurCS - (.not file.) - Gestionnaire de mise à jour Winsudate (WinSvc) .(.Pas de propriétaire - Pas de description.) - LEGACY_WINSVC => Clé supprimée avec succès
    HKCU\Software\ALWIL Software => Clé supprimée avec succès
    HKLM\Software\ALWIL Software => Clé supprimée avec succès

    ========== Valeur(s) du Registre ==========
    O47 - AAKE:Key Export SP - "C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe" [Enabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "C:\temp\CI_HITACHI\MAJ_Hitachi.exe" [Enabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "C:\WINDOWS\system32\sessmgr.exe" [Disabled] .(.Microsoft Corporation - Gestionnaire de session de l'aide sur le Bureau à distance de Microsoft®.) (.not file.) -- C:\WINDOWS\system32\sessmgr.exe => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "D:\PPMate\ppmnet.exe" [Disabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "D:\PPMate\ppmate.exe" [Enabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "C:\Program Files\PPStream\PPStream.exe" [Disabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "C:\Documents and Settings\Propriétaire\Application Data\SopCast\adv\SopAdver.exe" [Disabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "C:\Program Files\SopCast\SopCast.exe" [Disabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "C:\Program Files\Internet Explorer\iexplore.exe" [Enabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "C:\Program Files\Messenger\msmsgs.exe" [Enabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "D:\VLC\vlc.exe" [Disabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "C:\Documents and Settings\Propriétaire\Bureau\sopcast\adv\SopAdver.exe" [Disabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "C:\Documents and Settings\Propriétaire\Bureau\sopcast\SopCast.exe" [Disabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "C:\Program Files\eMule\emule.exe" [Disabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "C:\Documents and Settings\Propriétaire\Bureau\eMule\emule.exe" [Disabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "%windir%\Network Diagnostic\xpnetdiag.exe" [Enabled] .(.Microsoft Corporation - Network Diagnostic for Windows XP.) (.not file.) -- C:\WINDOWS\Network Diagnostic\xpnetdiag.exe => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "C:\Program Files\TVAnts\Tvants.exe" [Disabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "C:\Program Files\Real\RealPlayer\realplay.exe" [Enabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "C:\Program Files\Nokia\Nokia Home Media Server\Media Server\twonkymedia.exe" [Enabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "C:\Program Files\Nokia\Nokia Home Media Server\Media Server\twonkymediaserver.exe" [Enabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "C:\Program Files\TVUPlayer\TVUPlayer.exe" [Disabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "C:\Program Files\Bonjour\mDNSResponder.exe" [Enabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "C:\Program Files\iTunes\iTunes.exe" [Enabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "C:\Documents and Settings\Propriétaire\Mes documents\PROGRAMME\eMule\emule.exe" [Disabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "C:\Documents and Settings\Propriétaire\Mes documents\U96.exe" [Enabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "C:\Program Files\Yahoo!\Messenger\YServer.exe" [Enabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [Enabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "C:\Documents and Settings\Propriétaire\Bureau\U98.exe" [Disabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "C:\Documents and Settings\Propriétaire\Bureau\U99.exe" [Enabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "C:\Documents and Settings\Propriétaire\Mes documents\U99.exe" [Disabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "C:\Program Files\Windows Live\Messenger\wlcsdk.exe" [Enabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [Enabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe" [Enabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "C:\Documents and Settings\Propriétaire\Bureau\BlueSoleil 6.4.240.2WithMobile\Crack\BlueSoleilCS.exe" [Enabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "C:\Program Files\Mozilla Firefox\firefox.exe" [Enabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export DP - "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [Enabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export DP - "C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe" [Enabled] .(.) (.not file.) -- => Valeur supprimée avec succès

    ========== Autre ==========
    047 - AAKE:Key Export DP - "C:\Program Files\Windows Live\Messenger\wlcsdk.exe" [Enabled] .(.Pas de propriétaire - Pas de description.) (.not file.) -- => Format Non supporté

    ========== Récapitulatif ==========
    4 : Clé(s) du Registre
    37 : Valeur(s) du Registre
    1 : Autre

    End of the scan
    Rapport de ZHPFix 1.12.3227 par Nicolas Coolman, Update du 16/12/2010
    Fichier d'export Registre :
    Run by Propriétaire at 16/01/2011 07:24:20
    Windows XP Home Edition Service Pack 3 (Build 2600)
    Web site : http://www.premiumorange.com/zeb-help-process/zhpfix.html
    Contact : nicolascoolman@yahoo.fr

    ========== Clé(s) du Registre ==========
    HKCU\Software\TBSB07183 => Clé supprimée avec succès
    O64 - Services: CurCS - (.not file.) - Gestionnaire de mise à jour Winsudate (WinSvc) .(.Pas de propriétaire - Pas de description.) - LEGACY_WINSVC => Clé supprimée avec succès
    HKCU\Software\ALWIL Software => Clé supprimée avec succès
    HKLM\Software\ALWIL Software => Clé supprimée avec succès

    ========== Valeur(s) du Registre ==========
    O47 - AAKE:Key Export SP - "C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe" [Enabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "C:\temp\CI_HITACHI\MAJ_Hitachi.exe" [Enabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "C:\WINDOWS\system32\sessmgr.exe" [Disabled] .(.Microsoft Corporation - Gestionnaire de session de l'aide sur le Bureau à distance de Microsoft®.) (.not file.) -- C:\WINDOWS\system32\sessmgr.exe => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "D:\PPMate\ppmnet.exe" [Disabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "D:\PPMate\ppmate.exe" [Enabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "C:\Program Files\PPStream\PPStream.exe" [Disabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "C:\Documents and Settings\Propriétaire\Application Data\SopCast\adv\SopAdver.exe" [Disabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "C:\Program Files\SopCast\SopCast.exe" [Disabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "C:\Program Files\Internet Explorer\iexplore.exe" [Enabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "C:\Program Files\Messenger\msmsgs.exe" [Enabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "D:\VLC\vlc.exe" [Disabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "C:\Documents and Settings\Propriétaire\Bureau\sopcast\adv\SopAdver.exe" [Disabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "C:\Documents and Settings\Propriétaire\Bureau\sopcast\SopCast.exe" [Disabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "C:\Program Files\eMule\emule.exe" [Disabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "C:\Documents and Settings\Propriétaire\Bureau\eMule\emule.exe" [Disabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "%windir%\Network Diagnostic\xpnetdiag.exe" [Enabled] .(.Microsoft Corporation - Network Diagnostic for Windows XP.) (.not file.) -- C:\WINDOWS\Network Diagnostic\xpnetdiag.exe => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "C:\Program Files\TVAnts\Tvants.exe" [Disabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "C:\Program Files\Real\RealPlayer\realplay.exe" [Enabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "C:\Program Files\Nokia\Nokia Home Media Server\Media Server\twonkymedia.exe" [Enabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "C:\Program Files\Nokia\Nokia Home Media Server\Media Server\twonkymediaserver.exe" [Enabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "C:\Program Files\TVUPlayer\TVUPlayer.exe" [Disabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "C:\Program Files\Bonjour\mDNSResponder.exe" [Enabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "C:\Program Files\iTunes\iTunes.exe" [Enabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "C:\Documents and Settings\Propriétaire\Mes documents\PROGRAMME\eMule\emule.exe" [Disabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "C:\Documents and Settings\Propriétaire\Mes documents\U96.exe" [Enabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "C:\Program Files\Yahoo!\Messenger\YServer.exe" [Enabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [Enabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "C:\Documents and Settings\Propriétaire\Bureau\U98.exe" [Disabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "C:\Documents and Settings\Propriétaire\Bureau\U99.exe" [Enabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "C:\Documents and Settings\Propriétaire\Mes documents\U99.exe" [Disabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "C:\Program Files\Windows Live\Messenger\wlcsdk.exe" [Enabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [Enabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe" [Enabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "C:\Documents and Settings\Propriétaire\Bureau\BlueSoleil 6.4.240.2WithMobile\Crack\BlueSoleilCS.exe" [Enabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "C:\Program Files\Mozilla Firefox\firefox.exe" [Enabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export DP - "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [Enabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export DP - "C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe" [Enabled] .(.) (.not file.) -- => Valeur supprimée avec succès

    ========== Autre ==========
    047 - AAKE:Key Export DP - "C:\Program Files\Windows Live\Messenger\wlcsdk.exe" [Enabled] .(.Pas de propriétaire - Pas de description.) (.not file.) -- => Format Non supporté

    ========== Récapitulatif ==========
    4 : Clé(s) du Registre
    37 : Valeur(s) du Registre
    1 : Autre

    End of the scan
    Rapport de ZHPFix 1.12.3227 par Nicolas Coolman, Update du 16/12/2010
    Fichier d'export Registre :
    Run by Propriétaire at 16/01/2011 07:24:20
    Windows XP Home Edition Service Pack 3 (Build 2600)
    Web site : http://www.premiumorange.com/zeb-help-process/zhpfix.html
    Contact : nicolascoolman@yahoo.fr

    ========== Clé(s) du Registre ==========
    HKCU\Software\TBSB07183 => Clé supprimée avec succès
    O64 - Services: CurCS - (.not file.) - Gestionnaire de mise à jour Winsudate (WinSvc) .(.Pas de propriétaire - Pas de description.) - LEGACY_WINSVC => Clé supprimée avec succès
    HKCU\Software\ALWIL Software => Clé supprimée avec succès
    HKLM\Software\ALWIL Software => Clé supprimée avec succès

    ========== Valeur(s) du Registre ==========
    O47 - AAKE:Key Export SP - "C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe" [Enabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "C:\temp\CI_HITACHI\MAJ_Hitachi.exe" [Enabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "C:\WINDOWS\system32\sessmgr.exe" [Disabled] .(.Microsoft Corporation - Gestionnaire de session de l'aide sur le Bureau à distance de Microsoft®.) (.not file.) -- C:\WINDOWS\system32\sessmgr.exe => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "D:\PPMate\ppmnet.exe" [Disabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "D:\PPMate\ppmate.exe" [Enabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "C:\Program Files\PPStream\PPStream.exe" [Disabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "C:\Documents and Settings\Propriétaire\Application Data\SopCast\adv\SopAdver.exe" [Disabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "C:\Program Files\SopCast\SopCast.exe" [Disabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "C:\Program Files\Internet Explorer\iexplore.exe" [Enabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "C:\Program Files\Messenger\msmsgs.exe" [Enabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "D:\VLC\vlc.exe" [Disabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "C:\Documents and Settings\Propriétaire\Bureau\sopcast\adv\SopAdver.exe" [Disabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "C:\Documents and Settings\Propriétaire\Bureau\sopcast\SopCast.exe" [Disabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "C:\Program Files\eMule\emule.exe" [Disabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "C:\Documents and Settings\Propriétaire\Bureau\eMule\emule.exe" [Disabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "%windir%\Network Diagnostic\xpnetdiag.exe" [Enabled] .(.Microsoft Corporation - Network Diagnostic for Windows XP.) (.not file.) -- C:\WINDOWS\Network Diagnostic\xpnetdiag.exe => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "C:\Program Files\TVAnts\Tvants.exe" [Disabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "C:\Program Files\Real\RealPlayer\realplay.exe" [Enabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "C:\Program Files\Nokia\Nokia Home Media Server\Media Server\twonkymedia.exe" [Enabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "C:\Program Files\Nokia\Nokia Home Media Server\Media Server\twonkymediaserver.exe" [Enabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "C:\Program Files\TVUPlayer\TVUPlayer.exe" [Disabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "C:\Program Files\Bonjour\mDNSResponder.exe" [Enabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "C:\Program Files\iTunes\iTunes.exe" [Enabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "C:\Documents and Settings\Propriétaire\Mes documents\PROGRAMME\eMule\emule.exe" [Disabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "C:\Documents and Settings\Propriétaire\Mes documents\U96.exe" [Enabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "C:\Program Files\Yahoo!\Messenger\YServer.exe" [Enabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [Enabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "C:\Documents and Settings\Propriétaire\Bureau\U98.exe" [Disabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "C:\Documents and Settings\Propriétaire\Bureau\U99.exe" [Enabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "C:\Documents and Settings\Propriétaire\Mes documents\U99.exe" [Disabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "C:\Program Files\Windows Live\Messenger\wlcsdk.exe" [Enabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [Enabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe" [Enabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "C:\Documents and Settings\Propriétaire\Bureau\BlueSoleil 6.4.240.2WithMobile\Crack\BlueSoleilCS.exe" [Enabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export SP - "C:\Program Files\Mozilla Firefox\firefox.exe" [Enabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export DP - "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [Enabled] .(.) (.not file.) -- => Valeur supprimée avec succès
    O47 - AAKE:Key Export DP - "C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe" [Enabled] .(.) (.not file.) -- => Valeur supprimée avec succès

    ========== Autre ==========
    047 - AAKE:Key Export DP - "C:\Program Files\Windows Live\Messenger\wlcsdk.exe" [Enabled] .(.Pas de propriétaire - Pas de description.) (.not file.) -- => Format Non supporté

    ========== Récapitulatif ==========
    4 : Clé(s) du Registre
    37 : Valeur(s) du Registre
    1 : Autre

    End of the scan
    0
  16. noya83000 Messages postés 19 Statut Membre
     
    Rapport de ZHPDiag v1.27.1421 par Nicolas Coolman, Update du 16/12/2010
    Run by Propriétaire at 16/01/2011 07:55:54
    Web site : http://www.premiumorange.com/zeb-help-process/zhpdiag.html
    Contact : nicolascoolman@yahoo.fr

    ---\\ Web Browser
    MSIE: Internet Explorer v8.0.6001.18702
    MFIE: Mozilla Firefox v3.6.13 (fr) (Defaut)

    ---\\ System Information
    Windows XP Home Edition Service Pack 3 (Build 2600)
    Processor: x86 Family 15 Model 2 Stepping 9, GenuineIntel
    Operating System: 32 Bits
    Boot mode: Normal (Normal boot)
    Total RAM: 511 MB (32% free)
    System drive C: has 48 GB (67%) free of 70 GB

    ---\\ Logged in mode
    Computer Name: MARSEILLAIS
    User Name: Propriétaire
    All Users Names: SUPPORT_fddfa904, SUPPORT_388945a0, Propriétaire, HelpAssistant, ASPNET, Administrateur,
    Unselected Option: O1,O45,O61,O62,O65,O82
    Logged in as Administrator

    ---\\ DOS/Devices
    A:\ Floppy drive, Flash card reader, USB Key (Not Inserted)
    C:\ Hard drive, Flash drive, Thumb drive (Free 48 Go of 70 Go)
    D:\ Hard drive, Flash drive, Thumb drive (Free 1 Go of 4 Go)
    E:\ CD-ROM drive (Not Inserted)
    F:\ CD-ROM drive (Not Inserted)

    ---\\ Security Center & Tools Informations
    [HKLM\SOFTWARE\Microsoft\Security Center] AntiVirusOverride: OK
    [HKLM\SOFTWARE\Microsoft\Security Center] AntiVirusDisableNotify: OK
    [HKLM\SOFTWARE\Microsoft\Security Center] FirewallDisableNotify: OK
    [HKLM\SOFTWARE\Microsoft\Security Center] FirewallOverride: OK
    [HKLM\SOFTWARE\Microsoft\Security Center] UpdatesDisableNotify: OK
    [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced] Start_ShowSearch: OK
    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK

    ---\\ Recherche particulière de fichiers génériques
    [MD5.F2317622D29F9FF0F88AEECD5F60F0DD] - (.Microsoft Corporation - Explorateur Windows.) (.14/04/2008 03:34:03.) -- C:\Windows\Explorer.exe [1037824]
    [MD5.DD73D6B9F6B4CB630CF35B438B540174] - (.Microsoft Corporation - Application d'ouverture de session Windows NT.) (.14/04/2008 03:34:28.) -- C:\Windows\System32\Winlogon.exe [512000]
    [MD5.9F3A2F5AA6875C72BF062C712CFA2674] - (.Microsoft Corporation - IDE/ATAPI Port Driver.) (.13/04/2008 19:40:30.) -- C:\Windows\System32\drivers\atapi.sys [96512]
    [MD5.78A08DD6A8D65E697C18E1DB01C5CDCA] - (.Microsoft Corporation - NT File System Driver.) (.13/04/2008 20:15:53.) -- C:\Windows\System32\drivers\ntfs.sys [574976]

    ---\\ Processus lancés
    [MD5.9015BC03F62940527EC92D45EE89E46F] - (.Avira GmbH - Antivirus Scheduler.) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe [108289]
    [MD5.06A1ECB63DF139EC639E084D4AB3C9D7] - (.Hewlett-Packard Company - hpsysdrv.) -- C:\windows\system\hpsysdrv.exe [52736]
    [MD5.C39FCB57279D2C4D3235D31E43BE4196] - (.Hewlett-Packard - HPHmon05.) -- C:\WINDOWS\System32\hphmon05.exe [483328]
    [MD5.89D583FC41D48328128A974C25AFAEB7] - (.RealNetworks, Inc. - RealNetworks Scheduler.) -- C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe [185896]
    [MD5.D1458A77A6E15462CB96D34089549BAC] - (.Apple Inc. - iTunesHelper Module.) -- C:\Program Files\iTunes\iTunesHelper.exe [305440]
    [MD5.29680A793F690EEF4AAA68479D2A6DF8] - (.Avira GmbH - Antivirus System Tray Tool.) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [209153]
    [MD5.E182C395D3ACE8DF94F1C1764D66D2C3] - (.Motive Communications, Inc. - Pas de description.) -- C:\PROGRA~1\PRESAR~1\Presario\XPHWWRP4\plugin\bin\PCHButton.exe [159744]
    [MD5.93AD0B78C7357A05F50E594EC7C22300] - (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\system32\rundll32.exe [33792]
    [MD5.B8720A787C1223492E6F319465E996CE] - (.Avira GmbH - Antivirus On-Access Service.) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe [185089]
    [MD5.3F56903E124E820AEECE6D471583C6C1] - (.Apple Inc. - Bonjour Service.) -- C:\Program Files\Bonjour\mDNSResponder.exe [238888]
    [MD5.6E0FAEA90E71C5F1B9F3BC71B4CCA2FA] - (.Apple Inc. - iPodService Module (32-bit).) -- C:\Program Files\iPod\bin\iPodService.exe [545568]
    [MD5.0E20A3213ED010FC4997D1EF48082ABC] - (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe [912344]
    [MD5.62BB79160F86CD962F312C68C6239BFD] - (.Microsoft Corporation - Windows Update.) -- C:\WINDOWS\system32\wuauclt.exe [53472]
    [MD5.806A8E35707BEA615B209001E544F0F0] - (.Nicolas Coolman - Diagnostic Tool.) -- C:\Program Files\ZHPDiag\ZHPDiag.exe [620544]

    ---\\ Mozilla Firefox, Plugins,Demarrage,Recherche,Extensions (P2,M0,M1,M2)
    P2 - FPN:Firefox Plugin Navigator . (.Sun Microsystems, Inc. - NPRuntime Script Plug-in Library for Java(TM) Deploy.) -- C:\Program Files\Mozilla Firefox\Plugins\npdeployJava1.dll
    P2 - FPN:Firefox Plugin Navigator . (.mozilla.org - Default Plug-in.) -- C:\Program Files\Mozilla Firefox\Plugins\npnul32.dll
    P2 - FPN:Firefox Plugin Navigator . (.Adobe Systems Inc. - Adobe PDF Plug-In For Firefox and Netscape 10.0.0.) -- C:\Program Files\Mozilla Firefox\Plugins\nppdf32.dll
    P2 - FPN: [HKLM] [@adobe.com/FlashPlayer] - (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
    P2 - FPN: [HKLM] [@Apple.com/iTunes,version=1.0] - (.Pas de propriétaire - Pas de description.) -- C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
    P2 - FPN: [HKLM] [@google.com/npPicasa2,version=2.0.0] - (.Pas de propriétaire - Pas de description.) -- C:\Program Files\Picasa2\npPicasa2.dll (.not file.)
    P2 - FPN: [HKLM] [@java.com/JavaPlugin] - (.Sun Microsystems, Inc. - Next Generation Java Plug-in 1.6.0_22 for Mozilla browsers.) -- C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
    P2 - FPN: [HKLM] [@Microsoft.com/NpCtrl,version=1.0] - (. Microsoft Corporation - 4.0.51204.0.) -- c:\Program Files\Microsoft Silverlight\4.0.51204.0\npctrl.dll
    P2 - FPN: [HKLM] [@microsoft.com/OfficeLive,version=1.3] - (.Microsoft Corp. - Office Live Update v1.3.) -- C:\Program Files\Microsoft\Office Live\npOLW.dll
    P2 - FPN: [HKLM] [@microsoft.com/WLPG,version=14.0.8117.0416] - (.Microsoft Corporation - NPWLPG.) -- C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
    P2 - FPN: [HKLM] [@microsoft.com/WPF,version=3.5] - (.Microsoft Corporation - Windows Presentation Foundation (WPF) plug-in for Mozilla browsers.) -- c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
    P2 - FPN: [HKLM] [@real.com/nppl3260;version=6.0.12.46] - (.Pas de propriétaire - Pas de description.) -- C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (.not file.)
    P2 - FPN: [HKLM] [@real.com/nprjplug;version=1.0.3.46] - (.Pas de propriétaire - Pas de description.) -- C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (.not file.)
    P2 - FPN: [HKLM] [@real.com/nprpjplug;version=6.0.12.46] - (.Pas de propriétaire - Pas de description.) -- C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (.not file.)
    P2 - FPN: [HKLM] [@veetle.com/vbp;version=0.9.17] - (.Pas de propriétaire - Pas de description.) -- C:\Program Files\Veetle\VLCBroadcast\npvbp.dll (.not file.)
    P2 - FPN: [HKLM] [@veetle.com/veetleCorePlugin,version=0.9.18] - (.Veetle Inc - Version 0.9.18, Copyright 2006-2009 Veetle Inc<br><a href="http://www..) -- C:\Program Files\Veetle\plugins\npVeetle.dll
    P2 - FPN: [HKLM] [@veetle.com/veetlePlayerPlugin,version=0.9.18] - (.Veetle Inc - Version 0.9.18, copyright 2006-2010 Veetle Inc<br><a href="http://www..) -- C:\Program Files\Veetle\Player\npvlc.dll
    P2 - FPN: [HKLM] [@videolan.org/vlc,version=0.8.6b] - (.Pas de propriétaire - Pas de description.) -- D:\VLC\npvlc.dll (.not file.)
    M0 - MFSP: prefs.js [Propriétaire - 8vneijw1.default] http://www.sfr.fr/communiquer/messagerie/sfr-messagerie/authentification/index.jsp?domain=webmail-adsl&TYPE=33554433&REALMOID=06-4481d113-6021-105c-abe1-831cf8bb0cb3
    M2 - MFEP: prefs.js [Propriétaire - 8vneijw1.default\vshare@toolbar] [] vShare Plugin v1.0.0 (.vShare.)
    M2 - MFEP: prefs.js [Propriétaire - 8vneijw1.default\{20a82645-c095-46ed-80e3-08825760534b}] [MicrosoftCG] Microsoft .NET Framework Assistant v1.2.1 (.Microsoft.)
    M2 - MFEP: prefs.js [Propriétaire - 8vneijw1.default\{3112ca9c-de6d-4884-a869-9855de68056c}] [] Google Toolbar for Firefox v7.1.20101113Wb1 (.Google Inc..)
    M2 - MFEP: prefs.js [Propriétaire - 8vneijw1.default\{635abd67-4fe9-1b23-4f01-e679fa7484c1}] [yahoo.ytff] Yahoo! Toolbar v2.1.1.20091029021655 (.Yahoo!.)
    M2 - MFEP: prefs.js [Propriétaire - 8vneijw1.default\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}] [] Adobe DLM (powered by getPlus(R)) v1.6.2.97 (.NOS Microsystems Ltd..)

    ---\\ Google Chrome, Démarrage,Recherche,Extensions (G0,G1,G2)
    G0 - GCSP: Preference [User Data\Default][HomePage] https://www.google.com/?gws_rd=ssl

    ---\\ Internet Explorer, Démarrage,Recherche,URSearchHook (R0,R1,R3)
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
    R3 - URLSearchHook: Microsoft Url Search Hook - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} . (.Microsoft Corporation - Internet Explorer.) (8.00.6001.18992 (longhorn_ie8_gdr.101015-1700)) -- C:\WINDOWS\system32\ieframe.dll

    ---\\ Modification d'une valeur Ini (Changed inifile value, mapped to Registry) (F2)
    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe,
    F2 - REG:system.ini: VMApplet=rundll32 shell32,Control_RunDLL "sysdm.cpl"

    ---\\ Browser Helper Objects de navigateur (O2)
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} . (.Adobe Systems Incorporated - Adobe PDF Helper for Internet Explorer.) -- C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: Click-to-Call BHO - {5C255C8A-E604-49b4-9D64-90988571CECB} . (.Microsoft Corporation - Windows Live Call Click-to-Call BHO.) -- C:\Program Files\Windows Live\Messenger\wlchtc.dll
    O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} . (.Microsoft Corporation - Search Helper for Internet Explorer.) -- C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} . (.Microsoft Corporation - WindowsLiveLogin.dll.) -- C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} . (.Pas de propriétaire - Pas de description.) -- (.not file.)
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} . (.Sun Microsystems, Inc. - Java(TM) Platform SE binary.) -- C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} . (.Microsoft Corporation - Windows Live Toolbar Core.) -- C:\Program Files\Windows Live\Toolbar\wltcore.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} . (.Sun Microsystems, Inc. - Java(TM) Quick Starter binary.) -- C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

    ---\\ Internet Explorer Toolbars (O3)
    O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} . (.Microsoft Corporation - Windows Live Toolbar Core.) -- C:\Program Files\Windows Live\Toolbar\wltcore.dll

    ---\\ Applications démarrées par registre & par dossier (O4)
    O4 - HKLM\..\Run: [hpsysdrv] . (.Hewlett-Packard Company - hpsysdrv.) -- c:\windows\system\hpsysdrv.exe
    O4 - HKLM\..\Run: [HotKeysCmds] . (.Intel Corporation - hkcmd Module.) -- C:\WINDOWS\System32\hkcmd.exe
    O4 - HKLM\..\Run: [HPHmon05] . (.Hewlett-Packard - HPHmon05.) -- C:\WINDOWS\System32\hphmon05.exe
    O4 - HKLM\..\Run: [Recguard] . (.Pas de propriétaire - Recguard MFC Application.) -- C:\WINDOWS\SMINST\RECGUARD.exe
    O4 - HKLM\..\Run: [TkBellExe] . (.RealNetworks, Inc. - RealNetworks Scheduler.) -- C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
    O4 - HKLM\..\Run: [iTunesHelper] . (.Apple Inc. - iTunesHelper Module.) -- C:\Program Files\iTunes\iTunesHelper.exe
    O4 - HKLM\..\Run: [avgnt] . (.Avira GmbH - Antivirus System Tray Tool.) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] . (.Adobe Systems Incorporated - Adobe Acrobat SpeedLauncher.) -- C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe
    O4 - HKLM\..\Run: [Adobe ARM] . (.Adobe Systems Incorporated - Adobe Reader and Acrobat Manager.) -- C:\Program Files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe
    O4 - HKLM\..\RunOnce: [Uninstall Adobe Download Manager] . (.NOS Microsystems Ltd. - getPlus+(R).) -- C:\Program Files\NOS\bin\getPlusUninst_Adobe.exe
    O4 - HKCU\..\Run: [NVIEW] nview.dll
    O4 - HKCU\..\Run: [ctfmon.exe] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [Acme.PCHButton] . (.Motive Communications, Inc. - Pas de description.) -- C:\PROGRA~1\PRESAR~1\Presario\XPHWWRP4\plugin\bin\PCHButton.exe
    O4 - HKCU\..\Run: [msnmsgr] . (.Microsoft Corporation - Windows Live Messenger.) -- C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] . (.Microsoft Corporation - Watson Subscriber for SENS Network Notifica.) -- C:\PROGRA~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe
    O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] . (.Microsoft Corporation - Watson Subscriber for SENS Network Notifica.) -- C:\PROGRA~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\System32\CTFMON.exe
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\System32\CTFMON.exe
    O4 - HKUS\S-1-5-21-3959529750-497367016-2629840051-1003\..\Run: [NVIEW] nview.dll
    O4 - HKUS\S-1-5-21-3959529750-497367016-2629840051-1003\..\Run: [ctfmon.exe] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\ctfmon.exe
    O4 - HKUS\S-1-5-21-3959529750-497367016-2629840051-1003\..\Run: [Acme.PCHButton] . (.Motive Communications, Inc. - Pas de description.) -- C:\PROGRA~1\PRESAR~1\Presario\XPHWWRP4\plugin\bin\PCHButton.exe
    O4 - HKUS\S-1-5-21-3959529750-497367016-2629840051-1003\..\Run: [msnmsgr] . (.Microsoft Corporation - Windows Live Messenger.) -- C:\Program Files\Windows Live\Messenger\msnmsgr.exe

    ---\\ Autres liens utilisateurs (O4)
    O4 - Global Startup: C:\Documents And Settings\All Users\Menu Démarrer\Programmes\Adobe Reader X.lnk . (.Pas de propriétaire.) -- C:\WINDOWS\Installer\{AC76BA86-7AD7-1036-7B44-AA0000000001}\SC_Reader.ico
    O4 - Global Startup: C:\Documents And Settings\All Users\Menu Démarrer\Programmes\Apple Software Update.lnk . (.Pas de propriétaire.) -- C:\WINDOWS\Installer\{6956856F-B6B3-4BE0-BA0B-8F495BE32033}\AppleSoftwareUpdateIco.exe
    O4 - Global Startup: C:\Documents And Settings\All Users\Menu Démarrer\Programmes\Enregistrement OCR I.R.I.S..lnk . (.I.R.I.S. SA.) -- C:\Program Files\HP\Digital Imaging\DocProc\regipe.exe
    O4 - Global Startup: C:\Documents And Settings\All Users\Menu Démarrer\Programmes\Visionneuse Microsoft PowerPoint .lnk . (.Pas de propriétaire.) -- C:\WINDOWS\Installer\{95140000-00AF-040C-0000-0000000FF1CE}\ppvwicon.exe
    O4 - Global Startup: C:\Documents And Settings\Propriétaire\Menu Démarrer\Programmes\Assistance à distance.lnk . (.Microsoft Corporation.) -- C:\WINDOWS\system32\rcimlby.exe
    O4 - Global Startup: C:\Documents And Settings\Propriétaire\Menu Démarrer\Programmes\Windows Media Player.lnk . (.Microsoft Corporation.) -- C:\Program Files\Windows Media Player\wmplayer.exe

    ---\\ Boutons situés sur la barre d'outils principale d'Internet Explorer (O9)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} . (.not file.) - (.not file.)
    O9 - Extra button: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} . (.Microsoft Corporation - Windows Messenger.) -- C:\Program Files\Messenger\msmsgs.exe

    ---\\ Winsock hijacker (Layered Service Provider) (O10)
    O10 - WLSP:\000000000001\Winsock LSP File . (.Microsoft Corporation - Fournisseur de service Sockets 2.0 de Microsoft Windows.) -- C:\WINDOWS\system32\mswsock.dll
    O10 - WLSP:\000000000002\Winsock LSP File . (.Microsoft Corporation - LDAP RnR Provider DLL.) -- C:\WINDOWS\system32\winrnr.dll
    O10 - WLSP:\000000000003\Winsock LSP File . (.Microsoft Corporation - Fournisseur de service Sockets 2.0 de Microsoft Windows.) -- C:\WINDOWS\system32\mswsock.dll
    O10 - WLSP:\000000000004\Winsock LSP File . (.Apple Inc. - Bonjour Namespace Provider.) -- C:\Program Files\Bonjour\mdnsNSP.dll

    ---\\ Piratage de l'Option 'Rétablir les paramètres Web' (O14)
    O14 - IERESET.INF: START_PAGE_URL=START_PAGE_URL=https://www.01net.com/telecharger/

    ---\\ Objets ActiveX (Downloaded Program Files)(O16)
    O16 - DPF: Microsoft XML Parser for Java (Microsoft XML Parser for Java) - (.not file.) - C:\WINDOWS\Java\classes\xmldso.cab
    O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
    O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
    O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab56986.cab
    O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} () - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
    O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} () - http://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
    O16 - DPF: {A73BAEFA-EE65-494D-BEDB-DD3E5A34FA98} (Image Uploader) - http://www.extrafilm.fr/ImageUploader4.cab
    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
    O16 - DPF: {CAC677B6-4963-4305-9066-0BD135CD9233} (IPSUploader4 Control) - http://as.photoprintit.de/ips-opdata/layout/default01/activex/IPSUploader4.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} (get_atlcom Class) - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} (Windows Live Hotmail Photo Upload Tool) - http://gfx2.hotmail.com/mail/w4/pr01/photouploadcontrol/MSNPUpld.cab
    O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab

    ---\\ Modification Domaine/Adresses DNS (O17)
    O17 - HKLM\System\CCS\Services\Tcpip\..\{07340202-1385-49B8-8E99-11B58CFE0F2D}: DhcpNameServer = 192.168.1.1
    O17 - HKLM\System\CS1\Services\Tcpip\..\{07340202-1385-49B8-8E99-11B58CFE0F2D}: DhcpNameServer = 192.168.1.1
    O17 - HKLM\System\CS3\Services\Tcpip\..\{07340202-1385-49B8-8E99-11B58CFE0F2D}: DhcpNameServer = 192.168.1.1
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1

    ---\\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (autorun) (O20)
    O20 - Winlogon Notify: crypt32chain . (.Microsoft Corporation - Crypto API32.) -- C:\Windows\System32\crypt32.dll
    O20 - Winlogon Notify: cryptnet . (.Microsoft Corporation - Crypto Network Related API.) -- C:\Windows\System32\cryptnet.dll
    O20 - Winlogon Notify: cscdll . (.Microsoft Corporation - Agent réseau hors connexion.) -- C:\Windows\System32\cscdll.dll
    O20 - Winlogon Notify: dimsntfy . (.Microsoft Corporation - DIMS Notification Handler.) -- C:\WINDOWS\System32\dimsntfy.dll
    O20 - Winlogon Notify: ScCertProp . (.Microsoft Corporation - DLL commune de réception des notifications.) -- C:\Windows\System32\wlnotify.dll
    O20 - Winlogon Notify: Schedule . (.Microsoft Corporation - DLL commune de réception des notifications.) -- C:\Windows\System32\wlnotify.dll
    O20 - Winlogon Notify: sclgntfy . (.Microsoft Corporation - DLL secondaire de notification de service d.) -- C:\Windows\System32\sclgntfy.dll
    O20 - Winlogon Notify: SensLogn . (.Microsoft Corporation - DLL commune de réception des notifications.) -- C:\Windows\System32\WlNotify.dll
    O20 - Winlogon Notify: termsrv . (.Microsoft Corporation - DLL commune de réception des notifications.) -- C:\Windows\System32\wlnotify.dll
    O20 - Winlogon Notify: WgaLogon . (.Microsoft Corporation - Notifications Windows Genuine Advantage.) -- C:\Windows\System32\WgaLogon.dll
    O20 - Winlogon Notify: wlballoon . (.Microsoft Corporation - DLL commune de réception des notifications.) -- C:\Windows\System32\wlnotify.dll

    ---\\ Clé de Registre autorun ShellServiceObjectDelayLoad (SSO/SSODL) (O21)
    O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\WINDOWS\system32\SHELL32.dll
    O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\WINDOWS\system32\SHELL32.dll
    O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} . (.Microsoft Corporation - Web Site Monitor.) -- C:\WINDOWS\system32\webcheck.dll
    O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} . (.Microsoft Corporation - Objet du service d'environnement Systray.) -- C:\WINDOWS\System32\stobject.dll
    O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} . (.Microsoft Corporation - Windows Portable Device Shell Service Objec.) -- C:\WINDOWS\system32\WPDShServiceObj.dll

    ---\\ Clé de Registre autorun SharedTaskScheduler (STS) (O22)
    O22 - SharedTaskScheduler: (no name) - {8C7461EF-2B13-11d2-BE35-3078302C2030} . (.Microsoft Corporation - Bibliothèque de l'interface utilisateur du.) -- C:\WINDOWS\system32\browseui.dll

    ---\\ Liste des services NT non Microsoft et non désactivés (O23)
    O23 - Service: (AntiVirSchedulerService) . (.Avira GmbH - Antivirus Scheduler.) - C:\Program Files\Avira\AntiVir Desktop\sched.exe
    O23 - Service: (AntiVirService) . (.Avira GmbH - Antivirus On-Access Service.) - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
    O23 - Service: (Ati HotKey Poller) . (.Pas de propriétaire - Pas de description.) - C:\WINDOWS\System32\Ati2evxx.exe
    O23 - Service: (Bonjour Service) . (.Apple Inc. - Bonjour Service.) - C:\Program Files\Bonjour\mDNSResponder.exe

    ---\\ Enumération Active Desktop & MHTML Editor (O24)
    O24 - Default MHTML Editor: Last - .(.Pas de propriétaire - Pas de description.) - "C:\Program Files\Microsoft Office\Office10\WINWORD.exe (.not file.)

    ---\\ Tâches planifiées en automatique (O39)
    O39 - APT:Automatic Planified Task - C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
    O39 - APT:Automatic Planified Task - C:\WINDOWS\Tasks\Maintenance en 1 clic.job
    O39 - APT:Automatic Planified Task - C:\WINDOWS\Tasks\User_Feed_Synchronization-{FBF62423-3223-4865-B09A-CC8FFCDEDDF4}.job

    ---\\ Composants installés (ActiveSetup Installed Components) (O40)
    O40 - ASIC: Macromedia Shockwave Director 10.1 - {166B1BCA-3F9C-11CF-8075-444553540000} . (.Macromedia, Inc. - Shockwave ActiveX Control.) -- C:\WINDOWS\system32\Macromed\Director\SwDir.dll
    O40 - ASIC: Microsoft Windows Media Player 6.4 - {22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\INF\mswmp.inf
    O40 - ASIC: NetMeeting 3.01 - {44BBA842-CC51-11CF-AAFA-00AA00B6015B} . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\INF\msnetmtg.inf
    O40 - ASIC: Windows Messenger 4.7 - {5945c046-1e7d-11d1-bc44-00c04fd912be} . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\INF\msmsgs.inf
    O40 - ASIC: Microsoft Windows Media Player - {6BF52A52-394A-11d3-B153-00C04F79FAA6} . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\INF\wmp11.inf
    O40 - ASIC: Fax - {8b15971b-5355-4c82-8c07-7e181ea07608} . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\INF\fxsocm.inf
    O40 - ASIC: Adobe Flash Player - {D27CDB6E-AE6D-11CF-96B8-444553540000} . (.Adobe Systems, Inc. - Adobe Flash Player 10.1 r102.) -- C:\WINDOWS\system32\Macromed\Flash\Flash10l.ocx

    ---\\ Pilotes lancés au démarrage (O41)
    O41 - Driver: (AFD) . (.Microsoft Corporation - Ancillary Function Driver for WinSock.) - C:\WINDOWS\system32\drivers\afd.sys
    O41 - Driver: (AmdK7) . (.Microsoft Corporation - Pilote de périphérique processeur.) - C:\Windows\System32\DRIVERS\amdk7.sys
    O41 - Driver: (avgio) . (.Avira GmbH - Avira AntiVir Support for Minifilter.) - C:\Program Files\Avira\AntiVir Desktop\avgio.sys
    O41 - Driver: (avipbb) . (.Avira GmbH - Avira Driver for RootKit Detection.) - C:\Windows\System32\DRIVERS\avipbb.sys
    O41 - Driver: (Cdrom) . (.Microsoft Corporation - SCSI CD-ROM Driver.) - C:\Windows\System32\DRIVERS\cdrom.sys
    O41 - Driver: (i8042prt) . (.Microsoft Corporation - Pilote de port i8042.) - C:\Windows\System32\DRIVERS\i8042prt.sys
    O41 - Driver: (Imapi) . (.Microsoft Corporation - IMAPI Kernel Driver.) - C:\Windows\System32\DRIVERS\imapi.sys
    O41 - Driver: (intelppm) . (.Microsoft Corporation - Pilote de périphérique processeur.) - C:\Windows\System32\DRIVERS\intelppm.sys
    O41 - Driver: (IPSec) . (.Microsoft Corporation - IPSec Driver.) - C:\Windows\System32\DRIVERS\ipsec.sys
    O41 - Driver: (Kbdclass) . (.Microsoft Corporation - Pilote de la classe Clavier.) - C:\Windows\System32\DRIVERS\kbdclass.sys
    O41 - Driver: (Mouclass) . (.Microsoft Corporation - Pilote de la classe Souris.) - C:\Windows\System32\DRIVERS\mouclass.sys
    O41 - Driver: (MRxSmb) . (.Microsoft Corporation - Windows NT SMB Minirdr.) - C:\Windows\System32\DRIVERS\mrxsmb.sys
    O41 - Driver: (NetBIOS) . (.Microsoft Corporation - NetBIOS interface driver.) - C:\Windows\System32\DRIVERS\netbios.sys
    O41 - Driver: (NetBT) . (.Microsoft Corporation - MBT Transport driver.) - C:\Windows\System32\DRIVERS\netbt.sys
    O41 - Driver: (Processor) . (.Microsoft Corporation - Pilote de périphérique processeur.) - C:\Windows\System32\DRIVERS\processr.sys
    O41 - Driver: (RasAcd) . (.Microsoft Corporation - RAS Automatic Connection Driver.) - C:\Windows\System32\DRIVERS\rasacd.sys
    O41 - Driver: (Rdbss) . (.Microsoft Corporation - Redirected Drive Buffering SubSystem Driver.) - C:\Windows\System32\DRIVERS\rdbss.sys
    O41 - Driver: (RDPCDD) . (.Microsoft Corporation - RDP Miniport.) - C:\Windows\System32\DRIVERS\RDPCDD.sys
    O41 - Driver: (redbook) . (.Microsoft Corporation - Pilote de filtre audio Livre rouge.) - C:\Windows\System32\DRIVERS\redbook.sys
    O41 - Driver: (Serial) . (.Microsoft Corporation - Pilote de périphérique série.) - C:\Windows\System32\DRIVERS\serial.sys
    O41 - Driver: (SiSkp) . (.Silicon Integrated Systems Corporation - SiS VGA Driver Manager.) - C:\Windows\System32\DRIVERS\srvkp.sys
    O41 - Driver: (ssmdrv) . (.Avira GmbH - AVIRA SnapShot Driver.) - C:\Windows\System32\DRIVERS\ssmdrv.sys
    O41 - Driver: (Tcpip) . (.Microsoft Corporation - TCP/IP Protocol Driver.) - C:\Windows\System32\DRIVERS\tcpip.sys
    O41 - Driver: (TermDD) . (.Microsoft Corporation - Terminal Server Driver.) - C:\Windows\System32\DRIVERS\termdd.sys
    O41 - Driver: (Tosrfcom) . (.TOSHIBA Corporation - Bluetooth RFCOMM Driver.) - C:\Windows\System32\Drivers\tosrfcom.sys
    O41 - Driver: (tvtool) . (.TOSHIBA Corporation - Bluetooth RFCOMM Driver.) - C:\Program Files\TVTool 9.6.1\tvtool.sys (.not file.)
    O41 - Driver: Carte vidéo VGA. (VgaSave) . (.Microsoft Corporation - VGA/Super VGA Video Driver.) - C:\WINDOWS\system32\drivers\vga.sys

    ---\\ Logiciels installés (O42)
    O42 - Logiciel: Adobe Download Manager - (.NOS Microsystems Ltd..) [HKLM] -- {E2883E8F-472F-4fb0-9522-AC9BF37916A7}
    O42 - Logiciel: Adobe Flash Player 10 ActiveX - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player ActiveX
    O42 - Logiciel: Adobe Flash Player 10 Plugin - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player Plugin
    O42 - Logiciel: Adobe Reader X - Français - (.Adobe Systems Incorporated.) [HKLM] -- {AC76BA86-7AD7-1036-7B44-AA0000000001}
    O42 - Logiciel: Apple Application Support - (.Apple Inc..) [HKLM] -- {0C34B801-6AEC-4667-B053-03A67E2D0415}
    O42 - Logiciel: Apple Software Update - (.Apple Inc..) [HKLM] -- {6956856F-B6B3-4BE0-BA0B-8F495BE32033}
    O42 - Logiciel: Archiveur WinRAR - (.Pas de propriétaire.) [HKLM] -- WinRAR archiver
    O42 - Logiciel: Assistant de connexion Windows Live - (.Microsoft Corporation.) [HKLM] -- {DCE8CD14-FBF5-4464-B9A4-E18E473546C7}
    O42 - Logiciel: Avira AntiVir Personal - Free Antivirus - (.Avira GmbH.) [HKLM] -- Avira AntiVir Desktop
    O42 - Logiciel: Bonjour - (.Apple Inc..) [HKLM] -- {07287123-B8AC-41CE-8346-3D777245C35B}
    O42 - Logiciel: Canon MP Toolbox 4.1.1.0.mp10 - (.Pas de propriétaire.) [HKLM] -- {4669544E-20E4-4E56-8B44-2E6E1200051F}
    O42 - Logiciel: Galerie de photos Windows Live - (.Microsoft Corporation.) [HKLM] -- {1EE04769-91C4-4A06-92B7-FCAFE6BABDD9}
    O42 - Logiciel: Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) - (.Microsoft Corporation.) [HKLM] -- {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB953595
    O42 - Logiciel: Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) - (.Microsoft Corporation.) [HKLM] -- {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB958484
    O42 - Logiciel: Hotfix for Windows XP (KB915865) - (.Microsoft Corporation.) [HKLM] -- KB915865
    O42 - Logiciel: Hotfix for Windows XP (KB954550-v5) - (.Microsoft Corporation.) [HKLM] -- KB954550-v5
    O42 - Logiciel: Hotfix for Windows XP (KB976002-v5) - (.Microsoft Corporation.) [HKLM] -- KB976002-v5
    O42 - Logiciel: ID3 Lyrics Editor - (.Pas de propriétaire.) [HKLM] -- ID3EDIT En
    O42 - Logiciel: Installation Windows Live - (.Microsoft Corporation.) [HKLM] -- WinLiveSuite_Wave3
    O42 - Logiciel: Installation Windows Live - (.Microsoft Corporation.) [HKLM] -- {133742BA-6F46-4D3E-85AF-78631D9AD8B8}
    O42 - Logiciel: Java(TM) 6 Update 22 - (.Sun Microsystems, Inc..) [HKLM] -- {26A24AE4-039D-4CA4-87B4-2F83216020FF}
    O42 - Logiciel: Junk Mail filter update - (.Microsoft Corporation.) [HKLM] -- {8E5233E1-7495-44FB-8DEB-4BE906D59619}
    O42 - Logiciel: MSVCRT - (.Microsoft.) [HKLM] -- {22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
    O42 - Logiciel: MSXML 4.0 SP2 (KB954430) - (.Microsoft Corporation.) [HKLM] -- {86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
    O42 - Logiciel: MSXML 4.0 SP2 (KB973688) - (.Microsoft Corporation.) [HKLM] -- {F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
    O42 - Logiciel: MSXML 6.0 Parser (KB933579) - (.Microsoft Corporation.) [HKLM] -- {0A869A65-8C94-4F7C-A5C7-972D3C8CED9E}
    O42 - Logiciel: Microsoft .NET Framework 1.1 - (.Microsoft.) [HKLM] -- {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
    O42 - Logiciel: Microsoft .NET Framework 1.1 - (.Pas de propriétaire.) [HKLM] -- Microsoft .NET Framework 1.1 (1033)
    O42 - Logiciel: Microsoft .NET Framework 1.1 Security Update (KB2416447) - (.Pas de propriétaire.) [HKLM] -- M2416447
    O42 - Logiciel: Microsoft .NET Framework 1.1 Security Update (KB979906) - (.Pas de propriétaire.) [HKLM] -- M979906
    O42 - Logiciel: Microsoft .NET Framework 2.0 Service Pack 2 - (.Microsoft Corporation.) [HKLM] -- {C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}
    O42 - Logiciel: Microsoft .NET Framework 3.0 Service Pack 2 - (.Microsoft Corporation.) [HKLM] -- {A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}
    O42 - Logiciel: Microsoft .NET Framework 3.5 SP1 - (.Microsoft Corporation.) [HKLM] -- Microsoft .NET Framework 3.5 SP1
    O42 - Logiciel: Microsoft .NET Framework 3.5 SP1 - (.Microsoft Corporation.) [HKLM] -- {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
    O42 - Logiciel: Microsoft Choice Guard - (.Microsoft Corporation.) [HKLM] -- {F0E12BBA-AD66-4022-A453-A1C8A0C4D570}
    O42 - Logiciel: Microsoft Kernel-Mode Driver Framework Feature Pack 1.5 - (.Microsoft Corporation.) [HKLM] -- Wdf01005
    O42 - Logiciel: Microsoft Office Live Add-in 1.3 - (.Microsoft Corporation.) [HKLM] -- {57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}
    O42 - Logiciel: Microsoft SQL Server 2005 Compact Edition [ENU] - (.Microsoft Corporation.) [HKLM] -- {F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
    O42 - Logiciel: Microsoft Search Enhancement Pack - (.Microsoft Corporation.) [HKLM] -- {4CBA3D4C-8F51-4D60-B27E-F6B641C571E7}
    O42 - Logiciel: Microsoft Silverlight - (.Microsoft Corporation.) [HKLM] -- {89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
    O42 - Logiciel: Microsoft Sync Framework Runtime Native v1.0 (x86) - (.Microsoft Corporation.) [HKLM] -- {8A74E887-8F0F-4017-AF53-CBA42211AAA5}
    O42 - Logiciel: Microsoft Sync Framework Services Native v1.0 (x86) - (.Microsoft Corporation.) [HKLM] -- {BD64AF4A-8C80-4152-AD77-FCDDF05208AB}
    O42 - Logiciel: Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 - (.Microsoft Corporation.) [HKLM] -- {770657D0-A123-3C07-8E44-1C83EC895118}
    O42 - Logiciel: Microsoft Visual C++ 2005 Redistributable - (.Microsoft Corporation.) [HKLM] -- {837b34e3-7c30-493c-8f6a-2b0f04e2912c}
    O42 - Logiciel: Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 - (.Microsoft Corporation.) [HKLM] -- {002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}
    O42 - Logiciel: Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 - (.Microsoft Corporation.) [HKLM] -- {6AFCA4E1-9B78-3640-8F72-A7BF33448200}
    O42 - Logiciel: Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 - (.Microsoft Corporation.) [HKLM] -- {9A25302D-30C0-39D9-BD6F-21E6EC160475}
    O42 - Logiciel: Mozilla Firefox (3.6.13) - (.Mozilla.) [HKLM] -- Mozilla Firefox (3.6.13)
    O42 - Logiciel: Outil de téléchargement Windows Live - (.Microsoft Corporation.) [HKLM] -- {205C6BDD-7B73-42DE-8505-9A093F35A238}
    O42 - Logiciel: PC Connectivity Solution - (.Nokia.) [HKLM] -- {83258E90-1F76-4E13-9F60-A0F8ED41E76F}
    O42 - Logiciel: Package de pilotes Windows - Nokia pccsmcfd (08/22/2008 7.0.0.0) - (.Nokia.) [HKLM] -- 504244733D18C8F63FF584AEB290E3904E791693
    O42 - Logiciel: Pilotes Canon MP - (.Pas de propriétaire.) [HKLM] -- {58F8C6D9-5B55-486A-A322-4E8D87670031}
    O42 - Logiciel: SFR - Kit de connexion - (.SFR.) [HKLM] -- SFR_Kit
    O42 - Logiciel: Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473) - (.Microsoft Corporation.) [HKLM] -- {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB2416473
    O42 - Logiciel: Segoe UI - (.Microsoft Corp.) [HKLM] -- {A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}
    O42 - Logiciel: Update for Microsoft .NET Framework 3.5 SP1 (KB963707) - (.Microsoft Corporation.) [HKLM] -- {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB963707
    O42 - Logiciel: Veetle TV 0.9.18 - (.Veetle, Inc.) [HKLM] -- Veetle TV
    O42 - Logiciel: Visionneuse Microsoft PowerPoint - (.Microsoft Corporation.) [HKLM] -- {95140000-00AF-040C-0000-0000000FF1CE}
    O42 - Logiciel: Wikikou Messenger Cleaner - (.Pas de propriétaire.) [HKLM] -- Wikikou Messenger Cleaner
    O42 - Logiciel: Windows Feature Pack for Storage (32-bit) - IMAPI update for Blu-Ray - (.Microsoft Corporation.) [HKLM] -- KB952011
    O42 - Logiciel: Windows Genuine Advantage Validation Tool (KB892130) - (.Microsoft Corporation.) [HKLM] -- KB892130
    O42 - Logiciel: Windows Internet Explorer 8 - (.Microsoft Corporation.) [HKLM] -- ie8
    O42 - Logiciel: Windows Live Call - (.Microsoft Corporation.) [HKLM] -- {B3B487E7-6171-4376-9074-B28082CEB504}
    O42 - Logiciel: Windows Live Communications Platform - (.Microsoft Corporation.) [HKLM] -- {3175E049-F9A9-4A3D-8F19-AC9FB04514D1}
    O42 - Logiciel: Windows Live FolderShare - (.Microsoft Corporation.) [HKLM] -- {76810709-A7D3-468D-9167-A1780C1E766C}
    O42 - Logiciel: Windows Live Mail - (.Microsoft Corporation.) [HKLM] -- {5DD76286-9BE7-4894-A990-E905E91AC818}
    O42 - Logiciel: Windows Live Messenger - (.Microsoft Corporation.) [HKLM] -- {445B183D-F4F1-45C8-B9DB-F11355CA657B}
    O42 - Logiciel: Windows Live Toolbar - (.Microsoft Corporation.) [HKLM] -- {9D6524E6-15CF-4852-BF70-04FE973A3DE1}
    O42 - Logiciel: Windows XP Service Pack 3 - (.Microsoft Corporation.) [HKLM] -- Windows XP Service
    O42 - Logiciel: XML Paper Specification Shared Components Pack 1.0 - (.Microsoft Corporation.) [HKLM] -- XpsEPSC
    O42 - Logiciel: iTunes - (.Apple Inc..) [HKLM] -- {DA34FE93-5DC5-48E0-ACC8-A5389E05BB51}

    ---\\ HKCU & HKLM Software Keys
    [HKCU\Software\ACD Systems]
    [HKCU\Software\ARCSOFT]
    [HKCU\Software\Adobe]
    [HKCU\Software\Ahead]
    [HKCU\Software\AppConf]
    [HKCU\Software\Apple Computer, Inc.]
    [HKCU\Software\Aurigma]
    [HKCU\Software\Avira]
    [HKCU\Software\Borland]
    [HKCU\Software\CDBurnerXP]
    [HKCU\Software\CDDB]
    [HKCU\Software\CISRA]
    [HKCU\Software\Canon]
    [HKCU\Software\CeWe Color]
    [HKCU\Software\Classes]
    [HKCU\Software\Clients]
    [HKCU\Software\Club-Internet V5]
    [HKCU\Software\Cycore]
    [HKCU\Software\DivXNetworks]
    [HKCU\Software\Fnac_FR]
    [HKCU\Software\Gabest]
    [HKCU\Software\Gelios Software]
    [HKCU\Software\Google]
    [HKCU\Software\Grisoft]
    [HKCU\Software\HP]
    [HKCU\Software\Hewlett-Packard]
    [HKCU\Software\HookNetwork]
    [HKCU\Software\IM Providers]
    [HKCU\Software\Intel]
    [HKCU\Software\InterVideo]
    [HKCU\Software\JEDI-VCL]
    [HKCU\Software\JavaSoft]
    [HKCU\Software\LeaderTech]
    [HKCU\Software\Ligos]
    [HKCU\Software\Local AppWizard-Generated Applications]
    [HKCU\Software\Macromedia]
    [HKCU\Software\Magnet]
    [HKCU\Software\MainConcept]
    [HKCU\Software\Malwarebytes' Anti-Malware]
    [HKCU\Software\MeuhMeuhTV]
    [HKCU\Software\Motive]
    [HKCU\Software\MozillaPlugins]
    [HKCU\Software\Mozilla]
    [HKCU\Software\NVIDIA Corporation]
    [HKCU\Software\Nero]
    [HKCU\Software\Netscape]
    [HKCU\Software\Nokia]
    [HKCU\Software\ODBC]
    [HKCU\Software\Oak Technology]
    [HKCU\Software\Pegasys Inc.]
    [HKCU\Software\Policies]
    [HKCU\Software\RealNetworks]
    [HKCU\Software\SONIC]
    [HKCU\Software\SampleView]
    [HKCU\Software\SecuROM]
    [HKCU\Software\Simply Super Software]
    [HKCU\Software\Sony Corporation]
    [HKCU\Software\TVANTS]
    [HKCU\Software\Terravirtual]
    [HKCU\Software\TorrentAid]
    [HKCU\Software\Trolltech]
    [HKCU\Software\Ulead Systems]
    [HKCU\Software\Usbfix]
    [HKCU\Software\VB and VBA Program Settings]
    [HKCU\Software\Veetle]
    [HKCU\Software\WinDVD4]
    [HKCU\Software\WinRAR SFX]
    [HKCU\Software\WinRAR]
    [HKCU\Software\Yahoo]
    [HKCU\Software\ZjSoft]
    [HKCU\Software\eMule]
    [HKCU\Software\ej-technologies]
    [HKCU\Software\honestech]
    [HKCU\Software\mop]
    [HKLM\Software\2B9EC021-C823-4f3d-9752-C18522DB7D98]
    [HKLM\Software\781]
    [HKLM\Software\ACD Systems]
    [HKLM\Software\ADS Tech]
    [HKLM\Software\ATI Technologies]
    [HKLM\Software\Adobe]
    [HKLM\Software\Apple Computer, Inc.]
    [HKLM\Software\Apple Inc.]
    [HKLM\Software\ArcSoft]
    [HKLM\Software\Ariad]
    [HKLM\Software\Audible]
    [HKLM\Software\Avance]
    [HKLM\Software\Avira]
    [HKLM\Software\BSProductManage]
    [HKLM\Software\BroadJump]
    [HKLM\Software\C07ft5Y]
    [HKLM\Software\CEC]
    [HKLM\Software\CISRA]
    [HKLM\Software\Canon]
    [HKLM\Software\Classes]
    [HKLM\Software\Clients]
    [HKLM\Software\Club-Internet V5]
    [HKLM\Software\Conexant]
    [HKLM\Software\DivXNetworks]
    [HKLM\Software\Fnac_FR]
    [HKLM\Software\Foreignword]
    [HKLM\Software\Friendly Technologies]
    [HKLM\Software\Fujifilm]
    [HKLM\Software\FullCircle]
    [HKLM\Software\GEAR Software]
    [HKLM\Software\Gelios Software]
    [HKLM\Software\Gemplus]
    [HKLM\Software\Google]
    [HKLM\Software\Grisoft]
    [HKLM\Software\HPS]
    [HKLM\Software\HP]
    [HKLM\Software\HaaliMkx]
    [HKLM\Software\Hewlett-Packard]
    [HKLM\Software\IAN]
    [HKLM\Software\Infogrames Interactive]
    [HKLM\Software\InstallShield]
    [HKLM\Software\Intel]
    [HKLM\Software\InterVideo]
    [HKLM\Software\JavaSoft]
    [HKLM\Software\JreMetrics]
    [HKLM\Software\LEAD Technologies, Inc.]
    [HKLM\Software\Licenses]
    [HKLM\Software\LimeWire]
    [HKLM\Software\MP3]
    [HKLM\Software\Macromedia]
    [HKLM\Software\Macrovision]
    [HKLM\Software\Malwarebytes' Anti-Malware]
    [HKLM\Software\MeuhMeuhTV]
    [HKLM\Software\Micro Application]
    [HKLM\Software\MicroVision]
    [HKLM\Software\Mindscape]
    [HKLM\Software\Motive]
    [HKLM\Software\MozillaPlugins]
    [HKLM\Software\Mozilla]
    [HKLM\Software\NOS]
    [HKLM\Software\NSIS]
    [HKLM\Software\NVIDIA Corporation]
    [HKLM\Software\Nero]
    [HKLM\Software\Neuf]
    [HKLM\Software\Nokia]
    [HKLM\Software\ODBC]
    [HKLM\Software\Oak Technology]
    [HKLM\Software\PC Connectivity Solution]
    [HKLM\Software\Policies]
    [HKLM\Software\Program Groups]
    [HKLM\Software\Python]
    [HKLM\Software\RealNetworks]
    [HKLM\Software\Realtek]
    [HKLM\Software\RegisteredApplications]
    [HKLM\Software\RichFX]
    [HKLM\Software\S3R521]
    [HKLM\Software\S3]
    [HKLM\Software\Sanyo]
    [HKLM\Software\Schlumberger]
    [HKLM\Software\Secure]
    [HKLM\Software\SiS]
    [HKLM\Software\Soeperman Enterprises Ltd.]
    [HKLM\Software\Sonic]
    [HKLM\Software\TVTool8]
    [HKLM\Software\TerraVirtual]
    [HKLM\Software\Toshiba]
    [HKLM\Software\TwonkyMedia]
    [HKLM\Software\Ulead Systems]
    [HKLM\Software\Uniblue]
    [HKLM\Software\V-Stream Multimedia]
    [HKLM\Software\Veetle]
    [HKLM\Software\VideoLAN]
    [HKLM\Software\WidCommUpdate]
    [HKLM\Software\Wilson WindowWare]
    [HKLM\Software\WinDVD4]
    [HKLM\Software\WinISO]
    [HKLM\Software\Windows 3.1 Migration Status]
    [HKLM\Software\Windows]
    [HKLM\Software\Wise Solutions]
    [HKLM\Software\X-AVCSD]
    [HKLM\Software\Xing Technology Corp.]
    [HKLM\Software\Yahoo]
    [HKLM\Software\ahead]
    [HKLM\Software\lbttcp]
    [HKLM\Software\mozilla.org]
    [HKLM\Software\optimidata]

    ---\\ Contenu des dossiers ProgramFiles/ProgramData (O43)
    O43 - CFD: 25/12/2010 - 20:31:58 ----D- C:\Program Files\7-Zip
    O43 - CFD: 09/01/2011 - 19:42:52 ----D- C:\Program Files\ACD Systems
    O43 - CFD: 16/01/2011 - 07:39:04 ----D- C:\Program Files\Adobe
    O43 - CFD: 19/01/2009 - 21:40:06 ----D- C:\Program Files\Apple Software Update
    O43 - CFD: 10/06/2009 - 16:49:48 ----D- C:\Program Files\ArcSoft
    O43 - CFD: 08/11/2009 - 09:37:50 ----D- C:\Program Files\Avira
    O43 - CFD: 23/10/2006 - 05:47:18 ----D- C:\Program Files\AviSynth 2.5
    O43 - CFD: 09/10/2009 - 14:34:40 ----D- C:\Program Files\Bonjour
    O43 - CFD: 12/02/2007 - 09:55:42 ----D- C:\Program Files\BroadJump
    O43 - CFD: 12/10/2010 - 13:59:30 ----D- C:\Program Files\Canon
    O43 - CFD: 08/02/2007 - 13:35:34 ----D- C:\Program Files\Common Files
    O43 - CFD: 25/12/2008 - 19:55:34 ----D- C:\Program Files\DIFX
    O43 - CFD: 10/11/2006 - 18:32:10 ----D- C:\Program Files\directx
    O43 - CFD: 19/10/2010 - 16:53:28 ----D- C:\Program Files\Fichiers communs
    O43 - CFD: 01/12/2005 - 20:36:52 ----D- C:\Program Files\Foreignword
    O43 - CFD: 01/10/2008 - 19:38:20 ----D- C:\Program Files\Friendly Technologies
    O43 - CFD: 13/01/2011 - 19:35:12 ----D- C:\Program Files\Google
    O43 - CFD: 23/11/2006 - 18:11:04 ----D- C:\Program Files\Hewlett-Packard
    O43 - CFD: 23/11/2006 - 18:11:02 ----D- C:\Program Files\HP
    O43 - CFD: 13/01/2011 - 18:36:00 --H-D- C:\Program Files\InstallShield Installation Information
    O43 - CFD: 15/12/2010 - 05:57:28 ----D- C:\Program Files\Internet Explorer
    O43 - CFD: 20/03/2005 - 19:49:22 ----D- C:\Program Files\InterVideo
    O43 - CFD: 09/10/2009 - 14:35:36 ----D- C:\Program Files\iPod
    O43 - CFD: 09/10/2009 - 14:37:28 ----D- C:\Program Files\iTunes
    O43 - CFD: 15/01/2011 - 21:27:26 ----D- C:\Program Files\Java
    O43 - CFD: 14/01/2011 - 22:56:20 ----D- C:\Program Files\Malwarebytes' Anti-Malware
    O43 - CFD: 05/11/2008 - 16:15:42 ----D- C:\Program Files\Messenger
    O43 - CFD: 01/05/2007 - 18:16:26 ----D- C:\Program Files\Micro Scrabble
    O43 - CFD: 11/10/2009 - 13:46:00 ----D- C:\Program Files\Microsoft
    O43 - CFD: 04/11/2007 - 14:01:08 ----D- C:\Program Files\Microsoft CAPICOM 2.1.0.2
    O43 - CFD: 01/01/2003 - 22:11:22 ----D- C:\Program Files\microsoft frontpage
    O43 - CFD: 11/11/2010 - 21:17:44 ----D- C:\Program Files\Microsoft Office
    O43 - CFD: 06/01/2011 - 07:42:04 ----D- C:\Program Files\Microsoft Silverlight
    O43 - CFD: 31/07/2010 - 10:47:26 ----D- C:\Program Files\Microsoft SQL Server Compact Edition
    O43 - CFD: 31/07/2010 - 10:49:30 ----D- C:\Program Files\Microsoft Sync Framework
    O43 - CFD: 13/08/2010 - 04:30:16 ----D- C:\Program Files\Movie Maker
    O43 - CFD: 14/12/2010 - 20:10:02 ----D- C:\Program Files\Mozilla Firefox
    O43 - CFD: 06/05/2007 - 10:32:38 ----D- C:\Program Files\MP3
    O43 - CFD: 06/05/2007 - 10:43:42 ----D- C:\Program Files\MP3 Player Utilities 4.00
    O43 - CFD: 26/12/2007 - 21:24:48 ----D- C:\Program Files\MP3Gain
    O43 - CFD: 25/12/2008 - 19:44:40 ----D- C:\Program Files\MSBuild
    O43 - CFD: 11/11/2010 - 21:15:48 ----D- C:\Program Files\MSECache
    O43 - CFD: 28/08/2006 - 11:37:32 ----D- C:\Program Files\MSN
    O43 - CFD: 01/01/2003 - 22:08:06 ----D- C:\Program Files\MSN Gaming Zone
    O43 - CFD: 25/12/2008 - 20:22:20 ----D- C:\Program Files\MSXML 6.0
    O43 - CFD: 13/01/2011 - 22:26:16 ----D- C:\Program Files\Navilog1
    O43 - CFD: 05/11/2008 - 16:04:38 ----D- C:\Program Files\NetMeeting
    O43 - CFD: 07/03/2008 - 20:26:44 ----D- C:\Program Files\Neuf
    O43 - CFD: 16/01/2011 - 07:35:12 ----D- C:\Program Files\NOS
    O43 - CFD: 04/10/2010 - 18:30:38 ----D- C:\Program Files\OpenOffice.org 3
    O43 - CFD: 15/12/2010 - 05:52:40 ----D- C:\Program Files\Outlook Express
    O43 - CFD: 02/01/2003 - 00:28:02 ----D- C:\Program Files\Presario PC Help
    O43 - CFD: 01/01/2003 - 23:58:18 ----D- C:\Program Files\RecordNow!
    O43 - CFD: 25/12/2008 - 19:44:14 ----D- C:\Program Files\Reference Assemblies
    O43 - CFD: 16/10/2008 - 15:15:22 ----D- C:\Program Files\SFR
    O43 - CFD: 01/12/2009 - 19:22:02 ----D- C:\Program Files\THQ
    O43 - CFD: 11/02/2010 - 21:07:08 ----D- C:\Program Files\Trend Micro
    O43 - CFD: 02/04/2005 - 14:57:52 ----D- C:\Program Files\TVTool 9.6.1
    O43 - CFD: 29/03/2005 - 18:20:22 ----D- C:\Program Files\Ulead Systems
    O43 - CFD: 01/01/2003 - 23:50:34 --H-D- C:\Program Files\Uninstall Information
    O43 - CFD: 23/11/2010 - 19:26:22 ----D- C:\Program Files\Veetle
    O43 - CFD: 10/08/2008 - 12:08:52 ----D- C:\Program Files\WebTV
    O43 - CFD: 31/07/2010 - 10:21:42 ----D- C:\Program Files\Wikikou
    O43 - CFD: 31/07/2010 - 10:49:50 ----D- C:\Program Files\Windows Live
    O43 - CFD: 07/11/2009 - 18:27:46 ----D- C:\Program Files\Windows Live SkyDrive
    O43 - CFD: 25/12/2007 - 13:06:52 ----D- C:\Program Files\Windows Media Connect 2
    O43 - CFD: 13/12/2009 - 09:19:40 ----D- C:\Program Files\Windows Media Player
    O43 - CFD: 05/11/2008 - 16:04:34 ----D- C:\Program Files\Windows NT
    O43 - CFD: 19/08/2008 - 08:41:18 ----D- C:\Program Files\WinRAR
    O43 - CFD: 01/01/2003 - 22:11:22 ----D- C:\Program Files\xerox
    O43 - CFD: 09/01/2011 - 20:27:00 ----D- C:\Program Files\Yahoo!
    O43 - CFD: 16/01/2011 - 07:56:04 ----D- C:\Program Files\ZHPDiag
    O43 - CFD: 08/02/2007 - 13:36:24 ----D- C:\Program Files\Common Files\Motive
    O43 - CFD: 01/01/2003 - 23:55:36 ----D- C:\Program Files\Common Files\System

    ---\\ Derniers fichiers modifiés ou crées sous Windows et System32 (O44)
    O44 - LFC:[MD5.CCED1200F915817C00DCFD7FA0EE1200] - 16/01/2011 - 07:54:55 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\WindowsUpdate.log [2058796]
    O44 - LFC:[MD5.D49A6FF39D7679720E2CC19FCA14DC4A] - 16/01/2011 - 07:30:38 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\System32\wpa.dbl [1158]
    O44 - LFC:[MD5.D41D8CD98F00B204E9800998ECF8427E] - 16/01/2011 - 07:30:17 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\0.log [0]
    O44 - LFC:[MD5.CCED1200F915817C00DCFD7FA0EE1200] - 16/01/2011 - 07:30:06 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\wiadebug.log [159]
    O44 - LFC:[MD5.CCED1200F915817C00DCFD7FA0EE1200] - 16/01/2011 - 07:29:47 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\wiaservc.log [50]
    O44 - LFC:[MD5.6A2CB42966136854F4464516FBB4AE72] - 16/01/2011 - 07:29:26 -S-A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\bootstat.dat [2048]
    O44 - LFC:[MD5.CCED1200F915817C00DCFD7FA0EE1200] - 16/01/2011 - 07:28:06 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\SchedLgU.Txt [32516]
    O44 - LFC:[MD5.8F57507DBA7793EAF64A72680CC060B2] - 16/01/2011 - 07:24:20 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\ZHPExportRegistry-16-01-2011-07-24-20.txt [212084]
    O44 - LFC:[MD5.F5324B777CC8F581F9C92F2A7F16D3B8] - 15/01/2011 - 21:31:12 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\ZHPExportRegistry-15-01-2011-21-31-12.txt [21002]
    O44 - LFC:[MD5.8E625B68937794F734C35A7A13EBB6DB] - 15/01/2011 - 20:35:16 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\UsbFix.txt [1063]
    O44 - LFC:[MD5.D85C97E4D2074AD5E308BD9D4505D2E8] - 15/01/2011 - 12:37:16 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\UsbFix_Upload_Me_MARSEILLAIS.zip [4347]
    O44 - LFC:[MD5.813244FE61CE13771D225F191E20EEE8] - 01/01/2011 - 11:43:12 ---A- . (.Sony DADC Austria AG. - SecuROM Context-Menu for Explorer..) -- C:\WINDOWS\System32\CmdLineExt.dll [98304]
    O44 - LFC:[MD5.DB11C63CDBAA1845AD90570EB62C760F] - 23/12/2010 - 09:53:01 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\System32\CmdLineExt03.dll [43520]

    ---\\ Opérations et fonctions au démarrage de Windows Explorer (O46)
    O46 - SEH:ShellExecuteHooks - URL Exec Hook - {AEB6717E-7E19-11d0-97EE-00C04FD91972} - shell32.dll

    ---\\ Export de clé d'application autorisée (ECAA) (O47)
    O47 - AAKE:Key Export SP - "%windir%\system32\sessmgr.exe" [Enabled] .(.Microsoft Corporation - Gestionnaire de session de l'aide sur le Bureau à distance de Microsoft®.) -- C:\WINDOWS\system32\sessmgr.exe
    O47 - AAKE:Key Export DP - "%windir%\system32\sessmgr.exe" [Enabled] .(.Microsoft Corporation - Gestionnaire de session de l'aide sur le Bureau à distance de Microsoft®.) -- C:\WINDOWS\system32\sessmgr.exe
    O47 - AAKE:Key Export DP - "%windir%\Network Diagnostic\xpnetdiag.exe" [Enabled] .(.Microsoft Corporation - Network Diagnostic for Windows XP.) -- C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O47 - AAKE:Key Export DP - "C:\Program Files\Windows Live\Messenger\wlcsdk.exe" [Enabled] .(.Pas de propriétaire - Pas de description.) (.not file.) --

    ---\\ Déni du service (Local Security Authority) (LSA) (O48)
    O48 - LSA:Local Security Authority Authentication Packages . (.Microsoft Corporation - Microsoft Authentication Package v1.0.) -- C:\WINDOWS\System32\msv1_0.dll
    O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Microsoft Authentication Package v1.0.) -- C:\WINDOWS\System32\msv1_0.dll

    ---\\ Image File Execution Options (IFEO) (O50)
    O50 - IFEO:Image File Execution Options - Your Image File Name Here without a path - ntsd -d

    ---\\ Trojan Driver Search Data (HKLM)(TDSD) (O52)
    O52 - TDSD: \Drivers32\"msacm.trspch"="tssoft32.acm" . (.DSP GROUP, INC. - Codec audio TrueSpeech(TM) DSP Group pour MSACM V3.50.) -- C:\WINDOWS\System32\tssoft32.acm
    O52 - TDSD: \Drivers32\"vidc.cvid"="iccvid.dll" . (.Radius Inc. - Cinepak® Codec.) -- C:\WINDOWS\System32\iccvid.dll
    O52 - TDSD: \Drivers32\"vidc.iv31"="ir32_32.dll" . (.Ligos Corporation - Ligos Indeo® Video 3.2.) -- C:\WINDOWS\System32\ir32_32.dll
    O52 - TDSD: \Drivers32\"vidc.iv32"="ir32_32.dll" . (.Ligos Corporation - Ligos Indeo® Video 3.2.) -- C:\WINDOWS\System32\ir32_32.dll
    O52 - TDSD: \Drivers32\"msacm.sl_anet"="sl_anet.acm" . (.Sipro Lab Telecom Inc. - Audio codec for MS ACM.) -- C:\WINDOWS\System32\sl_anet.acm
    O52 - TDSD: \Drivers32\"msacm.l3acm"="C:\WINDOWS\System32\l3codeca.acm" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Layer-3 Audio Codec for MSACM.) -- C:\WINDOWS\System32\l3codeca.acm
    O52 - TDSD: \Drivers32\"vidc.LEAD"="LCODCCMP.DLL" . (.LEAD Technologies, Inc. - LEAD MCMP/MJPEG Codec.) -- C:\WINDOWS\System32\LCODCCMP.DLL
    O52 - TDSD: \Drivers32\"vidc.yv12"="DivX.dll" . (.DivX, Inc. - DivX.) -- C:\WINDOWS\System32\DivX.dll
    O52 - TDSD: \Drivers32\"VIDC.ACDV"="ACDV.dll" . (.ACD Systems - ACDV.) -- C:\WINDOWS\System32\ACDV.dll
    O52 - TDSD: \drivers.desc\"sl_anet.acm"="Sipro Lab Telecom Audio Codec" . (.Sipro Lab Telecom Inc. - Audio codec for MS ACM.) -- C:\WINDOWS\System32\sl_anet.acm
    O52 - TDSD: \drivers.desc\"C:\WINDOWS\System32\l3codeca.acm"="Fraunhofer IIS MPEG Layer-3 Codec" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Layer-3 Audio Codec for MSACM.) -- C:\WINDOWS\System32\l3codeca.acm
    O52 - TDSD: \drivers.desc\"LCODCCMP.DLL"="LEAD MCMP/MJPEG Codec (VFW)" . (.LEAD Technologies, Inc. - LEAD MCMP/MJPEG Codec.) -- C:\WINDOWS\System32\LCODCCMP.DLL
    O52 - TDSD: \drivers.desc\"iac25_32.ax"="Indeo® audio software" . (.Intel Corporation - Indeo® audio software.) -- C:\WINDOWS\System32\iac25_32.ax
    O52 - TDSD: \drivers.desc\"ir50_32.dll"="Indeo® video 5.10" . (.Pas de propriétaire - Pas de description.) -- (.not file.)
    O52 - TDSD: \drivers.desc\"tssoft32.acm"="tssoft32.acm" . (.DSP GROUP, INC. - Codec audio TrueSpeech(TM) DSP Group pour MSACM V3.50.) -- C:\WINDOWS\System32\tssoft32.acm
    O52 - TDSD: \drivers.desc\"iccvid.dll"="iccvid.dll" . (.Radius Inc. - Cinepak® Codec.) -- C:\WINDOWS\System32\iccvid.dll
    O52 - TDSD: \drivers.desc\"ir32_32.dll"="ir32_32.dll" . (.Ligos Corporation - Ligos Indeo® Video 3.2.) -- C:\WINDOWS\System32\ir32_32.dll
    O52 - TDSD: \drivers.desc\"DivX.dll"="DivX 6.4.0 Codec" . (.Pas de propriétaire - Pas de description.) -- (.not file.)
    O52 - TDSD: \drivers.desc\"ACDV.dll"="ACDV 1.0" . (.Pas de propriétaire - Pas de description.) -- (.not file.)

    ---\\ Microsoft Control Security Providers (MCSP) (O54)
    O54 - MCSP:[HKLM\...\CurrentControlSet\Control] - (SecurityProviders) - (.Microsoft Corporation - Client DPA pour plate-forme 32 bit.) -- C:\WINDOWS\system32\msapsspc.dll
    O54 - MCSP:[HKLM\...\CurrentControlSet\Control] - (SecurityProviders) - (.Microsoft Corporation - TLS / SSL Security Provider.) -- C:\WINDOWS\system32\schannel.dll
    O54 - MCSP:[HKLM\...\CurrentControlSet\Control] - (SecurityProviders) - (.Microsoft Corporation - Package d'authentification Digest SSPI.) -- C:\WINDOWS\system32\digest.dll
    O54 - MCSP:[HKLM\...\ControlSet001\Control] - (SecurityProviders) - (.Microsoft Corporation - Client DPA pour plate-forme 32 bit.) -- C:\WINDOWS\system32\msapsspc.dll
    O54 - MCSP:[HKLM\...\ControlSet001\Control] - (SecurityProviders) - (.Microsoft Corporation - TLS / SSL Security Provider.) -- C:\WINDOWS\system32\schannel.dll
    O54 - MCSP:[HKLM\...\ControlSet001\Control] - (SecurityProviders) - (.Microsoft Corporation - Package d'authentification Digest SSPI.) -- C:\WINDOWS\system32\digest.dll

    ---\\ Microsoft Windows Policies System (MWPS) (O55)
    O55 - MWPS:[HKLM\...\Policies\System] - "dontdisplaylastusername"=0
    O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticecaption"=
    O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticetext"=
    O55 - MWPS:[HKLM\...\Policies\System] - "shutdownwithoutlogon"=1
    O55 - MWPS:[HKLM\...\Policies\System] - "undockwithoutlogon"=1

    ---\\ Microsoft Windows Policies Explorer (MWPE) (O56)
    O56 - MWPE:[HKCU\...\policies\Explorer] - "NoDriveTypeAutoRun"=0
    O56 - MWPE:[HKCU\...\policies\Explorer] - "NoDriveAutoRun"=3
    O56 - MWPE:[HKCU\...\policies\Explorer] - "HonorAutoRunSetting"=0
    O56 - MWPE:[HKLM\...\policies\Explorer] - "HonorAutoRunSetting"=0
    O56 - MWPE:[HKLM\...\policies\Explorer] - "NoCDBurning"=0
    O56 - MWPE:[HKLM\...\policies\Explorer] - "NoDriveAutoRun"=3
    O56 - MWPE:[HKLM\...\policies\Explorer] - "NoDriveTypeAutoRun"=0

    ---\\ Liste des Drivers Système (SDL) (O58)
    O58 - SDL:[MD5.7D815767C1389817E2C4B85226FBAC1D] - 15/04/2003 - 17:39:54 ---A- . (.Intel Corporation - Silicon Image 164 Minidriver.) -- C:\WINDOWS\system32\drivers\a302.sys [11319]
    O58 - SDL:[MD5.3B2E9C558808392EEF3536C999C9EDA9] - 15/04/2003 - 17:39:58 ---A- . (.Intel Corporation - Chrontel 7007 Minidriver.) -- C:\WINDOWS\system32\drivers\a303.sys [29239]
    O58 - SDL:[MD5.F7BF7E2B3B1AD4FB4CFD4CAD5FC3D644] - 15/04/2003 - 17:40:04 ---A- . (.Intel Corporation - Focus 450 Minidriver.) -- C:\WINDOWS\system32\drivers\a304.sys [46647]
    O58 - SDL:[MD5.FB647C05F78E25F70D3C08582BEA1D71] - 15/04/2003 - 17:40:08 ---A- . (.Intel Corporation - National Semiconductor DS90C389R Minidriver.) -- C:\WINDOWS\system32\drivers\a305.sys [11831]
    O58 - SDL:[MD5.4234A4A9962C35A417592EC64E046217] - 15/04/2003 - 17:40:12 ---A- . (.Intel Corporation - National Semiconductor DS90C2501 Minidriver.) -- C:\WINDOWS\system32\drivers\a306.sys [16439]
    O58 - SDL:[MD5.A0ABB6D31DE6C8B7C28B7BF8C6F857CA] - 15/04/2003 - 17:40:16 ---A- . (.Intel Corporation - MBI TvPro Minidriver.) -- C:\WINDOWS\system32\drivers\a307.sys [21559]
    O58 - SDL:[MD5.EE215975C23AF07E0A5085EF1C89F0C1] - 15/04/2003 - 17:40:20 ---A- . (.Intel Corporation - THine 164 DVI Encoder.) -- C:\WINDOWS\system32\drivers\a308.sys [10807]
    O58 - SDL:[MD5.3B19D9D473A2F812088F113D004EBD70] - 15/04/2003 - 17:40:24 ---A- . (.Intel Corporation - Philips SAA7104 TV Encoder.) -- C:\WINDOWS\system32\drivers\a309.sys [25655]
    O58 - SDL:[MD5.F390CAEB835DFEE21ACB4234E093CB7C] - 15/04/2003 - 17:40:28 ---A- . (.Intel Corporation - Ch7017 Minidriver.) -- C:\WINDOWS\system32\drivers\a310.sys [33335]
    O58 - SDL:[MD5.7629F8AB287130C04F2EC2604C7557E8] - 15/04/2003 - 17:40:32 ---A- . (.Intel Corporation - Ch7017 Minidriver.) -- C:\WINDOWS
    0
  17. Patdam73 Messages postés 271 Statut Membre 13
     
    Hello

    Peux tu remettre ton dernier rapport zhpdiag sur cijoint.fr ?

    Il est trop long pour le forum et donc il en manque une partie.

    Merci
    0
  18. noya83000 Messages postés 19 Statut Membre
     
    bonsoir voila :http://www.cijoint.fr/cjlink.php?file=cj201101/cijYcPL50B.txt
    0
  19. Patdam73 Messages postés 271 Statut Membre 13
     
    Re

    Ton programme java n'est toujours pas à jour. Je ne sais pas si tu l'as zappé, ou si ça n'a pas maché :

    reprend la procédure ici :

    Permalink (#15)

    normalement il devrait te proposer la version 1.6.0.23

    ======

    Optimisation :

    OneClick2RestorePoint :

    Relance OneClick2RestorePoint de Laddy

    [*] Conserve-le tout au long de la désinfection et de l'optimisation.
    [*] Double clic dessus pour l'exécuter (Sous Vista/Seven, fais un clic droit et choisir Exécuter en tant qu'administrateur)
    [*] Entre la description suivante : Avant optimisation
    [*] Clic sur le bouton Créer, puis sur le bouton OK.:

    =====

    ZHPFix

    [*] Ferme toutes tes applications en cours.

    [*] Double clique sur l'icône ZHPFix sur ton bureau
    Note :
    Pour Vista et Windows 7 faites un clic droit sur l'icône et sélectionnez Exécuter en tant qu'administrateur.

    [*] Copie les lignes ci dessous :

    OPT:O4 - HKLM\..\Run: [HPHmon05] . (.Hewlett-Packard - HPHmon05.) -- C:\WINDOWS\System32\hphmon05.exe 
    OPT:O4 - HKLM\..\Run: [TkBellExe] . (.RealNetworks, Inc. - RealNetworks Scheduler.) -- C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
    OPT:O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] . (.Adobe Systems Incorporated - Adobe Acrobat SpeedLauncher.) -- C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe 
    OPT:O4 - HKLM\..\Run: [Adobe ARM] . (.Adobe Systems Incorporated - Adobe Reader and Acrobat Manager.) -- C:\Program Files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe
    OPT:O4 - HKLM\..\RunOnce: [Uninstall Adobe Download Manager] . (.NOS Microsystems Ltd. - getPlus+(R).) -- C:\Program Files\NOS\bin\getPlusUninst_Adobe.exe
    OPT:O4 - HKCU\..\Run: [ctfmon.exe] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\ctfmon.exe
    OPT:O4 - HKCU\..\Run: [Acme.PCHButton] . (.Motive Communications, Inc. - Pas de description.) -- C:\PROGRA~1\PRESAR~1\Presario\XPHWWRP4\plugin\bin\PCHButton.exe
    OPT:O4 - HKCU\..\Run: [msnmsgr] . (.Microsoft Corporation - Windows Live Messenger.) -- C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    OPT:O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] . (.Microsoft Corporation - Watson Subscriber for SENS Network Notifica.) -- C:\PROGRA~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe 
    OPT:O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] . (.Microsoft Corporation - Watson Subscriber for SENS Network Notifica.) -- C:\PROGRA~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe
    OPT:O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\System32\CTFMON.exe 
    OPT:O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\System32\CTFMON.exe
    OPT:O4 - HKUS\S-1-5-21-3959529750-497367016-2629840051-1003\..\Run: [ctfmon.exe] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\ctfmon.exe
    OPT:O4 - HKUS\S-1-5-21-3959529750-497367016-2629840051-1003\..\Run: [Acme.PCHButton] . (.Motive Communications, Inc. - Pas de description.) -- C:\PROGRA~1\PRESAR~1\Presario\XPHWWRP4\plugin\bin\PCHButton.exe 
    OPT:O4 - HKUS\S-1-5-21-3959529750-497367016-2629840051-1003\..\Run: [msnmsgr] . (.Microsoft Corporation - Windows Live Messenger.) -- C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    CTFDisabled
    O47 - AAKE:Key Export DP - "C:\Program Files\Windows Live\Messenger\wlcsdk.exe" [Enabled] .(.Pas de propriétaire - Pas de description.) (.not file.) -- 
    O64 - Services: CurCS - (.not file.) - File Security Driver (IKFileSec)  .(.Pas de propriétaire - Pas de description.) - LEGACY_IKFILESEC
    O64 - Services: CurCS - (.not file.) - System Filter Driver (IKSysFlt)  .(.Pas de propriétaire - Pas de description.) - LEGACY_IKSYSFLT
    O64 - Services: CurCS - (.not file.) - System Security Driver (IKSysSec)  .(.Pas de propriétaire - Pas de description.) - LEGACY_IKSYSSEC
    O64 - Services: CurCS - (.not file.) - Kl1 (Kl1)  .(.Pas de propriétaire - Pas de description.) - LEGACY_KL1
    O64 - Services: CurCS - (.not file.) - Klif (Klif)  .(.Pas de propriétaire - Pas de description.) - LEGACY_KLIF
    O64 - Services: CurCS - (.not file.) - Klmc (Klmc)  .(.Pas de propriétaire - Pas de description.) - LEGACY_KLMC
    O64 - Services: CurCS - (.not file.) - SAVRTPEL (SAVRTPEL)  .(.Pas de propriétaire - Pas de description.) - LEGACY_SAVRTPEL
    ServiceDisabled:SeaPort
    
    
    


    [*] Clique sur le bouton H pour coller ces lignes

    [*] Clique sur le bouton OK.

    [*] Clique sur le bouton Tous pour les sélectionner.

    [*] Clique sur le bouton Nettoyer afin de les supprimer

    [*] Accepte la désinstallation des programmes si proposé, mais refuse le redémarrage de ton pc si également proposé, car cela stopperai ZHPFix.

    [*] Ton navigateur risque de s'ouvrir pendant la désinstallation des toolbars, pas de panique c'est normal, ferme les fenêtres tout simplement.

    [*] Redémarre le pc, copie et colle le rapport ZHPFix.txt qui s'affiche.
    Note : le rapport est enregistré sous C:\Program Files\ZHPDiag\ZHPFixReport.txt

    ========

    Utilises tu plusieurs écran sur ton pc ?
    Utilises tu un ipod ou autre avec iTunes ?

    ========

    Refait un nouveau scan zhpdiag et met le sur cijoint.fr

    et dis moi comment se comporte ton pc, est il plus véloce ?

    @+
    0
  20. noya83000 Messages postés 19 Statut Membre
     
    bonsoir tout d abord je n ai pas d ipod et je ne sais meme pas a quoi sert itunes sinon voici les rapports :http://www.cijoint.fr/cjlink.php?file=cj201101/cijq5YWpiA.txt Rapport de ZHPFix 1.12.3237 par Nicolas Coolman, Update du 12/01/2011
    Fichier d'export Registre :
    Run by Propriétaire at 16/01/2011 22:50:06
    Windows XP Home Edition Service Pack 3 (Build 2600)
    Web site : http://www.premiumorange.com/zeb-help-process/zhpfix.html
    Contact : nicolascoolman@yahoo.fr

    ========== Clé(s) du Registre ==========
    O64 - Services: CurCS - (.not file.) - File Security Driver (IKFileSec) .(.Pas de propriétaire - Pas de description.) - LEGACY_IKFILESEC => Clé supprimée avec succès
    O64 - Services: CurCS - (.not file.) - System Filter Driver (IKSysFlt) .(.Pas de propriétaire - Pas de description.) - LEGACY_IKSYSFLT => Clé supprimée avec succès
    O64 - Services: CurCS - (.not file.) - System Security Driver (IKSysSec) .(.Pas de propriétaire - Pas de description.) - LEGACY_IKSYSSEC => Clé supprimée avec succès
    O64 - Services: CurCS - (.not file.) - Kl1 (Kl1) .(.Pas de propriétaire - Pas de description.) - LEGACY_KL1 => Clé supprimée avec succès
    O64 - Services: CurCS - (.not file.) - Klif (Klif) .(.Pas de propriétaire - Pas de description.) - LEGACY_KLIF => Clé supprimée avec succès
    O64 - Services: CurCS - (.not file.) - Klmc (Klmc) .(.Pas de propriétaire - Pas de description.) - LEGACY_KLMC => Clé supprimée avec succès
    O64 - Services: CurCS - (.not file.) - SAVRTPEL (SAVRTPEL) .(.Pas de propriétaire - Pas de description.) - LEGACY_SAVRTPEL => Clé supprimée avec succès

    ========== Valeur(s) du Registre ==========
    O4 - HKLM\..\Run: [HPHmon05] . (.Hewlett-Packard - HPHmon05.) -- C:\WINDOWS\System32\hphmon05.exe => Valeur supprimée avec succès
    O4 - HKLM\..\Run: [TkBellExe] . (.RealNetworks, Inc. - RealNetworks Scheduler.) -- C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe => Valeur supprimée avec succès
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] . (.Adobe Systems Incorporated - Adobe Acrobat SpeedLauncher.) -- C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe => Valeur supprimée avec succès
    O4 - HKLM\..\Run: [Adobe ARM] . (.Adobe Systems Incorporated - Adobe Reader and Acrobat Manager.) -- C:\Program Files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe => Valeur supprimée avec succès
    O4 - HKLM\..\RunOnce: [Uninstall Adobe Download Manager] . (.NOS Microsystems Ltd. - getPlus+(R).) -- C:\Program Files\NOS\bin\getPlusUninst_Adobe.exe => Valeur absente
    O4 - HKCU\..\Run: [ctfmon.exe] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\ctfmon.exe => Valeur supprimée avec succès
    O4 - HKCU\..\Run: [Acme.PCHButton] . (.Motive Communications, Inc. - Pas de description.) -- C:\PROGRA~1\PRESAR~1\Presario\XPHWWRP4\plugin\bin\PCHButton.exe => Valeur supprimée avec succès
    O4 - HKCU\..\Run: [msnmsgr] . (.Microsoft Corporation - Windows Live Messenger.) -- C:\Program Files\Windows Live\Messenger\msnmsgr.exe => Valeur supprimée avec succès
    O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] . (.Microsoft Corporation - Watson Subscriber for SENS Network Notifica.) -- C:\PROGRA~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe => Valeur supprimée avec succès
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\System32\CTFMON.exe => Valeur supprimée avec succès
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\System32\CTFMON.exe => Valeur supprimée avec succès
    O4 - HKUS\S-1-5-21-3959529750-497367016-2629840051-1003\..\Run: [ctfmon.exe] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\ctfmon.exe => Valeur absente
    O4 - HKUS\S-1-5-21-3959529750-497367016-2629840051-1003\..\Run: [Acme.PCHButton] . (.Motive Communications, Inc. - Pas de description.) -- C:\PROGRA~1\PRESAR~1\Presario\XPHWWRP4\plugin\bin\PCHButton.exe => Valeur absente
    O4 - HKUS\S-1-5-21-3959529750-497367016-2629840051-1003\..\Run: [msnmsgr] . (.Microsoft Corporation - Windows Live Messenger.) -- C:\Program Files\Windows Live\Messenger\msnmsgr.exe => Valeur absente
    O47 - AAKE:Key Export DP - "C:\Program Files\Windows Live\Messenger\wlcsdk.exe" [Enabled] .(.) (.not file.) -- => Valeur supprimée avec succès

    ========== Elément(s) de donnée du Registre ==========
    CTFDisabled => Donnée supprimée avec succès

    ========== Etat des services ==========
    SeaPort => Service arrêté avec succès
    SeaPort => Service configuré avec succès (disabled)

    ========== Récapitulatif ==========
    7 : Clé(s) du Registre
    15 : Valeur(s) du Registre
    1 : Elément(s) de donnée du Registre
    2 : Etat des services

    End of the scan
    0
  21. Patdam73 Messages postés 271 Statut Membre 13
     
    Très bien

    Remet un nouveau scan zhpdiag sur cijoint, on va désactiver en deux bricoles puis on termine.

    Bonne journée
    0
  • 1
  • 2