Google redirigé vers des sites commerciaux

Résolu
sushijunky Messages postés 1 Statut Membre -  
flo-91 Messages postés 5973 Statut Contributeur sécurité -
Bonjour,

Comme beaucoup, je suis actuellement victime d'une infection qui redirige systématiquement mes recherches Google vers divers sites.
En lisant le dernier post sur ce sujet (par Minhouche, le 10/04/2011), j'ai procédé moi aussi à un scan par ZHP Diag et suis passée par cijoint pour vous permettre d'accéder au rapport obtenu: http://cjoint.com/?1emnambPRFo

Voilà, j'espère de tout coeur qu'un de vos spécialistes saura m'aider, je n'arrive plus à m'en sortir...

Merci d'avance!

9 réponses

  1. flo-91 Messages postés 5973 Statut Contributeur sécurité 1 120
     
    Bonjour,

    Commence par faire ceci :

    * Lance ZHPFix (via ZHPDiag)
    * Clique sur l'icone représentant la lettre H (« coller les lignes Helper »)
    * Copie/colle les lignes suivantes et place les dans ZHPFix :

    O2 - BHO: (no name) - {10A754D5-5F14-4E65-B98D-B52F360E3A81} . (.Borland Software Corporation - Xerces XML DOM Interfaces.) -- C:\Windows\system32\api-ms-win-core-heap-l1-1-032.dll
    O4 - HKLM\..\Run: [RTHDBPL] . (...) -- C:\Users\Marine Nicolas\AppData\Roaming\SysWin\lsass.exe
    [HKCR\.fsharproj]
    [HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]:{D4027C7F-154A-4066-A1AD-4243D8127440}
    [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440}]
    [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}]
    [HKCU\Software\Ytskvggkvj]
    O23 - Service: (SDRSVC32) . (...) - C:\Windows\system32\iprtprio32.exe
    O23 - Service: (p2psvc32) . (...) - C:\Windows\system32\mswdat1032.exe
    O44 - LFC:[MD5.1CD2953B1AF23282A27C8104D4D154B0] - 07/04/2011 - 16:51:25 ---A- . (...) -- C:\Windows\System32\908041877 [28]
    O44 - LFC:[MD5.11CCDB7F360F25803C08FC0A1133CF3F] - 07/04/2011 - 16:39:52 ---A- . (...) -- C:\Windows\System32\api-ms-win-service-core-l1-1-032.exe [201728]
    O44 - LFC:[MD5.3CB3FF7FE77EC722EF9EC1CB4F38CDAF] - 06/04/2011 - 08:21:44 ---A- . (...) -- C:\Windows\System32\iprtprio32.exe [1410048]
    O44 - LFC:[MD5.3CB3FF7FE77EC722EF9EC1CB4F38CDAF] - 06/04/2011 - 08:21:44 ---A- . (...) -- C:\Windows\System32\mswdat1032.exe [1410048]
    O87 - FAEL: "{E5ACEE2C-22C2-4052-9A00-5B4F4E0612AD}" | In - Private - P17 - TRUE | .(...) -- C:\Windows\system32\iprtprio32.exe
    O87 - FAEL: "{13641B3F-6E6D-45C5-8D3A-D4FF03000E8A}" | In - Public - P17 - TRUE | .(...) -- C:\Windows\system32\iprtprio32.exe
    O87 - FAEL: "{4FD01514-CC0B-46FB-9FC0-743791494D94}" | In - Domain - P17 - TRUE | .(...) -- C:\Windows\system32\iprtprio32.exe
    O87 - FAEL: "{EAFAC70B-4D76-4138-9C8F-8923A4793861}" | In - Public - P17 - TRUE | .(...) -- C:\Windows\system32\mswdat1032.exe
    O87 - FAEL: "{C185A4C6-E1AF-413B-933F-648F6AA2F6B9}" | In - Domain - P17 - TRUE | .(...) -- C:\Windows\system32\mswdat1032.exe
    O87 - FAEL: "{F107F6B7-B61D-4FEA-82CD-CABAE7D665C4}" | In - Private - P17 - TRUE | .(...) -- C:\Windows\system32\mswdat1032.exe
    O87 - FAEL: "{F2CD2D59-5866-4746-9263-7953EBAAF37F}" | In - Domain - P17 - TRUE | .(...) -- C:\Windows\system32\iernonce32.exe
    O87 - FAEL: "{4509AAC5-8EFE-4785-A8DE-DC8C68A44838}" | In - Public - P17 - TRUE | .(...) -- C:\Windows\system32\iernonce32.exe
    O87 - FAEL: "{7F27747E-828B-4546-87A5-E53598718F14}" | In - Private - P17 - TRUE | .(...) -- C:\Windows\system32\iernonce32.exe


    * Clique sur « Tous », puis sur « Nettoyer »
    * Copie/colle la totalité du rapport dans ta prochaine réponse


    2)


    >Telecharge malwarebytes ici :

    https://www.commentcamarche.net/telecharger/securite/14361-malwarebytes-anti-malware/

    . sur la page cliques sur Télécharger Malwarebyte's Anti-Malware
    . enregistres le sur le bureau
    /!\Utilisateur de Vista : Clique droit sur le logo de Malwarebytes' Anti-Malware, « exécuter en tant qu'Administrateur »

    . Double cliques sur le fichier téléchargé pour lancer le processus d'installation.
    . Dans l'onglet "mise à jour", cliques sur le bouton Recherche de mise à jour
    . si le pare-feu demande l'autorisation de se connecter pour malwarebytes, acceptes
    . Une fois la mise à jour terminé
    . rend-toi dans l'onglet, Recherche
    . Sélectionnes Exécuter un examen complet
    . Cliques sur Rechercher
    . Le scan démarre.
    . A la fin de l'analyse, un message s'affiche : L'examen s'est terminé normalement. Cliquez sur 'Afficher les résultats' pour afficher tous les objets trouvés.
    . Cliques sur Ok pour poursuivre.
    . Si des malwares ont été détectés, cliques sur Afficher les résultats
    . Sélectionnes tout (ou laisses cochés) et cliques sur Supprimer la sélection Malwarebytes va détruire les fichiers et clés de registre et en mettre une copie dans la quarantaine.
    . Malwarebytes va ouvrir le bloc-notes et y copier le rapport d'analyse.
    . rends toi dans l'onglet rapport/log
    . tu cliques dessus pour l'afficher une fois affiché
    . tu cliques sur edition en haut du boc notes,et puis sur sélectionner tous
    . tu recliques sur edition et puis sur copier et tu reviens sur le forum et dans ta réponse
    . tu cliques droit dans le cadre de la reponse et coller

    Si tu as besoin d'aide regarde ce tutoriel :
    https://www.malekal.com/tutoriel-malwarebyte-anti-malware/
    0
  2. sushijunky
     
    Rebonjour!

    Je te remercie pour ton aide si précieuse! Désolée du retard, le scan MalwareBytes était très long...

    - Voilà le ZHP Fix Report:

    Rapport de ZHPFix 1.12.3275 par Nicolas Coolman, Update du 11/04/2011
    Fichier d'export Registre :
    Run by Marine Nicolas at 12/04/2011 15:10:02
    Windows 7 Home Premium Edition, 32-bit (Build 7600)
    Web site : http://www.premiumorange.com/zeb-help-process/zhpfix.html

    ========== Clé(s) du Registre ==========
    O2 - BHO: (no name) - {10A754D5-5F14-4E65-B98D-B52F360E3A81} . (.Borland Software Corporation - Xerces XML DOM Interfaces.) -- C:\Windows\system32\api-ms-win-core-heap-l1-1-032.dll => Clé supprimée avec succès
    HKCR\.fsharproj => Clé supprimée avec succès
    HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440} => Clé supprimée avec succès
    HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440} => Clé supprimée avec succès
    HKCU\Software\Ytskvggkvj => Clé supprimée avec succès
    O23 - Service: (SDRSVC32) . (...) - C:\Windows\system32\iprtprio32.exe => Clé supprimée avec succès
    O23 - Service: (p2psvc32) . (...) - C:\Windows\system32\mswdat1032.exe => Clé supprimée avec succès

    ========== Valeur(s) du Registre ==========
    O4 - HKLM\..\Run: [RTHDBPL] . (...) -- C:\Users\Marine Nicolas\AppData\Roaming\SysWin\lsass.exe => Valeur supprimée avec succès
    [HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]:{D4027C7F-154A-4066-A1AD-4243D8127440} => Valeur supprimée avec succès
    {E5ACEE2C-22C2-4052-9A00-5B4F4E0612AD} => Valeur supprimée avec succès
    {13641B3F-6E6D-45C5-8D3A-D4FF03000E8A} => Valeur supprimée avec succès
    {4FD01514-CC0B-46FB-9FC0-743791494D94} => Valeur supprimée avec succès
    {EAFAC70B-4D76-4138-9C8F-8923A4793861} => Valeur supprimée avec succès
    {C185A4C6-E1AF-413B-933F-648F6AA2F6B9} => Valeur supprimée avec succès
    {F107F6B7-B61D-4FEA-82CD-CABAE7D665C4} => Valeur supprimée avec succès
    {F2CD2D59-5866-4746-9263-7953EBAAF37F} => Valeur supprimée avec succès
    {4509AAC5-8EFE-4785-A8DE-DC8C68A44838} => Valeur supprimée avec succès
    {7F27747E-828B-4546-87A5-E53598718F14} => Valeur supprimée avec succès

    ========== Fichier(s) ==========
    c:\windows\system32\api-ms-win-core-heap-l1-1-032.dll => Supprimé et mis en quarantaine
    c:\users\marine nicolas\appdata\roaming\syswin\lsass.exe => Supprimé et mis en quarantaine
    c:\windows\system32\iprtprio32.exe => Supprimé et mis en quarantaine
    c:\windows\system32\mswdat1032.exe => Supprimé et mis en quarantaine
    c:\windows\system32\908041877 => Supprimé et mis en quarantaine
    c:\windows\system32\api-ms-win-service-core-l1-1-032.exe => Supprimé et mis en quarantaine

    ========== Récapitulatif ==========
    7 : Clé(s) du Registre
    11 : Valeur(s) du Registre
    6 : Fichier(s)

    End of the scan

    - J'ai ensuite procédé à la 2ème étape comme convenu avec MalwareBytes. Voilà le rapport:

    Malwarebytes' Anti-Malware 1.50
    www.malwarebytes.org

    Version de la base de données: 6341

    Windows 6.1.7600
    Internet Explorer 8.0.7600.16385

    12/04/2011 18:21:26
    mbam-log-2011-04-12 (18-21-26).txt

    Type d'examen: Examen complet (C:\|D:\|)
    Elément(s) analysé(s): 249359
    Temps écoulé: 1 heure(s), 58 minute(s), 7 seconde(s)

    Processus mémoire infecté(s): 0
    Module(s) mémoire infecté(s): 0
    Clé(s) du Registre infectée(s): 2
    Valeur(s) du Registre infectée(s): 0
    Elément(s) de données du Registre infecté(s): 0
    Dossier(s) infecté(s): 1
    Fichier(s) infecté(s): 9

    Processus mémoire infecté(s):
    (Aucun élément nuisible détecté)

    Module(s) mémoire infecté(s):
    (Aucun élément nuisible détecté)

    Clé(s) du Registre infectée(s):
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EapHost32 (Trojan.Tracur.S) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PlugPlay32 (Trojan.Tracur.S) -> Quarantined and deleted successfully.

    Valeur(s) du Registre infectée(s):
    (Aucun élément nuisible détecté)

    Elément(s) de données du Registre infecté(s):
    (Aucun élément nuisible détecté)

    Dossier(s) infecté(s):
    c:\Users\marine nicolas\AppData\Roaming\SysWin (Trojan.Agent) -> Quarantined and deleted successfully.

    Fichier(s) infecté(s):
    c:\Windows\System32\aeevts32.exe (Trojan.Tracur.S) -> Quarantined and deleted successfully.
    c:\Windows\System32\iernonce32.exe (Trojan.Tracur.S) -> Quarantined and deleted successfully.
    c:\program files\ZHPDiag\quarantine\api-ms-win-core-heap-l1-1-032.dll.vir (Trojan.Tracur.S) -> Delete on reboot.
    c:\program files\ZHPDiag\quarantine\api-ms-win-service-core-l1-1-032.exe.vir (Trojan.Tracur.S) -> Quarantined and deleted successfully.
    c:\program files\ZHPDiag\quarantine\iprtprio32.exe.vir (Trojan.Tracur.S) -> Quarantined and deleted successfully.
    c:\program files\ZHPDiag\quarantine\lsass.exe.vir (Trojan.Tracur.S) -> Quarantined and deleted successfully.
    c:\program files\ZHPDiag\quarantine\mswdat1032.exe.vir (Trojan.Tracur.S) -> Quarantined and deleted successfully.
    c:\system volume information\_restore{72646770-83dc-4890-a366-197c52efc9c7}\RP237\A0091423.exe (PUP.Fbsearch) -> Not selected for removal.
    c:\Users\marine nicolas\AppData\Local\Temp\Rar$EX19.355\setup.exe (Trojan.Tracur.S) -> Quarantined and deleted successfully.

    P.S. Encore merci, c'est vraiment très gentil de prendre le temps de nous aider!
    0
  3. flo-91 Messages postés 5973 Statut Contributeur sécurité 1 120
     
    Ok, la suite :

    Pour les ordinateurs équipés de Windows Vista et Windows 7, la désactivation du Contrôle des comptes utilisateurs est obligatoire
    sous peine de ne pas pouvoir faire fonctionner correctement l'outil.
    Tuto : https://www.commentcamarche.net/faq/8343-vista-desactiver-l-uac

    >Ad-Remover<

    >Telecharge Ad-Remover et enregistre-le sur ton bureau :

    https://www.commentcamarche.net/telecharger/securite/2547-ad-remover/

    >Désactive ton antivirus le temps de la manip
    >Déconnecte-toi d'Internet et ferme toutes applications en cours
    >Double-clique sur le programme d'installation, installe-le dans son emplacement par défaut (C:\Program Files).
    >Au menu principal, choisis l'option Scan
    >Poste le rapport généré (C:\Ad-Report-CLEAN.log).
    >N'oublie pas de réactiver ton anti-virus
    0
  4. sushijunky
     
    C'est tout bon.

    Seul bémol, après l'avoir enregistré sur le bureau, je n'ai pas eu accès à une option permettant de l'installer sous C:/ProgramFiles. J'ai donc lancé le scan à partir de son emplacement sur le bureau, l'intitulé du rapport est donc Ad-Report-SCAN[1] et pas C\Ad-Report-CLEAN.log.
    (Dois-je lancer l'option nettoyer?)

    ======= RAPPORT D'AD-REMOVER 2.0.0.2,G | UNIQUEMENT XP/VISTA/7 =======

    Mis à jour par TeamXscript le 12/04/11
    Contact: AdRemover[DOT]contact[AT]gmail[DOT]com
    Site web: http://www.teamxscript.org

    C:\Program Files\Ad-Remover\main.exe (SCAN [1]) -> Lancé à 19:18:09 le 12/04/2011, Mode normal

    Microsoft Windows 7 Édition Familiale Premium (X86)
    Marine Nicolas@MARINENICOLAS ( )

    ============== RECHERCHE ==============

    ============== SCAN ADDITIONNEL ==============

    **** Internet Explorer Version [8.0.7600.16385] ****

    HKCU_Main|Search Page - hxxp://go.microsoft.com/fwlink/?LinkId=54896
    HKCU_Main|Start Page - hxxp://www.google.fr/
    HKLM_Main|Default_Page_URL - hxxp://go.microsoft.com/fwlink/?LinkId=69157
    HKLM_Main|Default_Search_URL - hxxp://go.microsoft.com/fwlink/?LinkId=54896
    HKLM_Main|Search Page - hxxp://go.microsoft.com/fwlink/?LinkId=54896
    HKLM_Main|Start Page - hxxp://go.microsoft.com/fwlink/?LinkId=69157
    HKLM_ElevationPolicy\{07d873dc-b9b9-44f5-af0b-fb59fa54fb7a} - C:\Windows\System32\wpcer.exe (x)
    HKLM_ElevationPolicy\{0a402d70-1f10-4ae7-bec9-286a98240695} - C:\Windows\System32\winfxdocobj.exe (x)
    HKLM_ElevationPolicy\{70f641fd-9ffc-4d5b-a4dc-962af4ed7999} - C:\Program Files\Internet Explorer\iedw.exe (x)

    ========================================

    C:\Program Files\Ad-Remover\Quarantine: 0 Fichier(s)
    C:\Program Files\Ad-Remover\Backup: 1 Fichier(s)

    C:\Ad-Report-SCAN[1].txt - 12/04/2011 19:18:35 (1422 Octet(s))

    Fin à: 19:19:31, 12/04/2011

    ============== E.O.F ==============

    Merci!
    0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. flo-91 Messages postés 5973 Statut Contributeur sécurité 1 120
     
    Ok, tu es toujours redirigé ?

    Reposte un nouveau rapport ZHPDIAG stp =)
    0
  7. sushijunky
     
    Nan! On dirait que je ne suis plus redirigée :D J'ai essayé plusieurs fois et ça m'a l'air bon! J'ai quand même fait le ZHP Diag:

    Rapport de ZHPDiag v1.27.1868 par Nicolas Coolman, Update du 11/04/2011
    Run by Marine Nicolas at 12/04/2011 19:50:42
    Web site : http://www.premiumorange.com/zeb-help-process/zhpdiag.html

    ---\\ Web Browser
    MSIE: Internet Explorer v8.0.7600.16385 (Defaut)

    ---\\ System Information
    Windows 7 Home Premium Edition, 32-bit (Build 7600)
    Processor: x86 Family 15 Model 44 Stepping 2, AuthenticAMD
    Operating System: 32 Bits
    Boot mode: Normal (Normal boot)
    Total RAM: 1535 MB (55% free)
    System Restore: Activé (Enable)
    System drive C: has 33 GB (44%) free of 75 GB

    ---\\ Logged in mode
    Computer Name: MARINENICOLAS
    User Name: Marine Nicolas
    All Users Names: Marine Nicolas, HomeGroupUser$, ASPNET, Administrateur,
    Unselected Option: O45,O61,O62,O65,O66,O82
    Logged in as Administrator

    ---\\ Environnement Variables
    %AppData%=C:\Users\Marine Nicolas\AppData\Roaming
    %LocalAppData%=C:\Users\Marine Nicolas\AppData\Local
    %StartMenu%=C:\Users\Marine Nicolas\AppData\Roaming\Microsoft\Windows\Start Menu

    ---\\ DOS/Devices
    A:\ Floppy drive, Flash card reader, USB Key (Not Inserted)
    C:\ Hard drive, Flash drive, Thumb drive (Free 33 Go of 75 Go)
    D:\ Hard drive, Flash drive, Thumb drive (Free 32 Go of 76 Go)
    F:\ CD-ROM drive (Not Inserted)
    G:\ CD-ROM drive (Not Inserted)

    ---\\ Security Center & Tools Informations
    [HKLM\SOFTWARE\Microsoft\Security Center] AntiSpywareOverride: OK
    [HKLM\SOFTWARE\Microsoft\Security Center] AntiVirusOverride: OK
    [HKLM\SOFTWARE\Microsoft\Security Center] AntiVirusDisableNotify: OK
    [HKLM\SOFTWARE\Microsoft\Security Center] FirewallDisableNotify: OK
    [HKLM\SOFTWARE\Microsoft\Security Center] FirewallOverride: OK
    [HKLM\SOFTWARE\Microsoft\Security Center] UpdatesDisableNotify: OK
    [HKLM\SOFTWARE\Microsoft\Security Center] UacDisableNotify: OK
    [HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiSpywareOverride: OK
    [HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusOverride: OK
    [HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusDisableNotify: OK
    [HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallDisableNotify: OK
    [HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallOverride: OK
    [HKLM\SOFTWARE\Microsoft\Security Center\Svc] UpdatesDisableNotify: OK
    [HKLM\SOFTWARE\Microsoft\Security Center\Svc] UacDisableNotify: OK
    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System] NoActiveDesktopChanges: OK
    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: OK
    [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced] Start_ShowSearch: OK
    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK
    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: Modified

    ---\\ Recherche particulière de fichiers génériques
    [MD5.2626FC9755BE22F805D3CFA0CE3EE727] - (.Microsoft Corporation - Explorateur Windows.) (.31/10/2009 06:45:39.) -- C:\Windows\Explorer.exe [2614272]
    [MD5.B5C5DCAD3899512020D135600129D665] - (.Microsoft Corporation - Application de démarrage de Windows.) (.14/07/2009 02:14:45.) -- C:\Windows\system32\Wininit.exe [96256]
    [MD5.78B9ADA2BC8946AF7B17678E0D07A773] - (.Microsoft Corporation - Extensions Internet pour Win32.) (.21/12/2010 06:38:22.) -- C:\Windows\system32\wininet.dll [981504]
    [MD5.37CDB7E72EB66BA85A87CBE37E7F03FD] - (.Microsoft Corporation - Application d'ouverture de session Windows.) (.28/10/2009 07:17:59.) -- C:\Windows\system32\Winlogon.exe [285696]
    [MD5.338C86357871C167A96AB976519BF59E] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.14/07/2009 02:26:15.) -- C:\Windows\system32\drivers\atapi.sys [21584]
    [MD5.3795DCD21F740EE799FB7223234215AF] - (.Microsoft Corporation - Pilote du système de fichiers NT.) (.14/07/2009 02:20:44.) -- C:\Windows\system32\drivers\ntfs.sys [1210432]

    ---\\ Processus lancés
    [MD5.B70BCC55743C5A5BD7C7C6D6A02BB6F9] - (.Realtek Semiconductor Corp. - Realtek Sound Manager.) -- C:\Windows\SOUNDMAN.EXE [604704]
    [MD5.38AE7A942FC3FAB1C6A27EB65DE8F827] - (.AVAST Software - avast! Antivirus.) -- C:\Program Files\Alwil Software\Avast5\AvastUI.exe [2837864]
    [MD5.93DB1FF92B03D24738A71E6E4992DFD3] - (.Sun Microsystems, Inc. - Java(TM) Update Scheduler.) -- C:\Program Files\Common Files\Java\Java Update\jusched.exe [248552]
    [MD5.F3DEAA1F2FCF70FAF6DE3757CA343FA5] - (.Apple Inc. - iTunesHelper.) -- C:\Program Files\iTunes\iTunesHelper.exe [421160]
    [MD5.9D5E8B45BD348DF0882C69EED0E83111] - (.Avira GmbH - Antivirus System Tray Tool.) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [281768]
    [MD5.2AA7EE2774035050512F438C2DF052A2] - (.Creative Technology Ltd - Creative Camera Launcher Application.) -- C:\Program Files\Creative\Shared Files\CamTray.exe [299008]
    [MD5.E7704CBF568815C1CAA6E513387BD3F2] - (.Advanced Micro Devices Inc. - Catalyst Control Center: Monitoring program.) -- C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe [65536]
    [MD5.303EAD15DE8EE43CC874C709BB17BF2E] - (.OpenOffice.org - OpenOffice.org 2.1.) -- C:\Program Files\OpenOffice.org 2.1\program\soffice.exe [2334720]
    [MD5.550E3443C77EDE680C06BB47D9DA276D] - (.OpenOffice.org - OpenOffice.org 2.1.) -- C:\Program Files\OpenOffice.org 2.1\program\soffice.BIN [2486272]
    [MD5.74EF310FAC89341CE2897B7F2C4A7B0F] - (.ATI Technologies Inc. - Catalyst Control Centre: Host application.) -- C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe [65536]
    [MD5.AA08B68EF4E35EFA170CF85A44B23B70] - (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe [673040]
    [MD5.103C66E16FAA3D61F3B37BC7118EEA11] - (.Nicolas Coolman - Diagnostic Tool.) -- C:\Program Files\ZHPDiag\ZHPDiag.exe [642560]

    ---\\ Mozilla Firefox, Plugins,Demarrage,Recherche,Extensions (P2,M0,M1,M2,M3)
    P2 - FPN: [HKLM] [@Apple.com/iTunes,version=1.0] - (.Pas de propriétaire - Pas de description.) -- C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
    P2 - FPN: [HKLM] [@divx.com/DivX Browser Plugin,version=1.0.0] - (.DivX,Inc. - DivX Web Player version 2.0.0.254.) -- C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll
    P2 - FPN: [HKLM] [@java.com/JavaPlugin] - (.Sun Microsystems, Inc. - Next Generation Java Plug-in 1.6.0_23 for Mozilla browsers.) -- C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
    P2 - FPN: [HKLM] [@Microsoft.com/NpCtrl,version=1.0] - (. Microsoft Corporation - 4.0.60129.0.) -- c:\Program Files\Microsoft Silverlight\4.0.60129.0\npctrl.dll

    ---\\ Internet Explorer, Démarrage,Recherche,URLSearchHook, Phishing (R0,R1,R3,R4)
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com
    R0 - HKUS\S-1-5-21-3491047958-2690678013-3139997141-1001\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk
    R1 - HKUS\S-1-5-21-3491047958-2690678013-3139997141-1001\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com
    R3 - URLSearchHook: Microsoft Url Search Hook - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} . (.Microsoft Corporation - Navigateur Internet.) (8.00.7600.16385 (win7_rtm.090713-1255)) -- C:\Windows\System32\ieframe.dll
    R4 - HKLM\SOFTWARE\Microsoft\Internet Explorer\PhishingFilter,EnabledV8 = 1

    ---\\ Internet Explorer, Proxy Management (R5)
    R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key
    R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
    R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
    R5 - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
    R5 - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll

    ---\\ ---\\ Modification d'une valeur Ini (Changed inifile value, mapped to Registry) (F2)
    F2 - REG:system.ini: UserInit=C:\Windows\system32\userinit.exe,
    F2 - REG:system.ini: VMApplet=C:\WINDOWS\system32\SystemPropertiesPerformance.exe

    ---\\ Browser Helper Objects de navigateur (O2)
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} . (.Adobe Systems Incorporated - Adobe PDF Helper for Internet Explorer.) -- C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} . (.Microsoft Corp. - Microsoft® Windows Live ID Login Helper.) -- C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} . (.Sun Microsystems, Inc. - Java(TM) Platform SE binary.) -- C:\Program Files\Java\jre6\bin\jp2ssv.dll

    ---\\ ---\\ Applications démarrées par registre & par dossier (O4)
    O4 - HKLM\..\Run: [SoundMan] . (.Realtek Semiconductor Corp. - Realtek Sound Manager.) -- C:\Windows\SOUNDMAN.exe
    O4 - HKLM\..\Run: [StartCCC] . (.Advanced Micro Devices, Inc. - Catalyst® Control Center Launcher.) -- C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
    O4 - HKLM\..\Run: [avast5] . (.AVAST Software - avast! Antivirus.) -- C:\Program Files\Alwil Software\Avast5\avastUI.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] . (.Sun Microsystems, Inc. - Java(TM) Update Scheduler.) -- C:\Program Files\Common Files\Java\Java Update\jusched.exe
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] . (.Adobe Systems Incorporated - Adobe Acrobat SpeedLauncher.) -- C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
    O4 - HKLM\..\Run: [Adobe ARM] . (.Adobe Systems Incorporated - Adobe Reader and Acrobat Manager.) -- C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
    O4 - HKLM\..\Run: [QuickTime Task] . (.Apple Inc. - QuickTime Task.) -- C:\Program Files\QuickTime\QTTask.exe
    O4 - HKLM\..\Run: [iTunesHelper] . (.Apple Inc. - iTunesHelper.) -- C:\Program Files\iTunes\iTunesHelper.exe
    O4 - HKLM\..\Run: [avgnt] . (.Avira GmbH - Antivirus System Tray Tool.) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
    O4 - HKCU\..\Run: [msnmsgr] . (.Microsoft Corporation - Windows Live Messenger.) -- C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    O4 - HKCU\..\Run: [Creative WebCam Tray] . (.Creative Technology Ltd - Creative Camera Launcher Application.) -- C:\Program Files\Creative\Shared Files\CamTray.exe
    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files\Windows Sidebar\Sidebar.exe
    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files\Windows Sidebar\Sidebar.exe
    O4 - HKUS\S-1-5-21-3491047958-2690678013-3139997141-1001\..\Run: [msnmsgr] . (.Microsoft Corporation - Windows Live Messenger.) -- C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    O4 - HKUS\S-1-5-21-3491047958-2690678013-3139997141-1001\..\Run: [Creative WebCam Tray] . (.Creative Technology Ltd - Creative Camera Launcher Application.) -- C:\Program Files\Creative\Shared Files\CamTray.exe
    O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe
    O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe
    O4 - Global Startup: C:\Users\Marine Nicolas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 2.1.lnk . (...) -- C:\Program Files\OpenOffice.org 2.1\program\quickstart.exe

    ---\\ ---\\ Autres liens utilisateurs (O4)
    O4 - Global Startup: C:\Users\Marine Nicolas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk . (.Microsoft Corporation.) -- C:\Program Files\Internet Explorer\iexplore.exe
    O4 - Global Startup: C:\Users\Marine Nicolas\Desktop\AD-R.lnk . (...) -- C:\Program Files\Ad-Remover\main.exe
    O4 - Global Startup: C:\Users\Marine Nicolas\Desktop\Audacity.lnk . (...) -- C:\Program Files\Audacity\audacity.exe
    O4 - Global Startup: C:\Users\Marine Nicolas\Desktop\FrostWire 4.20.6.lnk . (.FrostWire Group.) -- C:\Program Files\FrostWire\FrostWire.exe
    O4 - Global Startup: C:\Users\Marine Nicolas\Desktop\Guitar Pro 4.lnk . (.Arobas Music.) -- C:\Program Files\Guitar Pro 4\GP4.exe
    O4 - Global Startup: C:\Users\Marine Nicolas\Desktop\HijackThis.lnk . (.Trend Micro Inc..) -- C:\Program Files\HijackThis.exe
    O4 - Global Startup: C:\Users\Marine Nicolas\Desktop\HP Deskjet F2200 series - Raccourci.lnk - Clé orpheline
    O4 - Global Startup: C:\Users\Marine Nicolas\Desktop\OpenOffice.org 2.1.lnk . (...) -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenOffice.org 2.1
    O4 - Global Startup: C:\Users\Marine Nicolas\Desktop\Perso Nico (projets - docs) - Raccourci.lnk . (...) -- D:\Perso Nico (projets - docs)
    O4 - Global Startup: C:\Users\Marine Nicolas\Desktop\PhotoFiltre.lnk . (...) -- C:\Program Files\PhotoFiltre\PhotoFiltre.exe
    O4 - Global Startup: C:\Users\Marine Nicolas\Desktop\Travail Nico - Raccourci.lnk . (...) -- D:\Travail Nico
    O4 - Global Startup: C:\Users\Marine Nicolas\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\FrostWire 4.20.6.lnk . (.FrostWire Group.) -- C:\Program Files\FrostWire\FrostWire.exe
    O4 - Global Startup: C:\Users\Marine Nicolas\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk . (.Microsoft Corporation.) -- C:\Program Files\Internet Explorer\iexplore.exe

    ---\\ Winsock hijacker (Layered Service Provider) (O10)
    O10 - WLSP:\000000000001\Winsock LSP File . (.Microsoft Corporation - Network Location Awareness 2.) -- C:\Windows\system32\NLAapi.dll
    O10 - WLSP:\000000000002\Winsock LSP File . (.Microsoft Corporation - Fournisseur de service Sockets 2.0 de Microsoft Windows.) -- C:\Windows\system32\mswsock.dll
    O10 - WLSP:\000000000003\Winsock LSP File . (.Microsoft Corporation - LDAP RnR Provider DLL.) -- C:\Windows\system32\winrnr.dll
    O10 - WLSP:\000000000004\Winsock LSP File . (.Microsoft Corporation - Fournisseur Shim d'affectation de noms de messagerie.) -- C:\Windows\system32\napinsp.dll
    O10 - WLSP:\000000000005\Winsock LSP File . (.Microsoft Corporation - Fournisseur d'espace de noms PNRP.) -- C:\Windows\system32\pnrpnsp.dll
    O10 - WLSP:\000000000006\Winsock LSP File . (.Microsoft Corporation - Fournisseur d'espace de noms PNRP.) -- C:\Windows\system32\pnrpnsp.dll
    O10 - WLSP:\000000000007\Winsock LSP File . (.Microsoft Corp. - Microsoft® Windows Live ID Namespace Provider.) -- C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL
    O10 - WLSP:\000000000008\Winsock LSP File . (.Microsoft Corp. - Microsoft® Windows Live ID Namespace Provider.) -- C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL
    O10 - WLSP:\000000000009\Winsock LSP File . (.Apple Inc. - Bonjour Namespace Provider.) -- C:\Program Files\Bonjour\mdnsNSP.dll

    ---\\ Objets ActiveX (Downloaded Program Files)(O16)
    O16 - DPF: {04CB5B64-5915-4629-B869-8945CEBADD21} (Module de délivrance de certificat MINEFI) - https://static.impots.gouv.fr/abos/static/securite/certdgi1.cab
    O16 - DPF: {05D96F71-87C6-11D3-9BE4-00902742D6E0} (QuickPlace Class) - http://dida.univ-tln.fr/qp2.cab
    O16 - DPF: {140E4DF8-9E14-4A34-9577-C77561ED7883} (SysInfo Class) - http://content.systemrequirementslab.com.s3.amazonaws.com/...
    O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
    O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
    O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} () - http://fichiers.touslesdrivers.com/maconfig/MaConfig_4_0_2_0.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} (Windows Live Hotmail Photo Upload Tool) - http://gfx2.hotmail.com/mail/w4/pr01/photouploadcontrol/VistaMSNPUpldfr-fr.cab

    ---\\ Modification Domaine/Adresses DNS (O17)
    O17 - HKLM\System\CCS\Services\Tcpip\..\{85562CE7-8E24-4017-952D-AAC9B260006D}: DhcpNameServer = 192.168.1.1
    O17 - HKLM\System\CS1\Services\Tcpip\..\{85562CE7-8E24-4017-952D-AAC9B260006D}: DhcpNameServer = 192.168.1.1
    O17 - HKLM\System\CS2\Services\Tcpip\..\{85562CE7-8E24-4017-952D-AAC9B260006D}: DhcpNameServer = 192.168.1.1
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1

    ---\\ Clé de Registre autorun ShellServiceObjectDelayLoad (SSO/SSODL) (O21)
    O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.

    ---\\ Liste des services NT non Microsoft et non désactivés (O23)
    O23 - Service: C:\Windows\system32\Alg.exe (AMD External Events Utility) . (.AMD - AMD External Events Service Module.) - C:\Windows\system32\atiesrxx.exe
    O23 - Service: (AntiVirSchedulerService) . (.Avira GmbH - Antivirus Scheduler.) - C:\Program Files\Avira\AntiVir Desktop\sched.exe
    O23 - Service: (AntiVirService) . (.Avira GmbH - Antivirus On-Access Service.) - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
    O23 - Service: (Apple Mobile Device) . (.Apple Inc. - MobileDeviceService.) - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    O23 - Service: (avast! Antivirus) . (.AVAST Software - avast! Service.) - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
    O23 - Service: (avast! Mail Scanner) . (.AVAST Software - avast! Service.) - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
    O23 - Service: (avast! Web Scanner) . (.AVAST Software - avast! Service.) - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
    O23 - Service: (Bonjour Service) . (.Apple Inc. - Bonjour Service.) - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: (iPod Service) . (.Apple Inc. - iPodService Module (32-bit).) - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: (wlidsvc) . (.Microsoft Corp. - Microsoft® Windows Live ID Service.) - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.exe

    ---\\ Enumération Active Desktop & MHTML Editor (O24)
    O24 - Default MHTML Editor: Last - .(...) - (.not file.)

    ---\\ Tâches planifiées en automatique (O39)
    [MD5.187E0D2AB859AD03393DDD731076BE81] [APT] [AppleSoftwareUpdate] (.Apple Inc..) -- C:\Program Files\Apple Software Update\SoftwareUpdate.exe

    ---\\ Pilotes lancés au démarrage (O41)
    O41 - Driver: C:\Windows\system32\drivers\afd.sys (AFD) . (.Microsoft Corporation - Ancillary Function Driver for WinSock.) - C:\Windows\system32\drivers\afd.sys
    O41 - Driver: (avipbb) . (.Avira GmbH - Avira Driver for Security Enhancement.) - C:\Windows\System32\DRIVERS\avipbb.sys
    O41 - Driver: (blbdrive) . (.Microsoft Corporation - BLB Drive Driver.) - C:\Windows\System32\DRIVERS\blbdrive.sys
    O41 - Driver: (cdrom) . (.Microsoft Corporation - SCSI CD-ROM Driver.) - C:\Windows\System32\DRIVERS\cdrom.sys
    O41 - Driver: C:\Windows\system32\drivers\dfsc.sys (DfsC) . (.Microsoft Corporation - DFS Namespace Client Driver.) - C:\Windows\System32\Drivers\dfsc.sys
    O41 - Driver: C:\Windows\system32\drivers\discache.sys (discache) . (.Microsoft Corporation - System Indexer/Cache Driver.) - C:\Windows\System32\drivers\discache.sys
    O41 - Driver: (mssmbios) . (.Microsoft Corporation - System Management BIOS Driver.) - C:\Windows\System32\DRIVERS\mssmbios.sys
    O41 - Driver: (NetBIOS) . (.Microsoft Corporation - NetBIOS interface driver.) - C:\Windows\System32\DRIVERS\netbios.sys
    O41 - Driver: C:\Windows\system32\drivers\netbt.sys (NetBT) . (.Microsoft Corporation - MBT Transport driver.) - C:\Windows\System32\DRIVERS\netbt.sys
    O41 - Driver: C:\Windows\system32\drivers\nsiproxy.sys (nsiproxy) . (.Microsoft Corporation - NSI Proxy.) - C:\Windows\System32\drivers\nsiproxy.sys
    O41 - Driver: C:\Windows\system32\drivers\pacer.sys (Psched) . (.Microsoft Corporation - Planificateur de paquets QoS.) - C:\Windows\System32\DRIVERS\pacer.sys
    O41 - Driver: C:\Windows\system32\wkssvc.dll (rdbss) . (.Microsoft Corporation - Pilote du sous-système de mise en mémoire t.) - C:\Windows\System32\DRIVERS\rdbss.sys
    O41 - Driver: C:\Windows\system32\DRIVERS\RDPCDD.sys (RDPCDD) . (.Microsoft Corporation - RDP Miniport.) - C:\Windows\System32\DRIVERS\RDPCDD.sys
    O41 - Driver: C:\Windows\system32\drivers\RDPENCDD.sys (RDPENCDD) . (.Microsoft Corporation - RDP Encoder Miniport.) - C:\Windows\System32\drivers\rdpencdd.sys
    O41 - Driver: C:\Windows\system32\drivers\RdpRefMp.sys (RDPREFMP) . (.Microsoft Corporation - RDP Reflector Driver Miniport.) - C:\Windows\System32\drivers\rdprefmp.sys
    O41 - Driver: (Serial) . (.Microsoft Corporation - Pilote de périphérique série.) - C:\Windows\System32\DRIVERS\serial.sys
    O41 - Driver: (ssmdrv) . (.Avira GmbH - AVIRA SnapShot Driver.) - C:\Windows\System32\DRIVERS\ssmdrv.sys
    O41 - Driver: C:\Windows\system32\tcpipcfg.dll (tdx) . (.Microsoft Corporation - TDI Translation Driver.) - C:\Windows\System32\DRIVERS\tdx.sys
    O41 - Driver: (TermDD) . (.Microsoft Corporation - Remote Desktop Server Driver.) - C:\Windows\System32\DRIVERS\termdd.sys
    O41 - Driver: (VgaSave) . (.Microsoft Corporation - VGA/Super VGA Video Driver.) - C:\Windows\system32\drivers\vga.sys
    O41 - Driver: C:\Windows\system32\rascfg.dll (Wanarpv6) . (.Microsoft Corporation - MS Remote Access and Routing ARP Driver.) - C:\Windows\System32\DRIVERS\wanarp.sys
    O41 - Driver: (WfpLwf) . (.Microsoft Corporation - WFP NDIS 6.20 Lightweight Filter Driver.) - C:\Windows\System32\DRIVERS\wfplwf.sys

    ---\\ Logiciels installés (O42)
    O42 - Logiciel: ATI Catalyst Install Manager - (.ATI Technologies, Inc..) [HKLM] -- {862AE7BF-8809-5D85-AC45-6E640936B4C8}
    O42 - Logiciel: Adobe Flash Player 10 ActiveX - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player ActiveX
    O42 - Logiciel: Adobe Reader 9.4.1 - Français - (.Adobe Systems Incorporated.) [HKLM] -- {AC76BA86-7AD7-1036-7B44-A94000000001}
    O42 - Logiciel: Amazon MP3 Downloader 1.0.9 - (.Pas de propriétaire.) [HKLM] -- Amazon MP3 Downloader
    O42 - Logiciel: Apple Application Support - (.Apple Inc..) [HKLM] -- {EE6097DD-05F4-4178-9719-D3170BF098E8}
    O42 - Logiciel: Apple Mobile Device Support - (.Apple Inc..) [HKLM] -- {5BF5F9C5-E95B-4AFA-94BE-F2A9CA73B61D}
    O42 - Logiciel: Apple Software Update - (.Apple Inc..) [HKLM] -- {C41300B9-185D-475E-BFEC-39EF732F19B1}
    O42 - Logiciel: Audacity 1.2.4 - (.Pas de propriétaire.) [HKLM] -- Audacity_is1
    O42 - Logiciel: Avira AntiVir Personal - Free Antivirus - (.Avira GmbH.) [HKLM] -- Avira AntiVir Desktop
    O42 - Logiciel: BioShock - (.2K Games.) [HKLM] -- {E280923D-C5D9-4728-8C79-AC9A0DC75875}
    O42 - Logiciel: Bonjour - (.Apple Inc..) [HKLM] -- {2A981294-F14C-4F0F-9627-D793270922F8}
    O42 - Logiciel: Catalyst Control Center - Branding - (.ATI.) [HKLM] -- {8D7133DE-27D2-47E5-B248-4180278D32AA}
    O42 - Logiciel: Complément Microsoft Enregistrer en tant que PDF ou XPS pour programmes Microsoft Office 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-00B2-040C-0000-0000000FF1CE}
    O42 - Logiciel: Creative Live! Cam Vista IM Driver (1.01.03.1104) - (.Pas de propriétaire.) [HKLM] -- Creative VF0260
    O42 - Logiciel: Creative Software AutoUpdate - (.Pas de propriétaire.) [HKLM] -- Creative Software AutoUpdate
    O42 - Logiciel: Creative System Information - (.Pas de propriétaire.) [HKLM] -- SysInfo
    O42 - Logiciel: Creative WebCam Center - (.Pas de propriétaire.) [HKLM] -- Creative WebCam Center
    O42 - Logiciel: Crossword Compiler Français 8 Démo - (.Pas de propriétaire.) [HKLM] -- Crossword Compiler Français 8 Démo
    O42 - Logiciel: D3DX10 - (.Microsoft.) [HKLM] -- {E09C4DB7-630C-4F06-A631-8EA7239923AF}
    O42 - Logiciel: DivX Plus Web Player - (.DivX,Inc..) [HKLM] -- {B7050CBDB2504B34BC2A9CA0A692CC29}
    O42 - Logiciel: FrostWire 4.20.6 - (.FrostWire, LLC.) [HKLM] -- FrostWire
    O42 - Logiciel: Guitar Pro 4 - (.Arobas Music.) [HKLM] -- {491CED7A-0F13-4BE6-957A-59DCA69E8271}
    O42 - Logiciel: Java(TM) 6 Update 23 - (.Sun Microsystems, Inc..) [HKLM] -- {26A24AE4-039D-4CA4-87B4-2F83216020FF}
    O42 - Logiciel: Junk Mail filter update - (.Microsoft Corporation.) [HKLM] -- {1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}
    O42 - Logiciel: Logiciel d'archivage WinRAR - (.Pas de propriétaire.) [HKLM] -- WinRAR archiver
    O42 - Logiciel: MSVCRT - (.Microsoft.) [HKLM] -- {8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}
    O42 - Logiciel: Malwarebytes' Anti-Malware - (.Malwarebytes Corporation.) [HKLM] -- Malwarebytes' Anti-Malware_is1
    O42 - Logiciel: Manuel d'utilisation de Creative Live! Cam Vista IM (Français) - (.Pas de propriétaire.) [HKLM] -- Manuel d'utilisation de Creative Live! Cam Vista IM French
    O42 - Logiciel: Microsoft .NET Framework 1.1 - (.Microsoft.) [HKLM] -- {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
    O42 - Logiciel: Microsoft .NET Framework 4 Client Profile - (.Microsoft Corporation.) [HKLM] -- Microsoft .NET Framework 4 Client Profile
    O42 - Logiciel: Microsoft .NET Framework 4 Client Profile - (.Microsoft Corporation.) [HKLM] -- {3C3901C5-3455-3E0A-A214-0B093A5070A6}
    O42 - Logiciel: Microsoft Silverlight - (.Microsoft Corporation.) [HKLM] -- {89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
    O42 - Logiciel: Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 - (.Microsoft Corporation.) [HKLM] -- {770657D0-A123-3C07-8E44-1C83EC895118}
    O42 - Logiciel: Microsoft Visual C++ 2005 Redistributable - (.Microsoft Corporation.) [HKLM] -- {7299052b-02a4-4627-81f2-1818da5d550d}
    O42 - Logiciel: Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 - (.Microsoft Corporation.) [HKLM] -- {1F1C2DFC-2D24-3E06-BCB8-725134ADF989}
    O42 - Logiciel: Oblivion - (.Bethesda Softworks.) [HKLM] -- {35CB6715-41F8-4F99-8881-6FC75BF054B0}
    O42 - Logiciel: OpenOffice.org 2.1 - (.OpenOffice.org.) [HKLM] -- {E5430A11-6799-41E0-A9D5-F68BDC67AAD8}
    O42 - Logiciel: QuickTime - (.Apple Inc..) [HKLM] -- {57752979-A1C9-4C02-856B-FBB27AC4E02C}
    O42 - Logiciel: Realtek AC'97 Audio - (.Pas de propriétaire.) [HKLM] -- {FB08F381-6533-4108-B7DD-039E11FBC27E}
    O42 - Logiciel: System Requirements Lab - (.Husdawg, LLC.) [HKLM] -- {9E1BAB75-EB78-440D-94C0-A3857BE2E733}
    O42 - Logiciel: VC80CRTRedist - 8.0.50727.4053 - (.DivX, Inc.) [HKLM] -- {5EE7D259-D137-4438-9A5F-42F432EC0421}
    O42 - Logiciel: VoiceOver Kit - (.Apple Inc..) [HKLM] -- {7C5B4583-7CBF-4289-B195-03B553959DEA}
    O42 - Logiciel: Windows Live - (.Microsoft Corporation.) [HKLM] -- WinLiveSuite
    O42 - Logiciel: Windows Live - (.Microsoft Corporation.) [HKLM] -- {34319F1F-7CF2-4CC9-B357-1AE7D2FF3AC5}
    O42 - Logiciel: Windows Live Communications Platform - (.Microsoft Corporation.) [HKLM] -- {D45240D3-B6B3-4FF9-B243-54ECE3E10066}
    O42 - Logiciel: Windows Live ID Sign-in Assistant - (.Microsoft Corporation.) [HKLM] -- {61AD15B2-50DB-4686-A739-14FE180D4429}
    O42 - Logiciel: Windows Live Installer - (.Microsoft Corporation.) [HKLM] -- {0B0F231F-CE6A-483D-AA23-77B364F75917}
    O42 - Logiciel: Windows Live MIME IFilter - (.Microsoft Corporation.) [HKLM] -- {AF844339-2F8A-4593-81B3-9F4C54038C4E}
    O42 - Logiciel: Windows Live Mail - (.Microsoft Corporation.) [HKLM] -- {9D56775A-93F3-44A3-8092-840E3826DE30}
    O42 - Logiciel: Windows Live Mail - (.Microsoft Corporation.) [HKLM] -- {9FAE6E8D-E686-49F5-A574-0A58DFD9580C}
    O42 - Logiciel: Windows Live Messenger - (.Microsoft Corporation.) [HKLM] -- {6057E21C-ABE9-4059-AE3E-3BEB9925E660}
    O42 - Logiciel: Windows Live Messenger - (.Microsoft Corporation.) [HKLM] -- {EB4DF488-AAEF-406F-A341-CB2AAA315B90}
    O42 - Logiciel: Windows Live PIMT Platform - (.Microsoft Corporation.) [HKLM] -- {4CBABDFD-49F8-47FD-BE7D-ECDE7270525A}
    O42 - Logiciel: Windows Live Photo Common - (.Microsoft Corporation.) [HKLM] -- {A9BDCA6B-3653-467B-AC83-94367DA3BFE3}
    O42 - Logiciel: Windows Live Photo Common - (.Microsoft Corporation.) [HKLM] -- {C893D8C0-1BA0-4517-B11C-E89B65E72F70}
    O42 - Logiciel: Windows Live SOXE - (.Microsoft Corporation.) [HKLM] -- {682B3E4F-696A-42DE-A41C-4C07EA1678B4}
    O42 - Logiciel: Windows Live SOXE Definitions - (.Microsoft Corporation.) [HKLM] -- {200FEC62-3C34-4D60-9CE8-EC372E01C08F}
    O42 - Logiciel: Windows Live UX Platform - (.Microsoft Corporation.) [HKLM] -- {CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}
    O42 - Logiciel: Windows Live UX Platform Language Pack - (.Microsoft Corporation.) [HKLM] -- {09F56A49-A7B1-4AAB-95B9-D13094254AD1}
    O42 - Logiciel: Windows Live Writer - (.Microsoft Corporation.) [HKLM] -- {AAAFC670-569B-4A2F-82B4-42945E0DE3EF}
    O42 - Logiciel: Windows Live Writer Resources - (.Microsoft Corporation.) [HKLM] -- {62687B11-58B5-4A18-9BC3-9DF4CE03F194}
    O42 - Logiciel: Windows Media Encoder 9 Series - (.Microsoft Corporation.) [HKLM] -- {E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}
    O42 - Logiciel: Windows Media Encoder 9 Series - (.Pas de propriétaire.) [HKLM] -- Windows Media Encoder 9
    O42 - Logiciel: avast! Free Antivirus - (.Alwil Software.) [HKLM] -- avast5
    O42 - Logiciel: iTunes - (.Apple Inc..) [HKLM] -- {AAD47011-8518-4608-9656-951DA35B587B}

    ---\\ HKCU & HKLM Software Keys
    [HKCU\Software\ALWIL Software]
    [HKCU\Software\ATI]
    [HKCU\Software\Ad-Remover]
    [HKCU\Software\Adobe]
    [HKCU\Software\AppDataLow\Software\Microsoft]
    [HKCU\Software\AppDataLow\Software]
    [HKCU\Software\AppDataLow]
    [HKCU\Software\Apple Computer, Inc.]
    [HKCU\Software\Apple Inc.]
    [HKCU\Software\Audacity]
    [HKCU\Software\Aurigma]
    [HKCU\Software\Avira]
    [HKCU\Software\Classes]
    [HKCU\Software\Clients]
    [HKCU\Software\Creative Tech]
    [HKCU\Software\DivXNetworks]
    [HKCU\Software\Hewlett-Packard]
    [HKCU\Software\IM Providers]
    [HKCU\Software\JavaSoft]
    [HKCU\Software\Macromedia]
    [HKCU\Software\Magnet]
    [HKCU\Software\Malwarebytes' Anti-Malware]
    [HKCU\Software\Netscape]
    [HKCU\Software\Opendisc]
    [HKCU\Software\Policies]
    [HKCU\Software\Realtek]
    [HKCU\Software\SecuROM]
    [HKCU\Software\System Requirements Lab]
    [HKCU\Software\WinRAR SFX]
    [HKCU\Software\WinRAR]
    [HKCU\Software\YahooPartnerToolbar]
    [HKLM\Software\2K Games]
    [HKLM\Software\ALWIL Software]
    [HKLM\Software\AMD]
    [HKLM\Software\ATI Technologies]
    [HKLM\Software\ATI]
    [HKLM\Software\Adobe]
    [HKLM\Software\Amazon]
    [HKLM\Software\Apple Computer, Inc.]
    [HKLM\Software\Apple Inc.]
    [HKLM\Software\Avira]
    [HKLM\Software\Bethesda Softworks]
    [HKLM\Software\BrowserChoice]
    [HKLM\Software\Classes]
    [HKLM\Software\Clients]
    [HKLM\Software\Creative Tech]
    [HKLM\Software\DivXNetworks]
    [HKLM\Software\GEAR Software]
    [HKLM\Software\Google]
    [HKLM\Software\Hewlett-Packard]
    [HKLM\Software\Intel]
    [HKLM\Software\JavaSoft]
    [HKLM\Software\JreMetrics]
    [HKLM\Software\Macromedia]
    [HKLM\Software\Malwarebytes' Anti-Malware]
    [HKLM\Software\MozillaPlugins]
    [HKLM\Software\ODBC]
    [HKLM\Software\OpenOffice.org]
    [HKLM\Software\Policies]
    [HKLM\Software\Realtek]
    [HKLM\Software\RegisteredApplications]
    [HKLM\Software\SRS Labs]
    [HKLM\Software\Sonic]
    [HKLM\Software\Sun Microsystems]
    [HKLM\Software\TrendMicro]
    [HKLM\Software\Volatile]
    [HKLM\Software\WinRAR]
    [HKLM\Software\Windows]
    [HKLM\Software\X-AVCSD]

    ---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43)
    O43 - CFD: 25/02/2010 - 22:57:24 - [6442409421] ----D- C:\Program Files\2K Games
    O43 - CFD: 12/04/2011 - 19:18:10 - [2826016] ----D- C:\Program Files\Ad-Remover
    O43 - CFD: 18/10/2010 - 18:21:52 - [162146313] ----D- C:\Program Files\Adobe
    O43 - CFD: 17/02/2010 - 23:53:04 - [143165471] ----D- C:\Program Files\Alwil Software
    O43 - CFD: 04/02/2011 - 19:50:44 - [2662080] ----D- C:\Program Files\Amazon
    O43 - CFD: 02/02/2011 - 21:50:42 - [2306366] ----D- C:\Program Files\Apple Software Update
    O43 - CFD: 25/02/2010 - 16:41:44 - [17067651] ----D- C:\Program Files\ATI
    O43 - CFD: 25/02/2010 - 16:44:36 - [69728485] ----D- C:\Program Files\ATI Technologies
    O43 - CFD: 23/01/2011 - 17:04:34 - [9457722] ----D- C:\Program Files\Audacity
    O43 - CFD: 12/04/2011 - 11:35:22 - [112832404] ----D- C:\Program Files\Avira
    O43 - CFD: 18/03/2010 - 21:05:18 - [9405169725] ----D- C:\Program Files\Bethesda Softworks
    O43 - CFD: 02/02/2011 - 21:49:58 - [617126] ----D- C:\Program Files\Bonjour
    O43 - CFD: 02/02/2011 - 21:49:40 - [446835814] ----D- C:\Program Files\Common Files
    O43 - CFD: 27/12/2010 - 16:23:12 - [18048238] ----D- C:\Program Files\Creative
    O43 - CFD: 12/03/2010 - 14:31:58 - [10965956] ----D- C:\Program Files\DivX
    O43 - CFD: 14/07/2009 - 11:01:10 - [83226132] ----D- C:\Program Files\DVD Maker
    O43 - CFD: 17/02/2010 - 23:24:04 - [0] -SH-D- C:\Program Files\Fichiers communs
    O43 - CFD: 06/05/2010 - 14:11:44 - [39193610] ----D- C:\Program Files\FrostWire
    O43 - CFD: 20/02/2010 - 16:38:02 - [8438993] ----D- C:\Program Files\Guitar Pro 4
    O43 - CFD: 27/12/2010 - 16:23:30 - [59903636] --H-D- C:\Program Files\InstallShield Installation Information
    O43 - CFD: 09/02/2011 - 12:51:16 - [5635865] ----D- C:\Program Files\Internet Explorer
    O43 - CFD: 02/02/2011 - 21:53:22 - [1856115] ----D- C:\Program Files\iPod
    O43 - CFD: 02/02/2011 - 22:23:14 - [172205068] ----D- C:\Program Files\iTunes
    O43 - CFD: 02/01/2011 - 19:19:42 - [91724743] ----D- C:\Program Files\Java
    O43 - CFD: 25/02/2010 - 16:52:52 - [1109] ----D- C:\Program Files\ma-config.com
    O43 - CFD: 12/04/2011 - 15:15:28 - [4920396] ----D- C:\Program Files\Malwarebytes' Anti-Malware
    O43 - CFD: 14/07/2009 - 11:01:00 - [147812402] ----D- C:\Program Files\Microsoft Games
    O43 - CFD: 08/03/2011 - 23:58:44 - [38371963] ----D- C:\Program Files\Microsoft Silverlight
    O43 - CFD: 25/06/2010 - 11:30:38 - [15715] ----D- C:\Program Files\Microsoft.NET
    O43 - CFD: 14/07/2009 - 06:52:32 - [25757] ----D- C:\Program Files\MSBuild
    O43 - CFD: 01/10/2010 - 15:13:36 - [1528435] ----D- C:\Program Files\MSECache
    O43 - CFD: 19/02/2010 - 11:41:12 - [263849536] ----D- C:\Program Files\OpenOffice.org 2.1
    O43 - CFD: 19/02/2010 - 11:54:48 - [29197239] ----D- C:\Program Files\PhotoFiltre
    O43 - CFD: 02/02/2011 - 21:51:44 - [76322555] ----D- C:\Program Files\QuickTime
    O43 - CFD: 14/07/2009 - 06:52:32 - [38597377] ----D- C:\Program Files\Reference Assemblies
    O43 - CFD: 07/03/2010 - 16:31:36 - [653432] ----D- C:\Program Files\SystemRequirementsLab
    O43 - CFD: 18/02/2010 - 16:29:40 - [2242808401] ----D- C:\Program Files\THQ
    O43 - CFD: 14/07/2009 - 06:53:24 - [0] --H-D- C:\Program Files\Uninstall Information
    O43 - CFD: 14/07/2009 - 10:39:40 - [3049984] ----D- C:\Program Files\Windows Defender
    O43 - CFD: 14/07/2009 - 11:01:08 - [7013496] ----D- C:\Program Files\Windows Journal
    O43 - CFD: 30/03/2011 - 10:02:00 - [93552181] ----D- C:\Program Files\Windows Live
    O43 - CFD: 15/12/2010 - 20:55:30 - [6180864] ----D- C:\Program Files\Windows Mail
    O43 - CFD: 27/12/2010 - 12:51:10 - [14028939] ----D- C:\Program Files\Windows Media Components
    O43 - CFD: 16/10/2010 - 15:57:26 - [6607787] ----D- C:\Program Files\Windows Media Player
    O43 - CFD: 17/02/2010 - 23:24:04 - [12197556] ----D- C:\Program Files\Windows NT
    O43 - CFD: 14/07/2009 - 10:39:40 - [4417800] ----D- C:\Program Files\Windows Photo Viewer
    O43 - CFD: 14/07/2009 - 06:52:34 - [189440] ----D- C:\Program Files\Windows Portable Devices
    O43 - CFD: 14/07/2009 - 10:39:40 - [6683295] ----D- C:\Program Files\Windows Sidebar
    O43 - CFD: 20/02/2010 - 18:40:04 - [3882468] ----D- C:\Program Files\WinRAR
    O43 - CFD: 12/04/2011 - 19:50:50 - [3894554] ----D- C:\Program Files\ZHPDiag
    O43 - CFD: 18/10/2010 - 18:22:00 - [6281214] ----D- C:\Program Files\Common Files\Adobe
    O43 - CFD: 02/02/2011 - 21:53:20 - [94755456] ----D- C:\Program Files\Common Files\Apple
    O43 - CFD: 12/03/2010 - 14:31:34 - [1619968] ----D- C:\Program Files\Common Files\DivX Shared
    O43 - CFD: 18/02/2010 - 16:28:00 - [6980367] ----D- C:\Program Files\Common Files\InstallShield
    O43 - CFD: 18/08/2010 - 12:33:36 - [1243079] ----D- C:\Program Files\Common Files\Java
    O43 - CFD: 04/11/2010 - 18:49:02 - [56156814] ----D- C:\Program Files\Common Files\microsoft shared
    O43 - CFD: 14/07/2009 - 04:37:06 - [2702] ----D- C:\Program Files\Common Files\Services
    O43 - CFD: 14/07/2009 - 04:37:06 - [41103783] ----D- C:\Program Files\Common Files\SpeechEngines
    O43 - CFD: 14/07/2009 - 10:39:40 - [10102259] ----D- C:\Program Files\Common Files\System
    O43 - CFD: 17/02/2010 - 23:31:34 - [228590172] ----D- C:\Program Files\Common Files\Windows Live
    O43 - CFD: 18/10/2010 - 18:22:00 - [763] ----D- C:\ProgramData\Adobe
    O43 - CFD: 20/03/2010 - 13:07:56 - [23394490] ----D- C:\ProgramData\Alwil Software
    O43 - CFD: 02/02/2011 - 21:49:40 - [63009280] ----D- C:\ProgramData\Apple
    O43 - CFD: 02/02/2011 - 21:53:20 - [67383921] ----D- C:\ProgramData\Apple Computer
    O43 - CFD: 14/07/2009 - 06:53:56 - [0] -SH-D- C:\ProgramData\Application Data
    O43 - CFD: 25/02/2010 - 16:47:04 - [188] ----D- C:\ProgramData\ATI
    O43 - CFD: 12/04/2011 - 11:35:22 - [80619347] ----D- C:\ProgramData\Avira
    O43 - CFD: 17/02/2010 - 23:24:04 - [0] -SH-D- C:\ProgramData\Bureau
    O43 - CFD: 14/07/2009 - 06:53:56 - [0] -SH-D- C:\ProgramData\Desktop
    O43 - CFD: 14/07/2009 - 06:53:56 - [0] -SH-D- C:\ProgramData\Documents
    O43 - CFD: 17/02/2010 - 23:24:04 - [0] -SH-D- C:\ProgramData\Favoris
    O43 - CFD: 14/07/2009 - 06:53:56 - [0] -SH-D- C:\ProgramData\Favorites
    O43 - CFD: 19/02/2010 - 11:16:54 - [23289] ----D- C:\ProgramData\Hewlett-Packard
    O43 - CFD: 25/02/2010 - 16:52:52 - [15518] ----D- C:\ProgramData\ma-config.com
    O43 - CFD: 12/04/2011 - 15:15:24 - [6534710] ----D- C:\ProgramData\Malwarebytes
    O43 - CFD: 25/02/2010 - 23:09:26 - [1353] ----D- C:\ProgramData\Media Center Programs
    O43 - CFD: 17/02/2010 - 23:24:04 - [0] -SH-D- C:\ProgramData\Menu Démarrer
    O43 - CFD: 04/11/2010 - 18:49:46 - [323922315] -S--D- C:\ProgramData\Microsoft
    O43 - CFD: 17/02/2010 - 23:24:04 - [0] -SH-D- C:\ProgramData\Modèles
    O43 - CFD: 14/07/2009 - 06:53:56 - [0] -SH-D- C:\ProgramData\Start Menu
    O43 - CFD: 06/05/2010 - 14:09:40 - [224] ----D- C:\ProgramData\Sun
    O43 - CFD: 14/07/2009 - 06:53:56 - [0] -SH-D- C:\ProgramData\Templates
    O43 - CFD: 21/02/2010 - 15:50:20 - [3762264] ----D- C:\Users\Marine Nicolas\AppData\Roaming\Adobe
    O43 - CFD: 04/02/2011 - 20:00:26 - [9925] ----D- C:\Users\Marine Nicolas\AppData\Roaming\Amazon
    O43 - CFD: 02/02/2011 - 22:12:38 - [2028409] ----D- C:\Users\Marine Nicolas\AppData\Roaming\Apple Computer
    O43 - CFD: 25/02/2010 - 16:47:04 - [0] ----D- C:\Users\Marine Nicolas\AppData\Roaming\ATI
    O43 - CFD: 12/04/2011 - 19:21:10 - [0] ----D- C:\Users\Marine Nicolas\AppData\Roaming\Avira
    O43 - CFD: 06/04/2010 - 13:54:46 - [997090] ----D- C:\Users\Marine Nicolas\AppData\Roaming\Bioshock
    O43 - CFD: 27/12/2010 - 16:27:10 - [1228] ----D- C:\Users\Marine Nicolas\AppData\Roaming\Creative
    O43 - CFD: 18/03/2010 - 21:10:32 - [0] ----D- C:\Users\Marine Nicolas\AppData\Roaming\Crossword Compiler Français 8
    O43 - CFD: 07/04/2011 - 18:51:14 - [24864169] ----D- C:\Users\Marine Nicolas\AppData\Roaming\FrostWire
    O43 - CFD: 17/02/2010 - 23:24:36 - [0] ----D- C:\Users\Marine Nicolas\AppData\Roaming\Identities
    O43 - CFD: 25/02/2010 - 22:10:34 - [0] ----D- C:\Users\Marine Nicolas\AppData\Roaming\InstallShield
    O43 - CFD: 18/02/2010 - 11:57:50 - [112183] ----D- C:\Users\Marine Nicolas\AppData\Roaming\Macromedia
    O43 - CFD: 12/04/2011 - 15:15:48 - [7867569] ----D- C:\Users\Marine Nicolas\AppData\Roaming\Malwarebytes
    O43 - CFD: 14/07/2009 - 11:00:24 - [0] ----D- C:\Users\Marine Nicolas\AppData\Roaming\Media Center Programs
    O43 - CFD: 27/12/2010 - 16:52:52 - [28050365] -S--D- C:\Users\Marine Nicolas\AppData\Roaming\Microsoft
    O43 - CFD: 12/04/2011 - 19:16:12 - [9086677] ----D- C:\Users\Marine Nicolas\AppData\Roaming\OpenOffice.org2
    O43 - CFD: 18/02/2010 - 01:51:26 - [16004] R-H-D- C:\Users\Marine Nicolas\AppData\Roaming\SecuROM
    O43 - CFD: 11/12/2010 - 12:55:32 - [0] ----D- C:\Users\Marine Nicolas\AppData\Roaming\Windows Live Writer
    O43 - CFD: 20/02/2010 - 18:42:36 - [12] ----D- C:\Users\Marine Nicolas\AppData\Roaming\WinRAR

    ---\\ Derniers fichiers modifiés ou crées sous Windows et System32 (O44)
    O44 - LFC:[MD5.1CDAED2B4A1C8C13C761A0B5A950AFF6] - 12/04/2011 - 18:24:33 --HA- . (...) -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [13440]
    O44 - LFC:[MD5.1CDAED2B4A1C8C13C761A0B5A950AFF6] - 12/04/2011 - 18:24:33 --HA- . (...) -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [13440]
    O44 - LFC:[MD5.120000000000000000000000FCEF1200] - 12/04/2011 - 18:22:25 ---A- . (...) -- C:\Windows\WindowsUpdate.log [1230025]
    O44 - LFC:[MD5.8BF94C15EAF04A335CC7490A98065E20] - 12/04/2011 - 18:20:59 ---A- . (...) -- C:\Windows\System32\PerfStringBackup.INI [1566202]
    O44 - LFC:[MD5.905ED9BC860894A22B1D3A3CBB084610] - 12/04/2011 - 18:20:59 ---A- . (...) -- C:\Windows\System32\perfc009.dat [109340]
    O44 - LFC:[MD5.0905F8A1948D81BDABFABC2EE412E9E1] - 12/04/2011 - 18:20:59 ---A- . (...) -- C:\Windows\System32\perfc00C.dat [134420]
    O44 - LFC:[MD5.6A720095245A8C233C62E7DF3D6A5A8C] - 12/04/2011 - 18:20:59 ---A- . (...) -- C:\Windows\System32\perfh009.dat [619902]
    O44 - LFC:[MD5.26447B478EC03B5F0F1A964834DF67F7] - 12/04/2011 - 18:20:59 ---A- . (...) -- C:\Windows\System32\perfh00C.dat [708990]
    O44 - LFC:[MD5.82CE99FCCB8DAE62F45DC025122CB118] - 12/04/2011 - 18:19:31 ---A- . (...) -- C:\Ad-Report-SCAN[1].txt [1560]
    O44 - LFC:[MD5.83712058905D59BEC6AF3141FD199F14] - 12/04/2011 - 18:15:59 ---A- . (...) -- C:\Windows\setupact.log [73697]
    O44 - LFC:[MD5.26DB88F2C79BDB1659485F5F5125412D] - 12/04/2011 - 18:15:51 -S-A- . (...) -- C:\Windows\bootstat.dat [67584]
    O44 - LFC:[MD5.DB5FA08091F420D20DCFAC6235576346] - 12/04/2011 - 18:15:42 ---A- . (...) -- C:\Windows\PFRO.log [3006]
    O44 - LFC:[MD5.E74DC2F3F9675A6025A4AA020EDD4341] - 12/04/2011 - 14:15:25 ---A- . (.Malwarebytes Corporation - Malwarebytes' Anti-Malware.) -- C:\Windows\System32\drivers\mbamswissarmy.sys [38224]
    O44 - LFC:[MD5.9B5CC6C481BDD00A963829B892623247] - 12/04/2011 - 14:15:19 ---A- . (.Malwarebytes Corporation - Malwarebytes' Anti-Malware.) -- C:\Windows\System32\drivers\mbam.sys [20952]
    O44 - LFC:[MD5.E1553B72E964CE32DAC2126DCC7919B6] - 12/04/2011 - 14:10:02 ---A- . (...) -- C:\ZHPExportRegistry-12-04-2011-15-10-02.txt [1562868]
    O44 - LFC:[MD5.4DD50A3D6C08C393E5BDD8903B210177] - 12/04/2011 - 11:53:42 ---A- . (...) -- C:\PhysicalDisk0_MBR.bin [512]
    O44 - LFC:[MD5.A36EE93698802CD899F98BFD553D8185] - 12/04/2011 - 10:35:24 ---A- . (.Avira GmbH - AVIRA SnapShot Driver.) -- C:\Windows\System32\drivers\ssmdrv.sys [28520]
    O44 - LFC:[MD5.DA39805E2BAD99D37FCE9477DD94E7F2] - 12/04/2011 - 10:35:22 ---A- . (.Avira GmbH - Avira Driver for Security Enhancement.) -- C:\Windows\System32\drivers\avipbb.sys [135096]
    O44 - LFC:[MD5.47B879406246FFDCED59E18D331A0E7D] - 12/04/2011 - 10:35:22 ---A- . (.Avira GmbH - Avira Minifilter Driver.) -- C:\Windows\System32\drivers\avgntflt.sys [61960]

    ---\\ Trojan Driver Search Data (HKLM) (O52)
    O52 - TDSD: \Drivers\"MSVideo.V0260VFW"="V0260Vfw.drv" . (.Pas de propriétaire - Pas de description.) -- (.not file.)
    O52 - TDSD: \Drivers32\"VIDC.I420"="msh263.drv" . (.Pas de propriétaire - Pas de description.) -- (.not file.)
    O52 - TDSD: \Drivers32\"msacm.l3acm"="C:\Windows\System32\l3codeca.acm" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Layer-3 Audio Codec for MSACM.) -- C:\Windows\System32\l3codeca.acm
    O52 - TDSD: \Drivers32\"vidc.cvid"="iccvid.dll" . (.Radius Inc. - Codec Cinepak®.) -- C:\Windows\System32\iccvid.dll
    O52 - TDSD: \drivers.desc\"C:\Windows\System32\l3codeca.acm"="Fraunhofer IIS MPEG Layer-3 Codec" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Layer-3 Audio Codec for MSACM.) -- C:\Windows\System32\l3codeca.acm

    ---\\ Microsoft Control Security Providers (O54)
    O54 - MCSP:[HKLM\...\CurrentControlSet\Control] - (SecurityProviders) - (.Microsoft Corporation - Credential Delegation Security Package.) -- C:\Windows\system32\credssp.dll
    O54 - MCSP:[HKLM\...\ControlSet001\Control] - (SecurityProviders) - (.Microsoft Corporation - Credential Delegation Security Package.) -- C:\Windows\system32\credssp.dll

    ---\\ Microsoft Windows Policies System (O55)
    O55 - MWPS:[HKLM\...\Policies\System] - "ConsentPromptBehaviorAdmin"=0
    O55 - MWPS:[HKLM\...\Policies\System] - "ConsentPromptBehaviorUser"=3
    O55 - MWPS:[HKLM\...\Policies\System] - "EnableInstallerDetection"=1
    O55 - MWPS:[HKLM\...\Policies\System] - "EnableLUA"=0
    O55 - MWPS:[HKLM\...\Policies\System] - "EnableSecureUIAPaths"=1
    O55 - MWPS:[HKLM\...\Policies\System] - "EnableUIADesktopToggle"=0
    O55 - MWPS:[HKLM\...\Policies\System] - "EnableVirtualization"=1
    O55 - MWPS:[HKLM\...\Policies\System] - "PromptOnSecureDesktop"=0
    O55 - MWPS:[HKLM\...\Policies\System] - "ValidateAdminCodeSignatures"=0
    O55 - MWPS:[HKLM\...\Policies\System] - "dontdisplaylastusername"=0
    O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticecaption"=
    O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticetext"=
    O55 - MWPS:[HKLM\...\Policies\System] - "scforceoption"=0
    O55 - MWPS:[HKLM\...\Policies\System] - "shutdownwithoutlogon"=1
    O55 - MWPS:[HKLM\...\Policies\System] - "undockwithoutlogon"=1
    O55 - MWPS:[HKLM\...\Policies\System] - "FilterAdministratorToken"=0

    ---\\ Liste des Drivers Système (O58)
    O58 - SDL:[MD5.21E785EBD7DC90A06391141AAC7892FB] - 14/07/2009 - 02:26:15 ---A- . (.Adaptec, Inc. - Adaptec Windows SAS/SATA Storport Driver.) -- C:\Windows\system32\drivers\adp94xx.sys [422976]
    O58 - SDL:[MD5.0C676BC278D5B59FF5ABD57BBE9123F2] - 14/07/2009 - 02:26:17 ---A- . (.Adaptec, Inc. - Adaptec Windows SATA Storport Driver.) -- C:\Windows\system32\drivers\adpahci.sys [297552]
    O58 - SDL:[MD5.7C7B5EE4B7B822EC85321FE23A27DB33] - 14/07/2009 - 02:26:15 ---A- . (.Adaptec, Inc. - Adaptec StorPort Ultra320 SCSI Driver.) -- C:\Windows\system32\drivers\adpu320.sys [146512]
    O58 - SDL:[MD5.0D40BCF52EA90FC7DF2AEAB6503DEA44] - 14/07/2009 - 02:26:15 ---A- . (.Acer Laboratories Inc. - ALi mini IDE Driver.) -- C:\Windows\system32\drivers\aliide.sys [14400]
    O58 - SDL:[MD5.2101A86C25C154F8314B24EF49D7FBC2] - 14/07/2009 - 02:26:15 ---A- . (.Advanced Micro Devices - AHCI 1.2 Device Driver.) -- C:\Windows\system32\drivers\amdsata.sys [79952]
    O58 - SDL:[MD5.EA43AF0C423FF267355F74E7A53BDABA] - 14/07/2009 - 02:26:15 ---A- . (.AMD Technologies Inc. - AMD Technology AHCI Compatible Controller Driver for Windows fa.) -- C:\Windows\system32\drivers\amdsbs.sys [159312]
    O58 - SDL:[MD5.B81C2B5616F6420A9941EA093A92B150] - 14/07/2009 - 02:26:15 ---A- . (.Advanced Micro Devices - Storage Filter Driver.) -- C:\Windows\system32\drivers\amdxata.sys [23616]
    O58 - SDL:[MD5.2932004F49677BD84DBC72EDB754FFB3] - 14/07/2009 - 02:26:15 ---A- . (.Adaptec, Inc. - Adaptec RAID Storport Driver.) -- C:\Windows\system32\drivers\arc.sys [76368]
    O58 - SDL:[MD5.5D6F36C46FD283AE1B57BD2E9FEB0BC7] - 14/07/2009 - 02:26:15 ---A- . (.Adaptec, Inc. - Adaptec SAS RAID WS03 Driver.) -- C:\Windows\system32\drivers\arcsas.sys [86608]
    O58 - SDL:[MD5.0C0B08847F2F24BAA7BD43D8F2C6C8B0] - 28/06/2010 - 21:32:33 ---A- . (.ALWIL Software - avast! File System Access Blocking Driver.) -- C:\Windows\system32\drivers\aswFsBlk.sys [17744]
    O58 - SDL:[MD5.EFFC39A1EDF04E83A42279D9DAA696A7] - 28/06/2010 - 21:32:56 ---A- . (.ALWIL Software - avast! File System Minifilter for Windows 2003/Vista.) -- C:\Windows\system32\drivers\aswMonFlt.sys [50256]
    O58 - SDL:[MD5.F385FFD39165453FDA96736AA3EDFD9D] - 28/06/2010 - 21:33:13 ---A- . (.ALWIL Software - avast! TDI RDR Driver.) -- C:\Windows\system32\drivers\aswRdr.sys [23376]
    O58 - SDL:[MD5.45ADEA26BF613A54FED64ECDD12E58A7] - 28/06/2010 - 21:37:30 ---A- . (.ALWIL Software - avast! self protection module.) -- C:\Windows\system32\drivers\aswSP.sys [165456]
    O58 - SDL:[MD5.C4EE975C87176F1900662D2874233C7F] - 28/06/2010 - 21:37:52 ---A- . (.ALWIL Software - avast! TDI Filter Driver.) -- C:\Windows\system32\drivers\aswTdi.sys [46672]
    O58 - SDL:[MD5.7E00428513C0A668E67A759DC6792A7F] - 03/02/2010 - 05:54:34 ---A- . (.ATI Technologies Inc. - ATI Radeon Kernel Mode Driver.) -- C:\Windows\system32\drivers\atikmdag.sys [5313536]
    O58 - SDL:[MD5.E34E4AA9EC11D89A3228761EE59B5957] - 03/02/2010 - 04:23:42 ---A- . (.Advanced Micro Devices, Inc. - AMD multi-vendor Miniport Driver.) -- C:\Windows\system32\drivers\atikmpag.sys [150016]
    O58 - SDL:[MD5.7E00428513C0A668E67A759DC6792A7F] - 03/02/2010 - 05:54:34 ---A- . (.ATI Technologies Inc. - ATI Radeon Kernel Mode Driver.) -- C:\Windows\system32\drivers\atipmdag.sys [5313536]
    O58 - SDL:[MD5.47B879406246FFDCED59E18D331A0E7D] - 04/02/2011 - 11:09:08 ---A- . (.Avira GmbH - Avira Minifilter Driver.) -- C:\Windows\system32\drivers\avgntflt.sys [61960]
    O58 - SDL:[MD5.DA39805E2BAD99D37FCE9477DD94E7F2] - 04/02/2011 - 11:09:08 ---A- . (.Avira GmbH - Avira Driver for Security Enhancement.) -- C:\Windows\system32\drivers\avipbb.sys [135096]
    O58 - SDL:[MD5.BD8869EB9CDE6BBE4508D869929869EE] - 14/07/2009 - 23:02:49 ---A- . (.Broadcom Corporation - Pilote unifié NDIS6.x Broadcom NetXtreme Gigabit Ethernet..) -- C:\Windows\system32\drivers\b57nd60x.sys [229888]
    O58 - SDL:[MD5.9F9ACC7F7CCDE8A15C282D3F88B43309] - 14/07/2009 - 23:53:28 ---A- . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Lower Filter Driver.) -- C:\Windows\system32\drivers\BrFiltLo.sys [13568]
    O58 - SDL:[MD5.56801AD62213A41F6497F96DEE83755A] - 14/07/2009 - 23:53:28 ---A- . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Upper Filter Driver.) -- C:\Windows\system32\drivers\BrFiltUp.sys [5248]
    O58 - SDL:[MD5.845B8CE732E67F3B4133164868C666EA] - 14/07/2009 - 01:57:25 ---A- . (.Brother Industries Ltd. - Pilote Brother Série I/F (WDM).) -- C:\Windows\system32\drivers\BrSerId.sys [272128]
    O58 - SDL:[MD5.203F0B1E73ADADBBB7B7B1FABD901F6B] - 14/07/2009 - 23:53:32 ---A- . (.Brother Industries Ltd. - Brother Serial driver (WDM version).) -- C:\Windows\system32\drivers\BrSerWdm.sys [62336]
    O58 - SDL:[MD5.BD456606156BA17E60A04E18016AE54B] - 14/07/2009 - 23:53:33 ---A- . (.Brother Industries Ltd. - Brother USB MDM Driver.) -- C:\Windows\system32\drivers\BrUsbMdm.sys [12160]
    O58 - SDL:[MD5.AF72ED54503F717A43268B3CC5FAEC2E] - 14/07/2009 - 23:53:33 ---A- . (.Brother Industries Ltd. - Brother USB Serial Driver.) -- C:\Windows\system32\drivers\BrUsbSer.sys [11904]
    O58 - SDL:[MD5.1A231ABEC60FD316EC54C66715543CEC] - 14/07/2009 - 23:02:48 ---A- . (.Broadcom Corporation - Broadcom NetXtreme II GigE VBD.) -- C:\Windows\system32\drivers\bxvbdx.sys [430080]
    O58 - SDL:[MD5.C537B1DB64D495B9B4717B4D6D9EDBF2] - 14/07/2009 - 02:26:21 ---A- . (.CMD Technology, Inc. - CMD PCI IDE Bus Driver.) -- C:\Windows\system32\drivers\cmdide.sys [15952]
    O58 - SDL:[MD5.8B30250D573A8F6B4BD23195160D8707] - 14/07/2009 - 02:20:28 ---A- . (.Adaptec, Inc. - Adaptec Ultra SCSI miniport.) -- C:\Windows\system32\drivers\djsvs.sys [70720]
    O58 - SDL:[MD5.0ED67910C8C326796FAA00B2BF6D9D3C] - 14/07/2009 - 02:20:28 ---A- . (.Emulex - Storport Miniport Driver for LightPulse HBAs.) -- C:\Windows\system32\drivers\elxstor.sys [453712]
    O58 - SDL:[MD5.024E1B5CAC09731E4D868E64DBFB4AB0] - 14/07/2009 - 23:02:48 ---A- . (.Broadcom Corporation - Broadcom NetXtreme II 10 GigE VBD.) -- C:\Windows\system32\drivers\evbdx.sys [3100160]
    O58 - SDL:[MD5.F5CB6CB6D12F495516BE27CFFCCDE4BF] - 14/07/2009 - 23:02:53 ---A- . (.VIA Technologies, Inc. - NDIS 6.0 miniport driver.) -- C:\Windows\system32\drivers\fetnd6.sys [44032]
    O58 - SDL:[MD5.8182FF89C65E4D38B2DE4BB0FB18564E] - 18/05/2009 - 13:17:00 ---A- . (.GEAR Software Inc. - CD DVD Filter.) -- C:\Windows\system32\drivers\GEARAspiWDM.sys [26600]
    O58 - SDL:[MD5.C44E3C2BAB6837DB337DDEE7544736DB] - 14/07/2009 - 23:54:14 ---A- . (.Hauppauge Computer Works, Inc. - Hauppauge WinTV 885 Consumer IR Driver for eHome.) -- C:\Windows\system32\drivers\hcw85cir.sys [26624]
    O58 - SDL:[MD5.295FDC419039090EB8B49FFDBB374549] - 14/07/2009 - 02:20:28 ---A- . (.Hewlett-Packard Company - Smart Array SAS/SATA Controller Media Driver.) -- C:\Windows\system32\drivers\HpSAMD.sys [67152]
    O58 - SDL:[MD5.934AF4D7C5F457B9F0743F4299B77B67] - 14/07/2009 - 02:20:36 ---A- . (.Intel Corporation - Intel Matrix Storage Manager driver - ia32.) -- C:\Windows\system32\drivers\iaStorV.sys [332352]
    O58 - SDL:[MD5.4173FF5708F3236CF25195FECD742915] - 14/07/2009 - 02:20:36 ---A- . (.Intel Corp./ICP vortex GmbH - Intel/ICP Raid Storport Driver.) -- C:\Windows\system32\drivers\iirsp.sys [41040]
    O58 - SDL:[MD5.EB119A53CCF2ACC000AC71B065B78FEF] - 14/07/2009 - 02:20:36 ---A- . (.LSI Corporation - LSI Fusion-MPT FC Driver (StorPort).) -- C:\Windows\system32\drivers\lsi_fc.sys [95824]
    O58 - SDL:[MD5.8ADE1C877256A22E49B75D1CC9161F9C] - 14/07/2009 - 02:20:37 ---A- . (.LSI Corporation - LSI Fusion-MPT SAS Driver (StorPort).) -- C:\Windows\system32\drivers\lsi_sas.sys [89168]
    O58 - SDL:[MD5.DC9DC3D3DAA0E276FD2EC262E38B11E9] - 14/07/2009 - 02:20:36 ---A- . (.LSI Corporation - LSI SAS Gen2 Driver (StorPort).) -- C:\Windows\system32\drivers\lsi_sas2.sys [54864]
    O58 - SDL:[MD5.0A036C7D7CAB643A7F07135AC47E0524] - 14/07/2009 - 02:20:36 ---A- . (.LSI Corporation - LSI Fusion-MPT SCSI Driver (StorPort).) -- C:\Windows\system32\drivers\lsi_scsi.sys [96848]
    O58 - SDL:[MD5.9B5CC6C481BDD00A963829B892623247] - 29/11/2010 - 16:42:06 ---A- . (.Malwarebytes Corporation - Malwarebytes' Anti-Malware.) -- C:\Windows\system32\drivers\mbam.sys [20952]
    O58 - SDL:[MD5.E74DC2F3F9675A6025A4AA020EDD4341] - 29/11/2010 - 16:42:18 ---A- . (.Malwarebytes Corporation - Malwarebytes' Anti-Malware.) -- C:\Windows\system32\drivers\mbamswissarmy.sys [38224]
    O58 - SDL:[MD5.0FFF5B045293002AB38EB1FD1FC2FB74] - 14/07/2009 - 02:20:36 ---A- . (.LSI Corporation - MEGASAS RAID Controller Driver for Windows 7 for x86.) -- C:\Windows\system32\drivers\megasas.sys [30800]
    O58 - SDL:[MD5.DCBAB2920C75F390CAF1D29F675D03D6] - 14/07/2009 - 02:20:36 ---A- . (.LSI Corporation, Inc. - LSI MegaRAID Software RAID Driver.) -- C:\Windows\system32\drivers\MegaSR.sys [235584]
    O58 - SDL:[MD5.1D85C4B390B0EE09C7A46B91EFB2C097] - 14/07/2009 - 02:20:44 ---A- . (.IBM Corporation - IBM ServeRAID Controller Driver.) -- C:\Windows\system32\drivers\nfrd960.sys [44624]
    O58 - SDL:[MD5.3F3D04B1D08D43C16EA7963954EC768D] - 14/07/2009 - 02:20:44 ---A- . (.NVIDIA Corporation - NVIDIA® nForce(TM) RAID Driver.) -- C:\Windows\system32\drivers\nvraid.sys [117312]
    O58 - SDL:[MD5.C99F251A5DE63C6F129CF71933ACED0F] - 14/07/2009 - 02:20:44 ---A- . (.NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver.) -- C:\Windows\system32\drivers\nvstor.sys [142416]
    O58 - SDL:[MD5.AB95ECF1F6659A60DDC166D8315B0751] - 14/07/2009 - 02:19:04 ---A- . (.QLogic Corporation - QLogic Fibre Channel Stor Miniport Driver.) -- C:\Windows\system32\drivers\ql2300.sys [1383488]
    O58 - SDL:[MD5.B4DD51DD25182244B86737DC51AF2270] - 14/07/2009 - 02:19:04 ---A- . (.QLogic Corporation - QLogic iSCSI Storport Miniport Driver.) -- C:\Windows\system32\drivers\ql40xx.sys [106064]
    O58 - SDL:[MD5.0F6756EF8BDA6DFA7BE50465C83132BB] - 14/05/2007 - 15:17:16 ---A- . (.Research In Motion Limited - BlackBerry Device Driver.) -- C:\Windows\system32\drivers\RimUsb.sys [22656]
    O58 - SDL:[MD5.7997B6F02CBDA0E31FA18CC85871B938] - 18/06/2009 - 19:45:02 ---A- . (.Realtek Semiconductor Corp. - Realtek AC'97 Audio Driver (WDM).) -- C:\Windows\system32\drivers\RTKVAC.SYS [4172832]
    O58 - SDL:[MD5.90A3935D05B494A5A39D37E71F09A677] - 13/07/2009 - 21:50:20 ---A- . (.Macrovision Corporation, Macrovision Europe - Macrovision SECURITY Driver.) -- C:\Windows\system32\drivers\secdrv.sys [20480]
    O58 - SDL:[MD5.A9F0486851BECB6DDA1D89D381E71055] - 14/07/2009 - 02:19:04 ---A- . (.Silicon Integrated Systems Corp. - SiS RAID Stor Miniport Driver.) -- C:\Windows\system32\drivers\sisraid2.sys [40016]
    O58 - SDL:[MD5.3727097B55738E2F554972C3BE5BC1AA] - 14/07/2009 - 02:19:04 ---A- . (.Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver.) -- C:\Windows\system32\drivers\sisraid4.sys [77888]
    O58 - SDL:[MD5.A36EE93698802CD899F98BFD553D8185] - 17/06/2010 - 13:28:02 ---A- . (.Avira GmbH - AVIRA SnapShot Driver.) -- C:\Windows\system32\drivers\ssmdrv.sys [28520]
    O58 - SDL:[MD5.DB32D325C192B801DF274BFD12A7E72B] - 14/07/2009 - 02:19:04 ---A- . (.Promise Technology - Promise SuperTrak EX Series Driver for Windows.) -- C:\Windows\system32\drivers\stexstor.sys [21072]
    O58 - SDL:[MD5.5C2BDC152BBAB34F36473DEAF7713F22] - 14/12/2010 - 18:51:20 ---A- . (.Apple, Inc. - Apple Mobile Device USB Driver.) -- C:\Windows\system32\drivers\usbaapl.sys [41984]
    O58 - SDL:[MD5.763D29317159BFE7AA915F6879293382] - 03/11/2006 - 11:16:44 ---A- . (.Creative Technology Ltd. - Universal Serial Bus Camera Driver.) -- C:\Windows\system32\drivers\V0260Cmd.sys [24872]
    O58 - SDL:[MD5.C90055BD2BB41443462EA715E0876B8D] - 04/11/2006 - 23:45:48 ---A- . (.Creative Technology Ltd. - Video streaming and Capture Device Driver.) -- C:\Windows\system32\drivers\V0260Vid.sys [178913]
    O58 - SDL:[MD5.E43574F6A56A0EE11809B48C09E4FD3C] - 14/07/2009 - 02:19:10 ---A- . (.VIA Technologies, Inc. - VIA Generic PCI IDE Bus Driver.) -- C:\Windows\system32\drivers\viaide.sys [16976]
    O58 - SDL:[MD5.9DFA0CC2F8855A04816729651175B631] - 14/07/2009 - 02:19:11 ---A- . (.VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR AMD-X86-64.) -- C:\Windows\system32\drivers\vsmraid.sys [141904]
    O58 - SDL:[MD5.8AAD333C876590293F72B315E162BCC7] - 13/07/2009 - 22:40:41 ---A- . (...) -- C:\Windows\system32\ANSI.SYS [9029]
    O58 - SDL:[MD5.0FE9F16075C9ACB941C957B7C649176E] - 13/07/2009 - 22:40:44 ---A- . (...) -- C:\Windows\system32\country.sys [27097]
    O58 - SDL:[MD5.E6BC0F98FECEF245A0010D350C1A0B9B] - 13/07/2009 - 22:40:40 ---A- . (...) -- C:\Windows\system32\HIMEM.SYS [4768]
    O58 - SDL:[MD5.492090267B9608C62B956CD29BE3AFB7] - 13/07/2009 - 22:40:43 ---A- . (...) -- C:\Windows\system32\KEY01.SYS [42809]
    O58 - SDL:[MD5.FBBCFEC1379C5C02D88A361993EDF1B8] - 13/07/2009 - 22:40:43 ---A- . (...) -- C:\Windows\system32\KEYBOARD.SYS [42537]
    O58 - SDL:[MD5.FFFF296A08DBF2AC0126C62E3778AC0D] - 13/07/2009 - 22:40:23 ---A- . (...) -- C:\Windows\system32\NTDOS.SYS [27866]
    O58 - SDL:[MD5.CF9ED169FF86D935E47999E82359E898] - 13/07/2009 - 22:40:31 ---A- . (...) -- C:\Windows\system32\NTDOS404.SYS [29146]
    O58 - SDL:[MD5.03B945AC0481CD8BB161C3569D8ED1C3] - 13/07/2009 - 22:40:35 ---A- . (...) -- C:\Windows\system32\NTDOS411.SYS [29370]
    O58 - SDL:[MD5.BBC957DC18C17CC027EB80B7C77F2AEA] - 13/07/2009 - 22:40:39 ---A- . (...) -- C:\Windows\system32\NTDOS412.SYS [29274]
    O58 - SDL:[MD5.3CFFAEFFF23B0D208214A6D3061A5B1B] - 13/07/2009 - 22:40:27 ---A- . (...) -- C:\Windows\system32\NTDOS804.SYS [29146]
    O58 - SDL:[MD5.2E4112FB7D1B76E11ADFD7487B5D0E95] - 13/07/2009 - 22:40:11 ---A- . (...) -- C:\Windows\system32\NTIO.SYS [33952]
    O58 - SDL:[MD5.A98EBD4C2DF983665BF2D1AF49949974] - 13/07/2009 - 22:40:15 ---A- . (...) -- C:\Windows\system32\NTIO404.SYS [34672]
    O58 - SDL:[MD5.3F7E6406EDEF197C5CAAB2240EEF6F48] - 13/07/2009 - 22:40:17 ---A- . (...) -- C:\Windows\system32\NTIO411.SYS [35776]
    O58 - SDL:[MD5.3E64D681B776CC57BDC38A46D881F85B] - 13/07/2009 - 22:40:19 ---A- . (...) -- C:\Windows\system32\NTIO412.SYS [35536]
    O58 - SDL:[MD5.D86B6435729231C171432B4E77801BDB] - 13/07/2009 - 22:40:13 ---A- . (...) -- C:\Windows\system32\NTIO804.SYS [34672]

    ---\\ Liste des outils de nettoyage (O63)
    O63 - Logiciel: Ad-Remover par C_XX - (.C_XX.) [HKLM] -- Ad-Remover
    O63 - Logiciel: HijackThis 2.0.2 - (.TrendMicro.) [HKLM] -- HijackThis
    O63 - Logiciel: ZHPDiag 1.27 - (.Nicolas Coolman.) [HKLM] -- ZHPDiag_is1

    ---\\ Liste des services Legacy (O64)
    O64 - Services: CurCS - C:\Windows\System32\DRIVERS\atipmdag.sys - amdkmdag (amdkmdag) .(.ATI Technologies Inc. - ATI Radeon Kernel Mode Driver.) - LEGACY_AMDKMDAG
    O64 - Services: CurCS - C:\Windows\system32\Drivers\ASWFSBLK.sys - (.not file.) - aswFsBlk (aswFsBlk) .(...) - LEGACY_ASWFSBLK
    O64 - Services: CurCS - C:\Windows\system32\drivers\aswMonFlt.sys - aswMonFlt (aswMonFlt) .(.ALWIL Software - avast! File System Minifilter for Windows 2.) - LEGACY_ASWMONFLT
    O64 - Services: CurCS - C:\Windows\system32\Drivers\ASWRDR.sys - (.not file.) - aswRdr (aswRdr) .(...) - LEGACY_ASWRDR
    O64 - Services: CurCS - C:\Windows\system32\Drivers\ASWSP.sys - (.not file.) - as
    0
  8. sushijunky
     
    Argh! Le rapport a été coupé, voilà la suite:

    O64 - Services: CurCS - C:\Windows\system32\Drivers\ASWSP.sys - (.not file.) - aswSP (aswSP) .(...) - LEGACY_ASWSP
    O64 - Services: CurCS - C:\Windows\system32\Drivers\ASWTDI.sys - (.not file.) - avast! Network Shield Support (aswTdi) .(...) - LEGACY_ASWTDI
    O64 - Services: CurCS - C:\Windows\System32\DRIVERS\avgntflt.sys - avgntflt (avgntflt) .(.Avira GmbH - Avira Minifilter Driver.) - LEGACY_AVGNTFLT
    O64 - Services: CurCS - C:\Windows\System32\DRIVERS\avipbb.sys - avipbb (avipbb) .(.Avira GmbH - Avira Driver for Security Enhancement.) - LEGACY_AVIPBB
    O64 - Services: CurCS - C:\Windows\system32\Drivers\BEEP.sys - (.not file.) - Beep (Beep) .(...) - LEGACY_BEEP
    O64 - Services: CurCS - C:\Windows\system32\Drivers\FASTFAT.sys - (.not file.) - FAT12/16/32 File System Driver (fastfat) .(...) - LEGACY_FASTFAT
    O64 - Services: CurCS - C:\Windows\system32\Drivers\FS_REC.sys - Fs_Rec (Fs_Rec) .(...) - LEGACY_FS_REC
    O64 - Services: CurCS - (.not file.) - mbr (mbr) .(...) - LEGACY_MBR
    O64 - Services: CurCS - C:\Windows\system32\Drivers\MSFS.sys - Msfs (Msfs) .(...) - LEGACY_MSFS
    O64 - Services: CurCS - C:\Windows\system32\Drivers\NDPROXY.sys - NDProxy (NDProxy) .(...) - LEGACY_NDPROXY
    O64 - Services: CurCS - C:\Windows\system32\Drivers\NPFS.sys - Npfs (Npfs) .(...) - LEGACY_NPFS
    O64 - Services: CurCS - C:\Windows\system32\Drivers\NTFS.sys - Ntfs (Ntfs) .(...) - LEGACY_NTFS
    O64 - Services: CurCS - C:\Windows\system32\Drivers\NULL.sys - Null (Null) .(...) - LEGACY_NULL
    O64 - Services: CurCS - C:\Windows\system32\Drivers\SECDRV.sys - (.not file.) - Security Driver (secdrv) .(...) - LEGACY_SECDRV
    O64 - Services: CurCS - C:\Windows\system32\Drivers\SPLDR.sys - (.not file.) - Security Processor Loader Driver (spldr) .(...) - LEGACY_SPLDR
    O64 - Services: CurCS - C:\Windows\System32\DRIVERS\ssmdrv.sys - ssmdrv (ssmdrv) .(.Avira GmbH - AVIRA SnapShot Driver.) - LEGACY_SSMDRV

    ---\\ File Associations Shell Spawning (O67)
    O67 - Shell Spawning: <.bat> <batfile>[HKLM\..\open\Command] "%1" %* (.not file.)
    O67 - Shell Spawning: <.cpl> <cplfile>[HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe
    O67 - Shell Spawning: <.cmd> <cmdfile>[HKLM\..\open\Command] "%1" %* (.not file.)
    O67 - Shell Spawning: <.com> <comfile>[HKLM\..\open\Command] "%1" %* (.not file.)
    O67 - Shell Spawning: <.exe> <exefile>[HKLM\..\open\Command] "%1" %* (.not file.)
    O67 - Shell Spawning: <.html> <htmlfile>[HKLM\..\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe
    O67 - Shell Spawning: <.js> <JSFile>[HKLM\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\Windows\System32\WScript.exe
    O67 - Shell Spawning: <.reg> <regfile>[HKLM\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\Windows\regedit.exe
    O67 - Shell Spawning: <.bat> <batfile>[HKCR\..\open\Command] "%1" %* (.not file.)
    O67 - Shell Spawning: <.cpl> <cplfile>[HKCR\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe
    O67 - Shell Spawning: <.cmd> <cmdfile>[HKCR\..\open\Command] "%1" %* (.not file.)
    O67 - Shell Spawning: <.com> <comfile>[HKCR\..\open\Command] "%1" %* (.not file.)
    O67 - Shell Spawning: <.exe> <exefile>[HKCR\..\open\Command] "%1" %* (.not file.)
    O67 - Shell Spawning: <.html> <htmlfile>[HKCR\..\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe
    O67 - Shell Spawning: <.js> <JSFile>[HKCR\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\Windows\System32\WScript.exe
    O67 - Shell Spawning: <.reg> <regfile>[HKCR\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\Windows\regedit.exe

    ---\\ Start Menu Internet (O68)
    O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer>[HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe

    ---\\ Search Browser Infection (O69)
    O69 - SBI: SearchScopes [HKCU] {18507EA4-1F9A-4B19-8379-1984530A1A29} [DefaultScope] - (Google) - http://www.google.com

    ---\\ Recherche particuliere à la racine de certains dossiers (O84)
    [MD5.C4CA7416A6DF6D95075F81D9E3B41AD1] [SPRF] (.Trend Micro Inc. - HijackThis.) -- C:\Program Files\HijackThis.exe [396288]
    [MD5.B9694C8D6074479BC466259F4CB5ACD0] [SPRF] (.ATI Technologies Inc. - ATI Uninstall Application.) -- C:\Users\Marine Nicolas\AppData\Local\Temp\AtiCimUn.exe [122880]
    [MD5.D93B6128D19907B308E7F8572A192EA8] [SPRF] (.DivX, Inc. - DivX Web Player Installer, L:EN;ES;DE;FR;JA;PT;ZH-CN;ZH-TW, DivX Plus Web Player 2.0.0.) -- C:\Users\Marine Nicolas\AppData\Local\Temp\DivXInstaller.exe [6667584]
    [MD5.6FC051B2D50915679732C01C06ADC8B4] [SPRF] (.Sony DADC Austria AG - SecuROM dynamic-data module.) -- C:\Users\Marine Nicolas\AppData\Local\Temp\drm_dyndata_7330014.dll [212992]
    [MD5.A7E7A44D9BF267886E0FC9E68BB81A2B] [SPRF] (.Sony DADC Austria AG - SecuROM dynamic-data module.) -- C:\Users\Marine Nicolas\AppData\Local\Temp\drm_dyndata_7340007.dll [212992]
    [MD5.E5F1E5CAE32811A1AD884BEA43F1247C] [SPRF] (.Adobe Systems, Inc. - Adobe® Flash® Player Installer/Uninstaller 10.1 r53.) -- C:\Users\Marine Nicolas\AppData\Local\Temp\FlashPlayerUpdate.exe [2605008]
    [MD5.DB5D2225E502A7E6329C8A0CAC2CBF1A] [SPRF] (.Sun Microsystems, Inc. - Java(TM) Platform SE binary.) -- C:\Users\Marine Nicolas\AppData\Local\Temp\jre-6u21-windows-i586-iftw-rv.exe [875296]
    [MD5.676A86173A1FE2698C6F049D74DC6EB2] [SPRF] (.Sun Microsystems, Inc. - Java(TM) Platform SE binary.) -- C:\Users\Marine Nicolas\AppData\Local\Temp\jre-6u22-windows-i586-iftw-rv.exe [875296]
    [MD5.34908E446D09432BD17830458D242BD2] [SPRF] (.Sun Microsystems, Inc. - Java(TM) Platform SE binary.) -- C:\Users\Marine Nicolas\AppData\Local\Temp\jre-6u23-windows-i586-iftw-rv.exe [884512]
    [MD5.BA30773120175EE6A40C261F9DE7FCD3] [SPRF] (.Macrovision Corporation - Setup.exe.) -- C:\Users\Marine Nicolas\AppData\Local\Temp\_is3E18.exe [456416]
    [MD5.BA30773120175EE6A40C261F9DE7FCD3] [SPRF] (.Macrovision Corporation - Setup.exe.) -- C:\Users\Marine Nicolas\AppData\Local\Temp\_is5896.exe [456416]
    [MD5.BA30773120175EE6A40C261F9DE7FCD3] [SPRF] (.Macrovision Corporation - Setup.exe.) -- C:\Users\Marine Nicolas\AppData\Local\Temp\_isB61F.exe [456416]
    [MD5.BA30773120175EE6A40C261F9DE7FCD3] [SPRF] (.Macrovision Corporation - Setup.exe.) -- C:\Users\Marine Nicolas\AppData\Local\Temp\_isF014.exe [456416]

    ---\\ Firewall Active Exception List (FirewallRules) (O87)
    O87 - FAEL: "FPS-SpoolSvc-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Application sous-système spouleur.) -- C:\Windows\system32\spoolsv.exe
    O87 - FAEL: "FPS-SpoolSvc-In-TCP" | In - Public - P6 - TRUE | .(.Microsoft Corporation - Application sous-système spouleur.) -- C:\Windows\system32\spoolsv.exe
    O87 - FAEL: "CoreNet-GP-LSASS-Out-TCP" | Out - Domain - P6 - TRUE | .(.Microsoft Corporation - Local Security Authority Process.) -- C:\Windows\system32\lsass.exe
    O87 - FAEL: "RemoteSvcAdmin-In-TCP-NoScope" | In - Domain - P6 - FALSE | .(.Microsoft Corporation - Applications Services et Contrôleur.) -- C:\Windows\system32\services.exe
    O87 - FAEL: "RemoteSvcAdmin-In-TCP" | In - Public - P6 - FALSE | .(.Microsoft Corporation - Applications Services et Contrôleur.) -- C:\Windows\system32\services.exe
    O87 - FAEL: "NetPres-In-TCP-NoScope" |In - Domain - P6 - FALSE | .(...) -- C:\Windows\system32\netproj.exe (.not file.)
    O87 - FAEL: "NetPres-Out-TCP-NoScope" |Out - Domain - P6 - FALSE | .(...) -- C:\Windows\system32\netproj.exe (.not file.)
    O87 - FAEL: "NetPres-WSD-In-UDP" |In - None - P17 - FALSE | .(...) -- C:\Windows\system32\netproj.exe (.not file.)
    O87 - FAEL: "NetPres-WSD-Out-UDP" |Out - None - P17 - FALSE | .(...) -- C:\Windows\system32\netproj.exe (.not file.)
    O87 - FAEL: "NetPres-In-TCP" |In - Public - P6 - FALSE | .(...) -- C:\Windows\system32\netproj.exe (.not file.)
    O87 - FAEL: "NetPres-Out-TCP" |Out - Public - P6 - FALSE | .(...) -- C:\Windows\system32\netproj.exe (.not file.)
    O87 - FAEL: "{64DDDB35-EE7C-4EFE-9BE6-A95ACDFE661A}" | In - Private - P6 - TRUE | .(.Microsoft Corporation - Application sous-système spouleur.) -- C:\Windows\system32\spoolsv.exe
    O87 - FAEL: "{5193653E-C7D3-4461-BE33-FF2925C9E4B4}" | In - None - P6 - TRUE | .(.Microsoft Corporation - Windows Live Messenger.) -- C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    O87 - FAEL: "{A3BF0EA8-C56C-45C3-A035-077024E0AC32}" |In - Private - P6 - TRUE | .(...) -- C:\Program Files\ma-config.com\maconfservice.exe (.not file.)
    O87 - FAEL: "{7C9BDFAB-1173-4BE0-AA26-6E2BBFFB5191}" |In - Private - P17 - TRUE | .(...) -- C:\Program Files\ma-config.com\maconfservice.exe (.not file.)
    O87 - FAEL: "{7EFBD275-DCB2-44C4-B7DC-FB95DF7E112E}" | In - Private - P6 - TRUE | .(.FrostWire Group - FrostWire.) -- C:\Program Files\FrostWire\FrostWire.exe
    O87 - FAEL: "{E0BE8F47-66D6-4F86-BE9D-C96DBCDC7368}" | In - Private - P17 - TRUE | .(.FrostWire Group - FrostWire.) -- C:\Program Files\FrostWire\FrostWire.exe
    O87 - FAEL: "{80ED64D2-D21C-4628-A553-AA06F372C5F6}" | In - Private - P6 - TRUE | .(.Apple Inc. - Bonjour Service.) -- C:\Program Files\Bonjour\mDNSResponder.exe
    O87 - FAEL: "{B2A25B38-84FC-4FE4-A6A6-16D841E8BA0D}" | In - Private - P17 - TRUE | .(.Apple Inc. - Bonjour Service.) -- C:\Program Files\Bonjour\mDNSResponder.exe
    O87 - FAEL: "{D3F6D688-CE5C-4B97-8877-07603B40203D}" | In - None - P17 - TRUE | .(.Apple Inc. - iTunes.) -- C:\Program Files\iTunes\iTunes.exe
    O87 - FAEL: "{9CF0EDA2-1C3D-44EB-ACD4-2AB89ADD0739}" |In - Domain - P17 - TRUE | .(...) -- C:\Windows\system32\aeevts32.exe (.not file.)
    O87 - FAEL: "{81329122-36AF-4540-8F61-CAACC6E63904}" |In - Private - P17 - TRUE | .(...) -- C:\Windows\system32\aeevts32.exe (.not file.)
    O87 - FAEL: "{7E040921-BDFA-4E8B-B147-E6F0FAF84F4D}" |In - Public - P17 - TRUE | .(...) -- C:\Windows\system32\aeevts32.exe (.not file.)

    ---\\ Etat général des services non Microsoft (EGS) (SR=Running, SS=Stopped)
    SR - | Auto 03/02/2010 172032 | (AMD External Events Utility) . (.AMD.) - C:\Windows\system32\atiesrxx.exe
    SR - | Auto 04/02/2011 135336 | (AntiVirSchedulerService) . (.Avira GmbH.) - C:\Program Files\Avira\AntiVir Desktop\sched.exe
    SR - | Auto 04/02/2011 267944 | (AntiVirService) . (.Avira GmbH.) - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
    SR - | Auto 05/01/2011 37664 | (Apple Mobile Device) . (.Apple Inc..) - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    SR - | Auto 28/06/2010 40384 | (avast! Antivirus) . (.AVAST Software.) - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
    SR - | Demand 28/06/2010 40384 | (avast! Mail Scanner) . (.AVAST Software.) - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
    SR - | Demand 28/06/2010 40384 | (avast! Web Scanner) . (.AVAST Software.) - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
    SR - | Auto 07/10/2010 345376 | (Bonjour Service) . (.Apple Inc..) - C:\Program Files\Bonjour\mDNSResponder.exe
    SR - | Demand 25/01/2011 820008 | (iPod Service) . (.Apple Inc..) - C:\Program Files\iPod\bin\iPodService.exe
    SR - | Auto 14/07/2009 20992 | C:\Windows\system32\wuaueng.dll (wuauserv) . (.Microsoft Corporation.) - C:\Windows\system32\svchost.exe

    ---\\ Recherche Master Boot Record Infection (MBR)(O80)
    Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
    Run by Marine Nicolas at 12/04/2011 19:51:16

    device: opened successfully
    user: MBR read successfully

    Disk trace:
    called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys halmacpi.dll ataport.SYS viaide.sys PCIIDEX.SYS atapi.sys
    C:\Windows\system32\DRIVERS\viaide.sys VIA Technologies, Inc. VIA PCI IDE MINI Driver
    1 ntkrnlpa!IofCallDriver[0x82A8B448] -> \Device\Harddisk0\DR0[0x854A1030]
    3 CLASSPNP[0x87BA459E] -> ntkrnlpa!IofCallDriver[0x82A8B448] -> [0x853DC898]
    5 ACPI[0x876463B2] -> ntkrnlpa!IofCallDriver[0x82A8B448] -> \Device\Ide\IdeDeviceP2T0L0-2[0x853E3908]
    kernel: MBR read successfully
    user & kernel MBR OK

    ---\\ Recherche Master Boot Record Infection (MBRCheck)(O80)
    Written by ad13, http://ad13.geekstog
    Run by Marine Nicolas at 12/04/2011 19:51:23

    ********* Dump file Name *********
    C:\PhysicalDisk0_MBR.bin

    ********* Dump File Header *********
    Windows Version: Windows 7 Home Premium Edition
    Windows Information: (build 7600), 32-bit
    Logical Drives Mask: 0x0000006d

    ********* Dump File Analysis *********
    Windows 7 MBR code detected

    End of the scan (799 lines in 00mn 40s)(0)

    Le seul problème c'est que j'ai eu une alerte de logiciel malveillant de Antivir pendant que je faisais le ZHP Diag. Tu penses qu'il ne reste plus rien?

    Merci :)
    0
  9. flo-91 Messages postés 5973 Statut Contributeur sécurité 1 120
     
    Bien, on va pouvoir terminer :

    Ce logiciel est utilisé pour nettoyer les outils qui ont servi à la désinfection :
    N'oublie pas de réactiver l'UAC si tu as eu besoin de la desactiver

    [*] Téléchargez DelFix d'Xplode
    [*] Lancez puis puis cliquez sur le bouton [Suppression]
    [*] Après quelques secondes, un rapport s'ouvrira.

    Tu vas utiliser le logiciel CCleaner pour faire un petit peu de nettoyage :

    ATTENTION :Ce n'est en aucun cas un logiciel de désinfection, ccleaner va nettoyer le pc des fichiers temporaires inutiles ( certains sont infectieux quelquefois ) et autres cookies internet et accessoirement, il répare le registre pour o[b]ptimiser le pc[/b], mais [b]il ne désinfecte pas[/b] le pc.

    => Famille outils d'optimisation

    Tu peux garder l'outil sur ton pc pour un nettoyage de temps en temps ( environ 1 fois/mois )

    >Telecharge et installe le Logiciel Ccleaner ici :

    https://www.commentcamarche.net/telecharger/utilitaires/5647-ccleaner/

    >Lances le programme et paramètre-le ainsi :

    >Onglet "option" clique sur "avancé" décoche la case "effacer les fichiers temporaires de windows datant de plus de 48 heures".

    >Nettoyage<

    >Onglet "Nettoyeur" clique sur "analyser" puis sur "nettoyer", tu refait l'opération jusqu'à ce qu'il n'y ai plus rien a supprimer

    >Onglet "registre" clique sur "rechercher les erreurs" puis "corriger les erreurs sélectionnées", tu refait l'opération jusqu'à ce qu'il n'y ai plus rien a réparer.

    >Il est conseillé de garder l'outil sur son pc et de faire quotidiennement un nettoyage.

    Les infections se logent souvent dans les restauration du systeme sans que ne l'on puisse le voir, il est donc important de la purger si tu ne veux pas être réinfecter à la prochaine restauration si tu as besoin :

    Purge la restauration de ton système

    *Désactive ta restauration :
    Clique droit sur poste de travail/propriétés/Restauration système/coche la case désactiver la restauration, appliquer, OK
    ---> Redémarre le PC ...

    *Réactive ta restauration :
    Clique droit sur poste de travail/propriétés/Restauration système/décoche la case désactiver la restauration, appliquer, OK
    --->Redémarre le PC ...


    Créé un nouveau point de restauration :


    > Démarrer
    > Tous les programmes
    > Accessoires
    > Outils Système
    > Restauration du système.

    Devant l'écran d'accueil, choisi "créer un point de restauration", puis donnes-lui un nom comme "point de restauration saint par exemple" et clique sur "créer".

    Il est important de garder un systeme et ses logiciels à jours, les logiciels évoluent constamment pour s'améliorer et combler les failles de sécurité.
    Un pc non à jour est donc plus vulnérable aux infections.

    Ta version de Java n'est pas à jour, utilise le logiciel Javarra pour la mettre à jour :


    Met a jour ta console Java


    >Telecharge et installe Javara ici :

    http://raproducts.org/click/click.php?id=1

    >Dézippe le fichier avec "extraire ici"
    >Double-clique sur JavaRa.exe pour lancer le programme
    >Sélectionne la langue Français
    >Clique sur "recherche de mises a jour"
    >Choisi l'option "Mettre a jour via jucheck.exe" puis clique sur recherche
    >Accepte l'installation de la nouvelle mise a jour

    >N'accepte surtout pas la toolbar yahoo qui est source de malwares


    >Retourne à l'interface principale et clique sur Effacer les anciennes versions
    >On te demande une confirmation, accepte

    Un tuto pour t'aider :

    http://www.libellules.ch/tuto_javara.php

    Ta version d'open office n'est pas à jour, désinstalle ton ancienne version et télécharge puis installe la dernier ici :

    http://fr.openoffice.org/about-downloads.html

    Enfin :


    Améliorer sa sécurité


    Conseils pour protéger son pc :

    Un bon antivirus :

    En gratuit : Avira Antivir ou Avast.

    En payant :
    Kaspersky ou Eset NOD32

    Un pare-feu :

    Le pare-feu de windows est suffisant pour une utilisation classique du pc.
    Cependant, pour les utilisateurs plus rigoureux et recherchant une meilleure protection, je conseille des pare-feu professionnels gratuits :

    Comodo ( désonseillé pour les novices et débutants car plutot complexe )
    Kerio
    Zone Alarm

    Désinstaller celui de windows si on choisi un de ci-dessus.
    Pour désactiver le pare-feu windows :

    > Cliquer sur "Démarrer" puis "panneau de configuration"
    > Cliquer sur "centre de sécurité" puis "pare-feu windows"
    > Cocher la case "désactiver" et cliquer sur "ok"

    Pour COMODO, voici un petit tuto pour le configurer : https://www.malekal.com/tutorial-comodo-firewall/

    Un anti malware en plus :

    Malwarebytes

    Je te conseille de naviguer avec Firefox si ce n'est déja fait, télécharge la derniere version ici :

    http://www.mozilla-europe.org/fr/firefox/

    Couplée avec de bons modules complémentaires, on améliore vraiment sa sécurité, tu le couple avec :

    - Noscript:
    https://addons.mozilla.org/fr/firefox/addon/noscript/

    >Tuto pour configurer noscript :

    https://www.commentcamarche.net/faq/15677-noscript-un-bon-bouclier-et-obeissant

    -Wot :

    https://addons.mozilla.org/fr/firefox/addon/wot-safe-browsing-tool/

    -Adblock plus :

    https://addons.mozilla.org/fr/firefox/addon/adblock-plus/

    Tuto> http://www.6ma.fr/tuto/adblock-plus-bloquer-les-publicites-sur-firefox/

    Evite les crack et le téléchargements avec des P2P (emule...) vecteurs de malwares :

    https://forum.malekal.com/viewtopic.php?t=893&start=

    https://forum.malekal.com/viewtopic.php?t=3208&start=

    A consulter :

    https://www.malekal.com/fichiers/projetantimalwares/ProjetAntiMalware-courte.pdf

    https://www.commentcamarche.net/faq/7752-logiciels-gratuits-pour-assurer-une-bonne-securite-de-base
    0
  10. sushijunky
     
    Bonjour!

    C'est bon, tout est fait... grâce à toi j'ai un PC tout neuf :D

    Alors merci encore pour toute ton aide, ta patience et ta persévérance; c'est vraiment sympa!
    0
    1. flo-91 Messages postés 5973 Statut Contributeur sécurité 1 120
       
      De rien ;)

      ++
      0