PhysicalDrive0 Controlled by rootkit

Manong -  
 Utilisateur anonyme -
Bonjour,



J'ai un énorme problème depuis quelques temps, avast bloque des adresses url malveillantes constamment, je trouve et supprime des trojan à chaque fois que je fais un scan Malwarebytes.
J'ai essayé de me débrouiller toute seule en regardant le forum, sachant qu'il y a deux semaines je ne savais même pas ce qu'était un trojan, mais la méthode avec bootkit ne donne rien, le rapport dit toujours :

"Bootkit Remover
(c) 2009 eSage Lab
www.esagelab.com
Program version: 1.2.0.0
OS Version: Microsoft Windows XP Professional Service Pack 3 (build 2600)
System volume is \\.\C:
\\.\C: -> \\.\PhysicalDrive0 at offset 0x00000000'00007e00

Size Device Name MBR Status
--------------------------------------------
149 GB \\.\PhysicalDrive0 Controlled by rootkit!

Boot code on some of your physical disks is hidden by a rootkit.
To disinfect the master boot sector, use the following command:
remover.exe fix <device_name>
To inspect the boot code manually, dump the master boot sector:
remover.exe dump <device_name> [output_file]

Done"

.
.
.
.
.
.

J'ai créé un fichier "tralala" en faisant start remover.exe dump...ect, et le scan virustotal.com donne :

.
.
.

"AhnLab-V3 2011.05.17.00 2011.05.16 -
AntiVir 7.11.8.37 2011.05.16 BOO/TDss.M
Antiy-AVL 2.0.3.7 2011.05.16 -
Avast 4.8.1351.0 2011.05.16 Alureon-G@mbr
Avast5 5.0.677.0 2011.05.16 Alureon-G@mbr
AVG 10.0.0.1190 2011.05.16 Win32/Alureon.MBR
BitDefender 7.2 2011.05.16 Rootkit.MBR.TDSS.B (Boot image)
CAT-QuickHeal 11.00 2011.05.16 Bootkit.TDSS.TDL4
ClamAV 0.97.0.0 2011.05.16 -
Commtouch 5.3.2.6 2011.05.16 -
Comodo 8725 2011.05.16 -
DrWeb 5.0.2.03300 2011.05.16 BackDoor.Tdss.4005
eSafe 7.0.17.0 2011.05.15 -
eTrust-Vet 36.1.8330 2011.05.16 Dos/Alureon
F-Prot 4.6.2.117 2011.05.16 -
F-Secure 9.0.16440.0 2011.05.16 Rootkit.MBR.TDSS.B \(Boot image\)
Fortinet 4.2.257.0 2011.05.14 BOOT/TDSS.A
GData 22 2011.05.16 Rootkit.MBR.TDSS.B
Ikarus T3.1.1.103.0 2011.05.16 Rootkit.Win32.TDSS
Jiangmin 13.0.900 2011.05.16 -
K7AntiVirus 9.103.4648 2011.05.14 -
Kaspersky 9.0.0.837 2011.05.16 Rootkit.Win32.TDSS.mbr
McAfee 5.400.0.1158 2011.05.16 TDSS!mbr
McAfee-GW-Edition 2010.1D 2011.05.16 TDSS!mbr
Microsoft 1.6802 2011.05.16 Trojan:DOS/Alureon.A
NOD32 6127 2011.05.16 -
Norman 6.07.07 2011.05.15 TDSSmbr.A
nProtect 2011-05-16.01 2011.05.16 -
Panda 10.0.3.5 2011.05.16 -
PCTools 7.0.3.5 2011.05.13 -
Prevx 3.0 2011.05.16 -
Rising 23.58.00.06 2011.05.16 -
Sophos 4.65.0 2011.05.16 Troj/TdlMbr-B
SUPERAntiSpyware 4.40.0.1006 2011.05.16 -
Symantec 20101.3.2.89 2011.05.16 -
TheHacker 6.7.0.1.198 2011.05.16 -
TrendMicro 9.200.0.1012 2011.05.16 -
TrendMicro-HouseCall 9.200.0.1012 2011.05.16 -
VBA32 3.12.16.0 2011.05.12 -
VIPRE 9299 2011.05.16 Trojan.Boot.Alureon.Gen (v)
ViRobot 2011.5.16.4461 2011.05.16 -
VirusBuster 13.6.357.0 2011.05.16 -
"

Je vous en supplie presque à genoux, aidez moi !
Merci d'avance pour votre attention.

21 réponses

  • 1
  • 2
Résumé de la discussion

Un utilisateur sous Windows XP et Firefox 4.0.1 signale un problème majeur où Avast bloque des URL malveillantes et où des trojans et un rootkit TDSS semblent réapparaître malgré Malwarebytes. Plusieurs réponses proposent un diagnostic avec ZHPDiag et ZHPFix pour nettoyer les traces, puis l’hébergement et le partage du rapport via pjjoint, cijoint ou casimages. D'autres éléments citent des résultats d’outils en ligne comme Jotti pour les analyses, et plusieurs messages décrivent les composants identifiés dans les rapports: services, démarrages et extensions affectées. En cas de doute, les échanges insistent sur l’exécution des outils en mode administrateur et sur la relance d’une vérification complète pour éviter les infections résiduelles.

Bobot (l'IA à votre service)
  1. juju666 Messages postés 35446 Date d'inscription   Statut Contributeur sécurité Dernière intervention   4 796
     
    Hello

    Oh c'tout gentil ça ^^ suffit de trouver le bon outil :p

    allé jawaryinti en piste :p

    .::. Contributeur Sécurité .::.
    0
  2. Utilisateur anonyme
     
    Bonsoir
    Le MBR est infecté
    Télécharge TDSSKiller (de Kaspersky) sur ton bureau
    https://support.kaspersky.com/downloads/utils/tdsskiller.exe

    Double clique sur TDSSKiller pour le lancer (avec Vista/Seven, clic droit
    dessus, et sur exécuter en tant qu'administrateur

    Clique sur Start scan, et laisse l'outil travailler

    Si des fichiers infectés sont trouvés, une nouvelle fenêtre va s'ouvrir

    Si TDSS. tdl2 est détecté, l'option delete sera cochée par défaut

    Si TDSS.tdl3 est détecté, vérifie que Cure est bien cochée

    Si TDSS.tdl4 (\HardDisk0\MBR) est détecté, vérifie que Cure
    est bien cochée

    Si Suspicious file est indiqué, laisse l'option cochée sur Skip

    Clique sur Continue, puis sur Reboot now pour
    redémarrer le PC

    Poste le rapport qui est sauvegardé dans C:\TDSSKiller_Quarantine\
    JJ.MM.AA_HH.MM.SS.
    (JJ.MM.AA date du passage de l'outil, HH.MM.SS
    heure de passage).

    0
    1. juju666 Messages postés 35446 Date d'inscription   Statut Contributeur sécurité Dernière intervention   4 796
       
      allé jawaryinti prends le ;)
      0
    2. Manong
       
      Merci beaucoup pour la réponse si rapide !
      J'ai du éteindre le pc, mais je fais ça demain dès que je peux et je poste le tout.
      0
    3. Utilisateur anonyme
       
      D'accord à demain pour le résultat
      0
  3. Manong
     
    Voilà le rapport de TDSSKiller :
    .
    .
    .
    .

    2011/05/17 17:35:07.0500 3808 TDSS rootkit removing tool 2.5.1.0 May 13 2011 13:20:29
    2011/05/17 17:35:09.0140 3808 ================================================================================
    2011/05/17 17:35:09.0140 3808 SystemInfo:
    2011/05/17 17:35:09.0140 3808
    2011/05/17 17:35:09.0156 3808 OS Version: 5.1.2600 ServicePack: 3.0
    2011/05/17 17:35:09.0156 3808 Product type: Workstation
    2011/05/17 17:35:09.0156 3808 ComputerName: TOMMY
    2011/05/17 17:35:09.0156 3808 UserName: Tommy
    2011/05/17 17:35:09.0156 3808 Windows directory: C:\WINDOWS
    2011/05/17 17:35:09.0156 3808 System windows directory: C:\WINDOWS
    2011/05/17 17:35:09.0156 3808 Processor architecture: Intel x86
    2011/05/17 17:35:09.0156 3808 Number of processors: 1
    2011/05/17 17:35:09.0156 3808 Page size: 0x1000
    2011/05/17 17:35:09.0156 3808 Boot type: Normal boot
    2011/05/17 17:35:09.0156 3808 ================================================================================
    2011/05/17 17:35:09.0718 3808 Initialize success
    2011/05/17 17:35:16.0875 3860 ================================================================================
    2011/05/17 17:35:16.0875 3860 Scan started
    2011/05/17 17:35:16.0875 3860 Mode: Manual;
    2011/05/17 17:35:16.0875 3860 ================================================================================
    2011/05/17 17:35:17.0671 3860 Aavmker4 (479c9835b91147be1a92cb76fad9c6de) C:\WINDOWS\system32\drivers\Aavmker4.sys
    2011/05/17 17:35:17.0968 3860 ACPI (e5e6dbfc41ea8aad005cb9a57a96b43b) C:\WINDOWS\system32\DRIVERS\ACPI.sys
    2011/05/17 17:35:18.0125 3860 ACPIEC (e4abc1212b70bb03d35e60681c447210) C:\WINDOWS\system32\drivers\ACPIEC.sys
    2011/05/17 17:35:18.0375 3860 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
    2011/05/17 17:35:18.0515 3860 AFD (7618d5218f2a614672ec61a80d854a37) C:\WINDOWS\System32\drivers\afd.sys
    2011/05/17 17:35:18.0656 3860 agp440 (08fd04aa961bdc77fb983f328334e3d7) C:\WINDOWS\system32\DRIVERS\agp440.sys
    2011/05/17 17:35:19.0890 3860 aswFsBlk (cba53c5e29ae0a0ce76f9a2be3a40d9e) C:\WINDOWS\system32\drivers\aswFsBlk.sys
    2011/05/17 17:35:20.0062 3860 aswMon2 (a1c52b822b7b8a5c2162d38f579f97b7) C:\WINDOWS\system32\drivers\aswMon2.sys
    2011/05/17 17:35:20.0218 3860 aswRdr (b6e8c5874377a42756c282fac2e20836) C:\WINDOWS\system32\drivers\aswRdr.sys
    2011/05/17 17:35:20.0359 3860 aswSP (b93a553c9b0f14263c8f016a44c3258c) C:\WINDOWS\system32\drivers\aswSP.sys
    2011/05/17 17:35:20.0531 3860 aswTdi (1408421505257846eb336feeef33352d) C:\WINDOWS\system32\drivers\aswTdi.sys
    2011/05/17 17:35:20.0687 3860 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
    2011/05/17 17:35:20.0828 3860 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
    2011/05/17 17:35:21.0109 3860 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
    2011/05/17 17:35:21.0250 3860 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
    2011/05/17 17:35:21.0406 3860 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
    2011/05/17 17:35:21.0609 3860 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
    2011/05/17 17:35:21.0765 3860 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
    2011/05/17 17:35:22.0046 3860 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
    2011/05/17 17:35:22.0171 3860 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
    2011/05/17 17:35:22.0281 3860 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
    2011/05/17 17:35:22.0968 3860 ctljystk (71007bd2e1e26927fe3e4eb00c0beedf) C:\WINDOWS\system32\DRIVERS\ctljystk.sys
    2011/05/17 17:35:23.0328 3860 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
    2011/05/17 17:35:23.0515 3860 dmboot (f5deadd42335fb33edca74ecb2f36cba) C:\WINDOWS\system32\drivers\dmboot.sys
    2011/05/17 17:35:23.0687 3860 dmio (5a7c47c9b3f9fb92a66410a7509f0c71) C:\WINDOWS\system32\drivers\dmio.sys
    2011/05/17 17:35:23.0843 3860 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
    2011/05/17 17:35:24.0000 3860 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
    2011/05/17 17:35:24.0265 3860 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
    2011/05/17 17:35:24.0421 3860 E100B (98ed0bea10477b0f252cca35eb50f838) C:\WINDOWS\system32\DRIVERS\e100b325.sys
    2011/05/17 17:35:24.0562 3860 emu10k (01f83e1b5dce05f5cb7d99113ca9e890) C:\WINDOWS\system32\drivers\emu10k1m.sys
    2011/05/17 17:35:24.0703 3860 emu10k1 (7ffa171cce6a8bfc774862a578ba39a2) C:\WINDOWS\system32\drivers\ctlfacem.sys
    2011/05/17 17:35:24.0875 3860 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
    2011/05/17 17:35:25.0046 3860 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys
    2011/05/17 17:35:25.0156 3860 Fips (31f923eb2170fc172c81abda0045d18c) C:\WINDOWS\system32\drivers\Fips.sys
    2011/05/17 17:35:25.0296 3860 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys
    2011/05/17 17:35:25.0406 3860 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
    2011/05/17 17:35:25.0578 3860 FsUsbExDisk (790a4ca68f44be35967b3df61f3e4675) C:\WINDOWS\system32\FsUsbExDisk.SYS
    2011/05/17 17:35:25.0718 3860 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
    2011/05/17 17:35:25.0828 3860 Ftdisk (a86859b77b908c18c2657f284aa29fe3) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
    2011/05/17 17:35:25.0984 3860 gameenum (065639773d8b03f33577f6cdaea21063) C:\WINDOWS\system32\DRIVERS\gameenum.sys
    2011/05/17 17:35:26.0156 3860 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\WINDOWS\system32\Drivers\GEARAspiWDM.sys
    2011/05/17 17:35:26.0281 3860 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
    2011/05/17 17:35:26.0453 3860 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
    2011/05/17 17:35:26.0703 3860 HPZid412 (d03d10f7ded688fecf50f8fbf1ea9b8a) C:\WINDOWS\system32\DRIVERS\HPZid412.sys
    2011/05/17 17:35:26.0843 3860 HPZipr12 (89f41658929393487b6b7d13c8528ce3) C:\WINDOWS\system32\DRIVERS\HPZipr12.sys
    2011/05/17 17:35:26.0984 3860 HPZius12 (abcb05ccdbf03000354b9553820e39f8) C:\WINDOWS\system32\DRIVERS\HPZius12.sys
    2011/05/17 17:35:27.0109 3860 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
    2011/05/17 17:35:27.0515 3860 i8042prt (a09bdc4ed10e3b2e0ec27bb94af32516) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
    2011/05/17 17:35:27.0656 3860 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
    2011/05/17 17:35:27.0953 3860 IntelIde (4b6da2f0a4095857a9e3f3697399d575) C:\WINDOWS\system32\DRIVERS\intelide.sys
    2011/05/17 17:35:28.0093 3860 intelppm (ad340800c35a42d4de1641a37feea34c) C:\WINDOWS\system32\DRIVERS\intelppm.sys
    2011/05/17 17:35:28.0218 3860 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
    2011/05/17 17:35:28.0328 3860 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
    2011/05/17 17:35:28.0484 3860 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
    2011/05/17 17:35:28.0625 3860 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
    2011/05/17 17:35:28.0765 3860 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
    2011/05/17 17:35:28.0906 3860 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
    2011/05/17 17:35:29.0078 3860 isapnp (355836975a67b6554bca60328cd6cb74) C:\WINDOWS\system32\DRIVERS\isapnp.sys
    2011/05/17 17:35:29.0234 3860 Kbdclass (16813155807c6881f4bfbf6657424659) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
    2011/05/17 17:35:29.0390 3860 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
    2011/05/17 17:35:29.0531 3860 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
    2011/05/17 17:35:29.0984 3860 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
    2011/05/17 17:35:30.0140 3860 Modem (510ade9327fe84c10254e1902697e25f) C:\WINDOWS\system32\drivers\Modem.sys
    2011/05/17 17:35:30.0328 3860 motmodem (b0f97021e7b56f0389168f3b5d5fb9bd) C:\WINDOWS\system32\DRIVERS\motmodem.sys
    2011/05/17 17:35:30.0437 3860 Mouclass (027c01bd7ef3349aaebc883d8a799efb) C:\WINDOWS\system32\DRIVERS\mouclass.sys
    2011/05/17 17:35:30.0578 3860 mouhid (124d6846040c79b9c997f78ef4b2a4e5) C:\WINDOWS\system32\DRIVERS\mouhid.sys
    2011/05/17 17:35:30.0765 3860 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
    2011/05/17 17:35:31.0031 3860 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
    2011/05/17 17:35:31.0203 3860 MRxSmb (0ea4d8ed179b75f8afa7998ba22285ca) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
    2011/05/17 17:35:31.0359 3860 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
    2011/05/17 17:35:31.0500 3860 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
    2011/05/17 17:35:31.0625 3860 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
    2011/05/17 17:35:31.0750 3860 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
    2011/05/17 17:35:31.0875 3860 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
    2011/05/17 17:35:32.0000 3860 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys
    2011/05/17 17:35:32.0125 3860 Mup (2f625d11385b1a94360bfc70aaefdee1) C:\WINDOWS\system32\drivers\Mup.sys
    2011/05/17 17:35:32.0250 3860 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
    2011/05/17 17:35:32.0375 3860 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
    2011/05/17 17:35:32.0546 3860 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys
    2011/05/17 17:35:32.0687 3860 NdisTapi (1ab3d00c991ab086e69db84b6c0ed78f) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
    2011/05/17 17:35:32.0828 3860 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
    2011/05/17 17:35:32.0968 3860 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
    2011/05/17 17:35:33.0125 3860 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
    2011/05/17 17:35:33.0281 3860 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
    2011/05/17 17:35:33.0500 3860 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
    2011/05/17 17:35:33.0765 3860 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
    2011/05/17 17:35:33.0921 3860 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
    2011/05/17 17:35:34.0140 3860 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
    2011/05/17 17:35:34.0281 3860 nv (71dbdc08df86b80511e72953fa1ad6b0) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
    2011/05/17 17:35:34.0484 3860 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
    2011/05/17 17:35:34.0593 3860 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
    2011/05/17 17:35:34.0781 3860 Parport (8fd0bdbea875d06ccf6c945ca9abaf75) C:\WINDOWS\system32\DRIVERS\parport.sys
    2011/05/17 17:35:34.0921 3860 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
    2011/05/17 17:35:35.0062 3860 ParVdm (9575c5630db8fb804649a6959737154c) C:\WINDOWS\system32\drivers\ParVdm.sys
    2011/05/17 17:35:35.0203 3860 PCI (043410877bda580c528f45165f7125bc) C:\WINDOWS\system32\DRIVERS\pci.sys
    2011/05/17 17:35:35.0453 3860 PCIIde (f4bfde7209c14a07aaa61e4d6ae69eac) C:\WINDOWS\system32\drivers\PCIIde.sys
    2011/05/17 17:35:35.0640 3860 Pcmcia (f0406cbc60bdb0394a0e17ffb04cdd3d) C:\WINDOWS\system32\drivers\Pcmcia.sys
    2011/05/17 17:35:36.0703 3860 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
    2011/05/17 17:35:36.0843 3860 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
    2011/05/17 17:35:37.0000 3860 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
    2011/05/17 17:35:37.0796 3860 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
    2011/05/17 17:35:37.0937 3860 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
    2011/05/17 17:35:38.0093 3860 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
    2011/05/17 17:35:38.0218 3860 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
    2011/05/17 17:35:38.0359 3860 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
    2011/05/17 17:35:38.0500 3860 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
    2011/05/17 17:35:38.0687 3860 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
    2011/05/17 17:35:38.0828 3860 RDPWD (6728e45b66f93c08f11de2e316fc70dd) C:\WINDOWS\system32\drivers\RDPWD.sys
    2011/05/17 17:35:38.0953 3860 redbook (d8eb2a7904db6c916eb5361878ddcbae) C:\WINDOWS\system32\DRIVERS\redbook.sys
    2011/05/17 17:35:39.0359 3860 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
    2011/05/17 17:35:39.0562 3860 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
    2011/05/17 17:35:39.0890 3860 Serial (93d313c31f7ad9ea2b75f26075413c7c) C:\WINDOWS\system32\DRIVERS\serial.sys
    2011/05/17 17:35:40.0109 3860 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
    2011/05/17 17:35:40.0265 3860 sfman (0b1a5e9cacb5cdd54a2815107bd7c772) C:\WINDOWS\system32\drivers\sfmanm.sys
    2011/05/17 17:35:40.0609 3860 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys
    2011/05/17 17:35:40.0890 3860 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
    2011/05/17 17:35:41.0187 3860 sr (39626e6dc1fb39434ec40c42722b660a) C:\WINDOWS\system32\DRIVERS\sr.sys
    2011/05/17 17:35:41.0390 3860 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys
    2011/05/17 17:35:42.0234 3860 StarOpen (306521935042fc0a6988d528643619b3) C:\WINDOWS\system32\drivers\StarOpen.sys
    2011/05/17 17:35:42.0390 3860 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys
    2011/05/17 17:35:42.0546 3860 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
    2011/05/17 17:35:42.0703 3860 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
    2011/05/17 17:35:43.0343 3860 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
    2011/05/17 17:35:43.0515 3860 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
    2011/05/17 17:35:43.0640 3860 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
    2011/05/17 17:35:43.0765 3860 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
    2011/05/17 17:35:43.0921 3860 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
    2011/05/17 17:35:44.0218 3860 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
    2011/05/17 17:35:44.0453 3860 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
    2011/05/17 17:35:44.0656 3860 USBAAPL (d4fb6ecc60a428564ba8768b0e23c0fc) C:\WINDOWS\system32\Drivers\usbaapl.sys
    2011/05/17 17:35:44.0781 3860 usbaudio (e919708db44ed8543a7c017953148330) C:\WINDOWS\system32\drivers\usbaudio.sys
    2011/05/17 17:35:44.0937 3860 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
    2011/05/17 17:35:45.0078 3860 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
    2011/05/17 17:35:45.0234 3860 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
    2011/05/17 17:35:45.0406 3860 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys
    2011/05/17 17:35:45.0546 3860 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
    2011/05/17 17:35:45.0718 3860 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
    2011/05/17 17:35:45.0859 3860 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
    2011/05/17 17:35:46.0046 3860 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
    2011/05/17 17:35:46.0328 3860 VolSnap (46de1126684369bace4849e4fc8c43ca) C:\WINDOWS\system32\drivers\VolSnap.sys
    2011/05/17 17:35:46.0531 3860 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
    2011/05/17 17:35:46.0671 3860 Wdf01000 (fd47474bd21794508af449d9d91af6e6) C:\WINDOWS\system32\DRIVERS\Wdf01000.sys
    2011/05/17 17:35:46.0937 3860 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
    2011/05/17 17:35:47.0234 3860 WpdUsb (cf4def1bf66f06964dc0d91844239104) C:\WINDOWS\system32\DRIVERS\wpdusb.sys
    2011/05/17 17:35:47.0343 3860 WS2IFSL (6abe6e225adb5a751622a9cc3bc19ce8) C:\WINDOWS\System32\drivers\ws2ifsl.sys
    2011/05/17 17:35:47.0500 3860 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
    2011/05/17 17:35:47.0625 3860 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
    2011/05/17 17:35:47.0765 3860 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
    2011/05/17 17:35:47.0921 3860 \HardDisk0 - detected Rootkit.Win32.TDSS.tdl4 (0)
    2011/05/17 17:35:47.0984 3860 ================================================================================
    2011/05/17 17:35:47.0984 3860 Scan finished
    2011/05/17 17:35:47.0984 3860 ================================================================================
    2011/05/17 17:35:48.0046 3852 Detected object count: 1
    2011/05/17 17:36:15.0828 3852 \HardDisk0 (Rootkit.Win32.TDSS.tdl4) - will be cured after reboot
    2011/05/17 17:36:15.0828 3852 \HardDisk0 - ok
    2011/05/17 17:36:15.0828 3852 Rootkit.Win32.TDSS.tdl4(\HardDisk0) - User select action: Cure
    2011/05/17 17:36:24.0703 3756 Deinitialize success
    0
  4. Utilisateur anonyme
     
    Bonsoir
    On va vérifier s'il reste des infections
    * Télécharge ZHPDiag (de Nicolas Coolman)
    http://www.premiumorange.com/zeb-help-process/zhpdiag.html

    Au cas où le premier lien ne marcherai pas, clique sur celui de dessous
    ftp://zebulon.fr/ZHPDiag2.exe

    * Laisse toi guider lors de l'installation, il se lancera automatiquement à la fin.
    * Surtout, n'oublie pas d'installer son icône sur le bureau
    * Clique sur l'icône représentant une loupe (« Lancer le diagnostic »)
    * Enregistre le rapport sur ton Bureau à l'aide de l'icône représentant une disquette
    Héberge le rapport ICI
    0
    1. Manong
       
      C'est fait :)
      http://up.sur-la-toile.com/iMYu
      0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. Utilisateur anonyme
     
    ton PC abrite un élevage de cochonneries, dont une grosse infection USB

    Télécharge USBFix (de El Desaparecido, C_XX) sur ton bureau
    http://www.teamxscript.org/usbfixTelechargement.html
    ou
    http://teamxscript.changelog.fr/UsbFix.html (miroir)

    # Double clic sur UsbFix présent sur ton bureau, et clique sur
    exécuter
    pour lancer l'installation qui se fera automatiquement

    # Clique sur Suppression

    # Branche toutes tes sources et données externes (clé USB, disque dur
    externe...) sans les ouvrir sur ton PC, et clique sur OK

    # La suppression est lancée. Le bureau va disparaitre, c'est normal

    # Ensuite poste le rapport UsbFix.txt qui est apparu avec le bureau .

    # Le rapport UsbFix.txt est sauvegardé a la racine du disque.( C:\UsbFix.txt )

    ( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

    0
  7. Manong
     
    Voici le rapport !
    .
    .
    .

    ############################## | UsbFix 7.045 | [Suppression]

    Utilisateur: Tommy (Administrateur) # TOMMY [ ]
    Mis à jour le 15/05/2011 par TeamXscript
    Lancé à 23:36:56 | 17/05/2011
    Site Web: http://www.teamxscript.org
    Submit your sample: http://www.teamxscript.org/Upload.php

    CPU: Intel(R) Pentium(R) 4 CPU 2.53GHz
    Microsoft Windows XP Professionnel (5.1.2600 32-Bit) # Service Pack 3
    Internet Explorer 8.0.6001.18702

    Pare-feu Windows: Activé
    Antivirus: avast! Antivirus 5.0.83952505 [(!) Disabled | Updated]
    RAM -> 767 Mo
    C:\ (%systemdrive%) -> Disque fixe # 49 Go (5 Go libre(s) - 10%) [] # NTFS
    D:\ -> CD-ROM
    E:\ -> CD-ROM
    G:\ -> Disque fixe # 149 Go (51 Go libre(s) - 34%) [Disque Local] # NTFS
    H:\ -> Disque amovible # 4 Go (4 Go libre(s) - 100%) [] # FAT32
    I:\ -> Disque amovible # 984 Mo (82 Mo libre(s) - 8%) [UDISK 2.0] # FAT

    ################## | Éléments infectieux |

    Supprimé! C:\Documents and Settings\Tommy\RavMonLog
    Supprimé! C:\Recycler\S-1-5-21-1343024091-1078145449-839522115-1003
    Supprimé! C:\Recycler\S-1-5-21-1343024091-1078145449-839522115-1004
    Supprimé! C:\Recycler\S-1-5-21-1343024091-1078145449-839522115-1006
    Supprimé! G:\Recycler\S-1-5-21-1229272821-813497703-682003330-36630
    Supprimé! G:\Recycler\S-1-5-21-1292428093-838170752-725345543-1003
    Supprimé! G:\Recycler\S-1-5-21-1292428093-838170752-725345543-1004
    Supprimé! G:\Recycler\S-1-5-21-1292428093-838170752-725345543-1005
    Supprimé! G:\Recycler\S-1-5-21-1292428093-838170752-725345543-1006
    Supprimé! G:\Recycler\S-1-5-21-1343024091-1078145449-839522115-1003
    Supprimé! G:\Recycler\S-1-5-21-1343024091-1078145449-839522115-1004
    Supprimé! G:\Recycler\S-1-5-21-1343024091-1078145449-839522115-1006
    Supprimé! G:\Recycler\S-1-5-21-1715567821-583907252-725345543-1003
    Supprimé! G:\Recycler\S-1-5-21-2052111302-1958367476-725345543-1004
    Supprimé! G:\Recycler\S-1-5-21-583907252-73586283-682003330-1004
    Supprimé! G:\Recycler\S-1-5-21-861567501-115176313-839522115-500
    Supprimé! C:\remover.exe

    ################## | Registre |

    Supprimé! HKLM\software\microsoft\windows nt\currentversion\winlogon|Taskman

    ################## | Mountpoints2 |

    Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{0c615aa9-8090-11dc-9f4c-0007e984ef91}
    Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{3ce93c2a-b18d-11dd-a497-0007e984ef91}
    Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{4f942556-cf88-11dd-a52c-0007e984ef91}
    Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{86c1f934-6d79-11dd-a33d-0007e984ef91}
    Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{90a966b0-87df-11dc-9f71-0007e984ef91}
    Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{aa8703c6-8c48-11dc-9f87-0007e984ef91}
    Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{c0b33df0-c287-11df-aab9-0007e984ef91}
    Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{c289a662-5b29-11de-a755-0007e984ef91}
    Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{d2e03eb2-89ad-11dc-9f7f-0007e984ef91}
    Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{d33b4e70-775f-11dc-9f13-0007e984ef91}
    Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{ee494abb-6ddf-11dc-9edd-0007e984ef91}

    ################## | Listing |

    [19/09/2007 - 17:27:50 | N | 0] C:\AUTOEXEC.BAT
    [19/09/2007 - 17:23:18 | SH | 212] C:\boot.ini
    [28/08/2001 - 14:00:00 | N | 4952] C:\Bootfont.bin
    [16/05/2011 - 23:41:21 | N | 39657] C:\bootkit_remover_debug_log.txt
    [27/03/2010 - 22:49:55 | N | 74] C:\CMLoader.log
    [15/05/2011 - 18:02:27 | HD ] C:\Config.Msi
    [19/09/2007 - 17:27:50 | N | 0] C:\CONFIG.SYS
    [07/06/2008 - 19:28:47 | D ] C:\ConvertTemp
    [16/05/2011 - 23:41:08 | N | 74] C:\copymbr.bat
    [16/05/2011 - 23:40:41 | N | 74] C:\COPYMBR;BAT.txt
    [27/02/2008 - 18:46:26 | N | 133] C:\DealioAu.log
    [19/09/2007 - 17:58:57 | D ] C:\dell
    [25/04/2011 - 21:20:46 | D ] C:\Documents and Settings
    [19/09/2007 - 17:27:50 | N | 0] C:\IO.SYS
    [20/09/2007 - 17:40:46 | N | 183] C:\LogiSetup.log
    [19/09/2007 - 17:27:50 | N | 0] C:\MSDOS.SYS
    [13/05/2008 - 20:51:13 | D ] C:\MSOCache
    [03/08/2004 - 22:38:34 | N | 47564] C:\NTDETECT.COM
    [21/03/2010 - 14:33:18 | N | 252240] C:\ntldr
    [17/05/2011 - 17:37:34 | ASH | 805306368] C:\pagefile.sys
    [17/05/2011 - 23:13:24 | N | 512] C:\PhysicalDisk0_MBR.bin
    [17/05/2011 - 23:04:11 | D ] C:\Program Files
    [17/05/2011 - 23:42:49 | SHD ] C:\RECYCLER
    [29/12/2007 - 20:35:29 | N | 268] C:\sqmdata00.sqm
    [14/03/2008 - 18:51:34 | N | 268] C:\sqmdata01.sqm
    [29/03/2008 - 10:41:54 | N | 268] C:\sqmdata02.sqm
    [07/04/2008 - 13:50:17 | N | 232] C:\sqmdata03.sqm
    [07/04/2008 - 20:29:09 | N | 268] C:\sqmdata04.sqm
    [10/06/2008 - 21:19:05 | N | 268] C:\sqmdata05.sqm
    [06/09/2008 - 22:46:23 | N | 268] C:\sqmdata06.sqm
    [13/09/2008 - 22:37:47 | N | 268] C:\sqmdata07.sqm
    [29/09/2008 - 21:14:50 | N | 268] C:\sqmdata08.sqm
    [29/09/2008 - 22:06:31 | N | 268] C:\sqmdata09.sqm
    [25/10/2008 - 16:36:38 | N | 268] C:\sqmdata10.sqm
    [29/10/2008 - 19:35:55 | N | 268] C:\sqmdata11.sqm
    [12/01/2009 - 22:26:19 | N | 268] C:\sqmdata12.sqm
    [06/02/2009 - 04:52:01 | N | 232] C:\sqmdata13.sqm
    [06/02/2009 - 23:22:53 | N | 268] C:\sqmdata14.sqm
    [13/03/2009 - 19:16:13 | N | 268] C:\sqmdata15.sqm
    [13/03/2009 - 23:25:58 | N | 268] C:\sqmdata16.sqm
    [13/04/2009 - 02:07:05 | N | 268] C:\sqmdata17.sqm
    [29/12/2007 - 20:35:29 | N | 244] C:\sqmnoopt00.sqm
    [14/03/2008 - 18:51:34 | N | 244] C:\sqmnoopt01.sqm
    [29/03/2008 - 10:41:54 | N | 244] C:\sqmnoopt02.sqm
    [07/04/2008 - 13:50:17 | N | 244] C:\sqmnoopt03.sqm
    [07/04/2008 - 20:29:09 | N | 172] C:\sqmnoopt04.sqm
    [10/06/2008 - 21:19:05 | N | 244] C:\sqmnoopt05.sqm
    [06/09/2008 - 22:46:23 | N | 244] C:\sqmnoopt06.sqm
    [13/09/2008 - 22:37:47 | N | 244] C:\sqmnoopt07.sqm
    [29/09/2008 - 21:14:50 | N | 244] C:\sqmnoopt08.sqm
    [29/09/2008 - 22:06:31 | N | 244] C:\sqmnoopt09.sqm
    [25/10/2008 - 16:36:38 | N | 244] C:\sqmnoopt10.sqm
    [29/10/2008 - 19:35:55 | N | 244] C:\sqmnoopt11.sqm
    [12/01/2009 - 22:26:19 | N | 244] C:\sqmnoopt12.sqm
    [06/02/2009 - 04:52:01 | N | 244] C:\sqmnoopt13.sqm
    [06/02/2009 - 23:22:53 | N | 244] C:\sqmnoopt14.sqm
    [13/03/2009 - 19:16:13 | N | 244] C:\sqmnoopt15.sqm
    [13/03/2009 - 23:25:58 | N | 244] C:\sqmnoopt16.sqm
    [13/04/2009 - 02:07:05 | N | 244] C:\sqmnoopt17.sqm
    [30/04/2011 - 10:58:15 | SHD ] C:\System Volume Information
    [17/05/2011 - 17:36:24 | N | 39930] C:\TDSSKiller.2.5.1.0_17.05.2011_17.35.07_log.txt
    [16/05/2011 - 23:41:21 | N | 512] C:\tralala
    [17/05/2011 - 23:42:49 | D ] C:\UsbFix
    [17/05/2011 - 23:44:04 | A | 2176] C:\UsbFix.txt
    [17/05/2011 - 22:41:34 | D ] C:\WINDOWS
    [26/04/2007 - 18:07:12 | D ] G:\&Save
    [20/09/2009 - 20:47:37 | D ] G:\Appareil
    [23/03/2011 - 23:52:13 | D ] G:\APPAREIL PHOTO
    [15/08/2009 - 02:01:03 | D ] G:\cac9445248e2f8a43fff6f
    [06/09/2005 - 10:08:26 | D ] G:\f0d15ac85da7ca4e1a
    [19/03/2011 - 13:23:55 | D ] G:\Laurence
    [15/05/2011 - 17:01:30 | D ] G:\Lena
    [25/04/2011 - 16:20:59 | D ] G:\Manon
    [16/05/2011 - 23:20:13 | N | 361326] G:\manonsauvegarde.reg
    [16/05/2011 - 23:21:22 | N | 5110] G:\manonsauvergarde2.reg
    [16/05/2011 - 23:21:50 | N | 454] G:\manonsauvergarde3.reg
    [27/03/2011 - 17:30:36 | D ] G:\Mes fichiers reçus
    [06/09/2005 - 09:15:56 | D ] G:\MSOCache
    [08/09/2010 - 21:36:21 | D ] G:\Office 2007 Portable by Servius
    [14/11/2010 - 17:21:52 | D ] G:\Photos + docu
    [17/05/2011 - 23:42:49 | SHD ] G:\RECYCLER
    [24/04/2011 - 22:20:02 | D ] G:\Saved
    [30/04/2011 - 13:32:51 | SHD ] G:\System Volume Information
    [30/10/2006 - 22:43:48 | ASH | 48640] G:\Thumbs.db
    [11/03/2011 - 23:48:36 | D ] G:\Tommy
    [04/04/2011 - 21:14:12 | D ] G:\_ISTMP1.DIR

    ################## | Vaccin |

    C:\Autorun.inf -> Vaccin créé par UsbFix (TeamXscript)
    G:\Autorun.inf -> Vaccin créé par UsbFix (TeamXscript)
    0
  8. Utilisateur anonyme
     
    on continuera demain, car il est tard y'en encore à faire
    0
    1. Manong
       
      D'accord merci merci merci encore de m'accorder du temps !
      0
  9. Utilisateur anonyme
     
    Bonjour
    On va continuer
    Les toolbars ne servent à rien. Certaines sont néfastes et espionnent ta navigation
    Certaines sont inutiles, elles ne font qu'alourdir la navigation
    Soit vigilent lorsque tu installes ou met à jour un logiciel gratuit
    Lit bien les instructions, et décoche la case sur les suppléments qu'on te propose
    telle que les barres d'outil comme Ask, Kiwee, Search Setting, Crawler, Daemon
    (à ne pas confondre avec le logiciel Daemon), Dealio qui sont les plus fréquentes
    et néfastes
    Les toolbars, c'est pas obligatoire
    Je vais te donner ceci en passant, c'est à lire
    https://forum.malekal.com/viewtopic.php?f=45&t=6173

    Télécharge Ad-Remover (de C_XX) sur ton bureau:
    http://www.teamxscript.org/adremoverTelechargement.html ( Lien officiel )
    https://www.androidworld.fr/ ( Miroir )
    [b]Désactive l'anti-virus/b

    Double clique sur le fichier que tu viens de télécharger, à l'écran qui apparait, clique sur [b]Scanner/b.
    Laisse travailler l'outil.
    Poste le rapport qui s'affiche à l'écran quand l'analyse est terminée.
    Il est sauvegardé dans [b]C:\Ad-Remover-SCAN[1].txt/b

    0
    1. manong
       
      Bonjour !
      J'essaye d'être la plus vigilante possible, mais toute ma famille utilise l'ordinateur, et tout le monde fait un peu n'importe quoi, donc c'est un peu compliqué. Voilà le rapport :

      ======= RAPPORT D'AD-REMOVER 2.0.0.2,G | UNIQUEMENT XP/VISTA/7 =======

      Mis à jour par TeamXscript le 12/04/11
      Contact: AdRemover[DOT]contact[AT]gmail[DOT]com
      Site web: http://www.teamxscript.org

      C:\Program Files\Ad-Remover\main.exe (SCAN [1]) -> Lancé à 13:48:06 le 18/05/2011, Mode normal

      Microsoft Windows XP Professionnel Service Pack 3 (X86)
      TommyTOMMY ( )

      ============== RECHERCHE ==============


      Fichier trouvé: C:\Documents and Settings\Tommy\Application Data\Mozilla\FireFox\Profiles\d0r6l0pr.default\searchplugins\ask.xml
      Dossier trouvé: C:\Documents and Settings\Tommy\Local Settings\Application Data\Conduit
      Dossier trouvé: C:\Documents and Settings\Lena\Application Data\Dealio
      Dossier trouvé: C:\Program Files\webHancer

      -- Fichier ouvert: C:\Documents and Settings\Tommy\Application Data\Mozilla\FireFox\Profiles\d0r6l0pr.default\Prefs.js --
      Ligne trouvée: user_pref("browser.search.defaultenginename", "Ask");
      Ligne trouvée: user_pref("browser.search.order.1", "Ask");
      Ligne trouvée: user_pref("extensions.snipit.askTbInstalled", true);
      Ligne trouvée: user_pref("extensions.snipit.chromeURL", "hxxp://toolbar.ask.com/toolbarv/askRedirect?o=13165&gct=&g...
      Ligne trouvée: user_pref("keyword.URL", "hxxp://toolbar.ask.com/toolbarv/askRedirect?o=13165&gct=&gc=1&q=");
      -- Fichier Fermé --


      Clé trouvée: HKLM\Software\Classes\Interface\{03C390E8-B836-4B82-8D56-1BFDDC06AE8A}
      Clé trouvée: HKLM\Software\Classes\Interface\{2C4470A2-E099-4B9E-ABFE-BBA56D046AFD}
      Clé trouvée: HKLM\Software\Classes\Interface\{391769AE-D8EC-45EC-967D-F5120456E514}
      Clé trouvée: HKLM\Software\Classes\Interface\{39AEF150-C270-4690-AE7D-955E51BC8960}
      Clé trouvée: HKLM\Software\Classes\Interface\{CD73B1AB-3403-4E47-B196-517C57BE76A2}
      Clé trouvée: HKLM\Software\Classes\TypeLib\{A471012F-E2E5-48EB-9A8B-9D4090B1D0C7}
      Clé trouvée: HKLM\Software\Classes\Conduit.Engine
      Clé trouvée: HKLM\Software\Classes\Dealio.CDealioSidebar
      Clé trouvée: HKLM\Software\Classes\Dealio.CDealioSidebar.1
      Clé trouvée: HKLM\Software\Classes\Dealio.DealioBHO
      Clé trouvée: HKLM\Software\Classes\Dealio.DealioBHO.1
      Clé trouvée: HKLM\Software\Classes\Dealio.DealioSearch
      Clé trouvée: HKLM\Software\Classes\Dealio.DealioSearch.1
      Clé trouvée: HKLM\Software\Classes\Dealio.DealioToolbar
      Clé trouvée: HKLM\Software\Classes\Dealio.DealioToolbar.1
      Clé trouvée: HKLM\Software\Classes\Dealio.DealioToolbarHelper
      Clé trouvée: HKLM\Software\Classes\Dealio.DealioToolbarHelper.1
      Clé trouvée: HKLM\Software\Classes\Sidebar.SESidebar
      Clé trouvée: HKLM\Software\Classes\Sidebar.SESidebar.1
      Clé trouvée: HKLM\Software\Classes\Sidebar.SidebarLogic
      Clé trouvée: HKLM\Software\Classes\Sidebar.SidebarLogic.1
      Clé trouvée: HKLM\Software\Classes\Toolbar.CT2583879
      Clé trouvée: HKLM\Software\AskBarDis
      Clé trouvée: HKCU\Software\AppDataLow\AskBarDis
      Clé trouvée: HKCU\Software\AppDataLow\AskSA
      Clé trouvée: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}
      Clé trouvée: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{CF739809-1C6C-47C0-85B9-569DBB141420}
      Clé trouvée: HKCU\Software\Microsoft\Internet Explorer\Explorer Bars\{315108E4-E3AF-460F-B264-F2ACC9E1ACEB}

      Valeur trouvée: HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks|{C94E154B-1459-4A47-966B-4B843BEFC7DB}
      Valeur trouvée: HKCU\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser|{3041D03E-FD4B-44E0-B742-2D9B88305F98}
      Valeur trouvée: HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser|{3041D03E-FD4B-44E0-B742-2D9B88305F98}
      Valeur trouvée: HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser|{E67C74F4-A00A-4F2C-9FEC-FD9DC004A67F}


      ============== SCAN ADDITIONNEL ==============

      **** Mozilla Firefox Version [4.0.1 (fr)] ****

      Searchplugins\bing.xml ( hxxp://www.bing.com/search)
      Components\browsercomps.dll (Mozilla Foundation)

      -- C:\Documents and Settings\Tommy\Application Data\Mozilla\FireFox\Profiles\d0r6l0pr.default --
      Extensions\2020Player 2020Technologies.com (20-20 3D Viewer)
      Searchplugins\ask.xml (?)
      Prefs.js - browser.download.lastDir, G:\\Manon\\0 ROCK 6 0
      Prefs.js - browser.search.defaultenginename, Ask
      Prefs.js - browser.search.selectedEngine, Google
      Prefs.js - browser.startup.homepage, hxxp://www.google.fr/
      Prefs.js - browser.startup.homepage_override.buildID, 20110413222027
      Prefs.js - browser.startup.homepage_override.mstone, rv:2.0.1
      Prefs.js - keyword.URL, hxxp://toolbar.ask.com/toolbarv/askRedirect?o=13165&gct=&gc=1&q=

      -- C:\Documents and Settings\Administrateur\Application Data\Mozilla\FireFox\Profiles\p73f0twj.default --
      Prefs.js - browser.startup.homepage_override.mstone, rv:1.9.1.18

      -- C:\Documents and Settings\Laurence\Application Data\Mozilla\FireFox\Profiles\bcaf8yub.default --
      Prefs.js - browser.download.lastDir, G:\\Manon
      Prefs.js - browser.startup.homepage_override.mstone, rv:1.9.1.16

      -- C:\Documents and Settings\Lena\Application Data\Mozilla\FireFox\Profiles\2ss05jkv.default --
      Extensions\ffxtlbr babylon.com (Babylon)
      Prefs.js - browser.startup.homepage_override.buildID, 20110413222027
      Prefs.js - browser.startup.homepage_override.mstone, rv:2.0.1
      Prefs.js - keyword.URL, hxxp://search.babylon.com/?babsrc=SP_ss&mntrId=c4484f690000000000000007e984ef91&tlver=1.4.19.19&instlRef=ss...

      ========================================

      **** Internet Explorer Version [8.0.6001.18702] ****

      HKCU_Main|Default_Page_URL - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
      HKCU_Main|Default_Search_URL - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
      HKCU_Main|Search bar - hxxp://go.microsoft.com/fwlink/?linkid=54896
      HKCU_Main|Search Page - hxxp://go.microsoft.com/fwlink/?LinkId=54896
      HKCU_Main|Start Page - hxxp://fr.msn.com/
      HKLM_Main|Default_Page_URL - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
      HKLM_Main|Default_Search_URL - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
      HKLM_Main|Search bar - hxxp://search.msn.com/spbasic.htm
      HKLM_Main|Search Page - hxxp://go.microsoft.com/fwlink/?LinkId=54896
      HKLM_Main|Start Page - hxxp://fr.msn.com/
      HKCU_URLSearchHooks|{C94E154B-1459-4A47-966B-4B843BEFC7DB} (x)
      HKCU_SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b} - "Tom's Guide France Customized Web Search" (hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT...)
      HKCU_SearchScopes\{CF739809-1C6C-47C0-85B9-569DBB141420} - "Ask Search" (hxxp://toolbar.ask.com/toolbarv/askRedirect?gct=&gc=1&q={searchTerms}&crm=1&tool...)
      HKCU_Toolbar\ShellBrowser|{3041D03E-FD4B-44E0-B742-2D9B88305F98} (x)
      HKCU_Toolbar\WebBrowser|{E67C74F4-A00A-4F2C-9FEC-FD9DC004A67F} (x)
      HKCU_Toolbar\WebBrowser|{3041D03E-FD4B-44E0-B742-2D9B88305F98} (x)
      HKLM_Extensions\{e2e2dd38-d088-4134-82b7-f2ba38496583} - "?" (?)
      BHO\{5C255C8A-E604-49b4-9D64-90988571CECB} (?)

      ========================================

      C:\Program Files\Ad-Remover\Quarantine: 0 Fichier(s)
      C:\Program Files\Ad-Remover\Backup: 1 Fichier(s)

      C:\Ad-Report-SCAN[1].txt - 18/05/2011 13:48:17 (6787 Octet(s))

      Fin à: 13:49:24, 18/05/2011

      ============== E.O.F ==============
      0
  10. Utilisateur anonyme
     
    Il va falloir passer le mot qu'il y a des cochonneries de plus en plus coriaces qui
    trainent sur le net, moi, j'interdirais l'accès au PC
    Si tu les laisses faire n'importe quoi, tu risques de revenir pour désinfecter le PC

    Double clique sur AD Remover, et clique sur Nettoyer.
    Laisse travailler l'outil.
    Poste le rapport qui s'affiche à l'écran quand l'analyse est terminée.
    Il est sauvegardé dans C:\Ad-Remover-CLEAN[1].txt

    0
    1. manong
       
      Je vais essayer de les surveillez le plus possible. En attendant, le rapport :

      ======= RAPPORT D'AD-REMOVER 2.0.0.2,G | UNIQUEMENT XP/VISTA/7 =======

      Mis à jour par TeamXscript le 12/04/11
      Contact: AdRemover[DOT]contact[AT]gmail[DOT]com
      Site web: http://www.teamxscript.org

      C:\Program Files\Ad-Remover\main.exe (CLEAN [1]) -> Lancé à 13:59:06 le 18/05/2011, Mode normal

      Microsoft Windows XP Professionnel Service Pack 3 (X86)
      Tommy TOMMY ( )

      ============== ACTION(S) ==============


      Fichier supprimé: C:\Documents and Settings\Tommy\Application Data\Mozilla\FireFox\Profiles\d0r6l0pr.default\searchplugins\ask.xml
      Dossier supprimé: C:\Documents and Settings\Tommy\Local Settings\Application Data\Conduit
      Dossier supprimé: C:\Documents and Settings\Lena\Application Data\Dealio
      Dossier supprimé: C:\Program Files\webHancer

      (!) -- Fichiers temporaires supprimés.


      -- Fichier ouvert: C:\Documents and Settings\Tommy\Application Data\Mozilla\FireFox\Profiles\d0r6l0pr.default\Prefs.js --
      Ligne supprimée: user_pref("browser.search.defaultenginename", "Ask");
      Ligne supprimée: user_pref("browser.search.order.1", "Ask");
      Ligne supprimée: user_pref("extensions.snipit.askTbInstalled", true);
      Ligne supprimée: user_pref("extensions.snipit.chromeURL", "hxxp://toolbar.ask.com/toolbarv/askRedirect?o=13165&gct=&g...
      Ligne supprimée: user_pref("keyword.URL", "hxxp://toolbar.ask.com/toolbarv/askRedirect?o=13165&gct=&gc=1&q=");
      -- Fichier Fermé --


      Clé supprimée: HKLM\Software\Classes\Interface\{03C390E8-B836-4B82-8D56-1BFDDC06AE8A}
      Clé supprimée: HKLM\Software\Classes\Interface\{2C4470A2-E099-4B9E-ABFE-BBA56D046AFD}
      Clé supprimée: HKLM\Software\Classes\Interface\{391769AE-D8EC-45EC-967D-F5120456E514}
      Clé supprimée: HKLM\Software\Classes\Interface\{39AEF150-C270-4690-AE7D-955E51BC8960}
      Clé supprimée: HKLM\Software\Classes\Interface\{CD73B1AB-3403-4E47-B196-517C57BE76A2}
      Clé supprimée: HKLM\Software\Classes\TypeLib\{A471012F-E2E5-48EB-9A8B-9D4090B1D0C7}
      Clé supprimée: HKLM\Software\Classes\Conduit.Engine
      Clé supprimée: HKLM\Software\Classes\Dealio.CDealioSidebar
      Clé supprimée: HKLM\Software\Classes\Dealio.CDealioSidebar.1
      Clé supprimée: HKLM\Software\Classes\Dealio.DealioBHO
      Clé supprimée: HKLM\Software\Classes\Dealio.DealioBHO.1
      Clé supprimée: HKLM\Software\Classes\Dealio.DealioSearch
      Clé supprimée: HKLM\Software\Classes\Dealio.DealioSearch.1
      Clé supprimée: HKLM\Software\Classes\Dealio.DealioToolbar
      Clé supprimée: HKLM\Software\Classes\Dealio.DealioToolbar.1
      Clé supprimée: HKLM\Software\Classes\Dealio.DealioToolbarHelper
      Clé supprimée: HKLM\Software\Classes\Dealio.DealioToolbarHelper.1
      Clé supprimée: HKLM\Software\Classes\Sidebar.SESidebar
      Clé supprimée: HKLM\Software\Classes\Sidebar.SESidebar.1
      Clé supprimée: HKLM\Software\Classes\Sidebar.SidebarLogic
      Clé supprimée: HKLM\Software\Classes\Sidebar.SidebarLogic.1
      Clé supprimée: HKLM\Software\Classes\Toolbar.CT2583879
      Clé supprimée: HKLM\Software\AskBarDis
      Clé supprimée: HKCU\Software\AppDataLow\AskBarDis
      Clé supprimée: HKCU\Software\AppDataLow\AskSA
      Clé supprimée: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}
      Clé supprimée: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{CF739809-1C6C-47C0-85B9-569DBB141420}
      Clé supprimée: HKCU\Software\Microsoft\Internet Explorer\Explorer Bars\{315108E4-E3AF-460F-B264-F2ACC9E1ACEB}

      Valeur supprimée: HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks|{C94E154B-1459-4A47-966B-4B843BEFC7DB}
      Valeur supprimée: HKCU\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser|{3041D03E-FD4B-44E0-B742-2D9B88305F98}
      Valeur supprimée: HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser|{3041D03E-FD4B-44E0-B742-2D9B88305F98}
      Valeur supprimée: HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser|{E67C74F4-A00A-4F2C-9FEC-FD9DC004A67F}


      ============== SCAN ADDITIONNEL ==============

      **** Mozilla Firefox Version [4.0.1 (fr)] ****

      Searchplugins\bing.xml ( hxxp://www.bing.com/search)
      Components\browsercomps.dll (Mozilla Foundation)

      -- C:\Documents and Settings\Tommy\Application Data\Mozilla\FireFox\Profiles\d0r6l0pr.default --
      Extensions\2020Player 2020Technologies.com (20-20 3D Viewer)
      Prefs.js - browser.download.lastDir, C:\\Documents and Settings\\Tommy\\Bureau
      Prefs.js - browser.search.defaultenginename, Ask
      Prefs.js - browser.search.selectedEngine, Google
      Prefs.js - browser.startup.homepage, hxxp://www.google.fr/
      Prefs.js - browser.startup.homepage_override.buildID, 20110413222027
      Prefs.js - browser.startup.homepage_override.mstone, rv:2.0.1
      Prefs.js - keyword.URL, hxxp://toolbar.ask.com/toolbarv/askRedirect?o=13165&gct=&gc=1&q=

      -- C:\Documents and Settings\Administrateur\Application Data\Mozilla\FireFox\Profiles\p73f0twj.default --
      Prefs.js - browser.startup.homepage_override.mstone, rv:1.9.1.18

      -- C:\Documents and Settings\Laurence\Application Data\Mozilla\FireFox\Profiles\bcaf8yub.default --
      Prefs.js - browser.download.lastDir, G:\\Manon
      Prefs.js - browser.startup.homepage_override.mstone, rv:1.9.1.16

      -- C:\Documents and Settings\Lena\Application Data\Mozilla\FireFox\Profiles\2ss05jkv.default --
      Extensions\ffxtlbr babylon.com (Babylon)
      Prefs.js - browser.startup.homepage_override.buildID, 20110413222027
      Prefs.js - browser.startup.homepage_override.mstone, rv:2.0.1
      Prefs.js - keyword.URL, hxxp://search.babylon.com/?babsrc=SP_ss&mntrId=c4484f690000000000000007e984ef91&tlver=1.4.19.19&instlRef=ss...

      ========================================

      **** Internet Explorer Version [8.0.6001.18702] ****

      HKCU_Main|Default_Page_URL - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
      HKCU_Main|Default_Search_URL - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
      HKCU_Main|Search bar - hxxp://go.microsoft.com/fwlink/?linkid=54896
      HKCU_Main|Start Page - hxxp://fr.msn.com/
      HKLM_Main|Default_Page_URL - hxxp://go.microsoft.com/fwlink/?LinkId=54896
      HKLM_Main|Default_Search_URL - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
      HKLM_Main|Search bar - hxxp://search.msn.com/spbasic.htm
      HKLM_Main|Search Page - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
      HKLM_Main|Start Page - hxxp://fr.msn.com/
      HKLM_Extensions\{e2e2dd38-d088-4134-82b7-f2ba38496583} - "?" (?)
      BHO\{5C255C8A-E604-49b4-9D64-90988571CECB} (?)

      ========================================

      C:\Program Files\Ad-Remover\Quarantine: 279 Fichier(s)
      C:\Program Files\Ad-Remover\Backup: 15 Fichier(s)

      C:\Ad-Report-CLEAN[1].txt - 18/05/2011 13:59:11 (1406 Octet(s))
      C:\Ad-Report-SCAN[1].txt - 18/05/2011 13:48:17 (7191 Octet(s))

      Fin à: 14:00:25, 18/05/2011

      ============== E.O.F ==============
      0
  11. Utilisateur anonyme
     
    Pourrais tu me refaire ZHPDiag, héberge le rapport, et donne le lien
    0
    1. manong
       
      http://up.sur-la-toile.com/iMZh
      0
  12. Utilisateur anonyme
     
    Attention, cet outil n'est pas à utiliser à la légère, et doit
    être recommandé que par une personne formée à cet outil

    Imprime la procédure

    Télécharge ComboFix de sUBs sur ton Bureau :
    http://download.bleepingcomputer.com/sUBs/ComboFix.exe

    tutoriel pour bien utiliser l'outil
    http://www.bleepingcomputer.com/combofix/fr/comment-utiliser­-combofix

    /!\ Déconnecte-toi du net et DESACTIVE TOUTES LES DEFENSES, antivirus et antispyware y compris /!\
    ---> Double-clique sur ComboFix.exe
    Un "pop-up" va apparaître qui dit que ComboFix est utilisé à vos risques et avec aucune garantie... Clique sur oui pour accepter
    Surtout, accepte d'installer la console de récupération
    ---> Mets-le en langue française F
    Tape sur la touche 1 (Yes) pour démarrer le scan.

    Ne touche à rien(souris, clavier) tant que le scan n'est pas terminé, car tu risques de figer ton PC

    En fin de scan, il est possible que ComboFix ait besoin de redémarrer le PC pour finaliser la désinfection, laisse-le faire.

    Une fois le scan achevé, un rapport va s'afficher : Poste son contenu

    /!\ Réactive la protection en temps réel de ton antivirus et de ton antispyware avant de te reconnecter à Internet. /!\

    Note : Le rapport se trouve également là : C:\ComboFix.txt

    Attention, il te reste que 2 GO d'espace disque il va falloir libérer de l'espace

    O.o°*??? Ex Nathandre aux 12938 messages depuis le 27.10.2008 °.Oø¤º°'°º¤ø
    0
  13. manong
     
    Désolée pour le temps que ça m'a mis à répondre, j'ai eu un empèchement.

    ComboFix 11-05-17.01 - Tommy 18/05/2011 14:48:39.1.1 - x86
    Microsoft Windows XP Professionnel 5.1.2600.3.1252.33.1036.18.767.482 [GMT 2:00]
    Lancé depuis: c:\documents and settings\Tommy\Bureau\ComboFix.exe
    AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
    .
    .
    (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    c:\documents and settings\Tommy\Application Data\Adobe\plugs
    c:\documents and settings\Tommy\Application Data\Adobe\shed
    .
    c:\windows\system32\imm32.dll . . . est infecté!!
    .
    .
    ((((((((((((((((((((((((((((( Fichiers créés du 2011-04-18 au 2011-05-18 ))))))))))))))))))))))))))))))))))))
    .
    .
    2011-05-18 11:48 . 2011-05-18 11:48 -------- d-----w- c:\program files\Ad-Remover
    2011-05-17 21:34 . 2011-05-17 21:42 -------- d-----w- C:\UsbFix
    2011-05-17 21:13 . 2011-05-18 12:21 512 ----a-w- C:\PhysicalDisk0_MBR.bin
    2011-05-17 21:04 . 2011-05-18 12:21 -------- d-----w- c:\program files\ZHPDiag
    2011-05-16 21:41 . 2011-05-16 21:41 74 ------w- C:\copymbr.bat
    2011-05-15 16:02 . 2011-05-15 16:02 -------- d-----w- c:\documents and settings\Tommy\Application Data\MSNInstaller
    2011-05-13 23:28 . 2011-05-13 23:28 -------- d-----w- c:\program files\iPod
    2011-05-13 23:27 . 2011-05-13 23:29 -------- d-----w- c:\program files\iTunes
    2011-05-13 23:19 . 2011-05-13 23:19 -------- d-----w- c:\program files\Bonjour
    2011-05-04 12:45 . 2011-05-04 12:45 -------- d-----w- c:\documents and settings\NetworkService\Mes documents
    2011-05-03 17:28 . 2011-05-17 21:20 1324 ----a-w- c:\windows\system32\d3d9caps.tmp
    2011-05-01 08:58 . 2011-05-01 08:58 -------- d-----w- c:\documents and settings\All Users\Application Data\nView_Profiles
    2011-04-30 12:46 . 2011-05-16 20:40 -------- d-----w- c:\documents and settings\All Users\Application Data\gA31000FmEoK31000
    2011-04-30 12:45 . 2011-05-04 12:45 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
    2011-04-27 21:04 . 2011-04-27 21:04 -------- d-----r- c:\documents and settings\LocalService\Favoris
    2011-04-27 19:56 . 2011-04-27 20:27 -------- d-----w- c:\documents and settings\Tommy\Application Data\WindSolutions
    2011-04-27 19:56 . 2011-04-27 20:02 -------- d-----w- c:\documents and settings\All Users\Application Data\WindSolutions
    2011-04-27 18:27 . 2011-04-27 18:27 -------- d-----w- c:\program files\CCleaner
    2011-04-26 17:12 . 2011-04-26 17:12 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
    2011-04-26 15:41 . 2011-04-26 15:41 -------- d-sh--w- c:\documents and settings\NetworkService\PrivacIE
    2011-04-26 15:38 . 2011-04-26 15:38 -------- d-sh--w- c:\documents and settings\NetworkService\IECompatCache
    2011-04-26 15:37 . 2011-04-26 15:39 -------- d-----r- c:\documents and settings\NetworkService\Favoris
    2011-04-25 20:16 . 2011-04-25 20:16 -------- d-----w- c:\documents and settings\Tommy\Application Data\Malwarebytes
    2011-04-25 19:27 . 2011-04-25 19:27 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
    2011-04-25 19:27 . 2010-12-20 16:09 38224 ----a-r- c:\windows\system32\drivers\mbamswissarmy.sys
    2011-04-25 19:27 . 2011-04-25 19:27 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
    2011-04-25 19:27 . 2010-12-20 16:08 20952 ----a-r- c:\windows\system32\drivers\mbam.sys
    2011-04-25 19:20 . 2011-04-25 19:20 -------- d-----w- c:\documents and settings\Administrateur
    2011-04-25 19:01 . 2011-04-25 19:01 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache
    .
    .
    .
    (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2011-04-06 14:20 . 2011-04-06 14:20 91424 ----a-w- c:\windows\system32\dnssd.dll
    2011-04-06 14:20 . 2011-04-06 14:20 75040 ----a-w- c:\windows\system32\jdns_sd.dll
    2011-04-06 14:20 . 2011-04-06 14:20 197920 ----a-w- c:\windows\system32\dnssdX.dll
    2011-04-06 14:20 . 2011-04-06 14:20 107808 ----a-w- c:\windows\system32\dns-sd.exe
    2011-03-07 05:33 . 2007-09-19 15:25 692736 ----a-r- c:\windows\system32\inetcomm.dll
    2011-03-04 06:36 . 2004-08-19 14:09 420864 ----a-r- c:\windows\system32\vbscript.dll
    2011-03-03 13:53 . 2004-08-19 14:00 1858048 ----a-r- c:\windows\system32\win32k.sys
    2011-02-22 23:05 . 2004-08-19 14:09 916480 ----a-r- c:\windows\system32\wininet.dll
    2011-02-22 23:05 . 2004-08-19 14:10 1469440 ----a-r- c:\windows\system32\inetcpl.cpl
    2011-02-22 23:05 . 2004-08-19 14:09 43520 ----a-r- c:\windows\system32\licmgr10.dll
    2011-02-22 11:42 . 2004-08-19 13:56 385024 ----a-r- c:\windows\system32\html.iec
    2011-02-18 14:36 . 2009-04-19 18:14 4184352 ----a-r- c:\windows\system32\usbaaplrc.dll
    2011-02-18 14:36 . 2007-12-09 10:57 41984 ----a-r- c:\windows\system32\drivers\usbaapl.sys
    2011-02-17 13:18 . 2004-08-03 21:15 455936 ----a-r- c:\windows\system32\drivers\mrxsmb.sys
    2011-02-17 13:18 . 2004-08-03 21:14 357888 ----a-r- c:\windows\system32\drivers\srv.sys
    2008-11-18 21:30 . 2008-11-18 21:30 20724432 -c--a-w- c:\program files\DivXInstaller.exe
    2008-11-18 20:28 . 2008-11-18 20:28 352461 -c--a-w- c:\program files\divx player.exe
    2007-11-16 00:45 . 2007-11-16 00:45 17837056 -c--a-w- c:\program files\VeohSetup-3.7.0.1020.exe
    2007-10-19 18:30 . 2007-10-19 18:30 11811416 -c--a-w- c:\program files\rp505fra.exe
    2011-04-14 16:47 . 2011-04-30 12:16 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
    .
    .
    ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
    REGEDIT4
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-06-02 148888]
    "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
    "AppleSyncNotifier"="c:\program files\Fichiers communs\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-10-08 47904]
    "avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2011-01-13 3396624]
    "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-04-26 421160]
    "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-11-29 421888]
    .
    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
    .
    [HKLM\~\startupfolder\C:^Documents and Settings^Tommy^Menu Démarrer^Programmes^Démarrage^OpenOffice.org 2.3.lnk]
    path=c:\documents and settings\Tommy\Menu Démarrer\Programmes\Démarrage\OpenOffice.org 2.3.lnk
    backup=c:\windows\pss\OpenOffice.org 2.3.lnkStartup
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
    2011-04-26 23:22 421160 ----a-w- c:\program files\iTunes\iTunesHelper.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
    2010-11-29 16:38 421888 ----a-w- c:\program files\QuickTime\QTTask.exe
    .
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall"= 0 (0x0)
    .
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\Program Files\\Messenger\\msmsgs.exe"=
    "c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
    "c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
    "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
    "c:\\Program Files\\iTunes\\iTunes.exe"=
    .
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "13541:TCP"= 13541:TCP:NortonAV
    "12733:TCP"= 12733:TCP:NortonAV
    "14913:TCP"= 14913:TCP:NortonAV
    .
    R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [08/05/2009 21:16 294608]
    R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [08/05/2009 21:16 17744]
    S0 rehjfqp;rehjfqp;c:\windows\system32\drivers\agai.sys --> c:\windows\system32\drivers\agai.sys [?]
    S2 kydftmhp;Print Class for IEEE-1284.4 HPZipr12Helper;c:\windows\System32\svchost.exe -k netsvcs [19/08/2004 16:10 14336]
    S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.Sys [14/05/2009 23:58 36608]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
    .
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
    kydftmhp
    .
    Contenu du dossier 'Tâches planifiées'
    .
    2011-02-28 c:\windows\Tasks\AppleSoftwareUpdate.job
    - c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 10:34]
    .
    .
    ------- Examen supplémentaire -------
    .
    uInternet Settings,ProxyOverride = localhost;*.local
    IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
    IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
    DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
    FF - ProfilePath - c:\documents and settings\Tommy\Application Data\Mozilla\Firefox\Profiles\d0r6l0pr.default\
    FF - prefs.js: browser.search.selectedEngine - Google
    FF - prefs.js: browser.startup.homepage - hxxp://www.google.fr/
    FF - prefs.js: keyword.URL - hxxp://toolbar.ask.com/toolbarv/askRedirect?o=13165&gct=&gc=1&q=
    .
    .
    **************************************************************************
    .
    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2011-05-18 14:58
    Windows 5.1.2600 Service Pack 3 NTFS
    .
    Recherche de processus cachés ...
    .
    Recherche d'éléments en démarrage automatique cachés ...
    .
    Recherche de fichiers cachés ...
    .
    Scan terminé avec succès
    Fichiers cachés: 0
    .
    **************************************************************************
    .
    Heure de fin: 2011-05-18 15:04:31
    ComboFix-quarantined-files.txt 2011-05-18 13:04
    .
    Avant-CF: 1 598 947 328 octets libres
    Après-CF: 1 750 417 408 octets libres
    .
    WindowsXP-KB310994-SP2-Pro-BootDisk-FRA.exe
    [boot loader]
    timeout=2
    default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
    [operating systems]
    c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
    UnsupportedDebug="do not select this" /debug
    multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professionnel" /noexecute=optin /fastdetect
    .
    - - End Of File - - 0FD7B11B09000F45D545B3503491C116
    0
  14. juju666 Messages postés 35446 Date d'inscription   Statut Contributeur sécurité Dernière intervention   4 796
     
    Hello pour avancer Jawaryinti

    ▶ Rentre dans ton panneau de configuration....
    ▶ Apparence et personnalisation...
    ▶ Option des dossiers...(double cliquer dessus)
    ▶ Dans l''onglet affichage un peu plus bas où il est indiqué "Afficher les dossiers et fichiers cachés": Coche cette option
    ▶ Encore plus bas : Masquer les fichiers protégés du système d''exploitation (recommandé) : à décocher.

    ▶ ▶ ensuite rends toi sur ce lien:
    https://www.virustotal.com/gui/

    (si virustotal ne fonctionne pas: https://virusscan.jotti.org/fr

    ▶ Là où il est indiqué "envoyer le fichier", Clique sur "parcourir"
    recherche les entrées suivante dans ton disque :

    c:\windows\system32\drivers\agai.sys 
    


    ▶ Clique sur Envoyer
    ▶ Si une fenêtre apparait disant, "Le fichier à déjà été Analysé", Alors clique sur Réanalyser le fichier maintenant

    ▶ Copie et colle le lien de ta barre d''adresse ici, après que l''analyse soit terminée
    0
    1. manong
       
      Bonsoir !
      Je ne trouve pas agai.sys !
      0
    2. juju666 Messages postés 35446 Date d'inscription   Statut Contributeur sécurité Dernière intervention   4 796
       
      Envoie celui là : c:\windows\system32\imm32.dll
      0
    3. manong
       
      http://virusscan.jotti.org/fr/scanresult/06ad73f6b21bf9ad2ffdd99f74e69a7c4538bf8c
      0
    4. juju666 Messages postés 35446 Date d'inscription   Statut Contributeur sécurité Dernière intervention   4 796
       
      ouais ComboFix s'affole pour rien ^^

      peux tu faire un clic droit > modifier sur C:\copymbr.bat
      et me coller le contenu ici?
      0
    5. manong
       
      @ECHO OFF
      cd c:\
      start remover.exe dump \\.\PhysicalDrive0 tralala
      EXIT
      0
  15. juju666 Messages postés 35446 Date d'inscription   Statut Contributeur sécurité Dernière intervention   4 796
     
    ▶ ▶ DÉSACTIVE TES PROTECTIONS DURANT LA PROCÉDURE

    ▶ ▶ SCRIPT PERSONNALISE A CET ORDINATEUR, NE PAS REPRODUIRE : DANGEREUX !!!!


    ▶ Créé un nouveau document texte : clic droit de souris sur le bureau > Nouveau > Document Texte, et copie dedans les lignes suivantes :

    KillAll::
    
    File::
    C:\copymbr.bat      
    c:\program files\rp505fra.exe      
    c:\program files\VeohSetup-3.7.0.1020.exe      
    c:\program files\divx player.exe    
      
    Rootkit::
    c:\windows\system32\drivers\agai.sys 
    
    Registry::
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Adobe Reader Speed Launcher"=-
    "iTunesHelper"=-
    "QuickTime Task"=-
    
    Netsvc::
    kydftmhp      
    
    Driver::
    rehjfqp
    
    FireFox::
    FF - prefs.js: keyword.URL - hxxp://toolbar.ask.com/toolbarv/askRedirect?o=13165&gct=&gc=1&q=    
     
    
    


    ▶ Enregistre ce fichier sous le nom CFScript

    ▶ Fait un glisser/déposer de ce fichier CFScript sur le fichier ComboFix.exe comme sur la capture :http://i261.photobucket.com/albums/ii49/Malekal_morte/CFScript-2.gif

    ▶ Combofix se lance, laisse toi guider..

    ▶ Patiente le temps du scan. Le bureau va disparaître à plusieurs reprises: c''est normal!
    Ne touche à rien tant que le scan n''est pas terminé.
    ▶ Une fois le scan achevé, un rapport va s''afficher: poste son contenu, en précisant où en sont tes soucis

    ▶ Si le fichier ne s''ouvre pas, il se trouve ici > C:\ComboFix.txt
    0
  16. manong
     
    Voili voilou :

    ComboFix 11-05-17.01 - Tommy 18/05/2011 21:25:55.2.1 - x86
    Microsoft Windows XP Professionnel 5.1.2600.3.1252.33.1036.18.767.403 [GMT 2:00]
    Lancé depuis: c:\documents and settings\Tommy\Bureau\ComboFix.exe
    Commutateurs utilisés :: c:\documents and settings\Tommy\Bureau\CFScript.txt
    AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
    * Un nouveau point de restauration a été créé
    .
    FILE ::
    "C:\copymbr.bat"
    "c:\program files\divx player.exe"
    "c:\program files\rp505fra.exe"
    "c:\program files\VeohSetup-3.7.0.1020.exe"
    .
    .
    (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    C:\copymbr.bat
    c:\program files\divx player.exe
    c:\program files\rp505fra.exe
    c:\program files\VeohSetup-3.7.0.1020.exe
    .
    .
    ((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    -------\Service_rehjfqp
    .
    .
    ((((((((((((((((((((((((((((( Fichiers créés du 2011-04-18 au 2011-05-18 ))))))))))))))))))))))))))))))))))))
    .
    .
    2011-05-18 11:48 . 2011-05-18 11:48 -------- d-----w- c:\program files\Ad-Remover
    2011-05-17 21:34 . 2011-05-17 21:42 -------- d-----w- C:\UsbFix
    2011-05-17 21:13 . 2011-05-18 12:21 512 ----a-w- C:\PhysicalDisk0_MBR.bin
    2011-05-17 21:04 . 2011-05-18 12:21 -------- d-----w- c:\program files\ZHPDiag
    2011-05-15 16:02 . 2011-05-15 16:02 -------- d-----w- c:\documents and settings\Tommy\Application Data\MSNInstaller
    2011-05-13 23:28 . 2011-05-13 23:28 -------- d-----w- c:\program files\iPod
    2011-05-13 23:27 . 2011-05-13 23:29 -------- d-----w- c:\program files\iTunes
    2011-05-13 23:19 . 2011-05-13 23:19 -------- d-----w- c:\program files\Bonjour
    2011-05-04 12:45 . 2011-05-04 12:45 -------- d-----w- c:\documents and settings\NetworkService\Mes documents
    2011-05-03 17:28 . 2011-05-18 18:52 1324 ----a-w- c:\windows\system32\d3d9caps.tmp
    2011-05-01 08:58 . 2011-05-01 08:58 -------- d-----w- c:\documents and settings\All Users\Application Data\nView_Profiles
    2011-04-30 12:46 . 2011-05-16 20:40 -------- d-----w- c:\documents and settings\All Users\Application Data\gA31000FmEoK31000
    2011-04-30 12:45 . 2011-05-04 12:45 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
    2011-04-27 21:04 . 2011-04-27 21:04 -------- d-----r- c:\documents and settings\LocalService\Favoris
    2011-04-27 19:56 . 2011-04-27 20:27 -------- d-----w- c:\documents and settings\Tommy\Application Data\WindSolutions
    2011-04-27 19:56 . 2011-04-27 20:02 -------- d-----w- c:\documents and settings\All Users\Application Data\WindSolutions
    2011-04-27 18:27 . 2011-04-27 18:27 -------- d-----w- c:\program files\CCleaner
    2011-04-26 17:12 . 2011-04-26 17:12 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
    2011-04-26 15:41 . 2011-04-26 15:41 -------- d-sh--w- c:\documents and settings\NetworkService\PrivacIE
    2011-04-26 15:38 . 2011-04-26 15:38 -------- d-sh--w- c:\documents and settings\NetworkService\IECompatCache
    2011-04-26 15:37 . 2011-04-26 15:39 -------- d-----r- c:\documents and settings\NetworkService\Favoris
    2011-04-25 20:16 . 2011-04-25 20:16 -------- d-----w- c:\documents and settings\Tommy\Application Data\Malwarebytes
    2011-04-25 19:27 . 2011-04-25 19:27 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
    2011-04-25 19:27 . 2010-12-20 16:09 38224 ----a-r- c:\windows\system32\drivers\mbamswissarmy.sys
    2011-04-25 19:27 . 2011-04-25 19:27 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
    2011-04-25 19:27 . 2010-12-20 16:08 20952 ----a-r- c:\windows\system32\drivers\mbam.sys
    2011-04-25 19:20 . 2011-04-25 19:20 -------- d-----w- c:\documents and settings\Administrateur
    2011-04-25 19:01 . 2011-04-25 19:01 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache
    .
    .
    .
    (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2011-04-06 14:20 . 2011-04-06 14:20 91424 ----a-w- c:\windows\system32\dnssd.dll
    2011-04-06 14:20 . 2011-04-06 14:20 75040 ----a-w- c:\windows\system32\jdns_sd.dll
    2011-04-06 14:20 . 2011-04-06 14:20 197920 ----a-w- c:\windows\system32\dnssdX.dll
    2011-04-06 14:20 . 2011-04-06 14:20 107808 ----a-w- c:\windows\system32\dns-sd.exe
    2011-03-07 05:33 . 2007-09-19 15:25 692736 ----a-r- c:\windows\system32\inetcomm.dll
    2011-03-04 06:36 . 2004-08-19 14:09 420864 ----a-r- c:\windows\system32\vbscript.dll
    2011-03-03 13:53 . 2004-08-19 14:00 1858048 ----a-r- c:\windows\system32\win32k.sys
    2011-02-22 23:05 . 2004-08-19 14:09 916480 ----a-r- c:\windows\system32\wininet.dll
    2011-02-22 23:05 . 2004-08-19 14:10 1469440 ----a-r- c:\windows\system32\inetcpl.cpl
    2011-02-22 23:05 . 2004-08-19 14:09 43520 ----a-r- c:\windows\system32\licmgr10.dll
    2011-02-22 11:42 . 2004-08-19 13:56 385024 ----a-r- c:\windows\system32\html.iec
    2011-02-18 14:36 . 2009-04-19 18:14 4184352 ----a-r- c:\windows\system32\usbaaplrc.dll
    2011-02-18 14:36 . 2007-12-09 10:57 41984 ----a-r- c:\windows\system32\drivers\usbaapl.sys
    2008-11-18 21:30 . 2008-11-18 21:30 20724432 -c--a-w- c:\program files\DivXInstaller.exe
    2011-04-14 16:47 . 2011-04-30 12:16 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
    .
    .
    ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
    REGEDIT4
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-06-02 148888]
    "AppleSyncNotifier"="c:\program files\Fichiers communs\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-10-08 47904]
    "avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2011-01-13 3396624]
    .
    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
    .
    [HKLM\~\startupfolder\C:^Documents and Settings^Tommy^Menu Démarrer^Programmes^Démarrage^OpenOffice.org 2.3.lnk]
    path=c:\documents and settings\Tommy\Menu Démarrer\Programmes\Démarrage\OpenOffice.org 2.3.lnk
    backup=c:\windows\pss\OpenOffice.org 2.3.lnkStartup
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
    2011-04-26 23:22 421160 ----a-w- c:\program files\iTunes\iTunesHelper.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
    2010-11-29 16:38 421888 ----a-w- c:\program files\QuickTime\QTTask.exe
    .
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall"= 0 (0x0)
    .
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\Program Files\\Messenger\\msmsgs.exe"=
    "c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
    "c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
    "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
    "c:\\Program Files\\iTunes\\iTunes.exe"=
    .
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "13541:TCP"= 13541:TCP:NortonAV
    "12733:TCP"= 12733:TCP:NortonAV
    "14913:TCP"= 14913:TCP:NortonAV
    .
    R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [08/05/2009 21:16 294608]
    R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [08/05/2009 21:16 17744]
    S2 kydftmhp;Print Class for IEEE-1284.4 HPZipr12Helper;c:\windows\System32\svchost.exe -k netsvcs [19/08/2004 16:10 14336]
    S3 CFcatchme;CFcatchme;\??\c:\docume~1\Tommy\LOCALS~1\Temp\CFcatchme.sys --> c:\docume~1\Tommy\LOCALS~1\Temp\CFcatchme.sys [?]
    S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.Sys [14/05/2009 23:58 36608]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
    .
    Contenu du dossier 'Tâches planifiées'
    .
    2011-02-28 c:\windows\Tasks\AppleSoftwareUpdate.job
    - c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 10:34]
    .
    .
    ------- Examen supplémentaire -------
    .
    uInternet Settings,ProxyOverride = localhost;*.local
    IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
    IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
    DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
    FF - ProfilePath - c:\documents and settings\Tommy\Application Data\Mozilla\Firefox\Profiles\d0r6l0pr.default\
    FF - prefs.js: browser.search.selectedEngine - Google
    FF - prefs.js: browser.startup.homepage - hxxp://www.google.fr/
    FF - prefs.js: keyword.URL - hxxp://toolbar.ask.com/toolbarv/askRedirect?o=13165&gct=&gc=1&q=
    .
    .
    **************************************************************************
    .
    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2011-05-18 21:37
    Windows 5.1.2600 Service Pack 3 NTFS
    .
    Recherche de processus cachés ...
    .
    Recherche d'éléments en démarrage automatique cachés ...
    .
    Recherche de fichiers cachés ...
    .
    Scan terminé avec succès
    Fichiers cachés: 0
    .
    **************************************************************************
    .
    --------------------- CLES DE REGISTRE BLOQUEES ---------------------
    .
    [HKEY_LOCAL_MACHINE\software\Swearware\backup\winsock2\Parameters]
    @DACL=(02 0000)
    @SACL=
    "WinSock_Registry_Version"="2.0"
    "Current_NameSpace_Catalog"="NameSpace_Catalog5"
    "Current_Protocol_Catalog"="Protocol_Catalog9"
    .
    --------------------- DLLs chargées dans les processus actifs ---------------------
    .
    - - - - - - - > 'explorer.exe'(1016)
    c:\program files\Fichiers communs\Adobe\Acrobat\ActiveX\PDFShell.dll
    c:\program files\Fichiers communs\Adobe\Acrobat\ActiveX\PDFShell.FRA
    c:\windows\system32\eappprxy.dll
    c:\windows\system32\webcheck.dll
    c:\windows\system32\WPDShServiceObj.dll
    c:\windows\system32\PortableDeviceTypes.dll
    c:\windows\system32\PortableDeviceApi.dll
    .
    ------------------------ Autres processus actifs ------------------------
    .
    c:\program files\Alwil Software\Avast5\AvastSvc.exe
    c:\program files\Fichiers communs\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    c:\program files\Bonjour\mDNSResponder.exe
    c:\program files\Java\jre6\bin\jqs.exe
    c:\windows\system32\devldr32.exe
    c:\windows\system32\wscntfy.exe
    .
    **************************************************************************
    .
    Heure de fin: 2011-05-18 21:43:46 - La machine a redémarré
    ComboFix-quarantined-files.txt 2011-05-18 19:43
    ComboFix2.txt 2011-05-18 13:04
    .
    Avant-CF: 1 898 110 976 octets libres
    Après-CF: 1 729 069 056 octets libres
    .
    - - End Of File - - 617271F1118BC3BB614AE4AF36BCBA35
    0
  17. juju666 Messages postés 35446 Date d'inscription   Statut Contributeur sécurité Dernière intervention   4 796
     
    parfait

    Nous allons effectuer un diagnostic de ton PC:
    Télécharge ZHPDiag sur ton bureau :

    https://www.zebulon.fr/telechargements/securite/systeme/zhpdiag.html
    ou :
    http://www.premiumorange.com/zeb-help-process/zhpdiag.html
    ou :
    ftp://zebulon.fr/ZHPDiag2.exe

    ▶ Laisse toi guider lors de l''installation,coche "Ajouter une icône sur le bureau" et décoche la case "Exécuter ZHPDiag"

    /!\Utilisateur de Vista et Seven : Clique droit sur le logo de ZHPdiag, « exécuter en tant qu''Administrateur »

    ▶ Clique sur l''icône représentant une loupe (« Lancer le diagnostic »)
    ▶ Enregistre le rapport sur ton Bureau à l''aide de l''icône représentant une disquette
    ▶ Héberge le rapport ZHPDiag.txt sur un des sites ci dessous, puis copie/colle le lien fourni dans ta prochaine réponse sur le forum :
    http://pjjoint.malekal.com/

    Si indispo:
    http://www.cijoint.fr/
    ou :
    http://ww38.toofiles.com/fr/documents-upload.html
    ou :
    https://www.cjoint.com/
    ou :
    https://www.casimages.com/

    ▶ Tuto zhpdiag :
    http://www.premiumorange.com/zeb-help-process/zhpdiag.html

    Hébergement de rapport sur pjjoint.malekal.com

    ▶ Rends toi sur pjjoint.malekal.com
    ▶ Clique sur le bouton Parcourir
    ▶ Sélectionne le fichier que tu veux heberger et clique sur Ouvrir
    ▶ Clique sur le bouton Envoyer
    ▶ Un message de confirmation s''affiche (L''upload a réussi ! - Le lien à transmettre à vos correspondant pour visualiser le fichier est : https://pjjoint.malekal.com/files.php?id=df5ea299241015 Copie le lien dans ta prochaine réponse.
    0
    1. Utilisateur anonyme
       
      Bonsoir Juju
      Il possède déjà ZHPDiag
      Manong, refait ZHPDiag et héberge le rapport et donne le lien
      0
    2. juju666 Messages postés 35446 Date d'inscription   Statut Contributeur sécurité Dernière intervention   4 796
       
      ah te revoilà ^^

      bonne suite :p
      0
    3. manong
       
      En fait, "elle" possède déjà ZHP Diag :)
      Et voici le lien du rapport :

      http://up.sur-la-toile.com/iN0P
      0
    4. Utilisateur anonyme
       
      @Juju
      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "Adobe Reader Speed Launcher"=-


      O42 - Logiciel: Adobe Reader 8.1.3 - Français - (.Adobe Systems Incorporated.) [HKLM] -- {AC76BA86-7AD7-1036-7B44-A81300000003}
      O42 - Logiciel: Java(TM) 6 Update 13 - (.Sun Microsystems, Inc..) [HKLM] -- {26A24AE4-039D-4CA4-87B4-2F83216013FF}
      O42 - Logiciel: Java(TM) 6 Update 2 - (.Sun Microsystems, Inc..) [HKLM] -- {3248F0A8-6813-11D6-A77B-00B0D0160020}
      O42 - Logiciel: Java(TM) 6 Update 6 - (.Sun Microsystems, Inc..) [HKLM] -- {3248F0A8-6813-11D6-A77B-00B0D0160060}

      Les valeurs de registre doivent être supprimées après avoir mis à jour les logiciels, car la
      valeur de registre va se réinstaller
      0
    5. manong
       
      Merci d'avoir pris le relai juju666 !
      0
  18. manong
     
    Bonjour !
    Désolée de vous relancer, j'aimerais savoir si je pouvais être tranquille ou s'il restait des menaces sur mon pc ?
    Merci !
    0
  19. Utilisateur anonyme
     
    Bonjour
    On va faire une dernière vérification
    Lance ZHPDiag, clique sur l'icône représentant la flèche verte, télécharge
    et installe la nouvelle version
    Ensuite, clique sur la loupe pour lancer le scan et héberge le rapport, puis
    donne moi le lien
    0
    1. manong
       
      Voici le lien !
      http://up.sur-la-toile.com/iN7R
      0
  20. Utilisateur anonyme
     
    On va désinstaller Java et Adobe qui ne sont pas à jour avec ZHPFix, et on va
    nettoyer encore des restants d'infections

    Copie les lignes suivantes en gras ci dessous, c'est à dire
    que tu sélectionnes les lignes indiquées en gras avec ta souris, tu fait
    clic droit dessus>copier

    O42 - Logiciel: Adobe Reader 8.1.3 - Français - (.Adobe Systems Incorporated.) [HKLM] -- {AC76BA86-7AD7-1036-7B44-A81300000003}
    O42 - Logiciel: Java(TM) 6 Update 13 - (.Sun Microsystems, Inc..) [HKLM] -- {26A24AE4-039D-4CA4-87B4-2F83216013FF}
    O42 - Logiciel: Java(TM) 6 Update 2 - (.Sun Microsystems, Inc..) [HKLM] -- {3248F0A8-6813-11D6-A77B-00B0D0160020}
    O42 - Logiciel: Java(TM) 6 Update 6 - (.Sun Microsystems, Inc..) [HKLM] -- {3248F0A8-6813-11D6-A77B-00B0D0160060}
    O81 - IFC: Internet Feature Controls [HKUS\.DEFAULT] [FEATURE_BROWSER_EMULATION] -- svchost.exe
    O81 - IFC: Internet Feature Controls [HKUS\S-1-5-18] [FEATURE_BROWSER_EMULATION] -- svchost.exe
    [HKLM\Software\Classes\AppID\SoftwareUpdate.exe] =>PUP.Eorezo
    [HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\conduitEngine] =>Toolbar.Conduit
    [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{201f27d4-3704-41d6-89c1-aa35e39143ed}] =>Toolbar.Ask
    [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3041d03e-fd4b-44e0-b742-2d9b88305f98}] =>Adware.AskTBar
    [HKCR\Interface\{3EDDA953-1C3B-4823-8F25-D075FBB2D2B5}] =>PUP.Dealio
    [HKCR\TypeLib\{4C1E5902-FE99-4591-8582-2A2605462857}] =>PUP.Dealio
    [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{6A87B991-A31F-4130-AE72-6D0C294BF082}] =>PUP.Dealio
    [HKCR\Interface\{B67A4CBA-520A-43DB-B03F-414E539F90EC}] =>PUP.Dealio
    [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E67C74F4-A00A-4F2C-9FEC-FD9DC004A67F}] =>PUP.Dealio
    [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{e908b145-c847-4e85-b315-07e2e70decf8}] =>PUP.Dealio
    [HKCU\Software\PT25DHYRAW] =>Trojan.FakeAlert
    C:\Documents and Settings\Tommy\Application Data\BabylonToolbar =>Toolbar.Babylon


    * Lance ZHPFix, soit à partir d'un raccourci sur le bureau, soit à partir de
    ZHPDiag (avec Vista/Seven, clic droit dessus, et sur exécuter en
    tant qu'administrateur
    )
    Clique sur l'icône représentant la lettre H (« coller les lignes Helper »)
    - Les lignes se collent automatiquement dans ZHPFix, sinon colle les lignes
    - Clique sur le bouton « GO » pour lancer le nettoyage,
    - Copie/colle la totalité du rapport dans ta prochaine réponse

    Installe la nouvelle version d'Adobe en cliquant sur ce lien
    https://acrobat.adobe.com/fr/fr/acrobat/pdf-reader.html
    Prend le temps de lire les instructions, et tu dois refuser
    le complément qu'on te propose
    Ensuite, fait ceci:
    * Lance Adobe Reader
    * Clique sur Edition --> Préférences --> JavaScript
    * Décoche Activer Acrobat JavaScript
    * Valide
    C'est pour désactiver l'interprétation de Javascript dans Adobe,
    car c'est source d'infections, et cela ne sert à rien

    Télécharge et installe la nouvelle version de Java
    https://java.com/fr/
    Attention, prend le temps de lire les informations,
    décoche la case Yahoo toolbar

    Redémarre ton PC

    Ensuite, poste moi un nouveau rapport ZHPDiag

    0
    1. manong
       
      Bonsoir ! Désolée je n'ai pas pu faire tout avant ajourd'hui !
      Voici le rapport ZHPFix :


      Rapport de ZHPDiag v1.27.21 par Nicolas Coolman, Update du 21/05/2011
      Run by Tommy at 21/05/2011 22:41:09
      Web site : http://www.premiumorange.com/zeb-help-process/zhpdiag.html


      ---\\ Web Browser
      MSIE: Internet Explorer v8.0.6001.18702 (Defaut)
      MFIE: Mozilla Firefox 4.0.1 v4.0.1

      ---\\ System Information
      Windows XP Professional Service Pack 3 (Build 2600)
      Processor: x86 Family 15 Model 2 Stepping 7, GenuineIntel
      Operating System: 32 Bits
      Boot mode: Normal (Normal boot)
      Total RAM: 767 MB (58% free)
      System Restore: Activé (Enable)
      System drive C: has 6 GB (12%) free of 49 GB

      ---\\ Logged in mode
      Computer Name: TOMMY
      User Name: Tommy
      All Users Names: Tommy, SUPPORT_388945a0, Lena, Laurence, HelpAssistant, ASPNET, Administrateur,
      Unselected Option: O45,O61,O62,O65,O66,O82
      Logged in as Administrator

      ---\\ Environnement Variables
      %AppData%=C:\Documents and Settings\Tommy\Application Data
      %LocalAppData%=C:\Documents and Settings\Tommy\Local Settings\Application Data
      %StartMenu%=C:\Documents and Settings\Tommy\Menu Démarrer

      ---\\ DOS/Devices
      A:\ Floppy drive, Flash card reader, USB Key (Not Inserted)
      C:\ Hard drive, Flash drive, Thumb drive (Free 6 Go of 49 Go)
      D:\ CD-ROM drive (Not Inserted)
      E:\ CD-ROM drive (Not Inserted)
      F:\ Hard drive, Flash drive, Thumb drive (Free 0 Go of 0 Go)
      G:\ Hard drive, Flash drive, Thumb drive (Free 52 Go of 149 Go)



      ---\\ Security Center & Tools Informations
      [HKLM\SOFTWARE\Microsoft\Security Center] AntiVirusOverride: OK
      [HKLM\SOFTWARE\Microsoft\Security Center] AntiVirusDisableNotify: OK
      [HKLM\SOFTWARE\Microsoft\Security Center] FirewallDisableNotify: OK
      [HKLM\SOFTWARE\Microsoft\Security Center] FirewallOverride: OK
      [HKLM\SOFTWARE\Microsoft\Security Center] UpdatesDisableNotify: OK
      [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: OK
      [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK



      ---\\ Recherche particulière de fichiers génériques
      [MD5.F2317622D29F9FF0F88AEECD5F60F0DD] - (.Microsoft Corporation - Explorateur Windows.) (.14/04/2008 03:34:03.) -- C:\WINDOWS\Explorer.exe [1037824]
      [MD5.77C66BD5CED4E555919A5FB713322CDD] - (.Microsoft Corporation - Internet Extensions for Win32.) (.23/02/2011 00:05:48.) -- C:\WINDOWS\system32\wininet.dll [916480]
      [MD5.DD73D6B9F6B4CB630CF35B438B540174] - (.Microsoft Corporation - Application d'ouverture de session Windows NT.) (.14/04/2008 03:34:28.) -- C:\WINDOWS\system32\Winlogon.exe [512000]
      [MD5.9F3A2F5AA6875C72BF062C712CFA2674] - (.Microsoft Corporation - IDE/ATAPI Port Driver.) (.13/04/2008 19:40:30.) -- C:\WINDOWS\system32\drivers\atapi.sys [96512]
      [MD5.78A08DD6A8D65E697C18E1DB01C5CDCA] - (.Microsoft Corporation - NT File System Driver.) (.13/04/2008 20:15:53.) -- C:\WINDOWS\system32\drivers\ntfs.sys [574976]



      ---\\ Processus lancés
      [MD5.25FB74EABCE5EC7836BA3CFB3C58449A] - (.AVAST Software - avast! Service.) -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [40384]
      [MD5.20F6F19FE9E753F2780DC2FA083AD597] - (.Apple Inc. - MobileDeviceService.) -- C:\Program Files\Fichiers communs\Apple\Mobile Device Support\AppleMobileDeviceService.exe [37664]
      [MD5.F2060A34C8A75BC24A9222EB4F8C07BD] - (.Apple Inc. - Bonjour Service.) -- C:\Program Files\Bonjour\mDNSResponder.exe [349472]
      [MD5.890369AED0DDE1A98F09F7DC239CA2BD] - (.Sun Microsystems, Inc. - Java(TM) Quick Starter Service.) -- C:\Program Files\Java\jre6\bin\jqs.exe [152984]
      [MD5.A2D390F1F2408B94EF34BFE3A00C29D3] - (.Sun Microsystems, Inc. - Java(TM) Platform SE binary.) -- C:\Program Files\Java\jre6\bin\jusched.exe [148888]
      [MD5.7B878518590E826F1F3A5B1D61D405F8] - (.AVAST Software - avast! Antivirus.) -- C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe [3396624]
      [MD5.43722D15C8A955A8130ACD3151178CE5] - (.Creative Technology Ltd. - DevLdr32.) -- C:\WINDOWS\system32\devldr32.exe [24064]
      [MD5.62BB79160F86CD962F312C68C6239BFD] - (.Microsoft Corporation - Windows Update.) -- C:\WINDOWS\system32\wuauclt.exe [53472]
      [MD5.E51BD095B2FDF56B17EE010BB794D6ED] - (.Apple Inc. - iPodService Module (32-bit).) -- C:\Program Files\iPod\bin\iPodService.exe [820520]
      [MD5.E83508D9A0F0D0D8449317DC6A4C5E02] - (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe [924632]
      [MD5.3B2CC09944488DB5ED5DFDC315C9AB57] - (.Mozilla Corporation - Plugin Container for Firefox.) -- C:\Program Files\Mozilla Firefox\plugin-container.exe [16856]
      [MD5.AF2A4686F7B696A3952F40350CC37DD3] - (.Nicolas Coolman - Diagnostic Tool.) -- C:\Program Files\ZHPDiag\ZHPDiag.exe [657408]



      ---\\ Mozilla Firefox, Plugins,Demarrage,Recherche,Extensions (P2,M0,M1,M2,M3)
      M3 - MFPP: Plugins - [Tommy] -- C:\Program Files\Mozilla FireFox\searchplugins\amazon-france.xml
      M3 - MFPP: Plugins - [Tommy] -- C:\Program Files\Mozilla FireFox\searchplugins\bing.xml
      M3 - MFPP: Plugins - [Tommy] -- C:\Program Files\Mozilla FireFox\searchplugins\cnrtl-tlfi-fr.xml
      M3 - MFPP: Plugins - [Tommy] -- C:\Program Files\Mozilla FireFox\searchplugins\eBay-france.xml
      M3 - MFPP: Plugins - [Tommy] -- C:\Program Files\Mozilla FireFox\searchplugins\google.xml
      M3 - MFPP: Plugins - [Tommy] -- C:\Program Files\Mozilla FireFox\searchplugins\wikipedia-fr.xml
      M3 - MFPP: Plugins - [Tommy] -- C:\Program Files\Mozilla FireFox\searchplugins\yahoo-france.xml
      P2 - FPN: [HKLM] [adobe.com/FlashPlayer] - (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
      P2 - FPN: [HKLM] [Apple.com/iTunes,version=1.0] - (.Pas de propriétaire - Pas de description.) -- C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
      P2 - FPN: [HKLM] [Microsoft.com/NpCtrl,version=1.0] - (. Microsoft Corporation - 4.0.60310.0.) -- C:\Program Files\Microsoft Silverlight\4.0.60310.0\npctrl.dll
      P2 - FPN: [HKLM] [microsoft.com/OfficeLive,version=1.3] - (.Microsoft Corp. - Office Live Update v1.3.) -- C:\Program Files\Microsoft\Office Live\npOLW.dll
      P2 - FPN: [HKLM] [microsoft.com/WLPG,version=14.0.8081.0709] - (.Microsoft Corporation - NPWLPG.) -- C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
      P2 - FPN: [HKLM] [microsoft.com/WPF,version=3.5] - (.Microsoft Corporation - Windows Presentation Foundation (WPF) plug-in for Mozilla browsers.) -- C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
      P2 - FPN: [HKCU] [adobe.com/FlashPlayer] - (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
      M0 - MFSP: prefs.js [Tommy - d0r6l0pr.default] http://www.google.fr/
      M2 - MFEP: prefs.js [Tommy - d0r6l0pr.default\2020Player2020Technologies.com] [] Visualisateur 3D de 20-20 v4.5.4.0 (.20-20 Technologies.)
      M2 - MFEP: prefs.js [Tommy - d0r6l0pr.default\{20a82645-c095-46ed-80e3-08825760534b}] [MicrosoftCG] Microsoft .NET Framework Assistant v1.1 (.Microsoft.)



      ---\\ Internet Explorer, Démarrage,Recherche,URLSearchHook, Phishing (R0,R1,R3,R4)
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com
      R0 - HKUS\S-1-5-21-1343024091-1078145449-839522115-1003\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk
      R1 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com
      R1 - HKUS\S-1-5-21-1343024091-1078145449-839522115-1003\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com
      R3 - URLSearchHook: Microsoft Url Search Hook - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} . (.Microsoft Corporation - Internet Explorer.) (8.00.6001.19048 (longhorn_ie8_gdr.110221-1700)) -- C:\WINDOWS\system32\ieframe.dll
      R4 - HKCU\SOFTWARE\Microsoft\Internet Explorer\PhishingFilter,Enabled = 2



      ---\\ Internet Explorer, Proxy Management (R5)
      R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;*.local
      R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key
      R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
      R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
      R5 - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
      R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyHttp1.1 = 1
      R5 - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll



      ---\\ ---\\ Modification d'une valeur Ini (Changed inifile value, mapped to Registry) (F2)
      F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,
      F2 - REG:system.ini: VMApplet=rundll32 shell32,Control_RunDLL "sysdm.cpl"



      ---\\ Browser Helper Objects de navigateur (O2)
      O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} . (.Adobe Systems Incorporated - Adobe PDF Helper for Internet Explorer.) -- C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
      O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} Clé orpheline
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} . (.Microsoft Corporation - WindowsLiveLogin.dll.) -- C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} . (.Sun Microsystems, Inc. - Java(TM) Platform SE binary.) -- C:\Program Files\Java\jre6\bin\jp2ssv.dll
      O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} . (.Sun Microsystems, Inc. - Java(TM) Quick Starter binary.) -- C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll



      ---\\ ---\\ Applications démarrées par registre & par dossier (O4)
      O4 - HKLM\..\Run: [SunJavaUpdateSched] . (.Sun Microsystems, Inc. - Java(TM) Platform SE binary.) -- C:\Program Files\Java\jre6\bin\jusched.exe
      O4 - HKLM\..\Run: [AppleSyncNotifier] . (.Apple Inc. - AppleSyncNotifier.) -- C:\Program Files\Fichiers communs\Apple\Mobile Device Support\AppleSyncNotifier.exe
      O4 - HKLM\..\Run: [avast5] . (.AVAST Software - avast! Antivirus.) -- C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe
      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\CTFMON.exe
      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\CTFMON.exe



      ---\\ ---\\ Autres liens utilisateurs (O4)
      O4 - Global Startup: C:\Documents And Settings\All Users\Menu Démarrer\Programmes\Mozilla Firefox.lnk . (.Mozilla Corporation.) -- C:\Program Files\Mozilla Firefox\firefox.exe
      O4 - Global Startup: C:\Documents And Settings\All Users\Menu Démarrer\Programmes\Windows Messenger.lnk . (.Microsoft Corporation.) -- C:\Program Files\Messenger\msmsgs.exe
      O4 - Global Startup: C:\Documents And Settings\Tommy\Menu Démarrer\Programmes\Outlook Express.lnk . (.Microsoft Corporation.) -- C:\Program Files\Outlook Express\msimn.exe



      ---\\ Lignes supplémentaires dans le menu contextuel d'Internet Explorer (O8)
      O8 - Extra context menu item: E&xporter vers Microsoft Excel . (.Microsoft Corporation - Microsoft Office Excel.) -- C:\PROGRA~1\MICROS~2\Office12\EXCEL.exe
      O8 - Extra context menu item: Google Sidewiki... - (.not file.) - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll



      ---\\ Boutons situés sur la barre d'outils principale d'Internet Explorer (O9)
      O9 - Extra button: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} . (.Microsoft Corporation - Windows Live Writer Blog This Extension.) -- C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
      O9 - Extra button: &Ajout Direct dans Windows Live Writer - {92780B25-18CC-41C8-B9BE-3C9C571A8263} . (...) -- C:\PROGRA~1\MICROS~2\Office12\REFBARH.ICO
      O9 - Extra button: xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} . (...) -- C:\PROGRA~1\MICROS~2\Office12\REFBARH.ICO
      O9 - Extra button: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} . (.Microsoft Corporation - Windows Messenger.) -- C:\Program Files\Messenger\msmsgs.exe



      ---\\ Winsock hijacker (Layered Service Provider) (O10)
      O10 - WLSP:\000000000001\Winsock LSP File . (.Microsoft Corporation - Fournisseur de service Sockets 2.0 de Microsoft Windows.) -- C:\WINDOWS\system32\mswsock.dll
      O10 - WLSP:\000000000002\Winsock LSP File . (.Microsoft Corporation - LDAP RnR Provider DLL.) -- C:\WINDOWS\system32\winrnr.dll
      O10 - WLSP:\000000000003\Winsock LSP File . (.Microsoft Corporation - Fournisseur de service Sockets 2.0 de Microsoft Windows.) -- C:\WINDOWS\system32\mswsock.dll
      O10 - WLSP:\000000000004\Winsock LSP File . (.Apple Inc. - Bonjour Namespace Provider.) -- C:\Program Files\Bonjour\mdnsNSP.dll



      ---\\ Objets ActiveX (Downloaded Program Files)(O16)
      O16 - DPF: Microsoft XML Parser for Java - (Microsoft XML Parser for Java) - (.not file.) - file:\\C:\WINDOWS\Java\classes\xmldso.cab
      O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
      O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w3/pr01/resources/MSNPUpld.cab
      O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
      O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} () - http://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
      O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab



      ---\\ Modification Domaine/Adresses DNS (O17)
      O17 - HKLM\System\CCS\Services\Tcpip\..\{510CFE70-90C9-49FE-A5CE-B24EB46787DD}: DhcpNameServer = 89.2.0.1 89.2.0.2
      O17 - HKLM\System\CS1\Services\Tcpip\..\{510CFE70-90C9-49FE-A5CE-B24EB46787DD}: DhcpNameServer = 89.2.0.1 89.2.0.2
      O17 - HKLM\System\CS3\Services\Tcpip\..\{510CFE70-90C9-49FE-A5CE-B24EB46787DD}: DhcpNameServer = 89.2.0.1 89.2.0.2
      O17 - HKLM\System\CCS\Services\Tcpip\..\{510CFE70-90C9-49FE-A5CE-B24EB46787DD}: DhcpDomain = numericable.fr
      O17 - HKLM\System\CS1\Services\Tcpip\..\{510CFE70-90C9-49FE-A5CE-B24EB46787DD}: DhcpDomain = numericable.fr
      O17 - HKLM\System\CS3\Services\Tcpip\..\{510CFE70-90C9-49FE-A5CE-B24EB46787DD}: DhcpDomain = numericable.fr
      O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 89.2.0.1 89.2.0.2



      ---\\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (autorun) (O20)
      O20 - Winlogon Notify: crypt32chain . (.Microsoft Corporation - Crypto API32.) -- C:\Windows\System32\crypt32.dll
      O20 - Winlogon Notify: cryptnet . (.Microsoft Corporation - Crypto Network Related API.) -- C:\Windows\System32\cryptnet.dll
      O20 - Winlogon Notify: cscdll . (.Microsoft Corporation - Agent réseau hors connexion.) -- C:\Windows\System32\cscdll.dll
      O20 - Winlogon Notify: dimsntfy . (.Microsoft Corporation - DIMS Notification Handler.) -- C:\WINDOWS\System32\dimsntfy.dll
      O20 - Winlogon Notify: ScCertProp . (.Microsoft Corporation - DLL commune de réception des notifications.) -- C:\Windows\System32\wlnotify.dll
      O20 - Winlogon Notify: Schedule . (.Microsoft Corporation - DLL commune de réception des notifications.) -- C:\Windows\System32\wlnotify.dll
      O20 - Winlogon Notify: sclgntfy . (.Microsoft Corporation - DLL secondaire de notification de service d.) -- C:\Windows\System32\sclgntfy.dll
      O20 - Winlogon Notify: SensLogn . (.Microsoft Corporation - DLL commune de réception des notifications.) -- C:\Windows\System32\WlNotify.dll
      O20 - Winlogon Notify: termsrv . (.Microsoft Corporation - DLL commune de réception des notifications.) -- C:\Windows\System32\wlnotify.dll
      O20 - Winlogon Notify: WgaLogon . (.Pas de propriétaire - Pas de description.) -- WgaLogon.dll
      O20 - Winlogon Notify: wlballoon . (.Microsoft Corporation - DLL commune de réception des notifications.) -- C:\Windows\System32\wlnotify.dll



      ---\\ Clé de Registre autorun ShellServiceObjectDelayLoad (SSO/SSODL) (O21)
      O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\WINDOWS\system32\shell32.dll
      O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\WINDOWS\system32\SHELL32.dll
      O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} . (.Microsoft Corporation - Web Site Monitor.) -- C:\WINDOWS\system32\webcheck.dll
      O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} . (.Microsoft Corporation - Objet du service d'environnement Systray.) -- C:\WINDOWS\system32\stobject.dll
      O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} . (.Microsoft Corporation - Windows Portable Device Shell Service Objec.) -- C:\WINDOWS\system32\WPDShServiceObj.dll



      ---\\ Clé de Registre autorun SharedTaskScheduler (STS) (O22)
      O22 - SharedTaskScheduler: (no name) - {438755C2-A8BA-11D1-B96B-00A0C90312E1} . (.Microsoft Corporation - Bibliothèque de l'interface utilisateur du.) -- C:\WINDOWS\system32\browseui.dll
      O22 - SharedTaskScheduler: (no name) - {8C7461EF-2B13-11d2-BE35-3078302C2030} . (.Microsoft Corporation - Bibliothèque de l'interface utilisateur du.) -- C:\WINDOWS\system32\browseui.dll



      ---\\ Liste des services NT non Microsoft et non désactivés (O23)
      O23 - Service: (Apple Mobile Device) . (.Apple Inc. - MobileDeviceService.) - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\AppleMobileDeviceService.exe
      O23 - Service: (avast! Antivirus) . (.AVAST Software - avast! Service.) - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
      O23 - Service: (Bonjour Service) . (.Apple Inc. - Bonjour Service.) - C:\Program Files\Bonjour\mDNSResponder.exe
      O23 - Service: (dmadmin) . (.Microsoft Corp., Veritas Software - Processus du service Gestionnaire de disque.) - C:\WINDOWS\System32\dmadmin.exe
      O23 - Service: (iPod Service) . (.Apple Inc. - iPodService Module (32-bit).) - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: (JavaQuickStarterService) . (.Sun Microsystems, Inc. - Java(TM) Quick Starter Service.) - C:\Program Files\Java\jre6\bin\jqs.exe



      ---\\ Enumération Active Desktop & MHTML Editor (O24)
      O24 - Default MHTML Editor: Last - .(.Microsoft Corporation - Microsoft Office Word.) - C:\Program Files\Microsoft Office\Office12\WINWORD.exe



      ---\\ Tâches planifiées en automatique (O39)
      O39 - APT:Automatic Planified Task - C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
      [MD5.7B43567B4C32AD7ADED537CD3B1342B9] [APT] [AppleSoftwareUpdate] (.Apple Inc..) -- C:\Program Files\Apple Software Update\SoftwareUpdate.exe



      ---\\ Pilotes lancés au démarrage (O41)
      O41 - Driver: (AFD) . (.Microsoft Corporation - Ancillary Function Driver for WinSock.) - C:\WINDOWS\system32\drivers\afd.sys
      O41 - Driver: (Cdrom) . (.Microsoft Corporation - SCSI CD-ROM Driver.) - C:\Windows\System32\DRIVERS\cdrom.sys
      O41 - Driver: (i8042prt) . (.Microsoft Corporation - Pilote de port i8042.) - C:\Windows\System32\DRIVERS\i8042prt.sys
      O41 - Driver: (Imapi) . (.Microsoft Corporation - IMAPI Kernel Driver.) - C:\Windows\System32\DRIVERS\imapi.sys
      O41 - Driver: (intelppm) . (.Microsoft Corporation - Pilote de périphérique processeur.) - C:\Windows\System32\DRIVERS\intelppm.sys
      O41 - Driver: (IPSec) . (.Microsoft Corporation - IPSec Driver.) - C:\Windows\System32\DRIVERS\ipsec.sys
      O41 - Driver: (Kbdclass) . (.Microsoft Corporation - Pilote de la classe Clavier.) - C:\Windows\System32\DRIVERS\kbdclass.sys
      O41 - Driver: (Mouclass) . (.Microsoft Corporation - Pilote de la classe Souris.) - C:\Windows\System32\DRIVERS\mouclass.sys
      O41 - Driver: (MRxSmb) . (.Microsoft Corporation - Windows NT SMB Minirdr.) - C:\Windows\System32\DRIVERS\mrxsmb.sys
      O41 - Driver: (NetBIOS) . (.Microsoft Corporation - NetBIOS interface driver.) - C:\Windows\System32\DRIVERS\netbios.sys
      O41 - Driver: (NetBT) . (.Microsoft Corporation - MBT Transport driver.) - C:\Windows\System32\DRIVERS\netbt.sys
      O41 - Driver: (RasAcd) . (.Microsoft Corporation - RAS Automatic Connection Driver.) - C:\Windows\System32\DRIVERS\rasacd.sys
      O41 - Driver: (Rdbss) . (.Microsoft Corporation - Redirected Drive Buffering SubSystem Driver.) - C:\Windows\System32\DRIVERS\rdbss.sys
      O41 - Driver: (RDPCDD) . (.Microsoft Corporation - RDP Miniport.) - C:\Windows\System32\DRIVERS\RDPCDD.sys
      O41 - Driver: (redbook) . (.Microsoft Corporation - Pilote de filtre audio Livre rouge.) - C:\Windows\System32\DRIVERS\redbook.sys
      O41 - Driver: (Serial) . (.Microsoft Corporation - Pilote de périphérique série.) - C:\Windows\System32\DRIVERS\serial.sys
      O41 - Driver: (Tcpip) . (.Microsoft Corporation - TCP/IP Protocol Driver.) - C:\Windows\System32\DRIVERS\tcpip.sys
      O41 - Driver: (TermDD) . (.Microsoft Corporation - Terminal Server Driver.) - C:\Windows\System32\DRIVERS\termdd.sys
      O41 - Driver: Carte vidéo VGA. (VgaSave) . (.Microsoft Corporation - VGA/Super VGA Video Driver.) - C:\WINDOWS\system32\drivers\vga.sys
      O41 - Driver: Environnement de prise en charge de Fournisseur de services non-IFS Windows Sockets 2.0 (WS2IFSL) . (.Microsoft Corporation - Winsock2 IFS Layer.) - C:\WINDOWS\system32\drivers\ws2ifsl.sys



      ---\\ Logiciels installés (O42)
      O42 - Logiciel: 32 Bit HP CIO Components Installer - (.Hewlett-Packard.) [HKLM] -- {F7B0E599-C114-4493-BC4D-D8FC7CBBABBB}
      O42 - Logiciel: Adobe Flash Player 10 ActiveX - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player ActiveX
      O42 - Logiciel: Adobe Flash Player 10 Plugin - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player Plugin
      O42 - Logiciel: Adobe Reader 8.1.3 - Français - (.Adobe Systems Incorporated.) [HKLM] -- {AC76BA86-7AD7-1036-7B44-A81300000003}
      O42 - Logiciel: Apple Application Support - (.Apple Inc..) [HKLM] -- {853A4763-6643-4604-8D64-28BDD8925F4C}
      O42 - Logiciel: Apple Mobile Device Support - (.Apple Inc..) [HKLM] -- {CACAEB5F-174D-4C7C-AC56-A33289A807CA}
      O42 - Logiciel: Apple Software Update - (.Apple Inc..) [HKLM] -- {6956856F-B6B3-4BE0-BA0B-8F495BE32033}
      O42 - Logiciel: Archiveur WinRAR - (.Pas de propriétaire.) [HKLM] -- WinRAR archiver
      O42 - Logiciel: Assistant de connexion Windows Live - (.Microsoft Corporation.) [HKLM] -- {D3116CC7-24DC-4CA3-9CE1-23FED836E9F2}
      O42 - Logiciel: AviSynth 2.5 - (.Pas de propriétaire.) [HKLM] -- AviSynth
      O42 - Logiciel: Bonjour - (.Apple Inc..) [HKLM] -- {C2E4B5BD-32DB-4817-A060-341AB17C3F90}
      O42 - Logiciel: CCleaner - (.Piriform.) [HKLM] -- CCleaner
      O42 - Logiciel: DivX Codec - (.DivX, Inc..) [HKLM] -- {7B63B2922B174135AFC0E1377DD81EC2}
      O42 - Logiciel: Galerie de photos Windows Live - (.Microsoft Corporation.) [HKLM] -- {B131E59D-202C-43C6-84C9-68F0C37541F1}
      O42 - Logiciel: Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) - (.Microsoft Corporation.) [HKLM] -- {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB953595
      O42 - Logiciel: Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) - (.Microsoft Corporation.) [HKLM] -- {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB958484
      O42 - Logiciel: Hotfix for Windows Media Format 11 SDK (KB929399) - (.Microsoft Corporation.) [HKLM] -- KB929399
      O42 - Logiciel: Hotfix for Windows XP (KB954550-v5) - (.Microsoft Corporation.) [HKLM] -- KB954550-v5
      O42 - Logiciel: Hotfix for Windows XP (KB976002-v5) - (.Microsoft Corporation.) [HKLM] -- KB976002-v5
      O42 - Logiciel: Installation Windows Live - (.Microsoft Corporation.) [HKLM] -- WinLiveSuite_Wave3
      O42 - Logiciel: Installation Windows Live - (.Microsoft Corporation.) [HKLM] -- {46ABBC54-1872-4AA3-95E2-F2C063A63F31}
      O42 - Logiciel: Intel(R) PRO Ethernet Adapter and Software - (.Pas de propriétaire.) [HKLM] -- PROSet
      O42 - Logiciel: Java(TM) 6 Update 13 - (.Sun Microsystems, Inc..) [HKLM] -- {26A24AE4-039D-4CA4-87B4-2F83216013FF}
      O42 - Logiciel: Java(TM) 6 Update 2 - (.Sun Microsystems, Inc..) [HKLM] -- {3248F0A8-6813-11D6-A77B-00B0D0160020}
      O42 - Logiciel: Java(TM) 6 Update 6 - (.Sun Microsystems, Inc..) [HKLM] -- {3248F0A8-6813-11D6-A77B-00B0D0160060}
      O42 - Logiciel: Junk Mail filter update - (.Microsoft Corporation.) [HKLM] -- {E2DFE069-083E-4631-9B6C-43C48E991DE5}
      O42 - Logiciel: K-Lite Codec Pack 3.4.5 Full - (.Pas de propriétaire.) [HKLM] -- KLiteCodecPack_is1
      O42 - Logiciel: MSVCRT - (.Microsoft.) [HKLM] -- {22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
      O42 - Logiciel: MSXML 4.0 SP2 (KB936181) - (.Microsoft Corporation.) [HKLM] -- {C04E32E0-0416-434D-AFB9-6969D703A9EF}
      O42 - Logiciel: MSXML 4.0 SP2 (KB954430) - (.Microsoft Corporation.) [HKLM] -- {86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
      O42 - Logiciel: MSXML 4.0 SP2 (KB973688) - (.Microsoft Corporation.) [HKLM] -- {F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
      O42 - Logiciel: MSXML 6 Service Pack 2 (KB973686) - (.Microsoft Corporation.) [HKLM] -- {56EA8BC0-3751-4B93-BC9D-6651CC36E5AA}
      O42 - Logiciel: Malwarebytes' Anti-Malware - (.Malwarebytes Corporation.) [HKLM] -- Malwarebytes' Anti-Malware_is1
      O42 - Logiciel: Microsoft .NET Framework 1.1 - (.Microsoft.) [HKLM] -- {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
      O42 - Logiciel: Microsoft .NET Framework 1.1 - (.Pas de propriétaire.) [HKLM] -- Microsoft .NET Framework 1.1 (1033)
      O42 - Logiciel: Microsoft .NET Framework 1.1 Security Update (KB2416447) - (.Pas de propriétaire.) [HKLM] -- M2416447
      O42 - Logiciel: Microsoft .NET Framework 1.1 Security Update (KB979906) - (.Pas de propriétaire.) [HKLM] -- M979906
      O42 - Logiciel: Microsoft .NET Framework 2.0 Service Pack 2 - (.Microsoft Corporation.) [HKLM] -- {C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}
      O42 - Logiciel: Microsoft .NET Framework 3.0 Service Pack 2 - (.Microsoft Corporation.) [HKLM] -- {A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}
      O42 - Logiciel: Microsoft .NET Framework 3.5 SP1 - (.Microsoft Corporation.) [HKLM] -- Microsoft .NET Framework 3.5 SP1
      O42 - Logiciel: Microsoft .NET Framework 3.5 SP1 - (.Microsoft Corporation.) [HKLM] -- {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
      O42 - Logiciel: Microsoft Choice Guard - (.Microsoft Corporation.) [HKLM] -- {F0E12BBA-AD66-4022-A453-A1C8A0C4D570}
      O42 - Logiciel: Microsoft Compression Client Pack 1.0 for Windows XP - (.Microsoft Corporation.) [HKLM] -- MSCompPackV1
      O42 - Logiciel: Microsoft Kernel-Mode Driver Framework Feature Pack 1.5 - (.Microsoft Corporation.) [HKLM] -- Wdf01005
      O42 - Logiciel: Microsoft Office 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}
      O42 - Logiciel: Microsoft Office 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-0015-040C-0000-0000000FF1CE}_PROPLUS_{AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
      O42 - Logiciel: Microsoft Office 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-0016-040C-0000-0000000FF1CE}_PROPLUS_{AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
      O42 - Logiciel: Microsoft Office 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-0018-040C-0000-0000000FF1CE}_PROPLUS_{AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
      O42 - Logiciel: Microsoft Office 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-0019-040C-0000-0000000FF1CE}_PROPLUS_{AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
      O42 - Logiciel: Microsoft Office 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-001A-040C-0000-0000000FF1CE}_PROPLUS_{AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
      O42 - Logiciel: Microsoft Office 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-001B-040C-0000-0000000FF1CE}_PROPLUS_{AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
      O42 - Logiciel: Microsoft Office 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-0044-040C-0000-0000000FF1CE}_PROPLUS_{AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
      O42 - Logiciel: Microsoft Office 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-006E-040C-0000-0000000FF1CE}_PROPLUS_{B165D3C2-40AE-4D39-86F7-E5C87C4264C0}
      O42 - Logiciel: Microsoft Office Access MUI (French) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-0015-040C-0000-0000000FF1CE}
      O42 - Logiciel: Microsoft Office Excel MUI (French) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-0016-040C-0000-0000000FF1CE}
      O42 - Logiciel: Microsoft Office InfoPath MUI (French) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-0044-040C-0000-0000000FF1CE}
      O42 - Logiciel: Microsoft Office Live Add-in 1.3 - (.Microsoft Corporation.) [HKLM] -- {57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}
      O42 - Logiciel: Microsoft Office Outlook Connector - (.Microsoft Corporation.) [HKLM] -- {95120000-0122-040C-0000-0000000FF1CE}
      O42 - Logiciel: Microsoft Office Outlook MUI (French) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-001A-040C-0000-0000000FF1CE}
      O42 - Logiciel: Microsoft Office PowerPoint MUI (French) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-0018-040C-0000-0000000FF1CE}
      O42 - Logiciel: Microsoft Office Professional Plus 2007 - (.Microsoft Corporation.) [HKLM] -- PROPLUS
      O42 - Logiciel: Microsoft Office Professional Plus 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}
      O42 - Logiciel: Microsoft Office Proof (Arabic) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-001F-0401-0000-0000000FF1CE}
      O42 - Logiciel: Microsoft Office Proof (Dutch) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-001F-0413-0000-0000000FF1CE}
      O42 - Logiciel: Microsoft Office Proof (English) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-001F-0409-0000-0000000FF1CE}
      O42 - Logiciel: Microsoft Office Proof (French) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-001F-040C-0000-0000000FF1CE}
      O42 - Logiciel: Microsoft Office Proof (German) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-001F-0407-0000-0000000FF1CE}
      O42 - Logiciel: Microsoft Office Proof (Spanish) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-001F-0C0A-0000-0000000FF1CE}
      O42 - Logiciel: Microsoft Office Proofing (French) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-002C-040C-0000-0000000FF1CE}
      O42 - Logiciel: Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-001F-0401-0000-0000000FF1CE}_PROPLUS_{14809F99-C601-4D4A-9391-F1E8FAA964C5}
      O42 - Logiciel: Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-001F-0407-0000-0000000FF1CE}_PROPLUS_{A0516415-ED61-419A-981D-93596DA74165}
      O42 - Logiciel: Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-001F-0409-0000-0000000FF1CE}_PROPLUS_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}
      O42 - Logiciel: Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-001F-040C-0000-0000000FF1CE}_PROPLUS_{F580DDD5-8D37-4998-968E-EBB76BB86787}
      O42 - Logiciel: Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-001F-0413-0000-0000000FF1CE}_PROPLUS_{D66D5A44-E480-4BA4-B4F2-C554F6B30EBB}
      O42 - Logiciel: Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-001F-0C0A-0000-0000000FF1CE}_PROPLUS_{187308AB-5FA7-4F14-9AB9-D290383A10D9}
      O42 - Logiciel: Microsoft Office Publisher MUI (French) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-0019-040C-0000-0000000FF1CE}
      O42 - Logiciel: Microsoft Office Shared MUI (French) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-006E-040C-0000-0000000FF1CE}
      O42 - Logiciel: Microsoft Office Word MUI (French) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-001B-040C-0000-0000000FF1CE}
      O42 - Logiciel: Microsoft SQL Server 2005 Compact Edition [ENU] - (.Microsoft Corporation.) [HKLM] -- {F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
      O42 - Logiciel: Microsoft Silverlight - (.Microsoft Corporation.) [HKLM] -- {89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
      O42 - Logiciel: Microsoft User-Mode Driver Framework Feature Pack 1.0 - (.Microsoft Corporation.) [HKLM] -- Wudf01000
      O42 - Logiciel: Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 - (.Microsoft Corporation.) [HKLM] -- {770657D0-A123-3C07-8E44-1C83EC895118}
      O42 - Logiciel: Microsoft Visual C++ 2005 Redistributable - (.Microsoft Corporation.) [HKLM] -- {7299052b-02a4-4627-81f2-1818da5d550d}
      O42 - Logiciel: Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 - (.Microsoft Corporation.) [HKLM] -- {1F1C2DFC-2D24-3E06-BCB8-725134ADF989}
      O42 - Logiciel: Mozilla Firefox 4.0.1 (x86 fr) - (.Mozilla.) [HKLM] -- Mozilla Firefox 4.0.1 (x86 fr)
      O42 - Logiciel: OpenOffice.org 2.3 - (.OpenOffice.org.) [HKLM] -- {FADB55D0-403F-4413-A268-CF0A6F1185C2}
      O42 - Logiciel: Outil de téléchargement Windows Live - (.Microsoft Corporation.) [HKLM] -- {205C6BDD-7B73-42DE-8505-9A093F35A238}
      O42 - Logiciel: Package de pilotes Windows - MobileTop (sshpmdm) Modem (02/23/2007 2.5.0.0) - (.MobileTop.) [HKLM] -- 6194C28A8F62DD817EA1B918E6E46E806A21B452
      O42 - Logiciel: Package de pilotes Windows - MobileTop (sshpusb) USB (02/23/2007 2.5.0.0) - (.MobileTop.) [HKLM] -- 65B6FE5418CE28F4D72543FB2D964C3CEC83F161
      O42 - Logiciel: QuickTime - (.Apple Inc..) [HKLM] -- {57752979-A1C9-4C02-856B-FBB27AC4E02C}
      O42 - Logiciel: Safari - (.Apple Inc..) [HKLM] -- {6B9B0C6F-E5FA-4633-A640-AB98A272ECCA}
      O42 - Logiciel: Security Update for 2007 Microsoft Office System (KB2288621) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{5C497F0B-2061-4CC9-A61C-6B45B867354D}
      O42 - Logiciel: Security Update for 2007 Microsoft Office System (KB2288931) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{CD769337-C8AC-46DB-A7DC-643E50089263}
      O42 - Logiciel: Security Update for 2007 Microsoft Office System (KB2345043) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{536FB502-775F-4494-BACE-C02CC90B7A5B}
      O42 - Logiciel: Security Update for 2007 Microsoft Office System (KB2466156) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{CEF209AB-F96D-404F-B5CC-44057C057CA3}
      O42 - Logiciel: Security Update for 2007 Microsoft Office System (KB2509488) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{AD0DE453-0804-4495-9C91-33D0F9AA5463}
      O42 - Logiciel: Security Update for 2007 Microsoft Office System (KB969559) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{69F52148-9BF6-4CDC-BF76-103DEAF3DD08}
      O42 - Logiciel: Security Update for 2007 Microsoft Office System (KB976321) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{7F207DCA-3399-40CB-A968-6E5991B1421A}
      O42 - Logiciel: Security Update for CAPICOM (KB931906) - (.Microsoft Corporation.) [HKLM] -- KB931906
      O42 - Logiciel: Security Update for CAPICOM (KB931906) - (.Microsoft Corporation.) [HKLM] -- {0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
      O42 - Logiciel: Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473) - (.Microsoft Corporation.) [HKLM] -- {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB2416473
      O42 - Logiciel: Security Update for Microsoft Office Access 2007 (KB979440) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{1142CCEC-ACA9-484B-BA90-C3A5CA1988C5}
      O42 - Logiciel: Security Update for Microsoft Office Access 2007 (KB979440) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{5A4E43D5-858F-49BD-BA72-8F30E1793060}
      O42 - Logiciel: Security Update for Microsoft Office Excel 2007 (KB2464583) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{151E2FEA-C3A6-4CB6-BE6B-16651FDF04BE}
      O42 - Logiciel: Security Update for Microsoft Office InfoPath 2007 (KB979441) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{1109D0B3-EFA3-4553-AAED-4C3E9AD130E8}
      O42 - Logiciel: Security Update for Microsoft Office InfoPath 2007 (KB979441) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{8CCB781A-CF6B-4FCB-B6D8-59C64DF5C6DB}
      O42 - Logiciel: Security Update for Microsoft Office PowerPoint 2007 (KB2535818) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{8588DD11-6BD7-4400-B55C-DD5AB74B43E1}
      O42 - Logiciel: Security Update for Microsoft Office PowerPoint Viewer 2007 (KB2464623) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{D75E6D0C-BADF-4F41-98B2-0C0F02C15062}
      O42 - Logiciel: Security Update for Microsoft Office Publisher 2007 (KB2284697) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{3A4CDE54-2403-483D-8D9A-15E3264410DF}
      O42 - Logiciel: Security Update for Microsoft Office Visio Viewer 2007 (KB973709) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{71127777-8B2C-4F97-AF7A-6CF8CAC8224D}
      O42 - Logiciel: Security Update for Microsoft Office Word 2007 (KB2344993) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{7A5B74FA-7A92-4FC9-821A-2DD5D4E73E48}
      O42 - Logiciel: Security Update for Microsoft Office system 2007 (972581) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{3D019598-7B59-447A-80AE-815B703B84FF}
      O42 - Logiciel: Security Update for Microsoft Office system 2007 (KB974234) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{FCD742B9-7A55-44BC-A776-F795F21FEDDC}
      O42 - Logiciel: Segoe UI - (.Microsoft Corp.) [HKLM] -- {A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}
      O42 - Logiciel: Update for 2007 Microsoft Office System (KB967642) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}
      O42 - Logiciel: Update for Microsoft .NET Framework 3.5 SP1 (KB963707) - (.Microsoft Corporation.) [HKLM] -- {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB963707
      O42 - Logiciel: Update for Microsoft Office Outlook 2007 (KB2509470) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{1365864D-4C58-489D-9982-844D75691CCC}
      O42 - Logiciel: Update for Outlook 2007 Junk Email Filter (KB2536413) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{95DF5260-331D-4FFD-A2D5-C64164751945}
      O42 - Logiciel: Utilitaire de configuration iPhone - (.Apple Inc..) [HKLM] -- {FA54AFB1-5745-4389-B8C1-9F7509672ED1}
      O42 - Logiciel: VCRedistSetup - (.Nero AG.) [HKLM] -- {3921A67A-5AB1-4E48-9444-C71814CF3027}
      O42 - Logiciel: Windows Genuine Advantage Notifications (KB905474) - (.Microsoft Corporation.) [HKLM] -- WgaNotify
      O42 - Logiciel: Windows Imaging Component - (.Microsoft Corporation.) [HKLM] -- WIC
      O42 - Logiciel: Windows Internet Explorer 8 - (.Microsoft Corporation.) [HKLM] -- ie8
      O42 - Logiciel: Windows Live Call - (.Microsoft Corporation.) [HKLM] -- {82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}
      O42 - Logiciel: Windows Live Communications Platform - (.Microsoft Corporation.) [HKLM] -- {3B4E636E-9D65-4D67-BA61-189800823F52}
      O42 - Logiciel: Windows Live Mail - (.Microsoft Corporation.) [HKLM] -- {5DD76286-9BE7-4894-A990-E905E91AC818}
      O42 - Logiciel: Windows Live Messenger - (.Microsoft Corporation.) [HKLM] -- {770F1BEC-2871-4E70-B837-FB8525FFA3B1}
      O42 - Logiciel: Windows Live OneCare safety scanner - (.Pas de propriétaire.) [HKLM] -- Windows Live OneCare safety scanner
      O42 - Logiciel: Windows Live Writer - (.Microsoft Corporation.) [HKLM] -- {4634B21A-CC07-4396-890C-2B8168661FEA}
      O42 - Logiciel: Windows Media Format 11 runtime - (.Microsoft Corporation.) [HKLM] -- WMFDist11
      O42 - Logiciel: Windows Media Format 11 runtime - (.Pas de propriétaire.) [HKLM] -- Windows Media Format Runtime
      O42 - Logiciel: Windows XP Service Pack 3 - (.Microsoft Corporation.) [HKLM] -- Windows XP Service
      O42 - Logiciel: iTunes - (.Apple Inc..) [HKLM] -- {F59A9E08-A6A4-4ACF-91F2-D0344956C30B}
      O42 - Logiciel: neroxml - (.Nero AG.) [HKLM] -- {56C049BE-79E9-4502-BEA7-9754A3E60F9B}

      ---\\ HKCU & HKLM Software Keys
      [HKCU\Software\AC3filter]
      [HKCU\Software\ALWIL Software]
      [HKCU\Software\AVS4YOU]
      [HKCU\Software\Adobe]
      [HKCU\Software\Ahead]
      [HKCU\Software\AppDataLow]
      [HKCU\Software\Apple Computer, Inc.]
      [HKCU\Software\Apple Inc.]
      [HKCU\Software\Aurigma]
      [HKCU\Software\Bugsplat]
      [HKCU\Software\CDDB]
      [HKCU\Software\CREATIVE TECH]
      [HKCU\Software\CeWe Color]
      [HKCU\Software\Classes]
      [HKCU\Software\Clients]
      [HKCU\Software\CoreVorbis]
      [HKCU\Software\Cucusoft, Inc.]
      [HKCU\Software\Cyberlink]
      [HKCU\Software\DSP-worx]
      [HKCU\Software\DVDVideoSoft]
      [HKCU\Software\DivXNetworks]
      [HKCU\Software\FotoWire]
      [HKCU\Software\GNU]
      [HKCU\Software\GSpot Appliance Corp]
      [HKCU\Software\Gabest]
      [HKCU\Software\Google]
      [HKCU\Software\Haali]
      [HKCU\Software\Hewlett-Packard]
      [HKCU\Software\IM Providers]
      [HKCU\Software\Intel]
      [HKCU\Software\Iris]
      [HKCU\Software\Jasc]
      [HKCU\Software\JavaSoft]
      [HKCU\Software\Local AppWizard-Generated Applications]
      [HKCU\Software\Logitech]
      [HKCU\Software\Macromedia]
      [HKCU\Software\Magnet]
      [HKCU\Software\Malwarebytes' Anti-Malware]
      [HKCU\Software\MozillaPlugins]
      [HKCU\Software\Mozilla]
      [HKCU\Software\Nero]
      [HKCU\Software\Netscape]
      [HKCU\Software\ODBC]
      [HKCU\Software\PT25DHYRAW]
      [HKCU\Software\Piriform]
      [HKCU\Software\Policies]
      [HKCU\Software\Samsung]
      [HKCU\Software\Skype]
      [HKCU\Software\Sysinternals]
      [HKCU\Software\Trafficninja]
      [HKCU\Software\Trolltech]
      [HKCU\Software\VB and VBA Program Settings]
      [HKCU\Software\Veoh]
      [HKCU\Software\Wget]
      [HKCU\Software\WinRAR SFX]
      [HKCU\Software\WinRAR]
      [HKCU\Software\YahooPartnerToolbar]
      [HKCU\Software\eBay]
      [HKCU\Software\yahooinstall]
      [HKLM\Software\781]
      [HKLM\Software\ALWIL Software]
      [HKLM\Software\AVAST Software]
      [HKLM\Software\AVS4YOU]
      [HKLM\Software\Adobe]
      [HKLM\Software\Ahead]
      [HKLM\Software\Apple Computer, Inc.]
      [HKLM\Software\Apple Inc.]
      [HKLM\Software\Audible]
      [HKLM\Software\BroadJump]
      [HKLM\Software\Broadcom]
      [HKLM\Software\BrowserChoice]
      [HKLM\Software\C07ft5Y]
      [HKLM\Software\CDDB]
      [HKLM\Software\CLSYSTEM]
      [HKLM\Software\Classes]
      [HKLM\Software\Clients]
      [HKLM\Software\Codec tweak Tool]
      [HKLM\Software\Creative Tech]
      [HKLM\Software\Cyberlink]
      [HKLM\Software\DVDVideoSoft]
      [HKLM\Software\DivXNetworks]
      [HKLM\Software\GEAR Software]
      [HKLM\Software\GNU]
      [HKLM\Software\Gabest]
      [HKLM\Software\Gemplus]
      [HKLM\Software\Google]
      [HKLM\Software\HPS]
      [HKLM\Software\HaaliMkx]
      [HKLM\Software\Hewlett-Packard]
      [HKLM\Software\I.R.I.S.]
      [HKLM\Software\InstallShield]
      [HKLM\Software\InstalledOptions]
      [HKLM\Software\Intel]
      [HKLM\Software\InterVideo]
      [HKLM\Software\JavaSoft]
      [HKLM\Software\KLCodecPack]
      [HKLM\Software\Ktdxgcor]
      [HKLM\Software\Logitech]
      [HKLM\Software\Macromedia]
      [HKLM\Software\Malwarebytes' Anti-Malware]
      [HKLM\Software\MarkAny]
      [HKLM\Software\Matrox]
      [HKLM\Software\MozillaPlugins]
      [HKLM\Software\Mozilla]
      [HKLM\Software\NVIDIA Corporation]
      [HKLM\Software\Nero]
      [HKLM\Software\Ntpad]
      [HKLM\Software\ODBC]
      [HKLM\Software\OpenOffice.org]
      [HKLM\Software\Piriform]
      [HKLM\Software\Policies]
      [HKLM\Software\Program Groups]
      [HKLM\Software\Rainbow Technologies]
      [HKLM\Software\RegisteredApplications]
      [HKLM\Software\Reviversoft]
      [HKLM\Software\S3R521]
      [HKLM\Software\Schlumberger]
      [HKLM\Software\Secure]
      [HKLM\Software\SoundFont]
      [HKLM\Software\Sun Microsystems]
      [HKLM\Software\Swearware]
      [HKLM\Software\Windows 3.1 Migration Status]
      [HKLM\Software\mozilla.org]



      ---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43)
      O43 - CFD: 21/11/2008 - 17:33:34 - [128796416] ----D- C:\Program Files\Adobe
      O43 - CFD: 13/07/2010 - 13:32:38 - [156388801] ----D- C:\Program Files\Alwil Software
      O43 - CFD: 27/09/2008 - 08:40:08 - [2221118] ----D- C:\Program Files\Apple Software Update
      O43 - CFD: 26/06/2010 - 18:45:16 - [4859926] ----D- C:\Program Files\AviSynth 2.5
      O43 - CFD: 14/05/2011 - 01:20:00 - [620967] ----D- C:\Program Files\Bonjour
      O43 - CFD: 27/04/2011 - 20:27:56 - [3704864] ----D- C:\Program Files\CCleaner
      O43 - CFD: 08/05/2009 - 22:59:28 - [1005568] ----D- C:\Program Files\Common Files
      O43 - CFD: 19/09/2007 - 17:24:50 - [0] ----D- C:\Program Files\ComPlus Applications
      O43 - CFD: 13/04/2011 - 20:42:14 - [14216193] ----D- C:\Program Files\Cucusoft
      O43 - CFD: 14/05/2009 - 23:58:44 - [2916264] ----D- C:\Program Files\DIFX
      O43 - CFD: 15/05/2011 - 18:01:14 - [1890602] ----D- C:\Program Files\DivX
      O43 - CFD: 18/05/2011 - 21:31:46 - [735423275] ----D- C:\Program Files\Fichiers communs
      O43 - CFD: 30/04/2011 - 14:50:56 - [3783584] ----D- C:\Program Files\Google
      O43 - CFD: 24/04/2011 - 22:01:26 - [368640] --H-D- C:\Program Files\InstallShield Installation Information
      O43 - CFD: 15/04/2011 - 21:21:44 - [5649624] ----D- C:\Program Files\Internet Explorer
      O43 - CFD: 14/05/2011 - 01:28:10 - [1856627] ----D- C:\Program Files\iPod
      O43 - CFD: 14/05/2011 - 01:29:42 - [128197016] ----D- C:\Program Files\iTunes
      O43 - CFD: 02/06/2009 - 13:14:34 - [237134287] ----D- C:\Program Files\Java
      O43 - CFD: 19/09/2007 - 18:26:48 - [26123917] ----D- C:\Program Files\K-Lite Codec Pack
      O43 - CFD: 30/04/2011 - 13:35:06 - [77214238] ----D- C:\Program Files\LimeWire
      O43 - CFD: 30/04/2011 - 13:36:28 - [0] ----D- C:\Program Files\Logitech
      O43 - CFD: 25/04/2011 - 21:27:38 - [4922237] ----D- C:\Program Files\Malwarebytes' Anti-Malware
      O43 - CFD: 22/03/2010 - 23:02:16 - [2147758] ----D- C:\Program Files\Messenger
      O43 - CFD: 09/12/2009 - 19:45:02 - [728627] ----D- C:\Program Files\Microsoft
      O43 - CFD: 10/03/2008 - 15:07:06 - [800662] ----D- C:\Program Files\Microsoft CAPICOM 2.1.0.2
      O43 - CFD: 19/09/2007 - 17:28:16 - [0] ----D- C:\Program Files\microsoft frontpage
      O43 - CFD: 13/05/2008 - 20:57:04 - [561454552] ----D- C:\Program Files\Microsoft Office
      O43 - CFD: 09/12/2009 - 19:50:10 - [1559148] ----D- C:\Program Files\Microsoft Office Outlook Connector
      O43 - CFD: 21/04/2011 - 19:59:10 - [38388859] ----D- C:\Program Files\Microsoft Silverlight
      O43 - CFD: 08/05/2009 - 23:10:44 - [1829877] ----D- C:\Program Files\Microsoft SQL Server Compact Edition
      O43 - CFD: 13/05/2008 - 20:56:58 - [14904] ----D- C:\Program Files\Microsoft Visual Studio
      O43 - CFD: 02/12/2009 - 00:56:52 - [3726168] ----D- C:\Program Files\Microsoft Works
      O43 - CFD: 22/08/2010 - 21:17:32 - [10374874] ----D- C:\Program Files\Movie Maker
      O43 - CFD: 15/05/2011 - 18:01:14 - [32638570] ----D- C:\Program Files\Mozilla Firefox
      O43 - CFD: 15/08/2009 - 02:01:28 - [26521] ----D- C:\Program Files\MSBuild
      O43 - CFD: 15/05/2011 - 18:02:56 - [19278399] ----D- C:\Program Files\MSN
      O43 - CFD: 19/09/2007 - 17:24:32 - [0] ----D- C:\Program Files\MSN Gaming Zone
      O43 - CFD: 14/11/2007 - 16:42:08 - [0] ----D- C:\Program Files\MSXML 4.0
      O43 - CFD: 15/08/2009 - 01:57:00 - [6849] ----D- C:\Program Files\MSXML 6.0
      O43 - CFD: 21/03/2010 - 14:37:18 - [3285523] ----D- C:\Program Files\NetMeeting
      O43 - CFD: 19/09/2007 - 17:24:40 - [1804] ----D- C:\Program Files\Online Services
      O43 - CFD: 07/11/2007 - 16:59:50 - [319687453] ----D- C:\Program Files\OpenOffice.org 2.3
      O43 - CFD: 16/12/2010 - 21:53:02 - [4379321] ----D- C:\Program Files\Outlook Express
      O43 - CFD: 30/01/2011 - 17:40:40 - [76322555] ----D- C:\Program Files\QuickTime
      O43 - CFD: 15/08/2009 - 02:01:16 - [36400897] ----D- C:\Program Files\Reference Assemblies
      O43 - CFD: 30/01/2011 - 17:46:02 - [42293335] ----D- C:\Program Files\Safari
      O43 - CFD: 19/09/2007 - 17:26:34 - [1025] ----D- C:\Program Files\Services en ligne
      O43 - CFD: 19/09/2007 - 17:33:48 - [0] --H-D- C:\Program Files\Uninstall Information
      O43 - CFD: 24/09/2009 - 17:30:06 - [23509198] ----D- C:\Program Files\Utilitaire de configuration iPhone
      O43 - CFD: 09/12/2009 - 19:49:00 - [130598388] ----D- C:\Program Files\Windows Live
      O43 - CFD: 15/07/2009 - 12:41:12 - [44923857] ----D- C:\Program Files\Windows Live Safety Center
      O43 - CFD: 08/05/2009 - 23:08:04 - [245112] ----D- C:\Program Files\Windows Live SkyDrive
      O43 - CFD: 14/12/2007 - 12:56:04 - [0] ----D- C:\Program Files\Windows Media Connect 2
      O43 - CFD: 08/07/2010 - 19:30:00 - [5142414] ----D- C:\Program Files\Windows Media Player
      O43 - CFD: 15/05/2011 - 20:46:42 - [1611264] ----D- C:\Program Files\Windows NT
      O43 - CFD: 19/09/2007 - 17:26:36 - [0] --H-D- C:\Program Files\WindowsUpdate
      O43 - CFD: 24/09/2007 - 20:30:10 - [4235318] ----D- C:\Program Files\Winrar
      O43 - CFD: 19/09/2007 - 17:28:16 - [0] ----D- C:\Program Files\xerox
      O43 - CFD: 21/05/2011 - 22:41:20 - [6444538] ----D- C:\Program Files\ZHPDiag
      O43 - CFD: 20/09/2007 - 20:12:44 - [1005568] ----D- C:\Program Files\Common Files\Motive
      O43 - CFD: 18/05/2011 - 14:56:46 - [4530200] --H-D- C:\Documents and Settings\Tommy\Application Data\Adobe
      O43 - CFD: 29/05/2010 - 18:34:02 - [53248] --H-D- C:\Documents and Settings\Tommy\Application Data\AdSigner
      O43 - CFD: 27/09/2008 - 14:49:44 - [0] --H-D- C:\Documents and Settings\Tommy\Application Data\Alchemy Mindworks
      O43 - CFD: 27/11/2010 - 11:59:48 - [9459425401] --H-D- C:\Documents and Settings\Tommy\Application Data\Apple Computer
      O43 - CFD: 10/08/2009 - 13:10:58 - [37265] --H-D- C:\Documents and Settings\Tommy\Application Data\AVS4YOU
      O43 - CFD: 16/04/2011 - 19:19:06 - [0] --H-D- C:\Documents and Settings\Tommy\Application Data\BabylonToolbar
      O43 - CFD: 13/04/2011 - 20:50:02 - [1462] --H-D- C:\Documents and Settings\Tommy\Application Data\DiskAid
      O43 - CFD: 24/11/2008 - 14:11:28 - [13368] --H-D- C:\Documents and Settings\Tommy\Application Data\DivX
      O43 - CFD: 04/04/2011 - 20:50:56 - [1323008] --H-D- C:\Documents and Settings\Tommy\Application Data\DTencryptor-H
      O43 - CFD: 31/12/2010 - 17:32:26 - [1323008] --H-D- C:\Documents and Settings\Tommy\Application Data\DTencryptor-I
      O43 - CFD: 28/10/2007 - 15:29:34 - [33039] --H-D- C:\Documents and Settings\Tommy\Application Data\Google
      O43 - CFD: 22/03/2009 - 15:15:00 - [51795] --H-D- C:\Documents and Settings\Tommy\Application Data\HP
      O43 - CFD: 19/09/2007 - 17:33:52 - [0] --H-D- C:\Documents and Settings\Tommy\Application Data\Identities
      O43 - CFD: 13/04/2011 - 20:43:00 - [4767209] --H-D- C:\Documents and Settings\Tommy\Application Data\iPhone Tool Kits
      O43 - CFD: 27/09/2008 - 18:07:28 - [0] --H-D- C:\Documents and Settings\Tommy\Application Data\Jasc
      O43 - CFD: 24/03/2011 - 00:29:54 - [103111644] --H-D- C:\Documents and Settings\Tommy\Application Data\LimeWire
      O43 - CFD: 21/09/2007 - 19:47:12 - [1931224] --H-D- C:\Documents and Settings\Tommy\Application Data\Macromedia
      O43 - CFD: 25/04/2011 - 22:16:46 - [14468] ----D- C:\Documents and Settings\Tommy\Application Data\Malwarebytes
      O43 - CFD: 20/09/2007 - 13:00:00 - [95] --H-D- C:\Documents and Settings\Tommy\Application Data\Media Player Classic
      O43 - CFD: 05/09/2010 - 14:54:18 - [9090716] -S--D- C:\Documents and Settings\Tommy\Application Data\Microsoft
      O43 - CFD: 13/11/2008 - 16:13:50 - [475096] --H-D- C:\Documents and Settings\Tommy\Application Data\Mostick
      O43 - CFD: 29/08/2008 - 16:30:00 - [24591694] --H-D- C:\Documents and Settings\Tommy\Application Data\Mozilla
      O43 - CFD: 15/05/2011 - 18:02:54 - [327] ----D- C:\Documents and Settings\Tommy\Application Data\MSNInstaller
      O43 - CFD: 12/12/2007 - 20:39:14 - [101085] --H-D- C:\Documents and Settings\Tommy\Application Data\Nero
      O43 - CFD: 01/05/2011 - 10:44:52 - [1714947] --H-D- C:\Documents and Settings\Tommy\Application Data\OpenOffice.org2
      O43 - CFD: 08/07/2010 - 18:59:06 - [0] --H-D- C:\Documents and Settings\Tommy\Application Data\Samsung
      O43 - CFD: 20/03/2011 - 22:42:58 - [5339941] --H-D- C:\Documents and Settings\Tommy\Application Data\Skype
      O43 - CFD: 20/03/2011 - 22:12:32 - [12536] --H-D- C:\Documents and Settings\Tommy\Application Data\skypePM
      O43 - CFD: 04/05/2008 - 19:31:24 - [9925952] --H-D- C:\Documents and Settings\Tommy\Application Data\Sun
      O43 - CFD: 08/06/2008 - 10:11:10 - [45056] --H-D- C:\Documents and Settings\Tommy\Application Data\TaoUSign
      O43 - CFD: 09/12/2009 - 20:37:06 - [18188499] --H-D- C:\Documents and Settings\Tommy\Application Data\Thinstall
      O43 - CFD: 17/09/2010 - 22:15:56 - [3604480] --H-D- C:\Documents and Settings\Tommy\Application Data\U3
      O43 - CFD: 27/04/2011 - 22:27:26 - [9164] ----D- C:\Documents and Settings\Tommy\Application Data\WindSolutions
      O43 - CFD: 13/02/2010 - 18:24:32 - [392942] --H-D- C:\Documents and Settings\Tommy\Local Settings\Application Data\Adobe
      O43 - CFD: 12/12/2007 - 20:51:56 - [2756426] --H-D- C:\Documents and Settings\Tommy\Local Settings\Application Data\Ahead
      O43 - CFD: 21/09/2007 - 20:44:46 - [0] --H-D- C:\Documents and Settings\Tommy\Local Settings\Application Data\Apple
      O43 - CFD: 27/11/2010 - 11:59:48 - [115339645] --H-D- C:\Documents and Settings\Tommy\Local Settings\Application Data\Apple Computer
      O43 - CFD: 10/08/2009 - 13:11:40 - [3966] --H-D- C:\Documents and Settings\Tommy\Local Settings\Application Data\ApplicationHistory
      O43 - CFD: 15/05/2011 - 16:42:24 - [83707] --H-D- C:\Documents and Settings\Tommy\Local Settings\Application Data\Google
      O43 - CFD: 22/03/2009 - 15:13:46 - [8892585] --H-D- C:\Documents and Settings\Tommy\Local Settings\Application Data\HP
      O43 - CFD: 23/10/2007 - 17:59:48 - [303396] --H-D- C:\Documents and Settings\Tommy\Local Settings\Application Data\Identities
      O43 - CFD: 20/09/2007 - 20:11:54 - [0] --H-D- C:\Documents and Settings\Tommy\Local Settings\Application Data\Logitech-LS
      O43 - CFD: 02/05/2011 - 22:47:00 - [333720244] --H-D- C:\Documents and Settings\Tommy\Local Settings\Application Data\Microsoft
      O43 - CFD: 13/05/2008 - 20:51:48 - [0] --H-D- C:\Documents and Settings\Tommy\Local Settings\Application Data\Microsoft Help
      O43 - CFD: 13/11/2008 - 16:13:50 - [580004] --H-D- C:\Documents and Settings\Tommy\Local Settings\Application Data\Mostick
      O43 - CFD: 14/04/2008 - 19:35:58 - [109298202] --H-D- C:\Documents and Settings\Tommy\Local Settings\Application Data\Mozilla
      O43 - CFD: 09/03/2008 - 17:25:34 - [0] --H-D- C:\Documents and Settings\Tommy\Local Settings\Application Data\PCHealth
      O43 - CFD: 27/04/2011 - 20:28:36 - [0] --H-D- C:\Documents and Settings\Tommy\Local Settings\Application Data\Temp



      ---\\ Derniers fichiers modifiés ou crées sous Windows et System32 (O44)
      O44 - LFC:[MD5.7F7AE8DA948DB614ED3ADEA99AE1E6AE] - 21/05/2011 - 21:28:05 ---A- . (...) -- C:\WINDOWS\System32\d3d9caps.tmp [1324]
      O44 - LFC:[MD5.DCEE1200F915817C00FCFD7FB0EF1200] - 21/05/2011 - 21:02:51 ---A- . (...) -- C:\WINDOWS\WindowsUpdate.log [1118424]
      O44 - LFC:[MD5.68AD2475739952AAEB5194C739D2B2DF] - 21/05/2011 - 15:58:53 ---A- . (...) -- C:\WINDOWS\setupapi.log [22601]
      O44 - LFC:[MD5.D41D8CD98F00B204E9800998ECF8427E] - 21/05/2011 - 15:58:52 ---A- . (...) -- C:\WINDOWS\0.log [0]
      O44 - LFC:[MD5.DCEE1200F915817C00FCFD7FB0EF1200] - 21/05/2011 - 15:58:22 ---A- . (...) -- C:\WINDOWS\wiadebug.log [159]
      O44 - LFC:[MD5.DCEE1200F915817C00FCFD7FB0EF1200] - 21/05/2011 - 15:58:22 ---A- . (...) -- C:\WINDOWS\wiaservc.log [50]
      O44 - LFC:[MD5.6A2CB42966136854F4464516FBB4AE72] - 21/05/2011 - 15:57:59 -S-A- . (...) -- C:\WINDOWS\bootstat.dat [2048]
      O44 - LFC:[MD5.D28DAF9AE85ECA769869D64C257DF485] - 21/05/2011 - 14:46:55 ---A- . (...) -- C:\WINDOWS\KB979687.log [12376]
      O44 - LFC:[MD5.36FCE79A750B6ADCB0257A58E89AF940] - 21/05/2011 - 14:46:14 ---A- . (...) -- C:\WINDOWS\KB978706.log [12001]
      O44 - LFC:[MD5.DCEE1200F915817C00FCFD7FB0EF1200] - 21/05/2011 - 10:49:37 ---A- . (...) -- C:\WINDOWS\SchedLgU.Txt [32520]
      O44 - LFC:[MD5.103D0C47794104B6B58A249000076422] - 21/05/2011 - 10:49:32 ---A- . (...) -- C:\WINDOWS\KB2485663.log [8481]
      O44 - LFC:[MD5.B668C3D052FE4749E94A1DCC207B3F13] - 21/05/2011 - 10:48:53 ---A- . (...) -- C:\WINDOWS\KB973904.log [8468]
      O44 - LFC:[MD5.13E839A1DE6DBABE2FEC8C363F099D4E] - 21/05/2011 - 10:48:13 ---A- . (...) -- C:\WINDOWS\KB923561.log [8468]
      O44 - LFC:[MD5.4022377A7F2CDAC1D57557C3D75562CB] - 18/05/2011 - 20:43:47 ---A- . (...) -- C:\ComboFix.txt [11028]
      O44 - LFC:[MD5.C9DD76D0EF94637C77FF8CA5E0FB0684] - 18/05/2011 - 20:37:45 ---A- . (...) -- C:\WINDOWS\system.ini [227]
      O44 - LFC:[MD5.499EF3AE8D9F4244E61811F99EA17993] - 18/05/2011 - 20:25:52 ---A- . (...) -- C:\CF-Submit.htm [1276]
      O44 - LFC:[MD5.88633907E9A7090974B545F46850423D] - 18/05/2011 - 13:45:27 RSHA- . (...) -- C:\boot.ini [328]
      O44 - LFC:[MD5.AE72E8619CB31D84DA25E2435E55003C] - 18/05/2011 - 13:38:15 ---A- . (.NirSoft - NirCmd.) -- C:\WINDOWS\NIRCMD.exe [31232]
      O44 - LFC:[MD5.01D95A1F8CF13D07CC564AABB36BCC0B] - 18/05/2011 - 13:38:15 ---A- . (.SteelWerX - Freeware implementation of REG.EXE.) -- C:\WINDOWS\SWREG.exe [161792]
      O44 - LFC:[MD5.B7517DB073B28F5696A1E5528ABEB5D0] - 18/05/2011 - 13:38:15 ---A- . (.SteelWerX - Freeware implementation of SC.EXE.) -- C:\WINDOWS\SWSC.exe [136704]
      O44 - LFC:[MD5.B1A9CF0B6F80611D31987C247EC630B4] - 18/05/2011 - 13:38:15 ---A- . (.SteelWerX - Freeware implementation of XCACLS.) -- C:\WINDOWS\SWXCACLS.exe [212480]
      O44 - LFC:[MD5.C790B08C6F0405499F813167DE1D48D0] - 18/05/2011 - 13:21:16 ---A- . (...) -- C:\PhysicalDisk0_MBR.bin [512]
      O44 - LFC:[MD5.43847A56AEE65BEC2EBCF96519616E27] - 01/05/2011 - 10:14:57 ---A- . (...) -- C:\WINDOWS\System32\d3d8caps.dat [552]
      O44 - LFC:[MD5.D68E165C3123ABA3B1282EDDB4213BD8] - 25/04/2011 - 20:27:35 R--A- . (.Malwarebytes Corporation - Malwarebytes' Anti-Malware.) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys [38224]
      O44 - LFC:[MD5.836E0E09CA9869BE7EB39EF2CF3602C7] - 25/04/2011 - 20:27:32 R--A- . (.Malwarebytes Corporation - Malwarebytes' Anti-Malware.) -- C:\WINDOWS\System32\drivers\mbam.sys [20952]
      O44 - LFC:[MD5.9DAA7218961710008D7385B01BD3F386] - 08/11/2010 - 00:20:24 ---A- . (...) -- C:\WINDOWS\MBR.exe [89088]
      O44 - LFC:[MD5.F1FBA6185A6A2BC6456970914875078E] - 26/04/2010 - 14:58:12 ---A- . (...) -- C:\WINDOWS\PEV.exe [256512]
      O44 - LFC:[MD5.775E188DD15C9AC9E735A556FB95578E] - 19/09/2007 - 16:23:18 ---A- . (...) -- C:\Boot.bak [212]
      O44 - LFC:[MD5.48C65662EC81FBCAA110509F50C51497] - 03/08/2004 - 22:00:08 RSHA- . (...) -- C:\cmldr [263488]
      O44 - LFC:[MD5.9E05A9C264C8A908A8E79450FCBFF047] - 31/08/2000 - 07:00:00 ---A- . (...) -- C:\WINDOWS\grep.exe [80412]
      O44 - LFC:[MD5.2B657A67AEBB84AEA5632C53E61E23BF] - 31/08/2000 - 07:00:00 ---A- . (...) -- C:\WINDOWS\sed.exe [98816]
      O44 - LFC:[MD5.5E832F4FAF5F481F2EAF3B3A48F603B8] - 31/08/2000 - 07:00:00 ---A- . (...) -- C:\WINDOWS\zip.exe [68096]



      ---\\ Opérations et fonctions au démarrage de Windows Explorer (O46)
      O46 - SEH:ShellExecuteHooks - URL Exec Hook - {AEB6717E-7E19-11d0-97EE-00C04FD91972} - shell32.dll



      ---\\ Export de clé d'application autorisée (O47)
      O47 - AAKE:Key Export SP - "%windir%\system32\sessmgr.exe" [Enabled] .(.Microsoft Corporation - Gestionnaire de session de l'aide sur le Bureau à distance de Microsoft®.) -- C:\WINDOWS\system32\sessmgr.exe
      O47 - AAKE:Key Export SP - "C:\Program Files\Messenger\msmsgs.exe" [Enabled] .(.Microsoft Corporation - Windows Messenger.) -- C:\Program Files\Messenger\msmsgs.exe
      O47 - AAKE:Key Export SP - "C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE" [Enabled] .(.Microsoft Corporation - Microsoft Office Outlook.) -- C:\Program Files\Microsoft Office\Office12\OUTLOOK.exe
      O47 - AAKE:Key Export SP - "C:\Program Files\Windows Live\Messenger\wlcsdk.exe" [Enabled] .(.Microsoft Corporation - Windows Live Call.) -- C:\Program Files\Windows Live\Messenger\wlcsdk.exe
      O47 - AAKE:Key Export SP - "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [Enabled] .(.Microsoft Corporation - Windows Live Messenger.) -- C:\Program Files\Windows Live\Messenger\msnmsgr.exe
      O47 - AAKE:Key Export SP - "%windir%\Network Diagnostic\xpnetdiag.exe" [Enabled] .(.Microsoft Corporation - Network Diagnostic for Windows XP.) -- C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O47 - AAKE:Key Export SP - "C:\Program Files\Bonjour\mDNSResponder.exe" [Enabled] .(.Apple Inc. - Bonjour Service.) -- C:\Program Files\Bonjour\mDNSResponder.exe
      O47 - AAKE:Key Export SP - "C:\Program Files\iTunes\iTunes.exe" [Enabled] .(.Apple Inc. - iTunes.) -- C:\Program Files\iTunes\iTunes.exe
      O47 - AAKE:Key Export DP - "%windir%\system32\sessmgr.exe" [Enabled] .(.Microsoft Corporation - Gestionnaire de session de l'aide sur le Bureau à distance de Microsoft®.) -- C:\WINDOWS\system32\sessmgr.exe
      O47 - AAKE:Key Export DP - "C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe" [Enabled] .(.Pas de propriétaire - P
      0
    2. manong
       
      Et le ZHPDiag après redémarrage :

      Rapport de ZHPDiag v1.27.21 par Nicolas Coolman, Update du 21/05/2011
      Run by Tommy at 24/05/2011 21:20:20
      Web site : http://www.premiumorange.com/zeb-help-process/zhpdiag.html


      ---\\ Web Browser
      MSIE: Internet Explorer v8.0.6001.18702 (Defaut)
      MFIE: Mozilla Firefox 4.0.1 v4.0.1

      ---\\ System Information
      Windows XP Professional Service Pack 3 (Build 2600)
      Processor: x86 Family 15 Model 2 Stepping 7, GenuineIntel
      Operating System: 32 Bits
      Boot mode: Normal (Normal boot)
      Total RAM: 767 MB (52% free)
      System Restore: Activé (Enable)
      System drive C: has 6 GB (11%) free of 49 GB

      ---\\ Logged in mode
      Computer Name: TOMMY
      User Name: Tommy
      All Users Names: Tommy, SUPPORT_388945a0, Lena, Laurence, HelpAssistant, ASPNET, Administrateur,
      Unselected Option: O45,O61,O62,O65,O66,O82
      Logged in as Administrator

      ---\\ Environnement Variables
      %AppData%=C:\Documents and Settings\Tommy\Application Data
      %LocalAppData%=C:\Documents and Settings\Tommy\Local Settings\Application Data
      %StartMenu%=C:\Documents and Settings\Tommy\Menu Démarrer

      ---\\ DOS/Devices
      A:\ Floppy drive, Flash card reader, USB Key (Not Inserted)
      C:\ Hard drive, Flash drive, Thumb drive (Free 6 Go of 49 Go)
      D:\ CD-ROM drive (Not Inserted)
      E:\ CD-ROM drive (Not Inserted)
      F:\ Hard drive, Flash drive, Thumb drive (Free 0 Go of 0 Go)
      G:\ Hard drive, Flash drive, Thumb drive (Free 52 Go of 149 Go)



      ---\\ Security Center & Tools Informations
      [HKLM\SOFTWARE\Microsoft\Security Center] AntiVirusOverride: OK
      [HKLM\SOFTWARE\Microsoft\Security Center] AntiVirusDisableNotify: OK
      [HKLM\SOFTWARE\Microsoft\Security Center] FirewallDisableNotify: OK
      [HKLM\SOFTWARE\Microsoft\Security Center] FirewallOverride: OK
      [HKLM\SOFTWARE\Microsoft\Security Center] UpdatesDisableNotify: OK
      [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: OK
      [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK



      ---\\ Recherche particulière de fichiers génériques
      [MD5.F2317622D29F9FF0F88AEECD5F60F0DD] - (.Microsoft Corporation - Explorateur Windows.) (.14/04/2008 03:34:03.) -- C:\WINDOWS\Explorer.exe [1037824]
      [MD5.77C66BD5CED4E555919A5FB713322CDD] - (.Microsoft Corporation - Internet Extensions for Win32.) (.23/02/2011 00:05:48.) -- C:\WINDOWS\system32\wininet.dll [916480]
      [MD5.DD73D6B9F6B4CB630CF35B438B540174] - (.Microsoft Corporation - Application d'ouverture de session Windows NT.) (.14/04/2008 03:34:28.) -- C:\WINDOWS\system32\Winlogon.exe [512000]
      [MD5.9F3A2F5AA6875C72BF062C712CFA2674] - (.Microsoft Corporation - IDE/ATAPI Port Driver.) (.13/04/2008 19:40:30.) -- C:\WINDOWS\system32\drivers\atapi.sys [96512]
      [MD5.78A08DD6A8D65E697C18E1DB01C5CDCA] - (.Microsoft Corporation - NT File System Driver.) (.13/04/2008 20:15:53.) -- C:\WINDOWS\system32\drivers\ntfs.sys [574976]



      ---\\ Processus lancés
      [MD5.25FB74EABCE5EC7836BA3CFB3C58449A] - (.AVAST Software - avast! Service.) -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [40384]
      [MD5.13B19DD5EBEB6FDDBD11DD77490A3585] - (.Sun Microsystems, Inc. - Java(TM) Update Scheduler.) -- C:\Program Files\Fichiers communs\Java\Java Update\jusched.exe [253672]
      [MD5.7B878518590E826F1F3A5B1D61D405F8] - (.AVAST Software - avast! Antivirus.) -- C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe [3396624]
      [MD5.20F6F19FE9E753F2780DC2FA083AD597] - (.Apple Inc. - MobileDeviceService.) -- C:\Program Files\Fichiers communs\Apple\Mobile Device Support\AppleMobileDeviceService.exe [37664]
      [MD5.F2060A34C8A75BC24A9222EB4F8C07BD] - (.Apple Inc. - Bonjour Service.) -- C:\Program Files\Bonjour\mDNSResponder.exe [349472]
      [MD5.11C3EFB4BAC41175D03B1595DB1A4A4F] - (.Sun Microsystems, Inc. - Java(TM) Quick Starter Service.) -- C:\Program Files\Java\jre6\bin\jqs.exe [153376]
      [MD5.62BB79160F86CD962F312C68C6239BFD] - (.Microsoft Corporation - Windows Update.) -- C:\WINDOWS\system32\wuauclt.exe [53472]
      [MD5.43722D15C8A955A8130ACD3151178CE5] - (.Creative Technology Ltd. - DevLdr32.) -- C:\WINDOWS\system32\devldr32.exe [24064]
      [MD5.E83508D9A0F0D0D8449317DC6A4C5E02] - (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe [924632]
      [MD5.3B2CC09944488DB5ED5DFDC315C9AB57] - (.Mozilla Corporation - Plugin Container for Firefox.) -- C:\Program Files\Mozilla Firefox\plugin-container.exe [16856]
      [MD5.9950380DD31FB50D18C02DAC635B1EB3] - (.Microsoft Corporation - Installation du Service Pack Windows.) -- C:\WINDOWS\SoftwareDistribution\Download\65e2b3a83ab21dd9a0a82631c6a532c8\update\update.exe [767352]
      [MD5.AF2A4686F7B696A3952F40350CC37DD3] - (.Nicolas Coolman - Diagnostic Tool.) -- C:\Program Files\ZHPDiag\ZHPDiag.exe [657408]



      ---\\ Mozilla Firefox, Plugins,Demarrage,Recherche,Extensions (P2,M0,M1,M2,M3)
      M3 - MFPP: Plugins - [Tommy] -- C:\Program Files\Mozilla FireFox\searchplugins\amazon-france.xml
      M3 - MFPP: Plugins - [Tommy] -- C:\Program Files\Mozilla FireFox\searchplugins\bing.xml
      M3 - MFPP: Plugins - [Tommy] -- C:\Program Files\Mozilla FireFox\searchplugins\cnrtl-tlfi-fr.xml
      M3 - MFPP: Plugins - [Tommy] -- C:\Program Files\Mozilla FireFox\searchplugins\eBay-france.xml
      M3 - MFPP: Plugins - [Tommy] -- C:\Program Files\Mozilla FireFox\searchplugins\google.xml
      M3 - MFPP: Plugins - [Tommy] -- C:\Program Files\Mozilla FireFox\searchplugins\wikipedia-fr.xml
      M3 - MFPP: Plugins - [Tommy] -- C:\Program Files\Mozilla FireFox\searchplugins\yahoo-france.xml
      P2 - FPN:Firefox Plugin Navigator . (.Sun Microsystems, Inc. - NPRuntime Script Plug-in Library for Java(TM) Deploy.) -- C:\Program Files\Mozilla Firefox\Plugins\npdeployJava1.dll
      P2 - FPN:Firefox Plugin Navigator . (.Adobe Systems Inc. - Adobe PDF Plug-In For Firefox and Netscape 10.0.1.) -- C:\Program Files\Mozilla Firefox\Plugins\nppdf32.dll
      P2 - FPN: [HKLM] [adobe.com/FlashPlayer] - (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
      P2 - FPN: [HKLM] [Apple.com/iTunes,version=1.0] - (.Pas de propriétaire - Pas de description.) -- C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
      P2 - FPN: [HKLM] [java.com/JavaPlugin] - (.Sun Microsystems, Inc. - Next Generation Java Plug-in 1.6.0_25 for Mozilla browsers.) -- C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
      P2 - FPN: [HKLM] [Microsoft.com/NpCtrl,version=1.0] - (. Microsoft Corporation - 4.0.60310.0.) -- C:\Program Files\Microsoft Silverlight\4.0.60310.0\npctrl.dll
      P2 - FPN: [HKLM] [microsoft.com/OfficeLive,version=1.3] - (.Microsoft Corp. - Office Live Update v1.3.) -- C:\Program Files\Microsoft\Office Live\npOLW.dll
      P2 - FPN: [HKLM] [microsoft.com/WLPG,version=14.0.8081.0709] - (.Microsoft Corporation - NPWLPG.) -- C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
      P2 - FPN: [HKLM] [microsoft.com/WPF,version=3.5] - (.Microsoft Corporation - Windows Presentation Foundation (WPF) plug-in for Mozilla browsers.) -- C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
      P2 - FPN: [HKCU] [adobe.com/FlashPlayer] - (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
      M0 - MFSP: prefs.js [Tommy - d0r6l0pr.default] http://www.google.fr/
      M2 - MFEP: prefs.js [Tommy - d0r6l0pr.default\2020Player2020Technologies.com] [] Visualisateur 3D de 20-20 v4.5.4.0 (.20-20 Technologies.)
      M2 - MFEP: prefs.js [Tommy - d0r6l0pr.default\{20a82645-c095-46ed-80e3-08825760534b}] [MicrosoftCG] Microsoft .NET Framework Assistant v1.1 (.Microsoft.)



      ---\\ Internet Explorer, Démarrage,Recherche,URLSearchHook, Phishing (R0,R1,R3,R4)
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com
      R0 - HKUS\S-1-5-21-1343024091-1078145449-839522115-1003\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk
      R1 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com
      R1 - HKUS\S-1-5-21-1343024091-1078145449-839522115-1003\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com
      R3 - URLSearchHook: Microsoft Url Search Hook - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} . (.Microsoft Corporation - Internet Explorer.) (8.00.6001.19048 (longhorn_ie8_gdr.110221-1700)) -- C:\WINDOWS\system32\ieframe.dll
      R4 - HKCU\SOFTWARE\Microsoft\Internet Explorer\PhishingFilter,Enabled = 2



      ---\\ Internet Explorer, Proxy Management (R5)
      R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;*.local
      R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key
      R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
      R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
      R5 - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
      R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyHttp1.1 = 1
      R5 - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll



      ---\\ ---\\ Modification d'une valeur Ini (Changed inifile value, mapped to Registry) (F2)
      F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,
      F2 - REG:system.ini: VMApplet=rundll32 shell32,Control_RunDLL "sysdm.cpl"



      ---\\ Browser Helper Objects de navigateur (O2)
      O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} . (.Adobe Systems Incorporated - Adobe PDF Helper for Internet Explorer.) -- C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
      O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} Clé orpheline
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} . (.Microsoft Corporation - WindowsLiveLogin.dll.) -- C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} . (.Sun Microsystems, Inc. - Java(TM) Platform SE binary.) -- C:\Program Files\Java\jre6\bin\jp2ssv.dll
      O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} . (.Sun Microsystems, Inc. - Java(TM) Quick Starter binary.) -- C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll



      ---\\ ---\\ Applications démarrées par registre & par dossier (O4)
      O4 - HKLM\..\Run: [SunJavaUpdateSched] . (.Sun Microsystems, Inc. - Java(TM) Update Scheduler.) -- C:\Program Files\Fichiers communs\Java\Java Update\jusched.exe
      O4 - HKLM\..\Run: [AppleSyncNotifier] . (.Apple Inc. - AppleSyncNotifier.) -- C:\Program Files\Fichiers communs\Apple\Mobile Device Support\AppleSyncNotifier.exe
      O4 - HKLM\..\Run: [avast5] . (.AVAST Software - avast! Antivirus.) -- C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] . (.Adobe Systems Incorporated - Adobe Acrobat SpeedLauncher.) -- C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe
      O4 - HKLM\..\Run: [Adobe ARM] . (.Adobe Systems Incorporated - Adobe Reader and Acrobat Manager.) -- C:\Program Files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe
      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\CTFMON.exe
      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\CTFMON.exe



      ---\\ ---\\ Autres liens utilisateurs (O4)
      O4 - Global Startup: C:\Documents And Settings\All Users\Menu Démarrer\Programmes\Adobe Reader X.lnk . (...) -- C:\WINDOWS\Installer\{AC76BA86-7AD7-1036-7B44-AA0000000001}\SC_Reader.ico
      O4 - Global Startup: C:\Documents And Settings\All Users\Menu Démarrer\Programmes\Mozilla Firefox.lnk . (.Mozilla Corporation.) -- C:\Program Files\Mozilla Firefox\firefox.exe
      O4 - Global Startup: C:\Documents And Settings\All Users\Menu Démarrer\Programmes\Windows Messenger.lnk . (.Microsoft Corporation.) -- C:\Program Files\Messenger\msmsgs.exe
      O4 - Global Startup: C:\Documents And Settings\Tommy\Menu Démarrer\Programmes\Outlook Express.lnk . (.Microsoft Corporation.) -- C:\Program Files\Outlook Express\msimn.exe



      ---\\ Lignes supplémentaires dans le menu contextuel d'Internet Explorer (O8)
      O8 - Extra context menu item: E&xporter vers Microsoft Excel . (.Microsoft Corporation - Microsoft Office Excel.) -- C:\PROGRA~1\MICROS~2\Office12\EXCEL.exe
      O8 - Extra context menu item: Google Sidewiki... - (.not file.) - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll



      ---\\ Boutons situés sur la barre d'outils principale d'Internet Explorer (O9)
      O9 - Extra button: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} . (.Microsoft Corporation - Windows Live Writer Blog This Extension.) -- C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
      O9 - Extra button: &Ajout Direct dans Windows Live Writer - {92780B25-18CC-41C8-B9BE-3C9C571A8263} . (...) -- C:\PROGRA~1\MICROS~2\Office12\REFBARH.ICO
      O9 - Extra button: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} . (...) -- C:\PROGRA~1\MICROS~2\Office12\REFBARH.ICO
      O9 - Extra button: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} . (.Microsoft Corporation - Windows Messenger.) -- C:\Program Files\Messenger\msmsgs.exe



      ---\\ Winsock hijacker (Layered Service Provider) (O10)
      O10 - WLSP:\000000000001\Winsock LSP File . (.Microsoft Corporation - Fournisseur de service Sockets 2.0 de Microsoft Windows.) -- C:\WINDOWS\system32\mswsock.dll
      O10 - WLSP:\000000000002\Winsock LSP File . (.Microsoft Corporation - LDAP RnR Provider DLL.) -- C:\WINDOWS\system32\winrnr.dll
      O10 - WLSP:\000000000003\Winsock LSP File . (.Microsoft Corporation - Fournisseur de service Sockets 2.0 de Microsoft Windows.) -- C:\WINDOWS\system32\mswsock.dll
      O10 - WLSP:\000000000004\Winsock LSP File . (.Apple Inc. - Bonjour Namespace Provider.) -- C:\Program Files\Bonjour\mdnsNSP.dll



      ---\\ Objets ActiveX (Downloaded Program Files)(O16)
      O16 - DPF: Microsoft XML Parser for Java - (Microsoft XML Parser for Java) - (.not file.) - file:\\C:\WINDOWS\Java\classes\xmldso.cab
      O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
      O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w3/pr01/resources/MSNPUpld.cab
      O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
      O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} () - http://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
      O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab



      ---\\ Modification Domaine/Adresses DNS (O17)
      O17 - HKLM\System\CCS\Services\Tcpip\..\{510CFE70-90C9-49FE-A5CE-B24EB46787DD}: DhcpNameServer = 89.2.0.1 89.2.0.2
      O17 - HKLM\System\CS1\Services\Tcpip\..\{510CFE70-90C9-49FE-A5CE-B24EB46787DD}: DhcpNameServer = 89.2.0.1 89.2.0.2
      O17 - HKLM\System\CS3\Services\Tcpip\..\{510CFE70-90C9-49FE-A5CE-B24EB46787DD}: DhcpNameServer = 89.2.0.1 89.2.0.2
      O17 - HKLM\System\CCS\Services\Tcpip\..\{510CFE70-90C9-49FE-A5CE-B24EB46787DD}: DhcpDomain = numericable.fr
      O17 - HKLM\System\CS1\Services\Tcpip\..\{510CFE70-90C9-49FE-A5CE-B24EB46787DD}: DhcpDomain = numericable.fr
      O17 - HKLM\System\CS3\Services\Tcpip\..\{510CFE70-90C9-49FE-A5CE-B24EB46787DD}: DhcpDomain = numericable.fr
      O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 89.2.0.1 89.2.0.2



      ---\\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (autorun) (O20)
      O20 - Winlogon Notify: crypt32chain . (.Microsoft Corporation - Crypto API32.) -- C:\Windows\System32\crypt32.dll
      O20 - Winlogon Notify: cryptnet . (.Microsoft Corporation - Crypto Network Related API.) -- C:\Windows\System32\cryptnet.dll
      O20 - Winlogon Notify: cscdll . (.Microsoft Corporation - Agent réseau hors connexion.) -- C:\Windows\System32\cscdll.dll
      O20 - Winlogon Notify: dimsntfy . (.Microsoft Corporation - DIMS Notification Handler.) -- C:\WINDOWS\System32\dimsntfy.dll
      O20 - Winlogon Notify: ScCertProp . (.Microsoft Corporation - DLL commune de réception des notifications.) -- C:\Windows\System32\wlnotify.dll
      O20 - Winlogon Notify: Schedule . (.Microsoft Corporation - DLL commune de réception des notifications.) -- C:\Windows\System32\wlnotify.dll
      O20 - Winlogon Notify: sclgntfy . (.Microsoft Corporation - DLL secondaire de notification de service d.) -- C:\Windows\System32\sclgntfy.dll
      O20 - Winlogon Notify: SensLogn . (.Microsoft Corporation - DLL commune de réception des notifications.) -- C:\Windows\System32\WlNotify.dll
      O20 - Winlogon Notify: termsrv . (.Microsoft Corporation - DLL commune de réception des notifications.) -- C:\Windows\System32\wlnotify.dll
      O20 - Winlogon Notify: WgaLogon . (.Pas de propriétaire - Pas de description.) -- WgaLogon.dll
      O20 - Winlogon Notify: wlballoon . (.Microsoft Corporation - DLL commune de réception des notifications.) -- C:\Windows\System32\wlnotify.dll



      ---\\ Clé de Registre autorun ShellServiceObjectDelayLoad (SSO/SSODL) (O21)
      O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\WINDOWS\system32\shell32.dll
      O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\WINDOWS\system32\SHELL32.dll
      O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} . (.Microsoft Corporation - Web Site Monitor.) -- C:\WINDOWS\system32\webcheck.dll
      O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} . (.Microsoft Corporation - Objet du service d'environnement Systray.) -- C:\WINDOWS\system32\stobject.dll
      O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} . (.Microsoft Corporation - Windows Portable Device Shell Service Objec.) -- C:\WINDOWS\system32\WPDShServiceObj.dll



      ---\\ Clé de Registre autorun SharedTaskScheduler (STS) (O22)
      O22 - SharedTaskScheduler: (no name) - {438755C2-A8BA-11D1-B96B-00A0C90312E1} . (.Microsoft Corporation - Bibliothèque de l'interface utilisateur du.) -- C:\WINDOWS\system32\browseui.dll
      O22 - SharedTaskScheduler: (no name) - {8C7461EF-2B13-11d2-BE35-3078302C2030} . (.Microsoft Corporation - Bibliothèque de l'interface utilisateur du.) -- C:\WINDOWS\system32\browseui.dll



      ---\\ Liste des services NT non Microsoft et non désactivés (O23)
      O23 - Service: (Apple Mobile Device) . (.Apple Inc. - MobileDeviceService.) - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\AppleMobileDeviceService.exe
      O23 - Service: (avast! Antivirus) . (.AVAST Software - avast! Service.) - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
      O23 - Service: (Bonjour Service) . (.Apple Inc. - Bonjour Service.) - C:\Program Files\Bonjour\mDNSResponder.exe
      O23 - Service: (dmadmin) . (.Microsoft Corp., Veritas Software - Processus du service Gestionnaire de disque.) - C:\WINDOWS\System32\dmadmin.exe
      O23 - Service: (iPod Service) . (.Apple Inc. - iPodService Module (32-bit).) - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: (JavaQuickStarterService) . (.Sun Microsystems, Inc. - Java(TM) Quick Starter Service.) - C:\Program Files\Java\jre6\bin\jqs.exe



      ---\\ Enumération Active Desktop & MHTML Editor (O24)
      O24 - Default MHTML Editor: Last - .(.Microsoft Corporation - Microsoft Office Word.) - C:\Program Files\Microsoft Office\Office12\WINWORD.exe



      ---\\ Tâches planifiées en automatique (O39)
      O39 - APT:Automatic Planified Task - C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
      [MD5.7B43567B4C32AD7ADED537CD3B1342B9] [APT] [AppleSoftwareUpdate] (.Apple Inc..) -- C:\Program Files\Apple Software Update\SoftwareUpdate.exe



      ---\\ Pilotes lancés au démarrage (O41)
      O41 - Driver: (AFD) . (.Microsoft Corporation - Ancillary Function Driver for WinSock.) - C:\WINDOWS\system32\drivers\afd.sys
      O41 - Driver: (Cdrom) . (.Microsoft Corporation - SCSI CD-ROM Driver.) - C:\Windows\System32\DRIVERS\cdrom.sys
      O41 - Driver: (i8042prt) . (.Microsoft Corporation - Pilote de port i8042.) - C:\Windows\System32\DRIVERS\i8042prt.sys
      O41 - Driver: (Imapi) . (.Microsoft Corporation - IMAPI Kernel Driver.) - C:\Windows\System32\DRIVERS\imapi.sys
      O41 - Driver: (intelppm) . (.Microsoft Corporation - Pilote de périphérique processeur.) - C:\Windows\System32\DRIVERS\intelppm.sys
      O41 - Driver: (IPSec) . (.Microsoft Corporation - IPSec Driver.) - C:\Windows\System32\DRIVERS\ipsec.sys
      O41 - Driver: (Kbdclass) . (.Microsoft Corporation - Pilote de la classe Clavier.) - C:\Windows\System32\DRIVERS\kbdclass.sys
      O41 - Driver: (Mouclass) . (.Microsoft Corporation - Pilote de la classe Souris.) - C:\Windows\System32\DRIVERS\mouclass.sys
      O41 - Driver: (MRxSmb) . (.Microsoft Corporation - Windows NT SMB Minirdr.) - C:\Windows\System32\DRIVERS\mrxsmb.sys
      O41 - Driver: (NetBIOS) . (.Microsoft Corporation - NetBIOS interface driver.) - C:\Windows\System32\DRIVERS\netbios.sys
      O41 - Driver: (NetBT) . (.Microsoft Corporation - MBT Transport driver.) - C:\Windows\System32\DRIVERS\netbt.sys
      O41 - Driver: (RasAcd) . (.Microsoft Corporation - RAS Automatic Connection Driver.) - C:\Windows\System32\DRIVERS\rasacd.sys
      O41 - Driver: (Rdbss) . (.Microsoft Corporation - Redirected Drive Buffering SubSystem Driver.) - C:\Windows\System32\DRIVERS\rdbss.sys
      O41 - Driver: (RDPCDD) . (.Microsoft Corporation - RDP Miniport.) - C:\Windows\System32\DRIVERS\RDPCDD.sys
      O41 - Driver: (redbook) . (.Microsoft Corporation - Pilote de filtre audio Livre rouge.) - C:\Windows\System32\DRIVERS\redbook.sys
      O41 - Driver: (Serial) . (.Microsoft Corporation - Pilote de périphérique série.) - C:\Windows\System32\DRIVERS\serial.sys
      O41 - Driver: (Tcpip) . (.Microsoft Corporation - TCP/IP Protocol Driver.) - C:\Windows\System32\DRIVERS\tcpip.sys
      O41 - Driver: (TermDD) . (.Microsoft Corporation - Terminal Server Driver.) - C:\Windows\System32\DRIVERS\termdd.sys
      O41 - Driver: Carte vidéo VGA. (VgaSave) . (.Microsoft Corporation - VGA/Super VGA Video Driver.) - C:\WINDOWS\system32\drivers\vga.sys
      O41 - Driver: Environnement de prise en charge de Fournisseur de services non-IFS Windows Sockets 2.0 (WS2IFSL) . (.Microsoft Corporation - Winsock2 IFS Layer.) - C:\WINDOWS\system32\drivers\ws2ifsl.sys



      ---\\ Logiciels installés (O42)
      O42 - Logiciel: 32 Bit HP CIO Components Installer - (.Hewlett-Packard.) [HKLM] -- {F7B0E599-C114-4493-BC4D-D8FC7CBBABBB}
      O42 - Logiciel: Adobe Flash Player 10 ActiveX - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player ActiveX
      O42 - Logiciel: Adobe Flash Player 10 Plugin - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player Plugin
      O42 - Logiciel: Adobe Reader X (10.0.1) - Français - (.Adobe Systems Incorporated.) [HKLM] -- {AC76BA86-7AD7-1036-7B44-AA0000000001}
      O42 - Logiciel: Apple Application Support - (.Apple Inc..) [HKLM] -- {853A4763-6643-4604-8D64-28BDD8925F4C}
      O42 - Logiciel: Apple Mobile Device Support - (.Apple Inc..) [HKLM] -- {CACAEB5F-174D-4C7C-AC56-A33289A807CA}
      O42 - Logiciel: Apple Software Update - (.Apple Inc..) [HKLM] -- {6956856F-B6B3-4BE0-BA0B-8F495BE32033}
      O42 - Logiciel: Archiveur WinRAR - (.Pas de propriétaire.) [HKLM] -- WinRAR archiver
      O42 - Logiciel: Assistant de connexion Windows Live - (.Microsoft Corporation.) [HKLM] -- {D3116CC7-24DC-4CA3-9CE1-23FED836E9F2}
      O42 - Logiciel: AviSynth 2.5 - (.Pas de propriétaire.) [HKLM] -- AviSynth
      O42 - Logiciel: Bonjour - (.Apple Inc..) [HKLM] -- {C2E4B5BD-32DB-4817-A060-341AB17C3F90}
      O42 - Logiciel: CCleaner - (.Piriform.) [HKLM] -- CCleaner
      O42 - Logiciel: DivX Codec - (.DivX, Inc..) [HKLM] -- {7B63B2922B174135AFC0E1377DD81EC2}
      O42 - Logiciel: Galerie de photos Windows Live - (.Microsoft Corporation.) [HKLM] -- {B131E59D-202C-43C6-84C9-68F0C37541F1}
      O42 - Logiciel: Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) - (.Microsoft Corporation.) [HKLM] -- {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB953595
      O42 - Logiciel: Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) - (.Microsoft Corporation.) [HKLM] -- {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB958484
      O42 - Logiciel: Hotfix for Windows Media Format 11 SDK (KB929399) - (.Microsoft Corporation.) [HKLM] -- KB929399
      O42 - Logiciel: Hotfix for Windows XP (KB954550-v5) - (.Microsoft Corporation.) [HKLM] -- KB954550-v5
      O42 - Logiciel: Hotfix for Windows XP (KB976002-v5) - (.Microsoft Corporation.) [HKLM] -- KB976002-v5
      O42 - Logiciel: Installation Windows Live - (.Microsoft Corporation.) [HKLM] -- WinLiveSuite_Wave3
      O42 - Logiciel: Installation Windows Live - (.Microsoft Corporation.) [HKLM] -- {46ABBC54-1872-4AA3-95E2-F2C063A63F31}
      O42 - Logiciel: Intel(R) PRO Ethernet Adapter and Software - (.Pas de propriétaire.) [HKLM] -- PROSet
      O42 - Logiciel: Java(TM) 6 Update 2 - (.Sun Microsystems, Inc..) [HKLM] -- {3248F0A8-6813-11D6-A77B-00B0D0160020}
      O42 - Logiciel: Java(TM) 6 Update 25 - (.Sun Microsystems, Inc..) [HKLM] -- {26A24AE4-039D-4CA4-87B4-2F83216013FF}
      O42 - Logiciel: Java(TM) 6 Update 6 - (.Sun Microsystems, Inc..) [HKLM] -- {3248F0A8-6813-11D6-A77B-00B0D0160060}
      O42 - Logiciel: Junk Mail filter update - (.Microsoft Corporation.) [HKLM] -- {E2DFE069-083E-4631-9B6C-43C48E991DE5}
      O42 - Logiciel: K-Lite Codec Pack 3.4.5 Full - (.Pas de propriétaire.) [HKLM] -- KLiteCodecPack_is1
      O42 - Logiciel: MSVCRT - (.Microsoft.) [HKLM] -- {22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
      O42 - Logiciel: MSXML 4.0 SP2 (KB936181) - (.Microsoft Corporation.) [HKLM] -- {C04E32E0-0416-434D-AFB9-6969D703A9EF}
      O42 - Logiciel: MSXML 4.0 SP2 (KB954430) - (.Microsoft Corporation.) [HKLM] -- {86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
      O42 - Logiciel: MSXML 4.0 SP2 (KB973688) - (.Microsoft Corporation.) [HKLM] -- {F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
      O42 - Logiciel: MSXML 6 Service Pack 2 (KB973686) - (.Microsoft Corporation.) [HKLM] -- {56EA8BC0-3751-4B93-BC9D-6651CC36E5AA}
      O42 - Logiciel: Malwarebytes' Anti-Malware - (.Malwarebytes Corporation.) [HKLM] -- Malwarebytes' Anti-Malware_is1
      O42 - Logiciel: Microsoft .NET Framework 1.1 - (.Microsoft.) [HKLM] -- {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
      O42 - Logiciel: Microsoft .NET Framework 1.1 - (.Pas de propriétaire.) [HKLM] -- Microsoft .NET Framework 1.1 (1033)
      O42 - Logiciel: Microsoft .NET Framework 1.1 Security Update (KB2416447) - (.Pas de propriétaire.) [HKLM] -- M2416447
      O42 - Logiciel: Microsoft .NET Framework 1.1 Security Update (KB979906) - (.Pas de propriétaire.) [HKLM] -- M979906
      O42 - Logiciel: Microsoft .NET Framework 2.0 Service Pack 2 - (.Microsoft Corporation.) [HKLM] -- {C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}
      O42 - Logiciel: Microsoft .NET Framework 3.0 Service Pack 2 - (.Microsoft Corporation.) [HKLM] -- {A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}
      O42 - Logiciel: Microsoft .NET Framework 3.5 SP1 - (.Microsoft Corporation.) [HKLM] -- Microsoft .NET Framework 3.5 SP1
      O42 - Logiciel: Microsoft .NET Framework 3.5 SP1 - (.Microsoft Corporation.) [HKLM] -- {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
      O42 - Logiciel: Microsoft Choice Guard - (.Microsoft Corporation.) [HKLM] -- {F0E12BBA-AD66-4022-A453-A1C8A0C4D570}
      O42 - Logiciel: Microsoft Compression Client Pack 1.0 for Windows XP - (.Microsoft Corporation.) [HKLM] -- MSCompPackV1
      O42 - Logiciel: Microsoft Kernel-Mode Driver Framework Feature Pack 1.5 - (.Microsoft Corporation.) [HKLM] -- Wdf01005
      O42 - Logiciel: Microsoft Office 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}
      O42 - Logiciel: Microsoft Office 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-0015-040C-0000-0000000FF1CE}_PROPLUS_{AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
      O42 - Logiciel: Microsoft Office 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-0016-040C-0000-0000000FF1CE}_PROPLUS_{AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
      O42 - Logiciel: Microsoft Office 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-0018-040C-0000-0000000FF1CE}_PROPLUS_{AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
      O42 - Logiciel: Microsoft Office 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-0019-040C-0000-0000000FF1CE}_PROPLUS_{AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
      O42 - Logiciel: Microsoft Office 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-001A-040C-0000-0000000FF1CE}_PROPLUS_{AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
      O42 - Logiciel: Microsoft Office 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-001B-040C-0000-0000000FF1CE}_PROPLUS_{AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
      O42 - Logiciel: Microsoft Office 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-0044-040C-0000-0000000FF1CE}_PROPLUS_{AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
      O42 - Logiciel: Microsoft Office 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-006E-040C-0000-0000000FF1CE}_PROPLUS_{B165D3C2-40AE-4D39-86F7-E5C87C4264C0}
      O42 - Logiciel: Microsoft Office Access MUI (French) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-0015-040C-0000-0000000FF1CE}
      O42 - Logiciel: Microsoft Office Excel MUI (French) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-0016-040C-0000-0000000FF1CE}
      O42 - Logiciel: Microsoft Office InfoPath MUI (French) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-0044-040C-0000-0000000FF1CE}
      O42 - Logiciel: Microsoft Office Live Add-in 1.3 - (.Microsoft Corporation.) [HKLM] -- {57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}
      O42 - Logiciel: Microsoft Office Outlook Connector - (.Microsoft Corporation.) [HKLM] -- {95120000-0122-040C-0000-0000000FF1CE}
      O42 - Logiciel: Microsoft Office Outlook MUI (French) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-001A-040C-0000-0000000FF1CE}
      O42 - Logiciel: Microsoft Office PowerPoint MUI (French) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-0018-040C-0000-0000000FF1CE}
      O42 - Logiciel: Microsoft Office Professional Plus 2007 - (.Microsoft Corporation.) [HKLM] -- PROPLUS
      O42 - Logiciel: Microsoft Office Professional Plus 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}
      O42 - Logiciel: Microsoft Office Proof (Arabic) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-001F-0401-0000-0000000FF1CE}
      O42 - Logiciel: Microsoft Office Proof (Dutch) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-001F-0413-0000-0000000FF1CE}
      O42 - Logiciel: Microsoft Office Proof (English) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-001F-0409-0000-0000000FF1CE}
      O42 - Logiciel: Microsoft Office Proof (French) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-001F-040C-0000-0000000FF1CE}
      O42 - Logiciel: Microsoft Office Proof (German) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-001F-0407-0000-0000000FF1CE}
      O42 - Logiciel: Microsoft Office Proof (Spanish) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-001F-0C0A-0000-0000000FF1CE}
      O42 - Logiciel: Microsoft Office Proofing (French) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-002C-040C-0000-0000000FF1CE}
      O42 - Logiciel: Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-001F-0401-0000-0000000FF1CE}_PROPLUS_{14809F99-C601-4D4A-9391-F1E8FAA964C5}
      O42 - Logiciel: Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-001F-0407-0000-0000000FF1CE}_PROPLUS_{A0516415-ED61-419A-981D-93596DA74165}
      O42 - Logiciel: Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-001F-0409-0000-0000000FF1CE}_PROPLUS_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}
      O42 - Logiciel: Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-001F-040C-0000-0000000FF1CE}_PROPLUS_{F580DDD5-8D37-4998-968E-EBB76BB86787}
      O42 - Logiciel: Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-001F-0413-0000-0000000FF1CE}_PROPLUS_{D66D5A44-E480-4BA4-B4F2-C554F6B30EBB}
      O42 - Logiciel: Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-001F-0C0A-0000-0000000FF1CE}_PROPLUS_{187308AB-5FA7-4F14-9AB9-D290383A10D9}
      O42 - Logiciel: Microsoft Office Publisher MUI (French) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-0019-040C-0000-0000000FF1CE}
      O42 - Logiciel: Microsoft Office Shared MUI (French) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-006E-040C-0000-0000000FF1CE}
      O42 - Logiciel: Microsoft Office Word MUI (French) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-001B-040C-0000-0000000FF1CE}
      O42 - Logiciel: Microsoft SQL Server 2005 Compact Edition [ENU] - (.Microsoft Corporation.) [HKLM] -- {F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
      O42 - Logiciel: Microsoft Silverlight - (.Microsoft Corporation.) [HKLM] -- {89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
      O42 - Logiciel: Microsoft User-Mode Driver Framework Feature Pack 1.0 - (.Microsoft Corporation.) [HKLM] -- Wudf01000
      O42 - Logiciel: Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 - (.Microsoft Corporation.) [HKLM] -- {770657D0-A123-3C07-8E44-1C83EC895118}
      O42 - Logiciel: Microsoft Visual C++ 2005 Redistributable - (.Microsoft Corporation.) [HKLM] -- {7299052b-02a4-4627-81f2-1818da5d550d}
      O42 - Logiciel: Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 - (.Microsoft Corporation.) [HKLM] -- {1F1C2DFC-2D24-3E06-BCB8-725134ADF989}
      O42 - Logiciel: Mozilla Firefox 4.0.1 (x86 fr) - (.Mozilla.) [HKLM] -- Mozilla Firefox 4.0.1 (x86 fr)
      O42 - Logiciel: OpenOffice.org 2.3 - (.OpenOffice.org.) [HKLM] -- {FADB55D0-403F-4413-A268-CF0A6F1185C2}
      O42 - Logiciel: Outil de téléchargement Windows Live - (.Microsoft Corporation.) [HKLM] -- {205C6BDD-7B73-42DE-8505-9A093F35A238}
      O42 - Logiciel: Package de pilotes Windows - MobileTop (sshpmdm) Modem (02/23/2007 2.5.0.0) - (.MobileTop.) [HKLM] -- 6194C28A8F62DD817EA1B918E6E46E806A21B452
      O42 - Logiciel: Package de pilotes Windows - MobileTop (sshpusb) USB (02/23/2007 2.5.0.0) - (.MobileTop.) [HKLM] -- 65B6FE5418CE28F4D72543FB2D964C3CEC83F161
      O42 - Logiciel: QuickTime - (.Apple Inc..) [HKLM] -- {57752979-A1C9-4C02-856B-FBB27AC4E02C}
      O42 - Logiciel: Safari - (.Apple Inc..) [HKLM] -- {6B9B0C6F-E5FA-4633-A640-AB98A272ECCA}
      O42 - Logiciel: Security Update for 2007 Microsoft Office System (KB2288621) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{5C497F0B-2061-4CC9-A61C-6B45B867354D}
      O42 - Logiciel: Security Update for 2007 Microsoft Office System (KB2288931) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{CD769337-C8AC-46DB-A7DC-643E50089263}
      O42 - Logiciel: Security Update for 2007 Microsoft Office System (KB2345043) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{536FB502-775F-4494-BACE-C02CC90B7A5B}
      O42 - Logiciel: Security Update for 2007 Microsoft Office System (KB2466156) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{CEF209AB-F96D-404F-B5CC-44057C057CA3}
      O42 - Logiciel: Security Update for 2007 Microsoft Office System (KB2509488) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{AD0DE453-0804-4495-9C91-33D0F9AA5463}
      O42 - Logiciel: Security Update for 2007 Microsoft Office System (KB969559) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{69F52148-9BF6-4CDC-BF76-103DEAF3DD08}
      O42 - Logiciel: Security Update for 2007 Microsoft Office System (KB976321) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{7F207DCA-3399-40CB-A968-6E5991B1421A}
      O42 - Logiciel: Security Update for CAPICOM (KB931906) - (.Microsoft Corporation.) [HKLM] -- KB931906
      O42 - Logiciel: Security Update for CAPICOM (KB931906) - (.Microsoft Corporation.) [HKLM] -- {0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
      O42 - Logiciel: Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473) - (.Microsoft Corporation.) [HKLM] -- {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB2416473
      O42 - Logiciel: Security Update for Microsoft Office Access 2007 (KB979440) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{1142CCEC-ACA9-484B-BA90-C3A5CA1988C5}
      O42 - Logiciel: Security Update for Microsoft Office Access 2007 (KB979440) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{5A4E43D5-858F-49BD-BA72-8F30E1793060}
      O42 - Logiciel: Security Update for Microsoft Office Excel 2007 (KB2464583) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{151E2FEA-C3A6-4CB6-BE6B-16651FDF04BE}
      O42 - Logiciel: Security Update for Microsoft Office InfoPath 2007 (KB979441) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{1109D0B3-EFA3-4553-AAED-4C3E9AD130E8}
      O42 - Logiciel: Security Update for Microsoft Office InfoPath 2007 (KB979441) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{8CCB781A-CF6B-4FCB-B6D8-59C64DF5C6DB}
      O42 - Logiciel: Security Update for Microsoft Office PowerPoint 2007 (KB2535818) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{8588DD11-6BD7-4400-B55C-DD5AB74B43E1}
      O42 - Logiciel: Security Update for Microsoft Office PowerPoint Viewer 2007 (KB2464623) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{D75E6D0C-BADF-4F41-98B2-0C0F02C15062}
      O42 - Logiciel: Security Update for Microsoft Office Publisher 2007 (KB2284697) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{3A4CDE54-2403-483D-8D9A-15E3264410DF}
      O42 - Logiciel: Security Update for Microsoft Office Visio Viewer 2007 (KB973709) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{71127777-8B2C-4F97-AF7A-6CF8CAC8224D}
      O42 - Logiciel: Security Update for Microsoft Office Word 2007 (KB2344993) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{7A5B74FA-7A92-4FC9-821A-2DD5D4E73E48}
      O42 - Logiciel: Security Update for Microsoft Office system 2007 (972581) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{3D019598-7B59-447A-80AE-815B703B84FF}
      O42 - Logiciel: Security Update for Microsoft Office system 2007 (KB974234) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{FCD742B9-7A55-44BC-A776-F795F21FEDDC}
      O42 - Logiciel: Segoe UI - (.Microsoft Corp.) [HKLM] -- {A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}
      O42 - Logiciel: Update for 2007 Microsoft Office System (KB967642) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}
      O42 - Logiciel: Update for Microsoft .NET Framework 3.5 SP1 (KB963707) - (.Microsoft Corporation.) [HKLM] -- {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB963707
      O42 - Logiciel: Update for Microsoft Office Outlook 2007 (KB2509470) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{1365864D-4C58-489D-9982-844D75691CCC}
      O42 - Logiciel: Update for Outlook 2007 Junk Email Filter (KB2536413) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{95DF5260-331D-4FFD-A2D5-C64164751945}
      O42 - Logiciel: Utilitaire de configuration iPhone - (.Apple Inc..) [HKLM] -- {FA54AFB1-5745-4389-B8C1-9F7509672ED1}
      O42 - Logiciel: VCRedistSetup - (.Nero AG.) [HKLM] -- {3921A67A-5AB1-4E48-9444-C71814CF3027}
      O42 - Logiciel: Windows Genuine Advantage Notifications (KB905474) - (.Microsoft Corporation.) [HKLM] -- WgaNotify
      O42 - Logiciel: Windows Imaging Component - (.Microsoft Corporation.) [HKLM] -- WIC
      O42 - Logiciel: Windows Internet Explorer 8 - (.Microsoft Corporation.) [HKLM] -- ie8
      O42 - Logiciel: Windows Live Call - (.Microsoft Corporation.) [HKLM] -- {82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}
      O42 - Logiciel: Windows Live Communications Platform - (.Microsoft Corporation.) [HKLM] -- {3B4E636E-9D65-4D67-BA61-189800823F52}
      O42 - Logiciel: Windows Live Mail - (.Microsoft Corporation.) [HKLM] -- {5DD76286-9BE7-4894-A990-E905E91AC818}
      O42 - Logiciel: Windows Live Messenger - (.Microsoft Corporation.) [HKLM] -- {770F1BEC-2871-4E70-B837-FB8525FFA3B1}
      O42 - Logiciel: Windows Live OneCare safety scanner - (.Pas de propriétaire.) [HKLM] -- Windows Live OneCare safety scanner
      O42 - Logiciel: Windows Live Writer - (.Microsoft Corporation.) [HKLM] -- {4634B21A-CC07-4396-890C-2B8168661FEA}
      O42 - Logiciel: Windows Media Format 11 runtime - (.Microsoft Corporation.) [HKLM] -- WMFDist11
      O42 - Logiciel: Windows Media Format 11 runtime - (.Pas de propriétaire.) [HKLM] -- Windows Media Format Runtime
      O42 - Logiciel: Windows XP Service Pack 3 - (.Microsoft Corporation.) [HKLM] -- Windows XP Service
      O42 - Logiciel: iTunes - (.Apple Inc..) [HKLM] -- {F59A9E08-A6A4-4ACF-91F2-D0344956C30B}
      O42 - Logiciel: neroxml - (.Nero AG.) [HKLM] -- {56C049BE-79E9-4502-BEA7-9754A3E60F9B}

      ---\\ HKCU & HKLM Software Keys
      [HKCU\Software\AC3filter]
      [HKCU\Software\ALWIL Software]
      [HKCU\Software\AVS4YOU]
      [HKCU\Software\Adobe]
      [HKCU\Software\Ahead]
      [HKCU\Software\AppDataLow]
      [HKCU\Software\Apple Computer, Inc.]
      [HKCU\Software\Apple Inc.]
      [HKCU\Software\Aurigma]
      [HKCU\Software\Bugsplat]
      [HKCU\Software\CDDB]
      [HKCU\Software\CREATIVE TECH]
      [HKCU\Software\CeWe Color]
      [HKCU\Software\Classes]
      [HKCU\Software\Clients]
      [HKCU\Software\CoreVorbis]
      [HKCU\Software\Cucusoft, Inc.]
      [HKCU\Software\Cyberlink]
      [HKCU\Software\DSP-worx]
      [HKCU\Software\DVDVideoSoft]
      [HKCU\Software\DivXNetworks]
      [HKCU\Software\FotoWire]
      [HKCU\Software\GNU]
      [HKCU\Software\GSpot Appliance Corp]
      [HKCU\Software\Gabest]
      [HKCU\Software\Google]
      [HKCU\Software\Haali]
      [HKCU\Software\Hewlett-Packard]
      [HKCU\Software\IM Providers]
      [HKCU\Software\Intel]
      [HKCU\Software\Iris]
      [HKCU\Software\Jasc]
      [HKCU\Software\JavaSoft]
      [HKCU\Software\Local AppWizard-Generated Applications]
      [HKCU\Software\Logitech]
      [HKCU\Software\Macromedia]
      [HKCU\Software\Magnet]
      [HKCU\Software\Malwarebytes' Anti-Malware]
      [HKCU\Software\MozillaPlugins]
      [HKCU\Software\Mozilla]
      [HKCU\Software\Nero]
      [HKCU\Software\Netscape]
      [HKCU\Software\ODBC]
      [HKCU\Software\Piriform]
      [HKCU\Software\Policies]
      [HKCU\Software\Samsung]
      [HKCU\Software\Skype]
      [HKCU\Software\Sysinternals]
      [HKCU\Software\Trafficninja]
      [HKCU\Software\Trolltech]
      [HKCU\Software\VB and VBA Program Settings]
      [HKCU\Software\Veoh]
      [HKCU\Software\Wget]
      [HKCU\Software\WinRAR SFX]
      [HKCU\Software\WinRAR]
      [HKCU\Software\YahooPartnerToolbar]
      [HKCU\Software\eBay]
      [HKCU\Software\yahooinstall]
      [HKLM\Software\781]
      [HKLM\Software\ALWIL Software]
      [HKLM\Software\AVAST Software]
      [HKLM\Software\AVS4YOU]
      [HKLM\Software\Adobe]
      [HKLM\Software\Ahead]
      [HKLM\Software\Apple Computer, Inc.]
      [HKLM\Software\Apple Inc.]
      [HKLM\Software\Audible]
      [HKLM\Software\BroadJump]
      [HKLM\Software\Broadcom]
      [HKLM\Software\BrowserChoice]
      [HKLM\Software\C07ft5Y]
      [HKLM\Software\CDDB]
      [HKLM\Software\CLSYSTEM]
      [HKLM\Software\Classes]
      [HKLM\Software\Clients]
      [HKLM\Software\Codec tweak Tool]
      [HKLM\Software\Creative Tech]
      [HKLM\Software\Cyberlink]
      [HKLM\Software\DVDVideoSoft]
      [HKLM\Software\DivXNetworks]
      [HKLM\Software\GEAR Software]
      [HKLM\Software\GNU]
      [HKLM\Software\Gabest]
      [HKLM\Software\Gemplus]
      [HKLM\Software\Google]
      [HKLM\Software\HPS]
      [HKLM\Software\HaaliMkx]
      [HKLM\Software\Hewlett-Packard]
      [HKLM\Software\I.R.I.S.]
      [HKLM\Software\InstallShield]
      [HKLM\Software\InstalledOptions]
      [HKLM\Software\Intel]
      [HKLM\Software\InterVideo]
      [HKLM\Software\JavaSoft]
      [HKLM\Software\JreMetrics]
      [HKLM\Software\KLCodecPack]
      [HKLM\Software\Ktdxgcor]
      [HKLM\Software\Logitech]
      [HKLM\Software\Macromedia]
      [HKLM\Software\Malwarebytes' Anti-Malware]
      [HKLM\Software\MarkAny]
      [HKLM\Software\Matrox]
      [HKLM\Software\MozillaPlugins]
      [HKLM\Software\Mozilla]
      [HKLM\Software\NVIDIA Corporation]
      [HKLM\Software\Nero]
      [HKLM\Software\Ntpad]
      [HKLM\Software\ODBC]
      [HKLM\Software\OpenOffice.org]
      [HKLM\Software\Piriform]
      [HKLM\Software\Policies]
      [HKLM\Software\Program Groups]
      [HKLM\Software\Rainbow Technologies]
      [HKLM\Software\RegisteredApplications]
      [HKLM\Software\Reviversoft]
      [HKLM\Software\S3R521]
      [HKLM\Software\Schlumberger]
      [HKLM\Software\Secure]
      [HKLM\Software\SoundFont]
      [HKLM\Software\Sun Microsystems]
      [HKLM\Software\Swearware]
      [HKLM\Software\Windows 3.1 Migration Status]
      [HKLM\Software\Windows]
      [HKLM\Software\mozilla.org]



      ---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43)
      O43 - CFD: 24/05/2011 - 21:01:20 - [114255585] ----D- C:\Program Files\Adobe
      O43 - CFD: 13/07/2010 - 13:32:38 - [156773270] ----D- C:\Program Files\Alwil Software
      O43 - CFD: 27/09/2008 - 08:40:08 - [2221118] ----D- C:\Program Files\Apple Software Update
      O43 - CFD: 26/06/2010 - 18:45:16 - [4859926] ----D- C:\Program Files\AviSynth 2.5
      O43 - CFD: 14/05/2011 - 01:20:00 - [620967] ----D- C:\Program Files\Bonjour
      O43 - CFD: 27/04/2011 - 20:27:56 - [3704864] ----D- C:\Program Files\CCleaner
      O43 - CFD: 08/05/2009 - 22:59:28 - [1005568] ----D- C:\Program Files\Common Files
      O43 - CFD: 19/09/2007 - 17:24:50 - [0] ----D- C:\Program Files\ComPlus Applications
      O43 - CFD: 13/04/2011 - 20:42:14 - [14216193] ----D- C:\Program Files\Cucusoft
      O43 - CFD: 14/05/2009 - 23:58:44 - [2916264] ----D- C:\Program Files\DIFX
      O43 - CFD: 15/05/2011 - 18:01:14 - [1890602] ----D- C:\Program Files\DivX
      O43 - CFD: 18/05/2011 - 21:31:46 - [729303644] ----D- C:\Program Files\Fichiers communs
      O43 - CFD: 30/04/2011 - 14:50:56 - [3783584] ----D- C:\Program Files\Google
      O43 - CFD: 24/04/2011 - 22:01:26 - [368640] --H-D- C:\Program Files\InstallShield Installation Information
      O43 - CFD: 15/04/2011 - 21:21:44 - [5793384] ----D- C:\Program Files\Internet Explorer
      O43 - CFD: 14/05/2011 - 01:28:10 - [1856627] ----D- C:\Program Files\iPod
      O43 - CFD: 14/05/2011 - 01:29:42 - [128197016] ----D- C:\Program Files\iTunes
      O43 - CFD: 24/05/2011 - 21:08:26 - [238748521] ----D- C:\Program Files\Java
      O43 - CFD: 19/09/2007 - 18:26:48 - [26123917] ----D- C:\Program Files\K-Lite Codec Pack
      O43 - CFD: 30/04/2011 - 13:35:06 - [77214238] ----D- C:\Program Files\LimeWire
      O43 - CFD: 30/04/2011 - 13:36:28 - [0] ----D- C:\Program Files\Logitech
      O43 - CFD: 25/04/2011 - 21:27:38 - [4922237] ----D- C:\Program Files\Malwarebytes' Anti-Malware
      O43 - CFD: 22/03/2010 - 23:02:16 - [2147758] ----D- C:\Program Files\Messenger
      O43 - CFD: 09/12/2009 - 19:45:02 - [728627] ----D- C:\Program Files\Microsoft
      O43 - CFD: 10/03/2008 - 15:07:06 - [800662] ----D- C:\Program Files\Microsoft CAPICOM 2.1.0.2
      O43 - CFD: 19/09/2007 - 17:28:16 - [0] ----D- C:\Program Files\microsoft frontpage
      O43 - CFD: 13/05/2008 - 20:57:04 - [561454552] ----D- C:\Program Files\Microsoft Office
      O43 - CFD: 09/12/2009 - 19:50:10 - [1559148] ----D- C:\Program Files\Microsoft Office Outlook Connector
      O43 - CFD: 21/04/2011 - 19:59:10 - [38388859] ----D- C:\Program Files\Microsoft Silverlight
      O43 - CFD: 08/05/2009 - 23:10:44 - [1829877] ----D- C:\Program Files\Microsoft SQL Server Compact Edition
      O43 - CFD: 13/05/2008 - 20:56:58 - [14904] ----D- C:\Program Files\Microsoft Visual Studio
      O43 - CFD: 02/12/2009 - 00:56:52 - [3726168] ----D- C:\Program Files\Microsoft Works
      O43 - CFD: 22/08/2010 - 21:17:32 - [10374874] ----D- C:\Program Files\Movie Maker
      O43 - CFD: 15/05/2011 - 18:01:14 - [33259279] ----D- C:\Program Files\Mozilla Firefox
      O43 - CFD: 15/08/2009 - 02:01:28 - [26521] ----D- C:\Program Files\MSBuild
      O43 - CFD: 15/05/2011 - 18:02:56 - [19278399] ----D- C:\Program Files\MSN
      O43 - CFD: 19/09/2007 - 17:24:32 - [0] ----D- C:\Program Files\MSN Gaming Zone
      O43 - CFD: 14/11/2007 - 16:42:08 - [0] ----D- C:\Program Files\MSXML 4.0
      O43 - CFD: 15/08/2009 - 01:57:00 - [6849] ----D- C:\Program Files\MSXML 6.0
      O43 - CFD: 21/03/2010 - 14:37:18 - [3285523] ----D- C:\Program Files\NetMeeting
      O43 - CFD: 19/09/2007 - 17:24:40 - [1804] ----D- C:\Program Files\Online Services
      O43 - CFD: 07/11/2007 - 16:59:50 - [319687453] ----D- C:\Program Files\OpenOffice.org 2.3
      O43 - CFD: 16/12/2010 - 21:53:02 - [4379321] ----D- C:\Program Files\Outlook Express
      O43 - CFD: 30/01/2011 - 17:40:40 - [76322555] ----D- C:\Program Files\QuickTime
      O43 - CFD: 15/08/2009 - 02:01:16 - [36400897] ----D- C:\Program Files\Reference Assemblies
      O43 - CFD: 30/01/2011 - 17:46:02 - [42293335] ----D- C:\Program Files\Safari
      O43 - CFD: 19/09/2007 - 17:26:34 - [1025] ----D- C:\Program Files\Services en ligne
      O43 - CFD: 19/09/2007 - 17:33:48 - [0] --H-D- C:\Program Files\Uninstall Information
      O43 - CFD: 24/09/2009 - 17:30:06 - [23509198] ----D- C:\Program Files\Utilitaire de configuration iPhone
      O43 - CFD: 09/12/2009 - 19:49:00 - [130598388] ----D- C:\Program Files\Windows Live
      O43 - CFD: 15/07/2009 - 12:41:12 - [44923857] ----D- C:\Program Files\Windows Live Safety Center
      O43 - CFD: 08/05/2009 - 23:08:04 - [245112] ----D- C:\Program Files\Windows Live SkyDrive
      O43 - CFD: 14/12/2007 - 12:56:04 - [0] ----D- C:\Program Files\Windows Media Connect 2
      O43 - CFD: 08/07/2010 - 19:30:00 - [5142414] ----D- C:\Program Files\Windows Media Player
      O43 - CFD: 15/05/2011 - 20:46:42 - [1611264] ----D- C:\Program Files\Windows NT
      O43 - CFD: 19/09/2007 - 17:26:36 - [0] --H-D- C:\Program Files\WindowsUpdate
      O43 - CFD: 24/09/2007 - 20:30:10 - [4235318] ----D- C:\Program Files\Winrar
      O43 - CFD: 19/09/2007 - 17:28:16 - [0] ----D- C:\Program Files\xerox
      O43 - CFD: 24/05/2011 - 21:20:30 - [6457524] ----D- C:\Program Files\ZHPDiag
      O43 - CFD: 20/09/2007 - 20:12:44 - [1005568] ----D- C:\Program Files\Common Files\Motive
      O43 - CFD: 24/05/2011 - 21:03:38 - [4614329] --H-D- C:\Documents and Settings\Tommy\Application Data\Adobe
      O43 - CFD: 29/05/2010 - 18:34:02 - [53248] --H-D- C:\Documents and Settings\Tommy\Application Data\AdSigner
      O43 - CFD: 27/09/2008 - 14:49:44 - [0] --H-D- C:\Documents and Settings\Tommy\Application Data\Alchemy Mindworks
      O43 - CFD: 27/11/2010 - 11:59:48 - [9459425401] --H-D- C:\Documents and Settings\Tommy\Application Data\Apple Computer
      O43 - CFD: 10/08/2009 - 13:10:58 - [37265] --H-D- C:\Documents and Settings\Tommy\Application Data\AVS4YOU
      O43 - CFD: 13/04/2011 - 20:50:02 - [1462] --H-D- C:\Documents and Settings\Tommy\Application Data\DiskAid
      O43 - CFD: 24/11/2008 - 14:11:28 - [13368] --H-D- C:\Documents and Settings\Tommy\Application Data\DivX
      O43 - CFD: 04/04/2011 - 20:50:56 - [1323008] --H-D- C:\Documents and Settings\Tommy\Application Data\DTencryptor-H
      O43 - CFD: 31/12/2010 - 17:32:26 - [1323008] --H-D- C:\Documents and Settings\Tommy\Application Data\DTencryptor-I
      O43 - CFD: 28/10/2007 - 15:29:34 - [33039] --H-D- C:\Documents and Settings\Tommy\Application Data\Google
      O43 - CFD: 22/03/2009 - 15:15:00 - [51795] --H-D- C:\Documents and Settings\Tommy\Application Data\HP
      O43 - CFD: 19/09/2007 - 17:33:52 - [0] --H-D- C:\Documents and Settings\Tommy\Application Data\Identities
      O43 - CFD: 13/04/2011 - 20:43:00 - [4767209] --H-D- C:\Documents and Settings\Tommy\Application Data\iPhone Tool Kits
      O43 - CFD: 27/09/2008 - 18:07:28 - [0] --H-D- C:\Documents and Settings\Tommy\Application Data\Jasc
      O43 - CFD: 24/03/2011 - 00:29:54 - [103111644] --H-D- C:\Documents and Settings\Tommy\Application Data\LimeWire
      O43 - CFD: 21/09/2007 - 19:47:12 - [1931224] --H-D- C:\Documents and Settings\Tommy\Application Data\Macromedia
      O43 - CFD: 25/04/2011 - 22:16:46 - [14468] ----D- C:\Documents and Settings\Tommy\Application Data\Malwarebytes
      O43 - CFD: 20/09/2007 - 13:00:00 - [95] --H-D- C:\Documents and Settings\Tommy\Application Data\Media Player Classic
      O43 - CFD: 24/05/2011 - 21:03:38 - [9090716] -S--D- C:\Documents and Settings\Tommy\Application Data\Microsoft
      O43 - CFD: 13/11/2008 - 16:13:50 - [475096] --H-D- C:\Documents and Settings\Tommy\Application Data\Mostick
      O43 - CFD: 29/08/2008 - 16:30:00 - [23563277] --H-D- C:\Documents and Settings\Tommy\Application Data\Mozilla
      O43 - CFD: 15/05/2011 - 18:02:54 - [327] ----D- C:\Documents and Settings\Tommy\Application Data\MSNInstaller
      O43 - CFD: 12/12/2007 - 20:39:14 - [101085] --H-D- C:\Documents and Settings\Tommy\Application Data\Nero
      O43 - CFD: 01/05/2011 - 10:44:52 - [1714947] --H-D- C:\Documents and Settings\Tommy\Application Data\OpenOffice.org2
      O43 - CFD: 08/07/2010 - 18:59:06 - [0] --H-D- C:\Documents and Settings\Tommy\Application Data\Samsung
      O43 - CFD: 20/03/2011 - 22:42:58 - [5339941] --H-D- C:\Documents and Settings\Tommy\Application Data\Skype
      O43 - CFD: 20/03/2011 - 22:12:32 - [12536] --H-D- C:\Documents and Settings\Tommy\Application Data\skypePM
      O43 - CFD: 04/05/2008 - 19:31:24 - [10764124] --H-D- C:\Documents and Settings\Tommy\Application Data\Sun
      O43 - CFD: 08/06/2008 - 10:11:10 - [45056] --H-D- C:\Documents and Settings\Tommy\Application Data\TaoUSign
      O43 - CFD: 09/12/2009 - 20:37:06 - [18188499] --H-D- C:\Documents and Settings\Tommy\Application Data\Thinstall
      O43 - CFD: 17/09/2010 - 22:15:56 - [3604480] --H-D- C:\Documents and Settings\Tommy\Application Data\U3
      O43 - CFD: 27/04/2011 - 22:27:26 - [9164] ----D- C:\Documents and Settings\Tommy\Application Data\WindSolutions
      O43 - CFD: 24/05/2011 - 20:59:58 - [15049450] --H-D- C:\Documents and Settings\Tommy\Local Settings\Application Data\Adobe
      O43 - CFD: 12/12/2007 - 20:51:56 - [2756426] --H-D- C:\Documents and Settings\Tommy\Local Settings\Application Data\Ahead
      O43 - CFD: 21/09/2007 - 20:44:46 - [0] --H-D- C:\Documents and Settings\Tommy\Local Settings\Application Data\Apple
      O43 - CFD: 27/11/2010 - 11:59:48 - [115339645] --H-D- C:\Documents and Settings\Tommy\Local Settings\Application Data\Apple Computer
      O43 - CFD: 10/08/2009 - 13:11:40 - [3966] --H-D- C:\Documents and Settings\Tommy\Local Settings\Application Data\ApplicationHistory
      O43 - CFD: 15/05/2011 - 16:42:24 - [83707] --H-D- C:\Documents and Settings\Tommy\Local Settings\Application Data\Google
      O43 - CFD: 22/03/2009 - 15:13:46 - [8892585] --H-D- C:\Documents and Settings\Tommy\Local Settings\Application Data\HP
      O43 - CFD: 23/10/2007 - 17:59:48 - [303396] --H-D- C:\Documents and Settings\Tommy\Local Settings\Application Data\Identities
      O43 - CFD: 20/09/2007 - 20:11:54 - [0] --H-D- C:\Documents and Settings\Tommy\Local Settings\Application Data\Logitech-LS
      O43 - CFD: 24/05/2011 - 21:03:38 - [333720244] --H-D- C:\Documents and Settings\Tommy\Local Settings\Application Data\Microsoft
      O43 - CFD: 13/05/2008 - 20:51:48 - [0] --H-D- C:\Documents and Settings\Tommy\Local Settings\Application Data\Microsoft Help
      O43 - CFD: 13/11/2008 - 16:13:50 - [580004] --H-D- C:\Documents and Settings\Tommy\Local Settings\Application Data\Mostick
      O43 - CFD: 14/04/2008 - 19:35:58 - [123792432] --H-D- C:\Documents and Settings\Tommy\Local Settings\Application Data\Mozilla
      O43 - CFD: 09/03/2008 - 17:25:34 - [0] --H-D- C:\Documents and Settings\Tommy\Local Settings\Application Data\PCHealth
      O43 - CFD: 24/05/2011 - 21:03:38 - [0] --H-D- C:\Documents and Settings\Tommy\Local Settings\Application Data\Temp



      ---\\ Derniers fichiers modifiés ou crées sous Windows et System32 (O44)
      O44 - LFC:[MD5.DCEE1200F915817C00FCFD7FB0EF1200] - 24/05/2011 - 20:21:30 ---A- . (...) -- C:\WINDOWS\WindowsUpdate.log [1315256]
      O44 - LFC:[MD5.FACF3606356EF34115D857906D449F13] - 24/05/2011 - 20:21:29 ---A- . (...) -- C:\WINDOWS\KB979687.log [22676]
      O44 - LFC:[MD5.BF061DE0D9953E13B1BF3CB1314C9378] - 24/05/2011 - 20:21:12 ---A- . (...) -- C:\WINDOWS\setupapi.log [38016]
      O44 - LFC:[MD5.0E7EE42092F2A5C24A77081FAD0CE306] - 24/05/2011 - 20:20:44 ---A- . (...) -- C:\WINDOWS\KB978706.log [22301]
      O44 - LFC:[MD5.D41D8CD98F00B204E9800998ECF8427E] - 24/05/2011 - 20:17:55 ---A- . (...) -- C:\WINDOWS\0.log [0]
      O44 - LFC:[MD5.DCEE1200F915817C00FCFD7FB0EF1200] - 24/05/2011 - 20:17:50 ---A- . (...) -- C:\WINDOWS\wiaservc.log [50]
      O44 - LFC:[MD5.DCEE1200F915817C00FCFD7FB0EF1200] - 24/05/2011 - 20:17:49 ---A- . (...) -- C:\WINDOWS\wiadebug.log [159]
      O44 - LFC:[MD5.6A2CB42966136854F4464516FBB4AE72] - 24/05/2011 - 20:17:18 -S-A- . (...) -- C:\WINDOWS\bootstat.dat [2048]
      O44 - LFC:[MD5.DCEE1200F915817C00FCFD7FB0EF1200] - 24/05/2011 - 20:16:23 ---A- . (...) -- C:\WINDOWS\SchedLgU.Txt [32520]
      O44 - LFC:[MD5.E7D612EDCDCD622447B8DDE67A1848EB] - 24/05/2011 - 20:08:37 ---A- . (...) -- C:\WINDOWS\System32\d3d9caps.tmp [1324]
      O44 - LFC:[MD5.1299E5D605BD39CA828B8FFB68CC29CD] - 24/05/2011 - 20:08:27 ---A- . (.Sun Microsystems, Inc. - Java(TM) Control Panel.) -- C:\WINDOWS\System32\REN201.tmp [73728]
      O44 - LFC:[MD5.C88C969B8E477E4297E4A65D66852BF3] - 24/05/2011 - 20:08:27 ---A- . (.Sun Microsystems, Inc. - Java(TM) Platform SE binary.) -- C:\WINDOWS\System32\deployJava1.dll [472808]
      O44 - LFC:[MD5.B157E305260FF2A607591F33DE41BFCA] - 24/05/2011 - 20:08:27 ---A- . (.Sun Microsystems, Inc. - Java(TM) Platform SE binary.) -- C:\WINDOWS\System32\java.exe [145184]
      O44 - LFC:[MD5.364F7A2B4B535659F3B50DE5E5C20123] - 24/05/2011 - 20:08:27 ---A- . (.Sun Microsystems, Inc. - Java(TM) Platform SE binary.) -- C:\WINDOWS\System32\javaw.exe [145184]
      O44 - LFC:[MD5.A0AC7907D47B54238CA60FC47807F119] - 24/05/2011 - 20:08:27 ---A- . (.Sun Microsystems, Inc. - Java(TM) Web Start Launcher.) -- C:\WINDOWS\System32\javaws.exe [157472]
      O44 - LFC:[MD5.D204CC2C8EC0998AD359AAD8A5CF9449] - 24/05/2011 - 20:08:24 ---A- . (...) -- C:\WINDOWS\System32\jupdate-1.6.0_25-b06.log [6844]
      O44 - LFC:[MD5.2A253D605FB6AE64134FFACD90E03A9E] - 24/05/2011 - 20:06:04 ---A- . (.Sun Microsystems, Inc. - Java(TM) Platform SE binary.) -- C:\jxpiinstall.exe [886560]
      O44 - LFC:[MD5.9CF86ACE040B86AA2A45C7EE58862CBE] - 24/05/2011 - 19:51:35 ---A- . (.Adobe Systems Incorporated - Adobe Self Extractor.) -- C:\AdbeRdr1001_fr_FR.exe [47929240]
      O44 - LFC:[MD5.7B7CB078E967092EDF3D2EB5780C1D30] - 24/05/2011 - 19:41:07 ---A- . (...) -- C:\ZHPExportRegistry-24-05-2011-20-41-07.txt [11808]
      O44 - LFC:[MD5.800911EC419D5BCD192DF88D7FD21009] - 23/05/2011 - 21:53:18 ---A- . (...) -- C:\WINDOWS\KB2485663.log [12713]
      O44 - LFC:[MD5.94FAC96C81819A69732C1FC490E986D1] - 23/05/2011 - 21:52:39 ---A- . (...) -- C:\WINDOWS\KB973904.log [12694]
      O44 - LFC:[MD5.55189104170E637C97EB8808F01FF7FD] - 23/05/2011 - 21:51:58 ---A- . (...) -- C:\WINDOWS\KB923561.log [12694]
      O44 - LFC:[MD5.4022377A7F2CDAC1D57557C3D75562CB] - 18/05/2011 - 20:43:47 ---A- . (...) -- C:\ComboFix.txt [11028]
      O44 - LFC:[MD5.C9DD76D0EF94637C77FF8CA5E0FB0684] - 18/05/2011 - 20:37:45 ---A- . (...) -- C:\WINDOWS\system.ini [227]
      O44 - LFC:[MD5.499EF3AE8D9F4244E61811F99EA17993] - 18/05/2011 - 20:25:52 ---A- . (...) -- C:\CF-Submit.htm [1276]
      O44 - LFC:[MD5.88633907E9A7090974B545F46850423D] - 18/05/2011 - 13:45:27 RSHA- . (...) -- C:\boot.ini [328]
      O44 - LFC:[MD5.AE72E8619CB31D84DA25E2435E55003C] - 18/05/2011 - 13:38:15 ---A- . (.NirSoft - NirCmd.) -- C:\WINDOWS\NIRCMD.exe [31232]
      O44 - LFC:[MD5.01D95A1F8CF13D07CC564AABB36BCC0B] - 18/05/2011 - 13:38:15 ---A- . (.SteelWerX - Freeware implementation of REG.EXE.) -- C:\WINDOWS\SWREG.exe [161792]
      O44 - LFC:[MD5.B7517DB073B28F5696A1E5528ABEB5D0] - 18/05/2011 - 13:38:15 ---A- . (.SteelWerX - Freeware implementation of SC.EXE.) -- C:\WINDOWS\SWSC.exe [136704]
      O44 - LFC:[MD5.B1A9CF0B6F80611D31987C247EC630B4] - 18/05/2011 - 13:38:15 ---A- . (.SteelWerX - Freeware implementation of XCACLS.) -- C:\WINDOWS\SWXCACLS.exe [212480]
      O44 - LFC:[MD5.C790B08C6F0405499F813167DE1D48D0] - 18/05/2011 - 13:21:16 ---A- . (...) -- C:\PhysicalDisk0_MBR.bin [512]
      O44 - LFC:[MD5.43847A56AEE65BEC2EBCF96519616E27] - 01/05/2011 - 10:14:57 ---A- . (...) -- C:\WINDOWS\System32\d3d8caps.dat [552]
      O44 - LFC:[MD5.9DAA7218961710008D7385B01BD3F386] - 08/11/2010 - 00:20:24 ---A- . (...) -- C:\WINDOWS\MBR.exe [89088]
      O44 - LFC:[MD5.F1FBA6185A6A2BC6456970914875078E] - 26/04/2010 - 14:58:12 ---A- . (...) -- C:\WINDOWS\PEV.exe [256512]
      O44 - LFC:[MD5.775E188DD15C9AC9E735A556FB95578E] - 19/09/2007 - 16:23:18 ---A- . (...) -- C:\Boot.bak [212]
      O44 - LFC:[MD5.48C65662EC81FBCAA110509F50C51497] - 03/08/2004 - 22:00:08 RSHA- . (...) -- C:\cmldr [263488]
      O44 - LFC:[MD5.9E05A9C264C8A908A8E79450FCBFF047] - 31/08/2000 - 07:00:00 ---A- . (...) -- C:\WINDOWS\grep.exe [80412]
      O44 - LFC:[MD5.2B657A67AEBB84AEA5632C53E61E23BF] - 31/08/2000 - 07:00:00 ---A- . (...) -- C:\WINDOWS\sed.exe [98816]
      O44 - LFC:[MD5.5E832F4FAF5F481F2EAF3B3A48F603B8] - 31/08/2000 - 07:00:00 ---A- . (...) -- C:\WINDOW
      0
  21. Utilisateur anonyme
     
    Bonsoir
    Il me faudrait le rapport de ZHPFix, et héberge le rapport de ZHPDiag, car il
    n'est pas entier
    0
    1. manong
       
      ZPHFix : http://up.sur-la-toile.com/iNfS

      ZPHDiag : http://up.sur-la-toile.com/iNfT
      0
  • 1
  • 2