-
Contributeur sécuritéSalut,
Ok tu peux vacciner tes supports.
Je relance, tu as fait deux fois ZHPfix ?
En attendant, fais ça ==>
ATTENTION ! Plusieurs heures de scan sont probables !
Télécharge Malwarebytes' Anti-Malware MBAMsur ton bureau : http://www.malwarebytes.org/mbam/program/mbam-setup.exe
Si problème essaie avec celui-ci : https://www.commentcamarche.net/telecharger/securite/14361-malwarebytes-anti-malware/
. Enregistre-le sur ton bureau.
. Double clique sur le fichier téléchargé pour lancer le processus d'installation. (Vista et 7 : Éxécuter en tant qu'administrateur)
. Si le pare-feu demande l'autorisation de se connecter pour malwarebytes, accepte.
. Dans l'onglet "Mise à jour", clique sur le bouton "Recherche de mise à jour".
Fais le plusieurs fois jusqu'à ce qu'il te dise que tu as la dernière version de base de données.
. Une fois la mise à jour terminée :
. Rends-toi dans l'onglet "Recherche"
. Sélectionne Exécuter un Examen complet.
. Sélectionne Tous les disques si proposé.
. Clique sur Rechercher.
. Le scan démarre. Patiente, cela peut durer plusieurs heures, selon la taille de tes disques.
. À la fin de l'analyse, un message s'affiche : L'examen s'est terminé normalement ou autre. Clique sur "Afficher les résultats" pour afficher tous les objets trouvés.
. Cliques sur Ok pour poursuivre.
. Si des malwares ont été détectés<souligne>, clique sur Afficher les résultats.
. <souligne>Sélectionne tout (ou laisse coché) et clique sur Supprimer la sélection, Malwarebytes va détruire les fichiers et clés de registre et en mettre une copie dans la quarantaine.
. Malwarebytes va ouvrir le bloc-notes et y copier le rapport d'analyse.
. Redemarre le PC si il le fait pas lui même.
. Une fois redémarré double-clique sur Malwarebytes' AntiMalware.
. Rends toi dans l'onglet "rapport/log".
. Tu cliques sur le rapport pour l'afficher.
. Tu cliques sur Edition en haut du boc notes,et puis sur Sélectionner tout.
. Tu recliques sur Edition et puis sur Copier et tu reviens sur le forum et dans ta réponse, colle le rapport (CTRL + V).
=> Si tu as besoin d'aide regarde ce tutoriel :
https://www.malekal.com/tutoriel-malwarebyte-anti-malware/
Si tu as des questions, n'hésite pas à me les poser !
Merci,
Gabriel.
-
Bonjour,
Oui J'ai fait deux fois car mon pc a planté a la première fois!
Je vais faire ce que tu m'as ecrit!
Merci -
Rapport Malwarebytes' AntiMalware:
Malwarebytes' Anti-Malware 1.51.1.1800
www.malwarebytes.org
Version de la base de données: 7373
Windows 5.1.2600 Service Pack 3
Internet Explorer 7.0.5730.13
04/08/2011 10:50:24
mbam-log-2011-08-04 (10-50-24).txt
Type d'examen: Examen complet (C:\|D:\|E:\|F:\|G:\|H:\|)
Elément(s) analysé(s): 179163
Temps écoulé: 23 minute(s), 54 seconde(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 0
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 1
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 60
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Elément(s) de données du Registre infecté(s):
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowHelp (PUM.Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully.
Dossier(s) infecté(s):
(Aucun élément nuisible détecté)
Fichier(s) infecté(s):
f:\program files\ad-remover\quarantine\F\documents and settings\K'2sy\application data\EoRezo\softwareupdate\softwareupdate.exe.vir (Rogue.Eorezo) -> Quarantined and deleted successfully.
f:\program files\ad-remover\quarantine\F\documents and settings\K'2sy\application data\EoRezo\softwareupdate\softwareupdatehp.exe.vir (Rogue.Eorezo) -> Quarantined and deleted successfully.
f:\program files\ad-remover\quarantine\F\documents and settings\K'2sy\application data\EoRezo\softwareupdate\Software\itsTV\3.0.1.294\bonjour.exe.vir (Trojan.StartPage) -> Quarantined and deleted successfully.
f:\program files\ad-remover\quarantine\F\documents and settings\K'2sy\application data\EoRezo\softwareupdate\Software\itsTV\3.0.1.316\bonjour.exe.vir (Trojan.StartPage) -> Quarantined and deleted successfully.
f:\program files\ad-remover\quarantine\F\documents and settings\K'2sy\application data\EoRezo\softwareupdate\Software\itsTV\3.0.1.322\bonjour.exe.vir (Trojan.StartPage) -> Quarantined and deleted successfully.
f:\program files\ad-remover\quarantine\F\documents and settings\K'2sy\application data\EoRezo\softwareupdate\Software\itsTV\3.0.1.323\bonjour.exe.vir (Trojan.StartPage) -> Quarantined and deleted successfully.
f:\program files\ad-remover\quarantine\F\documents and settings\K'2sy\application data\EoRezo\softwareupdate\Software\itsTV\4.0.0.1741743\itstv.exe.vir (Trojan.Clicker) -> Quarantined and deleted successfully.
f:\program files\ad-remover\quarantine\F\documents and settings\K'2sy\application data\EoRezo\softwareupdate\Software\itsTV\4.0.0.1461463\itstv.exe.vir (Trojan.Clicker) -> Quarantined and deleted successfully.
f:\program files\ad-remover\quarantine\F\documents and settings\K'2sy\application data\EoRezo\softwareupdate\Software\itsTV\4.0.0.1471471\itstv.exe.vir (Trojan.Clicker) -> Quarantined and deleted successfully.
f:\program files\ad-remover\quarantine\F\documents and settings\K'2sy\application data\EoRezo\softwareupdate\Software\itsTV\4.0.0.1491493\itstv.exe.vir (Trojan.Clicker) -> Quarantined and deleted successfully.
f:\program files\ad-remover\quarantine\F\documents and settings\K'2sy\application data\EoRezo\softwareupdate\Software\itsTV\4.0.0.1511512\itstv.exe.vir (Trojan.Clicker) -> Quarantined and deleted successfully.
f:\program files\ad-remover\quarantine\F\documents and settings\K'2sy\application data\EoRezo\softwareupdate\Software\itsTV\4.0.0.1531533\itstv.exe.vir (Trojan.Clicker) -> Quarantined and deleted successfully.
f:\program files\ad-remover\quarantine\F\documents and settings\K'2sy\application data\EoRezo\softwareupdate\Software\itsTV\4.0.0.1561563\itstv.exe.vir (Trojan.Clicker) -> Quarantined and deleted successfully.
f:\program files\ad-remover\quarantine\F\documents and settings\K'2sy\application data\EoRezo\softwareupdate\Software\itsTV\4.0.0.1731732\itstv.exe.vir (Trojan.Clicker) -> Quarantined and deleted successfully.
f:\program files\ad-remover\quarantine\F\documents and settings\K'2sy\application data\EoRezo\softwareupdate\Software\itsTV\4.0.0.1741742\itstv.exe.vir (Trojan.Clicker) -> Quarantined and deleted successfully.
f:\program files\ad-remover\quarantine\F\documents and settings\K'2sy\application data\EoRezo\softwareupdate\Software\itsTV\4.0.0.1761763\itstv.exe.vir (Trojan.Clicker) -> Quarantined and deleted successfully.
f:\program files\ad-remover\quarantine\F\documents and settings\K'2sy\application data\EoRezo\softwareupdate\Software\itsTV\4.0.0.1791793\itstv.exe.vir (Adware.Agent) -> Quarantined and deleted successfully.
f:\program files\ad-remover\quarantine\F\documents and settings\K'2sy\application data\EoRezo\softwareupdate\Software\itsTV\4.0.0.1801803\itstv.exe.vir (Adware.Agent) -> Quarantined and deleted successfully.
f:\program files\ad-remover\quarantine\F\documents and settings\K'2sy\application data\EoRezo\softwareupdate\Software\itsTV\4.0.0.1811812\itstv.exe.vir (Adware.Agent) -> Quarantined and deleted successfully.
f:\program files\ad-remover\quarantine\F\documents and settings\K'2sy\application data\EoRezo\softwareupdate\Software\itsTV\4.0.0.1811813\itstv.exe.vir (Trojan.Clicker) -> Quarantined and deleted successfully.
f:\program files\ad-remover\quarantine\F\documents and settings\K'2sy\application data\EoRezo\softwareupdate\Software\itsTV\4.0.0.2062063\sufr.exe.vir (Adware.Agent) -> Quarantined and deleted successfully.
f:\program files\ad-remover\quarantine\F\documents and settings\K'2sy\application data\EoRezo\softwareupdate\Software\itsTV\4.0.0.2072071\sufr.exe.vir (Adware.Agent) -> Quarantined and deleted successfully.
f:\program files\ad-remover\quarantine\F\documents and settings\K'2sy\application data\EoRezo\softwareupdate\Software\itsTV\4.0.0.2072073\sufr.exe.vir (Adware.Agent) -> Quarantined and deleted successfully.
f:\program files\ad-remover\quarantine\F\documents and settings\K'2sy\application data\EoRezo\softwareupdate\Software\itsTV\4.0.0.2132133\sufr.exe.vir (Adware.Agent) -> Quarantined and deleted successfully.
f:\program files\ad-remover\quarantine\F\program files\EoRezo\eorezo.exe.vir (Rogue.Eorezo) -> Quarantined and deleted successfully.
f:\program files\ad-remover\quarantine\F\program files\EoRezo\eoengine.exe.vir (Rogue.Eorezo) -> Quarantined and deleted successfully.
f:\program files\ad-remover\quarantine\F\program files\EoRezo\eorezobho.dll.vir (Rogue.Eorezo) -> Quarantined and deleted successfully.
f:\program files\ad-remover\quarantine\F\program files\EoRezo\EoAdv\eoadv.dll.vir (Rogue.Eorezo) -> Quarantined and deleted successfully.
f:\program files\ad-remover\quarantine\F\program files\EoRezo\EoAdv\eorezobho.dll.vir (Rogue.Eorezo) -> Quarantined and deleted successfully.
f:\program files\ad-remover\quarantine\F\program files\shoppingreport\Bin\2.6.79\shoppingreport.dll.vir (Adware.SmartShopper) -> Quarantined and deleted successfully.
f:\system volume information\_restore{5109cc3b-0b7e-4007-86f7-e11fca9193b2}\RP111\A0117673.dll (Adware.SmartShopper) -> Quarantined and deleted successfully.
f:\system volume information\_restore{5109cc3b-0b7e-4007-86f7-e11fca9193b2}\RP111\A0117701.exe (Trojan.StartPage) -> Quarantined and deleted successfully.
f:\system volume information\_restore{5109cc3b-0b7e-4007-86f7-e11fca9193b2}\RP111\A0117705.exe (Trojan.StartPage) -> Quarantined and deleted successfully.
f:\system volume information\_restore{5109cc3b-0b7e-4007-86f7-e11fca9193b2}\RP111\A0117707.exe (Trojan.StartPage) -> Quarantined and deleted successfully.
f:\system volume information\_restore{5109cc3b-0b7e-4007-86f7-e11fca9193b2}\RP111\A0117708.exe (Trojan.StartPage) -> Quarantined and deleted successfully.
f:\system volume information\_restore{5109cc3b-0b7e-4007-86f7-e11fca9193b2}\RP111\A0117772.exe (Trojan.Clicker) -> Quarantined and deleted successfully.
f:\system volume information\_restore{5109cc3b-0b7e-4007-86f7-e11fca9193b2}\RP111\A0117808.exe (Rogue.Eorezo) -> Quarantined and deleted successfully.
f:\system volume information\_restore{5109cc3b-0b7e-4007-86f7-e11fca9193b2}\RP111\A0117768.exe (Trojan.Clicker) -> Quarantined and deleted successfully.
f:\system volume information\_restore{5109cc3b-0b7e-4007-86f7-e11fca9193b2}\RP111\A0117769.exe (Trojan.Clicker) -> Quarantined and deleted successfully.
f:\system volume information\_restore{5109cc3b-0b7e-4007-86f7-e11fca9193b2}\RP111\A0117770.exe (Trojan.Clicker) -> Quarantined and deleted successfully.
f:\system volume information\_restore{5109cc3b-0b7e-4007-86f7-e11fca9193b2}\RP111\A0117771.exe (Trojan.Clicker) -> Quarantined and deleted successfully.
f:\system volume information\_restore{5109cc3b-0b7e-4007-86f7-e11fca9193b2}\RP111\A0117773.exe (Trojan.Clicker) -> Quarantined and deleted successfully.
f:\system volume information\_restore{5109cc3b-0b7e-4007-86f7-e11fca9193b2}\RP111\A0117774.exe (Trojan.Clicker) -> Quarantined and deleted successfully.
f:\system volume information\_restore{5109cc3b-0b7e-4007-86f7-e11fca9193b2}\RP111\A0117775.exe (Trojan.Clicker) -> Quarantined and deleted successfully.
f:\system volume information\_restore{5109cc3b-0b7e-4007-86f7-e11fca9193b2}\RP111\A0117776.exe (Trojan.Clicker) -> Quarantined and deleted successfully.
f:\system volume information\_restore{5109cc3b-0b7e-4007-86f7-e11fca9193b2}\RP111\A0117777.exe (Trojan.Clicker) -> Quarantined and deleted successfully.
f:\system volume information\_restore{5109cc3b-0b7e-4007-86f7-e11fca9193b2}\RP111\A0117778.exe (Adware.Agent) -> Quarantined and deleted successfully.
f:\system volume information\_restore{5109cc3b-0b7e-4007-86f7-e11fca9193b2}\RP111\A0117779.exe (Adware.Agent) -> Quarantined and deleted successfully.
f:\system volume information\_restore{5109cc3b-0b7e-4007-86f7-e11fca9193b2}\RP111\A0117780.exe (Adware.Agent) -> Quarantined and deleted successfully.
f:\system volume information\_restore{5109cc3b-0b7e-4007-86f7-e11fca9193b2}\RP111\A0117781.exe (Trojan.Clicker) -> Quarantined and deleted successfully.
f:\system volume information\_restore{5109cc3b-0b7e-4007-86f7-e11fca9193b2}\RP111\A0117782.exe (Adware.Agent) -> Quarantined and deleted successfully.
f:\system volume information\_restore{5109cc3b-0b7e-4007-86f7-e11fca9193b2}\RP111\A0117783.exe (Adware.Agent) -> Quarantined and deleted successfully.
f:\system volume information\_restore{5109cc3b-0b7e-4007-86f7-e11fca9193b2}\RP111\A0117784.exe (Adware.Agent) -> Quarantined and deleted successfully.
f:\system volume information\_restore{5109cc3b-0b7e-4007-86f7-e11fca9193b2}\RP111\A0117785.exe (Adware.Agent) -> Quarantined and deleted successfully.
f:\system volume information\_restore{5109cc3b-0b7e-4007-86f7-e11fca9193b2}\RP111\A0117809.exe (Rogue.Eorezo) -> Quarantined and deleted successfully.
f:\system volume information\_restore{5109cc3b-0b7e-4007-86f7-e11fca9193b2}\RP111\A0117812.dll (Rogue.Eorezo) -> Quarantined and deleted successfully.
f:\system volume information\_restore{5109cc3b-0b7e-4007-86f7-e11fca9193b2}\RP111\A0117813.dll (Rogue.Eorezo) -> Quarantined and deleted successfully.
f:\system volume information\_restore{5109cc3b-0b7e-4007-86f7-e11fca9193b2}\RP111\A0117819.exe (Rogue.Eorezo) -> Quarantined and deleted successfully.
f:\system volume information\_restore{5109cc3b-0b7e-4007-86f7-e11fca9193b2}\RP111\A0117821.exe (Rogue.Eorezo) -> Quarantined and deleted successfully.
f:\system volume information\_restore{5109cc3b-0b7e-4007-86f7-e11fca9193b2}\RP111\A0117822.dll (Rogue.Eorezo) -> Quarantined and deleted successfully. -
Contributeur sécuritéOk pas de soucis ;)
Tu peux me refaire un ZHPdiag pour vérifier si c'est clean ?
@+
Gabriel.
-
Rapport ZHPDiag:
Rapport de ZHPDiag v1.28.122 par Nicolas Coolman, Update du 03/08/2011
Run by K'2sy at 04/08/2011 18:17:54
Web site : http://www.premiumorange.com/zeb-help-process/zhpdiag.html
---\\ Web Browser
MSIE: Internet Explorer v7.0.5730.13 (Defaut)
---\\ Windows Product Information
Windows XP Professional Service Pack 3 (Build 2600)
Windows Automatic Updates : OK
---\\ System Information
~ Processor: x86 Family 6 Model 14 Stepping 12, GenuineIntel
~ Operating System: 32 Bits
Boot mode: Normal (Normal boot)
Total RAM: 502 MB (36% free)
System Restore: Activé (Enable)
System drive F: has 14 GB (57%) free of 24 GB
---\\ Logged in mode
~ Computer Name: TEAM-E675AC6A7C
~ User Name: K'2sy
~ All Users Names: K'2sy, HelpAssistant, ASPNET, Administrateur,
~ Unselected Option: O45,O61,O62,O65,O66,O82
Logged in as Administrator
---\\ Environnement Variables
~ System Unit : F:\
~ %AppData% : F:\Documents and Settings\K'2sy\Application Data\
~ %Desktop% : F:\Documents and Settings\K'2sy\Bureau\
~ %Favorites% : F:\Documents and Settings\K'2sy\Favoris\
~ %LocalAppData% : F:\Documents and Settings\K'2sy\Local Settings\Application Data\
~ %StartMenu% : F:\Documents and Settings\K'2sy\Menu Démarrer\
~ %Windir% : F:\WINDOWS\
~ %System% : F:\WINDOWS\system32\
---\\ DOS/Devices
C:\ Hard drive, Flash drive, Thumb drive (Free 23 Go of 24 Go)
D:\ Hard drive, Flash drive, Thumb drive (Free 26 Go of 26 Go)
E:\ CD-ROM drive (Not Inserted)
F:\ Hard drive, Flash drive, Thumb drive (Free 14 Go of 24 Go)
G:\ Floppy drive, Flash card reader, USB Key (Not Inserted)
H:\ Floppy drive, Flash card reader, USB Key (Not Inserted)
---\\ Security Center & Tools Informations
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Intl: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] XMLLookup: OK
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK
[HKLM\SYSTEM\CurrentControlSet\Services] wscsvc : Modified
~ Scan Security Center in 00mn 00s
---\\ Recherche particulière de fichiers génériques
[MD5.76445E197EB693EAE328078E331024F9] - (.Microsoft Corporation - Explorateur Windows.) (.04/08/2011 - 10:04:05.) -- F:\WINDOWS\Explorer.exe [1992704]
[MD5.93AD0B78C7357A05F50E594EC7C22300] - (....) (.04/08/2011 - 23:57:00.) -- F:\WINDOWS\system32\rundll32.exe [33792]
[MD5.78D3D2B0BE6AD3E6D82CCB115CF74310] - (.Microsoft Corporation - Internet Extensions for Win32.) (.04/08/2011 - 23:57:00.) -- F:\WINDOWS\system32\wininet.dll [827392]
[MD5.DD73D6B9F6B4CB630CF35B438B540174] - (.Microsoft Corporation - Application d'ouverture de session Windows NT.) (.04/08/2011 - 23:57:00.) -- F:\WINDOWS\system32\Winlogon.exe [512000]
[MD5.9F3A2F5AA6875C72BF062C712CFA2674] - (.Microsoft Corporation - IDE/ATAPI Port Driver.) (.04/08/2011 - 10:40:32.) -- F:\WINDOWS\system32\drivers\atapi.sys [96512]
[MD5.78A08DD6A8D65E697C18E1DB01C5CDCA] - (.Microsoft Corporation - NT File System Driver.) (.04/08/2011 - 23:57:00.) -- F:\WINDOWS\system32\drivers\ntfs.sys [574976]
~ Scan Generic Processes in 00mn 00s
---\\ Etat des fichiers cachés (Caché/Total)
~ Mes images (My Pictures) : 0/0
~ Mes musiques (My Musics) : 3/132
~ Mes Videos (My Video) : 0/0
~ Mes Favoris (My Favorites) : 1/22
~ Mes Documents (My Documents) : 25/313
~ Mon Bureau (My Desktop) : 0/19
~ Menu demarrer (Programs) : 4/24
~ Scan Hidden Files in 00mn 04s
---\\ Processus lancés
[MD5.E35B4E2DBBF315334E3218DCC814A627] - (.ALWIL Software - avast! firewall service.) -- F:\Program Files\Alwil Software\Avast5\afwServ.exe [119200]
[MD5.57E6D33E74C6D3F198890DB4933644A7] - (.ALWIL Software - avast! Service.) -- F:\Program Files\Alwil Software\Avast5\AvastSvc.exe [40384]
[MD5.D503DF3ABA595F551B98B9BAE017A271] - (.Apple Inc. - Apple Mobile Device Service.) -- F:\Program Files\Fichiers communs\Apple\Mobile Device Support\AppleMobileDeviceService.exe [144672]
[MD5.EBAD0F51D8D4DADE7660B1851ADDBD07] - (.Apple Inc. - Bonjour Service.) -- F:\Program Files\Bonjour\mDNSResponder.exe [345376]
[MD5.37036C07983EF1024B2FF3C28AAE5700] - (.Malwarebytes Corporation - Malwarebytes' Anti-Malware.) -- F:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [366640]
[MD5.BCCC9AE7DBB189F13A1EF07798D5EEA6] - (.Labtec Inc. - LVCom Server.) -- F:\WINDOWS\system32\LVCOMSX.EXE [221184]
[MD5.C1ED47899277B749B4D3EB8AA640B05D] - (.Labtec Inc. - ImageStudio Tray Application.) -- F:\Program Files\Logitech\Video\LogiTray.exe [217088]
[MD5.8DE8DEFE523C005C5F88852E2493D67D] - (.ALWIL Software - avast! Antivirus.) -- F:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe [2790472]
[MD5.A244E67F073377DE0E53D3068932B040] - (.Apple Inc. - iTunesHelper.) -- F:\Program Files\iTunes\iTunesHelper.exe [142120]
[MD5.33BFCE71F407F24E5DFDB7DD46CE2D6D] - (.Malwarebytes Corporation - Malwarebytes' Anti-Malware.) -- F:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe [449584]
[MD5.11B85909A98A0BE260D1884D13294176] - (.Labtec Inc. - QuickCam Framework Server.) -- F:\Program Files\Logitech\Video\FxSvr2.exe [192512]
[MD5.5D61BE7DB55B026A5D61A3EED09D0EAD] - (.Google Inc. - GoogleToolbarNotifier.) -- F:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408]
[MD5.BC9C9BE7BB74D629362608ACE470E7DA] - (.Microsoft Corporation - Notification de cadeaux MSN.) -- F:\Documents and Settings\K'2sy\Application Data\Microsoft\Notification de cadeaux MSN\lsnfier.exe [135680]
[MD5.3C30491045DBBD44A42876B3D6F3917D] - (.Apple Inc. - iPodService Module (32-bit).) -- F:\Program Files\iPod\bin\iPodService.exe [545576]
[MD5.197B7E4030CFBD8D2979D375E1787AA2] - (.Microsoft Corporation - Internet Explorer.) -- F:\Program Files\Internet Explorer\iexplore.exe [625664]
[MD5.20A098A4D12E49342228D3AFE98EAFDF] - (.Microsoft Corporation - Windows Live Toolbar User Elevation Helper.) -- F:\Program Files\Windows Live\Toolbar\wltuser.exe [223584]
[MD5.AB0C42AFB2B2E3A12058919EC07A2220] - (.Nicolas Coolman - Diagnostic Tool.) -- F:\Program Files\ZHPDiag\ZHPDiag.exe [663552]
~ Scan Processes Running in 00mn 00s
---\\ Mozilla Firefox, Plugins,Demarrage,Recherche,Extensions (P2,M0,M1,M2,M3)
P2 - FPN: [HKLM] [@adobe.com/ShockwavePlayer] - (.Adobe Systems, Inc. - Adobe Shockwave for Director Netscape plug-in, version 11.5.9.615.) -- F:\WINDOWS\system32\Adobe\Director\np32dsw.dll
P2 - FPN: [HKLM] [@Apple.com/iTunes,version=1.0] - (...) -- F:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
P2 - FPN: [HKLM] [@Microsoft.com/NpCtrl,version=1.0] - (. Microsoft Corporation - 3.0.40624.0.) -- F:\Program Files\Microsoft Silverlight\3.0.40624.0\npctrl.dll
P2 - FPN: [HKLM] [@microsoft.com/WLPG,version=14.0.8117.0416] - (.Microsoft Corporation - NPWLPG.) -- F:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
P2 - FPN: [HKLM] [@microsoft.com/WPF,version=3.5] - (.Microsoft Corporation - Windows Presentation Foundation (WPF) plug-in for Mozilla browsers.) -- F:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
~ Scan Firefox Browser in 00mn 00s
---\\ Internet Explorer, Démarrage,Recherche,URLSearchHook, Phishing (R0,R1,R3,R4)
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
R0 - HKUS\S-1-5-21-602162358-484763869-1177238915-1002\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.microsoft.com/fr-fr/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.microsoft.com/fr-fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk
R3 - URLSearchHook: Microsoft Url Search Hook - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} . (.Microsoft Corporation - Internet Explorer.) (7.00.6000.20815 (vista_ldr.080415-1732)) -- F:\WINDOWS\system32\ieframe.dll
R4 - HKCU\SOFTWARE\Microsoft\Internet Explorer\PhishingFilter,Enabled = 2
~ Scan IE Browser in 00mn 00s
---\\ Internet Explorer, Proxy Management (R5)
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll
~ Scan Proxy management in 00mn 00s
---\\ Modification d'une valeur Ini (Changed inifile value, mapped to Registry) (F2)
F2 - REG:system.ini: UserInit=F:\WINDOWS\system32\userinit.exe,
F2 - REG:system.ini: VMApplet=rundll32 shell32,Control_RunDLL "sysdm.cpl"
~ Scan Keys in 00mn 00s
---\\ Redirection du fichier Hosts (O1)
~ Scan Hosts File in 00mn 22s
---\\ Browser Helper Objects de navigateur (O2)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} Clé orpheline
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} . (.Microsoft Corp. - Microsoft Search Helper Extention.) -- F:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} . (.Microsoft Corporation - WindowsLiveLogin.dll.) -- F:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} . (.Google Inc. - Google Toolbar.) -- F:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} . (.Google Inc. - GoogleToolbarNotifier.) -- F:\Program Files\Google\GoogleToolbarNotifier\5.6.5612.1312\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} . (.Microsoft Corporation - Windows Live Toolbar Core.) -- F:\Program Files\Windows Live\Toolbar\wltcore.dll
~ Scan BHO in 00mn 00s
---\\ Internet Explorer Toolbars (O3)
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} . (.Google Inc. - Google Toolbar.) -- F:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} . (.Microsoft Corporation - Windows Live Toolbar Core.) -- F:\Program Files\Windows Live\Toolbar\wltcore.dll
~ Scan Toolbar in 00mn 00s
---\\ Applications démarrées par registre & par dossier (O4)
O4 - HKLM\..\Run: [DAEMON Tools] Clé orpheline
O4 - HKLM\..\Run: [RTHDCPL] . (.Realtek Semiconductor Corp. - Realtek HD Audio Control Panel.) -- F:\WINDOWS\RTHDCPL.exe
O4 - HKLM\..\Run: [Alcmtr] . (.Realtek Semiconductor Corp. - Realtek Azalia Audio - Event Monitor.) -- F:\WINDOWS\ALCMTR.exe
O4 - HKLM\..\Run: [LVCOMSX] . (.Labtec Inc. - LVCom Server.) -- F:\WINDOWS\system32\LVCOMSX.exe
O4 - HKLM\..\Run: [LogitechVideoRepair] . (.Labtec Inc. - Logitech QuickCam Startup Application.) -- F:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] . (.Labtec Inc. - ImageStudio Tray Application.) -- F:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [avast5] . (.ALWIL Software - avast! Antivirus.) -- F:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe
O4 - HKLM\..\Run: [QuickTime Task] . (.Apple Inc. - QuickTime Task.) -- F:\Program Files\QuickTime\qttask.exe
O4 - HKLM\..\Run: [iTunesHelper] . (.Apple Inc. - iTunesHelper.) -- F:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] . (.Malwarebytes Corporation - Malwarebytes' Anti-Malware.) -- F:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
O4 - HKCU\..\Run: [ctfmon.exe] . (.Microsoft Corporation - CTF Loader.) -- F:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] . (.Google Inc. - GoogleToolbarNotifier.) -- F:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [msnmsgr] . (.Microsoft Corporation - Windows Live Messenger.) -- F:\Program Files\Windows Live\Messenger\msnmsgr.exe
O4 - HKUS\S-1-5-21-602162358-484763869-1177238915-1002\..\Run: [ctfmon.exe] . (.Microsoft Corporation - CTF Loader.) -- F:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-21-602162358-484763869-1177238915-1002\..\Run: [swg] . (.Google Inc. - GoogleToolbarNotifier.) -- F:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-21-602162358-484763869-1177238915-1002\..\Run: [msnmsgr] . (.Microsoft Corporation - Windows Live Messenger.) -- F:\Program Files\Windows Live\Messenger\msnmsgr.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_2] Clé orpheline
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_3] rundll32 advpack.dll
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_2] Clé orpheline
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_3] rundll32 advpack.dll
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_2] Clé orpheline
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_3] rundll32 advpack.dll
O4 - HKUS\S-1-5-20\..\RunOnce: [nltide_2] Clé orpheline
O4 - HKUS\S-1-5-20\..\RunOnce: [nltide_3] rundll32 advpack.dll
~ Scan Application in 00mn 00s
---\\ Autres liens utilisateurs (O4)
O4 - Global Startup: F:\Documents And Settings\All Users\Menu Démarrer\Programmes\Apple Software Update.lnk . (...) -- F:\WINDOWS\Installer\{C41300B9-185D-475E-BFEC-39EF732F19B1}\AppleSoftwareUpdateIco.exe
O4 - Global Startup: F:\Documents And Settings\All Users\Menu Démarrer\Programmes\Paint.NET.lnk . (.dotPDN LLC.) -- F:\Program Files\Paint.NET\PaintDotNet.exe
O4 - Global Startup: F:\Documents And Settings\All Users\Menu Démarrer\Programmes\Windows Live Messenger.lnk . (.Microsoft Corporation.) -- F:\Program Files\Windows Live\Messenger\msnmsgr.exe
O4 - Global Startup: F:\Documents And Settings\All Users\Menu Démarrer\Programmes\Xtremsplit.lnk . (.Inekman.) -- F:\Program Files\Xtremsplit\Xtremsplit.exe
O4 - Global Startup: F:\Documents And Settings\K'2sy\Menu Démarrer\Programmes\Assistance à distance.lnk . (.Microsoft Corporation.) -- F:\WINDOWS\system32\rcimlby.exe
O4 - Global Startup: F:\Documents And Settings\K'2sy\Menu Démarrer\Programmes\Internet Explorer.lnk . (.Microsoft Corporation.) -- F:\Program Files\Internet Explorer\iexplore.exe
O4 - Global Startup: F:\Documents And Settings\K'2sy\Menu Démarrer\Programmes\Windows Media Player.lnk . (.Microsoft Corporation.) -- F:\Program Files\Windows Media Player\wmplayer.exe
~ Scan Global Startup in 00mn 00s
---\\ Lignes supplémentaires dans le menu contextuel d'Internet Explorer (O8)
O8 - Extra context menu item: Google Sidewiki... . (.Google Inc. - Google Toolbar for Internet Explorer.) -- F:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll
~ Scan IE Menu Contextuel in 00mn 00s
---\\ Boutons situés sur la barre d'outils principale d'Internet Explorer (O9)
O9 - Extra button: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} . (.Microsoft Corporation - Windows Live Writer Blog This Extension.) -- F:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} . (.Microsoft Corporation - Windows Live Writer Blog This Extension.) -- F:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
~ Scan IE Extra Buttons in 00mn 00s
---\\ Winsock hijacker (Layered Service Provider) (O10)
O10 - WLSP:\000000000001\Winsock LSP File . (.Microsoft Corporation - Fournisseur de service Sockets 2.0 de Microsoft Windows.) -- F:\WINDOWS\system32\mswsock.dll
O10 - WLSP:\000000000002\Winsock LSP File . (.Microsoft Corporation - LDAP RnR Provider DLL.) -- F:\WINDOWS\system32\winrnr.dll
O10 - WLSP:\000000000003\Winsock LSP File . (.Microsoft Corporation - Fournisseur de service Sockets 2.0 de Microsoft Windows.) -- F:\WINDOWS\system32\mswsock.dll
O10 - WLSP:\000000000004\Winsock LSP File . (.Apple Inc. - Bonjour Namespace Provider.) -- F:\Program Files\Bonjour\mdnsNSP.dll
~ Scan Winsock in 00mn 00s
---\\ Objets ActiveX (Downloaded Program Files)(O16)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {69731714-6886-4587-A9AA-D80C2763884D} (Google Gadget Control) - http://dl.google.com/dl/desktop/nv/GoogleGadgetPluginIEWin.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} () - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
~ Scan Objets ActiveX in 00mn 00s
---\\ Modification Domaine/Adresses DNS (O17)
O17 - HKLM\System\CCS\Services\Tcpip\..\{5AC5F7E0-9FBE-46D4-8A95-9B22EBB39249}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{5AC5F7E0-9FBE-46D4-8A95-9B22EBB39249}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{5AC5F7E0-9FBE-46D4-8A95-9B22EBB39249}: DhcpNameServer = 192.168.1.1
~ Scan Domain in 00mn 00s
---\\ Protocole additionnel (O18)
O18 - Handler: about - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- F:\WINDOWS\system32\mshtml.dll
O18 - Handler: cdl - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- F:\WINDOWS\system32\urlmon.dll
O18 - Handler: dvd - {12D51199-0DB5-46FE-A120-47A3D7D937CC} . (.Microsoft Corporation - Contrôle ActiveX pour le flux vidéo.) -- F:\WINDOWS\system32\msvidctl.dll
O18 - Handler: file - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- F:\WINDOWS\system32\urlmon.dll
O18 - Handler: ftp - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- F:\WINDOWS\system32\urlmon.dll
O18 - Handler: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- F:\WINDOWS\system32\urlmon.dll
O18 - Handler: http - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- F:\WINDOWS\system32\urlmon.dll
O18 - Handler: https - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- F:\WINDOWS\system32\urlmon.dll
O18 - Handler: javascript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- F:\WINDOWS\system32\mshtml.dll
O18 - Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} . (.Microsoft Corporation - Windows Live Messenger Protocol Handler Mod.) -- F:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Handler: local - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- F:\WINDOWS\system32\urlmon.dll
O18 - Handler: mailto - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- F:\WINDOWS\system32\mshtml.dll
O18 - Handler: mhtml - {05300401-BCBC-11d0-85E3-00C04FD85AB4} . (.Microsoft Corporation - Microsoft Internet Messaging API.) -- F:\WINDOWS\system32\inetcomm.dll
O18 - Handler: mk - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- F:\WINDOWS\system32\urlmon.dll
O18 - Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} . (.Microsoft Corporation - Windows Live Messenger Protocol Handler Mod.) -- F:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Handler: res - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- F:\WINDOWS\system32\mshtml.dll
O18 - Handler: tv - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} . (.Microsoft Corporation - Contrôle ActiveX pour le flux vidéo.) -- F:\WINDOWS\system32\msvidctl.dll
O18 - Handler: vbscript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- F:\WINDOWS\system32\mshtml.dll
O18 - Handler: wia - {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} . (.Microsoft Corporation - WIA Scripting Layer.) -- F:\WINDOWS\system32\wiascr.dll
O18 - Handler: wlmailhtml - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} . (.Microsoft Corporation - Windows Live Mail.) -- F:\Program Files\Windows Live\Mail\mailcomm.dll
O18 - Filter: application/octet-stream - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- F:\WINDOWS\system32\mscoree.dll
O18 - Filter: application/x-complus - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- F:\WINDOWS\system32\mscoree.dll
O18 - Filter: application/x-msdownload - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- F:\WINDOWS\system32\mscoree.dll
O18 - Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- F:\WINDOWS\system32\urlmon.dll
O18 - Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- F:\WINDOWS\system32\urlmon.dll
O18 - Filter: text/webviewhtml - {733AC4CB-F1A4-11d0-B951-00A0C90312E1} . (.Microsoft Corporation - DLL commune du shell Windows.) -- F:\WINDOWS\system32\SHELL32.dll
~ Scan Protocole Additionnel in 00mn 00s
---\\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (autorun) (O20)
O20 - Winlogon Notify: crypt32chain . (.Microsoft Corporation - Crypto API32.) -- F:\Windows\System32\crypt32.dll
O20 - Winlogon Notify: cryptnet . (.Microsoft Corporation - Crypto Network Related API.) -- F:\Windows\System32\cryptnet.dll
O20 - Winlogon Notify: cscdll . (.Microsoft Corporation - Agent réseau hors connexion.) -- F:\Windows\System32\cscdll.dll
O20 - Winlogon Notify: dimsntfy . (.Microsoft Corporation - DIMS Notification Handler.) -- F:\WINDOWS\System32\dimsntfy.dll
O20 - Winlogon Notify: ScCertProp . (.Microsoft Corporation - DLL commune de réception des notifications.) -- F:\Windows\System32\wlnotify.dll
O20 - Winlogon Notify: Schedule . (.Microsoft Corporation - DLL commune de réception des notifications.) -- F:\Windows\System32\wlnotify.dll
O20 - Winlogon Notify: sclgntfy . (.Microsoft Corporation - DLL secondaire de notification de service d.) -- F:\Windows\System32\sclgntfy.dll
O20 - Winlogon Notify: SensLogn . (.Microsoft Corporation - DLL commune de réception des notifications.) -- F:\Windows\System32\WlNotify.dll
O20 - Winlogon Notify: termsrv . (.Microsoft Corporation - DLL commune de réception des notifications.) -- F:\Windows\System32\wlnotify.dll
O20 - Winlogon Notify: WgaLogon . (.Microsoft Corporation - Windows Genuine Advantage Notification.) -- F:\Windows\System32\WgaLogon.dll
O20 - Winlogon Notify: wlballoon . (.Microsoft Corporation - DLL commune de réception des notifications.) -- F:\Windows\System32\wlnotify.dll
~ Scan Winlogon in 00mn 00s
---\\ Clé de Registre autorun ShellServiceObjectDelayLoad (SSO/SSODL) (O21)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} . (.Microsoft Corporation - Windows Portable Device Shell Service Objec.) -- F:\WINDOWS\system32\wpdshserviceobj.dll
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} . (.Microsoft Corporation - Web Site Monitor.) -- F:\WINDOWS\system32\webcheck.dll
O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} . (.Microsoft Corporation - DLL commune du shell Windows.) -- F:\WINDOWS\system32\SHELL32.dll
O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} . (.Microsoft Corporation - DLL commune du shell Windows.) -- F:\WINDOWS\system32\SHELL32.dll
O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} . (.Microsoft Corporation - Objet du service d'environnement Systray.) -- F:\WINDOWS\system32\stobject.dll
~ Scan SSODL in 00mn 00s
---\\ Clé de Registre autorun SharedTaskScheduler (STS) (O22)
O22 - SharedTaskScheduler: (no name) - {438755C2-A8BA-11D1-B96B-00A0C90312E1} . (.Microsoft Corporation - Bibliothèque de l'interface utilisateur du.) -- F:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: (no name) - {8C7461EF-2B13-11d2-BE35-3078302C2030} . (.Microsoft Corporation - Bibliothèque de l'interface utilisateur du.) -- F:\WINDOWS\system32\browseui.dll
~ Scan STS/SSO in 00mn 00s
---\\ Liste des services NT non Microsoft et non désactivés (O23)
O23 - Service: Apple Mobile Device (Apple Mobile Device) . (.Apple Inc. - Apple Mobile Device Service.) - F:\Program Files\Fichiers communs\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: avast! Antivirus (avast! Antivirus) . (.ALWIL Software - avast! Service.) - F:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Firewall (avast! Firewall) . (.ALWIL Software - avast! firewall service.) - F:\Program Files\Alwil Software\Avast5\afwServ.exe
O23 - Service: Service Bonjour (Bonjour Service) . (.Apple Inc. - Bonjour Service.) - F:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: (MBAMService) . (.Malwarebytes Corporation - Malwarebytes' Anti-Malware.) - F:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
~ Scan Services in 00mn 00s
---\\ Enumération Active Desktop & MHTML Editor (O24)
O24 - Default MHTML Editor: Last - .(...) - (.not file.)
~ Scan Desktop Component in 00mn 00s
---\\ Tâches planifiées en automatique (O39)
O39 - APT:Automatic Planified Task - F:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[MD5.187E0D2AB859AD03393DDD731076BE81] [APT] [AppleSoftwareUpdate] (.Apple Inc..) -- F:\Program Files\Apple Software Update\SoftwareUpdate.exe
~ Scan Scheduled Task in 00mn 00s
---\\ Pilotes lancés au démarrage (O41)
O41 - Driver: (AFD) . (.Microsoft Corporation - Ancillary Function Driver for WinSock.) - F:\WINDOWS\system32\drivers\afd.sys
O41 - Driver: (Cdrom) . (.Microsoft Corporation - SCSI CD-ROM Driver.) - F:\WINDOWS\system32\DRIVERS\cdrom.sys
O41 - Driver: (i8042prt) . (.Microsoft Corporation - Pilote de port i8042.) - F:\WINDOWS\system32\DRIVERS\i8042prt.sys
O41 - Driver: (Imapi) . (.Microsoft Corporation - IMAPI Kernel Driver.) - F:\WINDOWS\system32\DRIVERS\imapi.sys
O41 - Driver: (intelppm) . (.Microsoft Corporation - Pilote de périphérique processeur.) - F:\WINDOWS\system32\DRIVERS\intelppm.sys
O41 - Driver: (IPSec) . (.Microsoft Corporation - IPSec Driver.) - F:\WINDOWS\system32\DRIVERS\ipsec.sys
O41 - Driver: (Kbdclass) . (.Microsoft Corporation - Pilote de la classe Clavier.) - F:\WINDOWS\system32\DRIVERS\kbdclass.sys
O41 - Driver: (Mouclass) . (.Microsoft Corporation - Pilote de la classe Souris.) - F:\WINDOWS\system32\DRIVERS\mouclass.sys
O41 - Driver: (MRxSmb) . (.Microsoft Corporation - Windows NT SMB Minirdr.) - F:\WINDOWS\system32\DRIVERS\mrxsmb.sys
O41 - Driver: (NetBIOS) . (.Microsoft Corporation - NetBIOS interface driver.) - F:\WINDOWS\system32\DRIVERS\netbios.sys
O41 - Driver: (NetBT) . (.Microsoft Corporation - MBT Transport driver.) - F:\WINDOWS\system32\DRIVERS\netbt.sys
O41 - Driver: (RasAcd) . (.Microsoft Corporation - RAS Automatic Connection Driver.) - F:\WINDOWS\system32\DRIVERS\rasacd.sys
O41 - Driver: (Rdbss) . (.Microsoft Corporation - Redirected Drive Buffering SubSystem Driver.) - F:\WINDOWS\system32\DRIVERS\rdbss.sys
O41 - Driver: (RDPCDD) . (.Microsoft Corporation - RDP Miniport.) - F:\WINDOWS\system32\DRIVERS\RDPCDD.sys
O41 - Driver: (redbook) . (.Microsoft Corporation - Pilote de filtre audio Livre rouge.) - F:\WINDOWS\system32\DRIVERS\redbook.sys
O41 - Driver: (Tcpip) . (.Microsoft Corporation - TCP/IP Protocol Driver.) - F:\WINDOWS\system32\DRIVERS\tcpip.sys
O41 - Driver: (TermDD) . (.Microsoft Corporation - Terminal Server Driver.) - F:\WINDOWS\system32\DRIVERS\termdd.sys
O41 - Driver: (VgaSave) . (.Microsoft Corporation - VGA/Super VGA Video Driver.) - F:\WINDOWS\system32\drivers\vga.sys
~ Scan Drivers in 00mn 00s
---\\ Logiciels installés (O42)
O42 - Logiciel: Adobe Flash Player 10 ActiveX - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player ActiveX
O42 - Logiciel: Adobe Shockwave Player 11.5 - (.Adobe Systems, Inc..) [HKLM] -- Adobe Shockwave Player
O42 - Logiciel: Archiveur WinRAR - (.Pas de propriétaire.) [HKLM] -- WinRAR archiver
O42 - Logiciel: FileZilla (remove only) - (.Pas de propriétaire.) [HKLM] -- FileZilla
O42 - Logiciel: Google Toolbar for Internet Explorer - (.Google Inc..) [HKLM] -- {2318C2B1-4965-11d4-9B18-009027A5CD4F}
O42 - Logiciel: HashTab 1.14 for x32 - (.Cody Batt.) [HKLM] -- HashTab
O42 - Logiciel: Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) - (.Microsoft Corporation.) [HKLM] -- {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB953595
O42 - Logiciel: Hotfix for Windows XP (KB954550-v5) - (.Microsoft Corporation.) [HKLM] -- KB954550-v5
O42 - Logiciel: Installation Windows Live - (.Microsoft Corporation.) [HKLM] -- WinLiveSuite_Wave3
O42 - Logiciel: InterActual Player - (.Pas de propriétaire.) [HKLM] -- InterActual Player
O42 - Logiciel: K-Lite Codec Pack 4.1.4 (Full) - (.Pas de propriétaire.) [HKLM] -- KLiteCodecPack_is1
O42 - Logiciel: Kels' Vista CPL Bonus Pack! - (.Kelsenellenelvian EverDawn.) [HKLM] -- CPLBonus
O42 - Logiciel: Logiciel WebCam de Labtec - (.Labtec, Inc..) [HKLM] -- {BF45F502-D3F2-4E7C-91D8-9AA5A8141D08}
O42 - Logiciel: Malwarebytes' Anti-Malware version 1.51.1.1800 - (.Malwarebytes Corporation.) [HKLM] -- Malwarebytes' Anti-Malware_is1
O42 - Logiciel: Messenger Plus! Live - (.Patchou.) [HKLM] -- Messenger Plus! Live
O42 - Logiciel: Microsoft .NET Framework 1.1 - (.Pas de propriétaire.) [HKLM] -- Microsoft .NET Framework 1.1 (1033)
O42 - Logiciel: Microsoft .NET Framework 3.5 SP1 - (.Microsoft Corporation.) [HKLM] -- Microsoft .NET Framework 3.5 SP1
O42 - Logiciel: Module linguistique Microsoft .NET Framework 3.5 SP1- fra - (.Microsoft Corporation.) [HKLM] -- Microsoft .NET Framework 3.5 Language Pack SP1 - fra
O42 - Logiciel: Nero 8 Lite 8.3.2.1 - (.Updatepack.nl.) [HKLM] -- Nero8Lite_is1
O42 - Logiciel: Notepad++ - (.Pas de propriétaire.) [HKLM] -- Notepad++
O42 - Logiciel: Notification de cadeaux MSN - (.Microsoft.) [HKCU] -- Notification de cadeaux MSN
O42 - Logiciel: Programme de gestion Camera de Labtec® - (.Pas de propriétaire.) [HKLM] -- QcDrv
O42 - Logiciel: Realtek High Definition Audio Driver - (.Realtek Semiconductor Corp..) [HKLM] -- {F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}
O42 - Logiciel: Windows Live Safety Scanner - (.Pas de propriétaire.) [HKLM] -- Windows Live Safety Scanner
O42 - Logiciel: XML Paper Specification Shared Components Language Pack 1.0 - (.Microsoft Corporation.) [HKLM] -- XPSEPSCLP
O42 - Logiciel: avast! Internet Security - (.Alwil Software.) [HKLM] -- avast5
---\\ HKCU & HKLM Software Keys
[HKCU\Software\AC3filter]
[HKCU\Software\ACD Systems]
[HKCU\Software\ALWIL Software]
[HKCU\Software\Ad-Remover]
[HKCU\Software\Adobe]
[HKCU\Software\Ahead]
[HKCU\Software\AppDataLow\Software\Macromedia]
[HKCU\Software\AppDataLow\Software\Microsoft]
[HKCU\Software\AppDataLow\Software]
[HKCU\Software\AppDataLow]
[HKCU\Software\Apple Computer, Inc.]
[HKCU\Software\Classes]
[HKCU\Software\Cyberlink]
[HKCU\Software\DivXNetworks]
[HKCU\Software\ESET]
[HKCU\Software\FileZilla]
[HKCU\Software\GNU]
[HKCU\Software\GSpot Appliance Corp]
[HKCU\Software\Gabest]
[HKCU\Software\Google]
[HKCU\Software\HaaliMkx]
[HKCU\Software\Haali]
[HKCU\Software\HookNetwork]
[HKCU\Software\IADirectShow]
[HKCU\Software\IM Providers]
[HKCU\Software\Intel]
[HKCU\Software\InterActual Technologies]
[HKCU\Software\JavaSoft]
[HKCU\Software\Logitech]
[HKCU\Software\Macromedia]
[HKCU\Software\Malwarebytes' Anti-Malware]
[HKCU\Software\MediaInfo]
[HKCU\Software\Nero]
[HKCU\Software\Netscape]
[HKCU\Software\Paint.NET]
[HKCU\Software\Patchou]
[HKCU\Software\Policies]
[HKCU\Software\Realtek]
[HKCU\Software\Sysinternals]
[HKCU\Software\Usbfix]
[HKCU\Software\WPI]
[HKCU\Software\WinRAR SFX]
[HKCU\Software\WinRAR]
[HKCU\Software\techPowerUp]
[HKLM\Software\ACD Systems]
[HKLM\Software\ALWIL Software]
[HKLM\Software\AVAST Software]
[HKLM\Software\Adobe]
[HKLM\Software\Ahead]
[HKLM\Software\AppDataLow]
[HKLM\Software\Apple Computer, Inc.]
[HKLM\Software\Apple Inc.]
[HKLM\Software\Blimey! Games]
[HKLM\Software\C07ft5Y]
[HKLM\Software\Classes]
[HKLM\Software\Clients]
[HKLM\Software\Codec Tweak Tool]
[HKLM\Software\Cyberlink]
[HKLM\Software\DivXNetworks]
[HKLM\Software\ESET]
[HKLM\Software\GEAR Software]
[HKLM\Software\GNU]
[HKLM\Software\Gabest]
[HKLM\Software\Gemplus]
[HKLM\Software\Google]
[HKLM\Software\HaaliMkx]
[HKLM\Software\Intel]
[HKLM\Software\InterActual Technologies]
[HKLM\Software\InterVideo]
[HKLM\Software\JavaSoft]
[HKLM\Software\KLCodecPack]
[HKLM\Software\Labtec]
[HKLM\Software\Logitech]
[HKLM\Software\Macromedia]
[HKLM\Software\Malwarebytes' Anti-Malware (Trial)]
[HKLM\Software\Malwarebytes' Anti-Malware]
[HKLM\Software\MozillaPlugins]
[HKLM\Software\Nero]
[HKLM\Software\ODBC]
[HKLM\Software\Paint.NET]
[HKLM\Software\Patchou]
[HKLM\Software\Policies]
[HKLM\Software\Program Groups]
[HKLM\Software\Realtek]
[HKLM\Software\RegisteredApplications]
[HKLM\Software\S3R521]
[HKLM\Software\Schlumberger]
[HKLM\Software\Secure]
[HKLM\Software\Symantec]
[HKLM\Software\Windows 3.1 Migration Status]
[HKLM\Software\Windows]
[HKLM\Software\ZSMC]
~ Scan Softwares in 00mn 00s
---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43)
O43 - CFD: 02/08/2011 - 18:47:48 - [246426670] ----D- F:\Program Files\Ad-Remover
O43 - CFD: 02/05/2010 - 15:18:36 - [156975748] ----D- F:\Program Files\Alwil Software
O43 - CFD: 04/05/2010 - 21:32:18 - [2306366] ----D- F:\Program Files\Apple Software Update
O43 - CFD: 04/05/2010 - 21:31:06 - [599827] ----D- F:\Program Files\Bonjour
O43 - CFD: 27/07/2009 - 17:57:20 - [0] ----D- F:\Program Files\ComPlus Applications
O43 - CFD: 27/07/2009 - 18:24:38 - [636] ----D- F:\Program Files\DAEMON Tools
O43 - CFD: 03/08/2011 - 11:45:06 - [2864182046] ----D- F:\Program Files\eMule
O43 - CFD: 04/05/2010 - 21:30:48 - [521869013] ----D- F:\Program Files\Fichiers communs
O43 - CFD: 27/07/2009 - 18:21:42 - [13195686] ----D- F:\Program Files\FileZilla
O43 - CFD: 28/01/2010 - 18:43:50 - [11056722] ----D- F:\Program Files\Google
O43 - CFD: 27/07/2009 - 18:24:42 - [339641] ----D- F:\Program Files\HashTab Shell Extension
O43 - CFD: 24/08/2009 - 21:20:40 - [5868131] --H-D- F:\Program Files\InstallShield Installation Information
O43 - CFD: 01/09/2010 - 20:06:44 - [7540088] ----D- F:\Program Files\InterActual
O43 - CFD: 04/05/2010 - 21:33:26 - [2528816] ----D- F:\Program Files\Internet Explorer
O43 - CFD: 04/05/2010 - 21:34:20 - [1582707] ----D- F:\Program Files\iPod
O43 - CFD: 04/05/2010 - 21:35:08 - [126469319] ----D- F:\Program Files\iTunes
O43 - CFD: 27/07/2009 - 18:24:54 - [31791403] ----D- F:\Program Files\K-Lite Codec Pack
O43 - CFD: 24/08/2009 - 21:20:46 - [31217246] ----D- F:\Program Files\Logitech
O43 - CFD: 04/08/2011 - 10:13:32 - [6953653] ----D- F:\Program Files\Malwarebytes' Anti-Malware
O43 - CFD: 30/11/2009 - 19:46:28 - [16955760] ----D- F:\Program Files\Messenger Plus! Live
O43 - CFD: 27/07/2009 - 18:58:32 - [854520] ----D- F:\Program Files\Microsoft
O43 - CFD: 10/10/2009 - 10:18:02 - [15457915] ----D- F:\Program Files\Microsoft Silverlight
O43 - CFD: 27/07/2009 - 18:59:54 - [1829877] ----D- F:\Program Files\Microsoft SQL Server Compact Edition
O43 - CFD: 27/07/2009 - 19:00:50 - [2188837] ----D- F:\Program Files\Microsoft Sync Framework
O43 - CFD: 29/12/2009 - 01:04:56 - [25757] ----D- F:\Program Files\MSBuild
O43 - CFD: 27/07/2009 - 18:24:22 - [29849715] ----D- F:\Program Files\Nero
O43 - CFD: 27/07/2009 - 18:24:38 - [3229344] ----D- F:\Program Files\Notepad++
O43 - CFD: 27/07/2009 - 17:58:54 - [4379321] ----D- F:\Program Files\Outlook Express
O43 - CFD: 21/02/2011 - 19:33:40 - [31556567] ----D- F:\Program Files\Paint.NET
O43 - CFD: 04/05/2010 - 21:33:24 - [76384416] ----D- F:\Program Files\QuickTime
O43 - CFD: 29/12/2009 - 01:04:38 - [37895937] ----D- F:\Program Files\Reference Assemblies
O43 - CFD: 27/07/2009 - 18:25:14 - [0] --H-D- F:\Program Files\Uninstall Information
O43 - CFD: 30/01/2011 - 14:17:38 - [141956278] ----D- F:\Program Files\Windows Live
O43 - CFD: 27/07/2009 - 18:24:38 - [4486909] ----D- F:\Program Files\Windows Live Safety Center
O43 - CFD: 27/07/2009 - 18:58:14 - [245112] ----D- F:\Program Files\Windows Live SkyDrive
O43 - CFD: 27/07/2009 - 17:56:56 - [3581070] ----D- F:\Program Files\Windows Media Connect 2
O43 - CFD: 27/07/2009 - 18:00:32 - [7786090] ----D- F:\Program Files\Windows Media Player
O43 - CFD: 27/07/2009 - 18:22:10 - [12849407] R-H-D- F:\Program Files\Windows Sidebar
O43 - CFD: 27/07/2009 - 17:59:18 - [0] --H-D- F:\Program Files\WindowsUpdate
O43 - CFD: 02/05/2010 - 19:29:20 - [3436701] ----D- F:\Program Files\WinRAR
O43 - CFD: 27/07/2009 - 18:24:42 - [305664] ----D- F:\Program Files\Xtremsplit
O43 - CFD: 04/08/2011 - 18:18:32 - [18875413] ----D- F:\Program Files\ZHPDiag
O43 - CFD: 19/01/2010 - 19:46:46 - [2927736] ----D- F:\Program Files\Fichiers Communs\ACD Systems
O43 - CFD: 19/01/2010 - 19:41:14 - [0] ----D- F:\Program Files\Fichiers Communs\Adobe
O43 - CFD: 04/05/2010 - 21:34:14 - [97543967] ----D- F:\Program Files\Fichiers Communs\Apple
O43 - CFD: 24/08/2009 - 21:20:06 - [3066200] ----D- F:\Program Files\Fichiers Communs\InstallShield
O43 - CFD: 24/08/2009 - 21:21:10 - [23269453] ----D- F:\Program Files\Fichiers Communs\Logitech
O43 - CFD: 30/01/2011 - 14:14:10 - [12155072] ----D- F:\Program Files\Fichiers Communs\Microsoft Shared
O43 - CFD: 27/07/2009 - 17:58:52 - [284160] ----D- F:\Program Files\Fichiers Communs\MSSoap
O43 - CFD: 27/07/2009 - 18:24:06 - [28325498] ----D- F:\Program Files\Fichiers Communs\Nero
O43 - CFD: 27/07/2009 - 19:51:30 - [0] ----D- F:\Program Files\Fichiers Communs\ODBC
O43 - CFD: 27/07/2009 - 17:58:56 - [8106] ----D- F:\Program Files\Fichiers Communs\Services
O43 - CFD: 27/07/2009 - 17:58:38 - [6086041] ----D- F:\Program Files\Fichiers Communs\System
O43 - CFD: 27/07/2009 - 18:46:58 - [348202780] ----D- F:\Program Files\Fichiers Communs\Windows Live
O43 - CFD: 08/08/2009 - 16:17:26 - [0] ----D- F:\Documents and Settings\K'2sy\Application Data\ACD Systems
O43 - CFD: 13/12/2010 - 22:13:28 - [2129134] ----D- F:\Documents and Settings\K'2sy\Application Data\Adobe
O43 - CFD: 26/07/2010 - 06:18:42 - [277497] ----D- F:\Documents and Settings\K'2sy\Application Data\Apple Computer
O43 - CFD: 27/07/2009 - 18:21:38 - [0] ----D- F:\Documents and Settings\K'2sy\Application Data\ESET
O43 - CFD: 28/01/2010 - 18:44:26 - [0] ----D- F:\Documents and Settings\K'2sy\Application Data\Google
O43 - CFD: 27/07/2009 - 18:25:22 - [0] ----D- F:\Documents and Settings\K'2sy\Application Data\Identities
O43 - CFD: 13/12/2010 - 22:13:26 - [6403024] ----D- F:\Documents and Settings\K'2sy\Application Data\Macromedia
O43 - CFD: 04/08/2011 - 10:13:36 - [8099166] ----D- F:\Documents and Settings\K'2sy\Application Data\Malwarebytes
O43 - CFD: 03/11/2009 - 18:36:16 - [107] ----D- F:\Documents and Settings\K'2sy\Application Data\Media Player Classic
O43 - CFD: 03/08/2011 - 13:17:52 - [3095487] -S--D- F:\Documents and Settings\K'2sy\Application Data\Microsoft
O43 - CFD: 15/11/2009 - 17:20:24 - [134309] ----D- F:\Documents and Settings\K'2sy\Application Data\Nero
O43 - CFD: 07/08/2009 - 21:36:10 - [100636] ----D- F:\Documents and Settings\K'2sy\Application Data\Notepad++
O43 - CFD: 19/01/2010 - 19:33:58 - [11442634] ----D- F:\Documents and Settings\K'2sy\Application Data\OpenOffice.org
O43 - CFD: 26/07/2010 - 17:08:08 - [0] ----D- F:\Documents and Settings\K'2sy\Application Data\report
O43 - CFD: 27/09/2009 - 13:17:16 - [993] ----D- F:\Documents and Settings\K'2sy\Application Data\Sun
O43 - CFD: 02/09/2009 - 18:42:38 - [0] ----D- F:\Documents and Settings\K'2sy\Application Data\WinRAR
O43 - CFD: 23/11/2009 - 18:41:20 - [4041916] ----D- F:\Documents and Settings\K'2sy\Local Settings\Application Data\ACD Systems
O43 - CFD: 19/01/2010 - 19:41:00 - [47338898] ----D- F:\Documents and Settings\K'2sy\Local Settings\Application Data\Adobe
O43 - CFD: 04/05/2010 - 21:32:22 - [0] ----D- F:\Documents and Settings\K'2sy\Local Settings\Application Data\Apple
O43 - CFD: 04/05/2010 - 21:35:54 - [14175887] ----D- F:\Documents and Settings\K'2sy\Local Settings\Application Data\Apple Computer
O43 - CFD: 28/01/2010 - 18:44:30 - [161808] ----D- F:\Documents and Settings\K'2sy\Local Settings\Application Data\Google
O43 - CFD: 14/11/2009 - 13:39:34 - [161360] ----D- F:\Documents and Settings\K'2sy\Local Settings\Application Data\Identities
O43 - CFD: 03/08/2011 - 13:15:02 - [796079673] -S--D- F:\Documents and Settings\K'2sy\Local Settings\Application Data\Microsoft
O43 - CFD: 21/02/2011 - 22:27:20 - [0] ----D- F:\Documents and Settings\K'2sy\Local Settings\Application Data\Paint.NET
~ Scan Program Folder in 00mn 13s
---\\ Derniers fichiers modifiés ou crées sous Windows et System32 (O44)
O44 - LFC:[MD5.1AFDB3C2495B06CF819783568B26158B] - 04/08/2011 - 17:18:29 ---A- . (...) -- F:\WINDOWS\WindowsUpdate.log [1191189]
O44 - LFC:[MD5.C04D1CDDCA5B495C29F4B984BA64EF17] - 04/08/2011 - 17:17:59 ---A- . (...) -- F:\Program [40]
O44 - LFC:[MD5.5ACF1477920114C74E4541E4F0777D5B] - 04/08/2011 - 17:16:07 ---A- . (...) -- F:\PhysicalDisk0_MBR.bin [512]
O44 - LFC:[MD5.D41D8CD98F00B204E9800998ECF8427E] - 04/08/2011 - 17:11:41 ---A- . (...) -- F:\WINDOWS\0.log [0]
O44 - LFC:[MD5.9EC644D0CDAD3E00F7649435C467D913] - 04/08/2011 - 17:11:36 ---A- . (...) -- F:\WINDOWS\wiadebug.log [159]
O44 - LFC:[MD5.63F45FD146150D602220DF339332211E] - 04/08/2011 - 17:11:36 ---A- . (...) -- F:\WINDOWS\wiaservc.log [50]
O44 - LFC:[MD5.6A2CB42966136854F4464516FBB4AE72] - 04/08/2011 - 17:11:12 -S-A- . (...) -- F:\WINDOWS\bootstat.dat [2048]
O44 - LFC:[MD5.078B2516FAD5FB16A7BD201E26381DF8] - 04/08/2011 - 10:44:34 ---A- . (...) -- F:\WINDOWS\SchedLgU.Txt [32514]
O44 - LFC:[MD5.45EE0C5238459EF1A890E261597B1E89] - 03/08/2011 - 16:32:52 ---A- . (...) -- F:\UsbFix.txt [1422]
O44 - LFC:[MD5.06F541AD5ADF449ECE140E5EE17DE0AA] - 03/08/2011 - 16:25:29 ---A- . (...) -- F:\WINDOWS\setupapi.log [128870]
O44 - LFC:[MD5.09C1010AC098329917C04329832FFA59] - 03/08/2011 - 12:29:34 ---A- . (...) -- F:\ZHPExportRegistry-03-08-2011-13-29-34.txt [1742]
O44 - LFC:[MD5.09C1010AC098329917C04329832FFA59] - 03/08/2011 - 12:24:02 ---A- . (...) -- F:\ZHPExportRegistry-03-08-2011-13-24-02.txt [1742]
O44 - LFC:[MD5.1462F5923F9325B5AF2EB81BC7A638BB] - 03/08/2011 - 12:18:55 ---A- . (...) -- F:\ZHPExportRegistry-03-08-2011-13-18-55.txt [34590]
O44 - LFC:[MD5.5DCEF3451EF3FEB92081B3EA6A04F92A] - 02/08/2011 - 19:27:46 ---A- . (...) -- F:\Ad-Report-CLEAN[1].txt [15648]
O44 - LFC:[MD5.C9F7EB4EE0B8BC1DEE83655079B54B94] - 02/08/2011 - 19:20:08 ---A- . (...) -- F:\WINDOWS\system32\d3d9caps.dat [664]
O44 - LFC:[MD5.D524F808E22108CE082A64562D19D1B6] - 02/08/2011 - 17:50:03 ---A- . (...) -- F:\Ad-Report-SCAN[1].txt [17347]
O44 - LFC:[MD5.480D4F5BE08B7AAEB7E50602220CA934] - 02/08/2011 - 17:07:44 ---A- . (...) -- F:\WINDOWS\system32\wpa.dbl [2184]
O44 - LFC:[MD5.F966564A5746B55682319F306378556C] - 26/07/2011 - 19:41:38 ---A- . (...) -- F:\WINDOWS\system32\PerfStringBackup.INI [1115830]
O44 - LFC:[MD5.EA4B26057CF33037B624BF8048DFCDCF] - 26/07/2011 - 19:41:38 ---A- . (...) -- F:\WINDOWS\system32\perfc009.dat [70930]
O44 - LFC:[MD5.944191CC72DAF773BA08818007B4BE73] - 26/07/2011 - 19:41:38 ---A- . (...) -- F:\WINDOWS\system32\perfc00C.dat [84070]
O44 - LFC:[MD5.93447A52BDB75C75F52287087B1984A8] - 26/07/2011 - 19:41:38 ---A- . (...) -- F:\WINDOWS\system32\perfh009.dat [439946]
O44 - LFC:[MD5.CDD22576F2D2E851FCE503F1497EC612] - 26/07/2011 - 19:41:38 ---A- . (...) -- F:\WINDOWS\system32\perfh00C.dat [508976]
O44 - LFC:[MD5.ECA00EED9AB95489007B0EF84C7149DE] - 06/07/2011 - 18:52:42 ---A- . (.Malwarebytes Corporation - Malwarebytes' Anti-Malware.) -- F:\WINDOWS\system32\drivers\mbam.sys [22712]
O44 - LFC:[MD5.B18225739ED9CAA83BA2DF966E9F43E8] - 06/07/2011 - 18:52:42 ---A- . (.Malwarebytes Corporation - Malwarebytes' Anti-Malware.) -- F:\WINDOWS\system32\drivers\mbamswissarmy.sys [41272]
~ Scan Files in 00mn 04s
---\\ Export de clé d'application autorisée (O47)
O47 - AAKE:Key Export SP - "%windir%\Network Diagnostic\xpnetdiag.exe" [Enabled] .(.Microsoft Corporation - Network Diagnostic for Windows XP.) -- F:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O47 - AAKE:Key Export SP - "%windir%\system32\sessmgr.exe" [Enabled] .(.Microsoft Corporation - Gestionnaire de session de l'aide sur le Bureau à distance de Microsoft®.) -- F:\WINDOWS\system32\sessmgr.exe
O47 - AAKE:Key Export SP - "F:\Program Files\eMule\emule.exe" [Disabled] .(...) -- F:\Program Files\eMule\emule.exe (.not file.)
O47 - AAKE:Key Export SP - "F:\Program Files\Bonjour\mDNSResponder.exe" [Enabled] .(.Apple Inc. - Bonjour Service.) -- F:\Program Files\Bonjour\mDNSResponder.exe
O47 - AAKE:Key Export SP - "F:\Program Files\iTunes\iTunes.exe" [Enabled] .(.Apple Inc. - iTunes.) -- F:\Program Files\iTunes\iTunes.exe
O47 - AAKE:Key Export SP - "F:\Program Files\Windows Live\Messenger\msnmsgr.exe" [Enabled] .(.Microsoft Corporation - Windows Live Messenger.) -- F:\Program Files\Windows Live\Messenger\msnmsgr.exe
O47 - AAKE:Key Export SP - "F:\Program Files\Windows Live\Sync\WindowsLiveSync.exe" [Enabled] .(.Microsoft Corporation - Windows Live Sync.) -- F:\Program Files\Windows Live\Sync\WindowsLiveSync.exe
O47 - AAKE:Key Export DP - "%windir%\Network Diagnostic\xpnetdiag.exe" [Enabled] .(.Microsoft Corporation - Network Diagnostic for Windows XP.) -- F:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O47 - AAKE:Key Export DP - "%windir%\system32\sessmgr.exe" [Enabled] .(.Microsoft Corporation - Gestionnaire de session de l'aide sur le Bureau à distance de Microsoft®.) -- F:\WINDOWS\system32\sessmgr.exe
O47 - AAKE:Key Export DP - "F:\Program Files\Windows Live\Messenger\msnmsgr.exe" [Enabled] .(.Microsoft Corporation - Windows Live Messenger.) -- F:\Program Files\Windows Live\Messenger\msnmsgr.exe
O47 - AAKE:Key Export DP - "F:\Program Files\Windows Live\Sync\WindowsLiveSync.exe" [Enabled] .(.Microsoft Corporation - Windows Live Sync.) -- F:\Program Files\Windows Live\Sync\WindowsLiveSync.exe
~ Scan Keys in 00mn 00s
---\\ Contrôle du Safe Boot (CSB) (O49)
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\dmboot.sys . (.Microsoft Corp., Veritas Software - Pilote de démarrage du gestionnaire de disque NT.) -- F:\WINDOWS\system32\Drivers\dmboot.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\dmio.sys . (.Microsoft Corp., Veritas Software - Pilote E/S du Gestionnaire de disques NT.) -- F:\WINDOWS\system32\Drivers\dmio.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\dmload.sys . (.Microsoft Corp., Veritas Software. - NT Disk Manager Startup Driver.) -- F:\WINDOWS\system32\Drivers\dmload.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\sermouse.sys . (...) -- F:\WINDOWS\system32\Drivers\sermouse.sys (.not file.)
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\sr.sys . (.Microsoft Corporation - Pilote de filtre de système de fichiers pour la restauration du système.) -- F:\WINDOWS\system32\Drivers\sr.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\vga.sys . (.Microsoft Corporation - VGA/Super VGA Video Driver.) -- F:\WINDOWS\system32\Drivers\vga.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\vgasave.sys . (...) -- F:\WINDOWS\system32\Drivers\vgasave.sys (.not file.)
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\dmboot.sys . (.Microsoft Corp., Veritas Software - Pilote de démarrage du gestionnaire de disque NT.) -- F:\WINDOWS\system32\Drivers\dmboot.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\dmio.sys . (.Microsoft Corp., Veritas Software - Pilote E/S du Gestionnaire de disques NT.) -- F:\WINDOWS\system32\Drivers\dmio.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\dmload.sys . (.Microsoft Corp., Veritas Software. - NT Disk Manager Startup Driver.) -- F:\WINDOWS\system32\Drivers\dmload.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\ip6fw.sys . (.Microsoft Corporation - IPv6 Windows Firewall Driver.) -- F:\WINDOWS\system32\Drivers\ip6fw.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\ipnat.sys . (.Microsoft Corporation - IP Network Address Translator.) -- F:\WINDOWS\system32\Drivers\ipnat.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\rdpcdd.sys . (.Microsoft Corporation - RDP Miniport.) -- F:\WINDOWS\system32\Drivers\rdpcdd.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\rdpdd.sys . (...) -- F:\WINDOWS\system32\Drivers\rdpdd.sys (.not file.)
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\rdpwd.sys . (.Microsoft Corporation - RDP Terminal Stack Driver (US/Canada Only, Not for Export).) -- F:\WINDOWS\system32\Drivers\rdpwd.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\sermouse.sys . (...) -- F:\WINDOWS\system32\Drivers\sermouse.sys (.not file.)
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\sr.sys . (.Microsoft Corporation - Pilote de filtre de système de fichiers pour la restauration du système.) -- F:\WINDOWS\system32\Drivers\sr.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\tdpipe.sys . (.Microsoft Corporation - Named Pipe Transport Driver.) -- F:\WINDOWS\system32\Drivers\tdpipe.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\tdtcp.sys . (.Microsoft Corporation - TCP Transport Driver.) -- F:\WINDOWS\system32\Drivers\tdtcp.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\vga.sys . (.Microsoft Corporation - VGA/Super VGA Video Driver.) -- F:\WINDOWS\system32\Drivers\vga.sys
O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\vgasave.sys . (...) -- F:\WINDOWS\system32\Drivers\vgasave.sys (.not file.)
~ Scan CSB in 00mn 00s
---\\ Image File Execution Options (IFEO) (O50)
O50 - IFEO:Image File Execution Options - Your Image File Name Here without a path - ntsd -d
~ Scan IFEO in 00mn 00s
---\\ MountPoints2 Shell Key (O51)
O51 - MPSK:{35d1b7f2-051d-11df-8ded-000fb0d6668e}\AutoRun\command - Clé orpheline
~ Scan Keys in 00mn 00s
---\\ Trojan Driver Search Data (HKLM) (O52)
O52 - TDSD: \Drivers32\"msacm.trspch"="tssoft32.acm" . (.DSP GROUP, INC. - Codec audio TrueSpeech(TM) DSP Group pour MSACM V3.50.) -- F:\WINDOWS\system32\tssoft32.acm
O52 - TDSD: \Drivers32\"vidc.cvid"="iccvid.dll" . (.Radius Inc. - Cinepak® Codec.) -- F:\WINDOWS\system32\iccvid.dll
O52 - TDSD: \Drivers32\"VIDC.I420"="lvcodec2.dll" . (.Labtec Inc. - Video Codec.) -- F:\WINDOWS\system32\lvcodec2.dll
O52 - TDSD: \Drivers32\"vidc.iv31"="ir32_32.dll" . (...) -- F:\WINDOWS\system32\ir32_32.dll
O52 - TDSD: \Drivers32\"vidc.iv32"="ir32_32.dll" . (...) -- F:\WINDOWS\system32\ir32_32.dll
O52 - TDSD: \Drivers32\"vidc.iv41"="ir41_32.ax" . (.Intel Corporation - Intel Indeo® Video 4.5.) -- F:\WINDOWS\system32\ir41_32.ax
O52 - TDSD: \Drivers32\"msacm.sl_anet"="sl_anet.acm" . (.Sipro Lab Telecom Inc. - Audio codec for MS ACM.) -- F:\WINDOWS\system32\sl_anet.acm
O52 - TDSD: \Drivers32\"msacm.iac2"="F:\WINDOWS\system32\iac25_32.ax" . (.Intel Corporation - Indeo® audio software.) -- F:\WINDOWS\system32\iac25_32.ax
O52 - TDSD: \Drivers32\"vidc.iv50"="ir50_32.dll" . (.Intel Corporation - Intel Indeo® video 5.10.) -- F:\WINDOWS\system32\ir50_32.dll
O52 - TDSD: \Drivers32\"msacm.l3acm"="F:\WINDOWS\system32\l3codeca.acm" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Layer-3 Audio Codec for MSACM.) -- F:\WINDOWS\system32\l3codeca.acm
O52 - TDSD: \Drivers32\"VIDC.ACDV"="ACDV.dll" . (...) -- (.not file.)
O52 - TDSD: \Drivers32\"VIDC.DIVX"="divx.dll" . (.DivX, Inc. - DivX.) -- F:\WINDOWS\system32\divx.dll
O52 - TDSD: \Drivers32\"VIDC.XVID"="xvidvfw.dll" . (...) -- F:\WINDOWS\system32\xvidvfw.dll
O52 - TDSD: \Drivers32\"VIDC.YV12"="yv12vfw.dll" . (.www.helixcommunity.org - Helix YV12 YUV Codec.) -- F:\WINDOWS\system32\yv12vfw.dll
O52 - TDSD: \Drivers32\"msacm.ac3acm"="ac3acm.acm" . (.fccHandler - AC-3 ACM Codec.) -- F:\WINDOWS\system32\ac3acm.acm
O52 - TDSD: \Drivers32\"msacm.lameacm"="lameACM.acm" . (.http://www.mp3dev.org/ - Lame MP3 codec engine.) -- F:\WINDOWS\system32\lameACM.acm
O52 - TDSD: \Drivers32\"VIDC.FFDS"="ff_vfw.dll" . (...) -- F:\WINDOWS\system32\ff_vfw.dll
O52 - TDSD: \drivers.desc\"sl_anet.acm"="Sipro Lab Telecom Audio Codec" . (.Sipro Lab Telecom Inc. - Audio codec for MS ACM.) -- F:\WINDOWS\system32\sl_anet.acm
O52 - TDSD: \drivers.desc\"F:\WINDOWS\system32\iac25_32.ax"="Indeo® audio software" . (.Intel Corporation - Indeo® audio software.) -- F:\WINDOWS\system32\iac25_32.ax
O52 - TDSD: \drivers.desc\"ir50_32.dll"="Indeo® video 5.10" . (...) -- (.not file.)
O52 - TDSD: \drivers.desc\"F:\WINDOWS\system32\l3codeca.acm"="Fraunhofer IIS MPEG Layer-3 Codec" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Layer-3 Audio Codec for MSACM.) -- F:\WINDOWS\system32\l3codeca.acm
O52 - TDSD: \drivers.desc\"ACDV.dll"="ACDV 1.0" . (...) -- (.not file.)
O52 - TDSD: \drivers.desc\"divx.dll"="DivX 6.8.4" . (...) -- (.not file.)
O52 - TDSD: \drivers.desc\"xvidvfw.dll"="Xvid MPEG-4 Video Codec v1.2-dev" . (...) -- (.not file.)
O52 - TDSD: \drivers.desc\"lameACM.acm"="Lame ACM MP3 CODEC v3.98" . (...) -- (.not file.)
O52 - TDSD: \drivers.desc\"ac3acm.acm"="AC-3 ACM Codec" . (.fccHandler - AC-3 ACM Codec.) -- F:\WINDOWS\system32\ac3acm.acm
O52 - TDSD: \drivers.desc\"ff_vfw.dll"="ffdshow video encoder" . (...) -- F:\WINDOWS\system32\ff_vfw.dll
O52 - TDSD: \drivers.desc\"ir32_32.dll"="Indeo® video R3.2 by Intel" . (...) -- (.not file.)
O52 - TDSD: \drivers.desc\"ir41_32.ax"="Indeo® video interactive R4.3 by Intel" . (...) -- (.not file.)
O52 - TDSD: \drivers.desc\"iyvu9_32.dll"="Indeo® video Raw YVU9 by Intel" . (...) -- F:\WINDOWS\system32\iyvu9_32.dll
~ Scan Keys in 00mn 00s
---\\ Microsoft Control Security Providers (O54)
O54 - MCSP:[HKLM\...\CurrentControlSet\Control] - (SecurityProviders) - (.Microsoft Corporation - Client DPA pour plate-forme 32 bit.) -- F:\WINDOWS\system32\msapsspc.dll
O54 - MCSP:[HKLM\...\CurrentControlSet\Control] - (SecurityProviders) - (.Microsoft Corporation - TLS / SSL Security Provider.) -- F:\WINDOWS\system32\schannel.dll
O54 - MCSP:[HKLM\...\CurrentControlSet\Control] - (SecurityProviders) - (.Microsoft Corporation - Package d'authentification Digest SSPI.) -- F:\WINDOWS\system32\digest.dll
O54 - MCSP:[HKLM\...\ControlSet001\Control] - (SecurityProviders) - (.Microsoft Corporation - Client DPA pour plate-forme 32 bit.) -- F:\WINDOWS\system32\msapsspc.dll
O54 - MCSP:[HKLM\...\ControlSet001\Control] - (SecurityProviders) - (.Microsoft Corporation - TLS / SSL Security Provider.) -- F:\WINDOWS\system32\schannel.dll
O54 - MCSP:[HKLM\...\ControlSet001\Control] - (SecurityProviders) - (.Microsoft Corporation - Package d'authentification Digest SSPI.) -- F:\WINDOWS\system32\digest.dll
~ Scan Keys in 00mn 00s
---\\ Microsoft Windows Policies System (O55)
O55 - MWPS:[HKLM\...\Policies\System] - "dontdisplaylastusername"=0
O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticecaption"=
O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticetext"=
O55 - MWPS:[HKLM\...\Policies\System] - "shutdownwithoutlogon"=1
O55 - MWPS:[HKLM\...\Policies\System] - "undockwithoutlogon"=1
~ Scan Keys in 00mn 00s
---\\ Microsoft Windows Policies Explorer (O56)
O56 - MWPE:[HKCU\...\policies\Explorer] - "NoDriveTypeAutoRun"=0
O56 - MWPE:[HKCU\...\policies\Explorer] - "NoDriveAutoRun"=3
O56 - MWPE:[HKLM\...\policies\Explorer] - "NoDesktopCleanupWizard"=1
O56 - MWPE:[HKLM\...\policies\Explorer] - "NoDriveAutoRun"=3
O56 - MWPE:[HKLM\...\policies\Explorer] - "NoDriveTypeAutoRun"=0
~ Scan Keys in 00mn 00s
---\\ Liste des Drivers Système (O58)
O58 - SDL:[MD5.94321612E022BAED249BF6BC2B9DDF9E] - 04/08/2011 - 17:30:45 ---A- . (.ALWIL Software - avast! Base Kernel-Mode Device Driver for Windows NT/2000/XP.) -- F:\WINDOWS\system32\drivers\aavmker4.sys [28880]
O58 - SDL:[MD5.31FFDE1BE912D7CBD3F189FEB61F86B6] - 04/08/2011 - 23:57:00 ---A- . (.Advanced Micro Devices - AMD Processor Driver.) -- F:\WINDOWS\system32\drivers\amdk8.sys [43520]
O58 - SDL:[MD5.033448D435E65C4BD72E70521FD05C76] - 04/08/2011 - 23:57:00 ---A- . (.Advanced Micro Devices - AMD Processor Driver.) -- F:\WINDOWS\system32\drivers\amdppm.sys [33792]
O58 - SDL:[MD5.7F7135C14ED4FB190AA75CB1FD1F14E8] - 04/08/2011 - 17:31:01 ---A- . (.ALWIL Software - avast! File System Access Blocking Driver.) -- F:\WINDOWS\system32\drivers\aswFsBlk.sys [19024]
O58 - SDL:[MD5.B77C214FC6CC6F4FE9DE0AA7058577CA] - 04/08/2011 - 17:37:30 ---A- . (.ALWIL Software - avast! Filtering TDI driver.) -- F:\WINDOWS\system32\drivers\aswFW.sys [102736]
O58 - SDL:[MD5.098E3A9FFAE8CA693FAE7229F6E659B7] - 04/08/2011 - 17:31:09 ---A- . (.ALWIL Software - avast! File System Filter Driver for Windows NT/2000.) -- F:\WINDOWS\system32\drivers\aswmon.sys [94800]
O58 - SDL:[MD5.71A24FC1564C39CF834ACEC3396577E6] - 04/08/2011 - 17:31:12 ---A- . (.ALWIL Software - avast! File System Filter Driver for Windows XP.) -- F:\WINDOWS\system32\drivers\aswmon2.sys [100432]
O58 - SDL:[MD5.7B948E3657BEA62E437BC46CA6EF6012] - 04/08/2011 - 20:10:13 ---A- . (.ALWIL Software - avast! Filtering NDIS driver.) -- F:\WINDOWS\system32\drivers\aswNdis.sys [12112]
O58 - SDL:[MD5.64EFF838959FAA8C2A63EAA82214EC6F] - 04/08/2011 - 17:36:53 ---A- . (.ALWIL Software - avast! Filtering NDIS driver.) -- F:\WINDOWS\system32\drivers\aswNdis2.sys [196048]
O58 - SDL:[MD5.9A2F01E6BCECE7A1A1F39846E392CD41] - 04/08/2011 - 17:31:39 ---A- . (.ALWIL Software - avast! TDI RDR Driver.) -- F:\WINDOWS\system32\drivers\aswRdr.sys [23376]
O58 - SDL:[MD5.D82E45FBEA7C0668ABAB2F893A5E290B] - 04/08/2011 - 17:37:13 ---A- . (.ALWIL Software - avast! Virtualization Driver.) -- F:\WINDOWS\system32\drivers\aswSnx.sys [297552]
O58 - SDL:[MD5.7DF85E2E544B505EE74D734A394E39C7] - 04/08/2011 - 17:35:25 ---A- . (.ALWIL Software - avast! self protection module.) -- F:\WINDOWS\system32\drivers\aswSP.sys [162768]
O58 - SDL:[MD5.9E82102B7249EF33A1CC132F26AFEAC4] - 04/08/2011 - 17:35:47 ---A- . (.ALWIL Software - avast! TDI Filter Driver.) -- F:\WINDOWS\system32\drivers\aswTdi.sys [46672]
O58 - SDL:[MD5.3003C21E5E1F04BA84FC8E705A65DB2B] - 04/08/2011 - 23:59:21 ---A- . (.Broadcom Corporation - Broadcom 802.11 Network Adapter wireless driver.) -- F:\WINDOWS\system32\drivers\BCMWL5.SYS [564224]
O58 - S -
Contributeur sécurité
-
-
Contributeur sécuritéOk.
>Copie les lignes "helpers" (Avec Ctrl + C) :
--------------------------------------------
O47 - AAKE:Key Export SP - "F:\Program Files\Bonjour\mDNSResponder.exe" [Enabled] .(.Apple Inc. - Bonjour Service.) -- F:\Program Files\Bonjour\mDNSResponder.exe
[HKLM\Software\Classes\CLSID\{1a03f196-9617-4ca0-842b-a83ceecb022b}] => Toolbar.SweetIM
EmptyTemp
EmptyFlash
SysRestore
--------------------------------------------
>Ouvre ZHPfix, icone seringue (Vista et 7 : "Exécuter en tant qu'administrateur").
>Colle les lignes helpers : Pour ce, clique sur la balise document, à droite de l'appareil photo. Ou alors sur le H.
>Faire Ok.
>Clique sur "Tous".
>Clique sur "Nettoyer".
>Copie le rapport, et coller-le dans la prochaine réponse sur le forum.
Si tu as des questions, n'hésite pas à me les poser !
Et aussi désinstalle Emule ;)
Merci,
Gabriel.
-
Rapport de ZHPFix 1.12.3345 par Nicolas Coolman, Update du 29/07/2011
Fichier d'export Registre : F:\ZHPExportRegistry-05-08-2011-14-18-51.txt
Run by K'2sy at 05/08/2011 14:18:51
Windows XP Professional Service Pack 3 (Build 2600)
Web site : http://www.premiumorange.com/zeb-help-process/zhpfix.html
========== Clé(s) du Registre ==========
SUPPRIME Key: HKLM\Software\Classes\CLSID\{1a03f196-9617-4ca0-842b-a83ceecb022b}
========== Valeur(s) du Registre ==========
SUPPRIME AAKE KeyValue: F:\Program Files\Bonjour\mDNSResponder.exe
========== Dossier(s) ==========
SUPPRIME Temporaires Windows: : 6
SUPPRIME Flash Cookies: 1
========== Fichier(s) ==========
SUPPRIME f:\program files\bonjour\mdnsresponder.exe
SUPPRIME Temporaires Windows: : 6
SUPPRIME Flash Cookies: 0
========== Restauration Système ==========
Point de restauration du système créé avec succès
========== Récapitulatif ==========
1 : Clé(s) du Registre
1 : Valeur(s) du Registre
2 : Dossier(s)
3 : Fichier(s)
1 : Restauration Système
========== Chemin du fichier rapport ==========
F:\Program Files\ZHPDiag\ZHPFixReport.txt
End of the scan in 00mn 22s -
Contributeur sécuritéOk.
Comment va le PC ?
Encore des soucis ?
Merci,
Gabriel.
-
Le pc ca m'a l'air d'aller mieux!
Sauf que je rame un peu mais bon ce n'est pas le plus important!
Merci Beaucoup de votre aide! -
Contributeur sécuritéC'est normal, tu as 500Mo de RAM, l'idéal serait 3 fois plus.
On finalise donc :
Pour nettoyer les outils utilsés et mieux sécuriser ton pc
--------------------------------------------------------------
Je t'invite à suivre ce tutoriel pour le final
il inclut
♦ du nettoyage après desinfection
♦ des mises à jour pour combler des failles de securité de logiciels importants non mis à jour
▶ et enfin quelques conseils à suivre afin que la protection soit plus efficace
_________________________________________________
Telecharge ici : PureRa (par l'editeur de JavaRa)
Lance-le (clic droit "executer en tant qu'administrateur" pour Vista/7)
=> Configuration
clique sur "Clean"
L'outil va faire son scan puis son nettoyage
À la fin du rapport tu auras une ligne comme ca :
Total space cleaned: 8140878 bytes
Transmets juste cette ligne, le reste importe peu.
__________________________________________________
Si nous avons utilisé Defogger et cliqué sur "disable" , tu peux le "reenable"
__________________________________________________
▶ Télécharge DelFix sur ton bureau.
▶ Lance le, tape suppression puis valide
Patiente pendant le scan jusqu'à l'ouverture du rapport.
▶ Copie/Colle le contenu du rapport dans ta prochaine réponse.
Note : Le rapport se trouve également sous C:\DelFix.txt
Tu peux le desinstaller à présent.
___________________________________________________
▶ Télécharge et installe CCleaner (N'installe pas la Yahoo Toolbar) :
* Lance-le.(clic droit "en tant qu'administrateur" pour Vista/7)
=> Configuration
fais le nettoyage dans le registre et dans le nettoyeur autant de fois qu'il trouve des choses à l analyse
__________________________________________________
Attention : ne pas toucher au PC pendant qu'il travaille !
▶ Nettoyage et Défragmentation de tes Disques
*Nettoyage :
Clic droit sur "poste de travail"(ordinateur pour vista) ==>"ouvrir" ==>clic droit sur le disque C ==>Propriétés ==>onglet "Général"
Cliques sur le bouton "nettoyage de disque", OK
tu le fais pour chacun de tes disques
________________________________________________
*Vérifications des erreurs :
Clic droit sur "poste de travail"(ordinateur pour vista) ==>"ouvrir" ==>clic droit sur le disque C ==>Propriétés ==>onglet "Outil"
"Vérifier maintenant", une boîte s'ouvre, cocher les cases :
-réparer automatiquement les erreurs...
-rechercher et tenter une récupération...
--->Démarrer, ok
Note : s'il te dis de redémarrer ton Pc pour le faire , tu redémarres et tu laisses faire, cela prend un peu de temps c'est normal
tu le fais pour chacun de tes disques
________________________________________________
ensuite toujours dans le même onglet tu choisis :
*Défragmentation :
"défragmenter maintenant", OK
une boîte s'ouvre, tu sélectionnes le disque à défragmenter, et tu cliques sur "analyser", puis après l'analyse, "défragmenter" . OK
Tu le fais pour chacun de tes disques
_______________________________________________
Note : si tu as un utilitaire pour défragmenter , utilises le à la place
pour ce faire Defraggler est proposé
_________________________________________________
▶ Peux-tu vérifier ta Console Java ? :
Et installer la nouvelle version si besoin est.
Désinstalle les anciennes versions :
voici pour desinstaller :
JavaRa
Décompresse le fichier sur le Bureau (Clic droit > Extraire tout).
* Double-clique (clic droit "en tant qu'administrateur" pour Vista) sur le répertoire JavaRa.
* Puis double-clique sur le fichier JavaRa.exe (le exe peut ne pas s'afficher).
* Choisis Français puis clique sur Select.
* Clique sur Oui pour confirmer. Laisse travailler et clique ensuite sur OK, puis une deuxième fois sur OK.
* Ferme l'application.
Note : tu peux supprimer son rapport dans C:\ sous le nom JavaRa.log.
_________________________________________________
▶ Mets à jour Adobe Reader si ce n'est pas le cas (désinstalle avant la version antérieure)
et pense à decocher l'installation de McAfee proposée discrêtement
__________________________________________________
▶ Je te conseille si tu n en as pas , afin de mieux securiser ton pc , d'installer un parefeu :
Online armor ou KERIO ou JETICO ou ZONE ALARM (mettre que le parefeu gratuit) ou COMODO
https://www.commentcamarche.net/telecharger/securite/16545-online-armor-personal-firewall/
https://www.01net.com/telecharger/windows/Securite/firewall/fiches/39911.html
https://forum.pcastuces.com/sujet.asp?f=25&s=35606
https://www.clubic.com/telecharger-fiche11071-sunbelt-personal-firewall-ex-kerio.html
https://manuelsdaide.com/contact/
http://www.open-files.com/forum/index.php?showtopic=29277
https://www.commentcamarche.net/telecharger/securite/24863-zonealarm/
___________________________________________________
▶ Tu peux aussi vider ta corbeille,quoi que Ccleaner le fasse tout seul
_____________________________________________________
▶ Si nous avons utilisé MalwareByte's Anti-Malware , vide sa quarantaine :
* Lance le programme puis clique sur <Quarantaine>.
* Sélectionne tous les éléments puis clique sur <supprimer>.
* Quitte le programme.
______________________________________________________
▶ Idem pour ton antivirus : vide sa quarantaine si ce n'est pas déjà fait
______________________________________________________
▶ Désactive et réactive la restauration de système, pour cela : suis les instructions du lien :
Lien XP
Lien Vista
Lien Win7
▶ Sitôt fait , recrées un point de restoration dit "sain" pour parer à quelques eventuels problêmes dans le futur
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Quelques conseils et recommandations pour l'avenir :
▶ Passe un coup de MalwareByte's Anti-Malware de temps en temps (1 fois par semaine , suivant l'utilisation que tu fais de ton PC.
▶ Utilise aussi tes autres logiciels de protection (scannes antivirus, antispywares...). N'oublie pas de faire les mises à jour avant de les utiliser.
* Pense aussi à faire une défragmentation de tes disques durs de temps en temps (garde suffisamment d'espace sur C:\ (1/3 de libre pour être à l'aise))
_____________
▶ Pour bien protéger ton PC :
[1 seul Antivirus] + [1 seul Pare feu] + [Un bon Antispyware] + [Mises à Jour récentes Windows et Logiciels de Protection] + [Utilisation de Firefox -ou autres- (Internet Explorer présente des failles de sécurité qui mettent longtemps avant d'être corrigées mais il faut absolument le conserver pour les mises à jour Windows et Windows live Messenger)]
Je te conseille d'installer cette extension pour Firefox pour securiser ton surf : WOT
Je te conseille d'installer cette extension pour Internet Explorer pour securiser ton surf : WOT
PS : En fait la meilleure des protections c'est toi même : ce que tu fais avec ton PC : où tu surfes, télécharges...ect....
Les virus utilisent les failles de ton PC pour infecter un système
à lire aussi
Et ceci
sujet intéressant à lire :
https://www.luanagames.com/index.fr.html
▶ dans le souhait de vouloir desinstaller un antivirus au profit d'un autre , voici quelques liens :
Desinstaller Avast
Desinstaller BitDefender
Desinstaller Norton
Desinstaller Kaspersky
Desinstaller AVG
Ou tout en un :
Désinstallation Antivirus, Parefeu, Antispyware
_____________
▶ Si tu as Vista n'oublie pas de réactiver le controle des comptes des utilisateurs(UAC)
___________
▶ si nous avons affiché les fichiers cachés , n'oublies pas de les remettre en attribut "caché"
▶ Clique sur le menu Demarrer /Panneau de configuration/Options des dossiers/ puis dans l'onglet Affichage
* - Décoche Afficher les fichiers et dossiers cachés
* - coche Masquer les extensions des fichiers dont le type est connu
* - coche Masquer les fichiers protégés du système d'exploitation (recommandé)
▶ clique sur Appliquer, puis OK.
__________________
Si nous l'avons pas fait lors de la désinfection, vaccine tes supports amovibles ==>
- Télécharge UsbFix (créé par El Desaparecido & C_XX) sur ton Bureau : http://www.teamxscript.org/usbfixTelechargement.html Si ton antivirus affiche une alerte, ignore la et désactive l'antivirus temporairement.
- Branche toutes tes sources de données externes à ton PC (clé USB, disque dur externe, etc...) sans les ouvrir
- Double clique sur le raccourci UsbFix sur ton Bureau, l'installation se fera automatiquement.
- Clique sur "Vacciner".
__________________
Voila,
Bonne lecture, à bientot , une fois tout ceci fait,
tu peux mettre le topic en résolu
Bonne continuation et surtout, prudence et bon surf :)
@+
Gabriel.
Précédent
- 1
- 2