Virus system fix - rogue killer - et apres?

Bonjour,

je viens d'attraper le virus system fix.
J'ai vu dans un autre post qu'il fallait utiliser rogue killer pour règler le problème.
Je l'ai fait.
J'ai restauré mes documents.

Mais je voulais savoir si je devrais faire autre chose pour m'assurer que le problème soit totalement disparu.
Car l'Icone de System Fix est encore sur mon bureau. Dois-je simplement la supprimer?

Devrais-je faire autre chose???
Merci d'avance pour votre aide!

Voici le premier rapport avec rogue killer lorsque pèse l'option 2:

RogueKiller V6.1.10 [11/18/2011] by Tigzy
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.geekstogo.com/forum/files/file/413-roguekiller/
Blog: http://tigzyrk.blogspot.com

Operating System: Windows Vista (6.0.6002 Service Pack 2) 32 bits version
Started in : Normal mode
User: Charles [Admin rights]
Mode: Remove -- Date : 11/27/2011 15:17:11

¤¤¤ Bad processes: 2 ¤¤¤
[WINDOW : System Fix] 8t4cpOpDz5M9lm.exe -- C:\ProgramData\8t4cpOpDz5M9lm.exe -> KILLED [TermProc]
[SUSP PATH] kmCiLdhHPnMcPi.exe -- C:\ProgramData\kmCiLdhHPnMcPi.exe -> KILLED [TermProc]

¤¤¤ Registry Entries: 8 ¤¤¤
[SUSP PATH] HKCU\[...]\Run : kmCiLdhHPnMcPi.exe (C:\ProgramData\kmCiLdhHPnMcPi.exe) -> DELETED
[HJ] HKCU\[...]\Advanced : Start_ShowMyComputer (0) -> REPLACED (1)
[HJ] HKCU\[...]\Advanced : Start_ShowSearch (0) -> REPLACED (1)
[HJ] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> REPLACED (0)
[HJ] HKCU\[...]\ClassicStartMenu : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> REPLACED (0)
[HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)
[HJ] HKCU\[...]\ClassicStartMenu : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)
[HJ] HKCU\[...]\ClassicStartMenu : {645FF040-5081-101B-9F08-00AA002F954E} (1) -> REPLACED (0)

¤¤¤ Particular Files / Folders: ¤¤¤

¤¤¤ Driver: [LOADED] ¤¤¤

¤¤¤ Infection : Rogue.FakeHDD ¤¤¤

¤¤¤ HOSTS File: ¤¤¤
127.0.0.1 localhost

Finished : << RKreport[1].txt >>
RKreport[1].txt

Voici le 2e rapport lorsque pèse l'option 6:
RogueKiller V6.1.10 [11/18/2011] by Tigzy
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.geekstogo.com/forum/files/file/413-roguekiller/
Blog: http://tigzyrk.blogspot.com

Operating System: Windows Vista (6.0.6002 Service Pack 2) 32 bits version
Started in : Normal mode
User: Charles [Admin rights]
Mode: Shortcuts HJfix -- Date : 11/27/2011 15:19:28

¤¤¤ Bad processes: 0 ¤¤¤

¤¤¤ Driver: [LOADED] ¤¤¤

¤¤¤ File attributes restored: ¤¤¤
Desktop: Success 33 / Fail 0
Quick launch: Success 9 / Fail 0
Programs: Success 665 / Fail 0
Start menu: Success 34 / Fail 0
User folder: Success 6707 / Fail 0
My documents: Success 2356 / Fail 0
My favorites: Success 266 / Fail 0
My pictures: Success 10768 / Fail 0
My music: Success 9708 / Fail 0
My videos: Success 133 / Fail 0
Local drives: Success 26939 / Fail 0
Backup: [FOUND] Success 19 / Fail 1

Drives:
[C:] \Device\HarddiskVolume1 -- 0x3 --> Restored
[D:] \Device\HarddiskVolume2 -- 0x3 --> Restored
[E:] \Device\CdRom0 -- 0x5 --> Skipped

¤¤¤ Infection : Rogue.FakeHDD ¤¤¤

Finished : << RKreport[3].txt >>
RKreport[1].txt ; RKreport[2].txt ; RKreport[3].txt

30 réponses

Résumé de la discussion

Infection par System Fix signalée après l'utilisation d'un outil RogueKiller, l'utilisateur restaure des documents et demande s'il faut effectuer d'autres actions pour s'assurer que le problème est totalement éliminé et ne réapparaisse pas. Plusieurs conseils évoquent des outils et méthodes supplémentaires comme Malwarebytes, ComboFix, AdwCleaner et ZHPDiag, ainsi que des actions manuelles sur les répertoires et les paramètres système. Les rapports RogueKiller montrent des éléments supprimés et des restaurations de paramètres, avec des instances d'infection Rogue.FakeHDD et des redémarrages éventuels lors des analyses. D'autres méthodes recommandées incluent la sauvegarde des données sur un support externe et la vérification des paramètres système, sans garantie immédiate que l'infection soit complètement éradiquée.

Bobot (l’IA à votre service)
  1. bonsoir,

    * Télécharge ZHPDiag sur ton bureau :

    https://www.zebulon.fr/telechargements/securite/systeme/zhpdiag.html
    ou
    http://www.premiumorange.com/zeb-help-process/zhpdiag.html
    ou
    https://www.commentcamarche.net/telecharger/utilitaires/24803-zhpdiag/

    * Laisse toi guider lors de l'installation, il se lancera automatiquement à la fin.

    /!\Utilisateur de Vista et Seven : Clique droit sur le logo de ZHPdiag, « exécuter en tant qu'Administrateur »

    * Clique sur l'icône représentant une loupe (« Lancer le diagnostic »)
    * Enregistre le rapport sur ton Bureau à l'aide de l'icône représentant une disquette
    * Héberge le rapport ZHPDiag.txt sur Cijoint, puis copie/colle le lien fourni dans ta prochaine réponse sur le forum :
    https://www.cjoint.com/

    ou :
    http://dl.free.fr
    ou :
    http://ww38.toofiles.com/fr/documents-upload.html
    ou :
    https://www.terafiles.net/

    tuto zhpdiag :

    http://www.premiumorange.com/zeb-help-process/zhpdiag.html
    0
    1. relance roguekiller en option 4 e poste son rapport,

      vas dans le menu demarrer, programmes et fonctionnalité, désinstalle ceci :

      Java 6 Update 2

      télécharge la dernière version depuis son site dédié !

      ? Télécharger et enregistre ADWcleaner sur ton bureau (Merci à Xplode) :

      http://general-changelog-team.fr/telechargements/logiciels/viewdownload/75-outils-de-xplode/28-adwcleaner

      Lance le,
      clique sur rechercher et poste son rapport.

      0
      1. Rapport rogue killer:

        Rapport de ZHPDiag v1.28.2423 par Nicolas Coolman, Update du 27/11/2011
        Run by Charles at 2011-11-27 15:57:56
        Web site : http://www.premiumorange.com/zeb-help-process/zhpdiag.html
        State : Version à jour.

        ---\\ Web Browser
        MSIE: Internet Explorer v8.0.6001.19154
        MFIE: Mozilla Firefox 8.0 v8.0 (Defaut)

        ---\\ Windows Product Information
        ~ Langage: Français
        Windows Vista Home Premium Edition, 32-bit Service Pack 2 (Build 6002)
        Windows Server License Manager Script : OK
        ~ Vista, OEM_SLP channel
        System Locked Preinstallation (OEM_SLP) : OK
        Windows Automatic Updates : OK

        ---\\ System Information
        ~ Processor: x86 Family 6 Model 15 Stepping 13, GenuineIntel
        ~ Operating System: 32 Bits
        Boot mode: Normal (Normal boot)
        Total RAM: 3069 MB (61% free)
        System Restore: Activé (Enable)
        System drive C: has 25 GB (11%) free of 221 GB

        ---\\ Logged in mode
        ~ Computer Name: CHARLES-PC
        ~ User Name: Charles
        ~ All Users Names: Guest, Charles, Administrator,
        ~ Unselected Option: O45,O61,O62,O65,O66,O82,O89
        Logged in as Administrator

        ---\\ Environnement Variables
        ~ System Unit : C:\
        ~ %AppData% : C:\Users\Charles\AppData\Roaming\
        ~ %Desktop% : C:\Users\Charles\Desktop\
        ~ %Favorites% : C:\Users\Charles\Favorites\
        ~ %LocalAppData% : C:\Users\Charles\AppData\Local\
        ~ %StartMenu% : C:\Users\Charles\AppData\Roaming\Microsoft\Windows\Start Menu\
        ~ %Windir% : C:\Windows\
        ~ %System% : C:\Windows\system32\

        ---\\ DOS/Devices
        C:\ Hard drive, Flash drive, Thumb drive (Free 25 Go of 221 Go)
        D:\ Hard drive, Flash drive, Thumb drive (Free 2 Go of 12 Go)
        E:\ CD-ROM drive (Not Inserted)

        ---\\ Security Center & Tools Informations
        [HKLM\SOFTWARE\Microsoft\Security Center] AntiSpywareOverride: OK
        [HKLM\SOFTWARE\Microsoft\Security Center] AntiVirusOverride: OK
        [HKLM\SOFTWARE\Microsoft\Security Center] AntiVirusDisableNotify: OK
        [HKLM\SOFTWARE\Microsoft\Security Center] FirewallDisableNotify: OK
        [HKLM\SOFTWARE\Microsoft\Security Center] FirewallOverride: OK
        [HKLM\SOFTWARE\Microsoft\Security Center] UpdatesDisableNotify: OK
        [HKLM\SOFTWARE\Microsoft\Security Center] UacDisableNotify: OK
        [HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiSpywareOverride: OK
        [HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusOverride: OK
        [HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusDisableNotify: OK
        [HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallDisableNotify: OK
        [HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallOverride: OK
        [HKLM\SOFTWARE\Microsoft\Security Center\Svc] UpdatesDisableNotify: OK
        [HKLM\SOFTWARE\Microsoft\Security Center\Svc] UacDisableNotify: OK
        [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: OK
        [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoDesktop: OK
        [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoFolderOptions: OK
        [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoDesktop: OK
        [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoStartMenuSubFolder: OK
        [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoResolveSearch: OK
        [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoClose: OK
        [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System] NoActiveDesktopChanges: OK
        [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System] DisableTaskMgr: OK
        [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System] DisableRegistryTools: OK
        [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System] NoDispScrSavPage: OK
        [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: OK
        [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: OK
        [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced] Start_ShowSearch: OK
        [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced] Start_ShowMyComputer: OK
        [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings] WarnOnHTTPSToHTTPRedirect: OK
        [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK
        [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK
        [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK
        [HKLM\SYSTEM\CurrentControlSet\Services] wscsvc : OK
        [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install] LastSuccessTime : Out Of Date
        ~ Scan Security Center in 00mn 00s

        ---\\ Recherche particulière de fichiers génériques
        [MD5.D07D4C3038F3578FFCE1C0237F2A1253] - (.Microsoft Corporation - Windows Explorer.) (.2010-05-16 - 02:27:36.) -- C:\Windows\Explorer.exe [2926592]
        [MD5.4B555106290BD117334E9A08761C035A] - (....) (.2006-11-02 - 05:45:37.) -- C:\Windows\system32\rundll32.exe [44544]
        [MD5.101BA3EA053480BB5D957EF37C06B5ED] - (.Microsoft Corporation - Windows Start-Up Application.) (.2008-01-20 - 22:23:42.) -- C:\Windows\system32\Wininit.exe [96768]
        [MD5.18F17E90657528C232B1944DEB4EC160] - (.Microsoft Corporation - Internet Extensions for Win32.) (.2011-10-12 - 19:06:24.) -- C:\Windows\system32\wininet.dll [916480]
        [MD5.898E7C06A350D4A1A64A9EA264D55452] - (.Microsoft Corporation - Windows Logon Application.) (.2010-05-16 - 02:28:13.) -- C:\Windows\system32\Winlogon.exe [314368]
        [MD5.3911B972B55FEA0478476B2E777B29FA] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) (.2011-06-16 - 09:58:27.) -- C:\Windows\system32\drivers\AFD.sys [273408]
        [MD5.1F05B78AB91C9075565A9D8A4B880BC4] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.2010-05-16 - 02:32:26.) -- C:\Windows\system32\drivers\atapi.sys [19944]
        [MD5.7ADD03E75BEB9E6DD102C3081D29840A] - (.Microsoft Corporation - CD-ROM File System Driver.) (.2008-01-20 - 22:23:51.) -- C:\Windows\system32\drivers\Cdfs.sys [70144]
        [MD5.6B4BFFB9BECD728097024276430DB314] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.2010-05-16 - 00:39:17.) -- C:\Windows\system32\drivers\Cdrom.sys [67072]
        [MD5.622C41A07CA7E6DD91770F50D532CB6C] - (.Microsoft Corporation - DFS Namespace Client Driver.) (.2011-06-16 - 10:59:03.) -- C:\Windows\system32\drivers\DfsC.sys [75264]
        [MD5.062452B7FFD68C8C042A6261FE8DFF4A] - (.Microsoft Corporation - High Definition Audio Bus Driver.) (.2010-05-16 - 00:42:42.) -- C:\Windows\system32\drivers\HDAudBus.sys [561152]
        [MD5.22D56C8184586B7A1F6FA60BE5F5A2BD] - (.Microsoft Corporation - i8042 Port Driver.) (.2008-01-20 - 22:23:20.) -- C:\Windows\system32\drivers\i8042prt.sys [54784]
        [MD5.8793643A67B42CEC66490B2A0CF92D68] - (.Microsoft Corporation - IP Network Address Translator.) (.2008-01-20 - 22:24:25.) -- C:\Windows\system32\drivers\IpNat.sys [100864]
        [MD5.1E94971C4B446AB2290DEB71D01CF0C2] - (.Microsoft Corporation - Windows NT SMB Minirdr.) (.2011-06-16 - 09:24:40.) -- C:\Windows\system32\drivers\MRxSmb.sys [106496]
        [MD5.ECD64230A59CBD93C85F1CD1CAB9F3F6] - (.Microsoft Corporation - MBT Transport driver.) (.2010-05-16 - 00:45:37.) -- C:\Windows\system32\drivers\netBT.sys [185856]
        [MD5.6A4A98CEE84CF9E99564510DDA4BAA47] - (.Microsoft Corporation - NT File System Driver.) (.2010-05-16 - 02:32:49.) -- C:\Windows\system32\drivers\ntfs.sys [1083880]
        [MD5.0FA9B5055484649D63C303FE404E5F4D] - (.Microsoft Corporation - Parallel Port Driver.) (.2006-11-02 - 04:51:30.) -- C:\Windows\system32\drivers\Parport.sys [79360]
        [MD5.A214ADBAF4CB47DD2728859EF31F26B0] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.2008-01-20 - 22:24:55.) -- C:\Windows\system32\drivers\Rasl2tp.sys [76288]
        [MD5.FBC0BACD9C3D7F6956853F64A66E252D] - (.Microsoft Corporation - Microsoft RDP Device redirector.) (.2008-01-20 - 22:23:01.) -- C:\Windows\system32\drivers\rdpdr.sys [248832]
        [MD5.7B75299A4D201D6A6533603D6914AB04] - (.Microsoft Corporation - SMB Transport driver.) (.2010-05-16 - 00:45:22.) -- C:\Windows\system32\drivers\smb.sys [66560]
        [MD5.76B06EB8A01FC8624D699E7045303E54] - (.Microsoft Corporation - TDI Translation Driver.) (.2010-05-16 - 00:45:56.) -- C:\Windows\system32\drivers\tdx.sys [72192]
        [MD5.147281C01FCB1DF9252DE2A10D5E7093] - (.Microsoft Corporation - Volume Shadow Copy Driver.) (.2010-05-16 - 02:32:55.) -- C:\Windows\system32\drivers\volsnap.sys [226280]
        ~ Scan Generic Processes in 00mn 00s

        ---\\ Etat des fichiers cachés (Caché/Total)
        ~ Mes images (My Pictures) : 34/10688
        ~ Mes musiques (My Musics) : 139/7499
        ~ Mes Videos (My Videos) : 9/122
        ~ Mes Favoris (My Favorites) : 3/245
        ~ Mes Documents (My Documents) : 30/2182
        ~ Mon Bureau (My Desktop) : 1/44
        ~ Menu demarrer (Programs) : 6/26
        ~ Scan Hidden Files in 00mn 28s

        ---\\ Processus lancés
        [MD5.09DC37198C663E9C4415F9251730CCDD] - (.DigitalPersona, Inc. - DigitalPersona Local Agent.) -- C:\Program Files\DigitalPersona\Bin\DpAgent.exe [671744] [PID.2676]
        [MD5.19D93154C82FE39A99B269CED1056A92] - (.Synaptics, Inc. - Synaptics TouchPad Enhancements.) -- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1033512] [PID.3928]
        [MD5.4BBE1550C346FCE2D4927BF6EACD3CF7] - (.Motorola Inc. - Application executable file.) -- C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe [634880] [PID.3944]
        [MD5.66CF7713FE5BD782943975AF9427A4A8] - (.Realtek Semiconductor - HD Audio Control Panel.) -- C:\WINDOWS\RtHDVCpl.exe [4702208] [PID.3984]
        [MD5.C2C80A16DF3C72B331333B8C01E7731C] - (.Intel Corporation - Event Monitor User Notification Tool.) -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe [178712] [PID.4000]
        [MD5.F08A76C5E56BDB6F98F41BD22A4692E1] - (.CyberLink Corp. - HP QuickPlay Resident Program.) -- C:\Program Files\HP\QuickPlay\QPService.exe [468264] [PID.4008]
        [MD5.2CF59B201A59D0FF5534089F76297559] - (. Hewlett-Packard Development Company, L.P. - HP QuickTouch On Screen Display.) -- C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe [554320] [PID.4016]
        [MD5.B93C4070F24E46B0097648C276B5039E] - (.Hewlett-Packard Co. - Hewlett-Packard Product Assistant.) -- C:\Program Files\HP\HP Software Update\hpwuSchd2.exe [49152] [PID.532]
        [MD5.CB4EE42EE2D33A58EFD48C276B683663] - (.Hewlett-Packard Development Company, L.P. - HPWAMain Module.) -- C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [480560] [PID.2432]
        [MD5.B8AF02700299CD308046BB9339165813] - (.Hewlett-Packard Development Company, L.P. - Module to process WiFi messages..) -- C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe [311296] [PID.2304]
        [MD5.C983E62B6FB74457D173BA93F66F6068] - (.Avira GmbH - Antivirus System Tray Tool.) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [281768] [PID.2484]
        [MD5.87E1BFF68B690765D11C10E841BA6AA7] - (.Druide informatique inc. - AgentAntidote.) -- C:\Program Files\Druide\Antidote 7\Programmes32\agentantidote.exe [941440] [PID.2960]
        [MD5.13E7CFE8E269ED15E7FC9C3EBBCB7E2B] - (.Sun Microsystems, Inc. - Java(TM) Update Scheduler.) -- C:\Program Files\Common Files\Java\Java Update\jusched.exe [254696] [PID.2968]
        [MD5.879D74337173A6D630D3D06184D354C1] - (.Apple Inc. - iTunesHelper.) -- C:\Program Files\iTunes\iTunesHelper.exe [421736] [PID.3152]
        [MD5.79197AB8FC20E781BA141E291866A909] - (.Skype Technologies S.A. - Skype.) -- C:\Program Files\Skype\Phone\Skype.exe [17351304] [PID.3456]
        [MD5.7C6F44557A55CE933D7063162FE92FB2] - (.Broadcom Corporation. - Bluetooth Tray Application.) -- C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe [727592] [PID.3464]
        [MD5.1BA45CDEF852381DA4A95D056DDB4B48] - (.Hewlett-Packard Co. - HP Digital Imaging Monitor.) -- C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [210520] [PID.2652]
        [MD5.3B161E0C1D8F3253640D57B45FAC96DA] - (.Pas de propriétaire - HpqToaster Module.) -- C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe [677432] [PID.2752]
        [MD5.892699A6AEB910C58B726BD70BEA4F4B] - (.Synaptics, Inc. - Synaptics Pointing Device Helper.) -- C:\Program Files\Synaptics\SynTP\SynTPHelper.exe [95528] [PID.2040]
        [MD5.54B2B810DDBF02BA122DE4214AC074DB] - (.Broadcom Corporation. - Bluetooth Stack COM Server.) -- C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe [1620520] [PID.3784]
        [MD5.95967BA44CCC51382BEB882A15E314D2] - (.Hewlett-Packard Co. - HP CUE Status.) -- C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe [271960] [PID.1680]
        [MD5.A29999E6CF54648B4C9DA986A0AEB325] - (.Nicolas Coolman - Diagnostic Tool.) -- C:\Program Files\ZHPDiag\ZHPDiag.exe [707072] [PID.2992]
        [MD5.6080A176D09435FC8E6E800996656E18] - (.Microsoft Corporation - Console IME.) -- C:\Windows\system32\conime.exe [69120] [PID.4508]
        [MD5.C4D17F11526F87BC762F31DA5BD2580B] - (.NVIDIA Corporation - NVIDIA Driver Helper Service, Version 187.6.) -- C:\Windows\system32\nvvsvc.exe [219752] [PID.]
        [MD5.862BB4CBC05D80C5B45BE430E5EF872F] - (.Microsoft Corporation - Microsoft Software Licensing Service.) -- C:\Windows\system32\SLsvc.exe [3408896] [PID.]
        [MD5.876C4144EF6F1107C04A092CA03F89E0] - (.DigitalPersona, Inc. - DigitalPersona Local Host.) -- C:\Program Files\DigitalPersona\Bin\DpHostW.exe [299008] [PID.]
        [MD5.B4837FE56D76B2E9EA90E5365CF6A2BE] - (.Avira GmbH - Antivirus Scheduler.) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe [136360] [PID.]
        [MD5.11A52CF7B265631DEEB24C6149309EFF] - (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [64952] [PID.]
        [MD5.DF5A3016052755C910A206058B4A1729] - (.Avira GmbH - Antivirus On-Access Service.) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe [269480] [PID.]
        [MD5.20F6F19FE9E753F2780DC2FA083AD597] - (.Apple Inc. - MobileDeviceService.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [37664] [PID.]
        [MD5.1C87705CCB2F60172B0FC86B5D82F00D] - (.Apple Inc. - Bonjour Service.) -- C:\Program Files\Bonjour\mDNSResponder.exe [387944] [PID.]
        [MD5.8C91BD35AE9AA8B628EEC5E637BB1D0F] - (.Avira GmbH - AntiVir shadow copy service.) -- C:\Program Files\Avira\AntiVir Desktop\avshadow.exe [76968] [PID.]
        [MD5.681EF6E0CC7BBAA0C09ACABEB91F669E] - (.Intel Corporation - RAID Monitor.) -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe [358936] [PID.]
        [MD5.53710476495886D9961BE46983A6A33F] - (.Hewlett-Packard Company - LightScribe Service.) -- C:\Program Files\Common Files\LightScribe\LSSrvc.exe [79136] [PID.]
        [MD5.BA396D1C71934E22679D3F4DAC17E7AB] - (.Pas de propriétaire - CLCapSvc Module.) -- C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe [271760] [PID.]
        [MD5.04C1DCBB226C6AE647B794833CE3CEB6] - (.Hewlett-Packard Development Company, L.P. - hpqwmiex Module.) -- C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe [135168] [PID.]
        [MD5.4B455E8C41CAD3219CCF53024DCAD604] - (.Pas de propriétaire - CLSched Module.) -- C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe [112016] [PID.]
        [MD5.F62C69376A95795FE7CDB1C778EDACA4] - (.Apple Inc. - iPodService Module (32-bit).) -- C:\Program Files\iPod\bin\iPodService.exe [821096] [PID.]
        [MD5.89F9E1984C1CD9E5F4FE39642D886E11] - (.Hewlett-Packard - HP Health Check Service.) -- c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe [94208] [PID.]
        [MD5.F8D8BB3F6173FFF00128612F33D3197A] - (.Microsoft Corporation - WMI Reverse Performance Adapter Maintenance.) -- C:\Windows\system32\wbem\WMIADAP.EXE [117248] [PID.]
        ~ Scan Processes Running in 00mn 00s

        ---\\ Mozilla Firefox, Plugins,Demarrage,Recherche,Extensions (P2,M0,M1,M2,M3)
        C:\Users\Charles\AppData\Roaming\Mozilla\Firefox\Profiles\u2uvxst2.default\prefs.js
        M3 - MFPP: Plugins - [Charles] -- C:\Program Files\Mozilla FireFox\searchplugins\amazon-france.xml
        M3 - MFPP: Plugins - [Charles] -- C:\Program Files\Mozilla FireFox\searchplugins\bing.xml
        M3 - MFPP: Plugins - [Charles] -- C:\Program Files\Mozilla FireFox\searchplugins\cnrtl-tlfi-fr.xml
        M3 - MFPP: Plugins - [Charles] -- C:\Program Files\Mozilla FireFox\searchplugins\eBay-france.xml
        M3 - MFPP: Plugins - [Charles] -- C:\Program Files\Mozilla FireFox\searchplugins\google.xml
        M3 - MFPP: Plugins - [Charles] -- C:\Program Files\Mozilla FireFox\searchplugins\wikipedia-fr.xml
        M3 - MFPP: Plugins - [Charles] -- C:\Program Files\Mozilla FireFox\searchplugins\yahoo-france.xml
        M0 - MFSP: prefs.js [Charles - u2uvxst2.default] https://www.msn.com/en-ca?checklang=1
        M2 - MFEP: prefs.js [Charles - u2uvxst2.default\{20a82645-c095-46ed-80e3-08825760534b}] [MicrosoftCG] Microsoft .NET Framework Assistant v1.2.1 (.Microsoft.)
        P2 - FPN:Firefox Plugin Navigator . (.Sun Microsystems, Inc. - NPRuntime Script Plug-in Library for Java(TM) Deploy.) -- C:\Program Files\Mozilla Firefox\Plugins\npdeployJava1.dll
        P2 - FPN:Firefox Plugin Navigator . (.Microsoft Corporation - Office Plugin for Netscape Navigator.) -- C:\Program Files\Mozilla Firefox\Plugins\NPOFF12.DLL
        P2 - FPN:Firefox Plugin Navigator . (.Adobe Systems Inc. - Adobe PDF Plug-In For Firefox and Netscape 10.1.1.) -- C:\Program Files\Mozilla Firefox\Plugins\nppdf32.dll
        P2 - FPN:Firefox Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files\Mozilla Firefox\Plugins\npqtplugin.dll
        P2 - FPN:Firefox Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files\Mozilla Firefox\Plugins\npqtplugin2.dll
        P2 - FPN:Firefox Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files\Mozilla Firefox\Plugins\npqtplugin3.dll
        P2 - FPN:Firefox Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files\Mozilla Firefox\Plugins\npqtplugin4.dll
        P2 - FPN:Firefox Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files\Mozilla Firefox\Plugins\npqtplugin5.dll
        P2 - FPN:Firefox Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files\Mozilla Firefox\Plugins\npqtplugin6.dll
        P2 - FPN:Firefox Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files\Mozilla Firefox\Plugins\npqtplugin7.dll
        P2 - FPN: [HKLM] [@adobe.com/FlashPlayer] - (...) -- C:\WINDOWS\System32\Macromed\Flash\NPSWF32.dll
        P2 - FPN: [HKLM] [@Apple.com/iTunes,version=1.0] - (...) -- C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
        P2 - FPN: [HKLM] [@Google.com/GoogleEarthPlugin] - (.Google - GEPlugin.) -- C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
        P2 - FPN: [HKLM] [@java.com/JavaPlugin] - (.Sun Microsystems, Inc. - Next Generation Java Plug-in 1.6.0_26 for Mozilla browsers.) -- C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
        P2 - FPN: [HKLM] [@Microsoft.com/NpCtrl,version=1.0] - (. Microsoft Corporation - 4.0.60831.0.) -- C:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll
        P2 - FPN: [HKLM] [@microsoft.com/WPF,version=3.5] - (.Microsoft Corporation - Windows Presentation Foundation (WPF) plug-in for Mozilla browsers.) -- C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
        P2 - FPN: [HKLM] [@pandonetworks.com/PandoWebPlugin] - (.Pando Networks - Pando Web Plugin.) -- C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll
        P2 - FPN: [HKLM] [@tools.google.com/Google Update;version=3] - (.Google Inc. - Google Update.) -- C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll
        P2 - FPN: [HKLM] [@tools.google.com/Google Update;version=9] - (.Google Inc. - Google Update.) -- C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll
        P2 - FPN: [HKLM] [@viewpoint.com/VMP] - (.Pas de propriétaire - MetaStream 3 Plugin r4.) -- C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
        P2 - FPN: [HKLM] [Adobe Reader] - (.Adobe Systems Inc. - Adobe PDF Plug-In For Firefox and Netscape 10.1.1.) -- C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
        P2 - FPN: [HKCU] [pandonetworks.com/PandoWebPlugin] - (.Pando Networks - Pando Web Plugin.) -- C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll
        ~ Scan Firefox Browser in 00mn 00s

        ---\\ Internet Explorer, Démarrage,Recherche,URLSearchHook, Phishing (R0,R1,R3,R4)
        R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/en-ca?checklang=1
        R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com
        R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = https://www.microsoft.com/fr-fr/
        R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons
        R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk
        R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs,Tabs = res://ieframe.dll/tabswelcome.htm
        R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = https://www.bing.com/?toHttps=1&redig=17DBE7D168544FA98200E890A8051984
        R3 - URLSearchHook: Microsoft Url Search Hook - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} . (.Microsoft Corporation - Internet Explorer.) (8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)) -- C:\Windows\system32\ieframe.dll
        R4 - HKCU\SOFTWARE\Microsoft\Internet Explorer\PhishingFilter,Enabled = 2
        ~ Scan IE Browser in 00mn 00s

        ---\\ Internet Explorer, Proxy Management (R5)
        R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
        R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key
        R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
        R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
        R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 0
        R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyHttp1.1 = 0
        R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll
        R5 - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
        ~ Scan Proxy management in 00mn 00s

        ---\\ Modification d'une valeur Ini (Changed inifile value, mapped to Registry) (F2)
        F2 - REG:system.ini: UserInit=C:\Windows\system32\userinit.exe,
        F2 - REG:system.ini: VMApplet=rundll32 shell32,Control_RunDLL "sysdm.cpl"
        ~ Scan Keys in 00mn 00s

        ---\\ Redirection du fichier Hosts (O1)
        ~ Le fichier hosts est sain (The hosts file is clean).
        ~ Scan Hosts File in 00mn 00s

        ---\\ Browser Helper Objects de navigateur (O2)
        O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} Clé orpheline
        O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} . (.Adobe Systems Incorporated - Adobe PDF Helper for Internet Explorer.) -- C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
        O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} Clé orpheline
        O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} Clé orpheline
        O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} . (.Microsoft Corporation - WindowsLiveLogin.dll.) -- C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
        O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} . (.Sun Microsystems, Inc. - Java(TM) Platform SE binary.) -- C:\Program Files\Java\jre6\bin\jp2ssv.dll
        ~ Scan BHO in 00mn 00s

        ---\\ Internet Explorer Toolbars (O3)
        O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} . (...) -- (.not file.)
        ~ Scan Toolbar in 00mn 00s

        ---\\ Applications démarrées par registre & par dossier (O4)
        O4 - HKLM\..\Run: [SynTPEnh] . (.Synaptics, Inc. - Synaptics TouchPad Enhancements.) -- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
        O4 - HKLM\..\Run: [SMSERIAL] . (.Motorola Inc. - Application executable file.) -- C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
        O4 - HKLM\..\Run: [RtHDVCpl] . (.Realtek Semiconductor - HD Audio Control Panel.) -- C:\Windows\RtHDVCpl.exe
        O4 - HKLM\..\Run: [IAAnotif] . (.Intel Corporation - Event Monitor User Notification Tool.) -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
        O4 - HKLM\..\Run: [QPService] . (.CyberLink Corp. - HP QuickPlay Resident Program.) -- C:\Program Files\HP\QuickPlay\QPService.exe
        O4 - HKLM\..\Run: [OnScreenDisplay] . (. Hewlett-Packard Development Company, L.P. - HP QuickTouch On Screen Display.) -- C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe
        O4 - HKLM\..\Run: [UCam_Menu] . (.CyberLink Corp. - StartMen Application.) -- C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe
        O4 - HKLM\..\Run: [DpAgent] . (.DigitalPersona, Inc. - DigitalPersona Local Agent.) -- C:\Program Files\DigitalPersona\Bin\DpAgent.exe
        O4 - HKLM\..\Run: [HP Health Check Scheduler] . (.Hewlett-Packard - HP Health Check Scheduler.) -- C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
        O4 - HKLM\..\Run: [HP Software Update] . (.Hewlett-Packard Co. - Hewlett-Packard Product Assistant.) -- C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
        O4 - HKLM\..\Run: [hpWirelessAssistant] . (.Hewlett-Packard Development Company, L.P. - HPWAMain Module.) -- C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
        O4 - HKLM\..\Run: [WAWifiMessage] . (.Hewlett-Packard Development Company, L.P. - Module to process WiFi messages..) -- C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
        O4 - HKLM\..\Run: [avgnt] . (.Avira GmbH - Antivirus System Tray Tool.) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
        O4 - HKLM\..\Run: [agentantidote.exe] . (.Druide informatique inc. - AgentAntidote.) -- C:\Program Files\Druide\Antidote 7\Programmes32\agentantidote.exe
        O4 - HKLM\..\Run: [SunJavaUpdateSched] . (.Sun Microsystems, Inc. - Java(TM) Update Scheduler.) -- C:\Program Files\Common Files\Java\Java Update\jusched.exe
        O4 - HKLM\..\Run: [QuickTime Task] . (.Apple Inc. - QuickTime Task.) -- C:\Program Files\QuickTime\QTTask.exe
        O4 - HKLM\..\Run: [iTunesHelper] . (.Apple Inc. - iTunesHelper.) -- C:\Program Files\iTunes\iTunesHelper.exe
        O4 - HKLM\..\Run: [Adobe ARM] . (.Adobe Systems Incorporated - Adobe Reader and Acrobat Manager.) -- C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
        O4 - HKCU\..\Run: [Sidebar] . (.Microsoft Corporation - Windows Sidebar.) -- C:\Program Files\Windows Sidebar\sidebar.exe
        O4 - HKCU\..\Run: [Skype] . (.Skype Technologies S.A. - Skype.) -- C:\Program Files\Skype\Phone\Skype.exe
        O4 - HKUS\S-1-5-21-3197797478-1381546659-3490569594-1000\..\Run: [Sidebar] . (.Microsoft Corporation - Windows Sidebar.) -- C:\Program Files\Windows Sidebar\sidebar.exe
        O4 - HKUS\S-1-5-21-3197797478-1381546659-3490569594-1000\..\Run: [Skype] . (.Skype Technologies S.A. - Skype.) -- C:\Program Files\Skype\Phone\Skype.exe
        ~ Scan Application in 00mn 00s

        ---\\ Autres liens utilisateurs (O4)
        O4 - Global Startup: C:\Users\Charles\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk . (.Microsoft Corporation.) -- C:\Program Files\Internet Explorer\iexplore.exe
        O4 - Global Startup: C:\Users\Charles\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Mail.lnk . (.Microsoft Corporation.) -- C:\Program Files\Windows Mail\WinMail.exe
        O4 - Global Startup: C:\Users\Charles\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk . (.Microsoft Corporation.) -- C:\Program Files\Windows Media Player\wmplayer.exe
        O4 - Global Startup: C:\Users\Charles\Desktop\Any Video Converter.lnk . (.Any-Video-Converter.com.) -- C:\Program Files\AnvSoft\Any Video Converter\VideoConverter.exe
        O4 - Global Startup: C:\Users\Charles\Desktop\CCleaner.lnk . (.Piriform Ltd.) -- C:\Program Files\CCleaner\CCleaner.exe
        O4 - Global Startup: C:\Users\Charles\Desktop\Microsoft Office Word 2007.lnk . (...) -- C:\Windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\wordicon.exe
        O4 - Global Startup: C:\Users\Charles\Desktop\Partition.lnk . (...) -- C:\Users\Charles\Documents\Partition
        O4 - Global Startup: C:\Users\Charles\Desktop\System Fix.lnk . (...) -- C:\ProgramData\8t4cpOpDz5M9lm.exe
        O4 - Global Startup: C:\Users\Charles\Desktop\Terre des mémoires p. 67.lnk . (...) -- C:\Users\Charles\Documents\Terre des mémoires.pdf_
        O4 - Global Startup: C:\Users\Charles\Desktop\tuner - Shortcut.lnk . (.Audio Phonics, Inc..) -- C:\Program Files\AP Tuner\AP Tuner 3.08\tuner.exe
        O4 - Global Startup: C:\Users\Charles\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\iTunes.lnk . (.Apple Inc..) -- C:\Program Files\iTunes\iTunes.exe
        O4 - Global Startup: C:\Users\Charles\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk . (.Mozilla Corporation.) -- C:\Program Files\Mozilla Firefox\firefox.exe
        O4 - Global Startup: C:\Users\Charles\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Partition - Shortcut.lnk . (...) -- C:\Users\Charles\Documents\Partition
        O4 - Global Startup: C:\Users\Charles\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\System Fix.lnk . (...) -- C:\ProgramData\8t4cpOpDz5M9lm.exe
        O4 - Global Startup: C:\Users\Charles\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Windows Live Messenger .lnk . (.Microsoft Corporation.) -- C:\Program Files\Windows Live\Messenger\msnmsgr.exe
        O4 - Global Startup: C:\Users\Charles\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk . (.Microsoft Corporation.) -- C:\Program Files\Windows Media Player\wmplayer.exe
        ~ Scan Global Startup in 00mn 00s

        ---\\ Lignes supplémentaires dans le menu contextuel d'Internet Explorer (O8)
        O8 - Extra context menu item: E&xport to Microsoft Excel . (.Microsoft Corporation - Microsoft Office Excel.) -- C:\Program Files\MICROS~3\Office12\EXCEL.exe
        O8 - Extra context menu item: Send image to &Bluetooth Device... . (...) -- C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
        O8 - Extra context menu item: Send page to &Bluetooth Device... . (...) -- C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
        ~ Scan IE Menu Contextuel in 00mn 00s

        ---\\ Boutons situés sur la barre d'outils principale d'Internet Explorer (O9)
        O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} . (...) -- C:\Program Files\Microsoft Office\Office12\REFBARH.ICO
        O9 - Extra button: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} . (...) -- C:\Program Files\WIDCOMM\Bluetooth Software\bt_hot_icon.ico
        ~ Scan IE Extra Buttons in 00mn 00s

        ---\\ Winsock hijacker (Layered Service Provider) (O10)
        O10 - WLSP:\000000000001\Winsock LSP File . (.Microsoft Corporation - Network Location Awareness 2.) -- C:\Windows\system32\NLAapi.dll
        O10 - WLSP:\000000000002\Winsock LSP File . (.Microsoft Corporation - E-mail Naming Shim Provider.) -- C:\Windows\system32\napinsp.dll
        O10 - WLSP:\000000000003\Winsock LSP File . (.Microsoft Corporation - PNRP Name Space Provider.) -- C:\Windows\system32\pnrpnsp.dll
        O10 - WLSP:\000000000004\Winsock LSP File . (.Microsoft Corporation - PNRP Name Space Provider.) -- C:\Windows\system32\pnrpnsp.dll
        O10 - WLSP:\000000000005\Winsock LSP File . (.Microsoft Corporation - Microsoft Windows Sockets 2.0 Service Provider.) -- C:\Windows\system32\mswsock.dll
        O10 - WLSP:\000000000006\Winsock LSP File . (.Microsoft Corporation - LDAP RnR Provider DLL.) -- C:\Windows\system32\winrnr.dll
        O10 - WLSP:\000000000007\Winsock LSP File . (.Microsoft Corporation - Windows Sockets Helper DLL.) -- C:\Windows\system32\wshbth.dll
        O10 - WLSP:\000000000008\Winsock LSP File . (.Apple Inc. - Bonjour Namespace Provider.) -- C:\Program Files\Bonjour\mdnsNSP.dll
        ~ Scan Winsock in 00mn 00s

        ---\\ Objets ActiveX (Downloaded Program Files)(O16)
        O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} () - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
        ~ Scan Objets ActiveX in 00mn 00s

        ---\\ Modification Domaine/Adresses DNS (O17)
        O17 - HKLM\System\CCS\Services\Tcpip\..\{86D28062-DE5A-4894-A66B-A8AC92155B31}: DhcpNameServer = 192.168.0.1
        O17 - HKLM\System\CCS\Services\Tcpip\..\{DDE90C58-DF7E-48C2-99E2-A879098162DA}: DhcpNameServer = 192.168.0.1
        O17 - HKLM\System\CCS\Services\Tcpip\..\{86D28062-DE5A-4894-A66B-A8AC92155B31}: DhcpDomain = phub.net.cable.rogers.com
        O17 - HKLM\System\CCS\Services\Tcpip\..\{DDE90C58-DF7E-48C2-99E2-A879098162DA}: DhcpDomain = phub.net.cable.rogers.com
        O17 - HKLM\System\CS1\Services\Tcpip\..\{86D28062-DE5A-4894-A66B-A8AC92155B31}: DhcpNameServer = 192.168.0.1
        O17 - HKLM\System\CS1\Services\Tcpip\..\{DDE90C58-DF7E-48C2-99E2-A879098162DA}: DhcpNameServer = 192.168.0.1
        O17 - HKLM\System\CS1\Services\Tcpip\..\{86D28062-DE5A-4894-A66B-A8AC92155B31}: DhcpDomain = phub.net.cable.rogers.com
        O17 - HKLM\System\CS1\Services\Tcpip\..\{DDE90C58-DF7E-48C2-99E2-A879098162DA}: DhcpDomain = phub.net.cable.rogers.com
        O17 - HKLM\System\CS2\Services\Tcpip\..\{86D28062-DE5A-4894-A66B-A8AC92155B31}: DhcpNameServer = 192.168.0.1
        O17 - HKLM\System\CS2\Services\Tcpip\..\{DDE90C58-DF7E-48C2-99E2-A879098162DA}: DhcpNameServer = 192.168.0.1
        O17 - HKLM\System\CS2\Services\Tcpip\..\{86D28062-DE5A-4894-A66B-A8AC92155B31}: DhcpDomain = phub.net.cable.rogers.com
        O17 - HKLM\System\CS2\Services\Tcpip\..\{DDE90C58-DF7E-48C2-99E2-A879098162DA}: DhcpDomain = phub.net.cable.rogers.com
        ~ Scan Domain in 00mn 00s

        ---\\ Protocole additionnel (O18)
        O18 - Handler: about - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\Windows\system32\mshtml.dll
        O18 - Handler: cdl - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\system32\urlmon.dll
        O18 - Handler: dvd - {12D51199-0DB5-46FE-A120-47A3D7D937CC} . (.Microsoft Corporation - ActiveX control for streaming video.) -- C:\Windows\System32\msvidctl.dll
        O18 - Handler: file - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\system32\urlmon.dll
        O18 - Handler: ftp - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\system32\urlmon.dll
        O18 - Handler: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\system32\urlmon.dll
        O18 - Handler: http - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\system32\urlmon.dll
        O18 - Handler: https - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\system32\urlmon.dll
        O18 - Handler: its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\System32\itss.dll
        O18 - Handler: javascript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\Windows\system32\mshtml.dll
        O18 - Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} . (.Microsoft Corporation - Windows Live Messenger Protocol Handler Mod.) -- C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
        O18 - Handler: local - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\system32\urlmon.dll
        O18 - Handler: mailto - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\Windows\system32\mshtml.dll
        O18 - Handler: mhtml - {05300401-BCBC-11d0-85E3-00C04FD85AB4} . (.Microsoft Corporation - Microsoft Internet Messaging API Resources.) -- C:\Windows\system32\inetcomm.dll
        O18 - Handler: mk - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\system32\urlmon.dll
        O18 - Handler: ms-help - {314111c7-a502-11d2-bbca-00c04f8ec294} . (.Microsoft Corporation - Microsoft® Help Data Services Module.) -- C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
        O18 - Handler: ms-its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\System32\itss.dll
        O18 - Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} . (.Microsoft Corporation - Windows Live Messenger Protocol Handler Mod.) -- C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
        O18 - Handler: res - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\Windows\system32\mshtml.dll
        O18 - Handler: tv - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} . (.Microsoft Corporation - ActiveX control for streaming video.) -- C:\Windows\System32\msvidctl.dll
        O18 - Handler: vbscript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\Windows\system32\mshtml.dll
        O18 - Handler: wlmailhtml - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} . (.Microsoft Corporation - Windows Live Mail.) -- C:\Program Files\Windows Live\Mail\mailcomm.dll
        O18 - Filter: application/octet-stream - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\system32\mscoree.dll
        O18 - Filter: application/x-complus - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\system32\mscoree.dll
        O18 - Filter: application/x-msdownload - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\system32\mscoree.dll
        O18 - Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\system32\urlmon.dll
        O18 - Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\system32\urlmon.dll
        O18 - Filter: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} . (.Microsoft Corporation - Microsoft Office XML MIME Filter.) -- C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
        ~ Scan Protocole Additionnel in 00mn 00s

        ---\\ Clé de Registre autorun ShellServiceObjectDelayLoad (SSO/SSODL) (O21)
        O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} . (.Microsoft Corporation - Web Site Monitor.) -- C:\WINDOWS\System32\webcheck.dll
        ~ Scan SSODL in 00mn 00s

        ---\\ Clé de Registre autorun SharedTaskScheduler (STS) (O22)
        O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} . (.Microsoft Corporation - Shell Browser UI Library.) -- C:\Windows\system32\browseui.dll
        ~ Scan STS/SSO in 00mn 00s

        ---\\ Liste des services NT non Microsoft et non désactivés (O23)
        O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) . (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
        O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) . (.Avira GmbH - Antivirus Scheduler.) - C:\Program Files\Avira\AntiVir Desktop\sched.exe
        O23 - Service: Avira AntiVir Guard (AntiVirService) . (.Avira GmbH - Antivirus On-Access Service.) - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
        O23 - Service: Apple Mobile Device (Apple Mobile Device) . (.Apple Inc. - MobileDeviceService.) - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
        O23 - Service: Service Bonjour (Bonjour Service) . (.Apple Inc. - Bonjour Service.) - C:\Program Files\Bonjour\mDNSResponder.exe
        O23 - Service: Biometric Authentication Service (DpHost) . (.DigitalPersona, Inc. - DigitalPersona Local Host.) - C:\Program Files\DigitalPersona\Bin\DpHostW.exe
        O23 - Service: Service Google Update (gupdate) (gupdate) . (.Google Inc. - Google Installer.) - C:\Program Files\Google\Update\GoogleUpdate.exe
        O23 - Service: HP Health Check Service (HP Health Check Service) . (.Hewlett-Packard - HP Health Check Service.) - C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Service.exe
        O23 - Service: hpqwmiex (hpqwmiex) . (.Hewlett-Packard Development Company, L.P. - hpqwmiex Module.) - C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe
        O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) . (.Intel Corporation - RAID Monitor.) - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
        O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) . (.Hewlett-Packard Company - LightScribe Service.) - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
        O23 - Service: NVIDIA Display Driver Service (nvsvc) . (.NVIDIA Corporation - NVIDIA Driver Helper Service, Version 187.6.) - C:\WINDOWS\System32\nvvsvc.exe
        O23 - Service: QuickPlay Background Capture Service (QBCS) (QPCapSvc) . (.Pas de propriétaire - CLCapSvc Module.) - C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
        O23 - Service: QuickPlay Task Scheduler (QTS) (QPSched) . (.Pas de propriétaire - CLSched Module.) - C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe
        ~ Scan Services in 00mn 00s

        ---\\ Enumération Active Desktop & MHTML Editor (O24)
        O24 - Default MHTML Editor: Last - .(...) - (.not file.)
        ~ Scan Desktop Component in 00mn 00s

        ---\\ BootExecute (O34)
        O34 - HKLM BootExecute: (autocheck autochk *) - File not found
        ~ Scan Keys in 00mn 00s

        ---\\ Tâches planifiées en automatique (O39)
        O39 - APT:Automatic Planified Task - C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
        O39 - APT:Automatic Planified Task - C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
        [MD5.F02A533F517EB38333CB12A9E8963773] [APT] [GoogleUpdateTaskMachineCore] (.Google Inc..) -- C:\Program Files\Google\Update\GoogleUpdate.exe
        [MD5.F02A533F517EB38333CB12A9E8963773] [APT] [GoogleUpdateTaskMachineUA] (.Google Inc..) -- C:\Program Files\Google\Update\GoogleUpdate.exe
        [MD5.523D786AB9BFC3C228B8C851D402F502] [APT] [HP Health Check] (.Hewlett-Packard.) -- c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
        [MD5.79197AB8FC20E781BA141E291866A909] [APT] [{C78E7933-C7F9-41E9-901A-41EB46C58285}] (.Skype Technologies S.A..) -- C:\Program Files\Skype\Phone\Skype.exe
        [MD5.34EBD4FF6A24D86BB4716D6AFCC1A89B] [APT] [AppleSoftwareUpdate] (.Apple Inc..) -- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
        ~ Scan Scheduled Task in 00mn 03s

        ---\\ Composants installés (ActiveSetup Installed Components) (O40)
        O40 - ASIC: Microsoft Windows Media Player - >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Microsoft Windows Media Player Setup Utility.) -- C:\Windows\system32\unregmp2.exe
        O40 - ASIC: Internet Explorer - >{26923b43-4d38-484f-9b9e-de460746276c} . (.Microsoft Corporation - IE Per-User Initialization Utility.) -- C:\Windows\system32\ie4uinit.exe
        O40 - ASIC: Browser Customizations - >{60B49E34-C7CC-11D0-8953-00A0C90347FF} . (.Microsoft Corporation - IEAK branding.) -- C:\Windows\system32\iedkcs32.dll
        O40 - ASIC: Viewpoint Media Player - {03F998B2-0E00-11D3-A498-00104B6EB52E} . (.Viewpoint Corporation - Viewpoint Media Player for Internet Explorer.) -- C:\Program Files\Viewpoint\Viewpoint Experience Technology\AxMetaStream.dll
        O40 - ASIC: Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608500} . (.Sun Microsystems, Inc. - Java(TM) Platform SE binary.) -- C:\Program Files\Java\jre6\bin\regutils.dll
        O40 - ASIC: LightScribe Control Panel - {10880D85-AAD9-4558-ABDC-2AB1552D831F} . (.Hewlett-Packard Company - Pas de description.) -- C:\Program Files\Common Files\LightScribe\LSRunOnce.exe
        O40 - ASIC: Viewpoint Media Player - {1B00725B-C455-4DE6-BFB6-AD540AD427CD} . (.Viewpoint Corporation - Viewpoint Media Player for Internet Explorer.) -- C:\Program Files\Viewpoint\Viewpoint Experience Technology\AxMetaStream.dll
        O40 - ASIC: Microsoft Windows Media Player 11.0 - {22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Windows Media Player Extension.) -- C:\WINDOWS\System32\wmpdxm.dll
        O40 - ASIC: Microsoft Windows Media Player - {6BF52A52-394A-11d3-B153-00C04F79FAA6} . (.Microsoft Corporation - Windows Media Player.) -- C:\Windows\system32\wmp.dll
        O40 - ASIC: Internet Explorer - {89820200-ECBD-11cf-8B85-00AA005B4383} . (.Microsoft Corporation - IE Per-User Initialization Utility.) -- C:\Windows\system32\ie4uinit.exe
        O40 - ASIC: (no name) - {89B4C1CD-B018-4511-B0A1-5476DBF70820} . (.Microsoft Corporation - Microsoft .NET IE SECURITY REGISTRATION.) -- C:\Windows\system32\mscories.dll
        ~ Scan Active Setup in 00mn 00s

        ---\\ Pilotes lancés au démarrage (O41)
        O41 - Driver: (AFD) . (.Microsoft Corporation - Ancillary Function Driver for WinSock.) - C:\Windows\system32\drivers\afd.sys
        O41 - Driver: (avipbb) . (.Avira GmbH - Avira Driver for Security Enhancement.) - C:\Windows\system32\DRIVERS\avipbb.sys
        O41 - Driver: (cdrom) . (.Microsoft Corporation - SCSI CD-ROM Driver.) - C:\Windows\system32\DRIVERS\cdrom.sys
        O41 - Driver: C:\Windows\system32\drivers\dfsc.sys (DfsC) . (.Microsoft Corporation - DFS Namespace Client Driver.) - C:\Windows\system32\Drivers\dfsc.sys
        O41 - Driver: (i8042prt) . (.Microsoft Corporation - i8042 Port Driver.) - C:\Windows\system32\DRIVERS\i8042prt.sys
        O41 - Driver: (kbdclass) . (.Microsoft Corporation - Keyboard Class Driver.) - C:\Windows\system32\DRIVERS\kbdclass.sys
        O41 - Driver: (kbdhid) . (.Microsoft Corporation - HID Keyboard Filter Driver.) - C:\Windows\system32\DRIVERS\kbdhid.sys
        O41 - Driver: (mouclass) . (.Microsoft Corporation - Mouse Class Driver.) - C:\Windows\system32\DRIVERS\mouclass.sys
        O41 - Driver: (NetBIOS) . (.Microsoft Corporation - NetBIOS interface driver.) - C:\Windows\system32\DRIVERS\netbios.sys
        O41 - Driver: (netbt) . (.Microsoft Corporation - MBT Transport driver.) - C:\Windows\system32\DRIVERS\netbt.sys
        O41 - Driver: (nsiproxy) . (.Microsoft Corporation - NSI Proxy.) - C:\Windows\system32\drivers\nsiproxy.sys
        O41 - Driver: C:\Windows\system32\drivers\pacer.sys (PSched) . (.Microsoft Corporation - QoS Packet Scheduler.) - C:\Windows\system32\DRIVERS\pacer.sys
        O41 - Driver: (RasAcd) . (.Microsoft Corporation - RAS Automatic Connection Driver.) - C:\Windows\system32\DRIVERS\rasacd.sys
        O41 - Driver: (rdbss) . (.Microsoft Corporation - Redirected Drive Buffering SubSystem Driver.) - C:\Windows\system32\DRIVERS\rdbss.sys
        O41 - Driver: (RDPCDD) . (.Microsoft Corporation - RDP Miniport.) - C:\Windows\system32\DRIVERS\RDPCDD.sys
        O41 - Driver: (RDPENCDD) . (.Microsoft Corporation - RDP Miniport.) - C:\Windows\system32\drivers\rdpencdd.sys
        O41 - Driver: C:\Windows\system32\tcpipcfg.dll (Smb) . (.Microsoft Corporation - SMB Transport driver.) - C:\Windows\system32\DRIVERS\smb.sys
        O41 - Driver: (ssmdrv) . (.Avira GmbH - AVIRA SnapShot Driver.) - C:\Windows\system32\DRIVERS\ssmdrv.sys
        O41 - Driver: C:\Windows\system32\tcpipcfg.dll (tdx) . (.Microsoft Corporation - TDI Translation Driver.) - C:\Windows\system32\DRIVERS\tdx.sys
        O41 - Driver: (TermDD) . (.Microsoft Corporation - Terminal Server Driver.) - C:\Windows\system32\DRIVERS\termdd.sys
        O41 - Driver: (VgaSave) . (.Microsoft Corporation - VGA/Super VGA Video Driver.) - C:\Windows\system32\drivers\vga.sys
        O41 - Driver: (Wanarpv6) . (.Microsoft Corporation - MS Remote Access and Routing ARP Driver.) - C:\Windows\system32\DRIVERS\wanarp.sys
        ~ Scan Drivers in 00mn 00s

        ---\\ Logiciels installés (O42)
        O42 - Logiciel: 7-Zip 9.20 - (.Pas de propriétaire.) [HKLM] -- 7-Zip
        O42 - Logiciel: AP Tuner 3.08 - (.Pas de propriétaire.) [HKLM] -- AP Tuner 3.08
        O42 - Logiciel: Adobe Flash Player 11 Plugin - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player Plugin
        O42 - Logiciel: Adobe Reader X (10.1.1) - Français - (.Adobe Systems Incorporated.) [HKLM] -- {AC76BA86-7AD7-1036-7B44-AA1000000001}
        O42 - Logiciel: Adobe Shockwave Player - (.Adobe Systems, Inc..) [HKLM] -- {1BDC9633-895B-4842-BCB6-8FA1EC2A3C5A}
        O42 - Logiciel: Antidote HD - (.Druide informatique inc..) [HKLM] -- {56CDB4FE-895F-4E0D-8BB4-9A8D4310898D}
        O42 - Logiciel: Any Video Converter 3.2.7 - (.Any-Video-Converter.com.) [HKLM] -- Any Video Converter_is1
        O42 - Logiciel: Apple Application Support - (.Apple Inc..) [HKLM] -- {B3575D00-27EF-49C2-B9E0-14B3D954E992}
        O42 - Logiciel: Apple Mobile Device Support - (.Apple Inc..) [HKLM] -- {C23CD6DA-1958-43A5-ADD0-59396572E02E}
        O42 - Logiciel: Apple Software Update - (.Apple Inc..) [HKLM] -- {789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}
        O42 - Logiciel: Assistant de connexion Windows Live - (.Microsoft Corporation.) [HKLM] -- {DCE8CD14-FBF5-4464-B9A4-E18E473546C7}
        O42 - Logiciel: AuthenTec Fingerprint Sensor Minimum Install - (.AuthenTec.) [HKLM] -- {7F362F06-A9A3-440F-8B19-6A01A72723C4}
        O42 - Logiciel: Avira AntiVir Personal - Free Antivirus - (.Avira GmbH.) [HKLM] -- Avira AntiVir Desktop
        O42 - Logiciel: Bonjour - (.Apple Inc..) [HKLM] -- {D03482C5-9AD8-496D-B388-692AE04C93AF}
        O42 - Logiciel: CCleaner - (.Piriform.) [HKLM] -- CCleaner
        O42 - Logiciel: CyberLink YouCam - (.CyberLink Corp..) [HKLM] -- InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}
        O42 - Logiciel: DigitalPersona Personal 3.0.0 - (.DigitalPersona, Inc..) [HKLM] -- {C7AF7F33-9092-997E-2D29-DE8095863FE3}
        O42 - Logiciel: EA Link - (.Electronic Arts.) [HKLM] -- InstallShield_{F5577101-33CC-4711-8235-3A95BCD49DB0}
        O42 - Logiciel: FoxTab PDF Converter - (.Pas de propriétaire.) [HKCU] -- FoxTab PDF Converter
        O42 - Logiciel: GTA2 - (.Pas de propriétaire.) [HKLM] -- {2987EE84-C4EE-4FF5-8160-32DE00D6ABC6}
        O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM] -- {A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
        O42 - Logiciel: Google Earth - (.Google.) [HKLM] -- {5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}
        O42 - Logiciel: Grand Theft Auto - (.Pas de propriétaire.) [HKLM] -- {93AE605A-3FD6-40B7-A7EA-D64DA4EABF21}
        O42 - Logiciel: HP Active Support Library - (.Hewlett-Packard.) [HKLM] -- {5DAA9C36-8F8B-462F-8CCA-E205BC3751F5}
        O42 - Logiciel: HP Customer Experience Enhancements - (.Hewlett-Packard.) [HKLM] -- {BD0E2B92-3814-46F0-893B-4612EA010C7E}
        O42 - Logiciel: HP Customer Participation Program 8.0 - (.HP.) [HKLM] -- HPExtendedCapabilities
        O42 - Logiciel: HP Deskjet 8.0 Software - (.HP.) [HKLM] -- {58535A90-1788-44f5-80BB-CFF62D9CE6D5}
        O42 - Logiciel: HP Doc Viewer - (.Hewlett-Packard.) [HKLM] -- {082702D5-5DD8-4600-BCE5-48B15174687F}
        O42 - Logiciel: HP Easy Setup - Frontend - (.Hewlett-Packard.) [HKLM] -- {9885A11E-60E4-417C-B58B-8B31B21C0B8A}
        O42 - Logiciel: HP Help and Support - (.Hewlett-Packard.) [HKLM] -- {31216452-5540-4C96-B754-94890A63D5AB}
        O42 - Logiciel: HP Imaging Device Functions 8.0 - (.HP.) [HKLM] -- HP Imaging Device Functions
        O42 - Logiciel: HP Integrated Module with Bluetooth wireless technology 6.0.1.5500 - (.HP.) [HKLM] -- {03D1988F-469F-4843-8E6E-E5FE9D17889D}
        O42 - Logiciel: HP Photosmart Essential - (.HP.) [HKLM] -- {EB21A812-671B-4D08-B974-2A347F0D8F70}
        O42 - Logiciel: HP Photosmart Essential 2.5 - (.HP.) [HKLM] -- HP Photosmart Essential
        O42 - Logiciel: HP Quick Launch Buttons 6.30 E1 - (.Hewlett-Packard.) [HKLM] -- {34D2AB40-150D-475D-AE32-BD23FB5EE355}
        O42 - Logiciel: HP QuickPlay 3.6 - (.Pas de propriétaire.) [HKLM] -- {45D707E9-F3C4-11D9-A373-0050BAE317E1}
        O42 - Logiciel: HP QuickTouch 1.00 C4 - (.Hewlett-Packard.) [HKLM] -- {7DC4A410-9986-4329-9E5D-687B2C42CA39}
        O42 - Logiciel: HP Solution Center 8.0 - (.HP.) [HKLM] -- HP Solution Center & Imaging Support Tools
        O42 - Logiciel: HP Update - (.Hewlett-Packard.) [HKLM] -- {2EFA4E4C-7B5F-48F7-A1C0-1AA882B7A9C3}
        O42 - Logiciel: HP User Guides 0087 - (.Hewlett-Packard .) [HKLM] -- {4D49757C-367A-4333-BDB3-68966162B14E}
        O42 - Logiciel: HP Wireless Assistant - (.Hewlett-Packard.) [HKLM] -- {CBAE4F50-9FC9-4557-AB36-9826DF3C103C}
        O42 - Logiciel: HPNetworkAssistant - (.Hewlett-Packard..) [HKLM] -- {228C6B46-64E2-404E-898A-EF0830603EF4}
        O42 - Logiciel: Hauppauge MCE XP/Vista Software Encoder (2.0.25149) - (.Hauppauge Computer Works, Inc..) [HKLM] -- Hauppauge MCE2005 Software Encoder
        O42 - Logiciel: Hewlett-Packard Active Check for Health Check - (.Hewlett-Packard.) [HKLM] -- {254C37AA-6B72-4300-84F6-98A82419187E}
        O42 - Logiciel: Hewlett-Packard Asset Agent for Health Check - (.HP.) [HKLM] -- {669D4A35-146B-4314-89F1-1AC3D7B88367}
        O42 - Logiciel: Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) - (.Microsoft Corporation.) [HKLM] -- {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB953595
        O42 - Logiciel: Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) - (.Microsoft Corporation.) [HKLM] -- {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB958484
        O42 - Logiciel: Installation Windows Live - (.Microsoft Corporation.) [HKLM] -- WinLiveSuite_Wave3
        O42 - Logiciel: Installation Windows Live - (.Microsoft Corporation.) [HKLM] -- {133742BA-6F46-4D3E-85AF-78631D9AD8B8}
        O42 - Logiciel: Intel® Matrix Storage Manager - (.Pas de propriétaire.) [HKLM] -- {9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}
        O42 - Logiciel: Java(TM) 6 Update 2 - (.Sun Microsystems, Inc..) [HKLM] -- {3248F0A8-6813-11D6-A77B-00B0D0160020}
        O42 - Logiciel: Java(TM) 6 Update 26 - (.Oracle.) [HKLM] -- {26A24AE4-039D-4CA4-87B4-2F83216022FF}
        O42 - Logiciel: Junk Mail filter update - (.Microsoft Corporation.) [HKLM] -- {8E5233E1-7495-44FB-8DEB-4BE906D59619}
        O42 - Logiciel: League of Legends - (.Riot Games.) [HKLM] -- {92606477-9366-4D3B-8AE3-6BE4B29727AB}
        O42 - Logiciel: MSVCRT - (.Microsoft.) [HKLM] -- {22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
        O42 - Logiciel: MSXML 4.0 SP2 (KB954430) - (.Microsoft Corporation.) [HKLM] -- {86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
        O42 - Logiciel: MSXML 4.0 SP2 (KB973688) - (.Microsoft Corporation.) [HKLM] -- {F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
        O42 - Logiciel: Malwarebytes' Anti-Malware - (.Malwarebytes Corporation.) [HKLM] -- Malwarebytes' Anti-Malware_is1
        O42 - Logiciel: Microsoft .NET Framework 3.5 SP1 - (.Microsoft Corporation.) [HKLM] -- Microsoft .NET Framework 3.5 SP1
        O42 - Logiciel: Microsoft .NET Framework 3.5 SP1 - (.Microsoft Corporation.) [HKLM] -- {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
        O42 - Logiciel: Microsoft .NET Framework 4 Client Profile - (.Microsoft Corporation.) [HKLM] -- Microsoft .NET Framework 4 Client Profile
        O42 - Logiciel: Microsoft .NET Framework 4 Client Profile - (.Microsoft Corporation.) [HKLM] -- {3C3901C5-3455-3E0A-A214-0B093A5070A6}
        O42 - Logiciel: Microsoft Choice Guard - (.Microsoft Corporation.) [HKLM] -- {F0E12BBA-AD66-4022-A453-A1C8A0C4D570}
        O42 - Logiciel: Microsoft Office 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-0015-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}
        O42 - Logiciel: Microsoft Office 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-0016-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}
        O42 - Logiciel: Microsoft Office 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-0018-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}
        O42 - Logiciel: Microsoft Office 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-0019-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}
        O42 - Logiciel: Microsoft Office 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-001A-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}
        O42 - Logiciel: Microsoft Office 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-001B-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}
        O42 - Logiciel: Microsoft Office 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-006E-0409-0000-0000000FF1CE}_PROR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}
        O42 - Logiciel: Microsoft Office 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-0115-0409-0000-0000000FF1CE}_PROR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}
        O42 - Logiciel: Microsoft Office 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-0117-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}
        O42 - Logiciel: Microsoft Office 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {91120000-0014-0000-0000-0000000FF1CE}_PROR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}
        O42 - Logiciel: Microsoft Office Access MUI (English) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-0015-0409-0000-0000000FF1CE}
        O42 - Logiciel: Microsoft Office Access Setup Metadata MUI (English) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-0117-0409-0000-0000000FF1CE}
        O42 - Logiciel: Microsoft Office Excel MUI (English) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-0016-0409-0000-0000000FF1CE}
        O42 - Logiciel: Microsoft Office File Validation Add-In - (.Microsoft Corporation.) [HKLM] -- {90140000-2005-0000-0000-0000000FF1CE}
        O42 - Logiciel: Microsoft Office Outlook MUI (English) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-001A-0409-0000-0000000FF1CE}
        O42 - Logiciel: Microsoft Office PowerPoint MUI (English) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-0018-0409-0000-0000000FF1CE}
        O42 - Logiciel: Microsoft Office Professional 2007 - (.Microsoft Corporation.) [HKLM] -- PROR
        O42 - Logiciel: Microsoft Office Professional 2007 - (.Microsoft Corporation.) [HKLM] -- {91120000-0014-0000-0000-0000000FF1CE}
        O42 - Logiciel: Microsoft Office Proof (English) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-001F-0409-0000-0000000FF1CE}
        O42 - Logiciel: Microsoft Office Proof (French) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-001F-040C-0000-0000000FF1CE}
        O42 - Logiciel: Microsoft Office Proof (Spanish) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-001F-0C0A-0000-0000000FF1CE}
        O42 - Logiciel: Microsoft Office Proofing (English) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-002C-0409-0000-0000000FF1CE}
        O42 - Logiciel: Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-001F-0409-0000-0000000FF1CE}_PROR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}
        O42 - Logiciel: Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-001F-040C-0000-0000000FF1CE}_PROR_{F580DDD5-8D37-4998-968E-EBB76BB86787}
        O42 - Logiciel: Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-001F-0C0A-0000-0000000FF1CE}_PROR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}
        O42 - Logiciel: Microsoft Office Publisher MUI (English) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-0019-0409-0000-0000000FF1CE}
        O42 - Logiciel: Microsoft Office Shared MUI (English) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-006E-0409-0000-0000000FF1CE}
        O42 - Logiciel: Microsoft Office Shared Setup Metadata MUI (English) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-0115-0409-0000-0000000FF1CE}
        O42 - Logiciel: Microsoft Office Word MUI (English) 2007 - (.Microsoft Corporation.) [HKLM] -- {90120000-001B-0409-0000-0000000FF1CE}
        O42 - Logiciel: Microsoft Silverlight - (.Microsoft Corporation.) [HKLM] -- {89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
        O42 - Logiciel: Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 - (.Microsoft Corporation.) [HKLM] -- {770657D0-A123-3C07-8E44-1C83EC895118}
        O42 - Logiciel: Microsoft Visual C++ 2005 Redistributable - (.Microsoft Corporation.) [HKLM] -- {710f4c1c-cc18-4c49-8cbf-51240c89a1a2}
        O42 - Logiciel: Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 - (.Microsoft Corporation.) [HKLM] -- {86CE85E6-DBAC-3FFD-B977-E4B79F83C909}
        O42 - Logiciel: Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 - (.Microsoft Corporation.) [HKLM] -- {1F1C2DFC-2D24-3E06-BCB8-725134ADF989}
        O42 - Logiciel: Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 - (.Microsoft Corporation.) [HKLM] -- {9BE518E6-ECC6-35A9-88E4-87755C07200F}
        O42 - Logiciel: Motorola SM56 Data Fax Modem - (.Pas de propriétaire.) [HKLM] -- SMSERIAL
        O42 - Logiciel: Mozilla Firefox 8.0 (x86 fr) - (.Mozilla.) [HKLM] -- Mozilla Firefox 8.0 (x86 fr)
        O42 - Logiciel: My HP Games - (.WildTangent.) [HKLM] -- WildTangent hp Master Uninstall
        O42 - Logiciel: NVIDIA Drivers - (.NVIDIA Corporation.) [HKLM] -- NVIDIA Drivers
        O42 - Logiciel: Outil de téléchargement Windows Live - (.Microsoft Corporation.) [HKLM] -- {205C6BDD-7B73-42DE-8505-9A093F35A238}
        O42 - Logiciel: PVSonyDll - (.NVIDIA Corporation.) [HKLM] -- {3D3E663D-4E7E-4577-A560-7ECDDD45548A}
        O42 - Logiciel: Pando Media Booster - (.Pando Networks Inc..) [HKLM] -- {980A182F-E0A2-4A40-94C1-AE0C1235902E}
        O42 - Logiciel: QuickPlay SlingPlayer 0.4.6 - (.SlingMedia.) [HKLM] -- SlingMedia.QPSlingPlayer_is1
        O42 - Logiciel: QuickTime - (.Apple Inc..) [HKLM] -- {C9E14402-3631-4182-B377-6B0DFB1C0339}
        O42 - Logiciel: RICOH R5C83x/84x Flash Media Controller Driver Ver.3.51.01 - (.Pas de propriétaire.) [HKLM] -- {59F6A514-9813-47A3-948C-8A155460CC2A}
        O42 - Logiciel: Realtek 8169 PCI, 8168 and 8101E PCIe Ethernet Network Card Driver for Windows Vista - (.Realtek.) [HKLM] -- {8833FFB6-5B0C-4764-81AA-06DFEED9A476}
        O42 - Logiciel: Realtek High Definition Audio Driver - (.Realtek Semiconductor Corp..) [HKLM] -- {F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}
        O42 - Logiciel: Security Update for 2007 Microsoft Office System (KB2288621) - (.Microsoft.) [HKLM] -- {91120000-00
        0
        1. RogueKiller V6.1.10 [11/18/2011] by Tigzy
          mail: tigzyRK<at>gmail<dot>com
          Feedback: http://www.geekstogo.com/forum/files/file/413-roguekiller/
          Blog: http://tigzyrk.blogspot.com

          Operating System: Windows Vista (6.0.6002 Service Pack 2) 32 bits version
          Started in : Normal mode
          User: Charles [Admin rights]
          Mode: ProxyFix -- Date : 11/27/2011 17:08:52

          ¤¤¤ Bad processes: 0 ¤¤¤

          ¤¤¤ Driver: [LOADED] ¤¤¤

          ¤¤¤ Registry Entries: 0 ¤¤¤

          Finished : << RKreport[5].txt >>
          RKreport[1].txt ; RKreport[2].txt ; RKreport[3].txt ; RKreport[4].txt ; RKreport[5].txt

          # AdwCleaner v1.319 - Logfile created 11/27/2011 at 17:10:24
          # Updated 11/20/11 at 11:00a.m by Xplode
          # Operating system : Windows Vista (TM) Home Premium Service Pack 2 (32 bits)
          # User : Charles - CHARLES-PC (Administrator)
          # Running from : C:\Users\Charles\Desktop\adwcleaner.exe
          # Option [Search]

          ***** [Services] *****

          ***** [Files / Folders] *****

          Folder Found : C:\ProgramData\Viewpoint
          Folder Found : C:\Program Files\Viewpoint

          ***** [Registry] *****

          Key Found : HKLM\SOFTWARE\MetaStream
          Key Found : HKLM\SOFTWARE\Viewpoint
          Key Found : HKLM\SOFTWARE\Classes\AxMetaStream.MetaStreamCtl
          Key Found : HKLM\SOFTWARE\Classes\AxMetaStream.MetaStreamCtl.1
          Key Found : HKLM\SOFTWARE\Classes\AxMetaStream.MetaStreamCtlSecondary
          Key Found : HKLM\SOFTWARE\Classes\AxMetaStream.MetaStreamCtlSecondary.1
          Key Found : HKLM\SOFTWARE\Classes\CLSID\{03F998B2-0E00-11D3-A498-00104B6EB52E}
          Key Found : HKLM\SOFTWARE\Classes\CLSID\{1B00725B-C455-4DE6-BFB6-AD540AD427CD}
          Key Found : HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2796BAE63F1801E277261BA0D77770028F20EEE4
          Key Found : HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{03F998B2-0E00-11D3-A498-00104B6EB52E}
          Key Found : HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{1B00725B-C455-4DE6-BFB6-AD540AD427CD}
          Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ViewpointMediaPlayer
          Key Found : HKLM\SOFTWARE\MozillaPlugins\@viewpoint.com/VMP

          ***** [Internet Browsers] *****

          -\\ Internet Explorer v8.0.6001.19154

          Registry is OK.

          -\\ Mozilla Firefox v8.0 (fr)

          Profile : u2uvxst2.default
          File : C:\Users\Charles\AppData\Roaming\Mozilla\Firefox\Profiles\u2uvxst2.default\prefs.js

          File is OK.

          *************************

          AdwCleaner[R1].txt - [1905 octets] - [27/11/2011 16:55:41]
          AdwCleaner[R2].txt - [1836 octets] - [27/11/2011 17:10:24]

          ########## EOF - C:\AdwCleaner[R2].txt - [1964 octets] ##########

          Dois je supprimer également avec adwcleaner?
          0
          1. lance la suppression avec ADWC, poste son rapport :D

            relance zhpdiag,

            * Clique sur l'icône représentant une loupe (« Lancer le diagnostic »)
            * Enregistre le rapport sur ton Bureau à l'aide de l'icône représentant une disquette
            * Héberge le rapport ZHPDiag.txt sur Cijoint, puis copie/colle le lien fourni dans ta prochaine réponse sur le forum :
            https://www.cjoint.com/

            ou :
            http://dl.free.fr
            ou :
            http://ww38.toofiles.com/fr/documents-upload.html
            ou :
            https://www.terafiles.net/

            tuto zhpdiag :

            http://www.premiumorange.com/zeb-help-process/zhpdiag.html

            0
            1. Je ne sais pas si ça peut avoir affecter, mais le redémarrage de mon ordinateur après avoir utiliser adwcleaner s'est mal effectué.
              J'ai du fermer mon ordinateur manuellement et ensuite le rouvrir.

              # AdwCleaner v1.319 - Logfile created 11/27/2011 at 17:38:56
              # Updated 11/20/11 at 11:00a.m by Xplode
              # Operating system : Windows Vista (TM) Home Premium Service Pack 2 (32 bits)
              # User : Charles - CHARLES-PC (Administrator)
              # Running from : C:\Users\Charles\Desktop\adwcleaner.exe
              # Option [Delete]

              ***** [Services] *****

              ***** [Files / Folders] *****

              Folder Deleted : C:\ProgramData\Viewpoint
              Folder Deleted : C:\Program Files\Viewpoint

              ***** [Registry] *****

              Key Deleted : HKLM\SOFTWARE\MetaStream
              Key Deleted : HKLM\SOFTWARE\Viewpoint
              Key Deleted : HKLM\SOFTWARE\Classes\AxMetaStream.MetaStreamCtl
              Key Deleted : HKLM\SOFTWARE\Classes\AxMetaStream.MetaStreamCtl.1
              Key Deleted : HKLM\SOFTWARE\Classes\AxMetaStream.MetaStreamCtlSecondary
              Key Deleted : HKLM\SOFTWARE\Classes\AxMetaStream.MetaStreamCtlSecondary.1
              Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{03F998B2-0E00-11D3-A498-00104B6EB52E}
              Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1B00725B-C455-4DE6-BFB6-AD540AD427CD}
              Key Deleted : HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2796BAE63F1801E277261BA0D77770028F20EEE4
              Key Deleted : HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{03F998B2-0E00-11D3-A498-00104B6EB52E}
              Key Deleted : HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{1B00725B-C455-4DE6-BFB6-AD540AD427CD}
              Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ViewpointMediaPlayer
              Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@viewpoint.com/VMP

              ***** [Internet Browsers] *****

              -\\ Internet Explorer v8.0.6001.19154

              Registry is OK.

              -\\ Mozilla Firefox v8.0 (fr)

              Profile : u2uvxst2.default
              File : C:\Users\Charles\AppData\Roaming\Mozilla\Firefox\Profiles\u2uvxst2.default\prefs.js

              File is OK.

              *************************

              AdwCleaner[R1].txt - [1905 octets] - [27/11/2011 16:55:41]
              AdwCleaner[R2].txt - [1965 octets] - [27/11/2011 17:10:24]
              AdwCleaner[S1].txt - [1926 octets] - [27/11/2011 17:38:56]

              *************************

              Temporary folder : : 24 folder(s)et 20 file(s) deleted

              ########## EOF - C:\AdwCleaner[S1].txt - [2142 octets] ##########

              https://www.cjoint.com/?AKBxdgPwFGj
              0
              1. la suite, pour le reste, je te l'indiquerai ce soir, en rentrant du boulot :D

                * /!\ Utilisateur de Vista : Ne pas oublier de désactiver l'UAC juste le temps de désinfection de ton pc, il sera à réactiver plus tard :
                Tuto : https://www.commentcamarche.net/faq/8343-vista-desactiver-l-uac

                Télécharge Malwarebytes' Anti-Malware et enregistre le sur ton bureau:
                https://www.malekal.com/tutoriel-malwarebyte-anti-malware/

                ou ici :
                https://www.commentcamarche.net/telecharger/securite/14361-malwarebytes-anti-malware/

                /!\Utilisateur de Vista et Windows 7 : Clique droit sur le logo de Malwarebytes' Anti-Malware, « exécuter en tant qu'Administrateur »

                . Double cliques sur le fichier téléchargé pour lancer le processus d'installation.
                . Dans l'onglet "mise à jour", cliques sur le bouton Recherche de mise à jour
                . si le pare-feu demande l'autorisation de se connecter pour malwarebytes, acceptes
                . Une fois la mise à jour terminé
                . rend-toi dans l'onglet, Recherche
                . Sélectionnes Exécuter un examen complet
                . Cliques sur Rechercher
                . Le scan démarre.
                . A la fin de l'analyse, un message s'affiche : L'examen s'est terminé normalement. Clique sur 'Afficher les résultats' pour afficher tous les objets trouvés.
                . Cliques sur Ok pour poursuivre.
                . Si des malwares ont été détectés, cliques sur Afficher les résultats
                . Sélectionnes tout (ou laisses cochés) et cliques sur Supprimer la sélection Malwarebytes va détruire les fichiers et clés de registre et en mettre une copie dans la quarantaine.

                . Malwarebytes va ouvrir le bloc-notes et y copier le rapport d'analyse.
                . rends toi dans l'onglet rapport/log
                . tu cliques dessus pour l'afficher une fois affiché
                . tu cliques sur edition en haut du boc notes,et puis sur sélectionner tous
                . tu recliques sur edition et puis sur copier et tu reviens sur le forum et dans ta réponse
                . Tu cliques droit dans le cadre de la réponse et coller
                . À la fin du scan, il se peut que MBAM ait besoin de redémarrer le pc pour finaliser la suppression, donc pas de panique, redémarre ton pc !!!

                Si tu as besoin d'aide regarde ce tutoriel :
                https://www.malekal.com/tutoriel-malwarebyte-anti-malware/

                0
                1. C'est finalement fait!
                  2 fois j'ai essayé de le faire et Malwarebytes a boggé.

                  Malwarebytes' Anti-Malware 1.51.2.1300
                  www.malwarebytes.org

                  Version de la base de données: 8260

                  Windows 6.0.6002 Service Pack 2
                  Internet Explorer 8.0.6001.19154

                  2011-11-28 22:03:15
                  mbam-log-2011-11-28 (22-03-15).txt

                  Type d'examen: Examen complet (C:\|D:\|)
                  Elément(s) analysé(s): 349749
                  Temps écoulé: 2 heure(s), 35 minute(s), 24 seconde(s)

                  Processus mémoire infecté(s): 0
                  Module(s) mémoire infecté(s): 0
                  Clé(s) du Registre infectée(s): 0
                  Valeur(s) du Registre infectée(s): 0
                  Elément(s) de données du Registre infecté(s): 0
                  Dossier(s) infecté(s): 0
                  Fichier(s) infecté(s): 5

                  Processus mémoire infecté(s):
                  (Aucun élément nuisible détecté)

                  Module(s) mémoire infecté(s):
                  (Aucun élément nuisible détecté)

                  Clé(s) du Registre infectée(s):
                  (Aucun élément nuisible détecté)

                  Valeur(s) du Registre infectée(s):
                  (Aucun élément nuisible détecté)

                  Elément(s) de données du Registre infecté(s):
                  (Aucun élément nuisible détecté)

                  Dossier(s) infecté(s):
                  (Aucun élément nuisible détecté)

                  Fichier(s) infecté(s):
                  c:\programdata\8t4cpopdz5m9lm.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                  c:\programdata\kmcildhhpnmcpi.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                  c:\Users\Charles\AppData\LocalLow\Sun\Java\deployment\cache\6.0\32\a5c0020-409c3f55 (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                  c:\Users\Charles\Desktop\rk_quarantine\8t4cpopdz5m9lm.exe.vir (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                  c:\Users\Charles\Desktop\rk_quarantine\kmcildhhpnmcpi.exe.vir (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                  0
                  1. super,

                    vas dans le menu demarrer, programme et fonctionnalité, désinstalle java et réinstalle la dernière version depuis son site dédié :D

                    refais une nouvelle mise à jour de MBAM, relance un nouveau scan complet, s'il trouve des choses, mets tout en quarantaine, poste son rapport :D

                    @ ++
                    0
                    1. Bon j'ai essayé à 3 reprises... et les 3 fois MBAM a arrêté de fonctionner...
                      Je vais le réessayer pendant la nuit.
                      J'espère que ça fonctionnera.
                      0
                      1. si tu vois que MBAM ne se lance pas, désinstalle le, supprime son répertoire manuellement de ton disque dure s'il y a des restants, puis résinstalle le :D

                        0
                        1. Et voila, rien n'a été trouvé.

                          Malwarebytes' Anti-Malware 1.51.2.1300
                          www.malwarebytes.org

                          Version de la base de données: 8275

                          Windows 6.0.6002 Service Pack 2
                          Internet Explorer 8.0.6001.19154

                          2011-11-30 02:53:34
                          mbam-log-2011-11-30 (02-53-34).txt

                          Type d'examen: Examen complet (C:\|D:\|)
                          Elément(s) analysé(s): 355264
                          Temps écoulé: 2 heure(s), 49 minute(s), 38 seconde(s)

                          Processus mémoire infecté(s): 0
                          Module(s) mémoire infecté(s): 0
                          Clé(s) du Registre infectée(s): 0
                          Valeur(s) du Registre infectée(s): 0
                          Elément(s) de données du Registre infecté(s): 0
                          Dossier(s) infecté(s): 0
                          Fichier(s) infecté(s): 0

                          Processus mémoire infecté(s):
                          (Aucun élément nuisible détecté)

                          Module(s) mémoire infecté(s):
                          (Aucun élément nuisible détecté)

                          Clé(s) du Registre infectée(s):
                          (Aucun élément nuisible détecté)

                          Valeur(s) du Registre infectée(s):
                          (Aucun élément nuisible détecté)

                          Elément(s) de données du Registre infecté(s):
                          (Aucun élément nuisible détecté)

                          Dossier(s) infecté(s):
                          (Aucun élément nuisible détecté)

                          Fichier(s) infecté(s):
                          (Aucun élément nuisible détecté)
                          0
                          1. super,

                            comment se comprte le pc?

                            est ce qu'il fonctionne correctement ?

                            0
                            1. Je peux me servir de mon ordinateur normalement, mais il semble être un peu plus lent.
                              Ce n'est pas la fin du monde.

                              Par contre, 2 autres petites questions:
                              Premièrement, l'icône habituelle de system fix a été supprimé, mais il reste encore une petite icône sur mon bureau. Dois-je simplement la supprimer manuellement?

                              De plus, lorsque je clique sur l'onglet démarrer en bas à gauche, la petite fenêtre s'ouvre normalement, mais je n'ai plus d'options...
                              Je peux simplement cliquer sur le bouton ordinateur, les autres ont disparu...

                              Et ça je n'ai aucune idée comment les faire revenir.
                              0
                              1. Premièrement, l'icône habituelle de system fix a été supprimé, mais il reste encore une petite icône sur mon bureau. Dois-je simplement la supprimer manuellement?

                                oui, tu peux le supprimer,

                                De plus, lorsque je clique sur l'onglet démarrer en bas à gauche, la petite fenêtre s'ouvre normalement, mais je n'ai plus d'options...
                                Je peux simplement cliquer sur le bouton ordinateur, les autres ont disparu...


                                lance zhpfix, clique sur Hiddenfix, regarde voir si tout est visible de nouveau !

                                0
                                1. Ce n'est pas réapparu...
                                  Mais bon, c'est pas si grave.
                                  Voici ce que le rapport dit:

                                  Rapport de ZHPFix 1.12.3372 par Nicolas Coolman, Update du 22/11/2011
                                  Fichier d'export Registre :
                                  Run by Charles at 2011-11-30 14:03:36
                                  Windows Vista Home Premium Edition, 32-bit Service Pack 2 (Build 6002)
                                  Web site : http://www.premiumorange.com/zeb-help-process/zhpfix.html

                                  ========== Dossiers/Fichiers cachés restaurés ==========
                                  Mes images (My Pictures) : 0
                                  Ma musique (My Music) : 13 Restauré(s) avec succès
                                  Ma Video (My Video) : 9 Restauré(s) avec succès
                                  Mes Favoris (My Favorites) : 3 Restauré(s) avec succès
                                  Mes Documents (My Documents) : 33 Restauré(s) avec succès
                                  Mon Bureau (My Desktop) : 1 Restauré(s) avec succès
                                  Menu demarrer (Programs) : 6 Restauré(s) avec succès
                                  Dossier utilisateur (AppData) : 2365 Restauré(s) avec succès
                                  Programmes (Program Files) : 14 Restauré(s) avec succès

                                  ========== Récapitulatif ==========
                                  2444 : Dossiers/Fichiers cachés restaurés

                                  End of clean in 03mn 36s

                                  ========== Chemin de fichier rapport ==========
                                  C:\ZHP\ZHPFix[R1].txt - 2011-11-30 14:03:36 [979]
                                  0
                                  1. désactive l'UAC,

                                    * Télécharge Zeb-Restore :
                                    http://telechargement.zebulon.fr/zeb-restore.html
                                    Mets le dans un dossier, sur ton bureau par exemple.
                                    Lance Zebrestore en faisant un clique droit et le lancer en tant qu'administrateur !

                                    coche la/les case(s) suivante(s) :

                                    RegEdit
                                    Clés RUN
                                    Bouton Arrêter
                                    Gestionnaire des tâches
                                    Panneau de configuration

                                    Bureau
                                    Réparation IE
                                    Sites de confiance et sensibles
                                    Préfixes et Protocoles Internet
                                    Ajout/Suppression de programmes

                                    Policies
                                    Fichier Hosts
                                    Windows Update
                                    Extension des fichiers
                                    Restauration du système

                                    Ne coche que la/les case(s) indiquée(s).
                                    Clique sur le bouton <Restaurer>.
                                    Quitte le programme.

                                    0
                                    1. Ce n'est pas réapparu.
                                      J'ai fait un redémarrage de l'ordinateur et le seul changement que j'ai aperçu est que mon fond d'écran a passé du noir au bleu...
                                      0
                                      • 1
                                      • 2