Alerte police ! Voulez-vous acheter un vouche

Fermé
Guigui99 - 16 avril 2012 à 21:14
Valuu Messages postés 2163 Date d'inscription lundi 4 octobre 2010 Statut Contributeur Dernière intervention 12 avril 2015 - 16 avril 2012 à 23:29
Bonjour,

Bon voilà dès que je lance le PC j'ai une fenêtre de la police qui me dit de payer 100€ :)

Bon c'est très mal écrit, c'est un fake à 150% mais je suis bloqué car ça reste en plein écran et impossible de faire autre chose...

Donc là je suis en mode sans échec, j'ai cherché un peu et j'ai effectué un zhpdiag comme vu dans un autre topic...

Voici le rapport =>

Rapport de ZHPDiag v1.30.06 par Nicolas Coolman, Update du 16/04/2012
Run by U186132 at 16/04/2012 20:58:46
Web site : http://www.premiumorange.com/zeb-help-process/zhpdiag.html
Web site : http://nicolascoolman.skyrock.com/
State : Problème connexion internet


---\\ Web Browser
MSIE: Internet Explorer v7.0.6002.18005 (Defaut)

---\\ Windows Product Information
~ Langage: Français
Windows Vista Business Edition, 32-bit Service Pack 2 (Build 6002)
Windows Server License Manager Script : OK
Windows Automatic Updates : OK

---\\ System Information
~ Processor: x86 Family 6 Model 15 Stepping 11, GenuineIntel
~ Operating System: 32 Bits
Boot mode: Sans échec avec prise en charge du réseau (Fail-safe with network boot)
Total RAM: 2046 MB (78% free)
System Restore: Désactivé (Disabled)
System drive C: has 27 GB (36%) free of 75 GB

---\\ Logged in mode
~ Computer Name: B698218
~ User Name: U186132
~ All Users Names: pilote, Administrateur,
~ Unselected Option: O45,O61,O89
Logged in as User

---\\ Environnement Variables
~ System Unit : C:\
~ %AppData% : C:\Users\u186132\AppData\Roaming\
~ %Desktop% : C:\Users\u186132\Desktop\
~ %Favorites% : C:\Users\u186132\Favorites\
~ %LocalAppData% : C:\Users\u186132\AppData\Local\
~ %StartMenu% : C:\Users\u186132\AppData\Roaming\Microsoft\Windows\Start Menu\
~ %Windir% : C:\Windows\
~ %System% : C:\Windows\System32\

---\\ DOS/Devices
C:\ Hard drive, Flash drive, Thumb drive (Free 27 Go of 75 Go)
D:\ CD-ROM drive (Not Inserted)



---\\ Security Center & Tools Informations
[HKLM\SOFTWARE\Microsoft\Security Center] AntiSpywareOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center] AntiVirusOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center] AntiVirusDisableNotify: OK
[HKLM\SOFTWARE\Microsoft\Security Center] FirewallDisableNotify: OK
[HKLM\SOFTWARE\Microsoft\Security Center] FirewallOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center] UpdatesDisableNotify: OK
[HKLM\SOFTWARE\Microsoft\Security Center] UacDisableNotify: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiSpywareOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusDisableNotify: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallDisableNotify: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] UpdatesDisableNotify: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] UacDisableNotify: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoDesktop: OK
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoFolderOptions: OK
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoDesktop: OK
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoStartMenuSubFolder: OK
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoResolveSearch: OK
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoClose: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System] NoActiveDesktopChanges: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: Modified
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: OK
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced] Start_ShowSearch: OK
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced] Start_ShowMyComputer: OK
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings] WarnOnHTTPSToHTTPRedirect: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK
[HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] Load: OK
[HKLM\SYSTEM\CurrentControlSet\Services] wscsvc : OK
~ Scan Security Center in 00mn 00s



---\\ Recherche particulière de fichiers génériques
[MD5.D07D4C3038F3578FFCE1C0237F2A1253] - (.Microsoft Corporation - Explorateur Windows.) (.10/04/2009 - 22:27:38.) -- C:\Windows\Explorer.exe [2926592]
[MD5.101BA3EA053480BB5D957EF37C06B5ED] - (.Microsoft Corporation - Application de démarrage de Windows.) (.21/01/2008 - 03:24:09.) -- C:\Windows\System32\Wininit.exe [96768]
[MD5.72A45F23D07C6B13D23B84D043A81059] - (.Microsoft Corporation - Extensions Internet pour Win32.) (.20/10/2011 - 16:55:43.) -- C:\Windows\System32\wininet.dll [834048]
[MD5.898E7C06A350D4A1A64A9EA264D55452] - (.Microsoft Corporation - Application d'ouverture de session Windows.) (.10/04/2009 - 22:28:14.) -- C:\Windows\System32\Winlogon.exe [314368]
[MD5.3911B972B55FEA0478476B2E777B29FA] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) (.21/04/2011 - 14:58:27.) -- C:\Windows\system32\Drivers\AFD.sys [273408]
[MD5.1F05B78AB91C9075565A9D8A4B880BC4] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.10/04/2009 - 22:32:28.) -- C:\Windows\system32\Drivers\atapi.sys [19944]
[MD5.7ADD03E75BEB9E6DD102C3081D29840A] - (.Microsoft Corporation - CD-ROM File System Driver.) (.21/01/2008 - 03:24:15.) -- C:\Windows\system32\Drivers\Cdfs.sys [70144]
[MD5.6B4BFFB9BECD728097024276430DB314] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.10/04/2009 - 20:39:18.) -- C:\Windows\system32\Drivers\Cdrom.sys [67072]
[MD5.622C41A07CA7E6DD91770F50D532CB6C] - (.Microsoft Corporation - DFS Namespace Client Driver.) (.14/04/2011 - 15:59:03.) -- C:\Windows\system32\Drivers\DfsC.sys [75264]
[MD5.062452B7FFD68C8C042A6261FE8DFF4A] - (.Microsoft Corporation - High Definition Audio Bus Driver.) (.10/04/2009 - 20:42:44.) -- C:\Windows\system32\Drivers\HDAudBus.sys [561152]
[MD5.22D56C8184586B7A1F6FA60BE5F5A2BD] - (.Microsoft Corporation - Pilote de port i8042.) (.21/01/2008 - 03:23:44.) -- C:\Windows\system32\Drivers\i8042prt.sys [54784]
[MD5.8793643A67B42CEC66490B2A0CF92D68] - (.Microsoft Corporation - IP Network Address Translator.) (.21/01/2008 - 03:24:51.) -- C:\Windows\system32\Drivers\IpNat.sys [100864]
[MD5.1E94971C4B446AB2290DEB71D01CF0C2] - (.Microsoft Corporation - Windows NT SMB Minirdr.) (.29/04/2011 - 14:24:40.) -- C:\Windows\system32\Drivers\MRxSmb.sys [106496]
[MD5.ECD64230A59CBD93C85F1CD1CAB9F3F6] - (.Microsoft Corporation - MBT Transport driver.) (.10/04/2009 - 20:45:38.) -- C:\Windows\system32\Drivers\netBT.sys [185856]
[MD5.6A4A98CEE84CF9E99564510DDA4BAA47] - (.Microsoft Corporation - Pilote du système de fichiers NT.) (.10/04/2009 - 22:32:50.) -- C:\Windows\system32\Drivers\ntfs.sys [1083880]
[MD5.8A79FDF04A73428597E2CAF9D0D67850] - (.Microsoft Corporation - Pilote de port parallèle.) (.21/01/2008 - 03:23:27.) -- C:\Windows\system32\Drivers\Parport.sys [79360]
[MD5.A214ADBAF4CB47DD2728859EF31F26B0] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.21/01/2008 - 03:25:21.) -- C:\Windows\system32\Drivers\Rasl2tp.sys [76288]
[MD5.943B18305EAE3935598A9B4A3D560B4C] - (.Microsoft Corporation - Microsoft RDP Device redirector.) (.10/04/2009 - 20:52:36.) -- C:\Windows\system32\Drivers\rdpdr.sys [248320]
[MD5.7B75299A4D201D6A6533603D6914AB04] - (.Microsoft Corporation - SMB Transport driver.) (.10/04/2009 - 20:45:24.) -- C:\Windows\system32\Drivers\smb.sys [66560]
[MD5.76B06EB8A01FC8624D699E7045303E54] - (.Microsoft Corporation - TDI Translation Driver.) (.10/04/2009 - 20:45:58.) -- C:\Windows\system32\Drivers\tdx.sys [72192]
[MD5.147281C01FCB1DF9252DE2A10D5E7093] - (.Microsoft Corporation - Pilote de cliché instantané du volume.) (.10/04/2009 - 22:32:56.) -- C:\Windows\system32\Drivers\volsnap.sys [226280]
~ Scan Generic Processes in 00mn 00s



---\\ Etat des fichiers cachés (Caché/Total)
~ Mes images (My Pictures) : Non accessible (Not found)
~ Mes musiques (My Musics) : 1/2
~ Mes Videos (My Videos) : Non accessible (Not found)
~ Mes Favoris (My Favorites) : 2/22
~ Mes Documents (My Documents) : 16/8363
~ Mon Bureau (My Desktop) : 1/17
~ Menu demarrer (Programs) : 7/23
~ Scan Hidden Files in 00mn 01s



---\\ Processus lancés
[MD5.9F19140289278709F36AF738906B6EE6] - (...) -- C:\Program Files\ZHPDiag\ZHPDiag.exe [4508672] [PID.]
[MD5.27D036FB3D22CA8A6662FE960D1A937D] - (.Symantec Corporation - Symantec Service Framework.) -- C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe [108392] [PID.]
[MD5.BA2FB8F8AB24D0279CAA98A4C118150E] - (.Symantec Corporation - Symantec AntiVirus.) -- C:\Program Files\NavNT\Rtvscan.exe [2477304] [PID.]
~ Scan Processes Running in 00mn 00s



---\\ Mozilla Firefox, Plugins,Demarrage,Recherche,Extensions (P2,M0,M1,M2,M3)
C:\Users\u186132\AppData\Roaming\Mozilla\Firefox\Profiles\ipsl99db.default\prefs.js
M3 - MFPP: Plugins - [U186132] -- C:\Program Files\Mozilla FireFox\searchplugins\amazondotcom.xml
M3 - MFPP: Plugins - [U186132] -- C:\Program Files\Mozilla FireFox\searchplugins\answers.xml
M3 - MFPP: Plugins - [U186132] -- C:\Program Files\Mozilla FireFox\searchplugins\creativecommons.xml
M3 - MFPP: Plugins - [U186132] -- C:\Program Files\Mozilla FireFox\searchplugins\eBay.xml
M3 - MFPP: Plugins - [U186132] -- C:\Program Files\Mozilla FireFox\searchplugins\google.xml
M3 - MFPP: Plugins - [U186132] -- C:\Program Files\Mozilla FireFox\searchplugins\wikipedia.xml
M3 - MFPP: Plugins - [U186132] -- C:\Program Files\Mozilla FireFox\searchplugins\yahoo.xml
P2 - FPN:Firefox Plugin Navigator . (.Sun Microsystems, Inc. - NPRuntime Script Plug-in Library for Java(TM) Deploy.) -- C:\Program Files\Mozilla Firefox\Plugins\npdeployJava1.dll
P2 - FPN:Firefox Plugin Navigator . (.mozilla.org - Default Plug-in.) -- C:\Program Files\Mozilla Firefox\Plugins\npnul32.dll
P2 - FPN:Firefox Plugin Navigator . (.Adobe Systems Inc. - Adobe PDF Plug-In For Firefox and Netscape "9.3.3".) -- C:\Program Files\Mozilla Firefox\Plugins\nppdf32.dll
P2 - FPN: [HKLM] [@adobe.com/FlashPlayer] - (...) -- C:\Windows\system32\Macromed\Flash\NPSWF32.dll
P2 - FPN: [HKLM] [@java.com/JavaPlugin] - (.Sun Microsystems, Inc. - Next Generation Java Plug-in 1.6.0_21 for Mozilla browsers.) -- C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
P2 - FPN: [HKLM] [@Microsoft.com/NpCtrl,version=1.0] - (. Microsoft Corporation - 4.0.51204.0.) -- c:\Program Files\Microsoft Silverlight\4.0.51204.0\npctrl.dll
P2 - FPN: [HKLM] [@microsoft.com/OfficeAuthz,version=14.0] - (.Microsoft Corporation - Office Authorization plug-in for NPAPI browsers.) -- C:\Program Files\MsOffice\Office14\NPAUTHZ.dll
P2 - FPN: [HKLM] [@microsoft.com/SharePoint,version=14.0] - (.Microsoft Corporation - The plug-in allows you to open and edit files using Microsoft Office a.) -- C:\Program Files\MsOffice\Office14\NPSPWRAP.dll
P2 - FPN: [HKLM] [@microsoft.com/WPF,version=3.5] - (.Microsoft Corporation - Windows Presentation Foundation (WPF) plug-in for Mozilla browsers.) -- c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
P2 - FPN: [HKLM] [@videolan.org/vlc,version=1.1.9] - (.the VideoLAN Team - Version 1.1.9, copyright 1996-2011 The VideoLAN Team<br><a href="http:.) -- C:\Program Files\VideoLAN\VLC\npvlc.dll
~ Scan Firefox Browser in 00mn 00s



---\\ Internet Explorer, Démarrage,Recherche,URLSearchHook, Phishing (R0,R1,R3,R4)
R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://portail.inetpsa.com
R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://portail.inetpsa.com
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://portail.inetpsa.com
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs,Tabs = res://ieframe.dll/tabswelcome.htm
R3 - URLSearchHook: Microsoft Url Search Hook - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} . (.Microsoft Corporation - Internet Explorer.) (7.00.6000.16386 (vista_rtm.061101-2205)) -- C:\Windows\system32\ieframe.dll
R4 - HKCU\SOFTWARE\Microsoft\Internet Explorer\PhishingFilter,Enabled = 0
~ Scan IE Browser in 00mn 00s



---\\ Internet Explorer, Proxy Management (R5)
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.inetpsa.com;<local>
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http.internetpsa.inetpsa.com
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyHttp1.1 = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll
~ Scan Proxy management in 00mn 00s



---\\ Modification d'une valeur Ini (Changed inifile value, mapped to Registry) (F2)
F2 - REG:system.ini: UserInit=c:\sys\psa\prof.exe /userinit
F2 - REG:system.ini: VMApplet=rundll32 shell32,Control_RunDLL "sysdm.cpl"
~ Scan Keys in 00mn 00s



---\\ Redirection du fichier Hosts (O1)
~ Le fichier hosts est sain (The hosts file is clean).
~ Scan Hosts File in 00mn 00s
~ Nombre de lignes (Lines number): 20



---\\ Browser Helper Objects de navigateur (O2)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} . (.Adobe Systems Incorporated - Adobe PDF Helper for Internet Explorer.) -- C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: SSOX BHO - {1E1B2879-88FF-11D2-8D96-D7ACAC95951F} . (.AVENCIS - SSOX BHO for Internet Explorer.) -- C:\Program Files\AVENCIS\SSOX\ssoxbho.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} . (.Microsoft Corporation - Microsoft Office Document Cache Handler.) -- C:\Program Files\MsOffice\Office14\URLREDIR.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} . (.Sun Microsystems, Inc. - Java(TM) Platform SE binary.) -- C:\Program Files\Java\jre6\bin\jp2ssv.dll
~ Scan BHO in 00mn 00s



---\\ Internet Explorer Toolbars (O3)
O3 - Toolbar: InfoPoste - {9ABC1666-7F12-48F4-BEA4-50B7162945A4} . (.Pas de propriétaire - InfoPoste.) -- C:\Program Files\InfoPoste\InfoPoste.dll
O3 - Toolbar: InfoPoste - {9ABC1666-7F12-48F4-BEA4-50B7162945A4} . (.Pas de propriétaire - InfoPoste.) -- C:\Program Files\InfoPoste\InfoPoste.dll
~ Scan Toolbar in 00mn 00s



---\\ Applications démarrées par registre & par dossier (O4)
O4 - HKLM\..\Run: [Windows Defender] . (.Microsoft Corporation - Windows Defender User Interface.) -- C:\Program Files\Windows Defender\MSASCui.exe
O4 - HKLM\..\Run: [SynTPStart] . (.Synaptics, Inc. - Synaptics Pointing Device starter.) -- C:\Program Files\Synaptics\SynTP\SynTPStart.exe
O4 - HKLM\..\Run: [PSAPI_Prof] . (.PSA Peugeot-Citroën - Gestion Profil Utilisateur.) -- c:\sys\psa\prof.exe
O4 - HKLM\..\Run: [SoundMAXPnP] . (.Analog Devices, Inc. - SMax4PNP.) -- C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [NvCplDaemon] . (.NVIDIA Corporation - NVIDIA Display Properties Extension.) -- C:\Windows\system32\NvCpl.dll
O4 - HKLM\..\Run: [NvMediaCenter] . (.NVIDIA Corporation - NVIDIA Media Center Library.) -- C:\Windows\system32\NvMcTray.dll
O4 - HKLM\..\Run: [PV3MonitorV2] . (...) -- c:\sys\psa\PV3AgCG.exe
O4 - HKLM\..\Run: [_SSOX] . (.AVENCIS - SSOX.) -- C:\Program Files\AVENCIS\SSOX\watcher.exe
O4 - HKLM\..\Run: [Pshare] . (.Microsoft Corporation - Microsoft (R) Windows Based Script Host.) -- C:\Windows\System32\wscript.exe
O4 - HKLM\..\Run: [QlbCtrl.exe] . (. Hewlett-Packard Development Company, L.P. - Quick Launch Buttons.) -- C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] . (.Adobe Systems Incorporated - Adobe Acrobat SpeedLauncher.) -- C:\Program Files\Adobe\AcrobatReader\Reader\Reader_sl.exe
O4 - HKLM\..\Run: [Adobe ARM] . (.Adobe Systems Incorporated - Adobe Reader and Acrobat Manager.) -- C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
O4 - HKLM\..\Run: [ccApp] . (.Symantec Corporation - Symantec User Session.) -- C:\Program Files\Common Files\Symantec Shared\ccApp.exe
O4 - HKLM\..\Run: [escan] . (.Pas de propriétaire - Application MFC test.) -- C:\sys\psa\escan.exe
O4 - HKLM\..\Run: [PV4Compagnon] . (.PSA PEUGEOT CITROEN - Application PV4Event.) -- c:\sys\psa\PV3events\P1\PV4eventclient.exe
O4 - HKLM\..\Run: [PsaBackup] . (.PSA PEUGEOT CITROEN - WMIEvent Détection USB.) -- C:\Program Files\PSABackup\PV4WMIevent.exe
O4 - HKLM\..\Run: [VpnCisco] wscript C:\Program Files\Cisco\Cisco AnyConnect Secure Mobility Client\stat_service.vbs (.not file.)
O4 - HKLM\..\Run: [ZInfoPeriph] . (.PSA PEUGEOT CITROEN - PV3Wait2InfoPeriph.) -- c:\sys\psa\PV3Wait2InfoPeriph.exe
O4 - HKCU\..\Run: [Sidebar] . (.Microsoft Corporation - Volet Windows.) -- C:\Program Files\Windows Sidebar\sidebar.exe
O4 - HKLM\..\policies\Explorer\Run: [20901] . (.Sun Microsystems, Inc. - Java(TM) Platform SE binary.) -- C:\ProgramData\Local Settings\Temp\mshhwfp.com
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] . (.Microsoft Corporation - Volet Windows.) -- C:\Program Files\Windows Sidebar\Sidebar.exe
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] oobefldr.dll
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] . (.Microsoft Corporation - Volet Windows.) -- C:\Program Files\Windows Sidebar\Sidebar.exe
O4 - HKUS\S-1-5-20\..\Run: [WindowsWelcomeCenter] oobefldr.dll
O4 - HKUS\S-1-5-21-1993962763-299502267-1801674531-246623\..\Run: [Sidebar] . (.Microsoft Corporation - Volet Windows.) -- C:\Program Files\Windows Sidebar\sidebar.exe
~ Scan Application in 00mn 00s



---\\ Autres liens utilisateurs (O4)
O4 - Global Startup: C:\Users\pilote\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk . (.Microsoft Corporation.) -- C:\Program Files\Internet Explorer\iexplore.exe
O4 - Global Startup: C:\Users\pilote\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Rechercher une imprimante.lnk . (...) -- C:\SYS\PSA\MAJ-NOY\AD Printer Manager.exe
O4 - Global Startup: C:\Users\pilote\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk . (.Microsoft Corporation.) -- C:\Program Files\Windows Media Player\wmplayer.exe
O4 - Global Startup: C:\Users\pilote\Desktop\eMeeting.url . (.Microsoft Corporation.) -- C:\Users\pilote\Desktop\eMeeting.url
O4 - Global Startup: C:\Users\pilote\Desktop\Générateur de documents.lnk . (.Microsoft Corporation.) -- C:\Program Files\Internet Explorer\iexplore.exe
O4 - Global Startup: C:\Users\pilote\Desktop\Mes documents.lnk . (...) -- C:\User\U186132
O4 - Global Startup: C:\Users\pilote\Desktop\Mémento Vista.lnk . (...) -- C:\SYS\PSA\MAJ-NOY\mementoFR.pdf
O4 - Global Startup: C:\Users\pilote\Desktop\Rechercher une imprimante.lnk . (...) -- C:\SYS\PSA\MAJ-NOY\AD Printer Manager.exe
O4 - Global Startup: C:\Users\pilote\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\eMeeting.url . (...) -- C:\Users\pilote\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\eMeeting.url
O4 - Global Startup: C:\Users\pilote\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk . (.Microsoft Corporation.) -- C:\Program Files\Internet Explorer\iexplore.exe
O4 - Global Startup: C:\Users\pilote\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Lotus Notes.lnk . (...) -- C:\sys\psa\Lotus\firstlaunch\startNotes.cmd
O4 - Global Startup: C:\Users\Administrateur\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk . (.Microsoft Corporation.) -- C:\Program Files\Internet Explorer\iexplore.exe
O4 - Global Startup: C:\Users\Administrateur\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Mail.lnk . (.Microsoft Corporation.) -- C:\Program Files\Windows Mail\WinMail.exe
O4 - Global Startup: C:\Users\Administrateur\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk . (.Microsoft Corporation.) -- C:\Program Files\Windows Media Player\wmplayer.exe
O4 - Global Startup: C:\Users\Administrateur\Desktop\Microsoft Excel 2010 Interactive Guide FRA.lnk . (...) -- C:\Program Files\Microsoft\Microsoft Excel 2010 Interactive Guide FRA\Excel.html
O4 - Global Startup: C:\Users\Administrateur\Desktop\Microsoft PowerPoint 2010 Interactive Guide FRA.lnk . (...) -- C:\Program Files\Microsoft\Microsoft PowerPoint 2010 Interactive Guide FRA\PowerPoint.html
O4 - Global Startup: C:\Users\Administrateur\Desktop\Microsoft Word 2010 Interactive Guide FRA.lnk . (...) -- C:\Program Files\Microsoft\Microsoft Word 2010 Interactive Guide FRA\Word.html
O4 - Global Startup: C:\Users\Administrateur\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Microsoft Excel 2010 Interactive Guide FRA.lnk . (...) -- C:\Windows\Installer\{87869878-E37F-4D3C-9CB5-99A3BDB8E409}\_0B7285CEFAADAAE325555E.exe
O4 - Global Startup: C:\Users\Administrateur\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Microsoft PowerPoint 2010 Interactive Guide FRA.lnk . (...) -- C:\Windows\Installer\{C6184D5B-B006-4344-B850-EE6283A39777}\_E3DFF635063246EF8362E0.exe
O4 - Global Startup: C:\Users\Administrateur\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Microsoft Word 2010 Interactive Guide FRA.lnk . (...) -- C:\Windows\Installer\{BED64CF4-AED8-4E00-BABE-1C06B9EDB1FD}\_7691097CC91D5BF682FEBC.exe
~ Scan Global Startup in 00mn 00s



---\\ Lignes supplémentaires dans le menu contextuel d'Internet Explorer (O8)
O8 - Extra context menu item: &Envoyer à OneNote . (.Microsoft Corporation - Microsoft OneNote Internet Explorer Add-in.) -- C:\Program Files\MsOffice\Office14\ONBttnIE.dll
O8 - Extra context menu item: E&xport to Microsoft Excel - (.not file.) - C:\Program Files\MsOffice\OFFICE11\EXCEL.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel . (.Microsoft Corporation - Microsoft Excel.) -- C:\Program Files\MsOffice\Office14\EXCEL.exe
~ Scan IE Menu Contextuel in 00mn 00s



---\\ Boutons situés sur la barre d'outils principale d'Internet Explorer (O9)
O9 - Extra button: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} . (.Microsoft Corporation - Microsoft OneNote Internet Explorer Add-in.) -- C:\Program Files\MsOffice\Office14\ONBttnIE.dll
O9 - Extra button: Notes &liées OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} . (.Microsoft Corporation - Microsoft OneNote Internet Explorer Add-in.) -- C:\Program Files\MsOffice\Office14\ONBTTN~1.dll
O9 - Extra button: Notes &liées OneNote - {c95fe080-8f5d-11d2-a20b-00aa003c157a} . (.Microsoft Corporation - Microsoft OneNote Internet Explorer Add-in.) -- C:\Program Files\MsOffice\Office14\ONBttnIELinkedNotes.dll
~ Scan IE Extra Buttons in 00mn 00s



---\\ Winsock hijacker (Layered Service Provider) (O10)
O10 - WLSP:\000000000001\Winsock LSP File . (.Microsoft Corporation - Network Location Awareness 2.) -- C:\Windows\system32\NLAapi.dll
O10 - WLSP:\000000000002\Winsock LSP File . (.Microsoft Corporation - Fournisseur Shim d'affectation de noms de messagerie.) -- C:\Windows\system32\napinsp.dll
O10 - WLSP:\000000000003\Winsock LSP File . (.Microsoft Corporation - Fournisseur d'espace de noms PNRP.) -- C:\Windows\system32\pnrpnsp.dll
O10 - WLSP:\000000000004\Winsock LSP File . (.Microsoft Corporation - Fournisseur d'espace de noms PNRP.) -- C:\Windows\system32\pnrpnsp.dll
O10 - WLSP:\000000000005\Winsock LSP File . (.Microsoft Corporation - Fournisseur de service Sockets 2.0 de Microsoft Windows.) -- C:\Windows\system32\mswsock.dll
O10 - WLSP:\000000000006\Winsock LSP File . (.Microsoft Corporation - LDAP RnR Provider DLL.) -- C:\Windows\system32\winrnr.dll
~ Scan Winsock in 00mn 00s



---\\ Objets ActiveX (Downloaded Program Files)(O16)
O16 - DPF: 55963676-2F5E-4BAF-AC28-CF26AA587566 - (VPNWeb Control) - (.not file.) - vpnweb.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://psa.webex.com/client/T27LSP21/webex/ieatgpc1.cab
~ Scan Objets ActiveX in 00mn 00s



---\\ Modification Domaine/Adresses DNS (O17)
O17 - HKLM\System\CCS\Services\Tcpip\..\{0E85A6FC-BEE7-4CA8-9430-1457FA28E44E}: DhcpNameServer = 212.27.40.240 212.27.40.241
O17 - HKLM\System\CS1\Services\Tcpip\..\{0E85A6FC-BEE7-4CA8-9430-1457FA28E44E}: DhcpNameServer = 212.27.40.240 212.27.40.241
O17 - HKLM\System\CS2\Services\Tcpip\..\{0E85A6FC-BEE7-4CA8-9430-1457FA28E44E}: DhcpNameServer = 212.27.40.240 212.27.40.241
~ Scan Domain in 00mn 00s



---\\ Protocole additionnel (O18)
O18 - Handler: about - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\system32\mshtml.dll
O18 - Handler: cdl - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\system32\urlmon.dll
O18 - Handler: dvd - {12D51199-0DB5-46FE-A120-47A3D7D937CC} . (.Microsoft Corporation - Contrôle ActiveX pour le flux vidéo.) -- C:\Windows\System32\msvidctl.dll
O18 - Handler: file - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\system32\urlmon.dll
O18 - Handler: ftp - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\system32\urlmon.dll
O18 - Handler: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\system32\urlmon.dll
O18 - Handler: http - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\system32\urlmon.dll
O18 - Handler: https - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\system32\urlmon.dll
O18 - Handler: its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\System32\itss.dll
O18 - Handler: javascript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\system32\mshtml.dll
O18 - Handler: local - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\system32\urlmon.dll
O18 - Handler: mailto - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\system32\mshtml.dll
O18 - Handler: mhtml - {05300401-BCBC-11d0-85E3-00C04FD85AB4} . (.Microsoft Corporation - Microsoft Internet Messaging API Resources.) -- C:\Windows\system32\inetcomm.dll
O18 - Handler: mk - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\system32\urlmon.dll
O18 - Handler: ms-help - {314111c7-a502-11d2-bbca-00c04f8ec294} . (.Microsoft Corporation - Microsoft® Help Data Services Module.) -- C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Handler: ms-its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\System32\itss.dll
O18 - Handler: res - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\system32\mshtml.dll
O18 - Handler: tv - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} . (.Microsoft Corporation - Contrôle ActiveX pour le flux vidéo.) -- C:\Windows\System32\msvidctl.dll
O18 - Handler: vbscript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\system32\mshtml.dll
O18 - Filter: application/octet-stream - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll
O18 - Filter: application/x-complus - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll
O18 - Filter: application/x-msdownload - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll
O18 - Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\system32\urlmon.dll
O18 - Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\system32\urlmon.dll
O18 - Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} . (.Microsoft Corporation - Microsoft Office XML MIME Filter.) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.dll
~ Scan Protocole Additionnel in 00mn 00s



---\\ Clé de Registre autorun ShellServiceObjectDelayLoad (SSO/SSODL) (O21)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} . (.Microsoft Corporation - Contrôleur de site Web.) -- C:\Windows\system32\webcheck.dll
~ Scan SSODL in 00mn 00s



---\\ Clé de Registre autorun SharedTaskScheduler (STS) (O22)
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} . (.Microsoft Corporation - Bibliothèque de l'interface utilisateur du.) -- C:\Windows\System32\browseui.dll
~ Scan STS/SSO in 00mn 00s



---\\ Liste des services NT non Microsoft et non désactivés (O23)
O23 - Service: Andrea ADI Filters Service (AEADIFilters) . (.Andrea Electronics Corporation - Andrea filters APO access service (32-bit).) - C:\Windows\System32\AEADISRV.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) . (.Symantec Corporation - Symantec Service Framework.) - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) . (.Symantec Corporation - Symantec Service Framework.) - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: HP Service (hpsrv) . (.Hewlett-Packard Corporation - HpService.) - C:\Windows\System32\Hpservice.exe
O23 - Service: Service Cartes Industriel (induscards) . (.PSA PEUGEOT CITROEN - admindustrialservice.) - C:\Windows\System32\admindustrialservice.exe
O23 - Service: Diagnostics Lotus Notes (Lotus Notes Diagnostics) . (.IBM Corp - IBM Lotus Notes/Domino.) - C:\Program Files\IBM\Lotus\Notes\nsd.exe
O23 - Service: Nortel CVC Service (NvcRpcServer) . (.Nortel Networks NA, Inc. - Provides support for Nortel IPSec VPN tunne.) - C:\Program Files\Nortel Networks\NvcRpcSvr.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) . (.NVIDIA Corporation - NVIDIA Driver Helper Service, Version 176.5.) - C:\Windows\System32\nvvsvc.exe
O23 - Service: PCControlWinService (PCControlWinService) . (...) - C:\Program Files\PCControl\PCControlService.exe
O23 - Service: PV3 Update Service (PSASCE2) . (...) - c:\sys\PSA\PsaSce2.exe
O23 - Service: Service PSAV3 (PSASCE3) . (...) - c:\sys\PSA\PsaSce3.exe
O23 - Service: PSAV4 gestion de poste (PV4AdminDist) . (.PSA PEUGEOT CITROEN - PV3 ServiceTemplate.) - c:\sys\PSA\PV3AG3120.exe
O23 - Service: Symantec Management Client (SmcService) . (.Symantec Corporation - Symantec CMC Smc.) - C:\Program Files\NavNT\Smc.exe
O23 - Service: Switch Wifi PSA (Switch Wifi PSA) . (.PSA - Service Réseau.) - C:\Program Files\Switch_Wifi_PSA\Switch_Wifi_PSA.exe
O23 - Service: Symantec Endpoint Protection (Symantec AntiVirus) . (.Symantec Corporation - Symantec AntiVirus.) - C:\Program Files\NavNT\Rtvscan.exe
O23 - Service: Cisco AnyConnect Secure Mobility Agent (vpnagent) . (.Cisco Systems, Inc. - VPN Agent Service.) - C:\Program Files\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe
~ Scan Services in 00mn 00s



---\\ Enumération Active Desktop & MHTML Editor (O24)
O24 - Default MHTML Editor: Last - .(...) - (.not file.)
~ Scan Desktop Component in 00mn 00s



---\\ BootExecute (O34)
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
~ Scan Keys in 00mn 00s



---\\ Composants installés (ActiveSetup Installed Components) (O40)
O40 - ASIC: Microsoft Windows Media Player - >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Utilitaire d'installation du Lecteur Windows Media de Microsoft.) -- C:\Windows\system32\unregmp2.exe
O40 - ASIC: Internet Explorer - >{26923b43-4d38-484f-9b9e-de460746276c} . (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Explorer par utilisateur.) -- C:\Windows\system32\ie4uinit.exe
O40 - ASIC: Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608500} . (.Sun Microsystems, Inc. - Java(TM) Platform SE binary.) -- C:\Program Files\Java\jre6\bin\regutils.dll
O40 - ASIC: Macromedia Shockwave Director 10.1 - {166B1BCA-3F9C-11CF-8075-444553540000} . (.Adobe Systems, Inc. - Shockwave ActiveX Control.) -- C:\Windows\system32\macromed\Director\SwDir.dll
O40 - ASIC: Microsoft Windows Media Player 11.0 - {22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Windows Media Player Extension.) -- C:\Windows\System32\wmpdxm.dll
O40 - ASIC: Microsoft Windows Media Player - {6BF52A52-394A-11d3-B153-00C04F79FAA6} . (.Microsoft Corporation - Windows Media Player.) -- C:\Windows\System32\wmp.dll
O40 - ASIC: Internet Explorer - {89820200-ECBD-11cf-8B85-00AA005B4383} . (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Explorer par utilisateur.) -- C:\Windows\system32\ie4uinit.exe
O40 - ASIC: (no name) - {89B4C1CD-B018-4511-B0A1-5476DBF70820} . (.Microsoft Corporation - Microsoft .NET IE SECURITY REGISTRATION.) -- C:\Windows\system32\mscories.dll
~ Scan Active Setup in 00mn 00s



---\\ Pilotes lancés au démarrage (O41)
O41 - Driver: (AFD) . (.Microsoft Corporation - Ancillary Function Driver for WinSock.) - C:\Windows\system32\drivers\afd.sys
O41 - Driver: (cdrom) . (.Microsoft Corporation - SCSI CD-ROM Driver.) - C:\Windows\System32\DRIVERS\cdrom.sys
O41 - Driver: (CSC) . (.Microsoft Corporation - Windows Client Side Caching Driver.) - C:\Windows\System32\drivers\csc.sys
O41 - Driver: C:\Windows\System32\drivers\dfsc.sys (DfsC) . (.Microsoft Corporation - DFS Namespace Client Driver.) - C:\Windows\System32\Drivers\dfsc.sys
O41 - Driver: (eeCtrl) . (.Symantec Corporation - Symantec Eraser Control Driver.) - C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys
O41 - Driver: (i8042prt) . (.Microsoft Corporation - Pilote de port i8042.) - C:\Windows\System32\DRIVERS\i8042prt.sys
O41 - Driver: (kbdclass) . (.Microsoft Corporation - Pilote de la classe Clavier.) - C:\Windows\System32\DRIVERS\kbdclass.sys
O41 - Driver: (kbdhid) . (.Microsoft Corporation - Pilote de filtre clavier HID.) - C:\Windows\System32\DRIVERS\kbdhid.sys
O41 - Driver: (mouclass) . (.Microsoft Corporation - Pilote de la classe Souris.) - C:\Windows\System32\DRIVERS\mouclass.sys
O41 - Driver: (NetBIOS) . (.Microsoft Corporation - NetBIOS interface driver.) - C:\Windows\System32\DRIVERS\netbios.sys
O41 - Driver: (netbt) . (.Microsoft Corporation - MBT Transport driver.) - C:\Windows\System32\DRIVERS\netbt.sys
O41 - Driver: (nsiproxy) . (.Microsoft Corporation - NSI Proxy.) - C:\Windows\System32\drivers\nsiproxy.sys
O41 - Driver: C:\Windows\System32\drivers\pacer.sys (PSched) . (.Microsoft Corporation - Planificateur de paquets QoS.) - C:\Windows\System32\DRIVERS\pacer.sys
O41 - Driver: (RasAcd) . (.Microsoft Corporation - RAS Automatic Connection Driver.) - C:\Windows\System32\DRIVERS\rasacd.sys
O41 - Driver: (rdbss) . (.Microsoft Corporation - Redirected Drive Buffering SubSystem Driver.) - C:\Windows\System32\DRIVERS\rdbss.sys
O41 - Driver: (RDPCDD) . (.Microsoft Corporation - RDP Miniport.) - C:\Windows\System32\DRIVERS\RDPCDD.sys
O41 - Driver: (RDPENCDD) . (.Microsoft Corporation - RDP Miniport.) - C:\Windows\System32\drivers\rdpencdd.sys
O41 - Driver: C:\Windows\System32\tcpipcfg.dll (Smb) . (.Microsoft Corporation - SMB Transport driver.) - C:\Windows\System32\DRIVERS\smb.sys
O41 - Driver: (SPBBCDrv) . (.Symantec Corporation - SPBBC Driver.) - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys
O41 - Driver: (SRTSP) . (.Symantec Corporation - Symantec AutoProtect.) - C:\Windows\System32\Drivers\SRTSP.sys
O41 - Driver: (SRTSPX) . (.Symantec Corporation - Symantec AutoProtect.) - C:\Windows\System32\Drivers\SRTSPX.sys
O41 - Driver: C:\Windows\System32\tcpipcfg.dll (tdx) . (.Microsoft Corporation - TDI Translation Driver.) - C:\Windows\System32\DRIVERS\tdx.sys
O41 - Driver: (TermDD) . (.Microsoft Corporation - Terminal Server Driver.) - C:\Windows\System32\DRIVERS\termdd.sys
O41 - Driver: (VgaSave) . (.Microsoft Corporation - VGA/Super VGA Video Driver.) - C:\Windows\system32\drivers\vga.sys
O41 - Driver: (Wanarpv6) . (.Microsoft Corporation - MS Remote Access and Routing ARP Driver.) - C:\Windows\System32\DRIVERS\wanarp.sys
O41 - Driver: (WPS) . (.Symantec Corporation - Symantec CMC Firewall WPS.) - C:\Windows\system32\drivers\wpsdrvnt.sys
~ Scan Drivers in 00mn 00s



---\\ Logiciels installés (O42)
O42 - Logiciel: 7ZIP - (.FREEWARE.) [HKLM] -- {9620B370-FD19-4B33-9287-00B5170B485C}
O42 - Logiciel: Adobe Flash Player 10 ActiveX - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player ActiveX
O42 - Logiciel: Adobe Flash Player 10 Plugin - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player Plugin
O42 - Logiciel: Adobe Reader 9.3.4 - Français - (.Adobe Systems Incorporated.) [HKLM] -- {AC76BA86-7AD7-1036-7B44-A93000000001}
O42 - Logiciel: Adobe SVG Viewer 3.0 - (.Pas de propriétaire.) [HKLM] -- Adobe SVG Viewer
O42 - Logiciel: Adobe Shockwave Player - (.Adobe Systems, Inc..) [HKLM] -- {1BDC9633-895B-4842-BCB6-8FA1EC2A3C5A}
O42 - Logiciel: CRETA_3-4-407-0_INTL - (.AVL List GmbH.) [HKLM] -- {25158542-02F5-4DB1-841D-9CFF2CCC9393}
O42 - Logiciel: Chinese Simplified Fonts Support For Adobe Reader 9 - (.Adobe Systems Incorporated.) [HKLM] -- {AC76BA86-7AD7-2447-0000-900000000003}
O42 - Logiciel: Chinese Traditional Fonts Support For Adobe Reader 9 - (.Adobe Systems Incorporated.) [HKLM] -- {AC76BA86-7AD7-2448-0000-900000000003}
O42 - Logiciel: Cisco AnyConnect Secure Mobility Client - (.Cisco Systems, Inc..) [HKLM] -- Cisco AnyConnect Secure Mobility Client
O42 - Logiciel: Cisco AnyConnect Secure Mobility Client - (.Cisco Systems, Inc..) [HKLM] -- {B50289E4-36DB-4FEA-AC5D-043EF7F6DAE3}
O42 - Logiciel: DHTML Editing Component - (.Microsoft Corporation.) [HKLM] -- {2EA870FA-585F-4187-903D-CB9FFD21E2E0}
O42 - Logiciel: DIAMUXV5_5-4-3-2_INTL - (.PSA.) [HKLM] -- {94DAD4EC-715F-47F4-AC83-457074C10BE1}
O42 - Logiciel: DiagAlyser - (.PSA Peugeot Citroen.) [HKLM] -- {82599F91-31D3-41F9-BF13-0B5F26A672E0}
O42 - Logiciel: ETAS Drivers - ECU and Bus Interfaces 1.1.3 - (.ETAS GmbH.) [HKLM] -- {884220C7-6B7E-4829-A92E-8281298D7CE6}
O42 - Logiciel: HELP_1-0-0-3_INTL - (.PSA.) [HKLM] -- {A0D8BD05-8F0A-47B1-B338-025C81591DC8}
O42 - Logiciel: HP 3D DriveGuard - (.Hewlett-Packard.) [HKLM] -- {E44FFEA5-177E-4C5C-9EE1-33C8E3F2755B}
O42 - Logiciel: HP Common Access Service Library - (.Hewlett-Packard.) [HKLM] -- {732A3F80-008B-4350-BD58-EC5AE98707B8}
O42 - Logiciel: HP Quick Launch Buttons 6.40 L2 - (.Hewlett-Packard.) [HKLM] -- {34D2AB40-150D-475D-AE32-BD23FB5EE355}
O42 - Logiciel: Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) - (.Microsoft Corporation.) [HKLM] -- {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB953595
O42 - Logiciel: Hotfix for Microsoft Office 2010 (KB2466272) - (.Microsoft.) [HKLM] -- {90140000-0012-0000-0000-0000000FF1CE}_Office14.STANDARD_{2FD4E624-BAA6-40EF-A285-2EBABF60DF29}
O42 - Logiciel: Hotfix for Microsoft Office 2010 (KB2516475) - (.Microsoft.) [HKLM] -- {90140000-0012-0000-0000-0000000FF1CE}_Office14.STANDARD_{FDB8E4C6-A3EB-41A4-8CCD-4E83D24AE226}
O42 - Logiciel: Hotfix for Microsoft Office 2010 (KB2516481) - (.Microsoft.) [HKLM] -- {90140000-0012-0000-0000-0000000FF1CE}_Office14.STANDARD_{49440EE0-B4D7-4023-9E85-2609AAA7C3A8}
O42 - Logiciel: Hotfix for Microsoft Office 2010 (KB2516481) - (.Microsoft.) [HKLM] -- {90140000-0012-0000-0000-0000000FF1CE}_Office14.STANDARD_{6EC394C5-249C-40CC-AA98-A05317810A2B}
O42 - Logiciel: Hotfix for Microsoft Office 2010 (KB2516481) - (.Microsoft.) [HKLM] -- {90140000-0012-0000-0000-0000000FF1CE}_Office14.STANDARD_{AA9E4C48-857D-4558-A4F4-343CA7680277}
O42 - Logiciel: Hotfix for Microsoft Office 2010 (KB2516484) - (.Microsoft.) [HKLM] -- {90140000-0012-0000-0000-0000000FF1CE}_Office14.STANDARD_{35A39B91-84F5-4869-936B-64C8D581912B}
O42 - Logiciel: Hotfix for Microsoft Office 2010 (KB2516484) - (.Microsoft.) [HKLM] -- {90140000-0012-0000-0000-0000000FF1CE}_Office14.STANDARD_{69B4517D-40E2-4E72-A006-31EF4742C8CF}
O42 - Logiciel: Hotfix for Microsoft Office 2010 (KB2516493) - (.Microsoft.) [HKLM] -- {90140000-0012-0000-0000-0000000FF1CE}_Office14.STANDARD_{64F0B44F-4090-4AD8-9F3C-97F9EB356DF8}
O42 - Logiciel: Hotfix for Microsoft OneNote 2010 (KB2523130) - (.Microsoft.) [HKLM] -- {90140000-0012-0000-0000-0000000FF1CE}_Office14.STANDARD_{6FF16374-A39A-4396-8313-60796F025B01}
O42 - Logiciel: Hotfix for Microsoft Outlook 2010 (KB2516474) - (.Microsoft.) [HKLM] -- {90140000-0012-0000-0000-0000000FF1CE}_Office14.STANDARD_{63B27C98-FA97-46BA-B312-B682547ED597}
O42 - Logiciel: Hotfix for Microsoft Outlook Social Connector (KB2466271) - (.Microsoft.) [HKLM] -- {90140000-0012-0000-0000-0000000FF1CE}_Office14.STANDARD_{E47DF26F-F44B-41AD-A8DD-F9BE5945EE3A}
O42 - Logiciel: Hotfix for Microsoft Word 2010 (KB2523129) - (.Microsoft.) [HKLM] -- {90140000-0012-0000-0000-0000000FF1CE}_Office14.STANDARD_{A1C97320-BE44-48D3-B71B-BFD8DB35C58C}
O42 - Logiciel: INCA_6-2-1-122_INTL - (.PSA.) [HKLM] -- {228A3E35-AD5C-40AC-81B7-D3EAC00D3AF2}
O42 - Logiciel: INFOPOSTE_1-1-1-1800_INTL - (.PSA.) [HKLM] -- {023EE761-CF94-4388-BA68-4821FFC185B8}
O42 - Logiciel: JAVA-RUNTIME-ENVIRONMENT_1-4-2-10_INTL - (.Sun Microsystems, Inc..) [HKLM] -- {7148F0A8-6813-11D6-A77B-00B0D0142100}
O42 - Logiciel: JAVA-RUNTIME-ENVIRONMENT_1-5-0-17_INTL - (.Sun Microsystems, Inc..) [HKLM] -- {3248F0A8-6813-11D6-A77B-00B0D0150170}
O42 - Logiciel: JAVA-RUNTIME-ENVIRONMENT_1-6-0-21_INTL - (.Oracle.) [HKLM] -- {26A24AE4-039D-4CA4-87B4-2F83216021FF}
O42 - Logiciel: Japanese Fonts Support For Adobe Reader 9 - (.Adobe Systems Incorporated.) [HKLM] -- {AC76BA86-7AD7-5760-0000-900000000003}
O42 - Logiciel: Korean Fonts Support For Adobe Reader 9 - (.Adobe Systems Incorporated.) [HKLM] -- {AC76BA86-7AD7-5670-0000-900000000003}
O42 - Logiciel: LOTUS-SAMETIME-CONNECT_8-0-2-1_INTL - (.IBM.) [HKLM] -- {A2EF91BA-068C-4F6D-B6ED-52D1D272ED8F}
O42 - Logiciel: LiMa - (.ETAS GmbH.) [HKLM] -- {F19516CB-3FBD-4E6B-9A69-ED140E49757B}
O42 - Logiciel: LiveUpdate 3.3 (Symantec Corporation) - (.Symantec Corporation.) [HKLM] -- LiveUpdate
O42 - Logiciel: Lotus Notes 8.5.1 fr - (.IBM.) [HKLM] -- {276D3DDA-45F9-4DC8-80DF-7A36B61768C5}
O42 - Logiciel: MATLAB R2011b - (.The MathWorks, Inc..) [HKLM] -- Matlab R2011b
O42 - Logiciel: MSXML 4.0 SP2 (KB925672) - (.Microsoft Corporation.) [HKLM] -- {A9CF9052-F4A0-475D-A00F-A8388C62DD63}
O42 - Logiciel: MSXML 4.0 SP2 (KB927978) - (.Microsoft Corporation.) [HKLM] -- {37477865-A3F1-4772-AD43-AAFC6BCFF99F}
O42 - Logiciel: Micro Application - MediaDICO 12 - (.Pas de propriétaire.) [HKLM] -- MediaDICO12
O42 - Logiciel: Microsoft .NET Framework 3.5 SP1 - (.Microsoft Corporation.) [HKLM] -- Microsoft .NET Framework 3.5 SP1
O42 - Logiciel: Microsoft .NET Framework 3.5 SP1 - (.Microsoft Corporation.) [HKLM] -- {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
O42 - Logiciel: Microsoft .NET Framework 4 Client Profile - (.Microsoft Corporation.) [HKLM] -- Microsoft .NET Framework 4 Client Profile
O42 - Logiciel: Microsoft .NET Framework 4 Client Profile - (.Microsoft Corporation.) [HKLM] -- {3C3901C5-3455-3E0A-A214-0B093A5070A6}
O42 - Logiciel: Microsoft .NET Framework 4 Extended - (.Microsoft Corporation.) [HKLM] -- Microsoft .NET Framework 4 Extended
O42 - Logiciel: Microsoft .NET Framework 4 Extended - (.Microsoft Corporation.) [HKLM] -- {0A0CADCF-78DA-33C4-A350-CD51849B9702}
O42 - Logiciel: Microsoft Excel 2010 Interactive Guide FRA - (.Microsoft.) [HKLM] -- {87869878-E37F-4D3C-9CB5-99A3BDB8E409}
O42 - Logiciel: Microsoft Office 2000 Web Components - (.Microsoft Corporation.) [HKLM] -- {902E0409-6000-11D3-8CFE-0150048383C9}
O42 - Logiciel: Microsoft Office Excel MUI (French) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-0016-040C-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office OneNote MUI (French) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-00A1-040C-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Outlook MUI (French) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-001A-040C-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office PowerPoint MUI (French) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-0018-040C-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Proof (Arabic) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-001F-0401-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Proof (Dutch) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-001F-0413-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Proof (English) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-001F-0409-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Proof (French) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-001F-040C-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Proof (German) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-001F-0407-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Proof (Spanish) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-001F-0C0A-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Proofing (French) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-002C-040C-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Publisher MUI (French) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-0019-040C-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Shared MUI (French) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-006E-040C-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Standard 2010 - (.Microsoft Corporation.) [HKLM] -- Office14.STANDARD
O42 - Logiciel: Microsoft Office Standard 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-0012-0000-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Visio Viewer 2007 - (.Microsoft Corporation.) [HKLM] -- {95120000-0052-040C-0000-0000000FF1CE}
O42 - Logiciel: Microsoft Office Word MUI (French) 2010 - (.Microsoft Corporation.) [HKLM] -- {90140000-001B-040C-0000-0000000FF1CE}
O42 - Logiciel: Microsoft PowerPoint 2010 Interactive Guide FRA - (.Microsoft.) [HKLM] -- {C6184D5B-B006-4344-B850-EE6283A39777}
O42 - Logiciel: Microsoft Silverlight - (.Microsoft Corporation.) [HKLM] -- {89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
O42 - Logiciel: Microsoft Visual C++ 2005 Redistributable - (.Microsoft Corporation.) [HKLM] -- {710f4c1c-cc18-4c49-8cbf-51240c89a1a2}
O42 - Logiciel: Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 - (.Microsoft Corporation.) [HKLM] -- {FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}
O42 - Logiciel: Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 - (.Microsoft Corporation.) [HKLM] -- {9A25302D-30C0-39D9-BD6F-21E6EC160475}
O42 - Logiciel: Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 - (.Microsoft Corporation.) [HKLM] -- {F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}
O42 - Logiciel: Microsoft Visual J# 2.0 Redistributable Package - (.Microsoft Corporation.) [HKLM] -- Microsoft Visual J# 2.0 Redistributable Package
O42 - Logiciel: Microsoft Visual Studio 2010 Tools for Office Runtime (x86) - (.Microsoft Corporation.) [HKLM] -- Microsoft Visual Studio 2010 Tools for Office Runtime (x86)
O42 - Logiciel: Microsoft Visual Studio 2010 Tools for Office Runtime (x86) - (.Microsoft Corporation.) [HKLM] -- {83C4A333-DD44-3431-B1BF-6A66B971D07B}
O42 - Logiciel: Microsoft Word 2010 Interactive Guide FRA - (.Microsoft.) [HKLM] -- {BED64CF4-AED8-4E00-BABE-1C06B9EDB1FD}
O42 - Logiciel: Milou - (.PSA.) [HKLM] -- {CD5725D4-FEB1-4EA0-885E-01D65BDA4747}
O42 - Logiciel: Module linguistique Microsoft Visual Studio 2010 Tools pour Office Runtime (x86) - FRA - (.Microsoft Corporation.) [HKLM] -- Microsoft Visual Studio 2010 Tools for Office Runtime (x86) Language Pack - FRA
O42 - Logiciel: Mozilla Firefox (fr) - (.PSA.) [HKLM] -- {B0E65F4C-1431-4894-AF02-108AD6F95BBE}
O42 - Logiciel: NVIDIA Drivers - (.Pas de propriétaire.) [HKLM] -- NVIDIA Drivers
O42 - Logiciel: NVIDIA Performance Drivers - (.NVIDIA Corporation.) [HKLM] -- {71807498-D8E2-41C6-84CD-8ED7A076B6EC}
O42 - Logiciel: ORACLE-DSIN-CLIENT-DIX-G_10-2-0-2_INTL - (.PSA PEUGEOT CITROEN.) [HKLM] -- {38D6C3CF-EB86-4946-81BF-5E8A708F7844}
O42 - Logiciel: ORACLE-DSIN-CLIENT-DIX-G_10-2-0-4_INTL - (.Oracle.) [HKLM] -- {D5A3E040-E4AC-41DA-B42B-FFC8A12509C9}
O42 - Logiciel: PCControl - (.Novell.) [HKLM] -- {8F33F7F5-790A-4506-A22D-DC4692EE3DD4}
O42 - Logiciel: PDFCreator - (.Frank Heindörfer, Philip Chinery.) [HKLM] -- {0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}
O42 - Logiciel: PSA.OutlookRoomFinder - (.Microsoft.) [HKLM] -- {0241B1CD-83FF-44CF-BAC6-672FE78B7002}
O42 - Logiciel: PluginGuideInteractif - (.PSA.) [HKLM] -- {43A78566-B291-4F6A-B531-DE8FD487FB50}
O42 - Logiciel: RT-VC2008_2008-0-0-0_INTL - (.PSA.) [HKLM] -- {820B6609-4C97-3A2B-B644-573B06A0F0CC}
O42 - Logiciel: RT-VC2008_2008-0-0-1_INTL - (.Microsoft Corporation.) [HKLM] -- {1F1C2DFC-2D24-3E06-BCB8-725134ADF989}
O42 - Logiciel: RT-VC_2005-0-0-1_INTL - (.Microsoft Corporation.) [HKLM] -- {837b34e3-7c30-493c-8f6a-2b0f04e2912c}
O42 - Logiciel: SSOX - (.AVENCIS.) [HKLM] -- {AE2F5F0D-39D4-4B53-90DA-30238BBA61A4}
O42 - Logiciel: Scandiag UDS V2.2 - (.PSA Peugeot Citroën.) [HKLM] -- Scandiag UDS V2.2_is1
O42 - Logiciel: Security Update for Microsoft .NET Framework 3.5 SP1 (KB2657424) - (.Microsoft Corporation.) [HKLM] -- {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB2657424
O42 - Logiciel: Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351) - (.Microsoft Corporation.) [HKLM] -- {3C3901C5-3455-3E0A-A214-0B093A5070A6}.KB2656351
O42 - Logiciel: Security Update for Microsoft .NET Framework 4 Extended (KB2656351) - (.Microsoft Corporation.) [HKLM] -- {0A0CADCF-78DA-33C4-A350-CD51849B9702}.KB2656351
O42 - Logiciel: Switch Wifi PSA - (.PSA.) [HKLM] -- {08ED643D-635D-4728-93AB-67598453DD99}
O42 - Logiciel: Symantec Endpoint Protection - (.Symantec Corporation.) [HKLM] -- {2EFCC193-D915-4CCB-9201-31773A27BC06}
O42 - Logiciel: Synaptics Pointing Device Driver - (.Synaptics.) [HKLM] -- SynTPDeinstKey
O42 - Logiciel: USB Driver Kit rev101126 - (.Pas de propriétaire.) [HKLM] -- {f51d9479-31f5-4d48-95a4-ca24ae42c2d7}_is1
O42 - Logiciel: VLC_1-1-9-1_INTL - (.PSA.) [HKLM] -- {9F09A7F6-5AFC-43A3-89B5-13E4AEC9B799}
O42 - Logiciel: Vector CANalyzer 7.2 - (.Vector Informatik GmbH.) [HKLM] -- {B100DDC0-58F7-4FE2-A32C-10B18779AE71}
O42 - Logiciel: Vector CANoe/CANalyzer Redistributables 1.0 - (.Vector Informatik GmbH.) [HKLM] -- {FF9E31CF-F433-48FD-989E-A6E9A3FCFC01}
O42 - Logiciel: WebEx - (.Cisco WebEx LLC.) [HKLM] -- ActiveTouchMeetingClient

---\\ HKCU & HKLM Software Keys
[HKCU\Software\7-ZIP]
[HKCU\Software\ACD Systems]
[HKCU\Software\Adobe]
[HKCU\Software\Analog Devices]
[HKCU\Software\AppDataLow]
[HKCU\Software\Avenci]
[HKCU\Software\Bay Networks]
[HKCU\Software\Classes]
[HKCU\Software\Cygnus Solutions]
[HKCU\Software\DAX]
[HKCU\Software\ETAS]
[HKCU\Software\FileOpen]
[HKCU\Software\Hewlett-Packard]
[HKCU\Software\JavaSoft]
[HKCU\Software\Laventure]
[HKCU\Software\Macromedia]
[HKCU\Software\Mathworks]
[HKCU\Software\Miloou]
[HKCU\Software\NVIDIA Corporation]
[HKCU\Software\Netscape]
[HKCU\Software\ODBC]
[HKCU\Software\PDFCreator]
[HKCU\Software\PSA]
[HKCU\Software\Policies]
[HKCU\Software\Shortcuts]
[HKCU\Software\Symantec]
[HKCU\Software\Synaptics]
[HKCU\Software\Team17SoftwareLTD]
[HKCU\Software\VPN]
[HKCU\Software\WebEx]
[HKLM\Software\7-Zip]
[HKLM\Software\ACD Systems]
[HKLM\Software\AFPL Ghostscript]
[HKLM\Software\ActiveTouch]
[HKLM\Software\Adobe]
[HKLM\Software\Analog Devices]
[HKLM\Software\Avenci]
[HKLM\Software\CXT]
[HKLM\Software\Caphyon]
[HKLM\Software\Cisco]
[HKLM\Software\Classes]
[HKLM\Software\Clients]
[HKLM\Software\Conexant]
[HKLM\Software\Cygnus Solutions]
[HKLM\Software\DAX]
[HKLM\Software\ETAS]
[HKLM\Software\FLEXlm License Manager]
[HKLM\Software\Ghostgum]
[HKLM\Software\HPQ]
[HKLM\Software\Hewlett-Packard]
[HKLM\Software\IBM]
[HKLM\Software\InstallShield]
[HKLM\Software\InstalledOptions]
[HKLM\Software\Intel]
[HKLM\Software\JavaSoft]
[HKLM\Software\Kodak]
[HKLM\Software\Lotus]
[HKLM\Software\Macromedia]
[HKLM\Software\Macrovision]
[HKLM\Software\MathWorks]
[HKLM\Software\Micro Application]
[HKLM\Software\Mozilla.org]
[HKLM\Software\MozillaPlugins]
[HKLM\Software\Mozilla]
[HKLM\Software\NVIDIA Corporation]
[HKLM\Software\National Instruments]
[HKLM\Software\Nortel Networks]
[HKLM\Software\ODBC]
[HKLM\Software\ORACLE]
[HKLM\Software\PCControl]
[HKLM\Software\PSA]
[HKLM\Software\Policies]
[HKLM\Software\RegisteredApplications]
[HKLM\Software\Symantec]
[HKLM\Software\Synaptics]
[HKLM\Software\VECTOR]
[HKLM\Software\VideoLAN]
[HKLM\Software\Volatile]
[HKLM\Software\WOW6432Node]
[HKLM\Software\WholeSecurity]
[HKLM\Software\Windows]
[HKLM\Software\gendoc]
[HKLM\Software\home]
[HKLM\Software\intrepidcs]
[HKLM\Software\webex]
~ Scan Softwares in 00mn 00s



---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43)
O43 - CFD: 07/02/2012 - 11:04:56 - [3,348] ----D C:\Program Files\7-Zip
O43 - CFD: 04/04/2011 - 19:38:31 - [9,187] ----D C:\Program Files\ACD Systems
O43 - CFD: 04/04/2011 - 19:36:25 - [179,184] ----D C:\Program Files\Adobe
O43 - CFD: 04/04/2011 - 18:58:25 - [1,568] ----D C:\Program Files\Analog Devices
O43 - CFD: 04/04/2011 - 19:38:38 - [0,151] ----D C:\Program Files\Assistants
O43 - CFD: 04/04/2011 - 18:41:22 - [5,701] ----D C:\Program Files\AVENCIS
O43 - CFD: 07/02/2012 - 11:22:37 - [8,889] ----D C:\Program Files\Cisco
O43 - CFD: 07/02/2012 - 10:30:32 - [602,141] ----D C:\Program Files\Common Files
O43 - CFD: 26/05/2011 - 09:29:50 - [117,597] ----D C:\Program Files\CRETA
O43 - CFD: 07/02/2012 - 11:04:37 - [287,260] ----D C:\Program Files\DIAMUX V5
O43 - CFD: 26/05/2011 - 09:41:15 - [494,168] ----D C:\Program Files\ETAS
O43 - CFD: 24/06/2008 - 11:37:53 - [0] R---D C:\Program Files\Fichiers communs
O43 - CFD: 04/04/2011 - 19:38:29 - [0,024] ----D C:\Program Files\GenDoc
O43 - CFD: 07/02/2012 - 11:04:52 - [0,499] ----D C:\Program Files\HELP
O43 - CFD: 04/04/2011 - 19:34:10 - [27,887] ----D C:\Program Files\Hewlett-Packard
O43 - CFD: 04/04/2011 - 19:39:39 - [952,825] ----D C:\Program Files\IBM
O43 - CFD: 23/05/2011 - 14:53:52 - [0,105] ----D C:\Program Files\InfoPoste
O43 - CFD: 04/04/2011 - 19:47:17 - [6,144] --H-D C:\Program Files\InstallShield Installation Information
O43 - CFD: 07/02/2012 - 10:55:30 - [1,623] ----D C:\Program Files\Internet Explorer
O43 - CFD: 23/08/2011 - 09:31:20 - [198,404] ----D C:\Program Files\Java
O43 - CFD: 16/06/2011 - 12:40:23 - [24,227] ----D C:\Program Files\Labwindows
O43 - CFD: 05/04/2012 - 16:08:09 - [1583,793] ----D C:\Program Files\MATLAB
O43 - CFD: 16/06/2011 - 12:36:18 - [227,411] ----D C:\Program Files\Micro Application
O43 - CFD: 07/02/2012 - 11:06:43 - [11,761] ----D C:\Program Files\Microsoft
O43 - CFD: 07/02/2012 - 10:28:11 - [38,002] ----D C:\Program Files\Microsoft Analysis Services
O43 - CFD: 04/04/2011 - 18:42:53 - [10,683] ----D C:\Program Files\Microsoft Office
O43 - CFD: 23/08/2011 - 09:37:38 - [36,584] ----D C:\Program Files\Microsoft Silverlight
O43 - CFD: 04/04/2011 - 18:38:08 - [0,014] ----D C:\Program Files\Microsoft Visual Studio
O43 - CFD: 04/04/2011 - 19:29:28 - [0,020] ----D C:\Program Files\Microsoft Visual Studio .NET 2003
O43 - CFD: 07/02/2012 - 10:40:08 - [7,797] ----D C:\Program Files\Microsoft.NET
O43 - CFD: 12/04/2012 - 09:53:22 - [23,643] ----D C:\Program Files\MILOU
O43 - CFD: 04/04/2011 - 19:16:24 - [19,522] ----D C:\Program Files\Movie Maker
O43 - CFD: 16/04/2012 - 20:54:52 - [27,015] ----D C:\Program Files\Mozilla Firefox
O43 - CFD: 02/11/2006 - 14:37:40 - [0,025] ----D C:\Program Files\MSBuild
O43 - CFD: 07/02/2012 - 10:31:09 - [596,439] ----D C:\Program Files\MsOffice
O43 - CFD: 05/04/2011 - 09:32:36 - [0] ----D C:\Program Files\MSXML 4.0
O43 - CFD: 04/04/2011 - 19:46:14 - [0] ----D C:\Program Files\My Company Name
O43 - CFD: 16/06/2011 - 12:40:25 - [2,097] ----D C:\Program Files\National Instruments
O43 - CFD: 08/03/2012 - 16:02:31 - [40,339] ----D C:\Program Files\NavNT
O43 - CFD: 12/04/2012 - 09:27:04 - [0,078] ---AD C:\Program Files\Nortel Networks
O43 - CFD: 04/04/2011 - 19:09:05 - [2,996] ----D C:\Program Files\NVIDIA Corporation
O43 - CFD: 04/04/2011 - 19:29:30 - [1,953] ----D C:\Program Files\Oracle
O43 - CFD: 23/08/2011 - 09:28:07 - [4,014] ----D C:\Program Files\PCControl
O43 - CFD: 04/04/2011 - 19:35:02 - [32,149] ----D C:\Program Files\PDFCreator
O43 - CFD: 07/02/2012 - 11:06:38 - [4,366] ----D C:\Program Files\PSA
O43 - CFD: 07/02/2012 - 11:04:46 - [6,400] ----D C:\Program Files\PSABackup
O43 - CFD: 02/11/2006 - 14:37:40 - [36,014] ----D C:\Program Files\Reference Assemblies
O43 - CFD: 17/06/2011 - 14:37:53 - [34,219] ----D C:\Program Files\Scandiag UDS
O43 - CFD: 04/04/2011 - 19:38:42 - [0,032] ----D C:\Program Files\Switch_Wifi_PSA
O43 - CFD: 05/04/2011 - 08:36:31 - [16,032] ----D C:\Program Files\Symantec
O43 - CFD: 16/04/2012 - 20:31:39 - [6,444] ----D C:\Program Files\SymFedPSA
O43 - CFD: 04/04/2011 - 19:08:16 - [13,579] ----D C:\Program Files\Synaptics
O43 - CFD: 02/11/2006 - 15:01:28 - [0] --H-D C:\Program Files\Uninstall Information
O43 - CFD: 17/06/2011 - 14:36:43 - [22,876] ----D C:\Program Files\USB-MUX-Driver
O43 - CFD: 17/06/2011 - 14:04:54 - [365,019] ----D C:\Program Files\Vector CANalyzer 7.2
O43 - CFD: 07/02/2012 - 11:05:05 - [78,984] ----D C:\Program Files\VideoLAN
O43 - CFD: 04/04/2011 - 18:29:16 - [0,970] ----D C:\Program Files\Windows Calendar
O43 - CFD: 04/04/2011 - 18:29:16 - [2,610] ----D C:\Program Files\Windows Collaboration
O43 - CFD: 04/04/2011 - 18:29:14 - [4,283] ----D C:\Program Files\Windows Defender
O43 - CFD: 04/04/2011 - 18:29:16 - [6,756] ----D C:\Program Files\Windows Journal
O43 - CFD: 04/04/2011 - 19:16:24 - [8,694] ----D C:\Program Files\Windows Mail
O43 - CFD: 04/04/2011 - 19:16:23 - [4,286] ----D C:\Program Files\Windows Media Player
O43 - CFD: 24/06/2008 - 11:37:53 - [7,589] ----D C:\Program Files\Windows NT
O43 - CFD: 04/04/2011 - 18:29:16 - [7,847] ----D C:\Program Files\Windows Photo Gallery
O43 - CFD: 04/04/2011 - 18:29:16 - [3,702] ----D C:\Program Files\Windows Sidebar
O43 - CFD: 16/04/2012 - 20:58:48 - [11,405] ----D C:\Program Files\ZHPDiag
O43 - CFD: 04/04/2011 - 19:37:26 - [10,829] ----D C:\Program Files\Common Files\Adobe
O43 - CFD: 07/02/2012 - 10:30:32 - [0,095] ----D C:\Program Files\Common Files\DESIGNER
O43 - CFD: 07/02/2012 - 14:51:14 - [42,291] ----D C:\Program Files\Common Files\ETAS
O43 - CFD: 04/04/2011 - 18:36:48 - [22,725] ----D C:\Program Files\Common Files\InstallShield
O43 - CFD: 04/04/2011 - 18:41:48 - [55,847] ----D C:\Program Files\Common Files\Java
O43 - CFD: 17/06/2011 - 14:06:30 - [0,622] ----D C:\Program Files\Common Files\Macrovision Shared
O43 - CFD: 07/02/2012 - 10:30:35 - [390,272] ----D C:\Program Files\Common Files\microsoft shared
O43 - CFD: 02/11/2006 - 13:18:33 - [0,003] ----D C:\Program Files\Common Files\Services
O43 - CFD: 02/11/2006 - 13:18:33 - [39,198] ----D C:\Program Files\Common Files\SpeechEngines
O43 - CFD: 05/04/2011 - 08:37:59 - [20,275] ----D C:\Program Files\Common Files\Symantec Shared
O43 - CFD: 07/02/2012 - 14:27:22 - [15,620] ----D C:\Program Files\Common Files\System
O43 - CFD: 17/06/2011 - 14:04:30 - [4,367] ----D C:\Program Files\Common Files\Vector
O43 - CFD: 04/04/2011 - 19:37:24 - [0,001] ----D C:\ProgramData\Adobe
O43 - CFD: 02/11/2006 - 15:02:24 - [0] --H-D C:\ProgramData\Application Data
O43 - CFD: 24/06/2008 - 11:37:53 - [0] --H-D C:\ProgramData\Bureau
O43 - CFD: 07/02/2012 - 11:22:37 - [0,316] ----D C:\ProgramData\CISCO
O43 - CFD:
A voir également:

3 réponses

Valuu Messages postés 2163 Date d'inscription lundi 4 octobre 2010 Statut Contributeur Dernière intervention 12 avril 2015 201
16 avril 2012 à 21:19
Yop ;)

ça va s'arranger :)
Démarrez l'ordinateur en mode sans échec avec prise en charge réseau.
Téléchargez Ransomfix (merci à Xplode), et lancez-le. Rien ne s'affiche, c'est normal.

Un rapport sera créé sous C:\RansomFix_XXXX.txt (XXXX correspond à la date et l'heure de création du rapport)
0
# RansomFix v1.0 - Xplode
# OS : Windows Vista (TM) Business Service Pack 2 (32 bits)
# Username : U186132 - B698218 (Administrateur)

_____| Winlogon - Shell |_____

Value : explorer.exe [OK]

_____| HKCU\..\Run |_____

No bad key found

_____| Explorer.exe |_____

Checking explorer.exe...
Found : C:\Windows\explorer.exe [0xD07D4C3038F3578FFCE1C0237F2A1253]
[OK]

_____| EOF |_____
0
Alors t'en penses quoi Valuu ? J'ai l'impression que ça ne nous aide pas trop ça ? :)
0
Valuu Messages postés 2163 Date d'inscription lundi 4 octobre 2010 Statut Contributeur Dernière intervention 12 avril 2015 201
16 avril 2012 à 23:13
Effectivement ça nous aide pas :D

Tu ne l'a passé qu'une fois ?
Si tu l'a passé 2 fois, essaie de redémarrer normalement pour voir.

Sinon, refait un ZHPDiag, mais en hébergeant le rapport sur http://threat-rc.com/
0
Malekal_morte- Messages postés 180304 Date d'inscription mercredi 17 mai 2006 Statut Modérateur, Contributeur sécurité Dernière intervention 15 décembre 2020 24 660
16 avril 2012 à 23:15
O4 - HKLM\..\policies\Explorer\Run: [20901] . (.Sun Microsystems, Inc. - Java(TM) Platform SE binary.) -- C:\ProgramData\Local Settings\Temp\mshhwfp.com
0
Valuu Messages postés 2163 Date d'inscription lundi 4 octobre 2010 Statut Contributeur Dernière intervention 12 avril 2015 201
16 avril 2012 à 23:28
arf, merci Mak.
Je commence à me remettre dans le bain, j'avais arrété juste avant l'apparition de ces Ransom x)
0
Valuu Messages postés 2163 Date d'inscription lundi 4 octobre 2010 Statut Contributeur Dernière intervention 12 avril 2015 201
16 avril 2012 à 23:29
Donc toujours en MSE :

--------------------------------------------------------------------------------------
* Lance ZHPFix (si tu es sous Windows Vista ou Windows 7, lance le par un clic-droit dessus --> exécuter en temps qu'administrateur).
* Copie les lignes suivantes :

---------------------------------------------------
O4 - HKLM\..\policies\Explorer\Run: [20901] . (.Sun Microsystems, Inc. - Java(TM) Platform SE binary.) -- C:\ProgramData\Local Settings\Temp\mshhwfp.com
---------------------------------------------------

* Clique sur l'icône représentant la lettre H (« coller les lignes Helper »)
* Les lignes se collent automatiquement dans ZHPFix.
* Clique sur le bouton « GO » pour lancer le nettoyage,
* Colle le contenu du rapport dans ta prochaine réponse.
0