Icones de bureau supprimés et réapparaissent

Fermé
bluesky - 3 juin 2012 à 11:10
 bluesky - 3 juin 2012 à 12:23
Bonjour,
je supprime mes icones de bureau et ils réapparaissent à chaque fois .
Avez vous une solution à ce problème ?
Merci


8 réponses

Utilisateur anonyme
3 juin 2012 à 11:16
Salut,

Evite de faire deux topics.

Plus de détails stp.
0
pas fait exprès j ai cru que le premier n'etait pas envoyé.
tous les icones font ça ce n'est pas à cause de fichiers cachés ?
0
Utilisateur anonyme
3 juin 2012 à 12:02
Font quoi ?

Je ne vois pas le rapport avec les fichiers cachés..
0
je supprime mes icones sur le bureau et ils reapparaissent après chaque redemarage.
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
Utilisateur anonyme
3 juin 2012 à 12:07
Supprime-les puis vide la corbeille.
0
j'ai déja fait cela change rien au problème.
0
Utilisateur anonyme
3 juin 2012 à 12:12
Très étrange.

▶ Télécharge ZHPDiag (de Nicolas Coolman)

▶ Lance-le, (Clic droit "exécuter en tant qu'administrateur" si tu es sous Vista/7)

▶ Clique sur l'icône en forme de loupe pour lancer le diagnostique

▶ Héberge le rapport ZHPDiag.txt de ton bureau sur :

https://www.cjoint.com/

▶ Si le site ne fonctionne pas, consulte cette page : Autres hébergeurs en ligne
0
je n'arrive pas aller sur ce site je colle le rapport ici.

Rapport de ZHPDiag v1.31.095 par Nicolas Coolman, Update du 24/05/2012
Run by KZSQ2Q at 03/06/2012 12:16:16
Web site : http://www.premiumorange.com/zeb-help-process/zhpdiag.html
Web site : http://nicolascoolman.skyrock.com/
State : Error during network connexion


---\\ Web Browser
MSIE: Internet Explorer v

---\\ Windows Product Information
~ Langage: Anglais
Windows 7 Enterprise Edition, 32-bit Service Pack 1 (Build 7601)
Windows Server License Manager Script : Absent (Not found)
Windows ID Activation : Inconnue (Unknown)
Windows Licence : Inconnue (Unknown)
Software Protection Service (Protection logicielle) : KO
Windows Automatic Updates : OK
Windows Activation Technologies : OK

---\\ System Information
~ Processor: x86 Family 6 Model 23 Stepping 10, GenuineIntel
~ Operating System: 32 Bits
Boot mode: Normal (Normal boot)
Total RAM: 3325 MB (25% free)
System Restore: Inconnu (Unknown)
System drive C: has 79 GB (52%) free of 149 GB

---\\ Logged in mode
~ Computer Name: FRSTRWDLXA05743
~ User Name: KZSQ2Q
~ All Users Names: localadmin, Guest,
~ Unselected Option: O45,O61,O62,O65,O66,O80,O82,O89
Logged in as User

---\\ Environnement Variables
~ System Unit : C:\
~ %AppData% : C:\Users\KZSQ2Q.EUR\AppData\Roaming\
~ %Desktop% : C:\Users\KZSQ2Q.EUR\Desktop\
~ %Favorites% : C:\Users\KZSQ2Q.EUR\Favorites\
~ %LocalAppData% : C:\Users\KZSQ2Q.EUR\AppData\Local\
~ %StartMenu% : C:\Users\KZSQ2Q.EUR\AppData\Roaming\Microsoft\Windows\Start Menu\
~ %Windir% : C:\Windows\
~ %System% : C:\Windows\System32\

---\\ DOS/Devices
C:\ Hard drive, Flash drive, Thumb drive (Free 79 Go of 149 Go)
D:\ CD-ROM drive (Not Inserted)
E:\ CD-ROM drive (Not Inserted)



---\\ Security Center & Tools Informations
~ Scan Security Center in 00mn 00s



---\\ Search Generic System Files
[MD5.40D777B7A95E00593EB1568C68514493] - (.Microsoft Corporation - Explorateur Windows.) (.20/11/2010 - 03:17:10.) -- C:\Windows\Explorer.exe [2616320]
[MD5.B5C5DCAD3899512020D135600129D665] - (.Microsoft Corporation - Application de démarrage de Windows.) (.14/07/2009 - 02:14:45.) -- C:\Windows\System32\Wininit.exe [96256]
[MD5.7CCA8574A3B9BB41A4150739E21F1B23] - (.Microsoft Corporation - Extensions Internet pour Win32.) (.28/02/2012 - 06:38:52.) -- C:\Windows\System32\wininet.dll [981504]
[MD5.6D13E1406F50C66E2A95D97F22C47560] - (.Microsoft Corporation - Application d'ouverture de session Windows.) (.20/11/2010 - 03:17:56.) -- C:\Windows\System32\Winlogon.exe [286720]
[MD5.E3AE23569749DE12D45BA3B489A036AE] - (.Microsoft Corporation - Bibliothèque de licences.) (.20/11/2010 - 03:21:26.) -- C:\Windows\System32\sppcomapi.dll [193536]
[MD5.9EBBBA55060F786F0FCAA3893BFA2806] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) (.25/04/2011 - 03:18:03.) -- C:\Windows\system32\Drivers\AFD.sys [338944]
[MD5.338C86357871C167A96AB976519BF59E] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.14/07/2009 - 02:26:15.) -- C:\Windows\system32\Drivers\atapi.sys [21584]
[MD5.77EA11B065E0A8AB902D78145CA51E10] - (.Microsoft Corporation - CD-ROM File System Driver.) (.14/07/2009 - 00:11:15.) -- C:\Windows\system32\Drivers\Cdfs.sys [70656]
[MD5.BE167ED0FDB9C1FA1133953C18D5A6C9] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.20/11/2010 - 23:38:12.) -- C:\Windows\system32\Drivers\Cdrom.sys [108544]
[MD5.F024449C97EC1E464AAFFDA18593DB88] - (.Microsoft Corporation - DFS Namespace Client Driver.) (.20/11/2010 - 23:42:34.) -- C:\Windows\system32\Drivers\DfsC.sys [78336]
[MD5.9036377B8A6C15DC2EEC53E489D159B5] - (.Microsoft Corporation - High Definition Audio Bus Driver.) (.20/11/2010 - 00:59:30.) -- C:\Windows\system32\Drivers\HDAudBus.sys [108544]
[MD5.F151F0BDC47F4A28B1B20A0818EA36D6] - (.Microsoft Corporation - Pilote de port i8042.) (.14/07/2009 - 00:11:24.) -- C:\Windows\system32\Drivers\i8042prt.sys [80896]
[MD5.A5FA468D67ABCDAA36264E463A7BB0CD] - (.Microsoft Corporation - IP Network Address Translator.) (.14/07/2009 - 00:54:29.) -- C:\Windows\system32\Drivers\IpNat.sys [101888]
[MD5.5D16C921E3671636C0EBA3BBAAC5FD25] - (.Microsoft Corporation - Windows NT SMB Minirdr.) (.27/04/2011 - 03:17:22.) -- C:\Windows\system32\Drivers\MRxSmb.sys [123904]
[MD5.280122DDCF04B378EDD1AD54D71C1E54] - (.Microsoft Corporation - MBT Transport driver.) (.20/11/2010 - 23:39:46.) -- C:\Windows\system32\Drivers\netBT.sys [187904]
[MD5.33C3093D09017CFE2E219F2472BFF6EB] - (.Microsoft Corporation - Pilote du système de fichiers NT.) (.20/11/2010 - 03:30:08.) -- C:\Windows\system32\Drivers\ntfs.sys [1211264]
[MD5.2EA877ED5DD9713C5AC74E8EA7348D14] - (.Microsoft Corporation - Pilote de port parallèle.) (.14/07/2009 - 00:45:35.) -- C:\Windows\system32\Drivers\Parport.sys [79360]
[MD5.D9F91EAFEC2815365CBE6D167E4E332A] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.14/07/2009 - 00:54:34.) -- C:\Windows\system32\Drivers\Rasl2tp.sys [78848]
[MD5.B973FCFC50DC1434E1970A146F7E3885] - (.Microsoft Corporation - Microsoft RDP Device redirector.) (.20/11/2010 - 01:24:48.) -- C:\Windows\system32\Drivers\rdpdr.sys [133632]
[MD5.3E21C083B8A01CB70BA1F09303010FCE] - (.Microsoft Corporation - SMB Transport driver.) (.14/07/2009 - 00:53:41.) -- C:\Windows\system32\Drivers\smb.sys [71168]
[MD5.B459575348C20E8121D6039DA063C704] - (.Microsoft Corporation - TDI Translation Driver.) (.20/11/2010 - 23:39:18.) -- C:\Windows\system32\Drivers\tdx.sys [74752]
[MD5.F497F67932C6FA693D7DE2780631CFE7] - (.Microsoft Corporation - Pilote de cliché instantané du volume.) (.20/11/2010 - 03:30:18.) -- C:\Windows\system32\Drivers\volsnap.sys [245632]
~ Scan Generic Processes in 00mn 01s



---\\ Hidden files state (Hidden/Total)
~ Mes images (My Pictures) : 1/207
~ Mes Favoris (My Favorites) : 1/39
~ Mes Documents (My Documents) : 1/1622
~ Mon Bureau (My Desktop) : 0/31
~ Menu demarrer (Programs) : 1/22
~ Scan Hidden Files in 00mn 01s



---\\ Running Processes
[MD5.EED83F0FB807764F7CB97A8A6F8A4354] - (.IBM Corporation - Provide user a shortcut to some features of.) -- C:\Program Files\Encentuate\AATray.exe [2275008] [PID.2248]
[MD5.F72216C688E3D3DC09F42358961FE360] - (.IBM Corporation - DataProv Application.) -- C:\Program Files\Encentuate\DataProvider.exe [4828864] [PID.3124]
[MD5.9000FA06E80966E091A8D89BD70ED909] - (.IBM Corporation - Component of TAM E-SSO AccessAgent.) -- C:\Program Files\Encentuate\Sync.exe [2137792] [PID.4552]
[MD5.2C5AA20C922B3E2D37206C1A32D0B9E2] - (.Unknown owner - CUI.exe.) -- C:\Program Files\Manufacturer\Endpoint Agent\cui.exe [2393984] [PID.4712]
[MD5.361EB87C029B81E1CA13A0D2CDF92AA6] - (.Microsoft Corporation - Microsoft Office Communicator 2007 R2.) -- C:\Program Files\Microsoft Office Communicator\communicator.exe [5116256] [PID.2372]
[MD5.EC87FE6FC28C21AB9F41112234008522] - (.Analog Devices, Inc. - SMax4PNP.) -- C:\Program Files\Analog Devices\Core\smax4pnp.exe [1314816] [PID.2408]
[MD5.7685012305BC2C395139BAA9A1D7462E] - (.SupportSoft, Inc. - No comment.) -- C:\Program Files\level0\bin\sprtcmd.exe [202016] [PID.3284]
[MD5.07F5F51BB1921E3385C877E4A6E126F2] - (.McAfee, Inc. - Common User Interface.) -- C:\Program Files\McAfee\Common Framework\UdaterUI.exe [140608] [PID.5292]
[MD5.E5DEEA2755E79697AE62CE9DFA4F6CB4] - (.Cisco WebEx - Cisco WebEx Connect.) -- C:\Program Files\WebEx\Connect\connect.exe [1937208] [PID.2444]
[MD5.CFE2DC7D7F7063A24D27CAB09819CE3B] - (.McAfee, Inc. - McTray Application.) -- C:\Program Files\McAfee\Common Framework\McTray.exe [75072] [PID.5980]
[MD5.99CBCF9CA57ECAEF6F8E078E5287EF14] - (.McAfee, Inc. - VirusScan tray icon.) -- C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.exe [215360] [PID.2232]
[MD5.7D7FC404785D0DAADBC8CE1D6F0B4C58] - (.WebEx - WebEx mapi component.) -- C:\Program Files\WebEx\Connect\wbxcOIEx.exe [312120] [PID.2900]
[MD5.C613E69C3B191BB02C7A191741A1D024] - (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe [673040] [PID.5760]
[MD5.E8D48FD9AE7C45521EE57A0CB99CF320] - (.Adobe Systems Incorporated - Adobe® Flash® Player Installer/Uninstaller.) -- C:\WINDOWS\system32\Macromed\Flash\FlashUtil32_11_2_202_235_ActiveX.exe [351904] [PID.4900]
[MD5.CC926B0811C3FA2363C98711410FEF24] - (...) -- C:\Program Files\ZHPDiag\ZHPDiag.exe [4540928] [PID.4912]
~ Scan Processes Running in 00mn 01s



---\\ Internet Explorer Extensions, Start, Search (R4,R3,R0,R1)
R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://socrates.gm.com
R3 - URLSearchHook: (no name) - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} . (.Microsoft Corporation - Hôte de la fenêtre de la console.) (No version) -- (.not file.)
~ Scan IE Browser in 00mn 00s



---\\ Internet Explorer, Proxy Management (R5)
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll
~ Scan Proxy management in 00mn 00s



---\\ Hosts file redirection (O1)
~ Le fichier hosts est sain (The hosts file is clean).
~ Scan Hosts File in 00mn 00s
~ Nombre de lignes (Lines number): 0



---\\ Auto loading programs from Registry and folders (O4)
O4 - HKLM\..\Run: [Communicator] . (.Microsoft Corporation - Microsoft Office Communicator 2007 R2.) -- C:\Program Files\Microsoft Office Communicator\communicator.exe
O4 - HKLM\..\Run: [SoundMAXPnP] . (.Analog Devices, Inc. - SMax4PNP.) -- C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [Level0] . (.SupportSoft, Inc. - No comment.) -- C:\Program Files\Level0\bin\sprtcmd.exe
O4 - HKLM\..\Run: [McAfeeUpdaterUI] . (.McAfee, Inc. - Common User Interface.) -- C:\Program Files\McAfee\Common Framework\udaterui.exe
O4 - HKLM\..\Run: [Adobe ARM] . (.Adobe Systems Incorporated - Adobe Reader and Acrobat Manager.) -- C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
O4 - HKLM\..\Run: [APSDaemon] . (.Apple Inc. - Apple Push.) -- C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe
O4 - HKLM\..\Run: [QuickTime Task] . (.Apple Inc. - QuickTime Task.) -- C:\Program Files\QuickTime\QTTask.exe
O4 - HKLM\..\Run: [ShStatEXE] . (.McAfee, Inc. - VirusScan tray icon.) -- C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.exe
O4 - HKLM\..\Run: [Cisco WebEx Connect] . (.Cisco WebEx - Cisco WebEx Connect.) -- C:\Program Files\WebEx\Connect\connect.exe
O4 - HKLM\..\Run: [CheckUpdate] . (...) -- C:\Windows\System32\fmaj5.exe
~ Scan Application in 00mn 00s



---\\ Extra items in the IE right-click menu (O8)
O8 - Extra context menu item: E&xport to Microsoft Excel . (.Microsoft Corporation - Microsoft Office Excel.) -- C:\Program Files\MICROS~2\Office12\EXCEL.exe
~ Scan IE Menu Contextuel in 00mn 00s



---\\ Site in Trusted Zone (O15)
O15 - Trusted Zone: [HKCU\...\Domains] *.gm.com
O15 - Trusted Zone: [HKCU\...\Domains\www] *.gm.com
O15 - Trusted Zone: [HKCU\...\Domains] *.kontiki.com
O15 - Trusted Zone: [HKCU\...\Domains\www] *.kontiki.com
O15 - Trusted Zone: [HKCU\...\Domains] *.webex.com
O15 - Trusted Zone: [HKCU\...\Domains\www] *.webex.com
~ Scan IE Zone Confiance in 00mn 00s



---\\ Windows Active Desktop & MHTML Editor (O24)
O24 - Default MHTML Editor: Last - .(...) - (.not file.)
~ Scan Desktop Component in 00mn 00s



---\\ Task Planned Automatically(039)
O39 - APT:Automatic Planified Task - C:\Windows\Tasks\Adobe Flash Player Updater.job
O39 - APT:Automatic Planified Task - C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
O39 - APT:Automatic Planified Task - C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
~ Scan Scheduled Task in 00mn 04s



---\\ ActiveSetup Installed Components (O40) (None)

---\\ Contents of the Common Files folders (O43)
O43 - CFD: 24/11/2010 - 12:25:33 - [0] ----D C:\Program Files\6020AFK
O43 - CFD: 24/11/2010 - 12:20:39 - [1,257] ----D C:\Program Files\6020VBA
O43 - CFD: 21/06/2011 - 15:45:50 - [372,096] ----D C:\Program Files\Adobe
O43 - CFD: 17/11/2010 - 15:36:58 - [1,954] ----D C:\Program Files\Analog Devices
O43 - CFD: 21/01/2012 - 23:52:47 - [0,048] ----D C:\Program Files\Auralog
O43 - CFD: 21/01/2012 - 21:19:46 - [1198,540] ----D C:\Program Files\Common Files
O43 - CFD: 26/09/2011 - 16:15:29 - [79,515] ----D C:\Program Files\DVD Maker
O43 - CFD: 15/01/2012 - 12:33:33 - [82,045] ----D C:\Program Files\Encentuate
O43 - CFD: 05/02/2012 - 22:58:58 - [1,000] ----D C:\Program Files\FLIP Flash Album Free
O43 - CFD: 25/02/2012 - 08:01:14 - [138,108] ----D C:\Program Files\GIMP-2.0
O43 - CFD: 17/05/2012 - 23:23:45 - [66,496] ----D C:\Program Files\Google
O43 - CFD: 11/02/2012 - 00:40:27 - [0,012] ----D C:\Program Files\Hewlett-Packard
O43 - CFD: 24/11/2010 - 12:29:13 - [1,562] ----D C:\Program Files\InstallShield Installation Information
O43 - CFD: 19/05/2012 - 09:42:50 - [5,775] ----D C:\Program Files\Internet Explorer
O43 - CFD: 17/11/2010 - 10:55:26 - [0,024] ----D C:\Program Files\IT Service Center
O43 - CFD: 09/05/2012 - 11:46:37 - [511,521] ----D C:\Program Files\Java
O43 - CFD: 17/11/2010 - 11:13:57 - [25,261] ----D C:\Program Files\level0
O43 - CFD: 17/06/2010 - 19:01:58 - [770,614] ----D C:\Program Files\Lotus
O43 - CFD: 22/10/2011 - 23:06:50 - [59,138] ----D C:\Program Files\Manufacturer
O43 - CFD: 12/08/2011 - 13:01:38 - [0,000] ----D C:\Program Files\MaximoSilentPrint
O43 - CFD: 16/11/2011 - 21:26:09 - [160,935] ----D C:\Program Files\McAfee
O43 - CFD: 22/01/2012 - 03:55:11 - [0] ----D C:\Program Files\Microsoft
O43 - CFD: 17/06/2010 - 17:18:14 - [89,734] ----D C:\Program Files\Microsoft Games
O43 - CFD: 11/02/2012 - 00:39:21 - [916,628] ----D C:\Program Files\Microsoft Office
O43 - CFD: 17/06/2010 - 17:34:35 - [32,819] ----D C:\Program Files\Microsoft Office Communicator
O43 - CFD: 21/04/2012 - 21:29:21 - [36,634] ----D C:\Program Files\Microsoft Silverlight
O43 - CFD: 24/11/2010 - 12:25:33 - [0,154] ----D C:\Program Files\Microsoft Visual Studio
O43 - CFD: 17/06/2010 - 17:22:32 - [87,905] ----D C:\Program Files\Microsoft Visual Studio 8
O43 - CFD: 17/06/2010 - 17:34:17 - [19,555] ----D C:\Program Files\Microsoft Windows Performance Toolkit
O43 - CFD: 17/06/2010 - 17:26:05 - [3,554] ----D C:\Program Files\Microsoft Works
O43 - CFD: 11/02/2012 - 00:37:54 - [7,789] ----D C:\Program Files\Microsoft.NET
O43 - CFD: 17/06/2010 - 17:23:39 - [0,025] ----D C:\Program Files\MSBuild
O43 - CFD: 17/06/2010 - 17:33:58 - [4,257] ----D C:\Program Files\MSECache
O43 - CFD: 24/03/2012 - 12:41:00 - [0] ----D C:\Program Files\MSXML 4.0
O43 - CFD: 27/05/2012 - 05:33:48 - [72,429] ----D C:\Program Files\QuickTime
O43 - CFD: 14/05/2012 - 02:28:00 - [0,581] ----D C:\Program Files\Rapide Créateur d'Icône
O43 - CFD: 14/07/2009 - 06:52:30 - [39,391] ----D C:\Program Files\Reference Assemblies
O43 - CFD: 17/11/2010 - 11:15:58 - [301,953] ----D C:\Program Files\SAP
O43 - CFD: 02/06/2012 - 05:06:51 - [140,898] ----D C:\Program Files\Securite_Concept
O43 - CFD: 05/02/2012 - 04:40:31 - [0,000] ----D C:\Program Files\SmartDraw 2012
O43 - CFD: 28/01/2011 - 07:23:32 - [49,616] ----D C:\Program Files\Tracker Software
O43 - CFD: 02/06/2012 - 12:50:19 - [0,392] ----D C:\Program Files\Trend Micro
O43 - CFD: 14/07/2009 - 06:53:23 - [0] ----D C:\Program Files\Uninstall Information
O43 - CFD: 24/03/2012 - 10:46:53 - [15,967] ----D C:\Program Files\Viewer Central
O43 - CFD: 27/02/2012 - 19:50:12 - [56,892] ----D C:\Program Files\WebEx
O43 - CFD: 26/09/2011 - 16:15:17 - [3,108] ----D C:\Program Files\Windows Defender
O43 - CFD: 26/09/2011 - 16:15:26 - [6,905] ----D C:\Program Files\Windows Journal
O43 - CFD: 26/09/2011 - 16:15:29 - [6,944] ----D C:\Program Files\Windows Mail
O43 - CFD: 26/09/2011 - 16:15:27 - [6,572] ----D C:\Program Files\Windows Media Player
O43 - CFD: 14/07/2009 - 06:52:30 - [11,875] ----D C:\Program Files\Windows NT
O43 - CFD: 26/09/2011 - 16:15:26 - [4,309] ----D C:\Program Files\Windows Photo Viewer
O43 - CFD: 26/09/2011 - 16:15:27 - [0,181] ----D C:\Program Files\Windows Portable Devices
O43 - CFD: 26/09/2011 - 16:15:29 - [8,154] ----D C:\Program Files\Windows Sidebar
O43 - CFD: 11/02/2012 - 00:39:47 - [34,588] ----D C:\Program Files\WinZip
O43 - CFD: 14/05/2012 - 01:50:32 - [0] ----D C:\Program Files\WiseConvert
O43 - CFD: 03/06/2012 - 12:15:36 - [13,540] ----D C:\Program Files\ZHPDiag
O43 - CFD: 24/03/2012 - 12:33:17 - [3,065] ----D C:\Program Files\Common Files\Adobe
O43 - CFD: 02/06/2012 - 14:01:33 - [38,049] ----D C:\Program Files\Common Files\Adobe AIR
O43 - CFD: 04/10/2011 - 10:21:15 - [60,450] ----D C:\Program Files\Common Files\Apple
O43 - CFD: 17/11/2010 - 10:45:49 - [0,026] ----D C:\Program Files\Common Files\Cisco Systems
O43 - CFD: 24/11/2010 - 12:27:36 - [0,795] ----D C:\Program Files\Common Files\Data Dynamics
O43 - CFD: 17/06/2010 - 17:23:32 - [0,089] ----D C:\Program Files\Common Files\DESIGNER
O43 - CFD: 17/11/2010 - 11:15:51 - [9,532] ----D C:\Program Files\Common Files\ESRI
O43 - CFD: 24/11/2010 - 12:28:09 - [1,097] ----D C:\Program Files\Common Files\InstallShield
O43 - CFD: 24/11/2010 - 12:27:38 - [3,842] ----D C:\Program Files\Common Files\Interflex
O43 - CFD: 19/12/2011 - 12:37:37 - [562,519] ----D C:\Program Files\Common Files\McAfee
O43 - CFD: 11/02/2012 - 00:39:21 - [366,647] ----D C:\Program Files\Common Files\microsoft shared
O43 - CFD: 12/12/2011 - 11:55:48 - [29,804] ----D C:\Program Files\Common Files\PC SOFT
O43 - CFD: 17/11/2010 - 11:16:46 - [26,321] ----D C:\Program Files\Common Files\SAP Shared
O43 - CFD: 14/07/2009 - 04:37:05 - [0,003] ----D C:\Program Files\Common Files\Services
O43 - CFD: 14/07/2009 - 04:37:05 - [39,205] ----D C:\Program Files\Common Files\SpeechEngines
O43 - CFD: 17/11/2010 - 11:12:05 - [11,537] ----D C:\Program Files\Common Files\supportsoft
O43 - CFD: 14/12/2011 - 17:10:31 - [45,559] ----D C:\Program Files\Common Files\System
O43 - CFD: 21/01/2012 - 21:19:46 - [0] ----D C:\Program Files\Common Files\Windows Live
O43 - CFD: 12/08/2011 - 13:01:23 - [0,000] ----D C:\ProgramData\Adobe
O43 - CFD: 19/11/2010 - 13:30:34 - [0] ----D C:\ProgramData\Apple
O43 - CFD: 19/11/2010 - 13:30:24 - [0] ----D C:\ProgramData\Apple Computer
O43 - CFD: 14/07/2009 - 06:53:55 - [0] ----D C:\ProgramData\Application Data
O43 - CFD: 17/06/2010 - 17:34:39 - [15,055] ----D C:\ProgramData\Applications
O43 - CFD: 21/01/2012 - 23:44:34 - [0,001] ----D C:\ProgramData\DAEMON Tools Lite
O43 - CFD: 03/06/2012 - 09:40:45 - [0] ----D C:\ProgramData\dbg
O43 - CFD: 14/07/2009 - 06:53:55 - [0] ----D C:\ProgramData\Desktop
O43 - CFD: 14/07/2009 - 06:53:55 - [0] ----D C:\ProgramData\Documents
O43 - CFD: 14/07/2009 - 06:53:55 - [0] ----D C:\ProgramData\Favorites
O43 - CFD: 17/11/2010 - 11:05:25 - [0] ----D C:\ProgramData\GroupPolicy
O43 - CFD: 17/06/2010 - 18:58:12 - [0,354] ----D C:\ProgramData\Hewlett-Packard
O43 - CFD: 24/11/2010 - 13:00:19 - [3,745] ----D C:\ProgramData\Interflex
O43 - CFD: 17/06/2010 - 19:01:58 - [296,638] ----D C:\ProgramData\Lotus
O43 - CFD: 03/06/2012 - 11:56:04 - [35,847] ----D C:\ProgramData\McAfee
O43 - CFD: 22/01/2012 - 03:57:00 - [44,851] -S--D C:\ProgramData\Microsoft
O43 - CFD: 16/05/2012 - 16:42:58 - [0,364] ----D C:\ProgramData\Microsoft Help
O43 - CFD: 18/11/2010 - 15:16:04 - [0] ----D C:\ProgramData\RICOH
O43 - CFD: 12/12/2011 - 12:01:12 - [0,012] ----D C:\ProgramData\Securite_Concept
O43 - CFD: 17/11/2010 - 15:36:59 - [0,002] ----D C:\ProgramData\SonicFocus
O43 - CFD: 14/07/2009 - 06:53:55 - [0] ----D C:\ProgramData\Start Menu
O43 - CFD: 17/11/2010 - 11:11:51 - [17,358] ----D C:\ProgramData\SupportSoft
O43 - CFD: 14/07/2009 - 06:53:55 - [0] ----D C:\ProgramData\Templates
O43 - CFD: 20/04/2012 - 18:26:14 - [0,000] ----D C:\ProgramData\WinZip
O43 - CFD: 14/12/2011 - 15:59:50 - [1,365] ----D C:\Users\KZSQ2Q.EUR\AppData\Roaming\Adobe
O43 - CFD: 14/05/2012 - 05:26:17 - [0,001] ----D C:\Users\KZSQ2Q.EUR\AppData\Roaming\aicon
O43 - CFD: 31/12/2011 - 13:33:15 - [0,022] ----D C:\Users\KZSQ2Q.EUR\AppData\Roaming\Apple Computer
O43 - CFD: 12/05/2012 - 20:34:30 - [0,000] ----D C:\Users\KZSQ2Q.EUR\AppData\Roaming\Connect
O43 - CFD: 21/01/2012 - 23:46:01 - [0,005] ----D C:\Users\KZSQ2Q.EUR\AppData\Roaming\DAEMON Tools Lite
O43 - CFD: 19/05/2012 - 17:11:11 - [0,000] ----D C:\Users\KZSQ2Q.EUR\AppData\Roaming\gtk-2.0
O43 - CFD: 30/11/2011 - 11:56:58 - [0] ----D C:\Users\KZSQ2Q.EUR\AppData\Roaming\Identities
O43 - CFD: 05/02/2012 - 21:54:53 - [0,202] ----D C:\Users\KZSQ2Q.EUR\AppData\Roaming\iMapBuilder
O43 - CFD: 06/02/2012 - 00:04:46 - [0,022] ----D C:\Users\KZSQ2Q.EUR\AppData\Roaming\inkscape
O43 - CFD: 07/01/2012 - 20:35:22 - [0,001] ----D C:\Users\KZSQ2Q.EUR\AppData\Roaming\Interflex
O43 - CFD: 08/01/2012 - 05:30:10 - [0,000] ----D C:\Users\KZSQ2Q.EUR\AppData\Roaming\Macromedia
O43 - CFD: 28/05/2012 - 03:48:49 - [0,002] ----D C:\Users\KZSQ2Q.EUR\AppData\Roaming\Malwarebytes
O43 - CFD: 30/11/2011 - 11:57:31 - [0,345] ----D C:\Users\KZSQ2Q.EUR\AppData\Roaming\McAfee
O43 - CFD: 14/07/2009 - 09:20:18 - [0] ----D C:\Users\KZSQ2Q.EUR\AppData\Roaming\Media Center Programs
O43 - CFD: 05/03/2012 - 03:54:48 - [8,296] -S--D C:\Users\KZSQ2Q.EUR\AppData\Roaming\Microsoft
O43 - CFD: 01/01/2012 - 17:27:49 - [1,904] ----D C:\Users\KZSQ2Q.EUR\AppData\Roaming\Project Viewer 2010
O43 - CFD: 25/02/2012 - 08:13:13 - [0,001] ----D C:\Users\KZSQ2Q.EUR\AppData\Roaming\Softplicity
O43 - CFD: 08/01/2012 - 05:26:22 - [0,026] ----D C:\Users\KZSQ2Q.EUR\AppData\Roaming\TeamViewer
O43 - CFD: 05/05/2012 - 13:22:42 - [0,000] ----D C:\Users\KZSQ2Q.EUR\AppData\Roaming\vghd
O43 - CFD: 03/06/2012 - 10:57:09 - [0,031] ----D C:\Users\KZSQ2Q.EUR\AppData\Roaming\WebEx Connect
O43 - CFD: 14/12/2011 - 15:59:50 - [0,353] ----D C:\Users\KZSQ2Q.EUR\AppData\Local\Adobe
O43 - CFD: 31/12/2011 - 13:33:05 - [0,014] ----D C:\Users\KZSQ2Q.EUR\AppData\Local\Apple Computer
O43 - CFD: 14/12/2011 - 15:57:12 - [0] ----D C:\Users\KZSQ2Q.EUR\AppData\Local\Application Data
O43 - CFD: 19/05/2012 - 17:29:25 - [0] ----D C:\Users\KZSQ2Q.EUR\AppData\Local\Axialis
O43 - CFD: 24/03/2012 - 14:20:13 - [0] ----D C:\Users\KZSQ2Q.EUR\AppData\Local\ElevatedDiagnostics
O43 - CFD: 14/12/2011 - 15:57:12 - [0] ----D C:\Users\KZSQ2Q.EUR\AppData\Local\History
O43 - CFD: 14/12/2011 - 15:57:30 - [0,004] ----D C:\Users\KZSQ2Q.EUR\AppData\Local\Lotus
O43 - CFD: 27/05/2012 - 05:33:03 - [347,805] ----D C:\Users\KZSQ2Q.EUR\AppData\Local\Microsoft
O43 - CFD: 04/03/2012 - 20:53:11 - [0] ----D C:\Users\KZSQ2Q.EUR\AppData\Local\Microsoft Help
O43 - CFD: 18/02/2012 - 20:23:27 - [1,437] ----D C:\Users\KZSQ2Q.EUR\AppData\Local\SCV2
O43 - CFD: 03/06/2012 - 12:15:37 - [69,639] ----D C:\Users\KZSQ2Q.EUR\AppData\Local\Temp
O43 - CFD: 14/12/2011 - 15:57:12 - [0] ----D C:\Users\KZSQ2Q.EUR\AppData\Local\Temporary Internet Files
O43 - CFD: 12/05/2012 - 20:34:31 - [6,464] ----D C:\Users\KZSQ2Q.EUR\AppData\Local\WebEx Connect
O43 - CFD: 28/01/2012 - 09:14:09 - [0,251] ----D C:\Users\KZSQ2Q.EUR\AppData\Local\WinZip
O43 - CFD: 13/05/2012 - 19:49:47 - [0,013] R---D C:\Users\KZSQ2Q.EUR\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
O43 - CFD: 27/05/2012 - 05:40:29 - [0,000] R---D C:\Users\KZSQ2Q.EUR\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
O43 - CFD: 02/06/2012 - 13:19:12 - [0,003] ----D C:\Users\KZSQ2Q.EUR\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HiJackThis
O43 - CFD: 14/07/2009 - 06:37:42 - [0,001] R---D C:\Users\KZSQ2Q.EUR\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
O43 - CFD: 27/05/2012 - 19:30:47 - [0,000] R---D C:\Users\KZSQ2Q.EUR\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
O43 - CFD: 05/02/2012 - 04:24:25 - [0] ----D C:\Users\KZSQ2Q.EUR\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Visual Imagemapper
~ Scan Program Folder in 00mn 30s



---\\ Last modified or created files under Windows and System32 (O44)
O44 - LFC:[MD5.6C52B933B9ACE73D134752B8C077EDDF] - 03/06/2012 - 10:51:47 ---A- . (.Adobe Systems Incorporated - Adobe Flash Player Control Panel Applet.) -- C:\Windows\System32\FlashPlayerApp.exe [419488]
O44 - LFC:[MD5.2C9341C5E30174AD972AFFED9A10D5E3] - 03/06/2012 - 10:51:47 ---A- . (.Adobe Systems Incorporated - Adobe Flash Player Control Panel Applet.) -- C:\Windows\System32\FlashPlayerCPLApp.cpl [70304]
O44 - LFC:[MD5.4A0E957D9240B3F4069C48909727AE2F] - 03/06/2012 - 09:51:42 ---A- . (...) -- C:\Windows\SMSCFG.ini [462]
O44 - LFC:[MD5.6900DE8D8FC5B1A0A785DEA1ACEA5538] - 03/06/2012 - 09:48:22 ---A- . (...) -- C:\Windows\setupact.log [85723]
O44 - LFC:[MD5.6037C1124CEE31D6DEA2C5CE7A4054F7] - 03/06/2012 - 09:48:20 -S-A- . (...) -- C:\Windows\bootstat.dat [67584]
O44 - LFC:[MD5.2F0D1364CE2C204CB22E5BCA5BD36E98] - 03/06/2012 - 08:04:48 ---A- . (...) -- C:\Windows\System32\laststart [26]
O44 - LFC:[MD5.B91132A327B5C3A0FB743F2447AF5731] - 03/06/2012 - 08:01:30 ---A- . (...) -- C:\Windows\System32\PerfStringBackup.INI [2398246]
O44 - LFC:[MD5.0CD9056EA7421E6D5F10286C051DD039] - 03/06/2012 - 08:01:30 ---A- . (...) -- C:\Windows\System32\perfc009.dat [108184]
O44 - LFC:[MD5.7C08474A640B2D6D540E3CDE640755B0] - 03/06/2012 - 08:01:30 ---A- . (...) -- C:\Windows\System32\perfc00A.dat [138918]
O44 - LFC:[MD5.00C436A8AA127D47F561765270E2A3B4] - 03/06/2012 - 08:01:30 ---A- . (...) -- C:\Windows\System32\perfc00C.dat [132036]
O44 - LFC:[MD5.9BF2F1A350A07D7A15455843C35E1DC3] - 03/06/2012 - 08:01:30 ---A- . (...) -- C:\Windows\System32\perfh009.dat [630376]
O44 - LFC:[MD5.28FDC67B3D782CB5180144133D36EF64] - 03/06/2012 - 08:01:30 ---A- . (...) -- C:\Windows\System32\perfh00A.dat [707958]
O44 - LFC:[MD5.425997037D818B1FA03D12AAA9DDD3E7] - 03/06/2012 - 08:01:30 ---A- . (...) -- C:\Windows\System32\perfh00C.dat [708838]
O44 - LFC:[MD5.A6515D919BAC99EA1A26C253E18B91CF] - 03/06/2012 - 07:28:48 ---A- . (...) -- C:\Windows\ntbtlog.txt [363570]
O44 - LFC:[MD5.0A2256FC9E39C2C2B7F3320AA1ABE910] - 03/06/2012 - 07:23:00 ---A- . (...) -- C:\Windows\System32\spsys.log [552]
O44 - LFC:[MD5.03638171FE1FE2F8136331AAFBB7FAC7] - 03/06/2012 - 07:22:55 --HA- . (...) -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0.bak [12048]
O44 - LFC:[MD5.03638171FE1FE2F8136331AAFBB7FAC7] - 03/06/2012 - 07:22:55 --HA- . (...) -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0.bak [12048]
O44 - LFC:[MD5.D2D4D5D06094858E1B4FDDA56ECE8C1A] - 03/06/2012 - 07:20:02 ---A- . (...) -- C:\Windows\PFRO.log [385902]
O44 - LFC:[MD5.4431E51E8C62B37DC8B59BC1A3F5E3F7] - 01/06/2012 - 20:21:10 ---A- . (...) -- C:\Windows\WindowsUpdate.log [1556587]
O44 - LFC:[MD5.99F6963D1A57B00A129A5B49E757A7AC] - 21/05/2012 - 18:55:26 ---A- . (...) -- C:\Windows\FLUSER.INI [8293]
O44 - LFC:[MD5.46799BD8068A5551E29F6A5D8DE75FA7] - 09/05/2012 - 10:46:39 ---A- . (.Sun Microsystems, Inc. - Java(TM) Platform SE binary.) -- C:\Windows\System32\deployJava1.dll [472808]
O44 - LFC:[MD5.D2AE56CEAFD824CA022164A79FCB2F5C] - 09/05/2012 - 10:46:39 ---A- . (.Sun Microsystems, Inc. - Java(TM) Platform SE binary.) -- C:\Windows\System32\java.exe [149280]
O44 - LFC:[MD5.554E6CE596BBA78D581560A4F00B8333] - 09/05/2012 - 10:46:39 ---A- . (.Sun Microsystems, Inc. - Java(TM) Platform SE binary.) -- C:\Windows\System32\javaw.exe [149280]
O44 - LFC:[MD5.982C36CD2EA5CB73F46830638CA823E7] - 09/05/2012 - 10:46:39 ---A- . (.Sun Microsystems, Inc. - Java(TM) Web Start Launcher.) -- C:\Windows\System32\javaws.exe [157472]
~ Scan Files in 01mn 48s



---\\ Safe Boot Control (O49) (None)

---\\ MountPoints2 Shell Key (MPKS) (O51) (None)

---\\ ShareTools MSconfig StartupReg (SMSR) (O53) (None)

---\\ System Drivers List (SDL) (O58)
O58 - SDL:[MD5.9AE87D8E973B18B0CDA4A6AC69943BA5] - 22/06/2009 - 20:02:30 ---A- . (.Analog Devices, Inc. - High Definition Audio Function Driver.) -- C:\Windows\System32\Drivers\ADIHdAud.sys [381440]
O58 - SDL:[MD5.8AAD333C876590293F72B315E162BCC7] - 13/07/2009 - 22:40:41 ---A- . (...) -- C:\Windows\System32\ANSI.SYS [9029]
~ Scan Drivers in 00mn 00s



---\\ Start Menu Internet (SMI) (O68) (None)

---\\ Search Browser Infection (SBI) (O69)
O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} - (Bing) - http://www.bing.com
O69 - SBI: SearchScopes [HKCU] {8AACCDB6-FEE7-4740-B35C-060880AD947D} [DefaultScope] - (GM Search) - http://gmweb.gm.com
O69 - SBI: SearchScopes [HKCU] {AACBC36F-F553-47C7-BF8B-091B41EE23D6} - (Wikipedia) - http://en.wikipedia.org
O69 - SBI: SearchScopes [HKCU] {B685FEB1-160A-4607-A50E-DA661FE2BB23} - (GM People Finder) - http://gmweb.gm.com
O69 - SBI: SearchScopes [HKCU] {C15DDA60-0848-4950-B37F-5FDBF453ABCB} - (Google) - http://www.google.com
O69 - SBI: SearchScopes [HKCU] {C971E446-9718-4BC0-A139-93340DACDFF8} - (GM A to Z) - http://gmweb.gm.com
~ Scan Keys in 00mn 00s



---\\ Search Svchost Services (SSS) (O83) (None)

---\\ Search Particular Root Folder (SPRF) (O84)
[MD5.D78CA99E488FC130817D4244255A4B69] [SPRF][09/09/2011] (.WebUnion Media Ltd. - iMapBuilder Setup.) -- C:\Users\KZSQ2Q.EUR\AppData\Local\Temp\imapbuilder-interactive-flash-mapbuilder-6.01.exe [12703208]
[MD5.1C1D673FB3EFC0643271226EA42A25D9] [SPRF][27/03/2012] (.Conduit Ltd. - Conduit Toolbar.) -- C:\Users\KZSQ2Q.EUR\AppData\Local\Temp\nsc2416.tmp.tbWise.dll [4398376]
[MD5.1C1D673FB3EFC0643271226EA42A25D9] [SPRF][27/03/2012] (.Conduit Ltd. - Conduit Toolbar.) -- C:\Users\KZSQ2Q.EUR\AppData\Local\Temp\nsh9F4D.tmp.tbWise.dll [4398376]
[MD5.80B6B241B4264A43EACC4EC4EB2B858F] [SPRF][04/02/2012] (...) -- C:\Users\KZSQ2Q.EUR\AppData\Local\Temp\utt46FE.tmp.bat [67]
[MD5.CE406B42A9352F4C836DDA2A129029C5] [SPRF][13/05/2011] (.IBM Corporation - Upload Module.) -- C:\Windows\Downloaded Program Files\dwa85W.dll [435688]
~ Scan Files in 00mn 01s



---\\ Additionnal Scan (O88)
Database Version : 9170 - (24/05/2012)
Clés trouvées (Keys found) : 1
Valeurs trouvées (Values found) : 0
Dossiers trouvés (Folders found) : 1
Fichiers trouvés (Files found) : 0

[HKCU\Software\Totem] =>Adware.VirtualGirl
C:\Users\KZSQ2Q.EUR\AppData\Roaming\vghd =>Adware.VirtualGirl
~ Scan Additionnel in 00mn 10s



End of the scan (411 lines in 02mn 44s)(0)
0