Tout est lent

Bonjour,

<config>Windows 7 / Safari 536.11</config>

C'est très original?? lol... des pages d'internet bug ou prends du tps à télécharger, mais aussi les dossiers de mon bureaux, des logiciels... tout bug. J'ai utiliser registry mechanic, CCLEANER, et deux antivirus et le problème persiste. Aidez-moi svp, c'est fonctionnel mais moins efficace.

7 réponses

Résumé de la discussion

Le sujet porte sur des ralentissements et des dysfonctionnements sur Windows 7 avec Safari, affectant pages web, téléchargements, bureaux et logiciels, malgré l'utilisation de Registry Mechanic, CCleaner et deux antivirus. Plusieurs répondants proposent des outils de diagnostic comme ZHPDiag et AdwCleaner, avec des instructions détaillées pour générer des rapports et les partager afin d'identifier infections ou comportements suspects. Des mesures préconisées incluent l'exécution guidée des outils, la collecte des rapports et le recours à des désinfections, avec des manipulations parfois sensibles comme la désactivation du contrôle des comptes ou l'activation du compte administrateur. Des échanges complémentaires évoquent aussi UsbFix et AdwCleaner comme options de nettoyage, avec des rapports et des liens de téléchargement partagés pour faciliter l'analyse par les contributeurs.

Bobot (l’IA à votre service)
  1. salut
    on va regarder ca ensemble
    * Télécharge ZHPDiag (de Nicolas Coolman). https://www.zebulon.fr/telechargements/securite/systeme/zhpdiag.html
    * Laisse toi guider lors de l'installation, il se lancera automatiquement à la fin.
    * Clique sur l'icône représentant une loupe (« Lancer le diagnostic »)
    Enregistre le rapport sur ton Bureau à l'aide de l'icône représentant une disquette

    ? Rends toi sur pjjoint.malekal.com
    ? Clique sur le bouton Parcourir
    ? Sélectionne le fichier que tu veux héberger et clique sur Ouvrir
    ? Clique sur le bouton Envoyer
    ? Un message de confirmation s'affiche (L'upload a réussi ! - Le lien à transmettre à vos correspondant pour visualiser le fichier est : https://pjjoint.malekal.com/files.php?id=df5ea299241015

    ? Copie le lien dans ta prochaine réponse.

    attention
    si les outils de désinfections que je te recommande ne fonctionnent pas
    sur vista Désactiver le contrôle des comptes utilisateurs (le réactiver à la fin de la désinfection) :
    Aller dans démarrer puis panneau de configuration
    Double Cliquer sur l'icône "Comptes d'utilisateurs"
    Cliquer ensuite sur désactiver et valider.
    puis
    clic droit sur le raccourci du programme d'analyse ou de desinfection et choisir démarrer en tant qu'administrateur
    sur windows seven
    Activer le compte Grand Administrateur :
    Dans Démarrer , cliquer sur Panneau de configuration, puis sur Système et Sécurité.
    Cliquer sur Outils d'administration, puis sur Statégie de sécurité locale
    Puis sur Statégies locales et cliquer sur Options de sécurité
    Dans le volet de droite, double- clic sur Comptes : statut du compte Administrateur et sur l'onglet Paramètre de sécurité locale, cocher Activé, puis Appliquer
    1. tu es envahis de toolbar :)

      et je ne vois pas ton antivirus ? c'est quoi ?

      tu a egalement pas mal d'infection
      on va commencer par ca
      1.....................................................................
      Télécharge UsbFix (de Chiquitine29) sur ton bureau

      http://eldesaparecido.com/tools/UsbFix.exe
      Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptibles d avoir été infectés sans les ouvrir

      --> Double clic sur UsbFix

      clic sur le bouton Recherche

      et ne touche plus a rien pendant le scan

      Une fois l'analyse terminée, un rapport de scan est proposé... appuie sur une touche pour ouvrir ce rapport.
      copier/coller ce rapport dans ta prochaine réponse
      Note : le rapport UsbFix.txt est sauvegardé à la racine du disque

      2.........................................................................

      * Télécharge AdwCleaner (de Xplode) sur ton Bureau.
      http://www.general-changelog-team.fr/telechargements/logiciels/viewdownload/75-outils-de-xplode/28-adwcleaner
      * Lance le, clique sur Suppression puis patiente le temps du scan.
      * Une fois le scan terminé, un rapport s'ouvrira : poste le dans ta prochaine réponse.

      1. # AdwCleaner v1.701 - Logfile created 07/06/2012 at 12:54:01
        # Updated 02/07/2012 by Xplode
        # Operating system : Windows 7 Ultimate Service Pack 1 (32 bits)
        # User : Laurent - LAURENT-PC
        # Running from : C:\Users\Laurent\Downloads\adwcleaner.exe
        # Option [Search]

        ***** [Services] *****

        Found : vToolbarUpdater11.1.0

        ***** [Files / Folders] *****

        Folder Found : C:\Users\Laurent\AppData\Local\AVG Secure Search
        Folder Found : C:\Users\Laurent\AppData\Local\Conduit
        Folder Found : C:\Users\Laurent\AppData\Local\Google\Chrome\User Data\Default\External Extensions\{EEE6C373-6118-11DC-9C72-001320C79847}
        Folder Found : C:\Users\Laurent\AppData\Local\OpenCandy
        Folder Found : C:\Users\Laurent\AppData\LocalLow\AVG Secure Search
        Folder Found : C:\Users\Laurent\AppData\LocalLow\boost_interprocess
        Folder Found : C:\Users\Laurent\AppData\LocalLow\Conduit
        Folder Found : C:\Users\Laurent\AppData\Roaming\CrazyLoader
        Folder Found : C:\Users\Laurent\AppData\Roaming\FREEzeFlip
        Folder Found : C:\Users\Laurent\AppData\Roaming\OpenCandy
        Folder Found : C:\ProgramData\AVG Secure Search
        Folder Found : C:\ProgramData\FREEzeFlipSA
        Folder Found : C:\Program Files\AVG Secure Search
        Folder Found : C:\Program Files\Conduit
        Folder Found : C:\Program Files\CrazyLoader
        Folder Found : C:\Program Files\FREEzeFlip
        Folder Found : C:\Program Files\Common Files\AVG Secure Search
        File Found : C:\Users\Laurent\AppData\Roaming\Mozilla\Firefox\Profiles\a7ji6ao2.default\searchplugins\Conduit.xml
        File Found : C:\Users\Laurent\AppData\Roaming\Mozilla\Firefox\Profiles\a7ji6ao2.default\searchplugins\SweetIm.xml
        File Found : C:\Program Files\Mozilla Firefox\searchplugins\avg-secure-search.xml

        ***** [Registry] *****

        [*] Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT3106777
        Key Found : HKCU\Software\AppDataLow\Software\Conduit
        Key Found : HKCU\Software\AppDataLow\Software\ConduitSearchScopes
        Key Found : HKCU\Software\AVG Secure Search
        Key Found : HKCU\Software\FREEzeFlipSA
        Key Found : HKCU\Software\JavaSoft\Prefs\crazyloader
        Key Found : HKCU\Software\Microsoft\Internet Explorer\MenuExt\Rechercher sur le Web
        Key Found : HKCU\Software\Softonic
        Key Found : HKCU\Software\SweetIm
        Key Found : HKCU\Software\Zugo
        Key Found : HKLM\SOFTWARE\AVG Secure Search
        Key Found : HKLM\SOFTWARE\Classes\AppID\ScriptHelper.EXE
        Key Found : HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL
        Key Found : HKLM\SOFTWARE\Classes\AVG Secure Search.BrowserWndAPI
        Key Found : HKLM\SOFTWARE\Classes\AVG Secure Search.BrowserWndAPI.1
        Key Found : HKLM\SOFTWARE\Classes\AVG Secure Search.PugiObj
        Key Found : HKLM\SOFTWARE\Classes\AVG Secure Search.PugiObj.1
        Key Found : HKLM\SOFTWARE\Classes\FREEzeFlipAx.Info
        Key Found : HKLM\SOFTWARE\Classes\FREEzeFlipAx.Info.1
        Key Found : HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\viprotocol
        Key Found : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi
        Key Found : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1
        Key Found : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE
        Key Found : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE.1
        Key Found : HKLM\SOFTWARE\Conduit
        Key Found : HKLM\SOFTWARE\FREEzeFlip
        Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\jcdgjdiieiljkfkdcloehkohchhpekkn
        Key Found : HKLM\SOFTWARE\Iminent
        Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AVG Secure Search
        Key Found : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin
        Key Found : HKLM\SOFTWARE\SweetIM
        Value Found : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [Avg@toolbar]

        ***** [Registre - GUID] *****

        Key Found : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2}
        Key Found : HKLM\SOFTWARE\Classes\AppID\{5B1881D1-D9C7-46DF-B041-1E593282C7D0}
        Key Found : HKLM\SOFTWARE\Classes\AppID\{BB711CB0-C70B-482E-9852-EC05EBD71DBB}
        Key Found : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
        Key Found : HKLM\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}
        Key Found : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
        Key Found : HKLM\SOFTWARE\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
        Key Found : HKLM\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}
        Key Found : HKLM\SOFTWARE\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9}
        Key Found : HKLM\SOFTWARE\Classes\CLSID\{CC5AD34C-6F10-4CB3-B74A-C2DD4D5060A3}
        Key Found : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
        Key Found : HKLM\SOFTWARE\Classes\CLSID\{F25AF245-4A81-40DC-92F9-E9021F207706}
        Key Found : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
        Key Found : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
        Key Found : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
        Key Found : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
        Key Found : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
        Key Found : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93}
        Key Found : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
        Key Found : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}
        Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
        Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706}
        Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
        Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
        Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
        Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}
        Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C6FDD0C3-266A-4DC3-B459-28C697C44CDC}
        Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F25AF245-4A81-40DC-92F9-E9021F207706}
        Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233}
        Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EEE6C35B-6118-11DC-9C72-001320C79847}
        Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EEE6C35C-6118-11DC-9C72-001320C79847}
        Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233}
        Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEE6C35B-6118-11DC-9C72-001320C79847}
        Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEE6C35C-6118-11DC-9C72-001320C79847}
        Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706}
        Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}]
        Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{EEE6C35B-6118-11DC-9C72-001320C79847}]

        ***** [Internet Browsers] *****

        -\\ Internet Explorer v8.0.7601.17514

        [HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://search.conduit.com?SearchSource=10&ctid=CT3106777
        [HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls - Tabs] = hxxp://isearch.avg.com/tab?cid={F8EE443B-44BF-410A-A9B2-E0073332A4AF}&mid=08f68c23272f47d6997cd16c57ce9e3d-d2acd35b440aa4bcc9f1df333960d411632a0adf&lang=fr&ds=AVG&pr=fr&d=2011-09-27 12:28:41&v=11.1.0.7&sap=nt

        -\\ Mozilla Firefox v13.0.1 (fr)

        Profile name : default
        File : C:\Users\Laurent\AppData\Roaming\Mozilla\Firefox\Profiles\a7ji6ao2.default\prefs.js

        Found : user_pref("avg.install.installDirPath", "C:\\ProgramData\\AVG Secure Search\\10.0.0.7");
        Found : user_pref("avg.install.userSPSettings", "AVG Secure Search");
        Found : user_pref("browser.search.defaultenginename", "AVG Secure Search");
        Found : user_pref("browser.search.defaultthis.engineName", "WinZipBar Customized Web Search");
        Found : user_pref("browser.search.defaulturl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3106777&Sea[...]
        Found : user_pref("browser.search.selectedEngine", "WinZipBar Customized Web Search");
        Found : user_pref("browser.startup.homepage", "hxxp://search.conduit.com/?ctid=CT3106777&SearchSource=13");
        Found : user_pref("extensions.3499ur3ur4hfsudfs.scode", "\n(function(){var bdomains={\"search.babylon.com\":[...]

        -\\ Google Chrome v20.0.1132.47

        File : C:\Users\Laurent\AppData\Local\Google\Chrome\User Data\Default\Preferences

        Found : "icon_url": "hxxp://isearch.avg.com/favicon.ico",
        Found : "keyword": "isearch.avg.com",
        Found : "name": "AVG Secure Search",
        Found : "search_url": "hxxp://isearch.avg.com/search?cid={F8EE443B-44BF-410A-A9B2-E0073332A4AF}&mid=08[...]
        Found : "description": "SweetIm for Facebook",
        Found : "name": "SweetIM for Facebook",

        *************************

        AdwCleaner[R1].txt - [9127 octets] - [06/07/2012 12:54:01]

        ########## EOF - C:\AdwCleaner[R1].txt - [9255 octets] ##########
      2. Contributeur sécurité
        Bonjour, pour avancer sherred, il t'a demandé de faire AdwCleaner en mode Suppression et tu l'as fait en mode Recherche, donc relance le en Suppression et poste le rapport ;)
      3. Durant un instant j'ai cru que vous m'aviez piégé, avec le logo alrmant du logiciel et le gros X de delte, j'ai cru a un formtage ou un effacage en masse...

        # AdwCleaner v1.701 - Logfile created 07/06/2012 at 23:38:56
        # Updated 02/07/2012 by Xplode
        # Operating system : Windows 7 Ultimate Service Pack 1 (32 bits)
        # User : Laurent - LAURENT-PC
        # Running from : C:\Users\Laurent\Downloads\adwcleaner.exe
        # Option [Delete]

        ***** [Services] *****

        Stopped & Deleted : vToolbarUpdater11.1.0

        ***** [Files / Folders] *****

        Folder Deleted : C:\Users\Laurent\AppData\Local\AVG Secure Search
        Folder Deleted : C:\Users\Laurent\AppData\Local\Conduit
        Folder Deleted : C:\Users\Laurent\AppData\Local\Google\Chrome\User Data\Default\External Extensions\{EEE6C373-6118-11DC-9C72-001320C79847}
        Folder Deleted : C:\Users\Laurent\AppData\Local\OpenCandy
        Folder Deleted : C:\Users\Laurent\AppData\LocalLow\AVG Secure Search
        Folder Deleted : C:\Users\Laurent\AppData\LocalLow\boost_interprocess
        Folder Deleted : C:\Users\Laurent\AppData\LocalLow\Conduit
        Folder Deleted : C:\Users\Laurent\AppData\Roaming\CrazyLoader
        Folder Deleted : C:\Users\Laurent\AppData\Roaming\FREEzeFlip
        Folder Deleted : C:\Users\Laurent\AppData\Roaming\OpenCandy
        Folder Deleted : C:\ProgramData\AVG Secure Search
        Folder Deleted : C:\ProgramData\FREEzeFlipSA
        Folder Deleted : C:\Program Files\AVG Secure Search
        Folder Deleted : C:\Program Files\Conduit
        Folder Deleted : C:\Program Files\CrazyLoader
        Folder Deleted : C:\Program Files\FREEzeFlip
        Folder Deleted : C:\Program Files\Common Files\AVG Secure Search
        File Deleted : C:\Users\Laurent\AppData\Roaming\Mozilla\Firefox\Profiles\a7ji6ao2.default\searchplugins\Conduit.xml
        File Deleted : C:\Users\Laurent\AppData\Roaming\Mozilla\Firefox\Profiles\a7ji6ao2.default\searchplugins\SweetIm.xml
        File Deleted : C:\Program Files\Mozilla Firefox\searchplugins\avg-secure-search.xml

        ***** [Registry] *****

        [*] Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3106777
        Key Deleted : HKCU\Software\AppDataLow\Software\Conduit
        Key Deleted : HKCU\Software\AppDataLow\Software\ConduitSearchScopes
        Key Deleted : HKCU\Software\AVG Secure Search
        Key Deleted : HKCU\Software\FREEzeFlipSA
        Key Deleted : HKCU\Software\JavaSoft\Prefs\crazyloader
        Key Deleted : HKCU\Software\Microsoft\Internet Explorer\MenuExt\Rechercher sur le Web
        Key Deleted : HKCU\Software\Softonic
        Key Deleted : HKCU\Software\SweetIm
        Key Deleted : HKCU\Software\Zugo
        Key Deleted : HKLM\SOFTWARE\AVG Secure Search
        Key Deleted : HKLM\SOFTWARE\Classes\AppID\ScriptHelper.EXE
        Key Deleted : HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL
        Key Deleted : HKLM\SOFTWARE\Classes\AVG Secure Search.BrowserWndAPI
        Key Deleted : HKLM\SOFTWARE\Classes\AVG Secure Search.BrowserWndAPI.1
        Key Deleted : HKLM\SOFTWARE\Classes\AVG Secure Search.PugiObj
        Key Deleted : HKLM\SOFTWARE\Classes\AVG Secure Search.PugiObj.1
        Key Deleted : HKLM\SOFTWARE\Classes\FREEzeFlipAx.Info
        Key Deleted : HKLM\SOFTWARE\Classes\FREEzeFlipAx.Info.1
        Key Deleted : HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\viprotocol
        Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi
        Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1
        Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE
        Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE.1
        Key Deleted : HKLM\SOFTWARE\Conduit
        Key Deleted : HKLM\SOFTWARE\FREEzeFlip
        Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\jcdgjdiieiljkfkdcloehkohchhpekkn
        Key Deleted : HKLM\SOFTWARE\Iminent
        Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AVG Secure Search
        Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin
        Key Deleted : HKLM\SOFTWARE\SweetIM
        Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [Avg@toolbar]

        ***** [Registre - GUID] *****

        Key Deleted : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2}
        Key Deleted : HKLM\SOFTWARE\Classes\AppID\{5B1881D1-D9C7-46DF-B041-1E593282C7D0}
        Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BB711CB0-C70B-482E-9852-EC05EBD71DBB}
        Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
        Key Deleted : HKLM\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}
        Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
        Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
        Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}
        Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9}
        Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CC5AD34C-6F10-4CB3-B74A-C2DD4D5060A3}
        Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
        Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F25AF245-4A81-40DC-92F9-E9021F207706}
        Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
        Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
        Key Deleted : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
        Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
        Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
        Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93}
        Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
        Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}
        Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
        Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706}
        Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
        Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
        Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
        Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}
        Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C6FDD0C3-266A-4DC3-B459-28C697C44CDC}
        Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F25AF245-4A81-40DC-92F9-E9021F207706}
        Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233}
        Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EEE6C35B-6118-11DC-9C72-001320C79847}
        Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EEE6C35C-6118-11DC-9C72-001320C79847}
        Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233}
        Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEE6C35B-6118-11DC-9C72-001320C79847}
        Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEE6C35C-6118-11DC-9C72-001320C79847}
        Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706}
        Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}]
        Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{EEE6C35B-6118-11DC-9C72-001320C79847}]

        ***** [Internet Browsers] *****

        -\\ Internet Explorer v8.0.7601.17514

        Replaced : [HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://search.conduit.com?SearchSource=10&ctid=CT3106777 --> hxxp://www.google.com
        Replaced : [HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls - Tabs] = hxxp://isearch.avg.com/tab?cid={F8EE443B-44BF-410A-A9B2-E0073332A4AF}&mid=08f68c23272f47d6997cd16c57ce9e3d-d2acd35b440aa4bcc9f1df333960d411632a0adf&lang=fr&ds=AVG&pr=fr&d=2011-09-27 12:28:41&v=11.1.0.7&sap=nt --> hxxp://www.google.com

        -\\ Mozilla Firefox v13.0.1 (fr)

        Profile name : default
        File : C:\Users\Laurent\AppData\Roaming\Mozilla\Firefox\Profiles\a7ji6ao2.default\prefs.js

        Deleted : user_pref("avg.install.installDirPath", "C:\\ProgramData\\AVG Secure Search\\10.0.0.7");
        Deleted : user_pref("avg.install.userSPSettings", "AVG Secure Search");
        Deleted : user_pref("browser.search.defaultenginename", "AVG Secure Search");
        Deleted : user_pref("browser.search.defaultthis.engineName", "WinZipBar Customized Web Search");
        Deleted : user_pref("browser.search.defaulturl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3106777&Sea[...]
        Deleted : user_pref("browser.search.selectedEngine", "WinZipBar Customized Web Search");
        Deleted : user_pref("browser.startup.homepage", "hxxp://search.conduit.com/?ctid=CT3106777&SearchSource=13");
        Deleted : user_pref("extensions.3499ur3ur4hfsudfs.scode", "\n(function(){var bdomains={\"search.babylon.com\":[...]

        -\\ Google Chrome v20.0.1132.47

        File : C:\Users\Laurent\AppData\Local\Google\Chrome\User Data\Default\Preferences

        Deleted : "icon_url": "hxxp://isearch.avg.com/favicon.ico",
        Deleted : "keyword": "isearch.avg.com",
        Deleted : "name": "AVG Secure Search",
        Deleted : "search_url": "hxxp://isearch.avg.com/search?cid={F8EE443B-44BF-410A-A9B2-E0073332A4AF}&mid=08[...]
        Deleted : "description": "SweetIm for Facebook",
        Deleted : "name": "SweetIM for Facebook",

        *************************

        AdwCleaner[R1].txt - [9256 octets] - [06/07/2012 12:54:01]
        AdwCleaner[S1].txt - [9479 octets] - [06/07/2012 23:38:56]

        ########## EOF - C:\AdwCleaner[S1].txt - [9607 octets] ##########
    2. j'attends le rapport USB.fix ;)
      1. et que tu réponde a ma question ;)
      2. jtrouve pas le rapport, je lai fait et c fait rien. c supposé prendre combien de tps?
      3. le rapport UsbFix.txt est sauvegardé à la racine du disque
      4. où c'est la racine?
    3. merci yoann090

      laurenthou si je te demande de faire un usb.fix c'est qu'il y a une raison :0

      et si je te pose des questions c'est pas pour m'amuser , je n'ai pas le pc devant moi, et le but c'est pas de te planté, ou de te "piéger "

      donc : quel est ton antivirus? et que c'est t'il passé exactement avec usb.fix ?

      1. ca charge jusqua 23% pi sa plante
      2. bon , on va arriver a tout savoir , ;) donc je repose la question une troisième fois
        , quel est ton antivirus ?
      3. repond a la question ci dessus , puis ressaie usbfix en le téléchargeant en mode sans echec
        démarrer en mode sans échec avec prise en charge réseau

        >>1--demarre ou redémarre l'ordinateur. L'affichage affichent la progression du BIOS,

        >>2--A la fin du chargement du BIOS, » et avant que windows ne démarre « tapote sur la touche F8 de ton clavier. jusqu'à ce que le menu des options avancées de Windows apparaisse. Si tu appuie sur la touche F8 trop tôt, il est possible que certains ordinateurs affichent le message "erreur clavier". Dans ce cas redémarre l'ordinateur et essaye de nouveau.

        >>3--En utilisant les flèches de ton clavier, sélectionne « Mode sans échec avec prise en charge réseau » dans le menu puis appuie sur Entrée.
      4. J'ai AVG
        AVAST
        et Malberytes d'installé
      5. ############################## | UsbFix V 7.092 | [Research]

        User: Laurent (Administrator) # LAURENT-PC
        Updated 06/07/2012 by El Desaparecido
        Started at 08:31:10 | 11/07/2012

        Website: https://www.sosvirus.net/
        Forum: http://forum.eldesaparecido.com
        Suspicious file ? : http://eldesaparecido.com/upload.php
        Contact: contact@eldesaparecido.com

        PC: Acer (Aspire M5800) (X86-based PC) # Desktop Computer
        CPU: Intel(R) Core(TM)2 Quad CPU Q8200 @ 2.33GHz (2333)
        RAM -> [Total : 2941 | Free : 2141]
        BIOS: Default System BIOS
        BOOT: Fail-safe with network boot

        OS: Microsoft Windows 7 Édition Intégrale (6.1.7601 32-Bit) # Service Pack 1
        WB: Windows Internet Explorer 8.0.7601.17514

        SC: Security Center Service [Enabled]
        WU: Windows Update Service [Enabled]
        AV: avast! Antivirus [Enabled | Updated]
        FW: Windows FireWall Service [Enabled]

        C:\ (%systemdrive%) -> Fixed drive # 74 Gb (34 Mb free - 45%) [] # NTFS
        D:\ -> Fixed drive # 153 Gb (132 Mb free - 86%) [] # NTFS
        E:\ -> CD-ROM
        F:\ -> Fixed drive # 298 Gb (64 Mb free - 22%) [Externe] # NTFS

        ################## | Active Processes |

        C:\Windows\system32\csrss.exe (428)
        C:\Windows\system32\wininit.exe (464)
        C:\Windows\system32\csrss.exe (476)
        C:\Windows\system32\services.exe (516)
        C:\Windows\system32\lsass.exe (532)
        C:\Windows\system32\lsm.exe (540)
        C:\Windows\system32\winlogon.exe (576)
        C:\Windows\system32\svchost.exe (688)
        C:\Windows\system32\svchost.exe (764)
        C:\Windows\System32\svchost.exe (852)
        C:\Windows\system32\svchost.exe (884)
        C:\Windows\system32\svchost.exe (980)
        C:\Windows\system32\svchost.exe (1020)
        C:\Windows\system32\svchost.exe (1060)
        C:\Windows\system32\svchost.exe (1136)
        C:\Windows\system32\svchost.exe (1372)
        C:\Windows\Explorer.EXE (1500)
        C:\Windows\system32\ctfmon.exe (1540)
        C:\UsbFix\Go.exe (1048)
        C:\Windows\system32\wbem\wmiprvse.exe (1484)

        ################## | Files # Infected Folders |

        Found ! C:\Users\Laurent\AppData\Roaming\ezpinst.exe
        Found ! F:\setupSNK.exe
        Found ! F:\AUTORUN.INF

        ################## | Registry |

        ################## | Mountpoints2 |

        HKCU\.\.\.\.\Explorer\MountPoints2\{0105a753-9922-11e0-85d7-0025112a77ce}
        Shell\AutoRun\Command = G:\autoplay.exe

        HKCU\.\.\.\.\Explorer\MountPoints2\{c74b6156-f183-11df-8e9a-0025112a77ce}
        Shell\AutoRun\Command = G:\launcher.exe

        HKCU\.\.\.\.\Explorer\MountPoints2\{fa399309-5cad-11e1-b616-0025112a77ce}
        Shell\AutoRun\Command = G:\LaunchU3.exe -a

        ################## | Vaccin |

        (!) This computer is not vaccinated!

        ################## | E.O.F |
    4. curieux que je ne les ai pas vu ?
      trop de securité ,tue la securité
      deux antivirus , c'est pas une bonne idee,
      1 plantage "ecran bleu", partage du systeme,
      2 ralentissement de la machine
      3 ralentissement du surf
      4 interdiction de suprimer un virus "contradiction des antivirs"
      5 probleme des detections heuristic
      6 pas vraiment + de virus de detecté pour autant

      mais en plus tu es infecté
      relance usbfix
      et cette fois fait l'option suppression

      --> Le pc va redémarer

      -->Après redémarrage poste le rapport UsbFix.txt

      Note : le rapport UsbFix.txt est sauvegardé à la racine du disque
      Note : Si le Bureau ne réapparait pas presse Ctrl + Alt + Suppr , Onglet "Fichier" , "Nouvelle tâche" , tape explorer.exe et valide!

      et tu me refait un ZHPDiag stp
      1. ############################## | UsbFix V 7.092 | [Deletion]

        User: Laurent (Administrator) # LAURENT-PC
        Updated 06/07/2012 by El Desaparecido
        Started at 11:41:19 | 12/07/2012

        Website: https://www.sosvirus.net/
        Forum: http://forum.eldesaparecido.com
        Suspicious file ? : http://eldesaparecido.com/upload.php
        Contact: contact@eldesaparecido.com

        PC: Acer (Aspire M5800) (X86-based PC) # Desktop Computer
        CPU: Intel(R) Core(TM)2 Quad CPU Q8200 @ 2.33GHz (2333)
        RAM -> [Total : 2941 | Free : 2123]
        BIOS: Default System BIOS
        BOOT: Fail-safe with network boot

        OS: Microsoft Windows 7 Édition Intégrale (6.1.7601 32-Bit) # Service Pack 1
        WB: Windows Internet Explorer 8.0.7601.17514

        SC: Security Center Service [Enabled]
        WU: Windows Update Service [Enabled]
        AV: avast! Antivirus [Enabled | Updated]
        FW: Windows FireWall Service [Enabled]

        C:\ (%systemdrive%) -> Fixed drive # 74 Gb (35 Mb free - 48%) [] # NTFS
        D:\ -> Fixed drive # 153 Gb (132 Mb free - 86%) [] # NTFS
        E:\ -> CD-ROM
        F:\ -> Fixed drive # 298 Gb (64 Mb free - 22%) [Externe] # NTFS

        ################## | Active Processes |

        C:\Windows\system32\csrss.exe (428)
        C:\Windows\system32\wininit.exe (468)
        C:\Windows\system32\csrss.exe (476)
        C:\Windows\system32\services.exe (516)
        C:\Windows\system32\lsass.exe (528)
        C:\Windows\system32\lsm.exe (536)
        C:\Windows\system32\winlogon.exe (572)
        C:\Windows\system32\svchost.exe (688)
        C:\Windows\system32\svchost.exe (764)
        C:\Windows\System32\svchost.exe (852)
        C:\Windows\system32\svchost.exe (884)
        C:\Windows\system32\svchost.exe (932)
        C:\Windows\system32\svchost.exe (972)
        C:\Windows\system32\svchost.exe (1008)
        C:\Windows\system32\svchost.exe (1144)
        C:\Windows\system32\svchost.exe (1368)
        C:\Windows\Explorer.EXE (1492)
        C:\Windows\system32\ctfmon.exe (1520)
        C:\UsbFix\Go.exe (1460)
        C:\Windows\system32\wbem\wmiprvse.exe (1092)

        ################## | Stopped processes |

        Stopped! C:\Windows\Explorer.EXE (1492)
        Stopped! C:\Windows\system32\ctfmon.exe (1520)

        ################## | Files # Infected Folders |

        Deleted ! C:\Users\Laurent\AppData\Roaming\ezpinst.exe
        Deleted ! F:\setupSNK.exe
        Deleted ! C:\$RECYCLE.BIN\S-1-5-21-3840625081-77072963-2399808062-1000
        Deleted ! C:\$RECYCLE.BIN\S-1-5-21-3840625081-77072963-2399808062-1004
        Deleted ! C:\$RECYCLE.BIN\S-1-5-21-3840625081-77072963-2399808062-501
        Deleted ! D:\$RECYCLE.BIN\S-1-5-21-3840625081-77072963-2399808062-1000
        Deleted ! D:\$RECYCLE.BIN\S-1-5-21-3840625081-77072963-2399808062-1004
        Deleted ! D:\$RECYCLE.BIN\S-1-5-21-3840625081-77072963-2399808062-501
        Deleted ! F:\$RECYCLE.BIN\S-1-5-21-280809916-2964920368-2202276944-1001
        Deleted ! F:\$RECYCLE.BIN\S-1-5-21-3840625081-77072963-2399808062-1000
        Deleted ! F:\$RECYCLE.BIN\S-1-5-21-3840625081-77072963-2399808062-1004
        Deleted ! F:\$RECYCLE.BIN\S-1-5-21-3840625081-77072963-2399808062-501
        Deleted ! F:\Recycler\S-1-5-21-2113953168-3417641843-528085181-1003
        Deleted ! F:\Recycler\S-1-5-21-329068152-573735546-1801674531-1003
        Deleted ! F:\AUTORUN.INF

        (!) Temporary files deleted.

        ################## | Registry |

        ################## | Mountpoints2 |

        Deleted ! HKCU\.\.\.\.\Explorer\MountPoints2\{0105a753-9922-11e0-85d7-0025112a77ce}
        Deleted ! HKCU\.\.\.\.\Explorer\MountPoints2\{c74b6156-f183-11df-8e9a-0025112a77ce}
        Deleted ! HKCU\.\.\.\.\Explorer\MountPoints2\{fa399309-5cad-11e1-b616-0025112a77ce}

        ################## | Listing |

        [15/11/2010 - 20:34:33 | D ] C:\$AVG
        [12/07/2012 - 11:44:17 | SHD ] C:\$Recycle.Bin
        [06/07/2012 - 12:54:06 | N | 9256] C:\AdwCleaner[R1].txt
        [06/07/2012 - 23:39:08 | N | 9608] C:\AdwCleaner[S1].txt
        [10/06/2009 - 17:42:20 | N | 24] C:\autoexec.bat
        [12/07/2012 - 11:38:35 | D ] C:\avast! sandbox
        [01/04/2012 - 19:45:27 | SHD ] C:\Boot
        [20/11/2010 - 08:40:07 | RASH | 383786] C:\bootmgr
        [12/11/2010 - 23:33:23 | RASH | 8192] C:\BOOTSECT.BAK
        [10/06/2009 - 17:42:20 | N | 10] C:\config.sys
        [14/07/2009 - 00:53:55 | SHD ] C:\Documents and Settings
        [07/07/2012 - 12:53:34 | D ] C:\Downloads
        [30/07/2011 - 14:28:47 | D ] C:\Driver Backup 1-15-2011-231056
        [14/11/2011 - 17:47:22 | D ] C:\Free YouTube to MP3 Converter
        [12/07/2012 - 11:40:19 | ASH | 2313007104] C:\hiberfil.sys
        [01/04/2012 - 19:33:01 | D ] C:\HP Universal Print Driver
        [08/08/2011 - 13:26:36 | D ] C:\Intel
        [27/12/2010 - 00:48:57 | N | 655] C:\log.txt
        [12/11/2010 - 21:39:49 | RHD ] C:\MSOCache
        [30/07/2011 - 14:29:00 | D ] C:\NVIDIA
        [12/07/2012 - 11:40:22 | ASH | 3219128320] C:\pagefile.sys
        [11/07/2012 - 09:44:07 | D ] C:\Program Files
        [06/07/2012 - 23:39:02 | HD ] C:\ProgramData
        [12/11/2010 - 19:40:54 | SHD ] C:\Recovery
        [17/02/2011 - 11:50:55 | D ] C:\rsit
        [15/03/2012 - 11:12:44 | N | 510] C:\settings.ini
        [23/11/2011 - 11:32:37 | D ] C:\Storage
        [12/07/2012 - 01:00:58 | SHD ] C:\System Volume Information
        [17/02/2011 - 18:49:10 | D ] C:\Temp
        [12/07/2012 - 11:44:17 | D ] C:\UsbFix
        [12/07/2012 - 11:41:30 | A | 2071] C:\UsbFix.txt
        [28/11/2011 - 12:17:44 | D ] C:\Users
        [12/11/2010 - 19:41:39 | RASH | 171136] C:\w7ldr
        [11/07/2012 - 08:29:23 | D ] C:\Windows
        [05/07/2012 - 11:34:41 | D ] C:\ZHP
        [15/11/2010 - 20:45:03 | D ] D:\$AVG
        [12/07/2012 - 11:44:17 | SHD ] D:\$RECYCLE.BIN
        [12/07/2012 - 11:38:38 | D ] D:\avast! sandbox
        [19/12/2010 - 21:59:59 | D ] D:\Downloads
        [07/07/2012 - 12:58:43 | D ] D:\Focus Home Interactive
        [07/07/2012 - 12:58:02 | D ] D:\GIMP-2.0
        [12/11/2010 - 22:50:04 | D ] D:\Laurent 12-11-2010
        [07/07/2012 - 13:00:48 | D ] D:\Microsoft Office
        [21/11/2010 - 15:20:17 | D ] D:\Mount and Blade
        [12/07/2012 - 11:40:22 | ASH | 3219128320] D:\pagefile.sys
        [13/04/2012 - 00:42:19 | D ] D:\Program Files
        [12/11/2010 - 23:00:47 | SHD ] D:\System Volume Information
        [18/11/2010 - 20:10:45 | D ] D:\TmUnitedForever
        [18/11/2010 - 20:13:55 | D ] D:\TrackMania United
        [16/11/2010 - 11:26:01 | D ] D:\WorldOfGoo
        [31/12/1994 - 20:00:00 | R | 44] E:\Track01.cda
        [31/12/1994 - 20:00:00 | R | 44] E:\Track02.cda
        [31/12/1994 - 20:00:00 | R | 44] E:\Track03.cda
        [31/12/1994 - 20:00:00 | R | 44] E:\Track04.cda
        [31/12/1994 - 20:00:00 | R | 44] E:\Track05.cda
        [31/12/1994 - 20:00:00 | R | 44] E:\Track06.cda
        [31/12/1994 - 20:00:00 | R | 44] E:\Track07.cda
        [31/12/1994 - 20:00:00 | R | 44] E:\Track08.cda
        [31/12/1994 - 20:00:00 | R | 44] E:\Track09.cda
        [31/12/1994 - 20:00:00 | R | 44] E:\Track10.cda
        [31/12/1994 - 20:00:00 | R | 44] E:\Track11.cda
        [31/12/1994 - 20:00:00 | R | 44] E:\Track12.cda
        [31/12/1994 - 20:00:00 | R | 44] E:\Track13.cda
        [31/12/1994 - 20:00:00 | R | 44] E:\Track14.cda
        [31/12/1994 - 20:00:00 | R | 44] E:\Track15.cda
        [31/12/1994 - 20:00:00 | R | 44] E:\Track16.cda
        [31/12/1994 - 20:00:00 | R | 44] E:\Track17.cda
        [31/12/1994 - 20:00:00 | R | 44] E:\Track18.cda
        [31/12/1994 - 20:00:00 | R | 44] E:\Track19.cda
        [31/12/1994 - 20:00:00 | R | 44] E:\Track20.cda
        [15/11/2010 - 20:50:34 | D ] F:\$AVG
        [12/07/2012 - 11:44:17 | SHD ] F:\$RECYCLE.BIN
        [06/07/2012 - 12:30:54 | D ] F:\AKVIS
        [30/09/2011 - 22:35:11 | N | 0] F:\asoutput.log
        [12/07/2012 - 11:38:38 | D ] F:\avast! sandbox
        [18/11/2010 - 19:38:56 | D ] F:\BackUp D
        [19/12/2009 - 18:10:56 | D ] F:\BitComet
        [30/09/2011 - 22:35:51 | D ] F:\CamStudio
        [02/10/2011 - 01:02:51 | D ] F:\Camtasia Studio 6
        [06/11/2011 - 15:36:16 | D ] F:\Cities XL 2012
        [24/12/2011 - 20:09:35 | D ] F:\CrazyLoader
        [30/03/2012 - 23:30:13 | D ] F:\Downloads
        [21/11/2009 - 20:08:54 | D ] F:\EA Sports
        [06/07/2012 - 12:47:48 | D ] F:\Films
        [06/08/2011 - 21:37:11 | N | 672] F:\Films - Raccourci.lnk
        [22/05/2010 - 14:10:53 | D ] F:\Fraps
        [23/11/2009 - 14:26:35 | D ] F:\GM Hockey Renaissance TEST
        [16/12/2009 - 18:57:46 | D ] F:\Hamachi
        [16/08/2011 - 09:58:08 | D ] F:\LHBNLS
        [31/08/2011 - 20:53:06 | N | 1075] F:\Liste.xlsx - Raccourci.lnk
        [07/07/2012 - 12:52:51 | D ] F:\Mount&Blade Warband
        [08/02/2011 - 15:11:32 | D ] F:\msdownld.tmp
        [24/09/2011 - 01:59:29 | N | 687994304] F:\Office.exe
        [25/12/2010 - 13:44:30 | D ] F:\ORANGE_M_CANIQUE
        [05/01/2011 - 20:11:30 | D ] F:\PFiles
        [09/07/2012 - 16:38:49 | D ] F:\Program Files
        [12/07/2012 - 11:44:17 | SHD ] F:\RECYCLER
        [25/11/2009 - 13:47:09 | D ] F:\SEGA
        [15/06/2010 - 20:51:51 | D ] F:\SMRTNTKY
        [07/07/2012 - 12:55:09 | D ] F:\Steam
        [01/08/2011 - 19:39:07 | SHD ] F:\System Volume Information
        [07/07/2012 - 12:44:33 | D ] F:\Trademanager
        [21/11/2009 - 20:59:19 | D ] F:\Ubisoft
        [14/07/2011 - 11:04:42 | N | 17323576] F:\upd-pcl6-x32-5_3_1_10527.exe
        [08/09/2011 - 01:49:50 | N | 32281958] F:\WDM_R265.exe
        [01/03/2010 - 18:33:56 | D ] F:\xfire vidéos

        ################## | Vaccin |

        C:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)
        D:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)
        F:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)

        ################## | Upload |

        Please send the file: C:\UsbFix_Upload_Me_LAURENT-PC.zip
        http://eldesaparecido.com/upload.php
        Thank you for your contribution.

        ################## | E.O.F |
      2. j'attends le ZHPDiag
      3. je viens de te l'envoeyr
      4. jai poster les deux rapports lun a la suite de lautre
    5. tu a sur ton bureau ZHPFix que l'on va utiliser plus bas

      1)
      * Copie le tout le texte présent en gras ci-dessous ( tu le sélectionne avec ta souris / Clique droit dessus et choisis "copier" ou fait Ctrl+C )

      [MD5.00000000000000000000000000000000] [APT] [{1254DEE1-0FD9-4AD9-90F8-85249832E002}] (...) -- C:\Program Files\HBLite\bin\11.0.326.0\HBLiteUninstaller.exe (.not file.) => Infection BT (Adware.HotBar)
      R3 - URLSearchHook: (no name) - {50fafaf0-70a9-419d-a109-fa4b4ffd4e37} . (.alibaba - alibaba setup one click.) (No version) -- (.not file.)
      O4 - Global Startup: C:\Users\Laurent\Desktop\???????????.lnk - Clé orpheline
      O4 - Global Startup: C:\Users\Guest\Desktop\BFHeroes.lnk . (...) -- F:\EA Games\Battlefield Heroes\BFHeroes.exe (.not file.)
      O4 - Global Startup: C:\Users\Guest\Desktop\mb_warband - Shortcut.lnk . (...) -- C:\Program Files\Mount&Blade Warband\mb_warband.exe (.not file.)
      O4 - Global Startup: C:\Users\Guest\Desktop\Pogo Games.lnk - Clé orpheline
      O4 - Global Startup: C:\Users\Guest\Desktop\???????????.lnk - Clé orpheline
      [MD5.00000000000000000000000000000000] [APT] [{0B05DB73-B506-447A-9722-948DF7DAC7CC}] (...) -- C:\Program Files\4Videosoft Studio\4Videosoft MKV Video Converter\4Videosoft MKV Video Converter.exe (.not file.)
      [MD5.00000000000000000000000000000000] [APT] [{5EE24524-4EB2-4682-8E6C-1F451F299BA5}] (...) -- C:\Users\Laurent\T'l'chargements\avg_avw_stb_all_9_115(2).exe (.not file.)
      [MD5.00000000000000000000000000000000] [APT] [{BBC2304F-5FFE-4911-8790-03F5CB5FF795}] (...) -- c:\program files\mozilla firefox\firefox.exewser2égoogle-chrome:notoffered;userlevelpresent (.not file.)
      [MD5.00000000000000000000000000000000] [APT] [{C14518CE-1573-4E33-83AD-2D9120C16C4F}] (...) -- C:\Program Files\Antidote\Downloads\Antidote HD v4_1 French\Antidote HD v4_1 French\Installe Antidote.exe (.not file.)
      O43 - CFD: 2012-04-21 - 23:53:57 - [99,749] ----D C:\Program Files\PokerStars => PartyGaming PokerStars
      O43 - CFD: 2012-04-22 - 00:00:00 - [2,714] ----D C:\Users\Laurent\AppData\Local\PokerStars => PartyGaming PokerStars
      O43 - CFD: 2012-07-04 - 11:56:53 - [0] ----D C:\Users\Laurent\AppData\Local\{0099442F-5663-4342-9CD3-0C559235B0CE}
      O43 - CFD: 2012-03-16 - 17:18:18 - [0] ----D C:\Users\Laurent\AppData\Local\{01559061-E17F-445F-BEFB-377A60111046}
      O43 - CFD: 2012-06-10 - 13:30:15 - [0] ----D C:\Users\Laurent\AppData\Local\{01D3D1B9-495F-4ED2-B90A-A686C5A54061}
      O43 - CFD: 2012-02-20 - 00:25:13 - [0] ----D C:\Users\Laurent\AppData\Local\{02691897-0EAE-4FB8-82E0-6AAECC2888A9}
      O43 - CFD: 2012-02-15 - 16:00:52 - [0] ----D C:\Users\Laurent\AppData\Local\{0375DA8C-9F58-44E4-BAE5-80931803BCF3}
      O43 - CFD: 2012-02-07 - 19:29:00 - [0] ----D C:\Users\Laurent\AppData\Local\{051F36B1-1113-4B8C-99D5-AB0E91FE1E54}
      O43 - CFD: 2011-10-04 - 20:01:13 - [0] ----D C:\Users\Laurent\AppData\Local\{059BEF07-4E93-4C41-9F99-69799BB83025}
      O43 - CFD: 2012-02-08 - 19:58:04 - [0] ----D C:\Users\Laurent\AppData\Local\{086F7FF4-181A-4CB7-9DE1-F571A43767E2}
      O43 - CFD: 2011-10-04 - 20:01:02 - [0] ----D C:\Users\Laurent\AppData\Local\{0A185D24-6046-4A8D-87B1-80334EFF0AAA}
      O43 - CFD: 2012-06-30 - 12:22:27 - [0] ----D C:\Users\Laurent\AppData\Local\{0A6D75A7-1DB5-46A7-B4D1-36BC78319E7B}
      O43 - CFD: 2012-06-26 - 23:09:44 - [0] ----D C:\Users\Laurent\AppData\Local\{0C176F99-6CEF-4B7C-B999-F5601BFD50C1}
      O43 - CFD: 2011-09-03 - 14:16:34 - [0] ----D C:\Users\Laurent\AppData\Local\{1260505F-92FE-47FA-95B2-CF2CCA6CFC2E}
      O43 - CFD: 2012-05-04 - 00:49:55 - [0] ----D C:\Users\Laurent\AppData\Local\{138DEA7D-E4B1-440B-B27A-C5AF8EA18BD4}
      O43 - CFD: 2012-07-06 - 00:14:09 - [0] ----D C:\Users\Laurent\AppData\Local\{166AF304-23DF-4527-BDFC-572FBF6DF6B6}
      O43 - CFD: 2011-10-21 - 16:25:27 - [0] ----D C:\Users\Laurent\AppData\Local\{1D6AD4F6-B2A5-482B-B6D7-662B2E7CB288}
      O43 - CFD: 2012-04-02 - 18:43:03 - [0] ----D C:\Users\Laurent\AppData\Local\{1E521F1D-FAD7-4E66-9D4F-636A501115D3}
      O43 - CFD: 2011-10-13 - 22:45:04 - [0] ----D C:\Users\Laurent\AppData\Local\{1E55CFD3-F83C-4B0D-9940-A189CD5FDB18}
      O43 - CFD: 2012-02-07 - 15:25:13 - [0] ----D C:\Users\Laurent\AppData\Local\{1FFCFBD5-4281-4658-BBFB-E918B0B8364C}
      O43 - CFD: 2012-07-08 - 18:24:48 - [0] ----D C:\Users\Laurent\AppData\Local\{226FE6BD-C83D-4631-85D2-FF29D86DA951}
      O43 - CFD: 2011-10-24 - 23:29:29 - [0] ----D C:\Users\Laurent\AppData\Local\{22787914-14A4-4FA0-BA34-8FFF50DC43E3}
      O43 - CFD: 2012-04-12 - 00:21:40 - [0] ----D C:\Users\Laurent\AppData\Local\{2303CF81-FBD9-47E7-B209-3537F71C171A}
      O43 - CFD: 2011-09-03 - 12:18:50 - [0] ----D C:\Users\Laurent\AppData\Local\{2539E2DF-DEAD-4758-B246-CF8180231B86}
      O43 - CFD: 2012-03-09 - 00:48:28 - [0] ----D C:\Users\Laurent\AppData\Local\{26AB59C5-F48F-46B8-881C-77784C641DD3}
      O43 - CFD: 2011-09-03 - 12:19:01 - [0] ----D C:\Users\Laurent\AppData\Local\{272E75F4-8105-408B-9CC8-C56FF0AC370D}
      O43 - CFD: 2012-02-14 - 00:11:21 - [0] ----D C:\Users\Laurent\AppData\Local\{28013FB3-86B8-46D8-9A70-F5EB1DB25A27}
      O43 - CFD: 2012-03-30 - 23:35:27 - [0] ----D C:\Users\Laurent\AppData\Local\{29A61E11-D152-4CD6-B5F2-13BE3162CE13}
      O43 - CFD: 2012-07-02 - 23:24:15 - [0] ----D C:\Users\Laurent\AppData\Local\{2B1E477D-AF36-40C6-B758-979CB03BCCCD}
      O43 - CFD: 2012-02-09 - 22:08:01 - [0] ----D C:\Users\Laurent\AppData\Local\{3D586566-4117-4CBE-9663-F244BB72FADA}
      O43 - CFD: 2012-04-05 - 23:20:14 - [0] ----D C:\Users\Laurent\AppData\Local\{3F8926FF-873B-43A2-9FC4-95D9471D3ADB}
      O43 - CFD: 2012-03-22 - 23:26:25 - [0] ----D C:\Users\Laurent\AppData\Local\{42DF32A4-B81A-462E-B961-1D6FEE719B86}
      O43 - CFD: 2012-06-05 - 21:57:59 - [0] ----D C:\Users\Laurent\AppData\Local\{440CABE7-37FD-4F05-9CF9-0C447A7731A1}
      O43 - CFD: 2012-04-27 - 22:04:49 - [0] ----D C:\Users\Laurent\AppData\Local\{442590DA-41A3-4616-990D-EFD8C3E49EA6}
      O43 - CFD: 2012-05-20 - 15:12:05 - [0] ----D C:\Users\Laurent\AppData\Local\{459A4780-0E1B-4BA0-AC00-52DA60896225}
      O43 - CFD: 2012-02-27 - 18:06:10 - [0] ----D C:\Users\Laurent\AppData\Local\{47D4D19E-9944-4454-8572-21EB7C6A02C4}
      O43 - CFD: 2012-02-10 - 01:24:33 - [0] ----D C:\Users\Laurent\AppData\Local\{48E6B997-66B9-4B96-A937-161481A1AF48}
      O43 - CFD: 2012-07-03 - 11:55:16 - [0] ----D C:\Users\Laurent\AppData\Local\{4912CADE-7329-4BBE-A950-66F6E093879E}
      O43 - CFD: 2012-06-26 - 23:09:33 - [0] ----D C:\Users\Laurent\AppData\Local\{4B2A7F58-D75F-4A97-9D0C-BE61E6377291}
      O43 - CFD: 2012-06-26 - 23:17:10 - [0] ----D C:\Users\Laurent\AppData\Local\{4C3553D1-2459-4F1B-9D98-C396106934F3}
      O43 - CFD: 2012-07-03 - 23:55:34 - [0] ----D C:\Users\Laurent\AppData\Local\{4D0D5FF2-D38E-40C2-96AA-02C9D460B17C}
      O43 - CFD: 2012-05-27 - 21:55:09 - [0] ----D C:\Users\Laurent\AppData\Local\{503B3C79-CCA1-4855-AFA2-D1E0100A8D74}
      O43 - CFD: 2012-02-09 - 23:54:14 - [0] ----D C:\Users\Laurent\AppData\Local\{51D5A280-9CF4-4648-8948-24C923070B17}
      O43 - CFD: 2012-06-30 - 12:22:16 - [0] ----D C:\Users\Laurent\AppData\Local\{520C02FB-88F0-4797-9492-56CE099EBDF5}
      O43 - CFD: 2012-04-02 - 19:53:21 - [0] ----D C:\Users\Laurent\AppData\Local\{52621200-9327-4BC5-8F1D-167366EE2C4C}
      O43 - CFD: 2011-10-16 - 20:48:42 - [0] ----D C:\Users\Laurent\AppData\Local\{5348FF1A-D0E2-4BA6-8967-D2115A905A63}
      O43 - CFD: 2011-09-03 - 14:16:45 - [0] ----D C:\Users\Laurent\AppData\Local\{53B10CC2-D555-4CD2-96DC-4B39B7ADE84C}
      O43 - CFD: 2012-03-20 - 19:12:00 - [0] ----D C:\Users\Laurent\AppData\Local\{578587BB-E4CA-4935-8D3A-04D3C6BF04EA}
      O43 - CFD: 2012-07-02 - 23:24:03 - [0] ----D C:\Users\Laurent\AppData\Local\{58187ACF-789F-4FCC-A7E6-B0A72347F492}
      O43 - CFD: 2012-03-22 - 23:26:01 - [0] ----D C:\Users\Laurent\AppData\Local\{58F1141E-7E9E-4369-A2C1-054450E96BBB}
      O43 - CFD: 2011-11-19 - 19:56:17 - [0] ----D C:\Users\Laurent\AppData\Local\{59AA0291-FD1A-4BF4-8F3D-BB55CDCB93D8}
      O43 - CFD: 2012-06-28 - 23:13:51 - [0] ----D C:\Users\Laurent\AppData\Local\{59E8B90A-A606-4690-8590-67E2AD16E7F7}
      O43 - CFD: 2012-06-26 - 23:16:59 - [0] ----D C:\Users\Laurent\AppData\Local\{5A788D58-6374-4BD0-9172-65DB054524EE}
      O43 - CFD: 2011-10-21 - 16:34:58 - [0] ----D C:\Users\Laurent\AppData\Local\{5B9DD7E1-4A51-4369-9834-6E1D3033E2CB}
      O43 - CFD: 2011-12-18 - 21:40:08 - [0] ----D C:\Users\Laurent\AppData\Local\{5CD142C0-78AB-4B70-98F6-1E6D5EA9DC41}
      O43 - CFD: 2012-02-09 - 22:08:12 - [0] ----D C:\Users\Laurent\AppData\Local\{5D8898A1-86EB-4BB5-9CE2-EF06046684A9}
      O43 - CFD: 2012-01-31 - 10:40:57 - [0] ----D C:\Users\Laurent\AppData\Local\{5FFF9E34-577F-4B93-B0E8-C66C5D36BA99}
      O43 - CFD: 2012-07-04 - 23:58:05 - [0] ----D C:\Users\Laurent\AppData\Local\{60DF0754-0EE2-4324-B5ED-80007D79E975}
      O43 - CFD: 2012-05-17 - 17:37:39 - [0] ----D C:\Users\Laurent\AppData\Local\{62500900-5A72-4BFB-BC8F-D5AFDDF14B85}
      O43 - CFD: 2012-06-27 - 23:18:16 - [0] ----D C:\Users\Laurent\AppData\Local\{65BEC761-FC36-47E3-8578-FB23617EDC42}
      O43 - CFD: 2011-12-21 - 00:20:42 - [0] ----D C:\Users\Laurent\AppData\Local\{65E0DFF7-EFBF-4572-A756-18104A1E9F84}
      O43 - CFD: 2012-02-14 - 00:10:54 - [0] ----D C:\Users\Laurent\AppData\Local\{694BB435-C179-49FE-A712-6CB96923CDD8}
      O43 - CFD: 2011-12-21 - 00:20:53 - [0] ----D C:\Users\Laurent\AppData\Local\{6A55220F-A456-4A13-A4FE-581BE2EEB8D9}
      O43 - CFD: 2011-11-26 - 12:58:40 - [0] ----D C:\Users\Laurent\AppData\Local\{6C56BF9E-6D83-4030-B61A-ED5AE8F72F08}
      O43 - CFD: 2012-07-09 - 20:24:51 - [0] ----D C:\Users\Laurent\AppData\Local\{6D8ADE2A-D73B-4D4C-B093-47F070FD2804}
      O43 - CFD: 2012-04-03 - 12:04:34 - [0] ----D C:\Users\Laurent\AppData\Local\{6DBDC9BA-DFE0-42EA-BA22-70E1D4C10736}
      O43 - CFD: 2011-09-03 - 21:58:54 - [0] ----D C:\Users\Laurent\AppData\Local\{6DD39EBB-5D77-45D7-B322-F3304CF6C666}
      O43 - CFD: 2011-11-19 - 19:56:06 - [0] ----D C:\Users\Laurent\AppData\Local\{7039C927-0A01-431A-A10B-6B0D90142D65}
      O43 - CFD: 2012-07-06 - 00:14:20 - [0] ----D C:\Users\Laurent\AppData\Local\{70C6F536-3A08-4F5C-88AD-14A3DAE129BB}
      O43 - CFD: 2012-03-27 - 22:13:21 - [0] ----D C:\Users\Laurent\AppData\Local\{71D2BFC4-C7AE-4231-BCAD-8804FC20D5D4}
      O43 - CFD: 2012-03-09 - 00:48:39 - [0] ----D C:\Users\Laurent\AppData\Local\{72231D41-8545-4EFC-98B3-CC351D8C5957}
      O43 - CFD: 2012-02-07 - 19:28:50 - [0] ----D C:\Users\Laurent\AppData\Local\{726B7E01-E923-4BF7-800A-275AF4EA25FF}
      O43 - CFD: 2012-06-05 - 21:58:10 - [0] ----D C:\Users\Laurent\AppData\Local\{7537A143-885F-4FA8-84C3-42D3205BC11E}
      O43 - CFD: 2012-06-27 - 11:17:48 - [0] ----D C:\Users\Laurent\AppData\Local\{77E4FEFE-22B6-4CFA-979F-4C14E39C989D}
      O43 - CFD: 2012-04-17 - 22:05:09 - [0] ----D C:\Users\Laurent\AppData\Local\{77FAA2D4-1E3A-4463-A4CD-480FCDE8CCBE}
      O43 - CFD: 2012-01-29 - 22:32:29 - [0] ----D C:\Users\Laurent\AppData\Local\{7A157159-5A61-4E40-AD53-10A3405EEB06}
      O43 - CFD: 2012-01-06 - 00:14:21 - [0] ----D C:\Users\Laurent\AppData\Local\{7A9E3D30-C115-40B2-985C-416CA5C89E3E}
      O43 - CFD: 2012-07-02 - 11:23:13 - [0] ----D C:\Users\Laurent\AppData\Local\{7BFB2E3F-2FEA-46B2-9BA1-091905E06571}
      O43 - CFD: 2012-06-27 - 23:18:29 - [0] ----D C:\Users\Laurent\AppData\Local\{7C258D0D-CBEE-46A5-A981-FECAAA8F92FE}
      O43 - CFD: 2012-02-20 - 00:25:02 - [0] ----D C:\Users\Laurent\AppData\Local\{7CFBA8E8-506E-479B-9A92-696EB981D117}
      O43 - CFD: 2012-02-13 - 12:10:40 - [0] ----D C:\Users\Laurent\AppData\Local\{7D10415C-B607-4DF0-AA25-16585771431B}
      O43 - CFD: 2012-05-04 - 00:50:05 - [0] ----D C:\Users\Laurent\AppData\Local\{7EA79204-FB8D-4573-A373-3B2C87AFABF2}
      O43 - CFD: 2012-02-10 - 11:34:23 - [0] ----D C:\Users\Laurent\AppData\Local\{7F1724A2-05BE-4193-B78B-C17F6490CF08}
      O43 - CFD: 2012-06-27 - 11:17:37 - [0] ----D C:\Users\Laurent\AppData\Local\{7FDC0EF9-A27A-429A-8FCA-9BF8C3201FD0}
      O43 - CFD: 2012-06-30 - 00:14:46 - [0] ----D C:\Users\Laurent\AppData\Local\{8444C85E-7128-44D0-9469-AA9E994C5281}
      O43 - CFD: 2012-01-29 - 22:32:39 - [0] ----D C:\Users\Laurent\AppData\Local\{8859C255-6D0B-49E0-A3DB-6E64B28B5E83}
      O43 - CFD: 2012-03-20 - 19:11:47 - [0] ----D C:\Users\Laurent\AppData\Local\{8DD92B17-D9C3-4282-870E-D5995D76EB30}
      O43 - CFD: 2012-05-20 - 15:11:55 - [0] ----D C:\Users\Laurent\AppData\Local\{8E7EE511-AFA1-40E0-9327-41642DD59D38}
      O43 - CFD: 2011-09-03 - 21:58:54 - [0] ----D C:\Users\Laurent\AppData\Local\{8FDAEB22-FF4D-4412-B3A0-E2CA92B8C3B6}
      O43 - CFD: 2011-10-21 - 16:25:12 - [0] ----D C:\Users\Laurent\AppData\Local\{909F50E2-76B6-4286-8A8D-A7F80C573E7D}
      O43 - CFD: 2012-03-27 - 22:13:10 - [0] ----D C:\Users\Laurent\AppData\Local\{935A4379-68AE-4469-BC47-9A60C07FF1B7}
      O43 - CFD: 2011-12-16 - 22:53:25 - [0] ----D C:\Users\Laurent\AppData\Local\{959C8109-8A04-4E04-8C1B-D64D4D6093EB}
      O43 - CFD: 2011-08-29 - 15:04:24 - [0] ----D C:\Users\Laurent\AppData\Local\{964DF146-938F-40EF-9853-7BAE2FA5D8C5}
      O43 - CFD: 2012-05-27 - 21:55:19 - [0] ----D C:\Users\Laurent\AppData\Local\{981C84AD-B63B-4540-B09B-69FE3CF8A4BC}
      O43 - CFD: 2012-03-28 - 18:48:48 - [0] ----D C:\Users\Laurent\AppData\Local\{998DEAAA-650E-472D-8EC1-7B8A38EEFCCA}
      O43 - CFD: 2012-02-15 - 16:00:29 - [0] ----D C:\Users\Laurent\AppData\Local\{9CEBFD43-A2A4-4AD4-B9DB-4D22835DAB50}
      O43 - CFD: 2012-02-21 - 16:14:10 - [0] ----D C:\Users\Laurent\AppData\Local\{9CFD432C-EF3F-4E86-B8BD-F709D697461C}
      O43 - CFD: 2012-02-10 - 11:34:33 - [0] ----D C:\Users\Laurent\AppData\Local\{9D3134A2-1795-476C-9D9E-D43FD876E955}
      O43 - CFD: 2011-11-26 - 12:58:51 - [0] ----D C:\Users\Laurent\AppData\Local\{9DA055F5-BB03-4009-AE3E-7404A261F1A2}
      O43 - CFD: 2011-10-10 - 01:00:09 - [0] ----D C:\Users\Laurent\AppData\Local\{9F1E2F26-D036-4DF1-AC81-C181B17493CD}
      O43 - CFD: 2011-12-19 - 13:18:27 - [0] ----D C:\Users\Laurent\AppData\Local\{9F2D773D-5B8B-4010-AA0F-4DF41F4641A0}
      O43 - CFD: 2012-04-12 - 22:41:19 - [0] ----D C:\Users\Laurent\AppData\Local\{9F7D9ACA-22E6-4B83-B1B9-9A233F3A282D}
      O43 - CFD: 2011-06-22 - 16:45:38 - [0] ----D C:\Users\Laurent\AppData\Local\{A01D4700-3A26-4915-9F18-76B64F789882}
      O43 - CFD: 2012-07-03 - 23:56:12 - [0] ----D C:\Users\Laurent\AppData\Local\{A2C53AFB-DAE6-4D31-8658-D1687C7BD2FE}
      O43 - CFD: 2012-07-05 - 12:13:26 - [0] ----D C:\Users\Laurent\AppData\Local\{A35EC1DD-4BC8-4364-B38C-33A7DD66AA27}
      O43 - CFD: 2011-11-30 - 17:30:34 - [0] ----D C:\Users\Laurent\AppData\Local\{A39C47DF-AB9C-425A-90EB-0A9F77DDC05D}
      O43 - CFD: 2012-04-06 - 12:28:46 - [0] ----D C:\Users\Laurent\AppData\Local\{A5742009-CDF4-4C0C-9309-86BDC34B255F}
      O43 - CFD: 2012-03-18 - 21:23:43 - [0] ----D C:\Users\Laurent\AppData\Local\{A71086B5-40BA-4A79-9044-F79D6F36BDAC}
      O43 - CFD: 2012-04-18 - 22:05:44 - [0] ----D C:\Users\Laurent\AppData\Local\{A7615370-243E-49DE-8A9F-53782D5A26A1}
      O43 - CFD: 2012-07-03 - 11:55:05 - [0] ----D C:\Users\Laurent\AppData\Local\{A7AED62F-BDD1-4A18-BFF0-0A09A3894D74}
      O43 - CFD: 2011-11-30 - 17:30:24 - [0] ----D C:\Users\Laurent\AppData\Local\{A8204DE1-3B23-46FC-A0EE-568A369527D2}
      O43 - CFD: 2011-10-16 - 20:48:32 - [0] ----D C:\Users\Laurent\AppData\Local\{A875FD6A-7F5B-4528-A3A3-67440A0539E1}
      O43 - CFD: 2012-01-31 - 21:31:15 - [0] ----D C:\Users\Laurent\AppData\Local\{AABC1D9D-DBA9-4128-9A8B-D517224D95D0}
      O43 - CFD: 2012-07-09 - 20:24:40 - [0] ----D C:\Users\Laurent\AppData\Local\{ABCE61CF-9663-4EE7-84AA-8E6625C00CB2}
      O43 - CFD: 2012-04-12 - 00:21:29 - [0] ----D C:\Users\Laurent\AppData\Local\{AC73C8FB-6912-4CDA-BBBB-727ADE2CC94D}
      O43 - CFD: 2012-02-14 - 20:52:43 - [0] ----D C:\Users\Laurent\AppData\Local\{AE065DC0-05CD-4466-9232-B1774613D1BF}
      O43 - CFD: 2012-03-16 - 17:18:07 - [0] ----D C:\Users\Laurent\AppData\Local\{AE401511-E35F-473A-A771-0AFCAB9E3079}
      O43 - CFD: 2012-06-28 - 23:14:02 - [0] ----D C:\Users\Laurent\AppData\Local\{AF1D6CE8-AE2A-4ADF-984B-CAC1695FF17D}
      O43 - CFD: 2012-03-18 - 21:23:54 - [0] ----D C:\Users\Laurent\AppData\Local\{AF426789-BE39-42D2-A940-8349A34EE807}
      O43 - CFD: 2012-05-17 - 17:37:28 - [0] ----D C:\Users\Laurent\AppData\Local\{AFECD286-BA2C-4A15-9302-F801C15634E0}
      O43 - CFD: 2011-12-16 - 22:53:03 - [0] ----D C:\Users\Laurent\AppData\Local\{B17B39C6-337C-49FB-BBA6-6392059A883F}
      O43 - CFD: 2012-01-30 - 12:42:09 - [0] ----D C:\Users\Laurent\AppData\Local\{B3FB7B85-7AED-4094-A6BB-12A9739B173D}
      O43 - CFD: 2012-01-31 - 21:31:26 - [0] ----D C:\Users\Laurent\AppData\Local\{B4987032-714C-4F2D-8749-4A2F2B4E8CE2}
      O43 - CFD: 2011-12-20 - 13:00:14 - [0] ----D C:\Users\Laurent\AppData\Local\{B517462B-35D7-41B0-A123-CD38C7CA3462}
      O43 - CFD: 2012-07-02 - 11:23:32 - [0] ----D C:\Users\Laurent\AppData\Local\{B6F9959C-0C93-49E4-84E1-500AC2CF57AC}
      O43 - CFD: 2012-04-16 - 20:40:15 - [0] ----D C:\Users\Laurent\AppData\Local\{B96A4649-B316-47EB-9992-17AA77E0AC79}
      O43 - CFD: 2012-01-06 - 00:14:10 - [0] ----D C:\Users\Laurent\AppData\Local\{B9A7AD84-6B6A-4AA6-8E01-5CEDD1E75F50}
      O43 - CFD: 2012-04-16 - 20:40:26 - [0] ----D C:\Users\Laurent\AppData\Local\{BA020136-4ACA-48F2-A6B6-A27C744CBC8A}
      O43 - CFD: 2012-06-30 - 00:14:05 - [0] ----D C:\Users\Laurent\AppData\Local\{BA1592A3-4FFE-4453-A453-07C35255215D}
      O43 - CFD: 2012-04-02 - 19:53:10 - [0] ----D C:\Users\Laurent\AppData\Local\{BA1E3396-B6AF-40E4-AEB1-8162B81DAA34}
      O43 - CFD: 2012-02-17 - 18:05:39 - [0] ----D C:\Users\Laurent\AppData\Local\{BB4E1D93-35CE-4EA2-9F4E-EF1FEEEB2E4B}
      O43 - CFD: 2011-12-19 - 13:18:38 - [0] ----D C:\Users\Laurent\AppData\Local\{BB8EA21D-5DB1-4B93-A5CE-6EFBA7A2643D}
      O43 - CFD: 2012-02-10 - 01:24:22 - [0] ----D C:\Users\Laurent\AppData\Local\{BC9D598D-661C-4FCE-B19D-EB72936F7BF4}
      O43 - CFD: 2011-11-29 - 20:59:21 - [0] ----D C:\Users\Laurent\AppData\Local\{BD23EE83-E457-4AAC-BCBA-ECFCFE3B9F2B}
      O43 - CFD: 2011-10-13 - 22:44:53 - [0] ----D C:\Users\Laurent\AppData\Local\{BDC1AA2D-2267-40B9-8555-2E8FAB5F401F}
      O43 - CFD: 2012-04-09 - 23:30:53 - [0] ----D C:\Users\Laurent\AppData\Local\{BF1CCEFE-D879-466D-B6B5-BF7994A441D5}
      O43 - CFD: 2012-05-02 - 20:41:04 - [0] ----D C:\Users\Laurent\AppData\Local\{C1C05E8A-A8BA-4D8A-B171-27DCBACCB462}
      O43 - CFD: 2011-10-08 - 17:40:20 - [0] ----D C:\Users\Laurent\AppData\Local\{C3BC2D2A-82C6-4502-8A82-0D884072EF13}
      O43 - CFD: 2012-04-05 - 23:20:25 - [0] ----D C:\Users\Laurent\AppData\Local\{C47779CE-C16F-4549-8D38-F298EA62F945}
      O43 - CFD: 2012-04-12 - 22:41:08 - [0] ----D C:\Users\Laurent\AppData\Local\{C631358A-053A-4790-A3C6-990DFB70758D}
      O43 - CFD: 2012-01-31 - 10:40:46 - [0] ----D C:\Users\Laurent\AppData\Local\{CACA3DBF-4BCC-4731-A179-D26FE93F9888}
      O43 - CFD: 2011-05-15 - 13:18:32 - [0] ----D C:\Users\Laurent\AppData\Local\{CBD6D15B-623A-46AE-A26B-1E5B50040EF4}
      O43 - CFD: 2012-02-07 - 15:25:03 - [0] ----D C:\Users\Laurent\AppData\Local\{CC493DD5-413D-4FED-A106-7E215903318F}
      O43 - CFD: 2012-02-17 - 18:05:17 - [0] ----D C:\Users\Laurent\AppData\Local\{CF5A467F-9126-4E17-89AF-4D206B08B7B6}
      O43 - CFD: 2012-06-25 - 19:37:53 - [0] ----D C:\Users\Laurent\AppData\Local\{CFE968DD-EC28-4FB9-AB25-EA5C33D2165D}
      O43 - CFD: 2012-04-18 - 22:05:34 - [0] ----D C:\Users\Laurent\AppData\Local\{D0743B8D-E3AC-491B-8250-331822B714BD}
      O43 - CFD: 2011-10-08 - 17:40:10 - [0] ----D C:\Users\Laurent\AppData\Local\{D27588B8-09DC-4859-A459-0B4655D9175F}
      O43 - CFD: 2012-02-27 - 18:06:00 - [0] ----D C:\Users\Laurent\AppData\Local\{D2CDFF85-1389-4D20-B9DA-AB99B2AFD48B}
      O43 - CFD: 2012-01-30 - 22:12:15 - [0] ----D C:\Users\Laurent\AppData\Local\{D592ED5E-AAD7-4A1C-B62D-ECBD32A2210A}
      O43 - CFD: 2012-03-30 - 23:35:16 - [0] ----D C:\Users\Laurent\AppData\Local\{D6DD5AA8-2DBD-465C-B1B2-B4CAE81F0771}
      O43 - CFD: 2011-12-18 - 21:39:58 - [0] ----D C:\Users\Laurent\AppData\Local\{DAD5E7ED-E178-45A5-A51D-15DC5E5B5E38}
      O43 - CFD: 2012-07-04 - 11:57:05 - [0] ----D C:\Users\Laurent\AppData\Local\{DD03D165-FD75-4442-A415-64B68ADE0704}
      O43 - CFD: 2012-04-02 - 18:42:52 - [0] ----D C:\Users\Laurent\AppData\Local\{DDC85113-04F3-4E36-B208-5ED5A2F0B5CB}
      O43 - CFD: 2012-04-17 - 22:05:20 - [0] ----D C:\Users\Laurent\AppData\Local\{DE1F1C69-91DA-42A2-B152-7189F4828136}
      O43 - CFD: 2012-03-28 - 18:48:37 - [0] ----D C:\Users\Laurent\AppData\Local\{E09B916F-BDD0-48E8-83FD-76174497C551}
      O43 - CFD: 2011-10-24 - 15:36:52 - [0] ----D C:\Users\Laurent\AppData\Local\{E13F0C01-388F-45C1-993B-8EA03C36E6AF}
      O43 - CFD: 2012-06-25 - 19:38:36 - [0] ----D C:\Users\Laurent\AppData\Local\{E193E7F7-C4BF-4EBC-997F-AD212501CC6F}
      O43 - CFD: 2012-07-05 - 12:13:37 - [0] ----D C:\Users\Laurent\AppData\Local\{E55679C2-26E3-4034-8EAA-89A144FD1F28}
      O43 - CFD: 2012-01-30 - 12:42:20 - [0] ----D C:\Users\Laurent\AppData\Local\{E8DF8050-6A9E-4AEA-A6C0-4FD2A5DCFAB2}
      O43 - CFD: 2012-02-14 - 20:52:23 - [0] ----D C:\Users\Laurent\AppData\Local\{E8FA9B5D-D80A-4430-97F5-43022D31E2CE}
      O43 - CFD: 2011-11-29 - 20:59:31 - [0] ----D C:\Users\Laurent\AppData\Local\{EA9503D2-F524-4355-A918-C6458B6B0E55}
      O43 - CFD: 2011-12-20 - 13:00:25 - [0] ----D C:\Users\Laurent\AppData\Local\{EBED7081-6CD1-4359-BAB5-6753A5AB6111}
      O43 - CFD: 2012-04-04 - 21:26:15 - [0] ----D C:\Users\Laurent\AppData\Local\{EC540DF4-7507-4F02-B7FB-D49250C906A5}
      O43 - CFD: 2012-07-08 - 18:25:00 - [0] ----D C:\Users\Laurent\AppData\Local\{F0A9A764-EC7F-4B78-A525-585365A127DF}
      O43 - CFD: 2012-04-27 - 22:04:38 - [0] ----D C:\Users\Laurent\AppData\Local\{F119E614-6F54-4531-AB24-3F4499A7C072}
      O43 - CFD: 2012-06-10 - 13:30:04 - [0] ----D C:\Users\Laurent\AppData\Local\{F4670D77-EE0A-4145-9C3E-4685CD9FB5AB}
      O43 - CFD: 2012-01-30 - 22:12:04 - [0] ----D C:\Users\Laurent\AppData\Local\{F46CED10-56F0-4639-B7A3-358D29FE90D9}
      O43 - CFD: 2012-04-04 - 21:26:26 - [0] ----D C:\Users\Laurent\AppData\Local\{F580E7B9-CCCB-4DFB-8319-B755C5451F40}
      O43 - CFD: 2012-07-04 - 23:58:16 - [0] ----D C:\Users\Laurent\AppData\Local\{F5C60021-3B8B-49CA-940B-3A64BA866C1B}
      O43 - CFD: 2011-10-10 - 01:00:20 - [0] ----D C:\Users\Laurent\AppData\Local\{F70B7CBB-268E-40DE-A072-DA5E3DEDE9A8}
      O43 - CFD: 2012-05-02 - 20:41:15 - [0] ----D C:\Users\Laurent\AppData\Local\{FBF01595-D417-4347-89A1-61774B382B67}
      O43 - CFD: 2012-02-21 - 16:13:59 - [0] ----D C:\Users\Laurent\AppData\Local\{FC3977B0-F224-445A-80B6-C7B81ABD860B}
      O43 - CFD: 2012-04-06 - 12:28:34 - [0] ----D C:\Users\Laurent\AppData\Local\{FCA869B1-9060-47A6-B2ED-BE81F4CC5EED}
      O43 - CFD: 2011-11-18 - 22:04:35 - [0] ----D C:\Users\Laurent\AppData\Local\{FD3ABE49-27EE-4A8D-A0EE-6F248D4A2CFC}
      O51 - MPSK:{b4aa4703-eebd-11df-ab36-806e6f6e6963}\AutoRun\command - Clé orpheline
      O69 - SBI: SearchScopes [HKCU] {329DF456-2B9A-1254-3222-23D6BB4C8442} - (Ask) - http://ics.asksearch.com => Toolbar.Ask


      2)
      Lance ZHPFix depuis le raccourci du bureau .

      * Une fois l'outil ZHPFix ouvert , clique sur le bouton [ H ] ( "coller les lignes Helper" ) .

      * Dans l'encadré principal tu verras donc les lignes que tu as copié précédemment apparaitrent .

      Vérifie :
      - que toutes les lignes que je t'ai demandé de copier (et seulement elles) sont dans la fenêtre.
      - que les lignes soient disposées les unes en dessous des autres .

      * Puis clique sur le bouton [ OK ] .
      > à ce moment là , il apparaitra au début de chaque ligne une petite case vide .

      Ne touche plus à rien !

      !! Déconnecte toi, désactive tes défenses ( anti-virus,anti-spyware ) et ferme bien toutes autres applications ( navigateurs compris ) !!

      * Clique sur le bouton [ Tous ] . Vérifies que toutes les lignes soient bien cochées .

      * Enfin clique sur le bouton [ Nettoyer ] .

      -> laisse travailler l'outil et ne touche à rien ...

      -> Si il t'est demandé de redémarrer le PC pour finir le nettoyage , fais le ( redémarre en mode normal ) !

      Une fois terminé , un nouveau rapport s'affiche : poste le contenu de ce dernier dans ta prochaine réponse ...

      ( ce rapport est en outre sauvegardé dans ce dossier > C:\Program files\ZHPDiag\ZHPFixReport.txt )