Ecran noir à l'ouverture d'une session Windows, et plus encore.. [Résolu/Fermé]

Signaler
Messages postés
26
Date d'inscription
dimanche 13 janvier 2013
Statut
Membre
Dernière intervention
3 février 2013
-
Messages postés
35446
Date d'inscription
jeudi 18 décembre 2008
Statut
Contributeur sécurité
Dernière intervention
5 mai 2017
-
Bonjour,

Tout d'abord, il va vous sembler que ce sujet a été longtemps résolu, mais ce n'est pas le cas, car beaucoup d'internautes dont moi, sommes bloqués dans ce problème.
En fait, quand je démarre mon PC, tout est normal, on me demande de saisir mon MDP dans mon compte admin. c'est bien, mais quand je rentre tout est noir, impossible de créer une nouvelle tâche vu que le gestionnaire de tâches est désactivé. D'accord, j'essaie d'ouvrir une autre session, mais elle se ferme aussitôt qu'elle s'ouvre. Ensuite, j'essaie de passer en MSE, MSE avec prise en charge réseau, toujours pas de gestionnaire de tâches, mais dans les autres session, ça marche ! Et quand je rentre en MSE avec invite de commandes dans mon compte admin. j'arrive à démarrer explorer.exe, pour activer le gestionnaire de tâches alors, j'essaie de faire la manip dans le registre, mais cela ne marche pas non plus. Quand j'essaie de m'attribuer les droits, je vois ce maudit TrustedInstaller, mais je m'approprie quand même l'objet avec divers manips, mais je ne résous toujours pas mon problème. Je n'ai pas envie de passer par le formatage. Et merci d'avance pour votre aide.
PS: Au fait, j'ai posté ce message dans la rubrique Virus-Sécurité, car je crains que ce soit un virus qui me cause ces problèmes.


8 réponses


salut as tu internet en mode sans echec avec prise en charge reseau ?
Messages postés
26
Date d'inscription
dimanche 13 janvier 2013
Statut
Membre
Dernière intervention
3 février 2013

Oui, mais pas avec mon compte admin. Qui est toujours figé sur l'écran noir.

Télécharge ici :OTL

enregistre le sur ton Bureau.

si tu as XP => double clique
si tu as Vista ou windows 7 => clic droit "executer en tant que...."


sur OTL.exe pour le lancer.

=> Clique ici pour voir la Configuration

▶ Copie et colle le contenu de ce qui suit en gras dans la partie inférieure d'OTL "Personnalisation"

/md5start
explorer.exe
winlogon.exe
wininit.exe
volsnap.sys
atapi.sys
ndisuio.sys
ndis.sys
cdrom.sys
i8042prt.sys
iastor.sys
net.exe
tdx.sys
netbt.sys
afd.sys
net1.exe
Rundll32.exe
/md5stop
netsvcs
safebootminimal
safebootnetwork
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\system32\*.exe /lockedfiles
%systemroot%\system32\*.ini
%systemroot%\Tasks\*.*
%systemroot%\system32\Tasks\*.*
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\system32\config\*.exe /s
%systemroot%\system32\*.sys
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa /s
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon
CREATERESTOREPOINT


▶ Clic sur Analyse.

A la fin du scan, le Bloc-Notes va s'ouvrir avec le rapport (OTL.txt).

Ce fichier est sur ton Bureau (en général C:\Documents and settings\le_nom_de_ta_session\<Bureau ou Desktop>\OTL.txt)

▶▶▶ NE LE POSTE PAS SUR LE FORUM (il est trop long)

heberge OTL.txt et extra.txt sur https://www.cjoint.com/ et donne les liens
Messages postés
26
Date d'inscription
dimanche 13 janvier 2013
Statut
Membre
Dernière intervention
3 février 2013

Extras.txt : https://www.cjoint.com/?3AnpKtx6Wof
OTL.txt : https://www.cjoint.com/?3AnpJ2dZsfU

On passera au champagne j'espère ! :3
Messages postés
35446
Date d'inscription
jeudi 18 décembre 2008
Statut
Contributeur sécurité
Dernière intervention
5 mai 2017
4 728
Si tu paie le champ' pas de soucis :b

=================================

Ton PC c'est plus une poubelle mais un container !!!

ATTENTION !!! : Script personnalisé pour cette machine uniquement , ne pas reproduire !!


si tu as XP => double clique
si tu as Vista ou windows 7 => clic droit "executer en tant que...."


sur OTL.exe pour le lancer.


▶ Copie les instructions hébergées dans CE LIEN colle-la dans la zone sous "Personnalisation" :

▶ Clique sur "Correction" pour lancer la suppression.


▶ Poste le rapport qui logiquement s'ouvrira tout seul en fin de travail apres le redemarrage.

Messages postés
26
Date d'inscription
dimanche 13 janvier 2013
Statut
Membre
Dernière intervention
3 février 2013

Je sais, je sais, c'est écologique les container ! :D
Messages postés
35446
Date d'inscription
jeudi 18 décembre 2008
Statut
Contributeur sécurité
Dernière intervention
5 mai 2017
4 728
MDR.

Bon, j'attends le rapport de correction OTL et on passera ensuite aux outils spécifiques :)

@ te lire
Messages postés
26
Date d'inscription
dimanche 13 janvier 2013
Statut
Membre
Dernière intervention
3 février 2013

All processes killed
Error: Unable to interpret <:instructions> in the current context!
========== OTL ==========
No active process named SSVICHOSST.exe was found!
Service Web Assistant Updater stopped successfully!
Service Web Assistant Updater deleted successfully!
C:\Program Files\Web Assistant\ExtensionUpdaterService.exe moved successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{05eeb91a-aef7-4f8a-978f-fb83e7b03f8e} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{05eeb91a-aef7-4f8a-978f-fb83e7b03f8e}\ deleted successfully.
C:\Program Files\uTorrentBar_FR\prxtbuTo2.dll moved successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{235CD7CF-DF47-4617-AB9C-A1689D2A45F2}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{235CD7CF-DF47-4617-AB9C-A1689D2A45F2}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{8A96AF9E-4074-43b7-BEA3-87217BDA74C8}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8A96AF9E-4074-43b7-BEA3-87217BDA74C8}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2413}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2413}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{afdbddaa-5d3f-42ee-b79c-185a7020515b}\ not found.
Registry value HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\URLSearchHooks\\{9CB65206-89C4-402c-BA80-02D8C59F9B1D} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9CB65206-89C4-402c-BA80-02D8C59F9B1D}\ deleted successfully.
Registry key HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes\{4B8C28A7-A9BC-45F8-990D-21499EED643C}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4B8C28A7-A9BC-45F8-990D-21499EED643C}\ not found.
Registry value HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\URLSearchHooks\\{9CB65206-89C4-402c-BA80-02D8C59F9B1D} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9CB65206-89C4-402c-BA80-02D8C59F9B1D}\ not found.
Registry key HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes\{4B8C28A7-A9BC-45F8-990D-21499EED643C}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4B8C28A7-A9BC-45F8-990D-21499EED643C}\ not found.
Registry value HKEY_USERS\S-1-5-21-2170562045-1414757869-1238418950-500\Software\Microsoft\Internet Explorer\URLSearchHooks\\{9CB65206-89C4-402c-BA80-02D8C59F9B1D} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9CB65206-89C4-402c-BA80-02D8C59F9B1D}\ not found.
HKEY_USERS\S-1-5-21-2170562045-1414757869-1238418950-500\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_USERS\S-1-5-21-2170562045-1414757869-1238418950-500\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}\ not found.
Registry key HKEY_USERS\S-1-5-21-2170562045-1414757869-1238418950-500\Software\Microsoft\Internet Explorer\SearchScopes\{235CD7CF-DF47-4617-AB9C-A1689D2A45F2}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{235CD7CF-DF47-4617-AB9C-A1689D2A45F2}\ not found.
Registry key HKEY_USERS\S-1-5-21-2170562045-1414757869-1238418950-500\Software\Microsoft\Internet Explorer\SearchScopes\{4B8C28A7-A9BC-45F8-990D-21499EED643C}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4B8C28A7-A9BC-45F8-990D-21499EED643C}\ not found.
Registry key HKEY_USERS\S-1-5-21-2170562045-1414757869-1238418950-500\Software\Microsoft\Internet Explorer\SearchScopes\{8A96AF9E-4074-43b7-BEA3-87217BDA74C8}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8A96AF9E-4074-43b7-BEA3-87217BDA74C8}\ not found.
Registry key HKEY_USERS\S-1-5-21-2170562045-1414757869-1238418950-500\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2413}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2413}\ not found.
Registry key HKEY_USERS\S-1-5-21-2170562045-1414757869-1238418950-500\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{afdbddaa-5d3f-42ee-b79c-185a7020515b}\ not found.
Registry key HKEY_USERS\S-1-5-21-2170562045-1414757869-1238418950-500\Software\Microsoft\Internet Explorer\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}\ not found.
Prefs.js: ShopperReports@ShopperReports.com:3.0.517.0 removed from extensions.enabledItems
Prefs.js: "http://www1.search-results.com/web?l=dis&q=&o=APN10655&apn_dtid=%5EBND101%5EYY%5EFR&shad=s_0043&gct=ds&apn_ptnrs=%5EAG5&d=101-0&lang=en&atb=sysid%3D101%3Auid%3D91d66e44bfdc920e%3Asrc%3Dffb%3Ao%3DAPN10644%3Atg%3D&p2=%5EAG5%5EBND101%5EYY%5EFR" removed from keyword.URL
Registry value HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\ShopperReports@ShopperReports.com deleted successfully.
C:\Program Files\ShopperReports3\bin\3.0.517.0\firefox\firefoxtoolbar\extensions\components folder moved successfully.
C:\Program Files\ShopperReports3\bin\3.0.517.0\firefox\firefoxtoolbar\extensions\chrome folder moved successfully.
C:\Program Files\ShopperReports3\bin\3.0.517.0\firefox\firefoxtoolbar\extensions folder moved successfully.
Registry value HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\ClickPotatoLite@ClickPotatoLite.com deleted successfully.
File C:\Program Files\ClickPotatoLite\bin\11.0.19.0\firefox\extensions not found.
Registry value HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{336D0C35-8A85-403a-B9D2-65C292C39087} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{336D0C35-8A85-403a-B9D2-65C292C39087}\ deleted successfully.
C:\Program Files\Web Assistant\Firefox\defaults\preferences folder moved successfully.
C:\Program Files\Web Assistant\Firefox\defaults folder moved successfully.
C:\Program Files\Web Assistant\Firefox\chrome\skin folder moved successfully.
C:\Program Files\Web Assistant\Firefox\chrome\locale\en-US folder moved successfully.
C:\Program Files\Web Assistant\Firefox\chrome\locale folder moved successfully.
C:\Program Files\Web Assistant\Firefox\chrome\content\resources folder moved successfully.
C:\Program Files\Web Assistant\Firefox\chrome\content\libraries folder moved successfully.
C:\Program Files\Web Assistant\Firefox\chrome\content folder moved successfully.
C:\Program Files\Web Assistant\Firefox\chrome folder moved successfully.
C:\Program Files\Web Assistant\Firefox folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\ffxtlbr@babylon.com folder moved successfully.
Folder C:\PROGRAM FILES\SHOPPERREPORTS3\BIN\3.0.517.0\FIREFOX\FIREFOXTOOLBAR\EXTENSIONS\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2EECD738-5844-4a99-B4B6-146BF802613B}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2EECD738-5844-4a99-B4B6-146BF802613B}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{05eeb91a-aef7-4f8a-978f-fb83e7b03f8e}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{05eeb91a-aef7-4f8a-978f-fb83e7b03f8e}\ not found.
File C:\Program Files\uTorrentBar_FR\prxtbuTo2.dll not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{336D0C35-8A85-403a-B9D2-65C292C39087}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{336D0C35-8A85-403a-B9D2-65C292C39087}\ not found.
C:\Program Files\Web Assistant\Extension32.dll moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{43465D15-D37D-69EA-955D-0B1F2BDC7400}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{43465D15-D37D-69EA-955D-0B1F2BDC7400}\ deleted successfully.
C:\ProgramData\ADDICT-THING\bhoclass.dll moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6E13DDE1-2B6E-46CE-8B66-DC8BF36F6B99}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6E13DDE1-2B6E-46CE-8B66-DC8BF36F6B99}\ deleted successfully.
C:\Program Files\Incredibar.com\incredibar\1.5.11.14\bh\incredibar.dll moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7}\ deleted successfully.
C:\Program Files\Funmoods\1.5.23.22\bh\escort.dll moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{99079a25-328f-4bd4-be04-00955acaa0a7}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{99079a25-328f-4bd4-be04-00955acaa0a7}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9CB65201-89C4-402c-BA80-02D8C59F9B1D}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9CB65201-89C4-402c-BA80-02D8C59F9B1D}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A40DC6C5-79D0-4ca8-A185-8FF989AF1115}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A40DC6C5-79D0-4ca8-A185-8FF989AF1115}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A6174F27-1FFF-E1D6-A93F-BA48AD5DD448}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A6174F27-1FFF-E1D6-A93F-BA48AD5DD448}\ deleted successfully.
C:\Program Files\DealPly\DealPlyIE.dll moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AB360879-1D2D-C380-48EF-7A54738B9FAC}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AB360879-1D2D-C380-48EF-7A54738B9FAC}\ deleted successfully.
C:\ProgramData\TheBflix\bhoclass.dll moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ deleted successfully.
C:\Program Files\Ask.com\GenericAskToolbar.dll moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FE063DB1-4EC0-403e-8DD8-394C54984B2C}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FE063DB1-4EC0-403e-8DD8-394C54984B2C}\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{05eeb91a-aef7-4f8a-978f-fb83e7b03f8e} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{05eeb91a-aef7-4f8a-978f-fb83e7b03f8e}\ not found.
File C:\Program Files\uTorrentBar_FR\prxtbuTo2.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{98889811-442D-49dd-99D7-DC866BE87DBC} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{98889811-442D-49dd-99D7-DC866BE87DBC}\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{99079a25-328f-4bd4-be04-00955acaa0a7} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{99079a25-328f-4bd4-be04-00955acaa0a7}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{D4027C7F-154A-4066-A1AD-4243D8127440} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ not found.
File C:\Program Files\Ask.com\GenericAskToolbar.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{F9639E4A-801B-4843-AEE3-03D9DA199E77} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F9639E4A-801B-4843-AEE3-03D9DA199E77}\ deleted successfully.
C:\Program Files\Incredibar.com\incredibar\1.5.11.14\incredibarTlbr.dll moved successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{FE063DB9-4EC0-403e-8DD8-394C54984B2C} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FE063DB9-4EC0-403e-8DD8-394C54984B2C}\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\10 deleted successfully.
Registry value HKEY_USERS\S-1-5-21-2170562045-1414757869-1238418950-500\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{05EEB91A-AEF7-4F8A-978F-FB83E7B03F8E} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{05EEB91A-AEF7-4F8A-978F-FB83E7B03F8E}\ not found.
File C:\Program Files\uTorrentBar_FR\prxtbuTo2.dll not found.
Registry value HKEY_USERS\S-1-5-21-2170562045-1414757869-1238418950-500\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{FE063DB9-4EC0-403E-8DD8-394C54984B2C} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FE063DB9-4EC0-403E-8DD8-394C54984B2C}\ not found.
Registry value HKEY_USERS\S-1-5-21-2170562045-1414757869-1238418950-1001\\Software\Microsoft\Windows\CurrentVersion\Run\\Yahoo Messengger deleted successfully.
C:\Windows\System32\SSVICHOSST.exe moved successfully.
Registry value HKEY_USERS\S-1-5-21-2170562045-1414757869-1238418950-500\\Software\Microsoft\Windows\CurrentVersion\Run\\Yahoo Messengger deleted successfully.
File C:\Windows\System32\SSVICHOSST.exe not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:c:\progra~1\wia6eb~1\datamngr\datamngr.dll deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:c:\progra~1\wia6eb~1\datamngr\iebho.dll deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell:SSVICHOSST.exe deleted successfully.
File C:\Windows\System32\SSVICHOSST.exe not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\Program Files\uckehjxn\dicqumhe.exe deleted successfully.
C:\Program Files\uckehjxn\dicqumhe.exe moved successfully.
C:\Program Files\DealPly folder moved successfully.
C:\Program Files\Funmoods\1.5.23.22\bh folder moved successfully.
C:\Program Files\Funmoods\1.5.23.22 folder moved successfully.
C:\Program Files\Funmoods folder moved successfully.
C:\Program Files\uckehjxn folder moved successfully.
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\dicqumhe.exe moved successfully.
C:\Windows\SSVICHOSST.exe moved successfully.
C:\Windows\System32\bandoolmx.dll moved successfully.
========== FILES ==========
[color=#A23BEC]< ipconfig /flushdns /c >/color
Configuration IP de Windows
Cache de r'solution DNS vid'.
C:\Users\xx.XXPC\Downloads\cmd.bat deleted successfully.
C:\Users\xx.XXPC\Downloads\cmd.txt deleted successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: Administrateur

User: All Users

User: Default

User: Default User

User: oncf

User: Public

User: TEMP

User: xx

User: xx.XXPC

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 109289400 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 104,00 mb


OTL by OldTimer - Version 3.2.69.0 log created on 01132013_150244
Messages postés
35446
Date d'inscription
jeudi 18 décembre 2008
Statut
Contributeur sécurité
Dernière intervention
5 mai 2017
4 728
De retour :)

Tu as toujours rkfree sur ton PC ?

===========================

Pour le rapport Malwarebytes : https://dl.dropbox.com/u/22950063/mbam.JPG
J'en ai besoin, STP :)

===========================

Si je ne me trompes pas, tu as toujours Babylon Toolbar sur Chrome ?
Messages postés
35446
Date d'inscription
jeudi 18 décembre 2008
Statut
Contributeur sécurité
Dernière intervention
5 mai 2017
4 728
Parce que nous n'avons pas fini et qu'un enregistreur de frappes est enregistré sur ton PC :)
Et que quand je demande un rapport c'est que j'ai mes raisons :)
Messages postés
26
Date d'inscription
dimanche 13 janvier 2013
Statut
Membre
Dernière intervention
3 février 2013

D'accord. (;
Messages postés
26
Date d'inscription
dimanche 13 janvier 2013
Statut
Membre
Dernière intervention
3 février 2013

Je t'enverrai le rapport MAB demain, pour le rkfree, j'ai toujours un dossier nommé rkfree dans le dossier caché Appdata sur C. Et enfin, j'ai toujours un dossier BIEN caché babylon toolbar, mais il est vide.
Messages postés
35446
Date d'inscription
jeudi 18 décembre 2008
Statut
Contributeur sécurité
Dernière intervention
5 mai 2017
4 728
En attente pour continuer les opérations demain donc.

@+
Messages postés
26
Date d'inscription
dimanche 13 janvier 2013
Statut
Membre
Dernière intervention
3 février 2013

Messages postés
35446
Date d'inscription
jeudi 18 décembre 2008
Statut
Contributeur sécurité
Dernière intervention
5 mai 2017
4 728
Dis adieu à ton pc, t'es infecté par ramnit ...


Très grave

sauvegarde tes données (uniquement vidéos, photos et musique ,de préférence gravées car ramnit se propage aussi par les ports usb, tout le reste est infecté par ramnit , donc pas de cracks , exécutables , html , dll , etc.....), je pense que ça va se finir par une réinstallation de windows....

ne te sers du pc uniquement pour la désinfection , ne le redémarre pas sous Windows , le temps jour contre ton système , il est en train de mourir .
chaque redémarrage , chaque exécution d'un programme quel qu'il soit empire le problème et accélérera la mort du système.

Ne tente pas une restauration d'usine , il faut tout désinfecter d'abord , ramnit a infecté aussi toutes tes partitions clés usb , mp3 , dd externe , que tu aurais pu connecter dernièrement

si quelqu'un est venu chez toi et s'est connecté sur tes ports usb il a certainement infecté son ordi aussi

on va essayer quand même

================


fais ce live cd à partir d un autre pc sain ( "graver une image ISO" )

explications détaillées ici :

http://www.chantal11.com/2011/09/dr-web-livecd/
Messages postés
26
Date d'inscription
dimanche 13 janvier 2013
Statut
Membre
Dernière intervention
3 février 2013

Est-ce que Ramnit en est presque à bout de mon PC ? :o
Bref, est-ce que la manip' Kaspersky Removal Tools peut en venir à bout ?
Messages postés
26
Date d'inscription
dimanche 13 janvier 2013
Statut
Membre
Dernière intervention
3 février 2013

Et pour mes jeux ? Ils sont pas originales si tu vois ce que je veux dire... Et j'ai galéré pour les installer !
Messages postés
35446
Date d'inscription
jeudi 18 décembre 2008
Statut
Contributeur sécurité
Dernière intervention
5 mai 2017
4 728
et c'est ainsi que tu t'es infecté .....
nan tu fais dr web c'est le seul moyen et plus tu attends, plus ramnit s'installe sur ta machine et moins de chance tu as de l'avoir.
Messages postés
35446
Date d'inscription
jeudi 18 décembre 2008
Statut
Contributeur sécurité
Dernière intervention
5 mai 2017
4 728
Parfait !

La suite des opérations, à effectuer dans l'ordre indiqué impérativement.

● 1. AdwCleaner :

Télécharge sur cette page: AdwCleaner (de Xplode)

▶ Lance-le

clique sur Suppression et patiente le temps du nettoyage.

▶ Poste le contenu du rapport que tu trouveras dans ton disque dur c:\ADwcleaner[Sx].txt ou son contenu s'il s'ouvre.

● 2. USBFix :

▶ Téléchargez UsbFix (créé par El Desaparecido) sur votre Bureau.

▶ Si votre antivirus affiche une alerte, ignorez-la et désactivez l'antivirus temporairement.
Branchez toutes vos sources de données externes à votre PC (clé USB, disque dur externe, etc...) sans les ouvrir.
▶ Double cliquez sur UsbFix.exe.

▶ Cliquez sur suppression
▶ Laissez travailler l'outil.

▶ À la fin du scan, un rapport va s'afficher, postez-le dans votre prochaine réponse sur le forum.

▶ Le rapport est aussi sauvegardé à la racine du disque système ( C:\UsbFix.txt ).
Tutoriel vidéo

● 3. MBAM :

▶ Télécharge et installe Malwarebytes' Anti-Malware (MBAM).

▶ Exécute-le. Accepte la mise à jour.



Uniquement en cas de problème de mise à jour:

Télécharger mises à jour manuelles MBAM

● Exécute le fichier après l'installation de MBAM



▶ Sélectionne "Exécuter un examen complet"
▶ Clique sur "Rechercher"
▶ L'analyse démarre, le scan est relativement long, c'est normal.

A la fin de l'analyse, un message s'affiche :

Citation :

L'examen s'est terminé normalement. Clique sur 'Afficher les résultats' pour afficher tous les objets trouvés.

▶ Clique sur "Ok" pour poursuivre. Si MBAM n'a rien trouvé, il te le dira aussi.
▶ Ferme tes navigateurs.
▶ Si des malwares ont été détectés, clique sur Afficher les résultats.
▶ Sélectionne tout (ou laisse coché) et clique sur Supprimer la sélection, MBAM va détruire les fichiers et clés de registre et en mettre une copie dans la quarantaine.
MBAM va ouvrir le Bloc-notes et y copier le rapport d'analyse : ferme le.

Si MBAM demande à redémarrer le pc : ▶ fais-le.

Au redémarrage, relance MBAM, onglet "Rapport/Logs", copie/colle celui qui correspond à l'analyse effectuée.

● 4. OTL en analyse rapide :

▶ Relance OTL, n'appuie que sur Analyse rapide
▶ OTL.txt s'ouvrira après avoir balayé ton PC, envoie moi ce rapport via https://www.cjoint.com/

=============================

Sont attendus dans ton prochain message 4 rapports:

▶ AdwCleaner[S1].txt
▶ USBFix.txt
▶ MBAM-log_date_heure.log
▶ OTL.txt

Bon courage :o)
Messages postés
26
Date d'inscription
dimanche 13 janvier 2013
Statut
Membre
Dernière intervention
3 février 2013

Ah, l'USBfix:
############################## | UsbFix V 7.102 | [Suppression]

Utilisateur: Administrateur (Administrateur) # XXPC
Mis à jour le 20/12/2012 par El Desaparecido
Lancé à 15:22:07 | 13/01/2013

Site Web: https://www.sosvirus.net/
Contact: contact@eldesaparecido.com

PC: Dell Inc. (Latitude E4310) (X86-based PC
CPU: Intel(R) Core(TM) i5 CPU M 520 @ 2.40GHz (2393)
RAM -> [Total : 3510 | Free : 2771]
BIOS: Default System BIOS
BOOT: Fail-safe with network boot

OS: Microsoft Windows 7 Professionnel (6.1.7601 32-Bit) # Service Pack 1
WB: Windows Internet Explorer 9.0.8112.16421

SC: Security Center Service [Enabled]
WU: Windows Update Service [Enabled]
AS: Windows Defender [Enabled | (!) Outdated]
FW: Windows FireWall Service [Enabled]

C:\ -> Disque fixe # 98 Go (3 Go libre(s) - 3%) [] # NTFS
D:\ -> Disque fixe # 135 Go (20 Go libre(s) - 15%) [] # NTFS
E:\ -> CD-ROM
H:\ -> CD-ROM
I:\ -> CD-ROM

################## | Processus Actif |

C:\Windows\system32\csrss.exe (348)
C:\Windows\system32\csrss.exe (384)
C:\Windows\system32\wininit.exe (392)
C:\Windows\system32\winlogon.exe (432)
C:\Windows\system32\services.exe (480)
C:\Windows\system32\lsass.exe (488)
C:\Windows\system32\lsm.exe (500)
C:\Windows\system32\svchost.exe (608)
C:\Windows\system32\svchost.exe (680)
C:\Windows\System32\svchost.exe (780)
C:\Windows\system32\svchost.exe (820)
C:\Windows\system32\svchost.exe (880)
C:\Windows\system32\svchost.exe (908)
C:\Windows\system32\svchost.exe (952)
C:\Windows\system32\svchost.exe (1052)
C:\Windows\system32\svchost.exe (1112)
C:\Windows\System32\WUDFHost.exe (1328)
C:\Windows\Explorer.EXE (1476)
C:\Windows\system32\ctfmon.exe (1532)
C:\Windows\system32\svchost.exe (1920)
C:\Program Files\Google\Chrome\Application\chrome.exe (1980)
C:\Program Files\Google\Chrome\Application\chrome.exe (1216)
C:\Program Files\Google\Chrome\Application\chrome.exe (1308)
C:\Program Files\Google\Chrome\Application\chrome.exe (1424)
C:\Program Files\Google\Chrome\Application\chrome.exe (1860)
C:\Program Files\Google\Chrome\Application\chrome.exe (1876)
C:\Program Files\Google\Chrome\Application\chrome.exe (1696)
C:\Program Files\Google\Chrome\Application\chrome.exe (1560)
C:\Windows\system32\prevhost.exe (604)
C:\Windows\system32\NOTEPAD.EXE (1320)
C:\Windows\System32\svchost.exe (932)
C:\Program Files\Google\Chrome\Application\chrome.exe (1252)
C:\UsbFix\Go.exe (2272)
C:\Windows\system32\wbem\wmiprvse.exe (2460)

################## | Processus Stoppés |

Stoppé! C:\Windows\System32\WUDFHost.exe (1328)
Stoppé! C:\Windows\Explorer.EXE (1476)
Stoppé! C:\Windows\system32\ctfmon.exe (1532)
Stoppé! C:\Program Files\Google\Chrome\Application\chrome.exe (1980)
Stoppé! C:\Program Files\Google\Chrome\Application\chrome.exe (1216)
Stoppé! C:\Program Files\Google\Chrome\Application\chrome.exe (1308)
Stoppé! C:\Program Files\Google\Chrome\Application\chrome.exe (1424)
Stoppé! C:\Program Files\Google\Chrome\Application\chrome.exe (1860)
Stoppé! C:\Program Files\Google\Chrome\Application\chrome.exe (1876)
Stoppé! C:\Windows\system32\prevhost.exe (604)
Stoppé! C:\Windows\system32\NOTEPAD.EXE (1320)

################## | Éléments infectieux |

Supprimé! C:\Users\Administrateur\AppData\Roaming\bsop.exe
Supprimé! C:\NosTale.lnk
Non supprimé ! C:\$RECYCLE.BIN\S-1-5-18
Supprimé! C:\$RECYCLE.BIN\S-1-5-20
Supprimé! C:\$RECYCLE.BIN\S-1-5-21-2170562045-1414757869-1238418950-1000
Supprimé! C:\$RECYCLE.BIN\S-1-5-21-2170562045-1414757869-1238418950-1001
Supprimé! C:\$RECYCLE.BIN\S-1-5-21-2170562045-1414757869-1238418950-1003
Non supprimé ! C:\$RECYCLE.BIN\S-1-5-21-2170562045-1414757869-1238418950-500
Supprimé! C:\$RECYCLE.BIN\S-1-5-21-3316471367-3341167197-1010723499-1000
Supprimé! D:\$RECYCLE.BIN\S-1-5-21-2170562045-1414757869-1238418950-1000
Supprimé! D:\$RECYCLE.BIN\S-1-5-21-2170562045-1414757869-1238418950-1001
Supprimé! D:\$RECYCLE.BIN\S-1-5-21-2170562045-1414757869-1238418950-1003
Supprimé! D:\$RECYCLE.BIN\S-1-5-21-2170562045-1414757869-1238418950-500
Supprimé! D:\$RECYCLE.BIN\S-1-5-21-3316471367-3341167197-1010723499-1000
Supprimé! D:\Autorun.inf

(!) Fichiers temporaires supprimés.

################## | Registre |

Supprimé! HKLM\Software\Bifrost
Supprimé! HKCU\Software\Bifrost
Supprimé! HKU\.DEFAULT\Software\Bifrost
Supprimé! HKCU\Software\VB and VBA Program Settings\INSTALL
Supprimé! HKCU\Software\VB and VBA Program Settings\SrvID
Supprimé! HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System|DisableTaskMgr
Supprimé! HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\explorer|NoFolderOptions

################## | Mountpoints2 |

Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\F
Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{0004dec0-0bb9-11e1-8201-806e6f6e6963}
Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{0a857e8b-1172-11e2-a124-70f1a19b5127}
Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{0e4f1490-8ae6-11e1-aec1-70f1a19b5127}
Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{19a82615-054e-11e0-a3c1-70f1a19b5127}
Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{3e035866-2889-11e0-bf25-002314d2d530}
Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{3f4d1dcc-89f0-11e1-bed1-70f1a19b5127}
Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{48fa52d2-f5a1-11df-a659-70f1a19b5127}
Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{4dfbc15d-dbea-11e1-85fd-70f1a19b5127}
Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{65ff234b-01fb-11e1-ba29-0026b9e89859}
Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{6a2cc526-ebac-11e0-97c7-002314d2d530}
Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{837f2a56-29e3-11e2-b782-70f1a19b5127}
Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{a4d02b87-ef21-11e0-a311-002314d2d530}
Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{b66e6d73-0b79-11e1-bc91-0026b9e89859}
Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{b89a828f-0af3-11e2-a424-0026b9e89859}
Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{cad6aa5c-279f-11e0-894f-002314d2d530}
Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{fe35d958-d874-11df-a658-70f1a19b5127}

################## | Listing |

[13/01/2013 - 15:25:35 | SHD ] C:\$Recycle.Bin
[23/09/2005 - 21:01:45 | N | 15] C:\Administrateurlog.dat
[13/01/2013 - 15:16:36 | N | 63400] C:\AdwCleaner[S1].txt
[15/02/2012 - 16:38:33 | A | 0] C:\asoutput.log
[10/06/2009 - 21:42:20 | A | 24] C:\autoexec.bat
[03/01/2013 - 17:18:30 | N | 10480] C:\bootsqm.dat
[12/01/2013 - 13:10:54 | D ] C:\Config.Msi
[10/06/2009 - 21:42:20 | A | 10] C:\config.sys
[25/11/2012 - 08:08:50 | N | 216] C:\DebugTrace-RockallDLL.log
[28/10/2012 - 23:22:11 | D ] C:\dell
[14/07/2009 - 04:53:55 | SHD ] C:\Documents and Settings
[12/01/2013 - 20:29:02 | D ] C:\drvrtmp
[13/01/2013 - 15:18:17 | ASH | 2760261632] C:\hiberfil.sys
[19/04/2012 - 07:31:48 | A | 659] C:\INSTALL.LOG
[12/10/2010 - 09:24:06 | D ] C:\Intel
[14/10/2010 - 05:27:00 | N | 0] C:\IO.SYS
[08/04/2005 - 02:16:43 | AH | 15] C:\logs.dat
[14/10/2010 - 05:27:00 | N | 0] C:\MSDOS.SYS
[24/08/2012 - 21:53:32 | AH | 745] C:\os024889.bin
[13/01/2013 - 15:16:21 | D ] C:\Program Files
[13/01/2013 - 15:16:20 | HD ] C:\ProgramData
[30/08/2012 - 21:19:11 | D ] C:\Projets
[08/01/2013 - 19:36:10 | SHD ] C:\Recovery
[15/03/2012 - 15:12:44 | N | 510] C:\settings.ini
[19/02/2012 - 12:05:45 | A | 20272] C:\shared.log
[12/01/2013 - 14:20:03 | SHD ] C:\System Volume Information
[02/11/2012 - 14:22:45 | D ] C:\Temp
[28/07/2011 - 21:33:24 | A | 379] C:\TennisPC_log.rtf
[13/01/2013 - 15:25:36 | D ] C:\UsbFix
[13/01/2013 - 15:22:21 | A | 3240] C:\UsbFix.txt
[11/01/2013 - 15:17:42 | D ] C:\Users
[13/01/2013 - 15:18:17 | D ] C:\Windows
[13/01/2013 - 15:02:44 | D ] C:\_OTL
[13/01/2013 - 15:25:36 | SHD ] D:\$RECYCLE.BIN
[27/01/2012 - 18:21:32 | D ] D:\83cc5ba00f7104f399899edc
[17/05/2012 - 16:48:42 | D ] D:\ActiveSync
[16/04/2012 - 13:08:16 | D ] D:\apple
[24/11/2012 - 09:19:22 | D ] D:\Archimède
[16/04/2012 - 13:08:16 | D ] D:\BlackBerry
[11/01/2012 - 17:55:23 | D ] D:\Cheat Engine 6.1
[15/08/2012 - 00:59:04 | D ] D:\CodeBlocks
[08/03/2012 - 17:01:23 | D ] D:\DAEMON Tools Lite
[28/01/2012 - 10:47:09 | D ] D:\docs
[16/04/2012 - 13:08:05 | D ] D:\Dossier MAMA
[12/01/2013 - 14:06:34 | C | 4478166244] D:\Drivers+Office.mdx
[29/01/2012 - 12:15:44 | D ] D:\dt09.img
[27/01/2012 - 14:40:44 | D ] D:\dt0f.img
[08/03/2012 - 16:55:43 | D ] D:\EmpireEarth
[24/02/2012 - 07:22:51 | D ] D:\Eula
[07/11/2007 - 08:00:40 | C | 17734] D:\eula.1028.txt
[07/11/2007 - 08:00:40 | C | 17734] D:\eula.1031.txt
[07/11/2007 - 08:00:40 | C | 10134] D:\eula.1033.txt
[07/11/2007 - 08:00:40 | C | 17734] D:\eula.1036.txt
[07/11/2007 - 08:00:40 | C | 17734] D:\eula.1040.txt
[07/11/2007 - 08:00:40 | C | 118] D:\eula.1041.txt
[07/11/2007 - 08:00:40 | C | 17734] D:\eula.1042.txt
[07/11/2007 - 08:00:40 | C | 17734] D:\eula.2052.txt
[07/11/2007 - 08:00:40 | C | 17734] D:\eula.3082.txt
[15/08/2012 - 17:14:45 | D ] D:\Fake Webcam 7.1
[07/05/2012 - 21:38:53 | D ] D:\Feneris
[09/02/2012 - 13:17:26 | D ] D:\filelistvv
[08/03/2012 - 18:06:45 | D ] D:\final_Fatal.FRENCH.DVDRip.XviD-AYMO
[07/10/2012 - 15:48:35 | D ] D:\FL 8
[11/01/2013 - 19:14:06 | D ] D:\gag4.10
[01/11/2012 - 15:38:58 | D ] D:\Game
[31/03/2012 - 11:48:51 | D ] D:\GameSpy Arcade
[24/02/2012 - 07:22:51 | D ] D:\Gfwlive
[07/11/2007 - 08:00:40 | C | 1110] D:\globdata.ini
[16/04/2012 - 13:08:05 | D ] D:\hsjavastore
[21/12/2011 - 08:00:06 | D ] D:\Images
[07/11/2007 - 08:03:18 | C | 562688] D:\install.exe
[07/11/2007 - 08:00:40 | C | 843] D:\install.ini
[07/11/2007 - 08:03:18 | C | 76304] D:\install.res.1028.dll
[07/11/2007 - 08:03:18 | C | 96272] D:\install.res.1031.dll
[07/11/2007 - 08:03:18 | C | 91152] D:\install.res.1033.dll
[07/11/2007 - 08:03:18 | C | 97296] D:\install.res.1036.dll
[07/11/2007 - 08:03:18 | C | 95248] D:\install.res.1040.dll
[07/11/2007 - 08:03:18 | C | 81424] D:\install.res.1041.dll
[07/11/2007 - 08:03:18 | C | 79888] D:\install.res.1042.dll
[07/11/2007 - 08:03:18 | C | 75792] D:\install.res.2052.dll
[07/11/2007 - 08:03:18 | C | 96272] D:\install.res.3082.dll
[19/04/2012 - 22:10:53 | D ] D:\Internet Mobile
[16/04/2012 - 13:08:05 | D ] D:\javastore
[16/05/2012 - 17:36:35 | D ] D:\LOL
[24/11/2012 - 09:04:03 | D ] D:\MATHEMAT
[02/01/2013 - 15:43:53 | D ] D:\Metro 2033
[04/11/2012 - 15:40:43 | D ] D:\MFF
[30/01/2011 - 13:38:39 | D ] D:\MP4
[25/04/2012 - 21:06:05 | D ] D:\MPK
[05/10/2012 - 19:25:21 | D ] D:\msdownld.tmp
[27/01/2012 - 18:32:53 | RHD ] D:\MSOCache
[16/04/2012 - 13:08:14 | D ] D:\musik
[09/02/2012 - 13:22:06 | D ] D:\My Music
[09/04/2012 - 10:29:31 | C | 1926234112] D:\Naruto Shippuden Ultimate Ninja 5.ISO
[01/09/2012 - 21:03:18 | D ] D:\NFS
[07/10/2012 - 14:39:21 | D ] D:\NosTale(FR)
[30/01/2012 - 20:28:14 | D ] D:\Nouveau dossier
[30/01/2012 - 22:13:20 | D ] D:\Nouveau dossier (2)
[01/11/2012 - 18:21:46 | D ] D:\Nouveau dossier (3)
[05/11/2012 - 20:45:48 | D ] D:\Nouveau dossier (4)
[27/01/2012 - 18:30:15 | D ] D:\ORANT
[27/01/2012 - 18:34:46 | D ] D:\ORANT2
[21/12/2011 - 08:00:06 | D ] D:\Other files
[13/01/2013 - 15:18:24 | ASH | 3680350208] D:\pagefile.sys
[07/04/2012 - 22:04:12 | D ] D:\PCSX
[16/04/2012 - 13:08:16 | D ] D:\Photos
[17/06/2012 - 20:37:13 | D ] D:\PS CS6
[01/09/2012 - 13:33:33 | D ] D:\QuickTime
[24/02/2012 - 07:23:19 | D ] D:\Redist
[17/08/2012 - 12:43:32 | D ] D:\Rockstar Games
[30/10/2012 - 07:53:32 | D ] D:\Safari
[17/05/2012 - 16:48:43 | D ] D:\Scribus 1.4.1
[24/02/2012 - 07:23:20 | D ] D:\SetupMedia
[15/07/2012 - 20:39:59 | D ] D:\Sierra
[16/04/2012 - 13:08:16 | D ] D:\soapp
[18/02/2011 - 20:45:38 | D ] D:\SONY
[17/02/2011 - 13:32:40 | D ] D:\sony HD
[16/04/2012 - 13:08:16 | D ] D:\Sounds
[01/11/2012 - 18:21:33 | D ] D:\STDM
[30/03/2012 - 18:23:28 | D ] D:\Steam
[04/10/2010 - 09:00:06 | SHD ] D:\System Volume Information
[07/11/2007 - 08:00:40 | N | 5686] D:\vcredist.bmp
[07/11/2007 - 08:09:22 | N | 1442522] D:\VC_RED.cab
[07/11/2007 - 08:12:28 | N | 232960] D:\VC_RED.MSI
[21/12/2011 - 08:00:06 | D ] D:\Videos
[15/08/2012 - 17:05:40 | D ] D:\Webcam Simulator 7.3
[07/11/2011 - 22:48:48 | D ] D:\Whiteberry
[07/01/2013 - 20:03:31 | D ] D:\World_of_Tanks
[07/10/2012 - 15:48:55 | D ] D:\WST
[25/05/2007 - 00:54:50 | D ] E:\01
[24/05/2007 - 23:19:17 | D ] E:\02
[24/05/2007 - 23:20:50 | D ] E:\03
[25/05/2007 - 00:55:58 | D ] E:\05
[25/05/2007 - 00:13:48 | D ] E:\06
[24/05/2007 - 23:22:30 | D ] E:\07
[25/05/2007 - 00:16:34 | D ] E:\08

################## | Vaccin |
Messages postés
35446
Date d'inscription
jeudi 18 décembre 2008
Statut
Contributeur sécurité
Dernière intervention
5 mai 2017
4 728
Ok je serais au RDV, oublie pas la bouteille de Champagne ;-)
Messages postés
26
Date d'inscription
dimanche 13 janvier 2013
Statut
Membre
Dernière intervention
3 février 2013

On verra ça. :'D
Messages postés
26
Date d'inscription
dimanche 13 janvier 2013
Statut
Membre
Dernière intervention
3 février 2013

Au fait, je ne retrouve pas le rapport dans l'onglet "Rapport/Logs".
Messages postés
26
Date d'inscription
dimanche 13 janvier 2013
Statut
Membre
Dernière intervention
3 février 2013

Voilà pour l'analyse rapide OTL:
OTL logfile created on: 13/01/2013 20:43:29 - Run 3
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\xx.XXPC\Downloads
Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 0000040C | Country: France | Language: FRA | Date Format: dd/MM/yyyy

3,43 Gb Total Physical Memory | 2,76 Gb Available Physical Memory | 80,46% Memory free
6,85 Gb Paging File | 6,17 Gb Available in Paging File | 90,08% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 97,56 Gb Total Space | 4,37 Gb Free Space | 4,48% Space Free | Partition Type: NTFS
Drive D: | 135,23 Gb Total Space | 19,91 Gb Free Space | 14,72% Space Free | Partition Type: NTFS
Drive E: | 520,92 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS

Computer Name: XXPC | User Name: Administrateur | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

[color=#E56717]========== Processes (SafeList) ==========[/color]

PRC - [2013/01/13 14:13:27 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\xx.XXPC\Downloads\OTL.exe
PRC - [2012/12/14 16:49:28 | 000,824,232 | ---- | M] (Malwarebytes Corporation) -- D:\Malwarebytes' Anti-Malware\mbam.exe
PRC - [2012/11/28 03:43:18 | 001,242,728 | ---- | M] (Google Inc.) -- C:\Program Files\Google\Chrome\Application\chrome.exe
PRC - [2011/02/25 05:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2010/11/20 12:29:22 | 000,101,760 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\consent.exe


[color=#E56717]========== Modules (No Company Name) ==========[/color]

MOD - [2012/11/28 03:43:17 | 000,460,904 | ---- | M] () -- C:\Program Files\Google\Chrome\Application\23.0.1271.95\ppgooglenaclpluginchrome.dll
MOD - [2012/11/28 03:43:16 | 012,456,040 | ---- | M] () -- C:\Program Files\Google\Chrome\Application\23.0.1271.95\PepperFlash\pepflashplayer.dll
MOD - [2012/11/28 03:43:15 | 004,008,040 | ---- | M] () -- C:\Program Files\Google\Chrome\Application\23.0.1271.95\pdf.dll
MOD - [2012/11/28 03:42:22 | 000,157,304 | ---- | M] () -- C:\Program Files\Google\Chrome\Application\23.0.1271.95\avutil-51.dll
MOD - [2012/11/28 03:42:21 | 002,168,952 | ---- | M] () -- C:\Program Files\Google\Chrome\Application\23.0.1271.95\avcodec-54.dll
MOD - [2012/11/28 03:42:21 | 000,275,576 | ---- | M] () -- C:\Program Files\Google\Chrome\Application\23.0.1271.95\avformat-54.dll


[color=#E56717]========== Services (SafeList) ==========[/color]

SRV - File not found [On_Demand | Stopped] -- C:\ORANT2\BIN\ONRSD.EXE -- (OracleORACLE_HOME2ClientCache)
SRV - [2013/01/11 15:49:23 | 000,251,400 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012/09/30 14:27:16 | 000,218,624 | ---- | M] () [Auto | Stopped] -- C:\Program Files\Internet Mobile+\UpdateDog\ouc.exe -- (Internet Mobile+. RunOuc)
SRV - [2012/07/27 20:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) [Auto | Stopped] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2012/07/16 14:31:32 | 002,673,064 | ---- | M] (TeamViewer GmbH) [Auto | Stopped] -- C:\Program Files\TeamViewer\Version7\TeamViewer_Service.exe -- (TeamViewer7)
SRV - [2012/07/13 13:28:36 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2012/04/19 22:09:18 | 000,655,712 | ---- | M] () [Auto | Stopped] -- D:\Internet Mobile\UpdateDog\ouc.exe -- (Internet Mobile. RunOuc)
SRV - [2010/10/12 10:49:32 | 001,343,400 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\Wat\WatAdminSvc.exe -- (WatAdminSvc)
SRV - [2010/08/24 16:51:50 | 000,388,464 | ---- | M] (Dell Inc.) [Auto | Stopped] -- C:\Program Files\Dell\Dell System Manager\DCPSysMgrSvc.exe -- (dcpsysmgrsvc)
SRV - [2010/07/22 02:19:24 | 000,245,842 | ---- | M] (IDT, Inc.) [Auto | Stopped] -- C:\Program Files\IDT\WDM\stacsv.exe -- (STacSV)
SRV - [2010/07/08 23:44:32 | 002,533,400 | ---- | M] (Intel Corporation) [Auto | Stopped] -- C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe -- (UNS)
SRV - [2010/07/08 23:44:16 | 000,325,656 | ---- | M] (Intel Corporation) [Auto | Stopped] -- C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS)
SRV - [2010/05/06 09:29:12 | 000,293,456 | ---- | M] (Logitech, Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\LogiShrd\Bluetooth\LBTServ.exe -- (LBTServ)
SRV - [2010/03/29 12:45:48 | 001,164,648 | ---- | M] (Wave Systems Corp.) [Auto | Stopped] -- C:\Program Files\Wave Systems Corp\Trusted Drive Manager\TdmService.exe -- (TdmService)
SRV - [2010/03/24 00:09:28 | 000,812,448 | ---- | M] (Broadcom Corporation) [Auto | Stopped] -- C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostControlService.exe -- (Credential Vault Host Control Service)
SRV - [2010/03/24 00:09:28 | 000,027,040 | ---- | M] (Broadcom Corporation) [Auto | Stopped] -- C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostStorageService.exe -- (Credential Vault Host Storage)
SRV - [2010/03/05 10:01:46 | 000,862,480 | ---- | M] (Intel(R) Corporation) [Auto | Stopped] -- C:\Program Files\Intel\WiFi\bin\EvtEng.exe -- (EvtEng)
SRV - [2010/03/05 09:45:22 | 000,227,600 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe -- (MyWiFiDHCPDNS)
SRV - [2010/03/05 09:43:50 | 000,473,360 | ---- | M] (Intel(R) Corporation) [Auto | Stopped] -- C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe -- (RegSrvc)
SRV - [2009/11/20 17:42:48 | 000,278,304 | ---- | M] (Dell Inc.) [Auto | Stopped] -- C:\Program Files\Dell\Dell ControlPoint\DCPButtonSvc.exe -- (buttonsvc32)
SRV - [2009/07/16 17:04:16 | 000,316,664 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2009/07/14 01:16:15 | 000,016,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\StorSvc.dll -- (StorSvc)
SRV - [2009/07/14 01:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009/07/14 01:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc)
SRV - [2009/07/14 01:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)


[color=#E56717]========== Driver Services (SafeList) ==========[/color]

DRV - File not found [Kernel | System | Stopped] -- C:\Windows\system32\drivers\wewnpmng.sys -- (wewnpmng)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\system32\Drivers\PROCEXP151.SYS -- (PROCEXP151)
DRV - File not found [Kernel | System | Stopped] -- C:\Windows\system32\drivers\lgemwwaa.sys -- (lgemwwaa)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ewusbdev.sys -- (hwusbdev)
DRV - [2012/09/30 14:27:16 | 000,353,280 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ewusbwwan.sys -- (ewusbmbb)
DRV - [2012/09/30 14:27:16 | 000,193,792 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ewusbmdm.sys -- (hwdatacard)
DRV - [2012/09/30 14:27:16 | 000,102,784 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ew_hwusbdev.sys -- (ew_hwusbdev)
DRV - [2012/09/30 14:27:16 | 000,090,112 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ew_jucdcacm.sys -- (huawei_cdcacm)
DRV - [2012/09/30 14:27:16 | 000,073,216 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ew_jubusenum.sys -- (huawei_enumerator)
DRV - [2012/09/27 18:07:26 | 000,099,192 | ---- | M] (Tonec Inc.) [Kernel | Auto | Stopped] -- C:\Windows\System32\drivers\idmwfp.sys -- (IDMWFP)
DRV - [2012/02/22 10:34:36 | 000,022,400 | ---- | M] (ManyCam LLC) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\mcaudrv.sys -- (mcaudrv_simple)
DRV - [2012/01/11 06:11:20 | 000,032,000 | ---- | M] (ManyCam LLC) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\mcvidrv.sys -- (ManyCam)
DRV - [2011/11/11 13:08:19 | 000,027,248 | ---- | M] (Connectify) [Kernel | System | Running] -- C:\Windows\System32\drivers\cnnctfy2.sys -- (cnnctfy2)
DRV - [2011/11/10 14:23:41 | 000,443,448 | ---- | M] (Duplex Secure Ltd.) [Kernel | Boot | Stopped] -- C:\Windows\System32\drivers\sptd.sys -- (sptd)
DRV - [2011/10/29 11:57:58 | 000,232,512 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\Windows\System32\drivers\dtsoftbus01.sys -- (dtsoftbus01)
DRV - [2011/08/23 06:11:48 | 000,270,336 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\IntcDAud.sys -- (IntcDAud)
DRV - [2011/06/02 11:08:34 | 000,011,336 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Program Files\SystemRequirementsLab\cpudrv.sys -- (cpudrv)
DRV - [2011/05/26 10:50:30 | 000,305,488 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Apfiltr.sys -- (ApfiltrService)
DRV - [2010/11/20 12:30:15 | 000,175,360 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmbus.sys -- (vmbus)
DRV - [2010/11/20 12:30:15 | 000,040,704 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmstorfl.sys -- (storflt)
DRV - [2010/11/20 12:30:15 | 000,028,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\storvsc.sys -- (storvsc)
DRV - [2010/11/20 10:24:41 | 000,052,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV - [2010/11/20 09:59:44 | 000,035,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\winusb.sys -- (WinUsb)
DRV - [2010/11/20 09:14:45 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\VMBusHID.sys -- (VMBusHID)
DRV - [2010/11/20 09:14:41 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vms3cap.sys -- (s3cap)
DRV - [2010/07/22 02:19:24 | 000,431,616 | ---- | M] (IDT, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\stwrt.sys -- (STHDA)
DRV - [2010/07/08 23:43:52 | 000,041,088 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\HECI.sys -- (HECI)
DRV - [2010/05/31 12:04:30 | 006,766,080 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\NETw5s32.sys -- (NETw5s32)
DRV - [2010/04/06 00:36:20 | 000,224,424 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\e1k6232.sys -- (e1kexpress)
DRV - [2010/02/26 23:31:24 | 000,132,480 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\Impcd.sys -- (Impcd)
DRV - [2010/01/19 12:46:44 | 000,229,888 | ---- | M] (Wave Systems Corp.) [File_System | Auto | Stopped] -- C:\Windows\System32\drivers\WavxDMgr.sys -- (WavxDMgr)
DRV - [2009/11/03 17:40:42 | 000,033,832 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\cvusbdrv.sys -- (cvusbdrv)
DRV - [2009/08/27 13:18:30 | 000,103,552 | ---- | M] (TCT International Mobile Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\qcusbser.sys -- (qcusbser)
DRV - [2009/07/13 23:52:10 | 000,014,336 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vwifimp.sys -- (vwifimp)
DRV - [2009/06/15 13:05:16 | 000,143,968 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\CtClsFlt.sys -- (CtClsFlt)
DRV - [2009/05/28 10:48:20 | 000,134,144 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\CtAudDrv.sys -- (CtAudDrv)
DRV - [2009/03/18 16:35:40 | 000,026,176 | -H-- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\hamachi.sys -- (hamachi)
DRV - [2008/12/26 12:56:04 | 000,017,792 | ---- | M] (Avnex) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vcsvad.sys -- (VCSVADHWSer)
DRV - [2008/08/26 16:39:28 | 000,021,632 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\lgevdommodem.sys -- (USBEVDOmModem)
DRV - [2008/08/26 16:39:26 | 000,019,840 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\lgevdomdiag.sys -- (UsbEvdomDiag)
DRV - [2008/08/26 16:39:24 | 000,013,696 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\lgevdombus.sys -- (usbevdombus)
DRV - [2008/08/26 16:39:22 | 000,019,840 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\lgevdomatc.sys -- (UsbEvdomAtc)
DRV - [2008/06/04 14:14:00 | 000,026,608 | ---- | M] (Dell Inc) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\PBADRV.sys -- (PBADRV)
DRV - [2000/07/24 01:01:00 | 000,019,537 | ---- | M] (Brother Industries Ltd.) [Kernel | Auto | Stopped] -- C:\Windows\System32\drivers\BRPAR.SYS -- (BrPar)


[color=#E56717]========== Standard Registry (SafeList) ==========[/color]


[color=#E56717]========== Internet Explorer ==========[/color]

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search bar = http://www.bing.com/spresults.aspx
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = Reg Error: Value error.
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = https://www.bing.com/?scope=web&mkt=fr-FR{searchTerms}&FORM=IE8SRC


IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =

IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =

IE - HKU\S-1-5-21-2170562045-1414757869-1238418950-1001\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-2170562045-1414757869-1238418950-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-21-2170562045-1414757869-1238418950-500\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
IE - HKU\S-1-5-21-2170562045-1414757869-1238418950-500\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-2170562045-1414757869-1238418950-500\..\SearchScopes\${searchCLSID}: "URL" = https://www.bing.com/?scope=web&mkt=fr-FR{searchTerms}&src={referrer:source?}
IE - HKU\S-1-5-21-2170562045-1414757869-1238418950-500\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = https://www.bing.com/?scope=web&mkt=fr-FR{searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKU\S-1-5-21-2170562045-1414757869-1238418950-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-2170562045-1414757869-1238418950-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>

[color=#E56717]========== FireFox ==========[/color]

FF - prefs.js..extensions.enabledItems: {1FD91A9C-410C-4090-BBCC-55D3450EF433}:1.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: {F0E1168A-B4B5-484C-B77E-0D28E6B64096}:1.0
FF - prefs.js..extensions.enabledItems:
FF - prefs.js..extensions.enabledItems: fbsidebardisabler@vittgam.net:1.8-ffbuild1
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_5_502_146.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.9.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.9.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=15.0.6.14: c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=15.0.6.14: c:\program files\real\realplayer\Netscape6\nprjplug.dll File not found
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.4.53: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll File not found
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.6.14: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll File not found
FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=15.0.6.14: c:\program files\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\Administrateur\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\Administrateur\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKCU\Software\MozillaPlugins\electronicarts.com/GameFacePlugin: C:\Users\Administrateur\AppData\Roaming\Electronic Arts\Game Face\npGameFacePlugin.dll (Electronic Arts)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{0153E448-190B-4987-BDE1-F256CADA672F}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2013/01/11 12:05:18 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\K-Meleon\Extensions\\Plugins: D:\Euh\Plugins
FF - HKEY_LOCAL_MACHINE\software\mozilla\K-Meleon\Extensions\\Components: D:\Euh\Components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0.1\extensions\\Components: D:\Nouveau dossier (4)\components [2012/11/04 15:41:00 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0.1\extensions\\Plugins: D:\Nouveau dossier (4)\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\mozilla_cc@internetdownloadmanager.com: C:\Users\Administrateur\AppData\Roaming\IDM\idmmzcc5 [2012/11/01 21:08:40 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\SeaMonkey\Extensions\\mozilla_cc@internetdownloadmanager.com: C:\Users\Administrateur\AppData\Roaming\IDM\idmmzcc5 [2012/11/01 21:08:40 | 000,000,000 | ---D | M]

[2013/01/13 15:02:47 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
File not found (No name found) -- C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
File not found (No name found) -- C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{F0E1168A-B4B5-484C-B77E-0D28E6B64096}
File not found (No name found) -- C:\PROGRAM FILES\SHOPPERREPORTS3\BIN\3.0.517.0\FIREFOX\FIREFOXTOOLBAR\EXTENSIONS
File not found (No name found) -- C:\PROGRAM FILES\WINDOWS SEARCHQU TOOLBAR\DATAMNGR\FIREFOXEXTENSION
[2011/08/06 10:40:35 | 000,000,000 | ---D | M] (FB Chat Sidebar Disabler) -- C:\WINDOWS\SYSTEM32\CONFIG\SYSTEMPROFILE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZWVQELZZ.DEFAULT\EXTENSIONS\FBSIDEBARDISABLER@VITTGAM.NET

[color=#E56717]========== Chrome ==========[/color]

CHR - default_search_provider: ()
CHR - default_search_provider: search_url =
CHR - default_search_provider: suggest_url =
CHR - homepage: https://www.google.com/?gws_rd=ssl
CHR - Extension: No name found = C:\Windows\System32\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhkplhfnhceodhffomolpfigojocbpcb\1.0_0\

O1 HOSTS File: ([2009/06/10 21:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (IDM integration (IDMIEHlprObj Class)) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll File not found
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Free Download Manager) - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll File not found
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [GhostNav4] C:\Program Files\NetScop\Ghost Navigator 3\Ghostz.exe (NetScop)
O4 - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
O4 - HKLM..\Run: [TkBellExe] c:\program files\real\realplayer\update\realsched.exe (RealNetworks, Inc.)
O4 - HKU\S-1-5-21-2170562045-1414757869-1238418950-1001..\Run: [E09FXLRD_3952316] C:\Program Files\Microsoft Encarta\Microsoft Encarta 2009 - Collection DVD\EDICT.EXE (Microsoft Corporation)
O4 - HKU\S-1-5-21-2170562045-1414757869-1238418950-500..\Run: [Akamai NetSession Interface] C:\Users\Administrateur\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc.)
O4 - HKU\S-1-5-21-2170562045-1414757869-1238418950-500..\Run: [DAEMON Tools Lite] D:\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKU\S-1-5-21-2170562045-1414757869-1238418950-500..\Run: [E09FXLRD_44115366] C:\Program Files\Microsoft Encarta\Microsoft Encarta 2009 - Collection DVD\EDICT.EXE (Microsoft Corporation)
O4 - HKU\S-1-5-21-2170562045-1414757869-1238418950-500..\Run: [Facebook Update] C:\Users\Administrateur\AppData\Local\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
O4 - HKU\S-1-5-21-2170562045-1414757869-1238418950-500..\Run: [fTalk] C:\Users\Administrateur\AppData\Local\fTalk\ftalk.exe (Bandoo Media Inc.)
O4 - HKU\S-1-5-21-2170562045-1414757869-1238418950-500..\Run: [uTorrent] C:\Program Files\uTorrent\uTorrent.exe (BitTorrent, Inc.)
O4 - HKLM..\RunOnce: [] File not found
O4 - HKLM..\RunOnce: [Del1466502] C:\Windows\System32\cmd.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [Malwarebytes Anti-Malware] D:\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-2170562045-1414757869-1238418950-1001..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-2170562045-1414757869-1238418950-500..\RunOnce: [Application Restart #0] C:\Windows\System32\ctfmon.exe ctfmon.exe File not found
O4 - HKU\S-1-5-21-2170562045-1414757869-1238418950-500..\RunOnce: [Del1466502] C:\Windows\System32\cmd.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-2170562045-1414757869-1238418950-500..\RunOnce: [Report] \AdwCleaner[S1].txt ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O7 - HKU\S-1-5-21-2170562045-1414757869-1238418950-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-2170562045-1414757869-1238418950-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKU\S-1-5-21-2170562045-1414757869-1238418950-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O7 - HKU\S-1-5-21-2170562045-1414757869-1238418950-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 0
O7 - HKU\S-1-5-21-2170562045-1414757869-1238418950-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 3
O7 - HKU\S-1-5-21-2170562045-1414757869-1238418950-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKU\S-1-5-21-2170562045-1414757869-1238418950-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O8 - Extra context menu item: Télécharger avec Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm File not found
O8 - Extra context menu item: Télécharger la sélection avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm File not found
O8 - Extra context menu item: Télécharger la vidéo avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlfvideo.htm File not found
O8 - Extra context menu item: Tout télécharger avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm File not found
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O15 - HKU\S-1-5-21-2170562045-1414757869-1238418950-500\..Trusted Domains: dell.com ([]* in Trusted sites)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{02503AEC-664E-408B-B420-CD28F70BA1DB}: NameServer = 192.168.113.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{64478003-94A6-42DD-9690-D241772D5DF0}: DhcpNameServer = 192.168.1.1 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{FF0AF69A-8F10-4FE5-8985-A8B3F9DECD06}: Domain = ONCF.NET
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{FF0AF69A-8F10-4FE5-8985-A8B3F9DECD06}: NameServer = 172.16.26.6,172.16.126.201
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\Userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - Winlogon\Notify\LBTWlgn: DllName - (c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll) - c:\Program Files\Common Files\LogiShrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O30 - LSA: Authentication Packages - (wvauth) - C:\Windows\System32\wvauth.dll (Wave Systems Corp.)
O32 - HKLM CDRom: AutoRun - 1
O32 - Unable to obtain root file information for disk C:\
O33 - MountPoints2\{1ce165b3-8f04-11e1-ba66-70f1a19b5127}\Shell - "" = AutoRun
O33 - MountPoints2\{1ce165b3-8f04-11e1-ba66-70f1a19b5127}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{3f4d1dec-89f0-11e1-bed1-70f1a19b5127}\Shell - "" = AutoRun
O33 - MountPoints2\{3f4d1dec-89f0-11e1-bed1-70f1a19b5127}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{6a2cc511-ebac-11e0-97c7-002314d2d530}\Shell - "" = AutoRun
O33 - MountPoints2\{6a2cc511-ebac-11e0-97c7-002314d2d530}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{b89a8284-0af3-11e2-a424-0026b9e89859}\Shell - "" = AutoRun
O33 - MountPoints2\{b89a8284-0af3-11e2-a424-0026b9e89859}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{b89a82a3-0af3-11e2-a424-0026b9e89859}\Shell - "" = AutoRun
O33 - MountPoints2\{b89a82a3-0af3-11e2-a424-0026b9e89859}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\G\Shell - "" = AutoRun
O33 - MountPoints2\G\Shell\AutoRun\command - "" = G:\AutoRun.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]

[2013/01/13 15:30:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013/01/13 15:30:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2013/01/13 15:30:37 | 000,021,104 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2013/01/13 15:21:13 | 000,000,000 | ---D | C] -- C:\UsbFix
[2013/01/13 15:04:19 | 000,000,000 | ---D | C] -- C:\Program Files\uckehjxn
[2013/01/13 15:02:44 | 000,000,000 | ---D | C] -- C:\_OTL
[2013/01/12 20:44:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Windows Genuine Advantage
[2013/01/12 20:13:30 | 000,000,000 | ---D | C] -- C:\Program Files\C-Media
[2013/01/12 13:53:58 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\DAEMON Tools Images
[2013/01/12 12:58:17 | 000,000,000 | ---D | C] -- C:\Windows\System32\MpEngineStore
[2013/01/11 21:34:44 | 000,000,000 | ---D | C] -- C:\ProgramData\NCH Software
[2013/01/08 20:21:36 | 000,000,000 | ---D | C] -- C:\Windows\pss
[2013/01/07 20:10:35 | 000,528,384 | ---- | C] (IDT, Inc.) -- C:\Windows\System32\stapi32.dll

[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]

[2013/01/13 20:41:52 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013/01/13 20:41:43 | 2760,261,632 | -HS- | M] () -- C:\hiberfil.sys
[2013/01/13 15:30:38 | 000,000,618 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/01/13 15:04:35 | 000,001,068 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/01/12 20:13:19 | 000,000,026 | ---- | M] () -- C:\Windows\CMCDPLAY.INI
[2013/01/12 14:19:54 | 000,441,432 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2013/01/12 13:12:00 | 000,001,002 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/01/12 13:01:41 | 000,363,460 | ---- | M] () -- C:\Windows\System32\perfh00C.dat
[2013/01/12 13:01:41 | 000,299,952 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2013/01/12 13:01:41 | 000,045,178 | ---- | M] () -- C:\Windows\System32\perfc00C.dat
[2013/01/12 13:01:41 | 000,037,816 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2013/01/12 12:58:18 | 000,033,451 | ---- | M] () -- C:\Windows\System32\MRT.INI
[2013/01/12 12:56:55 | 000,021,120 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/01/12 12:56:55 | 000,021,120 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/01/11 22:19:33 | 000,015,360 | ---- | M] () -- C:\Windows\System32\umstartup.etl
[2013/01/11 12:06:26 | 000,001,072 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/01/07 18:54:49 | 000,001,040 | RHS- | M] () -- C:\Users\Administrateur\ntuser.pol
[2013/01/07 17:55:00 | 000,001,132 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-2170562045-1414757869-1238418950-500UA.job
[2013/01/03 17:18:30 | 000,010,480 | ---- | M] () -- C:\bootsqm.dat
[2013/01/02 15:57:07 | 000,000,937 | ---- | M] () -- C:\Users\Public\Desktop\SCANIA Truck Driving Simulator.lnk
[2013/01/02 15:15:46 | 000,000,380 | -H-- | M] () -- C:\Windows\tasks\TheBflixUpdaterLogonTask.job
[2013/01/02 15:15:44 | 000,000,360 | -H-- | M] () -- C:\Windows\tasks\TheBflixUpdaterRefreshTask.job
[2013/01/02 15:06:51 | 000,000,406 | ---- | M] () -- C:\Windows\tasks\ReclaimerUpdateFiles_Administrateur.job
[2013/01/02 15:06:51 | 000,000,402 | ---- | M] () -- C:\Windows\tasks\ReclaimerUpdateXML_Administrateur.job
[2012/12/18 17:39:24 | 000,000,473 | ---- | M] () -- C:\Windows\BRWMARK.INI
[2012/12/18 17:16:32 | 000,000,109 | RHS- | M] () -- C:\Windows\System32\autorun.ini

[color=#E56717]========== Files Created - No Company Name ==========[/color]

[2013/01/13 15:30:38 | 000,000,618 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/01/12 20:13:19 | 000,000,026 | ---- | C] () -- C:\Windows\CMCDPLAY.INI
[2013/01/12 14:19:41 | 000,441,432 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2013/01/11 15:23:32 | 000,002,024 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Dell System Manager.lnk
[2013/01/03 17:18:30 | 000,010,480 | ---- | C] () -- C:\bootsqm.dat
[2013/01/02 15:57:07 | 000,000,937 | ---- | C] () -- C:\Users\Public\Desktop\SCANIA Truck Driving Simulator.lnk
[2013/01/02 15:04:46 | 000,000,406 | ---- | C] () -- C:\Windows\tasks\ReclaimerUpdateFiles_Administrateur.job
[2013/01/02 15:04:41 | 000,000,402 | ---- | C] () -- C:\Windows\tasks\ReclaimerUpdateXML_Administrateur.job
[2012/12/18 17:16:32 | 000,000,109 | RHS- | C] () -- C:\Windows\System32\autorun.ini
[2012/12/03 20:03:30 | 000,008,490 | -HS- | C] () -- C:\Users\Administrateur\Folder.jpg
[2012/12/03 20:03:30 | 000,008,490 | -HS- | C] () -- C:\Users\Administrateur\AlbumArt_{0A4DF859-2080-4940-B81B-7A29074B8152}_Large.jpg
[2012/12/03 20:03:30 | 000,002,304 | -HS- | C] () -- C:\Users\Administrateur\AlbumArtSmall.jpg
[2012/12/03 20:03:30 | 000,002,304 | -HS- | C] () -- C:\Users\Administrateur\AlbumArt_{0A4DF859-2080-4940-B81B-7A29074B8152}_Small.jpg
[2012/12/03 17:04:36 | 000,000,038 | ---- | C] () -- C:\Windows\avisplitter.INI
[2012/11/24 09:04:07 | 000,000,804 | ---- | C] () -- C:\Windows\CEDERAMA.INI
[2012/11/24 09:02:50 | 000,008,000 | ---- | C] () -- C:\Windows\MATHICO.DLL
[2012/10/29 12:28:07 | 000,066,048 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe
[2012/10/29 00:28:08 | 000,867,020 | ---- | C] () -- C:\Windows\System32\igkrng575.bin
[2012/10/29 00:28:07 | 000,105,608 | ---- | C] () -- C:\Windows\System32\igfcg575m.bin
[2012/10/29 00:28:07 | 000,004,096 | ---- | C] ( ) -- C:\Windows\System32\IGFXDEVLib.dll
[2012/10/29 00:28:05 | 000,128,204 | ---- | C] () -- C:\Windows\System32\igcompkrng575.bin
[2012/10/29 00:28:04 | 013,913,600 | ---- | C] () -- C:\Windows\System32\ig4icd32.dll
[2012/10/29 00:28:04 | 000,094,208 | ---- | C] () -- C:\Windows\System32\IccLibDll.dll
[2012/10/29 00:28:04 | 000,000,146 | ---- | C] () -- C:\Windows\System32\GfxUI.exe.config
[2012/09/27 17:51:32 | 001,006,448 | ---- | C] () -- C:\Windows\System32\dmwu.exe
[2012/08/15 23:11:24 | 000,001,431 | ---- | C] () -- C:\Windows\SplitCam.INI
[2012/08/15 17:47:07 | 000,810,496 | ---- | C] () -- C:\Windows\System32\xvidcore.dll
[2012/08/15 17:47:07 | 000,080,896 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll
[2012/08/15 17:16:17 | 000,216,064 | ---- | C] ( ) -- C:\Windows\System32\LAGARITH.DLL
[2012/08/01 15:28:34 | 000,016,384 | ---- | C] () -- C:\Windows\System32\FileOps.exe
[2012/07/17 23:26:37 | 006,922,006 | ---- | C] () -- C:\Users\Administrateur\300763.mp3
[2012/07/17 23:08:58 | 004,765,127 | ---- | C] () -- C:\Users\Administrateur\3247-1-votingeditorial.mp3
[2012/05/27 18:18:04 | 000,107,520 | RHS- | C] () -- C:\Windows\System32\TAKDSDecoder.dll
[2012/05/05 19:17:53 | 000,846,316 | ---- | C] () -- C:\Users\Administrateur\Desktop.sla
[2012/05/02 19:15:18 | 000,077,824 | ---- | C] () -- C:\Windows\System32\BROSNMP.DLL
[2012/05/02 19:15:18 | 000,026,624 | ---- | C] () -- C:\Windows\System32\BRGSRC32.DLL
[2012/05/02 19:15:18 | 000,004,608 | ---- | C] () -- C:\Windows\System32\BRGSRC16.DLL
[2012/05/02 19:15:18 | 000,000,313 | ---- | C] () -- C:\Windows\BRDIAG.INI
[2012/05/02 19:15:18 | 000,000,146 | ---- | C] () -- C:\Windows\BRVIDEO.INI
[2012/05/02 19:15:18 | 000,000,023 | ---- | C] () -- C:\Windows\Brownie.ini
[2012/05/02 19:15:18 | 000,000,000 | ---- | C] () -- C:\Windows\bw5150d.ini
[2012/05/02 19:15:18 | 000,000,000 | ---- | C] () -- C:\Windows\brmx2001.ini
[2012/05/02 19:14:56 | 000,015,108 | ---- | C] () -- C:\Windows\HL-5150D.INI
[2012/05/02 19:14:33 | 000,000,030 | ---- | C] () -- C:\Windows\System32\BRSS01A.ini
[2012/05/02 19:14:32 | 000,000,473 | ---- | C] () -- C:\Windows\BRWMARK.INI
[2012/05/02 19:14:32 | 000,000,052 | ---- | C] () -- C:\Windows\BRPP2KA.INI
[2012/03/08 17:20:12 | 000,043,520 | ---- | C] () -- C:\Windows\System32\CmdLineExt03.dll
[2012/01/22 19:41:51 | 000,000,256 | ---- | C] () -- C:\ProgramData\svcdotnet.inc
[2011/12/31 20:05:20 | 000,150,664 | -H-- | C] () -- C:\Windows\System32\mlfcache.dat
[2011/12/30 17:15:26 | 000,001,762 | ---- | C] () -- C:\Windows\Sandboxie.ini
[2011/10/15 19:34:09 | 000,000,000 | ---- | C] () -- C:\ProgramData\e6f41770d0c9f2f710b6e08437340391_c
[2011/09/21 10:55:11 | 000,033,451 | ---- | C] () -- C:\Windows\System32\MRT.INI
[2011/08/06 10:21:23 | 000,061,257 | ---- | C] () -- C:\Windows\system32\config\systemprofile\AppData\Roaming\Administrateur3SQLite3.dll
[2011/08/06 10:20:01 | 000,000,000 | ---- | C] () -- C:\Windows\system32\config\systemprofile\AppData\Local\WavXMapDrive.bat
[2011/07/29 15:05:34 | 000,183,808 | ---- | C] () -- C:\Windows\System32\xvidvfw.dll
[2011/07/28 21:33:27 | 000,004,096 | ---- | C] () -- C:\Windows\d3dx.dat
[2011/04/09 18:55:28 | 000,179,261 | ---- | C] () -- C:\Windows\System32\xlive.dll.cat
[2011/04/06 11:14:03 | 000,001,040 | RHS- | C] () -- C:\Users\Administrateur\ntuser.pol
[2011/03/11 20:36:43 | 000,000,000 | ---- | C] () -- C:\Windows\ODBCT32.INI
[2011/02/27 18:19:00 | 000,000,056 | -H-- | C] () -- C:\Windows\System32\ezsidmv.dat
[2010/10/14 08:43:41 | 000,001,024 | ---- | C] () -- C:\Users\Administrateur\.rnd
[2005/12/21 22:43:48 | 007,473,086 | -H-- | C] () -- C:\Windows\system32\config\systemprofile\AppData\Roaming\Administrateurlog.dat

[color=#E56717]========== ZeroAccess Check ==========[/color]

[2009/07/14 04:42:31 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012/06/09 04:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 12:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009/07/14 01:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[color=#E56717]========== LOP Check ==========[/color]


[color=#E56717]========== Purity Check ==========[/color]



[color=#E56717]========== Alternate Data Streams ==========[/color]

@Alternate Data Stream - 3020 bytes -> C:\ProgramData\rkfree:cfg
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:890CC2F3

< End of report >