Comment supprimer Esaylifeapp Search de Firefox

patnour Messages postés 43 Statut Membre -  
patnour Messages postés 43 Statut Membre -
Bonjour à tous,

Je fais appel à votre assistance car que j'ai téléchargé une application demo gratuite "suitcase"d'un site connu, je l'ai installé mais avec par défaut cet indésirable easylifeapp search et depuis je n'ai que des problèmes avec mon explorateur qui au bout de peu de temps n'affiche plus grand chose, mon explorateur windows 7 a beaucoup de mal à charger les icônes à afficher les images ... il est devenu très lent.

Est ce que quelqu'un connait une procédure pour enlevé cette bestiole de mon système.
Merci à tous pour votre aide car je me casse la tête depuis un certain temps à trouver une solution sans succès.

Au secours !
A voir également:

31 réponses

patnour Messages postés 43 Statut Membre 2
 
Bonsoir Smart,

J'ai skip quand il m'a trouvé ceci :

SERVICE : SPTD suspect object medium risk
0
patnour Messages postés 43 Statut Membre 2
 
Re bonsoir,

Ci-dessous le deuxième rapport.
Merci encore.
patnour.

E:\ZHP\Quarantine\biosagent plus.lnk.VIR,e:\users\patnour\desktop\biosagent plus.lnk
E:\ZHP\Quarantine\esupport.com.VIR,e:\users\patnour\appdata\local\esupport.com
E:\ZHP\Quarantine\srvany.exe.VIR,e:\windows\srvany.exe
E:\ZHP\Quarantine\BrowseToSave.DIR,E:\Program Files\BrowseToSave
E:\ZHP\Quarantine\eSupport.com.DIR,E:\Users\patnour\AppData\Local\eSupport.com
E:\ZHP\Quarantine\my book 1130 - raccourci.lnk.VIR,e:\users\patnour\desktop\my book 1130 - raccourci.lnk
E:\ZHP\Quarantine\keygen.exe.VIR,c:\documents and settings\administrateur\bureau\keygen\keygen.exe
E:\ZHP\Quarantine\vmware-workstation-full-7.0.0-203739.exe.VIR,c:\documents and settings\administrateur\bureau\keygen\setup\vmware-workstation-full-7.0.0-203739.exe
E:\ZHP\Quarantine\clonecd.exe.VIR,c:\program files\elaborate bytes\clonecd\clonecd.5.0.4.2\snd-clonecd5.0.4.2.cracked.exe\clonecd.exe
E:\ZHP\Quarantine\file_id.diz.VIR,c:\program files\elaborate bytes\clonecd\clonecd.5.0.4.2\snd-clonecd5.0.4.2.cracked.exe\file_id.diz
E:\ZHP\Quarantine\registration.reg.VIR,c:\program files\elaborate bytes\clonecd\clonecd.5.0.4.2\snd-clonecd5.0.4.2.cracked.exe\registration.reg
E:\ZHP\Quarantine\snd.nfo.VIR,c:\program files\elaborate bytes\clonecd\clonecd.5.0.4.2\snd-clonecd5.0.4.2.cracked.exe\snd.nfo
E:\ZHP\Quarantine\(incl. keygen) swish max4 crack.zip.VIR,e:\program files\emule\incoming\software\(incl. keygen) swish max4 crack.zip
E:\ZHP\Quarantine\minecraft cracked.exe.VIR,h:\incoming\images nour\minecraft cracked.exe
E:\ZHP\Quarantine\vmware thinapp (formerly thinstall) v4.0.0.200 + keygen.rar.VIR,h:\incoming\logiciels\vmware thinapp (formerly thinstall) v4.0.0.200 + keygen.rar
E:\ZHP\Quarantine\cloutierfontes_crack-and-bold.zip.VIR,h:\itest\coffre\ressources photoshop\font\fonts cracked\cloutierfontes_crack-and-bold.zip
E:\ZHP\Quarantine\cloutierfontes_crack-and-bold.zip.VIR,w:\documents photoshop\ressources photoshop\font\fonts cracked\cloutierfontes_crack-and-bold.zip
E:\ZHP\Quarantine\McAfee.DIR,E:\ProgramData\McAfee
E:\ZHP\Quarantine\McAfee Security Scan.DIR,E:\Program Files\McAfee Security Scan
E:\ZHP\Quarantine\mipony-plugin.DIR,e:\users\patnour\appdata\locallow\mipony-plugin
E:\ZHP\Quarantine\{05C55691-B652-4F21-A92F-BAD1E4D59479}.DIR,E:\Users\patnour\AppData\Local\{05C55691-B652-4F21-A92F-BAD1E4D59479}
E:\ZHP\Quarantine\{0D12E030-86F4-4B4F-9522-944A2DAED429}.DIR,E:\Users\patnour\AppData\Local\{0D12E030-86F4-4B4F-9522-944A2DAED429}
E:\ZHP\Quarantine\{0D35864C-5C81-4D48-A508-2FFC443A5151}.DIR,E:\Users\patnour\AppData\Local\{0D35864C-5C81-4D48-A508-2FFC443A5151}
E:\ZHP\Quarantine\{13A39441-1446-4535-9B9C-6AE7F4BAC45B}.DIR,E:\Users\patnour\AppData\Local\{13A39441-1446-4535-9B9C-6AE7F4BAC45B}
E:\ZHP\Quarantine\{164F426E-F6C3-4F4F-B8B8-75A34959AF56}.DIR,E:\Users\patnour\AppData\Local\{164F426E-F6C3-4F4F-B8B8-75A34959AF56}
E:\ZHP\Quarantine\{16F9D1EA-5663-4EF1-B011-3DCFA9B41F87}.DIR,E:\Users\patnour\AppData\Local\{16F9D1EA-5663-4EF1-B011-3DCFA9B41F87}
E:\ZHP\Quarantine\{17BFC80A-A9F2-4131-975D-2BF5B7E03CD8}.DIR,E:\Users\patnour\AppData\Local\{17BFC80A-A9F2-4131-975D-2BF5B7E03CD8}
E:\ZHP\Quarantine\{1BBD658F-516C-4874-B37F-CFACCF19D8BB}.DIR,E:\Users\patnour\AppData\Local\{1BBD658F-516C-4874-B37F-CFACCF19D8BB}
E:\ZHP\Quarantine\{1F2B915F-BC44-4E0D-8297-77AA97EE5BDE}.DIR,E:\Users\patnour\AppData\Local\{1F2B915F-BC44-4E0D-8297-77AA97EE5BDE}
E:\ZHP\Quarantine\{2386F2E5-07D2-4785-A01A-401687E1A5D1}.DIR,E:\Users\patnour\AppData\Local\{2386F2E5-07D2-4785-A01A-401687E1A5D1}
E:\ZHP\Quarantine\{28D22490-6C53-496D-BC1D-23CA4A788596}.DIR,E:\Users\patnour\AppData\Local\{28D22490-6C53-496D-BC1D-23CA4A788596}
E:\ZHP\Quarantine\{2EE8AF39-A9F6-4D01-A96D-E54C7BA4A21C}.DIR,E:\Users\patnour\AppData\Local\{2EE8AF39-A9F6-4D01-A96D-E54C7BA4A21C}
E:\ZHP\Quarantine\{2FB9B24C-865C-47AA-935C-6827E23C55F4}.DIR,E:\Users\patnour\AppData\Local\{2FB9B24C-865C-47AA-935C-6827E23C55F4}
E:\ZHP\Quarantine\{30A04BB3-7CBF-4D52-96BB-1A5CD2FAA0C0}.DIR,E:\Users\patnour\AppData\Local\{30A04BB3-7CBF-4D52-96BB-1A5CD2FAA0C0}
E:\ZHP\Quarantine\{32DE391E-CACD-473D-B94F-5BF665FF23A6}.DIR,E:\Users\patnour\AppData\Local\{32DE391E-CACD-473D-B94F-5BF665FF23A6}
E:\ZHP\Quarantine\{3B268377-6183-40BA-A87E-53A3D633D827}.DIR,E:\Users\patnour\AppData\Local\{3B268377-6183-40BA-A87E-53A3D633D827}
E:\ZHP\Quarantine\{3C723513-46EB-4319-8F45-8BF0F9645898}.DIR,E:\Users\patnour\AppData\Local\{3C723513-46EB-4319-8F45-8BF0F9645898}
E:\ZHP\Quarantine\{3E65FEB3-67CB-48A2-B818-F183D2615BE0}.DIR,E:\Users\patnour\AppData\Local\{3E65FEB3-67CB-48A2-B818-F183D2615BE0}
E:\ZHP\Quarantine\{3FD92D49-51E7-4FE3-9F79-C6327A33ED24}.DIR,E:\Users\patnour\AppData\Local\{3FD92D49-51E7-4FE3-9F79-C6327A33ED24}
E:\ZHP\Quarantine\{40A8F28F-1DAF-4A42-8487-0033D77AF8BC}.DIR,E:\Users\patnour\AppData\Local\{40A8F28F-1DAF-4A42-8487-0033D77AF8BC}
E:\ZHP\Quarantine\{416FC33E-04BD-42DC-B7C8-EA8BF2EAB25D}.DIR,E:\Users\patnour\AppData\Local\{416FC33E-04BD-42DC-B7C8-EA8BF2EAB25D}
E:\ZHP\Quarantine\{451179F8-CA57-4D7B-9671-E97BE4A79EEE}.DIR,E:\Users\patnour\AppData\Local\{451179F8-CA57-4D7B-9671-E97BE4A79EEE}
E:\ZHP\Quarantine\{47FC3093-7FA6-4964-BF89-A0D119FC4217}.DIR,E:\Users\patnour\AppData\Local\{47FC3093-7FA6-4964-BF89-A0D119FC4217}
E:\ZHP\Quarantine\{48CD5EFC-8953-4D1D-9C25-5FC1EB09EF31}.DIR,E:\Users\patnour\AppData\Local\{48CD5EFC-8953-4D1D-9C25-5FC1EB09EF31}
E:\ZHP\Quarantine\{49C33A86-F4EF-49E6-A436-CAFEFBE2D9A6}.DIR,E:\Users\patnour\AppData\Local\{49C33A86-F4EF-49E6-A436-CAFEFBE2D9A6}
E:\ZHP\Quarantine\{4B3EF6D8-7914-4411-B28F-1CBD810BB7E9}.DIR,E:\Users\patnour\AppData\Local\{4B3EF6D8-7914-4411-B28F-1CBD810BB7E9}
E:\ZHP\Quarantine\{4E184254-EB94-4289-A1E7-93D65C7FDF0D}.DIR,E:\Users\patnour\AppData\Local\{4E184254-EB94-4289-A1E7-93D65C7FDF0D}
E:\ZHP\Quarantine\{518EA31D-B26D-49B7-8E66-9E49FC6E851F}.DIR,E:\Users\patnour\AppData\Local\{518EA31D-B26D-49B7-8E66-9E49FC6E851F}
E:\ZHP\Quarantine\{5ACF46BD-E860-4B37-BF64-9EB073AE6438}.DIR,E:\Users\patnour\AppData\Local\{5ACF46BD-E860-4B37-BF64-9EB073AE6438}
E:\ZHP\Quarantine\{5B1ACC82-3E57-44B2-BAE3-7FBEC73C19A9}.DIR,E:\Users\patnour\AppData\Local\{5B1ACC82-3E57-44B2-BAE3-7FBEC73C19A9}
E:\ZHP\Quarantine\{5B9C486C-C59C-4A79-B0AE-90E39DD8E2B8}.DIR,E:\Users\patnour\AppData\Local\{5B9C486C-C59C-4A79-B0AE-90E39DD8E2B8}
E:\ZHP\Quarantine\{5E66BA3D-DE62-436C-A9BA-637AC91D521E}.DIR,E:\Users\patnour\AppData\Local\{5E66BA3D-DE62-436C-A9BA-637AC91D521E}
E:\ZHP\Quarantine\{5EF42E0A-287A-4AF3-8452-E13723F87384}.DIR,E:\Users\patnour\AppData\Local\{5EF42E0A-287A-4AF3-8452-E13723F87384}
E:\ZHP\Quarantine\{613B5BD5-9C3E-4B1D-A355-048C8F88B238}.DIR,E:\Users\patnour\AppData\Local\{613B5BD5-9C3E-4B1D-A355-048C8F88B238}
E:\ZHP\Quarantine\{65FE9166-6155-4AEF-A34B-B567BCA95F00}.DIR,E:\Users\patnour\AppData\Local\{65FE9166-6155-4AEF-A34B-B567BCA95F00}
E:\ZHP\Quarantine\{6622933D-06C8-4344-B987-9B4425B542A8}.DIR,E:\Users\patnour\AppData\Local\{6622933D-06C8-4344-B987-9B4425B542A8}
E:\ZHP\Quarantine\{666CBBD4-99BD-468D-8756-3CBBF84397E6}.DIR,E:\Users\patnour\AppData\Local\{666CBBD4-99BD-468D-8756-3CBBF84397E6}
E:\ZHP\Quarantine\{679455D3-4826-4577-BA39-68D3DFE628F0}.DIR,E:\Users\patnour\AppData\Local\{679455D3-4826-4577-BA39-68D3DFE628F0}
E:\ZHP\Quarantine\{6C860817-3D26-4E08-93A7-A6371E9D592F}.DIR,E:\Users\patnour\AppData\Local\{6C860817-3D26-4E08-93A7-A6371E9D592F}
E:\ZHP\Quarantine\{6F71565C-992C-45AE-B8AB-BE83E4C41131}.DIR,E:\Users\patnour\AppData\Local\{6F71565C-992C-45AE-B8AB-BE83E4C41131}
E:\ZHP\Quarantine\{73A69282-35C5-4032-9F5A-3F60DD9F2841}.DIR,E:\Users\patnour\AppData\Local\{73A69282-35C5-4032-9F5A-3F60DD9F2841}
E:\ZHP\Quarantine\{7434AF43-B181-4F42-B76F-77C865C39695}.DIR,E:\Users\patnour\AppData\Local\{7434AF43-B181-4F42-B76F-77C865C39695}
E:\ZHP\Quarantine\{75CF3DAE-F80F-469E-B6B6-A3C2F21B0BEA}.DIR,E:\Users\patnour\AppData\Local\{75CF3DAE-F80F-469E-B6B6-A3C2F21B0BEA}
E:\ZHP\Quarantine\{7AFC8DBB-DF92-4D0D-BF79-8E755A1329C8}.DIR,E:\Users\patnour\AppData\Local\{7AFC8DBB-DF92-4D0D-BF79-8E755A1329C8}
E:\ZHP\Quarantine\{7FDD8E51-AB26-4B0A-9B54-59F3A4B5EB08}.DIR,E:\Users\patnour\AppData\Local\{7FDD8E51-AB26-4B0A-9B54-59F3A4B5EB08}
E:\ZHP\Quarantine\{8017210B-6F49-446C-9BE8-1A70BFCD5C0E}.DIR,E:\Users\patnour\AppData\Local\{8017210B-6F49-446C-9BE8-1A70BFCD5C0E}
E:\ZHP\Quarantine\{861C72CE-8783-430C-8D6D-5D52DA0AEB59}.DIR,E:\Users\patnour\AppData\Local\{861C72CE-8783-430C-8D6D-5D52DA0AEB59}
E:\ZHP\Quarantine\{88BDEEF1-E5E3-4E91-8C99-B81B62CA507A}.DIR,E:\Users\patnour\AppData\Local\{88BDEEF1-E5E3-4E91-8C99-B81B62CA507A}
E:\ZHP\Quarantine\{88F143C1-330F-4FDE-8C1E-A7487F2030CF}.DIR,E:\Users\patnour\AppData\Local\{88F143C1-330F-4FDE-8C1E-A7487F2030CF}
E:\ZHP\Quarantine\{8B6ED4C7-D297-41B3-8429-C8F8A80B60C8}.DIR,E:\Users\patnour\AppData\Local\{8B6ED4C7-D297-41B3-8429-C8F8A80B60C8}
E:\ZHP\Quarantine\{8DE4F101-810D-4D7D-8E77-AD0C193A89B2}.DIR,E:\Users\patnour\AppData\Local\{8DE4F101-810D-4D7D-8E77-AD0C193A89B2}
E:\ZHP\Quarantine\{8E3C4303-307A-4E59-9BB9-F674D1E5396B}.DIR,E:\Users\patnour\AppData\Local\{8E3C4303-307A-4E59-9BB9-F674D1E5396B}
E:\ZHP\Quarantine\{8F2E8B70-E234-431E-9851-C5FAB7408993}.DIR,E:\Users\patnour\AppData\Local\{8F2E8B70-E234-431E-9851-C5FAB7408993}
E:\ZHP\Quarantine\{941638A8-BD7C-4FE1-AD02-C20AE682F4BE}.DIR,E:\Users\patnour\AppData\Local\{941638A8-BD7C-4FE1-AD02-C20AE682F4BE}
E:\ZHP\Quarantine\{94284CD7-412E-4F0A-8312-6F8EF2DD9C21}.DIR,E:\Users\patnour\AppData\Local\{94284CD7-412E-4F0A-8312-6F8EF2DD9C21}
E:\ZHP\Quarantine\{95E50A24-1B5D-4269-9D2A-FCF7D4D074D3}.DIR,E:\Users\patnour\AppData\Local\{95E50A24-1B5D-4269-9D2A-FCF7D4D074D3}
E:\ZHP\Quarantine\{973E9DB5-1267-4BF1-A298-8174EF3B5454}.DIR,E:\Users\patnour\AppData\Local\{973E9DB5-1267-4BF1-A298-8174EF3B5454}
E:\ZHP\Quarantine\{99AF3717-338B-4028-A61E-61F455F77FDA}.DIR,E:\Users\patnour\AppData\Local\{99AF3717-338B-4028-A61E-61F455F77FDA}
E:\ZHP\Quarantine\{9C29F015-C095-4AEF-9306-35C08981A624}.DIR,E:\Users\patnour\AppData\Local\{9C29F015-C095-4AEF-9306-35C08981A624}
E:\ZHP\Quarantine\{9CC26C48-8E11-4D44-AB76-B4BFF7499A74}.DIR,E:\Users\patnour\AppData\Local\{9CC26C48-8E11-4D44-AB76-B4BFF7499A74}
E:\ZHP\Quarantine\{9F18CB86-9112-4E40-9D6E-5D545F9B5B69}.DIR,E:\Users\patnour\AppData\Local\{9F18CB86-9112-4E40-9D6E-5D545F9B5B69}
E:\ZHP\Quarantine\{9FB59E0C-3FE0-4367-8165-32915D1ED124}.DIR,E:\Users\patnour\AppData\Local\{9FB59E0C-3FE0-4367-8165-32915D1ED124}
E:\ZHP\Quarantine\{A2476D1E-E0B9-4C5D-AC3D-F6F9B6184EB4}.DIR,E:\Users\patnour\AppData\Local\{A2476D1E-E0B9-4C5D-AC3D-F6F9B6184EB4}
E:\ZHP\Quarantine\{A2E86D8C-4727-46BB-81B7-E6F355A93049}.DIR,E:\Users\patnour\AppData\Local\{A2E86D8C-4727-46BB-81B7-E6F355A93049}
E:\ZHP\Quarantine\{A9E8EE9E-F425-44A8-BB37-36EB38E5ADCF}.DIR,E:\Users\patnour\AppData\Local\{A9E8EE9E-F425-44A8-BB37-36EB38E5ADCF}
E:\ZHP\Quarantine\{ABA349F7-0C8C-4684-B106-7C9FE2D181AC}.DIR,E:\Users\patnour\AppData\Local\{ABA349F7-0C8C-4684-B106-7C9FE2D181AC}
E:\ZHP\Quarantine\{AC389D0F-BFB3-4E7B-8659-34714877B64F}.DIR,E:\Users\patnour\AppData\Local\{AC389D0F-BFB3-4E7B-8659-34714877B64F}
E:\ZHP\Quarantine\{B07E1737-F3F9-4FC4-9B16-9508D845FFA9}.DIR,E:\Users\patnour\AppData\Local\{B07E1737-F3F9-4FC4-9B16-9508D845FFA9}
E:\ZHP\Quarantine\{B33F7F4F-225D-4595-BFA4-F434593D4560}.DIR,E:\Users\patnour\AppData\Local\{B33F7F4F-225D-4595-BFA4-F434593D4560}
E:\ZHP\Quarantine\{BE820863-FEEF-43B7-955D-7198416A97BE}.DIR,E:\Users\patnour\AppData\Local\{BE820863-FEEF-43B7-955D-7198416A97BE}
E:\ZHP\Quarantine\{C3FAAE04-4600-4780-A8B2-1A6A0C2EDEA6}.DIR,E:\Users\patnour\AppData\Local\{C3FAAE04-4600-4780-A8B2-1A6A0C2EDEA6}
E:\ZHP\Quarantine\{C6CC7F4E-C497-4D7E-96D7-CD257E344239}.DIR,E:\Users\patnour\AppData\Local\{C6CC7F4E-C497-4D7E-96D7-CD257E344239}
E:\ZHP\Quarantine\{C71F79E8-7C30-4B10-8323-07A6C5DB3F12}.DIR,E:\Users\patnour\AppData\Local\{C71F79E8-7C30-4B10-8323-07A6C5DB3F12}
E:\ZHP\Quarantine\{CAD38990-B41A-4244-93D8-0726D0EDE006}.DIR,E:\Users\patnour\AppData\Local\{CAD38990-B41A-4244-93D8-0726D0EDE006}
E:\ZHP\Quarantine\{CE2F69F9-6C49-44FC-BD12-51387878C112}.DIR,E:\Users\patnour\AppData\Local\{CE2F69F9-6C49-44FC-BD12-51387878C112}
E:\ZHP\Quarantine\{CEA0E100-A0FC-4857-A582-1E86E5A852E0}.DIR,E:\Users\patnour\AppData\Local\{CEA0E100-A0FC-4857-A582-1E86E5A852E0}
E:\ZHP\Quarantine\{D55229D9-9B9D-4EA0-A90D-56288CC45294}.DIR,E:\Users\patnour\AppData\Local\{D55229D9-9B9D-4EA0-A90D-56288CC45294}
E:\ZHP\Quarantine\{D8506138-5EC5-4EFC-9374-0138E166F0BD}.DIR,E:\Users\patnour\AppData\Local\{D8506138-5EC5-4EFC-9374-0138E166F0BD}
E:\ZHP\Quarantine\{D9AC215D-ABFC-4741-83E8-22730D4ADD74}.DIR,E:\Users\patnour\AppData\Local\{D9AC215D-ABFC-4741-83E8-22730D4ADD74}
E:\ZHP\Quarantine\{DA7DE496-9FD3-4F5A-A9F9-A3FE4A5B7FDE}.DIR,E:\Users\patnour\AppData\Local\{DA7DE496-9FD3-4F5A-A9F9-A3FE4A5B7FDE}
E:\ZHP\Quarantine\{DA84CA7F-F28A-42F8-A2EE-A8E7C366A885}.DIR,E:\Users\patnour\AppData\Local\{DA84CA7F-F28A-42F8-A2EE-A8E7C366A885}
E:\ZHP\Quarantine\{DB6121E6-8000-4D73-9BA8-6A84DE8DCA2A}.DIR,E:\Users\patnour\AppData\Local\{DB6121E6-8000-4D73-9BA8-6A84DE8DCA2A}
E:\ZHP\Quarantine\{E197C368-8619-4524-ACEB-2AD46213E2EE}.DIR,E:\Users\patnour\AppData\Local\{E197C368-8619-4524-ACEB-2AD46213E2EE}
E:\ZHP\Quarantine\{E97829A0-3230-4A22-A529-11B510CE4A04}.DIR,E:\Users\patnour\AppData\Local\{E97829A0-3230-4A22-A529-11B510CE4A04}
E:\ZHP\Quarantine\{E997A1E9-5DF1-49C4-B34E-23F290E10D69}.DIR,E:\Users\patnour\AppData\Local\{E997A1E9-5DF1-49C4-B34E-23F290E10D69}
E:\ZHP\Quarantine\{E9A0E214-D5FF-41CB-BCC5-8399B72CFB8F}.DIR,E:\Users\patnour\AppData\Local\{E9A0E214-D5FF-41CB-BCC5-8399B72CFB8F}
E:\ZHP\Quarantine\{EA31B236-5B1B-4367-9642-E5662FB7F955}.DIR,E:\Users\patnour\AppData\Local\{EA31B236-5B1B-4367-9642-E5662FB7F955}
E:\ZHP\Quarantine\{EB1DC023-56D6-4DDE-A7E5-4B69B4E4FB25}.DIR,E:\Users\patnour\AppData\Local\{EB1DC023-56D6-4DDE-A7E5-4B69B4E4FB25}
E:\ZHP\Quarantine\{EF103A92-17DB-41CB-9343-6D7B41584864}.DIR,E:\Users\patnour\AppData\Local\{EF103A92-17DB-41CB-9343-6D7B41584864}
E:\ZHP\Quarantine\{F1B7B99A-DB7C-4AED-B98F-84B0A60B61F8}.DIR,E:\Users\patnour\AppData\Local\{F1B7B99A-DB7C-4AED-B98F-84B0A60B61F8}
E:\ZHP\Quarantine\{F2E9DA9E-CFBD-4AFB-AADC-885FC9849137}.DIR,E:\Users\patnour\AppData\Local\{F2E9DA9E-CFBD-4AFB-AADC-885FC9849137}
E:\ZHP\Quarantine\{FBC977BB-C53A-4E02-9BA7-A0E10DFEC0F4}.DIR,E:\Users\patnour\AppData\Local\{FBC977BB-C53A-4E02-9BA7-A0E10DFEC0F4}
E:\ZHP\Quarantine\{FDFD3763-1FAE-4968-B716-AC5484C85122}.DIR,E:\Users\patnour\AppData\Local\{FDFD3763-1FAE-4968-B716-AC5484C85122}
0
patnour Messages postés 43 Statut Membre 2
 
Re bonsoir,

je me suis trompé je crois que c'est ce rapport que tu veux.

Rapport de ZHPFix 2013.7.20.5 par Nicolas Coolman, Update du 20/07/2013
Fichier d'export Registre : E:\ZHP\ZHPExportRegistry-24-07-2013-23-55-58.txt
Run by patnour at 24/07/2013 23:55:56
High Elevated Privileges : OK
Windows 7 Ultimate Edition, 32-bit Service Pack 1 (Build 7601)

========== ==========
ABSENT Uninstall Process: e:\program files\browsetosave\uninstall.exe

SUPPRIME Memory Process: C:\Documents and Settings\Administrateur\Bureau\keygen\keygen.exe
SUPPRIME Memory Process: C:\Documents and Settings\Administrateur\Bureau\keygen\setup\vmware-workstation-full-7.0.0-203739.exe
SUPPRIME Memory Process: C:\Program Files\Elaborate Bytes\CloneCD\CloneCD.5.0.4.2\snd-clonecd5.0.4.2.cracked.exe\CloneCD.exe
SUPPRIME Memory Process: C:\Program Files\Elaborate Bytes\CloneCD\CloneCD.5.0.4.2\snd-clonecd5.0.4.2.cracked.exe\file_id.diz
SUPPRIME Memory Process: C:\Program Files\Elaborate Bytes\CloneCD\CloneCD.5.0.4.2\snd-clonecd5.0.4.2.cracked.exe\Registration.reg
SUPPRIME Memory Process: C:\Program Files\Elaborate Bytes\CloneCD\CloneCD.5.0.4.2\snd-clonecd5.0.4.2.cracked.exe\snd.nfo
SUPPRIME Memory Process: H:\Incoming\Images Nour\Minecraft Cracked.exe

SUPPRIME [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SP_231c6454]
SUPPRIME Key: Service: KMService
SUPPRIME Key: HKCU\Software\eSupport.com
SUPPRIME Key: StartupReg: Optimizer Pro
ABSENTE Key: Service: KMService
SUPPRIME Key: HKLM\Software\Microsoft\Tracing\Searchqu Toolbar uninstall_RASAPI32
SUPPRIME Key: HKLM\Software\Microsoft\Tracing\Searchqu Toolbar uninstall_RASMANCS
SUPPRIME Key: HKCU\AppEvents\Schemes\Apps\Explorer\Navigating\Old_Current
ABSENTE Key: HKCU\Software\eSupport.com
ABSENTE Key: HKLM\SYSTEM\CurrentControlSet\Services\KMServic
ABSENTE Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\SP_231c6454
ABSENTE Key: HKLM\Software\Microsoft\Shared Tools\MSConfig\startupreg\Optimizer Pro
SUPPRIME Key: HKCU\Software\MCAFEE

SUPPRIME Mozilla Pref: user_pref("extensions.enabledItems", "{3112ca9c-de6d-4884-a869-9855de68056c}:7.1.20110512W,illimitux@illimitux.net:4.0,{20a82645-c[...]
SUPPRIME Mozilla Pref: user_pref("extensions.illimitux.illimitux_backup_http", "");
SUPPRIME Mozilla Pref: user_pref("extensions.illimitux.illimitux_backup_port", 0);
SUPPRIME Mozilla Pref: user_pref("extensions.illimitux.illimitux_backup_referer", 2);
SUPPRIME Mozilla Pref: user_pref("extensions.illimitux.illimitux_backup_type", 0);
SUPPRIME Mozilla Pref: user_pref("extensions.illimitux.illimitux_changed", 1);
SUPPRIME Mozilla Pref: user_pref("extensions.illimitux.illimitux_last_http", "");
SUPPRIME Mozilla Pref: user_pref("extensions.illimitux.illimitux_last_port", 0);
SUPPRIME Mozilla Pref: user_pref("extensions.illimitux.illimitux_last_type", 0);
SUPPRIME Mozilla Pref: user_pref("extensions.illimitux.ilx_firsttime_4.0_", false);
SUPPRIME Mozilla Pref: user_pref("extensions.illimitux.ilx_firsttime_4.0b_", false);
SUPPRIME Mozilla Pref: user_pref("extensions.illimitux.ilx_mu_auto", "dl");
SUPPRIME Mozilla Pref: user_pref("extensions.illimitux.ilx_pref_auto", true);
SUPPRIME Mozilla Pref: user_pref("extensions.illimitux.ilx_pref_box", true);
SUPPRIME Mozilla Pref: user_pref("extensions.illimitux.ilx_pref_captcha", true);
SUPPRIME Mozilla Pref: user_pref("extensions.illimitux.ilx_pref_divx", true);
SUPPRIME Mozilla Pref: user_pref("extensions.illimitux.ilx_pref_embed", true);
SUPPRIME Mozilla Pref: user_pref("extensions.illimitux.ilx_pref_proxy", true);
SUPPRIME Mozilla Pref: user_pref("extensions.illimitux.ilx_pref_pt_4s", true);
SUPPRIME Mozilla Pref: user_pref("extensions.illimitux.ilx_pref_pt_captcha", true);
SUPPRIME Mozilla Pref: user_pref("extensions.illimitux.ilx_pref_pt_mp", true);
SUPPRIME Mozilla Pref: user_pref("extensions.illimitux.ilx_pref_pt_mu", true);
SUPPRIME Mozilla Pref: user_pref("extensions.illimitux.ilx_pref_pt_mv", true);
SUPPRIME Mozilla Pref: user_pref("extensions.illimitux.ilx_pref_pt_rs", true);
SUPPRIME Mozilla Pref: user_pref("extensions.illimitux.ilx_pref_pt_rs1", true);
SUPPRIME Mozilla Pref: user_pref("extensions.illimitux.ilx_pref_pt_zs", true);
SUPPRIME Mozilla Pref: user_pref("extensions.illimitux.ilx_pref_referer", true);
SUPPRIME Mozilla Pref: user_pref("extensions.illimitux.ilx_pref_rs", true);
SUPPRIME Mozilla Pref: user_pref("extensions.illimitux.ilx_pref_tab", true);
SUPPRIME Mozilla Pref: user_pref("extensions.illimitux.ilx_pref_zapmu", true);
SUPPRIME Mozilla Pref: user_pref("extensions.illimitux.locale", "fr");

SUPPRIME Folder: E:\Users\patnour\AppData\Local\{05C55691-B652-4F21-A92F-BAD1E4D59479}
SUPPRIME Folder: E:\Users\patnour\AppData\Local\{0D12E030-86F4-4B4F-9522-944A2DAED429}
SUPPRIME Folder: E:\Users\patnour\AppData\Local\{0D35864C-5C81-4D48-A508-2FFC443A5151}
SUPPRIME Folder: E:\Users\patnour\AppData\Local\{13A39441-1446-4535-9B9C-6AE7F4BAC45B}
SUPPRIME Folder: E:\Users\patnour\AppData\Local\{164F426E-F6C3-4F4F-B8B8-75A34959AF56}
SUPPRIME Folder: E:\Users\patnour\AppData\Local\{16F9D1EA-5663-4EF1-B011-3DCFA9B41F87}
SUPPRIME Folder: E:\Users\patnour\AppData\Local\{17BFC80A-A9F2-4131-975D-2BF5B7E03CD8}
SUPPRIME Folder: E:\Users\patnour\AppData\Local\{1BBD658F-516C-4874-B37F-CFACCF19D8BB}
SUPPRIME Folder: E:\Users\patnour\AppData\Local\{1F2B915F-BC44-4E0D-8297-77AA97EE5BDE}
SUPPRIME Folder: E:\Users\patnour\AppData\Local\{2386F2E5-07D2-4785-A01A-401687E1A5D1}
SUPPRIME Folder: E:\Users\patnour\AppData\Local\{28D22490-6C53-496D-BC1D-23CA4A788596}
SUPPRIME Folder: E:\Users\patnour\AppData\Local\{2EE8AF39-A9F6-4D01-A96D-E54C7BA4A21C}
SUPPRIME Folder: E:\Users\patnour\AppData\Local\{2FB9B24C-865C-47AA-935C-6827E23C55F4}
SUPPRIME Folder: E:\Users\patnour\AppData\Local\{30A04BB3-7CBF-4D52-96BB-1A5CD2FAA0C0}
SUPPRIME Folder: E:\Users\patnour\AppData\Local\{32DE391E-CACD-473D-B94F-5BF665FF23A6}
SUPPRIME Folder: E:\Users\patnour\AppData\Local\{3B268377-6183-40BA-A87E-53A3D633D827}
SUPPRIME Folder: E:\Users\patnour\AppData\Local\{3C723513-46EB-4319-8F45-8BF0F9645898}
SUPPRIME Folder: E:\Users\patnour\AppData\Local\{3E65FEB3-67CB-48A2-B818-F183D2615BE0}
SUPPRIME Folder: E:\Users\patnour\AppData\Local\{3FD92D49-51E7-4FE3-9F79-C6327A33ED24}
SUPPRIME Folder: E:\Users\patnour\AppData\Local\{40A8F28F-1DAF-4A42-8487-0033D77AF8BC}
SUPPRIME Folder: E:\Users\patnour\AppData\Local\{416FC33E-04BD-42DC-B7C8-EA8BF2EAB25D}
SUPPRIME Folder: E:\Users\patnour\AppData\Local\{451179F8-CA57-4D7B-9671-E97BE4A79EEE}
SUPPRIME Folder: E:\Users\patnour\AppData\Local\{47FC3093-7FA6-4964-BF89-A0D119FC4217}
SUPPRIME Folder: E:\Users\patnour\AppData\Local\{48CD5EFC-8953-4D1D-9C25-5FC1EB09EF31}
SUPPRIME Folder: E:\Users\patnour\AppData\Local\{49C33A86-F4EF-49E6-A436-CAFEFBE2D9A6}
SUPPRIME Folder: E:\Users\patnour\AppData\Local\{4B3EF6D8-7914-4411-B28F-1CBD810BB7E9}
SUPPRIME Folder: E:\Users\patnour\AppData\Local\{4E184254-EB94-4289-A1E7-93D65C7FDF0D}
SUPPRIME Folder: E:\Users\patnour\AppData\Local\{518EA31D-B26D-49B7-8E66-9E49FC6E851F}
SUPPRIME Folder: E:\Users\patnour\AppData\Local\{5ACF46BD-E860-4B37-BF64-9EB073AE6438}
SUPPRIME Folder: E:\Users\patnour\AppData\Local\{5B1ACC82-3E57-44B2-BAE3-7FBEC73C19A9}
SUPPRIME Folder: E:\Users\patnour\AppData\Local\{5B9C486C-C59C-4A79-B0AE-90E39DD8E2B8}
SUPPRIME Folder: E:\Users\patnour\AppData\Local\{5E66BA3D-DE62-436C-A9BA-637AC91D521E}
SUPPRIME Folder: E:\Users\patnour\AppData\Local\{5EF42E0A-287A-4AF3-8452-E13723F87384}
SUPPRIME Folder: E:\Users\patnour\AppData\Local\{613B5BD5-9C3E-4B1D-A355-048C8F88B238}
SUPPRIME Folder: E:\Users\patnour\AppData\Local\{65FE9166-6155-4AEF-A34B-B567BCA95F00}
SUPPRIME Folder: E:\Users\patnour\AppData\Local\{6622933D-06C8-4344-B987-9B4425B542A8}
SUPPRIME Folder: E:\Users\patnour\AppData\Local\{666CBBD4-99BD-468D-8756-3CBBF84397E6}
SUPPRIME Folder: E:\Users\patnour\AppData\Local\{679455D3-4826-4577-BA39-68D3DFE628F0}
SUPPRIME Folder: E:\Users\patnour\AppData\Local\{6C860817-3D26-4E08-93A7-A6371E9D592F}
SUPPRIME Folder: E:\Users\patnour\AppData\Local\{6F71565C-992C-45AE-B8AB-BE83E4C41131}
SUPPRIME Folder: E:\Users\patnour\AppData\Local\{73A69282-35C5-4032-9F5A-3F60DD9F2841}
SUPPRIME Folder: E:\Users\patnour\AppData\Local\{7434AF43-B181-4F42-B76F-77C865C39695}
SUPPRIME Folder: E:\Users\patnour\AppData\Local\{75CF3DAE-F80F-469E-B6B6-A3C2F21B0BEA}
SUPPRIME Folder: E:\Users\patnour\AppData\Local\{7AFC8DBB-DF92-4D0D-BF79-8E755A1329C8}
SUPPRIME Folder: E:\Users\patnour\AppData\Local\{7FDD8E51-AB26-4B0A-9B54-59F3A4B5EB08}
SUPPRIME Folder: E:\Users\patnour\AppData\Local\{8017210B-6F49-446C-9BE8-1A70BFCD5C0E}
SUPPRIME Folder: E:\Users\patnour\AppData\Local\{861C72CE-8783-430C-8D6D-5D52DA0AEB59}
SUPPRIME Folder: E:\Users\patnour\AppData\Local\{88BDEEF1-E5E3-4E91-8C99-B81B62CA507A}
SUPPRIME Folder: E:\Users\patnour\AppData\Local\{88F143C1-330F-4FDE-8C1E-A7487F2030CF}
SUPPRIME Folder: E:\Users\patnour\AppData\Local\{8B6ED4C7-D297-41B3-8429-C8F8A80B60C8}
SUPPRIME Folder: E:\Users\patnour\AppData\Local\{8DE4F101-810D-4D7D-8E77-AD0C193A89B2}
SUPPRIME Folder: E:\Users\patnour\AppData\Local\{8E3C4303-307A-4E59-9BB9-F674D1E5396B}
SUPPRIME Folder: E:\Users\patnour\AppData\Local\{8F2E8B70-E234-431E-9851-C5FAB7408993}
SUPPRIME Folder: E:\Users\patnour\AppData\Local\{941638A8-BD7C-4FE1-AD02-C20AE682F4BE}
SUPPRIME Folder: E:\Users\patnour\AppData\Local\{94284CD7-412E-4F0A-8312-6F8EF2DD9C21}
SUPPRIME Folder: E:\Users\patnour\AppData\Local\{95E50A24-1B5D-4269-9D2A-FCF7D4D074D3}
SUPPRIME Folder: E:\Users\patnour\AppData\Local\{973E9DB5-1267-4BF1-A298-8174EF3B5454}
SUPPRIME Folder: E:\Users\patnour\AppData\Local\{99AF3717-338B-4028-A61E-61F455F77FDA}
SUPPRIME Folder: E:\Users\patnour\AppData\Local\{9C29F015-C095-4AEF-9306-35C08981A624}
SUPPRIME Folder: E:\Users\patnour\AppData\Local\{9CC26C48-8E11-4D44-AB76-B4BFF7499A74}
SUPPRIME Folder: E:\Users\patnour\AppData\Local\{9F18CB86-9112-4E40-9D6E-5D545F9B5B69}
SUPPRIME Folder: E:\Users\patnour\AppData\Local\{9FB59E0C-3FE0-4367-8165-32915D1ED124}
SUPPRIME Folder: E:\Users\patnour\AppData\Local\{A2476D1E-E0B9-4C5D-AC3D-F6F9B6184EB4}
SUPPRIME Folder: E:\Users\patnour\AppData\Local\{A2E86D8C-4727-46BB-81B7-E6F355A93049}
SUPPRIME Folder: E:\Users\patnour\AppData\Local\{A9E8EE9E-F425-44A8-BB37-36EB38E5ADCF}
SUPPRIME Folder: E:\Users\patnour\AppData\Local\{ABA349F7-0C8C-4684-B106-7C9FE2D181AC}
SUPPRIME Folder: E:\Users\patnour\AppData\Local\{AC389D0F-BFB3-4E7B-8659-34714877B64F}
SUPPRIME Folder: E:\Users\patnour\AppData\Local\{B07E1737-F3F9-4FC4-9B16-9508D845FFA9}
SUPPRIME Folder: E:\Users\patnour\AppData\Local\{B33F7F4F-225D-4595-BFA4-F434593D4560}
SUPPRIME Folder: E:\Users\patnour\AppData\Local\{BE820863-FEEF-43B7-955D-7198416A97BE}
SUPPRIME Folder: E:\Users\patnour\AppData\Local\{C3FAAE04-4600-4780-A8B2-1A6A0C2EDEA6}
SUPPRIME Folder: E:\Users\patnour\AppData\Local\{C6CC7F4E-C497-4D7E-96D7-CD257E344239}
SUPPRIME Folder: E:\Users\patnour\AppData\Local\{C71F79E8-7C30-4B10-8323-07A6C5DB3F12}
SUPPRIME Folder: E:\Users\patnour\AppData\Local\{CAD38990-B41A-4244-93D8-0726D0EDE006}
SUPPRIME Folder: E:\Users\patnour\AppData\Local\{CE2F69F9-6C49-44FC-BD12-51387878C112}
SUPPRIME Folder: E:\Users\patnour\AppData\Local\{CEA0E100-A0FC-4857-A582-1E86E5A852E0}
SUPPRIME Folder: E:\Users\patnour\AppData\Local\{D55229D9-9B9D-4EA0-A90D-56288CC45294}
SUPPRIME Folder: E:\Users\patnour\AppData\Local\{D8506138-5EC5-4EFC-9374-0138E166F0BD}
SUPPRIME Folder: E:\Users\patnour\AppData\Local\{D9AC215D-ABFC-4741-83E8-22730D4ADD74}
SUPPRIME Folder: E:\Users\patnour\AppData\Local\{DA7DE496-9FD3-4F5A-A9F9-A3FE4A5B7FDE}
SUPPRIME Folder: E:\Users\patnour\AppData\Local\{DA84CA7F-F28A-42F8-A2EE-A8E7C366A885}
SUPPRIME Folder: E:\Users\patnour\AppData\Local\{DB6121E6-8000-4D73-9BA8-6A84DE8DCA2A}
SUPPRIME Folder: E:\Users\patnour\AppData\Local\{E197C368-8619-4524-ACEB-2AD46213E2EE}
SUPPRIME Folder: E:\Users\patnour\AppData\Local\{E97829A0-3230-4A22-A529-11B510CE4A04}
SUPPRIME Folder: E:\Users\patnour\AppData\Local\{E997A1E9-5DF1-49C4-B34E-23F290E10D69}
SUPPRIME Folder: E:\Users\patnour\AppData\Local\{E9A0E214-D5FF-41CB-BCC5-8399B72CFB8F}
SUPPRIME Folder: E:\Users\patnour\AppData\Local\{EA31B236-5B1B-4367-9642-E5662FB7F955}
SUPPRIME Folder: E:\Users\patnour\AppData\Local\{EB1DC023-56D6-4DDE-A7E5-4B69B4E4FB25}
SUPPRIME Folder: E:\Users\patnour\AppData\Local\{EF103A92-17DB-41CB-9343-6D7B41584864}
SUPPRIME Folder: E:\Users\patnour\AppData\Local\{F1B7B99A-DB7C-4AED-B98F-84B0A60B61F8}
SUPPRIME Folder: E:\Users\patnour\AppData\Local\{F2E9DA9E-CFBD-4AFB-AADC-885FC9849137}
SUPPRIME Folder: E:\Users\patnour\AppData\Local\{FBC977BB-C53A-4E02-9BA7-A0E10DFEC0F4}
SUPPRIME Folder: E:\Users\patnour\AppData\Local\{FDFD3763-1FAE-4968-B716-AC5484C85122}

SUPPRIME File: e:\users\patnour\desktop\biosagent plus.lnk
SUPPRIME Reboot: e:\users\patnour\appdata\local\esupport.com
SUPPRIME File: e:\windows\srvany.exe
ABSENT File: e:\program files\optimizer pro\optprolauncher.exe
ABSENT File: e:\windows\srvany.exe
ABSENT Folder/File: e:\program files\browsetosave
ABSENT Folder/File: e:\users\patnour\appdata\local\esupport.com
ABSENT Folder/File: e:\users\patnour\appdata\local\esupport.com\biosagentplus_796.exe
ABSENT Folder/File: e:\windows\srvany.exe
SUPPRIME File: e:\users\patnour\desktop\my book 1130 - raccourci.lnk
SUPPRIME File: c:\documents and settings\administrateur\bureau\keygen\keygen.exe
SUPPRIME File: c:\documents and settings\administrateur\bureau\keygen\setup\vmware-workstation-full-7.0.0-203739.exe
SUPPRIME File***: c:\program files\elaborate bytes\clonecd\clonecd.5.0.4.2\snd-clonecd5.0.4.2.cracked.exe\clonecd.exe
SUPPRIME File***: c:\program files\elaborate bytes\clonecd\clonecd.5.0.4.2\snd-clonecd5.0.4.2.cracked.exe\file_id.diz
SUPPRIME File***: c:\program files\elaborate bytes\clonecd\clonecd.5.0.4.2\snd-clonecd5.0.4.2.cracked.exe\registration.reg
SUPPRIME File***: c:\program files\elaborate bytes\clonecd\clonecd.5.0.4.2\snd-clonecd5.0.4.2.cracked.exe\snd.nfo
SUPPRIME File: E:\Program Files\eMule\Incoming\Software\(incl. KeyGen) SWiSH Max4 crack.zip
SUPPRIME File***: e:\program files\emule\incoming\software\(incl. keygen) swish max4 crack.zip
SUPPRIME File***: h:\incoming\images nour\minecraft cracked.exe
ABSENT Folder/File: h:\incoming\logiciels\le.petit.robert.2009.cracked.french.proper.iso-ecz.
SUPPRIME File: H:\Incoming\Logiciels\VMware ThinApp (formerly Thinstall) v4.0.0.200 + Keygen.rar
SUPPRIME File: H:\iTest\Coffre\Ressources photoshop\Font\Fonts Cracked\cloutierfontes_crack-and-bold.zip
SUPPRIME File***: h:\itest\coffre\ressources photoshop\font\fonts cracked\cloutierfontes_crack-and-bold.zip
SUPPRIME File: W:\Documents PHOTOSHOP\Ressources photoshop\Font\Fonts Cracked\cloutierfontes_crack-and-bold.zip
SUPPRIME File***: w:\documents photoshop\ressources photoshop\font\fonts cracked\cloutierfontes_crack-and-bold.zip

Task: {020D5831-C49B-4FA7-A492-BAAC8534E2D5}
Task: {91B257F0-0E2A-48D8-8FC1-1362C1F59B68}
Task: {9AEC496B-95A7-4B8C-A1DB-5AD7D4834CB1}
Task: {ADF9EB00-4435-4087-925C-FBBCA13C7B6C}
Task: {AE87B309-315D-486D-852C-73D142472336}
Task: {C279872C-B716-47E3-9B3C-9DDC1D985406}
Task: {D5223279-C9A8-403A-AE2C-0EA33FCFCF97}
Task: {E70C3FB9-7BB0-4715-A222-CB5EB5AB08EF}
Task: {EA72A355-94CC-4DAA-A7C5-3B3826E4351C}

NON TRAITE Warning: possible TDL3 rootkit infection !

7 :
13 :
93 :
25 :
1 :
31 :
9 :

End of clean in 01mn 42s

E:\ZHP\ZHPFix[R1].txt - 24/07/2013 23:55:58 [15630]
0
patnour Messages postés 43 Statut Membre 2
 
Bonsoir Smart,

Ci-dessous le lien du rapport TDSSKILLER.
merci encore.
patnour.

http://cjoint.com/?CGzunaRChtv
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
patnour Messages postés 43 Statut Membre 2
 
Bonsoir,

Le rapport ci-dessous ZHPDIAG.TXT.
merci pour ton aide.
patnour.

https://pjjoint.malekal.com/files.php?id=ZHPDiag_20130726_t5p12g6x6m13
0
patnour Messages postés 43 Statut Membre 2
 
Bonjour Smart,

Ci dessous le lien demandé sur le dernier rapport ZHPDiag.

http://cjoint.com/?CGBrmpbzdKZ

Je n'ai pas d'émulateur d'installer mais j'ai nero9, clone dvd, imgburn et j'avais vmware desktop.

Sinon j'ai toujours le même pb quand j'ouvre l'explorateur windows de windows 7, toute la partie de gauche s'affiche bien et quand je clique sur ordinateur par ex les drives s'affiche bien sur la colonne de droite mais au bout de quelques manip quand je clique à nouveau sur "ordinateur" les drives sur la droite ne s'affiche plus, il charge doucement, la jauge tout en haut se rempli doucement de vert il arrive en bout de course quelques temps après mais il n'affiche rien et le curseur tourne en rond sans arrêt. pareil pour les images ou autres, elles ne s'affiche pas. Par contre quand j'ouvre picassa toutes mes images s'affiche sans pb.
Ce pb je ne l'ai qu'avec l'explorateur de seven.

Merci encore
Cdt,
patnour
0
Smart91 Messages postés 30146 Statut Contributeur sécurité 2 329
 
On va faire autrement

* Va sur ce lien https://www.luanagames.com/index.fr.html (par tigzy)
* Clique sur l'icône RogueKiller qui correspond à ta version de Windows (64 bits ou non) pour télécharger RogueKiller

* Quitte tous les programmes en cours
* Lance RogueKiller.exe.
* Attendre la fin du Prescan ...
* Clique sur Scan.
* A la fin du scan Clique sur Rapport. Copie et colle le rapport dans ta réponse

S'il ne veut pas se lancer, renomme le en winlogon.exe et recommence

Smart
0
patnour Messages postés 43 Statut Membre 2
 
Bonjour Smart,

Ci-dessous le rapport.
Merci encore.
patnour.

RogueKiller V8.6.3 [Jul 17 2013] par Tigzy
mail : tigzyRK<at>gmail<dot>com
Remontees : http://www.adlice.com/forum/
Site Web : https://www.luanagames.com/index.fr.html
Blog : http://tigzyrk.blogspot.com/

Systeme d'exploitation : Windows 7 (6.1.7601 Service Pack 1) 32 bits version
Demarrage : Mode normal
Utilisateur : patnour [Droits d'admin]
Mode : Recherche -- Date : 07/28/2013 02:45:25
| ARK || FAK || MBR |

¤¤¤ Processus malicieux : 0 ¤¤¤

¤¤¤ Entrees de registre : 11 ¤¤¤
[HJ POL] HKLM\[...]\System : ConsentPromptBehaviorAdmin (0) -> TROUVÉ
[HJ POL] HKLM\[...]\System : EnableLUA (0) -> TROUVÉ
[HJ SMENU] HKCU\[...]\Advanced : Start_ShowMyGames (0) -> TROUVÉ
[HJ SMENU] HKCU\[...]\Advanced : Start_ShowPrinters (0) -> TROUVÉ
[HJ DESK] HKCU\[...]\ClassicStartMenu : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> TROUVÉ
[HJ DESK] HKCU\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> TROUVÉ
[HJ DESK] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> TROUVÉ
[HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> TROUVÉ
[SCREENSVR][SUSP PATH] HKCU\[...]\Desktop : SCRNSAVE.EXE (E:\Users\patnour\ULUMIS~1.SCR [-]) -> TROUVÉ
[EXT RUN][SUSP PATH] HKLM\ON_C:\[...]\Run : tsnp325 (C:\WINDOWS\tsnp325.exe [-]) -> TROUVÉ
[EXT RUN][SUSP PATH] HKLM\ON_C:\[...]\Run : snp325 (C:\WINDOWS\vsnp325.exe [-]) -> TROUVÉ

¤¤¤ Tâches planifiées : 0 ¤¤¤

¤¤¤ Entrées Startup : 0 ¤¤¤

¤¤¤ Navigateurs web : 0 ¤¤¤

¤¤¤ Fichiers / Dossiers particuliers: ¤¤¤

¤¤¤ Driver : [CHARGE] ¤¤¤

¤¤¤ Ruches Externes: ¤¤¤
-> C:\windows\system32\config\SYSTEM
C:\WINDOWS\system32
C:\Documents and Settings\Administrateur\Menu Démarrer\Programmes\Démarrage
-> C:\windows\system32\config\SOFTWARE
C:\WINDOWS\system32
C:\Documents and Settings\Administrateur\Menu Démarrer\Programmes\Démarrage
-> C:\windows\system32\config\SECURITY
C:\WINDOWS\system32
C:\Documents and Settings\Administrateur\Menu Démarrer\Programmes\Démarrage
-> C:\windows\system32\config\SAM
C:\WINDOWS\system32
C:\Documents and Settings\Administrateur\Menu Démarrer\Programmes\Démarrage
-> C:\windows\system32\config\DEFAULT
C:\WINDOWS\system32
C:\Documents and Settings\Administrateur\Menu Démarrer\Programmes\Démarrage
-> C:\Documents and Settings\Administrateur\NTUSER.DAT
C:\WINDOWS\system32
C:\Documents and Settings\Administrateur\Menu Démarrer\Programmes\Démarrage
-> C:\Documents and Settings\All Users\NTUSER.DAT
C:\WINDOWS\system32

-> C:\Documents and Settings\Default User\NTUSER.DAT
C:\WINDOWS\system32
C:\Documents and Settings\Administrateur\Menu Démarrer\Programmes\Démarrage
-> C:\Documents and Settings\LocalService\NTUSER.DAT
C:\WINDOWS\system32
C:\Documents and Settings\LocalService\Menu Démarrer\Programmes\Démarrage
-> C:\Documents and Settings\NeroMediaHomeUser.4\NTUSER.DAT
C:\WINDOWS\system32
C:\Documents and Settings\NeroMediaHomeUser.4\Menu Démarrer\Programmes\Démarrage
-> C:\Documents and Settings\NetworkService\NTUSER.DAT
C:\WINDOWS\system32
C:\Documents and Settings\NetworkService\Menu Démarrer\Programmes\Démarrage
-> H:\windows\system32\config\SYSTEM
C:\Windows\system32
C:\Users\patnour\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
-> H:\windows\system32\config\SOFTWARE
C:\Windows\system32
C:\Users\patnour\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
-> H:\windows\system32\config\SECURITY
C:\Windows\system32
C:\Users\patnour\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
-> H:\windows\system32\config\SAM
C:\Windows\system32
C:\Users\patnour\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
-> H:\windows\system32\config\DEFAULT
C:\Windows\system32
C:\Users\patnour\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
-> H:\Users\Default\NTUSER.DAT
C:\Windows\system32

-> H:\Users\Mcx1\NTUSER.DAT
C:\Windows\system32

-> H:\Users\patnour\NTUSER.DAT
C:\Windows\system32
C:\Users\patnour\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup

¤¤¤ Infection : ¤¤¤

¤¤¤ Fichier HOSTS: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts

127.0.0.1 localhost
127.0.0.1 activate.adobe.com
127.0.0.1 practivate.adobe.com
127.0.0.1 ereg.adobe.com
127.0.0.1 activate.wip3.adobe.com
127.0.0.1 wip3.adobe.com
127.0.0.1 3dns-3.adobe.com
127.0.0.1 3dns-2.adobe.com
127.0.0.1 adobe-dns.adobe.com
127.0.0.1 adobe-dns-2.adobe.com
127.0.0.1 adobe-dns-3.adobe.com
127.0.0.1 ereg.wip3.adobe.com
127.0.0.1 activate-sea.adobe.com
127.0.0.1 pagead2.googlesyndication.com
127.0.0.1 wwis-dubc1-vip60.adobe.com
127.0.0.1 activate-sjc0.adobe.com
127.0.0.1 activate.adobe.com
127.0.0.1 localhost
127.0.0.1 hl2rcv.adobe.com
[...]

¤¤¤ MBR Verif: ¤¤¤

+++++ PhysicalDrive0: ST3250310AS ATA Device +++++
--- User ---
[MBR] 42ac3d8144c83ccec737813e6c62c9df
[BSP] 4fd8d7d211cb3a052e9f42f8ea113a54 : Windows Vista MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 238472 Mo
User = LL1 ... OK!
User = LL2 ... OK!

+++++ PhysicalDrive1: ST3250310AS ATA Device +++++
--- User ---
[MBR] 46f2e09e6f83c60be45f962a6fc13ec3
[BSP] c6320e36cddf1a19165d2195b96db391 : MBR Code unknown
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 102477 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 209873160 | Size: 132512 Mo
2 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 481259205 | Size: 3380 Mo
3 - [XXXXXX] EXTEN-LBA (0x0f) [VISIBLE] Offset (sectors): 488183808 | Size: 103 Mo
User = LL1 ... OK!
User = LL2 ... OK!

Termine : << RKreport[0]_S_07282013_024525.txt >>
0
patnour Messages postés 43 Statut Membre 2
 
Bonjour Smart,

Voici le rapport demandé.
Merci, patnour.

RogueKiller V8.6.3 [Jul 17 2013] par Tigzy
mail : tigzyRK<at>gmail<dot>com
Remontees : http://www.adlice.com/forum/
Site Web : https://www.luanagames.com/index.fr.html
Blog : http://tigzyrk.blogspot.com/

Systeme d'exploitation : Windows 7 (6.1.7601 Service Pack 1) 32 bits version
Demarrage : Mode normal
Utilisateur : patnour [Droits d'admin]
Mode : Suppression -- Date : 07/28/2013 14:16:52
| ARK || FAK || MBR |

¤¤¤ Processus malicieux : 0 ¤¤¤

¤¤¤ Entrees de registre : 11 ¤¤¤
[HJ POL] HKLM\[...]\System : ConsentPromptBehaviorAdmin (0) -> REMPLACÉ (2)
[HJ POL] HKLM\[...]\System : EnableLUA (0) -> REMPLACÉ (1)
[HJ SMENU] HKCU\[...]\Advanced : Start_ShowMyGames (0) -> REMPLACÉ (1)
[HJ SMENU] HKCU\[...]\Advanced : Start_ShowPrinters (0) -> REMPLACÉ (1)
[HJ DESK] HKCU\[...]\ClassicStartMenu : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REMPLACÉ (0)
[HJ DESK] HKCU\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REMPLACÉ (0)
[HJ DESK] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> REMPLACÉ (0)
[HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REMPLACÉ (0)
[SCREENSVR][SUSP PATH] HKCU\[...]\Desktop : SCRNSAVE.EXE (E:\Users\patnour\ULUMIS~1.SCR [-]) -> REMPLACÉ (E:\Windows\system32\logon.scr)
[EXT RUN][SUSP PATH] HKLM\ON_C:\[...]\Run : tsnp325 (C:\WINDOWS\tsnp325.exe [-]) -> SUPPRIMÉ
[EXT RUN][SUSP PATH] HKLM\ON_C:\[...]\Run : snp325 (C:\WINDOWS\vsnp325.exe [-]) -> SUPPRIMÉ

¤¤¤ Tâches planifiées : 0 ¤¤¤

¤¤¤ Entrées Startup : 0 ¤¤¤

¤¤¤ Navigateurs web : 0 ¤¤¤

¤¤¤ Fichiers / Dossiers particuliers: ¤¤¤

¤¤¤ Driver : [CHARGE] ¤¤¤

¤¤¤ Ruches Externes: ¤¤¤
-> C:\windows\system32\config\SYSTEM
C:\WINDOWS\system32
C:\Documents and Settings\Administrateur\Menu Démarrer\Programmes\Démarrage
-> C:\windows\system32\config\SOFTWARE
C:\WINDOWS\system32
C:\Documents and Settings\Administrateur\Menu Démarrer\Programmes\Démarrage
-> C:\windows\system32\config\SECURITY
C:\WINDOWS\system32
C:\Documents and Settings\Administrateur\Menu Démarrer\Programmes\Démarrage
-> C:\windows\system32\config\SAM
C:\WINDOWS\system32
C:\Documents and Settings\Administrateur\Menu Démarrer\Programmes\Démarrage
-> C:\windows\system32\config\DEFAULT
C:\WINDOWS\system32
C:\Documents and Settings\Administrateur\Menu Démarrer\Programmes\Démarrage
-> C:\Documents and Settings\Administrateur\NTUSER.DAT
C:\WINDOWS\system32
C:\Documents and Settings\Administrateur\Menu Démarrer\Programmes\Démarrage
-> C:\Documents and Settings\All Users\NTUSER.DAT
C:\WINDOWS\system32

-> C:\Documents and Settings\Default User\NTUSER.DAT
C:\WINDOWS\system32
C:\Documents and Settings\Administrateur\Menu Démarrer\Programmes\Démarrage
-> C:\Documents and Settings\LocalService\NTUSER.DAT
C:\WINDOWS\system32
C:\Documents and Settings\LocalService\Menu Démarrer\Programmes\Démarrage
-> C:\Documents and Settings\NeroMediaHomeUser.4\NTUSER.DAT
C:\WINDOWS\system32
C:\Documents and Settings\NeroMediaHomeUser.4\Menu Démarrer\Programmes\Démarrage
-> C:\Documents and Settings\NetworkService\NTUSER.DAT
C:\WINDOWS\system32
C:\Documents and Settings\NetworkService\Menu Démarrer\Programmes\Démarrage
-> H:\windows\system32\config\SYSTEM
C:\Windows\system32
C:\Users\patnour\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
-> H:\windows\system32\config\SOFTWARE
C:\Windows\system32
C:\Users\patnour\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
-> H:\windows\system32\config\SECURITY
C:\Windows\system32
C:\Users\patnour\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
-> H:\windows\system32\config\SAM
C:\Windows\system32
C:\Users\patnour\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
-> H:\windows\system32\config\DEFAULT
C:\Windows\system32
C:\Users\patnour\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
-> H:\Users\Default\NTUSER.DAT
C:\Windows\system32

-> H:\Users\Mcx1\NTUSER.DAT
C:\Windows\system32

-> H:\Users\patnour\NTUSER.DAT
C:\Windows\system32
C:\Users\patnour\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup

¤¤¤ Infection : ¤¤¤

¤¤¤ Fichier HOSTS: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts

127.0.0.1 localhost
127.0.0.1 activate.adobe.com
127.0.0.1 practivate.adobe.com
127.0.0.1 ereg.adobe.com
127.0.0.1 activate.wip3.adobe.com
127.0.0.1 wip3.adobe.com
127.0.0.1 3dns-3.adobe.com
127.0.0.1 3dns-2.adobe.com
127.0.0.1 adobe-dns.adobe.com
127.0.0.1 adobe-dns-2.adobe.com
127.0.0.1 adobe-dns-3.adobe.com
127.0.0.1 ereg.wip3.adobe.com
127.0.0.1 activate-sea.adobe.com
127.0.0.1 pagead2.googlesyndication.com
127.0.0.1 wwis-dubc1-vip60.adobe.com
127.0.0.1 activate-sjc0.adobe.com
127.0.0.1 activate.adobe.com
127.0.0.1 localhost
127.0.0.1 hl2rcv.adobe.com
[...]

¤¤¤ MBR Verif: ¤¤¤

+++++ PhysicalDrive0: ST3250310AS ATA Device +++++
--- User ---
[MBR] 42ac3d8144c83ccec737813e6c62c9df
[BSP] 4fd8d7d211cb3a052e9f42f8ea113a54 : Windows Vista MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 238472 Mo
User = LL1 ... OK!
User = LL2 ... OK!

+++++ PhysicalDrive1: ST3250310AS ATA Device +++++
--- User ---
[MBR] 46f2e09e6f83c60be45f962a6fc13ec3
[BSP] c6320e36cddf1a19165d2195b96db391 : MBR Code unknown
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 102477 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 209873160 | Size: 132512 Mo
2 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 481259205 | Size: 3380 Mo
3 - [XXXXXX] EXTEN-LBA (0x0f) [VISIBLE] Offset (sectors): 488183808 | Size: 103 Mo
User = LL1 ... OK!
User = LL2 ... OK!

Termine : << RKreport[0]_D_07282013_141652.txt >>
RKreport[0]_S_07282013_024525.txt;RKreport[0]_S_07282013_141633.txt
0
patnour Messages postés 43 Statut Membre 2
 
bonsoir Smart,
j'ai toujours le même pb.

avant le redémarrage du pc une fenetre s'est ouverte et il m'a dit que explorer.exe la memoire ne peut etre written

merci encore
patnour
0
patnour Messages postés 43 Statut Membre 2
 
Bonjour Smart,

Désolé de ne pas t'avoir répondu plus tôt mais j'étais en vacances, voici le rapport ci-dessous de combofix.

ComboFix 13-08-21.01 - patnour 22/08/2013 1:44.1.4 - x86
Microsoft Windows 7 Édition Intégrale 6.1.7601.1.1252.33.1036.18.3567.2320 [GMT 2:00]
Lancé depuis: e:\users\patnour\Downloads\ComboFix.exe
AV: Kaspersky Internet Security *Disabled/Updated* {2EAA32A5-1EE1-1B22-95DA-337730C6E984}
FW: Kaspersky Internet Security *Disabled* {1691B380-548E-1A7A-BE85-9A42CE15AEFF}
SP: Kaspersky Internet Security *Disabled/Updated* {95CBD341-38DB-14AC-AF6A-08054B41A339}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\autorun.inf
e:\programdata\boost_interprocess\20130729014324.109999
e:\users\patnour\Documents\Retour SAV KAPORAL SEPT2012.JPG~RF41f02787.TMP
e:\users\patnour\xobglu32.dll
e:\windows\security\Database\tmp.edb
.
.
((((((((((((((((((((((((((((( Fichiers créés du 2013-07-21 au 2013-08-21 ))))))))))))))))))))))))))))))))))))
.
.
2013-08-21 23:59 . 2013-08-21 23:59 -------- d-----w- e:\users\Default\AppData\Local\temp
2013-08-14 03:42 . 2013-08-14 03:42 60872 ----a-w- e:\programdata\Microsoft\Windows Defender\Definition Updates\{14B3B7F7-48C2-4873-99B1-9775EDFA6D18}\offreg.dll
2013-08-14 03:40 . 2013-07-02 06:54 7143960 ----a-w- e:\programdata\Microsoft\Windows Defender\Definition Updates\{14B3B7F7-48C2-4873-99B1-9775EDFA6D18}\mpengine.dll
2013-08-11 23:09 . 2013-08-11 23:09 -------- d-----w- e:\users\Default\AppData\Local\Google
2013-07-29 17:29 . 2009-08-19 21:50 22872 ----a-r- e:\windows\system32\AdobePDFUI.dll
2013-07-29 17:27 . 2013-05-08 01:12 106088 ----a-w- e:\program files\Mozilla Firefox\plugins\nppdf32.dll
2013-07-29 17:26 . 2013-07-29 17:28 -------- d-----w- E:\_AcroTemp
2013-07-29 17:25 . 2013-08-21 23:58 -------- d-----w- e:\programdata\boost_interprocess
2013-07-24 21:50 . 2013-07-24 21:50 -------- d-----w- e:\program files\ZHPFix
2013-07-23 18:46 . 2013-07-27 15:08 512 ----a-w- E:\PhysicalDisk0_MBR.bin
2013-07-23 18:14 . 2013-07-27 15:08 -------- d-----w- e:\program files\ZHPDiag
2013-07-23 18:14 . 2013-07-27 14:52 -------- d-----w- E:\ZHP
.
.
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-08-21 13:52 . 2012-05-09 18:19 692104 ----a-w- e:\windows\system32\FlashPlayerApp.exe
2013-08-21 13:52 . 2011-07-16 23:12 71048 ----a-w- e:\windows\system32\FlashPlayerCPLApp.cpl
2013-06-18 19:02 . 2013-06-18 19:03 94632 ----a-w- e:\windows\system32\WindowsAccessBridge.dll
2013-06-18 19:02 . 2013-06-18 19:03 867240 ----a-w- e:\windows\system32\npDeployJava1.dll
2013-06-18 19:02 . 2013-06-18 19:03 789416 ----a-w- e:\windows\system32\deployJava1.dll
2013-06-16 13:49 . 2013-06-16 13:49 4675072 ----a-w- e:\users\patnour\Ulum Islamiya.scr
2013-06-11 23:43 . 2013-07-11 00:58 1767936 ----a-w- e:\windows\system32\wininet.dll
2013-06-11 23:43 . 2013-07-11 00:58 2877440 ----a-w- e:\windows\system32\jscript9.dll
2013-06-11 23:42 . 2013-07-11 00:58 61440 ----a-w- e:\windows\system32\iesetup.dll
2013-06-11 23:42 . 2013-07-11 00:58 109056 ----a-w- e:\windows\system32\iesysprep.dll
2013-06-11 22:51 . 2013-07-11 00:58 71680 ----a-w- e:\windows\system32\RegisterIEPKEYs.exe
2013-06-07 02:37 . 2013-07-11 00:58 2706432 ----a-w- e:\windows\system32\mshtml.tlb
2013-06-05 03:05 . 2013-07-10 04:33 2347520 ----a-w- e:\windows\system32\win32k.sys
2013-06-04 04:53 . 2013-07-10 04:33 509440 ----a-w- e:\windows\system32\qedit.dll
2009-12-23 20:23 . 2009-12-23 20:22 144123 ----a-w- e:\program files\Uninstal.exe
2009-11-09 20:08 . 2009-07-24 19:50 3672064 ----a-w- e:\program files\freepack.exe
2009-05-17 02:08 . 2009-09-05 16:31 647430 ----a-w- e:\program files\rtmpdump.exe
2009-05-01 06:31 . 2010-04-07 18:41 49664 ----a-w- e:\program files\SetupRes2.dll
2009-05-01 06:31 . 2010-04-07 18:41 675840 ----a-w- e:\program files\SetupRes.dll
2009-05-01 06:31 . 2010-04-07 18:41 1474560 ----a-w- e:\program files\xerces-c_1_6_0.dll
2009-05-01 06:31 . 2010-04-07 18:41 655872 ----a-w- e:\program files\msvcr90.dll
2009-05-01 06:31 . 2010-04-07 18:41 568832 ----a-w- e:\program files\msvcp90.dll
2009-05-01 06:31 . 2010-04-07 18:41 224768 ----a-w- e:\program files\msvcm90.dll
2009-05-01 06:31 . 2010-04-07 18:41 1645320 ----a-w- e:\program files\gdiplus.dll
2009-05-01 06:31 . 2010-04-07 18:41 451944 ----a-w- e:\program files\setup.exe
2009-05-01 06:30 . 2010-04-07 18:41 674664 ----a-w- e:\program files\SetupUi.dll
2009-05-01 06:30 . 2010-04-07 18:41 378128 ----a-w- e:\program files\UPI32.dll
2009-05-01 06:30 . 2010-04-07 18:41 182632 ----a-w- e:\program files\adlmutil.dll
2009-05-01 06:30 . 2010-04-07 18:41 1245032 ----a-w- e:\program files\adlmPIT.dll
2009-05-01 06:30 . 2010-04-07 18:41 672616 ----a-w- e:\program files\SetupAcadUi.dll
2009-05-01 06:30 . 2010-04-07 18:41 6656 ----a-w- e:\program files\PatchMgrRes.dll
2009-05-01 06:30 . 2010-04-07 18:41 61952 ----a-w- e:\program files\PPZlib123.dll
2009-05-01 06:30 . 2010-04-07 18:41 550248 ----a-w- e:\program files\DeployUi.dll
2009-05-01 06:30 . 2010-04-07 18:41 314880 ----a-w- e:\program files\CustomProductUI.dll
2009-05-01 06:30 . 2010-04-07 18:41 1447176 ----a-w- e:\program files\ProjectPointClient.dll
2009-05-01 06:30 . 2010-04-07 18:41 106344 ----a-w- e:\program files\LiteHtml.dll
2009-05-01 06:30 . 2010-04-07 18:41 1048576 ----a-w- e:\program files\PatchMgr.dll
2009-05-01 06:30 . 2010-04-07 18:41 87704 ----a-w- e:\program files\AcSetup.dll
2009-05-01 06:30 . 2010-04-07 18:41 6808 ----a-w- e:\program files\AcSetupRes.dll
2009-05-01 06:30 . 2010-04-07 18:41 161640 ----a-w- e:\program files\AcDelTree.exe
2008-10-22 18:07 . 2010-03-31 20:56 1986301 ----a-w- e:\program files\Adobe CS4 Master Collection_ACTIVATION PATCH by P!mPdOG.ExE
2006-03-14 09:46 . 2009-07-24 19:50 28 ----a-w- e:\program files\wifi.bat
.
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1]
@="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}"
[HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}]
2013-07-28 11:31 222832 ----a-w- e:\users\patnour\AppData\Local\Microsoft\SkyDrive\17.0.2011.0627\SkyDriveShell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2]
@="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}"
[HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}]
2013-07-28 11:31 222832 ----a-w- e:\users\patnour\AppData\Local\Microsoft\SkyDrive\17.0.2011.0627\SkyDriveShell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3]
@="{BBACC218-34EA-4666-9D7A-C78F2274A524}"
[HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}]
2013-07-28 11:31 222832 ----a-w- e:\users\patnour\AppData\Local\Microsoft\SkyDrive\17.0.2011.0627\SkyDriveShell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AcronisSyncError]
@="{934BC6C0-FEC2-4df5-A100-961DE2C8A0ED}"
[HKEY_CLASSES_ROOT\CLSID\{934BC6C0-FEC2-4df5-A100-961DE2C8A0ED}]
2012-08-23 01:48 2616808 ----a-w- e:\program files\Acronis\TrueImageHome\tishell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AcronisSyncInProgress]
@="{00F848DC-B1D4-4892-9C25-CAADC86A215D}"
[HKEY_CLASSES_ROOT\CLSID\{00F848DC-B1D4-4892-9C25-CAADC86A215D}]
2012-08-23 01:48 2616808 ----a-w- e:\program files\Acronis\TrueImageHome\tishell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AcronisSyncOk]
@="{71573297-552E-46fc-BE3D-3DFAF88D47B7}"
[HKEY_CLASSES_ROOT\CLSID\{71573297-552E-46fc-BE3D-3DFAF88D47B7}]
2012-08-23 01:48 2616808 ----a-w- e:\program files\Acronis\TrueImageHome\tishell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-08 23:01 130736 ----a-w- e:\users\patnour\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-08 23:01 130736 ----a-w- e:\users\patnour\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-08 23:01 130736 ----a-w- e:\users\patnour\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveBlacklistedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}]
2013-06-27 14:11 579024 ----a-w- e:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedEditOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}]
2013-06-27 14:11 579024 ----a-w- e:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedViewOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}]
2013-06-27 14:11 579024 ----a-w- e:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}]
2013-06-27 14:11 579024 ----a-w- e:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncingOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}]
2013-06-27 14:11 579024 ----a-w- e:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\HubicPublishedItemOverlayHandler]
@="{7C76B697-27DF-4CFF-9909-863905561298}"
[HKEY_CLASSES_ROOT\CLSID\{7C76B697-27DF-4CFF-9909-863905561298}]
2010-11-05 01:58 297808 ----a-w- e:\windows\System32\mscoree.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\HubicSyncItemOverlayHandler]
@="{9B497753-D273-4A80-9DE8-72248D7FA595}"
[HKEY_CLASSES_ROOT\CLSID\{9B497753-D273-4A80-9DE8-72248D7FA595}]
2010-11-05 01:58 297808 ----a-w- e:\windows\System32\mscoree.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\HubicUnsyncItemOverlayHandler]
@="{D5454A6E-0904-4BA3-9E4A-240A5080259D}"
[HKEY_CLASSES_ROOT\CLSID\{D5454A6E-0904-4BA3-9E4A-240A5080259D}]
2010-11-05 01:58 297808 ----a-w- e:\windows\System32\mscoree.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"FreeMi UPnP Media Server"="e:\program files\FreeMi UPnP Media Server\FreeMi UPnP Media Server.exe" [2011-04-02 93184]
"GoogleDriveSync"="e:\program files\Google\Drive\googledrivesync.exe" [2013-06-27 20097696]
"MediaFire Tray"="e:\users\patnour\AppData\Local\MediaFire Express\mf_systray.exe" [2013-04-04 2349640]
"985C28954ED23E621413B66341EEF9415CE346DC._service_run"="e:\program files\Google\Chrome\Application\chrome.exe" [2013-08-16 829392]
"swg"="e:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-01-13 39408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="e:\program files\Analog Devices\Core\smax4pnp.exe" [2007-07-10 1282048]
"atchk"="e:\program files\Intel\AMT\atchk.exe" [2007-06-07 408344]
"Athan"="e:\program files\Athan\Athan.exe" [2010-03-27 1146880]
"HomePlayer"="e:\program files\HomePlayer\HomePlayer.exe" [2007-11-06 294912]
"AVP"="e:\program files\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe" [2013-02-18 206448]
"tsnp325"="e:\windows\tsnp325.exe" [2006-10-10 270336]
.
e:\users\patnour\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - e:\users\patnour\AppData\Roaming\Dropbox\bin\Dropbox.exe /systemstartup [2013-5-25 27776968]
.
e:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
hubiC.lnk - e:\program files\OVH\hubiC\hubiC.exe [2013-7-22 3544064]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
"EnableLinkedConnections"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux4"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\985C28954ED23E621413B66341EEF9415CE346DC._service_run]
2013-08-16 03:21 829392 ----a-w- e:\program files\Google\Chrome\Application\chrome.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 8.0]
2013-05-08 01:17 642664 ----a-w- e:\program files\Adobe\Acrobat 9.0\Acrobat\acrotray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acronis Scheduler2 Service]
2012-08-23 01:47 403816 ----a-w- e:\program files\Common Files\Acronis\Schedule2\schedhlp.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AcronisTibMounterMonitor]
2012-07-24 14:14 943560 ----a-w- e:\program files\Common Files\Acronis\TibMounter\TibMounterMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Acrobat Speed Launcher]
2013-05-08 12:14 44128 ----a-w- e:\program files\Adobe\Acrobat 9.0\Acrobat\acrobat_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EEventManager]
2008-05-07 14:28 591696 ------w- e:\progra~1\EPSONS~1\EVENTM~1\EEventManager.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Facebook Update]
2011-12-26 15:06 137536 ----atw- e:\users\patnour\AppData\Local\Facebook\Update\FacebookUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Quick Search Box]
2011-05-20 20:16 126976 ----a-w- e:\program files\Google\Quick Search Box\GoogleQuickSearchBox.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OfficeSyncProcess]
2012-01-20 19:03 719672 ----a-w- e:\program files\Microsoft Office\Office14\MSOSYNC.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyDrive]
2013-07-28 11:31 257136 ----a-w- e:\users\patnour\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2010-01-13 09:29 39408 ----a-w- e:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TrueImageMonitor.exe]
2012-08-23 01:47 6048408 ----a-w- e:\program files\Acronis\TrueImageHome\TrueImageMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent]
2011-03-30 18:02 399736 ----a-w- e:\program files\uTorrent\uTorrent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WD Quick View]
2011-12-15 08:25 3998616 ----a-r- e:\program files\Western Digital\WD SmartWare\WDDMStatus.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"swg"="e:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
"LightScribe Control Panel"=e:\program files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
"OfficeSyncProcess"="e:\program files\Microsoft Office\Office14\MSOSYNC.EXE"
"MultiScreen"=e:\program files\MultiScreen\MultiScreen.exe
"uTorrent"="e:\program files\uTorrent\uTorrent.exe"
"985C28954ED23E621413B66341EEF9415CE346DC._service_run"="e:\program files\Google\Chrome\Application\chrome.exe" --type=service
"Sidebar"=e:\program files\Windows Sidebar\sidebar.exe /autoRun
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"PWRISOVM.EXE"=e:\program files\PowerISO\PWRISOVM.EXE
"StartCCC"="e:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
"Acrobat Assistant 8.0"="e:\program files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe"
"Google Updater"="e:\program files\Google\Google Updater\GoogleUpdater.exe" -systray -startup
"Google Quick Search Box"="e:\program files\Google\Quick Search Box\GoogleQuickSearchBox.exe" /autorun
"PaperPort PTD"="e:\program files\ScanSoft\PaperPort\pptd40nt.exe"
"IndexSearch"="e:\program files\ScanSoft\PaperPort\IndexSearch.exe"
"PDF5 Registry Controller"=e:\program files\Nuance\PDF Create 5\RegistryController.exe
"PDFHook"=e:\program files\Nuance\PDF Create 5\pdfcreate5hook.exe
"SSBkgdUpdate"="e:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
"Adobe ARM"="e:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"Adobe_ID0ENQBO"=e:\progra~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE
"Adobe Acrobat Speed Launcher"="e:\program files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe"
"BCSSync"="e:\program files\Microsoft Office\Office14\BCSSync.exe" /DelayServices
"AdobeCS4ServiceManager"="e:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
"snp325"=e:\windows\vsnp325.exe
"FixCamera"=e:\windows\FixCamera.exe
"AdobeAAMUpdater-1.0"="e:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
"AdobeCS6ServiceManager"="e:\program files\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin
"AdobeCS5ServiceManager"="e:\program files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
"SwitchBoard"=e:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
"iTunesHelper"="e:\program files\iTunes\iTunesHelper.exe"
"vmware-tray"="e:\program files\VMware\VMware Workstation\vmware-tray.exe"
"Nuance OmniPage 17-reminder"="e:\program files\Nuance\OmniPage17\Ereg\Ereg.exe" -r "e:\programdata\ScanSoft\OmniPage 17\Ereg\Ereg.ini"
"PPort11reminder"="e:\program files\ScanSoft\PaperPort\Ereg\Ereg.exe" -r "e:\programdata\ScanSoft\PaperPort\11\Config\Ereg\Ereg.ini"
"ATICustomerCare"="e:\program files\ATI\ATICustomerCare\ATICustomerCare.exe"
"Bonus.SSR.FR10"="e:\program files\ABBYY FineReader 10\Bonus.ScreenshotReader.exe" /autorun
"QuickTime Task"="e:\program files\QuickTime\QTTask.exe" -atboottime
"APSDaemon"="e:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
"SunJavaUpdateSched"="e:\program files\Common Files\Java\Java Update\jusched.exe"
.
R2 SkypeUpdate;Skype Updater;e:\program files\Skype\Updater\Updater.exe [2013-06-03 162408]
R3 Adobe Version Cue CS4;Adobe Version Cue CS4;e:\program files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe [2010-04-01 288112]
R3 afcdp;afcdp;e:\windows\system32\DRIVERS\afcdp.sys [2013-01-26 234752]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;e:\windows\system32\drivers\rdpvideominiport.sys [2012-08-23 14848]
R3 RTL8192cu;Realtek RTL8192CU Wireless LAN 802.11n USB 2.0 Network Adapter;e:\windows\system32\DRIVERS\RTL8192cu.sys [2010-08-10 629760]
R3 SwitchBoard;SwitchBoard;e:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
R3 Synth3dVsc;Synth3dVsc;e:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;e:\windows\system32\drivers\tsusbflt.sys [2012-08-23 49664]
R3 tsusbhub;tsusbhub;e:\windows\system32\drivers\tsusbhub.sys [x]
R3 VBoxUSB;VirtualBox USB;e:\windows\system32\Drivers\VBoxUSB.sys [2009-11-10 32016]
R3 VGPU;VGPU;e:\windows\system32\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Service Windows Activation Technologies;e:\windows\system32\Wat\WatAdminSvc.exe [2010-05-21 1343400]
R3 WDC_SAM;WD SCSI Pass Thru driver;e:\windows\system32\DRIVERS\wdcsam.sys [2009-02-13 11520]
R4 ABBYY.Licensing.FineReader.Corporate.10.0;ABBYY FineReader 10 CE Licensing Service;e:\program files\Common Files\ABBYY\FineReader\10.00\Licensing\CE\NetworkLicenseServer.exe [2009-12-18 814344]
R4 afcdpsrv;Acronis Nonstop Backup Service;e:\program files\Common Files\Acronis\CDP\afcdpsrv.exe [2013-01-26 3717112]
R4 sptd;sptd;e:\windows\System32\Drivers\sptd.sys [2010-04-03 691696]
R4 syncagentsrv;Acronis Sync Agent Service;e:\program files\Common Files\Acronis\SyncAgent\syncagentsrv.exe [2012-08-18 7026408]
R4 UNS;Intel(R) Active Management Technology User Notification Service;e:\program files\Intel\AMT\UNS.exe [2007-06-07 2521880]
R4 VMUSBArbService;VMware USB Arbitration Service;e:\program files\Common Files\VMware\USB\vmware-usbarbitrator.exe [2009-10-22 563760]
R4 WDDMService;WDDMService;e:\program files\Western Digital\WD SmartWare\WDDMService.exe [2011-12-15 265624]
R4 WDFMEService;WDFME;e:\program files\Western Digital\WD SmartWare\WDFME.exe [2011-12-15 1591176]
R4 WDRulesService;WDRules;e:\program files\Western Digital\WD SmartWare\WDRulesEngine.exe [2011-12-15 1091992]
R4 wlcrasvc;Windows Live Mesh remote connections service;e:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 51040]
S0 fltsrv;Acronis Storage Filter Management;e:\windows\system32\DRIVERS\fltsrv.sys [2013-01-26 93928]
S0 hotcore3;hc3ServiceName;e:\windows\system32\DRIVERS\hotcore3.sys [2009-03-18 40560]
S0 tib_mounter;Acronis TIB Mounter;e:\windows\system32\DRIVERS\tib_mounter.sys [2013-01-26 689672]
S0 vididr;Acronis Virtual Disk;e:\windows\system32\DRIVERS\vididr.sys [2013-01-26 139336]
S0 vidsflt;Acronis Disk Storage Filter;e:\windows\system32\DRIVERS\vidsflt.sys [2013-01-26 99720]
S1 kl2;kl2;e:\windows\system32\DRIVERS\kl2.sys [2011-03-04 11352]
S1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;e:\windows\system32\DRIVERS\klim6.sys [2011-03-10 23856]
S1 VBoxDrv;VirtualBox Service;e:\windows\system32\DRIVERS\VBoxDrv.sys [2009-11-10 116560]
S1 VBoxUSBMon;VirtualBox USB Monitor Driver;e:\windows\system32\DRIVERS\VBoxUSBMon.sys [2009-11-10 41424]
S2 AMD External Events Utility;AMD External Events Utility;e:\windows\system32\atiesrxx.exe [2009-09-23 172032]
S2 chromoting;Chrome Remote Desktop Service;e:\program files\Google\Chrome Remote Desktop\29.0.1547.32\remoting_host.exe [2013-07-23 10192]
S2 MBAMScheduler;MBAMScheduler;e:\program files\Malwarebytes' Anti-Malware\mbamscheduler.exe [2013-04-04 418376]
S2 MBAMService;MBAMService;e:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2013-04-04 701512]
S2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;e:\program files\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe [2011-07-20 1526592]
S2 vmci;VMware vmci;e:\windows\system32\Drivers\vmci.sys [2009-10-22 70704]
S3 klmouflt;Kaspersky Lab KLMOUFLT;e:\windows\system32\DRIVERS\klmouflt.sys [2009-11-02 19984]
S3 MBAMProtector;MBAMProtector;e:\windows\system32\drivers\mbam.sys [2013-04-04 22856]
S3 SNP325;USB PC Camera (SNPSTD325);e:\windows\system32\DRIVERS\snp325.sys [2007-04-20 10253056]
S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;e:\program files\TuneUp Utilities 2011\TuneUpUtilitiesDriver32.sys [2010-10-07 10064]
S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;e:\windows\system32\DRIVERS\VBoxNetAdp.sys [2009-11-10 95568]
S3 VBoxNetFlt;VBoxNetFlt Service;e:\windows\system32\DRIVERS\VBoxNetFlt.sys [2009-11-10 104016]
.
.
--- Autres Services/Pilotes en mémoire ---
.
*Deregistered* - klbg
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ SSDPSRV upnphost SCardSvr TBS fdrespub AppIDSvc QWAVE wcncsvc SensrSvc Mcx2Svc
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2009-08-20 12:24 451872 ----a-w- e:\program files\Common Files\LightScribe\LSRunOnce.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-08-20 17:08 1177552 ----a-w- e:\program files\Google\Chrome\Application\29.0.1547.57\Installer\chrmstp.exe
.
Contenu du dossier 'Tâches planifiées'
.
2013-08-21 e:\windows\Tasks\Adobe Flash Player Updater.job
- e:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-09 13:52]
.
2012-05-17 e:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2328672431-2337456220-4181837416-1000Core.job
- e:\users\patnour\AppData\Local\Facebook\Update\FacebookUpdate.exe [2011-12-26 15:06]
.
2012-05-17 e:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2328672431-2337456220-4181837416-1000UA.job
- e:\users\patnour\AppData\Local\Facebook\Update\FacebookUpdate.exe [2011-12-26 15:06]
.
2013-08-21 e:\windows\Tasks\Google Software Updater.job
- e:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2010-01-13 23:13]
.
2013-08-21 e:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- e:\program files\Google\Update\GoogleUpdate.exe [2010-01-13 09:31]
.
2013-08-21 e:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- e:\program files\Google\Update\GoogleUpdate.exe [2010-01-13 09:31]
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://google.fr/
uInternet Settings,ProxyOverride = *.local
IE: &Envoyer à OneNote - e:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
IE: Add to Google Photos Screensa&ver - e:\windows\system32\GPhotos.scr/200
IE: Ajouter la cible du lien à un fichier PDF existant - e:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Ajouter à l'Anti-bannière - e:\program files\Kaspersky Lab\Kaspersky Internet Security 2012\ie_banner_deny.htm
IE: Ajouter à un fichier PDF existant - e:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convertir au format Adobe PDF - e:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: Convertir la cible du lien au format Adobe PDF - e:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convertir les liens sélectionnés en fichier Adobe PDF - e:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: E&xporter vers Microsoft Excel - e:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: Télécharger avec Mipony - file://e:\program files\MiPony\Browser\IEContext.htm
LSP: e:\program files\VMware\VMware Workstation\vsocklib.dll
TCP: DhcpNameServer = 192.168.0.254
TCP: Interfaces\{5F6F255B-34B3-43CD-A9AC-23ED784A159C}: NameServer = 8.8.8.8,8.8.4.4
DPF: Microsoft XML Parser for Java - file:///E:/Windows/Java/classes/xmldso.cab
FF - ProfilePath - e:\users\patnour\AppData\Roaming\Mozilla\Firefox\Profiles\hxhpareb.default\
FF - prefs.js: browser.startup.homepage - about:home
FF - ExtSQL: 2013-06-29 12:23; {1280606b-2510-4fe0-97ef-9b5a22eafe30}; e:\users\patnour\AppData\Roaming\Mozilla\Firefox\Profiles\hxhpareb.default\extensions\{1280606b-2510-4fe0-97ef-9b5a22eafe30}.xpi
FF - ExtSQL: 2013-06-30 20:34; {9c491c49-071c-4039-98a5-66d3fe53b1b2}; e:\users\patnour\AppData\Roaming\Mozilla\Firefox\Profiles\hxhpareb.default\extensions\{9c491c49-071c-4039-98a5-66d3fe53b1b2}.xpi
FF - ExtSQL: 2013-06-30 20:34; {19503e42-ca3c-4c27-b1e2-9cdb2170ee34}; e:\users\patnour\AppData\Roaming\Mozilla\Firefox\Profiles\hxhpareb.default\extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34}.xpi
FF - ExtSQL: 2013-06-30 20:34; {1018e4d6-728f-4b20-ad56-37578a4de76b}; e:\users\patnour\AppData\Roaming\Mozilla\Firefox\Profiles\hxhpareb.default\extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b}
FF - ExtSQL: 2013-06-30 20:34; weidunewtab@gmail.com; e:\users\patnour\AppData\Roaming\Mozilla\Firefox\Profiles\hxhpareb.default\extensions\weidunewtab@gmail.com
FF - ExtSQL: 2013-06-30 20:34; vdpure@link64; e:\users\patnour\AppData\Roaming\Mozilla\Firefox\Profiles\hxhpareb.default\extensions\vdpure@link64.xpi
FF - ExtSQL: 2013-06-30 20:34; clickclean@hotcleaner.com; e:\users\patnour\AppData\Roaming\Mozilla\Firefox\Profiles\hxhpareb.default\extensions\clickclean@hotcleaner.com
FF - ExtSQL: 2013-07-25 19:59; tvfreebox@ssofast.com; e:\users\patnour\AppData\Roaming\Mozilla\Firefox\Profiles\hxhpareb.default\extensions\tvfreebox@ssofast.com.xpi
FF - ExtSQL: 2013-07-25 20:47; jid0-ArcprgabbM0n7h9DNfpBtLRqYC8@jetpack; e:\users\patnour\AppData\Roaming\Mozilla\Firefox\Profiles\hxhpareb.default\extensions\jid0-ArcprgabbM0n7h9DNfpBtLRqYC8@jetpack.xpi
FF - ExtSQL: !HIDDEN! 2009-11-11 15:50; {20a82645-c095-46ed-80e3-08825760534b}; e:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - ExtSQL: !HIDDEN! 2010-01-13 10:31; {3112ca9c-de6d-4884-a869-9855de68056c}; e:\programdata\Google\Toolbar for Firefox\{3112ca9c-de6d-4884-a869-9855de68056c}
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
.
.
------- Associations de fichier -------
.
.txt=UltraEdit.txt
.
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@e:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_11_8_800_94_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="e:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_11_8_800_94_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
--------------------- DLLs chargées dans les processus actifs ---------------------
.
- - - - - - - > 'winlogon.exe'(1220)
e:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
.
Heure de fin: 2013-08-22 02:02:51
ComboFix-quarantined-files.txt 2013-08-22 00:02
.
Avant-CF: 21 979 475 968 octets libres
Après-CF: 21 867 802 624 octets libres
.
- - End Of File - - E1196C5134616EBB5D17818902E08BB0
4F02A8D4048A138C450ED7F867EB0144

Merci d'avance.
0