Virus "Gendarmerie Nationale"

Résolu/Fermé
hom2ver Messages postés 78 Date d'inscription vendredi 17 août 2007 Statut Membre Dernière intervention 28 octobre 2013 - 18 oct. 2013 à 02:48
 Utilisateur anonyme - 28 oct. 2013 à 07:54
Hello tout le monde,

donc voilà j'ai attrapé un virus en me balladant sur le net: je me retrouve avec une page qui ne veut pas se fermer.
Il s'agit soit disant de la gendarmerie nationale qui me réclamerait 100 euros pour contenu illegal.
En cherchant sur le net on trouve tout de suite qu'il s'agit d'un virus mais je n'ai pas encore trouvé comment m'en débarasser.

j'ai suivi un post décrivant une solution pour ce problème mais ça n'a pas marché.
mon pc peut toujours redémarrer en mode sans échec
j'ai passé un scan complet de malwarebytes et un pti coup de rogue killer (sans etre en mode sans echec )
..sans succès

Pourriez vous m'aider s'il vous plait?




A voir également:

22 réponses

Utilisateur anonyme
18 oct. 2013 à 02:49
Bonsoir

poste moi ces rapports de RogueKiller et malwaresbytes;merci

@+
0
hom2ver Messages postés 78 Date d'inscription vendredi 17 août 2007 Statut Membre Dernière intervention 28 octobre 2013
18 oct. 2013 à 11:15
Hello Guillaume

je t'ai raté hier soir.
Merci pour ton coup de main.
Tu peux me dire comment faire pour poster les rapports s'il te plait?
0
Utilisateur anonyme
18 oct. 2013 à 18:33
Bonsoir

Tu le mets l'un après l'autre dans une réponse ici

@+
0
hom2ver Messages postés 78 Date d'inscription vendredi 17 août 2007 Statut Membre Dernière intervention 28 octobre 2013
20 oct. 2013 à 14:20
ah tout simplement! d'accord.
désolé d'avoir tardé à repasser, j'avais trop de boulot.

je refais des scans avec malewarebytes, OTL, Roguekiller et je poste tout ça.
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
Utilisateur anonyme
20 oct. 2013 à 14:22
Bonjour

Ces analyses ne sont pas à relancer;mais seulement les rapports à poster

@+
0
hom2ver Messages postés 78 Date d'inscription vendredi 17 août 2007 Statut Membre Dernière intervention 28 octobre 2013
Modifié par hom2ver le 20/10/2013 à 15:20
Bonjour Guillaume5188,

ok voilà pour roguekiller:

Systeme d'exploitation : Windows XP (5.1.2600 Service Pack 3) 32 bits version
Demarrage : Mode normal
Utilisateur : User [Droits d'admin]
Mode : Suppression -- Date : 10/18/2013 11:16:06
| ARK || FAK || MBR |

¤¤¤ Processus malicieux : 0 ¤¤¤

¤¤¤ Entrees de registre : 2 ¤¤¤
[HJ SMENU][PUM] HKCU\[...]\Advanced : Start_ShowRecentDocs (0) -> REMPLACÉ (1)
[HJ SMENU][PUM] HKCU\[...]\Advanced : Start_ShowPrinters (0) -> REMPLACÉ (1)

¤¤¤ Tâches planifiées : 0 ¤¤¤

¤¤¤ Entrées Startup : 0 ¤¤¤

¤¤¤ Navigateurs web : 0 ¤¤¤

¤¤¤ Fichiers / Dossiers particuliers: ¤¤¤

¤¤¤ Driver : [CHARGE] ¤¤¤
[Inline] IAT @explorer.exe (DeleteDC) : GDI32.dll -> HOOKED (C:\WINDOWS\system32\guard32.dll @ 0x10028D10)
[Inline] IAT @explorer.exe (CreateProcessW) : KERNEL32.dll -> HOOKED (C:\WINDOWS\system32\guard32.dll @ 0x10025070)
[Inline] EAT @explorer.exe (LdrLoadDll) : ntdll.dll -> HOOKED (C:\WINDOWS\system32\guard32.dll @ 0x10027F40)
[Inline] EAT @explorer.exe (LdrUnloadDll) : ntdll.dll -> HOOKED (C:\WINDOWS\system32\guard32.dll @ 0x1001D240)
[Inline] EAT @explorer.exe (NtClose) : ntdll.dll -> HOOKED (C:\WINDOWS\system32\guard32.dll @ 0x1001D120)
[Inline] EAT @explorer.exe (NtReplyWaitReceivePort) : ntdll.dll -> HOOKED (C:\WINDOWS\system32\guard32.dll @ 0x1002BCD0)
[Inline] EAT @explorer.exe (NtReplyWaitReceivePortEx) : ntdll.dll -> HOOKED (C:\WINDOWS\system32\guard32.dll @ 0x1002B9B0)
[Inline] EAT @explorer.exe (ZwClose) : ntdll.dll -> HOOKED (C:\WINDOWS\system32\guard32.dll @ 0x1001D120)
[Inline] EAT @explorer.exe (ZwReplyWaitReceivePort) : ntdll.dll -> HOOKED (C:\WINDOWS\system32\guard32.dll @ 0x1002BCD0)
[Inline] EAT @explorer.exe (ZwReplyWaitReceivePortEx) : ntdll.dll -> HOOKED (C:\WINDOWS\system32\guard32.dll @ 0x1002B9B0)
[Inline] EAT @explorer.exe (CreateProcessA) : kernel32.dll -> HOOKED (C:\WINDOWS\system32\guard32.dll @ 0x10025C00)
[Inline] EAT @explorer.exe (CreateProcessW) : kernel32.dll -> HOOKED (C:\WINDOWS\system32\guard32.dll @ 0x10025070)
[Inline] EAT @explorer.exe (CreateProcessAsUserA) : ADVAPI32.dll -> HOOKED (C:\WINDOWS\system32\guard32.dll @ 0x100244D0)
[Inline] EAT @explorer.exe (CreateProcessAsUserW) : ADVAPI32.dll -> HOOKED (C:\WINDOWS\system32\guard32.dll @ 0x10023BA0)
[Inline] EAT @explorer.exe (CreateDCA) : GDI32.dll -> HOOKED (C:\WINDOWS\system32\guard32.dll @ 0x10029E10)
[Inline] EAT @explorer.exe (CreateDCW) : GDI32.dll -> HOOKED (C:\WINDOWS\system32\guard32.dll @ 0x10029D10)
[Inline] EAT @explorer.exe (DeleteDC) : GDI32.dll -> HOOKED (C:\WINDOWS\system32\guard32.dll @ 0x10028D10)
[Inline] EAT @explorer.exe (GetPixel) : GDI32.dll -> HOOKED (C:\WINDOWS\system32\guard32.dll @ 0x10028AE0)
[Inline] EAT @explorer.exe (FilterConnectCommunicationPort) : fltlib.dll -> HOOKED (C:\WINDOWS\system32\guard32.dll @ 0x1001D190)
[Inline] EAT @explorer.exe (FilterSendMessage) : fltlib.dll -> HOOKED (C:\WINDOWS\system32\guard32.dll @ 0x1001D150)
[Inline] EAT @firefox.exe (LdrUnloadDll) : ntdll.dll -> HOOKED (C:\WINDOWS\system32\guard32.dll @ 0x1001D240)
[Inline] EAT @firefox.exe (NtClose) : ntdll.dll -> HOOKED (C:\WINDOWS\system32\guard32.dll @ 0x1001D120)
[Inline] EAT @firefox.exe (NtReplyWaitReceivePort) : ntdll.dll -> HOOKED (C:\WINDOWS\system32\guard32.dll @ 0x1002BCD0)
[Inline] EAT @firefox.exe (NtReplyWaitReceivePortEx) : ntdll.dll -> HOOKED (C:\WINDOWS\system32\guard32.dll @ 0x1002B9B0)
[Inline] EAT @firefox.exe (ZwClose) : ntdll.dll -> HOOKED (C:\WINDOWS\system32\guard32.dll @ 0x1001D120)
[Inline] EAT @firefox.exe (ZwReplyWaitReceivePort) : ntdll.dll -> HOOKED (C:\WINDOWS\system32\guard32.dll @ 0x1002BCD0)
[Inline] EAT @firefox.exe (ZwReplyWaitReceivePortEx) : ntdll.dll -> HOOKED (C:\WINDOWS\system32\guard32.dll @ 0x1002B9B0)
[Inline] EAT @firefox.exe (CreateProcessA) : kernel32.dll -> HOOKED (C:\WINDOWS\system32\guard32.dll @ 0x10025C00)
[Inline] EAT @firefox.exe (CreateProcessW) : kernel32.dll -> HOOKED (C:\WINDOWS\system32\guard32.dll @ 0x10025070)
[Inline] EAT @firefox.exe (CreateDCA) : GDI32.dll -> HOOKED (C:\WINDOWS\system32\guard32.dll @ 0x10029E10)
[Inline] EAT @firefox.exe (CreateDCW) : GDI32.dll -> HOOKED (C:\WINDOWS\system32\guard32.dll @ 0x10029D10)
[Inline] EAT @firefox.exe (DeleteDC) : GDI32.dll -> HOOKED (C:\WINDOWS\system32\guard32.dll @ 0x10028D10)
[Inline] EAT @firefox.exe (GetPixel) : GDI32.dll -> HOOKED (C:\WINDOWS\system32\guard32.dll @ 0x10028AE0)
[Inline] EAT @firefox.exe (CreateProcessAsUserA) : ADVAPI32.dll -> HOOKED (C:\WINDOWS\system32\guard32.dll @ 0x100244D0)
[Inline] EAT @firefox.exe (CreateProcessAsUserW) : ADVAPI32.dll -> HOOKED (C:\WINDOWS\system32\guard32.dll @ 0x10023BA0)
[Inline] EAT @firefox.exe (FilterConnectCommunicationPort) : fltlib.dll -> HOOKED (C:\WINDOWS\system32\guard32.dll @ 0x1001D190)
[Inline] EAT @firefox.exe (FilterSendMessage) : fltlib.dll -> HOOKED (C:\WINDOWS\system32\guard32.dll @ 0x1001D150)

¤¤¤ Ruches Externes: ¤¤¤

¤¤¤ Infection : ¤¤¤

¤¤¤ Fichier HOSTS: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts


127.0.0.1 localhost
127.0.0.1 3dns.adobe.com 3dns-1.adobe.com 3dns-2.adobe.com 3dns-3.adobe.com 3dns-4.adobe.com activate.adobe.com activate-sea.adobe.com activate-sjc0.adobe.com activate.wip.adobe.com
127.0.0.1 activate.wip1.adobe.com activate.wip2.adobe.com activate.wip3.adobe.com activate.wip4.adobe.com adobe-dns.adobe.com adobe-dns-1.adobe.com adobe-dns-2.adobe.com adobe-dns-3.adobe.com adobe-dns-4.adobe.com
127.0.0.1 adobeereg.com practivate.adobe practivate.adobe.com practivate.adobe.newoa practivate.adobe.ntp practivate.adobe.ipp ereg.adobe.com ereg.wip.adobe.com ereg.wip1.adobe.com
127.0.0.1 ereg.wip2.adobe.com ereg.wip3.adobe.com ereg.wip4.adobe.com hl2rcv.adobe.com wip.adobe.com wip1.adobe.com wip2.adobe.com wip3.adobe.com wip4.adobe.com
127.0.0.1 www.adobeereg.com wwis-dubc1-vip60.adobe.com www.wip.adobe.com www.wip1.adobe.com
127.0.0.1 www.wip2.adobe.com www.wip3.adobe.com www.wip4.adobe.com wwis-dubc1-vip60.adobe.com crl.verisign.net CRL.VERISIGN.NET ood.opsource.net


¤¤¤ MBR Verif: ¤¤¤

+++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ IDE) (Lecteurs de disque standard) - SAMSUNG SP2504C SCSI Disk Device +++++
--- User ---
[MBR] 7148ac1143ca0d68166ea330c9c7a1f2
[BSP] 9d23fcdeabd76be2351d6fc7982200af : Windows XP MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 100000 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 204802048 | Size: 138472 Mo
User = LL1 ... OK!
Error reading LL2 MBR!

Termine : << RKreport[0]_D_10182013_111606.txt >>
RKreport[0]_D_10172013_034042.txt;RKreport[0]_S_10172013_031454.txt;RKreport[0]_S_10182013_111221.txt
0
hom2ver Messages postés 78 Date d'inscription vendredi 17 août 2007 Statut Membre Dernière intervention 28 octobre 2013
20 oct. 2013 à 14:29
OTL:

OTL logfile created on: 17/10/2013 12:06:10 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\User\Mes documents\Téléchargements
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 0000040C | Country: France | Language: FRA | Date Format: dd/MM/yyyy

3,25 Gb Total Physical Memory | 2,29 Gb Available Physical Memory | 70,54% Memory free
5,09 Gb Paging File | 4,27 Gb Available in Paging File | 84,00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 97,66 Gb Total Space | 0,65 Gb Free Space | 0,67% Space Free | Partition Type: NTFS
Drive H: | 135,23 Gb Total Space | 48,59 Gb Free Space | 35,93% Space Free | Partition Type: NTFS
Drive K: | 931,40 Gb Total Space | 394,48 Gb Free Space | 42,35% Space Free | Partition Type: FAT32

Computer Name: USER-5824E3CCA0 | User Name: User | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

[color=#E56717]========== Processes (SafeList) ==========[/color]

PRC - [2013/10/17 12:04:37 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\User\Mes documents\Téléchargements\OTL.exe
PRC - [2013/10/09 19:33:16 | 002,104,968 | ---- | M] () -- C:\Program Files\COMODO\Dragon\dragon_updater.exe
PRC - [2013/10/01 21:15:16 | 000,274,840 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2013/05/16 16:44:05 | 001,012,000 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe
PRC - [2013/05/16 16:38:39 | 001,826,592 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
PRC - [2013/04/04 14:50:32 | 000,701,512 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2013/04/04 14:50:32 | 000,532,040 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2013/04/04 14:50:32 | 000,418,376 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
PRC - [2012/11/08 00:37:38 | 001,990,464 | ---- | M] (COMODO) -- C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
PRC - [2012/11/08 00:37:12 | 006,756,048 | ---- | M] (COMODO) -- C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
PRC - [2012/10/29 09:14:14 | 007,183,232 | ---- | M] (Wacom Technology, Corp.) -- C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe
PRC - [2012/10/29 09:14:14 | 004,053,888 | ---- | M] (Wacom Technology, Corp.) -- C:\Program Files\Tablet\Wacom\Wacom_TouchUser.exe
PRC - [2012/10/29 09:14:14 | 001,632,128 | ---- | M] (Wacom Technology, Corp.) -- C:\Program Files\Tablet\Wacom\Wacom_TabletUser.exe
PRC - [2012/10/29 09:14:14 | 000,520,576 | ---- | M] (Wacom Technology, Corp.) -- C:\Program Files\Tablet\Wacom\WTabletServicePro.exe
PRC - [2012/10/08 17:15:50 | 000,039,808 | ---- | M] (Wacom Technology) -- C:\Program Files\Tablet\Wacom\WacomHost.exe
PRC - [2010/03/10 15:26:48 | 000,189,728 | ---- | M] (Protexis Inc.) -- c:\Program Files\Fichiers communs\Protexis\License Service\PsiService_2.exe
PRC - [2009/10/07 10:16:50 | 000,472,280 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
PRC - [2009/10/07 10:15:42 | 001,461,080 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
PRC - [2009/07/23 18:23:56 | 000,178,720 | ---- | M] () -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
PRC - [2009/07/23 18:23:54 | 000,387,616 | ---- | M] () -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
PRC - [2008/04/13 18:34:04 | 001,037,824 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007/04/12 07:00:00 | 000,182,272 | ---- | M] (SEIKO EPSON CORPORATION) -- C:\WINDOWS\system32\spool\drivers\w32x86\3\E_FATICDE.EXE


[color=#E56717]========== Modules (No Company Name) ==========[/color]

MOD - [2013/10/09 19:33:16 | 002,104,968 | ---- | M] () -- C:\Program Files\COMODO\Dragon\dragon_updater.exe
MOD - [2013/10/01 21:15:13 | 003,279,768 | ---- | M] () -- C:\Program Files\Mozilla Firefox\mozjs.dll
MOD - [2012/10/29 09:14:16 | 000,963,456 | ---- | M] () -- C:\Program Files\Tablet\Wacom\libxml2.dll
MOD - [2009/07/23 18:23:56 | 000,178,720 | ---- | M] () -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
MOD - [2009/07/23 18:23:54 | 000,387,616 | ---- | M] () -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
MOD - [2009/07/23 18:23:48 | 000,436,768 | ---- | M] () -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\SpecialCase.dll
MOD - [2009/07/23 18:23:08 | 000,068,128 | ---- | M] () -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nv_common.dll


[color=#E56717]========== Services (SafeList) ==========[/color]

SRV - File not found [On_Demand | Stopped] -- %SystemRoot%\System32\appmgmts.dll -- (AppMgmt)
SRV - [2013/10/09 19:33:16 | 002,104,968 | ---- | M] () [Auto | Running] -- C:\Program Files\COMODO\Dragon\dragon_updater.exe -- (DragonUpdater)
SRV - [2013/10/01 21:15:14 | 000,118,680 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2013/06/21 10:13:12 | 000,162,408 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2013/05/16 16:38:39 | 001,826,592 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe -- (nvUpdatusService)
SRV - [2013/04/04 14:50:32 | 000,701,512 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2013/04/04 14:50:32 | 000,418,376 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)
SRV - [2013/01/20 17:29:06 | 000,654,848 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] -- C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2012/11/08 00:37:38 | 001,990,464 | ---- | M] (COMODO) [Auto | Running] -- C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe -- (cmdAgent)
SRV - [2012/10/29 09:14:14 | 000,520,576 | ---- | M] (Wacom Technology, Corp.) [Auto | Running] -- C:\Program Files\Tablet\Wacom\WTabletServicePro.exe -- (WTabletServicePro)
SRV - [2010/03/10 15:26:48 | 000,189,728 | ---- | M] (Protexis Inc.) [Auto | Running] -- c:\Program Files\Fichiers communs\Protexis\License Service\PsiService_2.exe -- (PSI_SVC_2)
SRV - [2009/10/07 10:21:14 | 000,020,680 | ---- | M] (ESET) [On_Demand | Stopped] -- C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe -- (EhttpSrv)
SRV - [2009/10/07 10:16:50 | 000,472,280 | ---- | M] (ESET) [Auto | Running] -- C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe -- (ekrn)
SRV - [2009/07/23 18:23:56 | 000,178,720 | ---- | M] () [Auto | Running] -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe -- (nSvcIp)
SRV - [2009/07/23 18:23:54 | 000,387,616 | ---- | M] () [Auto | Running] -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe -- (ForceWare Intelligent Application Manager (IAM)
SRV - [2006/10/26 20:49:34 | 000,441,136 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE12\ODSERV.EXE -- (odserv)
SRV - [2006/10/26 15:03:08 | 000,145,184 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Fichiers communs\Microsoft Shared\Source Engine\OSE.EXE -- (ose)


[color=#E56717]========== Driver Services (SafeList) ==========[/color]

DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt)
DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
DRV - [2013/04/04 14:50:32 | 000,022,856 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2013/02/25 07:27:48 | 000,128,672 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nvhda32.sys -- (NVHDA)
DRV - [2012/12/14 17:15:23 | 000,004,096 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Documents and Settings\User\Local Settings\Temp\ASFWHide -- (ASFWHide)
DRV - [2012/11/08 00:38:18 | 000,099,080 | ---- | M] (COMODO) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\inspect.sys -- (Inspect)
DRV - [2012/11/08 00:38:18 | 000,032,640 | ---- | M] (COMODO) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\cmdhlp.sys -- (cmdHlp)
DRV - [2012/11/08 00:38:16 | 000,497,952 | ---- | M] (COMODO) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\cmdGuard.sys -- (cmdGuard)
DRV - [2012/10/12 10:54:52 | 000,013,728 | ---- | M] (Wacom Technology) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\wacomrouterfilter.sys -- (wacomrouterfilter)
DRV - [2012/10/12 10:20:38 | 000,069,024 | ---- | M] (Wacom Technology) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\wachidrouter.sys -- (WacHidRouter)
DRV - [2012/10/12 10:20:38 | 000,011,680 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hidkmdf.sys -- (hidkmdf)
DRV - [2012/06/19 17:54:20 | 006,141,584 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService)
DRV - [2012/03/30 11:22:14 | 000,100,736 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Stopped] -- C:\WINDOWS\System32\drivers\nvlegacy.sys -- (nvlegacy)
DRV - [2012/03/30 11:22:14 | 000,013,616 | ---- | M] (Marvell Semiconductor Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\mvxxmm.sys -- (mvxxmm)
DRV - [2012/03/30 11:22:14 | 000,013,616 | ---- | M] (Marvell Semiconductor Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\mv61xxmm.sys -- (mv61xxmm)
DRV - [2012/03/30 11:22:14 | 000,005,632 | ---- | M] (Marvell Semiconductor Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\mv64xxmm.sys -- (mv64xxmm)
DRV - [2011/03/18 18:08:54 | 000,025,240 | ---- | M] (Almico Software) [Kernel | Boot | Running] -- C:\WINDOWS\system32\speedfan.sys -- (speedfan)
DRV - [2009/11/18 08:17:00 | 001,395,800 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Monfilt.sys -- (Monfilt)
DRV - [2009/11/18 08:16:00 | 001,691,480 | ---- | M] (Creative) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Ambfilt.sys -- (Ambfilt)
DRV - [2009/10/07 10:18:36 | 000,035,168 | ---- | M] () [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\epfwtdir.sys -- (epfwtdir)
DRV - [2009/10/07 10:12:22 | 000,054,184 | ---- | M] (ESET) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\easdrv.sys -- (easdrv)
DRV - [2009/10/07 10:11:10 | 000,040,824 | ---- | M] (ESET) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\eamon.sys -- (eamon)
DRV - [2009/07/01 12:53:34 | 000,013,824 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nvnetbus.sys -- (nvnetbus)
DRV - [2009/07/01 12:53:30 | 000,066,688 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\NVENETFD.sys -- (NVENETFD)
DRV - [2009/06/30 18:31:00 | 000,164,896 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\nvgts.sys -- (nvgts)
DRV - [2006/07/01 16:43:02 | 000,041,984 | ---- | M] (Advanced Micro Devices) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\AmdK8.sys -- (AmdK8)
DRV - [2004/08/13 12:56:20 | 000,005,810 | ---- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ASACPI.sys -- (MTsensor)
DRV - [2002/04/17 21:27:02 | 000,011,264 | ---- | M] (VOB Computersysteme GmbH) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\asapi.sys -- (Asapi)
DRV - [1996/04/03 21:33:26 | 000,005,248 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\system32\giveio.sys -- (giveio)


[color=#E56717]========== Standard Registry (SafeList) ==========[/color]


[color=#E56717]========== Internet Explorer ==========[/color]

IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = https://www.bing.com/?scope=web&mkt=fr-FR{searchTerms}&src={referrer:source?}


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-1547161642-1343024091-1801674531-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/?fr=fp-comodo
IE - HKU\S-1-5-21-1547161642-1343024091-1801674531-1004\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - SOFTWARE\Classes\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC}\InprocServer32 File not found
IE - HKU\S-1-5-21-1547161642-1343024091-1801674531-1004\..\URLSearchHook: {EEE6C35D-6118-11DC-9C72-001320C79847} - SOFTWARE\Classes\CLSID\{EEE6C35D-6118-11DC-9C72-001320C79847}\InprocServer32 File not found
IE - HKU\S-1-5-21-1547161642-1343024091-1801674531-1004\..\SearchScopes,DefaultScope = {8EEAC88A-079B-4b2c-80C1-7836F79EB40A}
IE - HKU\S-1-5-21-1547161642-1343024091-1801674531-1004\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = https://www.bing.com/?scope=web&mkt=fr-FR{searchTerms}&src=IE-SearchBox&Form=IE8SRC
IE - HKU\S-1-5-21-1547161642-1343024091-1801674531-1004\..\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}: "URL" = http://www.search.ask.com/?l=dis{searchTerms}&locale=&apn_ptnrs=^NY&apn_dtid=^YYYYYY^YY^FR&apn_uid=352DF5A5-2661-4F6A-B581-26F7D3FE1ABC&apn_sauid=79E4AAFB-9B03-48F5-9404-D9CFC1ACE70C&
IE - HKU\S-1-5-21-1547161642-1343024091-1801674531-1004\..\SearchScopes\{8EEAC88A-079B-4b2c-80C1-7836F79EB40A}: "URL" = https://fr.search.yahoo.com/web{searchTerms}&fr=chr-comodo
IE - HKU\S-1-5-21-1547161642-1343024091-1801674531-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1547161642-1343024091-1801674531-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local


[color=#E56717]========== FireFox ==========[/color]

FF - prefs.js..browser.search.defaultenginename: ""
FF - prefs.js..browser.startup.homepage: "https://www.tumblr.com/privacy/consent?redirect=http%3A%2F%2Fkushandwizdom.tumblr.com%2F"
FF - prefs.js..extensions.enabledAddons: %7B4DC70064-89E2-4a55-8FC6-E8CDEAE3618C%7D:0.7.7
FF - prefs.js..extensions.enabledAddons: %7B7067a92c-1db4-4e5e-869c-25f841287f8b%7D:0.2.4
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:24.0
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_9_900_117.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.7: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\@wacom.com/wtPlugin,version=2.1.0.2: C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll (Wacom)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Documents and Settings\User\Local Settings\Application Data\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Documents and Settings\User\Local Settings\Application Data\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKCU\Software\MozillaPlugins\wacom.com/WacomTabletPlugin: C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll (Wacom)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 24.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 24.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins

[2012/12/13 01:10:26 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\User\Application Data\Mozilla\Extensions
[2013/10/09 21:24:07 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\64xmy4z0.default\extensions
[2013/01/29 13:37:18 | 000,156,017 | ---- | M] () (No name found) -- C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\64xmy4z0.default\extensions\jid0-qmXajXkelvbDoOK2wfWokCbWJ2o@jetpack.xpi
[2012/12/17 14:21:30 | 000,013,345 | ---- | M] () (No name found) -- C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\64xmy4z0.default\extensions\{4DC70064-89E2-4a55-8FC6-E8CDEAE3618C}.xpi
[2013/01/29 13:26:50 | 000,031,339 | ---- | M] () (No name found) -- C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\64xmy4z0.default\extensions\{7067a92c-1db4-4e5e-869c-25f841287f8b}.xpi
[2013/10/09 21:24:06 | 000,915,554 | ---- | M] () (No name found) -- C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\64xmy4z0.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2011/11/17 20:25:44 | 000,002,333 | ---- | M] () -- C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\64xmy4z0.default\searchplugins\askcom.xml
[2013/10/01 21:14:49 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\browser\extensions
[2013/10/01 21:15:17 | 000,000,000 | ---D | M] (Default) -- C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

O1 HOSTS File: ([2011/01/27 15:00:57 | 000,001,211 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 3dns.adobe.com 3dns-1.adobe.com 3dns-2.adobe.com 3dns-3.adobe.com 3dns-4.adobe.com activate.adobe.com activate-sea.adobe.com activate-sjc0.adobe.com activate.wip.adobe.com
O1 - Hosts: 127.0.0.1 activate.wip1.adobe.com activate.wip2.adobe.com activate.wip3.adobe.com activate.wip4.adobe.com adobe-dns.adobe.com adobe-dns-1.adobe.com adobe-dns-2.adobe.com adobe-dns-3.adobe.com adobe-dns-4.adobe.com
O1 - Hosts: 127.0.0.1 adobeereg.com practivate.adobe practivate.adobe.com practivate.adobe.newoa practivate.adobe.ntp practivate.adobe.ipp ereg.adobe.com ereg.wip.adobe.com ereg.wip1.adobe.com
O1 - Hosts: 127.0.0.1 ereg.wip2.adobe.com ereg.wip3.adobe.com ereg.wip4.adobe.com hl2rcv.adobe.com wip.adobe.com wip1.adobe.com wip2.adobe.com wip3.adobe.com wip4.adobe.com
O1 - Hosts: 127.0.0.1 www.adobeereg.com wwis-dubc1-vip60.adobe.com www.wip.adobe.com www.wip1.adobe.com
O1 - Hosts: 127.0.0.1 www.wip2.adobe.com www.wip3.adobe.com www.wip4.adobe.com wwis-dubc1-vip60.adobe.com crl.verisign.net CRL.VERISIGN.NET ood.opsource.net
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll File not found
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll File not found
O3 - HKLM\..\Toolbar: (SweetPacks Toolbar for Internet Explorer) - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll File not found
O3 - HKU\S-1-5-21-1547161642-1343024091-1801674531-1004\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll File not found
O3 - HKU\S-1-5-21-1547161642-1343024091-1801674531-1004\..\Toolbar\WebBrowser: (SweetPacks Toolbar for Internet Explorer) - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll File not found
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Adobe ARM] C:\Program Files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [COMODO Internet Security] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO)
O4 - HKLM..\Run: [egui] C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe (ESET)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\nvmctray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [Nvtmru] C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nview\nwiz.exe ()
O4 - HKU\S-1-5-21-1547161642-1343024091-1801674531-1004..\Run: [EPSON Stylus DX7400 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICDE.EXE (SEIKO EPSON CORPORATION)
O4 - HKU\S-1-5-21-1547161642-1343024091-1801674531-1004..\Run: [Facebook Update] C:\Documents and Settings\User\Local Settings\Application Data\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1547161642-1343024091-1801674531-1004\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1547161642-1343024091-1801674531-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1547161642-1343024091-1801674531-1008\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1547161642-1343024091-1801674531-1008\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 212.27.40.241 212.27.40.240
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{CB33BEB0-C63D-444A-888A-3222E59B3C00}: DhcpNameServer = 212.27.40.241 212.27.40.240
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Fichiers communs\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Fichiers communs\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (C:\WINDOWS\system32\guard32.dll) - C:\WINDOWS\system32\guard32.dll (COMODO)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop Components:0 (Ma page d'accueil) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\User\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\User\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2012/12/12 18:49:10 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - %SystemRoot%\System32\appmgmts.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found


Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.XVID - C:\WINDOWS\System32\xvidvfw.dll ()

ActiveX: {10072CEC-8CC1-11D1-986E-00A0C955B42F} - Rendu VML (Vector Graphics Rendering)
ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} - NetShow
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Lecteur Windows Media Microsoft 6.4
ActiveX: {283807B5-2C60-11D0-A31D-00AA00B92C03} - DirectAnimation
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {36f8ec70-c29a-11d1-b5c7-0000f8051515} - Liaison de données Dynamic HTML pour Java
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {3bf42070-b3b1-11d1-b5c5-0000f8051515} - Uniscribe
ActiveX: {3C3901C5-3455-3E0A-A214-0B093A5070A6} - .NET Framework
ActiveX: {4278c270-a269-11d1-b5bf-0000f8051515} - Création avancée
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install
ActiveX: {44BBA842-CC51-11CF-AAFA-00AA00B6015B} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT
ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} - DirectShow
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f216970-c90c-11d1-b5c7-0000f8051515} - Classes Java DirectAnimation
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.7
ActiveX: {5945c046-1e7d-11d1-bc44-00c04fd912be} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser
ActiveX: {5A8D6EE0-3E18-11D0-821E-444553540000} - ICW
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {73fa19d0-2d75-11d2-995d-00c04f98bbc9} - Web Folders
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\WINDOWS\system32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - DOTNETFRAMEWORKS
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {ACC563BC-4266-43f0-B6ED-9D38C4202C7E} -
ActiveX: {C3C986D6-06B1-43BF-90DD-BE30756C00DE} - RevokedRootsUpdate
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {CC2A9BA0-3BDD-11D0-821E-444553540000} - Planificateur de tâches
ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1
ActiveX: {D27CDB6E-AE6D-11cf-96B8-444553540000} - Reg Error: Value error.
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: <{12d0ed0d-0ee0-4f90-8827-78cefb8f4988} - C:\WINDOWS\system32\ieudinit.exe
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\WINDOWS\inf\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\WINDOWS\system32\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS - RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP
ActiveX: >{881dd1c5-3dcf-431b-b061-f3f88e8be88a} - %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE

[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]

[2013/10/17 03:41:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User\Application Data\Malwarebytes
[2013/10/17 03:41:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Malwarebytes' Anti-Malware
[2013/10/17 03:41:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2013/10/17 03:41:33 | 000,022,856 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2013/10/17 03:41:32 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2013/10/17 03:12:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User\Bureau\RK_Quarantine
[2013/10/10 19:15:48 | 000,048,392 | ---- | C] (COMODO CA Limited) -- C:\WINDOWS\System32\certsentry.dll
[2013/10/01 21:14:49 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[2013/09/17 13:19:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User\Bureau\yayas
[10 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]

[2013/10/17 12:05:53 | 000,514,448 | ---- | M] () -- C:\WINDOWS\System32\perfh00C.dat
[2013/10/17 12:05:53 | 000,445,540 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2013/10/17 12:05:53 | 000,085,040 | ---- | M] () -- C:\WINDOWS\System32\perfc00C.dat
[2013/10/17 12:05:52 | 000,070,514 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2013/10/17 12:02:45 | 000,004,310 | ---- | M] () -- C:\WINDOWS\System32\nvAppTimestamps
[2013/10/17 12:01:23 | 000,001,048 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2013/10/17 12:01:14 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2013/10/17 03:46:02 | 000,000,994 | ---- | M] () -- C:\WINDOWS\tasks\FacebookUpdateTaskUserS-1-5-21-1547161642-1343024091-1801674531-1004UA.job
[2013/10/17 03:41:44 | 000,000,786 | ---- | M] () -- C:\Documents and Settings\All Users\Bureau\Malwarebytes Anti-Malware.lnk
[2013/10/17 03:41:00 | 000,001,052 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2013/10/16 18:46:00 | 000,000,972 | ---- | M] () -- C:\WINDOWS\tasks\FacebookUpdateTaskUserS-1-5-21-1547161642-1343024091-1801674531-1004Core.job
[2013/10/16 09:52:44 | 000,692,616 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerApp.exe
[2013/10/16 09:52:44 | 000,071,048 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2013/10/14 11:37:49 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2013/10/14 02:48:29 | 000,099,328 | ---- | M] () -- C:\Documents and Settings\User\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013/10/10 19:15:48 | 000,048,392 | ---- | M] (COMODO CA Limited) -- C:\WINDOWS\System32\certsentry.dll
[2013/10/05 12:25:32 | 000,000,532 | ---- | M] () -- C:\Documents and Settings\User\Bureau\Raccourci vers SUPER NOVA TEAM.lnk
[2013/09/20 01:17:47 | 000,002,265 | ---- | M] () -- C:\Documents and Settings\All Users\Bureau\Skype.lnk
[2013/09/18 14:10:02 | 000,000,416 | ---- | M] () -- C:\Documents and Settings\User\Bureau\Raccourci vers connaissances videos.lnk
[10 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

[color=#E56717]========== Files Created - No Company Name ==========[/color]

[2013/10/17 03:41:44 | 000,000,786 | ---- | C] () -- C:\Documents and Settings\All Users\Bureau\Malwarebytes Anti-Malware.lnk
[2013/10/05 12:25:34 | 000,000,532 | ---- | C] () -- C:\Documents and Settings\User\Bureau\Raccourci vers SUPER NOVA TEAM.lnk
[2013/09/18 14:10:02 | 000,000,416 | ---- | C] () -- C:\Documents and Settings\User\Bureau\Raccourci vers connaissances videos.lnk
[2013/03/05 20:56:52 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll
[2013/03/02 18:09:36 | 000,006,136 | ---- | C] () -- C:\WINDOWS\System32\drivers\nvphy.bin
[2013/03/02 17:33:54 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2013/02/28 01:20:05 | 000,000,037 | ---- | C] () -- C:\WINDOWS\SWFConverter.INI
[2013/02/28 00:59:00 | 000,000,067 | ---- | C] () -- C:\WINDOWS\swf2avi.INI
[2013/02/28 00:58:50 | 000,135,168 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2013/02/13 23:40:26 | 001,507,626 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-S-1-5-21-1547161642-1343024091-1801674531-1004-0.dat
[2013/02/13 23:40:26 | 000,521,154 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat
[2013/01/20 17:56:54 | 000,111,932 | ---- | C] () -- C:\WINDOWS\System32\EPPICPrinterDB.dat
[2013/01/20 17:56:54 | 000,031,053 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern131.dat
[2013/01/20 17:56:54 | 000,027,417 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern121.dat
[2013/01/20 17:56:54 | 000,026,154 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern1.dat
[2013/01/20 17:56:54 | 000,024,903 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern3.dat
[2013/01/20 17:56:54 | 000,021,390 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern5.dat
[2013/01/20 17:56:54 | 000,020,148 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern2.dat
[2013/01/20 17:56:54 | 000,011,811 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern4.dat
[2013/01/20 17:56:54 | 000,004,943 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern6.dat
[2013/01/20 17:56:54 | 000,001,146 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_DU.dat
[2013/01/20 17:56:54 | 000,001,139 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_PT.dat
[2013/01/20 17:56:54 | 000,001,139 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_BP.dat
[2013/01/20 17:56:54 | 000,001,136 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_ES.dat
[2013/01/20 17:56:54 | 000,001,129 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_FR.dat
[2013/01/20 17:56:54 | 000,001,129 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_CF.dat
[2013/01/20 17:56:54 | 000,001,120 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_IT.dat
[2013/01/20 17:56:54 | 000,001,107 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_GE.dat
[2013/01/20 17:56:54 | 000,001,104 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_EN.dat
[2013/01/20 17:56:54 | 000,000,097 | ---- | C] () -- C:\WINDOWS\System32\PICSDK.ini
[2013/01/20 05:59:44 | 002,463,976 | ---- | C] () -- C:\WINDOWS\System32\NPSWF32.dll
[2012/12/20 23:48:42 | 001,091,636 | ---- | C] () -- C:\WINDOWS\System32\nvdrsdb1.bin
[2012/12/20 23:48:42 | 001,091,636 | ---- | C] () -- C:\WINDOWS\System32\nvdrsdb0.bin
[2012/12/20 23:48:42 | 000,000,001 | ---- | C] () -- C:\WINDOWS\System32\nvdrssel.bin
[2012/12/20 23:48:05 | 002,288,168 | ---- | C] () -- C:\WINDOWS\System32\nvdata.data
[2012/12/20 22:38:13 | 000,025,548 | ---- | C] () -- C:\WINDOWS\System32\drivers\RTAIODAT.DAT
[2012/12/16 00:04:41 | 000,004,140 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\mtbjfghn.xbe
[2012/12/15 23:50:50 | 000,153,088 | ---- | C] () -- C:\WINDOWS\System32\IWUninstall.exe
[2012/12/13 21:17:03 | 000,099,328 | ---- | C] () -- C:\Documents and Settings\User\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/12/12 19:40:54 | 000,004,205 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2012/12/12 19:40:16 | 004,177,800 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2012/12/12 18:58:55 | 001,580,550 | ---- | C] () -- C:\WINDOWS\System32\nvdata.bin
[2012/12/12 18:58:55 | 000,261,632 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
[2012/12/12 18:58:03 | 000,005,810 | ---- | C] () -- C:\WINDOWS\System32\drivers\ASACPI.sys
[2012/12/12 18:50:12 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2012/12/12 18:48:02 | 000,021,892 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2012/12/12 11:33:54 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2012/12/12 11:33:51 | 000,514,448 | ---- | C] () -- C:\WINDOWS\System32\perfh00C.dat
[2012/12/12 11:33:51 | 000,445,540 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2012/12/12 11:33:51 | 000,322,810 | ---- | C] () -- C:\WINDOWS\System32\perfi00C.dat
[2012/12/12 11:33:51 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2012/12/12 11:33:51 | 000,085,040 | ---- | C] () -- C:\WINDOWS\System32\perfc00C.dat
[2012/12/12 11:33:51 | 000,070,514 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2012/12/12 11:33:51 | 000,034,108 | ---- | C] () -- C:\WINDOWS\System32\perfd00C.dat
[2012/12/12 11:33:51 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2012/12/12 11:33:50 | 000,004,461 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2012/12/12 11:33:49 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2012/12/12 11:33:48 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2012/12/12 11:33:42 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2012/12/12 11:33:42 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2012/12/12 11:33:35 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2012/12/12 11:33:31 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\Dcache.bin

[color=#E56717]========== ZeroAccess Check ==========[/color]


[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll -- [2012/12/27 12:24:18 | 001,510,912 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\fastprox.dll -- [2009/02/09 12:53:55 | 000,473,600 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\wbemess.dll -- [2008/04/13 18:33:50 | 000,273,920 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[color=#E56717]========== Custom Scans ==========[/color]

[color=#A23BEC]< MD5 for: EXPLORER.EXE >[/color]
[2013/01/23 17:12:07 | 000,017,408 | ---- | M] () MD5=64547625EF21CD4BE1E73365F96A79DC -- C:\Documents and Settings\User\Mes documents\Downloads\Adobe InDesign CS5.5 v7.5.1.304 Portable by Birungueta\Native\STUBEXE\8.0.1135\@WINDIR@\explorer.exe
[2008/04/13 18:34:04 | 001,037,824 | ---- | M] (Microsoft Corporation) MD5=F2317622D29F9FF0F88AEECD5F60F0DD -- C:\WINDOWS\explorer.exe
[2008/04/13 18:34:04 | 001,037,824 | ---- | M] (Microsoft Corporation) MD5=F2317622D29F9FF0F88AEECD5F60F0DD -- C:\WINDOWS\system32\dllcache\explorer.exe

[color=#A23BEC]< MD5 for: IEXPLORE.EXE >[/color]
[2008/04/13 18:34:08 | 000,093,184 | ---- | M] (Microsoft Corporation) MD5=3D3C316BD1E112F3B9C532D8B9939BDC -- C:\WINDOWS\ie8\iexplore.exe
[2013/04/04 14:50:32 | 000,218,184 | ---- | M] () MD5=B4C6E3889BB310CA7E974A04EC6E46AC -- C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\iexplore.exe
[2009/03/08 15:09:26 | 000,638,816 | ---- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E -- C:\Program Files\Internet Explorer\iexplore.exe
[2009/03/08 15:09:26 | 000,638,816 | ---- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E -- C:\WINDOWS\system32\dllcache\iexplore.exe

[color=#A23BEC]< MD5 for: USERINIT.EXE >[/color]
[2008/04/13 18:34:28 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=E74DDB12188C2FF57A78624DBF7332FC -- C:\WINDOWS\system32\dllcache\userinit.exe
[2008/04/13 18:34:28 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=E74DDB12188C2FF57A78624DBF7332FC -- C:\WINDOWS\system32\userinit.exe

[color=#A23BEC]< MD5 for: WINLOGON.EXE >[/color]
[2013/04/04 14:50:32 | 000,218,184 | ---- | M] () MD5=B4C6E3889BB310CA7E974A04EC6E46AC -- C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2008/04/13 18:34:30 | 000,512,000 | ---- | M] (Microsoft Corporation) MD5=DD73D6B9F6B4CB630CF35B438B540174 -- C:\WINDOWS\system32\dllcache\winlogon.exe
[2008/04/13 18:34:30 | 000,512,000 | ---- | M] (Microsoft Corporation) MD5=DD73D6B9F6B4CB630CF35B438B540174 -- C:\WINDOWS\system32\winlogon.exe

[color=#A23BEC]< %SYSTEMDRIVE%\*.exe >[/color]

[color=#A23BEC]< %ALLUSERSPROFILE%\Application Data\*. >[/color]
[2013/08/20 13:19:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Adobe
[2012/12/13 00:22:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Avira
[2013/02/09 01:42:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Comodo
[2013/02/13 23:48:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Corel
[2013/02/13 22:41:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Corel Painter 12
[2013/02/13 23:54:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Corel Painter 12.1 Update
[2012/12/14 17:07:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\CPA_VA
[2013/01/20 16:30:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\EPSON
[2012/12/13 17:22:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ESET
[2013/01/20 16:21:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\FLEXnet
[2012/12/20 22:27:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ma-config.com
[2013/10/17 03:41:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2012/12/12 19:22:27 | 000,000,000 | --SD | M] -- C:\Documents and Settings\All Users\Application Data\Microsoft
[2013/03/17 20:52:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Microsoft Help
[2012/12/13 01:10:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Mozilla
[2013/03/05 19:46:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\NVIDIA
[2012/12/20 23:49:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\NVIDIA Corporation
[2012/12/21 01:27:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\NVIDIA(2)
[2013/01/05 17:48:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Pinnacle
[2013/02/13 22:44:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Protexis
[2013/08/20 13:33:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\regid.1986-12.com.adobe
[2013/07/28 23:46:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Skype
[2013/02/09 01:38:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SweetIM
[2013/02/28 01:33:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Xilisoft

[color=#A23BEC]< %ALLUSERSPROFILE%\Application Data\*.exe /s >[/color]
[2012/01/03 09:37:53 | 000,320,456 | ---- | M] (Adobe Systems Incorporated) -- C:\Documents and Settings\All Users\Application Data\Adobe\Reader\9.2\ARM\ARM Update\AcrobatUpdater.exe
[2012/01/03 09:37:53 | 000,843,712 | ---- | M] (Adobe Systems Incorporated) -- C:\Documents and Settings\All Users\Application Data\Adobe\Reader\9.2\ARM\ARM Update\AdobeARM.exe
[2012/01/03 09:37:53 | 000,320,456 | ---- | M] (Adobe Systems Incorporated) -- C:\Documents and Settings\All Users\Application Data\Adobe\Reader\9.2\ARM\ARM Update\AdobeARMHelper.exe
[2012/01/03 09:37:53 | 000,320,456 | ---- | M] (Adobe Systems Incorporated) -- C:\Documents and Settings\All Users\Application Data\Adobe\Reader\9.2\ARM\ARM Update\ReaderUpdater.exe
[2012/12/03 09:35:28 | 000,352,960 | ---- | M] (Adobe Systems Incorporated) -- C:\Documents and Settings\All Users\Application Data\Adobe\Reader\9.5\ARM\21593\AcrobatUpdater.exe
[2012/12/03 09:35:28 | 000,946,352 | ---- | M] (Adobe Systems Incorporated) -- C:\Documents and Settings\All Users\Application Data\Adobe\Reader\9.5\ARM\21593\AdobeARM.exe
[2012/12/03 09:35:28 | 000,352,960 | ---- | M] (Adobe Systems Incorporated) -- C:\Documents and Settings\All Users\Application Data\Adobe\Reader\9.5\ARM\21593\AdobeARMHelper.exe
[2012/12/03 09:35:28 | 000,352,960 | ---- | M] (Adobe Systems Incorporated) -- C:\Documents and Settings\All Users\Application Data\Adobe\Reader\9.5\ARM\21593\ReaderUpdater.exe
[2013/04/04 23:06:36 | 000,353,912 | ---- | M] (Adobe Systems Incorporated) -- C:\Documents and Settings\All Users\Application Data\Adobe\Reader\9.5\ARM\8093\AcrobatUpdater.exe
[2013/04/04 23:06:36 | 000,958,576 | ---- | M] (Adobe Systems Incorporated) -- C:\Documents and Settings\All Users\Application Data\Adobe\Reader\9.5\ARM\8093\AdobeARM.exe
[2013/04/04 23:06:36 | 000,353,912 | ---- | M] (Adobe Systems Incorporated) -- C:\Documents and Settings\All Users\Application Data\Adobe\Reader\9.5\ARM\8093\AdobeARMHelper.exe
[2013/04/04 23:06:36 | 000,353,912 | ---- | M] (Adobe Systems Incorporated) -- C:\Documents and Settings\All Users\Application Data\Adobe\Reader\9.5\ARM\8093\ReaderUpdater.exe
[2012/01/03 19:46:15 | 000,345,520 | ---- | M] (Adobe Systems Incorporated) -- C:\Documents and Settings\All Users\Application Data\Adobe\Setup\{AC76BA86-7AD7-1036-7B44-A95000000001}\Setup.exe
[2007/01/11 05:02:00 | 000,113,664 | ---- | M] (SEIKO EPSON CORPORATION) -- C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE
[2013/10/15 21:20:38 | 000,173,136 | ---- | M] (NVIDIA Corporation) -- C:\Documents and Settings\All Users\Application Data\NVIDIA\Updatus\ApplicationOntology\OAWrapper.exe
[2013/05/25 13:19:43 | 001,791,776 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\NVIDIA\Updatus\Packages\00003a73\dao.15915059.exe
[2013/05/30 13:22:19 | 001,811,808 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\NVIDIA\Updatus\Packages\00003b33\dao.16044919.exe
[2013/06/01 14:57:15 | 001,835,728 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\NVIDIA\Updatus\Packages\00003b51\dao.16081870.exe
[2013/06/04 14:59:22 | 001,846,296 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\NVIDIA\Updatus\Packages\00003be2\dao.16137597.exe
[2013/06/06 15:01:28 | 001,853,336 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\NVIDIA\Updatus\Packages\00003bf1\dao.16173164.exe
[2013/06/07 15:02:23 | 001,856,952 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\NVIDIA\Updatus\Packages\00003bf6\dao.16199147.exe
[2013/06/15 22:03:07 | 001,902,064 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\NVIDIA\Updatus\Packages\00003d2d\dao.16249320.exe
[2013/06/18 22:04:55 | 001,902,064 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\NVIDIA\Updatus\Packages\00003e50\dao.16281631.exe
[2013/06/21 22:27:26 | 001,903,312 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\NVIDIA\Updatus\Packages\00003e66\dao.16303927.exe
[2013/06/26 19:35:12 | 001,916,672 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\NVIDIA\Updatus\Packages\00003e7b\dao.16329232.exe
[2013/06/27 19:36:45 | 001,916,712 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\NVIDIA\Updatus\Packages\00003e82\dao.16337275.exe
[2013/07/02 12:18:48 | 001,923,016 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\NVIDIA\Updatus\Packages\00003e93\dao.16368481.exe
[2013/07/06 13:23:11 | 001,949,376 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\NVIDIA\Updatus\Packages\00004049\dao.16397623.exe
[2013/07/11 14:10:07 | 001,948,520 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\NVIDIA\Updatus\Packages\00004139\dao.16438418.exe
[2013/07/13 14:11:38 | 001,948,376 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\NVIDIA\Updatus\Packages\000041d0\dao.16449855.exe
[2013/07/17 14:21:22 | 001,948,672 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\NVIDIA\Updatus\Packages\000041da\dao.16473425.exe
[2013/07/23 15:10:33 | 001,964,160 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\NVIDIA\Updatus\Packages\00004312\dao.16509223.exe
[2013/07/24 15:11:35 | 001,984,640 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\NVIDIA\Updatus\Packages\00004318\dao.16512755.exe
[2013/07/26 15:13:06 | 001,985,208 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\NVIDIA\Updatus\Packages\00004326\dao.16530916.exe
[2013/07/31 21:49:10 | 002,004,104 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\NVIDIA\Updatus\Packages\00004447\dao.16557018.exe
[2013/08/04 21:50:27 | 002,040,016 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\NVIDIA\Updatus\Packages\000044ea\dao.16585357.exe
[2013/08/09 23:44:54 | 002,083,376 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\NVIDIA\Updatus\Packages\000046ad\dao.16624331.exe
[2013/08/15 12:18:18 | 002,095,264 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\NVIDIA\Updatus\Packages\00004759\dao.16661196.exe
[2013/08/20 12:49:02 | 002,113,352 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\NVIDIA\Updatus\Packages\00004812\dao.16689610.exe
[2013/08/24 16:53:49 | 002,130,512 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\NVIDIA\Updatus\Packages\000048c5\dao.16719343.exe
[2013/08/28 18:23:16 | 002,175,976 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\NVIDIA\Updatus\Packages\00004960\dao.16746386.exe
[2013/08/30 22:03:30 | 002,210,720 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\NVIDIA\Updatus\Packages\00004a8c\dao.16768054.exe
[2013/09/03 22:10:10 | 002,259,320 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\NVIDIA\Updatus\Packages\00004ad4\dao.16798210.exe
[2013/09/05 22:13:41 | 002,275,760 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\NVIDIA\Updatus\Packages\00004b67\dao.16810112.exe
[2013/09/11 22:20:36 | 002,263,192 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\NVIDIA\Updatus\Packages\00004c04\dao.16851624.exe
[2013/09/14 22:28:44 | 002,269,032 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\NVIDIA\Updatus\Packages\00004cae\dao.16872449.exe
[2013/09/17 22:30:55 | 002,269,320 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\NVIDIA\Updatus\Packages\00004d42\dao.16890168.exe
[2013/09/18 22:33:00 | 002,282,136 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\NVIDIA\Updatus\Packages\00004d50\dao.16897403.exe
[2013/09/24 22:36:37 | 002,295,088 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\NVIDIA\Updatus\Packages\00004e97\dao.16937854.exe
[2013/09/25 22:38:40 | 002,295,072 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\NVIDIA\Updatus\Packages\00004ea9\dao.16946050.exe
[2013/09/30 22:43:28 | 002,304,504 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\NVIDIA\Updatus\Packages\00004f59\dao.16989644.exe
[2013/10/04 22:48:33 | 002,325,816 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\NVIDIA\Updatus\Packages\0000500a\dao.17010529.exe
[2013/10/05 22:50:44 | 002,348,240 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\NVIDIA\Updatus\Packages\000050a2\dao.17018238.exe
[2013/10/10 22:54:55 | 002,348,584 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\NVIDIA\Updatus\Packages\00005148\dao.17055351.exe
[2013/10/15 01:18:28 | 002,352,672 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\NVIDIA\Updatus\Packages\00005165\dao.17084698.exe
[2013/10/16 01:19:38 | 002,353,248 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\NVIDIA\Updatus\Packages\0000516f\dao.17090360.exe

[color=#A23BEC]< %APPDATA%\*. >[/color]
[2013/07/28 14:07:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Application Data\Adobe
[2013/10/16 22:18:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Application Data\AIMP3
[2012/12/16 00:03:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Application Data\Carambis
[2013/02/13 22:44:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Application Data\Corel
[2013/02/11 22:45:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Application Data\dvdcss
[2013/01/20 18:01:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Application Data\EPSON
[2013/02/06 06:40:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Application Data\Google
[2013/01/18 20:18:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Application Data\Haihaisoft PDF Reader
[2012/12/12 18:52:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Application Data\Identities
[2013/01/20 17:56:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Application Data\InstallShield
[2012/12/13 01:11:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Application Data\Macromedia
[2013/10/17 03:41:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Application Data\Malwarebytes
[2013/03/17 20:52:45 | 000,000,000 | --SD | M] -- C:\Documents and Settings\User\Application Data\Microsoft
[2013/02/28 00:48:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Application Data\Moyea
[2012/12/13 01:10:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Application Data\Mozilla
[2013/02/28 01:34:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Application Data\NVIDIA
[2013/09/20 01:18:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Application Data\Skype
[2013/07/19 13:48:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Application Data\Unity
[2013/10/15 02:16:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Application Data\uTorrent
[2013/10/15 01:49:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Application Data\vlc
[2012/12/13 00:30:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Application Data\WinRAR
[2012/12/13 01:15:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Application Data\WTablet
[2013/02/28 01:34:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Application Data\Xilisoft

[color=#A23BEC]< %APPDATA%\*.exe /s >[/color]

[color=#A23BEC]< %systemroot%\*. /mp /s >[/color]

[color=#A23BEC]< %systemroot%\system32\*.dll /lockedfiles >[/color]
[10 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

[color=#A23BEC]< %systemroot%\syswow64\*.dll /lockedfiles >[/color]

[color=#A23BEC]< %systemroot%\Tasks\*.job /lockedfiles >[/color]

[color=#A23BEC]< %systemroot%\system32\drivers\*.sys /lockedfiles >[/color]

[color=#A23BEC]< %systemroot%\syswow64\drivers\*.sys /lockedfiles >[/color]

[color=#A23BEC]< HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems /s >[/color]
"Debug" =
"Kmode" = %SystemRoot%\system32\win32k.sys -- [2013/06/05 11:08:39 | 001,876,864 | ---- | M] (Microsoft Corporation)
"Optional" = Posix [binary data]
"Posix" = %SystemRoot%\system32\psxss.exe
"Required" = DebugWindows [binary data]
"Windows" = %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems\CSRSS]
"CsrSrvSharedSectionBase" = 2137980928

[color=#A23BEC]< hklm\software\clients\startmenuinternet|command /rs >[/color]
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Dragon\InstallInfo\\ReinstallCommand: "C:\Program Files\Comodo\Dragon\dragon.exe" --make-default-browser [2013/10/09 19:33:14 | 001,285,256 | ---- | M] (Comodo)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Dragon\InstallInfo\\HideIconsCommand: "C:\Program Files\Comodo\Dragon\dragon.exe" --hide-icons [2013/10/09 19:33:14 | 001,285,256 | ---- | M] (Comodo)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Dragon\InstallInfo\\ShowIconsCommand: "C:\Program Files\Comodo\Dragon\dragon.exe" --show-icons [2013/10/09 19:33:14 | 001,285,256 | ---- | M] (Comodo)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Dragon\shell\open\command\\: "C:\Program Files\Comodo\Dragon\dragon.exe" [2013/10/09 19:33:14 | 001,285,25
0
hom2ver Messages postés 78 Date d'inscription vendredi 17 août 2007 Statut Membre Dernière intervention 28 octobre 2013
20 oct. 2013 à 15:10
Malwarebytes Anti-Malware (Essai) 1.75.0.1300
www.malwarebytes.org

Version de la base de données: v2013.10.19.04

Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702

Protection: Désactivé

20/10/2013 13:21:49
MBAM-log-2013-10-20 (14-51-50).txt

Type d'examen: Examen complet (C:\|H:\|K:\|)
Options d'examen activées: Mémoire | Démarrage | Registre | Système de fichiers | Heuristique/Extra | Heuristique/Shuriken | PUP | PUM
Options d'examen désactivées: P2P
Elément(s) analysé(s): 467962
Temps écoulé: 1 heure(s), 29 minute(s), 46 seconde(s)

Processus mémoire détecté(s): 0
(Aucun élément nuisible détecté)

Module(s) mémoire détecté(s): 0
(Aucun élément nuisible détecté)

Clé(s) du Registre détectée(s): 4
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{EEE6C35C-6118-11DC-9C72-001320C79847} (PUP.Optional.SweetPacks) -> Aucune action effectuée.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEE6C35C-6118-11DC-9C72-001320C79847} (PUP.Optional.SweetPacks) -> Aucune action effectuée.
HKCU\SOFTWARE\INSTALLCORE (PUP.Optional.InstallCore.A) -> Aucune action effectuée.
HKCU\SOFTWARE\SWEETIM (PUP.Optional.SweetIM.A) -> Aucune action effectuée.

Valeur(s) du Registre détectée(s): 2
HKCU\Software\InstallCore|tb (PUP.Optional.InstallCore.A) -> Données: 1W1B1I1T2U -> Aucune action effectuée.
HKCU\Software\SweetIM|simapp_id (PUP.Optional.SweetIM.A) -> Données: {6D9B36D0-619B-11E2-962C-00248C9E8B60} -> Aucune action effectuée.

Elément(s) de données du Registre détecté(s): 0
(Aucun élément nuisible détecté)

Dossier(s) détecté(s): 0
(Aucun élément nuisible détecté)

Fichier(s) détecté(s): 38
C:\Documents and Settings\User\Mes documents\Téléchargements\ESET\ESET Nod32 & Smart Security 5 & Crack A Vie Update\ESET PureFix v.2.03\ESET PureFix v2.03.exe (RiskWare.Tool.CK) -> Aucune action effectuée.
C:\System Volume Information\_restore{0831A744-9EC7-4EBA-89AF-1FE60D860BDF}\RP247\A0077350.dll (PUP.Optional.SweetIM) -> Aucune action effectuée.
C:\System Volume Information\_restore{0831A744-9EC7-4EBA-89AF-1FE60D860BDF}\RP247\A0077368.msi (PUP.Optional.SweetIM) -> Aucune action effectuée.
C:\System Volume Information\_restore{0831A744-9EC7-4EBA-89AF-1FE60D860BDF}\RP247\A0077340.dll (PUP.Optional.SweetIM) -> Aucune action effectuée.
C:\System Volume Information\_restore{0831A744-9EC7-4EBA-89AF-1FE60D860BDF}\RP247\A0077341.dll (PUP.Optional.SweetIM) -> Aucune action effectuée.
C:\System Volume Information\_restore{0831A744-9EC7-4EBA-89AF-1FE60D860BDF}\RP247\A0077342.dll (PUP.Optional.SweetIM) -> Aucune action effectuée.
C:\System Volume Information\_restore{0831A744-9EC7-4EBA-89AF-1FE60D860BDF}\RP247\A0077343.dll (PUP.Optional.SweetIM) -> Aucune action effectuée.
C:\System Volume Information\_restore{0831A744-9EC7-4EBA-89AF-1FE60D860BDF}\RP247\A0077344.exe (PUP.Optional.SweetIM) -> Aucune action effectuée.
C:\System Volume Information\_restore{0831A744-9EC7-4EBA-89AF-1FE60D860BDF}\RP247\A0077345.dll (PUP.Optional.SweetIM) -> Aucune action effectuée.
C:\System Volume Information\_restore{0831A744-9EC7-4EBA-89AF-1FE60D860BDF}\RP247\A0077346.exe (PUP.Optional.SweetIM) -> Aucune action effectuée.
C:\System Volume Information\_restore{0831A744-9EC7-4EBA-89AF-1FE60D860BDF}\RP247\A0077347.dll (PUP.Optional.SweetIM) -> Aucune action effectuée.
C:\System Volume Information\_restore{0831A744-9EC7-4EBA-89AF-1FE60D860BDF}\RP247\A0077348.dll (PUP.Optional.SweetIM) -> Aucune action effectuée.
C:\System Volume Information\_restore{0831A744-9EC7-4EBA-89AF-1FE60D860BDF}\RP247\A0077349.dll (PUP.Optional.SweetIM) -> Aucune action effectuée.
C:\System Volume Information\_restore{0831A744-9EC7-4EBA-89AF-1FE60D860BDF}\RP247\A0077351.dll (PUP.Optional.SweetIM) -> Aucune action effectuée.
C:\System Volume Information\_restore{0831A744-9EC7-4EBA-89AF-1FE60D860BDF}\RP247\A0077352.dll (PUP.Optional.SweetIM) -> Aucune action effectuée.
C:\System Volume Information\_restore{0831A744-9EC7-4EBA-89AF-1FE60D860BDF}\RP247\A0077353.dll (PUP.Optional.SweetIM) -> Aucune action effectuée.
C:\System Volume Information\_restore{0831A744-9EC7-4EBA-89AF-1FE60D860BDF}\RP247\A0077354.dll (PUP.Optional.SweetIM) -> Aucune action effectuée.
C:\System Volume Information\_restore{0831A744-9EC7-4EBA-89AF-1FE60D860BDF}\RP247\A0077355.dll (PUP.Optional.SweetIM) -> Aucune action effectuée.
C:\System Volume Information\_restore{0831A744-9EC7-4EBA-89AF-1FE60D860BDF}\RP247\A0077356.dll (PUP.Optional.SweetIM) -> Aucune action effectuée.
C:\System Volume Information\_restore{0831A744-9EC7-4EBA-89AF-1FE60D860BDF}\RP247\A0077357.dll (PUP.Optional.SweetIM) -> Aucune action effectuée.
C:\System Volume Information\_restore{0831A744-9EC7-4EBA-89AF-1FE60D860BDF}\RP247\A0077358.dll (PUP.Optional.SweetIM) -> Aucune action effectuée.
C:\System Volume Information\_restore{0831A744-9EC7-4EBA-89AF-1FE60D860BDF}\RP247\A0077359.dll (PUP.Optional.SweetIM) -> Aucune action effectuée.
C:\System Volume Information\_restore{0831A744-9EC7-4EBA-89AF-1FE60D860BDF}\RP247\A0077360.dll (PUP.Optional.SweetIM) -> Aucune action effectuée.
C:\System Volume Information\_restore{0831A744-9EC7-4EBA-89AF-1FE60D860BDF}\RP247\A0077361.dll (PUP.Optional.SweetIM) -> Aucune action effectuée.
C:\System Volume Information\_restore{0831A744-9EC7-4EBA-89AF-1FE60D860BDF}\RP247\A0077362.dll (PUP.Optional.SweetIM) -> Aucune action effectuée.
C:\System Volume Information\_restore{0831A744-9EC7-4EBA-89AF-1FE60D860BDF}\RP247\A0077363.dll (PUP.Optional.SweetIM) -> Aucune action effectuée.
C:\System Volume Information\_restore{0831A744-9EC7-4EBA-89AF-1FE60D860BDF}\RP247\A0077364.dll (PUP.Optional.SweetIM) -> Aucune action effectuée.
C:\System Volume Information\_restore{0831A744-9EC7-4EBA-89AF-1FE60D860BDF}\RP247\A0077365.dll (PUP.Optional.SweetIM) -> Aucune action effectuée.
C:\System Volume Information\_restore{0831A744-9EC7-4EBA-89AF-1FE60D860BDF}\RP247\A0077366.exe (PUP.Optional.SweetIM) -> Aucune action effectuée.
C:\System Volume Information\_restore{0831A744-9EC7-4EBA-89AF-1FE60D860BDF}\RP247\A0077367.dll (PUP.Optional.SweetIM) -> Aucune action effectuée.
C:\System Volume Information\_restore{0831A744-9EC7-4EBA-89AF-1FE60D860BDF}\RP247\A0077369.msi (PUP.Optional.SweetIM) -> Aucune action effectuée.
C:\System Volume Information\_restore{0831A744-9EC7-4EBA-89AF-1FE60D860BDF}\RP247\A0077370.msi (PUP.Optional.SweetIM) -> Aucune action effectuée.
C:\System Volume Information\_restore{0831A744-9EC7-4EBA-89AF-1FE60D860BDF}\RP247\A0077371.msi (PUP.Optional.SweetIM) -> Aucune action effectuée.
H:\Downloads\ESET NOD32 Antivirus 5.2.9.1 (x86) + ESET PureFix V2b [Jazz_Singh]\x86\x86\ESET_PureFix_V2b_0.rar (RiskWare.Tool.CK) -> Aucune action effectuée.
K:\jo\Bureau\logs\Sygate up goldbergraw\offline.exe (Backdoor.Bifrose) -> Aucune action effectuée.
K:\jo\Mes documents\Téléchargements\ESET.rar (RiskWare.Tool.CK) -> Aucune action effectuée.
K:\System Volume Information\_restore{0831A744-9EC7-4EBA-89AF-1FE60D860BDF}\RP247\A0077372.exe (PUP.Optional.OpenCandy) -> Aucune action effectuée.
K:\Downloads\ESET NOD32 Antivirus 5.2.9.1 (x86) + ESET PureFix V2b [Jazz_Singh]\x86\x86\ESET_PureFix_V2b_0.rar (RiskWare.Tool.CK) -> Aucune action effectuée.

(fin)
0
Utilisateur anonyme
20 oct. 2013 à 16:22
Re

Ouvre ce lien et télécharge ZHPDiag de Nicolas Coolman :

https://www.zebulon.fr/telechargements/securite/systeme/zhpdiag.html

Ou

https://www.commentcamarche.net/telecharger/utilitaires/24803-zhpdiag/

en bas de la page ZHP avec un numéro de version.

Une fois le téléchargement achevé,

Double-clique sur l'icône pour lancer le programme. Sous Vista ; Seven ou Windows 8 clic droit « exécuter en tant que administrateur »


Dans la fenêtre ZHPDiag qui vient de s'ouvrir, clique sur "Configurer"

Clique sur la loupe en bas à gauche avec le signe moins pour lancer l'analyse.

Clique sur OUI à la question "Voulez-vous un rapport full options"

Laisse l'outil travailler, il peut être assez long.

Un rapport s'ouvre. Ce rapport se trouve également sur ton bureau

Pour transmettre le rapport clique sur ce lien:
http://pjjoint.malekal.com/

Si problème utilise un des suivants

https://forums-fec.be/upload
https://www.cjoint.com/


Regarde sur le bureau

Sélectionne le fichier ZHPDiag.txt.

Clique sur "Cliquez ici pour déposer le fichier".

Un lien de cette forme :

http://www.cijoint.com/cjlink.php?file=cj200905/cijSKAP5fU.txt

est ajouté dans la page.

Copie ce lien dans ta réponse.

Merci

@+

0
hom2ver Messages postés 78 Date d'inscription vendredi 17 août 2007 Statut Membre Dernière intervention 28 octobre 2013
20 oct. 2013 à 16:46
Re

j'ai installé ZHPDiag mais je n'ai pas de loupe avec un signe moins dans configurer
0
Utilisateur anonyme
20 oct. 2013 à 16:49
Tu es bien sur ZHPDiag et non ZHPFix
0
hom2ver Messages postés 78 Date d'inscription vendredi 17 août 2007 Statut Membre Dernière intervention 28 octobre 2013
20 oct. 2013 à 16:53
oups tu as raison
c'est reparti
0
hom2ver Messages postés 78 Date d'inscription vendredi 17 août 2007 Statut Membre Dernière intervention 28 octobre 2013
20 oct. 2013 à 17:05
c'est moi qui te remercie Guillaume. c'est vraiment cool de m'aider.

voilà le lien:

https://pjjoint.malekal.com/files.php?id=ZHPDiag_20131020_c7j6q14d8t10
0
Utilisateur anonyme
20 oct. 2013 à 17:20
Re

Utilisation de l'outil ZHPFix :

* Copie tout le texte présent dans l'encadré ci-dessous (tu le sélectionnes avec ta souris / Clique droit dessus et choisis "copier" ou fait Ctrl+C )

Script ZHPFix
ShortcutFix
O3 - Toolbar: SweetPacks Toolbar for Internet Explorer - [HKLM]{EEE6C35B-6118-11DC-9C72-001320C79847} . (...) -- C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
O3 - Toolbar\WebBrowser: (no name) - [HKCU]{EEE6C35B-6118-11DC-9C72-001320C79847} Clé orpheline
O42 - Logiciel: SweetIM for Messenger 3.7 - (.SweetIM Technologies Ltd..) [HKLM] -- {A0C9DF2B-89B5-4483-8983-18A68200F1B4}
O42 - Logiciel: SweetPacks bundle uninstaller - (.SweetIM Technologies Ltd..) [HKLM] -- {0C43FE6B-E881-4AFC-B384-4AEBC90047E8}
O42 - Logiciel: Update Manager for SweetPacks 1.1 - (.SweetIM Technologies Ltd..) [HKLM] -- {EA8FA6BE-29BE-4AF2-9352-841F83215EB0}
[HKCU\Software\InstallCore]
[HKCU\Software\SweetIM]
O43 - CFD: 17/10/2013 - 04:01:17 - [2,204] ----D C:\Program Files\SweetIM
O43 - CFD: 09/02/2013 - 01:38:50 - [0,311] ----D C:\Documents and Settings\All Users\Application Data\SweetIM
O47 - AAKE:Key Export SP - "C:\Program Files\SweetIM\Communicator\SweetPacksUpdateManager.exe" [Enabled] .(...) -- C:\Program Files\SweetIM\Communicator\SweetPacksUpdateManager.exe (.not file.)
O90 - PUC: "9EE58E3C298524145B73CBBED3CAC4D3" . (.Internet Explorer Toolbar 4.6 by SweetPacks.) -- C:\WINDOWS\Installer\{C3E85EE9-5892-4142-B537-BCEB3DAC4C3D}\ARPPRODUCTICON.exe
[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{A0C9DF2B-89B5-4483-8983-18A68200F1B4}]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{0C43FE6B-E881-4AFC-B384-4AEBC90047E8}]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{EA8FA6BE-29BE-4AF2-9352-841F83215EB0}]
[HKLM\Software\Classes\CLSID\{A4A0CB15-8465-4F58-A7E5-73084EA2A064}]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D15DAF33C220F91468A1D7D57C31ACD7]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D6D0EB9FDBD90C04D92A7E729058F10D]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A189D17A469616C4688D23E192996267]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\98CC8BF5A4A6E6C4ABF7051DDAB8B058]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7FFA128C2B0FF414D805FC5627883401]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D3BA76A44C779424889063D5098ED2D6]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\397C771A7BCAC904697C3EC629ED33ED]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\351716A953E21214898904032EAE2E81]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2E6768B6932D112438F047C54D180635]
[HKLM\Software\Classes\Interface\{F4EBB1E2-21F3-4786-8CF4-16EC5925867F}]
[HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\sweetim.exe]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\F928123A039649549966D4C29D35B1C9]
[HKLM\Software\Classes\Installer\Features\EB6AF8AEEB922FA4392548F13812E50B]
[HKLM\Software\Classes\Installer\Products\EB6AF8AEEB922FA4392548F13812E50B]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\EB6AF8AEEB922FA4392548F13812E50B]
[HKCU\Software\SweetIM]
[HKLM\Software\Classes\Installer\Features\9EE58E3C298524145B73CBBED3CAC4D3]
[HKLM\Software\Classes\Installer\Products\9EE58E3C298524145B73CBBED3CAC4D3]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9EE58E3C298524145B73CBBED3CAC4D3]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{C3E85EE9-5892-4142-B537-BCEB3DAC4C3D}]
[HKCU\Software\InstallCore]
[HKLM\Software\Classes\Installer\Features\B2FD9C0A5B9838449838816A28001F4B]
[HKLM\Software\Classes\Installer\Products\B2FD9C0A5B9838449838816A28001F4B]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\B2FD9C0A5B9838449838816A28001F4B]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\02F47BF73B948514FAACADD8CBBDF37D]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\07D5290CDBDAE4242926B8E6CA650501]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\080D9F5E1E95FEE4794CE438E635239E]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0E3D8A5B48622A445A7DF73FEFF32C3F]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\789034A89BAC50E4782F0A7BDBF75632]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4318DF19719275242801CBE292063A4C]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\45FC115D1FEAEF849A4E1610D6EC8BF0]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\46A5861A389ADB844AF89E31BC9DF0A1]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\49B0E1A6FF50BBE4289E4E23DE6EA0C7]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4CCCAC049F34D0540AAC13011398BEDB]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5C4389D0BFB302C479DE4178BD5D9EBA]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5D2B09BDEF4FE54418E6F3373CDBC7AC]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\61B65D3397A1FBF4CB1571B5E4F6B5B0]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\68E8A05C60DD9254591DBD16C94EDDBF]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\697E782CF574CC34CBB9566440BA12BC]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6AE27A8613CF7EA4782F2886F67295E5]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\75D5168E5E176C24981B4E5DBD991078]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7CE172051F585E04187BCB97570BFA74]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\86A901BA5265452499DCBF719C378EE3]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8724E58E6C7D00C48A0D4F3345EB2C26]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\88ABD1CD5C40EC84789A7F6EF86DAC5E]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\980289C22F80A7C4BB9323DC61255E4E]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9A4B7EF3789F871419D9302583B20C15]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A6C53B0F76C44004A8F36716213017DB]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AB676B0E1B9EFA049B9F7DDDA9645734]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B31BBB0B825EDEF45AB0FE7099C68C81]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B471D8D7319336B4CA89374ED0D7B806]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B59F2D8189784CC46A4597F2842480B0]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BC30043663AA2CA4DA1DAA9CA5FDCC75]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BD746FB95FB8E5B45BF66BE54D5FD91F]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CCF399FCD6D2D3F46BF02A1378654FC9]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D149C1355C98DE24E82CEFBD996FE06A]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DB59FDB786388EA4D897F3EE715683AC]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DB8DAD19CFBCC2049A4477183787E8C5]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E1C820A74ED67374BA048B52CB3C3804]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EC65F200D112357449C8B1BC3CFA03D0]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F327D0C73C0973644A21E8CC852267A0]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FA96423FE2B98E248A3B23548D1E22D9]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FDC83385E6C239F4C876A77A37DF581D]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\34EDDB1BFB3A2D448845F3EFD0F15A43]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\427EA997C413D1D47907CBFC7B2DB432]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\A97CEC23332751B47BA4B95BAA50C9D0]
[HKLM\Software\Classes\MediaPlayer.GraphicsUtils]
[HKLM\Software\Classes\MediaPlayer.GraphicsUtils.1]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F754C503375A13344B22388E18DFE87E]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1E264E0A5959A1C46BA9175A878B12EA]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E4748F9A4181FCE46A23C13B517B9420]
[HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{79A765E1-C399-405B-85AF-466F52E918B0}]
[HKLM\Software\Classes\Interface\{EEE6C359-6118-11DC-9C72-001320C79847}]
[HKLM\Software\Classes\Interface\{EEE6C35A-6118-11DC-9C72-001320C79847}]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\08E33F7B61DEFF24BB9673ED7D467636]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0FF2AEFF45EEA0A48A4B33C1973B6094]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\12BF94BD06C95F343A77631402B9556A]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2124D8A8CF720FD44866190AF560228E]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\27A325ACED8CA4743A30127638591ADB]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\305B09CE8C53A214DB58887F62F25536]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\350D17402BD84234EAF7D32F08172D7C]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3EE8C5F419057E1478A654868CEE60B5]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4735D908D66E1BA46B6C2D7185A12B2B]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\69D6A6B2ED56AF24EA6335EAD6E91CA4]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\76D8378E2DDAED3428720A631F6E3BF0]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\86EDC790504E1834DBC20C9A04328FD2]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\97C3D0F82E712E241A2F969F45E3351C]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9A001B259DB7D694E818BE29B973992C]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9E7F556BF224D804D96A96F0F6344789]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BAE2EC163C6A68A48921573E0E7E199D]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BF4F885EDEE45644EB1E0C99E0162399]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C06C6662FA5B04646829E4A460857770]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CE21F3FD57B244142880EF15A165A156]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CEEB3E14ABE8270419B0FD762E18F7C6]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ED1B5E9A3BDB51349BF96E842C062D98]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FECBC2BC14DA6CD459BD59A041709836]
[HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks]:{00000000-6E41-4FD3-8538-502F5495E5FC}
C:\Program Files\SweetIM
C:\Documents and Settings\All Users\Application Data\SweetIM
M3 - MFPP: Plugins - [User] -- C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\64xmy4z0.default\searchplugins\askcom.xml
O3 - Toolbar: Ask Toolbar - [HKLM]{D4027C7F-154A-4066-A1AD-4243D8127440} . (...) -- C:\Program Files\Ask.com\GenericAskToolbar.dll
O3 - Toolbar\WebBrowser: (no name) - [HKCU]{D4027C7F-154A-4066-A1AD-4243D8127440} Clé orpheline
O42 - Logiciel: Ask Toolbar - (.Ask.com.) [HKLM] -- {86D4B82A-ABED-442A-BE86-96357B70F4FE}
[HKCU\Software\APN]
[HKCU\Software\Ask.com]
[HKCU\Software\AskToolbar]
[HKLM\Software\APN]
[HKLM\Software\AskToolbar]
O69 - SBI: C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\64xmy4z0.default\searchplugins\askcom.xml
O69 - SBI: SearchScopes [HKCU] {171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E} - (Ask Search) - http://www.search.ask.com/?o=10148&l=dis
O90 - PUC: "A28B4D68DEBAA244EB686953B7074FEF" . (.Ask Toolbar.) -- c:\program files\ask.com\fv_462.ico
[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{86D4B82A-ABED-442A-BE86-96357B70F4FE}]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000000-6E41-4FD3-8538-502F5495E5FC}]
[HKLM\Software\Classes\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC}]
[HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{171DEBEB-C3D4-40B7-AC73-056A5EBA4A7E}]
[HKLM\Software\Classes\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKLM\Software\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456}]
[HKLM\Software\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92}]
[HKLM\Software\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874}]
[HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}]
[HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}]
[HKLM\Software\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E}]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}]
[HKLM\Software\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
[HKLM\Software\Classes\AppID\GenericAskToolbar.DLL]
[HKLM\Software\Classes\GenericAskToolbar.ToolbarWnd]
[HKLM\Software\Classes\GenericAskToolbar.ToolbarWnd.1]
[HKLM\Software\Classes\sim-packages]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0E12F736682067FDE4D1158D5940A82E]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1A24B5BB8521B03E0C8D908F5ABC0AE6]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\261F213D1F55267499B1F87D0CC3BCF7]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2B0D56C4F4C46D844A57FFED6F0D2852]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\49D4375FE41653242AEA4C969E4E65E0]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6AA0923513360135B272E8289C5F13FA]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6F7467AF8F29C134CBBAB394ECCFDE96]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\741B4ADF27276464790022C965AB6DA8]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7DE196B10195F5647A2B21B761F3DE01]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\922525DCC5199162F8935747CA3D8E59]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9D4F5849367142E4685ED8C25E44C5ED]
[HKLM\Software\Classes\Installer\Features\A28B4D68DEBAA244EB686953B7074FEF]
[HKLM\Software\Classes\Installer\Products\A28B4D68DEBAA244EB686953B7074FEF]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A28B4D68DEBAA244EB686953B7074FEF]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A5875B04372C19545BEB90D4D606C472]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A876D9E80B896EC44A8620248CC79296]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B66FFAB725B92594C986DE826A867888]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BCDA179D619B91648538E3394CAC94CC]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D677B1A9671D4D4004F6F2A4469E86EA]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DD1402A9DD4215A43ABDE169A41AFA0E]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E36E114A0EAD2AD46B381D23AD69CDDF]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EF8E618DB3AEDFBB384561B5C548F65E]
[HKCU\Software\APN]
[HKLM\Software\APN]
[HKCU\Software\Ask.com]
[HKCU\Software\AskToolbar]
[HKLM\Software\AskToolbar]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0CFE535C35F99574E8340BFA75BF92C2]
[HKLM\Software\Microsoft\Internet Explorer\Toolbar]:{D4027C7F-154A-4066-A1AD-4243D8127440}
[HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]:{D4027C7F-154A-4066-A1AD-4243D8127440}


FirewallRAZ
Emptytemp
EmptyCLSID

--------------------------------------------------------------------------------------------
Lance ZHPFix à partir du raccourci sur ton Bureau (si tu es sous Windows Vista ou Windows 7 ou 8, fais le par un clic-droit --> Exécuter en tant qu'administrateur)

Cliquer sur le bouton Importer. Le contenu du Presse-papier vient se coller dans la zone de saisie de ZHPFix

NB (W8) : Dans certains cas le script se colle automatiquement dans la zone de script et ne nécessite pas de cliquer sur le bouton "IMPORTER".

* Clique sur le bouton GO pour lancer le nettoyage.

-> laisse travailler l'outil et ne touche à rien ...
-> S'il t'est demandé de redémarrer le PC pour finir le nettoyage, fais le !


Une fois terminé, un nouveau rapport s'affiche : poste le contenu de ce dernier dans ta prochaine réponse ...
Ce rapport est copié sur le bureau

( ce rapport est en outre sauvegardé dans ce dossier :
- Pour XP : C:\Documents and Settings\username\Local Settings\Application Data\ZHP
- Depuis Vista : C:\Users\username\AppData\Roaming\ZHP\ZHPFix [R1].txt
)


@+
0
hom2ver Messages postés 78 Date d'inscription vendredi 17 août 2007 Statut Membre Dernière intervention 28 octobre 2013
Modifié par hom2ver le 20/10/2013 à 17:33
ZHPFix m'a demandé à plusieurs reprises lors du nettoyage si je voulai

supprimer

certains élements mais lorsque je cliquai sur oui, il me demandai un chemin de

destination..ect..en gros j'ai cliqué sur non.

j'ai aussi refusé de vider la corbeille (au cas où). dis moi si je me suis trompé.

voilà le rapport:

Rapport de ZHPFix 2013.10.20.15 par Nicolas Coolman, Update du 20/10/2013
Fichier d'export Registre :
Run by User at 20/10/2013 17:25:33
High Elevated Privileges : OK
Windows XP Home Edition Service Pack 3 (Build 2600)

Corbeille vidée (Annulé par l'utilisateur)
Réparation des raccourcis navigateur

========== Logiciels ==========
SUPPRIMÉ: SweetIM for Messenger 3.7
SUPPRIMÉ: SweetPacks bundle uninstaller
SUPPRIMÉ: Update Manager for SweetPacks 1.1
SUPPRIMÉ: Ask Toolbar

========== Clés du Registre ==========
SUPPRIMÉ: [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A0C9DF2B-89B5-4483-8983-18A68200F1B4}]
SUPPRIMÉ: [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{0C43FE6B-E881-4AFC-B384-4AEBC90047E8}]
SUPPRIMÉ: [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{EA8FA6BE-29BE-4AF2-9352-841F83215EB0}]
SUPPRIMÉ: [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{86D4B82A-ABED-442A-BE86-96357B70F4FE}]
SUPPRIMÉ: [HKLM\SOFTWARE\Classes\CLSID\{EEE6C35B-6118-11DC-9C72-001320C79847}]
SUPPRIMÉ: HKCU\Software\InstallCore
SUPPRIMÉ: HKCU\Software\SweetIM
SUPPRIMÉ: [HKLM\Software\Classes\Installer\Products\\9EE58E3C298524145B73CBBED3CAC4D3]
SUPPRIMÉ: [HKLM\Software\Classes\Installer\Features\9EE58E3C298524145B73CBBED3CAC4D3]
SUPPRIMÉ: HKLM\Software\Classes\CLSID\{A4A0CB15-8465-4F58-A7E5-73084EA2A064}
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D15DAF33C220F91468A1D7D57C31ACD7
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D6D0EB9FDBD90C04D92A7E729058F10D
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A189D17A469616C4688D23E192996267
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\98CC8BF5A4A6E6C4ABF7051DDAB8B058
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7FFA128C2B0FF414D805FC5627883401
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D3BA76A44C779424889063D5098ED2D6
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\397C771A7BCAC904697C3EC629ED33ED
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\351716A953E21214898904032EAE2E81
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2E6768B6932D112438F047C54D180635
SUPPRIMÉ: HKLM\Software\Classes\Interface\{F4EBB1E2-21F3-4786-8CF4-16EC5925867F}
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\sweetim.exe
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\F928123A039649549966D4C29D35B1C9
SUPPRIMÉ: HKLM\Software\Classes\Installer\Features\EB6AF8AEEB922FA4392548F13812E50B
SUPPRIMÉ: HKLM\Software\Classes\Installer\Products\EB6AF8AEEB922FA4392548F13812E50B
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\EB6AF8AEEB922FA4392548F13812E50B
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9EE58E3C298524145B73CBBED3CAC4D3
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{C3E85EE9-5892-4142-B537-BCEB3DAC4C3D}
SUPPRIMÉ: HKLM\Software\Classes\Installer\Features\B2FD9C0A5B9838449838816A28001F4B
SUPPRIMÉ: HKLM\Software\Classes\Installer\Products\B2FD9C0A5B9838449838816A28001F4B
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\B2FD9C0A5B9838449838816A28001F4B
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\02F47BF73B948514FAACADD8CBBDF37D
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\07D5290CDBDAE4242926B8E6CA650501
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\080D9F5E1E95FEE4794CE438E635239E
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0E3D8A5B48622A445A7DF73FEFF32C3F
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\789034A89BAC50E4782F0A7BDBF75632
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4318DF19719275242801CBE292063A4C
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\45FC115D1FEAEF849A4E1610D6EC8BF0
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\46A5861A389ADB844AF89E31BC9DF0A1
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\49B0E1A6FF50BBE4289E4E23DE6EA0C7
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4CCCAC049F34D0540AAC13011398BEDB
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5C4389D0BFB302C479DE4178BD5D9EBA
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5D2B09BDEF4FE54418E6F3373CDBC7AC
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\61B65D3397A1FBF4CB1571B5E4F6B5B0
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\68E8A05C60DD9254591DBD16C94EDDBF
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\697E782CF574CC34CBB9566440BA12BC
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6AE27A8613CF7EA4782F2886F67295E5
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\75D5168E5E176C24981B4E5DBD991078
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7CE172051F585E04187BCB97570BFA74
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\86A901BA5265452499DCBF719C378EE3
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8724E58E6C7D00C48A0D4F3345EB2C26
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\88ABD1CD5C40EC84789A7F6EF86DAC5E
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\980289C22F80A7C4BB9323DC61255E4E
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9A4B7EF3789F871419D9302583B20C15
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A6C53B0F76C44004A8F36716213017DB
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AB676B0E1B9EFA049B9F7DDDA9645734
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B31BBB0B825EDEF45AB0FE7099C68C81
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B471D8D7319336B4CA89374ED0D7B806
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B59F2D8189784CC46A4597F2842480B0
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BC30043663AA2CA4DA1DAA9CA5FDCC75
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BD746FB95FB8E5B45BF66BE54D5FD91F
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CCF399FCD6D2D3F46BF02A1378654FC9
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D149C1355C98DE24E82CEFBD996FE06A
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DB59FDB786388EA4D897F3EE715683AC
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DB8DAD19CFBCC2049A4477183787E8C5
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E1C820A74ED67374BA048B52CB3C3804
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EC65F200D112357449C8B1BC3CFA03D0
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F327D0C73C0973644A21E8CC852267A0
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FA96423FE2B98E248A3B23548D1E22D9
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FDC83385E6C239F4C876A77A37DF581D
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\34EDDB1BFB3A2D448845F3EFD0F15A43
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\427EA997C413D1D47907CBFC7B2DB432
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\A97CEC23332751B47BA4B95BAA50C9D0
SUPPRIMÉ: HKLM\Software\Classes\MediaPlayer.GraphicsUtils
SUPPRIMÉ: HKLM\Software\Classes\MediaPlayer.GraphicsUtils.1
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F754C503375A13344B22388E18DFE87E
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1E264E0A5959A1C46BA9175A878B12EA
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E4748F9A4181FCE46A23C13B517B9420
SUPPRIMÉ: HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{79A765E1-C399-405B-85AF-466F52E918B0}
SUPPRIMÉ: HKLM\Software\Classes\Interface\{EEE6C359-6118-11DC-9C72-001320C79847}
SUPPRIMÉ: HKLM\Software\Classes\Interface\{EEE6C35A-6118-11DC-9C72-001320C79847}
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\08E33F7B61DEFF24BB9673ED7D467636
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0FF2AEFF45EEA0A48A4B33C1973B6094
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\12BF94BD06C95F343A77631402B9556A
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2124D8A8CF720FD44866190AF560228E
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\27A325ACED8CA4743A30127638591ADB
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\305B09CE8C53A214DB58887F62F25536
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\350D17402BD84234EAF7D32F08172D7C
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3EE8C5F419057E1478A654868CEE60B5
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4735D908D66E1BA46B6C2D7185A12B2B
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\69D6A6B2ED56AF24EA6335EAD6E91CA4
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\76D8378E2DDAED3428720A631F6E3BF0
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\86EDC790504E1834DBC20C9A04328FD2
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\97C3D0F82E712E241A2F969F45E3351C
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9A001B259DB7D694E818BE29B973992C
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9E7F556BF224D804D96A96F0F6344789
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BAE2EC163C6A68A48921573E0E7E199D
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BF4F885EDEE45644EB1E0C99E0162399
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C06C6662FA5B04646829E4A460857770
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CE21F3FD57B244142880EF15A165A156
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CEEB3E14ABE8270419B0FD762E18F7C6
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ED1B5E9A3BDB51349BF96E842C062D98
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FECBC2BC14DA6CD459BD59A041709836
SUPPRIMÉ: [HKLM\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}]
SUPPRIMÉ: HKCU\Software\APN
SUPPRIMÉ: HKCU\Software\Ask.com
SUPPRIMÉ: HKCU\Software\AskToolbar
SUPPRIMÉ: HKLM\Software\APN
SUPPRIMÉ: HKLM\Software\AskToolbar
SUPPRIMÉ: SearchScopes :{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}
SUPPRIMÉ: [HKLM\Software\Classes\Installer\Products\\A28B4D68DEBAA244EB686953B7074FEF]
SUPPRIMÉ: [HKLM\Software\Classes\Installer\Features\A28B4D68DEBAA244EB686953B7074FEF]
SUPPRIMÉ: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000000-6E41-4FD3-8538-502F5495E5FC}
SUPPRIMÉ: HKLM\Software\Classes\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC}
SUPPRIMÉ: HKLM\Software\Classes\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}
SUPPRIMÉ: HKLM\Software\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456}
SUPPRIMÉ: HKLM\Software\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92}
SUPPRIMÉ: HKLM\Software\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874}
SUPPRIMÉ: HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
SUPPRIMÉ: HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
SUPPRIMÉ: HKLM\Software\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E}
SUPPRIMÉ: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}
SUPPRIMÉ: HKLM\Software\Classes\AppID\GenericAskToolbar.DLL
SUPPRIMÉ: HKLM\Software\Classes\GenericAskToolbar.ToolbarWnd
SUPPRIMÉ: HKLM\Software\Classes\GenericAskToolbar.ToolbarWnd.1
SUPPRIMÉ: HKLM\Software\Classes\sim-packages
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0E12F736682067FDE4D1158D5940A82E
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1A24B5BB8521B03E0C8D908F5ABC0AE6
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\261F213D1F55267499B1F87D0CC3BCF7
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2B0D56C4F4C46D844A57FFED6F0D2852
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\49D4375FE41653242AEA4C969E4E65E0
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6AA0923513360135B272E8289C5F13FA
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6F7467AF8F29C134CBBAB394ECCFDE96
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\741B4ADF27276464790022C965AB6DA8
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7DE196B10195F5647A2B21B761F3DE01
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\922525DCC5199162F8935747CA3D8E59
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9D4F5849367142E4685ED8C25E44C5ED
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A28B4D68DEBAA244EB686953B7074FEF
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A5875B04372C19545BEB90D4D606C472
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A876D9E80B896EC44A8620248CC79296
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B66FFAB725B92594C986DE826A867888
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BCDA179D619B91648538E3394CAC94CC
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D677B1A9671D4D4004F6F2A4469E86EA
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DD1402A9DD4215A43ABDE169A41AFA0E
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E36E114A0EAD2AD46B381D23AD69CDDF
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EF8E618DB3AEDFBB384561B5C548F65E
SUPPRIMÉ: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0CFE535C35F99574E8340BFA75BF92C2

========== Valeurs du Registre ==========
SUPPRIMÉ: Toolbar: {EEE6C35B-6118-11DC-9C72-001320C79847}
SUPPRIMÉ AAKE KeyValue: C:\Program Files\SweetIM\Communicator\SweetPacksUpdateManager.exe
SUPPRIMÉ [HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks]:{00000000-6E41-4FD3-8538-502F5495E5FC}
SUPPRIMÉ: Toolbar: {D4027C7F-154A-4066-A1AD-4243D8127440}
SUPPRIMÉ: FirewallRaz (SP) : %windir%\Network Diagnostic\xpnetdiag.exe
SUPPRIMÉ: FirewallRaz (SP) : C:\Program Files\Bonjour\mDNSResponder.exe
SUPPRIMÉ: FirewallRaz (SP) : C:\Program Files\Fichiers communs\Comodo\GeekBuddyRSP.exe
SUPPRIMÉ: FirewallRaz (DP) : %windir%\Network Diagnostic\xpnetdiag.exe
SUPPRIMÉ: FirewallRaz (DP) : %windir%\system32\sessmgr.exe
Aucune valeur présente dans la clé d'exception du registre (FirewallRaz)

========== Dossiers ==========
Aucun dossiers CLSID Local utilisateur vide

========== Fichiers ==========
SUPPRIMÉ: c:\documents and settings\user\application data\mozilla\firefox\profiles\64xmy4z0.default\searchplugins\askcom.xml
SUPPRIMÉS Temporaires Windows (1240) (3 766 115 619 octets)


========== Récapitulatif ==========
147 : Clés du Registre
10 : Valeurs du Registre
1 : Dossiers
2 : Fichiers
4 : Logiciels


End of clean in 01mn 34s

========== Chemin de fichier rapport ==========
C:\Documents and Settings\User\Application Data\ZHP\ZHPFix[R1].txt - 20/10/2013 17:25:45 [18554]
0
hom2ver Messages postés 78 Date d'inscription vendredi 17 août 2007 Statut Membre Dernière intervention 28 octobre 2013
22 oct. 2013 à 11:09
HELP
0
Utilisateur anonyme
22 oct. 2013 à 22:07
Bonsoir

As tu encore des soucis?

A savoir j'ai aussi une vie privée et professionnelle !!!

@+
0
hom2ver Messages postés 78 Date d'inscription vendredi 17 août 2007 Statut Membre Dernière intervention 28 octobre 2013
Modifié par hom2ver le 24/10/2013 à 00:16
Bonsoir,

j'avais peur qu'on m'oublie c'est tout

j'ai pu fermer la page en question !elle était toute fatiguée

c'est ZHPFix qui à fait le nettoyage alors ? si je repasse un coup de ZHpDiag, tu

saurais déchifrer son rapport pour savoir si ma machine est toujours infectée ?
0
Utilisateur anonyme
24 oct. 2013 à 18:31
Bonsoir

As tu encore des soucis?

@+
0
hom2ver Messages postés 78 Date d'inscription vendredi 17 août 2007 Statut Membre Dernière intervention 28 octobre 2013
25 oct. 2013 à 00:25
Bonsoir,

apparemment non mais j'aimerai m'assurer que mon PC n'est plus infecté, comme je te le disais dans mon dernier message.
0
Utilisateur anonyme
25 oct. 2013 à 13:04
Bonjour

Pour moi c'est bon.

On avance:

Télécharge DelFix de Xplode

Lance le.
Tu as 5 choix :

Réactiver l'UAC
Supprimer les outils de désinfection (cocher par défaut)

Effectuer une sauvegarde du registre
Purger la restauration de système
Réinitialisation des paramètres usine

Tu coches ceux qui sont en gras
et tu exécutes
Le rapport se trouve ici généralement
C:\DelFix.txt



Le reste de la sécurité : http://forum.malekal.com/comment-securiser-son-ordinateur.html


@+
0
hom2ver Messages postés 78 Date d'inscription vendredi 17 août 2007 Statut Membre Dernière intervention 28 octobre 2013
25 oct. 2013 à 13:22
Salut,

voilà: # DelFix v10.5 - Rapport créé le 25/10/2013 à 13:19:46
# Mis à jour le 17/10/2013 par Xplode
# Nom d'utilisateur : User - USER-5824E3CCA0
# Système d'exploitation : Microsoft Windows XP Service Pack 3 (32 bits)

~ Suppression des outils de désinfection ...

Supprimé : C:\_OTL
Supprimé : C:\Documents and Settings\All Users\Menu Démarrer\Programmes\ZHP
Supprimé : C:\Documents and Settings\User\Bureau\RK_Quarantine
Supprimé : C:\Program Files\ZHPDiag
Supprimé : C:\Documents and Settings\User\Bureau\OTL.Txt
Supprimé : C:\Documents and Settings\User\Bureau\RKreport[0]_D_10172013_034042.txt
Supprimé : C:\Documents and Settings\User\Bureau\RKreport[0]_D_10182013_111606.txt
Supprimé : C:\Documents and Settings\User\Bureau\ZHPDiag.lnk
Supprimé : C:\Documents and Settings\User\Bureau\ZHPDiag.txt
Supprimé : C:\Documents and Settings\User\Bureau\ZHPFix.lnk
Supprimé : C:\Documents and Settings\User\Bureau\ZHPFixReport.txt
Supprimé : C:\Documents and Settings\User\Mes documents\Téléchargements\OTL.Txt
Supprimé : C:\Documents and Settings\User\Mes documents\Téléchargements\OTL.exe
Supprimé : C:\Documents and Settings\User\Mes documents\Téléchargements\proxyfirefoxenable.exe
Supprimé : C:\Documents and Settings\User\Mes documents\Téléchargements\proxyfirefoxovhenable.exe
Supprimé : C:\Documents and Settings\User\Mes documents\Téléchargements\RogueKiller.exe
Supprimé : C:\Documents and Settings\User\Mes documents\Téléchargements\ZHPDiag2(1).exe
Supprimé : C:\Documents and Settings\User\Mes documents\Téléchargements\ZHPDiag2.exe
Supprimée : HKLM\SOFTWARE\OldTimer Tools
Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ZHPDiag_is1

~ Purge de la restauration système ...

Supprimé : RP #203 [Point de vérification système | 08/24/2013 11:12:44]
Supprimé : RP #204 [Point de vérification système | 08/26/2013 13:14:57]
Supprimé : RP #205 [Point de vérification système | 08/27/2013 13:32:49]
Supprimé : RP #206 [Point de vérification système | 08/28/2013 16:41:06]
Supprimé : RP #207 [Point de vérification système | 08/29/2013 18:26:21]
Supprimé : RP #208 [Point de vérification système | 08/30/2013 20:16:50]
Supprimé : RP #209 [Point de vérification système | 09/01/2013 10:22:06]
Supprimé : RP #210 [Point de vérification système | 09/02/2013 11:05:10]
Supprimé : RP #211 [Point de vérification système | 09/03/2013 12:40:44]
Supprimé : RP #212 [Point de vérification système | 09/05/2013 01:23:37]
Supprimé : RP #213 [Point de vérification système | 09/06/2013 02:27:47]
Supprimé : RP #214 [Point de vérification système | 09/07/2013 13:48:47]
Supprimé : RP #215 [Point de vérification système | 09/08/2013 14:28:46]
Supprimé : RP #216 [Point de vérification système | 09/09/2013 17:14:10]
Supprimé : RP #217 [Point de vérification système | 09/10/2013 17:28:15]
Supprimé : RP #218 [Point de vérification système | 09/11/2013 19:35:44]
Supprimé : RP #219 [Point de vérification système | 09/13/2013 10:04:17]
Supprimé : RP #220 [Point de vérification système | 09/14/2013 11:19:50]
Supprimé : RP #221 [Point de vérification système | 09/15/2013 12:44:26]
Supprimé : RP #222 [Point de vérification système | 09/16/2013 13:53:16]
Supprimé : RP #223 [Point de vérification système | 09/17/2013 16:13:44]
Supprimé : RP #224 [Point de vérification système | 09/18/2013 16:33:05]
Supprimé : RP #225 [Point de vérification système | 09/19/2013 23:12:42]
Supprimé : RP #226 [Point de vérification système | 09/21/2013 12:06:57]
Supprimé : RP #227 [Point de vérification système | 09/22/2013 13:33:04]
Supprimé : RP #228 [Point de vérification système | 09/23/2013 21:22:19]
Supprimé : RP #229 [Point de vérification système | 09/24/2013 21:59:31]
Supprimé : RP #230 [Point de vérification système | 09/26/2013 00:47:08]
Supprimé : RP #231 [Point de vérification système | 09/27/2013 06:32:05]
Supprimé : RP #232 [Point de vérification système | 09/28/2013 10:06:18]
Supprimé : RP #233 [Point de vérification système | 09/29/2013 14:32:57]
Supprimé : RP #234 [Point de vérification système | 09/30/2013 19:26:04]
Supprimé : RP #235 [Point de vérification système | 10/01/2013 19:45:54]
Supprimé : RP #236 [Point de vérification système | 10/02/2013 20:29:58]
Supprimé : RP #237 [Point de vérification système | 10/04/2013 09:58:31]
Supprimé : RP #238 [Point de vérification système | 10/05/2013 11:06:00]
Supprimé : RP #239 [Point de vérification système | 10/06/2013 13:50:11]
Supprimé : RP #240 [Point de vérification système | 10/07/2013 13:55:26]
Supprimé : RP #241 [Point de vérification système | 10/08/2013 14:18:39]
Supprimé : RP #242 [Point de vérification système | 10/09/2013 15:30:53]
Supprimé : RP #243 [Point de vérification système | 10/10/2013 15:54:01]
Supprimé : RP #244 [Point de vérification système | 10/12/2013 14:10:34]
Supprimé : RP #245 [Point de vérification système | 10/13/2013 15:24:50]
Supprimé : RP #246 [Point de vérification système | 10/14/2013 15:59:41]
Supprimé : RP #247 [Point de vérification système | 10/16/2013 08:33:21]
Supprimé : RP #248 [Point de vérification système | 10/17/2013 11:24:33]
Supprimé : RP #249 [Point de vérification système | 10/18/2013 11:26:48]
Supprimé : RP #250 [Point de vérification système | 10/20/2013 16:53:46]
Supprimé : RP #251 [Point de vérification système | 10/21/2013 20:24:52]
Supprimé : RP #252 [Point de vérification système | 10/23/2013 07:25:14]
Supprimé : RP #253 [Point de vérification système | 10/24/2013 11:26:08]

Nouveau point de restauration créé !

########## - EOF - ##########
0