Pc infecter a mort...help!!!

Résolu
kevin -  
billmaxime Messages postés 50525 Date d'inscription   Statut Contributeur Dernière intervention   -
Bonjour,

Mon beau-père m'a passé son pc car il a des problèmes. Et effectivement au démarrage plein de pages bizarre et des programmes a la con.

Du coup je lance adwcleaner et Malwarebytes Anti-Malware et j'efface déjà beaucoup de choses, des centaines. Le pc va beaucoup mieux mais il y a des choses qui ne partent pas. Du coup je lance ZHPdiag mais la je suis un peut bloqué je sais pas trop quoi faire avec le rapport.

30 réponses

  • 1
  • 2
  1. geekatchoum63 Messages postés 54 Statut Membre 13
     
    Salut si tu veux pas t'embêter reboot son pc à l'aide du cd d'installation windows comme ça son pc sera tout neuf, mais attention à bien sauvegarder les données sur un support externe.
    1
  2. kevin
     
    Eh bien pour tout dire j'ai pas le cd d'installation. Ce serais pas possible de nettoyer avec zhpfix?
    Voilà le rapport:

    ~ Rapport de ZHPDiag v2014.8.13.118 - Nicolas Coolman (13-08-14)
    ~ Lancé par Home (14-08-14 15:35:41)
    ~ Adresse du Site Web http://nicolascoolman.fr
    ~ Adresse du Forum http://forum.nicolascoolman.fr
    ~ Traduit par Nicolas Coolman
    ~ Etat de la version : Version à jour.
    ~ Liste blanche : Désactivée par l'utilisateur
    ~ Elévation des Privilèges : OK
    ~ User Account Control (UAC): Deactivate by program

    ---\\ Navigateurs Internet
    MSIE: Internet Explorer v10.0.9200.17028
    MFIE: Mozilla Firefox 31.0
    GCIE: Google Chrome v36.0.1985.125 (Defaut)

    ---\\ Informations sur les produits Windows
    ~ Langage: Français
    Windows 8, 64-bit (Build 9200)
    Windows Server License Manager Script : OK
    ~ Windows(R) Operating System, OEM_DM channel
    Windows ID Activation : OK
    ~ Windows Partial Key : JTV36
    Windows License : OK
    ~ Windows Remaining Initializations Number : 998
    Software Protection Service (Protection logicielle) : OK
    Windows Automatic Updates : OK
    Windows Activation Technologies : OK

    ---\\ Logiciels de protection du système
    avast! Free Antivirus v9.0.2021
    Malwarebytes Anti-Malware version 2.0.2.1012
    Windows Defender W8 (Deactivate)

    ---\\ Logiciels d'optimisation du système

    ---\\ Logiciels de partage PeerToPeer

    ---\\ Surveillance de Logiciels
    Adobe Flash Player 14 Plugin
    Adobe Reader X
    Java 7 Update 60

    ---\\ Informations sur le système
    ~ Processor: Intel64 Family 6 Model 42 Stepping 7, GenuineIntel
    ~ Operating System: 64 Bits
    Boot mode: Normal (Normal boot)
    Total RAM: 8082 MB (71% free)
    System Restore: Activé (Enable)
    System drive C: has 333 GB (74%) free of 447 GB

    ---\\ Mode de connexion au système
    ~ Computer Name: HP
    ~ User Name: Home
    ~ All Users Names: HomeGroupUser$, Home, Administrateur,
    ~ Unselected Option: None
    Logged in as Administrator

    ---\\ Variables d'environnement
    ~ System Unit : C:\
    ~ %AppZHP% : C:\Users\Home\AppData\Roaming\ZHP\
    ~ %AppData% : C:\Users\Home\AppData\Roaming\
    ~ %Desktop% : C:\Users\Home\Desktop\
    ~ %Favorites% : C:\Users\Home\Favorites\
    ~ %LocalAppData% : C:\Users\Home\AppData\Local\
    ~ %StartMenu% : C:\Users\Home\AppData\Roaming\Microsoft\Windows\Start Menu\
    ~ %Windir% : C:\Windows\
    ~ %System% : C:\Windows\System32\

    ---\\ Enumération des unités disques
    C: Hard drive, Flash drive, Thumb drive (Free 333 Go of 447 Go)
    D: Hard drive, Flash drive, Thumb drive (Free 2 Go of 18 Go)
    E: CD-ROM drive (Not Inserted)
    F: Floppy drive, Flash card reader, USB Key (Free 0 Go of 0 Go)

    ---\\ Etat du Centre de Sécurité Windows
    [HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiSpywareOverride: OK
    [HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusOverride: OK
    [HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallOverride: OK
    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified
    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: OK
    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: OK
    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK
    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK
    [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK
    [HKLM\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK
    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install] LastSuccessTime : OK
    ~ Security Center: 41 Scanned in 00mn 00s

    ---\\ Recherche particulière de fichiers génériques
    [MD5.0E8E6463F81C80AFBED533E0F1F8895D] - (.Microsoft Corporation - Explorateur Windows.) (.01-06-13 - 12:34:21.) -- C:\Windows\Explorer.exe [2391280]
    [MD5.FE9AB232B56A12224E8A3F3F9878C9A3] - (.Microsoft Corporation - Application de démarrage de Windows.) (.26-07-12 - 04:08:50.) -- C:\Windows\System32\Wininit.exe [132608]
    [MD5.27E552632E6394DE0FA555EFDBA29A49] - (.Microsoft Corporation - Extensions Internet pour Win32.) (.19-06-14 - 03:12:11.) -- C:\Windows\System32\wininet.dll [2239488]
    [MD5.75DD70A14145499C9F7D903CF9A8C91B] - (.Microsoft Corporation - Application d'ouverture de session Windows.) (.12-04-14 - 10:10:31.) -- C:\Windows\System32\Winlogon.exe [578048]
    [MD5.9448F5740A037EC0C18F0E9177232DD0] - (.Microsoft Corporation - Bibliothèque de licences.) (.26-07-12 - 04:07:20.) -- C:\Windows\System32\sppcomapi.dll [273408]
    [MD5.FE7FB9612D354EB41DF4F0FF5D6FB259] - (.Microsoft Corporation - Pilote de fonction connexe pour WinSock.) (.29-05-14 - 23:24:46.) -- C:\Windows\system32\Drivers\AFD.sys [576512]
    [MD5.A721FF570C2387E383BDDEA9632863C9] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.26-07-12 - 06:00:48.) -- C:\Windows\system32\Drivers\atapi.sys [25840]
    [MD5.990B1BABE6E81FB18E65A87EBEFB1772] - (.Microsoft Corporation - CD-ROM File System Driver.) (.26-07-12 - 03:30:10.) -- C:\Windows\system32\Drivers\Cdfs.sys [108544]
    [MD5.339BFF85D788268752DA8C9644B188EE] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.26-07-12 - 03:26:36.) -- C:\Windows\system32\Drivers\Cdrom.sys [174080]
    [MD5.431141C6859990824D17F71C30A78728] - (.Microsoft Corporation - DFS Namespace Client Driver.) (.16-01-14 - 00:42:58.) -- C:\Windows\system32\Drivers\DfsC.sys [118784]
    [MD5.3865C4E388B31940C8BB9F73D9738E93] - (.Microsoft Corporation - High Definition Audio Bus Driver.) (.08-02-14 - 05:34:16.) -- C:\Windows\system32\Drivers\HDAudBus.sys [71168]
    [MD5.C9E9CBF73AFFBFE3E801EFB516787BA3] - (.Microsoft Corporation - Pilote de port i8042.) (.26-07-12 - 03:28:51.) -- C:\Windows\system32\Drivers\i8042prt.sys [112640]
    [MD5.3969B9C218DD3FAA9F4ED2FFC3651C02] - (.Microsoft Corporation - IP Network Address Translator.) (.26-07-12 - 03:23:01.) -- C:\Windows\system32\Drivers\IpNat.sys [145920]
    [MD5.7A761AEE58658378BBA45D360F874CB0] - (.Microsoft Corporation - Minirdr SMB Windows NT.) (.27-02-14 - 00:18:55.) -- C:\Windows\system32\Drivers\MRxSmb.sys [370688]
    [MD5.7CEC25C682D319D484630B3952C31A11] - (.Microsoft Corporation - MBT Transport driver.) (.26-07-12 - 03:24:28.) -- C:\Windows\system32\Drivers\netBT.sys [331776]
    [MD5.7BE3EDFFA3216F989A6BDCB14795DD08] - (.Microsoft Corporation - Pilote du système de fichiers NT.) (.27-01-14 - 04:39:40.) -- C:\Windows\system32\Drivers\ntfs.sys [1939288]
    [MD5.4563DAF8C6A740AD7F501E219BD10766] - (.Microsoft Corporation - Pilote de port parallèle.) (.26-07-12 - 03:29:53.) -- C:\Windows\system32\Drivers\Parport.sys [105984]
    [MD5.A14D625C5AEE5FFE0F47D1A1D419FAAE] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.26-07-12 - 03:23:17.) -- C:\Windows\system32\Drivers\Rasl2tp.sys [124928]
    [MD5.B2A3AD74FF2E2FFA73AF2567108231B3] - (.Microsoft Corporation - Redirecteur de périphérique de Microsoft RDP.) (.26-07-12 - 03:25:18.) -- C:\Windows\system32\Drivers\rdpdr.sys [179712]
    [MD5.73DC722CE5DF26D7638CE2446F2655C7] - (.Microsoft Corporation - TDI Translation Driver.) (.26-07-12 - 06:26:47.) -- C:\Windows\system32\Drivers\tdx.sys [117248]
    [MD5.78A5BBA3819FFFC62FFEC3E2220D102D] - (.Microsoft Corporation - Pilote de cliché instantané du volume.) (.01-06-13 - 12:26:33.) -- C:\Windows\system32\Drivers\volsnap.sys [327936]
    ~ Generic Processes: Scanned in 00mn 00s

    ---\\ Etat des fichiers cachés (Caché/Total)
    ~ Mes images (My Pictures) : 2/11413
    ~ Mes musiques (My Musics) : 1/14
    ~ Mes Videos (My Videos) : 1/2
    ~ Mes Favoris (My Favorites) : 1/8
    ~ Mes Documents (My Documents) : 3/2309
    ~ Mon Bureau (My Desktop) : 2/950
    ~ Menu demarrer (Programs) : 1/37
    ~ Hidden Files: Scanned in 00mn 18s

    ---\\ Processus lancés
    [MD5.B7F55E2AE978D3D34F7876EE5D689AAE] - (.CyberLink - YouCam Mirage.) -- C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe [136488] [PID.3996]
    [MD5.C2FCA465DC8C03E87DF7CFD6089267F9] - (...) -- C:\Users\Home\AppData\Roaming\Gameo\gameo.exe [41402880] [PID.2756]
    [MD5.43FCAD8DC068E94B170353DAD02A0053] - (.IVT Corporation - Bluetooth Application.) -- C:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\BtTray.exe [363520] [PID.2364]
    [MD5.B7995C675014EEBE77A0BEB7AFCCFC08] - (.CyberLink Corp. - PowerDVD RC Service.) -- C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [91432] [PID.920]
    [MD5.749949494676218FFA99501F4AA22ECC] - (.OpenOffice.org - OpenOffice.org 3.4.1.) -- C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe [10376704] [PID.388]
    [MD5.9F3655267BA37004F519ABDDB3AEE244] - (.Hewlett-Packard Development Company, L.P. - HP CoolSense.) -- C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe [1342008] [PID.3848]
    [MD5.4EE367B8B1964160A1F1B80095183D3A] - (.OpenOffice.org - OpenOffice.org 3.4.1.) -- C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin [10368512] [PID.3768]
    [MD5.6198A9BC15ED77F318D5DDD1918CF1D1] - (.Hewlett-Packard Development Company, L.P. - HP Message Service.) -- C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe [581024] [PID.240]
    [MD5.26B558B2D31C7425B455B00E562EAD93] - (.AVAST Software - avast! Antivirus.) -- C:\Program Files\AVAST Software\Avast\avastui.exe [4085896] [PID.3964]
    [MD5.EDAD4A8A1D46AFCF9E76B996D55116EB] - (.Oracle Corporation - Java(TM) Update Scheduler.) -- C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896] [PID.1888]
    [MD5.10F36FB8CD6218CD7F818268E0F3F9C6] - (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe [275568] [PID.5512]
    [MD5.02F8883595A2B3D7FFA11C71EAC68473] - (.Mozilla Corporation - Plugin Container for Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe [18544] [PID.5308]
    [MD5.192FFD3F99A0847740670AE711CB455A] - (.Adobe Systems, Inc. - Adobe Flash Player 14.0 r0.) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_14_0_0_145.exe [1869488] [PID.3292]
    [MD5.DC2E338E63159454B71659D82515A04E] - (.Nicolas Coolman - ZHPDiag.) -- C:\Program Files (x86)\ZHPDiag\ZHPDiag.exe [8091648] [PID.1408]
    ~ Processes Running: Scanned in 00mn 01s

    ---\\ Google Chrome, Démarrage,Recherche,Extensions (G0,G1,G2)
    C:\Users\Home\AppData\Local\Google\Chrome\User Data\Default\Preferences
    G0 - GCSP: Preference [User Data\Default][HomePage] http://www.msn.com
    G2 - GCE: Preference [User Data\Default] [ahfgeienlihckogmohjhadlkjgocpleb] Google Store v.0.2 (Activé)
    G02 - GCE: Preference [User Data\Default] [aohghmighlieiainnegkcijnfilokake] Google Docs v.0.7 (Activé)
    G2 - GCE: Preference [User Data\Default] [apdfllckaahabafndbhieahigkjlhalf] Google Drive v.6.3 (Activé)
    G2 - GCE: Preference [User Data\Default] [blpcfgokakmgnkcojhhkbfbldkacnbeo] YouTube v.4.2.6 (Activé)
    G2 - GCE: Preference [User Data\Default] [coobgpohoikkiipiblmjeljniedjpjpf] Recherche Google v.0.0.0.20 (Activé)
    G2 - GCE: Preference [User Data\Default] [eemcgdkfndhakfknompkggombfjjjeno] Bookmark Manager v.0.1 (Activé)
    G2 - GCE: Preference [User Data\Default] [ennkphjdgehloodpbhlhldgbnhmacadg] Settings v.0.2 (Activé)
    G2 - GCE: Preference [User Data\Default] [gfdkimpbcpahaombhbimeihdjnejgicl] Feedback v.1.0 (Activé)
    G2 - GCE: Preference [User Data\Default] [gomekmidlodglbbmalcneegieacbdmki] avast! Online Security v.9.0.2021.112, (Désactivé)
    G2 - GCE: Preference [User Data\Default] [iklgpchfbohgmghgfagediakopecfmbm] videos MediaPlay-Air v.1.26.68, (Désactivé) =>PUP.CrossRider
    G2 - GCE: Preference [User Data\Default] [kmendfapggjehodndflmmgagdbamhnfd] CryptoTokenExtension v.0.0.1 (Activé)
    G2 - GCE: Preference [User Data\Default] [mfehgcgbbipciphmccgaenjidiccnmng] Cloud Print v.0.1 (Activé)
    G2 - GCE: Preference [User Data\Default] [mfffpogegjflfpflabcdkioaeobkgjik] GaiaAuthExtension v.0.0.1, (Activé)
    G2 - GCE: Preference [User Data\Default] [mgndgikekgjfcpckkfioiadnlibdjbkf] Chrome v.0.1 (Activé)
    G2 - GCE: Preference [User Data\Default] [neajdppkdcdipfabeoofebfddakdcjhd] Google Network Speech v.1.0 (Activé)
    G2 - GCE: Preference [User Data\Default] [nkeimhogjdpnpccoofpliimaahmaaome] Hangout Services v.1.0 (Activé)
    G2 - GCE: Preference [User Data\Default] [nmmhkkegccagdldgiimedpiccmgmieda] Google Wallet v.0.0.6.1 (Activé)
    G2 - GCE: Preference [User Data\Default] [pafkbggdmjlpgkdkcbjmhmfcdpncadgh] Google Now v.1.2.0.1 (Activé)
    G2 - GCE: Preference [User Data\Default] [pjkljhegncpnkpknbcohdijeoejaedia] Gmail v.7 (Activé)

    ---\\ Liste des dossiers d'extension Google Chrome
    G2 - EXT: C:\Users\Home\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [Google Docs]
    G2 - EXT: C:\Users\Home\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [Google Drive]
    G2 - EXT: C:\Users\Home\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [YouTube]
    G2 - EXT: C:\Users\Home\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [Recherche Google]
    G2 - EXT: C:\Users\Home\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [Google Wallet]
    G2 - EXT: C:\Users\Home\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [Gmail]
    ~ Google Lines Browser: 26 Scanned in 00mn 00s

    ---\\ Mozilla Firefox, Plugins,Demarrage,Recherche,Extensions (P2,M0,M1,M2,M3)
    C:\Users\Home\AppData\Roaming\Mozilla\Firefox\Profiles\wiayun8r.default\prefs.js
    M3 - MFPP: Plugins - [Home] -- C:\Users\Home\AppData\Roaming\Mozilla\Firefox\Profiles\wiayun8r.default\searchplugins\bing-avast.xml
    M2 - MFEP: RegExtension {e4f94d1e-2f53-401e-8885-681602c0ddd8} . (...) -- C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi
    P2 - FPN: [HKLM] [@adobe.com/FlashPlayer] - (...) -- C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_145.dll
    P2 - FPN: [HKLM] [@Microsoft.com/NpCtrl,version=1.0] - (. Microsoft Corporation - 5.1.30514.0.) -- c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll
    P2 - FPN: [HKCU] [@Skype Limited.com/Facebook Video Calling Plugin] - (.Skype Limited - Facebook Video Calling Plugin.) -- C:\Users\Home\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll
    P2 - FPN: [HKCU] [@squareclock.com/SQ3DPlayer_Production_HBMV1] - (.SquareClock SAS - SquareClock 3D Plugin - Production_HBMV1.) -- C:\Users\Home\AppData\Local\SquareClock.Production_HBMV1\NPSQ3D.dll
    ~ Firefox Browser: 6 Scanned in 00mn 00s

    ---\\ Internet Explorer, Démarrage,Recherche,URLSearchHook, Phishing (R0,R1,R3,R4)
    R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com
    R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
    R0 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com
    R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.bing.com
    R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.msn.com
    R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
    R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
    R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons
    R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk
    R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com
    R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\AboutURLs,Tabs = about:newtab
    R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.bing.com
    R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons
    R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk
    R3 - URLSearchHook: Microsoft Url Search Hook [64Bits] - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} . (.Microsoft Corporation - Navigateur Internet.) (10.00.9200.16384 (win8_rtm.120725-1247)) -- C:\Windows\SysWOW64\ieframe.dll
    ~ IE Browser: 15 Scanned in 00mn 00s

    ---\\ Internet Explorer, Proxy Management (R5)
    R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key
    R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
    R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
    R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
    R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll
    ~ Proxy management: Scanned in 00mn 00s

    ---\\ Analyse des lignes F0, F1, F2, F3 - IniFiles, Autoloading programs
    F2 - REG:system.ini: USERINIT=C:\Windows\system32\userinit.exe,
    F2 - REG:system.ini: Shell=C:\Windows\explorer.exe
    F2 - REG:system.ini: VMApplet=C:\Windows\System32\SystemPropertiesPerformance.exe
    ~ Keys: Scanned in 00mn 00s

    ---\\ Hosts file redirection (O1)
    ~ Le fichier hôte est sain (The hosts file is clean).
    ~ Hosts File: Scanned in 00mn 00s

    ---\\ Browser Helper Objects de navigateur (O2)
    O2 - BHO: MSS+ Identifier [64Bits] - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} Clé orpheline
    O2 - BHO: Java(tm) Plug-In SSV Helper [64Bits] - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} . (.Oracle Corporation - Java(TM) Platform SE binary.) -- C:\Program Files (x86)\Java\jre7\bin\ssv.dll
    O2 - BHO: avast! Online Security [64Bits] - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} . (.AVAST Software - IE Webrep plugin.) -- C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
    O2 - BHO: Windows Live Messenger Companion Helper [64Bits] - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} . (.Microsoft Corporation - Windows Live Messenger Companion Core.) -- C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper [64Bits] - {DBC80044-A445-435b-BC74-9C25C1C588A9} . (.Oracle Corporation - Java(TM) Platform SE binary.) -- C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
    O2 - BHO: HP Network Check Helper [64Bits] - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} . (.Hewlett-Packard - HP Network Check IE Plug-in.) -- C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll
    ~ BHO: 8 Scanned in 00mn 00s

    ---\\ Internet Explorer Toolbars (O3)
    O3 - Toolbar: avast! Online Security - [HKLM]{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} . (...) -- (.not file.)
    O3 - Toolbar: (no name) - [HKLM]{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} Clé orpheline
    ~ Toolbar: Scanned in 00mn 00s

    ---\\ Autres liens utilisateurs (O4)
    O4 - GS\Desktop [Home]: Chatpassion.lnk . (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe http://chatpassion.org =>Hijacker.Browsers
    O4 - GS\Desktop [Home]: Savoir.lnk . (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe http://savoir.fr =>Hijacker.Browsers
    O4 - GS\Desktop [Home]: Telecharger-gratuit.lnk . (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe http://telecharger-gratuit.com =>Hijacker.Browsers
    ~ Global Startup: 3 Scanned in 00mn 01s

    ---\\ Applications lancées au démarrage du système (O4)
    O4 - HKLM\..\Run: [IgfxTray] . (.Intel Corporation - igfxTray Module.) -- C:\Windows\system32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] . (.Intel Corporation - hkcmd Module.) -- C:\Windows\system32\hkcmd.exe
    O4 - HKLM\..\Run: [Persistence] . (.Intel Corporation - persistence Module.) -- C:\Windows\system32\igfxpers.exe
    O4 - HKLM\..\Run: [SysTrayApp] . (.IDT, Inc. - IDT PC Audio.) -- C:\Program Files\IDT\WDM\sttray64.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files (x86)\Synaptics\SynTP\SynTPEnh.exe (.not file.)
    O4 - HKLM\..\RunOnce: [NCPluginUpdater] . (.Hewlett-Packard - NCPluginUpdater.) -- C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe
    O4 - HKCU\..\Run: [GarminExpressTrayApp] . (.Garmin Ltd or its subsidiaries - Express Tray.) -- C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe
    O4 - HKCU\..\Run: [Google+ Auto Backup] . (.Google Inc. - AutoBackup.) -- C:\Users\Home\AppData\Local\Programs\Google\Google+ Auto Backup\Google+ Auto Backup.exe
    O4 - HKCU\..\Run: [Facebook Update] . (.Facebook Inc. - Programme d'installation de Facebook.) -- C:\Users\Home\AppData\Local\Facebook\Update\FacebookUpdate.exe
    O4 - HKLM\..\Wow6432Node\Run: [BtTray] . (.IVT Corporation - Bluetooth Application.) -- C:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\BtTray.exe
    O4 - HKLM\..\Wow6432Node\Run: [RemoteControl10] . (.CyberLink Corp. - PowerDVD RC Service.) -- C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
    O4 - HKLM\..\Wow6432Node\Run: [HP CoolSense] . (.Hewlett-Packard Development Company, L.P. - HP CoolSense.) -- C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe
    O4 - HKLM\..\Wow6432Node\Run: [Adobe ARM] . (.Adobe Systems Incorporated - Adobe Reader and Acrobat Manager.) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe =>.Adobe Systems Incorporated
    O4 - HKLM\..\Wow6432Node\Run: [HP Quick Launch] . (.Hewlett-Packard Development Company, L.P. - HP Message Service.) -- C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
    O4 - HKLM\..\Wow6432Node\Run: [beid] C:\Program Files (x86)\Belgium Identity Card\beid35gui.exe (.not file.)
    O4 - HKLM\..\Wow6432Node\Run: [AvastUI.exe] . (.AVAST Software - avast! Antivirus.) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe
    O4 - HKLM\..\Wow6432Node\Run: [SunJavaUpdateSched] . (.Oracle Corporation - Java(TM) Update Scheduler.) -- C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe =>.Oracle Corporation
    O4 - HKLM\..\Wow6432Node\RunOnce: [Malwarebytes Anti-Malware (cleanup)] . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\mbamdor.exe
    O4 - HKUS\.DEFAULT\..\Run: [GarminExpressTrayApp] . (.Garmin Ltd or its subsidiaries - Express Tray.) -- C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe
    O4 - HKUS\S-1-5-18\..\Run: [GarminExpressTrayApp] . (.Garmin Ltd or its subsidiaries - Express Tray.) -- C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe
    O4 - HKUS\S-1-5-21-2254641191-106435527-948302892-1001\..\Run: [GarminExpressTrayApp] . (.Garmin Ltd or its subsidiaries - Express Tray.) -- C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe
    O4 - HKUS\S-1-5-21-2254641191-106435527-948302892-1001\..\Run: [Google+ Auto Backup] . (.Google Inc. - AutoBackup.) -- C:\Users\Home\AppData\Local\Programs\Google\Google+ Auto Backup\Google+ Auto Backup.exe
    O4 - HKUS\S-1-5-21-2254641191-106435527-948302892-1001\..\Run: [Facebook Update] . (.Facebook Inc. - Programme d'installation de Facebook.) -- C:\Users\Home\AppData\Local\Facebook\Update\FacebookUpdate.exe
    ~ Application: Scanned in 00mn 00s

    ---\\ Invisibilité de l'icône d'options IE dans le panneau de Configuration (O5)
    O5 - control.ini: [HKLM\..\Control Panel] inetcpl.cpl=no
    ~ IE Control Panel: 1 Scanned in 00mn 00s

    ---\\ Boutons situés sur la barre d'outils principale d'Internet Explorer (O9)
    O9 - Extra button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll,-102 [64Bits] - {25510184-5A38-4A99-B273-DCA8EEF6CD08} . (...) -- C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\Resources\Icons\HP.ico
    ~ IE Extra Buttons: Scanned in 00mn 00s

    ---\\ Winsock hijacker (Layered Service Provider) (O10)
    O10 - WLSP:\000000000001\Winsock LSP File . (.Microsoft Corporation - Fournisseur Shim d'affectation de noms de messagerie.) -- C:\Windows\system32\napinsp.dll
    O10 - WLSP:\000000000002\Winsock LSP File . (.Microsoft Corporation - Fournisseur d'espace de noms PNRP.) -- C:\Windows\system32\pnrpnsp.dll
    O10 - WLSP:\000000000003\Winsock LSP File . (.Microsoft Corporation - Fournisseur d'espace de noms PNRP.) -- C:\Windows\system32\pnrpnsp.dll
    O10 - WLSP:\000000000004\Winsock LSP File . (.Microsoft Corporation - Network Location Awareness 2.) -- C:\Windows\system32\NLAapi.dll
    O10 - WLSP:\000000000005\Winsock LSP File . (.Microsoft Corporation - Fournisseur de service Sockets 2.0 de Microsoft Windows.) -- C:\Windows\system32\mswsock.dll =>.Microsoft Corporation
    O10 - WLSP:\000000000006\Winsock LSP File . (.Microsoft Corporation - LDAP RnR Provider DLL.) -- C:\Windows\system32\winrnr.dll
    O10 - WLSP:\000000000007\Winsock LSP File . (.Microsoft Corporation - Windows Sockets Helper DLL.) -- C:\Windows\system32\wshbth.dll
    ~ Winsock: 7 Scanned in 00mn 00s

    ---\\ Modification Domaine/Adresses DNS (O17)
    O17 - HKLM\System\CCS\Services\Tcpip\..\{49E07008-D08C-4B6B-9492-C634D6FF11F1}: DhcpNameServer = 40.24.1.201 40.24.1.202
    O17 - HKLM\System\CCS\Services\Tcpip\..\{964150C9-D331-469F-A3A6-4C3725D87BF0}: DhcpNameServer = 192.168.1.1
    O17 - HKLM\System\CCS\Services\Tcpip\..\{49E07008-D08C-4B6B-9492-C634D6FF11F1}: DhcpDomain = E1-Line.com
    O17 - HKLM\System\CS1\Services\Tcpip\..\{49E07008-D08C-4B6B-9492-C634D6FF11F1}: DhcpNameServer = 40.24.1.201 40.24.1.202
    O17 - HKLM\System\CS1\Services\Tcpip\..\{964150C9-D331-469F-A3A6-4C3725D87BF0}: DhcpNameServer = 192.168.1.1
    O17 - HKLM\System\CS1\Services\Tcpip\..\{49E07008-D08C-4B6B-9492-C634D6FF11F1}: DhcpDomain = E1-Line.com
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
    ~ Domain: Scanned in 00mn 00s

    ---\\ Protocole additionnel (O18)
    O18 - Handler: wlpg [64Bits] - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} . (...) --
    O18 - Filter: application/x-msdownload [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll =>.Microsoft Corporation
    ~ Protocole Additionnel: Scanned in 00mn 00s

    ---\\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (autorun) (O20)
    O20 - Winlogon Notify: igfxcui . (.Intel Corporation - igfxdev Module.) -- C:\Windows\System32\igfxdev.dll
    ~ Winlogon: Scanned in 00mn 00s

    ---\\ Clé de Registre autorun ShellServiceObjectDelayLoad (SSO/SSODL) (O21)
    O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
    ~ SSODL: 1 Scanned in 00mn 00s

    ---\\ Liste des services NT non Microsoft et non désactivés (O23)
    O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) . (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
    O23 - Service: avast! Antivirus (avast! Antivirus) . (.AVAST Software - avast! Service.) - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
    O23 - Service: BlueSoleilCS (BlueSoleilCS) . (.IVT Corporation - Bluetooth Application.) - C:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\BlueSoleilCS.exe
    O23 - Service: Garmin Core Update Service (Garmin Core Update Service) . (.Garmin Ltd or its subsidiaries - Garmin Core Update Service.) - C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe
    O23 - Service: Service Google Update (gupdate) (gupdate) . (.Google Inc. - Programme d'installation de Google.) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe =>.Google Inc
    O23 - Service: HP Support Assistant Service (HP Support Assistant Service) . (.Hewlett-Packard Company - HP Support Assistant Service.) - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe =>.Hewlett-Packard Co
    O23 - Service: oem30.inf (hpsrv) . (.Hewlett-Packard Company - HpService.) - C:\Windows\System32\Hpservice.exe
    O23 - Service: HPWMISVC (HPWMISVC) . (.Hewlett-Packard Development Company, L.P. - HP Quick Launch WMI Service.) - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
    O23 - Service: IconMan_R (IconMan_R) . (.Realsil Microelectronics Inc. - Realtek Card Reader Patch Tool..) - C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
    O23 - Service: Intel(R) Capability Licensing Service Interface (Intel(R) Capability Licensing Service Interface) . (.Intel(R) Corporation - Intel(R) Capability Licensing Service Inter.) - C:\Program Files\Intel\iCLS Client\HeciServer.exe
    O23 - Service: Intel(R) ME Service (Intel(R) ME Service) . (.Intel Corporation - Intel(R) ME Service.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
    O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) . (.Intel Corporation - Intel(R) Dynamic Application Loader Host In.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
    O23 - Service: Intel(R) Management and Security Application Local Manageme (LMS) . (.Intel Corporation - Local Manageability Service.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
    O23 - Service: Online Games Manager (ogmservice) . (.RealNetworks, Inc. - Online Games Manager.) - C:\Program Files (x86)\Online Games Manager\ogmservice.exe
    O23 - Service: scores (scores) . (...) - C:\Windows\score.exe
    O23 - Service: C:\Windows\System32\stlang64.dll (STacSV) . (.IDT, Inc. - IDT PC Audio.) - C:\Program Files\IDT\WDM\STacSV64.exe
    O23 - Service: Intel(R) Management and Security Application User Notificat (UNS) . (.Intel Corporation - User Notification Service.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
    O23 - Service: WindowsMangerProtect Service (WindowsMangerProtect) . (...) - C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe (.not file.) =>PUP.Fuyu
    ~ Services: 17 Scanned in 00mn 08s

    ---\\ Enumération Active Desktop & MHTML Editor (O24)
    O24 - Default MHTML Editor: Last - .(...) - (.not file.)
    ~ Desktop Component: 4 Scanned in 00mn 00s

    ---\\ Enumère les données de BootExecute (BEX) (O34)
    O34 - HKLM BootExecute: (autocheck autochk *) - File not found
    ~ BEX: 1 Scanned in 00mn 00s

    ---\\ Tâches planifiées en automatique (O39)
    [MD5.A6B6AB9502B63F43A9A56AE6AFB22078] [APT] [Adobe Flash Player Updater] (.Adobe Systems Incorporated.) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [262320]
    [MD5.1AD8512A5C40AD1A0558498D8E0AC2AA] [APT] [avast! Emergency Update] (.AVAST Software.) -- C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [808448]
    [MD5.2A3FB4C98F139038E23330D2439DB8A4] [APT] [FacebookUpdateTaskUserS-1-5-21-2254641191-106435527-948302892-1001Core] (.Facebook Inc..) -- C:\Users\Home\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096]
    [MD5.2A3FB4C98F139038E23330D2439DB8A4] [APT] [FacebookUpdateTaskUserS-1-5-21-2254641191-106435527-948302892-1001UA] (.Facebook Inc..) -- C:\Users\Home\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096]
    [MD5.0D89E3E3070B542090C40A9384B76A52] [APT] [GarminUpdaterTask] (...) -- C:\Program Files (x86)\Garmin\Express Self Updater\ExpressSelfUpdater.exe [24920]
    [MD5.506708142BC63DABA64F2D3AD1DCD5BF] [APT] [GoogleUpdateTaskMachineCore] (.Google Inc..) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [116648]
    [MD5.506708142BC63DABA64F2D3AD1DCD5BF] [APT] [GoogleUpdateTaskMachineUA] (.Google Inc..) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [116648]
    [MD5.AF51D4FE088A3EFA5303B36FFFD0581B] [APT] [HPCeeScheduleForHome] (.Hewlett-Packard.) -- C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [91704]
    [MD5.B7F55E2AE978D3D34F7876EE5D689AAE] [APT] [MirageAgent] (.CyberLink.) -- C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe [136488]
    [MD5.3E53CC4591B043C8D42FB3D771D55FCE] [APT] [HP Support Assistant Quick Start] (.Hewlett-Packard Company.) -- C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [542008]
    [MD5.3E53CC4591B043C8D42FB3D771D55FCE] [APT] [PC Health Analysis] (.Hewlett-Packard Company.) -- C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [542008]
    [MD5.16F1F09240540D9409DA192839C9D786] [APT] [Update Check] (.Hewlett-Packard Company.) -- C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFUpdater.exe [630584]
    [MD5.701C65A8DF4B7663FFA4A1032598DFE9] [APT] [WarrantyChecker] (.Hewlett-Packard.) -- C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [1586392]
    [MD5.701C65A8DF4B7663FFA4A1032598DFE9] [APT] [WarrantyChecker_DeviceScan] (.Hewlett-Packard.) -- C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [1586392]
    O39 - APT: Adobe Flash Player Updater - (.Adobe Systems Incorporated.) -- C:\Windows\Tasks\Adobe Flash Player Updater.job [1002]
    O39 - APT: Adobe Flash Player Updater - (.Adobe Systems Incorporated.) -- C:\Windows\System32\Tasks\Adobe Flash Player Updater [1002]
    O39 - APT: FacebookUpdateTaskUserS-1-5-21-2254641191-106435527-948302892-1001Core - (.Facebook Inc..) -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2254641191-106435527-948302892-1001Core.job [908]
    O39 - APT: FacebookUpdateTaskUserS-1-5-21-2254641191-106435527-948302892-1001Core - (.Facebook Inc..) -- C:\Windows\System32\Tasks\FacebookUpdateTaskUserS-1-5-21-2254641191-106435527-948302892-1001Core [908]
    O39 - APT: FacebookUpdateTaskUserS-1-5-21-2254641191-106435527-948302892-1001UA - (.Facebook Inc..) -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2254641191-106435527-948302892-1001UA.job [930]
    O39 - APT: FacebookUpdateTaskUserS-1-5-21-2254641191-106435527-948302892-1001UA - (.Facebook Inc..) -- C:\Windows\System32\Tasks\FacebookUpdateTaskUserS-1-5-21-2254641191-106435527-948302892-1001UA [930]
    O39 - APT: GoogleUpdateTaskMachineCore - (.Google Inc..) -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job [1066]
    O39 - APT: GoogleUpdateTaskMachineCore - (.Google Inc..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore [1066]
    O39 - APT: GoogleUpdateTaskMachineUA - (.Google Inc..) -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job [1070]
    O39 - APT: GoogleUpdateTaskMachineUA - (.Google Inc..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA [1070]
    O39 - APT: HPCeeScheduleForHome - (.Hewlett-Packard.) -- C:\Windows\Tasks\HPCeeScheduleForHome.job [334]
    O39 - APT: HPCeeScheduleForHome - (.Hewlett-Packard.) -- C:\Windows\System32\Tasks\HPCeeScheduleForHome [334]
    ~ Scheduled Task: 22 Scanned in 00mn 05s

    ---\\ Composants installés (ActiveSetup Installed Components) (O40)
    O40 - ASIC: Microsoft Windows Media Player [64Bits] - >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Ressources du Lecteur Windows Media.) -- C:\Windows\System32\wmploc.dll =>.Microsoft Corporation
    O40 - ASIC: Microsoft Windows Media Player 12.0 [64Bits] - {22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Windows Media Player Extension.) -- C:\Windows\SysWOW64\wmpdxm.dll =>.Microsoft Corporation
    O40 - ASIC: Themes Setup [64Bits] - {2C7339CF-2B09-4501-B3F3-F3508C9228ED} . (.Microsoft Corporation - API Windows Theme.) -- C:\Windows\System32\themeui.dll
    O40 - ASIC: Microsoft Windows [64Bits] - {44BBA840-CC51-11CF-AAFA-00AA00B6015C} . (.Microsoft Corporation - Windows Mail.) -- C:\Program Files (x86)\Windows Mail\WinMail.exe =>.Microsoft Corporation
    O40 - ASIC: Browsing Enhancements [64Bits] - {630b1da0-b465-11d1-9948-00c04f98bbc9} . (.Microsoft Corporation - Extension Shell dossier FTP Microsoft Internet Explorer..) -- C:\Windows\System32\msieftp.dll
    O40 - ASIC: Microsoft Windows Media Player [64Bits] - {6BF52A52-394A-11d3-B153-00C04F79FAA6} . (.Microsoft Corporation - Ressources du Lecteur Windows Media.) -- C:\Windows\System32\wmploc.dll =>.Microsoft Corporation
    O40 - ASIC: Windows Desktop Update [64Bits] - {89820200-ECBD-11cf-8B85-00AA005B4340} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\Windows\System32\shell32.dll
    O40 - ASIC: Web Platform Customizations [64Bits] - {89820200-ECBD-11cf-8B85-00AA005B4383} . (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Explorer par utilisateur.) -- C:\Windows\System32\ie4uinit.exe
    O40 - ASIC: (no name) [64Bits] - {89B4C1CD-B018-4511-B0A1-5476DBF70820} . (.Microsoft Corporation - Microsoft .NET IE SECURITY REGISTRATION.) -- C:\Windows\System32\mscories.dll
    ~ Active Setup: 9 Scanned in 00mn 00s

    ---\\ Pilotes lancés au démarrage du système (O41)
    O41 - Driver: C:\Windows\System32\drivers\afd.sys (AFD) . (.Microsoft Corporation - Pilote de fonction connexe pour WinSock.) - C:\Windows\system32\drivers\afd.sys
    O41 - Driver: (aswRdr) . (.AVAST Software - avast! WFP Redirect Driver.) - C:\Windows\system32\drivers\aswRdr2.sys
    O41 - Driver: (aswSnx) . (.AVAST Software - avast! Virtualization Driver.) - C:\Windows\system32\drivers\aswSnx.sys
    O41 - Driver: (aswSP) . (.AVAST Software - avast! self protection module.) - C:\Windows\system32\drivers\aswSP.sys
    O41 - Driver: (BasicDisplay) . (.Microsoft Corporation - Microsoft Basic Display Driver.) - C:\Windows\system32\drivers\BasicDisplay.sys
    O41 - Driver: (BasicRender) . (.Microsoft Corporation - Microsoft Basic Render Driver.) - C:\Windows\system32\drivers\BasicRender.sys
    O41 - Driver: cdrom.inf (cdrom) . (.Microsoft Corporation - SCSI CD-ROM Driver.) - C:\Windows\system32\drivers\cdrom.sys
    O41 - Driver: C:\Windows\System32\drivers\dam.sys (dam) . (.Microsoft Corporation - DAM Kernel Driver.) - C:\Windows\System32\drivers\dam.sys
    O41 - Driver: C:\Windows\System32\wkssvc.dll (Dfsc) . (.Microsoft Corporation - DFS Namespace Client Driver.) - C:\Windows\System32\Drivers\dfsc.sys
    O41 - Driver: C:\Windows\System32\drivers\discache.sys (discache) . (.Microsoft Corporation - System Indexer/Cache Driver.) - C:\Windows\System32\drivers\discache.sys
    O41 - Driver: mssmbios.inf (mssmbios) . (.Microsoft Corporation - System Management BIOS Driver.) - C:\Windows\system32\drivers\mssmbios.sys
    O41 - Driver: netnb.inf (NetBIOS) . (.Microsoft Corporation - NetBIOS interface driver.) - C:\Windows\System32\DRIVERS\netbios.sys
    O41 - Driver: C:\Windows\System32\drivers\netbt.sys (NetBT) . (.Microsoft Corporation - MBT Transport driver.) - C:\Windows\System32\DRIVERS\netbt.sys
    O41 - Driver: npsvctrig.inf (npsvctrig) . (.Microsoft Corporation - Named pipe service triggers.) - C:\Windows\system32\drivers\npsvctrig.sys
    O41 - Driver: C:\Windows\System32\drivers\nsiproxy.sys (nsiproxy) . (.Microsoft Corporation - NSI Proxy.) - C:\Windows\System32\drivers\nsiproxy.sys
    O41 - Driver: C:\Windows\System32\drivers\pacer.sys (Psched) . (.Microsoft Corporation - Planificateur de paquets QoS.) - C:\Windows\system32\DRIVERS\pacer.sys
    O41 - Driver: C:\Windows\System32\wkssvc.dll (rdbss) . (.Microsoft Corporation - Pilote du sous-système de mise en mémoire t.) - C:\Windows\System32\DRIVERS\rdbss.sys
    O41 - Driver: C:\Windows\System32\tcpipcfg.dll (tdx) . (.Microsoft Corporation - TDI Translation Driver.) - C:\Windows\system32\DRIVERS\tdx.sys
    O41 - Driver: C:\Windows\System32\drivers\vwififlt.sys (vwififlt) . (.Microsoft Corporation - Virtual WiFi Filter Driver.) - C:\Windows\system32\DRIVERS\vwififlt.sys
    O41 - Driver: C:\Windows\System32\rascfg.dll (Wanarpv6) . (.Microsoft Corporation - MS Remote Access and Routing ARP Driver.) - C:\Windows\system32\DRIVERS\wanarp.sys
    ~ Drivers: 40 Scanned in 00mn 00s

    ---\\ Logiciels installés (O42)
    O42 - Logiciel: ANT Drivers 0.1.2.0 - (.ANT Drivers.) [HKLM][64Bits] -- ANT Drivers_is1
    O42 - Logiciel: ANT Drivers Installer x64 - (.Garmin Ltd or its subsidiaries.) [HKLM][64Bits] -- {6AB340AC-4B1B-4E36-8828-101FC7EC7959}
    O42 - Logiciel: Adobe Flash Player 14 Plugin - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- Adobe Flash Player Plugin
    O42 - Logiciel: Adobe Reader X (10.1.11) - Français - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {AC76BA86-7AD7-1036-7B44-AA1000000001}
    O42 - Logiciel: Adobe Shockwave Player 11.6 - (.Adobe Systems, Inc..) [HKLM][64Bits] -- Adobe Shockwave Player
    O42 - Logiciel: Advertising Center - (.Nero AG.) [HKLM][64Bits] -- {B2EC4A38-B545-4A00-8214-13FE0E915E6D}
    O42 - Logiciel: Belgium e-ID middleware 4.0.5 (build 7382) - (.Belgian Government.) [HKLM][64Bits] -- {824563DE-75AD-4166-9DC0-B6482F207382}
    O42 - Logiciel: Bookworm Deluxe - (.Zylom.) [HKLM][64Bits] -- 31729ee482c1d9987afe5121cc0ba1c2
    O42 - Logiciel: Complément Messenger - (.Microsoft Corporation.) [HKLM][64Bits] -- {6E5324C1-84FC-4F76-9A3A-C65E07F80EE6}
    O42 - Logiciel: Connected Music powered by Universal Music Group version 1.0 - (.Snowite.) [HKLM][64Bits] -- {46037DC7-F927-46DF-935F-D6F122BDD34B}_is1
    O42 - Logiciel: CyberLink LabelPrint - (.CyberLink Corp..) [HKLM][64Bits] -- InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}
    O42 - Logiciel: CyberLink LabelPrint - (.CyberLink Corp..) [HKLM][64Bits] -- {C59C179C-668D-49A9-B6EA-0121CCFC1243}
    O42 - Logiciel: CyberLink Media Suite 10 - (.CyberLink Corp..) [HKLM][64Bits] -- InstallShield_{1FBF6C24-C1fD-4101-A42B-0C564F9E8E79}
    O42 - Logiciel: CyberLink Media Suite 10 - (.CyberLink Corp..) [HKLM][64Bits] -- {1FBF6C24-C1fD-4101-A42B-0C564F9E8E79}
    O42 - Logiciel: CyberLink PhotoDirector - (.CyberLink Corp..) [HKLM][64Bits] -- InstallShield_{4862344A-A39C-4897-ACD4-A1BED5163C5A}
    O42 - Logiciel: CyberLink PhotoDirector - (.CyberLink Corp..) [HKLM][64Bits] -- {4862344A-A39C-4897-ACD4-A1BED5163C5A}
    O42 - Logiciel: CyberLink PowerDVD - (.CyberLink Corp..) [HKLM][64Bits] -- InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}
    O42 - Logiciel: CyberLink PowerDVD - (.CyberLink Corp..) [HKLM][64Bits] -- {DEC235ED-58A4-4517-A278-C41E8DAEAB3B}
    O42 - Logiciel: CyberLink PowerDirector 10 - (.CyberLink Corp..) [HKLM][64Bits] -- InstallShield_{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}
    O42 - Logiciel: CyberLink PowerDirector 10 - (.CyberLink Corp..) [HKLM][64Bits] -- {B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}
    O42 - Logiciel: CyberLink YouCam - (.CyberLink Corp..) [HKLM][64Bits] -- InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}
    O42 - Logiciel: CyberLink YouCam - (.CyberLink Corp..) [HKLM][64Bits] -- {01FB4998-33C4-4431-85ED-079E3EEFE75D}
    O42 - Logiciel: D3DX10 - (.Microsoft.) [HKLM][64Bits] -- {E09C4DB7-630C-4F06-A631-8EA7239923AF}
    O42 - Logiciel: Dropbox - (.Dropbox, Inc..) [HKCU][64Bits] -- Dropbox
    O42 - Logiciel: Elevated Installer - (.Garmin Ltd or its subsidiaries.) [HKLM][64Bits] -- {AA2A50EB-24BA-49C4-ACAA-73BFF91F9D7E}
    O42 - Logiciel: Energy Star - (.Hewlett-Packard.) [HKLM][64Bits] -- {0FA995CC-C849-4755-B14B-5404CC75DC24}
    O42 - Logiciel: Facebook Video Calling 3.1.0.521 - (.Skype Limited.) [HKLM][64Bits] -- {2091F234-EB58-4B80-8C96-8EB78C808CF7}
    O42 - Logiciel: Garmin Communicator Plugin - (.Garmin Ltd or its subsidiaries.) [HKLM][64Bits] -- {647BB978-2876-487B-9B0E-FDB73F0EA4A2}
    O42 - Logiciel: Garmin Communicator Plugin x64 - (.Garmin Ltd or its subsidiaries.) [HKLM][64Bits] -- {237D687E-9E50-4A30-B810-262764CC491B}
    O42 - Logiciel: Garmin Express - (.Garmin Ltd or its subsidiaries.) [HKLM][64Bits] -- {BF133B81-EEE5-4751-8F64-9BC8E42708A7} =>.Garmin Corporation
    O42 - Logiciel: Garmin Express - (.Garmin Ltd or its subsidiaries.) [HKLM][64Bits] -- {aece03a3-686f-4b3c-9931-9dafb71829b7} =>.Garmin Corporation
    O42 - Logiciel: Garmin Express Tray - (.Garmin Ltd or its subsidiaries.) [HKLM][64Bits] -- {1B54E2F7-0396-478A-8868-267922A98854} =>.Garmin Corporation
    O42 - Logiciel: Garmin USB Drivers - (.Garmin Ltd or its subsidiaries.) [HKLM][64Bits] -- {3D5D6CFC-3097-425A-8D8F-7EAF5D57641D}
    O42 - Logiciel: Geonaute Software - (.Geonaute.) [HKLM][64Bits] -- {548CBD79-054A-42F1-A1DA-B4F3FEF490ED}_is1
    O42 - Logiciel: Google Chrome - (.Google Inc..) [HKLM][64Bits] -- Google Chrome
    O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM][64Bits] -- {A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
    O42 - Logiciel: Google+ Auto Backup - (.Google.) [HKLM][64Bits] -- {A50DE037-B5C0-4C8A-8049-B0C576B313D1}
    O42 - Logiciel: Google Earth - (.Google.) [HKLM][64Bits] -- {4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}
    O42 - Logiciel: HP 3D DriveGuard - (.Hewlett-Packard Company.) [HKLM][64Bits] -- {F9E399CB-046F-45FD-A67F-CF399E2128E4}
    O42 - Logiciel: HP Connected Music (Meridian - installer) - (.Meridian Audio Ltd.) [HKLM][64Bits] -- StartHPConnectedMusic
    O42 - Logiciel: HP CoolSense - (.Hewlett-Packard Company.) [HKLM][64Bits] -- {16B7BDA1-B967-4D2D-8B27-E12727C28350}
    O42 - Logiciel: HP Customer Experience Enhancements - (.Hewlett-Packard.) [HKLM][64Bits] -- {07FA4960-B038-49EB-891B-9F95930AA544}
    O42 - Logiciel: HP Documentation - (.Hewlett-Packard.) [HKLM][64Bits] -- {18DE31AE-70D0-43A7-9E3C-2ED7283ECE8A}
    O42 - Logiciel: HP Postscript Converter - (.Hewlett-Packard.) [HKLM][64Bits] -- {6E14E6D6-3175-4E1A-B934-CAB5A86367CD}
    O42 - Logiciel: HP Quick Launch - (.Hewlett-Packard Company.) [HKLM][64Bits] -- {E5823036-6F09-4D0A-B05C-E2BAA129288A}
    O42 - Logiciel: HP Recovery Manager - (.Hewlett-Packard.) [HKLM][64Bits] -- {528AB81B-D65A-4AB0-A2B6-82B51A087D01}
    O42 - Logiciel: HP Registration Service - (.Hewlett-Packard.) [HKLM][64Bits] -- {E4D6CCF2-0AAF-4B9C-9DE5-893EDC9B4BAA}
    O42 - Logiciel: HP Software Framework - (.Hewlett-Packard Company.) [HKLM][64Bits] -- {98D5A5FA-1AA3-4CBE-B26C-A737E20F8A6D}
    O42 - Logiciel: HP Support Assistant - (.Hewlett-Packard Company.) [HKLM][64Bits] -- {E35A3B13-78CD-4967-8AC8-AA9FDA693EDE} =>.Hewlett-Packard Co
    O42 - Logiciel: HP Utility Center - (.Hewlett-Packard.) [HKLM][64Bits] -- {0C57987A-A03A-4B95-A309-D23F78F406CA}
    O42 - Logiciel: HP Wireless Button Driver - (.Hewlett-Packard Company.) [HKLM][64Bits] -- {30B2D1D8-0A07-4B71-9553-0710C5D31E35}
    O42 - Logiciel: Hewlett-Packard ACLM.NET v1.2.2.3 - (.Hewlett-Packard Company.) [HKLM][64Bits] -- {6F340107-F9AA-47C6-B54C-C3A19F11553F}
    O42 - Logiciel: HomeByMe - (.SquareClock SAS.) [HKCU][64Bits] -- SquareClock_Production_HBMV1
    O42 - Logiciel: IDT Audio - (.IDT.) [HKLM][64Bits] -- {E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}
    O42 - Logiciel: Intel(R) Management Engine Components - (.Intel Corporation.) [HKLM][64Bits] -- {65153EA5-8B6E-43B6-857B-C6E4FC25798A}
    O42 - Logiciel: Intel(R) Processor Graphics - (.Intel Corporation.) [HKLM][64Bits] -- {F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}
    O42 - Logiciel: Intel® Trusted Connect Service Client - (.Intel Corporation.) [HKLM][64Bits] -- {F4404AFD-2EF3-40C1-8C09-29E5F3B6972B}
    O42 - Logiciel: Java 7 Update 60 - (.Oracle.) [HKLM][64Bits] -- {26A24AE4-039D-4CA4-87B4-2F03217060FF}
    O42 - Logiciel: Junk Mail filter update - (.Microsoft Corporation.) [HKLM][64Bits] -- {1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}
    O42 - Logiciel: Logiciel d'archivage WinRAR - (...) [HKLM][64Bits] -- WinRAR archiver
    O42 - Logiciel: MSVCRT - (.Microsoft.) [HKLM][64Bits] -- {8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}
    O42 - Logiciel: MSVCRT_amd64 - (.Microsoft.) [HKLM][64Bits] -- {D0B44725-3666-492D-BEF6-587A14BD9BD9}
    O42 - Logiciel: Malwarebytes Anti-Malware version 2.0.2.1012 - (.Malwarebytes Corporation.) [HKLM][64Bits] -- Malwarebytes Anti-Malware_is1
    O42 - Logiciel: Mesh Runtime - (.Microsoft Corporation.) [HKLM][64Bits] -- {8C6D6116-B724-4810-8F2D-D047E6B7D68E}
    O42 - Logiciel: Messenger Companion - (.Microsoft Corporation.) [HKLM][64Bits] -- {0481A2EA-DA1D-4D10-A7C3-F8237948F6B5}
    O42 - Logiciel: Messenger Companion - (.Microsoft Corporation.) [HKLM][64Bits] -- {50816F92-1652-4A7C-B9BC-48F682742C4B}
    O42 - Logiciel: Microsoft Silverlight - (.Microsoft Corporation.) [HKLM][64Bits] -- {89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
    O42 - Logiciel: Movies Toolbar for Chrome (Dist. by Somoto Ltd.) - (.IAC Search and Media.) [HKLM][64Bits] -- somotomoviestoolbar181CR =>PUP.MoviesToolbar
    O42 - Logiciel: Mozilla Firefox 31.0 (x86 fr) - (.Mozilla.) [HKLM][64Bits] -- Mozilla Firefox 31.0 (x86 fr)
    O42 - Logiciel: Mozilla Maintenance Service - (.Mozilla.) [HKLM][64Bits] -- MozillaMaintenanceService
    O42 - Logiciel: Nero 9 Lite - (.Nero AG.) [HKLM][64Bits] -- {d96f38c4-d880-47e3-8402-55d03fddbe3b}
    O42 - Logiciel: Nero ControlCenter - (.Nero AG.) [HKLM][64Bits] -- {BD5CA0DA-71AD-43DA-B19E-6EEE0C9ADC9A}
    O42 - Logiciel: Nero Installer - (.Nero AG.) [HKLM][64Bits] -- {E8A80433-302B-4FF1-815D-FCC8EAC482FF}
    O42 - Logiciel: Nero Online Upgrade - (.Nero AG.) [HKLM][64Bits] -- {C81A2FE0-3574-00A9-CED4-BDAA334CBE8E}
    O42 - Logiciel: Nero StartSmart - (.Nero AG.) [HKLM][64Bits] -- {7748AC8C-18E3-43BB-959B-088FAEA16FB2}
    O42 - Logiciel: Online Games Manager v1.30 - (.Real Networks, Inc..) [HKLM][64Bits] -- Online Games Manager
    O42 - Logiciel: OpenOffice.org 3.4.1 - (.Apache Software Foundation.) [HKLM][64Bits] -- {7DA1C06F-C913-46C7-8A0F-DA2CBA17EA1D}
    O42 - Logiciel: PL-2303 USB-to-Serial - (.Prolific Technology INC.) [HKLM][64Bits] -- {ECC3713C-08A4-40E3-95F1-7D0704F1CE5E}
    O42 - Logiciel: Package de pilotes Windows - Dynastream Innovations, Inc. ANT LibUSB Driver - (.Dynastream Innovations, Inc..) [HKLM][64Bits] -- F9D2A789F9CFF8CEC36B544F53877C80F1F73C46
    O42 - Logiciel: Package de pilotes Windows - Fedict SmartCard (07/01/2013 4.0.0.8) - (.Fedict.) [HKLM][64Bits] -- D101DCAD83850799D453082F40CDF9958468129F
    O42 - Logiciel: Package de pilotes Windows - Silicon Labs Software (DSI_SiUSBXp_3_1) USB ( - (.Silicon Labs Software.) [HKLM][64Bits] -- D1506E0025B5A3F9EB8270FE81C1EEDD9388B8A2
    O42 - Logiciel: Picasa 3 - (.Google, Inc..) [HKLM][64Bits] -- Picasa 3
    O42 - Logiciel: Ralink Bluetooth Stack64 - (.Ralink Corporation.) [HKLM][64Bits] -- {58BC91D0-42E7-125D-F9B6-F2F5C0CDB096}
    O42 - Logiciel: Ralink RT3290 802.11bgn Wi-Fi Adapter - (.Ralink.) [HKLM][64Bits] -- {8FC4F1DD-F7FD-4766-804D-3C8FF1D309AF}
    O42 - Logiciel: Realtek Ethernet Controller Driver - (.Realtek.) [HKLM][64Bits] -- {8833FFB6-5B0C-4764-81AA-06DFEED9A476}
    O42 - Logiciel: Realtek PCIE Card Reader - (.Realtek Semiconductor Corp..) [HKLM][64Bits] -- {C1594429-8296-4652-BF54-9DBE4932A44C}
    O42 - Logiciel: Synaptics Pointing Device Driver - (.Synaptics Incorporated.) [HKLM][64Bits] -- SynTPDeinstKey
    O42 - Logiciel: Telecharger et Installer Packages - (...) [HKCU][64Bits] -- Telecharger et Installer Packages =>Adware.InstallCore
    O42 - Logiciel: Virtual COM Port Driver - (.STMicroelectronics.) [HKLM][64Bits] -- InstallShield_{9853299F-7AD8-4560-9896-60650BD8ACBF}
    O42 - Logiciel: Windows Driver Package - Garmin (grmnusb) GARMIN Devices (04/19/2012 2.3.1 - (.Garmin.) [HKLM][64Bits] -- 98157A226B40B173301B0F53C8E98C47805D5152
    O42 - Logiciel: avast! Free Antivirus v9.0.2021 - (.AVAST Software.) [HKLM][64Bits] -- avast
    O42 - Logiciel: neroxml - (.Nero AG.) [HKLM][64Bits] -- {56C049BE-79E9-4502-BEA7-9754A3E60F9B}
    O42 - Logiciel: scrabbleproB 1.1.3 - (.scrabblepro.) [HKLM][64Bits] -- scrabbleproB_is1
    O42 - Logiciel: swMSM - (.Adobe Systems, Inc.) [HKLM][64Bits] -- {612C34C7-5E90-47D8-9B5C-0F717DD82726}
    ~ Logic: 52 Scanned in 00mn 00s

    ---\\ HKCU & HKLM Software Keys
    [HKCU\Software\Adobe]
    [HKCU\Software\AppDataLow\Software\Adobe]
    [HKCU\Software\AppDataLow\Software\JavaSoft]
    [HKCU\Software\AppDataLow]
    [HKCU\Software\Avast Software]
    [HKCU\Software\BEID]
    [HKCU\Software\Chromium]
    [HKCU\Software\Classes]
    [HKCU\Software\Clients]
    [HKCU\Software\CyberLink]
    [HKCU\Software\Facebook]
    [HKCU\Software\Gameo]
    [HKCU\Software\Garmin]
    [HKCU\Software\GoldenGate]
    [HKCU\Software\Google]
    [HKCU\Software\Hewlett-Packard]
    [HKCU\Software\IM Providers]
    [HKCU\Software\Intel]
    [HKCU\Software\JavaSoft]
    [HKCU\Software\Lake]
    [HKCU\Software\Licenses]
    [HKCU\Software\MCAFEE]
    [HKCU\Software\Macromedia]
    [HKCU\Software\Macrovision]
    [HKCU\Software\Mine]
    [HKCU\Software\MozillaPlugins]
    [HKCU\Software\Mozilla]
    [HKCU\Software\Nero]
    [HKCU\Software\Netscape]
    [HKCU\Software\Norton]
    [HKCU\Software\OpenOffice.org]
    [HKCU\Software\Policies]
    [HKCU\Software\PopCap]
    [HKCU\Software\RegisteredApplications]
    [HKCU\Software\SkypeRS]
    [HKCU\Software\Symantec]
    [HKCU\Software\Synaptics]
    [HKCU\Software\TeamViewer]
    [HKCU\Software\TeleCharger]
    [HKCU\Software\Trolltech]
    [HKCU\Software\VB and VBA Program Settings]
    [HKCU\Software\WinRAR SFX]
    [HKCU\Software\WinRAR]
    [HKCU\Software\Wow6432Node]
    [HKCU\Software\ZebHelpProcess Helper]
    [HKCU\Software\skype]
    [HKCU\Software\telecharger-gratuit]
    [HKCU\Software\test]
    [HKLM\Software\AMD]
    [HKLM\Software\ATI Technologies]
    [HKLM\Software\Classes]
    [HKLM\Software\Clients]
    [HKLM\Software\CyberLink]
    [HKLM\Software\Dolby]
    [HKLM\Software\Geonaute]
    [HKLM\Software\HPQ]
    [HKLM\Software\Hewlett-Packard]
    [HKLM\Software\IDT]
    [HKLM\Software\InstalledOptions]
    [HKLM\Software\Intel]
    [HKLM\Software\Khronos]
    [HKLM\Software\Macromedia]
    [HKLM\Software\MozillaPlugins]
    [HKLM\Software\Mozilla]
    [HKLM\Software\Norton]
    [HKLM\Software\ODBC]
    [HKLM\Software\Policies]
    [HKLM\Software\RTLSetup]
    [HKLM\Software\Realtek Semiconductor Corp.]
    [HKLM\Software\Realtek]
    [HKLM\Software\RegisteredApplications]
    [HKLM\Software\Synaptics]
    [HKLM\Software\WinRAR]
    [HKLM\Software\Wow6432Node\009f6c92-c8da-46f6-9ff4-ed570730d70a]
    [HKLM\Software\Wow6432Node\0bcf5df0-4fd6-4897-a645-0ee111b55f16]
    [HKLM\Software\Wow6432Node\AVAST Software]
    [HKLM\Software\Wow6432Node\Adobe]
    [HKLM\Software\Wow6432Node\AdwCleaner]
    [HKLM\Software\Wow6432Node\AppDataLow]
    [HKLM\Software\Wow6432Node\BEID]
    [HKLM\Software\Wow6432Node\BSPACode]
    [HKLM\Software\Wow6432Node\Caphyon]
    [HKLM\Software\Wow6432Node\Classes]
    [HKLM\Software\Wow6432Node\Clients]
    [HKLM\Software\Wow6432Node\CyberLink]
    [HKLM\Software\Wow6432Node\DivXNetworks]
    [HKLM\Software\Wow6432Node\GameInstaller]
    [HKLM\Software\Wow6432Node\Garmin]
    [HKLM\Software\Wow6432Node\Google]
    [HKLM\Software\Wow6432Node\Hewlett-Packard]
    [HKLM\Software\Wow6432Node\IDT]
    [HKLM\Software\Wow6432Node\IVT Corporation]
    [HKLM\Software\Wow6432Node\InstallShield]
    [HKLM\Software\Wow6432Node\Insyde]
    [HKLM\Software\Wow6432Node\Intel]
    [HKLM\Software\Wow6432Node\JavaSoft]
    [HKLM\Software\Wow6432Node\JreMetrics]
    [HKLM\Software\Wow6432Node\Khronos]
    [HKLM\Software\Wow6432Node\Lake]
    [HKLM\Software\Wow6432Node\Licenses]
    [HKLM\Software\Wow6432Node\LogMeInRescueCallingCard]
    [HKLM\Software\Wow6432Node\Macromedia]
    [HKLM\Software\Wow6432Node\Malwarebytes' Anti-Malware]
    [HKLM\Software\Wow6432Node\MaxPower]
    [HKLM\Software\Wow6432Node\McAfee.com]
    [HKLM\Software\Wow6432Node\MozillaPlugins]
    [HKLM\Software\Wow6432Node\Mozilla]
    [HKLM\Software\Wow6432Node\Nero]
    [HKLM\Software\Wow6432Node\ODBC]
    [HKLM\Software\Wow6432Node\OpenOffice.org]
    [HKLM\Software\Wow6432Node\Policies]
    [HKLM\Software\Wow6432Node\PopCap]
    [HKLM\Software\Wow6432Node\Prolific Technology INC]
    [HKLM\Software\Wow6432Node\Ralink Corporation]
    [HKLM\Software\Wow6432Node\Ralink]
    [HKLM\Software\Wow6432Node\Realtek Semiconductor Corp.]
    [HKLM\Software\Wow6432Node\Realtek]
    [HKLM\Software\Wow6432Node\RegisteredApplications]
    [HKLM\Software\Wow6432Node\Silicon Laboratories, Inc.]
    [HKLM\Software\Wow6432Node\Symantec]
    [HKLM\Software\Wow6432Node\globalUpdate]
    [HKLM\Software\Wow6432Node\mcafeeupdater]
    [HKLM\Software\Wow6432Node\mozilla.org]
    [HKLM\Software\Wow6432Node]
    [HKLM\Software\mcafeeupdater]
    ~ Key Software: 274 Scanned in 00mn 00s

    ---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43)
    O43 - CFD: 19-03-13 - 19:33:09 - [] ----D C:\Program Files (x86)\Adobe
    O43 - CFD: 31-08-13 - 10:30:35 - [] ----D C:\Program Files (x86)\ANT Drivers
    O43 - CFD: 06-10-13 - 10:11:56 - [] ----D C:\Program Files (x86)\Belgium Identity Card
    O43 - CFD: 14-08-14 - 14:53:56 - [] ----D C:\Program Files (x86)\ClearThink
    O43 - CFD: 29-06-14 - 20:49:59 - [] ----D C:\Program Files (x86)\Common Files
    O43 - CFD: 01-09-12 - 17:46:31 - [] ----D C:\Program Files (x86)\Connected Music powered by Universal Music Group
    O43 - CFD: 22-12-13 - 17:35:50 - [] ----D C:\Program Files (x86)\CyberLink
    O43 - CFD: 23-02-14 - 15:23:01 - [] ----D C:\Program Files (x86)\FLV Video Player
    O43 - CFD: 24-07-14 - 09:02:23 - [] ----D C:\Program Files (x86)\Garmin
    O43 - CFD: 27-01-13 - 17:41:42 - [] ----D C:\Program Files (x86)\Garmin GPS Plugin
    O43 - CFD: 31-08-13 - 13:52:15 - [] ----D C:\Program Files (x86)\Google
    O43 - CFD: 24-03-14 - 19:59:27 - [] ----D C:\Program Files (x86)\Hewlett-Packard
    O43 - CFD: 01-09-12 - 17:46:25 - [] ----D C:\Program Files (x86)\HPConnectedMusic
    O43 - CFD: 24-03-14 - 20:00:25 - [] --H-D C:\Program Files (x86)\InstallShield Installation Information
    O43 - CFD: 19-03-13 - 20:16:42 - [] ----D C:\Program Files (x86)\Intel
    O43 - CFD: 13-07-14 - 12:03:01 - [] ----D C:\Program Files (x86)\Internet Explorer
    O43 - CFD: 29-06-14 - 20:49:34 - [] ----D C:\Program Files (x86)\Java
    O43 - CFD: 14-08-14 - 15:02:10 - [] ----D C:\Program Files (x86)\Malwarebytes Anti-Malware
    O43 - CFD: 26-07-14 - 12:09:32 - [0] ----D C:\Program Files (x86)\Microsoft
    O43 - CFD: 24-07-14 - 13:47:58 - [] ----D C:\Program Files (x86)\Microsoft Silverlight
    O43 - CFD: 01-09-12 - 17:42:11 - [] ----D C:\Program Files (x86)\Microsoft SQL Server Compact Edition
    O43 - CFD: 26-07-12 - 10:12:59 - [] ----D C:\Program Files (x86)\Microsoft.NET
    O43 - CFD: 25-07-14 - 14:01:06 - [] ----D C:\Program Files (x86)\Movie Maker 2.6
    O43 - CFD: 10-08-14 - 18:23:02 - [] ----D C:\Program Files (x86)\Mozilla Firefox
    O43 - CFD: 11-08-14 - 12:55:44 - [] ----D C:\Program Files (x86)\Mozilla Maintenance Service
    O43 - CFD: 04-08-12 - 00:37:58 - [] ----D C:\Program Files (x86)\MSBuild
    O43 - CFD: 19-01-13 - 17:00:07 - [] ----D C:\Program Files (x86)\Nero
    O43 - CFD: 07-10-13 - 09:17:35 - [] ----D C:\Program Files (x86)\Online Games Manager
    O43 - CFD: 19-01-13 - 16:07:11 - [] R---D C:\Program Files (x86)\Online Services
    O43 - CFD: 24-02-14 - 18:53:39 - [] ----D C:\Program Files (x86)\OpenOffice.org 3
    O43 - CFD: 18-09-12 - 03:51:08 - [] ----D C:\Program Files (x86)\Ralink Corporation
    O43 - CFD: 07-10-13 - 09:16:58 - [] ----D C:\Program Files (x86)\RealArcade
    O43 - CFD: 18-09-12 - 03:48:11 - [] ----D C:\Program Files (x86)\Realtek
    O43 - CFD: 04-08-12 - 00:37:58 - [] ----D C:\Program Files (x86)\Reference Assemblies
    O43 - CFD: 25-01-13 - 21:02:01 - [] ----D C:\Program Files (x86)\scrabbleproB1.1
    O43 - CFD: 02-02-13 - 18:22:10 - [] ----D C:\Program Files (x86)\STMicroelectronics
    O43 - CFD: 18-09-12 - 04:19:24 - [] ----D C:\Program Files (x86)\SymSilent
    O43 - CFD: 19-01-13 - 16:03:56 - [0] --H-D C:\Program Files (x86)\Uninstall Information
    O43 - CFD: 01-06-14 - 19:51:15 - [] ----D C:\Program Files (x86)\Windows Defender
    O43 - CFD: 25-07-14 - 13:50:39 - [] ----D C:\Program Files (x86)\Windows Live
    O43 - CFD: 22-01-13 - 10:47:13 - [] ----D C:\Program Files (x86)\Windows Mail =>.Microsoft Corporation
    O43 - CFD: 27-01-13 - 21:40:37 - [] ----D C:\Program Files (x86)\Windows Media Player =>.Microsoft Corporation
    O43 - CFD: 26-07-12 - 10:13:01 - [] ----D C:\Program Files (x86)\Windows Multimedia Platform
    O43 - CFD: 26-07-12 - 10:12:59 - [] ----D C:\Program Files (x86)\Windows NT
    O43 - CFD: 15-06-13 - 00:29:24 - [] ----D C:\Program Files (x86)\Windows Photo Viewer
    O43 - CFD: 26-07-12 - 10:13:01 - [] ----D C:\Program Files (x86)\Windows Portable Devices
    O43 - CFD: 26-07-12 - 10:12:59 - [] -SH-D C:\Program Files (x86)\Windows Sidebar
    O43 - CFD: 14-08-14 - 15:34:26 - [] ----D C:\Program Files (x86)\ZHPDiag =>.Nicolas Coolman
    O43 - CFD: 05-04-13 - 19:46:36 - [] ----D C:\Program Files (x86)\Common Files\Adobe
    O43 - CFD: 02-02-13 - 18:14:59 - [] ----D C:\Program Files (x86)\Common Files\InstallShield
    O43 - CFD: 18-09-12 - 03:42:56 - [] ----D C:\Program Files (x86)\Common Files\Intel
    O43 - CFD: 29-06-14 - 20:49:59 - [] ----D C:\Program Files (x86)\Common Files\Java
    O43 - CFD: 25-01-13 - 21:56:21 - [] ----D C:\Program Files (x86)\Common Files\Microsoft Shared
    O43 - CFD: 19-01-13 - 17:00:26 - [] ----D C:\Program Files (x86)\Common Files\Nero
    O43 - CFD: 01-09-12 - 17:32:02 - [] ----D C:\Program Files (x86)\Common Files\Nikon
    O43 - CFD: 18-09-12 - 03:44:06 - [] ----D C:\Program Files (x86)\Common Files\postureAgent
    O43 - CFD: 26-07-12 - 10:13:01 - [] ----D C:\Program Files (x86)\Common Files\Services
    O43 - CFD: 22-01-13 - 10:47:11 - [] ----D C:\Program Files (x86)\Common Files\System
    O43 - CFD: 01-09-12 - 17:40:55 - [] ----D C:\Program Files (x86)\Common Files\Windows Live
    O43 - CFD: 05-04-13 - 19:46:37 - [] ----D C:\ProgramData\Adobe
    O43 - CFD: 18-09-12 - 03:49:12 - [] ----D C:\ProgramData\Apple
    O43 - CFD: 26-07-12 - 09:22:08 - [] -SH-D C:\ProgramData\Application Data
    O43 - CFD: 16-10-13 - 09:15:56 - [] ----D C:\ProgramData\AVAST Software
    O43 - CFD: 19-01-13 - 13:54:58 - [] -SH-D C:\ProgramData\Bureaublad
    O43 - CFD: 07-03-13 - 23:09:38 - [] ----D C:\ProgramData\CyberLink
    O43 - CFD: 26-07-12 - 09:22:08 - [] -SH-D C:\ProgramData\Desktop
    O43 - CFD: 19-01-13 - 13:54:58 - [] -SH-D C:\ProgramData\Documenten
    O43 - CFD:
    0
  3. Cpassimple Messages postés 3987 Statut Membre 923
     
    Tu peux aussi commencer par télécharger et utiliser Revo Uninstaller.
    Une fois ouvert tu regardes les logiciels qui sont installés dans la machine
    (c'est un peu fastidieux mais très efficace).
    Pour les logiciels que tu connais et souhaite pas de problème, tu les laisses. Par contre, tu peux faire une recherche (Google est ton ami) de chaque logiciel inconnu, simplement en entrant leur nom sur le moteur de recherche. Si il est signalé comme Malware ou soft publicitaire tu le vire avec Revo Unistaller en prenant soin de coché "Mode de scan: Avancé" (cf photo). Attention aussi de ne pas redémarrer le PC lors de la désinstallation d'un logiciel, et de ne le faire que lorsque Revo Uninstaller, te l'indique (j'ai dis fastidieux?!).
    Après ça, quand tout les programmes indésirables sont supprimés tu peux lancer un coup de Ccleaner et recommencer les scan de désinfection:

    Ma préférence et dans l'ordre d'utilisation:
    ADWCleaner
    USBFix
    Et Malwarebytes
    (avec 1 scan supplémentaire une fois qu'il m'indique que tout va bien, histoire d'en être certain

    0
    1. Cpassimple Messages postés 3987 Statut Membre 923
       
      Si un logiciel n'est pas indiqué dans google, ou qu'aucune indication fiable y est noté. Ajoutes le mot Infection ou malware en plus du nom
      0
  4. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  5. lilidurhone Messages postés 800 Date d'inscription   Statut Contributeur sécurité Dernière intervention   3 818
     
    Hello

    Fais ce que Bill te demande à savoir héberger ton rapport sur Cjoint

    Ps pas besoin d'Usbfix....
    0
  6. kevin
     
    Voilà pour le rapport: http://cjoint.com/?3HotyJzWgby

    Entre temps j'ai fais un scan au démarrage avec avast et apparemment avast à trouvé pas mal de cochonneries. Le rapport ZHPdiag ci joint a été fait après le scan avast et après avoir lancé adwcleaner et malewarebites.
    0
  7. billmaxime Messages postés 50525 Date d'inscription   Statut Contributeur Dernière intervention   6 152
     
    re

    Le rapport ZHPdiag ci joint a été fait après le scan avast et après avoir lancé adwcleaner et malewarebites.

    refait quand même ceci dans l'ordre inscrit et poste les rapports

    1) relance la version d'adwcleaner qui est présente sur ton bureau et choisis "désinstaller"

    ensuite, télécharge adwcleaner sur ton bureau

    le lien https://toolslib.net

    utlisateurs vista-w7-w8 exécuter en tant qu'administrateur (clic droit)

    clique sur Scanner puis patiente le temps du scan

    une fois le scan terminé clique sur le bouton Nettoyer

    clique sur rapport pour qu'il s'affiche sur ton bureau

    le rapport est aussi sauvegarder dans C:\AdwCleaner\Adwcleaner [S0].txt

    poste le rapport via 1 copier/coller

    2) http://www.sosvirus.net/zhpcleaner-t92398.html

    poste le rapport via ce lien https://www.cjoint.com/

    3) refait 1 scan avec MBAM après l'avoir mit a jour

    dans l'onglet "examens" sélectionne "examen menaces" puis clique sur "examiner maintenant"

    a la fin du scan, clique sur "tout mettre en quarantaine " puis sur "appliquer les actions"

    si MBAM demande de redémarrer le pc, fait le

    le rapport s'affichera sur ton bureau, mais sera aussi disponible dans "historique" et "journaux de l'application"

    sélectionne le rapport et demande l'affichage (choisit bien le dernier en date)

    en bas a gauche, clique sur "exporter" et choisit "format texte"

    enregistre le sur ton bureau (pour le retrouver facilement)

    poste le rapport via 1 copier/coller dans ta prochaine réponse

    merci

    @+

    0
  8. kevin
     
    Voilà pour adwcleaner:

    # AdwCleaner v3.305 - Rapport créé le 14/08/2014 à 22:09:47
    # Mis à jour le 14/08/2014 par Xplode
    # Système d'exploitation : Windows 8 (64 bits)
    # Nom d'utilisateur : Home - HP
    # Exécuté depuis : C:\Users\Home\Desktop\adwcleaner_3.305.exe
    # Option : Nettoyer

    ***** [ Services ] *****

    ***** [ Fichiers / Dossiers ] *****

    ***** [ Tâches planifiées ] *****

    ***** [ Raccourcis ] *****

    ***** [ Registre ] *****

    Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
    Clé Supprimée : HKLM\Software\GlobalUpdate

    ***** [ Navigateurs ] *****

    -\\ Internet Explorer v10.0.9200.17028

    -\\ Mozilla Firefox v31.0 (x86 fr)

    [ Fichier : C:\Users\Home\AppData\Roaming\Mozilla\Firefox\Profiles\wiayun8r.default\prefs.js ]

    Ligne Supprimée : user_pref("extensions.ahermanthorne45outlookcom61787.61787.internaldb.monetization_plugin_bundledUrls.value", "%7B%22dealply_s%22%3A%7B%22urls%22%3A%5B%22ssfiles.com%22%5D%7D%2C%22dealply_p%22%3A%7B%2[...]

    -\\ Google Chrome v36.0.1985.125

    [ Fichier : C:\Users\Home\AppData\Local\Google\Chrome\User Data\Default\preferences ]

    *************************

    AdwCleaner[R0].txt - [1297 octets] - [14/08/2014 22:06:58]
    AdwCleaner[R1].txt - [1357 octets] - [14/08/2014 22:08:35]
    AdwCleaner[S0].txt - [1282 octets] - [14/08/2014 22:09:47]

    ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [1342 octets] ##########

    Pour ZHPcleaner : http://cjoint.com/?3HowWKkPzoD

    Et enfin MBAM :

    Malwarebytes Anti-Malware
    www.malwarebytes.org

    Scan Date: 14-08-14
    Scan Time: 22:24:14
    Logfile: rapport malwares.txt
    Administrator: Yes

    Version: 2.00.2.1012
    Malware Database: v2014.08.14.10
    Rootkit Database: v2014.08.04.01
    License: Free
    Malware Protection: Disabled
    Malicious Website Protection: Disabled
    Self-protection: Disabled

    OS: Windows 8
    CPU: x64
    File System: NTFS
    User: Home

    Scan Type: Threat Scan
    Result: Completed
    Objects Scanned: 314521
    Time Elapsed: 17 min, 54 sec

    Memory: Enabled
    Startup: Enabled
    Filesystem: Enabled
    Archives: Enabled
    Rootkits: Disabled
    Heuristics: Enabled
    PUP: Enabled
    PUM: Enabled

    Processes: 0
    (No malicious items detected)

    Modules: 0
    (No malicious items detected)

    Registry Keys: 0
    (No malicious items detected)

    Registry Values: 0
    (No malicious items detected)

    Registry Data: 0
    (No malicious items detected)

    Folders: 0
    (No malicious items detected)

    Files: 0
    (No malicious items detected)

    Physical Sectors: 0
    (No malicious items detected)

    (end)

    Voilà j'ai suivi les instructions à la lettre
    0
  9. billmaxime Messages postés 50525 Date d'inscription   Statut Contributeur Dernière intervention   6 152
     
    re

    Voilà j'ai suivi les instructions à la lettre

    oui, je vois ça^^

    refait moi 1 zhpdiag "complet" et poste le via ce lien https://www.cjoint.com/

    merci

    @+
    0
  10. billmaxime Messages postés 50525 Date d'inscription   Statut Contributeur Dernière intervention   6 152
     
    re

    dis moi si ceci est normal

    O17 - HKLM\System\CCS\Services\Tcpip\..\{49E07008-D08C-4B6B-9492-C634D6FF11F1}: DhcpNameServer = 40.24.1.201 40.24.1.202>>IP DES ETAS_UNIS
    O17 - HKLM\System\CCS\Services\Tcpip\..\{49E07008-D08C-4B6B-9492-C634D6FF11F1}: DhcpDomain = E1-Line.com>>VPN?

    tu peux désinstaller ceci

    Adobe Reader X
    Java 7 Update 60
    Adobe Shockwave Player 11.6

    et télécharger puis installer les dernières versions depuis ces liens

    adobe reader prend la version 11...
    Adobe Shockwave Player
    java

    ps: décoche les programmes additionnels (MCAFEE etc...)

    @+

    0
  11. kevin
     
    Voila j'ai désinstallé et réinstallé les 3 programmes.

    Par contre le reste je sais pas ce que c'est!

    O17 - HKLM\System\CCS\Services\Tcpip\..\{49E07008-D08C-4B6B-9492-C634D6FF11F1}: DhcpNameServer = 40.24.1.201 40.24.1.202>>IP DES ETAS_UNIS
    O17 - HKLM\System\CCS\Services\Tcpip\..\{49E07008-D08C-4B6B-9492-C634D6FF11F1}: DhcpDomain = E1-Line.com>>VPN?

    C'est un virus?
    0
  12. billmaxime Messages postés 50525 Date d'inscription   Statut Contributeur Dernière intervention   6 152
     
    re

    Voila j'ai désinstallé et réinstallé les 3 programmes.

    ok

    fait ceci et poste le rapport

    Télécharge roguekiller sur ton bureau

    prends le x64,regarde l'image clique ici

    Le lien https://www.luanagames.com/index.fr.html

    Le tuto http://tigzyrk.blogspot.be/2012/10/fr-roguekiller-tutoriel-officiel.html

    Quitte tous tes programmes en cours

    Lance roguekiller (utilisateurs vista-w7-w8 exécuter en tant qu'administrateur- clic droit)

    Laisse faire le prescan

    Clique sur scan

    Le rapport s'affichera sur ton bureau et dans C: RKReport[#].txt

    Poste le rapport via 1 copier/coller

    merci

    @+

    0
  13. kevin
     
    Voilà pour le rapport :

    RogueKiller V9.2.8.0 (x64) [Jul 11 2014] par Adlice Software
    Mail : http://www.adlice.com/contact/
    Remontées : http://forum.adlice.com
    Site Web : http://www.surlatoile.org/RogueKiller/
    Blog : http://www.adlice.com

    Système d'exploitation : Windows 8 (6.2.9200 ) 64 bits version
    Démarrage : Mode normal
    Utilisateur : Home [Droits d'admin]
    Mode : Recherche -- Date : 08/15/2014 11:33:47

    ¤¤¤ Processus malicieux : 1 ¤¤¤
    [Suspicious.Path] (SVC) scores -- C:\Windows\score.exe[-] -> STOPPÉ

    ¤¤¤ Entrées de registre : 16 ¤¤¤
    [Suspicious.Path] (X64) HKEY_USERS\S-1-5-21-2254641191-106435527-948302892-1001\Software\Microsoft\Windows\CurrentVersion\Run | Google+ Auto Backup : "C:\Users\Home\AppData\Local\Programs\Google\Google+ Auto Backup\Google+ Auto Backup.exe" /autostart -> TROUVÉ
    [Suspicious.Path] (X86) HKEY_USERS\S-1-5-21-2254641191-106435527-948302892-1001\Software\Microsoft\Windows\CurrentVersion\Run | Google+ Auto Backup : "C:\Users\Home\AppData\Local\Programs\Google\Google+ Auto Backup\Google+ Auto Backup.exe" /autostart -> TROUVÉ
    [Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\scores -> TROUVÉ
    [Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\WindowsMangerProtect -> TROUVÉ
    [Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\scores -> TROUVÉ
    [Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WindowsMangerProtect -> TROUVÉ
    [PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{49E07008-D08C-4B6B-9492-C634D6FF11F1} | DhcpNameServer : 40.24.1.201 40.24.1.202 -> TROUVÉ
    [PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{49E07008-D08C-4B6B-9492-C634D6FF11F1} | DhcpNameServer : 40.24.1.201 40.24.1.202 -> TROUVÉ
    [PUM.DesktopIcons] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> TROUVÉ
    [PUM.DesktopIcons] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> TROUVÉ
    [PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> TROUVÉ
    [PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> TROUVÉ
    [PUM.HomePage] (X64) HKEY_USERS\S-1-5-21-2254641191-106435527-948302892-1001\Software\Microsoft\Internet Explorer\Main | Start Page : http://google.com -> TROUVÉ
    [PUM.HomePage] (X86) HKEY_USERS\S-1-5-21-2254641191-106435527-948302892-1001\Software\Microsoft\Internet Explorer\Main | Start Page : http://google.com -> TROUVÉ
    [PUM.SearchPage] (X64) HKEY_USERS\S-1-5-21-2254641191-106435527-948302892-1001\Software\Microsoft\Internet Explorer\Main | Search Page : http://google.com -> TROUVÉ
    [PUM.SearchPage] (X86) HKEY_USERS\S-1-5-21-2254641191-106435527-948302892-1001\Software\Microsoft\Internet Explorer\Main | Search Page : http://google.com -> TROUVÉ

    ¤¤¤ Tâches planifiées : 0 ¤¤¤

    ¤¤¤ Fichiers : 0 ¤¤¤

    ¤¤¤ Fichier HOSTS : 0 ¤¤¤

    ¤¤¤ Antirootkit : 28 (Driver: CHARGE) ¤¤¤
    [EAT:Addr] (explorer.exe) webio.dll - BatMeterIconAnimationReset : C:\Windows\system32\BatMeter.dll @ 0x7ffca4a4554
    [EAT:Addr] (explorer.exe) webio.dll - BatMeterIconThemeReset : C:\Windows\system32\BatMeter.dll @ 0x7ffca4a46ec
    [EAT:Addr] (explorer.exe) webio.dll - BatMeterOnDeviceChange : C:\Windows\system32\BatMeter.dll @ 0x7ffca4a4134
    [EAT:Addr] (explorer.exe) webio.dll - CleanupBatteryData : C:\Windows\system32\BatMeter.dll @ 0x7ffca4a1884
    [EAT:Addr] (explorer.exe) webio.dll - CreateBatteryData : C:\Windows\system32\BatMeter.dll @ 0x7ffca4a2b98
    [EAT:Addr] (explorer.exe) webio.dll - GetBatMeterIconAnimationState : C:\Windows\system32\BatMeter.dll @ 0x7ffca4a41f0
    [EAT:Addr] (explorer.exe) webio.dll - GetBatMeterIconAnimationTimeDelay : C:\Windows\system32\BatMeter.dll @ 0x7ffca4a4370
    [EAT:Addr] (explorer.exe) webio.dll - GetBatMeterIconAnimationUpdate : C:\Windows\system32\BatMeter.dll @ 0x7ffca4a4494
    [EAT:Addr] (explorer.exe) webio.dll - GetBatteryCapacityInfo : C:\Windows\system32\BatMeter.dll @ 0x7ffca4a3f18
    [EAT:Addr] (explorer.exe) webio.dll - GetBatteryDetails : C:\Windows\system32\BatMeter.dll @ 0x7ffca4a5ad0
    [EAT:Addr] (explorer.exe) webio.dll - GetBatteryImmersiveIcon : C:\Windows\system32\BatMeter.dll @ 0x7ffca4a2060
    [EAT:Addr] (explorer.exe) webio.dll - GetBatteryInfo : C:\Windows\system32\BatMeter.dll @ 0x7ffca4a5100
    [EAT:Addr] (explorer.exe) webio.dll - GetBatteryStatusText : C:\Windows\system32\BatMeter.dll @ 0x7ffca4a5190
    [EAT:Addr] (explorer.exe) webio.dll - GetBatteryWorkingState : C:\Windows\system32\BatMeter.dll @ 0x7ffca4a19c0
    [EAT:Addr] (explorer.exe) webio.dll - IsBatteryBad : C:\Windows\system32\BatMeter.dll @ 0x7ffca4a3f0c
    [EAT:Addr] (explorer.exe) webio.dll - IsBatteryHealthWarningEnabled : C:\Windows\system32\BatMeter.dll @ 0x7ffca4a3f00
    [EAT:Addr] (explorer.exe) webio.dll - IsBatteryLevelCritical : C:\Windows\system32\BatMeter.dll @ 0x7ffca4a3ec4
    [EAT:Addr] (explorer.exe) webio.dll - IsBatteryLevelLow : C:\Windows\system32\BatMeter.dll @ 0x7ffca4a3ed8
    [EAT:Addr] (explorer.exe) webio.dll - IsBatteryLevelReserve : C:\Windows\system32\BatMeter.dll @ 0x7ffca4a3eec
    [EAT:Addr] (explorer.exe) webio.dll - PowerCapabilities : C:\Windows\system32\BatMeter.dll @ 0x7ffca4a1560
    [EAT:Addr] (explorer.exe) webio.dll - QueryBatteryData : C:\Windows\system32\BatMeter.dll @ 0x7ffca4a2c44
    [EAT:Addr] (explorer.exe) webio.dll - SetBatteryHealthWarningState : C:\Windows\system32\BatMeter.dll @ 0x7ffca4a3f00
    [EAT:Addr] (explorer.exe) webio.dll - SetBatteryLevel : C:\Windows\system32\BatMeter.dll @ 0x7ffca4a27a0
    [EAT:Addr] (explorer.exe) webio.dll - SetBatteryWorkingState : C:\Windows\system32\BatMeter.dll @ 0x7ffca4a1048
    [EAT:Addr] (explorer.exe) webio.dll - SubscribeBatteryUpdateNotification : C:\Windows\system32\BatMeter.dll @ 0x7ffca4a1fb8
    [EAT:Addr] (explorer.exe) webio.dll - UnsubscribeBatteryUpdateNotification : C:\Windows\system32\BatMeter.dll @ 0x7ffca4a1980
    [EAT:Addr] (explorer.exe) webio.dll - UpdateBatteryData : C:\Windows\system32\BatMeter.dll @ 0x7ffca4a50c4
    [EAT:Addr] (explorer.exe) webio.dll - UpdateBatteryDataAsync : C:\Windows\system32\BatMeter.dll @ 0x7ffca4a1b60

    ¤¤¤ Navigateurs web : 0 ¤¤¤

    ¤¤¤ MBR Verif : ¤¤¤
    +++++ PhysicalDrive0: TOSHIBA MQ01ABD050 +++++
    --- User ---
    [MBR] 1ed7d5618ae5146251d39ebe4735f6d2
    [BSP] 586473aada26c52be1b3741449848d7b : Unknown MBR Code
    Partition table:
    0 - [XXXXXX] UNKNOWN (0x0) [VISIBLE] Offset (sectors): 1 | Size: 476940 MB
    User = LL1 ... OK
    User = LL2 ... OK
    0
  14. billmaxime Messages postés 50525 Date d'inscription   Statut Contributeur Dernière intervention   6 152
     
    re

    tu relances roguekiller (si tu l'as fermé)

    tu laisses faire le pré-scan etc...

    quand le scan est terminé, dans l'onglet REGISTRE, tu sélectionnes tous les éléments

    détectés et tu cliques sur SUPPRIMER

    poste le rapport via 1 copier/coller

    merci

    @+
    0
  15. kevin
     
    voilà j'avais laissé le programme ouvert donc j'ai supprimé tout dans l'onglet REGISTRE etvoilà le rapport

    RogueKiller V9.2.8.0 (x64) [Jul 11 2014] par Adlice Software
    Mail : http://www.adlice.com/contact/
    Remontées : http://forum.adlice.com
    Site Web : http://www.surlatoile.org/RogueKiller/
    Blog : http://www.adlice.com

    Système d'exploitation : Windows 8 (6.2.9200 ) 64 bits version
    Démarrage : Mode normal
    Utilisateur : Home [Droits d'admin]
    Mode : Suppression -- Date : 08/15/2014 11:57:49

    ¤¤¤ Processus malicieux : 1 ¤¤¤
    [Suspicious.Path] (SVC) scores -- C:\Windows\score.exe[-] -> STOPPÉ

    ¤¤¤ Entrées de registre : 16 ¤¤¤
    [Suspicious.Path] (X64) HKEY_USERS\S-1-5-21-2254641191-106435527-948302892-1001\Software\Microsoft\Windows\CurrentVersion\Run | Google+ Auto Backup : "C:\Users\Home\AppData\Local\Programs\Google\Google+ Auto Backup\Google+ Auto Backup.exe" /autostart [x] -> SUPPRIMÉ
    [Suspicious.Path] (X86) HKEY_USERS\S-1-5-21-2254641191-106435527-948302892-1001\Software\Microsoft\Windows\CurrentVersion\Run | Google+ Auto Backup : "C:\Users\Home\AppData\Local\Programs\Google\Google+ Auto Backup\Google+ Auto Backup.exe" /autostart -> ERROR [2]
    [Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\scores -> SUPPRIMÉ
    [Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\WindowsMangerProtect -> SUPPRIMÉ
    [Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\scores -> SUPPRIMÉ
    [Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WindowsMangerProtect -> SUPPRIMÉ
    [PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{49E07008-D08C-4B6B-9492-C634D6FF11F1} | DhcpNameServer : 40.24.1.201 40.24.1.202 -> REMPLACÉ ()
    [PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{49E07008-D08C-4B6B-9492-C634D6FF11F1} | DhcpNameServer : 40.24.1.201 40.24.1.202 -> REMPLACÉ ()
    [PUM.DesktopIcons] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> REMPLACÉ (0)
    [PUM.DesktopIcons] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> REMPLACÉ (0)
    [PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> REMPLACÉ (0)
    [PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> REMPLACÉ (0)
    [PUM.HomePage] (X64) HKEY_USERS\S-1-5-21-2254641191-106435527-948302892-1001\Software\Microsoft\Internet Explorer\Main | Start Page : http://google.com -> REMPLACÉ (http://go.microsoft.com/fwlink/p/?LinkId=255141)
    [PUM.HomePage] (X86) HKEY_USERS\S-1-5-21-2254641191-106435527-948302892-1001\Software\Microsoft\Internet Explorer\Main | Start Page : http://google.com -> REMPLACÉ (http://go.microsoft.com/fwlink/p/?LinkId=255141)
    [PUM.SearchPage] (X64) HKEY_USERS\S-1-5-21-2254641191-106435527-948302892-1001\Software\Microsoft\Internet Explorer\Main | Search Page : http://google.com -> REMPLACÉ (http://go.microsoft.com/fwlink/?LinkId=54896)
    [PUM.SearchPage] (X86) HKEY_USERS\S-1-5-21-2254641191-106435527-948302892-1001\Software\Microsoft\Internet Explorer\Main | Search Page : http://google.com -> REMPLACÉ (http://go.microsoft.com/fwlink/?LinkId=54896)

    ¤¤¤ Tâches planifiées : 0 ¤¤¤

    ¤¤¤ Fichiers : 0 ¤¤¤

    ¤¤¤ Fichier HOSTS : 0 ¤¤¤

    ¤¤¤ Antirootkit : 28 (Driver: CHARGE) ¤¤¤
    [EAT:Addr] (explorer.exe) webio.dll - BatMeterIconAnimationReset : C:\Windows\system32\BatMeter.dll @ 0x7ffca4a4554
    [EAT:Addr] (explorer.exe) webio.dll - BatMeterIconThemeReset : C:\Windows\system32\BatMeter.dll @ 0x7ffca4a46ec
    [EAT:Addr] (explorer.exe) webio.dll - BatMeterOnDeviceChange : C:\Windows\system32\BatMeter.dll @ 0x7ffca4a4134
    [EAT:Addr] (explorer.exe) webio.dll - CleanupBatteryData : C:\Windows\system32\BatMeter.dll @ 0x7ffca4a1884
    [EAT:Addr] (explorer.exe) webio.dll - CreateBatteryData : C:\Windows\system32\BatMeter.dll @ 0x7ffca4a2b98
    [EAT:Addr] (explorer.exe) webio.dll - GetBatMeterIconAnimationState : C:\Windows\system32\BatMeter.dll @ 0x7ffca4a41f0
    [EAT:Addr] (explorer.exe) webio.dll - GetBatMeterIconAnimationTimeDelay : C:\Windows\system32\BatMeter.dll @ 0x7ffca4a4370
    [EAT:Addr] (explorer.exe) webio.dll - GetBatMeterIconAnimationUpdate : C:\Windows\system32\BatMeter.dll @ 0x7ffca4a4494
    [EAT:Addr] (explorer.exe) webio.dll - GetBatteryCapacityInfo : C:\Windows\system32\BatMeter.dll @ 0x7ffca4a3f18
    [EAT:Addr] (explorer.exe) webio.dll - GetBatteryDetails : C:\Windows\system32\BatMeter.dll @ 0x7ffca4a5ad0
    [EAT:Addr] (explorer.exe) webio.dll - GetBatteryImmersiveIcon : C:\Windows\system32\BatMeter.dll @ 0x7ffca4a2060
    [EAT:Addr] (explorer.exe) webio.dll - GetBatteryInfo : C:\Windows\system32\BatMeter.dll @ 0x7ffca4a5100
    [EAT:Addr] (explorer.exe) webio.dll - GetBatteryStatusText : C:\Windows\system32\BatMeter.dll @ 0x7ffca4a5190
    [EAT:Addr] (explorer.exe) webio.dll - GetBatteryWorkingState : C:\Windows\system32\BatMeter.dll @ 0x7ffca4a19c0
    [EAT:Addr] (explorer.exe) webio.dll - IsBatteryBad : C:\Windows\system32\BatMeter.dll @ 0x7ffca4a3f0c
    [EAT:Addr] (explorer.exe) webio.dll - IsBatteryHealthWarningEnabled : C:\Windows\system32\BatMeter.dll @ 0x7ffca4a3f00
    [EAT:Addr] (explorer.exe) webio.dll - IsBatteryLevelCritical : C:\Windows\system32\BatMeter.dll @ 0x7ffca4a3ec4
    [EAT:Addr] (explorer.exe) webio.dll - IsBatteryLevelLow : C:\Windows\system32\BatMeter.dll @ 0x7ffca4a3ed8
    [EAT:Addr] (explorer.exe) webio.dll - IsBatteryLevelReserve : C:\Windows\system32\BatMeter.dll @ 0x7ffca4a3eec
    [EAT:Addr] (explorer.exe) webio.dll - PowerCapabilities : C:\Windows\system32\BatMeter.dll @ 0x7ffca4a1560
    [EAT:Addr] (explorer.exe) webio.dll - QueryBatteryData : C:\Windows\system32\BatMeter.dll @ 0x7ffca4a2c44
    [EAT:Addr] (explorer.exe) webio.dll - SetBatteryHealthWarningState : C:\Windows\system32\BatMeter.dll @ 0x7ffca4a3f00
    [EAT:Addr] (explorer.exe) webio.dll - SetBatteryLevel : C:\Windows\system32\BatMeter.dll @ 0x7ffca4a27a0
    [EAT:Addr] (explorer.exe) webio.dll - SetBatteryWorkingState : C:\Windows\system32\BatMeter.dll @ 0x7ffca4a1048
    [EAT:Addr] (explorer.exe) webio.dll - SubscribeBatteryUpdateNotification : C:\Windows\system32\BatMeter.dll @ 0x7ffca4a1fb8
    [EAT:Addr] (explorer.exe) webio.dll - UnsubscribeBatteryUpdateNotification : C:\Windows\system32\BatMeter.dll @ 0x7ffca4a1980
    [EAT:Addr] (explorer.exe) webio.dll - UpdateBatteryData : C:\Windows\system32\BatMeter.dll @ 0x7ffca4a50c4
    [EAT:Addr] (explorer.exe) webio.dll - UpdateBatteryDataAsync : C:\Windows\system32\BatMeter.dll @ 0x7ffca4a1b60

    ¤¤¤ Navigateurs web : 0 ¤¤¤

    ¤¤¤ MBR Verif : ¤¤¤
    +++++ PhysicalDrive0: TOSHIBA MQ01ABD050 +++++
    --- User ---
    [MBR] 1ed7d5618ae5146251d39ebe4735f6d2
    [BSP] 586473aada26c52be1b3741449848d7b : Unknown MBR Code
    Partition table:
    0 - [XXXXXX] UNKNOWN (0x0) [VISIBLE] Offset (sectors): 1 | Size: 476940 MB
    User = LL1 ... OK
    User = LL2 ... OK

    ============================================
    RKreport_SCN_08152014_113347.log
    0
  16. billmaxime Messages postés 50525 Date d'inscription   Statut Contributeur Dernière intervention   6 152
     
    re

    ok, refait 1 scan avec MBAM et poste le rapport via 1 copier/coller

    ps: met le a jour avant de lancer le scan

    merci

    @+
    0
  17. kevin
     
    Voilà,

    Malwarebytes Anti-Malware
    www.malwarebytes.org

    Scan Date: 15-08-14
    Scan Time: 12:06:26
    Logfile: MLMM no malwared.txt
    Administrator: Yes

    Version: 2.00.2.1012
    Malware Database: v2014.08.15.03
    Rootkit Database: v2014.08.04.01
    License: Free
    Malware Protection: Disabled
    Malicious Website Protection: Disabled
    Self-protection: Disabled

    OS: Windows 8
    CPU: x64
    File System: NTFS
    User: Home

    Scan Type: Threat Scan
    Result: Completed
    Objects Scanned: 314671
    Time Elapsed: 1 hr, 0 min, 34 sec

    Memory: Enabled
    Startup: Enabled
    Filesystem: Enabled
    Archives: Enabled
    Rootkits: Disabled
    Heuristics: Enabled
    PUP: Enabled
    PUM: Enabled

    Processes: 0
    (No malicious items detected)

    Modules: 0
    (No malicious items detected)

    Registry Keys: 0
    (No malicious items detected)

    Registry Values: 0
    (No malicious items detected)

    Registry Data: 0
    (No malicious items detected)

    Folders: 0
    (No malicious items detected)

    Files: 0
    (No malicious items detected)

    Physical Sectors: 0
    (No malicious items detected)

    (end)

    Apparemment il n'a pas détecté de malwares
    0
  18. billmaxime Messages postés 50525 Date d'inscription   Statut Contributeur Dernière intervention   6 152
     
    re

    ok, refait 1 zhpdiag "complet" pour contrôle et poste le rapport via ce lien

    https://www.cjoint.com/

    merci

    @+
    0
  19. kevin
     
    Voilà ci joint : http://cjoint.com/?3HpnBcS4z15
    0
  20. billmaxime Messages postés 50525 Date d'inscription   Statut Contributeur Dernière intervention   6 152
     
    re

    ok, fait ceci et poste le rapport

    copie tout le texte depuis ce lien https://www.cjoint.com/c/DHpn4LuU0vv

    lance zhpfix en tant qu'administrateur (clic droit)

    clique sur importer et le texte s'affichera dans la fenêtre qui s'ouvre

    clic sur GO en bas de page et confirme par OUI pour

    lancer le nettoyage des données

    le rapport s'affichera sur ton bureau et dans C:\zhpfix.txt

    poste le rapport via ce lien https://www.cjoint.com/

    merci

    @+

    0
  • 1
  • 2