Autorun.inf

Bonjour,
autorun.inf c'est un virus ou pas ?? j'ais trop de fichier comme ca dans mon pc ??
c'est ses un virus comment le supprimer ??

aider moi svp merci !

--
♠♠ j'ais essaye d'arreter j'ais pas pue désole ! ♠♠

29 réponses

Résumé de la discussion

Autorun.inf est perçu comme une menace potentielle sur le PC et peut générer de nombreux fichiers indésirables, nécessitant une procédure de nettoyage et de vérification des périphériques externes. La solution préconisée repose sur UsbFix pour nettoyer et produire un rapport, avec exécution en tant qu'administrateur et suppression ciblée des éléments malveillants, et l'outil peut être complété par d'autres mesures selon le contexte. En parallèle, des conseils décrivent la désactivation temporaire de la fonction d'autostart et l'examen du rapport final pour identifier les éléments à corriger et reconfigurer les paramètres système concernés. Certains outils tels que ZHPDiag permettent de compléter le diagnostic, vérifier les traces et sécuriser le poste après nettoyage, notamment en analysant les rapports générés par UsbFix.

Bobot (l’IA à votre service)
  1. voila
    OTL logfile created on: 13/03/2011 22:50:42 - Run 2
    OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\am1.cr\Desktop
    Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
    Internet Explorer (Version = 8.0.7600.16385)
    Locale: 0000040c | Country: France | Language: FRA | Date Format: dd/MM/yyyy

    959,00 Mb Total Physical Memory | 213,00 Mb Available Physical Memory | 22,00% Memory free
    2,00 Gb Paging File | 1,00 Gb Available in Paging File | 54,00% Paging File free
    Paging file location(s): c:\pagefile.sys 0 0f:\pagefile.sys 1000 1001 [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
    Drive C: | 15,04 Gb Total Space | 0,99 Gb Free Space | 6,55% Space Free | Partition Type: NTFS
    Drive D: | 10,16 Gb Total Space | 0,39 Gb Free Space | 3,89% Space Free | Partition Type: NTFS
    Drive E: | 7,19 Gb Total Space | 2,54 Gb Free Space | 35,33% Space Free | Partition Type: NTFS
    Drive F: | 8,13 Gb Total Space | 3,00 Gb Free Space | 36,95% Space Free | Partition Type: NTFS
    Drive G: | 12,05 Gb Total Space | 10,48 Gb Free Space | 86,96% Space Free | Partition Type: NTFS
    Drive H: | 21,96 Gb Total Space | 6,07 Gb Free Space | 27,66% Space Free | Partition Type: NTFS
    Drive J: | 4,24 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: UDF
    Drive L: | 3,73 Gb Total Space | 0,19 Gb Free Space | 5,11% Space Free | Partition Type: FAT32

    Computer Name: AM1CR-PC | User Name: am1.cr | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: Current user
    Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

    [color=#E56717]========== Processes (SafeList) ==========[/color]

    PRC - File not found --
    PRC - [2011/02/23 16:04:20 | 003,451,496 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe
    PRC - [2011/01/07 23:48:12 | 000,108,080 | ---- | M] () -- C:\Program Files\Hotspot Shield\bin\openvpntray.exe
    PRC - [2010/10/03 12:02:08 | 000,176,128 | ---- | M] (FaceMoi) -- C:\Facemoi\facemoi.exe
    PRC - [2009/10/31 06:45:39 | 002,614,272 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
    PRC - [2009/07/14 02:14:42 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
    PRC - [2009/04/14 07:43:42 | 000,604,704 | ---- | M] (Realtek Semiconductor Corp.) -- C:\Windows\SOUNDMAN.EXE

    [color=#E56717]========== Modules (SafeList) ==========[/color]

    MOD - [2011/02/23 16:04:17 | 000,197,208 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\snxhk.dll
    MOD - [2010/08/21 06:21:32 | 001,680,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll
    MOD - [2009/07/14 02:15:20 | 000,027,136 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\fdProxy.dll

    [color=#E56717]========== Win32 Services (SafeList) ==========[/color]

    SRV - File not found [Auto | Running] -- -- (HssSrv)
    SRV - [2011/02/23 16:04:19 | 000,042,184 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
    SRV - [2011/02/23 16:04:17 | 000,121,000 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\afwServ.exe -- (avast! Firewall)
    SRV - [2011/01/07 23:48:18 | 000,057,640 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\Hotspot Shield\bin\HssTrayService.exe -- (HssTrayService)
    SRV - [2011/01/07 23:46:06 | 000,271,408 | ---- | M] () [Auto | Running] -- C:\Program Files\Hotspot Shield\bin\openvpnas.exe -- (HotspotShieldService)
    SRV - [2010/12/20 21:25:49 | 001,343,400 | ---- | M] (Microsoft Corporation) [Unknown | Stopped] -- C:\Windows\System32\Wat\WatAdminSvc.exe -- (WatAdminSvc)
    SRV - [2010/10/15 19:42:14 | 000,326,704 | ---- | M] () [Auto | Running] -- C:\Program Files\Hotspot Shield\bin\hsswd.exe -- (HssWd)
    SRV - [2009/07/14 02:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
    SRV - [2009/07/14 02:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc)
    SRV - [2009/07/14 02:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)

    [color=#E56717]========== Driver Services (SafeList) ==========[/color]

    DRV - File not found [Kernel | On_Demand | Running] -- -- (HssDrv)
    DRV - [2011/02/23 15:57:38 | 000,101,976 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswFW.sys -- (aswFW)
    DRV - [2011/02/23 15:56:55 | 000,371,544 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\System32\drivers\aswSnx.sys -- (aswSnx)
    DRV - [2011/02/23 15:56:45 | 000,301,528 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswSP.sys -- (aswSP)
    DRV - [2011/02/23 15:56:41 | 000,192,728 | ---- | M] (AVAST Software) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\aswNdis2.sys -- (aswNdis2)
    DRV - [2011/02/23 15:55:49 | 000,049,240 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswTdi.sys -- (aswTdi)
    DRV - [2011/02/23 15:55:10 | 000,025,432 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswRdr.sys -- (aswRdr)
    DRV - [2011/02/23 15:55:03 | 000,053,592 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\System32\drivers\aswMonFlt.sys -- (aswMonFlt)
    DRV - [2011/02/23 15:54:55 | 000,019,544 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\System32\drivers\aswFsBlk.sys -- (aswFsBlk)
    DRV - [2011/02/23 14:34:54 | 000,012,112 | ---- | M] (ALWIL Software) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\aswNdis.sys -- (aswNdis)
    DRV - [2010/09/22 20:19:02 | 000,032,768 | ---- | M] (AnchorFree Inc) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\taphss.sys -- (taphss)
    DRV - [2009/07/14 02:19:10 | 000,175,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\vmbus.sys -- (vmbus)
    DRV - [2009/07/14 02:19:10 | 000,040,896 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\vmstorfl.sys -- (storflt)
    DRV - [2009/07/14 02:19:10 | 000,028,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\storvsc.sys -- (storvsc)
    DRV - [2009/07/14 00:28:47 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\vms3cap.sys -- (s3cap)
    DRV - [2009/07/14 00:28:45 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\VMBusHID.sys -- (VMBusHID)
    DRV - [2009/07/13 23:02:53 | 000,044,032 | ---- | M] (VIA Technologies, Inc. ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\fetnd6.sys -- (FETNDIS)
    DRV - [2009/07/13 23:02:52 | 000,043,008 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Rtnicxp.sys -- (RTL8023xp)
    DRV - [2009/06/18 19:45:02 | 004,172,832 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\RTKVAC.SYS -- (ALCXWDM) Service for Realtek AC97 Audio (WDM)

    [color=#E56717]========== Standard Registry (SafeList) ==========[/color]

    [color=#E56717]========== Internet Explorer ==========[/color]

    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr

    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = https://www.msn.com/fr-fr?ocid=iehp
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = fr
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = E4 93 40 95 86 9F CB 01 [binary data]
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

    [color=#E56717]========== FireFox ==========[/color]

    FF - prefs.js..browser.search.defaultengine: ""
    FF - prefs.js..browser.search.defaultenginename: ""
    FF - prefs.js..browser.search.order.1: ""
    FF - prefs.js..browser.search.selectedEngine: ""
    FF - prefs.js..browser.search.selectedEngineURL: "http://mp3tubetoolbar.com/...{searchTerms}"
    FF - prefs.js..browser.startup.homepage: "http://mp3tubetoolbar.com/..."

    FF - HKLM\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF [2011/03/13 16:36:43 | 000,000,000 | ---D | M]

    [2011/01/07 11:43:13 | 000,000,000 | ---D | M] (No name found) -- C:\Users\am1.cr\AppData\Roaming\Mozilla\Extensions
    [2011/02/05 14:18:04 | 000,000,000 | ---D | M] (No name found) -- C:\Users\am1.cr\AppData\Roaming\Mozilla\FireFox\Profiles\0znx53qi.default\extensions
    [2011/02/05 14:15:37 | 000,000,000 | ---D | M] (Billeo) -- C:\Users\am1.cr\AppData\Roaming\Mozilla\FireFox\Profiles\0znx53qi.default\extensions\{4be68a18-deba-49e0-9e09-ee7796f3b62a}
    [2011/02/05 14:13:29 | 000,000,000 | ---D | M] (Temp Installer) -- C:\Users\am1.cr\AppData\Roaming\Mozilla\FireFox\Profiles\0znx53qi.default\extensions\{77868449-f49d-d6ec-3145-e651161b1ff8}
    [2011/02/05 14:18:05 | 000,000,000 | ---D | M] (KwiClick) -- C:\Users\am1.cr\AppData\Roaming\Mozilla\FireFox\Profiles\0znx53qi.default\extensions\vinceturk@gmail.com
    File not found (No name found) --
    [2011/03/13 16:36:43 | 000,000,000 | ---D | M] (avast! WebRep) -- C:\PROGRAM FILES\AVAST SOFTWARE\AVAST\WEBREP\FF
    File not found (No name found) -- D:\PROGRAM FILES\MOZILLA FIREFOX 4.0 BETA 3\EXTENSIONS\{34EFA911-B536-4C08-BECE-CD5E55C875B0}
    [2010/12/12 22:52:45 | 000,000,000 | ---D | M] (Skype extension) -- D:\PROGRAM FILES\MOZILLA FIREFOX 4.0 BETA 3\EXTENSIONS\{AB2CE124-6272-4B12-94A9-7303C7397BD1}
    [2010/12/13 13:16:38 | 000,000,000 | ---D | M] (MP3Tube Toolbar) -- D:\PROGRAM FILES\MOZILLA FIREFOX 4.0 BETA 3\EXTENSIONS\MP3TUBETOOLBAR@MP3TUBETOOLBAR.COM
    [2011/01/08 18:29:12 | 000,000,000 | ---D | M] (Feedback) -- D:\PROGRAM FILES\MOZILLA FIREFOX 4.0 BETA 3\EXTENSIONS\TESTPILOT@LABS.MOZILLA.COM

    O1 HOSTS File: ([2009/06/10 22:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
    O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll ()
    O2 - BHO: (WOT Helper) - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files\WOT\WOT.dll ()
    O3 - HKLM\..\Toolbar: (WOT) - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
    O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll ()
    O3 - HKCU\..\Toolbar\WebBrowser: (WOT) - {71576546-354D-41C9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
    O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
    O4 - HKLM..\Run: [Facemoi] c:\Facemoi\facemoi.exe (FaceMoi)
    O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
    O4 - HKLM..\Run: [SoundMan] C:\Windows\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
    O4 - HKCU..\Run: [Facemoi] C:\Facemoi\facemoi.exe (FaceMoi)
    O4 - HKLM..\RunOnce: [OTL] File not found
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 3
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 0
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 3
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 0
    O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr (Google Inc.)
    O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
    O13 - gopher Prefix: missing
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
    O18 - Protocol\Handler\wot {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll ()
    O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
    O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
    O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
    O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
    O32 - HKLM CDRom: AutoRun - 1
    O32 - AutoRun File - [2009/06/10 22:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
    O32 - AutoRun File - [2011/03/13 20:09:14 | 000,000,000 | RHSD | M] - C:\Autorun.inf -- [ NTFS ]
    O32 - AutoRun File - [2009/06/10 22:42:20 | 000,000,024 | ---- | M] () - D:\autoexec.bat -- [ NTFS ]
    O32 - AutoRun File - [2011/03/13 20:09:14 | 000,000,000 | RHSD | M] - D:\Autorun.inf -- [ NTFS ]
    O32 - AutoRun File - [2011/03/13 20:09:14 | 000,000,000 | RHSD | M] - E:\Autorun.inf -- [ NTFS ]
    O32 - AutoRun File - [2011/03/13 20:09:14 | 000,000,000 | RHSD | M] - F:\Autorun.inf -- [ NTFS ]
    O32 - AutoRun File - [2011/03/13 20:09:14 | 000,000,000 | RHSD | M] - G:\Autorun.inf -- [ NTFS ]
    O32 - AutoRun File - [2011/03/13 20:09:14 | 000,000,000 | RHSD | M] - H:\Autorun.inf -- [ NTFS ]
    O32 - AutoRun File - [2011/03/13 20:09:16 | 000,000,000 | RHSD | M] - L:\Autorun.inf -- [ FAT32 ]
    O34 - HKLM BootExecute: (autocheck autochk *) - File not found
    O35 - HKLM\..comfile [open] -- "%1" %*
    O35 - HKLM\..exefile [open] -- "%1" %*
    O37 - HKLM\...com [@ = comfile] -- "%1" %*
    O37 - HKLM\...exe [@ = exefile] -- "%1" %*

    [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]

    [2011/03/13 22:23:33 | 000,000,000 | ---D | C] -- C:\_OTL
    [2011/03/13 21:15:56 | 000,000,000 | ---D | C] -- C:\Program Files\Ad-Remover
    [2011/03/13 20:09:14 | 000,000,000 | RHSD | C] -- C:\Autorun.inf
    [2011/03/13 19:05:47 | 000,000,000 | ---D | C] -- C:\UsbFix
    [2011/03/13 18:45:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ZHP
    [2011/03/13 16:38:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\avast! Internet Security
    [2011/03/13 16:38:20 | 000,301,528 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswSP.sys
    [2011/03/13 16:38:20 | 000,019,544 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswFsBlk.sys
    [2011/03/13 16:37:58 | 000,101,976 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswFW.sys
    [2011/03/13 16:37:28 | 000,192,728 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswNdis2.sys
    [2011/03/13 16:37:28 | 000,025,432 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswRdr.sys
    [2011/03/13 16:37:27 | 000,371,544 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswSnx.sys
    [2011/03/13 16:37:27 | 000,049,240 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswTdi.sys
    [2011/03/13 16:37:25 | 000,053,592 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswMonFlt.sys
    [2011/03/13 16:36:39 | 000,012,112 | ---- | C] (ALWIL Software) -- C:\Windows\System32\drivers\aswNdis.sys
    [2011/03/13 16:36:37 | 000,040,648 | ---- | C] (AVAST Software) -- C:\Windows\avastSS.scr
    [2011/03/13 16:36:36 | 000,190,016 | ---- | C] (AVAST Software) -- C:\Windows\System32\aswBoot.exe
    [2011/03/13 16:36:29 | 000,000,000 | ---D | C] -- C:\ProgramData\AVAST Software
    [2011/03/13 16:36:29 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software
    [2011/03/13 16:34:04 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\Desktop\avast!+Internet+Security+6.0.1000+-+Final
    [2011/03/13 11:18:03 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\AppData\Local\{EAB8046D-5662-40EB-80EF-4B903FE407E8}
    [2011/03/12 21:03:10 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\Desktop\a la foire
    [2011/03/12 20:34:33 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\Desktop\Peugeot 308 RCZ
    [2011/03/12 11:24:50 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\AppData\Local\{E3827BE5-AE6F-425F-8B92-07E2C04760D4}
    [2011/03/11 22:30:11 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\AppData\Local\{6100EFA6-F4B9-4CB0-B2A3-503711673EC7}
    [2011/03/11 15:42:03 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\AppData\Roaming\WinRAR
    [2011/03/11 15:42:03 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
    [2011/03/11 15:42:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
    [2011/03/11 15:41:57 | 000,000,000 | ---D | C] -- C:\Program Files\WinRAR
    [2011/03/11 14:17:59 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\AppData\Local\WMTools Downloaded Files
    [2011/03/11 13:19:01 | 000,000,000 | ---D | C] -- C:\Program Files\Magical Jelly Bean
    [2011/03/11 13:19:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\KeyFinder
    [2011/03/11 13:18:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SIW
    [2011/03/11 12:59:06 | 000,000,000 | ---D | C] -- C:\Program Files\Movie Maker 2.6
    [2011/03/11 12:54:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
    [2011/03/11 11:51:02 | 000,000,000 | ---D | C] -- C:\Program Files\WOT
    [2011/03/11 10:00:05 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\AppData\Local\{CC828378-C1ED-447D-8AFD-65439449997A}
    [2011/03/10 13:46:56 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\AppData\Local\{E2881344-786A-4EA4-BF58-E371FC8D2B61}
    [2011/03/09 08:44:15 | 000,642,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\CPFilters.dll
    [2011/03/09 08:44:15 | 000,534,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\EncDec.dll
    [2011/03/09 08:44:14 | 000,850,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sbe.dll
    [2011/03/09 08:44:14 | 000,199,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mpg2splt.ax
    [2011/03/09 08:32:58 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\AppData\Local\{0052845C-12F4-41E9-81BC-E36B5AFFAE23}
    [2011/03/06 11:21:10 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\AppData\Local\{6316F92C-F87F-4158-B751-4969D31340D7}
    [2011/03/05 18:01:29 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\Desktop\fbml
    [2011/03/05 10:57:13 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\AppData\Local\{FFA278B1-0BB9-45E7-A2C6-DA54B636464C}
    [2011/03/04 21:25:10 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\AppData\Local\{BBFC780D-A032-4868-BB32-70DCC4E8576D}
    [2011/03/04 08:45:56 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\AppData\Local\{C5363477-5639-49A4-B967-D6B008F9AE06}
    [2011/03/03 23:36:39 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\Desktop\am1
    [2011/03/03 20:02:22 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\AppData\Local\{AAF85E9B-5C84-4F32-87CC-C8DAC0F6169C}
    [2011/02/25 18:09:45 | 000,028,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mdimon.dll
    [2011/02/25 18:08:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
    [2011/02/25 18:07:44 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\DESIGNER
    [2011/02/25 18:07:26 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft.NET
    [2011/02/25 13:52:55 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\AppData\Local\{680F6100-4C84-4636-9300-1FCBB26909BD}
    [2011/02/18 21:12:07 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\AppData\Roaming\Real
    [2011/02/18 17:30:15 | 000,000,000 | -H-D | C] -- C:\Windows\AxInstSV
    [2011/02/18 15:25:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Picasa 3
    [2011/02/18 15:24:41 | 000,000,000 | ---D | C] -- C:\Program Files\Google
    [2011/02/18 13:24:09 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\AppData\Roaming\Skype
    [2011/02/18 13:07:51 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\AppData\Local\{E4A4C0F8-B08F-46C6-8C4A-8C537B92508B}
    [2011/02/17 21:43:12 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\AppData\Local\{BF71FD3B-9499-4A1B-B937-B83B8D34E6F7}
    [2011/02/17 19:44:15 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\AppData\Local\{E730C43B-B4B1-4126-8D93-921F1748FD87}
    [2011/02/15 01:10:43 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\AppData\Local\{D1C98C22-A525-439E-AD2A-75D43FE3FD2E}
    [2011/02/14 13:02:00 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\AppData\Local\{A814B55B-3810-448F-BF3D-57F658C3982B}
    [2011/02/12 21:13:36 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\AppData\Local\{1FF3C6B9-90ED-4CCB-ABEE-37A678203AE5}
    [2011/02/12 00:32:21 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\Desktop\jeux
    [2011/02/11 23:29:34 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\EA Games
    [2011/02/11 23:20:24 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\AppData\Local\{E3197D5E-D469-4B0C-8882-C21732FC5A04}
    [2011/02/11 23:13:34 | 000,000,000 | ---D | C] -- C:\BigFishGamesCache

    [color=#E56717]========== Files - Modified Within 30 Days ==========[/color]

    [2011/03/13 22:33:03 | 000,001,054 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
    [2011/03/13 22:29:50 | 000,013,328 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
    [2011/03/13 22:29:50 | 000,013,328 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    [2011/03/13 22:03:02 | 000,001,080 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3927136478-1131520727-3849782078-1001UA.job
    [2011/03/13 21:36:45 | 000,001,050 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
    [2011/03/13 21:27:20 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
    [2011/03/13 21:27:16 | 753,836,032 | -HS- | M] () -- C:\hiberfil.sys
    [2011/03/13 21:15:57 | 000,001,801 | ---- | M] () -- C:\Users\am1.cr\Desktop\AD-R.lnk
    [2011/03/13 20:32:42 | 000,000,000 | ---- | M] () -- C:\Windows\System32\cd.dat
    [2011/03/13 20:11:04 | 335,085,774 | ---- | M] () -- C:\UsbFix_Upload_Me_AM1CR-PC.zip
    [2011/03/13 19:18:26 | 000,000,758 | ---- | M] () -- C:\Users\Public\Desktop\VLC media player.lnk
    [2011/03/13 18:45:54 | 000,000,690 | ---- | M] () -- C:\Users\Public\Desktop\MBRCheck.lnk
    [2011/03/13 18:45:54 | 000,000,685 | ---- | M] () -- C:\Users\Public\Desktop\ZHPDiag.lnk
    [2011/03/13 18:45:54 | 000,000,682 | ---- | M] () -- C:\Users\Public\Desktop\ZHPFix.lnk
    [2011/03/13 17:18:00 | 000,002,406 | ---- | M] () -- C:\Users\am1.cr\Desktop\Google Chrome.lnk
    [2011/03/13 17:03:01 | 000,001,028 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3927136478-1131520727-3849782078-1001Core.job
    [2011/03/13 16:38:21 | 000,001,998 | ---- | M] () -- C:\Users\Public\Desktop\avast! Internet Security.lnk
    [2011/03/13 16:37:25 | 000,002,577 | ---- | M] () -- C:\Windows\System32\config.nt
    [2011/03/13 11:15:24 | 000,357,480 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
    [2011/03/12 22:36:40 | 000,003,270 | ---- | M] () -- C:\Users\am1.cr\Desktop\flashcode.gif
    [2011/03/12 14:00:32 | 000,694,766 | ---- | M] () -- C:\Windows\System32\perfh00C.dat
    [2011/03/12 14:00:32 | 000,606,992 | ---- | M] () -- C:\Windows\System32\perfh009.dat
    [2011/03/12 14:00:32 | 000,127,478 | ---- | M] () -- C:\Windows\System32\perfc00C.dat
    [2011/03/12 14:00:32 | 000,103,370 | ---- | M] () -- C:\Windows\System32\perfc009.dat
    [2011/03/11 16:14:52 | 000,000,760 | ---- | M] () -- C:\Users\am1.cr\~anis logi 1.DDF
    [2011/03/11 13:57:31 | 000,064,492 | ---- | M] () -- C:\Users\am1.cr\Desktop\am1.jpg
    [2011/03/11 13:44:59 | 000,198,890 | ---- | M] () -- C:\Users\am1.cr\Desktop\LDSproobjects.jpg
    [2011/03/11 13:42:46 | 000,005,120 | ---- | M] () -- C:\Users\am1.cr\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2011/03/11 12:54:41 | 000,002,246 | ---- | M] () -- C:\Users\Public\Desktop\Google Earth.lnk
    [2011/02/25 18:09:49 | 000,000,382 | ---- | M] () -- C:\Windows\ODBC.INI
    [2011/02/25 14:50:12 | 000,001,248 | ---- | M] () -- C:\Users\Public\Desktop\Paint.NET.lnk
    [2011/02/23 16:04:21 | 000,040,648 | ---- | M] (AVAST Software) -- C:\Windows\avastSS.scr
    [2011/02/23 16:04:17 | 000,190,016 | ---- | M] (AVAST Software) -- C:\Windows\System32\aswBoot.exe
    [2011/02/23 15:57:38 | 000,101,976 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswFW.sys
    [2011/02/23 15:56:55 | 000,371,544 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswSnx.sys
    [2011/02/23 15:56:45 | 000,301,528 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswSP.sys
    [2011/02/23 15:56:41 | 000,192,728 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswNdis2.sys
    [2011/02/23 15:55:49 | 000,049,240 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswTdi.sys
    [2011/02/23 15:55:10 | 000,025,432 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswRdr.sys
    [2011/02/23 15:55:03 | 000,053,592 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswMonFlt.sys
    [2011/02/23 15:54:55 | 000,019,544 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswFsBlk.sys
    [2011/02/23 14:34:54 | 000,012,112 | ---- | M] (ALWIL Software) -- C:\Windows\System32\drivers\aswNdis.sys
    [2011/02/18 15:25:30 | 000,001,068 | ---- | M] () -- C:\Users\Public\Desktop\Picasa 3.lnk

    [color=#E56717]========== Files Created - No Company Name ==========[/color]

    [2011/03/13 21:15:57 | 000,001,801 | ---- | C] () -- C:\Users\am1.cr\Desktop\AD-R.lnk
    [2011/03/13 20:32:42 | 000,000,000 | ---- | C] () -- C:\Windows\System32\cd.dat
    [2011/03/13 20:10:05 | 335,085,774 | ---- | C] () -- C:\UsbFix_Upload_Me_AM1CR-PC.zip
    [2011/03/13 19:18:26 | 000,000,758 | ---- | C] () -- C:\Users\Public\Desktop\VLC media player.lnk
    [2011/03/13 18:45:54 | 000,000,690 | ---- | C] () -- C:\Users\Public\Desktop\MBRCheck.lnk
    [2011/03/13 18:45:54 | 000,000,685 | ---- | C] () -- C:\Users\Public\Desktop\ZHPDiag.lnk
    [2011/03/13 18:45:54 | 000,000,682 | ---- | C] () -- C:\Users\Public\Desktop\ZHPFix.lnk
    [2011/03/13 16:38:21 | 000,001,998 | ---- | C] () -- C:\Users\Public\Desktop\avast! Internet Security.lnk
    [2011/03/12 22:36:42 | 000,003,270 | ---- | C] () -- C:\Users\am1.cr\Desktop\flashcode.gif
    [2011/03/11 16:14:22 | 000,000,760 | ---- | C] () -- C:\Users\am1.cr\~anis logi 1.DDF
    [2011/03/11 16:04:19 | 000,001,320 | ---- | C] () -- C:\Users\am1.cr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\age of empie 2.bat
    [2011/03/11 15:47:17 | 000,001,320 | ---- | C] () -- C:\Users\am1.cr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\am1.bat
    [2011/03/11 13:57:29 | 000,064,492 | ---- | C] () -- C:\Users\am1.cr\Desktop\am1.jpg
    [2011/03/11 13:45:07 | 000,198,890 | ---- | C] () -- C:\Users\am1.cr\Desktop\LDSproobjects.jpg
    [2011/03/11 12:54:41 | 000,002,246 | ---- | C] () -- C:\Users\Public\Desktop\Google Earth.lnk
    [2011/03/11 12:28:25 | 000,001,054 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
    [2011/03/11 12:28:23 | 000,001,050 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
    [2011/03/09 20:18:20 | 000,005,120 | ---- | C] () -- C:\Users\am1.cr\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2011/03/06 13:14:41 | 000,070,746 | ---- | C] () -- C:\Users\am1.cr\Desktop\Img00025.jpg
    [2011/02/25 18:09:49 | 000,000,382 | ---- | C] () -- C:\Windows\ODBC.INI
    [2011/02/18 15:25:30 | 000,001,068 | ---- | C] () -- C:\Users\Public\Desktop\Picasa 3.lnk
    [2011/01/22 17:03:58 | 000,000,010 | ---- | C] () -- C:\Windows\popcinfo.dat
    [2010/12/20 15:13:23 | 000,012,288 | ---- | C] () -- C:\Windows\impborl.dll
    [2009/07/14 09:39:49 | 000,694,766 | ---- | C] () -- C:\Windows\System32\perfh00C.dat
    [2009/07/14 09:39:49 | 000,344,522 | ---- | C] () -- C:\Windows\System32\perfi00C.dat
    [2009/07/14 09:39:49 | 000,127,478 | ---- | C] () -- C:\Windows\System32\perfc00C.dat
    [2009/07/14 09:39:49 | 000,038,160 | ---- | C] () -- C:\Windows\System32\perfd00C.dat
    [2009/07/14 05:57:37 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
    [2009/07/14 05:33:53 | 000,357,480 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
    [2009/07/14 03:05:48 | 000,606,992 | ---- | C] () -- C:\Windows\System32\perfh009.dat
    [2009/07/14 03:05:48 | 000,291,294 | ---- | C] () -- C:\Windows\System32\perfi009.dat
    [2009/07/14 03:05:48 | 000,103,370 | ---- | C] () -- C:\Windows\System32\perfc009.dat
    [2009/07/14 03:05:48 | 000,031,548 | ---- | C] () -- C:\Windows\System32\perfd009.dat
    [2009/07/14 03:05:05 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
    [2009/07/14 03:04:11 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
    [2009/07/14 01:19:49 | 000,066,048 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe
    [2009/07/14 00:55:01 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
    [2009/07/14 00:51:43 | 000,073,728 | ---- | C] () -- C:\Windows\System32\BthpanContextHandler.dll
    [2009/07/14 00:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\System32\BWContextHandler.dll
    [2009/06/10 22:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
    [2009/04/14 07:43:32 | 000,154,144 | ---- | C] () -- C:\Windows\System32\RTLCPAPI.dll
    [2003/04/01 10:58:02 | 000,005,260 | ---- | C] () -- C:\Windows\System32\OUTLPERF.INI

    < End of report >
    0
    1. Contributeur sécurité
      ça c est run2
      c est le rapport de la correction qu il me fallait :-)
      0
    2. ils arrive
      0
  2. Contributeur sécurité
    ATTENTION !!! : Script personnalisé pour cette machine uniquement , ne pas reproduire !!

    si tu as XP => double clique
    si tu as Vista ou windows 7 => clic droit "executer en tant que...."

    sur OTL.exe pour le lancer.

    ▶ Copie/colle les lignes suivantes en gras et place les dans la zone "personnalisation" :


    :processes
    explorer.exe
    iexplore.exe
    firefox.exe
    msnmsgr.exe
    Teatimer.exe

    :Services
    AnchorFree

    :OTL
    O2 - BHO: (Hotspot Shield Class) - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files\Hotspot Shield\HssIE\HssIE.dll (AnchorFree Inc.)
    FF - prefs.js..browser.search.defaultengine: "Yahoo-Mp3Tube"
    FF - prefs.js..browser.search.defaultenginename: "Yahoo-Mp3Tube"
    FF - prefs.js..browser.search.order.1: "Yahoo-Mp3Tube"
    FF - prefs.js..browser.search.selectedEngine: "Yahoo-Mp3Tube"
    FF - prefs.js..browser.search.selectedEngineURL: "http://mp3tubetoolbar.com/{searchTerms}"
    FF - prefs.js..browser.startup.homepage: "http://mp3tubetoolbar.com/"
    FF - prefs.js..keyword.URL: "http://mp3tubetoolbar.com/?prt=undefined02ff&clid=&subid=&Keywords="

    :Files
    D:\PROGRAM FILES\MOZILLA FIREFOX 4.0 BETA 3\EXTENSIONS\{34EFA911-B536-4C08-BECE-CD5E55C875B0}
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Movie Maker 2.6.lnk
    C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe
    C:\Windows\System32\drivers\HssDrv.sys

    :commands
    [emptytemp]
    [start explorer]
    [reboot]



    ▶ Clique sur « Correction » et laisse l'outil travailler. L'ordinateur redémarre.

    ▶ Copie/colle la totalité du rapport dans ta prochaine réponse.

    Après redémarrage :

    ▶ Télécharge Malwarebytes' Anti-Malware et enregistre le sur ton bureau.

    ▶ ▶ Miroir 1 si inaccessible
    ▶ ▶ Miroir 2 si inaccessible

    ▶ ▶ /!\ Utilisateur de Vista et Windows 7 : Clique droit sur le logo de Malwarebytes' Anti-Malware, « exécuter en tant qu'Administrateur »

    ▶ Double clique sur le fichier téléchargé pour lancer le processus d'installation.
    ▶ Dans l'onglet "mise à jour", clique sur le bouton Recherche de mise à jour
    ▶ si le pare-feu demande l'autorisation de se connecter pour Malwarebytes, accepte
    ▶ Une fois la mise à jour terminée
    ▶ rends-toi dans l'onglet Recherche
    ▶ Sélectionne Exécuter un examen complet
    ▶ Clique sur Rechercher
    ▶ ▶ Le scan démarre.
    ▶ A la fin de l'analyse, un message s'affiche : L'examen s'est terminé normalement. Cliquez sur 'Afficher les résultats' pour afficher tous les objets trouvés.
    ▶ Clique sur Ok pour poursuivre.
    ▶ Si des malwares ont été détectés, cliques sur Afficher les résultats
    ▶ Sélectionne tout (ou laisse coché) et clique sur Supprimer la sélection . Malwarebytes va détruire les fichiers et clés de registre et en mettre une copie dans la quarantaine.
    ▶ Malwarebytes va ouvrir le bloc-notes et y copier le rapport d'analyse. Copie/colle le ici (ctrl+a pour tout sélectionner, ctrl+c pour copier, ctrl+v pour coller)

    ▶ ▶ Il se peut que MBAM ait besoin de redémarrer le pc pour finaliser la suppression, donc pas de panique, redémarre ton pc !!!
    ▶ Une fois le PC redémarré, rends toi dans l'onglet rapport/log
    ▶ Tu clique dessus pour l'afficher, une fois affiché
    ▶ Copie/colle le ici (ctrl+a pour tout sélectionner, ctrl+c pour copier, ctrl+v pour coller)

    Si tu as besoin d'aide regarde ce tutoriel :
    https://www.malekal.com/tutoriel-malwarebyte-anti-malware/

    Je reviens demain soir. @+ bonne nuit.
    0
    1. bon nuit je vais faire tout ca
      0
  3. \/\/\/\/\/\/\/\/\/\/voila \/\/\/\/\/\/\/\/\/\/\/
    OTL logfile created on: 13/03/2011 21:49:32 - Run 2
    OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\am1.cr\Desktop
    Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
    Internet Explorer (Version = 8.0.7600.16385)
    Locale: 0000040c | Country: France | Language: FRA | Date Format: dd/MM/yyyy

    959,00 Mb Total Physical Memory | 198,00 Mb Available Physical Memory | 21,00% Memory free
    2,00 Gb Paging File | 1,00 Gb Available in Paging File | 57,00% Paging File free
    Paging file location(s): c:\pagefile.sys 0 0f:\pagefile.sys 1000 1001 [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
    Drive C: | 15,04 Gb Total Space | 0,75 Gb Free Space | 5,01% Space Free | Partition Type: NTFS
    Drive D: | 10,16 Gb Total Space | 0,39 Gb Free Space | 3,89% Space Free | Partition Type: NTFS
    Drive E: | 7,19 Gb Total Space | 2,54 Gb Free Space | 35,33% Space Free | Partition Type: NTFS
    Drive F: | 8,13 Gb Total Space | 3,00 Gb Free Space | 36,95% Space Free | Partition Type: NTFS
    Drive G: | 12,05 Gb Total Space | 10,48 Gb Free Space | 86,96% Space Free | Partition Type: NTFS
    Drive H: | 21,96 Gb Total Space | 6,07 Gb Free Space | 27,66% Space Free | Partition Type: NTFS
    Drive J: | 4,24 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: UDF
    Drive L: | 3,73 Gb Total Space | 0,19 Gb Free Space | 5,11% Space Free | Partition Type: FAT32

    Computer Name: AM1CR-PC | User Name: am1.cr | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: Current user
    Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

    [color=#E56717]========== Processes (SafeList) ==========/color

    PRC - [2011/03/13 20:42:44 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Users\am1.cr\Desktop\OTL.exe
    PRC - [2011/02/23 16:04:20 | 003,451,496 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe
    PRC - [2011/01/07 23:48:12 | 000,108,080 | ---- | M] () -- C:\Program Files\Hotspot Shield\bin\openvpntray.exe
    PRC - [2010/10/03 12:02:08 | 000,176,128 | ---- | M] (FaceMoi) -- C:\Facemoi\facemoi.exe
    PRC - [2009/10/31 06:45:39 | 002,614,272 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
    PRC - [2009/07/14 02:14:42 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
    PRC - [2009/04/14 07:43:42 | 000,604,704 | ---- | M] (Realtek Semiconductor Corp.) -- C:\Windows\SOUNDMAN.EXE

    [color=#E56717]========== Modules (SafeList) ==========/color

    MOD - [2011/03/13 20:42:44 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Users\am1.cr\Desktop\OTL.exe
    MOD - [2011/02/23 16:04:17 | 000,197,208 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\snxhk.dll
    MOD - [2010/08/21 06:21:32 | 001,680,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll

    [color=#E56717]========== Win32 Services (SafeList) ==========/color

    SRV - [2011/02/23 16:04:19 | 000,042,184 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
    SRV - [2011/02/23 16:04:17 | 000,121,000 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\afwServ.exe -- (avast! Firewall)
    SRV - [2011/01/07 23:48:18 | 000,057,640 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\Hotspot Shield\bin\HssTrayService.exe -- (HssTrayService)
    SRV - [2011/01/07 23:46:06 | 000,271,408 | ---- | M] () [Auto | Running] -- C:\Program Files\Hotspot Shield\bin\openvpnas.exe -- (HotspotShieldService)
    SRV - [2011/01/05 19:30:36 | 000,352,304 | ---- | M] (AnchorFree Inc.) [Auto | Running] -- C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe -- (HssSrv)
    SRV - [2010/12/20 21:25:49 | 001,343,400 | ---- | M] (Microsoft Corporation) [Unknown | Stopped] -- C:\Windows\System32\Wat\WatAdminSvc.exe -- (WatAdminSvc)
    SRV - [2010/10/15 19:42:14 | 000,326,704 | ---- | M] () [Auto | Running] -- C:\Program Files\Hotspot Shield\bin\hsswd.exe -- (HssWd)
    SRV - [2009/07/14 02:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
    SRV - [2009/07/14 02:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc)
    SRV - [2009/07/14 02:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)

    [color=#E56717]========== Driver Services (SafeList) ==========/color

    DRV - [2011/02/23 15:57:38 | 000,101,976 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswFW.sys -- (aswFW)
    DRV - [2011/02/23 15:56:55 | 000,371,544 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\System32\drivers\aswSnx.sys -- (aswSnx)
    DRV - [2011/02/23 15:56:45 | 000,301,528 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswSP.sys -- (aswSP)
    DRV - [2011/02/23 15:56:41 | 000,192,728 | ---- | M] (AVAST Software) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\aswNdis2.sys -- (aswNdis2)
    DRV - [2011/02/23 15:55:49 | 000,049,240 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswTdi.sys -- (aswTdi)
    DRV - [2011/02/23 15:55:10 | 000,025,432 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswRdr.sys -- (aswRdr)
    DRV - [2011/02/23 15:55:03 | 000,053,592 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\System32\drivers\aswMonFlt.sys -- (aswMonFlt)
    DRV - [2011/02/23 15:54:55 | 000,019,544 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\System32\drivers\aswFsBlk.sys -- (aswFsBlk)
    DRV - [2011/02/23 14:34:54 | 000,012,112 | ---- | M] (ALWIL Software) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\aswNdis.sys -- (aswNdis)
    DRV - [2010/09/22 20:19:02 | 000,037,376 | ---- | M] (AnchorFree Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\HssDrv.sys -- (HssDrv)
    DRV - [2010/09/22 20:19:02 | 000,032,768 | ---- | M] (AnchorFree Inc) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\taphss.sys -- (taphss)
    DRV - [2009/07/14 02:19:10 | 000,175,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\vmbus.sys -- (vmbus)
    DRV - [2009/07/14 02:19:10 | 000,040,896 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\vmstorfl.sys -- (storflt)
    DRV - [2009/07/14 02:19:10 | 000,028,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\storvsc.sys -- (storvsc)
    DRV - [2009/07/14 00:28:47 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\vms3cap.sys -- (s3cap)
    DRV - [2009/07/14 00:28:45 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\VMBusHID.sys -- (VMBusHID)
    DRV - [2009/07/13 23:02:53 | 000,044,032 | ---- | M] (VIA Technologies, Inc. ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\fetnd6.sys -- (FETNDIS)
    DRV - [2009/07/13 23:02:52 | 000,043,008 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Rtnicxp.sys -- (RTL8023xp)
    DRV - [2009/06/18 19:45:02 | 004,172,832 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\RTKVAC.SYS -- (ALCXWDM) Service for Realtek AC97 Audio (WDM)

    [color=#E56717]========== Standard Registry (SafeList) ==========/color

    [color=#E56717]========== Internet Explorer ==========/color

    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr

    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = https://www.msn.com/fr-fr?ocid=iehp
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = fr
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = E4 93 40 95 86 9F CB 01 [binary data]
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

    [color=#E56717]========== FireFox ==========/color

    FF - prefs.js..browser.search.defaultengine: "Yahoo-Mp3Tube"
    FF - prefs.js..browser.search.defaultenginename: "Yahoo-Mp3Tube"
    FF - prefs.js..browser.search.order.1: "Yahoo-Mp3Tube"
    FF - prefs.js..browser.search.selectedEngine: "Yahoo-Mp3Tube"
    FF - prefs.js..browser.search.selectedEngineURL: "http://mp3tubetoolbar.com/...{searchTerms}"
    FF - prefs.js..browser.startup.homepage: "http://mp3tubetoolbar.com/..."
    FF - prefs.js..keyword.URL: "http://mp3tubetoolbar.com/?prt=undefined02ff&clid=&subid=&Keywords="

    FF - HKLM\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF [2011/03/13 16:36:43 | 000,000,000 | ---D | M]

    [2011/01/07 11:43:13 | 000,000,000 | ---D | M] (No name found) -- C:\Users\am1.cr\AppData\Roaming\Mozilla\Extensions
    [2011/02/05 14:18:04 | 000,000,000 | ---D | M] (No name found) -- C:\Users\am1.cr\AppData\Roaming\Mozilla\Firefox\Profiles\0znx53qi.default\extensions
    [2011/02/05 14:15:37 | 000,000,000 | ---D | M] (Billeo) -- C:\Users\am1.cr\AppData\Roaming\Mozilla\Firefox\Profiles\0znx53qi.default\extensions\{4be68a18-deba-49e0-9e09-ee7796f3b62a}
    [2011/02/05 14:13:29 | 000,000,000 | ---D | M] (Temp Installer) -- C:\Users\am1.cr\AppData\Roaming\Mozilla\Firefox\Profiles\0znx53qi.default\extensions\{77868449-f49d-d6ec-3145-e651161b1ff8}
    [2011/02/05 14:18:05 | 000,000,000 | ---D | M] (KwiClick) -- C:\Users\am1.cr\AppData\Roaming\Mozilla\Firefox\Profiles\0znx53qi.default\extensions\vinceturk@gmail.com
    File not found (No name found) --
    [2011/03/13 16:36:43 | 000,000,000 | ---D | M] (avast! WebRep) -- C:\PROGRAM FILES\AVAST SOFTWARE\AVAST\WEBREP\FF
    [2010/12/13 13:01:43 | 000,000,000 | ---D | M] (ResultBar) -- D:\PROGRAM FILES\MOZILLA FIREFOX 4.0 BETA 3\EXTENSIONS\{34EFA911-B536-4C08-BECE-CD5E55C875B0}
    [2010/12/12 22:52:45 | 000,000,000 | ---D | M] (Skype extension) -- D:\PROGRAM FILES\MOZILLA FIREFOX 4.0 BETA 3\EXTENSIONS\{AB2CE124-6272-4B12-94A9-7303C7397BD1}
    [2010/12/13 13:16:38 | 000,000,000 | ---D | M] (MP3Tube Toolbar) -- D:\PROGRAM FILES\MOZILLA FIREFOX 4.0 BETA 3\EXTENSIONS\MP3TUBETOOLBAR@MP3TUBETOOLBAR.COM
    [2011/01/08 18:29:12 | 000,000,000 | ---D | M] (Feedback) -- D:\PROGRAM FILES\MOZILLA FIREFOX 4.0 BETA 3\EXTENSIONS\TESTPILOT@LABS.MOZILLA.COM

    O1 HOSTS File: ([2009/06/10 22:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
    O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll ()
    O2 - BHO: (WOT Helper) - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files\WOT\WOT.dll ()
    O2 - BHO: (Hotspot Shield Class) - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files\Hotspot Shield\HssIE\HssIE.dll (AnchorFree Inc.)
    O3 - HKLM\..\Toolbar: (WOT) - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
    O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll ()
    O3 - HKCU\..\Toolbar\WebBrowser: (WOT) - {71576546-354D-41C9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
    O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
    O4 - HKLM..\Run: [Facemoi] c:\Facemoi\facemoi.exe (FaceMoi)
    O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
    O4 - HKLM..\Run: [SoundMan] C:\Windows\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
    O4 - HKCU..\Run: [Facemoi] C:\Facemoi\facemoi.exe (FaceMoi)
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 3
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 0
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 3
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 0
    O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr (Google Inc.)
    O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
    O13 - gopher Prefix: missing
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
    O18 - Protocol\Handler\wot {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll ()
    O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
    O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
    O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
    O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
    O32 - HKLM CDRom: AutoRun - 1
    O32 - AutoRun File - [2009/06/10 22:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
    O32 - AutoRun File - [2011/03/13 20:09:14 | 000,000,000 | RHSD | M] - C:\Autorun.inf -- [ NTFS ]
    O32 - AutoRun File - [2009/06/10 22:42:20 | 000,000,024 | ---- | M] () - D:\autoexec.bat -- [ NTFS ]
    O32 - AutoRun File - [2011/03/13 20:09:14 | 000,000,000 | RHSD | M] - D:\Autorun.inf -- [ NTFS ]
    O32 - AutoRun File - [2011/03/13 20:09:14 | 000,000,000 | RHSD | M] - E:\Autorun.inf -- [ NTFS ]
    O32 - AutoRun File - [2011/03/13 20:09:14 | 000,000,000 | RHSD | M] - F:\Autorun.inf -- [ NTFS ]
    O32 - AutoRun File - [2011/03/13 20:09:14 | 000,000,000 | RHSD | M] - G:\Autorun.inf -- [ NTFS ]
    O32 - AutoRun File - [2011/03/13 20:09:14 | 000,000,000 | RHSD | M] - H:\Autorun.inf -- [ NTFS ]
    O32 - AutoRun File - [2011/03/13 20:09:16 | 000,000,000 | RHSD | M] - L:\Autorun.inf -- [ FAT32 ]
    O34 - HKLM BootExecute: (autocheck autochk *) - File not found
    O35 - HKLM\..comfile [open] -- "%1" %*
    O35 - HKLM\..exefile [open] -- "%1" %*
    O37 - HKLM\...com [@ = comfile] -- "%1" %*
    O37 - HKLM\...exe [@ = exefile] -- "%1" %*

    [color=#E56717]========== Files/Folders - Created Within 30 Days ==========/color

    [2011/03/13 21:15:56 | 000,000,000 | ---D | C] -- C:\Program Files\Ad-Remover
    [2011/03/13 20:41:27 | 000,580,608 | ---- | C] (OldTimer Tools) -- C:\Users\am1.cr\Desktop\OTL.exe
    [2011/03/13 20:09:14 | 000,000,000 | RHSD | C] -- C:\Autorun.inf
    [2011/03/13 19:05:47 | 000,000,000 | ---D | C] -- C:\UsbFix
    [2011/03/13 18:45:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ZHP
    [2011/03/13 16:38:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\avast! Internet Security
    [2011/03/13 16:38:20 | 000,301,528 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswSP.sys
    [2011/03/13 16:38:20 | 000,019,544 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswFsBlk.sys
    [2011/03/13 16:37:58 | 000,101,976 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswFW.sys
    [2011/03/13 16:37:28 | 000,192,728 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswNdis2.sys
    [2011/03/13 16:37:28 | 000,025,432 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswRdr.sys
    [2011/03/13 16:37:27 | 000,371,544 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswSnx.sys
    [2011/03/13 16:37:27 | 000,049,240 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswTdi.sys
    [2011/03/13 16:37:25 | 000,053,592 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswMonFlt.sys
    [2011/03/13 16:36:39 | 000,012,112 | ---- | C] (ALWIL Software) -- C:\Windows\System32\drivers\aswNdis.sys
    [2011/03/13 16:36:37 | 000,040,648 | ---- | C] (AVAST Software) -- C:\Windows\avastSS.scr
    [2011/03/13 16:36:36 | 000,190,016 | ---- | C] (AVAST Software) -- C:\Windows\System32\aswBoot.exe
    [2011/03/13 16:36:29 | 000,000,000 | ---D | C] -- C:\ProgramData\AVAST Software
    [2011/03/13 16:36:29 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software
    [2011/03/13 16:34:04 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\Desktop\avast!+Internet+Security+6.0.1000+-+Final
    [2011/03/13 11:18:03 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\AppData\Local\{EAB8046D-5662-40EB-80EF-4B903FE407E8}
    [2011/03/12 21:03:10 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\Desktop\a la foire
    [2011/03/12 20:34:33 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\Desktop\Peugeot 308 RCZ
    [2011/03/12 11:24:50 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\AppData\Local\{E3827BE5-AE6F-425F-8B92-07E2C04760D4}
    [2011/03/11 22:30:11 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\AppData\Local\{6100EFA6-F4B9-4CB0-B2A3-503711673EC7}
    [2011/03/11 15:42:03 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\AppData\Roaming\WinRAR
    [2011/03/11 15:42:03 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
    [2011/03/11 15:42:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
    [2011/03/11 15:41:57 | 000,000,000 | ---D | C] -- C:\Program Files\WinRAR
    [2011/03/11 14:17:59 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\AppData\Local\WMTools Downloaded Files
    [2011/03/11 13:19:01 | 000,000,000 | ---D | C] -- C:\Program Files\Magical Jelly Bean
    [2011/03/11 13:19:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\KeyFinder
    [2011/03/11 13:18:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SIW
    [2011/03/11 12:59:06 | 000,000,000 | ---D | C] -- C:\Program Files\Movie Maker 2.6
    [2011/03/11 12:54:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
    [2011/03/11 11:51:02 | 000,000,000 | ---D | C] -- C:\Program Files\WOT
    [2011/03/11 10:00:05 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\AppData\Local\{CC828378-C1ED-447D-8AFD-65439449997A}
    [2011/03/10 13:46:56 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\AppData\Local\{E2881344-786A-4EA4-BF58-E371FC8D2B61}
    [2011/03/09 08:44:15 | 000,642,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\CPFilters.dll
    [2011/03/09 08:44:15 | 000,534,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\EncDec.dll
    [2011/03/09 08:44:14 | 000,850,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sbe.dll
    [2011/03/09 08:44:14 | 000,199,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mpg2splt.ax
    [2011/03/09 08:32:58 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\AppData\Local\{0052845C-12F4-41E9-81BC-E36B5AFFAE23}
    [2011/03/06 11:21:10 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\AppData\Local\{6316F92C-F87F-4158-B751-4969D31340D7}
    [2011/03/05 18:01:29 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\Desktop\fbml
    [2011/03/05 10:57:13 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\AppData\Local\{FFA278B1-0BB9-45E7-A2C6-DA54B636464C}
    [2011/03/04 21:25:10 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\AppData\Local\{BBFC780D-A032-4868-BB32-70DCC4E8576D}
    [2011/03/04 08:45:56 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\AppData\Local\{C5363477-5639-49A4-B967-D6B008F9AE06}
    [2011/03/03 23:36:39 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\Desktop\am1
    [2011/03/03 20:02:22 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\AppData\Local\{AAF85E9B-5C84-4F32-87CC-C8DAC0F6169C}
    [2011/02/25 18:09:45 | 000,028,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mdimon.dll
    [2011/02/25 18:08:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
    [2011/02/25 18:07:44 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\DESIGNER
    [2011/02/25 18:07:26 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft.NET
    [2011/02/25 13:52:55 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\AppData\Local\{680F6100-4C84-4636-9300-1FCBB26909BD}
    [2011/02/18 21:12:07 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\AppData\Roaming\Real
    [2011/02/18 17:30:15 | 000,000,000 | -H-D | C] -- C:\Windows\AxInstSV
    [2011/02/18 15:25:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Picasa 3
    [2011/02/18 15:24:41 | 000,000,000 | ---D | C] -- C:\Program Files\Google
    [2011/02/18 13:24:09 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\AppData\Roaming\Skype
    [2011/02/18 13:07:51 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\AppData\Local\{E4A4C0F8-B08F-46C6-8C4A-8C537B92508B}
    [2011/02/17 21:43:12 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\AppData\Local\{BF71FD3B-9499-4A1B-B937-B83B8D34E6F7}
    [2011/02/17 19:44:15 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\AppData\Local\{E730C43B-B4B1-4126-8D93-921F1748FD87}
    [2011/02/15 01:10:43 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\AppData\Local\{D1C98C22-A525-439E-AD2A-75D43FE3FD2E}
    [2011/02/14 13:02:00 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\AppData\Local\{A814B55B-3810-448F-BF3D-57F658C3982B}
    [2011/02/12 21:13:36 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\AppData\Local\{1FF3C6B9-90ED-4CCB-ABEE-37A678203AE5}
    [2011/02/12 00:32:21 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\Desktop\jeux
    [2011/02/11 23:29:34 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\EA Games
    [2011/02/11 23:20:24 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\AppData\Local\{E3197D5E-D469-4B0C-8882-C21732FC5A04}
    [2011/02/11 23:13:34 | 000,000,000 | ---D | C] -- C:\BigFishGamesCache
    [2011/02/11 22:53:56 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\Documents\EA Games
    [2011/02/11 22:44:05 | 000,442,368 | R--- | C] (On2.com) -- C:\Windows\System32\vp6vfw.dll
    [2011/02/11 22:41:18 | 000,000,000 | ---D | C] -- C:\NVIDIA
    [2011/02/11 22:40:27 | 000,000,000 | ---D | C] -- C:\ATI
    [2011/02/11 22:38:48 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\AppData\Local\{5A91C618-A81D-414F-A1B9-99AE9B9D2254}
    [2011/02/11 22:02:40 | 000,000,000 | ---D | C] -- C:\Users\am1.cr\AppData\Local\{4447881A-8E37-4C15-AE01-BB0A1EC048C8}
    [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
    [1 C:\*.tmp files -> C:\*.tmp -> ]

    [color=#E56717]========== Files - Modified Within 30 Days ==========/color

    [2011/03/13 21:36:45 | 000,001,050 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
    [2011/03/13 21:33:03 | 000,001,054 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
    [2011/03/13 21:27:20 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
    [2011/03/13 21:27:16 | 753,836,032 | -HS- | M] () -- C:\hiberfil.sys
    [2011/03/13 21:26:04 | 000,013,328 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
    [2011/03/13 21:26:04 | 000,013,328 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    [2011/03/13 21:15:57 | 000,001,801 | ---- | M] () -- C:\Users\am1.cr\Desktop\AD-R.lnk
    [2011/03/13 21:03:03 | 000,001,080 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3927136478-1131520727-3849782078-1001UA.job
    [2011/03/13 20:42:44 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Users\am1.cr\Desktop\OTL.exe
    [2011/03/13 20:32:42 | 000,000,000 | ---- | M] () -- C:\Windows\System32\cd.dat
    [2011/03/13 20:11:04 | 335,085,774 | ---- | M] () -- C:\UsbFix_Upload_Me_AM1CR-PC.zip
    [2011/03/13 19:18:26 | 000,000,758 | ---- | M] () -- C:\Users\Public\Desktop\VLC media player.lnk
    [2011/03/13 18:45:54 | 000,000,690 | ---- | M] () -- C:\Users\Public\Desktop\MBRCheck.lnk
    [2011/03/13 18:45:54 | 000,000,685 | ---- | M] () -- C:\Users\Public\Desktop\ZHPDiag.lnk
    [2011/03/13 18:45:54 | 000,000,682 | ---- | M] () -- C:\Users\Public\Desktop\ZHPFix.lnk
    [2011/03/13 17:18:00 | 000,002,406 | ---- | M] () -- C:\Users\am1.cr\Desktop\Google Chrome.lnk
    [2011/03/13 17:03:01 | 000,001,028 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3927136478-1131520727-3849782078-1001Core.job
    [2011/03/13 16:38:21 | 000,001,998 | ---- | M] () -- C:\Users\Public\Desktop\avast! Internet Security.lnk
    [2011/03/13 16:37:25 | 000,002,577 | ---- | M] () -- C:\Windows\System32\config.nt
    [2011/03/13 11:15:24 | 000,357,480 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
    [2011/03/12 22:36:40 | 000,003,270 | ---- | M] () -- C:\Users\am1.cr\Desktop\flashcode.gif
    [2011/03/12 14:00:32 | 000,694,766 | ---- | M] () -- C:\Windows\System32\perfh00C.dat
    [2011/03/12 14:00:32 | 000,606,992 | ---- | M] () -- C:\Windows\System32\perfh009.dat
    [2011/03/12 14:00:32 | 000,127,478 | ---- | M] () -- C:\Windows\System32\perfc00C.dat
    [2011/03/12 14:00:32 | 000,103,370 | ---- | M] () -- C:\Windows\System32\perfc009.dat
    [2011/03/11 16:14:52 | 000,000,760 | ---- | M] () -- C:\Users\am1.cr\~anis logi 1.DDF
    [2011/03/11 13:57:31 | 000,064,492 | ---- | M] () -- C:\Users\am1.cr\Desktop\am1.jpg
    [2011/03/11 13:44:59 | 000,198,890 | ---- | M] () -- C:\Users\am1.cr\Desktop\LDSproobjects.jpg
    [2011/03/11 13:42:46 | 000,005,120 | ---- | M] () -- C:\Users\am1.cr\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2011/03/11 12:54:41 | 000,002,246 | ---- | M] () -- C:\Users\Public\Desktop\Google Earth.lnk
    [2011/02/25 18:09:49 | 000,000,382 | ---- | M] () -- C:\Windows\ODBC.INI
    [2011/02/25 14:50:12 | 000,001,248 | ---- | M] () -- C:\Users\Public\Desktop\Paint.NET.lnk
    [2011/02/23 16:04:21 | 000,040,648 | ---- | M] (AVAST Software) -- C:\Windows\avastSS.scr
    [2011/02/23 16:04:17 | 000,190,016 | ---- | M] (AVAST Software) -- C:\Windows\System32\aswBoot.exe
    [2011/02/23 15:57:38 | 000,101,976 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswFW.sys
    [2011/02/23 15:56:55 | 000,371,544 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswSnx.sys
    [2011/02/23 15:56:45 | 000,301,528 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswSP.sys
    [2011/02/23 15:56:41 | 000,192,728 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswNdis2.sys
    [2011/02/23 15:55:49 | 000,049,240 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswTdi.sys
    [2011/02/23 15:55:10 | 000,025,432 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswRdr.sys
    [2011/02/23 15:55:03 | 000,053,592 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswMonFlt.sys
    [2011/02/23 15:54:55 | 000,019,544 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswFsBlk.sys
    [2011/02/23 14:34:54 | 000,012,112 | ---- | M] (ALWIL Software) -- C:\Windows\System32\drivers\aswNdis.sys
    [2011/02/18 15:25:30 | 000,001,068 | ---- | M] () -- C:\Users\Public\Desktop\Picasa 3.lnk
    [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
    [1 C:\*.tmp files -> C:\*.tmp -> ]

    [color=#E56717]========== Files Created - No Company Name ==========/color

    [2011/03/13 21:15:57 | 000,001,801 | ---- | C] () -- C:\Users\am1.cr\Desktop\AD-R.lnk
    [2011/03/13 20:32:42 | 000,000,000 | ---- | C] () -- C:\Windows\System32\cd.dat
    [2011/03/13 20:10:05 | 335,085,774 | ---- | C] () -- C:\UsbFix_Upload_Me_AM1CR-PC.zip
    [2011/03/13 19:18:26 | 000,000,758 | ---- | C] () -- C:\Users\Public\Desktop\VLC media player.lnk
    [2011/03/13 18:45:54 | 000,000,690 | ---- | C] () -- C:\Users\Public\Desktop\MBRCheck.lnk
    [2011/03/13 18:45:54 | 000,000,685 | ---- | C] () -- C:\Users\Public\Desktop\ZHPDiag.lnk
    [2011/03/13 18:45:54 | 000,000,682 | ---- | C] () -- C:\Users\Public\Desktop\ZHPFix.lnk
    [2011/03/13 16:38:21 | 000,001,998 | ---- | C] () -- C:\Users\Public\Desktop\avast! Internet Security.lnk
    [2011/03/12 22:36:42 | 000,003,270 | ---- | C] () -- C:\Users\am1.cr\Desktop\flashcode.gif
    [2011/03/11 16:14:22 | 000,000,760 | ---- | C] () -- C:\Users\am1.cr\~anis logi 1.DDF
    [2011/03/11 16:04:19 | 000,001,320 | ---- | C] () -- C:\Users\am1.cr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\age of empie 2.bat
    [2011/03/11 15:47:17 | 000,001,320 | ---- | C] () -- C:\Users\am1.cr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\am1.bat
    [2011/03/11 13:57:29 | 000,064,492 | ---- | C] () -- C:\Users\am1.cr\Desktop\am1.jpg
    [2011/03/11 13:45:07 | 000,198,890 | ---- | C] () -- C:\Users\am1.cr\Desktop\LDSproobjects.jpg
    [2011/03/11 12:59:06 | 000,002,495 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Movie Maker 2.6.lnk
    [2011/03/11 12:54:41 | 000,002,246 | ---- | C] () -- C:\Users\Public\Desktop\Google Earth.lnk
    [2011/03/11 12:28:25 | 000,001,054 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
    [2011/03/11 12:28:23 | 000,001,050 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
    [2011/03/09 20:18:20 | 000,005,120 | ---- | C] () -- C:\Users\am1.cr\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2011/03/06 13:14:41 | 000,070,746 | ---- | C] () -- C:\Users\am1.cr\Desktop\Img00025.jpg
    [2011/02/25 18:09:49 | 000,000,382 | ---- | C] () -- C:\Windows\ODBC.INI
    [2011/02/18 15:25:30 | 000,001,068 | ---- | C] () -- C:\Users\Public\Desktop\Picasa 3.lnk
    [2011/01/22 17:03:58 | 000,000,010 | ---- | C] () -- C:\Windows\popcinfo.dat
    [2010/12/20 15:13:23 | 000,012,288 | ---- | C] () -- C:\Windows\impborl.dll
    [2009/07/14 09:39:49 | 000,694,766 | ---- | C] () -- C:\Windows\System32\perfh00C.dat
    [2009/07/14 09:39:49 | 000,344,522 | ---- | C] () -- C:\Windows\System32\perfi00C.dat
    [2009/07/14 09:39:49 | 000,127,478 | ---- | C] () -- C:\Windows\System32\perfc00C.dat
    [2009/07/14 09:39:49 | 000,038,160 | ---- | C] () -- C:\Windows\System32\perfd00C.dat
    [2009/07/14 05:57:37 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
    [2009/07/14 05:33:53 | 000,357,480 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
    [2009/07/14 03:05:48 | 000,606,992 | ---- | C] () -- C:\Windows\System32\perfh009.dat
    [2009/07/14 03:05:48 | 000,291,294 | ---- | C] () -- C:\Windows\System32\perfi009.dat
    [2009/07/14 03:05:48 | 000,103,370 | ---- | C] () -- C:\Windows\System32\perfc009.dat
    [2009/07/14 03:05:48 | 000,031,548 | ---- | C] () -- C:\Windows\System32\perfd009.dat
    [2009/07/14 03:05:05 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
    [2009/07/14 03:04:11 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
    [2009/07/14 01:19:49 | 000,066,048 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe
    [2009/07/14 00:55:01 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
    [2009/07/14 00:51:43 | 000,073,728 | ---- | C] () -- C:\Windows\System32\BthpanContextHandler.dll
    [2009/07/14 00:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\System32\BWContextHandler.dll
    [2009/06/10 22:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
    [2009/04/14 07:43:32 | 000,154,144 | ---- | C] () -- C:\Windows\System32\RTLCPAPI.dll
    [2003/04/01 10:58:02 | 000,005,260 | ---- | C] () -- C:\Windows\System32\OUTLPERF.INI

    < End of report >
    0
    1. Contributeur sécurité
      c est ad-remover ça. J'ai demandé un nouveau OTL.

      ça:

      ▶ Tu peux suivre les indications de cette page pour t'aider : https://www.malekal.com/tutorial-otl/

      ▶ Télécharge http://www.geekstogo.com/forum/files/file/398-otl-oldtimers-list-it/ sur ton bureau.
      (Sous Vista/Win7, il faut cliquer droit sur OTL et choisir Exécuter en tant qu'administrateur)

      ▶ Lance OTL
      ▶ Sous Peronnalisation, copie-colle ce qu'il y a dans le cadre ci-dessous :
      netsvcs
      msconfig
      safebootminimal
      safebootnetwork
      activex
      drivers32
      %ALLUSERSPROFILE%\Application Data\*.
      %ALLUSERSPROFILE%\Application Data\*.exe /s
      %APPDATA%\*.
      %APPDATA%\*.exe /s
      %temp%\.exe /s
      %SYSTEMDRIVE%\*.exe
      %systemroot%\*. /mp /s
      %systemroot%\system32\*.dll /lockedfiles
      %systemroot%\Tasks\*.job /lockedfiles
      %systemroot%\system32\drivers\*.sys /lockedfiles
      %systemroot%\System32\config\*.sav
      /md5start
      explorer.exe
      winlogon.exe
      wininit.exe
      /md5stop
      CREATERESTOREPOINT
      nslookup www.google.fr /c 

      ▶ Clique sur le bouton Analyse.
      ▶ Quand le scan est fini, utilise le site http://pjjoint.malekal.com/ pour envoyer les rapports.
      Donnes le liens pjjoint ici ensuite pour pouvoir être consultés.
      0
      1. oki je le refait
        0
    2. Contributeur sécurité
      Bien.
      Refais OTL comme tu as déjà fait, avec les options demandées.
      On va finaliser ;)
      0
      1. Contributeur sécurité
        Désinstalle tout ce qui contient le mot toolbar, ça sert à rien et ça ralenti ta navigation. Voir : https://forum.malekal.com/viewtopic.php?t=6173&start=

        Tu es infecté de resultbar. Faut toujours lire ce qu'on te propose en plus comme logiciels et décocher ce qui est inutile. Ces logiciels récoltent des informations sur ta navigation.

        ▶ Télécharge de AD-Remover sur ton Bureau. (Merci à C_XX)

        http://www.teamxscript.org/adremoverTelechargement.html ( Lien officiel )
        OU
        https://www.androidworld.fr/ ( Miroir )

        /!\ Ferme toutes applications en cours /!\

        ▶ Double-clique sur l'icône Ad-remover située sur ton Bureau.
        ▶ Sur la page, clique sur le bouton « Nettoyer »
        ▶ Confirme lancement du scan
        ▶ Laisse travailler l'outil.
        ▶ Poste le rapport qui apparaît à la fin.

        (Le rapport est sauvegardé aussi sous C:\Ad-report(Scan/clean).Txt)

        (CTRL+A pour tout sélectionner, CTRL+C pour copier et CTRL+V pour coller)

        ++
        0
        1. meme la page IE9
          0
        2. Contributeur sécurité
          Gné ?
          0
      2. Contributeur sécurité
        C est un bug de l'outil...

        On va utiliser un outre outil de diagnostic

        ▶ Tu peux suivre les indications de cette page pour t'aider : https://www.malekal.com/tutorial-otl/

        ▶ Télécharge http://www.geekstogo.com/forum/files/file/398-otl-oldtimers-list-it/ sur ton bureau.
        (Sous Vista/Win7, il faut cliquer droit sur OTL et choisir Exécuter en tant qu'administrateur)

        ▶ Lance OTL
        ▶ Sous Peronnalisation, copie-colle ce qu'il y a dans le cadre ci-dessous :
        netsvcs
        msconfig
        safebootminimal
        safebootnetwork
        activex
        drivers32
        %ALLUSERSPROFILE%\Application Data\*.
        %ALLUSERSPROFILE%\Application Data\*.exe /s
        %APPDATA%\*.
        %APPDATA%\*.exe /s
        %temp%\.exe /s
        %SYSTEMDRIVE%\*.exe
        %systemroot%\*. /mp /s
        %systemroot%\system32\*.dll /lockedfiles
        %systemroot%\Tasks\*.job /lockedfiles
        %systemroot%\system32\drivers\*.sys /lockedfiles
        %systemroot%\System32\config\*.sav
        /md5start
        explorer.exe
        winlogon.exe
        wininit.exe
        /md5stop
        CREATERESTOREPOINT
        nslookup www.google.fr /c 

        ▶ Clique sur le bouton Analyse.
        ▶ Quand le scan est fini, utilise le site http://pjjoint.malekal.com/ pour envoyer les rapports.
        Donnes le liens pjjoint ici ensuite pour pouvoir être consultés.

        @+
        0
        1. pondant que je fusais le test a 62% tout l'écran et devenu bleu avec une écriture blanche tout les bouton ne marcher pas j'ais été forcer de le redémarre !!!! pour quoi ils a fait ça ??
          0
          1. Contributeur sécurité
            re,

            Présent! L:\ufyy.pif
            Présent! L:\KUGLICA

            tu n'as pas lancé la suppression mais la recherche

            relance usbfix et clique cette fois sur suppression !

            Ensuite passe à ZHPDiag, si tu le souhaite remet un mot de passe mais le même ;-)
            0
            1. Contributeur sécurité
              salut

              AM1 G , on n'est pas la pour te juger , mais pour te désinfecter. ce que tu fais avec ton pc n'intéresse que toi -)

              pour avancer juju

              ● Rends toi sur pjjoint.malekal.com

              ==> il inclut un mot de passe que tu enverras à juju par message privé

              ● Cliques sur " Parcourir "

              ● Sélectionnes le rapport ZHPdiag.txt qui se trouve sur ton bureau

              ● Clique ensuite sur "envoyer le fichier " et copie/colle le lien dans ton prochain message

              Chaque difficulté rencontrée doit être l'occasion d'un nouveau progrès.

              [Pierre de Coubertin]
              0
              1. m'est dans ce rapport ils ya tout sur moi mes logiciel mes favoris les nom de fichier priver je pue pas tu donner ses info

                --
                ?? j'ais essaye d'arreter j'ais pas pue désole ! ??
                0
                1. oki je vais le refaire une autre fois avec ZHPDiag
                  0
                  1. Contributeur sécurité
                    T'as ouvert ZHPFix et non ZHPDiag

                    Si tu ne lis pas ce que je te dis, t'en sortiras jamais.

                    J'attends toujours le rapport de USBFix
                    0
                    • 1
                    • 2