Diagnostic sur portable packard bell

Résolu/Fermé
Bonjour,
je voulais avoir l'avis d'un expert sur ce PC portable
http://www.cijoint.fr/cjlink.php?file=cj201109/cijbkKfjKn.txt
merci beaucoup
bonne soirée
Cloud9

22 réponses

  1. Contributeur sécurité
    Re,

    Attends pars pas^^ On finalise avant^^

    Si nous avons utilisé Malwarebytes' Anti-Malware, tu peux le garder et passer un scan complet une fois par semaine en prenant soin de bien le mettre à jour avant de lancer le scan.
    Autrement, installes-le, c'est un antimalware très efficace. Tu trouveras un tuto complet Ici

    1- Nous allons mettre à jour ton pc.

    Il est important d'avoir les dernières mises à jour sur ton PC. En effet, celles-ci corrigent des failles de sécurité qui peuvent parfois être exploitée par un programme malveillant.

    1ère étape : Java

    ▶ Télécharge >>>JavaRa<<< puis décompresse le sur ton bureau.
    ▶ Ouvre le dossier JavaRa puis exécute JavaRa.exe.
    ▶ Clique sur "Search For Updates".
    ▶ Sélectionne "Update Using jucheck.exe" puis clique sur "Search".
    ▶ Autorise le processus à se connecter s'il te le demande, clique sur "install" et suis la procédure d'installation.
    ▶ Une fois l'installation terminée, revient à l'écran de JavaRa et clique sur "Remove Older Versions".
    ▶ Clique sur " Oui " pour confirmer. Laisse l'outil travailler, puis clique sur " Ok " et une nouvelle fois sur "Ok".
    ▶ Un rapport s'ouvrira, copie/colle son contenu dans ton prochain message./list

    /!\ Si la méthode "Update Using jucheck.exe" ne fonctionne pas, télécharge la dernière version de java à Cette adresse puis passe directement à la partie Remove Older Versions" /!\

    2ème étape : Adobe Reader

    ▶ Si tu utilises adobe reader, il est important qu'il soit à jour.
    ▶ Si il n'est pas à jour, certains programmes malveillants peuvent exploiter différentes failles et infecter ton PC ( Voir ici )
    ▶ Pour vérifier qu'adobe reader est à jour, lance le puis clique sur Aide -> Rechercher les mises à jour.

    3ème étape : Mise à jour des logiciels

    ▶ Il est également primordial de garder tes logiciels à jour. Pour ce faire, il existe un petit utilitaire, Update Checker.
    ▶ Télécharge le Ici
    ▶ Un tutoriel pour son utilisation est disponible Ici.

    2- Vacciner les supports amovibles

    ▶ Si nous n'avons pas utilisé USBfix lors de la procédure, tu peux vacciner tes supports amovibles pour éviter qu'ils ne s'infectent.
    ▶ Télécharge USBfix puis lance le. (Clique droit/Exécuter en tant qu'administrateur pour Vista/7).
    ▶ Branche tout tes médias amovibles ( Clé USB, Disque dur externe, carte SD ) puis sélectionne l'option Vacciner.
    ▶ Appuie sur Ok au message de confirmation.
    ▶ Une fois la vaccination terminée, relance usbfix et choisis l'option Désinstaller.

    Note : Si ton antivirus émet une alerte, désactive le momentanément ( il s'agit d'un faux positif )

    3- DelFix

    ▶ Télécharge DelFix sur ton bureau.
    ▶ Lance le, clique sur Suppression
    ▶ Patiente pendant le scan jusqu'à l'ouverture du rapport.
    ▶ Copie/Colle le contenu du rapport dans ta prochaine réponse.

    WOT :

    Je te conseille d'installer cette extension pour Firefox pour securiser ton surf : WOT
    Je te conseille d'installer cette extension pour Internet Explorer pour securiser ton surf : WOT
    Je te conseille d'installer cette extension pour Chrome pour securiser ton surf : WOT
    Je te conseille d'installer cette extension pour Safari pour securiser ton surf : WOT

    4- Optimisation

    1ère étape : Suppression des fichiers inutiles

    ▶ Télécharge CCleaner.
    ▶ Installe le, puis lance le.
    ▶ Va dans l'onglet "Options" puis " Avancé " et décoche " Effacer uniquement les fichiers[...] ".
    ▶ Cliques sur l'onglet " Nettoyeur " puis cliques sur Analyser<gras>. A la fin de l'analyse, clique sur <gras>Nettoyer.
    ▶ Rends toi à l'onglet " Registre " puis cliques sur Chercher les erreurs. Cliques ensuite sur Corriger les erreurs sélectionnées.
    ▶ Accepte la sauvegarde puis enregistre la dans tes documents (tu pourras la supprimer si aucun problème n'apparaît après la suppression)2
    ▶ Cliques ensuite sur Corriger toutes les erreurs sélectionnées puis sur Fermer
    ▶ Tu peux renouveler ces opérations tous les jours./list
    2ème étape : Défragmentation

    Au fur et à mesure que tu installes des logiciels, copies des fichiers etc.. le disque dur se fragmente et les accès en lecture/écriture sont plus longs.

    ▶ Télécharge https://www.ccleaner.com/defraggler/download/standardDefraggler].
    ▶ Un tutoriel pour son utilisation est disponible Ici.

    3ème étape : Vérification des disques

    ▶ Ouvre l'explorateur, puis fais un clique droit sur ta partition principale ( généralement C:\ )
    ▶ Clique sur Propriété puis sur l'onglet Outils
    ▶ Clique sur Vérifier maintenant puis coche les deux cases présentes.
    ▶ Clique sur Démarrer (Tu devras éventuellement redémarrer ton PC et le scan du disque s'effectuera au prochain démarrage).

    4ème étape : Désactivation des programmes au démarrage

    ▶ Clique sur Démarrer puis Exécuter.
    ▶ Tape msconfig et valide par ok.
    ▶ A l'onglet Démarrage , décoche tout les éléments sauf ceux se rapportant à ton antivirus / pare-feu / Ordinateur (programmes acer...).
    ▶ Clique sur Appliquer puis ok et redémarre ton PC./list

    4- Purge de la restauration système

    La restauration système est un endroit que windows utilise pour créer des sauvegardes. En cas de soucis, tu peux utiliser ces sauvegardes pour revenir à un état antérieur au problème.

    ▶ Après une désinfection, il faut purger la restauration système pour supprimer toutes traces de malwares y résidant.

    ▶ Tutoriels :

    - Windows XP
    - Windows Vista
    - Windows 7

    5- UAC ( Uniquement pour Vista/Seven )

    Si tu as désactivé l'UAC, il est important de la réactiver.

    -> Pourquoi garder l'UAC activée?

    6- Security Check

    Afin de vérifier si toutes les mise à jour ont bien été installées , nous allons utiliser un petit programme.

    ▶ Télécharge Security Check (de Screen317) sur ton bureau.
    ▶ Lance le, patiente pendant le scan puis poste le rapport qui s'ouvrira dans ta prochaine réponse.
    ▶ Une fois le rapport posté, tu peux supprimer Security Check./list

    7- Liens utiles

    Ces liens sont en rapport direct avec la sécurité de ton PC.
    Prends le temps de les lire pour comprendre pourquoi tu as été infecté.

    - Les dangers du P2P
    - La sécurité de son PC, c'est quoi ?
    - Sécuriser son ordinateur
    - Pourquoi maintenir son navigateur à jour?
    - Les toolbars c'est pas obligatoire

    8-Glary Utilities

    Passe Glary Utilities en le téléchargeant ici.

    Attention, lors de l'installation, il est demandé d'installer la Toolbar ASK, refuse, cette dernière est infectieuse.

    Voilà.
    ► Donc pour les conseils en général :

    1-Utilise toujours une session utilisateur et non administrateur.

    2-Tiens tout tes logiciels à jour.

    3-Ne crack pas (Emule, BiTorrent, etc...)

    4-Surveille les sites où tu vas avec WoT.

    5-Ne clique pas n'importe où.

    Merci,

    Gabriel.
    0
    1. Bonsoir Gabriel
      merci beaucoup pour ta collaboration c'est extra !!
      le PC marche du tonnerre
      il a retrouvé son punch de jeunesse !!
      je marque le sujet comme résolu
      bonne continuation
      ce forum est vraiment génial
      encore merci
      bonne soirée
      Cloud9
      0
      1. Contributeur sécurité
        C'est clean :)

        Encore des soucis ?

        Comment va le PC ?

        @+

        Gabriel.
        0
        1. Contributeur sécurité
          Re,

          /!\Utilisateur de Vista et Seven/!\ : Clic droit sur le logo de ZHPdiag (parchemin) puis « Exécuter en tant qu'Administrateur »

          => Clique sur l'icône, en haut à gauche, représentant une loupe : « Lancer le diagnostic ».
          => Enregistre le rapport sur ton Bureau à l'aide de l'icône représentant une disquette.
          => Héberge le rapport ZHPDiag.txt sur un des sites ci-dessous, puis copie/colle le lien fourni dans ta prochaine réponse sur le forum :

          https://www.cjoint.com/

          ou

          http://www.cijoint.fr/

          ou :

          http://ww38.toofiles.com/fr/documents-upload.html

          ou :

          http://pjjoint.malekal.com/

          ou :

          https://www.casimages.com/

          Si tu as besoin d'aide, ou quelque chose n'est pas clair, n'hésite pas à poser la question.

          @+

          Gabriel.
          0
          1. Bonjour
            excuses moi mais je ne comprends pas ce que ça veut dire
            héberge quoi ??? comme quoi ???
            merci beaucoup de m'expliquer, je ne suis pas douée !!!
            bonne journée
            Cloud9
            0
            1. Contributeur sécurité
              Salut,

              Héberge le comme précédemment effectué ;)

              @+

              Gabriel.
              0
              1. Salut Gabriel,
                voici le rapport demandé
                merci pour le tuyau du gestionnaire des taches
                et comment je retrouve mon bureau avec celui-ci ?
                bonne nuit
                merci encore
                Cloud9

                Rapport de ZHPDiag v1.28.1346 par Nicolas Coolman, Update du 29/08/2011
                Run by GREGORY at 13/09/2011 00:02:11
                Web site : http://www.premiumorange.com/zeb-help-process/zhpdiag.html

                ---\\ Web Browser
                MSIE: Internet Explorer v9.0.8112.16421
                MFIE: Mozilla Firefox 6.0.2 v6.0.2 (Defaut)

                ---\\ Windows Product Information
                Windows Vista Home Premium Edition, 32-bit Service Pack 2 (Build 6002)
                Windows Server License Manager Script : OK
                ~ Vista, OEM_SLP channel
                System Locked Preinstallation (OEM_SLP) : OK
                Windows ID Activation : OK
                ~ Windows Partial Key : MQ3CQ
                Windows License : OK
                Windows Automatic Updates : OK

                ---\\ System Information
                ~ Processor: x86 Family 15 Model 104 Stepping 1, AuthenticAMD
                ~ Operating System: 32 Bits
                Boot mode: Normal (Normal boot)
                Total RAM: 2046 MB (62% free)
                System Restore: Activé (Enable)
                System drive C: has 59 GB (41%) free of 141 GB

                ---\\ Logged in mode
                ~ Computer Name: LILIE
                ~ User Name: GREGORY
                ~ All Users Names: GREGORY, ASPNET, Administrateur,
                ~ Unselected Option: O45,O61,O62,O65,O66,O82
                Logged in as Administrator

                ---\\ Environnement Variables
                ~ System Unit : C:\
                ~ %AppData% : C:\Users\GREGORY\AppData\Roaming\
                ~ %Desktop% : C:\Users\GREGORY\Pictures\Desktop\
                ~ %Favorites% : C:\Users\GREGORY\Favorites\
                ~ %LocalAppData% : C:\Users\GREGORY\AppData\Local\
                ~ %StartMenu% : C:\Users\GREGORY\AppData\Roaming\Microsoft\Windows\Start Menu\
                ~ %Windir% : C:\Windows\
                ~ %System% : C:\Windows\system32\

                ---\\ DOS/Devices
                C:\ Hard drive, Flash drive, Thumb drive (Free 59 Go of 141 Go)
                D:\ CD-ROM drive (Not Inserted)

                ---\\ Security Center & Tools Informations
                [HKLM\SOFTWARE\Microsoft\Security Center] AntiSpywareOverride: OK
                [HKLM\SOFTWARE\Microsoft\Security Center] AntiVirusOverride: OK
                [HKLM\SOFTWARE\Microsoft\Security Center] AntiVirusDisableNotify: OK
                [HKLM\SOFTWARE\Microsoft\Security Center] FirewallDisableNotify: OK
                [HKLM\SOFTWARE\Microsoft\Security Center] FirewallOverride: OK
                [HKLM\SOFTWARE\Microsoft\Security Center] UpdatesDisableNotify: OK
                [HKLM\SOFTWARE\Microsoft\Security Center] UacDisableNotify: OK
                [HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiSpywareOverride: OK
                [HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusOverride: OK
                [HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusDisableNotify: OK
                [HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallDisableNotify: OK
                [HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallOverride: OK
                [HKLM\SOFTWARE\Microsoft\Security Center\Svc] UpdatesDisableNotify: OK
                [HKLM\SOFTWARE\Microsoft\Security Center\Svc] UacDisableNotify: OK
                [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: OK
                [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoDesktop: OK
                [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoFolderOptions: OK
                [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoDesktop: OK
                [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoStartMenuSubFolder: OK
                [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoResolveSearch: OK
                [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoClose: OK
                [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System] NoActiveDesktopChanges: OK
                [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: OK
                [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: OK
                [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced] Start_ShowSearch: OK
                [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings] WarnOnHTTPSToHTTPRedirect: OK
                [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK
                [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK
                [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK
                [HKLM\SYSTEM\CurrentControlSet\Services] wscsvc : OK
                ~ Scan Security Center in 00mn 00s

                ---\\ Recherche particulière de fichiers génériques
                [MD5.D07D4C3038F3578FFCE1C0237F2A1253] - (.Microsoft Corporation - Explorateur Windows.) (.10/09/2011 - 07:27:36.) -- C:\Windows\Explorer.exe [2926592]
                [MD5.4B555106290BD117334E9A08761C035A] - (....) (.02/11/2006 - 10:45:37.) -- C:\Windows\system32\rundll32.exe [44544]
                [MD5.101BA3EA053480BB5D957EF37C06B5ED] - (.Microsoft Corporation - Application de démarrage de Windows.) (.24/03/2009 - 08:33:37.) -- C:\Windows\system32\Wininit.exe [96768]
                [MD5.2C7332C222D1FE1FC57D622699A8C001] - (.Microsoft Corporation - Extensions Internet pour Win32.) (.11/09/2011 - 14:21:59.) -- C:\Windows\system32\wininet.dll [1126912]
                [MD5.898E7C06A350D4A1A64A9EA264D55452] - (.Microsoft Corporation - Application d'ouverture de session Windows.) (.10/09/2011 - 07:28:13.) -- C:\Windows\system32\Winlogon.exe [314368]
                [MD5.1F05B78AB91C9075565A9D8A4B880BC4] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.10/09/2011 - 07:32:26.) -- C:\Windows\system32\drivers\atapi.sys [19944]
                [MD5.6A4A98CEE84CF9E99564510DDA4BAA47] - (.Microsoft Corporation - Pilote du système de fichiers NT.) (.10/09/2011 - 07:32:49.) -- C:\Windows\system32\drivers\ntfs.sys [1083880]
                [MD5.95F5FF73B076576C41740F1A842B9B57] - (....) (.24/03/2009 - 08:34:10.) -- C:\Windows\system32\fr-FR\user32.dll.mui [20480]
                ~ Scan Generic Processes in 00mn 00s

                ---\\ Etat des fichiers cachés (Caché/Total)
                ~ Mes images (My Pictures) : 29/2213
                ~ Mes musiques (My Musics) : 66/225
                ~ Mes Videos (My Videos) : 1/34
                ~ Mes Favoris (My Favorites) : 2/35
                ~ Mes Documents (My Documents) : 8/749
                ~ Mon Bureau (My Desktop) : 3/39
                ~ Menu demarrer (Programs) : 6/21
                ~ Scan Hidden Files in 00mn 04s

                ---\\ Processus lancés
                [MD5.0D392EDE3B97E0B3131B2F63EF1DB94E] - (.Microsoft Corporation - Windows Defender User Interface.) -- C:\Program Files\Windows Defender\MSASCui.exe [1008184] [PID.2952]
                [MD5.E4E99677636EF949B546A1751C9B3A35] - (.Synaptics, Inc. - Synaptics TouchPad Enhancements.) -- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [845360] [PID.3236]
                [MD5.FF32C2770BD4AD29178B00E77F92197C] - (.Realtek Semiconductor Corp. - Card Reader Software.) -- C:\Program Files\Realtek Semiconductor Corp\Realtek Card Reader Monitor\CardReaderMonitor.exe [643072] [PID.3268]
                [MD5.E26642C193B81F2AA06D6013D4E07D03] - (...) -- C:\Program Files\CyberLink\MagicSports\Kernel\MagicSports\MSPMirage.exe [102400] [PID.3292]
                [MD5.4B555106290BD117334E9A08761C035A] - (...) -- C:\Windows\System32\rundll32.exe [44544] [PID.3624]
                [MD5.9D5E8B45BD348DF0882C69EED0E83111] - (.Avira GmbH - Antivirus System Tray Tool.) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [281768] [PID.3644]
                [MD5.BF08674925F151BD4537B89A493E3E0C] - (.Microsoft Corporation - Media Center Tray Applet.) -- C:\Windows\ehome\ehtray.exe [125952] [PID.3796]
                [MD5.0F4195B9B348DE5CF9B822F81704B20E] - (.Microsoft Corporation - Media Center Media Status Aggregator Servic.) -- C:\Windows\ehome\ehmsas.exe [37376] [PID.3884]
                [MD5.63346640E170B63970C093F720065DAB] - (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe [924632] [PID.3556]
                [MD5.5676E75F98FF8E0F81DFF604A09288BB] - (.RealNetworks, Inc. - RealNetworks Scheduler.) -- C:\Program Files\Common Files\Real\Update_OB\realsched.exe [198160] [PID.3616]
                [MD5.7653CD0E8F2C0052185673B574DB699E] - (.Mozilla Corporation - Plugin Container for Firefox.) -- C:\Program Files\Mozilla Firefox\plugin-container.exe [16856] [PID.3944]
                [MD5.7914370AAC5CDE8DCAE1C674A6C90229] - (.Nicolas Coolman - Diagnostic Tool.) -- C:\Program Files\ZHPDiag\ZHPDiag.exe [669696] [PID.492]
                [MD5.6080A176D09435FC8E6E800996656E18] - (.Microsoft Corporation - Console IME.) -- C:\Windows\system32\conime.exe [69120] [PID.2676]
                [MD5.862BB4CBC05D80C5B45BE430E5EF872F] - (.Microsoft Corporation - Service de gestion des licences Microsoft.) -- C:\Windows\system32\SLsvc.exe [3408896] [PID.]
                [MD5.A5BCBAF0477C4869B67E0195AEA4A9CD] - (.Avira GmbH - Antivirus Scheduler.) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe [136360] [PID.]
                [MD5.11A52CF7B265631DEEB24C6149309EFF] - (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [64952] [PID.]
                [MD5.3CCE4AFA4AACDB28E01A148394212186] - (.Avira GmbH - Antivirus On-Access Service.) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe [269480] [PID.]
                [MD5.C3162AC1B592CEB43ABE2F972A7222D3] - (.Pas de propriétaire - RichVideo Module.) -- C:\Program Files\CyberLink\Shared Files\RichVideo.exe [266343] [PID.]
                [MD5.910FBA95EE4F56449AA81315884C8EFD] - (.Sonic Solutions - RoxSniffer9 Module.) -- C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe [166648] [PID.]
                [MD5.CDE000884FD7BAF0C1FDFE029B0891DE] - (.Avira GmbH - AntiVir shadow copy service.) -- C:\Program Files\Avira\AntiVir Desktop\avshadow.exe [76968] [PID.]
                [MD5.9638E5820858593A12005C753B03CEAE] - (.Sonic Solutions - RoxMediaDB9 Module.) -- C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe [887544] [PID.]
                [MD5.598AC9DA3CCD5511ECC4A986B18F7E61] - (.Google - Google Desktop.) -- C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [243200] [PID.]
                ~ Scan Processes Running in 00mn 01s

                ---\\ Mozilla Firefox, Plugins,Demarrage,Recherche,Extensions (P2,M0,M1,M2,M3)
                C:\Users\GREGORY\AppData\Roaming\Mozilla\Firefox\Profiles\e67htkl9.default\prefs.js
                C:\Users\GREGORY\AppData\Roaming\Mozilla\Firefox\Profiles\e67htkl9.default\user.js (.not file.)
                M3 - MFPP: Plugins - [GREGORY] -- C:\Program Files\Mozilla FireFox\searchplugins\amazon-france.xml
                M3 - MFPP: Plugins - [GREGORY] -- C:\Program Files\Mozilla FireFox\searchplugins\bing.xml
                M3 - MFPP: Plugins - [GREGORY] -- C:\Program Files\Mozilla FireFox\searchplugins\cnrtl-tlfi-fr.xml
                M3 - MFPP: Plugins - [GREGORY] -- C:\Program Files\Mozilla FireFox\searchplugins\eBay-france.xml
                M3 - MFPP: Plugins - [GREGORY] -- C:\Program Files\Mozilla FireFox\searchplugins\google.xml
                M3 - MFPP: Plugins - [GREGORY] -- C:\Program Files\Mozilla FireFox\searchplugins\wikipedia-fr.xml
                M3 - MFPP: Plugins - [GREGORY] -- C:\Program Files\Mozilla FireFox\searchplugins\yahoo-france.xml
                M0 - MFSP: prefs.js [GREGORY - e67htkl9.default] https://www.google.fr/?gws_rd=ssl
                P2 - FPN:Firefox Plugin Navigator . (.Microsoft Corporation - np-mswmp.) -- C:\Program Files\Mozilla Firefox\Plugins\np-mswmp.dll
                P2 - FPN:Firefox Plugin Navigator . (.Sun Microsystems, Inc. - NPRuntime Script Plug-in Library for Java(TM) Deploy.) -- C:\Program Files\Mozilla Firefox\Plugins\npdeployJava1.dll
                P2 - FPN:Firefox Plugin Navigator . (.Microsoft Corporation - 1.9.0009.1.) -- C:\Program Files\Mozilla Firefox\Plugins\npLegitCheckPlugin.dll
                P2 - FPN:Firefox Plugin Navigator . (.Microsoft Corporation - Office Plugin for Netscape Navigator.) -- C:\Program Files\Mozilla Firefox\Plugins\NPOFF12.DLL
                P2 - FPN:Firefox Plugin Navigator . (.Adobe Systems Inc. - Adobe PDF Plug-In For Firefox and Netscape 10.1.0.) -- C:\Program Files\Mozilla Firefox\Plugins\nppdf32.dll
                P2 - FPN:Firefox Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files\Mozilla Firefox\Plugins\npqtplugin.dll
                P2 - FPN:Firefox Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files\Mozilla Firefox\Plugins\npqtplugin2.dll
                P2 - FPN:Firefox Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files\Mozilla Firefox\Plugins\npqtplugin3.dll
                P2 - FPN:Firefox Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files\Mozilla Firefox\Plugins\npqtplugin4.dll
                P2 - FPN:Firefox Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files\Mozilla Firefox\Plugins\npqtplugin5.dll
                P2 - FPN:Firefox Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files\Mozilla Firefox\Plugins\npqtplugin6.dll
                P2 - FPN:Firefox Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files\Mozilla Firefox\Plugins\npqtplugin7.dll
                P2 - FPN: [HKLM] [@adobe.com/FlashPlayer] - (...) -- C:\Windows\system32\Macromed\Flash\NPSWF32.dll
                P2 - FPN: [HKLM] [@bittorrent.com/BitTorrentDNA] - (.BitTorrent, Inc. - Delivery Network Acceleration by BitTorrent(TM).) -- C:\Program Files\DNA\plugins\npbtdna.dll
                P2 - FPN: [HKLM] [@Google.com/GoogleEarthPlugin] - (.Google - GEPlugin.) -- C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
                P2 - FPN: [HKLM] [@java.com/JavaPlugin] - (.Sun Microsystems, Inc. - Next Generation Java Plug-in 1.6.0_27 for Mozilla browsers.) -- C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
                P2 - FPN: [HKLM] [@microsoft.com/OfficeLive,version=1.3] - (.Microsoft Corp. - Office Live Update v1.3.) -- C:\Program Files\Microsoft\Office Live\npOLW.dll
                P2 - FPN: [HKLM] [@microsoft.com/WPF,version=3.5] - (.Microsoft Corporation - Windows Presentation Foundation (WPF) plug-in for Mozilla browsers.) -- c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
                P2 - FPN: [HKLM] [@real.com/nppl3260;version=6.0.12.69] - (.RealNetworks, Inc. - RealPlayer(tm) LiveConnect-Enabled Plug-In.) -- C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll
                P2 - FPN: [HKLM] [@real.com/nprjplug;version=1.0.3.69] - (.RealNetworks, Inc. - RealJukebox Netscape Plugin.) -- C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll
                P2 - FPN: [HKLM] [@real.com/nprpjplug;version=6.0.12.69] - (.RealNetworks, Inc. - 6.0.12.69.) -- C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll
                P2 - FPN: [HKLM] [@tools.google.com/Google Update;version=3] - (.Google Inc. - Google Update.) -- C:\Program Files\Google\Update\1.3.21.69\npGoogleUpdate3.dll
                P2 - FPN: [HKLM] [@tools.google.com/Google Update;version=9] - (.Google Inc. - Google Update.) -- C:\Program Files\Google\Update\1.3.21.69\npGoogleUpdate3.dll
                P2 - FPN: [HKLM] [Adobe Reader] - (.Adobe Systems Inc. - Adobe PDF Plug-In For Firefox and Netscape 10.1.0.) -- C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
                ~ Scan Firefox Browser in 00mn 00s

                ---\\ Internet Explorer, Démarrage,Recherche,URLSearchHook, Phishing (R0,R1,R3,R4)
                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
                R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
                R0 - HKUS\S-1-5-21-2477963207-3090536540-4185239906-1002\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.microsoft.com/fr-fr/
                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.microsoft.com/fr-fr/
                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.microsoft.com/fr-fr/
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk
                R1 - HKUS\S-1-5-21-2477963207-3090536540-4185239906-1002\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.microsoft.com/fr-fr/
                R3 - URLSearchHook: (no name) - {08C06D61-F1F3-4799-86F8-BE1A89362C85} . (...) (No version) -- (.not file.)
                R3 - URLSearchHook: Microsoft Url Search Hook - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} . (.Microsoft Corporation - Navigateur Internet.) (9.00.8112.16421 (WIN7_IE9_RTM.110308-0330)) -- C:\Windows\system32\ieframe.dll
                ~ Scan IE Browser in 00mn 00s

                ---\\ Internet Explorer, Proxy Management (R5)
                R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key
                R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
                R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
                R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
                R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll
                ~ Scan Proxy management in 00mn 00s

                ---\\ Modification d'une valeur Ini (Changed inifile value, mapped to Registry) (F2)
                F2 - REG:system.ini: UserInit=C:\Windows\system32\Userinit.exe,
                F2 - REG:system.ini: VMApplet=rundll32 shell32,Control_RunDLL "sysdm.cpl"
                ~ Scan Keys in 00mn 00s

                ---\\ Redirection du fichier Hosts (O1)
                ~ Scan Hosts File in 00mn 00s

                ---\\ Browser Helper Objects de navigateur (O2)
                O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} . (.Adobe Systems Incorporated - Adobe PDF Helper for Internet Explorer.) -- C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
                O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} . (.Sun Microsystems, Inc. - Java(TM) Platform SE binary.) -- C:\Program Files\Java\jre6\bin\ssv.dll
                O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} . (.Microsoft Corporation - WindowsLiveLogin.dll.) -- C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} . (.Sun Microsystems, Inc. - Java(TM) Platform SE binary.) -- C:\Program Files\Java\jre6\bin\jp2ssv.dll
                ~ Scan BHO in 00mn 00s

                ---\\ Applications démarrées par registre & par dossier (O4)
                O4 - HKLM\..\Run: [Windows Defender] . (.Microsoft Corporation - Windows Defender User Interface.) -- C:\Program Files\Windows Defender\MSASCui.exe
                O4 - HKLM\..\Run: [SynTPEnh] . (.Synaptics, Inc. - Synaptics TouchPad Enhancements.) -- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                O4 - HKLM\..\Run: [CardReaderMonitor] . (.Realtek Semiconductor Corp. - Card Reader Software.) -- C:\Program Files\Realtek Semiconductor Corp.\Realtek Card Reader Monitor\CardReaderMonitor.exe
                O4 - HKLM\..\Run: [RoxWatchTray] . (.Sonic Solutions - RoxMMTrayApp Module.) -- C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
                O4 - HKLM\..\Run: [Google Desktop Search] . (.Google - Google Desktop.) -- C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                O4 - HKLM\..\Run: [MSPService] . (...) -- C:\Program Files\CyberLink\MagicSports\Kernel\MagicSports\MSPMirage.exe
                O4 - HKLM\..\Run: [toolbar_eula_launcher] . (...) -- C:\Program Files\Packard Bell\GOOGLE_EULA\EULALauncher.exe
                O4 - HKLM\..\Run: [QuickTime Task] . (.Apple Inc. - QuickTime Task.) -- C:\Program Files\QuickTime\QTTask.exe
                O4 - HKLM\..\Run: [TkBellExe] . (.RealNetworks, Inc. - RealNetworks Scheduler.) -- C:\Program Files\Common Files\Real\Update_OB\realsched.exe
                O4 - HKLM\..\Run: [NvSvc] . (.NVIDIA Corporation - NVIDIA Driver Helper Service, Version 156.6.) -- C:\Windows\system32\nvsvc.dll
                O4 - HKLM\..\Run: [NvCplDaemon] . (.NVIDIA Corporation - NVIDIA Display Properties Extension.) -- C:\Windows\system32\NvCpl.dll
                O4 - HKLM\..\Run: [NvMediaCenter] . (.NVIDIA Corporation - NVIDIA Media Center Library.) -- C:\Windows\system32\NvMcTray.dll
                O4 - HKLM\..\Run: [avgnt] . (.Avira GmbH - Antivirus System Tray Tool.) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
                O4 - HKLM\..\Run: [Adobe ARM] . (.Adobe Systems Incorporated - Adobe Reader and Acrobat Manager.) -- C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
                O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware (reboot)] . (.Malwarebytes Corporation - Malwarebytes' Anti-Malware.) -- C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
                O4 - HKCU\..\Run: [ehTray.exe] . (.Microsoft Corporation - Media Center Tray Applet.) -- C:\Windows\ehome\ehTray.exe
                O4 - HKUS\S-1-5-19\..\Run: [Sidebar] . (.Microsoft Corporation - Volet Windows.) -- C:\Program Files\Windows Sidebar\Sidebar.exe
                O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] oobefldr.dll
                O4 - HKUS\S-1-5-20\..\Run: [Sidebar] . (.Microsoft Corporation - Volet Windows.) -- C:\Program Files\Windows Sidebar\Sidebar.exe
                O4 - HKUS\S-1-5-20\..\Run: [WindowsWelcomeCenter] oobefldr.dll
                O4 - HKUS\S-1-5-21-2477963207-3090536540-4185239906-1002\..\Run: [ehTray.exe] . (.Microsoft Corporation - Media Center Tray Applet.) -- C:\Windows\ehome\ehTray.exe
                ~ Scan Application in 00mn 00s

                ---\\ Autres liens utilisateurs (O4)
                O4 - Global Startup: C:\Users\GREGORY\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk . (.Microsoft Corporation.) -- C:\Program Files\Internet Explorer\iexplore.exe
                O4 - Global Startup: C:\Users\GREGORY\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Mail.lnk . (.Microsoft Corporation.) -- C:\Program Files\Windows Mail\WinMail.exe
                O4 - Global Startup: C:\Users\GREGORY\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk . (.Microsoft Corporation.) -- C:\Program Files\Windows Media Player\wmplayer.exe
                O4 - Global Startup: C:\Users\GREGORY\Desktop\AD-R.lnk . (...) -- C:\Program Files\Ad-Remover\main.exe
                O4 - Global Startup: C:\Users\GREGORY\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Earth.lnk . (.Google.) -- C:\Program Files\Google\Google Earth\client\googleearth.exe
                O4 - Global Startup: C:\Users\GREGORY\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk . (.Microsoft Corporation.) -- C:\Program Files\Internet Explorer\iexplore.exe
                O4 - Global Startup: C:\Users\GREGORY\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Outlook.lnk . (.Microsoft Corporation.) -- C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE
                O4 - Global Startup: C:\Users\GREGORY\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Picture Manager.lnk . (...) -- C:\Windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\oisicon.exe
                O4 - Global Startup: C:\Users\GREGORY\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Microsoft® Works SE 9.lnk . (.Microsoft® Corporation.) -- C:\Program Files\Microsoft Works\MSWorks.exe
                O4 - Global Startup: C:\Users\GREGORY\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk . (.Mozilla Corporation.) -- C:\Program Files\Mozilla Firefox\firefox.exe
                O4 - Global Startup: C:\Users\GREGORY\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Ordinateur - Raccourci.lnk - Clé orpheline
                ~ Scan Global Startup in 00mn 00s

                ---\\ Lignes supplémentaires dans le menu contextuel d'Internet Explorer (O8)
                O8 - Extra context menu item: E&xporter vers Microsoft Excel . (.Microsoft Corporation - Microsoft Office Excel.) -- C:\PROGRA~1\MICROS~3\Office12\EXCEL.exe
                O8 - Extra context menu item: Google Sidewiki... - (.not file.) - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll
                ~ Scan IE Menu Contextuel in 00mn 00s

                ---\\ Boutons situés sur la barre d'outils principale d'Internet Explorer (O9)
                O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} . (...) -- C:\PROGRA~1\MICROS~3\Office12\REFBARH.ICO
                ~ Scan IE Extra Buttons in 00mn 00s

                ---\\ Winsock hijacker (Layered Service Provider) (O10)
                O10 - WLSP:\000000000001\Winsock LSP File . (.Microsoft Corporation - Network Location Awareness 2.) -- C:\Windows\system32\NLAapi.dll
                O10 - WLSP:\000000000002\Winsock LSP File . (.Microsoft Corporation - Fournisseur Shim d'affectation de noms de messagerie.) -- C:\Windows\system32\napinsp.dll
                O10 - WLSP:\000000000003\Winsock LSP File . (.Microsoft Corporation - Fournisseur d'espace de noms PNRP.) -- C:\Windows\system32\pnrpnsp.dll
                O10 - WLSP:\000000000004\Winsock LSP File . (.Microsoft Corporation - Fournisseur d'espace de noms PNRP.) -- C:\Windows\system32\pnrpnsp.dll
                O10 - WLSP:\000000000005\Winsock LSP File . (.Microsoft Corporation - Fournisseur de service Sockets 2.0 de Microsoft Windows.) -- C:\Windows\system32\mswsock.dll
                O10 - WLSP:\000000000006\Winsock LSP File . (.Microsoft Corporation - LDAP RnR Provider DLL.) -- C:\Windows\system32\winrnr.dll
                ~ Scan Winsock in 00mn 00s

                ---\\ Objets ActiveX (Downloaded Program Files)(O16)
                O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} () - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
                ~ Scan Objets ActiveX in 00mn 00s

                ---\\ Modification Domaine/Adresses DNS (O17)
                O17 - HKLM\System\CCS\Services\Tcpip\..\{08011A64-847A-4CE0-A337-1A597D9479CD}: DhcpNameServer = 192.168.1.1
                O17 - HKLM\System\CCS\Services\Tcpip\..\{28913EA0-97C1-4CD6-A81B-C690B2F4BF0F}: DhcpNameServer = 192.168.1.254
                O17 - HKLM\System\CS1\Services\Tcpip\..\{08011A64-847A-4CE0-A337-1A597D9479CD}: DhcpNameServer = 192.168.1.1
                O17 - HKLM\System\CS1\Services\Tcpip\..\{28913EA0-97C1-4CD6-A81B-C690B2F4BF0F}: DhcpNameServer = 192.168.1.254
                O17 - HKLM\System\CS2\Services\Tcpip\..\{08011A64-847A-4CE0-A337-1A597D9479CD}: DhcpNameServer = 192.168.1.1
                O17 - HKLM\System\CS2\Services\Tcpip\..\{28913EA0-97C1-4CD6-A81B-C690B2F4BF0F}: DhcpNameServer = 192.168.1.254
                ~ Scan Domain in 00mn 00s

                ---\\ Protocole additionnel (O18)
                O18 - Handler: about - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\system32\mshtml.dll
                O18 - Handler: cdl - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\system32\urlmon.dll
                O18 - Handler: dvd - {12D51199-0DB5-46FE-A120-47A3D7D937CC} . (.Microsoft Corporation - Contrôle ActiveX pour le flux vidéo.) -- C:\Windows\System32\msvidctl.dll
                O18 - Handler: file - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\system32\urlmon.dll
                O18 - Handler: ftp - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\system32\urlmon.dll
                O18 - Handler: http - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\system32\urlmon.dll
                O18 - Handler: https - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\system32\urlmon.dll
                O18 - Handler: its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\System32\itss.dll
                O18 - Handler: javascript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\system32\mshtml.dll
                O18 - Handler: local - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\system32\urlmon.dll
                O18 - Handler: mailto - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\system32\mshtml.dll
                O18 - Handler: mhtml - {05300401-BCBC-11d0-85E3-00C04FD85AB4} . (.Microsoft Corporation - Microsoft Internet Messaging API Resources.) -- C:\Windows\system32\inetcomm.dll
                O18 - Handler: mk - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - Extensions OLE32 pour Win32.) -- C:\Windows\system32\urlmon.dll
                O18 - Handler: ms-help - {314111c7-a502-11d2-bbca-00c04f8ec294} . (.Microsoft Corporation - Microsoft® Help Data Services Module.) -- C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
                O18 - Handler: ms-its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\System32\itss.dll
                O18 - Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll
                O18 - Handler: res - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\system32\mshtml.dll
                O18 - Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} . (.Skype Technologies - Skype for COM API.) -- C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
                O18 - Handler: tv - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} . (.Microsoft Corporation - Contrôle ActiveX pour le flux vidéo.) -- C:\Windows\System32\msvidctl.dll
                O18 - Handler: vbscript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Visionneuse HTML Microsoft (R).) -- C:\Windows\system32\mshtml.dll
                O18 - Filter: application/octet-stream - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\system32\mscoree.dll
                O18 - Filter: application/x-complus - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\system32\mscoree.dll
                O18 - Filter: application/x-msdownload - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\system32\mscoree.dll
                O18 - Filter: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} . (.Microsoft Corporation - Microsoft Office XML MIME Filter.) -- C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
                ~ Scan Protocole Additionnel in 00mn 00s

                ---\\ Clé de Registre autorun ShellServiceObjectDelayLoad (SSO/SSODL) (O21)
                O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} . (.Microsoft Corporation - Contrôleur de site Web.) -- C:\Windows\System32\webcheck.dll
                ~ Scan SSODL in 00mn 00s

                ---\\ Clé de Registre autorun SharedTaskScheduler (STS) (O22)
                O22 - SharedTaskScheduler: (no name) - {8C7461EF-2B13-11d2-BE35-3078302C2030} . (.Microsoft Corporation - Bibliothèque de l'interface utilisateur du.) -- C:\Windows\system32\browseui.dll
                ~ Scan STS/SSO in 00mn 00s

                ---\\ Liste des services NT non Microsoft et non désactivés (O23)
                O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) . (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
                O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) . (.Avira GmbH - Antivirus Scheduler.) - C:\Program Files\Avira\AntiVir Desktop\sched.exe
                O23 - Service: Avira AntiVir Guard (AntiVirService) . (.Avira GmbH - Antivirus On-Access Service.) - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                O23 - Service: Google Update Service (gupdate) (gupdate) . (.Google Inc. - Programme d'installation de Google.) - C:\Program Files\Google\Update\GoogleUpdate.exe
                O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) . (.Pas de propriétaire - RichVideo Module.) - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
                O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) . (.Sonic Solutions - RoxSniffer9 Module.) - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
                ~ Scan Services in 00mn 00s

                ---\\ Enumération Active Desktop & MHTML Editor (O24)
                O24 - Default MHTML Editor: Last - .(.Microsoft Corporation - Microsoft Office Word.) - C:\Program Files\Microsoft Office\Office12\WINWORD.exe
                ~ Scan Desktop Component in 00mn 00s

                ---\\ Tâches planifiées en automatique (O39)
                O39 - APT:Automatic Planified Task - C:\Windows\Tasks\Extension de garantie.job
                O39 - APT:Automatic Planified Task - C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
                O39 - APT:Automatic Planified Task - C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
                O39 - APT:Automatic Planified Task - C:\Windows\Tasks\HDReg.job
                O39 - APT:Automatic Planified Task - C:\Windows\Tasks\Recovery DVD Creator.job
                O39 - APT:Automatic Planified Task - C:\Windows\Tasks\User_Feed_Synchronization-{2861E1DB-17D4-4A20-9FAF-644E3E426C9A}.job
                [MD5.FA52C48CA18EDFB00180FD465E8F0B08] [APT] [Extension de garantie] (.Packard Bell BV.) -- C:\Program Files\Packard Bell\SetupmyPC\PBCarNot.exe
                [MD5.8F0DE4FEF8201E306F9938B0905AC96A] [APT] [GoogleUpdateTaskMachineCore] (.Google Inc..) -- C:\Program Files\Google\Update\GoogleUpdate.exe
                [MD5.8F0DE4FEF8201E306F9938B0905AC96A] [APT] [GoogleUpdateTaskMachineUA] (.Google Inc..) -- C:\Program Files\Google\Update\GoogleUpdate.exe
                [MD5.4CCD772ADC75A6F284461402BDB32981] [APT] [HDReg] (...) -- C:\Program Files\HDReg\HDRegRem.exe
                [MD5.B6D82C30267289D56B4BFDE3715D8F9F] [APT] [Recovery DVD Creator] (.Packard Bell BV.) -- C:\Program Files\Packard Bell\SetupMyPc\MCDCheck.exe
                ~ Scan Scheduled Task in 00mn 05s

                ---\\ Pilotes lancés au démarrage (O41)
                O41 - Driver: (AFD) . (.Microsoft Corporation - Ancillary Function Driver for WinSock.) - C:\Windows\system32\drivers\afd.sys
                O41 - Driver: (avipbb) . (.Avira GmbH - Avira Driver for Security Enhancement.) - C:\Windows\system32\DRIVERS\avipbb.sys
                O41 - Driver: (cdrom) . (.Microsoft Corporation - SCSI CD-ROM Driver.) - C:\Windows\system32\DRIVERS\cdrom.sys
                O41 - Driver: C:\Windows\system32\drivers\dfsc.sys (DfsC) . (.Microsoft Corporation - DFS Namespace Client Driver.) - C:\Windows\system32\Drivers\dfsc.sys
                O41 - Driver: (i8042prt) . (.Microsoft Corporation - Pilote de port i8042.) - C:\Windows\system32\DRIVERS\i8042prt.sys
                O41 - Driver: (kbdclass) . (.Microsoft Corporation - Pilote de la classe Clavier.) - C:\Windows\system32\DRIVERS\kbdclass.sys
                O41 - Driver: (mouclass) . (.Microsoft Corporation - Pilote de la classe Souris.) - C:\Windows\system32\DRIVERS\mouclass.sys
                O41 - Driver: (NetBIOS) . (.Microsoft Corporation - NetBIOS interface driver.) - C:\Windows\system32\DRIVERS\netbios.sys
                O41 - Driver: (netbt) . (.Microsoft Corporation - MBT Transport driver.) - C:\Windows\system32\DRIVERS\netbt.sys
                O41 - Driver: (nsiproxy) . (.Microsoft Corporation - NSI Proxy.) - C:\Windows\system32\drivers\nsiproxy.sys
                O41 - Driver: C:\Windows\system32\drivers\pacer.sys (PSched) . (.Microsoft Corporation - Planificateur de paquets QoS.) - C:\Windows\system32\DRIVERS\pacer.sys
                O41 - Driver: (RasAcd) . (.Microsoft Corporation - RAS Automatic Connection Driver.) - C:\Windows\system32\DRIVERS\rasacd.sys
                O41 - Driver: (rdbss) . (.Microsoft Corporation - Redirected Drive Buffering SubSystem Driver.) - C:\Windows\system32\DRIVERS\rdbss.sys
                O41 - Driver: (RDPCDD) . (.Microsoft Corporation - RDP Miniport.) - C:\Windows\system32\DRIVERS\RDPCDD.sys
                O41 - Driver: (RDPENCDD) . (.Microsoft Corporation - RDP Miniport.) - C:\Windows\system32\drivers\rdpencdd.sys
                O41 - Driver: C:\Windows\system32\tcpipcfg.dll (Smb) . (.Microsoft Corporation - SMB Transport driver.) - C:\Windows\system32\DRIVERS\smb.sys
                O41 - Driver: (ssmdrv) . (.Avira GmbH - AVIRA SnapShot Driver.) - C:\Windows\system32\DRIVERS\ssmdrv.sys
                O41 - Driver: C:\Windows\system32\tcpipcfg.dll (tdx) . (.Microsoft Corporation - TDI Translation Driver.) - C:\Windows\system32\DRIVERS\tdx.sys
                O41 - Driver: (TermDD) . (.Microsoft Corporation - Terminal Server Driver.) - C:\Windows\system32\DRIVERS\termdd.sys
                O41 - Driver: (VgaSave) . (.Microsoft Corporation - VGA/Super VGA Video Driver.) - C:\Windows\system32\drivers\vga.sys
                O41 - Driver: (Wanarpv6) . (.Microsoft Corporation - MS Remote Access and Routing ARP Driver.) - C:\Windows\system32\DRIVERS\wanarp.sys
                ~ Scan Drivers in 00mn 01s

                ---\\ Logiciels installés (O42)
                O42 - Logiciel: 7-Zip 9.20 - (.Pas de propriétaire.) [HKLM] -- 7-Zip
                O42 - Logiciel: Adobe Flash Player 10 ActiveX - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player ActiveX
                O42 - Logiciel: Adobe Flash Player 10 Plugin - (.Adobe Systems Incorporated.) [HKLM] -- Adobe Flash Player Plugin
                O42 - Logiciel: Adobe Reader 8 - (.Pas de propriétaire.) [HKLM] -- AdobeReader
                O42 - Logiciel: Avira AntiVir Personal - Free Antivirus - (.Avira GmbH.) [HKLM] -- Avira AntiVir Desktop
                O42 - Logiciel: Bison WebCam - (.Bison WebCam.) [HKLM] -- {4BB1DCED-84D3-47F9-B718-5947E904593E}
                O42 - Logiciel: CCleaner - (.Piriform.) [HKLM] -- CCleaner
                O42 - Logiciel: Camera RAW Plug-In for EPSON Creativity Suite - (.SEIKO EPSON CORPORATION.) [HKLM] -- {42EDF895-158C-484E-A7F2-42B90759F281}
                O42 - Logiciel: Canon EOS Kiss REBEL 300D Pilote TWAIN - (.Canon.) [HKLM] -- InstallShield_{4F9EF11C-A91A-42D0-BDAC-BB9695237075}
                O42 - Logiciel: Canon RAW Image Task for ZoomBrowser EX - (.Canon.) [HKLM] -- InstallShield_{D076E06B-F74B-454F-A56E-7510D7B6C9F0}
                O42 - Logiciel: Canon Utilities RemoteCapture 2.7 - (.Canon.) [HKLM] -- InstallShield_{14220DB1-DD96-4BCD-B3D5-03A4EA6631C4}
                O42 - Logiciel: Conexant HD Audio - (.Conexant.) [HKLM] -- CNXT_HDAUDIO
                O42 - Logiciel: Creator 9 - (.Pas de propriétaire.) [HKLM] -- CREATOR9
                O42 - Logiciel: EPSON Attach To Email - (.SEIKO EPSON.) [HKLM] -- InstallShield_{20C45B32-5AB6-46A4-94EF-58950CAF05E5}
                O42 - Logiciel: EPSON Easy Photo Print - (.SEIKO EPSON CORPORATION.) [HKLM] -- {8A8F8391-4C2C-4BE1-A984-CD4A5A546467}
                O42 - Logiciel: EPSON File Manager - (.Pas de propriétaire.) [HKLM] -- {46CBBDF8-55B5-40DB-B459-7B848394309C}
                O42 - Logiciel: EPSON Scan - (.Pas de propriétaire.) [HKLM] -- EPSON Scanner
                O42 - Logiciel: EPSON Scan Assistant - (.Pas de propriétaire.) [HKLM] -- {2A88F1BF-7041-4E42-84B1-6B4ACB83AC64}
                O42 - Logiciel: EPSON Stylus SX200 Series Printer Uninstall - (.SEIKO EPSON Corporation.) [HKLM] -- EPSON Stylus SX200 Series
                O42 - Logiciel: EPSON Stylus SX200_SX400_TX200_TX400 Manuel - (.Pas de propriétaire.) [HKLM] -- EPSON Stylus SX200_SX400_TX200_TX400 Guide d'utilisation
                O42 - Logiciel: Firefox - (.Pas de propriétaire.) [HKLM] -- FirefoxFR
                O42 - Logiciel: Flash Player 9 Internet Explorer - (.Pas de propriétaire.) [HKLM] -- Flashplayer
                O42 - Logiciel: ForceHCResetOnResume 1.1.0 - (.FIC, Inc..) [HKLM] -- ForceHCResetOnResume 1.1.0_is1
                O42 - Logiciel: Google Desktop - (.Google.) [HKLM] -- Google Desktop
                O42 - Logiciel: Guitar Pro 5.0 - (.Arobas Music.) [HKLM] -- Guitar Pro 5_is1
                O42 - Logiciel: Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) - (.Microsoft Corporation.) [HKLM] -- {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB953595
                O42 - Logiciel: Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) - (.Microsoft Corporation.) [HKLM] -- {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB958484
                O42 - Logiciel: Infocentre Rev. 2.0 - (.Pas de propriétaire.) [HKLM] -- Infocentre
                O42 - Logiciel: Magic Sports - (.Pas de propriétaire.) [HKLM] -- MagicSports
                O42 - Logiciel: MagicSports 3.5 - (.Pas de propriétaire.) [HKLM] -- {5927AF0D-335C-41D6-937B-54587EBD6D2C}
                O42 - Logiciel: Malwarebytes' Anti-Malware version 1.51.1.1800 - (.Malwarebytes Corporation.) [HKLM] -- Malwarebytes' Anti-Malware_is1
                O42 - Logiciel: Microsoft .NET Framework 1.1 - (.Pas de propriétaire.) [HKLM] -- Microsoft .NET Framework 1.1 (1033)
                O42 - Logiciel: Microsoft .NET Framework 1.1 Security Update (KB2416447) - (.Pas de propriétaire.) [HKLM] -- M2416447
                O42 - Logiciel: Microsoft .NET Framework 3.5 SP1 - (.Microsoft Corporation.) [HKLM] -- Microsoft .NET Framework 3.5 SP1
                O42 - Logiciel: Microsoft .NET Framework 4 Client Profile - (.Microsoft Corporation.) [HKLM] -- Microsoft .NET Framework 4 Client Profile
                O42 - Logiciel: Microsoft Office 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}
                O42 - Logiciel: Microsoft Office 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-0015-040C-0000-0000000FF1CE}_PROPLUS_{AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
                O42 - Logiciel: Microsoft Office 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-0016-040C-0000-0000000FF1CE}_PROPLUS_{AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
                O42 - Logiciel: Microsoft Office 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-0018-040C-0000-0000000FF1CE}_PROPLUS_{AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
                O42 - Logiciel: Microsoft Office 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-0019-040C-0000-0000000FF1CE}_PROPLUS_{AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
                O42 - Logiciel: Microsoft Office 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-001A-040C-0000-0000000FF1CE}_PROPLUS_{AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
                O42 - Logiciel: Microsoft Office 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-001B-040C-0000-0000000FF1CE}_PROPLUS_{AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
                O42 - Logiciel: Microsoft Office 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-0044-040C-0000-0000000FF1CE}_PROPLUS_{AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
                O42 - Logiciel: Microsoft Office 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-006E-040C-0000-0000000FF1CE}_PROPLUS_{B165D3C2-40AE-4D39-86F7-E5C87C4264C0}
                O42 - Logiciel: Microsoft Office Professional Plus 2007 - (.Microsoft Corporation.) [HKLM] -- PROPLUS
                O42 - Logiciel: Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-001F-0401-0000-0000000FF1CE}_PROPLUS_{14809F99-C601-4D4A-9391-F1E8FAA964C5}
                O42 - Logiciel: Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-001F-0407-0000-0000000FF1CE}_PROPLUS_{A0516415-ED61-419A-981D-93596DA74165}
                O42 - Logiciel: Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-001F-0409-0000-0000000FF1CE}_PROPLUS_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}
                O42 - Logiciel: Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-001F-040C-0000-0000000FF1CE}_PROPLUS_{F580DDD5-8D37-4998-968E-EBB76BB86787}
                O42 - Logiciel: Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-001F-0413-0000-0000000FF1CE}_PROPLUS_{D66D5A44-E480-4BA4-B4F2-C554F6B30EBB}
                O42 - Logiciel: Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) - (.Microsoft.) [HKLM] -- {90120000-001F-0C0A-0000-0000000FF1CE}_PROPLUS_{187308AB-5FA7-4F14-9AB9-D290383A10D9}
                O42 - Logiciel: Microsoft Works 9 SE - (.Pas de propriétaire.) [HKLM] -- works9se
                O42 - Logiciel: Module linguistique Microsoft .NET Framework 3.5 SP1- fra - (.Microsoft Corporation.) [HKLM] -- Microsoft .NET Framework 3.5 Language Pack SP1 - fra
                O42 - Logiciel: Module linguistique Microsoft .NET Framework 4 Client Profile FRA - (.Microsoft Corporation.) [HKLM] -- Microsoft .NET Framework 4 Client Profile FRA Language Pack
                O42 - Logiciel: Mozilla Firefox 6.0.2 (x86 fr) - (.Mozilla.) [HKLM] -- Mozilla Firefox 6.0.2 (x86 fr)
                O42 - Logiciel: NVIDIA Drivers - (.Pas de propriétaire.) [HKLM] -- NVIDIA Drivers
                O42 - Logiciel: Norton 360 - (.Pas de propriétaire.) [HKLM] -- N360_2007_FR
                O42 - Logiciel: Packard Bell ImageWriter - (.Pas de propriétaire.) [HKLM] -- ImageWriter
                O42 - Logiciel: Packard Bell LCD Test - (.Pas de propriétaire.) [HKLM] -- LCDTest
                O42 - Logiciel: Packard Bell Updator - (.Pas de propriétaire.) [HKLM] -- Updator
                O42 - Logiciel: Picasa2 - (.Pas de propriétaire.) [HKLM] -- Picasa_2
                O42 - Logiciel: QMC - (.Pas de propriétaire.) [HKCU] -- QUICKMEDIACONVERTER
                O42 - Logiciel: RealPlayer - (.RealNetworks.) [HKLM] -- RealPlayer 6.0
                O42 - Logiciel: Realtek Card Reader Monitor - (.Realtek Semiconductor Corp..) [HKLM] -- {D4210CB1-A469-41AF-A619-C97B07FDF6FD}
                O42 - Logiciel: Realtek USB 2.0 Card Reader - (.Realtek Semiconductor Corp..) [HKLM] -- {DC24971E-1946-445D-8A82-CE685433FA7D}
                O42 - Logiciel: Security Update for 2007 Microsoft Office System (KB2288621) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{5C497F0B-2061-4CC9-A61C-6B45B867354D}
                O42 - Logiciel: Security Update for 2007 Microsoft Office System (KB2288931) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{CD769337-C8AC-46DB-A7DC-643E50089263}
                O42 - Logiciel: Security Update for 2007 Microsoft Office System (KB2345043) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{536FB502-775F-4494-BACE-C02CC90B7A5B}
                O42 - Logiciel: Security Update for 2007 Microsoft Office System (KB2509488) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{AD0DE453-0804-4495-9C91-33D0F9AA5463}
                O42 - Logiciel: Security Update for 2007 Microsoft Office System (KB969559) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{69F52148-9BF6-4CDC-BF76-103DEAF3DD08}
                O42 - Logiciel: Security Update for 2007 Microsoft Office System (KB976321) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{7F207DCA-3399-40CB-A968-6E5991B1421A}
                O42 - Logiciel: Security Update for CAPICOM (KB931906) - (.Microsoft Corporation.) [HKLM] -- KB931906
                O42 - Logiciel: Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473) - (.Microsoft Corporation.) [HKLM] -- {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB2416473
                O42 - Logiciel: Security Update for Microsoft Office 2007 System (KB2541012) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{CD907315-705A-4475-A1A0-2A1245803E4D}
                O42 - Logiciel: Security Update for Microsoft Office Access 2007 (KB979440) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{1142CCEC-ACA9-484B-BA90-C3A5CA1988C5}
                O42 - Logiciel: Security Update for Microsoft Office Access 2007 (KB979440) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{5A4E43D5-858F-49BD-BA72-8F30E1793060}
                O42 - Logiciel: Security Update for Microsoft Office Excel 2007 (KB2541007) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{A0173254-F442-4D04-9154-43FA157B83D0}
                O42 - Logiciel: Security Update for Microsoft Office InfoPath 2007 (KB2510061) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{5D930261-AA5B-48D1-931F-425C9D767490}
                O42 - Logiciel: Security Update for Microsoft Office InfoPath 2007 (KB979441) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{1109D0B3-EFA3-4553-AAED-4C3E9AD130E8}
                O42 - Logiciel: Security Update for Microsoft Office InfoPath 2007 (KB979441) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{8CCB781A-CF6B-4FCB-B6D8-59C64DF5C6DB}
                O42 - Logiciel: Security Update for Microsoft Office PowerPoint 2007 (KB2535818) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{8588DD11-6BD7-4400-B55C-DD5AB74B43E1}
                O42 - Logiciel: Security Update for Microsoft Office PowerPoint Viewer 2007 (KB2464623) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{D75E6D0C-BADF-4F41-98B2-0C0F02C15062}
                O42 - Logiciel: Security Update for Microsoft Office Publisher 2007 (KB2284697) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{3A4CDE54-2403-483D-8D9A-15E3264410DF}
                O42 - Logiciel: Security Update for Microsoft Office Visio Viewer 2007 (KB973709) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{71127777-8B2C-4F97-AF7A-6CF8CAC8224D}
                O42 - Logiciel: Security Update for Microsoft Office Word 2007 (KB2344993) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{7A5B74FA-7A92-4FC9-821A-2DD5D4E73E48}
                O42 - Logiciel: Security Update for Microsoft Office system 2007 (972581) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{3D019598-7B59-447A-80AE-815B703B84FF}
                O42 - Logiciel: Security Update for Microsoft Office system 2007 (KB974234) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{FCD742B9-7A55-44BC-A776-F795F21FEDDC}
                O42 - Logiciel: SetUp My PC - (.Pas de propriétaire.) [HKLM] -- SETUPMYPC_FR
                O42 - Logiciel: Shockwave player 10 - (.Pas de propriétaire.) [HKLM] -- Shockwave
                O42 - Logiciel: Skype 3.2.2.163 - (.Pas de propriétaire.) [HKLM] -- SKYPE
                O42 - Logiciel: Sony Picture Utility - (.Sony Corporation.) [HKLM] -- {D5068583-D569-468B-9755-5FBF5848F46F}
                O42 - Logiciel: Sony USB Driver - (.Sony Corporation.) [HKLM] -- {5C29CB8B-AC1E-4114-8D68-9CD080140D4A}
                O42 - Logiciel: Synaptics Pointing Device Driver - (.Synaptics.) [HKLM] -- SynTPDeinstKey
                O42 - Logiciel: Update for 2007 Microsoft Office System (KB967642) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}
                O42 - Logiciel: Update for Microsoft .NET Framework 3.5 SP1 (KB963707) - (.Microsoft Corporation.) [HKLM] -- {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB963707
                O42 - Logiciel: Update for Microsoft Office 2007 (KB2508958) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{0C5823AA-7B6F-44E1-8D5B-8FD1FF0E6438}
                O42 - Logiciel: Update for Microsoft Office 2007 System (KB2539530) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{0B4CEEAE-AA88-490C-BCB2-AAC3421981A4}
                O42 - Logiciel: Update for Microsoft Office Outlook 2007 (KB2509470) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{1365864D-4C58-489D-9982-844D75691CCC}
                O42 - Logiciel: Update for Outlook 2007 Junk Email Filter (KB2586924) - (.Microsoft.) [HKLM] -- {90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{3B65DCBC-61EC-4578-9DF2-40D3B3829CD8}
                O42 - Logiciel: VLC media player 0.9.2 - (.VideoLAN Team.) [HKLM] -- VLC media player

                ---\\ HKCU & HKLM Software Keys
                [HKCU\Software\7-Zip]
                [HKCU\Software\ABBYY]
                [HKCU\Software\Ad-Remover]
                [HKCU\Software\Adobe]
                [HKCU\Software\AppDataLow\Software\Google]
                [HKCU\Software\AppDataLow\Software\Microsoft]
                [HKCU\Software\AppDataLow\Software]
                [HKCU\Software\AppDataLow]
                [HKCU\Software\Apple Computer, Inc.]
                [HKCU\Software\Astro_PC]
                [HKCU\Software\Avira]
                [HKCU\Software\BitTorrent]
                [HKCU\Software\CISRA]
                [HKCU\Software\Canon]
                [HKCU\Software\Classes]
                [HKCU\Software\Clients]
                [HKCU\Software\CocoonSoftware]
                [HKCU\Software\CyberLink]
                [HKCU\Software\DT Soft]
                [HKCU\Software\DivXNetworks]
                [HKCU\Software\EPSON]
                [HKCU\Software\Google]
                [HKCU\Software\IM Providers]
                [HKCU\Software\JavaSoft]
                [HKCU\Software\Local AppWizard-Generated Applications]
                [HKCU\Software\Macromedia]
                [HKCU\Software\Malwarebytes' Anti-Malware]
                [HKCU\Software\MicroVision]
                [HKCU\Software\MimarSinan]
                [HKCU\Software\MozillaPlugins]
                [HKCU\Software\Mozilla]
                [HKCU\Software\NVIDIA Corporation]
                [HKCU\Software\Netscape]
                [HKCU\Software\ODBC]
                [HKCU\Software\PAW-Software]
                [HKCU\Software\PC SOFT]
                [HKCU\Software\Packard Bell]
                [HKCU\Software\Pinnacle Systems]
                [HKCU\Software\Piriform]
                [HKCU\Software\Policies]
                [HKCU\Software\RealNetworks]
                [HKCU\Software\Roxio]
                [HKCU\Software\SEIKO EPSON]
                [HKCU\Software\Skype]
                [HKCU\Software\Sonic]
                [HKCU\Software\Sony Corporation]
                [HKCU\Software\Synaptics]
                [HKCU\Software\Trolltech]
                [HKCU\Software\Usbfix]
                [HKCU\Software\VOB]
                [HKCU\Software\Western Digital]
                [HKCU\Software\YahooPartnerToolbar]
                [HKCU\Software\keyhole.com]
                [HKLM\Software\ABBYY]
                [HKLM\Software\Adobe]
                [HKLM\Software\AdwCleaner]
                [HKLM\Software\Apple Computer, Inc.]
                [HKLM\Software\Arobas Music]
                [HKLM\Software\Avira]
                [HKLM\Software\Bison WebCam]
                [HKLM\Software\BitTorrent]
                [HKLM\Software\CISRA]
                [HKLM\Software\Canon]
                [HKLM\Software\Classes]
                [HKLM\Software\Clients]
                [HKLM\Software\Conexant Systems Inc ]
                [HKLM\Software\Conexant]
                [HKLM\Software\Creative Tech]
                [HKLM\Software\CyberLink]
                [HKLM\Software\DT Soft]
                [HKLM\Software\Debug]
                [HKLM\Software\DivX]
                [HKLM\Software\EPSON]
                [HKLM\Software\FAST Multimedia]
                [HKLM\Software\Google]
                [HKLM\Software\InstallShield]
                [HKLM\Software\InstalledOptions]
                [HKLM\Software\Intel]
                [HKLM\Software\JavaSoft]
                [HKLM\Software\JreMetrics]
                [HKLM\Software\Macromedia]
                [HKLM\Software\Malwarebytes' Anti-Malware]
                [HKLM\Software\Maxicours]
                [HKLM\Software\MicroVision]
                [HKLM\Software\MimarSinan]
                [HKLM\Software\MozillaPlugins]
                [HKLM\Software\Mozilla]
                [HKLM\Software\NEC Computers International]
                [HKLM\Software\NVIDIA Corporation]
                [HKLM\Software\ODBC]
                [HKLM\Software\PB_EBAY]
                [HKLM\Software\PB_FIRSTCHOICE]
                [HKLM\Software\PB_KODAK]
                [HKLM\Software\Pegasus Imaging]
                [HKLM\Software\PegasusImaging]
                [HKLM\Software\Pinnacle Systems]
                [HKLM\Software\Piriform]
                [HKLM\Software\Policies]
                [HKLM\Software\RealNetworks]
                [HKLM\Software\Realtek Semiconductor Corp.]
                [HKLM\Software\Realtek USB 2.0 Card Reader]
                [HKLM\Software\RegisteredApplications]
                [HKLM\Software\RichFX]
                [HKLM\Software\Roxio]
                [HKLM\Software\SONY PVC]
                [HKLM\Software\Skype]
                [HKLM\Software\Sonic]
                [HKLM\Software\Sony Corporation]
                [HKLM\Software\SymNRT]
                [HKLM\Software\Symantec]
                [HKLM\Software\Synaptics]
                [HKLM\Software\Thomson]
                [HKLM\Software\Trolltech]
                [HKLM\Software\VideoLAN]
                [HKLM\Software\Windows]
                [HKLM\Software\X-AVCSD]
                [HKLM\Software\Xing Technology Corp.]
                [HKLM\Software\ZSMC]
                [HKLM\Software\illiminable]
                [HKLM\Software\mozilla.org]
                ~ Scan Softwares in 00mn 01s

                ---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43)
                O43 - CFD: 10/09/2011 - 20:10:56 - [3511045] ----D- C:\Program Files\7-Zip
                O43 - CFD: 23/04/2009 - 16:47:08 - [124428627] ----D- C:\Program Files\ABBYY FineReader 6.0 Sprint
                O43 - CFD: 10/09/2011 - 20:19:56 - [233777836] ----D- C:\Program Files\Ad-Remover
                O43 - CFD: 10/09/2011 - 19:32:18 - [116541972] ----D- C:\Program Files\Adobe
                O43 - CFD: 04/02/2009 - 23:13:38 - [2221118] ----D- C:\Program Files\Apple Software Update
                O43 - CFD: 10/09/2011 - 19:04:10 - [147870792] ----D- C:\Program Files\Avira
                O43 - CFD: 11/11/2010 - 22:53:56 - [117239804] ----D- C:\Program Files\Canon
                O43 - CFD: 11/09/2011 - 19:17:50 - [4068448] ----D- C:\Program Files\CCleaner
                O43 - CFD: 10/09/2011 - 19:54:44 - [650263325] ----D- C:\Program Files\Common Files
                O43 - CFD: 01/01/2007 - 04:56:50 - [1319392] ----D- C:\Program Files\CONEXANT
                O43 - CFD: 01/01/2007 - 05:17:16 - [82427735] ----D- C:\Program Files\CyberLink
                O43 - CFD: 28/12/2008 - 16:14:12 - [9364182] ----D- C:\Program Files\DAEMON Tools Lite
                O43 - CFD: 31/08/2008 - 21:42:12 - [422720] ----D- C:\Program Files\DNA
                O43 - CFD: 23/04/2009 - 16:48:54 - [137723229] ----D- C:\Program Files\epson
                O43 - CFD: 15/06/2008 - 13:59:18 - [0] -SH-D- C:\Program Files\Fichiers communs
                O43 - CFD: 01/01/2007 - 04:58:28 - [2210798] ----D- C:\Program Files\ForceHCResetOnResume
                O43 - CFD: 09/06/2011 - 13:04:58 - [108025162] ----D- C:\Program Files\Google
                O43 - CFD: 01/07/2008 - 23:11:40 - [378438812] ----D- C:\Program Files\Guitar Pro 5
                O43 - CFD: 01/01/2007 - 05:07:04 - [1944017] ----D- C:\Program Files\HDReg
                O43 - CFD: 11/11/2010 - 22:56:34 - [72169019] --H-D- C:\Program Files\InstallShield Installation Information
                O43 - CFD: 11/09/2011 - 15:41:24 - [7063912] ----D- C:\Program Files\Internet Explorer
                O43 - CFD: 31/08/2008 - 10:25:30 - [14146977] ----D- C:\Program Files\Inventel
                O43 - CFD: 10/09/2011 - 20:00:58 - [89518792] ----D- C:\Program Files\Java
                O43 - CFD: 06/05/2009 - 10:38:52 - [7097890454] ---AD- C:\Program Files\MAGIX
                O43 - CFD: 11/09/2011 - 21:32:16 - [6963191] ----D- C:\Program Files\Malwarebytes' Anti-Malware
                O43 - CFD: 10/01/2009 - 00:04:56 - [706627] ----D- C:\Program Files\Microsoft
                O43 - CFD: 10/09/2008 - 21:40:10 - [800662] ----D- C:\Program Files\Microsoft CAPICOM 2.1.0.2
                O43 - CFD: 02/11/2006 - 14:37:36 - [93446071] ----D- C:\Program Files\Microsoft Games
                O43 - CFD: 09/09/2011 - 14:39:08 - [587392738] ----D- C:\Program Files\Microsoft Office
                O43 - CFD: 28/12/2008 - 16:35:04 - [14904] ----D- C:\Program Files\Microsoft Visual Studio
                O43 - CFD: 28/12/2008 - 16:31:00 - [1387249] ----D- C:\Program Files\Microsoft Visual Studio 8
                O43 - CFD: 17/12/2010 - 12:19:34 - [146453974] ----D- C:\Program Files\Microsoft Works
                O43 - CFD: 11/09/2011 - 17:47:10 - [8167779] ----D- C:\Program Files\Microsoft.NET
                O43 - CFD: 11/09/2011 - 11:57:00 - [99342446] ----D- C:\Program Files\Movie Maker
                O43 - CFD: 10/09/2011 - 18:28:14 - [40516665] ----D- C:\Program Files\Mozilla Firefox
                O43 - CFD: 28/12/2008 - 16:35:44 - [26521] ----D- C:\Program Files\MSBuild
                O43 - CFD: 26/06/2008 - 00:26:48 - [0] ----D- C:\Program Files\MSXML 4.0
                O43 - CFD: 10/09/2011 - 19:18:46 - [194902] ----D- C:\Program Files\Orange
                O43 - CFD: 04/09/2008 - 21:38:44 - [64522830] ----D- C:\Program Files\Packard Bell
                O43 - CFD: 12/05/2009 - 19:41:34 - [1062897002] ----D- C:\Program Files\Pinnacle
                O43 - CFD: 06/10/2010 - 16:26:30 - [80563271] ----D- C:\Program Files\QuickMediaConverter
                O43 - CFD: 04/02/2009 - 23:15:44 - [77199116] ----D- C:\Program Files\QuickTime
                O43 - CFD: 28/04/2009 - 10:03:54 - [41461400] ----D- C:\Program Files\Real
                O43 - CFD: 01/01/2007 - 05:01:42 - [660088] ----D- C:\Program Files\Realtek Semiconductor Corp
                O43 - CFD: 02/11/2006 - 14:37:36 - [38694657] ----D- C:\Program Files\Reference Assemblies
                O43 - CFD: 01/01/2007 - 05:15:06 - [74182375] ----D- C:\Program Files\Roxio
                O43 - CFD: 31/08/2008 - 10:32:36 - [38412056] ----D- C:\Program Files\Securitoo
                O43 - CFD: 01/01/2007 - 05:28:54 - [28983845] ----D- C:\Program Files\Skype
                O43 - CFD: 12/05/2009 - 20:30:54 - [66713433] ----D- C:\Program Files\Sony
                O43 - CFD: 01/01/2007 - 04:58:38 - [13544008] ----D- C:\Program Files\Synaptics
                O43 - CFD: 02/11/2006 - 15:01:56 - [0] --H-D- C:\Program Files\Uninstall Information
                O43 - CFD: 22/09/2008 - 17:33:32 - [49968262] ----D- C:\Program Files\VideoLAN
                O43 - CFD: 11/09/2011 - 11:57:02 - [1016832] ----D- C:\Program Files\Windows Calendar
                O43 - CFD: 11/09/2011 - 11:56:58 - [2737152] ----D- C:\Program Files\Windows Collaboration
                O43 - CFD: 11/09/2011 - 11:56:40 - [4490624] ----D- C:\Program Files\Windows Defender
                O43 - CFD: 11/09/2011 - 11:56:56 - [7084664] ----D- C:\Program Files\Windows Journal
                O43 - CFD: 08/03/2009 - 09:26:16 - [2922760] ----D- C:\Program Files\Windows Live
                O43 - CFD: 11/09/2011 - 14:27:10 - [9116344] ----D- C:\Program Files\Windows Mail
                O43 - CFD: 11/09/2011 - 11:56:58 - [4498121] ----D- C:\Program Files\Windows Media Player
                O43 - CFD: 15/06/2008 - 13:59:18 - [7957544] ----D- C:\Program Files\Windows NT
                O43 - CFD: 11/09/2011 - 11:56:56 - [13528738] ----D- C:\Program Files\Windows Photo Gallery
                O43 - CFD: 11/09/2011 - 14:27:24 - [134144] ----D- C:\Program Files\Windows Portable Devices
                O43 - CFD: 11/09/2011 - 11:56:58 - [7610938] ----D- C:\Program Files\Windows Sidebar
                O43 - CFD: 13/09/2011 - 00:02:52 - [6606990] ----D- C:\Program Files\ZHPDiag
                O43 - CFD: 10/09/2011 - 19:33:14 - [3606170] ----D- C:\Program Files\Common Files\Adobe
                O43 - CFD: 28/12/2008 - 16:35:04 - [92976] ----D- C:\Program Files\Common Files\DESIGNER
                O43 - CFD: 01/01/2007 - 05:16:48 - [18347339] ----D- C:\Program Files\Common Files\InstallShield
                O43 - CFD: 10/09/2011 - 19:54:44 - [1258951] ----D- C:\Program Files\Common Files\Java
                O43 - CFD: 10/09/2011 - 08:22:32 - [437525765] ----D- C:\Program Files\Common Files\microsoft shared
                O43 - CFD: 12/05/2009 - 19:41:42 - [401408] ----D- C:\Program Files\Common Files\Pegasus Imaging
                O43 - CFD: 12/05/2009 - 19:49:32 - [3385947] ----D- C:\Program Files\Common Files\Pinnacle
                O43 - CFD: 28/04/2009 - 10:03:58 - [20359414] ----D- C:\Program Files\Common Files\Real
                O43 - CFD: 01/01/2007 - 05:14:54 - [65562642] ----D- C:\Program Files\Common Files\Roxio Shared
                O43 - CFD: 02/11/2006 - 13:18:34 - [2702] ----D- C:\Program Files\Common Files\Services
                O43 - CFD: 01/01/2007 - 05:28:52 - [1828440] ----D- C:\Program Files\Common Files\Skype
                O43 - CFD: 01/01/2007 - 05:14:54 - [3925552] ----D- C:\Program Files\Common Files\Sonic Shared
                O43 - CFD: 02/11/2006 - 13:18:34 - [41101735] ----D- C:\Program Files\Common Files\SpeechEngines
                O43 - CFD: 01/01/2007 - 05:15:08 - [595968] ----D- C:\Program Files\Common Files\SureThing Shared
                O43 - CFD: 10/09/2011 - 18:56:56 - [475064] ----D- C:\Program Files\Common Files\Symantec Shared
                O43 - CFD: 11/09/2011 - 11:56:48 - [42800134] ----D- C:\Program Files\Common Files\System
                O43 - CFD: 09/01/2009 - 13:52:50 - [8324015] ----D- C:\Program Files\Common Files\Windows Live
                O43 - CFD: 28/04/2009 - 10:04:00 - [352256] ----D- C:\Program Files\Common Files\xing shared
                O43 - CFD: 12/05/2009 - 19:41:36 - [316847] ----D- C:\Program Files\Common Files\Yahoo!
                O43 - CFD: 11/09/2011 - 18:51:54 - [128654334] ----D- C:\ProgramData\Adobe
                O43 - CFD: 04/02/2009 - 23:13:36 - [2083840] ----D- C:\ProgramData\Apple
                O43 - CFD: 04/02/2009 - 23:14:44 - [27953664] ----D- C:\ProgramData\Apple Computer
                O43 - CFD: 02/11/2006 - 15:02:04 - [0] -SH-D- C:\ProgramData\Application Data
                O43 - CFD: 10/09/2011 - 19:04:10 - [55170472] ----D- C:\ProgramData\Avira
                O43 - CFD: 15/06/2008 - 13:59:18 - [0] -SH-D- C:\ProgramData\Bureau
                O43 - CFD: 01/01/2007 - 05:17:22 - [4197] ----D- C:\ProgramData\CyberL
                0
                1. Contributeur sécurité
                  Tu as vacciné déjà :)

                  Sinon, pour ouvrir le gestionnaire des tâches de Windows, tu fais Ctrl + Alt + Suppr

                  Refais moi un dernier ZHPdiag :)

                  Merci,

                  Gabriel.
                  0
                  1. salut
                    et voici
                    merci
                    A+
                    Cloud9

                    ############################## | UsbFix 7.058 | [Suppression]

                    Utilisateur: GREGORY (Administrateur) # LILIE [PACKARD BELL BV EasyNote_SJ81]
                    Mis à jour le 24/08/2011 par El Desaparecido
                    Lancé à 21:08:52 | 12/09/2011
                    Site Web: http://www.teamxscript.org
                    Submit your sample: http://www.teamxscript.org/Upload.php
                    Contact: contact@eldesaparecido.com

                    CPU: AMD Turion(tm) 64 X2 Mobile Technology TL-56
                    CPU 2: AMD Turion(tm) 64 X2 Mobile Technology TL-56
                    Microsoft® Windows Vista(TM) Édition Familiale Premium (6.0.6002 32-Bit) # Service Pack 2
                    Internet Explorer 9.0.8112.16421

                    Pare-feu Windows: Activé
                    RAM -> 2046 Mo
                    C:\ (%systemdrive%) -> Disque fixe # 141 Go (59 Go libre(s) - 42%) [HDD] # NTFS
                    D:\ -> CD-ROM
                    E:\ -> Disque amovible # 15 Go (2 Go libre(s) - 10%) [TRANSCEND] # FAT32
                    F:\ -> Disque fixe # 149 Go (60 Go libre(s) - 40%) [My Passport] # NTFS

                    ################## | Éléments infectieux |

                    Supprimé! C:\$RECYCLE.BIN\S-1-5-21-2152478756-3922319563-605102323-500
                    Supprimé! C:\$RECYCLE.BIN\S-1-5-21-2477963207-3090536540-4185239906-1002
                    Supprimé! C:\$RECYCLE.BIN\S-1-5-21-2477963207-3090536540-4185239906-1003
                    Supprimé! C:\$RECYCLE.BIN\S-1-5-21-2782973499-3522194488-1966776676-500
                    Supprimé! F:\$RECYCLE.BIN\S-1-5-21-1324848523-584337988-2581472049-1000
                    Supprimé! F:\Recycler\S-1-5-21-1645522239-484061587-725345543-1004
                    Supprimé! F:\Recycler\S-1-5-21-1801674531-1482476501-839522115-1003
                    Supprimé! F:\Recycler\S-1-5-21-2025429265-1844823847-839522115-1003
                    Supprimé! F:\Recycler\S-1-5-21-2416500018-651348643-142639809-1007
                    Supprimé! F:\Recycler\S-1-5-21-2847713566-3520705556-496475513-1005
                    Supprimé! F:\Recycler\S-1-5-21-2847713566-3520705556-496475513-1006
                    Supprimé! F:\Recycler\S-1-5-21-507921405-1935655697-839522115-1004
                    Supprimé! F:\Recycler\S-1-5-21-602162358-117609710-725345543-1003
                    Supprimé! F:\Recycler\S-1-5-21-602162358-117609710-725345543-1005
                    Supprimé! F:\Recycler\S-1-5-21-602162358-117609710-725345543-1006
                    Supprimé! F:\Recycler\S-1-5-21-790525478-879983540-725345543-1003

                    ################## | Registre |

                    ################## | Mountpoints2 |

                    Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\F
                    Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\K
                    Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{1ee90fc2-8238-11dd-90a3-df1613d78815}
                    Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{5d6d1532-d4e9-11dd-8c7b-00140b403047}
                    Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{8aa4e042-0ab8-11df-ba16-0015af528927}
                    Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{9898cf25-d545-11e0-b12c-00140b403047}
                    Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{af1b55bd-2a60-11de-a2db-00140b403047}

                    ################## | Listing |

                    [12/09/2011 - 21:10:23 | SHD ] C:\$Recycle.Bin
                    [24/09/2008 - 14:08:21 | D ] C:\5f492ed263d6d095e263aad324e179f5
                    [11/11/2010 - 10:57:13 | D ] C:\9f43da6fc95607a9a41f4ff0fd6cfd1b
                    [18/09/2006 - 23:43:36 | N | 24] C:\autoexec.bat
                    [11/09/2011 - 12:07:48 | D ] C:\boot
                    [11/04/2009 - 08:36:36 | RASH | 333257] C:\bootmgr
                    [01/01/2007 - 12:38:11 | N | 8192] C:\BOOTSECT.BAK
                    [18/09/2006 - 23:43:37 | N | 10] C:\config.sys
                    [02/11/2006 - 15:02:03 | SHD ] C:\Documents and Settings
                    [12/05/2009 - 20:41:49 | D ] C:\drivers
                    [30/09/2008 - 17:18:02 | N | 0] C:\IO.SYS
                    [30/09/2008 - 17:18:02 | N | 0] C:\MSDOS.SYS
                    [28/12/2008 - 16:28:16 | RHD ] C:\MSOCache
                    [12/09/2011 - 19:50:15 | ASH | 2460160000] C:\pagefile.sys
                    [24/09/2008 - 12:47:14 | D ] C:\PerfLogs
                    [12/09/2011 - 08:56:56 | N | 512] C:\PhysicalDisk0_MBR.bin
                    [11/09/2011 - 19:55:37 | D ] C:\Program Files
                    [10/09/2011 - 20:34:02 | HD ] C:\ProgramData
                    [10/09/2011 - 22:48:07 | D ] C:\Recycled
                    [12/09/2011 - 19:45:35 | SHD ] C:\System Volume Information
                    [12/09/2011 - 21:10:23 | D ] C:\UsbFix
                    [12/09/2011 - 21:08:54 | A | 3740] C:\UsbFix.txt
                    [08/10/2008 - 14:58:45 | D ] C:\Users
                    [12/09/2011 - 20:30:21 | D ] C:\Windows
                    [12/09/2011 - 19:45:39 | D ] C:\ZHP
                    [20/05/2011 - 19:27:20 | D ] E:\.Trashes
                    [20/05/2011 - 19:27:20 | N | 4096] E:\._.Trashes
                    [20/05/2011 - 19:28:30 | N | 6148] E:\.DS_Store
                    [15/02/2011 - 22:09:00 | D ] E:\films
                    [19/03/2011 - 14:20:06 | D ] E:\Auto_Entreprise
                    [19/03/2011 - 14:20:24 | D ] E:\perso
                    [19/03/2011 - 14:20:36 | D ] E:\programmes-pilotes
                    [23/02/2010 - 18:03:10 | N | 4750321] E:\la mer m'a parle.mp3
                    [22/03/2011 - 18:07:14 | RASHD ] E:\Autorun.inf
                    [19/05/2011 - 20:22:06 | D ] E:\Siemens-Paris
                    [09/06/2011 - 10:12:06 | N | 1120] E:\custam.txt
                    [09/06/2011 - 11:11:52 | D ] E:\desinfection
                    [11/06/2011 - 14:11:22 | D ] E:\salia
                    [17/06/2011 - 13:01:42 | N | 51132808] E:\avira_antivir_personal_free.exe
                    [17/06/2011 - 17:01:10 | N | 528] E:\MediaID.bin
                    [05/08/2011 - 19:50:08 | N | 134642] E:\info formationIC2011.pdf
                    [09/08/2011 - 23:18:06 | N | 896554] E:\info formationIC20112.jpg
                    [09/08/2011 - 23:22:52 | N | 483567] E:\formation-IC.jpg
                    [12/09/2011 - 21:10:23 | SHD ] F:\$RECYCLE.BIN
                    [03/06/2011 - 20:46:56 | D ] F:\Archives
                    [03/06/2011 - 20:11:14 | D ] F:\Boulot
                    [14/10/2010 - 00:00:55 | D ] F:\Danses trad
                    [19/06/2011 - 22:23:28 | D ] F:\films
                    [03/06/2011 - 20:37:52 | D ] F:\Mes Images
                    [12/09/2011 - 21:10:23 | SHD ] F:\RECYCLER
                    [12/06/2011 - 12:18:04 | D ] F:\scan-virus
                    [19/06/2011 - 20:19:52 | SHD ] F:\System Volume Information
                    [31/10/2010 - 17:32:07 | ASH | 9216] F:\Thumbs.db
                    [16/06/2011 - 12:42:00 | D ] F:\Utilitaires

                    ################## | Vaccin |

                    C:\Autorun.inf -> Vaccin créé par UsbFix (TeamXscript)
                    E:\Autorun.inf -> Vaccin créé par UsbFix (TeamXscript)
                    F:\Autorun.inf -> Vaccin créé par UsbFix (TeamXscript)

                    ################## | Upload |

                    Veuillez envoyer le fichier: C:\UsbFix_Upload_Me_LILIE.zip
                    http://www.teamxscript.org/Upload.php
                    Merci de votre contribution.

                    ################## | E.O.F |
                    0
                    1. salut
                      1--comment je vaccine mes supports ?
                      et
                      2--comment quand je n'ai plus d'icônes sur le bureau
                      j'ai accès au gestionnaire de taches ?
                      merci pour tout
                      cloud9
                      0
                      1. Contributeur sécurité
                        Passe le en mode suppression, poste le rapport. Ensuite, vaccine tes supports :)

                        @+

                        Gabriel.
                        0
                        1. Salut Gabriel
                          voici le lien que tu me demandes
                          http://www.cijoint.fr/cjlink.php?file=cj201109/cijuYrC5Mq.txt

                          merci encore
                          bonne soirée
                          j'attends que tu me dise la suite
                          Cloud9
                          0
                          1. Contributeur sécurité
                            Salut,

                            Oui c'est normal, mais sache que tu pouvais via le gestionnaire eds taches, récupérer ton bureau, je vais le rajouter tiens :)

                            Pour vérification, on va scanner tes supports :)

                            - Télécharge UsbFix (créé par El Desaparecido & C_XX) sur ton Bureau : http://www.teamxscript.org/usbfixTelechargement.html Si ton antivirus affiche une alerte, ignore la et désactive l'antivirus temporairement.
                            - Branche toutes tes sources de données externes à ton PC (clé USB, disque dur externe, etc...) sans les ouvrir
                            - Double clique sur le raccourci UsbFix sur ton Bureau, l'installation se fera automatiquement.
                            - Clique sur "Recherche".
                            - Laisse travailler l'outil.
                            - À la fin du scan, un rapport va s'afficher : post-le dans ta prochaine réponse sur le forum (il est aussi sauvegardé a la racine du disque dur).

                            @+

                            Gabriel.
                            0
                            1. Salut
                              voici le rapport que tu me demandes
                              à la fin il n'y avait plus d'icônes sur le bureau
                              seulement l'image de fonds
                              j'ai été obligé de le forcer à s'éteindre pour le rallumer ensuite
                              est ce que c'est normal docteur ???
                              en tout cas merci pour ton aide
                              j'attends que tu me dises si la désinfection est finie
                              merci encore bonne soirée
                              Cloud9

                              Rapport de ZHPFix 1.12.3360 par Nicolas Coolman, Update du 29/08/2011
                              Fichier d'export Registre :
                              Run by GREGORY at 12/09/2011 19:45:38
                              Windows Vista Home Premium Edition, 32-bit Service Pack 2 (Build 6002)
                              Web site : http://www.premiumorange.com/zeb-help-process/zhpfix.html

                              ========== Clé(s) du Registre ==========
                              SUPPRIME CLSID MPSK: {4f455e3f-7879-11df-8971-00140b403047}
                              SUPPRIME CLSID MPSK: {5a6e106e-83d7-11dd-b2ac-00140b403047}
                              SUPPRIME CLSID MPSK: {5b3dd243-9ffd-11df-8b8b-00140b403047}
                              SUPPRIME CLSID MPSK: {667634cb-73ca-11e0-90ef-00140b403047}
                              SUPPRIME CLSID MPSK: {7a75f23b-8420-11dd-b38f-00140b403047}
                              SUPPRIME CLSID MPSK: {c7ed9ce0-fd58-11de-9fb8-00140b403047}
                              SUPPRIME CLSID MPSK: {d5a2678f-f8f4-11dd-9dca-00140b403047}
                              SUPPRIME CLSID MPSK: {e47b861e-437a-11dd-ad2b-0015af528927}
                              SUPPRIME CLSID MPSK: {6c0e11ec-81f7-11e0-94d8-00140b403047}
                              SUPPRIME CLSID MPSK: {91068fa0-e1c2-11de-8813-00140b403047}
                              SUPPRIME O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\75125337.sys . (...) -- C:\Windows\system32\Drivers\75125337.sys (.not file.)
                              SUPPRIME O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\75125337.sys . (...) -- C:\Windows\system32\Drivers\75125337.sys (.not file.)

                              ========== Dossier(s) ==========
                              SUPPRIME Temporaires Windows: : 68

                              ========== Fichier(s) ==========
                              ABSENT File: c:\windows\system32\drivers\75125337.sys
                              ABSENT Folder/File: c:\users\gregory\appdata\roaming\mozilla\firefox\profiles\e67htkl9.default\user.js (.not file.)
                              SUPPRIME Temporaires Windows: : 26

                              ========== Restauration Système ==========
                              Point de restauration du système créé avec succès

                              ========== Autre ==========
                              NON TRAITE EmtyFlash

                              ========== Récapitulatif ==========
                              12 : Clé(s) du Registre
                              1 : Dossier(s)
                              3 : Fichier(s)
                              1 : Restauration Système
                              1 : Autre

                              End of the scan in 00mn 29s

                              ========== Chemin de fichier rapport ==========
                              C:\ZHP\ZHPFix[R1].txt - 12/09/2011 19:45:38 [1895]
                              0
                              1. Contributeur sécurité
                                Bien :)

                                >Copie les lignes "helpers" (Avec Ctrl + C) présentes dans le fichier texte : http://dl.dropbox.com/u/32869654/Pour%20cloud9.txt

                                >Ouvre ZHPfix, icone seringue (Vista et 7 : "Exécuter en tant qu'administrateur").
                                >Colle les lignes helpers : Pour ce, clique sur la balise document, à droite de l'appareil photo. Ou alors sur le H.
                                >Faire Ok.
                                >Clique sur "Tous".
                                >Clique sur "Nettoyer".
                                >Copie le rapport, et coller-le dans la prochaine réponse sur le forum.

                                Si tu as des questions, n'hésite pas à me les poser !

                                @+

                                Gabriel.
                                0
                                1. bonjour,
                                  voici le rapport que tu me demandes
                                  http://www.cijoint.fr/cjlink.php?file=cj201109/cijfJJ7j65.txt

                                  j'attends tes instructions
                                  c'est toi qui me diras si c'est fini ou pas
                                  en attendant je te remercie infiniment
                                  bonne journée
                                  Cloud9
                                  0
                                  1. Contributeur sécurité
                                    Ok :)

                                    Refais un ZHPdiag STP ;)

                                    Merci,

                                    Gabriel.
                                    0
                                    1. bonsoir
                                      voici le rapport demandé
                                      j'attends la suite de tes instructions,
                                      en attendant bonne nuit !
                                      et merci beaucoup

                                      Malwarebytes' Anti-Malware 1.51.1.1800
                                      www.malwarebytes.org

                                      Version de la base de données: 7696

                                      Windows 6.0.6002 Service Pack 2
                                      Internet Explorer 9.0.8112.16421

                                      11/09/2011 23:10:39
                                      mbam-log-2011-09-11 (23-10-39).txt

                                      Type d'examen: Examen complet (C:\|D:\|)
                                      Elément(s) analysé(s): 302877
                                      Temps écoulé: 1 heure(s), 32 minute(s), 41 seconde(s)

                                      Processus mémoire infecté(s): 0
                                      Module(s) mémoire infecté(s): 0
                                      Clé(s) du Registre infectée(s): 0
                                      Valeur(s) du Registre infectée(s): 0
                                      Elément(s) de données du Registre infecté(s): 0
                                      Dossier(s) infecté(s): 0
                                      Fichier(s) infecté(s): 0

                                      Processus mémoire infecté(s):
                                      (Aucun élément nuisible détecté)

                                      Module(s) mémoire infecté(s):
                                      (Aucun élément nuisible détecté)

                                      Clé(s) du Registre infectée(s):
                                      (Aucun élément nuisible détecté)

                                      Valeur(s) du Registre infectée(s):
                                      (Aucun élément nuisible détecté)

                                      Elément(s) de données du Registre infecté(s):
                                      (Aucun élément nuisible détecté)

                                      Dossier(s) infecté(s):
                                      (Aucun élément nuisible détecté)

                                      Fichier(s) infecté(s):
                                      (Aucun élément nuisible détecté)
                                      0
                                      1. Contributeur sécurité
                                        Salut,

                                        Redémarre le PC puis :

                                        ATTENTION ! Plusieurs heures de scan sont probables !

                                        Télécharge Malwarebytes' Anti-Malware MBAMsur ton bureau : http://www.malwarebytes.org/mbam/program/mbam-setup.exe

                                        Si problème essaie avec celui-ci : https://www.commentcamarche.net/telecharger/securite/14361-malwarebytes-anti-malware/

                                        . Enregistre-le sur ton bureau.
                                        . Double clique sur le fichier téléchargé pour lancer le processus d'installation. (Vista et 7 : Éxécuter en tant qu'administrateur)
                                        . Si le pare-feu demande l'autorisation de se connecter pour malwarebytes, accepte.
                                        . Dans l'onglet "Mise à jour", clique sur le bouton "Recherche de mise à jour".

                                        Fais le plusieurs fois jusqu'à ce qu'il te dise que tu as la dernière version de base de données.

                                        . Une fois la mise à jour terminée :
                                        . Rends-toi dans l'onglet "Recherche"
                                        . Sélectionne Exécuter un Examen complet.
                                        . Sélectionne Tous les disques si proposé.
                                        . Clique sur Rechercher.
                                        . Le scan démarre. Patiente, cela peut durer plusieurs heures, selon la taille de tes disques.
                                        . À la fin de l'analyse, un message s'affiche : L'examen s'est terminé normalement ou autre. Clique sur "Afficher les résultats" pour afficher tous les objets trouvés.
                                        . Cliques sur Ok pour poursuivre.
                                        . Si des malwares ont été détectés<souligne>, clique sur Afficher les résultats.
                                        . <souligne>Sélectionne tout
                                        (ou laisse coché) et clique sur Supprimer la sélection, Malwarebytes va détruire les fichiers et clés de registre et en mettre une copie dans la quarantaine.
                                        . Malwarebytes va ouvrir le bloc-notes et y copier le rapport d'analyse.
                                        . Redemarre le PC si il le fait pas lui même.
                                        . Une fois redémarré double-clique sur Malwarebytes' AntiMalware.
                                        . Rends toi dans l'onglet "rapport/log".
                                        . Tu cliques sur le rapport pour l'afficher.
                                        . Tu cliques sur Edition en haut du boc notes,et puis sur Sélectionner tout.
                                        . Tu recliques sur Edition et puis sur Copier et tu reviens sur le forum et dans ta réponse, colle le rapport (CTRL + V).

                                        => Si tu as besoin d'aide regarde ce tutoriel :

                                        https://www.malekal.com/tutoriel-malwarebyte-anti-malware/

                                        Si tu as des questions, n'hésite pas à me les poser !

                                        @+

                                        Gabriel.
                                        0
                                        • 1
                                        • 2