Security sphere 2012

Résolu
Bonsoir,

Je suis actuellement infectée par ce virus. Je recherche une solution. Si quelqu'un veut bien se dévouer pour venir à mon aide, j'accepterai avec joie.

Merci d'avance !

28 réponses

Résumé de la discussion

Infection par un virus sur un PC équipé de Windows XP et Safari 535.1, avec une demande d’aide pour identifier les menaces et trouver une solution efficace. Des mesures essentielles pour nettoyer l’ordinateur incluent TDSSKiller pour un éventuel rootkit, AdwCleaner pour la suppression de malwares et Ad-Remover pour nettoyer les entrées système. Ensuite, un examen complet avec Malwarebytes est recommandé et, le cas échéant, relancer ZHPDiag pour générer un nouveau rapport à transmettre ensuite par un lien de téléchargement. Des précautions consistent à réactiver l’antivirus, effectuer les mises à jour Windows et désinstaller les extensions suspectes identifiées lors des scans, afin de prévenir de nouvelles intrusions et renforcer la sécurité globale.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    bonjour, pourrais tu nous poster un zhpdiag pour avoir un état des l'infections et de pouvoir les identifier toutes !! merci

    Ouvre ce lien et télécharge ZHPDiag :

    https://www.zebulon.fr/telechargements/securite/systeme/zhpdiag.html

    cliques sur télécharger "celui du bas"

    ou directement ici: ftp://zebulon.fr/ZHPDiag2.exe

    Enregistres le sur ton Bureau.

    Une fois le téléchargement achevé

    pour XP, double-clique sur ZHPDiag

    pour Vista,et seven tu fais un clic droit sur l'icône et exécute en tant qu'administrateur.

    N'oublies pas de cocher la case qui permet de mettre un raccourci sur le Bureau.

    /|\ l'outil a créé 2 icônes ZHPDiag et ZHPFix.

    Double cliques sur le raccourci ZHPDiag sur ton Bureau pour XP sinon clique droit et en tant que administrateur !!

    Cliques sur la loupe pour lancer l'analyse.

    si tu as un message te demandant la validation pour SIGCHECK acceptes avec OK cela est pour nous faire un rapport plus complet et pouvoir en faire une lecture plus approfondis

    Laisses l'outil travailler, il peut être assez long

    A la fin de l'analyse,clique sur l'appareil photo et enregistre le rapport sur ton Bureau.

    Fermes ZHPDiag en fin d'analyse.

    Pour me le transmettre clique sur ce lien :

    http://www.cijoint.fr/index.php

    Clique sur Parcourir et cherche le fichier C:\Documents and settings\le_nom_de_ta_session\bureau\.ZHPDiag.txt

    ou directement en choisissant bureau et ZHPDiag.txt clique dessus

    Clique sur Ouvrir.

    Clique sur "Cliquez ici pour déposer le fichier".

    Un lien de cette forme :

    http://www.cijoint.fr/cjlink.php?file=cj200905/cib7SU.txt

    est ajouté dans la page.

    Copie ce lien dans ta réponse.

    et si problème passe par celui ci : https://www.cjoint.com/
    Perso je ne sais peut être pas grand chose, mais si le peu que je sais p­eut aider et bien,
    je veux bien le partager avec toi !!
    1. Bonjour,
      Déja merci pour cette aide précieuse, et ce sujet récent.
      J'ai été infecté il y a quelques jours par ce logiciel, et suis venue sur ce site.
      J'aimerais savoir si je peux reproduire exactement à la lettre tout ce qui est écrit, notamment les textes et lignes à copier, ou les textes à mettre sur les notes
      (Je m'excuse si je ne suis pas claire)

      Merci d'avance
      1. Contributeur sécurité
        anne.lise bonjour le mieux est d'ouvrir un sujet et de poster un zhpdiag , car si tu coipes les ligne donnés pour supprimer avec zhpfix tu prend des risque car elle sont lié au pc et pas au tien !!!
      2. http://cjoint.com/?ALrqlwKrsQW

        J'ai téléchargé Malwarebytes, a la fin du scan il notait 1 fichier infecté qui a été mis en quarantaine, mais lorsque j'ai redémarré mon pc en mode normal le logiciel security sphere 2012 était toujours présent
      3. merci
        désolé de ne pas la'voir fait plus tot
    2. Voilà j'ai tout fais !
      1. Contributeur sécurité
        ok si plus de problèmes tu puge la restauration système et puis mets ton sujet en résolu https://www.commentcamarche.net/infos/25917-marquer-un-fil-de-discussion-comme-etant-resolu/

        Après une désinfection il est utile de supprimer tous les points de restauration système de façon à ne pas remonter, par mégarde, un point de restauration infecté.

        Pour cela, il faut désactiver la restauration système (ce qui aura pour conséquence de supprimer tous les points de restauration existants) puis la réactiver juste après pour que Windows continue à faire des points de sauvegarde réguliers.

        Supprimer les anciens points de restauration : System Volume Information\_restore

        (1) Désactiver la Restauration du système

        cliques sur Démarrer
        Cliques droit sur Poste de travail
        cliques sur Propriétés
        Cliques sur l'onglet Restauration du système
        Coches Désactiver la Restauration du système sur tous les lecteurs
        Cliques sur Appliquer, Lorsque le message de confirmation apparaît,
        cliques sur Oui.
        Cliques sur OK.

        (2) Activer la Restauration du système

        cliques sur Démarrer
        Cliques droit sur Poste de travail
        cliques sur Propriétés
        Cliques sur l'onglet Restauration du système
        Décoches Désactiver la Restauration du système sur tous les lecteurs
        Cliques sur Appliquer, Lorsque le message de confirmation apparaît,
        cliques sur Oui.
        Cliques sur OK.
      2. Merci beaucoup pour ton aide et ton temps ! J'ai enfin retrouvé mon PC d'avant :)
    3. # DelFix v8.5 - Rapport créé le 08/10/2011 à 09:53:33
      # Mis à jour le 25/09/11 à 11h par Xplode
      # Système d'exploitation : Microsoft Windows XP Service Pack 3 (32 bits)
      # Nom d'utilisateur : Mr OZCAN - OZCAN-61D1365FC (Administrateur)
      # Exécuté depuis : C:\Documents and Settings\Mr OZCAN\Mes documents\Downloads\delfix0.exe
      # Option [Suppression]

      ~~~~~~ Dossiers(s) ~~~~~~

      Supprimé : C:\Qoobox
      Supprimé : C:\_OTM
      Supprimé : C:\Kill'em
      Supprimé : C:\ZHP
      Supprimé : C:\Documents and Settings\All Users\Menu Démarrer\Programmes\ZHP
      Supprimé : C:\Program Files\Ad-Remover
      Supprimé : C:\Program Files\Navilog1
      Supprimé : C:\Program Files\ZHPDiag

      ~~~~~~ Fichier(s) ~~~~~~

      Supprimé : C:\Ad-Report-CLEAN[1].txt
      Supprimé : C:\AdwCleaner[S1].txt
      Supprimé : C:\cleannavi.txt
      Supprimé : C:\ComboFix.txt
      Supprimé : C:\PhysicalDisk0_MBR.bin
      Supprimé : C:\rkill.log
      Supprimé : C:\UsbFix_Upload_Me_OZCAN-61D1365FC.zip
      Supprimé : C:\ZHPExportRegistry-01-12-2010-16-05-24.txt
      Supprimé : C:\ZHPExportRegistry-23-11-2010-17-14-34.txt
      Supprimé : C:\ZHPExportRegistry-28-11-2010-17-27-36.txt
      Supprimé : C:\ZHPExportRegistry-28-11-2010-17-31-35.txt
      Supprimé : C:\Documents and Settings\Mr OZCAN\Bureau\Ad-Remover.lnk
      Supprimé : C:\Documents and Settings\Mr OZCAN\Bureau\ComboFix.exe
      Supprimé : C:\Documents and Settings\Mr OZCAN\Bureau\Defogger.exe
      Supprimé : C:\Documents and Settings\Mr OZCAN\Bureau\defogger_disable.log
      Supprimé : C:\Documents and Settings\Mr OZCAN\Bureau\defogger_enable.log
      Supprimé : C:\Documents and Settings\Mr OZCAN\Bureau\Pre_scan.exe
      Supprimé : C:\Documents and Settings\Mr OZCAN\Bureau\Pre_Scan_05_10_2011_13_31_22.txt
      Supprimé : C:\Documents and Settings\Mr OZCAN\Bureau\Pre_Script.exe
      Supprimé : C:\Documents and Settings\Mr OZCAN\Bureau\Pre_script.txt
      Supprimé : C:\Documents and Settings\Mr OZCAN\Bureau\ZHPDiag.txt
      Supprimé : C:\Documents and Settings\Mr OZCAN\Bureau\ZHPDiag2.txt
      Supprimé : C:\Documents and Settings\Mr OZCAN\Bureau\ZHPFixReport.txt
      Supprimé : C:\Documents and Settings\Mr OZCAN\Mes documents\Downloads\AD-R.exe
      Supprimé : C:\Documents and Settings\Mr OZCAN\Mes documents\Downloads\adwcleaner0.exe
      Supprimé : C:\Documents and Settings\Mr OZCAN\Mes documents\Downloads\Reload_Tdsskiller.exe
      Supprimé : C:\Documents and Settings\Mr OZCAN\Mes documents\Downloads\ZHPDiag2.exe
      Supprimé : C:\Documents and Settings\All Users\Bureau\ZHPDiag.lnk
      Supprimé : C:\Documents and Settings\All Users\Bureau\ZHPFix.lnk
      Supprimé : C:\Documents and Settings\All Users\Bureau\MBRCheck.lnk
      Supprimé : C:\WINDOWS\grep.exe
      Supprimé : C:\WINDOWS\PEV.exe
      Supprimé : C:\WINDOWS\NIRCMD.exe
      Supprimé : C:\WINDOWS\MBR.exe
      Supprimé : C:\WINDOWS\SED.exe
      Supprimé : C:\WINDOWS\SWREG.exe
      Supprimé : C:\WINDOWS\SWSC.exe
      Supprimé : C:\WINDOWS\SWXCACLS.exe
      Supprimé : C:\WINDOWS\Zip.exe

      ~~~~~~ Registre ~~~~~~

      Clé Supprimée : HKCU\Software\Ad-Remover
      Clé Supprimée : HKCU\Software\g3n-h@ckm@n
      Clé Supprimée : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Ad-Remover
      Clé Supprimée : HKLM\SOFTWARE\OldTimer Tools
      Clé Supprimée : HKLM\SOFTWARE\AdwCleaner
      Clé Supprimée : HKLM\SOFTWARE\Swearware
      Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ZHPDiag_is1
      Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\combofix.exe

      ~~~~~~ Autres ~~~~~~

      -> Prefetch Vidé

      *************************

      DelFix[S1].txt - [3423 octets] - [08/10/2011 09:53:33]

      ########## EOF - C:\DelFix[S1].txt - [3547 octets] ##########
      1. Je ne vois rien d'anormal ! Tout se passe bien. On va pouvoir passer à la dernière étape ? ;)
        1. Contributeur sécurité
          ok pourrais tu poster un dernier zhpdiag pour voire , merci !!
        2. http://www.cijoint.fr/cjlink.php?file=cj201110/cijl5hJCzf.txt
        3. Contributeur sécurité
          bonjour, tu me fais le zhpfix et puis plus de problèmes on finalise !!

          . Copie les lignes suivantes en GRAS entre les deux lignes

          __________________________________________________________

          R3 - URLSearchHook: (no name) - {472734EA-242A-422b-ADF8-83D1E48CC825} . (...) (No version) -- (.not file.) => Fichier absent
          OPT:O4 - HKLM\..\Run: [QuickTime Task] . (.Apple Inc. - QuickTime Task.) -- C:\Program Files\QuickTime\qttask.exe
          OPT:O4 - HKCU\..\Run: [ctfmon.exe] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\ctfmon.exe
          OPT:O4 - HKUS\S-1-5-21-746137067-842925246-839522115-1004\..\Run: [ctfmon.exe] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\ctfmon.exe
          O42 - Logiciel: Softonic_France Toolbar - (.Softonic_France.) [HKLM] -- Softonic_France Toolbar => Toolbar.Conduit
          [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Softonic_France Toolbar] => Toolbar.Conduit
          SysRestore
          FirewallRAZ
          EmptyFlash
          EmptyTemp
          HostFix

          ___________________________________________________________________


          . Lance ZHPFix de Nicolas Coolman qui se trouve sur ton bureau
          . Pour XP, double-clique sur ZHPFix
          . pour Vista et seven, faire un clic droit sur l'icône et exécute en tant qu'administrateur.
          . Clique sur l'icone représentant la lettre H (« coller les lignes Helper »)

          Dans l'encadré principal tu verras donc les lignes que tu as copié précédemment apparaitrent .

          Vérifie que toutes les lignes que je t'ai demandé de copier (et seulement elles) sont dans la fenêtre.

          PS: si rien ne se colle clique sur l'icône en haut sur gauche celui juste à côté de l'appareil photos " coller le presse papier"

          !! Déconnecte toi, désactive tes défenses (anti-virus, anti-spyware ) et ferme bien toutes autres applications ( navigateurs compris ) !!

          . cliques sur OK
          . Clique sur « Tous », puis sur « Nettoyer »
          . Copie/colle la totalité du rapport dans ta prochaine réponse
          tu le trouveras dans le dossier de zhpdiag dans program files sous le nom de ZHPFixReport
        4. ?
        5. Contributeur sécurité
          ok si plus de problèmes tu passes delfix pour supprimer les outils et rapports , et puis tu fais la mises à jour de java et un nettoyage avec ccleaner !

          1) - DelFix - Option Suppression

          Télécharge DelFix (d'Xplode)

          Lance le puis sélectionne Suppression

          Copie/colle le contenu du rapport qui s'ouvrira à l'écran dans ton prochain message.

          Note : Le rapport est également sauvegardé à la racine du disque dur ( C:\DelFixSuppr.txt )

          Une fois le rapport posté sur le forum, relance DelFix en sélectionnant Désinstallation.

          2) désinstalles java car pas à jour et installes cette version

          https://www.java.com/fr/download/

          3) fais un nettoyage avec ccleaner et les réglages donnés

          télécharges Ccleaner à partir de cette adresses

          https://www.commentcamarche.net/telecharger/utilitaires/5647-ccleaner/

          .enregistres le sur le bureau
          .double-cliques si sous XP sinon pour vista et seven clique droit et en tant que administrateur sur le fichier pour lancer l'installation
          .sur la fenêtre de l'installation langage bien choisir français et OK
          .cliques sur suivant
          .lis la licence et j'accepte
          .cliques sur suivant
          .la tu ne gardes de coché que mettre un raccourci sur le bureau et puis contrôler automatiquement les mises à jour de Ccleaner

          ATTENTION refuse l'installation de tous ce qui est google si pas intéressé !!

          .cliques sur intaller
          .cliques sur fermer
          .double-cliques sur l'icône de Ccleaner pour l'ouvrir
          .une fois ouvert tu cliques sur option et puis avancé
          .tu décoches effacer uniquement les fichiers, du dossier temp de windows plus vieux que 24 heures
          .cliques sur nettoyeur
          .cliques sur windows et dans la colonne avancé
          .cochesla première case vieilles données du perfetch que celle-la
          .cliques sur analyse une fois l'analyse terminé
          .cliques sur lancer le nettoyage et sur la demande de confirmation OK il vas falloir que tu le refasses une autre fois une fois fini vériffis en appuiant de nouveau sur analyse pour être sur qu'il n'y est plus rien
          .cliques maintenant sur registre et puis sur rechercher les erreurs
          .laisses tout cochées et cliques sur réparrer les erreurs sélectionnées
          .il te demande de sauvegarder OUI
          .tu lui donnes un nom pour pouvoir la retrouver et enregistre
          .cliques sur corriger toutes les erreurs sélectionnées et sur la demande de confirmation OK
          .il supprime et fermer tu vériffis en relancant rechercher les erreurs
          .tu retournes dans option et tu recoches la case effacer uniquement les fichiers, du dossier temp de windows plus vieux que 24 heures et sur nettoyeur, windows sous avancé tu décoches la première case vieilles données du perfetch
          .tu peux fermer Ccleaner

          pour aider si besion tutoriel: https://www.vulgarisation-informatique.com/nettoyer-windows-ccleaner.php
      2. ok Jacques je t'avance :

        @haveaproblem :

        fais glisser une icone n'importe quel fichier sur Pre_scan , pre_script va apparaitre

        Lance Pre_script , une page vierge va s'ouvrir.

        selectionne tout le texte en gras ci-dessous, puis (clic droit/copier ou ctrl+c) :
        ___________________________________________________
        uninst::
        Softonic_France Toolbar

        Registry::
        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
        "QuickTime Task"=-
        [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\NeroFilterCheck]
        [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\259c194c-96ab-412f-b755-52ef156fd5b8]
        [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\3fc80187-bbb7-4e22-90e5-4d68c02c23ee]
        [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\991e9f70-6405-4c8d-8fd7-df3ca7387100]
        [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\af65c4b7-3796-45a7-bb43-ce39df826e72]
        [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\c0d3c77b-62ef-4913-b84d-7ebeb6b370a5]
        [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\fe1636ad-5226-488b-ac28-f4a58eba3475]
        [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EAFBBCD5-5127-44C0-9E0A-0BEA2DCB4761}]
        [-HKEY_CURRENT_USER\Software\Softonic_France]
        [-HKEY_LOCAL_MACHINE\Software\Softonic_France]
        [HKEY_LOCAL_MACHINE\System\CurrentControlSet\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
        "1900:UDP"=-
        "2869:TCP"=-

        File::
        C:\pcwords.dat
        C:\pcwords2.dat
        C:\pc_sign.slf
        C:\WINDOWS\432039893
        C:\Documents and Settings\Mr OZCAN\tmp1.2
        C:\Documents and Settings\Mr OZCAN\Application Data\qvjsge.dat

        Folder::
        C:\1171f38372693b901a1f
        C:\1eee66ccaeea881870250125042ef9
        C:\74de456a652bdf49d0f58090a4
        C:\d02ea8c4036999978b
        C:\eb1974373d80f471332c13ed
        C:\ecab45daa32a105147e416d080
        C:\f44189f6b54cece92e3e3acbb0
        C:\WINDOWS\432039893
        C:\Documents and Settings\Mr OZCAN\tmp1.2
        C:\Documents and Settings\Mr OZCAN\Local Settings\Application Data\ewyyud
        C:\Documents and Settings\Mr OZCAN\Local Settings\Application Data\Softonic_France
        C:\Program Files\Softonic_France

        attrib

        ___________________________________________________

        colle-le ensuite (clic droit/coller ou ctrl+V) dans la page vierge.

        puis onglet fichier => enregistrer (pas enregistrer sous...) , puis ferme le texte

        des fenetres noires risquent de clignoter , c'est normal , c'est le programme qui travaille

        poste le contenu du rapport qui s'ouvrira

        si ton bureau ne reapparait pas => ctrl+alt+supp , gestionnaire des taches => onglet fichier => nouvelle tache puis tape explorer
        1. Contributeur sécurité
          bonjour, merci à gen pour son intervention toujours au taquer ce gen !!

          bon comment va le pc suite à tous cela , merci
      3. moi il me bloqué tout et me redémarrer l'o
        rdi toutes les cinq minutes!
        1. bonjour spybot ne vaut pas un clou et cette desinfection est largement prise en charge :)
        2. slt! je suis loin d'être calé comme ceux qui t'aident mais je me suis dit que ça pourrais aider qq! c tt moi spybot me la virer SS pblm mais ça a pris du temps! bon courage!
        3. tu travailles pour spybot ou quoi ?
      4. alors il faut redémarrer et démarrer en mode sans échec tu lance spybot et voila! pour moi c t ça!
        si tu n'as pas spybot tu redémarre en mode sans échec mais avec prise en charge du réseau puis tu le télécharge et tu l'installe et tu le lance après un fois fois le virus supprimé tu redémarre normalement ! j'espère que j'ai pu t'aider
        1. ComboFix 11-10-03.01 - Mr OZCAN 03/10/2011 17:08:43.3.2 - x86
          Microsoft Windows XP Édition familiale 5.1.2600.3.1252.33.1036.18.958.583 [GMT 2:00]
          Lancé depuis: c:\documents and settings\Mr OZCAN\Bureau\ComboFix.exe
          Commutateurs utilisés :: c:\documents and settings\Mr OZCAN\Bureau\CFScript.txt
          AV: Microsoft Security Essentials *Disabled/Updated* {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
          AV: Microsoft Security Essentials *Enabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
          .
          FILE ::
          "c:\windows\SET167.tmp"
          "c:\windows\SET16A.tmp"
          "c:\windows\SET176.tmp"
          .
          .
          (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
          .
          .
          c:\documents and settings\All Users\ab05cc
          c:\documents and settings\All Users\ab05cc\RTab0_5608.exe
          c:\documents and settings\All Users\Application Data\iC04902KiFbH04902
          c:\documents and settings\All Users\Application Data\iC04902KiFbH04902\iC04902KiFbH04902
          c:\documents and settings\All Users\Application Data\nL04903JhMbD04903
          c:\documents and settings\All Users\Application Data\nL04903JhMbD04903\nL04903JhMbD04903
          c:\windows\SET167.tmp
          c:\windows\SET16A.tmp
          c:\windows\SET176.tmp
          .
          .
          ((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
          .
          .
          -------\Service_bqlrssbz
          .
          .
          ((((((((((((((((((((((((((((( Fichiers créés du 2011-09-03 au 2011-10-03 ))))))))))))))))))))))))))))))))))))
          .
          .
          2011-10-02 09:57 . 2011-10-02 09:57 -------- d-----w- c:\documents and settings\Mr OZCAN\Local Settings\Application Data\PCHealth
          2011-09-30 23:13 . 2011-09-30 23:13 -------- d-----w- c:\program files\Ad-Remover
          2011-09-30 22:08 . 2011-10-02 18:02 512 ----a-w- C:\PhysicalDisk0_MBR.bin
          2011-09-30 22:05 . 2011-10-02 18:02 -------- d-----w- C:\ZHP
          2011-09-30 22:05 . 2011-10-02 18:02 -------- d-----w- c:\program files\ZHPDiag
          2011-09-30 17:08 . 2011-09-30 18:26 -------- d-----w- c:\program files\PC Tools Security
          2011-09-30 17:08 . 2011-09-30 18:26 -------- d-----w- c:\program files\Fichiers communs\PC Tools
          2011-09-30 17:08 . 2011-09-30 18:25 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
          2011-09-30 17:02 . 2011-09-30 18:24 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Tools
          2011-09-30 16:32 . 2011-09-30 16:32 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Temp
          2011-09-30 16:32 . 2011-09-30 16:32 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
          2011-09-29 16:56 . 2007-03-08 04:20 16496 ----a-r- c:\windows\system32\drivers\HPZipr12.sys
          2011-09-29 16:56 . 2007-03-08 04:20 49920 ----a-r- c:\windows\system32\drivers\HPZid412.sys
          2011-09-29 14:13 . 2011-09-29 14:13 56200 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{39E1CE63-7175-4AB1-A8D3-8049F714EDEA}\offreg.dll
          2011-09-25 07:04 . 2011-09-12 23:14 7269712 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{39E1CE63-7175-4AB1-A8D3-8049F714EDEA}\mpengine.dll
          2011-09-16 14:17 . 2007-03-08 04:20 21568 ----a-r- c:\windows\system32\drivers\HPZius12.sys
          2011-09-13 16:31 . 2011-09-13 16:31 -------- d-----w- c:\windows\system32\config\systemprofile\Tracing
          2011-09-09 08:12 . 2011-06-23 18:31 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
          2011-09-09 08:12 . 2011-06-23 18:31 602112 -c----w- c:\windows\system32\dllcache\msfeeds.dll
          2011-09-09 08:12 . 2011-06-23 18:31 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll
          2011-09-09 08:12 . 2011-06-23 18:31 247808 -c----w- c:\windows\system32\dllcache\ieproxy.dll
          2011-09-09 08:12 . 2011-06-23 18:31 1991680 -c----w- c:\windows\system32\dllcache\iertutil.dll
          2011-09-09 08:12 . 2011-06-23 18:31 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll
          2011-09-09 08:12 . 2011-06-23 18:31 11081728 -c----w- c:\windows\system32\dllcache\ieframe.dll
          2011-09-09 07:47 . 2008-06-14 17:33 272768 -c----w- c:\windows\system32\dllcache\bthport.sys
          2011-09-09 07:46 . 2011-07-15 13:29 456320 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
          2011-09-09 07:40 . 2010-12-09 15:14 2194816 -c----w- c:\windows\system32\dllcache\ntoskrnl.exe
          2011-09-09 07:40 . 2010-12-09 15:14 2029056 -c----w- c:\windows\system32\dllcache\ntkrpamp.exe
          2011-09-09 07:40 . 2010-12-09 15:14 2150912 -c----w- c:\windows\system32\dllcache\ntkrnlmp.exe
          2011-09-09 07:40 . 2010-12-09 15:14 2071424 -c----w- c:\windows\system32\dllcache\ntkrnlpa.exe
          2011-09-08 15:01 . 2008-04-14 12:00 101888 -c--a-w- c:\windows\system32\dllcache\srusbusd.dll
          2011-09-08 15:00 . 2008-04-14 12:00 59392 -c--a-w- c:\windows\system32\dllcache\imscinst.exe
          2011-09-08 14:59 . 2003-03-24 13:52 20538 -c--a-w- c:\windows\system32\dllcache\fpremadm.exe
          2011-09-08 14:39 . 2001-08-17 18:13 27165 ----a-w- c:\windows\system32\drivers\fetnd5.sys
          2011-09-08 14:35 . 2008-04-14 12:00 24661 -c--a-w- c:\windows\system32\dllcache\spxcoins.dll
          2011-09-08 14:35 . 2008-04-14 12:00 24661 ----a-w- c:\windows\system32\spxcoins.dll
          2011-09-08 14:35 . 2008-04-14 12:00 13312 -c--a-w- c:\windows\system32\dllcache\irclass.dll
          2011-09-08 14:35 . 2008-04-14 12:00 13312 ----a-w- c:\windows\system32\irclass.dll
          2011-09-07 12:55 . 2011-09-07 12:55 -------- d-----r- c:\documents and settings\LocalService\Favoris
          2011-09-07 11:04 . 2011-09-07 11:05 -------- d-----w- c:\documents and settings\Administrateur.OZCAN-61D1365FC
          2011-09-07 10:04 . 2011-09-07 10:04 -------- d-----r- c:\documents and settings\NetworkService\Favoris
          2011-09-05 17:04 . 2011-09-05 17:04 183696 ----a-w- c:\program files\Mozilla Firefox\plugins\nppdf32.dll
          2011-09-05 17:04 . 2011-09-05 17:04 183696 ----a-w- c:\program files\Internet Explorer\Plugins\nppdf32.dll
          2011-09-04 21:16 . 2011-08-11 17:44 7152464 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Updates\mpengine.dll
          2011-09-03 17:31 . 2011-08-11 17:44 7152464 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
          .
          .
          .
          (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
          .
          2011-09-30 23:00 . 2008-04-14 12:00 66048 ----a-w- c:\windows\system32\drivers\serial.sys
          2011-09-17 10:12 . 2011-06-29 09:44 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
          2011-09-09 09:12 . 2008-04-14 12:00 606208 ----a-w- c:\windows\system32\crypt32.dll
          2011-08-31 15:00 . 2010-11-23 16:15 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
          2011-07-15 13:29 . 2008-04-14 12:00 456320 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
          2011-07-08 14:02 . 2008-04-14 12:00 10496 ----a-w- c:\windows\system32\drivers\ndistapi.sys
          2011-09-13 16:55 . 2011-04-06 13:41 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
          .
          .
          ((((((((((((((((((((((((((((( SnapShot_2011-10-02_09.48.27 )))))))))))))))))))))))))))))))))))))))))
          .
          + 2011-10-03 15:16 . 2011-10-03 15:16 16384 c:\windows\temp\Perflib_Perfdata_e0.dat
          .
          ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
          .
          .
          *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
          REGEDIT4
          .
          [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
          "msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2010-04-16 3872080]
          .
          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
          "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-05-09 7311360]
          "MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 997920]
          "SoundMan"="SOUNDMAN.EXE" [2007-04-16 577536]
          "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-11-10 417792]
          "VX3000"="c:\windows\vVX3000.exe" [2006-12-05 707360]
          .
          [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
          "msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2010-04-16 3872080]
          .
          [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
          "HonorAutoRunSetting"= 0 (0x0)
          .
          [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
          "HonorAutoRunSetting"= 0 (0x0)
          .
          [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
          "{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]
          .
          [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
          @="Service"
          .
          [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^HP Digital Imaging Monitor.lnk]
          path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\HP Digital Imaging Monitor.lnk
          backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
          .
          [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Windows Search.lnk]
          path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Windows Search.lnk
          backup=c:\windows\pss\Windows Search.lnkCommon Startup
          .
          [HKLM\~\startupfolder\C:^Documents and Settings^Mr OZCAN^Menu Démarrer^Programmes^Démarrage^Notification de cadeaux MSN.lnk]
          path=c:\documents and settings\Mr OZCAN\Menu Démarrer\Programmes\Démarrage\Notification de cadeaux MSN.lnk
          backup=c:\windows\pss\Notification de cadeaux MSN.lnkStartup
          .
          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
          2011-06-06 10:55 937920 ----a-w- c:\program files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe
          .
          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
          2006-11-16 17:04 139264 ----a-w- c:\program files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe
          .
          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
          2008-04-14 12:00 15360 ----a-w- c:\windows\system32\ctfmon.exe
          .
          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
          2011-06-06 15:45 136176 ----atw- c:\documents and settings\Mr OZCAN\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
          .
          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
          2007-03-11 19:34 49152 ----a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe
          .
          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LifeCam]
          2007-01-12 15:48 275800 ----a-w- c:\program files\Microsoft LifeCam\LifeExp.exe
          .
          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
          2008-04-14 02:34 1695232 ------w- c:\program files\Messenger\msmsgs.exe
          .
          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
          2006-01-12 13:40 155648 ----a-w- c:\program files\Fichiers communs\Ahead\Lib\NeroCheck.exe
          .
          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
          2006-05-09 14:50 86016 ----a-w- c:\windows\system32\nvmctray.dll
          .
          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
          2009-11-10 21:08 417792 ----a-w- c:\program files\QuickTime\QTTask.exe
          .
          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TomTomHOME.exe]
          2011-03-09 12:30 247728 ----a-w- c:\program files\TomTom HOME 2\TomTomHOMERunner.exe
          .
          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VTTimer]
          2010-02-18 15:19 53248 ----a-w- c:\windows\system32\VTTimer.exe
          .
          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VTTrayp]
          2010-02-18 15:19 176128 ----a-w- c:\windows\system32\VTTrayp.exe
          .
          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VX3000]
          2006-12-05 13:39 707360 ----a-w- c:\windows\vVX3000.exe
          .
          [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
          "%windir%\\system32\\sessmgr.exe"=
          "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
          "c:\\Program Files\\Messenger\\msmsgs.exe"=
          "c:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
          "c:\\WINDOWS\\pchealth\\helpctr\\binaries\\helpctr.exe"=
          "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
          "c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
          "c:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
          .
          R2 TomTomHOMEService;TomTomHOMEService;c:\program files\TomTom HOME 2\TomTomHOMEService.exe [09/03/2011 14:30 92592]
          S0 jekfznca;jekfznca; [x]
          S1 MpKsl3ebe2020;MpKsl3ebe2020;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{11661DA5-5298-4FC1-972A-2BCCA90CD684}\MpKsl3ebe2020.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{11661DA5-5298-4FC1-972A-2BCCA90CD684}\MpKsl3ebe2020.sys [?]
          S1 MpKslc6572dfc;MpKslc6572dfc;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{667BFE0C-2F90-45D0-AE20-FFD3301F595B}\MpKslc6572dfc.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{667BFE0C-2F90-45D0-AE20-FFD3301F595B}\MpKslc6572dfc.sys [?]
          S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18/03/2010 14:16 130384]
          S2 gupdate;Service Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [10/12/2009 20:11 135664]
          S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.Sys [06/03/2011 13:25 36608]
          S3 gupdatem;Service Google Update (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [10/12/2009 20:11 135664]
          S3 maconfservice;Ma-Config Service;c:\program files\ma-config.com\maconfservice.exe [26/01/2010 18:45 243056]
          S3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\windows\system32\drivers\mbamswissarmy.sys --> c:\windows\system32\drivers\mbamswissarmy.sys [?]
          S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18/03/2010 14:16 753504]
          .
          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
          HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
          hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
          .
          Contenu du dossier 'Tâches planifiées'
          .
          2011-09-28 c:\windows\Tasks\AppleSoftwareUpdate.job
          - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]
          .
          2011-10-03 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
          - c:\program files\Google\Update\GoogleUpdate.exe [2009-12-10 18:11]
          .
          2011-10-03 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
          - c:\program files\Google\Update\GoogleUpdate.exe [2009-12-10 18:11]
          .
          2011-09-28 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-746137067-842925246-839522115-1004Core.job
          - c:\documents and settings\Mr OZCAN\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-06-08 15:45]
          .
          2011-10-03 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-746137067-842925246-839522115-1004UA.job
          - c:\documents and settings\Mr OZCAN\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-06-08 15:45]
          .
          2011-10-01 c:\windows\Tasks\MP Scheduled Scan.job
          - c:\program files\Microsoft Security Client\Antimalware\MpCmdRun.exe [2011-04-27 13:39]
          .
          2011-10-03 c:\windows\Tasks\User_Feed_Synchronization-{8C734E8D-32B6-4C0C-999B-5C999564264D}.job
          - c:\windows\system32\msfeedssync.exe [2007-08-13 03:31]
          .
          .
          ------- Examen supplémentaire -------
          .
          uInternet Settings,ProxyServer = hxxp://127.0.0.1:8080
          uInternet Settings,ProxyOverride = *.local
          IE: Free YouTube to Mp3 Converter - c:\documents and settings\Mr OZCAN\Application Data\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
          IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.html
          TCP: DhcpNameServer = 212.27.40.240 212.27.40.241
          FF - ProfilePath - c:\documents and settings\Mr OZCAN\Application Data\Mozilla\Firefox\Profiles\to310717.default\
          FF - prefs.js: browser.search.selectedEngine - Bing
          FF - prefs.js: browser.startup.homepage - hxxp://www.google.fr/
          .
          .
          **************************************************************************
          .
          catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
          Rootkit scan 2011-10-03 17:18
          Windows 5.1.2600 Service Pack 3 NTFS
          .
          Recherche de processus cachés ...
          .
          Recherche d'éléments en démarrage automatique cachés ...
          .
          Recherche de fichiers cachés ...
          .
          Scan terminé avec succès
          Fichiers cachés: 0
          .
          **************************************************************************
          .
          --------------------- DLLs chargées dans les processus actifs ---------------------
          .
          - - - - - - - > 'explorer.exe'(3884)
          c:\program files\QuickTime\QTPlugin.ocx
          c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll
          c:\windows\system32\webcheck.dll
          c:\windows\system32\WPDShServiceObj.dll
          c:\windows\system32\PortableDeviceTypes.dll
          c:\windows\system32\PortableDeviceApi.dll
          c:\windows\system32\eappprxy.dll
          .
          ------------------------ Autres processus actifs ------------------------
          .
          c:\progra~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
          c:\program files\Java\jre6\bin\jqs.exe
          c:\program files\Microsoft LifeCam\MSCamS32.exe
          c:\windows\system32\SearchIndexer.exe
          c:\windows\SOUNDMAN.EXE
          .
          **************************************************************************
          .
          Heure de fin: 2011-10-03 17:19:32 - La machine a redémarré
          ComboFix-quarantined-files.txt 2011-10-03 15:19
          ComboFix2.txt 2011-10-02 09:51
          ComboFix3.txt 2011-09-08 16:01
          .
          Avant-CF: 215 688 171 520 octets libres
          Après-CF: 215 583 313 920 octets libres
          .
          - - End Of File - - 1F9861C846BDB72F0B3BA0191A5B1E61
          1. Contributeur sécurité
            ok postes un dernier zhpdiag et on pourras finaliser !!

            Double cliques sur le raccourci ZHPDiag sur ton Bureau pour XP sinon clique droit et en tant que administrateur !!

            Cliques sur la loupe pour lancer l'analyse.

            si tu as un message te demandant la validation pour SIGCHECK acceptes avec OK cela est pour nous faire un rapport plus complet et pouvoir en faire une lecture plus approfondis

            Laisses l'outil travailler, il peut être assez long

            A la fin de l'analyse,clique sur l'appareil photo et enregistre le rapport sur ton Bureau.

            Fermes ZHPDiag en fin d'analyse.

            Pour me le transmettre clique sur ce lien :

            http://www.cijoint.fr/index.php

            Clique sur Parcourir et cherche le fichier C:\Documents and settings\le_nom_de_ta_session\bureau\.ZHPDiag.txt

            ou directement en choisissant bureau et ZHPDiag.txt clique dessus

            Clique sur Ouvrir.

            Clique sur "Cliquez ici pour déposer le fichier".

            Un lien de cette forme :

            http://www.cijoint.fr/cjlink.php?file=cj200905/cib7SU.txt

            est ajouté dans la page.

            Copie ce lien dans ta réponse.

            et si problème passe par celui ci : https://www.cjoint.com/
          2. http://www.cijoint.fr/cjlink.php?file=cj201110/cijq3olOli.txt
          3. Contributeur sécurité
            ok merci , je vais voir le rapport , mais pourrais tu refaire un script combofix , car gen me signal un petit problèmes avec un drivers , et me demande de te le faire faire en mode sans echec , , donc tu fais cela

            PS: si tu as déjà un fichier texte CFScript sur le bureau tu supprimes afin d'éviter les conflits

            __________________________________________________
            =>/!\Le script qui suit a été écrit spécialement cet ordinateur/!\ <=
            =>il est fort déconseillé de le transposer sur un autre ordinateur !<=

            ----------------------------------------------------------------------------

            Toujours avec toutes les protections désactivées, fais ceci :

            ? Ouvre le bloc-notes (Menu démarrer --> programmes --> accessoires --> bloc-notes)
            ? Copie/colle dans le bloc-notes ce qui est entre les lignes en GRASci dessous (sans les lignes) :

            ----------------------------------------------------------

            Driver::
            jekfznca

            ------------------------------------------------------------------

            ? Enregistre ce fichier sur ton Bureau (et pas ailleurs !) sous le nom <gras>CFScript.txt

            ? Quitte le Bloc Notes

            REDÉMARRES EN MODE SANS ÉCHEC

            pour redémarrer en mode sans échec : /!\ Ne jamais démarrer en mode sans échec via MSCONFIG /!\

            (attention : pas de connexion possible en mode sans échec , donc copies ou imprimes bien la manipe pour éviter les erreurs ...)

            .Cliques sur Démarrer
            .Cliques sur Arrêter
            .Sélectionnes Redémarrer et au redémarrage
            .Appuis sur la touche F8 ou F5 celon les marques de pc sans discontinuer "1 appuis seconde" dès qu'un écran de texte apparaît puis disparaît
            .Utilises les touches de direction pour sélectionner mode sans échec
            .puis appuis sur ENTRÉE
            .Il faudra choisir ta session habituelle, pas le compte "Administrateur" ou une autre
            une fois démarré ne t'inquiette pas si les couleurs et les icônes ne sont pas comme d'abitude

            tuto:http://www.vista-xp.fr/forum/topic93.html

            une fois en mode sans echec tu fais comme expliqué

            ? Fais un glisser/déposer de ce fichier CFScript sur le fichier combofix

            ? Patiente le temps du scan. Le Bureau va disparaître à plusieurs reprises : c'est normal ! Ne touche à rien tant que le scan n'est pas terminé.
            ? Une fois le scan achevé, un rapport va s'afficher: poste son contenu.
            ? Si le fichier ne s'ouvre pas, il se trouve ici => C:\ComboFix.txt
          4. ComboFix 11-10-03.01 - Mr OZCAN 04/10/2011 18:35:19.4.2 - x86 MINIMAL
            Microsoft Windows XP Édition familiale 5.1.2600.3.1252.33.1036.18.958.716 [GMT 2:00]
            Lancé depuis: c:\documents and settings\Mr OZCAN\Bureau\ComboFix.exe
            Commutateurs utilisés :: c:\documents and settings\Mr OZCAN\Bureau\CFScript.txt
            AV: Microsoft Security Essentials *Disabled/Updated* {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
            AV: Microsoft Security Essentials *Enabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
            .
            .
            (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
            .
            .
            .
            ((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
            .
            .
            -------\Service_jekfznca
            .
            .
            ((((((((((((((((((((((((((((( Fichiers créés du 2011-09-04 au 2011-10-04 ))))))))))))))))))))))))))))))))))))
            .
            .
            2011-10-02 09:57 . 2011-10-02 09:57 -------- d-----w- c:\documents and settings\Mr OZCAN\Local Settings\Application Data\PCHealth
            2011-09-30 23:13 . 2011-09-30 23:13 -------- d-----w- c:\program files\Ad-Remover
            2011-09-30 22:08 . 2011-10-03 17:37 512 ----a-w- C:\PhysicalDisk0_MBR.bin
            2011-09-30 22:05 . 2011-10-03 17:37 -------- d-----w- C:\ZHP
            2011-09-30 22:05 . 2011-10-03 17:37 -------- d-----w- c:\program files\ZHPDiag
            2011-09-30 17:08 . 2011-09-30 18:26 -------- d-----w- c:\program files\PC Tools Security
            2011-09-30 17:08 . 2011-09-30 18:26 -------- d-----w- c:\program files\Fichiers communs\PC Tools
            2011-09-30 17:08 . 2011-09-30 18:25 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
            2011-09-30 17:02 . 2011-09-30 18:24 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Tools
            2011-09-30 16:32 . 2011-09-30 16:32 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Temp
            2011-09-30 16:32 . 2011-09-30 16:32 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
            2011-09-29 16:56 . 2007-03-08 04:20 16496 ----a-r- c:\windows\system32\drivers\HPZipr12.sys
            2011-09-29 16:56 . 2007-03-08 04:20 49920 ----a-r- c:\windows\system32\drivers\HPZid412.sys
            2011-09-29 14:13 . 2011-09-29 14:13 56200 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{39E1CE63-7175-4AB1-A8D3-8049F714EDEA}\offreg.dll
            2011-09-25 07:04 . 2011-09-12 23:14 7269712 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{39E1CE63-7175-4AB1-A8D3-8049F714EDEA}\mpengine.dll
            2011-09-16 14:17 . 2007-03-08 04:20 21568 ----a-r- c:\windows\system32\drivers\HPZius12.sys
            2011-09-13 16:31 . 2011-09-13 16:31 -------- d-----w- c:\windows\system32\config\systemprofile\Tracing
            2011-09-09 08:12 . 2011-06-23 18:31 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
            2011-09-09 08:12 . 2011-06-23 18:31 602112 -c----w- c:\windows\system32\dllcache\msfeeds.dll
            2011-09-09 08:12 . 2011-06-23 18:31 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll
            2011-09-09 08:12 . 2011-06-23 18:31 247808 -c----w- c:\windows\system32\dllcache\ieproxy.dll
            2011-09-09 08:12 . 2011-06-23 18:31 1991680 -c----w- c:\windows\system32\dllcache\iertutil.dll
            2011-09-09 08:12 . 2011-06-23 18:31 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll
            2011-09-09 08:12 . 2011-06-23 18:31 11081728 -c----w- c:\windows\system32\dllcache\ieframe.dll
            2011-09-09 07:47 . 2008-06-14 17:33 272768 -c----w- c:\windows\system32\dllcache\bthport.sys
            2011-09-09 07:46 . 2011-07-15 13:29 456320 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
            2011-09-09 07:40 . 2010-12-09 15:14 2194816 -c----w- c:\windows\system32\dllcache\ntoskrnl.exe
            2011-09-09 07:40 . 2010-12-09 15:14 2029056 -c----w- c:\windows\system32\dllcache\ntkrpamp.exe
            2011-09-09 07:40 . 2010-12-09 15:14 2150912 -c----w- c:\windows\system32\dllcache\ntkrnlmp.exe
            2011-09-09 07:40 . 2010-12-09 15:14 2071424 -c----w- c:\windows\system32\dllcache\ntkrnlpa.exe
            2011-09-08 15:01 . 2008-04-14 12:00 101888 -c--a-w- c:\windows\system32\dllcache\srusbusd.dll
            2011-09-08 15:00 . 2008-04-14 12:00 59392 -c--a-w- c:\windows\system32\dllcache\imscinst.exe
            2011-09-08 14:59 . 2003-03-24 13:52 20538 -c--a-w- c:\windows\system32\dllcache\fpremadm.exe
            2011-09-08 14:39 . 2001-08-17 18:13 27165 ----a-w- c:\windows\system32\drivers\fetnd5.sys
            2011-09-08 14:35 . 2008-04-14 12:00 24661 -c--a-w- c:\windows\system32\dllcache\spxcoins.dll
            2011-09-08 14:35 . 2008-04-14 12:00 24661 ----a-w- c:\windows\system32\spxcoins.dll
            2011-09-08 14:35 . 2008-04-14 12:00 13312 -c--a-w- c:\windows\system32\dllcache\irclass.dll
            2011-09-08 14:35 . 2008-04-14 12:00 13312 ----a-w- c:\windows\system32\irclass.dll
            2011-09-07 12:55 . 2011-09-07 12:55 -------- d-----r- c:\documents and settings\LocalService\Favoris
            2011-09-07 11:04 . 2011-09-07 11:05 -------- d-----w- c:\documents and settings\Administrateur.OZCAN-61D1365FC
            2011-09-07 10:04 . 2011-09-07 10:04 -------- d-----r- c:\documents and settings\NetworkService\Favoris
            2011-09-05 17:04 . 2011-09-05 17:04 183696 ----a-w- c:\program files\Mozilla Firefox\plugins\nppdf32.dll
            2011-09-05 17:04 . 2011-09-05 17:04 183696 ----a-w- c:\program files\Internet Explorer\Plugins\nppdf32.dll
            2011-09-04 21:16 . 2011-08-11 17:44 7152464 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Updates\mpengine.dll
            .
            .
            .
            (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
            .
            2011-09-30 23:00 . 2008-04-14 12:00 66048 ----a-w- c:\windows\system32\drivers\serial.sys
            2011-09-17 10:12 . 2011-06-29 09:44 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
            2011-09-09 09:12 . 2008-04-14 12:00 606208 ----a-w- c:\windows\system32\crypt32.dll
            2011-08-31 15:00 . 2010-11-23 16:15 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
            2011-08-11 17:44 . 2011-09-03 17:31 7152464 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
            2011-07-15 13:29 . 2008-04-14 12:00 456320 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
            2011-07-08 14:02 . 2008-04-14 12:00 10496 ----a-w- c:\windows\system32\drivers\ndistapi.sys
            2011-09-13 16:55 . 2011-04-06 13:41 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
            .
            .
            ((((((((((((((((((((((((((((( SnapShot_2011-10-02_09.48.27 )))))))))))))))))))))))))))))))))))))))))
            .
            + 2011-10-04 16:45 . 2011-10-04 16:45 16384 c:\windows\temp\Perflib_Perfdata_674.dat
            - 2011-10-02 09:48 . 2011-10-02 09:48 16384 c:\windows\Temp\Perflib_Perfdata_674.dat
            .
            ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
            .
            .
            *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
            REGEDIT4
            .
            [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
            "msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2010-04-16 3872080]
            .
            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
            "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-05-09 7311360]
            "MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 997920]
            "SoundMan"="SOUNDMAN.EXE" [2007-04-16 577536]
            "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-11-10 417792]
            "VX3000"="c:\windows\vVX3000.exe" [2006-12-05 707360]
            .
            [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
            "msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2010-04-16 3872080]
            .
            [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
            "HonorAutoRunSetting"= 0 (0x0)
            .
            [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
            "HonorAutoRunSetting"= 0 (0x0)
            .
            [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
            "{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]
            .
            [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
            @="Service"
            .
            [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^HP Digital Imaging Monitor.lnk]
            path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\HP Digital Imaging Monitor.lnk
            backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
            .
            [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Windows Search.lnk]
            path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Windows Search.lnk
            backup=c:\windows\pss\Windows Search.lnkCommon Startup
            .
            [HKLM\~\startupfolder\C:^Documents and Settings^Mr OZCAN^Menu Démarrer^Programmes^Démarrage^Notification de cadeaux MSN.lnk]
            path=c:\documents and settings\Mr OZCAN\Menu Démarrer\Programmes\Démarrage\Notification de cadeaux MSN.lnk
            backup=c:\windows\pss\Notification de cadeaux MSN.lnkStartup
            .
            [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
            2011-06-06 10:55 937920 ----a-w- c:\program files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe
            .
            [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
            2006-11-16 17:04 139264 ----a-w- c:\program files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe
            .
            [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
            2008-04-14 12:00 15360 ----a-w- c:\windows\system32\ctfmon.exe
            .
            [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
            2011-06-06 15:45 136176 ----atw- c:\documents and settings\Mr OZCAN\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
            .
            [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
            2007-03-11 19:34 49152 ----a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe
            .
            [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LifeCam]
            2007-01-12 15:48 275800 ----a-w- c:\program files\Microsoft LifeCam\LifeExp.exe
            .
            [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
            2008-04-14 02:34 1695232 ------w- c:\program files\Messenger\msmsgs.exe
            .
            [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
            2006-01-12 13:40 155648 ----a-w- c:\program files\Fichiers communs\Ahead\Lib\NeroCheck.exe
            .
            [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
            2006-05-09 14:50 86016 ----a-w- c:\windows\system32\nvmctray.dll
            .
            [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
            2009-11-10 21:08 417792 ----a-w- c:\program files\QuickTime\QTTask.exe
            .
            [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TomTomHOME.exe]
            2011-03-09 12:30 247728 ----a-w- c:\program files\TomTom HOME 2\TomTomHOMERunner.exe
            .
            [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VTTimer]
            2010-02-18 15:19 53248 ----a-w- c:\windows\system32\VTTimer.exe
            .
            [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VTTrayp]
            2010-02-18 15:19 176128 ----a-w- c:\windows\system32\VTTrayp.exe
            .
            [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VX3000]
            2006-12-05 13:39 707360 ----a-w- c:\windows\vVX3000.exe
            .
            [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
            "%windir%\\system32\\sessmgr.exe"=
            "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
            "c:\\Program Files\\Messenger\\msmsgs.exe"=
            "c:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
            "c:\\WINDOWS\\pchealth\\helpctr\\binaries\\helpctr.exe"=
            "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
            "c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
            "c:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
            .
            R2 TomTomHOMEService;TomTomHOMEService;c:\program files\TomTom HOME 2\TomTomHOMEService.exe [09/03/2011 14:30 92592]
            S1 MpKsl3ebe2020;MpKsl3ebe2020;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{11661DA5-5298-4FC1-972A-2BCCA90CD684}\MpKsl3ebe2020.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{11661DA5-5298-4FC1-972A-2BCCA90CD684}\MpKsl3ebe2020.sys [?]
            S1 MpKslc6572dfc;MpKslc6572dfc;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{667BFE0C-2F90-45D0-AE20-FFD3301F595B}\MpKslc6572dfc.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{667BFE0C-2F90-45D0-AE20-FFD3301F595B}\MpKslc6572dfc.sys [?]
            S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18/03/2010 14:16 130384]
            S2 gupdate;Service Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [10/12/2009 20:11 135664]
            S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.Sys [06/03/2011 13:25 36608]
            S3 gupdatem;Service Google Update (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [10/12/2009 20:11 135664]
            S3 maconfservice;Ma-Config Service;c:\program files\ma-config.com\maconfservice.exe [26/01/2010 18:45 243056]
            S3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\windows\system32\drivers\mbamswissarmy.sys --> c:\windows\system32\drivers\mbamswissarmy.sys [?]
            S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18/03/2010 14:16 753504]
            .
            [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
            HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
            hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
            .
            Contenu du dossier 'Tâches planifiées'
            .
            2011-09-28 c:\windows\Tasks\AppleSoftwareUpdate.job
            - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]
            .
            2011-10-04 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
            - c:\program files\Google\Update\GoogleUpdate.exe [2009-12-10 18:11]
            .
            2011-10-04 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
            - c:\program files\Google\Update\GoogleUpdate.exe [2009-12-10 18:11]
            .
            2011-09-28 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-746137067-842925246-839522115-1004Core.job
            - c:\documents and settings\Mr OZCAN\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-06-08 15:45]
            .
            2011-10-04 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-746137067-842925246-839522115-1004UA.job
            - c:\documents and settings\Mr OZCAN\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-06-08 15:45]
            .
            2011-10-01 c:\windows\Tasks\MP Scheduled Scan.job
            - c:\program files\Microsoft Security Client\Antimalware\MpCmdRun.exe [2011-04-27 13:39]
            .
            2011-10-04 c:\windows\Tasks\User_Feed_Synchronization-{8C734E8D-32B6-4C0C-999B-5C999564264D}.job
            - c:\windows\system32\msfeedssync.exe [2007-08-13 03:31]
            .
            .
            ------- Examen supplémentaire -------
            .
            uInternet Settings,ProxyServer = hxxp://127.0.0.1:8080
            uInternet Settings,ProxyOverride = *.local
            IE: Free YouTube to Mp3 Converter - c:\documents and settings\Mr OZCAN\Application Data\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
            IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.html
            TCP: DhcpNameServer = 212.27.40.240 212.27.40.241
            FF - ProfilePath - c:\documents and settings\Mr OZCAN\Application Data\Mozilla\Firefox\Profiles\to310717.default\
            FF - prefs.js: browser.search.selectedEngine - Bing
            FF - prefs.js: browser.startup.homepage - hxxp://www.google.fr/
            .
            .
            **************************************************************************
            .
            catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
            Rootkit scan 2011-10-04 18:49
            Windows 5.1.2600 Service Pack 3 NTFS
            .
            Recherche de processus cachés ...
            .
            Recherche d'éléments en démarrage automatique cachés ...
            .
            Recherche de fichiers cachés ...
            .
            Scan terminé avec succès
            Fichiers cachés: 0
            .
            **************************************************************************
            .
            --------------------- DLLs chargées dans les processus actifs ---------------------
            .
            - - - - - - - > 'explorer.exe'(2460)
            c:\program files\QuickTime\QTPlugin.ocx
            c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll
            c:\windows\system32\webcheck.dll
            c:\windows\system32\WPDShServiceObj.dll
            c:\windows\system32\PortableDeviceTypes.dll
            c:\windows\system32\PortableDeviceApi.dll
            c:\windows\system32\eappprxy.dll
            .
            ------------------------ Autres processus actifs ------------------------
            .
            c:\progra~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
            c:\program files\Java\jre6\bin\jqs.exe
            c:\program files\Microsoft LifeCam\MSCamS32.exe
            c:\windows\system32\SearchIndexer.exe
            c:\windows\SOUNDMAN.EXE
            .
            **************************************************************************
            .
            Heure de fin: 2011-10-04 18:51:54 - La machine a redémarré
            ComboFix-quarantined-files.txt 2011-10-04 16:51
            ComboFix2.txt 2011-10-03 15:19
            ComboFix3.txt 2011-10-02 09:51
            ComboFix4.txt 2011-09-08 16:01
            .
            Avant-CF: 215 593 320 448 octets libres
            Après-CF: 215 574 994 944 octets libres
            .
            - - End Of File - - 9027A3F5738D83329EBE7ED2488B271F
          5. Contributeur sécurité
            ok la je vais MP gen pour avoir son avis sur le rapport !!
        2. http://www.cijoint.fr/cjlink.php?file=cj201110/cijXDNhADY.txt
          1. Contributeur sécurité
            bon , mon amis gen-hackman en me propose un cript pour combo fix je te le transmet et tu fais cela , merci

            __________________________________________________
            =>/!\Le script qui suit a été écrit spécialement cet ordinateur/!\ <=
            =>il est fort déconseillé de le transposer sur un autre ordinateur !<=

            ----------------------------------------------------------------------------

            Toujours avec toutes les protections désactivées, fais ceci :

            ? Ouvre le bloc-notes (Menu démarrer --> programmes --> accessoires --> bloc-notes)
            ? Copie/colle dans le bloc-notes ce qui entre les lignes en GRASci dessous (sans les lignes) :

            ----------------------------------------------------------

            KillAll::

            File::
            c:\windows\SET176.tmp
            c:\windows\SET16A.tmp
            c:\windows\SET167.tmp

            Folder::
            c:\documents and settings\All Users\Application Data\iC04902KiFbH04902
            c:\documents and settings\All Users\ab05cc
            c:\documents and settings\All Users\Application Data\nL04903JhMbD04903

            Driver::
            bqlrssbz
            ekfznca


            ------------------------------------------------------------------

            ? Enregistre ce fichier sur ton Bureau (et pas ailleurs !) sous le nom CFScript.txt
            ? Quitte le Bloc Notes

            ? Fais un glisser/déposer de ce fichier CFScript sur le fichier combofix

            ? Patiente le temps du scan. Le Bureau va disparaître à plusieurs reprises : c'est normal ! Ne touche à rien tant que le scan n'est pas terminé.
            ? Une fois le scan achevé, un rapport va s'afficher: poste son contenu.
            ? Si le fichier ne s'ouvre pas, il se trouve ici => C:\ComboFix.txt
        3. Tout se passe bien, aucun problème ! J'aimerais être sur qu'il n'y ai plus rien. Que dit le rapport ?
          1. Contributeur sécurité
            il dit qu'il a nettoyer , mais si tu pouvais poster un drnier zhpdiag pour finaliser le nettoyage , merci de lui faire faire la mise à jour avant !!

            Double cliques sur le raccourci ZHPDiag sur ton Bureau pour XP sinon clique droit et en tant que administrateur !!

            clique sur la flèche verte "update" et installes la dernière version et lance l'analyse

            Cliques sur la loupe pour lancer l'analyse.

            si tu as un message te demandant la validation pour SIGCHECK acceptes avec OK cela est pour nous faire un rapport plus complet et pouvoir en faire une lecture plus approfondis

            Laisses l'outil travailler, il peut être assez long

            A la fin de l'analyse,clique sur l'appareil photo et enregistre le rapport sur ton Bureau.

            Fermes ZHPDiag en fin d'analyse.

            Pour me le transmettre clique sur ce lien :

            http://www.cijoint.fr/index.php

            Clique sur Parcourir et cherche le fichier C:\Documents and settings\le_nom_de_ta_session\bureau\.ZHPDiag.txt

            ou directement en choisissant bureau et ZHPDiag.txt clique dessus

            Clique sur Ouvrir.

            Clique sur "Cliquez ici pour déposer le fichier".

            Un lien de cette forme :

            http://www.cijoint.fr/cjlink.php?file=cj200905/cib7SU.txt

            est ajouté dans la page.

            Copie ce lien dans ta réponse.

            et si problème passe par celui ci : https://www.cjoint.com/
        4. http://www.cijoint.fr/cjlink.php?file=cj201110/cij3JKr51S.txt
          1. Contributeur sécurité
            ok et il va comment le pc ??
        5. oui je sais. je parlais du mode normale.

          J'ai utilisé Combofix ce matin mais ma connexion Internet ne s'est rétablie que récemment.

          ComboFix 11-10-01.03 - Mr OZCAN 02/10/2011 11:37:28.2.2 - x86
          Microsoft Windows XP Édition familiale 5.1.2600.3.1252.33.1036.18.958.683 [GMT 2:00]
          Lancé depuis: c:\documents and settings\Mr OZCAN\Bureau\ComboFix.exe
          AV: Microsoft Security Essentials *Disabled/Updated* {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
          AV: Microsoft Security Essentials *Enabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
          .
          .
          (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
          .
          .
          c:\documents and settings\Mr OZCAN\Application Data\Adobe\plugs
          c:\documents and settings\Mr OZCAN\Application Data\Adobe\plugs\KB11399093
          c:\documents and settings\Mr OZCAN\Application Data\Adobe\plugs\KB11399171
          c:\documents and settings\Mr OZCAN\Application Data\Adobe\shed
          c:\windows\$NtUninstallKB60033$
          c:\windows\$NtUninstallKB60033$\14198676
          c:\windows\$NtUninstallKB60033$\3580346393\@
          c:\windows\$NtUninstallKB60033$\3580346393\cfg.ini
          c:\windows\$NtUninstallKB60033$\3580346393\Desktop.ini
          c:\windows\$NtUninstallKB60033$\3580346393\L\wzhetcds
          c:\windows\system32\d3d9caps.dat
          .
          .
          ((((((((((((((((((((((((((((( Fichiers créés du 2011-09-02 au 2011-10-02 ))))))))))))))))))))))))))))))))))))
          .
          .
          2011-09-30 23:13 . 2011-09-30 23:13 -------- d-----w- c:\program files\Ad-Remover
          2011-09-30 22:08 . 2011-09-30 23:58 512 ----a-w- C:\PhysicalDisk0_MBR.bin
          2011-09-30 22:05 . 2011-09-30 23:58 -------- d-----w- C:\ZHP
          2011-09-30 22:05 . 2011-09-30 23:58 -------- d-----w- c:\program files\ZHPDiag
          2011-09-30 17:08 . 2011-09-30 18:26 -------- d-----w- c:\program files\PC Tools Security
          2011-09-30 17:08 . 2011-09-30 18:26 -------- d-----w- c:\program files\Fichiers communs\PC Tools
          2011-09-30 17:08 . 2011-09-30 18:25 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
          2011-09-30 17:02 . 2011-09-30 18:24 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Tools
          2011-09-30 16:32 . 2011-09-30 16:32 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Temp
          2011-09-30 16:32 . 2011-09-30 16:32 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
          2011-09-29 17:23 . 2011-09-30 23:51 -------- d-----w- c:\documents and settings\All Users\Application Data\iC04902KiFbH04902
          2011-09-29 16:56 . 2007-03-08 04:20 16496 ----a-r- c:\windows\system32\drivers\HPZipr12.sys
          2011-09-29 16:56 . 2007-03-08 04:20 49920 ----a-r- c:\windows\system32\drivers\HPZid412.sys
          2011-09-29 14:13 . 2011-09-29 14:13 56200 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{39E1CE63-7175-4AB1-A8D3-8049F714EDEA}\offreg.dll
          2011-09-25 07:04 . 2011-09-12 23:14 7269712 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{39E1CE63-7175-4AB1-A8D3-8049F714EDEA}\mpengine.dll
          2011-09-16 14:17 . 2007-03-08 04:20 21568 ----a-r- c:\windows\system32\drivers\HPZius12.sys
          2011-09-13 16:31 . 2011-09-13 16:31 -------- d-----w- c:\windows\system32\config\systemprofile\Tracing
          2011-09-09 08:12 . 2011-06-23 18:31 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
          2011-09-09 08:12 . 2011-06-23 18:31 602112 -c----w- c:\windows\system32\dllcache\msfeeds.dll
          2011-09-09 08:12 . 2011-06-23 18:31 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll
          2011-09-09 08:12 . 2011-06-23 18:31 247808 -c----w- c:\windows\system32\dllcache\ieproxy.dll
          2011-09-09 08:12 . 2011-06-23 18:31 1991680 -c----w- c:\windows\system32\dllcache\iertutil.dll
          2011-09-09 08:12 . 2011-06-23 18:31 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll
          2011-09-09 08:12 . 2011-06-23 18:31 11081728 -c----w- c:\windows\system32\dllcache\ieframe.dll
          2011-09-09 07:47 . 2008-06-14 17:33 272768 -c----w- c:\windows\system32\dllcache\bthport.sys
          2011-09-09 07:46 . 2011-07-15 13:29 456320 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
          2011-09-09 07:40 . 2010-12-09 15:14 2194816 -c----w- c:\windows\system32\dllcache\ntoskrnl.exe
          2011-09-09 07:40 . 2010-12-09 15:14 2029056 -c----w- c:\windows\system32\dllcache\ntkrpamp.exe
          2011-09-09 07:40 . 2010-12-09 15:14 2150912 -c----w- c:\windows\system32\dllcache\ntkrnlmp.exe
          2011-09-09 07:40 . 2010-12-09 15:14 2071424 -c----w- c:\windows\system32\dllcache\ntkrnlpa.exe
          2011-09-08 15:01 . 2008-04-14 12:00 101888 -c--a-w- c:\windows\system32\dllcache\srusbusd.dll
          2011-09-08 15:00 . 2008-04-14 12:00 59392 -c--a-w- c:\windows\system32\dllcache\imscinst.exe
          2011-09-08 14:59 . 2003-03-24 13:52 20538 -c--a-w- c:\windows\system32\dllcache\fpremadm.exe
          2011-09-08 14:39 . 2001-08-17 18:13 27165 ----a-w- c:\windows\system32\drivers\fetnd5.sys
          2011-09-08 14:35 . 2008-04-14 12:00 24661 -c--a-w- c:\windows\system32\dllcache\spxcoins.dll
          2011-09-08 14:35 . 2008-04-14 12:00 24661 ----a-w- c:\windows\system32\spxcoins.dll
          2011-09-08 14:35 . 2008-04-14 12:00 13312 -c--a-w- c:\windows\system32\dllcache\irclass.dll
          2011-09-08 14:35 . 2008-04-14 12:00 13312 ----a-w- c:\windows\system32\irclass.dll
          2011-09-08 14:35 . 2008-04-14 12:00 16825 ----a-r- c:\windows\SET176.tmp
          2011-09-08 14:35 . 2008-04-14 12:00 1088840 ----a-r- c:\windows\SET16A.tmp
          2011-09-08 14:35 . 2008-04-14 12:00 1246130 ----a-r- c:\windows\SET167.tmp
          2011-09-07 21:19 . 2011-09-07 21:21 -------- d-----w- c:\documents and settings\All Users\ab05cc
          2011-09-07 12:55 . 2011-09-07 12:55 -------- d-----r- c:\documents and settings\LocalService\Favoris
          2011-09-07 11:04 . 2011-09-07 11:05 -------- d-----w- c:\documents and settings\Administrateur.OZCAN-61D1365FC
          2011-09-07 10:04 . 2011-09-07 10:04 -------- d-----r- c:\documents and settings\NetworkService\Favoris
          2011-09-06 20:19 . 2011-09-07 11:52 -------- d-----w- c:\documents and settings\All Users\Application Data\nL04903JhMbD04903
          2011-09-05 17:04 . 2011-09-05 17:04 183696 ----a-w- c:\program files\Mozilla Firefox\plugins\nppdf32.dll
          2011-09-05 17:04 . 2011-09-05 17:04 183696 ----a-w- c:\program files\Internet Explorer\Plugins\nppdf32.dll
          2011-09-04 21:16 . 2011-08-11 17:44 7152464 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Updates\mpengine.dll
          2011-09-03 17:31 . 2011-08-11 17:44 7152464 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
          2011-09-03 09:08 . 2011-09-03 09:08 -------- d-----w- c:\windows\TempB9ABC669-F4F2-7925-EB83-EDD4BC92D951-Signatures
          2011-09-03 09:08 . 2011-09-04 21:20 -------- d-----w- c:\program files\Microsoft Security Client
          2011-09-02 16:52 . 2010-10-19 20:51 222080 ----a-w- c:\windows\system32\MpSigStub.exe
          .
          .
          .
          (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
          .
          2011-09-30 23:00 . 2008-04-14 12:00 66048 ----a-w- c:\windows\system32\drivers\serial.sys
          2011-09-17 10:12 . 2011-06-29 09:44 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
          2011-09-09 09:12 . 2008-04-14 12:00 606208 ----a-w- c:\windows\system32\crypt32.dll
          2011-08-31 15:00 . 2010-11-23 16:15 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
          2011-07-15 13:29 . 2008-04-14 12:00 456320 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
          2011-07-08 14:02 . 2008-04-14 12:00 10496 ----a-w- c:\windows\system32\drivers\ndistapi.sys
          2011-09-13 16:55 . 2011-04-06 13:41 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
          .
          .
          ((((((((((((((((((((((((((((( SnapShot@2011-09-08_15.58.21 )))))))))))))))))))))))))))))))))))))))))
          .
          + 2011-10-02 09:48 . 2011-10-02 09:48 16384 c:\windows\Temp\Perflib_Perfdata_674.dat
          + 2009-08-06 17:24 . 2009-08-06 17:24 44768 c:\windows\system32\wups2.dll
          + 2002-01-01 11:42 . 2009-08-06 17:24 35552 c:\windows\system32\wups.dll
          + 2002-01-01 11:42 . 2009-08-06 17:24 53472 c:\windows\system32\wuauclt.exe
          - 2008-04-14 12:00 . 2008-04-14 12:00 90112 c:\windows\system32\wshext.dll
          + 2008-04-14 12:00 . 2008-05-09 10:55 90112 c:\windows\system32\wshext.dll
          + 2008-04-14 12:00 . 2009-06-25 08:26 54272 c:\windows\system32\wdigest.dll
          + 2008-04-14 12:00 . 2011-07-08 13:49 46080 c:\windows\system32\tzchange.exe
          + 2008-04-14 12:00 . 2009-06-15 10:44 78848 c:\windows\system32\telnet.exe
          - 2008-04-14 12:00 . 2008-04-14 12:00 75776 c:\windows\system32\strmfilt.dll
          + 2008-04-14 12:00 . 2009-10-21 05:39 75776 c:\windows\system32\strmfilt.dll
          + 2008-04-14 12:00 . 2010-08-27 05:58 99840 c:\windows\system32\srvsvc.dll
          + 2008-10-02 12:45 . 2009-01-07 16:21 26144 c:\windows\system32\spupdsvc.exe
          - 2008-10-02 12:45 . 2009-01-07 17:21 26144 c:\windows\system32\spupdsvc.exe
          + 2008-04-14 12:00 . 2010-08-17 13:17 58880 c:\windows\system32\spoolsv.exe
          + 2011-09-07 17:03 . 2009-01-07 16:21 17952 c:\windows\system32\spmsg.dll
          + 2008-04-14 12:00 . 2009-06-25 08:26 56832 c:\windows\system32\secur32.dll
          + 2008-04-14 12:00 . 2009-02-06 10:39 35328 c:\windows\system32\sc.exe
          - 2008-04-14 12:00 . 2008-04-14 12:00 79872 c:\windows\system32\raschap.dll
          + 2008-04-14 12:00 . 2009-10-12 13:39 79872 c:\windows\system32\raschap.dll
          + 2008-04-14 12:00 . 2009-03-08 02:31 46592 c:\windows\system32\pngfilt.dll
          + 2006-03-02 12:00 . 2011-09-09 08:50 79978 c:\windows\system32\perfc009.dat
          - 2006-03-02 12:00 . 2011-09-08 15:20 79978 c:\windows\system32\perfc009.dat
          - 2006-06-29 06:05 . 2009-01-07 17:20 23552 c:\windows\system32\normaliz.dll
          + 2006-06-29 06:05 . 2009-01-07 16:20 23552 c:\windows\system32\normaliz.dll
          + 2006-06-28 15:59 . 2009-01-07 16:20 24576 c:\windows\system32\nlsdl.dll
          - 2006-06-28 15:59 . 2009-01-07 17:20 24576 c:\windows\system32\nlsdl.dll
          - 2002-01-01 11:40 . 2008-04-14 12:00 91648 c:\windows\system32\mtxoci.dll
          + 2002-01-01 11:40 . 2008-06-12 14:22 91648 c:\windows\system32\mtxoci.dll
          - 2008-04-14 12:00 . 2008-04-14 12:00 66560 c:\windows\system32\mtxclu.dll
          + 2008-04-14 12:00 . 2008-06-12 14:22 66560 c:\windows\system32\mtxclu.dll
          + 2008-04-13 19:33 . 2009-11-27 17:13 17920 c:\windows\system32\msyuv.dll
          + 2008-04-14 12:00 . 2008-08-28 07:47 74752 c:\windows\system32\msw3prt.dll
          + 2008-04-14 12:00 . 2009-11-27 16:08 28672 c:\windows\system32\msvidc32.dll
          + 2008-04-14 12:00 . 2009-11-27 16:08 11264 c:\windows\system32\msrle32.dll
          - 2008-04-14 12:00 . 2008-04-14 12:00 11264 c:\windows\system32\msrle32.dll
          + 2008-04-14 12:00 . 2009-03-08 02:31 48128 c:\windows\system32\mshtmler.dll
          + 2008-04-14 12:00 . 2011-06-23 18:31 66560 c:\windows\system32\mshtmled.dll
          + 2008-04-14 12:00 . 2009-03-08 02:31 45568 c:\windows\system32\mshta.exe
          - 2002-01-01 11:40 . 2008-04-14 12:00 58880 c:\windows\system32\msdtclog.dll
          + 2002-01-01 11:40 . 2008-06-12 14:22 58880 c:\windows\system32\msdtclog.dll
          + 2008-04-14 12:00 . 2008-06-24 16:44 74240 c:\windows\system32\mscms.dll
          + 2008-04-14 12:00 . 2009-09-04 21:04 58880 c:\windows\system32\msasn1.dll
          + 2008-04-14 12:00 . 2008-06-10 03:52 96768 c:\windows\system32\logagent.exe
          - 2008-04-14 12:00 . 2005-01-28 11:44 96768 c:\windows\system32\logagent.exe
          + 2008-04-14 12:00 . 2011-06-23 18:31 43520 c:\windows\system32\licmgr10.dll
          + 2008-04-14 12:00 . 2011-06-23 18:31 25600 c:\windows\system32\jsproxy.dll
          + 2008-04-13 19:33 . 2009-11-27 16:08 48128 c:\windows\system32\iyuv_32.dll
          - 2002-01-01 11:42 . 2008-04-14 12:00 86016 c:\windows\system32\isign32.dll
          + 2002-01-01 11:42 . 2010-11-18 18:12 86016 c:\windows\system32\isign32.dll
          + 2008-04-14 12:00 . 2009-03-08 02:32 94720 c:\windows\system32\inseng.dll
          + 2008-04-14 12:00 . 2009-03-08 02:31 34816 c:\windows\system32\imgutil.dll
          + 2007-08-13 16:39 . 2009-03-08 02:32 36864 c:\windows\system32\ieudinit.exe
          - 2007-08-13 16:39 . 2009-03-08 03:32 36864 c:\windows\system32\ieudinit.exe
          + 2008-04-14 12:00 . 2009-03-08 02:32 71680 c:\windows\system32\iesetup.dll
          + 2008-04-14 12:00 . 2009-03-08 02:32 55808 c:\windows\system32\iernonce.dll
          - 2006-06-29 06:05 . 2009-01-07 17:20 26112 c:\windows\system32\idndl.dll
          + 2006-06-29 06:05 . 2009-01-07 16:20 26112 c:\windows\system32\idndl.dll
          - 2008-04-14 12:00 . 2008-04-14 12:00 80384 c:\windows\system32\iccvid.dll
          + 2008-04-14 12:00 . 2010-06-17 14:03 80384 c:\windows\system32\iccvid.dll
          + 2008-04-14 12:00 . 2009-10-21 05:39 25088 c:\windows\system32\httpapi.dll
          + 2008-04-14 12:00 . 2009-10-15 16:32 81920 c:\windows\system32\fontsub.dll
          + 2008-04-14 12:00 . 2010-11-02 15:17 40960 c:\windows\system32\drivers\ndproxy.sys
          + 2008-04-14 12:00 . 2009-06-24 11:18 92928 c:\windows\system32\drivers\ksecdd.sys
          - 2008-04-14 12:00 . 2008-04-14 12:00 45568 c:\windows\system32\dnsrslvr.dll
          + 2008-04-14 12:00 . 2009-04-20 17:18 45568 c:\windows\system32\dnsrslvr.dll
          + 2002-01-01 11:42 . 2009-08-06 17:24 35552 c:\windows\system32\dllcache\wups.dll
          + 2002-01-01 11:42 . 2009-08-06 17:24 53472 c:\windows\system32\dllcache\wuauclt.exe
          + 2008-04-14 12:00 . 2008-05-09 10:55 90112 c:\windows\system32\dllcache\wshext.dll
          - 2008-04-14 12:00 . 2008-04-14 12:00 90112 c:\windows\system32\dllcache\wshext.dll
          + 2008-04-14 12:00 . 2009-06-25 08:26 54272 c:\windows\system32\dllcache\wdigest.dll
          + 2002-01-01 11:42 . 2010-10-11 14:59 45568 c:\windows\system32\dllcache\wab.exe
          + 2008-04-14 12:00 . 2009-06-15 10:44 78848 c:\windows\system32\dllcache\telnet.exe
          + 2008-04-14 12:00 . 2009-10-21 05:39 75776 c:\windows\system32\dllcache\strmfilt.dll
          - 2008-04-14 12:00 . 2008-04-14 12:00 75776 c:\windows\system32\dllcache\strmfilt.dll
          + 2008-04-14 12:00 . 2010-08-27 05:58 99840 c:\windows\system32\dllcache\srvsvc.dll
          + 2008-04-14 12:00 . 2010-08-17 13:17 58880 c:\windows\system32\dllcache\spoolsv.exe
          + 2008-04-14 12:00 . 2009-06-25 08:26 56832 c:\windows\system32\dllcache\secur32.dll
          + 2008-04-14 12:00 . 2009-02-06 10:39 35328 c:\windows\system32\dllcache\sc.exe
          + 2008-04-14 12:00 . 2009-10-12 13:39 79872 c:\windows\system32\dllcache\raschap.dll
          - 2008-04-14 12:00 . 2008-04-14 12:00 79872 c:\windows\system32\dllcache\raschap.dll
          + 2008-04-14 12:00 . 2009-03-08 02:31 46592 c:\windows\system32\dllcache\pngfilt.dll
          + 2008-04-14 12:00 . 2010-11-02 15:17 40960 c:\windows\system32\dllcache\ndproxy.sys
          + 2008-04-14 12:00 . 2011-07-08 14:02 10496 c:\windows\system32\dllcache\ndistapi.sys
          + 2002-01-01 11:40 . 2008-06-12 14:22 91648 c:\windows\system32\dllcache\mtxoci.dll
          - 2002-01-01 11:40 . 2008-04-14 12:00 91648 c:\windows\system32\dllcache\mtxoci.dll
          - 2008-04-14 12:00 . 2008-04-14 12:00 66560 c:\windows\system32\dllcache\mtxclu.dll
          + 2008-04-14 12:00 . 2008-06-12 14:22 66560 c:\windows\system32\dllcache\mtxclu.dll
          + 2009-11-27 17:13 . 2009-11-27 17:13 17920 c:\windows\system32\dllcache\msyuv.dll
          + 2008-04-14 12:00 . 2008-08-28 07:47 74752 c:\windows\system32\dllcache\msw3prt.dll
          + 2008-04-14 12:00 . 2009-11-27 16:08 28672 c:\windows\system32\dllcache\msvidc32.dll
          + 2008-04-14 12:00 . 2009-11-27 16:08 11264 c:\windows\system32\dllcache\msrle32.dll
          - 2008-04-14 12:00 . 2008-04-14 12:00 11264 c:\windows\system32\dllcache\msrle32.dll
          + 2008-04-14 12:00 . 2009-03-08 02:31 48128 c:\windows\system32\dllcache\mshtmler.dll
          + 2008-04-14 12:00 . 2011-06-23 18:31 66560 c:\windows\system32\dllcache\mshtmled.dll
          + 2008-04-14 12:00 . 2009-03-08 02:31 45568 c:\windows\system32\dllcache\mshta.exe
          + 2002-01-01 11:40 . 2008-06-12 14:22 58880 c:\windows\system32\dllcache\msdtclog.dll
          - 2002-01-01 11:40 . 2008-04-14 12:00 58880 c:\windows\system32\dllcache\msdtclog.dll
          + 2008-04-14 12:00 . 2008-06-24 16:44 74240 c:\windows\system32\dllcache\mscms.dll
          + 2008-04-14 12:00 . 2009-09-04 21:04 58880 c:\windows\system32\dllcache\msasn1.dll
          - 2008-04-14 12:00 . 2005-01-28 11:44 96768 c:\windows\system32\dllcache\logagent.exe
          + 2008-04-14 12:00 . 2008-06-10 03:52 96768 c:\windows\system32\dllcache\logagent.exe
          + 2008-04-14 12:00 . 2011-06-23 18:31 43520 c:\windows\system32\dllcache\licmgr10.dll
          + 2008-04-14 12:00 . 2009-06-24 11:18 92928 c:\windows\system32\dllcache\ksecdd.sys
          + 2008-04-14 12:00 . 2011-06-23 18:31 25600 c:\windows\system32\dllcache\jsproxy.dll
          + 2009-11-27 16:08 . 2009-11-27 16:08 48128 c:\windows\system32\dllcache\iyuv_32.dll
          - 2002-01-01 11:42 . 2008-04-14 12:00 86016 c:\windows\system32\dllcache\isign32.dll
          + 2002-01-01 11:42 . 2010-11-18 18:12 86016 c:\windows\system32\dllcache\isign32.dll
          + 2008-04-14 12:00 . 2009-03-08 02:32 94720 c:\windows\system32\dllcache\inseng.dll
          + 2008-04-14 12:00 . 2009-03-08 02:31 34816 c:\windows\system32\dllcache\imgutil.dll
          + 2008-04-14 12:00 . 2009-03-08 02:32 71680 c:\windows\system32\dllcache\iesetup.dll
          + 2008-04-14 12:00 . 2009-03-08 02:32 55808 c:\windows\system32\dllcache\iernonce.dll
          + 2008-04-14 12:00 . 2009-10-21 05:39 25088 c:\windows\system32\dllcache\httpapi.dll
          + 2002-01-01 11:42 . 2009-03-08 02:24 68608 c:\windows\system32\dllcache\hmmapi.dll
          + 2008-04-14 12:00 . 2009-10-15 16:32 81920 c:\windows\system32\dllcache\fontsub.dll
          + 2008-04-14 12:00 . 2009-04-20 17:18 45568 c:\windows\system32\dllcache\dnsrslvr.dll
          - 2008-04-14 12:00 . 2008-04-14 12:00 45568 c:\windows\system32\dllcache\dnsrslvr.dll
          + 2008-04-14 12:00 . 2011-04-26 11:07 33280 c:\windows\system32\dllcache\csrsrv.dll
          + 2008-04-14 12:00 . 2009-03-08 02:33 18944 c:\windows\system32\dllcache\corpol.dll
          + 2008-04-14 12:00 . 2009-08-06 17:24 96480 c:\windows\system32\dllcache\cdm.dll
          + 2008-04-14 12:00 . 2010-01-13 14:01 87040 c:\windows\system32\dllcache\cabview.dll
          - 2008-04-14 12:00 . 2008-04-14 12:00 85504 c:\windows\system32\dllcache\avifil32.dll
          + 2008-04-14 12:00 . 2009-11-27 16:08 85504 c:\windows\system32\dllcache\avifil32.dll
          - 2008-04-14 12:00 . 2008-04-14 12:00 58880 c:\windows\system32\dllcache\atl.dll
          + 2008-04-14 12:00 . 2009-07-17 19:03 58880 c:\windows\system32\dllcache\atl.dll
          + 2008-04-14 12:00 . 2010-03-05 14:38 65536 c:\windows\system32\dllcache\asycfilt.dll
          + 2008-04-14 12:00 . 2009-03-08 02:32 72704 c:\windows\system32\dllcache\admparse.dll
          + 2008-04-14 12:00 . 2011-04-26 11:07 33280 c:\windows\system32\csrsrv.dll
          + 2008-04-14 12:00 . 2009-03-08 02:33 18944 c:\windows\system32\corpol.dll
          + 2011-09-08 15:05 . 2011-09-13 16:30 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
          - 2011-09-08 15:05 . 2011-09-08 15:05 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
          + 2002-01-01 11:50 . 2011-09-13 16:30 32768 c:\windows\system32\config\systemprofile\Local Settings\Historique\History.IE5\index.dat
          - 2002-01-01 11:50 . 2011-09-08 15:04 32768 c:\windows\system32\config\systemprofile\Local Settings\Historique\History.IE5\index.dat
          - 2002-01-01 11:50 . 2011-09-08 15:04 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
          + 2011-09-13 16:30 . 2011-09-13 16:30 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
          + 2011-09-13 16:31 . 2011-09-13 16:31 14744 c:\windows\system32\config\systemprofile\Application Data\Microsoft\IdentityCRL\Production\ppcrlconfig.dll
          + 2008-04-14 12:00 . 2009-08-06 17:24 96480 c:\windows\system32\cdm.dll
          + 2008-04-14 12:00 . 2010-01-13 14:01 87040 c:\windows\system32\cabview.dll
          - 2008-04-14 12:00 . 2008-04-14 12:00 85504 c:\windows\system32\avifil32.dll
          + 2008-04-14 12:00 . 2009-11-27 16:08 85504 c:\windows\system32\avifil32.dll
          - 2008-04-14 12:00 . 2008-04-14 12:00 58880 c:\windows\system32\atl.dll
          + 2008-04-14 12:00 . 2009-07-17 19:03 58880 c:\windows\system32\atl.dll
          + 2008-04-14 12:00 . 2010-03-05 14:38 65536 c:\windows\system32\asycfilt.dll
          + 2008-04-14 12:00 . 2009-03-08 02:32 72704 c:\windows\system32\admparse.dll
          + 2011-09-24 13:55 . 2011-09-24 13:55 22016 c:\windows\Installer\122b651.msi
          + 2011-06-06 10:55 . 2011-06-06 10:55 17304 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA76301B744AA0100000010\10.1.0\ViewerPS.dll
          + 2011-06-06 10:55 . 2011-06-06 10:55 35736 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA76301B744AA0100000010\10.1.0\reader_sl.exe
          + 2011-06-06 10:55 . 2011-06-06 10:55 88992 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA76301B744AA0100000010\10.1.0\PDFPrevHndlr.dll
          + 2011-06-06 10:55 . 2011-06-06 10:55 94608 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA76301B744AA0100000010\10.1.0\eula.exe
          + 2011-06-06 10:55 . 2011-06-06 10:55 49064 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA76301B744AA0100000010\10.1.0\acrotextextractor.exe
          + 2011-06-06 10:55 . 2011-06-06 10:55 17824 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA76301B744AA0100000010\10.1.0\AcroRd32Info.exe
          + 2011-06-06 10:55 . 2011-06-06 10:55 63912 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA76301B744AA0100000010\10.1.0\acroiehelpershim.dll
          + 2011-06-06 10:55 . 2011-06-06 10:55 64928 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA76301B744AA0100000010\10.1.0\AcroIEHelper.dll
          + 2011-06-06 10:55 . 2011-06-06 10:55 63384 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA76301B744AA0100000010\10.1.0\Acrofx32.dll
          + 2011-09-09 08:13 . 2008-07-08 13:03 18296 c:\windows\ie8updates\KB982381-IE8\spmsg.dll
          + 2011-09-09 08:13 . 2008-07-08 13:03 26488 c:\windows\ie8updates\KB982381-IE8\spcustom.dll
          - 2010-06-09 12:10 . 2010-02-25 06:17 25600 c:\windows\ie8updates\KB982381-IE8\jsproxy.dll
          + 2010-06-09 12:10 . 2009-03-08 02:33 25600 c:\windows\ie8updates\KB982381-IE8\jsproxy.dll
          - 2011-08-10 08:26 . 2011-04-25 16:06 12800 c:\windows\ie8updates\KB2559049-IE8\xpshims.dll
          + 2011-08-10 08:26 . 2010-05-06 10:33 12800 c:\windows\ie8updates\KB2559049-IE8\xpshims.dll
          + 2011-09-09 08:13 . 2010-07-05 13:17 18296 c:\windows\ie8updates\KB2559049-IE8\spmsg.dll
          + 2011-09-09 08:13 . 2010-07-05 13:17 26488 c:\windows\ie8updates\KB2559049-IE8\spcustom.dll
          - 2011-08-10 08:26 . 2011-04-25 16:06 66560 c:\windows\ie8updates\KB2559049-IE8\mshtmled.dll
          + 2011-08-10 08:26 . 2009-03-08 02:31 66560 c:\windows\ie8updates\KB2559049-IE8\mshtmled.dll
          + 2011-08-10 08:26 . 2010-05-06 10:33 55296 c:\windows\ie8updates\KB2559049-IE8\msfeedsbs.dll
          - 2011-08-10 08:26 . 2011-04-25 16:06 55296 c:\windows\ie8updates\KB2559049-IE8\msfeedsbs.dll
          + 2011-08-10 08:26 . 2009-03-08 02:34 43008 c:\windows\ie8updates\KB2559049-IE8\licmgr10.dll
          - 2011-08-10 08:26 . 2011-04-25 16:06 25600 c:\windows\ie8updates\KB2559049-IE8\jsproxy.dll
          + 2011-08-10 08:26 . 2010-05-06 10:33 25600 c:\windows\ie8updates\KB2559049-IE8\jsproxy.dll
          + 2011-09-09 08:46 . 2010-07-05 13:17 18296 c:\windows\ie8updates\KB2544521-IE8\spmsg.dll
          + 2011-09-09 08:46 . 2010-07-05 13:17 26488 c:\windows\ie8updates\KB2544521-IE8\spcustom.dll
          + 2011-09-09 08:45 . 2010-07-05 13:17 18296 c:\windows\ie8updates\KB2510531-IE8\spmsg.dll
          + 2011-09-09 08:45 . 2010-07-05 13:17 26488 c:\windows\ie8updates\KB2510531-IE8\spcustom.dll
          + 2010-02-27 13:27 . 2011-06-21 18:19 37888 c:\windows\ie8\url.dll
          - 2010-02-27 13:29 . 2009-03-08 15:14 58448 c:\windows\ie8\spuninst\iecustom.dll
          + 2010-02-27 13:29 . 2009-03-08 14:14 58448 c:\windows\ie8\spuninst\iecustom.dll
          + 2011-09-09 08:11 . 2008-04-14 12:00 39424 c:\windows\ie8\pngfilt.dll
          + 2011-09-09 08:11 . 2008-04-14 12:00 97280 c:\windows\ie8\occache.dll
          + 2011-09-09 08:11 . 2008-04-14 12:00 57344 c:\windows\ie8\mshtmler.dll
          + 2011-09-09 08:11 . 2008-04-14 12:00 29184 c:\windows\ie8\mshta.exe
          + 2011-09-09 08:11 . 2008-04-14 12:00 22528 c:\windows\ie8\licmgr10.dll
          + 2011-09-09 08:11 . 2008-04-14 12:00 15872 c:\windows\ie8\jsproxy.dll
          + 2011-09-09 08:11 . 2008-04-14 12:00 96768 c:\windows\ie8\inseng.dll
          + 2011-09-09 08:11 . 2008-04-14 12:00 35840 c:\windows\ie8\imgutil.dll
          + 2011-09-09 08:11 . 2008-04-14 12:00 93184 c:\windows\ie8\iexplore.exe
          + 2011-09-09 08:11 . 2008-04-14 12:00 63488 c:\windows\ie8\iesetup.dll
          + 2011-09-09 08:11 . 2008-04-14 12:00 49152 c:\windows\ie8\iernonce.dll
          + 2011-09-09 08:11 . 2011-06-21 18:19 81920 c:\windows\ie8\ieencode.dll
          + 2011-09-09 08:11 . 2008-04-14 12:00 34304 c:\windows\ie8\ie4uinit.exe
          + 2011-09-09 08:11 . 2008-04-14 12:00 38912 c:\windows\ie8\hmmapi.dll
          + 2011-09-09 08:11 . 2008-04-14 12:00 35328 c:\windows\ie8\corpol.dll
          + 2011-09-09 08:11 . 2008-04-14 12:00 61440 c:\windows\ie8\admparse.dll
          + 2009-11-27 17:13 . 2009-11-27 17:13 17920 c:\windows\Driver Cache\i386\msyuv.dll
          + 2009-11-27 16:08 . 2009-11-27 16:08 48128 c:\windows\Driver Cache\i386\iyuv_32.dll
          + 2001-08-23 17:47 . 2009-11-27 16:08 8704 c:\windows\system32\tsbyuv.dll
          + 2009-11-27 16:08 . 2009-11-27 16:08 8704 c:\windows\system32\dllcache\tsbyuv.dll
          + 2009-11-27 16:08 . 2009-11-27 16:08 8704 c:\windows\Driver Cache\i386\tsbyuv.dll
          - 2008-04-14 12:00 . 2008-04-14 12:00 121856 c:\windows\system32\xmllite.dll
          + 2008-04-14 12:00 . 2009-01-07 16:21 121856 c:\windows\system32\xmllite.dll
          + 2002-01-01 11:42 . 2009-08-06 17:24 209632 c:\windows\system32\wuweb.dll
          + 2002-01-01 11:42 . 2009-08-06 17:24 327896 c:\windows\system32\wucltui.dll
          + 2002-01-01 11:42 . 2009-08-06 17:23 575704 c:\windows\system32\wuapi.dll
          - 2008-04-14 12:00 . 2008-04-14 12:00 155648 c:\windows\system32\wscript.exe
          + 2008-04-14 12:00 . 2008-05-08 11:24 155648 c:\windows\system32\wscript.exe
          + 2008-04-14 12:00 . 2009-04-09 23:01 413032 c:\windows\system32\wmspdmod.dll
          + 2008-04-14 12:00 . 2009-07-12 10:21 233472 c:\windows\system32\wmpdxm.dll
          - 2008-04-14 12:00 . 2008-04-14 12:00 233472 c:\windows\system32\wmpdxm.dll
          + 2008-04-14 12:00 . 2007-10-20 04:01 227328 c:\windows\system32\wmasf.dll
          - 2008-04-14 12:00 . 2008-04-14 12:00 132096 c:\windows\system32\wkssvc.dll
          + 2008-04-14 12:00 . 2009-06-10 06:15 132096 c:\windows\system32\wkssvc.dll
          + 2008-04-14 12:00 . 2009-12-24 07:00 177664 c:\windows\system32\wintrust.dll
          - 2008-04-14 12:00 . 2008-04-14 12:00 293888 c:\windows\system32\winsrv.dll
          + 2008-04-14 12:00 . 2011-06-20 17:44 293888 c:\windows\system32\winsrv.dll
          + 2008-04-14 12:00 . 2011-06-23 18:31 916480 c:\windows\system32\wininet.dll
          + 2008-04-14 12:00 . 2009-08-25 09:18 354816 c:\windows\system32\winhttp.dll
          + 2008-04-14 12:00 . 2008-08-28 07:47 105472 c:\windows\system32\win32spl.dll
          + 2008-04-14 12:00 . 2009-03-08 02:34 236544 c:\windows\system32\webcheck.dll
          + 2002-01-01 11:40 . 2009-02-06 10:10 227840 c:\windows\system32\wbem\wmiprvse.exe
          + 2002-01-01 11:40 . 2009-02-09 10:53 453120 c:\windows\system32\wbem\wmiprvsd.dll
          + 2002-01-01 11:40 . 2009-02-09 10:53 473600 c:\windows\system32\wbem\fastprox.dll
          + 2008-04-14 12:00 . 2011-03-04 06:36 420864 c:\windows\system32\vbscript.dll
          + 2008-04-14 12:00 . 2010-04-16 15:38 406016 c:\windows\system32\usp10.dll
          - 2008-04-14 12:00 . 2008-04-14 12:00 406016 c:\windows\system32\usp10.dll
          + 2008-04-14 12:00 . 2011-06-23 18:31 105984 c:\windows\system32\url.dll
          + 2008-04-14 12:00 . 2010-08-27 08:02 119808 c:\windows\system32\t2embed.dll
          + 2008-04-14 12:00 . 2009-08-26 08:01 247326 c:\windows\system32\strmdll.dll
          - 2008-04-14 12:00 . 2008-04-14 12:00 135680 c:\windows\system32\shsvcs.dll
          + 2008-04-14 12:00 . 2009-07-27 23:17 135680 c:\windows\system32\shsvcs.dll
          - 2008-04-14 12:00 . 2008-04-14 12:00 474624 c:\windows\system32\shlwapi.dll
          + 2008-04-14 12:00 . 2009-12-08 09:24 474624 c:\windows\system32\shlwapi.dll
          + 2008-04-14 12:00 . 2011-01-21 14:44 441344 c:\windows\system32\shimgvw.dll
          + 2008-04-14 12:00 . 2009-02-09 11:23 111104 c:\windows\system32\services.exe
          - 2008-04-14 12:00 . 2008-04-14 12:00 172032 c:\windows\system32\scrrun.dll
          + 2008-04-14 12:00 . 2008-05-09 10:55 172032 c:\windows\system32\scrrun.dll
          + 2008-04-14 12:00 . 2008-05-09 10:55 180224 c:\windows\system32\scrobj.dll
          - 2008-04-14 12:00 . 2008-04-14 12:00 180224 c:\windows\system32\scrobj.dll
          + 2008-04-14 12:00 . 2011-04-29 17:25 151552 c:\windows\system32\schannel.dll
          + 2008-04-14 12:00 . 2011-02-09 13:54 270848 c:\windows\system32\sbe.dll
          - 2008-04-14 12:00 . 2008-04-14 12:00 270848 c:\windows\system32\sbe.dll
          + 2008-04-14 12:00 . 2009-02-09 10:53 401408 c:\windows\system32\rpcss.dll
          + 2008-04-14 12:00 . 2010-08-16 08:44 590848 c:\windows\system32\rpcrt4.dll
          + 2008-04-14 12:00 . 2009-10-12 13:39 150528 c:\windows\system32\rastls.dll
          + 2006-03-02 12:00 . 2011-09-09 08:50 575200 c:\windows\system32\perfh00C.dat
          - 2006-03-02 12:00 . 2011-09-08 15:20 575200 c:\windows\system32\perfh00C.dat
          - 2006-03-02 12:00 . 2011-09-08 15:20 481714 c:\windows\system32\perfh009.dat
          + 2006-03-02 12:00 . 2011-09-09 08:50 481714 c:\windows\system32\perfh009.dat
          + 2006-03-02 12:00 . 2011-09-09 08:50 104108 c:\windows\system32\perfc00C.dat
          - 2006-03-02 12:00 . 2011-09-08 15:20 104108 c:\windows\system32\perfc00C.dat
          + 2008-04-14 12:00 . 2009-03-06 14:20 286720 c:\windows\system32\pdh.dll
          - 2008-04-14 12:00 . 2008-04-14 12:00 286720 c:\windows\system32\pdh.dll
          + 2008-04-14 12:00 . 2010-12-20 17:32 551936 c:\windows\system32\oleaut32.dll
          - 2008-04-14 12:00 . 2008-04-14 12:00 551936 c:\windows\system32\oleaut32.dll
          + 2008-04-14 12:00 . 2010-11-09 14:52 249856 c:\windows\system32\odbc32.dll
          - 2008-04-14 12:00 . 2008-04-14 12:00 249856 c:\windows\system32\odbc32.dll
          + 2008-04-14 12:00 . 2011-06-23 18:31 206848 c:\windows\system32\occache.dll
          - 2008-04-14 12:00 . 2008-04-14 12:00 271360 c:\windows\system32\oakley.dll
          + 2008-04-14 12:00 . 2009-10-13 10:33 271360 c:\windows\system32\oakley.dll
          + 2008-04-14 12:00 . 2010-12-09 15:15 743424 c:\windows\system32\ntdll.dll
          - 2008-04-14 12:00 . 2008-04-14 12:00 337408 c:\windows\system32\netapi32.dll
          + 2008-04-14 12:00 . 2008-10-15 16:35 337408 c:\windows\system32\netapi32.dll
          - 2008-04-14 12:00 . 2008-04-14 12:00 247808 c:\windows\system32\mswsock.dll
          + 2008-04-14 12:00 . 2008-06-20 16:03 247808 c:\windows\system32\mswsock.dll
          + 2008-04-14 12:00 . 2009-08-05 09:00 205312 c:\windows\system32\mswebdvd.dll
          + 2008-04-14 12:00 . 2009-09-11 14:18 136192 c:\windows\system32\msv1_0.dll
          + 2002-01-01 11:40 . 2011-01-27 11:57 677888 c:\windows\system32\mstsc.exe
          - 2002-01-01 11:40 . 2008-04-14 12:00 677888 c:\windows\system32\mstsc.exe
          + 2008-04-14 12:00 . 2011-06-23 18:31 611840 c:\windows\system32\mstime.dll
          + 2008-04-14 12:00 . 2009-03-08 02:34 193536 c:\windows\system32\msrating.dll
          + 2002-01-01 11:40 . 2009-12-17 07:41 347648 c:\windows\system32\mspaint.exe
          - 2002-01-01 11:40 . 2008-04-14 12:00 347648 c:\windows\system32\mspaint.exe
          + 2008-04-14 12:00 . 2009-03-08 02:22 156160 c:\windows\system32\msls31.dll
          - 2002-01-01 11:40 . 2008-04-14 12:00 161792 c:\windows\system32\msdtcuiu.dll
          + 2002-01-01 11:40 . 2008-06-12 14:22 161792 c:\windows\system32\msdtcuiu.dll
          + 2002-01-01 11:40 . 2008-06-12 14:22 956928 c:\windows\system32\msdtctm.dll
          - 2002-01-01 11:40 . 2008-04-14 12:00 956928 c:\windows\system32\msdtctm.dll
          + 2002-01-01 11:40 . 2008-06-12 14:22 428032 c:\windows\system32\msdtcprx.dll
          + 2009-01-07 16:20 . 2009-01-07 16:20 265720 c:\windows\system32\msdbg2.dll
          - 2009-01-07 16:20 . 2009-01-07 17:20 265720 c:\windows\system32\msdbg2.dll
          - 2008-04-14 12:00 . 2008-04-14 12:00 384512 c:\windows\system32\mp4sdmod.dll
          + 2008-04-14 12:00 . 2010-04-05 09:54 384512 c:\windows\system32\mp4sdmod.dll
          + 2008-04-14 12:00 . 2011-02-08 13:34 974848 c:\windows\system32\mfc42u.dll
          + 2008-04-14 12:00 . 2011-02-08 13:34 978944 c:\windows\system32\mfc42.dll
          + 2008-04-14 12:00 . 2010-09-18 06:53 953856 c:\windows\system32\mfc40u.dll
          + 2008-04-14 12:00 . 2010-09-18 06:53 954368 c:\windows\system32\mfc40.dll
          + 2011-09-17 10:11 . 2011-09-17 10:12 243360 c:\windows\system32\Macromed\Flash\FlashUtil10w_ActiveX.exe
          + 2011-09-17 10:12 . 2011-09-17 10:12 328864 c:\windows\system32\Macromed\Flash\FlashUtil10w_ActiveX.dll
          + 2008-04-14 12:00 . 2010-12-20 17:26 736768 c:\windows\system32\lsasrv.dll
          + 2008-04-14 12:00 . 2009-05-07 15:33 348672 c:\windows\system32\localspl.dll
          + 2008-04-14 12:00 . 2010-12-22 12:34 301568 c:\windows\system32\kerberos.dll
          + 2008-04-14 12:00 . 2011-03-04 06:36 726528 c:\windows\system32\jscript.dll
          + 2002-01-01 11:42 . 2011-05-02 15:31 692736 c:\windows\system32\inetcomm.dll
          + 2008-04-14 12:00 . 2011-06-23 18:31 184320 c:\windows\system32\iepeers.dll
          + 2008-04-14 12:00 . 2011-06-23 18:31 387584 c:\windows\system32\iedkcs32.dll
          + 2008-04-14 12:00 . 2009-03-08 02:32 163840 c:\windows\system32\ieakui.dll
          + 2008-04-14 12:00 . 2009-03-08 02:33 229376 c:\windows\system32\ieaksie.dll
          + 2008-04-14 12:00 . 2009-03-08 02:33 125952 c:\windows\system32\ieakeng.dll
          + 2008-04-14 12:00 . 2011-06-23 12:05 173568 c:\windows\system32\ie4uinit.exe
          + 2008-04-14 12:00 . 2008-10-23 12:36 286720 c:\windows\system32\gdi32.dll
          - 2002-01-01 12:34 . 2011-09-08 15:15 180240 c:\windows\system32\FNTCACHE.DAT
          + 2002-01-01 12:34 . 2011-09-09 08:18 180240 c:\windows\system32\FNTCACHE.DAT
          + 2008-04-14 12:00 . 2008-07-07 20:28 253952 c:\windows\system32\es.dll
          - 2008-04-14 12:00 . 2008-04-14 12:00 186880 c:\windows\system32\encdec.dll
          + 2008-04-14 12:00 . 2011-02-09 13:54 186880 c:\windows\system32\encdec.dll
          + 2008-04-14 12:00 . 2009-03-08 02:31 216064 c:\windows\system32\dxtrans.dll
          + 2008-04-14 12:00 . 2009-03-08 02:31 348160 c:\windows\system32\dxtmsft.dll
          + 2008-04-14 12:00 . 2010-02-11 12:02 226880 c:\windows\system32\drivers\tcpip6.sys
          + 2008-04-14 12:00 . 2008-06-20 11:51 361600 c:\windows\system32\drivers\tcpip.sys
          + 2008-04-14 12:00 . 2011-02-17 13:18 357888 c:\windows\system32\drivers\srv.sys
          + 2008-04-14 12:00 . 2008-05-08 14:02 203136 c:\windows\system32\drivers\rmcast.sys
          - 2002-01-01 11:40 . 2008-04-14 12:00 139656 c:\windows\system32\drivers\rdpwd.sys
          + 2002-01-01 11:40 . 2011-06-24 14:10 139656 c:\windows\system32\drivers\rdpwd.sys
          + 2008-04-14 12:00 . 2011-04-21 13:37 105472 c:\windows\system32\drivers\mup.sys
          + 2008-04-14 12:00 . 2009-10-20 16:20 265728 c:\windows\system32\drivers\http.sys
          + 2008-04-14 12:00 . 2008-06-14 17:33 272768 c:\windows\system32\drivers\bthport.sys
          + 2008-04-14 12:00 . 2011-02-16 13:22 138496 c:\windows\system32\drivers\afd.sys
          + 2008-04-14 12:00 . 2011-03-03 06:55 149504 c:\windows\system32\dnsapi.dll
          + 2002-01-01 11:42 . 2009-08-06 17:24 209632 c:\windows\system32\dllcache\wuweb.dll
          + 2002-01-01 11:42 . 2009-08-06 17:24 327896 c:\windows\system32\dllcache\wucltui.dll
          + 2002-01-01 11:42 . 2009-08-06 17:23 575704 c:\windows\system32\dllcache\wuapi.dll
          + 2008-04-14 12:00 . 2008-05-08 11:24 155648 c:\windows\system32\dllcache\wscript.exe
          - 2008-04-14 12:00 . 2008-04-14 12:00 155648 c:\windows\system32\dllcache\wscript.exe
          + 2002-01-01 11:40 . 2010-07-16 12:04 221696 c:\windows\system32\dllcache\wordpad.exe
          + 2008-04-14 12:00 . 2009-04-09 23:01 413032 c:\windows\system32\dllcache\wmspdmod.dll
          + 2008-04-14 12:00 . 2009-07-12 10:21 233472 c:\windows\system32\dllcache\wmpdxm.dll
          - 2008-04-14 12:00 . 2008-04-14 12:00 233472 c:\windows\system32\dllcache\wmpdxm.dll
          + 2002-01-01 11:40 . 2009-02-06 10:10 227840 c:\windows\system32\dllcache\wmiprvse.exe
          + 2002-01-01 11:40 . 2009-02-09 10:53 453120 c:\windows\system32\dllcache\wmiprvsd.dll
          + 2008-04-14 12:00 . 2007-10-20 04:01 227328 c:\windows\system32\dllcache\wmasf.dll
          - 2008-04-14 12:00 . 2008-04-14 12:00 132096 c:\windows\system32\dllcache\wkssvc.dll
          + 2008-04-14 12:00 . 2009-06-10 06:15 132096 c:\windows\system32\dllcache\wkssvc.dll
          + 2008-04-14 12:00 . 2009-12-24 07:00 177664 c:\windows\system32\dllcache\wintrust.dll
          - 2008-04-14 12:00 . 2008-04-14 12:00 293888 c:\windows\system32\dllcache\winsrv.dll
          + 2008-04-14 12:00 . 2011-06-20 17:44 293888 c:\windows\system32\dllcache\winsrv.dll
          + 2008-04-14 12:00 . 2011-06-23 18:31 916480 c:\windows\system32\dllcache\wininet.dll
          + 2008-04-14 12:00 . 2009-08-25 09:18 354816 c:\windows\system32\dllcache\winhttp.dll
          + 2008-04-14 12:00 . 2008-08-28 07:47 105472 c:\windows\system32\dllcache\win32spl.dll
          + 2008-04-14 12:00 . 2009-03-08 02:34 236544 c:\windows\system32\dllcache\webcheck.dll
          + 2002-01-01 11:42 . 2011-04-30 03:01 758784 c:\windows\system32\dllcache\vgx.dll
          + 2008-04-14 12:00 . 2011-03-04 06:36 420864 c:\windows\system32\dllcache\vbscript.dll
          + 2008-04-14 12:00 . 2010-04-16 15:38 406016 c:\windows\system32\dllcache\usp10.dll
          - 2008-04-14 12:00 . 2008-04-14 12:00 406016 c:\windows\system32\dllcache\usp10.dll
          + 2008-04-14 12:00 . 2011-06-23 18:31 105984 c:\windows\system32\dllcache\url.dll
          + 2002-01-01 11:42 . 2009-06-21 21:47 153088 c:\windows\system32\dllcache\triedit.dll
          - 2002-01-01 11:42 . 2008-04-14 12:00 153088 c:\windows\system32\dllcache\triedit.dll
          + 2008-04-14 12:00 . 2010-02-11 12:02 226880 c:\windows\system32\dllcache\tcpip6.sys
          + 2008-04-14 12:00 . 2008-06-20 11:51 361600 c:\windows\system32\dllcache\tcpip.sys
          + 2008-04-14 12:00 . 2010-08-27 08:02 119808 c:\windows\system32\dllcache\t2embed.dll
          + 2008-04-14 12:00 . 2009-08-26 08:01 247326 c:\windows\system32\dllcache\strmdll.dll
          + 2008-04-14 12:00 . 2011-02-17 13:18 357888 c:\windows\system32\dllcache\srv.sys
          + 2009-01-07 16:20 . 2009-01-07 16:20 134144 c:\windows\system32\dllcache\sqmapi.dll
          + 2008-04-14 12:00 . 2009-07-27 23:17 135680 c:\windows\system32\dllcache\shsvcs.dll
          - 2008-04-14 12:00 . 2008-04-14 12:00 135680 c:\windows\system32\dllcache\shsvcs.dll
          + 2008-04-14 12:00 . 2009-12-08 09:24 474624 c:\windows\system32\dllcache\shlwapi.dll
          - 2008-04-14 12:00 . 2008-04-14 12:00 474624 c:\windows\system32\dllcache\shlwapi.dll
          + 2008-04-14 12:00 . 2011-01-21 14:44 441344 c:\windows\system32\dllcache\shimgvw.dll
          + 2008-04-14 12:00 . 2009-02-09 11:23 111104 c:\windows\system32\dllcache\services.exe
          + 2008-04-14 12:00 . 2008-05-09 10:55 172032 c:\windows\system32\dllcache\scrrun.dll
          - 2008-04-14 12:00 . 2008-04-14 12:00 172032 c:\windows\system32\dllcache\scrrun.dll
          - 2008-04-14 12:00 . 2008-04-14 12:00 180224 c:\windows\system32\dllcache\scrobj.dll
          + 2008-04-14 12:00 . 2008-05-09 10:55 180224 c:\windows\system32\dllcache\scrobj.dll
          + 2008-04-14 12:00 . 2011-04-29 17:25 151552 c:\windows\system32\dllcache\schannel.dll
          - 2008-04-14 12:00 . 2008-04-14 12:00 270848 c:\windows\system32\dllcache\sbe.dll
          + 2008-04-14 12:00 . 2011-02-09 13:54 270848 c:\windows\system32\dllcache\sbe.dll
          + 2008-04-14 12:00 . 2009-02-09 10:53 401408 c:\windows\system32\dllcache\rpcss.dll
          + 2008-04-14 12:00 . 2010-08-16 08:44 590848 c:\windows\system32\dllcache\rpcrt4.dll
          + 2008-04-14 12:00 . 2008-05-08 14:02 203136 c:\windows\system32\dllcache\rmcast.sys
          - 2002-01-01 11:40 . 2008-04-14 12:00 139656 c:\windows\system32\dllcache\rdpwd.sys
          + 2002-01-01 11:40 . 2011-06-24 14:10 139656 c:\windows\system32\dllcache\rdpwd.sys
          + 2008-04-14 12:00 . 2009-10-12 13:39 150528 c:\windows\system32\dllcache\rastls.dll
          + 2008-04-14 12:00 . 2009-03-06 14:20 286720 c:\windows\system32\dllcache\pdh.dll
          - 2008-04-14 12:00 . 2008-04-14 12:00 286720 c:\windows\system32\dllcache\pdh.dll
          + 2008-04-14 12:00 . 2010-12-20 17:32 551936 c:\windows\system32\dllcache\oleaut32.dll
          - 2008-04-14 12:00 . 2008-04-14 12:00 551936 c:\windows\system32\dllcache\oleaut32.dll
          + 2008-04-14 12:00 . 2010-11-09 14:52 249856 c:\windows\system32\dllcache\odbc32.dll
          - 2008-04-14 12:00 . 2008-04-14 12:00 249856 c:\windows\system32\dllcache\odbc32.dll
          + 2008-04-14 12:00 . 2011-06-23 18:31 206848 c:\windows\system32\dllcache\occache.dll
          - 2008-04-14 12:00 . 2008-04-14 12:00 271360 c:\windows\system32\dllcache\oakley.dll
          + 2008-04-14 12:00 . 2009-10-13 10:33 271360 c:\windows\system32\dllcache\oakley.dll
          + 2008-04-14 12:00 . 2010-12-09 15:15 743424 c:\windows\system32\dllcache\ntdll.dll
          - 2008-04-14 12:00 . 2008-04-14 12:00 337408 c:\windows\system32\dllcache\netapi32.dll
          + 2008-04-14 12:00 . 2008-10-15 16:35 337408 c:\windows\system32\dllcache\netapi32.dll
          + 2008-04-14 12:00 . 2011-04-21 13:37 105472 c:\windows\system32\dllcache\mup.sys
          - 2008-04-14 12:00 . 2008-04-14 12:00 247808 c:\windows\system32\dllcache\mswsock.dll
          + 2008-04-14 12:00 . 2008-06-20 16:03 247808 c:\windows\system32\dllcache\mswsock.dll
          + 2008-04-14 12:00 . 2009-08-05 09:00 205312 c:\windows\system32\dllcache\mswebdvd.dll
          + 2008-04-14 12:00 . 2009-09-11 14:18 136192 c:\windows\system32\dllcache\msv1_0.dll
          + 2008-04-14 12:00 . 2011-06-23 18:31 611840 c:\windows\system32\dllcache\mstime.dll
          + 2008-04-14 12:00 . 2009-03-08 02:34 193536 c:\windows\system32\dllcache\msrating.dll
          - 2002-01-01 11:40 . 2008-04-14 12:00 347648 c:\windows\system32\dllcache\mspaint.exe
          + 2002-01-01 11:40 . 2009-12-17 07:41 347648 c:\windows\system32\dllcache\mspaint.exe
          + 2008-04-14 12:00 . 2009-03-08 02:22 156160 c:\windows\system32\dllcache\msls31.dll
          + 2002-01-01 11:42 . 2010-11-09 14:52 102400 c:\windows\system32\dllcache\msjro.dll
          - 2002-01-01 11:42 . 2008-04-14 12:00 102400 c:\windows\system32\dllcache\msjro.dll
          - 2002-01-01 11:40 . 2008-04-14 12:00 161792 c:\windows\system32\dllcache\msdtcuiu.dll
          + 2002-01-01 11:40 . 2008-06-12 14:22 161792 c:\windows\system32\dllcache\msdtcuiu.dll
          - 2002-01-01 11:40 . 2008-04-14 12:00 956928 c:\windows\system32\dllcache\msdtctm.dll
          + 2002-01-01 11:40 . 2008-06-12 14:22 956928 c:\windows\system32\dllcache\msdtctm.dll
          + 2002-01-01 11:40 . 2008-06-12 14:22 428032 c:\windows\system32\dllcache\msdtcprx.dll
          - 2002-01-01 11:42 . 2008-04-14 12:00 200704 c:\windows\system32\dllcache\msadox.dll
          + 2002-01-01 11:42 . 2010-11-09 14:52 200704 c:\windows\system32\dllcache\msadox.dll
          + 2002-01-01 11:42 . 2010-11-09 14:52 180224 c:\windows\system32\dllcache\msadomd.dll
          - 2002-01-01 11:42 . 2008-04-14 12:00 180224 c:\windows\system32\dllcache\msadomd.dll
          + 2002-01-01 11:42 . 2010-11-09 14:52 536576 c:\windows\system32\dllcache\msado15.dll
          - 2002-01-01 11:42 . 2008-04-14 12:00 536576 c:\windows\system32\dllcache\msado15.dll
          + 2002-01-01 11:42 . 2010-11-09 14:52 143360 c:\windows\system32\dllcache\msadco.dll
          - 2002-01-01 11:42 . 2008-04-14 12:00 143360 c:\windows\system32\dllcache\msadco.dll
          + 2002-01-01 11:42 . 2008-05-01 14:36 331776 c:\windows\system32\dllcache\msadce.dll
          - 2002-01-01 11:42 . 2008-04-14 12:00 331776 c:\windows\system32\dllcache\msadce.dll
          + 2008-04-14 12:00 . 2010-04-05 09:54 384512 c:\windows\system32\dllcache\mp4sdmod.dll
          - 2008-04-14 12:00 . 2008-04-14 12:00 384512 c:\windows\system32\dllcache\mp4sdmod.dll
          + 2010-03-30 10:24 . 2010-03-30 10:24 317440 c:\windows\system32\dllcache\mp4sdecd.dll
          + 2008-04-14 12:00 . 2011-02-08 13:34 974848 c:\windows\system32\dllcache\mfc42u.dll
          + 2008-04-14 12:00 . 2011-02-08 13:34 978944 c:\windows\system32\dllcache\mfc42.dll
          + 2008-04-14 12:00 . 2010-09-18 06:53 953856 c:\windows\system32\dllcache\mfc40u.dll
          + 2008-04-14 12:00 . 2010-09-18 06:53 954368 c:\windows\system32\dllcache\mfc40.dll
          + 2008-04-14 12:00 . 2010-12-20 17:26 736768 c:\windows\system32\dllcache\lsasrv.dll
          + 2008-04-14 12:00 . 2009-05-07 15:33 348672 c:\windows\system32\dllcache\localspl.dll
          - 2002-01-01 11:40 . 2008-04-14 12:00 677888 c:\windows\system32\dllcache\lhmstsc.exe
          + 2002-01-01 11:40 . 2011-01-27 11:57 677888 c:\windows\system32\dllcache\lhmstsc.exe
          + 2008-04-14 12:00 . 2010-12-22 12:34 301568 c:\windows\system32\dllcache\kerberos.dll
          + 2008-04-14 12:00 . 2011-03-04 06:36 726528 c:\windows\system32\dllcache\jscript.dll
          + 2002-01-01 11:42 . 2011-05-02 15:31 692736 c:\windows\system32\dllcache\inetcomm.dll
          + 2002-01-01 11:42 . 2009-03-08 12:09 638816 c:\windows\system32\dllcache\iexplore.exe
          + 2008-04-14 12:00 . 2011-06-23 18:31 184320 c:\windows\system32\dllcache\iepeers.dll
          + 2008-04-14 12:00 . 2011-06-23 18:31 387584 c:\windows\system32\dllcache\iedkcs32.dll
          + 2008-04-14 12:00 . 2009-03-08 02:32 163840 c:\windows\system32\dllcache\ieakui.dll
          + 2008-04-14 12:00 . 2009-03-08 02:33 229376 c:\windows\system32\dllcache\ieaksie.dll
          + 2008-04-14 12:00 . 2009-03-08 02:33 125952 c:\windows\system32\dllcache\ieakeng.dll
          + 2008-04-14 12:00 . 2011-06-23 12:05 173568 c:\windows\system32\dllcache\ie4uinit.exe
          + 2009-10-20 16:20 . 2009-10-20 16:20 265728 c:\windows\system32\dllcache\http.sys
          + 2002-01-01 11:42 . 2010-06-14 14:31 744448 c:\windows\system32\dllcache\helpsvc.exe
          - 2002-01-01 11:42 . 2008-04-14 12:00 744448 c:\windows\system32\dllcache\helpsvc.exe
          + 2008-04-14 12:00 . 2008-10-23 12:36 286720 c:\windows\system32\dllcache\gdi32.dll
          + 2002-01-01 11:40 . 2009-02-09 10:53 473600 c:\windows\system32\dllcache\fastprox.dll
          + 2008-04-14 12:00 . 2008-07-07 20:28 253952 c:\windows\system32\dllcache\es.dll
          + 2008-04-14 12:00 . 2011-02-09 13:54 186880 c:\windows\system32\dllcache\encdec.dll
          - 2008-04-14 12:00 . 2008-04-14 12:00 186880 c:\windows\system32\dllcache\encdec.dll
          + 2008-04-14 12:00 . 2009-03-08 02:31 216064 c:\windows\system32\dllcache\dxtrans.dll
          + 2008-04-14 12:00 . 2009-03-08 02:31 348160 c:\windows\system32\dllcache\dxtmsft.dll
          + 2008-04-14 12:00 . 2011-03-03 06:55 149504 c:\windows\system32\dllcache\dnsapi.dll
          + 2008-04-14 12:00 . 2008-05-07 09:07 135168 c:\windows\system32\dllcache\cscript.exe
          - 2008-04-14 12:00 . 2008-04-14 12:00 606208 c:\windows\system32\dllcache\crypt32.dll
          + 2008-04-14 12:00 . 2011-09-09 09:12 606208 c:\windows\system32\dllcache\crypt32.dll
          + 2008-04-14 12:00 . 2010-08-23 16:12 617472 c:\windows\system32\dllcache\comctl32.dll
          - 2008-04-14 12:00 . 2008-04-14 12:00 617472 c:\windows\system32\dllcache\comctl32.dll
          + 2008-04-14 12:00 . 2011-02-15 12:56 290432 c:\windows\system32\dllcache\atmfd.dll
          + 2008-04-14 12:00 . 2011-02-16 13:22 138496 c:\windows\system32\dllcache\afd.sys
          + 2008-04-14 12:00 . 2009-03-08 02:32 128512 c:\windows\system32\dllcache\advpack.dll
          + 2008-04-14 12:00 . 2009-02-09 10:53 685568 c:\windows\system32\dllcache\advapi32.dll
          - 2008-04-14 12:00 . 2008-04-14 12:00 685568 c:\windows\system32\dllcache\advapi32.dll
          + 2008-04-14 12:00 . 2009-11-21 15:58 471552 c:\windows\system32\dllcache\aclayers.dll
          + 2008-04-14 12:00 . 2010-02-12 04:34 100864 c:\windows\system32\dllcache\6to4svc.dll
          + 2008-04-14 12:00 . 2008-05-07 09:07 135168 c:\windows\system32\cscript.exe
          - 2008-04-14 12:00 . 2008-04-14 12:00 617472 c:\windows\system32\comctl32.dll
          + 2008-04-14 12:00 . 2010-08-23 16:12 617472 c:\windows\system32\comctl32.dll
          + 2008-04-14 12:00 . 2011-02-15 12:56 290432 c:\windows\system32\atmfd.dll
          + 2008-04-14 12:00 . 2009-03-08 02:32 128512 c:\windows\system32\advpack.dll
          - 2008-04-14 12:00 . 2008-04-14 12:00 685568 c:\windows\system32\advapi32.dll
          + 2008-04-14 12:00 . 2009-02-09 10:53 685568 c:\windows\system32\advapi32.dll
          + 2008-04-14 12:00 . 2010-02-12 04:34 100864 c:\windows\system32\6to4svc.dll
          - 2002-01-01 11:42 . 2008-04-14 12:00 744448 c:\windows\pchealth\helpctr\binaries\HelpSvc.exe
          + 2002-01-01 11:42 . 2010-06-14 14:31 744448 c:\windows\pchealth\helpctr\binaries\helpsvc.exe
          + 2011-06-06 10:55 . 2011-06-06 10:55 249232 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA76301B744AA0100000010\10.1.0\sqlite.dll
          + 2011-06-06 10:55 . 2011-06-06 10:55 394136 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA76301B744AA0100000010\10.1.0\pdfshell.dll
          + 2011-06-06 10:55 . 2011-06-06 10:55 103848 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA76301B744AA0100000010\10.1.0\PDFPrevHndlrShim.exe
          + 2011-06-06 10:55 . 2011-06-06 10:55 183696 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA76301B744AA0100000010\10.1.0\nppdf32.dll
          + 2011-06-06 10:55 . 2011-06-06 10:55 104344 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA76301B744AA0100000010\10.1.0\AiodLite.dll
          + 2011-06-06 10:55 . 2011-06-06 10:55 102808 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA76301B744AA0100000010\10.1.0\AcroRdIF.dll
          + 2011-06-06 10:55 . 2011-06-06 10:55 755088 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA76301B744AA0100000010\10.1.0\AcroPDF.dll
          + 2011-06-06 10:55 . 2011-06-06 10:55 296344 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA76301B744AA0100000010\10.1.0\acrobroker.exe
          + 2011-06-06 10:55 . 2011-06-06 10:55 205720 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA76301B744AA0100000010\10.1.0\a3dutils.dll
          + 2010-06-09 12:10 . 2009-03-08 02:34 914944 c:\windows\ie8updates\KB982381-IE8\wininet.dll
          + 2011-09-09 08:13 . 2010-02-22 14:25 406392 c:\windows\ie8updates\KB982381-IE8\updspapi.dll
          + 2011-09-09 08:13 . 2009-05-26 11:40 767352 c:\windows\ie8updates\KB982381-IE8\update.exe
          + 2011-09-09 08:13 . 2008-07-08 13:03 234872 c:\windows\ie8updates\KB982381-IE8\spuninst.exe
          + 2010-06-09 12:10 . 2009-03-08 02:34 109568 c:\windows\ie8updates\KB982381-IE8\occache.dll
          - 2010-06-09 12:10 . 2010-02-25 06:17 611840 c:\windows\ie8updates\KB982381-IE8\mstime.dll
          + 2010-06-09 12:10 . 2009-03-08 02:32 611840 c:\windows\ie8updates\KB982381-IE8\mstime.dll
          + 2010-06-09 12:10 . 2009-03-08 02:31 183808 c:\windows\ie8updates\KB982381-IE8\iepeers.dll
          + 2010-06-09 12:10 . 2009-03-08 12:09 391536 c:\windows\ie8updates\KB982381-IE8\iedkcs32.dll
          - 2010-06-09 12:10 . 2010-02-24 09:55 173056 c:\windows\ie8updates\KB982381-IE8\ie4uinit.exe
          + 2010-06-09 12:10 . 2009-03-08 02:32 173056 c:\windows\ie8updates\KB982381-IE8\ie4uinit.exe
          + 2011-08-10 08:26 . 2010-05-06 10:33 916480 c:\windows\ie8updates\KB2559049-IE8\wininet.dll
          - 2011-08-10 08:26 . 2011-04-25 16:06 916480 c:\windows\ie8updates\KB2559049-IE8\wininet.dll
          + 2011-08-10 08:26 . 2009-03-08 02:34 105984 c:\windows\ie8updates\KB2559049-IE8\url.dll
          - 2011-08-10 08:26 . 2009-03-08 03:34 105984 c:\windows\ie8updates\KB2559049-IE8\url.dll
          + 2011-09-09 08:13 . 2010-07-05 13:17 406392 c:\windows\ie8updates\KB2559049-IE8\updspapi.dll
          + 2011-09-09 08:13 . 2010-07-05 13:17 767352 c:\windows\ie8updates\KB2559049-IE8\update.exe
          + 2011-09-09 08:13 . 2010-07-05 13:17 234872 c:\windows\ie8updates\KB2559049-IE8\spuninst.exe
          - 2011-08-10 08:26 . 2011-04-25 16:06 206848 c:\windows\ie8updates\KB2559049-IE8\occache.dll
          + 2011-08-10 08:26 . 2010-05-06 10:33 206848 c:\windows\ie8updates\KB2559049-IE8\occache.dll
          - 2011-08-10 08:26 . 2011-04-25 16:06 611840 c:\windows\ie8updates\KB2559049-IE8\mstime.dll
          + 2011-08-10 08:26 . 2010-05-06 10:33 611840 c:\windows\ie8updates\KB2559049-IE8\mstime.dll
          + 2011-08-10 08:26 . 2010-05-06 10:33 599040 c:\windows\ie8updates\KB2559049-IE8\msfeeds.dll
          + 2011-08-10 08:26 . 2010-05-06 10:33 247808 c:\windows\ie8updates\KB2559049-IE8\ieproxy.dll
          - 2011-08-10 08:26 . 2011-04-25 16:06 247808 c:\windows\ie8updates\KB2559049-IE8\ieproxy.dll
          - 2011-08-10 08:26 . 2011-04-25 16:06 184320 c:\windows\ie8updates\KB2559049-IE8\iepeers.dll
          + 2011-08-10 08:26 . 2010-05-06 10:33 184320 c:\windows\ie8updates\KB2559049-IE8\iepeers.dll
          - 2011-08-10 08:26 . 2011-04-25 16:06 743424 c:\windows\ie8updates\KB2559049-IE8\iedvtool.dll
          + 2011-08-10 08:26 . 2010-05-06 10:33 743424 c:\windows\ie8updates\KB2559049-IE8\iedvtool.dll
          - 2011-08-10 08:26 . 2011-04-25 16:06 387584 c:\windows\ie8updates\KB2559049-IE8\iedkcs32.dll
          + 2011-08-10 08:26 . 2010-05-06 10:33 387584 c:\windows\ie8updates\KB2559049-IE8\iedkcs32.dll
          + 2011-08-10 08:26 . 2010-05-05 13:30 173056 c:\windows\ie8updates\KB2559049-IE8\ie4uinit.exe
          - 2011-06-14 18:39 . 2009-03-08 03:33 759296 c:\windows\ie8updates\KB2544521-IE8\vgx.dll
          + 2011-06-14 18:39 . 2009-03-08 02:33 759296 c:\windows\ie8updates\KB2544521-IE8\vgx.dll
          + 2011-09-09 08:46 . 2010-07-05 13:17 406392 c:\windows\ie8updates\KB2544521-IE8\updspapi.dll
          + 2011-09-09 08:46 . 2010-07-05 13:17 767352 c:\windows\ie8updates\KB2544521-IE8\update.exe
          + 2011-09-09 08:46 . 2010-07-05 13:17 234872 c:\windows\ie8updates\KB2544521-IE8\spuninst.exe
          + 2011-04-12 18:00 . 2009-03-08 02:33 420352 c:\windows\ie8updates\KB2510531-IE8\vbscript.dll
          - 2011-04-12 18:00 . 2010-03-10 06:16 420352 c:\windows\ie8updates\KB2510531-IE8\vbscript.dll
          + 2011-09-09 08:45 . 2010-07-05 13:18 406392 c:\windows\ie8updates\KB2510531-IE8\updspapi.dll
          + 2011-09-09 08:45 . 2010-07-05 13:17 767352 c:\windows\ie8updates\KB2510531-IE8\update.exe
          + 2011-09-09 08:45 . 2010-07-05 13:17 234872 c:\windows\ie8updates\KB2510531-IE8\spuninst.exe
          + 2011-04-12 18:00 . 2009-03-08 02:33 726528 c:\windows\ie8updates\KB2510531-IE8\jscript.dll
          - 2011-04-12 18:00 . 2009-12-09 05:54 726528 c:\windows\ie8updates\KB2510531-IE8\jscript.dll
          + 2010-02-27 13:27 . 2011-06-21 18:19 671232 c:\windows\ie8\wininet.dll
          + 2010-02-27 13:27 . 2008-04-14 12:00 281600 c:\windows\ie8\webcheck.dll
          + 2010-02-27 13:27 . 2011-04-29 19:07 852480 c:\windows\ie8\vgx.dll
          + 2010-02-27 13:27 . 2011-03-04 06:45 434176 c:\windows\ie8\vbscript.dll
          + 2010-02-27 13:27 . 2011-06-21 18:19 629248 c:\windows\ie8\urlmon.dll
          - 2010-02-27 13:29 . 2009-01-07 17:21 406048 c:\windows\ie8\spuninst\updspapi.dll
          + 2010-02-27 13:29 . 2009-01-07 16:21 406048 c:\windows\ie8\spuninst\updspapi.dll
          + 2010-02-27 13:29 . 2009-01-07 16:21 235040 c:\windows\ie8\spuninst\spuninst.exe
          - 2010-02-27 13:29 . 2009-01-07 17:21 235040 c:\windows\ie8\spuninst\spuninst.exe
          + 2011-09-09 08:11 . 2011-06-21 18:19 532480 c:\windows\ie8\mstime.dll
          + 2011-09-09 08:11 . 2008-04-14 12:00 146432 c:\windows\ie8\msrating.dll
          + 2011-09-09 08:11 . 2008-04-14 12:00 146432 c:\windows\ie8\msls31.dll
          + 2011-09-09 08:11 . 2011-06-21 18:19 449536 c:\windows\ie8\mshtmled.dll
          + 2011-09-09 08:11 . 2011-03-04 06:45 512000 c:\windows\ie8\jscript.dll
          - 2010-02-27 13:27 . 2008-05-09 10:55 512000 c:\windows\ie8\jscript.dll
          + 2011-09-09 08:11 . 2011-06-21 18:19 251904 c:\windows\ie8\iepeers.dll
          + 2011-09-09 08:11 . 2008-04-14 12:00 323584 c:\windows\ie8\iedkcs32.dll
          + 2011-09-09 08:11 . 2008-04-14 12:00 245760 c:\windows\ie8\ieakui.dll
          + 2011-09-09 08:11 . 2008-04-14 12:00 221184 c:\windows\ie8\ieaksie.dll
          + 2011-09-09 08:11 . 2008-04-14 12:00 143360 c:\windows\ie8\ieakeng.dll
          + 2011-09-09 08:11 . 2008-04-14 12:00 205312 c:\windows\ie8\dxtrans.dll
          + 2011-09-09 08:11 . 2008-04-14 12:00 357888 c:\windows\ie8\dxtmsft.dll
          + 2011-09-09 08:11 . 2008-04-14 12:00 101888 c:\windows\ie8\advpack.dll
          + 2011-09-09 07:46 . 2011-07-15 13:29 456320 c:\windows\Driver Cache\i386\mrxsmb.sys
          + 2009-10-20 16:20 . 2009-10-20 16:20 265728 c:\windows\Driver Cache\i386\http.sys
          + 2011-09-09 07:47 . 2008-06-14 17:33 272768 c:\windows\Driver Cache\i386\bthport.sys
          + 2008-04-14 12:00 . 2009-11-21 15:58 471552 c:\windows\AppPatch\aclayers.dll
          - 2009-12-10 20:12 . 2009-05-26 16:11 406392 c:\windows\$hf_mig$\KB955759\update\updspapi.dll
          + 2009-12-10 20:12 . 2009-05-26 15:11 406392 c:\windows\$hf_mig$\KB955759\update\updspapi.dll
          + 2011-09-09 07:43 . 2010-10-23 00:51 1748992 c:\windows\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.6002.22509_x-ww_c7dad023\GdiPlus.dll
          - 2011-04-12 17:26 . 2010-10-23 00:51 1748992 c:\windows\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.
          1. Contributeur sécurité
            ok ton rapport est pas complet peux tu le poster par le biais de cijoint , merci
        6. Bonjour,

          Oui, mon PC fonctionne normalement en mode sans échec. Seul mon antivirus ne veut plus s'activer.

          J'ai plusieurs logiciels de désinfection comme Malwerebytes et tous les autres téléchargés précédemment (ZHPDiag, etc ...)
          1. Contributeur sécurité
            je te demandais si ton pc fonctionnait normalement en mode normal pas en mode sans echec ??
            en mode sans echec normal que ton anti-virus de fonctionne pas !!

            pour les outils télécharger on les supprimera avec un outil qui supprimeras les outils et les rapport , la fais combofix si possible en démarrrant le pc normalement
        7. Je suis en mode sans échec en ce moment et effectivement lorsque je suis en mode normal, je ne vois aucune trace de " Security Sphere 2012".
          Merci beaucoup à Jacques !

          Je pense qu'il reste d'autres analyses à faire pour être sur ?
          J'attend vos conseils :)
          1. Contributeur sécurité
            bonjours , bon il y a des reste !!

            Gen salut si tu vois des choses que j'ai pas vu no problèmes tu peux intervenir !!

            haveaproblem ton pc fonctionne t'il normalement en mode normal , si oui tu fais ce qui suit en mode normal, merci

            Avant d'utiliser ComboFix :

            Les logiciels d'émulation de CD comme Daemon Tools peuvent gêner les outils de désinfection. Utilise Defogger pour les désactiver temporairement :

            si tu as ce genre de d'outils sur ton pc Utilise Defogger pour les désactiver temporairement : sinon passe directement à combofix

            . Télécharge Defogger (de jpshortstuff)sur ton Bureau

            . Lance le

            Une fenêtre apparait : clique sur "Disable"

            . Fais redémarrer l'ordinateur si l'outil te le demande

            Note : Quand nous aurons terminé la désinfection, tu pourras réactiver ces logiciels en relançant Defogger et en cliquant sur "Re-enable"

            Tutoriel officiel prends le temps de le regarder : https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix

            et

            note bien cette manipe https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix#restore car des fois après combofix la connection internet est déactivée

            Télécharge Combofix.exe de sUBs sur ton Bureau,

            http://download.bleepingcomputer.com/sUBs/ComboFix.exe

            Déconnectes toi d'internet et désactives ton antivirus et toutes protection résidente, pour que Combofix puisse s'exécuter normalement.

            Doubles clique sur Combofix.exe

            Mets le en langue française F

            Tape sur la touche 1 (Yes) pour démarrer le scan.

            tu ne touches pas au pc pendant qu'il travail sauf pour répondre quand il te le demande.

            si il te propose d'installer la console de récuppération accepte cela permet à l'outil de nettoyer certain fichiers système , et de réparrer si besion !!

            En fin de scan, il est possible que ComboFix ait besoin de redémarrer le PC pour finaliser la désinfection, laisse-le faire.

            Une fois le scan achevé, un rapport va s'afficher : Poste son contenu

            Réactives la protection en temps réel de ton Antivirus et de tes Antispywares, avant de te reconnecter à Internet.

            Note : Le rapport se trouve également là : C:\Combofix.txt
        8. bah déjà Jacques t'as levé une belle épine du pied je pense que ton pc devrait marcher mieux depuis ce passage d'outils non ?
          • 1
          • 2