Help ! Multiple virus?

Bonjour,



Depuis quelques jours, j'ai choppé un virus et j'arrive pas à l'enlever, j'espère que vous pourrez m'aider.

Ca a commencé avec la barre Searchqu, puis mes recherches google sont redirigées. Maintenant ça désactive mes antivirus, ça fait planter les scans des antivirus et je n'arrive pas à télécharger des .exe... ça crée des .part... J'ai un autre ordi à dispo pour télécharger des programmes et les transférer mais je sais plus par ou commencer.

Même le scan au démarrage de Avast plante lorsqu'il trouve un certain fichier infecté. Parmi les fichiers infectés il y a des Win32: Patched WQ...

Que dois-je faire?

MERCI BEAUCOUP!!

Galaxie

26 réponses

Résumé de la discussion

Une infection sous Windows XP et Firefox 7.0.1 provoque des redirections de recherches via Searchqu et la désactivation des antivirus, rendant les scans invalides et les téléchargements de fichiers .exe difficiles. Des conseils consistent à analyser le système avec des outils de sécurité comme ZHPDiag et OTL, puis à recourir à des remèdes dédiés tels que ZeroAccess Remover ou Webroot AntiZeroAccess. Les échanges évoquent des fichiers infectés repérés dans C:\Windows et les sauvegardes, avec des éléments comme BackDoor et Trojan signalés en désinfection partielle, quarantaine ou suppression selon les outils employés. En complément, certains évoquent la nécessité de mettre à jour les outils et de reprendre l’analyse après nettoyage, afin de confirmer l’absence de composants persistants et d’éviter les réinfections.

Bobot (l’IA à votre service)
  1. Re

    Sauvegarde tes données les plus importantes et réinstalle ton système à partir d'une sauvegarde si tu en disposes ou sinon à neuf.

    @+
    0
    1. OK, merci beaucoup quand même pour ton aide!
      Tu peux juste me dire quel virus j'ai eu ou quel est le problème qui fait que on peut pas résoudre le problème?
      0
    2. Tu as eu un cheval de Troie, souvent appelé "Trojan" (du nom anglophone Trojan horse)
      0
  2. Re

    * Télécharge http://www.geekstogo.com/forum/files/file/398-otl-oldtimers-list-it/ sur ton bureau.

    * Fait un double-clic sur l'icône d'OTL pour le lancer
    /!\ pour Vista/Seven fais un clic-droit sur l'icône d'OTL et choisis "Exécuter en tant qu'administrateur"

    * Assure toi d'avoir fermé toutes les applications en cours de fonctionnement.

    * Quand la fenêtre d'OTL apparaît, assure toi que dans la section "Rapport" (en haut à droite) la case "Rapport minimal" soit cochée.

    * Copies et colles le contenu de cette citation dans la partie inférieure d'OTL "Personnalisation"

    netsvcs
    msconfig
    safebootminimal
    safebootnetwork
    activex
    drivers32
    %ALLUSERSPROFILE%\Application Data\*.
    %ALLUSERSPROFILE%\Application Data\*.exe /s
    %SYSTEMDRIVE%\*.exe
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    cdrom.sys
    disk.sys
    ndis.sys
    mountmgr.sys
    aec.sys
    rasacd.sys
    mrxsmb10.sys
    mrxsmb20.sys
    termdd.sys
    mrxsmb.sys
    win32k.sys
    storport.sys
    IdeChnDr.sys
    viasraid.sys
    explorer.exe
    winlogon.exe
    wininit.exe
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    ahcix86.sys
    KR10N.sys
    nvstor32.sys
    ahcix86s.sys
    nvrd32.sys
    /md5stop
    %systemroot%\*. /mp /s
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\system32\drivers\*.sys /lockedfiles
    %systemroot%\System32\config\*.sav
    CREATERESTOREPOINT


    * Cliques sur l'icône "Analyse" (en haut à gauche) .
    * Laisse le scan aller à son terme sans te servir du PC
    * A la fin du scan un ou deux rapports vont s'ouvrir "OTL.Txt" et ( ou ) "Extras.Txt"( dans certains cas).
    * Copie et colle le ou les rapports dans ta réponse stp...
    * Au cas où, tu peux les retrouver dans le dossier C:\OTL ou sur ton bureau en fonction des cas rencontrés

    @+
    0
    1. OTL logfile created on: 16.11.2011 22:05:50 - Run 1
      OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Utilisateur\Bureau
      Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
      Internet Explorer (Version = 8.0.6001.18702)
      Locale: 0000100C | Country: Suisse | Language: FRS | Date Format: dd.MM.yyyy

      1.99 Gb Total Physical Memory | 1.57 Gb Available Physical Memory | 78.99% Memory free
      3.33 Gb Paging File | 3.09 Gb Available in Paging File | 92.77% Paging File free
      Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]

      %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
      Drive C: | 55.89 Gb Total Space | 17.33 Gb Free Space | 31.01% Space Free | Partition Type: NTFS

      Computer Name: UTILISAT-2BCF2C | User Name: Utilisateur | Logged in as Administrator.
      Boot Mode: Normal | Scan Mode: Current user
      Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

      [color=#E56717]========== Processes (SafeList) ==========/color

      PRC - C:\Documents and Settings\Utilisateur\Bureau\OTL.exe (OldTimer Tools)
      PRC - C:\Program Files\Ask.com\Updater\Updater.exe ({StringFileInfo_CompanyName})
      PRC - C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
      PRC - C:\Documents and Settings\Utilisateur\Application Data\HP SimpleSave Application\StartHelper.exe ()
      PRC - C:\Program Files\Adobe\Acrobat 9.0\Acrobat\acrotray.exe (Adobe Systems Inc.)
      PRC - C:\Program Files\Fichiers communs\Java\Java Update\jusched.exe (Sun Microsystems, Inc.)
      PRC - C:\Program Files\Sony\PMB\PMBVolumeWatcher.exe (Sony Corporation)
      PRC - C:\Program Files\HP\ToolboxFX\bin\HPTLBXFX.exe (HP)
      PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
      PRC - C:\Program Files\Fichiers communs\LightScribe\LightScribeControlPanel.exe (Hewlett-Packard Company)
      PRC - C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe (Analog Devices, Inc.)

      [color=#E56717]========== Modules (No Company Name) ==========/color

      MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\81096bfe85eb0da5f05e8a127ffa43b2\System.Runtime.Serialization.Formatters.Soap.ni.dll ()
      MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Deployment\cc5ac99e8af2738e85cda5525fdd944f\System.Deployment.ni.dll ()
      MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\bce0720436dc6cb76006377f295ea365\System.Configuration.ni.dll ()
      MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\70cacc44f0b4257f6037eda7a59a0aeb\System.Xml.ni.dll ()
      MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\71a2ae9ad561a62181cbd9fb11e9de7a\System.Windows.Forms.ni.dll ()
      MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\c10bea3c4bb7ef654651141bf9419090\System.Drawing.ni.dll ()
      MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\af39f6e644af02873b9bae319f2bfb13\System.ni.dll ()
      MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\ca87ba84221991839abbe7d4bc9c6721\mscorlib.ni.dll ()
      MOD - C:\WINDOWS\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll ()
      MOD - C:\Program Files\FileZilla FTP Client\fzshellext.dll ()
      MOD - C:\Documents and Settings\Utilisateur\Application Data\HP SimpleSave Application\StartHelper.exe ()
      MOD - C:\Program Files\Adobe\Acrobat 9.0\Acrobat\AcroTray.DEU ()
      MOD - C:\Program Files\Adobe\Acrobat 9.0\Acrobat\AcroTray.FRA ()
      MOD - C:\Program Files\HP\ToolboxFX\bin\HPFaxUtilities.dll ()
      MOD - C:\Program Files\HP\ToolboxFX\bin\Alerts.dll ()
      MOD - C:\Program Files\HP\ToolboxFX\bin\HPAppTools.dll ()
      MOD - C:\Program Files\HP\ToolboxFX\bin\HPToolkit.dll ()
      MOD - C:\Program Files\HP\ToolboxFX\bin\AppConstants.dll ()
      MOD - C:\Program Files\HP\ToolboxFX\bin\Enumeration.dll ()
      MOD - C:\Program Files\HP\ToolboxFX\bin\HPStreamsInterface.dll ()
      MOD - C:\Program Files\HP\ToolboxFX\bin\HPTools.dll ()
      MOD - C:\Program Files\HP\ToolboxFX\bin\NativeUtils.dll ()
      MOD - C:\WINDOWS\system32\msdmo.dll ()
      MOD - C:\Program Files\Fichiers communs\LightScribe\QtGui4.dll ()
      MOD - C:\Program Files\Fichiers communs\LightScribe\plugins\imageformats\qjpeg4.dll ()
      MOD - C:\Program Files\Fichiers communs\LightScribe\QtCore4.dll ()

      [color=#E56717]========== Win32 Services (SafeList) ==========/color

      SRV - (AntiVirSchedulerService) -- File not found
      SRV - (AntiVirService) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
      SRV - (MsMpSvc) -- c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe ()
      SRV - (odserv) -- C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE12\ODSERV.EXE (Microsoft Corporation)
      SRV - (Adobe Version Cue CS3) -- C:\Program Files\Fichiers communs\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe (Adobe Systems Incorporated)
      SRV - (ose) -- C:\Program Files\Fichiers communs\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
      SRV - (IDriverT) -- c:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)

      [color=#E56717]========== Driver Services (SafeList) ==========/color

      DRV - (Cdrom) -- C:\WINDOWS\system32\drivers\tsk7D.tmp (Microsoft Corporation)
      DRV - (PCTBD) -- C:\WINDOWS\system32\drivers\PCTBD.sys (PC Tools)
      DRV - (avipbb) -- C:\WINDOWS\system32\drivers\avipbb.sys (Avira GmbH)
      DRV - (avgntflt) -- C:\WINDOWS\system32\drivers\avgntflt.sys (Avira GmbH)
      DRV - (avgio) -- C:\Program Files\Avira\AntiVir Desktop\avgio.sys (Avira GmbH)
      DRV - (ssmdrv) -- C:\WINDOWS\system32\drivers\ssmdrv.sys (Avira GmbH)
      DRV - (s24trans) -- C:\WINDOWS\system32\drivers\s24trans.sys (Intel Corporation)
      DRV - (w29n51) Pilote de carte de connexion réseau Intel(R) -- C:\WINDOWS\system32\drivers\w29n51.sys (Intel® Corporation)
      DRV - (tifm21) -- C:\WINDOWS\system32\drivers\tifm21.sys (Texas Instruments)
      DRV - (HPFXBULK) -- C:\WINDOWS\system32\drivers\hpfxbulk.sys (Hewlett Packard)
      DRV - (incdrm) -- C:\WINDOWS\system32\drivers\InCDRm.sys (Nero AG)
      DRV - (InCDPass) -- C:\WINDOWS\system32\drivers\InCDPass.sys (Nero AG)
      DRV - (InCDfs) -- C:\WINDOWS\system32\drivers\InCDfs.sys (Nero AG)
      DRV - (HpqKbFiltr) -- C:\WINDOWS\system32\drivers\HpqKbFiltr.sys (Hewlett-Packard Development Company, L.P.)
      DRV - (GTIPCI21) -- C:\WINDOWS\system32\drivers\gtipci21.sys (Texas Instruments)
      DRV - (b57w2k) -- C:\WINDOWS\system32\drivers\b57xp32.sys (Broadcom Corporation)
      DRV - (AgereSoftModem) -- C:\WINDOWS\system32\drivers\AGRSM.sys (Agere Systems)
      DRV - (IFXTPM) -- C:\WINDOWS\system32\drivers\ifxtpm.sys (Infineon Technologies AG)
      DRV - (MarvinBus) -- C:\WINDOWS\system32\drivers\MarvinBus.sys (Pinnacle Systems GmbH)
      DRV - (SMCIRDA) -- C:\WINDOWS\system32\drivers\smcirda.sys (SMC)

      [color=#E56717]========== Standard Registry (SafeList) ==========/color

      [color=#E56717]========== Internet Explorer ==========/color

      IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/toolbar/ie8/sidebar.html

      IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://www.google.ch/?gws_rd=ssl
      IE - HKCU\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
      IE - HKCU\..\URLSearchHook: {472734EA-242A-422b-ADF8-83D1E48CC825} - C:\Program Files\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
      IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
      IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = proxyhes.etat-ge.ch:80

      [color=#E56717]========== FireFox ==========/color

      FF - prefs.js..browser.search.defaultengine: "Ask.com"
      FF - prefs.js..browser.search.defaultenginename: "Ask.com"
      FF - prefs.js..browser.search.order.1: "Ask.com"
      FF - prefs.js..browser.search.selectedEngine: "Google"
      FF - prefs.js..browser.search.useDBForOrder: true
      FF - prefs.js..browser.startup.homepage: "mail.maisondelariviere.ch"
      FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
      FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
      FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
      FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
      FF - prefs.js..extensions.enabledItems: {d04b0b40-3dab-4f0b-97a6-04ec3eddbfb0}:2.0.6
      FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:5.0.0.6906
      FF - prefs.js..extensions.enabledItems: {23fcfd51-4958-4f00-80a3-ae97e717ed8b}:2.1.1.94
      FF - prefs.js..extensions.enabledItems: {6904342A-8307-11DF-A508-4AE2DFD72085}:2.1.1.94
      FF - prefs.js..keyword.URL: "http://www.search.ask.com/?l=dis"
      FF - prefs.js..network.proxy.backup.ftp: "proxyhes.etat-ge.ch"
      FF - prefs.js..network.proxy.backup.ftp_port: 80
      FF - prefs.js..network.proxy.backup.gopher: "proxyhes.etat-ge.ch"
      FF - prefs.js..network.proxy.backup.gopher_port: 80
      FF - prefs.js..network.proxy.backup.socks: "proxyhes.etat-ge.ch"
      FF - prefs.js..network.proxy.backup.socks_port: 80
      FF - prefs.js..network.proxy.backup.ssl: "proxyhes.etat-ge.ch"
      FF - prefs.js..network.proxy.backup.ssl_port: 80
      FF - prefs.js..network.proxy.ftp: "proxyhes.etat-ge.ch"
      FF - prefs.js..network.proxy.ftp_port: 80
      FF - prefs.js..network.proxy.gopher: "proxyhes.etat-ge.ch"
      FF - prefs.js..network.proxy.gopher_port: 80
      FF - prefs.js..network.proxy.http: "proxyhes.etat-ge.ch"
      FF - prefs.js..network.proxy.http_port: 80
      FF - prefs.js..network.proxy.no_proxies_on: "localhost, 127.0.0.1, 195.176.237.102"
      FF - prefs.js..network.proxy.share_proxy_settings: true
      FF - prefs.js..network.proxy.socks: "proxyhes.etat-ge.ch"
      FF - prefs.js..network.proxy.socks_port: 80
      FF - prefs.js..network.proxy.ssl: "proxyhes.etat-ge.ch"
      FF - prefs.js..network.proxy.ssl_port: 80
      FF - prefs.js..network.proxy.type: 0

      FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
      FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
      FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
      FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
      FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa2,version=2.0.0: C:\Program Files\Picasa2\npPicasa2.dll (Google, Inc.)
      FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Picasa2\npPicasa3.dll (Google, Inc.)
      FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
      FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
      FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
      FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=8: C:\Program Files\Google\Update\1.2.183.39\npGoogleOneClick8.dll (Google Inc.)
      FF - HKLM\Software\MozillaPlugins\Adobe Acrobat: C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.)

      FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files\DivX\DivX Plus Web Player\firefox\html5video [2011.04.10 20:28:20 | 000,000,000 | ---D | M]
      FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{6904342A-8307-11DF-A508-4AE2DFD72085}: C:\Program Files\DivX\DivX Plus Web Player\firefox\wpa [2011.04.10 20:28:20 | 000,000,000 | ---D | M]
      FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{cb84136f-9c44-433a-9048-c5cd9df1dc16}: C:\Program Files\PC Tools\PC Tools Security\BDT\Firefox\ [2011.11.04 16:11:49 | 000,000,000 | ---D | M]
      FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011.11.16 09:26:38 | 000,000,000 | ---D | M]
      FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011.06.18 17:45:44 | 000,000,000 | ---D | M]

      [2011.10.26 11:15:15 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Utilisateur\Application Data\Mozilla\Extensions
      [2011.11.04 14:31:02 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Utilisateur\Application Data\Mozilla\Firefox\Profiles\l3v10nov.default\extensions
      [2010.06.24 12:57:44 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Utilisateur\Application Data\Mozilla\Firefox\Profiles\l3v10nov.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
      [2011.05.06 07:06:30 | 000,000,000 | ---D | M] (Ecosia - The Green Search) -- C:\Documents and Settings\Utilisateur\Application Data\Mozilla\Firefox\Profiles\l3v10nov.default\extensions\{d04b0b40-3dab-4f0b-97a6-04ec3eddbfb0}
      [2011.11.09 11:00:12 | 000,000,000 | ---D | M] ("Avira SearchFree Toolbar plus Web Protection") -- C:\Documents and Settings\Utilisateur\Application Data\Mozilla\Firefox\Profiles\l3v10nov.default\extensions\toolbar@ask.com
      [2011.11.16 09:27:56 | 000,002,406 | ---- | M] () -- C:\Documents and Settings\Utilisateur\Application Data\Mozilla\Firefox\Profiles\l3v10nov.default\searchplugins\askcom.xml
      [2011.05.06 07:06:50 | 000,005,212 | ---- | M] () -- C:\Documents and Settings\Utilisateur\Application Data\Mozilla\Firefox\Profiles\l3v10nov.default\searchplugins\ecosia.xml
      [2011.11.16 09:26:59 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
      [2010.04.19 08:10:03 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
      [2011.11.16 09:26:38 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
      [2010.09.15 03:50:38 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
      [2011.05.10 21:32:52 | 000,001,516 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazon-france.xml
      [2011.05.10 21:32:52 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
      [2011.05.10 21:32:52 | 000,001,822 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\cnrtl-tlfi-fr.xml
      [2011.05.10 21:32:52 | 000,001,154 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-france.xml
      [2011.10.25 17:03:28 | 000,002,520 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\SearchResults.xml
      [2011.05.10 21:32:52 | 000,001,426 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-fr.xml
      [2011.05.10 21:32:52 | 000,000,956 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-france.xml

      [color=#E56717]========== Chrome ==========/color

      CHR - default_search_provider: Google (Enabled)
      CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
      CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms}
      CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\15.0.874.106\gcswf32.dll
      CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
      CHR - plugin: Java Deployment Toolkit 6.0.220.4 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
      CHR - plugin: Java(TM) Platform SE 6 U22 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
      CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Browser\nppdf32.dll
      CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll
      CHR - plugin: Shockwave for Director (Enabled) = C:\WINDOWS\system32\Adobe\Director\np32dsw.dll
      CHR - plugin: DivX Web Player (Enabled) = C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll
      CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
      CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
      CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\15.0.874.106\ppGoogleNaClPluginChrome.dll
      CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\15.0.874.106\pdf.dll
      CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
      CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
      CHR - plugin: DivX VOD Helper Plug-in (Enabled) = C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll
      CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.2.183.39\npGoogleOneClick8.dll
      CHR - plugin: Picasa (Enabled) = C:\Program Files\Picasa2\npPicasa2.dll
      CHR - plugin: Picasa (Enabled) = C:\Program Files\Picasa2\npPicasa3.dll
      CHR - plugin: Windows Presentation Foundation (Enabled) = c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
      CHR - plugin: Default Plug-in (Enabled) = default_plugin
      CHR - Extension: DivX HiQ = C:\Documents and Settings\Utilisateur\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\fnjbmmemklcjgepojigaapkoodmkgbae\2.1.1.94_0\
      CHR - Extension: \u003Cvideo\u003E HTML5 DivX Plus Web Player = C:\Documents and Settings\Utilisateur\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.1.94_0\

      O1 HOSTS File: ([2011.11.06 17:57:27 | 000,000,789 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
      O1 - Hosts: 127.0.0.1 localhost
      O2 - BHO: (HP Print Enhancer) - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
      O2 - BHO: (HP Print Clips) - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll (Hewlett-Packard Co.)
      O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
      O2 - BHO: (PC Tools Browser Defender BHO) - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
      O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
      O2 - BHO: (DivX HiQ) - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
      O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
      O2 - BHO: (Avira SearchFree Toolbar plus Web Protection) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
      O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
      O3 - HKLM\..\Toolbar: (PC Tools Browser Defender) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
      O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
      O3 - HKLM\..\Toolbar: (Avira SearchFree Toolbar plus Web Protection) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
      O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
      O3 - HKCU\..\Toolbar\WebBrowser: (PC Tools Browser Defender) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
      O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
      O3 - HKCU\..\Toolbar\WebBrowser: (Avira SearchFree Toolbar plus Web Protection) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
      O4 - HKLM..\Run: [] File not found
      O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
      O4 - HKLM..\Run: [Adobe Acrobat Speed Launcher] C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe (Adobe Systems Incorporated)
      O4 - HKLM..\Run: [Adobe ARM] C:\Program Files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
      O4 - HKLM..\Run: [ApnUpdater] C:\Program Files\Ask.com\Updater\Updater.exe ({StringFileInfo_CompanyName})
      O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
      O4 - HKLM..\Run: [HPPQVideo] "C:\Program Files\HP\ScheduledLaunch\HP Color LaserJet CM1312 MFP Series\bin\hppschlnch.exe" -r SOFTWARE\Hewlett-Packard\ScheduledLaunch\CLJ_CM1312_MFP_Series -f PQOptimizerVideo.xml -o remindLater File not found
      O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
      O4 - HKLM..\Run: [PMBVolumeWatcher] C:\Program Files\Sony\PMB\PMBVolumeWatcher.exe (Sony Corporation)
      O4 - HKLM..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe (Analog Devices, Inc.)
      O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Fichiers communs\Java\Java Update\jusched.exe (Sun Microsystems, Inc.)
      O4 - HKLM..\Run: [ToolBoxFX] C:\Program Files\HP\ToolBoxFX\bin\HPTLBXFX.exe (HP)
      O4 - HKCU..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe (Nero AG)
      O4 - HKCU..\Run: [LightScribe Control Panel] C:\Program Files\Fichiers communs\LightScribe\LightScribeControlPanel.exe (Hewlett-Packard Company)
      O4 - Startup: C:\Documents and Settings\Utilisateur\Menu Démarrer\Programmes\Démarrage\HP SimpleSave Monitor.lnk = C:\Documents and Settings\Utilisateur\Application Data\HP SimpleSave Application\StartHelper.exe ()
      O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
      O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
      O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
      O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
      O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
      O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
      O8 - Extra context menu item: &Download with BitKinex - C:\Program Files\BitKinex\ieext_cp.htm ()
      O8 - Extra context menu item: &Register in BitKinex - C:\Program Files\BitKinex\ieext_reg.htm ()
      O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
      O8 - Extra context menu item: Ajouter à un fichier PDF existant - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
      O8 - Extra context menu item: Ajouter la cible du lien à un fichier PDF existant - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
      O8 - Extra context menu item: Convertir au format Adobe PDF - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
      O8 - Extra context menu item: Convertir la cible du lien au format Adobe PDF - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
      O9 - Extra Button: Livre de reliures HP - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll (Hewlett-Packard Co.)
      O9 - Extra Button: Sélection intelligente HP - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll (Hewlett-Packard Co.)
      O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Computer, Inc.)
      O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
      O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
      O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
      O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
      O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
      O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
      O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
      O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
      O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
      O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
      O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
      O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
      O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
      O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
      O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
      O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
      O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
      O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
      O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
      O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 62.2.17.60 62.2.24.162 62.2.17.61 62.2.24.158
      O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{6C134142-6AF4-4F41-AC50-B8DE0E6820DC}: DhcpNameServer = 62.2.17.60 62.2.24.162 62.2.17.61 62.2.24.158
      O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
      O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
      O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
      O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Fichiers communs\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
      O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
      O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
      O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
      O20 - HKCU Winlogon: Shell - (C:\Documents and Settings\Utilisateur\Local Settings\Application Data\b4c73fa4\X) -C:\Documents and Settings\Utilisateur\Local Settings\Application Data\b4c73fa4\X ()
      O24 - Desktop Components:0 (Ma page d'accueil) - About:Home
      O24 - Desktop WallPaper: C:\Documents and Settings\Utilisateur\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
      O24 - Desktop BackupWallPaper: C:\Documents and Settings\Utilisateur\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
      O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
      O32 - HKLM CDRom: AutoRun - 1
      O32 - AutoRun File - [2009.09.10 16:47:27 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
      O33 - MountPoints2\{4a69bd26-14aa-11df-8adf-001560c59743}\Shell\AutoRun\command - "" = E:\SamsungSoftware\APPInst.exe
      O33 - MountPoints2\{b4258462-17b5-11df-8ae3-001560c59743}\Shell - "" = AutoRun
      O33 - MountPoints2\{b4258462-17b5-11df-8ae3-001560c59743}\Shell\AutoRun\command - "" = E:\HPLauncher.exe
      O34 - HKLM BootExecute: (autocheck autochk *)
      O35 - HKLM\..comfile [open] -- "%1" %*
      O35 - HKLM\..exefile [open] -- "%1" %*
      O37 - HKLM\...com [@ = comfile] -- "%1" %*
      O37 - HKLM\...exe [@ = exefile] -- "%1" %*

      NetSvcs: 6to4 - File not found
      NetSvcs: Ias - File not found
      NetSvcs: Iprip - File not found
      NetSvcs: NWCWorkstation - File not found
      NetSvcs: Nwsapagent - File not found
      NetSvcs: WmdmPmSp - File not found

      MsConfig - StartUpFolder: C:^Documents and Settings^Utilisateur^Menu Démarrer^Programmes^Démarrage^OneNote 2007 - Capture d'écran et lancement.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE - (Microsoft Corporation)
      MsConfig - StartUpReg: [b]Adobe Reader Speed Launcher/b - hkey= - key= - File not found
      MsConfig - StartUpReg: [b]AGRSMMSG/b - hkey= - key= - C:\WINDOWS\AGRSMMSG.exe (Agere Systems)
      MsConfig - StartUpReg: [b]BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}/b - hkey= - key= - C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe (Nero AG)
      MsConfig - StartUpReg: [b]InCD/b - hkey= - key= - C:\Program Files\Nero\Nero 7\InCD\InCD.exe (Nero AG)
      MsConfig - StartUpReg: [b]IntelWireless/b - hkey= - key= - C:\Program Files\Fichiers communs\Intel\WirelessCommon\iFrmewrk.exe (Intel(R) Corporation)
      MsConfig - StartUpReg: [b]IntelZeroConfig/b - hkey= - key= - C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe (Intel(R) Corporation)
      MsConfig - StartUpReg: [b]LightScribe Control Panel/b - hkey= - key= - C:\Program Files\Fichiers communs\LightScribe\LightScribeControlPanel.exe (Hewlett-Packard Company)
      MsConfig - StartUpReg: [b]NeroFilterCheck/b - hkey= - key= - C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe (Nero AG)
      MsConfig - StartUpReg: [b]SecurDisc/b - hkey= - key= - C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe (Nero AG)
      MsConfig - State: "system.ini" - 0
      MsConfig - State: "win.ini" - 0
      MsConfig - State: "bootini" - 0
      MsConfig - State: "services" - 0
      MsConfig - State: "startup" - 2

      SafeBootMin: 07972014.sys - Driver
      SafeBootMin: 63347720.sys - Driver
      SafeBootMin: Base - Driver Group
      SafeBootMin: Boot Bus Extender - Driver Group
      SafeBootMin: Boot file system - Driver Group
      SafeBootMin: File system - Driver Group
      SafeBootMin: Filter - Driver Group
      SafeBootMin: Lavasoft Ad-Aware Service - Service
      SafeBootMin: MsMpSvc - c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe ()
      SafeBootMin: PCI Configuration - Driver Group
      SafeBootMin: PEVSystemStart - Service
      SafeBootMin: PNP Filter - Driver Group
      SafeBootMin: Primary disk - Driver Group
      SafeBootMin: procexp90.Sys - Driver
      SafeBootMin: SCSI Class - Driver Group
      SafeBootMin: sermouse.sys - Driver
      SafeBootMin: System Bus Extender - Driver Group
      SafeBootMin: vds - Service
      SafeBootMin: vga.sys - Driver
      SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
      SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
      SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
      SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
      SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
      SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
      SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
      SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
      SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
      SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
      SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
      SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
      SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
      SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices

      SafeBootNet: 07972014.sys - Driver
      SafeBootNet: 63347720.sys - Driver
      SafeBootNet: Base - Driver Group
      SafeBootNet: Boot Bus Extender - Driver Group
      SafeBootNet: Boot file system - Driver Group
      SafeBootNet: File system - Driver Group
      SafeBootNet: Filter - Driver Group
      SafeBootNet: Lavasoft Ad-Aware Service - Service
      SafeBootNet: MsMpSvc - c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe ()
      SafeBootNet: NDIS Wrapper - Driver Group
      SafeBootNet: NetBIOSGroup - Driver Group
      SafeBootNet: NetDDEGroup - Driver Group
      SafeBootNet: Network - Driver Group
      SafeBootNet: NetworkProvider - Driver Group
      SafeBootNet: PCI Configuration - Driver Group
      SafeBootNet: PEVSystemStart - Service
      SafeBootNet: PNP Filter - Driver Group
      SafeBootNet: PNP_TDI - Driver Group
      SafeBootNet: Primary disk - Driver Group
      SafeBootNet: procexp90.Sys - Driver
      SafeBootNet: SCSI Class - Driver Group
      SafeBootNet: sermouse.sys - Driver
      SafeBootNet: Streams Drivers - Driver Group
      SafeBootNet: System Bus Extender - Driver Group
      SafeBootNet: TDI - Driver Group
      SafeBootNet: vga.sys - Driver
      SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
      SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
      SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
      SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
      SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
      SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
      SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
      SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
      SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
      SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
      SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
      SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
      SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
      SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
      SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
      SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
      SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices

      ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Microsoft VM
      ActiveX: {10072CEC-8CC1-11D1-986E-00A0C955B42F} - Rendu VML (Vector Graphics Rendering)
      ActiveX: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "C:\Program Files\Fichiers communs\LightScribe\LSRunOnce.exe"
      ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} - Microsoft NetShow Player
      ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 6.4
      ActiveX: {283807B5-2C60-11D0-A31D-00AA00B92C03} - DirectAnimation
      ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
      ActiveX: {36f8ec70-c29a-11d1-b5c7-0000f8051515} - Liaison de données Dynamic HTML pour Java
      ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
      ActiveX: {3bf42070-b3b1-11d1-b5c5-0000f8051515} - Uniscribe
      ActiveX: {4278c270-a269-11d1-b5bf-0000f8051515} - Création avancée
      ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install
      ActiveX: {44BBA842-CC51-11CF-AAFA-00AA00B6015B} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT
      ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} - DirectShow
      ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
      ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
      ActiveX: {4f216970-c90c-11d1-b5c7-0000f8051515} - Classes Java DirectAnimation
      ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.8
      ActiveX: {5056b317-8d4c-43ee-8543-b9d1e234b8f4} - Mise à jour de sécurité pour Windows XP (KB923789)
      ActiveX: {5945c046-1e7d-11d1-bc44-00c04fd912be} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser
      ActiveX: {5A8D6EE0-3E18-11D0-821E-444553540000} - ICW
      ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
      ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
      ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
      ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
      ActiveX: {7131646D-CD3C-40F4-97B9-CD9E4E6262EF} - .NET Framework
      ActiveX: {73fa19d0-2d75-11d2-995d-00c04f98bbc9} - Web Folders
      ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install
      ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
      ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\WINDOWS\system32\ie4uinit.exe -BaseSettings
      ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - c:\WINDOWS\system32\Rundll32.exe c:\WINDOWS\system32\mscories.dll,Install
      ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
      ActiveX: {C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F} - .NET Framework
      ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
      ActiveX: {CC2A9BA0-3BDD-11D0-821E-444553540000} - Planificateur de tâches
      ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1
      ActiveX: {D27CDB6E-AE6D-11cf-96B8-444553540000} - Reg Error: Value error.
      ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
      ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
      ActiveX: <{12d0ed0d-0ee0-4f90-8827-78cefb8f4988} - C:\WINDOWS\system32\ieudinit.exe
      ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\WINDOWS\inf\unregmp2.exe /ShowWMP
      ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\WINDOWS\system32\ie4uinit.exe -UserIconConfig
      ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
      ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS - RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP
      ActiveX: >{881dd1c5-3dcf-431b-b061-f3f88e8be88a} - %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE

      Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
      Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
      Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
      Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
      Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
      Drivers32: vidc.DIVX - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
      Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
      Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
      Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
      Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
      Drivers32: vidc.mjpg - pvmjpg30.dll File not found
      Drivers32: vidc.yv12 - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)

      CREATERESTOREPOINT
      Restore point Set: OTL Restore Point

      [color=#E56717]========== Files/Folders - Created Within 30 Days ==========/color

      File not found -- C:\WINDOWS\System32\
      [2011.11.16 22:04:40 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Utilisateur\Bureau\OTL.exe
      [2011.11.16 21:19:20 | 000,518,144 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
      [2011.11.16 21:19:20 | 000,406,528 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
      [2011.11.16 21:19:20 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
      [2011.11.16 21:19:20 | 000,060,416 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
      [2011.11.16 21:19:11 | 000,000,000 | --SD | C] -- C:\asdehi23862a
      [2011.11.16 21:19:03 | 000,000,000 | ---D | C] -- C:\Qoobox
      [2011.11.16 21:17:41 | 004,297,251 | R--- | C] (Swearware) -- C:\Documents and Settings\Utilisateur\Bureau\asdehi.exe
      [2011.11.16 14:50:05 | 000,000,000 | --SD | C] -- C:\asdehi31690a
      [2011.11.16 14:14:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Utilisateur\Bureau\Anim Philippe
      [2011.11.06 17:25:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Utilisateur\Mes documents\Downloads
      [2011.11.06 10:50:10 | 000,000,000 | --SD | C] -- C:\asdehi
      [2011.11.05 11:55:58 | 000,000,000 | RHSD | C] -- C:\cmdcons
      [2011.11.05 11:51:29 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
      [2011.11.05 11:50:03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Utilisateur\Local Settings\Application Data\PCHealth
      [2011.11.05 10:23:52 | 000,094,896 | ---- | C] (Kaspersky Lab, GERT) -- C:\WINDOWS\System32\drivers\15855302.sys
      [2011.11.05 10:20:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Utilisateur\Bureau\tdsskiller
      [2011.11.05 10:04:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Utilisateur\Bureau\Antivirus forum
      [2011.11.04 16:33:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Google Chrome
      [2011.11.04 16:32:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Utilisateur\Local Settings\Application Data\Temp
      [2011.11.04 16:28:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Utilisateur\Local Settings\Application Data\Threat Expert
      [2011.11.04 15:35:10 | 023,635,896 | ---- | C] (Citrix Systems, Inc.) -- C:\Documents and Settings\Utilisateur\Bureau\CitrixReceiver.exe
      [2011.11.04 15:34:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Utilisateur\Application Data\Download Manager
      [2011.11.04 15:04:37 | 000,056,840 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\PCTBD.sys
      [2011.11.04 15:04:35 | 002,291,664 | ---- | C] (Threat Expert Ltd.) -- C:\WINDOWS\PCTBDCore.dll1146.old
      [2011.11.04 15:04:35 | 002,291,664 | ---- | C] (Threat Expert Ltd.) -- C:\WINDOWS\PCTBDCore.dll
      [2011.11.04 15:04:35 | 000,149,456 | ---- | C] (PC Tools) -- C:\WINDOWS\SGDetectionTool.dll1146.old
      [2011.11.04 15:04:35 | 000,149,456 | ---- | C] (PC Tools) -- C:\WINDOWS\SGDetectionTool.dll
      [2011.11.04 15:04:34 | 001,681,360 | ---- | C] (Threat Expert Ltd.) -- C:\WINDOWS\PCTBDRes.dll
      [2011.11.04 15:00:52 | 000,000,000 | ---D | C] -- C:\Program Files\PC Tools
      [2011.11.04 14:57:05 | 000,185,560 | ---- | C] (PC Tools) -- C:\WINDOWS\System32\drivers\PCTSD.sys
      [2011.11.04 14:57:04 | 000,000,000 | ---D | C] -- C:\Program Files\Fichiers communs\PC Tools
      [2011.11.04 14:52:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Utilisateur\Application Data\TestApp
      [2011.11.04 14:48:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Utilisateur\Application Data\AskToolbar
      [2011.11.04 14:31:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Utilisateur\Local Settings\Application Data\AskToolbar
      [2011.11.04 14:31:02 | 000,000,000 | ---D | C] -- C:\Program Files\Ask.com
      [2011.11.04 12:25:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Utilisateur\Application Data\Uniblue
      [2011.11.04 12:25:22 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\All Users\Application Data\{83C3B2FD-37EA-4C06-A228-E9B5E32FF0B1}
      [2011.11.04 12:25:22 | 000,000,000 | ---D | C] -- C:\Program Files\Uniblue
      [2011.11.04 12:25:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Uniblue
      [2011.11.04 12:24:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Utilisateur\Local Settings\Application Data\PackageAware
      [2011.11.04 11:47:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Utilisateur\Bureau\Nettoyage
      [2011.11.04 10:11:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Utilisateur\Bureau\MDLR
      [2011.10.28 12:46:06 | 000,021,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\hidserv.dll
      [2011.10.28 12:45:53 | 000,060,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\usbaudio.sys
      [2011.10.27 19:41:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\AVAST Software
      [2011.10.27 13:38:27 | 000,000,000 | ---D | C] -- C:\Program Files\Spybot - Search & Destroy
      [2011.10.26 15:00:17 | 000,000,000 | ---D | C] -- C:\Program Files\Lavasoft
      [2011.10.26 15:00:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Lavasoft
      [2011.10.26 14:23:13 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Utilisateur\Recent
      [2011.10.26 13:32:05 | 000,000,000 | ---D | C] -- C:\spoolerlogs
      [2011.10.25 21:20:26 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Utilisateur\Application Data\searchquband
      [2011.10.25 21:20:26 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Utilisateur\AppData
      [2011.10.25 16:40:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\boost_interprocess
      [2011.10.25 15:27:10 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ptpusb.dll
      [2011.10.25 15:27:09 | 000,159,232 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ptpusd.dll
      [2011.10.25 15:23:03 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Searchqu Toolbar
      [2011.10.23 20:13:59 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Utilisateur\Local Settings\Application Data\b4c73fa4
      [2011.05.09 09:17:33 | 016,212,232 | ---- | C] (Dropbox, Inc.) -- C:\Program Files\Dropbox 1.1.31.exe
      [2011.04.14 08:17:11 | 004,847,439 | ---- | C] (Koyote Soft ) -- C:\Program Files\Setup_FreeVideoConverter.exe
      [2011.03.15 09:53:36 | 008,465,752 | ---- | C] (Barad-Dur, LLC. ) -- C:\Program Files\bitkinex323.exe
      [2011.02.28 11:20:25 | 007,734,208 | ---- | C] (Malwarebytes Corporation ) -- C:\Program Files\mbam-setup.exe
      [2011.02.27 12:18:49 | 006,277,496 | ---- | C] (Microsoft Corporation) -- C:\Program Files\Silverlight.exe
      [2011.02.17 19:39:25 | 002,832,544 | ---- | C] (Adobe Systems, Inc.) -- C:\Program Files\install_flash_player.exe
      [2011.02.10 12:10:18 | 005,191,576 | ---- | C] (YouSendIt ) -- C:\Program Files\YouSendItExpressSetup2_8_1.exe
      [2011.01.07 10:23:21 | 021,164,424 | ---- | C] (Skype Technologies S.A.) -- C:\Program Files\SkypeSetupFull.exe
      [2011.01.07 10:22:46 | 001,029,000 | ---- | C] (Skype Technologies S.A.) -- C:\Program Files\SkypeSetup.exe
      [4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
      [1 C:\WINDOWS\System32\drivers\*.tmp files -> C:\WINDOWS\System32\drivers\*.tmp -> ]

      [color=#E56717]========== Files - Modified Within 30 Days ==========/color

      File not found -- C:\WINDOWS\System32\
      [2011.11.16 22:04:42 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Utilisateur\Bureau\OTL.exe
      [2011.11.16 22:04:42 | 000,527,704 | ---- | M] () -- C:\WINDOWS\System32\perfh00C.dat
      [2011.11.16 22:04:42 | 000,436,684 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
      [2011.11.16 22:04:42 | 000,091,668 | ---- | M] () -- C:\WINDOWS\System32\perfc00C.dat
      [2011.11.16 22:04:42 | 000,069,388 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
      [2011.11.16 21:29:08 | 000,000,440 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.ics
      [2011.11.16 21:27:19 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
      [2011.11.16 21:27:08 | 000,000,276 | ---- | M] () -- C:\WINDOWS\tasks\RegistryBooster.job
      [2011.11.16 21:26:29 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
      [2011.11.16 21:18:33 | 004,297,251 | R--- | M] (Swearware) -- C:\Documents and Settings\Utilisateur\Bureau\asdehi.exe
      [2011.11.16 21:01:00 | 000,000,246 | ---- | M] () -- C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
      [2011.11.16 19:18:25 | 000,500,347 | ---- | M] () -- C:\Documents and Settings\Utilisateur\Bureau\delfix.exe
      [2011.11.16 16:54:33 | 000,002,265 | ---- | M] () -- C:\Documents and Settings\All Users\Bureau\Skype.lnk
      [2011.11.16 16:00:16 | 000,002,086 | ---- | M] () -- C:\WINDOWS\epplauncher.mif
      [2011.11.16 14:34:57 | 021,073,936 | ---- | M] () -- C:\Program Files\vlc-1.1.11-win32.exe
      [2011.11.16 12:00:03 | 000,720,896 | ---- | M] () -- C:\Documents and Settings\Utilisateur\Bureau\Contacts journaliste.mdb
      [2011.11.09 18:25:57 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
      [2011.11.09 15:31:00 | 000,000,069 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
      [2011.11.09 15:07:50 | 012,021,760 | ---- | M] () -- C:\Documents and Settings\Utilisateur\Bureau\Ad-Aware96Install.msi
      [2011.11.07 01:29:08 | 000,000,000 | ---- | M] () -- C:\WINDOWS\2755643316
      [2011.11.06 17:57:27 | 000,000,789 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
      [2011.11.05 14:10:44 | 000,899,584 | ---- | M] () -- C:\Documents and Settings\Utilisateur\Bureau\MicrosoftFixit50535.msi
      [2011.11.05 11:56:04 | 000,000,328 | RHS- | M] () -- C:\boot.ini
      [2011.11.05 11:31:36 | 000,003,072 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
      [2011.11.05 10:24:28 | 000,002,575 | ---- | M] () -- C:\Documents and Settings\Utilisateur\Bureau\Word.lnk
      [2011.11.05 10:23:52 | 000,094,896 | ---- | M] (Kaspersky Lab, GERT) -- C:\WINDOWS\System32\drivers\15855302.sys
      [2011.11.04 16:33:28 | 000,001,813 | ---- | M] () -- C:\Documents and Settings\All Users\Bureau\Google Chrome.lnk
      [2011.11.04 16:33:28 | 000,001,791 | ---- | M] () -- C:\Documents and Settings\Utilisateur\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
      [2011.11.04 16:24:58 | 000,000,512 | ---- | M] () -- C:\WINDOWS\tasks\One-Click Tweak.job
      [2011.11.04 15:35:33 | 023,635,896 | ---- | M] (Citrix Systems, Inc.) -- C:\Documents and Settings\Utilisateur\Bureau\CitrixReceiver.exe
      [2011.11.04 14:57:47 | 000,709,660 | ---- | M] () -- C:\WINDOWS\System32\drivers\Cat.DB
      [2011.11.04 13:27:32 | 068,638,160 | ---- | M] () -- C:\Documents and Settings\Utilisateur\Bureau\avira_antivir_personal_fr.exe
      [2011.11.04 12:25:22 | 000,001,477 | ---- | M] () -- C:\Documents and Settings\Utilisateur\Application Data\Microsoft\Internet Explorer\Quick Launch\Uniblue RegistryBooster.lnk
      [2011.11.04 11:50:33 | 000,000,023 | -HS- | M] () -- C:\WINDOWS\System32\dcabdaf_d.dll
      [2011.11.04 11:50:33 | 000,000,023 | ---- | M] () -- C:\WINDOWS\System32\dbbecf0_d.ocx
      [2011.10.28 11:02:54 | 000,185,560 | ---- | M] (PC Tools) -- C:\WINDOWS\System32\drivers\PCTSD.sys
      [2011.10.26 10:52:30 | 000,002,529 | ---- | M] () -- C:\Documents and Settings\Utilisateur\Bureau\Excel.lnk
      [2011.10.25 18:02:51 | 000,000,349 | ---- | M] () -- C:\Documents and Settings\All Users\Documents\PCLECHAL.INI
      [2011.10.25 17:40:47 | 000,056,832 | ---- | M] () -- C:\Documents and Settings\Utilisateur\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
      [2011.10.25 17:03:31 | 000,000,816 | ---- | M] () -- C:\Documents and Settings\Utilisateur\Bureau\Free Video Converter.lnk
      [2011.10.25 13:38:20 | 000,149,456 | ---- | M] (PC Tools) -- C:\WINDOWS\SGDetectionTool.dll1146.old
      [2011.10.25 13:38:20 | 000,149,456 | ---- | M] (PC Tools) -- C:\WINDOWS\SGDetectionTool.dll
      [2011.10.25 13:38:18 | 002,291,664 | ---- | M] (Threat Expert Ltd.) -- C:\WINDOWS\PCTBDCore.dll1146.old
      [2011.10.25 13:38:18 | 002,291,664 | ---- | M] (Threat Expert Ltd.) -- C:\WINDOWS\PCTBDCore.dll
      [2011.10.25 13:38:18 | 001,681,360 | ---- | M] (Threat Expert Ltd.) -- C:\WINDOWS\PCTBDRes.dll
      [2011.10.25 13:38:08 | 000,767,952 | ---- | M] () -- C:\WINDOWS\BDTSupport.dll1146.old
      [2011.10.25 13:38:08 | 000,767,952 | ---- | M] () -- C:\WINDOWS\BDTSupport.dll
      [4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
      [1 C:\WINDOWS\System32\drivers\*.tmp files -> C:\WINDOWS\System32\drivers\*.tmp -> ]

      [color=#E56717]========== Files Created - No Company Name ==========/color

      [2011.11.16 21:19:20 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe
      [2011.11.16 21:19:20 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe
      [2011.11.16 21:19:20 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
      [2011.11.16 21:19:20 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
      [2011.11.16 21:19:20 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
      [2011.11.16 19:18:14 | 000,500,347 | ---- | C] () -- C:\Documents and Settings\Utilisateur\Bureau\delfix.exe
      [2011.11.16 14:30:55 | 021,073,936 | ---- | C] () -- C:\Program Files\vlc-1.1.11-win32.exe
      [2011.11.09 18:25:55 | 000,001,374 | ---- | C] () -- C:\WINDOWS\imsins.BAK
      [2011.11.09 18:14:42 | 000,720,896 | ---- | C] () -- C:\Documents and Settings\Utilisateur\Bureau\Contacts journaliste.mdb
      [2011.11.09 15:07:38 | 012,021,760 | ---- | C] () -- C:\Documents and Settings\Utilisateur\Bureau\Ad-Aware96Install.msi
      [2011.11.05 14:10:43 | 000,899,584 | ---- | C] () -- C:\Documents and Settings\Utilisateur\Bureau\MicrosoftFixit50535.msi
      [2011.11.05 11:56:04 | 000,000,212 | ---- | C] () -- C:\Boot.bak
      [2011.11.05 11:56:00 | 000,263,488 | RHS- | C] () -- C:\cmldr
      [2011.11.04 16:33:28 | 000,001,813 | ---- | C] () -- C:\Documents and Settings\All Users\Bureau\Google Chrome.lnk
      [2011.11.04 16:33:28 | 000,001,791 | ---- | C] () -- C:\Documents and Settings\Utilisateur\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
      [2011.11.04 16:24:57 | 000,000,512 | ---- | C] () -- C:\WINDOWS\tasks\One-Click Tweak.job
      [2011.11.04 15:04:36 | 000,767,952 | ---- | C] () -- C:\WINDOWS\BDTSupport.dll1146.old
      [2011.11.04 15:04:36 | 000,767,952 | ---- | C] () -- C:\WINDOWS\BDTSupport.dll
      [2011.11.04 15:04:35 | 000,003,488 | ---- | C] () -- C:\WINDOWS\UDB.zip
      [2011.11.04 15:04:35 | 000,000,882 | ---- | C] () -- C:\WINDOWS\RegSDImport.xml
      [2011.11.04 15:04:35 | 000,000,879 | ---- | C] () -- C:\WINDOWS\RegISSImport.xml
      [2011.11.04 15:04:35 | 000,000,131 | ---- | C] () -- C:\WINDOWS\IDB.zip
      [2011.11.04 14:57:19 | 000,709,660 | ---- | C] () -- C:\WINDOWS\System32\drivers\Cat.DB
      [2011.11.04 14:31:17 | 000,000,246 | ---- | C] () -- C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
      [2011.11.04 14:26:52 | 068,638,160 | ---- | C] () -- C:\Documents and Settings\Utilisateur\Bureau\avira_antivir_personal_fr.exe
      [2011.11.04 12:25:30 | 000,000,276 | ---- | C] () -- C:\WINDOWS\tasks\RegistryBooster.job
      [2011.11.04 12:25:22 | 000,001,477 | ---- | C] () -- C:\Documents and Settings\Utilisateur\Application Data\Microsoft\Internet Explorer\Quick Launch\Uniblue RegistryBooster.lnk
      [2011.11.04 11:50:33 | 000,000,023 | -HS- | C] () -- C:\WINDOWS\System32\dcabdaf_d.dll
      [2011.11.04 11:50:33 | 000,000,023 | ---- | C] () -- C:\WINDOWS\System32\dbbecf0_d.ocx
      [2011.10.23 20:14:02 | 000,000,000 | ---- | C] () -- C:\WINDOWS\2755643316
      [2011.06.18 16:21:12 | 000,000,200 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\~16310052
      [2011.06.18 16:21:12 | 000,000,160 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\~16310052r
      [2011.06.18 16:20:37 | 000,000,336 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\16310052
      [2011.06.16 23:32:10 | 000,000,336 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\17358628
      [2011.04.14 10:21:12 | 004,256,366 | ---- | C] () -- C:\Program Files\FileZilla_3.4.0_win32-setup.exe
      [2011.03.22 12:49:34 | 000,354,960 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
      [2011.02.27 12:44:02 | 020,364,702 | ---- | C] () -- C:\Program Files\vlc-1.1.7-win32.exe
      [2011.01.12 10:42:43 | 000,160,283 | ---- | C] () -- C:\WINDOWS\hpoins14.dat
      [2011.01.12 10:42:43 | 000,002,000 | ---- | C] () -- C:\WINDOWS\hpomdl14.dat
      [2011.01.07 10:25:07 | 000,000,048 | ---- | C] () -- C:\WINDOWS\System32\ezsidmv.dat
      [2010.06.03 08:46:12 | 000,056,832 | ---- | C] () -- C:\Documents and Settings\Utilisateur\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
      [2010.03.01 13:15:50 | 000,000,151 | ---- | C] () -- C:\WINDOWS\PhotoSnapViewer.INI
      [2010.02.18 09:38:41 | 000,078,312 | ---- | C] () -- C:\WINDOWS\hpqins05.dat
      [2010.02.15 12:39:09 | 000,417,792 | ---- | C] () -- C:\WINDOWS\System32\ZSM1120.exe
      [2010.02.15 12:39:08 | 000,167,936 | ---- | C] () -- C:\WINDOWS\System32\hpsfs.dll
      [2010.02.11 09:03:02 | 000,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
      [2010.02.04 14:20:21 | 000,000,665 | R--- | C] () -- C:\WINDOWS\System32\hppapr11.dat
      [2010.02.04 14:17:04 | 000,205,833 | ---- | C] () -- C:\WINDOWS\hppins11.dat
      [2010.02.04 14:17:04 | 000,006,091 | ---- | C] () -- C:\WINDOWS\hppmdl11.dat
      [2010.02.03 11:46:00 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
      [2010.02.03 08:15:15 | 002,463,976 | ---- | C] () -- C:\WINDOWS\System32\NPSWF32.dll
      [2009.09.10 18:34:36 | 000,004,205 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
      [2009.09.10 18:33:22 | 001,728,976 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
      [2009.09.10 17:06:04 | 000,000,271 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
      [2009.09.10 16:50:29 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
      [2009.09.10 16:44:03 | 000,021,892 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
      [2009.08.03 15:07:42 | 000,403,816 | ---- | C] () -- C:\WINDOWS\System32\OGACheckControl.dll
      [2009.08.03 15:07:42 | 000,230,768 | ---- | C] () -- C:\WINDOWS\System32\OGAEXEC.exe
      [2008.05.26 22:23:32 | 000,016,698 | ---- | C] () -- C:\WINDOWS\System32\gthrctr.ini
      [2008.05.26 22:23:30 | 000,021,596 | ---- | C] () -- C:\WINDOWS\System32\idxcntrs.ini
      [2008.05.26 22:23:28 | 000,016,036 | ---- | C] () -- C:\WINDOWS\System32\gsrvctr.ini
      [2008.05.26 21:59:42 | 000,018,904 | ---- | C] () -- C:\WINDOWS\System32\structuredqueryschematrivial.bin
      [2008.05.26 21:59:40 | 000,106,605 | ---- | C] () -- C:\WINDOWS\System32\structuredqueryschema.bin
      [2008.02.07 10:05:18 | 000,163,840 | ---- | C] () -- C:\WINDOWS\System32\hppatusg01.dll
      [2006.03.02 12:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
      [2006.03.02 12:00:00 | 000,527,704 | ---- | C] () -- C:\WINDOWS\System32\perfh00C.dat
      [2006.03.02 12:00:00 | 000,436,684 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
      [2006.03.02 12:00:00 | 000,322,810 | ---- | C] () -- C:\WINDOWS\System32\perfi00C.dat
      [2006.03.02 12:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
      [2006.03.02 12:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
      [2006.03.02 12:00:00 | 000,091,668 | ---- | C] () -- C:\WINDOWS\System32\perfc00C.dat
      [2006.03.02 12:00:00 | 000,069,388 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
      [2006.03.02 12:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
      0
    2. OTL Extras logfile created on: 16.11.2011 22:05:50 - Run 1
      OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Utilisateur\Bureau
      Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
      Internet Explorer (Version = 8.0.6001.18702)
      Locale: 0000100C | Country: Suisse | Language: FRS | Date Format: dd.MM.yyyy

      1.99 Gb Total Physical Memory | 1.57 Gb Available Physical Memory | 78.99% Memory free
      3.33 Gb Paging File | 3.09 Gb Available in Paging File | 92.77% Paging File free
      Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]

      %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
      Drive C: | 55.89 Gb Total Space | 17.33 Gb Free Space | 31.01% Space Free | Partition Type: NTFS

      Computer Name: UTILISAT-2BCF2C | User Name: Utilisateur | Logged in as Administrator.
      Boot Mode: Normal | Scan Mode: Current user
      Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

      [color=#E56717]========== Extra Registry (SafeList) ==========[/color]

      [color=#E56717]========== File Associations ==========[/color]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
      .cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*

      [HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
      .html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

      [color=#E56717]========== Shell Spawning ==========[/color]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
      batfile [open] -- "%1" %*
      cmdfile [open] -- "%1" %*
      comfile [open] -- "%1" %*
      cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
      exefile [open] -- "%1" %*
      piffile [open] -- "%1" %*
      regfile [merge] -- Reg Error: Key error.
      scrfile [config] -- "%1"
      scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
      scrfile [open] -- "%1" /S
      txtfile [edit] -- Reg Error: Key error.
      Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
      Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
      Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
      Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
      Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
      Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
      Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

      [color=#E56717]========== Security Center Settings ==========[/color]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
      "FirstRunDisabled" = 1
      "AntiVirusDisableNotify" = 0
      "FirewallDisableNotify" = 0
      "UpdatesDisableNotify" = 0
      "AntiVirusOverride" = 0
      "FirewallOverride" = 0

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

      [color=#E56717]========== System Restore Settings ==========[/color]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
      "DisableSR" = 0

      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
      "Start" = 0

      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
      "Start" = 2

      [color=#E56717]========== Firewall Settings ==========[/color]

      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
      "EnableFirewall" = 1
      "DisableNotifications" = 0
      "DoNotAllowExceptions" = 0

      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
      "139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
      "445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
      "137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
      "138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
      "EnableFirewall" = 1
      "DoNotAllowExceptions" = 0
      "DisableNotifications" = 0

      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
      "3703:TCP" = 3703:TCP:*:Enabled:Adobe Version Cue CS3 Server
      "3704:TCP" = 3704:TCP:*:Enabled:Adobe Version Cue CS3 Server
      "50900:TCP" = 50900:TCP:*:Enabled:Adobe Version Cue CS3 Server
      "50901:TCP" = 50901:TCP:*:Enabled:Adobe Version Cue CS3 Server
      "1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
      "2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008
      "139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
      "445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
      "137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
      "138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002

      [color=#E56717]========== Authorized Applications List ==========[/color]

      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
      "E:\SOFT\Nero7\SetupX.exe" = E:\SOFT\Nero7\SetupX.exe:*:Enabled:Nero ProductSetup
      "C:\Program Files\Bonjour\mDNSResponder.exe" = C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour
      "C:\Program Files\Fichiers communs\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe" = C:\Program Files\Fichiers communs\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe:*:Enabled:Adobe Version Cue CS3 Server -- (Adobe Systems Incorporated)
      "C:\Documents and Settings\Utilisateur\Mes documents\Téléchargements\AudioConverter_Setup.exe" = C:\Documents and Settings\Utilisateur\Mes documents\Téléchargements\AudioConverter_Setup.exe:*:Enabled:Audio Converter
      "C:\Program Files\Skype\Plugin Manager\skypePM.exe" = C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager
      "C:\Program Files\Pinnacle\Studio 14\Programs\RM.exe" = C:\Program Files\Pinnacle\Studio 14\Programs\RM.exe:*:Enabled:Render Manager -- (Pinnacle Systems)
      "C:\Program Files\Pinnacle\Studio 14\Programs\Studio.exe" = C:\Program Files\Pinnacle\Studio 14\Programs\Studio.exe:*:Enabled:Studio -- (Pinnacle Systems)
      "C:\Program Files\Pinnacle\Studio 14\Programs\umi.exe" = C:\Program Files\Pinnacle\Studio 14\Programs\umi.exe:*:Enabled:umi -- (Pinnacle Systems)
      "C:\Documents and Settings\Utilisateur\Application Data\Dropbox\bin\Dropbox.exe" = C:\Documents and Settings\Utilisateur\Application Data\Dropbox\bin\Dropbox.exe:*:Enabled:Dropbox -- (Dropbox, Inc.)
      "C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent
      "C:\Program Files\Free Video Converter\FreeVideoConverter.exe" = C:\Program Files\Free Video Converter\FreeVideoConverter.exe:*:Enabled:FreeVideoConverter -- (Koyote Soft)
      "C:\Documents and Settings\Utilisateur\Bureau\Setup_FreeVideoConverter.exe" = C:\Documents and Settings\Utilisateur\Bureau\Setup_FreeVideoConverter.exe:*:Enabled:Free Video Converter Install
      "C:\Program Files\VideoLAN\VLC\vlc.exe" = C:\Program Files\VideoLAN\VLC\vlc.exe:*:Enabled:VLC media player -- ()
      "C:\Program Files\DivX\DivX Plus Player\DivX Plus Player.exe" = C:\Program Files\DivX\DivX Plus Player\DivX Plus Player.exe:*:Enabled:DivX Plus Player -- ()
      "C:\Program Files\DivX\DivX Update\DivXUpdate.exe" = C:\Program Files\DivX\DivX Update\DivXUpdate.exe:*:Enabled:DivX Update -- ()
      "C:\Program Files\Pinnacle\Shared Files\Pixie\PixieTool.exe" = C:\Program Files\Pinnacle\Shared Files\Pixie\PixieTool.exe:*:Enabled:Pixie5 Registration and Licensing Tool -- (Pinnacle Systems)
      "C:\Program Files\Mozilla Firefox\firefox.exe" = C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox -- (Mozilla Corporation)
      "C:\Program Files\Java\jre6\bin\java.exe" = C:\Program Files\Java\jre6\bin\java.exe:*:Enabled:Java(TM) Platform SE binary -- (Sun Microsystems, Inc.)
      "C:\Program Files\FileZilla FTP Client\filezilla.exe" = C:\Program Files\FileZilla FTP Client\filezilla.exe:*:Enabled:FileZilla FTP Client -- (FileZilla Project)
      "C:\Documents and Settings\Utilisateur\Application Data\HP SimpleSave Application\HPSSBackup.exe" = C:\Documents and Settings\Utilisateur\Application Data\HP SimpleSave Application\HPSSBackup.exe:*:Enabled:HP SimpleSave Backup -- ()
      "C:\Program Files\Avira\AntiVir Desktop\update.exe" = C:\Program Files\Avira\AntiVir Desktop\update.exe:*:Enabled:product updater
      "C:\Program Files\Avira\AntiVir Desktop\avnotify.exe" = C:\Program Files\Avira\AntiVir Desktop\avnotify.exe:*:Enabled:Notification Tool -- (Avira GmbH)
      "C:\Program Files\Fichiers communs\Microsoft Shared\DW\DW20.EXE" = C:\Program Files\Fichiers communs\Microsoft Shared\DW\DW20.EXE:*:Enabled:Microsoft Application Error Reporting -- (Microsoft Corporation)
      "C:\Program Files\BitKinex\bitkinex.exe" = C:\Program Files\BitKinex\bitkinex.exe:*:Enabled:BitKinex FTP Client -- (Barad-Dur, LLC.)
      "C:\Documents and Settings\Utilisateur\Bureau\ccsetup312.exe" = C:\Documents and Settings\Utilisateur\Bureau\ccsetup312.exe:*:Enabled:CCleaner Installer
      "C:\Program Files\Picasa2\PicasaUpdater.exe" = C:\Program Files\Picasa2\PicasaUpdater.exe:*:Enabled:Picasa -- (Google Inc.)
      "C:\WINDOWS\system32\dwwin.exe" = C:\WINDOWS\system32\dwwin.exe:*:Enabled:Microsoft Application Error Reporting -- (Microsoft Corporation)
      "C:\Documents and Settings\Utilisateur\Local Settings\Temp\Searchqu_DM\toolbar\SearchquMediaBar.exe" = C:\Documents and Settings\Utilisateur\Local Settings\Temp\Searchqu_DM\toolbar\SearchquMediaBar.exe:*:Disabled:Searchqu Toolbar Installer
      "C:\Documents and Settings\Utilisateur\Local Settings\Temp\nsq177.tmp\Searchqu Toolbar uninstall.exe" = C:\Documents and Settings\Utilisateur\Local Settings\Temp\nsq177.tmp\Searchqu Toolbar uninstall.exe:*:Disabled:Searchqu Toolbar Installer
      "C:\Documents and Settings\Utilisateur\Local Settings\Temp\SetupDataMngr_Searchqu.exe" = C:\Documents and Settings\Utilisateur\Local Settings\Temp\SetupDataMngr_Searchqu.exe:*:Disabled:SetupDataMngr_Searchqu
      "C:\Documents and Settings\Utilisateur\Local Settings\Temp\is-9FBKP.tmp\spybotsd162.tmp" = C:\Documents and Settings\Utilisateur\Local Settings\Temp\is-9FBKP.tmp\spybotsd162.tmp:*:Enabled:Setup/Uninstall
      "C:\Program Files\Spybot - Search & Destroy\SDUpdate.exe" = C:\Program Files\Spybot - Search & Destroy\SDUpdate.exe:*:Enabled:Updater for Spybot-S&D
      "C:\WINDOWS\explorer.exe" = C:\WINDOWS\explorer.exe:*:Enabled:Explorateur Windows -- (Microsoft Corporation)
      "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" = C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe:*:Enabled:Malwarebytes' Anti-Malware
      "C:\Documents and Settings\Utilisateur\Local Settings\Temp\_av_sfx.tm~a01520\avast.setup" = C:\Documents and Settings\Utilisateur\Local Settings\Temp\_av_sfx.tm~a01520\avast.setup:*:Enabled:avast! antivirus Update
      "C:\Program Files\AVAST Software\Avast\AvastUI.exe" = C:\Program Files\AVAST Software\Avast\AvastUI.exe:*:Enabled:avast! Antivirus
      "C:\Program Files\Adobe\Adobe InDesign CS3\InDesign.exe" = C:\Program Files\Adobe\Adobe InDesign CS3\InDesign.exe:*:Enabled:Adobe InDesign CS3 -- (Adobe Systems Incorporated)
      "C:\Program Files\Windows Media Player\wmplayer.exe" = C:\Program Files\Windows Media Player\wmplayer.exe:*:Enabled:Windows Media Player -- ()
      "C:\Program Files\Java\jre6\bin\javaw.exe" = C:\Program Files\Java\jre6\bin\javaw.exe:*:Enabled:Java(TM) Platform SE binary -- (Sun Microsystems, Inc.)
      "C:\Program Files\Fichiers communs\Java\Java Update\jaucheck.exe" = C:\Program Files\Fichiers communs\Java\Java Update\jaucheck.exe:*:Enabled:Java(TM) Update Client Checker -- (Sun Microsystems, Inc.)
      "C:\Program Files\Onset Computer Corporation\HOBOware\HOBOware.exe" = C:\Program Files\Onset Computer Corporation\HOBOware\HOBOware.exe:*:Enabled:HOBOware -- (Onset Computer Corporation)
      "C:\Program Files\AVAST Software\Avast\Setup\avast.setup" = C:\Program Files\AVAST Software\Avast\Setup\avast.setup:*:Enabled:avast! antivirus Update
      "C:\Documents and Settings\Utilisateur\Local Settings\Temp\_iu14D2N.tmp" = C:\Documents and Settings\Utilisateur\Local Settings\Temp\_iu14D2N.tmp:*:Enabled:Setup/Uninstall
      "C:\Program Files\Uniblue\RegistryBooster\registrybooster.exe" = C:\Program Files\Uniblue\RegistryBooster\registrybooster.exe:*:Enabled:Uniblue RegistryBooster
      "C:\Program Files\Uniblue\RegistryBooster\rbmonitor.exe" = C:\Program Files\Uniblue\RegistryBooster\rbmonitor.exe:*:Enabled:Uniblue RegistryBooster Monitor
      "C:\Documents and Settings\Utilisateur\Local Settings\Temp\RarSFX0\apnstub.exe" = C:\Documents and Settings\Utilisateur\Local Settings\Temp\RarSFX0\apnstub.exe:*:Enabled:AskStub Application -- (Ask.com)
      "C:\Documents and Settings\Utilisateur\Local Settings\Temp\AskSLib.exe" = C:\Documents and Settings\Utilisateur\Local Settings\Temp\AskSLib.exe:*:Enabled:Wrapper Application
      "C:\Documents and Settings\Utilisateur\Local Settings\Temp\{86D4B82A-ABED-442A-BE86-96357B70F4FE}\AskPartnerCobrandingTool.exe" = C:\Documents and Settings\Utilisateur\Local Settings\Temp\{86D4B82A-ABED-442A-BE86-96357B70F4FE}\AskPartnerCobrandingTool.exe:*:Enabled:Ask Toolbar Partner Cobranding
      "C:\Program Files\Ask.com\TaskScheduler.exe" = C:\Program Files\Ask.com\TaskScheduler.exe:*:Enabled:TaskScheduler
      "C:\Program Files\Ask.com\Updater\Updater.exe" = C:\Program Files\Ask.com\Updater\Updater.exe:*:Enabled:{StringFileInfo_FileDescription} -- ({StringFileInfo_CompanyName})
      "C:\Documents and Settings\Utilisateur\Bureau\sdsetup.exe" = C:\Documents and Settings\Utilisateur\Bureau\sdsetup.exe:*:Enabled:PC Tools Installer for Spyware Doctor
      "C:\Documents and Settings\Utilisateur\Local Settings\Temp\is-C0H78.tmp\InnoMonitor2.exe" = C:\Documents and Settings\Utilisateur\Local Settings\Temp\is-C0H78.tmp\InnoMonitor2.exe:*:Enabled:InnoMonitor Application -- (PC Tools)
      "C:\Documents and Settings\Utilisateur\Local Settings\Temp\is-VOKJ0.tmp\InnoMonitor2.exe" = C:\Documents and Settings\Utilisateur\Local Settings\Temp\is-VOKJ0.tmp\InnoMonitor2.exe:*:Enabled:InnoMonitor Application -- (PC Tools)
      "C:\Program Files\Advanced PC Tweaker\AdvancedPCTweaker.exe" = C:\Program Files\Advanced PC Tweaker\AdvancedPCTweaker.exe:*:Enabled:Advanced PC Tweaker
      "C:\Documents and Settings\Utilisateur\Local Settings\Temp\GUM57.tmp\GoogleUpdate.exe" = C:\Documents and Settings\Utilisateur\Local Settings\Temp\GUM57.tmp\GoogleUpdate.exe:*:Enabled:Programme d'installation de Google
      "C:\Program Files\Google\Update\GoogleUpdate.exe" = C:\Program Files\Google\Update\GoogleUpdate.exe:*:Enabled:Programme d'installation de Google
      "C:\Documents and Settings\Utilisateur\Local Settings\Temp\_av_sfx.tm~a02092\avast.setup" = C:\Documents and Settings\Utilisateur\Local Settings\Temp\_av_sfx.tm~a02092\avast.setup:*:Enabled:avast! antivirus Update
      "C:\Program Files\Google\Chrome\Application\chrome.exe" = C:\Program Files\Google\Chrome\Application\chrome.exe:*:Enabled:Google Chrome -- (Google Inc.)
      "C:\Documents and Settings\Utilisateur\Bureau\ZHPDiag.exe" = C:\Documents and Settings\Utilisateur\Bureau\ZHPDiag.exe:*:Enabled:Diagnostic Tool
      "C:\Documents and Settings\Utilisateur\Bureau\tdsskiller\TDSSKiller.exe" = C:\Documents and Settings\Utilisateur\Bureau\tdsskiller\TDSSKiller.exe:*:Enabled:TDSS rootkit removing tool -- (Kaspersky Lab ZAO)
      "C:\Program Files\ZHPDiag\ZHPDiag.exe" = C:\Program Files\ZHPDiag\ZHPDiag.exe:*:Enabled:Diagnostic Tool

      [color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
      "{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
      "{04AF207D-9A77-465A-8B76-991F6AB66245}" = Adobe Help Viewer CS3
      "{05BFB060-4F22-4710-B0A2-2801A1B606C5}" = Microsoft Antimalware
      "{08B32819-6EEF-4057-AEDA-5AB681A36A23}" = Adobe Bridge Start Meeting
      "{1204162A-1E08-4BB4-8F9C-D963D6375834}" = Scan To
      "{1753255A-0AEB-4220-8C75-607B73F0C133}" = Copy
      "{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}" = Adobe WinSoft Linguistics Plugin
      "{18669FF9-C8FE-407a-9F70-E674896B1DB4}" = GPBaseService
      "{1B0BCA28-1F11-4D60-8A2F-DEBE04B5341E}" = Adobe Flash Video Encoder
      "{1D58229F-C505-45CA-8223-F35F3A34B963}" = Adobe Version Cue CS3 Server {ko_KR}
      "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
      "{22E4CA5B-3829-4C61-9A9C-E4729C96C133}" = hppscanCM1312
      "{24D7346D-D4B4-45E8-98EA-75EC14B42DD8}" = Adobe ExtendScript Toolkit 2
      "{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java(TM) 6 Update 22
      "{29E5EA97-5F74-4A57-B8B2-D4F169117183}" = Adobe Stock Photos CS3
      "{32E9C1A5-0FDA-4483-987D-DBABF9CC1DD8}" = Microsoft Antimalware Service FR-FR Language Pack
      "{34D2AB40-150D-475D-AE32-BD23FB5EE355}" = HP Quick Launch Buttons 6.30 J1
      "{350C940c-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
      "{35C0A1E4-D02A-412C-841F-266DBB116ABB}" = Logiciel Intel(R) PROSet/Wireless WiFi
      "{3700194C-C5DD-439A-BE06-A66960CA4C70}" = MSVCSetup
      "{3865D924-89FD-4D9B-A276-5938A397FFC4}" = hppFaxUtilityCM1312
      "{3DACACEC-5F90-4CEF-AB6B-77E0AF71BF5C}" = hppusgM1120
      "{415CDA53-9100-476F-A7B2-476691E117C7}" = HP Smart Web Printing
      "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
      "{4A70EF07-7F88-4434-BB61-D1DE8AE93DD4}" = SolutionCenter
      "{4BDB76C6-902E-41D5-9064-68768E02886B}" = Adobe Dreamweaver CS3
      "{4D106AEC-ED45-4F6E-BD99-C88C8E75857F}" = hppManualsCM1312
      "{50779A29-834E-4E36-BBEB-B7CABC67A825}" = Microsoft Security Client FR-FR Language Pack
      "{52A69E11-7CEB-4a7d-9607-68BA4F39A89B}" = DeviceDiscovery
      "{543E938C-BDC4-4933-A612-01293996845F}" = UnloadSupport
      "{545C0721-295B-498B-B306-FBAFE01FC319}" = hppSendFaxCM1312
      "{54793AA1-5001-42F4-ABB6-C364617C6078}" = Adobe Linguistics CS3
      "{54B6DC7D-8C5B-4DFB-BC15-C010A3326B2B}" = Microsoft Security Client
      "{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
      "{583EDB12-4CEA-48B5-A7BA-88069DD47BA2}" = hppQFolderCM1312
      "{5ACE69F0-A3E8-44eb-88C1-0A841E700180}" = TrayApp
      "{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
      "{63FF21C9-A810-464F-B60A-3111747B1A6D}" = GPBaseService2
      "{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
      "{679EC478-3FF9-4987-B2FF-C2C2B27532A2}" = DocProc
      "{6860B340-530D-46B3-91F8-1AE1F70F7C33}" = OpenOffice.org 3.0
      "{687FEF8A-8597-40b4-832C-297EA3F35817}" = BufferChm
      "{6ABE0BEE-D572-4FE8-B434-9E72A289431B}" = Adobe Fonts All
      "{6B708481-748A-4EB4-97C1-CD386244FF77}" = Adobe MotionPicture Color Files
      "{6BBAA81D-6A7E-43AD-8889-2F002DCAAFDD}" = AHV content for Acrobat and Flash
      "{6D70B0D8-63D0-4D88-A0DF-97818C4595B1}" = hppCLJCM1312
      "{6DE721A5-5E89-4D74-994C-652BB3C0672E}" = Pilote vidéo Pinnacle
      "{6E08CE13-C2AB-4749-9335-5900B958929E}" = Adobe Illustrator CS3
      "{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}" = Adobe Asset Services CS3
      "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
      "{73B5D990-04EA-4751-B10F-5534770B91F2}" = Adobe Color EU Recommended Settings
      "{75DEC63E-92C6-403C-ABDF-8AEFEC61C704}" = hppFaxDrvCM1312
      "{766D1E50-816B-417A-B8F7-3BC0B4A1913D}" = hppPQVideoCM1312
      "{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
      "{7E369B27-13E2-41A5-9879-358EE1C8B5AD}" = Broadcom Gigabit Integrated Controller
      "{802771A9-A856-4A41-ACF7-1450E523C923}" = Adobe XMP Panels CS3
      "{80533B67-C407-485D-8B5D-63BB8ED9D878}" = Scan
      "{80FD3971-8482-49C8-BA8C-B6464A15882F}" = Adobe Flash CS3
      "{824D3839-DAA1-4315-A822-7AE3E620E528}" = VideoToolkit01
      "{8389382B-53BA-4A87-8854-91E3D80A5AC7}" = HP Photosmart Essential2.01
      "{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
      "{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Ask Toolbar
      "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
      "{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel(R) Graphics Media Accelerator Driver for Mobile
      "{8C8224B7-AA9B-4807-97CD-55899BAC83FE}" = YouSendIt Express
      "{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}" = Adobe Device Central CS3
      "{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}" = Adobe Type Support
      "{8E72B982-D54F-486F-B35A-C24B6F171036}" = Nero 7 Essentials
      "{8EEDB90E-6ABC-42bb-AD4C-39DEE05E3EEA}" = HP Color LaserJet CM1312 MFP Series 3.1
      "{90120000-0010-040C-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (French) 12
      "{90120000-0015-040C-0000-0000000FF1CE}" = Microsoft Office Access MUI (French) 2007
      "{90120000-0015-040C-0000-0000000FF1CE}_ENTERPRISE_{AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}" = Microsoft Office 2007 Service Pack 2 (SP2)
      "{90120000-0016-040C-0000-0000000FF1CE}" = Microsoft Office Excel MUI (French) 2007
      "{90120000-0016-040C-0000-0000000FF1CE}_ENTERPRISE_{AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}" = Microsoft Office 2007 Service Pack 2 (SP2)
      "{90120000-0018-040C-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (French) 2007
      "{90120000-0018-040C-0000-0000000FF1CE}_ENTERPRISE_{AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}" = Microsoft Office 2007 Service Pack 2 (SP2)
      "{90120000-0019-040C-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (French) 2007
      "{90120000-0019-040C-0000-0000000FF1CE}_ENTERPRISE_{AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}" = Microsoft Office 2007 Service Pack 2 (SP2)
      "{90120000-001A-040C-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (French) 2007
      "{90120000-001A-040C-0000-0000000FF1CE}_ENTERPRISE_{AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}" = Microsoft Office 2007 Service Pack 2 (SP2)
      "{90120000-001B-040C-0000-0000000FF1CE}" = Microsoft Office Word MUI (French) 2007
      "{90120000-001B-040C-0000-0000000FF1CE}_ENTERPRISE_{AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}" = Microsoft Office 2007 Service Pack 2 (SP2)
      "{90120000-001F-0401-0000-0000000FF1CE}" = Microsoft Office Proof (Arabic) 2007
      "{90120000-001F-0401-0000-0000000FF1CE}_ENTERPRISE_{14809F99-C601-4D4A-9391-F1E8FAA964C5}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
      "{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007
      "{90120000-001F-0407-0000-0000000FF1CE}_ENTERPRISE_{A0516415-ED61-419A-981D-93596DA74165}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
      "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
      "{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
      "{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
      "{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
      "{90120000-001F-0413-0000-0000000FF1CE}" = Microsoft Office Proof (Dutch) 2007
      "{90120000-001F-0413-0000-0000000FF1CE}_ENTERPRISE_{D66D5A44-E480-4BA4-B4F2-C554F6B30EBB}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
      "{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
      "{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
      "{90120000-002C-040C-0000-0000000FF1CE}" = Microsoft Office Proofing (French) 2007
      "{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
      "{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
      "{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
      "{90120000-0044-040C-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (French) 2007
      "{90120000-0044-040C-0000-0000000FF1CE}_ENTERPRISE_{AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}" = Microsoft Office 2007 Service Pack 2 (SP2)
      "{90120000-006E-040C-0000-0000000FF1CE}" = Microsoft Office Shared MUI (French) 2007
      "{90120000-006E-040C-0000-0000000FF1CE}_ENTERPRISE_{B165D3C2-40AE-4D39-86F7-E5C87C4264C0}" = Microsoft Office 2007 Service Pack 2 (SP2)
      "{90120000-00A1-040C-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (French) 2007
      "{90120000-00A1-040C-0000-0000000FF1CE}_ENTERPRISE_{AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}" = Microsoft Office 2007 Service Pack 2 (SP2)
      "{90120000-00BA-040C-0000-0000000FF1CE}" = Microsoft Office Groove MUI (French) 2007
      "{90120000-00BA-040C-0000-0000000FF1CE}_ENTERPRISE_{AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}" = Microsoft Office 2007 Service Pack 2 (SP2)
      "{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
      "{90176341-0A8B-4CCC-A78D-F862228A6B95}" = Adobe Anchor Service CS3
      "{95120000-00AF-040C-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (French)
      "{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
      "{995F2783-8311-49BF-833E-DB659774B4F6}" = hppFonts
      "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
      "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
      "{9C9824D9-9000-4373-A6A5-D0E5D4831394}" = Adobe Bridge CS3
      "{9DE3F260-B88E-42CE-90E7-73C78C37D95E}" = 32 Bit HP BiDi Channel Components Installer
      "{A2B242BD-FF8D-4840-9DAA-9170EABEC59C}" = Adobe CMaps
      "{A2D81E70-2A98-4A08-A628-94388B063C5E}" = Adobe Color - Photoshop Specific
      "{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
      "{A651EC5E-A4FB-4AA6-B542-3F7ECB08D119}" = hppScanToCM1312
      "{A7CE3C9E-78B4-4855-8D24-5CDF498E31F9}" = BitKinex
      "{A82D052A-0806-42DF-80CD-1730A1AC0ED3}" = MrvlUsgTracking
      "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
      "{AA59DDE4-B672-4621-A016-4C248204957A}" = Skype(TM) 5.5
      "{AADD1C8F-D59F-4D55-A726-768C71A205A8}" = Pinnacle Studio 14
      "{AC5B0C19-D851-42F4-BDA0-410ECF7F70A5}" = PDF Settings
      "{AC76BA86-1033-F400-7760-000000000004}" = Adobe Acrobat 9 Pro - English, Français, Deutsch
      "{AC76BA86-1033-F400-7760-000000000004}_946" = Adobe Acrobat 9.4.6 - CPSID_83708
      "{AC76BA86-1033-F400-7760-000000000004}{AC76BA86-1033-F400-7760-000000000004}" = Adobe Acrobat 9 Pro - English, Français, Deutsch
      "{AF7FC1CA-79DF-43c3-90A3-33EFEB9294CE}" = AIO_Scan
      "{B0069CFA-5BB9-4C03-B1C6-89CE290E5AFE}" = HP Update
      "{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
      "{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}" = Adobe Camera Raw 4.0
      "{B3C02EC1-A7B0-4987-9A43-8789426AAA7D}" = Adobe Setup
      "{B4F35A00-24FD-4fb3-BF5E-413D5423434D}" = DJ_AIO_Software_min
      "{B671CBFD-4109-4D35-9252-3062D3CCB7B2}" = Adobe SING CS3
      "{B6A98E5F-D6A7-46FB-9E9D-1F7BF443491C}" = PMB
      "{B73CFB12-C814-4638-AFFD-7E3AAFAF0B4E}" = Adobe BridgeTalk Plugin CS3
      "{B8DBED1E-8BC3-4d08-B94A-F9D7D88E9BBF}" = HPSSupply
      "{B95350D0-DA64-468E-9DD0-308C78409538}" = hppTLBXFXCM1312
      "{B9B35331-B7E4-4E5C-BF4C-7BC87856124D}" = Adobe Default Language CS3
      "{BE5F3842-8309-4754-92D5-83E02E6077A3}" = Adobe Extension Manager CS3
      "{BEE8E835-BB38-4042-A80E-7F8CEDD5612A}" = Adobe Creative Suite 3 Design Premium
      "{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
      "{C1920D73-7374-49d9-8C37-58A6E49078A5}" = F2100_Help
      "{C1FA4B3B-1625-4922-9C9D-780E8FCE161A}" = Adobe Photoshop CS3
      "{C43326F5-F135-4551-8270-7F7ABA0462E1}" = HPProductAssistant
      "{C5BD220A-EFE8-48A5-B70E-9503D535FACE}" = Adobe WAS CS3
      "{C5EF81AC-FE4C-4157-97E3-2E08B000742A}" = F2100_doccd
      "{CA50045C-5119-48e7-9BA7-6B317379857A}" = DJ_AIO_Software
      "{CC4A73BF-938E-4C19-A553-853C035C9BA1}" = LightScribe System Software 1.10.13.1
      "{CCB9B81A-167F-4832-B305-D2A0430840B3}" = WebReg
      "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
      "{D0DFF92A-492E-4C40-B862-A74A173C25C5}" = Adobe Version Cue CS3 Client
      "{D142FE39-3386-4d82-9AD3-36D4A92AC3C2}" = DocMgr
      "{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}" = Adobe PDF Library Files
      "{D2E0F0CC-6BE0-490b-B08B-9267083E34C9}" = MarketResearch
      "{D99A8E3A-AE5A-4692-8B19-6F16D454E240}" = Destination Component
      "{DADD7B8A-BCB0-44F5-967A-ECB6B4F2ECD9}" = Adobe Color Common Settings
      "{DD7DB3C5-6FA3-4FA3-8A71-C2F2940EB029}" = Adobe Color JA Extra Settings
      "{E548726E-F4E8-459f-BAB8-45551BC071E9}" = DJ_AIO_ProductContext
      "{E69AE897-9E0B-485C-8552-7841F48D42D8}" = Adobe Update Manager CS3
      "{E92BCB17-FD2B-4AE3-882D-7C91B382AA66}" = hpzTLBXFX
      "{E9C18EBD-85BE-47D0-AA73-3FEDCC976B04}" = Toolbox
      "{EA7B3CC4-366D-4CF6-8350-FD7A7034116E}" = Adobe InDesign CS3 Icon Handler
      "{EAE2C948-26FA-49C1-8C80-99EBE55DD9E1}" = Adobe Setup
      "{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
      "{F1C409F0-8322-4c87-BD08-2F62777D490D}" = F2100
      "{F1E63043-54FC-429B-AB2C-31AF9FBA4BC7}" = 32 Bit HP CIO Components Installer
      "{F72E2DDC-3DB8-4190-A21D-63883D955FE7}" = PSSWCORE
      "{F7F7FE98-9D77-449B-A4EB-6F527AD1CCB4}" = hppusgCM1312
      "{FA8A44D7-3E8A-4034-9C4F-088FA6B72BC4}" = HP Deskjet All-In-One Software 9.0
      "{FD8D8B04-BEAD-4A55-AA1D-62D2373E7DEA}" = Status
      "{FE8327F9-3AC1-4586-8C7E-3DEE2BC92441}" = Adobe InDesign CS3
      "{FF29A7E2-FF40-4D07-B7E4-2093DE59E10A}" = Adobe Color NA Extra Settings
      "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
      "Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
      "Adobe Shockwave Player" = Adobe Shockwave Player 11.5
      "Adobe_3e054d2218e7aa282c2369d939e58ff" = Adobe ExtendScript Toolkit 2
      "Adobe_5647dddec81b3798d8bab8c5ac5fcb0" = Ajouter ou supprimer Adobe Creative Suite 3 Design Premium
      "Agere Systems Soft Modem" = Agere Systems AC'97 Modem
      "Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
      "Browser Defender_is1" = Browser Defender 4.0
      "C: Program Files Onset Computer Corporation HOBOware_is1" = HOBOware 3.2.1
      "DivX Setup.divx.com" = Configuration DivX
      "ENTERPRISE" = Microsoft Office Enterprise 2007
      "FileZilla Client" = FileZilla Client 3.5.1
      "Free Video Converter_is1" = Free Video Converter V 3.0
      "Google Chrome" = Google Chrome
      "HP Document Manager" = HP Document Manager 1.0
      "HP Imaging Device Functions" = HP Imaging Device Functions 10.0
      "HP LaserJet M1120 MFP" = HP LaserJet M1120 MFP Series
      "HP Photosmart Essential" = HP Photosmart Essential 2.01
      "HP Solution Center & Imaging Support Tools" = HP Solution Center 13.0
      "HPExtendedCapabilities" = HP Customer Participation Program 10.0
      "IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
      "ie8" = Windows Internet Explorer 8
      "InstallShield_{8C8224B7-AA9B-4807-97CD-55899BAC83FE}" = YouSendIt Express
      "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
      "Microsoft Security Client" = Microsoft Security Essentials
      "Mozilla Firefox 8.0 (x86 fr)" = Mozilla Firefox 8.0 (x86 fr)
      "MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
      "NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
      "Picasa 3" = Picasa 3
      "ProInst" = Intel PROSet Wireless
      "Shop for HP Supplies" = Shop for HP Supplies
      "Uniblue RegistryBooster" = Uniblue RegistryBooster
      "VaudTax2010" = VaudTax2010
      "VLC media player" = VLC media player 1.0.5
      "Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
      "Windows Media Format Runtime" = Windows Media Format 11 runtime
      "Windows Media Player" = Lecteur Windows Media 11
      "Windows XP Service" = Windows XP Service Pack 3
      "WinRAR archiver" = Archiveur WinRAR
      "WMFDist11" = Windows Media Format 11 runtime
      "wmp11" = Windows Media Player 11
      "Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
      "XMind" = XMind

      [color=#E56717]========== HKEY_CURRENT_USER Uninstall List ==========[/color]

      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
      "Dropbox" = Dropbox

      [color=#E56717]========== Last 10 Event Log Errors ==========[/color]

      [ Application Events ]
      Error - 09.11.2011 13:17:25 | Computer Name = UTILISAT-2BCF2C | Source = crypt32 | ID = 131077
      Description = Échec de la récupération de la mise à jour automatique du certificat
      racine tierce partie à partir de : <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/2796BAE63F1801E277261BA0D77770028F20EEE4.crt>
      avec l'erreur : Cette opération s'est terminée car le délai d'attente a expiré.

      Error - 09.11.2011 13:17:25 | Computer Name = UTILISAT-2BCF2C | Source = crypt32 | ID = 131077
      Description = Échec de la récupération de la mise à jour automatique du certificat
      racine tierce partie à partir de : <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/2796BAE63F1801E277261BA0D77770028F20EEE4.crt>
      avec l'erreur : Cette opération s'est terminée car le délai d'attente a expiré.

      Error - 09.11.2011 13:17:25 | Computer Name = UTILISAT-2BCF2C | Source = crypt32 | ID = 131077
      Description = Échec de la récupération de la mise à jour automatique du certificat
      racine tierce partie à partir de : <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/2796BAE63F1801E277261BA0D77770028F20EEE4.crt>
      avec l'erreur : Le serveur spécifié ne peut pas exécuter l'opération demandée.

      Error - 09.11.2011 13:17:25 | Computer Name = UTILISAT-2BCF2C | Source = crypt32 | ID = 131077
      Description = Échec de la récupération de la mise à jour automatique du certificat
      racine tierce partie à partir de : <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/2796BAE63F1801E277261BA0D77770028F20EEE4.crt>
      avec l'erreur : Le serveur spécifié ne peut pas exécuter l'opération demandée.

      Error - 09.11.2011 13:17:25 | Computer Name = UTILISAT-2BCF2C | Source = crypt32 | ID = 131077
      Description = Échec de la récupération de la mise à jour automatique du certificat
      racine tierce partie à partir de : <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/2796BAE63F1801E277261BA0D77770028F20EEE4.crt>
      avec l'erreur : Le serveur spécifié ne peut pas exécuter l'opération demandée.

      Error - 09.11.2011 13:17:25 | Computer Name = UTILISAT-2BCF2C | Source = crypt32 | ID = 131077
      Description = Échec de la récupération de la mise à jour automatique du certificat
      racine tierce partie à partir de : <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/2796BAE63F1801E277261BA0D77770028F20EEE4.crt>
      avec l'erreur : Le serveur spécifié ne peut pas exécuter l'opération demandée.

      Error - 16.11.2011 09:49:05 | Computer Name = UTILISAT-2BCF2C | Source = Microsoft Security Client | ID = 5000
      Description =

      Error - 16.11.2011 11:00:14 | Computer Name = UTILISAT-2BCF2C | Source = Microsoft Security Client | ID = 5000
      Description =

      Error - 16.11.2011 11:00:16 | Computer Name = UTILISAT-2BCF2C | Source = Microsoft Security Client Setup | ID = 100
      Description = HRESULT:0x8004FF01 Description:Cannot complete uninstall wizard. An
      error has prevented the Security Essentials Uninstall Wizard from continuing. Please
      restart your computer and try again. Error code:0x8004FF01.

      Error - 16.11.2011 11:00:18 | Computer Name = UTILISAT-2BCF2C | Source = Microsoft Security Client | ID = 5000
      Description =

      [ OSession Events ]
      Error - 11.02.2010 09:30:26 | Computer Name = UTILISAT-2BCF2C | Source = Microsoft Office 12 Sessions | ID = 7001
      Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
      12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 18358
      seconds with 5280 seconds of active time. This session ended with a crash.

      Error - 22.03.2010 09:46:34 | Computer Name = UTILISAT-2BCF2C | Source = Microsoft Office 12 Sessions | ID = 7001
      Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
      12.0.6504.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 18854
      seconds with 2520 seconds of active time. This session ended with a crash.

      Error - 23.06.2010 04:50:10 | Computer Name = UTILISAT-2BCF2C | Source = Microsoft Office 12 Sessions | ID = 7001
      Description = ID: 2, Application Name: Microsoft Office Access, Application Version:
      12.0.6423.1000, Microsoft Office Version: 12.0.6425.1000. This session lasted 1437
      seconds with 780 seconds of active time. This session ended with a crash.

      Error - 23.01.2011 13:07:29 | Computer Name = UTILISAT-2BCF2C | Source = Microsoft Office 12 Sessions | ID = 7001
      Description = ID: 3, Application Name: Microsoft Office PowerPoint, Application
      Version: 12.0.6500.5000, Microsoft Office Version: 12.0.6425.1000. This session
      lasted 741 seconds with 720 seconds of active time. This session ended with a crash.

      Error - 04.04.2011 18:45:15 | Computer Name = UTILISAT-2BCF2C | Source = Microsoft Office 12 Sessions | ID = 7001
      Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
      12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 129
      seconds with 60 seconds of active time. This session ended with a crash.

      Error - 22.08.2011 09:27:43 | Computer Name = UTILISAT-2BCF2C | Source = Microsoft Office 12 Sessions | ID = 7001
      Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
      12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 10083
      seconds with 1140 seconds of active time. This session ended with a crash.

      [ System Events ]
      Error - 16.11.2011 14:10:22 | Computer Name = UTILISAT-2BCF2C | Source = Service Control Manager | ID = 7009
      Description = Délai (30000 millisecondes) d'attente pour une connexion du service
      Avira AntiVir Guard.

      Error - 16.11.2011 14:10:22 | Computer Name = UTILISAT-2BCF2C | Source = Service Control Manager | ID = 7000
      Description = Le service Avira AntiVir Guard n'a pas pu démarrer en raison de l'erreur :
      %%1053

      Error - 16.11.2011 14:11:49 | Computer Name = UTILISAT-2BCF2C | Source = Service Control Manager | ID = 7022
      Description = Le service Service HP CUE DeviceDiscovery est en attente de démarrage.

      Error - 16.11.2011 14:11:49 | Computer Name = UTILISAT-2BCF2C | Source = Service Control Manager | ID = 7026
      Description = Le pilote de démarrage système ou d'amorçage suivant n'a pas pu se
      charger : SASDIFSV SASKUTIL

      Error - 16.11.2011 16:27:19 | Computer Name = UTILISAT-2BCF2C | Source = Service Control Manager | ID = 7000
      Description = Le service Microsoft Antimalware Service n'a pas pu démarrer en raison
      de l'erreur : %%5

      Error - 16.11.2011 16:27:19 | Computer Name = UTILISAT-2BCF2C | Source = Service Control Manager | ID = 7000
      Description = Le service Avira AntiVir Planificateur n'a pas pu démarrer en raison
      de l'erreur : %%2

      Error - 16.11.2011 16:27:19 | Computer Name = UTILISAT-2BCF2C | Source = Service Control Manager | ID = 7009
      Description = Délai (30000 millisecondes) d'attente pour une connexion du service
      Avira AntiVir Guard.

      Error - 16.11.2011 16:27:19 | Computer Name = UTILISAT-2BCF2C | Source = Service Control Manager | ID = 7000
      Description = Le service Avira AntiVir Guard n'a pas pu démarrer en raison de l'erreur :
      %%1053

      Error - 16.11.2011 16:28:40 | Computer Name = UTILISAT-2BCF2C | Source = Service Control Manager | ID = 7022
      Description = Le service Service HP CUE DeviceDiscovery est en attente de démarrage.

      Error - 16.11.2011 16:28:40 | Computer Name = UTILISAT-2BCF2C | Source = Service Control Manager | ID = 7026
      Description = Le pilote de démarrage système ou d'amorçage suivant n'a pas pu se
      charger : SASDIFSV SASKUTIL

      < End of report >
      0
    3. Re

      Utilise ces mêmes liens ci-joint ou autre pour me poster ces rapports;merci.

      @+
      0
  3. Re

    Poursuivons;

    Télécharge combofix : http://download.bleepingcomputer.com/sUBs/ComboFix.exe
    Ou ici : https://forospyware.com
    >Renomme le pour l'enregistrer sur ton bureau en asdehi (tout simplement pour que l'infection ne le contre pas)
    -> Double clique combofix.exe.(ou clic droit sous vista « exécuter en tant que... » )
    -> Tape sur la touche 1 (Yes) pour démarrer le scan.
    -> Lorsque le scan sera complété, un rapport apparaîtra. Copie/colle ce rapport dans ta prochaine réponse.

    NOTE : Le rapport se trouve également ici : C:\Combofix.txt

    Avant d'utiliser ComboFix :

    -> Déconnecte toi d'Internet et referme les fenêtres de tous les programmes en cours.

    -> Désactive provisoirement et seulement le temps de l'utilisation de ComboFix, la protection en temps réel de ton Antivirus et de tes Antispywares, qui peuvent gêner fortement la procédure de recherche et de nettoyage de l'outil.

    Une fois fait, sur ton bureau double-clic sur Combofix.exe ; (ou clic droit sous vista « exécuter en tant que... »)

    - Répond oui au message d'avertissement, pour que le programme commence à procéder à l'analyse du pc.

    - Installe le console de récupération comme demandé ;utile en cas de plantage

    - Attention Pendant la durée de cette étape, ne te sert pas du pc et n'ouvre aucun programme. Risque de figer l'ordinateur

    - En fin de scan il est possible que ComboFix ait besoin de redémarrer le pc pour finaliser la désinfection\recherche, laisses-le faire.

    - Un rapport s'ouvrira ensuite dans le bloc notes, ce fichier rapport Combofix.txt, est automatiquement sauvegardé et rangé à C:\Combofix.txt)

    -> Réactive la protection en temps réel de ton Antivirus et de tes Antispywares, avant de te reconnecter à internet.

    -> Reviens sur le forum, et copie et colle la totalité du contenu de C:\Combofix.txt dans ton prochain message.

    /!\ Ne touche à rien tant que le scan n'est pas terminé. /!\ : risque de figer l'ordinateur (plantage complet)

    ::Si combofix détecte quelque chose et de demande a redémarrer tu acceptes

    @+
    0
    1. Mon ordinateur plante toujours quand combofix tourne...
      0
    2. Et en mode sans echec?
      0
    3. la même chose
      0
  4. Re

    1) Télécharge DelFix de Xplode
    Ou si problème sur ce site : http://sd-1.archive-host.com/membres/up/17959594961240255/DelFix.exe

    Ou encore : https://www.commentcamarche.net/download/s/delfix

    * Lance le.
    * A l'invite, [Suppression]
    * Un rapport va s'ouvrir à la fin, colle le dans la réponse

    Ensuite pour le désinstaller ; tu relances et tu passes à l'option [Désinstallation]

    2)On reprend TDSSKiller.
    Télécharge TDSSKiller

    *Créez un nouveau dossier sur votre bureau puis décompressez l'archive dedans
    * Lancez le programme en cliquant sur TDSSKiller.exe, l'analyse se fait automatiquement, si l'infection est détectée, des éléments cachés (= hidden) seront alors affichés.

    Si TDSS.tdl2 est détecté: l'option delete sera cochée par défaut.
    Si TDSS.tdl3 est détecté: assure toi que Cure est bien cochée.
    Si TDSS.tdl4(\HardDisk0\MBR) est détecté: assure toi que Cure est bien cochée.
    Si Rootkit.Win32.ZAccess.* est détecté : règle sur "cure" en haut , et "delete" en bas
    Si Suspicious file est indiqué, laisse l''option cochée sur Skip
    une fois qu'il a terminé , redémarre s'il te le demande pour finir de nettoyer

    sinon , ferme TDSSKiller et le rapport s'affichera sur le bureau

    Poste moi son rapport à l'issue; merci

    @+

    0
    1. # DelFix v8.6 - Rapport créé le 16/11/2011 à 19:18:46
      # Mis à jour le 13/10/11 à 18h par Xplode
      # Système d'exploitation : Microsoft Windows XP Service Pack 3 (32 bits)
      # Nom d'utilisateur : Utilisateur - UTILISAT-2BCF2C (Administrateur)
      # Exécuté depuis : C:\Documents and Settings\Utilisateur\Bureau\delfix.exe
      # Option [Suppression]

      ~~~~~~ Dossiers(s) ~~~~~~

      Supprimé : C:\Qoobox
      Supprimé : C:\32788R22FWJFW
      Supprimé : C:\ZHP
      Supprimé : C:\Documents and Settings\Utilisateur\DoctorWeb
      Supprimé : C:\Documents and Settings\All Users\Menu Démarrer\Programmes\ZHP
      Supprimé : C:\Program Files\ZHPDiag

      ~~~~~~ Fichier(s) ~~~~~~

      Supprimé : C:\Documents and Settings\Utilisateur\Bureau\Antivirus forum\asdehi.exe <-- Combofix
      Supprimé : C:\AdwCleaner[R1].txt
      Supprimé : C:\TDSSKiller.2.6.15.0_05.11.2011_10.20.43_log.txt
      Supprimé : C:\TDSSKiller.2.6.15.0_05.11.2011_10.30.23_log.txt
      Supprimé : C:\TDSSKiller.2.6.15.0_08.11.2011_21.54.10_log.txt
      Supprimé : C:\Documents and Settings\All Users\Bureau\MBRCheck.lnk

      ~~~~~~ Registre ~~~~~~

      Clé Supprimée : HKCU\console_combofixbackup
      Clé Supprimée : HKCU\Software\IDAVLab
      Clé Supprimée : HKLM\SOFTWARE\AdwCleaner
      Clé Supprimée : HKLM\SOFTWARE\IDAVLab
      Clé Supprimée : HKLM\SOFTWARE\Swearware
      Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ZHPDiag_is1
      Clé Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\combofix.exe
      Clé Supprimée : HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart
      Clé Supprimée : HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys
      Clé Supprimée : HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PEVSystemStart
      Clé Supprimée : HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\procexp90.Sys

      ~~~~~~ Autres ~~~~~~

      -> Prefetch Vidé

      *************************

      DelFix[R1].txt - [1943 octets] - [16/11/2011 19:18:31]
      DelFix[S1].txt - [1921 octets] - [16/11/2011 19:18:46]

      ########## EOF - C:\DelFix[S1].txt - [2045 octets] ##########
      0
    2. TDSSKiller na rien trouvé
      0
    3. Re

      Poste moi le rapport;merci.
      0
    4. 19:56:22.0281 2112 TDSS rootkit removing tool 2.6.19.0 Nov 16 2011 12:18:50
      19:56:22.0578 2112 ============================================================
      19:56:22.0578 2112 Current date / time: 2011/11/16 19:56:22.0578
      19:56:22.0578 2112 SystemInfo:
      19:56:22.0578 2112
      19:56:22.0578 2112 OS Version: 5.1.2600 ServicePack: 3.0
      19:56:22.0578 2112 Product type: Workstation
      19:56:22.0578 2112 ComputerName: UTILISAT-2BCF2C
      19:56:22.0578 2112 UserName: Utilisateur
      19:56:22.0578 2112 Windows directory: C:\WINDOWS
      19:56:22.0578 2112 System windows directory: C:\WINDOWS
      19:56:22.0578 2112 Processor architecture: Intel x86
      19:56:22.0578 2112 Number of processors: 1
      19:56:22.0578 2112 Page size: 0x1000
      19:56:22.0578 2112 Boot type: Normal boot
      19:56:22.0578 2112 ============================================================
      19:56:23.0093 2112 Initialize success
      19:56:31.0125 3080 ============================================================
      19:56:31.0125 3080 Scan started
      19:56:31.0125 3080 Mode: Manual;
      19:56:31.0125 3080 ============================================================
      19:56:31.0390 3080 Abiosdsk - ok
      19:56:31.0437 3080 abp480n5 - ok
      19:56:31.0484 3080 ACPI (e5e6dbfc41ea8aad005cb9a57a96b43b) C:\WINDOWS\system32\DRIVERS\ACPI.sys
      19:56:31.0484 3080 ACPI - ok
      19:56:31.0531 3080 ACPIEC (e4abc1212b70bb03d35e60681c447210) C:\WINDOWS\system32\DRIVERS\ACPIEC.sys
      19:56:31.0531 3080 ACPIEC - ok
      19:56:31.0562 3080 adpu160m - ok
      19:56:31.0625 3080 aeaudio (ad707942e4ccb28d77cee5ed989c9e55) C:\WINDOWS\system32\drivers\aeaudio.sys
      19:56:31.0625 3080 aeaudio - ok
      19:56:31.0687 3080 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
      19:56:31.0687 3080 aec - ok
      19:56:31.0750 3080 AFD (1e44bc1e83d8fd2305f8d452db109cf9) C:\WINDOWS\System32\drivers\afd.sys
      19:56:31.0750 3080 AFD - ok
      19:56:31.0828 3080 AgereSoftModem (029e01cb2938bec5af31bf47b6af0159) C:\WINDOWS\system32\DRIVERS\AGRSM.sys
      19:56:31.0843 3080 AgereSoftModem - ok
      19:56:31.0859 3080 Aha154x - ok
      19:56:31.0890 3080 aic78u2 - ok
      19:56:31.0906 3080 aic78xx - ok
      19:56:31.0937 3080 AliIde - ok
      19:56:31.0953 3080 amsint - ok
      19:56:32.0000 3080 asc - ok
      19:56:32.0015 3080 asc3350p - ok
      19:56:32.0031 3080 asc3550 - ok
      19:56:32.0109 3080 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
      19:56:32.0109 3080 AsyncMac - ok
      19:56:32.0171 3080 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
      19:56:32.0171 3080 atapi - ok
      19:56:32.0187 3080 Atdisk - ok
      19:56:32.0234 3080 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
      19:56:32.0250 3080 Atmarpc - ok
      19:56:32.0296 3080 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
      19:56:32.0296 3080 audstub - ok
      19:56:32.0437 3080 avgio (0b497c79824f8e1bf22fa6aacd3de3a0) C:\Program Files\Avira\AntiVir Desktop\avgio.sys
      19:56:32.0453 3080 avgio - ok
      19:56:32.0578 3080 avgntflt (1e4114685de1ffa9675e09c6a1fb3f4b) C:\WINDOWS\system32\DRIVERS\avgntflt.sys
      19:56:32.0578 3080 avgntflt - ok
      19:56:32.0640 3080 avipbb (0f78d3dae6dedd99ae54c9491c62adf2) C:\WINDOWS\system32\DRIVERS\avipbb.sys
      19:56:32.0640 3080 avipbb - ok
      19:56:32.0750 3080 b57w2k (452649bd89ce0775cf3e25ec2a5b348d) C:\WINDOWS\system32\DRIVERS\b57xp32.sys
      19:56:32.0765 3080 b57w2k - ok
      19:56:32.0843 3080 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
      19:56:32.0843 3080 Beep - ok
      19:56:32.0984 3080 catchme - ok
      19:56:33.0140 3080 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
      19:56:33.0140 3080 cbidf2k - ok
      19:56:33.0203 3080 cd20xrnt - ok
      19:56:33.0312 3080 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
      19:56:33.0328 3080 Cdaudio - ok
      19:56:33.0390 3080 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
      19:56:33.0390 3080 Cdfs - ok
      19:56:33.0453 3080 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\drivers\tsk7D.tmp
      19:56:33.0453 3080 Cdrom - ok
      19:56:33.0468 3080 Changer - ok
      19:56:33.0562 3080 CmBatt (0f6c187d38d98f8df904589a5f94d411) C:\WINDOWS\system32\DRIVERS\CmBatt.sys
      19:56:33.0562 3080 CmBatt - ok
      19:56:33.0578 3080 CmdIde - ok
      19:56:33.0609 3080 Compbatt (6e4c9f21f0fae8940661144f41b13203) C:\WINDOWS\system32\DRIVERS\compbatt.sys
      19:56:33.0609 3080 Compbatt - ok
      19:56:33.0640 3080 Cpqarray - ok
      19:56:33.0671 3080 dac2w2k - ok
      19:56:33.0687 3080 dac960nt - ok
      19:56:33.0718 3080 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
      19:56:33.0718 3080 Disk - ok
      19:56:33.0781 3080 dmboot (f5deadd42335fb33edca74ecb2f36cba) C:\WINDOWS\system32\drivers\dmboot.sys
      19:56:33.0796 3080 dmboot - ok
      19:56:33.0828 3080 dmio (5a7c47c9b3f9fb92a66410a7509f0c71) C:\WINDOWS\system32\drivers\dmio.sys
      19:56:33.0828 3080 dmio - ok
      19:56:33.0859 3080 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
      19:56:33.0875 3080 dmload - ok
      19:56:33.0921 3080 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
      19:56:33.0921 3080 DMusic - ok
      19:56:33.0953 3080 dpti2o - ok
      19:56:33.0984 3080 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
      19:56:33.0984 3080 drmkaud - ok
      19:56:34.0000 3080 dwshd - ok
      19:56:34.0062 3080 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
      19:56:34.0062 3080 Fastfat - ok
      19:56:34.0093 3080 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\drivers\Fdc.sys
      19:56:34.0093 3080 Fdc - ok
      19:56:34.0125 3080 Fips (31f923eb2170fc172c81abda0045d18c) C:\WINDOWS\system32\drivers\Fips.sys
      19:56:34.0125 3080 Fips - ok
      19:56:34.0140 3080 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\drivers\Flpydisk.sys
      19:56:34.0140 3080 Flpydisk - ok
      19:56:34.0203 3080 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
      19:56:34.0203 3080 FltMgr - ok
      19:56:34.0250 3080 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
      19:56:34.0250 3080 Fs_Rec - ok
      19:56:34.0265 3080 Ftdisk (a86859b77b908c18c2657f284aa29fe3) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
      19:56:34.0265 3080 Ftdisk - ok
      19:56:34.0296 3080 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
      19:56:34.0296 3080 Gpc - ok
      19:56:34.0343 3080 GTIPCI21 (cea72ac01892b12514d15e21ef1bc75d) C:\WINDOWS\system32\DRIVERS\gtipci21.sys
      19:56:34.0359 3080 GTIPCI21 - ok
      19:56:34.0437 3080 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
      19:56:34.0437 3080 HidUsb - ok
      19:56:34.0515 3080 HPFXBULK (299683d4c8aaa3f6f5d5d226a1782a6e) C:\WINDOWS\system32\drivers\hpfxbulk.sys
      19:56:34.0515 3080 HPFXBULK - ok
      19:56:34.0546 3080 hpn - ok
      19:56:34.0593 3080 HpqKbFiltr (35956140e686d53bf676cf0c778880fc) C:\WINDOWS\system32\DRIVERS\HpqKbFiltr.sys
      19:56:34.0593 3080 HpqKbFiltr - ok
      19:56:34.0671 3080 HPZid412 (d03d10f7ded688fecf50f8fbf1ea9b8a) C:\WINDOWS\system32\DRIVERS\HPZid412.sys
      19:56:34.0671 3080 HPZid412 - ok
      19:56:34.0734 3080 HPZipr12 (89f41658929393487b6b7d13c8528ce3) C:\WINDOWS\system32\DRIVERS\HPZipr12.sys
      19:56:34.0734 3080 HPZipr12 - ok
      19:56:34.0765 3080 HPZius12 (abcb05ccdbf03000354b9553820e39f8) C:\WINDOWS\system32\DRIVERS\HPZius12.sys
      19:56:34.0765 3080 HPZius12 - ok
      19:56:34.0859 3080 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
      19:56:34.0859 3080 HTTP - ok
      19:56:34.0890 3080 i2omgmt - ok
      19:56:34.0906 3080 i2omp - ok
      19:56:34.0984 3080 i8042prt (a09bdc4ed10e3b2e0ec27bb94af32516) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
      19:56:34.0984 3080 i8042prt - ok
      19:56:35.0062 3080 ialm (9e52a1c2e2d7660612c52bc282259852) C:\WINDOWS\system32\DRIVERS\ialmnt5.sys
      19:56:35.0078 3080 ialm - ok
      19:56:35.0140 3080 IFXTPM (0a359837e021bc04a04a6fd189492c65) C:\WINDOWS\system32\DRIVERS\IFXTPM.SYS
      19:56:35.0140 3080 IFXTPM - ok
      19:56:35.0187 3080 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
      19:56:35.0203 3080 Imapi - ok
      19:56:35.0281 3080 InCDfs (580a81790cd0a48d85da322267da7ac4) C:\WINDOWS\system32\drivers\InCDFs.sys
      19:56:35.0281 3080 InCDfs - ok
      19:56:35.0296 3080 InCDPass (aaa2789d2ce21b31be9406ba1ceb7285) C:\WINDOWS\system32\drivers\InCDPass.sys
      19:56:35.0296 3080 InCDPass - ok
      19:56:35.0343 3080 InCDrec (4d022577e9072b5d22e0a383a7806bbb) C:\WINDOWS\system32\drivers\InCDrec.sys
      19:56:35.0343 3080 InCDrec - ok
      19:56:35.0359 3080 incdrm (c258e57321a3c3737f4fa815fa69ee0b) C:\WINDOWS\system32\drivers\InCDRm.sys
      19:56:35.0359 3080 incdrm - ok
      19:56:35.0390 3080 ini910u - ok
      19:56:35.0468 3080 IntelIde (4b6da2f0a4095857a9e3f3697399d575) C:\WINDOWS\system32\DRIVERS\intelide.sys
      19:56:35.0468 3080 IntelIde - ok
      19:56:35.0500 3080 intelppm (ad340800c35a42d4de1641a37feea34c) C:\WINDOWS\system32\DRIVERS\intelppm.sys
      19:56:35.0500 3080 intelppm - ok
      19:56:35.0546 3080 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
      19:56:35.0546 3080 Ip6Fw - ok
      19:56:35.0609 3080 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
      19:56:35.0609 3080 IpFilterDriver - ok
      19:56:35.0671 3080 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
      19:56:35.0671 3080 IpInIp - ok
      19:56:35.0718 3080 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
      19:56:35.0718 3080 IpNat - ok
      19:56:35.0750 3080 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
      19:56:35.0750 3080 IPSec - ok
      19:56:35.0781 3080 irda (aca5e7b54409f9cb5eed97ed0c81120e) C:\WINDOWS\system32\DRIVERS\irda.sys
      19:56:35.0796 3080 irda - ok
      19:56:35.0812 3080 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
      19:56:35.0812 3080 IRENUM - ok
      19:56:35.0875 3080 isapnp (355836975a67b6554bca60328cd6cb74) C:\WINDOWS\system32\DRIVERS\isapnp.sys
      19:56:35.0875 3080 isapnp - ok
      19:56:35.0921 3080 Kbdclass (16813155807c6881f4bfbf6657424659) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
      19:56:35.0937 3080 Kbdclass - ok
      19:56:35.0968 3080 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
      19:56:35.0968 3080 kmixer - ok
      19:56:36.0046 3080 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
      19:56:36.0046 3080 KSecDD - ok
      19:56:36.0078 3080 lbrtfdc - ok
      19:56:36.0156 3080 MarvinBus (a3e700d78eec390f1208098cdca5c6b6) C:\WINDOWS\system32\DRIVERS\MarvinBus.sys
      19:56:36.0156 3080 MarvinBus - ok
      19:56:36.0218 3080 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
      19:56:36.0218 3080 mnmdd - ok
      19:56:36.0265 3080 Modem (510ade9327fe84c10254e1902697e25f) C:\WINDOWS\system32\drivers\Modem.sys
      19:56:36.0265 3080 Modem - ok
      19:56:36.0312 3080 Mouclass (027c01bd7ef3349aaebc883d8a799efb) C:\WINDOWS\system32\DRIVERS\mouclass.sys
      19:56:36.0312 3080 Mouclass - ok
      19:56:36.0375 3080 mouhid (124d6846040c79b9c997f78ef4b2a4e5) C:\WINDOWS\system32\DRIVERS\mouhid.sys
      19:56:36.0375 3080 mouhid - ok
      19:56:36.0406 3080 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
      19:56:36.0406 3080 MountMgr - ok
      19:56:36.0453 3080 MpFilter (fee0baded54222e9f1dae9541212aab1) C:\WINDOWS\system32\DRIVERS\MpFilter.sys
      19:56:36.0453 3080 MpFilter - ok
      19:56:36.0656 3080 MpKslce6e99e1 - ok
      19:56:36.0671 3080 MpKslf62ca398 - ok
      19:56:36.0718 3080 mraid35x - ok
      19:56:36.0765 3080 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
      19:56:36.0781 3080 MRxDAV - ok
      19:56:36.0843 3080 MRxSmb (7d304a5eb4344ebeeab53a2fe3ffb9f0) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
      19:56:36.0843 3080 MRxSmb - ok
      19:56:36.0890 3080 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
      19:56:36.0890 3080 Msfs - ok
      19:56:36.0921 3080 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
      19:56:36.0937 3080 MSKSSRV - ok
      19:56:36.0953 3080 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
      19:56:36.0953 3080 MSPCLOCK - ok
      19:56:36.0968 3080 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
      19:56:36.0984 3080 MSPQM - ok
      19:56:37.0015 3080 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
      19:56:37.0015 3080 mssmbios - ok
      19:56:37.0078 3080 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys
      19:56:37.0078 3080 Mup - ok
      19:56:37.0125 3080 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
      19:56:37.0125 3080 NDIS - ok
      19:56:37.0187 3080 NdisTapi (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
      19:56:37.0187 3080 NdisTapi - ok
      19:56:37.0234 3080 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
      19:56:37.0250 3080 Ndisuio - ok
      19:56:37.0265 3080 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
      19:56:37.0265 3080 NdisWan - ok
      19:56:37.0328 3080 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
      19:56:37.0343 3080 NDProxy - ok
      19:56:37.0390 3080 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
      19:56:37.0390 3080 NetBIOS - ok
      19:56:37.0437 3080 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
      19:56:37.0437 3080 NetBT - ok
      19:56:37.0500 3080 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
      19:56:37.0500 3080 Npfs - ok
      19:56:37.0562 3080 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
      19:56:37.0562 3080 Ntfs - ok
      19:56:37.0625 3080 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
      19:56:37.0625 3080 Null - ok
      19:56:37.0687 3080 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
      19:56:37.0687 3080 NwlnkFlt - ok
      19:56:37.0765 3080 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
      19:56:37.0765 3080 NwlnkFwd - ok
      19:56:37.0843 3080 Parport (8fd0bdbea875d06ccf6c945ca9abaf75) C:\WINDOWS\system32\DRIVERS\parport.sys
      19:56:37.0859 3080 Parport - ok
      19:56:37.0921 3080 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
      19:56:37.0921 3080 PartMgr - ok
      19:56:38.0000 3080 ParVdm (9575c5630db8fb804649a6959737154c) C:\WINDOWS\system32\drivers\ParVdm.sys
      19:56:38.0000 3080 ParVdm - ok
      19:56:38.0046 3080 PCI (043410877bda580c528f45165f7125bc) C:\WINDOWS\system32\DRIVERS\pci.sys
      19:56:38.0046 3080 PCI - ok
      19:56:38.0062 3080 PCIDump - ok
      19:56:38.0109 3080 PCIIde (f4bfde7209c14a07aaa61e4d6ae69eac) C:\WINDOWS\system32\drivers\PCIIde.sys
      19:56:38.0109 3080 PCIIde - ok
      19:56:38.0156 3080 Pcmcia (f0406cbc60bdb0394a0e17ffb04cdd3d) C:\WINDOWS\system32\DRIVERS\pcmcia.sys
      19:56:38.0156 3080 Pcmcia - ok
      19:56:38.0203 3080 PCTBD (3a0262b85b5bb4d4cfc096ea00ed610b) C:\WINDOWS\system32\Drivers\PCTBD.sys
      19:56:38.0203 3080 PCTBD - ok
      19:56:38.0218 3080 PDCOMP - ok
      19:56:38.0250 3080 PDFRAME - ok
      19:56:38.0265 3080 PDRELI - ok
      19:56:38.0281 3080 PDRFRAME - ok
      19:56:38.0312 3080 perc2 - ok
      19:56:38.0328 3080 perc2hib - ok
      19:56:38.0421 3080 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
      19:56:38.0421 3080 PptpMiniport - ok
      19:56:38.0468 3080 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
      19:56:38.0468 3080 PSched - ok
      19:56:38.0500 3080 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
      19:56:38.0500 3080 Ptilink - ok
      19:56:38.0546 3080 PxHelp20 (e42e3433dbb4cffe8fdd91eab29aea8e) C:\WINDOWS\system32\Drivers\PxHelp20.sys
      19:56:38.0546 3080 PxHelp20 - ok
      19:56:38.0593 3080 ql1080 - ok
      19:56:38.0609 3080 Ql10wnt - ok
      19:56:38.0640 3080 ql12160 - ok
      19:56:38.0656 3080 ql1240 - ok
      19:56:38.0687 3080 ql1280 - ok
      19:56:38.0718 3080 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
      19:56:38.0718 3080 RasAcd - ok
      19:56:38.0765 3080 Rasirda (0207d26ddf796a193ccd9f83047bb5fc) C:\WINDOWS\system32\DRIVERS\rasirda.sys
      19:56:38.0765 3080 Rasirda - ok
      19:56:38.0828 3080 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
      19:56:38.0843 3080 Rasl2tp - ok
      19:56:38.0859 3080 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
      19:56:38.0859 3080 RasPppoe - ok
      19:56:38.0921 3080 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
      19:56:38.0921 3080 Raspti - ok
      19:56:38.0968 3080 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
      19:56:38.0968 3080 Rdbss - ok
      19:56:39.0015 3080 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
      19:56:39.0015 3080 RDPCDD - ok
      19:56:39.0078 3080 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
      19:56:39.0078 3080 rdpdr - ok
      19:56:39.0156 3080 RDPWD (fc105dd312ed64eb66bff111e8ec6eac) C:\WINDOWS\system32\drivers\RDPWD.sys
      19:56:39.0156 3080 RDPWD - ok
      19:56:39.0218 3080 redbook (d8eb2a7904db6c916eb5361878ddcbae) C:\WINDOWS\system32\DRIVERS\redbook.sys
      19:56:39.0234 3080 redbook - ok
      19:56:39.0281 3080 s24trans (96b4494d4734970f47c566e098c4f527) C:\WINDOWS\system32\DRIVERS\s24trans.sys
      19:56:39.0281 3080 s24trans - ok
      19:56:39.0437 3080 SASDIFSV - ok
      19:56:39.0453 3080 SASKUTIL - ok
      19:56:39.0531 3080 sdbus (8d04819a3ce51b9eb47e5689b44d43c4) C:\WINDOWS\system32\DRIVERS\sdbus.sys
      19:56:39.0531 3080 sdbus - ok
      19:56:39.0593 3080 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
      19:56:39.0593 3080 Secdrv - ok
      19:56:39.0625 3080 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
      19:56:39.0625 3080 serenum - ok
      19:56:39.0687 3080 Serial (93d313c31f7ad9ea2b75f26075413c7c) C:\WINDOWS\system32\DRIVERS\serial.sys
      19:56:39.0687 3080 Serial - ok
      19:56:39.0734 3080 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
      19:56:39.0734 3080 Sfloppy - ok
      19:56:39.0765 3080 Simbad - ok
      19:56:39.0828 3080 SMCIRDA (039f7b892ad78fd836cd56f0551dab33) C:\WINDOWS\system32\DRIVERS\smcirda.sys
      19:56:39.0828 3080 SMCIRDA - ok
      19:56:39.0859 3080 smwdm (858934c454bdc6664c752bf0cd3eaeae) C:\WINDOWS\system32\drivers\smwdm.sys
      19:56:39.0875 3080 smwdm - ok
      19:56:39.0890 3080 Sparrow - ok
      19:56:39.0937 3080 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
      19:56:39.0937 3080 splitter - ok
      19:56:40.0000 3080 sr (39626e6dc1fb39434ec40c42722b660a) C:\WINDOWS\system32\DRIVERS\sr.sys
      19:56:40.0000 3080 sr - ok
      19:56:40.0078 3080 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys
      19:56:40.0078 3080 Srv - ok
      19:56:40.0156 3080 ssmdrv (3ad0362cf68de3ac500e981700242cca) C:\WINDOWS\system32\DRIVERS\ssmdrv.sys
      19:56:40.0156 3080 ssmdrv - ok
      19:56:40.0234 3080 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
      19:56:40.0234 3080 swenum - ok
      19:56:40.0265 3080 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
      19:56:40.0265 3080 swmidi - ok
      19:56:40.0296 3080 symc810 - ok
      19:56:40.0328 3080 symc8xx - ok
      19:56:40.0343 3080 sym_hi - ok
      19:56:40.0359 3080 sym_u3 - ok
      19:56:40.0390 3080 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
      19:56:40.0406 3080 sysaudio - ok
      19:56:40.0484 3080 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
      19:56:40.0484 3080 Tcpip - ok
      19:56:40.0546 3080 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
      19:56:40.0546 3080 TDPIPE - ok
      19:56:40.0578 3080 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
      19:56:40.0578 3080 TDTCP - ok
      19:56:40.0609 3080 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
      19:56:40.0609 3080 TermDD - ok
      19:56:40.0703 3080 tifm21 (c424f991494e5674f2e9b3cf9f5f55d1) C:\WINDOWS\system32\drivers\tifm21.sys
      19:56:40.0703 3080 tifm21 - ok
      19:56:40.0734 3080 TosIde - ok
      19:56:40.0812 3080 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
      19:56:40.0828 3080 Udfs - ok
      19:56:40.0859 3080 ultra - ok
      19:56:40.0953 3080 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
      19:56:40.0953 3080 Update - ok
      19:56:41.0031 3080 usbaudio (e919708db44ed8543a7c017953148330) C:\WINDOWS\system32\drivers\usbaudio.sys
      19:56:41.0031 3080 usbaudio - ok
      19:56:41.0109 3080 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
      19:56:41.0109 3080 usbccgp - ok
      19:56:41.0171 3080 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
      19:56:41.0187 3080 usbehci - ok
      19:56:41.0250 3080 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
      19:56:41.0250 3080 usbhub - ok
      19:56:41.0312 3080 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys
      19:56:41.0312 3080 usbprint - ok
      19:56:41.0375 3080 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
      19:56:41.0375 3080 usbscan - ok
      19:56:41.0437 3080 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
      19:56:41.0453 3080 USBSTOR - ok
      19:56:41.0484 3080 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
      19:56:41.0484 3080 usbuhci - ok
      19:56:41.0515 3080 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
      19:56:41.0515 3080 VgaSave - ok
      19:56:41.0531 3080 ViaIde - ok
      19:56:41.0546 3080 VolSnap (46de1126684369bace4849e4fc8c43ca) C:\WINDOWS\system32\drivers\VolSnap.sys
      19:56:41.0562 3080 VolSnap - ok
      19:56:41.0718 3080 w29n51 (f0608f3b5b6d16f4870e867f9d069b6b) C:\WINDOWS\system32\DRIVERS\w29n51.sys
      19:56:41.0750 3080 w29n51 - ok
      19:56:41.0796 3080 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
      19:56:41.0796 3080 Wanarp - ok
      19:56:41.0875 3080 Wdf01000 (fd47474bd21794508af449d9d91af6e6) C:\WINDOWS\system32\DRIVERS\Wdf01000.sys
      19:56:41.0890 3080 Wdf01000 - ok
      19:56:41.0906 3080 WDICA - ok
      19:56:41.0953 3080 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
      19:56:41.0953 3080 wdmaud - ok
      19:56:42.0031 3080 WmiAcpi (c42584fd66ce9e17403aebca199f7bdb) C:\WINDOWS\system32\DRIVERS\wmiacpi.sys
      19:56:42.0031 3080 WmiAcpi - ok
      19:56:42.0093 3080 WS2IFSL (6abe6e225adb5a751622a9cc3bc19ce8) C:\WINDOWS\System32\drivers\ws2ifsl.sys
      19:56:42.0093 3080 WS2IFSL - ok
      19:56:42.0171 3080 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
      19:56:42.0171 3080 WudfPf - ok
      19:56:42.0203 3080 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
      19:56:42.0203 3080 WudfRd - ok
      19:56:42.0265 3080 MBR (0x1B8) (5f8b5082f3482cc06b72ec5806598ae9) \Device\Harddisk0\DR0
      19:56:43.0468 3080 \Device\Harddisk0\DR0 - ok
      19:56:43.0484 3080 Boot (0x1200) (c3d7f115683d9289182bd25be79d2294) \Device\Harddisk0\DR0\Partition0
      19:56:43.0484 3080 \Device\Harddisk0\DR0\Partition0 - ok
      19:56:43.0484 3080 ============================================================
      19:56:43.0484 3080 Scan finished
      19:56:43.0484 3080 ============================================================
      19:56:43.0500 2812 Detected object count: 0
      19:56:43.0500 2812 Actual detected object count: 0
      0
  5. Bonsoir

    Cette dernière version 1.51.2.1300 est la bonne ;mais tu n'as pas procéder à une mise à jour .
    Reprend l'analyse rapide après et poste moi un nouveau rapport;merci.

    @+
    0
    1. Merci, mais je n'arrive pas à faire la mise à jour, il met un message d'erreur: program_error:_updating (2,0, no address found)
      0
  6. Bonsoir

    Télécharge Malwaresbytes anti malware ici
    http://www.malwarebytes.org/mbam.php

    Bouton »Download free version »

    * Installe le (choisis bien "français" ; ne modifie pas les paramètres d'installe ) et mets le à jour .

    (NB : S'il te manque "COMCTL32.OCX" lors de l'installe, alors télécharge le ici : https://www.malekal.com/tutorial-aboutbuster/

    * Potasse le tuto pour te familiariser avec le prg :

    https://forum.pcastuces.com/sujet.asp?f=31&s=3

    (cela dis, il est très simple d'utilisation).

    relance Malwaresbytes en suivant scrupuleusement ces consignes :

    ! Déconnecte toi et ferme toutes applications en cours !

    * Lance Malwarebyte's. Sous Vista et Seven (clic droit de la souris « exécuter en tant que administrateur »)

    Fais un examen dit "Complet"

    --> Laisse le programme travailler ( et ne rien faire d'autre avec le PC durant le scan ).
    --> à la fin tu cliques sur "Afficher les résultats" " .
    --> Vérifie que tous les objets infectés soient validés, puis clique sur " supprimer la sélection " .

    Note : si il faut redémarrer ton PC pour finir le nettoyage, fais le !

    Poste le rapport sauvegardé après la suppression des objets infectés (dans l'onglet "rapport/log"de Malwaresbytes, le dernier en date)

    @+
    0
    1. Bonjour

      Désolé pour le délai, j'étais en déplacement quelques jours. Voici le log de l'examen rapide, je ne trouve pas le log de l'examen complet. De plus je n'ai pas pu faire la mise à jour au départ, il dit qu'il y a un problème. Y a t-il un moyen de télécharger la mise à jour séparément?

      Malwarebytes' Anti-Malware 1.46
      www.malwarebytes.org

      Version de la base de données: 5087

      Windows 5.1.2600 Service Pack 3
      Internet Explorer 7.0.5730.13

      10.11.2010 11:21:41
      mbam-log-2010-11-10 (11-21-41).txt

      Type d'examen: Examen rapide
      Elément(s) analysé(s): 165116
      Temps écoulé: 10 minute(s), 15 seconde(s)

      Processus mémoire infecté(s): 0
      Module(s) mémoire infecté(s): 0
      Clé(s) du Registre infectée(s): 0
      Valeur(s) du Registre infectée(s): 1
      Elément(s) de données du Registre infecté(s): 0
      Dossier(s) infecté(s): 0
      Fichier(s) infecté(s): 0

      Processus mémoire infecté(s):
      (Aucun élément nuisible détecté)

      Module(s) mémoire infecté(s):
      (Aucun élément nuisible détecté)

      Clé(s) du Registre infectée(s):
      (Aucun élément nuisible détecté)

      Valeur(s) du Registre infectée(s):
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\taskman (Worm.Autorun) -> Quarantined and deleted successfully.

      Elément(s) de données du Registre infecté(s):
      (Aucun élément nuisible détecté)

      Dossier(s) infecté(s):
      (Aucun élément nuisible détecté)

      Fichier(s) infecté(s):
      (Aucun élément nuisible détecté)
      0
    2. Malwarebytes' Anti-Malware 1.51.2.1300
      www.malwarebytes.org

      Version de la base de données: 7622

      Windows 5.1.2600 Service Pack 3
      Internet Explorer 8.0.6001.18702

      16.11.2011 10:56:25
      mbam-log-2011-11-16 (10-56-18).txt

      Type d'examen: Examen complet (C:\|)
      Elément(s) analysé(s): 352620
      Temps écoulé: 52 minute(s), 55 seconde(s)

      Processus mémoire infecté(s): 0
      Module(s) mémoire infecté(s): 0
      Clé(s) du Registre infectée(s): 0
      Valeur(s) du Registre infectée(s): 0
      Elément(s) de données du Registre infecté(s): 0
      Dossier(s) infecté(s): 0
      Fichier(s) infecté(s): 1

      Processus mémoire infecté(s):
      (Aucun élément nuisible détecté)

      Module(s) mémoire infecté(s):
      (Aucun élément nuisible détecté)

      Clé(s) du Registre infectée(s):
      (Aucun élément nuisible détecté)

      Valeur(s) du Registre infectée(s):
      (Aucun élément nuisible détecté)

      Elément(s) de données du Registre infecté(s):
      (Aucun élément nuisible détecté)

      Dossier(s) infecté(s):
      (Aucun élément nuisible détecté)

      Fichier(s) infecté(s):
      c:\system volume information\_restore{52dc0616-98b4-4d8b-bb8e-b9b5a34f7446}\RP327\A0081825.exe (Trojan.Agent) -> No action taken.
      0
  7. J'ai essayé encore Combofix, il commence par me dire ce message: Combo fix me transmet ces messages au cours du scan:"Vous êtes infectés par un rootkit.zero access qui est inséré dans la pile tcp/ip" "cela est compliqué"...
    0
    1. J'ai aussi fait ça: https://www.malekal.com/zeroaccesssirefef-remover/

      et il me dit que le système n'est pas infecté par ZeroAccess/Max++ Rootkit
      0
      1. Webroot AntiZeroAccess 0.8 Log File
        Execution time: 09/11/2011 - 08:57
        Host operation System: Windows Xp X86 version 5.1.2600 Service Pack 3
        08:57:28 - CheckSystem - Begin to check system...
        08:57:28 - OpenRootDrive - Opening system root volume and physical drive....
        08:57:28 - C Root Drive: Disk number: 0 Start sector: 0x0000003F Partition Size: 0x06FC7C41 sectors.
        08:57:28 - PrevX Main driver extracted in "C:\WINDOWS\system32\drivers\ZeroAccess.sys".
        08:57:29 - InstallAndStartDriver - Main driver was installed and now is running.
        08:57:29 - CheckSystem - Disk class driver state is OK.
        08:57:35 - StopAndRemoveDriver - AntiZeroAccess Driver is stopped and removed.
        08:57:35 - StopAndRemoveDriver - File "ZeroAccess.sys" was deleted!
        08:57:35 - Execution Ended!
        0
    2. J'ai essayé mais il plante à la fin du scan, même en mode sans échec..
      0
      1. Bonsoir

        Essaie maintenant de poster un rapport ZHPDiag;merci.

        @+
        0
        1. 0
          1. searchprotocolhost.exe C:\WINDOWS\system32 Trojan.Starter.1695 Désinfecté.
            wuauclt.exe.tmp C:\WINDOWS\system32 Trojan.Starter.1695 Désinfecté.
            x c:\documents and settings\utilisateur\local settings\application data\b4c73fa4 Trojan.Siggen3.16836 Irréparable.Quarantaine.
            rbmonitor.exe c:\program files\uniblue\registrybooster Program.Uniblue.4
            rbmonitor.exe c:\program files\uniblue\registrybooster Program.Uniblue.4
            596a7b0b-491af3c7 C:\Documents and Settings\Utilisateur\Application Data\Sun\Java\Deployment\cache\6.0\11 BackDoor.Maxplus.158 Irréparable.Quarantaine.
            394b7214-1ca75696 C:\Documents and Settings\Utilisateur\Application Data\Sun\Java\Deployment\cache\6.0\20 BackDoor.Maxplus.196 Irréparable.Quarantaine.
            73b56d3d-7551144c C:\Documents and Settings\Utilisateur\Application Data\Sun\Java\Deployment\cache\6.0\61 BackDoor.Maxplus.212 Irréparable.Quarantaine.
            registryboosterplc.exe C:\Documents and Settings\Utilisateur\Bureau\Nettoyage Program.Uniblue.7 - erreur de lecture
            Setup_FreeVideoConverter.exe C:\Program Files\Free Video Converter Adware.Downware.52
            Launcher.exe C:\Program Files\Uniblue\RegistryBooster Program.Uniblue.5 - erreur de lecture
            rbmonitor.exe C:\Program Files\Uniblue\RegistryBooster Program.Uniblue.4 - erreur de lecture
            rbnotifier.exe C:\Program Files\Uniblue\RegistryBooster Program.Uniblue.4 - erreur de lecture
            rb_move_serial.exe C:\Program Files\Uniblue\RegistryBooster Program.Uniblue.4 - erreur de lecture
            rb_ubm.exe C:\Program Files\Uniblue\RegistryBooster Program.Uniblue.4 - erreur de lecture
            registrybooster.exe C:\Program Files\Uniblue\RegistryBooster Program.Uniblue.4 - erreur de lecture
            A0064514.exe C:\System Volume Information\_restore{52DC0616-98B4-4D8B-BB8E-B9B5A34F7446}\RP309 Adware.Downware.52
            A0067025.exe C:\System Volume Information\_restore{52DC0616-98B4-4D8B-BB8E-B9B5A34F7446}\RP315 Trojan.Starter.1695 Désinfecté.
            A0068103.exe C:\System Volume Information\_restore{52DC0616-98B4-4D8B-BB8E-B9B5A34F7446}\RP315 Trojan.Starter.1695 Désinfecté.
            A0069989.ini C:\System Volume Information\_restore{52DC0616-98B4-4D8B-BB8E-B9B5A34F7446}\RP321 BackDoor.Siggen.37524 Supprimé.
            A0070003.ini C:\System Volume Information\_restore{52DC0616-98B4-4D8B-BB8E-B9B5A34F7446}\RP321 BackDoor.Siggen.37524 Supprimé.
            A0071003.ini C:\System Volume Information\_restore{52DC0616-98B4-4D8B-BB8E-B9B5A34F7446}\RP321 BackDoor.Siggen.37524 Supprimé.
            A0071049.exe C:\System Volume Information\_restore{52DC0616-98B4-4D8B-BB8E-B9B5A34F7446}\RP322 Trojan.Starter.1695 Désinfecté.
            A0071168.ini C:\System Volume Information\_restore{52DC0616-98B4-4D8B-BB8E-B9B5A34F7446}\RP322 BackDoor.Siggen.37524 Supprimé.
            A0071238.ini C:\System Volume Information\_restore{52DC0616-98B4-4D8B-BB8E-B9B5A34F7446}\RP325 BackDoor.Siggen.37524 Supprimé.
            A0072238.ini C:\System Volume Information\_restore{52DC0616-98B4-4D8B-BB8E-B9B5A34F7446}\RP325 BackDoor.Siggen.37524 Supprimé.
            A0075318.exe C:\System Volume Information\_restore{52DC0616-98B4-4D8B-BB8E-B9B5A34F7446}\RP326 Trojan.Starter.1695 Désinfecté.
            A0081713.exe C:\System Volume Information\_restore{52DC0616-98B4-4D8B-BB8E-B9B5A34F7446}\RP326 Program.Uniblue.7 - erreur de lecture
            A0081714.exe C:\System Volume Information\_restore{52DC0616-98B4-4D8B-BB8E-B9B5A34F7446}\RP327 Program.Uniblue.5 - erreur de lecture
            A0081715.exe C:\System Volume Information\_restore{52DC0616-98B4-4D8B-BB8E-B9B5A34F7446}\RP327 Program.Uniblue.4 - erreur de lecture
            A0081716.exe C:\System Volume Information\_restore{52DC0616-98B4-4D8B-BB8E-B9B5A34F7446}\RP327 Program.Uniblue.4 - erreur de lecture
            A0081717.exe C:\System Volume Information\_restore{52DC0616-98B4-4D8B-BB8E-B9B5A34F7446}\RP327 Program.Uniblue.4 - erreur de lecture
            A0081718.exe C:\System Volume Information\_restore{52DC0616-98B4-4D8B-BB8E-B9B5A34F7446}\RP327 Program.Uniblue.4 - erreur de lecture
            A0081719.exe C:\System Volume Information\_restore{52DC0616-98B4-4D8B-BB8E-B9B5A34F7446}\RP327 Program.Uniblue.4 - erreur de lecture
            2755643316:1262010459.exe C:\WINDOWS BackDoor.Maxplus.24 Supprimé.
            trz19.tmp C:\WINDOWS BackDoor.Maxplus.24 Supprimé.
            trz3B.tmp C:\WINDOWS BackDoor.Maxplus.24 Supprimé.
            Desktop.ini C:\WINDOWS\assembly\GAC_MSIL BackDoor.Siggen.37524 Supprimé.
            0
          2. C'est le rapport de Dr Web CureIt
            0
        2. Il me dit que ce n'est pas un applicatioin Win32 valide...
          0
          1. ah non pardon,c'est bon, il est en train de tourner..
            0
        3. Re

          Télécharge Dr Web CureIt sur ton Bureau :

          ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe

          - Double clique drweb-cureit.exe et ensuite clique sur Analyse;

          - Clique Ok à l'invite de l'analyse rapide. S'il trouve des processus infectés alors clique le bouton Oui.
          Note : une fenêtre s'ouvrira avec options pour "Commander" ou "50% de réduction" : Quitte en cliquant le "X".
          - Lorsque le scan rapide est terminé, clique sur le menu Options puis Changer la configuration ; Choisis l'onglet Scanner, et décoche Analyse heuristique. Clique ensuite sur Ok.
          - De retour à la fenêtre principale : clique pour activer Analyse complète
          - Clique le bouton avec flèche verte sur la droite, et le scan débutera.
          - Clique Oui< /gras> pour tout à l'invite <gras> Désinfecter ? lorsqu'un fichier est détecté, et ensuite clique Désinfecter.
          - Lorsque le scan sera complété, regarde si tu peux cliquer sur l'icône, adjacente aux fichiers détectés (plusieurs feuilles l'une sur l'autre). Si oui, alors clique dessus et ensuite clique sur l'icône Suivant, au dessous, et choisis <gras> Déplacer en quarantaine l'objet indésirable.
          - Du menu principal de l'outil, au haut à gauche, clique sur le menu Fichier et choisis Enregistrer le rapport. Sauvegarde le rapport sur ton Bureau. Ce dernier se nommera DrWeb.csv
          - Ferme Dr.Web Cureit
          - Redémarre ton ordi (important car certains fichiers peuvent être déplacés/réparés au redémarrage).
          - Suite au redémarrage, poste (Copie/Colle) le contenu du rapport de Dr.Web dans ta prochaine réponse.

          @+
          0
          1. Ca plante aussi :( est-ce que je ferai mieux de sauver mes fichiers sur clé USB et réinstaller windows?
            0
            1. Re

              Comme tu veux.

              @+
              0
            2. Je préférerai quand même enlever le virus, mais y a t-il d'autres solutions?
              0
          2. La première fois, le système a planté. J'ai relancé et ça a l'air de fonctionner mais ca fait 50 minutes qu'il tourne, c'est normal?
            0
            1. en fait il a planté aussi...
              0
          3. Re

            Laisse tomber et passe à ceci:

            Télécharge combofix : http://download.bleepingcomputer.com/sUBs/ComboFix.exe
            Ou ici : https://forospyware.com
            >Renomme le pour l'enregistrer sur ton bureau en asdehi (tout simplement pour que l'infection ne le contre pas)
            -> Double clique combofix.exe.(ou clic droit sous vista « exécuter en tant que... » )
            -> Tape sur la touche 1 (Yes) pour démarrer le scan.
            -> Lorsque le scan sera complété, un rapport apparaîtra. Copie/colle ce rapport dans ta prochaine réponse.

            NOTE : Le rapport se trouve également ici : C:\Combofix.txt

            Avant d'utiliser ComboFix :

            -> Déconnecte toi d'Internet et referme les fenêtres de tous les programmes en cours.

            -> Désactive provisoirement et seulement le temps de l'utilisation de ComboFix, la protection en temps réel de ton Antivirus et de tes Antispywares, qui peuvent gêner fortement la procédure de recherche et de nettoyage de l'outil.

            Une fois fait, sur ton bureau double-clic sur Combofix.exe ; (ou clic droit sous vista « exécuter en tant que... »)

            - Répond oui au message d'avertissement, pour que le programme commence à procéder à l'analyse du pc.

            - Installe le console de récupération comme demandé ;utile en cas de plantage

            - Attention Pendant la durée de cette étape, ne te sert pas du pc et n'ouvre aucun programme. Risque de figer l'ordinateur

            - En fin de scan il est possible que ComboFix ait besoin de redémarrer le pc pour finaliser la désinfection\recherche, laisses-le faire.

            - Un rapport s'ouvrira ensuite dans le bloc notes, ce fichier rapport Combofix.txt, est automatiquement sauvegardé et rangé à C:\Combofix.txt)

            -> Réactive la protection en temps réel de ton Antivirus et de tes Antispywares, avant de te reconnecter à internet.

            -> Reviens sur le forum, et copie et colle la totalité du contenu de C:\Combofix.txt dans ton prochain message.

            /!\ Ne touche à rien tant que le scan n'est pas terminé. /!\ : risque de figer l'ordinateur (plantage complet)

            ::Si combofix détecte quelque chose et de demande a redémarrer tu acceptes

            @+

            0
            1. J'ai essayé 2 fois mais le programme fait planter l'ordi vers 80%... j'essaie encore une fois, mais y a-t-il autre chose que je puisse faire?
              0
              1. Re

                Et bien maintenant essaye de me poster un rapport ZHPDiag;merci.

                @+
                0
                • 1
                • 2