Virus

Résolu
Bonjour, cher internaute

Pouvez-vous m'aider parce que a chaque démarrage de mon ordinateur portable il y a un vpn qui s'ouvre et c'est spot flux et je ne sais pas le viré de mon pc??
Comment faire svp??
Merci d'avance pour votre aide..
Marc

56 réponses

Résumé de la discussion

Le démarrage automatique d'un VPN, Spotflux, survient à chaque démarrage de l'ordinateur et nécessite une intervention pour en retirer les composants afin d'éviter les connexions indésirables. Plusieurs solutions proposées mettent en avant la suppression du pilote réseau Spotflux via le Centre Réseau et partage et les paramètres de l'adaptateur, puis l'option de désinstallation et la suppression du pilote. D'autres interventions recommandent des outils de détection et de nettoyage tels que RogueKiller, USBFix, ZHPFix, et des analyses antivirus comme Malwarebytes, afin d'éliminer les composants malveillants et les entrées de démarrage. En dernier recours, certains évoquent le démarrage en mode sans échec et des procédures de suppression plus poussées, sans conclure sur l'état final du système ni sur une solution universelle.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    Bonsoir,
    1/
    Tu peux refaire les procédures de fin de désinfection comme expliqué ici : https://forums.commentcamarche.net/forum/affich-28140450-virus?page=2#43

    2/
    Concernant l'autre PC, tu peux créer un nouveau sujet pour qu'on
    puisse t'aider! :-)

    Bonne nuit
    1. Bonjour, Fish
      voici
      # DelFix v10.4 - Rapport créé le 25/09/2013 à 15:06:28
      # Mis à jour le 19/07/2013 par Xplode
      # Nom d'utilisateur : marc - MARC-PC
      # Système d'exploitation : Windows 7 Home Premium Service Pack 1 (64 bits)

      ~ Suppression des outils de désinfection ...

      Supprimé : C:\Qoobox
      Supprimé : C:\ZHP
      Supprimé : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ZHP
      Supprimé : C:\Program Files (x86)\ZHPDiag
      Supprimé : C:\ComboFix.txt
      Supprimé : C:\PhysicalDisk0_MBR.bin
      Supprimé : C:\Users\Public\Desktop\ZHPDiag.lnk
      Supprimé : C:\Users\Public\Desktop\ZHPFix.lnk
      Supprimé : C:\Windows\grep.exe
      Supprimé : C:\Windows\PEV.exe
      Supprimé : C:\Windows\NIRCMD.exe
      Supprimé : C:\Windows\MBR.exe
      Supprimé : C:\Windows\SED.exe
      Supprimé : C:\Windows\SWREG.exe
      Supprimé : C:\Windows\SWSC.exe
      Supprimé : C:\Windows\SWXCACLS.exe
      Supprimé : C:\Windows\Zip.exe
      Supprimée : HKLM\SOFTWARE\AdwCleaner
      Supprimée : HKLM\SOFTWARE\Swearware
      Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ZHPDiag_is1
      Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\combofix.exe

      ########## - EOF - ##########
      Ok nouveau poste pour l'autre pc
    2. fish,
      j'ai posté un nouveau sujet comme suggéré dans disque dur, si tu pouvais m'aider svp.
      Mille merci
      Marc
  2. Bonsoir, fish
    Merci cela fonctionne et le pc aussi mille merci.
    Petite question quand je vais sur l'onglet a coté de la barre d'adresse, sur l'extrême droite m'indique nouvelle onglet et me dirige vers usage fréquent comment accédé a la page Google directement??
    Et es que tu pourrais m'aider concernant le pc de ma compagne son ancien compagne avait partitionné le disque dur en plusieurs partitions et maintenant le C pour faire tourné le pc est en rouge, j'ai bougé ce que je pouvais pour essayé de libéré de l'espace mais toujours en rouge, les autre partition son vide est que je sais remette les partition sur le c et comment faire, parce que j'aimerai ne pas formater vu que c'est son pc pour le travail infirmière et son programme coute cher vu qu'elle doit le réinstallé via le centre de dépannage...
    Merci d'avance
    1. fish
      Quand je me connecte sur le net j'ai une alerte sécurité qui s'affiche( la connexion que vous allez utilisé n'est sécurisée d'autre utilisateurs du web pourront dorénavant accéder aux information que vous envoyer)??
      1. Contributeur sécurité
        1/
        Utilise un autre navigateur pour vérifier si tu auras le même message!

        2/
        * Ouvre ton menu démarrer

        -> Si tu es sur XP, ouvre exécuter, tape cmd et valide par pression sur la touche Enter

        -> Sur Vista/Seven, dans le champ "Recherche" tape cmd , sur le résultat qui apparait, clic droit > exécuter en tant qu'administrateur

        * Dans la fenêtre noire, tape sfc /scannow et laisse Windows réparer les fichiers.

        -------------------------
        A demain

        Bonne nuit
    2. vComboFix 13-09-23.02 - marc 23/09/2013 21:48:25.2.2 - x64
      Microsoft Windows 7 Édition Familiale Premium 6.1.7601.1.1252.32.1036.18.2730.1554 [GMT 2:00]
      Lancé depuis: c:\users\marc\Desktop\marc.exe
      Commutateurs utilisés :: c:\users\marc\Desktop\CFScript.txt
      AV: Microsoft Security Essentials *Enabled/Updated* {641105E6-77ED-3F35-A304-765193BCB75F}
      SP: Microsoft Security Essentials *Enabled/Updated* {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}
      SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
      .
      FILE ::
      "c:\program files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll"
      .
      .
      (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
      .
      .
      C:\492985d07eff9f25891c
      c:\492985d07eff9f25891c\$shtdwn$.req
      c:\492985d07eff9f25891c\mrt.exe
      c:\492985d07eff9f25891c\mrtstub.exe
      c:\program files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
      .
      .
      ((((((((((((((((((((((((((((( Fichiers créés du 2013-08-23 au 2013-09-23 ))))))))))))))))))))))))))))))))))))
      .
      .
      2013-09-23 19:55 . 2013-09-23 19:55 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
      2013-09-23 19:55 . 2013-09-23 19:55 -------- d-----w- c:\users\Default\AppData\Local\temp
      2013-09-23 13:13 . 2013-09-05 05:32 9694160 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{365EC18A-7AB6-4345-BB61-856E3F9F4701}\mpengine.dll
      2013-09-22 07:04 . 2013-09-05 05:32 9694160 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
      2013-09-21 21:34 . 2013-09-22 06:59 -------- d-----w- c:\windows\system32\catroot2
      2013-09-21 21:12 . 2013-09-21 21:33 181064 ----a-w- c:\windows\PSEXESVC.EXE
      2013-09-21 20:58 . 2013-09-21 20:58 -------- d-----w- C:\RegBackup
      2013-09-21 20:36 . 2013-09-21 20:36 -------- d-----w- c:\program files (x86)\Tweaking.com
      2013-09-21 20:16 . 2013-09-23 14:09 512 ----a-w- C:\PhysicalDisk0_MBR.bin
      2013-09-21 19:24 . 2013-09-23 14:00 -------- d-----w- C:\ZHP
      2013-09-21 19:24 . 2013-09-23 14:00 -------- d-----w- c:\program files (x86)\ZHPDiag
      2013-09-21 16:28 . 2013-09-21 16:28 -------- d-----w- c:\program files (x86)\ASM104xUSB3
      2013-09-21 16:24 . 2013-09-21 16:24 -------- d-----w- c:\users\marc\AppData\Local\Akamai
      2013-09-21 14:28 . 2013-09-21 14:28 0 ----a-w- c:\windows\SysWow64\sho42A4.tmp
      2013-09-21 14:16 . 2013-09-21 14:18 -------- d-----w- c:\program files (x86)\Bluetooth Suite
      2013-09-21 14:14 . 2013-09-21 14:17 -------- d-----w- c:\program files (x86)\Common Files\Atheros
      2013-09-21 12:23 . 2013-09-22 07:02 -------- d-----w- c:\users\marc\AppData\Roaming\DriverTurbo
      2013-09-21 08:52 . 2013-09-21 08:52 -------- d-----w- c:\windows\CheckSur
      2013-09-20 19:14 . 2013-09-20 19:14 -------- d--h--w- c:\windows\msdownld.tmp
      2013-09-19 19:11 . 2013-09-19 19:10 312744 ----a-w- c:\windows\system32\javaws.exe
      2013-09-19 19:10 . 2013-09-19 19:10 108968 ----a-w- c:\windows\system32\WindowsAccessBridge-64.dll
      2013-09-19 19:10 . 2013-09-19 19:10 189352 ----a-w- c:\windows\system32\javaw.exe
      2013-09-19 19:10 . 2013-09-19 19:10 189352 ----a-w- c:\windows\system32\java.exe
      2013-09-19 19:09 . 2013-09-19 19:09 -------- d-----w- c:\program files\Java
      2013-09-19 19:05 . 2013-09-19 19:05 -------- d-----w- c:\program files\VideoLAN
      2013-09-19 10:49 . 2013-09-19 10:49 253952 ------w- c:\windows\Setup1.exe
      2013-09-19 10:49 . 2013-09-19 10:49 74752 ----a-w- c:\windows\ST6UNST.EXE
      2013-09-19 10:41 . 2013-09-19 10:44 -------- d-----w- c:\program files\WinRAR
      2013-09-15 19:44 . 2013-09-23 14:23 -------- d-----w- c:\programdata\Google Updater
      2013-09-15 15:47 . 2013-09-15 15:47 -------- d-----w- C:\7-ZipPortable
      2013-09-14 20:26 . 2013-09-14 20:26 0 ----a-w- c:\windows\SysWow64\sho9C1E.tmp
      2013-09-11 21:30 . 2013-08-10 03:17 2706432 ----a-w- c:\windows\system32\mshtml.tlb
      2013-09-11 21:30 . 2013-08-10 03:07 2706432 ----a-w- c:\windows\SysWow64\mshtml.tlb
      2013-09-11 18:47 . 2013-08-05 02:25 155584 ----a-w- c:\windows\system32\drivers\ataport.sys
      2013-09-06 12:45 . 2013-09-06 12:44 965008 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{4608B23C-5859-4851-81FA-2F2424BFCCCE}\gapaengine.dll
      2013-09-04 07:36 . 2013-09-04 07:40 -------- d-----w- c:\program files\Defraggler
      2013-08-31 18:39 . 2013-09-22 19:18 -------- d-----w- C:\AdwCleaner
      2013-08-31 08:58 . 2011-06-22 07:47 1002728 ----a-w- c:\windows\system32\WinUSBCoInstaller2.dll
      2013-08-31 08:57 . 2013-08-31 08:57 -------- d-----w- c:\program files (x86)\WIKO
      2013-08-31 08:55 . 2013-08-31 08:55 -------- d-----w- c:\users\marc\AppData\Roaming\MobileAction
      2013-08-31 08:43 . 2013-08-31 08:43 -------- d-----w- c:\program files (x86)\Mobile Action
      2013-08-29 21:12 . 2013-08-29 21:12 0 ----a-w- c:\windows\SysWow64\sho7F30.tmp
      2013-08-29 18:29 . 2013-08-29 18:29 48648 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\Markup.dll
      2013-08-29 18:29 . 2013-08-29 18:29 704136 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight-2\SpotlightResources.dll
      2013-08-29 08:46 . 2013-08-29 08:46 -------- d-----w- c:\users\marc\AppData\Local\avgchrome
      2013-08-25 17:22 . 2013-08-25 17:22 48648 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\Markup.dll
      2013-08-25 17:22 . 2013-08-25 17:22 704136 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
      .
      .
      .
      (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
      .
      2013-09-23 19:57 . 2012-03-10 16:42 45056 ----a-w- c:\windows\system32\acovcnt.exe
      2013-09-19 19:10 . 2012-08-21 20:29 973736 ----a-w- c:\windows\system32\deployJava1.dll
      2013-09-19 19:10 . 2012-08-21 20:29 1095080 ----a-w- c:\windows\system32\npDeployJava1.dll
      2013-09-01 15:08 . 2010-11-25 17:26 79143768 ----a-w- c:\windows\system32\MRT.exe
      2013-08-26 05:58 . 2012-06-19 19:59 941720 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
      2013-08-18 21:45 . 2013-08-18 21:45 0 ----a-w- c:\windows\SysWow64\sho2F3C.tmp
      2013-08-17 20:59 . 2013-08-17 20:59 0 ----a-w- c:\windows\SysWow64\shoD2C8.tmp
      2013-08-07 12:23 . 2013-08-07 12:23 644968 ----a-w- c:\windows\system32\drivers\iaStorA.sys
      2013-08-07 12:23 . 2013-08-07 12:23 28008 ----a-w- c:\windows\system32\drivers\iaStorF.sys
      2013-08-02 01:48 . 2013-09-11 18:46 44032 ----a-w- c:\windows\apppatch\acwow64.dll
      2013-07-31 09:24 . 2013-07-31 09:24 22240 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
      2013-07-25 09:25 . 2013-08-14 08:36 1888768 ----a-w- c:\windows\system32\WMVDECOD.DLL
      2013-07-25 08:57 . 2013-08-14 08:36 1620992 ----a-w- c:\windows\SysWow64\WMVDECOD.DLL
      2013-07-22 17:42 . 2012-04-24 19:43 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
      2013-07-22 17:42 . 2012-04-24 19:43 692104 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
      2013-07-19 01:58 . 2013-08-14 08:36 2048 ----a-w- c:\windows\system32\tzres.dll
      2013-07-19 01:41 . 2013-08-14 08:36 2048 ----a-w- c:\windows\SysWow64\tzres.dll
      2013-07-09 05:52 . 2013-08-14 08:36 224256 ----a-w- c:\windows\system32\wintrust.dll
      2013-07-09 05:51 . 2013-08-14 08:35 1217024 ----a-w- c:\windows\system32\rpcrt4.dll
      2013-07-09 05:46 . 2013-08-14 08:36 1472512 ----a-w- c:\windows\system32\crypt32.dll
      2013-07-09 05:46 . 2013-08-14 08:36 184320 ----a-w- c:\windows\system32\cryptsvc.dll
      2013-07-09 05:46 . 2013-08-14 08:36 139776 ----a-w- c:\windows\system32\cryptnet.dll
      2013-07-09 04:52 . 2013-08-14 08:35 663552 ----a-w- c:\windows\SysWow64\rpcrt4.dll
      2013-07-09 04:52 . 2013-08-14 08:36 175104 ----a-w- c:\windows\SysWow64\wintrust.dll
      2013-07-09 04:46 . 2013-08-14 08:36 1166848 ----a-w- c:\windows\SysWow64\crypt32.dll
      2013-07-09 04:46 . 2013-08-14 08:36 140288 ----a-w- c:\windows\SysWow64\cryptsvc.dll
      2013-07-09 04:46 . 2013-08-14 08:36 103936 ----a-w- c:\windows\SysWow64\cryptnet.dll
      2013-07-06 06:49 . 2013-07-06 06:49 96168 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
      2013-07-06 06:49 . 2013-05-19 08:31 867240 ----a-w- c:\windows\SysWow64\npDeployJava1.dll
      2013-07-06 06:49 . 2013-05-19 08:31 789416 ----a-w- c:\windows\SysWow64\deployJava1.dll
      2013-07-06 06:03 . 2013-08-14 08:35 1910208 ----a-w- c:\windows\system32\drivers\tcpip.sys
      2013-06-30 11:31 . 2013-06-16 16:55 196 ----a-w- c:\windows\DeleteOnReboot.bat
      2013-06-26 17:21 . 2013-06-26 17:21 23208 ----a-w- c:\windows\system32\drivers\Sftvollh.sys
      2013-06-26 17:21 . 2013-06-26 17:21 28840 ----a-w- c:\windows\system32\drivers\Sftredirlh.sys
      2013-06-26 17:21 . 2013-06-26 17:21 273576 ----a-w- c:\windows\system32\drivers\Sftplaylh.sys
      2013-06-26 17:21 . 2013-06-26 17:21 1777320 ----a-w- c:\windows\system32\sftldr.dll
      2013-06-26 17:21 . 2013-06-26 17:21 1130664 ----a-w- c:\windows\SysWow64\sftldr_wow64.dll
      2013-06-26 17:21 . 2013-06-26 17:21 767144 ----a-w- c:\windows\system32\drivers\Sftfslh.sys
      .
      .
      ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
      .
      .
      *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
      REGEDIT4
      .
      [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1]
      @="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}"
      [HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}]
      2013-07-31 14:00 222832 ----a-w- c:\users\marc\AppData\Local\Microsoft\SkyDrive\17.0.2011.0627\SkyDriveShell.dll
      .
      [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2]
      @="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}"
      [HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}]
      2013-07-31 14:00 222832 ----a-w- c:\users\marc\AppData\Local\Microsoft\SkyDrive\17.0.2011.0627\SkyDriveShell.dll
      .
      [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3]
      @="{BBACC218-34EA-4666-9D7A-C78F2274A524}"
      [HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}]
      2013-07-31 14:00 222832 ----a-w- c:\users\marc\AppData\Local\Microsoft\SkyDrive\17.0.2011.0627\SkyDriveShell.dll
      .
      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
      "ConsentPromptBehaviorAdmin"= 5 (0x5)
      "ConsentPromptBehaviorUser"= 3 (0x3)
      "EnableUIADesktopToggle"= 0 (0x0)
      "EnableSecureUIAPath"= 1 (0x1)
      .
      [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
      "LoadAppInit_DLLs"=1 (0x1)
      "AppInit_DLLs"=c:\windows\SysWOW64\nvinit.dll
      .
      [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
      BootExecute REG_MULTI_SZ autocheck autochk *\0sdnclean64.exe
      .
      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
      @="Service"
      .
      R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
      R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
      R3 BBSvc;Bing Bar Update Service;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE [x]
      R3 dc3d;MS Hardware Device Detection Driver (USB);c:\windows\system32\drivers\dc3d.sys;c:\windows\SYSNATIVE\drivers\dc3d.sys [x]
      R3 driverhardwarev2x64;driverhardwarev2x64;c:\program files\ma-config.com\Drivers\driverhardwarev2x64.sys;c:\program files\ma-config.com\Drivers\driverhardwarev2x64.sys [x]
      R3 EMVSCARD;EMVSCARD;c:\windows\system32\Drivers\EMVSCARD.sys;c:\windows\SYSNATIVE\Drivers\EMVSCARD.sys [x]
      R3 Futuremark SystemInfo Service;Futuremark SystemInfo Service;c:\program files (x86)\Common Files\Futuremark Shared\Futuremark SystemInfo\FMSISvc.exe;c:\program files (x86)\Common Files\Futuremark Shared\Futuremark SystemInfo\FMSISvc.exe [x]
      R3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS;c:\program files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe;c:\program files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [x]
      R3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface;c:\program files\Intel\iCLS Client\SocketHeciServer.exe;c:\program files\Intel\iCLS Client\SocketHeciServer.exe [x]
      R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys;c:\windows\SYSNATIVE\DRIVERS\NisDrvWFP.sys [x]
      R3 NisSrv;Inspection du réseau Microsoft;c:\program files\Microsoft Security Client\NisSrv.exe;c:\program files\Microsoft Security Client\NisSrv.exe [x]
      R3 Point64;Microsoft IntelliPoint Filter Driver;c:\windows\system32\drivers\point64.sys;c:\windows\SYSNATIVE\drivers\point64.sys [x]
      R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
      R3 RSUSBVSTOR;RtsUVStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUVStor.sys;c:\windows\SYSNATIVE\Drivers\RtsUVStor.sys [x]
      R3 tapSF0901;Spotflux Virtual Network Device Driver;c:\windows\system32\DRIVERS\tapSF0901.sys;c:\windows\SYSNATIVE\DRIVERS\tapSF0901.sys [x]
      R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
      R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
      R3 WatAdminSvc;Service Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
      R4 AFBAgent;AFBAgent;c:\windows\system32\FBAgent.exe;c:\windows\SYSNATIVE\FBAgent.exe [x]
      R4 SandraAgentSrv;SiSoftware Deployment Agent Service;c:\program files\SiSoftware\SiSoftware Sandra Lite 2011\RpcAgentSrv.exe;c:\program files\SiSoftware\SiSoftware Sandra Lite 2011\RpcAgentSrv.exe [x]
      R4 sptd;sptd;c:\windows\System32\Drivers\sptd.sys;c:\windows\SYSNATIVE\Drivers\sptd.sys [x]
      R4 TurboBoost;Intel(R) Turbo Boost Technology Monitor;c:\program files\Intel\TurboBoost\TurboBoost.exe;c:\program files\Intel\TurboBoost\TurboBoost.exe [x]
      S0 iaStorA;iaStorA;c:\windows\system32\DRIVERS\iaStorA.sys;c:\windows\SYSNATIVE\DRIVERS\iaStorA.sys [x]
      S0 iaStorF;iaStorF;c:\windows\system32\DRIVERS\iaStorF.sys;c:\windows\SYSNATIVE\DRIVERS\iaStorF.sys [x]
      S0 nvpciflt;nvpciflt;c:\windows\system32\DRIVERS\nvpciflt.sys;c:\windows\SYSNATIVE\DRIVERS\nvpciflt.sys [x]
      S1 ATKWMIACPIIO;ATKWMIACPI Driver;c:\program files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys;c:\program files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [x]
      S2 ASMMAP64;ASMMAP64;c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys;c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [x]
      S2 Atheros Bt&Wlan Coex Agent;Atheros Bt&Wlan Coex Agent;c:\program files (x86)\Bluetooth Suite\Ath_CoexAgent.exe;c:\program files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [x]
      S2 AtherosSvc;AtherosSvc;c:\program files (x86)\Bluetooth Suite\adminservice.exe;c:\program files (x86)\Bluetooth Suite\adminservice.exe [x]
      S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [x]
      S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe;c:\program files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [x]
      S2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe;c:\program files\Intel\iCLS Client\HeciServer.exe [x]
      S2 MaConfigAgent;Ma-Config Agent;c:\program files\ma-config.com\MaConfigAgent.exe;c:\program files\ma-config.com\MaConfigAgent.exe [x]
      S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [x]
      S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [x]
      S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [x]
      S2 TurboB;Turbo Boost UI Monitor driver;c:\windows\system32\DRIVERS\TurboB.sys;c:\windows\SYSNATIVE\DRIVERS\TurboB.sys [x]
      S3 AthBTPort;Atheros Virtual Bluetooth Class;c:\windows\system32\DRIVERS\btath_flt.sys;c:\windows\SYSNATIVE\DRIVERS\btath_flt.sys [x]
      S3 BTATH_A2DP;Bluetooth A2DP Audio Driver;c:\windows\system32\drivers\btath_a2dp.sys;c:\windows\SYSNATIVE\drivers\btath_a2dp.sys [x]
      S3 BTATH_BUS;Atheros Bluetooth Bus;c:\windows\system32\DRIVERS\btath_bus.sys;c:\windows\SYSNATIVE\DRIVERS\btath_bus.sys [x]
      S3 BTATH_HCRP;Bluetooth HCRP Server driver;c:\windows\system32\DRIVERS\btath_hcrp.sys;c:\windows\SYSNATIVE\DRIVERS\btath_hcrp.sys [x]
      S3 BTATH_LWFLT;Bluetooth LWFLT Device;c:\windows\system32\DRIVERS\btath_lwflt.sys;c:\windows\SYSNATIVE\DRIVERS\btath_lwflt.sys [x]
      S3 BTATH_RCP;Bluetooth AVRCP Device;c:\windows\system32\DRIVERS\btath_rcp.sys;c:\windows\SYSNATIVE\DRIVERS\btath_rcp.sys [x]
      S3 BtFilter;BtFilter;c:\windows\system32\DRIVERS\btfilter.sys;c:\windows\SYSNATIVE\DRIVERS\btfilter.sys [x]
      S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys;c:\windows\SYSNATIVE\DRIVERS\ETD.sys [x]
      S3 IntcDAud;Son Intel(R) pour écrans;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x]
      S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x]
      S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
      S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftfslh.sys [x]
      S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftplaylh.sys [x]
      S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftredirlh.sys [x]
      S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftvollh.sys [x]
      S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [x]
      .
      .
      [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
      2013-09-21 06:45 1177552 ----a-w- c:\program files (x86)\Google\Chrome\Application\29.0.1547.76\Installer\chrmstp.exe
      .
      Contenu du dossier 'Tâches planifiées'
      .
      2013-09-23 c:\windows\Tasks\Adobe Flash Player Updater.job
      - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-24 17:42]
      .
      2013-09-23 c:\windows\Tasks\Google Software Updater.job
      - c:\program files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [2013-09-15 19:46]
      .
      2013-09-23 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
      - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-04-24 19:36]
      .
      2013-09-23 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
      - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-04-24 19:36]
      .
      .
      --------- X64 Entries -----------
      .
      .
      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1]
      @="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}"
      [HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}]
      2013-07-31 14:00 261744 ----a-w- c:\users\marc\AppData\Local\Microsoft\SkyDrive\17.0.2011.0627\amd64\SkyDriveShell64.dll
      .
      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2]
      @="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}"
      [HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}]
      2013-07-31 14:00 261744 ----a-w- c:\users\marc\AppData\Local\Microsoft\SkyDrive\17.0.2011.0627\amd64\SkyDriveShell64.dll
      .
      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3]
      @="{BBACC218-34EA-4666-9D7A-C78F2274A524}"
      [HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}]
      2013-07-31 14:00 261744 ----a-w- c:\users\marc\AppData\Local\Microsoft\SkyDrive\17.0.2011.0627\amd64\SkyDriveShell64.dll
      .
      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2013-06-20 1356240]
      .
      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
      "AppInit_DLLs"=c:\windows\System32\nvinitx.dll
      .
      ------- Examen supplémentaire -------
      .
      uLocal Page = c:\windows\system32\blank.htm
      uStart Page = https://www.google.be/
      mLocal Page = c:\windows\SysWOW64\blank.htm
      uInternet Settings,ProxyOverride = <local>
      Trusted Zone: ma-config.com
      Trusted Zone: touslesdrivers.com
      TCP: DhcpNameServer = 62.197.111.140 109.88.203.3
      .
      - - - - ORPHELINS SUPPRIMES - - - -
      .
      Wow6432Node-HKLM-Run-<NO NAME> - (no file)
      AddRemove-PunkBusterSvc - c:\windows\system32\pbsvc.exe
      .
      .
      .
      --------------------- CLES DE REGISTRE BLOQUEES ---------------------
      .
      [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
      @Denied: (A 2) (Everyone)
      @="FlashBroker"
      "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_8_800_94_ActiveX.exe,-101"
      .
      [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
      "Enabled"=dword:00000001
      .
      [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
      @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_8_800_94_ActiveX.exe"
      .
      [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
      @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
      .
      [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
      @Denied: (A 2) (Everyone)
      @="IFlashBroker5"
      .
      [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
      @="{00020424-0000-0000-C000-000000000046}"
      .
      [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
      @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
      "Version"="1.0"
      .
      ------------------------ Autres processus actifs ------------------------
      .
      c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
      c:\program files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe
      c:\program files (x86)\ASUS\SmartLogon\sensorsrv.exe
      c:\program files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
      c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
      c:\windows\SysWOW64\PnkBstrA.exe
      c:\windows\SysWOW64\PnkBstrB.exe
      c:\program files (x86)\Microsoft\BingBar\SeaPort.EXE
      c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
      c:\program files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
      .
      **************************************************************************
      .
      Heure de fin: 2013-09-23 22:06:22 - La machine a redémarré
      ComboFix-quarantined-files.txt 2013-09-23 20:06
      ComboFix2.txt 2013-09-23 16:17
      .
      Avant-CF: 305.149.587.456 octets libres
      Après-CF: 304.820.842.496 octets libres
      .
      - - End Of File - - 0808F630D822BD867D0D4ECEB4CE1542
      5F8B5082F3482CC06B72EC5806598AE9
      oici, fish
      1. Contributeur sécurité
        Bonsoir,
        =>/!\Le script qui suit a été écrit spécialement cet ordinateur/!\ <=
        =>il est fort déconseillé de le transposer sur un autre ordinateur !<=

        -----------------------------------------------------------------------------------

        Toujours avec toutes les protections désactivées, fais ceci :

        * Ouvre le bloc-notes (Menu démarrer --> programmes --> accessoires --> bloc-notes)
        * Copie/colle dans le bloc-notes ce qui entre les lignes ci dessous (sans les lignes) :
        * Crée un nouveau document texte : clic droit de souris sur le bureau > Nouveau > Document Texte, et copie dedans les lignes suivantes :
        __________________________________________________


        KillAll::
        Folder::
        C:\492985d07eff9f25891c

        File::
        C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll

        RegLock::
        [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
        [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
        [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]

        Reboot::

        __________________________________________________

        * Enregistre ce fichier sous le nom CFScript
        * Fait un glisser/déposer de ce fichier CFScript sur le fichier
        ComboFix.exe comme sur : cette capture
        * Combofix se lance, laisse toi guider..

        * Patiente le temps du scan. Le bureau va disparaître à plusieurs reprises: c'est normal!
        * Ne touche à rien tant que le scan n'est pas terminé.
        * Une fois le scan achevé, un rapport va s'afficher: poste son contenu, en précisant où en sont tes soucis

        * Si le fichier ne s'ouvre pas, il se trouve ici > C:\ComboFix.txt

        1. fish
          Quand je me connecte sur le net j'ai une alerte sécurité qui s'affiche( la connexion que vous allez utilisé n'est sécurisée d'autre utilisateurs du web pourront dorénavant accéder aux information que vous envoyer)??
          1. voici fish
            ComboFix 13-09-23.02 - marc 23/09/2013 17:42:42.1.2 - x64
            Microsoft Windows 7 Édition Familiale Premium 6.1.7601.1.1252.32.1036.18.2730.1441 [GMT 2:00]
            Lancé depuis: c:\users\marc\Desktop\marc.exe
            AV: Microsoft Security Essentials *Enabled/Updated* {641105E6-77ED-3F35-A304-765193BCB75F}
            SP: Microsoft Security Essentials *Enabled/Updated* {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}
            .
            .
            (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
            .
            .
            C:\install.exe
            c:\programdata\xml9242.tmp
            c:\programdata\xml931D.tmp
            c:\programdata\xml93AA.tmp
            c:\programdata\xml9428.tmp
            c:\programdata\xmlC967.tmp
            c:\programdata\xmlCA42.tmp
            c:\windows\msvcr71.dll
            c:\windows\ST6UNST.000
            c:\windows\SysWow64\Packet.dll
            c:\windows\SysWow64\pthreadVC.dll
            c:\windows\SysWow64\wpcap.dll
            c:\windows\wininit.ini
            .
            .
            ((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
            .
            .
            -------\Legacy_NPF
            -------\Service_NPF
            .
            .
            ((((((((((((((((((((((((((((( Fichiers créés du 2013-08-23 au 2013-09-23 ))))))))))))))))))))))))))))))))))))
            .
            .
            2013-09-23 13:13 . 2013-09-05 05:32 9694160 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{365EC18A-7AB6-4345-BB61-856E3F9F4701}\mpengine.dll
            2013-09-22 07:04 . 2013-09-05 05:32 9694160 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
            2013-09-21 21:34 . 2013-09-22 06:59 -------- d-----w- c:\windows\system32\catroot2
            2013-09-21 21:12 . 2013-09-21 21:33 181064 ----a-w- c:\windows\PSEXESVC.EXE
            2013-09-21 20:58 . 2013-09-21 20:58 -------- d-----w- C:\RegBackup
            2013-09-21 20:36 . 2013-09-21 20:36 -------- d-----w- c:\program files (x86)\Tweaking.com
            2013-09-21 20:16 . 2013-09-23 14:09 512 ----a-w- C:\PhysicalDisk0_MBR.bin
            2013-09-21 19:24 . 2013-09-23 14:00 -------- d-----w- C:\ZHP
            2013-09-21 19:24 . 2013-09-23 14:00 -------- d-----w- c:\program files (x86)\ZHPDiag
            2013-09-21 16:28 . 2013-09-21 16:28 -------- d-----w- c:\program files (x86)\ASM104xUSB3
            2013-09-21 16:24 . 2013-09-21 16:24 -------- d-----w- c:\users\marc\AppData\Local\Akamai
            2013-09-21 14:28 . 2013-09-21 14:28 0 ----a-w- c:\windows\SysWow64\sho42A4.tmp
            2013-09-21 14:16 . 2013-09-21 14:18 -------- d-----w- c:\program files (x86)\Bluetooth Suite
            2013-09-21 14:14 . 2013-09-21 14:17 -------- d-----w- c:\program files (x86)\Common Files\Atheros
            2013-09-21 12:23 . 2013-09-22 07:02 -------- d-----w- c:\users\marc\AppData\Roaming\DriverTurbo
            2013-09-21 08:52 . 2013-09-21 08:52 -------- d-----w- c:\windows\CheckSur
            2013-09-20 19:14 . 2013-09-20 19:14 -------- d--h--w- c:\windows\msdownld.tmp
            2013-09-19 22:29 . 2013-09-19 22:29 -------- d-----w- C:\492985d07eff9f25891c
            2013-09-19 19:11 . 2013-09-19 19:10 312744 ----a-w- c:\windows\system32\javaws.exe
            2013-09-19 19:10 . 2013-09-19 19:10 108968 ----a-w- c:\windows\system32\WindowsAccessBridge-64.dll
            2013-09-19 19:10 . 2013-09-19 19:10 189352 ----a-w- c:\windows\system32\javaw.exe
            2013-09-19 19:10 . 2013-09-19 19:10 189352 ----a-w- c:\windows\system32\java.exe
            2013-09-19 19:09 . 2013-09-19 19:09 -------- d-----w- c:\program files\Java
            2013-09-19 19:05 . 2013-09-19 19:05 -------- d-----w- c:\program files\VideoLAN
            2013-09-19 10:49 . 2013-09-19 10:49 253952 ------w- c:\windows\Setup1.exe
            2013-09-19 10:49 . 2013-09-19 10:49 74752 ----a-w- c:\windows\ST6UNST.EXE
            2013-09-19 10:41 . 2013-09-19 10:44 -------- d-----w- c:\program files\WinRAR
            2013-09-15 19:44 . 2013-09-23 14:23 -------- d-----w- c:\programdata\Google Updater
            2013-09-15 15:47 . 2013-09-15 15:47 -------- d-----w- C:\7-ZipPortable
            2013-09-14 20:26 . 2013-09-14 20:26 0 ----a-w- c:\windows\SysWow64\sho9C1E.tmp
            2013-09-11 21:30 . 2013-08-10 03:17 2706432 ----a-w- c:\windows\system32\mshtml.tlb
            2013-09-11 21:30 . 2013-08-10 03:07 2706432 ----a-w- c:\windows\SysWow64\mshtml.tlb
            2013-09-11 18:47 . 2013-08-05 02:25 155584 ----a-w- c:\windows\system32\drivers\ataport.sys
            2013-09-06 12:45 . 2013-09-06 12:44 965008 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{4608B23C-5859-4851-81FA-2F2424BFCCCE}\gapaengine.dll
            2013-09-04 07:36 . 2013-09-04 07:40 -------- d-----w- c:\program files\Defraggler
            2013-08-31 18:39 . 2013-09-22 19:18 -------- d-----w- C:\AdwCleaner
            2013-08-31 08:58 . 2011-06-22 07:47 1002728 ----a-w- c:\windows\system32\WinUSBCoInstaller2.dll
            2013-08-31 08:57 . 2013-08-31 08:57 -------- d-----w- c:\program files (x86)\WIKO
            2013-08-31 08:55 . 2013-08-31 08:55 -------- d-----w- c:\users\marc\AppData\Roaming\MobileAction
            2013-08-31 08:43 . 2013-08-31 08:43 -------- d-----w- c:\program files (x86)\Mobile Action
            2013-08-29 21:12 . 2013-08-29 21:12 0 ----a-w- c:\windows\SysWow64\sho7F30.tmp
            2013-08-29 18:29 . 2013-08-29 18:29 48648 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\Markup.dll
            2013-08-29 18:29 . 2013-08-29 18:29 704136 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight-2\SpotlightResources.dll
            2013-08-29 08:46 . 2013-08-29 08:46 -------- d-----w- c:\users\marc\AppData\Local\avgchrome
            2013-08-25 17:22 . 2013-08-25 17:22 48648 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\Markup.dll
            2013-08-25 17:22 . 2013-08-25 17:22 704136 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
            .
            .
            .
            (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
            .
            2013-09-23 16:10 . 2012-03-10 16:42 45056 ----a-w- c:\windows\system32\acovcnt.exe
            2013-09-19 19:10 . 2012-08-21 20:29 973736 ----a-w- c:\windows\system32\deployJava1.dll
            2013-09-19 19:10 . 2012-08-21 20:29 1095080 ----a-w- c:\windows\system32\npDeployJava1.dll
            2013-09-01 15:08 . 2010-11-25 17:26 79143768 ----a-w- c:\windows\system32\MRT.exe
            2013-08-26 05:58 . 2012-06-19 19:59 941720 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
            2013-08-18 21:45 . 2013-08-18 21:45 0 ----a-w- c:\windows\SysWow64\sho2F3C.tmp
            2013-08-17 20:59 . 2013-08-17 20:59 0 ----a-w- c:\windows\SysWow64\shoD2C8.tmp
            2013-08-07 12:23 . 2013-08-07 12:23 644968 ----a-w- c:\windows\system32\drivers\iaStorA.sys
            2013-08-07 12:23 . 2013-08-07 12:23 28008 ----a-w- c:\windows\system32\drivers\iaStorF.sys
            2013-08-02 01:48 . 2013-09-11 18:46 44032 ----a-w- c:\windows\apppatch\acwow64.dll
            2013-07-31 09:24 . 2013-07-31 09:24 22240 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
            2013-07-25 09:25 . 2013-08-14 08:36 1888768 ----a-w- c:\windows\system32\WMVDECOD.DLL
            2013-07-25 08:57 . 2013-08-14 08:36 1620992 ----a-w- c:\windows\SysWow64\WMVDECOD.DLL
            2013-07-22 17:42 . 2012-04-24 19:43 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
            2013-07-22 17:42 . 2012-04-24 19:43 692104 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
            2013-07-19 01:58 . 2013-08-14 08:36 2048 ----a-w- c:\windows\system32\tzres.dll
            2013-07-19 01:41 . 2013-08-14 08:36 2048 ----a-w- c:\windows\SysWow64\tzres.dll
            2013-07-09 05:52 . 2013-08-14 08:36 224256 ----a-w- c:\windows\system32\wintrust.dll
            2013-07-09 05:51 . 2013-08-14 08:35 1217024 ----a-w- c:\windows\system32\rpcrt4.dll
            2013-07-09 05:46 . 2013-08-14 08:36 1472512 ----a-w- c:\windows\system32\crypt32.dll
            2013-07-09 05:46 . 2013-08-14 08:36 184320 ----a-w- c:\windows\system32\cryptsvc.dll
            2013-07-09 05:46 . 2013-08-14 08:36 139776 ----a-w- c:\windows\system32\cryptnet.dll
            2013-07-09 04:52 . 2013-08-14 08:35 663552 ----a-w- c:\windows\SysWow64\rpcrt4.dll
            2013-07-09 04:52 . 2013-08-14 08:36 175104 ----a-w- c:\windows\SysWow64\wintrust.dll
            2013-07-09 04:46 . 2013-08-14 08:36 1166848 ----a-w- c:\windows\SysWow64\crypt32.dll
            2013-07-09 04:46 . 2013-08-14 08:36 140288 ----a-w- c:\windows\SysWow64\cryptsvc.dll
            2013-07-09 04:46 . 2013-08-14 08:36 103936 ----a-w- c:\windows\SysWow64\cryptnet.dll
            2013-07-06 06:49 . 2013-07-06 06:49 96168 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
            2013-07-06 06:49 . 2013-05-19 08:31 867240 ----a-w- c:\windows\SysWow64\npDeployJava1.dll
            2013-07-06 06:49 . 2013-05-19 08:31 789416 ----a-w- c:\windows\SysWow64\deployJava1.dll
            2013-07-06 06:03 . 2013-08-14 08:35 1910208 ----a-w- c:\windows\system32\drivers\tcpip.sys
            2013-06-30 11:31 . 2013-06-16 16:55 196 ----a-w- c:\windows\DeleteOnReboot.bat
            2013-06-26 17:21 . 2013-06-26 17:21 23208 ----a-w- c:\windows\system32\drivers\Sftvollh.sys
            2013-06-26 17:21 . 2013-06-26 17:21 28840 ----a-w- c:\windows\system32\drivers\Sftredirlh.sys
            2013-06-26 17:21 . 2013-06-26 17:21 273576 ----a-w- c:\windows\system32\drivers\Sftplaylh.sys
            2013-06-26 17:21 . 2013-06-26 17:21 1777320 ----a-w- c:\windows\system32\sftldr.dll
            2013-06-26 17:21 . 2013-06-26 17:21 1130664 ----a-w- c:\windows\SysWow64\sftldr_wow64.dll
            2013-06-26 17:21 . 2013-06-26 17:21 767144 ----a-w- c:\windows\system32\drivers\Sftfslh.sys
            .
            .
            ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
            .
            .
            *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
            REGEDIT4
            .
            [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1]
            @="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}"
            [HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}]
            2013-07-31 14:00 222832 ----a-w- c:\users\marc\AppData\Local\Microsoft\SkyDrive\17.0.2011.0627\SkyDriveShell.dll
            .
            [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2]
            @="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}"
            [HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}]
            2013-07-31 14:00 222832 ----a-w- c:\users\marc\AppData\Local\Microsoft\SkyDrive\17.0.2011.0627\SkyDriveShell.dll
            .
            [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3]
            @="{BBACC218-34EA-4666-9D7A-C78F2274A524}"
            [HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}]
            2013-07-31 14:00 222832 ----a-w- c:\users\marc\AppData\Local\Microsoft\SkyDrive\17.0.2011.0627\SkyDriveShell.dll
            .
            [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
            "ConsentPromptBehaviorAdmin"= 5 (0x5)
            "ConsentPromptBehaviorUser"= 3 (0x3)
            "EnableUIADesktopToggle"= 0 (0x0)
            "EnableSecureUIAPath"= 1 (0x1)
            .
            [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
            "LoadAppInit_DLLs"=1 (0x1)
            "AppInit_DLLs"=c:\windows\SysWOW64\nvinit.dll
            .
            [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
            BootExecute REG_MULTI_SZ autocheck autochk *\0sdnclean64.exe
            .
            [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
            @="Service"
            .
            R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
            R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
            R3 BBSvc;Bing Bar Update Service;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE [x]
            R3 dc3d;MS Hardware Device Detection Driver (USB);c:\windows\system32\drivers\dc3d.sys;c:\windows\SYSNATIVE\drivers\dc3d.sys [x]
            R3 driverhardwarev2x64;driverhardwarev2x64;c:\program files\ma-config.com\Drivers\driverhardwarev2x64.sys;c:\program files\ma-config.com\Drivers\driverhardwarev2x64.sys [x]
            R3 EMVSCARD;EMVSCARD;c:\windows\system32\Drivers\EMVSCARD.sys;c:\windows\SYSNATIVE\Drivers\EMVSCARD.sys [x]
            R3 Futuremark SystemInfo Service;Futuremark SystemInfo Service;c:\program files (x86)\Common Files\Futuremark Shared\Futuremark SystemInfo\FMSISvc.exe;c:\program files (x86)\Common Files\Futuremark Shared\Futuremark SystemInfo\FMSISvc.exe [x]
            R3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS;c:\program files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe;c:\program files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [x]
            R3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface;c:\program files\Intel\iCLS Client\SocketHeciServer.exe;c:\program files\Intel\iCLS Client\SocketHeciServer.exe [x]
            R3 Point64;Microsoft IntelliPoint Filter Driver;c:\windows\system32\drivers\point64.sys;c:\windows\SYSNATIVE\drivers\point64.sys [x]
            R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
            R3 RSUSBVSTOR;RtsUVStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUVStor.sys;c:\windows\SYSNATIVE\Drivers\RtsUVStor.sys [x]
            R3 tapSF0901;Spotflux Virtual Network Device Driver;c:\windows\system32\DRIVERS\tapSF0901.sys;c:\windows\SYSNATIVE\DRIVERS\tapSF0901.sys [x]
            R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
            R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
            R3 WatAdminSvc;Service Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
            R4 AFBAgent;AFBAgent;c:\windows\system32\FBAgent.exe;c:\windows\SYSNATIVE\FBAgent.exe [x]
            R4 SandraAgentSrv;SiSoftware Deployment Agent Service;c:\program files\SiSoftware\SiSoftware Sandra Lite 2011\RpcAgentSrv.exe;c:\program files\SiSoftware\SiSoftware Sandra Lite 2011\RpcAgentSrv.exe [x]
            R4 sptd;sptd;c:\windows\System32\Drivers\sptd.sys;c:\windows\SYSNATIVE\Drivers\sptd.sys [x]
            R4 TurboBoost;Intel(R) Turbo Boost Technology Monitor;c:\program files\Intel\TurboBoost\TurboBoost.exe;c:\program files\Intel\TurboBoost\TurboBoost.exe [x]
            S0 iaStorA;iaStorA;c:\windows\system32\DRIVERS\iaStorA.sys;c:\windows\SYSNATIVE\DRIVERS\iaStorA.sys [x]
            S0 iaStorF;iaStorF;c:\windows\system32\DRIVERS\iaStorF.sys;c:\windows\SYSNATIVE\DRIVERS\iaStorF.sys [x]
            S0 nvpciflt;nvpciflt;c:\windows\system32\DRIVERS\nvpciflt.sys;c:\windows\SYSNATIVE\DRIVERS\nvpciflt.sys [x]
            S1 ATKWMIACPIIO;ATKWMIACPI Driver;c:\program files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys;c:\program files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [x]
            S2 ASMMAP64;ASMMAP64;c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys;c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [x]
            S2 Atheros Bt&Wlan Coex Agent;Atheros Bt&Wlan Coex Agent;c:\program files (x86)\Bluetooth Suite\Ath_CoexAgent.exe;c:\program files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [x]
            S2 AtherosSvc;AtherosSvc;c:\program files (x86)\Bluetooth Suite\adminservice.exe;c:\program files (x86)\Bluetooth Suite\adminservice.exe [x]
            S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [x]
            S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe;c:\program files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [x]
            S2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe;c:\program files\Intel\iCLS Client\HeciServer.exe [x]
            S2 MaConfigAgent;Ma-Config Agent;c:\program files\ma-config.com\MaConfigAgent.exe;c:\program files\ma-config.com\MaConfigAgent.exe [x]
            S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [x]
            S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [x]
            S2 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys;c:\windows\SYSNATIVE\DRIVERS\NisDrvWFP.sys [x]
            S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [x]
            S2 TurboB;Turbo Boost UI Monitor driver;c:\windows\system32\DRIVERS\TurboB.sys;c:\windows\SYSNATIVE\DRIVERS\TurboB.sys [x]
            S3 AthBTPort;Atheros Virtual Bluetooth Class;c:\windows\system32\DRIVERS\btath_flt.sys;c:\windows\SYSNATIVE\DRIVERS\btath_flt.sys [x]
            S3 BTATH_A2DP;Bluetooth A2DP Audio Driver;c:\windows\system32\drivers\btath_a2dp.sys;c:\windows\SYSNATIVE\drivers\btath_a2dp.sys [x]
            S3 BTATH_BUS;Atheros Bluetooth Bus;c:\windows\system32\DRIVERS\btath_bus.sys;c:\windows\SYSNATIVE\DRIVERS\btath_bus.sys [x]
            S3 BTATH_HCRP;Bluetooth HCRP Server driver;c:\windows\system32\DRIVERS\btath_hcrp.sys;c:\windows\SYSNATIVE\DRIVERS\btath_hcrp.sys [x]
            S3 BTATH_LWFLT;Bluetooth LWFLT Device;c:\windows\system32\DRIVERS\btath_lwflt.sys;c:\windows\SYSNATIVE\DRIVERS\btath_lwflt.sys [x]
            S3 BTATH_RCP;Bluetooth AVRCP Device;c:\windows\system32\DRIVERS\btath_rcp.sys;c:\windows\SYSNATIVE\DRIVERS\btath_rcp.sys [x]
            S3 BtFilter;BtFilter;c:\windows\system32\DRIVERS\btfilter.sys;c:\windows\SYSNATIVE\DRIVERS\btfilter.sys [x]
            S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys;c:\windows\SYSNATIVE\DRIVERS\ETD.sys [x]
            S3 IntcDAud;Son Intel(R) pour écrans;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x]
            S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x]
            S3 NisSrv;Inspection du réseau Microsoft;c:\program files\Microsoft Security Client\NisSrv.exe;c:\program files\Microsoft Security Client\NisSrv.exe [x]
            S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
            S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftfslh.sys [x]
            S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftplaylh.sys [x]
            S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftredirlh.sys [x]
            S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftvollh.sys [x]
            S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [x]
            .
            .
            --- Autres Services/Pilotes en mémoire ---
            .
            *NewlyCreated* - WS2IFSL
            .
            [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
            2013-09-21 06:45 1177552 ----a-w- c:\program files (x86)\Google\Chrome\Application\29.0.1547.76\Installer\chrmstp.exe
            .
            Contenu du dossier 'Tâches planifiées'
            .
            2013-09-23 c:\windows\Tasks\Adobe Flash Player Updater.job
            - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-24 17:42]
            .
            2013-09-23 c:\windows\Tasks\Google Software Updater.job
            - c:\program files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [2013-09-15 19:46]
            .
            2013-09-23 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
            - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-04-24 19:36]
            .
            2013-09-23 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
            - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-04-24 19:36]
            .
            .
            --------- X64 Entries -----------
            .
            .
            [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1]
            @="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}"
            [HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}]
            2013-07-31 14:00 261744 ----a-w- c:\users\marc\AppData\Local\Microsoft\SkyDrive\17.0.2011.0627\amd64\SkyDriveShell64.dll
            .
            [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2]
            @="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}"
            [HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}]
            2013-07-31 14:00 261744 ----a-w- c:\users\marc\AppData\Local\Microsoft\SkyDrive\17.0.2011.0627\amd64\SkyDriveShell64.dll
            .
            [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3]
            @="{BBACC218-34EA-4666-9D7A-C78F2274A524}"
            [HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}]
            2013-07-31 14:00 261744 ----a-w- c:\users\marc\AppData\Local\Microsoft\SkyDrive\17.0.2011.0627\amd64\SkyDriveShell64.dll
            .
            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
            "MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2013-06-20 1356240]
            .
            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
            "AppInit_DLLs"=c:\windows\System32\nvinitx.dll
            .
            ------- Examen supplémentaire -------
            .
            uLocal Page = c:\windows\system32\blank.htm
            uStart Page = https://www.google.be/
            mLocal Page = c:\windows\SysWOW64\blank.htm
            uInternet Settings,ProxyOverride = <local>
            Trusted Zone: ma-config.com
            Trusted Zone: touslesdrivers.com
            TCP: DhcpNameServer = 62.197.111.140 109.88.203.3
            .
            - - - - ORPHELINS SUPPRIMES - - - -
            .
            Wow6432Node-HKLM-Run-<NO NAME> - (no file)
            HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
            AddRemove-PunkBusterSvc - c:\windows\system32\pbsvc.exe
            .
            .
            .
            --------------------- CLES DE REGISTRE BLOQUEES ---------------------
            .
            [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
            @Denied: (A 2) (Everyone)
            @="FlashBroker"
            "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_8_800_94_ActiveX.exe,-101"
            .
            [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
            "Enabled"=dword:00000001
            .
            [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
            @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_8_800_94_ActiveX.exe"
            .
            [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
            @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
            .
            [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
            @Denied: (A 2) (Everyone)
            @="IFlashBroker5"
            .
            [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
            @="{00020424-0000-0000-C000-000000000046}"
            .
            [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
            @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
            "Version"="1.0"
            .
            ------------------------ Autres processus actifs ------------------------
            .
            c:\program files (x86)\ASUS\SmartLogon\smartlogon.exe
            c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
            c:\program files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe
            c:\program files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
            c:\program files (x86)\ASUS\SmartLogon\sensorsrv.exe
            c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
            c:\windows\SysWOW64\PnkBstrA.exe
            c:\windows\SysWOW64\PnkBstrB.exe
            c:\program files (x86)\Microsoft\BingBar\SeaPort.EXE
            c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
            c:\program files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
            .
            **************************************************************************
            .
            Heure de fin: 2013-09-23 18:17:39 - La machine a redémarré
            ComboFix-quarantined-files.txt 2013-09-23 16:17
            .
            Avant-CF: 306.425.503.744 octets libres
            Après-CF: 305.768.194.048 octets libres
            .
            - - End Of File - - D20F3415B5D718BCCF27C0D53AD9BC39
            5F8B5082F3482CC06B72EC5806598AE9
            1. Contributeur sécurité
              Salut,
              Supprime :
              C:\Users\marc\Documents\JEUXPC\minecraft full installer 1.8.1 + des packs de textures\Minecraft_Beta_Cracked_v1.8.1.exe
              Tu peux lire : les dangers des cracks
              -------------------------------
              Avant d'utiliser ComboFix :

              Les logiciels d'émulation de CD comme Daemon Tools peuvent gêner les outils de désinfection. Utilise Defogger pour les désactiver temporairement :

              si tu as ce genre de d'outils sur ton pc Utilise Defogger pour les désactiver temporairement : sinon passe directement à combofix

              * Télécharge Defogger (de jpshortstuff) sur ton Bureau
              * Lance le

              * Une fenêtre apparait : clique sur "Disable"

              * Fais redémarrer l'ordinateur si l'outil te le demande

              Note : Quand nous aurons terminé la désinfection, tu pourras réactiver ces logiciels en relançant Defogger et en cliquant sur "Re-enable"

              ===================================================

              Attention, avant de commencer, lis attentivement la procédure

              ********************************************************

              /!\ Ne pas utiliser ce logiciel en dehors du cadre de cette désinfection : DANGEUREUX /!\

              * Fais un clic droit sur ce lien, enregistre le dans ton bureau sous un autre nom exemple « ton pseudo.exe »
              Voici Aide combofix

              * /!\ Déconnecte-toi du net et ARRÊTE TES LOGICIELS DE PROTECTION /!\


              *Double-clique sur ComboFix.exe (ou exécuter en tant qu'administrateur pour vista et seven)

              Un "pop-up" va apparaître qui dit que ComboFix est utilisé à vos risques et avec aucune garantie... Clique sur oui pour accepter

              ** SURTOUT INSTALLES LA CONSOLE DE RECUPERATION
              (si il te propose de l'installer remets internet)

              ? Ne touche à rien(souris, clavier) tant que le scan n'est pas terminé, car tu risques de planter ton PC

              *En fin de scan, il est possible que ComboFix ait besoin de redémarrer le PC pour finaliser la désinfection, laisse-le faire.

              * Une fois le scan achevé, un rapport va s'afficher : Poste son contenu

              ** /!\ Réactive la protection en temps réel de ton antivirus et de ton antispyware avant de te reconnecter à Internet. /!\

              *Note : Le rapport se trouve également là : C:\ComboFix.txt

              1. Contributeur sécurité
                Bonjour,
                Le rapport est incomplet!
                Héberge le comme suit stp :
                * Rends toi sur pjjoint.malekal.com
                * Clique sur le bouton Parcourir
                * Sélectionne le fichier que tu veux héberger et clique sur Ouvrir
                * Clique sur le bouton Envoyer
                * Un message de confirmation s'affiche (L'upload a réussi ! - Le lien à transmettre à vos correspondant pour visualiser le fichier est : https://pjjoint.malekal.com/files.php?id=df5ea299241015

                * Copie le lien dans ta prochaine réponse.

                @+
                1. voici fish bonjour,
                  ~ Rapport de ZHPDiag v2013.9.22.410 - Nicolas Coolman (22/09/2013)
                  ~ Lancé par marc (22/09/2013 21:32:22)
                  ~ Adresse du Site Web https://nicolascoolman.webs.com/
                  ~ Traduit par Nicolas Coolman
                  ~ Etat de la version :
                  ~ Liste blanche : Désactivée par l'utilisateur
                  ~ Elévation des Privilèges : OK
                  ~ User Account Control (UAC): Activate by user

                  ---\\ Navigateurs Internet
                  MSIE: Internet Explorer v10.0.9200.16686 (Defaut)
                  GCIE: Google Chrome v29.0.1547.76

                  ---\\ Informations sur les produits Windows
                  ~ Langage: Français
                  Windows 7 Home Premium Edition, 64-bit Service Pack 1 (Build 7601)
                  Windows Server License Manager Script : OK
                  ~ Windows(R) 7, OEM_COA_NSLP channel
                  Windows ID Activation : OK
                  ~ Windows Partial Key : KR7H8
                  Windows License : OK
                  ~ Windows Remaining Initializations Number : 1
                  Software Protection Service (Protection logicielle) : OK
                  Windows Automatic Updates : OK
                  Windows Activation Technologies : OK

                  ---\\ Logiciels de protection du système
                  Malwarebytes Anti-Malware version 1.75.0.1300
                  Microsoft Security Client FR-FR Language Pack v2.1.1116.0
                  Windows Defender W7

                  ---\\ Logiciels d'optimisation du système
                  CCleaner v4.05 =>Piriform Ltd

                  ---\\ Logiciels de partage PeerToPeer
                  µTorrent v3.3.0.29677 =>P2P.µTorrent

                  ---\\ Surveillance de Logiciels
                  Adobe Flash Player 11 ActiveX
                  Extended Asian Language font pack for Adobe Reader XI
                  Java 7 Update 40
                  Java 7 Update 25

                  ---\\ Informations sur le système
                  ~ Processor: Intel64 Family 6 Model 42 Stepping 7, GenuineIntel
                  ~ Operating System: 64 Bits
                  Boot mode: Normal (Normal boot)
                  Total RAM: 2729 MB (47% free)
                  System Restore: Activé (Enable)
                  System drive C: has 287 GB (61%) free of 466 GB

                  ---\\ Mode de connexion au système
                  ~ Computer Name: MARC-PC
                  ~ User Name: marc
                  ~ All Users Names: UpdatusUser, marc, Administrateur,
                  ~ Unselected Option: None
                  Logged in as Administrator

                  ---\\ Variables d'environnement
                  ~ System Unit : C:\
                  ~ %AppData% : C:\Users\marc\AppData\Roaming\
                  ~ %Desktop% : C:\Users\marc\Desktop\
                  ~ %Favorites% : C:\Users\marc\Favorites\
                  ~ %LocalAppData% : C:\Users\marc\AppData\Local\
                  ~ %StartMenu% : C:\Users\marc\AppData\Roaming\Microsoft\Windows\Start Menu\
                  ~ %Windir% : C:\Windows\
                  ~ %System% : C:\Windows\System32\

                  ---\\ Enumération des unités disques
                  C: Hard drive, Flash drive, Thumb drive (Free 287 Go of 466 Go)
                  D: CD-ROM drive (Not Inserted)
                  F: CD-ROM drive (Not Inserted)
                  G: Floppy drive, Flash card reader, USB Key (Free 1 Go of 1 Go)
                  Q: Hard drive, Flash drive, Thumb drive (Free 0 Go of 0 Go)

                  ---\\ Etat du Centre de Sécurité Windows
                  [HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiSpywareOverride: OK
                  [HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusOverride: OK
                  [HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallOverride: OK
                  [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: OK
                  [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: OK
                  [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: OK
                  [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK
                  [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK
                  [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK
                  ~ Security Center: 36 Scanned in 00mn 00s

                  ---\\ Recherche particulière de fichiers génériques
                  [MD5.332FEAB1435662FC6C672E25BEB37BE3] - (.Microsoft Corporation - Explorateur Windows.) (.25/02/2011 - 07:19:30.) -- C:\Windows\Explorer.exe [2871808]
                  [MD5.94355C28C1970635A31B3FE52EB7CEBA] - (.Microsoft Corporation - Application de démarrage de Windows.) (.14/07/2009 - 02:39:52.) -- C:\Windows\System32\Wininit.exe [129024]
                  [MD5.AAFA952E774DDDB0956D3BDFAE5B5B99] - (.Microsoft Corporation - Extensions Internet pour Win32.) (.10/08/2013 - 06:22:18.) -- C:\Windows\System32\wininet.dll [2241024]
                  [MD5.1151B1BAA6F350B1DB6598E0FEA7C457] - (.Microsoft Corporation - Application d'ouverture de session Windows.) (.20/11/2010 - 05:25:32.) -- C:\Windows\System32\Winlogon.exe [390656]
                  [MD5.067FA52BFB59A56110A12312EF9AF243] - (.Microsoft Corporation - Bibliothèque de licences.) (.20/11/2010 - 05:27:28.) -- C:\Windows\System32\sppcomapi.dll [232448]
                  [MD5.1C7857B62DE5994A75B054A9FD4C3825] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) (.28/12/2011 - 04:59:24.) -- C:\Windows\system32\Drivers\AFD.sys [498688]
                  [MD5.02062C0B390B7729EDC9E69C680A6F3C] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.14/07/2009 - 02:52:21.) -- C:\Windows\system32\Drivers\atapi.sys [24128]
                  [MD5.B8BD2BB284668C84865658C77574381A] - (.Microsoft Corporation - CD-ROM File System Driver.) (.14/07/2009 - 00:19:47.) -- C:\Windows\system32\Drivers\Cdfs.sys [92160]
                  [MD5.F036CE71586E93D94DAB220D7BDF4416] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.20/11/2010 - 01:19:22.) -- C:\Windows\system32\Drivers\Cdrom.sys [147456]
                  [MD5.9BB2EF44EAA163B29C4A4587887A0FE4] - (.Microsoft Corporation - DFS Namespace Client Driver.) (.20/11/2010 - 01:26:34.) -- C:\Windows\system32\Drivers\DfsC.sys [102400]
                  [MD5.97BFED39B6B79EB12CDDBFEED51F56BB] - (.Microsoft Corporation - High Definition Audio Bus Driver.) (.20/11/2010 - 02:43:44.) -- C:\Windows\system32\Drivers\HDAudBus.sys [122368]
                  [MD5.FA55C73D4AFFA7EE23AC4BE53B4592D3] - (.Microsoft Corporation - Pilote de port i8042.) (.14/07/2009 - 00:19:57.) -- C:\Windows\system32\Drivers\i8042prt.sys [105472]
                  [MD5.AF9B39A7E7B6CAA203B3862582E9F2D0] - (.Microsoft Corporation - IP Network Address Translator.) (.14/07/2009 - 01:10:03.) -- C:\Windows\system32\Drivers\IpNat.sys [116224]
                  [MD5.A5D9106A73DC88564C825D317CAC68AC] - (.Microsoft Corporation - Windows NT SMB Minirdr.) (.27/04/2011 - 03:40:40.) -- C:\Windows\system32\Drivers\MRxSmb.sys [158208]
                  [MD5.09594D1089C523423B32A4229263F068] - (.Microsoft Corporation - MBT Transport driver.) (.20/11/2010 - 01:23:22.) -- C:\Windows\system32\Drivers\netBT.sys [261632]
                  [MD5.B98F8C6E31CD07B2E6F71F7F648E38C0] - (.Microsoft Corporation - Pilote du système de fichiers NT.) (.12/04/2013 - 15:45:08.) -- C:\Windows\system32\Drivers\ntfs.sys [1656680]
                  [MD5.0086431C29C35BE1DBC43F52CC273887] - (.Microsoft Corporation - Pilote de port parallèle.) (.14/07/2009 - 01:00:41.) -- C:\Windows\system32\Drivers\Parport.sys [97280]
                  [MD5.471815800AE33E6F1C32FB1B97C490CA] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.20/11/2010 - 02:52:36.) -- C:\Windows\system32\Drivers\Rasl2tp.sys [129536]
                  [MD5.548260A7B8654E024DC30BF8A7C5BAA4] - (.Microsoft Corporation - SMB Transport driver.) (.14/07/2009 - 01:09:09.) -- C:\Windows\system32\Drivers\smb.sys [93184]
                  [MD5.DDAD5A7AB24D8B65F8D724F5C20FD806] - (.Microsoft Corporation - TDI Translation Driver.) (.20/11/2010 - 01:21:58.) -- C:\Windows\system32\Drivers\tdx.sys [119296]
                  [MD5.0D08D2F3B3FF84E433346669B5E0F639] - (.Microsoft Corporation - Pilote de cliché instantané du volume.) (.20/11/2010 - 05:34:04.) -- C:\Windows\system32\Drivers\volsnap.sys [295808]
                  ~ Generic Processes: Scanned in 00mn 00s

                  ---\\ Etat des fichiers cachés (Caché/Total)
                  ~ Mes images (My Pictures) : 1/1090
                  ~ Mes musiques (My Musics) : 1/7
                  ~ Mes Videos (My Videos) : 1/15
                  ~ Mes Favoris (My Favorites) : 1/73
                  ~ Mes Documents (My Documents) : 1/154637
                  ~ Mon Bureau (My Desktop) : 1/183
                  ~ Menu demarrer (Programs) : 1/50
                  ~ Hidden Files: Scanned in 00mn 12s

                  ---\\ Processus lancés
                  [MD5.DE3B04D5AF8A1578F5430697546EB157] - (.ASUSTeK Computer Inc. - LiveUpdate.) -- C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe [1545856] [PID.1488]
                  [MD5.5BB1F77C8AF725A15EC9366498D275BB] - (.ASUS - ATKOSD2.) -- C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [5732992] [PID.2084]
                  [MD5.BC3DA234CDA880578526DAB028F40268] - (.ASUS - SmartLogon Application.) -- C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe [305792] [PID.2096]
                  [MD5.D1D5DAB39DCB4BE0359943738D87409B] - (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe [532040] [PID.2200]
                  [MD5.37287D98A1BF5D56AA729CEB9B27C6B1] - (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\IEXPLORE.exe [770648] [PID.3916]
                  [MD5.63DCE64797C64FB6110727B993440EA5] - (.Nicolas Coolman - ZHPDiag.) -- C:\Program Files (x86)\ZHPDiag\ZHPDiag.exe [8000512] [PID.3836]
                  [MD5.ADDA5E1951B90D3D23C56D3CF0622ADC] - (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [65640] [PID.1244]
                  [MD5.4C4A576818EA028257C624AE36FF7A03] - (.Atheros - Atheros Coex Service Application.) -- C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [138400] [PID.2420]
                  [MD5.65085456FD9A74D7F1A999520C299ECB] - (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376] [PID.2792]
                  [MD5.E0D7732F2D2E24B2DB3F67B6750295B8] - (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512] [PID.2908]
                  [MD5.831883B107684301F48ACE752C963984] - (...) -- C:\Windows\SysWOW64\PnkBstrA.exe [66872] [PID.2972]
                  [MD5.E24106A5EAECDDFF00B25497049DD65F] - (...) -- C:\Windows\SysWOW64\PnkBstrB.exe [107832] [PID.3000]
                  [MD5.39B1D0A636A400304565D4521FAD6D77] - (.Microsoft Corporation - Microsoft Application Virtualization Virtua.) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [207528] [PID.2180]
                  [MD5.77C5A741A7452812F278EF2C18478862] - (.Microsoft Corporation - Microsoft Application Virtualization Client.) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe [523944] [PID.3280]
                  [MD5.FD557A50A65E44041CD2FCEF4BEB04DB] - (.Microsoft Corporation - Microsoft Office Client Virtualization Serv.) -- C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.exe [822504] [PID.3460]
                  [MD5.20E83F4632E15A5E9E716FF2E8AC7FAE] - (.Intel Corporation - IAStorDataSvc.) -- C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15720] [PID.2476]
                  [MD5.3EA307C51069BC72DD74A4964F2A30A9] - (.Intel Corporation - Intel(R) Local Management Service.) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [366552] [PID.4672]
                  [MD5.00572C26C6DCF99362068FB7283B7126] - (.NVIDIA Corporation - NVIDIA Settings Update Manager.) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2009704] [PID.1456]
                  ~ Processes Running: Scanned in 00mn 01s

                  ---\\ Mozilla Firefox, Plugins,Demarrage,Recherche,Extensions (P2,M0,M1,M2,M3)
                  P2 - FPN: [HKLM] [@java.com/DTPlugin,version=10.40.2] - (.Oracle Corporation - NPRuntime Script Plug-in Library for Java(TM) Deploy.) -- C:\Windows\system32\npDeployJava1.dll
                  P2 - FPN: [HKLM] [@java.com/JavaPlugin,version=10.40.2] - (.Oracle Corporation - Next Generation Java Plug-in 10.40.2 for Mozilla browsers.) -- C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll
                  P2 - FPN: [HKLM] [@Microsoft.com/NpCtrl,version=1.0] - (. Microsoft Corporation - 5.1.20513.0.) -- c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll
                  P2 - FPN: [HKLM] [@microsoft.com/OfficeAuthz,version=14.0] - (.Microsoft Corporation - Office Authorization plug-in for NPAPI browsers.) -- C:\Program Files\Microsoft Office\Office14\NPAUTHZ.dll
                  P2 - FPN: [HKLM] [@videolan.org/vlc,version=2.0.8] - (.VideoLAN - VLC media player Web Plugin 2.0.6.) -- C:\Program Files\VideoLAN\VLC\npvlc.dll =>.VideoLAN
                  ~ Firefox Browser: 5 Scanned in 00mn 00s

                  ---\\ Internet Explorer, Démarrage,Recherche,URLSearchHook, Phishing (R0,R1,R3,R4)
                  R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://www.google.be/?gws_rd=ssl
                  R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/?gws_rd=ssl
                  R0 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
                  R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = https://www.microsoft.com/fr-fr/
                  R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons
                  R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk
                  R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.microsoft.com/fr-fr/
                  R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons
                  R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk
                  R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\AboutURLs,Tabs = res://ieframe.dll/tabswelcome.htm
                  R3 - URLSearchHook: Microsoft Url Search Hook [64Bits] - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} . (.Microsoft Corporation - Navigateur Internet.) (10.00.9200.16521 (win8_gdr_soc_ie.130216-2100)) -- C:\Windows\SysWOW64\ieframe.dll
                  R4 - HKLM\SOFTWARE\Microsoft\Internet Explorer\PhishingFilter,EnabledV8 = 1
                  R4 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\PhishingFilter,EnabledV8 = 1
                  ~ IE Browser: 15 Scanned in 00mn 00s

                  ---\\ Internet Explorer, Proxy Management (R5)
                  R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = <local>
                  R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key
                  R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
                  R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
                  R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
                  R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyHttp1.1 = 1
                  R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll
                  R5 - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
                  ~ Proxy management: Scanned in 00mn 00s

                  ---\\ Analyse des lignes F0, F1, F2, F3 - IniFiles, Autoloading programs
                  F2 - REG:system.ini: USERINIT=C:\Windows\system32\userinit.exe,
                  F2 - REG:system.ini: Shell=C:\Windows\explorer.exe
                  F2 - REG:system.ini: VMApplet=C:\Windows\System32\SystemPropertiesPerformance.exe
                  ~ Keys: Scanned in 00mn 00s

                  ---\\ Hosts file redirection (O1)
                  ~ Le fichier hosts est sain (The hosts file is clean).
                  ~ Hosts File: Scanned in 00mn 00s
                  ~ Nombre de lignes (Lines number): 19

                  ---\\ Internet Explorer Toolbars (O3)
                  O3 - Toolbar: Google Toolbar [64Bits] - [HKLM]{2318C2B1-4965-11d4-9B18-009027A5CD4F} . (.Google Inc. - Google Toolbar.) -- C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll =>Toolbar.Google
                  O3 - Toolbar\WebBrowser: (no name) [64Bits] - [HKCU]{2318C2B1-4965-11D4-9B18-009027A5CD4F} Clé orpheline
                  ~ Toolbar: Scanned in 00mn 00s

                  ---\\ Autres liens utilisateurs (O4)
                  O4 - GS\Desktop [Public]: CCleaner.lnk . (.Piriform Ltd - CCleaner.) -- C:\Program Files\CCleaner\CCleaner64.exe =>Piriform Ltd
                  O4 - GS\Desktop [Public]: Defraggler.lnk . (.Piriform Ltd - Defraggler.) -- C:\Program Files\Defraggler\Defraggler64.exe
                  O4 - GS\Desktop [Public]: eID Viewer.lnk . (.FedICT - eID Viewer.) -- C:\Program Files (x86)\Belgium Identity Card\EidViewer\eID Viewer.exe
                  O4 - GS\Desktop [Public]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
                  O4 - GS\Desktop [Public]: Ma-Config.com - Démarrer la détection.lnk . (...) -- C:\Program Files (x86)\ma-config.com\MCDetection.exe (.not file.)
                  O4 - GS\Desktop [Public]: Malwarebytes Anti-Malware.lnk . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe
                  O4 - GS\Desktop [Public]: VLC media player.lnk . (.VideoLAN - VLC media player 2.0.8.) -- C:\Program Files\VideoLAN\VLC\vlc.exe =>.VideoLAN
                  O4 - GS\Desktop [Public]: WahOO.lnk . (...) -- C:\Users\marc\AppData\Local\WahOO\Wahoo.exe
                  O4 - GS\Desktop [Public]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag Setup.) -- C:\Program Files (x86)\ZHPDiag\ZHPhep.exe =>.Nicolas Coolman
                  O4 - GS\Desktop [Public]: ZHPFix.lnk . (.Nicolas Coolman - ZHPDiag Setup.) -- C:\Program Files (x86)\ZHPDiag\ZHPFix\ZHPhep.exe =>.Nicolas Coolman
                  O4 - GS\Desktop [Public]: µTorrent.lnk . (.BitTorrent Inc. - µTorrent.) -- C:\Users\marc\AppData\Roaming\uTorrent\uTorrent.exe =>P2P.BitTorrent
                  O4 - GS\Program [Public]: Adobe Reader XI.lnk . (...) -- C:\Windows\Installer\{AC76BA86-7AD7-1033-7B44-AB0000000001}\SC_Reader.ico
                  O4 - GS\Program [Public]: Media Center.lnk . (.Microsoft Corporation - Windows Media Center.) -- C:\Windows\ehome\ehshell.exe =>.Microsoft Corporation
                  O4 - GS\Program [Public]: Microsoft Office 2010.lnk . (...) -- C:\Windows\Installer\{95140000-0070-0000-0000-0000000FF1CE}\oobeicon.exe
                  O4 - GS\Program [Public]: Microsoft Security Essentials.lnk . (...) -- C:\Program Files (x86)\Microsoft Security Client\msseces.exe (.not file.)
                  O4 - GS\Program [Public]: Movie Maker.lnk . (.Microsoft Corporation - Movie Maker.) -- C:\Program Files (x86)\Windows Live\Photo Gallery\MovieMaker.exe
                  O4 - GS\Program [Public]: Photo Gallery.lnk . (.Microsoft Corporation - Photo Gallery.) -- C:\Program Files (x86)\Windows Live\Photo Gallery\WLXPhotoGallery.exe
                  O4 - GS\Program [Public]: Sidebar.lnk . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files (x86)\Windows Sidebar\sidebar.exe =>.Microsoft Corporation
                  O4 - GS\Program [Public]: Visionneuse Microsoft Office PowerPoint 2007.lnk . (...) -- C:\Windows\Installer\{95120000-00AF-040C-0000-0000000FF1CE}\ppvwicon.exe =>.Microsoft Corporation
                  O4 - GS\Program [Public]: Windows Anytime Upgrade.lnk . (.Microsoft Corporation - Interface utilisateur de Mise à niveau expr.) -- C:\Windows\system32\WindowsAnytimeUpgradeUI.exe
                  O4 - GS\Program [Public]: Windows DVD Maker.lnk . (...) -- C:\Program Files (x86)\DVD Maker\DVDMaker.exe (.not file.)
                  O4 - GS\Program [Public]: Windows Fax and Scan.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) -- C:\Windows\system32\WFS.exe =>.Microsoft Corporation
                  O4 - GS\Program [Public]: Windows Live Mail.lnk . (.Microsoft Corporation - Windows Live Mail.) -- C:\Program Files (x86)\Windows Live\Mail\wlmail.exe =>.Microsoft Corporation
                  O4 - GS\Program [Public]: Windows Live Messenger.lnk . (.Microsoft Corporation - Windows Live Messenger.) -- C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
                  O4 - GS\Program [Public]: Windows Media Player.lnk . (.Microsoft Corporation - Lecteur Windows Media.) -- C:\Program Files (x86)\Windows Media Player\wmplayer.exe =>.Microsoft Corporation
                  O4 - GS\Program [Public]: XPS Viewer.lnk . (.Microsoft Corporation - Visionneuse XPS.) -- C:\Windows\system32\xpsrchvw.exe =>.Microsoft Corporation
                  O4 - GS\Program [Public]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag Setup.) -- C:\Program Files (x86)\ZHPDiag\ZHPhep.exe =>.Nicolas Coolman
                  O4 - GS\Accessories [Public]: Bluetooth File Transfer Wizard.lnk . (.Microsoft Corporation - Pas de description.) -- C:\Windows\System32\fsquirt.exe
                  O4 - GS\Accessories [Public]: Calculator.lnk . (.Microsoft Corporation - Calculatrice de Windows.) -- C:\Windows\system32\calc.exe =>.Microsoft Corporation
                  O4 - GS\Accessories [Public]: displayswitch.lnk . (.Microsoft Corporation - Afficher le commutateur.) -- C:\Windows\system32\displayswitch.exe =>.Microsoft Corporation
                  O4 - GS\Accessories [Public]: Math Input Panel.lnk . (.Microsoft Corporation - Accessoire du panneau de saisie mathématiqu.) -- C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\mip.exe =>.Microsoft Corporation
                  O4 - GS\Accessories [Public]: Mobility Center.lnk . (.Microsoft Corporation - Centre de mobilité Windows.) -- C:\Windows\system32\mblctr.exe =>.Microsoft Corporation
                  O4 - GS\Accessories [Public]: Paint.lnk . (.Microsoft Corporation - Paint.) -- C:\Windows\system32\mspaint.exe =>.Microsoft Corporation
                  O4 - GS\Accessories [Public]: Remote Desktop Connection.lnk . (.Microsoft Corporation - Connexion Bureau à distance.) -- C:\Windows\system32\mstsc.exe =>.Microsoft Corporation
                  O4 - GS\Accessories [Public]: Snipping Tool.lnk . (.Microsoft Corporation - Outil Capture.) -- C:\Windows\system32\SnippingTool.exe =>.Microsoft Corporation
                  O4 - GS\Accessories [Public]: Sound Recorder.lnk . (.Microsoft Corporation - Magnétophone Windows.) -- C:\Windows\system32\SoundRecorder.exe =>.Microsoft Corporation
                  O4 - GS\Accessories [Public]: Sticky Notes.lnk . (.Microsoft Corporation - Pense-bête.) -- C:\Windows\system32\StikyNot.exe =>.Microsoft Corporation
                  O4 - GS\Accessories [Public]: Sync Center.lnk . (.Microsoft Corporation - Microsoft Sync Center.) -- C:\Windows\System32\mobsync.exe =>.Microsoft Corporation
                  O4 - GS\Accessories [Public]: Welcome Center.lnk . (.Microsoft Corporation - Mise en route.) -- C:\Windows\system32\OobeFldr.dll =>.Microsoft Corporation
                  O4 - GS\Accessories [Public]: Wordpad.lnk . (.Microsoft Corporation - Application Windows Wordpad.) -- C:\Program Files (x86)\Windows NT\Accessories\wordpad.exe =>.Microsoft Corporation
                  O4 - GS\SystemTools [Public]: Character Map.lnk . (.Microsoft Corporation - Table des caractères.) -- C:\Windows\system32\charmap.exe =>.Microsoft Corporation
                  O4 - GS\SystemTools [Public]: dfrgui.lnk . (.Microsoft Corporation - Défragmenteur de disque Microsoft®.) -- C:\Windows\system32\dfrgui.exe =>.Microsoft Corporation
                  O4 - GS\SystemTools [Public]: Disk Cleanup.lnk . (.Microsoft Corporation - Gestionnaire de nettoyage de disque pour Wi.) -- C:\Windows\system32\cleanmgr.exe =>.Microsoft Corporation
                  O4 - GS\SystemTools [Public]: Resource Monitor.lnk . (.Microsoft Corporation - Moniteur de ressources et de performances.) -- C:\Windows\system32\perfmon.exe =>.Microsoft Corporation
                  O4 - GS\SystemTools [Public]: System Information.lnk . (.Microsoft Corporation - Informations système.) -- C:\Windows\system32\msinfo32.exe
                  O4 - GS\SystemTools [Public]: System Restore.lnk . (.Microsoft Corporation - Restauration du système de Microsoft® Windo.) -- C:\Windows\system32\rstrui.exe =>.Microsoft Corporation
                  O4 - GS\SystemTools [Public]: Task Scheduler.lnk . (...) -- C:\Windows\system32\taskschd.msc
                  O4 - GS\SystemTools [Public]: Windows Easy Transfer Reports.lnk . (.Microsoft Corporation - Application post-migration de transfert de.) -- C:\Windows\system32\migwiz\postmig.exe =>.Microsoft Corporation
                  O4 - GS\SystemTools [Public]: Windows Easy Transfer.lnk . (.Microsoft Corporation - Application Transfert de fichiers et paramè.) -- C:\Windows\system32\migwiz\migwiz.exe =>.Microsoft Corporation
                  O4 - GS\QuickLaunch [UpdatusUser]: MiPony.lnk . (.www.mipony.net - Mipony.) -- C:\Program Files (x86)\MiPony\MiPony.exe
                  O4 - GS\Accessories [UpdatusUser]: Command Prompt.lnk . (.Microsoft Corporation - Interpréteur de commandes Windows.) -- C:\Windows\system32\cmd.exe =>.Microsoft Corporation
                  O4 - GS\Accessories [UpdatusUser]: Notepad.lnk . (.Microsoft Corporation - Bloc-notes.) -- C:\Windows\system32\notepad.exe =>.Microsoft Corporation
                  O4 - GS\Accessories [UpdatusUser]: Run.lnk - Clé orpheline
                  O4 - GS\Accessories [UpdatusUser]: Windows Explorer.lnk . (.Microsoft Corporation - Explorateur Windows.) -- C:\Windows\explorer.exe =>.Microsoft Corporation
                  O4 - GS\SystemTools [UpdatusUser]: Private Character Editor.lnk . (.Microsoft Corporation - Éditeur de caractères privés.) -- C:\Windows\system32\eudcedit.exe =>.Microsoft Corporation
                  O4 - GS\Desktop [UpdatusUser]: Microsoft Office 2010.lnk . (...) -- C:\Windows\Installer\{95140000-0070-0000-0000-0000000FF1CE}\oobeicon.exe
                  O4 - GS\Desktop [UpdatusUser]: MiPony.lnk . (.www.mipony.net - Mipony.) -- C:\Program Files (x86)\MiPony\MiPony.exe
                  O4 - GS\Desktop [UpdatusUser]: Windows Live Family Safety.lnk . (...) -- C:\Windows\Installer\{46A5FBE9-ADB3-4493-A1CC-B4CFFD24D26A}\fssicon.ico (.not file.)
                  O4 - GS\Desktop [UpdatusUser]: Windows Live Mail.lnk . (.Microsoft Corporation - Windows Live Mail.) -- C:\Program Files (x86)\Windows Live\Mail\wlmail.exe =>.Microsoft Corporation
                  O4 - GS\Desktop [UpdatusUser]: Windows Live Mesh.lnk . (...) -- C:\Program Files (x86)\Windows Live\Mesh\WLSync.exe (.not file.)
                  O4 - GS\Desktop [UpdatusUser]: Windows Live Messenger.lnk . (.Microsoft Corporation - Windows Live Messenger.) -- C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
                  O4 - GS\Desktop [UpdatusUser]: Windows Live Movie Maker.lnk . (.Microsoft Corporation - Movie Maker.) -- C:\Program Files (x86)\Windows Live\Photo Gallery\MovieMaker.exe =>.Microsoft Corporation
                  O4 - GS\Desktop [UpdatusUser]: Windows Live Writer.lnk . (.Microsoft Corp. - Windows Live Writer.) -- C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriter.exe
                  O4 - GS\QuickLaunch [marc]: Launch Internet Explorer Browser.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
                  O4 - GS\QuickLaunch [marc]: MiPony.lnk . (.www.mipony.net - Mipony.) -- C:\Program Files (x86)\MiPony\MiPony.exe
                  O4 - GS\TaskBar [marc]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe
                  O4 - GS\TaskBar [marc]: Microsoft Outlook 2010.lnk . (...) -- C:\Windows\Installer\{90140000-0011-0000-0000-0000000FF1CE}\outicon.exe
                  O4 - GS\TaskBar [marc]: Windows Explorer.lnk . (.Microsoft Corporation - Explorateur Windows.) -- C:\Windows\explorer.exe =>.Microsoft Corporation
                  O4 - GS\TaskBar [marc]: Windows Live Mail.lnk . (.Microsoft Corporation - Windows Live Mail.) -- C:\Program Files (x86)\Windows Live\Mail\wlmail.exe =>.Microsoft Corporation
                  O4 - GS\TaskBar [marc]: Windows Media Player.lnk . (.Microsoft Corporation - Lecteur Windows Media.) -- C:\Program Files (x86)\Windows Media Player\wmplayer.exe =>.Microsoft Corporation
                  O4 - GS\Program [marc]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe
                  O4 - GS\Program [marc]: Microsoft SkyDrive.lnk . (.Microsoft Corporation - Microsoft SkyDrive.) -- C:\Users\marc\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe =>.Microsoft Corporation
                  O4 - GS\Program [marc]: Update Checker.lnk . (.FileHippo.com - FileHippo.com Update Checker.) -- C:\Program Files (x86)\FileHippo.com\UpdateChecker.exe
                  O4 - GS\Accessories [marc]: Command Prompt.lnk . (.Microsoft Corporation - Interpréteur de commandes Windows.) -- C:\Windows\system32\cmd.exe =>.Microsoft Corporation
                  O4 - GS\Accessories [marc]: Notepad.lnk . (.Microsoft Corporation - Bloc-notes.) -- C:\Windows\system32\notepad.exe =>.Microsoft Corporation
                  O4 - GS\Accessories [marc]: Run.lnk - Clé orpheline
                  O4 - GS\Accessories [marc]: Windows Explorer.lnk . (.Microsoft Corporation - Explorateur Windows.) -- C:\Windows\explorer.exe =>.Microsoft Corporation
                  O4 - GS\SystemTools [marc]: Internet Explorer (No Add-ons).lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe
                  O4 - GS\SystemTools [marc]: Private Character Editor.lnk . (.Microsoft Corporation - Éditeur de caractères privés.) -- C:\Windows\system32\eudcedit.exe =>.Microsoft Corporation
                  O4 - GS\SendTo [marc]: Format Factory.lnk . (.Free Time - FormatFactory.) -- C:\Program Files (x86)\FreeTime\FormatFactory\FormatFactory.exe
                  O4 - GS\SendTo [marc]: Skype.lnk . (.Skype Technologies S.A. - Skype.) -- C:\Program Files (x86)\Skype\Phone\Skype.exe
                  O4 - GS\Desktop [marc]: Android Manager.lnk . (.Mobile Action Tech. Inc. - Android Manager - Panel EXE.) -- C:\Program Files (x86)\Mobile Action\Android Manager\Panelexe.exe
                  O4 - GS\Desktop [marc]: Documents - Raccourci.lnk . (...) -- C:\Users\marc\AppData\Roaming\Microsoft\Windows\Libraries\Documents.library-ms
                  O4 - GS\Desktop [marc]: Format Factory.lnk . (.Free Time - FormatFactory.) -- C:\Program Files (x86)\FreeTime\FormatFactory\FormatFactory.exe
                  O4 - GS\Desktop [marc]: Internet Explorer (64-bit) (2).lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
                  O4 - GS\Desktop [marc]: MiPony.lnk . (.www.mipony.net - Mipony.) -- C:\Program Files (x86)\MiPony\MiPony.exe
                  O4 - GS\Desktop [marc]: Tweaking.com - Windows Repair (All in One).lnk . (.Tweaking.com - Pas de description.) -- C:\Program Files (x86)\Tweaking.com\Windows Repair (All in One)\Repair_Windows.exe
                  O4 - GS\Desktop [marc]: Update Checker.lnk . (.FileHippo.com - FileHippo.com Update Checker.) -- C:\Program Files (x86)\FileHippo.com\UpdateChecker.exe
                  O4 - GS\Desktop [marc]: VirtualDJ PRO Full.lnk . (.Atomix Productions - VirtualDJ.) -- C:\Program Files (x86)\VirtualDJ\virtualdj_pro.exe
                  O4 - GS\Desktop [marc]: WinRar 5.00 - 64 Bits Licence.rar - Raccourci.lnk . (...) -- C:\Users\marc\Documents\Mipony\WinRar 5.00 - 64 Bits + Licence\WinRar 5.00 - 64 Bits Licence.rar
                  ~ Global Startup: 90 Scanned in 00mn 08s

                  ---\\ Applications lancées au démarrage du sytème (O4)
                  O4 - HKLM\..\Run: [MSC] . (.Microsoft Corporation - Microsoft Security Client User Interface.) -- c:\Program Files\Microsoft Security Client\msseces.exe
                  O4 - HKUS\S-1-5-19\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files (x86)\Windows Sidebar\Sidebar.exe =>.Microsoft Corporation
                  O4 - HKUS\S-1-5-20\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files (x86)\Windows Sidebar\Sidebar.exe =>.Microsoft Corporation
                  O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =>.Microsoft Corporation
                  O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =>.Microsoft Corporation
                  ~ Application: Scanned in 00mn 00s

                  ---\\ Invisibilité de l'icône d'options IE dans le panneau de Configuration (O5)
                  O5 - control.ini: [HKLM\..\Control Panel] inetcpl.cpl=no
                  ~ IE Control Panel: 1 Scanned in 00mn 00s

                  ---\\ Boutons situés sur la barre d'outils principale d'Internet Explorer (O9)
                  O9 - Extra button: &Envoyer à OneNote [64Bits] - {2670000A-7350-4f3c-8081-5663EE0C6C49} -- C:\Program Files (x86)\MICROS~2\Office14\ONBttnIE.dll (.not file.)
                  O9 - Extra button: Notes &liées OneNote [64Bits] - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} -- C:\Program Files (x86)\MICROS~2\Office14\ONBTTN~1.dll (.not file.)
                  ~ IE Extra Buttons: Scanned in 00mn 00s

                  ---\\ Winsock hijacker (Layered Service Provider) (O10)
                  O10 - WLSP:\000000000001\Winsock LSP File . (.Microsoft Corporation - Network Location Awareness 2.) -- C:\Windows\system32\NLAapi.dll
                  O10 - WLSP:\000000000002\Winsock LSP File . (.Microsoft Corporation - Fournisseur Shim d'affectation de noms de messagerie.) -- C:\Windows\system32\napinsp.dll
                  O10 - WLSP:\000000000003\Winsock LSP File . (.Microsoft Corporation - Fournisseur d'espace de noms PNRP.) -- C:\Windows\system32\pnrpnsp.dll
                  O10 - WLSP:\000000000004\Winsock LSP File . (.Microsoft Corporation - Fournisseur d'espace de noms PNRP.) -- C:\Windows\system32\pnrpnsp.dll
                  O10 - WLSP:\000000000005\Winsock LSP File . (.Microsoft Corporation - Fournisseur de service Sockets 2.0 de Microsoft Windows.) -- C:\Windows\system32\mswsock.dll =>.Microsoft Corporation
                  O10 - WLSP:\000000000006\Winsock LSP File . (.Microsoft Corporation - LDAP RnR Provider DLL.) -- C:\Windows\system32\winrnr.dll
                  O10 - WLSP:\000000000007\Winsock LSP File . (.Microsoft Corp. - Microsoft® Windows Live ID Namespace Provider.) -- C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.dll =>.Microsoft Corporation
                  O10 - WLSP:\000000000008\Winsock LSP File . (.Microsoft Corp. - Microsoft® Windows Live ID Namespace Provider.) -- C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.dll =>.Microsoft Corporation
                  O10 - WLSP:\000000000009\Winsock LSP File . (.Microsoft Corporation - Windows Sockets Helper DLL.) -- C:\Windows\system32\wshbth.dll
                  ~ Winsock: 9 Scanned in 00mn 00s

                  ---\\ Site dans la Zone de confiance d'Internet Explorer (O15)
                  O15 - Trusted Zone: [HKCU\...\Domains] http.ma-config.com
                  O15 - Trusted Zone: [HKCU\...\Domains] http.touslesdrivers.com
                  ~ IE Zone Confiance: Scanned in 00mn 01s

                  ---\\ Modification Domaine/Adresses DNS (O17)
                  O17 - HKLM\System\CCS\Services\Tcpip\..\{BE8651DF-F4D0-48A2-AD35-5FE77E475229}: DhcpNameServer = 62.197.111.140 109.88.203.3
                  O17 - HKLM\System\CCS\Services\Tcpip\..\{BE8651DF-F4D0-48A2-AD35-5FE77E475229}: DhcpDomain = teledisnet.be
                  O17 - HKLM\System\CS1\Services\Tcpip\..\{BE8651DF-F4D0-48A2-AD35-5FE77E475229}: DhcpNameServer = 62.197.111.140 109.88.203.3
                  O17 - HKLM\System\CS1\Services\Tcpip\..\{BE8651DF-F4D0-48A2-AD35-5FE77E475229}: DhcpDomain = teledisnet.be
                  O17 - HKLM\System\CS2\Services\Tcpip\..\{BE8651DF-F4D0-48A2-AD35-5FE77E475229}: DhcpNameServer = 62.197.111.140 109.88.203.3
                  O17 - HKLM\System\CS2\Services\Tcpip\..\{BE8651DF-F4D0-48A2-AD35-5FE77E475229}: DhcpDomain = teledisnet.be
                  O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 62.197.111.140 109.88.203.3
                  ~ Domain: Scanned in 00mn 00s

                  ---\\ Protocole additionnel (O18)
                  O18 - Handler: wlpg [64Bits] - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} . (...) --
                  O18 - Filter: text/xml [64Bits] - {807573E5-5146-11D5-A672-00B0D022E945} . (.Microsoft Corporation - Microsoft Office XML MIME Filter.) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.dll =>.Microsoft Corporation
                  ~ Protocole Additionnel: Scanned in 00mn 00s

                  ---\\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (autorun) (O20)
                  O20 - Winlogon Notify: igfxcui . (.Intel Corporation - igfxdev Module.) -- C:\Windows\System32\igfxdev.dll
                  ~ Winlogon: Scanned in 00mn 00s

                  ---\\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (autorun) (O20)
                  O20 - AppInit_DLLs: . (.NVIDIA Corporation - NVIDIA Compatible NVIDIA shim initializatio.) - C:\Windows\system32\nvinitx.dll
                  ~ AppInit DLL: Scanned in 00mn 00s

                  ---\\ Clé de Registre autorun ShellServiceObjectDelayLoad (SSO/SSODL) (O21)
                  O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
                  ~ SSODL: 1 Scanned in 00mn 00s

                  ---\\ Liste des services NT non Microsoft et non désactivés (O23)
                  O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) . (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
                  O23 - Service: Atheros Bt&Wlan Coex Agent (Atheros Bt&Wlan Coex Agent) . (.Atheros - Atheros Coex Service Application.) - C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
                  O23 - Service: AtherosSvc (AtherosSvc) . (.Atheros Commnucations - AdminService Application.) - C:\Program Files (x86)\Bluetooth Suite\adminservice.exe
                  O23 - Service: Service Google Update (gupdate) (gupdate) . (.Google Inc. - Programme d'installation de Google.) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe =>.Google Inc
                  O23 - Service: Google Software Updater (gusvc) . (.Google - gusvc.) - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
                  O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) . (.Intel Corporation - IAStorDataSvc.) - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
                  O23 - Service: Intel(R) Capability Licensing Service In (Intel(R) Capability Licensing Service Interface) . (.Intel(R) Corporation - Intel(R) Capability Licensing Service Inter.) - C:\Program Files\Intel\iCLS Client\HeciServer.exe
                  O23 - Service: Intel(R) Management and Security Applica (LMS) . (.Intel Corporation - Intel(R) Local Management Service.) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
                  O23 - Service: Ma-Config Agent (MaConfigAgent) . (.CybelSoft - Service de détection matériel.) - C:\Program Files\ma-config.com\MaConfigAgent.exe
                  O23 - Service: (MBAMScheduler) . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
                  O23 - Service: (MBAMService) . (.Malwarebytes Corporation - Malwarebytes Anti-Malware.) - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
                  O23 - Service: NVIDIA Display Driver Service (NVSvc) . (.NVIDIA Corporation - NVIDIA Driver Helper Service, Version 268.5.) - C:\Windows\system32\nvvsvc.exe
                  O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) . (.NVIDIA Corporation - NVIDIA Settings Update Manager.) - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
                  O23 - Service: PnkBstrA (PnkBstrA) . (...) - C:\Windows\SysWOW64\PnkBstrA.exe
                  O23 - Service: PnkBstrB (PnkBstrB) . (...) - C:\Windows\SysWOW64\PnkBstrB.exe
                  O23 - Service: Skype Updater (SkypeUpdate) . (.Skype Technologies - Skype Updater Service.) - C:\Program Files (x86)\Skype\Updater\Updater.exe
                  ~ Services: 16 Scanned in 00mn 09s

                  ---\\ Enumération Active Desktop & MHTML Editor (O24)
                  O24 - Default MHTML Editor: Last - .(...) - (.not file.)
                  ~ Desktop Component: 4 Scanned in 00mn 00s

                  ---\\ Enumère les données de BootExecute (BEX) (O34)
                  O34 - HKLM BootExecute: (autocheck autochk *) - File not found
                  O34 - HKLM BootExecute: (sdnclean64.exe) - File not found
                  ~ BEX: 2 Scanned in 00mn 00s

                  ---\\ Tâches planifiées en automatique (O39)
                  O39 - APT:Automatic Planified Task - C:\Windows\Tasks\Adobe Flash Player Updater.job [1002]
                  O39 - APT:Automatic Planified Task - C:\Windows\Tasks\File Helper.job [346]
                  O39 - APT:Automatic Planified Task - C:\Windows\Tasks\Google Software Updater.job [1014]
                  O39 - APT:Automatic Planified Task - C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job [1060]
                  O39 - APT:Automatic Planified Task - C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job [1064]
                  [MD5.3ACABCA6A8DB71B7F19C8A7523AE1846] [APT] [ACMON] (.ASUS.) -- C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [691328]
                  [MD5.476BB014F3F68C0C15EDDD5B444DA8FF] [APT] [Adobe Flash Player Updater] (.Adobe Systems Incorporated.) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [257416]
                  [MD5.DE3B04D5AF8A1578F5430697546EB157] [APT] [ASUS Live Update] (.ASUSTeK Computer Inc..) -- C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe [1545856]
                  [MD5.180E79B16063F7DFD005DC021AC543C6] [APT] [ASUS P4G] (.ASUS.) -- C:\Program Files\P4G\BatteryLife.exe [977024]
                  [MD5.BC3DA234CDA880578526DAB028F40268] [APT] [ASUS SmartLogon Console Sensor] (.ASUS.) -- C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe [305792]
                  [MD5.5BB1F77C8AF725A15EC9366498D275BB] [APT] [ATKOSD2] (.ASUS.) -- C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [5732992]
                  [MD5.4C0A720AB377391D7D2EDE1ED905A420] [APT] [CCleanerSkipUAC] (.Piriform Ltd.) -- C:\Program Files\CCleaner\CCleaner.exe [3676952] =>Piriform Ltd
                  [MD5.00000000000000000000000000000000] [APT] [File Helper] (...) -- C:\Program Files (x86)\File Helper\File Helper.lnk --scan --stack=from-scheduler (.not file.) [0]
                  [MD5.5D4BC124FAAE6730AC002CDB67BF1A1C] [APT] [Google Software Updater] (.Google.) -- C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [194032]
                  [MD5.506708142BC63DABA64F2D3AD1DCD5BF] [APT] [GoogleUpdateTaskMachineCore] (.Google Inc..) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [116648]
                  [MD5.506708142BC63DABA64F2D3AD1DCD5BF] [APT] [GoogleUpdateTaskMachineUA] (.Google Inc..) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [116648]
                  [MD5.28405F60CCF4023CD253B0EB3640C078] [APT] [HPCustParticipation HP Photosmart 5520 series] (.Hewlett-Packard Co..) -- C:\Program Files\HP\HP Photosmart 5520 series\Bin\HPCustPartic.exe [4119656]
                  ~ Scheduled Task: 19 Scanned in 00mn 07s

                  ---\\ Composants installés (ActiveSetup Installed Components) (O40)
                  O40 - ASIC: Microsoft Windows Media Player [64Bits] - >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Ressources du Lecteur Windows Media.) -- C:\Windows\System32\wmploc.dll =>.Microsoft Corporation
                  O40 - ASIC: Microsoft Windows Media Player 12.0 [64Bits] - {22d6f312-b0f6-11d0-94ab-0080c74c7e95} . (.Microsoft Corporation - Windows Media Player Extension.) -- C:\Windows\SysWOW64\wmpdxm.dll =>.Microsoft Corporation
                  O40 - ASIC: Themes Setup [64Bits] - {2C7339CF-2B09-4501-B3F3-F3508C9228ED} . (.Microsoft Corporation - API Windows Theme.) -- C:\Windows\System32\themeui.dll
                  O40 - ASIC: Internet Explorer [64Bits] - {2D46B6DC-2207-486B-B523-A557E6D54B47} . (.Microsoft Corporation - Interpréteur de commandes Windows.) -- C:\Windows\system32\cmd.exe =>.Microsoft Corporation
                  O40 - ASIC: Microsoft Windows [64Bits] - {44BBA840-CC51-11CF-AAFA-00AA00B6015C} . (.Microsoft Corporation - Windows Mail.) -- C:\Program Files (x86)\Windows Mail\WinMail.exe =>.Microsoft Corporation
                  O40 - ASIC: Browsing Enhancements [64Bits] - {630b1da0-b465-11d1-9948-00c04f98bbc9} . (.Microsoft Corporation - Extension Shell dossier FTP Microsoft Internet Explorer..) -- C:\Windows\System32\msieftp.dll
                  O40 - ASIC: Microsoft Windows Media Player [64Bits] - {6BF52A52-394A-11d3-B153-00C04F79FAA6} . (.Microsoft Corporation - Ressources du Lecteur Windows Media.) -- C:\Windows\System32\wmploc.dll =>.Microsoft Corporation
                  O40 - ASIC: Windows Desktop Update [64Bits] - {89820200-ECBD-11cf-8B85-00AA005B4340} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\Windows\System32\shell32.dll
                  O40 - ASIC: Web Platform Customizations [64Bits] - {89820200-ECBD-11cf-8B85-00AA005B4383} . (.Microsoft Corporation - Utilitaire d'initialisation d'Internet Explorer par utilisateur.) -- C:\Windows\System32\ie4uinit.exe
                  O40 - ASIC: (no name) [64Bits] - {89B4C1CD-B018-4511-B0A1-5476DBF70820} . (.Microsoft Corporation - Microsoft .NET IE SECURITY REGISTRATION.) -- C:\Windows\system32\mscories.dll
                  ~ Active Setup: 10 Scanned in 00mn 00s

                  ---\\ Pilotes lancés au démarrage du système (O41)
                  O41 - Driver: C:\Windows\System32\drivers\afd.sys (AFD) . (.Microsoft Corporation - Ancillary Function Driver for WinSock.) - C:\Windows\system32\drivers\afd.sys
                  O41 - Driver: (ATKWMIACPIIO) . (.ASUS - ATK WMIACPI Utility.) - C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys
                  O41 - Driver: (blbdrive) . (.Microsoft Corporation - BLB Drive Driver.) - C:\Windows\System32\DRIVERS\blbdrive.sys
                  O41 - Driver: (cdrom) . (.Microsoft Corporation - SCSI CD-ROM Driver.) - C:\Windows\System32\DRIVERS\cdrom.sys
                  O41 - Driver: C:\Windows\System32\drivers\dfsc.sys (DfsC) . (.Microsoft Corporation - DFS Namespace Client Driver.) - C:\Windows\System32\Drivers\dfsc.sys
                  O41 - Driver: C:\Windows\System32\drivers\discache.sys (discache) . (.Microsoft Corporation - System Indexer/Cache Driver.) - C:\Windows\System32\drivers\discache.sys
                  O41 - Driver: (ElbyCDIO) . (.Elaborate Bytes AG - ElbyCD Windows x64 I/O driver.) - C:\Windows\System32\Drivers\ElbyCDIO.sys
                  O41 - Driver: (mssmbios) . (.Microsoft Corporation - System Management BIOS Driver.) - C:\Windows\System32\DRIVERS\mssmbios.sys
                  O41 - Driver: (NetBIOS) . (.Microsoft Corporation - NetBIOS interface driver.) - C:\Windows\System32\DRIVERS\netbios.sys
                  O41 - Driver: C:\Windows\System32\drivers\netbt.sys (NetBT) . (.Microsoft Corporation - MBT Transport driver.) - C:\Windows\System32\DRIVERS\netbt.sys
                  O41 - Driver: C:\Windows\System32\drivers\nsiproxy.sys (nsiproxy) . (.Microsoft Corporation - NSI Proxy.) - C:\Windows\System32\drivers\nsiproxy.sys
                  O41 - Driver: C:\Windows\System32\drivers\pacer.sys (Psched) . (.Microsoft Corporation - Planificateur de paquets QoS.) - C:\Windows\System32\DRIVERS\pacer.sys
                  O41 - Driver: C:\Windows\System32\wkssvc.dll (rdbss) . (.Microsoft Corporation - Pilote du sous-système de mise en mémoire t.) - C:\Windows\System32\DRIVERS\rdbss.sys
                  O41 - Driver: C:\Windows\System32\DRIVERS\RDPCDD.sys (RDPCDD) . (.Microsoft Corporation - RDP Miniport.) - C:\Windows\System32\DRIVERS\RDPCDD.sys
                  O41 - Driver: C:\Windows\System32\drivers\RDPENCDD.sys (RDPENCDD) . (.Microsoft Corporation - RDP Encoder Miniport.) - C:\Windows\System32\drivers\rdpencdd.sys
                  O41 - Driver: C:\Windows\System32\drivers\RdpRefMp.sys (RDPREFMP) . (.Microsoft Corporation - RDP Reflector Driver Miniport.) - C:\Windows\System32\drivers\rdprefmp.sys
                  O41 - Driver: C:\Windows\System32\tcpipcfg.dll (tdx) . (.Microsoft Corporation - TDI Translation Driver.) - C:\Windows\System32\DRIVERS\tdx.sys
                  O41 - Driver: (TermDD) . (.Microsoft Corporation - Remote Desktop Server Driver.) - C:\Windows\System32\DRIVERS\termdd.sys
                  O41 - Driver: (VgaSave) . (.Microsoft Corporation - VGA/Super VGA Video Driver.) - C:\Windows\system32\drivers\vga.sys
                  O41 - Driver: (vwififlt) . (.Microsoft Corporation - Virtual WiFi Filter Driver.) - C:\Windows\System32\DRIVERS\vwififlt.sys
                  O41 - Driver: C:\Windows\System32\rascfg.dll (Wanarpv6) . (.Microsoft Corporation - MS Remote Access and Routing ARP Driver.) - C:\Windows\System32\DRIVERS\wanarp.sys
                  O41 - Driver: (WfpLwf) . (.Microsoft Corporation - WFP NDIS 6.20 Lightweight Filter Driver.) - C:\Windows\System32\DRIVERS\wfplwf.sys
                  ~ Drivers: 66 Scanned in 00mn 00s

                  ---\\ Logiciels installés (O42)
                  O42 - Logiciel: 3DMark 11 - (.Futuremark Corporation.) [HKLM][64Bits] -- {46EDCFA5-7EDB-46A9-B093-1C6237470CEC}
                  O42 - Logiciel: 3DMark06 - (.Futuremark Corporation.) [HKLM][64Bits] -- {7F3AD00A-1819-4B15-BB7D-08B3586336D7}
                  O42 - Logiciel: 7-Zip 9.22 (x64 edition) - (.Igor Pavlov.) [HKLM][64Bits] -- {23170F69-40C1-2702-0922-000001000000}
                  O42 - Logiciel: AMD Drag and Drop Transcoding - (.ATI Technologies Inc..) [HKLM][64Bits] -- {8FCBB6DA-069C-8D08-DD99-F0881B9EECC3}
                  O42 - Logiciel: ASUS AI Recovery - (.ASUS.) [HKLM][64Bits] -- {38253529-D97D-4901-AE53-5CC9736D3A2E}
                  O42 - Logiciel: ASUS FancyStart - (.ASUSTeK Computer Inc..) [HKLM][64Bits] -- {2B81872B-A054-48DA-BE3B-FA5C164C303A}
                  O42 - Logiciel: ASUS K3 Series ScreenSaver - (.ASUS.) [HKLM][64Bits] -- ASUS K3 Series ScreenSaver
                  O42 - Logiciel: ASUS LifeFrame3 - (.ASUS.) [HKLM][64Bits] -- {1DBD1F12-ED93-49C0-A7CC-56CBDE488158}
                  O42 - Logiciel: ASUS Live Update - (.ASUS.) [HKLM][64Bits] -- {FA540E67-095C-4A1B-97BA-4D547DEC9AF4}
                  O42 - Logiciel: ASUS Power4Gear Hybrid - (.ASUS.) [HKLM][64Bits] -- {9B6239BF-4E85-4590-8D72-51E30DB1A9AA}
                  O42 - Logiciel: ASUS SmartLogon - (.ASUS.) [HKLM][64Bits] -- {64452561-169F-4A36-A2FF-B5E118EC65F5}
                  O42 - Logiciel: ASUS Splendid Video Enhancement Technology - (.ASUS.) [HKLM][64Bits] -- {0969AF05-4FF6-4C00-9406-43599238DE0D}
                  O42 - Logiciel: ASUS Virtual Camera - (.asus.) [HKLM][64Bits] -- {EC8BD21F-0CA0-4BBF-97D9-4A52B30041A1}
                  O42 - Logiciel: ATI Catalyst Install Manager - (.ATI Technologies, Inc..) [HKLM][64Bits] -- {CACBDC26-D504-49ED-3FEC-0CDDB3700240}
                  O42 - Logiciel: ATK Package - (.ASUS.) [HKLM][64Bits] -- {AB5C933E-5C7D-4D30-B314-9C83A49B94BE}
                  O42 - Logiciel: Adobe Flash Player 11 ActiveX - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- Adobe Flash Player ActiveX
                  O42 - Logiciel: Adobe Reader XI (11.0.04) - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {AC76BA86-7AD7-1033-7B44-AB0000000001}
                  O42 - Logiciel: Akamai NetSession Interface - (.Akamai Technologies, Inc.) [HKCU][64Bits] -- Akamai
                  O42 - Logiciel: Alcatraz - (.City Interactive.) [HKLM][64Bits] -- Alcatraz/FR-French_is1
                  O42 - Logiciel: Android Manager - (.Mobile Action.) [HKLM][64Bits] -- {83CF5DBB-EA0D-0100-0000-0000004F0022}
                  O42 - Logiciel: Asmedia ASM104x USB 3.0 Host Controller Driver - (.Asmedia Technology.) [HKLM][64Bits] -- {E4FB0B39-C991-4EE7-95DD-1A1A7857D33D}
                  O42 - Logiciel: Atheros Client Installation Program - (.Atheros.) [HKLM][64Bits] -- {28006915-2739-4EBE-B5E8-49B25D32EB33}
                  O42 - Logiciel: Belgium e-ID middleware 4.0.5 (build 7363) - (.Belgian Government.) [HKLM][64Bits] -- {824563DE-75AD-4166-9DC0-B6482F207363}
                  O42 - Logiciel: Bing Bar - (.Microsoft Corporation.) [HKLM][64Bits] -- {449CE12D-E2C7-4B97-B19E-55D163EA9435} =>Toolbar.Bing
                  O42 - Logiciel: Bluetooth Win7 Suite (64) - (.Atheros Communications.) [HKLM][64Bits] -- {230D1595-57DA-4933-8C4E-375797EBB7E1}
                  O42 - Logiciel: CCleaner - (.Piriform.) [HKLM][64Bits] -- CCleaner =>Piriform Ltd
                  O42 - Logiciel: Cisco Powerline AV Utility - (.Cisco Systems.) [HKLM][64Bits] -- {586A0CC4-E9A2-432B-8ACD-C398F1D94E63}
                  O42 - Logiciel: Convert FLV to MP3 - (.convertflvtomp3.com.) [HKLM][64Bits] -- {0B026E2A-3026-4608-A1B9-03AD1C8CDF77}_is1
                  O42 - Logiciel: D3DX10 - (.Microsoft.) [HKLM][64Bits] -- {E09C4DB7-630C-4F06-A631-8EA7239923AF}
                  O42 - Logiciel: Defraggler - (.Piriform.) [HKLM][64Bits] -- Defraggler
                  O42 - Logiciel: ETDWare PS/2-X64 8.0.5.0_WHQL - (.ELAN Microelectronic Corp..) [HKLM][64Bits] -- Elantech
                  O42 - Logiciel: Extended Asian Language font pack for Adobe Reader XI - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {AC76BA86-7AD7-2530-0000-A00000000004}
                  O42 - Logiciel: Far Cry 2 - (.Ubisoft.) [HKLM][64Bits] -- {F2835483-37F2-4123-B4FE-0E77D58447F2}
                  O42 - Logiciel: Fast Boot - (.ASUS.) [HKLM][64Bits] -- {13F4A7F3-EABC-4261-AF6B-1317777F0755}
                  O42 - Logiciel: FileHippo.com Update Checker - (...) [HKLM][64Bits] -- FileHippo.com
                  O42 - Logiciel: FormatFactory 3.0.1 - (.Free Time.) [HKLM][64Bits] -- FormatFactory
                  O42 - Logiciel: Futuremark SystemInfo - (.Futuremark Corporation.) [HKLM][64Bits] -- {BEE64C14-BEF1-4610-8A68-A16EAA47B882}
                  O42 - Logiciel: Galerie de photos - (.Microsoft Corporation.) [HKLM][64Bits] -- {F4D99A13-F63A-4FC1-8799-CFFDB78DDFB3}
                  O42 - Logiciel: Google Chrome - (.Google Inc..) [HKLM][64Bits] -- Google Chrome
                  O42 - Logiciel: Google Toolbar for Internet Explorer - (.Google Inc..) [HKLM][64Bits] -- {18455581-E099-4BA8-BC6B-F34B2F06600C} =>Toolbar.Google
                  O42 - Logiciel: Google Toolbar for Internet Explorer - (.Google Inc..) [HKLM][64Bits] -- {2318C2B1-4965-11d4-9B18-009027A5CD4F} =>Toolbar.Google
                  O42 - Logiciel: HP Photo Creations - (.HP.) [HKLM][64Bits] -- HP Photo Creations
                  O42 - Logiciel: HP Photosmart 5520 series Aide - (.Hewlett Packard.) [HKLM][64Bits] -- {CB08AF0F-D14B-4570-83CD-2567CE63CC5F}
                  O42 - Logiciel: HP Update - (.Hewlett-Packard.) [HKLM][64Bits] -- {6F1C00D2-25C2-4CBA-8126-AE9A6E2E9CD5}
                  O42 - Logiciel: Intel(R) Control Center - (.Intel Corporation.) [HKLM][64Bits] -- {F8A9085D-4C7A-41a9-8A77-C8998A96C421}
                  O42 - Logiciel: Intel(R) Management Engine Components - (.Intel Corporation.) [HKLM][64Bits] -- {65153EA5-8B6E-43B6-857B-C6E4FC25798A}
                  O42 - Logiciel: Intel(R) Processor Graphics - (.Intel Corporation.) [HKLM][64Bits] -- {F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}
                  O42 - Logiciel: Intel(R) Rapid Storage Technology - (.Intel Corporation.) [HKLM][64Bits] -- {409CB30E-E457-4008-9B1A-ED1B9EA21140}
                  O42 - Logiciel: Intel(R) Rapid Storage Technology - (.Intel Corporation.) [HKLM][64Bits] -- {93F692D4-0C4D-4EED-9BFE-657C1D5959FE}
                  O42 - Logiciel: Intel(R) SDK for OpenCL - CPU Only Runtime Package - (.Intel Corporation.) [HKLM][64Bits] -- {FCB3772C-B7D0-4933-B1A9-3707EBACC573}
                  O42 - Logiciel: Intel® Trusted Connect Service Client - (.Intel Corporation.) [HKLM][64Bits] -- {44B72151-611E-429D-9765-9BA093D7E48A}
                  O42 - Logiciel: Java 7 Update 25 - (.Oracle.) [HKLM][64Bits] -- {26A24AE4-039D-4CA4-87B4-2F83217025FF}
                  O42 - Logiciel: Java 7 Update 40 (64-bit) - (.Oracle.) [HKLM][64Bits] -- {26A24AE4-039D-4CA4-87B4-2F86417040FF}
                  O42 - Logiciel: Junk Mail filter update - (.Microsoft Corporation.) [HKLM][64Bits] -- {F6F30C28-38AA-4DBA-AE0B-7E30238E61BB}
                  O42 - Logiciel: Le testament de Sherlock Holmes - (.Focus Home Interactive.) [HKLM][64Bits] -- {38A96559-FF39-4089-A609-BFD76C4A6C07}_is1
                  O42 - Logiciel: Logiciel de base du périphérique HP Photosmart 5520 series - (.Hewlett-Packard Co..) [HKLM][64Bits] -- {97104D7C-FAC1-40A2-A34D-7950424FAEDE} =>.Hewlett-Packard Co
                  O42 - Logiciel: MSVCRT - (.Microsoft.) [HKLM][64Bits] -- {8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}
                  O42 - Logiciel: MSVCRT110 - (.Microsoft.) [HKLM][64Bits] -- {8E14DDC8-EA60-4E18-B3E3-1937104D5BDA}
                  O42 - Logiciel: MSVCRT110_amd64 - (.Microsoft.) [HKLM][64Bits] -- {E9FA781F-3E80-4399-825A-AD3E11C28C77}
                  O42 - Logiciel: MSVCRT_amd64 - (.Microsoft.) [HKLM][64Bits] -- {D0B44725-3666-492D-BEF6-587A14BD9BD9}
                  O42 - Logiciel: Ma-Config.com (64 bits) - (.Cybelsoft.) [HKLM][64Bits] -- {2D5F92C8-4CF7-4E02-A5A8-2E1DBD8CECD8}
                  O42 - Logiciel: MadOnion.com/3DMark2001 SE - (...) [HKLM][64Bits] -- {91B323B5-A79C-4D23-BD6D-046C565F9BCF}
                  O42 - Logiciel: Malwarebytes Anti-Malware version 1.75.0.1300 - (.Malwarebytes Corporation.) [HKLM][64Bits] -- Malwarebytes' Anti-Malware_is1
                  O42 - Logiciel: Medal of Honor (TM) - (.Electronic Arts.) [HKLM][64Bits] -- {415030B8-3E8B-462A-8C03-41D95AA3AB3B}
                  O42 - Logiciel: MiPony 2.1.0 - (...) [HKLM][64Bits] -- MiPony
                  O42 - Logiciel: Microsoft Antimalware Service FR-FR Language Pack - (.Microsoft Corporation.) [HKLM][64Bits] -- {32E9C1A5-0FDA-4483-987D-DBABF9CC1DD8}
                  O42 - Logiciel: Microsoft Security Client - (.Microsoft Corporation.) [HKLM][64Bits] -- {27726449-83B8-428D-92DE-101346C1E15C}
                  O42 - Logiciel: Microsoft Security Client FR-FR Language Pack - (.Microsoft Corporation.) [HKLM][64Bits] -- {DC911ADF-7B60-40F2-A112-FB1EB6402D07}
                  O42 - Logiciel: Microsoft Security Essentials - (.Microsoft Corporation.) [HKLM][64Bits] -- Microsoft Security Client
                  O42 - Logiciel: Microsoft Silverlight - (.Microsoft Corporation.) [HKLM][64Bits] -- {89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
                  O42 - Logiciel: Microsoft SkyDrive - (.Microsoft Corporation.) [HKCU][64Bits] -- SkyDriveSetup.exe =>.Microsoft Corporation
                  O42 - Logiciel: Mises à jour NVIDIA 1.11.3 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update
                  O42 - Logiciel: Moniteur de la technologie Intel® Turbo Boost - (.Intel.) [HKLM][64Bits] -- {39F4C6F9-618A-4E5B-8FB2-6BD661174E32}
                  O42 - Logiciel: NVIDIA Drivers - (.NVIDIA Corporation.) [HKLM][64Bits] -- NVIDIA Drivers
                  O42 - Logiciel: NVIDIA PhysX - (.NVIDIA Corporation.) [HKLM][64Bits] -- {64467D47-FFE4-4FBC-ABBA-A0DB829A17EB}
                  O42 - Logiciel: NVIDIA Pilote audio HD : 1.1.13.1 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver
                  O42 - Logiciel: NVIDIA Pilote graphique 268.56 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver
                  O42 - Logiciel: Package de pilotes Windows - Fedict SmartCard (10/04/2011 4.0.0.5) - (.Fedict.) [HKLM][64Bits] -- 3FE3642036A0F4AEC17772437CE14BB1E67006AA
                  O42 - Logiciel: PunkBuster Services - (.Even Balance, Inc..) [HKLM][64Bits] -- PunkBusterSvc
                  O42 - Logiciel: Realtek Ethernet Controller Driver - (.Realtek.) [HKLM][64Bits] -- {8833FFB6-5B0C-4764-81AA-06DFEED9A476}
                  O42 - Logiciel: Realtek High Definition Audio Driver - (.Realtek Semiconductor Corp..) [HKLM][64Bits] -- {F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}
                  O42 - Logiciel: Realtek USB 2.0 Reader Driver - (.Realtek Semiconductor Corp..) [HKLM][64Bits] -- {62BBB2F0-E220-4821-A564-730807D2C34D}
                  O42 - Logiciel: Sawbuck - (.Google Inc.) [HKLM][64Bits] -- {459BFE07-FCF3-4274-AC8B-8E8DDA7214BA}
                  O42 - Logiciel: SiSoftware Sandra Lite 2011 - (.SiSoftware.) [HKLM][64Bits] -- {C3113E55-7BCB-4de3-8EBF-60E6CE6B2296}_is1
                  O42 - Logiciel: Skype(TM) 6.3 - (.Skype Technologies S.A..) [HKLM][64Bits] -- {4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}
                  O42 - Logiciel: Tweaking.com - Windows Repair (All in One) - (.Tweaking.com.) [HKLM][64Bits] -- Tweaking.com - Windows Repair (All in One)
                  O42 - Logiciel: VLC media player 2.0.7 - (.VideoLAN.) [HKLM][64Bits] -- VLC media player =>.VideoLAN
                  O42 - Logiciel: VLC media player 2.0.8 - (.VideoLAN.) [HKLM][64Bits] -- VLC media player =>.VideoLAN
                  O42 - Logiciel: VirtualCloneDrive - (.Elaborate Bytes.) [HKLM][64Bits] -- VirtualCloneDrive
                  O42 - Logiciel: VirtualDJ PRO Full - (.Atomix Productions.) [HKLM][64Bits] -- {4769E972-2E92-49C5-B6F9-465EFD0C4D94}
                  O42 - Logiciel: Voobys - (.Voobys.) [HKLM][64Bits] -- {24EF2EDA-1224-4D3C-9C67-B45AF0C1D056}
                  O42 - Logiciel: WIKO CINK PEAX Drivers - (.WIKO.) [HKLM][64Bits] -- {1F7579EC-B217-4ABB-8E0C-17A3BC6CB5CF}
                  O42 - Logiciel: WahOO - (...) [HKLM][64Bits] -- {0271A4CB-D48C-4CDF-826F-62EE8D91663F}_is1
                  O42 - Logiciel: WinFlash - (.ASUS.) [HKLM][64Bits] -- {8F21291E-0444-4B1D-B9F9-4370A73E346D}
                  O42 - Logiciel: WinRAR 4.20 (32-bit) - (.win.rar GmbH.) [HKLM][64Bits] -- WinRAR archiver
                  O42 - Logiciel: WinRAR 5.00 (64-bit) - (.win.rar GmbH.) [HKLM][64Bits] -- WinRAR archiver
                  O42 - Logiciel: Wireless Console 3 - (.ASUS.) [HKLM][64Bits] -- {20FDF948-C8ED-4543-A539-F7F4AEF5AFA2}
                  O42 - Logiciel: µTorrent - (.BitTorrent Inc..) [HKLM][64Bits] -- uTorrent =>P2P.BitTorrent
                  O42 - Logiciel: Étude pour l'amélioration du produit HP Photosmart 5520 series - (.Hewlett-Packard Co..) [HKLM][64Bits] -- {DC2D49CF-2452-4191-A18C-41F1C02A7228}
                  ~ Logic: 154 Scanned in 00mn 00s

                  ---\\ HKCU & HKLM Software Keys
                  [HKCU\Software\ASUS]
                  [HKCU\Software\ATI]
                  [HKCU\Software\ATK0100]
                  [HKCU\Software\Adobe]
                  [HKCU\Software\AppDataLow\Aurigma]
                  [HKCU\Software\AppDataLow\Software\JavaSoft]
                  [HKCU\Software\AppDataLow]
                  [HKCU\Software\Atheros]
                  [HKCU\Software\BEID]
                  [HKCU\Software\BitTorrent] =>P2P.BitTorrent
                  [HKCU\Software\Bitdefender]
                  [HKCU\Software\Cisco]
                  [HKCU\Software\Classes]
                  [HKCU\Software\Clients]
                  [HKCU\Software\DT Soft]
                  [HKCU\Software\Elaborate Bytes]
                  [HKCU\Software\Elantech]
                  [HKCU\Software\Electronic Arts]
                  [HKCU\Software\FOCUS]
                  [HKCU\Software\File Helper]
                  [HKCU\Software\FileHippo.com]
                  [HKCU\Software\FreeTime]
                  [HKCU\Software\Futuremark]
                  [HKCU\Software\GNU]
                  [HKCU\Software\Gabest]
                  [HKCU\Software\Ghisler]
                  [HKCU\Software\Google]
                  [HKCU\Software\HP]
                  [HKCU\Software\Haali]
                  [HKCU\Software\Hewlett-Packard]
                  [HKCU\Software\IM Providers]
                  [HKCU\Software\Intel]
                  [HKCU\Software\JavaSoft]
                  [HKCU\Software\KowMedia]
                  [HKCU\Software\Licenses]
                  [HKCU\Software\LogiShrd]
                  [HKCU\Software\Macromedia]
                  [HKCU\Software\Malwarebytes' Anti-Malware]
                  [HKCU\Software\Mobile Action]
                  [HKCU\Software\MozillaPlugins]
                  [HKCU\Software\NVIDIA Corporation]
                  [HKCU\Software\NetifCfgStore]
                  [HKCU\Software\Netscape]
                  [HKCU\Software\ODBC]
                  [HKCU\Software\Piriform]
                  [HKCU\Software\Policies]
                  [HKCU\Software\Realtek]
                  [HKCU\Software\Safer Networking Limited]
                  [HKCU\Software\Skype]
                  [HKCU\Software\Sysinternals]
                  [HKCU\Software\Trolltech]
                  [HKCU\Software\VirtualDJ]
                  [HKCU\Software\Visan]
                  [HKCU\Software\Voobys]
                  [HKCU\Software\WahOO]
                  [HKCU\Software\WinRAR SFX]
                  [HKCU\Software\WinRAR]
                  [HKCU\Software\Wow6432Node]
                  [HKCU\Software\ZebHelpProcess Helper]
                  [HKCU\Software\mozilla]
                  [HKLM\Software\7-Zip]
                  [HKLM\Software\AGEIA Technologies]
                  [HKLM\Software\AMD]
                  [HKLM\Software\ASUS]
                  [HKLM\Software\ATHEROS]
                  [HKLM\Software\ATI Technologies]
                  [HKLM\Software\ATK0100]
                  [HKLM\Software\BrowserChoice]
                  [HKLM\Software\Classes]
                  [HKLM\Software\Clients]
                  [HKLM\Software\DTS]
                  [HKLM\Software\Dolby]
                  [HKLM\Software\File Helper]
                  [HKLM\Software\Ghisler]
                  [HKLM\Software\HP]
                  [HKLM\Software\IM Providers]
                  [HKLM\Software\Intel]
                  [HKLM\Software\JavaSoft]
                  [HKLM\Software\Khronos]
                  [HKLM\Software\Logishrd]
                  [HKLM\Software\Macromedia]
                  [HKLM\Software\Medal of Honor]
                  [HKLM\Software\MozillaPlugins]
                  [HKLM\Software\NVIDIA Corporation]
                  [HKLM\Software\ODBC]
                  [HKLM\Software\Piriform]
                  [HKLM\Software\Policies]
                  [HKLM\Software\RTLSetup]
                  [HKLM\Software\Realtek Semiconductor Corp.]
                  [HKLM\Software\Realtek]
                  [HKLM\Software\RegisteredApplications]
                  [HKLM\Software\SRS Labs]
                  [HKLM\Software\SiSoftware]
                  [HKLM\Software\SonicFocus]
                  [HKLM\Software\Sonic]
                  [HKLM\Software\VideoLAN]
                  [HKLM\Software\Volatile]
                  [HKLM\Software\Waves Audio]
                  [HKLM\Software\WidCommUpdate]
                  [HKLM\Software\WinRAR]
                  [HKLM\Software\Windows]
                  [HKLM\Software\Wow6432Node\AGEIA Technologies]
                  [HKLM\Software\Wow6432Node\AMD]
                  [HKLM\Software\Wow6432Node\ASUS]
                  [HKLM\Software\Wow6432Node\ATI Technologies]
                  [HKLM\Software\Wow6432Node\Adobe]
                  [HKLM\Software\Wow6432Node\AdwCleaner]
                  [HKLM\Software\Wow6432Node\AsLdr]
                  [HKLM\Software\Wow6432Node\Atheros]
                  [HKLM\Software\Wow6432Node\AviSynth]
                  [HKLM\Software\Wow6432Node\BEID]
                  [HKLM\Software\Wow6432Node\Bunndle]
                  [HKLM\Software\Wow6432Node\Cisco Systems]
                  [HKLM\Software\Wow6432Node\City Interactive]
                  [HKLM\Software\Wow6432Node\Classes]
                  [HKLM\Software\Wow6432Node\Clients]
                  [HKLM\Software\Wow6432Node\DT Soft]
                  [HKLM\Software\Wow6432Node\Elaborate Bytes]
                  [HKLM\Software\Wow6432Node\Electronic Arts]
                  [HKLM\Software\Wow6432Node\Even Balance]
                  [HKLM\Software\Wow6432Node\Frogwares]
                  [HKLM\Software\Wow6432Node\Futuremark Corporation]
                  [HKLM\Software\Wow6432Node\Futuremark]
                  1. Contributeur sécurité
                    Bonsoir,
                    D'accord! :-)
                    Lance ZHPDiag depuis le bureau,ensuite coche tout au tournevis (aide ici) puis lance l'analyse, ferme le et héberge le rapport. colle le lien dans ta prochaine réponse

                    @+
                    1. voila fish
                      Malwarebytes Anti-Malware (PRO) 1.75.0.1300
                      www.malwarebytes.org

                      Version de la base de données: v2013.09.21.10

                      Windows 7 Service Pack 1 x64 NTFS
                      Internet Explorer 10.0.9200.16686
                      marc :: MARC-PC [administrateur]

                      Protection: Activé

                      22/09/2013 18:53:52
                      mbam-log-2013-09-22 (18-53-52).txt

                      Type d'examen: Examen complet (C:\|F:\|Q:\|)
                      Options d'examen activées: Mémoire | Démarrage | Registre | Système de fichiers | Heuristique/Extra | Heuristique/Shuriken | PUP | PUM
                      Options d'examen désactivées: P2P
                      Elément(s) analysé(s): 504708
                      Temps écoulé: 1 heure(s), 29 minute(s), 1 seconde(s)

                      Processus mémoire détecté(s): 0
                      (Aucun élément nuisible détecté)

                      Module(s) mémoire détecté(s): 0
                      (Aucun élément nuisible détecté)

                      Clé(s) du Registre détectée(s): 0
                      (Aucun élément nuisible détecté)

                      Valeur(s) du Registre détectée(s): 0
                      (Aucun élément nuisible détecté)

                      Elément(s) de données du Registre détecté(s): 0
                      (Aucun élément nuisible détecté)

                      Dossier(s) détecté(s): 0
                      (Aucun élément nuisible détecté)

                      Fichier(s) détecté(s): 0
                      (Aucun élément nuisible détecté)

                      (fin)
                      1. fish,
                        voici malware que j'avais fait au matin,
                        Malwarebytes Anti-Malware (PRO) 1.75.0.1300
                        www.malwarebytes.org

                        Version de la base de données: v2013.09.21.10

                        Windows 7 Service Pack 1 x64 NTFS
                        Internet Explorer 10.0.9200.16686
                        marc :: MARC-PC [administrateur]

                        Protection: Activé

                        22/09/2013 09:15:21
                        mbam-log-2013-09-22 (09-15-21).txt

                        Type d'examen: Examen complet (C:\|F:\|Q:\|)
                        Options d'examen activées: Mémoire | Démarrage | Registre | Système de fichiers | Heuristique/Extra | Heuristique/Shuriken | PUP | PUM
                        Options d'examen désactivées: P2P
                        Elément(s) analysé(s): 514305
                        Temps écoulé: 2 heure(s), 5 minute(s), 51 seconde(s)

                        Processus mémoire détecté(s): 0
                        (Aucun élément nuisible détecté)

                        Module(s) mémoire détecté(s): 0
                        (Aucun élément nuisible détecté)

                        Clé(s) du Registre détectée(s): 0
                        (Aucun élément nuisible détecté)

                        Valeur(s) du Registre détectée(s): 0
                        (Aucun élément nuisible détecté)

                        Elément(s) de données du Registre détecté(s): 0
                        (Aucun élément nuisible détecté)

                        Dossier(s) détecté(s): 0
                        (Aucun élément nuisible détecté)

                        Fichier(s) détecté(s): 0
                        (Aucun élément nuisible détecté)

                        (fin)
                        1. Contributeur sécurité
                          Salut,
                          Rapport mbam : 22/09/2013 09:15:21
                          Rapport RogueKiller : 09/22/2013 11:24:53
                          Je veux le rapport de mbam juste après voir passé RogueKiller, relance le (mbam) puis poste le rapport stp
                      2. Contributeur sécurité
                        Bien!
                        -----------------
                        Lance Malwarebytes, fais la mise à jour, choisis une analyse complète, supprime tout ce qu'il trouve puis poste le rapport stp

                        @+
                        1. Bonjour fish
                          RogueKiller V8.6.12 _x64_ [Sep 18 2013] par Tigzy
                          mail : tigzyRK<at>gmail<dot>com
                          Remontees : http://www.adlice.com/forum/
                          Site Web : https://www.luanagames.com/index.fr.html
                          Blog : http://tigzyrk.blogspot.com/

                          Systeme d'exploitation : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
                          Demarrage : Mode normal
                          Utilisateur : marc [Droits d'admin]
                          Mode : Suppression -- Date : 09/22/2013 11:24:53
                          | ARK || FAK || MBR |

                          ¤¤¤ Processus malicieux : 0 ¤¤¤

                          ¤¤¤ Entrees de registre : 0 ¤¤¤

                          ¤¤¤ Tâches planifiées : 0 ¤¤¤

                          ¤¤¤ Entrées Startup : 0 ¤¤¤

                          ¤¤¤ Navigateurs web : 0 ¤¤¤

                          ¤¤¤ Fichiers / Dossiers particuliers: ¤¤¤

                          ¤¤¤ Driver : [NON CHARGE 0x0] ¤¤¤

                          ¤¤¤ Ruches Externes: ¤¤¤

                          ¤¤¤ Infection : ¤¤¤

                          ¤¤¤ Fichier HOSTS: ¤¤¤
                          --> %SystemRoot%\System32\drivers\etc\hosts

                          127.0.0.1 localhost

                          ¤¤¤ MBR Verif: ¤¤¤

                          +++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ IDE) (Lecteurs de disque standard) - WDC WD5000BPVT-24HXZ SCSI Disk Device +++++
                          --- User ---
                          [MBR] 64c77b42075fe9305be41772eb7333fd
                          [BSP] 92c323c5964c29d84c3314d60f2d6375 : Legit.C MBR Code
                          Partition table:
                          0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 476937 Mo
                          User = LL1 ... OK!
                          User = LL2 ... OK!

                          +++++ PhysicalDrive1: (\\.\PHYSICALDRIVE1 @ USB) (Lecteurs de disque standard) - CBM Flash Disk USB Device +++++
                          --- User ---
                          [MBR] 718ce2700a8382007568b2c6c5a1ed48
                          [BSP] 3127057f9a764b7b67f4452ae18bdc09 : Empty MBR Code
                          Partition table:
                          0 - [ACTIVE] FAT16 (0x06) [VISIBLE] Offset (sectors): 32 | Size: 1006 Mo
                          User = LL1 ... OK!
                          Error reading LL2 MBR!

                          Termine : << RKreport[0]_D_09222013_112453.txt >>
                          RKreport[0]_S_09222013_092458.txt;RKreport[0]_S_09222013_092701.txt;RKreport[0]_S_09222013_112437.txt

                          RogueKiller V8.6.12 _x64_ [Sep 18 2013] par Tigzy
                          mail : tigzyRK<at>gmail<dot>com
                          Remontees : http://www.adlice.com/forum/
                          Site Web : https://www.luanagames.com/index.fr.html
                          Blog : http://tigzyrk.blogspot.com/

                          Systeme d'exploitation : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
                          Demarrage : Mode normal
                          Utilisateur : marc [Droits d'admin]
                          Mode : HOSTS RAZ -- Date : 09/22/2013 11:25:53
                          | ARK || FAK || MBR |

                          ¤¤¤ Processus malicieux : 0 ¤¤¤

                          ¤¤¤ Entrees de registre : 0 ¤¤¤

                          ¤¤¤ Driver : [NON CHARGE 0x0] ¤¤¤

                          ¤¤¤ Ruches Externes: ¤¤¤

                          ¤¤¤ Infection : ¤¤¤

                          ¤¤¤ Fichier HOSTS: ¤¤¤
                          --> %SystemRoot%\System32\drivers\etc\hosts

                          127.0.0.1 localhost

                          ¤¤¤ Nouveau fichier HOSTS: ¤¤¤
                          127.0.0.1 localhost

                          Termine : << RKreport[0]_H_09222013_112553.txt >>
                          RKreport[0]_D_09222013_112453.txt;RKreport[0]_S_09222013_092458.txt;RKreport[0]_S_09222013_092701.txt
                          RKreport[0]_S_09222013_112437.txt
                          1. Contributeur sécurité
                            Bonjour,
                            Relance RogueKiller puis choisis "Suppression", ensuite Proxy RAZ et enfin Host RAZ
                            Poste les trois rapports correspondants à ces 3 options stp
                            -------------------------
                            <<<<<<<< AIDE ICI >>>>>>>>

                            @+
                            1. voici
                              RogueKiller V8.6.12 _x64_ [Sep 18 2013] par Tigzy
                              mail : tigzyRK<at>gmail<dot>com
                              Remontees : http://www.adlice.com/forum/
                              Site Web : https://www.luanagames.com/index.fr.html
                              Blog : http://tigzyrk.blogspot.com/

                              Systeme d'exploitation : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
                              Demarrage : Mode normal
                              Utilisateur : marc [Droits d'admin]
                              Mode : Recherche -- Date : 09/21/2013 22:46:36
                              | ARK || FAK || MBR |

                              ¤¤¤ Processus malicieux : 1 ¤¤¤
                              [SUSP PATH] Wahoo.exe -- C:\Users\marc\AppData\Local\WahOO\Wahoo.exe [7] -> TUÉ [TermProc]

                              ¤¤¤ Entrees de registre : 5 ¤¤¤
                              [RUN][SUSP PATH] HKCU\[...]\Run : Wahoo (C:\Users\marc\AppData\Local\WahOO\Wahoo.exe -a [7]) -> TROUVÉ
                              [RUN][SUSP PATH] HKUS\S-1-5-21-882527398-2222475609-3722137400-1001\[...]\Run : Wahoo (C:\Users\marc\AppData\Local\WahOO\Wahoo.exe -a [7]) -> TROUVÉ
                              [PROXY IE][PUM] HKCU\[...]\Internet Settings : ProxyServer (:0) -> TROUVÉ
                              [HJ DESK][PUM] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> TROUVÉ
                              [HJ DESK][PUM] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> TROUVÉ

                              ¤¤¤ Tâches planifiées : 0 ¤¤¤

                              ¤¤¤ Entrées Startup : 0 ¤¤¤

                              ¤¤¤ Navigateurs web : 0 ¤¤¤

                              ¤¤¤ Fichiers / Dossiers particuliers: ¤¤¤

                              ¤¤¤ Driver : [NON CHARGE 0x0] ¤¤¤

                              ¤¤¤ Ruches Externes: ¤¤¤

                              ¤¤¤ Infection : ¤¤¤

                              ¤¤¤ Fichier HOSTS: ¤¤¤
                              --> %SystemRoot%\System32\drivers\etc\hosts

                              127.0.0.1 www.007guard.com
                              127.0.0.1 007guard.com
                              127.0.0.1 008i.com
                              127.0.0.1 www.008k.com
                              127.0.0.1 008k.com
                              127.0.0.1 www.00hq.com
                              127.0.0.1 00hq.com
                              127.0.0.1 010402.com
                              127.0.0.1 www.032439.com
                              127.0.0.1 032439.com
                              127.0.0.1 www.0scan.com
                              127.0.0.1 0scan.com
                              127.0.0.1 1000gratisproben.com
                              127.0.0.1 www.1000gratisproben.com
                              127.0.0.1 1001namen.com
                              127.0.0.1 www.1001namen.com
                              127.0.0.1 100888290cs.com
                              127.0.0.1 www.100888290cs.com
                              127.0.0.1 www.100sexlinks.com
                              127.0.0.1 100sexlinks.com
                              [...]

                              ¤¤¤ MBR Verif: ¤¤¤

                              +++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ IDE) (Lecteurs de disque standard) - WDC WD5000BPVT-24HXZ SCSI Disk Device +++++
                              --- User ---
                              [MBR] 64c77b42075fe9305be41772eb7333fd
                              [BSP] 92c323c5964c29d84c3314d60f2d6375 : Legit.C MBR Code
                              Partition table:
                              0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 476937 Mo
                              User = LL1 ... OK!
                              User = LL2 ... OK!

                              +++++ PhysicalDrive1: (\\.\PHYSICALDRIVE1 @ USB) (Lecteurs de disque standard) - CBM Flash Disk USB Device +++++
                              --- User ---
                              [MBR] 718ce2700a8382007568b2c6c5a1ed48
                              [BSP] 3127057f9a764b7b67f4452ae18bdc09 : Empty MBR Code
                              Partition table:
                              0 - [ACTIVE] FAT16 (0x06) [VISIBLE] Offset (sectors): 32 | Size: 1006 Mo
                              User = LL1 ... OK!
                              Error reading LL2 MBR!

                              Termine : << RKreport[0]_S_09212013_224636.txt >>
                              1. Contributeur sécurité
                                Il existe des infections à supprimer :
                                * Télécharge sur le bureau RogueKiller (par tigzy)
                                https://www.luanagames.com/index.fr.html

                                * ( Sous Vista/Seven,clique droit, lancer en tant qu'administrateur )
                                * Quitte tous tes programmes en cours
                                * Lance RogueKiller.exe

                                Si l'infection bloque le programme, il faut le relancer plusieurs fois ou le renommer en winlogon.exe

                                * Laisse le prescan se terminer, clique sur Scan

                                * Clique sur Rapport pour l'ouvrir puis copie/colle le sur le dans ton prochain message

                                A demain

                                Bonne nuit

                                ¤¤¤ Le meilleur remède pour tous les problèmes, c'est la patience.... ¤¤¤
                                • 1
                                • 2
                                • 3