Bonjour à tous,

Je suis sous Windows 7 et j'ai du téléchargé une connerie car à chaque onglet, j'ai "toolbar:new_tab.html" et non pas google comme je le demande à chaque fois. Je n'ai pas vraiment à trouver l'aide adéquate en faisant une recherche par mots clés aussi bien sur le forum que sur le net.

J'ai lancé ccleaner.

Quelqu'un pourrait-il m'aider ? Merci mille fois !

Modifié par klykoo




1) Télécharge AdwCleaner par Xplode: ©©chargements - Outils de Xplode - AdwCleaner


Enregistre-le sur le bureau (et pas ailleurs).


Si tu es sous XP double clique sur AdwCleaner pour lancer l'outil.

Si tu es sous Vista/Seven, clique droit sur AdwCleaner et choisis exécuter en temps qu'administrateur.


Clique sur Suppression et laisse travailler l'outil.


Le rapport va s'ouvrir en fichier texte; copie la totalité de son contenu et colle-le dans ta réponse.


Le rapport est en outre sauvegardé sous C:\AdwCleaner[s1]


NB: Si l'outil "cale" en mode normal, le lancer en mode sans échec: Comment démarrer Windows en mode sans échec : Astuces pour Dépanner Windows XP




2) ZHPDiag :


  • Télécharge ZHPDiag de Nicolas Coolman. et enregistre-le sur le BUREAU.
  • Double-clique sur ZHPDiag.exe pour lancer l'installation
    • Important:
      Sous Vista et Windows 7 : il faut lancer le fichier par clic-droit -> Exécuter en tant qu'administrateur

N'oublie pas de cocher la case qui permet de mettre un raccourci sur le Bureau.


[*]L'outil a créé 2 icônes ZHPDiag et ZHPFix sur le Bureau.


[*]Double-clique sur ZHPDiag pour lancer l'exécution

  • Important:
    Sous Vista et Windows 7 : il faut lancer le fichier par clic-droit -> Exécuter en tant qu'administrateur


[*]Clique sur le petit tournevis tournevis.jpg et clique sur TOUS.


Décocher 045 et 061.


[*]Clique sur la loupe loupe-334dd63.png pour lancer l'analyse. Tu patientes jusqu'à ce que le scan affiche 100%

Tu refermes ZHPDiag


[*]Le rapport ZHPDiag.txt se trouve sur le Bureau. (et sous c:\ZHP\ZHPDiag.txt)

Ce rapport étant trop long pour le forum, héberge le :




Posté(e) (modifié)

Allo Appollo,

Le téléchargement par le lien que tu me proposes est bloqué par le filtre SmartScreen ...

EDIT: bon j'ai vu qu'il y avait un petit passage concernant ce bloquage ... je m'en vais donc le lire :)

Modifié par klykoo

Désactive le SmartScreen, tu le réactiveras plus tard si nécessaire; moi je l'ai désactivé définitivement, il bloque tous les outils ce c**-là :lol






Encore faut-il que je sache comment désactiver le filtre smartscreen ... Je n'ai aps forcément acces au bouton "action" :S


Alors voici les rapports, c'est grave Docteur ???


- Hijackthis

Lien BJrqhR5s9vs


- ADWCleaner

---\\ HKCU & HKLM Software Keys




[HKCU\Software\Adobe Lightroom]






[HKCU\Software\Apple Computer, Inc.]

[HKCU\Software\Apple Inc.]


[HKCU\Software\Avast Software]
















[HKCU\Software\Malwarebytes' Anti-Malware]

[HKCU\Software\Media Player - Codec Pack]



[HKCU\Software\NVIDIA Corporation]








[HKCU\Software\Safer Networking Limited]





[HKCU\Software\VB and VBA Program Settings]

[HKCU\Software\WinRAR SFX]


[HKCU\Software\Windows Live Writer]


[HKCU\Software\ZebHelpProcess Helper]





[HKLM\Software\ATI Technologies]


[HKLM\Software\Apple Computer, Inc.]

[HKLM\Software\Apple Inc.]






[HKLM\Software\GEAR Software]









[HKLM\Software\NVIDIA Corporation]





[HKLM\Software\Realtek Semiconductor Corp.]



[HKLM\Software\SRS Labs]





[HKLM\Software\Waves Audio]


[HKLM\Software\Wow6432Node\AVAST Software]



[HKLM\Software\Wow6432Node\Apple Computer, Inc.]

[HKLM\Software\Wow6432Node\Apple Inc.]















[HKLM\Software\Wow6432Node\Malwarebytes' Anti-Malware (Trial)]

[HKLM\Software\Wow6432Node\Malwarebytes' Anti-Malware]



[HKLM\Software\Wow6432Node\NVIDIA Corporation]


[HKLM\Software\Wow6432Node\Oberon Media]



[HKLM\Software\Wow6432Node\Realtek Semiconductor Corp.]



[HKLM\Software\Wow6432Node\Safer Networking Limited]











~ Scan Softwares in 00mn 01s




---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43)

O43 - CFD: 17/10/2012 - 11:13:55 - [114,758] ----D C:\Program Files (x86)\Adobe

O43 - CFD: 09/08/2012 - 08:44:02 - [9,472] ----D C:\Program Files (x86)\

O43 - CFD: 12/09/2012 - 09:32:23 - [2,316] ----D C:\Program Files (x86)\Apple Software Update

O43 - CFD: 31/07/2012 - 15:56:28 - [525,147] ----D C:\Program Files (x86)\ASUS

O43 - CFD: 19/04/2012 - 18:24:44 - [47,523] ----D C:\Program Files (x86)\Atheros

O43 - CFD: 12/09/2012 - 09:31:37 - [0,602] ----D C:\Program Files (x86)\Bonjour

O43 - CFD: 17/10/2012 - 11:16:44 - [443,163] ----D C:\Program Files (x86)\Common Files

O43 - CFD: 17/10/2012 - 07:41:18 - [677,301] ----D C:\Program Files (x86)\Google

O43 - CFD: 19/04/2012 - 18:29:36 - [169,832] --H-D C:\Program Files (x86)\InstallShield Installation Information

O43 - CFD: 19/04/2012 - 18:14:25 - [6,100] ----D C:\Program Files (x86)\Intel

O43 - CFD: 24/09/2012 - 07:35:12 - [7,105] ----D C:\Program Files (x86)\Internet Explorer

O43 - CFD: 14/10/2012 - 14:00:49 - [142,398] ----D C:\Program Files (x86)\iTunes

O43 - CFD: 17/10/2012 - 11:15:50 - [121,165] ----D C:\Program Files (x86)\Java

O43 - CFD: 17/10/2012 - 07:57:36 - [12,747] ----D C:\Program Files (x86)\Malwarebytes' Anti-Malware

O43 - CFD: 12/09/2012 - 11:01:49 - [0] ----D C:\Program Files (x86)\Microsoft

O43 - CFD: 03/08/2012 - 02:13:29 - [566,411] ----D C:\Program Files (x86)\Microsoft Office

O43 - CFD: 31/07/2012 - 16:19:03 - [36,641] ----D C:\Program Files (x86)\Microsoft Silverlight

O43 - CFD: 12/04/2011 - 22:42:56 - [1,745] ----D C:\Program Files (x86)\Microsoft SQL Server Compact Edition

O43 - CFD: 20/05/2012 - 08:47:54 - [0,014] ----D C:\Program Files (x86)\Microsoft Visual Studio

O43 - CFD: 20/05/2012 - 08:45:16 - [1,323] ----D C:\Program Files (x86)\Microsoft Visual Studio 8

O43 - CFD: 02/08/2012 - 03:42:02 - [3,554] ----D C:\Program Files (x86)\Microsoft Works

O43 - CFD: 20/05/2012 - 12:10:39 - [7,789] ----D C:\Program Files (x86)\Microsoft.NET

O43 - CFD: 16/10/2012 - 17:27:53 - [39,952] ----D C:\Program Files (x86)\Mozilla Firefox

O43 - CFD: 17/10/2012 - 09:49:10 - [0,212] ----D C:\Program Files (x86)\Mozilla Maintenance Service

O43 - CFD: 20/05/2012 - 08:47:58 - [0,025] ----D C:\Program Files (x86)\MSBuild

O43 - CFD: 19/04/2012 - 18:15:37 - [6,592] ----D C:\Program Files (x86)\NVIDIA Corporation

O43 - CFD: 12/09/2012 - 11:13:53 - [32,729] ----D C:\Program Files (x86)\PDFCreator

O43 - CFD: 19/04/2012 - 18:26:54 - [22,213] ----D C:\Program Files (x86)\Realtek

O43 - CFD: 14/07/2009 - 01:32:38 - [37,349] ----D C:\Program Files (x86)\Reference Assemblies

O43 - CFD: 26/08/2012 - 16:48:56 - [2,229] ----D C:\Program Files (x86)\RIFT Technologies

O43 - CFD: 17/10/2012 - 11:17:34 - [6,586] ----D C:\Program Files (x86)\Secunia

O43 - CFD: 31/07/2012 - 18:10:59 - [16,855] R---D C:\Program Files (x86)\Skype

O43 - CFD: 12/09/2012 - 10:59:04 - [4,372] ----D C:\Program Files (x86)\Spybot - Search & Destroy

O43 - CFD: 12/04/2011 - 22:49:28 - [161,465] ----D C:\Program Files (x86)\syncables

O43 - CFD: 04/08/2012 - 16:09:40 - [16,007] ----D C:\Program Files (x86)\TeamViewer

O43 - CFD: 19/04/2012 - 18:19:59 - [0] --H-D C:\Program Files (x86)\Temp

O43 - CFD: 17/10/2012 - 07:50:02 - [0,767] ----D C:\Program Files (x86)\trend micro

O43 - CFD: 14/07/2009 - 00:57:06 - [0] --H-D C:\Program Files (x86)\Uninstall Information

O43 - CFD: 17/09/2012 - 08:57:23 - [60,912] ----D C:\Program Files (x86)\Win7codecs

O43 - CFD: 20/05/2012 - 11:44:35 - [0,500] ----D C:\Program Files (x86)\Windows Defender

O43 - CFD: 12/04/2011 - 22:45:11 - [314,625] ----D C:\Program Files (x86)\Windows Live

O43 - CFD: 20/05/2012 - 11:44:36 - [5,895] ----D C:\Program Files (x86)\Windows Mail

O43 - CFD: 20/05/2012 - 11:44:35 - [4,791] ----D C:\Program Files (x86)\Windows Media Player

O43 - CFD: 14/07/2009 - 01:32:38 - [11,632] ----D C:\Program Files (x86)\Windows NT

O43 - CFD: 20/05/2012 - 11:44:35 - [4,213] ----D C:\Program Files (x86)\Windows Photo Viewer

O43 - CFD: 18/02/2011 - 16:09:10 - [0,181] ----D C:\Program Files (x86)\Windows Portable Devices

O43 - CFD: 20/05/2012 - 11:44:35 - [5,717] ----D C:\Program Files (x86)\Windows Sidebar

O43 - CFD: 17/10/2012 - 11:26:01 - [10,018] ----D C:\Program Files (x86)\ZHPDiag

O43 - CFD: 17/10/2012 - 11:14:02 - [6,224] ----D C:\Program Files (x86)\Common Files\Adobe

O43 - CFD: 14/10/2012 - 14:00:22 - [105,862] ----D C:\Program Files (x86)\Common Files\Apple

O43 - CFD: 19/04/2012 - 18:22:28 - [0,012] ----D C:\Program Files (x86)\Common Files\Atheros

O43 - CFD: 20/05/2012 - 08:47:54 - [0,089] ----D C:\Program Files (x86)\Common Files\DESIGNER

O43 - CFD: 19/04/2012 - 18:29:36 - [3,111] ----D C:\Program Files (x86)\Common Files\InstallShield

O43 - CFD: 19/04/2012 - 18:14:23 - [13,605] ----D C:\Program Files (x86)\Common Files\Intel

O43 - CFD: 17/10/2012 - 11:16:44 - [1,184] ----D C:\Program Files (x86)\Common Files\Java

O43 - CFD: 02/08/2012 - 03:42:08 - [229,227] ----D C:\Program Files (x86)\Common Files\microsoft shared

O43 - CFD: 12/04/2011 - 22:48:00 - [0,338] ----D C:\Program Files (x86)\Common Files\Oberon Media

O43 - CFD: 13/07/2009 - 23:20:08 - [0,003] ----D C:\Program Files (x86)\Common Files\Services

O43 - CFD: 31/07/2012 - 18:10:58 - [2,056] ----D C:\Program Files (x86)\Common Files\Skype

O43 - CFD: 13/07/2009 - 23:20:08 - [39,200] ----D C:\Program Files (x86)\Common Files\SpeechEngines

O43 - CFD: 03/08/2012 - 02:04:27 - [42,254] ----D C:\Program Files (x86)\Common Files\System

O43 - CFD: 12/04/2011 - 22:33:36 - [0] ----D C:\Program Files (x86)\Common Files\Windows Live

O43 - CFD: 14/10/2012 - 14:00:51 - [2,775] ----D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69

O43 - CFD: 17/10/2012 - 11:18:07 - [407,072] ----D C:\ProgramData\Adobe

O43 - CFD: 12/09/2012 - 09:32:17 - [65,805] ----D C:\ProgramData\Apple

O43 - CFD: 14/10/2012 - 14:00:22 - [49,870] ----D C:\ProgramData\Apple Computer

O43 - CFD: 14/07/2009 - 01:08:56 - [0] --H-D C:\ProgramData\Application Data

O43 - CFD: 12/09/2012 - 15:10:06 - [0,004] ----D C:\ProgramData\ASUS

O43 - CFD: 09/08/2012 - 11:58:35 - [0,678] ----D C:\ProgramData\Atheros

O43 - CFD: 20/05/2012 - 11:57:11 - [15,579] ----D C:\ProgramData\AVAST Software

O43 - CFD: 19/04/2012 - 04:02:29 - [4,522] ----D C:\ProgramData\ChangeFolderView

O43 - CFD: 14/07/2009 - 01:08:56 - [0] --H-D C:\ProgramData\Desktop

O43 - CFD: 14/07/2009 - 01:08:56 - [0] --H-D C:\ProgramData\Documents

O43 - CFD: 12/04/2011 - 22:33:02 - [18,933] ----D C:\ProgramData\Downloaded Installations

O43 - CFD: 14/07/2009 - 01:08:56 - [0] --H-D C:\ProgramData\Favorites

O43 - CFD: 12/04/2011 - 22:33:04 - [0,000] ----D C:\ProgramData\FLEXnet

O43 - CFD: 19/04/2012 - 03:59:29 - [1,048] ----D C:\ProgramData\FolderView

O43 - CFD: 12/04/2011 - 22:33:20 - [0,498] ----D C:\ProgramData\Google

O43 - CFD: 19/04/2012 - 18:18:18 - [0,002] ----D C:\ProgramData\Intel

O43 - CFD: 22/08/2012 - 04:02:02 - [15,964] ----D C:\ProgramData\Malwarebytes

O43 - CFD: 12/09/2012 - 11:01:49 - [518,237] -S--D C:\ProgramData\Microsoft

O43 - CFD: 10/10/2012 - 21:15:52 - [0,062] ----D C:\ProgramData\Microsoft Help

O43 - CFD: 29/08/2012 - 16:48:18 - [0,013] ----D C:\ProgramData\Mozilla

O43 - CFD: 12/09/2012 - 10:59:52 - [0] ----D C:\ProgramData\Nuance

O43 - CFD: 19/04/2012 - 18:17:10 - [9,482] ----D C:\ProgramData\NVIDIA

O43 - CFD: 19/04/2012 - 18:14:50 - [0,804] ----D C:\ProgramData\NVIDIA Corporation

O43 - CFD: 12/04/2011 - 22:48:44 - [27,601] ----D C:\ProgramData\OberonGameConsole

O43 - CFD: 19/04/2012 - 18:27:48 - [0,002] ----D C:\ProgramData\P4G

O43 - CFD: 31/07/2012 - 18:11:05 - [36,511] ----D C:\ProgramData\Skype

O43 - CFD: 19/04/2012 - 18:19:48 - [0,008] ----D C:\ProgramData\SonicFocus

O43 - CFD: 12/09/2012 - 10:59:03 - [0,074] ----D C:\ProgramData\Spybot - Search & Destroy

O43 - CFD: 14/07/2009 - 01:08:56 - [0] --H-D C:\ProgramData\Start Menu

O43 - CFD: 17/10/2012 - 11:16:45 - [0,000] ----D C:\ProgramData\Sun

O43 - CFD: 03/08/2012 - 14:03:56 - [0] ----D C:\ProgramData\

O43 - CFD: 14/07/2009 - 01:08:56 - [0] --H-D C:\ProgramData\Templates

O43 - CFD: 12/09/2012 - 10:57:28 - [5,646] ----D C:\ProgramData\Trend Micro

O43 - CFD: 17/09/2012 - 08:57:40 - [27,031] ----D C:\ProgramData\Win7codecs

O43 - CFD: 12/09/2012 - 09:33:44 - [0,004] ----D C:\ProgramData\{93E26451-CD9A-43A5-A2FA-C42392EA4001}

O43 - CFD: 17/09/2012 - 20:39:15 - [9,858] ----D C:\Users\Claire\AppData\Roaming\Adobe

O43 - CFD: 12/09/2012 - 11:11:10 - [0,192] ----D C:\Users\Claire\AppData\Roaming\Apple Computer

O43 - CFD: 25/04/2012 - 14:36:21 - [0] ----D C:\Users\Claire\AppData\Roaming\ASUS WebStorage

O43 - CFD: 17/10/2012 - 11:07:15 - [40,522] ----D C:\Users\Claire\AppData\Roaming\Dropbox

O43 - CFD: 25/04/2012 - 14:39:55 - [0,000] ----D C:\Users\Claire\AppData\Roaming\FLEXnet

O43 - CFD: 17/10/2012 - 07:43:56 - [0,000] ----D C:\Users\Claire\AppData\Roaming\Google

O43 - CFD: 25/04/2012 - 10:30:47 - [0] ----D C:\Users\Claire\AppData\Roaming\Identities

O43 - CFD: 20/05/2012 - 08:57:39 - [0,001] ----D C:\Users\Claire\AppData\Roaming\Macromedia

O43 - CFD: 22/08/2012 - 04:02:08 - [1,190] ----D C:\Users\Claire\AppData\Roaming\Malwarebytes

O43 - CFD: 14/07/2009 - 03:44:38 - [0] ----D C:\Users\Claire\AppData\Roaming\Media Center Programs

O43 - CFD: 14/10/2012 - 14:31:28 - [18,842] -S--D C:\Users\Claire\AppData\Roaming\Microsoft

O43 - CFD: 10/10/2012 - 07:52:06 - [22,126] ----D C:\Users\Claire\AppData\Roaming\Mozilla

O43 - CFD: 25/04/2012 - 14:39:54 - [0,000] ----D C:\Users\Claire\AppData\Roaming\Nuance

O43 - CFD: 17/10/2012 - 11:02:40 - [11,103] ----D C:\Users\Claire\AppData\Roaming\Skype

O43 - CFD: 03/08/2012 - 14:03:56 - [0] ----D C:\Users\Claire\AppData\Roaming\

O43 - CFD: 17/09/2012 - 08:57:38 - [0,001] ----D C:\Users\Claire\AppData\Roaming\Win7codecs

O43 - CFD: 14/10/2012 - 19:14:24 - [0] ----D C:\Users\Claire\AppData\Roaming\Windows Live Writer

O43 - CFD: 20/05/2012 - 10:19:56 - [0,000] ----D C:\Users\Claire\AppData\Roaming\WinRAR

O43 - CFD: 25/04/2012 - 14:39:52 - [0,061] ----D C:\Users\Claire\AppData\Roaming\Zeon

O43 - CFD: 17/09/2012 - 20:39:15 - [14,818] ----D C:\Users\Claire\AppData\Local\Adobe

O43 - CFD: 12/09/2012 - 09:32:30 - [0] ----D C:\Users\Claire\AppData\Local\Apple

O43 - CFD: 12/09/2012 - 09:34:32 - [7,303] ----D C:\Users\Claire\AppData\Local\Apple Computer

O43 - CFD: 25/04/2012 - 10:30:25 - [0] ----D C:\Users\Claire\AppData\Local\Application Data

O43 - CFD: 12/09/2012 - 15:10:03 - [1,310] ----D C:\Users\Claire\AppData\Local\ASUS

O43 - CFD: 25/04/2012 - 10:32:07 - [0] ----D C:\Users\Claire\AppData\Local\BMExplorer

O43 - CFD: 17/10/2012 - 08:07:30 - [4,676] ----D C:\Users\Claire\AppData\Local\CrashDumps

O43 - CFD: 05/09/2012 - 13:58:17 - [0] ----D C:\Users\Claire\AppData\Local\Diagnostics

O43 - CFD: 05/09/2012 - 13:58:17 - [0] ----D C:\Users\Claire\AppData\Local\ElevatedDiagnostics

O43 - CFD: 16/09/2012 - 22:16:55 - [0,234] ----D C:\Users\Claire\AppData\Local\Fnacmusic

O43 - CFD: 17/10/2012 - 07:43:16 - [56,175] ----D C:\Users\Claire\AppData\Local\Google

O43 - CFD: 25/04/2012 - 10:30:25 - [0] ----D C:\Users\Claire\AppData\Local\Historique

O43 - CFD: 17/09/2012 - 07:38:40 - [215,304] ----D C:\Users\Claire\AppData\Local\Microsoft

O43 - CFD: 20/05/2012 - 12:06:57 - [0] ----D C:\Users\Claire\AppData\Local\Microsoft Games

O43 - CFD: 17/08/2012 - 10:29:17 - [0,101] ----D C:\Users\Claire\AppData\Local\Microsoft Help

O43 - CFD: 29/08/2012 - 16:48:22 - [57,988] ----D C:\Users\Claire\AppData\Local\Mozilla

O43 - CFD: 17/10/2012 - 11:18:02 - [0] ----D C:\Users\Claire\AppData\Local\Secunia PSI

O43 - CFD: 17/10/2012 - 11:24:46 - [9,812] ----D C:\Users\Claire\AppData\Local\Temp

O43 - CFD: 25/04/2012 - 10:30:25 - [0] ----D C:\Users\Claire\AppData\Local\Temporary Internet Files

O43 - CFD: 12/09/2012 - 15:10:03 - [1,913] ----D C:\Users\Claire\AppData\Local\VirtualStore

O43 - CFD: 07/09/2012 - 17:18:03 - [0,035] ----D C:\Users\Claire\AppData\Local\Windows Live

O43 - CFD: 14/10/2012 - 19:14:34 - [0,620] ----D C:\Users\Claire\AppData\Local\Windows Live Writer

O43 - CFD: 14/07/2009 - 00:54:32 - [0,014] R---D C:\Users\Claire\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories

O43 - CFD: 02/08/2012 - 05:16:28 - [0,000] R---D C:\Users\Claire\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools

O43 - CFD: 31/07/2012 - 16:32:10 - [0,002] ----D C:\Users\Claire\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox

O43 - CFD: 14/07/2009 - 00:49:38 - [0,001] R---D C:\Users\Claire\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance

O43 - CFD: 10/08/2012 - 05:03:15 - [0,001] R---D C:\Users\Claire\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup

O43 - CFD: 18/09/2012 - 09:36:03 - [0,003] ----D C:\Users\Claire\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Unlocker

O43 - CFD: 20/05/2012 - 09:30:07 - [0,003] ----D C:\Users\Claire\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR

~ Scan Program Folder in 00mn 03s




---\\ Derniers fichiers modifiés ou crées sous Windows et System32 (O44)

O44 - LFC:[MD5.53F7FAAE48D1AEB57DDEB22E4F568B09] - 17/10/2012 - 11:19:23 ---A- . (...) -- C:\Windows\WindowsUpdate.log [1485159]

O44 - LFC:[MD5.6BCAF46E2B7FA9ACE92B4D39F3037C5C] - 17/10/2012 - 11:06:16 . (...) -- C:\Windows\System32\acovcnt.exe []

O44 - LFC:[MD5.6BCAF46E2B7FA9ACE92B4D39F3037C5C] - 17/10/2012 - 11:06:16 ---A- . (...) -- C:\Windows\SysNative\acovcnt.exe [45056]

O44 - LFC:[MD5.85269B850C69423807E3873B0F6C188A] - 17/10/2012 - 11:05:53 ---A- . (...) -- C:\log2.txt [0]

O44 - LFC:[MD5.9982DE5B241F4776F71698EB4D4FC7E9] - 17/10/2012 - 11:05:28 ---A- . (...) -- C:\Windows\setupact.log [168]

O44 - LFC:[MD5.90A54FAAB871A3F6B9F24C4900AA12B0] - 17/10/2012 - 11:05:26 -S-A- . (...) -- C:\Windows\bootstat.dat [67584]

O44 - LFC:[MD5.6AEB8A6652F91E2964D8F198769A5224] - 17/10/2012 - 09:49:58 ---A- . (...) -- C:\Windows\SysNative\ServiceFilter.ini [1424]

O44 - LFC:[MD5.03F84E43B5207B0C795F40C76B34BF50] - 17/10/2012 - 09:48:21 ---A- . (...) -- C:\AdwCleaner[s1].txt [11868]

O44 - LFC:[MD5.D41D8CD98F00B204E9800998ECF8427E] - 17/10/2012 - 08:50:26 ---A- . (...) -- C:\Windows\setuperr.log [0]

O44 - LFC:[MD5.9938BE62CF5763D74EA2493FC26534EB] - 17/10/2012 - 08:50:12 ---A- . (...) -- C:\Windows\PFRO.log [600]

O44 - LFC:[MD5.42E3CB0AD02B16B5D2B6A5F9AAB6F2C4] - 13/10/2012 - 22:07:58 ---A- . (...) -- C:\Windows\SysNative\PerfStringBackup.INI [1580460]

O44 - LFC:[MD5.65A7F77E2E2CAB3B337FC5080D2B0135] - 13/10/2012 - 22:07:58 ---A- . (...) -- C:\Windows\SysNative\perfc009.dat [110140]

O44 - LFC:[MD5.7DB41A61AB2DD0EDDE28C796BD5EF7A8] - 13/10/2012 - 22:07:58 ---A- . (...) -- C:\Windows\SysNative\perfc00C.dat [134506]

O44 - LFC:[MD5.DD44A752135261AFC96C7E1E823042D0] - 13/10/2012 - 22:07:58 ---A- . (...) -- C:\Windows\SysNative\perfh009.dat [627420]

O44 - LFC:[MD5.A9F7609A857A66C768D0A599321E3D5D] - 13/10/2012 - 22:07:58 ---A- . (...) -- C:\Windows\SysNative\perfh00C.dat [715892]

O44 - LFC:[MD5.914902083020773258CCC0A3382BC545] - 02/10/2012 - 07:47:47 ---A- . (...) -- C:\Windows\SysNative\AutoRunFilter.ini [2072]

~ Scan Files in 00mn 27s




---\\ Déni du service (Local Security Authority) (O48)

O48 - LSA:Local Security Authority Authentication Packages . (.Microsoft Corporation - Microsoft Authentication Package v1.0.) -- C:\Windows\System32\msv1_0.dll

O48 - LSA:Local Security Authority Notification Packages . (.Microsoft Corporation - Moteur du client de l’Éditeur de configuration de sécurité Windows.) -- C:\Windows\System32\scecli.dll

O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Package de sécurité Kerberos.) -- C:\Windows\System32\kerberos.dll

O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Microsoft Authentication Package v1.0.) -- C:\Windows\System32\msv1_0.dll

O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - TLS / SSL Security Provider.) -- C:\Windows\System32\schannel.dll

O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Microsoft Digest Access.) -- C:\Windows\System32\wdigest.dll

O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Web Service Security Package.) -- C:\Windows\System32\tspkg.dll

O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corporation - Pku2u Security Package.) -- C:\Windows\System32\pku2u.dll

O48 - LSA:Local Security Authority Security Packages . (.Microsoft Corp. - LiveSSP.) -- C:\Windows\System32\livessp.dll

~ Scan Keys in 00mn 00s




---\\ Contrôle du Safe Boot (CSB) (O49)

O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\sermouse.sys . (.Microsoft Corporation - Pilote de filtre souris série.) -- C:\Windows\System32\Drivers\sermouse.sys

O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\vga.sys . (.Microsoft Corporation - VGA/Super VGA Video Driver.) -- C:\Windows\System32\Drivers\vga.sys

O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\vgasave.sys . (...) -- C:\Windows\System32\Drivers\vgasave.sys (.not file.)

O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\volmgr.sys . (.Microsoft Corporation - Volume Manager Driver.) -- C:\Windows\System32\Drivers\volmgr.sys

O49 - CSB:Control Safe Boot HKLM\...\CCS\Minimal\volmgrx.sys . (.Microsoft Corporation - Pilote d’extension du gestionnaire de volumes.) -- C:\Windows\System32\Drivers\volmgrx.sys

O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\ipnat.sys . (.Microsoft Corporation - IP Network Address Translator.) -- C:\Windows\System32\Drivers\ipnat.sys

O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\nsiproxy.sys . (.Microsoft Corporation - NSI Proxy.) -- C:\Windows\System32\Drivers\nsiproxy.sys

O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\rdpencdd.sys . (.Microsoft Corporation - RDP Encoder Miniport.) -- C:\Windows\System32\Drivers\rdpencdd.sys

O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\sermouse.sys . (.Microsoft Corporation - Pilote de filtre souris série.) -- C:\Windows\System32\Drivers\sermouse.sys

O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\vga.sys . (.Microsoft Corporation - VGA/Super VGA Video Driver.) -- C:\Windows\System32\Drivers\vga.sys

O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\vgasave.sys . (...) -- C:\Windows\System32\Drivers\vgasave.sys (.not file.)

O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\volmgr.sys . (.Microsoft Corporation - Volume Manager Driver.) -- C:\Windows\System32\Drivers\volmgr.sys

O49 - CSB:Control Safe Boot HKLM\...\CCS\Network\volmgrx.sys . (.Microsoft Corporation - Pilote d’extension du gestionnaire de volumes.) -- C:\Windows\System32\Drivers\volmgrx.sys

~ Scan CSB in 00mn 00s




---\\ MountPoints2 Shell Key (O51) (None)


---\\ Trojan Driver Search Data (HKLM) (O52)

O52 - TDSD: \Drivers32\"msacm.l3acm"="C:\Windows\System32\l3codeca.acm" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Layer-3 Audio Codec for MSACM.) -- C:\Windows\System32\l3codeca.acm

O52 - TDSD: \Drivers32\"vidc.ffds"="ff_vfw.dll" . (.Pas de propriétaire - ffdshow VFW.) -- C:\Windows\System32\ff_vfw.dll

O52 - TDSD: \Drivers32\"vidc.lags"="lagarith.dll" . (.Pas de propriétaire - Lagarith.) -- C:\Windows\System32\lagarith.dll

O52 - TDSD: \drivers.desc\"C:\Windows\System32\l3codeca.acm"="Fraunhofer IIS MPEG Layer-3 Codec" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Layer-3 Audio Codec for MSACM.) -- C:\Windows\System32\l3codeca.acm

O52 - TDSD: \drivers.desc\"ff_vfw.dll"="ffdshow Video Codec" . (.Pas de propriétaire - ffdshow VFW.) -- C:\Windows\System32\ff_vfw.dll

O52 - TDSD: \drivers.desc\"lagarith.dll"="Lagarith lossless codec [LAGS]" . (.Pas de propriétaire - Lagarith.) -- C:\Windows\System32\lagarith.dll

~ Scan Keys in 00mn 00s




---\\ ShareTools MSconfig StartupReg (O53)

O53 - SMSR:HKLM\...\startupreg\ASUS Screen Saver Protector [Key] . (.ASUS - AsScrPro.) -- C:\Windows\AsScrPro.exe

O53 - SMSR:HKLM\...\startupreg\RtHDVCpl [Key] . (.Realtek Semiconductor - Gestionnaire audio HD Realtek.) -- C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe

O53 - SMSR:HKLM\...\startupreg\Skype [Key] . (.Skype Technologies S.A. - Skype.) -- C:\Program Files (x86)\Skype\Phone\Skype.exe

O53 - SMSR:HKLM\...\startupreg\Trend Micro Titanium [Key] . (...) -- C:\Program Files\Trend Micro\Titanium\VizorShortCut.exe (.not file.)

O53 - SMSR:HKLM\...\startupreg\VizorHtmlDialog.exe [Key] . (...) -- C:\Program Files\Trend Micro\Titanium\UIFramework\VizorHtmlDialog.exe (.not file.)

~ Scan SMSR Keys in 00mn 00s




---\\ Microsoft Control Security Providers (O54)

O54 - MCSP:[HKLM\...\CurrentControlSet\Control] - (SecurityProviders) - (.Microsoft Corporation - Credential Delegation Security Package.) -- C:\Windows\System32\credssp.dll

O54 - MCSP:[HKLM\...\ControlSet001\Control] - (SecurityProviders) - (.Microsoft Corporation - Credential Delegation Security Package.) -- C:\Windows\System32\credssp.dll

~ Scan Keys in 00mn 00s




---\\ Microsoft Windows Policies System (O55)

O55 - MWPS:[HKLM\...\Policies\System] - "ConsentPromptBehaviorAdmin"=5

O55 - MWPS:[HKLM\...\Policies\System] - "ConsentPromptBehaviorUser"=3

O55 - MWPS:[HKLM\...\Policies\System] - "EnableInstallerDetection"=1

O55 - MWPS:[HKLM\...\Policies\System] - "EnableLUA"=1

O55 - MWPS:[HKLM\...\Policies\System] - "EnableSecureUIAPaths"=1

O55 - MWPS:[HKLM\...\Policies\System] - "EnableUIADesktopToggle"=0

O55 - MWPS:[HKLM\...\Policies\System] - "EnableVirtualization"=1

O55 - MWPS:[HKLM\...\Policies\System] - "PromptOnSecureDesktop"=1

O55 - MWPS:[HKLM\...\Policies\System] - "ValidateAdminCodeSignatures"=0

O55 - MWPS:[HKLM\...\Policies\System] - "dontdisplaylastusername"=0

O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticecaption"=0

O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticetext"=0

O55 - MWPS:[HKLM\...\Policies\System] - "scforceoption"=0

O55 - MWPS:[HKLM\...\Policies\System] - "shutdownwithoutlogon"=1

O55 - MWPS:[HKLM\...\Policies\System] - "undockwithoutlogon"=1

O55 - MWPS:[HKLM\...\Policies\System] - "FilterAdministratorToken"=0

~ Scan Keys in 00mn 00s




---\\ Microsoft Windows Policies Explorer (O56)

O56 - MWPE:[HKLM\...\policies\Explorer] - "NoActiveDesktop"=1

O56 - MWPE:[HKLM\...\policies\Explorer] - "NoActiveDesktopChanges"=1

O56 - MWPE:[HKLM\...\policies\Explorer] - "ForceActiveDesktopOn"=0

~ Scan Keys in 00mn 00s




---\\ Liste des Drivers Système (O58)

O58 - SDL:[MD5.2F6B34B83843F0C5118B63AC634F5BF4] - 13/07/2009 - 21:52:21 ---A- . (.Adaptec, Inc. - Adaptec Windows SAS/SATA Storport Driver.) -- C:\Windows\System32\Drivers\adp94xx.sys [491088]

O58 - SDL:[MD5.DE8B9C3E0E09D918B394207F34AC16DD] - 08/07/2010 - 04:03:48 ---A- . (.Atheros Communications, Inc. - Atheros Extensible Wireless LAN device driver.) -- C:\Windows\System32\athrx.sys [2228736]

~ Scan Drivers in 00mn 00s




---\\ Liste des outils de nettoyage (O63)

O63 - Logiciel: ZHPDiag 1.31 - (.Nicolas Coolman.) [HKLM] -- ZHPDiag_is1

O63 - Logiciel: RSIT - (.random/random.)

~ Scan ADS in 00mn 00s




---\\ Liste des services Legacy (O64)

O64 - Services: CurCS - 02/07/2009 - C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys (ASMMAP64) .(.ASUS - Memory mapping Driver.) - LEGACY_ASMMAP64

O64 - Services: CurCS - ??\??\???? - C:\Windows\System32\Drivers\aswFsBlk.sys (aswFsBlk) .(.AVAST Software - avast! File System Access Blocking Driver.) - LEGACY_ASWFSBLK

O64 - Services: CurCS - 21/08/2012 - C:\Windows\system32\drivers\aswMonFlt.sys (aswMonFlt) .(.AVAST Software - avast! File System Minifilter for Windows 2.) - LEGACY_ASWMONFLT

O64 - Services: CurCS - 21/08/2012 - C:\Windows\system32\Drivers\aswrdr2.sys (aswRdr) .(.AVAST Software - avast! WFP Redirect Driver.) - LEGACY_ASWRDR

O64 - Services: CurCS - ??\??\???? - C:\Windows\System32\Drivers\aswSnx.sys (aswSnx) .(.AVAST Software - avast! Virtualization Driver.) - LEGACY_ASWSNX

O64 - Services: CurCS - ??\??\???? - C:\Windows\System32\Drivers\aswSP.sys (aswSP) .(.AVAST Software - avast! self protection module.) - LEGACY_ASWSP

O64 - Services: CurCS - ??\??\???? - C:\Windows\System32\Drivers\aswTdi.sys (aswTdi) .(.AVAST Software - avast! TDI Filter Driver.) - LEGACY_ASWTDI

O64 - Services: CurCS - 26/07/2010 - C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys (ATKWMIACPIIO) .(.ASUS - ATK WMIACPI Utility.) - LEGACY_ATKWMIACPIIO

O64 - Services: CurCS - 07/09/2012 - C:\Windows\system32\drivers\mbam.sys (MBAMProtector) .(.Malwarebytes Corporation - Malwarebytes Anti-Malware.) - LEGACY_MBAMPROTECTOR

O64 - Services: CurCS - 16/12/2011 - C:\Windows\System32\DRIVERS\psi_mf.sys (PSI) .(.Secunia - Secunia PSI Driver.) - LEGACY_PSI

O64 - Services: CurCS - ??\??\???? - C:\Windows\System32\Drivers\secdrv.sys (secdrv) .(.Macrovision Corporation, Macrovision Europe - Macrovision SECURITY Driver.) - LEGACY_SECDRV

O64 - Services: CurCS - 16/04/2010 - C:\Windows\System32\DRIVERS\TurboB.sys - Turbo Boost UI Monitor driver (TurboB) .(...) - LEGACY_TURBOB

O64 - Services: CurCS - 01/07/2010 - C:\Program Files\Unlocker\UnlockerDriver5.sys - UnlockerDriver5 (UnlockerDriver5) .(...) - LEGACY_UNLOCKERDRIVER5

~ Scan Services in 00mn 01s




---\\ File Associations Shell Spawning (O67)

O67 - Shell Spawning: <.bat> <batfile>[HKLM\..\open\Command] (...) -- "%1" %*

O67 - Shell Spawning: <.cpl> <cplfile>[HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe

O67 - Shell Spawning: <.cmd> <cmdfile>[HKLM\..\open\Command] (...) -- "%1" %*

O67 - Shell Spawning: <.com> <comfile>[HKLM\..\open\Command] (...) -- "%1" %*

O67 - Shell Spawning: <.evt> <evtfile>[HKLM\..\open\Command] (.Microsoft Corporation - Lanceur du composant logiciel enfichable Observateur d’événements.) -- C:\Windows\System32\eventvwr.exe

O67 - Shell Spawning: <.exe> <exefile>[HKLM\..\open\Command] (...) -- "%1" %*

O67 - Shell Spawning: <.html> <htmlfile>[HKLM\..\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe

O67 - Shell Spawning: <.js> <JSFile>[HKLM\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\Windows\System32\WScript.exe

O67 - Shell Spawning: <.reg> <regfile>[HKLM\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\Windows\regedit.exe

O67 - Shell Spawning: <.bat> <batfile>[HKCR\..\open\Command] (...) -- "%1" %*

O67 - Shell Spawning: <.cpl> <cplfile>[HKCR\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe

O67 - Shell Spawning: <.cmd> <cmdfile>[HKCR\..\open\Command] (...) -- "%1" %*

O67 - Shell Spawning: <.com> <comfile>[HKCR\..\open\Command] (...) -- "%1" %*

O67 - Shell Spawning: <.evt> <evtfile>[HKCR\..\open\Command] (.Microsoft Corporation - Lanceur du composant logiciel enfichable Observateur d’événements.) -- C:\Windows\System32\eventvwr.exe

O67 - Shell Spawning: <.exe> <exefile>[HKCR\..\open\Command] (...) -- "%1" %*

O67 - Shell Spawning: <.html> <htmlfile>[HKCR\..\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe

O67 - Shell Spawning: <.js> <JSFile>[HKCR\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\Windows\System32\WScript.exe

O67 - Shell Spawning: <.reg> <regfile>[HKCR\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\Windows\regedit.exe

~ Scan Keys in 00mn 00s




---\\ Start Menu Internet (O68)

O68 - StartMenuInternet: <FIREFOX.EXE> <Mozilla Firefox>[HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe

O68 - StartMenuInternet: <Google Chrome> <Google Chrome>[HKLM\..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer>[HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe

O68 - StartMenuInternet: <FIREFOX.EXE> <Mozilla Firefox>[HKLM\..\InstallInfo\ShowIconsCommand] (...) -- C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe (.not file.)

O68 - StartMenuInternet: <Google Chrome> <Google Chrome>[HKLM\..\InstallInfo\ShowIconsCommand] (...) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (.not file.)

O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer>[HKLM\..\InstallInfo\ShowIconsCommand] (...) -- C:\Windows\System32\ie4uinit.exe (.not file.)

O68 - StartMenuInternet: <FIREFOX.EXE> <Mozilla Firefox>[HKLM\..\InstallInfo\ReinstallCommand] (...) -- C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe (.not file.)

O68 - StartMenuInternet: <Google Chrome> <Google Chrome>[HKLM\..\InstallInfo\ReinstallCommand] (...) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (.not file.)

O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer>[HKLM\..\InstallInfo\ReinstallCommand] (...) -- C:\Windows\System32\ie4uinit.exe (.not file.)

O68 - StartMenuInternet: <FIREFOX.EXE> <Mozilla Firefox>[HKLM\..\InstallInfo\HideIconsCommand] (...) -- C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe (.not file.)

O68 - StartMenuInternet: <Google Chrome> <Google Chrome>[HKLM\..\InstallInfo\HideIconsCommand] (...) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (.not file.)

O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer>[HKLM\..\InstallInfo\HideIconsCommand] (...) -- C:\Windows\System32\ie4uinit.exe (.not file.)

~ Scan Keys in 00mn 00s




---\\ Search Browser Infection (O69)

O69 - SBI: SearchScopes [HKCU] {6A1806CD-94D4-4689-BA73-E35EA1EA9990} [DefaultScope] - (Google) - Google

~ Scan Keys in 00mn 00s




---\\ Recherche des services démarrés par Svchost (O83)

O83 - Search Svchost Services: AeLookupSvc (AeLookupSvc) . (.Microsoft Corporation - Service Expérience d’application.) -- C:\Windows\System32\aelupsvc.dll [72192]

O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Service de propagation de certificats de cartes à puce Microsoft.) -- C:\Windows\System32\certprop.dll [80384]

O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Service de propagation de certificats de cartes à puce Microsoft.) -- C:\Windows\System32\certprop.dll [80384]

O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - DLL du service Serveur.) -- C:\Windows\System32\srvsvc.dll [236032]

O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Client de stratégie de groupe.) -- C:\Windows\System32\gpsvc.dll [777728]

O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - Extension IKE.) -- C:\Windows\System32\ikeext.dll [853504]

O83 - Search Svchost Services: AudioSrv (AudioSrv) . (.Microsoft Corporation - Service Audio Windows.) -- C:\Windows\System32\Audiosrv.dll [679424]

O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Gestionnaire de numérotation automatique d’accès distant.) -- C:\Windows\System32\rasauto.dll [99328]

O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Gestionnaire de connexions d’accès distant.) -- C:\Windows\System32\rasmans.dll [344064]

O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Gestionnaire d’interface dynamique.) -- C:\Windows\System32\mprdim.dll [97792]

O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - Service de notification d’événements système (SENS).) -- C:\Windows\System32\sens.dll [64512]

O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Composants de l’application d’assistance à Microsoft NAT.) -- C:\Windows\System32\ipnathlp.dll [359424]

O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Serveur de téléphonie Microsoft® Windows.) -- C:\Windows\System32\tapisrv.dll [316928]

O83 - Search Svchost Services: TermService (TermService) . (.Microsoft Corporation - Gestionnaire des connexions distantes du serveur hôte de session Burea.) -- C:\Windows\System32\termsrv.dll [680960]

O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Agent de mise à jour automatique Windows Update.) -- C:\Windows\system32\wuaueng.dll [2428952]

O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Service de transfert intelligent en arrière-plan.) -- C:\Windows\System32\qmgr.dll [849920]

O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Dll des services Windows Shell.) -- C:\Windows\System32\shsvcs.dll [370688]

O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Service offrant une connectivité IPv6 sur un réseau IPv4..) -- C:\Windows\System32\iphlpsvc.dll [569344]

O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - DLL de service d’ouverture de session secondaire.) -- C:\Windows\system32\seclogon.dll [30720]

O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Service Informations d’application.) -- C:\Windows\System32\appinfo.dll [70656]

O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - Service de découverte iSCSI.) -- C:\Windows\System32\iscsiexe.dll [156672]

O83 - Search Svchost Services: MMCSS (MMCSS) . (.Microsoft Corporation - Service Planificateur de classes multimédias.) -- C:\Windows\System32\mmcss.dll [67584]

O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\Windows\System32\wbem\WMIsvc.dll [242688]

O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - Service Configuration des services Bureau à distance.) -- C:\Windows\System32\sessenv.dll [121856]

O83 - Search Svchost Services: browser (browser) . (.Microsoft Corporation - DLL du service Explorateur d’ordinateurs.) -- C:\Windows\System32\browser.dll [136704]

O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Service EAPHost Microsoft.) -- C:\Windows\System32\eapsvc.dll [111104]

O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - Service du Planificateur de tâches.) -- C:\Windows\System32\schedsvc.dll [1110016]

O83 - Search Svchost Services: hkmsvc (hkmsvc) . (.Microsoft Corporation - Service Gestion des clés.) -- C:\Windows\System32\kmsvc.dll [90624]

O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - Rapports et solutions aux problèmes.) -- C:\Windows\System32\wercplsupport.dll [84480]

O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) -- C:\Windows\System32\profsvc.dll [209920]

O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - DLL du service des thèmes Windows Shell.) -- C:\Windows\System32\themeservice.dll [44544]

O83 - Search Svchost Services: BDESVC (BDESVC) . (.Microsoft Corporation - Service BDE.) -- C:\Windows\System32\bdesvc.dll [100864]

~ Scan Services in 00mn 00s




---\\ Recherche particuliere à la racine de certains dossiers (O84)

[MD5.90E1D86D979B92738A47D7072CB22DA8] [sPRF][06/07/2010] (...) -- C:\ProgramData\FullRemove.exe [131472]

~ Scan Files in 00mn 00s




---\\ Firewall Active Exception List (FirewallRules) (O87)

O87 - FAEL: "WMPNSS-In-UDP-NoScope" |In - Domain - P17 - FALSE | .(...) -- C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (.not file.)

O87 - FAEL: "WMPNSS-Out-UDP-NoScope" |Out - Domain - P17 - FALSE | .(...) -- C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (.not file.)

O87 - FAEL: "WMPNSS-In-TCP-NoScope" |In - Domain - P6 - FALSE | .(...) -- C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (.not file.)

O87 - FAEL: "WMPNSS-Out-TCP-NoScope" |Out - Domain - P6 - FALSE | .(...) -- C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (.not file.)

O87 - FAEL: "WMPNSS-In-UDP" |In - Public - P17 - FALSE | .(...) -- C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (.not file.)

O87 - FAEL: "WMPNSS-Out-UDP" |Out - Public - P17 - FALSE | .(...) -- C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (.not file.)

O87 - FAEL: "WMPNSS-In-TCP" |In - Public - P6 - FALSE | .(...) -- C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (.not file.)

O87 - FAEL: "WMPNSS-Out-TCP" |Out - Public - P6 - FALSE | .(...) -- C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (.not file.)

O87 - FAEL: "NetPres-In-TCP-NoScope" |In - Domain - P6 - FALSE | .(...) -- C:\Windows\system32\netproj.exe (.not file.)

O87 - FAEL: "NetPres-Out-TCP-NoScope" |Out - Domain - P6 - FALSE | .(...) -- C:\Windows\system32\netproj.exe (.not file.)

O87 - FAEL: "NetPres-WSD-In-UDP" |In - None - P17 - FALSE | .(...) -- C:\Windows\system32\netproj.exe (.not file.)

O87 - FAEL: "NetPres-WSD-Out-UDP" |Out - None - P17 - FALSE | .(...) -- C:\Windows\system32\netproj.exe (.not file.)

O87 - FAEL: "NetPres-In-TCP" |In - Public - P6 - FALSE | .(...) -- C:\Windows\system32\netproj.exe (.not file.)

O87 - FAEL: "NetPres-Out-TCP" |Out - Public - P6 - FALSE | .(...) -- C:\Windows\system32\netproj.exe (.not file.)

O87 - FAEL: "{6D591AA7-13E4-4DBA-A0DA-4F3C26CC7A38}" | In - Public - P6 - FALSE | .(.NVIDIA Corporation - NVIDIA Settings Update Manager.) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe

O87 - FAEL: "{D4CAF9ED-9866-44D0-9D5E-E6E88ABF5662}" | In - Public - P17 - FALSE | .(.NVIDIA Corporation - NVIDIA Settings Update Manager.) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe

O87 - FAEL: "{06C4E370-81BA-41EE-A0C6-EE1D7EF1233C}" | In - Private - P6 - TRUE | .(.Dropbox, Inc. - Dropbox.) -- C:\Users\Claire\AppData\Roaming\Dropbox\bin\Dropbox.exe

O87 - FAEL: "{13BB5258-810D-4C3D-880C-FCA66198B288}" | In - Private - P17 - TRUE | .(.Dropbox, Inc. - Dropbox.) -- C:\Users\Claire\AppData\Roaming\Dropbox\bin\Dropbox.exe

O87 - FAEL: "{B1743ADA-C8D8-4078-9F7C-AE8BD557444B}" | In - None - P17 - TRUE | .(.Skype Technologies S.A. - Skype.) -- C:\Program Files (x86)\Skype\Phone\Skype.exe

O87 - FAEL: "TCP Query User{5FD0BCAB-36CE-416D-9AC4-5CCFA5BDD5EA}C:\users\claire\appdata\roaming\dropbox\bin\dropbox.exe" | In - Public - P6 - TRUE | .(.Dropbox, Inc. - Dropbox.) -- C:\users\claire\appdata\roaming\dropbox\bin\dropbox.exe

O87 - FAEL: "UDP Query User{F0AAD2FF-1A40-497D-9C64-5351B70DFE8B}C:\users\claire\appdata\roaming\dropbox\bin\dropbox.exe" | In - Public - P17 - TRUE | .(.Dropbox, Inc. - Dropbox.) -- C:\users\claire\appdata\roaming\dropbox\bin\dropbox.exe

O87 - FAEL: "{90D8BAFE-42D4-4A53-B5EA-025D93108A8B}" | In - Private - P6 - TRUE | .(.TeamViewer GmbH - TeamViewer Remote Control Application.) -- C:\Program Files (x86)\TeamViewer\Version7\TeamViewer.exe

O87 - FAEL: "{A758B1B2-F46A-40DB-9C69-73EDE0623CF8}" | In - Private - P17 - TRUE | .(.TeamViewer GmbH - TeamViewer Remote Control Application.) -- C:\Program Files (x86)\TeamViewer\Version7\TeamViewer.exe

O87 - FAEL: "{5D723D63-62EB-4F84-8822-F7AAA7F5DBFF}" | In - Private - P6 - TRUE | .(.TeamViewer GmbH - TeamViewer Remote Control Application.) -- C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe

O87 - FAEL: "{B1D44851-DF15-478C-BABF-4BD5E529D742}" | In - Private - P17 - TRUE | .(.TeamViewer GmbH - TeamViewer Remote Control Application.) -- C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe

O87 - FAEL: "{D1350EF5-267C-41F7-91E5-6BAB0766F6BD}" |Out - Private - P6 - TRUE | .(...) -- C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (.not file.)

O87 - FAEL: "{EB1C799D-1F76-447B-810A-D0687CC73576}" |In - Private - P6 - TRUE | .(...) -- C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (.not file.)

O87 - FAEL: "{94F0A601-736A-455A-BE96-E11B42C93C1E}" |Out - Private - P17 - TRUE | .(...) -- C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (.not file.)

O87 - FAEL: "{D1ED4762-E31B-438A-A35D-C3DF69B4AEE5}" |In - Private - P17 - TRUE | .(...) -- C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (.not file.)

O87 - FAEL: "{D79D0784-2CE9-4CFF-97F3-30FE991C5A33}" | In - None - P6 - TRUE | .(.Apple Inc. - WebKit2WebProcess.exe.) -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe

O87 - FAEL: "{F290C33C-D9ED-4C03-A596-89344763E7C5}" | In - Private - P6 - TRUE | .(.Apple Inc. - Bonjour Service.) -- C:\Program Files\Bonjour\mDNSResponder.exe

O87 - FAEL: "{6C76AD5C-48DB-4F4E-ACBC-EA58265B0AA7}" | In - Private - P17 - TRUE | .(.Apple Inc. - Bonjour Service.) -- C:\Program Files\Bonjour\mDNSResponder.exe

O87 - FAEL: "{9AB9EAAC-3496-43DA-B189-A9090029E920}" | In - Private - P6 - TRUE | .(.Apple Inc. - Bonjour Service.) -- C:\Program Files (x86)\Bonjour\mDNSResponder.exe

O87 - FAEL: "{9571D067-8B27-4B72-97F4-F60D3BC25B0A}" | In - Private - P17 - TRUE | .(.Apple Inc. - Bonjour Service.) -- C:\Program Files (x86)\Bonjour\mDNSResponder.exe

O87 - FAEL: "{982C7F9B-10C1-40C3-A33A-6597B17BB6BE}" | In - None - P17 - TRUE | .(.Apple Inc. - iTunes.) -- C:\Program Files (x86)\iTunes\iTunes.exe

~ Scan Firewall in 00mn 01s




---\\ Etat général des services non Microsoft (EGS) (SR=Running, SS=Stopped)

SS - | Auto 23/09/2012 65192 | (AdobeARMservice) . (.Adobe Systems Incorporated.) - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe

SS - | Demand 17/10/2012 250808 | (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

SS - | Auto 30/11/2010 379520 | (AFBAgent) . (.ASUSTeK Computer Inc..) - C:\Windows\system32\FBAgent.exe

SS - | Auto 11/08/2012 55184 | (Apple Mobile Device) . (.Apple Inc..) - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

SS - | Auto 15/06/2009 84536 | (ASLDRService) . (.ASUS.) - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe

SS - | Auto 24/05/2010 151552 | (Atheros Bt&Wlan Coex Agent) . (.Atheros.) - C:\Program Files (x86)\Atheros\Ath_CoexAgent.exe

SS - | Auto 25/11/2010 52896 | (AtherosSvc) . (.Atheros Commnucations.) - C:\Program Files (x86)\Atheros\Bluetooth Suite\adminservice.exe

SS - | Auto 15/12/2009 96896 | (ATKGFNEXSrv) . (.ASUS.) - C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe

SS - | Auto 21/08/2012 44808 | (avast! Antivirus) . (.AVAST Software.) - C:\Program Files\AVAST Software\Avast\AvastSvc.exe

SS - | Auto 30/08/2011 462184 | (Bonjour Service) . (.Apple Inc..) - C:\Program Files\Bonjour\mDNSResponder.exe

SS - | Demand 19/03/2012 276248 | (cphs) . (.Intel Corporation.) - C:\Windows\SysWow64\IntelCpHeciSvc.exe

SS - | Auto 12/04/2011 135664 | (gupdate) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

SS - | Demand 12/04/2011 135664 | (gupdatem) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

SS - | Disabled 12/04/2011 182768 | (gusvc) . (.Google.) - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe

SS - | Auto 149872 | (InstallClick) . (...) - C:\Program Files (x86)\RIFT Technologies\InstallClick Connector\installclick.exe

SS - | Demand 09/09/2012 936848 | (iPod Service) . (.Apple Inc..) - C:\Program Files\iPod\bin\iPodService.exe

SS - | Auto 07/09/2012 399432 | (MBAMScheduler) . (.Malwarebytes Corporation.) - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe

SS - | Auto 07/09/2012 676936 | (MBAMService) . (.Malwarebytes Corporation.) - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe

SS - | Demand 16/10/2012 115168 | (MozillaMaintenance) . (.Mozilla Foundation.) - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe

SS - | Auto 28/01/2011 993896 | (NVSvc) . (.NVIDIA Corporation.) - C:\Windows\System32\nvvsvc.exe

SS - | Auto 07/02/2011 2009704 | (nvUpdatusService) . (.NVIDIA Corporation.) - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe

SS - | Auto 24/09/2012 1328736 | (Secunia PSI Agent) . (.Secunia.) - C:\Program Files (x86)\Secunia\PSI\PSIA.exe

SS - | Auto 24/09/2012 656480 | (Secunia Update Agent) . (.Secunia.) - C:\Program Files (x86)\Secunia\PSI\sua.exe

SS - | Disabled 13/07/2012 160944 | (SkypeUpdate) . (.Skype Technologies.) - C:\Program Files (x86)\Skype\Updater\Updater.exe

SS - | Auto 16/07/2012 2673064 | (TeamViewer7) . (.TeamViewer GmbH.) - C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe

SS - | Auto 16/04/2010 134928 | (TurboBoost) . (.Intel® Corporation.) - C:\Program Files\Intel\TurboBoost\TurboBoost.exe

SS - | Auto 13/07/2009 27136 | C:\Program Files (x86)\Windows Defender\mpsvc.dll (WinDefend) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe

SS - | Auto 0 | (WMPNetworkSvc) . (...) - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe

SS - | Auto 13/07/2009 27136 | C:\Windows\system32\wuaueng.dll (wuauserv) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe

~ Scan Services in 00mn 14s




End of the scan (1449 lines in 01mn 20s)(0)

Posté(e) (modifié)

On demande sans cesse d'héberger les gros fichiers... sinon tu risques de planter le sujet, tout simplement.


Ton phénomène se passe sur Firefox? (et pas d'autre navigateur?)


Regarde dans tes extensions et modules s'il n'y a rien de louche et au cas où, vire ce qui est indésirable.


On fait enregistrer sur le bureau parce que certains outils ne peuvent pas être enregistrés ailleurs, tout simplement. C'est surtout le cas de ComboFix et de SFT.


Mais aussi pour ne jamais lancer d'outils depuis le net directement sinon ça va se mettre dans un temporaire, ce qui risque d'être très emmerdant parfois...



Modifié par Apollo

