Aller au contenu
  • Pas encore inscrit ?

    Pourquoi ne pas vous inscrire ? C'est simple, rapide et gratuit.
    Pour en savoir plus, lisez Les avantages de l'inscription... et la Charte de Zébulon.
    De plus, les messages que vous postez en tant qu'invité restent invisibles tant qu'un modérateur ne les a pas validés. Inscrivez-vous, ce sera un gain de temps pour tout le monde, vous, les helpeurs et les modérateurs ! :wink:

Messages recommandés

Posté(e) (modifié)

Bonsoir!

Voilà, mon pc (windows 7) a été infecté par "System care antivirus" donc après avoir cherché un peu sur internet depuis un autre ordi, j'ai redémarré en mode sans échec avec prise en charge du réseau. Dans mes recherches d'aide, il était indiqué de télécharger SpyHunter, mais ayant déjà Combofix sur mon pc, je l'ai lancé. Etait-ce la bonne marche à suivre? Combofix prépare actuellement le compte-rendu.

Merci d'avance :)

Modifié par PS02

Posté(e)

ComboFix 13-05-08.02 - Pauline-Sophie 08/05/2013 23:10:41.1.2 - x64 NETWORK

Microsoft Windows 7 Édition Familiale Premium 6.1.7601.1.1252.33.1036.18.4092.2981 [GMT 2:00]

Lancé depuis: c:\users\Pauline-Sophie\Desktop\ComboFix.exe

AV: Sophos Anti-Virus *Disabled/Outdated* {65FBD860-96D8-75EF-C7ED-7BE27E6C498A}

SP: Sophos Anti-Virus *Disabled/Outdated* {DE9A3984-B0E2-7A61-FD5D-409005EB0337}

SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

* Un nouveau point de restauration a été créé

.

.

(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))

.

.

C:\install.exe

c:\programdata\22537C5BEA27E0C2000022535A0EE719

c:\programdata\22537C5BEA27E0C2000022535A0EE719\22537C5BEA27E0C2000022535A0EE719

c:\programdata\22537C5BEA27E0C2000022535A0EE719\22537C5BEA27E0C2000022535A0EE719.exe

c:\programdata\22537C5BEA27E0C2000022535A0EE719\22537C5BEA27E0C2000022535A0EE719.ico

c:\programdata\HP

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\1025\1025.cab

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\1025\dj3055_Animations.xml

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\1025\synonyms-1025.xml

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\1026\1026.cab

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\1026\dj3055_Animations.xml

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\1026\synonyms-1026.xml

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\1028\1028.cab

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\1028\dj3055_Animations.xml

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\1028\synonyms-1028.xml

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\1029\1029.cab

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\1029\dj3055_Animations.xml

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\1029\synonyms-1029.xml

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\1030\1030.cab

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\1030\dj3055_Animations.xml

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\1030\synonyms-1030.xml

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\1031\1031.cab

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\1031\dj3055_Animations.xml

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\1031\synonyms-1031.xml

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\1032\1032.cab

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\1032\dj3055_Animations.xml

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\1032\synonyms-1032.xml

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\1033\1033.cab

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\1033\dj3055_Animations.xml

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\1033\synonyms-1033.xml

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\1034\1034.cab

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\1034\dj3055_Animations.xml

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\1034\synonyms-1034.xml

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\1035\1035.cab

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\1035\dj3055_Animations.xml

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\1035\synonyms-1035.xml

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\1036\1036.cab

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\1036\dj3055_Animations.xml

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\1036\synonyms-1036.xml

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\1037\1037.cab

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\1037\dj3055_Animations.xml

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\1037\synonyms-1037.xml

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\1038\1038.cab

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\1038\dj3055_Animations.xml

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\1038\synonyms-1038.xml

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\1040\1040.cab

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\1040\dj3055_Animations.xml

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\1040\synonyms-1040.xml

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\1042\1042.cab

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\1042\dj3055_Animations.xml

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\1042\synonyms-1042.xml

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\1043\1043.cab

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\1043\dj3055_Animations.xml

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\1043\synonyms-1043.xml

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\1044\1044.cab

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\1044\dj3055_Animations.xml

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\1044\synonyms-1044.xml

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\1045\1045.cab

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\1045\dj3055_Animations.xml

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\1045\synonyms-1045.xml

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\1046\1046.cab

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\1046\dj3055_Animations.xml

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\1046\synonyms-1046.xml

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\1048\1048.cab

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\1048\dj3055_Animations.xml

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\1048\synonyms-1048.xml

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\1049\1049.cab

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\1049\dj3055_Animations.xml

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\1049\synonyms-1049.xml

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\1050\1050.cab

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\1050\dj3055_Animations.xml

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\1050\synonyms-1050.xml

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\1051\1051.cab

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\1051\dj3055_Animations.xml

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\1051\synonyms-1051.xml

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\1053\1053.cab

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\1053\dj3055_Animations.xml

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\1053\synonyms-1053.xml

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\1054\1054.cab

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\1054\dj3055_Animations.xml

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\1054\synonyms-1054.xml

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\1055\1055.cab

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\1055\dj3055_Animations.xml

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\1055\synonyms-1055.xml

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\1057\1057.cab

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\1057\dj3055_Animations.xml

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\1057\synonyms-1057.xml

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\1060\1060.cab

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\1060\dj3055_Animations.xml

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\1060\synonyms-1060.xml

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\1061\1061.cab

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\1061\dj3055_Animations.xml

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\1061\synonyms-1061.xml

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\1062\1062.cab

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\1062\dj3055_Animations.xml

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\1062\synonyms-1062.xml

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\1063\1063.cab

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\1063\dj3055_Animations.xml

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\1063\synonyms-1063.xml

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\2052\2052.cab

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\2052\dj3055_Animations.xml

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\2052\synonyms-2052.xml

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\Accessory\AC_RunActiveContent.js

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\Accessory\cueFunctions.js

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\Accessory\hubURL.js

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\Accessory\images\bullet.gif

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\Accessory\images\checkbox.PNG

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\Accessory\images\cmyk-color-bar.svg

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\Accessory\images\collapsed.gif

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\Accessory\images\expanded.gif

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\Accessory\images\hyphen.PNG

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\Accessory\images\icon_caution_color.gif

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\Accessory\images\icon_warning_color.gif

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\Accessory\images\projector_icon.jpg

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\Accessory\images\registration-circle.svg

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\Accessory\images\RightArrow.jpg

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\Accessory\images\spacer.gif

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\Accessory\images\well.jpg

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\Accessory\masterStyle.css

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\flash\dj3055_black_copy.swf

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\flash\dj3055_CGD.swf

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\flash\dj3055_color_copy.swf

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\flash\dj3055_Com.swf

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\flash\dj3055_com_load_Envelope.swf

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\flash\dj3055_com_load_LargePaper.swf

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\flash\dj3055_com_load_media.swf

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\flash\dj3055_com_load_SmallPhoto.swf

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\flash\dj3055_copy_text_or_mixed_docs.swf

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\flash\dj3055_gtk_control_panel.swf

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\flash\dj3055_gtk_printer_parts.swf

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\flash\dj3055_ink_replace_cartridges.swf

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\flash\dj3055_paper_jam_back.swf

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\flash\dj3055_paper_jam_bottom.swf

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\flash\dj3055_paper_jam_front.swf

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\flash\dj3055_paper_jam_inside.swf

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\flash\dj3055_Zoom.swf

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\flash\globalAnivewerParts_V2.swf

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\graphics\online\c_panel.png

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\graphics\online\cart_contacts.png

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\graphics\online\cartridge_number.png

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\graphics\online\cleanout_door.png

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\graphics\online\cleanout_door_close.png

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\graphics\online\clear_jam_back.png

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\graphics\online\clear_jam_bottom.png

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\graphics\online\clear_jam_front.png

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\graphics\online\clear_jam_inside.png

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\graphics\online\colorlok.png

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\graphics\online\diagnostics_page.png

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\graphics\online\eprint_light.png

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\graphics\online\fcvr_ajr.png

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\graphics\online\fcvr_close.png

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\graphics\online\globe.png

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\graphics\online\icon_document.gif

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\graphics\online\icon_envelope.gif

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\graphics\online\icon_photo_horizontal.gif

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\graphics\online\icon_quickforms.png

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\graphics\online\ink_blk1.png

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\graphics\online\ink_cart_date.png

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\graphics\online\inkcart4.png

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\graphics\online\input_tray_1.png

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\graphics\online\ld_env3.png

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\graphics\online\ld_papr2.png

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\graphics\online\ld_papr3.png

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\graphics\online\ld_papr4.png

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\graphics\online\ld_photo_in_tray.png

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\graphics\online\ld_scan.png

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\graphics\online\ld_scan_close.png

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\graphics\online\ld_scan_open.png

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\graphics\online\Model_number.png

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\graphics\online\output_tray_1.png

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\graphics\online\ph_contacts.png

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\graphics\online\printer_parts.png

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\graphics\online\projector_icon.png

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\graphics\online\reg_ce.png

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\graphics\online\reg_ce_nh.png

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\graphics\online\reg_copyright_acknowledgements_no_bluetooth_ar_ww.png

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\graphics\online\reg_copyright_acknowledgements_no_bluetooth_bg_ww.png

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\graphics\online\reg_copyright_acknowledgements_no_bluetooth_cs_ww.png

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\graphics\online\reg_copyright_acknowledgements_no_bluetooth_da_ww.png

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\graphics\online\reg_copyright_acknowledgements_no_bluetooth_de_ww.png

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\graphics\online\reg_copyright_acknowledgements_no_bluetooth_el_ww.png

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\graphics\online\reg_copyright_acknowledgements_no_bluetooth_en_ww.png

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\graphics\online\reg_copyright_acknowledgements_no_bluetooth_es_ww.png

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\graphics\online\reg_copyright_acknowledgements_no_bluetooth_et_ww.png

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\graphics\online\reg_copyright_acknowledgements_no_bluetooth_fi_ww.png

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\graphics\online\reg_copyright_acknowledgements_no_bluetooth_fr_ww.png

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\graphics\online\reg_copyright_acknowledgements_no_bluetooth_he_ww.png

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\graphics\online\reg_copyright_acknowledgements_no_bluetooth_hr_ww.png

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\graphics\online\reg_copyright_acknowledgements_no_bluetooth_hu_ww.png

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\graphics\online\reg_copyright_acknowledgements_no_bluetooth_id_ww.png

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\graphics\online\reg_copyright_acknowledgements_no_bluetooth_it_ww.png

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\graphics\online\reg_copyright_acknowledgements_no_bluetooth_jp_ww.png

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\graphics\online\reg_copyright_acknowledgements_no_bluetooth_ko_ww.png

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\graphics\online\reg_copyright_acknowledgements_no_bluetooth_lt_ww.png

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\graphics\online\reg_copyright_acknowledgements_no_bluetooth_lv_ww.png

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\graphics\online\reg_copyright_acknowledgements_no_bluetooth_ms_ww.png

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\graphics\online\reg_copyright_acknowledgements_no_bluetooth_nl_ww.png

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\graphics\online\reg_copyright_acknowledgements_no_bluetooth_no_ww.png

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\graphics\online\reg_copyright_acknowledgements_no_bluetooth_pl_ww.png

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\graphics\online\reg_copyright_acknowledgements_no_bluetooth_pt_ww.png

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\graphics\online\reg_copyright_acknowledgements_no_bluetooth_ro_ww.png

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\graphics\online\reg_copyright_acknowledgements_no_bluetooth_ru_ww.png

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\graphics\online\reg_copyright_acknowledgements_no_bluetooth_sk_ww.png

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\graphics\online\reg_copyright_acknowledgements_no_bluetooth_sl_ww.png

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\graphics\online\reg_copyright_acknowledgements_no_bluetooth_sv_ww.png

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\graphics\online\reg_copyright_acknowledgements_no_bluetooth_th_ww.png

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\graphics\online\reg_copyright_acknowledgements_no_bluetooth_tr_ww.png

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\graphics\online\reg_copyright_acknowledgements_no_bluetooth_uk_ww.png

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\graphics\online\reg_copyright_acknowledgements_no_bluetooth_zh_cn.png

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\graphics\online\reg_copyright_acknowledgements_no_bluetooth_zh_tw.png

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\graphics\online\reg_energystar_logo_ww.jpg

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\graphics\online\reg_fcc_statement_class_b_us.png

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\graphics\online\reg_notice_to_users_ko_ww.png

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\graphics\online\reg_power_cord_notice_jp_ww.png

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\graphics\online\reg_rohs_table_generic_zh_cn.png

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\graphics\online\reg_vcci_class_b_notice_jp_ww.png

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\graphics\online\reg_weee_eu.png

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\graphics\online\reg_wireless_notice_to_users_br.png

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\graphics\online\reg_wireless_notice_to_users_ca.png

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\graphics\online\reg_wireless_notice_zh_tw.png

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\graphics\online\reg_wireless_radio_frequency_radiation_us.png

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\graphics\online\release_pcart_no_co.png

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\graphics\online\top_up3.png

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\graphics\online\unpack_cart.png

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\graphics\online\wireless_light.png

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\images\global_product_bg_blue.png

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\images\global_product_bg_blue_gtk.jpg

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\images\global_product_bg_blue_hd.jpg

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\images\global_product_bg_blue_wide.png

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\sysparm.xml

c:\programdata\HP\HP Deskjet 3050A J611 series\Help\topicmap.xml

c:\programdata\HP\HP Deskjet 3050A J611 series\HPCustPartic\schedule.ini

c:\programdata\HP\HP Deskjet 3050A J611 series\HPCustPartic\schedulekeeper.ini

c:\programdata\HP\HP Deskjet 3050A J611 series\Installer\Help\1025\HP_Setup_Help.chm

c:\programdata\HP\HP Deskjet 3050A J611 series\Installer\Help\1028\HP_Setup_Help.chm

c:\programdata\HP\HP Deskjet 3050A J611 series\Installer\Help\1029\HP_Setup_Help.chm

c:\programdata\HP\HP Deskjet 3050A J611 series\Installer\Help\1030\HP_Setup_Help.chm

c:\programdata\HP\HP Deskjet 3050A J611 series\Installer\Help\1031\HP_Setup_Help.chm

c:\programdata\HP\HP Deskjet 3050A J611 series\Installer\Help\1032\HP_Setup_Help.chm

c:\programdata\HP\HP Deskjet 3050A J611 series\Installer\Help\1033\HP_Setup_Help.chm

c:\programdata\HP\HP Deskjet 3050A J611 series\Installer\Help\1034\HP_Setup_Help.chm

c:\programdata\HP\HP Deskjet 3050A J611 series\Installer\Help\1035\HP_Setup_Help.chm

c:\programdata\HP\HP Deskjet 3050A J611 series\Installer\Help\1036\HP_Setup_Help.chm

c:\programdata\HP\HP Deskjet 3050A J611 series\Installer\Help\1037\HP_Setup_Help.chm

c:\programdata\HP\HP Deskjet 3050A J611 series\Installer\Help\1038\HP_Setup_Help.chm

c:\programdata\HP\HP Deskjet 3050A J611 series\Installer\Help\1040\HP_Setup_Help.chm

c:\programdata\HP\HP Deskjet 3050A J611 series\Installer\Help\1041\HP_Setup_Help.chm

c:\programdata\HP\HP Deskjet 3050A J611 series\Installer\Help\1042\HP_Setup_Help.chm

c:\programdata\HP\HP Deskjet 3050A J611 series\Installer\Help\1043\HP_Setup_Help.chm

c:\programdata\HP\HP Deskjet 3050A J611 series\Installer\Help\1044\HP_Setup_Help.chm

c:\programdata\HP\HP Deskjet 3050A J611 series\Installer\Help\1045\HP_Setup_Help.chm

c:\programdata\HP\HP Deskjet 3050A J611 series\Installer\Help\1046\HP_Setup_Help.chm

c:\programdata\HP\HP Deskjet 3050A J611 series\Installer\Help\1049\HP_Setup_Help.chm

c:\programdata\HP\HP Deskjet 3050A J611 series\Installer\Help\1053\HP_Setup_Help.chm

c:\programdata\HP\HP Deskjet 3050A J611 series\Installer\Help\1055\HP_Setup_Help.chm

c:\programdata\HP\HP Deskjet 3050A J611 series\Installer\Help\2052\HP_Setup_Help.chm

c:\programdata\HP\HP Deskjet 3050A J611 series\NetworkDevices\CN2751FH4605WK.ini

c:\programdata\HP\HP Deskjet 3050A J611 series\XmlFileCache\CN2751FH4605WK\Calibration\CalibrationManifest.xml

c:\programdata\HP\HP Deskjet 3050A J611 series\XmlFileCache\CN2751FH4605WK\DevMgmt\ConsumableConfigCap.xml

c:\programdata\HP\HP Deskjet 3050A J611 series\XmlFileCache\CN2751FH4605WK\DevMgmt\DiscoveryTree.xml

c:\programdata\HP\HP Deskjet 3050A J611 series\XmlFileCache\CN2751FH4605WK\DevMgmt\InternalPrintCap.xml

c:\programdata\HP\HP Deskjet 3050A J611 series\XmlFileCache\CN2751FH4605WK\DevMgmt\ProductConfigCap.xml

c:\programdata\HP\HP Deskjet 3050A J611 series\XmlFileCache\CN2751FH4605WK\ePrint\ePrintConfigCap.xml

c:\programdata\HP\HP Deskjet 3050A J611 series\XmlFileCache\CN2751FH4605WK\ePrint\ePrintManifest.xml

c:\programdata\HP\HP Deskjet 3050A J611 series\XmlFileCache\CN2751FH4605WK\IoMgmt\IoMgmtManifest.xml

c:\programdata\HP\HP Deskjet 3050A J611 series\XmlFileCache\CN2751FH4605WK\Scan\ScanCaps.xml

c:\programdata\HP\HP Deskjet 3050A J611 series\XmlFileCache\CN2751FH4605WK\WebFirmwareUpdate\WebFirmwareUpdateManifest.xml

c:\users\Pauline-Sophie\AppData\Local\Program Files\Amazon\MP3 Downloader\AmazonMP3DownloaderHelper.exe

c:\users\Pauline-Sophie\AppData\Roaming\eoRezo

c:\users\Pauline-Sophie\AppData\Roaming\eoRezo\install.exe

c:\users\Pauline-Sophie\AppData\Roaming\eoRezo\SoftwareUpdate\help_config.cyp

c:\users\Pauline-Sophie\AppData\Roaming\eoRezo\SoftwareUpdate\unins000.dat

c:\users\Pauline-Sophie\AppData\Roaming\eoRezo\SoftwareUpdate\unins000.exe

c:\users\Pauline-Sophie\AppData\Roaming\eoRezo\SoftwareUpdate\user_config.cyp

c:\users\Pauline-Sophie\AppData\Roaming\eoRezo\SoftwareUpdate\user_profil.cyp

c:\users\Pauline-Sophie\AppData\Roaming\Local

c:\users\Pauline-Sophie\AppData\Roaming\Local\Temp\DDM\Settings\settings.ddi

c:\users\Pauline-Sophie\AppData\Roaming\Local\Temp\DDM\Settings\Temporary Downloaded Files\mbsvzohgxmfr.avi.ddp

c:\users\Pauline-Sophie\AppData\Roaming\OfferBox

c:\users\Pauline-Sophie\AppData\Roaming\OfferBox\config.xml

c:\users\Pauline-Sophie\AppData\Roaming\OfferBox\http_app.offerbox.com\country.sxe

c:\users\Pauline-Sophie\AppData\Roaming\OfferBox\http_app.offerbox.com\extracountry.sxe

c:\users\Pauline-Sophie\AppData\Roaming\OfferBox\http_app.offerbox.com\history.db

c:\users\Pauline-Sophie\AppData\Roaming\OfferBox\http_app.offerbox.com\profile.sxe

c:\users\Pauline-Sophie\AppData\Roaming\OfferBox\http_app.offerbox.com\update.sxe

c:\users\Pauline-Sophie\AppData\Roaming\OfferBox\http_app.offerbox.com\update.xml

c:\windows\SysWow64\DEBUG.log

c:\windows\SysWow64\ijl11.dll

.

.

((((((((((((((((((((((((((((( Fichiers créés du 2013-04-08 au 2013-05-08 ))))))))))))))))))))))))))))))))))))

.

.

2013-05-08 21:22 . 2013-05-08 21:22 -------- d-----w- c:\users\Default\AppData\Local\temp

2013-05-08 21:13 . 2013-05-08 21:13 76232 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{FC94377B-596C-4F6E-BB66-A299166F69B9}\offreg.dll

2013-05-08 21:02 . 2013-05-08 21:02 -------- d-----w- c:\program files (x86)\Enigma Software Group

2013-05-07 15:50 . 2013-04-10 03:46 9317456 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{FC94377B-596C-4F6E-BB66-A299166F69B9}\mpengine.dll

2013-05-06 20:36 . 2013-05-06 20:36 -------- d-----w- c:\users\Pauline-Sophie\AppData\Roaming\Amazon

2013-05-06 20:35 . 2013-05-06 20:35 -------- d-----w- c:\users\Pauline-Sophie\AppData\Local\Program Files

2013-04-30 17:01 . 2013-04-30 17:01 163504 ----a-w- c:\programdata\Microsoft\Windows\Sqm\Manifest\Sqm10144.bin

2013-04-24 10:20 . 2013-04-12 14:45 1656680 ----a-w- c:\windows\system32\drivers\ntfs.sys

2013-04-13 10:01 . 2013-04-13 10:00 95648 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll

2013-04-10 13:24 . 2013-03-01 03:36 3153408 ----a-w- c:\windows\system32\win32k.sys

2013-04-10 13:24 . 2013-01-24 06:01 223752 ----a-w- c:\windows\system32\drivers\fvevol.sys

2013-04-10 13:24 . 2013-03-19 06:04 5550424 ----a-w- c:\windows\system32\ntoskrnl.exe

2013-04-10 13:24 . 2013-03-19 05:04 3913560 ----a-w- c:\windows\SysWow64\ntoskrnl.exe

2013-04-10 13:24 . 2013-03-19 05:04 3968856 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe

2013-04-10 13:24 . 2013-03-19 03:06 112640 ----a-w- c:\windows\system32\smss.exe

2013-04-10 13:24 . 2013-03-19 05:46 43520 ----a-w- c:\windows\system32\csrsrv.dll

2013-04-10 13:24 . 2013-03-19 04:47 6656 ----a-w- c:\windows\SysWow64\apisetschema.dll

.

.

.

(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))

.

2013-05-02 00:06 . 2010-08-27 08:32 278800 ------w- c:\windows\system32\MpSigStub.exe

2013-04-20 08:27 . 2012-07-26 16:18 691592 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe

2013-04-20 08:27 . 2011-05-22 19:10 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl

2013-04-13 10:00 . 2012-05-11 19:27 861088 ----a-w- c:\windows\SysWow64\npdeployJava1.dll

2013-04-13 10:00 . 2010-10-17 10:31 782240 ----a-w- c:\windows\SysWow64\deployJava1.dll

2013-04-10 15:24 . 2010-09-20 15:09 72702784 ----a-w- c:\windows\system32\MRT.exe

2013-03-13 22:21 . 2013-03-13 22:21 1054720 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe

2013-03-13 22:21 . 2013-03-13 22:21 226304 ----a-w- c:\windows\system32\elshyph.dll

2013-03-13 22:21 . 2013-03-13 22:21 185344 ----a-w- c:\windows\SysWow64\elshyph.dll

2013-03-13 22:21 . 2013-03-13 22:21 158720 ----a-w- c:\windows\SysWow64\msls31.dll

2013-03-13 22:21 . 2013-03-13 22:21 719360 ----a-w- c:\windows\SysWow64\mshtmlmedia.dll

2013-03-13 22:21 . 2013-03-13 22:21 523264 ----a-w- c:\windows\SysWow64\vbscript.dll

2013-03-13 22:21 . 2013-03-13 22:21 150528 ----a-w- c:\windows\SysWow64\iexpress.exe

2013-03-13 22:21 . 2013-03-13 22:21 138752 ----a-w- c:\windows\SysWow64\wextract.exe

2013-03-13 22:21 . 2013-03-13 22:21 73728 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe

2013-03-13 22:21 . 2013-03-13 22:21 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll

2013-03-13 22:21 . 2013-03-13 22:21 38400 ----a-w- c:\windows\SysWow64\imgutil.dll

2013-03-13 22:21 . 2013-03-13 22:21 137216 ----a-w- c:\windows\SysWow64\ieUnatt.exe

2013-03-13 22:21 . 2013-03-13 22:21 12800 ----a-w- c:\windows\SysWow64\mshta.exe

2013-03-13 22:21 . 2013-03-13 22:21 110592 ----a-w- c:\windows\SysWow64\IEAdvpack.dll

2013-03-13 22:21 . 2013-03-13 22:21 61952 ----a-w- c:\windows\SysWow64\tdc.ocx

2013-03-13 22:21 . 2013-03-13 22:21 361984 ----a-w- c:\windows\SysWow64\html.iec

2013-03-13 22:21 . 2013-03-13 22:21 23040 ----a-w- c:\windows\SysWow64\licmgr10.dll

2013-03-13 22:21 . 2013-03-13 22:21 1441280 ----a-w- c:\windows\SysWow64\inetcpl.cpl

2013-03-13 22:21 . 2013-03-13 22:21 762368 ----a-w- c:\windows\system32\ieapfltr.dll

2013-03-13 22:21 . 2013-03-13 22:21 452096 ----a-w- c:\windows\system32\dxtmsft.dll

2013-03-13 22:21 . 2013-03-13 22:21 441856 ----a-w- c:\windows\system32\html.iec

2013-03-13 22:21 . 2013-03-13 22:21 281600 ----a-w- c:\windows\system32\dxtrans.dll

2013-03-13 22:21 . 2013-03-13 22:21 216064 ----a-w- c:\windows\system32\msls31.dll

2013-03-13 22:21 . 2013-03-13 22:21 197120 ----a-w- c:\windows\system32\msrating.dll

2013-03-13 22:21 . 2013-03-13 22:21 1400416 ----a-w- c:\windows\system32\ieapfltr.dat

2013-03-13 22:21 . 2013-03-13 22:21 97280 ----a-w- c:\windows\system32\mshtmled.dll

2013-03-13 22:21 . 2013-03-13 22:21 905728 ----a-w- c:\windows\system32\mshtmlmedia.dll

2013-03-13 22:21 . 2013-03-13 22:21 81408 ----a-w- c:\windows\system32\icardie.dll

2013-03-13 22:21 . 2013-03-13 22:21 62976 ----a-w- c:\windows\system32\pngfilt.dll

2013-03-13 22:21 . 2013-03-13 22:21 599552 ----a-w- c:\windows\system32\vbscript.dll

2013-03-13 22:21 . 2013-03-13 22:21 27648 ----a-w- c:\windows\system32\licmgr10.dll

2013-03-13 22:21 . 2013-03-13 22:21 270848 ----a-w- c:\windows\system32\iedkcs32.dll

2013-03-13 22:21 . 2013-03-13 22:21 247296 ----a-w- c:\windows\system32\webcheck.dll

2013-03-13 22:21 . 2013-03-13 22:21 235008 ----a-w- c:\windows\system32\url.dll

2013-03-13 22:21 . 2013-03-13 22:21 173568 ----a-w- c:\windows\system32\ieUnatt.exe

2013-03-13 22:21 . 2013-03-13 22:21 167424 ----a-w- c:\windows\system32\iexpress.exe

2013-03-13 22:21 . 2013-03-13 22:21 1509376 ----a-w- c:\windows\system32\inetcpl.cpl

2013-03-13 22:21 . 2013-03-13 22:21 149504 ----a-w- c:\windows\system32\occache.dll

2013-03-13 22:21 . 2013-03-13 22:21 144896 ----a-w- c:\windows\system32\wextract.exe

2013-03-13 22:21 . 2013-03-13 22:21 102912 ----a-w- c:\windows\system32\inseng.dll

2013-03-13 22:21 . 2013-03-13 22:21 92160 ----a-w- c:\windows\system32\SetIEInstalledDate.exe

2013-03-13 22:21 . 2013-03-13 22:21 77312 ----a-w- c:\windows\system32\tdc.ocx

2013-03-13 22:21 . 2013-03-13 22:21 52224 ----a-w- c:\windows\system32\msfeedsbs.dll

2013-03-13 22:21 . 2013-03-13 22:21 51200 ----a-w- c:\windows\system32\imgutil.dll

2013-03-13 22:21 . 2013-03-13 22:21 48640 ----a-w- c:\windows\system32\mshtmler.dll

2013-03-13 22:21 . 2013-03-13 22:21 13824 ----a-w- c:\windows\system32\mshta.exe

2013-03-13 22:21 . 2013-03-13 22:21 136192 ----a-w- c:\windows\system32\iepeers.dll

2013-03-13 22:21 . 2013-03-13 22:21 135680 ----a-w- c:\windows\system32\IEAdvpack.dll

2013-03-13 22:21 . 2013-03-13 22:21 12800 ----a-w- c:\windows\system32\msfeedssync.exe

2013-02-12 05:45 . 2013-03-13 14:09 135168 ----a-w- c:\windows\apppatch\AppPatch64\AcXtrnal.dll

2013-02-12 05:45 . 2013-03-13 14:09 350208 ----a-w- c:\windows\apppatch\AppPatch64\AcLayers.dll

2013-02-12 05:45 . 2013-03-13 14:09 308736 ----a-w- c:\windows\apppatch\AppPatch64\AcGenral.dll

2013-02-12 05:45 . 2013-03-13 14:09 111104 ----a-w- c:\windows\apppatch\AppPatch64\acspecfc.dll

2013-02-12 04:48 . 2013-03-13 14:09 474112 ----a-w- c:\windows\apppatch\AcSpecfc.dll

2013-02-12 04:48 . 2013-03-13 14:09 2176512 ----a-w- c:\windows\apppatch\AcGenral.dll

2013-02-12 04:12 . 2013-03-13 22:07 19968 ----a-w- c:\windows\system32\drivers\usb8023.sys

.

.

((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés

REGEDIT4

.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"LightScribe Control Panel"="c:\program files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe" [2009-08-20 2363392]

"HPADVISOR"="c:\program files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe" [2009-09-29 1685048]

"Facebook Update"="c:\users\Pauline-Sophie\AppData\Local\Facebook\Update\FacebookUpdate.exe" [2013-01-27 138096]

"HP Deskjet 3050A J611 series (NET)"="c:\program files\HP\HP Deskjet 3050A J611 series\Bin\ScanToPCActivationApp.exe" [2011-06-08 2676584]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]

"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-08-04 98304]

"HPCam_Menu"="c:\program files (x86)\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe" [2009-05-19 222504]

"QlbCtrl.exe"="c:\program files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2010-02-25 323640]

"Easybits Recovery"="c:\program files (x86)\EasyBits For Kids\ezRecover.exe" [2009-09-02 60464]

"WirelessAssistant"="c:\program files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2009-07-23 498744]

"Sophos AutoUpdate Monitor"="c:\program files (x86)\Sophos\AutoUpdate\almon.exe" [2012-08-08 900160]

"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-01-28 59720]

"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]

"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2013-02-20 152392]

"HP Software Update"="c:\program files (x86)\Hp\HP Software Update\HPWuSchd2.exe" [2011-03-24 49208]

"SpyHunter"="c:\program files (x86)\Enigma Software Group\SpyHunter\SpyHunter.exe" [2007-04-26 2693248]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce]

"GrpConv"="grpconv -o" [X]

.

c:\users\Pauline-Sophie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\

OpenOffice.org 3.3.lnk - c:\program files (x86)\OpenOffice.org 3\program\quickstart.exe [2010-12-13 1198592]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"ConsentPromptBehaviorAdmin"= 5 (0x5)

"ConsentPromptBehaviorUser"= 3 (0x3)

"EnableUIADesktopToggle"= 0 (0x0)

"HideFastUserSwitching"= 0 (0x0)

.

[hkey_local_machine\software\Wow6432Node\microsoft\windows\currentversion\explorer\ShellExecuteHooks]

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]

"LoadAppInit_DLLs"=1 (0x1)

"AppInit_DLLs"=c:\progra~2\Sophos\SOPHOS~1\sophos_detoured.dll

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SAVService]

@="service"

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

@="Driver"

.

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SophosAntiVirus]

"DisableMonitoring"=dword:00000001

.

R1 SAVOnAccess;SAVOnAccess;c:\windows\system32\DRIVERS\savonaccess.sys [2012-07-27 144672]

R2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_960c1f056a541068\AESTSr64.exe [2009-03-02 89600]

R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-08-05 203264]

R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]

R2 ezSharedSvc;Easybits Shared Services for Windows;c:\windows\system32\svchost.exe [2009-07-14 27136]

R2 HP Support Assistant Service;HP Support Assistant Service;c:\program files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [2012-09-27 86528]

R2 hpsrv;HP Service;c:\windows\system32\Hpservice.exe [2011-05-13 30520]

R2 SAVAdminService;Sophos Anti-Virus status reporter;c:\program files (x86)\Sophos\Sophos Anti-Virus\SAVAdminService.exe [2012-09-27 216640]

R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-11-09 160944]

R2 Sophos Web Control Service;Sophos Web Control Service;c:\program files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe [2012-07-27 357400]

R2 swi_service;Sophos Web Intelligence Service;c:\program files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe [2012-09-27 2863168]

R2 swi_update_64;Sophos Web Intelligence Update;c:\programdata\Sophos\Web Intelligence\swi_update_64.exe [2012-08-08 2009152]

R3 Com4QLBEx;Com4QLBEx;c:\program files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2010-02-25 227896]

R3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys [2009-07-21 140712]

R3 netw5v64;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;c:\windows\system32\DRIVERS\netw5v64.sys [2009-06-10 5434368]

R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-08-23 19456]

R3 sdcfilter;sdcfilter;c:\windows\system32\DRIVERS\sdcfilter.sys [2012-07-27 36640]

R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL6.SYS [2009-06-10 292864]

R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV6.SYS [2009-06-10 1485312]

R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT6.SYS [2009-06-10 740864]

R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2012-08-23 57856]

R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2012-07-09 52736]

R3 WatAdminSvc;Service Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe [2010-08-28 1255736]

R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys [2009-06-10 389120]

R4 SophosBootDriver;SophosBootDriver;c:\windows\system32\DRIVERS\SophosBootDriver.sys [2011-02-12 25608]

S2 SAVService;Sophos Anti-Virus;c:\program files (x86)\Sophos\Sophos Anti-Virus\SavService.exe [2012-07-27 139840]

S3 enecir;ENE CIR Receiver;c:\windows\system32\DRIVERS\enecir.sys [2009-06-29 70656]

S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2009-05-23 215040]

S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys [2009-03-09 36408]

.

.

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs

ezSharedSvc

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]

2009-08-20 11:24 451872 ----a-w- c:\program files (x86)\Common Files\LightScribe\LSRunOnce.exe

.

Contenu du dossier 'Tâches planifiées'

.

2013-05-08 c:\windows\Tasks\Adobe Flash Player Updater.job

- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-07-26 08:27]

.

2013-05-08 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-405216875-598066598-2656060311-1000Core.job

- c:\users\Pauline-Sophie\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-11-30 16:36]

.

2013-05-08 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-405216875-598066598-2656060311-1000UA.job

- c:\users\Pauline-Sophie\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-11-30 16:36]

.

2013-05-08 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-10-10 18:42]

.

2013-05-08 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-10-10 18:42]

.

2013-05-08 c:\windows\Tasks\HP Photo Creations Messager.job

- c:\programdata\HP Photo Creations\MessageCheck.exe [2011-02-15 10:11]

.

2013-04-28 c:\windows\Tasks\HPCeeScheduleForHP$.job

- c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2009-10-07 03:22]

.

.

--------- X64 Entries -----------

.

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"SmartMenu"="c:\program files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe" [2009-08-25 610872]

"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-11-14 171520]

"SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2010-03-23 487424]

"Zune Launcher"="c:\program files\Zune\ZuneLauncher.exe" [2011-08-05 163552]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]

"AppInit_DLLs"=c:\progra~2\Sophos\SOPHOS~1\sophos_detoured_x64.dll

.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - LocalService

FontCache

.

------- Examen supplémentaire -------

.

uStart Page = about:blank

uLocal Page = c:\windows\system32\blank.htm

mLocal Page = c:\windows\SysWOW64\blank.htm

uInternet Settings,ProxyOverride = *.local

IE: E&xporter vers Microsoft Excel - c:\progra~2\MICROS~4\Office12\EXCEL.EXE/3000

LSP: c:\programdata\Sophos\Web Intelligence\swi_ifslsp.dll

TCP: DhcpNameServer = 192.168.1.1

DPF: {FAB2BB9D-91E9-457E-9D42-75A7FCCBBC00} - hxxp://www.opticiens-atol.com/pages/collections/adriana/total-immersion/plugin/DFusionHomeWebPlugIn.InstallerFull.exe

FF - ProfilePath - c:\users\Pauline-Sophie\AppData\Roaming\Mozilla\Firefox\Profiles\8ilzesm6.default\

FF - prefs.js: browser.startup.homepage - hxxp://fr.yahoo.com/

FF - prefs.js: keyword.URL - hxxp://search.babylon.com/?affID=111808&tt=3212_6&babsrc=KW_ss&mntrId=224ce0c2000000000000f67bcb5c60a4&q=

FF - prefs.js: network.proxy.type - 0

FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=111808&tt=3212_6

FF - user.js: extensions.BabylonToolbar_i.babExt -

FF - user.js: extensions.BabylonToolbar_i.srcExt - ss

FF - user.js: extensions.BabylonToolbar.tlbrSrchUrl - hxxp://www.google.com/search?babsrc=TB_ggl&q=

FF - user.js: extensions.BabylonToolbar.id - 224ce0c2000000000000f67bcb5c60a4

FF - user.js: extensions.BabylonToolbar.instlDay - 15558

FF - user.js: extensions.BabylonToolbar.vrsn - 1.6.4.6

FF - user.js: extensions.BabylonToolbar.vrsni - 1.6.4.6

FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.6.4.623:30

FF - user.js: extensions.BabylonToolbar.prtnrId - babylon

FF - user.js: extensions.BabylonToolbar.prdct - BabylonToolbar

FF - user.js: extensions.BabylonToolbar.aflt - babsst

FF - user.js: extensions.BabylonToolbar_i.smplGrp - none

FF - user.js: extensions.BabylonToolbar.tlbrId - base

FF - user.js: extensions.BabylonToolbar.instlRef - sst

FF - user.js: extensions.BabylonToolbar.dfltLng - en

FF - user.js: extensions.BabylonToolbar.excTlbr - false

FF - user.js: extensions.BabylonToolbar.admin - false

.

- - - - ORPHELINS SUPPRIMES - - - -

.

Wow6432Node-HKCU-Run-AmazonMP3DownloaderHelper - c:\users\Pauline-Sophie\AppData\Local\Program Files\Amazon\MP3 Downloader\AmazonMP3DownloaderHelper.exe

Wow6432Node-HKLM-Run-DivX Download Manager - c:\program files (x86)\DivX\DivX Plus Web Player\DDmService.exe

Wow6432Node-HKLM-Run-eorezo - (no file)

Wow6432Node-HKLM-Run-<NO NAME> - (no file)

Wow6432Node-HKLM-RunOnce-<NO NAME> - (no file)

HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start

HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe

AddRemove-EasyBits Magic Desktop - c:\windows\system32\ezMDUninstall.exe

AddRemove-SoftwareUpdate_is1 - c:\users\Pauline-Sophie\AppData\Roaming\EoRezo\SoftwareUpdate\unins000.exe

AddRemove-{EE202411-2C26-49E8-9784-1BC1DBF7DE96} - c:\program files (x86)\InstallShield Installation Information\{EE202411-2C26-49E8-9784-1BC1DBF7DE96}\setup.exe

.

.

.

--------------------- CLES DE REGISTRE BLOQUEES ---------------------

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="FlashBroker"

"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_169_ActiveX.exe,-101"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]

"Enabled"=dword:00000001

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]

@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_169_ActiveX.exe"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="IFlashBroker5"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]

@="{00020424-0000-0000-C000-000000000046}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

"Version"="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="FlashBroker"

"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_169_ActiveX.exe,-101"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]

"Enabled"=dword:00000001

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_169_ActiveX.exe"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]

@Denied: (A 2) (Everyone)

@="Shockwave Flash Object"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_169.ocx"

"ThreadingModel"="Apartment"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]

@="0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]

@="ShockwaveFlash.ShockwaveFlash.11"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_169.ocx, 1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]

@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]

@="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

@="ShockwaveFlash.ShockwaveFlash"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]

@Denied: (A 2) (Everyone)

@="Macromedia Flash Factory Object"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_169.ocx"

"ThreadingModel"="Apartment"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]

@="FlashFactory.FlashFactory.1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_169.ocx, 1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]

@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]

@="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

@="FlashFactory.FlashFactory"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="IFlashBroker5"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]

@="{00020424-0000-0000-C000-000000000046}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

"Version"="1.0"

.

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]

@Denied: (Full) (Everyone)

.

Heure de fin: 2013-05-09 00:38:20

ComboFix-quarantined-files.txt 2013-05-08 22:38

.

Avant-CF: 544 620 118 016 octets libres

Après-CF: 545 434 517 504 octets libres

.

- - End Of File - - F0CA2444D59FF8787806F9568151F3D9

Posté(e)

Bonjour,

 

SpyHunter est un logiciel crapuleux, à éviter!

 

On répète de ne pas se servir de ComboFix si cela ne vous est pas demandé expressément, mais vous n'en avez cure... jusqu'au jour où le pc ne fonctionnera plus, à cause d'un bug du tool.

 

Remove System Care Antivirus (Uninstall Guide)

 

1) Télécharge RogueKiller (par Tigzy) sur le bureau

(A partir d'une clé USB si le Rogue empêche l'accès au net) .

Télécharger RogueKiller (Site Officiel)

Quitte tous les programmes en cours

Lance RogueKiller.exe.

 

Sous Vista/Seven/8, faire un clic droit et choisir Exécuter en tant qu'administrateur. Clique sur scan

 

Poste le rapport stp.

 

----------------------------------

 

2) Clique sur Suppression et poste le rapport.

 

@++

Posté(e)

RogueKiller V8.5.4 _x64_ [Mar 18 2013] par Tigzy

mail : tigzyRK<at>gmail<dot>com

Remontees : [RogueKiller] Remontées

Site Web : Télécharger RogueKiller (Site Officiel)

Blog : tigzy-RK

 

Systeme d'exploitation : Windows 7 (6.1.7601 Service Pack 1) 64 bits version

Demarrage : Mode sans echec avec prise en charge reseau

Utilisateur : Pauline-Sophie [Droits d'admin]

Mode : Recherche -- Date : 09/05/2013 13:25:09

| ARK || FAK || MBR |

 

¤¤¤ Processus malicieux : 0 ¤¤¤

 

¤¤¤ Entrees de registre : 4 ¤¤¤

[HJPOL] HKLM\[...]\System : DisableRegistryTools (0) -> TROUVÉ

[HJPOL] HKLM\[...]\Wow6432Node\System : DisableRegistryTools (0) -> TROUVÉ

[HJ DESK] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> TROUVÉ

[HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> TROUVÉ

 

¤¤¤ Fichiers / Dossiers particuliers: ¤¤¤

 

¤¤¤ Driver : [NON CHARGE] ¤¤¤

 

¤¤¤ Fichier HOSTS: ¤¤¤

--> C:\Windows\system32\drivers\etc\hosts

 

127.0.0.1 localhost

 

 

¤¤¤ MBR Verif: ¤¤¤

 

+++++ PhysicalDrive0: WDC WD6400BEVT-60A0RT0 ATA Device +++++

--- User ---

[MBR] abacb5afb30a85dc6c4f45c93d76d2d6

[bSP] fc45442aec06745f596dd8dcbc665ec5 : Windows Vista/7/8 MBR Code

Partition table:

0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 199 Mo

1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 409600 | Size: 596151 Mo

2 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 1221326848 | Size: 14025 Mo

3 - [XXXXXX] FAT32-LBA (0x0c) [VISIBLE] Offset (sectors): 1250050048 | Size: 103 Mo

User = LL1 ... OK!

User = LL2 ... OK!

 

Termine : << RKreport[1]_S_09052013_132509.txt >>

RKreport[1]_S_09052013_132509.txt

Posté(e)

RogueKiller V8.5.4 _x64_ [Mar 18 2013] par Tigzy

mail : tigzyRK<at>gmail<dot>com

Remontees : [RogueKiller] Remontées

Site Web : Télécharger RogueKiller (Site Officiel)

Blog : tigzy-RK

 

Systeme d'exploitation : Windows 7 (6.1.7601 Service Pack 1) 64 bits version

Demarrage : Mode sans echec avec prise en charge reseau

Utilisateur : Pauline-Sophie [Droits d'admin]

Mode : Suppression -- Date : 09/05/2013 13:30:14

| ARK || FAK || MBR |

 

¤¤¤ Processus malicieux : 0 ¤¤¤

 

¤¤¤ Entrees de registre : 3 ¤¤¤

[HJPOL] HKLM\[...]\System : DisableRegistryTools (0) -> SUPPRIMÉ

[HJ DESK] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> REMPLACÉ (0)

[HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REMPLACÉ (0)

 

¤¤¤ Fichiers / Dossiers particuliers: ¤¤¤

 

¤¤¤ Driver : [NON CHARGE] ¤¤¤

 

¤¤¤ Fichier HOSTS: ¤¤¤

--> C:\Windows\system32\drivers\etc\hosts

 

127.0.0.1 localhost

 

 

¤¤¤ MBR Verif: ¤¤¤

 

+++++ PhysicalDrive0: WDC WD6400BEVT-60A0RT0 ATA Device +++++

--- User ---

[MBR] abacb5afb30a85dc6c4f45c93d76d2d6

[bSP] fc45442aec06745f596dd8dcbc665ec5 : Windows Vista/7/8 MBR Code

Partition table:

0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 199 Mo

1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 409600 | Size: 596151 Mo

2 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 1221326848 | Size: 14025 Mo

3 - [XXXXXX] FAT32-LBA (0x0c) [VISIBLE] Offset (sectors): 1250050048 | Size: 103 Mo

User = LL1 ... OK!

User = LL2 ... OK!

 

Termine : << RKreport[2]_D_09052013_133014.txt >>

RKreport[1]_S_09052013_132509.txt ; RKreport[2]_D_09052013_133014.txt

 

J'espère avoir tout bien fait :)

Oui effectivement pour combofix, une fois lancé j'ai regardé un peu sur internet et j'ai eu la trouille :$ . C'était un prof d'informatique qui me l'avait installé, il ne m'avait pas informée des risques et je ne l'avais jamais utilisé. En tout cas maintenant, pour sûr que je ne l'utiliserai plus :)

Posté(e)

BONJOUR.

 

1) Télécharger SFTGC.exe sur le Bureau >>>> il ne peut pas être ailleurs!

 

Sous XP, double cliquer sur le fichier.

Sous les autres versions de Windows, clic droit sur le fichier et choisir Exécuter en tant qu'administrateur.

 

Après l'initialisation, cliquer sur Go pour lancer le nettoyage.

 

Un rapport va s'ouvrir à la fin.

Ce rapport est sur le bureau (SFT.txt)

 

Héberger sur Accueil de Cjoint.com pour ne pas planter le sujet.

 

-----------------------------

2) Télécharge Malwarebytes' Anti-Malware (MBAM).

 

Enregistre l'exécutable sur le bureau. Malwarebytes : Téléchargement gratuit anti-malware, antivirus et anti-espion

 

Télécharger Malwarebytes´ Anti-Malware - Logithèque PC Astuces

 

Attention, ne rien installer d'autre que MBAM car il est parfois proposé des trucs inutiles comme Registry Booster ou autres bêtises. A éviter donc.

A la fin de l'installation, décocher la case proposant l'essai de la version Pro.

 

MBAMPRO.jpg

 

sshot-1-371c28a.jpg

 

Si MBAM est déjà installé, aller directement à la mise à jour puis à l'analyse.

 

Ce logiciel est à garder.

 

Uniquement en cas de problème de mise à jour:

 

Télécharger mises à jour MBAM

 

Exécute le fichier après l'installation de MBAM

 

Connecter les supports amovibles (clés usb etc.) avant de lancer l'analyse.

 

  • Double clique sur le fichier téléchargé pour lancer le processus d'installation.
  • Dans l'onglet "Mise à jour", clique sur le bouton "Recherche de mise à jour": si le pare-feu demande l'autorisation à MBAM de se connecter, accepte.
  • Une fois la mise à jour terminée, rends-toi dans l'onglet "Recherche".
  • Sélectionne "Exécuter un examen complet"
  • Clique sur "Rechercher"
  • L'analyse démarre, le scan est relativement long, c'est normal.
  • A la fin de l'analyse, un message s'affiche :
    L'examen s'est terminé normalement. Clique sur 'Afficher les résultats' pour afficher tous les objets trouvés.
    Clique sur "Ok" pour poursuivre. Si MBAM n'a rien trouvé, il te le dira aussi.
  • Ferme tes navigateurs.
  • Si des malwares ont été détectés, clique sur Afficher les résultats.
    Sélectionne tout (ou laisse coché) et clique sur Supprimer la sélection, MBAM va détruire les fichiers et clés de registre et en mettre une copie dans la quarantaine.
  • MBAM va ouvrir le Bloc-notes et y copier le rapport d'analyse. Copie-colle ce rapport et poste-le dans ta prochaine réponse.

Si MBAM demande à redémarrer le pc, fais-le.

 

Si au redémarrage Windows te dit qu'il a bloqué certains programmes de démarrage, clique sur la bulle puis sur Exécuter les programmes bloqués/Malwarebytes Anti-Malware.

 

@++

Posté(e)

Attention! Si MBAM propose de liquider Notepad.exe, n'en tiens surtout pas compte, il y a un faux-positif à son sujet en ce moment...

 

Il ne faut pas virer ce fichier ou tout au moins ne pas vider la quarantaine avant confirmation.

 

@++

Posté(e)

Bon visiblement ça fonctionne!!! Alors je vous remercie beaucoup!!!! Z'êtes géniaux :D

Euh par contre que dois-je faire des rapports et des logiciels installés? Je garde MBAM, mais Roguekiller et SFTGC ?

Rejoindre la conversation

Vous pouvez publier maintenant et vous inscrire plus tard. Si vous avez un compte, connectez-vous maintenant pour publier avec votre compte.
Remarque : votre message nécessitera l’approbation d’un modérateur avant de pouvoir être visible.

Invité
Répondre à ce sujet…

×   Collé en tant que texte enrichi.   Coller en tant que texte brut à la place

  Seulement 75 émoticônes maximum sont autorisées.

×   Votre lien a été automatiquement intégré.   Afficher plutôt comme un lien

×   Votre contenu précédent a été rétabli.   Vider l’éditeur

×   Vous ne pouvez pas directement coller des images. Envoyez-les depuis votre ordinateur ou insérez-les depuis une URL.

  • En ligne récemment   0 membre est en ligne

    • Aucun utilisateur enregistré regarde cette page.
×
×
  • Créer...