FORUM D’ENTRAIDE INFORMATIQUE (FEI)
Site d’assistance et de sécurité informatique

Aide à la désinfection (pages publicitaires, moteur de recherche remplacé, redirections, virus...).
Règles du forum : Entraide concernant la désinfection et la sécurité informatique : en cas de publicités intempestives, pop-up, redirections, logiciels indésirables, ralentissements suspects, virus, etc.
Une désinfection complète vous sera assurée : désinfection, sécurisation, puis prévention.
Seuls les helpers (personnes qualifiées et formées à la désinfection) ainsi que le staff sont autorisés à apporter leur aide dans cette section.
Merci également de prendre connaissance de la charte générale du forum.
  • Avatar du membre
  • Avatar du membre
#107799
Bonjour,

Depuis 3 semaines , mon pc m'ouvre des fenêtres de pub intempestives et certaines pages contiennent en en-tête " rvzr-a.akamaihd.net"

J'ai essayé de suivre les procédures décrites dans les forum concernant la suppression de ce virus mais rien n'y fait.

J'ai successivement utilisé ADW cleaner ,puis Junkware removal tool et enfin Malwarebiyte antimalware.

Pour la suite il est indiqué qu'il faut  réinitialiser les navigateurs mais là je bloque.

une âme charitable peut elle m'aider à supprimer ce virus coriace ?

Christophe
#108127
Bonsoir,

Je viens juste de rentrer du travail .
Voici les 3 rapports demandés :

# AdwCleaner v3.015 - Rapport créé le 24/02/2014 à 15:53:27
# Mis à jour le 10/12/2013 par Xplode
# Système d'exploitation : Windows 7 Home Premium Service Pack 1 (64 bits)
# Nom d'utilisateur : christophe - CHRISTOPHE-HP
# Exécuté depuis : C:\Users\christophe\Desktop\Sécurité\adwcleaner (3).exe
# Option : Nettoyer

***** [ Services ] *****


***** [ Fichiers / Dossiers ] *****


***** [ Raccourcis ] *****


***** [ Registre ] *****


***** [ Navigateurs ] *****

-\\ Internet Explorer v11.0.9600.16518


-\\ Google Chrome v31.0.1650.63

[ Fichier : C:\Users\christophe\AppData\Local\Google\Chrome\User Data\Default\preferences ]

Supprimée : icon_url
Supprimée : search_url
Supprimée : suggest_url

*************************

AdwCleaner[R0].txt - [15264 octets] - [24/11/2013 23:33:59]
AdwCleaner[R10].txt - [2127 octets] - [29/01/2014 19:04:11]
AdwCleaner[R11].txt - [2185 octets] - [02/02/2014 11:08:40]
AdwCleaner[R12].txt - [2307 octets] - [17/02/2014 18:59:14]
AdwCleaner[R13].txt - [2430 octets] - [24/02/2014 15:51:41]
AdwCleaner[R1].txt - [4064 octets] - [20/12/2013 20:48:31]
AdwCleaner[R2].txt - [1467 octets] - [20/12/2013 21:39:09]
AdwCleaner[R3].txt - [1327 octets] - [20/12/2013 21:58:35]
AdwCleaner[R4].txt - [1505 octets] - [30/12/2013 14:10:56]
AdwCleaner[R5].txt - [1853 octets] - [04/01/2014 16:13:53]
AdwCleaner[R6].txt - [1973 octets] - [12/01/2014 23:35:22]
AdwCleaner[R7].txt - [2299 octets] - [18/01/2014 12:54:25]
AdwCleaner[R8].txt - [1795 octets] - [18/01/2014 13:08:22]
AdwCleaner[R9].txt - [1915 octets] - [18/01/2014 13:44:55]
AdwCleaner[S0].txt - [11938 octets] - [24/11/2013 23:35:33]
AdwCleaner[S10].txt - [2231 octets] - [02/02/2014 11:10:41]
AdwCleaner[S11].txt - [2353 octets] - [17/02/2014 19:49:39]
AdwCleaner[S12].txt - [1793 octets] - [24/02/2014 15:53:27]
AdwCleaner[S1].txt - [3603 octets] - [20/12/2013 21:04:22]
AdwCleaner[S2].txt - [1470 octets] - [20/12/2013 21:40:52]
AdwCleaner[S3].txt - [1390 octets] - [20/12/2013 22:06:44]
AdwCleaner[S4].txt - [1506 octets] - [30/12/2013 14:12:18]
AdwCleaner[S5].txt - [1814 octets] - [04/01/2014 16:16:27]
AdwCleaner[S6].txt - [1934 octets] - [12/01/2014 23:37:29]
AdwCleaner[S7].txt - [2264 octets] - [18/01/2014 12:56:42]
AdwCleaner[S8].txt - [1856 octets] - [18/01/2014 13:09:47]
AdwCleaner[S9].txt - [2172 octets] - [29/01/2014 19:06:02]

########## EOF - C:\AdwCleaner\AdwCleaner[S12].txt - [2394 octets] ##########

Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.2 (02.20.2014:1)
OS: Windows 7 Home Premium x64
Ran by christophe on 24/02/2014 at 16:00:37,20
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{039ACC03-903E-4737-A3EC-90FA641C96E5}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{4409EB3B-F970-4507-8239-F2B6E2179AE1}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{039ACC03-903E-4737-A3EC-90FA641C96E5}



~~~ Files



~~~ Folders

Successfully deleted: [Folder] "C:\Users\christophe\appdata\local\software"
Successfully deleted: [Folder] "C:\Users\christophe\appdata\locallow\datamngr"
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{0042F8E1-0DC8-47B4-BB44-3342259F0613}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{01DC3B6F-C42F-4508-875D-AF98D902AF1A}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{03D901CE-211B-4364-9665-31B43335428D}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{04D348E9-3C21-4AAD-A8E5-B9EF3662AF1E}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{059443F7-E804-4CD4-852B-8F3D636AFF54}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{07387021-CD85-4359-810F-C763452DBA06}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{08CED47A-5208-402B-B954-7C4C8CC5ADEB}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{090AA826-ABE7-4819-ACB8-D73CB5811351}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{0BD63647-2115-42EE-B2CD-0DC683C29734}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{0E61390F-4A3F-4A66-B3C7-C635F4DF1B3C}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{11FBB185-8A46-4545-8814-84A76D7BFF47}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{122258C2-2156-4803-9BBE-2C6B3D175F51}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{140CEC1E-7568-48FA-90B4-71D109E3F7A6}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{174B6372-D37D-478E-A2A1-E272DBC7FAF6}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{178C36F3-030D-4C7D-A992-E92E9E0EAB65}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{1A23AEE0-41D5-42EC-9F7E-FA5D0ADD001E}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{1B6926D7-E397-4960-AC09-3BEDA5E15287}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{1C5844B0-40E2-4292-A5BC-8DF79C8F0645}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{1CD98676-D55A-41EB-873B-3A0EC54A22A4}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{1F5DA09E-C6C0-4DE8-B474-BA11843836B6}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{1FE792A4-F950-4AA8-B953-9FA3D165615D}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{21B2CA96-5BDB-40D5-AEB9-91E65BF6FA60}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{24055162-AEEA-4453-BA46-E81FCEF5078B}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{24347736-04B9-48F8-B4B3-A90F5DB2C88E}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{262CC1BC-B3D6-4AD4-9104-29B6DE4DA7B4}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{27A1DE88-96D9-40D2-8E54-857B08E7B533}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{2AC1F37E-6CAA-4B79-80B9-947BA0CE1344}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{2D61CEF4-BC13-4A7C-8C6D-9623F1863D0F}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{2E00C81C-4240-4975-A4B1-7BB3BFFC13E7}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{2FE38F8B-904A-4238-B9F7-12C9876A657A}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{309C308C-20AC-4013-B5C1-7D1F33315649}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{31B6CC15-0E69-47BF-A42C-52905E6F3D82}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{3352CC9B-36FB-4324-96AE-88F914EEBFD6}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{34015E0D-EBC5-4711-9F4F-B68D818949D2}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{34796AE6-68B9-4BA9-B8C0-38D39FB6F888}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{347EF920-E41A-4913-91E1-9CD74D6E6AF8}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{3487DF01-E746-4CEB-B613-7490F6556994}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{3637315A-0219-4312-99A9-A92EC9FBDA18}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{37DE7850-039B-47FA-B7F4-4256B1BF18F1}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{388E0AA3-E943-4184-A608-6DAB3587EAC9}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{38CF816D-934C-4909-B6F8-16BF8CD7A435}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{390336C9-91D5-4225-A282-2E720C43F320}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{392777FA-7BC7-449B-A669-D3B08E2FC034}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{39B915A7-E85F-4120-AD8D-8F302C741FFA}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{3B199827-AA1E-42E5-9E0C-C65662644D47}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{3B451C0C-7157-49E7-AD2B-AC67F0A3F8A7}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{3CBBB489-CDDA-41EA-941A-F21E3FC6DA2B}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{3E47365C-9797-413C-8276-C6DF71B596BA}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{3EDD3A6D-03EA-4E73-A431-02650FF9E6BD}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{3FF45517-5D3D-447D-9E7E-634EE9E39528}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{45581557-F8C9-48FC-B888-62690AEC3047}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{45EE2AB8-F994-40A8-AF04-980FA96C91EE}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{4764E5C6-9009-44B7-86BF-D2E30C4DDB91}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{4795361B-47D5-48CB-A64B-29FEAA4AFE4F}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{486CC1B1-6FE5-4F64-8890-351F9835271A}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{4BCDED08-86E2-4E33-A4ED-F674E8225484}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{4CDA7D40-5EB8-41C7-8644-4626B9F7A57B}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{4D1A35D0-BF12-4B7A-9A6A-AA790CF0FC2F}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{4DF52171-B8B9-49BE-9DBD-90B46BAA8924}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{4FED33D5-459E-4268-AD42-77A4BFC6729A}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{52357F33-622A-4FCB-A70E-1B06CDE7CC92}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{548AA05B-EDF5-4796-BF0A-F53481A95574}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{566AA1EF-4FDB-46EB-968B-0210DB7994A5}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{56BBF56A-563D-4510-92B9-46717AF75261}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{578046DE-A5AF-44D2-B062-1E47BA6D19EA}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{585ACC01-A35E-4CB1-B738-D313435900D6}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{5A597384-7285-4A2F-A51E-D9C63EA2437A}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{5B9609D9-6B44-4DDD-AB1A-DF13A6266C9D}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{5E1A90F7-8763-457A-A859-E2FDE2E3F5EE}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{5E5A6F7F-D809-4D97-9118-4E94A4FBBE8D}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{5F8DAC37-7145-4D60-A4A3-3C567C2EEFD0}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{62A9353C-B401-47D3-8AB8-9E6DF4D16209}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{63A7986F-1F9F-492D-8CC1-D76F9B56D50E}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{64C68582-5A0F-473F-BDDC-3E02D91BD7C9}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{67FEA657-B9A3-40B4-96F6-88F785D25733}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{6B32F1DA-8963-4ECC-8F5E-98894DEC930C}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{6B6046C7-7A8F-400A-A6B1-C1903591C5E6}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{6C61D737-630D-486D-9424-CC3BD3D5E94B}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{6EA87408-6C78-44DE-B826-0BB4281E0B76}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{6F1C8D6C-5337-44F2-B59D-F07EAE28B1D7}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{705B97F1-FA11-4854-9613-7F09267A80FF}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{70C9901A-D7B0-4C86-8B14-A28C1FB0380F}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{71F81934-8AD4-439D-BE01-B01392F2B75C}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{7282AC1E-9F54-4BB3-B1B7-56DDC2927D5F}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{758D4B32-EDBB-4186-B2B4-125CB548892B}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{75B338EE-AA99-4713-A726-0D9FB424F30C}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{76CAB0CF-ADB8-4CAB-93F4-4AA3E8D9224E}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{77F20E90-16CC-4D3F-B575-331E66765608}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{780EFBC8-BB14-421D-B787-BF6EBC056EB8}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{7AFD4E45-CA50-4C10-9366-40BF2B7C9E7A}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{7FFCF619-343F-4769-BA8F-65BDFF4488EA}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{8018049F-F8D9-485C-B086-E6D8E18A76E2}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{80940568-6E44-4851-80F6-FEC11F008B8A}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{81A3E659-ECFE-4E7F-9BEC-77D7E4DA8E28}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{83475848-F90D-4647-9010-DA3EAC1D7B5C}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{836CF593-6010-4D2F-9BDC-89F3D3FFDABE}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{87064EED-9205-4E10-85D4-62CC03F04050}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{87A30421-9F4A-41A0-8AE1-68609E97F274}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{87C8CB4A-8055-4F61-A299-2A7948B16643}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{87E1EDDE-4155-4CD0-8FAA-381EDEC04C7E}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{8BDA76C0-07E0-4CFD-B66C-A0F22EF91A05}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{8BE996F9-3684-47CB-9E8A-982CCBB73211}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{8DC2A117-FB20-4910-8B06-3E5E5E490266}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{8F0973D4-C1DF-466E-8CE1-7AC302915F35}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{901C7070-8527-4CA7-A32B-FC8F3987A7AE}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{91C4E5A2-1548-483A-9393-9DC5834FABB7}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{92623747-F443-4671-A711-F1F2ED009E87}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{92C0D7F6-BF20-4EF1-B408-6603886F68FC}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{9322432E-39C1-4B5A-A997-269D18782FC4}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{94799E47-C6F1-4292-8416-AFD996615BB5}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{95797F6F-7FD3-46F6-9E9C-9C25CA2918ED}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{96E065F2-0FDE-4C42-9679-8C306526832F}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{978F7EDA-4D02-46E0-BB8D-15592E8D36E2}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{9A8E3F33-B5B3-47CF-AA82-B4BBE3C88879}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{9B71D843-103A-4302-832C-656B99063653}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{9B949810-25C2-432C-BD0E-5E9BCD73FBA3}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{9DB97CAF-0A85-44F4-84F0-A7911015ACFD}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{9E92FBD5-4BF9-4879-A86A-61480291952E}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{A1821D30-86D6-46CB-97C6-78635A327EB6}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{A45B0B06-B76B-4ED4-8547-188285D75883}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{A5460920-232A-43DA-A011-5943D7BABD76}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{A71768A4-0272-41E3-A84B-CE16908584F4}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{A7FA4F34-3205-40BE-90B1-93F69E23CAA1}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{A89AAFBB-BEB4-4004-A03E-BD9CE3415FC1}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{AC075723-B9AD-4741-9610-1242DC2B16B6}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{AD0A527E-D76F-4C85-AD1E-BD304556394E}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{AE1CBCCE-2278-42E1-AE42-7779E9EFEE8D}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{AE9C8946-7B09-4C64-97CB-9F75E9D4F8CF}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{B05DE740-8DF0-41F2-9FB2-81E0DB1C035B}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{B3EA20F9-20AE-4477-820B-F40FDB52CD45}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{B4AB0E2A-BFCC-44E8-A28C-B452E8C0FA3E}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{B552EDCE-9C6E-44FD-BB6C-9FC132A48C2A}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{B7787F56-F339-4DBE-852C-163346EFEFBF}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{B7ED6701-B960-41D0-88E0-C1F23DB08EDF}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{B9828053-F3B8-46FC-90B7-5C94C009C861}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{BBA0FEEA-FE77-4ACA-B972-9DBD31B15B11}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{BD31E38E-1910-42D4-A160-AF7E9F862FD9}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{BDA67B3B-6AA2-4C8C-BFE6-F9856262C9A8}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{C3F376D9-70D9-4771-8C12-22A2AD320FDA}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{C460FBD7-DFFC-44AC-AA0C-516BAB185A53}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{C55316BD-4E00-4E9D-B0F8-1E4C751DD42C}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{C6498EA3-6DA4-4F67-B61F-BF9CD5B3333E}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{C7C8A500-ADDC-47BE-AF31-9191FA2FBE09}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{C9776769-F5B9-45E2-9241-7A1AD8576482}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{C9BCD51E-9D41-412D-A22E-8F2B0EA789D9}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{C9D6A245-8FF4-474A-BF9A-F82836AB94CA}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{CA91B5FD-0797-43F0-9E9A-9A292B771E97}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{CCA15CA2-0A23-4136-918F-3CE8E132F78C}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{D18FFFC3-22D5-4C11-B2EF-FB3C382B348D}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{D1C29C22-A6A3-488E-88D0-DE12381D2C09}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{D20D6BF5-60E6-434D-9E0D-4477C743F5DF}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{D8227870-E9C6-4D22-A18E-E265CE0B4551}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{DB108999-42ED-49F3-BAF3-3F1C423EE2B6}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{DCEEB4FD-4D58-4236-B18C-FEDC51AA0F81}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{DEF5A37E-524F-4B11-B6C6-4B847B65F457}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{DFD6EE66-9D8D-419B-97A4-448BF75D63AF}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{E0BC1B07-D2BB-4A34-B05A-14E0EB87D36C}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{E2EB1311-FCBA-418E-BC4A-F50D7DC8E501}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{E3624943-9A6C-4C08-B4BF-ABBFE67C7240}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{E4C7FB8F-385F-41BB-AFA7-32BE61FB7981}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{E52A2885-1980-4B22-B538-1BFE8067DA2C}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{E5DA118E-0655-4764-9896-BC42301D3082}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{E6777EF4-A48B-4488-B3C6-A64CFEC60993}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{E7563FC1-8C49-4F89-B03C-11E2E2A53ED7}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{E7BC21F7-E801-4475-AEF2-6C65D1DFC08C}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{EC2E4467-57FD-44FB-A8AD-067F00A15131}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{EC3531E2-8D43-4632-8690-74475C843DDA}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{ED9FB080-274A-489E-B247-B0B7D1F05EE6}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{F0814CE0-0E9C-4E5B-A51D-F3F1102038BB}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{F1697EEE-7F4E-416B-B68D-1260458099E6}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{F23AE391-B62C-425C-B04F-D372AD2A92E9}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{F24978F2-9631-47EC-B909-6684938D2852}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{F39AB42E-1AD5-452D-AA7C-4872FCEA62F8}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{FB62D8BE-9303-4D8F-A87E-1BEEC719F22F}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{FC9048E6-AC84-457C-BE1A-23422C494D74}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{FD748F63-1936-4DC8-9B46-82D922E1D7D2}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{FEE0F354-C20A-4D83-B826-0FC3135CE498}
Successfully deleted: [Empty Folder] C:\Users\christophe\appdata\local\{FF8B0AB4-B5E5-48C2-84F5-C646805E911F}



~~~ Chrome

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Google\Chrome\Extensions\aaaaabcbmongicmdegkmmfgdickgnnob



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 24/02/2014 at 16:15:39,68
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Malwarebytes Anti-Malware 1.75.0.1300
http://www.malwarebytes.org

Version de la base de données: v2014.02.02.02

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 11.0.9600.16518
christophe :: CHRISTOPHE-HP [administrateur]

24/02/2014 16:22:36
mbam-log-2014-02-24 (16-22-36).txt

Type d'examen: Examen rapide
Options d'examen activées: Mémoire | Démarrage | Registre | Système de fichiers | Heuristique/Extra | Heuristique/Shuriken | PUP | PUM
Options d'examen désactivées: P2P
Elément(s) analysé(s): 206956
Temps écoulé: 6 minute(s), 2 seconde(s)

Processus mémoire détecté(s): 0
(Aucun élément nuisible détecté)

Module(s) mémoire détecté(s): 0
(Aucun élément nuisible détecté)

Clé(s) du Registre détectée(s): 0
(Aucun élément nuisible détecté)

Valeur(s) du Registre détectée(s): 0
(Aucun élément nuisible détecté)

Elément(s) de données du Registre détecté(s): 0
(Aucun élément nuisible détecté)

Dossier(s) détecté(s): 0
(Aucun élément nuisible détecté)

Fichier(s) détecté(s): 0
(Aucun élément nuisible détecté)

(fin)

ET VOILA !!

Christophe
#108211
Je n'ai pas réussi à supprimer ADW mais je pense en avoir téléchargée une nouvelle.
Voici les 2 rapports demandés :

# AdwCleaner v3.019 - Rapport créé le 25/02/2014 à 22:01:15
# Mis à jour le 17/02/2014 par Xplode
# Système d'exploitation : Windows 7 Home Premium Service Pack 1 (64 bits)
# Nom d'utilisateur : christophe - CHRISTOPHE-HP
# Exécuté depuis : C:\Users\christophe\Downloads\adwcleaner (8).exe
# Option : Nettoyer

***** [ Services ] *****


***** [ Fichiers / Dossiers ] *****


***** [ Raccourcis ] *****


***** [ Registre ] *****

Clé Supprimée : HKLM\Software\caphyon

***** [ Navigateurs ] *****

-\\ Internet Explorer v11.0.9600.16518


-\\ Google Chrome v31.0.1650.63

[ Fichier : C:\Users\christophe\AppData\Local\Google\Chrome\User Data\Default\preferences ]

Supprimée : icon_url
Supprimée : search_url
Supprimée : suggest_url

*************************

AdwCleaner[R0].txt - [15264 octets] - [24/11/2013 23:33:59]
AdwCleaner[R10].txt - [2127 octets] - [29/01/2014 19:04:11]
AdwCleaner[R11].txt - [2185 octets] - [02/02/2014 11:08:40]
AdwCleaner[R12].txt - [2307 octets] - [17/02/2014 18:59:14]
AdwCleaner[R13].txt - [2430 octets] - [24/02/2014 15:51:41]
AdwCleaner[R14].txt - [2583 octets] - [25/02/2014 21:58:58]
AdwCleaner[R1].txt - [4064 octets] - [20/12/2013 20:48:31]
AdwCleaner[R2].txt - [1467 octets] - [20/12/2013 21:39:09]
AdwCleaner[R3].txt - [1327 octets] - [20/12/2013 21:58:35]
AdwCleaner[R4].txt - [1505 octets] - [30/12/2013 14:10:56]
AdwCleaner[R5].txt - [1853 octets] - [04/01/2014 16:13:53]
AdwCleaner[R6].txt - [1973 octets] - [12/01/2014 23:35:22]
AdwCleaner[R7].txt - [2299 octets] - [18/01/2014 12:54:25]
AdwCleaner[R8].txt - [1795 octets] - [18/01/2014 13:08:22]
AdwCleaner[R9].txt - [1915 octets] - [18/01/2014 13:44:55]
AdwCleaner[S0].txt - [11938 octets] - [24/11/2013 23:35:33]
AdwCleaner[S10].txt - [2231 octets] - [02/02/2014 11:10:41]
AdwCleaner[S11].txt - [2353 octets] - [17/02/2014 19:49:39]
AdwCleaner[S12].txt - [2475 octets] - [24/02/2014 15:53:27]
AdwCleaner[S13].txt - [1947 octets] - [25/02/2014 22:01:15]
AdwCleaner[S1].txt - [3603 octets] - [20/12/2013 21:04:22]
AdwCleaner[S2].txt - [1470 octets] - [20/12/2013 21:40:52]
AdwCleaner[S3].txt - [1390 octets] - [20/12/2013 22:06:44]



Puis:

¤¤¤¤¤¤¤¤¤¤ | Shortcut_Module | g3n-h@ckm@n | 25.02.2014.5

¤¤¤¤¤ XP | Vista | 7 | 8 - 32/64 bits ¤¤¤¤¤ - Start 22:22:19 - 25/02/2014

Mis à jour le : 25/02/2014 | 15.15 par g3n-h@ckm@n

Contact : http://www.sosvirus.net

Boot : Normal

Système : Windows 7 Home Premium (64 bits) HomePremium Service Pack 1

Mémoire RAM = Total (MB) : 3647 | Libre (MB) : 1672
Pagefile = Total (MB) : 7292 | Libre (MB) : 4793
Virtuelle = Total (MB) : 4194 | Libre (MB) : 4043


Registre sauvegardé , pour restaurer : C:\Shortcut_Module\Save\Clean\ERDNT.exe

¤¤¤¤¤¤¤¤¤¤ | Mises à jour Windows

Aucune mise à jour détectée !!!

¤¤¤¤¤¤¤¤¤¤ | Processus tués

784 | C:\PROGRA~1\ENIGMA~1\SPYHUN~1\SH4SER~1.EXE (.Enigma Software Group USA, LLC. - Service scanner interface.) - (1.1.42.90) - C:\PROGRA~1\ENIGMA~1\SPYHUN~1\SH4SER~1.EXE
868 | C:\Windows\system32\atiesrxx.exe (.AMD - AMD External Events Service Module.) - (6.14.11.1096) - C:\Windows\system32\atiesrxx.exe
512 | C:\Program Files\IDT\WDM\STacSV64.exe (.IDT, Inc. - IDT PC Audio.) - (1.0.6319.0) - "C:\Program Files\IDT\WDM\STacSV64.exe"
1328 | C:\Program Files (x86)\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe (.Cisco Systems, Inc. - VPN Agent Service.) - (2.4.1012.0) - "C:\Program Files (x86)\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe"
1380 | C:\Windows\system32\atieclxx.exe (.AMD - AMD External Events Client Module.) - (6.14.11.1096) - atieclxx
1692 | C:\Windows\System32\spoolsv.exe (.Microsoft Corporation - Application sous-système spouleur.) - (6.1.7601.17777) - C:\Windows\System32\spoolsv.exe
1896 | C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) - (1.701.3.3014) - "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
1936 | C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe (.Advanced Micro Devices, Inc. - Service Fusion Utility.) - (1.0.0.0) - "C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe" /launchService
1960 | C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (.Apple Inc. - MobileDeviceService.) - (17.96.2.2) - "C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe"
2000 | C:\Program Files\Bonjour\mDNSResponder.exe (.Apple Inc. - Bonjour Service.) - (3.0.0.10) - "C:\Program Files\Bonjour\mDNSResponder.exe"
332 | C:\Windows\SysWOW64\ezSharedSvcHost.exe (.EasyBits Software AS - Shared EasyBits services for Windows.) - (5.0.0.101) - C:\Windows\SysWOW64\ezSharedSvcHost.exe
1556 | C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe (.Hewlett-Packard Company - HP Client Services.) - (1.1.0.3539) - "C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe"
1580 | C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe (.Hewlett-Packard Company - HP Quick Synchronization Service.) - (6.1.16.1) - "C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe"
1020 | C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe (.Hewlett-Packard Development Company, L.P. - HP Quick Launch WMI Service.) - (2.7.1.0) - "C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe"
2076 | C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe (.Realsil Microelectronics Inc. - Realtek Card Reader Icon Tool..) - (1.3.4.1) - "C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe"
2128 | C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE (.Microsoft Corporation - Microsoft SeaPort Search Enhancement Broker.) - (3.1.158.0) - "C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE"
2300 | C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (.Microsoft Corp. - Microsoft® Windows Live ID Service.) - (7.250.4232.0) - "C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
2476 | C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (.Microsoft Corp. - Microsoft® Windows Live ID Service Monitor.) - (7.250.4232.0) - WLIDSvcM.exe 2300
2992 | C:\Windows\system32\taskhost.exe (.Microsoft Corporation - Processus hôte pour Tâches Windows.) - (6.1.7601.18010) - "taskhost.exe"
2344 | C:\Windows\Explorer.EXE (.Microsoft Corporation - Explorateur Windows.) - (6.1.7601.17567) - C:\Windows\Explorer.EXE
2812 | C:\Windows\system32\taskeng.exe (.Microsoft Corporation - Moteur du Planificateur de tâches.) - (6.1.7601.17514) - taskeng.exe {774F6BAD-9570-4146-8670-A8709294308B}
3376 | C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (.Synaptics Incorporated - Synaptics TouchPad Enhancements.) - (15.3.11.0) - "C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
3384 | C:\Program Files\IDT\WDM\sttray64.exe (.IDT, Inc. - IDT PC Audio.) - (1.0.6319.0) - "C:\Program Files\IDT\WDM\sttray64.exe"
3420 | C:\Windows\System32\ico.exe (.Primax Electronics Ltd. - Mouse Suite 98 Daemon.) - (1.0.1.4) - "C:\Windows\System32\ico.exe"
3444 | C:\Program Files\Hewlett-Packard\HP LaunchBox\HPTaskBar1.exe (. - HP Taskbar Process HP.) - (1.0.11.0) - "C:\Program Files\Hewlett-Packard\HP LaunchBox\HPTaskBar1.exe"
3456 | C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe (.Microsoft Corporation - Windows Live Messenger.) - (15.4.3555.308) - "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
3576 | C:\Program Files\Hewlett-Packard\HP LaunchBox\HPTaskBar2.exe (.Hewlett-Packard Development Company, L.P. - HP Taskbar Process TP.) - (1.0.11.0) - "C:\Program Files\Hewlett-Packard\HP LaunchBox\HPTaskBar2.exe"
3972 | C:\Windows\System32\Pelmiced.exe (.Primax Electronics Ltd. - Mouse Suite 98 Daemon.) - (1.1.1.0) - Pelmiced.exe
3992 | C:\Program Files (x86)\Skype\Phone\Skype.exe (.Skype Technologies S.A. - Skype .) - (6.11.0.102) - "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
4052 | C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (.Synaptics Incorporated - Synaptics Pointing Device Helper.) - (15.3.11.0) - "C:\Program Files\Synaptics\SynTP\SynTPHelper.exe"
2848 | C:\Windows\system32\SearchIndexer.exe (.Microsoft Corporation - Indexeur Microsoft Windows Search.) - (7.0.7601.17610) - C:\Windows\system32\SearchIndexer.exe /Embedding
3436 | C:\Program Files (x86)\CineForm\Tools\GoProCineFormStatusViewer.exe (.GoPro - GoPro/CineForm Status Viewer.) - (1.0.0.0) - "C:\Program Files (x86)\CineForm\Tools\GoProCineFormStatusViewer.exe"
3596 | C:\Program Files (x86)\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe (.Hewlett-Packard - hpotdd01.) - (1.0.0.1) - "C:\Program Files (x86)\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe"
1856 | C:\Program Files\Windows Media Player\wmpnetwk.exe (.Microsoft Corporation - Service Partage réseau du Lecteur Windows Media.) - (12.0.7601.17514) - "C:\Program Files\Windows Media Player\wmpnetwk.exe"
4072 | C:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe (.Hewlett-Packard Company - HP QuickWeb Utilities.) - (3.1.0.9742) - "C:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe"
3720 | C:\Program Files (x86)\iTunes\iTunesHelper.exe (.Apple Inc. - iTunesHelper.) - (11.0.2.26) - "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
1128 | C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe (.Hewlett-Packard Development Company, L.P. - HP Message Service.) - (2.7.2.0) - "C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe"
3564 | C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe (.Hewlett-Packard Development Company, L.P. - HP On Screen Display.) - (1.3.5.0) - "C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe"
1844 | C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (.Oracle Corporation - Java(TM) Update Scheduler.) - (2.1.9.8) - "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
4196 | C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe (.CyberLink - YouCam Mirage.) - (1.0.0.526) - "C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe"
4576 | C:\Program Files\iPod\bin\iPodService.exe (.Apple Inc. - iPodService Module (64-bit).) - (11.0.2.26) - "C:\Program Files\iPod\bin\iPodService.exe"
5252 | C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe (.Hewlett-Packard Company - HP Software Framework WMI Service.) - (6.1.16.1) - "C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe"
6096 | C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (.Advanced Micro Devices Inc. - Catalyst Control Center: Monitoring program.) - (2.0.0.0) - "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM"
5268 | C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (.ATI Technologies Inc. - Catalyst Control Center: Host application.) - (3.5.0.0) - "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
5944 | C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe (.Hewlett-Packard Company - HP Support Assistant Service.) - (7.2.45.3) - "C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe"
4536 | C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe (.Microsoft Corporation - PresentationFontCache.exe.) - (3.0.6920.5011) - C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
4788 | C:\Program Files (x86)\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe (.Hewlett-Packard Co. - HP OfficeJet COM Device Objects.) - (4.2.0.20) - "C:\Program Files (x86)\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe"
5688 | C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (.Google Inc. - Google Chrome.) - (31.0.1650.63) - "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "http://zimbra.free.fr/zimbra/mail"
168 | C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (.Google Inc. - Google Chrome.) - (31.0.1650.63) - "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="5688.0.1334103391\587172663" --supports-dual-gpus=false --gpu-driver-bug-workarounds=0,3,12,22 --gpu-vendor-id=0x1002 --gpu-device-id=0x9643 --gpu-driver-vendor="ATI Technologies Inc." --gpu-driver-version=8.861.1.2000 --ignored=" --type=renderer " /prefetch:822062411
5980 | C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (.Google Inc. - Google Chrome.) - (31.0.1650.63) - "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=fr --force-fieldtrials="AutocompleteDynamicTrial_2/DefaultControl_R2_Stable/BrowserPreReadExperiment/100-pct-default/CookieRetentionPriorityStudy/ExperimentOn/DeferBackgroundExtensionCreation/RateLimited/ForceCompositingMode/thread/InstantExtended/Group2 pct:10a stable:r5 use_remote_ntp_on_startup:1 espv:210 suppress_on_srp:1/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_05/UMA-Uniformity-Trial-1-Percent/group_81/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_02/UMA-Uniformity-Trial-5-Percent/default/UMA-Uniformity-Trial-50-Percent/group_01/" --enable-threaded-compositing --renderer-print-preview --instant-process --disable-html-notifications --channel="5688.1.622550215\919316875" /prefetch:673131151
5008 | C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (.Google Inc. - Google Chrome.) - (31.0.1650.63) - "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=fr --force-fieldtrials="AutocompleteDynamicTrial_2/DefaultControl_R2_Stable/BrowserPreReadExperiment/100-pct-default/CookieRetentionPriorityStudy/ExperimentOn/DeferBackgroundExtensionCreation/RateLimited/ForceCompositingMode/thread/InstantExtended/Group2 pct:10a stable:r5 use_remote_ntp_on_startup:1 espv:210 suppress_on_srp:1/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_05/UMA-Uniformity-Trial-1-Percent/group_81/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_02/UMA-Uniformity-Trial-5-Percent/default/UMA-Uniformity-Trial-50-Percent/group_01/" --enable-threaded-compositing --renderer-print-preview --disable-html-notifications --channel="5688.2.2087746950\422549625" /prefetch:673131151
5396 | C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (.Google Inc. - Google Chrome.) - (31.0.1650.63) - "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=fr --force-fieldtrials="AutocompleteDynamicTrial_2/DefaultControl_R2_Stable/BrowserPreReadExperiment/100-pct-default/CookieRetentionPriorityStudy/ExperimentOn/DeferBackgroundExtensionCreation/RateLimited/ForceCompositingMode/thread/InstantExtended/Group2 pct:10a stable:r5 use_remote_ntp_on_startup:1 espv:210 suppress_on_srp:1/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_05/UMA-Uniformity-Trial-1-Percent/group_81/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_02/UMA-Uniformity-Trial-5-Percent/default/UMA-Uniformity-Trial-50-Percent/group_01/" --enable-threaded-compositing --extension-process --renderer-print-preview --disable-html-notifications --channel="5688.3.2027451991\1673747594" /prefetch:673131151
3440 | C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (.Google Inc. - Google Chrome.) - (31.0.1650.63) - "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=fr --force-fieldtrials="AutocompleteDynamicTrial_2/DefaultControl_R2_Stable/BrowserPreReadExperiment/100-pct-default/CookieRetentionPriorityStudy/ExperimentOn/DeferBackgroundExtensionCreation/RateLimited/ForceCompositingMode/thread/InstantExtended/Group2 pct:10a stable:r5 use_remote_ntp_on_startup:1 espv:210 suppress_on_srp:1/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_05/UMA-Uniformity-Trial-1-Percent/group_81/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_02/UMA-Uniformity-Trial-5-Percent/default/UMA-Uniformity-Trial-50-Percent/group_01/" --enable-threaded-compositing --extension-process --renderer-print-preview --disable-html-notifications --channel="5688.4.1138596641\1268671210" /prefetch:673131151
3056 | C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (.Google Inc. - Google Chrome.) - (31.0.1650.63) - "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=ppapi --channel="5688.5.45818244\1025190924" --ppapi-flash-args --lang=fr --ignored=" --type=renderer " /prefetch:-632637702

¤¤¤¤¤¤¤¤¤¤ | Processus démarrés


[14/07/2009 00:36:49] - 500 | C:\Windows\system32\wininit.exe (.Microsoft Corporation - Application de démarrage de Windows.) - (6.1.7600.16385) - wininit.exe [96256 Ko]
[14/07/2009 00:19:28] - 704 | C:\Windows\system32\svchost.exe (.Microsoft Corporation - Processus hôte pour les services Windows.) - (6.1.7600.16385) - C:\Windows\system32\svchost.exe -k DcomLaunch [20992 Ko]
[14/07/2009 00:19:28] - 820 | C:\Windows\system32\svchost.exe (.Microsoft Corporation - Processus hôte pour les services Windows.) - (6.1.7600.16385) - C:\Windows\system32\svchost.exe -k RPCSS [20992 Ko]
[14/07/2009 00:19:28] - 960 | C:\Windows\System32\svchost.exe (.Microsoft Corporation - Processus hôte pour les services Windows.) - (6.1.7600.16385) - C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted [20992 Ko]
[14/07/2009 00:19:28] - 1000 | C:\Windows\System32\svchost.exe (.Microsoft Corporation - Processus hôte pour les services Windows.) - (6.1.7600.16385) - C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted [20992 Ko]
[14/07/2009 00:19:28] - 328 | C:\Windows\system32\svchost.exe (.Microsoft Corporation - Processus hôte pour les services Windows.) - (6.1.7600.16385) - C:\Windows\system32\svchost.exe -k LocalService [20992 Ko]
[14/07/2009 00:19:28] - 388 | C:\Windows\system32\svchost.exe (.Microsoft Corporation - Processus hôte pour les services Windows.) - (6.1.7600.16385) - C:\Windows\system32\svchost.exe -k netsvcs [20992 Ko]
[14/07/2009 00:19:28] - 1360 | C:\Windows\system32\svchost.exe (.Microsoft Corporation - Processus hôte pour les services Windows.) - (6.1.7600.16385) - C:\Windows\system32\svchost.exe -k NetworkService [20992 Ko]
[24/02/2014 16:39:18] - 1532 | C:\Program Files\AVAST Software\Avast\AvastSvc.exe (.AVAST Software - avast! Service.) - (9.0.2013.292) - "C:\Program Files\AVAST Software\Avast\AvastSvc.exe" [50344 Ko]
[14/07/2009 00:19:28] - 1740 | C:\Windows\system32\svchost.exe (.Microsoft Corporation - Processus hôte pour les services Windows.) - (6.1.7600.16385) - C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork [20992 Ko]
[14/07/2009 00:19:28] - 1316 | C:\Windows\system32\svchost.exe (.Microsoft Corporation - Processus hôte pour les services Windows.) - (6.1.7600.16385) - C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [20992 Ko]
[14/07/2009 00:19:28] - 2252 | C:\Windows\system32\svchost.exe (.Microsoft Corporation - Processus hôte pour les services Windows.) - (6.1.7600.16385) - C:\Windows\system32\svchost.exe -k imgsvc [20992 Ko]
[21/11/2010 04:24:27] - 2508 | C:\Windows\system32\wbem\wmiprvse.exe (.Microsoft Corporation - WMI Provider Host.) - (6.1.7601.17514) - C:\Windows\system32\wbem\wmiprvse.exe [257536 Ko]
[14/07/2009 00:19:28] - 1244 | C:\Windows\system32\svchost.exe (.Microsoft Corporation - Processus hôte pour les services Windows.) - (6.1.7600.16385) - C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted [20992 Ko]
[24/02/2014 16:39:18] - 1812 | C:\Program Files\AVAST Software\Avast\AvastUI.exe (.AVAST Software - avast! Antivirus.) - (9.0.2013.292) - "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui [3767096 Ko]
[14/07/2009 00:19:28] - 4520 | C:\Windows\System32\svchost.exe (.Microsoft Corporation - Processus hôte pour les services Windows.) - (6.1.7600.16385) - C:\Windows\System32\svchost.exe -k LocalServicePeerNet [20992 Ko]
[14/07/2009 00:43:52] - 5988 | C:\Windows\system32\DllHost.exe (.Microsoft Corporation - COM Surrogate.) - (6.1.7600.16385) - C:\Windows\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7} [7168 Ko]
[14/07/2009 00:19:28] - 2248 | C:\Windows\System32\svchost.exe (.Microsoft Corporation - Processus hôte pour les services Windows.) - (6.1.7600.16385) - C:\Windows\System32\svchost.exe -k secsvcs [20992 Ko]
[25/02/2014 21:54:47] - 1428 | C:\Users\christophe\Downloads\Shortcut_Module.exe (. - Shortcut_Module.) - (25.2.2014.5) - "C:\Users\christophe\Downloads\Shortcut_Module.exe" [2138112 Ko]
[21/11/2010 04:24:27] - 2936 | C:\Windows\system32\wbem\wmiprvse.exe (.Microsoft Corporation - WMI Provider Host.) - (6.1.7601.17514) - C:\Windows\system32\wbem\wmiprvse.exe [257536 Ko]
[24/07/2011 17:51:25] - 5020 | C:\Windows\explorer.exe (.Microsoft Corporation - Explorateur Windows.) - (6.1.7601.17567) - explorer.exe [2871808 Ko]
[21/11/2010 04:24:52] - 4776 | C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe (.Microsoft Corporation - PresentationFontCache.exe.) - (3.0.6920.5011) - C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [42856 Ko]
[17/12/2009 23:32:30] - 5164 | C:\Program Files (x86)\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe (.Cisco Systems, Inc. - VPN Agent Service.) - (2.4.1012.0) - "C:\Program Files (x86)\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe" [497856 Ko]

¤¤¤¤¤¤¤¤¤¤ | Services

Service en fonctionnement : WINDEFEND
Service stoppé : WINDEFEND

¤¤¤¤¤¤¤¤¤¤ | Hosts

C:\Windows\System32\Drivers\etc\hosts : Remis a zéro avec succès

¤¤¤¤¤¤¤¤¤¤ | Registre

Supprimé avec succès : [64]HKLM\Software\Classes\SoftwareUpdate.OnDemandCOMClassSvc
Supprimé avec succès : [64]HKLM\Software\Classes\SoftwareUpdate.Update3COMClassService
Supprimé avec succès : [64]HKLM\Software\Classes\SoftwareUpdate.Update3WebSvc
Supprimé avec succès : [64]HKLM\Software\Classes\TorchHTML.BJV3ESDJRKJAHTOFOSM2ZDMM6I
Supprimé avec succès : [64]HKLM\Software\Classes\SoftwareUpdate.OnDemandCOMClassSvc.1.0
Supprimé avec succès : [64]HKLM\Software\Classes\SoftwareUpdate.Update3WebSvc.1.0
Supprimé avec succès : [32]HKLM\Software\Classes\SoftwareUpdate.Update3COMClassService.1.0
Supprimé avec succès : HKU\S-1-5-21-3147190806-3266541912-746446338-1002\Software\Classes\.bubbledock
Supprimé avec succès : HKU\S-1-5-21-3147190806-3266541912-746446338-1002\Software\Classes\bubbledock
Supprimé avec succès : [64]HKLM\Software\Classes\AppID\{6A070EEA-E3F8-411E-9D3A-F3814ED6D1A8} : SoftwareUpdateApp
Supprimé avec succès : [64]HKLM\Software\Classes\AppID\{B1DBD7F1-13D4-4FBE-8CC1-7BF878C10CDA} : IESurfMatch
Supprimé avec succès : [32]:[32]HKLM\Software\Classes\TypeLib\{17734227-EAAA-4C5E-9AA3-036AD981B3A6} : C:\Program Files (x86)\Nosibay\Bubble Dock\extensions\axSurfMatch.dll
Supprimé avec succès : [64]HKLM\Software\Classes\Interface\{8C973B84-E6DA-49D8-B786-9C93C2E587F5} : {17734227-EAAA-4C5E-9AA3-036AD981B3A6}
Supprimé avec succès : [32]HKLM\Software\Classes\Interface\{8C973B84-E6DA-49D8-B786-9C93C2E587F5} : {17734227-EAAA-4C5E-9AA3-036AD981B3A6}
Supprimé avec succès : [64]HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Microsoft-Windows-CertificateServicesClient : {73370bd6-85e5-430b-b60a-fea1285808a7}
Supprimé avec succès : [64]HKLM\Software\Microsoft\Tracing\InternetUpdaterService_RASAPI32
Supprimé avec succès : [64]HKLM\Software\Microsoft\Tracing\InternetUpdaterService_RASMANCS
Supprimé avec succès : HKU\S-1-5-18\Software\AskPartnerNetwork
Supprimé avec succès : HKU\S-1-5-18\Software\AskToolbar
Supprimé avec succès : [64]HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{737B90FC-5F3C-4C2D-960C-E9F9C973295E} : C:\PROGRA~2\MOVIES~1\Datamngr\SRTOOL~1\IE
Supprimé avec succès : [64]HKLM\Software\Classes\Installer\Products\0336A2D4B8F23E11C9048BCAF6798BE8 : C:\Windows\Temp\._msige61\
Supprimé avec succès : [64]HKLM\Software\Classes\Installer\Products\0694AF70830BBE9498B1F95939A05A44 : C:\Users\ADMINI~1\AppData\Local\Temp\_is341A\
Supprimé avec succès : [64]HKLM\Software\Classes\Installer\Products\12DA52202E3F6194FB3F563D9F505228 : C:\Users\CHRIST~1\AppData\Local\Temp\IXP371.TMP\
Supprimé avec succès : [64]HKLM\Software\Classes\Installer\Products\1af2a8da7e60d0b429d7e6453b3d0182 : C:\Windows\TEMP\IXP000.TMP\
Supprimé avec succès : [64]HKLM\Software\Classes\Installer\Products\2B0163E6D0340BE4183EB2758E9BEDD8 : C:\Users\CHRIST~1\AppData\Local\Temp\IXP172.TMP\
Supprimé avec succès : [64]HKLM\Software\Classes\Installer\Products\46B5A9879DD95AB419A50FCFA0B1B7EF : C:\Users\CHRIST~1\AppData\Local\Temp\IXP172.TMP\
Supprimé avec succès : [64]HKLM\Software\Classes\Installer\Products\5D6775DE4B957B64FA18F5D2497D6C04 : C:\Users\ADMINI~1\AppData\Local\Temp\RTLINS~1\EAP\
Supprimé avec succès : [64]HKLM\Software\Classes\Installer\Products\701043F6AA9F6C745BC43C1AF91155F3 : C:\Users\CHRIST~1\AppData\Local\Temp\
Supprimé avec succès : [64]HKLM\Software\Classes\Installer\Products\7810FB462D3FB89499AE61A39FEAE69C : C:\Users\ADMINI~1\AppData\Local\Temp\RTLINS~1\EAP\
Supprimé avec succès : [64]HKLM\Software\Classes\Installer\Products\7AA65C54B1DE00849AF7DEFDF353021B : C:\Users\CHRIST~1\AppData\Local\Temp\IXP371.TMP\
Supprimé avec succès : [64]HKLM\Software\Classes\Installer\Products\7B65D4CC81F6B0747843BADC57CB4F1F : C:\Users\ADMINI~1\AppData\Local\Temp\{484FC538-46D9-4574-B8B2-7D22D850E103}\
Supprimé avec succès : [64]HKLM\Software\Classes\Installer\Products\84b9c17023c712640acaf308593282f8 : C:\Users\CHRIST~1\AppData\Local\Temp\IXP001.TMP\
Supprimé avec succès : [64]HKLM\Software\Classes\Installer\Products\883658EADAFA357418FD9DB6910D1AC7 : C:\Users\ADMINI~1\AppData\Local\Temp\{130C53DA-0C40-40E6-923F-A9E7760A11F0}\
Supprimé avec succès : [64]HKLM\Software\Classes\Installer\Products\A9A38029D9457504888E22E30A5836AF : C:\Users\CHRIST~1\AppData\Local\Temp\install\A08563F\
Supprimé avec succès : [64]HKLM\Software\Classes\Installer\Products\b25099274a207264182f8181add555d0 : C:\Users\CHRIST~1\AppData\Local\Temp\IXP001.TMP\
Supprimé avec succès : [64]HKLM\Software\Classes\Installer\Products\BE31195E5820DFB43AA77BE9CAB6F8B4 : C:\Users\CHRIST~1\AppData\Local\Temp\{D0D6654C-542D-44C8-B767-01628BD15935}\{948E7FF1-1F96-4F04-8099-EBEF72B47042}\
Supprimé avec succès : [64]HKLM\Software\Classes\Installer\Products\c1c4f01781cc94c4c8fb1542c0981a2a : C:\Windows\TEMP\IXP000.TMP\
Supprimé avec succès : [64]HKLM\Software\Classes\Installer\Products\C953167FDEC9EA54A915D96650DC554C : C:\Users\ADMINI~1\AppData\Local\Temp\
Supprimé avec succès : [64]HKLM\Software\Classes\Installer\Products\FD97738F5F1E2A347AEB37F258F6DA7B : C:\Users\CHRIST~1\AppData\Local\Temp\{D0D6654C-542D-44C8-B767-01628BD15935}\{8D95588C-406F-4B8A-92D6-5B116FA0E2F8}\
Supprimé avec succès : [64]HKLM\Software\Classes\Installer\Products\045F27F206F16624596059B2126D46D0 : C:\Users\CHRIST~1\AppData\Local\Temp\IXP371.TMP\
Supprimé avec succès : [64]HKLM\Software\Classes\Installer\Products\70DA7C156F3C5364E8A83231608D01EF : C:\Users\ADMINI~1\AppData\Local\Temp\RTLINS~1\EAP\
Supprimé avec succès : [32]HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\06CECDAEEF3B92B408462C2A084A6A0E] : C:\Users\CHRIST~1\AppData\Local\Temp\x86\
Supprimé avec succès : [32]HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1A24B5BB8521B03E0C8D908F5ABC0AE6] : C:\Program Files (x86)\Ask.com\
Supprimé avec succès : [32]HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1E683A52C4884D342905BC6EDBA0EC09] : C?\Users\CHRIST~1\AppData\Local\Temp\x64\HPWarrantyIDDll.dll
Supprimé avec succès : [32]HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2B0D56C4F4C46D844A57FFED6F0D2852] : C:\Program Files (x86)\Ask.com\
Supprimé avec succès : [32]HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2C38A6DAA8574DA47B10E16A4B6B0AF3] : C:\Users\CHRIST~1\AppData\Local\Temp\
Supprimé avec succès : [32]HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\328AAC5304B7FC440B4CCEF5F78415EE] : C:\Users\CHRIST~1\AppData\Local\Temp\x86\
Supprimé avec succès : [32]HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\37C24879C63E3FD47B3E00EAFE1B998C] : C:\Users\CHRIST~1\AppData\Local\Temp\
Supprimé avec succès : [32]HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\49D4375FE41653242AEA4C969E4E65E0] : C:\Program Files (x86)\Ask.com\
Supprimé avec succès : [32]HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4CCC2B2E74069BA41A103439AB39F3B7] : C:\Users\CHRIST~1\AppData\Local\Temp\x64\
Supprimé avec succès : [32]HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\64030CC7D9F0ADB4CBD35E2064192FE9] : C?\Users\CHRIST~1\AppData\Local\Temp\x86\HPWarrantyIDDll.dll
Supprimé avec succès : [32]HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6AA0923513360135B272E8289C5F13FA] : C:\Program Files (x86)\Ask.com\
Supprimé avec succès : [32]HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6F7467AF8F29C134CBBAB394ECCFDE96] : C:\Program Files (x86)\Ask.com\
Supprimé avec succès : [32]HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7F5CAE480A624D34D88D2D710E7BEF4D] : C:\Users\christophe\AppData\Local\APN\GoogleCRXs\apnorjtoolbar.crx
Supprimé avec succès : [32]HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\860F6081015010744A5F416EF66254F0] : C:\Users\CHRIST~1\AppData\Local\Temp\x64\
Supprimé avec succès : [32]HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\922525DCC5199162F8935747CA3D8E59] : C:\Program Files (x86)\Ask.com\
Supprimé avec succès : [32]HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A5158C88AB644E7478BE24381E8CF08E] : C:\Users\CHRIST~1\AppData\Local\Temp\ACO\
Supprimé avec succès : [32]HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B32A3B97FB77C644F964C5A7D514A957] : C:\Users\CHRIST~1\AppData\Local\Temp\x64\
Supprimé avec succès : [32]HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BCDA179D619B91648538E3394CAC94CC] : C:\Firefox\toolbar@ask.com\defaults\preferences\defaults.js
Supprimé avec succès : [32]HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C1824D42765F6104B9A53AB93B4DB5D9] : 02:\Software\Microsoft\MSN\Toolbar\Version
Supprimé avec succès : [32]HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C54E1B132FD60ED468793CE47FBD725D] : 02:\Software\Microsoft\Internet Explorer\Toolbar\{8dcb7100-df86-4384-8842-8fa844297b3f}
Supprimé avec succès : [32]HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CA0054A5AB3EFFE4CB5660E44A1E7DCC] : 02:\Software\Boxore\BoxoreClient\version
Supprimé avec succès : [32]HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D677B1A9671D4D4004F6F2A4469E86EA] : C:\Firefox\toolbar@ask.com\searchplugins\askcom.xml
Supprimé avec succès : [32]HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D6F7DDBFBD0D6FFC395351FADBD4FC9D] : C:\Users\CHRIST~1\AppData\Local\Temp\Ceement\src\setup.exe
Supprimé avec succès : [32]HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DD1402A9DD4215A43ABDE169A41AFA0E] : C:\Program Files (x86)\Ask.com\
Supprimé avec succès : [32]HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E36E114A0EAD2AD46B381D23AD69CDDF] : C:\Firefox\toolbar@ask.com\
Supprimé avec succès : [32]HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E52C63413EE9A9049A3EADF14E9A29DB] : C:\Users\CHRIST~1\AppData\Local\Temp\x64\
Supprimé avec succès : [32]HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E990E6132DD3AC8419DBA758DAB66450] : C:\Users\CHRIST~1\AppData\Local\Temp\Ceement\
Supprimé avec succès : [32]HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EF8E618DB3AEDFBB384561B5C548F65E] : C:\Firefox\toolbar@ask.com\chrome\content\about.js
Supprimé avec succès : [32]HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F51782A3AEF02EA4996614D61DDD1A49] : C:\Users\CHRIST~1\AppData\Local\Temp\x86\
Supprimé avec succès : [32]HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FE496FE1C36ED374DA22E30C7A5FC085] : C:\Users\CHRIST~1\AppData\Local\Temp\x86\
Supprimé avec succès : HKU\S-1-5-21-3147190806-3266541912-746446338-1002\Software\Microsoft\Windows\CurrentVersion\Uninstall\Bubble Dock : "C:\Users\christophe\AppData\Roaming\Nosibay\Bubble Dock\Uninstall Bubble Dock.exe"

¤¤¤¤¤¤¤¤¤¤ | IFEO


¤¤¤¤¤¤¤¤¤¤ | Dossiers

Supprimé avec succès : C:\Users\christophe\AppData\Roaming\Bubble Dock.installation.log
Supprimé avec succès : C:\Users\christophe\AppData\Local\Google\Chrome\User Data\Default\Extensions\poahhcggenldhhngmcdolbgdjnpicfim\1.26.67_0\crossriderManifest.json
Supprimé avec succès : C:\Users\christophe\AppData\Local\Google\Chrome\User Data\Default\Extensions\poahhcggenldhhngmcdolbgdjnpicfim\1.26.67_0\js\lib\crossriderAPI.js
Supprimé avec succès : C:\Users\christophe\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\iLivid.lnk
Supprimé avec succès : C:\Users\christophe\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Torch.lnk
Supprimé avec succès : C:\Users\christophe\Desktop\Rom@in\cacaoweb.exe.9tz1041.partial
Supprimé avec succès : C:\Users\christophe\Desktop\Rom@in\cacaoweb.exe.ehwr07s.partial
Supprimé avec succès : C:\Windows\System32\Config\Systemprofile\AppData\Local\Google\Custom Buttons\toolbar.google.com_MXE8GT6B9RBHXCGLZ06L.xml
Supprimé avec succès : C:\Users\christophe\AppData\Roaming\Mozilla\Firefox\extensions\support@websteroidsapp.com

¤¤¤¤¤¤¤¤¤¤ | Détournements de raccourcis

Désinfecté : C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Music, Photos and Videos\Photos Snapfish.lnk : C:\Program Files (x86)\Hewlett-Packard\Shared\WizLink.exe (hxxp://www.snapfish.com/hp_notebook_desktopicon_2011_fr)
Désinfecté : C:\Users\Public\Desktop\Photos Snapfish.lnk : C:\Program Files (x86)\Hewlett-Packard\Shared\WizLink.exe (hxxp://www.snapfish.com/hp_notebook_desktopicon_2011_fr)

¤¤¤¤¤¤¤¤¤¤ | Détournement internet Explorer

Réparé : [HKU\S-1-5-21-3147190806-3266541912-746446338-1002\Software\Microsoft\Internet Explorer\Main]|[Search Bar] : Preserve - http://www.google.com/
Réparé : [HKU\S-1-5-21-3147190806-3266541912-746446338-1002\Software\Microsoft\Internet Explorer\Main]|[Local Page] : C:\Windows\system32\blank.htm - C:\Windows\SysWOW64\blank.htm
Réparé : [HKU\S-1-5-21-3147190806-3266541912-746446338-1002\Software\Microsoft\Internet Explorer\Main]|[Search Page] : http://go.microsoft.com/fwlink/?LinkId=54896 - http://www.microsoft.com/isapi/redir.dl ... r=iesearch
Réparé : [64][HKLM\Software\Microsoft\Internet Explorer\Main]|[Start Page] : http://go.microsoft.com/fwlink/p/?LinkId=255141 - http://go.microsoft.com/fwlink/?LinkId=69157
Réparé : [64][HKLM\Software\Microsoft\Internet Explorer\Main]|[Default_Page_URL] : http://go.microsoft.com/fwlink/p/?LinkId=255141 - http://go.microsoft.com/fwlink/?LinkId=69157
Réparé : [32][HKLM\Software\Microsoft\Internet Explorer\Main]|[Start Page] : http://go.microsoft.com/fwlink/p/?LinkId=255141 - http://go.microsoft.com/fwlink/?LinkId=69157
Réparé : [32][HKLM\Software\Microsoft\Internet Explorer\Main]|[Local Page] : C:\Windows\System32\blank.htm - C:\Windows\SysWOW64\blank.htm
Réparé : [32][HKLM\Software\Microsoft\Internet Explorer\Main]|[Default_Page_URL] : http://go.microsoft.com/fwlink/p/?LinkId=255141 - http://go.microsoft.com/fwlink/?LinkId=69157
Réparé : [HKU\S-1-5-21-3147190806-3266541912-746446338-1002\Software\Microsoft\Windows\CurrentVersion\Internet settings]|[WarnonZoneCrossing] : 0 - 1

¤¤¤¤¤¤¤¤¤¤ | Détournement Google Chrome

[christophe] Remise à zéro impossible : SearchURL !
[christophe] Remise à zéro impossible : Preferences !

¤¤¤¤¤¤¤¤¤¤ | Détournement Firefox


¤¤¤¤¤¤¤¤¤¤ | Détournement des clés StartMenuInternet

Réparé : [64][HKLM\Software\Clients\StartMenuInternet\IExplore.exe\shell\open\command] : C:\Program Files\Internet Explorer\iexplore.exe - "C:\Program Files (x86)\Internet Explorer\iexplore.exe"

¤¤¤¤¤¤¤¤¤¤ | AppInit_DLLs



[64][HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]|[LoadAppInit_DLLs] : 1
[32][HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]|[LoadAppInit_DLLs] : 1

¤¤¤¤¤¤¤¤¤¤ | Détournement Javascript


¤¤¤¤¤¤¤¤¤¤ | Firewall

Réparé : [HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]|[EnableFirewall] : 1 - 0
Réparé : [HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]|[EnableFirewall] : 1 - 0
Réparé : [HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]|[EnableFirewall] : 1 - 0


¤¤¤¤¤¤¤¤¤¤ | Fichiers temporaires

[All Users] Fichiers temporaires Supprimés : 0 Ko
[Default User] Fichiers temporaires Supprimés : 0 Ko
[Default] Fichiers temporaires Supprimés : 0 Ko
[Public] Fichiers temporaires Supprimés : 0 Ko
[christophe] Fichiers temporaires Supprimés : 47 Ko


¤¤¤¤¤¤¤¤¤¤ |EOF| ¤¤¤¤¤¤¤¤¤¤ | 22:35:02


Et voila ! c'est un peu long car j'ai des multitudes de fenêtres de téléchargement qui s'ouvrent à chaque recherche.
#108377
Bonsoir,

Voici le rapport de Zhp Diag.

Pour info depuis mon dernier message ,quasiment pas de fenêtre publicitaires .

C'est bon signe ...


~ Rapport de ZHPDiag v2014.2.23.20 - Nicolas Coolman (23/02/2014)
~ Lancé par christophe (26/02/2014 19:08:54)
~ Adresse du Site Web http://nicolascoolman.webs.com
~ Forums gratuits d'Assistance à la désinfection : http://nicolascoolman.webs.com/apps/links/
~ Traduit par Nicolas Coolman
~ Etat de la version :
~ Liste blanche : Activée par le programme
~ Elévation des Privilèges : OK
~ User Account Control (UAC): Deactivate by user


---\\ Navigateurs Internet
MSIE: Internet Explorer v11.0.9600.16518
GCIE: Google Chrome v31.0.1650.63 (Defaut)

---\\ Informations sur les produits Windows
~ Langage: Français
Windows 7 Home Premium, 64-bit Service Pack 1 (Build 7601)
Windows Server License Manager Script : OK
~ Windows(R) 7, OEM_SLP channel
System Locked Preinstallation (OEM_SLP) : OK
Windows ID Activation : OK
~ Windows Partial Key : 3Q6C9
Windows License : OK
~ Windows Remaining Initializations Number : 1
Software Protection Service (Protection logicielle) : OK
Windows Automatic Updates : OK
Windows Activation Technologies : OK

---\\ Logiciels de protection du système
avast! Free Antivirus v9.0.2013
Malwarebytes Anti-Malware version 1.75.0.1300
Windows Defender W7

---\\ Logiciels d'optimisation du système
CCleaner v3.17 =Piriform Ltd

---\\ Logiciels de partage PeerToPeer

---\\ Surveillance de Logiciels
Adobe Flash Player 12 ActiveX
Adobe Reader X
Java 7 Update 51

---\\ Informations sur le système
~ Processor: AMD64 Family 18 Model 1 Stepping 0, AuthenticAMD
~ Operating System: 64 Bits
Boot mode: Normal (Normal boot)
Total RAM: 3561 MB (48% free)
System Restore: Activé (Enable)
System drive C: has 453 GB (78%) free of 576 GB

---\\ Mode de connexion au système
~ Computer Name: CHRISTOPHE-HP
~ User Name: christophe
~ All Users Names: HomeGroupUser$, christophe, Administrateur,
~ Unselected Option: O45,O61,O62,O65,O66,O80,O82,O89
Logged in as Administrator

---\\ Variables d'environnement
~ System Unit : C:\
~ %AppZHP% : C:\Users\christophe\AppData\Roaming\ZHP\
~ %AppData% : C:\Users\christophe\AppData\Roaming\
~ %Desktop% : C:\Users\christophe\Desktop\
~ %Favorites% : C:\Users\christophe\Favorites\
~ %LocalAppData% : C:\Users\christophe\AppData\Local\
~ %StartMenu% : C:\Users\christophe\AppData\Roaming\Microsoft\Windows\Start Menu\
~ %Windir% : C:\Windows\
~ %System% : C:\Windows\System32\

---\\ Enumération des unités disques
C: Hard drive, Flash drive, Thumb drive (Free 453 Go of 576 Go)
D: Hard drive, Flash drive, Thumb drive (Free 2 Go of 16 Go)
E: Hard drive, Flash drive, Thumb drive (Free 0 Go of 4 Go)
F: CD-ROM drive (Free 0 Go of 0 Go)



---\\ Etat du Centre de Sécurité Windows
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: Modified
~ Security Center: 49 Legitimates Filtered in 00mn 00s



---\\ Recherche particulière de fichiers génériques
[MD5.332FEAB1435662FC6C672E25BEB37BE3] - (.Microsoft Corporation - Explorateur Windows.) (.24/07/2011 - 17:51:25.) -- C:\Windows\Explorer.exe [2871808]
[MD5.94355C28C1970635A31B3FE52EB7CEBA] - (.Microsoft Corporation - Application de démarrage de Windows.) (.14/07/2009 - 02:39:52.) -- C:\Windows\System32\Wininit.exe [129024]
[MD5.263B6E451526A90FF8B1CEC759F22956] - (.Microsoft Corporation - Extensions Internet pour Win32.) (.06/02/2014 - 10:24:52.) -- C:\Windows\System32\wininet.dll [2334208]
[MD5.1151B1BAA6F350B1DB6598E0FEA7C457] - (.Microsoft Corporation - Application d’ouverture de session Windows.) (.21/11/2010 - 04:24:29.) -- C:\Windows\System32\Winlogon.exe [390656]
[MD5.067FA52BFB59A56110A12312EF9AF243] - (.Microsoft Corporation - Bibliothèque de licences.) (.21/11/2010 - 04:24:16.) -- C:\Windows\System32\sppcomapi.dll [232448]
[MD5.79059559E89D06E8B80CE2944BE20228] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) (.28/09/2013 - 02:09:10.) -- C:\Windows\system32\Drivers\AFD.sys [497152]
[MD5.02062C0B390B7729EDC9E69C680A6F3C] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.14/07/2009 - 02:52:21.) -- C:\Windows\system32\Drivers\atapi.sys [24128]
[MD5.B8BD2BB284668C84865658C77574381A] - (.Microsoft Corporation - CD-ROM File System Driver.) (.14/07/2009 - 00:19:47.) -- C:\Windows\system32\Drivers\Cdfs.sys [92160]
[MD5.F036CE71586E93D94DAB220D7BDF4416] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.21/11/2010 - 04:23:47.) -- C:\Windows\system32\Drivers\Cdrom.sys [147456]
[MD5.9BB2EF44EAA163B29C4A4587887A0FE4] - (.Microsoft Corporation - DFS Namespace Client Driver.) (.21/11/2010 - 04:24:32.) -- C:\Windows\system32\Drivers\DfsC.sys [102400]
[MD5.97BFED39B6B79EB12CDDBFEED51F56BB] - (.Microsoft Corporation - High Definition Audio Bus Driver.) (.21/11/2010 - 04:23:47.) -- C:\Windows\system32\Drivers\HDAudBus.sys [122368]
[MD5.FA55C73D4AFFA7EE23AC4BE53B4592D3] - (.Microsoft Corporation - Pilote de port i8042.) (.14/07/2009 - 00:19:57.) -- C:\Windows\system32\Drivers\i8042prt.sys [105472]
[MD5.AF9B39A7E7B6CAA203B3862582E9F2D0] - (.Microsoft Corporation - IP Network Address Translator.) (.14/07/2009 - 01:10:03.) -- C:\Windows\system32\Drivers\IpNat.sys [116224]
[MD5.A5D9106A73DC88564C825D317CAC68AC] - (.Microsoft Corporation - Windows NT SMB Minirdr.) (.15/07/2011 - 10:00:09.) -- C:\Windows\system32\Drivers\MRxSmb.sys [158208]
[MD5.09594D1089C523423B32A4229263F068] - (.Microsoft Corporation - MBT Transport driver.) (.21/11/2010 - 04:23:51.) -- C:\Windows\system32\Drivers\netBT.sys [261632]
[MD5.B98F8C6E31CD07B2E6F71F7F648E38C0] - (.Microsoft Corporation - Pilote du système de fichiers NT.) (.12/04/2013 - 15:45:08.) -- C:\Windows\system32\Drivers\ntfs.sys [1656680]
[MD5.0086431C29C35BE1DBC43F52CC273887] - (.Microsoft Corporation - Pilote de port parallèle.) (.14/07/2009 - 01:00:41.) -- C:\Windows\system32\Drivers\Parport.sys [97280]
[MD5.471815800AE33E6F1C32FB1B97C490CA] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.21/11/2010 - 04:24:33.) -- C:\Windows\system32\Drivers\Rasl2tp.sys [129536]
[MD5.548260A7B8654E024DC30BF8A7C5BAA4] - (.Microsoft Corporation - SMB Transport driver.) (.14/07/2009 - 01:09:09.) -- C:\Windows\system32\Drivers\smb.sys [93184]
[MD5.DDAD5A7AB24D8B65F8D724F5C20FD806] - (.Microsoft Corporation - TDI Translation Driver.) (.21/11/2010 - 04:24:32.) -- C:\Windows\system32\Drivers\tdx.sys [119296]
[MD5.0D08D2F3B3FF84E433346669B5E0F639] - (.Microsoft Corporation - Pilote de cliché instantané du volume.) (.21/11/2010 - 04:23:47.) -- C:\Windows\system32\Drivers\volsnap.sys [295808]
~ Generic Processes: Scanned in 00mn 01s



---\\ Etat des fichiers cachés (Caché/Total)
~ Mes images (My Pictures) : 1/342
~ Mes musiques (My Musics) : 1/134
~ Mes Videos (My Videos) : 1/17
~ Mes Favoris (My Favorites) : 1/50
~ Mes Documents (My Documents) : 2/26
~ Mon Bureau (My Desktop) : 2/1002
~ Menu demarrer (Programs) : 1/28
~ Hidden Files: Scanned in 00mn 01s



---\\ Processus lancés
[MD5.58920E6A409046BA06548D9D139CE0F0] - (.Skype Technologies S.A. - Skype.) -- C:\Program Files (x86)\Skype\Phone\Skype.exe [20584608] [PID.3824]
[MD5.03163BAF3A5DBF8742804093931D7D32] - (.Hewlett-Packard Co. - HP OfficeJet COM Device Objects.) -- C:\Program Files (x86)\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe [147456] [PID.4052]
[MD5.53966C74A69B0CFE51C8BF01C94028F3] - (.Hewlett-Packard Company - HP QuickWeb Utilities.) -- C:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe [168504] [PID.3344]
[MD5.A564A22308A3F55235BA2478EE82992D] - (.Hewlett-Packard - hpotdd01.) -- C:\Program Files (x86)\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe [28672] [PID.3304]
[MD5.8E2A7F1F62467A7DCB8AB2C0642F47CA] - (.Apple Inc. - iTunesHelper.) -- C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392] [PID.3340]
[MD5.8192B2E274607D1D530F5C191698C544] - (.Hewlett-Packard Development Company, L.P. - HP Message Service.) -- C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe [578944] [PID.2316]
[MD5.8A3B69683E63808719D24E1C68C21CC7] - (.Hewlett-Packard Development Company, L.P. - HP On Screen Display.) -- C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe [379960] [PID.3464]
[MD5.5B6E8E09BE6401A7E022F52FDFCB2FF8] - (.Oracle Corporation - Java(TM) Update Scheduler.) -- C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336] [PID.3160]
[MD5.A78AAB0D2D70EF7DD56B7328AC502059] - (.AVAST Software - avast! Antivirus.) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe [3767096] [PID.3548]
[MD5.B7F55E2AE978D3D34F7876EE5D689AAE] - (.CyberLink - YouCam Mirage.) -- C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe [136488] [PID.4364]
[MD5.376A9B411BF8B77D5BF84B24D0C7DACD] - (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [863184] [PID.3780]
[MD5.42FEDBCB3ED926F6F529E0FDDF750BE0] - (.Nicolas Coolman - ZHPDiag.) -- C:\Program Files (x86)\ZHPDiag\ZHPDiag.exe [8339968] [PID.1132]
[MD5.5EA22CB6B100212837A97F281EDB3C47] - (.Cisco Systems, Inc. - VPN Agent Service.) -- C:\Program Files (x86)\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe [497856] [PID.1328]
[MD5.CC42F104172B4A62793083D380867317] - (.AVAST Software - avast! Service.) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344] [PID.1484]
[MD5.B362181ED3771DC03B4141927C80F801] - (.Adobe Systems Incorporated - Adobe Acrobat Update Service.) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [65432] [PID.1828]
[MD5.4FE5C6D40664AE07BE5105874357D2ED] - (.Apple Inc. - MobileDeviceService.) -- C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [57008] [PID.1920]
[MD5.CA793DCC1D5F619021EF1D37CC7A831E] - (.EasyBits Software AS - Shared EasyBits services for Windows.) -- C:\Windows\SysWOW64\ezSharedSvcHost.exe [514232] [PID.2004]
[MD5.33761EBD9A26DE33BC83DD2DAFEC4513] - (.Hewlett-Packard Company - HP Quick Synchronization Service.) -- C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [270624] [PID.1528]
[MD5.2BEC76BDCD1BC080210325E7B5094834] - (.Hewlett-Packard Development Company, L.P. - HP Quick Launch WMI Service.) -- C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [35200] [PID.1508]
[MD5.D2946D9F020AE76E9CEF9B4A6DF838C0] - (.Hewlett-Packard Company - HP Software Framework WMI Service.) -- C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe [1129760] [PID.4592]
~ Processes Running: Scanned in 00mn 01s



---\\ Google Chrome, Démarrage,Recherche,Extensions (G0,G1,G2)
C:\Users\christophe\AppData\Local\Google\Chrome\User Data\Default\Preferences
G1 - GCS: Preference [User Data\Default] http://www.search.ask.com
G2 - GCE: Preference [User Data\Default] [flpcjncodpafbgdpnkljologafpionhb] Managera v.0.1 (Activé)
G2 - GCE: Preference [User Data\Default] [igjjkeeamkpihpncmmbgdkhdnjpcfmfb] Websteroids v.2.6.53 (Activé) =PUP.TubeDimmer
~ Google Browser: 16 Legitimates Filtered in 02mn 36s



---\\ Internet Explorer, Proxy Management (R5)
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyHttp1.1 = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll
~ Proxy management: Scanned in 00mn 00s



---\\ Analyse des lignes F0, F1, F2, F3 - IniFiles, Autoloading programs
F2 - REG:system.ini: USERINIT=C:\Windows\system32\userinit.exe,
F2 - REG:system.ini: Shell=C:\Windows\explorer.exe
F2 - REG:system.ini: VMApplet=C:\Windows\System32\SystemPropertiesPerformance.exe
~ Keys: Scanned in 00mn 00s



---\\ Hosts file redirection (O1)
~ Le fichier hosts est sain (The hosts file is clean).
~ Hosts File: Scanned in 00mn 00s
~ Nombre de lignes (Lines number): 21



---\\ Internet Explorer Toolbars (O3)
O3 - Toolbar: avast! Online Security - [HKLM]{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} . (.AVAST Software - IE Webrep plugin.) -- C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll
O3 - Toolbar: avast! Online Security - [HKLM]{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} . (.AVAST Software - IE Webrep plugin.) -- C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll
O3 - Toolbar\WebBrowser: (no name) - [HKCU]{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} Clé orpheline
~ Toolbar: Scanned in 00mn 00s



---\\ Autres liens utilisateurs (O4)
O4 - GS\Desktop [Public]: Découvrez HP webOS.lnk . (...) -- C:\Program Files (x86)\Hewlett-Packard\Shared\WizLink.exe
O4 - GS\Desktop [Public]: Feux Instructifs.lnk . (...) -- C:\Program Files (x86)\Feux Instructifs\FeuxInstructifs.exe
O4 - GS\Desktop [Public]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
O4 - GS\Desktop [Public]: HP Director.lnk . (.Hewlett-Packard Co. - HP Director application.) -- C:\Program Files (x86)\Hewlett-Packard\Digital Imaging\bin\Hpqdirec.exe
O4 - GS\Desktop [Public]: Magic Desktop.lnk . (.EasyBits Software AS - EasyBits Security Shield.) -- C:\Program Files (x86)\EasyBits For Kids\ezSecShield.exe =.EasyBits Software AS
O4 - GS\QuickLaunch [christophe]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
O4 - GS\QuickLaunch [christophe]: Launch Internet Explorer Browser.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
O4 - GS\TaskBar [christophe]: HP Recommended.LNK . (...) -- C:\Program Files (x86)\Hewlett-Packard\HP LaunchBox\HPTaskBar1.exe (.not file.)
O4 - GS\TaskBar [christophe]: HPWarrantyChecker.lnk . (.Hewlett-Packard - HPWarrantyChecker.) -- C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe
O4 - GS\TaskBar [christophe]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
O4 - GS\Program [christophe]: Crédit Mutuel.lnk . (.Microsoft Corporation - Microsoft Silverlight Out-of-Browser Launch.) -- C:\Program Files (x86)\Microsoft Silverlight\sllauncher.exe
O4 - GS\Program [christophe]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
O4 - GS\SystemTools [christophe]: Internet Explorer (No Add-ons).lnk . (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
O4 - GS\SendTo [christophe]: Evernote.lnk . (.Evernote Corp., 333 W Evelyn Ave. Mountain - Evernote.) -- C:\Program Files (x86)\Evernote\Evernote\Evernote.exe
O4 - GS\Desktop [christophe]: Cisco AnyConnect VPN Client.lnk . (.Cisco Systems, Inc. - VPN User Interface.) -- C:\Program Files (x86)\Cisco\Cisco AnyConnect VPN Client\vpnui.exe
O4 - GS\Desktop [christophe]: Crédit Mutuel.lnk . (.Microsoft Corporation - Microsoft Silverlight Out-of-Browser Launch.) -- C:\Program Files (x86)\Microsoft Silverlight\sllauncher.exe
O4 - GS\Desktop [christophe]: GoPro Studio.lnk . (...) -- C:\Program Files (x86)\GoPro\Tools\GoPro Studio.exe
O4 - GS\Desktop [christophe]: HP Support Assistant.lnk . (.Hewlett-Packard Company - HP Support Assistant.) -- C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe =.Hewlett-Packard Co
O4 - GS\Desktop [christophe]: Ordinateur - Raccourci.lnk - Clé orpheline
O4 - GS\Desktop [christophe]: SpyHunter.lnk . (...) -- C:\Program Files (x86)\Enigma Software Group\SpyHunter\SpyHunter4.exe (.not file.) =Crapware.SpyHunter
~ Global Startup: 84 Legitimates Filtered in 00mn 02s



---\\ Applications lancées au démarrage du sytème (O4)
O4 - GS\Startup [Public]: CineForm Status.lnk . (.GoPro - GoPro/CineForm Status Viewer.) -- C:\Program Files (x86)\CineForm\Tools\GoProCineFormStatusViewer.exe
O4 - GS\Startup [Public]: hp psc 1000 series.lnk . (.Hewlett-Packard Co. - HP OfficeJet COM Device Objects.) -- C:\Program Files (x86)\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe =.Hewlett-Packard Co
O4 - GS\Startup [Public]: hpoddt01.exe.lnk . (.Hewlett-Packard - hpotdd01.) -- C:\Program Files (x86)\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files (x86)\Synaptics\SynTP\SynTPEnh.exe (.not file.)
O4 - HKLM\..\Run: [SysTrayApp] . (.IDT, Inc. - IDT PC Audio.) -- C:\Program Files\IDT\WDM\sttray64.exe
O4 - HKLM\..\Run: [SetDefault] . (.Hewlett-Packard Development Company, L.P. - SetDefault.) -- C:\Program Files\Hewlett-Packard\HP LaunchBox\SetDefault.exe
O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] . (.Primax Electronics Ltd. - Mouse Suite 98 Daemon.) -- C:\Windows\System32\ICO.exe
O4 - HKLM\..\RunOnce: [NCPluginUpdater] . (.Hewlett-Packard - NCPluginUpdater.) -- C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe
O4 - HKCU\..\Run: [msnmsgr] . (.Microsoft Corporation - Windows Live Messenger.) -- C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
O4 - HKCU\..\Run: [Skype] . (.Skype Technologies S.A. - Skype.) -- C:\Program Files (x86)\Skype\Phone\Skype.exe =.Skype Technologies S.A.
O4 - HKCU\..\Run: [Mobile Partner] Clé orpheline
O4 - HKCU\..\Run: [ccleaner] . (.Piriform Ltd - CCleaner.) -- C:\Program Files\CCleaner\CCleaner64.exe =Piriform Ltd
O4 - HKLM\..\Wow6432Node\Run: [StartCCC] . (.Advanced Micro Devices, Inc. - Catalyst® Control Center Launcher.) -- C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe =.Advanced Micro Devices, Inc
O4 - HKLM\..\Wow6432Node\Run: [HPQuickWebProxy] . (.Hewlett-Packard Company - HP QuickWeb Utilities.) -- C:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe
O4 - HKLM\..\Wow6432Node\Run: [Adobe Reader Speed Launcher] . (.Adobe Systems Incorporated - Adobe Acrobat SpeedLauncher.) -- C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe
O4 - HKLM\..\Wow6432Node\Run: [Adobe ARM] . (.Adobe Systems Incorporated - Adobe Reader and Acrobat Manager.) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe =.Adobe Systems Incorporated
O4 - HKLM\..\Wow6432Node\Run: [Easybits Recovery] . (.EasyBits Software AS - Pas de description.) -- C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe =.EasyBits Software AS
O4 - HKLM\..\Wow6432Node\Run: [APSDaemon] . (.Apple Inc. - Apple Push.) -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
O4 - HKLM\..\Wow6432Node\Run: [iTunesHelper] . (.Apple Inc. - iTunesHelper.) -- C:\Program Files (x86)\iTunes\iTunesHelper.exe
O4 - HKLM\..\Wow6432Node\Run: [HP Quick Launch] . (.Hewlett-Packard Development Company, L.P. - HP Message Service.) -- C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
O4 - HKLM\..\Wow6432Node\Run: [HPOSD] . (.Hewlett-Packard Development Company, L.P. - HP On Screen Display.) -- C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
O4 - HKLM\..\Wow6432Node\Run: [SunJavaUpdateSched] . (.Oracle Corporation - Java(TM) Update Scheduler.) -- C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe =.Oracle Corporation
O4 - HKLM\..\Wow6432Node\Run: [AvastUI.exe] . (.AVAST Software - avast! Antivirus.) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files (x86)\Windows Sidebar\Sidebar.exe =.Microsoft Corporation
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files (x86)\Windows Sidebar\Sidebar.exe =.Microsoft Corporation
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =.Microsoft Corporation
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] . (.Microsoft Corporation - MCTAdmin.) -- C:\Windows\System32\mctadmin.exe =.Microsoft Corporation
O4 - HKUS\S-1-5-21-3147190806-3266541912-746446338-1002\..\Run: [msnmsgr] . (.Microsoft Corporation - Windows Live Messenger.) -- C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
O4 - HKUS\S-1-5-21-3147190806-3266541912-746446338-1002\..\Run: [Skype] . (.Skype Technologies S.A. - Skype.) -- C:\Program Files (x86)\Skype\Phone\Skype.exe =.Skype Technologies S.A.
O4 - HKUS\S-1-5-21-3147190806-3266541912-746446338-1002\..\Run: [Mobile Partner] Clé orpheline
O4 - HKUS\S-1-5-21-3147190806-3266541912-746446338-1002\..\Run: [ccleaner] . (.Piriform Ltd - CCleaner.) -- C:\Program Files\CCleaner\CCleaner64.exe =Piriform Ltd
~ Application: Scanned in 00mn 00s



---\\ Boutons situés sur la barre d'outils principale d'Internet Explorer (O9)
O9 - Extra button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll,-102 [64Bits] - {25510184-5A38-4A99-B273-DCA8EEF6CD08} . (...) -- C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\Resources\Icons\HP.ico
O9 - Extra button: Envoyer à OneNote [64Bits] - {2670000A-7350-4f3c-8081-5663EE0C6C49} -- C:\Program Files (x86)\MICROS~2\Office14\ONBttnIE.dll (.not file.)
O9 - Extra button: Notes liées OneNote [64Bits] - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} -- C:\Program Files (x86)\MICROS~2\Office14\ONBTTN~1.dll (.not file.)
~ IE Extra Buttons: Scanned in 00mn 00s



---\\ Modification Domaine/Adresses DNS (O17)
O17 - HKLM\System\CCS\Services\Tcpip\..\{66E05AA0-6B15-4F8B-A83F-45376B214CF3}: DhcpNameServer = 212.27.40.240 212.27.40.241
O17 - HKLM\System\CCS\Services\Tcpip\..\{F7489860-C68F-410F-8AE5-386C2F4848CE}: DhcpNameServer = 172.20.10.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{66E05AA0-6B15-4F8B-A83F-45376B214CF3}: DhcpNameServer = 212.27.40.240 212.27.40.241
O17 - HKLM\System\CS1\Services\Tcpip\..\{F7489860-C68F-410F-8AE5-386C2F4848CE}: DhcpNameServer = 172.20.10.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{66E05AA0-6B15-4F8B-A83F-45376B214CF3}: DhcpNameServer = 212.27.40.240 212.27.40.241
O17 - HKLM\System\CS2\Services\Tcpip\..\{F7489860-C68F-410F-8AE5-386C2F4848CE}: DhcpNameServer = 172.20.10.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 212.27.40.240 212.27.40.241
~ Domain: Scanned in 00mn 00s



---\\ Protocole additionnel (O18)
O18 - Handler: wlpg [64Bits] - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} . (...) --
O18 - Filter: video/x-flv [64Bits] - {20C75730-7C25-476B-95DC-C65810F9E489} . (.Advanced Micro Devices - MIME Video Detector for IE.) -- C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll
~ Protocole Additionnel: Scanned in 00mn 00s



---\\ Logiciels installés (O42)
O42 - Logiciel: Feux Instructifs version 1.0 - (.ANAXIMANDRE.) [HKLM][64Bits] -- {26925E27-DBD8-4FDA-B667-DDC3A7BAF344}_is1
~ Logic: 49 Legitimates Filtered in 00mn 01s



---\\ HKCU HKLM Software Keys
[HKCU\Software\CNPP]
[HKLM\Software\Wow6432Node\Shortcut_Module]
~ Key Software: 301 Legitimates Filtered in 00mn 01s



---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43)
O43 - CFD: 18/04/2012 - 18:24:01 - [1142,784] ----D C:\Program Files (x86)\Feux Instructifs
O43 - CFD: 14/12/2011 - 16:58:13 - [29,358] ----D C:\Program Files (x86)\Mares
O43 - CFD: 20/12/2013 - 22:27:53 - [1,225] ----D C:\ProgramData\Updater =PUP.CrossRider
O43 - CFD: 21/01/2014 - 11:58:19 - [43,420] ----D C:\ProgramData\{18165758-115C-4DC0-9EC2-FF89F725767F}
O43 - CFD: 24/11/2013 - 20:15:44 - [0] ----D C:\Users\christophe\AppData\Roaming\driver
O43 - CFD: 11/12/2011 - 10:06:54 - [0,001] ----D C:\Users\christophe\AppData\Roaming\newfolder3
O43 - CFD: 14/12/2011 - 16:59:48 - [0,001] ----D C:\Users\christophe\AppData\Local\Mares_Spa
O43 - CFD: 19/01/2014 - 14:54:53 - [0,005] ----D C:\Users\christophe\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpyHunter =Crapware.SpyHunter
~ 3 Dossiers CLSID vides (CLSID Empty Folders)
~ Program Folder: 167 Legitimates Filtered in 00mn 33s



---\\ Derniers fichiers modifiés ou crées sous Windows et System32 (O44)
O44 - LFC:[MD5.1237061F30B4211B85E67FD779C0DF92] - 26/02/2014 - 09:14:29 ---A- . (...) -- C:\Windows\win.ini [458]
~ Files: 55 Legitimates Filtered in 00mn 09s



---\\ Clé de registre Shell MountPoints2 (MPKS) (O51)
O51 - MPSK:{50f8911a-66e0-11e1-8606-101f74ccf689}\AutoRun\command. (...) -- G:\WD SmartWare.exe (.not file.)
O51 - MPSK:{9bfd4a3c-c181-11e2-9ca3-101f74ccf689}\AutoRun\command. (...) -- G:\AutoRun.exe (.not file.)
O51 - MPSK:{fee0c4d2-21eb-11e1-b369-806e6f6e6963}\AutoRun\command. (.Hewlett-Packard - ICE 1.1 Setup.) -- F:\setup.exe
~ Keys: Scanned in 00mn 00s



---\\ Enumération des clés de registre PoliciesSystem (MWPS) (O55)
O55 - MWPS:[HKLM\...\Policies\System] - "EnableLUA"=0
O55 - MWPS:[HKLM\...\Policies\System] - "EnableUIADesktopToggle"=0
O55 - MWPS:[HKLM\...\Policies\System] - "PromptOnSecureDesktop"=0
O55 - MWPS:[HKLM\...\Policies\System] - "FilterAdministratorToken"=0
~ MWPS: 21 Legitimates Filtered in 00mn 00s



---\\ Enumération des clés de registre PoliciesExplorer (MWPE) (O56)
O56 - MWPE:[HKLM\...\policies\Explorer] - "NoActiveDesktopChanges"=1
~ MWPE Keys: 4 Legitimates Filtered in 00mn 00s



---\\ Liste des pilotes du système (SDL) (O58)
O58 - SDL:[MD5.C04F7B373881009D7994D9BF55D24AB4] - 24/02/2014 - 16:39:27 ---A- . (...) -- C:\Windows\System32\Drivers\aswRvrt.sys [65776]
O58 - SDL:[MD5.90399625F341AB76BA4B85A5E860EB1F] - 24/02/2014 - 16:39:27 ---A- . (...) -- C:\Windows\System32\Drivers\aswVmm.sys [207904]
O58 - SDL:[MD5.0E5DA5369A0FCAEA12456DD852545184] - 14/07/2009 - 02:47:48 ---A- . (.Emulex - Storport Miniport Driver for LightPulse HBAs.) -- C:\Windows\System32\Drivers\elxstor.sys [530496]
O58 - SDL:[MD5.3B32CAA07D672F8A2E0DF5CB3A873F45] - 22/06/2012 - 11:01:32 ---A- . (...) -- C:\Windows\System32\Drivers\EsgScanner.sys [22704]
O58 - SDL:[MD5.06691B7CB86444BE0F95ACEB700F8140] - 18/01/2010 - 17:48:12 ---A- . (.Huawei Tech. Co., Ltd. - HUAWEI USB Smart Card Driver.) -- C:\Windows\System32\Drivers\ewdcsc.sys [32768]
O58 - SDL:[MD5.F2523EF6460FC42405B12248338AB2F0] - 10/06/2009 - 21:31:59 ---A- . (.Hauppauge Computer Works, Inc. - Hauppauge WinTV 885 Consumer IR Driver for eHome.) -- C:\Windows\System32\Drivers\hcw85cir.sys [31232]
O58 - SDL:[MD5.B51D1DA59AD8174E1C5E1F30ED02E93B] - 19/01/2008 - 18:47:00 R--A- . (.Primax Electronics Ltd. - Mouse Suite Driver (For Windows 2000 and Whistler Only).) -- C:\Windows\System32\Drivers\PELMOUSE.SYS [35840]
O58 - SDL:[MD5.98AFF2FA7BCF27FE0AF70E59634B48CF] - 27/03/2008 - 12:10:00 R--A- . (.Primax Electronics Ltd. - PS/2 Mouse Filter Driver (For Windows 2000 Only).) -- C:\Windows\System32\Drivers\PELPS2M.SYS [25088]
O58 - SDL:[MD5.CEA613F892F7FDBB33DFA88C38916515] - 03/06/2008 - 17:54:38 R--A- . (.Primax Electronics Ltd. - USB Mouse Low Filter Driver.) -- C:\Windows\System32\Drivers\PELUSBLF.SYS [27648]
O58 - SDL:[MD5.F3817967ED533D08327DC73BC4D5542A] - 14/07/2009 - 02:45:55 ---A- . (.Promise Technology - Promise SuperTrak EX Series Driver for Windows.) -- C:\Windows\System32\Drivers\stexstor.sys [24656]
O58 - SDL:[MD5.AA3C0336514C239A171F00A6902B59B8] - 17/12/2010 - 12:41:36 ---A- . (.IDT, Inc. - IDT PC Audio.) -- C:\Windows\System32\Drivers\stwrt64.sys [520192]
O58 - SDL:[MD5.C9E9D59C0099A9FF51697E9306A44240] - 13/12/2012 - 12:50:36 ---A- . (.Apple, Inc. - Apple Mobile Device USB Driver.) -- C:\Windows\System32\Drivers\usbaapl64.sys [54784]
~ Drivers: 21 Legitimates Filtered in 00mn 05s



---\\ Liste des outils de désinfection (LATC) (O63)
O63 - Logiciel: ZHPDiag 2014 - (.Nicolas Coolman.) [HKLM] -- ZHPDiag_is1 =.Nicolas Coolman
~ ADS: Scanned in 00mn 00s



---\\ Associations Shell Spawning (O67)
O67 - Shell Spawning: [HKCU\..\open\Command] (.Not Key.)
~ FASS Keys: 11 Legitimates Filtered in 00mn 00s



---\\ Menu de démarrage Internet (SMI) (O68)
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (...) -- C:\Users\christophe\AppData\Local\Torch\Application\torch.exe (.not file.)
~ Keys: Scanned in 00mn 00s



---\\ Recherche d'infection sur les navigateurs internet (SBI) (O69)
O69 - SBI: SearchScopes [HKCU] {0633EE93-D776-472f-A0FF-E1416B8B2E3A} - (Bing) - http://www.bing.com
O69 - SBI: SearchScopes [HKCU] {D944BB61-2E34-4DBF-A683-47E505C587DC} - (eBay) - http://rover.ebay.com =Toolbar.eBay
~ Keys: Scanned in 00mn 00s



---\\ Enumère les codes produits des logiciels (PUC) (O90)
O90 - PUC: "25BD30E1BC5D83343A835E62DDD4D41B" . (.Bing Bar.) -- C:\Windows\Installer\{1E03DB52-D5CB-4338-A338-E526DD4D4DB1}\icon_installer_ico =Toolbar.Bing
~ Update Products: 134 Legitimates Filtered in 00mn 00s



---\\ Etat général des services non Microsoft (EGS) (SR=Running, SS=Stopped)
SS - | Demand 20/02/2014 257928 | (AdobeFlashPlayerUpdateSvc) . (.Adobe Systems Incorporated.) - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
SS - | Demand 01/03/2011 183560 | (BBSvc) . (.Microsoft Corporation..) - C:\Program Files (x86)\Microsoft\BingBar\BBSvc.exe
SS - | Demand 12/10/2010 206072 | (GamesAppService) . (.WildTangent, Inc..) - C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe
SS - | Auto 09/12/2011 136176 | (gupdate) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
SS - | Demand 09/12/2011 136176 | (gupdatem) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
SS - | Auto 23/10/2013 172192 | (SkypeUpdate) . (.Skype Technologies.) - C:\Program Files (x86)\Skype\Updater\Updater.exe

SR - | Auto 18/12/2013 65432 | (AdobeARMservice) . (.Adobe Systems Incorporated.) - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
SR - | Auto 06/07/2011 204288 | (AMD External Events Utility) . (.AMD.) - C:\Windows\System32\atiesrxx.exe
SR - | Auto 05/07/2011 365568 | (AMD FUEL Service) . (.Advanced Micro Devices, Inc..) - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
SR - | Auto 21/12/2012 57008 | (Apple Mobile Device) . (.Apple Inc..) - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
SR - | Auto 24/02/2014 50344 | (avast! Antivirus) . (.AVAST Software.) - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
SR - | Auto 30/08/2011 462184 | (Bonjour Service) . (.Apple Inc..) - C:\Program Files\Bonjour\mDNSResponder.exe
SR - | Auto 10/07/1658 0 | (ezSharedSvc) . (.EasyBits Software AS.) - C:\Windows\System32\ezSharedSvcHost.exe =.EasyBits Software AS
SR - | Auto 04/11/2013 92160 | (HP Support Assistant Service) . (.Hewlett-Packard Company.) - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe =.Hewlett-Packard Co
SR - | Auto 11/10/2010 346168 | (HPClientSvc) . (.Hewlett-Packard Company.) - C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe
SR - | Auto 13/05/2013 270624 | (HPDrvMntSvc.exe) . (.Hewlett-Packard Company.) - C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
SR - | Demand 13/05/2013 1129760 | (hpqwmiex) . (.Hewlett-Packard Company.) - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
SR - | Auto 05/03/2012 35200 | (HPWMISVC) . (.Hewlett-Packard Development Company, L.P..) - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
SR - | Auto 23/06/2013 2413056 | (IconMan_R) . (.Realsil Microelectronics Inc..) - C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
SR - | Demand 20/02/2013 641352 | (iPod Service) . (.Apple Inc..) - C:\Program Files\iPod\bin\iPodService.exe
SR - | Auto 25/02/2011 249648 | (SeaPort) . (.Microsoft Corporation.) - C:\Program Files (x86)\Microsoft\BingBar\SeaPort.exe
SR - | Auto 18/10/2013 1025408 | (SpyHunter 4 Service) . (.Enigma Software Group USA, LLC..) - C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe =Crapware.SpyHunter
SR - | Auto 17/12/2010 276992 | (STacSV) . (.IDT, Inc..) - C:\Program Files\IDT\WDM\STacSV64.exe
SR - | Auto 17/12/2009 497856 | (vpnagent) . (.Cisco Systems, Inc..) - C:\Program Files (x86)\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe
SR - | Auto 14/07/2009 27136 | C:\Program Files (x86)\Windows Defender\mpsvc.dll (WinDefend) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe
SR - | Auto 10/07/1658 0 | (WMPNetworkSvc) . (...) - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe =.Microsoft Corporation
SR - | Auto 14/07/2009 27136 | C:\Windows\System32\wuaueng.dll (wuauserv) . (.Microsoft Corporation.) - C:\Windows\System32\svchost.exe

~ Services: Scanned in 00mn 23s



---\\ Scan Additionnel (O88)
Database Version : 13031 - (23/02/2014)
Clés trouvées (Keys found) : 9
Valeurs trouvées (Values found) : 1
Dossiers trouvés (Folders found) : 3
Fichiers trouvés (Files found) : 1

[HKLM\Software\Google\Chrome\Extensions\igjjkeeamkpihpncmmbgdkhdnjpcfmfb] =PUP.TubeDimmer^
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0E12F736682067FDE4D1158D5940A82E] =Toolbar.Ask
[HKLM\SYSTEM\CurrentControlSet\Services\SpyHunter 4 Service] =Crapware.SpyHunter
[HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{1E03DB52-D5CB-4338-A338-E526DD4D4DB1}] =Toolbar.Bing
[HKLM\Software\Classes\Installer\Features\25BD30E1BC5D83343A835E62DDD4D41B] =Toolbar.Bing
[HKLM\Software\Classes\Installer\Products\25BD30E1BC5D83343A835E62DDD4D41B] =Toolbar.Bing
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\25BD30E1BC5D83343A835E62DDD4D41B] =Toolbar.Bing
[HKLM\Software\Wow6432Node\Classes\Installer\Features\25BD30E1BC5D83343A835E62DDD4D41B] =Toolbar.Bing
[HKLM\Software\Wow6432Node\Classes\Installer\Products\25BD30E1BC5D83343A835E62DDD4D41B] =Toolbar.Bing
C:\Users\christophe\AppData\Local\Google\Chrome\User Data\Default\Extensions\igjjkeeamkpihpncmmbgdkhdnjpcfmfb =PUP.TubeDimmer^
C:\ProgramData\Updater =PUP.CrossRider^
C:\Users\christophe\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpyHunter =Crapware.SpyHunter^
C:\Users\christophe\Desktop\SpyHunter.lnk =Crapware.SpyHunter
~ Additionnel Scan: 330135 Items scanned in 00mn 40s



---\\ Récapitulatif des détections trouvées sur votre station
~ http://nicolascoolman.webs.com/apps/blo ... tubedimmer =PUP.TubeDimmer
~ http://nicolascoolman.webs.com/apps/blo ... -spyhunter =Crapware.SpyHunter
~ http://nicolascoolman.webs.com/apps/blo ... crossrider =PUP.CrossRider
~ http://nicolascoolman.webs.com/apps/blo ... oolbar-ask =Toolbar.Ask
~ MSI: 4 link(s) detected in 00mn 40s



~ 1150 Legitimates filtered by white list
End of the scan (454 lines in 05mn 10s)(0)

Et voila.
#108461
Bonsoir,

C'est fait et voici le rapport.

Rapport de ZHPFix 2014.2.16.5 par Nicolas Coolman, Update du 16/02/2014
Fichier d'export Registre :
Run by christophe at 26/02/2014 23:15:03
High Elevated Privileges : OK
Windows 7 Home Premium Edition, 64-bit Service Pack 1 (Build 7601)

Corbeille vidée (00mn 03s)
Dossier Prefetcher vidé

========== Clés du Registre ==========
SUPPRIMÉ: SearchScopes :{D944BB61-2E34-4DBF-A683-47E505C587DC}
SUPPRIMÉ: Service: BBSvc
SUPPRIMÉ:* HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0E12F736682067FDE4D1158D5940A82E
SUPPRIMÉ: HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{1E03DB52-D5CB-4338-A338-E526DD4D4DB1}
SUPPRIMÉ:* HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\25BD30E1BC5D83343A835E62DDD4D41B
SUPPRIMÉ: Service: SpyHunter 4 Service

========== Préférences navigateur ==========
PRESENT Chrome File: C:\Users\christophe\AppData\Local\Google\Chrome\User Data\Default\Preferences
SUPPRIMÉ Chrome Site: http://www.search.ask.com

========== Dossiers ==========
SUPPRIMÉ: C:\Users\christophe\AppData\Local\{4E36880E-5023-42ED-BAE0-D6F6ABD48F0B}
SUPPRIMÉ: C:\Users\christophe\AppData\Local\{91BCB2AF-78CD-4693-9783-9264BD786FCE}
SUPPRIMÉ: C:\Users\christophe\AppData\Local\{D829596B-165F-49D1-A8E2-070F8880F136}
SUPPRIMÉ: C:\Users\christophe\AppData\Local\{F64AFC04-B2FA-4650-9B15-96DFD0176F16}

========== Fichiers ==========
SUPPRIMÉ: c:\users\christophe\appdata\local\google\chrome\user data\default\preferences
SUPPRIMÉS Temporaires Windows (8) (41 127 octets)
SUPPRIMÉS Flash Cookies (0) (0 octets)

========== Restauration Système ==========
Point de restauration du système créé avec succès

========== Autre ==========
NON TRAITÉ O4 - HKLM \ .. \ Wow6432Node \ Run: [Adobe Reader Speed ??Launcher]. (.. Adobe Systems Incorporated - Adobe Acrobat SpeedLauncher) - C: \ Program Files (x86) \ Adobe \ lecteur 10.0 \ Reader \ reader_sl.exe
NON TRAITÉ O4 - GS \ Desktop [christophe]: Ordinateur - Raccourci.lnk - Clé orpheline
NON TRAITÉ O4 - HKLM \ .. \ Run: [Mobile Partner] Clé orpheline
NON TRAITÉ O4 - HKUS \ S-1-5-21-3147190806-3266541912-746446338-1002 \ .. \ Run: [Mobile Partner] Clé orpheline
NON TRAITÉ [HKLM \ Software \ Classes \ Installer \ Features \ 25BD30E1BC5D83343A835E62DDD4D41B]
NON TRAITÉ [HKLM \ Software \ Classes \ Installer \ Products \ 25BD30E1BC5D83343A835E62DDD4D41B]
NON TRAITÉ [HKLM \ Software \ Wow6432Node \ Classes \ Installer \ Features \ 25BD30E1BC5D83343A835E62DDD4D41B]
NON TRAITÉ [HKLM \ Software \ Wow6432Node \ Classes \ Installer \ Products \ 25BD30E1BC5D83343A835E62DDD4D41B]
NON TRAITÉ O4 - GS \ Desktop [christophe]: SpyHunter.lnk. (...) - C: \ Program Files (x86) \ Enigma Software Group \ SpyHunter \ SpyHunter4.exe (pas déposer..)
NON TRAITÉ [HKLM \ Software \ Google \ Chrome \ Extensions \ igjjkeeamkpihpncmmbgdkhdnjpcfmfb]
NON TRAITÉ [HKLM \ SYSTEM \ CurrentControlSet \ Services \ SpyHunter 4 Service]
NON TRAITÉ C: \ Users \ christophe \ AppData \ Local \ Google \ Chrome \ User \ données par défaut \ Extensions \ igjjkeeamkpihpncmmbgdkhdnjpcfmfb
NON TRAITÉ C: \ ProgramData \ Updater
NON TRAITÉ C: \ Users \ christophe \ AppData \ Roaming \ Microsoft \ Windows \ Start Menu \ Programs \ SpyHunter
NON TRAITÉ C: \ Users \ christophe \ Desktop \ SpyHunter.lnk


========== Récapitulatif ==========
6 : Clés du Registre
4 : Dossiers
3 : Fichiers
2 : Préférences navigateur
1 : Restauration Système
15 : Autre


End of clean in 00mn 25s

========== Chemin de fichier rapport ==========
C:\Users\christophe\AppData\Roaming\ZHP\ZHPFix[R1].txt - 26/02/2014 23:15:07 [3601]


Christophe
#108670
Bonsoir,

voici les rapports de la finalisation.

# DelFix v10.6 - Rapport créé le 27/02/2014 à 20:13:33
# Mis à jour le 11/11/2013 par Xplode
# Nom d'utilisateur : christophe - CHRISTOPHE-HP
# Système d'exploitation : Windows 7 Home Premium Service Pack 1 (64 bits)

~ Activation de l'UAC ... OK

~ Suppression des outils de désinfection ...

Supprimé : C:\AdwCleaner
Supprimé : C:\Users\christophe\AppData\Roaming\ZHP
Supprimé : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ZHP
Supprimé : C:\Program Files (x86)\ZHPDiag
Supprimé : C:\Users\christophe\Downloads\adwcleaner (1).exe
Supprimé : C:\Users\christophe\Downloads\adwcleaner (2).exe
Supprimé : C:\Users\christophe\Downloads\adwcleaner (3).exe
Supprimé : C:\Users\christophe\Downloads\adwcleaner (4).exe
Supprimé : C:\Users\christophe\Downloads\adwcleaner (5).exe
Supprimé : C:\Users\christophe\Downloads\adwcleaner (6).exe
Supprimé : C:\Users\christophe\Downloads\adwcleaner (7).exe
Supprimé : C:\Users\christophe\Downloads\adwcleaner (8).exe
Supprimé : C:\Users\christophe\Downloads\adwcleaner.exe
Supprimé : C:\Users\christophe\Downloads\JRT.exe
Supprimé : C:\Users\christophe\Downloads\zhpdiag20.exe
Supprimée : HKLM\SOFTWARE\AdwCleaner
Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ZHPDiag_is1

~ Sauvegarde de la base de registre ... OK

~ Purge de la restauration système ...

Supprimé : RP #247 [avast! antivirus system restore point | 02/24/2014 15:37:15]
Supprimé : RP #249 [Installé hp psc 1200 series | 02/25/2014 21:04:30]
Supprimé : RP #250 [ZHPFix Restore System Point | 02/26/2014 22:14:49]

Nouveau point de restauration créé !

########## - EOF - ##########



et puis:

Results of screen317's Security Check version 0.99.79  
Windows 7 Service Pack 1 x64 (UAC is enabled)  
Internet Explorer 11  
``````````````Antivirus/Firewall Check:``````````````
avast! Antivirus  
Antivirus up to date!  
`````````Anti-malware/Other Utilities Check:`````````
Malwarebytes Anti-Malware version 1.75.0.1300  
Java 7 Update 51  
Adobe Reader 10.1.9 Adobe Reader out of Date!  
Google Chrome 31.0.1650.57  
Google Chrome 31.0.1650.63  
````````Process Check: objlist.exe by Laurent````````  
AVAST Software Avast AvastSvc.exe  
AVAST Software Avast AvastUI.exe  
`````````````````System Health check`````````````````
Total Fragmentation on Drive C: =
````````````````````End of Log``````````````````````


Je pense que cette fois c'est tout bon.
Merci  pour cette aide précieuse et pour votre disponibilité.

et encore     

Christophe

Merci encore pour votre aide. :good: Je vous tr[…]

Bonjour, Je viens de monter un pc bureautique et &[…]

Présentation Kev28

Salut :cheers: