Pb allssearch

Fermé
laikai - 15 juil. 2012 à 10:30
anthony5151 Messages postés 10573 Date d'inscription vendredi 27 juin 2008 Statut Contributeur sécurité Dernière intervention 2 mars 2015 - 16 juil. 2012 à 13:36
Bonjour,
j'ai un problème en ouvrant firefox, la page d'accueil s'ouvre avec allssearch.

J'ai essayé qq trucs trouvés sur le net mais le problème est tjs là.

Je poste mon rapport ZHPDiag, si quelqu'un pouvait m'aider ce serait sympa.

Rapport de ZHPDiag v1.31.105 par Nicolas Coolman, Update du 25/06/2012
Run by Laikai at 15/07/2012 10:27:06
Web site : http://www.premiumorange.com/zeb-help-process/zhpdiag.html
Web site : http://nicolascoolman.skyrock.com/
State : Version à jour.


---\\ Web Browser
MSIE: Internet Explorer v

---\\ Windows Product Information
~ Langage: Français
Windows 7 Home Premium Edition, 64-bit Service Pack 1 (Build 7601)
Windows Server License Manager Script : OK
~ Windows(R) 7, OEM_SLP channel
System Locked Preinstallation (OEM_SLP) : OK
Windows ID Activation : OK
~ Windows Partial Key : 9YQTR
Windows License : OK
~ Windows Remaining Initializations Number : 1
Software Protection Service (Protection logicielle) : KO
Windows Automatic Updates : OK
Windows Activation Technologies : OK

---\\ System Information
~ Processor: Intel64 Family 6 Model 42 Stepping 7, GenuineIntel
~ Operating System: 64 Bits
Boot mode: Normal (Normal boot)
Total RAM: 6050 MB (67% free)
System Restore: Inconnu (Unknown)
System drive C: has 217 GB (77%) free of 279 GB

---\\ Logged in mode
~ Computer Name: LAIKAI-PC
~ User Name: Laikai
~ All Users Names: UpdatusUser, Laikai, HomeGroupUser$, Administrateur,
~ Unselected Option: O45,O61,O62,O65,O66,O80,O82,O89
Logged in as Administrator

---\\ Environnement Variables
~ System Unit : C:\
~ %AppData% : C:\Users\Laikai\AppData\Roaming\
~ %Desktop% : C:\Users\Laikai\Desktop\
~ %Favorites% : C:\Users\Laikai\Favorites\
~ %LocalAppData% : C:\Users\Laikai\AppData\Local\
~ %StartMenu% : C:\Users\Laikai\AppData\Roaming\Microsoft\Windows\Start Menu\
~ %Windir% : C:\Windows\
~ %System% : C:\Windows\System32\

---\\ DOS/Devices
C:\ Hard drive, Flash drive, Thumb drive (Free 217 Go of 279 Go)
D:\ Hard drive, Flash drive, Thumb drive (Free 257 Go of 394 Go)
E:\ CD-ROM drive (Not Inserted)
Q:\ Hard drive, Flash drive, Thumb drive (Free 0 Go of 0 Go)



---\\ Security Center & Tools Informations
~ Scan Security Center in 00mn 00s



---\\ Recherche particulière de fichiers génériques
[MD5.332FEAB1435662FC6C672E25BEB37BE3] - (.Microsoft Corporation - Explorateur Windows.) (.25/02/2011 - 07:19:30.) -- C:\Windows\Explorer.exe [2871808]
[MD5.94355C28C1970635A31B3FE52EB7CEBA] - (.Microsoft Corporation - Application de démarrage de Windows.) (.14/07/2009 - 02:39:52.) -- C:\Windows\System32\Wininit.exe [129024]
[MD5.5A45FA344F4AD99D903F4B20E43B89EC] - (.Microsoft Corporation - Extensions Internet pour Win32.) (.02/06/2012 - 13:05:28.) -- C:\Windows\System32\wininet.dll [1392128]
[MD5.1151B1BAA6F350B1DB6598E0FEA7C457] - (.Microsoft Corporation - Application d'ouverture de session Windows.) (.20/11/2010 - 14:25:32.) -- C:\Windows\System32\Winlogon.exe [390656]
[MD5.067FA52BFB59A56110A12312EF9AF243] - (.Microsoft Corporation - Bibliothèque de licences.) (.20/11/2010 - 14:27:28.) -- C:\Windows\System32\sppcomapi.dll [232448]
[MD5.1C7857B62DE5994A75B054A9FD4C3825] - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) (.28/12/2011 - 04:59:24.) -- C:\Windows\system32\Drivers\AFD.sys [498688]
[MD5.02062C0B390B7729EDC9E69C680A6F3C] - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) (.14/07/2009 - 02:52:21.) -- C:\Windows\system32\Drivers\atapi.sys [24128]
[MD5.B8BD2BB284668C84865658C77574381A] - (.Microsoft Corporation - CD-ROM File System Driver.) (.14/07/2009 - 00:19:47.) -- C:\Windows\system32\Drivers\Cdfs.sys [92160]
[MD5.F036CE71586E93D94DAB220D7BDF4416] - (.Microsoft Corporation - SCSI CD-ROM Driver.) (.20/11/2010 - 10:19:22.) -- C:\Windows\system32\Drivers\Cdrom.sys [147456]
[MD5.9BB2EF44EAA163B29C4A4587887A0FE4] - (.Microsoft Corporation - DFS Namespace Client Driver.) (.20/11/2010 - 10:26:34.) -- C:\Windows\system32\Drivers\DfsC.sys [102400]
[MD5.97BFED39B6B79EB12CDDBFEED51F56BB] - (.Microsoft Corporation - High Definition Audio Bus Driver.) (.20/11/2010 - 11:43:44.) -- C:\Windows\system32\Drivers\HDAudBus.sys [122368]
[MD5.FA55C73D4AFFA7EE23AC4BE53B4592D3] - (.Microsoft Corporation - Pilote de port i8042.) (.14/07/2009 - 00:19:57.) -- C:\Windows\system32\Drivers\i8042prt.sys [105472]
[MD5.AF9B39A7E7B6CAA203B3862582E9F2D0] - (.Microsoft Corporation - IP Network Address Translator.) (.14/07/2009 - 01:10:03.) -- C:\Windows\system32\Drivers\IpNat.sys [116224]
[MD5.A5D9106A73DC88564C825D317CAC68AC] - (.Microsoft Corporation - Windows NT SMB Minirdr.) (.27/04/2011 - 03:40:40.) -- C:\Windows\system32\Drivers\MRxSmb.sys [158208]
[MD5.09594D1089C523423B32A4229263F068] - (.Microsoft Corporation - MBT Transport driver.) (.20/11/2010 - 10:23:22.) -- C:\Windows\system32\Drivers\netBT.sys [261632]
[MD5.A2F74975097F52A00745F9637451FDD8] - (.Microsoft Corporation - Pilote du système de fichiers NT.) (.11/03/2011 - 07:41:34.) -- C:\Windows\system32\Drivers\ntfs.sys [1659776]
[MD5.0086431C29C35BE1DBC43F52CC273887] - (.Microsoft Corporation - Pilote de port parallèle.) (.14/07/2009 - 01:00:41.) -- C:\Windows\system32\Drivers\Parport.sys [97280]
[MD5.471815800AE33E6F1C32FB1B97C490CA] - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) (.20/11/2010 - 11:52:36.) -- C:\Windows\system32\Drivers\Rasl2tp.sys [129536]
[MD5.548260A7B8654E024DC30BF8A7C5BAA4] - (.Microsoft Corporation - SMB Transport driver.) (.14/07/2009 - 01:09:09.) -- C:\Windows\system32\Drivers\smb.sys [93184]
[MD5.DDAD5A7AB24D8B65F8D724F5C20FD806] - (.Microsoft Corporation - TDI Translation Driver.) (.20/11/2010 - 10:21:58.) -- C:\Windows\system32\Drivers\tdx.sys [119296]
[MD5.0D08D2F3B3FF84E433346669B5E0F639] - (.Microsoft Corporation - Pilote de cliché instantané du volume.) (.20/11/2010 - 14:34:04.) -- C:\Windows\system32\Drivers\volsnap.sys [295808]
~ Scan Generic Processes in 00mn 00s



---\\ Etat des fichiers cachés (Caché/Total)
~ Mes images (My Pictures) : 1/11
~ Mes Favoris (My Favorites) : 1/8
~ Mes Documents (My Documents) : 1/117
~ Mon Bureau (My Desktop) : 1/77
~ Menu demarrer (Programs) : 0/33
~ Scan Hidden Files in 00mn 00s



---\\ Processus lancés
[MD5.5BB1F77C8AF725A15EC9366498D275BB] - (.ASUS - ATKOSD2.) -- C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [5732992] [PID.2328]
[MD5.37DEB76A2CF005841C4E45DE2B94D84F] - (.ASUS - AsScrPro.) -- C:\Windows\AsScrPro.exe [3058304] [PID.2356]
[MD5.57B4D34232852BFE4453BE571DF90D21] - (.CyberLink - CyberLink MediaLibray Service.) -- C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe [103720] [PID.2736]
[MD5.34B200C21B9B314ABF6D41EA3743ABF2] - (.Siber Systems - RoboForm TaskBar Icon.) -- C:\Program Files (x86)\Siber Systems\AI RoboForm\robotaskbaricon.exe [107000] [PID.4312]
[MD5.7EE22E13DEC8A6D18F4643C1EA34B0F0] - (.Virage Logic Corporation / Sonic Focus - ASUS_MATray.exe.) -- C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe [984400] [PID.4580]
[MD5.79A3B950988F8D2B81906D0C0473158B] - (.ASUS - ATK Media.) -- C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [170624] [PID.4624]
[MD5.5AEBF6FA9805C9101220AA4FB4FA17E7] - (.ASUS - HControlUser.) -- C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [105016] [PID.4640]
[MD5.36E7CE6EA4C190AA88C25CDD3C89D84C] - (.ASUS - Wireless Console 3.) -- C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [2255360] [PID.4668]
[MD5.22EC0852DBF032A93D8DA697065FA189] - (.CyberLink Corp. - PowerDVD RC Service.) -- C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [87336] [PID.4688]
[MD5.C252C2303FE79F201E64F269FEFF0DDB] - (.cyberlink - brs.) -- C:\Program Files (x86)\CyberLink\Shared files\brs.exe [75048] [PID.4696]
[MD5.2B5CB6B9ED2DB19F23C26E9BAE652052] - (.SEIKO EPSON CORPORATION - EEventManager Application.) -- C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe [669520] [PID.4752]
[MD5.D3C0837346C49095B8AF9EF54AD7E90A] - (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe [913888] [PID.7156]
[MD5.BE955BAB4EFC2A28BE2692D102FFC85A] - (...) -- C:\Program Files (x86)\ZHPDiag\ZHPDiag.exe [3838464] [PID.828]
~ Scan Processes Running in 00mn 00s



---\\ Mozilla Firefox, Plugins,Demarrage,Recherche,Extensions (P2,M0,M1,M2,M3)
C:\Users\Laikai\AppData\Roaming\Mozilla\Firefox\Profiles\ap923qdm.default\prefs.js
C:\Users\Laikai\AppData\Roaming\Mozilla\Firefox\Profiles\ap923qdm.default\user.js
M3 - MFPP: Plugins - [Laikai] -- C:\Users\Laikai\AppData\Roaming\Mozilla\Firefox\Profiles\ap923qdm.default\searchplugins\google-language-fr.xml
M3 - MFPP: Plugins - [Laikai] -- C:\Users\Laikai\AppData\Roaming\Mozilla\Firefox\Profiles\ap923qdm.default\searchplugins\yahoo-zugo.xml
M3 - MFPP: Plugins - [Laikai] -- C:\Program Files (x86)\Mozilla FireFox\searchplugins\amazon-france.xml
M3 - MFPP: Plugins - [Laikai] -- C:\Program Files (x86)\Mozilla FireFox\searchplugins\bing.xml
M3 - MFPP: Plugins - [Laikai] -- C:\Program Files (x86)\Mozilla FireFox\searchplugins\cnrtl-tlfi-fr.xml
M3 - MFPP: Plugins - [Laikai] -- C:\Program Files (x86)\Mozilla FireFox\searchplugins\eBay-france.xml
M3 - MFPP: Plugins - [Laikai] -- C:\Program Files (x86)\Mozilla FireFox\searchplugins\google.xml
M3 - MFPP: Plugins - [Laikai] -- C:\Program Files (x86)\Mozilla FireFox\searchplugins\wikipedia-fr.xml
M3 - MFPP: Plugins - [Laikai] -- C:\Program Files (x86)\Mozilla FireFox\searchplugins\yahoo-france.xml
M0 - MFSP: prefs.js [Laikai - ap923qdm.default] http://allssearch.com
M0 - MFSP: user.js [Laikai - ap923qdm.default] http://allssearch.com/
M2 - MFEP: prefs.js [Laikai - ap923qdm.default\{5911488E-9D1E-40ec-8CBB-06B231CC153F}] [] StartNow Toolbar v2.4.0 (.StartNow.com.)
M2 - MFEP: prefs.js [Laikai - ap923qdm.default\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}] [] BitComet ????? v1.31 (.BitComet.)
P2 - FPN:Firefox Plugin Navigator . (.Microsoft Corporation - np-mswmp.) -- C:\Program Files (x86)\Mozilla Firefox\Plugins\np-mswmp.dll
P2 - FPN:Firefox Plugin Navigator . (.BitComet - BitCometAgent v1.30 for Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\Plugins\npBitCometAgent.dll
P2 - FPN:Firefox Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files (x86)\Mozilla Firefox\Plugins\npqtplugin.dll
P2 - FPN:Firefox Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files (x86)\Mozilla Firefox\Plugins\npqtplugin2.dll
P2 - FPN:Firefox Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files (x86)\Mozilla Firefox\Plugins\npqtplugin3.dll
P2 - FPN:Firefox Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files (x86)\Mozilla Firefox\Plugins\npqtplugin4.dll
P2 - FPN:Firefox Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files (x86)\Mozilla Firefox\Plugins\npqtplugin5.dll
P2 - FPN:Firefox Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files (x86)\Mozilla Firefox\Plugins\npqtplugin6.dll
P2 - FPN:Firefox Plugin Navigator . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) -- C:\Program Files (x86)\Mozilla Firefox\Plugins\npqtplugin7.dll
~ Scan Firefox Browser in 00mn 00s



---\\ Internet Explorer, Démarrage,Recherche,URLSearchHook, Phishing (R0,R1,R3,R4)
R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://allssearch.com
R0 - HKCU\SOFTWARE\Classes\Software\Microsoft\Internet Explorer\Main,Start Page = http://allssearch.com
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://asus.msn.com
R3 - URLSearchHook: (no name) [64Bits] - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} . (.Apple Inc. - The QuickTime Plugin allows you to view a wide variety of multimedia c.) (No version) -- (.not file.)
~ Scan IE Browser in 00mn 00s



---\\ Internet Explorer, Proxy Management (R5)
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = no key
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll
~ Scan Proxy management in 00mn 00s



---\\ Redirection du fichier Hosts (O1)
~ Le fichier hosts est sain (The hosts file is clean).
~ Scan Hosts File in 00mn 00s
~ Nombre de lignes (Lines number): 21



---\\ Applications démarrées par registre & par dossier (O4)
O4 - HKCU\..\Run: [Sidebar] . (.Microsoft Corporation - Gadgets du Bureau Windows.) -- C:\Program Files\Windows Sidebar\sidebar.exe
O4 - HKCU\..\Run: [RoboForm] . (.Siber Systems - RoboForm TaskBar Icon.) -- C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
O4 - HKCU\..\Run: [EPSON SX510W Series] . (.SEIKO EPSON CORPORATION - EPSON Status Monitor 3.) -- C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIFIE.exe
O4 - HKCU\..\Run: [Epson Stylus SX510W(Réseau)] . (.SEIKO EPSON CORPORATION - EPSON Status Monitor 3.) -- C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIFIE.exe
~ Scan Application in 00mn 00s



---\\ Autres liens utilisateurs (O4)
O4 - Global Startup: C:\Users\Laikai\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk . (.Microsoft Corporation.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
O4 - Global Startup: C:\Users\Laikai\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk . (.Microsoft Corporation.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
O4 - Global Startup: C:\Users\Laikai\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\eBay Turbo Lister 2.lnk . (.eBay Inc..) -- C:\Program Files (x86)\eBay\Turbo Lister2\tl.exe
O4 - Global Startup: C:\Users\Laikai\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk . (.Google Inc..) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
O4 - Global Startup: C:\Users\Laikai\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk . (.Microsoft Corporation.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
~ Scan Global Startup in 00mn 00s



---\\ Lignes supplémentaires dans le menu contextuel d'Internet Explorer (O8)
O8 - Extra context menu item: Barre RoboForm - (.not file.) - file:\\C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Enregistrer le formulaire - (.not file.) - file:\\C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O8 - Extra context menu item: Personnaliser le menu - (.not file.) - file:\\C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Remplir le formulaire - (.not file.) - file:\\C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: Tout télécharger avec BitComet . (.www.BitComet.com - BitComet - a BitTorrent Client.) -- C:\Program Files (x86)\BitComet\BitComet.exe
O8 - Extra context menu item: Télécharger avec BitComet . (.www.BitComet.com - BitComet - a BitTorrent Client.) -- C:\Program Files (x86)\BitComet\BitComet.exe
~ Scan IE Menu Contextuel in 00mn 00s



---\\ Enumération Active Desktop & MHTML Editor (O24)
O24 - Default MHTML Editor: Last - .(...) - (.not file.)
~ Scan Desktop Component in 00mn 00s



---\\ Tâches planifiées en automatique (O39)
O39 - APT:Automatic Planified Task - C:\Windows\Tasks\Adobe Flash Player Updater.job
O39 - APT:Automatic Planified Task - C:\Windows\Tasks\Epson Printer Software Downloader.job
O39 - APT:Automatic Planified Task - C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
O39 - APT:Automatic Planified Task - C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
[MD5.5BB1F77C8AF725A15EC9366498D275BB] [APT] [ATKOSD2] (.ASUS.) -- C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
[MD5.6F90566A055EF53135205897AAE68AA4] [APT] [Epson Printer Software Downloader] (.SEIKO EPSON CORPORATION.) -- C:\Program Files (x86)\EPSON\EPAPDL\E_SAPDL2.exe
[MD5.34B200C21B9B314ABF6D41EA3743ABF2] [APT] [Run RoboForm TaskBar Icon] (.Siber Systems.) -- C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
[MD5.666A1E7EB3DFADB5ECE37B3E3B42FD06] [APT] [{114DCACC-BE2D-46E6-BE3F-F8F8B7C8D7D1}] (...) -- D:\Downloads\virtualdub\auxsetup.exe
[MD5.34EBD4FF6A24D86BB4716D6AFCC1A89B] [APT] [AppleSoftwareUpdate] (.Apple Inc..) -- C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe
~ Scan Scheduled Task in 00mn 00s



---\\ Composants installés (ActiveSetup Installed Components) (O40) (None)

---\\ Contenu des dossiers Programs/ProgramFiles/ProgramData/AppData (O43)
O43 - CFD: 15/04/2012 - 09:47:16 - [118,664] ----D C:\Program Files (x86)\ABBYY FineReader 6.0 Sprint
O43 - CFD: 29/06/2012 - 19:08:44 - [0] ----D C:\Program Files (x86)\allsearch
O43 - CFD: 14/10/2011 - 08:58:11 - [2,896] ----D C:\Program Files (x86)\AmIcoSingLun
O43 - CFD: 08/04/2012 - 20:17:47 - [2,316] ----D C:\Program Files (x86)\Apple Software Update
O43 - CFD: 18/02/2012 - 12:22:47 - [517,058] ----D C:\Program Files (x86)\ASUS
O43 - CFD: 18/02/2012 - 21:49:30 - [24,712] ----D C:\Program Files (x86)\BitComet
O43 - CFD: 14/10/2011 - 08:58:23 - [3,432] ----D C:\Program Files (x86)\Cisco
O43 - CFD: 07/07/2012 - 10:33:44 - [171,877] ----D C:\Program Files (x86)\Common Files
O43 - CFD: 14/10/2011 - 09:03:18 - [476,601] ----D C:\Program Files (x86)\CyberLink
O43 - CFD: 10/06/2012 - 11:21:56 - [43,736] ----D C:\Program Files (x86)\eBay
O43 - CFD: 15/04/2012 - 09:49:56 - [15,447] ----D C:\Program Files (x86)\epson
O43 - CFD: 15/04/2012 - 09:48:56 - [114,292] ----D C:\Program Files (x86)\Epson Software
O43 - CFD: 15/04/2012 - 09:27:29 - [14,058] ----D C:\Program Files (x86)\EpsonNet
O43 - CFD: 28/05/2012 - 21:29:09 - [289,649] ----D C:\Program Files (x86)\Google
O43 - CFD: 15/04/2012 - 09:54:20 - [58,166] --H-D C:\Program Files (x86)\InstallShield Installation Information
O43 - CFD: 14/10/2011 - 08:51:52 - [14,997] ----D C:\Program Files (x86)\Intel
O43 - CFD: 12/07/2012 - 05:13:11 - [8,175] ----D C:\Program Files (x86)\Internet Explorer
O43 - CFD: 07/06/2012 - 21:55:12 - [57,095] ----D C:\Program Files (x86)\K-Lite Codec Pack
O43 - CFD: 15/07/2012 - 09:03:22 - [11,720] ----D C:\Program Files (x86)\Malwarebytes' Anti-Malware
O43 - CFD: 13/04/2011 - 04:47:20 - [17,977] ----D C:\Program Files (x86)\Microsoft
O43 - CFD: 06/03/2012 - 22:32:43 - [12,399] ----D C:\Program Files (x86)\Microsoft Application Virtualization Client
O43 - CFD: 06/03/2012 - 11:58:48 - [6,425] ----D C:\Program Files (x86)\Microsoft Office
O43 - CFD: 12/05/2012 - 22:16:41 - [40,838] ----D C:\Program Files (x86)\Microsoft Silverlight
O43 - CFD: 13/04/2011 - 04:42:56 - [1,745] ----D C:\Program Files (x86)\Microsoft SQL Server Compact Edition
O43 - CFD: 21/02/2012 - 22:20:00 - [0,015] ----D C:\Program Files (x86)\Microsoft.NET
O43 - CFD: 17/06/2012 - 08:13:51 - [44,259] ----D C:\Program Files (x86)\Mozilla Firefox
O43 - CFD: 18/06/2012 - 15:01:49 - [0,195] ----D C:\Program Files (x86)\Mozilla Maintenance Service
O43 - CFD: 14/06/2012 - 18:29:14 - [50,769] ----D C:\Program Files (x86)\MpcStar
O43 - CFD: 14/07/2009 - 07:32:38 - [0,025] ----D C:\Program Files (x86)\MSBuild
O43 - CFD: 13/04/2011 - 04:33:04 - [42,963] ----D C:\Program Files (x86)\Nuance
O43 - CFD: 14/10/2011 - 08:54:28 - [6,580] ----D C:\Program Files (x86)\NVIDIA Corporation
O43 - CFD: 09/06/2012 - 17:35:01 - [72,431] ----D C:\Program Files (x86)\QuickTime
O43 - CFD: 14/10/2011 - 08:58:21 - [11,877] ----D C:\Program Files (x86)\Ralink
O43 - CFD: 14/10/2011 - 08:57:18 - [12,690] ----D C:\Program Files (x86)\Realtek
O43 - CFD: 14/07/2009 - 07:32:38 - [37,349] ----D C:\Program Files (x86)\Reference Assemblies
O43 - CFD: 18/02/2012 - 17:20:45 - [17,352] ----D C:\Program Files (x86)\Siber Systems
O43 - CFD: 07/07/2012 - 10:34:03 - [34,215] R---D C:\Program Files (x86)\Skype
O43 - CFD: 26/05/2012 - 17:20:13 - [0,300] ----D C:\Program Files (x86)\StartNow Toolbar
O43 - CFD: 13/04/2011 - 04:49:28 - [161,465] ----D C:\Program Files (x86)\syncables
O43 - CFD: 14/10/2011 - 08:57:48 - [0] --H-D C:\Program Files (x86)\Temp
O43 - CFD: 14/07/2009 - 06:57:06 - [0] --H-D C:\Program Files (x86)\Uninstall Information
O43 - CFD: 07/06/2012 - 21:58:12 - [88,797] ----D C:\Program Files (x86)\VideoLAN
O43 - CFD: 28/05/2012 - 21:36:58 - [90,254] ----D C:\Program Files (x86)\WebSite X5 v8 - Evolution
O43 - CFD: 28/05/2012 - 21:27:12 - [0,002] ----D C:\Program Files (x86)\WebSite X5 v9 - Evolution
O43 - CFD: 23/02/2012 - 19:51:22 - [0,500] ----D C:\Program Files (x86)\Windows Defender
O43 - CFD: 20/06/2012 - 15:23:03 - [329,401] ----D C:\Program Files (x86)\Windows Live
O43 - CFD: 23/02/2012 - 19:51:22 - [5,895] ----D C:\Program Files (x86)\Windows Mail
O43 - CFD: 23/02/2012 - 19:51:22 - [4,791] ----D C:\Program Files (x86)\Windows Media Player
O43 - CFD: 14/07/2009 - 07:32:38 - [11,632] ----D C:\Program Files (x86)\Windows NT
O43 - CFD: 23/02/2012 - 19:51:22 - [4,213] ----D C:\Program Files (x86)\Windows Photo Viewer
O43 - CFD: 18/02/2011 - 22:09:10 - [0,181] ----D C:\Program Files (x86)\Windows Portable Devices
O43 - CFD: 23/02/2012 - 19:52:00 - [5,717] ----D C:\Program Files (x86)\Windows Sidebar
O43 - CFD: 18/02/2012 - 17:18:03 - [4,008] ----D C:\Program Files (x86)\WinRAR
O43 - CFD: 15/07/2012 - 10:27:11 - [12,845] ----D C:\Program Files (x86)\ZHPDiag
O43 - CFD: 08/04/2012 - 20:17:52 - [60,279] ----D C:\Program Files (x86)\Common Files\Apple
O43 - CFD: 06/03/2012 - 11:58:48 - [0,095] ----D C:\Program Files (x86)\Common Files\DESIGNER
O43 - CFD: 30/04/2012 - 10:37:21 - [4,115] ----D C:\Program Files (x86)\Common Files\EPSON
O43 - CFD: 15/04/2012 - 09:48:16 - [4,893] ----D C:\Program Files (x86)\Common Files\InstallShield
O43 - CFD: 14/10/2011 - 08:51:53 - [13,612] ----D C:\Program Files (x86)\Common Files\Intel
O43 - CFD: 20/06/2012 - 15:22:33 - [37,365] ----D C:\Program Files (x86)\Common Files\microsoft shared
O43 - CFD: 13/04/2011 - 04:48:00 - [0,338] ----D C:\Program Files (x86)\Common Files\Oberon Media
O43 - CFD: 14/10/2011 - 08:50:15 - [0,154] ----D C:\Program Files (x86)\Common Files\postureAgent
O43 - CFD: 14/07/2009 - 05:20:08 - [0,003] ----D C:\Program Files (x86)\Common Files\Services
O43 - CFD: 07/07/2012 - 10:33:44 - [2,056] ----D C:\Program Files (x86)\Common Files\Skype
O43 - CFD: 14/07/2009 - 05:20:08 - [39,200] ----D C:\Program Files (x86)\Common Files\SpeechEngines
O43 - CFD: 23/02/2012 - 19:51:58 - [9,767] ----D C:\Program Files (x86)\Common Files\System
O43 - CFD: 13/04/2011 - 04:33:36 - [0] ----D C:\Program Files (x86)\Common Files\Windows Live
O43 - CFD: 14/10/2011 - 08:58:11 - [0,000] ----D C:\ProgramData\AmUStor
O43 - CFD: 08/04/2012 - 20:17:46 - [41,037] ----D C:\ProgramData\Apple
O43 - CFD: 09/06/2012 - 17:34:52 - [25,578] ----D C:\ProgramData\Apple Computer
O43 - CFD: 14/07/2009 - 07:08:56 - [0] --H-D C:\ProgramData\Application Data
O43 - CFD: 13/03/2012 - 19:07:38 - [0,063] ----D C:\ProgramData\ASUS
O43 - CFD: 14/07/2012 - 22:40:14 - [0] ----D C:\ProgramData\boost_interprocess
O43 - CFD: 18/02/2012 - 12:09:14 - [4,522] ----D C:\ProgramData\ChangeFolderView
O43 - CFD: 02/03/2012 - 20:22:12 - [0,053] ----D C:\ProgramData\CyberLink
O43 - CFD: 14/07/2009 - 07:08:56 - [0] --H-D C:\ProgramData\Desktop
O43 - CFD: 14/07/2009 - 07:08:56 - [0] --H-D C:\ProgramData\Documents
O43 - CFD: 13/04/2011 - 04:33:02 - [18,933] ----D C:\ProgramData\Downloaded Installations
O43 - CFD: 10/06/2012 - 11:21:56 - [52,464] ----D C:\ProgramData\eBay
O43 - CFD: 05/03/2012 - 10:49:51 - [8,356] ----D C:\ProgramData\EPSON
O43 - CFD: 24/03/2012 - 08:53:28 - [142,126] ----D C:\ProgramData\ESET
O43 - CFD: 14/07/2009 - 07:08:56 - [0] --H-D C:\ProgramData\Favorites
O43 - CFD: 13/04/2011 - 04:33:04 - [3,807] ----D C:\ProgramData\FLEXnet
O43 - CFD: 18/02/2012 - 12:06:14 - [0,893] ----D C:\ProgramData\FolderView
O43 - CFD: 14/10/2011 - 08:53:16 - [0,002] ----D C:\ProgramData\Intel
O43 - CFD: 15/07/2012 - 09:03:21 - [8,142] ----D C:\ProgramData\Malwarebytes
O43 - CFD: 10/06/2012 - 18:59:41 - [2009,573] -S--D C:\ProgramData\Microsoft
O43 - CFD: 03/05/2012 - 12:46:56 - [0,007] ----D C:\ProgramData\Mozilla
O43 - CFD: 27/03/2012 - 15:32:36 - [0,000] ----D C:\ProgramData\Nuance
O43 - CFD: 14/10/2011 - 08:55:37 - [9,520] ----D C:\ProgramData\NVIDIA
O43 - CFD: 14/10/2011 - 08:53:41 - [0,892] ----D C:\ProgramData\NVIDIA Corporation
O43 - CFD: 13/04/2011 - 04:48:44 - [27,601] ----D C:\ProgramData\OberonGameConsole
O43 - CFD: 14/10/2011 - 08:58:41 - [0,002] ----D C:\ProgramData\P4G
O43 - CFD: 12/05/2012 - 07:27:12 - [0,001] ----D C:\ProgramData\Partner
O43 - CFD: 14/10/2011 - 08:58:23 - [3,877] ----D C:\ProgramData\Ralink Driver
O43 - CFD: 18/02/2012 - 17:21:29 - [0,000] ----D C:\ProgramData\RoboForm
O43 - CFD: 13/04/2011 - 04:33:05 - [1,216] ----D C:\ProgramData\ScanSoft
O43 - CFD: 07/07/2012 - 10:34:03 - [29,110] ----D C:\ProgramData\Skype
O43 - CFD: 14/10/2011 - 08:57:35 - [0,009] ----D C:\ProgramData\SonicFocus
O43 - CFD: 14/07/2009 - 07:08:56 - [0] --H-D C:\ProgramData\Start Menu
O43 - CFD: 14/10/2011 - 09:03:07 - [0,188] ----D C:\ProgramData\Temp
O43 - CFD: 14/07/2009 - 07:08:56 - [0] --H-D C:\ProgramData\Templates
O43 - CFD: 24/03/2012 - 08:42:36 - [6,112] ----D C:\ProgramData\Trend Micro
O43 - CFD: 15/04/2012 - 09:49:30 - [0,003] ----D C:\ProgramData\UDL
O43 - CFD: 08/03/2012 - 08:55:32 - [0] ----D C:\ProgramData\VirtualizedApplications
O43 - CFD: 18/02/2012 - 12:08:21 - [34,998] ----D C:\Users\Laikai\AppData\Roaming\Adobe
O43 - CFD: 09/04/2012 - 06:47:03 - [0,022] ----D C:\Users\Laikai\AppData\Roaming\Apple Computer
O43 - CFD: 18/02/2012 - 17:12:47 - [0,000] ----D C:\Users\Laikai\AppData\Roaming\ASUS WebStorage
O43 - CFD: 19/06/2012 - 14:27:10 - [3,491] ----D C:\Users\Laikai\AppData\Roaming\BitComet
O43 - CFD: 08/04/2012 - 20:26:52 - [0,474] ----D C:\Users\Laikai\AppData\Roaming\CometPlayer
O43 - CFD: 02/03/2012 - 20:22:06 - [0,002] ----D C:\Users\Laikai\AppData\Roaming\CyberLink
O43 - CFD: 15/04/2012 - 10:06:30 - [0,002] ----D C:\Users\Laikai\AppData\Roaming\Epson
O43 - CFD: 24/03/2012 - 08:54:25 - [0] ----D C:\Users\Laikai\AppData\Roaming\ESET
O43 - CFD: 27/03/2012 - 15:32:37 - [0,000] ----D C:\Users\Laikai\AppData\Roaming\FLEXnet
O43 - CFD: 07/06/2012 - 21:54:15 - [0] ----D C:\Users\Laikai\AppData\Roaming\GetRightToGo
O43 - CFD: 28/05/2012 - 21:26:58 - [0] ----D C:\Users\Laikai\AppData\Roaming\Google
O43 - CFD: 29/05/2012 - 11:59:56 - [0,000] ----D C:\Users\Laikai\AppData\Roaming\Identities
O43 - CFD: 15/04/2012 - 09:16:36 - [0] ----D C:\Users\Laikai\AppData\Roaming\InstallShield
O43 - CFD: 18/02/2012 - 12:08:21 - [0,009] ----D C:\Users\Laikai\AppData\Roaming\Macromedia
O43 - CFD: 15/07/2012 - 09:03:32 - [1,041] ----D C:\Users\Laikai\AppData\Roaming\Malwarebytes
O43 - CFD: 14/07/2009 - 09:44:38 - [0] ----D C:\Users\Laikai\AppData\Roaming\Media Center Programs
O43 - CFD: 15/07/2012 - 10:12:48 - [10,345] -S--D C:\Users\Laikai\AppData\Roaming\Microsoft
O43 - CFD: 18/02/2012 - 14:42:50 - [23,939] ----D C:\Users\Laikai\AppData\Roaming\Mozilla
O43 - CFD: 27/03/2012 - 15:32:36 - [0,000] ----D C:\Users\Laikai\AppData\Roaming\Nuance
O43 - CFD: 15/07/2012 - 00:43:29 - [3,334] ----D C:\Users\Laikai\AppData\Roaming\Skype
O43 - CFD: 15/07/2012 - 00:52:01 - [1,269] ----D C:\Users\Laikai\AppData\Roaming\SoftGrid Client
O43 - CFD: 15/06/2012 - 21:30:54 - [0,541] ----D C:\Users\Laikai\AppData\Roaming\tigerplayer
O43 - CFD: 06/03/2012 - 11:59:30 - [0] ----D C:\Users\Laikai\AppData\Roaming\TP
O43 - CFD: 16/06/2012 - 22:35:11 - [0,077] ----D C:\Users\Laikai\AppData\Roaming\vlc
O43 - CFD: 07/06/2012 - 21:45:17 - [0,039] ----D C:\Users\Laikai\AppData\Roaming\WebPlayerBdd
O43 - CFD: 18/02/2012 - 17:18:25 - [0,000] ----D C:\Users\Laikai\AppData\Roaming\WinRAR
O43 - CFD: 05/03/2012 - 10:29:47 - [0,076] ----D C:\Users\Laikai\AppData\Roaming\Zeon
O43 - CFD: 08/04/2012 - 20:17:48 - [0] ----D C:\Users\Laikai\AppData\Local\Apple
O43 - CFD: 18/02/2012 - 12:05:32 - [0] ----D C:\Users\Laikai\AppData\Local\Application Data
O43 - CFD: 13/03/2012 - 19:07:35 - [1,310] ----D C:\Users\Laikai\AppData\Local\ASUS
O43 - CFD: 04/06/2012 - 18:41:47 - [0] ----D C:\Users\Laikai\AppData\Local\ElevatedDiagnostics
O43 - CFD: 24/03/2012 - 08:54:25 - [2,080] ----D C:\Users\Laikai\AppData\Local\ESET
O43 - CFD: 28/05/2012 - 21:26:58 - [0] ----D C:\Users\Laikai\AppData\Local\Google
O43 - CFD: 18/02/2012 - 12:05:32 - [0] ----D C:\Users\Laikai\AppData\Local\Historique
O43 - CFD: 12/06/2012 - 15:43:18 - [0] ----D C:\Users\Laikai\AppData\Local\Macromedia
O43 - CFD: 12/06/2012 - 15:43:18 - [317,268] ----D C:\Users\Laikai\AppData\Local\Microsoft
O43 - CFD: 18/02/2012 - 14:42:42 - [56,282] ----D C:\Users\Laikai\AppData\Local\Mozilla
O43 - CFD: 18/02/2012 - 17:27:50 - [0,039] ----D C:\Users\Laikai\AppData\Local\Power2Go
O43 - CFD: 06/03/2012 - 11:59:25 - [0,582] ----D C:\Users\Laikai\AppData\Local\SoftGrid Client
O43 - CFD: 15/07/2012 - 10:12:48 - [132,568] ----D C:\Users\Laikai\AppData\Local\Temp
O43 - CFD: 18/02/2012 - 12:05:32 - [0] ----D C:\Users\Laikai\AppData\Local\Temporary Internet Files
O43 - CFD: 15/04/2012 - 10:11:46 - [0,114] ----D C:\Users\Laikai\AppData\Local\VirtualStore
O43 - CFD: 14/07/2012 - 12:26:52 - [0,055] ----D C:\Users\Laikai\AppData\Local\Windows Live
O43 - CFD: 14/07/2009 - 06:54:32 - [0,014] R---D C:\Users\Laikai\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
O43 - CFD: 12/07/2012 - 05:15:17 - [0,000] R---D C:\Users\Laikai\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
O43 - CFD: 14/10/2011 - 09:03:38 - [0,013] ----D C:\Users\Laikai\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink Blu-ray Disc Suite
O43 - CFD: 14/07/2009 - 06:49:38 - [0,001] R---D C:\Users\Laikai\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
O43 - CFD: 15/07/2012 - 10:07:43 - [0] R---D C:\Users\Laikai\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
O43 - CFD: 18/02/2012 - 17:18:03 - [0,003] ----D C:\Users\Laikai\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
O43 - CFD: 15/04/2012 - 09:47:16 - [118,664] ----D C:\Program Files (x86)\ABBYY FineReader 6.0 Sprint
O43 - CFD: 29/06/2012 - 19:08:44 - [0] ----D C:\Program Files (x86)\allsearch
O43 - CFD: 14/10/2011 - 08:58:11 - [2,896] ----D C:\Program Files (x86)\AmIcoSingLun
O43 - CFD: 08/04/2012 - 20:17:47 - [2,316] ----D C:\Program Files (x86)\Apple Software Update
O43 - CFD: 18/02/2012 - 12:22:47 - [517,058] ----D C:\Program Files (x86)\ASUS
O43 - CFD: 18/02/2012 - 21:49:30 - [24,712] ----D C:\Program Files (x86)\BitComet
O43 - CFD: 14/10/2011 - 08:58:23 - [3,432] ----D C:\Program Files (x86)\Cisco
O43 - CFD: 07/07/2012 - 10:33:44 - [171,877] ----D C:\Program Files (x86)\Common Files
O43 - CFD: 14/10/2011 - 09:03:18 - [476,601] ----D C:\Program Files (x86)\CyberLink
O43 - CFD: 10/06/2012 - 11:21:56 - [43,736] ----D C:\Program Files (x86)\eBay
O43 - CFD: 15/04/2012 - 09:49:56 - [15,447] ----D C:\Program Files (x86)\epson
O43 - CFD: 15/04/2012 - 09:48:56 - [114,292] ----D C:\Program Files (x86)\Epson Software
O43 - CFD: 15/04/2012 - 09:27:29 - [14,058] ----D C:\Program Files (x86)\EpsonNet
O43 - CFD: 28/05/2012 - 21:29:09 - [289,649] ----D C:\Program Files (x86)\Google
O43 - CFD: 15/04/2012 - 09:54:20 - [58,166] --H-D C:\Program Files (x86)\InstallShield Installation Information
O43 - CFD: 14/10/2011 - 08:51:52 - [14,997] ----D C:\Program Files (x86)\Intel
O43 - CFD: 12/07/2012 - 05:13:11 - [8,175] ----D C:\Program Files (x86)\Internet Explorer
O43 - CFD: 07/06/2012 - 21:55:12 - [57,095] ----D C:\Program Files (x86)\K-Lite Codec Pack
O43 - CFD: 15/07/2012 - 09:03:22 - [11,720] ----D C:\Program Files (x86)\Malwarebytes' Anti-Malware
O43 - CFD: 13/04/2011 - 04:47:20 - [17,977] ----D C:\Program Files (x86)\Microsoft
O43 - CFD: 06/03/2012 - 22:32:43 - [12,399] ----D C:\Program Files (x86)\Microsoft Application Virtualization Client
O43 - CFD: 06/03/2012 - 11:58:48 - [6,425] ----D C:\Program Files (x86)\Microsoft Office
O43 - CFD: 12/05/2012 - 22:16:41 - [40,838] ----D C:\Program Files (x86)\Microsoft Silverlight
O43 - CFD: 13/04/2011 - 04:42:56 - [1,745] ----D C:\Program Files (x86)\Microsoft SQL Server Compact Edition
O43 - CFD: 21/02/2012 - 22:20:00 - [0,015] ----D C:\Program Files (x86)\Microsoft.NET
O43 - CFD: 17/06/2012 - 08:13:51 - [44,259] ----D C:\Program Files (x86)\Mozilla Firefox
O43 - CFD: 18/06/2012 - 15:01:49 - [0,195] ----D C:\Program Files (x86)\Mozilla Maintenance Service
O43 - CFD: 14/06/2012 - 18:29:14 - [50,769] ----D C:\Program Files (x86)\MpcStar
O43 - CFD: 14/07/2009 - 07:32:38 - [0,025] ----D C:\Program Files (x86)\MSBuild
O43 - CFD: 13/04/2011 - 04:33:04 - [42,963] ----D C:\Program Files (x86)\Nuance
O43 - CFD: 14/10/2011 - 08:54:28 - [6,580] ----D C:\Program Files (x86)\NVIDIA Corporation
O43 - CFD: 09/06/2012 - 17:35:01 - [72,431] ----D C:\Program Files (x86)\QuickTime
O43 - CFD: 14/10/2011 - 08:58:21 - [11,877] ----D C:\Program Files (x86)\Ralink
O43 - CFD: 14/10/2011 - 08:57:18 - [12,690] ----D C:\Program Files (x86)\Realtek
O43 - CFD: 14/07/2009 - 07:32:38 - [37,349] ----D C:\Program Files (x86)\Reference Assemblies
O43 - CFD: 18/02/2012 - 17:20:45 - [17,352] ----D C:\Program Files (x86)\Siber Systems
O43 - CFD: 07/07/2012 - 10:34:03 - [34,215] R---D C:\Program Files (x86)\Skype
O43 - CFD: 26/05/2012 - 17:20:13 - [0,300] ----D C:\Program Files (x86)\StartNow Toolbar
O43 - CFD: 13/04/2011 - 04:49:28 - [161,465] ----D C:\Program Files (x86)\syncables
O43 - CFD: 14/10/2011 - 08:57:48 - [0] --H-D C:\Program Files (x86)\Temp
O43 - CFD: 14/07/2009 - 06:57:06 - [0] --H-D C:\Program Files (x86)\Uninstall Information
O43 - CFD: 07/06/2012 - 21:58:12 - [88,797] ----D C:\Program Files (x86)\VideoLAN
O43 - CFD: 28/05/2012 - 21:36:58 - [90,254] ----D C:\Program Files (x86)\WebSite X5 v8 - Evolution
O43 - CFD: 28/05/2012 - 21:27:12 - [0,002] ----D C:\Program Files (x86)\WebSite X5 v9 - Evolution
O43 - CFD: 23/02/2012 - 19:51:22 - [0,500] ----D C:\Program Files (x86)\Windows Defender
O43 - CFD: 20/06/2012 - 15:23:03 - [329,401] ----D C:\Program Files (x86)\Windows Live
O43 - CFD: 23/02/2012 - 19:51:22 - [5,895] ----D C:\Program Files (x86)\Windows Mail
O43 - CFD: 23/02/2012 - 19:51:22 - [4,791] ----D C:\Program Files (x86)\Windows Media Player
O43 - CFD: 14/07/2009 - 07:32:38 - [11,632] ----D C:\Program Files (x86)\Windows NT
O43 - CFD: 23/02/2012 - 19:51:22 - [4,213] ----D C:\Program Files (x86)\Windows Photo Viewer
O43 - CFD: 18/02/2011 - 22:09:10 - [0,181] ----D C:\Program Files (x86)\Windows Portable Devices
O43 - CFD: 23/02/2012 - 19:52:00 - [5,717] ----D C:\Program Files (x86)\Windows Sidebar
O43 - CFD: 18/02/2012 - 17:18:03 - [4,008] ----D C:\Program Files (x86)\WinRAR
O43 - CFD: 15/07/2012 - 10:27:11 - [12,845] ----D C:\Program Files (x86)\ZHPDiag
O43 - CFD: 08/04/2012 - 20:17:52 - [60,279] ----D C:\Program Files (x86)\Common Files\Apple
O43 - CFD: 06/03/2012 - 11:58:48 - [0,095] ----D C:\Program Files (x86)\Common Files\DESIGNER
O43 - CFD: 30/04/2012 - 10:37:21 - [4,115] ----D C:\Program Files (x86)\Common Files\EPSON
O43 - CFD: 15/04/2012 - 09:48:16 - [4,893] ----D C:\Program Files (x86)\Common Files\InstallShield
O43 - CFD: 14/10/2011 - 08:51:53 - [13,612] ----D C:\Program Files (x86)\Common Files\Intel
O43 - CFD: 20/06/2012 - 15:22:33 - [37,365] ----D C:\Program Files (x86)\Common Files\microsoft shared
O43 - CFD: 13/04/2011 - 04:48:00 - [0,338] ----D C:\Program Files (x86)\Common Files\Oberon Media
O43 - CFD: 14/10/2011 - 08:50:15 - [0,154] ----D C:\Program Files (x86)\Common Files\postureAgent
O43 - CFD: 14/07/2009 - 05:20:08 - [0,003] ----D C:\Program Files (x86)\Common Files\Services
O43 - CFD: 07/07/2012 - 10:33:44 - [2,056] ----D C:\Program Files (x86)\Common Files\Skype
O43 - CFD: 14/07/2009 - 05:20:08 - [39,200] ----D C:\Program Files (x86)\Common Files\SpeechEngines
O43 - CFD: 23/02/2012 - 19:51:58 - [9,767] ----D C:\Program Files (x86)\Common Files\System
O43 - CFD: 13/04/2011 - 04:33:36 - [0] ----D C:\Program Files (x86)\Common Files\Windows Live
~ Scan Program Folder in 00mn 01s



---\\ Derniers fichiers modifiés ou crées sous Windows et System32 (O44)
O44 - LFC:[MD5.4BD90AAA3DD2C53A881831A8601086FE] - 15/07/2012 - 09:05:13 ---A- . (...) -- C:\Windows\WindowsUpdate.log [1361615]
O44 - LFC:[MD5.889299E2BB859F715B0524787EC4F730] - 15/07/2012 - 08:51:33 ---A- . (...) -- C:\Windows\setupact.log [65955]
O44 - LFC:[MD5.5009146BEA835444D7132A88559CA627] - 15/07/2012 - 08:51:32 -S-A- . (...) -- C:\Windows\bootstat.dat [67584]
O44 - LFC:[MD5.F04FA43C113E8C4DA980E2BCB09FB08B] - 15/07/2012 - 08:51:25 ---A- . (...) -- C:\Windows\PFRO.log [400028]
O44 - LFC:[MD5.031EF3DFDF8DB5A2A3820CCA0CFEB28E] - 12/07/2012 - 04:14:33 ---A- . (...) -- C:\Windows\SysNative\FNTCACHE.DAT [275208]
O44 - LFC:[MD5.8505932C98FB1E009EBA1C65B0A496ED] - 09/07/2012 - 17:37:15 ---A- . (...) -- C:\Windows\SysNative\PerfStringBackup.INI [1582208]
O44 - LFC:[MD5.7F80823395AE326A487316CFC811160D] - 09/07/2012 - 17:37:15 ---A- . (...) -- C:\Windows\SysNative\perfc009.dat [110560]
O44 - LFC:[MD5.AC887BD9309FBCD69C7776E62C6EDB85] - 09/07/2012 - 17:37:15 ---A- . (...) -- C:\Windows\SysNative\perfc00C.dat [134926]
O44 - LFC:[MD5.E9FFC17D21E9B9434693A655A2C8E3E8] - 09/07/2012 - 17:37:15 ---A- . (...) -- C:\Windows\SysNative\perfh009.dat [628098]
O44 - LFC:[MD5.8932214CB816A11EDC57B35CCB010D51] - 09/07/2012 - 17:37:15 ---A- . (...) -- C:\Windows\SysNative\perfh00C.dat [716570]
O44 - LFC:[MD5.8505932C98FB1E009EBA1C65B0A496ED] - 09/07/2012 - 17:37:15 ---A- . (...) -- C:\Windows\System32\PerfStringBackup.INI [1582208]
O44 - LFC:[MD5.7632B8E20053430E2BCF966CD5008D0C] - 08/07/2012 - 06:08:36 . (...) -- C:\Windows\System32\AutoRunFilter.ini []
O44 - LFC:[MD5.7632B8E20053430E2BCF966CD5008D0C] - 08/07/2012 - 06:08:36 ---A- . (...) -- C:\Windows\SysNative\AutoRunFilter.ini [2132]
O44 - LFC:[MD5.DDDDF09ECDE613B473CA8B974E7A8740] - 08/07/2012 - 06:08:36 ---A- . (...) -- C:\Windows\SysNative\ServiceFilter.ini [1334]
O44 - LFC:[MD5.C67A42F4CEA5E541B8F7BEDA0A1C27F5] - 20/06/2012 - 14:22:00 ---A- . (...) -- C:\Windows\DirectX.log [580]
O44 - LFC:[MD5.85D6E8F735865B502D65D1D91A79E3F3] - 23/02/2010 - 09:16:17 . (...) -- C:\Windows\System32\browserchoice.exe []]
~ Scan Files in 00mn 03s



---\\ Contrôle du Safe Boot (CSB) (O49) (None)

---\\ MountPoints2 Shell Key (O51) (None)

---\\ ShareTools MSconfig StartupReg (O53) (None)

---\\ Liste des Drivers Système (O58)
O58 - SDL:[MD5.2F6B34B83843F0C5118B63AC634F5BF4] - 14/07/2009 - 02:52:21 ---A- . (.Adaptec, Inc. - Adaptec Windows SAS/SATA Storport Driver.) -- C:\Windows\System32\Drivers\adp94xx.sys [491088]
~ Scan Drivers in 00mn 00s



---\\ File Associations Shell Spawning (O67)
O67 - Shell Spawning: <.html> <FirefoxHTML>[HKCU\..\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
O67 - Shell Spawning: <.html> <FirefoxHTML>[HKCR\..\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
~ Scan Keys in 00mn 00s



---\\ Start Menu Internet (O68) (None)

---\\ Search Browser Infection (O69)
O69 - SBI: SearchScopes [HKCU] {0388404D-6072-4CEB-B521-8F090FEAEE57} [DefaultScope] - (Yahoo!) - http://klit.startnow.com
~ Scan Keys in 00mn 00s



---\\ Recherche des services démarrés par Svchost (O83) (None)

---\\ Recherche particuliere à la racine de certains dossiers (O84)
[MD5.90E1D86D979B92738A47D7072CB22DA8] [SPRF][07/07/2010] (...) -- C:\ProgramData\FullRemove.exe [131472]
[MD5.885E9EB42889CA547F4E3515DCDE5D3D] [SPRF][14/05/2006] (...) -- C:\Users\Laikai\AppData\Local\Temp\7za.exe [476672]
[MD5.710626F0C8B94C9CF89458409E3EE12E] [SPRF][07/06/2012] (.Conduit - Pas de description.) -- C:\Users\Laikai\AppData\Local\Temp\conduitinstaller.exe [211792]
[MD5.2CE6EEF84B7F306858C23000F017E2A0] [SPRF][19/03/2012] (...) -- C:\Users\Laikai\AppData\Local\Temp\Extract.bat [80]
[MD5.54F530FC8928E532C437F2AB931306EF] [SPRF][25/05/2012] (...) -- C:\Users\Laikai\AppData\Local\Temp\gghelp.exe [1479504]
[MD5.514B4609AD18D73CC06AF6F00E08E9C8] [SPRF][10/05/2012] (.Adobe Systems, Inc. - Adobe Flash Player 10.1 r52.) -- C:\Users\Laikai\AppData\Local\Temp\push.exe [5203150]
[MD5.4B10EF0D961B9C4B968C96E90294F20D] [SPRF][07/06/2012] (...) -- C:\Users\Laikai\AppData\Local\Temp\Setup.exe [817672]
[MD5.FBAB280D0CAC5E21C72F0A1A7B5B9608] [SPRF][22/06/2007] (.Macrovision Corporation - Setup.exe.) -- C:\Users\Laikai\AppData\Local\Temp\_is33BC.exe [455600]
[MD5.A205551E7BA8580D2C0FF896A4D79FA9] [SPRF][31/08/2007] (.Macrovision Corporation - Setup.exe.) -- C:\Users\Laikai\AppData\Local\Temp\_is58AA.exe [460248]
[MD5.FBAB280D0CAC5E21C72F0A1A7B5B9608] [SPRF][25/05/2006] (.Macrovision Corporation - Setup.exe.) -- C:\Users\Laikai\AppData\Local\Temp\_is9416.exe [455600]
[MD5.FBAB280D0CAC5E21C72F0A1A7B5B9608] [SPRF][25/05/2006] (.Macrovision Corporation - Setup.exe.) -- C:\Users\Laikai\AppData\Local\Temp\_isA987.exe [455600]
[MD5.A38934F1B14F3FA7A449E0F42AA7D67D] [SPRF][05/03/2012] (...) -- C:\Users\Laikai\AppData\Local\Temp\__PDFCORE_FMP.dat [70588]
[MD5.0C78701C6F42345DFF2B2B6C3C3D01EF] [SPRF][25/07/2002] (.InstallShield Software Corporation - InstallShield Update Service Web Agent.) -- C:\Windows\Downloaded Program Files\isusweb.dll [172032]
~ Scan Files in 00mn 00s



---\\ Scan Additionnel (O88)
Database Version : 9170 - (25/06/2012)
Clés trouvées (Keys found) : 1
Valeurs trouvées (Values found) : 0
Dossiers trouvés (Folders found) : 2
Fichiers trouvés (Files found) : 0

[HKCU\Software\Zugo] =>Adware.Zugo
C:\Program Files (x86)\StartNow Toolbar =>Adware.Zugo
~ Scan Additionnel in 00mn 04s



End of the scan (530 lines in 00mn 19s)(0)



1 réponse

anthony5151 Messages postés 10573 Date d'inscription vendredi 27 juin 2008 Statut Contributeur sécurité Dernière intervention 2 mars 2015 790
16 juil. 2012 à 13:36
Bonjour,


Bienvenue sur CCM !
Nous allons essayer de régler ton problème ensemble. D'abord, quelques rappels :

- N'ouvre pas d'autres sujets pour le même problème (que ce soit sur ce forum ou sur un autre)
- N'hésite pas à poser des questions en cas de besoin ;)
- Sois patient(e) quand tu postes un message, je ne réponds pas instantanément : je suis bénévole et je ne suis pas en permanence devant mon ordinateur. Mais rassure toi, je ne laisse jamais tomber personne ;)
- La désinfection (si nécessaire) va se dérouler en plusieurs étapes. Même si les symptômes de l'infection disparaissent, la désinfection ne sera terminée que quand je te le confirmerai --> Merci de revenir jusqu'au bout, sinon ce qu'on a fait n'aura servi à rien.


Le rapport de ZHPDiag est incomplet. Utilise le comme ceci pour régler le problème :
- Relance le par un clic-droit --> Exécuter en temps qu'administrateur.
- Clique sur l'icône "UAC" en haut à droite de ZHPDiag.
- Clique sur l'icône représentant une loupe (« Lancer le diagnostic »)
- Enregistre le rapport sur ton Bureau à l'aide de l'icône représentant une disquette
- Ne poste PAS le rapport ici directement, il est trop long. Rends toi sur ce site, clique sur "Parcourir", sélectionne le rapport de ZHPDiag et clique sur Envoyer le fichier. Patiente pendant l'envoi du fichier, puis copie/colle le lien fourni dans ta prochaine réponse sur le forum.

0