Votre question

[résolu] Trojan récalcitrant

Tags :
  • Sécurité
Dernière réponse : dans Sécurité et virus
20 Juin 2009 12:36:12

Bonjour,

Je rencontre des problèmes depuis quelques temps avec trojan dropper qui sont apparus au travers de mns, en envoyant des liens à tous mes contacts, j'ai essayé msn fix qui ne détecte rien.
En revanche a-squared détecte plusieurs trojan qui restent malgré l'élimination.

Pourriez-vous m'aider?

Merci

Autres pages sur : resolu trojan recalcitrant

a c 327 8 Sécurité
20 Juin 2009 15:31:42

Bonjour,

  • Télécharge Random's System Information Tool (RSIT) (par random/random) sur ton Bureau.
  • Double-clique sur RSIT.exe afin de lancer le programme.
    (Sous Vista, il faut cliquer droit sur RSIT.exe et choisir Exécuter en tant qu'administrateur)
  • Clique sur Continue à l'écran Disclaimer.
  • Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.
  • Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront. Poste le contenu de log.txt (c'est celui qui apparaît à l'écran) ainsi que de info.txt (que tu verras dans la barre des tâches).

    Note : les rapports sont sauvegardés dans le dossier C:\rsit.
    20 Juin 2009 15:36:07

    Bonjour,
    voici les rapports:

    Logfile of random's system information tool 1.06 (written by random/random)
    Run by Celine at 2009-06-20 15:34:13
    Microsoft Windows XP Édition familiale Service Pack 3
    System drive C: has 281 GB (92%) free of 305 GB
    Total RAM: 2046 MB (38% free)

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 15:34:21, on 20/06/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Avira\AntiVir Desktop\sched.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\RTHDCPL.EXE
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\Program Files\BroadJump\Client Foundation\CFD.exe
    C:\Program Files\Winamp\winampa.exe
    C:\Program Files\Java\jre6\bin\jusched.exe
    C:\WINDOWS\UMStor\Res.EXE
    C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
    C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Picasa2\PicasaMediaDetector.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\Program Files\Microsoft Office\Office\OSA.EXE
    C:\Program Files\a-squared Free\a2service.exe
    C:\Program Files\Avira\AntiVir Desktop\avguard.exe
    C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
    C:\Program Files\Windows Live\Family Safety\fsssvc.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
    C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\WINDOWS\system32\wbem\wmiapsrv.exe
    C:\Program Files\a-squared Free\a2free.exe
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    C:\Program Files\Windows Live\Contacts\wlcomm.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
    C:\Program Files\Microsoft\Office Live\OfficeLiveSignIn.exe
    C:\SphinxV5\Sphinx.exe
    C:\Program Files\Microsoft Office\OFFICE11\POWERPNT.EXE
    C:\Program Files\Tracker Software\PDF-XChange Viewer\pdf-viewer\PDFXCview.exe
    C:\WINDOWS\system32\NOTEPAD.EXE
    C:\Documents and Settings\Celine\Bureau\RSIT.exe
    C:\Program Files\trend micro\Celine.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.myheritage.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.myheritage.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.live.com/sphome.aspx
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer avec Club-Internet
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;*.local
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    R3 - URLSearchHook: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\pdfforge Toolbar\SearchSettings.dll
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
    O2 - BHO: PHPNukeFR Toolbar - {258fe8b8-a13c-4b91-9a0c-c2d3cab8b990} - C:\Program Files\PHPNukeFR\tbPHP1.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
    O2 - BHO: pdfforge Toolbar - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\WidgiToolbarIE.dll
    O2 - BHO: PDF-XChange Viewer IE-Plugin - {C5D07EB6-BBCE-4DAE-ACBB-D13A8D28CB1F} - C:\Program Files\Tracker Software\PDF-XChange Viewer\pdf-viewer\PDFXCviewIEPlugin.dll
    O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
    O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll
    O2 - BHO: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\pdfforge Toolbar\SearchSettings.dll
    O3 - Toolbar: PHPNukeFR Toolbar - {258fe8b8-a13c-4b91-9a0c-c2d3cab8b990} - C:\Program Files\PHPNukeFR\tbPHP1.dll
    O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
    O3 - Toolbar: pdfforge Toolbar - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\WidgiToolbarIE.dll
    O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
    O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
    O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
    O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
    O4 - HKLM\..\Run: [USB Storage Toolbox] C:\WINDOWS\UMStor\Res.EXE
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [Family Tree Builder Update] C:\Program Files\MyHeritage\Bin\FTBCheckUpdates.exe
    O4 - HKLM\..\Run: [SearchSettings] C:\Program Files\pdfforge Toolbar\SearchSettings.exe
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [RegistryBooster 2 d’Uniblue ] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - HKCU\..\Run: [Uniblue RegistryBooster 2009] C:\Program Files\Uniblue\RegistryBooster\RegistryBooster.exe /S
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O4 - Startup: Démarrage d'Office.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
    O4 - Startup: Ekiga.lnk = C:\Program Files\Ekiga\ekiga.exe
    O4 - Startup: ex-fumeurs.lnk = C:\Program Files\ex-fumeurs\ex-fumeurs.exe
    O4 - Startup: Microsoft Recherche accélérée.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
    O4 - Startup: OpenOffice.org 3.0.lnk.disabled
    O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
    O4 - Global Startup: Docteur Club Internet.lnk.disabled
    O4 - Global Startup: WinZip Quick Pick.lnk.disabled
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O8 - Extra context menu item: Add to AMV Convert Tool... - C:\Program Files\MP3 Player Utilities 4.00\AMVConverter\grab.html
    O8 - Extra context menu item: Add to AMV Converter... - C:\Program Files\MP3 Player Utilities 4.04\AMVConverter\grab.html
    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Program Files\MP3 Player Utilities 4.00\MediaManager\grab.html
    O8 - Extra context menu item: Tout télécharger avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
    O8 - Extra context menu item: Télécharger avec Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
    O8 - Extra context menu item: Télécharger la sélection avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
    O8 - Extra context menu item: Télécharger la vidéo avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlfvideo.htm
    O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
    O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Contro...
    O17 - HKLM\System\CCS\Services\Tcpip\..\{24AB0520-3295-4062-90D6-60FBF4F747A7}: NameServer = 86.64.145.140,84.103.237.140
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
    O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
    O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
    O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
    O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
    O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
    O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
    O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

    --
    End of file - 13282 bytes

    ======Scheduled tasks folder======

    C:\WINDOWS\tasks\A3310BBC91B2BEDC.job
    C:\WINDOWS\tasks\AppleSoftwareUpdate.job

    ======Registry dump======

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
    Adobe PDF Link Helper - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{22BF413B-C6D2-4d91-82A9-A0F997BA588C}]
    Skype add-on (mastermind) - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2009-06-02 1082880]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{258fe8b8-a13c-4b91-9a0c-c2d3cab8b990}]
    PHPNukeFR Toolbar - C:\Program Files\PHPNukeFR\tbPHP1.dll [2009-06-10 2094616]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
    Spybot-S&D IE Protection - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll [2009-01-26 1879896]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
    Search Helper - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll [2009-05-19 137600]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
    Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll [2009-05-07 259696]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
    Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll [2009-05-07 668656]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B922D405-6D13-4A2B-AE89-08A030DA4402}]
    pdfforge Toolbar - C:\Program Files\pdfforge Toolbar\WidgiToolbarIE.dll [2009-01-30 650752]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C5D07EB6-BBCE-4DAE-ACBB-D13A8D28CB1F}]
    PDF-XChange Viewer IE-Plugin - C:\Program Files\Tracker Software\PDF-XChange Viewer\pdf-viewer\PDFXCviewIEPlugin.dll [2009-03-30 1092888]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C84D72FE-E17D-4195-BB24-76C02E2E7C4E}]
    Google Dictionary Compression sdch - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll [2009-05-07 470512]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CC59E0F9-7E43-44FA-9FAA-8377850BF205}]
    FDMIECookiesBHO Class - C:\Program Files\Free Download Manager\iefdm2.dll [2008-11-12 94208]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}]
    C:\Program Files\pdfforge Toolbar\SearchSettings.dll [2009-01-30 1114112]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    {258fe8b8-a13c-4b91-9a0c-c2d3cab8b990} - PHPNukeFR Toolbar - C:\Program Files\PHPNukeFR\tbPHP1.dll [2009-06-10 2094616]
    {21FA44EF-376D-4D53-9B0F-8A89D3229068} - &Windows Live Toolbar - C:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-02-06 1068904]
    {B922D405-6D13-4A2B-AE89-08A030DA4402} - pdfforge Toolbar - C:\Program Files\pdfforge Toolbar\WidgiToolbarIE.dll [2009-01-30 650752]
    {2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll [2009-05-07 259696]

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    "RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2007-05-10 16342528]
    "nwiz"=nwiz.exe /install []
    "NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2008-05-02 86016]
    "NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2008-05-02 13529088]
    "NeroFilterCheck"=C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe [2007-03-01 153136]
    "BJCFD"=C:\Program Files\BroadJump\Client Foundation\CFD.exe [2003-01-27 376912]
    "Alcmtr"=C:\WINDOWS\ALCMTR.EXE [2005-05-03 69632]
    "WinampAgent"=C:\Program Files\Winamp\winampa.exe [2007-10-10 36352]
    "SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-04-10 148888]
    "USB Storage Toolbox"=C:\WINDOWS\UMStor\Res.EXE [2005-09-14 65536]
    "Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-02-27 35696]
    "Family Tree Builder Update"=C:\Program Files\MyHeritage\Bin\FTBCheckUpdates.exe [2009-01-14 113680]
    "SearchSettings"=C:\Program Files\pdfforge Toolbar\SearchSettings.exe [2009-01-30 992256]
    "TkBellExe"=C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe [2009-02-06 185872]
    "avgnt"=C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [2009-03-02 209153]
    "QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2009-05-26 413696]
    "iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2009-05-30 292136]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
    "Picasa Media Detector"=C:\Program Files\Picasa2\PicasaMediaDetector.exe [2008-08-21 443968]
    "swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2008-12-15 68856]
    "RegistryBooster 2 d’Uniblue "=C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S []
    "SpybotSD TeaTimer"=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2009-01-26 2144088]
    "Uniblue RegistryBooster 2009"=C:\Program Files\Uniblue\RegistryBooster\RegistryBooster.exe /S []

    C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage
    Cisco Systems VPN Client.lnk - C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
    Docteur Club Internet.lnk.disabled - C:\Program Files\Club-Internet\Dr Club Internet\bin\matcli.exe
    WinZip Quick Pick.lnk.disabled - C:\Program Files\WinZip\WZQKPICK.EXE

    C:\Documents and Settings\Celine\Menu Démarrer\Programmes\Démarrage
    Démarrage d'Office.lnk - C:\Program Files\Microsoft Office\Office\OSA.EXE
    Ekiga.lnk - C:\Program Files\Ekiga\ekiga.exe
    ex-fumeurs.lnk - C:\Program Files\ex-fumeurs\ex-fumeurs.exe
    Microsoft Recherche accélérée.lnk - C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
    OpenOffice.org 3.0.lnk.disabled - C:\Program Files\OpenOffice.org 3\program\quickstart.exe

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
    WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\aawservice]

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
    "dontdisplaylastusername"=0
    "legalnoticecaption"=
    "legalnoticetext"=
    "shutdownwithoutlogon"=1
    "undockwithoutlogon"=1

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
    "NoDriveTypeAutoRun"=145
    "NoDriveAutoRun"=4294967295

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
    "NoDriveTypeAutoRun"=
    "HonorAutoRunSetting"=

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
    "%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
    "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
    "D:\NeroExpress\Installation\Setupx.exe"="D:\NeroExpress\Installation\Setupx.exe:*:Enabled:Nero ProductSetup"
    "C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
    "C:\Program Files\Messenger\msmsgs.exe"="C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger"
    "C:\Program Files\SecondLife\SLVoice.exe"="C:\Program Files\SecondLife\SLVoice.exe:*:D isabled:SLVoice"
    "C:\Program Files\BitDownload\BitDownload.exe"="C:\Program Files\BitDownload\BitDownload.exe:*:Enabled:BitDownload"
    "C:\Program Files\LimeWire\LimeWire.exe"="C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire"
    "C:\Program Files\Vuze\Azureus.exe"="C:\Program Files\Vuze\Azureus.exe:*:Enabled:Azureus"
    "C:\Program Files\eMule\emule.exe"="C:\Program Files\eMule\emule.exe:*:Enabled:eMule"
    "C:\Program Files\Free Download Manager\fdm.exe"="C:\Program Files\Free Download Manager\fdm.exe:*:Enabled:Free Download Manager"
    "DEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~ӟ"="DEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~ӟ:*:Enabled:Nod32 Service"
    "C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
    "C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe"="C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync"
    "C:\Program Files\SecondLife\SecondLife.exe"="C:\Program Files\SecondLife\SecondLife.exe:*:Enabled:Second Life"
    "C:\Program Files\Mozilla Firefox\firefox.exe"="C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox"
    "C:\Program Files\Ekiga\ekiga.exe"="C:\Program Files\Ekiga\ekiga.exe:*:D isabled:ekiga"
    "C:\Python23\pythonw.exe"="C:\Python23\pythonw.exe:*:Enabled:p ythonw"
    "C:\Documents and Settings\Celine\Local Settings\Temp\Rar$EX02.468\eMule0.49c\emule.exe"="C:\Documents and Settings\Celine\Local Settings\Temp\Rar$EX02.468\eMule0.49c\emule.exe:*:Enabled:eMule"
    "C:\Program Files\Fichiers communs\Ahead\Nero Web\SetupX.exe"="C:\Program Files\Fichiers communs\Ahead\Nero Web\SetupX.exe:*:Enabled:Nero ProductSetup"
    "C:\Documents and Settings\Celine\Local Settings\Temp\Nero Web\SetupXu.exe"="C:\Documents and Settings\Celine\Local Settings\Temp\Nero Web\SetupXu.exe:*:Enabled:Nero ProductSetup"
    "C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
    "C:\Program Files\iTunes\iTunes.exe"="C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes"
    "C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
    "%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
    "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
    "C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
    "C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
    "C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe"="C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync"

    ======List of files/folders created in the last 1 months======

    2009-06-18 09:52:27 ----A---- C:\WINDOWS\msnfix.txt
    2009-06-16 08:22:10 ----D---- C:\Documents and Settings\Celine\Application Data\vlc
    2009-06-16 08:21:52 ----D---- C:\Documents and Settings\Celine\Application Data\dvdcss
    2009-06-16 08:20:21 ----SHD---- C:\Config.Msi
    2009-06-16 08:14:46 ----A---- C:\Documents and Settings\All Users\Application Data\vlc-0.9.9-win32.exe
    2009-06-14 12:54:22 ----D---- C:\Program Files\Hotspot_Shield
    2009-06-14 08:45:30 ----D---- C:\Program Files\Fichiers communs\Skype
    2009-06-14 08:45:27 ----RD---- C:\Program Files\Skype
    2009-06-11 09:17:43 ----HDC---- C:\WINDOWS\$NtUninstallKB961501$
    2009-06-11 09:17:37 ----HDC---- C:\WINDOWS\$NtUninstallKB969897$
    2009-06-11 09:17:33 ----HDC---- C:\WINDOWS\$NtUninstallKB969898$
    2009-06-11 09:16:07 ----HDC---- C:\WINDOWS\$NtUninstallKB970238$
    2009-06-11 09:15:41 ----HDC---- C:\WINDOWS\$NtUninstallKB968537$
    2009-06-06 23:27:40 ----D---- C:\Documents and Settings\Celine\Application Data\Help
    2009-06-05 09:45:14 ----D---- C:\Program Files\iPod
    2009-06-05 09:45:12 ----D---- C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
    2009-06-05 09:43:33 ----D---- C:\Program Files\QuickTime
    2009-06-05 09:39:07 ----D---- C:\Program Files\Safari
    2009-05-22 08:28:26 ----D---- C:\Documents and Settings\Celine\Application Data\GetRightToGo

    ======List of files/folders modified in the last 1 months======

    2009-06-20 15:34:14 ----D---- C:\Program Files\trend micro
    2009-06-20 15:32:48 ----D---- C:\WINDOWS\Prefetch
    2009-06-20 14:26:06 ----AH---- C:\WINDOWS\system32\FFASTLOG.TXT
    2009-06-20 12:10:47 ----D---- C:\Program Files\Mozilla Firefox
    2009-06-20 10:53:59 ----D---- C:\Program Files\a-squared Free
    2009-06-20 10:51:13 ----D---- C:\WINDOWS\Temp
    2009-06-20 09:08:34 ----D---- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
    2009-06-20 09:08:21 ----D---- C:\Program Files\Spybot - Search & Destroy
    2009-06-20 08:31:19 ----D---- C:\WINDOWS\Debug
    2009-06-20 08:19:04 ----D---- C:\WINDOWS\system32\CatRoot2
    2009-06-20 00:14:27 ----A---- C:\WINDOWS\SchedLgU.Txt
    2009-06-20 00:11:03 ----D---- C:\Documents and Settings\Celine\Application Data\Skype
    2009-06-19 23:49:32 ----D---- C:\WINDOWS\system32
    2009-06-19 23:18:38 ----A---- C:\WINDOWS\NeroDigital.ini
    2009-06-19 22:24:34 ----RD---- C:\Program Files
    2009-06-19 22:24:34 ----D---- C:\Program Files\Navilog1
    2009-06-19 17:24:41 ----D---- C:\Documents and Settings\Celine\Application Data\skypePM
    2009-06-19 07:41:16 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
    2009-06-18 15:55:34 ----D---- C:\WINDOWS
    2009-06-18 09:51:33 ----D---- C:\unzipped
    2009-06-18 08:57:34 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
    2009-06-18 08:57:31 ----D---- C:\WINDOWS\system32\drivers
    2009-06-18 08:46:16 ----D---- C:\WINDOWS\Minidump
    2009-06-16 08:21:17 ----SHD---- C:\WINDOWS\Installer
    2009-06-16 08:20:49 ----DC---- C:\WINDOWS\system32\DRVSTORE
    2009-06-16 08:19:24 ----D---- C:\Python23
    2009-06-15 18:03:41 ----D---- C:\Program Files\eMule
    2009-06-15 10:53:43 ----SHD---- C:\System Volume Information
    2009-06-15 10:49:54 ----D---- C:\WINDOWS\repair
    2009-06-15 10:49:49 ----D---- C:\WINDOWS\Registration
    2009-06-14 12:54:15 ----HD---- C:\WINDOWS\inf
    2009-06-14 08:45:30 ----D---- C:\Program Files\Fichiers communs
    2009-06-14 08:45:30 ----D---- C:\Documents and Settings\All Users\Application Data\Skype
    2009-06-12 07:21:25 ----D---- C:\Program Files\Bonjour
    2009-06-12 07:20:59 ----D---- C:\Program Files\Winamp
    2009-06-11 09:18:14 ----A---- C:\WINDOWS\win.ini
    2009-06-11 09:17:45 ----RSHDC---- C:\WINDOWS\system32\dllcache
    2009-06-11 09:17:33 ----HD---- C:\WINDOWS\$hf_mig$
    2009-06-10 09:53:45 ----D---- C:\Program Files\PHPNukeFR
    2009-06-08 10:35:03 ----D---- C:\Program Files\WinZip
    2009-06-05 09:45:30 ----D---- C:\Program Files\iTunes
    2009-06-05 09:45:13 ----D---- C:\Program Files\Fichiers communs\Apple
    2009-06-05 09:37:46 ----D---- C:\Program Files\Windows Media Player
    2009-06-01 09:51:14 ----A---- C:\WINDOWS\system32\MRT.exe

    ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

    R1 AmdK8;Pilote de processeur AMD; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2006-06-19 43520]
    R1 avgio;avgio; \??\C:\Program Files\Avira\AntiVir Desktop\avgio.sys []
    R1 avipbb;avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [2009-03-30 96104]
    R1 ssmdrv;ssmdrv; C:\WINDOWS\system32\DRIVERS\ssmdrv.sys [2009-02-13 28376]
    R2 avgntflt;avgntflt; C:\WINDOWS\system32\DRIVERS\avgntflt.sys [2009-03-24 55640]
    R2 CVPNDRVA;Cisco Systems IPsec Driver; \??\C:\WINDOWS\system32\Drivers\CVPNDRVA.sys []
    R2 fssfltr;FssFltr; C:\WINDOWS\system32\DRIVERS\fssfltr_tdi.sys [2008-12-08 55136]
    R3 DNE;Deterministic Network Enhancer Miniport; C:\WINDOWS\system32\DRIVERS\dne2000.sys [2007-01-24 127376]
    R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys [2009-03-19 23400]
    R3 HDAudBus;Pilote de bus Microsoft UAA pour High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-14 144384]
    R3 hidusb;Pilote de classe HID Microsoft; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
    R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2007-05-10 4419584]
    R3 mouhid;Pilote HID de souris; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2008-04-14 12288]
    R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2008-05-02 6554496]
    R3 RTL8023xp;Realtek 10/100/1000 PCI NIC Family NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtnicxp.sys [2006-12-14 85120]
    R3 usbehci;Pilote miniport de contrôleur d'hôte amélioré Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-14 30208]
    R3 usbhub;Concentrateur USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-14 59520]
    R3 usbohci;Pilote miniport de contrôleur hôte ouvert USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbohci.sys [2008-04-14 17152]
    R3 usbprint;Classe d'imprimantes USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
    R3 USBSTOR;Pilote de stockage de masse USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
    S3 catchme;catchme; \??\C:\DOCUME~1\Celine\LOCALS~1\Temp\catchme.sys []
    S3 CVirtA;Cisco Systems VPN Adapter; C:\WINDOWS\system32\DRIVERS\CVirtA.sys [2007-01-18 5275]
    S3 gdrv;gdrv; \??\C:\WINDOWS\gdrv.sys []
    S3 ICDSX;Sony IC Recorder (SX); C:\WINDOWS\System32\Drivers\ICDSX.sys [2003-10-01 31744]
    S3 MRENDIS5;MRENDIS5 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS []
    S3 tapvpn;TAP VPN Adapter; C:\WINDOWS\system32\DRIVERS\tapvpn.sys [2006-10-26 27136]
    S3 vsdatant;vsdatant; \??\C:\WINDOWS\system32\vsdatant.sys []
    S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
    S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
    S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
    S4 WS2IFSL;Environnement de prise en charge de Fournisseur de services non-IFS Windows Sockets 2.0; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2008-04-14 12032]

    ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

    R2 a2free;a-squared Free Service; C:\Program Files\a-squared Free\a2service.exe [2009-06-12 718880]
    R2 aawservice;Lavasoft Ad-Aware Service; C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe [2009-01-02 611664]
    R2 AntiVirSchedulerService;Avira AntiVir Planificateur; C:\Program Files\Avira\AntiVir Desktop\sched.exe [2009-04-01 108289]
    R2 AntiVirService;Avira AntiVir Guard; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [2009-03-02 185089]
    R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2009-05-29 144712]
    R2 Bonjour Service;Service Bonjour; C:\Program Files\Bonjour\mDNSResponder.exe [2008-12-12 238888]
    R2 CVPND;Cisco Systems, Inc. VPN Service; C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe [2007-07-16 1524512]
    R2 fsssvc;Windows Live Contrôle parental; C:\Program Files\Windows Live\Family Safety\fsssvc.exe [2009-02-06 533360]
    R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-04-10 152984]
    R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe [2008-01-24 73728]
    R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2008-05-02 159812]
    R2 SeaPort;SeaPort; C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-05-19 240512]
    R3 iPod Service;Service de l’iPod; C:\Program Files\iPod\bin\iPodService.exe [2009-05-30 541992]
    S3 aspnet_state;Service d'état ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
    S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
    S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2009-01-30 654848]
    S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
    S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-05-07 182768]
    S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
    S3 NBService;NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2007-11-28 800040]
    S3 ose;Office Source Engine; C:\Program Files\Fichiers communs\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
    S3 WMPNetworkSvc;Service Partage réseau du Lecteur Windows Media; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-11-03 918016]
    S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
    S4 NetTcpPortSharing;Service de partage de ports Net.Tcp; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
    S4 NMIndexingService;NMIndexingService; C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe [2007-06-27 279848]

    -----------------EOF-----------------
    Contenus similaires
    a c 327 8 Sécurité
    20 Juin 2009 15:38:25

    Et le rapport info ?
    20 Juin 2009 15:42:30

    oups pardon, le voilà

    info.txt logfile of random's system information tool 1.06 2009-03-30 19:09:33

    ======Uninstall list======

    -->C:\PROGRA~1\CLUB-I~1\DRCLUB~1\Uninstall.exe TONLFR
    -->C:\PROGRA~1\Yahoo!\Common\UNYT_W~1.EXE
    -->C:\Program Files\Fichiers communs\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
    -->C:\Program Files\Nero\Nero 7\\nero\uninstall\UNNERO.exe /UNINSTALL
    -->C:\WINDOWS\UNNeroBackItUp.exe /UNINSTALL
    -->C:\WINDOWS\UNNeroMediaHome.exe /UNINSTALL
    -->C:\WINDOWS\UNNeroShowTime.exe /UNINSTALL
    -->C:\WINDOWS\UNNeroVision.exe /UNINSTALL
    -->C:\WINDOWS\UNRecode.exe /UNINSTALL
    -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
    Ad-Aware-->MsiExec.exe /I{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}
    Adobe AIR-->c:\Program Files\Fichiers communs\Adobe AIR\Versions\1.0\Resources\Adobe AIR Updater.exe -arp:uninstall
    Adobe AIR-->MsiExec.exe /I{A2BCA9F1-566C-4805-97D1-7FDC93386723}
    Adobe Anchor Service CS3-->MsiExec.exe /I{A4464AC3-D85E-4649-8748-706191063DF6}
    Adobe Asset Services CS3-->MsiExec.exe /I{7302810D-7ACF-4339-B27B-57016CAADDCD}
    Adobe Bridge CS3-->MsiExec.exe /I{FABA59CC-347B-478B-B2A7-37BF0885CACB}
    Adobe Bridge Start Meeting-->MsiExec.exe /I{CE52110A-7773-444F-9E5D-4A45E4792DB6}
    Adobe Camera Raw 4.0-->MsiExec.exe /I{AED353B9-E6D7-406F-B007-2C55C5265EB3}
    Adobe CMaps-->MsiExec.exe /I{D8FC8E35-D397-4C16-87AE-141A625221E4}
    Adobe Default Language CS3-->MsiExec.exe /I{D446BA40-1F5F-44EB-A794-0AC14F809C79}
    Adobe Device Central CS3-->MsiExec.exe /I{265FCC3B-4814-4B2B-89D6-217DFB8AD886}
    Adobe ExtendScript Toolkit 2-->MsiExec.exe /I{F36CFE58-47C0-4D75-995B-E0172563FA83}
    Adobe Flash Player 10 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
    Adobe Flash Player 10 Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
    Adobe Fonts All-->MsiExec.exe /I{162DDD86-C087-4E59-B7A8-0C1D8F884A9A}
    Adobe Help Viewer 1.1-->MsiExec.exe /I{F3697BA5-C8D8-4925-ACCA-F486C76BAD33}
    Adobe Linguistics CS3-->MsiExec.exe /I{E5C28906-EC86-404E-BB4F-6AB2590451FF}
    Adobe PDF Library Files-->MsiExec.exe /I{91D829E6-F1D1-433F-861F-0552DFED0EAD}
    Adobe Photoshop CS3-->C:\Program Files\Fichiers communs\Adobe\Installers\8d0dc9390f2c596455e1446b5918a40\Setup.exe
    Adobe Photoshop CS3-->MsiExec.exe /I{F32F1F7C-322D-46B9-B69A-5C3EDC88B74C}
    Adobe Reader 9.1 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A91000000001}
    Adobe Setup-->MsiExec.exe /I{CBF7A9A4-C0D4-4BA0-8991-C9B7D90A5298}
    Adobe Stock Photos CS3-->MsiExec.exe /I{73B79E83-490B-460D-B0D6-2C7B73980325}
    Adobe Type Support-->MsiExec.exe /I{A78A65E4-1D88-477A-83B4-3EC540F6A55A}
    Adobe Version Cue CS3 Client-->MsiExec.exe /I{BF18C55F-791F-4C17-AB75-E397EE01C14B}
    Adobe WinSoft Linguistics Plugin-->MsiExec.exe /I{51DC4D9C-F729-48A7-9CE0-BC77529ECCA2}
    Adobe XMP Panels CS3-->MsiExec.exe /I{F0CF6455-EDD8-41C6-A96A-223874E660CC}
    Apple Mobile Device Support-->MsiExec.exe /I{EC4455AB-F155-4CC1-A4C5-88F3777F9886}
    Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
    AppSnap 1.3.0-->C:\Program Files\AppSnap\uninst.exe
    Archiveur WinRAR-->C:\Program Files\WinRAR\uninstall.exe
    a-squared Free 4.0-->"C:\Program Files\a-squared Free\unins000.exe"
    Assistant de connexion Windows Live-->MsiExec.exe /I{DCE8CD14-FBF5-4464-B9A4-E18E473546C7}
    Audacity 1.2.6-->"C:\Program Files\Audacity\unins000.exe"
    Avira AntiVir Personal - Free Antivirus-->C:\Program Files\Avira\AntiVir PersonalEdition Classic\SETUP.EXE /REMOVE
    BroadJump Client Foundation-->C:\WINDOWS\IsUninst.exe -f"C:\Program Files\BroadJump\Client Foundation\Uninst.isu" -c"C:\Program Files\BroadJump\Client Foundation\RmvBJCFD.dll" -b"CFD" -h"CFD" -a
    CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
    Choice Guard-->MsiExec.exe /I{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}
    Configurateur Modem-->"C:\Program Files\Club-Internet\Assistance\uninstall.exe"
    Correctif pour Lecteur Windows Media 11 (KB939683)-->"C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
    Correctif pour Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
    Correctif pour Windows XP (KB961118)-->"C:\WINDOWS\$NtUninstallKB961118$\spuninst\spuninst.exe"
    Docteur Club Internet-->C:\WINDOWS\Motive\TONLFR\MCCUninst.exe
    DVD Shrink 3.2-->"C:\Program Files\DVD Shrink\unins000.exe"
    Earthsim-->"C:\Documents and Settings\All Users\Application Data\Earthsim\Channel\esuninst.exe"
    eMule-->"C:\Program Files\eMule\Uninstall.exe"
    eMusic - 50 Free MP3 offer-->"C:\Program Files\Winamp\eMusic\Uninst-eMusic-promotion.exe"
    ex-fumeurs (désinstallation)-->"C:\Program Files\ex-fumeurs\uninst-ex-fumeurs.exe"
    Favorit-->"c:\documents and settings\celine\local settings\application data\ikiwq.exe" -uninstall
    ffdshow [rev 2033] [2008-07-05]-->"C:\Program Files\ffdshow\unins000.exe"
    Finance 2003 version 10.03-->"C:\Program Files\SoftChris\Finance 2003\unins000.exe"
    Flary Address-->MsiExec.exe /X{F618BFCB-BCD8-4698-BEE8-B0C5FD75DA23}
    Free Download Manager 2.5 build 758-->C:\Program Files\Free Download Manager\uninst.exe
    Galerie de photos Windows Live-->MsiExec.exe /X{44E54A81-9D91-4AA1-9417-80AFF134F5FF}
    Gimp 2.6.1-->"C:\Program Files\Gimp-2.0\setup\unins000.exe"
    Google Earth-->MsiExec.exe /I{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}
    Google Toolbar for Internet Explorer-->"C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_0531C63A913CC9D1.exe" /uninstall
    HijackThis 2.0.2-->"C:\Documents and Settings\Celine\Bureau\HijackThis.exe" /uninstall
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
    Hotfix for Windows Media Format 11 SDK (KB929399)-->"C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
    ID3 Lyrics Editor-->C:\WINDOWS\IsUninst.exe -f"C:\Program Files\MP3\ID3EDIT\Uninst.isu"
    Inkscape 0.46-->C:\Program Files\Inkscape\Uninstall.exe
    Installation Windows Live-->C:\Program Files\Windows Live\Installer\wlarp.exe
    Installation Windows Live-->MsiExec.exe /I{7370DF47-B4F9-4279-BFC3-3F09919F720D}
    iTunes-->MsiExec.exe /I{318AB667-3230-41B5-A617-CB3BF748D371}
    Java(TM) 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
    Junk Mail filter update-->MsiExec.exe /I{4DE3E3D9-AE81-45DE-9195-3015F7B1DBF3}
    Le Sphinx-->C:\SphinxV5\licence\UNWISE.EXE C:\SphinxV5\licence\install.log
    Lecteur CANAL-->MsiExec.exe /X{04DA096D-6236-4A5D-8FB6-3081E67009BA}
    Lecteur Windows Media 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
    LightScribe System Software 1.12.29.2-->MsiExec.exe /X{CF8C077A-B467-4C43-8DB5-3A9B94FF9681}
    MadOnion.com/3DMark2001 SE-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{91B323B5-A79C-4D23-BD6D-046C565F9BCF}\Setup.exe" -l0x9 uninstall -uninst
    Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
    Media Player Classic fr-->"C:\Program Files\Media Player Classic\uninstall.exe"
    Microsoft .NET Framework 1.1 French Language Pack-->MsiExec.exe /X{9A394342-4A68-4EBA-85A6-55B559F4E700}
    Microsoft .NET Framework 1.1 Hotfix (KB928366)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"
    Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
    Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
    Microsoft .NET Framework 2.0 Service Pack 2 Language Pack - FRA-->MsiExec.exe /I{72AD53CC-CCC0-3757-8480-9EE176866A7C}
    Microsoft .NET Framework 2.0 Service Pack 2-->MsiExec.exe /I{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}
    Microsoft .NET Framework 3.0 Service Pack 2 Language Pack - FRA-->MsiExec.exe /I{0BD83598-C2EF-3343-847B-7D2E84599128}
    Microsoft .NET Framework 3.0 Service Pack 2-->MsiExec.exe /I{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}
    Microsoft .NET Framework 3.5 Language Pack SP1 - fra-->MsiExec.exe /I{3E31821C-7917-367E-938E-E65FC413EA31}
    Microsoft .NET Framework 3.5 SP1-->C:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
    Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
    Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
    Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
    Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
    Microsoft Office 2003 Web Components-->MsiExec.exe /I{90A4040C-6000-11D3-8CFE-0150048383C9}
    Microsoft Office 97 Professional-->C:\Program Files\Microsoft Office\Office\Install\Acme.exe /w Off97Pro.STF
    Microsoft Office Live Add-in 1.3-->MsiExec.exe /I{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}
    Microsoft Office Outlook Connector-->MsiExec.exe /I{95120000-0120-040C-0000-0000000FF1CE}
    Microsoft Office Professional Edition 2003-->MsiExec.exe /I{9011040C-6000-11D3-8CFE-0150048383C9}
    Microsoft Office XP Web Components-->MsiExec.exe /I{9026040C-6000-11D3-8CFE-0150048383C9}
    Microsoft Search Enhancement Pack-->MsiExec.exe /I{9C9CEB9D-53FD-49A7-85D2-FE674F72F24E}
    Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
    Microsoft SQL Server 2005 Compact Edition [ENU]-->MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
    Microsoft Sync Framework Runtime Native v1.0 (x86)-->MsiExec.exe /I{8A74E887-8F0F-4017-AF53-CBA42211AAA5}
    Microsoft Sync Framework Services Native v1.0 (x86)-->MsiExec.exe /I{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}
    Microsoft User-Mode Driver Framework Feature Pack 1.0-->"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
    Mise à jour critique pour Lecteur Windows Media 11 (KB959772)-->"C:\WINDOWS\$NtUninstallKB959772_WM11$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Lecteur Windows Media (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Lecteur Windows Media 11 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Lecteur Windows Media 11 (KB954154)-->"C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB923689)-->"C:\WINDOWS\$NtUninstallKB923689$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB923789)-->C:\WINDOWS\system32\MacroMed\Flash\genuinst.exe C:\WINDOWS\system32\MacroMed\Flash\KB923789.inf
    Mise à jour de sécurité pour Windows XP (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB954211)-->"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB954459)-->"C:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB954600)-->"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB956391)-->"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB956841)-->"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB957095)-->"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB958215)-->"C:\WINDOWS\$NtUninstallKB958215$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB958687)-->"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB958690)-->"C:\WINDOWS\$NtUninstallKB958690$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB960225)-->"C:\WINDOWS\$NtUninstallKB960225$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB960714)-->"C:\WINDOWS\$NtUninstallKB960714$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB960715)-->"C:\WINDOWS\$NtUninstallKB960715$\spuninst\spuninst.exe"
    Mise à jour pour Windows XP (KB898461)-->"C:\WINDOWS\$NtUninstallKB898461$\spuninst\spuninst.exe"
    Mise à jour pour Windows XP (KB951072-v2)-->"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
    Mise à jour pour Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
    Mise à jour pour Windows XP (KB955839)-->"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
    Mise à jour pour Windows XP (KB967715)-->"C:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe"
    Module linguistique Microsoft .NET Framework 3.5 SP1- fra-->c:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 Language Pack SP1 - fra\setup.exe
    Mozilla Firefox (3.0.8)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
    MozyHome Remote Backup-->MsiExec.exe /X{D2058971-12C7-46E2-9DDB-933C8A6D2051}
    MP3 Player Utilities 4.00-->MsiExec.exe /I{7784A172-61F1-445E-8368-601607E0DD22}
    MP3 Player Utilities 4.04-->MsiExec.exe /I{8B9852AF-B0B0-47B7-9BC5-89A95D77B6C9}
    MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
    MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
    Navilog1 3.7.6-->"C:\Program Files\Navilog1\unins000.exe"
    Nero 7 Essentials-->MsiExec.exe /X{7BAA9BA8-0761-42EF-842A-23FAA5321036}
    neroxml-->MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B}
    NVIDIA Drivers-->C:\WINDOWS\system32\nvuninst.exe UninstallGUI
    OpenOffice.org 3.0-->MsiExec.exe /I{1572F66F-F9AD-4D45-B0D2-0F45A0D5A0F6}
    Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
    Package de pilotes Windows - Advanced Micro Devices (AmdK8) Processor (05/27/2006 1.3.2.0)-->C:\PROGRA~1\DIFX\7B44739871F4D539FA473F57A832EA4B6A59EF06\DPInst.exe /d /u C:\WINDOWS\system32\DRVSTORE\amdk8_C7A451815AD6A55564D6F47B5A12C61D8B4DCFD1\amdk8.inf
    Paint.NET v3.36-->MsiExec.exe /X{43602F34-1AA3-44FB-AEB2-D08C2C73743F}
    PhotoFiltre-->"C:\Program Files\PhotoFiltre\Uninst.exe"
    PHPNukeFR Toolbar-->C:\PROGRA~1\PHPNUK~1\UNWISE.EXE /U C:\PROGRA~1\PHPNUK~1\INSTALL.LOG
    Picasa 2-->"C:\Program Files\Picasa2\Uninstall.exe"
    QuickTime-->MsiExec.exe /I{F958CA02-BB40-4007-894B-258729456EE4}
    RealPlayer-->C:\Program Files\Fichiers communs\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
    REALTEK GbE & FE Ethernet PCI NIC Driver-->C:\Program Files\InstallShield Installation Information\{ACCA20B0-C4D1-4BF5-BF21-0A0EB5EF9730}\SETUP.EXE -runfromtemp -l0x040c -removeonly
    REALTEK GbE & FE Ethernet PCI-E NIC Driver-->C:\Program Files\InstallShield Installation Information\{C9BED750-1211-4480-B1A5-718A3BE15525}\setup.exe -runfromtemp -l0x040c -removeonly
    Realtek High Definition Audio Driver-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\SETUP.EXE" -l0x40c -removeonly
    SecondLife (remove only)-->"C:\Program Files\SecondLife\uninst.exe" /P="SecondLife"
    Segoe UI-->MsiExec.exe /I{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}
    Skype™ 3.8-->MsiExec.exe /X{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}
    Spybot - Search & Destroy-->"C:\Program Files\Spybot - Search & Destroy\unins000.exe"
    SpywareBlaster 4.1-->"C:\Program Files\SpywareBlaster\unins000.exe"
    The_Pirate_Bay Toolbar-->C:\PROGRA~1\THE_PI~1\UNWISE.EXE /U C:\PROGRA~1\THE_PI~1\INSTALL.LOG
    USB Disk Win98 Driver-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BF5EE349-90CD-4422-A43B-661778180173}\Setup.exe"
    VLC media player 0.9.2-->C:\Program Files\VideoLAN\VLC\uninstall.exe
    VPN Client-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5624C000-B109-11D4-9DB4-00E0290FCAC5}\Setup.exe" -l0x9 VpnUninstall
    Winamp-->"C:\Program Files\Winamp\UninstWA.exe"
    Windows Live Call-->MsiExec.exe /I{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}
    Windows Live Communications Platform-->MsiExec.exe /I{3B4E636E-9D65-4D67-BA61-189800823F52}
    Windows Live Contrôle parental-->MsiExec.exe /X{D6A2DDE3-9D7C-412C-932A-756580D29919}
    Windows Live Mail-->MsiExec.exe /I{63DC2DA0-2A6C-4C38-9249-B75395458657}
    Windows Live Messenger-->MsiExec.exe /X{059C042E-796A-4ACC-A81A-ECC2010BB78C}
    Windows Live Sync-->MsiExec.exe /X{9C5EB781-0D37-44B8-9A58-77B3E4BF5F5E}
    Windows Live Toolbar-->MsiExec.exe /X{F7D27C70-90F5-49B9-B188-0A133C0CE353}
    Windows Live Writer-->MsiExec.exe /X{2231CE39-B963-4B9D-823A-F412ECA637B1}
    Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
    Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
    Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
    WinZip-->"C:\Program Files\WinZip\WINZIP32.EXE" /uninstall
    XML Paper Specification Shared Components Language Pack 1.0-->"C:\WINDOWS\$NtUninstallXPSEPSCLP$\spuninst\spuninst.exe"
    Yahoo! Toolbar-->C:\PROGRA~1\Yahoo!\Common\UNYT_W~1.EXE
    ZebHelpProcess 2.33-->"C:\Program Files\ZebHelpProcess 2\unins000.exe"

    ======Hosts File======

    127.0.0.1 www.007guard.com
    127.0.0.1 007guard.com
    127.0.0.1 008i.com
    127.0.0.1 www.008k.com
    127.0.0.1 008k.com
    127.0.0.1 www.00hq.com
    127.0.0.1 00hq.com
    127.0.0.1 010402.com
    127.0.0.1 www.032439.com
    127.0.0.1 032439.com

    ======Security center information======

    AV: Avira AntiVir PersonalEdition Classic

    ======System event log======

    Computer Name: PEREA-A88DA7661
    Event Code: 51
    Message: Une erreur a été détectée sur le périphérique \Device\Harddisk6\D au cours d'une opération de pagination.

    Record Number: 7427
    Source Name: Disk
    Time Written: 20090301171757.000000+060
    Event Type: Avertissement
    User:

    Computer Name: PEREA-A88DA7661
    Event Code: 51
    Message: Une erreur a été détectée sur le périphérique \Device\Harddisk6\D au cours d'une opération de pagination.

    Record Number: 7426
    Source Name: Disk
    Time Written: 20090301171746.000000+060
    Event Type: Avertissement
    User:

    Computer Name: PEREA-A88DA7661
    Event Code: 51
    Message: Une erreur a été détectée sur le périphérique \Device\Harddisk6\D au cours d'une opération de pagination.

    Record Number: 7425
    Source Name: Disk
    Time Written: 20090301171735.000000+060
    Event Type: Avertissement
    User:

    Computer Name: PEREA-A88DA7661
    Event Code: 51
    Message: Une erreur a été détectée sur le périphérique \Device\Harddisk6\D au cours d'une opération de pagination.

    Record Number: 7424
    Source Name: Disk
    Time Written: 20090301171734.000000+060
    Event Type: Avertissement
    User:

    Computer Name: PEREA-A88DA7661
    Event Code: 51
    Message: Une erreur a été détectée sur le périphérique \Device\Harddisk6\D au cours d'une opération de pagination.

    Record Number: 7423
    Source Name: Disk
    Time Written: 20090301171723.000000+060
    Event Type: Avertissement
    User:

    =====Application event log=====

    Computer Name: PEREA-A88DA7661
    Event Code: 4096
    Message: Le service AntiVir a bien démarré!

    Record Number: 1294
    Source Name: Avira AntiVir
    Time Written: 20090201094343.000000+060
    Event Type: Informations
    User: AUTORITE NT\SYSTEM

    Computer Name: PEREA-A88DA7661
    Event Code: 1800
    Message: Le service Centre de sécurité Windows a démarré.

    Record Number: 1293
    Source Name: SecurityCenter
    Time Written: 20090201094342.000000+060
    Event Type: Informations
    User:

    Computer Name: PEREA-A88DA7661
    Event Code: 0
    Message:
    Record Number: 1292
    Source Name: SeaPort
    Time Written: 20090201094342.000000+060
    Event Type: Informations
    User:

    Computer Name: PEREA-A88DA7661
    Event Code: 4
    Message: The LightScribe Service started successfully.

    Record Number: 1291
    Source Name: LightScribeService
    Time Written: 20090201094339.000000+060
    Event Type: Informations
    User:

    Computer Name: PEREA-A88DA7661
    Event Code: 1
    Message:
    Record Number: 1290
    Source Name: Bonjour Service
    Time Written: 20090201094339.000000+060
    Event Type: Informations
    User:

    ======Environment variables======

    "ComSpec"=%SystemRoot%\system32\cmd.exe
    "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\QuickTime\QTSystem\
    "windir"=%SystemRoot%
    "FP_NO_HOST_CHECK"=NO
    "OS"=Windows_NT
    "PROCESSOR_ARCHITECTURE"=x86
    "PROCESSOR_LEVEL"=15
    "PROCESSOR_IDENTIFIER"=x86 Family 15 Model 107 Stepping 2, AuthenticAMD
    "PROCESSOR_REVISION"=6b02
    "NUMBER_OF_PROCESSORS"=2
    "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
    "TEMP"=%SystemRoot%\TEMP
    "TMP"=%SystemRoot%\TEMP
    "CLASSPATH"=.;C:\Program Files\Java\jre1.6.0_07\lib\ext\QTJava.zip
    "QTJAVA"=C:\Program Files\Java\jre1.6.0_07\lib\ext\QTJava.zip

    -----------------EOF-----------------
    a c 327 8 Sécurité
    20 Juin 2009 15:47:26

  • Désinstalle Navilog1.

    Peux-tu me poster le rapport du dernier scan que tu as fait avec MBAM ?
    20 Juin 2009 15:52:28

    Je mets MBAM, j'aurais bien mis celui de a-squared que je viens de faire mais je ne le trouve pas.

    Malwarebytes' Anti-Malware 1.38
    Version de la base de données: 2302
    Windows 5.1.2600 Service Pack 3

    18/06/2009 09:47:54
    mbam-log-2009-06-18 (09-47-54).txt

    Type de recherche: Examen complet (C:\|D:\|E:\|F:\|G:\|H:\|)
    Eléments examinés: 185159
    Temps écoulé: 46 minute(s), 15 second(s)

    Processus mémoire infecté(s): 0
    Module(s) mémoire infecté(s): 0
    Clé(s) du Registre infectée(s): 0
    Valeur(s) du Registre infectée(s): 0
    Elément(s) de données du Registre infecté(s): 0
    Dossier(s) infecté(s): 0
    Fichier(s) infecté(s): 0

    Processus mémoire infecté(s):
    (Aucun élément nuisible détecté)

    Module(s) mémoire infecté(s):
    (Aucun élément nuisible détecté)

    Clé(s) du Registre infectée(s):
    (Aucun élément nuisible détecté)

    Valeur(s) du Registre infectée(s):
    (Aucun élément nuisible détecté)

    Elément(s) de données du Registre infecté(s):
    (Aucun élément nuisible détecté)

    Dossier(s) infecté(s):
    (Aucun élément nuisible détecté)

    Fichier(s) infecté(s):
    (Aucun élément nuisible détecté)

    ------------------------------------------------------------------------------------------------------


    a c 327 8 Sécurité
    20 Juin 2009 15:59:34

    Change ton mot de passe MSN et ta question secrète.

    As-tu fait un scan avec AntiVir ?
    20 Juin 2009 16:09:08

    voilà j'ai changé le passe.

    J'ai scané avec antivir hier mais rien trouvé, il n'y a que a-squared qui trouve le trojan dropper et un autre.
    a c 327 8 Sécurité
    20 Juin 2009 16:18:51

    Tu peux me donner l'emplacement et le nom du fichier infecté ?
    20 Juin 2009 16:21:47

    Je refais un scan et poste le résultat
    20 Juin 2009 21:13:04

    et bien comme de par hasard il ne détecte rien, alors que 3 fois de suite il relevait les trojan..enfin dois je penser que c'est réglé?
    21 Juin 2009 01:34:57

    voilà mission accomplie...merci beaucoup pour tous ces conseils avisés...tout roule maintenant?
    a c 327 8 Sécurité
    21 Juin 2009 01:41:52

    Non, je viens de remarquer un truc dans le rapport log de RSIT.

  • Télécharge Lop S&D sur ton Bureau.
  • Double-clique dessus pour lancer l'installation.
  • Puis double-clique sur le raccourci Lop S&D présent sur ton Bureau.
  • Sélectionne la langue souhaitée, puis choisis l'option 1 (Recherche) .
  • Patiente jusqu'à la fin du scan.
  • Poste le rapport généré (C:\lopR.txt).
    21 Juin 2009 01:56:29

    je me disais aussi..héé catchme??...le rapport:


    --------------------\\ Lop S&D 4.2.5-0 XP/Vista

    Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 3
    X86-based PC ( Multiprocessor Free : AMD Athlon(tm) 64 X2 Dual Core Processor 5200+ )
    BIOS : Award Modular BIOS v6.00PG
    USER : Celine ( Administrator )
    BOOT : Normal boot
    Antivirus : AntiVir Desktop 9.0.1.26 (Activated)
    C:\ (Local Disk) - NTFS - Total:298 Go (Free:274 Go)
    D:\ (CD or DVD)
    E:\ (USB)
    F:\ (USB)
    G:\ (USB)
    H:\ (USB)

    "C:\Lop SD" ( MAJ : 19-12-2008|23:40 )
    Option : [1] ( 21/06/2009| 1:52 )

    --------------------\\ Listing des dossiers dans APPLIC~1

    [05/06/2009|09:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
    [24/03/2009|08:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
    [14/11/2008|16:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Ahead
    [15/12/2008|21:43] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple
    [15/12/2008|21:44] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
    [15/05/2009|17:15] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Avira
    [21/12/2008|10:48] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Azureus
    [09/12/2008|18:02] C:\DOCUME~1\ALLUSE~1\APPLIC~1\DVD Shrink
    [11/12/2008|19:12] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Earthsim
    [08/02/2009|10:03] C:\DOCUME~1\ALLUSE~1\APPLIC~1\FLEXnet
    [26/01/2009|20:05] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
    [11/12/2008|19:49] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Grisoft
    [11/12/2008|18:37] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Kaspersky Lab Setup Files
    [02/01/2009|07:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
    [11/12/2008|19:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\LightScribe
    [26/12/2008|16:03] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Malwarebytes
    [21/02/2009|09:23] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
    [09/12/2008|16:47] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Motive
    [03/04/2009|08:35] C:\DOCUME~1\ALLUSE~1\APPLIC~1\MyHeritage
    [14/11/2008|16:03] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Nero
    [23/03/2009|07:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\NOS
    [25/12/2008|09:43] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SITEguard
    [14/06/2009|08:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Skype
    [21/06/2009|01:24] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
    [05/05/2009|07:19] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Steek
    [25/12/2008|10:55] C:\DOCUME~1\ALLUSE~1\APPLIC~1\STOPzilla!
    [03/02/2009|14:56] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
    [14/11/2008|17:24] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
    [09/12/2008|18:19] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Live Toolbar

    [18/04/2009|10:52] C:\DOCUME~1\Celine\APPLIC~1\Adobe
    [11/12/2008|22:23] C:\DOCUME~1\Celine\APPLIC~1\Ahead
    [21/12/2008|10:43] C:\DOCUME~1\Celine\APPLIC~1\Apple Computer
    [11/12/2008|18:54] C:\DOCUME~1\Celine\APPLIC~1\Axialis
    [21/12/2008|11:07] C:\DOCUME~1\Celine\APPLIC~1\Azureus
    [11/04/2009|22:51] C:\DOCUME~1\Celine\APPLIC~1\BitSpirit
    [19/06/2009|22:35] C:\DOCUME~1\Celine\APPLIC~1\dvdcss
    [10/04/2009|16:31] C:\DOCUME~1\Celine\APPLIC~1\Free Download Manager
    [22/05/2009|08:29] C:\DOCUME~1\Celine\APPLIC~1\GetRightToGo
    [11/12/2008|19:18] C:\DOCUME~1\Celine\APPLIC~1\Google
    [13/05/2009|09:30] C:\DOCUME~1\Celine\APPLIC~1\gtk-2.0
    [06/06/2009|23:27] C:\DOCUME~1\Celine\APPLIC~1\Help
    [14/11/2008|15:49] C:\DOCUME~1\Celine\APPLIC~1\Identities
    [09/12/2008|18:07] C:\DOCUME~1\Celine\APPLIC~1\Inkscape
    [14/11/2008|15:54] C:\DOCUME~1\Celine\APPLIC~1\InstallShield
    [02/01/2009|07:17] C:\DOCUME~1\Celine\APPLIC~1\Lavasoft
    [18/12/2008|21:19] C:\DOCUME~1\Celine\APPLIC~1\LimeWire
    [15/11/2008|10:42] C:\DOCUME~1\Celine\APPLIC~1\Macromedia
    [26/12/2008|16:03] C:\DOCUME~1\Celine\APPLIC~1\Malwarebytes
    [25/12/2008|03:29] C:\DOCUME~1\Celine\APPLIC~1\Media Player Classic
    [11/04/2009|16:46] C:\DOCUME~1\Celine\APPLIC~1\Microsoft
    [06/02/2009|09:22] C:\DOCUME~1\Celine\APPLIC~1\Mozilla
    [03/04/2009|08:33] C:\DOCUME~1\Celine\APPLIC~1\MyHeritage
    [14/12/2008|15:26] C:\DOCUME~1\Celine\APPLIC~1\OpenOffice.org
    [06/02/2009|10:16] C:\DOCUME~1\Celine\APPLIC~1\Real
    [11/12/2008|18:28] C:\DOCUME~1\Celine\APPLIC~1\SecondLife
    [20/06/2009|00:11] C:\DOCUME~1\Celine\APPLIC~1\Skype
    [19/06/2009|17:24] C:\DOCUME~1\Celine\APPLIC~1\skypePM
    [11/12/2008|19:37] C:\DOCUME~1\Celine\APPLIC~1\Sphinx
    [09/12/2008|18:10] C:\DOCUME~1\Celine\APPLIC~1\Sun
    [03/04/2009|08:31] C:\DOCUME~1\Celine\APPLIC~1\The Complete Genealogy Reporter - FTB
    [06/02/2009|09:22] C:\DOCUME~1\Celine\APPLIC~1\Thunderbird
    [11/12/2008|23:37] C:\DOCUME~1\Celine\APPLIC~1\Uniblue
    [16/06/2009|08:22] C:\DOCUME~1\Celine\APPLIC~1\vlc
    [09/12/2008|18:09] C:\DOCUME~1\Celine\APPLIC~1\Winamp
    [14/12/2008|15:25] C:\DOCUME~1\Celine\APPLIC~1\WinRAR
    [14/02/2009|13:28] C:\DOCUME~1\Celine\APPLIC~1\Yahoo!

    [14/11/2008|15:45] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft

    [31/12/2008|06:43] C:\DOCUME~1\INVIT~1\APPLIC~1\Adobe
    [31/12/2008|06:43] C:\DOCUME~1\INVIT~1\APPLIC~1\Grisoft
    [31/12/2008|06:42] C:\DOCUME~1\INVIT~1\APPLIC~1\Identities
    [31/12/2008|06:43] C:\DOCUME~1\INVIT~1\APPLIC~1\Macromedia
    [31/12/2008|06:44] C:\DOCUME~1\INVIT~1\APPLIC~1\Microsoft
    [31/12/2008|06:55] C:\DOCUME~1\INVIT~1\APPLIC~1\Mozilla
    [04/01/2009|07:24] C:\DOCUME~1\INVIT~1\APPLIC~1\Winamp
    [04/01/2009|03:21] C:\DOCUME~1\INVIT~1\APPLIC~1\WinRAR

    [09/12/2008|18:04] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft

    [24/12/2008|11:39] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft

    --------------------\\ Tâches planifiées dans C:\WINDOWS\tasks

    [20/06/2009 21:00][--ah-----] C:\WINDOWS\tasks\A3310BBC91B2BEDC.job
    [16/06/2009 09:31][--a------] C:\WINDOWS\tasks\AppleSoftwareUpdate.job
    [21/06/2009 01:23][--ah-----] C:\WINDOWS\tasks\SA.DAT
    [14/04/2008 14:00][-r-h-----] C:\WINDOWS\tasks\desktop.ini

    ( A3310BBC91B2BEDC.job )=( c:\docume~1\celine\applic~1\mealtr~1\1601jugs.exe )

    --------------------\\ Listing des dossiers dans C:\Program Files

    [30/01/2009|18:23] C:\Program Files\Adobe
    [15/12/2008|21:43] C:\Program Files\Apple Software Update
    [09/12/2008|18:11] C:\Program Files\AppSnap
    [21/12/2008|10:48] C:\Program Files\AskSearch
    [20/06/2009|16:21] C:\Program Files\a-squared Free
    [09/12/2008|18:00] C:\Program Files\Audacity
    [15/05/2009|17:15] C:\Program Files\Avira
    [11/12/2008|19:01] C:\Program Files\Axialis
    [19/04/2009|19:16] C:\Program Files\BitSpirit
    [12/06/2009|07:21] C:\Program Files\Bonjour
    [09/12/2008|16:45] C:\Program Files\BroadJump
    [21/03/2009|18:12] C:\Program Files\Canal
    [14/02/2009|13:28] C:\Program Files\CCleaner
    [11/12/2008|20:19] C:\Program Files\Cisco Systems
    [09/12/2008|16:47] C:\Program Files\Club-Internet
    [09/12/2008|16:47] C:\Program Files\Common Files
    [14/11/2008|15:43] C:\Program Files\ComPlus Applications
    [25/01/2009|11:51] C:\Program Files\Conduit
    [14/11/2008|15:52] C:\Program Files\DIFX
    [09/12/2008|18:02] C:\Program Files\DVD Shrink
    [15/06/2009|18:03] C:\Program Files\eMule
    [14/03/2009|19:09] C:\Program Files\ex-fumeurs
    [09/12/2008|18:04] C:\Program Files\ffdshow
    [21/06/2009|01:31] C:\Program Files\Fichiers communs
    [27/03/2009|16:36] C:\Program Files\Flary Address
    [30/01/2009|18:02] C:\Program Files\Free Download Manager
    [09/12/2008|18:04] C:\Program Files\Gimp-2.0
    [26/01/2009|23:23] C:\Program Files\Google
    [11/12/2008|19:49] C:\Program Files\Grisoft
    [14/06/2009|12:54] C:\Program Files\Hotspot_Shield
    [09/12/2008|18:06] C:\Program Files\Inkscape
    [03/03/2009|18:17] C:\Program Files\InstallShield Installation Information
    [21/06/2009|01:41] C:\Program Files\Internet Explorer
    [05/06/2009|09:45] C:\Program Files\iPod
    [05/06/2009|09:45] C:\Program Files\iTunes
    [21/06/2009|01:33] C:\Program Files\Java
    [02/01/2009|07:17] C:\Program Files\Lavasoft
    [09/12/2008|18:17] C:\Program Files\MadOnion.com
    [18/06/2009|08:57] C:\Program Files\Malwarebytes' Anti-Malware
    [21/12/2008|10:43] C:\Program Files\Meal trust real
    [09/12/2008|18:03] C:\Program Files\Media Player Classic
    [14/11/2008|17:36] C:\Program Files\Messenger
    [17/12/2008|08:01] C:\Program Files\Microsoft
    [14/11/2008|15:45] C:\Program Files\microsoft frontpage
    [14/12/2008|15:34] C:\Program Files\Microsoft Office
    [11/02/2009|10:30] C:\Program Files\Microsoft Office Outlook Connector
    [26/02/2009|07:27] C:\Program Files\Microsoft Silverlight
    [17/12/2008|07:57] C:\Program Files\Microsoft SQL Server Compact Edition
    [17/12/2008|07:59] C:\Program Files\Microsoft Sync Framework
    [11/12/2008|19:05] C:\Program Files\Microsoft.NET
    [09/12/2008|16:47] C:\Program Files\Motive
    [14/11/2008|15:44] C:\Program Files\Movie Maker
    [21/06/2009|01:30] C:\Program Files\Mozilla Firefox
    [11/02/2009|10:33] C:\Program Files\Mozilla Thunderbird
    [27/03/2009|16:36] C:\Program Files\MP3
    [27/03/2009|16:32] C:\Program Files\MP3 Player Utilities 4.00
    [27/03/2009|16:31] C:\Program Files\MP3 Player Utilities 4.04
    [27/01/2009|09:35] C:\Program Files\MSBuild
    [11/02/2009|10:29] C:\Program Files\MSECache
    [14/11/2008|15:42] C:\Program Files\MSN
    [14/11/2008|15:43] C:\Program Files\MSN Gaming Zone
    [14/11/2008|17:36] C:\Program Files\MSXML 4.0
    [03/04/2009|08:35] C:\Program Files\MyHeritage
    [20/06/2009|15:53] C:\Program Files\Navilog1
    [14/11/2008|16:03] C:\Program Files\Nero
    [14/11/2008|15:44] C:\Program Files\NetMeeting
    [23/03/2009|07:06] C:\Program Files\NOS
    [09/12/2008|18:01] C:\Program Files\OpenOffice.org 3
    [14/11/2008|15:44] C:\Program Files\Outlook Express
    [27/01/2009|09:45] C:\Program Files\Paint.NET
    [11/04/2009|16:47] C:\Program Files\PDFCreator
    [09/12/2008|18:06] C:\Program Files\PhotoFiltre
    [10/06/2009|09:53] C:\Program Files\PHPNukeFR
    [09/12/2008|18:06] C:\Program Files\Picasa2
    [05/06/2009|09:43] C:\Program Files\QuickTime
    [06/02/2009|10:14] C:\Program Files\Real
    [11/12/2008|16:47] C:\Program Files\Realtek
    [27/01/2009|09:35] C:\Program Files\Reference Assemblies
    [05/06/2009|09:39] C:\Program Files\Safari
    [24/12/2008|11:14] C:\Program Files\Safer Networking
    [30/12/2008|16:33] C:\Program Files\SecondLife
    [14/11/2008|15:44] C:\Program Files\Services en ligne
    [14/06/2009|08:45] C:\Program Files\Skype
    [09/12/2008|18:02] C:\Program Files\SoftChris
    [20/06/2009|09:08] C:\Program Files\Spybot - Search & Destroy
    [03/02/2009|14:54] C:\Program Files\SpywareBlaster
    [07/05/2009|09:36] C:\Program Files\Steek
    [31/03/2009|13:31] C:\Program Files\Text2PDF v1.5
    [03/04/2009|08:10] C:\Program Files\Tracker Software
    [20/06/2009|15:39] C:\Program Files\trend micro
    [14/11/2008|15:49] C:\Program Files\Uninstall Information
    [03/03/2009|18:17] C:\Program Files\USB Disk Win98 Driver
    [09/12/2008|18:03] C:\Program Files\VideoLAN
    [24/12/2008|19:20] C:\Program Files\Vuze
    [12/06/2009|07:20] C:\Program Files\Winamp
    [21/02/2009|09:23] C:\Program Files\Windows Live
    [17/12/2008|07:55] C:\Program Files\Windows Live SkyDrive
    [17/12/2008|09:22] C:\Program Files\Windows Live Toolbar
    [14/11/2008|17:32] C:\Program Files\Windows Media Connect 2
    [05/06/2009|09:37] C:\Program Files\Windows Media Player
    [14/12/2008|15:33] C:\Program Files\Windows Messaging
    [23/12/2008|11:44] C:\Program Files\Windows NT
    [14/11/2008|15:44] C:\Program Files\WindowsUpdate
    [14/12/2008|15:25] C:\Program Files\WinRAR
    [08/06/2009|10:35] C:\Program Files\WinZip
    [14/11/2008|15:45] C:\Program Files\xerox
    [11/04/2009|20:24] C:\Program Files\Yahoo!
    [05/02/2009|07:48] C:\Program Files\ZebHelpProcess 2

    --------------------\\ Listing des dossiers dans C:\Program Files\Fichiers communs

    [20/04/2009|19:42] C:\Program Files\Fichiers communs\Adobe
    [21/03/2009|18:11] C:\Program Files\Fichiers communs\Adobe AIR
    [14/11/2008|16:05] C:\Program Files\Fichiers communs\Ahead
    [05/06/2009|09:45] C:\Program Files\Fichiers communs\Apple
    [05/02/2009|07:48] C:\Program Files\Fichiers communs\Borland Shared
    [14/12/2008|15:41] C:\Program Files\Fichiers communs\DESIGNER
    [11/12/2008|20:19] C:\Program Files\Fichiers communs\Deterministic Networks
    [09/12/2008|18:16] C:\Program Files\Fichiers communs\InstallShield
    [24/12/2008|19:09] C:\Program Files\Fichiers communs\iS3
    [14/11/2008|16:06] C:\Program Files\Fichiers communs\LightScribe
    [30/01/2009|18:17] C:\Program Files\Fichiers communs\Macrovision Shared
    [15/05/2009|17:14] C:\Program Files\Fichiers communs\Microsoft Shared
    [09/12/2008|16:47] C:\Program Files\Fichiers communs\Motive
    [14/11/2008|15:44] C:\Program Files\Fichiers communs\MSSoap
    [14/11/2008|16:38] C:\Program Files\Fichiers communs\ODBC
    [06/02/2009|10:14] C:\Program Files\Fichiers communs\Real
    [14/11/2008|15:44] C:\Program Files\Fichiers communs\Services
    [14/06/2009|08:45] C:\Program Files\Fichiers communs\Skype
    [14/11/2008|16:38] C:\Program Files\Fichiers communs\SpeechEngines
    [17/12/2008|08:01] C:\Program Files\Fichiers communs\System
    [17/12/2008|07:49] C:\Program Files\Fichiers communs\Windows Live
    [02/01/2009|07:16] C:\Program Files\Fichiers communs\Wise Installation Wizard
    [06/02/2009|10:14] C:\Program Files\Fichiers communs\xing shared

    --------------------\\ Process

    ( 52 Processes )

    ... OK !

    --------------------\\ Recherche avec S_Lop

    Aucun fichier / dossier Lop trouvé !

    --------------------\\ Recherche de Fichiers / Dossiers Lop

    C:\Program Files\mealtr~1
    C:\WINDOWS\Tasks\A3310BBC91B2BEDC.job

    --------------------\\ Verification du Registre

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

    ..... OK !

    --------------------\\ Verification du fichier Hosts

    Fichier Hosts PROPRE


    --------------------\\ Recherche de fichiers avec Catchme

    catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2009-06-21 01:53:27
    Windows 5.1.2600 Service Pack 3 NTFS
    scanning hidden processes ...
    scanning hidden files ...
    scan completed successfully
    hidden processes: 0
    hidden files: 0

    --------------------\\ Recherche d'autres infections


    Aucune autre infection trouvée !

    [F:68][D:13]-> C:\DOCUME~1\Celine\LOCALS~1\Temp
    [F:15][D:0]-> C:\DOCUME~1\Celine\Cookies
    [F:6][D:4]-> C:\DOCUME~1\Celine\LOCALS~1\TEMPOR~1\content.IE5

    1 - "C:\Lop SD\LopR_1.txt" - 31/03/2009| 7:21 - Option : [1]
    2 - "C:\Lop SD\LopR_2.txt" - 21/06/2009| 1:55 - Option : [1]

    --------------------\\ Fin du rapport a 1:55:07
    a c 327 8 Sécurité
    21 Juin 2009 01:58:47

    J'ai bien fait de vérifier, je vois une infection Lop.

  • Relance Lop S&D.
  • Choisis cette fois-ci l'option 2 (Suppression).
  • Ne ferme pas la fenêtre lors de la suppression !
  • Poste le rapport généré (C:\lopR.txt).

    (Si le Bureau ne réapparaît pas, presse Ctrl+Alt+Suppr, Onglet Fichier, Nouvelle tâche, tape explorer.exe et valide)
    21 Juin 2009 02:08:17

    c'est koi?


    --------------------\\ Lop S&D 4.2.5-0 XP/Vista

    Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 3
    X86-based PC ( Multiprocessor Free : AMD Athlon(tm) 64 X2 Dual Core Processor 5200+ )
    BIOS : Award Modular BIOS v6.00PG
    USER : Celine ( Administrator )
    BOOT : Normal boot
    Antivirus : AntiVir Desktop 9.0.1.26 (Activated)
    C:\ (Local Disk) - NTFS - Total:298 Go (Free:274 Go)
    D:\ (CD or DVD)
    E:\ (USB)
    F:\ (USB)
    G:\ (USB)
    H:\ (USB)

    "C:\Lop SD" ( MAJ : 19-12-2008|23:40 )
    Option : [2] ( 21/06/2009| 2:06 )


    \\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ SUPPRESSION

    Supprime! - C:\WINDOWS\Tasks\A3310BBC91B2BEDC.job
    Supprime! - C:\Program Files\mealtr~1
    -
    [ Fichier Hosts ] .. Restaure!

    \\\\\\\\\\\\\\\\\\\\\\\\\\\\\\


    --------------------\\ Listing des dossiers dans APPLIC~1

    [05/06/2009|09:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
    [24/03/2009|08:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
    [14/11/2008|16:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Ahead
    [15/12/2008|21:43] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple
    [15/12/2008|21:44] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
    [15/05/2009|17:15] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Avira
    [21/12/2008|10:48] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Azureus
    [09/12/2008|18:02] C:\DOCUME~1\ALLUSE~1\APPLIC~1\DVD Shrink
    [11/12/2008|19:12] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Earthsim
    [08/02/2009|10:03] C:\DOCUME~1\ALLUSE~1\APPLIC~1\FLEXnet
    [26/01/2009|20:05] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
    [11/12/2008|19:49] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Grisoft
    [11/12/2008|18:37] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Kaspersky Lab Setup Files
    [02/01/2009|07:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
    [11/12/2008|19:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\LightScribe
    [26/12/2008|16:03] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Malwarebytes
    [21/02/2009|09:23] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
    [09/12/2008|16:47] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Motive
    [03/04/2009|08:35] C:\DOCUME~1\ALLUSE~1\APPLIC~1\MyHeritage
    [14/11/2008|16:03] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Nero
    [21/06/2009|02:05] C:\DOCUME~1\ALLUSE~1\APPLIC~1\NOS
    [25/12/2008|09:43] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SITEguard
    [14/06/2009|08:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Skype
    [21/06/2009|01:24] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
    [05/05/2009|07:19] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Steek
    [25/12/2008|10:55] C:\DOCUME~1\ALLUSE~1\APPLIC~1\STOPzilla!
    [03/02/2009|14:56] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
    [14/11/2008|17:24] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
    [09/12/2008|18:19] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Live Toolbar

    [18/04/2009|10:52] C:\DOCUME~1\Celine\APPLIC~1\Adobe
    [11/12/2008|22:23] C:\DOCUME~1\Celine\APPLIC~1\Ahead
    [21/12/2008|10:43] C:\DOCUME~1\Celine\APPLIC~1\Apple Computer
    [11/12/2008|18:54] C:\DOCUME~1\Celine\APPLIC~1\Axialis
    [21/12/2008|11:07] C:\DOCUME~1\Celine\APPLIC~1\Azureus
    [11/04/2009|22:51] C:\DOCUME~1\Celine\APPLIC~1\BitSpirit
    [19/06/2009|22:35] C:\DOCUME~1\Celine\APPLIC~1\dvdcss
    [10/04/2009|16:31] C:\DOCUME~1\Celine\APPLIC~1\Free Download Manager
    [22/05/2009|08:29] C:\DOCUME~1\Celine\APPLIC~1\GetRightToGo
    [11/12/2008|19:18] C:\DOCUME~1\Celine\APPLIC~1\Google
    [13/05/2009|09:30] C:\DOCUME~1\Celine\APPLIC~1\gtk-2.0
    [06/06/2009|23:27] C:\DOCUME~1\Celine\APPLIC~1\Help
    [14/11/2008|15:49] C:\DOCUME~1\Celine\APPLIC~1\Identities
    [09/12/2008|18:07] C:\DOCUME~1\Celine\APPLIC~1\Inkscape
    [14/11/2008|15:54] C:\DOCUME~1\Celine\APPLIC~1\InstallShield
    [02/01/2009|07:17] C:\DOCUME~1\Celine\APPLIC~1\Lavasoft
    [18/12/2008|21:19] C:\DOCUME~1\Celine\APPLIC~1\LimeWire
    [15/11/2008|10:42] C:\DOCUME~1\Celine\APPLIC~1\Macromedia
    [26/12/2008|16:03] C:\DOCUME~1\Celine\APPLIC~1\Malwarebytes
    [25/12/2008|03:29] C:\DOCUME~1\Celine\APPLIC~1\Media Player Classic
    [11/04/2009|16:46] C:\DOCUME~1\Celine\APPLIC~1\Microsoft
    [06/02/2009|09:22] C:\DOCUME~1\Celine\APPLIC~1\Mozilla
    [03/04/2009|08:33] C:\DOCUME~1\Celine\APPLIC~1\MyHeritage
    [14/12/2008|15:26] C:\DOCUME~1\Celine\APPLIC~1\OpenOffice.org
    [06/02/2009|10:16] C:\DOCUME~1\Celine\APPLIC~1\Real
    [11/12/2008|18:28] C:\DOCUME~1\Celine\APPLIC~1\SecondLife
    [20/06/2009|00:11] C:\DOCUME~1\Celine\APPLIC~1\Skype
    [19/06/2009|17:24] C:\DOCUME~1\Celine\APPLIC~1\skypePM
    [11/12/2008|19:37] C:\DOCUME~1\Celine\APPLIC~1\Sphinx
    [09/12/2008|18:10] C:\DOCUME~1\Celine\APPLIC~1\Sun
    [03/04/2009|08:31] C:\DOCUME~1\Celine\APPLIC~1\The Complete Genealogy Reporter - FTB
    [06/02/2009|09:22] C:\DOCUME~1\Celine\APPLIC~1\Thunderbird
    [11/12/2008|23:37] C:\DOCUME~1\Celine\APPLIC~1\Uniblue
    [16/06/2009|08:22] C:\DOCUME~1\Celine\APPLIC~1\vlc
    [09/12/2008|18:09] C:\DOCUME~1\Celine\APPLIC~1\Winamp
    [14/12/2008|15:25] C:\DOCUME~1\Celine\APPLIC~1\WinRAR
    [14/02/2009|13:28] C:\DOCUME~1\Celine\APPLIC~1\Yahoo!

    [14/11/2008|15:45] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft

    [31/12/2008|06:43] C:\DOCUME~1\INVIT~1\APPLIC~1\Adobe
    [31/12/2008|06:43] C:\DOCUME~1\INVIT~1\APPLIC~1\Grisoft
    [31/12/2008|06:42] C:\DOCUME~1\INVIT~1\APPLIC~1\Identities
    [31/12/2008|06:43] C:\DOCUME~1\INVIT~1\APPLIC~1\Macromedia
    [31/12/2008|06:44] C:\DOCUME~1\INVIT~1\APPLIC~1\Microsoft
    [31/12/2008|06:55] C:\DOCUME~1\INVIT~1\APPLIC~1\Mozilla
    [04/01/2009|07:24] C:\DOCUME~1\INVIT~1\APPLIC~1\Winamp
    [04/01/2009|03:21] C:\DOCUME~1\INVIT~1\APPLIC~1\WinRAR

    [09/12/2008|18:04] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft

    [24/12/2008|11:39] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft

    --------------------\\ Tâches planifiées dans C:\WINDOWS\tasks

    [16/06/2009 09:31][--a------] C:\WINDOWS\tasks\AppleSoftwareUpdate.job
    [21/06/2009 02:04][--ah-----] C:\WINDOWS\tasks\SA.DAT
    [14/04/2008 14:00][-r-h-----] C:\WINDOWS\tasks\desktop.ini

    --------------------\\ Listing des dossiers dans C:\Program Files

    [30/01/2009|18:23] C:\Program Files\Adobe
    [15/12/2008|21:43] C:\Program Files\Apple Software Update
    [09/12/2008|18:11] C:\Program Files\AppSnap
    [21/12/2008|10:48] C:\Program Files\AskSearch
    [20/06/2009|16:21] C:\Program Files\a-squared Free
    [09/12/2008|18:00] C:\Program Files\Audacity
    [15/05/2009|17:15] C:\Program Files\Avira
    [11/12/2008|19:01] C:\Program Files\Axialis
    [19/04/2009|19:16] C:\Program Files\BitSpirit
    [12/06/2009|07:21] C:\Program Files\Bonjour
    [09/12/2008|16:45] C:\Program Files\BroadJump
    [21/03/2009|18:12] C:\Program Files\Canal
    [14/02/2009|13:28] C:\Program Files\CCleaner
    [11/12/2008|20:19] C:\Program Files\Cisco Systems
    [09/12/2008|16:47] C:\Program Files\Club-Internet
    [09/12/2008|16:47] C:\Program Files\Common Files
    [14/11/2008|15:43] C:\Program Files\ComPlus Applications
    [25/01/2009|11:51] C:\Program Files\Conduit
    [14/11/2008|15:52] C:\Program Files\DIFX
    [09/12/2008|18:02] C:\Program Files\DVD Shrink
    [15/06/2009|18:03] C:\Program Files\eMule
    [14/03/2009|19:09] C:\Program Files\ex-fumeurs
    [09/12/2008|18:04] C:\Program Files\ffdshow
    [21/06/2009|01:31] C:\Program Files\Fichiers communs
    [27/03/2009|16:36] C:\Program Files\Flary Address
    [30/01/2009|18:02] C:\Program Files\Free Download Manager
    [09/12/2008|18:04] C:\Program Files\Gimp-2.0
    [26/01/2009|23:23] C:\Program Files\Google
    [11/12/2008|19:49] C:\Program Files\Grisoft
    [14/06/2009|12:54] C:\Program Files\Hotspot_Shield
    [09/12/2008|18:06] C:\Program Files\Inkscape
    [03/03/2009|18:17] C:\Program Files\InstallShield Installation Information
    [21/06/2009|02:04] C:\Program Files\Internet Explorer
    [05/06/2009|09:45] C:\Program Files\iPod
    [05/06/2009|09:45] C:\Program Files\iTunes
    [21/06/2009|01:33] C:\Program Files\Java
    [02/01/2009|07:17] C:\Program Files\Lavasoft
    [09/12/2008|18:17] C:\Program Files\MadOnion.com
    [18/06/2009|08:57] C:\Program Files\Malwarebytes' Anti-Malware
    [09/12/2008|18:03] C:\Program Files\Media Player Classic
    [14/11/2008|17:36] C:\Program Files\Messenger
    [17/12/2008|08:01] C:\Program Files\Microsoft
    [14/11/2008|15:45] C:\Program Files\microsoft frontpage
    [14/12/2008|15:34] C:\Program Files\Microsoft Office
    [11/02/2009|10:30] C:\Program Files\Microsoft Office Outlook Connector
    [26/02/2009|07:27] C:\Program Files\Microsoft Silverlight
    [17/12/2008|07:57] C:\Program Files\Microsoft SQL Server Compact Edition
    [17/12/2008|07:59] C:\Program Files\Microsoft Sync Framework
    [11/12/2008|19:05] C:\Program Files\Microsoft.NET
    [09/12/2008|16:47] C:\Program Files\Motive
    [14/11/2008|15:44] C:\Program Files\Movie Maker
    [21/06/2009|02:05] C:\Program Files\Mozilla Firefox
    [11/02/2009|10:33] C:\Program Files\Mozilla Thunderbird
    [27/03/2009|16:36] C:\Program Files\MP3
    [27/03/2009|16:32] C:\Program Files\MP3 Player Utilities 4.00
    [27/03/2009|16:31] C:\Program Files\MP3 Player Utilities 4.04
    [27/01/2009|09:35] C:\Program Files\MSBuild
    [11/02/2009|10:29] C:\Program Files\MSECache
    [14/11/2008|15:42] C:\Program Files\MSN
    [14/11/2008|15:43] C:\Program Files\MSN Gaming Zone
    [14/11/2008|17:36] C:\Program Files\MSXML 4.0
    [03/04/2009|08:35] C:\Program Files\MyHeritage
    [20/06/2009|15:53] C:\Program Files\Navilog1
    [14/11/2008|16:03] C:\Program Files\Nero
    [14/11/2008|15:44] C:\Program Files\NetMeeting
    [21/06/2009|02:05] C:\Program Files\NOS
    [09/12/2008|18:01] C:\Program Files\OpenOffice.org 3
    [14/11/2008|15:44] C:\Program Files\Outlook Express
    [27/01/2009|09:45] C:\Program Files\Paint.NET
    [11/04/2009|16:47] C:\Program Files\PDFCreator
    [09/12/2008|18:06] C:\Program Files\PhotoFiltre
    [10/06/2009|09:53] C:\Program Files\PHPNukeFR
    [09/12/2008|18:06] C:\Program Files\Picasa2
    [05/06/2009|09:43] C:\Program Files\QuickTime
    [06/02/2009|10:14] C:\Program Files\Real
    [11/12/2008|16:47] C:\Program Files\Realtek
    [27/01/2009|09:35] C:\Program Files\Reference Assemblies
    [05/06/2009|09:39] C:\Program Files\Safari
    [24/12/2008|11:14] C:\Program Files\Safer Networking
    [30/12/2008|16:33] C:\Program Files\SecondLife
    [14/11/2008|15:44] C:\Program Files\Services en ligne
    [14/06/2009|08:45] C:\Program Files\Skype
    [09/12/2008|18:02] C:\Program Files\SoftChris
    [20/06/2009|09:08] C:\Program Files\Spybot - Search & Destroy
    [03/02/2009|14:54] C:\Program Files\SpywareBlaster
    [07/05/2009|09:36] C:\Program Files\Steek
    [31/03/2009|13:31] C:\Program Files\Text2PDF v1.5
    [03/04/2009|08:10] C:\Program Files\Tracker Software
    [20/06/2009|15:39] C:\Program Files\trend micro
    [14/11/2008|15:49] C:\Program Files\Uninstall Information
    [03/03/2009|18:17] C:\Program Files\USB Disk Win98 Driver
    [09/12/2008|18:03] C:\Program Files\VideoLAN
    [24/12/2008|19:20] C:\Program Files\Vuze
    [12/06/2009|07:20] C:\Program Files\Winamp
    [21/02/2009|09:23] C:\Program Files\Windows Live
    [17/12/2008|07:55] C:\Program Files\Windows Live SkyDrive
    [17/12/2008|09:22] C:\Program Files\Windows Live Toolbar
    [14/11/2008|17:32] C:\Program Files\Windows Media Connect 2
    [05/06/2009|09:37] C:\Program Files\Windows Media Player
    [14/12/2008|15:33] C:\Program Files\Windows Messaging
    [23/12/2008|11:44] C:\Program Files\Windows NT
    [14/11/2008|15:44] C:\Program Files\WindowsUpdate
    [14/12/2008|15:25] C:\Program Files\WinRAR
    [08/06/2009|10:35] C:\Program Files\WinZip
    [14/11/2008|15:45] C:\Program Files\xerox
    [11/04/2009|20:24] C:\Program Files\Yahoo!
    [05/02/2009|07:48] C:\Program Files\ZebHelpProcess 2

    --------------------\\ Listing des dossiers dans C:\Program Files\Fichiers communs

    [20/04/2009|19:42] C:\Program Files\Fichiers communs\Adobe
    [21/03/2009|18:11] C:\Program Files\Fichiers communs\Adobe AIR
    [14/11/2008|16:05] C:\Program Files\Fichiers communs\Ahead
    [05/06/2009|09:45] C:\Program Files\Fichiers communs\Apple
    [05/02/2009|07:48] C:\Program Files\Fichiers communs\Borland Shared
    [14/12/2008|15:41] C:\Program Files\Fichiers communs\DESIGNER
    [11/12/2008|20:19] C:\Program Files\Fichiers communs\Deterministic Networks
    [09/12/2008|18:16] C:\Program Files\Fichiers communs\InstallShield
    [24/12/2008|19:09] C:\Program Files\Fichiers communs\iS3
    [14/11/2008|16:06] C:\Program Files\Fichiers communs\LightScribe
    [30/01/2009|18:17] C:\Program Files\Fichiers communs\Macrovision Shared
    [15/05/2009|17:14] C:\Program Files\Fichiers communs\Microsoft Shared
    [09/12/2008|16:47] C:\Program Files\Fichiers communs\Motive
    [14/11/2008|15:44] C:\Program Files\Fichiers communs\MSSoap
    [14/11/2008|16:38] C:\Program Files\Fichiers communs\ODBC
    [06/02/2009|10:14] C:\Program Files\Fichiers communs\Real
    [14/11/2008|15:44] C:\Program Files\Fichiers communs\Services
    [14/06/2009|08:45] C:\Program Files\Fichiers communs\Skype
    [14/11/2008|16:38] C:\Program Files\Fichiers communs\SpeechEngines
    [17/12/2008|08:01] C:\Program Files\Fichiers communs\System
    [17/12/2008|07:49] C:\Program Files\Fichiers communs\Windows Live
    [02/01/2009|07:16] C:\Program Files\Fichiers communs\Wise Installation Wizard
    [06/02/2009|10:14] C:\Program Files\Fichiers communs\xing shared

    --------------------\\ Process

    ( 56 Processes )

    ... OK !

    --------------------\\ Recherche avec S_Lop

    Aucun fichier / dossier Lop trouvé !

    --------------------\\ Recherche de Fichiers / Dossiers Lop

    Aucun fichier / dossier Lop trouvé !

    --------------------\\ Verification du Registre

    ..... OK !

    --------------------\\ Verification du fichier Hosts

    Fichier Hosts PROPRE


    --------------------\\ Recherche de fichiers avec Catchme

    catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2009-06-21 02:07:05
    Windows 5.1.2600 Service Pack 3 NTFS
    scanning hidden processes ...
    scanning hidden files ...
    scan completed successfully
    hidden processes: 0
    hidden files: 0

    --------------------\\ Recherche d'autres infections


    Aucune autre infection trouvée !

    [F:69][D:13]-> C:\DOCUME~1\Celine\LOCALS~1\Temp
    [F:15][D:0]-> C:\DOCUME~1\Celine\Cookies
    [F:10][D:4]-> C:\DOCUME~1\Celine\LOCALS~1\TEMPOR~1\content.IE5

    1 - "C:\Lop SD\LopR_1.txt" - 31/03/2009| 7:21 - Option : [1]
    2 - "C:\Lop SD\LopR_2.txt" - 21/06/2009| 1:55 - Option : [1]
    3 - "C:\Lop SD\LopR_3.txt" - 21/06/2009| 2:07 - Option : [2]

    --------------------\\ Fin du rapport a 2:07:37
    a c 327 8 Sécurité
    21 Juin 2009 02:12:23

    Infection Lop supprimée, ça vient du programme BitDownload.

  • Télécharge Ad-Remover (de Cyrildu17 / C_XX) sur ton Bureau.

    /!\ Déconnecte-toi et ferme toutes applications en cours /!\

  • Double-clique sur le programme d'installation, installe-le dans son emplacement par défaut (C:\Program files).
  • Double-clique sur le raccourci d'Ad-Remover situé sur ton Bureau pour le lancer.
    (Sous Vista, il faut cliquer droit sur le raccourci d'Ad-Remover et choisir Exécuter en tant qu'administrateur)
  • Choisis la langue F pour français.
  • Au menu principal, choisis l'option S.

    /!\ Laisse travailler l'outil /!\

  • Poste le rapport qui apparaît à la fin (C:\Ad-Report-SCAN.log).

    (CTRL+A pour tout sélectionner, CTRL+C pour copier et CTRL+V pour coller)

    Note : "Process.exe", une composante de l'outil, est détectée par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool. Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus. Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.
    21 Juin 2009 08:51:32

    Bonjour, le rapport comme prévu

    .
    ======= RAPPORT D'AD-REMOVER 1.1.4.5_L | UNIQUEMENT XP/VISTA/SEVEN =======
    .
    Mit à jour par C_XX le 20/06/2009 à 3:20 PM
    Contact: AdRemover.contact@gmail.com
    Site web: http://pagesperso-orange.fr/NosTools/ad_remover.html
    .
    Lancé à: 8:36:27, 21/06/2009 | Mode Normal | Option: SCAN
    Exécuté de: C:\Program Files\Ad-remover\
    Système d'exploitation: Microsoft® Windows XP™ Service Pack 3 v5.1.2600
    Nom du PC: PEREA-A88DA7661 | Utilisateur actuel: Celine
    .
    Administrateur: Administrateur
    N'est pas administrateur: ASPNET
    Administrateur: Celine
    N'est pas administrateur: HelpAssistant *Desactive*
    N'est pas administrateur: Invité
    N'est pas administrateur: SUPPORT_388945a0 *Desactive*
    .
    ============== ÉLÉMENT(S) TROUVÉ(S) ==============
    .
    .
    HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
    .
    C:\Program Files\AskSearch
    C:\DOCUME~1\Celine\APPLIC~1\Mozilla\Firefox\Profiles\fuj5rmd8.default\searchplugins\ask.xml
    .
    ============== Scan additionnel ==============
    .

    * Mozilla FireFox Version 3.0.11 *

    Nom du profil: fuj5rmd8.default (Celine)
    .
    (Prefs.js) user_pref("browser.search.defaultenginename", "Live Search");
    (Prefs.js) user_pref("browser.search.selectedEngine", "Yahoo");
    (Prefs.js) user_pref("browser.search.defaulturl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2098232&SearchSource=3&q={searchTerms}");
    (Prefs.js) user_pref("browser.startup.homepage", "hxxp://www.google.fr/ig?hl=fr");
    (Prefs.js) user_pref("browser.startup.homepage_override.mstone", "rv:1.9.0.11");
    .
    .

    * Internet Explorer Version 8.0.6001.18702 *

    [HKEY_CURRENT_USER\..\Internet Explorer\Main]

    Default_Search_URL: hxxp://www.google.com/ie
    Search bar: hxxp://www.google.com/ie
    Search Page: hxxp://www.google.com
    Start Page: hxxp://search.myheritage.com

    [HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]

    Default_Page_URL: hxxp://go.microsoft.com/fwlink/?LinkId=69157
    Default_Search_URL: hxxp://go.microsoft.com/fwlink/?LinkId=54896
    Search Page: hxxp://go.microsoft.com/fwlink/?LinkId=54896
    Start Page: hxxp://go.microsoft.com/fwlink/?LinkId=69157

    [HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]

    Tabs: res://ieframe.dll/tabswelcome.htm

    ============== Suspect (Cracks, Serials ... ) ==============

    .
    .
    ===================================
    .
    2365 Octet(s) - C:\Ad-Report-SCAN.log
    .
    67 Fichier(s) - C:\DOCUME~1\Celine\LOCALS~1\Temp
    1 Fichier(s) - C:\WINDOWS\Temp
    .
    1 Fichier(s) - C:\Program Files\Ad-remover\BACKUP
    0 Fichier(s) - C:\Program Files\Ad-remover\QUARANTINE
    .
    Fin à: 8:49:27 | 21/06/2009
    .
    ============== E.O.F ==============
    .
    a c 327 8 Sécurité
    21 Juin 2009 16:08:51

    /!\ Déconnecte-toi et ferme toutes applications en cours /!\

  • Double-clique sur le raccourci d'Ad-Remover pour le lancer.
    (Sous Vista, il faut cliquer droit sur le raccourci d'Ad-Remover et choisir Exécuter en tant qu'administrateur)
  • Choisis la langue F pour français.
  • Au menu principal, choisis l'option L et tape sur [Entrée] pour valider.

    /!\ Laisse travailler l'outil et ne touche à rien /!\

  • Poste le rapport qui apparaît à la fin (C:\Ad-Report-CLEAN.log)

    (CTRL+A Pour tout sélectionner , CTRL+C pour copier et CTRL+V pour coller)

    Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool. Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus. Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.
    21 Juin 2009 16:25:18

    voilà:

    .
    ======= RAPPORT D'AD-REMOVER 1.1.4.5_L | UNIQUEMENT XP/VISTA/SEVEN =======
    .
    Mit à jour par C_XX le 20/06/2009 à 3:20 PM
    Contact: AdRemover.contact@gmail.com
    Site web: http://pagesperso-orange.fr/NosTools/ad_remover.html
    .
    Lancé à: 16:10:28, 21/06/2009 | Mode Normal | Option: CLEAN
    Exécuté de: C:\Program Files\Ad-remover\
    Système d'exploitation: Microsoft® Windows XP™ Service Pack 3 v5.1.2600
    Nom du PC: PEREA-A88DA7661 | Utilisateur actuel: Celine
    .
    Administrateur: Administrateur
    N'est pas administrateur: ASPNET
    Administrateur: Celine
    N'est pas administrateur: HelpAssistant *Desactive*
    N'est pas administrateur: Invité
    N'est pas administrateur: SUPPORT_388945a0 *Desactive*
    .
    ============== ÉLÉMENT(S) NEUTRALISÉ(S) ==============
    .
    .
    HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
    .
    C:\Program Files\AskSearch\bin
    C:\Program Files\AskSearch\bin\DefaultSearch.dll
    C:\Program Files\AskSearch
    C:\DOCUME~1\Celine\APPLIC~1\Mozilla\Firefox\Profiles\fuj5rmd8.default\searchplugins\ask.xml

    (!) -- Fichiers temporaires supprimés.

    .
    ============== Scan additionnel ==============
    .

    * Mozilla FireFox Version 3.0.11 *

    Nom du profil: fuj5rmd8.default (Celine)
    .
    (Prefs.js) user_pref("browser.search.defaultenginename", "Live Search");
    (Prefs.js) user_pref("browser.search.selectedEngine", "Yahoo");
    (Prefs.js) user_pref("browser.search.defaulturl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2098232&SearchSource=3&q={searchTerms}");
    (Prefs.js) user_pref("browser.startup.homepage", "hxxp://www.google.fr/ig?hl=fr");
    (Prefs.js) user_pref("browser.startup.homepage_override.mstone", "rv:1.9.0.11");
    .
    .

    * Internet Explorer Version 8.0.6001.18702 *

    [HKEY_CURRENT_USER\..\Internet Explorer\Main]

    Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnh...
    Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
    Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
    Search Page: hxxp://www.google.com
    Start Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnh...

    [HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]

    Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnh...
    Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
    Search bar: hxxp://search.msn.com/spbasic.htm
    Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
    Start Page: hxxp://fr.msn.com/

    [HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]

    Tabs: res://ieframe.dll/tabswelcome.htm

    ============== Suspect (Cracks, Serials ... ) ==============

    .
    .
    ===================================
    .
    2746 Octet(s) - C:\Ad-Report-CLEAN.log
    2677 Octet(s) - C:\Ad-Report-SCAN.log
    .
    30 Fichier(s) - C:\DOCUME~1\Celine\LOCALS~1\Temp
    1 Fichier(s) - C:\WINDOWS\Temp
    .
    21 Fichier(s) - C:\Program Files\Ad-remover\BACKUP
    2 Fichier(s) - C:\Program Files\Ad-remover\QUARANTINE
    .
    Fin à: 16:23:10 | 21/06/2009
    .
    ============== E.O.F ==============
    .
    a c 327 8 Sécurité
    21 Juin 2009 16:41:26

  • Désinstalle Ad-Remover.

  • Refais un scan RSIT et poste le rapport log.
    21 Juin 2009 16:47:24

    mon rapport chef, héé

    Logfile of random's system information tool 1.06 (written by random/random)
    Run by Celine at 2009-06-21 16:46:22
    Microsoft Windows XP Édition familiale Service Pack 3
    System drive C: has 282 GB (93%) free of 305 GB
    Total RAM: 2046 MB (63% free)

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 16:46:29, on 21/06/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v8.00 (8.00.6001.18702)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Avira\AntiVir Desktop\sched.exe
    C:\Program Files\a-squared Free\a2service.exe
    C:\Program Files\Avira\AntiVir Desktop\avguard.exe
    C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
    C:\Program Files\Windows Live\Family Safety\fsssvc.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
    C:\WINDOWS\system32\wbem\wmiapsrv.exe
    C:\WINDOWS\RTHDCPL.EXE
    C:\Program Files\BroadJump\Client Foundation\CFD.exe
    C:\Program Files\Winamp\winampa.exe
    C:\WINDOWS\UMStor\Res.EXE
    C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
    C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Java\jre6\bin\jusched.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Picasa2\PicasaMediaDetector.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\Program Files\Microsoft Office\Office\OSA.EXE
    C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
    C:\Program Files\Microsoft\Office Live\OfficeLiveSignIn.exe
    C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE
    C:\WINDOWS\explorer.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    C:\Program Files\Windows Live\Contacts\wlcomm.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Documents and Settings\Celine\Bureau\RSIT.exe
    C:\Program Files\trend micro\Celine.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://go.microsoft.com/fwlink/?linkid=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.live.com/sphome.aspx
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;*.local
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
    O2 - BHO: PHPNukeFR Toolbar - {258fe8b8-a13c-4b91-9a0c-c2d3cab8b990} - C:\Program Files\PHPNukeFR\tbPHP1.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
    O2 - BHO: PDF-XChange Viewer IE-Plugin - {C5D07EB6-BBCE-4DAE-ACBB-D13A8D28CB1F} - C:\Program Files\Tracker Software\PDF-XChange Viewer\pdf-viewer\PDFXCviewIEPlugin.dll
    O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
    O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O3 - Toolbar: PHPNukeFR Toolbar - {258fe8b8-a13c-4b91-9a0c-c2d3cab8b990} - C:\Program Files\PHPNukeFR\tbPHP1.dll
    O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
    O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
    O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
    O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
    O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
    O4 - HKLM\..\Run: [USB Storage Toolbox] C:\WINDOWS\UMStor\Res.EXE
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [Family Tree Builder Update] C:\Program Files\MyHeritage\Bin\FTBCheckUpdates.exe
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [RegistryBooster 2 d’Uniblue ] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - HKCU\..\Run: [Uniblue RegistryBooster 2009] C:\Program Files\Uniblue\RegistryBooster\RegistryBooster.exe /S
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O4 - Startup: Démarrage d'Office.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
    O4 - Startup: Ekiga.lnk = C:\Program Files\Ekiga\ekiga.exe
    O4 - Startup: ex-fumeurs.lnk = C:\Program Files\ex-fumeurs\ex-fumeurs.exe
    O4 - Startup: Microsoft Recherche accélérée.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
    O4 - Startup: OpenOffice.org 3.0.lnk.disabled
    O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
    O4 - Global Startup: Docteur Club Internet.lnk.disabled
    O4 - Global Startup: WinZip Quick Pick.lnk.disabled
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O8 - Extra context menu item: Add to AMV Convert Tool... - C:\Program Files\MP3 Player Utilities 4.00\AMVConverter\grab.html
    O8 - Extra context menu item: Add to AMV Converter... - C:\Program Files\MP3 Player Utilities 4.04\AMVConverter\grab.html
    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Program Files\MP3 Player Utilities 4.00\MediaManager\grab.html
    O8 - Extra context menu item: Tout télécharger avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
    O8 - Extra context menu item: Télécharger avec Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
    O8 - Extra context menu item: Télécharger la sélection avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
    O8 - Extra context menu item: Télécharger la vidéo avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlfvideo.htm
    O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
    O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Contro...
    O17 - HKLM\System\CCS\Services\Tcpip\..\{24AB0520-3295-4062-90D6-60FBF4F747A7}: NameServer = 86.64.145.140,84.103.237.140
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
    O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
    O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
    O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
    O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
    O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
    O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
    O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

    --
    End of file - 12781 bytes

    ======Scheduled tasks folder======

    C:\WINDOWS\tasks\AppleSoftwareUpdate.job

    ======Registry dump======

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
    Adobe PDF Link Helper - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{22BF413B-C6D2-4d91-82A9-A0F997BA588C}]
    Skype add-on (mastermind) - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2009-06-02 1082880]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{258fe8b8-a13c-4b91-9a0c-c2d3cab8b990}]
    PHPNukeFR Toolbar - C:\Program Files\PHPNukeFR\tbPHP1.dll [2009-06-10 2094616]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
    Spybot-S&D IE Protection - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll [2009-01-26 1879896]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
    Search Helper - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll [2009-05-19 137600]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
    Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll [2009-05-07 259696]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
    Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll [2009-05-07 668656]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C5D07EB6-BBCE-4DAE-ACBB-D13A8D28CB1F}]
    PDF-XChange Viewer IE-Plugin - C:\Program Files\Tracker Software\PDF-XChange Viewer\pdf-viewer\PDFXCviewIEPlugin.dll [2009-03-30 1092888]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C84D72FE-E17D-4195-BB24-76C02E2E7C4E}]
    Google Dictionary Compression sdch - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll [2009-05-07 470512]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CC59E0F9-7E43-44FA-9FAA-8377850BF205}]
    FDMIECookiesBHO Class - C:\Program Files\Free Download Manager\iefdm2.dll [2008-11-12 94208]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
    Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-06-21 41368]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
    JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-06-21 73728]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    {258fe8b8-a13c-4b91-9a0c-c2d3cab8b990} - PHPNukeFR Toolbar - C:\Program Files\PHPNukeFR\tbPHP1.dll [2009-06-10 2094616]
    {21FA44EF-376D-4D53-9B0F-8A89D3229068} - &Windows Live Toolbar - C:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-02-06 1068904]
    {2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll [2009-05-07 259696]

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    "RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2007-05-10 16342528]
    "nwiz"=nwiz.exe /install []
    "NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2008-05-02 86016]
    "NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2008-05-02 13529088]
    "NeroFilterCheck"=C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe [2007-03-01 153136]
    "BJCFD"=C:\Program Files\BroadJump\Client Foundation\CFD.exe [2003-01-27 376912]
    "Alcmtr"=C:\WINDOWS\ALCMTR.EXE [2005-05-03 69632]
    "WinampAgent"=C:\Program Files\Winamp\winampa.exe [2007-10-10 36352]
    "USB Storage Toolbox"=C:\WINDOWS\UMStor\Res.EXE [2005-09-14 65536]
    "Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-02-27 35696]
    "Family Tree Builder Update"=C:\Program Files\MyHeritage\Bin\FTBCheckUpdates.exe [2009-01-14 113680]
    "TkBellExe"=C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe [2009-02-06 185872]
    "avgnt"=C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [2009-03-02 209153]
    "QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2009-05-26 413696]
    "iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2009-05-30 292136]
    "SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-06-21 148888]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
    "Picasa Media Detector"=C:\Program Files\Picasa2\PicasaMediaDetector.exe [2008-08-21 443968]
    "swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2008-12-15 68856]
    "RegistryBooster 2 d’Uniblue "=C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S []
    "SpybotSD TeaTimer"=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2009-01-26 2144088]
    "Uniblue RegistryBooster 2009"=C:\Program Files\Uniblue\RegistryBooster\RegistryBooster.exe /S []

    C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage
    Cisco Systems VPN Client.lnk - C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
    Docteur Club Internet.lnk.disabled - C:\Program Files\Club-Internet\Dr Club Internet\bin\matcli.exe
    WinZip Quick Pick.lnk.disabled - C:\Program Files\WinZip\WZQKPICK.EXE

    C:\Documents and Settings\Celine\Menu Démarrer\Programmes\Démarrage
    Démarrage d'Office.lnk - C:\Program Files\Microsoft Office\Office\OSA.EXE
    Ekiga.lnk - C:\Program Files\Ekiga\ekiga.exe
    ex-fumeurs.lnk - C:\Program Files\ex-fumeurs\ex-fumeurs.exe
    Microsoft Recherche accélérée.lnk - C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
    OpenOffice.org 3.0.lnk.disabled - C:\Program Files\OpenOffice.org 3\program\quickstart.exe

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
    WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\aawservice]

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
    "dontdisplaylastusername"=0
    "legalnoticecaption"=
    "legalnoticetext"=
    "shutdownwithoutlogon"=1
    "undockwithoutlogon"=1

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
    "NoDriveTypeAutoRun"=145
    "NoDriveAutoRun"=4294967295

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
    "NoDriveTypeAutoRun"=
    "HonorAutoRunSetting"=

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
    "%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
    "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
    "D:\NeroExpress\Installation\Setupx.exe"="D:\NeroExpress\Installation\Setupx.exe:*:Enabled:Nero ProductSetup"
    "C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
    "C:\Program Files\Messenger\msmsgs.exe"="C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger"
    "C:\Program Files\SecondLife\SLVoice.exe"="C:\Program Files\SecondLife\SLVoice.exe:*:D isabled:SLVoice"
    "C:\Program Files\BitDownload\BitDownload.exe"="C:\Program Files\BitDownload\BitDownload.exe:*:Enabled:BitDownload"
    "C:\Program Files\LimeWire\LimeWire.exe"="C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire"
    "C:\Program Files\Vuze\Azureus.exe"="C:\Program Files\Vuze\Azureus.exe:*:Enabled:Azureus"
    "C:\Program Files\eMule\emule.exe"="C:\Program Files\eMule\emule.exe:*:Enabled:eMule"
    "C:\Program Files\Free Download Manager\fdm.exe"="C:\Program Files\Free Download Manager\fdm.exe:*:Enabled:Free Download Manager"
    "DEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~ӟ"="DEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~ӟ:*:Enabled:Nod32 Service"
    "C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
    "C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe"="C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync"
    "C:\Program Files\SecondLife\SecondLife.exe"="C:\Program Files\SecondLife\SecondLife.exe:*:Enabled:Second Life"
    "C:\Program Files\Mozilla Firefox\firefox.exe"="C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox"
    "C:\Program Files\Ekiga\ekiga.exe"="C:\Program Files\Ekiga\ekiga.exe:*:D isabled:ekiga"
    "C:\Python23\pythonw.exe"="C:\Python23\pythonw.exe:*:Enabled:p ythonw"
    "C:\Documents and Settings\Celine\Local Settings\Temp\Rar$EX02.468\eMule0.49c\emule.exe"="C:\Documents and Settings\Celine\Local Settings\Temp\Rar$EX02.468\eMule0.49c\emule.exe:*:Enabled:eMule"
    "C:\Program Files\Fichiers communs\Ahead\Nero Web\SetupX.exe"="C:\Program Files\Fichiers communs\Ahead\Nero Web\SetupX.exe:*:Enabled:Nero ProductSetup"
    "C:\Documents and Settings\Celine\Local Settings\Temp\Nero Web\SetupXu.exe"="C:\Documents and Settings\Celine\Local Settings\Temp\Nero Web\SetupXu.exe:*:Enabled:Nero ProductSetup"
    "C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
    "C:\Program Files\iTunes\iTunes.exe"="C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes"
    "C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
    "%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
    "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
    "C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
    "C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
    "C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe"="C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync"

    ======List of files/folders created in the last 1 months======

    2009-06-21 02:15:49 ----D---- C:\Program Files\Ad-remover
    2009-06-21 01:40:57 ----D---- C:\WINDOWS\ie8updates
    2009-06-21 01:40:35 ----A---- C:\WINDOWS\imsins.BAK
    2009-06-21 01:39:31 ----HDC---- C:\WINDOWS\ie8
    2009-06-21 01:37:32 ----A---- C:\WINDOWS\system32\javaws.exe
    2009-06-21 01:37:32 ----A---- C:\WINDOWS\system32\javaw.exe
    2009-06-21 01:37:32 ----A---- C:\WINDOWS\system32\java.exe
    2009-06-18 09:52:27 ----A---- C:\WINDOWS\msnfix.txt
    2009-06-16 08:22:10 ----D---- C:\Documents and Settings\Celine\Application Data\vlc
    2009-06-16 08:21:52 ----D---- C:\Documents and Settings\Celine\Application Data\dvdcss
    2009-06-16 08:14:46 ----A---- C:\Documents and Settings\All Users\Application Data\vlc-0.9.9-win32.exe
    2009-06-14 12:54:22 ----D---- C:\Program Files\Hotspot_Shield
    2009-06-14 08:45:30 ----D---- C:\Program Files\Fichiers communs\Skype
    2009-06-14 08:45:27 ----RD---- C:\Program Files\Skype
    2009-06-11 09:17:43 ----HDC---- C:\WINDOWS\$NtUninstallKB961501$
    2009-06-11 09:17:37 ----HDC---- C:\WINDOWS\$NtUninstallKB969897$
    2009-06-11 09:17:33 ----HDC---- C:\WINDOWS\$NtUninstallKB969898$
    2009-06-11 09:16:07 ----HDC---- C:\WINDOWS\$NtUninstallKB970238$
    2009-06-11 09:15:41 ----HDC---- C:\WINDOWS\$NtUninstallKB968537$
    2009-06-06 23:27:40 ----D---- C:\Documents and Settings\Celine\Application Data\Help
    2009-06-05 09:45:14 ----D---- C:\Program Files\iPod
    2009-06-05 09:45:12 ----D---- C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
    2009-06-05 09:43:33 ----D---- C:\Program Files\QuickTime
    2009-06-05 09:39:07 ----D---- C:\Program Files\Safari
    2009-05-22 08:28:26 ----D---- C:\Documents and Settings\Celine\Application Data\GetRightToGo

    ======List of files/folders modified in the last 1 months======

    2009-06-21 16:46:25 ----D---- C:\WINDOWS\Prefetch
    2009-06-21 16:46:23 ----D---- C:\Program Files\trend micro
    2009-06-21 16:45:12 ----D---- C:\WINDOWS\Temp
    2009-06-21 16:27:12 ----AH---- C:\WINDOWS\system32\FFASTLOG.TXT
    2009-06-21 16:23:55 ----D---- C:\Program Files\Mozilla Firefox
    2009-06-21 16:22:08 ----RD---- C:\Program Files
    2009-06-21 14:24:55 ----D---- C:\WINDOWS\system32\CatRoot2
    2009-06-21 14:23:44 ----A---- C:\WINDOWS\SchedLgU.Txt
    2009-06-21 12:57:58 ----D---- C:\Program Files\eMule
    2009-06-21 12:37:43 ----D---- C:\WINDOWS\system32
    2009-06-21 08:45:35 ----A---- C:\WINDOWS\NeroDigital.ini
    2009-06-21 02:13:13 ----D---- C:\Downloads
    2009-06-21 02:12:15 ----D---- C:\Documents and Settings\All Users\Application Data\NOS
    2009-06-21 02:07:37 ----D---- C:\Lop SD
    2009-06-21 02:07:37 ----A---- C:\lopR.txt
    2009-06-21 02:06:25 ----SD---- C:\WINDOWS\Tasks
    2009-06-21 02:05:10 ----D---- C:\Program Files\NOS
    2009-06-21 02:04:44 ----D---- C:\WINDOWS
    2009-06-21 02:04:20 ----RSHDC---- C:\WINDOWS\system32\dllcache
    2009-06-21 02:04:20 ----D---- C:\WINDOWS\system32\fr-fr
    2009-06-21 02:04:20 ----D---- C:\WINDOWS\Help
    2009-06-21 02:04:20 ----D---- C:\Program Files\Internet Explorer
    2009-06-21 01:54:52 ----HD---- C:\WINDOWS\inf
    2009-06-21 01:54:50 ----D---- C:\WINDOWS\system32\CatRoot
    2009-06-21 01:41:00 ----HD---- C:\WINDOWS\$hf_mig$
    2009-06-21 01:40:27 ----D---- C:\WINDOWS\WBEM
    2009-06-21 01:40:22 ----D---- C:\WINDOWS\Media
    2009-06-21 01:37:43 ----SHD---- C:\WINDOWS\Installer
    2009-06-21 01:37:18 ----A---- C:\WINDOWS\system32\deploytk.dll
    2009-06-21 01:33:03 ----D---- C:\Program Files\Java
    2009-06-21 01:31:30 ----D---- C:\Program Files\Fichiers communs
    2009-06-21 01:29:45 ----D---- C:\WINDOWS\WinSxS
    2009-06-21 01:24:07 ----D---- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
    2009-06-20 16:21:47 ----D---- C:\Program Files\a-squared Free
    2009-06-20 15:53:11 ----D---- C:\Program Files\Navilog1
    2009-06-20 09:08:21 ----D---- C:\Program Files\Spybot - Search & Destroy
    2009-06-20 08:31:19 ----D---- C:\WINDOWS\Debug
    2009-06-20 00:11:03 ----D---- C:\Documents and Settings\Celine\Application Data\Skype
    2009-06-19 17:24:41 ----D---- C:\Documents and Settings\Celine\Application Data\skypePM
    2009-06-19 07:41:16 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
    2009-06-18 09:51:33 ----D---- C:\unzipped
    2009-06-18 08:57:34 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
    2009-06-18 08:57:31 ----D---- C:\WINDOWS\system32\drivers
    2009-06-18 08:46:16 ----D---- C:\WINDOWS\Minidump
    2009-06-16 08:20:49 ----DC---- C:\WINDOWS\system32\DRVSTORE
    2009-06-16 08:19:24 ----D---- C:\Python23
    2009-06-15 10:53:43 ----SHD---- C:\System Volume Information
    2009-06-15 10:49:54 ----D---- C:\WINDOWS\repair
    2009-06-15 10:49:49 ----D---- C:\WINDOWS\Registration
    2009-06-14 08:45:30 ----D---- C:\Documents and Settings\All Users\Application Data\Skype
    2009-06-12 07:21:25 ----D---- C:\Program Files\Bonjour
    2009-06-12 07:20:59 ----D---- C:\Program Files\Winamp
    2009-06-11 09:18:14 ----A---- C:\WINDOWS\win.ini
    2009-06-10 09:53:45 ----D---- C:\Program Files\PHPNukeFR
    2009-06-08 10:35:03 ----D---- C:\Program Files\WinZip
    2009-06-05 09:45:30 ----D---- C:\Program Files\iTunes
    2009-06-05 09:45:13 ----D---- C:\Program Files\Fichiers communs\Apple
    2009-06-05 09:37:46 ----D---- C:\Program Files\Windows Media Player
    2009-06-01 09:51:14 ----A---- C:\WINDOWS\system32\MRT.exe

    ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

    R1 AmdK8;Pilote de processeur AMD; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2006-06-19 43520]
    R1 avgio;avgio; \??\C:\Program Files\Avira\AntiVir Desktop\avgio.sys []
    R1 avipbb;avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [2009-03-30 96104]
    R1 ssmdrv;ssmdrv; C:\WINDOWS\system32\DRIVERS\ssmdrv.sys [2009-02-13 28376]
    R2 avgntflt;avgntflt; C:\WINDOWS\system32\DRIVERS\avgntflt.sys [2009-03-24 55640]
    R2 CVPNDRVA;Cisco Systems IPsec Driver; \??\C:\WINDOWS\system32\Drivers\CVPNDRVA.sys []
    R2 fssfltr;FssFltr; C:\WINDOWS\system32\DRIVERS\fssfltr_tdi.sys [2008-12-08 55136]
    R3 DNE;Deterministic Network Enhancer Miniport; C:\WINDOWS\system32\DRIVERS\dne2000.sys [2007-01-24 127376]
    R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys [2009-03-19 23400]
    R3 HDAudBus;Pilote de bus Microsoft UAA pour High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-14 144384]
    R3 hidusb;Pilote de classe HID Microsoft; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
    R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2007-05-10 4419584]
    R3 mouhid;Pilote HID de souris; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2008-04-14 12288]
    R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2008-05-02 6554496]
    R3 RTL8023xp;Realtek 10/100/1000 PCI NIC Family NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtnicxp.sys [2006-12-14 85120]
    R3 usbehci;Pilote miniport de contrôleur d'hôte amélioré Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-14 30208]
    R3 usbhub;Concentrateur USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-14 59520]
    R3 usbohci;Pilote miniport de contrôleur hôte ouvert USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbohci.sys [2008-04-14 17152]
    R3 usbprint;Classe d'imprimantes USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
    R3 USBSTOR;Pilote de stockage de masse USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
    S3 catchme;catchme; \??\C:\DOCUME~1\Celine\LOCALS~1\Temp\catchme.sys []
    S3 CVirtA;Cisco Systems VPN Adapter; C:\WINDOWS\system32\DRIVERS\CVirtA.sys [2007-01-18 5275]
    S3 gdrv;gdrv; \??\C:\WINDOWS\gdrv.sys []
    S3 ICDSX;Sony IC Recorder (SX); C:\WINDOWS\System32\Drivers\ICDSX.sys [2003-10-01 31744]
    S3 MRENDIS5;MRENDIS5 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS []
    S3 tapvpn;TAP VPN Adapter; C:\WINDOWS\system32\DRIVERS\tapvpn.sys [2006-10-26 27136]
    S3 vsdatant;vsdatant; \??\C:\WINDOWS\system32\vsdatant.sys []
    S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
    S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
    S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
    S4 WS2IFSL;Environnement de prise en charge de Fournisseur de services non-IFS Windows Sockets 2.0; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2008-04-14 12032]

    ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

    R2 a2free;a-squared Free Service; C:\Program Files\a-squared Free\a2service.exe [2009-06-12 718880]
    R2 aawservice;Lavasoft Ad-Aware Service; C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe [2009-01-02 611664]
    R2 AntiVirSchedulerService;Avira AntiVir Planificateur; C:\Program Files\Avira\AntiVir Desktop\sched.exe [2009-04-01 108289]
    R2 AntiVirService;Avira AntiVir Guard; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [2009-03-02 185089]
    R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2009-05-29 144712]
    R2 Bonjour Service;Service Bonjour; C:\Program Files\Bonjour\mDNSResponder.exe [2008-12-12 238888]
    R2 CVPND;Cisco Systems, Inc. VPN Service; C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe [2007-07-16 1524512]
    R2 fsssvc;Windows Live Contrôle parental; C:\Program Files\Windows Live\Family Safety\fsssvc.exe [2009-02-06 533360]
    R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-06-21 152984]
    R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe [2008-01-24 73728]
    R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2008-05-02 159812]
    R2 SeaPort;SeaPort; C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-05-19 240512]
    R3 iPod Service;Service de l’iPod; C:\Program Files\iPod\bin\iPodService.exe [2009-05-30 541992]
    S3 aspnet_state;Service d'état ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
    S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
    S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2009-01-30 654848]
    S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
    S3 getPlus(R) Helper;getPlus(R) Helper; C:\Program Files\NOS\bin\getPlus_HelperSvc.exe [2009-06-04 66048]
    S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-05-07 182768]
    S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
    S3 NBService;NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2007-11-28 800040]
    S3 ose;Office Source Engine; C:\Program Files\Fichiers communs\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
    S3 WMPNetworkSvc;Service Partage réseau du Lecteur Windows Media; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-11-03 918016]
    S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
    S4 NetTcpPortSharing;Service de partage de ports Net.Tcp; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
    S4 NMIndexingService;NMIndexingService; C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe [2007-06-27 279848]

    -----------------EOF-----------------
    a c 327 8 Sécurité
    21 Juin 2009 16:55:57

  • Télécharge OTM (OldTimer) sur ton Bureau.
  • Double-clique sur OTM.exe afin de le lancer.
  • Copie (Ctrl+C) le texte suivant ci-dessous :

    :processes
    explorer.exe
    TeaTimer.exe

    :files
    C:\Program Files\BitDownload

    :reg
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]
    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
    "C:\Program Files\BitDownload\BitDownload.exe"=-

    :commands
    [purity]
    [emptytemp]
    [reboot]

  • Colle (Ctrl+V) le texte précédemment copié dans le cadre Paste Instructions for Items to be Moved.
  • Clique maintenant sur le bouton MoveIt! puis ferme OTM.

    ---> Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
    Accepte en cliquant sur YES.

  • Poste le rapport situé dans ce dossier : C:\_OTM\MovedFiles\
    ---> Le nom du rapport correspond au moment de sa création : date_heure.log
    21 Juin 2009 17:02:49

    y voilà:

    ========== PROCESSES ==========
    Process explorer.exe killed successfully.
    Process TeaTimer.exe killed successfully.
    ========== FILES ==========
    File/Folder C:\Program Files\BitDownload not found.
    ========== REGISTRY ==========
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\\ deleted successfully.
    Registry value HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list\\C:\Program Files\BitDownload\BitDownload.exe deleted successfully.
    ========== COMMANDS ==========
    File delete failed. C:\DOCUME~1\Celine\LOCALS~1\Temp\VBE\MSForms.exd scheduled to be deleted on reboot.
    File delete failed. C:\DOCUME~1\Celine\LOCALS~1\Temp\VBE\RefEdit.exd scheduled to be deleted on reboot.
    File delete failed. C:\DOCUME~1\Celine\LOCALS~1\Temp\etilqs_SyqaGezjGQgo4CAxD8bs scheduled to be deleted on reboot.
    File delete failed. C:\DOCUME~1\Celine\LOCALS~1\Temp\~DF1585.tmp scheduled to be deleted on reboot.
    File delete failed. C:\DOCUME~1\Celine\LOCALS~1\Temp\~DF1F77.tmp scheduled to be deleted on reboot.
    File delete failed. C:\DOCUME~1\Celine\LOCALS~1\Temp\~DF20E3.tmp scheduled to be deleted on reboot.
    File delete failed. C:\DOCUME~1\Celine\LOCALS~1\Temp\~DF2DC.tmp scheduled to be deleted on reboot.
    File delete failed. C:\DOCUME~1\Celine\LOCALS~1\Temp\~DF42E4.tmp scheduled to be deleted on reboot.
    File delete failed. C:\DOCUME~1\Celine\LOCALS~1\Temp\~DF4E07.tmp scheduled to be deleted on reboot.
    File delete failed. C:\DOCUME~1\Celine\LOCALS~1\Temp\~DF4FA2.tmp scheduled to be deleted on reboot.
    File delete failed. C:\DOCUME~1\Celine\LOCALS~1\Temp\~DF516D.tmp scheduled to be deleted on reboot.
    File delete failed. C:\DOCUME~1\Celine\LOCALS~1\Temp\~DF7155.tmp scheduled to be deleted on reboot.
    File delete failed. C:\DOCUME~1\Celine\LOCALS~1\Temp\~DF7BDB.tmp scheduled to be deleted on reboot.
    File delete failed. C:\DOCUME~1\Celine\LOCALS~1\Temp\~DF7BFF.tmp scheduled to be deleted on reboot.
    File delete failed. C:\DOCUME~1\Celine\LOCALS~1\Temp\~DF8AE1.tmp scheduled to be deleted on reboot.
    File delete failed. C:\DOCUME~1\Celine\LOCALS~1\Temp\~DF92A4.tmp scheduled to be deleted on reboot.
    File delete failed. C:\DOCUME~1\Celine\LOCALS~1\Temp\~DF9807.tmp scheduled to be deleted on reboot.
    File delete failed. C:\DOCUME~1\Celine\LOCALS~1\Temp\~DF9AAE.tmp scheduled to be deleted on reboot.
    File delete failed. C:\DOCUME~1\Celine\LOCALS~1\Temp\~DFC848.tmp scheduled to be deleted on reboot.
    File delete failed. C:\DOCUME~1\Celine\LOCALS~1\Temp\~DFC86D.tmp scheduled to be deleted on reboot.
    File delete failed. C:\DOCUME~1\Celine\LOCALS~1\Temp\~DFD1D8.tmp scheduled to be deleted on reboot.
    File delete failed. C:\DOCUME~1\Celine\LOCALS~1\Temp\~DFD304.tmp scheduled to be deleted on reboot.
    File delete failed. C:\DOCUME~1\Celine\LOCALS~1\Temp\~DFD5B6.tmp scheduled to be deleted on reboot.
    File delete failed. C:\DOCUME~1\Celine\LOCALS~1\Temp\~DFD839.tmp scheduled to be deleted on reboot.
    File delete failed. C:\DOCUME~1\Celine\LOCALS~1\Temp\~DFE168.tmp scheduled to be deleted on reboot.
    File delete failed. C:\DOCUME~1\Celine\LOCALS~1\Temp\~DFF3FA.tmp scheduled to be deleted on reboot.
    File delete failed. C:\DOCUME~1\Celine\LOCALS~1\Temp\~DFF659.tmp scheduled to be deleted on reboot.
    File delete failed. C:\DOCUME~1\Celine\LOCALS~1\Temp\~DFF91A.tmp scheduled to be deleted on reboot.
    User's Temp folder emptied.
    User's Internet Explorer cache folder emptied.
    File delete failed. C:\Documents and Settings\Celine\Local Settings\Temporary Internet Files\Content.Word\~WRF0001.tmp scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\Celine\Local Settings\Temporary Internet Files\Content.Word\~WRS0000.tmp scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\Celine\Local Settings\Temporary Internet Files\Content.MSO\277F1FCC.emf scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\Celine\Local Settings\Temporary Internet Files\Content.MSO\53613F37.emf scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\Celine\Local Settings\Temporary Internet Files\Content.MSO\756E1BBB.emf scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\Celine\Local Settings\Temporary Internet Files\Content.MSO\7AD0348E.emf scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\Celine\Local Settings\Temporary Internet Files\Content.MSO\8AE6EA80.emf scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\Celine\Local Settings\Temporary Internet Files\Content.MSO\90B93C73.emf scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\Celine\Local Settings\Temporary Internet Files\Content.MSO\AA43A1F9.emf scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\Celine\Local Settings\Temporary Internet Files\Content.MSO\B12B3BA.emf scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\Celine\Local Settings\Temporary Internet Files\Content.MSO\C30BE55D.emf scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\Celine\Local Settings\Temporary Internet Files\Content.MSO\EB8E3D8.emf scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\Celine\Local Settings\Temporary Internet Files\Content.MSO\F5A8E881.emf scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\Celine\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
    User's Temporary Internet Files folder emptied.
    Local Service Temp folder emptied.
    File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
    Local Service Temporary Internet Files folder emptied.
    Network Service Temp folder emptied.
    Network Service Temporary Internet Files folder emptied.
    File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_378.dat scheduled to be deleted on reboot.
    Windows Temp folder emptied.
    Java cache emptied.
    File delete failed. C:\Documents and Settings\Celine\Local Settings\Application Data\Mozilla\Firefox\Profiles\fuj5rmd8.default\Cache\_CACHE_001_ scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\Celine\Local Settings\Application Data\Mozilla\Firefox\Profiles\fuj5rmd8.default\Cache\_CACHE_002_ scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\Celine\Local Settings\Application Data\Mozilla\Firefox\Profiles\fuj5rmd8.default\Cache\_CACHE_003_ scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\Celine\Local Settings\Application Data\Mozilla\Firefox\Profiles\fuj5rmd8.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\Celine\Local Settings\Application Data\Mozilla\Firefox\Profiles\fuj5rmd8.default\urlclassifier3.sqlite scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\Celine\Local Settings\Application Data\Mozilla\Firefox\Profiles\fuj5rmd8.default\XUL.mfl scheduled to be deleted on reboot.
    FireFox cache emptied.
    Temp folders emptied.

    OTM by OldTimer - Version 2.1.0.1 log created on 06212009_165821

    Files moved on Reboot...
    C:\DOCUME~1\Celine\LOCALS~1\Temp\VBE\MSForms.exd moved successfully.
    C:\DOCUME~1\Celine\LOCALS~1\Temp\VBE\RefEdit.exd moved successfully.
    File C:\DOCUME~1\Celine\LOCALS~1\Temp\etilqs_SyqaGezjGQgo4CAxD8bs not found!
    File C:\DOCUME~1\Celine\LOCALS~1\Temp\~DF1585.tmp not found!
    File C:\DOCUME~1\Celine\LOCALS~1\Temp\~DF1F77.tmp not found!
    File C:\DOCUME~1\Celine\LOCALS~1\Temp\~DF20E3.tmp not found!
    File C:\DOCUME~1\Celine\LOCALS~1\Temp\~DF2DC.tmp not found!
    File C:\DOCUME~1\Celine\LOCALS~1\Temp\~DF42E4.tmp not found!
    File C:\DOCUME~1\Celine\LOCALS~1\Temp\~DF4E07.tmp not found!
    File C:\DOCUME~1\Celine\LOCALS~1\Temp\~DF4FA2.tmp not found!
    File C:\DOCUME~1\Celine\LOCALS~1\Temp\~DF516D.tmp not found!
    File C:\DOCUME~1\Celine\LOCALS~1\Temp\~DF7155.tmp not found!
    File C:\DOCUME~1\Celine\LOCALS~1\Temp\~DF7BDB.tmp not found!
    File C:\DOCUME~1\Celine\LOCALS~1\Temp\~DF7BFF.tmp not found!
    File C:\DOCUME~1\Celine\LOCALS~1\Temp\~DF8AE1.tmp not found!
    File C:\DOCUME~1\Celine\LOCALS~1\Temp\~DF92A4.tmp not found!
    File C:\DOCUME~1\Celine\LOCALS~1\Temp\~DF9807.tmp not found!
    File C:\DOCUME~1\Celine\LOCALS~1\Temp\~DF9AAE.tmp not found!
    File C:\DOCUME~1\Celine\LOCALS~1\Temp\~DFC848.tmp not found!
    File C:\DOCUME~1\Celine\LOCALS~1\Temp\~DFC86D.tmp not found!
    File C:\DOCUME~1\Celine\LOCALS~1\Temp\~DFD1D8.tmp not found!
    File C:\DOCUME~1\Celine\LOCALS~1\Temp\~DFD304.tmp not found!
    File C:\DOCUME~1\Celine\LOCALS~1\Temp\~DFD5B6.tmp not found!
    File C:\DOCUME~1\Celine\LOCALS~1\Temp\~DFD839.tmp not found!
    File C:\DOCUME~1\Celine\LOCALS~1\Temp\~DFE168.tmp not found!
    File C:\DOCUME~1\Celine\LOCALS~1\Temp\~DFF3FA.tmp not found!
    File C:\DOCUME~1\Celine\LOCALS~1\Temp\~DFF659.tmp not found!
    File C:\DOCUME~1\Celine\LOCALS~1\Temp\~DFF91A.tmp not found!
    File C:\Documents and Settings\Celine\Local Settings\Temporary Internet Files\Content.Word\~WRF0001.tmp not found!
    File C:\Documents and Settings\Celine\Local Settings\Temporary Internet Files\Content.Word\~WRS0000.tmp not found!
    File C:\Documents and Settings\Celine\Local Settings\Temporary Internet Files\Content.MSO\277F1FCC.emf not found!
    File C:\Documents and Settings\Celine\Local Settings\Temporary Internet Files\Content.MSO\53613F37.emf not found!
    File C:\Documents and Settings\Celine\Local Settings\Temporary Internet Files\Content.MSO\756E1BBB.emf not found!
    File C:\Documents and Settings\Celine\Local Settings\Temporary Internet Files\Content.MSO\7AD0348E.emf not found!
    File C:\Documents and Settings\Celine\Local Settings\Temporary Internet Files\Content.MSO\8AE6EA80.emf not found!
    File C:\Documents and Settings\Celine\Local Settings\Temporary Internet Files\Content.MSO\90B93C73.emf not found!
    File C:\Documents and Settings\Celine\Local Settings\Temporary Internet Files\Content.MSO\AA43A1F9.emf not found!
    File C:\Documents and Settings\Celine\Local Settings\Temporary Internet Files\Content.MSO\B12B3BA.emf not found!
    File C:\Documents and Settings\Celine\Local Settings\Temporary Internet Files\Content.MSO\C30BE55D.emf not found!
    File C:\Documents and Settings\Celine\Local Settings\Temporary Internet Files\Content.MSO\EB8E3D8.emf not found!
    File C:\Documents and Settings\Celine\Local Settings\Temporary Internet Files\Content.MSO\F5A8E881.emf not found!
    File C:\WINDOWS\temp\Perflib_Perfdata_378.dat not found!
    C:\Documents and Settings\Celine\Local Settings\Application Data\Mozilla\Firefox\Profiles\fuj5rmd8.default\Cache\_CACHE_001_ moved successfully.
    C:\Documents and Settings\Celine\Local Settings\Application Data\Mozilla\Firefox\Profiles\fuj5rmd8.default\Cache\_CACHE_002_ moved successfully.
    C:\Documents and Settings\Celine\Local Settings\Application Data\Mozilla\Firefox\Profiles\fuj5rmd8.default\Cache\_CACHE_003_ moved successfully.
    C:\Documents and Settings\Celine\Local Settings\Application Data\Mozilla\Firefox\Profiles\fuj5rmd8.default\Cache\_CACHE_MAP_ moved successfully.
    C:\Documents and Settings\Celine\Local Settings\Application Data\Mozilla\Firefox\Profiles\fuj5rmd8.default\urlclassifier3.sqlite moved successfully.
    C:\Documents and Settings\Celine\Local Settings\Application Data\Mozilla\Firefox\Profiles\fuj5rmd8.default\XUL.mfl moved successfully.

    Registry entries deleted on Reboot...
    a c 327 8 Sécurité
    21 Juin 2009 17:04:28

    Pas de souci ?
    21 Juin 2009 17:18:32

    et bien je dirai que tout va bien..
    Merci beaucoup pour la mobilisation de tes compétences impressionnantes en la matière.
    a c 327 8 Sécurité
    21 Juin 2009 17:22:36

    1/

  • Désinstalle HijackThis.

  • Télécharge ToolsCleaner2 sur ton Bureau.
  • Double-clique sur ToolsCleaner2.exe pour le lancer.
  • Clique sur Recherche et laisse le scan agir.
  • Clique sur Suppression pour finaliser.
  • Tu peux, si tu le souhaites, te servir des Options Facultatives.
  • Clique sur Quitter pour obtenir le rapport.
  • Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\).


    2/

  • Télécharge et installe CCleaner Slim.
  • Lance-le. Va dans Options puis Avancé et décoche la case Effacer uniquement les fichiers etc....
  • Va dans Nettoyeur, choisis Analyser. Une fois terminé, lance le nettoyage.


    3/

  • Il est nécessaire de désactiver puis réactiver la restauration système pour la purger.


    ==Prévention==

    Supprimer les popups d'Antivir : Lien

    Conserve MBAM. Il te servira à scanner les fichiers douteux en complément de l'antivirus et scanne le disque dur régulièrement.

    Par rapport au P2P : Lien

    Voici un dossier complet (A lire avec Adobe Reader ou Foxit Reader) : Lien


    ==Problème résolu ?==

    Si tu estimes que ton problème est résolu :

    ---> Ajoute maintenant [Résolu] au titre. Pour cela :
  • Clique, dans ton premier message, sur le bouton Editer .
  • Rajoute la mention [Résolu] devant le titre.
  • Clique ensuite sur Valider votre message.


    Sois plus vigilant(e) sur Internet ;) 
    21 Juin 2009 17:30:25

    Comment s'est arrivé?

    [ Rapport ToolsCleaner version 2.3.6 (par A.Rothstein & dj QUIOU) ]

    --> Recherche:

    C:\fixnavi.txt: trouvé !
    C:\cleannavi.txt: trouvé !
    C:\lopR.txt: trouvé !
    C:\TB.txt: trouvé !
    C:\Lop SD: trouvé !
    C:\!Killbox: trouvé !
    C:\_OTM: trouvé !
    C:\Toolbar SD: trouvé !
    C:\Rsit: trouvé !
    C:\Documents and Settings\Celine\Bureau\LopSD.exe: trouvé !
    C:\Documents and Settings\Celine\Bureau\OTM.exe: trouvé !
    C:\Documents and Settings\Celine\Bureau\Rsit.exe: trouvé !
    C:\Documents and Settings\Celine\Recent\MSNFix.lnk: trouvé !
    C:\Program Files\Navilog1: trouvé !
    C:\Program Files\Ad-remover: trouvé !
    C:\Program Files\Ad-remover\BACKUP\Ad-R.exe: trouvé !
    C:\Program Files\trend micro\HijackThis.exe: trouvé !
    C:\Program Files\trend micro\hijackthis.log: trouvé !
    C:\unzipped\MsnFix: trouvé !
    C:\unzipped\MSNFix\MsnFix: trouvé !
    C:\WINDOWS\msnfix.txt: trouvé !

    ---------------------------------
    --> Suppression:

    C:\Documents and Settings\Celine\Bureau\LopSD.exe: supprimé !
    C:\Documents and Settings\Celine\Bureau\OTM.exe: supprimé !
    C:\Documents and Settings\Celine\Recent\MSNFix.lnk: supprimé !
    C:\Program Files\Ad-remover\BACKUP\Ad-R.exe: supprimé !
    C:\Program Files\trend micro\HijackThis.exe: supprimé !
    C:\fixnavi.txt: supprimé !
    C:\cleannavi.txt: supprimé !
    C:\lopR.txt: supprimé !
    C:\TB.txt: supprimé !
    C:\Documents and Settings\Celine\Bureau\Rsit.exe: supprimé !
    C:\Program Files\trend micro\hijackthis.log: supprimé !
    C:\WINDOWS\msnfix.txt: supprimé !
    C:\Lop SD: supprimé !
    C:\!Killbox: supprimé !
    C:\_OTM: supprimé !
    C:\Toolbar SD: supprimé !
    C:\Rsit: supprimé !
    C:\Program Files\Navilog1: supprimé !
    C:\Program Files\Ad-remover: supprimé !
    C:\unzipped\MsnFix: supprimé !
    a c 327 8 Sécurité
    21 Juin 2009 17:31:52

    Tu peux supprimer ToolsCleaner.
    21 Juin 2009 17:39:01

    oki merci encore
    tchussy
    a c 327 8 Sécurité
    21 Juin 2009 17:39:21

    Bonne fin de journée ;) 
    Tom's guide dans le monde
    • Allemagne
    • Italie
    • Irlande
    • Royaume Uni
    • Etats Unis
    Suivre Tom's Guide
    Inscrivez-vous à la Newsletter
    • ajouter à twitter
    • ajouter à facebook
    • ajouter un flux RSS