Se connecter / S'enregistrer
Votre question

[Résolu]Probleme de pub

Tags :
  • Internet Explorer
  • Sécurité
Dernière réponse : dans Sécurité et virus
8 Mars 2009 21:29:44

bonjour voila mon probleme est que des que je vais sur internet avec internet explorer j'ai une tonne de pub qui apparaisse et c'est assez chiant . Comment faire pour les enlever ?? merci


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:24:31, on 08/03/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\DellTPad\Apoint.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Download Manager\IDMan.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\DellTPad\Apntex.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\SigmaTel\C-Major Audio\DellXPM_5515v133\WDM\STacSV.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Internet Download Manager\IEMonitor.exe
C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Athan\Athan.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\MOUNIR\Mes documents\Downloads\Programs\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://login.live.com/ppsecure/sha1auth.srf?lc=1036
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: IDMIEHlprObj Class - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\stsystra.exe
O4 - HKLM\..\Run: [clock drv coal bird] C:\Documents and Settings\All Users\Application Data\book this clock drv\Idol name.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Athan] C:\Program Files\Athan\Athan.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot
O4 - HKCU\..\Run: [LongSlow] C:\DOCUME~1\MOUNIR\APPLIC~1\MESSAI~1\POP SAFE ANTE.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: BTTray.lnk = ?
O8 - Extra context menu item: Envoyer au périphérique &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Télécharger avec IDM - C:\Program Files\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: Télécharger le contenu de video FLV avec IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm
O8 - Extra context menu item: Télécharger tous les liens avec IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/fl...
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Program Files\SigmaTel\C-Major Audio\DellXPM_5515v133\WDM\STacSV.exe
O23 - Service: Intel(R) PROSet/Wireless SSO Service (WLANKEEPER) - Intel(R) Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

--
End of file - 9221 bytes

Autres pages sur : resolu probleme pub

a c 267 8 Sécurité
a b , Internet Explorer
8 Mars 2009 21:41:28

Salut,

Tu as une infection Lop.

Je vais te poster une procédure.
8 Mars 2009 21:44:14

merci
Contenus similaires
a c 267 8 Sécurité
a b , Internet Explorer
8 Mars 2009 21:44:41

  • Télécharge Lop S&D sur ton Bureau.
  • Double-clique dessus pour lancer l'installation.
  • Puis double-clique sur le raccourci Lop S&D présent sur ton Bureau.
    (Sous Vista, il faut cliquer droit sur Lop S&D et choisir Exécuter en tant qu'administrateur)
  • Sélectionne la langue souhaitée, puis choisis l'option 1 (Recherche) .
  • Patiente jusqu'à la fin du scan.
  • Poste le rapport généré (C:\lopR.txt).
    8 Mars 2009 21:56:23


    --------------------\\ Lop S&D 4.2.5-0 XP/Vista

    Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 3
    X86-based PC ( Multiprocessor Free : Intel(R) Core(TM)2 Duo CPU T5450 @ 1.66GHz )
    BIOS : Phoenix ROM BIOS PLUS Version 1.10 A16
    USER : admin ( Administrator )
    BOOT : Normal boot
    Antivirus : avast! antivirus 4.8.1335 [VPS 090307-0] 4.8.1335 (Activated)
    C:\ (Local Disk) - NTFS - Total:19 Go (Free:10 Go)
    D:\ (Local Disk) - NTFS - Total:97 Go (Free:58 Go)
    E:\ (Local Disk) - NTFS - Total:115 Go (Free:85 Go)
    F:\ (CD or DVD)

    "C:\Lop SD" ( MAJ : 19-12-2008|23:40 )
    Option : [1] ( 08/03/2009|21:52 )

    --------------------\\ Listing des dossiers dans APPLIC~1

    [02/03/2009|19:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
    [23/02/2009|19:35] C:\DOCUME~1\ALLUSE~1\APPLIC~1\book this clock drv
    [26/02/2009|21:44] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
    [23/02/2009|18:49] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Intel
    [06/03/2009|19:39] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Malwarebytes
    [02/03/2009|19:15] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
    [23/02/2009|21:41] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Office Genuine Advantage
    [23/02/2009|19:46] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Skype
    [23/02/2009|21:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
    [23/02/2009|20:52] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
    [08/03/2009|20:25] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Yahoo! Companion

    [23/02/2009|18:50] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Intel
    [23/02/2009|18:28] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft

    [23/02/2009|18:50] C:\DOCUME~1\LOCALS~1\APPLIC~1\Intel
    [23/02/2009|18:28] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft

    [02/03/2009|19:30] C:\DOCUME~1\MOUNIR\APPLIC~1\Adobe
    [08/03/2009|19:48] C:\DOCUME~1\MOUNIR\APPLIC~1\DMCache
    [04/03/2009|22:38] C:\DOCUME~1\MOUNIR\APPLIC~1\dvdcss
    [26/02/2009|21:47] C:\DOCUME~1\MOUNIR\APPLIC~1\Google
    [23/02/2009|18:33] C:\DOCUME~1\MOUNIR\APPLIC~1\Identities
    [23/02/2009|19:41] C:\DOCUME~1\MOUNIR\APPLIC~1\IDM
    [23/02/2009|20:44] C:\DOCUME~1\MOUNIR\APPLIC~1\InstallShield
    [23/02/2009|18:50] C:\DOCUME~1\MOUNIR\APPLIC~1\Intel
    [23/02/2009|21:45] C:\DOCUME~1\MOUNIR\APPLIC~1\Macromedia
    [06/03/2009|19:39] C:\DOCUME~1\MOUNIR\APPLIC~1\Malwarebytes
    [23/02/2009|19:36] C:\DOCUME~1\MOUNIR\APPLIC~1\Mess aim site
    [05/03/2009|20:36] C:\DOCUME~1\MOUNIR\APPLIC~1\Microsoft
    [23/02/2009|19:32] C:\DOCUME~1\MOUNIR\APPLIC~1\Mozilla
    [08/03/2009|21:50] C:\DOCUME~1\MOUNIR\APPLIC~1\Skype
    [08/03/2009|16:09] C:\DOCUME~1\MOUNIR\APPLIC~1\skypePM
    [07/03/2009|01:19] C:\DOCUME~1\MOUNIR\APPLIC~1\uTorrent
    [23/02/2009|21:25] C:\DOCUME~1\MOUNIR\APPLIC~1\vlc
    [23/02/2009|20:44] C:\DOCUME~1\MOUNIR\APPLIC~1\WinRAR
    [08/03/2009|20:20] C:\DOCUME~1\MOUNIR\APPLIC~1\Yahoo!

    [23/02/2009|18:50] C:\DOCUME~1\NETWOR~1\APPLIC~1\Intel
    [23/02/2009|18:28] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft

    --------------------\\ Tâches planifiées dans C:\WINDOWS\tasks

    [08/03/2009 21:00][--ah-----] C:\WINDOWS\tasks\A8D909F0918E8018.job
    [08/03/2009 19:48][--ah-----] C:\WINDOWS\tasks\SA.DAT
    [28/09/2001 15:00][-r-h-----] C:\WINDOWS\tasks\desktop.ini

    ( A8D909F0918E8018.job )=( c:\docume~1\mounir\applic~1\messai~1\Waittestcopy.exe )

    --------------------\\ Listing des dossiers dans C:\Program Files

    [02/03/2009|19:29] C:\Program Files\Adobe
    [23/02/2009|19:42] C:\Program Files\Alwil Software
    [08/03/2009|19:57] C:\Program Files\Athan
    [08/03/2009|20:20] C:\Program Files\CCleaner
    [23/02/2009|18:25] C:\Program Files\ComPlus Applications
    [23/02/2009|18:36] C:\Program Files\CONEXANT
    [23/02/2009|20:44] C:\Program Files\Dell
    [23/02/2009|18:52] C:\Program Files\DellTPad
    [02/03/2009|19:29] C:\Program Files\Fichiers communs
    [26/02/2009|21:44] C:\Program Files\Google
    [23/02/2009|21:14] C:\Program Files\InstallShield Installation Information
    [23/02/2009|21:13] C:\Program Files\Intel
    [03/03/2009|20:22] C:\Program Files\Internet Download Manager
    [23/02/2009|20:26] C:\Program Files\Internet Explorer
    [23/02/2009|21:24] C:\Program Files\K-Lite Codec Pack
    [08/03/2009|21:16] C:\Program Files\Lopxp
    [06/03/2009|19:39] C:\Program Files\Malwarebytes' Anti-Malware
    [23/02/2009|19:35] C:\Program Files\Mess aim site
    [23/02/2009|20:52] C:\Program Files\Messenger
    [08/03/2009|19:53] C:\Program Files\Messenger Plus! Live
    [23/02/2009|18:29] C:\Program Files\microsoft frontpage
    [23/02/2009|22:39] C:\Program Files\Microsoft Silverlight
    [23/02/2009|18:26] C:\Program Files\Movie Maker
    [05/03/2009|22:10] C:\Program Files\Mozilla Firefox
    [23/02/2009|18:24] C:\Program Files\MSN
    [23/02/2009|18:25] C:\Program Files\MSN Gaming Zone
    [08/03/2009|19:53] C:\Program Files\MSN Messenger
    [23/02/2009|18:27] C:\Program Files\NetMeeting
    [23/02/2009|18:25] C:\Program Files\Online Services
    [23/02/2009|18:27] C:\Program Files\Outlook Express
    [23/02/2009|18:27] C:\Program Files\Services en ligne
    [23/02/2009|18:51] C:\Program Files\SigmaTel
    [23/02/2009|19:46] C:\Program Files\Skype
    [08/03/2009|14:21] C:\Program Files\Trend Micro
    [23/02/2009|18:33] C:\Program Files\Uninstall Information
    [05/03/2009|20:27] C:\Program Files\uTorrent
    [23/02/2009|21:23] C:\Program Files\VideoLAN
    [23/02/2009|18:44] C:\Program Files\WIDCOMM
    [08/03/2009|19:53] C:\Program Files\Windows Live
    [23/02/2009|21:22] C:\Program Files\Windows Media Connect 2
    [23/02/2009|22:06] C:\Program Files\Windows Media Player
    [23/02/2009|18:25] C:\Program Files\Windows NT
    [23/02/2009|18:27] C:\Program Files\WindowsUpdate
    [23/02/2009|19:32] C:\Program Files\WinRAR
    [23/02/2009|18:29] C:\Program Files\xerox
    [08/03/2009|20:20] C:\Program Files\Yahoo!

    --------------------\\ Listing des dossiers dans C:\Program Files\Fichiers communs

    [02/03/2009|19:30] C:\Program Files\Fichiers communs\Adobe
    [23/02/2009|18:51] C:\Program Files\Fichiers communs\InstallShield
    [23/02/2009|19:28] C:\Program Files\Fichiers communs\Microsoft Shared
    [23/02/2009|18:26] C:\Program Files\Fichiers communs\MSSoap
    [23/02/2009|19:18] C:\Program Files\Fichiers communs\ODBC
    [23/02/2009|18:27] C:\Program Files\Fichiers communs\Services
    [23/02/2009|19:46] C:\Program Files\Fichiers communs\Skype
    [23/02/2009|19:18] C:\Program Files\Fichiers communs\SpeechEngines
    [23/02/2009|18:26] C:\Program Files\Fichiers communs\System

    --------------------\\ Process

    ( 60 Processes )

    IEXPLORE.EXE ~ [PID:140]
    IEXPLORE.EXE ~ [PID:452]
    IEXPLORE.EXE ~ [PID:464]
    IEXPLORE.EXE ~ [PID:1716]
    IEXPLORE.EXE ~ [PID:1588]

    --------------------\\ Recherche avec S_Lop

    Aucun fichier / dossier Lop trouvé !

    --------------------\\ Recherche de Fichiers / Dossiers Lop

    C:\DOCUME~1\MOUNIR\APPLIC~1\messai~1
    C:\DOCUME~1\MOUNIR\APPLIC~1\messai~1\barb flaw sixth ford.exe
    C:\DOCUME~1\MOUNIR\APPLIC~1\messai~1\krwpookz.exe
    C:\DOCUME~1\MOUNIR\APPLIC~1\messai~1\POP SAFE ANTE.exe
    C:\DOCUME~1\MOUNIR\APPLIC~1\messai~1\Waittestcopy.exe
    C:\Program Files\messai~1
    C:\DOCUME~1\MOUNIR\LOCALS~1\Temp\nsx5.tmp
    C:\DOCUME~1\MOUNIR\Cookies\mounir@advertising[1].txt
    C:\WINDOWS\Tasks\A8D909F0918E8018.job

    --------------------\\ Verification du Registre

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "LongSlow"="C:\\DOCUME~1\\MOUNIR\\APPLIC~1\\MESSAI~1\\POP SAFE ANTE.exe"

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

    --------------------\\ Verification du fichier Hosts

    Fichier Hosts PROPRE


    --------------------\\ Recherche de fichiers avec Catchme

    catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2009-03-08 21:53:30
    Windows 5.1.2600 Service Pack 3 NTFS
    scanning hidden processes ...
    scanning hidden files ...
    scan completed successfully
    hidden processes: 0
    hidden files: 0

    --------------------\\ Recherche d'autres infections


    Aucune autre infection trouvée !

    [F:36][D:2]-> C:\DOCUME~1\MOUNIR\LOCALS~1\Temp
    [F:23][D:0]-> C:\DOCUME~1\MOUNIR\Cookies
    [F:516][D:4]-> C:\DOCUME~1\MOUNIR\LOCALS~1\TEMPOR~1\content.IE5

    1 - "C:\Lop SD\LopR_1.txt" - 08/03/2009|21:54 - Option : [1]

    --------------------\\ Fin du rapport a 21:54:02
    a c 267 8 Sécurité
    a b , Internet Explorer
    8 Mars 2009 21:58:18

  • Relance Lop S&D.
  • Choisis cette fois-ci l'option 2 (Suppression).
  • Ne ferme pas la fenêtre lors de la suppression !
  • Poste le rapport généré (C:\lopR.txt).

    (Si le Bureau ne réapparaît pas, presse Ctrl+Alt+Suppr, Onglet Fichier, Nouvelle tâche, tape explorer.exe et valide)
    8 Mars 2009 22:06:12

    Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 3
    X86-based PC ( Multiprocessor Free : Intel(R) Core(TM)2 Duo CPU T5450 @ 1.66GHz )
    BIOS : Phoenix ROM BIOS PLUS Version 1.10 A16
    USER : MOUNIR ( Administrator )
    BOOT : Normal boot
    Antivirus : avast! antivirus 4.8.1335 [VPS 090307-0] 4.8.1335 (Activated)
    C:\ (Local Disk) - NTFS - Total:19 Go (Free:10 Go)
    D:\ (Local Disk) - NTFS - Total:97 Go (Free:58 Go)
    E:\ (Local Disk) - NTFS - Total:115 Go (Free:85 Go)
    F:\ (CD or DVD)

    "C:\Lop SD" ( MAJ : 19-12-2008|23:40 )
    Option : [2] ( 08/03/2009|22:00 )


    \\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ SUPPRESSION

    Supprime! - C:\DOCUME~1\MOUNIR\APPLIC~1\messai~1\barb flaw sixth ford.exe
    Supprime! - C:\DOCUME~1\MOUNIR\APPLIC~1\messai~1\krwpookz.exe
    Supprime! - C:\DOCUME~1\MOUNIR\APPLIC~1\messai~1\POP SAFE ANTE.exe
    Supprime! - C:\DOCUME~1\MOUNIR\APPLIC~1\messai~1\Waittestcopy.exe
    Supprime! - C:\DOCUME~1\MOUNIR\LOCALS~1\Temp\nsx5.tmp
    Supprime! - C:\DOCUME~1\MOUNIR\Cookies\mounir@advertising[1].txt
    Supprime! - C:\WINDOWS\Tasks\A8D909F0918E8018.job
    Supprime! - C:\DOCUME~1\MOUNIR\APPLIC~1\messai~1
    Supprime! - C:\Program Files\messai~1

    \\\\\\\\\\\\\\\\\\\\\\\\\\\\\\


    --------------------\\ Listing des dossiers dans APPLIC~1

    [02/03/2009|19:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
    [23/02/2009|19:35] C:\DOCUME~1\ALLUSE~1\APPLIC~1\book this clock drv
    [26/02/2009|21:44] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
    [23/02/2009|18:49] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Intel
    [06/03/2009|19:39] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Malwarebytes
    [02/03/2009|19:15] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
    [23/02/2009|21:41] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Office Genuine Advantage
    [23/02/2009|19:46] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Skype
    [23/02/2009|21:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
    [23/02/2009|20:52] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
    [08/03/2009|20:25] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Yahoo! Companion

    [23/02/2009|18:50] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Intel
    [23/02/2009|18:28] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft

    [23/02/2009|18:50] C:\DOCUME~1\LOCALS~1\APPLIC~1\Intel
    [23/02/2009|18:28] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft

    [02/03/2009|19:30] C:\DOCUME~1\MOUNIR\APPLIC~1\Adobe
    [08/03/2009|19:48] C:\DOCUME~1\MOUNIR\APPLIC~1\DMCache
    [04/03/2009|22:38] C:\DOCUME~1\MOUNIR\APPLIC~1\dvdcss
    [26/02/2009|21:47] C:\DOCUME~1\MOUNIR\APPLIC~1\Google
    [23/02/2009|18:33] C:\DOCUME~1\MOUNIR\APPLIC~1\Identities
    [23/02/2009|19:41] C:\DOCUME~1\MOUNIR\APPLIC~1\IDM
    [23/02/2009|20:44] C:\DOCUME~1\MOUNIR\APPLIC~1\InstallShield
    [23/02/2009|18:50] C:\DOCUME~1\MOUNIR\APPLIC~1\Intel
    [23/02/2009|21:45] C:\DOCUME~1\MOUNIR\APPLIC~1\Macromedia
    [06/03/2009|19:39] C:\DOCUME~1\MOUNIR\APPLIC~1\Malwarebytes
    [05/03/2009|20:36] C:\DOCUME~1\MOUNIR\APPLIC~1\Microsoft
    [23/02/2009|19:32] C:\DOCUME~1\MOUNIR\APPLIC~1\Mozilla
    [08/03/2009|21:52] C:\DOCUME~1\MOUNIR\APPLIC~1\Skype
    [08/03/2009|16:09] C:\DOCUME~1\MOUNIR\APPLIC~1\skypePM
    [07/03/2009|01:19] C:\DOCUME~1\MOUNIR\APPLIC~1\uTorrent
    [23/02/2009|21:25] C:\DOCUME~1\MOUNIR\APPLIC~1\vlc
    [23/02/2009|20:44] C:\DOCUME~1\MOUNIR\APPLIC~1\WinRAR
    [08/03/2009|20:20] C:\DOCUME~1\MOUNIR\APPLIC~1\Yahoo!

    [23/02/2009|18:50] C:\DOCUME~1\NETWOR~1\APPLIC~1\Intel
    [23/02/2009|18:28] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft

    --------------------\\ Tâches planifiées dans C:\WINDOWS\tasks

    [08/03/2009 19:48][--ah-----] C:\WINDOWS\tasks\SA.DAT
    [28/09/2001 15:00][-r-h-----] C:\WINDOWS\tasks\desktop.ini

    --------------------\\ Listing des dossiers dans C:\Program Files

    [02/03/2009|19:29] C:\Program Files\Adobe
    [23/02/2009|19:42] C:\Program Files\Alwil Software
    [08/03/2009|19:57] C:\Program Files\Athan
    [08/03/2009|20:20] C:\Program Files\CCleaner
    [23/02/2009|18:25] C:\Program Files\ComPlus Applications
    [23/02/2009|18:36] C:\Program Files\CONEXANT
    [23/02/2009|20:44] C:\Program Files\Dell
    [23/02/2009|18:52] C:\Program Files\DellTPad
    [02/03/2009|19:29] C:\Program Files\Fichiers communs
    [26/02/2009|21:44] C:\Program Files\Google
    [23/02/2009|21:14] C:\Program Files\InstallShield Installation Information
    [23/02/2009|21:13] C:\Program Files\Intel
    [03/03/2009|20:22] C:\Program Files\Internet Download Manager
    [23/02/2009|20:26] C:\Program Files\Internet Explorer
    [23/02/2009|21:24] C:\Program Files\K-Lite Codec Pack
    [08/03/2009|21:16] C:\Program Files\Lopxp
    [06/03/2009|19:39] C:\Program Files\Malwarebytes' Anti-Malware
    [23/02/2009|20:52] C:\Program Files\Messenger
    [08/03/2009|19:53] C:\Program Files\Messenger Plus! Live
    [23/02/2009|18:29] C:\Program Files\microsoft frontpage
    [23/02/2009|22:39] C:\Program Files\Microsoft Silverlight
    [23/02/2009|18:26] C:\Program Files\Movie Maker
    [05/03/2009|22:10] C:\Program Files\Mozilla Firefox
    [23/02/2009|18:24] C:\Program Files\MSN
    [23/02/2009|18:25] C:\Program Files\MSN Gaming Zone
    [08/03/2009|19:53] C:\Program Files\MSN Messenger
    [23/02/2009|18:27] C:\Program Files\NetMeeting
    [23/02/2009|18:25] C:\Program Files\Online Services
    [23/02/2009|18:27] C:\Program Files\Outlook Express
    [23/02/2009|18:27] C:\Program Files\Services en ligne
    [23/02/2009|18:51] C:\Program Files\SigmaTel
    [23/02/2009|19:46] C:\Program Files\Skype
    [08/03/2009|14:21] C:\Program Files\Trend Micro
    [23/02/2009|18:33] C:\Program Files\Uninstall Information
    [05/03/2009|20:27] C:\Program Files\uTorrent
    [23/02/2009|21:23] C:\Program Files\VideoLAN
    [23/02/2009|18:44] C:\Program Files\WIDCOMM
    [08/03/2009|19:53] C:\Program Files\Windows Live
    [23/02/2009|21:22] C:\Program Files\Windows Media Connect 2
    [23/02/2009|22:06] C:\Program Files\Windows Media Player
    [23/02/2009|18:25] C:\Program Files\Windows NT
    [23/02/2009|18:27] C:\Program Files\WindowsUpdate
    [23/02/2009|19:32] C:\Program Files\WinRAR
    [23/02/2009|18:29] C:\Program Files\xerox
    [08/03/2009|20:20] C:\Program Files\Yahoo!

    --------------------\\ Listing des dossiers dans C:\Program Files\Fichiers communs

    [02/03/2009|19:30] C:\Program Files\Fichiers communs\Adobe
    [23/02/2009|18:51] C:\Program Files\Fichiers communs\InstallShield
    [23/02/2009|19:28] C:\Program Files\Fichiers communs\Microsoft Shared
    [23/02/2009|18:26] C:\Program Files\Fichiers communs\MSSoap
    [23/02/2009|19:18] C:\Program Files\Fichiers communs\ODBC
    [23/02/2009|18:27] C:\Program Files\Fichiers communs\Services
    [23/02/2009|19:46] C:\Program Files\Fichiers communs\Skype
    [23/02/2009|19:18] C:\Program Files\Fichiers communs\SpeechEngines
    [23/02/2009|18:26] C:\Program Files\Fichiers communs\System

    --------------------\\ Process

    ( 54 Processes )

    ... OK !

    --------------------\\ Recherche avec S_Lop

    Aucun fichier / dossier Lop trouvé !

    --------------------\\ Recherche de Fichiers / Dossiers Lop

    Aucun fichier / dossier Lop trouvé !

    --------------------\\ Verification du Registre

    ..... OK !

    --------------------\\ Verification du fichier Hosts

    Fichier Hosts PROPRE


    --------------------\\ Recherche de fichiers avec Catchme

    catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2009-03-08 22:01:39
    Windows 5.1.2600 Service Pack 3 NTFS
    scanning hidden processes ...
    scanning hidden files ...
    scan completed successfully
    hidden processes: 0
    hidden files: 0

    --------------------\\ Recherche d'autres infections


    Aucune autre infection trouvée !

    [F:33][D:1]-> C:\DOCUME~1\MOUNIR\LOCALS~1\Temp
    [F:24][D:0]-> C:\DOCUME~1\MOUNIR\Cookies
    [F:559][D:4]-> C:\DOCUME~1\MOUNIR\LOCALS~1\TEMPOR~1\content.IE5

    1 - "C:\Lop SD\LopR_1.txt" - 08/03/2009|21:54 - Option : [1]
    2 - "C:\Lop SD\LopR_2.txt" - 08/03/2009|22:02 - Option : [2]

    --------------------\\ Fin du rapport a 22:02:07
    a c 267 8 Sécurité
    a b , Internet Explorer
    8 Mars 2009 22:14:30

  • Télécharge Random's System Information Tool (RSIT) (par random/random) sur ton Bureau.
  • Double-clique sur RSIT.exe afin de lancer le programme.
  • Clique sur Continue à l'écran Disclaimer.
  • Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.
  • Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront. Poste le contenu de log.txt (c'est celui qui apparaît à l'écran) ainsi que de info.txt (que tu verras dans la barre des tâches).

    Note : les rapports sont sauvegardés dans le dossier C:\rsit.
    8 Mars 2009 22:21:31

    Logfile of random's system information tool 1.05 (written by random/random)
    Run by MOUNIR at 2009-03-08 22:19:47
    Microsoft Windows XP Professionnel Service Pack 3
    System drive C: has 10 GB (52%) free of 20 GB
    Total RAM: 2038 MB (75% free)

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 22:19:48, on 08/03/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16791)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
    C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\DellTPad\Apoint.exe
    C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
    C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
    C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\WINDOWS\system32\igfxtray.exe
    C:\WINDOWS\system32\hkcmd.exe
    C:\WINDOWS\system32\igfxpers.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Internet Download Manager\IDMan.exe
    C:\Program Files\Skype\Phone\Skype.exe
    C:\WINDOWS\system32\igfxsrvc.exe
    C:\Program Files\DellTPad\ApMsgFwd.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
    C:\Program Files\DellTPad\HidFind.exe
    C:\Program Files\DellTPad\Apntex.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
    C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    C:\Program Files\SigmaTel\C-Major Audio\DellXPM_5515v133\WDM\STacSV.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\Program Files\Internet Download Manager\IEMonitor.exe
    C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
    C:\Program Files\Skype\Plugin Manager\skypePM.exe
    C:\Program Files\MSN Messenger\usnsvc.exe
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\Program Files\Athan\Athan.exe
    C:\WINDOWS\system32\NOTEPAD.EXE
    C:\Documents and Settings\MOUNIR\Bureau\RSIT.exe
    C:\Documents and Settings\MOUNIR\Mes documents\Downloads\Programs\MOUNIR.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://login.live.com/ppsecure/sha1auth.srf?lc=1036
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: IDMIEHlprObj Class - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
    O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
    O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe
    O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
    O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
    O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\stsystra.exe
    O4 - HKLM\..\Run: [clock drv coal bird] C:\Documents and Settings\All Users\Application Data\book this clock drv\Idol name.exe
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [Athan] C:\Program Files\Athan\Athan.exe
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot
    O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O4 - Global Startup: BTTray.lnk = ?
    O8 - Extra context menu item: Envoyer au périphérique &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
    O8 - Extra context menu item: Télécharger avec IDM - C:\Program Files\Internet Download Manager\IEExt.htm
    O8 - Extra context menu item: Télécharger le contenu de video FLV avec IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm
    O8 - Extra context menu item: Télécharger tous les liens avec IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/fl...
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
    O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
    O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Program Files\SigmaTel\C-Major Audio\DellXPM_5515v133\WDM\STacSV.exe
    O23 - Service: Intel(R) PROSet/Wireless SSO Service (WLANKEEPER) - Intel(R) Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

    --
    End of file - 8870 bytes

    ======Registry dump======

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0055C089-8582-441B-A0BF-17B458C2A3A8}]
    IDMIEHlprObj Class - C:\Program Files\Internet Download Manager\IDMIECC.dll [2008-10-28 153008]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]
    &Yahoo! Toolbar Helper - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll [2008-07-28 882416]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
    Adobe PDF Link Helper - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2008-06-11 75128]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
    Windows Live Sign-in Helper - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2006-08-31 322368]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
    Google Toolbar Helper - c:\program files\google\googletoolbar1.dll [2009-02-26 2436160]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
    Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll [2009-03-05 737776]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}]
    SingleInstance Class - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll [2008-07-28 160496]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    {2318C2B1-4965-11d4-9B18-009027A5CD4F} - &Google - c:\program files\google\googletoolbar1.dll [2009-02-26 2436160]
    {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Yahoo! Toolbar - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll [2008-07-28 882416]

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    "Apoint"=C:\Program Files\DellTPad\Apoint.exe [2007-10-25 167936]
    "IntelZeroConfig"=C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe [2007-07-25 823296]
    "IntelWireless"=C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe [2007-07-25 974848]
    "SigmatelSysTrayApp"=C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe [2007-05-10 405504]
    "clock drv coal bird"=C:\Documents and Settings\All Users\Application Data\book this clock drv\Idol name.exe [2009-03-08 786432]
    "avast!"=C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe [2009-02-05 81000]
    "IgfxTray"=C:\WINDOWS\system32\igfxtray.exe [2007-09-05 141848]
    "HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe [2007-09-05 166424]
    "Persistence"=C:\WINDOWS\system32\igfxpers.exe [2007-09-05 137752]
    "Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2008-06-12 34672]
    "Athan"=C:\Program Files\Athan\Athan.exe [2007-09-06 1003520]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-13 15360]
    "MsnMsgr"=C:\Program Files\MSN Messenger\MsnMsgr.Exe [2007-01-19 5674352]
    "IDMan"=C:\Program Files\Internet Download Manager\IDMan.exe [2008-10-29 2610608]
    "Skype"=C:\Program Files\Skype\Phone\Skype.exe [2009-02-04 23975720]
    "swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2009-03-05 68856]

    C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage
    BTTray.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
    C:\WINDOWS\system32\igfxdev.dll [2007-08-24 208896]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
    WgaLogon.dll []

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
    WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
    "dontdisplaylastusername"=0
    "legalnoticecaption"=
    "legalnoticetext"=
    "shutdownwithoutlogon"=1
    "undockwithoutlogon"=1

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
    "NoDriveTypeAutoRun"=145

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
    "HonorAutoRunSetting"=

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
    "%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
    "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
    "C:\Program Files\MSN Messenger\msnmsgr.exe"="C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
    "C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
    "C:\Program Files\uTorrent\uTorrent.exe"="C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
    "C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
    "%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
    "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
    "C:\Program Files\MSN Messenger\msnmsgr.exe"="C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
    "C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"

    ======List of files/folders created in the last 1 months======

    2009-03-08 22:19:47 ----D---- C:\rsit
    2009-03-08 21:52:28 ----A---- C:\lopR.txt
    2009-03-08 21:51:09 ----D---- C:\Lop SD
    2009-03-08 21:12:03 ----D---- C:\Program Files\Lopxp
    2009-03-08 20:20:18 ----D---- C:\Documents and Settings\MOUNIR\Application Data\Yahoo!
    2009-03-08 20:20:18 ----D---- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
    2009-03-08 20:20:13 ----D---- C:\Program Files\CCleaner
    2009-03-08 19:57:29 ----A---- C:\WINDOWS\iun6002.exe
    2009-03-08 19:57:13 ----D---- C:\WINDOWS\system32\athan
    2009-03-08 19:57:11 ----D---- C:\Program Files\Athan
    2009-03-08 19:53:11 ----D---- C:\Program Files\Windows Live
    2009-03-08 15:10:09 ----D---- C:\Program Files\Yahoo!
    2009-03-08 14:21:38 ----D---- C:\Program Files\Trend Micro
    2009-03-06 19:39:13 ----D---- C:\Documents and Settings\MOUNIR\Application Data\Malwarebytes
    2009-03-06 19:39:08 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
    2009-03-06 19:39:08 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
    2009-03-05 20:27:36 ----D---- C:\Program Files\uTorrent
    2009-03-05 20:27:34 ----D---- C:\Documents and Settings\MOUNIR\Application Data\uTorrent
    2009-03-04 22:38:36 ----D---- C:\Documents and Settings\MOUNIR\Application Data\dvdcss
    2009-03-02 19:29:57 ----D---- C:\Documents and Settings\All Users\Application Data\Adobe
    2009-03-02 19:29:48 ----D---- C:\Program Files\Fichiers communs\Adobe
    2009-03-02 19:29:48 ----D---- C:\Program Files\Adobe
    2009-02-27 22:24:37 ----D---- C:\Documents and Settings\MOUNIR\Application Data\skypePM
    2009-02-26 21:47:36 ----D---- C:\Documents and Settings\MOUNIR\Application Data\Google
    2009-02-26 21:44:25 ----D---- C:\Documents and Settings\All Users\Application Data\Google
    2009-02-26 21:44:21 ----D---- C:\Program Files\Google
    2009-02-26 21:44:11 ----D---- C:\WINDOWS\system32\Adobe
    2009-02-25 13:04:01 ----HDC---- C:\WINDOWS\$NtUninstallKB941569$
    2009-02-25 13:03:44 ----HDC---- C:\WINDOWS\$NtUninstallKB967715$
    2009-02-25 13:03:33 ----HDC---- C:\WINDOWS\$NtUninstallKB929399$
    2009-02-25 13:03:18 ----HDC---- C:\WINDOWS\$NtUninstallKB939683$
    2009-02-25 13:03:03 ----HDC---- C:\WINDOWS\$NtUninstallKB954154_WM11$
    2009-02-25 13:02:54 ----HDC---- C:\WINDOWS\$NtUninstallKB936782_WMP11$
    2009-02-24 19:43:53 ----A---- C:\WINDOWS\system32\muweb.dll
    2009-02-24 19:43:53 ----A---- C:\WINDOWS\system32\mucltui.dll.mui
    2009-02-24 19:43:53 ----A---- C:\WINDOWS\system32\mucltui.dll
    2009-02-23 22:39:02 ----D---- C:\Program Files\Microsoft Silverlight
    2009-02-23 22:06:34 ----N---- C:\WINDOWS\system32\spmsg.dll
    2009-02-23 21:45:12 ----D---- C:\Documents and Settings\MOUNIR\Application Data\Macromedia
    2009-02-23 21:45:12 ----D---- C:\Documents and Settings\MOUNIR\Application Data\Adobe
    2009-02-23 21:41:20 ----D---- C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
    2009-02-23 21:30:44 ----D---- C:\WINDOWS\system32\appmgmt
    2009-02-23 21:25:36 ----D---- C:\Documents and Settings\MOUNIR\Application Data\vlc
    2009-02-23 21:24:58 ----A---- C:\WINDOWS\system32\unrar.dll
    2009-02-23 21:24:56 ----A---- C:\WINDOWS\system32\yv12vfw.dll
    2009-02-23 21:24:56 ----A---- C:\WINDOWS\system32\xvidvfw.dll
    2009-02-23 21:24:56 ----A---- C:\WINDOWS\system32\xvidcore.dll
    2009-02-23 21:24:56 ----A---- C:\WINDOWS\system32\qt-dx331.dll
    2009-02-23 21:24:56 ----A---- C:\WINDOWS\system32\dpl100.dll
    2009-02-23 21:24:55 ----A---- C:\WINDOWS\system32\divx.dll
    2009-02-23 21:24:54 ----A---- C:\WINDOWS\system32\ff_vfw.dll.manifest
    2009-02-23 21:24:54 ----A---- C:\WINDOWS\system32\ff_vfw.dll
    2009-02-23 21:24:53 ----D---- C:\Program Files\K-Lite Codec Pack
    2009-02-23 21:23:26 ----D---- C:\Program Files\VideoLAN
    2009-02-23 21:22:48 ----HDC---- C:\WINDOWS\$NtUninstallMSCompPackV1$
    2009-02-23 21:22:37 ----D---- C:\Program Files\Windows Media Connect 2
    2009-02-23 21:22:26 ----HDC---- C:\WINDOWS\$NtUninstallwmp11$
    2009-02-23 21:21:51 ----HDC---- C:\WINDOWS\$NtUninstallWMFDist11$
    2009-02-23 21:21:30 ----D---- C:\WINDOWS\system32\LogFiles
    2009-02-23 21:21:26 ----HDC---- C:\WINDOWS\$NtUninstallWudf01000$
    2009-02-23 21:17:27 ----SHD---- C:\RECYCLER
    2009-02-23 21:14:54 ----A---- C:\WINDOWS\system32\snymsico.dll
    2009-02-23 21:14:54 ----A---- C:\WINDOWS\system32\rixdicon.dll
    2009-02-23 20:58:08 ----A---- C:\Program Files\removewga_removewga_1.2_anglais_21437.exe
    2009-02-23 20:52:52 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2$
    2009-02-23 20:52:48 ----HDC---- C:\WINDOWS\$NtUninstallKB952954$
    2009-02-23 20:52:44 ----HDC---- C:\WINDOWS\$NtUninstallKB946648$
    2009-02-23 20:52:40 ----HDC---- C:\WINDOWS\$NtUninstallKB956803$
    2009-02-23 20:52:35 ----HDC---- C:\WINDOWS\$NtUninstallKB955839$
    2009-02-23 20:52:29 ----HDC---- C:\WINDOWS\$NtUninstallKB951978$
    2009-02-23 20:52:24 ----HDC---- C:\WINDOWS\$NtUninstallKB950974$
    2009-02-23 20:52:17 ----D---- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
    2009-02-23 20:51:58 ----HDC---- C:\WINDOWS\$NtUninstallKB951698$
    2009-02-23 20:51:53 ----HDC---- C:\WINDOWS\$NtUninstallKB954211$
    2009-02-23 20:51:49 ----HDC---- C:\WINDOWS\$NtUninstallKB950762$
    2009-02-23 20:51:44 ----HDC---- C:\WINDOWS\$NtUninstallKB957097$
    2009-02-23 20:51:40 ----HDC---- C:\WINDOWS\$NtUninstallKB960715$
    2009-02-23 20:51:36 ----HDC---- C:\WINDOWS\$NtUninstallKB958687$
    2009-02-23 20:51:32 ----HDC---- C:\WINDOWS\$NtUninstallKB952287$
    2009-02-23 20:51:28 ----HDC---- C:\WINDOWS\$NtUninstallKB950760$
    2009-02-23 20:51:23 ----HDC---- C:\WINDOWS\$NtUninstallKB951066$
    2009-02-23 20:51:20 ----HDC---- C:\WINDOWS\$NtUninstallKB938464$
    2009-02-23 20:51:16 ----HDC---- C:\WINDOWS\$NtUninstallKB954600$
    2009-02-23 20:51:12 ----HDC---- C:\WINDOWS\$NtUninstallKB958644$
    2009-02-23 20:51:04 ----HDC---- C:\WINDOWS\$NtUninstallKB955069$
    2009-02-23 20:47:01 ----A---- C:\WINDOWS\system32\igfxres.dll
    2009-02-23 20:44:49 ----D---- C:\Program Files\Dell
    2009-02-23 20:44:46 ----D---- C:\Documents and Settings\MOUNIR\Application Data\InstallShield
    2009-02-23 20:44:15 ----AD---- C:\Documents and Settings\All Users\Application Data\TEMP
    2009-02-23 20:44:14 ----D---- C:\Documents and Settings\MOUNIR\Application Data\WinRAR
    2009-02-23 20:38:54 ----A---- C:\WINDOWS\system32\igxprd32.dll
    2009-02-23 20:38:54 ----A---- C:\WINDOWS\system32\igxpgd32.dll
    2009-02-23 20:38:54 ----A---- C:\WINDOWS\system32\igxpdv32.dll
    2009-02-23 20:38:54 ----A---- C:\WINDOWS\system32\igmedcompkrn.dll
    2009-02-23 20:38:54 ----A---- C:\WINDOWS\system32\igfxzoom.exe
    2009-02-23 20:38:54 ----A---- C:\WINDOWS\system32\igfxtray.exe
    2009-02-23 20:38:54 ----A---- C:\WINDOWS\system32\igfxsrvc.exe
    2009-02-23 20:38:54 ----A---- C:\WINDOWS\system32\igfxsrvc.dll
    2009-02-23 20:38:54 ----A---- C:\WINDOWS\system32\igfxpers.exe
    2009-02-23 20:38:54 ----A---- C:\WINDOWS\system32\igfxext.exe
    2009-02-23 20:38:54 ----A---- C:\WINDOWS\system32\igfxexps.dll
    2009-02-23 20:38:54 ----A---- C:\WINDOWS\system32\igfxdev.dll
    2009-02-23 20:38:54 ----A---- C:\WINDOWS\system32\igfxCoIn_v4864.dll
    2009-02-23 20:38:54 ----A---- C:\WINDOWS\system32\igfxcfg.exe
    2009-02-23 20:38:54 ----A---- C:\WINDOWS\system32\ig4icd32.dll
    2009-02-23 20:38:54 ----A---- C:\WINDOWS\system32\ig4dev32.dll
    2009-02-23 20:38:54 ----A---- C:\WINDOWS\system32\hkcmd.exe
    2009-02-23 20:38:54 ----A---- C:\WINDOWS\system32\hccutils.dll
    2009-02-23 20:38:53 ----D---- C:\WINDOWS\system32\Lang
    2009-02-23 20:38:53 ----A---- C:\WINDOWS\system32\igxpun.exe
    2009-02-23 20:38:53 ----A---- C:\WINDOWS\system32\igxpdx32.dll
    2009-02-23 20:38:53 ----A---- C:\WINDOWS\system32\igmedkrn.dll
    2009-02-23 20:38:53 ----A---- C:\WINDOWS\system32\igfxress.dll
    2009-02-23 20:38:53 ----A---- C:\WINDOWS\system32\igfxpph.dll
    2009-02-23 20:38:53 ----A---- C:\WINDOWS\system32\igfxdo.dll
    2009-02-23 20:38:53 ----A---- C:\WINDOWS\system32\difxapi.dll
    2009-02-23 20:38:46 ----D---- C:\Intel
    2009-02-23 20:28:32 ----D---- C:\WINDOWS\system32\PreInstall
    2009-02-23 20:28:30 ----HDC---- C:\WINDOWS\$NtUninstallKB898461$
    2009-02-23 19:56:26 ----D---- C:\WINDOWS\ie7updates
    2009-02-23 19:56:13 ----D---- C:\WINDOWS\WBEM
    2009-02-23 19:55:12 ----HDC---- C:\WINDOWS\ie7
    2009-02-23 19:54:59 ----HDC---- C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$
    2009-02-23 19:54:46 ----HDC---- C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$
    2009-02-23 19:54:35 ----HD---- C:\WINDOWS\$hf_mig$
    2009-02-23 19:53:15 ----A---- C:\WINDOWS\system32\MRT.exe
    2009-02-23 19:47:04 ----D---- C:\Documents and Settings\MOUNIR\Application Data\Skype
    2009-02-23 19:46:56 ----D---- C:\Program Files\Fichiers communs\Skype
    2009-02-23 19:46:55 ----RD---- C:\Program Files\Skype
    2009-02-23 19:46:45 ----D---- C:\Documents and Settings\All Users\Application Data\Skype
    2009-02-23 19:42:42 ----A---- C:\WINDOWS\system32\MSVCR71.dll
    2009-02-23 19:42:42 ----A---- C:\WINDOWS\system32\MSVCP71.dll
    2009-02-23 19:42:42 ----A---- C:\WINDOWS\system32\MFC71.dll
    2009-02-23 19:42:42 ----A---- C:\WINDOWS\system32\aswBoot.exe
    2009-02-23 19:42:40 ----D---- C:\Program Files\Alwil Software
    2009-02-23 19:35:40 ----D---- C:\Documents and Settings\All Users\Application Data\book this clock drv
    2009-02-23 19:34:47 ----D---- C:\Program Files\Messenger Plus! Live
    2009-02-23 19:33:44 ----D---- C:\Documents and Settings\MOUNIR\Application Data\IDM
    2009-02-23 19:33:43 ----D---- C:\Documents and Settings\MOUNIR\Application Data\DMCache
    2009-02-23 19:33:37 ----D---- C:\Program Files\Internet Download Manager
    2009-02-23 19:32:49 ----D---- C:\Documents and Settings\MOUNIR\Application Data\Mozilla
    2009-02-23 19:32:44 ----D---- C:\Program Files\Mozilla Firefox
    2009-02-23 19:32:14 ----D---- C:\Program Files\WinRAR
    2009-02-23 19:28:21 ----D---- C:\Program Files\MSN Messenger
    2009-02-23 19:27:06 ----D---- C:\WINDOWS\system32\SoftwareDistribution
    2009-02-23 19:23:09 ----A---- C:\WINDOWS\system32\h323log.txt
    2009-02-23 19:20:55 ----A---- C:\WINDOWS\system32\vfwwdm32.dll
    2009-02-23 19:20:55 ----A---- C:\WINDOWS\system32\ksuser.dll
    2009-02-23 19:19:52 ----A---- C:\WINDOWS\system32\usbui.dll
    2009-02-23 19:18:42 ----SHD---- C:\WINDOWS\Installer
    2009-02-23 19:18:42 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
    2009-02-23 19:18:41 ----D---- C:\Program Files\Fichiers communs\ODBC
    2009-02-23 19:18:41 ----A---- C:\WINDOWS\ODBCINST.INI
    2009-02-23 19:18:38 ----D---- C:\Program Files\Fichiers communs\SpeechEngines
    2009-02-23 19:18:38 ----D---- C:\Program Files\Fichiers communs\Microsoft Shared
    2009-02-23 19:18:37 ----RD---- C:\Program Files
    2009-02-23 19:18:37 ----D---- C:\Program Files\Fichiers communs
    2009-02-23 19:18:34 ----RA---- C:\WINDOWS\system32\kbdtuq.dll
    2009-02-23 19:18:34 ----RA---- C:\WINDOWS\system32\kbdtuf.dll
    2009-02-23 19:18:34 ----RA---- C:\WINDOWS\system32\kbdazel.dll
    2009-02-23 19:18:33 ----RA---- C:\WINDOWS\system32\kbduzb.dll
    2009-02-23 19:18:33 ----RA---- C:\WINDOWS\system32\kbdtat.dll
    2009-02-23 19:18:33 ----RA---- C:\WINDOWS\system32\kbdmon.dll
    2009-02-23 19:18:33 ----RA---- C:\WINDOWS\system32\kbdkyr.dll
    2009-02-23 19:18:33 ----RA---- C:\WINDOWS\system32\kbdaze.dll
    2009-02-23 19:18:32 ----RA---- C:\WINDOWS\system32\kbdycc.dll
    2009-02-23 19:18:32 ----RA---- C:\WINDOWS\system32\kbdur.dll
    2009-02-23 19:18:32 ----RA---- C:\WINDOWS\system32\kbdru1.dll
    2009-02-23 19:18:32 ----RA---- C:\WINDOWS\system32\kbdru.dll
    2009-02-23 19:18:32 ----RA---- C:\WINDOWS\system32\kbdkaz.dll
    2009-02-23 19:18:32 ----RA---- C:\WINDOWS\system32\kbdbu.dll
    2009-02-23 19:18:32 ----RA---- C:\WINDOWS\system32\kbdblr.dll
    2009-02-23 19:18:31 ----RA---- C:\WINDOWS\system32\kbdhept.dll
    2009-02-23 19:18:31 ----RA---- C:\WINDOWS\system32\kbdhela3.dll
    2009-02-23 19:18:31 ----RA---- C:\WINDOWS\system32\kbdhela2.dll
    2009-02-23 19:18:31 ----RA---- C:\WINDOWS\system32\kbdhe319.dll
    2009-02-23 19:18:31 ----RA---- C:\WINDOWS\system32\kbdhe220.dll
    2009-02-23 19:18:31 ----RA---- C:\WINDOWS\system32\kbdhe.dll
    2009-02-23 19:18:31 ----RA---- C:\WINDOWS\system32\kbdgkl.dll
    2009-02-23 19:18:29 ----RA---- C:\WINDOWS\system32\kbdlv1.dll
    2009-02-23 19:18:29 ----RA---- C:\WINDOWS\system32\kbdlv.dll
    2009-02-23 19:18:29 ----RA---- C:\WINDOWS\system32\kbdlt1.dll
    2009-02-23 19:18:29 ----RA---- C:\WINDOWS\system32\kbdlt.dll
    2009-02-23 19:18:29 ----RA---- C:\WINDOWS\system32\kbdest.dll
    2009-02-23 19:18:28 ----RA---- C:\WINDOWS\system32\kbdsl1.dll
    2009-02-23 19:18:28 ----RA---- C:\WINDOWS\system32\kbdsl.dll
    2009-02-23 19:18:28 ----RA---- C:\WINDOWS\system32\kbdro.dll
    2009-02-23 19:18:28 ----RA---- C:\WINDOWS\system32\kbdpl1.dll
    2009-02-23 19:18:28 ----RA---- C:\WINDOWS\system32\kbdpl.dll
    2009-02-23 19:18:28 ----RA---- C:\WINDOWS\system32\kbdhu1.dll
    2009-02-23 19:18:28 ----RA---- C:\WINDOWS\system32\kbdhu.dll
    2009-02-23 19:18:28 ----RA---- C:\WINDOWS\system32\kbdcz2.dll
    2009-02-23 19:18:28 ----RA---- C:\WINDOWS\system32\kbdcz1.dll
    2009-02-23 19:18:28 ----RA---- C:\WINDOWS\system32\kbdcz.dll
    2009-02-23 19:18:28 ----RA---- C:\WINDOWS\system32\kbdcr.dll
    2009-02-23 19:18:28 ----RA---- C:\WINDOWS\system32\KBDAL.DLL
    2009-02-23 19:18:27 ----RA---- C:\WINDOWS\system32\kbdycl.dll
    2009-02-23 19:18:25 ----A---- C:\WINDOWS\system32\spxcoins.dll
    2009-02-23 19:18:25 ----A---- C:\WINDOWS\system32\irclass.dll
    2009-02-23 19:18:25 ----A---- C:\WINDOWS\system32\EqnClass.Dll
    2009-02-23 19:18:25 ----A---- C:\WINDOWS\system32\dgsetup.dll
    2009-02-23 19:18:25 ----A---- C:\WINDOWS\system32\dgrpsetu.dll
    2009-02-23 19:18:23 ----N---- C:\WINDOWS\system32\CONFIG.TMP
    2009-02-23 19:18:23 ----A---- C:\WINDOWS\TASKMAN.EXE
    2009-02-23 19:18:23 ----A---- C:\WINDOWS\system32\batt.dll
    2009-02-23 19:18:22 ----A---- C:\WINDOWS\NOTEPAD.EXE
    2009-02-23 19:18:21 ----A---- C:\WINDOWS\system32\storprop.dll
    2009-02-23 19:18:15 ----ASH---- C:\Documents and Settings\All Users\Application Data\desktop.ini
    2009-02-23 19:18:11 ----RA---- C:\WINDOWS\SET8.tmp
    2009-02-23 19:18:09 ----RA---- C:\WINDOWS\SET4.tmp
    2009-02-23 19:18:07 ----RA---- C:\WINDOWS\SET3.tmp
    2009-02-23 19:18:03 ----D---- C:\WINDOWS\system32\CatRoot2
    2009-02-23 19:18:03 ----D---- C:\WINDOWS\system32\CatRoot
    2009-02-23 19:17:57 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft
    2009-02-23 19:17:33 ----D---- C:\Documents and Settings
    2009-02-23 19:17:32 ----SHD---- C:\System Volume Information
    2009-02-23 19:16:51 ----SH---- C:\boot.ini
    2009-02-23 19:11:41 ----RSHDC---- C:\WINDOWS\system32\dllcache
    2009-02-23 19:11:41 ----RSD---- C:\WINDOWS\Fonts
    2009-02-23 19:11:41 ----RD---- C:\WINDOWS\Web
    2009-02-23 19:11:41 ----HD---- C:\WINDOWS\inf
    2009-02-23 19:11:41 ----D---- C:\WINDOWS\WinSxS
    2009-02-23 19:11:41 ----D---- C:\WINDOWS\twain_32
    2009-02-23 19:11:41 ----D---- C:\WINDOWS\Temp
    2009-02-23 19:11:41 ----D---- C:\WINDOWS\system32\wins
    2009-02-23 19:11:41 ----D---- C:\WINDOWS\system32\wbem
    2009-02-23 19:11:41 ----D---- C:\WINDOWS\system32\usmt
    2009-02-23 19:11:41 ----D---- C:\WINDOWS\system32\spool
    2009-02-23 19:11:41 ----D---- C:\WINDOWS\system32\ShellExt
    2009-02-23 19:11:41 ----D---- C:\WINDOWS\system32\Setup
    2009-02-23 19:11:41 ----D---- C:\WINDOWS\system32\ras
    2009-02-23 19:11:41 ----D---- C:\WINDOWS\system32\oobe
    2009-02-23 19:11:41 ----D---- C:\WINDOWS\system32\npp
    2009-02-23 19:11:41 ----D---- C:\WINDOWS\system32\mui
    2009-02-23 19:11:41 ----D---- C:\WINDOWS\system32\inetsrv
    2009-02-23 19:11:41 ----D---- C:\WINDOWS\system32\IME
    2009-02-23 19:11:41 ----D---- C:\WINDOWS\system32\icsxml
    2009-02-23 19:11:41 ----D---- C:\WINDOWS\system32\ias
    2009-02-23 19:11:41 ----D---- C:\WINDOWS\system32\fr-fr
    2009-02-23 19:11:41 ----D---- C:\WINDOWS\system32\fr
    2009-02-23 19:11:41 ----D---- C:\WINDOWS\system32\export
    2009-02-23 19:11:41 ----D---- C:\WINDOWS\system32\drivers
    2009-02-23 19:11:41 ----D---- C:\WINDOWS\system32\dhcp
    2009-02-23 19:11:41 ----D---- C:\WINDOWS\system32\config
    2009-02-23 19:11:41 ----D---- C:\WINDOWS\system32\3com_dmi
    2009-02-23 19:11:41 ----D---- C:\WINDOWS\system32\3076
    2009-02-23 19:11:41 ----D---- C:\WINDOWS\system32\2052
    2009-02-23 19:11:41 ----D---- C:\WINDOWS\system32\1054
    2009-02-23 19:11:41 ----D---- C:\WINDOWS\system32\1042
    2009-02-23 19:11:41 ----D---- C:\WINDOWS\system32\1041
    2009-02-23 19:11:41 ----D---- C:\WINDOWS\system32\1037
    2009-02-23 19:11:41 ----D---- C:\WINDOWS\system32\1036
    2009-02-23 19:11:41 ----D---- C:\WINDOWS\system32\1033
    2009-02-23 19:11:41 ----D---- C:\WINDOWS\system32\1031
    2009-02-23 19:11:41 ----D---- C:\WINDOWS\system32\1028
    2009-02-23 19:11:41 ----D---- C:\WINDOWS\system32\1025
    2009-02-23 19:11:41 ----D---- C:\WINDOWS\system32
    2009-02-23 19:11:41 ----D---- C:\WINDOWS\system
    2009-02-23 19:11:41 ----D---- C:\WINDOWS\security
    2009-02-23 19:11:41 ----D---- C:\WINDOWS\Resources
    2009-02-23 19:11:41 ----D---- C:\WINDOWS\repair
    2009-02-23 19:11:41 ----D---- C:\WINDOWS\Provisioning
    2009-02-23 19:11:41 ----D---- C:\WINDOWS\PeerNet
    2009-02-23 19:11:41 ----D---- C:\WINDOWS\pchealth
    2009-02-23 19:11:41 ----D---- C:\WINDOWS\Network Diagnostic
    2009-02-23 19:11:41 ----D---- C:\WINDOWS\mui
    2009-02-23 19:11:41 ----D---- C:\WINDOWS\msapps
    2009-02-23 19:11:41 ----D---- C:\WINDOWS\msagent
    2009-02-23 19:11:41 ----D---- C:\WINDOWS\Media
    2009-02-23 19:11:41 ----D---- C:\WINDOWS\L2Schemas
    2009-02-23 19:11:41 ----D---- C:\WINDOWS\java
    2009-02-23 19:11:41 ----D---- C:\WINDOWS\ime
    2009-02-23 19:11:41 ----D---- C:\WINDOWS\Help
    2009-02-23 19:11:41 ----D---- C:\WINDOWS\ehome
    2009-02-23 19:11:41 ----D---- C:\WINDOWS\Driver Cache
    2009-02-23 19:11:41 ----D---- C:\WINDOWS\Debug
    2009-02-23 19:11:41 ----D---- C:\WINDOWS\Cursors
    2009-02-23 19:11:41 ----D---- C:\WINDOWS\Connection Wizard
    2009-02-23 19:11:41 ----D---- C:\WINDOWS\Config
    2009-02-23 19:11:41 ----D---- C:\WINDOWS\AppPatch
    2009-02-23 19:11:41 ----D---- C:\WINDOWS\addins
    2009-02-23 19:11:41 ----D---- C:\WINDOWS
    2009-02-23 18:52:00 ----A---- C:\WINDOWS\system32\stlang.dll
    2009-02-23 18:52:00 ----A---- C:\WINDOWS\system32\stacsv.exe
    2009-02-23 18:52:00 ----A---- C:\WINDOWS\stsystra.exe
    2009-02-23 18:51:53 ----A---- C:\WINDOWS\system32\stacapi.dll
    2009-02-23 18:51:53 ----A---- C:\WINDOWS\system32\st325602.dll
    2009-02-23 18:51:52 ----HD---- C:\Program Files\InstallShield Installation Information
    2009-02-23 18:51:52 ----D---- C:\Program Files\SigmaTel
    2009-02-23 18:51:28 ----D---- C:\Program Files\Fichiers communs\InstallShield
    2009-02-23 18:50:07 ----D---- C:\Documents and Settings\MOUNIR\Application Data\Intel
    2009-02-23 18:50:05 ----A---- C:\WINDOWS\system32\results.txt
    2009-02-23 18:50:01 ----A---- C:\WINDOWS\system32\AegisI5Installer.exe
    2009-02-23 18:49:42 ----D---- C:\Documents and Settings\All Users\Application Data\Intel
    2009-02-23 18:49:26 ----A---- C:\WINDOWS\system32\NETw4r32.dll
    2009-02-23 18:49:26 ----A---- C:\WINDOWS\system32\NETw4c32.dll
    2009-02-23 18:49:23 ----D---- C:\Program Files\Intel
    2009-02-23 18:44:11 ----A---- C:\WINDOWS\system32\btw_ci.dll
    2009-02-23 18:44:06 ----D---- C:\Program Files\WIDCOMM
    2009-02-23 18:41:37 ----A---- C:\WINDOWS\system32\hidserv.dll
    2009-02-23 18:36:24 ----A---- C:\WINDOWS\system32\spupdsvc.exe
    2009-02-23 18:36:22 ----HDC---- C:\WINDOWS\$NtUninstallWdf01005$
    2009-02-23 18:36:13 ----D---- C:\Program Files\DellTPad
    2009-02-23 18:36:12 ----D---- C:\WINDOWS\system32\ReinstallBackups
    2009-02-23 18:36:08 ----DC---- C:\WINDOWS\system32\DRVSTORE
    2009-02-23 18:36:08 ----A---- C:\WINDOWS\system32\WdfCoInstaller01005.dll
    2009-02-23 18:36:08 ----A---- C:\WINDOWS\system32\Vxdif.dll
    2009-02-23 18:36:05 ----RA---- C:\WINDOWS\system32\UCI32M21.dll
    2009-02-23 18:36:05 ----RA---- C:\WINDOWS\system32\mdmxsdk.dll
    2009-02-23 18:36:05 ----D---- C:\Program Files\CONEXANT
    2009-02-23 18:35:47 ----D---- C:\dell
    2009-02-23 18:33:47 ----D---- C:\Documents and Settings\MOUNIR\Application Data\Identities
    2009-02-23 18:33:45 ----HD---- C:\Program Files\Uninstall Information
    2009-02-23 18:33:39 ----SD---- C:\Documents and Settings\MOUNIR\Application Data\Microsoft
    2009-02-23 18:33:39 ----ASH---- C:\Documents and Settings\MOUNIR\Application Data\desktop.ini
    2009-02-23 18:32:10 ----D---- C:\WINDOWS\SoftwareDistribution
    2009-02-23 18:32:08 ----D---- C:\WINDOWS\Prefetch
    2009-02-23 18:32:07 ----SD---- C:\WINDOWS\system32\Microsoft
    2009-02-23 18:32:07 ----N---- C:\WINDOWS\SchedLgU.Txt
    2009-02-23 18:29:00 ----D---- C:\WINDOWS\system32\xircom
    2009-02-23 18:29:00 ----D---- C:\Program Files\xerox
    2009-02-23 18:29:00 ----D---- C:\Program Files\microsoft frontpage
    2009-02-23 18:28:43 ----A---- C:\WINDOWS\control.ini
    2009-02-23 18:28:43 ----A---- C:\AUTOEXEC.BAT
    2009-02-23 18:28:29 ----A---- C:\WINDOWS\system32\mapi32.dll
    2009-02-23 18:27:45 ----SD---- C:\WINDOWS\Downloaded Program Files
    2009-02-23 18:27:45 ----RD---- C:\WINDOWS\Offline Web Pages
    2009-02-23 18:27:45 ----RAH---- C:\WINDOWS\system32\logonui.exe.manifest
    2009-02-23 18:27:40 ----RAH---- C:\WINDOWS\system32\cdplayer.exe.manifest
    2009-02-23 18:27:36 ----HD---- C:\Program Files\WindowsUpdate
    2009-02-23 18:27:33 ----D---- C:\Program Files\Services en ligne
    2009-02-23 18:27:18 ----D---- C:\WINDOWS\system32\DirectX
    2009-02-23 18:27:12 ----A---- C:\WINDOWS\system32\atrace.dll
    2009-02-23 18:27:09 ----A---- C:\WINDOWS\system32\desktop.ini
    2009-02-23 18:27:09 ----A---- C:\WINDOWS\desktop.ini
    2009-02-23 18:27:03 ----A---- C:\WINDOWS\system32\nmevtmsg.dll
    2009-02-23 18:27:02 ----D---- C:\Program Files\Fichiers communs\Services
    2009-02-23 18:27:02 ----A---- C:\WINDOWS\system32\acctres.dll
    2009-02-23 18:26:59 ----SD---- C:\WINDOWS\Tasks
    2009-02-23 18:26:59 ----A---- C:\WINDOWS\system32\icfgnt5.dll
    2009-02-23 18:26:58 ----D---- C:\Program Files\Fichiers communs\MSSoap
    2009-02-23 18:26:55 ----D---- C:\WINDOWS\srchasst
    2009-02-23 18:26:54 ----D---- C:\WINDOWS\system32\Macromed
    2009-02-23 18:26:51 ----A---- C:\WINDOWS\system32\wuweb.dll
    2009-02-23 18:26:51 ----A---- C:\WINDOWS\system32\wups.dll
    2009-02-23 18:26:51 ----A---- C:\WINDOWS\system32\wucltui.dll
    2009-02-23 18:26:51 ----A---- C:\WINDOWS\system32\wuauserv.dll
    2009-02-23 18:26:51 ----A---- C:\WINDOWS\system32\wuaueng1.dll
    2009-02-23 18:26:51 ----A---- C:\WINDOWS\system32\wuaueng.dll
    2009-02-23 18:26:50 ----A---- C:\WINDOWS\system32\wuauclt1.exe
    2009-02-23 18:26:50 ----A---- C:\WINDOWS\system32\wuauclt.exe
    2009-02-23 18:26:50 ----A---- C:\WINDOWS\system32\wuapi.dll
    2009-02-23 18:26:50 ----A---- C:\WINDOWS\system32\qmgrprxy.dll
    2009-02-23 18:26:50 ----A---- C:\WINDOWS\system32\qmgr.dll
    2009-02-23 18:26:50 ----A---- C:\WINDOWS\system32\bitsprx4.dll
    2009-02-23 18:26:50 ----A---- C:\WINDOWS\system32\bitsprx3.dll
    2009-02-23 18:26:50 ----A---- C:\WINDOWS\system32\bitsprx2.dll
    2009-02-23 18:26:46 ----D---- C:\Program Files\Movie Maker
    2009-02-23 18:26:28 ----A---- C:\WINDOWS\system32\safrslv.dll
    2009-02-23 18:26:28 ----A---- C:\WINDOWS\system32\safrdm.dll
    2009-02-23 18:26:28 ----A---- C:\WINDOWS\system32\safrcdlg.dll
    2009-02-23 18:26:28 ----A---- C:\WINDOWS\system32\racpldlg.dll
    2009-02-23 18:26:25 ----A---- C:\WINDOWS\system32\fltMc.exe
    2009-02-23 18:26:25 ----A---- C:\WINDOWS\system32\fltlib.dll
    2009-02-23 18:26:24 ----D---- C:\WINDOWS\system32\Restore
    2009-02-23 18:26:24 ----A---- C:\WINDOWS\system32\srsvc.dll
    2009-02-23 18:26:24 ----A---- C:\WINDOWS\system32\srrstr.dll
    2009-02-23 18:26:24 ----A---- C:\WINDOWS\system32\srclient.dll
    2009-02-23 18:26:23 ----A---- C:\WINDOWS\system32\nmmkcert.dll
    2009-02-23 18:26:23 ----A---- C:\WINDOWS\system32\msconf.dll
    2009-02-23 18:26:23 ----A---- C:\WINDOWS\system32\mnmsrvc.exe
    2009-02-23 18:26:23 ----A---- C:\WINDOWS\system32\mnmdd.dll
    2009-02-23 18:26:23 ----A---- C:\WINDOWS\system32\isrdbg32.dll
    2009-02-23 18:26:23 ----A---- C:\WINDOWS\system32\ils.dll
    2009-02-23 18:26:20 ----D---- C:\Program Files\NetMeeting
    2009-02-23 18:26:20 ----A---- C:\WINDOWS\system32\msoert2.dll
    2009-02-23 18:26:20 ----A---- C:\WINDOWS\system32\msoeacct.dll
    2009-02-23 18:26:19 ----A---- C:\WINDOWS\system32\inetres.dll
    2009-02-23 18:26:19 ----A---- C:\WINDOWS\system32\inetcomm.dll
    2009-02-23 18:26:17 ----D---- C:\Program Files\Outlook Express
    2009-02-23 18:26:17 ----A---- C:\WINDOWS\system32\schedsvc.dll
    2009-02-23 18:26:17 ----A---- C:\WINDOWS\system32\mstinit.exe
    2009-02-23 18:26:17 ----A---- C:\WINDOWS\system32\mstask.dll
    2009-02-23 18:26:16 ----A---- C:\WINDOWS\system32\isign32.dll
    2009-02-23 18:26:16 ----A---- C:\WINDOWS\system32\inetcfg.dll
    2009-02-23 18:26:16 ----A---- C:\WINDOWS\system32\icwphbk.dll
    2009-02-23 18:26:16 ----A---- C:\WINDOWS\system32\icwdial.dll
    2009-02-23 18:26:10 ----D---- C:\Program Files\Fichiers communs\System
    2009-02-23 18:26:06 ----D---- C:\Program Files\Internet Explorer
    2009-02-23 18:25:32 ----D---- C:\Program Files\ComPlus Applications
    2009-02-23 18:25:30 ----A---- C:\WINDOWS\vbaddin.ini
    2009-02-23 18:25:30 ----A---- C:\WINDOWS\vb.ini
    2009-02-23 18:25:26 ----D---- C:\WINDOWS\Registration
    2009-02-23 18:25:19 ----D---- C:\Program Files\Online Services
    2009-02-23 18:25:18 ----D---- C:\Program Files\Windows Media Player
    2009-02-23 18:25:13 ----D---- C:\Program Files\Messenger
    2009-02-23 18:25:09 ----D---- C:\Program Files\MSN Gaming Zone
    2009-02-23 18:25:09 ----A---- C:\WINDOWS\system32\write.exe
    2009-02-23 18:25:00 ----A---- C:\WINDOWS\system32\sndvol32.exe
    2009-02-23 18:25:00 ----A---- C:\WINDOWS\system32\hticons.dll
    2009-02-23 18:25:00 ----A---- C:\WINDOWS\system32\avwav.dll
    2009-02-23 18:25:00 ----A---- C:\WINDOWS\system32\avtapi.dll
    2009-02-23 18:25:00 ----A---- C:\WINDOWS\system32\avmeter.dll
    2009-02-23 18:24:59 ----A---- C:\WINDOWS\system32\winchat.exe
    2009-02-23 18:24:53 ----A---- C:\WINDOWS\system32\getuname.dll
    2009-02-23 18:24:53 ----A---- C:\WINDOWS\system32\charmap.exe
    2009-02-23 18:24:53 ----A---- C:\WINDOWS\system32\calc.exe
    2009-02-23 18:24:52 ----A---- C:\WINDOWS\system32\winmine.exe
    2009-02-23 18:24:52 ----A---- C:\WINDOWS\system32\sol.exe
    2009-02-23 18:24:52 ----A---- C:\WINDOWS\system32\reset.exe
    2009-02-23 18:24:52 ----A---- C:\WINDOWS\system32\mshearts.exe
    2009-02-23 18:24:52 ----A---- C:\WINDOWS\system32\freecell.exe
    2009-02-23 18:24:51 ----A---- C:\WINDOWS\system32\usrlogon.cmd
    2009-02-23 18:24:51 ----A---- C:\WINDOWS\system32\tsshutdn.exe
    2009-02-23 18:24:51 ----A---- C:\WINDOWS\system32\tslabels.ini
    2009-02-23 18:24:51 ----A---- C:\WINDOWS\system32\tskill.exe
    2009-02-23 18:24:51 ----A---- C:\WINDOWS\system32\tsdiscon.exe
    2009-02-23 18:24:51 ----A---- C:\WINDOWS\system32\tscon.exe
    2009-02-23 18:24:51 ----A---- C:\WINDOWS\system32\shadow.exe
    2009-02-23 18:24:51 ----A---- C:\WINDOWS\system32\rwinsta.exe
    2009-02-23 18:24:51 ----A---- C:\WINDOWS\system32\regini.exe
    2009-02-23 18:24:51 ----A---- C:\WINDOWS\system32\rdpcfgex.dll
    2009-02-23 18:24:51 ----A---- C:\WINDOWS\system32\qwinsta.exe
    2009-02-23 18:24:51 ----A---- C:\WINDOWS\system32\qappsrv.exe
    2009-02-23 18:24:51 ----A---- C:\WINDOWS\system32\msg.exe
    2009-02-23 18:24:51 ----A---- C:\WINDOWS\system32\logoff.exe
    2009-02-23 18:24:50 ----A---- C:\WINDOWS\system32\msdtcprf.ini
    2009-02-23 18:24:50 ----A---- C:\WINDOWS\system32\cdmodem.dll
    2009-02-23 18:24:45 ----A---- C:\WINDOWS\system32\wmimgmt.msc
    2009-02-23 18:24:32 ----D---- C:\Program Files\MSN
    2009-02-23 18:24:31 ----A---- C:\WINDOWS\system32\sndrec32.exe
    2009-02-23 18:24:31 ----A---- C:\WINDOWS\system32\mplay32.exe
    2009-02-23 18:24:31 ----A---- C:\WINDOWS\system32\accwiz.exe
    2009-02-23 18:24:30 ----D---- C:\Program Files\Windows NT
    2009-02-23 18:24:30 ----A---- C:\WINDOWS\system32\mspaint.exe
    2009-02-23 18:24:30 ----A---- C:\WINDOWS\system32\hypertrm.dll
    2009-02-23 18:24:30 ----A---- C:\WINDOWS\system32\clipbrd.exe
    2009-02-23 18:24:29 ----A---- C:\WINDOWS\system32\spider.exe
    2009-02-23 18:24:28 ----A---- C:\WINDOWS\system32\tsgqec.dll
    2009-02-23 18:24:28 ----A---- C:\WINDOWS\system32\tscfgwmi.dll
    2009-02-23 18:24:28 ----A---- C:\WINDOWS\system32\rhttpaa.dll
    2009-02-23 18:24:28 ----A---- C:\WINDOWS\system32\aaclient.dll
    2009-02-23 18:24:27 ----A---- C:\WINDOWS\system32\sessmgr.exe
    2009-02-23 18:24:27 ----A---- C:\WINDOWS\system32\remotepg.dll
    2009-02-23 18:24:27 ----A---- C:\WINDOWS\system32\rdshost.exe
    2009-02-23 18:24:27 ----A---- C:\WINDOWS\system32\rdsaddin.exe
    2009-02-23 18:24:27 ----A---- C:\WINDOWS\system32\rdchost.dll
    2009-02-23 18:24:27 ----A---- C:\WINDOWS\system32\mstscax.dll
    2009-02-23 18:24:27 ----A---- C:\WINDOWS\system32\mstsc.exe
    2009-02-23 18:24:26 ----D---- C:\WINDOWS\system32\MsDtc
    2009-02-23 18:24:26 ----A---- C:\WINDOWS\system32\termsrv.dll
    2009-02-23 18:24:26 ----A---- C:\WINDOWS\system32\rdpwsx.dll
    2009-02-23 18:24:26 ----A---- C:\WINDOWS\system32\rdpsnd.dll
    2009-02-23 18:24:26 ----A---- C:\WINDOWS\system32\rdpclip.exe
    2009-02-23 18:24:26 ----A---- C:\WINDOWS\system32\qprocess.exe
    2009-02-23 18:24:26 ----A---- C:\WINDOWS\system32\mtxoci.dll
    2009-02-23 18:24:26 ----A---- C:\WINDOWS\system32\msdtcuiu.dll
    2009-02-23 18:24:26 ----A---- C:\WINDOWS\system32\icaapi.dll
    2009-02-23 18:24:26 ----A---- C:\WINDOWS\system32\cfgbkend.dll
    2009-02-23 18:24:25 ----A---- C:\WINDOWS\system32\xolehlp.dll
    2009-02-23 18:24:25 ----A---- C:\WINDOWS\system32\msdtctm.dll
    2009-02-23 18:24:25 ----A---- C:\WINDOWS\system32\msdtcprx.dll
    2009-02-23 18:24:25 ----A---- C:\WINDOWS\system32\msdtclog.dll
    2009-02-23 18:24:25 ----A---- C:\WINDOWS\system32\msdtc.exe
    2009-02-23 18:24:24 ----D---- C:\WINDOWS\system32\Com
    2009-02-23 18:24:24 ----A---- C:\WINDOWS\system32\mtxlegih.dll
    2009-02-23 18:24:24 ----A---- C:\WINDOWS\system32\mtxex.dll
    2009-02-23 18:24:24 ----A---- C:\WINDOWS\system32\mtxdm.dll
    2009-02-23 18:24:24 ----A---- C:\WINDOWS\system32\dcomcnfg.exe
    2009-02-23 18:24:24 ----A---- C:\WINDOWS\system32\comrepl.dll
    2009-02-23 18:24:24 ----A---- C:\WINDOWS\system32\comaddin.dll
    2009-02-23 18:24:24 ----A---- C:\WINDOWS\system32\colbact.dll
    2009-02-23 18:24:23 ----A---- C:\WINDOWS\system32\stclient.dll
    2009-02-23 18:24:23 ----A---- C:\WINDOWS\system32\comsvcs.dll
    2009-02-23 18:24:23 ----A---- C:\WINDOWS\system32\clbcatex.dll
    2009-02-23 18:24:23 ----A---- C:\WINDOWS\system32\catsrvut.dll
    2009-02-23 18:24:23 ----A---- C:\WINDOWS\system32\catsrvps.dll
    2009-02-23 18:24:23 ----A---- C:\WINDOWS\system32\catsrv.dll
    2009-02-23 18:24:22 ----A---- C:\WINDOWS\system32\comuid.dll
    2009-02-23 18:24:22 ----A---- C:\WINDOWS\system32\comsnap.dll
    2009-02-23 18:24:22 ----A---- C:\WINDOWS\system32\clbcatq.dll
    2009-02-23 18:24:15 ----A---- C:\WINDOWS\system32\servdeps.dll
    2009-02-23 18:24:15 ----A---- C:\WINDOWS\system32\mmfutil.dll
    2009-02-23 18:24:15 ----A---- C:\WINDOWS\system32\licwmi.dll
    2009-02-23 18:24:15 ----A---- C:\WINDOWS\system32\cmprops.dll

    ======List of files/folders modified in the last 1 months======

    2009-02-23 21:22:42 ----A---- C:\WINDOWS\win.ini
    2009-02-23 19:18:37 ----A---- C:\WINDOWS\system.ini

    ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

    R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2009-02-05 26944]
    R1 aswSP;avast! Self Protection; C:\WINDOWS\system32\drivers\aswSP.sys [2009-02-05 114768]
    R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2009-02-05 51376]
    R1 intelppm;Pilote de processeur Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-13 40576]
    R1 kbdhid;Pilote HID de clavier; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-13 14720]
    R1 WmiAcpi;Interface de gestion Microsoft Windows pour ACPI; C:\WINDOWS\system32\DRIVERS\wmiacpi.sys [2008-04-13 8832]
    R2 AegisP;AEGIS Protocol (IEEE 802.1x) v3.7.4.0; C:\WINDOWS\system32\DRIVERS\AegisP.sys [2009-02-23 21393]
    R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2009-02-05 20560]
    R2 aswMon2;avast! Standard Shield Support; C:\WINDOWS\system32\drivers\aswMon2.sys [2009-02-05 94032]
    R2 mdmxsdk;mdmxsdk; C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys [2006-06-19 12672]
    R2 rimmptsk;rimmptsk; C:\WINDOWS\system32\DRIVERS\rimmptsk.sys [2007-02-24 39936]
    R2 rimsptsk;rimsptsk; C:\WINDOWS\system32\DRIVERS\rimsptsk.sys [2007-01-23 42496]
    R2 rismxdp;Ricoh xD-Picture Card Driver; C:\WINDOWS\system32\DRIVERS\rixdptsk.sys [2007-03-21 37376]
    R2 s24trans;Transport RLAN; C:\WINDOWS\system32\DRIVERS\s24trans.sys [2007-05-29 12416]
    R3 ApfiltrService;Alps Touch Pad Filter Driver for Windows 2000/XP/Vista; C:\WINDOWS\system32\DRIVERS\Apfiltr.sys [2007-12-26 164400]
    R3 Arp1394;Protocole client ARP 1394; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-13 60800]
    R3 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2009-02-05 23152]
    R3 btaudio;Périphérique audio Bluetooth; C:\WINDOWS\system32\drivers\btaudio.sys [2007-03-23 539072]
    R3 BTDriver;Pilote de communications virtuelles Bluetooth; C:\WINDOWS\system32\DRIVERS\btport.sys [2007-03-23 37424]
    R3 BTKRNL;Enumérateur de bus Bluetooth; C:\WINDOWS\system32\DRIVERS\btkrnl.sys [2007-03-31 876384]
    R3 BTWDNDIS;Serveur d'accès au réseau local Bluetooth; C:\WINDOWS\system32\DRIVERS\btwdndis.sys [2007-03-23 149123]
    R3 btwmodem;Modem télécopieur Bluetooth; C:\WINDOWS\system32\DRIVERS\btwmodem.sys [2007-03-23 37280]
    R3 BTWUSB;WIDCOMM USB Bluetooth Driver; C:\WINDOWS\System32\Drivers\btwusb.sys [2007-03-23 67960]
    R3 CmBatt;Pilote d'adaptateur secteur Microsoft; C:\WINDOWS\system32\DRIVERS\CmBatt.sys [2008-04-13 13952]
    R3 HDAudBus;Pilote de bus Microsoft UAA pour High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
    R3 HidUsb;Pilote de classe HID Microsoft; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
    R3 HSF_DPV;HSF_DPV; C:\WINDOWS\system32\DRIVERS\HSF_DPV.sys [2007-08-02 989952]
    R3 HSFHWAZL;HSFHWAZL; C:\WINDOWS\system32\DRIVERS\HSFHWAZL.sys [2007-08-02 211200]
    R3 ialm;ialm; C:\WINDOWS\system32\DRIVERS\igxpmp32.sys [2007-08-24 5776928]
    R3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI Service; C:\WINDOWS\system32\drivers\IntcHdmi.sys [2007-05-04 105984]
    R3 mouhid;Pilote HID de souris; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-23 12288]
    R3 NETw4x32;Pilote de carte Intel(R) Wireless WiFi Link pour Windows XP 32 bits; C:\WINDOWS\system32\DRIVERS\NETw4x32.sys [2007-08-08 2211456]
    R3 NIC1394;Pilote réseau 1394; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-13 61824]
    R3 sdbus;sdbus; C:\WINDOWS\system32\DRIVERS\sdbus.sys [2008-04-13 79232]
    R3 STHDA;SigmaTel High Definition Audio CODEC; C:\WINDOWS\system32\drivers\sthda.sys [2007-05-10 1222840]
    R3 usbccgp;Pilote parent générique USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
    R3 usbehci;Pilote miniport de contrôleur d'hôte amélioré Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
    R3 usbhub;Pilote de concentrateur standard USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
    R3 usbuhci;Pilote miniport de contrôleur hôte universel USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
    R3 usbvideo;Périphérique vidéo USB (WDM); C:\WINDOWS\System32\Drivers\usbvideo.sys [2008-04-13 121984]
    R3 Wdf01000;Wdf01000; C:\WINDOWS\system32\DRIVERS\Wdf01000.sys [2006-11-02 492000]
    R3 winachsf;winachsf; C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys [2007-08-02 731136]
    S3 CCDECODE;Décodeur sous-titre fermé; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
    S3 MSTEE;Convertisseur en T/site-à-site de répartition Microsoft; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
    S3 NABTSFEC;Codec NABTS/FEC VBI; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
    S3 NdisIP;Connection TV/vidéo Microsoft; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
    S3 SLIP;Détrameur décalage BDA; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
    S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
    S3 USBSTOR;Pilote de stockage de masse USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
    S3 WSTCODEC;Codec Teletext standard; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
    S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
    S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
    S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []

    ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

    R2 aswUpdSv;avast! iAVS4 Control Service; C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe [2009-02-05 18752]
    R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast4\ashServ.exe [2009-02-05 138680]
    R2 btwdins;Bluetooth Service; C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe [2007-05-17 260968]
    R2 EvtEng;Intel(R) PROSet/Wireless Event Log; C:\Program Files\Intel\Wireless\Bin\EvtEng.exe [2007-07-25 647168]
    R2 RegSrvc;Intel(R) PROSet/Wireless Registry Service; C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe [2007-07-25 327680]
    R2 S24EventMonitor;Intel(R) PROSet/Wireless Service; C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe [2007-07-25 987136]
    R2 STacSV;SigmaTel Audio Service; C:\Program Files\SigmaTel\C-Major Audio\DellXPM_5515v133\WDM\STacSV.exe [2007-05-10 94208]
    R2 WLANKEEPER;Intel(R) PROSet/Wireless SSO Service; C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe [2007-07-25 294912]
    R3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe [2009-02-05 254040]
    R3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast4\ashWebSv.exe [2009-02-05 352920]
    R3 usnjsvc;Service Messenger Sharing Folders USN Journal Reader; C:\Program Files\MSN Messenger\usnsvc.exe [2007-01-19 97136]
    S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-02-26 138168]
    S3 WMPNetworkSvc;Service Partage réseau du Lecteur Windows Media; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-24 918016]
    S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-13 14336]

    -----------------EOF-----------------
    a c 267 8 Sécurité
    a b , Internet Explorer
    8 Mars 2009 22:27:54

  • Télécharge OTMoveIt3 (OldTimer) sur ton Bureau.
  • Double-clique sur OTMoveIt3.exe afin de le lancer.
  • Copie (Ctrl+C) le texte suivant ci-dessous :

    :processes
    explorer.exe

    :files
    C:\Documents and Settings\All Users\Application Data\book this clock drv

    :reg
    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    "clock drv coal bird"=-
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]

    :commands
    [purity]
    [emptytemp]
    [reboot]


  • Colle (Ctrl+V) le texte précédemment copié dans le cadre Paste Instructions for Items to be Moved.
  • Clique maintenant sur le bouton MoveIt! puis ferme OTMoveIt3.

    ---> Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
    Accepte en cliquant sur YES.

  • Poste le rapport situé dans ce dossier : C:\_OTMoveIt\MovedFiles\
    ---> Le nom du rapport correspond au moment de sa création : date_heure.log
    12 Mars 2009 19:57:05

    + de probleme de pub merci Destrio5
    a c 267 8 Sécurité
    a b , Internet Explorer
    12 Mars 2009 20:00:06

    Tu as fait la dernière manip' ?
    12 Mars 2009 20:01:10

    no
    a c 267 8 Sécurité
    a b , Internet Explorer
    12 Mars 2009 20:03:16

    Pourtant, elle sert à supprimer un dossier infecté par Lop d'où l'utilité de suivre mes recommandations.
    12 Mars 2009 20:13:34

    ========== PROCESSES ==========
    Process explorer.exe killed successfully.
    ========== FILES ==========
    File/Folder C:\Documents and Settings\All Users\Application Data\book this clock drv not found.
    ========== REGISTRY ==========
    Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\clock drv coal bird not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon\\ not found.
    ========== COMMANDS ==========
    File delete failed. C:\DOCUME~1\MOUNIR\LOCALS~1\Temp\etilqs_mxX011hAJEztaaLvGK9L scheduled to be deleted on reboot.
    File delete failed. C:\DOCUME~1\MOUNIR\LOCALS~1\Temp\etilqs_mxX011hAJEztaaLvGK9L-journal scheduled to be deleted on reboot.
    File delete failed. C:\DOCUME~1\MOUNIR\LOCALS~1\Temp\~DF7CE8.tmp scheduled to be deleted on reboot.
    File delete failed. C:\DOCUME~1\MOUNIR\LOCALS~1\Temp\~DFA440.tmp scheduled to be deleted on reboot.
    File delete failed. C:\DOCUME~1\MOUNIR\LOCALS~1\Temp\~DFA452.tmp scheduled to be deleted on reboot.
    File delete failed. C:\DOCUME~1\MOUNIR\LOCALS~1\Temp\~DFC1D2.tmp scheduled to be deleted on reboot.
    File delete failed. C:\DOCUME~1\MOUNIR\LOCALS~1\Temp\~DFF204.tmp scheduled to be deleted on reboot.
    File delete failed. C:\DOCUME~1\MOUNIR\LOCALS~1\Temp\~DFF216.tmp scheduled to be deleted on reboot.
    User's Temp folder emptied.
    User's Temporary Internet Files folder emptied.
    User's Internet Explorer cache folder emptied.
    Local Service Temp folder emptied.
    File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
    Local Service Temporary Internet Files folder emptied.
    File delete failed. C:\WINDOWS\temp\_avast4_\Webshlock.txt scheduled to be deleted on reboot.
    File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_5f8.dat scheduled to be deleted on reboot.
    Windows Temp folder emptied.
    FireFox cache emptied.
    Temp folders emptied.

    OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 03122009_200811

    Files moved on Reboot...
    File C:\DOCUME~1\MOUNIR\LOCALS~1\Temp\etilqs_mxX011hAJEztaaLvGK9L not found!
    File C:\DOCUME~1\MOUNIR\LOCALS~1\Temp\etilqs_mxX011hAJEztaaLvGK9L-journal not found!
    C:\DOCUME~1\MOUNIR\LOCALS~1\Temp\~DF7CE8.tmp moved successfully.
    File C:\DOCUME~1\MOUNIR\LOCALS~1\Temp\~DFA440.tmp not found!
    File C:\DOCUME~1\MOUNIR\LOCALS~1\Temp\~DFA452.tmp not found!
    C:\DOCUME~1\MOUNIR\LOCALS~1\Temp\~DFC1D2.tmp moved successfully.
    File C:\DOCUME~1\MOUNIR\LOCALS~1\Temp\~DFF204.tmp not found!
    File C:\DOCUME~1\MOUNIR\LOCALS~1\Temp\~DFF216.tmp not found!
    C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat moved successfully.
    File C:\WINDOWS\temp\_avast4_\Webshlock.txt not found!
    File C:\WINDOWS\temp\Perflib_Perfdata_5f8.dat not found!
    a c 267 8 Sécurité
    a b , Internet Explorer
    12 Mars 2009 20:21:45

    Bien. Pour finir :


    1/

  • Désinstalle HijackThis.

  • Télécharge ToolsCleaner2 sur ton Bureau.
  • Double-clique sur ToolsCleaner2.exe pour le lancer.
  • Clique sur Recherche et laisse le scan agir.
  • Clique sur Suppression pour finaliser.
  • Tu peux, si tu le souhaites, te servir des Options Facultatives.
  • Clique sur Quitter pour obtenir le rapport.
  • Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\).


    2/

  • Télécharge et installe CCleaner Slim.
  • Lance-le. Va dans Options puis Avancé et décoche la case Effacer uniquement les fichiers etc....
  • Va dans Nettoyeur, choisis Analyse. Une fois terminé, lance le nettoyage.
  • Ensuite, choisis Registre, puis Chercher des erreurs. Une fois terminé, répare toutes les erreurs (Sauvegarde la base de registre).


    3/

  • Il est nécessaire de désactiver puis réactiver la restauration système pour la purger.

  • Je te conseille de créer un point de restauration que tu pourras utiliser plus tard si tu as un problème.


    ==Prévention==

    Je te conseille de remplacer Avast par Antivir.

    Télécharge et installe Malwarebytes' Anti-Malware (MBAM). Il te servira à scanner les fichiers douteux en complément de l'antivirus et scanne le disque dur régulièrement.

    Comme navigateur, utilise plutôt Mozilla Firefox qu'Internet Explorer. Tu peux utiliser l'extension NoScript pour plus de sécurité.

    Vérifie que les mises à jour automatiques sont bien activées (Menu Démarrer, clique droit sur Poste de travail, onglet Mises à jour automatiques).

    Tu peux aussi modifier le fichier Hosts pour améliorer la sécurité de ton PC : Lien

    Par rapport au P2P : Lien

    Voici un dossier complet (A lire avec Adobe Reader ou Foxit Reader) : Lien


    ==Problème résolu ?==

    Si tu estimes que ton problème est résolu :

    ---> Ajoute maintenant [Résolu] au titre. Pour cela :
  • Clique, dans ton premier message, sur le bouton Editer .
  • Rajoute la mention [Résolu] devant le titre.
  • Clique ensuite sur Valider votre message.


    Sois plus vigilant(e) sur Internet ;) 
    12 Mars 2009 20:35:23

    [ Rapport ToolsCleaner version 2.3.2 (par A.Rothstein & dj QUIOU) ]

    -->- Recherche:


    ---------------------------------
    -->- Suppression:

    a c 267 8 Sécurité
    a b , Internet Explorer
    12 Mars 2009 20:38:40

    Tu peux supprimer ToolsCleaner.
    12 Mars 2009 20:40:23

    merci a toi destrio5
    a c 267 8 Sécurité
    a b , Internet Explorer
    12 Mars 2009 20:41:39

    Bonne soirée ;) 
    Tom's guide dans le monde
    • Allemagne
    • Italie
    • Irlande
    • Royaume Uni
    • Etats Unis
    Suivre Tom's Guide
    Inscrivez-vous à la Newsletter
    • ajouter à twitter
    • ajouter à facebook
    • ajouter un flux RSS