Votre question

Pub Intempestives(CID)... [Résolu]

Tags :
  • Sécurité
Dernière réponse : dans Sécurité et virus
15 Septembre 2008 22:05:03

Bonjour à tous !

Voici mon problème, depuis 4 jours, suite à l'ouverture d'un mail dont je ne connaissais pas le destinataire, j'ai sans arrêt des pages de pub intempestives qui ne font que de s'ouvrir (orange, voyance web ect...). Ca va jusque 10 par minute et c'est très embetant ! Voici mon rapport Hijack.

Merci beaucoup pour votrai aide.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:04:26, on 15/09/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Belkin\Logiciel Bluetooth\bin\btwdins.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Acer\Empowering Technology\eRecovery\Monitor.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Acer\Acer eMode Management\AspireService.exe
C:\Program Files\Acer\Acer eConsole\MediaSync.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Belkin\Logiciel Bluetooth\BTTray.exe
C:\Program Files\TRENDnet\TEW-424UB\WlanCU.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Fichiers communs\Real\Update_OB\RealOneMessageCenter.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://fr.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [LaunchApp] Alaunch
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AspireService] C:\Program Files\Acer\Acer eMode Management\AspireService.exe
O4 - HKLM\..\Run: [MediaSync] C:\Program Files\Acer\Acer eConsole\MediaSync.exe
O4 - HKLM\..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\Monitor.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [EEventManager] C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Proc pure bold multi] C:\Documents and Settings\All Users\Application Data\aim mix proc pure\Cash chin.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Instant Access] rundll32.exe EGACCESS4_1066.dll,InstantAccess
O4 - HKCU\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [tmhcjda] c:\windows\system32\tmhcjda.exe tmhcjda
O4 - HKCU\..\Run: [svchost] C:\WINDOWS\svchost.exe
O4 - HKCU\..\Run: [gprhvtwlx] c:\windows\system32\gprhvtwlx.exe gprhvtwlx
O4 - HKCU\..\Run: [ajkgyoct] c:\windows\system32\ajkgyoct.exe ajkgyoct
O4 - HKCU\..\Run: [book ante] C:\DOCUME~1\PAPAOU~1\APPLIC~1\ELSEPL~1\AXISNEW.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Wireless Configuration Utility HW.14.lnk = C:\Program Files\TRENDnet\TEW-424UB\WlanCU.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Belkin\Logiciel Bluetooth\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Belkin\Logiciel Bluetooth\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267....
O16 - DPF: {029FDBA6-3547-11D7-AA4C-0050BF051A00} (Rawflow ICD Client) - http://s.tf1.fr/mmdia/static/rawflow/clients/5.3.1.0/Ra...
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/FacebookPhotoUpload...
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.ca...
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClie...
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game01.zylom.com/activex/zylomgamesplayer.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPACl...
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/fl...
O16 - DPF: {DF1C8E21-4045-4D67-B528-335F1A4F0DE9} - http://scripts.dlv4.com/binaries/egaccess4/egaccess4_10...
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown....
O17 - HKLM\System\CCS\Services\Tcpip\..\{34D677D2-65BC-45BA-A13F-C44FF0044F0F}: NameServer = 84.103.237.143 86.64.145.143
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\Belkin\Logiciel Bluetooth\bin\btwdins.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Performance Monitor - Unknown owner - C:\WINDOWS\perfmon.exe (file missing)
O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe

--
End of file - 11953 bytes

Autres pages sur : pub intempestives cid resolu

a b 8 Sécurité
16 Septembre 2008 12:56:57

Bonjour,

Télécharge Navilog1.exe (IL-MAFIOSO)
Enregistre-le sur ton Bureau.
Lance l'installation en double cliquant sur navilog.exe.
Une fois l'installation terminée, l'utilitaire s'exécutera automatiquement.
(Si ce n'est pas le cas, double clique sur le raccourci présent sur le Bureau)

Laisse-toi guider par l'utilitaire. Choisis l'option 1 puis valide.
[#ff0000]! N'utilise pas l'option 2, 3 et 4 sans notre accord ![/#f]
Patiente jusqu'à l'apparition de ce message :
"*** Analyse Termine le ..... ***"
Appuie sur une touche comme demandé. Le Bloc-notes va s'ouvrir. Poste-nous son contenu de cette manière :

-> Edition / Sélectionner tout
-> Edition / Copier
-> Clique-Droit / Coller dans ta réponse


NOTE : Le rapport se trouve également ici : C:\fixnavi.txt
16 Septembre 2008 14:51:49

Merci de votre aide, voici le rapport


Search Navipromo version 3.6.5 commencé le 16/09/2008 à 14:49:14,84

!!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
!!! Postez ce rapport sur le forum pour le faire analyser !!!
!!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

Outil exécuté depuis C:\Program Files\navilog1
Session actuelle : "PAPA OU MAMAN"

Mise à jour le 22.08.2008 à 17h30 par IL-MAFIOSO


Microsoft Windows XP [version 5.1.2600]
Internet Explorer : 7.0.5730.11
Système de fichiers : FAT32

Recherche executé en mode normal

*** Recherche Programmes installés ***


*** Recherche dossiers dans "C:\WINDOWS" ***


*** Recherche dossiers dans "C:\Program Files" ***


*** Recherche dossiers dans "C:\Documents and Settings\All Users\menudÉ~1\progra~1" ***


*** Recherche dossiers dans "C:\Documents and Settings\All Users\menudÉ~1" ***


*** Recherche dossiers dans "c:\docume~1\alluse~1\applic~1" ***


*** Recherche dossiers dans "C:\Documents and Settings\PAPA OU MAMAN\applic~1" ***


*** Recherche dossiers dans "C:\DOCUME~1\HAMIDI~1\applic~1" ***


*** Recherche dossiers dans "C:\DOCUME~1\SAMIR\applic~1" ***


*** Recherche dossiers dans "C:\DOCUME~1\ADMINI~1\applic~1" ***


*** Recherche dossiers dans "C:\Documents and Settings\PAPA OU MAMAN\locals~1\applic~1" ***


*** Recherche dossiers dans "C:\DOCUME~1\HAMIDI~1\locals~1\applic~1" ***


*** Recherche dossiers dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" ***


*** Recherche dossiers dans "C:\Documents and Settings\PAPA OU MAMAN\menud+~1\progra~1" ***


*** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
pour + d'infos : http://www.gmer.net



*** Recherche avec GenericNaviSearch ***
!!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
!!! A vérifier impérativement avant toute suppression manuelle !!!

* Recherche dans "C:\WINDOWS\system32" *

* Recherche dans "C:\Documents and Settings\PAPA OU MAMAN\locals~1\applic~1" *

* Recherche dans "C:\DOCUME~1\HAMIDI~1\locals~1\applic~1" *

* Recherche dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" *



*** Recherche fichiers ***


C:\WINDOWS\Downloaded Program Files\egaccess4.inf trouvé !

*** Recherche clés spécifiques dans le Registre ***


*** Module de Recherche complémentaire ***
(Recherche fichiers spécifiques)

1)Recherche nouveaux fichiers Instant Access :


2)Recherche Heuristique :

* Dans "C:\WINDOWS\system32" :


* Dans "C:\Documents and Settings\PAPA OU MAMAN\locals~1\applic~1" :


* Dans "C:\DOCUME~1\HAMIDI~1\locals~1\applic~1" :


* Dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" :


3)Recherche Certificats :

Certificat Egroup trouvé !
Certificat Electronic-Group absent !
Certificat Montorgueil absent !
Certificat OOO-Favorit absent !
Certificat Sunny-Day-Design-Ltd absent !

4)Recherche fichiers connus :



*** Analyse terminée le 16/09/2008 à 14:51:35,50 ***
Contenus similaires
a b 8 Sécurité
16 Septembre 2008 20:12:37

Re,

Double clique sur le raccourci de Navilog1 présent sur ton Bureau.
Suis les instructions. Choisis ensuite l'option 2 puis valide.
Laisse toi guider et réponds aux questions éventuelles.

L'utilitaire va t'informer qu'il va redémarrer l'ordinateur.
[#ff0000]**Ferme toutes les fenêtres ouvertes et enregistre tes documents personnels ouverts**[/#f]
Appuie maintenant sur une touche, comme demandé.
(si ton PC ne redémarre pas automatiquement, fais-le manuellement)

Patiente jusqu'à l'apparition de ce message :
"*** Nettoyage Termine le ..... ***"

Le Bloc-notes va s'ouvrir.
Sauvegarde le rapport de manière à le retrouver.
Referme le Bloc-notes. Ton bureau va maintenant réapparaître.

NOTE : Si ton Bureau ne réapparait pas, appuie simultanément sur Ctrl+Alt+Suppr pour ouvrir le Gestionnaire des tâches.
Rends-toi sur l'onglet "Processus". Clique en haut à gauche sur Fichier et choisis "Exécuter..."
Tape explorer puis valide.

Poste le rapport sauvegardé auparavant (C:\cleannavi.txt)
Ainsi qu'un nouveau rapport Hijackthis.
16 Septembre 2008 20:47:49

Clean Navipromo version 3.6.5 commencé le 16/09/2008 à 20:40:06,09

Outil exécuté depuis C:\Program Files\navilog1
Session actuelle : "PAPA OU MAMAN"

Mise à jour le 22.08.2008 à 17h30 par IL-MAFIOSO


Microsoft Windows XP [version 5.1.2600]
Internet Explorer : 7.0.5730.11
Système de fichiers : FAT32

Mode suppression automatique
avec prise en charge résultats Catchme et GNS


Nettoyage exécuté au redémarrage de l'ordinateur


*** fsbl1.txt non trouvé ***
(Assurez-vous que Catchme n'avait rien trouvé lors de la recherche)


*** Suppression avec sauvegardes résultats GenericNaviSearch ***

* Suppression dans "C:\WINDOWS\System32" *


* Suppression dans "C:\Documents and Settings\PAPA OU MAMAN\locals~1\applic~1" *


* Suppression dans "C:\DOCUME~1\HAMIDI~1\locals~1\applic~1" *

* Suppression dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" *


*** Suppression dossiers dans "C:\WINDOWS" ***


*** Suppression dossiers dans "C:\Program Files" ***


*** Suppression dossiers dans "C:\Documents and Settings\All Users\menudÉ~1\progra~1" ***


*** Suppression dossiers dans "C:\Documents and Settings\All Users\menudÉ~1" ***


*** Suppression dossiers dans "c:\docume~1\alluse~1\applic~1" ***


*** Suppression dossiers dans "C:\Documents and Settings\PAPA OU MAMAN\applic~1" ***


*** Suppression dossiers dans "C:\DOCUME~1\HAMIDI~1\applic~1" ***


*** Suppression dossiers dans "C:\DOCUME~1\SAMIR\applic~1" ***


*** Suppression dossiers dans "C:\DOCUME~1\ADMINI~1\applic~1" ***


*** Suppression dossiers dans "C:\Documents and Settings\PAPA OU MAMAN\locals~1\applic~1" ***


*** Suppression dossiers dans "C:\DOCUME~1\HAMIDI~1\locals~1\applic~1" ***


*** Suppression dossiers dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" ***


*** Suppression dossiers dans "C:\Documents and Settings\PAPA OU MAMAN\menud+~1\progra~1" ***



*** Suppression fichiers ***

C:\WINDOWS\Downloaded Program Files\egaccess4.inf supprimé !

*** Suppression fichiers temporaires ***

Nettoyage contenu C:\WINDOWS\Temp effectué !
Nettoyage contenu C:\Documents and Settings\PAPA OU MAMAN\locals~1\Temp effectué !

*** Traitement Recherche complémentaire ***
(Recherche fichiers spécifiques)

1)Suppression avec sauvegardes nouveaux fichiers Instant Access :

2)Recherche, création sauvegardes et suppression Heuristique :


* Dans "C:\WINDOWS\system32" *


* Dans "C:\Documents and Settings\PAPA OU MAMAN\locals~1\applic~1" *


* Dans "C:\DOCUME~1\HAMIDI~1\locals~1\applic~1" *


* Dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" *


*** Sauvegarde du Registre vers dossier Safebackup ***

sauvegarde du Registre réalisée avec succès !

*** Nettoyage Registre ***

Nettoyage Registre Ok


*** Certificats ***

Certificat Egroup supprimé !
Certificat Electronic-Group absent !
Certificat Montorgueil absent !
Certificat OOO-Favorit absent !
Certificat Sunny-Day-Design-Ltdt absent !

*** Clés RUN orphelines Navipromo ***
!! Résultats temporairement non pris en charge !!
!! Les clés trouvées ne sont pas forcément infectées !!

Clés trouvés :

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"tmhcjda"="c:\\windows\\system32\\tmhcjda.exe tmhcjda"

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"gprhvtwlx"="c:\\windows\\system32\\gprhvtwlx.exe gprhvtwlx"

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ajkgyoct"="c:\\windows\\system32\\ajkgyoct.exe ajkgyoct"


*** Nettoyage terminé le 16/09/2008 à 20:43:42,62 ***

16 Septembre 2008 20:48:20

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:48:05, on 16/09/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Belkin\Logiciel Bluetooth\bin\btwdins.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Acer\Empowering Technology\eRecovery\Monitor.exe
C:\Program Files\Acer\Acer eMode Management\AspireService.exe
C:\Program Files\Acer\Acer eConsole\MediaSync.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Belkin\Logiciel Bluetooth\BTTray.exe
C:\Program Files\TRENDnet\TEW-424UB\WlanCU.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://fr.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [LaunchApp] Alaunch
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AspireService] C:\Program Files\Acer\Acer eMode Management\AspireService.exe
O4 - HKLM\..\Run: [MediaSync] C:\Program Files\Acer\Acer eConsole\MediaSync.exe
O4 - HKLM\..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\Monitor.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [EEventManager] C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Proc pure bold multi] C:\Documents and Settings\All Users\Application Data\aim mix proc pure\Cash chin.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [tmhcjda] c:\windows\system32\tmhcjda.exe tmhcjda
O4 - HKCU\..\Run: [svchost] C:\WINDOWS\svchost.exe
O4 - HKCU\..\Run: [gprhvtwlx] c:\windows\system32\gprhvtwlx.exe gprhvtwlx
O4 - HKCU\..\Run: [ajkgyoct] c:\windows\system32\ajkgyoct.exe ajkgyoct
O4 - HKCU\..\Run: [book ante] C:\DOCUME~1\PAPAOU~1\APPLIC~1\ELSEPL~1\AXISNEW.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Wireless Configuration Utility HW.14.lnk = C:\Program Files\TRENDnet\TEW-424UB\WlanCU.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Belkin\Logiciel Bluetooth\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Belkin\Logiciel Bluetooth\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267....
O16 - DPF: {029FDBA6-3547-11D7-AA4C-0050BF051A00} (Rawflow ICD Client) - http://s.tf1.fr/mmdia/static/rawflow/clients/5.3.1.0/Ra...
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/FacebookPhotoUpload...
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.ca...
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClie...
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game01.zylom.com/activex/zylomgamesplayer.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPACl...
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/fl...
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown....
O17 - HKLM\System\CCS\Services\Tcpip\..\{34D677D2-65BC-45BA-A13F-C44FF0044F0F}: NameServer = 84.103.237.142 86.64.145.142
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\Belkin\Logiciel Bluetooth\bin\btwdins.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Performance Monitor - Unknown owner - C:\WINDOWS\perfmon.exe (file missing)
O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe

--
End of file - 11372 bytes
a b 8 Sécurité
16 Septembre 2008 20:49:23

Reposte un rapport Hijackthis.
16 Septembre 2008 20:50:30

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:50:17, on 16/09/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Belkin\Logiciel Bluetooth\bin\btwdins.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Acer\Empowering Technology\eRecovery\Monitor.exe
C:\Program Files\Acer\Acer eMode Management\AspireService.exe
C:\Program Files\Acer\Acer eConsole\MediaSync.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Belkin\Logiciel Bluetooth\BTTray.exe
C:\Program Files\TRENDnet\TEW-424UB\WlanCU.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://fr.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [LaunchApp] Alaunch
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AspireService] C:\Program Files\Acer\Acer eMode Management\AspireService.exe
O4 - HKLM\..\Run: [MediaSync] C:\Program Files\Acer\Acer eConsole\MediaSync.exe
O4 - HKLM\..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\Monitor.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [EEventManager] C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Proc pure bold multi] C:\Documents and Settings\All Users\Application Data\aim mix proc pure\Cash chin.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [tmhcjda] c:\windows\system32\tmhcjda.exe tmhcjda
O4 - HKCU\..\Run: [svchost] C:\WINDOWS\svchost.exe
O4 - HKCU\..\Run: [gprhvtwlx] c:\windows\system32\gprhvtwlx.exe gprhvtwlx
O4 - HKCU\..\Run: [ajkgyoct] c:\windows\system32\ajkgyoct.exe ajkgyoct
O4 - HKCU\..\Run: [book ante] C:\DOCUME~1\PAPAOU~1\APPLIC~1\ELSEPL~1\AXISNEW.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Wireless Configuration Utility HW.14.lnk = C:\Program Files\TRENDnet\TEW-424UB\WlanCU.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Belkin\Logiciel Bluetooth\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Belkin\Logiciel Bluetooth\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267....
O16 - DPF: {029FDBA6-3547-11D7-AA4C-0050BF051A00} (Rawflow ICD Client) - http://s.tf1.fr/mmdia/static/rawflow/clients/5.3.1.0/Ra...
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/FacebookPhotoUpload...
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.ca...
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClie...
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game01.zylom.com/activex/zylomgamesplayer.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPACl...
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/fl...
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown....
O17 - HKLM\System\CCS\Services\Tcpip\..\{34D677D2-65BC-45BA-A13F-C44FF0044F0F}: NameServer = 84.103.237.142 86.64.145.142
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\Belkin\Logiciel Bluetooth\bin\btwdins.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Performance Monitor - Unknown owner - C:\WINDOWS\perfmon.exe (file missing)
O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe

--
End of file - 11339 bytes
a b 8 Sécurité
16 Septembre 2008 20:56:55

Re,

Fix les lignes dans le cadre ci-dessous avec HijackThis : AIDE EN IMAGES

O4 - HKCU\..\Run: [tmhcjda] c:\windows\system32\tmhcjda.exe tmhcjda
O4 - HKCU\..\Run: [svchost] C:\WINDOWS\svchost.exe
O4 - HKCU\..\Run: [gprhvtwlx] c:\windows\system32\gprhvtwlx.exe gprhvtwlx
O4 - HKCU\..\Run: [ajkgyoct] c:\windows\system32\ajkgyoct.exe ajkgyoct


&

Télécharge Lop S&D.exe ([#ff0000]Eric_71[/#f]) sur ton Bureau.

  • Lance l'installation du programme en exécutant le fichier téléchargé.
  • Double-clique maintenant sur le raccourci de LopS&D.
  • Sélectionne la langue souhaitée en tapant la lettre de ton choix puis en validant avec la touche Entrée.
  • Choisis maintenant l'option 1 (Recherche). Patiente jusqu'à la fin de la recherche.
  • Poste le rapport généré (C:\lopR.txt*)
    16 Septembre 2008 21:07:47


    --------------------\\ Lop S&D 4.2.4-3 XP/Vista

    Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 3
    X86-based PC ( Uniprocessor Free : AMD Athlon(tm) 64 Processor 3400+ )
    BIOS : )Phoenix - Award WorkstationBIOS v6.00PG
    USER : PAPA OU MAMAN ( Administrator )
    BOOT : Normal boot
    Antivirus : Avira AntiVir PersonalEdition 8.0.1.27 (Activated)
    C:\ (Local Disk) - FAT32 - Total : 72 Go Free : 22 Go
    D:\ (Local Disk) - FAT32 - Total : 72 Go Free : 72 Go
    E:\ (CD or DVD)
    F:\ (USB)
    G:\ (USB)
    H:\ (USB)
    I:\ (USB)

    "C:\Lop SD" ( MAJ : 14-09-2008|22:40 )
    Option : [1] ( 16/09/2008|21:05 )

    --------------------\\ Listing des dossiers dans APPLIC~1

    [23/01/2005|12:07] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Identities
    [23/01/2005|11:51] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft
    [23/01/2005|12:13] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Symantec

    [06/10/2006|16:57] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
    [12/09/2008|23:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\aim mix proc pure
    [09/09/2007|09:41] C:\DOCUME~1\ALLUSE~1\APPLIC~1\AntiVir PersonalEdition Classic
    [12/07/2007|18:54] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple
    [23/12/2006|19:41] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
    [31/03/2006|13:38] C:\DOCUME~1\ALLUSE~1\APPLIC~1\avg7
    [20/08/2006|22:22] C:\DOCUME~1\ALLUSE~1\APPLIC~1\BOONTY
    [02/06/2007|17:44] C:\DOCUME~1\ALLUSE~1\APPLIC~1\CopyPod
    [25/02/2006|16:48] C:\DOCUME~1\ALLUSE~1\APPLIC~1\CyberLink
    [25/02/2006|16:46] C:\DOCUME~1\ALLUSE~1\APPLIC~1\eConsole
    [30/05/2007|13:12] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
    [08/09/2007|19:38] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Grisoft
    [24/12/2006|22:13] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Messenger Plus!
    [23/01/2005|11:51] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
    [31/07/2007|17:39] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Mozilla
    [01/05/2006|19:01] C:\DOCUME~1\ALLUSE~1\APPLIC~1\mp3copyclockfork
    [28/05/2007|16:19] C:\DOCUME~1\ALLUSE~1\APPLIC~1\OFFICE One v7
    [02/04/2007|10:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\QuickTime
    [19/06/2006|20:01] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Skype
    [23/01/2005|12:13] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec
    [31/03/2006|13:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WinAntiVirus Pro 2006
    [29/11/2006|22:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
    [02/06/2007|23:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WindowsLiveInstaller
    [02/06/2007|23:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller
    [09/04/2008|13:16] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Yahoo! Companion
    [03/09/2006|13:37] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Zylom

    [23/01/2005|11:51] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft
    [23/03/2006|20:30] C:\DOCUME~1\NETWOR~1\APPLIC~1\Symantec

    [31/03/2006|13:40] C:\DOCUME~1\LOCALS~1\APPLIC~1\AVG7
    [23/01/2005|11:51] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft

    [25/02/2006|16:35] C:\DOCUME~1\HAMIDI~1\APPLIC~1\Adobe
    [27/04/2006|17:06] C:\DOCUME~1\HAMIDI~1\APPLIC~1\AdobeUM
    [26/06/2006|21:49] C:\DOCUME~1\HAMIDI~1\APPLIC~1\Ahead
    [23/12/2006|19:42] C:\DOCUME~1\HAMIDI~1\APPLIC~1\Apple Computer
    [10/03/2006|14:50] C:\DOCUME~1\HAMIDI~1\APPLIC~1\ArcSoft
    [31/03/2006|13:38] C:\DOCUME~1\HAMIDI~1\APPLIC~1\AVG7
    [22/03/2007|22:22] C:\DOCUME~1\HAMIDI~1\APPLIC~1\CopyPod
    [22/03/2007|22:23] C:\DOCUME~1\HAMIDI~1\APPLIC~1\CopyPodPhoto
    [25/02/2006|16:58] C:\DOCUME~1\HAMIDI~1\APPLIC~1\CyberLink
    [08/12/2006|17:28] C:\DOCUME~1\HAMIDI~1\APPLIC~1\DivX
    [18/05/2006|19:12] C:\DOCUME~1\HAMIDI~1\APPLIC~1\Droppix
    [01/05/2006|19:00] C:\DOCUME~1\HAMIDI~1\APPLIC~1\Else plus
    [15/05/2007|13:59] C:\DOCUME~1\HAMIDI~1\APPLIC~1\Eltima Software
    [18/11/2006|13:43] C:\DOCUME~1\HAMIDI~1\APPLIC~1\EPSON
    [24/03/2006|09:45] C:\DOCUME~1\HAMIDI~1\APPLIC~1\Google
    [08/09/2007|19:39] C:\DOCUME~1\HAMIDI~1\APPLIC~1\Grisoft
    [12/03/2006|11:36] C:\DOCUME~1\HAMIDI~1\APPLIC~1\Help
    [22/03/2007|22:21] C:\DOCUME~1\HAMIDI~1\APPLIC~1\iCloner
    [23/01/2005|12:07] C:\DOCUME~1\HAMIDI~1\APPLIC~1\Identities
    [26/03/2006|19:24] C:\DOCUME~1\HAMIDI~1\APPLIC~1\Lavasoft
    [06/10/2006|20:08] C:\DOCUME~1\HAMIDI~1\APPLIC~1\Leadertech
    [23/03/2006|16:48] C:\DOCUME~1\HAMIDI~1\APPLIC~1\Macromedia
    [23/01/2005|11:51] C:\DOCUME~1\HAMIDI~1\APPLIC~1\Microsoft
    [28/02/2006|18:17] C:\DOCUME~1\HAMIDI~1\APPLIC~1\Microsoft Web Folders
    [08/12/2006|17:16] C:\DOCUME~1\HAMIDI~1\APPLIC~1\Mozilla
    [08/10/2006|10:55] C:\DOCUME~1\HAMIDI~1\APPLIC~1\MSNInstaller
    [06/08/2006|13:02] C:\DOCUME~1\HAMIDI~1\APPLIC~1\Not a Number
    [28/05/2007|16:40] C:\DOCUME~1\HAMIDI~1\APPLIC~1\OpenOffice.org2
    [24/03/2006|09:43] C:\DOCUME~1\HAMIDI~1\APPLIC~1\Real
    [14/10/2007|16:48] C:\DOCUME~1\HAMIDI~1\APPLIC~1\Samsung
    [09/04/2007|14:14] C:\DOCUME~1\HAMIDI~1\APPLIC~1\Screenshot Sender
    [21/06/2007|18:24] C:\DOCUME~1\HAMIDI~1\APPLIC~1\SecondLife
    [19/06/2006|20:01] C:\DOCUME~1\HAMIDI~1\APPLIC~1\Skype
    [28/02/2006|12:33] C:\DOCUME~1\HAMIDI~1\APPLIC~1\Sun
    [23/01/2005|12:13] C:\DOCUME~1\HAMIDI~1\APPLIC~1\Symantec
    [31/07/2007|17:40] C:\DOCUME~1\HAMIDI~1\APPLIC~1\Talkback
    [27/05/2006|23:47] C:\DOCUME~1\HAMIDI~1\APPLIC~1\vlc
    [11/04/2008|19:59] C:\DOCUME~1\HAMIDI~1\APPLIC~1\Yahoo!

    [08/12/2006|15:46] C:\DOCUME~1\SAMIR\APPLIC~1\Mozilla

    [14/01/2007|15:06] C:\DOCUME~1\PAPAOU~1\APPLIC~1\Adobe
    [15/01/2008|13:28] C:\DOCUME~1\PAPAOU~1\APPLIC~1\Apple Computer
    [05/12/2006|20:52] C:\DOCUME~1\PAPAOU~1\APPLIC~1\ArcSoft
    [22/11/2006|20:30] C:\DOCUME~1\PAPAOU~1\APPLIC~1\AVG7
    [10/04/2008|15:56] C:\DOCUME~1\PAPAOU~1\APPLIC~1\DivX
    [12/09/2008|23:35] C:\DOCUME~1\PAPAOU~1\APPLIC~1\Else plus
    [20/11/2006|20:52] C:\DOCUME~1\PAPAOU~1\APPLIC~1\EPSON
    [25/03/2006|21:28] C:\DOCUME~1\PAPAOU~1\APPLIC~1\Google
    [09/09/2007|20:41] C:\DOCUME~1\PAPAOU~1\APPLIC~1\Grisoft
    [23/01/2005|12:07] C:\DOCUME~1\PAPAOU~1\APPLIC~1\Identities
    [27/05/2006|18:52] C:\DOCUME~1\PAPAOU~1\APPLIC~1\Lavasoft
    [25/03/2006|21:29] C:\DOCUME~1\PAPAOU~1\APPLIC~1\Macromedia
    [23/01/2005|11:51] C:\DOCUME~1\PAPAOU~1\APPLIC~1\Microsoft
    [25/03/2006|21:28] C:\DOCUME~1\PAPAOU~1\APPLIC~1\Real
    [15/04/2006|14:29] C:\DOCUME~1\PAPAOU~1\APPLIC~1\ShopperReports
    [11/03/2007|00:20] C:\DOCUME~1\PAPAOU~1\APPLIC~1\Sun
    [23/01/2005|12:13] C:\DOCUME~1\PAPAOU~1\APPLIC~1\Symantec
    [25/02/2008|15:52] C:\DOCUME~1\PAPAOU~1\APPLIC~1\vlc
    [09/04/2008|13:16] C:\DOCUME~1\PAPAOU~1\APPLIC~1\Yahoo!

    [08/09/2007|19:44] C:\DOCUME~1\ADMINI~1\APPLIC~1\Grisoft
    [23/01/2005|12:07] C:\DOCUME~1\ADMINI~1\APPLIC~1\Identities
    [23/01/2005|11:51] C:\DOCUME~1\ADMINI~1\APPLIC~1\Microsoft
    [23/01/2005|12:13] C:\DOCUME~1\ADMINI~1\APPLIC~1\Symantec

    --------------------\\ Tâches planifiées dans C:\WINDOWS\tasks

    [04/09/2008 21:57][--a------] C:\WINDOWS\tasks\AppleSoftwareUpdate.job
    [16/09/2008 20:42][--ah-----] C:\WINDOWS\tasks\SA.DAT
    [05/08/2004 05:00][-r-h-----] C:\WINDOWS\tasks\desktop.ini

    --------------------\\ Listing des dossiers dans C:\Program Files

    [25/02/2006|16:30] C:\Program Files\Acer
    [23/01/2005|12:10] C:\Program Files\Adobe
    [04/08/2006|18:21] C:\Program Files\Ahead
    [23/11/2006|21:53] C:\Program Files\Alwil Software
    [23/01/2005|12:16] C:\Program Files\AMD
    [16/08/2006|22:12] C:\Program Files\Antipub
    [09/09/2007|09:41] C:\Program Files\AntiVir PersonalEdition Classic
    [23/12/2006|19:41] C:\Program Files\Apple Software Update
    [11/09/2007|17:31] C:\Program Files\Audacity
    [23/01/2005|11:57] C:\Program Files\AviSynth 2.5
    [04/08/2006|19:13] C:\Program Files\AvRack
    [10/11/2006|14:03] C:\Program Files\Belkin
    [04/04/2007|18:41] C:\Program Files\BlueSquad
    [20/08/2006|20:43] C:\Program Files\Boonty
    [20/08/2006|20:43] C:\Program Files\BoontyGames
    [05/01/2008|14:14] C:\Program Files\Circle Developement
    [31/03/2006|13:31] C:\Program Files\Common Files
    [23/01/2005|11:56] C:\Program Files\ComPlus Applications
    [02/06/2007|17:44] C:\Program Files\CopyPod
    [23/01/2005|12:13] C:\Program Files\CyberLink
    [26/03/2006|20:14] C:\Program Files\DivX
    [04/07/2006|20:12] C:\Program Files\Droppix
    [12/09/2008|23:35] C:\Program Files\Else plus
    [15/05/2007|13:59] C:\Program Files\Eltima Software
    [23/03/2006|14:31] C:\Program Files\eMule
    [18/11/2006|13:27] C:\Program Files\epson
    [18/04/2007|21:41] C:\Program Files\eRightSoft
    [23/01/2005|11:52] C:\Program Files\Fichiers communs
    [22/07/2007|16:21] C:\Program Files\Free Audio Pack
    [15/05/2007|14:59] C:\Program Files\GetFlash
    [24/03/2006|09:45] C:\Program Files\Google
    [31/03/2006|13:38] C:\Program Files\Grisoft
    [23/01/2005|12:07] C:\Program Files\InstallShield Installation Information
    [23/01/2005|11:56] C:\Program Files\Internet Explorer
    [04/04/2007|18:55] C:\Program Files\Investintech.com Inc
    [25/02/2006|16:34] C:\Program Files\Java
    [17/08/2006|19:11] C:\Program Files\JCA2000
    [23/03/2006|11:08] C:\Program Files\Kit ADSL
    [26/03/2006|19:24] C:\Program Files\Lavasoft
    [09/04/2006|11:38] C:\Program Files\Logitech
    [20/08/2006|20:45] C:\Program Files\Mes Jeux T‚l‚charg‚s
    [23/01/2005|11:55] C:\Program Files\Messenger
    [11/12/2006|13:10] C:\Program Files\Messenger Plus! Live
    [21/09/2006|17:31] C:\Program Files\MessengerDiscovery
    [02/06/2007|23:30] C:\Program Files\MessengerPlus! 3(2)
    [23/01/2005|11:58] C:\Program Files\microsoft frontpage
    [28/02/2006|18:17] C:\Program Files\Microsoft Office
    [18/04/2007|22:55] C:\Program Files\MIKSOFT
    [23/01/2005|11:56] C:\Program Files\Movie Maker
    [08/12/2006|15:46] C:\Program Files\Mozilla Firefox
    [18/02/2007|17:04] C:\Program Files\MSECache
    [23/01/2005|11:55] C:\Program Files\MSN
    [23/01/2005|11:55] C:\Program Files\MSN Gaming Zone
    [11/06/2007|16:45] C:\Program Files\MSN Messenger
    [09/09/2007|16:32] C:\Program Files\Navilog1
    [26/06/2006|21:45] C:\Program Files\Nero
    [23/01/2005|11:56] C:\Program Files\NetMeeting
    [23/01/2005|12:11] C:\Program Files\NewTech Infosystems
    [27/08/2007|20:53] C:\Program Files\Odebit Multim‚dia
    [23/01/2005|11:55] C:\Program Files\Online Services
    [28/05/2007|16:39] C:\Program Files\OpenOffice.org 2.2
    [23/01/2005|11:56] C:\Program Files\Outlook Express
    [03/10/2006|09:31] C:\Program Files\Panicware
    [04/04/2007|18:41] C:\Program Files\PDF2W
    [06/08/2006|13:10] C:\Program Files\PhotoFiltre
    [24/03/2006|09:44] C:\Program Files\Real
    [04/08/2006|19:13] C:\Program Files\Realtek AC97
    [04/08/2006|19:13] C:\Program Files\Realtek Sound Manager
    [23/01/2005|11:57] C:\Program Files\Services en ligne
    [07/04/2006|19:53] C:\Program Files\Shareaza
    [01/03/2006|19:09] C:\Program Files\Snapshot Viewer
    [06/08/2008|16:11] C:\Program Files\Sun
    [15/09/2008|22:03] C:\Program Files\Trend Micro
    [24/02/2008|17:33] C:\Program Files\TRENDnet
    [18/02/2007|12:14] C:\Program Files\UnFREEz
    [23/01/2005|12:07] C:\Program Files\Uninstall Information
    [23/03/2006|11:09] C:\Program Files\USB Driver-Express
    [23/03/2006|19:18] C:\Program Files\Valve
    [15/12/2007|13:49] C:\Program Files\Veoh Networks
    [27/05/2006|23:47] C:\Program Files\VideoLAN
    [26/03/2006|19:56] C:\Program Files\Vidmex
    [02/06/2007|23:20] C:\Program Files\Windows Live
    [23/01/2005|11:55] C:\Program Files\Windows Media Player
    [23/01/2005|11:55] C:\Program Files\Windows NT
    [23/01/2005|11:57] C:\Program Files\WindowsUpdate
    [22/03/2007|22:21] C:\Program Files\WindSolutions
    [30/05/2006|20:13] C:\Program Files\WinRAR
    [23/01/2005|11:58] C:\Program Files\xerox
    [15/09/2007|23:01] C:\Program Files\Xi
    [06/10/2006|16:57] C:\Program Files\Yahoo!

    --------------------\\ Listing des dossiers dans C:\Program Files\Fichiers communs

    [06/10/2006|16:39] C:\Program Files\Fichiers communs\Adobe
    [26/06/2006|21:45] C:\Program Files\Fichiers communs\Ahead
    [12/07/2007|18:54] C:\Program Files\Fichiers communs\Apple
    [20/08/2006|22:22] C:\Program Files\Fichiers communs\BOONTY Shared
    [26/12/2007|17:38] C:\Program Files\Fichiers communs\Designer
    [04/07/2006|20:12] C:\Program Files\Fichiers communs\Droppix
    [23/01/2005|12:05] C:\Program Files\Fichiers communs\InstallShield
    [25/02/2006|16:34] C:\Program Files\Fichiers communs\Java
    [09/04/2006|11:38] C:\Program Files\Fichiers communs\Logitech
    [23/01/2005|11:52] C:\Program Files\Fichiers communs\Microsoft Shared
    [23/01/2005|11:56] C:\Program Files\Fichiers communs\MSSoap
    [23/01/2005|12:12] C:\Program Files\Fichiers communs\muvee Technologies
    [23/01/2005|11:52] C:\Program Files\Fichiers communs\ODBC
    [24/03/2006|09:44] C:\Program Files\Fichiers communs\Real
    [23/01/2005|11:56] C:\Program Files\Fichiers communs\Services
    [23/01/2005|11:52] C:\Program Files\Fichiers communs\SpeechEngines
    [23/01/2005|12:13] C:\Program Files\Fichiers communs\Symantec Shared
    [23/01/2005|11:56] C:\Program Files\Fichiers communs\System
    [16/08/2008|14:25] C:\Program Files\Fichiers communs\xing shared

    --------------------\\ Process

    ( 42 Processes )

    IEXPLORE.EXE ~ [PID:3660]
    IEXPLORE.EXE ~ [PID:3800]
    iexplore.exe ~ [PID:1152]
    IEXPLORE.EXE ~ [PID:3740]

    --------------------\\ Recherche avec S_Lop

    Aucun fichier / dossier Lop trouvé !

    --------------------\\ Recherche de Fichiers / Dossiers Lop

    C:\DOCUME~1\ALLUSE~1\APPLIC~1\aim mix proc pure
    C:\DOCUME~1\ALLUSE~1\APPLIC~1\aim mix proc pure\Cash chin.exe
    C:\DOCUME~1\HAMIDI~1\APPLIC~1\ELSE PLUS
    C:\DOCUME~1\PAPAOU~1\APPLIC~1\ELSE PLUS
    C:\DOCUME~1\PAPAOU~1\APPLIC~1\ELSE PLUS\AXISNEW.exe
    C:\DOCUME~1\PAPAOU~1\APPLIC~1\ELSE PLUS\jotnqktq.exe
    C:\DOCUME~1\PAPAOU~1\APPLIC~1\ELSE PLUS\JoyPokeForkBlue.exe
    C:\DOCUME~1\PAPAOU~1\APPLIC~1\ELSE PLUS\Thunkdeafgreat.exe
    C:\Program Files\ELSE PLUS
    C:\Program Files\Circle Developement
    C:\Program Files\Circle Developement\Uninstall.exe
    C:\DOCUME~1\PAPAOU~1\Cookies\papa_ou_maman@d2.advertserve[1].txt
    C:\DOCUME~1\PAPAOU~1\Cookies\papa_ou_maman@advertstream[2].txt
    C:\DOCUME~1\PAPAOU~1\Cookies\papa_ou_maman@advertstream[3].txt
    C:\DOCUME~1\PAPAOU~1\Cookies\papa_ou_maman@advertstream[4].txt
    C:\DOCUME~1\PAPAOU~1\Cookies\papa_ou_maman@adultfriendfinder[2].txt
    C:\DOCUME~1\PAPAOU~1\Cookies\papa_ou_maman@adultfriendfinder[1].txt
    C:\DOCUME~1\PAPAOU~1\Cookies\papa_ou_maman@adultfriendfinder[3].txt
    C:\DOCUME~1\PAPAOU~1\Cookies\papa_ou_maman@advertising[2].txt
    C:\DOCUME~1\PAPAOU~1\Cookies\papa_ou_maman@ero-advertising[1].txt
    C:\DOCUME~1\PAPAOU~1\Cookies\papa_ou_maman@advertising[3].txt
    C:\DOCUME~1\PAPAOU~1\Cookies\papa_ou_maman@fr1.seafight.bigpoint[2].txt
    C:\DOCUME~1\PAPAOU~1\Cookies\papa_ou_maman@adin.bigpoint[2].txt
    C:\DOCUME~1\PAPAOU~1\Cookies\papa_ou_maman@bigpoint[2].txt
    C:\DOCUME~1\PAPAOU~1\Cookies\papa_ou_maman@fr.xblaster.bigpoint[2].txt
    C:\DOCUME~1\PAPAOU~1\Cookies\papa_ou_maman@casinoking[1].txt
    C:\DOCUME~1\PAPAOU~1\Cookies\papa_ou_maman@banner.casinoking[2].txt
    C:\DOCUME~1\PAPAOU~1\Cookies\papa_ou_maman@cotedazurpalace[1].txt
    C:\DOCUME~1\PAPAOU~1\Cookies\papa_ou_maman@banner.cotedazurpalace[2].txt
    C:\DOCUME~1\PAPAOU~1\Cookies\papa_ou_maman@adopt.euroclick[2].txt
    C:\DOCUME~1\PAPAOU~1\Cookies\papa_ou_maman@pacificpoker[1].txt
    C:\DOCUME~1\PAPAOU~1\Cookies\papa_ou_maman@partypoker[2].txt
    C:\DOCUME~1\PAPAOU~1\Cookies\papa_ou_maman@fr1.seafight.bigpoint[2].txt
    C:\DOCUME~1\PAPAOU~1\Cookies\papa_ou_maman@32vegas[1].txt
    C:\DOCUME~1\PAPAOU~1\Cookies\papa_ou_maman@banner.32vegas[2].txt
    C:\DOCUME~1\PAPAOU~1\Cookies\papa_ou_maman@2xmoinscher[1].txt
    C:\DOCUME~1\PAPAOU~1\Cookies\papa_ou_maman@www.2xmoinscher[1].txt

    --------------------\\ Verification du Registre

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Proc pure bold multi"="C:\\Documents and Settings\\All Users\\Application Data\\aim mix proc pure\\Cash chin.exe"

    --------------------\\ Verification du fichier Hosts

    Fichier Hosts MODIFIE

    127.0.0.1 bin.errorprotector.com ## added by CiD
    127.0.0.1 br.errorsafe.com ## added by CiD
    127.0.0.1 br.winantivirus.com ## added by CiD
    127.0.0.1 br.winfixer.com ## added by CiD
    127.0.0.1 cdn.drivecleaner.com ## added by CiD
    127.0.0.1 cdn.errorsafe.com ## added by CiD
    127.0.0.1 cdn.winsoftware.com ## added by CiD
    127.0.0.1 de.errorsafe.com ## added by CiD
    127.0.0.1 de.winantivirus.com ## added by CiD
    127.0.0.1 download.cdn.drivecleaner.com ## added by CiD
    127.0.0.1 download.cdn.errorsafe.com ## added by CiD
    127.0.0.1 download.cdn.winsoftware.com ## added by CiD
    127.0.0.1 download.errorsafe.com ## added by CiD
    127.0.0.1 download.systemdoctor.com ## added by CiD
    127.0.0.1 download.winantispyware.com ## added by CiD
    127.0.0.1 download.windrivecleaner.com ## added by CiD
    127.0.0.1 download.winfixer.com ## added by CiD
    127.0.0.1 drivecleaner.com ## added by CiD
    127.0.0.1 dynamique.drivecleaner.com ## added by CiD
    127.0.0.1 errorprotector.com ## added by CiD
    127.0.0.1 errorsafe.com ## added by CiD
    127.0.0.1 es.winantivirus.com ## added by CiD
    127.0.0.1 fr.winantivirus.com ## added by CiD
    127.0.0.1 fr.winfixer.com ## added by CiD
    127.0.0.1 go.drivecleaner.com ## added by CiD
    127.0.0.1 go.errorsafe.com ## added by CiD
    127.0.0.1 go.winantispyware.com ## added by CiD
    127.0.0.1 go.winantivirus.com ## added by CiD
    127.0.0.1 hk.winantivirus.com ## added by CiD
    127.0.0.1 instlog.errorsafe.com ## added by CiD
    127.0.0.1 instlog.winantivirus.com ## added by CiD
    127.0.0.1 instlog.winfixer.com ## added by CiD
    127.0.0.1 jsp.drivecleaner.com ## added by CiD
    127.0.0.1 kb.errorsafe.com ## added by CiD
    127.0.0.1 kb.winantivirus.com ## added by CiD
    127.0.0.1 nl.errorsafe.com ## added by CiD
    127.0.0.1 se.errorsafe.com ## added by CiD
    127.0.0.1 secure.drivecleaner.com ## added by CiD
    127.0.0.1 secure.errorsafe.com ## added by CiD
    127.0.0.1 secure.winantispam.com ## added by CiD
    127.0.0.1 secure.winantispy.com ## added by CiD
    127.0.0.1 secure.winantivirus.com ## added by CiD
    127.0.0.1 support.winantivirus.com ## added by CiD
    127.0.0.1 trial.updates.winsoftware.com ## added by CiD
    127.0.0.1 ulog.winantivirus.com ## added by CiD
    127.0.0.1 utils.errorsafe.com ## added by CiD
    127.0.0.1 utils.winantivirus.com ## added by CiD
    127.0.0.1 utils.winfixer.com ## added by CiD
    127.0.0.1 winantispyware.com ## added by CiD
    127.0.0.1 winantivirus.com ## added by CiD
    127.0.0.1 winfixer.com ## added by CiD
    127.0.0.1 winfixer2006.com ## added by CiD
    127.0.0.1 winsoftware.com ## added by CiD
    127.0.0.1 www.drivecleaner.com ## added by CiD
    127.0.0.1 www.errorprotector.com ## added by CiD
    127.0.0.1 www.errorsafe.com ## added by CiD
    127.0.0.1 www.systemdoctor.com ## added by CiD
    127.0.0.1 www.utils.winfixer.com ## added by CiD
    127.0.0.1 www.win-anti-virus-pro.com ## added by CiD
    127.0.0.1 www.win-virus-pro.com ## added by CiD
    127.0.0.1 www.winantispam.com ## added by CiD
    127.0.0.1 www.winantispy.com ## added by CiD
    127.0.0.1 www.winantispyware.com ## added by CiD
    127.0.0.1 www.winantivirus.com ## added by CiD
    127.0.0.1 www.winantiviruspro.com ## added by CiD
    127.0.0.1 www.windrivecleaner.com ## added by CiD
    127.0.0.1 www.windrivesafe.com ## added by CiD
    127.0.0.1 www.winfixer.com ## added by CiD
    127.0.0.1 www.winfixer2006.com ## added by CiD
    127.0.0.1 www.winsoftware.com ## added by CiD

    -> 72 [ 70 ## added by CiD ]

    --------------------\\ Recherche de fichiers avec Catchme

    catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-09-16 21:06:10
    Windows 5.1.2600 Service Pack 3 FAT NTAPI
    scanning hidden processes ...
    scanning hidden files ...
    scan completed successfully
    hidden processes: 0
    hidden files: 0

    --------------------\\ Recherche d'autres infections

    --------------------\\ ROGUES ..

    C:\DOCUME~1\ALLUSE~1\APPLIC~1\WinAntiVirus Pro 2006

    --------------------\\ Cracks & Keygens ..

    C:\DOCUME~1\PAPAOU~1\Application Data\Real\RealPlayer\History\Pilotes Crack Musik feat. Hamz.lnk


    [F:4][D:1]-> C:\DOCUME~1\PAPAOU~1\LOCALS~1\Temp
    [F:1665][D:0]-> C:\DOCUME~1\PAPAOU~1\Cookies
    [F:18597][D:34]-> C:\DOCUME~1\PAPAOU~1\LOCALS~1\TEMPOR~1\content.IE5
    [F:7][D:0]-> C:\Recycled

    1 - "C:\Lop SD\LopR_1.txt" - 16/09/2008|21:07 - Option : [1]

    --------------------\\ Fin du rapport a 21:07:33
    a b 8 Sécurité
    16 Septembre 2008 21:10:46

    Re,

    Relance Lop S&D en double-cliquant sur le raccourci. Tape sur "2" puis valide en appuyant sur "Entrée".
    [#ff0000]! Ne ferme pas la fenêtre lors de la suppression ! [/#f]
    Un rapport sera généré, poste son contenu ici.
    16 Septembre 2008 21:16:17


    --------------------\\ Lop S&D 4.2.4-3 XP/Vista

    Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 3
    X86-based PC ( Uniprocessor Free : AMD Athlon(tm) 64 Processor 3400+ )
    BIOS : )Phoenix - Award WorkstationBIOS v6.00PG
    USER : PAPA OU MAMAN ( Administrator )
    BOOT : Normal boot
    Antivirus : Avira AntiVir PersonalEdition 8.0.1.27 (Activated)
    C:\ (Local Disk) - FAT32 - Total : 72 Go Free : 22 Go
    D:\ (Local Disk) - FAT32 - Total : 72 Go Free : 72 Go
    E:\ (CD or DVD)
    F:\ (USB)
    G:\ (USB)
    H:\ (USB)
    I:\ (USB)

    "C:\Lop SD" ( MAJ : 14-09-2008|22:40 )
    Option : [2] ( 16/09/2008|21:13 )


    \\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ SUPPRESSION

    Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\aim mix proc pure\Cash chin.exe
    Supprime! - C:\DOCUME~1\PAPAOU~1\APPLIC~1\ELSE PLUS\AXISNEW.exe
    Supprime! - C:\DOCUME~1\PAPAOU~1\APPLIC~1\ELSE PLUS\jotnqktq.exe
    Supprime! - C:\DOCUME~1\PAPAOU~1\APPLIC~1\ELSE PLUS\JoyPokeForkBlue.exe
    Supprime! - C:\DOCUME~1\PAPAOU~1\APPLIC~1\ELSE PLUS\Thunkdeafgreat.exe
    Supprime! - C:\Program Files\Circle Developement\Uninstall.exe
    Supprime! - C:\DOCUME~1\PAPAOU~1\Cookies\papa_ou_maman@d2.advertserve[1].txt
    Supprime! - C:\DOCUME~1\PAPAOU~1\Cookies\papa_ou_maman@advertstream[2].txt
    Supprime! - C:\DOCUME~1\PAPAOU~1\Cookies\papa_ou_maman@advertstream[3].txt
    Supprime! - C:\DOCUME~1\PAPAOU~1\Cookies\papa_ou_maman@advertstream[4].txt
    Supprime! - C:\DOCUME~1\PAPAOU~1\Cookies\papa_ou_maman@adultfriendfinder[2].txt
    Supprime! - C:\DOCUME~1\PAPAOU~1\Cookies\papa_ou_maman@adultfriendfinder[1].txt
    Supprime! - C:\DOCUME~1\PAPAOU~1\Cookies\papa_ou_maman@adultfriendfinder[3].txt
    Supprime! - C:\DOCUME~1\PAPAOU~1\Cookies\papa_ou_maman@advertising[2].txt
    Supprime! - C:\DOCUME~1\PAPAOU~1\Cookies\papa_ou_maman@ero-advertising[1].txt
    Supprime! - C:\DOCUME~1\PAPAOU~1\Cookies\papa_ou_maman@advertising[3].txt
    Supprime! - C:\DOCUME~1\PAPAOU~1\Cookies\papa_ou_maman@fr1.seafight.bigpoint[2].txt
    Supprime! - C:\DOCUME~1\PAPAOU~1\Cookies\papa_ou_maman@adin.bigpoint[2].txt
    Supprime! - C:\DOCUME~1\PAPAOU~1\Cookies\papa_ou_maman@bigpoint[2].txt
    Supprime! - C:\DOCUME~1\PAPAOU~1\Cookies\papa_ou_maman@fr.xblaster.bigpoint[2].txt
    Supprime! - C:\DOCUME~1\PAPAOU~1\Cookies\papa_ou_maman@casinoking[1].txt
    Supprime! - C:\DOCUME~1\PAPAOU~1\Cookies\papa_ou_maman@banner.casinoking[2].txt
    Supprime! - C:\DOCUME~1\PAPAOU~1\Cookies\papa_ou_maman@cotedazurpalace[1].txt
    Supprime! - C:\DOCUME~1\PAPAOU~1\Cookies\papa_ou_maman@banner.cotedazurpalace[2].txt
    Supprime! - C:\DOCUME~1\PAPAOU~1\Cookies\papa_ou_maman@pacificpoker[1].txt
    Supprime! - C:\DOCUME~1\PAPAOU~1\Cookies\papa_ou_maman@partypoker[2].txt
    Supprime! - C:\DOCUME~1\PAPAOU~1\Cookies\papa_ou_maman@32vegas[1].txt
    Supprime! - C:\DOCUME~1\PAPAOU~1\Cookies\papa_ou_maman@banner.32vegas[2].txt
    Supprime! - C:\DOCUME~1\PAPAOU~1\Cookies\papa_ou_maman@2xmoinscher[1].txt
    Supprime! - C:\DOCUME~1\PAPAOU~1\Cookies\papa_ou_maman@www.2xmoinscher[1].txt
    Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\aim mix proc pure
    Supprime! - C:\DOCUME~1\HAMIDI~1\APPLIC~1\ELSE PLUS
    Supprime! - C:\DOCUME~1\PAPAOU~1\APPLIC~1\ELSE PLUS
    Supprime! - C:\Program Files\ELSE PLUS
    Supprime! - C:\Program Files\Circle Developement
    -
    [ Fichier Hosts ] .. Restaure!

    \\\\\\\\\\\\\\\\\\\\\\\\\\\\\\


    --------------------\\ Listing des dossiers dans APPLIC~1

    [23/01/2005|12:07] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Identities
    [23/01/2005|11:51] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft
    [23/01/2005|12:13] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Symantec

    [06/10/2006|16:57] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
    [09/09/2007|09:41] C:\DOCUME~1\ALLUSE~1\APPLIC~1\AntiVir PersonalEdition Classic
    [12/07/2007|18:54] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple
    [23/12/2006|19:41] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
    [31/03/2006|13:38] C:\DOCUME~1\ALLUSE~1\APPLIC~1\avg7
    [20/08/2006|22:22] C:\DOCUME~1\ALLUSE~1\APPLIC~1\BOONTY
    [02/06/2007|17:44] C:\DOCUME~1\ALLUSE~1\APPLIC~1\CopyPod
    [25/02/2006|16:48] C:\DOCUME~1\ALLUSE~1\APPLIC~1\CyberLink
    [25/02/2006|16:46] C:\DOCUME~1\ALLUSE~1\APPLIC~1\eConsole
    [30/05/2007|13:12] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
    [08/09/2007|19:38] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Grisoft
    [24/12/2006|22:13] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Messenger Plus!
    [23/01/2005|11:51] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
    [31/07/2007|17:39] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Mozilla
    [01/05/2006|19:01] C:\DOCUME~1\ALLUSE~1\APPLIC~1\mp3copyclockfork
    [28/05/2007|16:19] C:\DOCUME~1\ALLUSE~1\APPLIC~1\OFFICE One v7
    [02/04/2007|10:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\QuickTime
    [19/06/2006|20:01] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Skype
    [23/01/2005|12:13] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec
    [31/03/2006|13:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WinAntiVirus Pro 2006
    [29/11/2006|22:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
    [02/06/2007|23:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WindowsLiveInstaller
    [02/06/2007|23:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller
    [09/04/2008|13:16] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Yahoo! Companion
    [03/09/2006|13:37] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Zylom

    [23/01/2005|11:51] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft
    [23/03/2006|20:30] C:\DOCUME~1\NETWOR~1\APPLIC~1\Symantec

    [31/03/2006|13:40] C:\DOCUME~1\LOCALS~1\APPLIC~1\AVG7
    [23/01/2005|11:51] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft

    [25/02/2006|16:35] C:\DOCUME~1\HAMIDI~1\APPLIC~1\Adobe
    [27/04/2006|17:06] C:\DOCUME~1\HAMIDI~1\APPLIC~1\AdobeUM
    [26/06/2006|21:49] C:\DOCUME~1\HAMIDI~1\APPLIC~1\Ahead
    [23/12/2006|19:42] C:\DOCUME~1\HAMIDI~1\APPLIC~1\Apple Computer
    [10/03/2006|14:50] C:\DOCUME~1\HAMIDI~1\APPLIC~1\ArcSoft
    [31/03/2006|13:38] C:\DOCUME~1\HAMIDI~1\APPLIC~1\AVG7
    [22/03/2007|22:22] C:\DOCUME~1\HAMIDI~1\APPLIC~1\CopyPod
    [22/03/2007|22:23] C:\DOCUME~1\HAMIDI~1\APPLIC~1\CopyPodPhoto
    [25/02/2006|16:58] C:\DOCUME~1\HAMIDI~1\APPLIC~1\CyberLink
    [08/12/2006|17:28] C:\DOCUME~1\HAMIDI~1\APPLIC~1\DivX
    [18/05/2006|19:12] C:\DOCUME~1\HAMIDI~1\APPLIC~1\Droppix
    [15/05/2007|13:59] C:\DOCUME~1\HAMIDI~1\APPLIC~1\Eltima Software
    [18/11/2006|13:43] C:\DOCUME~1\HAMIDI~1\APPLIC~1\EPSON
    [24/03/2006|09:45] C:\DOCUME~1\HAMIDI~1\APPLIC~1\Google
    [08/09/2007|19:39] C:\DOCUME~1\HAMIDI~1\APPLIC~1\Grisoft
    [12/03/2006|11:36] C:\DOCUME~1\HAMIDI~1\APPLIC~1\Help
    [22/03/2007|22:21] C:\DOCUME~1\HAMIDI~1\APPLIC~1\iCloner
    [23/01/2005|12:07] C:\DOCUME~1\HAMIDI~1\APPLIC~1\Identities
    [26/03/2006|19:24] C:\DOCUME~1\HAMIDI~1\APPLIC~1\Lavasoft
    [06/10/2006|20:08] C:\DOCUME~1\HAMIDI~1\APPLIC~1\Leadertech
    [23/03/2006|16:48] C:\DOCUME~1\HAMIDI~1\APPLIC~1\Macromedia
    [23/01/2005|11:51] C:\DOCUME~1\HAMIDI~1\APPLIC~1\Microsoft
    [28/02/2006|18:17] C:\DOCUME~1\HAMIDI~1\APPLIC~1\Microsoft Web Folders
    [08/12/2006|17:16] C:\DOCUME~1\HAMIDI~1\APPLIC~1\Mozilla
    [08/10/2006|10:55] C:\DOCUME~1\HAMIDI~1\APPLIC~1\MSNInstaller
    [06/08/2006|13:02] C:\DOCUME~1\HAMIDI~1\APPLIC~1\Not a Number
    [28/05/2007|16:40] C:\DOCUME~1\HAMIDI~1\APPLIC~1\OpenOffice.org2
    [24/03/2006|09:43] C:\DOCUME~1\HAMIDI~1\APPLIC~1\Real
    [14/10/2007|16:48] C:\DOCUME~1\HAMIDI~1\APPLIC~1\Samsung
    [09/04/2007|14:14] C:\DOCUME~1\HAMIDI~1\APPLIC~1\Screenshot Sender
    [21/06/2007|18:24] C:\DOCUME~1\HAMIDI~1\APPLIC~1\SecondLife
    [19/06/2006|20:01] C:\DOCUME~1\HAMIDI~1\APPLIC~1\Skype
    [28/02/2006|12:33] C:\DOCUME~1\HAMIDI~1\APPLIC~1\Sun
    [23/01/2005|12:13] C:\DOCUME~1\HAMIDI~1\APPLIC~1\Symantec
    [31/07/2007|17:40] C:\DOCUME~1\HAMIDI~1\APPLIC~1\Talkback
    [27/05/2006|23:47] C:\DOCUME~1\HAMIDI~1\APPLIC~1\vlc
    [11/04/2008|19:59] C:\DOCUME~1\HAMIDI~1\APPLIC~1\Yahoo!

    [08/12/2006|15:46] C:\DOCUME~1\SAMIR\APPLIC~1\Mozilla

    [14/01/2007|15:06] C:\DOCUME~1\PAPAOU~1\APPLIC~1\Adobe
    [15/01/2008|13:28] C:\DOCUME~1\PAPAOU~1\APPLIC~1\Apple Computer
    [05/12/2006|20:52] C:\DOCUME~1\PAPAOU~1\APPLIC~1\ArcSoft
    [22/11/2006|20:30] C:\DOCUME~1\PAPAOU~1\APPLIC~1\AVG7
    [10/04/2008|15:56] C:\DOCUME~1\PAPAOU~1\APPLIC~1\DivX
    [20/11/2006|20:52] C:\DOCUME~1\PAPAOU~1\APPLIC~1\EPSON
    [25/03/2006|21:28] C:\DOCUME~1\PAPAOU~1\APPLIC~1\Google
    [09/09/2007|20:41] C:\DOCUME~1\PAPAOU~1\APPLIC~1\Grisoft
    [23/01/2005|12:07] C:\DOCUME~1\PAPAOU~1\APPLIC~1\Identities
    [27/05/2006|18:52] C:\DOCUME~1\PAPAOU~1\APPLIC~1\Lavasoft
    [25/03/2006|21:29] C:\DOCUME~1\PAPAOU~1\APPLIC~1\Macromedia
    [23/01/2005|11:51] C:\DOCUME~1\PAPAOU~1\APPLIC~1\Microsoft
    [25/03/2006|21:28] C:\DOCUME~1\PAPAOU~1\APPLIC~1\Real
    [15/04/2006|14:29] C:\DOCUME~1\PAPAOU~1\APPLIC~1\ShopperReports
    [11/03/2007|00:20] C:\DOCUME~1\PAPAOU~1\APPLIC~1\Sun
    [23/01/2005|12:13] C:\DOCUME~1\PAPAOU~1\APPLIC~1\Symantec
    [25/02/2008|15:52] C:\DOCUME~1\PAPAOU~1\APPLIC~1\vlc
    [09/04/2008|13:16] C:\DOCUME~1\PAPAOU~1\APPLIC~1\Yahoo!

    [08/09/2007|19:44] C:\DOCUME~1\ADMINI~1\APPLIC~1\Grisoft
    [23/01/2005|12:07] C:\DOCUME~1\ADMINI~1\APPLIC~1\Identities
    [23/01/2005|11:51] C:\DOCUME~1\ADMINI~1\APPLIC~1\Microsoft
    [23/01/2005|12:13] C:\DOCUME~1\ADMINI~1\APPLIC~1\Symantec

    --------------------\\ Tâches planifiées dans C:\WINDOWS\tasks

    [04/09/2008 21:57][--a------] C:\WINDOWS\tasks\AppleSoftwareUpdate.job
    [16/09/2008 20:42][--ah-----] C:\WINDOWS\tasks\SA.DAT
    [05/08/2004 05:00][-r-h-----] C:\WINDOWS\tasks\desktop.ini

    --------------------\\ Listing des dossiers dans C:\Program Files

    [25/02/2006|16:30] C:\Program Files\Acer
    [23/01/2005|12:10] C:\Program Files\Adobe
    [04/08/2006|18:21] C:\Program Files\Ahead
    [23/11/2006|21:53] C:\Program Files\Alwil Software
    [23/01/2005|12:16] C:\Program Files\AMD
    [16/08/2006|22:12] C:\Program Files\Antipub
    [09/09/2007|09:41] C:\Program Files\AntiVir PersonalEdition Classic
    [23/12/2006|19:41] C:\Program Files\Apple Software Update
    [11/09/2007|17:31] C:\Program Files\Audacity
    [23/01/2005|11:57] C:\Program Files\AviSynth 2.5
    [04/08/2006|19:13] C:\Program Files\AvRack
    [10/11/2006|14:03] C:\Program Files\Belkin
    [04/04/2007|18:41] C:\Program Files\BlueSquad
    [20/08/2006|20:43] C:\Program Files\Boonty
    [20/08/2006|20:43] C:\Program Files\BoontyGames
    [31/03/2006|13:31] C:\Program Files\Common Files
    [23/01/2005|11:56] C:\Program Files\ComPlus Applications
    [02/06/2007|17:44] C:\Program Files\CopyPod
    [23/01/2005|12:13] C:\Program Files\CyberLink
    [26/03/2006|20:14] C:\Program Files\DivX
    [04/07/2006|20:12] C:\Program Files\Droppix
    [15/05/2007|13:59] C:\Program Files\Eltima Software
    [23/03/2006|14:31] C:\Program Files\eMule
    [18/11/2006|13:27] C:\Program Files\epson
    [18/04/2007|21:41] C:\Program Files\eRightSoft
    [23/01/2005|11:52] C:\Program Files\Fichiers communs
    [22/07/2007|16:21] C:\Program Files\Free Audio Pack
    [15/05/2007|14:59] C:\Program Files\GetFlash
    [24/03/2006|09:45] C:\Program Files\Google
    [31/03/2006|13:38] C:\Program Files\Grisoft
    [23/01/2005|12:07] C:\Program Files\InstallShield Installation Information
    [23/01/2005|11:56] C:\Program Files\Internet Explorer
    [04/04/2007|18:55] C:\Program Files\Investintech.com Inc
    [25/02/2006|16:34] C:\Program Files\Java
    [17/08/2006|19:11] C:\Program Files\JCA2000
    [23/03/2006|11:08] C:\Program Files\Kit ADSL
    [26/03/2006|19:24] C:\Program Files\Lavasoft
    [09/04/2006|11:38] C:\Program Files\Logitech
    [20/08/2006|20:45] C:\Program Files\Mes Jeux T‚l‚charg‚s
    [23/01/2005|11:55] C:\Program Files\Messenger
    [11/12/2006|13:10] C:\Program Files\Messenger Plus! Live
    [21/09/2006|17:31] C:\Program Files\MessengerDiscovery
    [02/06/2007|23:30] C:\Program Files\MessengerPlus! 3(2)
    [23/01/2005|11:58] C:\Program Files\microsoft frontpage
    [28/02/2006|18:17] C:\Program Files\Microsoft Office
    [18/04/2007|22:55] C:\Program Files\MIKSOFT
    [23/01/2005|11:56] C:\Program Files\Movie Maker
    [08/12/2006|15:46] C:\Program Files\Mozilla Firefox
    [18/02/2007|17:04] C:\Program Files\MSECache
    [23/01/2005|11:55] C:\Program Files\MSN
    [23/01/2005|11:55] C:\Program Files\MSN Gaming Zone
    [11/06/2007|16:45] C:\Program Files\MSN Messenger
    [09/09/2007|16:32] C:\Program Files\Navilog1
    [26/06/2006|21:45] C:\Program Files\Nero
    [23/01/2005|11:56] C:\Program Files\NetMeeting
    [23/01/2005|12:11] C:\Program Files\NewTech Infosystems
    [27/08/2007|20:53] C:\Program Files\Odebit Multim‚dia
    [23/01/2005|11:55] C:\Program Files\Online Services
    [28/05/2007|16:39] C:\Program Files\OpenOffice.org 2.2
    [23/01/2005|11:56] C:\Program Files\Outlook Express
    [03/10/2006|09:31] C:\Program Files\Panicware
    [04/04/2007|18:41] C:\Program Files\PDF2W
    [06/08/2006|13:10] C:\Program Files\PhotoFiltre
    [24/03/2006|09:44] C:\Program Files\Real
    [04/08/2006|19:13] C:\Program Files\Realtek AC97
    [04/08/2006|19:13] C:\Program Files\Realtek Sound Manager
    [23/01/2005|11:57] C:\Program Files\Services en ligne
    [07/04/2006|19:53] C:\Program Files\Shareaza
    [01/03/2006|19:09] C:\Program Files\Snapshot Viewer
    [06/08/2008|16:11] C:\Program Files\Sun
    [15/09/2008|22:03] C:\Program Files\Trend Micro
    [24/02/2008|17:33] C:\Program Files\TRENDnet
    [18/02/2007|12:14] C:\Program Files\UnFREEz
    [23/01/2005|12:07] C:\Program Files\Uninstall Information
    [23/03/2006|11:09] C:\Program Files\USB Driver-Express
    [23/03/2006|19:18] C:\Program Files\Valve
    [15/12/2007|13:49] C:\Program Files\Veoh Networks
    [27/05/2006|23:47] C:\Program Files\VideoLAN
    [26/03/2006|19:56] C:\Program Files\Vidmex
    [02/06/2007|23:20] C:\Program Files\Windows Live
    [23/01/2005|11:55] C:\Program Files\Windows Media Player
    [23/01/2005|11:55] C:\Program Files\Windows NT
    [23/01/2005|11:57] C:\Program Files\WindowsUpdate
    [22/03/2007|22:21] C:\Program Files\WindSolutions
    [30/05/2006|20:13] C:\Program Files\WinRAR
    [23/01/2005|11:58] C:\Program Files\xerox
    [15/09/2007|23:01] C:\Program Files\Xi
    [06/10/2006|16:57] C:\Program Files\Yahoo!

    --------------------\\ Listing des dossiers dans C:\Program Files\Fichiers communs

    [06/10/2006|16:39] C:\Program Files\Fichiers communs\Adobe
    [26/06/2006|21:45] C:\Program Files\Fichiers communs\Ahead
    [12/07/2007|18:54] C:\Program Files\Fichiers communs\Apple
    [20/08/2006|22:22] C:\Program Files\Fichiers communs\BOONTY Shared
    [26/12/2007|17:38] C:\Program Files\Fichiers communs\Designer
    [04/07/2006|20:12] C:\Program Files\Fichiers communs\Droppix
    [23/01/2005|12:05] C:\Program Files\Fichiers communs\InstallShield
    [25/02/2006|16:34] C:\Program Files\Fichiers communs\Java
    [09/04/2006|11:38] C:\Program Files\Fichiers communs\Logitech
    [23/01/2005|11:52] C:\Program Files\Fichiers communs\Microsoft Shared
    [23/01/2005|11:56] C:\Program Files\Fichiers communs\MSSoap
    [23/01/2005|12:12] C:\Program Files\Fichiers communs\muvee Technologies
    [23/01/2005|11:52] C:\Program Files\Fichiers communs\ODBC
    [24/03/2006|09:44] C:\Program Files\Fichiers communs\Real
    [23/01/2005|11:56] C:\Program Files\Fichiers communs\Services
    [23/01/2005|11:52] C:\Program Files\Fichiers communs\SpeechEngines
    [23/01/2005|12:13] C:\Program Files\Fichiers communs\Symantec Shared
    [23/01/2005|11:56] C:\Program Files\Fichiers communs\System
    [16/08/2008|14:25] C:\Program Files\Fichiers communs\xing shared

    --------------------\\ Process

    ( 37 Processes )

    ... OK !

    --------------------\\ Recherche avec S_Lop

    Aucun fichier / dossier Lop trouvé !

    --------------------\\ Recherche de Fichiers / Dossiers Lop

    C:\DOCUME~1\PAPAOU~1\Cookies\papa_ou_maman@adopt.euroclick[1].txt

    --------------------\\ Verification du Registre

    ..... OK !

    --------------------\\ Verification du fichier Hosts

    Fichier Hosts PROPRE


    --------------------\\ Recherche de fichiers avec Catchme

    catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-09-16 21:14:25
    Windows 5.1.2600 Service Pack 3 FAT NTAPI
    scanning hidden processes ...
    scanning hidden files ...
    scan completed successfully
    hidden processes: 0
    hidden files: 0

    --------------------\\ Recherche d'autres infections

    --------------------\\ ROGUES ..

    C:\DOCUME~1\ALLUSE~1\APPLIC~1\WinAntiVirus Pro 2006

    --------------------\\ Cracks & Keygens ..

    C:\DOCUME~1\PAPAOU~1\Application Data\Real\RealPlayer\History\Pilotes Crack Musik feat. Hamz.lnk


    [F:5][D:1]-> C:\DOCUME~1\PAPAOU~1\LOCALS~1\Temp
    [F:1641][D:0]-> C:\DOCUME~1\PAPAOU~1\Cookies
    [F:18667][D:34]-> C:\DOCUME~1\PAPAOU~1\LOCALS~1\TEMPOR~1\content.IE5
    [F:7][D:0]-> C:\Recycled

    1 - "C:\Lop SD\LopR_1.txt" - 16/09/2008|21:07 - Option : [1]
    2 - "C:\Lop SD\LopR_2.txt" - 16/09/2008|21:15 - Option : [2]

    --------------------\\ Fin du rapport a 21:15:29
    a b 8 Sécurité
    17 Septembre 2008 12:46:47

    Re,

    Copie (Ctrl+C) le texte se situant dans le cadre ci-dessous :

    C:\DOCUME~1\ALLUSE~1\APPLIC~1\mp3copyclockfork
    C:\DOCUME~1\ALLUSE~1\APPLIC~1\WinAntiVirus Pro 2006
    C:\DOCUME~1\PAPAOU~1\Cookies\papa_ou_maman@adopt.euroclick[1].txt


  • Relance Lop S&D.
  • Choisis cette fois-ci l'option 4 (LopScript). Une page blanche va s'ouvrir, colle (Ctrl+V) le texte précedemment copié.
  • Ferme cette page, il te sera demandé de l'enregistrer, accepte.
    [#ff0000]! Ne ferme pas la fenêtre lors de la suppression ![/#f]
  • Poste le rapport généré (C:\lopR.txt*)

    (Si le Bureau ne réapparaît pas, presse Ctrl + Alt + Suppr , Onglet Fichier , Nouvelle tâche , tape explorer.exe et valide)
    * le nom de la partition peut changer
    17 Septembre 2008 16:22:47


    --------------------\\ Lop S&D 4.2.4-3 XP/Vista

    Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 3
    X86-based PC ( Uniprocessor Free : AMD Athlon(tm) 64 Processor 3400+ )
    BIOS : )Phoenix - Award WorkstationBIOS v6.00PG
    USER : PAPA OU MAMAN ( Administrator )
    BOOT : Normal boot
    Antivirus : Avira AntiVir PersonalEdition 8.0.1.27 (Activated)
    C:\ (Local Disk) - FAT32 - Total : 72 Go Free : 22 Go
    D:\ (Local Disk) - FAT32 - Total : 72 Go Free : 72 Go
    E:\ (CD or DVD)
    F:\ (USB)
    G:\ (USB)
    H:\ (USB)
    I:\ (USB)

    "C:\Lop SD" ( MAJ : 14-09-2008|22:40 )
    Option : [4] ( 17/09/2008|16:20 )

    \\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ Lop Script

    C:\DOCUME~1\ALLUSE~1\APPLIC~1\mp3copyclockfork
    C:\DOCUME~1\ALLUSE~1\APPLIC~1\WinAntiVirus Pro 2006
    C:\DOCUME~1\PAPAOU~1\Cookies\papa_ou_maman@adopt.euroclick[1].txt


    \\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ SUPPRESSION

    Supprime! - C:\DOCUME~1\PAPAOU~1\Cookies\papa_ou_maman@adopt.euroclick[1].txt
    Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\mp3copyclockfork
    Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\WinAntiVirus Pro 2006

    \\\\\\\\\\\\\\\\\\\\\\\\\\\\\\


    --------------------\\ Listing des dossiers dans APPLIC~1

    [23/01/2005|12:07] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Identities
    [23/01/2005|11:51] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft
    [23/01/2005|12:13] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Symantec

    [06/10/2006|16:57] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
    [09/09/2007|09:41] C:\DOCUME~1\ALLUSE~1\APPLIC~1\AntiVir PersonalEdition Classic
    [12/07/2007|18:54] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple
    [23/12/2006|19:41] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
    [31/03/2006|13:38] C:\DOCUME~1\ALLUSE~1\APPLIC~1\avg7
    [20/08/2006|22:22] C:\DOCUME~1\ALLUSE~1\APPLIC~1\BOONTY
    [02/06/2007|17:44] C:\DOCUME~1\ALLUSE~1\APPLIC~1\CopyPod
    [25/02/2006|16:48] C:\DOCUME~1\ALLUSE~1\APPLIC~1\CyberLink
    [25/02/2006|16:46] C:\DOCUME~1\ALLUSE~1\APPLIC~1\eConsole
    [30/05/2007|13:12] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
    [08/09/2007|19:38] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Grisoft
    [24/12/2006|22:13] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Messenger Plus!
    [23/01/2005|11:51] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
    [31/07/2007|17:39] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Mozilla
    [28/05/2007|16:19] C:\DOCUME~1\ALLUSE~1\APPLIC~1\OFFICE One v7
    [02/04/2007|10:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\QuickTime
    [19/06/2006|20:01] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Skype
    [23/01/2005|12:13] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec
    [29/11/2006|22:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
    [02/06/2007|23:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WindowsLiveInstaller
    [02/06/2007|23:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller
    [09/04/2008|13:16] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Yahoo! Companion
    [03/09/2006|13:37] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Zylom

    [23/01/2005|11:51] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft
    [23/03/2006|20:30] C:\DOCUME~1\NETWOR~1\APPLIC~1\Symantec

    [31/03/2006|13:40] C:\DOCUME~1\LOCALS~1\APPLIC~1\AVG7
    [23/01/2005|11:51] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft

    [25/02/2006|16:35] C:\DOCUME~1\HAMIDI~1\APPLIC~1\Adobe
    [27/04/2006|17:06] C:\DOCUME~1\HAMIDI~1\APPLIC~1\AdobeUM
    [26/06/2006|21:49] C:\DOCUME~1\HAMIDI~1\APPLIC~1\Ahead
    [23/12/2006|19:42] C:\DOCUME~1\HAMIDI~1\APPLIC~1\Apple Computer
    [10/03/2006|14:50] C:\DOCUME~1\HAMIDI~1\APPLIC~1\ArcSoft
    [31/03/2006|13:38] C:\DOCUME~1\HAMIDI~1\APPLIC~1\AVG7
    [22/03/2007|22:22] C:\DOCUME~1\HAMIDI~1\APPLIC~1\CopyPod
    [22/03/2007|22:23] C:\DOCUME~1\HAMIDI~1\APPLIC~1\CopyPodPhoto
    [25/02/2006|16:58] C:\DOCUME~1\HAMIDI~1\APPLIC~1\CyberLink
    [08/12/2006|17:28] C:\DOCUME~1\HAMIDI~1\APPLIC~1\DivX
    [18/05/2006|19:12] C:\DOCUME~1\HAMIDI~1\APPLIC~1\Droppix
    [15/05/2007|13:59] C:\DOCUME~1\HAMIDI~1\APPLIC~1\Eltima Software
    [18/11/2006|13:43] C:\DOCUME~1\HAMIDI~1\APPLIC~1\EPSON
    [24/03/2006|09:45] C:\DOCUME~1\HAMIDI~1\APPLIC~1\Google
    [08/09/2007|19:39] C:\DOCUME~1\HAMIDI~1\APPLIC~1\Grisoft
    [12/03/2006|11:36] C:\DOCUME~1\HAMIDI~1\APPLIC~1\Help
    [22/03/2007|22:21] C:\DOCUME~1\HAMIDI~1\APPLIC~1\iCloner
    [23/01/2005|12:07] C:\DOCUME~1\HAMIDI~1\APPLIC~1\Identities
    [26/03/2006|19:24] C:\DOCUME~1\HAMIDI~1\APPLIC~1\Lavasoft
    [06/10/2006|20:08] C:\DOCUME~1\HAMIDI~1\APPLIC~1\Leadertech
    [23/03/2006|16:48] C:\DOCUME~1\HAMIDI~1\APPLIC~1\Macromedia
    [23/01/2005|11:51] C:\DOCUME~1\HAMIDI~1\APPLIC~1\Microsoft
    [28/02/2006|18:17] C:\DOCUME~1\HAMIDI~1\APPLIC~1\Microsoft Web Folders
    [08/12/2006|17:16] C:\DOCUME~1\HAMIDI~1\APPLIC~1\Mozilla
    [08/10/2006|10:55] C:\DOCUME~1\HAMIDI~1\APPLIC~1\MSNInstaller
    [06/08/2006|13:02] C:\DOCUME~1\HAMIDI~1\APPLIC~1\Not a Number
    [28/05/2007|16:40] C:\DOCUME~1\HAMIDI~1\APPLIC~1\OpenOffice.org2
    [24/03/2006|09:43] C:\DOCUME~1\HAMIDI~1\APPLIC~1\Real
    [14/10/2007|16:48] C:\DOCUME~1\HAMIDI~1\APPLIC~1\Samsung
    [09/04/2007|14:14] C:\DOCUME~1\HAMIDI~1\APPLIC~1\Screenshot Sender
    [21/06/2007|18:24] C:\DOCUME~1\HAMIDI~1\APPLIC~1\SecondLife
    [19/06/2006|20:01] C:\DOCUME~1\HAMIDI~1\APPLIC~1\Skype
    [28/02/2006|12:33] C:\DOCUME~1\HAMIDI~1\APPLIC~1\Sun
    [23/01/2005|12:13] C:\DOCUME~1\HAMIDI~1\APPLIC~1\Symantec
    [31/07/2007|17:40] C:\DOCUME~1\HAMIDI~1\APPLIC~1\Talkback
    [27/05/2006|23:47] C:\DOCUME~1\HAMIDI~1\APPLIC~1\vlc
    [11/04/2008|19:59] C:\DOCUME~1\HAMIDI~1\APPLIC~1\Yahoo!

    [08/12/2006|15:46] C:\DOCUME~1\SAMIR\APPLIC~1\Mozilla

    [14/01/2007|15:06] C:\DOCUME~1\PAPAOU~1\APPLIC~1\Adobe
    [15/01/2008|13:28] C:\DOCUME~1\PAPAOU~1\APPLIC~1\Apple Computer
    [05/12/2006|20:52] C:\DOCUME~1\PAPAOU~1\APPLIC~1\ArcSoft
    [22/11/2006|20:30] C:\DOCUME~1\PAPAOU~1\APPLIC~1\AVG7
    [10/04/2008|15:56] C:\DOCUME~1\PAPAOU~1\APPLIC~1\DivX
    [20/11/2006|20:52] C:\DOCUME~1\PAPAOU~1\APPLIC~1\EPSON
    [25/03/2006|21:28] C:\DOCUME~1\PAPAOU~1\APPLIC~1\Google
    [09/09/2007|20:41] C:\DOCUME~1\PAPAOU~1\APPLIC~1\Grisoft
    [23/01/2005|12:07] C:\DOCUME~1\PAPAOU~1\APPLIC~1\Identities
    [27/05/2006|18:52] C:\DOCUME~1\PAPAOU~1\APPLIC~1\Lavasoft
    [25/03/2006|21:29] C:\DOCUME~1\PAPAOU~1\APPLIC~1\Macromedia
    [23/01/2005|11:51] C:\DOCUME~1\PAPAOU~1\APPLIC~1\Microsoft
    [25/03/2006|21:28] C:\DOCUME~1\PAPAOU~1\APPLIC~1\Real
    [15/04/2006|14:29] C:\DOCUME~1\PAPAOU~1\APPLIC~1\ShopperReports
    [11/03/2007|00:20] C:\DOCUME~1\PAPAOU~1\APPLIC~1\Sun
    [23/01/2005|12:13] C:\DOCUME~1\PAPAOU~1\APPLIC~1\Symantec
    [25/02/2008|15:52] C:\DOCUME~1\PAPAOU~1\APPLIC~1\vlc
    [09/04/2008|13:16] C:\DOCUME~1\PAPAOU~1\APPLIC~1\Yahoo!

    [08/09/2007|19:44] C:\DOCUME~1\ADMINI~1\APPLIC~1\Grisoft
    [23/01/2005|12:07] C:\DOCUME~1\ADMINI~1\APPLIC~1\Identities
    [23/01/2005|11:51] C:\DOCUME~1\ADMINI~1\APPLIC~1\Microsoft
    [23/01/2005|12:13] C:\DOCUME~1\ADMINI~1\APPLIC~1\Symantec

    --------------------\\ Tâches planifiées dans C:\WINDOWS\tasks

    [04/09/2008 21:57][--a------] C:\WINDOWS\tasks\AppleSoftwareUpdate.job
    [17/09/2008 14:43][--ah-----] C:\WINDOWS\tasks\SA.DAT
    [05/08/2004 05:00][-r-h-----] C:\WINDOWS\tasks\desktop.ini

    --------------------\\ Listing des dossiers dans C:\Program Files

    [25/02/2006|16:30] C:\Program Files\Acer
    [23/01/2005|12:10] C:\Program Files\Adobe
    [04/08/2006|18:21] C:\Program Files\Ahead
    [23/11/2006|21:53] C:\Program Files\Alwil Software
    [23/01/2005|12:16] C:\Program Files\AMD
    [16/08/2006|22:12] C:\Program Files\Antipub
    [09/09/2007|09:41] C:\Program Files\AntiVir PersonalEdition Classic
    [23/12/2006|19:41] C:\Program Files\Apple Software Update
    [11/09/2007|17:31] C:\Program Files\Audacity
    [23/01/2005|11:57] C:\Program Files\AviSynth 2.5
    [04/08/2006|19:13] C:\Program Files\AvRack
    [10/11/2006|14:03] C:\Program Files\Belkin
    [04/04/2007|18:41] C:\Program Files\BlueSquad
    [20/08/2006|20:43] C:\Program Files\Boonty
    [20/08/2006|20:43] C:\Program Files\BoontyGames
    [31/03/2006|13:31] C:\Program Files\Common Files
    [23/01/2005|11:56] C:\Program Files\ComPlus Applications
    [02/06/2007|17:44] C:\Program Files\CopyPod
    [23/01/2005|12:13] C:\Program Files\CyberLink
    [26/03/2006|20:14] C:\Program Files\DivX
    [04/07/2006|20:12] C:\Program Files\Droppix
    [15/05/2007|13:59] C:\Program Files\Eltima Software
    [23/03/2006|14:31] C:\Program Files\eMule
    [18/11/2006|13:27] C:\Program Files\epson
    [18/04/2007|21:41] C:\Program Files\eRightSoft
    [23/01/2005|11:52] C:\Program Files\Fichiers communs
    [22/07/2007|16:21] C:\Program Files\Free Audio Pack
    [15/05/2007|14:59] C:\Program Files\GetFlash
    [24/03/2006|09:45] C:\Program Files\Google
    [31/03/2006|13:38] C:\Program Files\Grisoft
    [23/01/2005|12:07] C:\Program Files\InstallShield Installation Information
    [23/01/2005|11:56] C:\Program Files\Internet Explorer
    [04/04/2007|18:55] C:\Program Files\Investintech.com Inc
    [25/02/2006|16:34] C:\Program Files\Java
    [17/08/2006|19:11] C:\Program Files\JCA2000
    [23/03/2006|11:08] C:\Program Files\Kit ADSL
    [26/03/2006|19:24] C:\Program Files\Lavasoft
    [09/04/2006|11:38] C:\Program Files\Logitech
    [20/08/2006|20:45] C:\Program Files\Mes Jeux T‚l‚charg‚s
    [23/01/2005|11:55] C:\Program Files\Messenger
    [11/12/2006|13:10] C:\Program Files\Messenger Plus! Live
    [21/09/2006|17:31] C:\Program Files\MessengerDiscovery
    [02/06/2007|23:30] C:\Program Files\MessengerPlus! 3(2)
    [23/01/2005|11:58] C:\Program Files\microsoft frontpage
    [28/02/2006|18:17] C:\Program Files\Microsoft Office
    [18/04/2007|22:55] C:\Program Files\MIKSOFT
    [23/01/2005|11:56] C:\Program Files\Movie Maker
    [08/12/2006|15:46] C:\Program Files\Mozilla Firefox
    [18/02/2007|17:04] C:\Program Files\MSECache
    [23/01/2005|11:55] C:\Program Files\MSN
    [23/01/2005|11:55] C:\Program Files\MSN Gaming Zone
    [11/06/2007|16:45] C:\Program Files\MSN Messenger
    [09/09/2007|16:32] C:\Program Files\Navilog1
    [26/06/2006|21:45] C:\Program Files\Nero
    [23/01/2005|11:56] C:\Program Files\NetMeeting
    [23/01/2005|12:11] C:\Program Files\NewTech Infosystems
    [27/08/2007|20:53] C:\Program Files\Odebit Multim‚dia
    [23/01/2005|11:55] C:\Program Files\Online Services
    [28/05/2007|16:39] C:\Program Files\OpenOffice.org 2.2
    [23/01/2005|11:56] C:\Program Files\Outlook Express
    [03/10/2006|09:31] C:\Program Files\Panicware
    [04/04/2007|18:41] C:\Program Files\PDF2W
    [06/08/2006|13:10] C:\Program Files\PhotoFiltre
    [24/03/2006|09:44] C:\Program Files\Real
    [04/08/2006|19:13] C:\Program Files\Realtek AC97
    [04/08/2006|19:13] C:\Program Files\Realtek Sound Manager
    [23/01/2005|11:57] C:\Program Files\Services en ligne
    [07/04/2006|19:53] C:\Program Files\Shareaza
    [01/03/2006|19:09] C:\Program Files\Snapshot Viewer
    [06/08/2008|16:11] C:\Program Files\Sun
    [15/09/2008|22:03] C:\Program Files\Trend Micro
    [24/02/2008|17:33] C:\Program Files\TRENDnet
    [18/02/2007|12:14] C:\Program Files\UnFREEz
    [23/01/2005|12:07] C:\Program Files\Uninstall Information
    [23/03/2006|11:09] C:\Program Files\USB Driver-Express
    [23/03/2006|19:18] C:\Program Files\Valve
    [15/12/2007|13:49] C:\Program Files\Veoh Networks
    [27/05/2006|23:47] C:\Program Files\VideoLAN
    [26/03/2006|19:56] C:\Program Files\Vidmex
    [02/06/2007|23:20] C:\Program Files\Windows Live
    [23/01/2005|11:55] C:\Program Files\Windows Media Player
    [23/01/2005|11:55] C:\Program Files\Windows NT
    [23/01/2005|11:57] C:\Program Files\WindowsUpdate
    [22/03/2007|22:21] C:\Program Files\WindSolutions
    [30/05/2006|20:13] C:\Program Files\WinRAR
    [23/01/2005|11:58] C:\Program Files\xerox
    [15/09/2007|23:01] C:\Program Files\Xi
    [06/10/2006|16:57] C:\Program Files\Yahoo!

    --------------------\\ Listing des dossiers dans C:\Program Files\Fichiers communs

    [06/10/2006|16:39] C:\Program Files\Fichiers communs\Adobe
    [26/06/2006|21:45] C:\Program Files\Fichiers communs\Ahead
    [12/07/2007|18:54] C:\Program Files\Fichiers communs\Apple
    [20/08/2006|22:22] C:\Program Files\Fichiers communs\BOONTY Shared
    [26/12/2007|17:38] C:\Program Files\Fichiers communs\Designer
    [04/07/2006|20:12] C:\Program Files\Fichiers communs\Droppix
    [23/01/2005|12:05] C:\Program Files\Fichiers communs\InstallShield
    [25/02/2006|16:34] C:\Program Files\Fichiers communs\Java
    [09/04/2006|11:38] C:\Program Files\Fichiers communs\Logitech
    [23/01/2005|11:52] C:\Program Files\Fichiers communs\Microsoft Shared
    [23/01/2005|11:56] C:\Program Files\Fichiers communs\MSSoap
    [23/01/2005|12:12] C:\Program Files\Fichiers communs\muvee Technologies
    [23/01/2005|11:52] C:\Program Files\Fichiers communs\ODBC
    [24/03/2006|09:44] C:\Program Files\Fichiers communs\Real
    [23/01/2005|11:56] C:\Program Files\Fichiers communs\Services
    [23/01/2005|11:52] C:\Program Files\Fichiers communs\SpeechEngines
    [23/01/2005|12:13] C:\Program Files\Fichiers communs\Symantec Shared
    [23/01/2005|11:56] C:\Program Files\Fichiers communs\System
    [16/08/2008|14:25] C:\Program Files\Fichiers communs\xing shared

    --------------------\\ Process

    ( 38 Processes )

    ... OK !

    --------------------\\ Recherche avec S_Lop

    Aucun fichier / dossier Lop trouvé !

    --------------------\\ Recherche de Fichiers / Dossiers Lop

    C:\DOCUME~1\PAPAOU~1\Cookies\papa_ou_maman@advertising[1].txt

    --------------------\\ Verification du Registre

    ..... OK !

    --------------------\\ Verification du fichier Hosts

    Fichier Hosts PROPRE


    --------------------\\ Recherche de fichiers avec Catchme

    catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-09-17 16:20:51
    Windows 5.1.2600 Service Pack 3 FAT NTAPI
    scanning hidden processes ...
    scanning hidden files ...
    scan completed successfully
    hidden processes: 0
    hidden files: 0

    --------------------\\ Recherche d'autres infections

    --------------------\\ Cracks & Keygens ..

    C:\DOCUME~1\PAPAOU~1\Application Data\Real\RealPlayer\History\Pilotes Crack Musik feat. Hamz.lnk


    [F:13][D:1]-> C:\DOCUME~1\PAPAOU~1\LOCALS~1\Temp
    [F:1640][D:0]-> C:\DOCUME~1\PAPAOU~1\Cookies
    [F:12769][D:34]-> C:\DOCUME~1\PAPAOU~1\LOCALS~1\TEMPOR~1\content.IE5
    [F:2][D:0]-> C:\Recycled

    1 - "C:\Lop SD\LopR_1.txt" - 16/09/2008|21:07 - Option : [1]
    2 - "C:\Lop SD\LopR_2.txt" - 16/09/2008|21:15 - Option : [2]
    3 - "C:\Lop SD\LopR_3.txt" - 17/09/2008|16:22 - Option : [4]

    --------------------\\ Fin du rapport a 16:22:01
    a b 8 Sécurité
    17 Septembre 2008 17:00:04

    Reposte un rapport Hijackthis.
    17 Septembre 2008 19:38:43

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 19:38:38, on 17/09/2008
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16705)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
    C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
    C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\Program Files\Belkin\Logiciel Bluetooth\bin\btwdins.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\SOUNDMAN.EXE
    C:\Acer\Empowering Technology\eRecovery\Monitor.exe
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\Program Files\Acer\Acer eMode Management\AspireService.exe
    C:\Program Files\Acer\Acer eConsole\MediaSync.exe
    C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
    C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
    C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\Program Files\Belkin\Logiciel Bluetooth\BTTray.exe
    C:\Program Files\TRENDnet\TEW-424UB\WlanCU.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.yahoo.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://fr.yahoo.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.yahoo.com
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
    O4 - HKLM\..\Run: [LaunchApp] Alaunch
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
    O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
    O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
    O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [AspireService] C:\Program Files\Acer\Acer eMode Management\AspireService.exe
    O4 - HKLM\..\Run: [MediaSync] C:\Program Files\Acer\Acer eConsole\MediaSync.exe
    O4 - HKLM\..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\Monitor.exe
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe"
    O4 - HKLM\..\Run: [EEventManager] C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
    O4 - HKCU\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O4 - Global Startup: BTTray.lnk = ?
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O4 - Global Startup: Wireless Configuration Utility HW.14.lnk = C:\Program Files\TRENDnet\TEW-424UB\WlanCU.exe
    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
    O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Belkin\Logiciel Bluetooth\btsendto_ie.htm
    O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Belkin\Logiciel Bluetooth\btsendto_ie.htm
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267....
    O16 - DPF: {029FDBA6-3547-11D7-AA4C-0050BF051A00} (Rawflow ICD Client) - http://s.tf1.fr/mmdia/static/rawflow/clients/5.3.1.0/Ra...
    O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/FacebookPhotoUpload...
    O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.ca...
    O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
    O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClie...
    O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game01.zylom.com/activex/zylomgamesplayer.cab
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPACl...
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/fl...
    O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown....
    O17 - HKLM\System\CCS\Services\Tcpip\..\{34D677D2-65BC-45BA-A13F-C44FF0044F0F}: NameServer = 84.103.237.147 86.64.145.147
    O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
    O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
    O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\Belkin\Logiciel Bluetooth\bin\btwdins.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: Performance Monitor - Unknown owner - C:\WINDOWS\perfmon.exe (file missing)
    O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe

    --
    End of file - 10708 bytes
    a b 8 Sécurité
    17 Septembre 2008 20:05:59

    D'autres soucis ?
    17 Septembre 2008 20:44:15

    Non c'est parfait ! Je n'est plus de pubs ! Merci de ton aide ! :) 
    a b 8 Sécurité
    18 Septembre 2008 16:54:16

    Bon surf.
    Tom's guide dans le monde
    • Allemagne
    • Italie
    • Irlande
    • Royaume Uni
    • Etats Unis
    Suivre Tom's Guide
    Inscrivez-vous à la Newsletter
    • ajouter à twitter
    • ajouter à facebook
    • ajouter un flux RSS