SpyAxe - Page 2

  1. SmitFraudFix v2.388

    Rapport fait à 22:24:17,03, 14/01/2009
    Executé à partir de C:\Users\Ma couille\Downloads\SmitfraudFix
    OS: Microsoft Windows [version 6.0.6001] - Windows_NT
    Le type du système de fichiers est NTFS
    Fix executé en mode normal

    »»»»»»»»»»»»»»»»»»»»»»»» Process

    C:\Windows\system32\csrss.exe
    C:\Windows\system32\wininit.exe
    C:\Windows\system32\csrss.exe
    C:\Windows\system32\services.exe
    C:\Windows\system32\lsass.exe
    C:\Windows\system32\lsm.exe
    C:\Windows\system32\svchost.exe
    C:\Windows\system32\winlogon.exe
    C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
    C:\Windows\system32\svchost.exe
    C:\Windows\System32\svchost.exe
    C:\Windows\system32\Ati2evxx.exe
    C:\Windows\System32\svchost.exe
    C:\Windows\System32\svchost.exe
    C:\Windows\system32\svchost.exe
    C:\Windows\system32\SLsvc.exe
    C:\Windows\system32\svchost.exe
    C:\Windows\system32\Ati2evxx.exe
    C:\Windows\system32\svchost.exe
    C:\Windows\System32\spoolsv.exe
    C:\Windows\system32\Dwm.exe
    C:\Windows\system32\taskeng.exe
    C:\Windows\system32\svchost.exe
    C:\Windows\Explorer.EXE
    C:\Windows\system32\taskeng.exe
    C:\Program Files\Windows Defender\MSASCui.exe
    C:\Program Files\Java\jre6\bin\jusched.exe
    C:\Program Files\Toshiba\ConfigFree\NDSTray.exe
    C:\Program Files\McAfee.com\Agent\mcagent.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\Toshiba\HDMICtrlMan\HDMICtrlMan.exe
    C:\Program Files\Toshiba\Power Saver\TPwrMain.exe
    C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
    C:\Program Files\Toshiba\SmoothView\SmoothView.exe
    C:\Program Files\Toshiba\FlashCards\TCrdMain.exe
    C:\Program Files\Toshiba\Registration\ToshibaRegistration.exe
    C:\Program Files\Windows Sidebar\sidebar.exe
    C:\Program Files\Toshiba\TOSCDSPD\TOSCDSPD.exe
    C:\Program Files\Windows Sidebar\sidebar.exe
    C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
    C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
    c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
    C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
    C:\Program Files\McAfee\MPF\MPFSrv.exe
    C:\Program Files\McAfee\MSK\MskSrver.exe
    C:\Program Files\O2Micro Flash Memory Card Driver\o2flash.exe
    C:\Windows\system32\PnkBstrA.exe
    C:\Windows\system32\svchost.exe
    C:\Program Files\Alcohol Soft\Alcohol 52\StarWind\StarWindServiceAE.exe
    C:\Windows\system32\svchost.exe
    C:\Program Files\Toshiba TEMPRO\TempoSVC.exe
    C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe
    C:\Windows\system32\TODDSrv.exe
    C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe
    C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe
    C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
    C:\Windows\System32\svchost.exe
    C:\Windows\system32\SearchIndexer.exe
    C:\Windows\system32\DRIVERS\xaudio.exe
    C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
    C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
    C:\Program Files\Toshiba\ConfigFree\CFSwMgr.exe
    C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
    c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
    c:\PROGRA~1\mcafee\msc\mcuimgr.exe
    C:\Windows\system32\wbem\unsecapp.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    C:\Program Files\Windows Media Player\wmplayer.exe
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    C:\Program Files\Windows Live\Messenger\usnsvc.exe
    C:\Windows\system32\conime.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Windows\system32\cmd.exe
    C:\Windows\system32\SearchProtocolHost.exe
    C:\Windows\system32\SearchFilterHost.exe
    C:\Windows\system32\wbem\wmiprvse.exe

    »»»»»»»»»»»»»»»»»»»»»»»» hosts

    »»»»»»»»»»»»»»»»»»»»»»»» C:\

    »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows

    »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system

    »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\Web

    »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system32

    »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system32\LogFiles

    »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\Ma couille

    »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\MACOUI~1\AppData\Local\Temp

    »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\Ma couille\Application Data

    »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

    »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\MACOUI~1\FAVORI~1

    »»»»»»»»»»»»»»»»»»»»»»»» Bureau

    »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

    »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

    »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

    »»»»»»»»»»»»»»»»»»»»»»»» o4Patch
    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

    o4Patch
    Credits: Malware Analysis & Diagnostic
    Code: S!Ri

    »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

    IEDFix
    Credits: Malware Analysis & Diagnostic
    Code: S!Ri

    »»»»»»»»»»»»»»»»»»»»»»»» Agent.OMZ.Fix
    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

    Agent.OMZ.Fix
    Credits: Malware Analysis & Diagnostic
    Code: S!Ri

    »»»»»»»»»»»»»»»»»»»»»»»» VACFix
    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

    VACFix
    Credits: Malware Analysis & Diagnostic
    Code: S!Ri

    »»»»»»»»»»»»»»»»»»»»»»»» 404Fix
    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

    404Fix
    Credits: Malware Analysis & Diagnostic
    Code: S!Ri

    »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

    SrchSTS.exe by S!Ri
    Search SharedTaskScheduler's .dll

    »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
    "AppInit_DLLs"="C:\\PROGRA~1\\Google\\GOOGLE~3\\GOEC62~1.DLL"
    "LoadAppInit_DLLs"=dword:00000001

    »»»»»»»»»»»»»»»»»»»»»»»» Winlogon
    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
    "Userinit"="C:\\Windows\\system32\\userinit.exe,"

    »»»»»»»»»»»»»»»»»»»»»»»» RK

    »»»»»»»»»»»»»»»»»»»»»»»» DNS

    Description: Marvell Yukon 88E8040T PCI-E Fast Ethernet Controller
    DNS Server Search Order: 172.18.0.254

    HKLM\SYSTEM\CCS\Services\Tcpip\..\{721BFF50-04B0-4328-B2D4-8E6F0B1E0816}: DhcpNameServer=172.18.0.254
    HKLM\SYSTEM\CCS\Services\Tcpip\..\{FAEC06C6-2688-42B1-9FB5-83A7A3E5E3DA}: DhcpNameServer=192.168.1.1
    HKLM\SYSTEM\CS1\Services\Tcpip\..\{721BFF50-04B0-4328-B2D4-8E6F0B1E0816}: DhcpNameServer=172.18.0.254
    HKLM\SYSTEM\CS1\Services\Tcpip\..\{FAEC06C6-2688-42B1-9FB5-83A7A3E5E3DA}: DhcpNameServer=192.168.1.1
    HKLM\SYSTEM\CS2\Services\Tcpip\..\{721BFF50-04B0-4328-B2D4-8E6F0B1E0816}: DhcpNameServer=172.18.0.254
    HKLM\SYSTEM\CS2\Services\Tcpip\..\{FAEC06C6-2688-42B1-9FB5-83A7A3E5E3DA}: DhcpNameServer=192.168.1.1
    HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=172.18.0.254
    HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=172.18.0.254
    HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=172.18.0.254

    »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

    »»»»»»»»»»»»»»»»»»»»»»»» Fin
    0
    1. Contributeur sécurité
      Faire l'option 2 en mode sans echec car là fait en mode normale. et faire aussi hoster.
      0
      1. Smit fraudfix

        Option 2

        SmitFraudFix v2.388

        Rapport fait à 8:21:56,15, 15/01/2009
        Executé à partir de C:\Users\Ma couille\Downloads\SmitfraudFix
        OS: Microsoft Windows [version 6.0.6001] - Windows_NT
        Le type du système de fichiers est NTFS
        Fix executé en mode sans echec

        »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Avant SmitFraudFix
        !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

        SrchSTS.exe by S!Ri
        Search SharedTaskScheduler's .dll

        »»»»»»»»»»»»»»»»»»»»»»»» Arret des processus

        »»»»»»»»»»»»»»»»»»»»»»»» hosts

        127.0.0.1 localhost

        »»»»»»»»»»»»»»»»»»»»»»»» VACFix

        VACFix
        Credits: Malware Analysis & Diagnostic
        Code: S!Ri

        »»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

        S!Ri's WS2Fix: LSP not Found.

        »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

        GenericRenosFix by S!Ri

        »»»»»»»»»»»»»»»»»»»»»»»» Suppression des fichiers infectés

        »»»»»»»»»»»»»»»»»»»»»»»» IEDFix

        IEDFix
        Credits: Malware Analysis & Diagnostic
        Code: S!Ri

        »»»»»»»»»»»»»»»»»»»»»»»» Agent.OMZ.Fix

        Agent.OMZ.Fix
        Credits: Malware Analysis & Diagnostic
        Code: S!Ri

        »»»»»»»»»»»»»»»»»»»»»»»» 404Fix

        404Fix
        Credits: Malware Analysis & Diagnostic
        Code: S!Ri

        »»»»»»»»»»»»»»»»»»»»»»»» RK

        »»»»»»»»»»»»»»»»»»»»»»»» DNS

        HKLM\SYSTEM\CCS\Services\Tcpip\..\{721BFF50-04B0-4328-B2D4-8E6F0B1E0816}: DhcpNameServer=172.18.0.254
        HKLM\SYSTEM\CCS\Services\Tcpip\..\{FAEC06C6-2688-42B1-9FB5-83A7A3E5E3DA}: DhcpNameServer=192.168.1.1
        HKLM\SYSTEM\CS1\Services\Tcpip\..\{721BFF50-04B0-4328-B2D4-8E6F0B1E0816}: DhcpNameServer=172.18.0.254
        HKLM\SYSTEM\CS1\Services\Tcpip\..\{FAEC06C6-2688-42B1-9FB5-83A7A3E5E3DA}: DhcpNameServer=192.168.1.1
        HKLM\SYSTEM\CS3\Services\Tcpip\..\{721BFF50-04B0-4328-B2D4-8E6F0B1E0816}: DhcpNameServer=172.18.0.254
        HKLM\SYSTEM\CS3\Services\Tcpip\..\{FAEC06C6-2688-42B1-9FB5-83A7A3E5E3DA}: DhcpNameServer=192.168.1.1
        HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=172.18.0.254
        HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=172.18.0.254
        HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=172.18.0.254

        »»»»»»»»»»»»»»»»»»»»»»»» Suppression Fichiers Temporaires

        »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
        !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]

        »»»»»»»»»»»»»»»»»»»»»»»» Nettoyage du registre

        Nettoyage terminé.

        »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Après SmitFraudFix
        !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

        SrchSTS.exe by S!Ri
        Search SharedTaskScheduler's .dll

        »»»»»»»»»»»»»»»»»»»»»»»» Fin

        smitfraudfix

        option 1 après redémarrage

        SmitFraudFix v2.388

        Rapport fait à 8:30:21,75, 15/01/2009
        Executé à partir de C:\Users\Ma couille\Downloads\SmitfraudFix
        OS: Microsoft Windows [version 6.0.6001] - Windows_NT
        Le type du système de fichiers est NTFS
        Fix executé en mode normal

        »»»»»»»»»»»»»»»»»»»»»»»» Process

        C:\Windows\system32\csrss.exe
        C:\Windows\system32\wininit.exe
        C:\Windows\system32\csrss.exe
        C:\Windows\system32\services.exe
        C:\Windows\system32\lsass.exe
        C:\Windows\system32\lsm.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\system32\winlogon.exe
        C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\System32\svchost.exe
        C:\Windows\system32\Ati2evxx.exe
        C:\Windows\System32\svchost.exe
        C:\Windows\System32\svchost.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\system32\SLsvc.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\system32\Ati2evxx.exe
        C:\Windows\System32\spoolsv.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\system32\taskeng.exe
        C:\Windows\system32\Dwm.exe
        C:\Windows\Explorer.EXE
        C:\Program Files\Windows Defender\MSASCui.exe
        C:\Program Files\Java\jre6\bin\jusched.exe
        C:\Program Files\Toshiba\ConfigFree\NDSTray.exe
        C:\Program Files\McAfee.com\Agent\mcagent.exe
        C:\Windows\system32\taskeng.exe
        C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
        C:\Program Files\Toshiba\HDMICtrlMan\HDMICtrlMan.exe
        C:\Program Files\Toshiba\Power Saver\TPwrMain.exe
        C:\Program Files\Toshiba\SmoothView\SmoothView.exe
        C:\Program Files\Toshiba\FlashCards\TCrdMain.exe
        C:\Program Files\Toshiba\Registration\ToshibaRegistration.exe
        C:\Program Files\Toshiba TEMPRO\Toshiba.Tempo.UI.TrayApplication.exe
        C:\Program Files\Windows Sidebar\sidebar.exe
        C:\Program Files\Toshiba\TOSCDSPD\TOSCDSPD.exe
        C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
        C:\Program Files\Windows Sidebar\sidebar.exe
        C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
        c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
        C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
        C:\Program Files\McAfee\MPF\MPFSrv.exe
        C:\Program Files\McAfee\MSK\MskSrver.exe
        C:\Program Files\O2Micro Flash Memory Card Driver\o2flash.exe
        C:\Windows\system32\PnkBstrA.exe
        C:\Windows\system32\svchost.exe
        C:\Program Files\Alcohol Soft\Alcohol 52\StarWind\StarWindServiceAE.exe
        C:\Windows\system32\svchost.exe
        C:\Program Files\Toshiba TEMPRO\TempoSVC.exe
        C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe
        C:\Windows\system32\TODDSrv.exe
        C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe
        C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe
        C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
        C:\Windows\System32\svchost.exe
        C:\Windows\system32\SearchIndexer.exe
        C:\Windows\system32\DRIVERS\xaudio.exe
        C:\Program Files\Mozilla Firefox\firefox.exe
        C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
        C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
        C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
        C:\Program Files\Toshiba\ConfigFree\CFSwMgr.exe
        C:\Windows\system32\prevhost.exe
        C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
        C:\Windows\system32\cmd.exe
        C:\Windows\system32\conime.exe
        C:\Windows\system32\SearchProtocolHost.exe
        C:\Windows\system32\SearchFilterHost.exe
        C:\Windows\system32\wbem\wmiprvse.exe

        »»»»»»»»»»»»»»»»»»»»»»»» hosts

        »»»»»»»»»»»»»»»»»»»»»»»» C:\

        »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows

        »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system

        »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\Web

        »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system32

        »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system32\LogFiles

        »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\Ma couille

        »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\MACOUI~1\AppData\Local\Temp

        »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\Ma couille\Application Data

        »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

        »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\MACOUI~1\FAVORI~1

        »»»»»»»»»»»»»»»»»»»»»»»» Bureau

        »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

        »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

        »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

        »»»»»»»»»»»»»»»»»»»»»»»» o4Patch
        !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

        o4Patch
        Credits: Malware Analysis & Diagnostic
        Code: S!Ri

        »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
        !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

        IEDFix
        Credits: Malware Analysis & Diagnostic
        Code: S!Ri

        »»»»»»»»»»»»»»»»»»»»»»»» Agent.OMZ.Fix
        !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

        Agent.OMZ.Fix
        Credits: Malware Analysis & Diagnostic
        Code: S!Ri

        »»»»»»»»»»»»»»»»»»»»»»»» VACFix
        !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

        VACFix
        Credits: Malware Analysis & Diagnostic
        Code: S!Ri

        »»»»»»»»»»»»»»»»»»»»»»»» 404Fix
        !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

        404Fix
        Credits: Malware Analysis & Diagnostic
        Code: S!Ri

        »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
        !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

        SrchSTS.exe by S!Ri
        Search SharedTaskScheduler's .dll

        »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
        !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
        "AppInit_DLLs"="C:\\PROGRA~1\\Google\\GOOGLE~3\\GOEC62~1.DLL"
        "LoadAppInit_DLLs"=dword:00000001

        »»»»»»»»»»»»»»»»»»»»»»»» Winlogon
        !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
        "Userinit"="C:\\Windows\\system32\\userinit.exe,"

        »»»»»»»»»»»»»»»»»»»»»»»» RK

        »»»»»»»»»»»»»»»»»»»»»»»» DNS

        Description: Marvell Yukon 88E8040T PCI-E Fast Ethernet Controller
        DNS Server Search Order: 172.18.0.254

        HKLM\SYSTEM\CCS\Services\Tcpip\..\{721BFF50-04B0-4328-B2D4-8E6F0B1E0816}: DhcpNameServer=172.18.0.254
        HKLM\SYSTEM\CCS\Services\Tcpip\..\{FAEC06C6-2688-42B1-9FB5-83A7A3E5E3DA}: DhcpNameServer=192.168.1.1
        HKLM\SYSTEM\CS1\Services\Tcpip\..\{721BFF50-04B0-4328-B2D4-8E6F0B1E0816}: DhcpNameServer=172.18.0.254
        HKLM\SYSTEM\CS1\Services\Tcpip\..\{FAEC06C6-2688-42B1-9FB5-83A7A3E5E3DA}: DhcpNameServer=192.168.1.1
        HKLM\SYSTEM\CS3\Services\Tcpip\..\{721BFF50-04B0-4328-B2D4-8E6F0B1E0816}: DhcpNameServer=172.18.0.254
        HKLM\SYSTEM\CS3\Services\Tcpip\..\{FAEC06C6-2688-42B1-9FB5-83A7A3E5E3DA}: DhcpNameServer=192.168.1.1
        HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=172.18.0.254
        HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=172.18.0.254
        HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=172.18.0.254

        »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

        »»»»»»»»»»»»»»»»»»»»»»»» Fin
        0
        1. Contributeur sécurité
          Fait hoster.
          0
          1. je les fait fais il ne m'a rien affiché
            0
            1. Contributeur sécurité
              refait moi un hijackthis
              0
              1. Logfile of Trend Micro HijackThis v2.0.2
                Scan saved at 18:36:57, on 15/01/2009
                Platform: Windows Vista SP1 (WinNT 6.00.1905)
                MSIE: Internet Explorer v7.00 (7.00.6001.18000)
                Boot mode: Normal

                Running processes:
                C:\Windows\system32\taskeng.exe
                C:\Windows\system32\Dwm.exe
                C:\Windows\Explorer.EXE
                C:\Program Files\Windows Defender\MSASCui.exe
                C:\Program Files\Java\jre6\bin\jusched.exe
                C:\Program Files\Toshiba\ConfigFree\NDSTray.exe
                C:\Program Files\McAfee.com\Agent\mcagent.exe
                C:\Program Files\Toshiba\Toshiba Online Product Information\TOPI.exe
                C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                C:\Program Files\Toshiba\HDMICtrlMan\HDMICtrlMan.exe
                C:\Program Files\Toshiba\Power Saver\TPwrMain.exe
                C:\Program Files\Toshiba\SmoothView\SmoothView.exe
                C:\Program Files\Toshiba\FlashCards\TCrdMain.exe
                C:\Program Files\Toshiba\Registration\ToshibaRegistration.exe
                C:\Program Files\Windows Sidebar\sidebar.exe
                C:\Program Files\Toshiba\TOSCDSPD\TOSCDSPD.exe
                C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
                C:\Program Files\Windows Sidebar\sidebar.exe
                C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
                C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
                C:\Program Files\Mozilla Firefox\firefox.exe
                C:\Program Files\Toshiba\ConfigFree\CFSwMgr.exe
                c:\PROGRA~1\mcafee\msc\mcuimgr.exe
                C:\Windows\system32\wbem\unsecapp.exe
                C:\Program Files\Windows Media Player\wmplayer.exe
                C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                O2 - BHO: McAntiPhishingBHO - {377C180E-6F0E-4D4C-980F-F45BD3D40CF4} - c:\PROGRA~1\mcafee\msk\mcapbho.dll
                O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
                O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
                O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll (file missing)
                O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll (file missing)
                O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
                O4 - HKLM\..\Run: [ITSecMng] %ProgramFiles%\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe /START
                O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
                O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
                O4 - HKLM\..\Run: [Desktop SMS] C:\Program Files\IDM\Desktop SMS\DesktopSMS.exe /auto
                O4 - HKLM\..\Run: [topi] C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe -startup
                O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
                O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                O4 - HKLM\..\Run: [Camera Assistant Software] "C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe" /start
                O4 - HKLM\..\Run: [HDMICtrlMan] C:\Program Files\TOSHIBA\HDMICtrlMan\HDMICtrlMan.exe
                O4 - HKLM\..\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
                O4 - HKLM\..\Run: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe
                O4 - HKLM\..\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
                O4 - HKLM\..\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
                O4 - HKLM\..\Run: [Toshiba Registration] C:\Program Files\Toshiba\Registration\ToshibaRegistration.exe
                O4 - HKLM\..\Run: [Toshiba TEMPO] C:\Program Files\Toshiba TEMPRO\Toshiba.Tempo.UI.TrayApplication.exe
                O4 - HKLM\..\Run: [SMSTray] C:\Program Files\Samsung\EmoDio\SMSTray.exe
                O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe
                O4 - HKCU\..\Run: [TOSCDSPD] TOSCDSPD.EXE
                O4 - HKCU\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
                O4 - HKCU\..\Run: [sswaoog] "c:\users\ma couille\appdata\local\sswaoog.exe" sswaoog
                O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 52\axcmd.exe" /automount
                O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                O4 - HKUS\S-1-5-18\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'SYSTEM')
                O4 - HKUS\.DEFAULT\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'Default user')
                O4 - .DEFAULT User Startup: TRDCReminder.lnk = C:\Program Files\Toshiba\TRDCReminder\TRDCReminder.exe (User 'Default user')
                O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
                O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
                O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
                O9 - Extra button: (no name) - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - (no file)
                O9 - Extra button: eBay - Achetez, Vendez - {76577871-04EC-495E-A12B-91F7C3600AFA} - https://www.ebay.fr (file missing)
                O9 - Extra button: Amazon.fr - {8A918C1D-E123-4E36-B562-5C1519E434CE} - https://www.amazon.fr/exec/obidos/subst/home/home.html/262-6263521-6325360?_encoding=UTF8&link_code=hom&tag=Toshibafrbholink-21 (file missing)
                O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
                O13 - Gopher Prefix:
                O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
                O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
                O23 - Service: ConfigFree Service - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
                O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
                O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
                O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
                O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
                O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
                O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
                O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
                O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
                O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
                O23 - Service: O2Micro Flash Memory Card Service (o2flash) - O2Micro International - C:\Program Files\O2Micro Flash Memory Card Driver\o2flash.exe
                O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
                O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
                O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
                O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 52\StarWind\StarWindServiceAE.exe
                O23 - Service: Notebook Performance Tuning Service (TempoMonitoringService) - Toshiba Europe GmbH - C:\Program Files\Toshiba TEMPRO\TempoSVC.exe
                O23 - Service: TOSHIBA Navi Support Service (TNaviSrv) - TOSHIBA Corporation - C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe
                O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe
                O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe
                O23 - Service: TOSHIBA Bluetooth Service - Unknown owner - c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe (file missing)
                O23 - Service: TOSHIBA SMART Log Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe
                O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
                O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
                0
                1. Contributeur sécurité
                  Etape 1/ Télécharge :

                  - FindyKill http://sd-1.archive-host.com/membres/up/116615172019703188/FindyKill.exe (Chiquitine29) sur le Bureau.

                  Note importante : l'infection bagle s'installant au moyen d'un crack/keygen, tu dois IMPERATIVEMENT supprimer ce type de fichier.

                  # Etape 2/

                  Lance l'installation avec les paramètres par défaut
                  - Double-clique sur le raccourci FindyKill sur le Bureau (sous Vista : clic droit sur le raccourci --> Exécuter en temps qu'Administrateur)
                  - Au menu principal, sélectionne l'option 1 (Recherche)
                  - Le rapport est sauvegardé à la racine du disque dur (C:\FindyKill.txt )
                  Avant de faire quoi que ce soit d'autre, il est fortement recommandé de poster le rapport sur le forum pour avoir l'avis d'un spécialiste.Après confirmation par un intervenant qualifié du forum, passe au nettoyage
                  0
                  1. ----------------- FindyKill V4.712 ------------------

                    * User : Ma couille - MA-COUILLE
                    * Emplacement : C:\Program Files\FindyKill
                    * Outils Mis a jours le 14/01/09 par Chiquitine29
                    * Recherche effectuée à 13:01:52 le 16/01/2009
                    * Windows Vista - Internet Explorer 7.0.6001.18000

                    ((((((((((((((((( *** Recherche *** ))))))))))))))))))

                    --------------- [ Processus actifs ] ----------------

                    C:\Windows\System32\smss.exe
                    C:\Windows\system32\csrss.exe
                    C:\Windows\system32\wininit.exe
                    C:\Windows\system32\csrss.exe
                    C:\Windows\system32\services.exe
                    C:\Windows\system32\lsass.exe
                    C:\Windows\system32\lsm.exe
                    C:\Windows\system32\svchost.exe
                    C:\Windows\system32\winlogon.exe
                    C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
                    C:\Windows\system32\svchost.exe
                    C:\Windows\System32\svchost.exe
                    C:\Windows\system32\Ati2evxx.exe
                    C:\Windows\System32\svchost.exe
                    C:\Windows\System32\svchost.exe
                    C:\Windows\system32\svchost.exe
                    C:\Windows\system32\SLsvc.exe
                    C:\Windows\system32\svchost.exe
                    C:\Windows\system32\Ati2evxx.exe
                    C:\Windows\system32\svchost.exe
                    C:\Windows\System32\spoolsv.exe
                    C:\Windows\system32\Dwm.exe
                    C:\Windows\system32\taskeng.exe
                    C:\Windows\system32\svchost.exe
                    C:\Windows\Explorer.EXE
                    C:\Program Files\Windows Defender\MSASCui.exe
                    C:\Program Files\Java\jre6\bin\jusched.exe
                    C:\Program Files\Toshiba\ConfigFree\NDSTray.exe
                    C:\Program Files\McAfee.com\Agent\mcagent.exe
                    C:\Program Files\Toshiba\Toshiba Online Product Information\TOPI.exe
                    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                    C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe
                    C:\Program Files\Toshiba\HDMICtrlMan\HDMICtrlMan.exe
                    C:\Program Files\Toshiba\Power Saver\TPwrMain.exe
                    C:\Program Files\Toshiba\SmoothView\SmoothView.exe
                    C:\Program Files\Toshiba\FlashCards\TCrdMain.exe
                    C:\Windows\system32\taskeng.exe
                    C:\Program Files\Toshiba\Registration\ToshibaRegistration.exe
                    C:\Program Files\Toshiba TEMPRO\Toshiba.Tempo.UI.TrayApplication.exe
                    C:\Program Files\Samsung\EmoDio\SMSTray.exe
                    C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
                    c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
                    C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
                    C:\Program Files\McAfee\MPF\MPFSrv.exe
                    C:\Program Files\Windows Sidebar\sidebar.exe
                    C:\Program Files\McAfee\MSK\MskSrver.exe
                    C:\Program Files\O2Micro Flash Memory Card Driver\o2flash.exe
                    C:\Windows\system32\PnkBstrA.exe
                    C:\Windows\system32\svchost.exe
                    C:\Program Files\Alcohol Soft\Alcohol 52\StarWind\StarWindServiceAE.exe
                    C:\Windows\system32\svchost.exe
                    C:\Program Files\Toshiba TEMPRO\TempoSVC.exe
                    C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe
                    C:\Windows\system32\TODDSrv.exe
                    C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe
                    C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe
                    C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
                    C:\Windows\System32\svchost.exe
                    C:\Windows\system32\SearchIndexer.exe
                    C:\Windows\system32\DRIVERS\xaudio.exe
                    C:\Program Files\Toshiba\TOSCDSPD\TOSCDSPD.exe
                    C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
                    C:\Program Files\Camera Assistant Software for Toshiba\CEC_MAIN.exe
                    C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
                    C:\Program Files\Toshiba\ConfigFree\CFSwMgr.exe
                    C:\Program Files\Windows Sidebar\sidebar.exe
                    C:\Program Files\Mozilla Firefox\firefox.exe
                    C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
                    C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
                    C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
                    C:\Program Files\Internet Explorer\iexplore.exe
                    c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
                    c:\PROGRA~1\mcafee\msc\mcuimgr.exe
                    C:\Windows\system32\wbem\wmiprvse.exe
                    C:\Windows\system32\wbem\unsecapp.exe
                    C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
                    c:\PROGRA~1\mcafee\VIRUSS~1\mcvsshld.exe
                    C:\Windows\system32\conime.exe

                    --------------- [ Fichiers/Dossiers infectieux ] ----------------

                    »»»» Presence des fichiers dans C:

                    »»»» Presence des fichiers dans C:\Windows

                    »»»» Presence des fichiers dans C:\Windows\Prefetch

                    Found ! - C:\Windows\Prefetch\O4PATCH.EXE-85AAB71C.pf

                    »»»» Presence des fichiers dans C:\Windows\system32

                    »»»» Presence des fichiers dans C:\Windows\system32\drivers

                    »»»» Presence des fichiers dans C:\Users\Ma couille\AppData\Roaming

                    »»»» Presence des fichiers dans C:\Users\MACOUI~1\AppData\Local\Temp

                    --------------- [ Registre / Startup ] ----------------

                    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
                    Sidebar=C:\Program Files\Windows Sidebar\sidebar.exe
                    TOSCDSPD=TOSCDSPD.EXE
                    ISUSPM Startup=C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
                    sswaoog="c:\users\ma couille\appdata\local\sswaoog.exe" sswaoog
                    AlcoholAutomount="C:\Program Files\Alcohol Soft\Alcohol 52\axcmd.exe" /automount

                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
                    Windows Defender=%ProgramFiles%\Windows Defender\MSASCui.exe -hide
                    SunJavaUpdateSched="C:\Program Files\Java\jre6\bin\jusched.exe"
                    NDSTray.exe=NDSTray.exe
                    ITSecMng=%ProgramFiles%\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe /START
                    Adobe Reader Speed Launcher="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                    mcagent_exe=C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
                    Google Desktop Search="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
                    Desktop SMS=C:\Program Files\IDM\Desktop SMS\DesktopSMS.exe /auto
                    topi=C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe -startup
                    StartCCC="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
                    SynTPEnh=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                    Camera Assistant Software="C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe" /start
                    HDMICtrlMan=C:\Program Files\TOSHIBA\HDMICtrlMan\HDMICtrlMan.exe
                    TPwrMain=%ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
                    HSON=%ProgramFiles%\TOSHIBA\TBS\HSON.exe
                    SmoothView=%ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
                    00TCrdMain=%ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
                    Toshiba Registration=C:\Program Files\Toshiba\Registration\ToshibaRegistration.exe
                    Toshiba TEMPO=C:\Program Files\Toshiba TEMPRO\Toshiba.Tempo.UI.TrayApplication.exe
                    SMSTray=C:\Program Files\Samsung\EmoDio\SMSTray.exe
                    HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents=
                    <NO NAME>=
                    HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL=
                    Installed=1
                    <NO NAME>=
                    HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI=
                    NoChange=1
                    Installed=1
                    <NO NAME>=
                    HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS=
                    Installed=1
                    <NO NAME>=

                    [HKEY_CURRENT_USER\software\local appwizard-generated applications\Samsung Media Studio]

                    --------------- [ Registre / Clés infectieuses ] ----------------

                    Found ! - HKEY_USERS\S-1-5-21-2021771536-4248035453-290974279-1000\Software\Ubisoft

                    --------------- [ Etat / Services ] ----------------

                    +- Services : [ Auto=2 / Demande=3 / Désactivé=4 ]

                    Ndisuio - Type de démarrage = 3

                    EapHost - Type de démarrage = 3

                    Wlansvc - Type de démarrage = 2

                    /!\ SharedAccess - Type de démarrage = 4

                    wuauserv - Type de démarrage = 2

                    wscsvc - Type de démarrage = 2

                    WinDefend - Type de démarrage = 2

                    /!\ UAC is Disable

                    --------------- [ Recherche dans supports amovibles] ----------------

                    +- Informations :

                    C: - Lecteur fixe
                    E: - Lecteur fixe

                    +- presence des fichiers :

                    --------------- [ Registre / Mountpoint2 ] ----------------

                    -> Not found !

                    ------------------- ! Fin du rapport ! --------------------
                    0
                    1. Contributeur sécurité
                      Etape 3/

                      Branche toutes tes sources de données externes au PC (clés USB, disques durs externes, lecteurs mp3, iPod...) sans les ouvrir- Relance FindyKill,
                      - Cette fois, sélectionne l'option 2 (Suppression) au menu principal.
                      - Il y aura 2 redémarrages, laisse travailler l'outil jusqu'à l'apparition du message "Nettoyage effectué !"
                      - Ensuite poste le rapport C:\FindyKill.txt
                      0
                      1. Contributeur sécurité
                        Ensuite tu va désinstaller navilog et le réinstaller et passer directement à l'option 2. Merci.
                        0
                        Précédent
                        • 1
                        • 2