Connection lente - A L'aide SVP

Résolu
Bonjour,
J'ai été infecté le 5 janvier 09 par Navipromo. J'ai passé Malwaresbytes' qui a mis Navipromo en quarantaine + Ad-Awre + Spybot + Avast Pro au démarrage mais aujourd'hui, j'ai une page blanche au démarrage d'internet Explorer et une connection lente. A l'aide SVP
Configuration: Windows XP
Internet Explorer 7.0

40 réponses

Résumé de la discussion

Une infection supposée par Navipromo le 5 janvier 2009 sur Windows XP entraîne une page blanche au démarrage d'Internet Explorer et une connexion lente persistante. Plusieurs outils de sécurité ont été utilisés, notamment Malwarebytes' Anti-Malware qui n'a détecté aucune infection lors d'un scan complet, Ad-Aware, Spybot et Avast Pro, tout en signalant des lenteurs et des soucis de navigation. En cas de suite, l'échange met en évidence des divergences entre les outils de détection et l'importance d'une vérification manuelle des processus et du fichier hosts.

Bobot (l’IA à votre service)
  1. Voici le rapport Malwarebyte :

    Malwarebytes' Anti-Malware 1.32
    Database version: 1648
    Windows 5.1.2600 Service Pack 3

    15/01/2009 17:23:05
    mbam-log-2009-01-15 (17-23-05).txt

    Scan type: Full Scan (C:\|D:\|)
    Objects scanned: 131372
    Time elapsed: 4 hour(s), 1 minute(s), 57 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 0

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    (No malicious items detected)
    1
    1. bonjour :

      commences par ceci pour voir ce qu'il en est,avoir un diagnostic précis et donc repérer les infections possibles et les neutraliser:

      Télécharges et installes le logiciel de diagnostic HijackThis :

      ici HijackThis
      ou ici http://www.trendsecure.com/portal/en-US/_download/HJTInstall.exe
      ou ici https://www.clubic.com/telecharger-fiche17891-hijackthis.html

      1- Cliques sur le setup pour lancer l'installe : laisses toi guider et ne modifies pas les paramètres d'installation .
      A la fin de l'installe , le prg ce lance automatiquement : fermes le en cliquant sur la croix rouge .
      Au final, tu dois avoir un raccourci sur ton bureau et aussi un cheminement comme :
      "C:\ program files\Trend Micro\HijackThis\HijackThis.exe " .

      tuto pour utilisation :
      Regardes ici, c'est parfaitement expliqué en images (merci balltrap34),
      http://perso.orange.fr/rginformatique/section%20virus/demohijack.htm
      ( Ne fixes encore AUCUNE ligne, cela pourrait empêcher ton PC de fonctionner correctement )

      2- !! Déconnectes toi et fermes toute tes applications en cours !!

      Cliques sur le raccourci du bureau pour lancer le prg :
      fais un scan HijackThis en cliquant sur : "Do a system scan and save a logfile"

      --->copies-colles le rapport généré pour analyse
      0
      1. Un très grand Merci à toi, gen-hackman de prendre le temps de m'aider.

        Voici donc le rapport Hijackthis :

        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 17:06:16, on 13/01/2009
        Platform: Windows XP SP3 (WinNT 5.01.2600)
        MSIE: Internet Explorer v7.00 (7.00.6000.16762)
        Boot mode: Normal

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        C:\Program Files\Alwil Software\Avast4\ashServ.exe
        C:\WINDOWS\Explorer.EXE
        C:\WINDOWS\system32\spoolsv.exe
        C:\WINDOWS\SOUNDMAN.EXE
        C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
        C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE
        C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
        C:\Program Files\ActivBoard\ABoard.exe
        C:\Program Files\Java\jre6\bin\jusched.exe
        C:\Program Files\Free Download Manager\fdm.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
        C:\Program Files\ActivBoard\AOSD.exe
        C:\Program Files\ABBYY FineReader 9.0\NetworkLicenseServer.exe
        C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe
        C:\Program Files\Java\jre6\bin\jqs.exe
        C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
        C:\Program Files\Wireless 802.11g Monitor\WLService.exe
        C:\Program Files\Wireless 802.11g Monitor\WLanCfgG.exe
        C:\Program Files\Cyberlink\Shared files\RichVideo.exe
        C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe
        C:\Program Files\Sunbelt Software\Personal Firewall\SbPFSvc.exe
        C:\WINDOWS\system32\svchost.exe
        C:\Program Files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe
        C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe
        C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
        C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
        C:\WINDOWS\system32\wbem\wmiapsrv.exe
        C:\Program Files\Sunbelt Software\Personal Firewall\SbPFCl.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
        C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
        C:\WINDOWS\system32\wuauclt.exe
        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://portail.free.fr/
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
        O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
        O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
        O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
        O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
        O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
        O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
        O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
        O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll
        O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
        O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
        O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
        O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
        O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
        O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
        O4 - HKLM\..\Run: [EPSON Stylus DX3800 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE /P26 "EPSON Stylus DX3800 Series" /O6 "USB001" /M "Stylus DX3800"
        O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
        O4 - HKLM\..\Run: [ActivBoard] C:\Program Files\ActivBoard\ABoard.exe
        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
        O4 - HKCU\..\Run: [Free Download Manager] "C:\Program Files\Free Download Manager\fdm.exe" -autorun
        O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
        O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
        O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
        O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
        O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
        O8 - Extra context menu item: Download video with Free Download Manager - file://C:\Program Files\Free Download Manager\dlfvideo.htm
        O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
        O8 - Extra context menu item: Tout télécharger avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
        O8 - Extra context menu item: Télécharger avec Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
        O8 - Extra context menu item: Télécharger la sélection avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
        O8 - Extra context menu item: Télécharger la vidéo avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlfvideo.htm
        O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
        O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
        O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
        O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
        O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
        O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
        O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
        O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.zebulon.fr/scan8/oscan8.cab
        O16 - DPF: {80DD2229-B8E4-4C77-B72F-F22972D723EA} - http://www.inoculer.com/antivirus/Msie/bitdefender.cab
        O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://dl8-cdn-01.sun.com/s/ESD5/JSCDL/jre/6u11-b90/jinstall-6u11-windows-i586-jc.cab?e=1229200137576&h=2d38eb83d12be0dba2ae064c246ef5df/&filename=jinstall-6u11-windows-i586-jc.cab
        O16 - DPF: {8F48147B-78D9-40F9-ACC0-BDDE59B246F4} (AccountHelper Class) - http://abonnement.aliceadsl.fr/configurateur/AccountHelper.cab
        O16 - DPF: {9D190AE6-C81E-4039-8061-978EBAD10073} (F-Secure Online Scanner 3.0) - https://www.f-secure.com/en/home/support
        O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} - https://www.f-secure.com/en/home/support
        O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
        O17 - HKLM\System\CS1\Services\Tcpip\..\{1F5A37B1-973F-451D-9430-518761143B3E}: NameServer = 213.36.80.1
        O23 - Service: Service de licence ABBYY FineReader 9.0 (ABBYY.Licensing.FineReader.Professional.9.0) - ABBYY (BIT Software) - C:\Program Files\ABBYY FineReader 9.0\NetworkLicenseServer.exe
        O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
        O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
        O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
        O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
        O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe
        O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe
        O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
        O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
        O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
        O23 - Service: R54G Wireless Service - Unknown owner - C:\Program Files\Wireless 802.11g Monitor\WLService.exe
        O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\Cyberlink\Shared files\RichVideo.exe
        O23 - Service: SbPF.Launcher - Sunbelt Software, Inc. - C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe
        O23 - Service: Sunbelt Personal Firewall 4 (SPF4) - Sunbelt Software, Inc. - C:\Program Files\Sunbelt Software\Personal Firewall\SbPFSvc.exe
        O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - C:\Program Files\TuneUp Utilities 2006\WinStylerThemeSvc.exe
        O23 - Service: BitDefender Communicator (XCOMM) - BitDefender - C:\Program Files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe
        0
        1. Télécharge MalwareByte's :
          http://www.malwarebytes.org/mbam.php ou ici :
          http://www.malwarebytes.org/mbam/program/mbam-setup.exe

          * Installe le ( choisis bien "francais" ; ne modifie pas les paramètres d'installe ) et mets le à jour .

          (NB : S'il te manque "COMCTL32.OCX" lors de l'installe, alors télécharge le ici : https://www.malekal.com/tutorial-aboutbuster/ )

          * Potasse le tuto pour te familiariser avec le prg :
          https://forum.pcastuces.com/sujet.asp?f=31&s=3
          ( cela dis, il est très simple d'utilisation ).

          ! Déconnecte toi et ferme toutes applications en cours !

          * Lance Malwarebyte's .

          Fais un examen dit "Rapide" .

          --> Laisse le programme travailler ( et ne rien faire d'autre avec le PC durant le scan ).
          --> à la fin tu cliques sur "résultat" .
          --> Vérifie que tous les objets infectés soient validés, puis clique sur " suppression " .

          Note : si il faut redémarrer ton PC pour finir le nettoyage, fais le !

          Poste le rapport sauvegardé après la suppression des objets infectés (dans l'onglet "rapport/log"de Malwarebytes, le dernier en date)

          0
          1. Merci gen-hackman,

            Voivci le rapport :

            Malwarebytes' Anti-Malware 1.32
            Version de la base de données: 1648
            Windows 5.1.2600 Service Pack 3

            13/01/2009 21:40:47
            mbam-log-2009-01-13 (21-40-47).txt

            Type de recherche: Examen rapide
            Eléments examinés: 57577
            Temps écoulé: 2 minute(s), 52 second(s)

            Processus mémoire infecté(s): 0
            Module(s) mémoire infecté(s): 0
            Clé(s) du Registre infectée(s): 0
            Valeur(s) du Registre infectée(s): 0
            Elément(s) de données du Registre infecté(s): 0
            Dossier(s) infecté(s): 0
            Fichier(s) infecté(s): 0

            Processus mémoire infecté(s):
            (Aucun élément nuisible détecté)

            Module(s) mémoire infecté(s):
            (Aucun élément nuisible détecté)

            Clé(s) du Registre infectée(s):
            (Aucun élément nuisible détecté)

            Valeur(s) du Registre infectée(s):
            (Aucun élément nuisible détecté)

            Elément(s) de données du Registre infecté(s):
            (Aucun élément nuisible détecté)

            Dossier(s) infecté(s):
            (Aucun élément nuisible détecté)

            Fichier(s) infecté(s):
            (Aucun élément nuisible détecté)

            Et pourtant, lorsque je lance Internet Explorer, j'ai d'abord une page blanche et je suis obligée d'en lancer une aute pour avoir la connection. Puis une fois sur deux, les pages plantent
            0
        2. bonjour :

          Télécharge Random's System Information Tool (RSIT) de random/random et enregistre l'exécutable sur ton Bureau.

          -> http://images.malwareremoval.com/random/RSIT.exe

          ! Déconnecte toi et ferme toutes tes applications en cours !

          Double-clique sur " RSIT.exe " pour le lancer .

          -> Une première fenêtre s'ouvre avec en titre : " Disclaimer of warranty " .

          * Devant l'option "List files/folders created ..." , tu choisis : 2 months

          * clique ensuite sur " Continue " pour lancer l'analyse ...

          -> laisse faire le scan et ne touche pas au PC ...

          Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront (probablement avec le bloc-note).

          Poste le contenu de " log.txt " (c'est celui qui apparait à l'écran), ainsi que de " info.txt " (que tu verras dans la barre des tâches), pour analyse et attends la suite ...

          Important : poste un rapport, puis l'autre dans la réponse suivante
          Si tu essaies de poster les deux en même temps, cela risque d'être trop long pour le forum

          ( Note : les rapports seront en outre sauvegardés dans ce dossier -> C:\rsit )
          0
          1. Voici le premier rapport gen-hackman ,

            Logfile of random's system information tool 1.05 (written by random/random)
            Run by Sophie at 2009-01-14 10:03:15
            Microsoft Windows XP Édition familiale Service Pack 3
            System drive C: has 23 GB (67%) free of 35 GB
            Total RAM: 1023 MB (55% free)

            Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 10:03:28, on 14/01/2009
            Platform: Windows XP SP3 (WinNT 5.01.2600)
            MSIE: Internet Explorer v7.00 (7.00.6000.16762)
            Boot mode: Normal

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
            C:\Program Files\Alwil Software\Avast4\ashServ.exe
            C:\WINDOWS\Explorer.EXE
            C:\WINDOWS\system32\spoolsv.exe
            C:\Program Files\ABBYY FineReader 9.0\NetworkLicenseServer.exe
            C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe
            C:\Program Files\Java\jre6\bin\jqs.exe
            C:\Program Files\Wireless 802.11g Monitor\WLService.exe
            C:\Program Files\Cyberlink\Shared files\RichVideo.exe
            C:\Program Files\Wireless 802.11g Monitor\WLanCfgG.exe
            C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe
            C:\Program Files\Sunbelt Software\Personal Firewall\SbPFSvc.exe
            C:\WINDOWS\system32\svchost.exe
            C:\Program Files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe
            C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe
            C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
            C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
            C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
            C:\Program Files\Sunbelt Software\Personal Firewall\SbPFCl.exe
            C:\WINDOWS\system32\wbem\wmiapsrv.exe
            C:\WINDOWS\SOUNDMAN.EXE
            C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
            C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE
            C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
            C:\Program Files\ActivBoard\ABoard.exe
            C:\Program Files\Java\jre6\bin\jusched.exe
            C:\Program Files\ActivBoard\AOSD.exe
            C:\Program Files\Free Download Manager\fdm.exe
            C:\WINDOWS\system32\ctfmon.exe
            C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
            C:\WINDOWS\System32\svchost.exe
            C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
            C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
            C:\WINDOWS\system32\wuauclt.exe
            C:\WINDOWS\system32\taskmgr.exe
            C:\WINDOWS\system32\NOTEPAD.EXE
            C:\Documents and Settings\Sophie\Bureau\RSIT.exe
            C:\Program Files\Trend Micro\HijackThis\Sophie.exe

            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://portail.free.fr/
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
            O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
            O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
            O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
            O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
            O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
            O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
            O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
            O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
            O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll
            O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
            O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
            O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
            O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
            O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
            O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
            O4 - HKLM\..\Run: [EPSON Stylus DX3800 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE /P26 "EPSON Stylus DX3800 Series" /O6 "USB001" /M "Stylus DX3800"
            O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
            O4 - HKLM\..\Run: [ActivBoard] C:\Program Files\ActivBoard\ABoard.exe
            O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
            O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
            O4 - HKCU\..\Run: [Free Download Manager] "C:\Program Files\Free Download Manager\fdm.exe" -autorun
            O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
            O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
            O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
            O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
            O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
            O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
            O8 - Extra context menu item: Download video with Free Download Manager - file://C:\Program Files\Free Download Manager\dlfvideo.htm
            O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
            O8 - Extra context menu item: Tout télécharger avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
            O8 - Extra context menu item: Télécharger avec Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
            O8 - Extra context menu item: Télécharger la sélection avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
            O8 - Extra context menu item: Télécharger la vidéo avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlfvideo.htm
            O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
            O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
            O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
            O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
            O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
            O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
            O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
            O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.zebulon.fr/scan8/oscan8.cab
            O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://dl8-cdn-01.sun.com/s/ESD5/JSCDL/jre/6u11-b90/jinstall-6u11-windows-i586-jc.cab?e=1229200137576&h=2d38eb83d12be0dba2ae064c246ef5df/&filename=jinstall-6u11-windows-i586-jc.cab
            O16 - DPF: {8F48147B-78D9-40F9-ACC0-BDDE59B246F4} (AccountHelper Class) - http://abonnement.aliceadsl.fr/configurateur/AccountHelper.cab
            O16 - DPF: {9D190AE6-C81E-4039-8061-978EBAD10073} (F-Secure Online Scanner 3.0) - https://www.f-secure.com/en/home/support
            O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
            O17 - HKLM\System\CS1\Services\Tcpip\..\{1F5A37B1-973F-451D-9430-518761143B3E}: NameServer = 213.36.80.1
            O23 - Service: Service de licence ABBYY FineReader 9.0 (ABBYY.Licensing.FineReader.Professional.9.0) - ABBYY (BIT Software) - C:\Program Files\ABBYY FineReader 9.0\NetworkLicenseServer.exe
            O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
            O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
            O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
            O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
            O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
            O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe
            O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe
            O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
            O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
            O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
            O23 - Service: R54G Wireless Service - Unknown owner - C:\Program Files\Wireless 802.11g Monitor\WLService.exe
            O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\Cyberlink\Shared files\RichVideo.exe
            O23 - Service: SbPF.Launcher - Sunbelt Software, Inc. - C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe
            O23 - Service: Sunbelt Personal Firewall 4 (SPF4) - Sunbelt Software, Inc. - C:\Program Files\Sunbelt Software\Personal Firewall\SbPFSvc.exe
            O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - C:\Program Files\TuneUp Utilities 2006\WinStylerThemeSvc.exe
            O23 - Service: BitDefender Communicator (XCOMM) - BitDefender - C:\Program Files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe
            0
            1. Et voici le deuxième :

              info.txt logfile of random's system information tool 1.05 2009-01-14 10:00:53

              ======Uninstall list======

              -->MsiExec.exe /X{E9F81423-211E-46B6-9AE0-38568BC5CF6F}
              -->C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
              -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
              µTorrent-->"C:\Program Files\uTorrent\uninstall.exe"
              ABBYY FineReader 9.0 Professional Edition-->MsiExec.exe /I{F9000000-0001-0000-0000-074957833700}
              Absolute Video Converter 2.6.7-->"C:\Program Files\Absolute Video Converter\unins000.exe"
              ActivBoard v1.2-->"C:\Program Files\ActivBoard\unins000.exe"
              Ad-Aware SE Personal-->C:\PROGRA~1\Lavasoft\AD-AWA~1\UNWISE.EXE C:\PROGRA~1\Lavasoft\AD-AWA~1\INSTALL.LOG
              Adobe Acrobat 5.0-->C:\WINDOWS\ISUNINST.EXE -f"C:\Program Files\Fichiers communs\Adobe\Acrobat 5.0\NT\Uninst.isu" -c"C:\Program Files\Fichiers communs\Adobe\Acrobat 5.0\NT\Uninst.dll"
              Adobe Acrobat and Reader 6.0.3 Update-->MsiExec.exe /I{AC76BA86-0000-7EC8-7489-000000000603}
              Adobe Flash Player 10 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
              Adobe Reader 6.0.1 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A00000000001}
              Adobe Shockwave Player-->C:\WINDOWS\system32\Adobe\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Adobe\SHOCKW~1\Install.log
              Archiveur WinRAR-->C:\Program Files\WinRAR\uninstall.exe
              ATI - Utilitaire de désinstallation du logiciel-->C:\Program Files\ATI Technologies\UninstallAll\AtiCimUn.exe
              ATI Catalyst Control Center-->MsiExec.exe /I{BE83EC7F-7519-4036-8B59-ECE494308124}
              ATI Display Driver-->rundll32 C:\WINDOWS\system32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
              ATI HYDRAVISION-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{083F79E4-6FE9-46FB-A6C6-4F8862742947}\setup.exe"
              ATI Parental Control & Encoder-->MsiExec.exe /I{8D70145A-3BD3-4DBF-9CBF-223EF4A43257}
              avast! Antivirus-->C:\Program Files\Alwil Software\Avast4\aswRunDll.exe "C:\Program Files\Alwil Software\Avast4\Setup\setiface.dll",RunSetup
              AVG Anti-Rootkit Free-->C:\Program Files\GRISOFT\AVG Anti-Rootkit Free\Uninstall.exe
              AVIConverter Smart-->C:\Program Files\AVIConverter\uninst.exe
              AVS Video Converter 3.4.3.183-->"C:\Program Files\AVSMedia\VideoConverter3\unins000.exe"
              CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
              CloneDVD2-->"C:\Program Files\Elaborate Bytes\CloneDVD2\CloneDVD2-uninst.exe" /D="C:\Program Files\Elaborate Bytes\CloneDVD2"
              Correctif pour Lecteur Windows Media 11 (KB939683)-->"C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
              Correctif pour Windows Internet Explorer 7 (KB947864)-->"C:\WINDOWS\ie7updates\KB947864-IE7\spuninst\spuninst.exe"
              Correctif pour Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
              devolo dLAN - Assistant de configuration-->C:\Program Files\devolo\setup.exe /remove:dlanconf
              devolo EasyClean-->C:\Program Files\devolo\setup.exe /remove:easyclean
              devolo EasyShare-->C:\Program Files\devolo\setup.exe /remove:easyshare
              devolo Informer-->C:\Program Files\devolo\setup.exe /remove:dslmon
              DivX Converter-->C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
              DivX Player-->C:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYER
              DivX Web Player-->C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
              D-Jix Media-->MsiExec.exe /X{D2449F4E-17DF-4414-8DC8-6FFB96038BE7}
              DVD Shrink 3.2-->"C:\Program Files\DVD Shrink\unins000.exe"
              EPSON Attach To Email-->C:\Program Files\Fichiers communs\InstallShield\Driver\8\Intel 32\IDriver.exe /M{20C45B32-5AB6-46A4-94EF-58950CAF05E5} /l1033 ADDREMOVEDLG
              EPSON Copy Utility 3-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{67EDD823-135A-4D59-87BD-950616D6E857}\SETUP.EXE" -l0x40c -UnInstall
              EPSON Easy Photo Print-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5DA7BC15-18D3-41A0-9F59-838DA3EAEF17}\SETUP.EXE" -l0x40c UNINST
              EPSON File Manager-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E86BC406-944E-41F6-ADE6-2C136734C96B}\Setup.exe" -l0x40c UNINST
              EPSON Image Clip Palette-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{314F6D08-A8B7-11D8-8446-0050BA1D384D}\Setup.exe" -l0x40c -u
              EPSON Logiciel imprimante-->C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\EPUPDATE.EXE /R
              EPSON Scan Assistant-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2A88F1BF-7041-4E42-84B1-6B4ACB83AC64}\Setup.exe" -l0x40c -u
              EPSON Scan-->C:\Program Files\epson\escndv\setup\setup.exe /r
              ESDX3800 Guide d'utilisation-->C:\Program Files\EPSON\TPMANUAL\ESDX3800\USE_G\DOCUNINS.EXE
              EVEREST Home Edition v2.20-->"C:\Program Files\Lavalys\EVEREST Home Edition\unins000.exe"
              Free Download Manager 2.5 Language pack-->"C:\Program Files\Free Download Manager\unins000.exe"
              Google Toolbar for Internet Explorer-->"C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_0531C63A913CC9D1.exe" /uninstall
              Hauppauge WinTV Infrared Remote-->C:\PROGRA~1\WinTV\UNir32.EXE C:\PROGRA~1\WinTV\ir32.LOG
              HijackThis 2.0.2-->"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
              Hotfix for Windows Media Format 11 SDK (KB929399)-->"C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
              IsoBuster 1.7-->"C:\Program Files\Smart Projects\IsoBuster\Uninst\unins000.exe"
              Java(TM) 6 Update 11-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216011FF}
              Kaspersky Online Scanner-->C:\WINDOWS\system32\KASPER~1\KASPER~1\kavuninstall.exe
              KC Softwares VideoInspector-->"C:\Program Files\KC Softwares\VideoInspector\unins000.exe"
              Language pack for Ad-Aware SE-->C:\PROGRA~1\Lavasoft\AD-AWA~1\Plugins\Langs\UNWISE.EXE C:\PROGRA~1\Lavasoft\AD-AWA~1\Plugins\Langs\INSTALL.LOG
              Lecteur Windows Media 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
              Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
              Matroska Playback Pack-->C:\Program Files\Matroska Playback Pack\uninstall.exe
              Media Player Classic fr-->"C:\Program Files\Media Player Classic\uninstall.exe"
              Microsoft .NET Framework 1.1 Hotfix (KB928366)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"
              Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
              Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
              Microsoft .NET Framework 2.0 Service Pack 1 Language Pack - FRA-->MsiExec.exe /I{3F7924B9-D148-3141-87B1-68F36043A940}
              Microsoft .NET Framework 2.0 Service Pack 1-->MsiExec.exe /I{B508B3F1-A24A-32C0-B310-85786919EF28}
              Microsoft .NET Framework 3.0 Service Pack 1 Language Pack - FRA-->MsiExec.exe /I{511DF669-2930-30C0-8EB6-552887E29EC8}
              Microsoft .NET Framework 3.0 Service Pack 1-->MsiExec.exe /I{2BA00471-0328-3743-93BD-FA813353A783}
              Microsoft .NET Framework 3.5 Language Pack - fra-->MsiExec.exe /I{5B76AEA2-D4E5-3B55-B965-ACC36AE0EAFC}
              Microsoft .NET Framework 3.5-->C:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5\setup.exe
              Microsoft .NET Framework 3.5-->MsiExec.exe /I{2FC099BD-AC9B-33EB-809C-D332E1B27C40}
              Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
              Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
              Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
              Microsoft Office XP Professional avec FrontPage-->MsiExec.exe /I{9028040C-6000-11D3-8CFE-0050048383C9}
              Microsoft User-Mode Driver Framework Feature Pack 1.0-->"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
              Microsoft Works-->MsiExec.exe /I{A059DE09-1B49-4450-B340-7AE097EC3F04}
              Mise à jour de sécurité pour Lecteur Windows Media (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Lecteur Windows Media 11 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Lecteur Windows Media 11 (KB954154)-->"C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows Internet Explorer 7 (KB938127)-->"C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows Internet Explorer 7 (KB944533)-->"C:\WINDOWS\ie7updates\KB944533-IE7\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows Internet Explorer 7 (KB950759)-->"C:\WINDOWS\ie7updates\KB950759-IE7\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows Internet Explorer 7 (KB953838)-->"C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows Internet Explorer 7 (KB956390)-->"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows Internet Explorer 7 (KB958215)-->"C:\WINDOWS\ie7updates\KB958215-IE7\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows Internet Explorer 7 (KB960714)-->"C:\WINDOWS\ie7updates\KB960714-IE7\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB923789)-->C:\WINDOWS\system32\MacroMed\Flash\genuinst.exe C:\WINDOWS\system32\MacroMed\Flash\KB923789.inf
              Mise à jour de sécurité pour Windows XP (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB950760)-->"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB951376)-->"C:\WINDOWS\$NtUninstallKB951376$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB953839)-->"C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB954211)-->"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB954459)-->"C:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB954600)-->"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB956391)-->"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB956841)-->"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB957095)-->"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
              Mise à jour pour Windows XP (KB951072-v2)-->"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
              Mise à jour pour Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
              Mise à jour pour Windows XP (KB955839)-->"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
              Module linguistique Microsoft .NET Framework 3.5 - fra-->C:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 Language Pack - fra\setup.exe
              Mozilla Firefox (2.0.0.11)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
              MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
              MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
              MSXML 6.0 Parser (KB933579)-->MsiExec.exe /I{0A869A65-8C94-4F7C-A5C7-972D3C8CED9E}
              Nero 6 Ultra Edition-->C:\Program Files\Ahead\nero\uninstall\UNNERO.exe /UNINSTALL
              NeroVision Express 3-->C:\WINDOWS\UNNeroVision.exe /UNINSTALL
              PeerGuardian 2.0-->"C:\Program Files\PeerGuardian2\unins000.exe"
              PowerCinema-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2637C347-9DAD-11D6-9EA2-00055D0CA761}\Setup.exe" -uninstall
              QuickTime Alternative 2.4.0-->"C:\Program Files\QuickTime Alternative\unins000.exe"
              SAMSUNG CDMA Modem Driver Set-->C:\WINDOWS\system32\Samsung_USB_Drivers\3\SSCDUninstall.exe
              SAMSUNG Mobile Composite Device Software-->C:\WINDOWS\system32\Samsung_USB_Drivers\6\SSBCUninstall.exe
              Samsung Mobile phone USB driver Software-->C:\WINDOWS\system32\Samsung_USB_Drivers\5\SSSDUninstall.exe
              SAMSUNG Mobile USB Modem 1.0 Software-->C:\WINDOWS\system32\Samsung_USB_Drivers\1\SS_Uninstall.exe
              SAMSUNG Mobile USB Modem Software-->C:\WINDOWS\system32\Samsung_USB_Drivers\2\SSM_Uninstall.exe
              Samsung PC Studio 3-->"C:\Program Files\InstallShield Installation Information\{C4A4722E-79F9-417C-BD72-8D359A090C97}\setup.exe" -runfromtemp -l0x040c -removeonly
              SimpleOCR 3.1-->C:\PROGRA~1\SIMPLE~1\UNWISE.EXE C:\PROGRA~1\SIMPLE~1\INSTALL.LOG
              Spybot - Search & Destroy-->"C:\Program Files\Spybot - Search & Destroy\unins000.exe"
              Sunbelt Personal Firewall-->MsiExec.exe /X{F61A549E-9C8A-4859-8BFE-2A4A018BBA4A}
              TuneUp Utilities 2006-->MsiExec.exe /I{868D7896-99D4-4513-BC62-2B3AD3E24926}
              Ulead PhotoImpact 12-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{11AFE21E-B193-430D-B57A-DFF7815BB962}\Setup.exe" -l0x40c
              Windows Imaging Component-->"C:\WINDOWS\$NtUninstallWIC$\spuninst\spuninst.exe"
              Windows Live Messenger-->MsiExec.exe /I{F6326B60-1B1D-4ABF-BFCD-7B7404F44411}
              Windows Live Sign-in Assistant-->MsiExec.exe /I{49672EC2-171B-47B4-8CE7-50D7806360D7}
              Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
              Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
              Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
              Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
              Wireless 802.11g USB Adapter-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2FB7E71E-32A3-4A7E-B22A-430CC8AD7029}\setup.exe" -l0x40c
              XML Paper Specification Shared Components Language Pack 1.0-->"C:\WINDOWS\$NtUninstallXPSEPSCLP$\spuninst\spuninst.exe"
              Xvid 1.1.3 final uninstall-->"C:\Program Files\Xvid\unins000.exe"
              ZebHelpProcess 2.24-->"C:\Program Files\ZebHelpProcess 2\unins000.exe"

              ======Hosts File======

              127.0.0.1 www.007guard.com
              127.0.0.1 007guard.com
              127.0.0.1 008i.com
              127.0.0.1 www.008k.com
              127.0.0.1 008k.com
              127.0.0.1 www.00hq.com
              127.0.0.1 00hq.com
              127.0.0.1 010402.com
              127.0.0.1 www.032439.com
              127.0.0.1 032439.com

              ======Security center information======

              AV: avast! antivirus 4.8.1296 [VPS 090113-1]
              FW: Sunbelt Personal Firewall

              System event log

              Computer Name: DIASSOPHIE
              Event Code: 256
              Message: Un délai a expiré lors de l'envoi de la notification de modification d'interface de périphérique à la fenêtre de "Dialog"

              Record Number: 39462
              Source Name: PlugPlayManager
              Time Written: 20081225194740.000000+060
              Event Type: Avertissement
              User:

              Computer Name: DIASSOPHIE
              Event Code: 256
              Message: Un délai a expiré lors de l'envoi de la notification de modification d'interface de périphérique à la fenêtre de "Dialog"

              Record Number: 39461
              Source Name: PlugPlayManager
              Time Written: 20081225194740.000000+060
              Event Type: Avertissement
              User:

              Computer Name: DIASSOPHIE
              Event Code: 256
              Message: Un délai a expiré lors de l'envoi de la notification de modification d'interface de périphérique à la fenêtre de "Dialog"

              Record Number: 39460
              Source Name: PlugPlayManager
              Time Written: 20081225194740.000000+060
              Event Type: Avertissement
              User:

              Computer Name: DIASSOPHIE
              Event Code: 256
              Message: Un délai a expiré lors de l'envoi de la notification de modification d'interface de périphérique à la fenêtre de "Dialog"

              Record Number: 39459
              Source Name: PlugPlayManager
              Time Written: 20081225194740.000000+060
              Event Type: Avertissement
              User:

              Computer Name: DIASSOPHIE
              Event Code: 256
              Message: Un délai a expiré lors de l'envoi de la notification de modification d'interface de périphérique à la fenêtre de "Dialog"

              Record Number: 39458
              Source Name: PlugPlayManager
              Time Written: 20081225194740.000000+060
              Event Type: Avertissement
              User:

              Application event log

              Computer Name: DIASSOPHIE
              Event Code: 0
              Message:
              Record Number: 1702
              Source Name: CLSched
              Time Written: 20080611104158.000000+120
              Event Type: Informations
              User:

              Computer Name: DIASSOPHIE
              Event Code: 1800
              Message: Le service Centre de sécurité Windows a démarré.

              Record Number: 1701
              Source Name: SecurityCenter
              Time Written: 20080611104157.000000+120
              Event Type: Informations
              User:

              Computer Name: DIASSOPHIE
              Event Code: 0
              Message:
              Record Number: 1700
              Source Name: CLCapSvc
              Time Written: 20080611104154.000000+120
              Event Type: Informations
              User:

              Computer Name: DIASSOPHIE
              Event Code: 0
              Message:
              Record Number: 1699
              Source Name: RichVideo
              Time Written: 20080611104149.000000+120
              Event Type: Informations
              User:

              Computer Name: DIASSOPHIE
              Event Code: 105
              Message: The service was started.

              Record Number: 1698
              Source Name: ATI Smart
              Time Written: 20080611104144.000000+120
              Event Type: Informations
              User:

              ======Environment variables======

              "ComSpec"=%SystemRoot%\system32\cmd.exe
              "Path"=%systemroot%\system32;%systemroot%;%systemroot%\system32\wbem;C:\Program Files\Samsung\Samsung PC Studio 3;C:\Program Files\Samsung\Samsung PC Studio 3\
              "windir"=%SystemRoot%
              "FP_NO_HOST_CHECK"=NO
              "OS"=Windows_NT
              "PROCESSOR_ARCHITECTURE"=x86
              "PROCESSOR_LEVEL"=15
              "PROCESSOR_IDENTIFIER"=x86 Family 15 Model 47 Stepping 2, AuthenticAMD
              "PROCESSOR_REVISION"=2f02
              "NUMBER_OF_PROCESSORS"=1
              "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
              "TEMP"=%SystemRoot%\TEMP
              "TMP"=%SystemRoot%\TEMP

              -----------------EOF-----------------
              0
              1. Telecharge maintenant FindyKill sur ton bureau :

                http://sd-1.archive-host.com/membres/up/116615172019703188/FindyKill.exe

                --> Lance l installation avec les parametres par default

                --> Au menu principal,choisi l option 1 (Recherche)

                --> Post le rapport FindyKill.txt

                Note : le rapport FindyKill.txt est sauvegardé a la racine du disque
                0
                1. Voici le rapport FindyKill :

                  ----------------- FindyKill V4.711 ------------------

                  * User : Sophie - DIASSOPHIE
                  * Emplacement : C:\Program Files\FindyKill
                  * Outils Mis a jours le 05/01/09 par Chiquitine29
                  * Recherche effectuée à 11:21:49 le 14/01/2009
                  * Windows XP - Internet Explorer 7.0.5730.13

                  ((((((((((((((((( *** Recherche *** ))))))))))))))))))

                  --------------- [ Processus actifs ] ----------------

                  C:\WINDOWS\System32\smss.exe
                  C:\WINDOWS\system32\csrss.exe
                  C:\WINDOWS\system32\winlogon.exe
                  C:\WINDOWS\system32\services.exe
                  C:\WINDOWS\system32\lsass.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                  C:\Program Files\Alwil Software\Avast4\ashServ.exe
                  C:\WINDOWS\Explorer.EXE
                  C:\WINDOWS\system32\spoolsv.exe
                  C:\WINDOWS\SOUNDMAN.EXE
                  C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
                  C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE
                  C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                  C:\Program Files\ActivBoard\ABoard.exe
                  C:\Program Files\Java\jre6\bin\jusched.exe
                  C:\Program Files\Free Download Manager\fdm.exe
                  C:\WINDOWS\system32\ctfmon.exe
                  C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                  C:\Program Files\ActivBoard\AOSD.exe
                  C:\Program Files\ABBYY FineReader 9.0\NetworkLicenseServer.exe
                  C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe
                  C:\Program Files\Java\jre6\bin\jqs.exe
                  C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
                  C:\Program Files\Wireless 802.11g Monitor\WLService.exe
                  C:\Program Files\Cyberlink\Shared files\RichVideo.exe
                  C:\Program Files\Wireless 802.11g Monitor\WLanCfgG.exe
                  C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe
                  C:\Program Files\Sunbelt Software\Personal Firewall\SbPFSvc.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\Program Files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe
                  C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe
                  C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                  C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                  C:\WINDOWS\system32\wbem\wmiapsrv.exe
                  C:\Program Files\Sunbelt Software\Personal Firewall\SbPFCl.exe
                  C:\WINDOWS\system32\wbem\wmiprvse.exe
                  C:\WINDOWS\System32\alg.exe
                  C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
                  C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\WINDOWS\system32\wuauclt.exe
                  C:\WINDOWS\system32\sol.exe
                  C:\Program Files\Internet Explorer\iexplore.exe
                  C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
                  C:\Program Files\Adobe\Acrobat 5.0\Reader\AcroRd32.exe
                  C:\WINDOWS\explorer.exe

                  --------------- [ Fichiers/Dossiers infectieux ] ----------------

                  »»»» Presence des fichiers dans C:

                  »»»» Presence des fichiers dans C:\WINDOWS

                  »»»» Presence des fichiers dans C:\WINDOWS\Prefetch

                  »»»» Presence des fichiers dans C:\WINDOWS\system32

                  »»»» Presence des fichiers dans C:\WINDOWS\system32\drivers

                  »»»» Presence des fichiers dans C:\Documents and Settings\Sophie\Application Data

                  »»»» Presence des fichiers dans C:\DOCUME~1\Sophie\LOCALS~1\Temp

                  »»»» Presence des fichiers dans C:\Documents and Settings\Sophie\Local Settings\Temporary Internet Files\Content.IE5

                  Found ! [06/12/2004 16:44] - C:\Program Files\epson\Creativity Suite\File Manager\Readme\_de\ReadMe.txt
                  Found ! [19/11/2004 12:28] - C:\Program Files\epson\Creativity Suite\File Manager\Readme\_en_GB\ReadMe.txt
                  Found ! [19/11/2004 12:28] - C:\Program Files\epson\Creativity Suite\File Manager\Readme\_en_US\ReadMe.txt
                  Found ! [06/12/2004 16:45] - C:\Program Files\epson\Creativity Suite\File Manager\Readme\_es\ReadMe.txt
                  Found ! [06/12/2004 16:48] - C:\Program Files\epson\Creativity Suite\File Manager\Readme\_fr\ReadMe.txt
                  Found ! [06/12/2004 16:45] - C:\Program Files\epson\Creativity Suite\File Manager\Readme\_it\ReadMe.txt
                  Found ! [06/12/2004 16:52] - C:\Program Files\epson\Creativity Suite\File Manager\Readme\_ko\ReadMe.txt
                  Found ! [06/12/2004 16:47] - C:\Program Files\epson\Creativity Suite\File Manager\Readme\_nl\ReadMe.txt
                  Found ! [06/12/2004 16:48] - C:\Program Files\epson\Creativity Suite\File Manager\Readme\_pt\ReadMe.txt
                  Found ! [06/12/2004 17:01] - C:\Program Files\epson\Creativity Suite\File Manager\Readme\_ru\ReadMe.txt
                  Found ! [06/12/2004 16:55] - C:\Program Files\epson\Creativity Suite\File Manager\Readme\_zh_CN\ReadMe.txt
                  Found ! [06/12/2004 16:57] - C:\Program Files\epson\Creativity Suite\File Manager\Readme\_zh_TW\ReadMe.txt

                  --------------- [ Registre / Startup ] ----------------

                  [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
                  Free Download Manager="C:\Program Files\Free Download Manager\fdm.exe" -autorun
                  ctfmon.exe=C:\WINDOWS\system32\ctfmon.exe
                  swg=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
                  NeroFilterCheck=C:\WINDOWS\system32\NeroCheck.exe
                  SoundMan=SOUNDMAN.EXE
                  ATICCC="C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
                  EPSON Stylus DX3800 Series=C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE /P26 "EPSON Stylus DX3800 Series" /O6 "USB001" /M "Stylus DX3800"
                  avast!=C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                  ActivBoard=C:\Program Files\ActivBoard\ABoard.exe
                  SunJavaUpdateSched="C:\Program Files\Java\jre6\bin\jusched.exe"
                  Malwarebytes' Anti-Malware="C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
                  HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents=
                  HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL=
                  Installed=1
                  HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI=
                  Installed=1
                  NoChange=1
                  HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS=
                  Installed=1

                  [HKEY_CURRENT_USER\software\local appwizard-generated applications\ABoard]
                  [HKEY_CURRENT_USER\software\local appwizard-generated applications\ashDisp]
                  [HKEY_CURRENT_USER\software\local appwizard-generated applications\DocUnins]
                  [HKEY_CURRENT_USER\software\local appwizard-generated applications\hldrrr]
                  [HKEY_CURRENT_USER\software\local appwizard-generated applications\mdelk]
                  [HKEY_CURRENT_USER\software\local appwizard-generated applications\nideiect]

                  --------------- [ Registre / Clés infectieuses ] ----------------

                  Found ! - HKEY_USERS\S-1-5-21-515967899-1844823847-682003330-1004\Software\Local AppWizard-Generated Applications\hldrrr
                  Found ! - HKEY_USERS\S-1-5-21-515967899-1844823847-682003330-1004\Software\Local AppWizard-Generated Applications\mdelk
                  Found ! - HKEY_USERS\S-1-5-21-515967899-1844823847-682003330-1004\Software\Local AppWizard-Generated Applications\nideiect
                  Found ! - HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\hldrrr
                  Found ! - HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\mdelk
                  Found ! - HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\nideiect

                  --------------- [ Etat / Services ] ----------------

                  +- Services : [ Auto=2 / Demande=3 / Désactivé=4 ]

                  /!\ Ndisuio - Type de démarrage = 4

                  EapHost - Type de démarrage = 3

                  Ip6Fw - Type de démarrage = 3

                  SharedAccess - Type de démarrage = 2

                  wuauserv - Type de démarrage = 2

                  wscsvc - Type de démarrage = 2

                  --------------- [ Recherche dans supports amovibles] ----------------

                  +- Informations :

                  C: - Lecteur fixe

                  D: - Lecteur fixe

                  +- presence des fichiers :

                  --------------- [ Registre / Mountpoint2 ] ----------------

                  -> Not found !

                  ------------------- ! Fin du rapport ! --------------------
                  0
                  1. Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) suceptible d avoir été infectés sans les ouvrir

                    -->double clic sur le raccourci FindyKill sur ton bureau

                    --> Au menu principal,choisi l option 2 (Suppression)

                    /!\ il y aura 2 redémarrage, laisse travailler l outils jusqu a l apparition du message "nettoyage effectué"

                    /!\ Ne te sert pas du pc durant la suppression , ton bureau ne sera pas accessible c est normal !

                    -------> ensuite post le rapport FindyKill.txt

                    Note : le rapport FindyKill.txt est sauvegardé a la racine du disque
                    0
                    1. Merci gen-hackman,

                      Je dois partir, je ferai ce que tu m'a conseillé en début d'après midi. Je te remercie pour ton aide.
                      0
                      1. Voici le rapport gen-hackmann,

                        Ma connection a encore très lente, j'ai peur de devoir réinitialiser

                        ----------------- FindyKill V4.711 ------------------

                        * User : Sophie - DIASSOPHIE
                        * executed from : C:\Program Files\FindyKill
                        * Update on 05/01/09 par Chiquitine29
                        * Start at 15:53:11 the 14/01/2009
                        * Windows XP - Internet Explorer 7.0.5730.13

                        ((((((((((((((( *** deleting *** ))))))))))))))))))

                        --------------- [ Active Processes ] ----------------

                        C:\WINDOWS\System32\smss.exe
                        C:\WINDOWS\system32\csrss.exe
                        C:\WINDOWS\system32\winlogon.exe
                        C:\WINDOWS\system32\services.exe
                        C:\WINDOWS\system32\lsass.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\system32\logonui.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                        C:\Program Files\Alwil Software\Avast4\ashServ.exe
                        C:\WINDOWS\system32\userinit.exe
                        C:\WINDOWS\system32\spoolsv.exe
                        C:\Program Files\Alwil Software\Avast4\setup\avast.setup
                        C:\Program Files\ABBYY FineReader 9.0\NetworkLicenseServer.exe
                        C:\WINDOWS\system32\ati2sgag.exe
                        C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe

                        --------------- [ Infected files / folders ] ----------------

                        »»»» Supression files in C:

                        »»»» Supression files in C:\WINDOWS

                        »»»» Supression files in C:\WINDOWS\Prefetch

                        »»»» Supression files in C:\WINDOWS\system32

                        »»»» Supression files in C:\WINDOWS\system32\drivers

                        »»»» Supression files in C:\Documents and Settings\Sophie\Application Data

                        »»»» Supression files in C:\DOCUME~1\Sophie\LOCALS~1\Temp

                        »»»» Supression files in C:\Documents and Settings\Sophie\Local Settings\Temporary Internet Files\Content.IE5

                        --------------- [ Registry / Infected keys ] ----------------

                        Deleted ! - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mdelk.exe
                        Deleted ! - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wintems.exe
                        Deleted ! - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\flec006.exe
                        Deleted ! - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\hldrrr.exe
                        Deleted ! - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\winfilse.exe
                        Deleted ! - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\winupgro.exe
                        Deleted ! - HKEY_USERS\S-1-5-21-515967899-1844823847-682003330-1004\Software\Local AppWizard-Generated Applications\hldrrr
                        Deleted ! - HKEY_USERS\S-1-5-21-515967899-1844823847-682003330-1004\Software\Local AppWizard-Generated Applications\mdelk
                        Deleted ! - HKEY_USERS\S-1-5-21-515967899-1844823847-682003330-1004\Software\Local AppWizard-Generated Applications\nideiect

                        --------------- [ States / Restarting of services ] ----------------

                        +- Services : [ Auto=2 / Request=3 / Disable=4 ]

                        Ndisuio - Type of startup = 3

                        EapHost - Type of startup = 2

                        Ip6Fw - Type of startup = 2

                        SharedAccess - Type of startup = 2

                        wuauserv - Type of startup = 2

                        wscsvc - Type of startup = 2

                        --------------- [ Cleaning removable drives ] ----------------

                        +- Informations :

                        C: - Lecteur fixe

                        D: - Lecteur fixe

                        J: - Lecteur amovible

                        K: - Lecteur fixe

                        +- deleting files :

                        --------------- [ Registry / Mountpoint2 ] ----------------

                        -> Not found !

                        --------------- [ Searching Other Infections ] ----------------

                        --------------- [ Searching Cracks / Keygen ] ----------------

                        C:\Documents and Settings\Sophie\.housecall6.6\Quarantine\[French] Alcohol.120%.(Version.1.9.2.1705).+.Crack.rar.bac_a00700
                        C:\Documents and Settings\Sophie\.housecall6.6\Quarantine\[French] Alcohol.120%.(Version.1.9.2.1705).+.Crack.rar.bac_a03156

                        ---------------- ! End of report ! ------------------
                        0
                        1. ---> Désactive ton antivirus le temps de la manipulation car OTMoveIt3 est détecté comme une infection à tort.

                          ---> Télécharge OTMoveIt3 (OldTimer) sur ton Bureau :
                          http://oldtimer.geekstogo.com/OTMoveIt3.exe

                          ---> Double-clique sur OTMoveIt3.exe afin de le lancer.

                          ---> Copie (Ctrl+C) le texte suivant ci-dessous :

                          :processes
                          explorer.exe

                          :files
                          C:\Documents and Settings\Sophie\.housecall6.6\Quarantine\[French] Alcohol.120%.(Version.1.9.2.1705).+.Crack.rar.bac_a00700
                          C:\Documents and Settings\Sophie\.housecall6.6\Quarantine\[French] Alcohol.120%.(Version.1.9.2.1705).+.Crack.rar.bac_a03156

                          :commands
                          [purity]
                          [emptytemp]
                          [start explorer]
                          [reboot]


                          ---> Colle (Ctrl+V) le texte précédemment copié dans le cadre Paste Instructions for Items to be Moved.

                          ---> Clique maintenant sur le bouton MoveIt! puis ferme OTMoveIt3.

                          Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
                          Accepte en cliquant sur YES.

                          ---> Poste le rapport situé dans ce dossier : C:\_OTMoveIt\MovedFiles\
                          Le nom du rapport correspond au moment de sa création : date_heure.log
                          0
                          1. Voici donc le rapport :

                            ========== PROCESSES ==========
                            Process explorer.exe killed successfully.
                            ========== FILES ==========
                            C:\Documents and Settings\Sophie\.housecall6.6\Quarantine\[French] Alcohol.120%.(Version.1.9.2.1705).+.Crack.rar.bac_a00700 moved successfully.
                            C:\Documents and Settings\Sophie\.housecall6.6\Quarantine\[French] Alcohol.120%.(Version.1.9.2.1705).+.Crack.rar.bac_a03156 moved successfully.
                            ========== COMMANDS ==========
                            File delete failed. C:\DOCUME~1\Sophie\LOCALS~1\Temp\Perflib_Perfdata_adc.dat scheduled to be deleted on reboot.
                            File delete failed. C:\DOCUME~1\Sophie\LOCALS~1\Temp\Perflib_Perfdata_b58.dat scheduled to be deleted on reboot.
                            File delete failed. C:\DOCUME~1\Sophie\LOCALS~1\Temp\Perflib_Perfdata_e40.dat scheduled to be deleted on reboot.
                            File delete failed. C:\DOCUME~1\Sophie\LOCALS~1\Temp\Perflib_Perfdata_e48.dat scheduled to be deleted on reboot.
                            User's Temp folder emptied.
                            User's Temporary Internet Files folder emptied.
                            User's Internet Explorer cache folder emptied.
                            File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat scheduled to be deleted on reboot.
                            File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Fichiers Internet temporaires\Content.IE5\index.dat scheduled to be deleted on reboot.
                            File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat scheduled to be deleted on reboot.
                            Local Service Temp folder emptied.
                            Local Service Temporary Internet Files folder emptied.
                            File delete failed. C:\WINDOWS\temp\_avast4_\Webshlock.txt scheduled to be deleted on reboot.
                            File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_61c.dat scheduled to be deleted on reboot.
                            Windows Temp folder emptied.
                            Java cache emptied.
                            FireFox cache emptied.
                            Temp folders emptied.
                            Explorer started successfully

                            OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 01142009_212927

                            Files moved on Reboot...
                            File C:\DOCUME~1\Sophie\LOCALS~1\Temp\Perflib_Perfdata_adc.dat not found!
                            File C:\DOCUME~1\Sophie\LOCALS~1\Temp\Perflib_Perfdata_b58.dat not found!
                            File C:\DOCUME~1\Sophie\LOCALS~1\Temp\Perflib_Perfdata_e40.dat not found!
                            File C:\DOCUME~1\Sophie\LOCALS~1\Temp\Perflib_Perfdata_e48.dat not found!
                            C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat moved successfully.
                            C:\Documents and Settings\LocalService\Local Settings\Temp\Fichiers Internet temporaires\Content.IE5\index.dat moved successfully.
                            C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat moved successfully.
                            File C:\WINDOWS\temp\_avast4_\Webshlock.txt not found!
                            File C:\WINDOWS\temp\Perflib_Perfdata_61c.dat not found!
                            0
                            1. maintenant desinstalle findykill , reinstalle-le et refais l'option 2 stp
                              0
                              1. un Très très grand Merci gen-hackman, il semblerai que tu m'ais sortie de mes problème. Plus de page blanche au démarrage et connection redevenu normal. Je touche du bois pour ne pas avoir parler trop vite.

                                Voici le rapport :

                                ----------------- FindyKill V4.711 ------------------

                                * User : Sophie - DIASSOPHIE
                                * executed from : C:\Program Files\FindyKill
                                * Update on 05/01/09 par Chiquitine29
                                * Start at 8:21:23 the 15/01/2009
                                * Windows XP - Internet Explorer 7.0.5730.13

                                ((((((((((((((( *** deleting *** ))))))))))))))))))

                                --------------- [ Active Processes ] ----------------

                                C:\WINDOWS\System32\smss.exe
                                C:\WINDOWS\system32\csrss.exe
                                C:\WINDOWS\system32\winlogon.exe
                                C:\WINDOWS\system32\services.exe
                                C:\WINDOWS\system32\lsass.exe
                                C:\WINDOWS\system32\svchost.exe
                                C:\WINDOWS\system32\svchost.exe
                                C:\WINDOWS\System32\svchost.exe
                                C:\WINDOWS\system32\svchost.exe
                                C:\WINDOWS\system32\logonui.exe
                                C:\WINDOWS\system32\svchost.exe
                                C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                C:\WINDOWS\system32\userinit.exe
                                C:\WINDOWS\system32\spoolsv.exe
                                C:\Program Files\ABBYY FineReader 9.0\NetworkLicenseServer.exe

                                --------------- [ Infected files / folders ] ----------------

                                »»»» Supression files in C:

                                »»»» Supression files in C:\WINDOWS

                                »»»» Supression files in C:\WINDOWS\Prefetch

                                »»»» Supression files in C:\WINDOWS\system32

                                »»»» Supression files in C:\WINDOWS\system32\drivers

                                »»»» Supression files in C:\Documents and Settings\Sophie\Application Data

                                »»»» Supression files in C:\DOCUME~1\Sophie\LOCALS~1\Temp

                                »»»» Supression files in C:\Documents and Settings\Sophie\Local Settings\Temporary Internet Files\Content.IE5

                                --------------- [ Registry / Infected keys ] ----------------

                                Deleted ! - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mdelk.exe
                                Deleted ! - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wintems.exe
                                Deleted ! - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\flec006.exe
                                Deleted ! - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\hldrrr.exe
                                Deleted ! - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\winfilse.exe
                                Deleted ! - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\winupgro.exe

                                --------------- [ States / Restarting of services ] ----------------

                                +- Services : [ Auto=2 / Request=3 / Disable=4 ]

                                Ndisuio - Type of startup = 3

                                EapHost - Type of startup = 2

                                Ip6Fw - Type of startup = 2

                                SharedAccess - Type of startup = 2

                                wuauserv - Type of startup = 2

                                wscsvc - Type of startup = 2

                                --------------- [ Cleaning removable drives ] ----------------

                                +- Informations :

                                C: - Lecteur fixe

                                D: - Lecteur fixe

                                +- deleting files :

                                --------------- [ Registry / Mountpoint2 ] ----------------

                                -> Not found !

                                --------------- [ Searching Other Infections ] ----------------

                                --------------- [ Searching Cracks / Keygen ] ----------------

                                ---------------- ! End of report ! ------------------
                                0
                                1. Bonjour ,
                                  tu as reinstallé Findykill avec l'installeur que je t'ai fait telecharger hier soir ?
                                  0
                                  1. oui, je l'ai mis sur le bureau et je l'ai installé a partir de là.

                                    Pourquoi ? Il y a quelque chos qui ne va pas ?
                                    0
                                    1. oui il a ete remis a jour hier soir vers 20.00 h

                                      donc je voudrais(pour etre sur)que tu desinstalles,supprimes , retelecharges au lien cité plus haut ,que tu reinstalles et que tu refasses l'option "suppression" car il y avait un petit bug (rien de grave )mais maintenant il est bon

                                      (remis a jour par notre ami Chiquitine29)
                                      0
                                      • 1
                                      • 2