Cheval de troie purityscan - Page 2

Résolu
  1. Voila!!!

    ========== PROCESSES ==========
    Process explorer.exe killed successfully.
    ========== REGISTRY ==========
    Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\Bxjfk deleted successfully.
    Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\Euec deleted successfully.
    Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\Rll deleted successfully.
    ========== FILES ==========
    File/Folder c:\documents and settings\laura\application data\s?stem\??rvices.exe not found.
    File/Folder c:\program files\ystem~1\userinit.exe not found.
    File/Folder c:\documents and settings\laura\application data\?ystem\w?wexec.exe not found.
    File/Folder c:\documents and settings\laura\application data\s?stem\??rvices.exe not found.
    File/Folder c:\documents and settings\laura\application data\?ystem\w?wexec.exe not found.
    ========== COMMANDS ==========
    User's Temp folder emptied.
    User's Temporary Internet Files folder emptied.
    User's Internet Explorer cache folder emptied.
    Local Service Temp folder emptied.
    Local Service Temporary Internet Files folder emptied.
    Windows Temp folder emptied.
    FireFox cache emptied.
    Temp folders emptied.

    OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 02072009_100229

    ca a l'air beaucoup mieux, je n'ai plus les icones de pubs qui se reinstallent a chaque fois...
    0
    1. Re,

      Redémarre ton pc et refait un rapport avec rsit.

      merci
      0
      1. merci a toi!

        rsit m'a juste sorti un rapport log, le rapport info n'a pas ete modifie

        Logfile of random's system information tool 1.05 (written by random/random)
        Run by Laura at 2009-02-08 09:02:34
        Microsoft Windows XP Édition familiale Service Pack 2
        System drive C: has 8 GB (50%) free of 17 GB
        Total RAM: 445 MB (16% free)

        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 09:02, on 2009-02-08
        Platform: Windows XP SP2 (WinNT 5.01.2600)
        MSIE: Internet Explorer v7.00 (7.00.6000.16762)
        Boot mode: Normal

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
        C:\Acer\eManager\anbmServ.exe
        C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
        C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
        C:\Program Files\Bonjour\mDNSResponder.exe
        C:\Program Files\Java\jre6\bin\jqs.exe
        C:\WINDOWS\Explorer.EXE
        C:\WINDOWS\system32\keyhook.exe
        C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
        C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
        C:\WINDOWS\system32\wbem\wmiapsrv.exe
        C:\Program Files\Launch Manager\QtZgAcer.EXE
        C:\Acer\Empowering Technology\eRecovery\Monitor.exe
        C:\WINDOWS\SOUNDMAN.EXE
        C:\Program Files\Java\jre6\bin\jusched.exe
        C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\WINDOWS\system32\sistray.exe
        C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\wuauclt.exe
        C:\Program Files\Mozilla Firefox\firefox.exe
        C:\WINDOWS\system32\wuauclt.exe
        C:\Documents and Settings\Laura\Bureau\RSIT.exe
        C:\hijackthis\Laura.exe

        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
        R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
        O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
        O2 - BHO: (no name) - {1FD79A1C-09AB-0A5C-8C3D-50C0705881C8} - C:\WINDOWS\system32\fdid.dll (file missing)
        O2 - BHO: (no name) - {33E3FF63-388C-3804-A34D-68E33CEDFA91} - C:\WINDOWS\system32\lcey.dll (file missing)
        O2 - BHO: (no name) - {398DF3BE-6F0E-39DA-2975-3BB6094DA4C1} - C:\WINDOWS\system32\ejcydgb.dll (file missing)
        O2 - BHO: (no name) - {418E1354-DAB8-F539-C52A-89CD5519DE9B} - C:\WINDOWS\system32\opntlhi.dll (file missing)
        O2 - BHO: (no name) - {671FD78E-483B-45B9-4CF3-13D4CEC2A993} - C:\WINDOWS\system32\ptmauvma.dll (file missing)
        O2 - BHO: (no name) - {7011EE4A-29AE-7D22-897F-7B129343B5CE} - C:\WINDOWS\system32\vrcm.dll (file missing)
        O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
        O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
        O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
        O4 - HKLM\..\Run: [LaunchApp] Alaunch
        O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
        O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\system32\keyhook.exe
        O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
        O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
        O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
        O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
        O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
        O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
        O4 - HKLM\..\Run: [LManager] C:\Program Files\Launch Manager\QtZgAcer.EXE
        O4 - HKLM\..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\Monitor.exe
        O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
        O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
        O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKCU\..\Run: [Nphb] "C:\DOCUME~1\Laura\MESDOC~1\CROSOF~1.NET\mshta.exe" -vt yazb
        O4 - HKCU\..\Run: [Czapd] C:\WINDOWS\F?nts\??chost.exe
        O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\WANADOO\Shell.exe appLaunchClientZone.shl|DEFAULT=cnx|PARAM=
        O4 - HKCU\..\Run: [updateMgr] c:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_1_0
        O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
        O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
        O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe
        O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
        O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
        O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
        O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
        O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
        O23 - Service: Notebook Manager Service (anbmService) - OSA Technologies Inc. - C:\Acer\eManager\anbmServ.exe
        O23 - Service: Planificateur Avira AntiVir Personal - Free Antivirus (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
        O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
        O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
        O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
        O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
        0
        1. Bonjour!
          et voila le rapport combofix

          ComboFix 09-02-03.01 - Laura 2009-02-09 15:24:28.2 - [color=red][b]FAT32[/b][/color]x86
          Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.445.186 [GMT 1:00]
          Lancé depuis: c:\documents and settings\Laura\Bureau\C-Fix.exe
          AV: Avira AntiVir PersonalEdition Classic *On-access scanning disabled* (Updated)

          AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
          .

          (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
          .
          .
          ---- Exécution préalable -------
          .
          c:\documents and settings\Laura\Application Data\MANTEC~1
          c:\documents and settings\Laura\Application Data\RACLE~1
          c:\documents and settings\Laura\Application Data\SSTEM~1
          c:\documents and settings\Laura\Application Data\YSTEM~1
          c:\documents and settings\Laura\Application Data\YSTEM~1\?ystem\
          c:\documents and settings\Laura\Application Data\YSTEM~1\w?wexec.exe
          c:\documents and settings\Laura\Menu Démarrer\Programmes\Outerinfo
          c:\documents and settings\Laura\Menu Démarrer\Programmes\Outerinfo\Terms.lnk
          c:\documents and settings\Laura\Menu Démarrer\Programmes\Outerinfo\Uninstall.lnk
          c:\documents and settings\Laura\Menu Démarrer\Programmes\ucmore - the search accelerator
          c:\documents and settings\Laura\Menu Démarrer\Programmes\ucmore - the search accelerator\How To Uninstall.lnk
          c:\documents and settings\Laura\Menu Démarrer\Programmes\ucmore - the search accelerator\UCmore - The Search Accelerator.lnk
          c:\documents and settings\Laura\Menu Démarrer\Programmes\ucmore - the search accelerator\UCmore Tour.lnk
          c:\documents and settings\Laura\Mes documents\CROSOF~1.NET
          c:\documents and settings\Laura\Mes documents\CROSOF~1.NET\??crosoft.NET\
          c:\documents and settings\Laura\Mes documents\STEM~1
          c:\program files\dobe~1
          c:\program files\outerinfo
          c:\program files\outerinfo\FF\chrome.manifest
          c:\program files\outerinfo\FF\components\FF.dll
          c:\program files\outerinfo\FF\components\OuterinfoAds.xpt
          c:\program files\outerinfo\FF\install.rdf
          c:\program files\outerinfo\outerinfo.ico
          c:\program files\outerinfo\Terms.rtf
          c:\program files\pppatc~1
          c:\windows\crosof~1
          c:\windows\fnts~1
          c:\windows\fnts~1\??chost.exe
          c:\windows\hosts
          c:\windows\icroso~1
          c:\windows\system\oeminfo.ini
          c:\windows\system32\asks~1
          c:\windows\system32\ppatch~1
          c:\windows\system32\sks~1
          c:\windows\system32\wnsapisv.exe

          .
          ((((((((((((((((((((((((((((( Fichiers créés du 2009-01-09 au 2009-02-09 ))))))))))))))))))))))))))))))))))))
          .

          2009-02-07 10:02 . 2009-02-07 10:02 <REP> d-------- C:\_OTMoveIt
          2009-02-05 10:11 . 2009-02-05 10:11 <REP> d-------- C:\rsit
          2009-02-04 10:39 . 2009-02-04 10:39 <REP> d-------- C:\hijackthis
          2009-02-02 20:45 . 2009-02-02 20:45 <REP> d-------- c:\windows\system32\CatRoot_bak
          2009-02-02 20:43 . 2008-06-14 18:59 272,768 --------- c:\windows\system32\drivers\bthport.sys
          2009-02-02 20:43 . 2008-06-14 18:59 272,768 --------- c:\windows\system32\dllcache\bthport.sys
          2009-02-02 20:26 . 2009-02-02 20:26 410,984 --a------ c:\windows\system32\deploytk.dll
          2009-02-02 17:51 . 2009-02-02 17:51 <REP> d-------- c:\program files\Avira
          2009-02-02 17:51 . 2009-02-02 17:51 <REP> d-------- c:\documents and settings\All Users\Application Data\Avira
          2009-02-02 17:29 . 2009-02-02 17:29 <REP> d-------- c:\program files\OINAnalytics
          2009-02-02 17:04 . 2009-02-02 17:04 <REP> d-------- c:\documents and settings\Coco\Application Data\Apple Computer

          .
          (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
          .
          2008-12-13 06:37 3,593,216 ----a-w c:\windows\system32\dllcache\mshtml.dll
          2008-12-11 11:57 333,184 ----a-w c:\windows\system32\drivers\srv.sys
          2008-12-11 11:57 333,184 ----a-w c:\windows\system32\dllcache\srv.sys
          2006-08-31 19:59 93,663 --sha-w c:\program files\Fichiers communs\Y1220OU.exe
          2006-08-28 21:46 278,528 ----a-w c:\program files\Fichiers communs\FDEUnInstaller.exe
          2008-04-25 09:23 67,696 ----a-w c:\program files\mozilla firefox\components\jar50.dll
          2008-04-25 09:23 54,376 ----a-w c:\program files\mozilla firefox\components\jsd3250.dll
          2008-04-25 09:23 34,952 ----a-w c:\program files\mozilla firefox\components\myspell.dll
          2008-04-25 09:23 46,720 ----a-w c:\program files\mozilla firefox\components\spellchk.dll
          2008-04-25 09:23 172,144 ----a-w c:\program files\mozilla firefox\components\xpinstal.dll
          .

          ((((((((((((((((((((((((((((( snapshot@2009-02-04_12.27.33,59 )))))))))))))))))))))))))))))))))))))))))
          .
          + 2008-03-01 13:58:06 124,928 ------w c:\windows\ie7updates\KB958215-IE7\advpack.dll
          + 2008-03-01 13:58:06 347,136 ------w c:\windows\ie7updates\KB958215-IE7\dxtmsft.dll
          + 2008-03-01 13:58:06 214,528 ------w c:\windows\ie7updates\KB958215-IE7\dxtrans.dll
          + 2008-03-01 13:58:06 133,120 ------w c:\windows\ie7updates\KB958215-IE7\extmgr.dll
          + 2008-03-01 13:58:06 63,488 ------w c:\windows\ie7updates\KB958215-IE7\icardie.dll
          + 2008-02-29 09:56:42 70,656 ------w c:\windows\ie7updates\KB958215-IE7\ie4uinit.exe
          + 2008-03-01 13:58:06 153,088 ------w c:\windows\ie7updates\KB958215-IE7\ieakeng.dll
          + 2008-03-01 13:58:06 230,400 ------w c:\windows\ie7updates\KB958215-IE7\ieaksie.dll
          + 2008-02-15 06:44:26 161,792 ------w c:\windows\ie7updates\KB958215-IE7\ieakui.dll
          + 2008-03-01 13:58:08 383,488 ------w c:\windows\ie7updates\KB958215-IE7\ieapfltr.dll
          + 2008-03-01 13:58:08 384,512 ------w c:\windows\ie7updates\KB958215-IE7\iedkcs32.dll
          + 2008-03-01 13:58:08 6,066,176 ------w c:\windows\ie7updates\KB958215-IE7\ieframe.dll
          + 2008-03-01 13:58:08 44,544 ------w c:\windows\ie7updates\KB958215-IE7\iernonce.dll
          + 2008-03-01 13:58:08 267,776 ------w c:\windows\ie7updates\KB958215-IE7\iertutil.dll
          + 2008-02-22 11:00:52 13,824 ------w c:\windows\ie7updates\KB958215-IE7\ieudinit.exe
          + 2008-02-29 09:57:06 625,664 ------w c:\windows\ie7updates\KB958215-IE7\iexplore.exe
          + 2008-03-01 13:58:08 27,648 ------w c:\windows\ie7updates\KB958215-IE7\jsproxy.dll
          + 2008-03-01 13:58:08 459,264 ------w c:\windows\ie7updates\KB958215-IE7\msfeeds.dll
          + 2008-03-01 13:58:08 52,224 ------w c:\windows\ie7updates\KB958215-IE7\msfeedsbs.dll
          + 2008-03-01 13:58:10 478,208 ------w c:\windows\ie7updates\KB958215-IE7\mshtmled.dll
          + 2008-03-01 13:58:10 193,024 ------w c:\windows\ie7updates\KB958215-IE7\msrating.dll
          + 2008-03-01 13:58:10 671,232 ------w c:\windows\ie7updates\KB958215-IE7\mstime.dll
          + 2008-03-01 13:58:10 102,912 ------w c:\windows\ie7updates\KB958215-IE7\occache.dll
          + 2008-03-01 13:58:10 44,544 ------w c:\windows\ie7updates\KB958215-IE7\pngfilt.dll
          + 2007-03-06 01:34:38 216,800 ------w c:\windows\ie7updates\KB958215-IE7\spuninst\spuninst.exe
          + 2007-03-06 01:35:48 394,976 ------w c:\windows\ie7updates\KB958215-IE7\spuninst\updspapi.dll
          + 2008-03-01 13:58:10 105,984 ------w c:\windows\ie7updates\KB958215-IE7\url.dll
          + 2008-03-01 13:58:10 1,159,680 ------w c:\windows\ie7updates\KB958215-IE7\urlmon.dll
          + 2008-03-01 13:58:12 233,472 ------w c:\windows\ie7updates\KB958215-IE7\webcheck.dll
          + 2008-03-01 13:58:12 826,368 ------w c:\windows\ie7updates\KB958215-IE7\wininet.dll
          + 2008-03-01 17:28:10 3,591,680 ------w c:\windows\ie7updates\KB960714-IE7\mshtml.dll
          + 2007-03-06 01:34:38 216,800 ------w c:\windows\ie7updates\KB960714-IE7\spuninst\spuninst.exe
          + 2007-03-06 01:35:48 394,976 ------w c:\windows\ie7updates\KB960714-IE7\spuninst\updspapi.dll
          + 2009-02-04 12:16:38 32,768 ----a-r c:\windows\Installer\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}\icon.exe
          - 2008-03-01 13:58:06 124,928 ----a-w c:\windows\system32\advpack.dll
          + 2008-10-16 20:18:32 124,928 ----a-w c:\windows\system32\advpack.dll
          - 2008-03-01 13:58:06 124,928 ----a-w c:\windows\system32\dllcache\advpack.dll
          + 2008-10-16 20:18:32 124,928 ----a-w c:\windows\system32\dllcache\advpack.dll
          - 2004-08-19 18:56:22 138,496 ----a-w c:\windows\system32\dllcache\afd.sys
          + 2008-08-14 09:51:44 138,368 ------w c:\windows\system32\dllcache\afd.sys
          - 2008-02-20 06:35:06 148,992 ----a-w c:\windows\system32\dllcache\dnsapi.dll
          + 2008-06-20 17:41:06 148,992 ----a-w c:\windows\system32\dllcache\dnsapi.dll
          - 2008-03-01 13:58:06 347,136 ----a-w c:\windows\system32\dllcache\dxtmsft.dll
          + 2008-10-16 20:18:32 347,136 ----a-w c:\windows\system32\dllcache\dxtmsft.dll
          - 2008-03-01 13:58:06 214,528 ----a-w c:\windows\system32\dllcache\dxtrans.dll
          + 2008-10-16 20:18:32 214,528 ----a-w c:\windows\system32\dllcache\dxtrans.dll
          - 2005-07-26 05:39:58 243,200 ----a-w c:\windows\system32\dllcache\es.dll
          + 2008-07-07 20:31:48 253,952 ----a-w c:\windows\system32\dllcache\es.dll
          - 2008-03-01 13:58:06 133,120 ----a-w c:\windows\system32\dllcache\extmgr.dll
          + 2008-10-16 20:18:32 133,120 ----a-w c:\windows\system32\dllcache\extmgr.dll
          - 2008-02-20 07:51:00 282,624 ----a-w c:\windows\system32\dllcache\gdi32.dll
          + 2008-10-23 13:00:16 283,648 ----a-w c:\windows\system32\dllcache\gdi32.dll
          - 2008-03-01 13:58:06 63,488 ------w c:\windows\system32\dllcache\icardie.dll
          + 2008-10-16 20:18:32 63,488 ------w c:\windows\system32\dllcache\icardie.dll
          - 2008-02-29 09:56:42 70,656 ----a-w c:\windows\system32\dllcache\ie4uinit.exe
          + 2008-10-16 13:12:20 70,656 ----a-w c:\windows\system32\dllcache\ie4uinit.exe
          - 2008-03-01 13:58:06 153,088 ----a-w c:\windows\system32\dllcache\ieakeng.dll
          + 2008-10-16 20:18:32 153,088 ----a-w c:\windows\system32\dllcache\ieakeng.dll
          - 2008-03-01 13:58:06 230,400 ----a-w c:\windows\system32\dllcache\ieaksie.dll
          + 2008-10-16 20:18:32 230,400 ----a-w c:\windows\system32\dllcache\ieaksie.dll
          - 2008-02-15 06:44:26 161,792 ----a-w c:\windows\system32\dllcache\ieakui.dll
          + 2008-10-15 07:04:54 161,792 ----a-w c:\windows\system32\dllcache\ieakui.dll
          - 2008-03-01 13:58:08 383,488 ------w c:\windows\system32\dllcache\ieapfltr.dll
          + 2008-10-16 20:18:32 383,488 ------w c:\windows\system32\dllcache\ieapfltr.dll
          - 2008-03-01 13:58:08 384,512 ----a-w c:\windows\system32\dllcache\iedkcs32.dll
          + 2008-10-16 20:18:32 384,512 ----a-w c:\windows\system32\dllcache\iedkcs32.dll
          - 2008-03-01 13:58:08 6,066,176 ------w c:\windows\system32\dllcache\ieframe.dll
          + 2008-10-16 20:18:36 6,066,176 ------w c:\windows\system32\dllcache\ieframe.dll
          - 2008-03-01 13:58:08 44,544 ----a-w c:\windows\system32\dllcache\iernonce.dll
          + 2008-10-16 20:18:36 44,544 ----a-w c:\windows\system32\dllcache\iernonce.dll
          - 2008-03-01 13:58:08 267,776 ------w c:\windows\system32\dllcache\iertutil.dll
          + 2008-10-16 20:18:36 267,776 ------w c:\windows\system32\dllcache\iertutil.dll
          - 2008-02-22 11:00:52 13,824 ------w c:\windows\system32\dllcache\ieudinit.exe
          + 2008-10-16 13:11:10 13,824 ------w c:\windows\system32\dllcache\ieudinit.exe
          - 2008-02-29 09:57:06 625,664 ----a-w c:\windows\system32\dllcache\iexplore.exe
          + 2008-10-15 07:06:26 633,632 ----a-w c:\windows\system32\dllcache\iexplore.exe
          - 2007-08-21 07:17:24 683,520 ----a-w c:\windows\system32\dllcache\inetcomm.dll
          + 2008-04-11 18:51:06 683,520 ----a-w c:\windows\system32\dllcache\inetcomm.dll
          - 2008-03-01 13:58:08 27,648 ----a-w c:\windows\system32\dllcache\jsproxy.dll
          + 2008-10-16 20:18:36 27,648 ----a-w c:\windows\system32\dllcache\jsproxy.dll
          - 2006-10-18 19:03:58 100,864 ----a-w c:\windows\system32\dllcache\logagent.exe
          + 2008-06-18 00:09:22 100,864 ----a-w c:\windows\system32\dllcache\logagent.exe
          - 2006-05-05 10:41:46 453,120 ------w c:\windows\system32\dllcache\mrxsmb.sys
          + 2008-10-24 11:10:42 453,632 ------w c:\windows\system32\dllcache\mrxsmb.sys
          - 2004-08-05 04:00:00 331,776 ----a-w c:\windows\system32\dllcache\msadce.dll
          + 2008-05-01 14:31:48 331,776 ----a-w c:\windows\system32\dllcache\msadce.dll
          - 2005-06-29 02:49:42 74,240 ----a-w c:\windows\system32\dllcache\mscms.dll
          + 2008-06-24 16:23:56 74,240 ----a-w c:\windows\system32\dllcache\mscms.dll
          - 2008-03-01 13:58:08 459,264 ------w c:\windows\system32\dllcache\msfeeds.dll
          + 2008-10-16 20:18:38 459,264 ------w c:\windows\system32\dllcache\msfeeds.dll
          - 2008-03-01 13:58:08 52,224 ------w c:\windows\system32\dllcache\msfeedsbs.dll
          + 2008-10-16 20:18:38 52,224 ------w c:\windows\system32\dllcache\msfeedsbs.dll
          - 2008-03-01 13:58:10 478,208 ----a-w c:\windows\system32\dllcache\mshtmled.dll
          + 2008-10-16 20:18:40 477,696 ----a-w c:\windows\system32\dllcache\mshtmled.dll
          - 2008-03-01 13:58:10 193,024 ----a-w c:\windows\system32\dllcache\msrating.dll
          + 2008-10-16 20:18:40 193,024 ----a-w c:\windows\system32\dllcache\msrating.dll
          - 2008-03-01 13:58:10 671,232 ----a-w c:\windows\system32\dllcache\mstime.dll
          + 2008-10-16 20:18:42 671,232 ----a-w c:\windows\system32\dllcache\mstime.dll
          - 2004-08-19 19:02:00 72,704 ----a-w c:\windows\system32\dllcache\msw3prt.dll
          + 2008-08-28 08:03:22 74,752 ----a-w c:\windows\system32\dllcache\msw3prt.dll
          - 2004-08-19 19:02:02 247,808 ----a-w c:\windows\system32\dllcache\mswsock.dll
          + 2008-06-20 17:41:06 247,808 ----a-w c:\windows\system32\dllcache\mswsock.dll
          - 2007-06-26 07:09:14 1,104,896 ----a-w c:\windows\system32\dllcache\msxml3.dll
          + 2008-09-04 16:45:12 1,106,944 ----a-w c:\windows\system32\dllcache\msxml3.dll
          - 2006-08-17 13:29:50 332,288 ----a-w c:\windows\system32\dllcache\netapi32.dll
          + 2008-10-15 16:59:28 332,800 ----a-w c:\windows\system32\dllcache\netapi32.dll
          - 2007-02-28 17:02:22 2,138,112 ------w c:\windows\system32\dllcache\ntkrnlmp.exe
          + 2008-08-14 13:44:36 2,138,112 ------w c:\windows\system32\dllcache\ntkrnlmp.exe
          - 2007-02-28 17:02:36 2,059,648 ------w c:\windows\system32\dllcache\ntkrnlpa.exe
          + 2008-08-14 13:44:40 2,059,776 ------w c:\windows\system32\dllcache\ntkrnlpa.exe
          - 2007-02-28 17:02:22 2,017,792 ------w c:\windows\system32\dllcache\ntkrpamp.exe
          + 2008-08-14 13:44:34 2,017,792 ------w c:\windows\system32\dllcache\ntkrpamp.exe
          - 2007-02-28 17:02:36 2,182,400 ------w c:\windows\system32\dllcache\ntoskrnl.exe
          + 2008-08-14 13:44:38 2,182,400 ------w c:\windows\system32\dllcache\ntoskrnl.exe
          - 2008-03-01 13:58:10 102,912 ----a-w c:\windows\system32\dllcache\occache.dll
          + 2008-10-16 20:18:42 102,912 ----a-w c:\windows\system32\dllcache\occache.dll
          - 2008-03-01 13:58:10 44,544 ----a-w c:\windows\system32\dllcache\pngfilt.dll
          + 2008-10-16 20:18:42 44,544 ----a-w c:\windows\system32\dllcache\pngfilt.dll
          - 2007-10-29 23:43:32 1,293,824 ----a-w c:\windows\system32\dllcache\quartz.dll
          + 2008-05-07 05:15:36 1,293,824 ----a-w c:\windows\system32\dllcache\quartz.dll
          - 2006-07-13 09:48:58 202,240 ----a-w c:\windows\system32\dllcache\rmcast.sys
          + 2008-05-08 12:28:50 202,752 ----a-w c:\windows\system32\dllcache\rmcast.sys
          - 2006-08-24 12:19:40 246,814 ----a-w c:\windows\system32\dllcache\strmdll.dll
          + 2008-10-03 10:17:02 247,326 ----a-w c:\windows\system32\dllcache\strmdll.dll
          - 2007-10-30 18:20:56 360,064 ----a-w c:\windows\system32\dllcache\tcpip.sys
          + 2008-06-20 10:45:14 360,320 ----a-w c:\windows\system32\dllcache\tcpip.sys
          - 2006-08-16 10:37:30 225,664 ----a-w c:\windows\system32\dllcache\tcpip6.sys
          + 2008-06-20 09:52:06 225,920 ----a-w c:\windows\system32\dllcache\tcpip6.sys
          - 2008-03-01 13:58:10 105,984 ----a-w c:\windows\system32\dllcache\url.dll
          + 2008-10-16 20:18:42 105,984 ----a-w c:\windows\system32\dllcache\url.dll
          - 2008-03-01 13:58:10 1,159,680 ----a-w c:\windows\system32\dllcache\urlmon.dll
          + 2008-10-16 20:18:42 1,160,192 ----a-w c:\windows\system32\dllcache\urlmon.dll
          - 2008-03-01 13:58:12 233,472 ----a-w c:\windows\system32\dllcache\webcheck.dll
          + 2008-10-16 20:18:42 233,472 ----a-w c:\windows\system32\dllcache\webcheck.dll
          - 2008-03-20 09:09:22 1,845,376 ----a-w c:\windows\system32\dllcache\win32k.sys
          + 2008-09-15 15:39:16 1,846,144 ----a-w c:\windows\system32\dllcache\win32k.sys
          - 2004-08-19 19:10:34 102,400 ----a-w c:\windows\system32\dllcache\win32spl.dll
          + 2008-08-28 08:03:22 104,960 ----a-w c:\windows\system32\dllcache\win32spl.dll
          - 2008-03-01 13:58:12 826,368 ----a-w c:\windows\system32\dllcache\wininet.dll
          + 2008-10-16 20:18:44 826,368 ----a-w c:\windows\system32\dllcache\wininet.dll
          - 2006-10-18 20:47:20 937,984 ----a-w c:\windows\system32\dllcache\WMNetMgr.dll
          + 2008-06-18 04:03:08 938,496 ----a-w c:\windows\system32\dllcache\WMNetmgr.dll
          - 2006-10-18 20:47:22 2,450,944 ----a-w c:\windows\system32\dllcache\wmvcore.dll
          + 2008-06-18 04:03:14 2,458,112 ----a-w c:\windows\system32\dllcache\WMVCore.dll
          - 2008-02-20 06:35:06 148,992 ----a-w c:\windows\system32\dnsapi.dll
          + 2008-06-20 17:41:06 148,992 ----a-w c:\windows\system32\dnsapi.dll
          - 2004-08-19 18:56:22 138,496 ----a-w c:\windows\system32\drivers\afd.sys
          + 2008-08-14 09:51:44 138,368 ----a-w c:\windows\system32\drivers\afd.sys
          - 2006-05-05 10:41:46 453,120 ----a-w c:\windows\system32\drivers\mrxsmb.sys
          + 2008-10-24 11:10:42 453,632 ----a-w c:\windows\system32\drivers\mrxsmb.sys
          - 2006-07-13 09:48:58 202,240 ----a-w c:\windows\system32\drivers\RMCast.sys
          + 2008-05-08 12:28:50 202,752 ----a-w c:\windows\system32\drivers\RMCast.sys
          - 2007-10-30 18:20:56 360,064 ----a-w c:\windows\system32\drivers\tcpip.sys
          + 2008-06-20 10:45:14 360,320 ----a-w c:\windows\system32\drivers\tcpip.sys
          - 2006-08-16 10:37:30 225,664 ----a-w c:\windows\system32\drivers\tcpip6.sys
          + 2008-06-20 09:52:06 225,920 ----a-w c:\windows\system32\drivers\tcpip6.sys
          - 2008-03-01 13:58:06 347,136 ----a-w c:\windows\system32\dxtmsft.dll
          + 2008-10-16 20:18:32 347,136 ----a-w c:\windows\system32\dxtmsft.dll
          - 2008-03-01 13:58:06 214,528 ----a-w c:\windows\system32\dxtrans.dll
          + 2008-10-16 20:18:32 214,528 ----a-w c:\windows\system32\dxtrans.dll
          - 2005-07-26 05:39:58 243,200 ----a-w c:\windows\system32\es.dll
          + 2008-07-07 20:31:48 253,952 ----a-w c:\windows\system32\es.dll
          - 2008-03-01 13:58:06 133,120 ----a-w c:\windows\system32\extmgr.dll
          + 2008-10-16 20:18:32 133,120 ----a-w c:\windows\system32\extmgr.dll
          - 2009-02-02 15:53:22 258,248 ----a-w c:\windows\system32\FNTCACHE.DAT
          + 2009-02-05 09:03:06 258,248 ----a-w c:\windows\system32\FNTCACHE.DAT
          - 2008-02-20 07:51:00 282,624 ----a-w c:\windows\system32\gdi32.dll
          + 2008-10-23 13:00:16 283,648 ----a-w c:\windows\system32\gdi32.dll
          - 2008-03-01 13:58:06 63,488 ----a-w c:\windows\system32\icardie.dll
          + 2008-10-16 20:18:32 63,488 ----a-w c:\windows\system32\icardie.dll
          - 2008-02-29 09:56:42 70,656 ----a-w c:\windows\system32\ie4uinit.exe
          + 2008-10-16 13:12:20 70,656 ----a-w c:\windows\system32\ie4uinit.exe
          - 2008-03-01 13:58:06 153,088 ----a-w c:\windows\system32\ieakeng.dll
          + 2008-10-16 20:18:32 153,088 ----a-w c:\windows\system32\ieakeng.dll
          - 2008-03-01 13:58:06 230,400 ----a-w c:\windows\system32\ieaksie.dll
          + 2008-10-16 20:18:32 230,400 ----a-w c:\windows\system32\ieaksie.dll
          - 2008-02-15 06:44:26 161,792 ----a-w c:\windows\system32\ieakui.dll
          + 2008-10-15 07:04:54 161,792 ----a-w c:\windows\system32\ieakui.dll
          - 2008-03-01 13:58:08 383,488 ----a-w c:\windows\system32\ieapfltr.dll
          + 2008-10-16 20:18:32 383,488 ----a-w c:\windows\system32\ieapfltr.dll
          - 2008-03-01 13:58:08 384,512 ----a-w c:\windows\system32\iedkcs32.dll
          + 2008-10-16 20:18:32 384,512 ----a-w c:\windows\system32\iedkcs32.dll
          - 2008-03-01 13:58:08 6,066,176 ----a-w c:\windows\system32\ieframe.dll
          + 2008-10-16 20:18:36 6,066,176 ----a-w c:\windows\system32\ieframe.dll
          - 2008-03-01 13:58:08 44,544 ----a-w c:\windows\system32\iernonce.dll
          + 2008-10-16 20:18:36 44,544 ----a-w c:\windows\system32\iernonce.dll
          - 2008-03-01 13:58:08 267,776 ----a-w c:\windows\system32\iertutil.dll
          + 2008-10-16 20:18:36 267,776 ----a-w c:\windows\system32\iertutil.dll
          - 2008-02-22 11:00:52 13,824 ----a-w c:\windows\system32\ieudinit.exe
          + 2008-10-16 13:11:10 13,824 ----a-w c:\windows\system32\ieudinit.exe
          - 2007-08-21 07:17:24 683,520 ----a-w c:\windows\system32\inetcomm.dll
          + 2008-04-11 18:51:06 683,520 ----a-w c:\windows\system32\inetcomm.dll
          - 2008-03-01 13:58:08 27,648 ----a-w c:\windows\system32\jsproxy.dll
          + 2008-10-16 20:18:36 27,648 ----a-w c:\windows\system32\jsproxy.dll
          - 2006-10-18 19:03:58 100,864 ----a-w c:\windows\system32\logagent.exe
          + 2008-06-18 00:09:22 100,864 ----a-w c:\windows\system32\logagent.exe
          - 2008-05-09 13:35:06 16,863,864 ----a-w c:\windows\system32\MRT.exe
          + 2009-01-09 16:35:30 20,853,704 ----a-w c:\windows\system32\MRT.exe
          - 2005-06-29 02:49:42 74,240 ----a-w c:\windows\system32\mscms.dll
          + 2008-06-24 16:23:56 74,240 ----a-w c:\windows\system32\mscms.dll
          - 2008-03-01 13:58:08 459,264 ----a-w c:\windows\system32\msfeeds.dll
          + 2008-10-16 20:18:38 459,264 ----a-w c:\windows\system32\msfeeds.dll
          - 2008-03-01 13:58:08 52,224 ----a-w c:\windows\system32\msfeedsbs.dll
          + 2008-10-16 20:18:38 52,224 ----a-w c:\windows\system32\msfeedsbs.dll
          - 2008-03-01 17:28:10 3,591,680 ----a-w c:\windows\system32\mshtml.dll
          + 2008-12-13 06:37:56 3,593,216 ----a-w c:\windows\system32\mshtml.dll
          - 2008-03-01 13:58:10 478,208 ----a-w c:\windows\system32\mshtmled.dll
          + 2008-10-16 20:18:40 477,696 ----a-w c:\windows\system32\mshtmled.dll
          - 2008-03-01 13:58:10 193,024 ----a-w c:\windows\system32\msrating.dll
          + 2008-10-16 20:18:40 193,024 ----a-w c:\windows\system32\msrating.dll
          - 2008-03-01 13:58:10 671,232 ----a-w c:\windows\system32\mstime.dll
          + 2008-10-16 20:18:42 671,232 ----a-w c:\windows\system32\mstime.dll
          - 2004-08-19 19:02:00 72,704 ----a-w c:\windows\system32\msw3prt.dll
          + 2008-08-28 08:03:22 74,752 ----a-w c:\windows\system32\msw3prt.dll
          - 2004-08-19 19:02:02 247,808 ----a-w c:\windows\system32\mswsock.dll
          + 2008-06-20 17:41:06 247,808 ----a-w c:\windows\system32\mswsock.dll
          - 2007-06-26 07:09:14 1,104,896 ----a-w c:\windows\system32\msxml3.dll
          + 2008-09-04 16:45:12 1,106,944 ----a-w c:\windows\system32\msxml3.dll
          - 2007-05-08 14:03:04 1,275,392 ----a-w c:\windows\system32\msxml4.dll
          + 2008-09-30 15:43:34 1,286,152 ----a-w c:\windows\system32\msxml4.dll
          - 2007-05-15 14:43:10 1,320,800 ----a-w c:\windows\system32\msxml6.dll
          + 2008-08-29 19:06:44 1,350,664 ----a-w c:\windows\system32\msxml6.dll
          - 2006-08-17 13:29:50 332,288 ----a-w c:\windows\system32\netapi32.dll
          + 2008-10-15 16:59:28 332,800 ----a-w c:\windows\system32\netapi32.dll
          - 2007-02-28 17:02:36 2,059,648 ----a-w c:\windows\system32\ntkrnlpa.exe
          + 2008-08-14 13:44:40 2,059,776 ----a-w c:\windows\system32\ntkrnlpa.exe
          - 2007-02-28 17:02:36 2,182,400 ----a-w c:\windows\system32\ntoskrnl.exe
          + 2008-08-14 13:44:38 2,182,400 ----a-w c:\windows\system32\ntoskrnl.exe
          - 2008-03-01 13:58:10 102,912 ----a-w c:\windows\system32\occache.dll
          + 2008-10-16 20:18:42 102,912 ----a-w c:\windows\system32\occache.dll
          - 2008-03-01 13:58:10 44,544 ----a-w c:\windows\system32\pngfilt.dll
          + 2008-10-16 20:18:42 44,544 ----a-w c:\windows\system32\pngfilt.dll
          - 2007-10-29 23:43:32 1,293,824 ----a-w c:\windows\system32\quartz.dll
          + 2008-05-07 05:15:36 1,293,824 ----a-w c:\windows\system32\quartz.dll
          - 2006-10-16 15:10:58 14,640 ------w c:\windows\system32\spmsg.dll
          + 2007-11-30 11:19:06 18,296 ------w c:\windows\system32\spmsg.dll
          - 2006-08-24 12:19:40 246,814 ----a-w c:\windows\system32\strmdll.dll
          + 2008-10-03 10:17:02 247,326 ----a-w c:\windows\system32\strmdll.dll
          - 2007-11-13 12:31:12 60,416 ------w c:\windows\system32\tzchange.exe
          + 2008-10-22 09:47:08 62,976 ------w c:\windows\system32\tzchange.exe
          - 2008-03-01 13:58:10 105,984 ----a-w c:\windows\system32\url.dll
          + 2008-10-16 20:18:42 105,984 ----a-w c:\windows\system32\url.dll
          - 2008-03-01 13:58:10 1,159,680 ----a-w c:\windows\system32\urlmon.dll
          + 2008-10-16 20:18:42 1,160,192 ----a-w c:\windows\system32\urlmon.dll
          - 2008-03-01 13:58:12 233,472 ----a-w c:\windows\system32\webcheck.dll
          + 2008-10-16 20:18:42 233,472 ----a-w c:\windows\system32\webcheck.dll
          - 2008-03-20 09:09:22 1,845,376 ----a-w c:\windows\system32\win32k.sys
          + 2008-09-15 15:39:16 1,846,144 ----a-w c:\windows\system32\win32k.sys
          - 2004-08-19 19:10:34 102,400 ----a-w c:\windows\system32\win32spl.dll
          + 2008-08-28 08:03:22 104,960 ----a-w c:\windows\system32\win32spl.dll
          - 2008-03-01 13:58:12 826,368 ----a-w c:\windows\system32\wininet.dll
          + 2008-10-16 20:18:44 826,368 ----a-w c:\windows\system32\wininet.dll
          - 2006-10-18 20:47:20 937,984 ----a-w c:\windows\system32\WMNetMgr.dll
          + 2008-06-18 04:03:08 938,496 ----a-w c:\windows\system32\WMNetmgr.dll
          - 2006-10-18 20:47:20 295,936 ------w c:\windows\system32\wmpeffects.dll
          + 2008-06-24 17:12:58 295,936 ------w c:\windows\system32\wmpeffects.dll
          - 2006-10-18 20:47:22 2,450,944 ----a-w c:\windows\system32\wmvcore.dll
          + 2008-06-18 04:03:14 2,458,112 ----a-w c:\windows\system32\WMVCore.dll
          + 2009-02-09 14:13:34 16,384 ----a-w c:\windows\Temp\Perflib_Perfdata_750.dat
          + 2008-09-30 15:42:08 1,286,152 ----a-w c:\windows\WinSxS\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9870.0_x-ww_a32d74cf\msxml4.dll
          + 2008-09-30 15:45:12 91,656 ----a-w c:\windows\WinSxS\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.1.0_x-ww_2a41bceb\msxml4r.dll
          + 2008-04-15 17:57:00 1,724,416 ----a-w c:\windows\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.3352_x-ww_81af8e88\GdiPlus.dll
          .
          -- Instantané actualisé --
          .
          ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
          .
          .
          *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
          REGEDIT4

          [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1FD79A1C-09AB-0A5C-8C3D-50C0705881C8}]
          c:\windows\system32\fdid.dll [BU]

          [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{33E3FF63-388C-3804-A34D-68E33CEDFA91}]
          c:\windows\system32\lcey.dll [BU]

          [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{398DF3BE-6F0E-39DA-2975-3BB6094DA4C1}]
          c:\windows\system32\ejcydgb.dll [BU]

          [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{418E1354-DAB8-F539-C52A-89CD5519DE9B}]
          c:\windows\system32\opntlhi.dll [BU]

          [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{671FD78E-483B-45B9-4CF3-13D4CEC2A993}]
          c:\windows\system32\ptmauvma.dll [BU]

          [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7011EE4A-29AE-7D22-897F-7B129343B5CE}]
          c:\windows\system32\vrcm.dll [BU]

          [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
          "Czapd"="c:\windows\F?nts\??chost.exe" [?]
          "CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-19 15360]
          "Nphb"="c:\docume~1\Laura\MESDOC~1\CROSOF~1.NET\mshta.exe" [BU]
          "WOOKIT"="c:\progra~1\WANADOO\Shell.exe" [BU]
          "updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
          "LaunchApp"="Alaunch" [X]
          "SiS Windows KeyHook"="c:\windows\system32\keyhook.exe" [2005-03-04 32768]
          "SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2004-10-07 98394]
          "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2004-10-07 688218]
          "IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-05 208952]
          "MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-19 59392]
          "PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-19 455168]
          "PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-19 455168]
          "LManager"="c:\program files\Launch Manager\QtZgAcer.EXE" [2005-03-28 315392]
          "eRecoveryService"="c:\acer\Empowering Technology\eRecovery\Monitor.exe" [2005-11-16 393216]
          "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-03-28 413696]
          "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-02-02 136600]
          "avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
          "SiSPower"="SiSPower.dll" [2005-02-25 c:\windows\system32\SiSPower.dll]
          "SoundMan"="SOUNDMAN.EXE" [2005-02-23 c:\windows\SOUNDMAN.EXE]

          [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
          "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-19 15360]

          c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
          Utility Tray.lnk - c:\windows\system32\sistray.exe [2005-01-04 331776]
          Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-04-23 29696]

          [HKEY_LOCAL_MACHINE\software\microsoft\security center]
          "AntiVirusDisableNotify"=dword:00000001

          [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
          "EnableFirewall"= 0 (0x0)

          [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
          "%windir%\\system32\\sessmgr.exe"=
          "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
          "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=

          R2 osaio;osaio;c:\windows\system32\drivers\osaio.sys [2005-06-30 7296]
          R2 osanbm;osanbm;c:\windows\system32\drivers\osanbm.sys [2005-01-14 4010]
          R3 HSFHWSIS;HSFHWSIS;c:\windows\system32\drivers\HSFHWSIS.sys [2004-12-15 200576]
          S3 SIS163u;SiS163 usb Wireless LAN Adapter Driver;c:\windows\system32\drivers\SIS163u.SYS [2005-06-20 215040]

          --- Autres Services/Pilotes en mémoire ---

          *NewlyCreated* - INT15.SYS
          .
          Contenu du dossier 'Tâches planifiées'

          2009-02-04 c:\windows\Tasks\AppleSoftwareUpdate.job
          - c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 14:57]
          .
          .
          ------- Examen supplémentaire -------
          .
          uStart Page = hxxp://www.wanadoo.fr/
          uInternet Settings,ProxyOverride = *.local
          uSearchURL,(Default) = hxxp://g.msn.fr/0SEFRFR/SAOS01?FORM=TOOLBR
          IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
          FF - ProfilePath - c:\documents and settings\Laura\Application Data\Mozilla\Firefox\Profiles\tzcrje39.default\
          FF - prefs.js: browser.search.defaulturl - hxxp://fr.search.yahoo.com/search?ei=UTF-8&fr=ytff-sunm&p=
          FF - prefs.js: browser.search.selectedEngine - Yahoo
          FF - prefs.js: keyword.URL - hxxp://fr.search.yahoo.com/search?ei=UTF-8&fr=ytff-sunm&p=
          FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll
          .

          **************************************************************************

          catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
          Rootkit scan 2009-02-09 15:25:53
          Windows 5.1.2600 Service Pack 2 FAT NTAPI

          Recherche de processus cachés ...

          Recherche d'éléments en démarrage automatique cachés ...

          Recherche de fichiers cachés ...

          Scan terminé avec succès
          Fichiers cachés: 0

          **************************************************************************
          .
          Heure de fin: 2009-02-09 15:27:02
          ComboFix-quarantined-files.txt 2009-02-09 14:27:02

          Avant-CF: 8,675,622,912 octets libres
          Après-CF: 8,686,403,584 octets libres

          432 --- E O F --- 2009-02-09 14:18:11
          0
          1. Re,

            ▶ Télécharge et installe MalwareByte's Anti-Malware
            Malwarebyte

            ▶ Mets le à jour

            ▶ Double clique sur le raccourci de MalwareByte's Anti-Malware qui est sur le bureau.

            ▶ Sélectionne Exécuter un examen RAPIDE si ce n'est pas déjà fait

            ▶ clique sur Rechercher

            ▶ Une fois le scan terminé, une fenêtre s'ouvre, clique sur sur Ok

            ▶ Si MalwareByte's n'a rien détecté, clique sur Ok Un rapport va apparaître ferme-le.

            ▶ Si MalwareByte's a détecté des infections, clique sur Afficher les résultats ensuite sur Supprimer la sélection

            ▶ Enregistre le rapport sur ton Bureau comme cela il sera plus facile à retrouver, poste ensuite ce rapport.

            Note : Si MalwareByte's a besoin de redémarrer pour terminer la suppression, accepte en cliquant sur Ok

            Si un rapport ne passe pas faire une alerte à la conciergerie avec le /!\ jaune.

            Tutoriel pour MalwareByte's
            0
            1. rapport malawarebytes

              Malwarebytes' Anti-Malware 1.33
              Version de la base de données: 1654
              Windows 5.1.2600 Service Pack 2

              09/02/2009 16:14:20
              mbam-log-2009-02-09 (16-14-20).txt

              Type de recherche: Examen rapide
              Eléments examinés: 51003
              Temps écoulé: 4 minute(s), 57 second(s)

              Processus mémoire infecté(s): 0
              Module(s) mémoire infecté(s): 0
              Clé(s) du Registre infectée(s): 7
              Valeur(s) du Registre infectée(s): 2
              Elément(s) de données du Registre infecté(s): 0
              Dossier(s) infecté(s): 1
              Fichier(s) infecté(s): 2

              Processus mémoire infecté(s):
              (Aucun élément nuisible détecté)

              Module(s) mémoire infecté(s):
              (Aucun élément nuisible détecté)

              Clé(s) du Registre infectée(s):
              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{671fd78e-483b-45b9-4cf3-13d4cec2a993} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\CLSID\{671fd78e-483b-45b9-4cf3-13d4cec2a993} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\oincs.oinanalytics (Adware.BHO) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\oincs.oinanalytics.1 (Adware.BHO) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\AppID\{f7fa36a4-3177-4b57-b9c1-e9c5b2e0d3a9} (Adware.BHO) -> Quarantined and deleted successfully.
              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\oinanalytics (Trojan.Agent) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\AppID\OINAnalytics.DLL (Adware.BHO) -> Quarantined and deleted successfully.

              Valeur(s) du Registre infectée(s):
              HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\Extensions\{59a40ac9-e67d-4155-b31d-4b7330fcd2d6} (Adware.Agent) -> Quarantined and deleted successfully.
              HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\nphb (Trojan.Agent) -> Quarantined and deleted successfully.

              Elément(s) de données du Registre infecté(s):
              (Aucun élément nuisible détecté)

              Dossier(s) infecté(s):
              C:\Program Files\OINAnalytics (Trojan.Agent) -> Quarantined and deleted successfully.

              Fichier(s) infecté(s):
              C:\Program Files\OINAnalytics\OINAnalytics2.dll (Trojan.Agent) -> Quarantined and deleted successfully.
              C:\Program Files\OINAnalytics\Uninstall.exe (Trojan.Agent) -> Quarantined and deleted successfully.
              0
              1. Re,

                Supprime bien la quarantaine de malwarebyte.

                Redémarre ton PC normalement et refait un log avec RSIT.

                merci
                0
                1. log rsit merci encore!

                  Logfile of random's system information tool 1.05 (written by random/random)
                  Run by Laura at 2009-02-09 16:22:36
                  Microsoft Windows XP Édition familiale Service Pack 2
                  System drive C: has 8 GB (49%) free of 17 GB
                  Total RAM: 445 MB (32% free)

                  Logfile of Trend Micro HijackThis v2.0.2
                  Scan saved at 16:22:43, on 09/02/2009
                  Platform: Windows XP SP2 (WinNT 5.01.2600)
                  MSIE: Internet Explorer v7.00 (7.00.6000.16762)
                  Boot mode: Normal

                  Running processes:
                  C:\WINDOWS\System32\smss.exe
                  C:\WINDOWS\system32\winlogon.exe
                  C:\WINDOWS\system32\services.exe
                  C:\WINDOWS\system32\lsass.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                  C:\WINDOWS\system32\spoolsv.exe
                  C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                  C:\Acer\eManager\anbmServ.exe
                  C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                  C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                  C:\Program Files\Bonjour\mDNSResponder.exe
                  C:\Program Files\Java\jre6\bin\jqs.exe
                  C:\WINDOWS\system32\wbem\wmiapsrv.exe
                  C:\WINDOWS\Explorer.EXE
                  C:\WINDOWS\system32\keyhook.exe
                  C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
                  C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                  C:\Acer\Empowering Technology\eRecovery\Monitor.exe
                  C:\Program Files\Launch Manager\QtZgAcer.EXE
                  C:\WINDOWS\SOUNDMAN.EXE
                  C:\Program Files\Java\jre6\bin\jusched.exe
                  C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\WINDOWS\system32\ctfmon.exe
                  C:\WINDOWS\system32\wuauclt.exe
                  C:\WINDOWS\system32\sistray.exe
                  C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                  C:\WINDOWS\system32\wuauclt.exe
                  C:\Documents and Settings\Laura\Bureau\RSIT.exe
                  C:\hijackthis\Laura.exe

                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                  R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
                  R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                  O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                  O2 - BHO: (no name) - {1FD79A1C-09AB-0A5C-8C3D-50C0705881C8} - C:\WINDOWS\system32\fdid.dll (file missing)
                  O2 - BHO: (no name) - {33E3FF63-388C-3804-A34D-68E33CEDFA91} - C:\WINDOWS\system32\lcey.dll (file missing)
                  O2 - BHO: (no name) - {398DF3BE-6F0E-39DA-2975-3BB6094DA4C1} - C:\WINDOWS\system32\ejcydgb.dll (file missing)
                  O2 - BHO: (no name) - {418E1354-DAB8-F539-C52A-89CD5519DE9B} - C:\WINDOWS\system32\opntlhi.dll (file missing)
                  O2 - BHO: (no name) - {7011EE4A-29AE-7D22-897F-7B129343B5CE} - C:\WINDOWS\system32\vrcm.dll (file missing)
                  O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
                  O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                  O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
                  O4 - HKLM\..\Run: [LaunchApp] Alaunch
                  O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
                  O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\system32\keyhook.exe
                  O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
                  O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                  O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
                  O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
                  O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
                  O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
                  O4 - HKLM\..\Run: [LManager] C:\Program Files\Launch Manager\QtZgAcer.EXE
                  O4 - HKLM\..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\Monitor.exe
                  O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
                  O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                  O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                  O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                  O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                  O4 - HKCU\..\Run: [Czapd] C:\WINDOWS\F?nts\??chost.exe
                  O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\WANADOO\Shell.exe appLaunchClientZone.shl|DEFAULT=cnx|PARAM=
                  O4 - HKCU\..\Run: [updateMgr] c:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_1_0
                  O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                  O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                  O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe
                  O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                  O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                  O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                  O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                  O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                  O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
                  O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
                  O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                  O23 - Service: Notebook Manager Service (anbmService) - OSA Technologies Inc. - C:\Acer\eManager\anbmServ.exe
                  O23 - Service: Planificateur Avira AntiVir Personal - Free Antivirus (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                  O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                  O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                  O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                  O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
                  0
                  1. Re,

                    ▶ Relance hijack et clique sur "Do a system scan only"

                    ▶ Ensuite recherche ces lignes et coches les cases

                    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
                    O2 - BHO: (no name) - {1FD79A1C-09AB-0A5C-8C3D-50C0705881C8} - C:\WINDOWS\system32\fdid.dll (file missing)
                    O2 - BHO: (no name) - {33E3FF63-388C-3804-A34D-68E33CEDFA91} - C:\WINDOWS\system32\lcey.dll (file missing)
                    O2 - BHO: (no name) - {398DF3BE-6F0E-39DA-2975-3BB6094DA4C1} - C:\WINDOWS\system32\ejcydgb.dll (file missing)
                    O2 - BHO: (no name) - {418E1354-DAB8-F539-C52A-89CD5519DE9B} - C:\WINDOWS\system32\opntlhi.dll (file missing)
                    O2 - BHO: (no name) - {7011EE4A-29AE-7D22-897F-7B129343B5CE} - C:\WINDOWS\system32\vrcm.dll (file missing)
                    O4 - HKCU\..\Run: [Czapd] C:\WINDOWS\F?nts\??chost.exe

                    ▶ Ensuite clique sur "Fix checked"
                    xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
                    ▶ Télécharge RegCleaner

                    ▶ Une fois installé, double-clique sur son icône pour l'exécuter

                    ▶ Dans la barre de menu, clique sur Options puis sélectionne Language => Choose the language

                    ▶ recherche French.rlg et double-clique dessus pour appliquer la langue

                    ▶ Clique ensuite sur Outils dans la barre de menu

                    ▶ Sélectionne Nettoyage du registre => Nettoyeur de registre automatique

                    ▶ RegCleaner va alors lancer le nettoyage automatiquement

                    ▶ Coche ensuite les entrées invalides et clique sur Supprimer sélections => Terminer => Quitter

                    Tutoriel REG-CLEANER
                    0
                    1. Merci beaucoup V-X!!!

                      J'ai refait une analyse antivirus et plus de purity scan!!!!
                      Par contre j'ai un autre cheval de troie...trash.gen, je dois commencer une autre discussion?

                      mon rapport avira


                      Avira AntiVir Personal
                      Date de création du fichier de rapport : mercredi 11 février 2009 09:47

                      La recherche porte sur 1330286 souches de virus.

                      Détenteur de la licence :Avira AntiVir PersonalEdition Classic
                      Numéro de série : 0000149996-ADJIE-0001
                      Plateforme : Windows XP
                      Version de Windows :(Service Pack 2) [5.1.2600]
                      Mode Boot : Démarré normalement
                      Identifiant : SYSTEM
                      Nom de l'ordinateur :ACER-79F6FF2248

                      Informations de version :
                      BUILD.DAT : 8.2.0.52 16931 Bytes 02/12/2008 14:55:00
                      AVSCAN.EXE : 8.1.4.10 315649 Bytes 18/11/2008 08:21:02
                      AVSCAN.DLL : 8.1.4.1 49921 Bytes 21/07/2008 13:44:28
                      LUKE.DLL : 8.1.4.5 164097 Bytes 12/06/2008 12:44:18
                      LUKERES.DLL : 8.1.4.0 13057 Bytes 04/07/2008 07:30:28
                      ANTIVIR0.VDF : 7.1.0.0 15603712 Bytes 27/10/2008 11:30:38
                      ANTIVIR1.VDF : 7.1.1.113 2817536 Bytes 14/01/2009 17:02:00
                      ANTIVIR2.VDF : 7.1.1.240 1659904 Bytes 07/02/2009 14:29:00
                      ANTIVIR3.VDF : 7.1.2.6 96256 Bytes 11/02/2009 08:36:24
                      Version du moteur: 8.2.0.76
                      AEVDF.DLL : 8.1.1.0 106868 Bytes 02/02/2009 17:03:00
                      AESCRIPT.DLL : 8.1.1.43 344442 Bytes 07/02/2009 08:59:02
                      AESCN.DLL : 8.1.1.6 127348 Bytes 02/02/2009 17:02:56
                      AERDL.DLL : 8.1.1.3 438645 Bytes 04/11/2008 13:58:40
                      AEPACK.DLL : 8.1.3.8 397684 Bytes 07/02/2009 08:58:58
                      AEOFFICE.DLL : 8.1.0.33 196987 Bytes 02/02/2009 17:02:50
                      AEHEUR.DLL : 8.1.0.90 1573237 Bytes 07/02/2009 08:58:56
                      AEHELP.DLL : 8.1.2.0 119159 Bytes 02/02/2009 17:02:34
                      AEGEN.DLL : 8.1.1.14 332148 Bytes 07/02/2009 08:58:44
                      AEEMU.DLL : 8.1.0.9 393588 Bytes 14/10/2008 10:05:58
                      AECORE.DLL : 8.1.6.4 176501 Bytes 02/02/2009 17:02:30
                      AEBB.DLL : 8.1.0.3 53618 Bytes 14/10/2008 10:05:58
                      AVWINLL.DLL : 1.0.0.12 15105 Bytes 09/07/2008 08:40:04
                      AVPREF.DLL : 8.0.2.0 38657 Bytes 16/05/2008 09:28:00
                      AVREP.DLL : 8.0.0.2 98344 Bytes 31/07/2008 12:02:16
                      AVREG.DLL : 8.0.0.1 33537 Bytes 09/05/2008 11:26:38
                      AVARKT.DLL : 1.0.0.23 307457 Bytes 12/02/2008 08:29:20
                      AVEVTLOG.DLL : 8.0.0.16 119041 Bytes 12/06/2008 12:27:48
                      SQLITE3.DLL : 3.3.17.1 339968 Bytes 22/01/2008 17:28:04
                      SMTPLIB.DLL : 1.2.0.23 28929 Bytes 12/06/2008 12:49:38
                      NETNT.DLL : 8.0.0.1 7937 Bytes 25/01/2008 12:05:08
                      RCIMAGE.DLL : 8.0.0.51 2371841 Bytes 04/07/2008 07:23:18
                      RCTEXT.DLL : 8.0.52.1 86273 Bytes 17/07/2008 10:08:44

                      Configuration pour la recherche actuelle :
                      Nom de la tâche..................: Contrôle intégral du système
                      Fichier de configuration.........: c:\program files\avira\antivir personaledition classic\sysscan.avp
                      Documentation....................: bas
                      Action principale................: interactif
                      Action secondaire................: ignorer
                      Recherche sur les secteurs d'amorçage maître: marche
                      Recherche sur les secteurs d'amorçage: marche
                      Secteurs d'amorçage..............: C:, D:,
                      Recherche dans les programmes actifs: marche
                      Recherche en cours sur l'enregistrement: marche
                      Recherche de Rootkits............: arrêt
                      Fichier mode de recherche........: Sélection de fichiers intelligente
                      Recherche sur les archives.......: marche
                      Limiter la profondeur de récursivité: 20
                      Archive Smart Extensions.........: marche
                      Heuristique de macrovirus........: marche
                      Heuristique fichier..............: moyen

                      Début de la recherche : mercredi 11 février 2009 09:47

                      La recherche sur les processus démarrés commence :
                      Processus de recherche 'avscan.exe' - '1' module(s) sont contrôlés
                      Processus de recherche 'avscan.exe' - '1' module(s) sont contrôlés
                      Processus de recherche 'update.exe' - '1' module(s) sont contrôlés
                      Processus de recherche 'avcenter.exe' - '1' module(s) sont contrôlés
                      Processus de recherche 'WUAUCLT.EXE' - '1' module(s) sont contrôlés
                      Processus de recherche 'WUAUCLT.EXE' - '1' module(s) sont contrôlés
                      Processus de recherche 'SISTRAY.EXE' - '1' module(s) sont contrôlés
                      Processus de recherche 'avgnt.exe' - '1' module(s) sont contrôlés
                      Processus de recherche 'jusched.exe' - '1' module(s) sont contrôlés
                      Processus de recherche 'QTTask.exe' - '1' module(s) sont contrôlés
                      Processus de recherche 'SOUNDMAN.EXE' - '1' module(s) sont contrôlés
                      Processus de recherche 'QtZgAcer.EXE' - '1' module(s) sont contrôlés
                      Processus de recherche 'SynTPEnh.exe' - '1' module(s) sont contrôlés
                      Processus de recherche 'SVCHOST.EXE' - '1' module(s) sont contrôlés
                      Processus de recherche 'SynTPLpr.exe' - '1' module(s) sont contrôlés
                      Processus de recherche 'Keyhook.exe' - '1' module(s) sont contrôlés
                      Processus de recherche 'ctfmon.exe' - '1' module(s) sont contrôlés
                      Processus de recherche 'Monitor.exe' - '1' module(s) sont contrôlés
                      Processus de recherche 'WUAUCLT.EXE' - '1' module(s) sont contrôlés
                      Processus de recherche 'explorer.exe' - '1' module(s) sont contrôlés
                      Processus de recherche 'WMIAPSRV.EXE' - '1' module(s) sont contrôlés
                      Processus de recherche 'ALG.EXE' - '1' module(s) sont contrôlés
                      Processus de recherche 'JQS.EXE' - '1' module(s) sont contrôlés
                      Processus de recherche 'mDNSResponder.exe' - '1' module(s) sont contrôlés
                      Processus de recherche 'AppleMobileDeviceService.exe' - '1' module(s) sont contrôlés
                      Processus de recherche 'AVGUARD.EXE' - '1' module(s) sont contrôlés
                      Processus de recherche 'anbmServ.exe' - '1' module(s) sont contrôlés
                      Processus de recherche 'SCHED.EXE' - '1' module(s) sont contrôlés
                      Processus de recherche 'SPOOLSV.EXE' - '1' module(s) sont contrôlés
                      Processus de recherche 'SVCHOST.EXE' - '1' module(s) sont contrôlés
                      Processus de recherche 'SVCHOST.EXE' - '1' module(s) sont contrôlés
                      Processus de recherche 'SVCHOST.EXE' - '1' module(s) sont contrôlés
                      Processus de recherche 'SVCHOST.EXE' - '1' module(s) sont contrôlés
                      Processus de recherche 'SVCHOST.EXE' - '1' module(s) sont contrôlés
                      Processus de recherche 'LSASS.EXE' - '1' module(s) sont contrôlés
                      Processus de recherche 'SERVICES.EXE' - '1' module(s) sont contrôlés
                      Processus de recherche 'WINLOGON.EXE' - '1' module(s) sont contrôlés
                      Processus de recherche 'CSRSS.EXE' - '1' module(s) sont contrôlés
                      Processus de recherche 'SMSS.EXE' - '1' module(s) sont contrôlés
                      '39' processus ont été contrôlés avec '39' modules

                      La recherche sur les secteurs d'amorçage maître commence :
                      Secteur d'amorçage maître HD0
                      [INFO] Aucun virus trouvé !

                      La recherche sur les secteurs d'amorçage commence :
                      Secteur d'amorçage 'C:\'
                      [INFO] Aucun virus trouvé !
                      Secteur d'amorçage 'D:\'
                      [INFO] Aucun virus trouvé !

                      La recherche sur les renvois aux fichiers exécutables (registre) commence.
                      Le registre a été contrôlé ( '66' fichiers).

                      La recherche sur les fichiers sélectionnés commence :

                      Recherche débutant dans 'C:\' <ACER>
                      C:\hiberfil.sys
                      [AVERTISSEMENT] Impossible d'ouvrir le fichier !
                      C:\PAGEFILE.SYS
                      [AVERTISSEMENT] Impossible d'ouvrir le fichier !
                      C:\System Volume Information\_restore{3FFD409C-A779-4E68-83FD-8EA2CEAF0EFF}\RP51\A0030372.dll
                      [RESULTAT] Contient le cheval de Troie TR/Trash.Gen
                      [REMARQUE] Le fichier a été déplacé dans le répertoire de quarantaine sous le nom '49c29c69.qua' !
                      C:\System Volume Information\_restore{3FFD409C-A779-4E68-83FD-8EA2CEAF0EFF}\RP51\A0030373.exe
                      [RESULTAT] Contient le cheval de Troie TR/Trash.Gen
                      [REMARQUE] Le fichier a été déplacé dans le répertoire de quarantaine sous le nom '49c29c6e.qua' !
                      Recherche débutant dans 'D:\' <ACERDATA>

                      Fin de la recherche : mercredi 11 février 2009 10:41
                      Temps nécessaire: 54:38 Minute(s)

                      La recherche a été effectuée intégralement

                      4798 Les répertoires ont été contrôlés
                      246532 Des fichiers ont été contrôlés
                      2 Des virus ou programmes indésirables ont été trouvés
                      0 Des fichiers ont été classés comme suspects
                      0 Des fichiers ont été supprimés
                      0 Des virus ou programmes indésirables ont été réparés
                      2 Les fichiers ont été déplacés dans la quarantaine
                      0 Les fichiers ont été renommés
                      2 Impossible de contrôler des fichiers
                      246528 Fichiers non infectés
                      6471 Les archives ont été contrôlées
                      2 Avertissements
                      2 Consignes
                      0
                      1. J'ai un peu attendu pour verifier que mon cheval de troie ne revenait pas mais ca a l'air bon!!
                        merci a V-X pour son aide!
                        0
                        Précédent
                        • 1
                        • 2