Help !!! trojans, vers bagle 476 infections

Résolu
Bonjour,

Je lance un appel au secours aux experts de la lutte des infections PC, Je crois bien avoir de tout ! C'est la honte ! et la panique !
J'ai un PC XP
Grace à vous, j'ai réussi à -me mettre en mode sans echec sans passer par les touches habituelles qui ne fonctionnent pas,
-avoir de nouveau accès au net j'ai aussi pu me télécharger certains outils ( ELIBAGLA COMBO FIX) qui m'ont permis de parvenir à ouvrir des applications ( jusque là tout ce que j'ouvrait était signaler par le message : ... n'est pas une application WIN 32 VALIDE).

Pour vous situer le début de mes ennuis .... Mon antivirus avast pro a disparu, C CLEANER est devenu inutilisable, le net innaccessible, le mode sans echec impossible avec les touches habituelles, et l'ordi se coupait se rallumait en affichant tout en plus gros et en me proposant l'antivirus 360 °

Avec vos précieux conseils et astuces, j'ai réussi à télécharger a-squared Free, il scann depuis de nombreuses heures et sans même avoir fini il a repèré déjà 476 infections!!!! Et là je panique !
Help! SOS! au secours !
Je cherche une âme généreuse et patiente pour me guidée pour la suite des évènements MERCI
Configuration: Windows XP
LIVE BOX ORANGE

73 réponses

Résumé de la discussion

Le problème central est une infection multiple sur Windows XP avec perte d’antivirus, navigation réseau bloquée et difficulté à accéder au mode sans échec, suscitant panique et recherche d’assistance technique. Des solutions incluent l’usage d’outils de détection et de nettoyage tels que ToolsCleaner, HijackThis et JavaRa, puis l’analyse des rapports pour guider la désinfection et la remise en service. En parallèle, des conseils portent sur le nettoyage des fichiers temporaires et du registre à l’aide d’outils tels que CCleaner, et sur les éléments de démarrage pour prévenir les réinfections. D'autres interventions évoquent la suppression de barres d’outils et d’éléments persistant non valides identifiés dans les rapports, afin d’éviter des résidus avant une éventuelle réinstallation ou remise à niveau.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    Bonjour,

    desinstalle ELIBAGLA AVANT la manip il entre en conflit

    puis

    * Telecharge Findykill sur ton bureau https://www.androidworld.fr/

    * (c'est le numéro 18 en bas de la page)

    * Lance l installation avec les parametres par default

    * Double clic sur le raccourci FindyKill sur ton bureau

    * Au menu principal,choisi l option 1 (Recherche)

    * Post le rapport FindyKill.txt

    * Note : le rapport FindyKill.txt est sauvegardé a la racine du disque
    0
    1. j'ai viré elibagla, et voici le rapport findykill

      ############################## [ FindyKill V4.717 ]

      # User : Administrateur (Administrateurs) # PERSO-C7DA5A812
      # Update on 17/02/09 by Chiquitine29
      # Start at: 18:47:47 | 24/02/2009

      # Intel(R) Pentium(R) 4 CPU 2.00GHz
      # Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 3
      # Internet Explorer 7.0.5730.13
      # Windows Firewall Status : Enabled

      # A:\ # Lecteur de disquettes 3 ½ pouces
      # C:\ # Disque fixe local # NTFS
      # D:\ # Disque CD-ROM

      ############################## [ Processus actifs ]

      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\csrss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\a-squared Free\a2service.exe
      C:\WINDOWS\System32\FTRTSVC.exe
      C:\Program Files\Java\jre6\bin\jqs.exe
      C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
      C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\CDBurnerXP\NMSAccessU.exe
      C:\WINDOWS\system32\HPZipm12.exe
      C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
      C:\Program Files\Java\jre6\bin\jusched.exe
      C:\WINDOWS\system32\rundll32.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
      C:\WINDOWS\System32\alg.exe
      C:\WINDOWS\system32\wbem\wmiapsrv.exe
      C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
      C:\PROGRA~1\Wanadoo\GestionnaireInternet.exe
      C:\WINDOWS\System32\svchost.exe
      C:\PROGRA~1\Wanadoo\ComComp.exe
      C:\PROGRA~1\Wanadoo\Toaster.exe
      C:\PROGRA~1\Wanadoo\Inactivity.exe
      C:\PROGRA~1\Wanadoo\PollingModule.exe
      C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
      C:\PROGRA~1\Wanadoo\Watch.exe
      C:\PROGRA~1\Wanadoo\WOOBrowser\WOOBrowser.exe
      C:\WINDOWS\system32\wbem\wmiprvse.exe

      ################## [ Fichiers / Dossiers infectieux C:\ ]

      Found ! - C:\InfoSat.txt

      ################## [ C:\WINDOWS ]

      ################## [ C:\WINDOWS\system32 ]

      ################## [ C:\WINDOWS\system32\drivers ]

      ################## [ C:\.. Application Data ... ]

      Found ! - "C:\Documents and Settings\Administrateur\Application Data\m\shared"
      Found ! - "C:\Documents and Settings\Administrateur\Application Data\m"

      ################## [ Registre / Clés infectieuses ]

      Found ! - HKEY_USERS\S-1-5-21-1960408961-484763869-839522115-500\Software\Local AppWizard-Generated Applications\patch
      Found ! - HKEY_USERS\S-1-5-21-1960408961-484763869-839522115-500\Software\Local AppWizard-Generated Applications\winupgro
      Found ! - HKEY_USERS\S-1-5-21-1960408961-484763869-839522115-500\Software\FirtR
      Found ! - HKEY_USERS\S-1-5-21-1960408961-484763869-839522115-500\Software\MuleAppData
      Found ! - HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\patch
      Found ! - HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\winupgro
      Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\srosa
      Found ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA
      Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SROSA
      Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_SROSA
      Found ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sK9Ou0s
      Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sK9Ou0s
      Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sK9Ou0s
      Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sK9Ou0s
      Found ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SK9OU0S
      Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SK9OU0S
      Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_SK9OU0S
      Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_SK9OU0S
      Found ! - HKEY_CURRENT_USER\Software\FirtR

      ################## [ Recherche dans supports amovibles]

      # Presence des fichiers :

      ################## [ Registre / Mountpoint2 ]

      # -> Not found !

      ################## [ ! Fin du rapport # FindyKill V4.717 ! ]

      j'attends la suite !!!
      je compte sur toi, peut être que je ne peux pas accomplir rapidement ce que tu me conseilles , il faut aussi que je m'occupe de ma famille
      merci encore à plus !
      0
  2. Contributeur sécurité
    et stop le scan A squared pour l'instant
    0
    1. Contributeur sécurité
      * télecharge HijackThis sur ton bureau :
      http://www.commentcamarche.net/telecharger/telecharger 159 hijackthis

      * installe le , puis vas sur
      Programes files -- trend micro -- hijackthis.exe renomme le en HJT.exe

      * ouvre HJT.exe puis fait " do a system scan and save a log file "

      * le bloc notes s'ouvre copie - colle le rapport

      un tutorial:
      https://www.androidworld.fr/

      Bon courage
      0
      1. merci de t'interéssé à mon triste cas !
        voici le rapport

        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 19:14:49, on 24/02/2009
        Platform: Windows XP SP3 (WinNT 5.01.2600)
        MSIE: Internet Explorer v7.00 (7.00.6000.16762)
        Boot mode: Normal

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\Program Files\a-squared Free\a2service.exe
        C:\WINDOWS\System32\FTRTSVC.exe
        C:\Program Files\Java\jre6\bin\jqs.exe
        C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
        C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
        C:\WINDOWS\Explorer.EXE
        C:\Program Files\CDBurnerXP\NMSAccessU.exe
        C:\WINDOWS\system32\HPZipm12.exe
        C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
        C:\WINDOWS\system32\svchost.exe
        C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
        C:\Program Files\Java\jre6\bin\jusched.exe
        C:\WINDOWS\system32\rundll32.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
        C:\WINDOWS\system32\wbem\wmiapsrv.exe
        C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
        C:\PROGRA~1\Wanadoo\GestionnaireInternet.exe
        C:\WINDOWS\System32\svchost.exe
        C:\PROGRA~1\Wanadoo\ComComp.exe
        C:\PROGRA~1\Wanadoo\Toaster.exe
        C:\PROGRA~1\Wanadoo\Inactivity.exe
        C:\PROGRA~1\Wanadoo\PollingModule.exe
        C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
        C:\PROGRA~1\Wanadoo\Watch.exe
        C:\PROGRA~1\Wanadoo\WOOBrowser\WOOBrowser.exe
        C:\WINDOWS\system32\rundll32.exe
        C:\PROGRA~1\Wanadoo\WOOBRO~1\DownloadManager.exe
        C:\Program Files\Trend Micro\HijackThis\HJT.exe.exe

        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Orange
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
        R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
        R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
        O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
        O2 - BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
        O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
        O2 - BHO: (no name) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - (no file)
        O2 - BHO: (no name) - {4FC762BA-4251-401A-B6B2-BCCE3531B092} - (no file)
        O2 - BHO: (no name) - {62CED47C-1064-4961-9F90-6DBD660A6F24} - (no file)
        O2 - BHO: EoBho Class - {64F56FC1-1272-44CD-BA6E-39723696E350} - C:\PROGRA~1\EoRezo\EoAdv\EOREZO~1.DLL (file missing)
        O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
        O2 - BHO: (no name) - {70376bb7-dcd1-4cfc-a0e6-53ac5052870c} - C:\WINDOWS\system32\luyehije.dll (file missing)
        O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
        O2 - BHO: (no name) - {77AB5974-55A3-4737-9FD5-B93C64307F78} - C:\WINDOWS\system32\xfosjtlt.dll
        O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
        O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
        O2 - BHO: &Research - {D263FA6D-84CC-48A8-9AF6-C664362B7A5B} - C:\WINDOWS\system32\winconfig.dll
        O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
        O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
        O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
        O2 - BHO: SweetIM Toolbar Helper - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
        O2 - BHO: (no name) - {f592709f-ff4a-4862-b659-4afabda56312} - (no file)
        O2 - BHO: (no name) - {F85CBF8F-F668-4682-A8AB-5C05D300FD0B} - C:\WINDOWS\system32\iifgHwvw.dll
        O3 - Toolbar: SweetIM Toolbar for Internet Explorer - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
        O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
        O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
        O4 - HKLM\..\Run: [Mgemihanofowaceh] rundll32.exe "C:\WINDOWS\Qqexiwifapo.dll",e
        O4 - HKLM\..\Run: [vezokirosi] Rundll32.exe "C:\WINDOWS\system32\juyodufu.dll",s
        O4 - HKLM\..\Run: [CPM77491acb] Rundll32.exe "c:\windows\system32\fapalogo.dll",a
        O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
        O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
        O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
        O4 - HKCU\..\Run: [wmgoc] "c:\documents and settings\administrateur\local settings\application data\wmgoc.exe" wmgoc
        O4 - HKCU\..\Run: [3C3760EC4C6B8BD2EDA4178E3F736DAC] C:\Program Files\A360\av360.exe
        O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\CCleaner.exe" /AUTO
        O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
        O4 - HKUS\S-1-5-19\..\Run: [vezokirosi] Rundll32.exe "C:\WINDOWS\system32\juyodufu.dll",s (User 'SERVICE LOCAL')
        O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
        O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "c:\PROGRA~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
        O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "c:\PROGRA~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
        O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
        O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
        O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office12\EXCEL.EXE/3000
        O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
        O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
        O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
        O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
        O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\Office12\REFIEBAR.DLL
        O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
        O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
        O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - C:\Program Files\Yahoo!\Common\yinsthelper.dll
        O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www3.snapfish.fr/SnapfishActivia.cab
        O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} (Image Uploader Control) - http://www.extrafilm.fr/ImageUploader5.cab
        O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
        O16 - DPF: {7DA181BB-EF8D-4A7E-8C53-7BFC718EF71D} (Upload Class) - http://photoservice.photos.orange.fr/migrationorange/index.cfm
        O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://cid-0c4ed52d9ade83dc.spaces.live.com/PhotoUpload/MsnPUpld.cab
        O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - https://www.touslesdrivers.com/index.php?v_page=29
        O16 - DPF: {CAC677B6-4963-4305-9066-0BD135CD9233} (IPSUploader4 Control) - http://as.photoprintit.de/ips-opdata/layout/default01/activex/IPSUploader4.cab
        O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
        O16 - DPF: {EDFCB7CB-942C-4822-AF14-F0B687409848} (Image Uploader Control) - http://www.leaderphoto.com/uploaders/aurigma_4_7_16/ImageUploader4.cab
        O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
        O20 - AppInit_DLLs: C:\WINDOWS\system32\rejijejo.dll c:\windows\system32\fapalogo.dll
        O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\fapalogo.dll
        O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\fapalogo.dll
        O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
        O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
        O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
        O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
        O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
        O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
        O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\SrvLnch\SrvLnch.exe
        O23 - Service: NMIndexingService - Unknown owner - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe (file missing)
        O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
        O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
        O23 - Service: PC Tools Auxiliary Service (sdAuxService) - Unknown owner - C:\Program Files\Spyware Doctor\pctsAuxs.exe (file missing)
        O23 - Service: PC Tools Security Service (sdCoreService) - Unknown owner - C:\Program Files\Spyware Doctor\pctsSvc.exe (file missing)
        0
    2. Contributeur sécurité
      désolé plopus, j'avais pas vu ton message
      a toi de continuer
      A+++
      0
      1. voici les rapports que j'ai

        Version - a-squared Free 4.0
        Dernière mise à jour : 24/02/2009 13:56:48

        Paramètres des balayages :

        Éléments : Mémoire, Traces, Cookies, C:\
        Balaye dans les archives : Marche
        Analyse heuristique : Marche
        Balaye dans les ADS : Marche

        Début du balayage : 24/02/2009 14:13:19

        [700] C:\WINDOWS\system32\iifgHwvw.dll Objets détectés : Trojan.Win32.Monderd!IK
        [612] C:\WINDOWS\system32\iifgHwvw.dll Objets détectés : Trojan.Win32.Monderd!IK
        [612] C:\WINDOWS\Qqexiwifapo.dll Objets détectés : Trojan.Win32.Hiloti!IK
        [2428] C:\WINDOWS\Qqexiwifapo.dll Objets détectés : Trojan.Win32.Hiloti!IK
        [2580] C:\WINDOWS\Qqexiwifapo.dll Objets détectés : Trojan.Win32.Hiloti!IK
        [2996] C:\WINDOWS\Qqexiwifapo.dll Objets détectés : Trojan.Win32.Hiloti!IK
        [3336] C:\WINDOWS\Qqexiwifapo.dll Objets détectés : Trojan.Win32.Hiloti!IK
        [3500] C:\WINDOWS\Qqexiwifapo.dll Objets détectés : Trojan.Win32.Hiloti!IK
        [3552] C:\WINDOWS\Qqexiwifapo.dll Objets détectés : Trojan.Win32.Hiloti!IK
        [3692] C:\WINDOWS\Qqexiwifapo.dll Objets détectés : Trojan.Win32.Hiloti!IK
        [3976] C:\WINDOWS\Qqexiwifapo.dll Objets détectés : Trojan.Win32.Hiloti!IK
        [180] C:\WINDOWS\Qqexiwifapo.dll Objets détectés : Trojan.Win32.Hiloti!IK
        [1032] C:\WINDOWS\Qqexiwifapo.dll Objets détectés : Trojan.Win32.Hiloti!IK
        [1100] C:\WINDOWS\Qqexiwifapo.dll Objets détectés : Trojan.Win32.Hiloti!IK
        [2924] C:\WINDOWS\Qqexiwifapo.dll Objets détectés : Trojan.Win32.Hiloti!IK
        [892] C:\WINDOWS\Qqexiwifapo.dll Objets détectés : Trojan.Win32.Hiloti!IK
        [3096] C:\WINDOWS\Qqexiwifapo.dll Objets détectés : Trojan.Win32.Hiloti!IK
        [2284] C:\WINDOWS\Qqexiwifapo.dll Objets détectés : Trojan.Win32.Hiloti!IK
        [3688] C:\WINDOWS\Qqexiwifapo.dll Objets détectés : Trojan.Win32.Hiloti!IK
        c:\windows\system32\ifhelper.dll Objets détectés : Trace.File.SearchCentrix!A2
        Value: HKEY_CLASSES_ROOT\CLSID\{82AC53B4-164C-4B07-A016-437A8388B81A}\InprocServer32 --> ThreadingModel Objets détectés : Trace.Registry.Sweet IM!A2
        Value: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{82AC53B4-164C-4B07-A016-437A8388B81A}\InprocServer32 --> ThreadingModel Objets détectés : Trace.Registry.Sweet IM!A2
        Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\SweetIM.exe --> Path Objets détectés : Trace.Registry.Sweet IM!A2
        Value: HKEY_USERS\S-1-5-21-1960408961-484763869-839522115-500\Software\MessengerSkinner --> bnrid Objets détectés : Trace.Registry.MessengerSkinner!A2
        Value: HKEY_USERS\S-1-5-21-1960408961-484763869-839522115-500\Software\MessengerSkinner --> grpid Objets détectés : Trace.Registry.MessengerSkinner!A2
        Value: HKEY_USERS\S-1-5-21-1960408961-484763869-839522115-500\Software\MessengerSkinner --> installdt Objets détectés : Trace.Registry.MessengerSkinner!A2
        Value: HKEY_USERS\S-1-5-21-1960408961-484763869-839522115-500\Software\MessengerSkinner --> InstallOpt1 Objets détectés : Trace.Registry.MessengerSkinner!A2
        Value: HKEY_USERS\S-1-5-21-1960408961-484763869-839522115-500\Software\MessengerSkinner --> Language Objets détectés : Trace.Registry.MessengerSkinner!A2
        Value: HKEY_USERS\S-1-5-21-1960408961-484763869-839522115-500\Software\AntiMalwareGuard --> InstallDate Objets détectés : Trace.Registry. AntiMalwareGuard!A2
        Value: HKEY_CLASSES_ROOT\AppID\DownloadManager.EXE --> AppID Objets détectés : Trace.Registry.MediaPipe!A2
        Value: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\DownloadManager.EXE --> AppID Objets détectés : Trace.Registry.MediaPipe!A2
        C:\Documents and Settings\Administrateur\Bureau\SmitfraudFix\Reboot.exe Objets détectés : Riskware.RiskTool.Win32.Reboot.f!A2
        C:\Program Files\Fichiers communs\LightScribe\LightScribeControlPanel.exe -hidden Objets détectés : Trojan.Crypt!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP445\A0115881.sys Objets détectés : Win32.SuspectCrc!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP445\A0115882.sys Objets détectés : Trojan-Downloader.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP446\A0115899.sys Objets détectés : Trojan-Downloader.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP446\A0115900.sys Objets détectés : Win32.SuspectCrc!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP446\A0115915.sys Objets détectés : Win32.SuspectCrc!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP446\A0115917.sys Objets détectés : Trojan-Downloader.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP447\A0115921.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP447\A0115927.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP447\A0115936.sys Objets détectés : Trojan-Downloader.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP447\A0115938.sys Objets détectés : Win32.SuspectCrc!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP447\A0115958.sys Objets détectés : Win32.SuspectCrc!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP447\A0115960.sys Objets détectés : Trojan-Downloader.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP447\A0115963.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP447\A0115964.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP447\A0115965.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP448\A0115970.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP448\A0115973.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP448\A0115975.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP448\A0115976.exe Objets détectés : possible-threat.Connect2.SuspendedPage!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP448\A0115977.exe Objets détectés : possible-threat.Connect2.SuspendedPage!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP448\A0115978.exe Objets détectés : possible-threat.Connect2.SuspendedPage!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP448\A0115979.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP448\A0115995.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP448\A0115996.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP448\A0115997.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP448\A0116004.sys Objets détectés : Trojan-Downloader.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP448\A0116005.sys Objets détectés : Win32.SuspectCrc!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP448\A0116012.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP449\A0116035.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP449\A0116038.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP449\A0116040.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP449\A0116041.exe Objets détectés : possible-threat.Connect2.SuspendedPage!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP449\A0116042.exe Objets détectés : possible-threat.Connect2.SuspendedPage!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP449\A0116043.exe Objets détectés : possible-threat.Connect2.SuspendedPage!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP449\A0116044.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP449\A0116060.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP449\A0116061.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP449\A0116062.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP449\A0116070.sys Objets détectés : Trojan-Downloader.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP449\A0116072.sys Objets détectés : Win32.SuspectCrc!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP449\A0116076.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP449\A0116099.sys Objets détectés : Win32.SuspectCrc!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP449\A0116101.sys Objets détectés : Trojan-Downloader.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP449\A0116104.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP449\A0116105.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP449\A0116106.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP449\A0116172.sys Objets détectés : Win32.SuspectCrc!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP449\A0116173.sys Objets détectés : Trojan-Downloader.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP449\A0116176.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP449\A0116181.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP449\A0116182.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP449\A0116292.sys Objets détectés : Win32.SuspectCrc!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP449\A0116293.sys Objets détectés : Trojan-Downloader.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP449\A0116296.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP449\A0116297.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP449\A0116298.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP449\A0116311.sys Objets détectés : Win32.SuspectCrc!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP449\A0116312.sys Objets détectés : Trojan-Downloader.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP449\A0116315.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP449\A0116316.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP449\A0116431.sys Objets détectés : Win32.SuspectCrc!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP449\A0116432.sys Objets détectés : Trojan-Downloader.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP449\A0116436.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP449\A0116437.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP449\A0116438.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP449\A0116446.sys Objets détectés : Win32.SuspectCrc!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP449\A0116448.sys Objets détectés : Trojan-Downloader.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP449\A0116460.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP449\A0116478.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP449\A0116479.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP449\A0116497.sys Objets détectés : Win32.SuspectCrc!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP449\A0116498.sys Objets détectés : Trojan-Downloader.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP449\A0116501.dll Objets détectés : Trojan.Win32.Monderd!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP449\A0116512.sys Objets détectés : Win32.SuspectCrc!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP449\A0116513.sys Objets détectés : Trojan-Downloader.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP449\A0116538.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP449\A0116539.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP449\A0116551.sys Objets détectés : Win32.SuspectCrc!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP449\A0116552.sys Objets détectés : Trojan-Downloader.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP449\A0116558.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP449\A0116559.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP449\A0116563.dll Objets détectés : Trojan.Win32.Monderd!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP449\A0116574.sys Objets détectés : Win32.SuspectCrc!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP449\A0116575.sys Objets détectés : Trojan-Downloader.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP449\A0116580.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP449\A0116581.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP449\A0116698.sys Objets détectés : Win32.SuspectCrc!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP449\A0116699.sys Objets détectés : Trojan-Downloader.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP449\A0116704.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP449\A0116705.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP450\A0116721.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP450\A0116722.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP450\A0116723.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP450\A0116724.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP450\A0116740.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP450\A0116751.sys Objets détectés : Trojan-Downloader.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP450\A0116752.sys Objets détectés : Win32.SuspectCrc!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP451\A0116779.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP451\A0116780.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP451\A0116781.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP451\A0116782.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP451\A0116798.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP451\A0116810.sys Objets détectés : Trojan-Downloader.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP451\A0116812.sys Objets détectés : Win32.SuspectCrc!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP451\A0116820.sys Objets détectés : Win32.SuspectCrc!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP451\A0116821.sys Objets détectés : Trojan-Downloader.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP451\A0116825.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP451\A0116826.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP451\A0116840.sys Objets détectés : Win32.SuspectCrc!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP451\A0116841.sys Objets détectés : Trojan-Downloader.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP451\A0116845.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP451\A0116846.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP451\A0116847.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP451\A0116870.sys Objets détectés : Win32.SuspectCrc!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP451\A0116871.sys Objets détectés : Trojan-Downloader.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP452\A0117872.sys Objets détectés : Win32.SuspectCrc!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP452\A0117873.sys Objets détectés : Trojan-Downloader.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP452\A0117880.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP452\A0117906.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP452\A0117907.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP452\A0118003.sys Objets détectés : Win32.SuspectCrc!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP452\A0118004.sys Objets détectés : Trojan-Downloader.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP452\A0118090.sys Objets détectés : Win32.SuspectCrc!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP452\A0118091.sys Objets détectés : Trojan-Downloader.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP452\A0118093.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP452\A0118094.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP453\A0118103.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP453\A0118104.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP453\A0118105.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP453\A0118106.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP453\A0118116.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP453\A0118125.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP453\A0118126.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP453\A0118134.dll Objets détectés : Trojan.Win32.Monderd!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP453\A0118139.sys Objets détectés : Trojan-Downloader.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP453\A0118140.sys Objets détectés : Win32.SuspectCrc!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP454\A0118184.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP454\A0118185.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP454\A0118186.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP454\A0118187.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP454\A0118197.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP454\A0118206.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP454\A0118207.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP454\A0118215.dll Objets détectés : Trojan.Win32.Monderd!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP454\A0118220.sys Objets détectés : Trojan-Downloader.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP454\A0118221.sys Objets détectés : Win32.SuspectCrc!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP455\A0118262.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP455\A0118263.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP455\A0118264.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP455\A0118265.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP455\A0118275.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP455\A0118284.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP455\A0118285.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP455\A0118293.dll Objets détectés : Trojan.Win32.Monderd!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP455\A0118298.sys Objets détectés : Trojan-Downloader.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP455\A0118299.sys Objets détectés : Win32.SuspectCrc!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP455\A0118331.sys Objets détectés : Win32.SuspectCrc!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP455\A0118334.sys Objets détectés : Trojan-Downloader.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP455\A0118451.sys Objets détectés : Win32.SuspectCrc!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP455\A0118452.sys Objets détectés : Trojan-Downloader.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP455\A0118458.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP455\A0118478.sys Objets détectés : Win32.SuspectCrc!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP455\A0118480.sys Objets détectés : Trojan-Downloader.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP455\A0118483.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP455\A0118485.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP455\A0118486.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP455\A0118493.sys Objets détectés : Win32.SuspectCrc!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP455\A0118494.sys Objets détectés : Trojan-Downloader.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP455\A0118502.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP455\A0118503.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP455\A0118531.sys Objets détectés : Win32.SuspectCrc!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP455\A0118533.sys Objets détectés : Trojan-Downloader.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP455\A0118551.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP455\A0118554.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP455\A0118570.sys Objets détectés : Win32.SuspectCrc!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP455\A0118572.sys Objets détectés : Trojan-Downloader.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP455\A0118590.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP455\A0118591.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP456\A0118592.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP463\A0119108.sys Objets détectés : Win32.SuspectCrc!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP463\A0119109.sys Objets détectés : Trojan-Downloader.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP463\A0120105.sys Objets détectés : Win32.SuspectCrc!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP463\A0120106.sys Objets détectés : Trojan-Downloader.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP467\A0121706.sys Objets détectés : Win32.SuspectCrc!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP467\A0121708.sys Objets détectés : Trojan-Downloader.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP467\A0121711.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP467\A0121718.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP467\A0121719.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP468\A0121749.sys Objets détectés : Win32.SuspectCrc!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP468\A0121750.sys Objets détectés : Trojan-Downloader.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP468\A0121755.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP468\A0121756.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP468\A0121763.sys Objets détectés : Win32.SuspectCrc!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP468\A0121766.sys Objets détectés : Trojan-Downloader.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP468\A0121773.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP468\A0121774.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP472\A0121819.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0121822.exe Objets détectés : Win32.SuspectCrc!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0121826.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0121958.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0121961.dll Objets détectés : Trojan.Win32.Monderc!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0121962.dll Objets détectés : Trojan.Win32.Monderc!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0123764.sys Objets détectés : Win32.SuspectCrc!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0123765.sys Objets détectés : Trojan-Downloader.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0123776.sys Objets détectés : Win32.SuspectCrc!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0123777.sys Objets détectés : Trojan-Downloader.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0124776.sys Objets détectés : Win32.SuspectCrc!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0124777.sys Objets détectés : Trojan-Downloader.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0126776.sys Objets détectés : Win32.SuspectCrc!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0126777.sys Objets détectés : Trojan-Downloader.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0127778.sys Objets détectés : Win32.SuspectCrc!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0127779.sys Objets détectés : Trojan-Downloader.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0127831.exe Objets détectés : Trojan.Zlob!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0127890.sys Objets détectés : Win32.SuspectCrc!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0127891.sys Objets détectés : Trojan-Downloader.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0128889.sys Objets détectés : Win32.SuspectCrc!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0128890.sys Objets détectés : Trojan-Downloader.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0129897.sys Objets détectés : Win32.SuspectCrc!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0129898.sys Objets détectés : Trojan-Downloader.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0131897.sys Objets détectés : Win32.SuspectCrc!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0131898.sys Objets détectés : Trojan-Downloader.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0132897.sys Objets détectés : Win32.SuspectCrc!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0132898.sys Objets détectés : Trojan-Downloader.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0133897.sys Objets détectés : Win32.SuspectCrc!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0133898.sys Objets détectés : Trojan-Downloader.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0133933.sys Objets détectés : Win32.SuspectCrc!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0133934.sys Objets détectés : Trojan-Downloader.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0134933.sys Objets détectés : Win32.SuspectCrc!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0134934.sys Objets détectés : Trojan-Downloader.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0135933.sys Objets détectés : Win32.SuspectCrc!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0135934.sys Objets détectés : Trojan-Downloader.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0137933.sys Objets détectés : Win32.SuspectCrc!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0137934.sys Objets détectés : Trojan-Downloader.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0137938.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0138933.sys Objets détectés : Win32.SuspectCrc!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0138934.sys Objets détectés : Trojan-Downloader.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0138944.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0139933.sys Objets détectés : Win32.SuspectCrc!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0139934.sys Objets détectés : Trojan-Downloader.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0140933.sys Objets détectés : Win32.SuspectCrc!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0140934.sys Objets détectés : Trojan-Downloader.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0141933.sys Objets détectés : Win32.SuspectCrc!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0141934.sys Objets détectés : Trojan-Downloader.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0141948.sys Objets détectés : Win32.SuspectCrc!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0141949.sys Objets détectés : Trojan-Downloader.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0142948.sys Objets détectés : Win32.SuspectCrc!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0142950.sys Objets détectés : Trojan-Downloader.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0144232.sys Objets détectés : Win32.SuspectCrc!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0144233.sys Objets détectés : Trojan-Downloader.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0145251.sys Objets détectés : Win32.SuspectCrc!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0145252.sys Objets détectés : Trojan-Downloader.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146339.sys Objets détectés : Win32.SuspectCrc!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146340.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146341.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146342.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146343.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146344.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146345.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146346.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146347.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146348.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146349.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146350.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146351.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146352.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146353.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146354.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146355.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146356.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146357.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146358.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146359.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146360.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146361.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146362.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146363.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146364.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146365.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146366.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146367.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146368.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146369.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146370.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146371.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146373.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146374.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146375.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146376.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146377.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146378.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146379.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146380.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146381.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146382.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146383.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146384.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146385.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146386.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146387.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146388.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146389.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146390.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146391.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146392.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146393.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146394.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146395.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146396.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146397.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146398.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146399.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146400.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146401.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146402.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146403.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146404.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146405.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146406.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146407.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146408.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146409.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146410.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146411.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146412.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146413.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146414.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146415.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146416.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146417.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146418.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146419.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146420.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146421.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146422.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146423.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146424.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146425.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146426.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146427.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146428.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146429.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146430.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146431.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146432.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146433.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146434.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146435.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146436.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146437.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146438.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146439.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146440.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146441.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146442.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146443.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146444.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146445.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146446.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146447.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146448.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146449.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146450.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146451.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146452.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146453.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146454.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146455.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146456.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146457.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146458.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146459.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146460.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146461.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146462.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146463.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146464.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146465.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146466.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146467.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146468.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146469.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146470.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146471.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146472.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146473.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146474.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146475.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146476.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146477.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146483.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146484.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146485.exe Objets détectés : Trojan.Crypt!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146486.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146487.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146488.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146489.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146490.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146491.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146492.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146493.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146494.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146495.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146496.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146497.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146498.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146499.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146500.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146501.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146502.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146503.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146504.sys Objets détectés : Trojan-Downloader.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146711.exe Objets détectés : possible-threat.Connect2.SuspendedPage!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146712.exe Objets détectés : possible-threat.Connect2.SuspendedPage!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0146725.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0147485.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0147486.exe Objets détectés : Gen.Packer!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0147487.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0147488.exe Objets détectés : Email-Worm.Win32.Bagle!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0148080.exe Objets détectés : possible-threat.Connect2.SuspendedPage!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0148176.exe Objets détectés : possible-threat.Connect2.SuspendedPage!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0148177.exe Objets détectés : possible-threat.Connect2.SuspendedPage!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0148178.exe Objets détectés : possible-threat.Connect2.SuspendedPage!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0148192.exe Objets détectés : possible-threat.Connect2.SuspendedPage!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0148195.exe Objets détectés : possible-threat.Connect2.SuspendedPage!IK
        C:\System Volume Information\_restore{AB7ADA23-3C31-485C-8109-BDA0CA666B7E}\RP473\A0148199.exe Objets détectés : possible-threat.Connect2.SuspendedPage!IK
        C:\System Volume Inf
        0
        1. sacrée collection de virus!!!!!!!!!!!!!!!
          0
      2. Contributeur sécurité
        bonjour,

        le site bug grave sa fait 2 fois que je poste et je ne vois toujours aucun poste...

        desinstalle ELIBAGLA

        * Telecharge Findykill sur ton bureau https://www.androidworld.fr/

        * (c'est le numéro 18 en bas de la page)

        * Lance l installation avec les parametres par default

        * Double clic sur le raccourci FindyKill sur ton bureau

        * Au menu principal,choisi l option 1 (Recherche)

        * Post le rapport FindyKill.txt

        * Note : le rapport FindyKill.txt est sauvegardé a la racine du disque
        0
        1. Contributeur sécurité
          oula

          d'un coup 7 poste :s bon le premier et le 2eme sont passé c'est le principale

          donc elfedelaune en attente du rapport findykill et deinstalle bien AVANT elibagla et supprime TOUT tes crack qui ton infecté
          0
          1. MERCI POUR CETTE AIDE
            j'ai enregistré tes conseils . Ne t'inqiète pas si tu as l'impression que je ne suis pas à l'écoute, c'est juste que j'ai un enfant et qu'il faut aussi que je m'en occupe !!!
            as tu vu mes rapports ?
            dis moi si en fonction d'eux il faut que je fasse ce que tu m'as conseillé avant de te les montrer
            mille fois merci
            0
            1. peux tu me dire sur le site comment je peux voir tes messages car sur l'icone envelloppe il y a rien alors que je vois bien tes messages sur ma boite mail
              merci
              0
              1. Salut,

                C'est le risque d'un crack, déjà supprime l'application cracké.
                0
                1. qu'est ce que le dossier craqué et comment je fais pour le trouvé ?
                  J'ai vidé tous les fichiers dans mes documents
                  0
                  1. Contributeur sécurité
                    re

                    il n' arien detecté mais

                    * Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) suceptible d avoir été infectés sans les ouvrir
                    * Double clic sur le raccourci FindyKill sur ton bureau
                    * Au menu principal,choisi l option 2 (Suppression)

                    /!\ il y aura 1 redémarrage, laisse travailler l outils jusqu a l apparition du message "nettoyage effectué"

                    /!\ Ne te sert pas du pc durant la suppression , ton bureau ne sera pas accessible c est normal !
                    * ensuite post le rapport FindyKill.txt

                    * Note : le rapport FindyKill.txt est sauvegardé a la racine du disque
                    * Note : Si le Bureau ne réapparait pas presse Ctrl + Alt + Suppr , Onglet "Fichier" , "Nouvelle tâche" , tapes explorer.exe et valides

                    puis

                    * Télécharge hijackthis https://www.androidworld.fr/

                    * Tout est expliqué pour bien l installer et savoir l'utiliser.

                    Comment copier/coller le rapport :

                    Quand tu as le rapport à l écran, tu fais ctrl A pour "sélectionner tout" puis ctrl C pour "copier".

                    Ensuite tu viens sur le forum pour me répondre et tu fais ctrl V pour "coller" le rapport.
                    0
                    1. Contributeur sécurité
                      re

                      ben oui tu abrite pas mal de virus on commence par le rogue antivirus 360

                      Option 1 - Recherche :

                      * Télécharge Smitfraudfix et enregistre le sur le bureau

                      (c est le numéro 2 en bas de la page) :
                      * Ensuite double clique sur smitfraudfix puis exécuter
                      * Sélectionner 1 pour créer un rapport des fichiers responsables de l'infection.

                      (attention : N utilises pas l option 2 si je ne te l ai pas demandé !!)
                      * copier/coller le rapport dans la réponse.

                      Un tutoriel sonore et animé est à ta disposition sur le site.

                      (Attention : "process.exe", un composant de l'outil, est détecté par certains antivirus comme étant un "RiskTool".
                      Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus. Mis entre de mauvaises mains,
                      cet utilitaire pourrait arrêter des logiciels de sécurité.)
                      0
                      1. Contributeur sécurité
                        rolala c'est chiant les bug du site....

                        donc deja poste a la suite du sujet a la fin pas en milieu de page merci

                        puis

                        Option 1 - Recherche :

                        * Télécharge Smitfraudfix et enregistre le sur le bureau https://www.androidworld.fr/

                        (c est le numéro 2 en bas de la page) :
                        * Ensuite double clique sur smitfraudfix puis exécuter
                        * Sélectionner 1 pour créer un rapport des fichiers responsables de l'infection.

                        (attention : N utilises pas l option 2 si je ne te l ai pas demandé !!)
                        * copier/coller le rapport dans la réponse.

                        Un tutoriel sonore et animé est à ta disposition sur le site.

                        (Attention : "process.exe", un composant de l'outil, est détecté par certains antivirus comme étant un "RiskTool".
                        Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus. Mis entre de mauvaises mains,
                        cet utilitaire pourrait arrêter des logiciels de sécurité.)
                        0
                        1. je suis désolée, pour mes mauvaises manip
                          je te récapitule ce que j'ai fait et refait
                          1) FINDYKILL recherche et nettoyage
                          ############################## [ FindyKill V4.717 ]

                          # User : Administrateur (Administrateurs) # PERSO-C7DA5A812
                          # Update on 17/02/09 by Chiquitine29
                          # Start at: 19:34:18 | 24/02/2009

                          # Intel(R) Pentium(R) 4 CPU 2.00GHz
                          # Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 3
                          # Internet Explorer 7.0.5730.13
                          # Windows Firewall Status : Enabled

                          # A:\ # Lecteur de disquettes 3 ½ pouces
                          # C:\ # Disque fixe local # NTFS
                          # D:\ # Disque CD-ROM
                          # E:\ # Disque CD-ROM

                          ############################## [ Active Processes ]

                          C:\WINDOWS\System32\smss.exe
                          C:\WINDOWS\system32\csrss.exe
                          C:\WINDOWS\system32\winlogon.exe
                          C:\WINDOWS\system32\services.exe
                          C:\WINDOWS\system32\lsass.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\system32\spoolsv.exe
                          C:\Program Files\a-squared Free\a2service.exe
                          C:\WINDOWS\System32\FTRTSVC.exe
                          C:\Program Files\Java\jre6\bin\jqs.exe
                          C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
                          C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
                          C:\Program Files\CDBurnerXP\NMSAccessU.exe
                          C:\WINDOWS\system32\HPZipm12.exe
                          C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
                          C:\Program Files\Java\jre6\bin\jusched.exe
                          C:\WINDOWS\system32\rundll32.exe
                          C:\WINDOWS\system32\ctfmon.exe
                          C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
                          C:\WINDOWS\System32\alg.exe
                          C:\WINDOWS\system32\wbem\wmiapsrv.exe
                          C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
                          C:\PROGRA~1\Wanadoo\GestionnaireInternet.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\PROGRA~1\Wanadoo\ComComp.exe
                          C:\PROGRA~1\Wanadoo\Toaster.exe
                          C:\PROGRA~1\Wanadoo\Inactivity.exe
                          C:\PROGRA~1\Wanadoo\PollingModule.exe
                          C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
                          C:\PROGRA~1\Wanadoo\Watch.exe
                          C:\PROGRA~1\Wanadoo\WOOBrowser\WOOBrowser.exe
                          C:\WINDOWS\system32\rundll32.exe
                          C:\PROGRA~1\Wanadoo\WOOBRO~1\DownloadManager.exe
                          C:\WINDOWS\system32\wbem\wmiprvse.exe

                          ################## [ Infected Files / Folders C:\ ]

                          Deleted ! - C:\InfoSat.txt

                          ################## [ C:\WINDOWS ]

                          ################## [ C:\WINDOWS\system32 ]

                          ################## [ C:\WINDOWS\system32\drivers ]

                          ################## [ C:\.. Application Data ... ]

                          Deleted ! - "C:\Documents and Settings\Administrateur\Application Data\m\shared"
                          Deleted ! - "C:\Documents and Settings\Administrateur\Application Data\m"
                          Deleted ! - "C:\Documents and Settings\Administrateur\Application Data\inst.exe"

                          ################## [ Registry / Infected keys ]

                          Deleted ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA
                          Deleted ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SROSA
                          Deleted ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_SROSA
                          Deleted ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SK9OU0S
                          Deleted ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_SK9OU0S
                          Deleted ! - HKEY_CURRENT_USER\Software\FirtR
                          Deleted ! - HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\patch
                          Deleted ! - HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\winupgro

                          ################## [ Cleaning Removable drives ]

                          # Deleting files :

                          ################## [ Registry / Mountpoint2 ]

                          # -> Not found !

                          ################## [ Searching Other Infections ]

                          # -> Nothing found ! ..

                          ################## [ ! End of Report # FindyKill V4.717 ! ]
                          ______________________________________________________________________________________________________________________________________________________________________________________ Logfile of Trend Micro HijackThis v2.0.2
                          Scan saved at 19:50:07, on 24/02/2009
                          Platform: Windows XP SP3 (WinNT 5.01.2600)
                          MSIE: Internet Explorer v7.00 (7.00.6000.16762)
                          Boot mode: Normal

                          Running processes:
                          C:\WINDOWS\System32\smss.exe
                          C:\WINDOWS\system32\winlogon.exe
                          C:\WINDOWS\system32\services.exe
                          C:\WINDOWS\system32\lsass.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\WINDOWS\system32\spoolsv.exe
                          C:\Program Files\a-squared Free\a2service.exe
                          C:\WINDOWS\System32\FTRTSVC.exe
                          C:\Program Files\Java\jre6\bin\jqs.exe
                          C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
                          C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
                          C:\Program Files\CDBurnerXP\NMSAccessU.exe
                          C:\WINDOWS\system32\HPZipm12.exe
                          C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
                          C:\WINDOWS\system32\wbem\wmiapsrv.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\WINDOWS\explorer.exe
                          C:\WINDOWS\system32\notepad.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\Program Files\Wanadoo\GestionnaireInternet.exe
                          C:\Program Files\Wanadoo\ComComp.exe
                          C:\PROGRA~1\Wanadoo\Toaster.exe
                          C:\PROGRA~1\Wanadoo\Inactivity.exe
                          C:\PROGRA~1\Wanadoo\PollingModule.exe
                          C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
                          C:\Program Files\Wanadoo\Watch.exe
                          C:\PROGRA~1\Wanadoo\WOOBrowser\WOOBrowser.exe
                          C:\WINDOWS\system32\ctfmon.exe
                          C:\Program Files\Trend Micro\HijackThis\HJT.exe.exe

                          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
                          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Orange
                          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                          R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
                          R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
                          O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
                          O2 - BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
                          O2 - BHO: (no name) - {19873120-106A-4A43-95C3-A55EDF280F42} - C:\WINDOWS\system32\iifgHwvw.dll
                          O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
                          O2 - BHO: (no name) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - (no file)
                          O2 - BHO: (no name) - {4FC762BA-4251-401A-B6B2-BCCE3531B092} - (no file)
                          O2 - BHO: (no name) - {62CED47C-1064-4961-9F90-6DBD660A6F24} - (no file)
                          O2 - BHO: EoBho Class - {64F56FC1-1272-44CD-BA6E-39723696E350} - C:\PROGRA~1\EoRezo\EoAdv\EOREZO~1.DLL (file missing)
                          O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
                          O2 - BHO: (no name) - {70376bb7-dcd1-4cfc-a0e6-53ac5052870c} - C:\WINDOWS\system32\luyehije.dll (file missing)
                          O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
                          O2 - BHO: (no name) - {77AB5974-55A3-4737-9FD5-B93C64307F78} - C:\WINDOWS\system32\xfosjtlt.dll
                          O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                          O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                          O2 - BHO: &Research - {D263FA6D-84CC-48A8-9AF6-C664362B7A5B} - C:\WINDOWS\system32\winconfig.dll
                          O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                          O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                          O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
                          O2 - BHO: SweetIM Toolbar Helper - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
                          O2 - BHO: (no name) - {f592709f-ff4a-4862-b659-4afabda56312} - (no file)
                          O3 - Toolbar: SweetIM Toolbar for Internet Explorer - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
                          O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                          O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
                          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                          O4 - HKLM\..\Run: [Mgemihanofowaceh] rundll32.exe "C:\WINDOWS\Qqexiwifapo.dll",e
                          O4 - HKLM\..\Run: [vezokirosi] Rundll32.exe "C:\WINDOWS\system32\juyodufu.dll",s
                          O4 - HKLM\..\Run: [CPM77491acb] Rundll32.exe "c:\windows\system32\fapalogo.dll",a
                          O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
                          O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
                          O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                          O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
                          O4 - HKCU\..\Run: [wmgoc] "c:\documents and settings\administrateur\local settings\application data\wmgoc.exe" wmgoc
                          O4 - HKCU\..\Run: [3C3760EC4C6B8BD2EDA4178E3F736DAC] C:\Program Files\A360\av360.exe
                          O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\CCleaner.exe" /AUTO
                          O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                          O4 - HKUS\S-1-5-19\..\Run: [vezokirosi] Rundll32.exe "C:\WINDOWS\system32\juyodufu.dll",s (User 'SERVICE LOCAL')
                          O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                          O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "c:\PROGRA~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
                          O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "c:\PROGRA~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
                          O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
                          O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
                          O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office12\EXCEL.EXE/3000
                          O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
                          O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
                          O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                          O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                          O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\Office12\REFIEBAR.DLL
                          O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                          O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                          O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
                          O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
                          O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - C:\Program Files\Yahoo!\Common\yinsthelper.dll
                          O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www3.snapfish.fr/SnapfishActivia.cab
                          O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} (Image Uploader Control) - http://www.extrafilm.fr/ImageUploader5.cab
                          O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
                          O16 - DPF: {7DA181BB-EF8D-4A7E-8C53-7BFC718EF71D} (Upload Class) - http://photoservice.photos.orange.fr/migrationorange/index.cfm
                          O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://cid-0c4ed52d9ade83dc.spaces.live.com/PhotoUpload/MsnPUpld.cab
                          O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - https://www.touslesdrivers.com/index.php?v_page=29
                          O16 - DPF: {CAC677B6-4963-4305-9066-0BD135CD9233} (IPSUploader4 Control) - http://as.photoprintit.de/ips-opdata/layout/default01/activex/IPSUploader4.cab
                          O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                          O16 - DPF: {EDFCB7CB-942C-4822-AF14-F0B687409848} (Image Uploader Control) - http://www.leaderphoto.com/uploaders/aurigma_4_7_16/ImageUploader4.cab
                          O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
                          O20 - AppInit_DLLs: C:\WINDOWS\system32\rejijejo.dll c:\windows\system32\fapalogo.dll
                          O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\fapalogo.dll
                          O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\fapalogo.dll
                          O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
                          O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
                          O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
                          O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
                          O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
                          O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
                          O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\SrvLnch\SrvLnch.exe
                          O23 - Service: NMIndexingService - Unknown owner - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe (file missing)
                          O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
                          O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
                          O23 - Service: PC Tools Auxiliary Service (sdAuxService) - Unknown owner - C:\Program Files\Spyware Doctor\pctsAuxs.exe (file missing)
                          O23 - Service: PC Tools Security Service (sdCoreService) - Unknown owner - C:\Program Files\Spyware Doctor\pctsSvc.exe (file missing)
                          0
                      2. Contributeur sécurité
                        lol

                        j'hallucine avec les bug du site, je ne voyait pas tout ce que findykill avait detecté

                        en attente de la suite
                        0
                        1. SmitFraudFix v2.398

                          Rapport fait à 20:05:32,54, 24/02/2009
                          Executé à partir de C:\DOCUME~1\ADMINI~1\Bureau\SmitfraudFix
                          OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
                          Le type du système de fichiers est NTFS
                          Fix executé en mode normal

                          »»»»»»»»»»»»»»»»»»»»»»»» Process

                          C:\WINDOWS\System32\smss.exe
                          C:\WINDOWS\system32\winlogon.exe
                          C:\WINDOWS\system32\services.exe
                          C:\WINDOWS\system32\lsass.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\WINDOWS\system32\spoolsv.exe
                          C:\Program Files\a-squared Free\a2service.exe
                          C:\WINDOWS\System32\FTRTSVC.exe
                          C:\Program Files\Java\jre6\bin\jqs.exe
                          C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
                          C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
                          C:\Program Files\CDBurnerXP\NMSAccessU.exe
                          C:\WINDOWS\system32\HPZipm12.exe
                          C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
                          C:\WINDOWS\system32\wbem\wmiapsrv.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\WINDOWS\explorer.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\Program Files\Wanadoo\GestionnaireInternet.exe
                          C:\Program Files\Wanadoo\ComComp.exe
                          C:\PROGRA~1\Wanadoo\Toaster.exe
                          C:\PROGRA~1\Wanadoo\Inactivity.exe
                          C:\PROGRA~1\Wanadoo\PollingModule.exe
                          C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
                          C:\Program Files\Wanadoo\Watch.exe
                          C:\PROGRA~1\Wanadoo\WOOBrowser\WOOBrowser.exe
                          C:\WINDOWS\system32\ctfmon.exe
                          C:\WINDOWS\system32\rundll32.exe
                          C:\PROGRA~1\Wanadoo\WOOBRO~1\DownloadManager.exe
                          C:\DOCUME~1\ADMINI~1\Bureau\SmitfraudFix\Policies.exe
                          C:\WINDOWS\system32\cmd.exe

                          »»»»»»»»»»»»»»»»»»»»»»»» hosts

                          »»»»»»»»»»»»»»»»»»»»»»»» C:\

                          »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

                          »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

                          »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

                          »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

                          »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles

                          »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Administrateur

                          »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp

                          »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Administrateur\Application Data

                          »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

                          »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\ADMINI~1\Favoris

                          »»»»»»»»»»»»»»»»»»»»»»»» Bureau

                          »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

                          »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

                          »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

                          »»»»»»»»»»»»»»»»»»»»»»»» o4Patch
                          !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                          o4Patch
                          Credits: Malware Analysis & Diagnostic
                          Code: S!Ri

                          »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
                          !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                          IEDFix
                          Credits: Malware Analysis & Diagnostic
                          Code: S!Ri

                          »»»»»»»»»»»»»»»»»»»»»»»» Agent.OMZ.Fix
                          !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                          Agent.OMZ.Fix
                          Credits: Malware Analysis & Diagnostic
                          Code: S!Ri

                          »»»»»»»»»»»»»»»»»»»»»»»» VACFix
                          !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                          VACFix
                          Credits: Malware Analysis & Diagnostic
                          Code: S!Ri

                          »»»»»»»»»»»»»»»»»»»»»»»» 404Fix
                          !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                          404Fix
                          Credits: Malware Analysis & Diagnostic
                          Code: S!Ri

                          »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
                          !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                          SrchSTS.exe by S!Ri
                          Search SharedTaskScheduler's .dll

                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
                          "{EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4}"="STS"

                          [HKEY_CLASSES_ROOT\CLSID\{EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4}\InProcServer32]
                          @="c:\windows\system32\fapalogo.dll"

                          [HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4}\InProcServer32]
                          @="c:\windows\system32\fapalogo.dll"

                          »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
                          !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
                          "AppInit_DLLs"="C:\\WINDOWS\\system32\\rejijejo.dll c:\\windows\\system32\\fapalogo.dll "
                          "LoadAppInit_DLLs"=dword:00000001

                          »»»»»»»»»»»»»»»»»»»»»»»» Winlogon
                          !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
                          "Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
                          "System"=""

                          »»»»»»»»»»»»»»»»»»»»»»»» RK

                          »»»»»»»»»»»»»»»»»»»»»»»» DNS

                          Description: Intel(R) PRO/100 VE Network Connection - Miniport d'ordonnancement de paquets
                          DNS Server Search Order: 192.168.1.1

                          Description: Intel(R) PRO/100 VE Network Connection - Miniport d'ordonnancement de paquets
                          DNS Server Search Order: 192.168.1.1

                          HKLM\SYSTEM\CCS\Services\Tcpip\..\{63B50981-1FDA-4EFE-A302-D5DECED5B2A9}: DhcpNameServer=192.168.1.1
                          HKLM\SYSTEM\CCS\Services\Tcpip\..\{AAED222D-DA9A-4001-A79D-FF4E3BBE258C}: DhcpNameServer=192.168.1.1
                          HKLM\SYSTEM\CS1\Services\Tcpip\..\{63B50981-1FDA-4EFE-A302-D5DECED5B2A9}: DhcpNameServer=192.168.1.1
                          HKLM\SYSTEM\CS2\Services\Tcpip\..\{63B50981-1FDA-4EFE-A302-D5DECED5B2A9}: DhcpNameServer=192.168.1.1
                          HKLM\SYSTEM\CS2\Services\Tcpip\..\{AAED222D-DA9A-4001-A79D-FF4E3BBE258C}: DhcpNameServer=192.168.1.1
                          HKLM\SYSTEM\CS3\Services\Tcpip\..\{63B50981-1FDA-4EFE-A302-D5DECED5B2A9}: DhcpNameServer=192.168.1.1
                          HKLM\SYSTEM\CS3\Services\Tcpip\..\{AAED222D-DA9A-4001-A79D-FF4E3BBE258C}: DhcpNameServer=192.168.1.1
                          HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
                          HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
                          HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1

                          »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

                          »»»»»»»»»»»»»»»»»»»»»»»» Fin
                          0
                      3. Contributeur sécurité
                        bon il a rien detecté

                        desactive ton antivirus et toutes tes defense et telecharge sur ton BUREAU puis deconnecte toi d'internet

                        combofix http://download.bleepingcomputer.com/sUBs/ComboFix.exe

                        lance le et ne touche + a rien et poste le rapport à la fin
                        0
                        1. comme tu le dis avec les bugs j'ai eu du mal à te suivre, j'espère que je te suis bien 1 etape FINDYKILL
                          2 etape HIDJACK 3 etape smitfraudfix
                          OK missions accomplies !
                          Tu dois pouvoir voir les trois rapports à la suite

                          (pendant ce temps mon fils lui s'éclate, il joue de la batterie avec des bouteilles de vin, coca, eau !!!!!)
                          0
                          1. Contributeur sécurité
                            oui c'est bon , suit le poste 21 avec combofix
                            0
                            1. Etape 4 COMBO FIX

                              ComboFix 09-02-21.01 - Administrateur 2009-02-24 20:38:05.1 - NTFSx86
                              Microsoft Windows XP Professionnel 5.1.2600.3.1252.1.1036.18.247.97 [GMT 1:00]
                              Lancé depuis: c:\documents and settings\Administrateur\Bureau\Bibitte.exe
                              * Un nouveau point de restauration a été créé
                              .
                              [color=purple]Les fichiers ci-dessous ont été désactivés pendant l'exécution:[/color]
                              c:\windows\system32\rejijejo.dll
                              c:\windows\system32\fapalogo.dll

                              (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
                              .

                              c:\documents and settings\Administrateur\Application Data\QUAD Backups
                              c:\documents and settings\Administrateur\Local Settings\Application Data\ddpfglo.dat
                              c:\documents and settings\Administrateur\Local Settings\Application Data\ddpfglo_nav.dat
                              c:\documents and settings\Administrateur\Local Settings\Application Data\ddpfglo_navps.dat
                              c:\documents and settings\Administrateur\Local Settings\Application Data\egakiiy.dat
                              c:\documents and settings\Administrateur\Local Settings\Application Data\egakiiy_nav.dat
                              c:\documents and settings\Administrateur\Local Settings\Application Data\egakiiy_navps.dat
                              c:\documents and settings\Administrateur\Local Settings\Application Data\wmgoc.dat
                              c:\documents and settings\Administrateur\Local Settings\Application Data\wmgoc_nav.dat
                              c:\documents and settings\Administrateur\Local Settings\Application Data\wmgoc_navps.dat
                              c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
                              c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
                              c:\windows\BM77491acb.txt
                              c:\windows\BM77491acb.xml
                              c:\windows\cookies.ini
                              c:\windows\dialerexe.ini
                              c:\windows\pskt.ini
                              c:\windows\system32\404Fix.exe
                              c:\windows\system32\Agent.OMZ.Fix.exe
                              c:\windows\system32\anewewij.ini
                              c:\windows\system32\bubedena.dll
                              c:\windows\system32\chvstpwo.ini
                              c:\windows\system32\cxvjxyjs.ini
                              c:\windows\system32\dahiliwi.dll.tmp
                              c:\windows\system32\DcLllUvw.ini
                              c:\windows\system32\DcLllUvw.ini2
                              c:\windows\system32\dhiqkcge.ini
                              c:\windows\system32\dumphive.exe
                              c:\windows\system32\fapalogo.dll.vir
                              c:\windows\system32\fewibuvo.dll
                              c:\windows\system32\fkvyncwn.ini
                              c:\windows\system32\gogramdi.ini
                              c:\windows\system32\hizuruvo.dll
                              c:\windows\system32\idmargog.dll
                              c:\windows\system32\IEDFix.C.exe
                              c:\windows\system32\IEDFix.exe
                              c:\windows\system32\iifgHwvw.dll
                              c:\windows\system32\jegehude.dll
                              c:\windows\system32\juyodufu.dll
                              c:\windows\system32\korulawa.dll.tmp
                              c:\windows\system32\lekobiga.dll.tmp
                              c:\windows\system32\luyehije.dll.tmp
                              c:\windows\system32\nkymvgnu.ini
                              c:\windows\system32\nwcnyvkf.dll
                              c:\windows\system32\o4Patch.exe
                              c:\windows\system32\ohuheyed.ini
                              c:\windows\system32\opnopNda.dll
                              c:\windows\system32\owptsvhc.dll
                              c:\windows\system32\pqwfgnur.ini
                              c:\windows\system32\Process.exe
                              c:\windows\system32\qXFPAJjl.ini
                              c:\windows\system32\qXFPAJjl.ini2
                              c:\windows\system32\rejijejo.dll.vir
                              c:\windows\system32\rojisabo.dll.tmp
                              c:\windows\system32\sahoruhe.dll.tmp
                              c:\windows\system32\SrchSTS.exe
                              c:\windows\system32\swsc.exe
                              c:\windows\system32\tmp.reg
                              c:\windows\system32\tnkibuby.ini
                              c:\windows\system32\txlrhsiy.ini
                              c:\windows\system32\VACFix.exe
                              c:\windows\system32\VCCLSID.exe
                              c:\windows\system32\wouqwdgh.ini
                              c:\windows\system32\WS2Fix.exe
                              c:\windows\system32\wvUllLcD.dll.vir
                              c:\windows\system32\wvwHgfii.ini
                              c:\windows\system32\wvwHgfii.ini2
                              c:\windows\system32\xxyyyVOI.dll
                              c:\windows\Tasks\vpuaquyx.job
                              c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat . . . . impossible à supprimer
                              c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat . . . . impossible à supprimer

                              ----- BITS: Il y a peut-être des sites infectés -----

                              hxxp://childhe.com
                              .
                              ((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
                              .

                              -------\Legacy_BOONTY_GAMES
                              -------\Service_Boonty Games

                              ((((((((((((((((((((((((((((( Fichiers créés du 2009-01-24 au 2009-02-24 ))))))))))))))))))))))))))))))))))))
                              .

                              2009-02-24 19:06 . 2009-02-24 19:06 <REP> d-------- c:\program files\Trend Micro
                              2009-02-24 18:46 . 2009-02-24 19:44 <REP> d-------- c:\program files\FindyKill
                              2009-02-24 01:53 . 2009-02-24 01:53 <REP> d-------- c:\program files\SpywareBlaster
                              2009-02-24 01:38 . 2009-02-24 17:34 <REP> d-------- c:\program files\a-squared Free
                              2009-02-24 00:04 . 2009-02-24 00:13 <REP> d-------- c:\documents and settings\All Users\Application Data\_comodo_
                              2009-02-23 23:52 . 2009-02-23 23:52 <REP> d-------- c:\program files\AskBarDis
                              2009-02-23 23:52 . 2009-02-23 23:52 249,592 --a------ c:\windows\system32\cssdll32.dll
                              2009-02-23 23:50 . 2009-02-24 12:12 <REP> d-------- c:\program files\COMODO
                              2009-02-23 16:01 . 2009-02-23 16:19 <REP> d-------- C:\32788R22FWJFW.0.tmp
                              2009-02-10 22:35 . 2009-02-10 22:35 40,960 --a------ c:\windows\Qqexiwifapo.dll
                              2009-02-10 11:35 . 2009-02-24 16:04 <REP> d-------- c:\program files\Fighters
                              2009-02-10 11:22 . 2009-02-10 11:22 <REP> d-------- c:\program files\VIRUSfighter
                              2009-02-01 21:47 . 2009-02-01 21:47 78,415 --a------ c:\windows\system32\drivers\klif.cab
                              2009-02-01 21:43 . 2009-02-01 21:43 <REP> d-------- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
                              2009-02-01 20:46 . 2009-02-01 20:46 301,056 --a------ c:\windows\system32\winconfig.dll
                              2009-01-28 22:43 . 2009-01-28 22:43 104,960 --a------ c:\windows\system32\xfosjtlt.dll
                              2009-01-26 17:18 . 2009-01-26 17:19 <REP> d-------- c:\windows\system32\Adobe

                              .
                              (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                              .
                              2009-02-24 19:47 --------- d-----w c:\program files\Wanadoo
                              2009-02-24 11:19 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
                              2009-02-23 23:49 --------- d-----w c:\documents and settings\Administrateur\Application Data\EoRezo
                              2009-02-10 10:22 --------- d--h--w c:\program files\InstallShield Installation Information
                              2009-02-01 19:45 --------- d-----w c:\program files\Common Files
                              2009-02-01 19:02 --------- d-----w c:\documents and settings\All Users\Application Data\Apple Computer
                              2009-02-01 18:54 --------- d-----w c:\program files\Inkscape
                              2009-02-01 18:51 --------- d-----w c:\documents and settings\Administrateur\Application Data\Inkscape
                              2009-02-01 18:46 --------- d-----w c:\program files\Hewlett-Packard
                              2009-02-01 18:04 --------- d-----w c:\program files\Fichiers communs\HP
                              2009-02-01 16:25 --------- d-----w c:\program files\Conduit
                              2009-01-27 17:02 --------- d-----w c:\program files\Alwil Software
                              2009-01-25 11:51 --------- d-----w c:\program files\Microsoft Games
                              2009-01-16 16:57 --------- d-----w c:\program files\YouTube Video Downloader
                              2009-01-14 10:12 --------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help
                              2009-01-13 16:36 --------- d-----w c:\documents and settings\Administrateur\Application Data\Snapfish
                              2009-01-11 13:29 --------- d-----w c:\documents and settings\Administrateur\Application Data\gtk-2.0
                              2009-01-06 13:10 --------- d-----w c:\program files\Java
                              2009-01-06 09:28 --------- d-----w c:\program files\Kukuxumusu
                              2008-12-30 06:48 --------- d-----w c:\program files\MSN Messenger
                              2008-12-04 23:11 308,584 ----a-w c:\windows\WLXPGSS.SCR
                              2008-11-05 19:56 83,723 ----a-w c:\documents and settings\polices\spahrty_girl_regular.zip
                              2008-11-05 19:54 28,879 ----a-w c:\documents and settings\polices\dearest_dorothy_normal.zip
                              2008-11-05 19:53 72,643 ----a-w c:\documents and settings\polices\penelope_regular.zip
                              2008-11-05 19:12 102,911 ----a-w c:\documents and settings\polices\fleurs_de_liane_regular.zip
                              2008-11-05 19:08 357,977 ----a-w c:\documents and settings\polices\helenademoversion_regular.zip
                              2008-11-05 19:06 47,256 ----a-w c:\documents and settings\polices\vtks_alcalina_regular.zip
                              2008-05-24 07:58 47,360 -c--a-w c:\documents and settings\Administrateur\Application Data\pcouffin.sys
                              2008-08-05 20:22 32,768 -csha-w c:\windows\system32\config\systemprofile\Local Settings\Historique\History.IE5\MSHist012008080520080806\index.dat
                              .

                              ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
                              .
                              .
                              *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
                              REGEDIT4

                              [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
                              2008-08-06 15:20 279944 --a------ c:\program files\AskBarDis\bar\bin\askBar.dll

                              [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847}]
                              2008-03-27 13:12 1164600 --a------ c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll

                              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
                              "{EEE6C35B-6118-11DC-9C72-001320C79847}"= "c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll" [2008-03-27 1164600]
                              "{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-08-06 279944]

                              [HKEY_CLASSES_ROOT\clsid\{eee6c35b-6118-11dc-9c72-001320c79847}]
                              [HKEY_CLASSES_ROOT\SWEETIE.SWEETIE.3]
                              [HKEY_CLASSES_ROOT\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}]
                              [HKEY_CLASSES_ROOT\SWEETIE.SWEETIE]

                              [HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
                              [HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

                              [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
                              "{EEE6C35B-6118-11DC-9C72-001320C79847}"= "c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll" [2008-03-27 1164600]
                              "{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-08-06 279944]

                              [HKEY_CLASSES_ROOT\clsid\{eee6c35b-6118-11dc-9c72-001320c79847}]
                              [HKEY_CLASSES_ROOT\SWEETIE.SWEETIE.3]
                              [HKEY_CLASSES_ROOT\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}]
                              [HKEY_CLASSES_ROOT\SWEETIE.SWEETIE]

                              [HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
                              [HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

                              [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                              "CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
                              "WOOKIT"="c:\progra~1\Wanadoo\Shell.exe" [2004-08-23 122880]
                              "ccleaner"="c:\program files\CCleaner\CCleaner.exe" [2008-10-23 1336560]

                              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                              "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-06 136600]
                              "Mgemihanofowaceh"="c:\windows\Qqexiwifapo.dll" [2009-02-10 40960]
                              "WOOTASKBARICON"="c:\progra~1\Wanadoo\GestMaj.exe" [2004-10-14 32768]
                              "WOOWATCH"="c:\progra~1\Wanadoo\Watch.exe" [2004-08-23 20480]

                              [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
                              "DWQueuedReporting"="c:\progra~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe" [2007-08-24 437160]

                              c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
                              Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2008-08-31 66864]

                              [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
                              "ConsentPromptBehaviorAdmin"= 0 (0x0)

                              [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
                              "AppInit_DLLs"=c:\windows\system32\rejijejo.dll c:\windows\system32\fapalogo.dll

                              [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
                              "vidc.iv41"= ir41_32.dll
                              "MSACM.CEGSM"= mobilev.acm

                              [HKEY_LOCAL_MACHINE\software\microsoft\security center]
                              "UpdatesDisableNotify"=dword:00000001
                              "AntiVirusOverride"=dword:00000001
                              "FirewallOverride"=dword:00000001

                              [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
                              "%windir%\\system32\\sessmgr.exe"=
                              "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
                              "c:\\Program Files\\uTorrent\\uTorrent.exe"=
                              "c:\\Program Files\\Fichiers communs\\Nero\\Nero Web\\SetupX.exe"=
                              "c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
                              "c:\\Program Files\\Microsoft Games\\Age of Empires II\\EMPIRES2.ICD"=
                              "c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
                              "c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
                              "c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
                              "c:\\Program Files\\MSN Messenger\\livecall.exe"=

                              R2 SeaPort;SeaPort;c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2008-12-04 226640]
                              S2 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe --> c:\program files\Spyware Doctor\pctsAuxs.exe [?]
                              S2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [2006-11-03 13592]
                              S3 Ltn_stk7070P;PCTV based TV tuner device;c:\windows\system32\drivers\Ltn_stk7070P.sys [2008-09-02 466048]
                              S3 Ltn_stkrc;PCTV Infrared Receiver;c:\windows\system32\drivers\Ltn_stkrc.sys [2008-09-02 13440]

                              [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1ab0e842-d4db-11dc-96b0-806d6172696f}]
                              \Shell\AutoRun\command - D:\Autorun.exe

                              [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
                              "c:\program files\Fichiers communs\LightScribe\LSRunOnce.exe"
                              .
                              Contenu du dossier 'Tâches planifiées'

                              2009-02-24 c:\windows\Tasks\MP Scheduled Scan.job
                              - c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 19:20]
                              .
                              - - - - ORPHELINS SUPPRIMES - - - -

                              BHO-{19873120-106A-4A43-95C3-A55EDF280F42} - c:\windows\system32\iifgHwvw.dll
                              BHO-{4FC762BA-4251-401A-B6B2-BCCE3531B092} - (no file)
                              BHO-{62CED47C-1064-4961-9F90-6DBD660A6F24} - (no file)
                              BHO-{70376bb7-dcd1-4cfc-a0e6-53ac5052870c} - c:\windows\system32\luyehije.dll
                              BHO-{f592709f-ff4a-4862-b659-4afabda56312} - (no file)
                              HKCU-Run-wmgoc - c:\documents and settings\administrateur\local settings\application data\wmgoc.exe
                              HKCU-Run-3C3760EC4C6B8BD2EDA4178E3F736DAC - c:\program files\A360\av360.exe
                              HKLM-Run-CPM77491acb - c:\windows\system32\fapalogo.dll

                              .
                              ------- Examen supplémentaire -------
                              .
                              uStart Page = hxxp://www.orange.fr
                              IE: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
                              IE: E&xporter vers Microsoft Excel - c:\progra~1\MI1933~1\Office12\EXCEL.EXE/3000
                              IE: { - c:\program files\Messenger\msmsgs.exe
                              Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
                              DPF: CabBuilder - hxxp://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
                              DPF: {7DA181BB-EF8D-4A7E-8C53-7BFC718EF71D} - hxxp://photos.orange.fr/resources/activex/Ephoto.cab
                              DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - hxxp://fichiers.touslesdrivers.com/fichiers/hardwaredetection/hardwaredetection_2_0_4_12.cab
                              DPF: {CAC677B6-4963-4305-9066-0BD135CD9233} - hxxp://as.photoprintit.de/ips-opdata/layout/default01/activex/IPSUploader4.cab
                              .
                              .
                              ------- Associations de fichier -------
                              .
                              .

                              **************************************************************************

                              catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                              Rootkit scan 2009-02-24 20:45:25
                              Windows 5.1.2600 Service Pack 3 NTFS

                              Recherche de processus cachés ...

                              Recherche d'éléments en démarrage automatique cachés ...

                              Recherche de fichiers cachés ...

                              Scan terminé avec succès
                              Fichiers cachés: 0

                              **************************************************************************
                              .
                              --------------------- CLES DE REGISTRE BLOQUEES ---------------------

                              [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32*]
                              "ThreadingModel"="Apartment"
                              @="c:\\WINDOWS\\system32\\OLE32.DLL"
                              "cd042efbbd7f7af1647644e76e06692b"=hex:c8,28,51,af,b0,29,a3,98,42,f2,30,67,73,
                              8c,08,7e,e2,63,26,f1,3f,c8,ff,68,ea,8b,ac,c8,84,b8,95,26,e2,63,26,f1,3f,c8,\

                              [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32*]
                              "ThreadingModel"="Apartment"
                              @="c:\\WINDOWS\\system32\\OLE32.DLL"
                              "bca643cdc5c2726b20d2ecedcc62c59b"=hex:71,3b,04,66,8b,46,0d,96,8f,5e,68,5c,18,
                              ab,d5,15,6a,9c,d6,61,af,45,84,18,15,80,bc,aa,eb,ac,e2,79,6a,9c,d6,61,af,45,\

                              [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32*]
                              "ThreadingModel"="Apartment"
                              @="c:\\WINDOWS\\system32\\OLE32.DLL"
                              "2c81e34222e8052573023a60d06dd016"=hex:25,da,ec,7e,55,20,c9,26,f1,24,0d,42,10,
                              26,dc,ad,ff,7c,85,e0,43,d4,0e,fe,2d,ae,9c,24,d8,3e,0b,7d,ff,7c,85,e0,43,d4,\

                              [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32*]
                              "ThreadingModel"="Apartment"
                              @="c:\\WINDOWS\\system32\\OLE32.DLL"
                              "2582ae41fb52324423be06337561aa48"=hex:86,8c,21,01,be,91,eb,e7,34,df,cf,c3,2f,
                              3d,4d,b3,86,8c,21,01,be,91,eb,e7,b3,99,cd,84,98,3d,34,d2,86,8c,21,01,be,91,\

                              [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32*]
                              "ThreadingModel"="Apartment"
                              @="c:\\WINDOWS\\system32\\OLE32.DLL"
                              "caaeda5fd7a9ed7697d9686d4b818472"=hex:e9,02,6c,fa,fb,1d,47,57,b3,2c,f5,0b,3c,
                              29,5c,88,f5,1d,4d,73,a8,13,5c,05,be,c9,11,cd,d0,ad,f6,71,f5,1d,4d,73,a8,13,\

                              [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32*]
                              "ThreadingModel"="Apartment"
                              @="c:\\WINDOWS\\system32\\OLE32.DLL"
                              "a4a1bcf2cc2b8bc3716b74b2b4522f5d"=hex:b0,18,ed,a7,3f,8d,37,a4,1c,c5,6a,a5,a1,
                              8e,b5,df,df,20,58,62,78,6b,cf,c8,b0,73,e3,70,d0,bd,95,8a,df,20,58,62,78,6b,\

                              [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32*]
                              "ThreadingModel"="Apartment"
                              @="c:\\WINDOWS\\system32\\OLE32.DLL"
                              "4d370831d2c43cd13623e232fed27b7b"=hex:fb,a7,78,e6,12,2f,9a,ea,9a,bd,bc,bc,20,
                              a1,2a,84,fb,a7,78,e6,12,2f,9a,ea,0d,ec,67,99,22,0f,59,f2,fb,a7,78,e6,12,2f,\

                              [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32*]
                              "ThreadingModel"="Apartment"
                              @="c:\\WINDOWS\\system32\\OLE32.DLL"
                              "1d68fe701cdea33e477eb204b76f993d"=hex:83,6c,56,8b,a0,85,96,ab,fb,d9,7d,a8,b9,
                              36,5f,02,01,3a,48,fc,e8,04,4a,f1,b9,de,99,c9,56,51,d2,9b,01,3a,48,fc,e8,04,\

                              [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32*]
                              "ThreadingModel"="Apartment"
                              @="c:\\WINDOWS\\system32\\OLE32.DLL"
                              "1fac81b91d8e3c5aa4b0a51804d844a3"=hex:51,fa,6e,91,28,9e,14,cc,71,88,57,35,ec,
                              db,02,2e,f6,0f,4e,58,98,5b,89,c9,63,c6,b5,32,95,5c,c0,b1,f6,0f,4e,58,98,5b,\

                              [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32*]
                              "ThreadingModel"="Apartment"
                              @="c:\\WINDOWS\\system32\\OLE32.DLL"
                              "f5f62a6129303efb32fbe080bb27835b"=hex:b1,cd,45,5a,a8,c4,f8,b9,d9,94,a9,83,92,
                              a9,a0,7a,3d,ce,ea,26,2d,45,aa,78,14,cc,06,e9,c4,71,3e,e6,3d,ce,ea,26,2d,45,\

                              [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32*]
                              "ThreadingModel"="Apartment"
                              @="c:\\WINDOWS\\system32\\OLE32.DLL"
                              "fd4e2e1a3940b94dceb5a6a021f2e3c6"=hex:2a,b7,cc,b5,b9,7f,41,e7,08,30,9b,ec,e2,
                              7e,92,cc,2a,b7,cc,b5,b9,7f,41,e7,87,33,f5,ee,39,66,1a,4b,2a,b7,cc,b5,b9,7f,\

                              [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32*]
                              "ThreadingModel"="Apartment"
                              @="c:\\WINDOWS\\system32\\OLE32.DLL"
                              "8a8aec57dd6508a385616fbc86791ec2"=hex:05,73,21,dd,54,d8,4a,c5,c8,0b,2a,ff,70,
                              85,59,c5,6c,43,2d,1e,aa,22,2f,9c,5c,25,c8,97,df,cb,12,0b,6c,43,2d,1e,aa,22,\
                              .
                              ------------------------ Autres processus actifs ------------------------
                              .
                              c:\program files\a-squared Free\a2service.exe
                              c:\windows\system32\FTRTSVC.exe
                              c:\program files\Java\jre6\bin\jqs.exe
                              c:\program files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
                              c:\program files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
                              c:\program files\CDBurnerXP\NMSAccessU.exe
                              c:\windows\system32\HPZipm12.exe
                              c:\program files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
                              c:\windows\system32\rundll32.exe
                              c:\progra~1\Wanadoo\TaskBarIcon.exe
                              c:\windows\system32\wbem\wmiapsrv.exe
                              .
                              **************************************************************************
                              .
                              Heure de fin: 2009-02-24 20:56:21 - La machine a redémarré
                              ComboFix-quarantined-files.txt 2009-02-24 19:56:16

                              Avant-CF: 5 716 881 408 octets libres
                              Après-CF: 5,599,006,720 octets libres

                              WindowsXP-KB310994-SP2-Pro-BootDisk-FRA.exe
                              [boot loader]
                              timeout=2
                              default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
                              [operating systems]
                              c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
                              multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professionnel" /noexecute=optin
                              /fastdetect

                              343 --- E O F --- 2009-01-23 07:49:19
                              0
                          2. Contributeur sécurité
                            • Télécharge OTMoveIt3 (de OldTimer) sur ton Bureau : http://oldtimer.geekstogo.com/OTMoveIt3.exe
                            PUIS DECONNECTE TOI d'internet
                            • Double-clique sur OTMoveIt3.exe afin de le lancer.
                            • Copie/colle le texte suivant dans le cadre « Paste Instructions for Items to be Moved » et clique sur Moveit :

                            :processes
                            explorer.exe

                            :files
                            c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
                            c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat

                            :commands
                            [purity]
                            [emptytemp]
                            [start explorer]
                            [reboot]

                            • Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer. Accepte en cliquant sur YES.

                            • Poste le rapport situé dans ce dossier : C:\_OTMoveIt\MovedFiles
                            Le nom du rapport correspond au moment de sa création : date_heure.log

                            puis

                            * Télécharge et enregistre le fichier d installation sur ton bureau :

                            http://sd-1.archive-host.com/membres/up/16506160323759868/AD-R.exe

                            * Double clique sur le programme d'installation , et installe le dans son emplacement par défaut. ( le bureau )

                            * Ouvre le dossier Ad-remover présent sur ton bureau, et double clique sur Ad-remover.bat.

                            * Au menu principal choisi l'option "A"

                            * Poste le rapport qui apparait à la fin.

                            ( le rapport est sauvegardé aussi sous C:\Ad-report.log )

                            (CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

                            Note :

                            Process.exe est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
                            Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
                            Mis
                            entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels
                            de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces
                            antivirus.
                            0
                            1. je fais une pose repas (15 minutes maxi) et je fais tout ça
                              a tout à l'heure
                              merci
                              0
                          • 1
                          • 2
                          • 3
                          • 4