Win32 skimorph [cryp]

Bonjour,
Mon Avast à détécté ce virus "Win32:SkiMorph [Cryp]"
Pourriez vous m'aider à l'enlever ? J'ai deja fait un rapport avec Navilog1:

Search Navipromo version 3.7.5 commencé le 09/03/2009 à 19:06:24,63

!!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
!!! Postez ce rapport sur le forum pour le faire analyser !!!
!!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

Outil exécuté depuis C:\Program Files\navilog1

Mise à jour le 26.02.2009 à 18h00 par IL-MAFIOSO

Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6001 ) Service Pack 1
X86-based PC ( Multiprocessor Free : Intel(R) Core(TM)2 Duo CPU T5450 @ 1.66GHz )
BIOS : Ver 1.00PARTTBL
USER : Pierre Marie ( Administrator )
BOOT : Fail-safe with network boot

Antivirus : Norton Internet Security 2007 (Activated)
Firewall : Norton Internet Security 2007 (Activated)

C:\ (Local Disk) - NTFS - Total:92 Go (Free:23 Go)
E:\ (Local Disk) - NTFS - Total:92 Go (Free:91 Go)
F:\ (CD or DVD)

Recherche executé en mode sans échec

*** Recherche Programmes installés ***

*** Recherche dossiers dans "C:\Windows" ***

*** Recherche dossiers dans "C:\Program Files" ***

*** Recherche dossiers dans "c:\progra~2\micros~1\windows\startm~1\programs" ***

*** Recherche dossiers dans "c:\progra~2\micros~1\windows\startm~1" ***

*** Recherche dossiers dans "C:\ProgramData" ***

*** Recherche dossiers dans "c:\users\pierre~1\appdata\roaming\micros~1\windows\startm~1\programs" ***

*** Recherche dossiers dans "C:\Users\Pierre Marie\AppData\Local\virtualstore\Program Files" ***

*** Recherche dossiers dans "C:\Users\Pierre Marie\AppData\Local" ***

*** Recherche dossiers dans "C:\Users\Pierre Marie\AppData\Roaming" ***

*** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
pour + d'infos : http://www.gmer.net

*** Recherche avec GenericNaviSearch ***
!!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
!!! A vérifier impérativement avant toute suppression manuelle !!!

* Recherche dans "C:\Windows\system32" *

* Recherche dans "C:\Users\Pierre Marie\AppData\Local\Microsoft" *

* Recherche dans "C:\Users\Pierre Marie\AppData\Local" *

*** Recherche fichiers ***

*** Recherche clés spécifiques dans le Registre ***
!! Les clés trouvées ne sont pas forcément infectées !!

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"yiikg"="\"c:\\users\\pierre marie\\appdata\\local\\yiikg.exe\" yiikg"

*** Module de Recherche complémentaire ***
(Recherche fichiers spécifiques)

1)Recherche nouveaux fichiers Instant Access :

2)Recherche Heuristique :

* Dans "C:\Windows\system32" :

* Dans "C:\Users\Pierre Marie\AppData\Local\Microsoft" :

* Dans "C:\Users\Pierre Marie\AppData\Local" :

yiikg.exe trouvé !
yiikg.dat trouvé !
yiikg_nav.dat trouvé !
yiikg_navps.dat trouvé !

3)Recherche Certificats :

Certificat Egroup absent !
Certificat Electronic-Group absent !
Certificat Montorgueil absent !
Certificat OOO-Favorit absent !
Certificat Sunny-Day-Design-Ltd absent !

4)Recherche autres dossiers et fichiers connus :

*** Analyse terminée le 09/03/2009 à 19:19:03,07 ***
Configuration: Windows Vista
Internet Explorer 7.0

35 réponses

Résumé de la discussion

Win32:SkiMorph [Cryp] est détecté par Avast et complique la désinfection sur Windows Vista, avec un rapport Navilog1 et des avertissements sur la vérification manuelle des fichiers avant toute suppression. Plusieurs méthodes sont évoquées, dont une désinfection automatique via Navilog1, des analyses supplémentaires avec des outils comme Catchme, GNS et FindyKill, et des scans en ligne sur Bitdefender pour compléter le diagnostic. Les réponses recommandent ensuite des étapes concrètes: redémarrer en mode sans échec, relancer des outils multiples, télécharger des utilitaires et obtenir l'avis d'un spécialiste avant toute suppression. En cas d'incompatibilité ou d'absence de redémarrage, la discussion évoque des alternatives en ligne et la vérification des éléments détectés comme yiikg.exe et yiikg.dat, avec l'idée d'obtenir une confirmation avant toute suppression.

Bobot (l’IA à votre service)
  1. salut,

    Passe l'option 2 de navilog puis poste moi le rapport.
    puis,

    I)Telecharger random's system information tool: (RSIT)

    http://images.malwareremoval.com/random/RSIT.exe

    1)Double clique sur l’icône RSIT.exe
    2)Clique sur continue.
    3)L’analyse terminée, deux fichiers s’ouvriront, poste moi les 2 rapports stp.
    Si les 2 fichiers ne s’ouvrent pas va dans C:\rsit , tu y trouvera les 2 fichiers info.txt et log.txt
    1. Contributeur sécurité
      désinfection automatique

      * Relancez Navilog1 comme expliqué lors de la recherche.
      * Cette fois-ci tapez 2 pour exécuter une désinfection automatique. (le bureau disparaît, c'est normal)
      * Le PC va redémarrer.
      * Après redémarrage, un rapport va être généré dans le bloc note.
      * Vérifiez que tout a bien été supprimé car il se pourrait que certains fichiers ne soient pas supprimés lors de la désinfection automatique...

      Ensuite ceci :

      Etape 1/ Télécharge :

      - FindyKill http://sd-1.archive-host.com/membres/up/116615172019703188/FindyKill.exe sur le Bureau.

      Note importante : l'infection bagle s'installant au moyen d'un crack/keygen, tu dois IMPERATIVEMENT supprimer ce type de fichier.

      # Etape 2/

      Lance l'installation avec les paramètres par défaut
      - Double-clique sur le raccourci FindyKill sur le Bureau (sous Vista : clic droit sur le raccourci --> Exécuter en temps qu'Administrateur)
      - Au menu principal, sélectionne l'option 1 (Recherche)
      - Le rapport est sauvegardé à la racine du disque dur (C:\FindyKill.txt )
      Avant de faire quoi que ce soit d'autre, il est fortement recommandé de poster le rapport sur le forum pour avoir l'avis d'un spécialiste.Après confirmation par un intervenant qualifié du forum, passe au nettoyage

      Si besoin: Tutoriel

      Pour ceux qui ont vista, ne pas oublier de désactiver Le contrôle des comptes utilisateurs

      1. ok voila le rapport 2 de navilog:

        Clean Navipromo version 3.7.5 commencé le 09/03/2009 à 20:02:13,88

        Outil exécuté depuis C:\Program Files\navilog1

        Mise à jour le 26.02.2009 à 18h00 par IL-MAFIOSO

        Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6001 ) Service Pack 1
        X86-based PC ( Multiprocessor Free : Intel(R) Core(TM)2 Duo CPU T5450 @ 1.66GHz )
        BIOS : Ver 1.00PARTTBL
        USER : Pierre Marie ( Administrator )
        BOOT : Fail-safe with network boot

        Antivirus : Norton Internet Security 2007 (Activated)
        Firewall : Norton Internet Security 2007 (Activated)

        C:\ (Local Disk) - NTFS - Total:92 Go (Free:23 Go)
        E:\ (Local Disk) - NTFS - Total:92 Go (Free:91 Go)
        F:\ (CD or DVD)

        Mode suppression automatique
        avec prise en charge résultats Catchme et GNS

        Nettoyage executé en mode sans échec

        *** fsbl1.txt non trouvé ***
        (Assurez-vous que Catchme n'avait rien trouvé lors de la recherche)

        *** Suppression avec sauvegardes résultats GenericNaviSearch ***

        * Suppression dans "C:\Windows\System32" *

        * Suppression dans "C:\Users\Pierre Marie\AppData\Local\Microsoft" *

        * Suppression dans "C:\Users\Pierre Marie\AppData\Local" *

        *** Suppression dossiers dans "C:\Windows" ***

        *** Suppression dossiers dans "C:\Program Files" ***

        *** Suppression dossiers dans "c:\progra~2\micros~1\windows\startm~1\programs" ***

        *** Suppression dossiers dans "c:\progra~2\micros~1\windows\startm~1" ***

        *** Suppression dossiers dans "C:\ProgramData" ***

        *** Suppression dossiers dans c:\users\pierre~1\appdata\roaming\micros~1\windows\startm~1\programs ***

        *** Suppression dossiers dans "C:\Users\Pierre Marie\AppData\Local\virtualstore\Program Files" ***

        *** Suppression dossiers dans "C:\Users\Pierre Marie\AppData\Local" ***

        *** Suppression dossiers dans "C:\Users\Pierre Marie\AppData\Roaming" ***

        *** Suppression fichiers ***

        *** Suppression fichiers temporaires ***

        Nettoyage contenu C:\Windows\Temp effectué !
        Nettoyage contenu C:\Users\PIERRE~1\AppData\Local\Temp effectué !

        *** Traitement Recherche complémentaire ***
        (Recherche fichiers spécifiques)

        1)Suppression avec sauvegardes nouveaux fichiers Instant Access :

        2)Recherche, création sauvegardes et suppression Heuristique :

        * Dans "C:\Windows\system32" *

        * Dans "C:\Users\Pierre Marie\AppData\Local\Microsoft" *

        * Dans "C:\Users\Pierre Marie\AppData\Local" *

        yiikg.exe trouvé !
        Copie yiikg.exe réalisée avec succès !
        yiikg.exe supprimé !

        yiikg.dat trouvé !
        Copie yiikg.dat réalisée avec succès !
        yiikg.dat supprimé !

        yiikg_nav.dat trouvé !
        Copie yiikg_nav.dat réalisée avec succès !
        yiikg_nav.dat supprimé !

        yiikg_navps.dat trouvé !
        Copie yiikg_navps.dat réalisée avec succès !
        yiikg_navps.dat supprimé !

        *** Sauvegarde du Registre vers dossier Safebackup ***

        sauvegarde du Registre réalisée avec succès !

        *** Nettoyage Registre ***

        Nettoyage Registre Ok

        *** Certificats ***

        Certificat Egroup absent !
        Certificat Electronic-Group absent !
        Certificat Montorgueil absent !
        Certificat OOO-Favorit absent !
        Certificat Sunny-Day-Design-Ltdt absent !

        *** Recherche autres dossiers et fichiers connus ***

        *** Nettoyage terminé le 09/03/2009 à 20:03:37,20 ***
        1. le blok not log

          Logfile of random's system information tool 1.05 (written by random/random)
          Run by Pierre Marie at 2009-03-09 20:00:47
          Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 1
          System drive C: has 24 GB (25%) free of 95 GB
          Total RAM: 2046 MB (76% free)

          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 20:00:55, on 09/03/2009
          Platform: Windows Vista SP1 (WinNT 6.00.1905)
          MSIE: Internet Explorer v7.00 (7.00.6001.18000)
          Boot mode: Safe mode with network support

          Running processes:
          C:\Windows\Explorer.EXE
          C:\Program Files\Windows Media Player\wmpnscfg.exe
          C:\Windows\notepad.exe
          C:\Program Files\Internet Explorer\iexplore.exe
          C:\Program Files\Internet Explorer\iexplore.exe
          C:\Users\Pierre Marie\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CB3FUWCA\RSIT[1].exe
          C:\Program Files\trend micro\Pierre Marie.exe

          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://actus.sfr.fr
          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://actus.sfr.fr
          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://y.lo.st#home
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://actus.sfr.fr
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = https://actus.sfr.fr
          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
          R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
          O1 - Hosts: ::1 localhost
          O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
          O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll
          O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
          O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
          O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
          O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
          O2 - BHO: EoBHO - {C7B76B90-3455-4AE6-A752-EAC4D19689E5} - C:\Program Files\EoRezo\EoAdv\EoRezoBHO.dll
          O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
          O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
          O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll
          O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
          O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
          O4 - HKLM\..\Run: [KeNotify] C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
          O4 - HKLM\..\Run: [SVPWUTIL] C:\Program Files\TOSHIBA\Utilities\SVPWUTIL.exe SVPwUTIL
          O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
          O4 - HKLM\..\Run: [topi] C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe -startup
          O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
          O4 - HKLM\..\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
          O4 - HKLM\..\Run: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe
          O4 - HKLM\..\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
          O4 - HKLM\..\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
          O4 - HKLM\..\Run: [HWSetup] \HWSetup.exe hwSetUP
          O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
          O4 - HKLM\..\Run: [Desktop SMS] C:\Program Files\IDM\Desktop SMS\DesktopSMS.exe /auto
          O4 - HKLM\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
          O4 - HKLM\..\Run: [Camera Assistant Software] "C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe"
          O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
          O4 - HKLM\..\Run: [Toshiba Registration] C:\Program Files\Toshiba\Registration\ToshibaRegistration.exe
          O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
          O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
          O4 - HKLM\..\Run: [Skytel] Skytel.exe
          O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
          O4 - HKLM\..\Run: [EoEngine] "C:\Program Files\EoRezo\EoEngine.exe"
          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
          O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
          O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
          O4 - HKLM\..\RunOnce: [SoftwareHelper] C:\Users\Pierre Marie\AppData\Roaming\eoRezo\SoftwareUpdate\SoftwareUpdateHP.exe -runonce
          O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
          O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
          O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
          O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
          O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
          O4 - HKCU\..\Run: [yiikg] "c:\users\pierre marie\appdata\local\yiikg.exe" yiikg
          O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
          O4 - Startup: OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
          O9 - Extra button: eBay - {C08CAF1D-C0A3-40D5-9970-06D067EAC017} - http://www.webtip.ch/cgi-bin/toshiba/tracker_url.pl?FR (file missing)
          O13 - Gopher Prefix:
          O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
          O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
          O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
          O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
          O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
          O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
          O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
          O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
          O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
          O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
          O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
          O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
          O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
          O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
          O23 - Service: Service Google Update (gupdate1c99ce365ca2e60) (gupdate1c99ce365ca2e60) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
          O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
          O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
          O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
          O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
          O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
          O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
          O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
          O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
          O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
          O23 - Service: TOSHIBA Navi Support Service (TNaviSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe
          O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe
          O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
          O23 - Service: TOSHIBA Bluetooth Service - Unknown owner - c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe (file missing)
          O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
        2. @pimset le bloc note info:

          info.txt logfile of random's system information tool 1.05 2009-03-09 20:00:57

          ======Uninstall list======

          -->"C:\Program Files\InstallShield Installation Information\{A644254B-92F6-4970-8635-AB0775371E72}\setup.exe" --u:{A644254B-92F6-4970-8635-AB0775371E72}
          -->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{622E6F16-0904-49B6-BBE1-4CC836314CCF}\setup.exe" -l0x40c
          -->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{697AFC77-F318-4CD4-BF16-F50F4C1072DA}\setup.exe" -l0x40c
          12Ghosts Popup-Killer-->C:\Program Files\12Ghosts\uninstall.exe
          Adobe Flash Player 10 ActiveX-->C:\Windows\system32\Macromed\Flash\uninstall_activeX.exe
          Adobe Flash Player 10 Plugin-->C:\Windows\system32\Macromed\Flash\uninstall_plugin.exe
          Adobe Reader 7.0.9 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A70900000002}
          AppCore-->MsiExec.exe /I{EFB5B3B5-A280-4E25-BE1C-634EEFE32C1B}
          Apple Mobile Device Support-->MsiExec.exe /I{EC4455AB-F155-4CC1-A4C5-88F3777F9886}
          Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
          Archiveur WinRAR-->C:\Program Files\WinRAR\uninstall.exe
          Assistant de connexion Windows Live-->MsiExec.exe /I{DCE8CD14-FBF5-4464-B9A4-E18E473546C7}
          AV-->MsiExec.exe /I{F4DB525F-A986-4249-B98B-42A8066251CA}
          avast! Antivirus-->C:\Program Files\Alwil Software\Avast4\aswRunDll.exe "C:\Program Files\Alwil Software\Avast4\Setup\setiface.dll",RunSetup
          Bluetooth Stack for Windows by Toshiba-->MsiExec.exe /X{CEBB6BFB-D708-4F99-A633-BC2600E01EF6}
          Bonjour-->MsiExec.exe /I{07287123-B8AC-41CE-8346-3D777245C35B}
          Camera Assistant Software for Toshiba-->C:\Program Files\InstallShield Installation Information\{37C866E4-AA67-4725-9E95-A39968DD7960}\setup.exe -runfromtemp -l0x040c
          Catalyst Control Center - Branding-->MsiExec.exe /I{22543949-70E8-45D0-A938-F38143EB8BF8}
          ccCommon-->MsiExec.exe /I{3CCAD2EF-CFF2-4637-82AA-AABF370282D3}
          Choice Guard-->MsiExec.exe /I{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}
          Codeur Windows Media Série 9-->msiexec.exe /I {E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}
          Codeur Windows Media Série 9-->MsiExec.exe /I{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}
          Desktop SMS-->MsiExec.exe /I{5980B928-1C95-4B3E-957B-B02D8147FF9E}
          DivX Codec-->C:\Program Files\DivX\DivXCodecUninstall.exe /CODEC
          DivX Player-->C:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYER
          DivX Web Player-->C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
          DVD MovieFactory for TOSHIBA-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F214EAA4-A069-4BAF-9DA4-4DB8BEEDE485}\setup.exe" -l0x40c
          Emdedded IR Driver-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\1050\INTEL3~1\IDriver.exe /M{A6D4234C-CB02-4048-AC3E-AD09404FA35A}
          eoEngine 9.1-->"C:\Program Files\EoRezo\unins000.exe"
          Google Toolbar for Internet Explorer-->"C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_0531C63A913CC9D1.exe" /uninstall
          Google Update Helper-->MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
          Google Earth-->MsiExec.exe /X{548EAC70-EE00-11DD-908C-005056806466}
          HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
          Installation Windows Live-->C:\Program Files\Windows Live\Installer\wlarp.exe
          Installation Windows Live-->MsiExec.exe /I{7370DF47-B4F9-4279-BFC3-3F09919F720D}
          Intel Matrix Storage Manager-->C:\Windows\system32\imsmudlg.exe -uninstall
          iPod for Windows 2006-01-10-->C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{3D047C15-C859-45F7-81CE-F2681778069B} /l1036
          iTunes-->MsiExec.exe /I{F5C63795-2708-4D15-BF18-5ABBFF7DFFC8}
          Java(TM) 6 Update 11-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216011FF}
          Java(TM) 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
          Java(TM) SE Runtime Environment 6-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160000}
          Junk Mail filter update-->MsiExec.exe /I{4DE3E3D9-AE81-45DE-9195-3015F7B1DBF3}
          LimeWire 4.18.8-->"C:\Program Files\LimeWire\uninstall.exe"
          LiveUpdate 3.2 (Symantec Corporation)-->"C:\Program Files\Symantec\LiveUpdate\LSETUP.EXE" /U
          LiveUpdate Notice (Symantec Corporation)-->MsiExec.exe /X{DBA4DB9D-EE51-4944-A419-98AB1F1249C8}
          Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{A49F249F-0C91-497F-86DF-B2585E8E76B7}
          MobileMe Control Panel-->MsiExec.exe /I{A14C24F6-615B-415E-84B0-610FDAD19B68}
          Mozilla Firefox (3.0.7)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
          MSRedist-->MsiExec.exe /I{B7C61755-DB48-4003-948F-3D34DB8EAF69}
          MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
          MSXML 4.0 SP2 (KB927978)-->MsiExec.exe /I{37477865-A3F1-4772-AD43-AAFC6BCFF99F}
          MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
          myphotobook 3.1-->C:\Program Files\myphotobook\uninst.exe
          Navilog1 3.7.5-->"C:\Program Files\Navilog1\unins000.exe"
          Neuf - Kit de connexion-->C:\Program Files\Neuf\Kit\uninstall.exe
          Norton AntiVirus-->MsiExec.exe /X{830D8CBD-C668-49e2-A969-C2C2106332E0}
          Norton Confidential Browser Component-->MsiExec.exe /I{4843B611-8FCB-4428-8C23-31D0A5EAE164}
          Norton Confidential Web Protection Component-->MsiExec.exe /I{D353CC51-430D-4C6F-9B7E-52003DA1E05A}
          Norton Internet Security (Symantec Corporation)-->"C:\Program Files\Common Files\Symantec Shared\SymSetup\{5AA2CD16-706F-41f3-87C5-2B5A031F2B3B}_10_2_0_30\{5AA2CD16-706F-41f3-87C5-2B5A031F2B3B}.exe" /X
          Norton Internet Security-->MsiExec.exe /I{3672B097-EA69-4bfe-B92F-29AE6D9D2B34}
          Norton Internet Security-->MsiExec.exe /I{48185814-A224-447A-81DA-71BD20580E1B}
          Norton Internet Security-->MsiExec.exe /I{5AA2CD16-706F-41f3-87C5-2B5A031F2B3B}
          Norton Internet Security-->MsiExec.exe /I{E3EFA461-EB83-4C3B-9C47-2C1D58A01555}
          Norton Internet Security-->MsiExec.exe /I{E5EE9939-259F-4DE2-8023-5C49E16A4F43}
          Norton Protection Center-->MsiExec.exe /I{9A129ABC-A53A-4209-A21E-D5DEDFB7CCA8}
          OpenOffice.org 3.0-->MsiExec.exe /I{6860B340-530D-46B3-91F8-1AE1F70F7C33}
          Outil de mise à jour Google-->"C:\Program Files\Google\Google Updater\GoogleUpdater.exe" -uninstall
          Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
          ParetoLogic DriverCure-->C:\Program Files\ParetoLogic\DriverCure\uninstall.exe
          PMM Video Encoder v 1.0-->C:\Users\Pierre Marie\Desktop\ISO\VIDEO\Uninstal.exe
          QuickTime-->MsiExec.exe /I{216AB108-2AE1-4130-B3D5-20B2C4C80F8F}
          Realtek 8169 PCI, 8168 and 8101E PCIe Ethernet Network Card Driver for Windows Vista-->C:\Program Files\InstallShield Installation Information\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}\setup.exe -runfromtemp -l0x040c -removeonly
          Realtek High Definition Audio Driver-->RtlUpd.exe -r -m
          Réducteur de bruit lect. CD/DVD-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9FE35071-CAB2-4E79-93E7-BFC6A2DC5C5D}\setup.exe" -l0x40c
          Safari-->MsiExec.exe /I{D90AFDE3-3E67-407A-ACA8-F0BAAD012F08}
          SecondLife (remove only)-->"C:\Program Files\SecondLife\uninst.exe" /P="SecondLife"
          Security Update for Windows Media Encoder (KB954156)-->msiexec.exe /I {E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E} MSIPATCHREMOVE={E836F1B7-43FB-46B0-A0D9-E4D2A5951659} /qb
          SoftwareUpdate 1.0-->"C:\Users\Pierre Marie\AppData\Roaming\eoRezo\SoftwareUpdate\unins000.exe"
          SPBBC 32bit-->MsiExec.exe /I{77772678-817F-4401-9301-ED1D01A8DA56}
          Synaptics Pointing Device Driver-->rundll32.exe "C:\Program Files\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall
          Texas Instruments PCIxx21/x515/xx12 drivers.-->C:\Program Files\InstallShield Installation Information\{DB780B85-B4B5-4864-A49C-9B706B169C93}\setup.exe -runfromtemp -l0x040c
          TOSHIBA Assist-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{12B3A009-A080-4619-9A2A-C6DB151D8D67}\setup.exe" -l0x40c
          TOSHIBA ConfigFree-->C:\Program Files\InstallShield Installation Information\{78C6A78A-8B03-48C8-A47C-78BA1FCA2307}\setup.exe -runfromtemp -l0x040c uninstall -removeonly
          TOSHIBA Disc Creator-->MsiExec.exe /X{5DA0E02F-970B-424B-BF41-513A5018E4C0}
          TOSHIBA DVD PLAYER-->C:\Program Files\InstallShield Installation Information\{6C5F3BDC-0A1B-4436-A696-5939629D5C31}\setup.exe -runfromtemp -l0x040c -ADDREMOVE -removeonly
          TOSHIBA Extended Tiles for Windows Mobility Center-->C:\Program Files\InstallShield Installation Information\{617C36FD-0CBE-4600-84B2-441CEB12FADF}\setup.exe -runfromtemp -l0x040c
          TOSHIBA Flash Cards Support Utility-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{620BBA5E-F848-4D56-8BDA-584E44584C5E}
          TOSHIBA Hardware Setup-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{5279374D-87FE-4879-9385-F17278EBB9D3} /l1036
          TOSHIBA Mot de passe responsable-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{51B4E156-14A5-4904-9AE4-B1AA2A0E46BE} /l1036
          Toshiba Online Product Information-->C:\Program Files\InstallShield Installation Information\{2290A680-4083-410A-ADCC-7092C67FC052}\setup.exe -runfromtemp -l0x040c -removeonly
          TOSHIBA SD Memory Utilities-->MsiExec.exe /X{EBFF48F5-3CFA-436F-8FD5-94FB01D3A0A7}
          TOSHIBA Software Modem-->Tosmreg -U
          TOSHIBA Value Added Package-->C:\Program Files\InstallShield Installation Information\{FEDD27A0-B306-45EF-BF58-B527406B42C8}\setup.exe -runfromtemp -l0x040c
          VC80CRTRedist - 8.0.50727.762-->MsiExec.exe /I{767CC44C-9BBC-438D-BAD3-FD4595DD148B}
          WebPopupKiller 1.0-->"C:\Program Files\WebPopupKiller\unins000.exe"
          Windows Live Call-->MsiExec.exe /I{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}
          Windows Live Communications Platform-->MsiExec.exe /I{3B4E636E-9D65-4D67-BA61-189800823F52}
          Windows Live Mail-->MsiExec.exe /I{63DC2DA0-2A6C-4C38-9249-B75395458657}
          Windows Live Messenger-->MsiExec.exe /X{059C042E-796A-4ACC-A81A-ECC2010BB78C}

          ======Security center information======

          AV: Norton Internet Security
          FW: Norton Internet Security
          AS: Windows Defender (disabled)
          AS: Norton Internet Security

          System event log

          Computer Name: PC-de-PierreMar
          Event Code: 7026
          Message: Le pilote de démarrage système ou d'amorçage suivant n'a pas pu se charger :
          aswSP
          eeCtrl
          SPBBCDrv
          spldr
          SRTSPX
          SYMTDI
          Wanarpv6
          Record Number: 46229
          Source Name: Service Control Manager
          Time Written: 20090309174454.000000-000
          Event Type: Erreur
          User:

          Computer Name: PC-de-PierreMar
          Event Code: 7036
          Message: Le service Connexions réseau est entré dans l'état : en cours d'exécution.
          Record Number: 46230
          Source Name: Service Control Manager
          Time Written: 20090309174454.000000-000
          Event Type: Information
          User:

          Computer Name: PC-de-PierreMar
          Event Code: 7036
          Message: Le service Services de base de module de plateforme sécurisée est entré dans l'état : arrêté.
          Record Number: 46231
          Source Name: Service Control Manager
          Time Written: 20090309174549.000000-000
          Event Type: Information
          User:

          Computer Name: PC-de-PierreMar
          Event Code: 537
          Message: Aucun périphérique de sécurité du module de plateforme sécurisée compatible trouvé sur cet ordinateur. Impossible de démarrer les services de base de module de plateforme sécurisée.
          Record Number: 46232
          Source Name: Microsoft-Windows-TBS
          Time Written: 20090309174549.236634-000
          Event Type: Information
          User: AUTORITE NT\SERVICE LOCAL

          Computer Name: PC-de-PierreMar
          Event Code: 4226
          Message: TCP/IP a atteint la limite de sécurité imposée sur le nombre de tentatives de connexion TCP simultanées.
          Record Number: 46233
          Source Name: Tcpip
          Time Written: 20090309175642.502234-000
          Event Type: Avertissement
          User:

          Application event log

          Computer Name: PC-de-PierreMar
          Event Code: 6000
          Message: L’abonné aux notifications Winlogon <GPClient> n’était pas disponible pour traiter un événement de notification.
          Record Number: 9280
          Source Name: Microsoft-Windows-Winlogon
          Time Written: 20090309174417.000000-000
          Event Type: Avertissement
          User:

          Computer Name: PC-de-PierreMar
          Event Code: 6000
          Message: L’abonné aux notifications Winlogon <Sens> n’était pas disponible pour traiter un événement de notification.
          Record Number: 9281
          Source Name: Microsoft-Windows-Winlogon
          Time Written: 20090309174417.000000-000
          Event Type: Information
          User:

          Computer Name: PC-de-PierreMar
          Event Code: 4609
          Message: Le système d'événements de COM+ a détecté un code de renvoi erroné lors de son traitement interne. Le HRESULT est 8007043c à partir de la ligne 45 de d:\vistasp1_gdr\com\complus\src\events\tier1\eventsystemobj.cpp. Contactez les services de support technique Microsoft pour signaler cette erreur.
          Record Number: 9282
          Source Name: Microsoft-Windows-EventSystem
          Time Written: 20090309174426.000000-000
          Event Type: Erreur
          User:

          Computer Name: PC-de-PierreMar
          Event Code: 8211
          Message: Erreur du service de cliché instantané de volumes : le rédacteur de nom WMI Writer et d'identificateur {a6ad56c2-b509-4e6c-bb19-49d8f43532f0} a tenté de s'abonner en mode sans échec.

          Opération :
          Rédacteur en cours d’initialisation

          Contexte :
          ID de classe du rédacteur: {a6ad56c2-b509-4e6c-bb19-49d8f43532f0}
          Nom du rédacteur: WMI Writer
          Record Number: 9283
          Source Name: VSS
          Time Written: 20090309174448.000000-000
          Event Type: Information
          User:

          Computer Name: PC-de-PierreMar
          Event Code: 5617
          Message: Sous-systèmes WMI (Windows Management Instrumentation) correctement initialisés
          Record Number: 9284
          Source Name: Microsoft-Windows-WMI
          Time Written: 20090309174451.000000-000
          Event Type: Information
          User:

          Security event log

          Computer Name: PC-de-PierreMar
          Event Code: 5038
          Message: L’intégrité du code a déterminé que le hachage de l’image d’un fichier n’est pas valide. Le fichier peut être endommagé en raison d’une modification non autorisée ou le hachage non valide peut indiquer une erreur d’unité de disque potentielle.

          Nom du fichier : \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys
          Record Number: 10888
          Source Name: Microsoft-Windows-Security-Auditing
          Time Written: 20090309190055.265434-000
          Event Type: Échec de l'audit
          User:

          Computer Name: PC-de-PierreMar
          Event Code: 5038
          Message: L’intégrité du code a déterminé que le hachage de l’image d’un fichier n’est pas valide. Le fichier peut être endommagé en raison d’une modification non autorisée ou le hachage non valide peut indiquer une erreur d’unité de disque potentielle.

          Nom du fichier : \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys
          Record Number: 10889
          Source Name: Microsoft-Windows-Security-Auditing
          Time Written: 20090309190055.281034-000
          Event Type: Échec de l'audit
          User:

          Computer Name: PC-de-PierreMar
          Event Code: 5038
          Message: L’intégrité du code a déterminé que le hachage de l’image d’un fichier n’est pas valide. Le fichier peut être endommagé en raison d’une modification non autorisée ou le hachage non valide peut indiquer une erreur d’unité de disque potentielle.

          Nom du fichier : \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys
          Record Number: 10890
          Source Name: Microsoft-Windows-Security-Auditing
          Time Written: 20090309190055.312234-000
          Event Type: Échec de l'audit
          User:

          Computer Name: PC-de-PierreMar
          Event Code: 5038
          Message: L’intégrité du code a déterminé que le hachage de l’image d’un fichier n’est pas valide. Le fichier peut être endommagé en raison d’une modification non autorisée ou le hachage non valide peut indiquer une erreur d’unité de disque potentielle.

          Nom du fichier : \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys
          Record Number: 10891
          Source Name: Microsoft-Windows-Security-Auditing
          Time Written: 20090309190055.327834-000
          Event Type: Échec de l'audit
          User:

          Computer Name: PC-de-PierreMar
          Event Code: 5038
          Message: L’intégrité du code a déterminé que le hachage de l’image d’un fichier n’est pas valide. Le fichier peut être endommagé en raison d’une modification non autorisée ou le hachage non valide peut indiquer une erreur d’unité de disque potentielle.

          Nom du fichier : \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys
          Record Number: 10892
          Source Name: Microsoft-Windows-Security-Auditing
          Time Written: 20090309190055.343434-000
          Event Type: Échec de l'audit
          User:

          ======Environment variables======

          "ComSpec"=%SystemRoot%\system32\cmd.exe
          "FP_NO_HOST_CHECK"=NO
          "OS"=Windows_NT
          "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\PROGRA~1\COMMON~1\ULEADS~1\MPEG;C:\Program Files\ATI Technologies\ATI.ACE\Core-Static;C:\Program Files\QuickTime\QTSystem\
          "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
          "PROCESSOR_ARCHITECTURE"=x86
          "TEMP"=%SystemRoot%\TEMP
          "TMP"=%SystemRoot%\TEMP
          "USERNAME"=SYSTEM
          "windir"=%SystemRoot%
          "PROCESSOR_LEVEL"=6
          "PROCESSOR_IDENTIFIER"=x86 Family 6 Model 15 Stepping 13, GenuineIntel
          "PROCESSOR_REVISION"=0f0d
          "NUMBER_OF_PROCESSORS"=2
          "CLASSPATH"=.;C:\Program Files\Java\jre6\lib\ext\QTJava.zip
          "QTJAVA"=C:\Program Files\Java\jre6\lib\ext\QTJava.zip
          "SAFEBOOT_OPTION"=NETWORK

          -----------------EOF-----------------
        3. @pimset le bloc note info:

          info.txt logfile of random's system information tool 1.05 2009-03-09 20:00:57

          ======Uninstall list======

          -->"C:\Program Files\InstallShield Installation Information\{A644254B-92F6-4970-8635-AB0775371E72}\setup.exe" --u:{A644254B-92F6-4970-8635-AB0775371E72}
          -->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{622E6F16-0904-49B6-BBE1-4CC836314CCF}\setup.exe" -l0x40c
          -->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{697AFC77-F318-4CD4-BF16-F50F4C1072DA}\setup.exe" -l0x40c
          12Ghosts Popup-Killer-->C:\Program Files\12Ghosts\uninstall.exe
          Adobe Flash Player 10 ActiveX-->C:\Windows\system32\Macromed\Flash\uninstall_activeX.exe
          Adobe Flash Player 10 Plugin-->C:\Windows\system32\Macromed\Flash\uninstall_plugin.exe
          Adobe Reader 7.0.9 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A70900000002}
          AppCore-->MsiExec.exe /I{EFB5B3B5-A280-4E25-BE1C-634EEFE32C1B}
          Apple Mobile Device Support-->MsiExec.exe /I{EC4455AB-F155-4CC1-A4C5-88F3777F9886}
          Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
          Archiveur WinRAR-->C:\Program Files\WinRAR\uninstall.exe
          Assistant de connexion Windows Live-->MsiExec.exe /I{DCE8CD14-FBF5-4464-B9A4-E18E473546C7}
          AV-->MsiExec.exe /I{F4DB525F-A986-4249-B98B-42A8066251CA}
          avast! Antivirus-->C:\Program Files\Alwil Software\Avast4\aswRunDll.exe "C:\Program Files\Alwil Software\Avast4\Setup\setiface.dll",RunSetup
          Bluetooth Stack for Windows by Toshiba-->MsiExec.exe /X{CEBB6BFB-D708-4F99-A633-BC2600E01EF6}
          Bonjour-->MsiExec.exe /I{07287123-B8AC-41CE-8346-3D777245C35B}
          Camera Assistant Software for Toshiba-->C:\Program Files\InstallShield Installation Information\{37C866E4-AA67-4725-9E95-A39968DD7960}\setup.exe -runfromtemp -l0x040c
          Catalyst Control Center - Branding-->MsiExec.exe /I{22543949-70E8-45D0-A938-F38143EB8BF8}
          ccCommon-->MsiExec.exe /I{3CCAD2EF-CFF2-4637-82AA-AABF370282D3}
          Choice Guard-->MsiExec.exe /I{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}
          Codeur Windows Media Série 9-->msiexec.exe /I {E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}
          Codeur Windows Media Série 9-->MsiExec.exe /I{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}
          Desktop SMS-->MsiExec.exe /I{5980B928-1C95-4B3E-957B-B02D8147FF9E}
          DivX Codec-->C:\Program Files\DivX\DivXCodecUninstall.exe /CODEC
          DivX Player-->C:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYER
          DivX Web Player-->C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
          DVD MovieFactory for TOSHIBA-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F214EAA4-A069-4BAF-9DA4-4DB8BEEDE485}\setup.exe" -l0x40c
          Emdedded IR Driver-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\1050\INTEL3~1\IDriver.exe /M{A6D4234C-CB02-4048-AC3E-AD09404FA35A}
          eoEngine 9.1-->"C:\Program Files\EoRezo\unins000.exe"
          Google Toolbar for Internet Explorer-->"C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_0531C63A913CC9D1.exe" /uninstall
          Google Update Helper-->MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
          Google Earth-->MsiExec.exe /X{548EAC70-EE00-11DD-908C-005056806466}
          HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
          Installation Windows Live-->C:\Program Files\Windows Live\Installer\wlarp.exe
          Installation Windows Live-->MsiExec.exe /I{7370DF47-B4F9-4279-BFC3-3F09919F720D}
          Intel Matrix Storage Manager-->C:\Windows\system32\imsmudlg.exe -uninstall
          iPod for Windows 2006-01-10-->C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{3D047C15-C859-45F7-81CE-F2681778069B} /l1036
          iTunes-->MsiExec.exe /I{F5C63795-2708-4D15-BF18-5ABBFF7DFFC8}
          Java(TM) 6 Update 11-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216011FF}
          Java(TM) 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
          Java(TM) SE Runtime Environment 6-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160000}
          Junk Mail filter update-->MsiExec.exe /I{4DE3E3D9-AE81-45DE-9195-3015F7B1DBF3}
          LimeWire 4.18.8-->"C:\Program Files\LimeWire\uninstall.exe"
          LiveUpdate 3.2 (Symantec Corporation)-->"C:\Program Files\Symantec\LiveUpdate\LSETUP.EXE" /U
          LiveUpdate Notice (Symantec Corporation)-->MsiExec.exe /X{DBA4DB9D-EE51-4944-A419-98AB1F1249C8}
          Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{A49F249F-0C91-497F-86DF-B2585E8E76B7}
          MobileMe Control Panel-->MsiExec.exe /I{A14C24F6-615B-415E-84B0-610FDAD19B68}
          Mozilla Firefox (3.0.7)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
          MSRedist-->MsiExec.exe /I{B7C61755-DB48-4003-948F-3D34DB8EAF69}
          MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
          MSXML 4.0 SP2 (KB927978)-->MsiExec.exe /I{37477865-A3F1-4772-AD43-AAFC6BCFF99F}
          MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
          myphotobook 3.1-->C:\Program Files\myphotobook\uninst.exe
          Navilog1 3.7.5-->"C:\Program Files\Navilog1\unins000.exe"
          Neuf - Kit de connexion-->C:\Program Files\Neuf\Kit\uninstall.exe
          Norton AntiVirus-->MsiExec.exe /X{830D8CBD-C668-49e2-A969-C2C2106332E0}
          Norton Confidential Browser Component-->MsiExec.exe /I{4843B611-8FCB-4428-8C23-31D0A5EAE164}
          Norton Confidential Web Protection Component-->MsiExec.exe /I{D353CC51-430D-4C6F-9B7E-52003DA1E05A}
          Norton Internet Security (Symantec Corporation)-->"C:\Program Files\Common Files\Symantec Shared\SymSetup\{5AA2CD16-706F-41f3-87C5-2B5A031F2B3B}_10_2_0_30\{5AA2CD16-706F-41f3-87C5-2B5A031F2B3B}.exe" /X
          Norton Internet Security-->MsiExec.exe /I{3672B097-EA69-4bfe-B92F-29AE6D9D2B34}
          Norton Internet Security-->MsiExec.exe /I{48185814-A224-447A-81DA-71BD20580E1B}
          Norton Internet Security-->MsiExec.exe /I{5AA2CD16-706F-41f3-87C5-2B5A031F2B3B}
          Norton Internet Security-->MsiExec.exe /I{E3EFA461-EB83-4C3B-9C47-2C1D58A01555}
          Norton Internet Security-->MsiExec.exe /I{E5EE9939-259F-4DE2-8023-5C49E16A4F43}
          Norton Protection Center-->MsiExec.exe /I{9A129ABC-A53A-4209-A21E-D5DEDFB7CCA8}
          OpenOffice.org 3.0-->MsiExec.exe /I{6860B340-530D-46B3-91F8-1AE1F70F7C33}
          Outil de mise à jour Google-->"C:\Program Files\Google\Google Updater\GoogleUpdater.exe" -uninstall
          Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
          ParetoLogic DriverCure-->C:\Program Files\ParetoLogic\DriverCure\uninstall.exe
          PMM Video Encoder v 1.0-->C:\Users\Pierre Marie\Desktop\ISO\VIDEO\Uninstal.exe
          QuickTime-->MsiExec.exe /I{216AB108-2AE1-4130-B3D5-20B2C4C80F8F}
          Realtek 8169 PCI, 8168 and 8101E PCIe Ethernet Network Card Driver for Windows Vista-->C:\Program Files\InstallShield Installation Information\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}\setup.exe -runfromtemp -l0x040c -removeonly
          Realtek High Definition Audio Driver-->RtlUpd.exe -r -m
          Réducteur de bruit lect. CD/DVD-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9FE35071-CAB2-4E79-93E7-BFC6A2DC5C5D}\setup.exe" -l0x40c
          Safari-->MsiExec.exe /I{D90AFDE3-3E67-407A-ACA8-F0BAAD012F08}
          SecondLife (remove only)-->"C:\Program Files\SecondLife\uninst.exe" /P="SecondLife"
          Security Update for Windows Media Encoder (KB954156)-->msiexec.exe /I {E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E} MSIPATCHREMOVE={E836F1B7-43FB-46B0-A0D9-E4D2A5951659} /qb
          SoftwareUpdate 1.0-->"C:\Users\Pierre Marie\AppData\Roaming\eoRezo\SoftwareUpdate\unins000.exe"
          SPBBC 32bit-->MsiExec.exe /I{77772678-817F-4401-9301-ED1D01A8DA56}
          Synaptics Pointing Device Driver-->rundll32.exe "C:\Program Files\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall
          Texas Instruments PCIxx21/x515/xx12 drivers.-->C:\Program Files\InstallShield Installation Information\{DB780B85-B4B5-4864-A49C-9B706B169C93}\setup.exe -runfromtemp -l0x040c
          TOSHIBA Assist-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{12B3A009-A080-4619-9A2A-C6DB151D8D67}\setup.exe" -l0x40c
          TOSHIBA ConfigFree-->C:\Program Files\InstallShield Installation Information\{78C6A78A-8B03-48C8-A47C-78BA1FCA2307}\setup.exe -runfromtemp -l0x040c uninstall -removeonly
          TOSHIBA Disc Creator-->MsiExec.exe /X{5DA0E02F-970B-424B-BF41-513A5018E4C0}
          TOSHIBA DVD PLAYER-->C:\Program Files\InstallShield Installation Information\{6C5F3BDC-0A1B-4436-A696-5939629D5C31}\setup.exe -runfromtemp -l0x040c -ADDREMOVE -removeonly
          TOSHIBA Extended Tiles for Windows Mobility Center-->C:\Program Files\InstallShield Installation Information\{617C36FD-0CBE-4600-84B2-441CEB12FADF}\setup.exe -runfromtemp -l0x040c
          TOSHIBA Flash Cards Support Utility-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{620BBA5E-F848-4D56-8BDA-584E44584C5E}
          TOSHIBA Hardware Setup-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{5279374D-87FE-4879-9385-F17278EBB9D3} /l1036
          TOSHIBA Mot de passe responsable-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{51B4E156-14A5-4904-9AE4-B1AA2A0E46BE} /l1036
          Toshiba Online Product Information-->C:\Program Files\InstallShield Installation Information\{2290A680-4083-410A-ADCC-7092C67FC052}\setup.exe -runfromtemp -l0x040c -removeonly
          TOSHIBA SD Memory Utilities-->MsiExec.exe /X{EBFF48F5-3CFA-436F-8FD5-94FB01D3A0A7}
          TOSHIBA Software Modem-->Tosmreg -U
          TOSHIBA Value Added Package-->C:\Program Files\InstallShield Installation Information\{FEDD27A0-B306-45EF-BF58-B527406B42C8}\setup.exe -runfromtemp -l0x040c
          VC80CRTRedist - 8.0.50727.762-->MsiExec.exe /I{767CC44C-9BBC-438D-BAD3-FD4595DD148B}
          WebPopupKiller 1.0-->"C:\Program Files\WebPopupKiller\unins000.exe"
          Windows Live Call-->MsiExec.exe /I{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}
          Windows Live Communications Platform-->MsiExec.exe /I{3B4E636E-9D65-4D67-BA61-189800823F52}
          Windows Live Mail-->MsiExec.exe /I{63DC2DA0-2A6C-4C38-9249-B75395458657}
          Windows Live Messenger-->MsiExec.exe /X{059C042E-796A-4ACC-A81A-ECC2010BB78C}

          ======Security center information======

          AV: Norton Internet Security
          FW: Norton Internet Security
          AS: Windows Defender (disabled)
          AS: Norton Internet Security

          System event log

          Computer Name: PC-de-PierreMar
          Event Code: 7026
          Message: Le pilote de démarrage système ou d'amorçage suivant n'a pas pu se charger :
          aswSP
          eeCtrl
          SPBBCDrv
          spldr
          SRTSPX
          SYMTDI
          Wanarpv6
          Record Number: 46229
          Source Name: Service Control Manager
          Time Written: 20090309174454.000000-000
          Event Type: Erreur
          User:

          Computer Name: PC-de-PierreMar
          Event Code: 7036
          Message: Le service Connexions réseau est entré dans l'état : en cours d'exécution.
          Record Number: 46230
          Source Name: Service Control Manager
          Time Written: 20090309174454.000000-000
          Event Type: Information
          User:

          Computer Name: PC-de-PierreMar
          Event Code: 7036
          Message: Le service Services de base de module de plateforme sécurisée est entré dans l'état : arrêté.
          Record Number: 46231
          Source Name: Service Control Manager
          Time Written: 20090309174549.000000-000
          Event Type: Information
          User:

          Computer Name: PC-de-PierreMar
          Event Code: 537
          Message: Aucun périphérique de sécurité du module de plateforme sécurisée compatible trouvé sur cet ordinateur. Impossible de démarrer les services de base de module de plateforme sécurisée.
          Record Number: 46232
          Source Name: Microsoft-Windows-TBS
          Time Written: 20090309174549.236634-000
          Event Type: Information
          User: AUTORITE NT\SERVICE LOCAL

          Computer Name: PC-de-PierreMar
          Event Code: 4226
          Message: TCP/IP a atteint la limite de sécurité imposée sur le nombre de tentatives de connexion TCP simultanées.
          Record Number: 46233
          Source Name: Tcpip
          Time Written: 20090309175642.502234-000
          Event Type: Avertissement
          User:

          Application event log

          Computer Name: PC-de-PierreMar
          Event Code: 6000
          Message: L’abonné aux notifications Winlogon <GPClient> n’était pas disponible pour traiter un événement de notification.
          Record Number: 9280
          Source Name: Microsoft-Windows-Winlogon
          Time Written: 20090309174417.000000-000
          Event Type: Avertissement
          User:

          Computer Name: PC-de-PierreMar
          Event Code: 6000
          Message: L’abonné aux notifications Winlogon <Sens> n’était pas disponible pour traiter un événement de notification.
          Record Number: 9281
          Source Name: Microsoft-Windows-Winlogon
          Time Written: 20090309174417.000000-000
          Event Type: Information
          User:

          Computer Name: PC-de-PierreMar
          Event Code: 4609
          Message: Le système d'événements de COM+ a détecté un code de renvoi erroné lors de son traitement interne. Le HRESULT est 8007043c à partir de la ligne 45 de d:\vistasp1_gdr\com\complus\src\events\tier1\eventsystemobj.cpp. Contactez les services de support technique Microsoft pour signaler cette erreur.
          Record Number: 9282
          Source Name: Microsoft-Windows-EventSystem
          Time Written: 20090309174426.000000-000
          Event Type: Erreur
          User:

          Computer Name: PC-de-PierreMar
          Event Code: 8211
          Message: Erreur du service de cliché instantané de volumes : le rédacteur de nom WMI Writer et d'identificateur {a6ad56c2-b509-4e6c-bb19-49d8f43532f0} a tenté de s'abonner en mode sans échec.

          Opération :
          Rédacteur en cours d’initialisation

          Contexte :
          ID de classe du rédacteur: {a6ad56c2-b509-4e6c-bb19-49d8f43532f0}
          Nom du rédacteur: WMI Writer
          Record Number: 9283
          Source Name: VSS
          Time Written: 20090309174448.000000-000
          Event Type: Information
          User:

          Computer Name: PC-de-PierreMar
          Event Code: 5617
          Message: Sous-systèmes WMI (Windows Management Instrumentation) correctement initialisés
          Record Number: 9284
          Source Name: Microsoft-Windows-WMI
          Time Written: 20090309174451.000000-000
          Event Type: Information
          User:

          Security event log

          Computer Name: PC-de-PierreMar
          Event Code: 5038
          Message: L’intégrité du code a déterminé que le hachage de l’image d’un fichier n’est pas valide. Le fichier peut être endommagé en raison d’une modification non autorisée ou le hachage non valide peut indiquer une erreur d’unité de disque potentielle.

          Nom du fichier : \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys
          Record Number: 10888
          Source Name: Microsoft-Windows-Security-Auditing
          Time Written: 20090309190055.265434-000
          Event Type: Échec de l'audit
          User:

          Computer Name: PC-de-PierreMar
          Event Code: 5038
          Message: L’intégrité du code a déterminé que le hachage de l’image d’un fichier n’est pas valide. Le fichier peut être endommagé en raison d’une modification non autorisée ou le hachage non valide peut indiquer une erreur d’unité de disque potentielle.

          Nom du fichier : \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys
          Record Number: 10889
          Source Name: Microsoft-Windows-Security-Auditing
          Time Written: 20090309190055.281034-000
          Event Type: Échec de l'audit
          User:

          Computer Name: PC-de-PierreMar
          Event Code: 5038
          Message: L’intégrité du code a déterminé que le hachage de l’image d’un fichier n’est pas valide. Le fichier peut être endommagé en raison d’une modification non autorisée ou le hachage non valide peut indiquer une erreur d’unité de disque potentielle.

          Nom du fichier : \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys
          Record Number: 10890
          Source Name: Microsoft-Windows-Security-Auditing
          Time Written: 20090309190055.312234-000
          Event Type: Échec de l'audit
          User:

          Computer Name: PC-de-PierreMar
          Event Code: 5038
          Message: L’intégrité du code a déterminé que le hachage de l’image d’un fichier n’est pas valide. Le fichier peut être endommagé en raison d’une modification non autorisée ou le hachage non valide peut indiquer une erreur d’unité de disque potentielle.

          Nom du fichier : \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys
          Record Number: 10891
          Source Name: Microsoft-Windows-Security-Auditing
          Time Written: 20090309190055.327834-000
          Event Type: Échec de l'audit
          User:

          Computer Name: PC-de-PierreMar
          Event Code: 5038
          Message: L’intégrité du code a déterminé que le hachage de l’image d’un fichier n’est pas valide. Le fichier peut être endommagé en raison d’une modification non autorisée ou le hachage non valide peut indiquer une erreur d’unité de disque potentielle.

          Nom du fichier : \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys
          Record Number: 10892
          Source Name: Microsoft-Windows-Security-Auditing
          Time Written: 20090309190055.343434-000
          Event Type: Échec de l'audit
          User:

          ======Environment variables======

          "ComSpec"=%SystemRoot%\system32\cmd.exe
          "FP_NO_HOST_CHECK"=NO
          "OS"=Windows_NT
          "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\PROGRA~1\COMMON~1\ULEADS~1\MPEG;C:\Program Files\ATI Technologies\ATI.ACE\Core-Static;C:\Program Files\QuickTime\QTSystem\
          "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
          "PROCESSOR_ARCHITECTURE"=x86
          "TEMP"=%SystemRoot%\TEMP
          "TMP"=%SystemRoot%\TEMP
          "USERNAME"=SYSTEM
          "windir"=%SystemRoot%
          "PROCESSOR_LEVEL"=6
          "PROCESSOR_IDENTIFIER"=x86 Family 6 Model 15 Stepping 13, GenuineIntel
          "PROCESSOR_REVISION"=0f0d
          "NUMBER_OF_PROCESSORS"=2
          "CLASSPATH"=.;C:\Program Files\Java\jre6\lib\ext\QTJava.zip
          "QTJAVA"=C:\Program Files\Java\jre6\lib\ext\QTJava.zip
          "SAFEBOOT_OPTION"=NETWORK

          -----------------EOF-----------------
      2. Pimprenelle Quant tu a dis: " Note importante : l'infection bagle s'installant au moyen d'un crack/keygen, tu dois IMPERATIVEMENT supprimer ce type de fichier."

        De quel fichier esque tu parlai exactement et coment le suprimer ?
        1. Contributeur sécurité
          ok j'attends findikyll car j'ai pas demandé : RSIT
          1. ok voila le rapport:

            ############################## [ FindyKill V4.719 ]

            # User : Pierre Marie (Administrateurs) # PC-DE-PIERREMAR
            # Update on 06/03/09 by Chiquitine29
            # Start at: 21:00:52 | 09/03/2009

            # Intel(R) Core(TM)2 Duo CPU T5450 @ 1.66GHz
            # Microsoft© Windows VistaT dition Familiale Premium (6.0.6001 32-bit) # Service Pack 1
            # Internet Explorer 7.0.6001.18000
            # Windows Firewall Status : Disabled
            # AV : Norton Internet Security 2007 [ Enabled | Updated ]
            # FW : Norton Internet Security[ Enabled ]2007

            # C:\ # Disque fixe local # 92,77 Go (23,7 Go free) [Vista] # NTFS
            # E:\ # Disque fixe local # 92,07 Go (91,98 Go free) [Data] # NTFS
            # F:\ # Disque CD-ROM

            ############################## [ Processus actifs ]

            C:\Windows\System32\smss.exe
            C:\Windows\system32\csrss.exe
            C:\Windows\system32\csrss.exe
            C:\Windows\system32\wininit.exe
            C:\Windows\system32\winlogon.exe
            C:\Windows\system32\services.exe
            C:\Windows\system32\lsass.exe
            C:\Windows\system32\lsm.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\System32\svchost.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\System32\svchost.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\Explorer.EXE
            C:\Program Files\Windows Media Player\wmpnscfg.exe
            C:\Program Files\Internet Explorer\iexplore.exe
            C:\Windows\system32\wbem\wmiprvse.exe

            ################## [ Fichiers / Dossiers infectieux C:\ ]

            ################## [ C:\Windows ]

            ################## [ C:\Windows\system32 ]

            ################## [ C:\Windows\system32\drivers ]

            ################## [ C:\.. Application Data ... ]

            ################## [ Registre / Clés infectieuses ]

            ################## [ Recherche dans supports amovibles]

            # Presence des fichiers :

            ################## [ Registre / Mountpoint2 ]

            # -> Not found !

            ################## [ ! Fin du rapport # FindyKill V4.719 ! ]
            1. Contributeur sécurité
              C'est bon pas d'infection de se coter là. maintenant ceci :

              Fait ceci et poste moi le rapport à la suite de la question êtes vous aider par quelqu'un, répondre oui. Merci.

              Télécharge GenProc sur ton bureau (Attention le fichier est un fichier zip)
              Dézippe le dossier, double-clique sur GenProc.bat
              En final, poste le contenu du rapport qui s'affiche.
              Comment utiliser GenProc

              Pour ceux qui ont vista, ne pas oublier de désactiver Le contrôle des comptes utilisateurs

              IMPORTANT : poste le rapport et ne fais rien d'autre pour l'instant ( souvent il faut ajouter des consignes à la manipe indiquée pour que cela fonctionne parfaitement )

              1. Rapport GenProc 2.415 [1] - 09/03/2009 à 22:38:19 - Windows Vista

                GenProc n'a détecté aucune infection caractéristique et suggère de suivre la procédure suivante :

                Poste un rapport Nod32 https://www.eset.com/ (il faut utiliser Internet Explorer)
                - coche toutes les cases à chaque fois, et lorsque c'est terminé, colle le rapport :
                - C:\Program Files\EsetOnlineScanner\log.txt

                __________________________________________________________________________________________________________

                Sites officiels GenProc : www.alt-shift-return.org et www.genproc.com
            2. Contributeur sécurité
              Tu as un rogue eorezo, il faut l'enlever :

              Télécharges AD-Remover ( de Cyrildu17 / C_XX ) sur ton bureau :

              /!\ Déconnectes toi et fermes toutes applications en cours

              ● Double clique sur le programme d'installation , et installe le dans son emplacement par défaut. ( C:\Program files )
              ● Double clique sur l'icône Ad-removersituée sur ton bureau
              ● Au menu principal choisi l'option "A"
              ● Postes le rapport qui apparait à la fin .

              ( le rapport est sauvegardé aussi sous C:\Ad-report(date).log )

              (CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

              Pour ceux qui ont vista, ne pas oublier de désactiver Le contrôle des comptes utilisateurs

              1. ------- LOGFILE OF AD-REMOVER 1.1.1.6 | ONLY XP/VISTA -------

                Updated by C_XX on 09/03/2009 at 21:20

                Start at: 22:47:18, Mon 09/03/2009 | Boot mode: Safe Boot
                Option: SCAN | Executed from: C:\Program Files\Ad-remover\Ad-remover.bat
                Operating System: Microsoft® Windows Vista™ Home Premium Service Pack 1 (version 6.0.6001)
                Computer Name: PC-DE-PIERREMAR
                Current User: Pierre Marie - Administrator
                Drive(s):
                - C:\ (File System: NTFS)
                - E:\ (File System: NTFS)
                System Drive: C:\
                Windows Directory: C:\Windows\
                System Directory: C:\Windows\System32\

                --- Running Processes: 24
                --- User Account Control is DISABLE

                +-----------------| Boonty/Boonty Games Elements Found:

                .
                .

                +-----------------| Eorezo Elements Found:

                HKCR\AppID\{362A53B2-2913-4F8A-82F5-7E0A23FDC6F9}
                HKCR\AppID\EoRezoBHO.DLL
                HKCR\CLSID\{C7B76B90-3455-4AE6-A752-EAC4D19689E5}
                HKCR\EoRezoBHO.EoBho
                HKCR\EoRezoBHO.EoBho.1
                HKCR\Typelib\{B6ACB3F1-6A83-432C-B854-3E1056F87F4E}
                HKCU\Software\EoRezo
                HKLM\Software\EoRezo
                HKLM\Software\Classes\AppID\{362A53B2-2913-4F8A-82F5-7E0A23FDC6F9}
                HKLM\Software\Classes\AppID\EoRezoBHO.DLL
                HKLM\Software\Classes\CLSID\{C7B76B90-3455-4AE6-A752-EAC4D19689E5}
                HKLM\Software\Classes\EoRezoBHO.EoBho
                HKLM\Software\Classes\EoRezoBHO.EoBho.1
                HKLM\Software\Classes\TypeLib\{B6ACB3F1-6A83-432C-B854-3E1056F87F4E}
                HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C7B76B90-3455-4AE6-A752-EAC4D19689E5}
                HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\eoEngine_is1
                HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\SoftwareUpdate_is1
                HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\Eoengine
                HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce\\Softwarehelper
                .
                C:\Program Files\EoRezo
                C:\Users\Pierre Marie\AppData\Roaming\EoRezo
                C:\Windows\Prefetch\SOFTWAREUPDATEHP.EXE-53296842.pf
                C:\Users\Pierre Marie\AppData\Roaming\Microsoft\Windows\Cookies\pierre_marie@ads.eorezo[1].txt
                C:\Users\Pierre Marie\AppData\Roaming\Microsoft\Windows\Cookies\pierre_marie@dl.eorezo[1].txt
                C:\Users\Pierre Marie\AppData\Roaming\Microsoft\Windows\Cookies\pierre_marie@eorezo[1].txt

                +-----------------| Infected Poker Softwares Elements Found:

                .

                +-----------------| FunWebProducts/MyWay/MyWebSearch Elements Found:

                .
                .

                +-----------------| It's TV Elements Found:

                .

                +-----------------| Sweetim Elements Found:

                .

                +-----------------| Other Adwares Found:

                .
                .
                C:\Users\Pierre Marie\AppData\Roaming\Microsoft\Windows\Cookies\pierre_marie@atdmt[2].txt
                C:\Users\Pierre Marie\AppData\Roaming\Microsoft\Windows\Cookies\pierre_marie@bs.serving-sys[1].txt

                +-----------------| Added Scan:

                ---- Mozilla FireFox Version 3.0.7 ----

                ProfilePath: qg5bq52e.default
                .
                .
                .
                .
                .
                .

                ---- Internet Explorer Version 7.0.6001.18000 ----

                +-[HKEY_CURRENT_USER\..\Internet Explorer\Main]

                Search bar: hxxp://recherche.neuf.fr/ie/default.html
                Search Page: hxxp://recherche.neuf.fr/
                Start page: hxxp://y.lo.st#home

                +-[HKEY_USERS\S-1-5-21-1183140647-2202194003-2035419698-1000\..\Internet Explorer\Main]

                Search bar: hxxp://recherche.neuf.fr/ie/default.html
                Search Page: hxxp://recherche.neuf.fr/
                Start page: hxxp://y.lo.st#home

                +-[HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]

                Default_Page_URL: hxxp://go.microsoft.com/fwlink/?LinkId=69157
                Default_Search_URL: hxxp://recherche.neuf.fr/
                Search Page: hxxp://go.microsoft.com/fwlink/?LinkId=54896
                Start page: hxxp://go.microsoft.com/fwlink/?LinkId=69157

                +-[HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]

                Tabs: hxxp://y.lo.st

                +---------------------------------------------------------------------------+

                3687 Byte(s) - C:\Ad-Report-Scan-09.03.2009.log

                0 File(s) - C:\Program Files\Ad-remover\TOOLS\BACKUP
                0 File(s) - C:\Program Files\Ad-remover\TOOLS\QUARANTINE

                Before run: 25,199,702,016 Byte(s) free
                After run: 25,199,697,920 Byte(s) free

                End at: 22:48:16 | 09/03/2009
                .
                +-----------------| E.O.F - 85 Lines
                .
                1. Contributeur sécurité
                  Et ba il y en avait du monde eorezo :

                  ! Déconnectes toi et fermes toutes applications en cours !

                  Redémarre en mode sans échec comme indiqué ici ; Choisis ta session courante.

                  * Relances "Ad-remover" : au menu principal choisi l'option "B" .

                  --> le programme va travailler ...

                  * Postes le rapport qui apparait à la fin + un nouvel Hijackthis pour analyse ...

                  ( le rapport est sauvegardé aussi sous C:\Ad-report.log )

                  /!\ Si le Bureau ne réapparait pas presse Ctrl + Alt + Suppr , Onglet "Fichier" , "Nouvelle tâche" , tapes explorer.exe et valides) /!\

                  Et ensuite ceci :

                  Télécharges ToolBar S&D ( de Eric_71/Team IDN ) :

                  Tuto

                  !! Déconnectes toi et fermes toute tes applications en cours le temps de la manipe !! désactive ton antivirus.

                  * double-cliques sur l'.exe pour lancer l'installe et laisses toi guider ...
                  * Une fois fait, cliques sur le raccourci créé sur ton bureau pour lancer l'outil .
                  * Choisis l'option 1 ( "recherche") et tapes "entrée" .
                  * Une fois le scan finit , un rapport va apparaître, copie/colles l'intégralité
                  de son contenu dans ta prochaine réponse ...
                  ( le rapport est en outre sauvegardé ici -> C:\TB.txt )

                  Pour ceux qui ont vista, ne pas oublier de désactiver Le contrôle des comptes utilisateurs

                  Ensuite fait moi ceci :
                  1. donc la g choisi l'option b mai il me propose plein d' autres ardwares. Je peu tous decocher et lancé ?
                    1. Contributeur sécurité
                      non que eorezo il n'y a que lui sur le rapport.
                      1. ------- LOGFILE OF AD-REMOVER 1.1.1.6 | ONLY XP/VISTA -------

                        Updated by C_XX on 09/03/2009 at 21:20

                        **** LIMITED TO ****

                        Eorezo

                        ********************

                        Start at: 23:27:23, Mon 09/03/2009 | Boot mode: Safe Boot
                        Option: CLEAN | Executed from: C:\Program Files\Ad-remover\Ad-remover.bat
                        Operating System: Microsoft® Windows Vista™ Home Premium Service Pack 1 (version 6.0.6001)
                        Computer Name: PC-DE-PIERREMAR
                        Current User: Pierre Marie - Administrator
                        Drive(s):
                        - C:\ (File System: NTFS)
                        - E:\ (File System: NTFS)
                        System Drive: C:\
                        Windows Directory: C:\Windows\
                        System Directory: C:\Windows\System32\

                        --- Running Processes: 24
                        --- User Account Control is DISABLE

                        (!) ---- IE start pages/Tabs reset

                        +-----------------| Eorezo Elements Deleted :

                        HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\Eoengine
                        HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce\\Softwarehelper
                        HKCR\AppID\{362A53B2-2913-4F8A-82F5-7E0A23FDC6F9}
                        HKCR\AppID\EoRezoBHO.DLL
                        HKCR\CLSID\{C7B76B90-3455-4AE6-A752-EAC4D19689E5}
                        HKCR\EoRezoBHO.EoBho
                        HKCR\EoRezoBHO.EoBho.1
                        HKCR\Typelib\{B6ACB3F1-6A83-432C-B854-3E1056F87F4E}
                        HKCU\Software\EoRezo
                        HKLM\Software\EoRezo
                        HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C7B76B90-3455-4AE6-A752-EAC4D19689E5}
                        HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\eoEngine_is1
                        HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\SoftwareUpdate_is1
                        .
                        C:\Program Files\EoRezo
                        C:\Users\Pierre Marie\AppData\Roaming\EoRezo
                        C:\Windows\Prefetch\SOFTWAREUPDATEHP.EXE-53296842.pf
                        C:\Users\Pierre Marie\AppData\Roaming\Microsoft\Windows\Cookies\pierre_marie@ads.eorezo[1].txt
                        C:\Users\Pierre Marie\AppData\Roaming\Microsoft\Windows\Cookies\pierre_marie@dl.eorezo[1].txt
                        C:\Users\Pierre Marie\AppData\Roaming\Microsoft\Windows\Cookies\pierre_marie@eorezo[1].txt

                        (!) ---- Temp files deleted.
                        (!) ---- Recycle bin emptied in all drives.

                        +-----------------| Added Scan :

                        ---- Mozilla FireFox Version 3.0.7 ----

                        ProfilePath: qg5bq52e.default
                        .
                        .
                        .
                        .
                        .
                        .

                        ---- Internet Explorer Version 7.0.6001.18000 ----

                        +-[HKEY_CURRENT_USER\..\Internet Explorer\Main]

                        Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
                        Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                        Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
                        Search Page: hxxp://recherche.neuf.fr/
                        Start page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome

                        +-[HKEY_USERS\S-1-5-21-1183140647-2202194003-2035419698-1000\..\Internet Explorer\Main]

                        Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
                        Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                        Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
                        Search Page: hxxp://recherche.neuf.fr/
                        Start page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome

                        +-[HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]

                        Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
                        Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                        Search bar: hxxp://search.msn.com/spbasic.htm
                        Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                        Start page: hxxp://fr.msn.com/

                        +-[HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]

                        Tabs: hxxp://ieframe.dll/tabswelcome.htm

                        +---------------------------------------------------------------------------+

                        3518 Byte(s) - C:\Ad-Report-Clean-09.03.2009.log
                        4022 Byte(s) - C:\Ad-Report-Scan-09.03.2009.log

                        2 File(s) - C:\Program Files\Ad-remover\TOOLS\BACKUP
                        4 File(s) - C:\Program Files\Ad-remover\TOOLS\QUARANTINE

                        Before run: 25,363,996,672 Byte(s) free
                        After run: 29,520,572,416 Byte(s) free

                        End at: 23:29:50 | 09/03/2009
                        .
                        +-----------------| E.O.F - 73 Lines
                        .
                        • 1
                        • 2