Virus Hacktool Rootkit

Bonjour à tous,

je viens d'installer internet explorer 8 et depuis je n'arrête pas d'avoir des messages d'alerte de Norton en me signalant que le virus Racktool rootkit menaçait mon ordi. J'ai essayé de supprimer les fichiers mais aucun moyen, rien à faire il ne veux pas les supprimer. Il s'agit de fichiers types .dll dans WINDOWS, system 32. J'ai bien évidemment regarder toutes les réponses de votre forum mais je n'ai rien compris du tout. Je suis une brelle en informatique et visiblement ce n'est pas très simple de réparer tout ça.

De plus mon ordi rame, il s'éteint alors que je ne lui ai rien demandé.

Est-ce que quelqu'un pourrait m'aider?

Merci d'avance

Fannette
Configuration: Windows XP
Internet Explorer 8.0

48 réponses

Résumé de la discussion

Des alertes Norton signalent la présence d’un rootkit Racktool après l’installation d’Internet Explorer 8 sur Windows XP, les fichiers DLL situés dans Windows\System32 résistant à la suppression et provoquant des ralentissements. Des solutions en discussion incluent l’usage de Combofix et l’analyse à l’aide de Malwarebytes et d’Avira, avec la présentation d’un rapport détaillé sur les éléments détectés. Des exemples d’éléments problématiques apparaissent dans le journal d’exécution, notamment des entrées dans system32, des outils de restauration et des dossiers suspects créés récemment, indiquant une compromission active. En cas de doute persistant, l’examen des journaux et l’utilisation d’un point de restauration hors ligne, puis une éventuelle réinstallation sécurisée et la mise à jour complète du système peuvent être nécessaires pour prévenir une réinfection.

Bobot (l’IA à votre service)
  1. Contributeur
    Salut,

    Telecharges RSIT " Random's System Information Tool " sur ton bureau : http://images.malwareremoval.com/random/RSIT.exe

    - Fermes toutes les applications en cours et double clic sur RSIT.exe
    - Selectionnes " Continue " à l'ecran >> RSIT va analyser le pc et verifier si l'outil hijackthis ( version à jour) est present sur le pc, si ce n'est pas le cas, RSIT le telechargera >> acceptes la license
    - Une fois l'analyse terminée, 2 rapports.txt s'ouvrent, log.txt à l'écran et info.txt dans la barre des taches
    - Postes le contenu des 2 rapports
    .
    0
    1. Re, merci de votre rapidité, voici mes rapports, dans un premier temps le rapport log.txt (quelle liste!!):

      HijackThis download failed

      ======Scheduled tasks folder======

      C:\WINDOWS\tasks\AppleSoftwareUpdate.job
      C:\WINDOWS\tasks\Norton AntiVirus - Analyser mon ordinateur - Fannette.job

      ======Registry dump======

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
      AcroIEHlprObj Class - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2004-12-14 63136]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
      Search Helper - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll [2009-01-14 92504]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{74EB420F-7B78-48AF-A5FD-902B85868337}]
      C:\WINDOWS\system32\bat.dll [2004-08-05 97792]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
      Programme d'aide de l'Assistant de connexion Windows Live - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{905502AB-1987-46cd-9EC5-42B1E087D319}]
      LTIEHelper Class - C:\Program Files\EasyPrediction\2.0\ltie.dll [2009-03-12 229376]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9ECB9560-04F9-4bbc-943D-298DDF1699E1}]
      CNisExtBho Class - C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll [2005-05-24 104024]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
      Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll [2009-04-15 251504]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
      Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll [2009-04-15 657904]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BDF3E430-B101-42AD-A544-FADC6B084872}]
      CNavExtBho Class - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll [2005-11-04 218720]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C84D72FE-E17D-4195-BB24-76C02E2E7C4E}]
      Google Dictionary Compression sdch - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll [2009-04-15 522224]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10}]
      Windows Live Toolbar Helper - C:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-02-06 1068904]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
      {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - Norton Internet Security - C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll [2005-05-24 104024]
      {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - Norton AntiVirus - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll [2005-11-04 218720]
      {21FA44EF-376D-4D53-9B0F-8A89D3229068} - &Windows Live Toolbar - C:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-02-06 1068904]
      {2318C2B1-4965-11d4-9B18-009027A5CD4F} - &Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll [2009-04-15 251504]

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
      "SunJavaUpdateSched"=C:\Program Files\Java\jre1.5.0\bin\jusched.exe [2009-04-02 36972]
      "ccApp"=C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe [2008-02-12 49488]
      "ATIPTA"=C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe [2005-04-05 339968]
      "LaunchAp"=C:\Program Files\Launch Manager\LaunchAp.exe [2005-03-30 32768]
      "HotkeyApp"=C:\Program Files\Launch Manager\HotkeyApp.exe [2005-05-02 57344]
      "LMgrVolOSD"=C:\Program Files\Launch Manager\OSD.exe [2005-03-16 204800]
      "LMgrOSD"=C:\Program Files\Launch Manager\OSDCtrl.exe [2004-10-11 245760]
      "Wbutton"=C:\Program Files\Launch Manager\Wbutton.exe [2005-04-18 81920]
      "SoundMan"=C:\WINDOWS\SOUNDMAN.EXE [2005-03-24 77824]
      "SynTPLpr"=C:\Program Files\Synaptics\SynTP\SynTPLpr.exe [2005-03-18 98393]
      "SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2005-03-18 688217]
      "CtrlVol"=C:\Program Files\Launch Manager\CtrlVol.exe [2003-09-16 20480]
      "Symantec NetDriver Monitor"=C:\PROGRA~1\SYMNET~1\SNDMon.exe [2009-04-02 100056]
      "NeroFilterCheck"=C:\WINDOWS\system32\NeroCheck.exe [2001-07-09 155648]
      "QuickTime Task"=C:\Program Files\QuickTime\qttask.exe [2007-02-16 282624]

      [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
      "CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
      "msnmsgr"=C:\Program Files\Windows Live\Messenger\msnmsgr.exe [2009-02-06 3885408]
      "A00FE6741.exe"=C:\DOCUME~1\Fannette\LOCALS~1\Temp\_A00FE6741.exe []
      "A00FF32EE.exe"=C:\DOCUME~1\Fannette\LOCALS~1\Temp\_A00FF32EE.exe []
      "A00FF6D57.exe"=C:\DOCUME~1\Fannette\LOCALS~1\Temp\_A00FF6D57.exe []

      C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage
      Lancement rapide d'Adobe Reader.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe

      C:\Documents and Settings\Fannette\Menu Démarrer\Programmes\Démarrage
      Notification de cadeaux MSN.lnk - C:\Documents and Settings\Fannette\Application Data\Microsoft\Notification de cadeaux MSN\lsnfier.exe

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
      C:\WINDOWS\system32\Ati2evxx.dll [2005-04-05 46080]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\OdysseyClient]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\__c0094DEF]
      C:\WINDOWS\system32\__c0094DEF.dat []

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
      WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
      "dontdisplaylastusername"=0
      "legalnoticecaption"=
      "legalnoticetext"=
      "shutdownwithoutlogon"=1
      "undockwithoutlogon"=1
      "DisableTaskMgr"=0

      [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
      "NoDriveTypeAutoRun"=145
      "NoFolderOptions"=0

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
      "HonorAutoRunSetting"=

      [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
      "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
      "C:\Program Files\Messenger\msmsgs.exe"="C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger"
      "C:\Program Files\Windows Live\Messenger\wlcsdk.exe"="C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call"
      "C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe"="C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync"
      "%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
      "C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"

      [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
      "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
      "C:\Program Files\Windows Live\Messenger\wlcsdk.exe"="C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call"
      "C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe"="C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync"
      "%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
      "C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"

      ======List of files/folders created in the last 1 months======

      2009-04-17 10:45:34 ----D---- C:\Program Files\trend micro
      2009-04-17 10:44:46 ----D---- C:\rsit
      2009-04-15 18:33:18 ----D---- C:\Documents and Settings\Fannette\Application Data\Google
      2009-04-15 18:20:30 ----D---- C:\Program Files\Google
      2009-04-15 18:20:30 ----D---- C:\Documents and Settings\All Users\Application Data\Google
      2009-04-15 17:01:53 ----D---- C:\Program Files\Microsoft Office
      2009-04-15 12:32:23 ----A---- C:\WINDOWS\wininit.ini
      2009-04-15 10:36:16 ----D---- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
      2009-04-15 10:21:37 ----D---- C:\Program Files\Enigma Software Group
      2009-04-15 10:18:01 ----A---- C:\WINDOWS\system32\cabin.dll
      2009-04-15 10:16:22 ----A---- C:\WINDOWS\system32\ati2evx.dll
      2009-04-15 09:51:21 ----HDC---- C:\WINDOWS\$NtUninstallKB959426$
      2009-04-15 09:51:09 ----HDC---- C:\WINDOWS\$NtUninstallKB961373$
      2009-04-15 09:48:34 ----HDC---- C:\WINDOWS\$NtUninstallKB956572$
      2009-04-15 09:48:14 ----HDC---- C:\WINDOWS\$NtUninstallKB952004$
      2009-04-15 09:48:04 ----HDC---- C:\WINDOWS\$NtUninstallKB960803$
      2009-04-15 09:47:46 ----HDC---- C:\WINDOWS\$NtUninstallKB923561$
      2009-04-14 10:44:24 ----A---- C:\WINDOWS\system32\cdosy.dll
      2009-04-14 03:00:24 ----HDC---- C:\WINDOWS\$NtUninstallKB951978$
      2009-04-13 11:45:04 ----D---- C:\WINDOWS\Prefetch
      2009-04-13 10:56:57 ----HDC---- C:\WINDOWS\$NtUninstallKB967715$
      2009-04-13 10:56:41 ----HDC---- C:\WINDOWS\$NtUninstallKB960225$
      2009-04-13 10:56:31 ----HDC---- C:\WINDOWS\$NtUninstallKB958690$
      2009-04-13 10:56:15 ----HDC---- C:\WINDOWS\$NtUninstallKB958687$
      2009-04-13 10:56:00 ----HDC---- C:\WINDOWS\$NtUninstallKB958644$
      2009-04-13 10:55:48 ----HDC---- C:\WINDOWS\$NtUninstallKB957097$
      2009-04-13 10:55:35 ----HDC---- C:\WINDOWS\$NtUninstallKB956841$
      2009-04-13 10:55:22 ----HDC---- C:\WINDOWS\$NtUninstallKB956803$
      2009-04-13 10:55:06 ----HDC---- C:\WINDOWS\$NtUninstallKB956802$
      2009-04-13 10:54:47 ----HDC---- C:\WINDOWS\$NtUninstallKB955069$
      2009-04-13 10:54:34 ----HDC---- C:\WINDOWS\$NtUninstallKB954600$
      2009-04-13 10:54:24 ----HDC---- C:\WINDOWS\$NtUninstallKB952954$
      2009-04-13 10:54:12 ----HDC---- C:\WINDOWS\$NtUninstallKB952287$
      2009-04-13 10:53:56 ----HDC---- C:\WINDOWS\$NtUninstallKB951748$
      2009-04-13 10:53:41 ----HDC---- C:\WINDOWS\$NtUninstallKB951698$
      2009-04-13 10:53:28 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2$
      2009-04-13 10:53:15 ----HDC---- C:\WINDOWS\$NtUninstallKB951066$
      2009-04-13 10:53:00 ----HDC---- C:\WINDOWS\$NtUninstallKB950974$
      2009-04-13 10:52:45 ----HDC---- C:\WINDOWS\$NtUninstallKB950762$
      2009-04-13 10:52:34 ----HDC---- C:\WINDOWS\$NtUninstallKB946648$
      2009-04-13 10:52:23 ----HDC---- C:\WINDOWS\$NtUninstallKB938464-v2$
      2009-04-13 10:47:05 ----D---- C:\WINDOWS\l2schemas
      2009-04-13 10:47:04 ----D---- C:\WINDOWS\system32\fr
      2009-04-13 10:47:03 ----D---- C:\WINDOWS\system32\bits
      2009-04-13 10:43:19 ----D---- C:\WINDOWS\ServicePackFiles
      2009-04-13 10:39:59 ----D---- C:\WINDOWS\network diagnostic
      2009-04-13 10:33:09 ----HDC---- C:\WINDOWS\$NtServicePackUninstall$
      2009-04-13 10:32:52 ----D---- C:\WINDOWS\EHome
      2009-04-13 10:06:03 ----D---- C:\Documents and Settings\Fannette\Application Data\Apple Computer
      2009-04-13 10:04:30 ----D---- C:\Documents and Settings\Fannette\Application Data\AdobeUM
      2009-04-13 10:03:20 ----HDC---- C:\WINDOWS\$NtUninstallKB929399$
      2009-04-13 10:02:24 ----HDC---- C:\WINDOWS\$NtUninstallKB939683$
      2009-04-13 10:01:18 ----D---- C:\Documents and Settings\Fannette\Application Data\ArcSoft
      2009-04-13 10:00:55 ----D---- C:\Program Files\Fichiers communs\ArcSoft
      2009-04-13 10:00:45 ----A---- C:\WINDOWS\PCDLIB32.DLL
      2009-04-13 10:00:31 ----D---- C:\Program Files\QuickTime
      2009-04-13 10:00:06 ----HDC---- C:\WINDOWS\$NtUninstallKB959772_WM11$
      2009-04-13 09:59:15 ----HDC---- C:\WINDOWS\$NtUninstallKB954154_WM11$
      2009-04-13 09:59:07 ----D---- C:\Program Files\Apple Software Update
      2009-04-13 09:58:05 ----D---- C:\WINDOWS\system32\PhotoImpression Slideshow
      2009-04-13 09:58:05 ----D---- C:\Program Files\ArcSoft
      2009-04-13 09:56:58 ----D---- C:\Documents and Settings\All Users\Application Data\Apple Computer
      2009-04-13 09:56:43 ----HDC---- C:\WINDOWS\$NtUninstallKB936782_WMP11$
      2009-04-13 00:49:45 ----A---- C:\WINDOWS\NeroDigital.ini
      2009-04-13 00:46:59 ----HDC---- C:\WINDOWS\$NtUninstallKB926239$
      2009-04-13 00:46:28 ----N---- C:\WINDOWS\system32\spmsg.dll
      2009-04-13 00:46:22 ----HDC---- C:\WINDOWS\$NtUninstallMSCompPackV1$
      2009-04-13 00:45:32 ----D---- C:\Program Files\Windows Media Connect 2
      2009-04-13 00:45:12 ----HDC---- C:\WINDOWS\$NtUninstallwmp11$
      2009-04-13 00:43:51 ----HDC---- C:\WINDOWS\$NtUninstallWMFDist11$
      2009-04-13 00:42:35 ----HDC---- C:\WINDOWS\$NtUninstallWudf01000$
      2009-04-13 00:37:53 ----D---- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
      2009-04-12 23:43:09 ----D---- C:\Documents and Settings\All Users\Application Data\EscapeTheMuseum
      2009-04-12 21:55:15 ----A---- C:\WINDOWS\system32\capico.dll
      2009-04-12 19:48:39 ----A---- C:\WINDOWS\system32\cabine.dll
      2009-04-12 19:01:32 ----HD---- C:\WINDOWS\msdownld.tmp
      2009-04-12 19:01:18 ----D---- C:\WINDOWS\ie8updates
      2009-04-12 18:59:43 ----D---- C:\WINDOWS\WBEM
      2009-04-12 18:56:58 ----HDC---- C:\WINDOWS\ie8
      2009-04-12 18:56:58 ----D---- C:\WINDOWS\system32\fr-FR
      2009-04-12 03:27:17 ----A---- C:\WINDOWS\system32\bat.dll
      2009-04-10 23:02:29 ----A---- C:\WINDOWS\The Hidden Object Show Setup Log.txt
      2009-04-10 22:21:30 ----D---- C:\Documents and Settings\Fannette\Application Data\RobinsonCrusoe
      2009-04-10 22:20:57 ----A---- C:\WINDOWS\Mythic Mahjong Setup Log.txt
      2009-04-06 14:02:13 ----D---- C:\Documents and Settings\All Users\Application Data\MysteryChronicles
      2009-04-06 13:54:02 ----D---- C:\Documents and Settings\All Users\Application Data\Trymedia
      2009-04-05 15:08:01 ----D---- C:\Program Files\EasyPrediction
      2009-04-05 15:04:20 ----D---- C:\Program Files\vghd
      2009-04-05 15:04:20 ----D---- C:\Documents and Settings\Fannette\Application Data\vghd
      2009-04-04 22:09:57 ----D---- C:\Documents and Settings\Fannette\Application Data\cerasus.media
      2009-04-04 17:31:21 ----D---- C:\Documents and Settings\Fannette\Application Data\PlayFirst
      2009-04-04 17:31:21 ----D---- C:\Documents and Settings\All Users\Application Data\PlayFirst
      2009-04-04 09:57:41 ----D---- C:\Program Files\Microsoft CAPICOM 2.1.0.2
      2009-04-04 09:57:30 ----D---- C:\Program Files\MSXML 6.0
      2009-04-04 09:57:05 ----HDC---- C:\WINDOWS\$NtUninstallKB925720$
      2009-04-03 22:06:36 ----D---- C:\Program Files\GameTop.com
      2009-04-03 22:06:14 ----D---- C:\Documents and Settings\All Users\Application Data\MonteCristo
      2009-04-03 22:00:10 ----D---- C:\Program Files\Games
      2009-04-03 21:58:54 ----SHD---- C:\WINDOWS\ftpcache
      2009-04-03 21:57:21 ----D---- C:\Documents and Settings\Fannette\Application Data\Magic Academy
      2009-04-03 19:59:36 ----D---- C:\Documents and Settings\Fannette\Application Data\Big Fish Games
      2009-04-03 19:59:04 ----D---- C:\WINDOWS\Little Shop - City Lights [h33t] [oi812heet]
      2009-04-03 19:26:08 ----D---- C:\Documents and Settings\Fannette\Application Data\Friday's games
      2009-04-03 14:36:00 ----D---- C:\Documents and Settings\Fannette\Application Data\Pirateville
      2009-04-03 14:34:10 ----D---- C:\Documents and Settings\Fannette\Application Data\JoyBits
      2009-04-03 14:24:45 ----D---- C:\Documents and Settings\All Users\Application Data\PlayPond
      2009-04-03 14:11:21 ----D---- C:\Documents and Settings\Fannette\Application Data\Games
      2009-04-03 14:08:16 ----D---- C:\Documents and Settings\All Users\Application Data\Mushroom Age
      2009-04-03 13:47:26 ----D---- C:\Documents and Settings\Fannette\Application Data\Artogon
      2009-04-03 13:29:20 ----D---- C:\Documents and Settings\All Users\Application Data\Alawar Stargaze
      2009-04-03 13:27:25 ----D---- C:\Games
      2009-04-03 11:21:44 ----D---- C:\Documents and Settings\Fannette\Application Data\Meridian93
      2009-04-03 09:38:50 ----A---- C:\WINDOWS\system32\muweb.dll
      2009-04-03 09:38:50 ----A---- C:\WINDOWS\system32\mucltui.dll.mui
      2009-04-03 09:38:50 ----A---- C:\WINDOWS\system32\mucltui.dll
      2009-04-02 21:33:43 ----D---- C:\Documents and Settings\Fannette\Application Data\Flood Light Games
      2009-04-02 21:33:43 ----D---- C:\Documents and Settings\All Users\Application Data\Flood Light Games
      2009-04-02 21:28:38 ----D---- C:\Documents and Settings\Fannette\Application Data\Gogii Games
      2009-04-02 21:28:38 ----D---- C:\Documents and Settings\All Users\Application Data\Gogii Games
      2009-04-02 21:26:22 ----D---- C:\Documents and Settings\All Users\Application Data\Zylom
      2009-04-02 21:26:14 ----D---- C:\Program Files\Zylom Games
      2009-04-02 21:24:23 ----D---- C:\Documents and Settings\All Users\Application Data\JollyBear
      2009-04-02 21:09:21 ----D---- C:\Documents and Settings\All Users\Application Data\AdventureChronicles1
      2009-04-02 21:08:57 ----AD---- C:\Documents and Settings\All Users\Application Data\TEMP
      2009-04-02 19:06:20 ----D---- C:\Documents and Settings\All Users\Application Data\Babylon
      2009-04-02 19:06:19 ----D---- C:\Documents and Settings\Fannette\Application Data\Babylon
      2009-04-02 19:06:10 ----D---- C:\Documents and Settings\Fannette\Application Data\WinRAR
      2009-04-02 18:43:53 ----A---- C:\Program Files\eMule0.49c-Installer.exe
      2009-04-02 18:38:04 ----D---- C:\Program Files\Fichiers communs\Nero
      2009-04-02 18:35:48 ----A---- C:\WINDOWS\system32\NeroCheck.exe
      2009-04-02 18:31:32 ----D---- C:\WINDOWS\system32\LogFiles
      2009-04-02 18:25:57 ----D---- C:\Program Files\MSBuild
      2009-04-02 18:15:12 ----D---- C:\WINDOWS\system32\XPSViewer
      2009-04-02 18:15:10 ----D---- C:\WINDOWS\system32\en-us
      2009-04-02 18:14:08 ----D---- C:\Program Files\Reference Assemblies
      2009-04-02 18:13:28 ----N---- C:\WINDOWS\system32\spmsg2.dll
      2009-04-02 18:12:16 ----D---- C:\a4ea7133e28b9a5f4326caad34
      2009-04-02 18:12:02 ----A---- C:\WINDOWS\system32\d3dx9_30.dll
      2009-04-02 17:36:13 ----D---- C:\Documents and Settings\All Users\Application Data\Ahead
      2009-04-02 17:36:11 ----N---- C:\WINDOWS\system32\picn20.dll
      2009-04-02 17:36:11 ----A---- C:\WINDOWS\system32\TwnLib20.dll
      2009-04-02 17:36:01 ----D---- C:\Program Files\Fichiers communs\Ahead
      2009-04-02 17:35:55 ----D---- C:\Program Files\Ahead
      2009-04-02 17:29:34 ----D---- C:\Program Files\Microsoft Silverlight
      2009-04-02 17:29:09 ----DC---- C:\WINDOWS\system32\DRVSTORE
      2009-04-02 17:23:28 ----D---- C:\Program Files\Microsoft Sync Framework
      2009-04-02 17:22:15 ----A---- C:\WINDOWS\system32\d3dx9_32.dll
      2009-04-02 17:22:05 ----D---- C:\Program Files\Microsoft SQL Server Compact Edition
      2009-04-02 17:21:23 ----HDC---- C:\WINDOWS\$NtUninstallWIC$
      2009-04-02 17:20:05 ----D---- C:\Program Files\Microsoft
      2009-04-02 17:19:32 ----D---- C:\Program Files\Windows Live SkyDrive
      2009-04-02 17:18:49 ----D---- C:\Program Files\Windows Live
      2009-04-02 17:11:35 ----D---- C:\Program Files\Fichiers communs\Windows Live
      2009-04-02 17:10:47 ----A---- C:\Program Files\Installation_WLMessenger2009.exe
      2009-04-02 14:24:06 ----HDC---- C:\WINDOWS\$MSI31Uninstall_KB893803v2$
      2009-04-02 14:23:37 ----A---- C:\Program Files\WindowsInstaller-KB893803-v2-x86.exe
      2009-04-02 14:20:43 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2_0$
      2009-04-02 14:20:23 ----HDC---- C:\WINDOWS\$NtUninstallKB952954_0$
      2009-04-02 14:20:12 ----HDC---- C:\WINDOWS\$NtUninstallKB946648_0$
      2009-04-02 14:19:58 ----HDC---- C:\WINDOWS\$NtUninstallKB956803_0$
      2009-04-02 14:19:39 ----HDC---- C:\WINDOWS\$NtUninstallKB955839$
      2009-04-02 14:19:01 ----HDC---- C:\WINDOWS\$NtUninstallKB958215$
      2009-04-02 14:18:38 ----HDC---- C:\WINDOWS\$NtUninstallKB950974_0$
      2009-04-02 14:18:24 ----HDC---- C:\WINDOWS\$NtUninstallKB951698_0$
      2009-04-02 14:16:33 ----A---- C:\WINDOWS\system32\MRT.exe
      2009-04-02 14:16:22 ----HDC---- C:\WINDOWS\$NtUninstallKB960225_0$
      2009-04-02 14:16:07 ----HDC---- C:\WINDOWS\$NtUninstallKB956841_0$
      2009-04-02 14:15:47 ----HDC---- C:\WINDOWS\$NtUninstallKB960714$
      2009-04-02 14:15:34 ----HDC---- C:\WINDOWS\$NtUninstallKB938464-v2_0$
      2009-04-02 14:15:24 ----HDC---- C:\WINDOWS\$NtUninstallKB952069_WM9$
      2009-04-02 14:15:10 ----HDC---- C:\WINDOWS\$NtUninstallKB941569$
      2009-04-02 14:14:33 ----HDC---- C:\WINDOWS\$NtUninstallKB950762_0$
      2009-04-02 14:14:23 ----HDC---- C:\WINDOWS\$NtUninstallKB957097_0$
      2009-04-02 14:14:12 ----HDC---- C:\WINDOWS\$NtUninstallKB960715$
      2009-04-02 14:13:35 ----HDC---- C:\WINDOWS\$NtUninstallKB923689$
      2009-04-02 14:13:03 ----HDC---- C:\WINDOWS\$NtUninstallKB958687_0$
      2009-04-02 14:12:54 ----HDC---- C:\WINDOWS\$NtUninstallKB952287_0$
      2009-04-02 14:12:33 ----A---- C:\Program Files\wlsetup-web.exe
      2009-04-02 14:12:19 ----HDC---- C:\WINDOWS\$NtUninstallKB967715_0$
      2009-04-02 14:12:03 ----HDC---- C:\WINDOWS\$NtUninstallKB950760$
      2009-04-02 14:11:54 ----HDC---- C:\WINDOWS\$NtUninstallKB951066_0$
      2009-04-02 14:11:36 ----HDC---- C:\WINDOWS\$NtUninstallKB958690_0$
      2009-04-02 14:11:11 ----HDC---- C:\WINDOWS\$NtUninstallKB951748_0$
      2009-04-02 14:08:02 ----HDC---- C:\WINDOWS\$NtUninstallKB954600_0$
      2009-04-02 14:07:51 ----HDC---- C:\WINDOWS\$NtUninstallKB958644_0$
      2009-04-02 14:07:42 ----HDC---- C:\WINDOWS\$NtUninstallKB955069_0$
      2009-04-02 14:07:32 ----HDC---- C:\WINDOWS\$NtUninstallKB956802_0$
      2009-04-02 14:07:12 ----HDC---- C:\WINDOWS\$NtUninstallKB944338-v2$
      2009-04-02 14:06:38 ----HDC---- C:\WINDOWS\$NtUninstallKB936782_WMP10$
      2009-04-02 14:01:26 ----D---- C:\Documents and Settings\Fannette\Application Data\Macromedia
      2009-04-02 13:58:33 ----D---- C:\Program Files\eMule
      2009-04-02 13:58:12 ----A---- C:\Program Files\eMulePlus-1.2d.Installer.exe
      2009-04-02 13:56:33 ----D---- C:\Program Files\WinRAR
      2009-04-02 13:56:17 ----A---- C:\Program Files\wrar380.exe
      2009-04-02 13:22:57 ----D---- C:\Documents and Settings\All Users\Application Data\UDL
      2009-04-02 13:22:05 ----A---- C:\WINDOWS\system32\PICSDK.ini
      2009-04-02 13:22:05 ----A---- C:\WINDOWS\system32\PICSDK.dll
      2009-04-02 13:22:05 ----A---- C:\WINDOWS\system32\EpPicPrt.dll
      2009-04-02 13:22:04 ----A---- C:\WINDOWS\system32\EPPicMgr.dll
      2009-04-02 13:07:43 ----D---- C:\Program Files\epson
      2009-04-02 13:06:28 ----A---- C:\WINDOWS\CDE DX3800EFGIPSD.ini
      2009-04-02 13:05:52 ----A---- C:\WINDOWS\epsswt_log.txt
      2009-04-02 13:03:49 ----D---- C:\WINDOWS\system32\PreInstall
      2009-04-02 13:03:45 ----HDC---- C:\WINDOWS\$NtUninstallKB898461$
      2009-04-02 12:20:57 ----D---- C:\Program Files\SymNetDrv
      2009-04-02 12:16:53 ----D---- C:\WINDOWS\system32\SoftwareDistribution
      2009-04-02 11:46:18 ----D---- C:\WINDOWS\tiinst
      2009-04-02 11:45:10 ----D---- C:\WINDOWS\OPTIONS
      2009-04-02 11:44:35 ----A---- C:\WINDOWS\system32\SynTPFcs.dll
      2009-04-02 11:44:34 ----A---- C:\WINDOWS\system32\SynTPCo2.dll
      2009-04-02 11:44:34 ----A---- C:\WINDOWS\system32\SynTPAPI.dll
      2009-04-02 11:44:33 ----A---- C:\WINDOWS\system32\SynCtrl.dll
      2009-04-02 11:44:33 ----A---- C:\WINDOWS\system32\SynCOM.dll
      2009-04-02 11:44:32 ----D---- C:\Program Files\Synaptics
      2009-04-02 11:44:14 ----D---- C:\Program Files\CONEXANT
      2009-04-02 11:44:08 ----A---- C:\WINDOWS\system32\mdmxsdk.dll
      2009-04-02 11:44:08 ----A---- C:\WINDOWS\system32\hsfci012.dll
      2009-04-02 11:43:02 ----A---- C:\WINDOWS\system32\ksuser.dll
      2009-04-02 11:42:49 ----A---- C:\WINDOWS\system32\RTLCPAPI.dll
      2009-04-02 11:42:48 ----N---- C:\WINDOWS\system32\ChCfg.exe
      2009-04-02 11:42:48 ----A---- C:\WINDOWS\SOUNDMAN.EXE
      2009-04-02 11:42:47 ----A---- C:\WINDOWS\system32\RTLCPL.EXE
      2009-04-02 11:42:45 ----N---- C:\WINDOWS\alcupd.exe
      2009-04-02 11:42:45 ----N---- C:\WINDOWS\alcrmv.exe
      2009-04-02 11:42:42 ----N---- C:\WINDOWS\RtlExUpd.dll
      2009-04-02 11:42:34 ----D---- C:\Program Files\Launch Manager
      2009-04-02 11:41:09 ----D---- C:\Program Files\ATI Technologies
      2009-04-02 11:40:24 ----D---- C:\WINDOWS\system32\ReinstallBackups
      2009-04-02 11:40:20 ----D---- C:\Program Files\AMD
      2009-04-02 11:40:19 ----HD---- C:\Program Files\InstallShield Installation Information
      2009-04-02 11:40:06 ----D---- C:\Program Files\Fichiers communs\InstallShield
      2009-04-02 11:39:50 ----A---- C:\WINDOWS\system32\ativvaxx.dll
      2009-04-02 11:39:50 ----A---- C:\WINDOWS\system32\atitvo32.dll
      2009-04-02 11:39:50 ----A---- C:\WINDOWS\system32\atipdlxx.dll
      2009-04-02 11:39:50 ----A---- C:\WINDOWS\system32\atioglxx.dll
      2009-04-02 11:39:50 ----A---- C:\WINDOWS\system32\atikvmag.dll
      2009-04-02 11:39:50 ----A---- C:\WINDOWS\system32\atiiiexx.dll
      2009-04-02 11:39:50 ----A---- C:\WINDOWS\system32\ATIDEMGR.dll
      2009-04-02 11:39:50 ----A---- C:\WINDOWS\system32\ati3duag.dll
      2009-04-02 11:39:50 ----A---- C:\WINDOWS\system32\Ati2mdxx.exe
      2009-04-02 11:39:50 ----A---- C:\WINDOWS\system32\ati2evxx.exe
      2009-04-02 11:39:50 ----A---- C:\WINDOWS\system32\ati2evxx.dll
      2009-04-02 11:39:50 ----A---- C:\WINDOWS\system32\ati2edxx.dll
      2009-04-02 11:39:49 ----A---- C:\WINDOWS\system32\ati2dvag.dll
      2009-04-02 11:39:49 ----A---- C:\WINDOWS\system32\ati2cqag.dll
      2009-04-02 11:39:21 ----A---- C:\FSC-DeskUpdate.txt
      2009-04-02 11:37:57 ----D---- C:\Documents and Settings\Fannette\Application Data\Adobe
      2009-04-02 11:37:00 ----A---- C:\WINDOWS\system32\odyGina.dll
      2009-04-02 11:36:58 ----A---- C:\WINDOWS\system32\odyEvent.dll
      2009-04-02 11:36:58 ----A---- C:\WINDOWS\system32\odGinaLibrary.dll
      2009-04-02 11:36:43 ----A---- C:\WINDOWS\init.ini
      2009-04-02 11:36:01 ----D---- C:\fsc.tmp
      2009-04-02 11:33:29 ----D---- C:\WINDOWS\RegisteredPackages
      2009-04-02 11:30:50 ----D---- C:\Program Files\Fichiers communs\Adobe
      2009-04-02 11:30:43 ----D---- C:\Documents and Settings\All Users\Application Data\Adobe
      2009-04-02 11:28:15 ----D---- C:\Program Files\Adobe
      2009-04-02 10:56:12 ----D---- C:\Program Files\Norton Internet Security
      2009-04-02 10:55:31 ----D---- C:\Documents and Settings\Fannette\Application Data\Symantec
      2009-04-02 10:54:51 ----A---- C:\WINDOWS\system32\S32EVNT1.DLL
      2009-04-02 10:54:45 ----D---- C:\Program Files\Symantec
      2009-04-02 10:54:45 ----A---- C:\WINDOWS\system32\capicom.dll
      2009-04-02 10:54:39 ----D---- C:\Documents and Settings\All Users\Application Data\Symantec
      2009-04-02 10:54:33 ----D---- C:\Program Files\Fichiers communs\Symantec Shared
      2009-04-02 10:40:44 ----A---- C:\WINDOWS\UPGRADE.TXT
      2009-04-02 10:22:54 ----D---- C:\Program Files\Securitoo
      2009-04-02 03:10:36 ----A---- C:\WINDOWS\system32\h323log.txt
      2009-04-02 02:51:58 ----A---- C:\WINDOWS\system32\usbui.dll
      2009-04-02 02:50:21 ----A---- C:\WINDOWS\imsins.BAK
      2009-04-02 02:50:18 ----SHD---- C:\WINDOWS\Installer
      2009-04-02 02:50:18 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
      2009-04-02 02:50:17 ----D---- C:\Program Files\Fichiers communs\ODBC
      2009-04-02 02:50:17 ----A---- C:\WINDOWS\ODBCINST.INI
      2009-04-02 02:50:12 ----D---- C:\Program Files\Fichiers communs\SpeechEngines
      2009-04-02 02:50:11 ----RD---- C:\Program Files
      2009-04-02 02:50:11 ----D---- C:\Program Files\Fichiers communs\Microsoft Shared
      2009-04-02 02:50:11 ----D---- C:\Program Files\Fichiers communs
      2009-04-02 02:50:07 ----RA---- C:\WINDOWS\system32\kbdtuq.dll
      2009-04-02 02:50:07 ----RA---- C:\WINDOWS\system32\kbdtuf.dll
      2009-04-02 02:50:07 ----RA---- C:\WINDOWS\system32\kbdazel.dll
      2009-04-02 02:50:05 ----RA---- C:\WINDOWS\system32\kbdycc.dll
      2009-04-02 02:50:05 ----RA---- C:\WINDOWS\system32\kbduzb.dll
      2009-04-02 02:50:05 ----RA---- C:\WINDOWS\system32\kbdur.dll
      2009-04-02 02:50:05 ----RA---- C:\WINDOWS\system32\kbdtat.dll
      2009-04-02 02:50:05 ----RA---- C:\WINDOWS\system32\kbdru1.dll
      2009-04-02 02:50:05 ----RA---- C:\WINDOWS\system32\kbdmon.dll
      2009-04-02 02:50:05 ----RA---- C:\WINDOWS\system32\kbdkyr.dll
      2009-04-02 02:50:05 ----RA---- C:\WINDOWS\system32\kbdkaz.dll
      2009-04-02 02:50:05 ----RA---- C:\WINDOWS\system32\kbdaze.dll
      2009-04-02 02:50:04 ----RA---- C:\WINDOWS\system32\kbdru.dll
      2009-04-02 02:50:04 ----RA---- C:\WINDOWS\system32\kbdbu.dll
      2009-04-02 02:50:04 ----RA---- C:\WINDOWS\system32\kbdblr.dll
      2009-04-02 02:50:02 ----RA---- C:\WINDOWS\system32\kbdhept.dll
      2009-04-02 02:50:02 ----RA---- C:\WINDOWS\system32\kbdhela3.dll
      2009-04-02 02:50:02 ----RA---- C:\WINDOWS\system32\kbdhela2.dll
      2009-04-02 02:50:02 ----RA---- C:\WINDOWS\system32\kbdhe319.dll
      2009-04-02 02:50:02 ----RA---- C:\WINDOWS\system32\kbdhe220.dll
      2009-04-02 02:50:02 ----RA---- C:\WINDOWS\system32\kbdhe.dll
      2009-04-02 02:50:02 ----RA---- C:\WINDOWS\system32\kbdgkl.dll
      2009-04-02 02:50:01 ----RA---- C:\WINDOWS\system32\kbdlt1.dll
      2009-04-02 02:50:01 ----RA---- C:\WINDOWS\system32\kbdlt.dll
      2009-04-02 02:50:00 ----RA---- C:\WINDOWS\system32\kbdlv1.dll
      2009-04-02 02:50:00 ----RA---- C:\WINDOWS\system32\kbdlv.dll
      2009-04-02 02:50:00 ----RA---- C:\WINDOWS\system32\kbdest.dll
      2009-04-02 02:49:58 ----RA---- C:\WINDOWS\system32\kbdycl.dll
      2009-04-02 02:49:58 ----RA---- C:\WINDOWS\system32\kbdsl1.dll
      2009-04-02 02:49:58 ----RA---- C:\WINDOWS\system32\kbdsl.dll
      2009-04-02 02:49:58 ----RA---- C:\WINDOWS\system32\kbdro.dll
      2009-04-02 02:49:58 ----RA---- C:\WINDOWS\system32\kbdpl1.dll
      2009-04-02 02:49:58 ----RA---- C:\WINDOWS\system32\kbdpl.dll
      2009-04-02 02:49:58 ----RA---- C:\WINDOWS\system32\kbdhu1.dll
      2009-04-02 02:49:58 ----RA---- C:\WINDOWS\system32\kbdhu.dll
      2009-04-02 02:49:58 ----RA---- C:\WINDOWS\system32\kbdcz2.dll
      2009-04-02 02:49:58 ----RA---- C:\WINDOWS\system32\kbdcz1.dll
      2009-04-02 02:49:58 ----RA---- C:\WINDOWS\system32\kbdcz.dll
      2009-04-02 02:49:58 ----RA---- C:\WINDOWS\system32\kbdcr.dll
      2009-04-02 02:49:58 ----RA---- C:\WINDOWS\system32\KBDAL.DLL
      2009-04-02 02:49:55 ----A---- C:\WINDOWS\system32\irclass.dll
      2009-04-02 02:49:55 ----A---- C:\WINDOWS\system32\dgsetup.dll
      2009-04-02 02:49:55 ----A---- C:\WINDOWS\system32\dgrpsetu.dll
      2009-04-02 02:49:54 ----A---- C:\WINDOWS\system32\spxcoins.dll
      2009-04-02 02:49:54 ----A---- C:\WINDOWS\system32\EqnClass.Dll
      2009-04-02 02:49:52 ----N---- C:\WINDOWS\system32\CONFIG.TMP
      2009-04-02 02:49:52 ----A---- C:\WINDOWS\TASKMAN.EXE
      2009-04-02 02:49:51 ----A---- C:\WINDOWS\notepad.exe
      2009-04-02 02:49:49 ----A---- C:\WINDOWS\system32\storprop.dll
      2009-04-02 02:49:36 ----RA---- C:\WINDOWS\SET29.tmp
      2009-04-02 02:49:36 ----RA---- C:\WINDOWS\SET28.tmp
      2009-04-02 02:49:36 ----RA---- C:\WINDOWS\SET27.tmp
      2009-04-02 02:49:36 ----RA---- C:\WINDOWS\SET26.tmp
      2009-04-02 02:49:36 ----ASH---- C:\Documents and Settings\All Users\Application Data\desktop.ini
      2009-04-02 02:49:35 ----RA---- C:\WINDOWS\SET25.tmp
      2009-04-02 02:49:31 ----RA---- C:\WINDOWS\SET8.tmp
      2009-04-02 02:49:28 ----RA---- C:\WINDOWS\SET4.tmp
      2009-04-02 02:49:25 ----RA---- C:\WINDOWS\SET3.tmp
      2009-04-02 02:49:18 ----D---- C:\WINDOWS\system32\CatRoot2
      2009-04-02 02:49:18 ----D---- C:\WINDOWS\system32\CatRoot
      2009-04-02 02:49:12 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft
      2009-04-02 02:48:44 ----A---- C:\WINDOWS\setuplog.txt
      2009-04-02 02:48:40 ----D---- C:\Documents and Settings
      2009-04-02 02:48:39 ----SHD---- C:\System Volume Information
      2009-04-02 02:47:40 ----SH---- C:\boot.ini
      2009-04-02 02:36:09 ----RSHDC---- C:\WINDOWS\system32\dllcache
      2009-04-02 02:36:09 ----RSD---- C:\WINDOWS\Fonts
      2009-04-02 02:36:09 ----RD---- C:\WINDOWS\Web
      2009-04-02 02:36:09 ----HD---- C:\WINDOWS\inf
      2009-04-02 02:36:09 ----D---- C:\WINDOWS\WinSxS
      2009-04-02 02:36:09 ----D---- C:\WINDOWS\twain_32
      2009-04-02 02:36:09 ----D---- C:\WINDOWS\Temp
      2009-04-02 02:36:09 ----D---- C:\WINDOWS\system32\wins
      2009-04-02 02:36:09 ----D---- C:\WINDOWS\system32\wbem
      2009-04-02 02:36:09 ----D---- C:\WINDOWS\system32\usmt
      2009-04-02 02:36:09 ----D---- C:\WINDOWS\system32\spool
      2009-04-02 02:36:09 ----D---- C:\WINDOWS\system32\ShellExt
      2009-04-02 02:36:09 ----D---- C:\WINDOWS\system32\Setup
      2009-04-02 02:36:09 ----D---- C:\WINDOWS\system32\ras
      2009-04-02 02:36:09 ----D---- C:\WINDOWS\system32\oobe
      2009-04-02 02:36:09 ----D---- C:\WINDOWS\system32\npp
      2009-04-02 02:36:09 ----D---- C:\WINDOWS\system32\mui
      2009-04-02 02:36:09 ----D---- C:\WINDOWS\system32\inetsrv
      2009-04-02 02:36:09 ----D---- C:\WINDOWS\system32\IME
      2009-04-02 02:36:09 ----D---- C:\WINDOWS\system32\icsxml
      2009-04-02 02:36:09 ----D---- C:\WINDOWS\system32\ias
      2009-04-02 02:36:09 ----D---- C:\WINDOWS\system32\export
      2009-04-02 02:36:09 ----D---- C:\WINDOWS\system32\drivers
      2009-04-02 02:36:09 ----D---- C:\WINDOWS\system32\dhcp
      2009-04-02 02:36:09 ----D---- C:\WINDOWS\system32\config
      2009-04-02 02:36:09 ----D---- C:\WINDOWS\system32\3com_dmi
      2009-04-02 02:36:09 ----D---- C:\WINDOWS\system32\3076
      2009-04-02 02:36:09 ----D---- C:\WINDOWS\system32\2052
      2009-04-02 02:36:09 ----D---- C:\WINDOWS\system32\1054
      2009-04-02 02:36:09 ----D---- C:\WINDOWS\system32\1042
      2009-04-02 02:36:09 ----D---- C:\WINDOWS\system32\1041
      2009-04-02 02:36:09 ----D---- C:\WINDOWS\system32\1037
      2009-04-02 02:36:09 ----D---- C:\WINDOWS\system32\1036
      2009-04-02 02:36:09 ----D---- C:\WINDOWS\system32\1033
      2009-04-02 02:36:09 ----D---- C:\WINDOWS\system32\1031
      2009-04-02 02:36:09 ----D---- C:\WINDOWS\system32\1028
      2009-04-02 02:36:09 ----D---- C:\WINDOWS\system32\1025
      2009-04-02 02:36:09 ----D---- C:\WINDOWS\system32
      2009-04-02 02:36:09 ----D---- C:\WINDOWS\system
      2009-04-02 02:36:09 ----D---- C:\WINDOWS\security
      2009-04-02 02:36:09 ----D---- C:\WINDOWS\Resources
      2009-04-02 02:36:09 ----D---- C:\WINDOWS\repair
      2009-04-02 02:36:09 ----D---- C:\WINDOWS\Provisioning
      2009-04-02 02:36:09 ----D---- C:\WINDOWS\PeerNet
      2009-04-02 02:36:09 ----D---- C:\WINDOWS\pchealth
      2009-04-02 02:36:09 ----D---- C:\WINDOWS\OEM
      2009-04-02 02:36:09 ----D---- C:\WINDOWS\mui
      2009-04-02 02:36:09 ----D---- C:\WINDOWS\msapps
      2009-04-02 02:36:09 ----D---- C:\WINDOWS\msagent
      2009-04-02 02:36:09 ----D---- C:\WINDOWS\Media
      2009-04-02 02:36:09 ----D---- C:\WINDOWS\java
      2009-04-02 02:36:09 ----D---- C:\WINDOWS\ime
      2009-04-02 02:36:09 ----D---- C:\WINDOWS\Help
      2009-04-02 02:36:09 ----D---- C:\WINDOWS\Driver Cache
      2009-04-02 02:36:09 ----D---- C:\WINDOWS\Debug
      2009-04-02 02:36:09 ----D---- C:\WINDOWS\Cursors
      2009-04-02 02:36:09 ----D---- C:\WINDOWS\Connection Wizard
      2009-04-02 02:36:09 ----D---- C:\WINDOWS\Config
      2009-04-02 02:36:09 ----D---- C:\WINDOWS\AppPatch
      2009-04-02 02:36:09 ----D---- C:\WINDOWS\addins
      2009-04-02 02:36:09 ----D---- C:\WINDOWS
      2009-04-02 01:41:08 ----SHD---- C:\RECYCLER
      2009-04-02 01:32:04 ----A---- C:\WINDOWS\system32\wmpns.dll
      2009-04-02 01:32:02 ----D---- C:\Documents and Settings\Fannette\Application Data\Identities
      2009-04-02 01:32:00 ----HD---- C:\Program Files\Uninstall Information
      2009-04-02 01:31:50 ----ASH---- C:\Documents and Settings\Fannette\Application Data\desktop.ini
      2009-04-02 01:31:49 ----SD---- C:\Documents and Settings\Fannette\Application Data\Microsoft
      2009-04-02 01:29:41 ----D---- C:\WINDOWS\SoftwareDistribution
      2009-04-02 01:29:39 ----SD---- C:\WINDOWS\system32\Microsoft
      2009-04-02 01:29:39 ----A---- C:\WINDOWS\SchedLgU.Txt
      2009-04-02 01:24:20 ----D---- C:\WINDOWS\system32\xircom
      2009-04-02 01:24:20 ----D---- C:\Program Files\xerox
      2009-04-02 01:24:20 ----D---- C:\Program Files\microsoft frontpage
      2009-04-02 01:23:59 ----A---- C:\WINDOWS\system32\OEMINFO.INI
      2009-04-02 01:23:42 ----A---- C:\WINDOWS\system32\javaws.exe
      2009-04-02 01:23:42 ----A---- C:\WINDOWS\system32\javaw.exe
      2009-04-02 01:23:42 ----A---- C:\WINDOWS\system32\java.exe
      2009-04-02 01:23:23 ----D---- C:\Program Files\Java
      2009-04-02 01:23:21 ----D---- C:\Program Files\Fichiers communs\Java
      2009-04-02 01:21:39 ----RSD---- C:\WINDOWS\assembly
      2009-04-02 01:21:39 ----D---- C:\WINDOWS\Microsoft.NET
      2009-04-02 01:21:38 ----D---- C:\WINDOWS\system32\URTTemp
      2009-04-02 01:20:51 ----D---- C:\WINDOWS\fsc
      2009-04-02 01:20:28 ----D---- C:\AddOn
      2009-04-02 01:19:51 ----HD---- C:\WINDOWS\$hf_mig$
      2009-04-02 01:19:45 ----A---- C:\WINDOWS\system32\spupdsvc.exe
      2009-04-02 01:19:27 ----A---- C:\WINDOWS\control.ini
      2009-04-02 01:19:27 ----A---- C:\AUTOEXEC.BAT
      2009-04-02 01:19:05 ----A---- C:\WINDOWS\OEWABLog.txt
      2009-04-02 01:18:58 ----A---- C:\WINDOWS\system32\mapi32.dll
      2009-04-02 01:17:34 ----SD---- C:\WINDOWS\Downloaded Program Files
      2009-04-02 01:17:34 ----RD---- C:\WINDOWS\Offline Web Pages
      2009-04-02 01:17:34 ----RAH---- C:\WINDOWS\system32\logonui.exe.manifest
      2009-04-02 01:17:23 ----RAH---- C:\WINDOWS\system32\cdplayer.exe.manifest
      2009-04-02 01:17:16 ----HD---- C:\Program Files\WindowsUpdate
      2009-04-02 01:17:10 ----D---- C:\Program Files\Services en ligne
      2009-04-02 01:16:45 ----D---- C:\WINDOWS\system32\DirectX
      2009-04-02 01:16:18 ----A---- C:\WINDOWS\system32\atrace.dll
      2009-04-02 01:16:14 ----A---- C:\WINDOWS\system32\desktop.ini
      2009-04-02 01:16:14 ----A---- C:\WINDOWS\desktop.ini
      2009-04-02 01:16:07 ----A---- C:\WINDOWS\system32\nmevtmsg.dll
      2009-04-02 01:16:05 ----D---- C:\Program Files\Fichiers communs\Services
      2009-04-02 01:16:05 ----A---- C:\WINDOWS\system32\acctres.dll
      2009-04-02 01:16:02 ----SD---- C:\WINDOWS\Tasks
      2009-04-02 01:16:02 ----A---- C:\WINDOWS\system32\icfgnt5.dll
      2009-04-02 01:16:01 ----D---- C:\Program Files\Fichiers communs\MSSoap
      2009-04-02 01:15:55 ----D---- C:\WINDOWS\srchasst
      2009-04-02 01:15:54 ----D---- C:\WINDOWS\system32\Macromed
      2009-04-02 01:15:50 ----A---- C:\WINDOWS\system32\wuweb.dll
      2009-04-02 01:15:50 ----A---- C:\WINDOWS\system32\wucltui.dll
      2009-04-02 01:15:50 ----A---- C:\WINDOWS\system32\wuauserv.dll
      2009-04-02 01:15:50 ----A---- C:\WINDOWS\system32\wuaueng1.dll
      2009-04-02 01:15:49 ----A---- C:\WINDOWS\system32\wups.dll
      2009-04-02 01:15:49 ----A---- C:\WINDOWS\system32\wuaueng.dll
      2009-04-02 01:15:49 ----A---- C:\WINDOWS\system32\wuauclt1.exe
      2009-04-02 01:15:49 ----A---- C:\WINDOWS\system32\wuauclt.exe
      2009-04-02 01:15:49 ----A---- C:\WINDOWS\system32\wuapi.dll
      2009-04-02 01:15:49 ----A---- C:\WINDOWS\system32\bitsprx3.dll
      2009-04-02 01:15:48 ----A---- C:\WINDOWS\system32\qmgrprxy.dll
      2009-04-02 01:15:48 ----A---- C:\WINDOWS\system32\qmgr.dll
      2009-04-02 01:15:48 ----A---- C:\WINDOWS\system32\bitsprx2.dll
      2009-04-02 01:15:42 ----D---- C:\Program Files\Movie Maker
      2009-04-02 01:15:38 ----A---- C:\WINDOWS\system32\safrslv.dll
      2009-04-02 01:15:38 ----A---- C:\WINDOWS\system32\safrdm.dll
      2009-04-02 01:15:38 ----A---- C:\WINDOWS\system32\safrcdlg.dll
      2009-04-02 01:15:38 ----A---- C:\WINDOWS\system32\racpldlg.dll
      2009-04-02 01:15:32 ----D---- C:\WINDOWS\system32\Restore
      2009-04-02 01:15:32 ----A---- C:\WINDOWS\system32\srsvc.dll
      2009-04-02 01:15:32 ----A---- C:\WINDOWS\system32\srrstr.dll
      2009-04-02 01:15:32 ----A---- C:\WINDOWS\system32\fltmc.exe
      2009-04-02 01:15:32 ----A---- C:\WINDOWS\system32\fltlib.dll
      2009-04-02 01:15:31 ----A---- C:\WINDOWS\system32\srclient.dll
      2009-04-02 01:15:31 ----A---- C:\WINDOWS\system32\ils.dll
      2009-04-02 01:15:30 ----A---- C:\WINDOWS\system32\nmmkcert.dll
      2009-04-02 01:15:30 ----A---- C:\WINDOWS\system32\msconf.dll
      2009-04-02 01:15:30 ----A---- C:\WINDOWS\system32\mnmsrvc.exe
      2009-04-02 01:15:30 ----A---- C:\WINDOWS\system32\mnmdd.dll
      2009-04-02 01:15:30 ----A---- C:\WINDOWS\system32\isrdbg32.dll
      2009-04-02 01:15:27 ----D---- C:\Program Files\NetMeeting
      2009-04-02 01:15:27 ----A---- C:\WINDOWS\system32\msoert2.dll
      2009-04-02 01:15:26 ----A---- C:\WINDOWS\system32\msoeacct.dll
      2009-04-02 01:15:25 ----A---- C:\WINDOWS\system32\inetres.dll
      2009-04-02 01:15:25 ----A---- C:\WINDOWS\system32\inetcomm.dll
      2009-04-02 01:15:22 ----D---- C:\Program Files\Outlook Express
      2009-04-02 01:15:22 ----A---- C:\WINDOWS\system32\schedsvc.dll
      2009-04-02 01:15:22 ----A---- C:\WINDOWS\system32\mstinit.exe
      2009-04-02 01:15:22 ----A---- C:\WINDOWS\system32\mstask.dll
      2009-04-02 01:15:21 ----A---- C:\WINDOWS\system32\isign32.dll
      2009-04-02 01:15:21 ----A---- C:\WINDOWS\system32\inetcfg.dll
      2009-04-02 01:15:21 ----A---- C:\WINDOWS\system32\icwphbk.dll
      2009-04-02 01:15:21 ----A---- C:\WINDOWS\system32\icwdial.dll
      2009-04-02 01:15:14 ----D---- C:\Program Files\Fichiers communs\System
      2009-04-02 01:15:07 ----D---- C:\Program Files\Internet Explorer
      2009-04-02 01:14:48 ----D---- C:\Program Files\ComPlus Applications
      2009-04-02 01:14:45 ----A---- C:\WINDOWS\vbaddin.ini
      2009-04-02 01:14:45 ----A---- C:\WINDOWS\vb.ini
      2009-04-02 01:14:37 ----D---- C:\WINDOWS\Registration
      2009-04-02 01:13:48 ----D---- C:\Program Files\Online Services
      2009-04-02 01:13:47 ----D---- C:\Program Files\Windows Media Player
      2009-04-02 01:13:39 ----D---- C:\Program Files\Messenger
      2009-04-02 01:13:34 ----D---- C:\Program Files\MSN Gaming Zone
      2009-04-02 01:13:34 ----A---- C:\WINDOWS\system32\write.exe
      2009-04-02 01:13:23 ----A---- C:\WINDOWS\system32\sndvol32.exe
      2009-04-02 01:13:23 ----A---- C:\WINDOWS\system32\hticons.dll
      2009-04-02 01:13:23 ----A---- C:\WINDOWS\system32\avwav.dll
      2009-04-02 01:13:23 ----A---- C:\WINDOWS\system32\avtapi.dll
      2009-04-02 01:13:23 ----A---- C:\WINDOWS\system32\avmeter.dll
      2009-04-02 01:13:22 ----A---- C:\WINDOWS\system32\winchat.exe
      2009-04-02 01:13:15 ----A---- C:\WINDOWS\system32\getuname.dll
      2009-04-02 01:13:14 ----A---- C:\WINDOWS\system32\sol.exe
      2009-04-02 01:13:14 ----A---- C:\WINDOWS\system32\charmap.exe
      2009-04-02 01:13:14 ----A---- C:\WINDOWS\system32\calc.exe
      2009-04-02 01:13:13 ----A---- C:\WINDOWS\system32\winmine.exe
      2009-04-02 01:13:13 ----A---- C:\WINDOWS\system32\usrlogon.cmd
      2009-04-02 01:13:13 ----A---- C:\WINDOWS\system32\reset.exe
      2009-04-02 01:13:13 ----A---- C:\WINDOWS\system32\mshearts.exe
      2009-04-02 01:13:13 ----A---- C:\WINDOWS\system32\freecell.exe
      2009-04-02 01:13:12 ----A---- C:\WINDOWS\system32\tsshutdn.exe
      2009-04-02 01:13:12 ----A---- C:\WINDOWS\system32\tslabels.ini
      2009-04-02 01:13:12 ----A---- C:\WINDOWS\system32\tskill.exe
      2009-04-02 01:13:12 ----A---- C:\WINDOWS\system32\tsdiscon.exe
      2009-04-02 01:13:12 ----A---- C:\WINDOWS\system32\tscon.exe
      2009-04-02 01:13:12 ----A---- C:\WINDOWS\system32\shadow.exe
      2009-04-02 01:13:12 ----A---- C:\WINDOWS\system32\rwinsta.exe
      2009-04-02 01:13:12 ----A---- C:\WINDOWS\system32\regini.exe
      2009-04-02 01:13:12 ----A---- C:\WINDOWS\system32\rdpcfgex.dll
      2009-04-02 01:13:12 ----A---- C:\WINDOWS\system32\qwinsta.exe
      2009-04-02 01:13:12 ----A---- C:\WINDOWS\system32\qappsrv.exe
      2009-04-02 01:13:12 ----A---- C:\WINDOWS\system32\msg.exe
      2009-04-02 01:13:11 ----A---- C:\WINDOWS\system32\msdtcprf.ini
      2009-04-02 01:13:11 ----A---- C:\WINDOWS\system32\logoff.exe
      2009-04-02 01:13:11 ----A---- C:\WINDOWS\system32\cdmodem.dll
      2009-04-02 01:13:10 ----A---- C:\WINDOWS\system32\stclient.dll
      2009-04-02 01:13:10 ----A---- C:\WINDOWS\system32\mtxlegih.dll
      2009-04-02 01:13:10 ----A---- C:\WINDOWS\system32\mtxex.dll
      2009-04-02 01:13:10 ----A---- C:\WINDOWS\system32\mtxdm.dll
      2009-04-02 01:13:10 ----A---- C:\WINDOWS\system32\dcomcnfg.exe
      2009-04-02 01:13:10 ----A---- C:\WINDOWS\system32\comrepl.dll
      2009-04-02 01:13:10 ----A---- C:\WINDOWS\system32\comaddin.dll
      2009-04-02 01:13:09 ----A---- C:\WINDOWS\system32\comsnap.dll
      2009-04-02 01:13:04 ----A---- C:\WINDOWS\system32\wmimgmt.msc
      2009-04-02 01:12:45 ----D---- C:\Program Files\MSN
      2009-04-02 01:12:44 ----A---- C:\WINDOWS\system32\sndrec32.exe
      2009-04-02 01:12:44 ----A---- C:\WINDOWS\system32\accwiz.exe
      2009-04-02 01:12:43 ----D---- C:\Program Files\Windows NT
      2009-04-02 01:12:43 ----A---- C:\WINDOWS\system32\mplay32.exe
      2009-04-02 01:12:43 ----A---- C:\WINDOWS\system32\hypertrm.dll
      2009-04-02 01:12:42 ----A---- C:\WINDOWS\system32\spider.exe
      2009-04-02 01:12:42 ----A---- C:\WINDOWS\system32\mspaint.exe
      2009-04-02 01:12:42 ----A---- C:\WINDOWS\system32\clipbrd.exe
      2009-04-02 01:12:41 ----A---- C:\WINDOWS\system32\tscfgwmi.dll
      2009-04-02 01:12:41 ----A---- C:\WINDOWS\system32\mstscax.dll
      2009-04-02 01:12:40 ----A---- C:\WINDOWS\system32\tscupgrd.exe
      2009-04-02 01:12:40 ----A---- C:\WINDOWS\system32\sessmgr.exe
      2009-04-02 01:12:40 ----A---- C:\WINDOWS\system32\remotepg.dll
      2009-04-02 01:12:40 ----A---- C:\WINDOWS\system32\rdshost.exe
      2009-04-02 01:12:40 ----A---- C:\WINDOWS\system32\rdsaddin.exe
      2009-04-02 01:12:40 ----A---- C:\WINDOWS\system32\rdchost.dll
      2009-04-02 01:12:40 ----A---- C:\WINDOWS\system32\mstsc.exe
      2009-04-02 01:12:39 ----D---- C:\WINDOWS\system32\MsDtc
      2009-04-02 01:12:39 ----A---- C:\WINDOWS\system32\termsrv.dll
      2009-04-02 01:12:39 ----A---- C:\WINDOWS\system32\rdpwsx.dll
      2009-04-02 01:12:39 ----A---- C:\WINDOWS\system32\rdpsnd.dll
      2009-04-02 01:12:39 ----A---- C:\WINDOWS\system32\rdpclip.exe
      2009-04-02 01:12:39 ----A---- C:\WINDOWS\system32\qprocess.exe
      2009-04-02 01:12:39 ----A---- C:\WINDOWS\system32\icaapi.dll
      2009-04-02 01:12:39 ----A---- C:\WINDOWS\system32\cfgbkend.dll
      2009-04-02 01:12:38 ----A---- C:\WINDOWS\system32\mtxoci.dll
      2009-04-02 01:12:38 ----A---- C:\WINDOWS\system32\msdtcuiu.dll
      2009-04-02 01:12:38 ----A---- C:\WINDOWS\system32\msdtctm.dll
      2009-04-02 01:12:38 ----A---- C:\WINDOWS\system32\msdtcprx.dll
      2009-04-02 01:12:37 ----A---- C:\WINDOWS\system32\xolehlp.dll
      2009-04-02 01:12:37 ----A---- C:\WINDOWS\system32\msdtclog.dll
      2009-04-02 01:12:37 ----A---- C:\WINDOWS\system32\msdtc.exe
      2009-04-02 01:12:36 ----D---- C:\WINDOWS\system32\Com
      2009-04-02 01:12:36 ----A---- C:\WINDOWS\system32\colbact.dll
      2009-04-02 01:12:36 ----A---- C:\WINDOWS\system32\clbcatex.dll
      2009-04-02 01:12:36 ----A---- C:\WINDOWS\system32\catsrvut.dll
      2009-04-02 01:12:36 ----A---- C:\WINDOWS\system32\catsrvps.dll
      2009-04-02 01:12:36 ----A---- C:\WINDOWS\system32\catsrv.dll
      2009-04-02 01:12:35 ----A---- C:\WINDOWS\system32\comuid.dll
      2009-04-02 01:12:35 ----A---- C:\WINDOWS\system32\comsvcs.dll
      2009-04-02 01:12:34 ----A---- C:\WINDOWS\system32\clbcatq.dll
      2009-04-02 01:12:27 ----A---- C:\WINDOWS\system32\servdeps.dll
      2009-04-02 01:12:27 ----A---- C:\WINDOWS\system32\mmfutil.dll
      2009-04-02 01:12:27 ----A---- C:\WINDOWS\system32\licwmi.dll
      2009-04-02 01:12:27 ----A---- C:\WINDOWS\system32\cmprops.dll

      ======List of files/folders modified in the last 1 months======

      2009-04-13 00:45:47 ----A---- C:\WINDOWS\win.ini
      2009-04-02 02:50:10 ----A---- C:\WINDOWS\system.ini
      2009-03-21 16:07:58 ----A---- C:\WINDOWS\system32\kernel32.dll

      ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

      R1 AmdK8;Pilote de processeur AMD; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2004-08-11 43520]
      R1 eeCtrl;Symantec Eraser Control driver; \??\C:\Program Files\Fichiers communs\Symantec Shared\EENGINE\eeCtrl.sys []
      R1 Hotkey;Hotkey; C:\WINDOWS\system32\drivers\Hotkey.sys [2003-04-28 9867]
      R1 SAVRTPEL;SAVRTPEL; \??\C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVRTPEL.SYS []
      R1 SPBBCDrv;SPBBCDrv; \??\C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCDrv.sys []
      R1 SYMTDI;SYMTDI; C:\WINDOWS\System32\Drivers\SYMTDI.SYS [2007-03-28 266552]
      R1 WmiAcpi;Interface de gestion Microsoft Windows pour ACPI; C:\WINDOWS\system32\DRIVERS\wmiacpi.sys [2008-04-13 8832]
      R2 fssfltr;FssFltr; C:\WINDOWS\system32\DRIVERS\fssfltr_tdi.sys [2009-02-06 55152]
      R2 mdmxsdk;mdmxsdk; C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys [2004-03-17 13059]
      R3 Afc;PPdus ASPI Shell; C:\WINDOWS\system32\drivers\Afc.sys [2005-02-23 11776]
      R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2005-03-25 2314560]
      R3 AR5211;Atheros Wireless Network Adapter Service; C:\WINDOWS\system32\DRIVERS\ar5211.sys [2005-05-05 463168]
      R3 Arp1394;Protocole client ARP 1394; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-13 60800]
      R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2005-04-05 1035776]
      R3 CmBatt;Pilote d'adaptateur secteur Microsoft; C:\WINDOWS\system32\DRIVERS\CmBatt.sys [2008-04-13 13952]
      R3 hidusb;Pilote de classe HID Microsoft; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
      R3 HSF_DP;HSF_DP; C:\WINDOWS\system32\DRIVERS\HSF_DP.sys [2004-12-15 1038208]
      R3 HSFHWATI;HSFHWATI; C:\WINDOWS\system32\DRIVERS\HSFHWATI.sys [2004-12-15 200192]
      R3 mouhid;Pilote HID de souris; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2004-08-05 12288]
      R3 NAVENG;NAVENG; \??\C:\PROGRA~1\FICHIE~1\SYMANT~1\VIRUSD~1\20090415.003\NAVENG.Sys []
      R3 NAVEX15;NAVEX15; \??\C:\PROGRA~1\FICHIE~1\SYMANT~1\VIRUSD~1\20090415.003\NavEx15.Sys []
      R3 NIC1394;Pilote réseau 1394; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-13 61824]
      R3 RTL8023xp;Realtek RTL8139/810x/8169/8110 all in one NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtlnicxp.sys [2004-12-02 70912]
      R3 SAVRT;SAVRT; \??\C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVRT.SYS []
      R3 SYMDNS;SYMDNS; C:\WINDOWS\System32\Drivers\SYMDNS.SYS [2007-03-28 11480]
      R3 SymEvent;SymEvent; \??\C:\Program Files\Symantec\SYMEVENT.SYS []
      R3 SYMFW;SYMFW; C:\WINDOWS\System32\Drivers\SYMFW.SYS [2007-03-28 171928]
      R3 SYMIDS;SYMIDS; C:\WINDOWS\System32\Drivers\SYMIDS.SYS [2007-03-28 37016]
      R3 SYMIDSCO;SYMIDSCO; \??\C:\PROGRA~1\FICHIE~1\SYMANT~1\SymcData\idsdefs\20090407.002\symidsco.sys []
      R3 SYMNDIS;SYMNDIS; C:\WINDOWS\System32\Drivers\SYMNDIS.SYS [2007-03-28 47192]
      R3 SYMREDRV;SYMREDRV; C:\WINDOWS\System32\Drivers\SYMREDRV.SYS [2007-03-28 18904]
      R3 SynTP;Synaptics TouchPad Driver; C:\WINDOWS\system32\DRIVERS\SynTP.sys [2005-03-18 188928]
      R3 tifm21;tifm21; C:\WINDOWS\system32\drivers\tifm21.sys [2005-02-16 146304]
      R3 usbehci;Pilote miniport de contrôleur d'hôte amélioré Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
      R3 usbhub;Concentrateur USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
      R3 usbohci;Pilote miniport de contrôleur hôte ouvert USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbohci.sys [2008-04-13 17152]
      R3 winachsf;winachsf; C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys [2004-12-15 703232]
      S1 mailKmd;mailKmd; C:\WINDOWS\system32\drivers\mailKmd.sys []
      S1 Wbutton;Wbutton; C:\WINDOWS\system32\drivers\Wbutton.sys []
      S2 asc3550p;asc3550p; C:\WINDOWS\system32\drivers\asc3550p.sys []
      S3 aujasnkj;aujasnkj; \??\C:\DOCUME~1\Fannette\LOCALS~1\Temp\aujasnkj.sys []
      S3 EraserUtilDrv10910;EraserUtilDrv10910; \??\C:\Program Files\Fichiers communs\Symantec Shared\EENGINE\EraserUtilDrv10910.sys []
      S3 odysseyIM4;Odyssey Network Agent Miniport; C:\WINDOWS\system32\DRIVERS\odysseyIM4.sys [2005-05-18 173056]
      S3 rtl8139;Pilote NT de carte Realtek PCI Fast Ethernet à base RTL8139(A/B/C); C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2004-08-04 20992]
      S3 usbccgp;Pilote parent générique USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
      S3 usbprint;Classe d'imprimantes USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
      S3 USBSTOR;Pilote de stockage de masse USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
      S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
      S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
      S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []

      ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

      R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2005-04-05 364544]
      R2 ccEvtMgr;Symantec Event Manager; C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe [2008-02-12 185680]
      R2 ccProxy;Symantec Network Proxy; C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe [2006-07-31 239264]
      R2 ccSetMgr;Symantec Settings Manager; C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe [2008-02-12 177488]
      R2 ISSVC;ISSvc; C:\Program Files\Norton Internet Security\ISSVC.exe [2005-05-06 83584]
      R2 navapsvc;Service Norton AntiVirus Auto-Protect; C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe [2007-01-12 128624]
      R2 Planificateur LiveUpdate automatique;Planificateur LiveUpdate automatique; C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe [2006-08-03 100032]
      R2 SeaPort;SeaPort; C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-01-14 226656]
      R2 SNDSrvc;Symantec Network Drivers Service; C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe [2007-03-28 206552]
      R2 SPBBCSvc;Symantec SPBBCSvc; C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe [2005-03-30 992864]
      S2 SBService;ScriptBlocking Service; C:\PROGRA~1\FICHIE~1\SYMANT~1\SCRIPT~1\SBServ.exe [2005-11-04 67184]
      S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2005-09-23 29896]
      S3 ccPwdSvc;Symantec Password Validation; C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe [2008-02-12 83280]
      S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2005-09-23 66240]
      S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe [2006-10-20 36864]
      S3 fsssvc;Windows Live Contrôle parental; C:\Program Files\Windows Live\Family Safety\fsssvc.exe [2009-02-06 533360]
      S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-04-15 137200]
      S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2006-10-30 741376]
      S3 LiveUpdate;LiveUpdate; C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE [2006-08-03 2119360]
      S3 SAVScan;SAVScan; C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe [2005-10-10 198368]
      S3 WMPNetworkSvc;Service Partage réseau du Lecteur Windows Media; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-11-03 918016]
      S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
      S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2006-10-30 122880]

      -----------------EOF-----------------
      0
      1. Et voici le deuxième rapport info.txt:

        info.txt logfile of random's system information tool 1.06 2009-04-17 10:45:57

        ======Uninstall list======

        -->C:\Program Files\Ahead\nero\uninstall\UNNERO.exe /UNINSTALL
        -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
        10 Jours Sous Les Mers-->"C:\Games\10 Jours Sous Les Mers\uninstall.exe"
        Abra Academy-->"C:\Games\Abra Academy\uninstall.exe"
        Adobe Acrobat 7.0.1 and Reader 7.0.1 Update-->MsiExec.exe /I{AC76BA86-0000-7EC8-7489-000000000702}
        Adobe Acrobat 7.0.2 and Reader 7.0.2 Update-->MsiExec.exe /I{AC76BA86-0000-7EC8-7489-000000000703}
        Adobe Flash Player 10 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
        Adobe Reader 7.0 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A70000000000}
        Agatha Christie - Death on the Nile-->C:\Program Files\Agatha Christie - Death on the Nile\Uninstal.exe
        Alabama Smith - Escape from Pompeii-->"C:\Games\Alabama Smith - Escape from Pompeii\uninstall.exe"
        Animal Agents-->"C:\Games\Animal Agents\uninstall.exe"
        Apple Software Update-->MsiExec.exe /I{A260B422-70E1-41E2-957D-F76FA21266D5}
        ArcSoft PhotoImpression 6-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9092875A-D6E1-4B76-84F5-F9C0C6E14D10}\Setup.exe" -l0x40c
        Assistant de connexion Windows Live-->MsiExec.exe /I{DCE8CD14-FBF5-4464-B9A4-E18E473546C7}
        Athlon 64 Processor Driver-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C151CE54-E7EA-4804-854B-F515368B0798}\setup.exe" -l0x40c
        ATI - Utilitaire de désinstallation du logiciel-->C:\Program Files\ATI Technologies\UninstallAll\AtiCimUn.exe
        ATI Control Panel-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{0BEDBD4E-2D34-47B5-9973-57E62B29307C}\setup.exe"
        ATI Display Driver-->rundll32 C:\WINDOWS\system32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
        Azada - Ancient Magic-->"C:\Games\Azada - Ancient Magic\uninstall.exe"
        Big City Adventure - Sydney Australia-->"C:\Games\Big City Adventure - Sydney Australia\uninstall.exe"
        Big City Adventure - Sydney Deluxe-->"C:\Program Files\Zylom Games\Big City Adventure - Sydney Deluxe\GameInstlr.exe" --uninstall UnInstall.log
        CC_ccProxyExt-->MsiExec.exe /I{DA42FDCA-7C5A-43EF-9A05-CCE148ADF919}
        ccCommon-->MsiExec.exe /I{D8F6834B-D5E7-4451-8681-B051ABD8561D}
        ccPxyCore-->MsiExec.exe /I{FC08587A-4F01-4188-819F-F55880022917}
        Choice Guard-->MsiExec.exe /I{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}
        Cooking Quest-->"C:\Games\Cooking Quest\uninstall.exe"
        Correctif pour Lecteur Windows Media 11 (KB939683)-->"C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
        Correctif pour Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
        Dream Chronicles-->"C:\Games\Dream Chronicles\uninstall.exe"
        EasyPrediction-->C:\Program Files\EasyPrediction\2.0\Uninstall.exe
        eMule-->"C:\Program Files\eMule\Uninstall.exe"
        EPSON Logiciel imprimante-->C:\WINDOWS\System32\spool\DRIVERS\W32X86\EPUPDATE.EXE /r
        ESDX3800 Guide d'utilisation-->C:\Program Files\EPSON\TPMANUAL\ESDX3800\USE_G\DOCUNINS.EXE
        G.H.O.S.T. Hunters - The Haunting of Majesty Manor-->"C:\Games\G.H.O.S.T. Hunters - The Haunting of Majesty Manor\uninstall.exe"
        Galerie de photos Windows Live-->MsiExec.exe /X{44E54A81-9D91-4AA1-9417-80AFF134F5FF}
        Google Toolbar for Internet Explorer-->"C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_0531C63A913CC9D1.exe" /uninstall
        Haunted Hotel-->"C:\Games\Haunted Hotel\uninstall.exe"
        Hidden Expedition - Amazon-->"C:\Games\Hidden Expedition - Amazon\uninstall.exe"
        Hidden Expedition - Everest-->"C:\Games\Hidden Expedition - Everest\uninstall.exe"
        Hidden World Of Art 1.00-->C:\Documents and Settings\Fannette\Bureau\HIDDEN OBJECTS\Hidden World Of Art\Uninstall.exe
        Hide and Secret-->"C:\Games\Hide and Secret\uninstall.exe"
        Home Sweet Home-->"C:\Games\uninstall.exe"
        Hotfix for Windows Media Format 11 SDK (KB929399)-->"C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
        Installation Windows Live-->C:\Program Files\Windows Live\Installer\wlarp.exe
        Installation Windows Live-->MsiExec.exe /I{7370DF47-B4F9-4279-BFC3-3F09919F720D}
        J2SE Runtime Environment 5.0-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150000}
        Junk Mail filter update-->MsiExec.exe /I{4DE3E3D9-AE81-45DE-9195-3015F7B1DBF3}
        La maison du péril-->C:\Program Files\La maison du péril\Uninstal.exe
        Launch Manager V1.3.4-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D0846526-66DD-4DC9-A02C-98F9A2806812}\Setup.exe" -l0x40c
        Le Comte de Monte Cristo-->"C:\Games\Le Comte de Monte Cristo\uninstall.exe"
        Le Periple de Cassandra - L'Heritage de Nostradamus Cracked by -->"C:\Program Files\Le Periple de Cassandra - L'Heritage de Nostradamus\unins000.exe"
        Lecteur Windows Media 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
        Les Chasseurs de Tresor - Reves d'Or-->"C:\Games\uninstall.exe"
        Little Shop - City Lights [h33t] [oi812heet]-->"C:\WINDOWS\Little Shop - City Lights [h33t] [oi812heet]\uninstall.exe" "/U:C:\Program Files\Little Shop - City Lights [h33t] [oi812heet]\Uninstall\uninstall.xml"
        LiveReg (Symantec Corporation)-->C:\Program Files\Fichiers communs\Symantec Shared\LiveReg\VCSetup.exe /REMOVE
        LiveUpdate 3.0 (Symantec Corporation)-->"C:\Program Files\Symantec\LiveUpdate\LSETUP.EXE" /U
        Magic Academy-->"C:\Games\Magic Academy\uninstall.exe"
        Magic Encyclopedia-->"C:\Games\Magic Encyclopedia\uninstall.exe"
        Microsoft .NET Framework 1.1 French Language Pack-->MsiExec.exe /X{9A394342-4A68-4EBA-85A6-55B559F4E700}
        Microsoft .NET Framework 1.1 Hotfix (KB928366)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"
        Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
        Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
        Microsoft .NET Framework 2.0-->C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.exe
        Microsoft .NET Framework 3.0-->c:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\setup.exe
        Microsoft .NET Framework 3.0-->MsiExec.exe /X{15095BF3-A3D7-4DDF-B193-3A496881E003}
        Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
        Microsoft Office PowerPoint Viewer 2003-->MsiExec.exe /X{90AF040C-6000-11D3-8CFE-0150048383C9}
        Microsoft Search Enhancement Pack-->MsiExec.exe /I{9C9CEB9D-53FD-49A7-85D2-FE674F72F24E}
        Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
        Microsoft SQL Server 2005 Compact Edition [ENU]-->MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
        Microsoft Sync Framework Runtime Native v1.0 (x86)-->MsiExec.exe /I{8A74E887-8F0F-4017-AF53-CBA42211AAA5}
        Microsoft Sync Framework Services Native v1.0 (x86)-->MsiExec.exe /I{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}
        Microsoft User-Mode Driver Framework Feature Pack 1.0-->"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
        Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
        Mise à jour critique pour Lecteur Windows Media 11 (KB959772)-->"C:\WINDOWS\$NtUninstallKB959772_WM11$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Lecteur Windows Media (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Lecteur Windows Media 10 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP10$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Lecteur Windows Media 11 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Lecteur Windows Media 11 (KB954154)-->"C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB923561)-->"C:\WINDOWS\$NtUninstallKB923561$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB923789)-->C:\WINDOWS\system32\MacroMed\Flash\genuinst.exe C:\WINDOWS\system32\MacroMed\Flash\KB923789.inf
        Mise à jour de sécurité pour Windows XP (KB938464-v2)-->"C:\WINDOWS\$NtUninstallKB938464-v2$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB950760)-->"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB952004)-->"C:\WINDOWS\$NtUninstallKB952004$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB954600)-->"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB956572)-->"C:\WINDOWS\$NtUninstallKB956572$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB956841)-->"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB958215)-->"C:\WINDOWS\$NtUninstallKB958215$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB958687)-->"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB958690)-->"C:\WINDOWS\$NtUninstallKB958690$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB959426)-->"C:\WINDOWS\$NtUninstallKB959426$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB960225)-->"C:\WINDOWS\$NtUninstallKB960225$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB960714)-->"C:\WINDOWS\$NtUninstallKB960714$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB960715)-->"C:\WINDOWS\$NtUninstallKB960715$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB960803)-->"C:\WINDOWS\$NtUninstallKB960803$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB961373)-->"C:\WINDOWS\$NtUninstallKB961373$\spuninst\spuninst.exe"
        Mise à jour pour Windows Internet Explorer 8 (KB968220)-->"C:\WINDOWS\ie8updates\KB968220-IE8\spuninst\spuninst.exe"
        Mise à jour pour Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
        Mise à jour pour Windows XP (KB955839)-->"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
        Mise à jour pour Windows XP (KB967715)-->"C:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe"
        Miss Teri Tale - Vote 4 Me-->"C:\Games\Miss Teri Tale - Vote 4 Me\uninstall.exe"
        Missions Secretes - Mata Hari et les Sous-Marins du Kaiser-->"C:\Games\Missions Secretes - Mata Hari et les Sous-Marins du Kaiser\uninstall.exe"
        Monster Quest 1.00-->C:\Program Files\Games\Monster Quest\Uninstall.exe
        MSRedist-->MsiExec.exe /I{B7C61755-DB48-4003-948F-3D34DB8EAF69}
        MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
        MSXML 6 Service Pack 2 (KB954459)-->MsiExec.exe /I{1A528690-6A2D-4BC5-B143-8C4AE8D19D96}
        Mushroom Age-->"C:\Games\Mushroom Age\uninstall.exe"
        Mystère a Londres-->C:\Program Files\Mystère a Londres\Uninstal.exe
        Mystery Case Files - Huntsville-->"C:\Games\Mystery Case Files - Huntsville\uninstall.exe"
        Mystery Case Files - Prime Suspects-->"C:\Games\Mystery Case Files - Prime Suspects\uninstall.exe"
        Mystery Chronicles - Meurtre Entre Amis-->"C:\Games\Mystery Chronicles - Meurtre Entre Amis\uninstall.exe"
        Mystery Legends - Sleepy Hollow Cracked by Cryptic-->"C:\Program Files\Mystery Legends - Sleepy Hollow\unins000.exe"
        Mystery of Unicorn Castle-->"C:\Games\Mystery of Unicorn Castle\uninstall.exe"
        Mystery Stories - Island of Hope-->"C:\Games\Mystery Stories - Island of Hope\uninstall.exe"
        Mysteryville 2-->"C:\Games\Mysteryville 2\uninstall.exe"
        Mysteryville-->"C:\Games\Mysteryville\uninstall.exe"
        Natalie Brooks - Secrets of Treasure House-->"C:\Games\Natalie Brooks - Secrets of Treasure House\uninstall.exe"
        Nero Suite-->C:\Program Files\Fichiers communs\Nero\Uninstall\Setupx.exe /uninstall ExtraUninstallID=""
        Norton AntiSpam-->MsiExec.exe /I{3B29A786-5803-4e9e-9B58-3014A5B4E519}
        Norton AntiSpam-->MsiExec.exe /I{5677563D-0CB1-485f-9E18-C5025306BB3F}
        Norton AntiVirus 2005-->MsiExec.exe /X{C6F5B6CF-609C-428E-876F-CA83176C021B}
        Norton Internet Security 2005 (Symantec Corporation)-->C:\Program Files\Fichiers communs\Symantec Shared\SymSetup\{A93C9E60-29B6-49da-BA21-F70AC6AADE20}.exe /X
        Norton Internet Security-->MsiExec.exe /I{12E2B9E9-05B1-407d-B0FD-B5F350535125}
        Norton Internet Security-->MsiExec.exe /I{449F3A9E-9903-4a0d-A209-08030D45A935}
        Norton Internet Security-->MsiExec.exe /I{48185814-A224-447a-81DA-71BD20580E1B}
        Norton Internet Security-->MsiExec.exe /I{526AD5DC-CFC4-4f2a-8442-C84CC91D6C7F}
        Norton Internet Security-->MsiExec.exe /I{A93C9E60-29B6-49da-BA21-F70AC6AADE20}
        Norton Internet Security-->MsiExec.exe /I{C9D599E1-6B68-4a1f-8A4F-A1DB433DB1BF}
        Norton Internet Security-->MsiExec.exe /I{E3EFA461-EB83-4C3B-9C47-2C1D58A01555}
        Norton Internet Security-->MsiExec.exe /I{E5EE9939-259F-4DE2-8023-5C49E16A4F43}
        Norton Internet Security-->MsiExec.exe /I{FC2C0536-583C-46c0-844A-62CECAE01F22}
        Norton WMI Update-->MsiExec.exe /X{E85FA9A1-C241-4698-893B-DD99509B8DB0}
        Norton WMI Update-->MsiExec.exe /X{F64306A5-4C32-41bb-B153-53986527FAB4}
        Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
        Paparazzi-->"C:\Games\Paparazzi\uninstall.exe"
        PIF DESIGNER-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B90450DF-E781-46FD-B1F1-0C86DA40E443}\SETUP.EXE" -l0x40c anything
        Pirates: Battle for the Caribbean-->"C:\Program Files\GameTop.com\Pirates\unins000.exe"
        Pirateville-->C:\Program Files\Pirateville\Uninstal.exe
        QuickTime-->MsiExec.exe /I{5E863175-E85D-44A6-8968-82507D34AE7F}
        Realtek AC'97 Audio-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FB08F381-6533-4108-B7DD-039E11FBC27E}\setup.exe" REMOVE
        REALTEK Gigabit and Fast Ethernet NIC Driver-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{94FB906A-CF42-4128-A509-D353026A607E}\setup.exe" -l0x40c REMOVE
        Security Update for CAPICOM (KB931906)-->MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
        Security Update for CAPICOM (KB931906)-->MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
        Segoe UI-->MsiExec.exe /I{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}
        Sherlock Holmes - Le Mystere du Tapis Persan-->"C:\Games\Sherlock Holmes - Le Mystere du Tapis Persan\uninstall.exe"
        SoftV90 Data Fax Modem with SmartCP-->C:\Program Files\CONEXANT\CNXT_MODEM_PCI_VEN_1002&DEV_4378&SUBSYS_10921734\HXFSETUP.EXE -U -IVEN_1002&DEV_4378&SUBSYS_10921734
        SPBBC-->MsiExec.exe /I{77772678-817F-4401-9301-ED1D01A8DA56}
        Sprill - Le Mystere du Triangle des Bermudes-->"C:\Games\Sprill - Le Mystere du Triangle des Bermudes\uninstall.exe"
        Symantec Script Blocking Installer-->MsiExec.exe /I{D327AFC9-7BAA-473A-8319-6EB7A0D40138}
        SymNet-->MsiExec.exe /I{2DA85B02-13C0-4E6D-9A76-22E6B3DD0CB2}
        Synaptics Pointing Device Driver-->rundll32.exe "C:\Program Files\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall
        Texas Instruments PCIxx21/x515 drivers.-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{E7A744FD-E1B8-4FF6-ADC1-EA4C32181457} /l1033
        The Magicians Handbook - Cursed Valley-->"C:\Games\The Magicians Handbook - Cursed Valley\uninstall.exe"
        The Secret of Margrave Manor-->"C:\Games\The Secret of Margrave Manor\uninstall.exe"
        The Stone of Destiny-->"C:\Games\The Stone of Destiny\uninstall.exe"
        Veronica Rivers - Portails de l'Inconnu-->"C:\Games\Veronica Rivers - Portails de l'Inconnu\uninstall.exe"
        VirtuaGirl HD-->C:\Documents and Settings\Fannette\Menu Démarrer\Programmes\VirtuaGirl HD\uninstall.lnk
        Wild West Quest-->"C:\Games\Wild West Quest\uninstall.exe"
        Windows Communication Foundation-->MsiExec.exe /X{491DD792-AD81-429C-9EB4-86DD3D22E333}
        Windows Imaging Component-->"C:\WINDOWS\$NtUninstallWIC$\spuninst\spuninst.exe"
        Windows Live Call-->MsiExec.exe /I{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}
        Windows Live Communications Platform-->MsiExec.exe /I{3B4E636E-9D65-4D67-BA61-189800823F52}
        Windows Live Contrôle parental-->MsiExec.exe /X{D6A2DDE3-9D7C-412C-932A-756580D29919}
        Windows Live Mail-->MsiExec.exe /I{63DC2DA0-2A6C-4C38-9249-B75395458657}
        Windows Live Messenger-->MsiExec.exe /X{059C042E-796A-4ACC-A81A-ECC2010BB78C}
        Windows Live Sync-->MsiExec.exe /X{9C5EB781-0D37-44B8-9A58-77B3E4BF5F5E}
        Windows Live Toolbar-->MsiExec.exe /X{F7D27C70-90F5-49B9-B188-0A133C0CE353}
        Windows Live Writer-->MsiExec.exe /X{2231CE39-B963-4B9D-823A-F412ECA637B1}
        Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
        Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
        Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
        Windows Presentation Foundation-->MsiExec.exe /X{BAF78226-3200-4DB4-BE33-4D922A799840}
        Windows Workflow Foundation-->MsiExec.exe /I{7D1B85BD-AA07-48B8-808D-67A4067FC6BD}
        Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
        WinRAR archiver-->C:\Program Files\WinRAR\uninstall.exe
        Women's Murder Club-->C:\Documents and Settings\Fannette\Bureau\HIDDEN OBJECTS\Uninstal.exe

        ======Hosts File======

        127.0.0.1 localhost

        ======Security center information======

        AV: Norton Internet Security
        FW: Norton Internet Security

        ======System event log======

        Computer Name: FANNETTE-A5D666
        Event Code: 26
        Message: Application popup : Windows - Pas de disque : Il n'y a pas de disque dans le lecteur. Insérez un disque dans le lecteur D:.

        Record Number: 116
        Source Name: Application Popup
        Time Written: 20090402104121.000000+120
        Event Type: Informations
        User:

        Computer Name: FANNETTE-A5D666
        Event Code: 26
        Message: Application popup : Windows - Pas de disque : Il n'y a pas de disque dans le lecteur. Insérez un disque dans le lecteur D:.

        Record Number: 115
        Source Name: Application Popup
        Time Written: 20090402104119.000000+120
        Event Type: Informations
        User:

        Computer Name: FANNETTE-A5D666
        Event Code: 26
        Message: Application popup : Windows - Pas de disque : Il n'y a pas de disque dans le lecteur. Insérez un disque dans le lecteur D:.

        Record Number: 114
        Source Name: Application Popup
        Time Written: 20090402104119.000000+120
        Event Type: Informations
        User:

        Computer Name: FANNETTE-A5D666
        Event Code: 26
        Message: Application popup : Windows - Pas de disque : Il n'y a pas de disque dans le lecteur. Insérez un disque dans le lecteur D:.

        Record Number: 113
        Source Name: Application Popup
        Time Written: 20090402104118.000000+120
        Event Type: Informations
        User:

        Computer Name: FANNETTE-A5D666
        Event Code: 26
        Message: Application popup : Windows - Pas de disque : Il n'y a pas de disque dans le lecteur. Insérez un disque dans le lecteur D:.

        Record Number: 112
        Source Name: Application Popup
        Time Written: 20090402104118.000000+120
        Event Type: Informations
        User:

        =====Application event log=====

        Computer Name: FANNETTE-A5D666
        Event Code: 101
        Message: Niveau d'information : success

        Le Planificateur a lancé LiveUpdate automatique.

        Record Number: 491
        Source Name: Automatic LiveUpdate Scheduler
        Time Written: 20090403174015.000000+120
        Event Type: Informations
        User: AUTORITE NT\SYSTEM

        Computer Name: FANNETTE-A5D666
        Event Code: 101
        Message: Niveau d'information : success

        L'exécution suivante a été planifiée pour intervenir approximativement à 5:40 PM.

        Record Number: 490
        Source Name: Automatic LiveUpdate Scheduler
        Time Written: 20090403132141.000000+120
        Event Type: Informations
        User: AUTORITE NT\SYSTEM

        Computer Name: FANNETTE-A5D666
        Event Code: 101
        Message: Niveau d'information : success

        LiveUpdate automatique a terminé.

        Record Number: 489
        Source Name: Automatic LiveUpdate Scheduler
        Time Written: 20090403132141.000000+120
        Event Type: Informations
        User: AUTORITE NT\SYSTEM

        Computer Name: FANNETTE-A5D666
        Event Code: 101
        Message: Niveau d'information : success

        Le Planificateur a lancé LiveUpdate automatique.

        Record Number: 488
        Source Name: Automatic LiveUpdate Scheduler
        Time Written: 20090403132047.000000+120
        Event Type: Informations
        User: AUTORITE NT\SYSTEM

        Computer Name: FANNETTE-A5D666
        Event Code: 1002
        Message: L'environnement s'est arrêté de façon inattendue et Explorer.exe a redémarré.

        Record Number: 487
        Source Name: Winlogon
        Time Written: 20090403112527.000000+120
        Event Type: Informations
        User:

        ======Environment variables======

        "ComSpec"=%SystemRoot%\system32\cmd.exe
        "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\ATI Technologies\ATI Control Panel;C:\Program Files\QuickTime\QTSystem\
        "windir"=%SystemRoot%
        "FP_NO_HOST_CHECK"=NO
        "OS"=Windows_NT
        "PROCESSOR_ARCHITECTURE"=x86
        "PROCESSOR_LEVEL"=15
        "PROCESSOR_IDENTIFIER"=x86 Family 15 Model 36 Stepping 2, AuthenticAMD
        "PROCESSOR_REVISION"=2402
        "NUMBER_OF_PROCESSORS"=1
        "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
        "TEMP"=%SystemRoot%\TEMP
        "TMP"=%SystemRoot%\TEMP
        "CLASSPATH"=.;C:\Program Files\Java\jre1.5.0\lib\ext\QTJava.zip
        "QTJAVA"=C:\Program Files\Java\jre1.5.0\lib\ext\QTJava.zip

        -----------------EOF-----------------

        Merci

        Fannette
        0
        1. Contributeur
          Telecharge et installe ccleaner : https://filehippo.com/download_ccleaner/
          - Durant l'installation, n'installe pas la barre d'outils yahoo et decoche la case " ajouter l'option des mises à jour"

          - Une fois installé, fermes toutes les applications en cours et lance ccleaner
          - clic >> option >> avancé et decoches " effacer les fichiers etc... plus vieux que 48h
          - Selectionne " nettoyeur " >> clic sur Analyse puis nettoyage, puis referme le programme...

          -------------------------

          * telecharge SDFix sur ton bureau : http://downloads.andymanchesta.com/RemovalTools/SDFix.exe

          - Fermes toutes les applications en cours, puis double clic sur le raccourci de ton bureau
          - Clic sur " Install " pour l'extraire dans un dossier dedié

          - Redemarres ton pc en mode sans echec :
          - Au demarrage du pc, tapotes sur la touche F8 ou F5 du clavier juste aprés le bip du bios et avant le logo " windows "
          - Un ecran avec plusieurs choix apparaitra > selectionnes " mode sans echec " et valides par la touche " Entrée " de ton clavier

          - Une fois en " mode sans echec " , ouvres le fichier créé, puis double clic sur " Runthis.bat "
          - Une fenetre noir apparait, appuies sur la touche " Y " pour lancer le nettoyage
          - Le bureau va disparaitre, c'est normal
          - L'outil va travailler, patientes jusqu'à la fin du scan
          - Une fois terminé, Sdfix te signalera que l'ordi doit redemarrer, acceptes en pressant une touche..
          - Le pc va redemarrer en mode normal, une fois ton bureau en place, il va générer un rapport
          - Sauvegardes le et poste son contenu ( tu le trouveras aussi à c:\report.txt)

          Note :

          -Si SDfix ne se lance pas --> ça peut arriver
          - clic sur Démarrer->Exécuter
          - Copie/colle ceci dans la fenêtre :

          %systemroot%\system32\cmd.exe /K %systemdrive%\SDFix\apps\FixPath.exe

          - Clique sur ok, et valide.
          - Redémarre et essaye de nouveau de lancer SDfix.

          -------
          0
          1. Re,

            voici le rapport après toutes les opérations effectuées (quand j'ai redémarré mon ordi norton a encore détecté le même virus sur mon ordi (est-ce normal?).

            [b]SDFix: Version 1.240 [/b]
            Run by Fannette on 17/04/2009 at 13:37

            Microsoft Windows XP [version 5.1.2600]
            Running From: C:\SDFix

            [b]Checking Services [/b]:

            Restoring Default Security Values
            Restoring Default Hosts File

            Rebooting

            Service asc3550p - Deleted after Reboot

            [b]Checking Files [/b]:

            No Trojan Files Found

            Removing Temp Files

            [b]ADS Check [/b]:

            [b]Final Check [/b]:

            catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
            Rootkit scan 2009-04-17 16:14:47
            Windows 5.1.2600 Service Pack 3 NTFS

            scanning hidden processes ...

            scanning hidden services & system hive ...

            scanning hidden registry entries ...

            scanning hidden files ...

            scan completed successfully
            hidden processes: 0
            hidden services: 0
            hidden files: 0

            [b]Remaining Services [/b]:

            Authorized Application Key Export:

            [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
            "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
            "C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
            "C:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"="C:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe:*:Enabled:Windows Live Call"
            "C:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"="C:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe:*:Enabled:Windows Live Sync"
            "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
            "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"

            [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
            "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
            "C:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"="C:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe:*:Enabled:Windows Live Call"
            "C:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"="C:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe:*:Enabled:Windows Live Sync"
            "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
            "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"

            [b]Remaining Files [/b]:

            [b]Files with Hidden Attributes [/b]:

            Mon 13 Apr 2009 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"

            [b]Finished![/b]
            0
            1. Contributeur
              * Supprimes Norton, c'est une daube et il ne te sert à rien, la preuve !!!

              - Pour supprimer Norton proprement, sers toi de l'utilitaire de Symantec : http://service1.symantec.com/SUPPORT/INTER/tsgeninfointl.nsf/fr_docid/20050414110429924

              - Telecharges Avira Antivir , qui est beaucoup plus performant ( le meilleur gratuit actuellement)

              - Sers toi de ce Tutoriel Avira Antivir pour l'installer et le configurer...

              Puis,

              - Telecharges Malwarebytes' Anti-Malware :
              http://www.malwarebytes.org/mbam/program/mbam-setup.exe

              - Installe le > double-clic sur Mbam-setup.exe, à la fin de l'installation, il se mettra automatiquement à jour
              - Une fois installé, fermes toutes les applications en cours et lances Malwarebytes
              - Executes un examen rapide du pc ( tu n'auras pas accés à internet pendant l'analyse)
              - A la fin du scan clic sur " Afficher les resultats ", si Malwarebytes a trouvé des infections >> clic sur " Supprimer la selection "
              - Si il a besoin de redemarrer le pc pour finir la desinfection, acceptes
              - Un rapport s'etablira, postes son contenu.
              ----------------------------------
              0
              1. Re,

                alors ça y est j'ai téléchrger avira et malwarebytes, j'ai fait l'analyse avec malwarebytes mais avec pas mal de soucis car toutes les 30 secondes avira me detecté un virus (TR/BHO.Gen) donc l'analyse a été plus longue que prévue. Voic le rapport:

                es' Anti-Malware 1.36
                Version de la base de données: 1993
                Windows 5.1.2600 Service Pack 3

                17/04/2009 17:40:37
                mbam-log-2009-04-17 (17-40-32).txt

                Type de recherche: Examen rapide
                Eléments examinés: 63598
                Temps écoulé: 17 minute(s), 14 second(s)

                Processus mémoire infecté(s): 0
                Module(s) mémoire infecté(s): 1
                Clé(s) du Registre infectée(s): 4
                Valeur(s) du Registre infectée(s): 7
                Elément(s) de données du Registre infecté(s): 0
                Dossier(s) infecté(s): 0
                Fichier(s) infecté(s): 6

                Processus mémoire infecté(s):
                (Aucun élément nuisible détecté)

                Module(s) mémoire infecté(s):
                C:\WINDOWS\system32\bat.dll (Spyware.Bzub) -> No action taken.

                Clé(s) du Registre infectée(s):
                HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{74eb420f-7b78-48af-a5fd-902b85868337} (Trojan.BHO.H) -> No action taken.
                HKEY_CLASSES_ROOT\CLSID\{74eb420f-7b78-48af-a5fd-902b85868337} (Trojan.BHO.H) -> No action taken.
                HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\__c0094def (Trojan.Vundo) -> No action taken.
                HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{74eb420f-7b78-48af-a5fd-902b85868337} (Spyware.Bzub) -> No action taken.

                Valeur(s) du Registre infectée(s):
                HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\a00fe6741.exe (Trojan.Agent) -> No action taken.
                HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\a00ff32ee.exe (Trojan.Agent) -> No action taken.
                HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\a00ff6d57.exe (Trojan.Agent) -> No action taken.
                HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\bf (Trojan.Agent) -> No action taken.
                HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\bk (Trojan.Agent) -> No action taken.
                HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\iu (Trojan.Agent) -> No action taken.
                HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\mu (Trojan.Agent) -> No action taken.

                Elément(s) de données du Registre infecté(s):
                (Aucun élément nuisible détecté)

                Dossier(s) infecté(s):
                (Aucun élément nuisible détecté)

                Fichier(s) infecté(s):
                C:\WINDOWS\system32\config\32717790.Evt (Rootkit.Agent.H) -> No action taken.
                C:\WINDOWS\system32\bat.dll (Trojan.BHO.H) -> No action taken.
                C:\Documents and Settings\Fannette\Local Settings\Temp\memhofym.dat (Rootkit.Agent) -> No action taken.
                C:\WINDOWS\system32\capico.dll (Trojan.Agent) -> No action taken.
                C:\WINDOWS\system32\__c003AB29.dat (Trojan.Agent) -> No action taken.
                C:\WINDOWS\system32\cabine.dll (Spyware.BZub) -> No action taken.

                Merci

                Fannette
                0
                1. Contributeur
                  No action Taken --> tu n'as pas supprimer la selection ?

                  - Verifies dans l'onglet " Quarantaine ", si présent supprimes tout et postes le rapport généré, si Malwarebytes doit redemarrer le pc pour finir la desinfection, acceptes

                  - Postes le rapport généré stp

                  - Tu as bien desinstallé Norton ? car il ne faut qu'un et un seul antivirus sur le meme pc, sinon risque de conflit !

                  - J'attends le rapport Malwarebytes en mode suppression stp, si tu ne trouves rien dans la quarantaine, refais un scan rapide et supprimes la selection, puis postes le rapport généré
                  0
                  1. En effet, je ne les avais pas supprimé. Voici donc le nouveau rapport:

                    Malwarebytes' Anti-Malware 1.36
                    Version de la base de données: 1993
                    Windows 5.1.2600 Service Pack 3

                    17/04/2009 18:15:48
                    mbam-log-2009-04-17 (18-15-48).txt

                    Type de recherche: Examen rapide
                    Eléments examinés: 63749
                    Temps écoulé: 16 minute(s), 34 second(s)

                    Processus mémoire infecté(s): 0
                    Module(s) mémoire infecté(s): 0
                    Clé(s) du Registre infectée(s): 3
                    Valeur(s) du Registre infectée(s): 4
                    Elément(s) de données du Registre infecté(s): 0
                    Dossier(s) infecté(s): 0
                    Fichier(s) infecté(s): 2

                    Processus mémoire infecté(s):
                    (Aucun élément nuisible détecté)

                    Module(s) mémoire infecté(s):
                    (Aucun élément nuisible détecté)

                    Clé(s) du Registre infectée(s):
                    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{74eb420f-7b78-48af-a5fd-902b85868337} (Trojan.BHO.H) -> Delete on reboot.
                    HKEY_CLASSES_ROOT\CLSID\{74eb420f-7b78-48af-a5fd-902b85868337} (Trojan.BHO.H) -> Delete on reboot.
                    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{74eb420f-7b78-48af-a5fd-902b85868337} (Spyware.Bzub) -> Quarantined and deleted successfully.

                    Valeur(s) du Registre infectée(s):
                    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\bf (Trojan.Agent) -> Delete on reboot.
                    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\bk (Trojan.Agent) -> Delete on reboot.
                    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\iu (Trojan.Agent) -> Delete on reboot.
                    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\mu (Trojan.Agent) -> Delete on reboot.

                    Elément(s) de données du Registre infecté(s):
                    (Aucun élément nuisible détecté)

                    Dossier(s) infecté(s):
                    (Aucun élément nuisible détecté)

                    Fichier(s) infecté(s):
                    C:\WINDOWS\system32\bat.dll (Trojan.BHO.H) -> Delete on reboot.
                    C:\Documents and Settings\Fannette\Local Settings\Temp\memhofym.dat (Rootkit.Agent) -> Delete on reboot.
                    0
                    1. Contributeur
                      Telecharges Combofix et enregistres le sur ton bureau

                      http://download.bleepingcomputer.com/sUBs/ComboFix.exe -

                      /!\ Desactives ton antivirus et la garde de ton antispyware ( si tu en as un) /!\

                      - Deconnectes toi et fermes toutes les applications en cours
                      - Double clic sur Combofix.exe >> un message apparait > réponds " oui "
                      - ( Il est conseillé d'installer la console de recuperations)
                      - Selectionnes la langue et presse la touche 1 ( yes) pour lancer le scan

                      /!\ Ne touche ni à la souris, ni au clavier durant le scan, cela pourrait figer l'ordi /!\

                      - A la fin du scan, Combofix aura besoin de redemarrer pour finir la desinfection, laisses le faire
                      - Une fois terminé, un rapport s'affiche, poste son contenu que tu peux aussi trouver à c:\combofix.txt
                      ---------------------------
                      0
                      1. Alors combofix ne m'a pasdemandé de redémarrer, voici le compte rendu:

                        ComboFix 09-04-17.05 - Fannette 17/04/2009 18:35.1 - NTFSx86
                        Microsoft Windows XP Édition familiale 5.1.2600.3.1252.33.1036.18.382.167 [GMT 2:00]
                        Lancé depuis: c:\documents and settings\Fannette\Bureau\ComboFix.exe
                        AV: Avira AntiVir PersonalEdition Classic *On-access scanning disabled* (Updated)
                        * Un nouveau point de restauration a été créé
                        .

                        ((((((((((((((((((((((((((((( Fichiers créés du 2009-03-17 au 2009-04-17 ))))))))))))))))))))))))))))))))))))
                        .

                        2009-04-17 15:19 . 2009-04-17 15:19 -------- d-----w c:\documents and settings\Fannette\Application Data\Malwarebytes
                        2009-04-17 15:18 . 2009-04-06 13:32 15504 ----a-w c:\windows\system32\drivers\mbam.sys
                        2009-04-17 15:18 . 2009-04-06 13:32 38496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
                        2009-04-17 15:18 . 2009-04-17 15:18 -------- d-----w c:\documents and settings\All Users\Application Data\Malwarebytes
                        2009-04-17 15:06 . 2009-04-17 15:06 -------- d-----w c:\documents and settings\All Users\Application Data\Avira
                        2009-04-17 11:35 . 2009-04-17 11:35 579584 -c--a-w c:\windows\system32\dllcache\user32.dll
                        2009-04-17 11:31 . 2009-04-17 11:31 -------- d-----w c:\windows\ERUNT
                        2009-04-17 11:21 . 2009-04-17 14:26 -------- d-----w C:\SDFix
                        2009-04-17 10:26 . 2009-04-17 10:26 -------- d-sh--w c:\documents and settings\Fannette\IECompatCache
                        2009-04-17 08:44 . 2009-04-17 08:45 -------- d-----w C:\rsit
                        2009-04-16 12:25 . 2009-04-16 12:50 -------- d-----w c:\documents and settings\Fannette\10DaysUnderTheSea
                        2009-04-15 16:33 . 2009-04-15 20:32 -------- d-----w c:\documents and settings\Fannette\Local Settings\Application Data\Google
                        2009-04-15 10:32 . 2009-04-15 10:32 146 ----a-w c:\windows\wininit.ini
                        2009-04-15 08:36 . 2009-04-15 15:52 -------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
                        2009-04-15 08:18 . 2004-08-05 12:00 97792 ----a-w c:\windows\system32\cabin.dll
                        2009-04-15 08:16 . 2005-04-05 19:54 97792 ----a-w c:\windows\system32\ati2evx.dll
                        2009-04-14 21:49 . 2009-02-06 10:10 227840 -c----w c:\windows\system32\dllcache\wmiprvse.exe
                        2009-04-14 21:49 . 2009-03-06 14:20 286720 -c----w c:\windows\system32\dllcache\pdh.dll
                        2009-04-14 21:49 . 2009-02-09 11:23 111104 -c----w c:\windows\system32\dllcache\services.exe
                        2009-04-14 21:49 . 2009-02-09 10:53 401408 -c----w c:\windows\system32\dllcache\rpcss.dll
                        2009-04-14 21:49 . 2009-02-09 10:53 473600 -c----w c:\windows\system32\dllcache\fastprox.dll
                        2009-04-14 21:49 . 2009-02-09 10:53 685568 -c----w c:\windows\system32\dllcache\advapi32.dll
                        2009-04-14 21:49 . 2009-02-09 10:53 735744 -c----w c:\windows\system32\dllcache\lsasrv.dll
                        2009-04-14 21:49 . 2009-02-09 10:53 453120 -c----w c:\windows\system32\dllcache\wmiprvsd.dll
                        2009-04-14 21:49 . 2009-02-09 10:53 739840 -c----w c:\windows\system32\dllcache\ntdll.dll
                        2009-04-14 21:48 . 2008-12-16 12:31 354304 -c----w c:\windows\system32\dllcache\winhttp.dll
                        2009-04-14 21:48 . 2008-04-21 21:15 219136 -c----w c:\windows\system32\dllcache\wordpad.exe
                        2009-04-14 08:44 . 2008-04-14 02:33 97792 ----a-w c:\windows\system32\cdosy.dll
                        2009-04-13 08:47 . 2009-04-13 08:47 -------- d-----w c:\windows\l2schemas
                        2009-04-13 08:47 . 2009-04-13 08:47 -------- d-----w c:\windows\system32\fr
                        2009-04-13 08:47 . 2009-04-13 08:47 -------- d-----w c:\windows\system32\bits
                        2009-04-13 08:43 . 2009-04-13 08:47 -------- d-----w c:\windows\ServicePackFiles
                        2009-04-13 08:32 . 2009-04-13 08:32 -------- d-----w c:\windows\EHome
                        2009-04-13 08:06 . 2009-04-13 08:06 -------- d-----w c:\documents and settings\Fannette\Application Data\Apple Computer
                        2009-04-13 08:05 . 2009-04-13 08:05 54156 ---ha-w c:\windows\QTFont.qfn
                        2009-04-13 08:05 . 2009-04-13 08:05 1409 ----a-w c:\windows\QTFont.for
                        2009-04-13 08:04 . 2009-04-13 08:04 -------- d-----w c:\documents and settings\Fannette\Application Data\AdobeUM
                        2009-04-13 08:01 . 2009-04-14 11:34 -------- d-----w c:\documents and settings\Fannette\Application Data\ArcSoft
                        2009-04-13 08:00 . 2005-02-23 12:58 11776 ----a-w c:\windows\system32\drivers\afc.sys
                        2009-04-13 08:00 . 1995-08-01 02:44 212480 ----a-w c:\windows\PCDLIB32.DLL
                        2009-04-13 08:00 . 2006-10-26 07:34 126976 ----a-w c:\windows\system32\PhotoImpression Slideshow.scr
                        2009-04-13 07:58 . 2009-04-13 08:00 -------- d-----w c:\windows\system32\PhotoImpression Slideshow
                        2009-04-13 07:56 . 2009-04-13 07:58 -------- d-----w c:\documents and settings\All Users\Application Data\Apple Computer
                        2009-04-12 22:49 . 2009-04-12 22:49 69 ----a-w c:\windows\NeroDigital.ini
                        2009-04-12 22:46 . 2009-03-27 06:54 1203922 -c--a-w c:\windows\system32\dllcache\sysmain.sdb
                        2009-04-12 22:42 . 2009-04-12 22:44 -------- d-----w c:\windows\system32\drivers\UMDF
                        2009-04-12 21:43 . 2009-04-12 21:43 -------- d-----w c:\documents and settings\All Users\Application Data\EscapeTheMuseum
                        2009-04-12 17:12 . 2009-04-12 17:12 -------- d-sh--w c:\documents and settings\NetworkService\IETldCache
                        2009-04-12 17:10 . 2009-04-12 17:10 -------- d-sh--w c:\documents and settings\Fannette\PrivacIE
                        2009-04-12 17:06 . 2009-04-12 17:06 -------- d-sh--w c:\documents and settings\Fannette\IETldCache
                        2009-04-12 17:01 . 2009-04-12 17:01 -------- d--h--w c:\windows\msdownld.tmp
                        2009-04-12 17:01 . 2009-04-12 17:01 -------- d-----w c:\windows\ie8updates
                        2009-04-12 16:56 . 2009-04-13 08:47 -------- d-----w c:\windows\system32\fr-FR
                        2009-04-12 16:56 . 2009-04-12 16:58 -------- dc-h--w c:\windows\ie8
                        2009-04-12 16:53 . 2009-02-28 04:55 105984 -c----w c:\windows\system32\dllcache\iecompat.dll
                        2009-04-12 01:27 . 2004-08-05 12:00 97792 ----a-w c:\windows\system32\bat.dll
                        2009-04-11 18:04 . 2009-04-11 18:04 -------- d-----w c:\documents and settings\Fannette\Local Settings\Application Data\Ahead
                        2009-04-10 20:21 . 2009-04-10 21:23 -------- d-----w c:\documents and settings\Fannette\Application Data\RobinsonCrusoe
                        2009-04-06 12:02 . 2009-04-06 12:02 -------- d-----w c:\documents and settings\All Users\Application Data\MysteryChronicles
                        2009-04-06 11:54 . 2009-04-06 11:54 -------- d-----w c:\documents and settings\All Users\Application Data\Trymedia
                        2009-04-06 08:09 . 2009-04-06 08:09 -------- d-----w c:\documents and settings\Fannette\Local Settings\Application Data\EasyPrediction
                        2009-04-05 13:04 . 2009-04-05 13:04 152904 ----a-w c:\windows\system32\vghd.scr
                        2009-04-05 13:04 . 2009-04-05 13:08 -------- d-----w c:\documents and settings\Fannette\Application Data\vghd
                        2009-04-04 20:09 . 2009-04-06 12:06 -------- d-----w c:\documents and settings\Fannette\Application Data\cerasus.media
                        2009-04-04 15:31 . 2009-04-04 15:31 -------- d-----w c:\documents and settings\Fannette\Application Data\PlayFirst
                        2009-04-04 15:31 . 2009-04-04 15:31 -------- d-----w c:\documents and settings\All Users\Application Data\PlayFirst
                        2009-04-03 20:06 . 2009-04-03 20:06 -------- d-----w c:\documents and settings\All Users\Application Data\MonteCristo
                        2009-04-03 19:58 . 2009-04-03 19:58 -------- d-sh--w c:\windows\ftpcache
                        2009-04-03 19:57 . 2009-04-03 19:58 -------- d-----w c:\documents and settings\Fannette\Application Data\Magic Academy
                        2009-04-03 17:59 . 2009-04-04 20:07 -------- d-----w c:\documents and settings\Fannette\Application Data\Big Fish Games
                        2009-04-03 17:59 . 2009-04-03 17:59 -------- d-----w c:\windows\Little Shop - City Lights [h33t] [oi812heet]
                        2009-04-03 17:26 . 2009-04-03 17:26 -------- d-----w c:\documents and settings\Fannette\Application Data\Friday's games
                        2009-04-03 15:31 . 2009-04-03 15:31 -------- d-----w c:\documents and settings\Fannette\Local Settings\Application Data\Identities
                        2009-04-03 12:36 . 2009-04-03 12:36 -------- d-----w c:\documents and settings\Fannette\Application Data\Pirateville
                        2009-04-03 12:34 . 2009-04-03 12:34 -------- d-----w c:\documents and settings\Fannette\Application Data\JoyBits
                        2009-04-03 12:24 . 2009-04-03 12:24 -------- d-----w c:\documents and settings\All Users\Application Data\PlayPond
                        2009-04-03 12:11 . 2009-04-03 12:11 -------- d-----w c:\documents and settings\Fannette\Application Data\Games
                        2009-04-03 12:08 . 2009-04-03 12:08 -------- d-----w c:\documents and settings\All Users\Application Data\Mushroom Age
                        2009-04-03 11:47 . 2009-04-03 11:47 -------- d-----w c:\documents and settings\Fannette\Application Data\Artogon
                        2009-04-03 11:29 . 2009-04-03 11:29 -------- d-----w c:\documents and settings\Fannette\Local Settings\Application Data\STARGAZE_IMAGE_CACHE
                        2009-04-03 11:29 . 2009-04-03 11:29 -------- d-----w c:\documents and settings\All Users\Application Data\Alawar Stargaze
                        2009-04-03 11:27 . 2009-04-10 21:14 -------- d-----w C:\Games
                        2009-04-03 09:21 . 2009-04-03 15:48 -------- d-----w c:\documents and settings\Fannette\Application Data\Meridian93
                        2009-04-03 07:38 . 2008-10-16 12:06 268648 ----a-w c:\windows\system32\mucltui.dll
                        2009-04-03 07:38 . 2008-10-16 12:06 208744 ----a-w c:\windows\system32\muweb.dll
                        2009-04-03 07:38 . 2008-10-16 12:06 27496 ----a-w c:\windows\system32\mucltui.dll.mui
                        2009-04-02 19:33 . 2009-04-03 12:28 -------- d-----w c:\documents and settings\Fannette\Application Data\Flood Light Games
                        2009-04-02 19:33 . 2009-04-03 12:28 -------- d-----w c:\documents and settings\All Users\Application Data\Flood Light Games
                        2009-04-02 19:33 . 2009-04-02 19:33 -------- d-----w c:\documents and settings\Fannette\Saved Games
                        2009-04-02 19:28 . 2009-04-02 19:28 -------- d-----w c:\documents and settings\Fannette\Application Data\Gogii Games
                        2009-04-02 19:28 . 2009-04-02 19:28 -------- d-----w c:\documents and settings\All Users\Application Data\Gogii Games
                        2009-04-02 19:27 . 2009-04-05 13:10 -------- d-----w c:\documents and settings\Fannette\Local Settings\Application Data\Game Mill Files
                        2009-04-02 19:26 . 2009-04-02 19:26 -------- d-----w c:\documents and settings\All Users\Application Data\Zylom
                        2009-04-02 19:24 . 2009-04-06 11:55 -------- d-----w c:\documents and settings\Fannette\Local Settings\Application Data\JollyBear
                        2009-04-02 19:24 . 2009-04-06 11:55 -------- d-----w c:\documents and settings\All Users\Application Data\JollyBear
                        2009-04-02 19:09 . 2009-04-02 19:09 -------- d-----w c:\documents and settings\All Users\Application Data\AdventureChronicles1
                        2009-04-02 19:08 . 2009-04-16 14:51 -------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
                        2009-04-02 17:06 . 2009-04-02 17:06 -------- d-----w c:\documents and settings\All Users\Application Data\Babylon
                        2009-04-02 17:06 . 2009-04-02 17:06 -------- d-----w c:\documents and settings\Fannette\Application Data\Babylon
                        2009-04-02 16:35 . 2001-07-09 08:50 155648 ----a-w c:\windows\system32\NeroCheck.exe
                        2009-04-02 16:32 . 2009-04-02 16:32 -------- d-sh--w c:\documents and settings\Fannette\UserData
                        2009-04-02 16:31 . 2009-04-12 22:42 -------- d-----w c:\windows\system32\LogFiles
                        2009-04-02 16:25 . 2009-04-02 16:25 63904 ----a-w c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
                        2009-04-02 16:15 . 2009-04-02 16:15 -------- d-----w c:\windows\system32\XPSViewer
                        2009-04-02 16:13 . 2006-06-29 11:07 14048 ------w c:\windows\system32\spmsg2.dll
                        2009-04-02 16:12 . 2009-04-02 16:23 -------- d-----w C:\a4ea7133e28b9a5f4326caad34
                        2009-04-02 15:36 . 2009-04-02 15:36 -------- d-----w c:\documents and settings\All Users\Application Data\Ahead
                        2009-04-02 15:36 . 2001-06-26 05:15 38912 ------w c:\windows\system32\picn20.dll
                        2009-04-02 15:36 . 2000-06-26 08:45 106496 ----a-w c:\windows\system32\TwnLib20.dll
                        2009-04-02 15:30 . 2009-04-17 16:18 -------- d-----w c:\documents and settings\Fannette\Tracing
                        2009-04-02 15:29 . 2009-04-02 15:29 -------- dc----w c:\windows\system32\DRVSTORE
                        2009-04-02 15:29 . 2009-02-06 16:08 55152 ----a-w c:\windows\system32\drivers\fssfltr_tdi.sys
                        2009-04-02 15:22 . 2006-11-29 11:06 3426072 ----a-w c:\windows\system32\d3dx9_32.dll
                        2009-04-02 12:08 . 2009-04-02 12:12 -------- d-----w c:\documents and settings\Fannette\Local Settings\Application Data\ApplicationHistory
                        2009-04-02 12:08 . 2009-04-02 12:08 131 ----a-w c:\documents and settings\Fannette\Local Settings\Application Data\fusioncache.dat
                        2009-04-02 12:01 . 2009-04-02 15:30 12912 ----a-w c:\documents and settings\Fannette\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
                        2009-04-02 11:25 . 2004-08-03 20:41 126686 ------w c:\windows\system32\drivers\mtlmnt5.sys
                        2009-04-02 11:25 . 2004-08-03 20:41 1309184 ------w c:\windows\system32\drivers\mtlstrm.sys
                        2009-04-02 11:25 . 2004-08-03 20:29 452736 ------w c:\windows\system32\drivers\mtxparhm.sys
                        2009-04-02 11:25 . 2004-07-17 09:35 67866 ------w c:\windows\system32\drivers\netwlan5.img
                        2009-04-02 11:25 . 2004-08-03 20:41 1041536 ------w c:\windows\system32\drivers\hsfdpsp2.sys
                        2009-04-02 11:25 . 2004-08-03 20:41 685056 ------w c:\windows\system32\drivers\hsfcxts2.sys
                        2009-04-02 11:25 . 2004-08-03 20:41 220032 ------w c:\windows\system32\drivers\hsfbs2s2.sys
                        2009-04-02 11:25 . 2004-07-17 20:55 129045 ------w c:\windows\system32\drivers\cxthsfs2.cty
                        2009-04-02 11:22 . 2009-04-02 11:27 -------- d-----w c:\documents and settings\All Users\Application Data\UDL

                        .
                        (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                        .
                        2009-04-17 15:40 . 2009-04-17 15:18 -------- d-----w c:\program files\Malwarebytes' Anti-Malware
                        2009-04-17 15:06 . 2009-04-17 15:06 -------- d-----w c:\program files\Avira
                        2009-04-17 10:24 . 2009-04-17 10:24 -------- d-----w c:\program files\CCleaner
                        2009-04-17 08:45 . 2009-04-17 08:45 -------- d-----w c:\program files\trend micro
                        2009-04-15 16:21 . 2009-04-15 16:20 -------- d-----w c:\program files\Google
                        2009-04-15 15:54 . 2009-04-02 11:07 -------- d-----w c:\program files\epson
                        2009-04-15 15:51 . 2009-04-02 09:40 -------- d--h--w c:\program files\InstallShield Installation Information
                        2009-04-15 08:21 . 2009-04-15 08:21 -------- d-----w c:\program files\Enigma Software Group
                        2009-04-15 08:07 . 2004-08-05 12:00 83832 ----a-w c:\windows\system32\perfc00C.dat
                        2009-04-15 08:07 . 2004-08-05 12:00 505480 ----a-w c:\windows\system32\perfh00C.dat
                        2009-04-13 08:50 . 2009-04-01 23:18 76507 ----a-w c:\windows\pchealth\helpctr\OfflineCache\index.dat
                        2009-04-13 08:39 . 2004-08-05 12:00 252240 --sha-r C:\ntldr
                        2009-04-13 08:02 . 2009-04-13 08:00 -------- d-----w c:\program files\QuickTime
                        2009-04-13 08:00 . 2009-04-13 08:00 -------- d-----w c:\program files\Fichiers communs\ArcSoft
                        2009-04-13 07:59 . 2009-04-13 07:59 -------- d-----w c:\program files\Apple Software Update
                        2009-04-13 07:58 . 2009-04-13 07:58 -------- d-----w c:\program files\ArcSoft
                        2009-04-12 22:45 . 2009-04-12 22:45 -------- d-----w c:\program files\Windows Media Connect 2
                        2009-04-12 17:04 . 2009-04-05 13:04 -------- d-----w c:\program files\vghd
                        2009-04-05 13:08 . 2009-04-05 13:08 -------- d-----w c:\program files\EasyPrediction
                        2009-04-04 08:18 . 2009-04-02 15:29 -------- d-----w c:\program files\Microsoft Silverlight
                        2009-04-04 07:57 . 2009-04-04 07:57 -------- d-----w c:\program files\Microsoft CAPICOM 2.1.0.2
                        2009-04-04 07:57 . 2009-04-04 07:57 -------- d-----w c:\program files\MSXML 6.0
                        2009-04-03 20:09 . 2009-04-03 20:06 -------- d-----w c:\program files\GameTop.com
                        2009-04-03 20:03 . 2009-04-03 20:00 -------- d-----w c:\program files\Games
                        2009-04-03 11:30 . 2009-04-02 19:26 -------- d-----w c:\program files\Zylom Games
                        2009-04-03 08:19 . 2009-04-02 09:42 -------- d-----w c:\program files\Launch Manager
                        2009-04-02 16:45 . 2009-04-02 11:58 -------- d-----w c:\program files\eMule
                        2009-04-02 16:44 . 2009-04-02 16:43 3342809 ----a-w c:\program files\eMule0.49c-Installer.exe
                        2009-04-02 16:38 . 2009-04-02 16:38 -------- d-----w c:\program files\Fichiers communs\Nero
                        2009-04-02 16:36 . 2009-04-02 15:35 -------- d-----w c:\program files\Ahead
                        2009-04-02 16:25 . 2009-04-02 16:25 -------- d-----w c:\program files\MSBuild
                        2009-04-02 16:14 . 2009-04-02 16:14 -------- d-----w c:\program files\Reference Assemblies
                        2009-04-02 15:36 . 2009-04-02 15:36 -------- d-----w c:\program files\Fichiers communs\Ahead
                        2009-04-02 15:31 . 2009-04-02 15:18 -------- d-----w c:\program files\Windows Live
                        2009-04-02 15:23 . 2009-04-02 15:23 -------- d-----w c:\program files\Microsoft Sync Framework
                        2009-04-02 15:22 . 2009-04-02 15:22 -------- d-----w c:\program files\Microsoft SQL Server Compact Edition
                        2009-04-02 15:20 . 2009-04-02 15:20 -------- d-----w c:\program files\Microsoft
                        2009-04-02 15:19 . 2009-04-02 15:19 -------- d-----w c:\program files\Windows Live SkyDrive
                        2009-04-02 15:11 . 2009-04-02 15:11 -------- d-----w c:\program files\Fichiers communs\Windows Live
                        2009-04-02 15:10 . 2009-04-02 15:10 1842024 ----a-w c:\program files\Installation_WLMessenger2009.exe
                        2009-04-02 12:23 . 2009-04-02 12:23 2585872 ----a-w c:\program files\WindowsInstaller-KB893803-v2-x86.exe
                        2009-04-02 12:12 . 2009-04-02 12:12 1161576 ----a-w c:\program files\wlsetup-web.exe
                        2009-04-02 11:58 . 2009-04-02 11:58 2648090 ----a-w c:\program files\eMulePlus-1.2d.Installer.exe
                        2009-04-02 11:56 . 2009-04-02 11:56 1234120 ----a-w c:\program files\wrar380.exe
                        2009-04-02 11:32 . 2009-04-02 09:40 -------- d-----w c:\program files\Fichiers communs\InstallShield
                        2009-04-02 09:46 . 2009-04-02 09:39 1555 ----a-w C:\FSC-DeskUpdate.txt
                        2009-04-02 09:44 . 2009-04-02 09:44 -------- d-----w c:\program files\Synaptics
                        2009-04-02 09:44 . 2009-04-02 09:44 -------- d-----w c:\program files\CONEXANT
                        2009-04-02 09:41 . 2009-04-02 09:41 -------- d-----w c:\program files\ATI Technologies
                        2009-04-02 09:40 . 2009-04-02 09:40 -------- d-----w c:\program files\AMD
                        2009-04-02 09:30 . 2009-04-02 09:30 -------- d-----w c:\program files\Fichiers communs\Adobe
                        2009-04-02 08:24 . 2009-04-02 08:23 90 ----a-w C:\Setup.log
                        2009-04-02 08:22 . 2009-04-02 08:22 -------- d-----w c:\program files\Securitoo
                        2009-04-01 23:24 . 2009-04-01 23:24 -------- d-----w c:\program files\microsoft frontpage
                        2009-04-01 23:23 . 2009-04-01 23:23 -------- d-----w c:\program files\Java
                        2009-04-01 23:23 . 2009-04-01 23:23 -------- d-----w c:\program files\Fichiers communs\Java
                        2009-04-01 23:17 . 2009-04-01 23:17 -------- d-----w c:\program files\Services en ligne
                        2009-04-01 23:15 . 2009-04-01 23:15 21892 ----a-w c:\windows\system32\emptyregdb.dat
                        2009-03-08 02:34 . 2004-09-29 18:49 914944 ----a-w c:\windows\system32\wininet.dll
                        2009-03-08 02:34 . 2004-08-05 12:00 43008 ----a-w c:\windows\system32\licmgr10.dll
                        2009-03-08 02:33 . 2004-08-05 12:00 18944 ----a-w c:\windows\system32\corpol.dll
                        2009-03-08 02:33 . 2004-08-05 12:00 420352 ----a-w c:\windows\system32\vbscript.dll
                        2009-03-08 02:32 . 2004-08-05 12:00 72704 ----a-w c:\windows\system32\admparse.dll
                        2009-03-08 02:32 . 2004-08-05 12:00 71680 ----a-w c:\windows\system32\iesetup.dll
                        2009-03-08 02:31 . 2004-08-05 12:00 34816 ----a-w c:\windows\system32\imgutil.dll
                        2009-03-08 02:31 . 2004-08-05 12:00 48128 ----a-w c:\windows\system32\mshtmler.dll
                        2009-03-08 02:31 . 2004-08-05 12:00 45568 ----a-w c:\windows\system32\mshta.exe
                        2009-03-08 02:22 . 2004-08-05 12:00 156160 ----a-w c:\windows\system32\msls31.dll
                        2009-03-06 14:20 . 2004-08-05 12:00 286720 ----a-w c:\windows\system32\pdh.dll
                        2009-02-10 17:06 . 2004-08-04 00:48 2068096 ----a-w c:\windows\system32\ntkrnlpa.exe
                        2009-02-09 14:05 . 2004-08-05 12:00 1846912 ----a-w c:\windows\system32\win32k.sys
                        2009-02-09 11:24 . 2004-08-05 12:00 2191104 ----a-w c:\windows\system32\ntoskrnl.exe
                        2009-02-09 11:23 . 2004-08-05 12:00 111104 ----a-w c:\windows\system32\services.exe
                        2009-02-09 10:53 . 2004-10-28 01:23 735744 ----a-w c:\windows\system32\lsasrv.dll
                        2009-02-09 10:53 . 2004-08-05 12:00 739840 ----a-w c:\windows\system32\ntdll.dll
                        2009-02-09 10:53 . 2004-08-05 12:00 685568 ----a-w c:\windows\system32\advapi32.dll
                        2009-02-09 10:53 . 2004-08-05 12:00 401408 ----a-w c:\windows\system32\rpcss.dll
                        2009-02-06 17:39 . 2009-02-06 17:39 308600 ----a-w c:\windows\WLXPGSS.SCR
                        2009-02-06 16:52 . 2009-02-06 16:52 49504 ----a-w c:\windows\system32\sirenacm.dll
                        2009-02-06 10:39 . 2004-08-05 12:00 35328 ----a-w c:\windows\system32\sc.exe
                        2009-02-03 19:58 . 2004-08-05 12:00 56832 ----a-w c:\windows\system32\secur32.dll
                        .

                        ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
                        .
                        .
                        *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
                        REGEDIT4

                        [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{74EB420F-7B78-48AF-A5FD-902B85868337}]
                        2004-08-05 12:00 97792 ----a-w c:\windows\system32\bat.dll

                        [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{905502AB-1987-46cd-9EC5-42B1E087D319}]
                        2009-03-12 11:09 229376 ----a-w c:\program files\EasyPrediction\2.0\ltie.dll

                        [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                        "CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
                        "msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]

                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                        "SunJavaUpdateSched"="c:\program files\Java\jre1.5.0\bin\jusched.exe" [2009-04-01 36972]
                        "ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-04-05 339968]
                        "LaunchAp"="c:\program files\Launch Manager\LaunchAp.exe" [2005-03-30 32768]
                        "HotkeyApp"="c:\program files\Launch Manager\HotkeyApp.exe" [2005-05-02 57344]
                        "LMgrVolOSD"="c:\program files\Launch Manager\OSD.exe" [2005-03-16 204800]
                        "LMgrOSD"="c:\program files\Launch Manager\OSDCtrl.exe" [2004-10-11 245760]
                        "Wbutton"="c:\program files\Launch Manager\Wbutton.exe" [2005-04-18 81920]
                        "SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2005-03-18 98393]
                        "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-03-18 688217]
                        "CtrlVol"="c:\program files\Launch Manager\CtrlVol.exe" [2003-09-16 20480]
                        "NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
                        "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-02-16 282624]
                        "avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
                        "SoundMan"="SOUNDMAN.EXE" - c:\windows\SOUNDMAN.EXE [2005-03-24 77824]

                        [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
                        "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

                        c:\documents and settings\Fannette\Menu D‚marrer\Programmes\D‚marrage\
                        Notification de cadeaux MSN.lnk - c:\documents and settings\Fannette\Application Data\Microsoft\Notification de cadeaux MSN\lsnfier.exe [2009-4-12 135680]

                        c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
                        Lancement rapide d'Adobe Reader.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]

                        [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
                        "DisableMonitoring"=dword:00000001

                        [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
                        "DisableMonitoring"=dword:00000001

                        [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
                        "EnableFirewall"= 0 (0x0)

                        [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
                        "%windir%\\system32\\sessmgr.exe"=
                        "c:\\Program Files\\Messenger\\msmsgs.exe"=
                        "c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
                        "c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
                        "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
                        "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=

                        R1 mailKmd;mailKmd; [x]
                        R1 Wbutton;Wbutton; [x]
                        R3 fsssvc;Windows Live Contrôle parental;c:\program files\Windows Live\Family Safety\fsssvc.exe [2009-02-06 533360]
                        S0 eitgmblo;eitgmblo;c:\windows\system32\drivers\eitgmblo.sys [2004-08-05 23424]
                        S1 Hotkey;Hotkey; [x]
                        S2 fssfltr;fssfltr;c:\windows\system32\DRIVERS\fssfltr_tdi.sys [2009-02-06 55152]
                        S2 SeaPort;SeaPort;c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-01-14 226656]
                        S3 HSFHWATI;HSFHWATI;c:\windows\system32\DRIVERS\HSFHWATI.sys [2004-12-15 200192]

                        .
                        Contenu du dossier 'Tâches planifiées'

                        2009-04-13 c:\windows\Tasks\AppleSoftwareUpdate.job
                        - c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-01-10 13:42]
                        .
                        - - - - ORPHELINS SUPPRIMES - - - -

                        Notify-OdysseyClient - (no file)

                        .
                        ------- Examen supplémentaire -------
                        .
                        uStart Page = go.microsoft.com/fwlink/?LinkId=69157
                        .

                        **************************************************************************

                        catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                        Rootkit scan 2009-04-17 18:38
                        Windows 5.1.2600 Service Pack 3 NTFS

                        Recherche de processus cachés ...

                        Recherche d'éléments en démarrage automatique cachés ...

                        HKLM\Software\Microsoft\Windows\CurrentVersion\Run
                        CtrlVol = c:\program files\Launch Manager\CtrlVol.exe?`???T??????|x??|????q??|?j?wQj?w????????,??? ???|???????????\??????|????????h?????@????????????????s???????s???sx??s@??????????????|h??sl??????????s?????????????????C?sc"?sx??s???????w??@?N'?s?D??-6@??E?????????

                        Recherche de fichiers cachés ...

                        Scan terminé avec succès
                        Fichiers cachés: 0

                        **************************************************************************
                        .
                        --------------------- DLLs chargées dans les processus actifs ---------------------

                        - - - - - - - > 'winlogon.exe'(588)
                        c:\windows\system32\Ati2evxx.dll

                        - - - - - - - > 'explorer.exe'(1160)
                        c:\windows\system32\ieframe.dll
                        c:\windows\system32\eappprxy.dll
                        c:\windows\system32\webcheck.dll
                        c:\windows\system32\WPDShServiceObj.dll
                        c:\windows\system32\PortableDeviceTypes.dll
                        c:\windows\system32\PortableDeviceApi.dll
                        c:\program files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                        c:\program files\Fichiers communs\Ahead\Lib\NeroDigitalExt.dll
                        c:\program files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll
                        .
                        Heure de fin: 2009-04-17 18:40
                        ComboFix-quarantined-files.txt 2009-04-17 16:40

                        Avant-CF: 68 601 872 384 octets libres
                        Après-CF: 68 650 164 224 octets libres

                        WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe
                        [boot loader]
                        timeout=2
                        default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
                        [operating systems]
                        c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
                        multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP dition familiale" /noexecute=optin /fastdetect

                        322 --- E O F --- 2009-04-15 07:51
                        0
                        1. Contributeur
                          Mets Adobe à jour : ( n'installes pas la barre d'outil google, décoches la)
                          https://get2.adobe.com/reader/otherversions/

                          ---------------------
                          * Installes la dernière version de Java :
                          https://www.java.com/fr/download/manual.jsp

                          -------------------
                          * Une fois à jour, télécharges JavaRa.zip
                          http://raproducts.org/click/click.php?id=1
                          ---> Autorise le processus a se connecter si il te le demande
                          . Cliques sur Install et suis les instructions

                          - Quand l'installation est finie, reviens à l'écran JavaRa

                          -Clic sur " Remove Old Versions " ou "supprimer les anciennes versions " --> cliques sur " oui "

                          -l'outil va travailler, cliques ensuite sur " Ok " et à nouveau sur Ok

                          - Un rapport s'ouvrira, refermes l'application puis postes le

                          - Met un coup de ccleaner >> nettoyage

                          ------------------------

                          - Lances un scan avec Avira antivir --> en mode sans echec et postes le rapport généré

                          0
                          1. Pour adobe ok c'est fait

                            par contre avec javara j'ai un soucis je l'ai télécharger il s'est ouvert avec winrar et rien ne s'est passé. Je crois ne pas avoir fait la bonne manip. Quand je suis sur le site de javara que faut-il que je fasse? J'ai pris javara sur la ligne orange du haut, est-ce que c'est ça ou est-ce autre chose?
                            0
                            1. Voici la rapport de javara, je fais la suite tout de suite

                              JavaRa 1.13 Removal Log.

                              Report follows after line.

                              ------------------------------------

                              The JavaRa removal process was started on Fri Apr 17 20:13:34 2009

                              Found and removed: C:\Program Files\Java\jre1.5.0

                              Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.5.0\

                              ------------------------------------

                              Finished reporting.
                              0
                              1. Alors, voici le rapport après avoir effectué l'analyse avec avira en mode sans échec:

                                Avira AntiVir Personal
                                Date de création du fichier de rapport : vendredi 17 avril 2009 20:35

                                La recherche porte sur 1355692 souches de virus.

                                Détenteur de la licence :Avira AntiVir PersonalEdition Classic
                                Numéro de série : 0000149996-ADJIE-0001
                                Plateforme : Windows XP
                                Version de Windows :(Service Pack 3) [5.1.2600]
                                Mode Boot : Mode sans échec
                                Identifiant : Fannette
                                Nom de l'ordinateur :FANNETTE-A5D666

                                Informations de version :
                                BUILD.DAT : 8.2.0.52 16931 Bytes 02/12/2008 14:55:00
                                AVSCAN.EXE : 8.1.4.10 315649 Bytes 18/11/2008 07:21:00
                                AVSCAN.DLL : 8.1.4.1 49921 Bytes 21/07/2008 12:44:27
                                LUKE.DLL : 8.1.4.5 164097 Bytes 12/06/2008 11:44:16
                                LUKERES.DLL : 8.1.4.0 13057 Bytes 04/07/2008 06:30:27
                                ANTIVIR0.VDF : 7.1.0.0 15603712 Bytes 27/10/2008 10:30:36
                                ANTIVIR1.VDF : 7.1.2.12 3336192 Bytes 11/02/2009 15:09:13
                                ANTIVIR2.VDF : 7.1.3.63 1588224 Bytes 16/04/2009 15:09:16
                                ANTIVIR3.VDF : 7.1.3.70 16384 Bytes 17/04/2009 15:09:17
                                Version du moteur: 8.2.0.143
                                AEVDF.DLL : 8.1.1.0 106868 Bytes 17/04/2009 15:09:24
                                AESCRIPT.DLL : 8.1.1.75 373113 Bytes 17/04/2009 15:09:23
                                AESCN.DLL : 8.1.1.10 127348 Bytes 17/04/2009 15:09:22
                                AERDL.DLL : 8.1.1.3 438645 Bytes 04/11/2008 12:58:38
                                AEPACK.DLL : 8.1.3.12 397687 Bytes 17/04/2009 15:09:22
                                AEOFFICE.DLL : 8.1.0.36 196987 Bytes 17/04/2009 15:09:21
                                AEHEUR.DLL : 8.1.0.116 1708407 Bytes 17/04/2009 15:09:21
                                AEHELP.DLL : 8.1.2.2 119158 Bytes 17/04/2009 15:09:19
                                AEGEN.DLL : 8.1.1.34 340340 Bytes 17/04/2009 15:09:18
                                AEEMU.DLL : 8.1.0.9 393588 Bytes 14/10/2008 09:05:56
                                AECORE.DLL : 8.1.6.9 176500 Bytes 17/04/2009 15:09:18
                                AEBB.DLL : 8.1.0.3 53618 Bytes 14/10/2008 09:05:56
                                AVWINLL.DLL : 1.0.0.12 15105 Bytes 09/07/2008 07:40:02
                                AVPREF.DLL : 8.0.2.0 38657 Bytes 16/05/2008 08:27:58
                                AVREP.DLL : 8.0.0.3 155905 Bytes 17/04/2009 15:09:17
                                AVREG.DLL : 8.0.0.1 33537 Bytes 09/05/2008 10:26:37
                                AVARKT.DLL : 1.0.0.23 307457 Bytes 12/02/2008 07:29:19
                                AVEVTLOG.DLL : 8.0.0.16 119041 Bytes 12/06/2008 11:27:46
                                SQLITE3.DLL : 3.3.17.1 339968 Bytes 22/01/2008 16:28:02
                                SMTPLIB.DLL : 1.2.0.23 28929 Bytes 12/06/2008 11:49:36
                                NETNT.DLL : 8.0.0.1 7937 Bytes 25/01/2008 11:05:07
                                RCIMAGE.DLL : 8.0.0.51 2371841 Bytes 04/07/2008 06:23:16
                                RCTEXT.DLL : 8.0.52.1 86273 Bytes 17/07/2008 09:08:43

                                Configuration pour la recherche actuelle :
                                Nom de la tâche..................: Contrôle intégral du système
                                Fichier de configuration.........: c:\program files\avira\antivir personaledition classic\sysscan.avp
                                Documentation....................: bas
                                Action principale................: interactif
                                Action secondaire................: ignorer
                                Recherche sur les secteurs d'amorçage maître: marche
                                Recherche sur les secteurs d'amorçage: marche
                                Secteurs d'amorçage..............: C:,
                                Recherche dans les programmes actifs: marche
                                Recherche en cours sur l'enregistrement: marche
                                Recherche de Rootkits............: arrêt
                                Fichier mode de recherche........: Sélection de fichiers intelligente
                                Recherche sur les archives.......: marche
                                Limiter la profondeur de récursivité: 20
                                Archive Smart Extensions.........: marche
                                Heuristique de macrovirus........: marche
                                Heuristique fichier..............: moyen

                                Début de la recherche : vendredi 17 avril 2009 20:35

                                La recherche sur les processus démarrés commence :
                                Processus de recherche 'avscan.exe' - '1' module(s) sont contrôlés
                                Processus de recherche 'avcenter.exe' - '1' module(s) sont contrôlés
                                Processus de recherche 'avgnt.exe' - '1' module(s) sont contrôlés
                                Processus de recherche 'ctfmon.exe' - '1' module(s) sont contrôlés
                                Processus de recherche 'explorer.exe' - '1' module(s) sont contrôlés
                                Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
                                Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
                                Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
                                Processus de recherche 'lsass.exe' - '1' module(s) sont contrôlés
                                Processus de recherche 'services.exe' - '1' module(s) sont contrôlés
                                Processus de recherche 'winlogon.exe' - '1' module(s) sont contrôlés
                                Processus de recherche 'csrss.exe' - '1' module(s) sont contrôlés
                                Processus de recherche 'smss.exe' - '1' module(s) sont contrôlés
                                '13' processus ont été contrôlés avec '13' modules

                                La recherche sur les secteurs d'amorçage maître commence :
                                Secteur d'amorçage maître HD0
                                [INFO] Aucun virus trouvé !

                                La recherche sur les secteurs d'amorçage commence :
                                Secteur d'amorçage 'C:\'
                                [INFO] Aucun virus trouvé !

                                La recherche sur les renvois aux fichiers exécutables (registre) commence.
                                Le registre a été contrôlé ( '61' fichiers).

                                La recherche sur les fichiers sélectionnés commence :

                                Recherche débutant dans 'C:\'
                                C:\pagefile.sys
                                [AVERTISSEMENT] Impossible d'ouvrir le fichier !
                                C:\Program Files\Adobe\Reader 9.0\Setup Files\{AC76BA86-7AD7-1036-7B44-A91000000001}\Data1.cab
                                [0] Type d'archive: CAB (Microsoft)
                                --> Hls.fra
                                [AVERTISSEMENT] Impossible d'écrire le fichier !
                                --> MinionPro_Bold.otf
                                [AVERTISSEMENT] Aucun autre fichier n'a pu être décompressé de cette archive. L'archive est refermée.
                                C:\WINDOWS\system32\ati2evx.dll
                                [RESULTAT] Contient le cheval de Troie TR/BHO.Gen
                                [REMARQUE] Le fichier a été déplacé dans le répertoire de quarantaine sous le nom '4a51e09b.qua' !
                                C:\WINDOWS\system32\bat.dll
                                [RESULTAT] Contient le cheval de Troie TR/Trash.Gen
                                [AVERTISSEMENT] Erreur lors de la création d'une copie de sécurité du fichier. Le fichier n'a pas été supprimé. Code d'erreur : 26003
                                [AVERTISSEMENT] Impossible de supprimer le fichier!
                                [REMARQUE] Tentative en cours d'exécuter l'action à l'aide de la bibliothèque ARK.
                                [REMARQUE] Impossible d'initialiser le pilote.
                                [AVERTISSEMENT] Impossible de repérer le fichier pour sa suppression après le redémarrage. Cause possible : Accès refusé.

                                C:\WINDOWS\system32\cabin.dll
                                [RESULTAT] Contient le cheval de Troie TR/BHO.Gen
                                [REMARQUE] Le fichier a été déplacé dans le répertoire de quarantaine sous le nom '4a4ae0a2.qua' !
                                C:\WINDOWS\system32\cdosy.dll
                                [RESULTAT] Contient le cheval de Troie TR/BHO.Gen
                                [REMARQUE] Le fichier a été déplacé dans le répertoire de quarantaine sous le nom '4a57e0ac.qua' !

                                Fin de la recherche : vendredi 17 avril 2009 22:11
                                Temps nécessaire: 1:35:59 Heure(s)

                                La recherche a été effectuée intégralement

                                4279 Les répertoires ont été contrôlés
                                123659 Des fichiers ont été contrôlés
                                4 Des virus ou programmes indésirables ont été trouvés
                                0 Des fichiers ont été classés comme suspects
                                0 Des fichiers ont été supprimés
                                0 Des virus ou programmes indésirables ont été réparés
                                3 Les fichiers ont été déplacés dans la quarantaine
                                0 Les fichiers ont été renommés
                                1 Impossible de contrôler des fichiers
                                123654 Fichiers non infectés
                                821 Les archives ont été contrôlées
                                4 Avertissements
                                4 Consignes
                                0
                                1. Contributeur
                                  Ok,

                                  - Postes un nouveau rapport RSIT stp...
                                  0
                                  1. Je n'ai qu'un rapport RSIT cette fois:

                                    Logfile of random's system information tool 1.06 (written by random/random)
                                    Run by Fannette at 2009-04-17 23:41:37
                                    Microsoft Windows XP Édition familiale Service Pack 3
                                    System drive C: has 65 GB (86%) free of 76 GB
                                    Total RAM: 382 MB (38% free)

                                    Logfile of Trend Micro HijackThis v2.0.2
                                    Scan saved at 23:41:39, on 17/04/2009
                                    Platform: Windows XP SP3 (WinNT 5.01.2600)
                                    MSIE: Internet Explorer v8.00 (8.00.6001.18702)
                                    Boot mode: Normal

                                    Running processes:
                                    C:\WINDOWS\System32\smss.exe
                                    C:\WINDOWS\system32\winlogon.exe
                                    C:\WINDOWS\system32\services.exe
                                    C:\WINDOWS\system32\lsass.exe
                                    C:\WINDOWS\system32\Ati2evxx.exe
                                    C:\WINDOWS\system32\svchost.exe
                                    C:\WINDOWS\System32\svchost.exe
                                    C:\WINDOWS\system32\spoolsv.exe
                                    C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                                    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                                    C:\Program Files\Java\jre6\bin\jqs.exe
                                    C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                                    C:\WINDOWS\system32\wbem\wmiapsrv.exe
                                    C:\WINDOWS\system32\Ati2evxx.exe
                                    C:\WINDOWS\Explorer.EXE
                                    C:\WINDOWS\system32\wscntfy.exe
                                    C:\WINDOWS\system32\wuauclt.exe
                                    C:\Program Files\Java\jre6\bin\jusched.exe
                                    C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                                    C:\Program Files\Launch Manager\LaunchAp.exe
                                    C:\Program Files\Launch Manager\HotkeyApp.exe
                                    C:\Program Files\Launch Manager\OSD.exe
                                    C:\Program Files\Launch Manager\OSDCtrl.exe
                                    C:\Program Files\Launch Manager\Wbutton.exe
                                    C:\WINDOWS\SOUNDMAN.EXE
                                    C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
                                    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                                    C:\Program Files\QuickTime\qttask.exe
                                    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                                    C:\WINDOWS\system32\ctfmon.exe
                                    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                                    C:\Documents and Settings\Fannette\Application Data\Microsoft\Notification de cadeaux MSN\lsnfier.exe
                                    C:\WINDOWS\System32\svchost.exe
                                    C:\Program Files\Internet Explorer\IEXPLORE.EXE
                                    C:\Program Files\Internet Explorer\IEXPLORE.EXE
                                    C:\Program Files\Windows Live\Toolbar\wltuser.exe
                                    C:\Documents and Settings\Fannette\Bureau\RSIT.exe
                                    C:\Program Files\trend micro\Fannette.exe

                                    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = go.microsoft.com/fwlink/?LinkId=69157
                                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                                    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                                    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
                                    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
                                    O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
                                    O2 - BHO: (no name) - {74EB420F-7B78-48AF-A5FD-902B85868337} - C:\WINDOWS\system32\bat.dll
                                    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                                    O2 - BHO: LTIEHelper Class - {905502AB-1987-46cd-9EC5-42B1E087D319} - C:\Program Files\EasyPrediction\2.0\ltie.dll
                                    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
                                    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
                                    O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
                                    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                                    O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                                    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
                                    O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                                    O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
                                    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                                    O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                                    O4 - HKLM\..\Run: [LaunchAp] C:\Program Files\Launch Manager\LaunchAp.exe
                                    O4 - HKLM\..\Run: [HotkeyApp] C:\Program Files\Launch Manager\HotkeyApp.exe
                                    O4 - HKLM\..\Run: [LMgrVolOSD] C:\Program Files\Launch Manager\OSD.exe
                                    O4 - HKLM\..\Run: [LMgrOSD] C:\Program Files\Launch Manager\OSDCtrl.exe
                                    O4 - HKLM\..\Run: [Wbutton] "C:\Program Files\Launch Manager\Wbutton.exe"
                                    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
                                    O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
                                    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                                    O4 - HKLM\..\Run: [CtrlVol] C:\Program Files\Launch Manager\CtrlVol.exe
                                    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
                                    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                                    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                                    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
                                    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                                    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                                    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                                    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                                    O4 - Startup: Notification de cadeaux MSN.lnk = C:\Documents and Settings\Fannette\Application Data\Microsoft\Notification de cadeaux MSN\lsnfier.exe
                                    O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                                    O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                                    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                                    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                                    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                    O23 - Service: Planificateur Avira AntiVir Personal - Free Antivirus (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                                    O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                                    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                                    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
                                    O23 - Service: Planificateur LiveUpdate automatique - Unknown owner - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing)
                                    0
                                    1. Bonjour,

                                      je voulais savoir si vous aviez eu mon rapport RSIT.

                                      Merci

                                      fannette
                                      0
                                      1. Contributeur
                                        Rends toi sur ce site :

                                        https://www.virustotal.com/gui/

                                        Clique sur parcourir et cherche ces fichiers :C:\Program Files\EasyPrediction\2.0\ltie.dll

                                        - Cherches celui-ci aussi : C:\WINDOWS\system32\bat.dll --> Trojan BHO, normalement mais juste pour voir

                                        Une fois sélectionné , cliques sur " Ouvrir ".

                                        - Puis Cliques sur " Envoyer " .

                                        - A la fin de l'analyse, postes le rapport généré... Tutorial Virus Total

                                        * 1 à la fois, biensur !

                                        0
                                        • 1
                                        • 2
                                        • 3