Virus qui bloque tous

Résolu
Bonjour,

J'ai télécharger un logiciel pour convertir des musiques et une fois télécharger, je l'ai lancer et tous d'un coup avast c'est arrêter. Je me suis dis que c'était un virus alors j'ai éteint rapidement mon pc, j'ai d'ébrancher ma clé wifi pour ne plus être connecter a internet et j'ai rallumer mon pc.

Une fois allumer avast ne c'est pas lancer, j'asseye de l'allumer manuellement et j'ai reçu ce message "c:/program files/alwil software/avast4...n'est pas une application Win32 valide"
Ensuite j'ai essayer de lancer spybot et ccleaner et rien ne se lance.
Puis j'ai essayer de faire une restauration du système a une date antérieur et il me dise qu'il y a une erreur.

Je suis sous windows vista.

Voila je ne sait plus quoi faire. Pouvez vous m'aider s'il vous plais ?

Merci d'avance
Configuration: Windows xp
Firefox 3.0.13

31 réponses

Résumé de la discussion

Un utilisateur signale une infection soupçonnée après le téléchargement d'un logiciel de conversion musicale qui bloque Avast et empêche le démarrage des outils de sécurité sur Windows Vista, notamment Avast et Spybot. Des mesures consistent à désactiver temporairement l'UAC, exécuter des outils dédiés (FindyKill, Ad-Remover), déconnecter les supports externes et lancer les analyses pour générer des rapports et nettoyer les restes éventuels. D'autres propositions visent à désinstaller certains composants potentiels (Search Settings, programmes indésirables) et à suivre des procédures guidées d'éradication, puis à redémarrer et vérifier les journaux pour éviter les conflits. Enfin, des éléments indiquent de vérifier les restes de programmes antivirus et d'analyser les journaux système pour diagnostiquer les causes profondes et envisager une réinstallation si nécessaire.

Bobot (l’IA à votre service)
  1. Modérateur
    Bonjour,

    --> Désactive l'UAC le temps de la désinfection.

    --> Télécharge FindyKill (de Chiquitine29 & C_XX) sur ton Bureau.

    --> Lance l'installation avec les paramètres par défaut.

    --> Branche tes sources de données externes à ton PC (clé USB, disque dur externe, carte SD, etc...) sans les ouvrir.

    --> Double-clique sur le raccourci FindyKill sur ton Bureau.
    (Sous Vista, il faut cliquer droit sur le raccourci FindyKill et choisir Exécuter en tant qu'administrateur)

    --> Au menu principal, choisis l'option 1 (Recherche).

    --> Poste le rapport FindyKill.txt

    Note : le rapport FindyKill.txt est sauvegardé à la racine du disque.
    1. Merci de m'avoir répondu mais avant de télécharger findykill es ce que j'aurai pas un risque de me refaire contaminer par un autre virus sans avast en allant sur internet ?
      1. ahh j'ai un autre problème mon pc ne peu plus se connecter a internet,

        si je télécharge findykill sur un autre pc et que je le transfert avec clé USB sur l'ordi infecter es ce que je ne vais pas contaminer mon deuxieme pc ??
        1. ############################## | FindyKill V5.006 |

          # User : Benoit (Administrateurs) # PC-DE-BENOIT
          # Update on 14/08/09 by Chiquitine29
          # Start at: 17:02:40 | 22/08/2009
          # Website : http://pagesperso-orange.fr/NosTools/index.html

          # Intel(R) Core(TM)2 Quad CPU Q8200 @ 2.33GHz
          # Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6002 32-bit) # Service Pack 2
          # Internet Explorer 8.0.6001.18813
          # Windows Firewall Status : Enabled

          # C:\ # Disque fixe local # 293,33 Go (171,87 Go free) [ACER] # NTFS
          # D:\ # Disque fixe local # 293,08 Go (260,53 Go free) [DATA] # NTFS
          # E:\ # Disque CD-ROM
          # F:\ # Disque amovible
          # G:\ # Disque amovible
          # H:\ # Disque amovible
          # I:\ # Disque amovible
          # J:\ # Disque amovible # 7,53 Go (7,52 Go free) [KINGSTON] # FAT32

          ############################## | Processus actifs |

          C:\Windows\System32\smss.exea
          C:\Windows\system32\csrss.exe
          C:\Windows\system32\wininit.exe
          C:\Windows\system32\csrss.exe
          C:\Windows\system32\services.exe
          C:\Windows\system32\lsass.exe
          C:\Windows\system32\lsm.exe
          C:\Windows\system32\winlogon.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\system32\nvvsvc.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\System32\svchost.exe
          C:\Windows\System32\svchost.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\system32\SLsvc.exe
          C:\Windows\system32\rundll32.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\System32\spoolsv.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\system32\Dwm.exe
          C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
          C:\Windows\Explorer.EXE
          C:\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
          C:\Windows\system32\taskeng.exe
          C:\Windows\system32\HerculesWiFiService.exe
          C:\Program Files\Common Files\LightScribe\LSSrvc.exe
          C:\Windows\system32\PnkBstrA.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\System32\svchost.exe
          C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
          C:\Windows\system32\SearchIndexer.exe
          C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
          C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
          C:\Windows\system32\wbem\wmiprvse.exe
          C:\Windows\System32\rundll32.exe
          C:\Users\Benoit\AppData\Roaming\drivers\winupgro.exe
          C:\Users\Benoit\AppData\Roaming\m\flec006.exe
          C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
          C:\Windows\system32\wbem\unsecapp.exe
          C:\Windows\system32\wbem\wmiprvse.exe
          C:\Windows\system32\SearchProtocolHost.exe
          C:\Windows\system32\SearchFilterHost.exe
          C:\Windows\system32\conime.exe

          ############################## | Processus infectieux stoppés |

          "C:\Users\Benoit\AppData\Roaming\drivers\winupgro.exe" (3224)
          "C:\Users\Benoit\AppData\Roaming\m\flec006.exe" (3232)

          ################## | C: |

          ################## | C:\Windows |

          ################## | C:\Windows\system32 |

          ################## | C:\Windows\system32\drivers |

          ################## | C:\Users\Benoit\AppData\Roaming |

          Présent ! C:\Users\Benoit\AppData\Roaming\drivers
          Présent ! C:\Users\Benoit\AppData\Roaming\drivers\111wfs1intwq.sys
          Présent ! C:\Users\Benoit\AppData\Roaming\drivers\11s11ro1s1a2.sys
          Présent ! C:\Users\Benoit\AppData\Roaming\drivers\downld
          Présent ! C:\Users\Benoit\AppData\Roaming\drivers\winupgro.exe
          Présent ! C:\Users\Benoit\AppData\Roaming\m
          Présent ! C:\Users\Benoit\AppData\Roaming\m\flec006.exe

          ################## | C:\Users\Benoit\Temporary Internet Files |

          Présent ! C:\Users\Benoit\Local Settings\Temporary Internet Files\Content.IE5\B5CXT5PO\b64[1].jpg

          ################## | Registre / Clés infectieuses |

          Présent ! [HKLM\SYSTEM\CurrentControlSet\Services\111111s1ro1s1a]
          Présent ! [HKLM\SYSTEM\ControlSet001\Services\111111s1ro1s1a]
          Présent ! [HKLM\SYSTEM\ControlSet003\Services\111111s1ro1s1a]
          Présent ! [HKLM\SYSTEM\CurrentControlSet\Services\sK9Ou0s]
          Présent ! [HKLM\SYSTEM\ControlSet001\Services\sK9Ou0s]
          Présent ! [HKLM\SYSTEM\ControlSet003\Services\sK9Ou0s]
          Présent ! [HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_111111s1ro1s1a]
          Présent ! [HKLM\SYSTEM\ControlSet001\Enum\Root\LEGACY_111111s1ro1s1a]
          Présent ! [HKLM\SYSTEM\ControlSet003\Enum\Root\LEGACY_111111s1ro1s1a]
          Présent ! [HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SK9OU0S]
          Présent ! [HKLM\SYSTEM\ControlSet001\Enum\Root\LEGACY_SK9OU0S]
          Présent ! [HKLM\SYSTEM\ControlSet003\Enum\Root\LEGACY_SK9OU0S]
          Présent ! [HKCU\Software\bisoft]
          Présent ! [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] "drvsyskit"
          Présent ! [HKU\S-1-5-21-1428904940-2868715994-2916266846-1000\Software\Microsoft\Windows\CurrentVersion\Run] "drvsyskit"
          Présent ! [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] "mule_st_key"
          Présent ! [HKU\S-1-5-21-1428904940-2868715994-2916266846-1000\Software\Microsoft\Windows\CurrentVersion\Run] "mule_st_key"
          Présent ! [HKU\S-1-5-21-1428904940-2868715994-2916266846-1000\Software\bisoft]
          Présent ! [HKCU\Software\Local AppWizard-Generated Applications\winupgro]
          Présent ! [HKU\S-1-5-21-1428904940-2868715994-2916266846-1000\Software\Local AppWizard-Generated Applications\winupgro]

          ################## | Etat / Services / Informations |

          # Affichage des fichiers cachés : OK

          # Mode sans echec : OK

          # (!) Uac = 0x0

          # (!) Ndisuio -> Start = 4 ( Good = 3 | Bad = 4 )
          # EapHost -> Start = 3 ( Good = 2 | Bad = 4 )
          # Wlansvc -> Start = 2 ( Good = 2 | Bad = 4 )
          # (!) SharedAccess -> Start = 4 ( Good = 2 | Bad = 4 )
          # (!) windefend -> Start = 4 ( Good = 2 | Bad = 4 )
          # (!) wuauserv -> Start = 4 ( Good = 2 | Bad = 4 )
          # (!) wscsvc -> Start = 4 ( Good = 2 | Bad = 4 )

          ################## | Cracks / Keygens / Serials |

          ################## | ! Fin du rapport # FindyKill V5.006 ! |
          1. Pour avancer mon amis Destrio5 .

            Benoit ,

            ! Déconnecte toi et ferme toutes application en cours ( navigateur compris ) .

            • Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...)

            • Relance "FindyKill" : au menu principal choisis l'option " F " pour français et tape sur [entrée] .

            • Au second menu choisis l'option 2 (suppression) et tape sur [entrée]

            • Le pc va redémarrer automatiquement ...

            ▶ le programme va travailler , ne touche à rien ... , ton bureau ne sera pas accessible c est normal !

            --> Poste le rapport qui apparait à la fin ( le rapport est sauvegardé aussi sous C:\FindyKill.txt )

            /!\ Si le Bureau ne réapparait pas, presse Ctrl + Alt + Suppr , Onglet "Fichier" , "Nouvelle tâche" , tape explorer.exe et valide

            Aides en images ( Suppression ) : http://pagesperso-orange.fr/NosTools/findykill.html

            1. ############################## | FindyKill V5.006 |

              # User : Benoit (Administrateurs) # PC-DE-BENOIT
              # Update on 14/08/09 by Chiquitine29
              # Start at: 18:34:18 | 22/08/2009
              # Website : http://pagesperso-orange.fr/NosTools/index.html

              # Intel(R) Core(TM)2 Quad CPU Q8200 @ 2.33GHz
              # Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6002 32-bit) # Service Pack 2
              # Internet Explorer 8.0.6001.18813
              # Windows Firewall Status : Enabled

              # C:\ # Disque fixe local # 293,33 Go (167,84 Go free) [ACER] # NTFS
              # D:\ # Disque fixe local # 293,08 Go (260,53 Go free) [DATA] # NTFS
              # E:\ # Disque CD-ROM
              # F:\ # Disque amovible
              # G:\ # Disque amovible
              # H:\ # Disque amovible
              # I:\ # Disque amovible

              ############################## | Processus actifs |

              C:\Windows\System32\smss.exe
              C:\Windows\system32\csrss.exe
              C:\Windows\system32\wininit.exe
              C:\Windows\system32\csrss.exe
              C:\Windows\system32\services.exe
              C:\Windows\system32\lsass.exe
              C:\Windows\system32\lsm.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\system32\nvvsvc.exe
              C:\Windows\system32\winlogon.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\system32\LogonUI.exe
              C:\Windows\System32\svchost.exe
              C:\Windows\System32\svchost.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\system32\SLsvc.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\system32\rundll32.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\System32\spoolsv.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\system32\userinit.exe
              C:\Windows\system32\Dwm.exe
              C:\Windows\system32\taskeng.exe
              C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
              C:\Windows\Explorer.EXE
              C:\Windows\system32\runonce.exe
              C:\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
              C:\Windows\system32\taskeng.exe
              C:\Program Files\Google\Update\GoogleUpdate.exe
              C:\Program Files\Google\Update\GoogleUpdate.exe
              C:\Windows\system32\HerculesWiFiService.exe
              C:\Windows\system32\conime.exe
              C:\Program Files\Google\Update\GoogleUpdate.exe
              C:\Program Files\Common Files\LightScribe\LSSrvc.exe
              C:\Windows\system32\PnkBstrA.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\System32\svchost.exe
              C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
              C:\Windows\system32\SearchIndexer.exe
              C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
              C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
              C:\Windows\system32\wbem\wmiprvse.exe
              C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe

              ################## | C: |

              ################## | C:\Windows |

              ################## | C:\Windows\system32 |

              ################## | C:\Windows\system32\drivers |

              ################## | C:\Users\Benoit\AppData\Roaming |

              Supprimé ! C:\Users\Benoit\AppData\Roaming\drivers\111wfs1intwq.sys
              Supprimé ! C:\Users\Benoit\AppData\Roaming\drivers\11s11ro1s1a2.sys
              Supprimé ! C:\Users\Benoit\AppData\Roaming\drivers\winupgro.exe
              Supprimé ! C:\Users\Benoit\AppData\Roaming\m\flec006.exe
              Supprimé ! C:\Users\Benoit\AppData\Roaming\drivers\downld
              Supprimé ! C:\Users\Benoit\AppData\Roaming\drivers
              Supprimé ! C:\Users\Benoit\AppData\Roaming\m

              ################## | Autres ... |

              # Références de comparaison Bagle MD5 :

              File : C:\Users\Benoit\AppData\Roaming\drivers\winupgro.exe
              -> Crc32 : 0155c093 | Md5 : d96a5602347e06de6eb485a57c960d07

              ################## | Temporary Internet Files |

              Supprimé ! C:\Users\Benoit\Local Settings\Temporary Internet Files\Content.IE5\B5CXT5PO\b64[1].jpg

              ################## | Registre / Clés infectieuses |

              Supprimé ! [HKCU\Software\bisoft]
              Supprimé ! [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] "drvsyskit"
              Supprimé ! [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] "mule_st_key"
              Supprimé ! [HKCU\Software\Local AppWizard-Generated Applications\winupgro]

              ################## | Etat / Services / Informations |

              # Mode sans echec : OK

              # Affichage des fichiers cachés : OK

              # Uac : OK

              # Ndisuio -> Start = 3 ( Good = 3 | Bad = 4 )
              # EapHost -> Start = 2 ( Good = 2 | Bad = 4 )
              # Wlansvc -> Start = 2 ( Good = 2 | Bad = 4 )
              # SharedAccess -> Start = 2 ( Good = 2 | Bad = 4 )
              # windefend -> Start = 2 ( Good = 2 | Bad = 4 )
              # wuauserv -> Start = 2 ( Good = 2 | Bad = 4 )
              # wscsvc -> Start = 2 ( Good = 2 | Bad = 4 )

              ################## | PEH ... |

              Corrompu : C:\Program Files\Alwil Software\Avast4\ashAvast.exe
              [Offset = 0000011C - Valeur = 0x0001]

              Corrompu : C:\Program Files\Alwil Software\Avast4\ashDisp.exe
              [Offset = 00000124 - Valeur = 0x0001]

              ################## | Cracks / Keygens / Serials |

              "C:\ProgramData\America's Army Deploy Client\dcds\patches\"AA2DeployInstaller.exe""
              01/07/2009 22:06 |Size 280292 |Crc32 e0fb02a5 |Md5 fe97275d6d84b85a7b8be715f47167b1

              ################## | ! Fin du rapport # FindyKill V5.006 ! |
              1. 1 ) Désinstal findykill

                2 ) redémarre le pc

                3 ) ▶ Télécharge random's system information tool (RSIT) et sauvegarde-le sur le Bureau.

                • Double-clique sur RSIT.exe afin de lancer RSIT.

                • Lis le contenu de l'écran Disclaimer puis clique sur Continue (si tu acceptes les conditions).

                • Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.

                • Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront.

                • Poste le contenu de log.txt et info.txt .

                • Tuto : https://forum.pcastuces.com/randoms_system_information_tool_rsit-f31s31.htm
                1. Voici rapport Info

                  info.txt logfile of random's system information tool 1.06 2009-08-22 19:00:10

                  ======Uninstall list======

                  7-Zip 4.65-->"C:\Program Files\7-Zip\Uninstall.exe"
                  Acer Arcade Live Main Page-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{EFBDC2B0-FAA8-4B78-8DE1-AEBE7958FA37}\SETUP.exe" -uninstall
                  Acer DV Magician-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F6EFFB76-4A07-11DA-9D78-000129760D75}\SETUP.exe" -uninstall
                  Acer eDataSecurity Management-->C:\Acer\Empowering Technology\eDataSecurity\x86\eDSnstHelper.exe -Operation UNINSTALL
                  Acer Empowering Technology-->"C:\Program Files\InstallShield Installation Information\{AB6097D9-D722-4987-BD9E-A076E2848EE2}\setup.exe" -runfromtemp -l0x040c -removeonly
                  Acer ePerformance Management-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D462BF9E-0C35-4705-BF9B-3DF9F3816643}\setup.exe" -l0x40c -removeonly
                  Acer eSettings Management-->"C:\Program Files\InstallShield Installation Information\{CE65A9A0-9686-45C6-9098-3C9543A412F0}\setup.exe" -runfromtemp -l0x040c -removeonly
                  Acer HomeMedia Connect-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{132888AE-EF67-41C5-BCA2-7D5D2488AB63}\SETUP.exe" -uninstall
                  Acer HomeMedia Trial Creator-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B580C409-E16F-44FF-904D-3AE94E113BE0}\SETUP.EXE" -uninstall
                  Acer SlideShow DVD-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{41581EF5-45A7-11DA-9D78-000129760D75}\SETUP.exe" -uninstall
                  Adobe Flash Player 10 Plugin-->C:\Windows\system32\Macromed\Flash\uninstall_plugin.exe
                  Adobe Flash Player 9 ActiveX-->C:\Windows\system32\Macromed\Flash\FlashUtil9b.exe -uninstallDelete
                  Adobe Flash Player ActiveX-->C:\Windows\system32\Macromed\Flash\uninstall_activeX.exe
                  Adobe Reader 8.1.6 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A81300000003}
                  Age of Empires III-->C:\Program Files\InstallShield Installation Information\{70F8B183-99EB-4304-BA35-080E2DFFD2A3}\install.exe -runfromtemp -l0x040c
                  America's Army 3-->"C:\Program Files\Steam\steam.exe" steam://uninstall/13140
                  America's Army Deploy Client-->MsiExec.exe /I{6D6204C8-6B1D-4FBA-ADA9-CB6DFF9BF80D}
                  Analyseur et SDK MSXML 4.0 SP2-->MsiExec.exe /I{716E0306-8318-4364-8B8F-0CC4E9376BAC}
                  Assistant de connexion Windows Live ID-->MsiExec.exe /X{10A44844-4465-456E-8C97-80BDD4F68845}
                  avast! Antivirus-->C:\Program Files\Alwil Software\Avast4\aswRunDll.exe "C:\Program Files\Alwil Software\Avast4\Setup\setiface.dll",RunSetup
                  CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
                  Cessena 414A Chancellor For FSX FSX-->C:\PROGRA~2\TARMAI~1\{66434~1\Setup.exe /remove /q0
                  Choice Guard-->MsiExec.exe /I{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}
                  Concorde Collection FSX -->C:\PROGRA~2\TARMAI~1\{154F6~1\Setup.exe /remove /q0
                  DRIV3R-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{01DBF423-E27B-45DA-B7F3-F9D4DB39B1C9}\setup.exe" -l0x40c
                  Euro Truck Simulator 1.2-->C:\Program Files\Euro Truck Simulator\uninst.exe
                  Everest Poker (Remove Only)-->C:\Program Files\Everest Poker\cstart.exe /uninstall
                  FlatOut Ultimate Carnage-->C:\Program Files\Empire Interactive\FlatOut Ultimate Carnage\Uninstall.exe
                  Google Update Helper-->MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
                  Google Earth-->MsiExec.exe /X{CC016F21-3970-11DE-B878-005056806466}
                  Hercules WiFi N-->C:\Program Files\InstallShield Installation Information\{DECE22F4-EEDD-4615-BC56-2F4827FAD64B}\setup.exe -runfromtemp -l0x040c -removeonly
                  HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
                  Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
                  Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
                  Installation Windows Live-->C:\Program Files\Windows Live\Installer\wlarp.exe
                  Installation Windows Live-->MsiExec.exe /I{7370DF47-B4F9-4279-BFC3-3F09919F720D}
                  Java(TM) 6 Update 11-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216011FF}
                  K-Lite Codec Pack 4.3.4 (Full)-->"C:\Program Files\K-Lite Codec Pack\unins000.exe"
                  Les Sims : Entre Chiens et Chats-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7C32C567-DC0F-4C80-B06C-7873850A2E06}\Setup.exe" -l040c
                  livebox-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{17342E3B-0818-4A6F-BFF8-99476605ADD6}\Setup.exe" -l0x40c
                  Microsoft .NET Framework 3.5 Language Pack SP1 - fra-->MsiExec.exe /I{3E31821C-7917-367E-938E-E65FC413EA31}
                  Microsoft .NET Framework 3.5 SP1-->C:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
                  Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
                  Microsoft Flight Simulator X Service Pack 1-->C:\Windows\system32\msiexec.exe /qb /l*vx "%TEMP%\FlightSimPatchUninstall.log" /uninstall {4576CB22-DC03-48A0-B74C-6C0A7F23E0A8} /package {9527A496-5DF9-412A-ADC7-168BA5379CA6}
                  Microsoft Flight Simulator X-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\11\INTEL3~1\IDriver.exe /M{9527A496-5DF9-412A-ADC7-168BA5379CA6}
                  Microsoft Flight Simulator X-->MsiExec.exe /X{9527A496-5DF9-412A-ADC7-168BA5379CA6}
                  Microsoft Games for Windows - LIVE Redistributable-->MsiExec.exe /X{B578C85A-A84C-4230-A177-C5B2AF565B8C}
                  Microsoft Games for Windows - LIVE-->MsiExec.exe /X{B45FABE7-D101-4D99-A671-E16DA40AF7F0}
                  Microsoft Office Live Add-in 1.4-->MsiExec.exe /I{AE3CF174-872C-46C6-B9F6-C0593F3BC7B8}
                  Microsoft Office Professional Edition 2003-->MsiExec.exe /I{9011040C-6000-11D3-8CFE-0150048383C9}
                  Microsoft Silverlight-->MsiExec.exe /I{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
                  Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053-->MsiExec.exe /X{770657D0-A123-3C07-8E44-1C83EC895118}
                  Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
                  Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{A49F249F-0C91-497F-86DF-B2585E8E76B7}
                  Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148-->MsiExec.exe /X{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}
                  Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022-->MsiExec.exe /X{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}
                  Microsoft Works-->MsiExec.exe /I{6B1CB38D-E2E4-4A30-933D-EFDEBA76AD9C}
                  Module linguistique Microsoft .NET Framework 3.5 SP1- fra-->C:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 Language Pack SP1 - fra\setup.exe
                  Mozilla Firefox (3.5.2)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
                  MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
                  MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
                  NTI Backup NOW! 4.7-->C:\Program Files\InstallShield Installation Information\{1598034D-7147-432C-8CA8-888E0632D124}\setup.exe -runfromtemp -l0x040c
                  NTI CD & DVD-Maker-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{1577A05B-EE62-4BBC-9DB7-FE748FA44EC2} /l1036 CDM7
                  NVIDIA Drivers-->C:\Windows\system32\nvuninst.exe UninstallGUI
                  PunkBuster Services-->C:\Windows\system32\pbsvc.exe -u
                  QuickTime-->MsiExec.exe /I{216AB108-2AE1-4130-B3D5-20B2C4C80F8F}
                  Realtek High Definition Audio Driver-->RtlUpd.exe -r -m -nrg2709
                  Search Settings 1.2.1-->MsiExec.exe /X{0B1AAC97-8563-41D9-AE47-58E6A222F0E1}
                  Skype™ 4.0-->MsiExec.exe /X{24D753CA-6AE9-4E30-8F5F-EFC93E08BF3D}
                  SpeedFan (remove only)-->"C:\Program Files\SpeedFan\uninstall.exe"
                  Spybot - Search & Destroy-->"C:\Program Files\Spybot - Search & Destroy\unins000.exe"
                  Steam-->MsiExec.exe /X{048298C9-A4D3-490B-9FF9-AB023A9238F3}
                  TmNationsForever-->"C:\Program Files\TmNationsForever\unins000.exe"
                  Tom A330-200 FSX-->C:\PROGRA~2\TARMAI~1\{8E326~1\Setup.exe /remove /q0
                  Update for Microsoft .NET Framework 3.5 SP1 (KB963707)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {B2AE9C82-DC7B-3641-BFC8-87275C4F3607} /qb+ REBOOTPROMPT=""
                  Visual C++ 2008 x86 Runtime - (v9.0.30729)-->MsiExec.exe /X{F333A33D-125C-32A2-8DCE-5C5D14231E27}
                  Visual C++ 2008 x86 Runtime - v9.0.30729.01-->C:\Windows\system32\msiexec.exe /x {F333A33D-125C-32A2-8DCE-5C5D14231E27} /qb+ REBOOTPROMPT=""
                  WarRock-->C:\Program Files\InstallShield Installation Information\{00D15456-F679-4AD4-8BD2-56450D4C3F72}\setup.exe -runfromtemp -l0x0009 -removeonly
                  Windows Live Call-->MsiExec.exe /I{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}
                  Windows Live Communications Platform-->MsiExec.exe /I{3B4E636E-9D65-4D67-BA61-189800823F52}
                  Windows Live Messenger-->MsiExec.exe /X{059C042E-796A-4ACC-A81A-ECC2010BB78C}
                  Windows Live OneCare safety scanner-->MsiExec.exe /X{FE0646A7-19D0-41B4-A2BB-2C35D644270D}
                  Windows Media Player Firefox Plugin-->MsiExec.exe /I{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}

                  ======Hosts File======

                  127.0.0.1 www.007guard.com
                  127.0.0.1 007guard.com
                  127.0.0.1 008i.com
                  127.0.0.1 www.008k.com
                  127.0.0.1 008k.com
                  127.0.0.1 www.00hq.com
                  127.0.0.1 00hq.com
                  127.0.0.1 010402.com
                  127.0.0.1 www.032439.com
                  127.0.0.1 032439.com

                  ======Security center information======

                  AS: Windows Defender

                  ======System event log======

                  Computer Name: PC-de-Benoit
                  Event Code: 4376
                  Message: Servicing a requis un redémarrage pour terminer la définition du package KB905866(Update) à l’état Désinstallation demandée(Uninstall Requested)
                  Record Number: 68458
                  Source Name: Microsoft-Windows-Servicing
                  Time Written: 20090311170821.000000-000
                  Event Type: Avertissement
                  User: AUTORITE NT\SYSTEM

                  Computer Name: PC-de-Benoit
                  Event Code: 4376
                  Message: Servicing a requis un redémarrage pour terminer la définition du package KB905866(Update) à l’état Installation demandée(Install Requested)
                  Record Number: 68456
                  Source Name: Microsoft-Windows-Servicing
                  Time Written: 20090311170821.000000-000
                  Event Type: Avertissement
                  User: AUTORITE NT\SYSTEM

                  Computer Name: PC-de-Benoit
                  Event Code: 4376
                  Message: Servicing a requis un redémarrage pour terminer la définition du package KB905866(Update) à l’état Installation demandée(Install Requested)
                  Record Number: 68454
                  Source Name: Microsoft-Windows-Servicing
                  Time Written: 20090311170821.000000-000
                  Event Type: Avertissement
                  User: AUTORITE NT\SYSTEM

                  Computer Name: PC-de-Benoit
                  Event Code: 4376
                  Message: Servicing a requis un redémarrage pour terminer la définition du package KB905866(Update) à l’état Installation demandée(Install Requested)
                  Record Number: 68451
                  Source Name: Microsoft-Windows-Servicing
                  Time Written: 20090311170821.000000-000
                  Event Type: Avertissement
                  User: AUTORITE NT\SYSTEM

                  Computer Name: PC-de-Benoit
                  Event Code: 4376
                  Message: Servicing a requis un redémarrage pour terminer la définition du package KB905866(Update) à l’état Installation demandée(Install Requested)
                  Record Number: 68448
                  Source Name: Microsoft-Windows-Servicing
                  Time Written: 20090311170821.000000-000
                  Event Type: Avertissement
                  User: AUTORITE NT\SYSTEM

                  =====Application event log=====

                  Computer Name: PC-de-Benoit
                  Event Code: 8194
                  Message: Erreur du service de cliché instantané des volumes : erreur lors de l’interrogation de l’interface IVssWriterCallback. hr = 0x80070005. Cette erreur est souvent due à des paramètres de sécurité incorrects dans le processus du rédacteur ou du demandeur.

                  Opération :
                  Données du rédacteur en cours de collecte

                  Contexte :
                  ID de classe du rédacteur: {e8132975-6f93-4464-a53e-1050253ae220}
                  Nom du rédacteur: System Writer
                  ID d’instance du rédacteur: {6c28860c-0096-4bb1-9480-56f416cc3075}
                  Record Number: 637
                  Source Name: VSS
                  Time Written: 20081205201601.000000-000
                  Event Type: Erreur
                  User:

                  Computer Name: PC-de-Benoit
                  Event Code: 10
                  Message: Le filtre d’événement avec la requête « SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99 » n’a pas pu être réactivé dans l’espace de noms « //./root/CIMV2 » à cause de l’erreur 0x80041003. Les événements ne peuvent pas être délivrés à travers ce filtre tant que le problème ne sera pas corrigé.
                  Record Number: 624
                  Source Name: Microsoft-Windows-WMI
                  Time Written: 20081205190101.000000-000
                  Event Type: Erreur
                  User:

                  Computer Name: PC-de-Benoit
                  Event Code: 10
                  Message: Le filtre d’événement avec la requête « SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99 » n’a pas pu être réactivé dans l’espace de noms « //./root/CIMV2 » à cause de l’erreur 0x80041003. Les événements ne peuvent pas être délivrés à travers ce filtre tant que le problème ne sera pas corrigé.
                  Record Number: 594
                  Source Name: Microsoft-Windows-WMI
                  Time Written: 20081205183847.000000-000
                  Event Type: Erreur
                  User:

                  Computer Name: PC-de-Benoit
                  Event Code: 10
                  Message: Le filtre d’événement avec la requête « SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99 » n’a pas pu être réactivé dans l’espace de noms « //./root/CIMV2 » à cause de l’erreur 0x80041003. Les événements ne peuvent pas être délivrés à travers ce filtre tant que le problème ne sera pas corrigé.
                  Record Number: 535
                  Source Name: Microsoft-Windows-WMI
                  Time Written: 20081205180933.000000-000
                  Event Type: Erreur
                  User:

                  Computer Name: PC-de-Benoit
                  Event Code: 1008
                  Message: Le service Windows Search tente de supprimer l’ancien catalogue.

                  Record Number: 529
                  Source Name: Microsoft-Windows-Search
                  Time Written: 20081205180931.000000-000
                  Event Type: Avertissement
                  User:

                  =====Security event log=====

                  Computer Name: PC-de-Benoit
                  Event Code: 4648
                  Message: Tentative d’ouverture de session en utilisant des informations d’identification explicites.

                  Sujet :
                  ID de sécurité : S-1-5-18
                  Nom du compte : PC-DE-BENOIT$
                  Domaine du compte : WORKGROUP
                  ID d’ouverture de session : 0x3e7
                  GUID d’ouverture de session : {00000000-0000-0000-0000-000000000000}

                  Compte dont les informations d’identification ont été utilisées :
                  Nom du compte : SYSTEM
                  Domaine du compte : AUTORITE NT
                  GUID d’ouverture de session : {00000000-0000-0000-0000-000000000000}

                  Serveur cible :
                  Nom du serveur cible : localhost
                  Informations supplémentaires : localhost

                  Informations sur le processus :
                  ID du processus : 0x270
                  Nom du processus : C:\Windows\System32\services.exe

                  Informations sur le réseau :
                  Adresse du réseau : -
                  Port : -

                  Cet événement est généré lorsqu’un processus tente d’ouvrir une session pour un compte en spécifiant explicitement les informations d’identification de ce compte. Ceci se produit le plus souvent dans les configurations par lot comme les tâches planifiées, ou avec l’utilisation de la commande RUNAS.
                  Record Number: 21571
                  Source Name: Microsoft-Windows-Security-Auditing
                  Time Written: 20090312201211.955840-000
                  Event Type: Succès de l'audit
                  User:

                  Computer Name: PC-de-Benoit
                  Event Code: 4902
                  Message: La table de stratégie d’audit par utilisateur a été créée.

                  Nombre d’éléments : 0
                  ID de la stratégie : 0x10ef2
                  Record Number: 21570
                  Source Name: Microsoft-Windows-Security-Auditing
                  Time Written: 20090312201211.877839-000
                  Event Type: Succès de l'audit
                  User:

                  Computer Name: PC-de-Benoit
                  Event Code: 4624
                  Message: L’ouverture de session d’un compte s’est correctement déroulée.

                  Sujet :
                  ID de sécurité : S-1-0-0
                  Nom du compte : -
                  Domaine du compte : -
                  ID d’ouverture de session : 0x0

                  Type d’ouverture de session : 0

                  Nouvelle ouverture de session :
                  ID de sécurité : S-1-5-18
                  Nom du compte : SYSTEM
                  Domaine du compte : AUTORITE NT
                  ID d’ouverture de session : 0x3e7
                  GUID d’ouverture de session : {00000000-0000-0000-0000-000000000000}

                  Informations sur le processus :
                  ID du processus : 0x4
                  Nom du processus :

                  Informations sur le réseau :
                  Nom de la station de travail : -
                  Adresse du réseau source : -
                  Port source : -

                  Informations détaillées sur l’authentification :
                  Processus d’ouverture de session : -
                  Package d’authentification : -
                  Services en transit : -
                  Nom du package (NTLM uniquement) : -
                  Longueur de la clé : 0

                  Cet événement est généré lors de la création d’une ouverture de session. Il est généré sur l’ordinateur sur lequel l’ouverture de session a été effectuée.

                  Le champ Objet indique le compte sur le système local qui a demandé l’ouverture de session. Il s’agit le plus souvent d’un service, comme le service Serveur, ou un processus local tel que Winlogon.exe ou Services.exe.

                  Le champ Type d’ouverture de session indique le type d’ouverture de session qui s’est produit. Les types les plus courants sont 2 (interactif) et 3 (réseau).

                  Le champ Nouvelle ouverture de session indique le compte pour lequel la nouvelle ouverture de session a été créée, par exemple, le compte qui s’est connecté.

                  Les champs relatifs au réseau indiquent la provenance d’une demande d’ouverture de session à distance. Le nom de la station de travail n’étant pas toujours disponible, peut être laissé vide dans certains cas.

                  Les champs relatifs aux informations d’authentification fournissent des détails sur cette demande d’ouverture de session spécifique.
                  - Le GUID d’ouverture de session est un identificateur unique pouvant servir à associer cet événement à un événement KDC .
                  - Les services en transit indiquent les services intermédiaires qui ont participé à cette demande d’ouverture de session.
                  - Nom du package indique quel est le sous-protocole qui a été utilisé parmi les protocoles NTLM.
                  - La longueur de la clé indique la longueur de la clé de session générée. Elle a la valeur 0 si aucune clé de session n’a été demandée.
                  Record Number: 21569
                  Source Name: Microsoft-Windows-Security-Auditing
                  Time Written: 20090312201211.846639-000
                  Event Type: Succès de l'audit
                  User:

                  Computer Name: PC-de-Benoit
                  Event Code: 4608
                  Message: Windows démarre.

                  Cet événement est journalisé lorsque LSASS.EXE démarre et que le sous-système d’audit est initialisé.
                  Record Number: 21568
                  Source Name: Microsoft-Windows-Security-Auditing
                  Time Written: 20090312201211.846639-000
                  Event Type: Succès de l'audit
                  User:

                  Computer Name: PC-de-Benoit
                  Event Code: 4634
                  Message: Fermeture de session d’un compte.

                  Sujet :
                  ID de sécurité : S-1-5-7
                  Nom du compte : ANONYMOUS LOGON
                  Domaine du compte : AUTORITE NT
                  ID du compte : 0x5be7f

                  Type d’ouverture de session : 3

                  Cet événement est généré lorsqu’une session ouverte est supprimée. Il peut être associé à un événement d’ouverture de session en utilisant la valeur ID d’ouverture de session. Les ID d’ouverture de session ne sont uniques qu’entre les redémarrages sur un même ordinateur.
                  Record Number: 21567
                  Source Name: Microsoft-Windows-Security-Auditing
                  Time Written: 20090312201107.181200-000
                  Event Type: Succès de l'audit
                  User:

                  ======Environment variables======

                  "ComSpec"=%SystemRoot%\system32\cmd.exe
                  "FP_NO_HOST_CHECK"=NO
                  "OS"=Windows_NT
                  "Path"=%CommonProgramFiles%\Microsoft Shared\Windows Live;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Acer\Empowering Technology\eDataSecurity;C:\Acer\Empowering Technology\eDataSecurity\x86;C:\Acer\Empowering Technology\eDataSecurity\x64;C:\Program Files\QuickTime\QTSystem\
                  "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
                  "PROCESSOR_ARCHITECTURE"=x86
                  "TEMP"=%SystemRoot%\TEMP
                  "TMP"=%SystemRoot%\TEMP
                  "USERNAME"=SYSTEM
                  "windir"=%SystemRoot%
                  "PROCESSOR_LEVEL"=6
                  "PROCESSOR_IDENTIFIER"=x86 Family 6 Model 23 Stepping 7, GenuineIntel
                  "PROCESSOR_REVISION"=1707
                  "NUMBER_OF_PROCESSORS"=4
                  "TRACE_FORMAT_SEARCH_PATH"=\\NTREL202.ntdev.corp.microsoft.com\4F18C3A5-CA09-4DBD-B6FC-219FDD4C6BE0\TraceFormat
                  "DFSTRACINGON"=FALSE
                  "CLASSPATH"=.;C:\Program Files\Java\jre6\lib\ext\QTJava.zip
                  "QTJAVA"=C:\Program Files\Java\jre6\lib\ext\QTJava.zip

                  -----------------EOF-----------------
                  1. Pour le rapport log j'ai fais une bêtise je l'ai fermer donc je refai l'analyse et je le poste
                    1. voila le rapport log

                      Logfile of random's system information tool 1.06 (written by random/random)
                      Run by Benoit at 2009-08-22 19:17:51
                      Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 2
                      System drive C: has 172 GB (57%) free of 300 GB
                      Total RAM: 3071 MB (68% free)

                      Logfile of Trend Micro HijackThis v2.0.2
                      Scan saved at 19:17:57, on 22/08/2009
                      Platform: Windows Vista SP2 (WinNT 6.00.1906)
                      MSIE: Internet Explorer v8.00 (8.00.6001.18813)
                      Boot mode: Normal

                      Running processes:
                      C:\Windows\system32\Dwm.exe
                      C:\Windows\system32\taskeng.exe
                      C:\Windows\Explorer.EXE
                      C:\Windows\System32\rundll32.exe
                      C:\Program Files\SpeedFan\speedfan.exe
                      C:\Windows\system32\wbem\unsecapp.exe
                      C:\Users\Benoit\Desktop\RSIT.exe
                      C:\Program Files\trend micro\Benoit.exe

                      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&l=040c&s=1&o=vp32&d=0908&m=aspire_m3641
                      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
                      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ask.com/?o=101764&l=dis
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://fr.fr.acer.yahoo.com
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
                      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ustart.org
                      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                      R3 - URLSearchHook: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\kb128\SearchSettings.dll
                      O1 - Hosts: ::1 localhost
                      O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                      O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
                      O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
                      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                      O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                      O2 - BHO: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\kb128\SearchSettings.dll
                      O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll
                      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                      O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
                      O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
                      O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                      O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                      O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                      O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                      O4 - Startup: SpeedFan.lnk = C:\Program Files\SpeedFan\speedfan.exe
                      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                      O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                      O13 - Gopher Prefix:
                      O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
                      O23 - Service: ePerformance Service (AcerMemUsageCheckService) - Unknown owner - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
                      O23 - Service: eDataSecurity Service - Egis Incorporated - C:\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
                      O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
                      O23 - Service: eSettings Service (eSettingsService) - Unknown owner - C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
                      O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
                      O23 - Service: HerculesWiFi - Guillemot Corporation - C:\Windows\system32\HerculesWiFiService.exe
                      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
                      O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                      O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
                      O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
                      O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
                      1. Télécharge Toolbar-S&D (Team IDN) sur ton Bureau.

                        * Double-clique maintenant sur ToolBarSD.exe
                        * Sélectionne la langue souhaitée en tapant la lettre de ton choix puis en validant avec la touche Entrée.
                        * Choisis maintenant l'option 2 (RSuppression). Patiente jusqu'à la fin de la recherche.
                        * Poste le rapport généré. (C:\TB.txt)

                        #########

                        désisntal avast car hors servive , dailleurs je te propose de le remplacer par antivir (gratuit aussi )

                        Regarde ceci concernant avast :

                        Antivir vs Avast :

                        -> http://forum.malekal.com/ftopic3528.php

                        Alors je te conseille de le desinstaller et d´installer antivir a la place

                        Telecharge et instales l'antivirus Antivir Personal Edition Classic :

                        ->Antivir le telecharger

                        • Tuto : https://www.malekal.com/avira-free-security-antivirus-gratuit/
                        • Tuto : http://www.swl1f.net/viewtopic.php?f=14&t=59

                        Pour désinstaller Avast telecharge cet outil

                        ##########

                        Une fois antivir a jours , scan avec celui ci et post son rapport stp .
                        1. Euh toolbar ne marche pas il me met se message "windows ne trouve pas c:/toolbarsd/ toolbarsd.cmd"verifier que vous avez entrer le nom correcte.

                          Et pour antivir je suis en train de m'y mettre
                          1. ok passe antivir ,

                            Destrio prendra la suite a son retour , car j ai a faire .

                            Bonne soirée .
                            1. Modérateur
                              ● Désinstalle Search Settings.

                              ● Télécharge Ad-Remover (de Cyrildu17 / C_XX) sur ton Bureau.

                              /!\ Déconnecte-toi d'Internet et ferme toutes applications en cours. /!\

                              ● Double-clique sur le programme d'installation, installe-le dans son emplacement par défaut (C:\Program Files).
                              ● Double-clique sur le raccourci d'Ad-Remover située sur ton Bureau.
                              (Sous Vista, il faut cliquer droit sur le raccourci d'Ad-Remover et choisir Exécuter en tant qu'administrateur)
                              ● Au menu principal, choisis l'option L.
                              ● Poste le rapport généré (C:\Ad-Report-CLEAN.log).

                              (CTRL+A pour tout sélectionner, CTRL+C pour copier et CTRL+V pour coller)

                              Note : "Process.exe", une composante de l'outil, est détectée par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
                              1. Voila le rapport d'antivir

                                Avira AntiVir Personal
                                Date de création du fichier de rapport : samedi 22 août 2009 21:17

                                La recherche porte sur 1651917 souches de virus.

                                Détenteur de la licence : Avira AntiVir Personal - FREE Antivirus
                                Numéro de série : 0000149996-ADJIE-0000001
                                Plateforme : Windows Vista
                                Version de Windows : (Service Pack 2) [6.0.6002]
                                Mode Boot : Démarré normalement
                                Identifiant : SYSTEM
                                Nom de l'ordinateur : PC-DE-BENOIT

                                Informations de version :
                                BUILD.DAT : 9.0.0.65 17959 Bytes 22/04/2009 12:06:00
                                AVSCAN.EXE : 9.0.3.6 466689 Bytes 21/04/2009 12:20:54
                                AVSCAN.DLL : 9.0.3.0 49409 Bytes 03/03/2009 09:21:02
                                LUKE.DLL : 9.0.3.2 209665 Bytes 20/02/2009 10:35:11
                                LUKERES.DLL : 9.0.2.0 13569 Bytes 03/03/2009 09:21:31
                                ANTIVIR0.VDF : 7.1.0.0 15603712 Bytes 27/10/2008 10:29:38
                                ANTIVIR1.VDF : 7.1.4.132 5707264 Bytes 24/06/2009 08:20:48
                                ANTIVIR2.VDF : 7.1.5.146 3087360 Bytes 21/08/2009 09:34:54
                                ANTIVIR3.VDF : 7.1.5.149 9728 Bytes 21/08/2009 14:51:20
                                Version du moteur : 8.2.1.3
                                AEVDF.DLL : 8.1.1.1 106868 Bytes 30/04/2009 13:33:10
                                AESCRIPT.DLL : 8.1.2.25 459130 Bytes 12/08/2009 13:26:48
                                AESCN.DLL : 8.1.2.4 127348 Bytes 22/07/2009 15:43:44
                                AERDL.DLL : 8.1.2.4 430452 Bytes 14/07/2009 16:08:26
                                AEPACK.DLL : 8.1.3.18 401783 Bytes 27/05/2009 16:10:34
                                AEOFFICE.DLL : 8.1.0.38 196987 Bytes 17/06/2009 13:32:46
                                AEHEUR.DLL : 8.1.0.155 1921400 Bytes 18/08/2009 13:02:16
                                AEHELP.DLL : 8.1.6.0 233846 Bytes 18/08/2009 13:02:16
                                AEGEN.DLL : 8.1.1.57 356725 Bytes 18/08/2009 13:02:16
                                AEEMU.DLL : 8.1.0.9 393588 Bytes 15/10/2008 09:49:36
                                AECORE.DLL : 8.1.7.6 184694 Bytes 22/07/2009 15:43:42
                                AEBB.DLL : 8.1.0.3 53618 Bytes 15/10/2008 09:49:34
                                AVWINLL.DLL : 9.0.0.3 18177 Bytes 12/12/2008 07:47:30
                                AVPREF.DLL : 9.0.0.1 43777 Bytes 03/12/2008 10:39:26
                                AVREP.DLL : 8.0.0.3 155905 Bytes 20/01/2009 13:34:28
                                AVREG.DLL : 9.0.0.0 36609 Bytes 07/11/2008 14:24:42
                                AVARKT.DLL : 9.0.0.3 292609 Bytes 24/03/2009 14:05:22
                                AVEVTLOG.DLL : 9.0.0.7 167169 Bytes 30/01/2009 09:36:37
                                SQLITE3.DLL : 3.6.1.0 326401 Bytes 28/01/2009 14:03:49
                                SMTPLIB.DLL : 9.2.0.25 28417 Bytes 02/02/2009 07:20:57
                                NETNT.DLL : 9.0.0.0 11521 Bytes 07/11/2008 14:40:59
                                RCIMAGE.DLL : 9.0.0.21 2438401 Bytes 17/02/2009 12:49:32
                                RCTEXT.DLL : 9.0.37.0 88321 Bytes 15/04/2009 09:07:05

                                Configuration pour la recherche actuelle :
                                Nom de la tâche...............................: Contrôle intégral du système
                                Fichier de configuration......................: c:\program files\avira\antivir desktop\sysscan.avp
                                Documentation.................................: bas
                                Action principale.............................: interactif
                                Action secondaire.............................: ignorer
                                Recherche sur les secteurs d'amorçage maître..: marche
                                Recherche sur les secteurs d'amorçage.........: marche
                                Secteurs d'amorçage...........................: C:, D:,
                                Recherche dans les programmes actifs..........: marche
                                Recherche en cours sur l'enregistrement.......: marche
                                Recherche de Rootkits.........................: marche
                                Contrôle d'intégrité de fichiers système......: arrêt
                                Fichier mode de recherche.....................: Tous les fichiers
                                Recherche sur les archives....................: marche
                                Limiter la profondeur de récursivité..........: 20
                                Archive Smart Extensions......................: marche
                                Heuristique de macrovirus.....................: marche
                                Heuristique fichier...........................: moyen

                                Début de la recherche : samedi 22 août 2009 21:17

                                La recherche d'objets cachés commence.
                                '85637' objets ont été contrôlés, '0' objets cachés ont été trouvés.

                                La recherche sur les processus démarrés commence :
                                Processus de recherche 'avscan.exe' - '1' module(s) sont contrôlés
                                Processus de recherche 'avscan.exe' - '1' module(s) sont contrôlés
                                Processus de recherche 'avguard.exe' - '1' module(s) sont contrôlés
                                Processus de recherche 'avgnt.exe' - '1' module(s) sont contrôlés
                                Processus de recherche 'sched.exe' - '1' module(s) sont contrôlés
                                Processus de recherche 'taskeng.exe' - '1' module(s) sont contrôlés
                                Processus de recherche 'WmiPrvSE.exe' - '1' module(s) sont contrôlés
                                Processus de recherche 'unsecapp.exe' - '1' module(s) sont contrôlés
                                Processus de recherche 'sidebar.exe' - '1' module(s) sont contrôlés
                                Processus de recherche 'WLIDSVCM.EXE' - '1' module(s) sont contrôlés
                                Processus de recherche 'WmiPrvSE.exe' - '1' module(s) sont contrôlés
                                Processus de recherche 'speedfan.exe' - '1' module(s) sont contrôlés
                                Processus de recherche 'sidebar.exe' - '1' module(s) sont contrôlés
                                Processus de recherche 'rundll32.exe' - '1' module(s) sont contrôlés
                                Processus de recherche 'capuserv.exe' - '1' module(s) sont contrôlés
                                Processus de recherche 'eRecoveryService.exe' - '1' module(s) sont contrôlés
                                Processus de recherche 'SearchIndexer.exe' - '1' module(s) sont contrôlés
                                Processus de recherche 'WLIDSVC.EXE' - '1' module(s) sont contrôlés
                                Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
                                Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
                                Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
                                Processus de recherche 'PnkBstrA.exe' - '1' module(s) sont contrôlés
                                Processus de recherche 'LSSrvc.exe' - '1' module(s) sont contrôlés
                                Processus de recherche 'taskeng.exe' - '1' module(s) sont contrôlés
                                Processus de recherche 'HerculesWiFiService.exe' - '1' module(s) sont contrôlés
                                Processus de recherche 'explorer.exe' - '1' module(s) sont contrôlés
                                Processus de recherche 'eDSService.exe' - '1' module(s) sont contrôlés
                                Processus de recherche 'taskeng.exe' - '1' module(s) sont contrôlés
                                Processus de recherche 'dwm.exe' - '1' module(s) sont contrôlés
                                Processus de recherche 'MemCheck.exe' - '1' module(s) sont contrôlés
                                Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
                                Processus de recherche 'spoolsv.exe' - '1' module(s) sont contrôlés
                                Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
                                Processus de recherche 'rundll32.exe' - '1' module(s) sont contrôlés
                                Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
                                Processus de recherche 'SLsvc.exe' - '1' module(s) sont contrôlés
                                Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
                                Processus de recherche 'audiodg.exe' - '0' module(s) sont contrôlés
                                Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
                                Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
                                Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
                                Processus de recherche 'winlogon.exe' - '1' module(s) sont contrôlés
                                Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
                                Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
                                Processus de recherche 'nvvsvc.exe' - '1' module(s) sont contrôlés
                                Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
                                Processus de recherche 'lsm.exe' - '1' module(s) sont contrôlés
                                Processus de recherche 'lsass.exe' - '1' module(s) sont contrôlés
                                Processus de recherche 'services.exe' - '1' module(s) sont contrôlés
                                Processus de recherche 'csrss.exe' - '1' module(s) sont contrôlés
                                Processus de recherche 'wininit.exe' - '1' module(s) sont contrôlés
                                Processus de recherche 'csrss.exe' - '1' module(s) sont contrôlés
                                Processus de recherche 'smss.exe' - '1' module(s) sont contrôlés
                                '52' processus ont été contrôlés avec '52' modules

                                La recherche sur les secteurs d'amorçage maître commence :
                                Secteur d'amorçage maître HD0
                                [INFO] Aucun virus trouvé !
                                Secteur d'amorçage maître HD1
                                [INFO] Aucun virus trouvé !
                                [INFO] Veuillez relancer la recherche avec les droits d'administrateur
                                Secteur d'amorçage maître HD2
                                [INFO] Aucun virus trouvé !
                                [INFO] Veuillez relancer la recherche avec les droits d'administrateur
                                Secteur d'amorçage maître HD3
                                [INFO] Aucun virus trouvé !
                                [INFO] Veuillez relancer la recherche avec les droits d'administrateur
                                Secteur d'amorçage maître HD4
                                [INFO] Aucun virus trouvé !
                                [INFO] Veuillez relancer la recherche avec les droits d'administrateur

                                La recherche sur les secteurs d'amorçage commence :
                                Secteur d'amorçage 'C:\'
                                [INFO] Aucun virus trouvé !
                                Secteur d'amorçage 'D:\'
                                [INFO] Aucun virus trouvé !

                                La recherche sur les renvois aux fichiers exécutables (registre) commence :
                                Le registre a été contrôlé ( '36' fichiers).

                                La recherche sur les fichiers sélectionnés commence :

                                Recherche débutant dans 'C:\' <ACER>
                                C:\hiberfil.sys
                                [AVERTISSEMENT] Impossible d'ouvrir le fichier !
                                [REMARQUE] Ce fichier est un fichier système Windows.
                                [REMARQUE] Il est correct que ce fichier ne puisse pas être ouvert pour la recherche.
                                C:\pagefile.sys
                                [AVERTISSEMENT] Impossible d'ouvrir le fichier !
                                [REMARQUE] Ce fichier est un fichier système Windows.
                                [REMARQUE] Il est correct que ce fichier ne puisse pas être ouvert pour la recherche.
                                C:\Program Files\Everest Poker\cstart-tmp.exe
                                [RESULTAT] Contient le modèle de détection du ver WORM/SdBot.146432.4
                                C:\Windows\System32\drivers\sptd.sys
                                [AVERTISSEMENT] Impossible d'ouvrir le fichier !
                                Recherche débutant dans 'D:\' <DATA>

                                Début de la désinfection :
                                C:\Program Files\Everest Poker\cstart-tmp.exe
                                [RESULTAT] Contient le modèle de détection du ver WORM/SdBot.146432.4
                                [REMARQUE] Le fichier a été déplacé dans le répertoire de quarantaine sous le nom '4b044eda.qua' !

                                Fin de la recherche : samedi 22 août 2009 22:00
                                Temps nécessaire: 42:55 Minute(s)

                                La recherche a été effectuée intégralement

                                21146 Les répertoires ont été contrôlés
                                494372 Des fichiers ont été contrôlés
                                1 Des virus ou programmes indésirables ont été trouvés
                                0 Des fichiers ont été classés comme suspects
                                0 Des fichiers ont été supprimés
                                0 Des virus ou programmes indésirables ont été réparés
                                1 Les fichiers ont été déplacés dans la quarantaine
                                0 Les fichiers ont été renommés
                                3 Impossible de contrôler des fichiers
                                494368 Fichiers non infectés
                                2713 Les archives ont été contrôlées
                                3 Avertissements
                                3 Consignes
                                85637 Des objets ont été contrôlés lors du Rootkitscan
                                0 Des objets cachés ont été trouvés
                                1. Et voici le rapport de AD remouver

                                  .
                                  ======= RAPPORT D'AD-REMOVER 1.1.4.5_O | UNIQUEMENT XP/VISTA/SEVEN =======
                                  .
                                  Mit à jour par C_XX le 24/06/2009 à 7:10 PM
                                  Contact: AdRemover.contact@gmail.com
                                  Site web: http://pagesperso-orange.fr/NosTools/ad_remover.html
                                  .
                                  Lancé à: 22:19:00, 22/08/2009 | Mode Normal | Option: CLEAN
                                  Exécuté de: C:\Program Files\Ad-remover\
                                  Système d'exploitation: Microsoft® Windows Vista™ Home Premium Service Pack 2 v6.0.6002
                                  Nom du PC: PC-DE-BENOIT | Utilisateur actuel: Benoit
                                  .
                                  Administrateur: Administrateur *Desactive*
                                  Administrateur: Benoit
                                  N'est pas administrateur: Invité *Desactive*
                                  .
                                  ============== ÉLÉMENT(S) NEUTRALISÉ(S) ==============
                                  .
                                  .
                                  HKCR\CLSID\{9afb8248-617f-460d-9366-d71cdeda3179}
                                  HKCU\Software\AppDataLow\HavingFunOnline
                                  HKCU\Software\Grand Virtual
                                  HKCU\Software\Titan Poker
                                  HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Everest Poker
                                  HKLM\Software\Titan Poker
                                  HKLM\Software\Trymedia Systems
                                  .
                                  C:\PROGRA~2\MICROS~1\Windows\STARTM~1\Programs\Everest Poker\Everest Poker.lnk
                                  C:\PROGRA~2\MICROS~1\Windows\STARTM~1\Programs\Everest Poker\Uninstall Everest Poker.lnk
                                  C:\PROGRA~2\MICROS~1\Windows\STARTM~1\Programs\Everest Poker
                                  C:\ProgramData\Trymedia\data
                                  C:\ProgramData\Trymedia\licenses
                                  C:\ProgramData\Trymedia\data\{10881F3C-279D-D073-9F66-F6556F800BE2}
                                  C:\ProgramData\Trymedia\data\{2A8995E5-DFE1-772F-A617-5819AF190FBB}
                                  C:\ProgramData\Trymedia\data\{2AE42B5F-3A4C-5853-6243-AE206B8D9FC7}
                                  C:\ProgramData\Trymedia\data\{53543362-9229-21D7-982E-627771AAC5AC}
                                  C:\ProgramData\Trymedia\data\{5C4AEF11-D703-2EA4-72A0-B05290B95717}
                                  C:\ProgramData\Trymedia\data\{81771CD3-802B-4B7B-6CF4-89ECE0E1F128}
                                  C:\ProgramData\Trymedia\data\{81BE140A-0057-1A51-5C8C-2C7AF27285B6}
                                  C:\ProgramData\Trymedia\data\{9B99B4D4-3CD2-B264-DAA0-E98BABD26F99}
                                  C:\ProgramData\Trymedia\data\{A618D6EE-F6BA-7DAE-01CF-DBCF8FCAA136}
                                  C:\ProgramData\Trymedia\data\{B767AB69-00EC-94BF-BA57-C2443F225D54}
                                  C:\ProgramData\Trymedia\data\{E135BC3E-EA68-B0F8-15B4-F9A59DE5A915}
                                  C:\ProgramData\Trymedia\data\{FF8882D8-D9FB-A10C-8E0F-BED5284ADC8F}
                                  C:\ProgramData\Trymedia
                                  C:\Program Files\Everest Poker\casino.exe
                                  C:\Program Files\Everest Poker\cstart.exe
                                  C:\Program Files\Everest Poker\data
                                  C:\Program Files\Everest Poker\Everest Poker.exe
                                  C:\Program Files\Everest Poker\gvbase.dll
                                  C:\Program Files\Everest Poker\gvcrt.dll
                                  C:\Program Files\Everest Poker\gvgfx-dib.dll
                                  C:\Program Files\Everest Poker\gvgfx.dll
                                  C:\Program Files\Everest Poker\gvmain.dll
                                  C:\Program Files\Everest Poker\gvmain.exe
                                  C:\Program Files\Everest Poker\gvnetwork.dll
                                  C:\Program Files\Everest Poker\gvsound.dll
                                  C:\Program Files\Everest Poker\history
                                  C:\Program Files\Everest Poker\init.ini
                                  C:\Program Files\Everest Poker\log.dat
                                  C:\Program Files\Everest Poker\notes
                                  C:\Program Files\Everest Poker\settings.ini
                                  C:\Program Files\Everest Poker\toc_fr.ini
                                  C:\Program Files\Everest Poker\var
                                  C:\Program Files\Everest Poker\data\fonts
                                  C:\Program Files\Everest Poker\data\mp-lobby
                                  C:\Program Files\Everest Poker\data\mp-poker
                                  C:\Program Files\Everest Poker\data\shared
                                  C:\Program Files\Everest Poker\data\startup
                                  C:\Program Files\Everest Poker\data\fonts\kgp-en.ttf
                                  C:\Program Files\Everest Poker\data\mp-lobby\fr.gvt
                                  C:\Program Files\Everest Poker\data\mp-lobby\shared.gvt
                                  C:\Program Files\Everest Poker\data\mp-poker\background
                                  C:\Program Files\Everest Poker\data\mp-poker\fr
                                  C:\Program Files\Everest Poker\data\mp-poker\shared.gvt
                                  C:\Program Files\Everest Poker\data\mp-poker\background\cabin.gvt
                                  C:\Program Files\Everest Poker\data\mp-poker\background\china.gvt
                                  C:\Program Files\Everest Poker\data\mp-poker\background\default.gvt
                                  C:\Program Files\Everest Poker\data\mp-poker\background\garden.gvt
                                  C:\Program Files\Everest Poker\data\mp-poker\background\hawaii.gvt
                                  C:\Program Files\Everest Poker\data\mp-poker\background\med.gvt
                                  C:\Program Files\Everest Poker\data\mp-poker\fr\bitmaps.gvt
                                  C:\Program Files\Everest Poker\data\mp-poker\fr\mp-poker_strings.txt
                                  C:\Program Files\Everest Poker\data\mp-poker\fr\mp-poker_tutorial.txt
                                  C:\Program Files\Everest Poker\data\shared\fr
                                  C:\Program Files\Everest Poker\data\shared\shared
                                  C:\Program Files\Everest Poker\data\shared\fr\country.txt
                                  C:\Program Files\Everest Poker\data\shared\fr\language.txt
                                  C:\Program Files\Everest Poker\data\shared\fr\ordinal.txt
                                  C:\Program Files\Everest Poker\data\shared\shared\bitmaps
                                  C:\Program Files\Everest Poker\data\shared\shared\sounds
                                  C:\Program Files\Everest Poker\data\shared\shared\bitmaps\btn_scroll.gvt
                                  C:\Program Files\Everest Poker\data\shared\shared\bitmaps\check.art
                                  C:\Program Files\Everest Poker\data\shared\shared\bitmaps\chips.art
                                  C:\Program Files\Everest Poker\data\shared\shared\sounds\button.ogg
                                  C:\Program Files\Everest Poker\data\shared\shared\sounds\carddeal.ogg
                                  C:\Program Files\Everest Poker\data\shared\shared\sounds\cardflip.ogg
                                  C:\Program Files\Everest Poker\data\shared\shared\sounds\chipclick.ogg
                                  C:\Program Files\Everest Poker\data\startup\en
                                  C:\Program Files\Everest Poker\data\startup\fr
                                  C:\Program Files\Everest Poker\data\startup\shared
                                  C:\Program Files\Everest Poker\data\startup\en\startup_strings.txt
                                  C:\Program Files\Everest Poker\data\startup\fr\cstart.txt
                                  C:\Program Files\Everest Poker\data\startup\fr\startup_strings.txt
                                  C:\Program Files\Everest Poker\data\startup\shared\bitmaps
                                  C:\Program Files\Everest Poker\data\startup\shared\icons
                                  C:\Program Files\Everest Poker\data\startup\shared\sounds
                                  C:\Program Files\Everest Poker\data\startup\shared\bitmaps\splash_poker.art
                                  C:\Program Files\Everest Poker\data\startup\shared\icons\ep.ico
                                  C:\Program Files\Everest Poker\data\startup\shared\sounds\alert.ogg
                                  C:\Program Files\Everest Poker\history\1.txt
                                  C:\Program Files\Everest Poker\history\10.txt
                                  C:\Program Files\Everest Poker\history\100.txt
                                  C:\Program Files\Everest Poker\history\102.txt
                                  C:\Program Files\Everest Poker\history\103.txt
                                  C:\Program Files\Everest Poker\history\104.txt
                                  C:\Program Files\Everest Poker\history\105.txt
                                  C:\Program Files\Everest Poker\history\107.txt
                                  C:\Program Files\Everest Poker\history\108.txt
                                  C:\Program Files\Everest Poker\history\109.txt
                                  C:\Program Files\Everest Poker\history\110.txt
                                  C:\Program Files\Everest Poker\history\113.txt
                                  C:\Program Files\Everest Poker\history\114.txt
                                  C:\Program Files\Everest Poker\history\115.txt
                                  C:\Program Files\Everest Poker\history\116.txt
                                  C:\Program Files\Everest Poker\history\117.txt
                                  C:\Program Files\Everest Poker\history\118.txt
                                  C:\Program Files\Everest Poker\history\119.txt
                                  C:\Program Files\Everest Poker\history\12.txt
                                  C:\Program Files\Everest Poker\history\120.txt
                                  C:\Program Files\Everest Poker\history\121.txt
                                  C:\Program Files\Everest Poker\history\122.txt
                                  C:\Program Files\Everest Poker\history\123.txt
                                  C:\Program Files\Everest Poker\history\124.txt
                                  C:\Program Files\Everest Poker\history\125.txt
                                  C:\Program Files\Everest Poker\history\126.txt
                                  C:\Program Files\Everest Poker\history\127.txt
                                  C:\Program Files\Everest Poker\history\128.txt
                                  C:\Program Files\Everest Poker\history\129.txt
                                  C:\Program Files\Everest Poker\history\13.txt
                                  C:\Program Files\Everest Poker\history\130.txt
                                  C:\Program Files\Everest Poker\history\131.txt
                                  C:\Program Files\Everest Poker\history\132.txt
                                  C:\Program Files\Everest Poker\history\133.txt
                                  C:\Program Files\Everest Poker\history\14.txt
                                  C:\Program Files\Everest Poker\history\15.txt
                                  C:\Program Files\Everest Poker\history\16.txt
                                  C:\Program Files\Everest Poker\history\17.txt
                                  C:\Program Files\Everest Poker\history\18.txt
                                  C:\Program Files\Everest Poker\history\20.txt
                                  C:\Program Files\Everest Poker\history\21.txt
                                  C:\Program Files\Everest Poker\history\22.txt
                                  C:\Program Files\Everest Poker\history\23.txt
                                  C:\Program Files\Everest Poker\history\24.txt
                                  C:\Program Files\Everest Poker\history\25.txt
                                  C:\Program Files\Everest Poker\history\26.txt
                                  C:\Program Files\Everest Poker\history\27.txt
                                  C:\Program Files\Everest Poker\history\28.txt
                                  C:\Program Files\Everest Poker\history\29.txt
                                  C:\Program Files\Everest Poker\history\3.txt
                                  C:\Program Files\Everest Poker\history\30.txt
                                  C:\Program Files\Everest Poker\history\31.txt
                                  C:\Program Files\Everest Poker\history\32.txt
                                  C:\Program Files\Everest Poker\history\33.txt
                                  C:\Program Files\Everest Poker\history\34.txt
                                  C:\Program Files\Everest Poker\history\35.txt
                                  C:\Program Files\Everest Poker\history\36.txt
                                  C:\Program Files\Everest Poker\history\37.txt
                                  C:\Program Files\Everest Poker\history\38.txt
                                  C:\Program Files\Everest Poker\history\39.txt
                                  C:\Program Files\Everest Poker\history\4.txt
                                  C:\Program Files\Everest Poker\history\40.txt
                                  C:\Program Files\Everest Poker\history\41.txt
                                  C:\Program Files\Everest Poker\history\42.txt
                                  C:\Program Files\Everest Poker\history\43.txt
                                  C:\Program Files\Everest Poker\history\45.txt
                                  C:\Program Files\Everest Poker\history\46.txt
                                  C:\Program Files\Everest Poker\history\47.txt
                                  C:\Program Files\Everest Poker\history\48.txt
                                  C:\Program Files\Everest Poker\history\49.txt
                                  C:\Program Files\Everest Poker\history\5.txt
                                  C:\Program Files\Everest Poker\history\50.txt
                                  C:\Program Files\Everest Poker\history\54.txt
                                  C:\Program Files\Everest Poker\history\55.txt
                                  C:\Program Files\Everest Poker\history\56.txt
                                  C:\Program Files\Everest Poker\history\57.txt
                                  C:\Program Files\Everest Poker\history\58.txt
                                  C:\Program Files\Everest Poker\history\59.txt
                                  C:\Program Files\Everest Poker\history\6.txt
                                  C:\Program Files\Everest Poker\history\60.txt
                                  C:\Program Files\Everest Poker\history\61.txt
                                  C:\Program Files\Everest Poker\history\62.txt
                                  C:\Program Files\Everest Poker\history\63.txt
                                  C:\Program Files\Everest Poker\history\65.txt
                                  C:\Program Files\Everest Poker\history\66.txt
                                  C:\Program Files\Everest Poker\history\67.txt
                                  C:\Program Files\Everest Poker\history\68.txt
                                  C:\Program Files\Everest Poker\history\69.txt
                                  C:\Program Files\Everest Poker\history\70.txt
                                  C:\Program Files\Everest Poker\history\71.txt
                                  C:\Program Files\Everest Poker\history\72.txt
                                  C:\Program Files\Everest Poker\history\73.txt
                                  C:\Program Files\Everest Poker\history\74.txt
                                  C:\Program Files\Everest Poker\history\75.txt
                                  C:\Program Files\Everest Poker\history\76.txt
                                  C:\Program Files\Everest Poker\history\77.txt
                                  C:\Program Files\Everest Poker\history\78.txt
                                  C:\Program Files\Everest Poker\history\79.txt
                                  C:\Program Files\Everest Poker\history\8.txt
                                  C:\Program Files\Everest Poker\history\80.txt
                                  C:\Program Files\Everest Poker\history\81.txt
                                  C:\Program Files\Everest Poker\history\83.txt
                                  C:\Program Files\Everest Poker\history\84.txt
                                  C:\Program Files\Everest Poker\history\86.txt
                                  C:\Program Files\Everest Poker\history\87.txt
                                  C:\Program Files\Everest Poker\history\88.txt
                                  C:\Program Files\Everest Poker\history\89.txt
                                  C:\Program Files\Everest Poker\history\9.txt
                                  C:\Program Files\Everest Poker\history\90.txt
                                  C:\Program Files\Everest Poker\history\91.txt
                                  C:\Program Files\Everest Poker\history\92.txt
                                  C:\Program Files\Everest Poker\history\93.txt
                                  C:\Program Files\Everest Poker\history\94.txt
                                  C:\Program Files\Everest Poker\history\95.txt
                                  C:\Program Files\Everest Poker\history\96.txt
                                  C:\Program Files\Everest Poker\history\97.txt
                                  C:\Program Files\Everest Poker\history\98.txt
                                  C:\Program Files\Everest Poker\history\99.txt
                                  C:\Program Files\Everest Poker\notes\Player-Benito21600
                                  C:\Program Files\Everest Poker\var\content-fr.dat
                                  C:\Program Files\Everest Poker
                                  C:\Windows\Prefetch\EVEREST POKER.EXE-49449C8C.pf

                                  (!) -- Fichiers temporaires supprimés.

                                  .
                                  ============== Scan additionnel ==============
                                  .

                                  * Mozilla FireFox Version 3.5.2 *

                                  Nom du profil: xuu06tza.default (Benoit)
                                  .
                                  .
                                  .

                                  * Internet Explorer Version 8.0.6001.18813 *

                                  [HKEY_CURRENT_USER\..\Internet Explorer\Main]

                                  Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
                                  Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                                  Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
                                  Search Page: hxxp://go.microsoft.com/fwlink/?LinkId=54896
                                  Start Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome

                                  [HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]

                                  Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
                                  Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                                  Search bar: hxxp://search.msn.com/spbasic.htm
                                  Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                                  Start Page: hxxp://fr.msn.com/

                                  [HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]

                                  Tabs: res://ieframe.dll/tabswelcome.htm

                                  .
                                  ============== Processus Caches/Bloque ==============
                                  .
                                  PID: 1256 [LOCKED] audiodg.exe
                                  .
                                  .
                                  ===================================
                                  .
                                  12907 Octet(s) - C:\Ad-Report-CLEAN.log
                                  .
                                  3 Fichier(s) - C:\Users\Benoit\AppData\Local\Temp
                                  9 Fichier(s) - C:\Windows\Temp
                                  .
                                  20 Fichier(s) - C:\Program Files\Ad-remover\BACKUP
                                  145 Fichier(s) - C:\Program Files\Ad-remover\QUARANTINE
                                  .
                                  Fin à: 22:23:45 | 22/08/2009
                                  .
                                  ============== E.O.F ==============
                                  .
                                  1. Es ce que tous est normal maintenant ou es ce qu'il reste encore quelque petite trace du virus ??
                                    • 1
                                    • 2