Infecté par adware-gen, trojan-gen et alureon

Résolu
Bonjour,

Bonjour, mon pc ne demarre plus (seul la souris est visible sur un ecran noir) apres avoir été infecté par ces 3 virus ...
Je me sert d'un autre PC pour vous écrire, aidez moi SVP
Configuration: Windows XP Internet Explorer 6.0

34 réponses

Résumé de la discussion

Le problème décrit est un démarrage bloqué sur Windows XP, avec écran noir et seule la souris visible après une infection par plusieurs virus répandus. Plusieurs réponses proposent des outils et méthodes de nettoyage et de restauration du système, notamment l’exécution en mode sans échec, puis des scans avec Avast, Ad-Aware et Malwarebytes. D’autres conseils évoquent l’utilisation d’OTM pour nettoyer les traces, JavaRa pour la maintenance Java, et des mesures comme l’analyse du rapport HijackThis ou le redémarrage en mode normal après nettoyage. Des échanges évoquent aussi un blocage du BIOS lors du branchement d’un disque dur externe, et des incertitudes sur l’étape suivante jusqu’à réception de nouveaux conseils.

Bobot (l’IA à votre service)
  1. HELP PLEASE ....

    suis en train de faire tourner AD-Aware et Avast en mode sans echec ... mais apres, je sais pas quoi faire
    0
    1. Salut ,

      Suite à ta demande en mp .

      Arrete le scan ad aware et avast

      Redémarre en mode sans echec avec prise en charge reseau .

      ▶ Télécharge random's system information tool (RSIT) et sauvegarde-le sur le Bureau.

      • Double-clique sur RSIT.exe afin de lancer RSIT.

      • Lis le contenu de l'écran Disclaimer puis clique sur Continue (si tu acceptes les conditions).

      • Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.

      • Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront.

      • Poste le contenu de log.txt .

      • Tuto : https://forum.pcastuces.com/randoms_system_information_tool_rsit-f31s31.htm
      0
      1. Logfile of random's system information tool 1.06 (written by random/random)
        Run by Administrateur at 2009-09-01 15:17:40
        Microsoft Windows XP Édition familiale Service Pack 3
        System drive C: has 10 GB (17%) free of 60 GB
        Total RAM: 3007 MB (89% free)

        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 15:17:49, on 01/09/2009
        Platform: Windows XP SP3 (WinNT 5.01.2600)
        MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
        Boot mode: Safe mode with network support

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\system32\svchost.exe
        C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
        C:\WINDOWS\Explorer.EXE
        C:\Program Files\Internet Explorer\Iexplore.exe
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\Documents and Settings\Administrateur\Bureau\RSIT.exe
        C:\Program Files\trend micro\Administrateur.exe

        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://toolbar.ask.com/toolbarv/askRedirect?o=10611&gct=&gc=1&q=
        R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://toolbar.ask.com/toolbarv/askRedirect?o=10611&gct=&gc=1&q=
        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
        R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.canfind.org/search/ac.php?aid=158&sid=clean12
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
        R3 - Default URLSearchHook is missing
        O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
        O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
        O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
        O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
        O2 - BHO: BHO Barre de Confiance - {988B07F5-7392-455A-8A1F-64935CB8B6ED} - C:\Program Files\BarreConfCMCIC\TAPBar.dll
        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
        O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
        O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
        O3 - Toolbar: Barre de confiance - {55BDF3B0-C0A8-481A-B8A6-01CD2BE0F3FD} - C:\Program Files\BarreConfCMCIC\TAPBar.dll
        O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
        O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
        O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
        O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\WINDOWS\JM\JMInsIDE.exe
        O4 - HKLM\..\Run: [JMB36X Configure] C:\WINDOWS\system32\JMRaidSetup.exe boot
        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
        O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
        O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
        O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
        O4 - HKLM\..\Run: [PRISMSTA.EXE] Prismsta.exe /START
        O4 - HKLM\..\Run: [PRISMSVR.EXE] Prismsvr.exe /APPLY
        O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
        O4 - HKLM\..\Run: [Canal Widget] "C:\Program Files\Canal\Canal Widget\Launcher.exe"
        O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
        O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
        O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
        O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
        O4 - HKLM\..\Run: [NokiaMServer] C:\Program Files\Fichiers communs\Nokia\MPlatform\NokiaMServer /watchfiles
        O4 - HKLM\..\Run: [CanalPlayerHelper] C:\Program Files\Lecteur CANALPLAY\CanalPlayerHelper.exe
        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
        O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
        O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
        O4 - HKLM\..\RunOnce: [aswAhAScr.dll] C:\PROGRA~1\ALWILS~1\Avast4\ASWREG~1.EXE "C:\Program Files\Alwil Software\Avast4\AhAScr.dll"
        O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE
        O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
        O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
        O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
        O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
        O4 - Global Startup: Démarrage rapide de HP Photosmart Premier.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
        O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
        O4 - Global Startup: Nokia Ovi Suite.lnk = C:\Program Files\Nokia\Ovi\Suite\RunLauncher.exe
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\npjpi160_07.dll
        O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\npjpi160_07.dll
        O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
        O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
        O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
        O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O15 - Trusted Zone: *.canalplay.com (HKLM)
        O15 - Trusted Zone: *.canalplusactive.com (HKLM)
        O16 - DPF: {07041BB2-F22C-413C-9597-622D474EE889} (DLCFRAME (version 1,2,4,41)) - http://service.wuerth.de/duebeltechnik/DLCFrame.cab
        O16 - DPF: {1FF43AD5-2262-4C2F-81D4-26D710C3F305} (VB2S Mannequin Virtuel Control) - http://mannequin.redoute.fr/activex/Mannequin.cab
        O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} (Image Uploader Control) - http://www.photoweb.fr/moncompte/Account/LogOn?ReturnUrl=%2ftransfert
        O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
        O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab2.cab
        O16 - DPF: {A73BAEFA-EE65-494D-BEDB-DD3E5A34FA98} (Image Uploader) - http://www.extrafilm.fr/ImageUploader4.cab
        O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/...
        O17 - HKLM\System\CCS\Services\Tcpip\..\{4A79E050-E6AE-496A-B01A-611CDE2CD600}: NameServer = 192.168.1.1
        O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
        O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
        O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
        O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
        O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
        O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
        O23 - Service: BvrpKrnl - Unknown owner - C:\Program Files\WinFax eXPert\BVRPKrnl.exe
        O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
        O23 - Service: CanalPlus.VOD - Canal+ Active - C:\Program Files\Canal\Canal Widget\VOD\CanalPlus.VOD.exe
        O23 - Service: Firebird Server - MAGIX Instance (FirebirdServerMAGIXInstance) - MAGIX® - C:\Program Files\MAGIX\Common\Database\bin\fbserver.exe
        O23 - Service: FreezeScreenSaver - Unknown owner - C:\WINDOWS\system32\FreezeScreenSaver.exe
        O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
        O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
        O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
        O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
        O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Nokia\PC Connectivity Solution\ServiceLayer.exe
        O23 - Service: TwonkyMedia - PacketVideo - C:\Program Files\Nokia\Nokia Home Media Server\Media Server\TwonkyMedia.exe
        0
    2. T as chopé un rootkit

      Télécharge combofix : http://download.bleepingcomputer.com/sUBs/ComboFix.exe

      -> Double clique sur combofix.exe.
      -> Tape sur la touche 1 (Yes) pour démarrer le scan.
      -> Lorsque le scan sera complété, un rapport apparaîtra. Copie/colle ce rapport dans ta prochaine réponse.

      NOTE : Le rapport se trouve également ici : C:\Combofix.txt

      Avant d'utiliser ComboFix :

      -> Déconnecte toi d'internet et referme les fenêtres de tous les programmes en cours.

      -> Désactive provisoirement et seulement le temps de l'utilisation de ComboFix, la protection en temps réel de ton Antivirus et de tes Antispywares, qui peuvent géner fortement la procédure de recherche et de nettoyage de l'outil.

      Une fois fait, sur ton bureau double-clic sur Combofix.exe.

      - Répond oui au message d'avertissement, pour que le programme commence à procéder à l'analyse du pc.

      /!\ Pendant la durée de cette étape, ne te sert pas du pc et n'ouvre aucun programmes.

      - En fin de scan il est possible que ComboFix ait besoin de redemarrer le pc pour finaliser la désinfection\recherche, laisses-le faire.

      - Un rapport s'ouvrira ensuite dans le bloc notes, ce fichier rapport Combofix.txt, est automatiquement sauvegardé et rangé à C:\Combofix.txt)

      -> Réactive la protection en temps réel de ton Antivirus et de tes Antispywares, avant de te reconnecter à internet.

      -> Reviens sur le forum, et copie et colle la totalité du contenu de C:\Combofix.txt dans ton prochain message.

      0
      1. je suis en mode sans echec, c'est bon aussi (car il ne demarre toujours pas en mode normal, c'est plus un ecran noir mais se bloque assez rapidement)
        0
        1. oui fais la manipe en mode sans echec

          tu verras combofix redémarrera le pc , tu devrais pouvoir avoir acces au mode normal ensuite
          0
          1. il se passe rien quand je cliques sur combofix !!!! a cause du mode sans echec avec connexions reseau ???
            0
            1. non pas a cause de ce mode

              essai ceci , renome l exe de combofix en Kill et essai de l executer

              0
              1. ComboFix 09-08-31.03 - PUIG 01/09/2009 16:17.1.2 - NTFSx86
                Microsoft Windows XP Édition familiale 5.1.2600.3.1252.33.1036.18.3007.2554 [GMT 2:00]
                Running from: c:\documents and settings\Administrateur\Bureau\Kill.exe
                AV: avast! antivirus 4.8.1169 [VPS 090831-0] *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}

                WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
                .

                ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
                .

                c:\documents and settings\PUIG\Application Data\inst.exe
                c:\program files\AskSearch\bin\DefaultSearch.dll
                c:\windows\Installer\2e5821cc.msi
                c:\windows\Installer\363e3b.msi
                c:\windows\msa.exe
                c:\windows\system32\drivers\kbiwkmxrurbxmo.sys
                c:\windows\system32\drivers\Sonyhcp.dll
                c:\windows\system32\drivers\UAClniorowpbp.sys
                c:\windows\system32\kbiwkmjjxmhxdh.dll
                c:\windows\system32\UACbltltitkbm.dll
                c:\windows\system32\UACfsyjkbavgy.dat
                c:\windows\system32\uacinit.dll
                c:\windows\system32\UACixudjnokyo.dll
                c:\windows\system32\UACmouyevtgbm.db
                c:\windows\system32\UACrpqjoqvqwu.dll
                c:\windows\system32\UACybxkyvexbr.dll

                .
                ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
                .

                -------\Service_UACd.sys
                -------\Legacy_UACd.sys
                -------\Legacy_FREEZESCREENSAVER
                -------\Service_FreezeScreenSaver
                -------\Service_kbiwkmujcraqpt

                ((((((((((((((((((((((((( Files Created from 2009-08-01 to 2009-09-01 )))))))))))))))))))))))))))))))
                .

                2009-09-01 14:26 . 2009-09-01 14:26 -------- d-sh--w- C:\found.000
                2009-09-01 13:17 . 2009-09-01 13:17 -------- d-----w- C:\rsit
                2009-09-01 13:17 . 2009-09-01 13:17 -------- d-----w- c:\program files\trend micro
                2009-08-31 11:24 . 2009-08-31 11:24 70144 ----a-w- c:\windows\system32\drivers\yymbfpuoiemqxvjq.sys
                2009-08-31 11:23 . 2009-09-01 09:56 -------- d-----w- c:\program files\AV Care
                2009-08-14 08:42 . 2009-08-14 08:29 38208 ----a-w- c:\documents and settings\Default User\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
                2009-08-14 08:31 . 2009-07-10 13:27 1315328 -c----w- c:\windows\system32\dllcache\msoe.dll
                2009-08-10 15:37 . 2009-08-10 15:37 -------- d-----w- c:\program files\Dnote Software
                2009-08-03 09:17 . 2009-08-03 09:17 -------- d-----w- c:\windows\system32\Debug
                2009-08-02 21:01 . 2009-08-02 21:02 -------- d-----w- c:\program files\CA

                .
                (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
                .
                2009-09-01 14:36 . 2004-08-05 12:00 85644 ----a-w- c:\windows\system32\perfc00C.dat
                2009-09-01 14:36 . 2004-08-05 12:00 513498 ----a-w- c:\windows\system32\perfh00C.dat
                2009-08-25 19:45 . 2007-10-31 08:39 -------- d-----w- c:\program files\ZGuideTV
                2009-08-23 18:04 . 2007-07-13 17:13 145448 -c--a-w- c:\documents and settings\PUIG\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
                2009-08-17 16:10 . 2007-07-13 17:12 1279456 ----a-w- c:\windows\system32\aswBoot.exe
                2009-08-17 16:06 . 2007-07-13 17:12 93392 -c--a-w- c:\windows\system32\drivers\aswmon.sys
                2009-08-17 16:06 . 2007-07-13 17:12 94160 ----a-w- c:\windows\system32\drivers\aswmon2.sys
                2009-08-17 16:05 . 2008-04-08 07:37 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
                2009-08-17 16:05 . 2008-04-08 07:37 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
                2009-08-17 16:04 . 2007-07-13 17:12 51376 ----a-w- c:\windows\system32\drivers\aswTdi.sys
                2009-08-17 16:04 . 2007-07-13 17:12 23152 ----a-w- c:\windows\system32\drivers\aswRdr.sys
                2009-08-17 16:03 . 2007-07-13 17:12 26944 ----a-w- c:\windows\system32\drivers\aavmker4.sys
                2009-08-17 16:02 . 2007-07-13 17:12 97480 ----a-w- c:\windows\system32\AvastSS.scr
                2009-08-14 08:42 . 2008-11-28 17:16 -------- d-----w- c:\program files\Fichiers communs\Adobe AIR
                2009-08-14 08:29 . 2009-09-01 09:43 38208 ----a-w- c:\documents and settings\Administrateur\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
                2009-08-05 09:00 . 2004-08-05 12:00 205312 ----a-w- c:\windows\system32\mswebdvd.dll
                2009-07-31 14:16 . 2007-10-25 08:03 -------- d-----w- c:\program files\eMule
                2009-07-29 10:22 . 2008-12-09 23:36 -------- d-----w- c:\documents and settings\PUIG\Application Data\PC Suite
                2009-07-26 19:55 . 2009-06-26 06:53 -------- d-----r- c:\program files\mueproprogramme
                2009-07-22 15:43 . 2007-10-22 10:07 -------- d-----w- c:\program files\mueprodatabase
                2009-07-17 19:03 . 2004-08-05 12:00 58880 ----a-w- c:\windows\system32\atl.dll
                2009-07-13 21:43 . 2004-08-05 12:00 286208 ----a-w- c:\windows\system32\wmpdxm.dll
                2009-07-10 17:23 . 2009-07-06 18:14 -------- d-----w- c:\documents and settings\PUIG\Application Data\Mavi
                2009-07-06 18:14 . 2009-07-06 18:14 -------- d-----w- c:\documents and settings\All Users\Application Data\Mavi
                2009-07-06 18:14 . 2009-07-06 18:14 -------- d-----w- c:\program files\Mavi
                2009-06-26 16:50 . 2004-08-05 12:00 670720 ----a-w- c:\windows\system32\wininet.dll
                2009-06-26 16:50 . 2004-08-05 12:00 81920 ----a-w- c:\windows\system32\ieencode.dll
                2009-06-16 14:40 . 2004-08-05 12:00 81920 ----a-w- c:\windows\system32\fontsub.dll
                2009-06-16 14:40 . 2004-08-05 12:00 119808 ----a-w- c:\windows\system32\t2embed.dll
                2009-06-15 10:44 . 2004-08-05 12:00 78848 ----a-w- c:\windows\system32\telnet.exe
                2009-06-10 14:14 . 2004-08-05 12:00 85504 ----a-w- c:\windows\system32\avifil32.dll
                2009-06-10 07:21 . 2007-07-10 22:29 2066432 ----a-w- c:\windows\system32\mstscax.dll
                2009-06-10 06:15 . 2004-08-05 12:00 132096 ----a-w- c:\windows\system32\wkssvc.dll
                2009-06-03 19:10 . 2004-08-05 12:00 1297408 ----a-w- c:\windows\system32\quartz.dll
                2007-07-11 17:20 . 2007-07-11 17:20 278528 -c--a-w- c:\program files\Fichiers communs\FDEUnInstaller.exe
                2007-11-22 06:56 . 2007-11-22 06:54 24 --sh--w- c:\windows\S02EA33A7.tmp
                .

                ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
                .
                .
                *Note* empty entries & legit default entries are not shown
                REGEDIT4

                [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-09-02 68856]
                "SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
                "MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]

                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                "NokiaMServer"="c:\program files\Fichiers communs\Nokia\MPlatform\NokiaMServer" [X]
                "SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2006-12-18 868352]
                "JMB36X IDE Setup"="c:\windows\JM\JMInsIDE.exe" [2006-10-30 36864]
                "JMB36X Configure"="c:\windows\system32\JMRaidSetup.exe" [2006-10-30 1953792]
                "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-04-19 7700480]
                "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-04-19 86016]
                "SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
                "avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-08-17 81000]
                "HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 49152]
                "NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
                "Canal Widget"="c:\program files\Canal\Canal Widget\Launcher.exe" [2009-04-22 170072]
                "PinnacleDriverCheck"="c:\windows\system32\PSDrvCheck.exe" [2004-03-10 406016]
                "itype"="c:\program files\Microsoft IntelliType Pro\itype.exe" [2007-08-31 988584]
                "IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2007-08-31 1037736]
                "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
                "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696]
                "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-01-06 290088]
                "PRISMSTA.EXE"="Prismsta.exe" - c:\windows\system32\PRISMSTA.exe [2003-11-08 254044]
                "PRISMSVR.EXE"="Prismsvr.exe" - c:\windows\system32\PRISMSVR.exe [2003-11-20 282713]

                [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
                "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

                c:\documents and settings\PUIG\Menu D‚marrer\Programmes\D‚marrage\
                Barre d'Outils Olitec.lnk - c:\olifaxvx\TOOLBAR.EXE [2007-7-13 118784]
                Outil de d‚tection de support Picture Motion Browser.lnk - c:\program files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe [2008-2-18 344064]

                c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
                D‚marrage rapide de HP Photosmart Premier.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2006-2-10 73728]
                HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2006-2-19 288472]
                Nokia Ovi Suite.lnk - c:\program files\Nokia\Ovi\Suite\RunLauncher.exe [2008-7-25 951600]

                [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
                @="Service"

                [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
                "%windir%\\system32\\sessmgr.exe"=
                "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
                "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
                "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
                "c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
                "c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
                "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
                "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
                "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
                "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
                "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
                "c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
                "c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
                "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
                "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
                "c:\\Program Files\\Messenger\\msmsgs.exe"=
                "c:\\Program Files\\WinFax eXPert\\WinFax.exe"=
                "c:\\Program Files\\WinFax eXPert\\BvrpKrnl.exe"=
                "c:\\Program Files\\eMule\\emule.exe"=
                "c:\\Program Files\\NetMeeting\\conf.exe"=
                "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
                "c:\\Program Files\\Nokia\\Nokia Home Media Server\\Media Server\\twonkymedia.exe"=
                "c:\\Program Files\\Nokia\\Nokia Home Media Server\\Media Server\\twonkymediaserver.exe"=
                "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
                "c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
                "c:\\Program Files\\Microsoft Games\\Age of Empires III\\age3.exe"=
                "c:\\Program Files\\Vuze\\Azureus.exe"=
                "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
                "c:\\Program Files\\iTunes\\iTunes.exe"=
                "c:\\Program Files\\K-Lite Codec Pack\\Media Player Classic\\mplayerc.exe"=

                [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
                "135:TCP"= 135:TCP:Port DCOM (135)

                R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [08/04/2008 09:37 114768]
                R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [08/04/2008 09:37 20560]
                R2 CanalPlus.VOD;CanalPlus.VOD;c:\program files\Canal\Canal Widget\VOD\CanalPlus.VOD.exe [11/04/2008 19:24 188416]
                S2 TwonkyMedia;TwonkyMedia;c:\program files\Nokia\Nokia Home Media Server\Media Server\TwonkyMedia.exe -serviceversion 0 --> c:\program files\Nokia\Nokia Home Media Server\Media Server\TwonkyMedia.exe -serviceversion 0 [?]
                S3 BvrpKrnl;BvrpKrnl;c:\program files\WinFax eXPert\BvrpKrnl.exe [22/10/2007 11:46 548864]
                S3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;c:\program files\MAGIX\Common\Database\bin\fbserver.exe [19/02/2008 18:00 1527900]
                S3 SIS163u;SiS163 USB Wireless LAN Adapter Driver;c:\windows\system32\drivers\sis163u.sys [11/07/2007 18:56 217088]
                .
                Contents of the 'Scheduled Tasks' folder

                2009-08-25 c:\windows\Tasks\AppleSoftwareUpdate.job
                - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
                .
                - - - - ORPHANS REMOVED - - - -

                URLSearchHooks-{C94E154B-1459-4A47-966B-4B843BEFC7DB} - (no file)
                HKCU-Run-srvreg - c:\windows\system32\srvreg.exe
                HKCU-Run-MsgCenterExe - c:\program files\Fichiers communs\Real\Update_OB\RealOneMessageCenter.exe
                HKLM-Run-CanalPlayerHelper - c:\program files\Lecteur CANALPLAY\CanalPlayerHelper.exe

                .
                ------- Supplementary Scan -------
                .
                uStart Page = hxxp://www.google.fr/
                uSearch Page = hxxp://www.google.com
                uSearch Bar = hxxp://www.google.com/ie
                mDefault_Search_URL = hxxp://www.google.com/ie
                uInternet Settings,ProxyOverride = *.local
                uSearchAssistant = hxxp://www.google.com/ie
                uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
                mSearchAssistant = hxxp://www.google.com/ie
                IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                Trusted Zone: cic.fr\www
                Trusted Zone: canalplay.com
                Trusted Zone: canalplusactive.com
                TCP: {4A79E050-E6AE-496A-B01A-611CDE2CD600} = 192.168.1.1
                DPF: {07041BB2-F22C-413C-9597-622D474EE889} - hxxp://service.wuerth.de/duebeltechnik/DLCFrame.cab
                DPF: {1FF43AD5-2262-4C2F-81D4-26D710C3F305} - hxxp://mannequin.redoute.fr/activex/Mannequin.cab
                .

                **************************************************************************

                catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                Rootkit scan 2009-09-01 16:32
                Windows 5.1.2600 Service Pack 3 NTFS

                scanning hidden processes ...

                scanning hidden autostart entries ...

                scanning hidden files ...

                scan completed successfully
                hidden files: 0

                **************************************************************************

                [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\kbiwkmujcraqpt]
                "imagepath"="\systemroot\system32\drivers\kbiwkmxrurbxmo.sys"
                .
                --------------------- LOCKED REGISTRY KEYS ---------------------

                [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
                @Denied: (A 2) (Everyone)
                @="FlashBroker"
                "LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"

                [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
                "Enabled"=dword:00000001

                [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
                @="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe"

                [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
                @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

                [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32*]
                "ThreadingModel"="Apartment"
                @="c:\\WINDOWS\\system32\\OLE32.DLL"
                "cd042efbbd7f7af1647644e76e06692b"=hex:e2,63,26,f1,3f,c8,ff,68,df,de,e5,17,8c,
                f2,61,86,2e,e8,e1,00,eb,16,2b,de,1e,02,0d,09,aa,f7,e2,77,e2,63,26,f1,3f,c8,\

                [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32*]
                "ThreadingModel"="Apartment"
                @="c:\\WINDOWS\\system32\\OLE32.DLL"
                "bca643cdc5c2726b20d2ecedcc62c59b"=hex:71,3b,04,66,8b,46,0d,96,41,62,90,16,02,
                54,54,04,46,47,15,b0,92,4b,c7,ef,db,15,38,eb,53,77,4d,ff,6a,9c,d6,61,af,45,\

                [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32*]
                "ThreadingModel"="Apartment"
                @="c:\\WINDOWS\\system32\\OLE32.DLL"
                "2c81e34222e8052573023a60d06dd016"=hex:7a,45,05,fd,91,e8,6f,31,a3,ce,25,ce,07,
                32,69,6d,7a,45,05,fd,91,e8,6f,31,2a,a2,1f,5d,e8,9f,8f,92,ff,7c,85,e0,43,d4,\

                [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32*]
                "ThreadingModel"="Apartment"
                @="c:\\WINDOWS\\system32\\OLE32.DLL"
                "2582ae41fb52324423be06337561aa48"=hex:86,8c,21,01,be,91,eb,e7,f0,0b,9c,c9,66,
                ed,5a,4e,6b,65,49,6a,7e,99,74,f7,d2,48,2b,68,e5,f8,9c,4e,86,8c,21,01,be,91,\

                [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32*]
                "ThreadingModel"="Apartment"
                @="c:\\WINDOWS\\system32\\OLE32.DLL"
                "caaeda5fd7a9ed7697d9686d4b818472"=hex:cd,44,cd,b9,a6,33,6c,cd,99,9a,3b,e4,8e,
                5a,96,58,e9,02,6c,fa,fb,1d,47,57,57,c4,18,2e,8e,d4,cb,b9,f5,1d,4d,73,a8,13,\

                [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32*]
                "ThreadingModel"="Apartment"
                @="c:\\WINDOWS\\system32\\OLE32.DLL"
                "a4a1bcf2cc2b8bc3716b74b2b4522f5d"=hex:b0,18,ed,a7,3f,8d,37,a4,83,28,c6,98,14,
                6f,a2,e5,50,93,e5,ab,ec,6a,4e,ab,e0,0a,2a,75,14,8b,5c,46,df,20,58,62,78,6b,\

                [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32*]
                "ThreadingModel"="Apartment"
                @="c:\\WINDOWS\\system32\\OLE32.DLL"
                "4d370831d2c43cd13623e232fed27b7b"=hex:31,77,e1,ba,b1,f8,68,02,3a,98,c8,3b,28,
                f9,2a,87,97,20,4e,9a,c7,f1,35,ee,0d,72,c1,ef,5f,2b,95,4d,fb,a7,78,e6,12,2f,\

                [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32*]
                "ThreadingModel"="Apartment"
                @="c:\\WINDOWS\\system32\\OLE32.DLL"
                "1d68fe701cdea33e477eb204b76f993d"=hex:01,3a,48,fc,e8,04,4a,f1,9a,a2,a2,d3,00,
                02,4b,0a,aa,52,c6,00,84,3c,26,64,83,40,62,5a,7d,ea,19,06,01,3a,48,fc,e8,04,\

                [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32*]
                "ThreadingModel"="Apartment"
                @="c:\\WINDOWS\\system32\\OLE32.DLL"
                "1fac81b91d8e3c5aa4b0a51804d844a3"=hex:f6,0f,4e,58,98,5b,89,c9,5d,80,ad,1b,b0,
                26,5c,49,b2,46,9a,e2,1b,fe,1b,94,43,f0,9c,e7,bc,81,3e,b2,f6,0f,4e,58,98,5b,\

                [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32*]
                "ThreadingModel"="Apartment"
                @="c:\\WINDOWS\\system32\\OLE32.DLL"
                "f5f62a6129303efb32fbe080bb27835b"=hex:3d,ce,ea,26,2d,45,aa,78,41,00,9c,74,c6,
                34,3f,99,37,a4,aa,c3,a6,15,56,0a,69,40,aa,94,d3,bb,14,75,3d,ce,ea,26,2d,45,\

                [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32*]
                "ThreadingModel"="Apartment"
                @="c:\\WINDOWS\\system32\\OLE32.DLL"
                "fd4e2e1a3940b94dceb5a6a021f2e3c6"=hex:2a,b7,cc,b5,b9,7f,41,e7,d0,9c,37,53,a3,
                e2,b0,a4,f8,31,0f,a9,5f,a0,ec,fb,4f,9f,90,b8,16,17,14,de,2a,b7,cc,b5,b9,7f,\

                [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32*]
                "ThreadingModel"="Apartment"
                @="c:\\WINDOWS\\system32\\OLE32.DLL"
                "8a8aec57dd6508a385616fbc86791ec2"=hex:fa,ea,66,7f,d4,3b,6b,70,d9,dc,eb,db,92,
                6a,73,d8,05,73,21,dd,54,d8,4a,c5,bf,20,1e,cc,14,96,93,c7,6c,43,2d,1e,aa,22,\

                [HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
                @Denied: (A 2) (Everyone)
                @="IFlashBroker3"

                [HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
                @="{00020424-0000-0000-C000-000000000046}"

                [HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
                @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
                "Version"="1.0"

                [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø•€|ÿÿÿÿ•€|ù•9~*]
                "C040110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"

                [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\kbiwkmujcraqpt]
                @DACL=(02 0000)
                "start"=dword:00000001
                "type"=dword:00000001
                "group"="file system"
                "imagepath"=expand:"\\systemroot\\system32\\drivers\\kbiwkmxrurbxmo.sys"
                .
                --------------------- DLLs Loaded Under Running Processes ---------------------

                - - - - - - - > 'explorer.exe'(4000)
                c:\windows\system32\WPDShServiceObj.dll
                c:\windows\system32\PortableDeviceTypes.dll
                c:\windows\system32\PortableDeviceApi.dll
                c:\windows\system32\eappprxy.dll
                .
                ------------------------ Other Running Processes ------------------------
                .
                c:\program files\Lavasoft\Ad-Aware\aawservice.exe
                c:\program files\Alwil Software\Avast4\aswUpdSv.exe
                c:\program files\Alwil Software\Avast4\ashServ.exe
                c:\program files\Fichiers communs\Nokia\MPlatform\NokiaMServer.exe
                c:\program files\Microsoft IntelliType Pro\dpupdchk.exe
                c:\program files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                c:\program files\Bonjour\mDNSResponder.exe
                c:\windows\system32\drivers\CDAC11BA.EXE
                c:\program files\HP\Digital Imaging\bin\hpqimzone.exe
                c:\windows\system32\nvsvc32.exe
                c:\windows\system32\HPZipm12.exe
                c:\program files\HP\Digital Imaging\bin\hpqste08.exe
                c:\program files\Alwil Software\Avast4\ashMaiSv.exe
                c:\program files\Alwil Software\Avast4\ashWebSv.exe
                c:\program files\iPod\bin\iPodService.exe
                c:\program files\Windows Live\Messenger\usnsvc.exe
                c:\program files\Java\jre1.6.0_07\bin\jucheck.exe
                .
                **************************************************************************
                .
                Completion time: 2009-09-01 16:37 - machine was rebooted
                ComboFix-quarantined-files.txt 2009-09-01 14:37

                Pre-Run: 12 096 237 568 octets libres
                Post-Run: 12 002 107 392 octets libres

                327 --- E O F --- 2009-08-26 10:00
                0
            2. ok, la il tourne et je te poste le rapport des qu'il a finis. ah, il redemarre. suspense. deja ça a pas planté ce qui est nouveau !!!

              il reboote pour la seconde fois ... il execute CHKDSK
              0
              1. ▶ Télécharge OTM de OldTimer sur ton Bureau.

                • Double-clique sur OTM.exe afin de le lancer.

                • Copie (Ctrl+C) le texte suivant ci-dessous :

                :processes
                explorer.exe

                :services
                kbiwkmujcraqpt

                :files
                c:\windows\S02EA33A7.tmp

                :commands
                [emptytemp]
                [reboot]


                • Colle (Ctrl+V) le texte précédemment copié dans le cadre Paste Instructions for Items to be Moved.

                • Clique maintenant sur le bouton MoveIt! puis ferme OTM.

                ▶ Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
                ▶ Accepte en cliquant sur YES.

                • Poste le rapport situé dans ce dossier : C:\_OTM\MovedFiles\
                Le nom du rapport correspond au moment de sa création : date_heure.log


                ##########

                • Telecharge malwarebytes

                • Tu l´instale, le programme va se mettre automatiquement a jour.

                • Une fois a jour, le programme va se lancer.

                • Click sur l´onglet parametre, et coche la case : "Arreter internet explorer pendant la suppression".

                • Click maintenant sur l´onglet recherche et coche la case : "executer un examen rapide".

                • Puis click sur "rechercher".

                • Laisse le scanner le pc...

                • Si des elements on ete trouvés > click sur supprimer la selection.

                • Si il t´es demandé de redemarrer > click sur "yes".

                • A la fin un rapport va s´ouvrir, sauvegarde le de maniere a le retrouver en vu de le poster sur le forum.
                • Copie et colle le rapport stp.

                0
                1. otm c'est ferme tout seul des l'appui sur moveit et depuis, seul le fond d'ecran du bureau et la souris sont visible !!! il se passe rien !!!
                  0
                  1. c'est bon, j'ai fait ALT CTRL SUP et taper explorer.exe dans la barre des taches. Du coup, le bureau est "revenu".
                    J'ai retelecharger OTM qui avait disparu, et il c'est lancé correctement, il redemarre le PC en ce moment.
                    Je te joint le rapport des qu'il est pret.

                    Je suis pas pret de te remercier, vraiment un enormissime MERCI
                    0
                    1. rapport de OTM :
                      All processes killed
                      ========== PROCESSES ==========
                      Process explorer.exe killed successfully!
                      ========== SERVICES/DRIVERS ==========
                      Service\Driver kbiwkmujcraqpt not found.
                      Service\Driver key kbiwkmujcraqpt deleted successfully.
                      ========== FILES ==========
                      File move failed. c:\windows\S02EA33A7.tmp scheduled to be moved on reboot.
                      ========== COMMANDS ==========

                      [EMPTYTEMP]

                      User: Administrateur
                      ->Temp folder emptied: 0 bytes
                      ->Temporary Internet Files folder emptied: 67 bytes

                      User: All Users

                      User: Default User
                      ->Temp folder emptied: 0 bytes
                      ->Temporary Internet Files folder emptied: 67 bytes

                      User: LocalService
                      ->Temp folder emptied: 65716 bytes
                      File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
                      ->Temporary Internet Files folder emptied: 10996805 bytes

                      User: NetworkService
                      ->Temp folder emptied: 0 bytes
                      File delete failed. C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
                      ->Temporary Internet Files folder emptied: 32835 bytes

                      User: PUIG
                      ->Temp folder emptied: 19230 bytes
                      ->Temporary Internet Files folder emptied: 1108811 bytes
                      ->Java cache emptied: 0 bytes

                      %systemdrive% .tmp files removed: 0 bytes
                      File delete failed. C:\WINDOWS\S02EA33A7.tmp scheduled to be deleted on reboot.
                      %systemroot% .tmp files removed: 2134530 bytes
                      %systemroot%\System32 .tmp files removed: 2933248 bytes
                      File delete failed. C:\WINDOWS\temp\_avast4_\Webshlock.txt scheduled to be deleted on reboot.
                      File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_5e8.dat scheduled to be deleted on reboot.
                      Windows Temp folder emptied: 16384 bytes
                      RecycleBin emptied: 0 bytes

                      Total Files Cleaned = 16,51 mb

                      OTM by OldTimer - Version 3.0.0.6 log created on 09012009_165612

                      Files moved on Reboot...
                      File move failed. c:\windows\S02EA33A7.tmp scheduled to be moved on reboot.
                      File C:\WINDOWS\temp\_avast4_\Webshlock.txt not found!
                      File C:\WINDOWS\temp\Perflib_Perfdata_5e8.dat not found!

                      Registry entries deleted on Reboot...
                      0
                      1. nickel , malewarebyte's maintenant ;)

                        je sors faire une courses et re
                        0
                        1. Malwarebytes' Anti-Malware 1.40
                          Version de la base de données: 2725
                          Windows 5.1.2600 Service Pack 3

                          01/09/2009 17:10:57
                          mbam-log-2009-09-01 (17-10-57).txt

                          Type de recherche: Examen rapide
                          Eléments examinés: 102321
                          Temps écoulé: 5 minute(s), 42 second(s)

                          Processus mémoire infecté(s): 0
                          Module(s) mémoire infecté(s): 0
                          Clé(s) du Registre infectée(s): 2
                          Valeur(s) du Registre infectée(s): 0
                          Elément(s) de données du Registre infecté(s): 0
                          Dossier(s) infecté(s): 2
                          Fichier(s) infecté(s): 6

                          Processus mémoire infecté(s):
                          (Aucun élément nuisible détecté)

                          Module(s) mémoire infecté(s):
                          (Aucun élément nuisible détecté)

                          Clé(s) du Registre infectée(s):
                          HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\av care (Rogue.AVCare) -> Quarantined and deleted successfully.
                          HKEY_LOCAL_MACHINE\SOFTWARE\AV Care (Rogue.AVCare) -> Quarantined and deleted successfully.

                          Valeur(s) du Registre infectée(s):
                          (Aucun élément nuisible détecté)

                          Elément(s) de données du Registre infecté(s):
                          (Aucun élément nuisible détecté)

                          Dossier(s) infecté(s):
                          C:\Program Files\AV Care (Rogue.AVCare) -> Quarantined and deleted successfully.
                          C:\Documents and Settings\PUIG\Menu Démarrer\Programmes\AV Care (Rogue.AVCare) -> Quarantined and deleted successfully.

                          Fichier(s) infecté(s):
                          C:\Program Files\AV Care\avc.ico (Rogue.AVCare) -> Quarantined and deleted successfully.
                          C:\Program Files\AV Care\AVCare.exe (Rogue.AVCare) -> Quarantined and deleted successfully.
                          C:\Program Files\AV Care\AVCare.ini (Rogue.AVCare) -> Quarantined and deleted successfully.
                          C:\Program Files\AV Care\Uninstall.exe (Rogue.AVCare) -> Quarantined and deleted successfully.
                          C:\Documents and Settings\PUIG\Menu Démarrer\Programmes\AV Care\AV Care.lnk (Rogue.AVCare) -> Quarantined and deleted successfully.
                          C:\Documents and Settings\PUIG\Bureau\AV Care.lnk (Rogue.AVCare) -> Quarantined and deleted successfully.
                          0
                          1. ok, encore merci (j'espere que tu avait bien compris mon message un peu plus haut, ou j'ai oublié le mot "arreter", ce qui aurait du donner "je suis pas pret d'arreter de te remercier".

                            pourras tu me donner des trucs (quel logiciel faut il avoir ??? frequence d'utilisation ??? peut on "nettoyer" le pc de certaine aplications qui serai inutiles et se lancerai au demarage ???)

                            Et enfin, j'ai debranché mon disque dur externe depuis le probleme de virus (celui ci ne sert que en stockage). Par contre, en le rebranchant, le pc rame avant ou pendant l'execution du BIOS !!! Cela il avait deja fait quand je l'ai eu, et cela c'etait arrete comme par magie, et maintenant rebelote (avant que tes talents ne repare mon PC)

                            Je n'ai pas encore rebranché le DD externe, j'attends tes conseils.
                            0
                            1. réouvre malewarebyte's , va sur quarantaine et supprime tout

                              #######

                              Télécharge JavaRa.zip de Paul 'Prm753' McLain et Fred de Vries.
                              Décompresse le fichier sur ton bureau (clique droit > Extraire tout.)
                              Double-clique sur le répertoire JavaRa obtenu.
                              Puis double-clique sur le fichier JavaRa.exe (le .exe peut ne pas s'afficher)
                              Clique sur Search For Updates.
                              Sélectionne Update Using jucheck.exe puis clique sur Search.
                              Autorise le processus à se connecter s'il te le demande, clique sur Install et suis les instructions d'installation. Cela prendra quelques minutes.
                              Quand l'installation est terminée, revient à l'écran de JavaRa et clique sur Remove Older Versions.
                              Clique sur Oui pour confirmer. L'outil va travailler, clique ensuite sur Ok, puis une deuxième fois sur Ok.
                              Un rapport va s'ouvrir, copie-colle le dans ta prochaine réponse.
                              Note : le rapport se trouve aussi à la racine de la partition système, en général C:\ sous le nom JavaRa.log
                              (c:\JavaRa.log)
                              Ferme l'application.

                              #####

                              je sors faire une courses et reviens

                              0
                              1. avaRa 1.15 Removal Log.

                                Report follows after line.

                                ------------------------------------

                                The JavaRa removal process was started on Tue Sep 01 17:23:14 2009

                                Found and removed: C:\Program Files\Java\jre1.6.0

                                Found and removed: C:\Program Files\Java\jre1.6.0_03

                                Found and removed: C:\Program Files\Java\jre1.6.0_05

                                Found and removed: C:\Program Files\Java\jre1.6.0_07

                                Found and removed: C:\Documents and Settings\PUIG\Application Data\Sun\Java\jre1.6.0

                                Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA}

                                Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}

                                Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}

                                Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBB}

                                Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBB}

                                Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBB}

                                Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBC}

                                Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBC}

                                Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBC}

                                Found and removed: SOFTWARE\Classes\Installer\Features\8A0F842331866D117AB7000B0D610000

                                Found and removed: SOFTWARE\Classes\Installer\Features\8A0F842331866D117AB7000B0D610003

                                Found and removed: SOFTWARE\Classes\Installer\Features\8A0F842331866D117AB7000B0D610005

                                Found and removed: SOFTWARE\Classes\Installer\Products\8A0F842331866D117AB7000B0D610000

                                Found and removed: SOFTWARE\Classes\Installer\Products\8A0F842331866D117AB7000B0D610003

                                Found and removed: SOFTWARE\Classes\Installer\Products\8A0F842331866D117AB7000B0D610005

                                Found and removed: SOFTWARE\Classes\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D610000

                                Found and removed: SOFTWARE\Classes\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D610003

                                Found and removed: SOFTWARE\Classes\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D610005

                                Found and removed: SOFTWARE\Classes\JavaPlugin.160

                                Found and removed: SOFTWARE\Classes\JavaPlugin.160_03

                                Found and removed: SOFTWARE\Classes\JavaPlugin.160_05

                                Found and removed: SOFTWARE\JavaSoft\Java Plug-in\1.6.0

                                Found and removed: SOFTWARE\JavaSoft\Java Plug-in\1.6.0_03

                                Found and removed: SOFTWARE\JavaSoft\Java Plug-in\1.6.0_05

                                Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.6.0

                                Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.6.0_03

                                Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.6.0_05

                                Found and removed: SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA}

                                Found and removed: SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}

                                Found and removed: SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}

                                Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D610000

                                Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D610003

                                Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D610005

                                Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ACBB9B2318A96D117A58000B0D610000

                                Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ACBB9B2318A96D117A58000B0D610003

                                Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ACBB9B2318A96D117A58000B0D610005

                                Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8A0F842331866D117AB7000B0D610000

                                Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8A0F842331866D117AB7000B0D610003

                                Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8A0F842331866D117AB7000B0D610005

                                Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3248F0A8-6813-11D6-A77B-00B0D0160000}

                                Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3248F0A8-6813-11D6-A77B-00B0D0160030}

                                Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3248F0A8-6813-11D6-A77B-00B0D0160050}

                                Found and removed: Software\Classes\JavaPlugin.160

                                Found and removed: Software\Classes\JavaPlugin.160_03

                                Found and removed: Software\Classes\JavaPlugin.160_05

                                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0003-ABCDEFFEDCBA}

                                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0004-ABCDEFFEDCBA}

                                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0005-ABCDEFFEDCBA}

                                Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1

                                Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_02

                                Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_03

                                Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_04

                                Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2

                                Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2.0_01

                                Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.6.0

                                Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.6.0_03

                                Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.6.0_05

                                Found and removed: Software\JavaSoft\Java2D\1.6.0

                                Found and removed: Software\JavaSoft\Java2D\1.6.0_03

                                Found and removed: Software\JavaSoft\Java2D\1.6.0_05

                                Found and removed: Software\JavaSoft\Java Runtime Environment\1.6.0

                                Found and removed: Software\JavaSoft\Java Runtime Environment\1.6.0_03

                                Found and removed: Software\JavaSoft\Java Runtime Environment\1.6.0_05

                                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA}

                                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBA}

                                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBB}

                                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA}

                                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBB}

                                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBA}

                                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBB}

                                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBA}

                                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBB}

                                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBA}

                                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBB}

                                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBA}

                                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBB}

                                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBA}

                                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBB}

                                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBA}

                                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBB}

                                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBA}

                                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBB}

                                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBA}

                                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBB}

                                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBA}

                                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBB}

                                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBA}

                                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBB}

                                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBA}

                                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBB}

                                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBA}

                                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBB}

                                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBA}

                                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBB}

                                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBA}

                                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBB}

                                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBA}

                                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBB}

                                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBA}

                                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBB}

                                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBA}

                                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBB}

                                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBA}

                                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBB}

                                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBA}

                                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBB}

                                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBA}

                                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBB}

                                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBA}

                                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBB}

                                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBA}

                                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBB}

                                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBA}

                                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBB}

                                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBA}

                                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBB}

                                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBA}

                                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBB}

                                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBA}

                                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBB}

                                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBA}

                                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBB}

                                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBA}

                                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBB}

                                Found and removed: SOFTWARE\JavaSoft\Java Plug-in\1.6.0_07

                                Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.6.0_07

                                Found and removed: SOFTWARE\Microsoft\Active Setup\Installed Components\{08B0E5C0-4FCB-11CF-AAA5-00401C608500}

                                Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ACBB9B2318A96D117A58000B0D610007

                                Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8A0F842331866D117AB7000B0D610007

                                Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3248F0A8-6813-11D6-A77B-00B0D0160070}

                                Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.6.0\

                                Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.6.0_03\

                                Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.6.0_05\

                                Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.6.0\bin\

                                Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.6.0_03\bin\

                                Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.6.0_05\bin\

                                Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.6.0_07\bin\

                                ------------------------------------

                                Finished reporting.
                                0
                                1. comme je dois moi aussi m'absenter, voici un nouveau rapport de RSIT :

                                  Logfile of random's system information tool 1.06 (written by random/random)
                                  Run by PUIG at 2009-09-01 17:25:04
                                  Microsoft Windows XP Édition familiale Service Pack 3
                                  System drive C: has 12 GB (19%) free of 60 GB
                                  Total RAM: 3007 MB (78% free)

                                  Logfile of Trend Micro HijackThis v2.0.2
                                  Scan saved at 17:25:13, on 01/09/2009
                                  Platform: Windows XP SP3 (WinNT 5.01.2600)
                                  MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
                                  Boot mode: Normal

                                  Running processes:
                                  C:\WINDOWS\System32\smss.exe
                                  C:\WINDOWS\system32\winlogon.exe
                                  C:\WINDOWS\system32\services.exe
                                  C:\WINDOWS\system32\lsass.exe
                                  C:\WINDOWS\system32\svchost.exe
                                  C:\WINDOWS\System32\svchost.exe
                                  C:\WINDOWS\system32\svchost.exe
                                  C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
                                  C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                  C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                  C:\WINDOWS\Explorer.EXE
                                  C:\Program Files\Analog Devices\Core\smax4pnp.exe
                                  C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                                  C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                                  C:\WINDOWS\system32\Prismsta.exe
                                  C:\WINDOWS\system32\Prismsvr.exe
                                  C:\Program Files\Microsoft IntelliType Pro\itype.exe
                                  C:\Program Files\Microsoft IntelliPoint\ipoint.exe
                                  C:\Program Files\Fichiers communs\Nokia\MPlatform\NokiaMServer.exe
                                  C:\Program Files\Microsoft IntelliType Pro\dpupdchk.exe
                                  C:\Program Files\iTunes\iTunesHelper.exe
                                  C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                                  C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                                  C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
                                  C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                                  C:\OLIFAXVX\TOOLBAR.EXE
                                  C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
                                  C:\WINDOWS\system32\spoolsv.exe
                                  C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                  C:\Program Files\Bonjour\mDNSResponder.exe
                                  C:\WINDOWS\system32\drivers\CDAC11BA.EXE
                                  C:\Program Files\Canal\Canal Widget\VOD\CanalPlus.VOD.exe
                                  C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
                                  C:\WINDOWS\system32\nvsvc32.exe
                                  C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
                                  C:\WINDOWS\system32\HPZipm12.exe
                                  C:\WINDOWS\system32\svchost.exe
                                  C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                                  C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                                  C:\Program Files\iPod\bin\iPodService.exe
                                  C:\WINDOWS\System32\svchost.exe
                                  C:\Program Files\Windows Live\Messenger\usnsvc.exe
                                  C:\WINDOWS\system32\wuauclt.exe
                                  C:\Documents and Settings\PUIG\Bureau\JavaRa\JavaRa.exe
                                  C:\WINDOWS\system32\msiexec.exe
                                  C:\Program Files\Java\jre6\bin\jqs.exe
                                  C:\WINDOWS\system32\wbem\wmiapsrv.exe
                                  C:\WINDOWS\system32\NOTEPAD.EXE
                                  C:\Program Files\Internet Explorer\iexplore.exe
                                  C:\Documents and Settings\PUIG\Bureau\RSIT.exe
                                  C:\Program Files\trend micro\PUIG.exe

                                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                  R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                                  O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                                  O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                  O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                                  O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                                  O2 - BHO: BHO Barre de Confiance - {988B07F5-7392-455A-8A1F-64935CB8B6ED} - C:\Program Files\BarreConfCMCIC\TAPBar.dll
                                  O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
                                  O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
                                  O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
                                  O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                                  O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
                                  O3 - Toolbar: Barre de confiance - {55BDF3B0-C0A8-481A-B8A6-01CD2BE0F3FD} - C:\Program Files\BarreConfCMCIC\TAPBar.dll
                                  O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
                                  O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
                                  O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\WINDOWS\JM\JMInsIDE.exe
                                  O4 - HKLM\..\Run: [JMB36X Configure] C:\WINDOWS\system32\JMRaidSetup.exe boot
                                  O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                                  O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
                                  O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                                  O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                                  O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                                  O4 - HKLM\..\Run: [PRISMSTA.EXE] Prismsta.exe /START
                                  O4 - HKLM\..\Run: [PRISMSVR.EXE] Prismsvr.exe /APPLY
                                  O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
                                  O4 - HKLM\..\Run: [Canal Widget] "C:\Program Files\Canal\Canal Widget\Launcher.exe"
                                  O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
                                  O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
                                  O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
                                  O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                                  O4 - HKLM\..\Run: [NokiaMServer] C:\Program Files\Fichiers communs\Nokia\MPlatform\NokiaMServer /watchfiles
                                  O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                                  O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                                  O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
                                  O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                                  O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                                  O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                                  O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                                  O4 - Startup: Barre d'Outils Olitec.lnk = C:\OLIFAXVX\TOOLBAR.EXE
                                  O4 - Startup: Outil de détection de support Picture Motion Browser.lnk = C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
                                  O4 - Global Startup: Démarrage rapide de HP Photosmart Premier.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
                                  O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                                  O4 - Global Startup: Nokia Ovi Suite.lnk = C:\Program Files\Nokia\Ovi\Suite\RunLauncher.exe
                                  O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                                  O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                                  O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                  O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                  O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                                  O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                                  O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                  O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                  O15 - Trusted Zone: *.canalplay.com (HKLM)
                                  O15 - Trusted Zone: *.canalplusactive.com (HKLM)
                                  O16 - DPF: {07041BB2-F22C-413C-9597-622D474EE889} (DLCFRAME (version 1,2,4,41)) - http://service.wuerth.de/duebeltechnik/DLCFrame.cab
                                  O16 - DPF: {1FF43AD5-2262-4C2F-81D4-26D710C3F305} (VB2S Mannequin Virtuel Control) - http://mannequin.redoute.fr/activex/Mannequin.cab
                                  O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} (Image Uploader Control) - http://www.photoweb.fr/moncompte/Account/LogOn?ReturnUrl=%2ftransfert
                                  O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
                                  O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab2.cab
                                  O16 - DPF: {A73BAEFA-EE65-494D-BEDB-DD3E5A34FA98} (Image Uploader) - http://www.extrafilm.fr/ImageUploader4.cab
                                  O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/...
                                  O17 - HKLM\System\CCS\Services\Tcpip\..\{4A79E050-E6AE-496A-B01A-611CDE2CD600}: NameServer = 192.168.1.1
                                  O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
                                  O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                  O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                  O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                  O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                                  O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                                  O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                                  O23 - Service: BvrpKrnl - Unknown owner - C:\Program Files\WinFax eXPert\BVRPKrnl.exe
                                  O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
                                  O23 - Service: CanalPlus.VOD - Canal+ Active - C:\Program Files\Canal\Canal Widget\VOD\CanalPlus.VOD.exe
                                  O23 - Service: Firebird Server - MAGIX Instance (FirebirdServerMAGIXInstance) - MAGIX® - C:\Program Files\MAGIX\Common\Database\bin\fbserver.exe
                                  O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                  O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
                                  O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                                  O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
                                  O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                                  O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
                                  O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Nokia\PC Connectivity Solution\ServiceLayer.exe
                                  O23 - Service: TwonkyMedia - PacketVideo - C:\Program Files\Nokia\Nokia Home Media Server\Media Server\TwonkyMedia.exe
                                  0
                                  1. oki ,

                                    a ton retour

                                    désisntal Lavasoft Ad-Aware car innefficace garde plutot malewarebyte's ;)

                                    #####

                                    désinstal Adobe Reader 8.0 et instal la version a jours la 9 :

                                    https://get2.adobe.com/fr/reader/otherversions/

                                    ########

                                    va a ce fichier : C:\Program Files\trend micro\PUIG.exe

                                    c est hijackthis , double clic dessus et choisi do a system scan only

                                    dans la liste coche ces lignes :

                                    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

                                    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                                    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                                    O4 - Startup: Barre d'Outils Olitec.lnk = C:\OLIFAXVX\TOOLBAR.EXE

                                    O16 - DPF: {07041BB2-F22C-413C-9597-622D474EE889} (DLCFRAME (version 1,2,4,41)) - http://service.wuerth.de/duebeltechnik/DLCFrame.cab
                                    O16 - DPF: {1FF43AD5-2262-4C2F-81D4-26D710C3F305} (VB2S Mannequin Virtuel Control) - http://mannequin.redoute.fr/activex/Mannequin.cab
                                    O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} (Image Uploader Control) - http://www.photoweb.fr/moncompte/Account/LogOn?ReturnUrl=%2ftransfert
                                    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/default.aspx
                                    O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab2.cab
                                    O16 - DPF: {A73BAEFA-EE65-494D-BEDB-DD3E5A34FA98} (Image Uploader) - http://www.extrafilm.fr/ImageUploader4.cab
                                    O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/

                                    tu les coches et tu clic sur fix checked

                                    ##########

                                    je vais te faire changer d antivirus par antivir un plus performant

                                    désinstal avast :

                                    Pour désinstaller Avast telecharge cet outil

                                    instal antivir a la place :

                                    ->Antivir le telecharger

                                    pour info : Antivir vs Avast :

                                    -> http://forum.malekal.com/ftopic3528.php

                                    tuto antivir :

                                    • Tuto : https://www.malekal.com/avira-free-security-antivirus-gratuit/
                                    • Tuto : http://www.swl1f.net/viewtopic.php?f=14&t=59

                                    ############

                                    Maintenant , nous allons supprimer les logiciels de désinfection que je t'ai fait téléchargé.
                                    En effet , s'en servir est dangereux pour le pc si l'on ne s'y connais pas.
                                    De plus ils sont mis régulièrement à jours.

                                    → Ferme toutes les applications en cours, puis télécharge ToolsCleaner2 sur ton Bureau.

                                    → Double clique sur ToolsCleaner2.exe
                                    → Clique sur .Recherche
                                    → puis sur Suppression quand la liste est trouvée.
                                    → Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\).

                                    (CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

                                    Note : ton bureau RISQUE de disparaître, c'est normal. S'il n'apparaît pas à la fin du scan, fais la manip suivante :

                                    CTRL+ALT+SUPP pour ouvrir le Gestionnaire des tâches.
                                    Puis rends toi à l'onglet "Processus". Clique en haut à gauche sur Fichiers et choisis "Exécuter"

                                    Tape explorer.exe et valide. Cela fera re-apparaître le Bureau

                                    ############

                                    Purge de la restauration système :

                                    *Désactive ta restauration :
                                    Clique droit sur poste de travail/propriétés/Restauration système/coche la case désactiver la restauration, appliquer, OK
                                    ---> Redémarre ton PC ...

                                    *Réactive ta restauration :
                                    Clique droit sur poste de travail/propriétés/Restauration système/décoche la case désactiver la restauration, appliquer, OK
                                    --->Redémarre ton PC ...

                                    ( Note : tu peux aussi y accéder via panneau de configuration->" système "->" restauration système " ).

                                    Tuto xp : http://service1.symantec.com/support/inter/tsgeninfointl.Nsf/fr_docid/20020830101856924

                                    ##########

                                    pour finir , verifie que antivir soit a jours et lance un scan de ton pc puis post le rapport
                                    0
                                    1. re salut

                                      rapport :

                                      [ Rapport ToolsCleaner version 2.3.10 (par A.Rothstein & dj QUIOU) ]

                                      --> Recherche:

                                      C:\Combofix.txt: trouvé !
                                      C:\Qoobox: trouvé !
                                      C:\_OTM: trouvé !
                                      C:\Rsit: trouvé !
                                      C:\Documents and Settings\Administrateur\Bureau\Rsit.exe: trouvé !
                                      C:\Documents and Settings\PUIG\Bureau\OTM.exe: trouvé !
                                      C:\Documents and Settings\PUIG\Bureau\Rsit.exe: trouvé !
                                      C:\Program Files\trend micro\HijackThis.exe: trouvé !
                                      C:\Program Files\trend micro\hijackthis.log: trouvé !
                                      C:\Qoobox\Quarantine\catchme.log: trouvé !

                                      ---------------------------------
                                      --> Suppression:

                                      C:\Documents and Settings\PUIG\Bureau\OTM.exe: supprimé !
                                      C:\Program Files\trend micro\HijackThis.exe: supprimé !
                                      C:\Combofix.txt: supprimé !
                                      C:\Documents and Settings\Administrateur\Bureau\Rsit.exe: supprimé !
                                      C:\Documents and Settings\PUIG\Bureau\Rsit.exe: supprimé !
                                      C:\Program Files\trend micro\hijackthis.log: supprimé !
                                      C:\Qoobox\Quarantine\catchme.log: supprimé !
                                      C:\Qoobox: supprimé !
                                      C:\_OTM: supprimé !
                                      C:\Rsit: supprimé !
                                      0
                                      • 1
                                      • 2