Pb virus

Résolu
Bonjour,
Neofite en informatik, je solicite votre aide car pb avec pc antispyware 2010 impossible a suprimé. je sui sur orange g antivir é je ne coné pa la config de mon matos j compren rien. urgent, merci davance
Configuration: Windows XP Internet Explorer 6.0

19 réponses

Résumé de la discussion

Infection par PC Antispyware 2010 sur Windows XP avec Internet Explorer 6, et une impossibilité initiale de suppression qui pousse à demander une aide urgente. Des éléments techniques et des rapports d'outils tels que ComboFix et HijackThis révèlent des fichiers et des démarrages indésirables, témoignant d'une présence persistante du malware et d'une compromission profonde du système. Les interventions préconisent de ne pas redémarrer avant nettoyage, puis de relancer ComboFix et d'analyser les rapports pour cibler les éléments malveillants dans la mémoire, le registre et les tâches planifiées. Certaines entrées et fichiers repérés évoquent des relais logiciels variés et des composants lancés au démarrage, ce qui complique le nettoyage et justifie un suivi avec des rapports complémentaires.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    On est mal barré...

    Il ne faut pas que tu redemarre le pc !jamais sous aucun pretexte

    Refais combofix stp.
    1. Suite au message de DID, je sais plus quoi faire

      Dois-je redemarer mon pc ou non?
  2. Que dois-je faire ?

    ComboFix 09-09-08.01 - M 08/09/2009 21:09.3.1 - NTFSx86
    Microsoft Windows XP Édition familiale 5.1.2600.1.1252.33.1036.18.511.140 [GMT 2:00]
    Lancé depuis: c:\documents and settings\M\Bureau\ComboFix.exe
    FW: Sunbelt Kerio Personal Firewall *enabled* {E659E0EE-10E6-49B7-8696-60F38D0EB174}

    AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
    .

    (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\documents and settings\All Users\Application Data\ifaju.com
    c:\documents and settings\All Users\Application Data\vudupife.scr
    c:\documents and settings\All Users\Documents\ohot.scr
    c:\documents and settings\All Users\Documents\tugarenor.sys
    c:\documents and settings\M\Application Data\jozuj.bin
    c:\documents and settings\M\Application Data\kydaxakehi._sy
    c:\documents and settings\M\Application Data\Microsoft\Internet Explorer\Quick Launch\PC_Antispyware2010.lnk
    c:\documents and settings\M\Application Data\orapiqi.pif
    c:\documents and settings\M\Application Data\qozy.inf
    c:\documents and settings\M\Application Data\umeb.bat
    c:\documents and settings\M\Application Data\wiaservg.log
    c:\documents and settings\M\Application Data\zajenacego.dll
    c:\documents and settings\M\Bureau\PC_Antispyware2010.lnk
    c:\documents and settings\M\Cookies\bihu.bat
    c:\documents and settings\M\Cookies\jahet.com
    c:\documents and settings\M\Cookies\rede.reg
    c:\documents and settings\M\Cookies\rymizali.ban
    c:\documents and settings\M\Cookies\uheruho.scr
    c:\documents and settings\M\Local Settings\Application Data\pobebu.dl
    c:\documents and settings\M\Local Settings\Application Data\ucunaqim.ban
    c:\documents and settings\M\Local Settings\Application Data\usecopily.vbs
    c:\documents and settings\M\Local Settings\Application Data\wehev.ban
    c:\documents and settings\M\Local Settings\Temporary Internet Files\nedewepimo.inf
    c:\documents and settings\M\Local Settings\Temporary Internet Files\nesupikur.dll
    c:\program files\Fichiers communs\efixu.bat
    c:\program files\Fichiers communs\faramak.sys
    c:\program files\Fichiers communs\kimihuvax.sys
    c:\program files\Fichiers communs\sygomab.bin
    c:\program files\Fichiers communs\ujofesuze.sys
    c:\program files\Fichiers communs\usisipa.reg
    c:\program files\Fichiers communs\xofoqawol._dl
    c:\program files\PC_Antispyware2010
    c:\program files\PC_Antispyware2010\AVEngn.dll
    c:\program files\PC_Antispyware2010\data\daily.cvd
    c:\program files\PC_Antispyware2010\htmlayout.dll
    c:\program files\PC_Antispyware2010\Microsoft.VC80.CRT\Microsoft.VC80.CRT.manifest
    c:\program files\PC_Antispyware2010\Microsoft.VC80.CRT\msvcm80.dll
    c:\program files\PC_Antispyware2010\Microsoft.VC80.CRT\msvcp80.dll
    c:\program files\PC_Antispyware2010\Microsoft.VC80.CRT\msvcr80.dll
    c:\program files\PC_Antispyware2010\PC_Antispyware2010.cfg
    c:\program files\PC_Antispyware2010\PC_Antispyware2010.exe
    c:\program files\PC_Antispyware2010\pthreadVC2.dll
    c:\program files\PC_Antispyware2010\Uninstall.exe
    c:\program files\PC_Antispyware2010\wscui.cpl
    c:\windows\braviax.exe
    c:\windows\ehej.sys
    c:\windows\iraqiju.bat
    c:\windows\kajypi.dll
    c:\windows\ojuruby.dl
    c:\windows\system32\_scui.cpl
    c:\windows\system32\braviax.exe
    c:\windows\system32\fywavam.ban
    c:\windows\system32\gipohesan.dl
    c:\windows\system32\sdra64.exe
    c:\windows\system32\wbem\proquota.exe
    c:\windows\system32\wisdstr.exe
    c:\windows\uzosudy.dl
    c:\windows\ylyle.dl
    c:\windows\yxejy.scr

    c:\windows\system32\proquota.exe était absent
    Copie restaurée à partir de - c:\system volume information\_restore{38A3208A-B97D-447D-8125-61BF3B0915B1}\RP521\A0065905.exe

    .
    ((((((((((((((((((((((((((((( Fichiers créés du 2009-08-08 au 2009-09-08 ))))))))))))))))))))))))))))))))))))
    .

    2009-09-08 19:18 . 2003-04-24 12:00 45568 -c--a-w- c:\windows\system32\dllcache\proquota.exe
    2009-09-08 19:18 . 2003-04-24 12:00 45568 ----a-w- c:\windows\system32\proquota.exe
    2009-09-07 15:12 . 2009-09-07 15:26 -------- d-----w- c:\documents and settings\M\DoctorWeb
    2009-09-06 22:16 . 2009-09-06 22:16 -------- d-----w- C:\_OTM
    2009-09-06 16:33 . 2009-09-06 16:33 -------- d-----w- c:\windows\ERUNT
    2009-09-06 16:20 . 2009-09-06 16:57 -------- d-----w- C:\SDFix
    2009-09-06 15:46 . 2009-09-08 18:49 -------- d-----w- C:\rsit
    2009-09-01 17:08 . 2009-09-01 17:08 -------- d-----w- C:\CD_Permanent
    2009-08-22 17:35 . 2009-08-22 17:35 -------- d-----w- c:\documents and settings\M\Local Settings\Application Data\Google
    2009-08-16 17:09 . 2009-08-16 17:09 -------- d-----w- c:\documents and settings\All Users\Application Data\Trymedia
    2009-08-16 17:08 . 2009-08-16 17:08 -------- d-----w- c:\program files\BFG
    2009-08-11 18:18 . 2009-08-11 18:18 -------- d-----w- c:\documents and settings\All Users\Application Data\Zylom

    .
    (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2009-09-08 18:46 . 2008-04-22 18:06 -------- d-----w- c:\program files\Trend Micro
    2009-09-08 18:05 . 2009-09-08 18:05 18275 ----a-w- c:\documents and settings\M\Application Data\ykejydyjih.dat
    2009-09-08 18:05 . 2009-09-08 18:05 15927 ----a-w- c:\program files\Fichiers communs\acemodewim._sy
    2009-09-06 18:49 . 2009-09-06 18:49 17271 ----a-w- c:\documents and settings\All Users\Application Data\pebeh.dat
    2009-09-06 16:32 . 2008-07-26 08:58 362 ----a-w- c:\windows\system32\drivers\fwdrv.err
    2009-09-06 09:27 . 2009-09-06 09:27 12315 ----a-w- c:\program files\Fichiers communs\upycu.lib
    2009-09-05 21:32 . 2009-09-05 21:32 13102 ----a-w- c:\program files\Fichiers communs\lygujuzi.lib
    2009-09-05 20:16 . 2007-08-10 20:03 197760 ----a-w- c:\windows\system32\drivers\ndis.sys
    2009-09-01 17:08 . 2003-08-12 20:08 -------- d--h--w- c:\program files\InstallShield Installation Information
    1999-04-06 12:27 . 1999-04-06 12:27 99840 -c--a-w- c:\program files\Fichiers communs\IRAABOUT.DLL
    1998-12-09 02:53 . 1998-12-09 02:53 70144 -c--a-w- c:\program files\Fichiers communs\IRAMDMTR.DLL
    1998-12-09 02:53 . 1998-12-09 02:53 48640 -c--a-w- c:\program files\Fichiers communs\IRALPTTR.DLL
    1998-12-09 02:53 . 1998-12-09 02:53 31744 -c--a-w- c:\program files\Fichiers communs\IRAWEBTR.DLL
    1998-12-09 02:53 . 1998-12-09 02:53 186368 -c--a-w- c:\program files\Fichiers communs\IRAREG.DLL
    1998-12-09 02:53 . 1998-12-09 02:53 17920 -c--a-w- c:\program files\Fichiers communs\IRASRIAL.DLL
    .

    ------- Sigcheck -------

    [-] 2009-09-05 20:16 . 41B572BED1081B840EEBA74DB5B60010 . 197760 . . [------] . . c:\windows\system32\drivers\ndis.sys
    [-] 2009-09-05 20:16 . 41B572BED1081B840EEBA74DB5B60010 . 197760 . . [------] . . c:\windows\system32\dllcache\ndis.sys
    [7] 2003-10-04 . D999CE17681D7D074D534FC5BC662E0A . 168192 . . [5.1.2600.1254] . . c:\windows\Driver Cache\i386\ndis.sys
    [7] 2003-04-24 . 3B350E5A2A5E951453F3993275A4523A . 167552 . . [5.1.2600.1106] . . c:\windows\LastGood.Tmp\System32\DllCache\ndis.sys
    [7] 2003-04-24 . 3B350E5A2A5E951453F3993275A4523A . 167552 . . [5.1.2600.1106] . . c:\windows\LastGood.Tmp\System32\DRIVERS\ndis.sys

    c:\windows\system32\drivers\beep.sys ... manque !!
    c:\windows\system32\xmlprov.dll ... manque !!
    .
    ((((((((((((((((((((((((((((( SnapShot@2009-09-06_18.42.42 )))))))))))))))))))))))))))))))))))))))))
    .
    + 2003-08-12 20:04 . 2009-09-08 17:57 81920 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
    - 2003-08-12 20:04 . 2009-09-06 18:21 81920 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
    + 2003-08-12 20:04 . 2009-09-08 17:57 32768 c:\windows\system32\config\systemprofile\Local Settings\Historique\History.IE5\index.dat
    - 2003-08-12 20:04 . 2009-09-06 18:21 32768 c:\windows\system32\config\systemprofile\Local Settings\Historique\History.IE5\index.dat
    + 2003-08-12 20:04 . 2009-09-08 17:57 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
    - 2003-08-12 20:04 . 2009-09-06 18:21 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
    + 2009-09-08 18:32 . 2009-07-29 15:49 24281536 c:\windows\system32\MRT.exe
    .
    ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "LogitechSoftwareUpdate"="c:\program files\Logitech\Video\ManifestEngine.exe" [2005-06-08 196608]
    "MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
    "PcSync"="c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2006-06-27 1449984]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "LiveMonitor"="c:\program files\MSI\Live Update 3\LMonitor.exe" [2007-01-17 496640]
    "ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 45056]
    "LVCOMSX"="c:\windows\System32\LVCOMSX.EXE" [2005-07-19 221184]
    "LogitechVideoRepair"="c:\program files\Logitech\Video\ISStart.exe" [2005-06-08 458752]
    "LogitechVideoTray"="c:\program files\Logitech\Video\LogiTray.exe" [2005-06-08 217088]
    "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-06-29 286720]
    "ORAHSSSessionManager"="c:\program files\OrangeHSS\SessionManager\SessionManager.exe" [2008-01-22 107248]
    "Orange_McciTrayApp"="c:\program files\Orange\LiveAssistant.exe" [2007-12-21 1476608]
    "avgnt"="c:\program files\AntiVir PersonalEdition Classic\avgnt.exe" [2007-04-02 327720]
    "!AVG Anti-Spyware"="c:\program files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 6731312]
    "Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe" [2005-06-23 57344]
    "SoundMan"="SOUNDMAN.EXE" - c:\windows\soundman.exe [2006-11-17 577536]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2003-04-24 13312]

    c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
    Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2007-10-31 67128]

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
    "ForceClassicControlPanel"= 1 (0x1)

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
    @="Service"

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AVG Anti-Spyware Guard]
    @="Service"

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^InterVideo WinCinema Manager.lnk]
    path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\InterVideo WinCinema Manager.lnk
    backup=c:\windows\pss\InterVideo WinCinema Manager.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Microsoft Office.lnk]
    path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Microsoft Office.lnk
    backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Symantec Fax Starter Edition Port.lnk]
    path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Symantec Fax Starter Edition Port.lnk
    backup=c:\windows\pss\Symantec Fax Starter Edition Port.lnkCommon Startup

    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "UpdatesDisableNotify"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
    "c:\\Program Files\\OrangeHSS\\Connectivity\\ConnectivityManager.exe"=

    R0 avgntmgr;avgntmgr;c:\windows\system32\drivers\avgntmgr.sys [23/04/2008 11:58 14848]
    R1 avgntdd;avgntdd;c:\windows\system32\drivers\avgntdd.sys [23/04/2008 11:58 40000]
    R1 fwdrv;Firewall Driver;c:\windows\system32\drivers\fwdrv.sys [16/03/2007 09:56 302000]
    R1 khips;Kerio HIPS Driver;c:\windows\system32\drivers\khips.sys [16/03/2007 09:56 72496]
    S3 Ip6FwHlp;Pare-feu de connexion Internet IPv6;c:\windows\System32\svchost.exe -k netsvcs [10/08/2007 22:03 12800]
    .
    Contenu du dossier 'Tâches planifiées'

    2009-09-08 c:\windows\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job
    - c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2006-09-27 15:39]
    .
    - - - - ORPHELINS SUPPRIMES - - - -

    HKLM-Run-rkfree - c:\program files\rkfree\rkfree.exe
    HKLM-Run-PC Antispyware 2010 - c:\program files\PC_Antispyware2010\PC_Antispyware2010.exe

    .
    ------- Examen supplémentaire -------
    .
    uStart Page = hxxp://www.google.com
    mStart Page = hxxp://www.google.com
    uSearchURL,(Default) = hxxp://g.msn.fr/0SEFRFR/SAOS01?FORM=TOOLBR
    IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
    IE: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
    IE: Ouvrir dans un nouvel onglet d'arrière-plan - c:\program files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?8c4b13925d1f493f825a604478a29d6c
    IE: Ouvrir dans un nouvel onglet de premier plan - c:\program files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?8c4b13925d1f493f825a604478a29d6c
    IE: Translate this web page with Babylon - c:\program files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/ActionTU.htm
    IE: Translate with Babylon - c:\program files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Action.htm
    Trusted Zone: 0.0.0.0
    Trusted Zone: motive.com\pfttbc.ft
    Trusted Zone: orange.fr
    Trusted Zone: voila.fr\rw.search.ke
    Trusted Zone: weborama.fr\orange
    TCP: {F99B4C81-5CC1-4C14-9CA4-917D8CC03323} = 212.27.32.176
    Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
    DPF: {8167C273-DF59-4416-B647-C8BB2C7EE83E} - hxxp://liveupdate.msi.com.tw/autobios/LOnline/install.cab
    .

    **************************************************************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2009-09-08 21:18
    Windows 5.1.2600 Service Pack 1 NTFS

    Recherche de processus cachés ...

    Recherche d'éléments en démarrage automatique cachés ...

    Recherche de fichiers cachés ...

    Scan terminé avec succès
    Fichiers cachés: 0

    **************************************************************************
    .
    --------------------- CLES DE REGISTRE BLOQUEES ---------------------

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
    @Denied: (A 2) (Everyone)
    @="FlashBroker"
    "LocalizedString"="@c:\\WINDOWS\\System32\\Macromed\\Flash\\FlashUtil10c.exe,-101"

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
    "Enabled"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
    @="c:\\WINDOWS\\System32\\Macromed\\Flash\\FlashUtil10c.exe"

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
    @Denied: (A 2) (Everyone)
    @="IFlashBroker3"

    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
    @="{00020424-0000-0000-C000-000000000046}"

    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    "Version"="1.0"
    .
    --------------------- DLLs chargées dans les processus actifs ---------------------

    - - - - - - - > 'winlogon.exe'(560)
    c:\windows\system32\ODBC32.dll
    c:\windows\system32\Ati2evxx.dll

    - - - - - - - > 'lsass.exe'(620)
    c:\windows\System32\dssenh.dll
    .
    Heure de fin: 2009-09-08 21:22
    ComboFix-quarantined-files.txt 2009-09-08 19:22
    ComboFix2.txt 2009-09-06 18:51

    Avant-CF: 13 990 461 440 octets libres
    Après-CF: 14 011 461 632 octets libres

    247 --- E O F --- 2009-09-08 18:33
    1. Contributeur sécurité
      Salut franky

      juste de passage : ne redémarre pas le PC car les infections reviendront.

      ++
      1. ok, je te remercie!
    2. Contributeur sécurité
      Salut.

      - Télécharge Random's System Information Tool (RSIT) (par random/random) sur ton Bureau.

      - Double-clique sur RSIT.exe afin de lancer le programme.

      - A l'écran Disclaimer Choisis "1 months" dans le menu déroulant puis clique sur <continue>.

      - Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.

      - Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront. Poste le contenu de log.txt

      Note : Les rapports sont sauvegardés dans le dossier C:\rsit.
      1. Logfile of random's system information tool 1.06 (written by random/random)
        Run by M at 2009-09-06 17:46:49
        Microsoft Windows XP Édition familiale Service Pack 1
        System drive C: has 14 GB (69%) free of 20 GB
        Total RAM: 511 MB (24% free)

        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 17:47:08, on 06/09/2009
        Platform: Windows XP SP1 (WinNT 5.01.2600)
        MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
        Boot mode: Normal

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\System32\Ati2evxx.exe
        info.txt logfile of random's system information tool 1.06 2009-09-06 17:47:13

        ======Uninstall list======

        -->C:\Program Files\DialMessenger/uninstall.exe
        -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
        4x4 Evo2-->C:\WINDOWS\IsUninst.exe -f"D:\Program Files\Terminal Reality\4x4 Evo2\Uninst.isu"
        ABBYY FineReader 6.0 Sprint-->MsiExec.exe /I{ACF60000-22B9-4CE9-98D6-2CCF359BAC07}
        Ad-Aware 2007-->MsiExec.exe /X{E31C348B-63A9-4CBF-8D7F-D932ABB63244}
        Adobe Acrobat 5.0-->C:\WINDOWS\ISUNINST.EXE -f"C:\Program Files\Fichiers communs\Adobe\Acrobat 5.0\NT\Uninst.isu" -c"C:\Program Files\Fichiers communs\Adobe\Acrobat 5.0\NT\Uninst.dll"
        Adobe Flash Player 10 ActiveX-->C:\WINDOWS\System32\Macromed\Flash\uninstall_activeX.exe
        Adobe Shockwave Player 11.5-->"C:\WINDOWS\System32\Adobe\Shockwave 11\uninstaller.exe"
        Adobe® Photoshop® Album Edition Découverte 3.0-->MsiExec.exe /I{4BDFD2CE-6329-42E4-9801-9B3D1F10D79B}
        Apple Software Update-->MsiExec.exe /I{74EC78BC-B379-4E29-9006-8F161DCAABA6}
        ATI - Software Uninstall Utility-->C:\Program Files\ATI Technologies\UninstallAll\AtiCimUn.exe
        ATI Catalyst Control Center-->MsiExec.exe /I{EA9FAF16-0E5C-42C4-9742-9AF8D5F6D69B}
        ATI Display Driver-->rundll32 C:\WINDOWS\System32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
        AVG Anti-Spyware 7.5-->C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\Uninstall.exe
        Avira AntiVir PersonalEdition Classic-->C:\Program Files\AntiVir PersonalEdition Classic\setup.exe /REMOVE
        Barre d'outils Outlook de Windows Live (Windows Live Toolbar)-->MsiExec.exe /X{4002F73D-EBB3-4EA1-A2FF-DBCB4529759E}
        Bloqueur de fenêtres pop-up (Windows Live Toolbar)-->MsiExec.exe /X{51F366F4-C2E4-429A-866A-59C885ED42FD}
        Camera RAW Plug-In for EPSON Creativity Suite-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{8DAC1AE4-33D1-4A78-8A42-00E09EDECC3E}\SETUP.EXE" -l0x40c UNINST
        CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
        CD Permanent Conventions Collectives-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{96DC8B11-4DC4-11D4-BC93-00A0C956D5C8}\setup.exe"
        CDBurnerXP Pro 3-->MsiExec.exe /I{896D642C-7125-44F0-AC49-A23ABF82209C}
        Correctif pour le Lecteur Windows Media [Voir Q828026 pour plus d'informations]-->C:\WINDOWS\$NtUninstallQ828026$\spuninst\spuninst.exe
        Correctif Windows XP - KB810217-->C:\WINDOWS\$NtUninstallKB810217$\spuninst\spuninst.exe
        Correctif Windows XP - KB820291-->C:\WINDOWS\$NtUninstallKB820291$\spuninst\spuninst.exe
        Correctif Windows XP - KB821253-->C:\WINDOWS\$NtUninstallKB821253$\spuninst\spuninst.exe
        Correctif Windows XP - KB822603-->C:\WINDOWS\$NtUninstallKB822603$\spuninst\spuninst.exe
        Correctif Windows XP - KB823182-->C:\WINDOWS\$NtUninstallKB823182$\spuninst\spuninst.exe
        Correctif Windows XP - KB824105-->C:\WINDOWS\$NtUninstallKB824105$\spuninst\spuninst.exe
        Correctif Windows XP - KB826939-->C:\WINDOWS\$NtUninstallKB826939$\spuninst\spuninst.exe
        Correctif Windows XP - KB826942-->C:\WINDOWS\$NtUninstallKB826942$\spuninst\spuninst.exe
        Correctif Windows XP - KB828035-->C:\WINDOWS\$NtUninstallKB828035$\spuninst\spuninst.exe
        Correctif Windows XP - KB833987-->C:\WINDOWS\$NtUninstallKB833987$\spuninst\spuninst.exe
        Correctif Windows XP - KB835732-->C:\WINDOWS\$NtUninstallKB835732$\spuninst\spuninst.exe
        Correctif Windows XP - KB837001-->C:\WINDOWS\$NtUninstallKB837001$\spuninst\spuninst.exe
        Correctif Windows XP - KB839645-->C:\WINDOWS\$NtUninstallKB839645$\spuninst\spuninst.exe
        Correctif Windows XP - KB840374-->C:\WINDOWS\$NtUninstallKB840374$\spuninst\spuninst.exe
        Correctif Windows XP - KB840987-->C:\WINDOWS\$NtUninstallKB840987$\spuninst\spuninst.exe
        Correctif Windows XP - KB841356-->C:\WINDOWS\$NtUninstallKB841356$\spuninst\spuninst.exe
        Correctif Windows XP - KB841533-->C:\WINDOWS\$NtUninstallKB841533$\spuninst\spuninst.exe
        Correctif Windows XP - KB841873-->C:\WINDOWS\$NtUninstallKB841873$\spuninst\spuninst.exe
        Correctif Windows XP - KB842773-->C:\WINDOWS\$NtUninstallKB842773$\spuninst\spuninst.exe
        Correctif Windows XP - KB873339-->C:\WINDOWS\$NtUninstallKB873339$\spuninst\spuninst.exe
        Correctif Windows XP - KB873376-->C:\WINDOWS\$NtUninstallKB873376$\spuninst\spuninst.exe
        Correctif Windows XP - KB885835-->C:\WINDOWS\$NtUninstallKB885835$\spuninst\spuninst.exe
        Correctif Windows XP - KB885836-->C:\WINDOWS\$NtUninstallKB885836$\spuninst\spuninst.exe
        Correctif Windows XP - KB888302-->C:\WINDOWS\$NtUninstallKB888302$\spuninst\spuninst.exe
        Correctif Windows XP - KB890859-->"C:\WINDOWS\$NtUninstallKB890859$\spuninst\spuninst.exe"
        Correctif Windows XP - KB891781-->C:\WINDOWS\$NtUninstallKB891781$\spuninst\spuninst.exe
        Correctif Windows XP - KB911567-->"C:\WINDOWS\$NtUninstallKB911567-OE6SP1-20060316.165634$\spuninst\spuninst.exe"
        Correctif Windows XP - KB918439-->"C:\WINDOWS\$NtUninstallKB918439-IE6SP1-20060530.145346$\spuninst\spuninst.exe"
        Correctif Windows XP - KB918899-->"C:\WINDOWS\$NtUninstallKB918899-IE6SP1-20060725.123917$\spuninst\spuninst.exe"
        Correctif Windows XP - KB925486-->"C:\WINDOWS\$NtUninstallKB925486-IE6SP1-20060918.120000$\spuninst\spuninst.exe"
        Correctif Windows XP (SP2) Q322011-->C:\WINDOWS\$NtUninstallQ322011$\spuninst\spuninst.exe
        Correctif Windows XP (SP2) Q327979-->C:\WINDOWS\$NtUninstallQ327979$\spuninst\spuninst.exe
        Correctif Windows XP (SP2) Q814995-->C:\WINDOWS\$NtUninstallQ814995$\spuninst\spuninst.exe
        Détecteur de flux Windows Live Toolbar (Windows Live Toolbar)-->MsiExec.exe /X{175B7C4A-CAF8-437A-B597-73E0D2D970FE}
        eMule-->"C:\Program Files\eMule\Uninstall.exe"
        EPSON Attach To Email-->C:\Program Files\Fichiers communs\InstallShield\Driver\8\Intel 32\IDriver.exe /M{20C45B32-5AB6-46A4-94EF-58950CAF05E5} /l1033 ADDREMOVEDLG
        EPSON Copy Utility 3-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{67EDD823-135A-4D59-87BD-950616D6E857}\SETUP.EXE" -l0x40c -UnInstall
        EPSON Easy Photo Print-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B66E665A-DF96-4C38-9422-C7F74BC1B4E5}\SETUP.EXE" -l0x40c UNINST
        EPSON File Manager-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2EB81825-E9EE-44F4-8F51-1240C3898DC6}\Setup.exe" -l0x40c UNINST
        EPSON Logiciel imprimante-->C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\EPUPDATE.EXE /R
        EPSON Scan Assistant-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2A88F1BF-7041-4E42-84B1-6B4ACB83AC64}\Setup.exe" -l0x40c -u
        EPSON Scan-->C:\Program Files\epson\escndv\setup\setup.exe /r
        EPSON Web-To-Page-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7F14F68C-17FA-4F88-B3FD-7F449C1EBF32}\SETUP.EXE" -l0x40c -anything
        ESDX6000_CX5900 Guide util.-->C:\Program Files\EPSON\TPMANUAL\ESDX6000_CX5900\USE_G\DOCUNINS.EXE
        Extension de Windows Live Toolbar (Windows Live Toolbar)-->MsiExec.exe /X{D518AD32-C710-4616-BA0D-D4B1FA5F82E8}
        Favorit-->"c:\documents and settings\m\local settings\application data\ofgmnuee.exe" -uninstall
        HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
        Hotfix for Windows Media Format SDK (KB902344)-->"C:\WINDOWS\$NtUninstallKB902344$\spuninst\spuninst.exe"
        J2SE Runtime Environment 5.0 Update 16-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150160}
        Java(TM) 6 Update 11-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216011FF}
        K-Lite Codec Pack 2.72 Full-->"C:\Program Files\K-Lite Codec Pack\unins000.exe"
        Lecteur Windows Media 10-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
        live assistant 2.0-->C:\WINDOWS\UnInstall.exe
        Logiciel QuickCam de Logitech-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C43048A9-742C-4DAD-90D2-E3B53C9DB825}\setup.exe" -l0x40c
        Logitech Desktop Messenger-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{900B1197-53F5-4F46-A882-2CFFFE2EEDCB}\Setup.exe" -l0x40c UNINSTALL
        Logitech Print Service-->C:\PROGRA~1\Logitech\PRINTS~1\UNWISE.EXE C:\PROGRA~1\Logitech\PRINTS~1\INSTALL.LOG
        Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
        Menus intelligents (Windows Live Toolbar)-->MsiExec.exe /X{3585ED1C-74C5-43B0-A232-831B96A12A2B}
        Microsoft .NET Framework 1.1 French Language Pack-->MsiExec.exe /X{9A394342-4A68-4EBA-85A6-55B559F4E700}
        Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
        Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
        Microsoft Office 2000 SR-1 Premium-->MsiExec.exe /I{0000040C-78E1-11D2-B60F-006097C998E7}
        Mise à jour de sécurité pour Lecteur Windows Media (KB911564)-->"C:\WINDOWS\$NtUninstallKB911564$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Lecteur Windows Media 10 (KB917734)-->"C:\WINDOWS\$NtUninstallKB917734_WMP10$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Lecteur Windows Media 8 (KB917734)-->"C:\WINDOWS\$NtUninstallKB917734_WMP8$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB890046)-->"C:\WINDOWS\$NtUninstallKB890046$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB893756)-->"C:\WINDOWS\$NtUninstallKB893756$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB896358)-->"C:\WINDOWS\$NtUninstallKB896358$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB896423)-->"C:\WINDOWS\$NtUninstallKB896423$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB896424)-->"C:\WINDOWS\$NtUninstallKB896424$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB896428)-->"C:\WINDOWS\$NtUninstallKB896428$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB899587)-->"C:\WINDOWS\$NtUninstallKB899587$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB899591)-->"C:\WINDOWS\$NtUninstallKB899591$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB900725)-->"C:\WINDOWS\$NtUninstallKB900725$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB901017)-->"C:\WINDOWS\$NtUninstallKB901017$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB901214)-->"C:\WINDOWS\$NtUninstallKB901214$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB902400)-->"C:\WINDOWS\$NtUninstallKB902400$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB905414)-->"C:\WINDOWS\$NtUninstallKB905414$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB905495)-->"C:\WINDOWS\$NtUninstallKB905495$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB905749)-->"C:\WINDOWS\$NtUninstallKB905749$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB908519)-->"C:\WINDOWS\$NtUninstallKB908519$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB911562)-->"C:\WINDOWS\$NtUninstallKB911562$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB911927)-->"C:\WINDOWS\$NtUninstallKB911927$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB912919)-->"C:\WINDOWS\$NtUninstallKB912919$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB913580)-->"C:\WINDOWS\$NtUninstallKB913580$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB914388)-->"C:\WINDOWS\$NtUninstallKB914388$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB914389)-->"C:\WINDOWS\$NtUninstallKB914389$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB917344)-->"C:\WINDOWS\$NtUninstallKB917344$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB917422)-->"C:\WINDOWS\$NtUninstallKB917422$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB917953)-->"C:\WINDOWS\$NtUninstallKB917953$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB919007)-->"C:\WINDOWS\$NtUninstallKB919007$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB920670)-->"C:\WINDOWS\$NtUninstallKB920670$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB920683)-->"C:\WINDOWS\$NtUninstallKB920683$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB920685)-->"C:\WINDOWS\$NtUninstallKB920685$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB921398)-->"C:\WINDOWS\$NtUninstallKB921398$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB921883)-->"C:\WINDOWS\$NtUninstallKB921883$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB922616)-->"C:\WINDOWS\$NtUninstallKB922616$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB922819)-->"C:\WINDOWS\$NtUninstallKB922819$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB923191)-->"C:\WINDOWS\$NtUninstallKB923191$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB923414)-->"C:\WINDOWS\$NtUninstallKB923414$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB924191)-->"C:\WINDOWS\$NtUninstallKB924191$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB924496)-->"C:\WINDOWS\$NtUninstallKB924496$\spuninst\spuninst.exe"
        Mise à jour pour Windows XP (KB835409)-->"C:\WINDOWS\$NtUninstallKB835409$\spuninst\spuninst.exe"
        Mise à jour pour Windows XP (KB898461)-->"C:\WINDOWS\$NtUninstallKB898461$\spuninst\spuninst.exe"
        Mise à jour pour Windows XP (KB908531)-->"C:\WINDOWS\$NtUninstallKB908531$\spuninst\spuninst.exe"
        Mise à jour pour Windows XP (KB910437)-->"C:\WINDOWS\$NtUninstallKB910437$\spuninst\spuninst.exe"
        Mise à jour pour Windows XP (KB911280)-->"C:\WINDOWS\$NtUninstallKB911280$\spuninst\spuninst.exe"
        MSI Live Update 3-->C:\WINDOWS\IsUninst.exe -f"C:\Program Files\MSI\Live Update 3\Uninst.isu"
        MSXML4 Parser-->MsiExec.exe /I{01501EBA-EC35-4F9F-8889-3BE346E5DA13}
        Navigation par onglets (Windows Live Toolbar)-->MsiExec.exe /X{E74559C2-BB47-45AD-83DD-0D66B67E7811}
        Nero - Burning Rom-->MsiExec.exe /X{A4D7B764-4140-11D4-88EB-0050DA3579C0}
        Nokia Connectivity Cable Driver-->MsiExec.exe /X{6882DD11-33B8-4DEA-8305-7E765BF74BD3}
        Nokia Lifeblog 2.1-->MsiExec.exe /I{EE565795-2776-415A-B31C-EB3A8D7C6FA4}
        Nokia MTP driver-->MsiExec.exe /I{59359B3D-ABE7-46BF-AB55-43B67A64DC68}
        Nokia N73 highlights-->MsiExec.exe /I{02B71D92-A84B-4DFB-9A10-D12BB01AC1F2}
        Nokia Nseries Skin for Microsoft Windows Media Player-->MsiExec.exe /I{73E30715-9EC4-4DAE-BE67-64500AEB8012}
        Nokia PC Suite-->MsiExec.exe /I{531317A5-586A-4E36-87C1-CA823447B375}
        Nokia themes for your device-->MsiExec.exe /I{77F5816C-64A6-4FBE-BBE5-52EFE5EB84E8}
        NVIDIA Drivers-->C:\WINDOWS\system32\nvuenet.exe UninstallGUI
        NVIDIA Ethernet Driver-->C:\WINDOWS\System32\nvuenet.exe Uninstall C:\WINDOWS\System32\Nvenet.nvu,NVIDIA Ethernet Driver
        OneCare Advisor (Windows Live Toolbar)-->MsiExec.exe /X{F242B06B-517F-4D62-B654-16B11564A912}
        Orange - Logiciels Internet-->C:\Program Files\OrangeHSS\installation\core\Installgui.exe -u
        Pack réseau avancé pour Windows XP-->C:\WINDOWS\$NtUninstallKB817778$\spuninst\spuninst.exe
        Package de base Microsoft de service de chiffrement pour cartes à puce-->"C:\WINDOWS\$NtUninstallbasecsp$\spuninst\spuninst.exe"
        PC Antispyware 2010-->C:\Program Files\PC_Antispyware2010\Uninstall.exe
        PC Connectivity Solution-->MsiExec.exe /I{99A40651-0BC2-4095-8F9A-A40FAB224FEF}
        Programme de gestion Camera de Logitech®-->"C:\Program Files\Fichiers communs\Logitech\QCDRV\BIN\SETUP.EXE" UNINSTALL REMOVEPROMPT
        QuickTime-->MsiExec.exe /I{95A890AA-B3B1-44B6-9C18-A8F7AB3EE7FC}
        Realtek AC'97 Audio-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FB08F381-6533-4108-B7DD-039E11FBC27E}\Setup.exe" -l0x40c -removeonly
        Revo Uninstaller 1.30-->C:\Program Files\VS Revo Group\Revo Uninstaller\uninst.exe
        SA30xx Device Manager-->C:\Program Files\InstallShield Installation Information\{289CDCBA-1E82-460A-9DCA-E9FB6BAC1A42}\setup.exe -runfromtemp -l0x040c -removeonly
        SA30xx Media Converter-->C:\Program Files\InstallShield Installation Information\{1E06D48E-5448-4BCC-9F87-9FB4EBD59898}\setup.exe -runfromtemp -l0x040c -removeonly
        Sunbelt Kerio Personal Firewall-->MsiExec.exe /X{E659E0EE-10E6-49B7-8696-60F38D0EB174}
        USB Flash Disk-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{EDFEDAEF-95AA-11D7-A949-5254AB1235E1}\Setup.exe" -l0x9
        Windows Driver Package - Nokia Modem (06/12/2006 6.81.0.21)-->C:\PROGRA~1\DIFX\D6ACC4BE676423A2B130B78A4B627FC457D98997\dpinst.exe /u C:\WINDOWS\System32\DRVSTORE\nokbtmdm_62A340731F8930057B44B8864F236850B0D49D65\nokbtmdm.inf
        Windows Installer 3.1 (KB893803)-->"C:\WINDOWS\$MSI31Uninstall_KB893803v2$\spuninst\spuninst.exe"
        Windows Live Favorites pour Windows Live Toolbar-->MsiExec.exe /X{DCE65B11-710D-4C54-9DE5-1A6A0BD2186B}
        Windows Live Messenger-->MsiExec.exe /I{F6326B60-1B1D-4ABF-BFCD-7B7404F44411}
        Windows Live Sign-in Assistant-->MsiExec.exe /I{49672EC2-171B-47B4-8CE7-50D7806360D7}
        Windows Live Toolbar-->"C:\Program Files\Windows Live Toolbar\UnInstall.exe" {05AE605F-3146-46ED-BC52-0A14EBF57962}
        Windows Live Toolbar-->MsiExec.exe /X{05AE605F-3146-46ED-BC52-0A14EBF57962}
        Windows Media Format Runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
        Windows Media Format SDK Hotfix - KB891122-->"C:\WINDOWS\$NtUninstallKB891122$\spuninst\spuninst.exe"

        ======System event log======

        Computer Name: FIZERO
        Event Code: 10005
        Message: DCOM a reçu l'erreur "%1058" lors de la mise en route du service wuauserv avec les arguments ""
        pour démarrer le serveur :
        {E60687F7-01A1-40AA-86AC-DB1CBF673334}

        Record Number: 38131
        Source Name: DCOM
        Time Written: 20090718112700.000000+120
        Event Type: erreur
        User: AUTORITE NT\SYSTEM

        Computer Name: FIZERO
        Event Code: 10005
        Message: DCOM a reçu l'erreur "%1058" lors de la mise en route du service wuauserv avec les arguments ""
        pour démarrer le serveur :
        {E60687F7-01A1-40AA-86AC-DB1CBF673334}

        Record Number: 38130
        Source Name: DCOM
        Time Written: 20090718102700.000000+120
        Event Type: erreur
        User: AUTORITE NT\SYSTEM

        Computer Name: FIZERO
        Event Code: 10005
        Message: DCOM a reçu l'erreur "%1058" lors de la mise en route du service wuauserv avec les arguments ""
        pour démarrer le serveur :
        {E60687F7-01A1-40AA-86AC-DB1CBF673334}

        Record Number: 38129
        Source Name: DCOM
        Time Written: 20090718092700.000000+120
        Event Type: erreur
        User: AUTORITE NT\SYSTEM

        Computer Name: FIZERO
        Event Code: 10005
        Message: DCOM a reçu l'erreur "%1058" lors de la mise en route du service wuauserv avec les arguments ""
        pour démarrer le serveur :
        {E60687F7-01A1-40AA-86AC-DB1CBF673334}

        Record Number: 38128
        Source Name: DCOM
        Time Written: 20090718082700.000000+120
        Event Type: erreur
        User: AUTORITE NT\SYSTEM

        Computer Name: FIZERO
        Event Code: 10005
        Message: DCOM a reçu l'erreur "%1058" lors de la mise en route du service wuauserv avec les arguments ""
        pour démarrer le serveur :
        {E60687F7-01A1-40AA-86AC-DB1CBF673334}

        Record Number: 38127
        Source Name: DCOM
        Time Written: 20090718072700.000000+120
        Event Type: erreur
        User: AUTORITE NT\SYSTEM

        =====Application event log=====

        Computer Name: FIZERO
        Event Code: 12001
        Message: The Messenger Sharing USN Journal Reader service started successfully.

        Record Number: 5985
        Source Name: usnjsvc
        Time Written: 20090305174745.000000+060
        Event Type:
        User:

        Computer Name: FIZERO
        Event Code: 1015
        Message: Le délai d'exécution de la fonction "PerfProc" de collecte de données de
        performance dans la bibliothèque "C:\WINDOWS\system32\perfproc.dll" a expiré. Il y a peut-être un
        problème pour ce compteur extensible ou le service dont il tire ses
        informations, ou le système était peut-être très occupé au moment où
        l'appel a été tenté.

        Record Number: 5984
        Source Name: Perflib
        Time Written: 20090305174644.000000+060
        Event Type: erreur
        User:

        Computer Name: FIZERO
        Event Code: 2002
        Message: La procédure d'ouverture du service "WmiApRpl" dans la bibliothèque "C:\WINDOWS\System32\wbem\wmiaprpl.dll" a
        pris plus longtemps que le délai imparti pour cette opération. Il y a
        peut-être un problème pour ce compteur extensible ou le service dont il
        tire ses informations, ou le système était peut-être très occupé au moment
        où l'appel a été tenté.

        Record Number: 5983
        Source Name: Perflib
        Time Written: 20090305174619.000000+060
        Event Type: erreur
        User:

        Computer Name: FIZERO
        Event Code: 1015
        Message: Le délai d'exécution de la fonction "Spooler" de collecte de données de
        performance dans la bibliothèque "C:\WINDOWS\System32\winspool.drv" a expiré. Il y a peut-être un
        problème pour ce compteur extensible ou le service dont il tire ses
        informations, ou le système était peut-être très occupé au moment où
        l'appel a été tenté.

        Record Number: 5982
        Source Name: Perflib
        Time Written: 20090305174606.000000+060
        Event Type: erreur
        User:

        Computer Name: FIZERO
        Event Code: 0
        Message:
        Record Number: 5981
        Source Name: McciCMService
        Time Written: 20090305174600.000000+060
        Event Type: Informations
        User:

        ======Environment variables======

        "ComSpec"=%SystemRoot%\system32\cmd.exe
        "Path"=C:\Program Files\PC Connectivity Solution\;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\QuickTime\QTSystem\
        "windir"=%SystemRoot%
        "OS"=Windows_NT
        "PROCESSOR_ARCHITECTURE"=x86
        "PROCESSOR_LEVEL"=15
        "PROCESSOR_IDENTIFIER"=x86 Family 15 Model 44 Stepping 2, AuthenticAMD
        "PROCESSOR_REVISION"=2c02
        "NUMBER_OF_PROCESSORS"=1
        "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
        "TEMP"=%SystemRoot%\TEMP
        "TMP"=%SystemRoot%\TEMP
        "CLASSPATH"=.;C:\Program Files\QuickTime\QTSystem\QTJava.zip
        "QTJAVA"=C:\Program Files\QuickTime\QTSystem\QTJava.zip

        -----------------EOF-----------------

        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\Ati2evxx.exe
        C:\WINDOWS\System32\sdra64.exe
        C:\WINDOWS\Explorer.EXE
        C:\WINDOWS\system32\spoolsv.exe
        C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
        C:\Program Files\MSI\Live Update 3\LMonitor.exe
        C:\WINDOWS\SOUNDMAN.EXE
        C:\WINDOWS\System32\LVCOMSX.EXE
        C:\Program Files\Logitech\Video\LogiTray.exe
        C:\Program Files\Orange\LiveAssistant.exe
        C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
        C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE
        C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe
        C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
        C:\Program Files\rkfree\rkfree.exe
        C:\Program Files\PC_Antispyware2010\PC_Antispyware2010.exe
        C:\WINDOWS\System32\reader_s.exe
        C:\Program Files\OrangeHSS\Launcher\Launcher.exe
        C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe
        C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
        C:\Documents and Settings\M\reader_s.exe
        C:\documents and settings\m\local settings\application data\ofgmnuee.exe
        C:\Program Files\Logitech\Video\FxSvr2.exe
        C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe
        C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
        C:\PROGRA~1\FICHIE~1\Nokia\MPAPI\MPAPI3s.exe
        C:\Program Files\Orange\NavigateurLiveAssistant.exe
        C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
        C:\Program Files\Java\jre6\bin\jqs.exe
        C:\Program Files\Fichiers communs\Motive\McciCMService.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
        C:\Program Files\OrangeHSS\systray\systrayapp.exe
        C:\Program Files\OrangeHSS\Deskboard\deskboard.exe
        C:\Program Files\OrangeHSS\connectivity\connectivitymanager.exe
        C:\Program Files\OrangeHSS\connectivity\CoreCom\CoreCom.exe
        C:\Program Files\OrangeHSS\connectivity\CoreCom\OraConfigRecover.exe
        C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTCOMModule\0\FTCOMModule.exe
        C:\Program Files\OrangeHSS\browser\browser.exe
        C:\Program Files\Orange\NavigateurLiveAssistant.exe
        C:\Documents and Settings\M\Local Settings\Temporary Internet Files\Content.IE5\VZOSZISQ\RSIT[1].exe
        C:\Program Files\trend micro\M.exe

        R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
        R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\OrangeHSS\SearchURLHook\SearchPageURL.dll
        F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\System32\sdra64.exe,
        O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
        O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
        O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
        O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
        O4 - HKLM\..\Run: [LiveMonitor] C:\Program Files\MSI\Live Update 3\LMonitor.exe
        O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
        O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
        O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\System32\LVCOMSX.EXE
        O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
        O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
        O4 - HKLM\..\Run: [ORAHSSSessionManager] C:\Program Files\OrangeHSS\SessionManager\SessionManager.exe
        O4 - HKLM\..\Run: [Orange_McciTrayApp] C:\Program Files\Orange\LiveAssistant.exe
        O4 - HKLM\..\Run: [70d751cd] rundll32.exe "C:\WINDOWS\System32\vtdpdpep.dll",b
        O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
        O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
        O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup
        O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe"
        O4 - HKLM\..\Run: [rkfree] "C:\Program Files\rkfree\rkfree.exe" /b
        O4 - HKLM\..\Run: [PC Antispyware 2010] "C:\Program Files\PC_Antispyware2010\PC_Antispyware2010.exe" /hide
        O4 - HKLM\..\Run: [reader_s] C:\WINDOWS\System32\reader_s.exe
        O4 - HKLM\..\Run: [braviax] braviax.exe
        O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
        O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
        O4 - HKCU\..\Run: [EPSON Stylus DX6000 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBIE.EXE /FU "C:\WINDOWS\TEMP\E_S95.tmp" /EF "HKCU"
        O4 - HKCU\..\Run: [Orange_Install] "C:\DOCUME~1\M\LOCALS~1\Temp\KIT2.tmp\Installation\Tempcomponents\LIVEASSISTANT\Live Assistant 2.0.exe"
        O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
        O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
        O4 - HKCU\..\Run: [braviax] ƒ
        O4 - HKCU\..\Run: [reader_s] C:\Documents and Settings\M\reader_s.exe
        O4 - HKCU\..\Run: [ofgmnuee] "c:\documents and settings\m\local settings\application data\ofgmnuee.exe" ofgmnuee
        O4 - HKCU\..\RunOnce: [Shockwave Updater] C:\WINDOWS\system32\Adobe\SHOCKW~1\SWHELP~2.EXE -Update -1100465 -"Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; Orange 8.0; NaviWoo2.0; .NET CLR 1.1.4322)" -"http://www8.agame.com/..."
        O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
        O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
        O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
        O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
        O4 - Startup: dfqupd32.exe
        O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
        O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
        O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
        O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?8c4b13925d1f493f825a604478a29d6c
        O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?8c4b13925d1f493f825a604478a29d6c
        O8 - Extra context menu item: Translate this web page with Babylon - res://C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/ActionTU.htm
        O8 - Extra context menu item: Translate with Babylon - res://C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Action.htm
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
        O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
        O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
        O15 - Trusted Zone: http://pfttbc.ft.motive.com
        O15 - Trusted Zone: http://*.orange.fr
        O15 - Trusted Zone: http://rw.search.ke.voila.fr
        O15 - Trusted Zone: http://orange.weborama.fr
        O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} (DjVuCtl Class) - http://www.lizardtech.com/download/files/win/djvuplugin/en_US/DjVuControl_en_US.cab
        O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
        O16 - DPF: {8167C273-DF59-4416-B647-C8BB2C7EE83E} (WebSDev Control) - http://liveupdate.msi.com.tw/autobios/LOnline/install.cab
        O17 - HKLM\System\CCS\Services\Tcpip\..\{F99B4C81-5CC1-4C14-9CA4-917D8CC03323}: NameServer = 212.27.32.176
        O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
        O20 - AppInit_DLLs: C:\WINDOWS\system32\cru629.dat
        O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
        O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
        O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
        O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
        O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
        O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
        O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
        O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
        O23 - Service: Sunbelt Kerio Personal Firewall 4 (KPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
        O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Fichiers communs\Motive\McciCMService.exe
        O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
    3. Contributeur sécurité
      Télécharge SDFix (créé par AndyManchesta) et sauvegarde le sur ton Bureau.

      Une fois sauvegardé sur ton bureau, double clique sur SDFix.exe et choisis Install pour l’extraire dans un dossier dédié sur le Bureau.

      Redémarre ton ordinateur en mode sans échec en suivant la procédure que voici :
      * Redémarre ton ordinateur
      * Après avoir entendu l’ordinateur biper lors du démarrage, mais avant que l’icône Windows apparaisse, tapote la touche F8 (une pression par seconde).
      * A la place du chargement normal de Windows, un menu avec différentes options devrait apparaître.
      * Choisis la première option, pour exécuter Windows en mode sans échec, puis appuie sur "Entrée".
      * Choisis ton compte.

      Déroule la liste des instructions ci-dessous :
      * Ouvre le dossier SDFix qui vient d’être créé dans le répertoire C:\ et double clique sur RunThis.bat pour lancer le script.
      * Appuie sur Y pour commencer le processus de nettoyage.
      * Il va supprimer les services et les entrées du Registre de certains trojans trouvés puis te demandera d’appuyer sur une touche pour redémarrer.
      * Appuie sur une touche pour redémarrer le PC.

      * Ton système sera plus long pour redémarrer qu’à l’accoutumée car l’outil va continuer à s’exécuter et supprimer des fichiers.
      * Après le chargement du Bureau, l’outil terminera son travail et affichera Finished.
      * Appuie sur une touche pour finir l’exécution du script et charger les icônes de ton Bureau.
      * Les icônes du Bureau affichées, le rapport SDFix s’ouvrira à l’écran et s’enregistrera aussi dans le dossier SDFix sous le nom Report.txt.

      • Enfin, copie/colle le contenu du fichier Report.txt dans ta prochaine réponse sur le forum

      TUTO Si besoin

      Si SDfix ne se lance pas (ça arrive!)

      * Démarrer->Exécuter

      * Copie/colle ceci :

      %systemroot%\system32\cmd.exe /K %systemdrive%\SDFix\apps\FixPath.exe

      * Clique sur ok, et valide.

      * Redémarre et essaye de nouveau de lancer SDfix.

      1. [b]SDFix: Version 1.240 [/b]
        Run by M on 06/09/2009 at 18:43

        Microsoft Windows XP [version 5.1.2600]
        Running From: C:\SDFix

        [b]Checking Services [/b]:

        Restoring Default Security Values
        Restoring Default Hosts File
        Resetting AppInit_DLLs value

        Rebooting

        [b]Infected beep.sys Found![/b]

        beep.sys File Locations:

        "C:\WINDOWS\system32\dllcache\beep.sys" 29184 05/09/2009 22:15
        "C:\WINDOWS\system32\drivers\beep.sys" 29184 05/09/2009 22:15

        Infected File Listed Below:

        C:\WINDOWS\system32\dllcache\beep.sys
        C:\WINDOWS\system32\drivers\beep.sys

        File copied to Backups Folder
        Attempting to replace beep.sys with original version

        Original beep.sys Restored

        "C:\WINDOWS\system32\dllcache\beep.sys" 4224 07/08/2008 15:27
        "C:\WINDOWS\system32\drivers\beep.sys" 4224 07/08/2008 15:27

        [b]Checking Files [/b]:

        Trojan Files Found:

        C:\DOCUME~1\M\COOKIES\WYVURI._DL - Deleted
        C:\DOCUME~1\M\COOKIES\FUWIZU~1.LIB - Deleted
        C:\DOCUME~1\M\COOKIES\EPIGOR.SYS - Deleted
        C:\Program Files\Fichiers communs\vorapevi.scr - Deleted
        C:\WINDOWS\braviax.exe - Deleted
        C:\WINDOWS\cru629.dat - Deleted
        C:\WINDOWS\pskt.ini - Deleted
        C:\WINDOWS\system32\_scui.cpl - Deleted
        C:\WINDOWS\system32\braviax.exe - Deleted

        Could Not Remove C:\WINDOWS\system32\cru629.dat

        Removing Temp Files

        [b]ADS Check [/b]:

        [b]Final Check [/b]:

        catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
        Rootkit scan 2009-09-06 18:55:05
        Windows 5.1.2600 Service Pack 1 NTFS

        scanning hidden processes ...

        IPC error: 2 Le fichier spécifié est introuvable.
        scanning hidden services & system hive ...

        scanning hidden registry entries ...

        scanning hidden files ...

        scan completed successfully
        hidden processes: 0
        hidden services: 0
        hidden files: 0

        [b]Remaining Services [/b]:

        Authorized Application Key Export:

        [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
        "C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"="C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger"
        "C:\\Program Files\\OrangeHSS\\Connectivity\\ConnectivityManager.exe"="C:\\Program Files\\OrangeHSS\\Connectivity\\ConnectivityManager.exe:*:enabled:CSS"

        [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
        "C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"="C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger"

        [b]Remaining Files [/b]:

        C:\WINDOWS\system32\cru629.dat Found

        File Backups: - C:\SDFix\backups\backups.zip

        [b]Files with Hidden Attributes [/b]:

        Sat 11 Aug 2007 4,348 A.SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
        Sat 11 Aug 2007 400 A.SH. --- "C:\Documents and Settings\All Users\DRM\v2ks.bla.bak"
        Sat 11 Aug 2007 48 A.SH. --- "C:\Documents and Settings\All Users\DRM\v2ks.sec.bak"
        Sat 11 Aug 2007 4,348 ...H. --- "C:\Documents and Settings\M\Mes documents\Ma musique\Sauvegarde de la licence\drmv1key.bak"
        Sat 13 Oct 2007 20 A..H. --- "C:\Documents and Settings\M\Mes documents\Ma musique\Sauvegarde de la licence\drmv1lic.bak"
        Sat 11 Aug 2007 400 A.SH. --- "C:\Documents and Settings\M\Mes documents\Ma musique\Sauvegarde de la licence\drmv2key.bak"

        [b]Finished![/b]
    4. Contributeur sécurité

      /!\ Désactive tous tes logiciels de protection /!\


      • Télécharge (de sUBs) ComboFix sur ton Bureau.
      • Fais un clic-droit sur ComboFix.exe ( pour vista : choisis "Exécuter en temps qu'administrateur".
      • Ne touche à rien pendant le scan.
      • Lorsque la recherche sera terminée, un rapport apparaîtra. Poste ce rapport (C:\Combofix.txt) dans ta prochaine réponse.

      Tutoriel officiel de Combofix

      1. desole pour la lenteur de ma reponse mé mon ordi na céssé de planté!

        ComboFix 09-09-06.02 - M 06/09/2009 20:30.2.1 - NTFSx86
        Microsoft Windows XP Édition familiale 5.1.2600.1.1252.33.1036.18.511.190 [GMT 2:00]
        Running from: c:\documents and settings\M\Bureau\ComboFix.exe
        FW: Sunbelt Kerio Personal Firewall *enabled* {E659E0EE-10E6-49B7-8696-60F38D0EB174}

        WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
        .

        ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
        .

        c:\windows\system32\braviax.exe
        c:\windows\system32\dllcache\beep.sys
        c:\windows\system32\dllcache\figaro.sys
        c:\windows\system32\lowsec
        c:\windows\system32\lowsec\local.ds
        c:\windows\system32\lowsec\user.ds
        c:\windows\system32\sdra64.exe
        .
        ---- Previous Run -------
        .
        c:\documents and settings\All Users\Application Data\acipyly.exe
        c:\documents and settings\All Users\Application Data\icizip.ban
        c:\documents and settings\All Users\Application Data\jejetigyk.lib
        c:\documents and settings\All Users\Application Data\onigigaw.reg
        c:\documents and settings\All Users\Application Data\opacorawy.inf
        c:\documents and settings\All Users\Application Data\pepoti.inf
        c:\documents and settings\All Users\Application Data\yvejoru.vbs
        c:\documents and settings\All Users\Documents\axutilewe.sys
        c:\documents and settings\All Users\Documents\feduz.inf
        c:\documents and settings\All Users\Documents\iruvoreqa.bin
        c:\documents and settings\All Users\Documents\syvema.inf
        c:\documents and settings\All Users\Documents\tusaq.com
        c:\documents and settings\All Users\Documents\wora.dl
        c:\documents and settings\M\Application Data\alonapytub.bin
        c:\documents and settings\M\Application Data\bowus.dl
        c:\documents and settings\M\Application Data\Microsoft\Internet Explorer\Quick Launch\PC_Antispyware2010.lnk
        c:\documents and settings\M\Application Data\osewigoj.reg
        c:\documents and settings\M\Application Data\wiaservg.log
        c:\documents and settings\M\Application Data\ycybacyby.dl
        c:\documents and settings\M\Cookies\rywujohiru.bat
        c:\documents and settings\M\Cookies\ynelyjole.com
        c:\documents and settings\M\Local Settings\Application Data\agehi.pif
        c:\documents and settings\M\Local Settings\Application Data\ajicudyf.sys
        c:\documents and settings\M\Local Settings\Application Data\kynopy.inf
        c:\documents and settings\M\Local Settings\Application Data\ofgmnuee.dat
        c:\documents and settings\M\Local Settings\Application Data\ofgmnuee.exe
        c:\documents and settings\M\Local Settings\Application Data\ofgmnuee_nav.dat
        c:\documents and settings\M\Local Settings\Application Data\ofgmnuee_navps.dat
        c:\documents and settings\M\Local Settings\Application Data\onuqysudi.reg
        c:\documents and settings\M\Local Settings\Application Data\xehu.dll
        c:\documents and settings\M\Local Settings\Application Data\ykijyb.sys
        c:\documents and settings\M\Local Settings\Application Data\yzojyjafar.dl
        c:\documents and settings\M\Local Settings\Temporary Internet Files\ajel.scr
        c:\documents and settings\M\Local Settings\Temporary Internet Files\ivojexocir.ban
        c:\documents and settings\M\Local Settings\Temporary Internet Files\lehygoq.inf
        c:\documents and settings\M\Local Settings\Temporary Internet Files\otuvy.dll
        c:\documents and settings\M\Local Settings\Temporary Internet Files\ydynunol.pif
        c:\documents and settings\M\reader_s.exe
        c:\program files\Fichiers communs\abahala.reg
        c:\program files\Fichiers communs\acavekeg.reg
        c:\program files\Fichiers communs\bezovexix.vbs
        c:\program files\Fichiers communs\epadulamuz.sys
        c:\program files\Fichiers communs\hawuw.com
        c:\program files\Fichiers communs\neqat.bat
        c:\program files\Fichiers communs\niliqozo.dl
        c:\program files\Fichiers communs\nimep.com
        c:\program files\Fichiers communs\riko.dl
        c:\program files\Fichiers communs\romu.vbs
        c:\program files\PC_Antispyware2010\AVEngn.dll
        c:\program files\PC_Antispyware2010\data\daily.cvd
        c:\program files\PC_Antispyware2010\htmlayout.dll
        c:\program files\PC_Antispyware2010\Microsoft.VC80.CRT\Microsoft.VC80.CRT.manifest
        c:\program files\PC_Antispyware2010\Microsoft.VC80.CRT\msvcm80.dll
        c:\program files\PC_Antispyware2010\Microsoft.VC80.CRT\msvcp80.dll
        c:\program files\PC_Antispyware2010\Microsoft.VC80.CRT\msvcr80.dll
        c:\program files\PC_Antispyware2010\PC_Antispyware2010.cfg
        c:\program files\PC_Antispyware2010\PC_Antispyware2010.exe
        c:\program files\PC_Antispyware2010\pthreadVC2.dll
        c:\program files\PC_Antispyware2010\Uninstall.exe
        c:\program files\PC_Antispyware2010\wscui.cpl
        c:\windows\aloqijol.bin
        c:\windows\BM73e46251.txt
        c:\windows\BM73e46251.xml
        c:\windows\bonabolyz.vbs
        c:\windows\cookies.ini
        c:\windows\dalyg._dl
        c:\windows\egogehukid.sys
        c:\windows\epod.bin
        c:\windows\puduhege.exe
        c:\windows\puguvuho.bat
        c:\windows\rojig.bat
        c:\windows\rylihan.vbs
        c:\windows\system\oeminfo.ini
        c:\windows\system32\aomvjwbu.ini
        c:\windows\system32\cru629.dat
        c:\windows\system32\drivers\ntndis.sys
        c:\windows\system32\eijutklm.ini
        c:\windows\system32\fomodiv.pif
        c:\windows\system32\ghkmp.ini
        c:\windows\system32\ghkmp.ini2
        c:\windows\system32\hlprpdag.ini
        c:\windows\system32\kmthdjif.dll
        c:\windows\system32\lkahddow.ini
        c:\windows\system32\loedckdd.ini
        c:\windows\system32\lowsec\local.ds
        c:\windows\system32\lowsec\user.ds
        c:\windows\system32\mehdmyuj.ini
        c:\windows\system32\mertdboy.ini
        c:\windows\system32\mhwdywwb.ini
        c:\windows\system32\mstfpplf.ini
        c:\windows\system32\msuugiji.ini
        c:\windows\system32\mxrsjeie.dll
        c:\windows\system32\omgivyno.ini
        c:\windows\system32\oqtwa.ini
        c:\windows\system32\oqtwa.ini2
        c:\windows\system32\ovlxdqib.ini
        c:\windows\system32\qkgbyrae.ini
        c:\windows\system32\reader_s.exe
        c:\windows\system32\rnurovue.dll
        c:\windows\system32\sbgsmqnd.dll
        c:\windows\system32\sdra64.exe
        c:\windows\system32\tkjuohne.dll
        c:\windows\system32\tmp.reg
        c:\windows\system32\ujiywhcp.dll
        c:\windows\system32\verunabaso.scr
        c:\windows\system32\wbem\proquota.exe
        c:\windows\system32\wisdstr.exe
        c:\windows\system32\wjgmebrs.dll
        c:\windows\system32\xlgcnesa.dll
        c:\windows\system32\xmfinhwn.ini
        c:\windows\system32\xscoymdu.ini
        c:\windows\system32\yJiOnnnn.ini
        c:\windows\system32\yJiOnnnn.ini2
        c:\windows\system32\yusjkjhv.ini
        c:\windows\tymakom.ban
        c:\windows\uhurara.pif
        c:\windows\usuziqu.reg
        c:\windows\zekivy.sys
        C:\xcrashdump.dat

        c:\windows\system32\proquota.exe was missing
        Restored copy from - c:\system volume information\_restore{38A3208A-B97D-447D-8125-61BF3B0915B1}\RP517\A0064794.exe

        Infected copy of c:\windows\system32\drivers\beep.sys was found and disinfected
        Restored copy from - c:\system volume information\_restore{38A3208A-B97D-447D-8125-61BF3B0915B1}\RP521\A0065903.sys

        c:\windows\system32\proquota.exe was missing
        Restored copy from - c:\system volume information\_restore{38A3208A-B97D-447D-8125-61BF3B0915B1}\RP521\A0065905.exe

        .
        ((((((((((((((((((((((((( Files Created from 2009-08-06 to 2009-09-06 )))))))))))))))))))))))))))))))
        .

        2009-09-06 18:43 . 2009-09-06 18:43 191357 ----a-w- c:\windows\system32\wisdstr.exe
        2009-09-06 18:42 . 2009-09-06 18:42 -------- d-sh--w- c:\windows\system32\lowsec
        2009-09-06 18:42 . 2009-09-06 18:42 39424 ----a-w- c:\documents and settings\M\reader_s.exe
        2009-09-06 18:42 . 2009-09-06 18:42 39424 ----a-w- c:\windows\system32\reader_s.exe
        2009-09-06 18:38 . 2009-09-06 18:42 29184 ----a-w- c:\windows\system32\drivers\beep.sys
        2009-09-06 16:33 . 2009-09-06 16:33 -------- d-----w- c:\windows\ERUNT
        2009-09-06 16:20 . 2009-09-06 16:57 -------- d-----w- C:\SDFix
        2009-09-06 15:46 . 2009-09-06 15:48 -------- d-----w- C:\rsit
        2009-09-06 09:27 . 2009-09-06 09:27 14800 ----a-w- c:\windows\cajomezeho.dat
        2009-09-06 09:27 . 2009-09-06 09:27 17113 ----a-w- c:\windows\aturi.dat
        2009-09-06 09:27 . 2009-09-06 09:27 15467 ----a-w- c:\program files\Fichiers communs\ytyl.dat
        2009-09-05 21:32 . 2009-09-05 21:32 16367 ----a-w- c:\windows\zuxocazyh.com
        2009-09-01 17:08 . 2009-09-01 17:08 -------- d-----w- C:\CD_Permanent
        2009-08-22 17:35 . 2009-08-22 17:35 -------- d-----w- c:\documents and settings\M\Local Settings\Application Data\Google
        2009-08-16 17:09 . 2009-08-16 17:09 -------- d-----w- c:\documents and settings\All Users\Application Data\Trymedia
        2009-08-16 17:08 . 2009-08-16 17:08 -------- d-----w- c:\program files\BFG
        2009-08-11 18:18 . 2009-08-11 18:18 -------- d-----w- c:\documents and settings\All Users\Application Data\Zylom

        .
        (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
        .
        2009-09-06 16:32 . 2008-07-26 08:58 362 ----a-w- c:\windows\system32\drivers\fwdrv.err
        2009-09-06 15:47 . 2008-04-22 18:06 -------- d-----w- c:\program files\Trend Micro
        2009-09-06 09:27 . 2009-09-06 09:27 12315 ----a-w- c:\program files\Fichiers communs\upycu.lib
        2009-09-05 21:32 . 2009-09-05 21:32 13102 ----a-w- c:\program files\Fichiers communs\lygujuzi.lib
        2009-09-05 20:16 . 2007-08-10 20:03 168192 ----a-w- c:\windows\system32\drivers\ndis.sys
        2009-09-01 17:08 . 2003-08-12 20:08 -------- d--h--w- c:\program files\InstallShield Installation Information
        2009-07-17 00:46 . 2009-07-17 00:46 -------- d-----w- c:\program files\rkfree
        2009-07-17 00:46 . 2009-07-17 00:46 -------- d---a-w- c:\documents and settings\All Users\Application Data\rkfree
        1999-04-06 12:27 . 1999-04-06 12:27 99840 -c--a-w- c:\program files\Fichiers communs\IRAABOUT.DLL
        1998-12-09 02:53 . 1998-12-09 02:53 70144 -c--a-w- c:\program files\Fichiers communs\IRAMDMTR.DLL
        1998-12-09 02:53 . 1998-12-09 02:53 48640 -c--a-w- c:\program files\Fichiers communs\IRALPTTR.DLL
        1998-12-09 02:53 . 1998-12-09 02:53 31744 -c--a-w- c:\program files\Fichiers communs\IRAWEBTR.DLL
        1998-12-09 02:53 . 1998-12-09 02:53 186368 -c--a-w- c:\program files\Fichiers communs\IRAREG.DLL
        1998-12-09 02:53 . 1998-12-09 02:53 17920 -c--a-w- c:\program files\Fichiers communs\IRASRIAL.DLL
        .

        ------- Sigcheck -------

        [7] D999CE17681D7D074D534FC5BC662E0A [5.1.2600.1254 (xpsp2.030801-1834)] c:\windows\Driver Cache\i386\ndis.sys
        [-] D999CE17681D7D074D534FC5BC662E0A [5.1.2600.1254 (xpsp2.030801-1834)] c:\windows\LastGood\System32\DllCache\ndis.sys
        [-] D999CE17681D7D074D534FC5BC662E0A [5.1.2600.1254 (xpsp2.030801-1834)] c:\windows\LastGood\System32\DRIVERS\ndis.sys
        [-] D999CE17681D7D074D534FC5BC662E0A [5.1.2600.1254 (xpsp2.030801-1834)] c:\windows\system32\dllcache\ndis.sys
        [-] D999CE17681D7D074D534FC5BC662E0A [5.1.2600.1254 (xpsp2.030801-1834)] c:\windows\system32\drivers\ndis.sys

        [-] 87EC3D93642CBC76E7A28DFD25EE43B9 [------] c:\windows\system32\drivers\beep.sys

        c:\windows\system32\xmlprov.dll ... is missing !!
        .
        ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
        .
        .
        *Note* empty entries & legit default entries are not shown
        REGEDIT4

        [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
        "braviax"="²" [X]
        "LogitechSoftwareUpdate"="c:\program files\Logitech\Video\ManifestEngine.exe" [2005-06-08 196608]
        "MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
        "PcSync"="c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2006-06-27 1449984]
        "reader_s"="c:\documents and settings\M\reader_s.exe" [2009-09-06 39424]

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
        "braviax"="²" [X]
        "LiveMonitor"="c:\program files\MSI\Live Update 3\LMonitor.exe" [2007-01-17 496640]
        "ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 45056]
        "LVCOMSX"="c:\windows\System32\LVCOMSX.EXE" [2005-07-19 221184]
        "LogitechVideoRepair"="c:\program files\Logitech\Video\ISStart.exe" [2005-06-08 458752]
        "LogitechVideoTray"="c:\program files\Logitech\Video\LogiTray.exe" [2005-06-08 217088]
        "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-06-29 286720]
        "ORAHSSSessionManager"="c:\program files\OrangeHSS\SessionManager\SessionManager.exe" [2008-01-22 107248]
        "Orange_McciTrayApp"="c:\program files\Orange\LiveAssistant.exe" [2007-12-21 1476608]
        "avgnt"="c:\program files\AntiVir PersonalEdition Classic\avgnt.exe" [2007-04-02 327720]
        "!AVG Anti-Spyware"="c:\program files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 6731312]
        "Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe" [2005-06-23 57344]
        "rkfree"="c:\program files\rkfree\rkfree.exe" [2009-07-17 71168]
        "PC Antispyware 2010"="c:\program files\PC_Antispyware2010\PC_Antispyware2010.exe" [2009-09-03 598797]
        "reader_s"="c:\windows\System32\reader_s.exe" [2009-09-06 39424]
        "SoundMan"="SOUNDMAN.EXE" - c:\windows\soundman.exe [2006-11-17 577536]

        [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
        "CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2003-04-24 13312]

        c:\documents and settings\M\Menu D‚marrer\Programmes\D‚marrage\
        dfqupd32.exe [1601-7-8 37888]

        c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
        Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2007-10-31 67128]

        [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
        "EnableProfileQuota"= 1 (0x1)

        [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
        "ForceClassicControlPanel"= 1 (0x1)

        [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
        "Userinit"="c:\windows\system32\userinit.exe,c:\windows\System32\sdra64.exe,"

        [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
        @="Service"

        [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AVG Anti-Spyware Guard]
        @="Service"

        [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^InterVideo WinCinema Manager.lnk]
        path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\InterVideo WinCinema Manager.lnk
        backup=c:\windows\pss\InterVideo WinCinema Manager.lnkCommon Startup

        [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Microsoft Office.lnk]
        path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Microsoft Office.lnk
        backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

        [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Symantec Fax Starter Edition Port.lnk]
        path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Symantec Fax Starter Edition Port.lnk
        backup=c:\windows\pss\Symantec Fax Starter Edition Port.lnkCommon Startup

        [HKEY_LOCAL_MACHINE\software\microsoft\security center]
        "AntiVirusDisableNotify"=dword:00000001
        "FirewallDisableNotify"=dword:00000001
        "UpdatesDisableNotify"=dword:00000001

        [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
        "EnableFirewall"= 0 (0x0)

        [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
        "c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
        "c:\\Program Files\\OrangeHSS\\Connectivity\\ConnectivityManager.exe"=

        R0 avgntmgr;avgntmgr;c:\windows\system32\drivers\avgntmgr.sys [23/04/2008 11:58 14848]
        R1 avgntdd;avgntdd;c:\windows\system32\drivers\avgntdd.sys [23/04/2008 11:58 40000]
        R1 fwdrv;Firewall Driver;c:\windows\system32\drivers\fwdrv.sys [16/03/2007 09:56 302000]
        R1 khips;Kerio HIPS Driver;c:\windows\system32\drivers\khips.sys [16/03/2007 09:56 72496]
        S3 Ip6FwHlp;Pare-feu de connexion Internet IPv6;c:\windows\System32\svchost.exe -k netsvcs [10/08/2007 22:03 12800]
        .
        Contents of the 'Scheduled Tasks' folder

        2009-09-06 c:\windows\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job
        - c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2006-09-27 15:39]
        .
        - - - - ORPHANS REMOVED - - - -

        HKCU-Run-LDM - c:\program files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
        HKCU-Run-ofgmnuee - c:\documents and settings\m\local settings\application data\ofgmnuee.exe
        HKLM-Run-70d751cd - c:\windows\System32\vtdpdpep.dll
        SafeBoot-AVG Anti-Spyware Driver

        .
        ------- Supplementary Scan -------
        .
        uSearch Page = hxxp://www.google.com
        uStart Page = hxxp://www.google.com
        uSearch Bar = hxxp://www.google.com/ie
        mDefault_Search_URL = hxxp://www.google.com/ie
        mSearch Page = hxxp://www.google.com
        mStart Page = hxxp://www.google.com
        uSearchURL,(Default) = hxxp://g.msn.fr/0SEFRFR/SAOS01?FORM=TOOLBR
        mSearchAssistant = hxxp://www.google.com
        IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
        IE: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
        IE: Ouvrir dans un nouvel onglet d'arrière-plan - c:\program files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?8c4b13925d1f493f825a604478a29d6c
        IE: Ouvrir dans un nouvel onglet de premier plan - c:\program files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?8c4b13925d1f493f825a604478a29d6c
        IE: Translate this web page with Babylon - c:\program files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/ActionTU.htm
        IE: Translate with Babylon - c:\program files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Action.htm
        Trusted Zone: 0.0.0.0
        Trusted Zone: motive.com\pfttbc.ft
        Trusted Zone: orange.fr
        Trusted Zone: voila.fr\rw.search.ke
        Trusted Zone: weborama.fr\orange
        TCP: {F99B4C81-5CC1-4C14-9CA4-917D8CC03323} = 212.27.32.176
        Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
        DPF: {8167C273-DF59-4416-B647-C8BB2C7EE83E} - hxxp://liveupdate.msi.com.tw/autobios/LOnline/install.cab
        .

        **************************************************************************

        catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
        Rootkit scan 2009-09-06 20:41
        Windows 5.1.2600 Service Pack 1 NTFS

        scanning hidden processes ...

        scanning hidden autostart entries ...

        scanning hidden files ...

        c:\windows\system32\sdra64.exe 266752 bytes executable
        c:\windows\system32\wisdstr.exe 191357 bytes executable
        c:\windows\system32\reader_s.exe 39424 bytes executable
        c:\windows\system32\lowsec

        scan completed successfully
        hidden files: 4

        **************************************************************************
        .
        --------------------- LOCKED REGISTRY KEYS ---------------------

        [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
        @Denied: (A 2) (Everyone)
        @="FlashBroker"
        "LocalizedString"="@c:\\WINDOWS\\System32\\Macromed\\Flash\\FlashUtil10c.exe,-101"

        [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
        "Enabled"=dword:00000001

        [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
        @="c:\\WINDOWS\\System32\\Macromed\\Flash\\FlashUtil10c.exe"

        [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
        @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

        [HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
        @Denied: (A 2) (Everyone)
        @="IFlashBroker3"

        [HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
        @="{00020424-0000-0000-C000-000000000046}"

        [HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
        @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
        "Version"="1.0"
        .
        --------------------- DLLs Loaded Under Running Processes ---------------------

        - - - - - - - > 'winlogon.exe'(564)
        c:\windows\system32\ODBC32.dll
        c:\windows\system32\Ati2evxx.dll

        - - - - - - - > 'lsass.exe'(624)
        c:\windows\System32\dssenh.dll
        .
        ------------------------ Other Running Processes ------------------------
        .
        c:\windows\system32\ati2evxx.exe
        c:\windows\system32\ati2evxx.exe
        c:\program files\AntiVir PersonalEdition Classic\avguard.exe
        c:\program files\Lavasoft\Ad-Aware 2007\aawservice.exe
        c:\program files\AntiVir PersonalEdition Classic\sched.exe
        c:\program files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
        c:\progra~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
        c:\program files\Java\jre6\bin\jqs.exe
        c:\program files\Sunbelt Software\Personal Firewall\kpf4ss.exe
        c:\program files\Fichiers communs\Motive\McciCMService.exe
        c:\windows\system32\wdfmgr.exe
        c:\program files\Sunbelt Software\Personal Firewall\kpf4gui.exe
        c:\progra~1\Nokia\NOKIAP~1\LAUNCH~1.EXE
        c:\program files\OrangeHSS\Launcher\Launcher.exe
        c:\program files\Sunbelt Software\Personal Firewall\kpf4gui.exe
        c:\program files\PC Connectivity Solution\ServiceLayer.exe
        c:\program files\Logitech\Video\FxSvr2.exe
        c:\progra~1\FICHIE~1\Nokia\MPAPI\MPAPI3s.exe
        c:\qoobox\Quarantine\C\WINDOWS\system32\braviax.exe.virtIcon
        c:\program files\MSN Messenger\usnsvc.exe
        c:\program files\OrangeHSS\Systray\SystrayApp.exe
        c:\program files\OrangeHSS\Deskboard\Deskboard.exe
        c:\program files\OrangeHSS\Connectivity\ConnectivityManager.exe
        c:\progra~1\FICHIE~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe
        c:\program files\OrangeHSS\Connectivity\corecom\CoreCom.exe
        c:\program files\OrangeHSS\Connectivity\corecom\OraConfigRecover.exe
        c:\progra~1\FICHIE~1\France Telecom\Shared Modules\FTCOMModule\0\FTCOMModule.exe
        c:\windows\system32\rundll32.exe
        .
        **************************************************************************
        .
        Completion time: 2009-09-06 20:51 - machine was rebooted
        ComboFix-quarantined-files.txt 2009-09-06 18:51

        Pre-Run: 14 203 662 336 octets libres
        Post-Run: 14 120 636 416 octets libres

        372 --- E O F --- 2008-03-16 16:50
    5. Contributeur sécurité
      * Télécharge OtmoveIT (de Old_Timer) sur ton Bureau

      (c est le numéro 7 en bas de la page) :

      * Double-clique sur OTMoveIt.exe pour le lancer.

      * Assure toi que la case Unregister Dll's and Ocx's soit bien cochée.

      * Copie la liste qui se trouve en gras dans la citation ci-dessous et colle-la dans le cadre de gauche de OTMoveIt sous Paste List of Files/Folders to move.


      :processes
      explorer.exe

      :services

      :files
      c:\windows\system32\wisdstr.exe
      c:\windows\system32\lowsec
      c:\documents and settings\M\reader_s.exe
      c:\windows\system32\reader_s.exe
      c:\windows\cajomezeho.dat
      c:\windows\aturi.dat
      c:\program files\Fichiers communs\ytyl.dat
      c:\windows\zuxocazyh.com
      c:\program files\rkfree
      c:\documents and settings\All Users\Application Data\rkfree

      :Commands
      [emptytemp]
      [purity]
      [start explorer]
      [Reboot]


      # clique sur MoveIt! pour lancer la suppression.

      # Le résultat apparaitra dans le cadre "Results".

      # Clique sur Exit pour fermer.

      # Poste le rapport situé dans C:\_OTMoveIt\MovedFiles.

      # Il te sera peut-être demandé de redémarrer le pc pour achever la suppression. Si c'est le cas accepte par Yes.

      1. All processes killed
        ========== PROCESSES ==========
        No active process named explorer.exe was found!
        ========== SERVICES/DRIVERS ==========
        ========== FILES ==========
        File/Folder c:\windows\system32\wisdstr.exe not found.
        File/Folder c:\windows\system32\lowsec not found.
        File/Folder c:\documents and settings\M\reader_s.exe not found.
        File/Folder c:\windows\system32\reader_s.exe not found.
        File/Folder c:\windows\cajomezeho.dat not found.
        File/Folder c:\windows\aturi.dat not found.
        File/Folder c:\program files\Fichiers communs\ytyl.dat not found.
        File/Folder c:\windows\zuxocazyh.com not found.
        File/Folder c:\program files\rkfree not found.
        File/Folder c:\documents and settings\All Users\Application Data\rkfree not found.
        ========== COMMANDS ==========

        [EMPTYTEMP]

        User: Administrateur
        ->Temp folder emptied: 0 bytes
        ->Temporary Internet Files folder emptied: 0 bytes

        User: All Users

        User: Default User
        ->Temp folder emptied: 0 bytes
        ->Temporary Internet Files folder emptied: 0 bytes

        User: LocalService
        ->Temp folder emptied: 0 bytes
        File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
        ->Temporary Internet Files folder emptied: 33170 bytes

        User: M
        ->Temp folder emptied: 313491 bytes
        File delete failed. C:\Documents and Settings\M\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
        ->Temporary Internet Files folder emptied: 1790622 bytes
        ->Java cache emptied: 0 bytes

        User: NetworkService
        ->Temp folder emptied: 0 bytes
        ->Temporary Internet Files folder emptied: 0 bytes

        %systemdrive% .tmp files removed: 0 bytes
        C:\WINDOWS\LastGood.Tmp\System32\Setup folder deleted successfully.
        C:\WINDOWS\LastGood.Tmp\System32\Macromed folder deleted successfully.
        File delete failed. C:\WINDOWS\LastGood.Tmp\System32\DRIVERS\ndis.sys scheduled to be deleted on reboot.
        Folder delete failed. C:\WINDOWS\LastGood.Tmp\System32\DRIVERS scheduled to be deleted on reboot.
        File delete failed. C:\WINDOWS\LastGood.Tmp\System32\DllCache\ndis.sys scheduled to be deleted on reboot.
        Folder delete failed. C:\WINDOWS\LastGood.Tmp\System32\DllCache scheduled to be deleted on reboot.
        C:\WINDOWS\LastGood.Tmp\System32\directx\websetup folder deleted successfully.
        C:\WINDOWS\LastGood.Tmp\System32\directx folder deleted successfully.
        Folder delete failed. C:\WINDOWS\LastGood.Tmp\System32 scheduled to be deleted on reboot.
        C:\WINDOWS\LastGood.Tmp\RegisteredPackages\{AA936DF4-2B08-4B1F-B071-72192E287704} folder deleted successfully.
        C:\WINDOWS\LastGood.Tmp\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C} folder deleted successfully.
        C:\WINDOWS\LastGood.Tmp\RegisteredPackages folder deleted successfully.
        C:\WINDOWS\LastGood.Tmp\INF folder deleted successfully.
        C:\WINDOWS\LastGood.Tmp\help folder deleted successfully.
        C:\WINDOWS\LastGood.Tmp\Driver Cache\i386 folder deleted successfully.
        C:\WINDOWS\LastGood.Tmp\Driver Cache folder deleted successfully.
        C:\WINDOWS\LastGood.Tmp\Downloaded Program Files folder deleted successfully.
        C:\WINDOWS\LastGood.Tmp\AppPatch folder deleted successfully.
        Folder delete failed. C:\WINDOWS\LastGood.Tmp scheduled to be deleted on reboot.
        %systemroot% .tmp files removed: 132069316 bytes
        %systemroot%\System32 .tmp files removed: 0 bytes
        Windows Temp folder emptied: 0 bytes
        RecycleBin emptied: 0 bytes

        Total Files Cleaned = 127,99 mb

        OTM by OldTimer - Version 3.0.0.6 log created on 09072009_002412

        Files moved on Reboot...
        File move failed. C:\WINDOWS\LastGood.Tmp\System32\DRIVERS\ndis.sys scheduled to be moved on reboot.
        Folder move failed. C:\WINDOWS\LastGood.Tmp\System32\DRIVERS scheduled to be moved on reboot.
        File move failed. C:\WINDOWS\LastGood.Tmp\System32\DllCache\ndis.sys scheduled to be moved on reboot.
        Folder move failed. C:\WINDOWS\LastGood.Tmp\System32\DllCache scheduled to be moved on reboot.
        Folder move failed. C:\WINDOWS\LastGood.Tmp\System32\DRIVERS scheduled to be moved on reboot.
        Folder move failed. C:\WINDOWS\LastGood.Tmp\System32\DllCache scheduled to be moved on reboot.
        Folder move failed. C:\WINDOWS\LastGood.Tmp\System32 scheduled to be moved on reboot.
        Folder move failed. C:\WINDOWS\LastGood.Tmp\System32\DRIVERS scheduled to be moved on reboot.
        Folder move failed. C:\WINDOWS\LastGood.Tmp\System32\DllCache scheduled to be moved on reboot.
        Folder move failed. C:\WINDOWS\LastGood.Tmp\System32 scheduled to be moved on reboot.
        Folder move failed. C:\WINDOWS\LastGood.Tmp scheduled to be moved on reboot.

        Registry entries deleted on Reboot...
      2. je te renvoi 1 rapor aparemen le 1er mon ordi a encor redemare?

        All processes killed
        ========== PROCESSES ==========
        No active process named explorer.exe was found!
        ========== SERVICES/DRIVERS ==========
        ========== FILES ==========
        c:\windows\system32\wisdstr.exe moved successfully.
        c:\windows\system32\lowsec moved successfully.
        c:\documents and settings\M\reader_s.exe moved successfully.
        c:\windows\system32\reader_s.exe moved successfully.
        c:\windows\cajomezeho.dat moved successfully.
        c:\windows\aturi.dat moved successfully.
        c:\program files\Fichiers communs\ytyl.dat moved successfully.
        c:\windows\zuxocazyh.com moved successfully.
        c:\program files\rkfree moved successfully.
        c:\documents and settings\All Users\Application Data\rkfree\maps moved successfully.
        c:\documents and settings\All Users\Application Data\rkfree\data\M moved successfully.
        c:\documents and settings\All Users\Application Data\rkfree\data moved successfully.
        c:\documents and settings\All Users\Application Data\rkfree moved successfully.
        ========== COMMANDS ==========

        [EMPTYTEMP]

        User: Administrateur
        ->Temp folder emptied: 0 bytes
        ->Temporary Internet Files folder emptied: 67 bytes

        User: All Users

        User: Default User
        ->Temp folder emptied: 0 bytes
        ->Temporary Internet Files folder emptied: 67 bytes

        User: LocalService
        ->Temp folder emptied: 0 bytes
        File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
        ->Temporary Internet Files folder emptied: 32902 bytes

        User: M
        ->Temp folder emptied: 313491 bytes
        ->Temporary Internet Files folder emptied: 6517266 bytes
        ->Java cache emptied: 0 bytes

        User: NetworkService
        ->Temp folder emptied: 0 bytes
        ->Temporary Internet Files folder emptied: 67 bytes

        %systemdrive% .tmp files removed: 0 bytes
        C:\WINDOWS\LastGood.Tmp\System32\drivers folder deleted successfully.
        C:\WINDOWS\LastGood.Tmp\System32\DllCache folder deleted successfully.
        C:\WINDOWS\LastGood.Tmp\System32 folder deleted successfully.
        C:\WINDOWS\LastGood.Tmp\INF folder deleted successfully.
        C:\WINDOWS\LastGood.Tmp folder deleted successfully.
        %systemroot% .tmp files removed: 57351985 bytes
        %systemroot%\System32 .tmp files removed: 3072 bytes
        Windows Temp folder emptied: 0 bytes
        RecycleBin emptied: 1686 bytes

        Total Files Cleaned = 61,25 mb

        OTM by OldTimer - Version 3.0.0.6 log created on 09072009_001633

        Files moved on Reboot...

        Registry entries deleted on Reboot...
    6. c le bon? chak foi ke je ve envoyé 1 truk ca bug é il fo ke je recomence é g de la chance kan ca redemar pa
      1. Contributeur sécurité
        Heu...

        c:\windows\system32\reader_s.exe

        ViruT nan ?


        Va savoir ludo... :p,j'avais pas tilté sur le coup..

        Franky013

        Langage sms = contraire à la charte...evite ecrit en bon francais que se soit lisible.Tu veras tout va bien se passer ;)

        > Télécharge ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe Dr Web CureIt sur ton Bureau :

        - Double clique <drweb-cureit.exe> et ensuite clique sur <Analyse>;

        - Clique <Ok> à l'invite de l'analyse rapide. S'il trouve des processus infectés alors clique le bouton <Oui>.
        Note : une fenêtre s'ouvrira avec options pour "Commander" ou "50% de réduction" : Quitte en cliquant le "X".
        - Lorsque le scan rapide est terminé, clique sur le menu <Options> puis <Changer la configuration> ; Choisis l'onglet <Scanner>, et décoche <Analyse heuristique>. Clique ensuite sur <Ok>.
        - De retour à la fenêtre principale : clique pour activer <Analyse complète>
        - Clique le bouton avec flèche verte sur la droite, et le scan débutera.
        - Clique <Oui> pour tout à l'invite "Désinfecter ?" lorsqu'un fichier est détecté, et ensuite clique "Désinfecter".
        - Lorsque le scan sera complété, regarde si tu peux cliquer sur l' icône, adjacente aux fichiers détectés (plusieurs feuilles l'une sur l'autre). Si oui, alors clique dessus et ensuite clique sur l'icône <Suivant>, au dessous, et choisis <Déplacer en quarantaine l'objet indésirable>.
        - Du menu principal de l'outil, au haut à gauche, clique sur le menu <Fichier> et choisis <Enregistrer le rapport>. Sauvegarde le rapport sur ton Bureau. Ce dernier se nommera DrWeb.csv
        - Ferme Dr.Web Cureit
        - Redémarre ton ordi (important car certains fichiers peuvent être déplacés/réparés au redémarrage).
        - Suite au redémarrage, poste (Copie/Colle) le contenu du rapport de Dr.Web dans ta prochaine réponse

        1. Contributeur sécurité
          Salut A tous :)

          Kevin : Très coriace le braviax et le virut :p ...

          Mais , je connais une manip efficace pour s'en débarrasser puisque l'infection patche les fichiers systèmes , faudrait installer la console de récupération avec Combofix , après le passage de dr-web cureit .

          Voili voilou , bonne chasse a vous ;)

          franky013,

          La suite : > https://forums.commentcamarche.net/forum/affich-14270878-pb-virus#12

          ++
          1. Contributeur sécurité
            Salut fix ;p

            Ouép y'as du boulot

            Il est bourré son pc...
            1. Contributeur sécurité
              Oué :( ...

              C'est des variantes très coriaces de braviax ...

              Bonne chasse , mais je reste quand même pour suivre ;)
              1. Contributeur sécurité
                Ouép :(,il est mal barré en tout cas.
                1. Et bien le voilà rassuré je présume :p
                2. Salut,
                  N'ayant pas de nouvelles et étant toujours "infecté", je suis inquiet !
                  peux-tu me dire si il y a d'autres demarches a effectuer afin de venir a bout de ce virus
              2. bonsoir,

                Desolé, je n'ai pu repondre avant!
                dfqupd32.exe;c:\documents and settings\m\menu démarrer\programmes\démarrage;Trojan.Botnetlog.11;Supprimé.;
                pc_antispyware2010.exe;c:\program files\pc_antispyware2010;Trojan.Fakealert.4967;Irréparable.Quarantaine.;
                cru629.dat;c:\windows\system32;Trojan.Proxy.1739;Supprimé.;
                beep.sys;c:\windows\system32\drivers;Trojan.NtRootKit.3206;Supprimé.;
                upload_moi_FIZERO.tar.gz/upload_moi.tar\WINDOWS/System32/mxrsjeie.dll;C:\upload_moi_FIZERO.tar.gz/upload_moi.tar;Trojan.Virtumod.based;;
                upload_moi_FIZERO.tar.gz/upload_moi.tar\WINDOWS/System32/tkjuohne.dll;C:\upload_moi_FIZERO.tar.gz/upload_moi.tar;Trojan.Virtumod.372;;
                upload_moi_FIZERO.tar.gz/upload_moi.tar\WINDOWS/System32/xlgcnesa.dll;C:\upload_moi_FIZERO.tar.gz/upload_moi.tar;Trojan.Virtumod.based;;
                upload_moi_FIZERO.tar.gz/upload_moi.tar\WINDOWS/System32/sbgsmqnd.dll;C:\upload_moi_FIZERO.tar.gz/upload_moi.tar;Trojan.Virtumod.based;;
                upload_moi_FIZERO.tar.gz/upload_moi.tar\WINDOWS/System32/wjgmebrs.dll;C:\upload_moi_FIZERO.tar.gz/upload_moi.tar;Trojan.Virtumod.based;;
                upload_moi_FIZERO.tar.gz/upload_moi.tar\WINDOWS/System32/kmthdjif.dll;C:\upload_moi_FIZERO.tar.gz/upload_moi.tar;Trojan.Virtumod.based;;
                upload_moi.tar;C:\;L'archive contient des éléments infectés;;
                upload_moi_FIZERO.tar.gz;C:\;L'archive contient des éléments infectés;Quarantaine.;
                pskill.exe;C:\Documents and Settings\M\Bureau\clean\clean;Tool.ProcessKill.7;Quarantaine.;
                Patch_ACDSee501_vf.exe;C:\Program Files\ACD Systems\ACDSee\5.0;Tool.ASEye.2;Quarantaine.;
                Uninstall.exe;C:\Program Files\PC_Antispyware2010;Trojan.Fakealert.4747;Irréparable.Quarantaine.;
                wscui.cpl;C:\Program Files\PC_Antispyware2010;Trojan.Fakealert.4739;Supprimé.;
                reader_s.exe.vir;C:\Qoobox\Quarantine\C\Documents and Settings\M;Trojan.DownLoad.37236;Supprimé.;
                PC_Antispyware2010.exe.vir;C:\Qoobox\Quarantine\C\Program Files\PC_Antispyware2010;Trojan.Fakealert.4967;Irréparable.Quarantaine.;
                Uninstall.exe.vir;C:\Qoobox\Quarantine\C\Program Files\PC_Antispyware2010;Trojan.Fakealert.4747;Irréparable.Quarantaine.;
                wscui.cpl.vir;C:\Qoobox\Quarantine\C\Program Files\PC_Antispyware2010;Trojan.Fakealert.4739;Supprimé.;
                kmthdjif.dll.vir;C:\Qoobox\Quarantine\C\WINDOWS\system32;Trojan.Virtumod.based;Irréparable.Quarantaine.;
                mxrsjeie.dll.vir;C:\Qoobox\Quarantine\C\WINDOWS\system32;Trojan.Virtumod.based;Irréparable.Quarantaine.;
                reader_s.exe.vir;C:\Qoobox\Quarantine\C\WINDOWS\system32;Trojan.DownLoad.37236;Supprimé.;
                sbgsmqnd.dll.vir;C:\Qoobox\Quarantine\C\WINDOWS\system32;Trojan.Virtumod.based;Irréparable.Quarantaine.;
                tkjuohne.dll.vir;C:\Qoobox\Quarantine\C\WINDOWS\system32;Trojan.Virtumod.372;Supprimé.;
                wisdstr.exe.vir;C:\Qoobox\Quarantine\C\WINDOWS\system32;Trojan.Fakealert.4747;Irréparable.Quarantaine.;
                wjgmebrs.dll.vir;C:\Qoobox\Quarantine\C\WINDOWS\system32;Trojan.Virtumod.based;Irréparable.Quarantaine.;
                xlgcnesa.dll.vir;C:\Qoobox\Quarantine\C\WINDOWS\system32;Trojan.Virtumod.based;Irréparable.Quarantaine.;
                beep.sys.vir;C:\Qoobox\Quarantine\C\WINDOWS\system32\dllcache;Trojan.NtRootKit.3206;Supprimé.;
                figaro.sys.vir;C:\Qoobox\Quarantine\C\WINDOWS\system32\dllcache;Trojan.NtRootKit.3206;Supprimé.;
                beep.sys.vir;C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers;Trojan.NtRootKit.3206;Supprimé.;
                Process.exe;C:\SDFix\apps;Tool.Prockill;Quarantaine.;
                A0064805.cpl;C:\System Volume Information\_restore{38A3208A-B97D-447D-8125-61BF3B0915B1}\RP517;Trojan.Fakealert.4739;Supprimé.;
                A0065553.sys;C:\System Volume Information\_restore{38A3208A-B97D-447D-8125-61BF3B0915B1}\RP519;Trojan.NtRootKit.3206;Supprimé.;
                A0065563.cpl;C:\System Volume Information\_restore{38A3208A-B97D-447D-8125-61BF3B0915B1}\RP519;Trojan.Fakealert.4739;Supprimé.;
                MFEX-1.DAT;C:\System Volume Information\_restore{38A3208A-B97D-447D-8125-61BF3B0915B1}\RP519\snapshot;Trojan.NtRootKit.3206;Supprimé.;
                A0065587.cpl;C:\System Volume Information\_restore{38A3208A-B97D-447D-8125-61BF3B0915B1}\RP520;Trojan.Fakealert.4739;Supprimé.;
                A0065592.exe;C:\System Volume Information\_restore{38A3208A-B97D-447D-8125-61BF3B0915B1}\RP520;Trojan.Fakealert.4747;Irréparable.Quarantaine.;
                A0065593.cpl;C:\System Volume Information\_restore{38A3208A-B97D-447D-8125-61BF3B0915B1}\RP520;Trojan.Fakealert.4739;Supprimé.;
                A0065601.exe;C:\System Volume Information\_restore{38A3208A-B97D-447D-8125-61BF3B0915B1}\RP520;Trojan.Fakealert.4967;Irréparable.Quarantaine.;
                A0065652.cpl;C:\System Volume Information\_restore{38A3208A-B97D-447D-8125-61BF3B0915B1}\RP521;Trojan.Fakealert.4739;Supprimé.;
                A0065657.exe;C:\System Volume Information\_restore{38A3208A-B97D-447D-8125-61BF3B0915B1}\RP521;Trojan.Fakealert.4747;Irréparable.Quarantaine.;
                A0065658.cpl;C:\System Volume Information\_restore{38A3208A-B97D-447D-8125-61BF3B0915B1}\RP521;Trojan.Fakealert.4739;Supprimé.;
                A0065666.exe;C:\System Volume Information\_restore{38A3208A-B97D-447D-8125-61BF3B0915B1}\RP521;Trojan.Fakealert.4967;Irréparable.Quarantaine.;
                A0065718.sys;C:\System Volume Information\_restore{38A3208A-B97D-447D-8125-61BF3B0915B1}\RP521;Trojan.NtRootKit.3206;Supprimé.;
                A0065721.cpl;C:\System Volume Information\_restore{38A3208A-B97D-447D-8125-61BF3B0915B1}\RP521;Trojan.Fakealert.4739;Supprimé.;
                A0065739.sys;C:\System Volume Information\_restore{38A3208A-B97D-447D-8125-61BF3B0915B1}\RP521;Trojan.NtRootKit.3206;Supprimé.;
                A0065744.cpl;C:\System Volume Information\_restore{38A3208A-B97D-447D-8125-61BF3B0915B1}\RP521;Trojan.Fakealert.4739;Supprimé.;
                A0065819.exe;C:\System Volume Information\_restore{38A3208A-B97D-447D-8125-61BF3B0915B1}\RP521;Trojan.DownLoad.37236;Supprimé.;
                A0065834.exe;C:\System Volume Information\_restore{38A3208A-B97D-447D-8125-61BF3B0915B1}\RP521;Trojan.Fakealert.4967;Irréparable.Quarantaine.;
                A0065836.exe;C:\System Volume Information\_restore{38A3208A-B97D-447D-8125-61BF3B0915B1}\RP521;Trojan.Fakealert.4747;Irréparable.Quarantaine.;
                A0065837.cpl;C:\System Volume Information\_restore{38A3208A-B97D-447D-8125-61BF3B0915B1}\RP521;Trojan.Fakealert.4739;Supprimé.;
                A0065851.dll;C:\System Volume Information\_restore{38A3208A-B97D-447D-8125-61BF3B0915B1}\RP521;Trojan.Virtumod.based;Irréparable.Quarantaine.;
                A0065859.dll;C:\System Volume Information\_restore{38A3208A-B97D-447D-8125-61BF3B0915B1}\RP521;Trojan.Virtumod.based;Irréparable.Quarantaine.;
                A0065864.exe;C:\System Volume Information\_restore{38A3208A-B97D-447D-8125-61BF3B0915B1}\RP521;Trojan.DownLoad.37236;Supprimé.;
                A0065866.dll;C:\System Volume Information\_restore{38A3208A-B97D-447D-8125-61BF3B0915B1}\RP521;Trojan.Virtumod.based;Irréparable.Quarantaine.;
                A0065867.dll;C:\System Volume Information\_restore{38A3208A-B97D-447D-8125-61BF3B0915B1}\RP521;Trojan.Virtumod.372;Supprimé.;
                A0065871.exe;C:\System Volume Information\_restore{38A3208A-B97D-447D-8125-61BF3B0915B1}\RP521;Trojan.Fakealert.4747;Irréparable.Quarantaine.;
                A0065872.dll;C:\System Volume Information\_restore{38A3208A-B97D-447D-8125-61BF3B0915B1}\RP521;Trojan.Virtumod.based;Irréparable.Quarantaine.;
                A0065873.dll;C:\System Volume Information\_restore{38A3208A-B97D-447D-8125-61BF3B0915B1}\RP521;Trojan.Virtumod.based;Irréparable.Quarantaine.;
                A0068684.exe;C:\System Volume Information\_restore{38A3208A-B97D-447D-8125-61BF3B0915B1}\RP521;Trojan.Botnetlog.11;Supprimé.;
                A0068685.exe;C:\System Volume Information\_restore{38A3208A-B97D-447D-8125-61BF3B0915B1}\RP521;Trojan.Fakealert.4967;Irréparable.Quarantaine.;
                A0068686.sys;C:\System Volume Information\_restore{38A3208A-B97D-447D-8125-61BF3B0915B1}\RP521;Trojan.NtRootKit.3206;Supprimé.;
                A0068687.exe;C:\System Volume Information\_restore{38A3208A-B97D-447D-8125-61BF3B0915B1}\RP521;Trojan.Fakealert.4747;Irréparable.Quarantaine.;
                A0068688.cpl;C:\System Volume Information\_restore{38A3208A-B97D-447D-8125-61BF3B0915B1}\RP521;Trojan.Fakealert.4739;Supprimé.;
                cru629.dat;C:\WINDOWS\system32;Trojan.Proxy.1739;Supprimé.;
                vbwFunctionsVB6.dll;C:\WINDOWS\system32;Trojan.Siggen.2468;Supprimé.;
                _scui.cpl;C:\WINDOWS\system32;Trojan.Fakealert.4739;Supprimé.;
                reader_s.exe;C:\_OTM\MovedFiles\09072009_001633\documents and settings\M;Trojan.DownLoad.37236;Supprimé.;
                reader_s.exe;C:\_OTM\MovedFiles\09072009_001633\windows\system32;Trojan.DownLoad.37236;Supprimé.;
                wisdstr.exe;C:\_OTM\MovedFiles\09072009_001633\windows\system32;Trojan.Fakealert.4747;Irréparable.Quarantaine.;
                1. ci-joint nouveau rapport et merci encore !

                  Logfile of random's system information tool 1.06 (written by random/random)
                  Run by M at 2009-09-08 20:46:20
                  Microsoft Windows XP Édition familiale Service Pack 1
                  System drive C: has 13 GB (67%) free of 20 GB
                  Total RAM: 511 MB (39% free)

                  Logfile of Trend Micro HijackThis v2.0.2
                  Scan saved at 20:46:22, on 08/09/2009
                  Platform: Windows XP SP1 (WinNT 5.01.2600)
                  MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
                  Boot mode: Normal

                  Running processes:
                  C:\WINDOWS\System32\smss.exe
                  C:\WINDOWS\system32\winlogon.exe
                  C:\WINDOWS\system32\services.exe
                  C:\WINDOWS\system32\lsass.exe
                  C:\WINDOWS\System32\Ati2evxx.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\WINDOWS\system32\Ati2evxx.exe
                  C:\WINDOWS\Explorer.EXE
                  C:\WINDOWS\system32\spoolsv.exe
                  C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
                  C:\Program Files\MSI\Live Update 3\LMonitor.exe
                  C:\WINDOWS\SOUNDMAN.EXE
                  C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
                  C:\WINDOWS\System32\LVCOMSX.EXE
                  C:\Program Files\Logitech\Video\LogiTray.exe
                  C:\Program Files\Orange\LiveAssistant.exe
                  C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
                  C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
                  C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE
                  C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe
                  C:\WINDOWS\System32\braviax.exe
                  C:\Program Files\OrangeHSS\Launcher\Launcher.exe
                  C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe
                  C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                  C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
                  C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe
                  C:\Program Files\Logitech\Video\FxSvr2.exe
                  C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
                  C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                  C:\PROGRA~1\FICHIE~1\Nokia\MPAPI\MPAPI3s.exe
                  C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
                  C:\Program Files\Java\jre6\bin\jqs.exe
                  C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\Program Files\Fichiers communs\Motive\McciCMService.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\Program Files\OrangeHSS\systray\systrayapp.exe
                  C:\Program Files\OrangeHSS\Deskboard\deskboard.exe
                  C:\Program Files\OrangeHSS\connectivity\connectivitymanager.exe
                  C:\Program Files\OrangeHSS\connectivity\CoreCom\CoreCom.exe
                  C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
                  C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
                  C:\Program Files\OrangeHSS\connectivity\CoreCom\OraConfigRecover.exe
                  C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTCOMModule\0\FTCOMModule.exe
                  C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
                  C:\Program Files\MSN Messenger\usnsvc.exe
                  C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
                  C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
                  C:\Program Files\OrangeHSS\browser\browser.exe
                  C:\Program Files\PC_Antispyware2010\PC_Antispyware2010.exe
                  C:\Documents and Settings\M\Bureau\RSIT.exe
                  C:\Program Files\trend micro\M.exe

                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                  R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                  R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\OrangeHSS\SearchURLHook\SearchPageURL.dll
                  O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                  O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
                  O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
                  O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                  O4 - HKLM\..\Run: [LiveMonitor] C:\Program Files\MSI\Live Update 3\LMonitor.exe
                  O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
                  O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
                  O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\System32\LVCOMSX.EXE
                  O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
                  O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
                  O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                  O4 - HKLM\..\Run: [ORAHSSSessionManager] C:\Program Files\OrangeHSS\SessionManager\SessionManager.exe
                  O4 - HKLM\..\Run: [Orange_McciTrayApp] C:\Program Files\Orange\LiveAssistant.exe
                  O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
                  O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
                  O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup
                  O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe"
                  O4 - HKLM\..\Run: [rkfree] "C:\Program Files\rkfree\rkfree.exe" /b
                  O4 - HKLM\..\Run: [reader_s] C:\WINDOWS\System32\reader_s.exe
                  O4 - HKLM\..\Run: [braviax] braviax.exe
                  O4 - HKLM\..\Run: [PC Antispyware 2010] "C:\Program Files\PC_Antispyware2010\PC_Antispyware2010.exe" /hide
                  O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
                  O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
                  O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
                  O4 - HKCU\..\Run: [reader_s] C:\Documents and Settings\M\reader_s.exe
                  O4 - HKCU\..\RunOnce: [Shockwave Updater] C:\WINDOWS\system32\Adobe\SHOCKW~1\SWHELP~2.EXE -Update -1100465 -"Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; Orange 8.0; NaviWoo2.0; .NET CLR 1.1.4322)" -"http://www8.agame.com/..."
                  O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
                  O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
                  O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
                  O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
                  O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
                  O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?8c4b13925d1f493f825a604478a29d6c
                  O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?8c4b13925d1f493f825a604478a29d6c
                  O8 - Extra context menu item: Translate this web page with Babylon - res://C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/ActionTU.htm
                  O8 - Extra context menu item: Translate with Babylon - res://C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Action.htm
                  O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
                  O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
                  O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
                  O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
                  O15 - Trusted Zone: http://pfttbc.ft.motive.com
                  O15 - Trusted Zone: http://*.orange.fr
                  O15 - Trusted Zone: http://rw.search.ke.voila.fr
                  O15 - Trusted Zone: http://orange.weborama.fr
                  O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} (DjVuCtl Class) - http://www.lizardtech.com/download/files/win/djvuplugin/en_US/DjVuControl_en_US.cab
                  O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
                  O16 - DPF: {8167C273-DF59-4416-B647-C8BB2C7EE83E} (WebSDev Control) - http://liveupdate.msi.com.tw/autobios/LOnline/install.cab
                  O17 - HKLM\System\CCS\Services\Tcpip\..\{F99B4C81-5CC1-4C14-9CA4-917D8CC03323}: NameServer = 212.27.32.176
                  O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
                  O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                  O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
                  O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
                  O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
                  O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
                  O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                  O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
                  O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
                  O23 - Service: Sunbelt Kerio Personal Firewall 4 (KPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
                  O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Fichiers communs\Motive\McciCMService.exe
                  O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
                  1. Non !

                    Pas combofix !

                    [Je prends la relève]

                    Fais ceci 2/3 fois de suite et poste les 2/3 rapports générés à la suite dans ta réponse stp !
                    > Télécharge Dr.Web CureIt sur ton Bureau : ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe ou https://free.drweb.com/cureit/
                    - Double clique <drweb-cureit.exe> et ensuite clique sur <Analyse>;
                    - Clique <Ok> à l'invite de l'analyse rapide. S'il trouve des processus infectés alors clique le bouton <Oui>.
                    Note : une fenêtre s'ouvrira avec options pour "Commander" ou "50% de réduction" : Quitte en cliquant le "X".
                    - Lorsque le scan rapide est terminé, clique sur le menu <Options> puis <Changer la configuration> ; Choisis l'onglet <Scanner>, et décoche <Analyse heuristique>. Clique ensuite sur <Ok>.
                    - De retour à la fenêtre principale : clique pour activer <Analyse complète>
                    - Clique le bouton avec flèche verte sur la droite, et le scan débutera.
                    - Clique <Oui> pour tout à l'invite "Désinfecter ?" lorsqu'un fichier est détecté, et ensuite clique "Désinfecter".
                    - Lorsque le scan sera complété, regarde si tu peux cliquer sur l'icône, adjacente aux fichiers détectés (plusieurs feuilles l'une sur l'autres). Si oui, alors clique dessus et ensuite clique sur l'icône <Suivant>, au dessous, et choisis <Déplacer en quarantaine l'objet indésirable>.
                    - Du menu principal de l'outil, au haut à gauche, clique sur le menu <Fichier> et choisis <Enregistrer le rapport>. Sauvegarde le rapport sur ton Bureau. Ce dernier se nommera DrWeb.csv
                    - Ferme Dr.Web Cureit
                    - Redémarre ton ordi (important car certains fichiers peuvent être déplacés/réparés au redémarrage).
                    - Suite au redémarrage, poste (Copie/Colle) le contenu du rapport de Dr.Web dans ta prochaine réponse.

                    A+
                    1. salut,

                      je sais pas trop quoi faire redemarrer ou pas ? ca se complique car moi j'y comprend vraiment rien!
                  2. Contributeur sécurité
                    1. Salut

                      Je n'ai pu te repondre avant car je viens a peine de recuperer mon pc. Tout etait planté(plus de connexion etc...) et j ai galere pour tout faire reinstaller. Ce fut laborieux mais fait avec succes. Je te remercie vraiment de ton aide
                    2. @franky013De toutes façons le formatage était quasi inévitable. :_/

                      Alors bonne continuation et salut ;-)
                    3. @Utilisateur anonymeapparement c'etait la seule solution mais encore 1 fois mille merci a tous pour votre aide