Virus

Résolu
Bonjour,
j'ai fait un scan avec avast il m'a dectecté 2 vius
WIN32:trojan-gen
WIN32:def-mzg {trj}

je les ai mis en quarantaine.
faut il les supprimer ?

Merci de m'aider (je connais pas grand chose en virus )
Flo.
Configuration: Windows Vista Internet Explorer 7.0

65 réponses

Résumé de la discussion

Deux éléments détectés par Avast, WIN32:trojan-gen et WIN32:def-mzg, ont été placés en quarantaine après un scan; la question porte sur leur suppression et la nécessité d’aller plus loin. Plusieurs réponses recommandent de lancer un scan au démarrage avant le démarrage de Windows et, le cas échéant, d’utiliser Malwarebytes Anti-Malware pour une analyse plus complète et une mise en quarantaine des débris. En cas de détection continue, il est généralement conseillé de vérifier les modifications système, supprimer les extensions indésirables et nettoyer les programmes susceptibles d’avoir installé des barres d’outils ou du malware. Une vérification finale après suppression et un nouveau scan sont souvent recommandés pour confirmer l’absence de restes, et des paramètres de sécurité peuvent être réactivés ou ajustés.

Bobot (l’IA à votre service)
  1. Refait un scan au redémarrage avant le démarrage de Windows !

    Clic droit sur l'icône d'Avast (près de l'heure) puis "Démarrer Avast antivirus.
    Après le scan mémoire, choisis "Planifier un scan au démarrage"
    1
    1. Contributeur sécurité
      bonjour

      les supprimer...oui

      eventuellement poster le rapport d'avast
      0
      1. donc je vais dans avast et je supprime
        0
        1. Salut

          Quand Avast trouve un virus, la première action à faire c'est de cliquer sur "réparer". Si c'est pas possible il ne reste qu'à supprimer au risque que Windows ou une application ne fonctionne plus correctement.
          Un fichier infecté mis en quarantaine sera bloqué et donc inutilisable, et donc inoffensif.
          0
          1. Suppression des fichiers sélectionnés

            L'action a été accomplie avec succès !
            0
            1. comment tu fais pour poster le rapport d'avast
              0
              1. Contributeur sécurité
                tu ouvres le rapport
                et un copier coller ici
                0
                1. le scan vient de se finir,et mon ordi vient de redémarrer .
                  pour le rapport, je fais comment?
                  je ne sais ou le trouver.
                  0
                  1. Clic droit sur l'icone et journal.

                    Mais il aurait demandé quoi faire s'il avait trouvé un virus.
                    0
                    1. j'ai ouvert le visualiseur de journaux avast (c'est ça )
                      je clic sur quoi aprés (désolé je ne sais pas )

                      je peux faire un HijackThis c'est peut etre plus simple
                      0
                      1. Contributeur sécurité
                        ok
                        pour le même prix fais plutôt ceci

                        • Télécharge Random's System Information Tool (RSIT) de Random/Random.

                        http://images.malwareremoval.com/random/RSIT.exe

                        • Enregistre le sur ton Bureau.

                        • Double clique sur RSIT.exe pour lancer l'outil.

                        • Clique sur "Continue" à l'écran Disclaimer.

                        • Si l'outil HijackThis n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu s'il te le demande)

                        et tu devras accepter la licence.

                        • Une fois le scan terminé, deux rapports vont apparaître : poste les dans deux messages séparés stp

                        Les rapports se trouvent à cet endroit:
                        C:\rsit\info.txt
                        C:\rsit\log.txt
                        0
                        1. voici le rapport

                          Logfile of random's system information tool 1.06 (written by random/random)
                          Run by LES LEVOYER'S at 2009-12-19 14:14:21
                          Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 2
                          System drive C: has 58 GB (41%) free of 143 GB
                          Total RAM: 2038 MB (34% free)

                          Logfile of Trend Micro HijackThis v2.0.2
                          Scan saved at 14:14:23, on 19/12/2009
                          Platform: Windows Vista SP2 (WinNT 6.00.1906)
                          MSIE: Internet Explorer v7.00 (7.00.6002.18005)
                          Boot mode: Normal

                          Running processes:
                          C:\Windows\system32\taskeng.exe
                          C:\Windows\system32\Dwm.exe
                          C:\Windows\Explorer.EXE
                          C:\Windows\system32\taskeng.exe
                          C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
                          C:\Program Files\Sony\VAIO Update 3\VAIOUpdt.exe
                          C:\Program Files\Windows Defender\MSASCui.exe
                          C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                          C:\Windows\System32\hkcmd.exe
                          C:\Windows\System32\igfxpers.exe
                          C:\Program Files\Sony\ISB Utility\ISBMgr.exe
                          C:\Program Files\Search Settings\SearchSettings.exe
                          C:\Program Files\iTunes\iTunesHelper.exe
                          C:\Program Files\Alwil Software\Avast4\ashDisp.exe
                          C:\Windows\system32\igfxsrvc.exe
                          C:\Program Files\Java\jre6\bin\jusched.exe
                          C:\Windows\ehome\ehtray.exe
                          C:\Program Files\Windows Sidebar\sidebar.exe
                          C:\Program Files\Windows Media Player\wmpnscfg.exe
                          C:\Program Files\Winsudate\gibusr.exe
                          C:\Program Files\Picasa2\PicasaMediaDetector.exe
                          C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
                          C:\Program Files\OpenOffice.org 3\program\soffice.exe
                          C:\Program Files\SkypeMate\SkypeMate.exe
                          C:\Windows\system32\wbem\unsecapp.exe
                          C:\Program Files\OpenOffice.org 3\program\soffice.bin
                          C:\Windows\ehome\ehmsas.exe
                          C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
                          C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
                          C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
                          C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosAVRC.exe
                          C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe
                          C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtProc.exe
                          C:\Windows\System32\mobsync.exe
                          C:\Program Files\Internet Explorer\ieuser.exe
                          C:\Program Files\Internet Explorer\iexplore.exe
                          C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe
                          C:\Program Files\Windows Live\Toolbar\wltuser.exe
                          C:\Windows\system32\Macromed\Flash\FlashUtil10c.exe
                          C:\Program Files\Alwil Software\Avast4\ashLogV.exe
                          C:\Users\LES LEVOYER'S\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1F9PD9Z1\RSIT[1].exe
                          C:\Windows\system32\SearchFilterHost.exe
                          C:\Program Files\Internet Explorer\iexplore.exe
                          C:\Users\LES LEVOYER'S\Desktop\RSIT.exe
                          C:\Program Files\Trend Micro\HijackThis\LES LEVOYER'S.exe

                          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.club-vaio.com
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                          R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                          R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                          R3 - URLSearchHook: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\kb127\SearchSettings.dll
                          O1 - Hosts: ::1 localhost
                          O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                          O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                          O2 - BHO: Windows Live Family Safety Browser Helper - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll
                          O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
                          O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
                          O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
                          O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll
                          O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                          O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                          O2 - BHO: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\kb127\SearchSettings.dll
                          O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
                          O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                          O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                          O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
                          O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                          O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                          O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                          O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
                          O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
                          O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
                          O4 - HKLM\..\Run: [ISBMgr.exe] "C:\Program Files\Sony\ISB Utility\ISBMgr.exe"
                          O4 - HKLM\..\Run: [fssui] "C:\Program Files\Windows Live\Family Safety\fsui.exe" -autorun
                          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                          O4 - HKLM\..\Run: [SearchSettings] C:\Program Files\Search Settings\SearchSettings.exe
                          O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                          O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                          O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                          O4 - HKLM\..\Run: [Skytel] Skytel.exe
                          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                          O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                          O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                          O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                          O4 - HKCU\..\Run: [WinUsr] C:\Program Files\Winsudate\gibusr.exe
                          O4 - HKCU\..\Run: [AdobeUpdater] "C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe"
                          O4 - HKCU\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
                          O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\CCleaner.exe" /AUTO
                          O4 - HKCU\..\RunOnce: [Shockwave Updater] C:\Windows\System32\Adobe\SHOCKW~1\SWHELP~2.EXE -Update -1103471 -"Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0; GTB6; SLCC1; .NET CLR 2.0.50727; Media Center PC 5.0; .NET CLR 3.5.30729; .NET CLR 3.0.30729)" -"http://www.jeux-gratuits.com/jeu/112/jeu+gratuit+skate+de+rue/"
                          O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                          O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                          O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                          O4 - HKUS\S-1-5-18\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'SYSTEM')
                          O4 - HKUS\.DEFAULT\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'Default user')
                          O4 - Startup: OpenOffice.org 3.1.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
                          O4 - Startup: SkypeMate.lnk = C:\Program Files\SkypeMate\SkypeMate.exe
                          O4 - Global Startup: Bluetooth Manager.lnk = ?
                          O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
                          O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
                          O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
                          O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                          O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                          O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
                          O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
                          O13 - Gopher Prefix:
                          O15 - Trusted Zone: *.canalplay.com
                          O15 - Trusted Zone: *.canalplusactive.com
                          O15 - Trusted Zone: *.canalplay.com (HKLM)
                          O15 - Trusted Zone: *.canalplusactive.com (HKLM)
                          O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
                          O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://appldnld.apple.com/QuickTime/qtactivex/qtplugin.cab
                          O16 - DPF: {04CB5B64-5915-4629-B869-8945CEBADD21} (Module de délivrance de certificat MINEFI) - https://static.impots.gouv.fr/abos/static/securite/certdgi1.cab
                          O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
                          O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
                          O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w3/resources/VistaMSNPUpldfr-fr.cab
                          O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab56986.cab
                          O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
                          O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
                          O16 - DPF: {B9F79165-A264-4C4A-A211-133A5E8D647F} (F-Secure Health Check 1.1) - http://orange.securitoo.com/pchc/fscax.cab
                          O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
                          O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
                          O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
                          O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
                          O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
                          O23 - Service: Adobe Active File Monitor V5 (AdobeActiveFileMonitor5.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
                          O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                          O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                          O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                          O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                          O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                          O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                          O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
                          O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                          O23 - Service: Service Google Update (gupdate1c9b9b08083cb0) (gupdate1c9b9b08083cb0) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
                          O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
                          O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                          O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
                          O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
                          O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
                          O23 - Service: Service CANALPLAY - Canal+ Active - C:\Program Files\Lecteur CANALPLAY\CanalPlayService.exe
                          O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
                          O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
                          O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
                          O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
                          O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe
                          O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
                          O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
                          O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe
                          O23 - Service: VAIO Media Content Collection (VAIOMediaPlatform-UCLS-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\UCLS.exe
                          O23 - Service: VAIO Media Content Collection (HTTP) (VAIOMediaPlatform-UCLS-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
                          O23 - Service: VAIO Media Content Collection (UPnP) (VAIOMediaPlatform-UCLS-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
                          O23 - Service: VAIO Content Metadata Intelligent Analyzing Manager (VcmIAlzMgr) - Sony Corporation - C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe
                          O23 - Service: VAIO Content Metadata XML Interface (VcmXmlIfHelper) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper.exe
                          O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
                          O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
                          O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
                          O23 - Service: Gestionnaire de mise à jour Winsudate (WinSvc) - Winsudate - C:\Program Files\Winsudate\gibsvc.exe
                          O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
                          0
                          1. le deuxieme

                            End of file - 16534 bytes

                            ======Scheduled tasks folder======

                            C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
                            C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
                            C:\Windows\tasks\User_Feed_Synchronization-{DE07AA01-D503-43FC-90CA-C85F00D4B173}.job

                            ======Registry dump======

                            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]
                            &Yahoo! Toolbar Helper - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll [2008-07-28 882416]

                            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
                            Aide pour le lien d'Adobe PDF Reader - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]

                            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4f3ed5cd-0726-42a9-87f5-d13f3d2976ac}]
                            Windows Live Family Safety Browser Helper Class - C:\Program Files\Windows Live\Family Safety\fssbho.dll [2009-08-05 113512]

                            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]

                            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
                            Search Helper - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll [2009-05-19 137600]

                            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
                            Programme d'aide de l'Assistant de connexion Windows Live - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]

                            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
                            Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2009-12-05 263280]

                            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
                            Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll [2009-12-05 764912]

                            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
                            Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-10-11 41760]

                            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10}]
                            Windows Live Toolbar Helper - C:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-02-06 1068904]

                            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}]
                            SearchSettings Class - C:\Program Files\Search Settings\kb127\SearchSettings.dll [2008-06-12 1111904]

                            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}]
                            SingleInstance Class - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll [2008-07-28 160496]

                            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
                            {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Yahoo! Toolbar - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll [2008-07-28 882416]
                            {21FA44EF-376D-4D53-9B0F-8A89D3229068} - &Windows Live Toolbar - C:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-02-06 1068904]
                            {2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2009-12-05 263280]

                            [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
                            "Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-19 1008184]
                            "RtHDVCpl"=C:\Windows\RtHDVCpl.exe [2007-04-08 4423680]
                            "SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2007-03-10 835584]
                            "IgfxTray"=C:\Windows\system32\igfxtray.exe [2007-06-30 137752]
                            "HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2007-06-30 154136]
                            "Persistence"=C:\Windows\system32\igfxpers.exe [2007-06-30 133656]
                            "ISBMgr.exe"=C:\Program Files\Sony\ISB Utility\ISBMgr.exe [2007-06-11 317560]
                            "fssui"=C:\Program Files\Windows Live\Family Safety\fsui.exe [2009-08-05 647520]
                            "QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2009-02-25 413696]
                            "SearchSettings"=C:\Program Files\Search Settings\SearchSettings.exe [2008-06-12 991584]
                            "iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2009-04-02 342312]
                            "avast!"=C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe [2009-08-17 81000]
                            "Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-10-15 39792]
                            "Skytel"=C:\Windows\Skytel.exe [2007-04-08 1822720]
                            "SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-10-11 149280]

                            [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
                            "ehTray.exe"=C:\Windows\ehome\ehTray.exe [2008-01-19 125952]
                            "Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2009-04-11 1233920]
                            "WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe [2008-01-19 202240]
                            "WinUsr"=C:\Program Files\Winsudate\gibusr.exe [2009-07-27 88304]
                            "AdobeUpdater"=C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe [2008-11-11 2356088]
                            "Picasa Media Detector"=C:\Program Files\Picasa2\PicasaMediaDetector.exe [2008-08-21 443968]
                            "ccleaner"=C:\Program Files\CCleaner\CCleaner.exe [2008-03-25 906480]

                            [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
                            "Shockwave Updater"=C:\Windows\System32\Adobe\SHOCKW~1\SWHELP~2.EXE [2008-12-05 460216]

                            C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
                            Bluetooth Manager.lnk - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe

                            C:\Users\LES LEVOYER'S\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
                            OpenOffice.org 3.1.lnk - C:\Program Files\OpenOffice.org 3\program\quickstart.exe
                            SkypeMate.lnk - C:\Program Files\SkypeMate\SkypeMate.exe

                            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
                            "AppInit_DLLS"="C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL"

                            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
                            C:\Windows\system32\igfxdev.dll [2007-06-30 204800]

                            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\VESWinlogon]
                            C:\Windows\system32\VESWinlogon.dll [2007-07-24 98304]

                            [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]

                            [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]

                            [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]

                            [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]

                            [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
                            "dontdisplaylastusername"=0
                            "legalnoticecaption"=
                            "legalnoticetext"=
                            "shutdownwithoutlogon"=1
                            "undockwithoutlogon"=1
                            "EnableUIADesktopToggle"=0

                            [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
                            "NoDriveTypeAutoRun"=145

                            [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
                            "BindDirectlyToPropertySetStorage"=

                            [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

                            [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

                            [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0a21c760-839e-11dd-ad99-001bfbcd081f}]
                            shell\AutoRun\command - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL XOAUsUf.EXe

                            [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f7ebe47c-0356-11de-8730-001bfbcd081f}]
                            shell\Auto\command - RavMonE.exe e
                            shell\AutoRun\command - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RavMonE.exe e

                            ======List of files/folders created in the last 1 months======

                            2009-12-19 14:11:40 ----D---- C:\rsit
                            2009-12-19 09:39:20 ----D---- C:\ProgramData\Nero
                            2009-12-19 09:39:18 ----D---- C:\Program Files\Common Files\Nero
                            2009-12-12 12:46:19 ----D---- C:\Users\LES LEVOYER'S\AppData\Roaming\OpenOffice.org
                            2009-12-12 12:44:35 ----D---- C:\Program Files\JRE
                            2009-12-12 12:44:23 ----D---- C:\Program Files\OpenOffice.org 3
                            2009-12-12 12:43:20 ----A---- C:\Windows\system32\javaws.exe
                            2009-12-12 12:43:20 ----A---- C:\Windows\system32\javaw.exe
                            2009-12-12 12:43:20 ----A---- C:\Windows\system32\java.exe
                            2009-12-10 06:12:05 ----A---- C:\Windows\system32\nshhttp.dll
                            2009-12-10 06:12:00 ----A---- C:\Windows\system32\httpapi.dll
                            2009-12-09 06:09:48 ----A---- C:\Windows\system32\winhttp.dll
                            2009-12-09 06:09:41 ----A---- C:\Windows\system32\wininet.dll
                            2009-12-09 06:09:40 ----A---- C:\Windows\system32\mshtml.dll
                            2009-12-09 06:09:39 ----A---- C:\Windows\system32\urlmon.dll
                            2009-12-09 06:09:37 ----A---- C:\Windows\system32\ieframe.dll
                            2009-12-09 06:09:36 ----A---- C:\Windows\system32\ieui.dll
                            2009-12-09 06:09:34 ----A---- C:\Windows\system32\ieencode.dll
                            2009-12-09 06:09:32 ----A---- C:\Windows\system32\ieapfltr.dll
                            2009-12-09 06:05:06 ----A---- C:\Windows\system32\rastls.dll
                            2009-11-26 07:30:58 ----A---- C:\Windows\system32\tzres.dll
                            2009-11-25 06:11:29 ----A---- C:\Windows\system32\msxml6.dll
                            2009-11-25 06:11:29 ----A---- C:\Windows\system32\msxml3.dll

                            ======List of files/folders modified in the last 1 months======

                            2009-12-19 14:14:18 ----D---- C:\Windows\Prefetch
                            2009-12-19 14:14:17 ----D---- C:\Windows\Temp
                            2009-12-19 11:01:49 ----SHD---- C:\System Volume Information
                            2009-12-19 10:46:59 ----D---- C:\Users\LES LEVOYER'S\AppData\Roaming\OpenOffice.org2
                            2009-12-19 09:55:01 ----D---- C:\Program Files\Circle Developemet
                            2009-12-19 09:48:19 ----SHD---- C:\Windows\Installer
                            2009-12-19 09:48:18 ----RD---- C:\Program Files
                            2009-12-19 09:42:43 ----D---- C:\Users\LES LEVOYER'S\AppData\Roaming\Nero
                            2009-12-19 09:39:20 ----HD---- C:\ProgramData
                            2009-12-19 09:39:18 ----D---- C:\Program Files\Common Files
                            2009-12-19 09:38:25 ----D---- C:\Windows\system32\Tasks
                            2009-12-19 09:38:05 ----D---- C:\Windows\winsxs
                            2009-12-19 09:37:54 ----D---- C:\Program Files\Common Files\microsoft shared
                            2009-12-18 18:56:30 ----D---- C:\Users\LES LEVOYER'S\AppData\Roaming\vlc
                            2009-12-18 12:13:22 ----D---- C:\Windows\System32
                            2009-12-18 12:13:22 ----D---- C:\Windows\inf
                            2009-12-18 12:13:22 ----A---- C:\Windows\system32\PerfStringBackup.INI
                            2009-12-18 12:12:41 ----D---- C:\Windows\system32\LogFiles
                            2009-12-18 05:24:56 ----D---- C:\Windows
                            2009-12-17 22:27:48 ----D---- C:\Users\LES LEVOYER'S\AppData\Roaming\Skype
                            2009-12-17 22:25:59 ----D---- C:\Users\LES LEVOYER'S\AppData\Roaming\skypePM
                            2009-12-15 07:41:13 ----D---- C:\Windows\system32\catroot2
                            2009-12-12 12:45:36 ----RSD---- C:\Windows\assembly
                            2009-12-12 12:44:47 ----RSD---- C:\Windows\Fonts
                            2009-12-12 12:42:22 ----D---- C:\Program Files\Java
                            2009-12-10 06:58:11 ----D---- C:\Windows\rescache
                            2009-12-10 06:43:16 ----D---- C:\Windows\system32\catroot
                            2009-12-10 06:40:31 ----D---- C:\Windows\system32\fr-FR
                            2009-12-10 06:40:31 ----D---- C:\Windows\system32\drivers
                            2009-12-10 06:40:31 ----D---- C:\Program Files\Windows Mail
                            2009-12-10 06:17:05 ----D---- C:\Windows\Debug
                            2009-12-02 00:06:19 ----A---- C:\Windows\system32\mrt.exe

                            ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

                            R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr.sys [2009-08-17 23152]
                            R1 aswSP;avast! Self Protection; C:\Windows\system32\drivers\aswSP.sys [2009-08-17 114768]
                            R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2009-08-17 51376]
                            R1 DMICall;Sony DMI Call service; C:\Windows\system32\DRIVERS\DMICall.sys [2007-06-27 10216]
                            R1 Tosrfcom;Bluetooth RFCOMM; C:\Windows\System32\Drivers\tosrfcom.sys [2005-08-01 64896]
                            R2 aswFsBlk;aswFsBlk; C:\Windows\system32\DRIVERS\aswFsBlk.sys [2009-08-17 20560]
                            R2 aswMonFlt;aswMonFlt; C:\Windows\system32\DRIVERS\aswMonFlt.sys [2009-08-17 53328]
                            R2 mdmxsdk;mdmxsdk; C:\Windows\system32\DRIVERS\mdmxsdk.sys [2007-06-16 12672]
                            R2 regi;regi; C:\Windows\system32\drivers\regi.sys [2007-04-17 11032]
                            R2 XAudio;XAudio; C:\Windows\system32\DRIVERS\xaudio.sys [2007-06-16 8192]
                            R3 Afc;PPdus ASPI Shell; C:\Windows\system32\drivers\Afc.sys [2006-11-10 18688]
                            R3 CmBatt;Pilote pour Batterie à méthode de contrôle ACPI Microsoft; C:\Windows\system32\DRIVERS\CmBatt.sys [2008-01-19 14208]
                            R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2009-03-19 23400]
                            R3 HSF_DPV;HSF_DPV; C:\Windows\system32\DRIVERS\HSX_DPV.sys [2007-06-16 985600]
                            R3 HSXHWAZL;HSXHWAZL; C:\Windows\system32\DRIVERS\HSXHWAZL.sys [2007-06-16 207360]
                            R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys [2007-06-30 1671680]
                            R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2007-04-08 1761696]
                            R3 NETw4v32;Pilote de carte Intel(R) Wireless WiFi Link pour Windows Vista 32 bits; C:\Windows\system32\DRIVERS\NETw4v32.sys [2007-06-30 2222080]
                            R3 R5U870FLx86;R5U870 UVC Lower Filter ; C:\Windows\System32\Drivers\R5U870FLx86.sys [2007-04-20 73472]
                            R3 R5U870FUx86;R5U870 UVC Upper Filter ; C:\Windows\System32\Drivers\R5U870FUx86.sys [2007-04-20 43904]
                            R3 RTL8169;Realtek 8169 NT Driver; C:\Windows\system32\DRIVERS\Rtlh86.sys [2007-07-06 84480]
                            R3 SNC;Sony Firmware Extension Parser Device; C:\Windows\System32\Drivers\SonyNC.sys [2006-11-06 27520]
                            R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2007-03-10 181560]
                            R3 ti21sony;ti21sony; C:\Windows\system32\drivers\ti21sony.sys [2007-06-06 812544]
                            R3 tosporte;Bluetooth COM Port; C:\Windows\system32\DRIVERS\tosporte.sys [2006-10-10 41600]
                            R3 tosrfbd;Bluetooth RFBUS; C:\Windows\system32\DRIVERS\tosrfbd.sys [2007-04-24 113920]
                            R3 tosrfbnp;Bluetooth RFBNEP; C:\Windows\System32\Drivers\tosrfbnp.sys [2006-11-20 36480]
                            R3 Tosrfhid;Bluetooth RFHID; C:\Windows\system32\DRIVERS\Tosrfhid.sys [2007-03-01 73728]
                            R3 tosrfnds;Bluetooth Personal Area Network; C:\Windows\system32\DRIVERS\tosrfnds.sys [2005-01-06 18612]
                            R3 tosrfusb;Bluetooth USB Controller; C:\Windows\system32\DRIVERS\tosrfusb.sys [2007-04-24 41856]
                            R3 usbvideo;R5U870 (UVC) ; C:\Windows\System32\Drivers\usbvideo.sys [2008-01-19 134016]
                            R3 winachsf;winachsf; C:\Windows\system32\DRIVERS\HSX_CNXT.sys [2007-06-16 659968]
                            R3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-19 83328]
                            S3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2007-07-07 2591232]
                            S3 drmkaud;Filtre de décodeur DRM (Noyau Microsoft); C:\Windows\system32\drivers\drmkaud.sys [2008-01-19 5632]
                            S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys [2009-08-05 54632]
                            S3 HdAudAddService;Pilote de fonction UAA 1.1 Microsoft pour le service High Definition Audio; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
                            S3 HSFHWAZL;HSFHWAZL; C:\Windows\system32\DRIVERS\VSTAZL3.SYS [2006-11-02 200704]
                            S3 JL2005C;Dual Mode Camera; C:\Windows\System32\Drivers\jl2005c.sys [2007-01-26 68954]
                            S3 MSKSSRV;Proxy de service de répartition Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-19 8192]
                            S3 MSPCLOCK;Proxy d'horloge de répartition Microsoft; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-19 5888]
                            S3 MSPQM;Proxy de gestion de qualité de répartition Microsoft; C:\Windows\system32\drivers\MSPQM.sys [2008-01-19 5504]
                            S3 MSTEE;Convertisseur en T/site-à-site de répartition Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2008-01-19 6016]
                            S3 TcUsb;TC USB Kernel Driver; C:\Windows\System32\Drivers\tcusb.sys [2007-05-29 46992]
                            S3 USBAAPL;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl.sys [2009-03-26 36864]
                            S3 usbaudio;Pilote USB audio (WDM); C:\Windows\system32\drivers\usbaudio.sys [2009-04-11 73216]
                            S3 WimFltr;WimFltr; C:\Windows\system32\DRIVERS\wimfltr.sys [2007-02-13 128104]
                            S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2009-10-01 40448]
                            S4 UIUSys;Conexant Setup API; C:\Windows\system32\DRIVERS\UIUSYS.SYS []
                            S4 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\drivers\wmiacpi.sys [2006-11-02 11264]

                            ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

                            R2 AdobeActiveFileMonitor5.0;Adobe Active File Monitor V5; C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe [2006-12-22 108712]
                            R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2009-03-26 132424]
                            R2 aswUpdSv;avast! iAVS4 Control Service; C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe [2009-08-17 18752]
                            R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast4\ashServ.exe [2009-08-17 138680]
                            R2 Bonjour Service;Service Bonjour; C:\Program Files\Bonjour\mDNSResponder.exe [2008-12-12 238888]
                            R2 IviRegMgr;IviRegMgr; C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe [2007-01-04 112152]
                            R2 SeaPort;SeaPort; C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-05-19 240512]
                            R2 TOSHIBA Bluetooth Service;TOSHIBA Bluetooth Service; C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe [2007-02-25 125048]
                            R2 VAIO Event Service;VAIO Event Service; C:\Program Files\Sony\VAIO Event Service\VESMgr.exe [2007-07-24 182392]
                            R2 VzCdbSvc;VAIO Entertainment Database Service; C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe [2007-06-28 188416]
                            R2 VzFw;VAIO Entertainment File Import Service; C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe [2007-06-28 184320]
                            R2 WinSvc;Gestionnaire de mise à jour Winsudate; C:\Program Files\Winsudate\gibsvc.exe [2009-07-27 70896]
                            R2 XAudioService;XAudioService; C:\Windows\system32\DRIVERS\xaudio.exe [2007-06-16 386560]
                            R3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe [2009-08-17 254040]
                            R3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast4\ashWebSv.exe [2009-08-17 352920]
                            R3 iPod Service;Service de l’iPod; C:\Program Files\iPod\bin\iPodService.exe [2009-04-02 656168]
                            R3 Vcsw;VAIO Entertainment UPnP Client Adapter; C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe [2007-06-28 274432]
                            S2 CLTNetCnService;Symantec Lic NetConnect service; C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe /h ccCommon []
                            S2 gupdate1c9b9b08083cb0;Service Google Update (gupdate1c9b9b08083cb0); C:\Program Files\Google\Update\GoogleUpdate.exe [2009-04-10 133104]
                            S3 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-01-19 21504]
                            S3 fsssvc;Service Windows Live Contrôle parental; C:\Program Files\Windows Live\Family Safety\fsssvc.exe [2009-08-05 704864]
                            S3 GoogleDesktopManager;GoogleDesktopManager; C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [2007-08-14 1831424]
                            S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-09-10 182768]
                            S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [2005-11-14 69632]
                            S3 MSCSPTISRV;MSCSPTISRV; C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe [2006-12-14 45056]
                            S3 PACSPTISVR;PACSPTISVR; C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe [2006-12-14 57344]
                            S3 Service CANALPLAY;Service CANALPLAY; C:\Program Files\Lecteur CANALPLAY\CanalPlayService.exe [2007-07-09 415392]
                            S3 SPTISRV;Sony SPTI Service; C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe [2006-12-14 69632]
                            S3 VAIO Entertainment TV Device Arbitration Service;VAIO Entertainment TV Device Arbitration Service; C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe [2007-06-28 73728]
                            S3 VAIOMediaPlatform-IntegratedServer-AppServer;VAIO Media Integrated Server; C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe [2007-06-20 2523136]
                            S3 VAIOMediaPlatform-IntegratedServer-HTTP;VAIO Media Integrated Server (HTTP); C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe [2007-06-20 397312]
                            S3 VAIOMediaPlatform-IntegratedServer-UPnP;VAIO Media Integrated Server (UPnP); C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe [2007-06-20 1089536]
                            S3 VAIOMediaPlatform-Mobile-Gateway;VAIO Media Gateway Server; C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe [2007-06-20 499712]
                            S3 VAIOMediaPlatform-UCLS-AppServer;VAIO Media Content Collection; C:\Program Files\Sony\VAIO Media Integrated Server\UCLS.exe [2007-01-10 745472]
                            S3 VAIOMediaPlatform-UCLS-HTTP;VAIO Media Content Collection (HTTP); C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe [2007-06-20 397312]
                            S3 VAIOMediaPlatform-UCLS-UPnP;VAIO Media Content Collection (UPnP); C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe [2007-06-20 1089536]
                            S3 VcmIAlzMgr;VAIO Content Metadata Intelligent Analyzing Manager; C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe [2007-07-05 292152]
                            S3 VcmXmlIfHelper;VAIO Content Metadata XML Interface; C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper.exe [2007-07-05 79736]

                            -----------------EOF-----------------
                            0
                            1. Contributeur sécurité
                              ok

                              plusieurs infections

                              Téléchargez USBFIX de Chiquitine29, C_xx

                              http://pagesperso-orange.fr/NosTools/Chiquitine29/UsbFix.exe
                              ou
                              https://www.ionos.fr/?affiliate_id=77097

                              /!\ Utilisateur de vista et windows 7 :
                              ne pas oublier de désactiver Le contrôle des comptes utilisateurs
                              https://www.commentcamarche.net/faq/8343-vista-desactiver-l-uac

                              /!\ Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptible d'avoir été infectées sans les ouvrir

                              • Double clic sur le raccourci UsbFix présent sur le bureau .

                              • Choisir l'option 1 (Recherche)
                              (d’autres options disponibles, voir le tutoriel).
                              • Laissez travailler l'outil.

                              • Ensuite postez le rapport UsbFix.txt qui apparaîtra.

                              • Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque. ( C:\UsbFix.txt )

                              ( CTRL+A Pour tout sélectionner , CTRL+C pour copier et CTRL+V pour coller )

                              • Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
                              Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
                              Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.

                              • Tuto : http://pagesperso-orange.fr/NosTools/usbfix.html

                              0
                              1. voilà

                                User : LES LEVOYER'S (Administrateurs) # LES_LEVOYERS
                                Update on 18/12/2009 by Chiquitine29, C_XX & Chimay8
                                Start at: 14:51:33 | 19/12/2009
                                Website : http://pagesperso-orange.fr/NosTools/index.html
                                Contact : FindyKill.Contact@gmail.com

                                Intel(R) Core(TM)2 Duo CPU T7250 @ 2.00GHz
                                Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6002 32-bit) # Service Pack 2
                                Internet Explorer 7.0.6002.18005
                                Windows Firewall Status : Enabled

                                C:\ -> Disque fixe local # 140,07 Go (56,58 Go free) # NTFS
                                D:\ -> Disque amovible
                                E:\ -> Disque amovible
                                F:\ -> Disque CD-ROM
                                G:\ -> Disque amovible # 977,72 Mo (973,98 Mo free) [CORSAIR] # FAT
                                H:\ -> Disque fixe local # 232,83 Go (91,42 Go free) [My Passport] # FAT32
                                I:\ -> Disque amovible # 3,91 Go (2,77 Go free) # FAT32

                                ############################## | Processus actifs |

                                C:\Windows\System32\smss.exe 420
                                C:\Windows\system32\csrss.exe 620
                                C:\Windows\system32\wininit.exe 664
                                C:\Windows\system32\csrss.exe 676
                                C:\Windows\system32\services.exe 712
                                C:\Windows\system32\lsass.exe 728
                                C:\Windows\system32\lsm.exe 736
                                C:\Windows\system32\winlogon.exe 812
                                C:\Windows\system32\svchost.exe 924
                                C:\Windows\system32\svchost.exe 996
                                C:\Windows\System32\svchost.exe 1040
                                C:\Windows\System32\svchost.exe 1136
                                C:\Windows\System32\svchost.exe 1172
                                C:\Windows\system32\svchost.exe 1204
                                C:\Windows\system32\SLsvc.exe 1336
                                C:\Windows\system32\svchost.exe 1396
                                C:\Windows\system32\svchost.exe 1512
                                C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe 1644
                                C:\Program Files\Alwil Software\Avast4\ashServ.exe 1660
                                C:\Windows\System32\spoolsv.exe 1976
                                C:\Windows\system32\svchost.exe 2000
                                C:\Windows\system32\taskeng.exe 1476
                                C:\Windows\system32\Dwm.exe 1524
                                C:\Windows\system32\taskeng.exe 1928
                                C:\Windows\Explorer.EXE 1100
                                C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe 2176
                                C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe 2236
                                C:\Program Files\Bonjour\mDNSResponder.exe 2248
                                C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe 2320
                                C:\Windows\system32\svchost.exe 2360
                                C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe 2468
                                C:\Windows\system32\svchost.exe 2536
                                C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe 2572
                                C:\Program Files\Sony\VAIO Event Service\VESMgr.exe 2680
                                C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe 2732
                                C:\Windows\system32\taskeng.exe 2740
                                C:\Windows\System32\svchost.exe 2780
                                C:\Program Files\Winsudate\gibsvc.exe 2808
                                C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe 2848
                                C:\Windows\system32\SearchIndexer.exe 2872
                                C:\Program Files\Sony\VAIO Update 3\VAIOUpdt.exe 2904
                                C:\Windows\system32\DRIVERS\xaudio.exe 2948
                                C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe 3000
                                C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe 3088
                                C:\Program Files\Sony\VAIO Event Service\VESMgrSub.exe 3196
                                C:\Windows\system32\WUDFHost.exe 3336
                                C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe 3376
                                C:\Program Files\Alwil Software\Avast4\ashWebSv.exe 3404
                                C:\Windows\system32\igfxext.exe 3432
                                C:\Windows\system32\igfxsrvc.exe 3468
                                C:\Program Files\Windows Defender\MSASCui.exe 3956
                                C:\Program Files\Synaptics\SynTP\SynTPEnh.exe 3996
                                C:\Windows\System32\igfxpers.exe 4048
                                C:\Program Files\Sony\ISB Utility\ISBMgr.exe 4060
                                C:\Program Files\Search Settings\SearchSettings.exe 2092
                                C:\Program Files\iTunes\iTunesHelper.exe 1768
                                C:\Program Files\Alwil Software\Avast4\ashDisp.exe 708
                                C:\Program Files\Java\jre6\bin\jusched.exe 2512
                                C:\Windows\ehome\ehtray.exe 980
                                C:\Program Files\Windows Sidebar\sidebar.exe 852
                                C:\Program Files\Windows Media Player\wmpnscfg.exe 2660
                                C:\Program Files\Winsudate\gibusr.exe 308
                                C:\Program Files\Picasa2\PicasaMediaDetector.exe 3012
                                C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe 2928
                                C:\Program Files\SkypeMate\SkypeMate.exe 3444
                                C:\Program Files\OpenOffice.org 3\program\soffice.exe 2664
                                C:\Windows\system32\igfxsrvc.exe 2116
                                C:\Windows\ehome\ehmsas.exe 3984
                                C:\Program Files\OpenOffice.org 3\program\soffice.bin 2632
                                C:\Program Files\Windows Media Player\wmpnetwk.exe 3776
                                C:\Program Files\Sony\VAIO Power Management\SPMgr.exe 4444
                                C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe 4460
                                C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe 4632
                                C:\Windows\system32\wbem\unsecapp.exe 4672
                                C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe 4780
                                C:\Windows\system32\wbem\wmiprvse.exe 4880
                                C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosAVRC.exe 4992
                                C:\Program Files\iPod\bin\iPodService.exe 5140
                                C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe 5576
                                C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtProc.exe 6036
                                C:\Program Files\Internet Explorer\ieuser.exe 4240
                                C:\Windows\system32\msiexec.exe 6104
                                C:\Program Files\Internet Explorer\iexplore.exe 656
                                C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe 4848
                                C:\Program Files\Windows Live\Toolbar\wltuser.exe 4600
                                C:\Windows\system32\Macromed\Flash\FlashUtil10c.exe 3916
                                C:\Windows\servicing\TrustedInstaller.exe 4548
                                C:\Windows\system32\conime.exe 4364
                                C:\Windows\system32\taskeng.exe 5476
                                \\?\C:\Windows\system32\wbem\WMIADAP.EXE 3788
                                C:\Windows\system32\wbem\wmiprvse.exe 5332

                                ################## | Fichiers # Dossiers infectieux |

                                G:\autorun.0nf
                                H:\autorun.inf

                                ################## | Registre # Clés infectieuses |

                                ################## | Registre # Mountpoints2 |

                                HKCU\..\..\Explorer\MountPoints2\{0a21c760-839e-11dd-ad99-001bfbcd081f}
                                shell\AutoRun\command =C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL XOAUsUf.EXe

                                HKCU\..\..\Explorer\MountPoints2\{f7ebe47c-0356-11de-8730-001bfbcd081f}
                                shell\Auto\command =RavMonE.exe e
                                shell\AutoRun\command =C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RavMonE.exe e

                                ################## | Cracks / Keygens / Serials |

                                ################## | ! Fin du rapport # UsbFix V6.065 ! |
                                0
                                1. Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
                                  Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
                                  Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.

                                  je fais quoi avec ça
                                  0
                                  1. tu as rien aqrandre si tu les mis en qarantien
                                    0
                                    • 1
                                    • 2
                                    • 3
                                    • 4