TR/Vundo.Gen pourrit l'existence

Résolu
Papillon_des_neiges Messages postés 12 Statut Membre -  
Papillon_des_neiges Messages postés 12 Statut Membre -
Bonjour,

Je me trouve aujourd'hui avec un problème de cheval de troie (TR/Vundo.Gen) que je n'arrive pas à résoudre seul. Mes connaissances informatiques sont tout de même basiques.
J'ai découvert fin novembre 2009 que j'avais un cheval de troie sur mon ordi. Malgré tout ce que j'ai essayé, je n'arrive pas a le faire partir.

Je vous laisse donc mon Hijack, en espérant que vous allez pouvoir m'aider car je ne sais plus quoi faire.
Merci beaucoup d'avance.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:07:01, on 20/12/2009
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18865)
Boot mode: Normal

Running processes:
C:\Windows\System32\smss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\AUDIODG.EXE
C:\Windows\system32\svchost.exe
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\ZoneLabs\vsmon.exe
C:\Windows\System32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\agrsmsvc.exe
C:\Program Files\Dassault Systemes\B16\intel_a\code\bin\CATSysDemon.exe
C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
C:\Acer\Empowering Technology\eNet\eNet Service.exe
C:\Windows\system32\svchost.exe
c:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Acer\Mobility Center\MobilityService.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\SearchIndexer.exe
C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
C:\Acer\Empowering Technology\ePower\ePowerSvc.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\System32\alg.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Launch Manager\OSDCtrl.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Windows\ehome\ehtray.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\ma-config.com\maconfservice.exe
C:\Acer\Empowering Technology\eRecovery\eRAgent.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\PROGRA~1\GLARYU~1\shredder.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\System32\mspaint.exe
C:\PROGRA~1\GLARYU~1\gsd.exe
C:\Program Files\Windows Mail\WinMail.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\system32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: NetXfer - {83B80A9C-D91A-4F22-8DCF-EA7204039F79} - C:\Program Files\Xi\NetXfer\NXIEHelper.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll
O3 - Toolbar: NetXfer - {C16CBAAC-A75C-4DB5-A0DD-CDF5CAFCDD3A} - C:\Program Files\Xi\NetXfer\NXToolBar.dll
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [LMgrOSD] "C:\Program Files\Launch Manager\OSDCtrl.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [USB2Check] RUNDLL32.EXE "C:\Windows\system32\PCLECoInst.dll",CheckUSBController
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - Global Startup: Empowering Technology Launcher.lnk = C:\Acer\Empowering Technology\eAPLauncher.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Tout télécharger avec Free Download Manager - file://D:\Free Download Manager\dlall.htm
O8 - Extra context menu item: Tout télécharger avec NetXfer - C:\Program Files\Xi\NetXfer\NXAddList.html
O8 - Extra context menu item: Télécharger avec Free Download Manager - file://D:\Free Download Manager\dllink.htm
O8 - Extra context menu item: Télécharger avec NetXfer - C:\Program Files\Xi\NetXfer\NXAddLink.html
O8 - Extra context menu item: Télécharger la sélection avec Free Download Manager - file://D:\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Télécharger la vidéo avec Free Download Manager - file://D:\Free Download Manager\dlfvideo.htm
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\program files\hummingbird\connectivity\11.00\exceed\humshmx.dll
O10 - Unknown file in Winsock LSP: c:\program files\hummingbird\connectivity\11.00\exceed\humshmx.dll
O10 - Unknown file in Winsock LSP: c:\program files\hummingbird\connectivity\11.00\exceed\humshmx.dll
O15 - Trusted Zone: http://www.tellmemorecampus.com
O15 - Trusted Zone: http://www3.tellmemorecampus.com
O15 - Trusted Zone: http://www.tellmemorecampus.com (HKLM)
O15 - Trusted Zone: http://www3.tellmemorecampus.com (HKLM)
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - (no file)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: Backbone Service (BBDemon) - Dassault Systemes - C:\Program Files\Dassault Systemes\B16\intel_a\code\bin\CATSysDemon.exe
O23 - Service: eDSService.exe (eDataSecurity Service) - HiTRSUT - C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
O23 - Service: eNet Service - Acer Inc. - C:\Acer\Empowering Technology\eNet\eNet Service.exe
O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
O23 - Service: eSettings Service (eSettingsService) - Unknown owner - C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
O23 - Service: Service Google Update (gupdate1c9d6f5d4e428f5) (gupdate1c9d6f5d4e428f5) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
O23 - Service: PCLEPCI - Pinnacle Systems GmbH - C:\Windows\system32\drivers\pclepci.sys
O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\Windows\System32\ZoneLabs\vsmon.exe
O23 - Service: WisLMSvc - Wistron Corp. - C:\Program Files\Launch Manager\WisLMSvc.exe
O23 - Service: ePower Service (WMIService) - acer - C:\Acer\Empowering Technology\ePower\ePowerSvc.exe

--
End of file - 10421 bytes
Configuration: Windows Vista - Edition Familiale Premium - SP2
Firefox 3.0.16
Avira Antivir Personal et Zonealarm

19 réponses

  1. Utilisateur anonyme
     
    Bonjour,
    Télécharge Random's System Information Tool (RSIT) : http://images.malwareremoval.com/random/RSIT.exe par random/random et sauvegarde-le sur ton Bureau.

    Important (Sous Vista)

    tu dois exécuter RSIT avec les droits d'administrateur, pour cela Clic droit sur RSIT et "Lances en tant qu'administrateur"

    ==> Double-clique sur RSIT.exe afin de lancer RSIT.
    ==> Clique sur Continue à l'écran Disclaimer.
    ==> Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera et tu devras accepter la licence.
    ==>Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront.

    ==> Poste le contenu des deux rapports ==> log.txt (<==qui sera affiché) ainsi que de info.txt (<==qui sera réduit dans la Barre des Tâches).

    Note : Les deux rapports sont également sauvegardés %systemroot%\rsit
    1
  2. Papillon_des_neiges Messages postés 12 Statut Membre
     
    J'ai beaucoup de services (quand je fais ctr+alt+suppr) qui sont arretés et impossibles à relancer, du genre Antivir ! live update ! etc...je n'ai plus de points de restauration et ne peux en créer ! Bref, je suis vraiment dans l'impasse, je crois. Voici les deux rapports demandés (RSIT) :

    Logfile of random's system information tool 1.06 (written by random/random)
    Run by SaMi at 2009-12-20 17:24:31
    Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 2
    System drive C: has 17 GB (23%) free of 72 GB
    Total RAM: 2045 MB (62% free)

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 17:24:56, on 20/12/2009
    Platform: Windows Vista SP2 (WinNT 6.00.1906)
    MSIE: Internet Explorer v8.00 (8.00.6001.18865)
    Boot mode: Normal

    Running processes:
    C:\Windows\system32\taskeng.exe
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\Launch Manager\OSDCtrl.exe
    C:\Program Files\Microsoft IntelliPoint\ipoint.exe
    C:\Windows\ehome\ehtray.exe
    C:\Windows\ehome\ehmsas.exe
    C:\Windows\system32\wbem\unsecapp.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Users\SaMi\Desktop\RSIT.exe
    C:\Windows\system32\SearchFilterHost.exe
    C:\Program Files\Trend Micro\HijackThis\SaMi.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
    O2 - BHO: NetXfer - {83B80A9C-D91A-4F22-8DCF-EA7204039F79} - C:\Program Files\Xi\NetXfer\NXIEHelper.dll
    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll
    O3 - Toolbar: NetXfer - {C16CBAAC-A75C-4DB5-A0DD-CDF5CAFCDD3A} - C:\Program Files\Xi\NetXfer\NXToolBar.dll
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [LMgrOSD] "C:\Program Files\Launch Manager\OSDCtrl.exe"
    O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
    O4 - HKLM\..\Run: [USB2Check] RUNDLL32.EXE "C:\Windows\system32\PCLECoInst.dll",CheckUSBController
    O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
    O4 - Global Startup: Empowering Technology Launcher.lnk = C:\Acer\Empowering Technology\eAPLauncher.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
    O8 - Extra context menu item: Tout télécharger avec Free Download Manager - file://D:\Free Download Manager\dlall.htm
    O8 - Extra context menu item: Tout télécharger avec NetXfer - C:\Program Files\Xi\NetXfer\NXAddList.html
    O8 - Extra context menu item: Télécharger avec Free Download Manager - file://D:\Free Download Manager\dllink.htm
    O8 - Extra context menu item: Télécharger avec NetXfer - C:\Program Files\Xi\NetXfer\NXAddLink.html
    O8 - Extra context menu item: Télécharger la sélection avec Free Download Manager - file://D:\Free Download Manager\dlselected.htm
    O8 - Extra context menu item: Télécharger la vidéo avec Free Download Manager - file://D:\Free Download Manager\dlfvideo.htm
    O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
    O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O10 - Unknown file in Winsock LSP: c:\program files\hummingbird\connectivity\11.00\exceed\humshmx.dll
    O10 - Unknown file in Winsock LSP: c:\program files\hummingbird\connectivity\11.00\exceed\humshmx.dll
    O10 - Unknown file in Winsock LSP: c:\program files\hummingbird\connectivity\11.00\exceed\humshmx.dll
    O15 - Trusted Zone: http://www.tellmemorecampus.com
    O15 - Trusted Zone: http://www3.tellmemorecampus.com
    O15 - Trusted Zone: http://www.tellmemorecampus.com (HKLM)
    O15 - Trusted Zone: http://www3.tellmemorecampus.com (HKLM)
    O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - (no file)
    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
    O23 - Service: Backbone Service (BBDemon) - Dassault Systemes - C:\Program Files\Dassault Systemes\B16\intel_a\code\bin\CATSysDemon.exe
    O23 - Service: eDSService.exe (eDataSecurity Service) - HiTRSUT - C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
    O23 - Service: eNet Service - Acer Inc. - C:\Acer\Empowering Technology\eNet\eNet Service.exe
    O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
    O23 - Service: eSettings Service (eSettingsService) - Unknown owner - C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
    O23 - Service: Service Google Update (gupdate1c9d6f5d4e428f5) (gupdate1c9d6f5d4e428f5) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
    O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
    O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
    O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
    O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
    O23 - Service: PCLEPCI - Pinnacle Systems GmbH - C:\Windows\system32\drivers\pclepci.sys
    O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\Windows\System32\ZoneLabs\vsmon.exe
    O23 - Service: WisLMSvc - Wistron Corp. - C:\Program Files\Launch Manager\WisLMSvc.exe
    O23 - Service: ePower Service (WMIService) - acer - C:\Acer\Empowering Technology\ePower\ePowerSvc.exe
    0
  3. Utilisateur anonyme
     
    Suis les étapes :

    1. Désactive l'uac ! : https://forum.malekal.com/viewtopic.php?t=6517&start=

    2.

    Desactive ton antivirus le temps de la manip ainsi que ton parefeu si présent

    ▶ Télécharge List&Kill'em et enregistre le sur ton bureau

    ▶ dezippe-le , (clic droit/ extraire.....)

    Il ne necessite pas d'installation

    ▶ double clic (clic droit "executer en tant qu'administrateur" pour Vista) pour lancer le scan

    choisis la langue puis choisis l'option 1 = Mode Recherche

    ▶ laisse travailler l'outil

    un rapport du nom de catchme apparait sur ton bureau , ignore-le , mais ne le supprime pas pour l instant

    ▶ Poste le contenu du rapport qui s'ouvre
    0
  4. Papillon_des_neiges Messages postés 12 Statut Membre
     
    Il reste la fin qui n'est pas passée :
    Microsoft Office Proofing (English) 2007-->MsiExec.exe /X{90120000-002C-0409-0000-0000000FF1CE}
    Microsoft Office Proofing (French) 2007-->MsiExec.exe /X{90120000-002C-040C-0000-0000000FF1CE}
    Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0401-0000-0000000FF1CE} /uninstall {14809F99-C601-4D4A-9391-F1E8FAA964C5}
    Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0401-0000-0000000FF1CE} /uninstall {14809F99-C601-4D4A-9391-F1E8FAA964C5}
    Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0401-0000-0000000FF1CE} /uninstall {14809F99-C601-4D4A-9391-F1E8FAA964C5}
    Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0407-0000-0000000FF1CE} /uninstall {A0516415-ED61-419A-981D-93596DA74165}
    Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0407-0000-0000000FF1CE} /uninstall {A0516415-ED61-419A-981D-93596DA74165}
    Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0407-0000-0000000FF1CE} /uninstall {A0516415-ED61-419A-981D-93596DA74165}
    Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {ABDDE972-355B-4AF1-89A8-DA50B7B5C045}
    Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {ABDDE972-355B-4AF1-89A8-DA50B7B5C045}
    Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {ABDDE972-355B-4AF1-89A8-DA50B7B5C045}
    Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {ABDDE972-355B-4AF1-89A8-DA50B7B5C045}
    Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {ABDDE972-355B-4AF1-89A8-DA50B7B5C045}
    Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {ABDDE972-355B-4AF1-89A8-DA50B7B5C045}
    Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-040C-0000-0000000FF1CE} /uninstall {F580DDD5-8D37-4998-968E-EBB76BB86787}
    Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-040C-0000-0000000FF1CE} /uninstall {F580DDD5-8D37-4998-968E-EBB76BB86787}
    Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-040C-0000-0000000FF1CE} /uninstall {F580DDD5-8D37-4998-968E-EBB76BB86787}
    Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-040C-0000-0000000FF1CE} /uninstall {F580DDD5-8D37-4998-968E-EBB76BB86787}
    Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-040C-0000-0000000FF1CE} /uninstall {F580DDD5-8D37-4998-968E-EBB76BB86787}
    Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-040C-0000-0000000FF1CE} /uninstall {F580DDD5-8D37-4998-968E-EBB76BB86787}
    Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0413-0000-0000000FF1CE} /uninstall {D66D5A44-E480-4BA4-B4F2-C554F6B30EBB}
    Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0413-0000-0000000FF1CE} /uninstall {D66D5A44-E480-4BA4-B4F2-C554F6B30EBB}
    Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0413-0000-0000000FF1CE} /uninstall {D66D5A44-E480-4BA4-B4F2-C554F6B30EBB}
    Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0C0A-0000-0000000FF1CE} /uninstall {187308AB-5FA7-4F14-9AB9-D290383A10D9}
    Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0C0A-0000-0000000FF1CE} /uninstall {187308AB-5FA7-4F14-9AB9-D290383A10D9}
    Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0C0A-0000-0000000FF1CE} /uninstall {187308AB-5FA7-4F14-9AB9-D290383A10D9}
    Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0C0A-0000-0000000FF1CE} /uninstall {187308AB-5FA7-4F14-9AB9-D290383A10D9}
    Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0C0A-0000-0000000FF1CE} /uninstall {187308AB-5FA7-4F14-9AB9-D290383A10D9}
    Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0C0A-0000-0000000FF1CE} /uninstall {187308AB-5FA7-4F14-9AB9-D290383A10D9}
    Microsoft Office Publisher MUI (English) 2007-->MsiExec.exe /X{90120000-0019-0409-0000-0000000FF1CE}
    Microsoft Office Publisher MUI (French) 2007-->MsiExec.exe /X{90120000-0019-040C-0000-0000000FF1CE}
    Microsoft Office Shared MUI (English) 2007-->MsiExec.exe /X{90120000-006E-0409-0000-0000000FF1CE}
    Microsoft Office Shared MUI (French) 2007-->MsiExec.exe /X{90120000-006E-040C-0000-0000000FF1CE}
    Microsoft Office Shared Setup Metadata MUI (English) 2007-->MsiExec.exe /X{90120000-0115-0409-0000-0000000FF1CE}
    Microsoft Office SharePoint Designer 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0017-040C-0000-0000000FF1CE} /uninstall {CCDA3DD6-E33D-4D75-B7C9-FF585580CE83}
    Microsoft Office SharePoint Designer MUI (French) 2007-->MsiExec.exe /X{90120000-0017-040C-0000-0000000FF1CE}
    Microsoft Office Visio 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0051-0000-0000-0000000FF1CE} /uninstall {0FD405D3-CAF8-4CA6-8BFD-911D2F8A6585}
    Microsoft Office Visio 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0054-0409-0000-0000000FF1CE} /uninstall {519D9F45-CBF4-4E57-B419-11F196CCA8AE}
    Microsoft Office Visio 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0054-040C-0000-0000000FF1CE} /uninstall {7EC87B94-B9A7-4C72-9C55-21C1C9DEE3C5}
    Microsoft Office Visio 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0055-040C-0000-0000000FF1CE} /uninstall {7EC87B94-B9A7-4C72-9C55-21C1C9DEE3C5}
    Microsoft Office Visio Language Pack 2007 - French/Français-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall VISMUI.FR-FR /dll OSETUP.DLL
    Microsoft Office Visio MUI (English) 2007-->MsiExec.exe /X{90120000-0054-0409-0000-0000000FF1CE}
    Microsoft Office Visio MUI (French) 2007-->MsiExec.exe /X{90120000-0054-040C-0000-0000000FF1CE}
    Microsoft Office Visio Professional 2007-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall VISPRO /dll OSETUP.DLL
    Microsoft Office Visio Professional 2007-->MsiExec.exe /X{90120000-0051-0000-0000-0000000FF1CE}
    Microsoft Office VisMUI (French) 2007-->MsiExec.exe /X{90120000-0055-040C-0000-0000000FF1CE}
    Microsoft Office Word MUI (English) 2007-->MsiExec.exe /X{90120000-001B-0409-0000-0000000FF1CE}
    Microsoft Office Word MUI (French) 2007-->MsiExec.exe /X{90120000-001B-040C-0000-0000000FF1CE}
    Microsoft Office X MUI (French) 2007-->MsiExec.exe /X{90120000-0101-040C-0000-0000000FF1CE}
    Microsoft Silverlight-->MsiExec.exe /I{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
    Microsoft SQL Server 2005 Compact Edition [ENU]-->MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
    Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053-->MsiExec.exe /X{770657D0-A123-3C07-8E44-1C83EC895118}
    Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
    Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148-->MsiExec.exe /X{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17-->MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475}
    Microsoft Visual Studio 2005 Tools for Applications - ENU-->MsiExec.exe /X{D481EA96-2313-4A7C-98EE-710D1AF884AC}
    Microsoft Visual Studio 2005 Tools for Applications - ENU-->MsiExec.exe /X{D481EA96-2313-4A7C-98EE-710D1AF884AC}
    Microsoft Visual Studio 2005 Tools for Applications - FRA-->MsiExec.exe /X{726179B8-DB7D-4D62-9E65-B1E6BB9EB0F7}
    Microsoft Visual Studio 2005 Tools for Applications - FRA-->MsiExec.exe /X{726179B8-DB7D-4D62-9E65-B1E6BB9EB0F7}
    MiKTeX 2.7-->"C:\Program Files\MiKTeX 2.7\miktex\bin\copystart_admin.exe" "C:\Program Files\MiKTeX 2.7\miktex\config\uninstall.dat"
    MinGW 5.1.4-->C:\MinGW\uninst.exe
    Mise à jour Microsoft Office Excel 2007 Help (KB963678)-->msiexec /package {90120000-0016-040C-0000-0000000FF1CE} /uninstall {B761869A-B85C-40E2-994C-A1CE78AC8F2C}
    Mise à jour Microsoft Office Outlook 2007 Help (KB963677)-->msiexec /package {90120000-001A-040C-0000-0000000FF1CE} /uninstall {51EFB347-1F3D-4BAC-8B79-F056B904FE21}
    Mise à jour Microsoft Office Powerpoint 2007 Help (KB963669)-->msiexec /package {90120000-0018-040C-0000-0000000FF1CE} /uninstall {C3DCA38E-005E-41BA-A52A-7C3429F351C3}
    Mise à jour Microsoft Office Word 2007 Help (KB963665)-->msiexec /package {90120000-001B-040C-0000-0000000FF1CE} /uninstall {81536A04-DBFB-4DB3-978F-0F284590C223}
    Module linguistique Microsoft .NET Framework 3.5 SP1- fra-->C:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 Language Pack SP1 - fra\setup.exe
    Mozilla Firefox (3.0.16)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
    MP3 CD Converter 4.00-->"C:\Program Files\MP3 CD Converter\unins000.exe"
    MP3 Player Utilities-->MsiExec.exe /I{5BBFB0E4-2250-49C3-A8A3-65BE2197D13B}
    MSVC80_x86_v2-->MsiExec.exe /I{6D3245B1-8DB8-4A23-9CD2-2C90F40ABAF6}
    MSVC80_x86-->MsiExec.exe /I{212748BB-0DA5-46DE-82A1-403736DC9F27}
    MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
    MSXML 4.0 SP2 (KB927978)-->MsiExec.exe /I{37477865-A3F1-4772-AD43-AAFC6BCFF99F}
    MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
    MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
    MSXML 4.0 SP2 (KB973688)-->MsiExec.exe /I{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
    MSXML 4.0 SP2 Parser and SDK-->MsiExec.exe /I{716E0306-8318-4364-8B8F-0CC4E9376BAC}
    MusicIP Mixer 1.8.1-->"C:\Program Files\MusicIP\MusicIP Mixer\unins000.exe"
    MusicIP Mixer Language Pack 1.8-->"C:\Program Files\MusicIP\MusicIP Mixer\unins001.exe"
    MusicIP MyDJ iTunes Plugin 1.0-->"C:\Program Files\MusicIP\MusicIP MyDJ iTunes Plugin (1.0)\uninstall.exe"
    Nero Digital-->C:\Windows\UNNeroVision.exe /UNINSTALL
    NetXfer 2.52.386-->"C:\Program Files\Xi\NetXfer\unins000.exe"
    Nokia Connectivity Cable Driver-->MsiExec.exe /I{6869591A-7DD8-46D2-837F-57CBF7358955}
    Nokia PC Suite-->C:\ProgramData\Installations\{9249D7E7-33E7-4CC8-BB0B-3DF3C3CB2568}\Nokia_PC_Suite_7_1_40_1_fre.exe
    Nokia PC Suite-->MsiExec.exe /I{9249D7E7-33E7-4CC8-BB0B-3DF3C3CB2568}
    Notepad++-->C:\Program Files\Notepad++\uninstall.exe
    NTI Backup NOW! 4.7-->"C:\Program Files\InstallShield Installation Information\{67ADE9AF-5CD9-4089-8825-55DE4B366799}\setup.exe" -removeonly
    NTI CD & DVD-Maker-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{1577A05B-EE62-4BBC-9DB7-FE748FA44EC2} /l1036 CDM7
    OGA Notifier 2.0.0048.0-->MsiExec.exe /I{B2544A03-10D0-4E5E-BA69-0362FFC20D18}
    OpenOffice.org 3.0-->MsiExec.exe /I{6860B340-530D-46B3-91F8-1AE1F70F7C33}
    Outil de mise à jour Google-->"C:\Program Files\Google\Google Updater\GoogleUpdater.exe" -uninstall
    Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
    Package de pilotes Windows - Nokia Modem (06/01/2009 7.01.0.4)-->C:\PROGRA~1\DIFX\270581355A767BF1\dpinst.exe /u C:\Windows\System32\DriverStore\FileRepository\nokbtmdm.inf_3a2e1afb\nokbtmdm.inf
    Package de pilotes Windows - Nokia Modem (10/05/2009 4.2)-->C:\PROGRA~1\DIFX\270581355A767BF1\dpinst.exe /u C:\Windows\System32\DriverStore\FileRepository\nokia_bluetooth.inf_d5bc047a\nokia_bluetooth.inf
    Package de pilotes Windows - Nokia pccsmcfd (08/22/2008 7.0.0.0)-->C:\PROGRA~1\DIFX\B4723E9A0713E5B1\dpinst.exe /u C:\Windows\system32\DRVSTORE\pccsmcfd_A3B3916E5D8138F59EE218321B27B044D3B18294\pccsmcfd.inf
    Paint Shop Pro 7-->MsiExec.exe /I{D6DE02C7-1F47-11D4-9515-00105AE4B89A}
    PC Connectivity Solution-->MsiExec.exe /I{6E0352EE-6F0D-4FBC-B1B8-4FF032C78BE0}
    PDFCreator-->C:\Program Files\PDFCreator\unins000.exe
    Power Video Downloader-->"C:\Windows\Power Video Downloader\uninstall.exe" "/U:C:\Program Files\Power Video Downloader\Uninstall\uninstall.xml"
    PowerProducer-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B7A0CE06-068E-11D6-97FD-0050BACBF861}\Setup.exe" -uninstall
    QuickTime-->MsiExec.exe /I{1451DE6B-ABE1-4F62-BE9A-B363A17588A2}
    Radio Recorder v.1.4-->"C:\Program Files\Radio Recorder v.1.4\unins000.exe"
    Realtek High Definition Audio Driver-->RtlUpd.exe -r -m
    Revo Uninstaller 1.80-->C:\Program Files\VS Revo Group\Revo Uninstaller\uninst.exe
    SeaTools Enterprise-->C:\Windows\uninst.exe -f"C:\Program Files\SeaTools Enterprise\DeIsL1.isu" -c"C:\Program Files\SeaTools Enterprise\_ISREG32.DLL"
    Security Update for 2007 Microsoft Office System (KB969559)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {69F52148-9BF6-4CDC-BF76-103DEAF3DD08}
    Security Update for 2007 Microsoft Office System (KB969559)-->msiexec /package {90120000-003B-0000-0000-0000000FF1CE} /uninstall {69F52148-9BF6-4CDC-BF76-103DEAF3DD08}
    Security Update for 2007 Microsoft Office System (KB969559)-->msiexec /package {90120000-0051-0000-0000-0000000FF1CE} /uninstall {69F52148-9BF6-4CDC-BF76-103DEAF3DD08}
    Security Update for 2007 Microsoft Office System (KB973704)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {E626DC89-A787-4553-9BB3-DC2EC7E1593F}
    Security Update for Microsoft Office Excel 2007 (KB973593)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {7D6255E3-3423-4D8B-A328-F6F8D28DD5FE}
    Security Update for Microsoft Office Outlook 2007 (KB972363)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {120BE9A0-9B09-4855-9E0C-7DEE45CB03C0}
    Security Update for Microsoft Office PowerPoint 2007 (KB957789)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {7559E742-FF9F-4FAE-B279-008ED296CB4D}
    Security Update for Microsoft Office Publisher 2007 (KB969693)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {7BE67088-1EB3-4569-8E75-DDAFBF61BC4E}
    Security Update for Microsoft Office system 2007 (972581)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {3D019598-7B59-447A-80AE-815B703B84FF}
    Security Update for Microsoft Office system 2007 (972581)-->msiexec /package {90120000-003B-0000-0000-0000000FF1CE} /uninstall {3D019598-7B59-447A-80AE-815B703B84FF}
    Security Update for Microsoft Office system 2007 (972581)-->msiexec /package {90120000-0051-0000-0000-0000000FF1CE} /uninstall {3D019598-7B59-447A-80AE-815B703B84FF}
    Security Update for Microsoft Office system 2007 (KB969613)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {5ECEB317-CBE9-4E08-AB10-756CB6F0FB6C}
    Security Update for Microsoft Office system 2007 (KB974234)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {FCD742B9-7A55-44BC-A776-F795F21FEDDC}
    Security Update for Microsoft Office system 2007 (KB974234)-->msiexec /package {90120000-003B-0000-0000-0000000FF1CE} /uninstall {FCD742B9-7A55-44BC-A776-F795F21FEDDC}
    Security Update for Microsoft Office system 2007 (KB974234)-->msiexec /package {90120000-0051-0000-0000-0000000FF1CE} /uninstall {FCD742B9-7A55-44BC-A776-F795F21FEDDC}
    Security Update for Microsoft Office Visio Viewer 2007 (KB973709)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {71127777-8B2C-4F97-AF7A-6CF8CAC8224D}
    Skype™ 4.0-->MsiExec.exe /X{24D753CA-6AE9-4E30-8F5F-EFC93E08BF3D}
    Sleepy-->"C:\Program Files\Sleepy\uninstall.exe"
    Spelling Dictionaries Support For Adobe Reader 9-->MsiExec.exe /I{AC76BA86-7AD7-5464-3428-900000000004}
    StationRipper V1.13-->C:\Program Files\Ratajik Software\StationRipper\uninst.exe
    STOIK Video Converter 2-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A8DF8593-F619-47DE-AD27-BCABF233433A}\setup.exe" -l0x9 -removeonly
    Subtitle Workshop 2.51-->"C:\Program Files\URUSoft\Subtitle Workshop\uninstall.exe"
    Suppress plus 1.8-->"C:\Program Files\splus\unins000.exe"
    syn Version 2.1.0.43-->"C:\Program Files\Syn Text Editor\unins000.exe"
    Synaptics Pointing Device Driver-->rundll32.exe "C:\Program Files\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall
    System Requirements Lab-->C:\Program Files\SystemRequirementsLab\Uninstall.exe
    TBS WMP Plug-in-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\1050\INTEL3~1\IDriver.exe /M{13515135-48BB-4184-8C1F-2FAE0138E200}
    Texas Instruments PCIxx21/x515/xx12 drivers.-->C:\Program Files\InstallShield Installation Information\{F7B05784-334C-4F76-8BAB-30ABEB7FD534}\setup.exe -runfromtemp -l0x0409
    Uniblue RegistryBooster 2010-->"C:\Program Files\Uniblue\RegistryBooster\unins000.exe"
    Update for 2007 Microsoft Office System (KB967642)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {C444285D-5E4F-48A4-91DD-47AAAA68E92D}
    Update for 2007 Microsoft Office System (KB967642)-->msiexec /package {90120000-003B-0000-0000-0000000FF1CE} /uninstall {C444285D-5E4F-48A4-91DD-47AAAA68E92D}
    Update for 2007 Microsoft Office System (KB967642)-->msiexec /package {90120000-0051-0000-0000-0000000FF1CE} /uninstall {C444285D-5E4F-48A4-91DD-47AAAA68E92D}
    Update for Microsoft .NET Framework 3.5 SP1 (KB963707)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {B2AE9C82-DC7B-3641-BFC8-87275C4F3607} /qb+ REBOOTPROMPT=""
    Update for Microsoft Office 2007 Help for Common Features (KB963673)-->msiexec /package {90120000-006E-0409-0000-0000000FF1CE} /uninstall {AB365889-0395-4FAD-B702-CA5985D53D42}
    Update for Microsoft Office 2007 Help for Common Features (KB963673)-->msiexec /package {90120000-006E-0409-0000-0000000FF1CE} /uninstall {AB365889-0395-4FAD-B702-CA5985D53D42}
    Update for Microsoft Office 2007 Help for Common Features (KB963673)-->msiexec /package {90120000-006E-0409-0000-0000000FF1CE} /uninstall {AB365889-0395-4FAD-B702-CA5985D53D42}
    Update for Microsoft Office Access 2007 Help (KB963663)-->msiexec /package {90120000-0015-0409-0000-0000000FF1CE} /uninstall {6B76A18A-AA1E-42AB-A7AD-6C84BBB43987}
    Update for Microsoft Office Excel 2007 Help (KB963678)-->msiexec /package {90120000-0016-0409-0000-0000000FF1CE} /uninstall {199DF7B6-169C-448C-B511-1054101BE9C9}
    Update for Microsoft Office InfoPath 2007 (KB976416)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {432C5EE4-8096-4FF1-95E1-65219365DFF7}
    Update for Microsoft Office Infopath 2007 Help (KB963662)-->msiexec /package {90120000-0044-0409-0000-0000000FF1CE} /uninstall {716B81B8-B13C-41DF-8EAC-7A2F656CAB63}
    Update for Microsoft Office OneNote 2007 Help (KB963670)-->msiexec /package {90120000-00A1-0409-0000-0000000FF1CE} /uninstall {2744EF05-38E1-4D5D-B333-E021EDAEA245}
    Update for Microsoft Office Outlook 2007 Help (KB963677)-->msiexec /package {90120000-001A-0409-0000-0000000FF1CE} /uninstall {0451F231-E3E3-4943-AB9F-58EB96171784}
    Update for Microsoft Office Powerpoint 2007 Help (KB963669)-->msiexec /package {90120000-0018-0409-0000-0000000FF1CE} /uninstall {397B1D4F-ED7B-4ACA-A637-43B670843876}
    Update for Microsoft Office Project 2007 Help (KB963668)-->msiexec /package {90120000-00B4-0409-0000-0000000FF1CE} /uninstall {1DF07773-4289-4998-BC2C-83539AD85C50}
    Update for Microsoft Office Publisher 2007 Help (KB963667)-->msiexec /package {90120000-0019-0409-0000-0000000FF1CE} /uninstall {2E40DE55-B289-4C8B-8901-5D369B16814F}
    Update for Microsoft Office Script Editor Help (KB963671)-->msiexec /package {90120000-006E-0409-0000-0000000FF1CE} /uninstall {CD11C6A2-FFC6-4271-8EAB-79C3582F505C}
    Update for Microsoft Office Script Editor Help (KB963671)-->msiexec /package {90120000-006E-0409-0000-0000000FF1CE} /uninstall {CD11C6A2-FFC6-4271-8EAB-79C3582F505C}
    Update for Microsoft Office Script Editor Help (KB963671)-->msiexec /package {90120000-006E-0409-0000-0000000FF1CE} /uninstall {CD11C6A2-FFC6-4271-8EAB-79C3582F505C}
    Update for Microsoft Office Visio 2007 Help (KB963666)-->msiexec /package {90120000-0054-0409-0000-0000000FF1CE} /uninstall {D2C4ACC9-12F5-4E1C-81A8-5DC878AC6278}
    Update for Microsoft Office Word 2007 (KB974561)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {0CDDBAA2-2111-4A0E-A1B0-76C40C635331}
    Update for Microsoft Office Word 2007 Help (KB963665)-->msiexec /package {90120000-001B-0409-0000-0000000FF1CE} /uninstall {80E762AA-C921-4839-9D7D-DB62A72C0726}
    Update for Outlook 2007 Junk Email Filter (kb976884)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {FB60F280-C70F-4174-BADB-471412AA42F0}
    VC80CRTRedist - 8.0.50727.762-->MsiExec.exe /I{767CC44C-9BBC-438D-BAD3-FD4595DD148B}
    VideoLAN VLC media player 0.8.6d-->C:\Program Files\VideoLAN\VLC\uninstall.exe
    Vimeo Video Downloader 3.14-->"C:\Program Files\DownloadToolz\Vimeo Video Downloader\unins000.exe"
    Virtual-DivX 1.00-->"C:\Virtual-DivX\uninstall.exe"
    VueScan-->C:\VueScan\vuescan.exe /remove
    Winamp-->"C:\Program Files\Winamp\UninstWA.exe"
    Windows Live Call-->MsiExec.exe /I{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}
    Windows Live Communications Platform-->MsiExec.exe /I{3B4E636E-9D65-4D67-BA61-189800823F52}
    Windows Live Messenger-->MsiExec.exe /X{059C042E-796A-4ACC-A81A-ECC2010BB78C}
    Windows Live Movie Maker Bêta-->MsiExec.exe /X{F874DF52-A31F-44C1-A606-EF40F1549261}
    Windows Live Sync-->MsiExec.exe /X{9C5EB781-0D37-44B8-9A58-77B3E4BF5F5E}
    Windows Live Writer-->MsiExec.exe /X{2231CE39-B963-4B9D-823A-F412ECA637B1}
    Windows Media Player Firefox Plugin-->MsiExec.exe /I{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}
    Windows Movie Maker 2.6-->MsiExec.exe /X{B3DAF54F-DB25-4586-9EF1-96D24BB14088}
    WinImage-->"C:\Program Files\WinImage\winimage.exe" /uninstall
    XnView 1.92-->"C:\Program Files\XnView\unins000.exe"
    ZHPDiag 1.24-->"C:\Program Files\ZHPDiag\unins000.exe"
    ZoneAlarm-->C:\Program Files\Zone Labs\ZoneAlarm\zauninst.exe

    ======Hosts File======

    127.0.0.1 www.007guard.com
    127.0.0.1 007guard.com
    127.0.0.1 008i.com
    127.0.0.1 www.008k.com
    127.0.0.1 008k.com
    127.0.0.1 www.00hq.com
    127.0.0.1 00hq.com
    127.0.0.1 010402.com
    127.0.0.1 www.032439.com
    127.0.0.1 032439.com

    ======Security center information======

    FW: ZoneAlarm Firewall
    AS: Spybot - Search and Destroy (disabled) (outdated)
    AS: Windows Defender

    ======System event log======

    Computer Name: Sami
    Event Code: 412
    Message: Le service du Planificateur de tâches n'a pas pu lancer les tâches déclenchées par le démarrage de l'ordinateur. Données supplémentaires : Valeur de l'erreur : 2147549183. Action de l'utilisateur : redémarrer le service du Planificateur de tâches.
    Record Number: 908211
    Source Name: Microsoft-Windows-TaskScheduler
    Time Written: 20091220152642.396502-000
    Event Type: Erreur
    User: AUTORITE NT\SYSTEM

    Computer Name: Sami
    Event Code: 2511
    Message: Le service Serveur n'a pas pu recréer le partage LEFT 4 DEAD. FRENCH . PCDVD .(2008).by AkTivisT car le répertoire D:\Jeux Dossiers Installation\LEFT 4 DEAD\LEFT 4 DEAD.[FRENCH].[PCDVD].(2008).by AkTivisT n'existe plus. Veuillez exécuter "netshare LEFT 4 DEAD. FRENCH . PCDVD .(2008).by AkTivisT/supprimer" pour supprimer le partage ou recréer le répertoire D:\Jeux Dossiers Installation\LEFT 4 DEAD\LEFT 4 DEAD.[FRENCH].[PCDVD].(2008).by AkTivisT.
    Record Number: 908210
    Source Name: Server
    Time Written: 20091220152642.000000-000
    Event Type: Avertissement
    User:

    Computer Name: Sami
    Event Code: 2511
    Message: Le service Serveur n'a pas pu recréer le partage film ep car le répertoire C:\Films soirée EP\film ep n'existe plus. Veuillez exécuter "netshare film ep/supprimer" pour supprimer le partage ou recréer le répertoire C:\Films soirée EP\film ep.
    Record Number: 908209
    Source Name: Server
    Time Written: 20091220152642.000000-000
    Event Type: Avertissement
    User:

    Computer Name: Sami
    Event Code: 4001
    Message: Le Service d’autoconfiguration WLAN s’est arrêté correctement.

    Record Number: 908196
    Source Name: Microsoft-Windows-WLAN-AutoConfig
    Time Written: 20091220152447.317930-000
    Event Type: Avertissement
    User: AUTORITE NT\SYSTEM

    Computer Name: Sami
    Event Code: 7034
    Message: Le service eRecovery Service s'est terminé de façon inattendue pour la 1ème fois.
    Record Number: 908176
    Source Name: Service Control Manager
    Time Written: 20091220041655.000000-000
    Event Type: Erreur
    User:

    =====Application event log=====

    Computer Name: Sami
    Event Code: 4113
    Message: AntiVir a détecté dans le fichier C:\Windows\System32\tdlcmd.dll un code suspect avec la désignation 'TR/Vundo.Gen'!
    Record Number: -929730357
    Source Name: Avira AntiVir
    Time Written: 20091220041931.000000-000
    Event Type: Avertissement
    User: AUTORITE NT\SYSTEM

    Computer Name: Sami
    Event Code: 4113
    Message: AntiVir a détecté dans le fichier C:\Windows\System32\tdlcmd.dll un code suspect avec la désignation 'TR/Vundo.Gen'!
    Record Number: -929730358
    Source Name: Avira AntiVir
    Time Written: 20091220041430.000000-000
    Event Type: Avertissement
    User: AUTORITE NT\SYSTEM

    Computer Name: Sami
    Event Code: 4113
    Message: AntiVir a détecté dans le fichier C:\Windows\System32\tdlcmd.dll un code suspect avec la désignation 'TR/Vundo.Gen'!
    Record Number: -929730359
    Source Name: Avira AntiVir
    Time Written: 20091220041200.000000-000
    Event Type: Avertissement
    User: AUTORITE NT\SYSTEM

    Computer Name: Sami
    Event Code: 4113
    Message: AntiVir a détecté dans le fichier C:\Windows\System32\tdlcmd.dll un code suspect avec la désignation 'TR/Vundo.Gen'!
    Record Number: -929730361
    Source Name: Avira AntiVir
    Time Written: 20091220040927.000000-000
    Event Type: Avertissement
    User: AUTORITE NT\SYSTEM

    Computer Name: Sami
    Event Code: 4113
    Message: AntiVir a détecté dans le fichier C:\Windows\System32\tdlcmd.dll un code suspect avec la désignation 'TR/Vundo.Gen'!
    Record Number: -929730362
    Source Name: Avira AntiVir
    Time Written: 20091220040426.000000-000
    Event Type: Avertissement
    User: AUTORITE NT\SYSTEM

    =====Security event log=====

    Computer Name: Sami
    Event Code: 4672
    Message: Privilèges spéciaux attribués à la nouvelle ouverture de session.

    Sujet :
    ID de sécurité : S-1-5-18
    Nom du compte : SYSTEM
    Domaine du compte : AUTORITE NT
    ID d’ouverture de session : 0x3e7

    Privilèges : SeAssignPrimaryTokenPrivilege
    SeTcbPrivilege
    SeSecurityPrivilege
    SeTakeOwnershipPrivilege
    SeLoadDriverPrivilege
    SeBackupPrivilege
    SeRestorePrivilege
    SeDebugPrivilege
    SeAuditPrivilege
    SeSystemEnvironmentPrivilege
    SeImpersonatePrivilege
    Record Number: 131385
    Source Name: Microsoft-Windows-Security-Auditing
    Time Written: 20090611102954.291405-000
    Event Type: Succès de l'audit
    User:

    Computer Name: Sami
    Event Code: 4624
    Message: L’ouverture de session d’un compte s’est correctement déroulée.

    Sujet :
    ID de sécurité : S-1-5-18
    Nom du compte : SAMI$
    Domaine du compte : WORKGROUP
    ID d’ouverture de session : 0x3e7

    Type d’ouverture de session : 5

    Nouvelle ouverture de session :
    ID de sécurité : S-1-5-18
    Nom du compte : SYSTEM
    Domaine du compte : AUTORITE NT
    ID d’ouverture de session : 0x3e7
    GUID d’ouverture de session : {00000000-0000-0000-0000-000000000000}

    Informations sur le processus :
    ID du processus : 0x2c0
    Nom du processus : C:\Windows\System32\services.exe

    Informations sur le réseau :
    Nom de la station de travail :
    Adresse du réseau source : -
    Port source : -

    Informations détaillées sur l’authentification :
    Processus d’ouverture de session : Advapi
    Package d’authentification : Negotiate
    Services en transit : -
    Nom du package (NTLM uniquement) : -
    Longueur de la clé : 0

    Cet événement est généré lors de la création d’une ouverture de session. Il est généré sur l’ordinateur sur lequel l’ouverture de session a été effectuée.

    Le champ Objet indique le compte sur le système local qui a demandé l’ouverture de session. Il s’agit le plus souvent d’un service, comme le service Serveur, ou un processus local tel que Winlogon.exe ou Services.exe.

    Le champ Type d’ouverture de session indique le type d’ouverture de session qui s’est produit. Les types les plus courants sont 2 (interactif) et 3 (réseau).

    Le champ Nouvelle ouverture de session indique le compte pour lequel la nouvelle ouverture de session a été créée, par exemple, le compte qui s’est connecté.

    Les champs relatifs au réseau indiquent la provenance d’une demande d’ouverture de session à distance. Le nom de la station de travail n’étant pas toujours disponible, peut être laissé vide dans certains cas.

    Les champs relatifs aux informations d’authentification fournissent des détails sur cette demande d’ouverture de session spécifique.
    - Le GUID d’ouverture de session est un identificateur unique pouvant servir à associer cet événement à un événement KDC .
    - Les services en transit indiquent les services intermédiaires qui ont participé à cette demande d’ouverture de session.
    - Nom du package indique quel est le sous-protocole qui a été utilisé parmi les protocoles NTLM.
    - La longueur de la clé indique la longueur de la clé de session générée. Elle a la valeur 0 si aucune clé de session n’a été demandée.
    Record Number: 131384
    Source Name: Microsoft-Windows-Security-Auditing
    Time Written: 20090611102954.291405-000
    Event Type: Succès de l'audit
    User:

    Computer Name: Sami
    Event Code: 4648
    Message: Tentative d’ouverture de session en utilisant des informations d’identification explicites.

    Sujet :
    ID de sécurité : S-1-5-18
    Nom du compte : SAMI$
    Domaine du compte : WORKGROUP
    ID d’ouverture de session : 0x3e7
    GUID d’ouverture de session : {00000000-0000-0000-0000-000000000000}

    Compte dont les informations d’identification ont été utilisées :
    Nom du compte : SYSTEM
    Domaine du compte : AUTORITE NT
    GUID d’ouverture de session : {00000000-0000-0000-0000-000000000000}

    Serveur cible :
    Nom du serveur cible : localhost
    Informations supplémentaires : localhost

    Informations sur le processus :
    ID du processus : 0x2c0
    Nom du processus : C:\Windows\System32\services.exe

    Informations sur le réseau :
    Adresse du réseau : -
    Port : -

    Cet événement est généré lorsqu’un processus tente d’ouvrir une session pour un compte en spécifiant explicitement les informations d’identification de ce compte. Ceci se produit le plus souvent dans les configurations par lot comme les tâches planifiées, ou avec l’utilisation de la commande RUNAS.
    Record Number: 131383
    Source Name: Microsoft-Windows-Security-Auditing
    Time Written: 20090611102954.291405-000
    Event Type: Succès de l'audit
    User:

    Computer Name: Sami
    Event Code: 5056
    Message: Un autotest de chiffrement a été effectué.

    Sujet :
    ID de sécurité : S-1-5-18
    Nom du compte : SAMI$
    Domaine du compte : WORKGROUP
    ID d’ouverture de session : 0x3e7

    Module : ncrypt.dll

    Code de retour : 0x0
    Record Number: 131382
    Source Name: Microsoft-Windows-Security-Auditing
    Time Written: 20090611102925.442794-000
    Event Type: Succès de l'audit
    User:

    Computer Name: Sami
    Event Code: 4672
    Message: Privilèges spéciaux attribués à la nouvelle ouverture de session.

    Sujet :
    ID de sécurité : S-1-5-18
    Nom du compte : SYSTEM
    Domaine du compte : AUTORITE NT
    ID d’ouverture de session : 0x3e7

    Privilèges : SeAssignPrimaryTokenPrivilege
    SeTcbPrivilege
    SeSecurityPrivilege
    SeTakeOwnershipPrivilege
    SeLoadDriverPrivilege
    SeBackupPrivilege
    SeRestorePrivilege
    SeDebugPrivilege
    SeAuditPrivilege
    SeSystemEnvironmentPrivilege
    SeImpersonatePrivilege
    Record Number: 131381
    Source Name: Microsoft-Windows-Security-Auditing
    Time Written: 20090611102923.789183-000
    Event Type: Succès de l'audit
    User:

    ======Environment variables======

    "ComSpec"=%SystemRoot%\system32\cmd.exe
    "FP_NO_HOST_CHECK"=NO
    "HummPATH11"=C:\Program Files\Hummingbird\Connectivity\11.00\Accessories\;C:\Program Files\Hummingbird\Connectivity\11.00\NFS Maestro\;
    "LIBRARY_PATH"=c:\mingw\lib;c:\mingw\lib\gcc-lib\i686-pc-mingw32\4.0.3
    "NUMBER_OF_PROCESSORS"=2
    "OS"=Windows_NT
    "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\system32\wbem;C:\Program Files\PC Connectivity Solution;C:\Program Files\MiKTeX 2.7\miktex\bin;C:\Program Files\MATLAB\R2007b\bin;C:\Program Files\MATLAB\R2007b\bin\win32;C:\Program Files\Common Files\Adobe\AGL;C:\Program Files\IVI\bin;C:\Program Files\IVI Foundation\VISA\WinNT\Bin;C:\Program Files\QuickTime\QTSystem;%HummPATH11%;C:\Program Files\Common Files\DivX Shared;C:\Program Files\QuickTime\QTSystem\
    "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
    "PROCESSOR_ARCHITECTURE"=x86
    "PROCESSOR_IDENTIFIER"=x86 Family 6 Model 14 Stepping 12, GenuineIntel
    "PROCESSOR_LEVEL"=6
    "PROCESSOR_REVISION"=0e0c
    "TEMP"=%SystemRoot%\TEMP
    "TMP"=%SystemRoot%\TEMP
    "tvdumpflags"=8
    "USERNAME"=SYSTEM
    "windir"=%SystemRoot%
    "CLASSPATH"=.;C:\Program Files\Java\jre6\lib\ext\QTJava.zip
    "QTJAVA"=C:\Program Files\Java\jre6\lib\ext\QTJava.zip

    -----------------EOF-----------------
    0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. Papillon_des_neiges Messages postés 12 Statut Membre
     
    L'outil travaille...
    Il faut savoir que beaucoup de services et processus sont arrêtés depuis aujourd'hui, et je n'y vois aucune explication.
    En voici quelques exemples, et c'est depuis le début d'après-midi :
    - MBAM : je ne peux effectuer de mise à jour ! pourtant, je l'avais déjà installer (puis redésinstaller) et il se mettait très bien à jour. Voici un imprim écran du problème de MAJ : http://www.cijoint.fr/cjlink.php?file=cj20.../cijsMa0HBy.jpg
    - Il n'y a plus antivir et zonealarm qui se lancent au démarrage ! Voici le problème d'antivir, dont le service ne veut pas se lancer : http://www.cijoint.fr/cjlink.php?file=cj20.../cijknENzK5.jpg
    - Il semble que je sois très infecté, je ne peux même pas faire de point de restauration système : http://www.cijoint.fr/cjlink.php?file=cj20.../cijbo89X7A.jpg
    0
  7. Utilisateur anonyme
     
    Les images marche pas...... Dès que l'outil a terminer, montre le rapport !
    0
  8. Papillon_des_neiges Messages postés 12 Statut Membre
     
    Après 4h30 d'analyse, l'outil semble bloqué à 98% sur la recherche "Cracks : serial : keygen" comme le montre cet imprim écran : http://www.cijoint.fr/cjlink.php?file=cj200912/cijO4mRTBL.jpg. J'attends encore ?
    0
  9. Papillon_des_neiges Messages postés 12 Statut Membre
     
    Il y a bien par contre un fichier catchme.log créé sur mon bureau. J'ai pris une grosse initiative (je suis tellement pressé de résoudre cette infection) et j'espère que vous ne m'en tiendrez pas rigueur. Je connais les dangers à utiliser combofix sans qu'on nous le demande, mais bon...comme List&Kill'em n'a pas marché, je me suis dire que j'allais vous fournir un autre rapport utile pour faire avancer les choses :

    ComboFix 09-12-19.03 - SaMi 21/12/2009 0:02.7.2 - x86
    Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6002.2.1252.33.1036.18.2045.1114 [GMT 1:00]
    Lancé depuis: c:\users\SaMi\Desktop\22989-CF.exe
    FW: ZoneAlarm Firewall *enabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
    SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
    SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
    .

    (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe

    .
    ((((((((((((((((((((((((((((( Fichiers créés du 2009-11-20 au 2009-12-20 ))))))))))))))))))))))))))))))))))))
    .

    2009-12-20 23:19 . 2009-12-20 23:19 -------- d-----w- c:\users\SaMi\AppData\Local\temp
    2009-12-20 23:19 . 2009-12-20 23:19 -------- d-----w- c:\users\Public\AppData\Local\temp
    2009-12-20 23:19 . 2009-12-20 23:19 -------- d-----w- c:\users\Default\AppData\Local\temp
    2009-12-20 22:58 . 2009-12-03 15:14 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
    2009-12-20 22:58 . 2009-12-03 15:13 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
    2009-12-20 22:58 . 2009-12-20 22:58 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
    2009-12-20 22:53 . 2009-12-20 22:53 -------- d-----w- c:\windows\LastGood
    2009-12-20 16:48 . 2009-12-20 16:48 -------- dc----w- C:\Kill'em
    2009-12-20 16:24 . 2009-12-20 16:24 -------- d-----w- C:\rsit
    2009-12-20 15:58 . 2009-12-20 22:36 -------- dc----w- C:\Malwarebytes' Anti-Malware
    2009-12-20 15:22 . 2009-12-20 15:22 19944 ----a-w- c:\windows\system32\drivers\tsk_atapi.sys
    2009-12-20 15:21 . 2009-12-20 15:21 16904 ----a-w- c:\windows\system32\drivers\KLMD.sys
    2009-12-20 15:20 . 2009-12-20 15:20 -------- d-----w- C:\tdsskiller
    2009-12-20 14:03 . 2009-12-20 14:06 -------- d-----w- c:\program files\Toolbar Uninstaller
    2009-12-19 16:44 . 2009-12-19 16:44 -------- d-----w- c:\program files\ZHPDiag
    2009-12-19 00:26 . 2009-12-19 00:26 -------- dc----w- C:\IBMTOOLS
    2009-12-18 20:12 . 2009-12-20 22:30 -------- d-----w- c:\programdata\ma-config.com
    2009-12-18 20:12 . 2009-12-20 22:30 -------- d-----w- c:\program files\ma-config.com
    2009-12-18 19:04 . 2009-12-18 19:04 -------- d-----w- c:\program files\Western Digital
    2009-12-09 13:10 . 2009-11-09 12:31 24064 ----a-w- c:\windows\system32\nshhttp.dll
    2009-12-09 13:10 . 2009-11-09 10:36 411648 ----a-w- c:\windows\system32\drivers\http.sys
    2009-12-09 13:10 . 2009-11-09 12:30 30720 ----a-w- c:\windows\system32\httpapi.dll
    2009-12-09 12:59 . 2009-10-07 11:36 243712 ----a-w- c:\windows\system32\rastls.dll
    2009-12-05 16:10 . 2009-12-05 16:11 -------- d-----w- c:\program files\QuickTime
    2009-12-01 11:26 . 2009-12-01 20:29 -------- d-----w- c:\users\SaMi\AppData\Roaming\GlarySoft
    2009-12-01 11:12 . 2009-12-01 11:12 -------- d-----w- c:\program files\Glary Utilities
    2009-11-29 20:40 . 2009-12-01 20:53 -------- d-----w- c:\program files\zztoy
    2009-11-29 16:46 . 2009-11-29 16:46 -------- d-----w- c:\program files\Uniblue
    2009-11-29 02:07 . 2009-11-29 02:07 -------- d-----w- c:\program files\Sleepy
    2009-11-28 18:10 . 2009-12-20 15:06 -------- d-----w- c:\program files\Trend Micro
    2009-11-27 06:07 . 2009-11-27 06:07 -------- d-----w- c:\program files\Common Files\xing shared
    2009-11-27 06:00 . 2009-11-27 06:01 -------- d-----w- c:\users\Default\AppData\Local\Adobe
    2009-11-25 01:41 . 2009-10-29 09:17 2048 ----a-w- c:\windows\system32\tzres.dll
    2009-11-25 00:47 . 2009-08-11 16:44 1401856 ----a-w- c:\windows\system32\msxml6.dll
    2009-11-25 00:47 . 2009-08-11 16:44 1248768 ----a-w- c:\windows\system32\msxml3.dll

    .
    (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2009-12-20 23:13 . 2009-12-20 23:13 55788 ----a-w- c:\programdata\nvModes.dat
    2009-12-20 23:01 . 2009-01-05 03:11 1 ----a-w- c:\users\SaMi\AppData\Roaming\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
    2009-12-20 22:57 . 2006-11-02 15:48 503938 ----a-w- c:\windows\system32\perfc00C.dat
    2009-12-20 22:57 . 2006-11-02 15:48 1780320 ----a-w- c:\windows\system32\perfh00C.dat
    2009-12-20 22:37 . 2009-02-10 18:42 352615 ---ha-w- c:\windows\system32\drivers\vsconfig.xml
    2009-12-20 22:33 . 2007-12-10 22:37 -------- d-----w- c:\programdata\Spybot - Search & Destroy
    2009-12-20 22:31 . 2008-12-24 03:06 -------- d-----w- c:\program files\Emule049b
    2009-12-20 17:10 . 2007-08-24 11:16 -------- d-----w- c:\programdata\Google Updater
    2009-12-20 15:26 . 2009-09-24 14:14 19944 ----a-w- c:\windows\system32\drivers\atapi.sys
    2009-12-20 04:17 . 2006-12-02 18:49 -------- d--h--w- c:\program files\InstallShield Installation Information
    2009-12-20 04:17 . 2006-12-10 10:30 -------- d-----w- c:\program files\Acer Arcade Deluxe
    2009-12-20 03:59 . 2007-04-09 15:26 -------- d-----w- c:\program files\Acer Inc
    2009-12-19 05:03 . 2008-02-01 22:00 -------- d-----w- c:\program files\eMule
    2009-12-17 12:29 . 2009-03-25 15:50 15826810 ----a-w- c:\windows\Internet Logs\tvDebug.zip
    2009-12-16 21:36 . 2007-08-26 20:58 -------- d-----w- c:\users\SaMi\AppData\Roaming\dvdcss
    2009-12-11 02:43 . 2009-07-15 17:38 56816 ----a-w- c:\windows\system32\drivers\avgntflt.sys
    2009-12-09 13:16 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
    2009-12-09 13:12 . 2008-05-19 13:32 -------- d-----w- c:\programdata\Microsoft Help
    2009-12-06 12:28 . 2009-02-05 15:24 -------- d-----w- c:\program files\Sam Scanner
    2009-12-01 23:48 . 2009-02-17 17:37 1356 ----a-w- c:\users\SaMi\AppData\Local\d3d9caps.dat
    2009-12-01 20:23 . 2008-01-03 06:46 -------- d-----w- c:\program files\WinImage
    2009-12-01 20:21 . 2008-06-27 21:14 -------- d-----w- c:\users\SaMi\AppData\Roaming\Todae
    2009-11-29 16:32 . 2009-01-20 07:06 -------- d-----w- c:\users\SaMi\AppData\Roaming\Uniblue
    2009-11-28 19:45 . 2007-08-24 11:19 -------- d-----w- c:\program files\Common Files\Adobe
    2009-11-27 06:07 . 2007-10-06 00:19 -------- d-----w- c:\program files\Common Files\Real
    2009-11-21 06:40 . 2009-12-09 13:00 916480 ----a-w- c:\windows\system32\wininet.dll
    2009-11-21 06:34 . 2009-12-09 13:00 109056 ----a-w- c:\windows\system32\iesysprep.dll
    2009-11-21 06:34 . 2009-12-09 13:00 71680 ----a-w- c:\windows\system32\iesetup.dll
    2009-11-21 04:59 . 2009-12-09 13:00 133632 ----a-w- c:\windows\system32\ieUnatt.exe
    2009-11-19 00:55 . 2009-11-08 02:29 -------- d-----w- c:\program files\DIFX
    2009-11-19 00:51 . 2009-11-19 00:51 -------- d-----w- c:\program files\Common Files\PCSuite
    2009-11-19 00:51 . 2009-11-19 00:51 -------- d-----w- c:\program files\Common Files\Nokia
    2009-11-19 00:51 . 2009-11-08 02:19 -------- d-----w- c:\program files\Nokia
    2009-11-19 00:46 . 2009-11-19 00:46 -------- d-----w- c:\program files\PC Connectivity Solution
    2009-11-19 00:34 . 2008-07-19 17:36 -------- d-----w- c:\programdata\Installations
    2009-11-19 00:34 . 2009-11-19 00:35 34503600 ----a-w- c:\programdata\Installations\{9249D7E7-33E7-4CC8-BB0B-3DF3C3CB2568}\Nokia_PC_Suite_7_1_40_1_fre.exe
    2009-11-19 00:34 . 2009-11-19 00:35 34503600 ----a-w- c:\programdata\Application Data\Installations\{9249D7E7-33E7-4CC8-BB0B-3DF3C3CB2568}\Nokia_PC_Suite_7_1_40_1_fre.exe
    2009-11-19 00:34 . 2009-11-19 00:35 34503600 ----a-w- c:\programdata\Application Data\Application Data\Installations\{9249D7E7-33E7-4CC8-BB0B-3DF3C3CB2568}\Nokia_PC_Suite_7_1_40_1_fre.exe
    2009-11-19 00:34 . 2009-11-19 00:35 34503600 ----a-w- c:\programdata\Application Data\Application Data\Application Data\Installations\{9249D7E7-33E7-4CC8-BB0B-3DF3C3CB2568}\Nokia_PC_Suite_7_1_40_1_fre.exe
    2009-11-19 00:34 . 2009-11-19 00:35 34503600 ----a-w- c:\programdata\Application Data\Application Data\Application Data\Application Data\Installations\{9249D7E7-33E7-4CC8-BB0B-3DF3C3CB2568}\Nokia_PC_Suite_7_1_40_1_fre.exe
    2009-11-19 00:34 . 2009-11-19 00:35 34503600 ----a-w- c:\programdata\Application Data\Application Data\Application Data\Application Data\Application Data\Installations\{9249D7E7-33E7-4CC8-BB0B-3DF3C3CB2568}\Nokia_PC_Suite_7_1_40_1_fre.exe
    2009-11-19 00:34 . 2009-11-19 00:35 34503600 ----a-w- c:\programdata\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Installations\{9249D7E7-33E7-4CC8-BB0B-3DF3C3CB2568}\Nokia_PC_Suite_7_1_40_1_fre.exe
    2009-11-19 00:34 . 2009-11-19 00:35 34503600 ----a-w- c:\programdata\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Installations\{9249D7E7-33E7-4CC8-BB0B-3DF3C3CB2568}\Nokia_PC_Suite_7_1_40_1_fre.exe
    2009-11-19 00:34 . 2009-11-19 00:35 34503600 ----a-w- c:\programdata\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Installations\{9249D7E7-33E7-4CC8-BB0B-3DF3C3CB2568}\Nokia_PC_Suite_7_1_40_1_fre.exe
    2009-11-19 00:34 . 2009-11-19 00:35 34503600 ----a-w- c:\programdata\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Installations\{9249D7E7-33E7-4CC8-BB0B-3DF3C3CB2568}\Nokia_PC_Suite_7_1_40_1_fre.exe
    2009-11-17 19:58 . 2009-11-17 19:58 -------- d-----w- c:\program files\Windows Portable Devices
    2009-11-17 19:58 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat
    2009-11-17 19:57 . 2009-11-17 19:57 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_07_00.Wdf
    2009-11-17 19:55 . 2009-11-17 19:55 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
    2009-11-14 16:59 . 2009-11-08 02:37 -------- d-----w- c:\users\SaMi\AppData\Roaming\Nokia
    2009-11-14 16:59 . 2009-11-08 02:37 -------- d-----w- c:\users\SaMi\AppData\Roaming\PC Suite
    2009-11-08 02:45 . 2009-11-08 02:45 0 ---ha-w- c:\windows\system32\drivers\Msft_User_PCCSWpdDriver_01_07_00.Wdf
    2009-11-08 02:44 . 2009-11-08 02:37 -------- d-----w- c:\programdata\PC Suite
    2009-11-08 02:44 . 2009-11-08 02:44 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01007.Wdf
    2009-11-08 02:01 . 2009-11-08 02:01 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01005.Wdf
    2009-11-02 19:42 . 2009-10-03 08:05 195456 ------w- c:\windows\system32\MpSigStub.exe
    2009-11-01 22:54 . 2007-08-13 21:02 115160 ----a-w- c:\users\SaMi\AppData\Local\GDIPFONTCACHEV1.DAT
    2009-10-22 12:48 . 2008-01-31 20:36 -------- d-----w- c:\users\SaMi\AppData\Roaming\Winamp
    2009-10-22 12:45 . 2008-02-12 17:29 -------- d-----w- c:\program files\Pinnacle
    2009-10-20 11:33 . 2009-10-22 12:48 545280 ----a-w- c:\users\SaMi\AppData\Roaming\Mozilla\Firefox\Profiles\l52hi599.default\extensions\piclens@cooliris.com\libs\PicLensHelper.exe
    2009-10-20 11:33 . 2009-10-22 12:48 103424 ----a-w- c:\users\SaMi\AppData\Roaming\Mozilla\Firefox\Profiles\l52hi599.default\extensions\piclens@cooliris.com\libs\pixomatic.dll
    2009-10-20 11:33 . 2009-10-22 12:48 4716544 ----a-w- c:\users\SaMi\AppData\Roaming\Mozilla\Firefox\Profiles\l52hi599.default\extensions\piclens@cooliris.com\components\cooliris.dll
    2009-10-20 11:33 . 2009-10-22 12:48 344064 ----a-w- c:\users\SaMi\AppData\Roaming\Mozilla\Firefox\Profiles\l52hi599.default\extensions\piclens@cooliris.com\libs\LaunchCooliris.exe
    2009-10-20 11:33 . 2009-10-22 12:48 153600 ----a-w- c:\users\SaMi\AppData\Roaming\Mozilla\Firefox\Profiles\l52hi599.default\extensions\piclens@cooliris.com\plugins\npcoolirisplugin.dll
    2009-10-08 21:08 . 2009-11-17 18:05 555520 ----a-w- c:\windows\system32\UIAutomationCore.dll
    2009-10-08 21:08 . 2009-11-17 18:05 234496 ----a-w- c:\windows\system32\oleacc.dll
    2009-10-08 21:07 . 2009-11-17 18:05 4096 ----a-w- c:\windows\system32\oleaccrc.dll
    2009-10-06 10:52 . 2008-05-02 09:58 91136 ----a-w- c:\windows\system32\nmwcdcls.dll
    2009-10-01 01:02 . 2009-11-17 18:08 2537472 ----a-w- c:\windows\system32\wpdshext.dll
    2009-10-01 01:02 . 2009-11-17 18:08 30208 ----a-w- c:\windows\system32\WPDShextAutoplay.exe
    2009-10-01 01:02 . 2009-11-17 18:08 334848 ----a-w- c:\windows\system32\PortableDeviceApi.dll
    2009-10-01 01:02 . 2009-11-17 18:08 87552 ----a-w- c:\windows\system32\WPDShServiceObj.dll
    2009-10-01 01:02 . 2009-11-17 18:08 31232 ----a-w- c:\windows\system32\BthMtpContextHandler.dll
    2009-10-01 01:01 . 2009-11-17 18:08 546816 ----a-w- c:\windows\system32\wpd_ci.dll
    2009-10-01 01:01 . 2009-11-17 18:08 160256 ----a-w- c:\windows\system32\PortableDeviceTypes.dll
    2009-10-01 01:01 . 2009-11-17 18:08 60928 ----a-w- c:\windows\system32\PortableDeviceConnectApi.dll
    2009-10-01 01:01 . 2009-11-17 18:08 350208 ----a-w- c:\windows\system32\WPDSp.dll
    2009-10-01 01:01 . 2009-11-17 18:08 196608 ----a-w- c:\windows\system32\PortableDeviceWMDRM.dll
    2009-10-01 01:01 . 2009-11-17 18:08 100864 ----a-w- c:\windows\system32\PortableDeviceClassExtension.dll
    2009-10-01 01:01 . 2009-11-17 18:08 81920 ----a-w- c:\windows\system32\wpdbusenum.dll
    2009-10-01 01:01 . 2009-11-17 18:08 40448 ----a-w- c:\windows\system32\drivers\WpdUsb.sys
    2009-10-01 01:01 . 2009-11-17 18:08 226816 ----a-w- c:\windows\system32\WpdMtp.dll
    2009-10-01 01:01 . 2009-11-17 18:08 33280 ----a-w- c:\windows\system32\WpdConns.dll
    2009-10-01 01:01 . 2009-11-17 18:08 61952 ----a-w- c:\windows\system32\WpdMtpUS.dll
    2009-09-25 02:10 . 2009-11-17 18:09 974848 ----a-w- c:\windows\system32\WindowsCodecs.dll
    2009-09-25 02:07 . 2009-11-17 18:09 189440 ----a-w- c:\windows\system32\WindowsCodecsExt.dll
    2009-09-25 02:04 . 2009-11-17 18:09 321024 ----a-w- c:\windows\system32\PhotoMetadataHandler.dll
    2009-09-25 01:49 . 2009-11-17 18:09 1554432 ----a-w- c:\windows\system32\xpsservices.dll
    2009-09-25 01:48 . 2009-11-17 18:09 351232 ----a-w- c:\windows\system32\XpsPrint.dll
    2009-09-25 01:38 . 2009-11-17 18:09 847360 ----a-w- c:\windows\system32\OpcServices.dll
    2009-09-25 01:36 . 2009-11-17 18:09 280064 ----a-w- c:\windows\system32\XpsGdiConverter.dll
    2009-09-25 01:35 . 2009-11-17 18:09 135680 ----a-w- c:\windows\system32\XpsRasterService.dll
    2009-09-25 01:33 . 2009-11-17 18:09 195584 ----a-w- c:\windows\system32\dxdiagn.dll
    2009-09-25 01:33 . 2009-11-17 18:09 829440 ----a-w- c:\windows\system32\d3d10warp.dll
    2009-09-25 01:33 . 2009-11-17 18:09 369664 ----a-w- c:\windows\system32\WMPhoto.dll
    2009-09-25 01:32 . 2009-11-17 18:09 252928 ----a-w- c:\windows\system32\dxdiag.exe
    2009-09-25 01:31 . 2009-11-17 18:09 519680 ----a-w- c:\windows\system32\d3d11.dll
    2009-09-25 01:31 . 2009-11-17 18:09 486912 ----a-w- c:\windows\system32\d3d10level9.dll
    2009-09-25 01:31 . 2009-11-17 18:09 161280 ----a-w- c:\windows\system32\d3d10_1.dll
    2009-09-25 01:31 . 2009-11-17 18:09 218112 ----a-w- c:\windows\system32\d3d10_1core.dll
    2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
    2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
    .

    ------- Sigcheck -------

    [-] 2009-12-20 15:26 . B8429E028C08351D63E654B764DA68FA . 19944 . . [------] . . c:\windows\System32\drivers\atapi.sys
    [7] 2009-04-11 . 1F05B78AB91C9075565A9D8A4B880BC4 . 19944 . . [6.0.6002.18005] . . c:\windows\ERDNT\cache\atapi.sys
    [7] 2009-04-11 . 1F05B78AB91C9075565A9D8A4B880BC4 . 19944 . . [6.0.6002.18005] . . c:\windows\System32\DriverStore\FileRepository\mshdc.inf_b12d8e84\atapi.sys
    [7] 2008-02-13 . B35CFCEF838382AB6490B321C87EDF17 . 21560 . . [6.0.6000.16632] . . c:\windows\System32\DriverStore\FileRepository\mshdc.inf_7de13c21\atapi.sys
    [7] 2008-01-19 . 2D9C903DC76A66813D350A562DE40ED9 . 21560 . . [6.0.6001.18000] . . c:\windows\System32\DriverStore\FileRepository\mshdc.inf_cc18792d\atapi.sys
    [7] 2006-11-02 . 4F4FCB8B6EA06784FB6D475B7EC7300F . 19048 . . [6.0.6000.16386] . . c:\windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys
    .
    ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
    REGEDIT4

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\humnfsoverlay]
    @="{647E9AF4-DF80-40EF-B7FB-1B1B0C221193}"
    [HKEY_CLASSES_ROOT\CLSID\{647E9AF4-DF80-40EF-B7FB-1B1B0C221193}]
    2005-09-21 06:47 67240 ----a-w- c:\program files\Hummingbird\Connectivity\11.00\NFS Maestro\hcnfsexp.dll

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-10-23 815104]
    "LMgrOSD"="c:\program files\Launch Manager\OSDCtrl.exe" [2006-08-29 241664]
    "Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2009-01-20 517768]
    "IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2008-06-10 1406024]
    "USB2Check"="c:\windows\system32\PCLECoInst.dll" [2007-01-23 81920]
    "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-08-01 13548064]
    "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-08-01 92704]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "EnableUIADesktopToggle"= 0 (0x0)
    "EnableLUA"= 0 (0x0)

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
    "aux"=wdmaud.drv

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ProfSvc]
    @=""

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
    @=""

    [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Gamma.lnk]
    backup=c:\windows\pss\Adobe Gamma.lnk.CommonStartup
    backupExtension=.CommonStartup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
    2009-09-04 11:08 935288 ----a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
    2009-10-03 03:08 35696 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avgnt]
    2009-03-02 11:08 209153 ----a-w- c:\program files\Avira\AntiVir Desktop\avgnt.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eDataSecurity Loader]
    2007-01-02 16:58 464168 -c----w- c:\acer\Empowering Technology\eDataSecurity\eDSloader.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HumMeteringClient]
    2005-09-21 06:45 153288 ----a-w- c:\program files\Hummingbird\Connectivity\11.00\Accessories\MeteringClient.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LaunchAp]
    2005-07-25 11:36 32768 ----a-w- c:\program files\Launch Manager\LaunchAp.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LManager]
    2007-01-10 09:34 200704 ----a-w- c:\program files\Launch Manager\HotkeyApp.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NFSUserSIDGSSLink]
    2005-09-21 06:47 38560 ----a-w- c:\program files\Hummingbird\Connectivity\11.00\NFS Maestro\HumGSS.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Suite Tray]
    2009-11-11 09:57 1451520 ----a-w- c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
    2009-11-10 22:08 417792 ----a-w- c:\program files\QuickTime\QTTask.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl]
    2006-11-09 18:57 3784704 ----a-w- c:\windows\RtHDVCpl.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
    2009-11-27 06:07 198160 ----a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\USB2Check]
    2007-01-23 09:12 81920 ----a-w- c:\windows\System32\PCLECoInst.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\USBToolTip]
    2006-10-16 12:50 202312 ----a-w- c:\program files\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WarReg_PopUp]
    2006-11-05 19:48 57344 -c--a-w- c:\acer\WR_PopUp\WarReg_PopUp.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Wbutton]
    2006-11-09 12:37 86016 ----a-w- c:\program files\Launch Manager\WButton.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
    2009-07-01 16:37 37888 ----a-w- c:\program files\Winamp\winampa.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ZoneAlarm Client]
    2008-03-03 14:05 959976 ----a-w- c:\program files\Zone Labs\ZoneAlarm\zlclient.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
    "Malwarebytes Anti-Malware (reboot)"="c:\program files\zztoy\zztoy.exe" /runcleanupscript
    "GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe"

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
    "VistaSp2"=hex(b):5e,46,6f,19,2d,3d,ca,01

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-1576903536-255805909-3727375607-1000]
    "EnableNotificationsRef"=dword:00000001

    R1 LUM;LUM;c:\windows\System32\drivers\LUM.sys [05/06/2007 17:57 16528]
    R1 LUMDriver;LUMDriver;c:\windows\System32\drivers\LUMDriver.sys [24/04/2007 16:52 16688]
    R2 BBDemon;Backbone Service;c:\program files\Dassault Systemes\B16\intel_a\code\bin\CATSysDemon.exe [06/09/2005 22:11 35840]
    R2 HCLNFS;HCLNFS;c:\windows\System32\drivers\hclnfs.sys [21/09/2005 07:47 283720]
    R2 Vcs;Vcs support;c:\windows\System32\drivers\Vcs.sys [18/01/2009 23:38 6852]
    S2 gupdate1c9d6f5d4e428f5;Service Google Update (gupdate1c9d6f5d4e428f5);c:\program files\Google\Update\GoogleUpdate.exe [17/05/2009 14:45 133104]
    S3 FontCache;Service de cache de police Windows;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [31/05/2008 04:26 21504]
    S3 Ltn_stk7070P;PCTV based TV tuner device;c:\windows\System32\drivers\Ltn_stk7070P.sys [16/09/2008 23:30 466048]
    S3 Ltn_stkrc;PCTV Infrared Receiver;c:\windows\System32\drivers\Ltn_stkrc.sys [16/09/2008 23:30 13440]
    S3 PctvVirtualNdis;Pinnacle Virtual Miniport;c:\windows\System32\drivers\PctvVirtualNdis.sys [31/03/2009 21:38 13696]
    S3 WisLMSvc;WisLMSvc;c:\program files\Launch Manager\WisLMSvc.exe [09/04/2007 16:29 118784]
    S3 WSVD;WSVD;c:\windows\System32\drivers\WSVD.sys [14/08/2007 09:47 80744]
    S4 AntiVirSchedulerService;Avira AntiVir Planificateur;c:\program files\Avira\AntiVir Desktop\sched.exe [15/07/2009 18:38 108289]
    S4 HCLExport;Hummingbird Export;c:\windows\System32\Hummingbird\Connectivity\11.00\NFS Maestro\expserv.exe [21/09/2005 07:47 63136]
    S4 HumNamemapping;Hummingbird Name Mapping Server;c:\program files\Hummingbird\Connectivity\11.00\NFS Maestro\Humnmap.exe [21/09/2005 07:47 91816]
    S4 HUMNFSServer;Hummingbird NFS Maestro Server;c:\program files\Hummingbird\Connectivity\11.00\NFS Maestro\hcwinsvr.exe [21/09/2005 07:47 226992]
    S4 HUMPortmapper;Hummingbird Port Mapper;c:\program files\Hummingbird\Connectivity\11.00\NFS Maestro\hcportmp.exe [21/09/2005 07:47 59040]
    S4 msvsmon80;Visual Studio 2005 Remote Debugger;c:\program files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe [23/09/2005 07:01 2799808]
    S4 PESRV;Hummingbird HostExplorer Print Services;c:\program files\Hummingbird\Connectivity\11.00\HostExplorer\PrintServices\PESRV.exe [21/09/2005 07:46 149152]
    S4 ProxyEngine;Hummingbird Proxy Server;c:\program files\Hummingbird\Connectivity\11.00\Accessories\ProxyEngine.exe [21/09/2005 07:45 120496]

    --- Autres Services/Pilotes en mémoire ---

    *Deregistered* - IDSvix86
    *Deregistered* - SYMDNS
    *Deregistered* - SymEvent
    *Deregistered* - SYMFW
    *Deregistered* - SYMIDS
    *Deregistered* - SYMNDISV
    *Deregistered* - SYMREDRV
    *Deregistered* - SYMTDI

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
    hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
    LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache

    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{FE827D64-FD1F-40B4-86B1-F3683B7D7959}]
    2005-09-21 06:45 91816 ----a-w- c:\program files\Hummingbird\Connectivity\11.00\Accessories\HumSettings.exe
    .
    ------- Examen supplémentaire -------
    .
    uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
    uStart Page = hxxp://www.google.fr/
    IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
    IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~3\Office10\EXCEL.EXE/3000
    IE: Tout télécharger avec Free Download Manager - file://d:\free download manager\dlall.htm
    IE: Télécharger avec Free Download Manager - file://d:\free download manager\dllink.htm
    IE: Télécharger la sélection avec Free Download Manager - file://d:\free download manager\dlselected.htm
    IE: Télécharger la vidéo avec Free Download Manager - file://d:\free download manager\dlfvideo.htm
    LSP: c:\program files\Hummingbird\Connectivity\11.00\Exceed\humshmx.dll
    Trusted Zone: tellmemorecampus.com\www
    Trusted Zone: tellmemorecampus.com\www3
    Trusted Zone: tellmemorecampus.com\www
    Trusted Zone: tellmemorecampus.com\www3
    FF - ProfilePath - c:\users\SaMi\AppData\Roaming\Mozilla\Firefox\Profiles\l52hi599.default\
    FF - prefs.js: browser.startup.homepage - hxxp://www.google.fr/
    FF - component: c:\program files\Nokia\Nokia PC Suite 7\bkmrksync\components\BkMrkExt.dll
    FF - component: c:\program files\Real\RealPlayer\browserrecord\firefox\ext\components\nprpffbrowserrecordext.dll
    FF - component: c:\users\SaMi\AppData\Roaming\Mozilla\Firefox\Profiles\l52hi599.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}\components\WinampTBPlayer.dll
    FF - component: c:\users\SaMi\AppData\Roaming\Mozilla\Firefox\Profiles\l52hi599.default\extensions\piclens@cooliris.com\components\cooliris.dll
    FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
    FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
    FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
    FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
    FF - plugin: c:\program files\Mozilla Firefox\plugins\NPTURNMED.dll
    FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
    FF - plugin: c:\users\SaMi\AppData\Roaming\Mozilla\Firefox\Profiles\l52hi599.default\extensions\piclens@cooliris.com\plugins\npcoolirisplugin.dll
    FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

    ---- PARAMETRES FIREFOX ----
    FF - user.js: general.useragent.extra.zencast - Creative ZENcast v2.00.13);user_pref(general.useragent.extra.zencast, .
    - - - - ORPHELINS SUPPRIMES - - - -

    HKLM-Run-eRecoveryService - (no file)
    MSConfigStartUp-DAEMON Tools - c:\program files\DAEMON Tools\daemon.exe
    AddRemove-AviSynth2 - c:\program files\AviSynth2\uninst.exe
    AddRemove-HijackThis - c:\users\SaMi\Desktop\HijackThis.exe
    AddRemove-BitTorrent - d:\bittorrent\uninst.exe

    **************************************************************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2009-12-21 00:19
    Windows 6.0.6002 Service Pack 2 NTFS

    Recherche de processus cachés ...

    Recherche d'éléments en démarrage automatique cachés ...

    Recherche de fichiers cachés ...

    Scan terminé avec succès
    Fichiers cachés: 0

    **************************************************************************
    .
    --------------------- CLES DE REGISTRE BLOQUEES ---------------------

    [HKEY_USERS\S-1-5-21-1576903536-255805909-3727375607-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*1]%%]
    @Class="Shell"
    @Allowed: (Read) (RestrictedCode)

    [HKEY_USERS\S-1-5-21-1576903536-255805909-3727375607-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*1]%%\OpenWithList]
    @Class="Shell"

    [HKEY_USERS\S-1-5-21-1576903536-255805909-3727375607-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*c%&**]
    @Class="Shell"
    @Allowed: (Read) (RestrictedCode)

    [HKEY_USERS\S-1-5-21-1576903536-255805909-3727375607-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*c%&**\OpenWithList]
    @Class="Shell"

    [HKEY_USERS\S-1-5-21-1576903536-255805909-3727375607-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*i%**]
    @Class="Shell"
    @Allowed: (Read) (RestrictedCode)

    [HKEY_USERS\S-1-5-21-1576903536-255805909-3727375607-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*i%**\OpenWithList]
    @Class="Shell"

    [HKEY_USERS\S-1-5-21-1576903536-255805909-3727375607-1000\Software\SecuROM\License information*]
    @Allowed: (Read) (RestrictedCode)
    "datasecu"=hex:8e,af,d5,c2,45,b6,7d,74,ae,b7,69,08,5f,f5,e9,a3,ce,6f,51,91,94,
    e0,85,05,ff,48,23,87,2b,ea,25,1e,dc,43,69,6c,1c,70,33,ac,68,94,87,86,dd,18,\
    "rkeysecu"=hex:23,96,34,e3,ef,77,0c,36,a8,6e,fb,2a,c5,6c,43,cf

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet023\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    "MSCurrentCountry"=dword:000000b5
    .
    Heure de fin: 2009-12-21 00:27:03
    ComboFix-quarantined-files.txt 2009-12-20 23:27

    Avant-CF: 16 279 748 608 octets libres
    Après-CF: 16 254 607 360 octets libres

    - - End Of File - - 602C1CF32C1B14CCD5FC2BA03A1F6D72
    0
  10. Utilisateur anonyme
     
    J'allais te le proposer^^
    Refait un RSIT !
    0
  11. Papillon_des_neiges Messages postés 12 Statut Membre
     
    Il n'y a qu'un fichier log.txt qui est apparu : le voici copié collé :
    Logfile of random's system information tool 1.06 (written by random/random)
    Run by SaMi at 2009-12-21 14:03:16
    Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 2
    System drive C: has 15 GB (21%) free of 72 GB
    Total RAM: 2045 MB (53% free)

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 14:03:28, on 21/12/2009
    Platform: Windows Vista SP2 (WinNT 6.00.1906)
    MSIE: Internet Explorer v8.00 (8.00.6001.18865)
    Boot mode: Normal

    Running processes:
    C:\Windows\System32\smss.exe
    C:\Windows\system32\csrss.exe
    C:\Windows\system32\wininit.exe
    C:\Windows\system32\csrss.exe
    C:\Windows\system32\services.exe
    C:\Windows\system32\lsass.exe
    C:\Windows\system32\lsm.exe
    C:\Windows\system32\winlogon.exe
    C:\Windows\system32\svchost.exe
    C:\Windows\system32\nvvsvc.exe
    C:\Windows\system32\svchost.exe
    C:\Windows\System32\svchost.exe
    C:\Windows\System32\svchost.exe
    C:\Windows\System32\svchost.exe
    C:\Windows\system32\svchost.exe
    C:\Windows\system32\svchost.exe
    C:\Windows\system32\SLsvc.exe
    C:\Windows\system32\svchost.exe
    C:\Windows\system32\rundll32.exe
    C:\Windows\system32\svchost.exe
    C:\Windows\System32\ZoneLabs\vsmon.exe
    C:\Windows\System32\spoolsv.exe
    C:\Program Files\Avira\AntiVir Desktop\sched.exe
    C:\Program Files\Avira\AntiVir Desktop\avguard.exe
    C:\Windows\system32\svchost.exe
    C:\Windows\system32\Dwm.exe
    C:\Windows\system32\taskeng.exe
    C:\Windows\Explorer.EXE
    C:\Windows\system32\taskeng.exe
    C:\Windows\system32\agrsmsvc.exe
    C:\Program Files\Dassault Systemes\B16\intel_a\code\bin\CATSysDemon.exe
    C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
    C:\Acer\Empowering Technology\eNet\eNet Service.exe
    C:\Windows\system32\svchost.exe
    c:\Program Files\Common Files\LightScribe\LSSrvc.exe
    C:\Acer\Mobility Center\MobilityService.exe
    C:\Windows\System32\svchost.exe
    C:\Windows\System32\svchost.exe
    C:\Windows\system32\svchost.exe
    C:\Windows\system32\svchost.exe
    C:\Windows\System32\svchost.exe
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
    C:\Windows\system32\SearchIndexer.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
    C:\Program Files\Launch Manager\OSDCtrl.exe
    C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
    C:\Program Files\Microsoft IntelliPoint\ipoint.exe
    C:\Windows\System32\rundll32.exe
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\Acer\Empowering Technology\ePower\ePowerSvc.exe
    C:\Program Files\Launch Manager\LaunchAp.exe
    C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
    C:\Windows\ehome\ehtray.exe
    C:\Windows\ehome\ehmsas.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
    C:\Windows\system32\wbem\unsecapp.exe
    C:\Windows\System32\alg.exe
    C:\Windows\system32\wbem\unsecapp.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Windows\system32\SearchProtocolHost.exe
    C:\Windows\system32\SearchFilterHost.exe
    C:\Users\SaMi\Desktop\RSIT.exe
    C:\Windows\system32\taskeng.exe
    C:\Program Files\Trend Micro\HijackThis\SaMi.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [LMgrOSD] "C:\Program Files\Launch Manager\OSDCtrl.exe"
    O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
    O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
    O4 - HKLM\..\Run: [USB2Check] RUNDLL32.EXE "C:\Windows\system32\PCLECoInst.dll",CheckUSBController
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    O4 - HKLM\..\Run: [LaunchAp] "C:\Program Files\Launch Manager\LaunchAp.exe"
    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
    O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
    O4 - Global Startup: Empowering Technology Launcher.lnk = C:\Acer\Empowering Technology\eAPLauncher.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
    O8 - Extra context menu item: Tout télécharger avec Free Download Manager - file://D:\Free Download Manager\dlall.htm
    O8 - Extra context menu item: Télécharger avec Free Download Manager - file://D:\Free Download Manager\dllink.htm
    O8 - Extra context menu item: Télécharger la sélection avec Free Download Manager - file://D:\Free Download Manager\dlselected.htm
    O8 - Extra context menu item: Télécharger la vidéo avec Free Download Manager - file://D:\Free Download Manager\dlfvideo.htm
    O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
    O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O10 - Unknown file in Winsock LSP: c:\program files\hummingbird\connectivity\11.00\exceed\humshmx.dll
    O10 - Unknown file in Winsock LSP: c:\program files\hummingbird\connectivity\11.00\exceed\humshmx.dll
    O10 - Unknown file in Winsock LSP: c:\program files\hummingbird\connectivity\11.00\exceed\humshmx.dll
    O15 - Trusted Zone: http://www.tellmemorecampus.com
    O15 - Trusted Zone: http://www3.tellmemorecampus.com
    O15 - Trusted Zone: http://www.tellmemorecampus.com (HKLM)
    O15 - Trusted Zone: http://www3.tellmemorecampus.com (HKLM)
    O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - (no file)
    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
    O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
    O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
    O23 - Service: Backbone Service (BBDemon) - Dassault Systemes - C:\Program Files\Dassault Systemes\B16\intel_a\code\bin\CATSysDemon.exe
    O23 - Service: eDSService.exe (eDataSecurity Service) - HiTRSUT - C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
    O23 - Service: eNet Service - Acer Inc. - C:\Acer\Empowering Technology\eNet\eNet Service.exe
    O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
    O23 - Service: eSettings Service (eSettingsService) - Unknown owner - C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
    O23 - Service: Service Google Update (gupdate1c9d6f5d4e428f5) (gupdate1c9d6f5d4e428f5) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
    O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
    O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
    O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
    O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
    O23 - Service: PCLEPCI - Pinnacle Systems GmbH - C:\Windows\system32\drivers\pclepci.sys
    O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\Windows\System32\ZoneLabs\vsmon.exe
    O23 - Service: WisLMSvc - Wistron Corp. - C:\Program Files\Launch Manager\WisLMSvc.exe
    O23 - Service: ePower Service (WMIService) - acer - C:\Acer\Empowering Technology\ePower\ePowerSvc.exe
    0
  12. Papillon_des_neiges Messages postés 12 Statut Membre
     
    ======File associations======

    .js - edit - C:\Windows\System32\Notepad.exe %1
    .txt - open -

    ======List of files/folders created in the last 1 months======

    2009-12-21 02:36:46 ----DC---- C:\Kill'em
    2009-12-21 01:25:26 ----D---- C:\ProgramData\Avira
    2009-12-21 01:25:26 ----D---- C:\Program Files\Avira
    2009-12-21 00:27:10 ----SHDC---- C:\$RECYCLE.BIN
    2009-12-21 00:27:03 ----AC---- C:\ComboFix.txt
    2009-12-21 00:02:03 ----A---- C:\Windows\MBR.exe
    2009-12-21 00:01:39 ----DC---- C:\Qoobox
    2009-12-20 23:58:35 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
    2009-12-20 17:49:13 ----AC---- C:\List'em.txt
    2009-12-20 17:24:31 ----D---- C:\rsit
    2009-12-20 16:58:12 ----DC---- C:\Malwarebytes' Anti-Malware
    2009-12-20 16:20:13 ----D---- C:\tdsskiller
    2009-12-20 15:03:20 ----D---- C:\Program Files\Toolbar Uninstaller
    2009-12-19 17:44:50 ----D---- C:\Program Files\ZHPDiag
    2009-12-19 01:26:24 ----DC---- C:\IBMTOOLS
    2009-12-19 00:31:52 ----A---- C:\Windows\WA.INI
    2009-12-18 21:12:26 ----D---- C:\ProgramData\ma-config.com
    2009-12-18 21:12:26 ----D---- C:\Program Files\ma-config.com
    2009-12-18 20:04:00 ----D---- C:\Program Files\Western Digital
    2009-12-09 14:10:07 ----A---- C:\Windows\system32\nshhttp.dll
    2009-12-09 14:10:00 ----A---- C:\Windows\system32\httpapi.dll
    2009-12-09 14:00:51 ----A---- C:\Windows\system32\winhttp.dll
    2009-12-09 14:00:44 ----A---- C:\Windows\system32\mshtml.dll
    2009-12-09 14:00:43 ----A---- C:\Windows\system32\ieframe.dll
    2009-12-09 14:00:42 ----A---- C:\Windows\system32\iertutil.dll
    2009-12-09 14:00:41 ----A---- C:\Windows\system32\wininet.dll
    2009-12-09 14:00:41 ----A---- C:\Windows\system32\urlmon.dll
    2009-12-09 14:00:40 ----A---- C:\Windows\system32\occache.dll
    2009-12-09 14:00:40 ----A---- C:\Windows\system32\msfeedsbs.dll
    2009-12-09 14:00:40 ----A---- C:\Windows\system32\msfeeds.dll
    2009-12-09 14:00:40 ----A---- C:\Windows\system32\ieUnatt.exe
    2009-12-09 14:00:40 ----A---- C:\Windows\system32\ieui.dll
    2009-12-09 14:00:40 ----A---- C:\Windows\system32\iesysprep.dll
    2009-12-09 14:00:40 ----A---- C:\Windows\system32\iepeers.dll
    2009-12-09 14:00:40 ----A---- C:\Windows\system32\iedkcs32.dll
    2009-12-09 14:00:39 ----A---- C:\Windows\system32\msfeedssync.exe
    2009-12-09 14:00:39 ----A---- C:\Windows\system32\jsproxy.dll
    2009-12-09 14:00:39 ----A---- C:\Windows\system32\iesetup.dll
    2009-12-09 14:00:39 ----A---- C:\Windows\system32\iernonce.dll
    2009-12-09 14:00:39 ----A---- C:\Windows\system32\ie4uinit.exe
    2009-12-09 13:59:35 ----A---- C:\Windows\system32\rastls.dll
    2009-12-06 14:23:06 ----AC---- C:\TCleaner.txt
    2009-12-05 17:10:16 ----D---- C:\Program Files\QuickTime
    2009-12-01 12:26:07 ----D---- C:\Users\SaMi\AppData\Roaming\GlarySoft
    2009-12-01 12:12:25 ----D---- C:\Program Files\Glary Utilities
    2009-11-29 21:40:48 ----D---- C:\Program Files\zztoy
    2009-11-29 17:46:00 ----D---- C:\Program Files\Uniblue
    2009-11-29 03:07:43 ----D---- C:\Program Files\Sleepy
    2009-11-28 19:10:35 ----D---- C:\Program Files\Trend Micro
    2009-11-27 07:08:49 ----D---- C:\ProgramData\Real
    2009-11-27 07:07:55 ----A---- C:\Windows\system32\rmoc3260.dll
    2009-11-27 07:07:33 ----A---- C:\Windows\system32\pndx5032.dll
    2009-11-27 07:07:33 ----A---- C:\Windows\system32\pndx5016.dll
    2009-11-27 07:07:28 ----D---- C:\Program Files\Common Files\xing shared
    2009-11-25 02:41:39 ----A---- C:\Windows\system32\tzres.dll
    2009-11-25 01:47:33 ----A---- C:\Windows\system32\msxml6.dll
    2009-11-25 01:47:31 ----A---- C:\Windows\system32\msxml3.dll

    ======List of files/folders modified in the last 1 months======

    2009-12-21 14:03:26 ----D---- C:\Windows\temp
    2009-12-21 13:55:23 ----D---- C:\Program Files\Mozilla Firefox
    2009-12-21 13:53:25 ----D---- C:\Windows\System32
    2009-12-21 13:53:25 ----A---- C:\Windows\system32\PerfStringBackup.INI
    2009-12-21 13:51:26 ----D---- C:\Windows\Internet Logs
    2009-12-21 02:13:33 ----D---- C:\Windows
    2009-12-21 02:03:41 ----D---- C:\Windows\system32\config
    2009-12-21 01:25:35 ----D---- C:\Windows\system32\drivers
    2009-12-21 01:25:26 ----D---- C:\ProgramData
    2009-12-21 01:25:26 ----D---- C:\Program Files
    2009-12-21 01:23:48 ----SHD---- C:\Windows\Installer
    2009-12-21 01:23:48 ----DC---- C:\Config.Msi
    2009-12-21 01:11:59 ----D---- C:\ProgramData\NVIDIA
    2009-12-21 00:19:50 ----AC---- C:\Windows\system.ini
    2009-12-21 00:09:38 ----D---- C:\Windows\AppPatch
    2009-12-21 00:09:37 ----D---- C:\Program Files\Common Files
    2009-12-20 23:53:12 ----D---- C:\Windows\system32\catroot
    2009-12-20 23:53:08 ----D---- C:\Windows\inf
    2009-12-20 23:51:38 ----D---- C:\Program Files\Common Files\microsoft shared
    2009-12-20 23:50:55 ----SHD---- C:\System Volume Information
    2009-12-20 23:39:43 ----D---- C:\Windows\Tasks
    2009-12-20 23:33:58 ----D---- C:\ProgramData\Spybot - Search & Destroy
    2009-12-20 23:31:39 ----D---- C:\Program Files\Emule049b
    2009-12-20 18:10:24 ----D---- C:\ProgramData\Google Updater
    2009-12-20 18:10:11 ----D---- C:\Windows\system32\Tasks
    2009-12-20 17:19:42 ----D---- C:\Windows\system32\catroot2
    2009-12-20 05:17:16 ----HD---- C:\Program Files\InstallShield Installation Information
    2009-12-20 05:17:14 ----D---- C:\Program Files\Acer Arcade Deluxe
    2009-12-20 04:59:28 ----D---- C:\Program Files\Acer Inc
    2009-12-20 04:10:48 ----D---- C:\Windows\Debug
    2009-12-19 06:03:20 ----D---- C:\Program Files\eMule
    2009-12-17 18:33:39 ----D---- C:\Windows\Prefetch
    2009-12-16 22:36:44 ----D---- C:\Users\SaMi\AppData\Roaming\dvdcss
    2009-12-09 22:54:07 ----A---- C:\Windows\PEV.exe
    2009-12-09 14:37:14 ----D---- C:\Windows\rescache
    2009-12-09 14:30:46 ----D---- C:\Windows\winsxs
    2009-12-09 14:16:12 ----D---- C:\Windows\system32\migration
    2009-12-09 14:16:11 ----D---- C:\Program Files\Internet Explorer
    2009-12-09 14:16:10 ----D---- C:\Windows\system32\fr-FR
    2009-12-09 14:16:10 ----D---- C:\Program Files\Windows Mail
    2009-12-09 14:12:56 ----D---- C:\ProgramData\Microsoft Help
    2009-12-09 14:09:39 ----RSD---- C:\Windows\assembly
    2009-12-06 13:28:42 ----D---- C:\Program Files\Sam Scanner
    2009-12-01 22:42:48 ----D---- C:\Windows\ERDNT
    2009-12-01 21:23:25 ----D---- C:\Program Files\WinImage
    2009-12-01 21:23:25 ----AD---- C:\ProgramData\TEMP
    2009-12-01 21:21:27 ----D---- C:\Users\SaMi\AppData\Roaming\Todae
    2009-12-01 21:06:19 ----A---- C:\Windows\system32\mrt.exe
    2009-12-01 13:12:42 ----D---- C:\Users\SaMi\AppData\Roaming\Real
    2009-11-29 17:32:15 ----D---- C:\Users\SaMi\AppData\Roaming\Uniblue
    2009-11-28 20:45:09 ----D---- C:\Program Files\Common Files\Adobe
    2009-11-28 20:44:51 ----D---- C:\ProgramData\Adobe
    2009-11-28 20:44:45 ----D---- C:\Program Files\Adobe
    2009-11-27 07:07:58 ----D---- C:\Program Files\Common Files\Real
    2009-11-27 07:07:07 ----A---- C:\Windows\system32\pncrt.dll

    ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

    R1 avgio;avgio; \??\C:\Program Files\Avira\AntiVir Desktop\avgio.sys [2009-02-13 11608]
    R1 avipbb;avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [2009-03-30 96104]
    R1 Hotkey;Hotkey; C:\Windows\system32\drivers\Hotkey.sys [2003-04-28 9867]
    R1 LUM;LUM; \??\C:\Windows\system32\drivers\LUM.sys [2007-06-05 16528]
    R1 LUMDriver;LUMDriver; \??\C:\Windows\system32\drivers\LUMDriver.sys [2007-04-24 16688]
    R1 ssmdrv;ssmdrv; C:\Windows\system32\DRIVERS\ssmdrv.sys [2009-05-11 28520]
    R1 Vsdatant;Zone Alarm Firewall Driver; C:\Windows\system32\DRIVERS\vsdatant.sys [2008-03-03 279440]
    R2 avgntflt;avgntflt; C:\Windows\system32\DRIVERS\avgntflt.sys [2009-11-25 56816]
    R2 HCLNFS;HCLNFS; \??\C:\Windows\system32\drivers\hclnfs.sys [2005-09-21 283720]
    R2 int15;int15; \??\C:\Acer\Empowering Technology\eRecovery\int15.sys [2006-12-07 76584]
    R2 Vcs;Vcs support; \??\C:\Windows\system32\Drivers\Vcs.sys [2004-11-14 6852]
    R3 AgereSoftModem;Agere Systems Soft Modem; C:\Windows\system32\DRIVERS\AGRSM.sys [2006-10-05 1161152]
    R3 BCM43XX;Pilote pour carte réseau Broadcom 802.11; C:\Windows\system32\DRIVERS\bcmwl6.sys [2006-12-19 534016]
    R3 Cam5607;Acer OrbiCam; C:\Windows\System32\Drivers\BisonC07.sys [2006-11-25 792368]
    R3 CmBatt;Pilote pour Batterie à méthode de contrôle ACPI Microsoft; C:\Windows\system32\DRIVERS\CmBatt.sys [2008-01-19 14208]
    R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2006-11-09 1647976]
    R3 MarvinBus;Pinnacle Marvin Bus; C:\Windows\system32\DRIVERS\MarvinBus.sys [2007-01-04 171520]
    R3 NTIDrvr;Upper Class Filter Driver; C:\Windows\system32\DRIVERS\NTIDrvr.sys [2006-12-10 6144]
    R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2008-08-01 7549568]
    R3 pfc;Padus ASPI Shell; C:\Windows\system32\drivers\pfc.sys [2005-11-02 10368]
    R3 RTL8169;Pilote Realtek 8169 NT; C:\Windows\system32\DRIVERS\Rtlh86.sys [2006-11-02 44544]
    R3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2009-04-11 89088]
    R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2006-10-23 179896]
    R3 tifm21;tifm21; C:\Windows\system32\drivers\tifm21.sys [2006-07-06 168448]
    R3 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\DRIVERS\wmiacpi.sys [2008-01-19 11264]
    S3 61883;Pilote d'unité 61883; C:\Windows\system32\DRIVERS\61883.sys [2008-01-19 45696]
    S3 Avc;Périphérique AVC; C:\Windows\system32\DRIVERS\avc.sys [2008-01-19 40448]
    S3 catchme;catchme; \??\C:\Users\SaMi\AppData\Local\Temp\catchme.sys []
    S3 CVirtA;Cisco Systems VPN Adapter; C:\Windows\system32\DRIVERS\CVirtA.sys [2007-01-18 5275]
    S3 Dot4;Pilote MS IEEE-1284.4; C:\Windows\system32\DRIVERS\Dot4.sys [2008-01-19 131584]
    S3 Dot4Print;Pilote de classe Imprimante pour IEEE-1284.4; C:\Windows\system32\DRIVERS\Dot4Prt.sys [2008-01-19 16384]
    S3 dot4usb;MS Dot4USB Filter Dot4USB Filter; C:\Windows\system32\DRIVERS\dot4usb.sys [2008-01-19 36864]
    S3 drmkaud;Filtre de décodeur DRM (Noyau Microsoft); C:\Windows\system32\drivers\drmkaud.sys [2008-01-19 5632]
    S3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2008-11-18 25280]
    S3 Ltn_stk7070P;PCTV based TV tuner device; C:\Windows\system32\DRIVERS\Ltn_stk7070P.sys [2007-06-14 466048]
    S3 Ltn_stkrc;PCTV Infrared Receiver; C:\Windows\system32\DRIVERS\Ltn_stkrc.sys [2007-06-13 13440]
    S3 MSDV;Microsoft DV Camera and VCR; C:\Windows\system32\DRIVERS\msdv.sys [2008-01-19 52608]
    S3 MSKSSRV;Proxy de service de répartition Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-19 8192]
    S3 MSPCLOCK;Proxy d'horloge de répartition Microsoft; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-19 5888]
    S3 MSPQM;Proxy de gestion de qualité de répartition Microsoft; C:\Windows\system32\drivers\MSPQM.sys [2008-01-19 5504]
    S3 MSTEE;Convertisseur en T/site-à-site de répartition Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2008-01-19 6016]
    S3 NuidFltr;NUID filter driver; C:\Windows\system32\DRIVERS\NuidFltr.sys [2007-08-31 18856]
    S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfd.sys [2008-08-26 18816]
    S3 PctvVirtualNdis;Pinnacle Virtual Miniport; C:\Windows\system32\DRIVERS\PctvVirtualNdis.sys [2007-02-02 13696]
    S3 PinnacleMarvinUsb;Pinnacle Systems Service for MovieBox Deluxe, 500-USB and 700-USB; C:\Windows\system32\DRIVERS\MarvinUsb.sys [2007-01-23 441472]
    S3 Point32;Microsoft IntelliPoint Filter Driver; C:\Windows\system32\DRIVERS\point32k.sys [2008-06-10 33352]
    S3 upperdev;upperdev; C:\Windows\system32\DRIVERS\usbser_lowerflt.sys []
    S3 USBAAPL;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl.sys [2007-10-31 30464]
    S3 usbscan;Pilote de scanneur USB; C:\Windows\system32\DRIVERS\usbscan.sys [2008-01-19 35328]
    S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2009-10-01 40448]
    S3 WSVD;WSVD; \??\C:\Windows\system32\drivers\WSVD.sys [2006-09-19 80744]
    S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-19 83328]
    S4 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys []

    ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

    R2 AgereModemAudio;Agere Modem Call Progress Audio; C:\Windows\system32\agrsmsvc.exe [2006-10-05 9216]
    R2 AntiVirSchedulerService;Avira AntiVir Planificateur; C:\Program Files\Avira\AntiVir Desktop\sched.exe [2009-05-13 108289]
    R2 AntiVirService;Avira AntiVir Guard; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [2009-07-21 185089]
    R2 BBDemon;Backbone Service; C:\Program Files\Dassault Systemes\B16\intel_a\code\bin\CATSysDemon.exe [2005-09-06 35840]
    R2 eDataSecurity Service;eDSService.exe; C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe [2007-01-02 457512]
    R2 eNet Service;eNet Service; C:\Acer\Empowering Technology\eNet\eNet Service.exe [2006-12-28 126976]
    R2 eRecoveryService;eRecovery Service; C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe [2007-07-03 53248]
    R2 eSettingsService;eSettings Service; C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe [2007-01-02 24576]
    R2 hpqddsvc;Service HP CUE DeviceDiscovery; C:\Windows\system32\svchost.exe [2008-01-19 21504]
    R2 LightScribeService;LightScribeService Direct Disc Labeling Service; c:\Program Files\Common Files\LightScribe\LSSrvc.exe [2006-10-19 61440]
    R2 MobilityService;MobilityService; C:\Acer\Mobility Center\MobilityService.exe [2006-11-24 107008]
    R2 Net Driver HPZ12;Net Driver HPZ12; C:\Windows\System32\svchost.exe [2008-01-19 21504]
    R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2008-08-01 196608]
    R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\Windows\System32\svchost.exe [2008-01-19 21504]
    R2 vsmon;TrueVector Internet Monitor; C:\Windows\System32\ZoneLabs\vsmon.exe [2008-03-03 79400]
    R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2009-03-30 1533808]
    R2 WMIService;ePower Service; C:\Acer\Empowering Technology\ePower\ePowerSvc.exe [2007-01-02 135168]
    S2 gupdate1c9d6f5d4e428f5;Service Google Update (gupdate1c9d6f5d4e428f5); C:\Program Files\Google\Update\GoogleUpdate.exe [2009-05-17 133104]
    S2 LiveUpdate Notice Service;LiveUpdate Notice Service; C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe [2009-01-20 517768]
    S2 PCLEPCI;PCLEPCI; C:\Windows\system32\drivers\pclepci.sys [2005-02-09 14165]
    S2 Planificateur LiveUpdate automatique;Planificateur LiveUpdate automatique; C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe [2009-01-20 554352]
    S3 Adobe LM Service;Adobe LM Service; C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [2008-01-30 72704]
    S3 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-01-19 21504]
    S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
    S3 LiveUpdate;LiveUpdate; C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE [2007-09-26 2999664]
    S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2008-10-25 65888]
    S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
    S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
    S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2009-10-27 657408]
    S3 WisLMSvc;WisLMSvc; C:\Program Files\Launch Manager\WisLMSvc.exe [2006-11-17 118784]
    S4 HCLExport;Hummingbird Export; C:\Windows\system32\Hummingbird\Connectivity\11.00\NFS Maestro\expserv.exe [2005-09-21 63136]
    S4 HCLInetd;Hummingbird InetD; C:\Program Files\Hummingbird\Connectivity\11.00\InetD\inetd32.exe [2005-09-21 54928]
    S4 hpqcxs08;hpqcxs08; C:\Windows\system32\svchost.exe [2008-01-19 21504]
    S4 HumNamemapping;Hummingbird Name Mapping Server; C:\Program Files\Hummingbird\Connectivity\11.00\NFS Maestro\Humnmap.exe [2005-09-21 91816]
    S4 HUMNFSServer;Hummingbird NFS Maestro Server; C:\Program Files\Hummingbird\Connectivity\11.00\NFS Maestro\hcwinsvr.exe [2005-09-21 226992]
    S4 HUMPortmapper;Hummingbird Port Mapper; C:\Program Files\Hummingbird\Connectivity\11.00\NFS Maestro\hcportmp.exe [2005-09-21 59040]
    S4 msvsmon80;Visual Studio 2005 Remote Debugger; C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe [2005-09-23 2799808]
    S4 PESRV;Hummingbird HostExplorer Print Services; C:\Program Files\Hummingbird\Connectivity\11.00\HostExplorer\PrintServices\PESRV.exe [2005-09-21 149152]
    S4 ProxyEngine;Hummingbird Proxy Server; C:\Program Files\Hummingbird\Connectivity\11.00\Accessories\ProxyEngine.exe [2005-09-21 120496]

    -----------------EOF-----------------
    0
  13. Utilisateur anonyme
     
    Va dans : "C:\Program Files\Trend Micro" Double clic sur le raccourci avec ton nom (ou le nom d'ordi)

    Clique sur "Do a system scan only"

    Coche ces lignes :

    O15 - Trusted Zone: http://www.tellmemorecampus.com
    O15 - Trusted Zone: http://www3.tellmemorecampus.com
    O15 - Trusted Zone: http://www.tellmemorecampus.com (HKLM)
    O15 - Trusted Zone: http://www3.tellmemorecampus.com (HKLM) 


    Et fait "Fix Cheked"

    Comment va l'ordi ?
    0
  14. Papillon_des_neiges Messages postés 12 Statut Membre
     
    Il va impécablement bien. Merci vraiment beaucoup. Me reste-t-il des choses à faire (du genre désinstaller les petits logiciels de sécurité téléchargés et réactiver le controle des utilisateurs) ?
    0
  15. Papillon_des_neiges Messages postés 12 Statut Membre
     
    Logfile of random's system information tool 1.06 (written by random/random)
    Run by SaMi at 2009-12-21 17:10:10
    Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 2
    System drive C: has 15 GB (21%) free of 72 GB
    Total RAM: 2045 MB (48% free)

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 17:10:29, on 21/12/2009
    Platform: Windows Vista SP2 (WinNT 6.00.1906)
    MSIE: Internet Explorer v8.00 (8.00.6001.18865)
    Boot mode: Normal

    Running processes:
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Windows\system32\taskeng.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\Launch Manager\OSDCtrl.exe
    C:\Program Files\Microsoft IntelliPoint\ipoint.exe
    C:\Windows\System32\rundll32.exe
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\Program Files\Launch Manager\LaunchAp.exe
    C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
    C:\Windows\ehome\ehtray.exe
    C:\Windows\ehome\ehmsas.exe
    C:\Windows\system32\wbem\unsecapp.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Users\SaMi\Desktop\RSIT.exe
    C:\Program Files\Trend Micro\HijackThis\SaMi.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [LMgrOSD] "C:\Program Files\Launch Manager\OSDCtrl.exe"
    O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
    O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
    O4 - HKLM\..\Run: [USB2Check] RUNDLL32.EXE "C:\Windows\system32\PCLECoInst.dll",CheckUSBController
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    O4 - HKLM\..\Run: [LaunchAp] "C:\Program Files\Launch Manager\LaunchAp.exe"
    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
    O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
    O4 - Global Startup: Empowering Technology Launcher.lnk = C:\Acer\Empowering Technology\eAPLauncher.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
    O8 - Extra context menu item: Tout télécharger avec Free Download Manager - file://D:\Free Download Manager\dlall.htm
    O8 - Extra context menu item: Télécharger avec Free Download Manager - file://D:\Free Download Manager\dllink.htm
    O8 - Extra context menu item: Télécharger la sélection avec Free Download Manager - file://D:\Free Download Manager\dlselected.htm
    O8 - Extra context menu item: Télécharger la vidéo avec Free Download Manager - file://D:\Free Download Manager\dlfvideo.htm
    O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
    O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O10 - Unknown file in Winsock LSP: c:\program files\hummingbird\connectivity\11.00\exceed\humshmx.dll
    O10 - Unknown file in Winsock LSP: c:\program files\hummingbird\connectivity\11.00\exceed\humshmx.dll
    O10 - Unknown file in Winsock LSP: c:\program files\hummingbird\connectivity\11.00\exceed\humshmx.dll
    O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - (no file)
    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
    O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
    O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
    O23 - Service: Backbone Service (BBDemon) - Dassault Systemes - C:\Program Files\Dassault Systemes\B16\intel_a\code\bin\CATSysDemon.exe
    O23 - Service: eDSService.exe (eDataSecurity Service) - HiTRSUT - C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
    O23 - Service: eNet Service - Acer Inc. - C:\Acer\Empowering Technology\eNet\eNet Service.exe
    O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
    O23 - Service: eSettings Service (eSettingsService) - Unknown owner - C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
    O23 - Service: Service Google Update (gupdate1c9d6f5d4e428f5) (gupdate1c9d6f5d4e428f5) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
    O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
    O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
    O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
    O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
    O23 - Service: PCLEPCI - Pinnacle Systems GmbH - C:\Windows\system32\drivers\pclepci.sys
    O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\Windows\System32\ZoneLabs\vsmon.exe
    O23 - Service: WisLMSvc - Wistron Corp. - C:\Program Files\Launch Manager\WisLMSvc.exe
    O23 - Service: ePower Service (WMIService) - acer - C:\Acer\Empowering Technology\ePower\ePowerSvc.exe
    0
  16. Utilisateur anonyme
     
    Pour moi, c'est bon mais pour voir si il reste des traces :

    • Télécharge Malwarebytes' Anti-Malware (MBAM)
    http://www.malwarebytes.org/mbam/program/mbam-setup.exe

    * Double clique sur le fichier téléchargé pour lancer le processus d'installation.
    * Dans l'onglet "Mise à jour", clique sur le bouton "Recherche de mise à jour": si le pare-feu demande l'autorisation à MBAM de se connecter, accepte.
    * Une fois la mise à jour terminée, rends-toi dans l'onglet "Recherche".
    * Sélectionne "Exécuter un examen complet"
    * Clique sur "Rechercher"
    * L'analyse démarre, le scan est relativement long, c'est normal.
    * A la fin de l'analyse, un message s'affiche :

    L'examen s'est terminé normalement. Clique sur 'Afficher les résultats' pour afficher tous les objets trouvés.

    Clique sur "Ok" pour poursuivre. Si MBAM n'a rien trouvé, il te le dira aussi.
    * Ferme tes navigateurs.
    * Si des malwares ont été détectés, clique sur Afficher les résultats.
    Sélectionne tout (ou laisse coché) et clique sur Supprimer la sélection, MBAM va détruire les fichiers et clés de registre et en mettre une copie dans la quarantaine.
    * MBAM va ouvrir le Bloc-notes et y copier le rapport d'analyse. Copie-colle ce rapport et poste-le dans ta prochaine réponse.

    NB : Si MBAM te demande à redémarrer, fais-le.
    0
  17. Utilisateur anonyme
     
    J'arrete ! : http://forum.zebulon.fr/comment-puis-je-eradiquer-vundo-gen-qui-a-infecte-en-particulier
    0
  18. Papillon_des_neiges Messages postés 12 Statut Membre
     
    Mille fois merci, MBAM ne trouve rien (comme le montre le rapport copié collé). J'effacerai moi même les petits logiciels...je comprends que vous ne vouliez plus m'aider puisque j'ai aussi poster mon problème ailleurs (je devais régler mon problème au plus vite, donc écouter le premier qui me réponde pendant des fêtes de Noël où tout est "gelé". Je n'aurais pas fait cela en temps normal, je me doutais que ce n'étais pas correct malgré que je ne me sois jamais inscrit auparavant à un forum, mais je n'ai pas eu le courage d'aller vérifier ou de demander...I apologize. Bonnes fêtes à vous.

    Malwarebytes' Anti-Malware 1.42
    Version de la base de données: 3402
    Windows 6.0.6002 Service Pack 2
    Internet Explorer 8.0.6001.18865

    21/12/2009 21:18:56
    mbam-log-2009-12-21 (21-18-56).txt

    Type de recherche: Examen complet (C:\|D:\|)
    Eléments examinés: 592569
    Temps écoulé: 4 hour(s), 15 minute(s), 18 second(s)

    Processus mémoire infecté(s): 0
    Module(s) mémoire infecté(s): 0
    Clé(s) du Registre infectée(s): 0
    Valeur(s) du Registre infectée(s): 0
    Elément(s) de données du Registre infecté(s): 0
    Dossier(s) infecté(s): 0
    Fichier(s) infecté(s): 0

    Processus mémoire infecté(s):
    (Aucun élément nuisible détecté)

    Module(s) mémoire infecté(s):
    (Aucun élément nuisible détecté)

    Clé(s) du Registre infectée(s):
    (Aucun élément nuisible détecté)

    Valeur(s) du Registre infectée(s):
    (Aucun élément nuisible détecté)

    Elément(s) de données du Registre infecté(s):
    (Aucun élément nuisible détecté)

    Dossier(s) infecté(s):
    (Aucun élément nuisible détecté)

    Fichier(s) infecté(s):
    (Aucun élément nuisible détecté)
    0