Rapport d'erreur "Hijack This"

Résolu
Bonjour, J'aimerai faire un rapport d'erreur avec Hijack This pour éventuellement identifier et supprimer ces virus qui peuvent nuirent à mon PC. Est-ce qu'il y aurait quelqu'un de bien aimable pour m'aider à identifier ces erreurs ?
Configuration: Ordinateur:
Type de système PC avec processeur x86 ACPI (Mobile)
Système d'exploitation Microsoft Windows Vista Home Basic
Service Pack du système [ TRIAL VERSION ]
Internet Explorer 7.0.6002.18005
DirectX DirectX 10.1
Nom du système PC-DE-CYRIL-MAR
Nom de l'utilisateur karima
Domaine de connexion [ TRIAL VERSION ]
Date / Heure 2009-10-24 / 00:00

Carte mère:
Type de processeur Mobile DualCore Intel Pentium T4200, 2000 MHz (10 x 200)
Nom de la carte mère PACKARD BELL BV PE2
Chipset de la carte mère Intel Cantiga GM45
Mémoire système [ TRIAL VERSION ]
DIMM1: Samsung M4 70T5663QZ3-CE6 2 Go DDR2-667 DDR2 SDRAM (5-5-5-15 @ 333 MHz) (4-4-4-12 @ 266 MHz) (3-3-3-9 @ 200 MHz)
DIMM3: Samsung M4 70T5663QZ3-CE6 [ TRIAL VERSION ]
Type de BIOS Phoenix (12/22/08)

Multimédia:
Carte audio Realtek ALC272 @ Intel 82801IB ICH9 - High Definition Audio Controller [A-3]

Stockage:
Contrôleur IDE Intel(R) ICH9M/M-E 2 port Serial ATA Storage Controller 1 - 2928
Contrôleur IDE Intel(R) ICH9M/M-E 2 port Serial ATA Storage Controller 2 - 292D
Contrôleur de stockage Initiateur Microsoft iSCSI
Disque dur WDC WD3200BEVT-22ZCT0 ATA Device (298 Go, IDE)
Lecteur optique HL-DT-ST DVDRAM GSA-T50N ATA Device (DVD+R9:6x, DVD-R9:6x, DVD+RW:8x/8x, DVD-RW:8x/6x, DVD-RAM:5x, DVD-ROM:8x, CD:24x/24x/24x DVD+RW/DVD-RW/DVD-RAM)
État des disques durs SMART OK

Partitions:
C: (NTFS) [ TRIAL VERSION ]
Taille totale [ TRIAL VERSION ]

Entrée:
Clavier Clavier standard PS/2
Souris Synaptics PS/2 Port TouchPad

Réseau:
Adresse IP principale [ TRIAL VERSION ]
Adresse MAC principale 00-17-C4-71-A1-9D
Carte réseau Realtek RTL8102E Family PCI-E Fast Ethernet NIC (NDIS 6.0)
Carte réseau Realtek RTL8187B Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter (192. [ TRIAL VERSION ])

Périphériques:
Imprimante Microsoft XPS Document Writer
Contrôleur USB1 Intel 82801IB ICH9 - USB Universal Host Controller [A-3]
Contrôleur USB1 Intel 82801IB ICH9 - USB Universal Host Controller [A-3]
Contrôleur USB1 Intel 82801IB ICH9 - USB Universal Host Controller [A-3]
Contrôleur USB1 Intel 82801IB ICH9 - USB Universal Host Controller [A-3]
Contrôleur USB1 Intel 82801IB ICH9 - USB Universal Host Controller [A-3]
Contrôleur USB1 Intel 82801IB ICH9 - USB Universal Host Controller [A-3]
Contrôleur USB2 Intel 82801IB ICH9 - USB2 Enhanced Host Controller [A-3]
Contrôleur USB2 Intel 82801IB ICH9 - USB2 Enhanced Host Controller [A-3]
Périphérique USB Périphérique USB composite
Périphérique USB Realtek RTL8187B Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter
Périphérique USB Realtek USB 2.0 Card Reader
Périphérique USB USB 2.0 Camera
Batterie Adaptateur secteur Microsoft
Batterie Batterie à méthode de contrôle compatible ACPI Microsoft

DMI:
Distributeur du BIOS Phoenix Technologies LTD
Version du BIOS PBPE200N.P14
Fabricant du système PACKARD BELL BV
Nom du système EasyNote MH45
Version du système LX.B200Y.012
Numéro de série du système [ TRIAL VERSION ]
UUID du système [ TRIAL VERSION ]
Fabricant de la carte mère PACKARD BELL BV
Nom de la carte mère PE2
Version de la carte mère
Numéro de série de la carte mère [ TRIAL VERSION ]
Fabricant du châssis PACKARD BELL BV
Version du châssis N/A
Numéro de série du châssis [ TRIAL VERSION ]
Identifiant du châssis [ TRIAL VERSION ]

53 réponses

Résumé de la discussion

HijackThis est évoqué comme outil pour générer un rapport d’erreur permettant d’identifier des infections virales et de guider leur suppression sur un PC Windows Vista. Des mesures essentielles recommandent Malwarebytes Anti-Malware, téléchargement et installation, mise à jour, puis examen complet et suppression des éléments détectés, le rapport d’analyse étant copié dans la réponse. D'autres évoquent l'envoi d'un rapport plus détaillé via RSIT et la consultation de tutoriels pour MalwareBytes, afin de faciliter l’identification et la suppression des programmes indésirables. Par ailleurs, la présence d’outils ou composants comme Iminent et des éléments de démarrage peut masquer des infections, ce qui rend nécessaire une vérification croisée avec d’autres outils et une sauvegarde des données.

Bobot (l’IA à votre service)
  1. Si je poste le rapport "Hijack This" y a quelqu'un qui peut identifier les erreurs ? svp c'est important
    0
    1. Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 19:56:01, on 19/12/2009
      Platform: Windows Vista SP2 (WinNT 6.00.1906)
      MSIE: Internet Explorer v7.00 (7.00.6002.18005)
      Boot mode: Normal

      Running processes:
      C:\Windows\system32\Dwm.exe
      C:\Windows\system32\taskeng.exe
      C:\Windows\Explorer.EXE
      C:\Program Files\Windows Defender\MSASCui.exe
      C:\Windows\system32\igfxsrvc.exe
      C:\Windows\system32\wbem\unsecapp.exe
      C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      C:\Program Files\PACKARD BELL\SetUpMyPC\SmpSys.exe
      C:\Windows\RtHDVCpl.exe
      C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
      C:\Windows\System32\wpcumi.exe
      C:\Windows\System32\igfxtray.exe
      C:\Windows\System32\hkcmd.exe
      C:\Windows\System32\igfxpers.exe
      C:\Program Files\Iminent\IMBooster\IMBooster.exe
      C:\Program Files\Java\jre6\bin\jusched.exe
      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
      C:\Program Files\Steam\steam.exe
      C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      C:\Users\karima\AppData\Roaming\Microsoft\Notification de cadeaux MSN\lsnfier.exe
      C:\Program Files\Windows Live\Contacts\wlcomm.exe
      C:\Program Files\Mozilla Firefox\firefox.exe
      C:\Windows\system32\conime.exe
      c:\program files\steam\steamapps\common\football manager 2010\fm.exe
      C:\Program Files\Steam\GameOverlayUI.exe
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
      C:\Windows\system32\SearchFilterHost.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ww12.cherche.us
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ww12.cherche.us
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ww12.cherche.us
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ww12.cherche.us
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ww12.cherche.us
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.packardbell.com/rdr.aspx?b=ACPW&l=040c&s=2&o=vb32&d=0309&m=easynote_mh45
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.packardbell.com/rdr.aspx?b=ACPW&l=040c&s=2&o=vb32&d=0309&m=easynote_mh45
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
      R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.cherche.us/keyword/%s
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://ww12.cherche.us
      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
      R3 - URLSearchHook: Eazel-FR Toolbar - {a8f9752d-e2b8-4e7a-86b5-499f4330e2fe} - C:\Program Files\Eazel-FR\tbEaze.dll
      F2 - REG:system.ini: UserInit=C:\Windows\system32\userinit.exe
      O1 - Hosts: ::1 localhost
      O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
      O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
      O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
      O2 - BHO: CHelperBHO - {84FF7BD6-B47F-46F8-9130-01B2696B36CB} - C:\Program Files\Iminent\SearchTheWeb\Iminent.BHO.NavigationError.dll
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Iminent.LinkToContent - {A6E9BAAF-53CD-4575-967B-2AF710A7D21F} - C:\Program Files\Iminent\IMBooster\Iminent.LinkToContent.dll
      O2 - BHO: Eazel-FR Toolbar - {a8f9752d-e2b8-4e7a-86b5-499f4330e2fe} - C:\Program Files\Eazel-FR\tbEaze.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll
      O2 - BHO: MegaIEMn - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - C:\Program Files\Megaupload\Mega Manager\MegaIEMn.dll
      O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
      O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
      O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
      O3 - Toolbar: Eazel-FR Toolbar - {a8f9752d-e2b8-4e7a-86b5-499f4330e2fe} - C:\Program Files\Eazel-FR\tbEaze.dll
      O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
      O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
      O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      O4 - HKLM\..\Run: [SmpcSys] C:\Program Files\Packard Bell\SetupMyPC\SmpSys.exe
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
      O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
      O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
      O4 - HKLM\..\Run: [WPCUMI] C:\Windows\system32\WpcUmi.exe
      O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
      O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
      O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
      O4 - HKLM\..\Run: [IMBooster] C:\Program Files\Iminent\IMBooster\imbooster.exe /warmup
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
      O4 - HKLM\..\Run: [Iminent.Notifier] C:\Program Files\Iminent\SearchTheWeb\Iminent.Notifier.exe
      O4 - HKCU\..\Run: [SmpcSys] C:\Program Files\PACKARD BELL\SetUpMyPC\SmpSys.exe
      O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
      O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent
      O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
      O4 - HKCU\..\RunOnce: [Iminent.Notifier Install] "C:\Users\karima\AppData\Local\Temp\NotifierSetup.exe" /s
      O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
      O4 - Startup: Notification de cadeaux MSN.lnk = C:\Users\karima\AppData\Roaming\Microsoft\Notification de cadeaux MSN\lsnfier.exe
      O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
      O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
      O8 - Extra context menu item: Recherche avec cherche.us - C:\Users\karima\scriptjava.html
      O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
      O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
      O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
      O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
      O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
      O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
      O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
      O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
      O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
      O13 - Gopher Prefix:
      O15 - Trusted Zone: *.chat-land.org
      O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
      O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
      O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
      O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
      O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
      0
      1. Contributeur sécurité
        bonjour

        • Télécharge Random's System Information Tool (RSIT) de Random/Random.

        (outil de diagnostic)

        http://images.malwareremoval.com/random/RSIT.exe

        • Enregistre le sur ton Bureau.

        • Double clique sur RSIT.exe pour lancer l'outil.

        • Clique sur "Continue" à l'écran Disclaimer.

        • Si l'outil HijackThis n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu s'il te le demande)

        et tu devras accepter la licence.

        • Une fois le scan terminé, deux rapports vont apparaître : poste les dans deux messages séparés stp

        Les rapports se trouvent à cet endroit:
        C:\rsit\info.txt
        C:\rsit\log.txt
        0
        1. Logfile of random's system information tool 1.06 (written by random/random)
          Run by karima at 2010-02-06 15:29:39
          Microsoft® Windows Vista™ Édition Familiale Basique Service Pack 2
          System drive C: has 220 GB (75%) free of 292 GB
          Total RAM: 3000 MB (53% free)

          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 15:29:40, on 06/02/2010
          Platform: Windows Vista SP2 (WinNT 6.00.1906)
          MSIE: Internet Explorer v7.00 (7.00.6002.18005)
          Boot mode: Normal

          Running processes:
          C:\Windows\system32\Dwm.exe
          C:\Windows\Explorer.EXE
          C:\Windows\system32\taskeng.exe
          C:\Program Files\Windows Defender\MSASCui.exe
          C:\Windows\system32\igfxsrvc.exe
          C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
          C:\Program Files\PACKARD BELL\SetUpMyPC\SmpSys.exe
          C:\Windows\RtHDVCpl.exe
          C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
          C:\Windows\System32\wpcumi.exe
          C:\Windows\System32\igfxtray.exe
          C:\Windows\System32\hkcmd.exe
          C:\Windows\System32\igfxpers.exe
          C:\Program Files\Java\jre6\bin\jusched.exe
          C:\Program Files\Iminent\IMBooster\IMBooster.exe
          C:\Program Files\Windows Live\Messenger\Windows Live Messenger.exe
          C:\Program Files\Steam\steam.exe
          C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
          C:\Windows\system32\wbem\unsecapp.exe
          C:\Program Files\Windows Live\Contacts\wlcomm.exe
          C:\Windows\system32\conime.exe
          C:\Program Files\Mozilla Firefox\firefox.exe
          C:\Program Files\Iminent\MMServer\Iminent.MMServer.exe
          C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
          C:\Program Files\Common Files\Adobe\Updater6\Adobe_Updater.exe
          C:\Users\karima\Downloads\RSIT.exe
          C:\Users\karima\Downloads\RSIT.exe
          C:\Program Files\Trend Micro\HijackThis\karima.exe

          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ww12.cherche.us
          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ww12.cherche.us
          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ww12.cherche.us
          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ww12.cherche.us
          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.packardbell.com/rdr.aspx?b=ACPW&l=040c&s=2&o=vb32&d=0309&m=easynote_mh45
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.packardbell.com/rdr.aspx?b=ACPW&l=040c&s=2&o=vb32&d=0309&m=easynote_mh45
          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
          R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.cherche.us/keyword/%s
          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://ww12.cherche.us
          R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
          R3 - URLSearchHook: Eazel-FR Toolbar - {a8f9752d-e2b8-4e7a-86b5-499f4330e2fe} - C:\Program Files\Eazel-FR\tbEaze.dll
          F2 - REG:system.ini: UserInit=C:\Windows\system32\userinit.exe
          O1 - Hosts: ::1 localhost
          O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
          O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
          O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
          O2 - BHO: CHelperBHO - {84FF7BD6-B47F-46F8-9130-01B2696B36CB} - C:\Program Files\Iminent\SearchTheWeb\Iminent.BHO.NavigationError.dll
          O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
          O2 - BHO: IMinent WebBooster - {A09AB6EB-31B5-454C-97EC-9B294D92EE2A} - C:\Program Files\Iminent\IMBooster4Web\Iminent.WebBooster.dll
          O2 - BHO: Iminent.LinkToContent - {A6E9BAAF-53CD-4575-967B-2AF710A7D21F} - C:\Program Files\Iminent\IMBooster\Iminent.LinkToContent.dll
          O2 - BHO: Eazel-FR Toolbar - {a8f9752d-e2b8-4e7a-86b5-499f4330e2fe} - C:\Program Files\Eazel-FR\tbEaze.dll
          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
          O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll
          O2 - BHO: MegaIEMn - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - C:\Program Files\Megaupload\Mega Manager\MegaIEMn.dll
          O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
          O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
          O3 - Toolbar: Eazel-FR Toolbar - {a8f9752d-e2b8-4e7a-86b5-499f4330e2fe} - C:\Program Files\Eazel-FR\tbEaze.dll
          O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
          O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
          O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
          O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
          O4 - HKLM\..\Run: [SmpcSys] C:\Program Files\Packard Bell\SetupMyPC\SmpSys.exe
          O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
          O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
          O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
          O4 - HKLM\..\Run: [WPCUMI] C:\Windows\system32\WpcUmi.exe
          O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
          O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
          O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
          O4 - HKLM\..\Run: [IMBooster] C:\Program Files\Iminent\IMBooster\imbooster.exe /warmup
          O4 - HKLM\..\Run: [Iminent.Notifier] C:\Program Files\Iminent\SearchTheWeb\Iminent.Notifier.exe
          O4 - HKCU\..\Run: [SmpcSys] C:\Program Files\PACKARD BELL\SetUpMyPC\SmpSys.exe
          O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\Windows Live Messenger.exe" /background
          O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent
          O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
          O4 - HKCU\..\RunOnce: [Iminent.Notifier Install] "C:\Users\karima\AppData\Local\Temp\NotifierSetup.exe" /s
          O4 - HKCU\..\RunOnce: [.IMinentUpdate] C:\Users\karima\AppData\Local\Temp\NotifierSetup.exe /s
          O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
          O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
          O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
          O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
          O8 - Extra context menu item: Recherche avec cherche.us - C:\Users\karima\scriptjava.html
          O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
          O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
          O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
          O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
          O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
          O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
          O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
          O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
          O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
          O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
          O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
          O13 - Gopher Prefix:
          O15 - Trusted Zone: *.chat-land.org
          O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
          O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
          O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
          O23 - Service: Service Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
          O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
          O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
          0
          1. info.txt logfile of random's system information tool 1.06 2010-02-06 15:26:46

            ======Uninstall list======

            Adobe Flash Player 10 Plugin-->C:\Windows\system32\Macromed\Flash\uninstall_plugin.exe
            Adobe Flash Player ActiveX-->C:\Windows\system32\Macromed\Flash\uninstall_activeX.exe
            Adobe Reader 9 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A90000000001}
            ALTools Update-->"C:\Program Files\ESTsoft\ALUpdate\unins000.exe"
            ALZip-->"C:\Program Files\ESTsoft\ALZip\unins000.exe"
            Assistant de connexion Windows Live-->MsiExec.exe /I{DCE8CD14-FBF5-4464-B9A4-E18E473546C7}
            Avira AntiVir Personal - Free Antivirus-->C:\Program Files\Avira\AntiVir Desktop\setup.exe /REMOVE
            CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
            Eazel-FR Toolbar-->C:\PROGRA~1\Eazel-FR\UNWISE.EXE /U C:\PROGRA~1\Eazel-FR\INSTALL.LOG
            Football Manager 2010-->"C:\Program Files\Steam\steam.exe" steam://uninstall/34000
            Google Toolbar for Internet Explorer-->"C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_E85CDE7661A53A6A.exe" /uninstall
            Google Toolbar for Internet Explorer-->MsiExec.exe /I{18455581-E099-4BA8-BC6B-F34B2F06600C}
            Google Update Helper-->MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
            HijackThis 2.0.2-->"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
            Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
            Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
            IMBooster-->"C:\ProgramData\{DF3D7EF6-7048-48B8-BA35-8E517A744670}\IMBoosterUpdate.3.0.1005.0.exe" REMOVE=TRUE MODIFY=FALSE
            IMBooster-->C:\ProgramData\{DF3D7EF6-7048-48B8-BA35-8E517A744670}\IMBoosterUpdate.3.0.1005.0.exe
            IMBooster4Web-->C:\ProgramData\{924B45CC-9477-41E9-808B-6F623B920F1E}\IMBooster4Web.Setup.exe
            Installation Windows Live-->C:\Program Files\Windows Live\Installer\wlarp.exe
            Installation Windows Live-->MsiExec.exe /I{46ABBC54-1872-4AA3-95E2-F2C063A63F31}
            Intel(R) Graphics Media Accelerator Driver-->C:\Windows\system32\igxpun.exe -uninstall
            Intel(R) TV Wizard-->C:\Windows\system32\TVWizudlg.exe -uninstall
            Java(TM) 6 Update 17-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216014FF}
            Junk Mail filter update-->MsiExec.exe /I{E2DFE069-083E-4631-9B6C-43C48E991DE5}
            K-Lite Codec Pack 5.0.0 (Full)-->"C:\Program Files\K-Lite Codec Pack\unins000.exe"
            Ma-Config.com-->MsiExec.exe /X{425FFD94-36BD-4933-881B-FE0B9DADF2B7}
            Mega Manager-->C:\Program Files\InstallShield Installation Information\{3B6E3FC6-274C-4B6C-BC85-5C3B15DE18E2}\setup.exe -runfromtemp -l0x0009 -removeonly
            Microsoft .NET Framework 3.5 Language Pack SP1 - fra-->MsiExec.exe /I{3E31821C-7917-367E-938E-E65FC413EA31}
            Microsoft .NET Framework 3.5 SP1-->c:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
            Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
            Microsoft Choice Guard-->MsiExec.exe /X{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}
            Microsoft Office Live Add-in 1.3-->MsiExec.exe /I{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}
            Microsoft Office XP Professional avec FrontPage-->MsiExec.exe /I{9028040C-6000-11D3-8CFE-0050048383C9}
            Microsoft Search Enhancement Pack-->MsiExec.exe /X{4CBA3D4C-8F51-4D60-B27E-F6B641C571E7}
            Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
            Microsoft Sync Framework Runtime Native v1.0 (x86)-->MsiExec.exe /I{8A74E887-8F0F-4017-AF53-CBA42211AAA5}
            Microsoft Sync Framework Services Native v1.0 (x86)-->MsiExec.exe /I{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}
            Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148-->MsiExec.exe /X{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}
            Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17-->MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475}
            Microsoft Works-->MsiExec.exe /I{0214A441-A4AB-43A8-8DEF-2F73C5364673}
            Module linguistique Microsoft .NET Framework 3.5 SP1- fra-->c:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 Language Pack SP1 - fra\setup.exe
            Mozilla Firefox (3.5.7)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
            MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
            MSXML 4.0 SP2 (KB973688)-->MsiExec.exe /I{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
            neroxml-->MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B}
            Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
            Realtek 8169 8168 8101E 8102E Ethernet Driver-->C:\Program Files\InstallShield Installation Information\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}\setup.exe -runfromtemp -l0x040c -removeonly
            Realtek High Definition Audio Driver-->RtlUpd.exe -r -m -nrg2709
            Realtek USB 2.0 Card Reader-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{DC24971E-1946-445D-8A82-CE685433FA7D}\setup.exe" -l0x9 -removeonly
            SearchTheWeb-->"C:\ProgramData\{FBF25D20-0F4E-4122-B315-14FEAEC696D6}\NotifierSetup.exe" REMOVE=TRUE MODIFY=FALSE
            SearchTheWeb-->C:\ProgramData\{FBF25D20-0F4E-4122-B315-14FEAEC696D6}\NotifierSetup.exe
            Setup My PC-->"C:\Program Files\InstallShield Installation Information\{28518520-F25C-48C3-A224-861F331602F4}\setup.exe" -runfromtemp -l0x040c -removeonly
            Steam-->MsiExec.exe /X{048298C9-A4D3-490B-9FF9-AB023A9238F3}
            Synaptics Pointing Device Driver-->rundll32.exe "C:\Program Files\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall
            Update for Microsoft .NET Framework 3.5 SP1 (KB963707)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {B2AE9C82-DC7B-3641-BFC8-87275C4F3607} /qb+ REBOOTPROMPT=""
            Windows Live Call-->MsiExec.exe /I{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}
            Windows Live Communications Platform-->MsiExec.exe /I{ED00D08A-3C5F-488D-93A0-A04F21F23956}
            Windows Live Mail-->MsiExec.exe /I{5DD76286-9BE7-4894-A990-E905E91AC818}
            Windows Live Messenger-->MsiExec.exe /X{770F1BEC-2871-4E70-B837-FB8525FFA3B1}
            Windows Live Toolbar-->MsiExec.exe /X{F7D27C70-90F5-49B9-B188-0A133C0CE353}
            Windows Live Writer-->MsiExec.exe /X{4634B21A-CC07-4396-890C-2B8168661FEA}
            Windows Media Player Firefox Plugin-->MsiExec.exe /I{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}

            ======Security center information======

            AS: Windows Defender

            ======System event log======

            Computer Name: PC-de-Cyril-MARCO
            Event Code: 15016
            Message: Impossible d’initialiser le package de sécurité Kerberos pour l’authentification côté serveur. Le champ de données contient le numéro de l’erreur.
            Record Number: 44150
            Source Name: Microsoft-Windows-HttpEvent
            Time Written: 20090831083653.177099-000
            Event Type: Erreur
            User:

            Computer Name: PC-de-Cyril-MARCO
            Event Code: 4001
            Message: Le Service d’autoconfiguration WLAN s’est arrêté correctement.

            Record Number: 44137
            Source Name: Microsoft-Windows-WLAN-AutoConfig
            Time Written: 20090830232031.836400-000
            Event Type: Avertissement
            User: AUTORITE NT\SYSTEM

            Computer Name: PC-de-Cyril-MARCO
            Event Code: 7000
            Message: Le service Parallel port driver n'a pas pu démarrer en raison de l'erreur :
            Le service ne peut pas être démarré parce qu'il est désactivé ou qu'aucun périphérique activé ne lui est associé.
            Record Number: 44082
            Source Name: Service Control Manager
            Time Written: 20090830214505.000000-000
            Event Type: Erreur
            User:

            Computer Name: PC-de-Cyril-MARCO
            Event Code: 15016
            Message: Impossible d’initialiser le package de sécurité Kerberos pour l’authentification côté serveur. Le champ de données contient le numéro de l’erreur.
            Record Number: 44042
            Source Name: Microsoft-Windows-HttpEvent
            Time Written: 20090830214452.479104-000
            Event Type: Erreur
            User:

            Computer Name: PC-de-Cyril-MARCO
            Event Code: 4001
            Message: Le Service d’autoconfiguration WLAN s’est arrêté correctement.

            Record Number: 44032
            Source Name: Microsoft-Windows-WLAN-AutoConfig
            Time Written: 20090830184728.396000-000
            Event Type: Avertissement
            User: AUTORITE NT\SYSTEM

            =====Application event log=====

            Computer Name: PC-de-karima
            Event Code: 0
            Message:
            Record Number: 1037
            Source Name: AtBroker
            Time Written: 20090417140406.000000-000
            Event Type: Avertissement
            User:

            Computer Name: PC-de-karima
            Event Code: 1534
            Message: Échec de la notification du profil de l’événement Delete pour le composant {DE3F3560-3032-41B4-B6CF-F703B1B95640}. Le code d’erreur est -2147024875.

            Record Number: 1014
            Source Name: Microsoft-Windows-User Profiles Service
            Time Written: 20090417133537.000000-000
            Event Type: Avertissement
            User: AUTORITE NT\SYSTEM

            Computer Name: PC-de-karima
            Event Code: 2
            Message: Impossible de supprimer les données indexées par le service Windows Search pour l’utilisateur 'PC-de-karima\Administrateur' suite à la suppression du profil utilisateur. Code d’erreur 0x80070015.

            Le périphérique n'est pas prêt.
            .
            Record Number: 1013
            Source Name: Microsoft-Windows-Search-ProfileNotify
            Time Written: 20090417133537.000000-000
            Event Type: Erreur
            User:

            Computer Name: PC-de-karima
            Event Code: 10
            Message: Le filtre d’événement avec la requête « SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99 » n’a pas pu être réactivé dans l’espace de noms « //./root/CIMV2 » à cause de l’erreur 0x80041003. Les événements ne peuvent pas être délivrés à travers ce filtre tant que le problème ne sera pas corrigé.
            Record Number: 1004
            Source Name: Microsoft-Windows-WMI
            Time Written: 20090417133513.000000-000
            Event Type: Erreur
            User:

            Computer Name: PC-de-karima
            Event Code: 1008
            Message: Le service Windows Search tente de supprimer l’ancien catalogue.

            Record Number: 1000
            Source Name: Microsoft-Windows-Search
            Time Written: 20090417133511.000000-000
            Event Type: Avertissement
            User:

            =====Security event log=====

            Computer Name: PC-de-karima
            Event Code: 4647
            Message: Fermeture de session initiée par l’utilisateur :

            Sujet :
            ID de sécurité : S-1-5-21-965736646-3695093779-2154893468-1000
            Nom du compte : karima
            Domaine du compte : PC-de-karima
            ID d’ouverture de session : 0x1837b

            Cet événement est généré lorsqu’une fermeture de session est initiée, mais que le nombre de références du jeton n’étant pas zéro, la session ouverte ne peut pas être supprimée. Aucune autre activité initiée par l’utilisateur ne peut se produire. Cet événement peut être interprété comme un événement de fermeture de session.
            Record Number: 9503
            Source Name: Microsoft-Windows-Security-Auditing
            Time Written: 20090821101602.158901-000
            Event Type: Succès de l'audit
            User:

            Computer Name: PC-de-karima
            Event Code: 5038
            Message: L’intégrité du code a déterminé que le hachage de l’image d’un fichier n’est pas valide. Le fichier peut être endommagé en raison d’une modification non autorisée ou le hachage non valide peut indiquer une erreur d’unité de disque potentielle.

            Nom du fichier : \Device\HarddiskVolume2\Program Files\Iminent\IMBooster\Iminent.WinCore.dll
            Record Number: 9502
            Source Name: Microsoft-Windows-Security-Auditing
            Time Written: 20090821101226.103301-000
            Event Type: Échec de l'audit
            User:

            Computer Name: PC-de-karima
            Event Code: 5038
            Message: L’intégrité du code a déterminé que le hachage de l’image d’un fichier n’est pas valide. Le fichier peut être endommagé en raison d’une modification non autorisée ou le hachage non valide peut indiquer une erreur d’unité de disque potentielle.

            Nom du fichier : \Device\HarddiskVolume2\Program Files\Iminent\IMBooster\Iminent.WinCore.dll
            Record Number: 9501
            Source Name: Microsoft-Windows-Security-Auditing
            Time Written: 20090821101226.075301-000
            Event Type: Échec de l'audit
            User:

            Computer Name: PC-de-karima
            Event Code: 4904
            Message: Une tentative d’inscription de la source d’un événement de sécurité a été effectuée.

            Sujet :
            ID de sécurité : S-1-5-18
            Nom du compte : PC-DE-KARIMA$
            Domaine du compte : WORKGROUP
            ID d’ouverture de session : 0x3e7

            Processus :
            ID du processus : 0xf74
            Nom du processus : C:\Windows\System32\VSSVC.exe

            Source de l’événement :
            Nom de la source : VSSAudit
            ID de la source de l’événement : 0xe25d7
            Record Number: 9500
            Source Name: Microsoft-Windows-Security-Auditing
            Time Written: 20090821083820.998301-000
            Event Type: Succès de l'audit
            User:

            Computer Name: PC-de-karima
            Event Code: 4905
            Message: Une tentative d’annulation d’inscription de la source d’un événement de sécurité a été effectuée.

            Sujet :
            ID de sécurité : S-1-5-18
            Nom du compte : PC-DE-KARIMA$
            Domaine du compte : WORKGROUP
            ID d’ouverture de session : 0x3e7

            Processus :
            ID du processus : 0xf74
            Nom du processus : C:\Windows\System32\VSSVC.exe

            Source de l’événement :
            Nom de la source : VSSAudit
            ID de la source de l’événement : 0xe25d7
            Record Number: 9499
            Source Name: Microsoft-Windows-Security-Auditing
            Time Written: 20090821083820.998301-000
            Event Type: Succès de l'audit
            User:

            ======Environment variables======

            "ComSpec"=%SystemRoot%\system32\cmd.exe
            "FP_NO_HOST_CHECK"=NO
            "OS"=Windows_NT
            "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\ESTsoft\ALZip
            "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
            "PROCESSOR_ARCHITECTURE"=x86
            "TEMP"=%SystemRoot%\TEMP
            "TMP"=%SystemRoot%\TEMP
            "USERNAME"=SYSTEM
            "windir"=%SystemRoot%
            "PROCESSOR_LEVEL"=6
            "PROCESSOR_IDENTIFIER"=x86 Family 6 Model 23 Stepping 10, GenuineIntel
            "PROCESSOR_REVISION"=170a
            "NUMBER_OF_PROCESSORS"=2
            "TRACE_FORMAT_SEARCH_PATH"=\\NTREL202.ntdev.corp.microsoft.com\4F18C3A5-CA09-4DBD-B6FC-219FDD4C6BE0\TraceFormat
            "DFSTRACINGON"=FALSE

            -----------------EOF-----------------
            0
            1. Contributeur sécurité
              Téléchargez MalwareByte's Anti-Malware
              https://www.commentcamarche.net/telecharger/securite/14361-malwarebytes-anti-malware/

              . Enregistres le sur le bureau
              . Double cliques sur le fichier téléchargé pour lancer le processus d'installation.
              . Dans l'onglet "mise à jour", cliques sur le bouton Recherche de mise à jour
              . Si le pare-feu demande l'autorisation de se connecter pour malwarebytes, accepte
              . Une fois la mise à jour terminé
              . Rend-toi dans l'onglet, Recherche
              . Sélectionnes Exécuter un examen complet (examen assez long)
              . Cliques sur Rechercher
              . Le scan démarre.
              . A la fin de l'analyse, un message s'affiche : L'examen s'est terminé normalement. Cliquez sur 'Afficher les résultats' pour afficher tous les objets trouvés.
              . Cliques sur Ok pour poursuivre.
              . Si des malwares ont été détectés, clique sur Afficher les résultats
              . Sélectionnes tout (ou laisses cochés) et cliques sur Supprimer la sélection Malwarebytes va détruire les fichiers et clés de registre et en mettre une copie dans la quarantaine. . Malwarebytes va ouvrir le bloc-notes et y copier le rapport d'analyse.
              . Rends toi dans l'onglet rapport/log
              . Tu cliques dessus pour l'afficher, une fois affiché
              . Tu cliques sur edition en haut du boc notes, et puis sur sélectionner tous
              . Tu recliques sur edition et puis sur copier et tu reviens sur le forum et dans ta réponse
              . tu cliques droit dans le cadre de la reponse et coller

              Si tu as besoin d'aide regarde ces tutoriels :
              Aide: https://www.malekal.com/tutoriel-malwarebyte-anti-malware/
              http://www.infos-du-net.com/forum/278396-11-tuto-malwarebytes-anti-malware-mbam


              Je cherche beaucoup...et maintenant je trouve !
              (sourire)
              0
              1. Malwarebytes' Anti-Malware 1.44
                Version de la base de données: 3697
                Windows 6.0.6002 Service Pack 2
                Internet Explorer 7.0.6002.18005

                06/02/2010 16:57:46
                mbam-log-2010-02-06 (16-57-46).txt

                Type de recherche: Examen complet (C:\|)
                Eléments examinés: 212761
                Temps écoulé: 39 minute(s), 44 second(s)

                Processus mémoire infecté(s): 0
                Module(s) mémoire infecté(s): 0
                Clé(s) du Registre infectée(s): 1
                Valeur(s) du Registre infectée(s): 0
                Elément(s) de données du Registre infecté(s): 5
                Dossier(s) infecté(s): 0
                Fichier(s) infecté(s): 0

                Processus mémoire infecté(s):
                (Aucun élément nuisible détecté)

                Module(s) mémoire infecté(s):
                (Aucun élément nuisible détecté)

                Clé(s) du Registre infectée(s):
                HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\Recherche avec cherche.us (Redir.ChercheUs) -> Quarantined and deleted successfully.

                Valeur(s) du Registre infectée(s):
                (Aucun élément nuisible détecté)

                Elément(s) de données du Registre infecté(s):
                HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\Default_Page_URL (Hijack.StartPage) -> Bad: (http://www.cherche.us) Good: (http://www.google.com) -> Quarantined and deleted successfully.
                HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\Start Page_bak (Hijack.StartPage) -> Bad: (http://www.cherche.us) Good: (http://www.google.com) -> Quarantined and deleted successfully.
                HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\Default_Search_URL (Hijack.SearchPage) -> Bad: (http://ww12.cherche.us Good: (http://www.google.com) -> Quarantined and deleted successfully.
                HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\Search Bar (Hijack.SearchPage) -> Bad: (http://www.cherche.us) Good: (http://www.google.com) -> Quarantined and deleted successfully.
                HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\Search Page (Hijack.SearchPage) -> Bad: (http://www.cherche.us) Good: (http://www.google.com) -> Quarantined and deleted successfully.

                Dossier(s) infecté(s):
                (Aucun élément nuisible détecté)

                Fichier(s) infecté(s):
                (Aucun élément nuisible détecté)
                0
                1. Contributeur sécurité
                  ok

                  tu peux vider la quarantaine

                  .............

                  Desactive ton antivirus le temps de la manip ainsi que ton parefeu si présent(car il est detecté a tort comme infection)

                  ▶ Télécharge et installe List&Kill'em et enregistre le sur ton bureau
                  http://sd-1.archive-host.com/membres/up/829108531491024/List_Killem_Install.exe

                  double clique ( clic droit "executer en tant qu'administrateur" pour Vista/7 ) sur le raccourci sur ton bureau pour lancer l'installation

                  coche la case "creer une icone sur le bureau"

                  une fois terminée , clic sur "terminer" et le programme se lancer seul

                  choisis la langue puis choisis l'option 1 = Mode Recherche

                  ▶ laisse travailler l'outil

                  à l'apparition de la fenetre blanche , c'est un peu long , c'est normal , le programme n'est pas bloqué.

                  un rapport du nom de catchme apparait sur ton bureau , ignore-le,ne le poste pas , mais ne le supprime pas pour l instant, le scan n'est pas fini.

                  ▶ Poste le contenu du rapport qui s'ouvre aux 100 % du scan à l'ecran "COMPLETED"

                  tu peux supprimer le rapport catchme.log de ton bureau maintenant.
                  0
                  1. ok je vais faire ça ...Donc si on fait un bilan, mon PC est-il infécté ?
                    0
                    1. Contributeur sécurité
                      il l'était et killem est là pour ne rien oublier
                      0
                      1. Il était infécté par quoi ? Et beaucoup ?

                        Pourtant mon PC est recent je l'ai acheté cet été, il va relativement vite, il n'y a pas de pub qui se lance au démarrage. Sauf que là j'ai voulu faire un petit contrôle pour voir si mon PC n'était pas infécté.
                        0
                        1. Contributeur sécurité
                          un détournement internet que l'on attrape avec chat-land.org

                          fais killem
                          0
                          1. List'em by g3n-h@ckm@n 1.2.4.0

                            User : karima (Administrateurs)
                            Update on 05/02/2010 by g3n-h@ckm@n ::::: 18.40
                            Start at: 17:43:57 | 06/02/2010
                            Contact : https://forums.commentcamarche.net/forum/virus-securite-7

                            Pentium(R) Dual-Core CPU T4200 @ 2.00GHz
                            Microsoft® Windows Vista™ Édition Familiale Basique (6.0.6002 32-bit) # Service Pack 2
                            Internet Explorer 7.0.6002.18005
                            Windows Firewall Status : Disabled

                            C:\ -> Disque fixe local | 285,09 Go (215,11 Go free) [OS] | NTFS
                            D:\ -> Disque CD-ROM

                            ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running

                            C:\Windows\System32\smss.exe
                            C:\Windows\system32\csrss.exe
                            C:\Windows\system32\wininit.exe
                            C:\Windows\system32\csrss.exe
                            C:\Windows\system32\services.exe
                            C:\Windows\system32\lsass.exe
                            C:\Windows\system32\lsm.exe
                            C:\Windows\system32\winlogon.exe
                            C:\Windows\system32\svchost.exe
                            C:\Windows\system32\svchost.exe
                            C:\Windows\System32\svchost.exe
                            C:\Windows\System32\svchost.exe
                            C:\Windows\System32\svchost.exe
                            C:\Windows\system32\svchost.exe
                            C:\Windows\system32\SLsvc.exe
                            C:\Windows\system32\svchost.exe
                            C:\Windows\system32\svchost.exe
                            C:\Windows\System32\spoolsv.exe
                            C:\Windows\system32\Dwm.exe
                            C:\Windows\Explorer.EXE
                            C:\Windows\system32\taskeng.exe
                            C:\Program Files\Avira\AntiVir Desktop\sched.exe
                            C:\Windows\system32\svchost.exe
                            C:\Windows\system32\taskeng.exe
                            C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                            C:\Windows\system32\svchost.exe
                            C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                            C:\Windows\system32\svchost.exe
                            C:\Windows\System32\svchost.exe
                            C:\Windows\system32\SearchIndexer.exe
                            C:\Program Files\Windows Defender\MSASCui.exe
                            C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                            C:\Program Files\PACKARD BELL\SetUpMyPC\SmpSys.exe
                            C:\Windows\RtHDVCpl.exe
                            C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
                            C:\Windows\System32\wpcumi.exe
                            C:\Windows\System32\igfxtray.exe
                            C:\Windows\System32\hkcmd.exe
                            C:\Windows\System32\igfxpers.exe
                            C:\Program Files\Java\jre6\bin\jusched.exe
                            C:\Windows\system32\igfxsrvc.exe
                            C:\Program Files\Iminent\IMBooster\IMBooster.exe
                            C:\Program Files\Windows Live\Messenger\Windows Live Messenger.exe
                            C:\Windows\system32\wbem\wmiprvse.exe
                            C:\Program Files\Steam\steam.exe
                            C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                            C:\Windows\system32\wbem\unsecapp.exe
                            C:\Program Files\Common Files\Steam\SteamService.exe
                            C:\Program Files\Mozilla Firefox\firefox.exe
                            C:\Program Files\Iminent\MMServer\Iminent.MMServer.exe
                            c:\program files\steam\steamapps\common\football manager 2010\fm.exe
                            C:\Program Files\Steam\GameOverlayUI.exe
                            C:\Program Files\Windows Live\Contacts\wlcomm.exe
                            C:\Windows\system32\conime.exe
                            C:\Windows\system32\SearchProtocolHost.exe
                            C:\Windows\system32\SearchFilterHost.exe
                            C:\Program Files\List_Kill'em\List_Kill'em.scr
                            C:\Windows\system32\cmd.exe
                            C:\Windows\system32\wbem\wmiprvse.exe
                            C:\Users\karima\AppData\Local\Temp\9B26.tmp\pv.exe

                            ======================
                            Keys "Run"
                            ======================
                            [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                            SmpcSys REG_SZ C:\Program Files\PACKARD BELL\SetUpMyPC\SmpSys.exe
                            msnmsgr REG_SZ "C:\Program Files\Windows Live\Messenger\Windows Live Messenger.exe" /background
                            Steam REG_SZ "C:\Program Files\Steam\Steam.exe" -silent
                            swg REG_SZ "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"

                            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                            Windows Defender REG_EXPAND_SZ %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                            SynTPEnh REG_SZ C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                            SmpcSys REG_SZ C:\Program Files\Packard Bell\SetupMyPC\SmpSys.exe
                            Adobe Reader Speed Launcher REG_SZ "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
                            RtHDVCpl REG_SZ RtHDVCpl.exe
                            avgnt REG_SZ "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
                            WPCUMI REG_SZ C:\Windows\system32\WpcUmi.exe
                            IgfxTray REG_SZ C:\Windows\system32\igfxtray.exe
                            HotKeysCmds REG_SZ C:\Windows\system32\hkcmd.exe
                            Persistence REG_SZ C:\Windows\system32\igfxpers.exe
                            SunJavaUpdateSched REG_SZ "C:\Program Files\Java\jre6\bin\jusched.exe"
                            IMBooster REG_SZ C:\Program Files\Iminent\IMBooster\imbooster.exe /warmup
                            Iminent.Notifier REG_SZ C:\Program Files\Iminent\SearchTheWeb\Iminent.Notifier.exe
                            Malwarebytes Anti-Malware (reboot) REG_SZ "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript

                            [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]

                            [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]

                            =====================
                            Other Keys
                            =====================
                            [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
                            ConsentPromptBehaviorAdmin REG_DWORD 2 (0x2)
                            ConsentPromptBehaviorUser REG_DWORD 1 (0x1)
                            EnableInstallerDetection REG_DWORD 1 (0x1)
                            EnableLUA REG_DWORD 1 (0x1)
                            EnableSecureUIAPaths REG_DWORD 1 (0x1)
                            EnableVirtualization REG_DWORD 1 (0x1)
                            PromptOnSecureDesktop REG_DWORD 1 (0x1)
                            ValidateAdminCodeSignatures REG_DWORD 0 (0x0)
                            dontdisplaylastusername REG_DWORD 0 (0x0)
                            legalnoticecaption REG_SZ
                            legalnoticetext REG_SZ
                            scforceoption REG_DWORD 0 (0x0)
                            shutdownwithoutlogon REG_DWORD 1 (0x1)
                            undockwithoutlogon REG_DWORD 1 (0x1)
                            FilterAdministratorToken REG_DWORD 0 (0x0)
                            EnableUIADesktopToggle REG_DWORD 0 (0x0)

                            ===============
                            [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
                            NoDriveTypeAutoRun REG_DWORD 145 (0x91)

                            ===============
                            [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
                            BindDirectlyToPropertySetStorage REG_DWORD 0 (0x0)

                            ===============
                            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
                            AppInit_DLLS REG_SZ

                            ===============
                            [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
                            ReportBootOk REG_SZ 1
                            Shell REG_SZ explorer.exe
                            Userinit REG_SZ C:\Windows\system32\userinit.exe
                            VmApplet REG_SZ rundll32 shell32,Control_RunDLL "sysdm.cpl"
                            AutoRestartShell REG_DWORD 1 (0x1)
                            LegalNoticeCaption REG_SZ
                            LegalNoticeText REG_SZ
                            PowerdownAfterShutdown REG_SZ 0
                            ShutdownWithoutLogon REG_SZ 0
                            cachedlogonscount REG_SZ 10
                            forceunlocklogon REG_DWORD 0 (0x0)
                            passwordexpirywarning REG_DWORD 14 (0xe)
                            Background REG_SZ 0 0 0
                            DebugServerCommand REG_SZ no
                            WinStationsDisabled REG_SZ 0
                            DisableCAD REG_DWORD 1 (0x1)
                            scremoveoption REG_SZ 0
                            ShutdownFlags REG_DWORD 39 (0x27)
                            Windows Shell (ezShellStart) REG_SZ C:\Windows\system32\userinit.exe,

                            ===============
                            [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\igfxcui]

                            ===============
                            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]

                            ===============
                            [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

                            [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

                            ===============
                            ActivX controls
                            ===============
                            HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{8AD9C840-044E-11D1-B3E9-00805F499D93}
                            HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
                            HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}

                            ===============
                            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}
                            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{26923b43-4d38-484f-9b9e-de460746276c}
                            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}
                            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{08B0E5C0-4FCB-11CF-AAA5-00401C608500}
                            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2179C5D3-EBFF-11CF-B6FD-00AA00B4E220}
                            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}
                            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}
                            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{3af36230-a269-11d1-b5bf-0000f8051515}
                            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}
                            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA848-CC51-11CF-AAFA-00AA00B6015C}
                            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA855-CC51-11CF-AAFA-00AA00B6015F}
                            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{45ea75a0-a269-11d1-b5bf-0000f8051515}
                            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4f645220-306d-11d2-995d-00c04f98bbc9}
                            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5fd399c0-a70a-11d1-9948-00c04f98bbc9}
                            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{630b1da0-b465-11d1-9948-00c04f98bbc9}
                            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}
                            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6fab99d0-bab8-11d1-994a-00c04f98bbc9}
                            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{73FA19D0-2D75-11D2-995D-00C04F98BBC9}
                            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7790769C-0471-11d2-AF11-00C04FA35D02}
                            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7C028AF8-F614-47B3-82DA-BA94E41B1089}
                            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4340}
                            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4383}
                            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}
                            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9381D8F2-0288-11D0-9501-00AA00B911A5}
                            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C6BAF60B-6E91-453F-BFF9-D3789CFEFCDD}
                            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C9E9A340-D1F1-11D0-821E-444553540600}
                            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CDD7975E-60F8-41d5-8149-19E51D6F71D0}
                            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{D27CDB6E-AE6D-11CF-96B8-444553540000}
                            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{de5aed00-a4bf-11d1-9948-00c04f98bbc9}
                            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{E92B03AB-B707-11d2-9CBD-0000F87A369E}

                            ==============
                            BHO :
                            ======
                            [<NO NAME> REG_SZ ]
                            [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{84FF7BD6-B47F-46F8-9130-01B2696B36CB}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{A09AB6EB-31B5-454C-97EC-9B294D92EE2A}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{A6E9BAAF-53CD-4575-967B-2AF710A7D21F}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{a8f9752d-e2b8-4e7a-86b5-499f4330e2fe}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{bf00e119-21a3-4fd1-b178-3b8537e75c92}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10}]

                            ================
                            Internet Explorer :
                            ================
                            [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
                            Start Page REG_SZ http://homepage.packardbell.com/rdr.aspx?b=ACPW&l=040c&s=2&o=vb32&d=0309&m=easynote_mh45

                            [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                            Start Page REG_SZ https://www.msn.com/fr-fr/?ocid=iehp

                            ========
                            Services
                            ========
                            [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services]

                            Ndisuio : 0x3 ( OK = 3 )
                            EapHost : 0x3 ( OK = 2 )
                            Wlansvc : 0x2 ( OK = 2 )
                            SharedAccess : 0x4 ( OK = 2 )
                            windefend : 0x2 ( OK = 2 )
                            wuauserv : 0x2 ( OK = 2 )
                            wscsvc : 0x2 ( OK = 2 )

                            =========
                            Atapi.sys
                            =========

                            %%%% HASHDEEP-1.0
                            %%%% size,md5,sha256,filename
                            ## Invoked from: C:\Users\karima\AppData\Local\Temp\9B26.tmp
                            ## C:\> hashdeep C:\Windows\System32\Drivers\atapi.sys
                            ##
                            19944,1f05b78ab91c9075565a9d8a4b880bc4,737be9f9376dab0ccdfed93ea6d67f0c432367ea63cd772a453485be769af3bd,C:\Windows\System32\Drivers\atapi.sys

                            Sources
                            =======

                            C:\Windows\System32\drivers\atapi.sys
                            C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_b12d8e84\atapi.sys
                            C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys
                            C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_cc18792d\atapi.sys
                            C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a2189ce9c\atapi.sys
                            C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_df23a1261eab99e8\atapi.sys

                            Référence :
                            ==========

                            Win XP_32b : a64013e98426e1877cb653685c5c0009
                            Win XP_SP2_32b : CDFE4411A69C224BD1D11B2DA92DAC51
                            Win XP_SP3_32b : 9F3A2F5AA6875C72BF062C712CFA2674
                            Vista_32b : e03e8c99d15d0381e02743c36afc7c6f
                            Vista_SP1_32b : 2d9c903dc76a66813d350a562de40ed9
                            Vista_SP2_32b : 1F05B78AB91C9075565A9D8A4B880BC4
                            Vista_SP2_64b : 1898FAE8E07D97F2F6C2D5326C633FAC
                            Windows 7_32b : 80C40F7FDFC376E4C5FEEC28B41C119E
                            Windows 7_64b : 02062C0B390B7729EDC9E69C680A6F3C

                            =======
                            Drive :
                            =======

                            D‚fragmenteur de disque Windows
                            Copyright (c) 2006 Microsoft Corp.

                            Rapport d'analyse pour le volume C: OS

                            Taille du volume = 285 Go
                            Espace libre = 215 Go
                            tendue d'espace libre la plus grande = 121 Go
                            Pourcentage de fragmentation des fichiers = 1 %

                            Remarqueÿ: sur les volumes NTFS, les fragments de fichiers de plus de 64ÿMo ne sont pas inclus dans les statistiques de fragmentation.

                            Il n'est pas n‚cessaire de d‚fragmenter ce volume.

                            ¤¤¤¤¤¤¤¤¤¤ Files/folders :

                            Present !! : C:\Windows\Installer\{E1B94435-241E-4519-B1C3-C4DD9EB352A2}
                            Present !! : C:\Windows\msnimport.exe
                            Present !! : C:\Windows\System32\EZUPBH~1.DLL
                            Present !! : C:\Users\karima\LOCAL Settings\Temp\NotifierSetup.exe

                            ¤¤¤¤¤¤¤¤¤¤ Keys :

                            Present !! : HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Iminent.Notifier
                            Present !! : "HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}"
                            Present !! : "HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}"
                            Present !! : HKCR\CLSID\{248dd896-bb45-11cf-9abc-0080c7e7b78d}
                            Present !! : HKCR\CLSID\{248dd897-bb45-11cf-9abc-0080c7e7b78d}
                            Present !! : HKCR\ezUPBHook.ShellObj
                            Present !! : HKCR\ezUPBHook.ShellObj.1
                            Present !! : HKCR\Interface\{248dd892-bb45-11cf-9abc-0080c7e7b78d}
                            Present !! : HKCR\Interface\{248dd893-bb45-11cf-9abc-0080c7e7b78d}
                            Present !! : HKCR\TypeLib\{248dd890-bb45-11cf-9abc-0080c7e7b78d}
                            Present !! : HKCR\TypeLib\{478CAB91-9E28-11D4-97FF-0050047D51FB}
                            Present !! : HKCU\software\Iminent
                            Present !! : HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{83ff80f4-8c74-4b80-b5ba-c8ddd434e5c4}
                            Present !! : HKLM\Software\Classes\Interface\{01009AEC-AFAA-4982-9F2B-6411C5C27E77}
                            Present !! : HKLM\software\Iminent

                            ============

                            catchme 0.3.1398.3 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                            Rootkit scan 2010-02-06 17:52:35
                            Windows 6.0.6002 Service Pack 2 NTFS

                            scanning hidden processes ...

                            scanning hidden services & system hive ...

                            scanning hidden registry entries ...

                            scanning hidden files ...

                            scan completed successfully
                            hidden processes: 0
                            hidden services: 0
                            hidden files: 0

                            Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

                            device: opened successfully
                            user: MBR read successfully
                            called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ataport.SYS hal.dll pciide.sys PCIIDEX.SYS atapi.sys dxgkrnl.sys igdkmd32.sys
                            kernel: MBR read successfully
                            user & kernel MBR OK

                            ==========
                            Programs
                            ==========

                            Adobe
                            Avira
                            CCleaner
                            Common Files
                            Conduit
                            desktop.ini
                            Eazel-FR
                            ESTsoft
                            Fichiers communs
                            Google
                            Iminent
                            InstallShield Installation Information
                            Intel
                            Internet Explorer
                            Java
                            K-Lite Codec Pack
                            List_Kill'em
                            ma-config.com
                            Malwarebytes' Anti-Malware
                            Megaupload
                            Microsoft
                            Microsoft Games
                            Microsoft Office
                            Microsoft Silverlight
                            Microsoft Sync Framework
                            Microsoft Works
                            Movie Maker
                            Mozilla Firefox
                            MSBuild
                            MSXML 4.0
                            Nero
                            PACKARD BELL
                            Realtek
                            Reference Assemblies
                            Sports Interactive
                            Steam
                            Synaptics
                            Trend Micro
                            Uninstall Information
                            Windows Calendar
                            Windows Collaboration
                            Windows Defender
                            Windows Live
                            Windows Live SkyDrive
                            Windows Mail
                            Windows Media Player
                            Windows NT
                            Windows Photo Gallery
                            Windows Portable Devices
                            Windows Sidebar
                            Zero G Registry

                            ============
                            Drive C:
                            ============

                            $Recycle.Bin
                            ACER
                            autoexec.bat
                            Boot
                            bootmgr
                            BOOTSECT.BAK
                            config.sys
                            Documents and Settings
                            hiberfil.sys
                            Intel
                            Kill'em
                            List'em.txt
                            pagefile.sys
                            PerfLogs
                            Program Files
                            ProgramData
                            PS.log
                            RHDSetup.log
                            rsit
                            System Volume Information
                            Users
                            Windows

                            ¤¤¤¤¤¤¤¤¤¤ Cracks | Keygens | Serials

                            C:\ACER\Preload\PatchLog
                            C:\ACER\Preload\PatchLog\CodeTracer
                            C:\ACER\Preload\PatchLog\DecompressFM2009-03-11 18-09-18.log
                            C:\ACER\Preload\PatchLog\PAP0102M00000005.csv
                            C:\ACER\Preload\PatchLog\PAP0102M03F01C22.csv
                            C:\ACER\Preload\PatchLog\CodeTracer\CodeTracer2009-03-11 18-08-43.log
                            C:\Program Files\PACKARD BELL\adobe_premiere_sources\sources\Patch.cmd
                            C:\Program Files\Microsoft Works\Install.exe

                            ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
                            0
                            1. Contributeur sécurité
                              redemarres le pc

                              ensuite

                              ▶ Relance List&Kill'em avec le raccourci sur ton bureau ,

                              mais cette fois-ci :

                              ▶ choisis l'option 2 = Mode Suppression

                              laisse travailler l'outil.

                              en fin de scan un rapport s'ouvre

                              ▶ colle le contenu dans ta reponse
                              0
                              1. Kill'em by g3n-h@ckm@n 1.2.4.0

                                User : karima (Administrateurs)
                                Update on 05/02/2010 by g3n-h@ckm@n ::::: 18.40
                                Start at: 18:43:28 | 06/02/2010
                                Contact : https://forums.commentcamarche.net/forum/virus-securite-7

                                Pentium(R) Dual-Core CPU T4200 @ 2.00GHz
                                Microsoft® Windows Vista™ Édition Familiale Basique (6.0.6002 32-bit) # Service Pack 2
                                Internet Explorer 7.0.6002.18005
                                Windows Firewall Status : Enabled

                                C:\ -> Disque fixe local | 285,09 Go (215,12 Go free) [OS] | NTFS
                                D:\ -> Disque CD-ROM

                                ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running

                                C:\Windows\System32\smss.exe
                                C:\Windows\system32\csrss.exe
                                C:\Windows\system32\wininit.exe
                                C:\Windows\system32\csrss.exe
                                C:\Windows\system32\services.exe
                                C:\Windows\system32\lsass.exe
                                C:\Windows\system32\lsm.exe
                                C:\Windows\system32\winlogon.exe
                                C:\Windows\system32\svchost.exe
                                C:\Windows\system32\svchost.exe
                                C:\Windows\System32\svchost.exe
                                C:\Windows\System32\svchost.exe
                                C:\Windows\System32\svchost.exe
                                C:\Windows\system32\svchost.exe
                                C:\Windows\system32\SLsvc.exe
                                C:\Windows\system32\svchost.exe
                                C:\Windows\system32\svchost.exe
                                C:\Windows\System32\spoolsv.exe
                                C:\Windows\system32\Dwm.exe
                                C:\Windows\system32\taskeng.exe
                                C:\Program Files\Avira\AntiVir Desktop\sched.exe
                                C:\Windows\system32\svchost.exe
                                C:\Windows\system32\taskeng.exe
                                C:\Windows\Explorer.EXE
                                C:\Program Files\Windows Defender\MSASCui.exe
                                C:\Windows\system32\igfxsrvc.exe
                                C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                                C:\Windows\system32\svchost.exe
                                C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                                C:\Windows\system32\svchost.exe
                                C:\Windows\System32\svchost.exe
                                C:\Windows\system32\SearchIndexer.exe
                                C:\Windows\system32\wbem\unsecapp.exe
                                C:\Windows\system32\wbem\wmiprvse.exe
                                C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                                C:\Program Files\PACKARD BELL\SetUpMyPC\SmpSys.exe
                                C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe
                                C:\Windows\RtHDVCpl.exe
                                C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
                                C:\Windows\System32\wpcumi.exe
                                C:\Windows\System32\igfxtray.exe
                                C:\Windows\System32\hkcmd.exe
                                C:\Windows\System32\igfxpers.exe
                                C:\Program Files\Java\jre6\bin\jusched.exe
                                C:\Program Files\Iminent\IMBooster\IMBooster.exe
                                C:\Program Files\Windows Live\Messenger\Windows Live Messenger.exe
                                C:\Program Files\Steam\steam.exe
                                C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                                C:\Program Files\Common Files\Steam\SteamService.exe
                                C:\Windows\system32\wbem\wmiprvse.exe
                                C:\Program Files\Iminent\MMServer\Iminent.MMServer.exe
                                C:\Windows\system32\SearchProtocolHost.exe
                                C:\Windows\system32\SearchFilterHost.exe
                                C:\Program Files\List_Kill'em\List_Kill'em.scr
                                C:\Windows\system32\conime.exe
                                C:\Windows\system32\cmd.exe
                                C:\Users\karima\AppData\Local\Temp\E233.tmp\ERUNT.EXE
                                C:\Users\karima\AppData\Local\Temp\E233.tmp\pv.exe

                                Detections :
                                ==========

                                ¤¤¤¤¤¤¤¤¤¤ Files/folders :

                                Quarantined & Deleted !! : C:\Windows\Installer\{E1B94435-241E-4519-B1C3-C4DD9EB352A2}
                                Quarantined & Deleted !! : C:\Windows\msnimport.exe

                                Quarantined & Deleted !! : C:\Windows\SYSTEM32\EZUPBH~1.DLL
                                Quarantined & Deleted !! : C:\Users\karima\LOCAL Settings\Temp\NotifierSetup.exe

                                ==============
                                host file OK !
                                ==============

                                ========
                                Registry
                                ========

                                Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Iminent.Notifier
                                Deleted : "HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}"
                                Deleted : "HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}"
                                Deleted : HKCR\CLSID\{248dd896-bb45-11cf-9abc-0080c7e7b78d}
                                Deleted : HKCR\CLSID\{248dd897-bb45-11cf-9abc-0080c7e7b78d}
                                Deleted : HKCR\ezUPBHook.ShellObj
                                Deleted : HKCR\ezUPBHook.ShellObj.1
                                Deleted : HKCR\Interface\{248dd892-bb45-11cf-9abc-0080c7e7b78d}
                                Deleted : HKCR\Interface\{248dd893-bb45-11cf-9abc-0080c7e7b78d}
                                Deleted : HKCR\TypeLib\{248dd890-bb45-11cf-9abc-0080c7e7b78d}
                                Deleted : HKCR\TypeLib\{478CAB91-9E28-11D4-97FF-0050047D51FB}
                                Deleted : HKCU\software\Iminent
                                Deleted : HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{83ff80f4-8c74-4b80-b5ba-c8ddd434e5c4}
                                Deleted : HKLM\Software\Classes\Interface\{01009AEC-AFAA-4982-9F2B-6411C5C27E77}
                                Deleted : HKLM\software\Iminent
                                ========
                                Services
                                =========

                                Ndisuio : Start = 3
                                EapHost : Start = 2
                                Wlansvc : Start = 2
                                SharedAccess : Start = 2
                                windefend : Start = 2
                                wuauserv : Start = 2
                                wscsvc : Start = 2

                                ============
                                Disk Cleaned
                                ============

                                ================
                                Prefetch cleaned
                                ================

                                ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
                                0
                                1. Contributeur sécurité
                                  ok

                                  le pc se présente bien...

                                  je vérifierai tout ca de chez moi et te posterai le nettoyage finale ce soir ou demain si tout va bien
                                  0
                                  1. Ok merci bien, c'est gentil...Sinon ça peut venir de quoi, mon PC est moins rapide qu'avant, il est toujours rapide lorsque je navigue sur internet mais légèrement moins qu'avant, ça peut venir de quoi ?
                                    0
                                    1. Contributeur sécurité
                                      moins qu'avant quoi ?
                                      avant l'utilisation des outils de désinfections ou depuis leur passage ?
                                      0
                                      1. Avant la désinfection excuse moi j'avais pas précisé.
                                        0
                                        • 1
                                        • 2
                                        • 3