Virus supposé

Bonjour,

Je pense qu'un virus s'est introduit dans mon ordinateur, mais je ne trouve pas comment le détecter.
Cependant je n'en suis pas certain.
L'exécution de mon ordinateur semble ralentie et parfois il se comporte de façon inhabituelle.
Pourriez-vous m'aider s'il vous plaît?
Merci d'avance.
Configuration: Windows XP
Firefox 3.0.17

26 réponses

Résumé de la discussion

Un utilisateur sur Windows XP et Firefox 3.0.17 pense qu'un virus s'est infiltré sur son PC en raison d'un ralentissement et de comportements inhabituels, et demande comment le détecter. Plusieurs réponses proposent des outils de détection et de nettoyage, notamment UsbFix pour les clés et disques externes, puis génération d'un rapport, et avertissent que certains composants peuvent être vus comme risques. D'autres intervenants évoquent l'emploi de JavaRa pour nettoyer les éléments Java obsolètes et des outils comme HijackThis/ToolCleaner pour générer des rapports et supprimer les traces d'infection. En complément, certains messages indiquent la nécessité de vider l'espace disque et de vérifier les dossiers suspects avant d'effectuer une défragmentation, afin d'éviter des faux positifs et d'assurer le bon nettoyage.

Bobot (l’IA à votre service)
  1. salut :

    Télécharge OTL de OLDTimer

    ▶ enregistre le sur ton Bureau.

    ▶ Double clic ( pour vista / 7 => clic droit "executer en tant qu'administrateur") sur OTL.exe pour le lancer.

    ▶ Coche les 2 cases Lop et Purity

    ▶ Coche la case devant scan all users

    ▶ règle-le sur "60 Days"

    ▶ dans la colonne de gauche , mets tout sur all

    ne modifie pas ceci :

    "files created whithin" et "files modified whithin"


    ▶Clic sur Run Scan.

    A la fin du scan, le Bloc-Notes va s'ouvrir avec le rapport (OTL.txt).

    Ce fichier est sur ton Bureau (en général C:\Documents and settings\le_nom_de_ta_session\OTL.txt)

    ▶▶▶ NE LE POSTE PAS SUR LE FORUM

    Pour me le transmettre clique sur ce lien : http://www.cijoint.fr/

    ▶ Clique sur Parcourir et cherche le fichier ci-dessus.

    ▶ Clique sur Ouvrir.

    ▶ Clique sur "Cliquez ici pour déposer le fichier".

    Un lien de cette forme :

    http://www.cijoint.fr/cjlink.php?file=cjge368/cijSKAP5fU.txt

    est ajouté dans la page.

    ▶ Copie ce lien dans ta réponse.

    ▶▶ Tu feras la meme chose avec le "Extra.txt".
    1. Voilà

      http://www.cijoint.fr/cjlink.php?file=cj201002/cijkBKAMiM.txt
      http://www.cijoint.fr/cjlink.php?file=cj201002/cijXI88cgy.txt

      Je te remercie.
  2. Bonjour,

    Est-ce que quelqu'un peut me dire si je suis bien infecté ou non s'il vous plaît?

    Merci d'avance
    1. bonjour

      ▶ Télécharge UsbFix

      (!) Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptible d'avoir été infectées sans les ouvrir

      ▶ Double clic sur le raccourci UsbFix présent sur ton bureau .

      ▶ Au menu principal choisis l'option " F " pour français et tape sur [entrée] .

      ▶ Au second menu Choisis l'option " 1 " (recherche) et tape sur [entrée]

      ▶ Laisse travailler l'outil.

      ▶ Ensuite post le rapport UsbFix.txt qui apparaitra.

      Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque. ( C:\UsbFix.txt )

      ( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

      Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
      Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
      Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.
      1. hello

        Desactive ton antivirus le temps de la manip ainsi que ton parefeu si présent(car il est detecté a tort comme infection)

        ▶ Télécharge List&Kill'em et enregistre le sur ton bureau

        ▶ Branche clés usb , disques durs externes , mp3 , mp4 , etc..

        double clique ( clic droit "executer en tant qu'administrateur" pour Vista/7 ) sur le raccourci sur ton bureau pour lancer l'installation

        coche la case "creer une icone sur le bureau"

        une fois terminée , clic sur "terminer" et le programme se lancera seul

        choisis la langue puis choisis l'option 1 = Mode Recherche

        ▶ laisse travailler l'outil

        à l'apparition de la fenetre blanche , c'est un peu long , c'est normal , le programme n'est pas bloqué.

        un rapport du nom de catchme apparait sur ton bureau , ignore-le,ne le poste pas , mais ne le supprime pas pour l instant, le scan n'est pas fini.

        ▶ Poste le contenu du rapport qui s'ouvre aux 100 % du scan à l'ecran "COMPLETED"

        tu peux supprimer le rapport catchme.log de ton bureau maintenant.

        1. Bonjour,

          voilà le lien
          http://www.cijoint.fr/cjlink.php?file=cj201002/cijsiEMSr9.txt

          Merci de prendre le temps de m'aider.
          A bientôt.
          1. List'em by g3n-h@ckm@n 1.2.5.3

            User : Charles-Victor (Administrateurs)
            Update on 19/02/2010 by g3n-h@ckm@n ::::: 13.15
            Start at: 01:26:49 | 19/02/2010
            Contact : https://forums.commentcamarche.net/forum/virus-securite-7

            Genuine Intel(R) CPU T2300 @ 1.66GHz
            Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 3
            Internet Explorer 8.0.6001.18702
            Windows Firewall Status : Disabled
            AV : AntiVir Desktop 9.0.1.32 [ Enabled | Updated ]
            FW : Sunbelt Personal Firewall[ Enabled ]4.6.1861 T

            C:\ -> Disque fixe local | 148,8 Go (1,98 Go free) | NTFS
            D:\ -> Disque CD-ROM
            E:\ -> Disque CD-ROM | 642,67 Mo (0 Mo free) [My Disc] | CDFS
            F:\ -> Disque fixe local | 298,09 Go (2,89 Go free) [externe] | NTFS
            H:\ -> Disque amovible | 3,82 Go (2,81 Go free) [USB DISK] | FAT32

            ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running

            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\csrss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\svchost.exe
            C:\Program Files\Windows Defender\MsMpEng.exe
            C:\WINDOWS\System32\svchost.exe
            C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
            C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\spoolsv.exe
            C:\Program Files\Avira\AntiVir Desktop\sched.exe
            C:\WINDOWS\system32\svchost.exe
            C:\Program Files\a-squared Free\a2service.exe
            C:\Program Files\Avira\AntiVir Desktop\avguard.exe
            C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
            C:\Program Files\Bonjour\mDNSResponder.exe
            C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
            C:\WINDOWS\system32\CTsvcCDA.EXE
            C:\WINDOWS\system32\DVDRAMSV.exe
            C:\WINDOWS\eHome\ehRecvr.exe
            C:\WINDOWS\eHome\ehSched.exe
            C:\MATLAB7\webserver\bin\win32\matlabserver.exe
            C:\WINDOWS\system32\nvsvc32.exe
            C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
            c:\matlab7\bin\win32\matlab.exe
            C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe
            C:\Program Files\Sunbelt Software\Personal Firewall\SbPFSvc.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\svchost.exe
            C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
            C:\WINDOWS\ehome\mcrdsvc.exe
            C:\WINDOWS\system32\dllhost.exe
            C:\WINDOWS\System32\alg.exe
            C:\WINDOWS\system32\wbem\wmiprvse.exe
            C:\Program Files\Sunbelt Software\Personal Firewall\SbPFCl.exe
            C:\WINDOWS\Explorer.EXE
            C:\WINDOWS\ehome\ehtray.exe
            C:\WINDOWS\eHome\ehmsas.exe
            C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
            C:\Program Files\Toshiba\Windows Utilities\Hotkey.exe
            C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
            C:\Program Files\Synaptics\SynTP\Toshiba.exe
            C:\WINDOWS\System32\DLA\DLACTRLW.EXE
            C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
            C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
            C:\Program Files\DAEMON Tools\daemon.exe
            C:\Program Files\BboxUpdate\BTLiveUpdate.exe
            C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
            C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
            C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
            C:\Program Files\WinRoll\winroll.exe
            C:\Program Files\SuperCopier2\SuperCopier2.exe
            C:\Program Files\Messenger\msmsgs.exe
            C:\WINDOWS\system32\ctfmon.exe
            C:\WINDOWS\system32\RAMASST.exe
            C:\Program Files\List_Kill'em\List_Kill'em.scr
            C:\WINDOWS\system32\cmd.exe
            C:\WINDOWS\system32\wbem\wmiprvse.exe
            C:\Documents and Settings\Charles-Victor\Local Settings\Temp\B.tmp\pv.exe

            ======================
            Keys "Run"
            ======================
            [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
            TOSCDSPD REG_SZ C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
            WinRoll REG_SZ "C:\Program Files\WinRoll\winroll.exe"
            SuperCopier2.exe REG_SZ C:\Program Files\SuperCopier2\SuperCopier2.exe
            MSMSGS REG_SZ "C:\Program Files\Messenger\msmsgs.exe" /background
            msnmsgr REG_SZ "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
            ctfmon.exe REG_SZ C:\WINDOWS\system32\ctfmon.exe

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
            ehTray REG_SZ C:\WINDOWS\ehome\ehtray.exe
            nwiz REG_SZ nwiz.exe /installquiet
            NvCplDaemon REG_SZ RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
            SynTPEnh REG_SZ C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
            Toshiba Hotkey Utility REG_SZ "C:\Program Files\Toshiba\Windows Utilities\Hotkey.exe" /lang FR
            NDSTray.exe REG_SZ NDSTray.exe
            DLA REG_SZ C:\WINDOWS\System32\DLA\DLACTRLW.EXE
            IntelZeroConfig REG_SZ "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
            IntelWireless REG_SZ "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
            DAEMON Tools REG_SZ "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
            EPSON Stylus DX4000 Series REG_SZ C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBEE.EXE /FU "C:\WINDOWS\TEMP\E_S2F8.tmp" /EF "HKLM"
            Adobe Reader Speed Launcher REG_SZ "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
            QuickTime Task REG_SZ "C:\Program Files\QuickTime\QTTask.exe" -atboottime
            AppleSyncNotifier REG_SZ C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
            BboxUpdate REG_SZ C:\Program Files\BboxUpdate\BTLiveUpdate.exe
            avgnt REG_SZ "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
            Windows Defender REG_SZ "C:\Program Files\Windows Defender\MSASCui.exe" -hide
            IMJPMIG8.1 REG_SZ "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
            IMEKRMIG6.1 REG_SZ C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
            MSPY2002 REG_SZ C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
            PHIME2002ASync REG_SZ C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
            PHIME2002A REG_SZ C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName

            [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]

            [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]

            =====================
            Other Keys
            =====================
            [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
            dontdisplaylastusername REG_DWORD 0 (0x0)
            legalnoticecaption REG_SZ
            legalnoticetext REG_SZ
            shutdownwithoutlogon REG_DWORD 1 (0x1)
            undockwithoutlogon REG_DWORD 1 (0x1)
            InstallVisualStyle REG_EXPAND_SZ C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
            InstallTheme REG_EXPAND_SZ C:\WINDOWS\Resources\Themes\Royale.theme

            ===============
            [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
            NoDriveTypeAutoRun REG_DWORD 255 (0xff)
            NoDriveAutoRun REG_DWORD 255 (0xff)
            HonorAutoRunSetting REG_DWORD 0 (0x0)

            ===============
            [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
            NoCDBurning REG_DWORD 0 (0x0)
            HonorAutoRunSetting REG_DWORD 0 (0x0)
            NoLogOff REG_DWORD 0 (0x0)
            NoControlPanel REG_DWORD 0 (0x0)
            NoDriveAutoRun REG_DWORD 255 (0xff)
            NoDriveTypeAutoRun REG_DWORD 255 (0xff)

            ===============
            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
            AppInit_DLLS REG_SZ

            ===============
            [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
            AutoRestartShell REG_DWORD 1 (0x1)
            DefaultUserName REG_SZ Charles-Victor
            LegalNoticeCaption REG_SZ
            LegalNoticeText REG_SZ
            PowerdownAfterShutdown REG_SZ 0
            ReportBootOk REG_SZ 1
            Shell REG_SZ explorer.exe
            ShutdownWithoutLogon REG_SZ 0
            System REG_SZ
            Userinit REG_SZ C:\WINDOWS\system32\userinit.exe,
            VmApplet REG_SZ rundll32 shell32,Control_RunDLL "sysdm.cpl"
            SfcQuota REG_DWORD -1 (0xffffffff)
            allocatecdroms REG_SZ 0
            allocatedasd REG_SZ 0
            allocatefloppies REG_SZ 0
            cachedlogonscount REG_SZ 10
            forceunlocklogon REG_DWORD 0 (0x0)
            passwordexpirywarning REG_DWORD 14 (0xe)
            scremoveoption REG_SZ 0
            AllowMultipleTSSessions REG_DWORD 1 (0x1)
            UIHost REG_SZ logonui.exe
            LogonType REG_DWORD 1 (0x1)
            Background REG_SZ 0 0 0
            DebugServerCommand REG_SZ no
            SFCDisable REG_DWORD 0 (0x0)
            WinStationsDisabled REG_SZ 0
            HibernationPreviouslyEnabled REG_DWORD 1 (0x1)
            ShowLogonOptions REG_DWORD 0 (0x0)
            AltDefaultUserName REG_SZ Charles-Victor
            AltDefaultDomainName REG_SZ CV
            DefaultDomainName REG_SZ CV
            ChangePasswordUseKerberos REG_DWORD 1 (0x1)

            ===============
            [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\crypt32chain]
            [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cryptnet]
            [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cscdll]
            [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\dimsntfy]
            [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\igfxcui]
            [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ScCertProp]
            [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Schedule]
            [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\sclgntfy]
            [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\SensLogn]
            [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\termsrv]
            [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wlballoon]

            ===============
            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
            {AEB6717E-7E19-11d0-97EE-00C04FD91972} REG_SZ
            {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} REG_SZ Microsoft AntiMalware ShellExecuteHook

            ===============
            [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
            %windir%\system32\sessmgr.exe REG_SZ %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
            C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe REG_SZ C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe:*:Enabled:Sunbelt Firewall GUI
            %windir%\Network Diagnostic\xpnetdiag.exe REG_SZ %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
            C:\Program Files\Grisoft\AVG Free\avginet.exe REG_SZ C:\Program Files\Grisoft\AVG Free\avginet.exe:*:Enabled:avginet.exe
            C:\Program Files\Grisoft\AVG Free\avgamsvr.exe REG_SZ C:\Program Files\Grisoft\AVG Free\avgamsvr.exe:*:Enabled:avgamsvr.exe
            C:\Program Files\Grisoft\AVG Free\avgcc.exe REG_SZ C:\Program Files\Grisoft\AVG Free\avgcc.exe:*:Enabled:avgcc.exe
            C:\Program Files\Grisoft\AVG Free\avgemc.exe REG_SZ C:\Program Files\Grisoft\AVG Free\avgemc.exe:*:Enabled:avgemc.exe
            C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE REG_SZ C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook
            C:\Program Files\uTorrent\uTorrent.exe REG_SZ C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent
            C:\Program Files\Pando Networks\Pando\pando.exe REG_SZ C:\Program Files\Pando Networks\Pando\pando.exe:*:Enabled:Pando Application
            C:\Program Files\Joost\xulrunner\tvprunner.exe REG_SZ C:\Program Files\Joost\xulrunner\tvprunner.exe:*:Enabled:tvprunner
            C:\Program Files\Bonjour\mDNSResponder.exe REG_SZ C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour
            C:\Program Files\Hummingbird\Connectivity\13.00\Exceed\exceed.exe REG_SZ C:\Program Files\Hummingbird\Connectivity\13.00\Exceed\exceed.exe:*:Enabled:Exceed 2008 X Server
            C:\Program Files\Skype\Phone\Skype.exe REG_SZ C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype
            C:\Program Files\Windows Live\Messenger\wlcsdk.exe REG_SZ C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call
            D:\eSKernel.exe REG_SZ D:\eSKernel.exe:*:Enabled:Bbox assistant d'installation
            C:\Program Files\Bbox\eSKernel.exe REG_SZ C:\Program Files\Bbox\eSKernel.exe:*:Enabled:Bbox assistant d'installation
            C:\Program Files\BboxUpdate\BTLiveUpdate.exe REG_SZ C:\Program Files\BboxUpdate\BTLiveUpdate.exe:*:Enabled:Bbox - Bouygues Telecom - Utilitaire de mise à jour
            C:\Program Files\Windows Live\Messenger\msnmsgr.exe REG_SZ C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger
            C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe REG_SZ C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live FolderShare
            C:\Program Files\ma-config.com\maconfservice.exe REG_SZ C:\Program Files\ma-config.com\maconfservice.exe:LocalSubNet:Enabled:maconfservice

            [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
            %windir%\system32\sessmgr.exe REG_SZ %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
            %windir%\Network Diagnostic\xpnetdiag.exe REG_SZ %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
            C:\Program Files\Windows Live\Messenger\wlcsdk.exe REG_SZ C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call
            C:\Program Files\Windows Live\Messenger\msnmsgr.exe REG_SZ C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger
            C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe REG_SZ C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live FolderShare

            ===============
            ActivX controls
            ===============
            HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{215B8138-A3CF-44C5-803F-8226143CFC0A}
            HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{2D8ED06D-3C30-438B-96AE-4D110FDC1FB8}
            HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{5D86DDB5-BDF9-441B-9E9E-D4730F4EE499}
            HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{74D05D43-3236-11D4-BDCD-00C04F9A3B61}
            HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{8AD9C840-044E-11D1-B3E9-00805F499D93}
            HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{A3256902-51FA-45A0-8A97-FC1143C169D9}
            HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA}
            HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{D27CDB6E-AE6D-11CF-96B8-444553540000}

            ===============
            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\<{12d0ed0d-0ee0-4f90-8827-78cefb8f4988}
            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}
            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{26923b43-4d38-484f-9b9e-de460746276c}
            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}
            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}
            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{ED3DF1A7-E9AD-41C7-A62A-1CDA6E33F517}
            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\KB910393
            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{08B0E5C0-4FCB-11CF-AAA5-00401C608500}
            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10072CEC-8CC1-11D1-986E-00A0C955B42F}
            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2179C5D3-EBFF-11CF-B6FD-00AA00B4E220}
            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}
            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{233C1507-6A77-46A4-9443-F871F945D258}
            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{283807B5-2C60-11D0-A31D-00AA00B92C03}
            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2A202491-F00D-11cf-87CC-0020AFEECF20}
            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}
            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{36f8ec70-c29a-11d1-b5c7-0000f8051515}
            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{3af36230-a269-11d1-b5bf-0000f8051515}
            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{3bf42070-b3b1-11d1-b5c5-0000f8051515}
            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{407408d4-94ed-4d86-ab69-a7f649d112ee}
            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{411EDCF7-755D-414E-A74B-3DCD6583F589}
            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4278c270-a269-11d1-b5bf-0000f8051515}
            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}
            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}
            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA848-CC51-11CF-AAFA-00AA00B6015C}
            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA855-CC51-11CF-AAFA-00AA00B6015F}
            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{45ea75a0-a269-11d1-b5bf-0000f8051515}
            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4f216970-c90c-11d1-b5c7-0000f8051515}
            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4f645220-306d-11d2-995d-00c04f98bbc9}
            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5945c046-1e7d-11d1-bc44-00c04fd912be}
            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5A8D6EE0-3E18-11D0-821E-444553540000}
            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5fd399c0-a70a-11d1-9948-00c04f98bbc9}
            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{630b1da0-b465-11d1-9948-00c04f98bbc9}
            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}
            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6fab99d0-bab8-11d1-994a-00c04f98bbc9}
            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}
            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{73FA19D0-2D75-11D2-995D-00C04F98BBC9}
            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7790769C-0471-11d2-AF11-00C04FA35D02}
            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4340}
            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4383}
            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}
            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9381D8F2-0288-11D0-9501-00AA00B911A5}
            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9A394342-4A68-4EBA-85A6-55B559F4E700}
            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{B508B3F1-A24A-32C0-B310-85786919EF28}
            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{BDE0FA43-6952-4BA8-8C58-09AF690F88E1}
            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}
            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C9E9A340-D1F1-11D0-821E-444553540600}
            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CC2A9BA0-3BDD-11D0-821E-444553540000}
            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CDD7975E-60F8-41d5-8149-19E51D6F71D0}
            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{D27CDB6E-AE6D-11cf-96B8-444553540000}
            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{D9B934D0-6A20-450E-9F69-F5595636C28E}
            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{DAA94A2A-2A8D-4D3B-9DB8-56FBECED082D}
            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{de5aed00-a4bf-11d1-9948-00c04f98bbc9}
            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{E8EA5BD6-D931-4001-ABF6-81BAA500360A}
            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{E92B03AB-B707-11d2-9CBD-0000F87A369E}
            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{EA29D410-CE41-4953-A862-2DE706A1DAD7}
            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{FDC11A6F-17D1-48f9-9EA3-9051954BAA24}

            ==============
            BHO :
            ======
            [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
            [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]
            [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{5CA3D70E-1895-11CF-8E15-001234567890}]
            [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
            [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{E99421FB-68DD-40F0-B4AC-B7027CAE2F1A}]

            ================
            Internet Explorer :
            ================
            [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
            Start Page REG_SZ https://www.msn.com/fr-fr

            [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
            Start Page REG_SZ http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome

            ========
            Services
            ========
            [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services]

            Ndisuio : 0x3 ( OK = 3 )
            EapHost : 0x3 ( OK = 2 )
            SharedAccess : 0x2 ( OK = 2 )
            windefend : 0x2 ( OK = 2 )
            wuauserv : 0x2 ( OK = 2 )

            =========
            Atapi.sys
            =========

            %%%% HASHDEEP-1.0
            %%%% size,md5,sha256,filename
            ## Invoked from: C:\Documents and Settings\Charles-Victor\Local Settings\Temp\B.tmp
            ## C:\> hashdeep C:\WINDOWS\System32\Drivers\atapi.sys
            ##
            96512,9f3a2f5aa6875c72bf062c712cfa2674,b4df1d2c56a593c6b54de57395e3b51d288f547842893b32b0f59228a0cf70b9,C:\WINDOWS\System32\Drivers\atapi.sys

            Sources
            =======

            C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
            C:\WINDOWS\ServicePackFiles\i386\atapi.sys
            C:\WINDOWS\system32\drivers\atapi.sys
            C:\WINDOWS\system32\ReinstallBackups\0007\DriverFiles\i386\atapi.sys

            Référence :
            ==========

            Win XP_32b : a64013e98426e1877cb653685c5c0009
            Win XP_SP2_32b : CDFE4411A69C224BD1D11B2DA92DAC51
            Win XP_SP3_32b : 9F3A2F5AA6875C72BF062C712CFA2674
            Vista_32b : e03e8c99d15d0381e02743c36afc7c6f
            Vista_SP1_32b : 2d9c903dc76a66813d350a562de40ed9
            Vista_SP2_32b : 1F05B78AB91C9075565A9D8A4B880BC4
            Vista_SP2_64b : 1898FAE8E07D97F2F6C2D5326C633FAC
            Windows 7_32b : 80C40F7FDFC376E4C5FEEC28B41C119E
            Windows 7_64b : 02062C0B390B7729EDC9E69C680A6F3C

            E:\Autorun.inf :
            ----------------
            [autorun]
            open=autorun.exe
            icon=Detect.exe
            =======
            Drive :
            =======

            D‚fragmenteur de disque Windows
            Copyright (c) 2001 Microsoft Corp. et Executive Software International Inc.

            Rapport d'analyse
            149 Go total, 1,98 Go libre (1%), 20% fragment‚ (fragmentation du fichier 39%)

            Vous devriez d‚fragmenter ce volume.

            ¤¤¤¤¤¤¤¤¤¤ Files/folders :

            Present !! : C:\WINDOWS\002954_.tmp
            Present !! : C:\WINDOWS\aucfg.ini
            Present !! : C:\WINDOWS\kb913800.exe
            Present !! : C:\WINDOWS\patch.exe
            Present !! : C:\WINDOWS\System32\*.dll.tmp"
            Present !! : C:\WINDOWS\System32\drivers\etc\hosts.msn
            Present !! : C:\WINDOWS\System32\tmp.reg"
            Present !! : C:\WINDOWS\unins000.dat
            Present !! : C:\WINDOWS\unins000.exe

            ¤¤¤¤¤¤¤¤¤¤ Keys :

            Present !! : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{0E5CBF21-D15F-11D0-8301-00AA005B4383}
            Present !! : HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoLogoff
            Present !! : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Install.exe"
            Present !! : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Setup.exe"
            Present !! : HKCR\CLSID\{248dd896-bb45-11cf-9abc-0080c7e7b78d}
            Present !! : HKCR\CLSID\{248dd897-bb45-11cf-9abc-0080c7e7b78d}
            Present !! : HKCR\Interface\{248dd892-bb45-11cf-9abc-0080c7e7b78d}
            Present !! : HKCR\Interface\{248dd893-bb45-11cf-9abc-0080c7e7b78d}
            Present !! : HKCR\TypeLib\{248dd890-bb45-11cf-9abc-0080c7e7b78d}
            Present !! : HKLM\SYSTEM\CurrentControlSet\Services\mchInjDrv

            ============

            catchme 0.3.1398.3 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
            Rootkit scan 2010-02-19 01:27:16
            Windows 5.1.2600 Service Pack 3 NTFS

            scanning hidden processes ...

            scanning hidden services & system hive ...

            [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg]
            "s1"=dword:8cff2c55
            "s2"=dword:6b8d4de0
            "h0"=dword:00000001

            [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
            "p0"="C:\Program Files\DAEMON Tools\"
            "h0"=dword:00000000
            "khjeh"=hex:89,0a,f8,08,1a,b2,25,88,15,2a,36,b7,82,cb,09,dc,74,12,eb,14,4e,..

            [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
            "a0"=hex:20,01,00,00,c6,34,2a,0f,8f,be,ce,d5,72,4a,c4,ef,96,4f,2f,15,a8,..
            "khjeh"=hex:04,63,8c,c2,53,36,9b,54,a2,9a,3f,6e,95,78,43,e1,d9,f8,81,d6,6e,..

            [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
            "khjeh"=hex:39,63,d7,56,fc,1d,b3,fd,5f,c4,25,f7,45,93,59,fd,71,a4,ee,bc,bd,..
            [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
            "p0"="C:\Program Files\DAEMON Tools\"
            "h0"=dword:00000000
            "khjeh"=hex:89,0a,f8,08,1a,b2,25,88,15,2a,36,b7,82,cb,09,dc,74,12,eb,14,4e,..

            [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
            "a0"=hex:20,01,00,00,c6,34,2a,0f,8f,be,ce,d5,72,4a,c4,ef,96,4f,2f,15,a8,..
            "khjeh"=hex:04,63,8c,c2,53,36,9b,54,a2,9a,3f,6e,95,78,43,e1,d9,f8,81,d6,6e,..

            [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
            "khjeh"=hex:39,63,d7,56,fc,1d,b3,fd,5f,c4,25,f7,45,93,59,fd,71,a4,ee,bc,bd,..
            [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
            "p0"="C:\Program Files\DAEMON Tools\"
            "h0"=dword:00000000
            "khjeh"=hex:89,0a,f8,08,1a,b2,25,88,15,2a,36,b7,82,cb,09,dc,74,12,eb,14,4e,..

            [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
            "a0"=hex:20,01,00,00,c6,34,2a,0f,8f,be,ce,d5,72,4a,c4,ef,96,4f,2f,15,a8,..
            "khjeh"=hex:04,63,8c,c2,53,36,9b,54,a2,9a,3f,6e,95,78,43,e1,d9,f8,81,d6,6e,..

            [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
            "khjeh"=hex:8c,d5,5c,da,60,be,9a,69,0f,4e,79,41,3c,69,8a,d3,c5,12,50,13,20,..

            scanning hidden registry entries ...

            [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{5AEF54D2-F54F-CD63-3457-6EDC4AA4CFBC}]

            scanning hidden files ...

            scan completed successfully
            hidden processes: 0
            hidden services: 0
            hidden files: 0

            Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

            device: opened successfully
            user: MBR read successfully
            called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys sptd.sys >>UNKNOWN [0x8736C7AC]<<
            kernel: MBR read successfully
            user & kernel MBR OK

            ==========
            Programs
            ==========

            a-squared Free
            ABBYY FineReader 6.0 Sprint
            Adobe
            adslTV
            AIDA32 - Personal System Information
            Apple Software Update
            Avira
            AviSynth 2.5
            AVS4YOU
            BboxUpdate
            Blender Foundation
            Bonjour
            CCleaner
            Combined Community Codec Pack
            Common Files
            ComPlus Applications
            CONEXANT
            Creative
            DAEMON Tools
            directx
            DivX
            DOSBox-0.72
            DVD-RAM
            DVDVideoSoft
            EA Sports
            Electronic Arts
            epson
            eRightSoft
            FastStone Image Viewer
            ffdshow
            Fichiers communs
            Guitar Pro 5
            Hummingbird
            Hummingbird Evaluation Media
            icamdancing-readme.txt
            icamplay_config.exe
            iColorFolder
            ImgBurn
            InstallShield Installation Information
            InstantTimeZone
            Intel
            Internet Explorer
            InterVideo
            ISO Commander
            IZArc
            Java
            KONAMI
            List_Kill'em
            Loop12 V2
            LucasArts
            ma-config.com
            Malwarebytes' Anti-Malware
            Messenger
            Messenger Plus! Live
            Microsoft
            Microsoft ATS
            Microsoft CAPICOM 2.1.0.2
            microsoft frontpage
            Microsoft Office
            Microsoft Office Outlook Connector
            Microsoft Silverlight
            Microsoft SQL Server Compact Edition
            Microsoft Visual Studio
            Microsoft Visual Studio 8
            Microsoft Works
            Microsoft.NET
            MiKTeX 2.7
            Movie Maker
            Mozilla Firefox
            MP3 Recorder Studio
            MSBuild
            MSECache
            MSN
            MSN Gaming Zone
            MSXML 4.0
            Navilog1
            NCH Software
            NCH Swift Sound
            NetMeeting
            nullDC
            Offre Wanadoo
            Online Services
            Outlook Express
            Paint.NET
            Panda Security
            PDFCreator
            Philips
            Philips SPC 610NC PC Camera
            Quicksys
            QuickTime
            Reference Assemblies
            Simple PDF
            Skype
            Sonic
            SopCast
            Spybot - Search & Destroy
            Spyware Doctor
            SpywareBlaster
            Stick Figures
            StuffPlug3
            Sunbelt Software
            SuperCopier2
            Synaptics
            Teamspeak2_RC2
            Texmaker
            Toshiba
            Tracker Software
            Trend Micro
            Trnsys16 Demo
            Uninstall Information
            uTorrent
            Veetle
            VideoLAN
            Winamp
            Winamp Desk Band
            Winamp Detect
            Windows Defender
            Windows Desktop Search
            Windows Live
            Windows Live Safety Center
            Windows Live SkyDrive
            Windows Media Connect 2
            Windows Media Player
            Windows NT
            Windows Plus
            WindowsUpdate
            WinMerge
            WinRoll
            X10 Hardware
            xerox
            Zattoo

            ============
            Drive C:
            ============

            Amond Output
            AUTOEXEC.BAT
            autorun.inf
            BOOT.BKK
            boot.ini
            Bootfont.bin c2ef5226c88d3fd4694d56
            cleannavi.txt
            CMPNENTS
            Config.Msi
            CONFIG.SYS
            CtDrvIns.log
            cygwin
            DeusEx
            Dev-Cpp
            disque
            Documents and Settings
            fixnavi.txt
            Fluent.Inc
            gambit.fnl
            Games
            hiberfil.sys
            I386
            IO.SYS
            JEUX
            Kill'em
            license.dat
            List'em.txt
            MATLAB7
            MP4debug.log
            MSDOS.SYS
            MSOCache
            NTDETECT.COM
            ntldr
            pagefile.sys
            photos
            Program Files
            rapport.txt
            RECYCLER
            resetlog.txt
            rsit
            SUPPORT
            SWSTAMP.TXT
            System Volume Information
            Temp
            TEST.XML
            tools
            Toolscd
            UsbFix
            UsbFix.txt
            UsbFix_Upload_Me_CV.zip
            VALUEADD
            WakeupOnStandBy
            winamplog.txt
            WINDOWS
            xscan.txt

            ¤¤¤¤¤¤¤¤¤¤ Cracks | Keygens | Serials

            F:\formatage\dossiers\utile\FlashFXP.v2.0.901\Crack.exe

            ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

            End of scan : 1:20:53,12
            1. F:\formatage\dossiers\utile\FlashFXP.v2.0.901\Crack.exe

              supprime ceci source d'infections ,

              ensuite :

              ▶ Relance List_Kill'em(soit en clic droit pour vista/7),avec le raccourci sur ton bureau.
              mais cette fois-ci :

              ▶ choisis l'option 2 = Mode Suppression

              laisse travailler l'outil.

              en fin de scan un rapport s'ouvre

              ▶ colle le contenu dans ta reponse
              1. Voilà

                Kill'em by g3n-h@ckm@n 1.2.5.3

                User : Charles-Victor (Administrateurs)
                Update on 19/02/2010 by g3n-h@ckm@n ::::: 13.15
                Start at: 01:22:08 | 19/02/2010
                Contact : https://forums.commentcamarche.net/forum/virus-securite-7

                Genuine Intel(R) CPU T2300 @ 1.66GHz
                Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 3
                Internet Explorer 8.0.6001.18702
                Windows Firewall Status : Disabled
                AV : AntiVir Desktop 9.0.1.32 [ (!) Disabled | Updated ]
                FW : Sunbelt Personal Firewall[ (!) Disabled ]4.6.1861 T

                C:\ -> Disque fixe local | 148,8 Go (1,6 Go free) | NTFS
                D:\ -> Disque CD-ROM | 0 Mo (0 Mo free) [Audio CD] | CDFS
                E:\ -> Disque CD-ROM | 642,67 Mo (0 Mo free) [My Disc] | CDFS
                F:\ -> Disque fixe local | 298,09 Go (2,89 Go free) [externe] | NTFS
                H:\ -> Disque amovible | 3,82 Go (2,81 Go free) [USB DISK] | FAT32

                ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running

                C:\WINDOWS\System32\smss.exe
                C:\WINDOWS\system32\csrss.exe
                C:\WINDOWS\system32\winlogon.exe
                C:\WINDOWS\system32\services.exe
                C:\WINDOWS\system32\lsass.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\system32\svchost.exe
                C:\Program Files\Windows Defender\MsMpEng.exe
                C:\WINDOWS\System32\svchost.exe
                C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
                C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\system32\spoolsv.exe
                C:\Program Files\Avira\AntiVir Desktop\sched.exe
                C:\WINDOWS\system32\svchost.exe
                C:\Program Files\a-squared Free\a2service.exe
                C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                C:\Program Files\Bonjour\mDNSResponder.exe
                C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
                C:\WINDOWS\system32\CTsvcCDA.EXE
                C:\WINDOWS\system32\DVDRAMSV.exe
                C:\WINDOWS\eHome\ehRecvr.exe
                C:\WINDOWS\eHome\ehSched.exe
                C:\MATLAB7\webserver\bin\win32\matlabserver.exe
                C:\WINDOWS\system32\nvsvc32.exe
                c:\matlab7\bin\win32\matlab.exe
                C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
                C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe
                C:\Program Files\Sunbelt Software\Personal Firewall\SbPFSvc.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\system32\svchost.exe
                C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
                C:\WINDOWS\ehome\mcrdsvc.exe
                C:\WINDOWS\system32\wuauclt.exe
                C:\WINDOWS\system32\dllhost.exe
                C:\WINDOWS\System32\alg.exe
                C:\Program Files\Sunbelt Software\Personal Firewall\SbPFCl.exe
                C:\WINDOWS\system32\wbem\wmiprvse.exe
                C:\WINDOWS\Explorer.EXE
                C:\WINDOWS\ehome\ehtray.exe
                C:\WINDOWS\eHome\ehmsas.exe
                C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                C:\Program Files\Toshiba\Windows Utilities\Hotkey.exe
                C:\Program Files\Synaptics\SynTP\Toshiba.exe
                C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
                C:\WINDOWS\System32\DLA\DLACTRLW.EXE
                C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
                C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
                C:\Program Files\DAEMON Tools\daemon.exe
                C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
                C:\Program Files\BboxUpdate\BTLiveUpdate.exe
                C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
                C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
                C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
                C:\Program Files\WinRoll\winroll.exe
                C:\Program Files\SuperCopier2\SuperCopier2.exe
                C:\Program Files\Messenger\msmsgs.exe
                C:\WINDOWS\system32\ctfmon.exe
                C:\WINDOWS\system32\RAMASST.exe
                C:\WINDOWS\system32\wscntfy.exe
                C:\Program Files\List_Kill'em\List_Kill'em.scr
                C:\WINDOWS\system32\cmd.exe
                C:\WINDOWS\system32\wbem\wmiprvse.exe
                C:\Documents and Settings\Charles-Victor\Local Settings\Temp\C.tmp\ERUNT.EXE
                C:\Documents and Settings\Charles-Victor\Local Settings\Temp\C.tmp\pv.exe

                Detections :
                ==========

                ¤¤¤¤¤¤¤¤¤¤ Files/folders :

                ==============
                host file OK !
                ==============

                ========
                Registry
                ========

                Deleted : HKLM\SYSTEM\CurrentControlSet\Services\mchInjDrv
                ========
                Services
                =========

                Ndisuio : Start = 3
                EapHost : Start = 2
                Ip6Fw : Start = 2
                SharedAccess : Start = 2
                windefend : Start = 2
                wuauserv : Start = 2
                wscsvc : Start = 2

                ============
                Disk Cleaned
                ============

                =================
                anti-ver blaster : OK !!
                =================

                ================
                Prefetch cleaned
                ================

                ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
                1. Oui, trois fois, il me semble parce que mon ordinateur s'est éteint d'un coup les deux premières fois (je pense qu'il chauffe trop).
                  1. remets le rapport de ceci stp

                    http://sd-1.archive-host.com/membres/up/829108531491024/Temp_Tools/folder.exe
                    1. Salut,

                      excuse-moi, je suis assez pris en ce moment.
                      Il prend combien de temps à s'exécuter folder.exe? Parce qu'il ouvre dès que je le lance un fichier texte sans rien écrit.
                      Par contre j'ai pas encore eu le temps de le laisser aller jusqu'au bout, peut être ce week end.
                      1. ok fais List_Kill'em option 6 et refais un scan OTL comme precedement précité via cijoint.fr
                        1. Bonsoir,

                          Excuse-moi, j'ai mis un petit peu de temps.
                          Voilà le lien pour le rapport OTL:

                          http://www.cijoint.fr/cjlink.php?file=cj201002/cij5CZEko4.txt

                          Merci
                          1. Bonjour,

                            oui c'est un petit utilitaire qui permet de rendre les fenêtres transparentes. Utile pour voir 2 choses en même temps. Pourquoi, c'est pas bon?
                            1. le nom m'avait paru bizarre sur le coup mais apres recherches.....

                              Imprime ces instructions car il faudra fermer toutes les fenêtres et applications lors de l'installation et de l'analyse.

                              ▶ Télécharge :

                              Malwarebytes

                              ou :

                              Malwarebytes

                              ▶ Installe le ( choisis bien "francais" ; ne modifie pas les paramètres d'installe ) et mets le à jour .

                              (NB : Si tu as un message d'erreur t'indiquant qu'il te manque "COMCTL32.OCX" lors de l'installe, alors télécharge le ici : COMCTL32.OCX

                              ▶ Potasses le Tuto pour te familiariser avec le prg :

                              ( cela dit, il est très simple d'utilisation ).

                              relance malwarebytes en suivant scrupuleusement ces consignes :

                              ! Déconnecte toi et ferme toutes applications en cours !

                              ▶ Lance Malwarebyte's .

                              Fais un examen dit "Complet" .

                              ▶ Laisse le programme travailler ( et ne rien faire d'autre avec le PC durant le scan ).
                              ▶ à la fin tu cliques sur "résultat" .
                              ▶ Vérifie que tous les objets infectés soient validés, puis clique sur " suppression " .

                              ▶ Note : si il faut redémarrer ton PC pour finir le nettoyage, fais le !

                              ▶ Poste le rapport sauvegardé après la suppression des objets infectés (dans l'onglet "rapport/log"de Malwarebytes, le dernier en date)

                              1. Voilà,

                                malwarebytes n'a rien trouvé...en mode normal et sans échec.

                                Malwarebytes' Anti-Malware 1.44
                                Version de la base de données: 3825
                                Windows 5.1.2600 Service Pack 3
                                Internet Explorer 8.0.6001.18702

                                04/03/2010 22:12:23
                                mbam-log-2010-03-04 (22-12-23).txt

                                Type de recherche: Examen complet (C:\|D:\|E:\|F:\|H:\|)
                                Eléments examinés: 430884
                                Temps écoulé: 2 hour(s), 16 minute(s), 35 second(s)

                                Processus mémoire infecté(s): 0
                                Module(s) mémoire infecté(s): 0
                                Clé(s) du Registre infectée(s): 0
                                Valeur(s) du Registre infectée(s): 0
                                Elément(s) de données du Registre infecté(s): 0
                                Dossier(s) infecté(s): 0
                                Fichier(s) infecté(s): 0

                                Processus mémoire infecté(s):
                                (Aucun élément nuisible détecté)

                                Module(s) mémoire infecté(s):
                                (Aucun élément nuisible détecté)

                                Clé(s) du Registre infectée(s):
                                (Aucun élément nuisible détecté)

                                Valeur(s) du Registre infectée(s):
                                (Aucun élément nuisible détecté)

                                Elément(s) de données du Registre infecté(s):
                                (Aucun élément nuisible détecté)

                                Dossier(s) infecté(s):
                                (Aucun élément nuisible détecté)

                                Fichier(s) infecté(s):
                                (Aucun élément nuisible détecté)
                                • 1
                                • 2