Cheval de troie

Bonjour, j'ai comme anti virus Avast!

Il me signal que j'ai un cheval de troie sur mon ordinateur et étant nul en informatique je ne sais que faire...

J'essaie de mettre en quarantaine, mais dès lors un message apparait : Le processus ne peut accéder au fichier car ce fichier est utilisé par un autre processus .

Que dois-je faire pour éliminé ce cheval de troie ?

Merci.
Configuration: Windows XP
Firefox 3.0.17

32 réponses

Résumé de la discussion

Plusieurs utilisateurs cherchent à comprendre comment éliminer un cheval de Troie signalé par Avast! sur un PC sous Windows XP, après qu’un fichier mis en quarantaine reste verrouillé par un autre processus. Les réponses recommandent d’utiliser des outils dédiés tels que List Kill'em, ComboFix ou OTL pour nettoyer les composants malveillants puis Malwarebytes pour le contrôle final. Des instructions ajoutent aussi de fermer les applications, redémarrer en mode sans échec et réaliser un premier balayage complet avant de supprimer les éléments détectés et de redémarrer. En dernier lieu, certains conseillent de vérifier les entrées de registre et les programmes lancés au démarrage, puis de refaire un scan après installation de la désinfection pour confirmer la suppression.

Bobot (l’IA à votre service)
  1. salut :

    Télécharge OTL de OLDTimer

    ▶ enregistre le sur ton Bureau.

    ▶ Double clic ( pour vista / 7 => clic droit "executer en tant qu'administrateur") sur OTL.exe pour le lancer.

    ▶ Coche les 2 cases Lop et Purity

    ▶ Coche la case devant scan all users

    ▶ règle-le sur "60 Days"

    ▶ dans la colonne de gauche , mets tout sur "all"

    ne modifie pas ceci :

    "files created whithin" et "files modified whithin"


    ▶Clic sur Run Scan.

    A la fin du scan, le Bloc-Notes va s'ouvrir avec le rapport (OTL.txt).

    Ce fichier est sur ton Bureau (en général C:\Documents and settings\le_nom_de_ta_session\OTL.txt)

    ▶▶▶ NE LE POSTE PAS SUR LE FORUM

    Pour me le transmettre clique sur ce lien : http://www.cijoint.fr/

    ▶ Clique sur Parcourir et cherche le fichier ci-dessus.

    ▶ Clique sur Ouvrir.

    ▶ Clique sur "Cliquez ici pour déposer le fichier".

    Un lien de cette forme :

    http://www.cijoint.fr/cjlink.php?file=cjge368/cijSKAP5fU.txt

    est ajouté dans la page.

    ▶ Copie ce lien dans ta réponse.

    ▶▶ Tu feras la meme chose avec le "Extra.txt".
    1. Merci beaucoup, j'ai suivi toutes tes instructions .

      Pour le premier fichier le lien est : http://www.cijoint.fr/cjlink.php?file=cj201002/cijgMZtTeR.txt

      et pour le deuxieme : http://www.cijoint.fr/cjlink.php?file=cj201002/cijQZvfN8g.txt

      Que dois-je faire ?
  2. Desactive ton antivirus le temps de la manip ainsi que ton parefeu si présent(car il est detecté a tort comme infection)

    ▶ Télécharge List&Kill'em et enregistre le sur ton bureau

    ▶ Branche clés usb , disques durs externes , mp3 , mp4 , etc..

    double clique ( clic droit "executer en tant qu'administrateur" pour Vista/7 ) sur le raccourci sur ton bureau pour lancer l'installation

    coche la case "creer une icone sur le bureau"

    une fois terminée , clic sur "terminer" et le programme se lancera seul

    choisis la langue puis choisis l'option 1 = Mode Recherche

    ▶ laisse travailler l'outil

    à l'apparition de la fenetre blanche , c'est un peu long , c'est normal , le programme n'est pas bloqué.

    un rapport du nom de catchme apparait sur ton bureau , ignore-le,ne le poste pas , mais ne le supprime pas pour l instant, le scan n'est pas fini.

    ▶ Poste le contenu du rapport qui s'ouvre aux 100 % du scan à l'ecran "COMPLETED"

    tu peux supprimer le rapport catchme.log de ton bureau maintenant.

    1. Merci le programme s'est ouvert, affichant : F : français E : English

      J'ai donc taper dans choisir/choose : F Mode de recherche

      et j'ai ensuite appuyer sur Enter.

      Rien ne se passe, est ce normal ou ai-je fait une erreure ?

      Merci.
      1. tu as desactivé l antivirus ?
        1. Oui j'ai désactivé la protection résidente et le pare-feu.
      2. J'essaie de relancer le programme mais bon mon pc bug beaucoup et plus rien ne va :S

        Tu crois que si je l'éteinds et que je le rallume , il ne va plus marcher ?
        1. Ah non tout va bien.

          J'ai fais ce que tu m'as dis.

          J'ai réouvert le programme, j'arrive donc sur cette fenêtre bleue et j'écris

          Choisir/choose : F en mode échec

          Puis j'appuie sur Enter , la fenêtre se ferme mais rien ne se passe...
          1. ?????????????


            /!\ ATTENTION SUIVRE SCRUPULEUSEMENT A LA LETTRE CES INDICATIONS/!\

            ▶ Surtout , pense à l'enregistrement à renommer Combofix en "ton prenom.exe" avant qu'il soit enregistré sur ton disque dur

            _______________________________________________________________
            >Ce logiciel n'est à utiliser que prescrit par un helper qualifié et formé à l'outil.<
            >>>>>>>Ne pas utiliser en dehors de ce cas de figure : dangereux!<<<<<<<<
            ======================================================


            ▶ On va utiliser ComboFix.exe. Rends toi sur cette page web pour obtenir les liens de téléchargement, ainsi que des instructions pour exécuter l'outil:

            https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix

            Avant d'utiliser ComboFix :
            ______________________________________________________________________
            >> referme les fenêtres de tous les programmes en cours.
            >> Désactive provisoirement et seulement le temps de l'utilisation de ComboFix,
            >>la protection en temps réel de ton Antivirus et de tes Antispywares,
            >>qui peuvent gêner fortement la procédure de recherche et de nettoyage de l'outil.

            °°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°


            ▶ !!!!!NE TOUCHE A RIEN PENDANT LE TRAVAIL DE COMBOFIX (SOURIS/CLAVIER.....)!!!!!

            ▶ n'oublie pas de reactiver la garde de ton Antivirus et de tes Antispywares, avant de te reconnecter à internet.

            >> Reviens sur le forum, et

            ▶ copie et colle la totalité du contenu de C:\Combofix.txt dans ton prochain message.

            1. Donc voila j'ai suivis toutes les instructions avec ComboFix.

              J'étais arrivé aux étapes quand mon ordinateur afficha une page bleue où il était écrit que si je voyais cette page pour la première fois je devais redémarré mon ordinateur et que si cela revenait je devais suivre certaines étapes... J'ai donc redémarré mon ordinateur et voila. Mon anti virus s'est remis en marche et il ne m'annonce plus que j'ai un cheval de troie... Je ne sais pas ce qui s'est passé et je ne sais pas si le cheval de troie est toujours présents ou pas.

              Merci.
              1. Aparement non, aucun signe de ce fichier.. :S

                Je ne comprends pas non plus pourquoi le cheval de troie n'intervient plus.

                Je peux recommencer avec Combofix si c'est nécessaire.
                1. Pourquoi t'enmerdé avec des gens qui connaisse rien ?

                  La solution simple : Presse CTRL + ALT + SUPPR

                  Va dans la catégorie processus.

                  Comme l'antivirus t'indique a la fin le nom du fichier [ Genre : c:/Tonnom/Appdata/Jesuislevirus.exe ]

                  Tu cherche dans processus ce nom et tu fait propriété, tu cherche ou il est, tu y va a partir de ton naviguateur Windows, et tu fait clique droit, supprimé, ensuite, tu va encore dans la colonne processus, tu clique sur le virus [ Exemple : Jesuislevirus.exe ] et tu fait arrêté le processus.

                  Voilà, sans installé aucun logiciel :)
                  1. Merci c'est super gentil, je ferai comme tu dis si le cheval de troie se remontre, parce que pour le moment, je n'ai plus aucun signe de lui... (tant mieux :p) Du coup je ne sais pas quel est le nom du fichier.

                    Merci beaucoup.
                    1. encore un qui croit tout savoir !!!! va arreter un rootkit comme ca ou viruT !! non mais vraiment !!! avec 85 messages il a de l experience lui ?

                      lolo05

                      Imprime ces instructions car il faudra fermer toutes les fenêtres et applications lors de l'installation et de l'analyse.

                      ▶ Télécharge :

                      Malwarebytes

                      ou :

                      Malwarebytes

                      ▶ Installe le ( choisis bien "francais" ; ne modifie pas les paramètres d'installe ) et mets le à jour .

                      (NB : Si tu as un message d'erreur t'indiquant qu'il te manque "COMCTL32.OCX" lors de l'installe, alors télécharge le ici : COMCTL32.OCX

                      ▶ Potasses le Tuto pour te familiariser avec le prg :

                      ( cela dit, il est très simple d'utilisation ).

                      relance malwarebytes en suivant scrupuleusement ces consignes :

                      ! Déconnecte toi et ferme toutes applications en cours !

                      ▶ Lance Malwarebyte's .

                      Fais un examen dit "Complet" .

                      ▶ Laisse le programme travailler ( et ne rien faire d'autre avec le PC durant le scan ).
                      ▶ à la fin tu cliques sur "résultat" .
                      ▶ Vérifie que tous les objets infectés soient validés, puis clique sur " suppression " .

                      ▶ Note : si il faut redémarrer ton PC pour finir le nettoyage, fais le !

                      ▶ Poste le rapport sauvegardé après la suppression des objets infectés (dans l'onglet "rapport/log"de Malwarebytes, le dernier en date)

                      1. Voilà !

                        J'ai fais tout ce que tu m'as dis

                        Je postes donc le rapport :

                        Malwarebytes' Anti-Malware 1.44
                        Version de la base de données: 3751
                        Windows 5.1.2600 Service Pack 2
                        Internet Explorer 8.0.6001.18702

                        17/02/2010 19:19:54
                        mbam-log-2010-02-17 (19-19-54).txt

                        Type de recherche: Examen complet (A:\|C:\|D:\|E:\|F:\|H:\|)
                        Eléments examinés: 184789
                        Temps écoulé: 31 minute(s), 1 second(s)

                        Processus mémoire infecté(s): 0
                        Module(s) mémoire infecté(s): 0
                        Clé(s) du Registre infectée(s): 3
                        Valeur(s) du Registre infectée(s): 0
                        Elément(s) de données du Registre infecté(s): 0
                        Dossier(s) infecté(s): 0
                        Fichier(s) infecté(s): 1

                        Processus mémoire infecté(s):
                        (Aucun élément nuisible détecté)

                        Module(s) mémoire infecté(s):
                        (Aucun élément nuisible détecté)

                        Clé(s) du Registre infectée(s):
                        HKEY_CURRENT_USER\SOFTWARE\AppDataLow\HavingFunOnline (Adware.BHO.FL) -> Quarantined and deleted successfully.
                        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{39bad6b7-9ff7-c2ce-0299-345180d2f45e} (Adware.AdRotator) -> Quarantined and deleted successfully.
                        HKEY_CLASSES_ROOT\CLSID\{39bad6b7-9ff7-c2ce-0299-345180d2f45e} (Adware.AdRotator) -> Quarantined and deleted successfully.

                        Valeur(s) du Registre infectée(s):
                        (Aucun élément nuisible détecté)

                        Elément(s) de données du Registre infecté(s):
                        (Aucun élément nuisible détecté)

                        Dossier(s) infecté(s):
                        (Aucun élément nuisible détecté)

                        Fichier(s) infecté(s):
                        C:\WINDOWS\system32\3a6ba851-4177-d926-f02c-bdc320d52a42.dll (Adware.AdRotator) -> Quarantined and deleted successfully.
                        1. J'ai retenté, j'ai enfin réussis , mais a 85% +- la page bleu que j'ai eu avec Combofix apparait et me dis que un problème a été détecté et que j'devrais redémarré...

                          J'ai retenté plusieurs fois mais toujours la même chose...
                          1. Ok voilà :) :

                            List'em by g3n-h@ckm@n 1.2.5.2

                            User : Admin (Administrateurs)
                            Update on 16/02/2010 by g3n-h@ckm@n ::::: 13.30
                            Start at: 19:51:36 | 17/02/2010
                            Contact : https://forums.commentcamarche.net/forum/virus-securite-7

                            AMD Phenom(tm) 9550 Quad-Core Processor
                            Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 2
                            Internet Explorer 8.0.6001.18702
                            Windows Firewall Status : Disabled
                            AV : avast! antivirus 4.8.1351 [VPS 100217-1] 4.8.1351 [ (!) Disabled | Updated ]

                            A:\ -> Lecteur de disquettes 3 ½ pouces
                            C:\ -> Disque fixe local | 97,65 Go (40,29 Go free) | NTFS
                            D:\ -> Disque CD-ROM
                            E:\ -> Disque CD-ROM
                            F:\ -> Disque fixe local | 135,22 Go (135,12 Go free) | NTFS
                            G:\ -> Disque amovible | 3,68 Go (1,25 Go free) [PHILIPS] | FAT32
                            H:\ -> Disque amovible

                            ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running

                            C:\WINDOWS\System32\smss.exe
                            C:\WINDOWS\system32\csrss.exe
                            C:\WINDOWS\system32\winlogon.exe
                            C:\WINDOWS\system32\services.exe
                            C:\WINDOWS\system32\savedump.exe
                            C:\WINDOWS\system32\lsass.exe
                            C:\WINDOWS\system32\svchost.exe
                            C:\WINDOWS\system32\svchost.exe
                            C:\WINDOWS\System32\svchost.exe
                            C:\WINDOWS\system32\svchost.exe
                            C:\WINDOWS\system32\svchost.exe
                            C:\WINDOWS\system32\svchost.exe
                            C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                            C:\Program Files\Alwil Software\Avast4\ashServ.exe
                            C:\WINDOWS\system32\brsvc01a.exe
                            C:\WINDOWS\system32\spoolsv.exe
                            C:\WINDOWS\system32\brss01a.exe
                            C:\WINDOWS\Explorer.EXE
                            C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                            C:\WINDOWS\RTHDCPL.EXE
                            C:\WINDOWS\system32\RUNDLL32.EXE
                            C:\WINDOWS\V0420Mon.exe
                            C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
                            C:\Program Files\Brother\ControlCenter2\brctrcen.exe
                            C:\Program Files\Java\jre6\bin\jusched.exe
                            C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
                            C:\WINDOWS\system32\svchost.exe
                            C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                            C:\WINDOWS\system32\ctfmon.exe
                            C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
                            C:\Program Files\Creative\Creative Live! Cam\Live! Cam Manager\CTLCMgr.exe
                            C:\WINDOWS\system32\FsUsbExService.Exe
                            C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                            C:\Program Files\Java\jre6\bin\jqs.exe
                            C:\Program Files\Fichiers communs\Ahead\lib\NMBgMonitor.exe
                            C:\WINDOWS\system32\nvsvc32.exe
                            C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe
                            C:\WINDOWS\system32\svchost.exe
                            C:\Program Files\McAfee Security Scan\1.0.150\SSScheduler.exe
                            C:\Program Files\OpenOffice.org 3\program\soffice.exe
                            C:\Program Files\OpenOffice.org 3\program\soffice.bin
                            C:\WINDOWS\system32\wuauclt.exe
                            C:\WINDOWS\system32\wbem\wmiapsrv.exe
                            C:\WINDOWS\System32\alg.exe
                            C:\WINDOWS\system32\wbem\wmiprvse.exe
                            C:\WINDOWS\system32\wbem\wmiprvse.exe
                            C:\Program Files\List_Kill'em\List_Kill'em.scr
                            C:\WINDOWS\system32\cmd.exe
                            C:\WINDOWS\system32\wscntfy.exe
                            C:\WINDOWS\system32\wuauclt.exe
                            C:\Documents and Settings\Admin\Local Settings\Temp\5.tmp\pv.exe

                            ======================
                            Keys "Run"
                            ======================
                            [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                            CTFMON.EXE REG_SZ C:\WINDOWS\system32\ctfmon.exe
                            MsnMsgr REG_SZ "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                            Creative Live! Cam Manager REG_SZ "C:\Program Files\Creative\Creative Live! Cam\Live! Cam Manager\CTLCMgr.exe"
                            swg REG_SZ "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
                            BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} REG_SZ "C:\Program Files\Fichiers communs\Ahead\lib\NMBgMonitor.exe"
                            ares REG_SZ "C:\Program Files\Ares\Ares.exe" -h
                            Skype REG_SZ "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
                            AutoStartNPSAgent REG_SZ C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe

                            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                            avast! REG_SZ C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                            NeroFilterCheck REG_SZ C:\WINDOWS\system32\NeroCheck.exe
                            RTHDCPL REG_SZ RTHDCPL.EXE
                            Alcmtr REG_SZ ALCMTR.EXE
                            NvCplDaemon REG_SZ RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                            nwiz REG_SZ nwiz.exe /install
                            NvMediaCenter REG_SZ RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
                            V0420Mon.exe REG_SZ C:\WINDOWS\V0420Mon.exe
                            SSBkgdUpdate REG_SZ "C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
                            PaperPort PTD REG_SZ C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
                            IndexSearch REG_SZ C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe
                            SetDefPrt REG_SZ C:\Program Files\Brother\Brmfl05a\BrStDvPt.exe
                            ControlCenter2.0 REG_SZ C:\Program Files\Brother\ControlCenter2\brctrcen.exe /autorun
                            SunJavaUpdateSched REG_SZ "C:\Program Files\Java\jre6\bin\jusched.exe"
                            NPSStartup REG_SZ
                            Adobe Reader Speed Launcher REG_SZ "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
                            Adobe ARM REG_SZ "C:\Program Files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe"
                            TkBellExe REG_SZ "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                            KernelFaultCheck REG_EXPAND_SZ %systemroot%\system32\dumprep 0 -k

                            [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]

                            [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]

                            =====================
                            Other Keys
                            =====================
                            [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
                            dontdisplaylastusername REG_DWORD 0 (0x0)
                            legalnoticecaption REG_SZ
                            legalnoticetext REG_SZ
                            shutdownwithoutlogon REG_DWORD 1 (0x1)
                            undockwithoutlogon REG_DWORD 1 (0x1)

                            ===============
                            [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
                            NoDriveTypeAutoRun REG_DWORD 323 (0x143)
                            NoDriveAutoRun REG_DWORD 67108863 (0x3ffffff)

                            ===============
                            [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
                            HonorAutoRunSetting REG_DWORD 1 (0x1)
                            NoCDBurning REG_DWORD 0 (0x0)
                            NoDriveAutoRun REG_DWORD 67108863 (0x3ffffff)
                            NoDriveTypeAutoRun REG_DWORD 323 (0x143)

                            ===============
                            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]

                            ===============
                            [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
                            AutoRestartShell REG_DWORD 1 (0x1)
                            DefaultDomainName REG_SZ ADMIN-3EB9D1403
                            DefaultUserName REG_SZ Admin
                            LegalNoticeCaption REG_SZ
                            LegalNoticeText REG_SZ
                            PowerdownAfterShutdown REG_SZ 0
                            ReportBootOk REG_SZ 1
                            Shell REG_SZ Explorer.exe
                            ShutdownWithoutLogon REG_SZ 0
                            System REG_SZ
                            Userinit REG_SZ C:\WINDOWS\system32\userinit.exe,
                            VmApplet REG_SZ rundll32 shell32,Control_RunDLL "sysdm.cpl"
                            SfcQuota REG_DWORD -1 (0xffffffff)
                            allocatecdroms REG_SZ 0
                            allocatedasd REG_SZ 0
                            allocatefloppies REG_SZ 0
                            cachedlogonscount REG_SZ 10
                            forceunlocklogon REG_DWORD 0 (0x0)
                            passwordexpirywarning REG_DWORD 14 (0xe)
                            scremoveoption REG_SZ 0
                            AllowMultipleTSSessions REG_DWORD 1 (0x1)
                            UIHost REG_EXPAND_SZ logonui.exe
                            LogonType REG_DWORD 1 (0x1)
                            Background REG_SZ 0 0 0
                            DebugServerCommand REG_SZ no
                            SFCDisable REG_DWORD 0 (0x0)
                            WinStationsDisabled REG_SZ 0
                            HibernationPreviouslyEnabled REG_DWORD 1 (0x1)
                            ShowLogonOptions REG_DWORD 0 (0x0)
                            AltDefaultUserName REG_SZ Admin
                            AltDefaultDomainName REG_SZ ADMIN-3EB9D1403
                            KeepRASConnections REG_SZ 1

                            ===============
                            [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\crypt32chain]
                            [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cryptnet]
                            [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cscdll]
                            [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ScCertProp]
                            [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Schedule]
                            [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\sclgntfy]
                            [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\SensLogn]
                            [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\termsrv]
                            [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wlballoon]

                            ===============
                            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
                            {AEB6717E-7E19-11d0-97EE-00C04FD91972} REG_SZ

                            ===============
                            [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
                            %windir%\system32\sessmgr.exe REG_SZ %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
                            C:\Program Files\MSN Messenger\livecall.exe REG_SZ C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)
                            C:\Program Files\ma-config.com\maconfservice.exe REG_SZ C:\Program Files\ma-config.com\maconfservice.exe:LocalSubNet:Enabled:maconfservice
                            C:\Program Files\LimeWire\LimeWire.exe REG_SZ C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire
                            C:\Program Files\eMule\eMule.exe REG_SZ C:\Program Files\eMule\eMule.exe:*:Enabled:eMule Plus
                            C:\Program Files\Ares\Ares.exe REG_SZ C:\Program Files\Ares\Ares.exe:*:Enabled:Ares p2p for windows
                            C:\Program Files\SightSpeed\SightSpeed.exe REG_SZ C:\Program Files\SightSpeed\SightSpeed.exe:*:Enabled:SightSpeed
                            C:\Program Files\Messenger\msmsgs.exe REG_SZ C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger
                            C:\Program Files\Windows Live\Messenger\wlcsdk.exe REG_SZ C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call
                            C:\Program Files\Windows Live\Messenger\msnmsgr.exe REG_SZ C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger
                            C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe REG_SZ C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live FolderShare
                            C:\Program Files\Samsung\Samsung New PC Studio\npsasvr.exe REG_SZ C:\Program Files\Samsung\Samsung New PC Studio\npsasvr.exe:*:Enabled:KTF MUSIC AoD Server
                            C:\Program Files\Samsung\Samsung New PC Studio\npsvsvr.exe REG_SZ C:\Program Files\Samsung\Samsung New PC Studio\npsvsvr.exe:*:Enabled:KTF MUSIC VoD Server
                            C:\Program Files\Skype\Phone\Skype.exe REG_SZ C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype

                            [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
                            %windir%\system32\sessmgr.exe REG_SZ %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
                            C:\Program Files\MSN Messenger\livecall.exe REG_SZ C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)
                            C:\Program Files\Windows Live\Messenger\wlcsdk.exe REG_SZ C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call
                            C:\Program Files\Windows Live\Messenger\msnmsgr.exe REG_SZ C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger
                            C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe REG_SZ C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live FolderShare

                            ===============
                            ActivX controls
                            ===============
                            HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{0CCA191D-13A6-4E29-B746-314DEE697D83}
                            HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{166B1BCA-3F9C-11CF-8075-444553540000}
                            HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{20A60F0D-9AFA-4515-A0FD-83BD84642501}
                            HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{215B8138-A3CF-44C5-803F-8226143CFC0A}
                            HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{4A85DBE0-BFB2-4119-8401-186A7C6EB653}
                            HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{5C051655-FCD5-4969-9182-770EA5AA5565}
                            HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{5D6F45B3-9043-443D-A792-115447494D24}
                            HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{5D86DDB5-BDF9-441B-9E9E-D4730F4EE499}
                            HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{80DD2229-B8E4-4C77-B72F-F22972D723EA}
                            HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{8100D56A-5661-482C-BEE8-AFECE305D968}
                            HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{867E13F2-7F31-44FB-AC97-CD38E0DC46EF}
                            HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{8AD9C840-044E-11D1-B3E9-00805F499D93}
                            HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
                            HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{9191F686-7F0A-441D-8A98-2FE3AC1BD913}
                            HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{B8BE5E93-A60C-4D26-A2DC-220313175592}
                            HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{C3F79A2B-B9B4-4A66-B012-3EE46475B072}
                            HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
                            HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
                            HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
                            HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}
                            HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{E5F5D008-DD2C-4D32-977D-1A0ADF03058B}
                            HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{F5A7706B-B9C0-4C89-A715-7A0C6B05DD48}
                            HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{F8C5C0F1-D884-43EB-A5A0-9E1C4A102FA8}

                            ===============
                            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\<{12d0ed0d-0ee0-4f90-8827-78cefb8f4988}
                            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}
                            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{26923b43-4d38-484f-9b9e-de460746276c}
                            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}
                            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{CB58DED6-4AF3-4080-9DF1-DEE72075169F}
                            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{08B0E5C0-4FCB-11CF-AAA5-00401C608500}
                            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10072CEC-8CC1-11D1-986E-00A0C955B42F}
                            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2179C5D3-EBFF-11CF-B6FD-00AA00B4E220}
                            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}
                            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{283807B5-2C60-11D0-A31D-00AA00B92C03}
                            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}
                            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{36f8ec70-c29a-11d1-b5c7-0000f8051515}
                            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{3af36230-a269-11d1-b5bf-0000f8051515}
                            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{3bf42070-b3b1-11d1-b5c5-0000f8051515}
                            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4278c270-a269-11d1-b5bf-0000f8051515}
                            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}
                            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}
                            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA848-CC51-11CF-AAFA-00AA00B6015C}
                            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA855-CC51-11CF-AAFA-00AA00B6015F}
                            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{45ea75a0-a269-11d1-b5bf-0000f8051515}
                            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4f216970-c90c-11d1-b5c7-0000f8051515}
                            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4f645220-306d-11d2-995d-00c04f98bbc9}
                            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5945c046-1e7d-11d1-bc44-00c04fd912be}
                            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5A8D6EE0-3E18-11D0-821E-444553540000}
                            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5fd399c0-a70a-11d1-9948-00c04f98bbc9}
                            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{630b1da0-b465-11d1-9948-00c04f98bbc9}
                            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}
                            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6fab99d0-bab8-11d1-994a-00c04f98bbc9}
                            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}
                            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{73FA19D0-2D75-11D2-995D-00C04F98BBC9}
                            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7790769C-0471-11d2-AF11-00C04FA35D02}
                            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4340}
                            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4383}
                            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}
                            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9381D8F2-0288-11D0-9501-00AA00B911A5}
                            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{ACC563BC-4266-43f0-B6ED-9D38C4202C7E}
                            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}
                            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C9E9A340-D1F1-11D0-821E-444553540600}
                            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CC2A9BA0-3BDD-11D0-821E-444553540000}
                            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CDD7975E-60F8-41d5-8149-19E51D6F71D0}
                            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{D27CDB6E-AE6D-11cf-96B8-444553540000}
                            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{de5aed00-a4bf-11d1-9948-00c04f98bbc9}
                            HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{E92B03AB-B707-11d2-9CBD-0000F87A369E}

                            ==============
                            BHO :
                            ======
                            [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{C84D72FE-E17D-4195-BB24-76C02E2E7C4E}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]

                            ================
                            Internet Explorer :
                            ================
                            [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
                            Start Page REG_SZ https://www.msn.com/fr-fr/?ocid=iehp

                            [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                            Start Page REG_SZ https://www.google.com/?gws_rd=ssl

                            ========
                            Services
                            ========
                            [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services]

                            Ndisuio : 0x3 ( OK = 3 )
                            SharedAccess : 0x2 ( OK = 2 )
                            wuauserv : 0x2 ( OK = 2 )

                            =========
                            Atapi.sys
                            =========

                            %%%% HASHDEEP-1.0
                            %%%% size,md5,sha256,filename
                            ## Invoked from: C:\Documents and Settings\Admin\Local Settings\Temp\5.tmp
                            ## C:\> hashdeep C:\WINDOWS\System32\Drivers\atapi.sys
                            ##
                            95360,cdfe4411a69c224bd1d11b2da92dac51,0e6b23a80f171550575bebc56f7500cd87a5cf03b2b9fdc49bc3de96282cd69d,C:\WINDOWS\System32\Drivers\atapi.sys

                            Sources
                            =======

                            C:\WINDOWS\SoftwareDistribution\Download\327771f7f3830b5acec68906a2aac4ab\atapi.sys
                            C:\WINDOWS\SoftwareDistribution\Download\44b6174a4a693136d02d4a7ecd7cbd54\atapi.sys
                            C:\WINDOWS\system32\drivers\atapi.sys

                            Référence :
                            ==========

                            Win XP_32b : a64013e98426e1877cb653685c5c0009
                            Win XP_SP2_32b : CDFE4411A69C224BD1D11B2DA92DAC51
                            Win XP_SP3_32b : 9F3A2F5AA6875C72BF062C712CFA2674
                            Vista_32b : e03e8c99d15d0381e02743c36afc7c6f
                            Vista_SP1_32b : 2d9c903dc76a66813d350a562de40ed9
                            Vista_SP2_32b : 1F05B78AB91C9075565A9D8A4B880BC4
                            Vista_SP2_64b : 1898FAE8E07D97F2F6C2D5326C633FAC
                            Windows 7_32b : 80C40F7FDFC376E4C5FEEC28B41C119E
                            Windows 7_64b : 02062C0B390B7729EDC9E69C680A6F3C

                            =======
                            Drive :
                            =======

                            Défragmenteur de disque Windows
                            Copyright (c) 2001 Microsoft Corp. et Executive Software International Inc.

                            Rapport d'analyse
                            97,65 Go total, 40,30 Go libre (41%), 22% fragmenté (fragmentation du fichier 45%)

                            Vous devriez défragmenter ce volume.

                            ¤¤¤¤¤¤¤¤¤¤ Files/folders :

                            Present !! : C:\WINDOWS\SET25.tmp
                            Present !! : C:\WINDOWS\SET3.tmp
                            Present !! : C:\WINDOWS\SET4.tmp
                            Present !! : C:\WINDOWS\SET8.tmp
                            Present !! : C:\WINDOWS\mbr.exe
                            Present !! : C:\WINDOWS\System32\drivers\etc\hosts.msn
                            Present !! : C:\WINDOWS\System32\SET*.tmp
                            Present !! : C:\Documents and Settings\Admin\Application Data\Microsoft\Clip Organizer\mstore10.mgc
                            Present !! : C:\Documents and Settings\Admin\Application Data\Microsoft\Clip Organizer\Offic10.MGC
                            Present !! : C:\Documents and Settings\Admin\LOCAL Settings\Temp\catchme.dll

                            ¤¤¤¤¤¤¤¤¤¤ Keys :

                            Present !! : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{0E5CBF21-D15F-11D0-8301-00AA005B4383}
                            Present !! : HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools
                            Present !! : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Install.exe"
                            Present !! : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Setup.exe"

                            ============
                            1. ▶ Relance List&Kill'em(soit en clic droit pour vista),avec le raccourci sur ton bureau.
                              mais cette fois-ci :

                              ▶ choisis l'option 2 = Mode Suppression

                              laisse travailler l'outil.

                              en fin de scan un rapport s'ouvre

                              ▶ colle le contenu dans ta reponse
                              • 1
                              • 2