Belle brochette de virus

Bonjour,
nous avons apparemment attrapé une belle brochette de virus.

J'ai passé la journée à tenter de les enlever moi-même, mais voilà, il y en a un qui m'empêche d'ouvrir à peu près tous les programmes dont j'ai besoin (Malware, Spyware Doctor, Hijack This, etc). Lorsque je clique dessus, le sablier apparaît un peu, puis rien ne se passe (aucun message d'erreur, juste rien...)

J'ai réussi (je crois) à enlever le Paladin. Il y a toujours le XP Antispyware 2010, et possiblement le av.exe ainsi qu'un autre dont je ne me souviens pas le nom.

Je ne peux pas aller sur Internet, je reçois un message comme quoi il est dangeureux d'aller sur Internet, que je dois télécharger tel programme d'antivirus, etc.

SVP, pouvez-vous m'aider?
Rappelez vous qu'il m'est impossible d'ouvrir les programmes que l'on utilise normalement pour faire un rapport...

J'ai déjà essayé de les ouvrir en mode sans échec, sans succès!

SVP si quelqu'un veut bien m'aider j'apprécierais qu'il m'aide jusqu'au bout, souvent, sur ce forum, on m'abandonne en cours de processus...
Configuration: Windows XP / Internet Explorer 7.0
Je n'utilise pas le même ordinateur pour poster ce message que celui qui a un problème.

27 réponses

Résumé de la discussion

Une infection par des virus et des logiciels espions bloque l'ouverture des programmes de sécurité et limite l'accès à Internet sur Windows XP, compliquant le diagnostic et le rapport. Plusieurs solutions proposées impliquent l'utilisation d'outils de diagnostic comme OTL (OLDTimer) pour générer des rapports détaillés et, après sauvegarde des logs sur un dépôt, l'analyse des journaux afin d'identifier les composants malveillants. Des approches complémentaires recommandent des pare-feu renforcés (par exemple Comodo), des antivirus variés (AntiVir, Avira) et des outils comme RegRun, ainsi que des vérifications en ligne via des analyses multi-anti-virus. En dernier élément utile, l'examen des éléments de démarrage et des clés Run peut révéler des entrées modifiées par le logiciel malveillant, nécessitant une analyse ciblée de ces valeurs.

Bobot (l’IA à votre service)
  1. salut ouvre ton gestionnaire des taches coupe le processus av.exe" tiens moi au ourant
    0
    1. salut,

      merci de ta réponse.

      J'ai déjà essayé, et cela ne change rien.
      0
  2. Modérateur
    Bonjour a vous,

    Télécharge RegRun Reanimator (Par Greatis Software).

    Transfère le par clé USB Télécharge aussi USBFix pour vérifier et désinfecter la clé usb entre les transfers,

    N'ouvre pas ta clé usb sur le pc saint avant de vérifier.

    Installe Reanimator

    Note:Certains avec l'installation bloquée ont réussi a le faire en redémarrant avant qu'un virus se lance,

    Clic sur scan for viruses.

    Clic sur scan windows startup.

    Coche la case "Use deep level scanning once".

    Clic sur "Make scan now".

    Clic sur la flèche verte "Fix problems".

    Si il propose Regguard,répond simplement Non,ou peu importe,c'est a ta discretion.

    Clic-droit sur le nom du premier item trouvé (dans le milieu de la fenètre) et "Save to file" pour sauvegarder le premier résultat dans un fichier nommé 1.txt (Par défaut dans "Mes Documents")

    Clic sur la flèche verte (en haut a droite) pour l'item suivant

    Clic-droit sur le nom du deuxième item trouvé (dans le milieu de la fenètre) et "Save to file" pour sauvegarder le deuxième résultat dans un fichier nommé 2.txt

    Ainsi de suite jusqu'au dernier ensuite,choisit "Exit" quand il te le sera proposé.

    Et poste les résultats contenus dans les fichiers 1.txt 2.txt 3.txt....
    0
    1. Bonjour,

      merci à toi aussi de ta réponse. Je n'ai pas eu le temps d'essayer tes suggestions hier et ce matin je quitte la maison jusqu'à mercredi.

      Je ferai cela mercredi après-midi (HNE) en espérant que tu pourras toujours m'aider à ce moment.

      A bientôt donc!
      0
    2. Modérateur
      @giRafeSalut,

      Vu que tu a de la difficuleté a installer ou utiliser certans outils,je ne veut pas t'empècher de supprimer ce malware (si tu sait bien ce que tu fait) plutot que de me faire une liste et fermer le programme ensuite,

      Autrement dit,si tu tombe pile dessus,choisit "Get it out" confirme et utilise "Reboot" a la fin plutot que "Exit".

      Pour le reste,liste les comme je t'ai demandé en premier.

      Je ne voudrait pas lire plus tard "J'ai tout supprimé et j'ai un écran noir ou bleu ou le pc reboot tout seul".

      PS:Essaie le fichier FixExe.reg ici:https://forums.commentcamarche.net/forum/affich-16718559-virus-mechant#13
      0
    3. Ouain, j'ai bloqué assez vite.

      Premièrement, je ne comprends pas bien comment "vérifier et désinfecter ma clé usb" si je ne dois pas "ouvrir la clé usb sur le pc saint avant de vérifier"... ??? Peux-tu clarifier comment je dois procéder?

      Ensuite, j'ai tenté de télécharger Usbfix.exe et lorsque je clique sur le .exe, je reçois un message qui dit Message d'analyse lors de l'Accès et "Alerte Virus Scan" et que le fichier C:\UsbFix\Tools\Kill_P.exe a été supprimé. Je n'ai comme option que de fermer la fenêtre après quoi il ne se passe rien...

      Alors je suis bloquée ici...

      Merci de ta patience.
      0
  3. Modérateur
    Si tu clic sur une clé infecté,le malware est exécuté. il faut l'analyser et supprimer (si elle est infecté par un fichier Autorun.inf et un fichier exécutable indésirable.

    USBFix option 1 recherche puis option 2 Suppression

    Accès et "Alerte Virus Scan" de XP Antispyware 2010?

    Si tu le fait en mode sans échec?

    Note qu'il est possible que Reanimator ne détecte rien si il analyse en mode sans échec,donc,une autre procédure légèrement différente s'impose.

    Télécharge RegRun Reanimator (Par Greatis Software).

    Installe le.

    Clic sur scan for viruses.

    Clic sur scan windows startup.

    Coche la case "Use deep level scanning once".

    Important:Prends note de ce qui suit avant de continuer:

    L'ordinateur redémarrera et le programme analysera avant d'arriver sur le bureau,alors,tu n'y aurra pas accès durant un moment.

    Clic sur "Reboot" et confirme.

    Laisse le redémarrer en mode normal.

    Clic sur la flèche verte "Fix problems".

    Si il propose Regguard,répond simplement Non,ou peu importe,c'est a ta discretion.

    Clic-droit sur le nom du premier item trouvé (dans le milieu de la fenètre) et "Save to file" pour sauvegarder le premier résultat dans un fichier nommé 1.txt (Par défaut dans "Mes Documents")

    Note:Si tu les enregistre sur C: ils seront plus facilement accessibles par la suite.

    Clic sur la flèche verte (en haut a droite) pour l'item suivant

    Clic-droit sur le nom du deuxième item trouvé (dans le milieu de la fenètre) et "Save to file" pour sauvegarder le deuxième résultat dans un fichier nommé 2.txt

    Ainsi de suite jusqu'au dernier ensuite,choisit "Reboot" quand il te le sera proposé pour redémarrer en mode sans échec.

    Et poste les résultats contenus dans tous les fichiers 1.txt 2.txt 3.txt...
    0
    1. Désolée mais je ne comprends pas.

      Je n'arrive pas à ouvrir usbfix.exe

      Je crois qu'il s'Agit du Spybot (sur mon ordi sain) qui m'empêche de l'ouvrir.

      Commencons par régler cette étape avant tout d'accord?

      Merci
      0
    2. Modérateur
      @giRafeDésactive Spybot,je crois que c'est le module Tea timer.

      "Process.exe", une composante de l'outil USBFix, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool. Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus. Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.

      0
    3. @fabulj'ai terminé Spybot mais ça a fait la même chose.

      McAfee peut-être?
      0
    4. @fabulOK, j'ai désactivé McAfee et ce ne l'a pas fait.

      Par contre, il y a une petite fenêtre toute blanche qui s'ouvre et se referme très rapidement sans qu'il ne se passe quoi que ce soit de plus... est-ce normal?

      J'ai branché ma USB dans son port et ai réessayé de nouveau, ça n'a rien fait de plus...

      Quoi maintenant?
      0
  4. J'ai eu le même virus il y a 1h et je l'ai vaincu :D voila comment j'ai fait:

    - J'ai télécharger l'antivirus "Malwarebytes"
    - Aprés le téléchargement je ne l'ai pas éxécuter tout de suite j'ai redémarré mon ordi en mode sans échec
    - Tu installe l'anti-virus puis tu fais un scan
    - Dés le scan est fini, tu redémarre ton ordi en mode normal et voila

    Maintenant pour être en sécurité j'ai comme antivirus Malwarebytes, Avira et Bitdefender 2009 :)
    0
    1. Modérateur
      Avira et Bitdefender 2009

      Jamais deux antivirus en mème temps.
      0
    2. Merci Rexxxor mais je ne peux même pas ouvrir l'.exe même en mode sans échec.
      0
  5. Pourquoi ???
    0
    1. Modérateur
      Ils se nuisent,les deux qui travaillent ensemble travaillent moins bien que un seul.
      0
    2. @fabulOK, fabul, j'ai téléchargé Reanimator sur ma clé USB.

      Je vais aller tenter de l'installer sur l'ordi infecté. J'Aimerais savoir avant si tu me conseilles de le partir en mode sans échec (safe mode) ou de façon normale?

      Merci
      0
    3. Modérateur
      @giRafeEn mode sans échec,tu aurra plus de chance de pouvoir l'installer,

      Et clic sur le fichier Fixexe.reg si il le faut.
      https://forums.commentcamarche.net/forum/affich-16718559-virus-mechant#13

      Et suis cette méthode https://forums.commentcamarche.net/forum/affich-16725834-belle-brochette-de-virus#7

      PS:La plupart des objects détectés sont légitimes et a ne pas supprimer.si tu vois des logiciels de sécurité dont tu a confiance,il n'est pas nécessaire de les mettre dans la liste.
      0
    4. @fabulÇa a fonctionné!

      voici les fichiers .txt

      Item Name: {B6D223F6-C185-49a2-BA7E-A03E84744702}
      Author:
      Related File: C:\WINDOWS\system32\iehelper.dll
      Type: Browser Helper Objects

      Item Name: .exe
      Author: Unknown
      Related File: "C:\Documents and Settings\Administrator\Local Settings\Application Data\av.exe" /START "%1" %*
      Type: Main File Extensions

      Item Name: kbupdate
      Author:
      Related File: kbupdate.dll
      Type: Winlogon Notification

      Item Name: SSHNAS
      Author: Unknown
      Related File: C:\WINDOWS\system32\sshnas21.dll
      Type: Svchost DLLs

      Item Name: Paladin Antivirus
      Author: Unknown
      Related File: "C:\Program Files\Paladin Antivirus\pav.exe" -noscan
      Type: Registry Run

      Item Name: {35DC3473-A719-4d14-B7C1-FD326CA84A0C}
      Author: Unknown
      Related File: C:\WINDOWS\msa.exe
      Type: Scheduled Tasks

      Item Name: av.exe
      Author: Unknown
      Related File: C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\LOCAL SETTINGS\APPLICATION DATA\AV.EXE
      Type: Running Processes

      Item Name: UserInit
      Author: Unknown
      Related File: C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\wsnpoema.exe,
      Type: UserInit Value

      Item Name: RTHDBPL
      Author:
      Related File: C:\Documents and Settings\Administrator\Application Data\SystemProc\lsass.exe
      Type: Explorer Run

      Item Name: SimpleShlExt
      Author: Unknown
      Related File: C:\PROGRA~1\PALADI~1\pavext.dll
      Type: Context Menu Handlers

      Item Name: taskman
      Author: Unknown
      Related File: C:\RECYCLER\S-1-5-21-8950794466-6626781014-450798415-0461\vesita.exe
      Type: Winlogon System

      Item Name: msacm.ac3filter
      Author: Unknown
      Related File: ac3filter.acm
      Type: Codecs

      Item Name: ctjamsxh
      Author:
      Related File: C:\Documents and Settings\Administrator\Local Settings\Application Data\jaqgol\qgeysysguard.exe
      Type: Registry Run

      Item Name: TOY5KNQ8OC
      Author: Unknown
      Related File: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Nvr.exe
      Type: Registry Run

      Item Name: eventcreatexp.exe
      Author: Unknown
      Related File: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\eventcreatexp.exe
      Type: Registry Run

      Item Name: CTFMON
      Author: Unknown
      Related File: C:\WINDOWS\Temp\_ex-08.exe
      Type: Registry Run

      Item Name: Microsoft Office.lnk
      Author: Microsoft Corporation
      Related File: C:\Program Files\Microsoft Office\Office\OSA9.EXE
      Type: Common Startup Folder

      Item Name: {66BA574B-1E11-49b8-909C-8CC9E0E8E015}
      Author: Unknown
      Related File: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Nvr.exe
      Type: Scheduled Tasks
      0
    5. @fabulQue dois-je faire ensuite?

      Merci
      0
  6. Modérateur
    Ton titre était juste,c'en est une belle, 2 Légitimes (ac3filter.acm,OSA9.EXE)

    Le pc va perdre du poid.

    Get it out,confirmer et Reboot a la fin.

    Item Name: {B6D223F6-C185-49a2-BA7E-A03E84744702}
    Author:
    Related File: C:\WINDOWS\system32\iehelper.dll
    Type: Browser Helper Objects

    Item Name: .exe
    Author: Unknown
    Related File: "C:\Documents and Settings\Administrator\Local Settings\Application Data\av.exe" /START "%1" %*
    Type: Main File Extensions

    Item Name: kbupdate
    Author:
    Related File: kbupdate.dll
    Type: Winlogon Notification

    Item Name: SSHNAS
    Author: Unknown
    Related File: C:\WINDOWS\system32\sshnas21.dll
    Type: Svchost DLLs

    Item Name: UserInit
    Author: Unknown
    Related File: C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\wsnpoema.exe,
    Type: UserInit Value

    Item Name: Paladin Antivirus
    Author: Unknown
    Related File: "C:\Program Files\Paladin Antivirus\pav.exe" -noscan
    Type: Registry Run

    Item Name: {35DC3473-A719-4d14-B7C1-FD326CA84A0C}
    Author: Unknown
    Related File: C:\WINDOWS\msa.exe
    Type: Scheduled Tasks

    Item Name: av.exe
    Author: Unknown
    Related File: C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\LOCAL SETTINGS\APPLICATION DATA\AV.EXE
    Type: Running Processes

    Item Name: UserInit
    Author: Unknown
    Related File: C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\wsnpoema.exe,
    Type: UserInit Value

    Item Name: RTHDBPL
    Author:
    Related File: C:\Documents and Settings\Administrator\Application Data\SystemProc\lsass.exe
    Type: Explorer Run

    Item Name: SimpleShlExt
    Author: Unknown
    Related File: C:\PROGRA~1\PALADI~1\pavext.dll
    Type: Context Menu Handlers

    Item Name: ctjamsxh
    Author:
    Related File: C:\Documents and Settings\Administrator\Local Settings\Application Data\jaqgol\qgeysysguard.exe
    Type: Registry Run

    Item Name: TOY5KNQ8OC
    Author: Unknown
    Related File: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Nvr.exe
    Type: Registry Run

    Item Name: eventcreatexp.exe
    Author: Unknown
    Related File: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\eventcreatexp.exe
    Type: Registry Run

    Item Name: CTFMON
    Author: Unknown
    Related File: C:\WINDOWS\Temp\_ex-08.exe
    Type: Registry Run

    Item Name: {66BA574B-1E11-49b8-909C-8CC9E0E8E015}
    Author: Unknown
    Related File: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Nvr.exe
    Type: Scheduled Tasks
    0
    1. Salut,

      je ne comprends pas exactement ce que je dois faire...

      merci!
      0
    2. Modérateur
      @giRafeDémarre en mode sans échec et démarre reanimator,

      Clic sur scan for viruses.

      Clic sur scan windows startup.

      Coche la case "Use deep level scanning once".

      Important:Prends note des fichiers a supprimer avant de continuer.

      Clic sur "Reboot" et confirme.

      Laisse le redémarrer en mode normal.

      Clic sur la flèche verte "Fix problems".

      Si il propose Regguard,répond simplement Non,ou peu importe,c'est a ta discretion.

      Choisit "Get it out" pour les fichiers a supprimer et clic sur "Reboot" quand une fenètre s'ouvrira et te le proposera.

      (Passe avec la flèche pour les fichiers qui ne doivent pas ètre supprimés EX:2 Légitimes (ac3filter.acm,OSA9.EXE) ).
      0
    3. @fabulVoilà c'est fait, mais ne m'ont pas été proposés av.exe et .exe tout court.

      Sinon, j'ai l'impression que de nouveaux ont été détectés.

      Donc là je vais rouler Malware mais est-ce que je supprime tout ce que Malware me propose?!
      0
    4. Modérateur
      @giRafeOui,pour malwarebytes

      Et pour les nouveaux trouvés,refait la manip,je voudrait savoir quoi.

      Clic-droit sur le nom du premier item trouvé (dans le milieu de la fenètre) et "Save to file" pour sauvegarder le premier résultat dans un fichier nommé 1.txt (Par défaut dans "Mes Documents")

      Note:Si tu les enregistre sur C: ils seront plus facilement accessibles par la suite.

      Clic sur la flèche verte (en haut a droite) pour l'item suivant

      Clic-droit sur le nom du deuxième item trouvé (dans le milieu de la fenètre) et "Save to file" pour sauvegarder le deuxième résultat dans un fichier nommé 2.txt

      Ainsi de suite jusqu'au dernier ensuite,choisit "Reboot" quand il te le sera proposé pour redémarrer en mode sans échec.

      Et ne démarre qu'en mode sans échec entre les opérations si possible.

      Ou ne redémarre pas du tout (si tu est en mode normal seulement) "Clic sur "Make scan now" plutot que "Reboot" et dit moi la liste immédiatement pour qu'on supprime si il faut au prochain redémarrage.

      0
    5. @fabulLes voici
      Je n'ai pas encore roulé Malware, j'y vais après ceci :

      Item Name: catchme
      Author:
      Related File: \??\C:\ComboFix\catchme.sys
      Type: Services detected by Partizan

      Item Name: wsnpoem.sys
      Author:
      Related File: \??\C:\WINDOWS\system32\drivers\wsnpoem.sys
      Type: Services detected by Partizan

      Item Name: taskman
      Author: Unknown
      Related File: C:\RECYCLER\S-1-5-21-8950794466-6626781014-450798415-0461\vesita.exe
      Type: Winlogon System

      Item Name: taskman
      Author: Unknown
      Related File: C:\RECYCLER\S-1-5-21-8950794466-6626781014-450798415-0461\vesita.exe
      Type: Winlogon System

      Item Name: _VOIDd.sys
      Author:
      Related File: \systemroot\system32\drivers\_VOIDvdksemwsft.sys
      Type: Services detected by Partizan

      Item Name: vesita.exe
      Author: Unknown
      Related File: C:\RECYCLER\S-1-5-21-8950794466-6626781014-450798415-0461\VESITA.EXE
      Type: Running Processes

      Merci
      0
  7. Modérateur
    Ensuite,Malwarebytes,mise a jour,analyse complète,suppression.

    Nettoyage CCleaner Portable et ATF-Cleaner

    Désinstallation de l'ancien antivirus Revo Uninstaller Portable

    Nettoyage Wise Registry Cleaner Portable

    Nouvel antivirus AntiVir

    Pare feu Comodo

    Je crois que ça devrait ètre bon,donne moi un retour.
    0
    1. Salut encore fabul,

      j'ai de la difficulté à voir ce que je dois faire avec Wise Registry Cleaner Portable.

      peux-tu m'expliquer les étapes à suivre svp?

      Merci!
      0
    2. Je crois que je me suis débrouillée avec Wise Cleaner.

      Sur mon portable j'ai Spybot Search & Destroy, est-ce que tu me le recommande?
      Est-ce que ça remplacerait Comodo?
      0
    3. Modérateur
      @giRafeNon,Comodo controle l'accès a internet,c'est différent,spybot ne fait pas ça,

      Spybot détecte surtout des cookies et parfois,sa protection résidente peut devenir gènante.

      Commence par faire comme dit Gen-Hackman,surtout avant d'installer Spybot (si tu le fait).
      0
    4. @fabulSalut fabul,

      voilà, j'ai fait toutes les étapes au no 26, j'ai installé Antivir et Comodo.
      J'ai fait les instrcutions de gen-hackman et ai posté le rapport...

      J'attends la suite, mais à première vue, tout semble bien fonctionner maintenant!!!

      Merci énormément!
      0
  8. salut sans rapport diagnostic tu arrives à dire que le pc va bien ?

    Desactive ton antivirus le temps de la manip ainsi que ton parefeu si présent(car il est detecté a tort comme infection)

    ▶ Télécharge List_Kill'em et enregistre le sur ton bureau

    ▶ Branche clés usb , disques durs externes , mp3 , mp4 , etc..

    double clique ( clic droit "executer en tant qu'administrateur" pour Vista/7 ) sur le raccourci sur ton bureau pour lancer l'installation

    coche la case "creer une icone sur le bureau"

    une fois terminée , clic sur "terminer" et le programme se lancera seul

    choisis la langue puis choisis l'option 1 = Mode Recherche........Ne fais pas l option 2 pour l'instant

    ▶ laisse travailler l'outil

    à l'apparition de la fenetre blanche , c'est un peu long , c'est normal , le programme n'est pas bloqué.

    un rapport du nom de catchme apparait sur ton bureau , ignore-le,ne le poste pas , , il s'auto supprimera a la fin du scan

    ▶ Poste le contenu du rapport qui s'ouvre aux 100 % du scan à l'ecran "COMPLETED"

    0
    1. Salut gen-hackman

      voici le résultat du rapport. Merci de me dire ce que je dois faire ensuite.

      List'em by g3n-h@ckm@n 1.2.8.1

      User : Administrator (Administrators)
      Update on 26/02/2010 by g3n-h@ckm@n ::::: 14.30
      Start at: 15:03:19 | 2010-02-28
      Contact : https://forums.commentcamarche.net/forum/virus-securite-7

      Intel(R) Pentium(R) 4 CPU 2.53GHz
      Microsoft Windows XP Professional (5.1.2600 32-bit) # Service Pack 3
      Internet Explorer 7.0.5730.13
      Windows Firewall Status : Enabled
      AV : Paladin Antivirus 1.0 [ Enabled | (!) Outdated ]
      AV : AntiVir Desktop 9.0.1.32 [ (!) Disabled | (!) Outdated ]

      C:\ -> Local Fixed Disk | 37,21 Go (3,88 Go free) | NTFS
      D:\ -> CD-ROM Disc

      Boot: Normal

      ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running

      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\csrss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Avira\AntiVir Desktop\sched.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\BCMSMMSG.exe
      C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb05.exe
      C:\Program Files\QuickTime\QTTask.exe
      C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
      C:\Program Files\Logitech\QuickCam\Quickcam.exe
      C:\Program Files\Search Settings\SearchSettings.exe
      C:\Program Files\Spyware Doctor\pctsTray.exe
      C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
      C:\Program Files\Avira\AntiVir Desktop\avguard.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      C:\Program Files\Messenger\msmsgs.exe
      C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
      C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\internet explorer\iexplore.exe
      C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
      C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
      C:\WINDOWS\system32\wuauclt.exe
      C:\Program Files\List_Kill'em\List_Kill'em.scr
      C:\WINDOWS\system32\cmd.exe
      C:\WINDOWS\system32\wbem\wmiprvse.exe
      C:\Documents and Settings\Administrator\Local Settings\temp\7.tmp\pv.exe

      ======================
      Keys "Run"
      ======================
      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      ctfmon.exe REG_SZ C:\WINDOWS\system32\ctfmon.exe
      swg REG_SZ "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
      MSMSGS REG_SZ "C:\Program Files\Messenger\msmsgs.exe" /background

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      IgfxTray REG_SZ C:\WINDOWS\system32\igfxtray.exe
      HotKeysCmds REG_SZ C:\WINDOWS\system32\hkcmd.exe
      BCMSMMSG REG_SZ BCMSMMSG.exe
      HPDJ Taskbar Utility REG_SZ C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb05.exe
      QuickTime Task REG_SZ "C:\Program Files\QuickTime\QTTask.exe" -atboottime
      LogitechCommunicationsManager REG_SZ "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
      LogitechQuickCamRibbon REG_SZ "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
      SearchSettings REG_SZ C:\Program Files\Search Settings\SearchSettings.exe
      Adobe Reader Speed Launcher REG_SZ "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
      Adobe ARM REG_SZ "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
      ISTray REG_SZ "C:\Program Files\Spyware Doctor\pctsTray.exe"
      avgnt REG_SZ "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
      COMODO Internet Security REG_SZ "C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
      HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce\ApprovedByRegRun2

      =====================
      Other Keys
      =====================
      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
      dontdisplaylastusername REG_DWORD 0 (0x0)
      legalnoticecaption REG_SZ
      legalnoticetext REG_SZ
      shutdownwithoutlogon REG_DWORD 1 (0x1)
      undockwithoutlogon REG_DWORD 1 (0x1)
      DisableRegistryTools REG_DWORD 0 (0x0)
      HideLegacyLogonScripts REG_DWORD 0 (0x0)
      HideLogoffScripts REG_DWORD 0 (0x0)
      RunLogonScriptSync REG_DWORD 1 (0x1)
      RunStartupScriptSync REG_DWORD 0 (0x0)
      HideStartupScripts REG_DWORD 0 (0x0)

      ===============
      [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
      NoDriveTypeAutoRun REG_DWORD 145 (0x91)

      ===============
      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
      NoDriveAutoRun REG_DWORD 67108863 (0x3ffffff)
      NoDriveTypeAutoRun REG_DWORD 255 (0xff)
      NoDrives REG_DWORD 0 (0x0)
      HonorAutoRunSetting REG_DWORD 1 (0x1)

      ===============
      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]

      ===============
      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
      AutoRestartShell REG_DWORD 1 (0x1)
      DefaultDomainName REG_SZ DENIS-500860AF8
      DefaultUserName REG_SZ Administrator
      LegalNoticeCaption REG_SZ
      LegalNoticeText REG_SZ
      PowerdownAfterShutdown REG_SZ 0
      ReportBootOk REG_SZ 1
      Shell REG_SZ Explorer.exe
      ShutdownWithoutLogon REG_SZ 0
      System REG_SZ
      Userinit REG_SZ c:\windows\system32\userinit.exe,
      VmApplet REG_SZ rundll32 shell32,Control_RunDLL "sysdm.cpl"
      SfcQuota REG_DWORD -1 (0xffffffff)
      allocatecdroms REG_SZ 0
      allocatedasd REG_SZ 0
      allocatefloppies REG_SZ 0
      cachedlogonscount REG_SZ 10
      forceunlocklogon REG_DWORD 0 (0x0)
      passwordexpirywarning REG_DWORD 14 (0xe)
      scremoveoption REG_SZ 0
      AllowMultipleTSSessions REG_DWORD 1 (0x1)
      UIHost REG_EXPAND_SZ logonui.exe
      LogonType REG_DWORD 1 (0x1)
      Background REG_SZ 0 0 0
      DebugServerCommand REG_SZ no
      SFCDisable REG_DWORD 0 (0x0)
      WinStationsDisabled REG_SZ 0
      HibernationPreviouslyEnabled REG_DWORD 1 (0x1)
      ShowLogonOptions REG_DWORD 0 (0x0)
      AltDefaultUserName REG_SZ Administrator
      AltDefaultDomainName REG_SZ DENIS-500860AF8
      ChangePasswordUseKerberos REG_DWORD 1 (0x1)

      ===============
      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\crypt32chain]
      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cryptnet]
      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cscdll]
      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\dimsntfy]
      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\igfxcui]
      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ScCertProp]
      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Schedule]
      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\sclgntfy]
      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\SensLogn]
      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\termsrv]
      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WgaLogon]
      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wlballoon]

      ===============
      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
      {AEB6717E-7E19-11d0-97EE-00C04FD91972} REG_SZ

      ===============
      [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
      %windir%\system32\sessmgr.exe REG_SZ %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
      C:\Program Files\Grisoft\AVG7\avginet.exe REG_SZ C:\Program Files\Grisoft\AVG7\avginet.exe:*:Enabled:avginet.exe
      C:\Program Files\Grisoft\AVG7\avgamsvr.exe REG_SZ C:\Program Files\Grisoft\AVG7\avgamsvr.exe:*:Enabled:avgamsvr.exe
      C:\Program Files\Grisoft\AVG7\avgcc.exe REG_SZ C:\Program Files\Grisoft\AVG7\avgcc.exe:*:Enabled:avgcc.exe
      %windir%\Network Diagnostic\xpnetdiag.exe REG_SZ %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
      C:\Program Files\mIRC\mirc.exe REG_SZ C:\Program Files\mIRC\mirc.exe:*:Enabled:mIRC
      C:\Program Files\Marratech\Marratech6.1\bin\Marratech.exe REG_SZ C:\Program Files\Marratech\Marratech6.1\bin\Marratech.exe:*:Enabled:Marratech
      C:\Program Files\Java\jre1.5.0_12\bin\javaw.exe REG_SZ C:\Program Files\Java\jre1.5.0_12\bin\javaw.exe:*:Enabled:Java(TM) 2 Platform Standard Edition binary
      C:\Program Files\Internet Explorer\iexplore.exe REG_SZ C:\Program Files\Internet Explorer\iexplore.exe:*:Enabled:Internet Explorer
      C:\Program Files\Skype\Phone\Skype.exe REG_SZ C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype
      C:\Program Files\Windows Live\Messenger\wlcsdk.exe REG_SZ C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call
      C:\Program Files\Windows Live\Messenger\msnmsgr.exe REG_SZ C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger

      [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
      %windir%\system32\sessmgr.exe REG_SZ %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
      %windir%\Network Diagnostic\xpnetdiag.exe REG_SZ %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
      C:\Program Files\Windows Live\Messenger\wlcsdk.exe REG_SZ C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call
      C:\Program Files\Windows Live\Messenger\msnmsgr.exe REG_SZ C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger

      ===============
      ActivX controls
      ===============
      HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{0CCA191D-13A6-4E29-B746-314DEE697D83}
      HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{166B1BCA-3F9C-11CF-8075-444553540000}
      HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{4F1E5B1A-2A80-42CA-8532-2D05CB959537}
      HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{6414512B-B978-451D-A0D8-FCFDF33E833C}
      HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{8AD9C840-044E-11D1-B3E9-00805F499D93}
      HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
      HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0015-0000-0012-ABCDEFFEDCBA}
      HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
      HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
      HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{D27CDB6E-AE6D-11CF-96B8-444553540000}
      HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{E77F23EB-E7AB-4502-8F37-247DBAF1A147}

      ===============
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\<{12d0ed0d-0ee0-4f90-8827-78cefb8f4988}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{26923b43-4d38-484f-9b9e-de460746276c}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{010527D8-5CAC-E7A8-2083-A1DCF95E419B}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{08B0E5C0-4FCB-11CF-AAA5-00401C608500}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10072CEC-8CC1-11D1-986E-00A0C955B42F}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2179C5D3-EBFF-11CF-B6FD-00AA00B4E220}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{283807B5-2C60-11D0-A31D-00AA00B92C03}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{36f8ec70-c29a-11d1-b5c7-0000f8051515}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{3af36230-a269-11d1-b5bf-0000f8051515}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{3bf42070-b3b1-11d1-b5c5-0000f8051515}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{411EDCF7-755D-414E-A74B-3DCD6583F589}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4278c270-a269-11d1-b5bf-0000f8051515}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA848-CC51-11CF-AAFA-00AA00B6015C}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA855-CC51-11CF-AAFA-00AA00B6015F}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{45ea75a0-a269-11d1-b5bf-0000f8051515}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4f216970-c90c-11d1-b5c7-0000f8051515}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4f645220-306d-11d2-995d-00c04f98bbc9}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5056b317-8d4c-43ee-8543-b9d1e234b8f4}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5945c046-1e7d-11d1-bc44-00c04fd912be}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5A8D6EE0-3E18-11D0-821E-444553540000}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5fd399c0-a70a-11d1-9948-00c04f98bbc9}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{630b1da0-b465-11d1-9948-00c04f98bbc9}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6fab99d0-bab8-11d1-994a-00c04f98bbc9}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7790769C-0471-11d2-AF11-00C04FA35D02}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4340}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4383}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9381D8F2-0288-11D0-9501-00AA00B911A5}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{B508B3F1-A24A-32C0-B310-85786919EF28}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C9E9A340-D1F1-11D0-821E-444553540600}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CC2A9BA0-3BDD-11D0-821E-444553540000}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CDD7975E-60F8-41d5-8149-19E51D6F71D0}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{D27CDB6E-AE6D-11cf-96B8-444553540000}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{DAA94A2A-2A8D-4D3B-9DB8-56FBECED082D}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{de5aed00-a4bf-11d1-9948-00c04f98bbc9}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{E92B03AB-B707-11d2-9CBD-0000F87A369E}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{EF289A85-8E57-408d-BE47-73B55609861A}

      ==============
      BHO :
      ======
      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{145B29F4-A56B-4b90-BBAC-45784EBEBBB7}]
      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{22BF413B-C6D2-4d91-82A9-A0F997BA588C}]
      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]
      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}]

      ===
      DNS
      ===

      HKLM\SYSTEM\CCS\Services\Tcpip\..\{2A3A0E51-019D-4255-AFA6-7A6B724D8B0F}: DhcpNameServer=192.168.10.1
      HKLM\SYSTEM\CS1\Services\Tcpip\..\{2A3A0E51-019D-4255-AFA6-7A6B724D8B0F}: DhcpNameServer=192.168.10.1
      HKLM\SYSTEM\CS3\Services\Tcpip\..\{2A3A0E51-019D-4255-AFA6-7A6B724D8B0F}: DhcpNameServer=192.168.10.1
      HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.10.1
      HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.10.1
      HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.10.1

      ================
      Internet Explorer :
      ================
      [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
      Start Page REG_SZ https://www.msn.com/fr-fr/?ocid=iehp

      [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
      Start Page REG_SZ https://www.mcn21.org/

      ========
      Services
      ========
      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services]

      Ndisuio : 0x3 ( OK = 3 )
      EapHost : 0x3 ( OK = 2 )
      SharedAccess : 0x4 ( OK = 2 )
      wuauserv : 0x2 ( OK = 2 )

      =========
      Atapi.sys
      =========

      %%%% HASHDEEP-1.0
      %%%% size,md5,sha256,filename
      ## Invoked from: C:\Documents and Settings\Administrator\Local Settings\temp\7.tmp
      ## C:\> hashdeep.exe C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
      ##
      95360,cdfe4411a69c224bd1d11b2da92dac51,0e6b23a80f171550575bebc56f7500cd87a5cf03b2b9fdc49bc3de96282cd69d,C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
      %%%% HASHDEEP-1.0
      %%%% size,md5,sha256,filename
      ## Invoked from: C:\Documents and Settings\Administrator\Local Settings\temp\7.tmp
      ## C:\> hashdeep.exe C:\WINDOWS\ServicePackFiles\i386\atapi.sys
      ##
      96512,9f3a2f5aa6875c72bf062c712cfa2674,b4df1d2c56a593c6b54de57395e3b51d288f547842893b32b0f59228a0cf70b9,C:\WINDOWS\ServicePackFiles\i386\atapi.sys
      %%%% HASHDEEP-1.0
      %%%% size,md5,sha256,filename
      ## Invoked from: C:\Documents and Settings\Administrator\Local Settings\temp\7.tmp
      ## C:\> hashdeep.exe C:\WINDOWS\system32\drivers\atapi.sys
      ##
      96512,9f3a2f5aa6875c72bf062c712cfa2674,b4df1d2c56a593c6b54de57395e3b51d288f547842893b32b0f59228a0cf70b9,C:\WINDOWS\system32\drivers\atapi.sys
      %%%% HASHDEEP-1.0
      %%%% size,md5,sha256,filename
      ## Invoked from: C:\Documents and Settings\Administrator\Local Settings\temp\7.tmp
      ## C:\> hashdeep.exe C:\WINDOWS\system32\ReinstallBackups\0006\DriverFiles\i386\atapi.sys
      ##
      95360,cdfe4411a69c224bd1d11b2da92dac51,0e6b23a80f171550575bebc56f7500cd87a5cf03b2b9fdc49bc3de96282cd69d,C:\WINDOWS\system32\ReinstallBackups\0006\DriverFiles\i386\atapi.sys

      Référence :
      ==========

      Win 2000_SP2 : ff953a8f08ca3f822127654375786bbe
      Win XP_32b : a64013e98426e1877cb653685c5c0009
      Win XP_SP2_32b : CDFE4411A69C224BD1D11B2DA92DAC51
      Win XP_SP3_32b : 9F3A2F5AA6875C72BF062C712CFA2674
      Vista_32b : e03e8c99d15d0381e02743c36afc7c6f
      Vista_SP1_32b : 2d9c903dc76a66813d350a562de40ed9
      Vista_SP2_32b : 1F05B78AB91C9075565A9D8A4B880BC4
      Vista_SP2_64b : 1898FAE8E07D97F2F6C2D5326C633FAC
      Windows 7_32b : 80C40F7FDFC376E4C5FEEC28B41C119E
      Windows 7_64b : 02062C0B390B7729EDC9E69C680A6F3C

      =======
      Drive :
      =======

      Windows Disk Defragmenter
      Copyright (c) 2001 Microsoft Corp. and Executive Software International, Inc.

      Analysis Report
      37,21 GB Total, 3,88 GB (10%) Free, 13% Fragmented (23% file fragmentation)

      You should defragment this volume.

      ¤¤¤¤¤¤¤¤¤¤ Files/folders :

      Present !! : C:\confin.sys
      Present !! : C:\Program Files\Mozilla Firefox\extensions\{8CE11043-9A15-4207-A565-0C94C42D590D}
      Present !! : C:\Program Files\Search Settings
      Present !! : C:\WINDOWS\003016_.tmp
      Present !! : C:\WINDOWS\SET3.tmp
      Present !! : C:\WINDOWS\SET4.tmp
      Present !! : C:\WINDOWS\SET8.tmp
      Present !! : C:\WINDOWS\System32\404Fix.exe
      Present !! : C:\WINDOWS\System32\drivers\Cdaudio.sys
      Present !! : C:\WINDOWS\System32\drivers\etc\hosts.msn
      Present !! : C:\WINDOWS\System32\dumphive.exe"
      Present !! : C:\WINDOWS\System32\IEDFix.exe
      Present !! : C:\WINDOWS\System32\Process.exe
      Present !! : C:\WINDOWS\System32\SrchSTS.exe
      Present !! : C:\WINDOWS\System32\tmp.reg"
      Present !! : C:\WINDOWS\System32\VACFix.exe
      Present !! : C:\WINDOWS\System32\VCCLSID.exe
      Present !! : C:\WINDOWS\System32\WS2Fix.exe
      Present !! : C:\WINDOWS\winstart.bat
      Present !! : C:\Documents and Settings\Administrator\Application Data\Search Settings
      Present !! : C:\Documents and Settings\Administrator\Application Data\SystemProc

      ¤¤¤¤¤¤¤¤¤¤ Keys :

      Present !! : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{0E5CBF21-D15F-11D0-8301-00AA005B4383}
      Present !! : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{E67C74F4-A00A-4F2C-9FEC-FD9DC004A67F}
      Present !! : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}
      Present !! : HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDrives
      Present !! : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Install.exe"
      Present !! : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Setup.exe"
      Present !! : "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}"
      Present !! : "HKLM\Software\Search Settings"
      Present !! : HKCR\CLSID\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}
      Present !! : HKCR\SearchSettings.BHO
      Present !! : HKCR\SearchSettings.BHO.1
      Present !! : HKCR\secfile
      Present !! : HKCU\Software\AvScan
      Present !! : HKCU\SOFTWARE\Microsoft\Handle
      Present !! : HKCU\SOFTWARE\ROUA3O12PW
      Present !! : HKLM\Software\Classes\CLSID\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}
      Present !! : HKLM\Software\Classes\SearchSettings.BHO
      Present !! : HKLM\Software\Classes\SearchSettings.BHO.1
      Present !! : HKLM\Software\Classes\TypeLib\{937936AF-28CA-4973-B8AE-F250406149A2}
      Present !! : HKLM\Software\Classes\TypeLib\{CD082CCA-086F-4FD8-8FD7-247A0DBBD1CC}
      Present !! : HKLM\Software\Dealio
      Present !! : HKLM\SYSTEM\ControlSet001\Enum\Root\Legacy_SSHNAS
      Present !! : HKLM\SYSTEM\ControlSet003\Enum\Root\Legacy_SSHNAS
      Present !! : HKLM\SYSTEM\CurrentControlSet\Enum\Root\Legacy_SSHNAS

      ============

      catchme 0.3.1398.3 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
      Rootkit scan 2010-02-28 15:20:21
      Windows 5.1.2600 Service Pack 3 NTFS

      scanning hidden processes ...

      ? [13584]

      scanning hidden services & system hive ...

      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\jjeputv]
      "Type"=dword:00000001
      "Start"=dword:00000000
      "ErrorControl"=dword:00000000
      "Group"="Boot Bus Extender"
      [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\jjeputv]
      "Type"=dword:00000001
      "Start"=dword:00000000
      "ErrorControl"=dword:00000000
      "Group"="Boot Bus Extender"

      scanning hidden registry entries ...

      scanning hidden files ...

      scan completed successfully
      hidden processes: 1
      hidden services: 0
      hidden files: 0

      Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

      device: opened successfully
      user: MBR read successfully
      called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys atapi.sys hal.dll pciide.sys PCIIDEX.SYS
      kernel: MBR read successfully
      user & kernel MBR OK

      ==========
      Programs
      ==========

      AcrobatUpd810_euro_incr.msp
      Adobe
      Analog Devices
      Apple Software Update
      Avira
      Broadcom
      burnsetup.exe
      Common Files
      COMODO
      ComPlus Applications
      Enigma Software Group
      Google
      Greatis
      Grisoft
      Hewlett-Packard
      hp deskjet 5550 series
      InstallShield Installation Information
      Intel
      Internet Explorer
      Java
      Lavasoft
      List_Kill'em
      Logitech
      LSSF7
      Malwarebytes' Anti-Malware
      Marratech61.msi
      Media.Player.Codec.Pack.V3.3.1.Setup.exe
      Messenger
      Microsoft
      Microsoft CAPICOM 2.1.0.2
      microsoft frontpage
      Microsoft Office
      Microsoft Silverlight
      mIRC
      Movie Maker
      Mozilla Firefox
      MSBuild
      MSN
      MSN Gaming Zone
      NCH Swift Sound
      NetMeeting
      Online Services
      Outlook Express
      Paladin Antivirus
      QuickTime
      QuickTimeInstaller.exe
      R
      Radio-Canada
      Reference Assemblies
      Search Settings
      Skype
      Spybot - Search & Destroy
      Spyware Doctor
      StumbleUpon
      Tinn-R
      Trend Micro
      Uninstall Information
      VideoLAN
      Windows Live
      Windows Live SkyDrive
      Windows Media Connect 2
      Windows Media Player
      Windows NT
      WindowsUpdate
      xerox
      Xvid

      ============
      Drive C:
      ============

      $AVG8.VAULT$
      56f0069810575933201bc09aa98dcb
      AUTOEXEC.BAT
      boot.ini
      ComboFix.txt
      CONFIG.SYS
      confin.sys
      DELL
      Documents and Settings
      hpfr5550.log
      IO.SYS
      Kill'em
      List'em.txt
      MSDOS.SYS
      NTDETECT.COM
      ntldr
      pagefile.sys
      Program Files
      QooBox
      R files
      RECYCLER
      rkill.log
      sqmdata00.sqm
      sqmdata01.sqm
      sqmdata02.sqm
      sqmdata03.sqm
      sqmdata04.sqm
      sqmdata05.sqm
      sqmdata06.sqm
      sqmdata07.sqm
      sqmdata08.sqm
      sqmdata09.sqm
      sqmdata10.sqm
      sqmdata11.sqm
      sqmdata12.sqm
      sqmdata13.sqm
      sqmdata14.sqm
      sqmdata15.sqm
      sqmdata16.sqm
      sqmdata17.sqm
      sqmdata18.sqm
      sqmdata19.sqm
      sqmnoopt00.sqm
      sqmnoopt01.sqm
      sqmnoopt02.sqm
      sqmnoopt03.sqm
      sqmnoopt04.sqm
      sqmnoopt05.sqm
      sqmnoopt06.sqm
      sqmnoopt07.sqm
      sqmnoopt08.sqm
      sqmnoopt09.sqm
      sqmnoopt10.sqm
      sqmnoopt11.sqm
      sqmnoopt12.sqm
      sqmnoopt13.sqm
      sqmnoopt14.sqm
      sqmnoopt15.sqm
      sqmnoopt16.sqm
      sqmnoopt17.sqm
      sqmnoopt18.sqm
      sqmnoopt19.sqm
      System Volume Information
      WINDOWS

      ¤¤¤¤¤¤¤¤¤¤ Cracks | Keygens | Serials

      ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

      End of scan : 15:38:34,96
      0
  9. hello

    ▶ Relance List_Kill'em(soit en clic droit pour vista/7),avec le raccourci sur ton bureau.
    mais cette fois-ci :

    ▶ choisis l'option 2 = Mode Suppression

    laisse travailler l'outil.

    en fin de scan un rapport s'ouvre

    ▶ colle le contenu dans ta reponse
    0
    1. salut,
      je suis désolée pour le délai. J'ai été prise dans un tourbillon de vie qui n'est pas terminé malheureusement...
      je suis rarement chez moi, quand j'y suis j'ai à peine le temps de respirer.

      J'ai très peu utilisé mon ordi entre-temps mais les choses ne se sont pas améliorées. Maintenant, quand je pars l'ordi, j'arrive sur l'écran noir qui me donne le choix entre Safe mode, Safe mode with networking, Safe mode with *something else, Last known working configuration ou Normal.

      Le seul choix qui fonctionne est "Last known config" les autres me ramenent continuellement au même écran...
      Ensuite, mon Internet Explorer fonctionne une fois sur deux. Il ouvre et se referme immédiatement... Quand ça ne fonctionne pas, je dois redémarrer...

      Bon, j'ai quand même fait l'option 2 dans Kill'Em alors voici le rapport :
      Merci de votre patience et de votre aide. je vais activer les réponses par email comme ça je tarderai peut-être moins à répondre...

      Kill'em by g3n-h@ckm@n 1.2.8.1

      User : Administrator (Administrators)
      Update on 26/02/2010 by g3n-h@ckm@n ::::: 14.30
      Start at: 20:08:49 | 2010-04-08
      Contact : https://forums.commentcamarche.net/forum/virus-securite-7

      Intel(R) Pentium(R) 4 CPU 2.53GHz
      Microsoft Windows XP Professional (5.1.2600 32-bit) # Service Pack 3
      Internet Explorer 7.0.5730.13
      Windows Firewall Status : Enabled
      AV : Paladin Antivirus 1.0 [ Enabled | (!) Outdated ]
      AV : AntiVir Desktop 9.0.1.32 [ (!) Disabled | (!) Outdated ]
      FW : COMODO Firewall[ Enabled ]3.9

      C:\ -> Local Fixed Disk | 37,21 Go (2,77 Go free) | NTFS
      D:\ -> CD-ROM Disc

      ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running

      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\csrss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Avira\AntiVir Desktop\sched.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Avira\AntiVir Desktop\avguard.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
      C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
      C:\WINDOWS\BCMSMMSG.exe
      C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb05.exe
      C:\Program Files\QuickTime\qttask.exe
      C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
      C:\Program Files\Logitech\QuickCam\Quickcam.exe
      C:\Program Files\Search Settings\SearchSettings.exe
      C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
      C:\Program Files\Spyware Doctor\pctsTray.exe
      C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
      C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      C:\Program Files\Messenger\msmsgs.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\wuauclt.exe
      C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
      C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
      C:\WINDOWS\system32\wuauclt.exe
      C:\WINDOWS\System32\svchost.exe
      c:\program files\logitech\quickcam\lu\lulnchr.exe
      c:\program files\logitech\quickcam\lu\LogitechUpdate.exe
      C:\Program Files\List_Kill'em\List_Kill'em.scr
      C:\WINDOWS\system32\cmd.exe
      C:\WINDOWS\system32\wbem\wmiprvse.exe
      C:\Documents and Settings\Administrator\Local Settings\temp\6.tmp\pv.exe

      Detections :
      ==========

      ¤¤¤¤¤¤¤¤¤¤ Files/folders :

      Quarantined & Deleted !! : C:\confin.sys
      Quarantined & Deleted !! : C:\Program Files\Mozilla Firefox\extensions\{8CE11043-9A15-4207-A565-0C94C42D590D}
      Quarantined & Deleted !! : C:\Program Files\Search Settings
      Quarantined & Deleted !! : C:\WINDOWS\003016_.tmp
      Quarantined & Deleted !! : C:\WINDOWS\SET3.tmp
      Quarantined & Deleted !! : C:\WINDOWS\SET4.tmp
      Quarantined & Deleted !! : C:\WINDOWS\SET8.tmp

      Quarantined & Deleted !! : C:\WINDOWS\System32\404Fix.exe
      Quarantined & Deleted !! : C:\WINDOWS\System32\drivers\Cdaudio.sys
      Quarantined & Deleted !! : C:\WINDOWS\System32\drivers\etc\hosts.msn
      Quarantined & Deleted !! : C:\WINDOWS\System32\dumphive.exe
      Quarantined & Deleted !! : C:\WINDOWS\System32\IEDFix.exe
      Quarantined & Deleted !! : C:\WINDOWS\System32\Process.exe
      Quarantined & Deleted !! : C:\WINDOWS\System32\SrchSTS.exe
      Quarantined & Deleted !! : C:\WINDOWS\System32\tmp.reg
      Quarantined & Deleted !! : C:\WINDOWS\System32\VACFix.exe
      Quarantined & Deleted !! : C:\WINDOWS\System32\VCCLSID.exe
      Quarantined & Deleted !! : C:\WINDOWS\System32\WS2Fix.exe
      Quarantined & Deleted !! : C:\WINDOWS\winstart.bat
      Quarantined & Deleted !! : C:\Documents and Settings\Administrator\Application Data\Search Settings
      Quarantined & Deleted !! : C:\Documents and Settings\Administrator\Application Data\SystemProc

      ==============
      host file OK !
      ==============

      ========
      Registry
      ========

      Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{0E5CBF21-D15F-11D0-8301-00AA005B4383}
      Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{E67C74F4-A00A-4F2C-9FEC-FD9DC004A67F}
      Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}
      Deleted : HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDrives
      Deleted : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Install.exe"
      Deleted : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Setup.exe"
      Deleted : "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}"
      Deleted : "HKLM\Software\Search Settings"
      Deleted : HKCR\CLSID\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}
      Deleted : HKCR\SearchSettings.BHO
      Deleted : HKCR\SearchSettings.BHO.1
      Deleted : HKCU\Software\AvScan
      Deleted : HKCU\SOFTWARE\Microsoft\Handle
      Deleted : HKCU\SOFTWARE\ROUA3O12PW
      Deleted : HKLM\Software\Classes\TypeLib\{937936AF-28CA-4973-B8AE-F250406149A2}
      Deleted : HKLM\Software\Classes\TypeLib\{CD082CCA-086F-4FD8-8FD7-247A0DBBD1CC}
      Deleted : HKLM\Software\Dealio
      Deleted : HKLM\SYSTEM\CurrentControlSet\Enum\Root\Legacy_SSHNAS
      ========
      Services
      =========

      Ndisuio : Start = 3
      EapHost : Start = 2
      Ip6Fw : Start = 2
      SharedAccess : Start = 2
      wuauserv : Start = 2
      wscsvc : Start = 2

      ============
      Disk Cleaned
      ============

      =================
      anti-ver blaster : OK !!
      =================

      ================
      Prefetch cleaned
      ================

      ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
      0
  10. bah un mois apres ....il s'en est passé des choses dans un pc

    desinstalle List_Kill'em

    Télécharge OTL de OLDTimer

    enregistre le sur ton Bureau.

    ▶ Double clic ( pour vista / 7 => clic droit "executer en tant qu'administrateur") sur OTL.exe pour le lancer.

    ▶ Coche les 2 cases Lop et Purity

    ▶ Coche la case devant scan all users

    ▶ règle-le sur "60 Days"

    ▶ dans la moitié gauche , mets tout sur "all"

    ne modifie pas ceci :

    "files created whithin" et "files modified whithin"


    ▶Clic sur Run Scan.

    A la fin du scan, le Bloc-Notes va s'ouvrir avec le rapport (OTL.txt).

    Ce fichier est sur ton Bureau (en général C:\Documents and settings\le_nom_de_ta_session\OTL.txt)

    ▶▶▶ NE LE POSTE PAS SUR LE FORUM

    Pour me le transmettre clique sur ce lien : http://www.cijoint.fr/

    ▶ Clique sur Parcourir et cherche le fichier ci-dessus.

    ▶ Clique sur Ouvrir.

    ▶ Clique sur "Cliquez ici pour déposer le fichier".

    Un lien de cette forme :

    http://www.cijoint.fr/cjlink.php?file=cjge368/cijSKAP5fU.txt

    est ajouté dans la page.

    ▶ Copie ce lien dans ta réponse.

    ▶▶ Tu feras la meme chose avec le "Extra.txt" qui logiquement sera aussi sur ton bureau.
    0
    1. Merci d'être toujours là après tout ce temps... je me demande où tu habites car il semble que l'on ne soit pas sur les mêmes fuseaux horaires :) tu dois être en france?

      Pour OTL.txt
      Le lien à transmettre est http://www.cijoint.fr/cjlink.php?file=cj201004/cij3E075EU.txt

      Et Extras.txt
      Le lien à transmettre est http://www.cijoint.fr/cjlink.php?file=cj201004/cijHTbCwP7.txt

      Merci!
      0
      1. DESACTIVE TON ANTIVIRUS ET TON PAREFEU SI PRESENTS !!!!!(car il est detecté a tort comme infection)

        ▶ Télécharge List_Kill'em et enregistre le sur ton bureau

        double clique ( clic droit "executer en tant qu'administrateur" pour Vista/7 ) sur le raccourci sur ton bureau pour lancer l'installation

        une fois terminée , clic sur "terminer" et le programme se lancera seul

        choisis l'option Search

        un icone blanc et noir va s'afficher sur le bureau , il te servira à relancer le programme par la suite.
        un autre rouge et noir te servira a desinstaller le prog a la fin de la desinfection.

        ▶ laisse travailler l'outil

        à l'apparition de la fenetre blanche , c'est un peu long , c'est normal , le programme n'est pas bloqué.

        un rapport du nom de catchme apparait sur ton bureau , ignore-le,ne le poste pas , , il s'auto supprimera a la fin du scan

        ▶ Poste le contenu du rapport qui s'ouvre aux 100 % du scan à l'ecran "COMPLETED"

        0
        1. est-ce que je pourrai travailler en même temps car j'ai vraiment énormément de boulot à abattre aujourd'hui?
          0
      2. oui
        0
        1. parce que hier pendant que je roulais Kill'Em je ne pouvais ouvrir aucun autre logiciel en même temps...
          0
      3. non c'est pendant la suppression que tu ne peux rien ouvrir

        là on fait une nouvelle recherche

        la version que tu avais est plus qu'obsolete
        0
        1. List'em by g3n-h@ckm@n 1.7.0.4

          User : Administrator (Administrators)
          Update on 09/04/2010 by g3n-h@ckm@n ::::: 15.30
          Start at: 10:56:15 | 2010-04-09

          Intel(R) Pentium(R) 4 CPU 2.53GHz
          Microsoft Windows XP Professional (5.1.2600 32-bit) # Service Pack 3
          Internet Explorer 7.0.5730.13
          Windows Firewall Status : Enabled
          AV : Paladin Antivirus 1.0 [ Enabled | (!) Outdated ]
          AV : AntiVir Desktop 9.0.1.32 [ Enabled | Updated ]
          FW : COMODO Firewall[ Enabled ]3.9

          C:\ -> Local Fixed Disk | 37,21 Go (3,21 Go free) | NTFS
          D:\ -> CD-ROM Disc

          Boot: Normal

          ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running

          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\csrss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\spoolsv.exe
          C:\Program Files\Avira\AntiVir Desktop\sched.exe
          C:\WINDOWS\system32\svchost.exe
          C:\Program Files\Avira\AntiVir Desktop\avguard.exe
          C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
          C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
          C:\WINDOWS\Explorer.EXE
          C:\WINDOWS\BCMSMMSG.exe
          C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb05.exe
          C:\Program Files\QuickTime\qttask.exe
          C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
          C:\Program Files\Logitech\QuickCam\Quickcam.exe
          C:\Program Files\Spyware Doctor\pctsTray.exe
          C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
          C:\WINDOWS\system32\wuauclt.exe
          C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
          C:\WINDOWS\system32\ctfmon.exe
          C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
          C:\Program Files\Messenger\msmsgs.exe
          C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
          c:\program files\logitech\quickcam\lu\lulnchr.exe
          c:\program files\logitech\quickcam\lu\LogitechUpdate.exe
          C:\Program Files\internet explorer\iexplore.exe
          C:\Program Files\Windows Live\Messenger\msnmsgr.exe
          C:\Program Files\Microsoft Office\Office\EXCEL.EXE
          C:\Program Files\List_Kill'em\List_Kill'em.exe
          C:\WINDOWS\system32\cmd.exe
          C:\WINDOWS\system32\wbem\wmiprvse.exe
          C:\Program Files\List_Kill'em\pv.exe

          ======================
          Keys "Run"
          ======================

          [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
          ctfmon.exe REG_SZ C:\WINDOWS\system32\ctfmon.exe
          swg REG_SZ "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
          MSMSGS REG_SZ "C:\Program Files\Messenger\msmsgs.exe" /background

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
          IgfxTray REG_SZ C:\WINDOWS\system32\igfxtray.exe
          HotKeysCmds REG_SZ C:\WINDOWS\system32\hkcmd.exe
          BCMSMMSG REG_SZ BCMSMMSG.exe
          HPDJ Taskbar Utility REG_SZ C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb05.exe
          QuickTime Task REG_SZ "C:\Program Files\QuickTime\qttask.exe" -atboottime
          LogitechCommunicationsManager REG_SZ "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
          LogitechQuickCamRibbon REG_SZ "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
          SearchSettings REG_SZ C:\Program Files\Search Settings\SearchSettings.exe
          Adobe Reader Speed Launcher REG_SZ "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
          Adobe ARM REG_SZ "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
          ISTray REG_SZ "C:\Program Files\Spyware Doctor\pctsTray.exe"
          avgnt REG_SZ "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
          COMODO Internet Security REG_SZ "C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h

          [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]

          [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
          HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce\ApprovedByRegRun2

          =====================
          Other Keys
          =====================
          [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
          dontdisplaylastusername REG_DWORD 0 (0x0)
          legalnoticecaption REG_SZ
          legalnoticetext REG_SZ
          shutdownwithoutlogon REG_DWORD 1 (0x1)
          undockwithoutlogon REG_DWORD 1 (0x1)
          DisableRegistryTools REG_DWORD 0 (0x0)
          HideLegacyLogonScripts REG_DWORD 0 (0x0)
          HideLogoffScripts REG_DWORD 0 (0x0)
          RunLogonScriptSync REG_DWORD 1 (0x1)
          RunStartupScriptSync REG_DWORD 0 (0x0)
          HideStartupScripts REG_DWORD 0 (0x0)

          ===============
          [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
          NoDriveTypeAutoRun REG_DWORD 145 (0x91)

          ===============
          [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
          NoDriveAutoRun REG_DWORD 67108863 (0x3ffffff)
          NoDriveTypeAutoRun REG_DWORD 255 (0xff)
          HonorAutoRunSetting REG_DWORD 1 (0x1)

          ===============
          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]

          ===============

          [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
          AutoRestartShell REG_DWORD 1 (0x1)
          DefaultDomainName REG_SZ DENIS-500860AF8
          DefaultUserName REG_SZ Administrator
          LegalNoticeCaption REG_SZ
          LegalNoticeText REG_SZ
          PowerdownAfterShutdown REG_SZ 0
          ReportBootOk REG_SZ 1
          Shell REG_SZ Explorer.exe
          ShutdownWithoutLogon REG_SZ 0
          System REG_SZ
          Userinit REG_SZ c:\windows\system32\userinit.exe,
          VmApplet REG_SZ rundll32 shell32,Control_RunDLL "sysdm.cpl"
          SfcQuota REG_DWORD -1 (0xffffffff)
          allocatecdroms REG_SZ 0
          allocatedasd REG_SZ 0
          allocatefloppies REG_SZ 0
          cachedlogonscount REG_SZ 10
          forceunlocklogon REG_DWORD 0 (0x0)
          passwordexpirywarning REG_DWORD 14 (0xe)
          scremoveoption REG_SZ 0
          AllowMultipleTSSessions REG_DWORD 1 (0x1)
          UIHost REG_EXPAND_SZ logonui.exe
          LogonType REG_DWORD 1 (0x1)
          Background REG_SZ 0 0 0
          DebugServerCommand REG_SZ no
          SFCDisable REG_DWORD 0 (0x0)
          WinStationsDisabled REG_SZ 0
          HibernationPreviouslyEnabled REG_DWORD 1 (0x1)
          ShowLogonOptions REG_DWORD 0 (0x0)
          AltDefaultUserName REG_SZ Administrator
          AltDefaultDomainName REG_SZ DENIS-500860AF8
          ChangePasswordUseKerberos REG_DWORD 1 (0x1)

          ===============

          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\crypt32chain]
          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cryptnet]
          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cscdll]
          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\dimsntfy]
          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\igfxcui]
          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ScCertProp]
          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Schedule]
          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\sclgntfy]
          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\SensLogn]
          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\termsrv]
          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WgaLogon]
          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wlballoon]

          ===============

          [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
          {AEB6717E-7E19-11d0-97EE-00C04FD91972} REG_SZ

          ===============
          [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
          %windir%\system32\sessmgr.exe REG_SZ %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
          C:\Program Files\Grisoft\AVG7\avginet.exe REG_SZ C:\Program Files\Grisoft\AVG7\avginet.exe:*:Enabled:avginet.exe
          C:\Program Files\Grisoft\AVG7\avgamsvr.exe REG_SZ C:\Program Files\Grisoft\AVG7\avgamsvr.exe:*:Enabled:avgamsvr.exe
          C:\Program Files\Grisoft\AVG7\avgcc.exe REG_SZ C:\Program Files\Grisoft\AVG7\avgcc.exe:*:Enabled:avgcc.exe
          %windir%\Network Diagnostic\xpnetdiag.exe REG_SZ %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
          C:\Program Files\mIRC\mirc.exe REG_SZ C:\Program Files\mIRC\mirc.exe:*:Enabled:mIRC
          C:\Program Files\Marratech\Marratech6.1\bin\Marratech.exe REG_SZ C:\Program Files\Marratech\Marratech6.1\bin\Marratech.exe:*:Enabled:Marratech
          C:\Program Files\Java\jre1.5.0_12\bin\javaw.exe REG_SZ C:\Program Files\Java\jre1.5.0_12\bin\javaw.exe:*:Enabled:Java(TM) 2 Platform Standard Edition binary
          C:\Program Files\Internet Explorer\iexplore.exe REG_SZ C:\Program Files\Internet Explorer\iexplore.exe:*:Enabled:Internet Explorer
          C:\Program Files\Skype\Phone\Skype.exe REG_SZ C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype
          C:\Program Files\Windows Live\Messenger\wlcsdk.exe REG_SZ C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call
          C:\Program Files\Windows Live\Messenger\msnmsgr.exe REG_SZ C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
          %windir%\system32\sessmgr.exe REG_SZ %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
          %windir%\Network Diagnostic\xpnetdiag.exe REG_SZ %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
          C:\Program Files\Windows Live\Messenger\wlcsdk.exe REG_SZ C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call
          C:\Program Files\Windows Live\Messenger\msnmsgr.exe REG_SZ C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger

          ===============
          ActivX controls
          ===============
          [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{0CCA191D-13A6-4E29-B746-314DEE697D83}]
          [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{166B1BCA-3F9C-11CF-8075-444553540000}]
          [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{4F1E5B1A-2A80-42CA-8532-2D05CB959537}]
          [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{6414512B-B978-451D-A0D8-FCFDF33E833C}]
          [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{8AD9C840-044E-11D1-B3E9-00805F499D93}]
          [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}]
          [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0015-0000-0012-ABCDEFFEDCBA}]
          [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}]
          [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}]
          [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{D27CDB6E-AE6D-11CF-96B8-444553540000}]
          [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{E77F23EB-E7AB-4502-8F37-247DBAF1A147}]

          ===============
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\<{12d0ed0d-0ee0-4f90-8827-78cefb8f4988}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{26923b43-4d38-484f-9b9e-de460746276c}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{010527D8-5CAC-E7A8-2083-A1DCF95E419B}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{08B0E5C0-4FCB-11CF-AAA5-00401C608500}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10072CEC-8CC1-11D1-986E-00A0C955B42F}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2179C5D3-EBFF-11CF-B6FD-00AA00B4E220}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{283807B5-2C60-11D0-A31D-00AA00B92C03}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{36f8ec70-c29a-11d1-b5c7-0000f8051515}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{3af36230-a269-11d1-b5bf-0000f8051515}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{3bf42070-b3b1-11d1-b5c5-0000f8051515}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{411EDCF7-755D-414E-A74B-3DCD6583F589}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4278c270-a269-11d1-b5bf-0000f8051515}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA848-CC51-11CF-AAFA-00AA00B6015C}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA855-CC51-11CF-AAFA-00AA00B6015F}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{45ea75a0-a269-11d1-b5bf-0000f8051515}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4f216970-c90c-11d1-b5c7-0000f8051515}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4f645220-306d-11d2-995d-00c04f98bbc9}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5056b317-8d4c-43ee-8543-b9d1e234b8f4}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5A8D6EE0-3E18-11D0-821E-444553540000}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5fd399c0-a70a-11d1-9948-00c04f98bbc9}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{630b1da0-b465-11d1-9948-00c04f98bbc9}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6fab99d0-bab8-11d1-994a-00c04f98bbc9}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4340}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4383}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9381D8F2-0288-11D0-9501-00AA00B911A5}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{B508B3F1-A24A-32C0-B310-85786919EF28}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C9E9A340-D1F1-11D0-821E-444553540600}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CC2A9BA0-3BDD-11D0-821E-444553540000}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CDD7975E-60F8-41d5-8149-19E51D6F71D0}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{DAA94A2A-2A8D-4D3B-9DB8-56FBECED082D}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{de5aed00-a4bf-11d1-9948-00c04f98bbc9}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{E92B03AB-B707-11d2-9CBD-0000F87A369E}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{EF289A85-8E57-408d-BE47-73B55609861A}]

          ==============
          BHO :
          ======
          [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
          [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{22BF413B-C6D2-4d91-82A9-A0F997BA588C}]
          [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]
          [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
          [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
          [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
          [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]

          ===
          DNS
          ===

          HKLM\SYSTEM\CCS\Services\Tcpip\..\{2A3A0E51-019D-4255-AFA6-7A6B724D8B0F}: DhcpNameServer=192.168.10.1
          HKLM\SYSTEM\CS1\Services\Tcpip\..\{2A3A0E51-019D-4255-AFA6-7A6B724D8B0F}: DhcpNameServer=192.168.10.1
          HKLM\SYSTEM\CS2\Services\Tcpip\..\{2A3A0E51-019D-4255-AFA6-7A6B724D8B0F}: DhcpNameServer=192.168.10.1
          HKLM\SYSTEM\CS3\Services\Tcpip\..\{2A3A0E51-019D-4255-AFA6-7A6B724D8B0F}: DhcpNameServer=192.168.10.1
          HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.10.1
          HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.10.1
          HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.10.1
          HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.10.1

          ================
          Internet Explorer :
          ================
          [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
          Start Page REG_SZ https://www.msn.com/fr-fr/?ocid=iehp
          Search Page REG_SZ http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch

          [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
          Start Page REG_SZ https://www.mcn21.org/
          Search Page REG_SZ http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch

          ========
          Services
          ========
          [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services]

          Ndisuio : 0x3 ( OK = 3 )
          EapHost : 0x3 ( OK = 2 )
          SharedAccess : 0x4 ( OK = 2 )
          wuauserv : 0x2 ( OK = 2 )

          =========
          Atapi.sys
          =========

          %%%% HASHDEEP-1.0
          %%%% size,md5,sha256,filename
          ## Invoked from: C:\Program Files\List_Kill'em
          ## C:\> hashdeep.exe C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
          ##
          95360,cdfe4411a69c224bd1d11b2da92dac51,0e6b23a80f171550575bebc56f7500cd87a5cf03b2b9fdc49bc3de96282cd69d,C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
          %%%% HASHDEEP-1.0
          %%%% size,md5,sha256,filename
          ## Invoked from: C:\Program Files\List_Kill'em
          ## C:\> hashdeep.exe C:\WINDOWS\ServicePackFiles\i386\atapi.sys
          ##
          96512,9f3a2f5aa6875c72bf062c712cfa2674,b4df1d2c56a593c6b54de57395e3b51d288f547842893b32b0f59228a0cf70b9,C:\WINDOWS\ServicePackFiles\i386\atapi.sys
          %%%% HASHDEEP-1.0
          %%%% size,md5,sha256,filename
          ## Invoked from: C:\Program Files\List_Kill'em
          ## C:\> hashdeep.exe C:\WINDOWS\system32\drivers\atapi.sys
          ##
          96512,9f3a2f5aa6875c72bf062c712cfa2674,b4df1d2c56a593c6b54de57395e3b51d288f547842893b32b0f59228a0cf70b9,C:\WINDOWS\system32\drivers\atapi.sys
          %%%% HASHDEEP-1.0
          %%%% size,md5,sha256,filename
          ## Invoked from: C:\Program Files\List_Kill'em
          ## C:\> hashdeep.exe C:\WINDOWS\system32\ReinstallBackups\0006\DriverFiles\i386\atapi.sys
          ##
          95360,cdfe4411a69c224bd1d11b2da92dac51,0e6b23a80f171550575bebc56f7500cd87a5cf03b2b9fdc49bc3de96282cd69d,C:\WINDOWS\system32\ReinstallBackups\0006\DriverFiles\i386\atapi.sys

          Référence :
          ==========

          Win 2000_SP2 : ff953a8f08ca3f822127654375786bbe
          Win 2000_SP4 : 8c718aa8c77041b3285d55a0ce980867
          Win XP_32b : a64013e98426e1877cb653685c5c0009
          Win XP_SP2_32b : CDFE4411A69C224BD1D11B2DA92DAC51
          Win XP_SP3_32b : 9F3A2F5AA6875C72BF062C712CFA2674
          Vista_32b : e03e8c99d15d0381e02743c36afc7c6f
          Vista_SP1_32b : 2d9c903dc76a66813d350a562de40ed9
          Vista_SP2_32b : 1F05B78AB91C9075565A9D8A4B880BC4
          Vista_SP2_64b : 1898FAE8E07D97F2F6C2D5326C633FAC
          Windows 7_32b : 80C40F7FDFC376E4C5FEEC28B41C119E
          Windows 7_64b : 02062C0B390B7729EDC9E69C680A6F3C
          Windows 7_32b_Ultimate : 338c86357871c167a96ab976519bf59e

          =======
          Drive :
          =======

          Windows Disk Defragmenter
          Copyright (c) 2001 Microsoft Corp. and Executive Software International, Inc.

          Analysis Report
          37,21 GB Total, 3,21 GB (8%) Free, 13% Fragmented (23% file fragmentation)

          You should defragment this volume.

          ¤¤¤¤¤¤¤¤¤¤ Files/folders :

          Present !! : C:\Documents and Settings\All Users\Application Data\_VOIDkrl32mainweq.dll
          Present !! : C:\Documents and Settings\All Users\Application Data\_VOIDmainqt.dll
          Present !! : C:\Documents and Settings\All Users\Application Data\mswintmp.dat
          Present !! : C:\WINDOWS\System32\_VOID*.*
          Present !! : C:\Documents and Settings\Administrator\Application Data\Search Settings
          Present !! : C:\Documents and Settings\Administrator\Local Settings\Temp\dw.log
          Present !! : C:\Documents and Settings\Administrator\Local Settings\Temp\F.tmp

          ¤¤¤¤¤¤¤¤¤¤ Keys :

          Present !! : HKLM\Software\Microsoft\Windows\CurrentVersion\Run\SearchSettings
          Present !! : "HKLM\SOFTWARE\Paladin Antivirus"
          Present !! : HKCR\secfile
          Present !! : HKCU\SOFTWARE\_VOID
          Present !! : HKLM\SOFTWARE\_VOID
          Present !! : HKLM\SYSTEM\CurrentControlSet\Enum\Root\Legacy_SSHNAS
          Present !! : HKLM\SYSTEM\CurrentControlSet\Services\bcm4sbxp

          ============

          catchme 0.3.1398.3 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
          Rootkit scan 2010-04-09 11:17:49
          Windows 5.1.2600 Service Pack 3 FAT NTAPI

          scanning hidden processes ...

          ? [21488]

          scanning hidden services ...

          scanning hidden autostart entries ...

          scanning hidden files ...

          scan completed successfully
          hidden processes: 1
          hidden services: 0
          hidden files: 0

          Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

          device: opened successfully
          user: MBR read successfully
          called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys atapi.sys hal.dll pciide.sys PCIIDEX.SYS
          kernel: MBR read successfully
          user & kernel MBR OK

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
          FirstRunDisabled REG_DWORD 1 (0x1)
          AntiVirusDisableNotify REG_DWORD 0 (0x0)
          FirewallDisableNotify REG_DWORD 1 (0x1)
          UpdatesDisableNotify REG_DWORD 1 (0x1)
          AntiVirusOverride REG_DWORD 1 (0x1)
          FirewallOverride REG_DWORD 1 (0x1)

          ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

          End of scan : 11:17:51,12
          0
          1. ▶ Relance List_Kill'em(soit en clic droit pour vista/7),avec le raccourci sur ton bureau.
            mais cette fois-ci :

            ▶ choisis l'Option Clean

            ton PC va redemarrer,

            laisse travailler l'outil.

            en fin de scan la fenetre se ferme , et tu as un rapport du nom de Kill'em.txt sur ton bureau ,

            ▶ colle le contenu dans ta reponse
            0
            1. Kill'em by g3n-h@ckm@n 1.7.0.4

              User : Administrator (Administrators)
              Update on 09/04/2010 by g3n-h@ckm@n ::::: 15.30
              Start at: 11:51:25 | 2010-04-09

              Intel(R) Pentium(R) 4 CPU 2.53GHz
              Microsoft Windows XP Professional (5.1.2600 32-bit) # Service Pack 3
              Internet Explorer 7.0.5730.13
              Windows Firewall Status : Enabled
              AV : Paladin Antivirus 1.0 [ Enabled | (!) Outdated ]
              AV : AntiVir Desktop 9.0.1.32 [ Enabled | Updated ]
              FW : COMODO Firewall[ Enabled ]3.9

              C:\ -> Local Fixed Disk | 37,21 Go (3,21 Go free) | NTFS
              D:\ -> CD-ROM Disc

              ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running

              C:\WINDOWS\System32\smss.exe
              C:\WINDOWS\system32\csrss.exe
              C:\WINDOWS\system32\winlogon.exe
              C:\WINDOWS\system32\services.exe
              C:\WINDOWS\system32\lsass.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\system32\svchost.exe
              C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
              C:\WINDOWS\system32\logonui.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\system32\spoolsv.exe
              C:\Program Files\Avira\AntiVir Desktop\sched.exe
              C:\WINDOWS\system32\svchost.exe
              C:\Program Files\Avira\AntiVir Desktop\avguard.exe
              C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
              C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\system32\wuauclt.exe
              C:\WINDOWS\Explorer.EXE
              C:\WINDOWS\system32\cmd.exe
              C:\WINDOWS\system32\wbem\wmiprvse.exe
              C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
              C:\Program Files\List_Kill'em\ERUNT.EXE
              C:\Program Files\List_Kill'em\pv.exe

              Detections :
              ==========

              ¤¤¤¤¤¤¤¤¤¤ Files/folders :

              Quarantined & Deleted !! : C:\Documents and Settings\All Users\Application Data\_VOIDkrl32mainweq.dll
              Quarantined & Deleted !! : C:\Documents and Settings\All Users\Application Data\_VOIDmainqt.dll
              Quarantined & Deleted !! : C:\Documents and Settings\All Users\Application Data\mswintmp.dat

              Quarantined & Deleted !! : C:\WINDOWS\System32\_VOIDfpamtbbobr.dat
              Quarantined & Deleted !! : C:\Documents and Settings\Administrator\Application Data\Search Settings
              Quarantined & Deleted !! : C:\Documents and Settings\Administrator\Local Settings\Temp\dw.log
              Deleted !! : C:\RECYCLER\S-1-5-21-515967899-484061587-1801674531-500\Dc1.lnk
              Deleted !! : C:\RECYCLER\S-1-5-21-515967899-484061587-1801674531-500\Dc10.com
              Deleted !! : C:\RECYCLER\S-1-5-21-515967899-484061587-1801674531-500\Dc11.exe
              Deleted !! : C:\RECYCLER\S-1-5-21-515967899-484061587-1801674531-500\Dc2.lnk
              Deleted !! : C:\RECYCLER\S-1-5-21-515967899-484061587-1801674531-500\Dc3.lnk
              Deleted !! : C:\RECYCLER\S-1-5-21-515967899-484061587-1801674531-500\Dc4.lnk
              Deleted !! : C:\RECYCLER\S-1-5-21-515967899-484061587-1801674531-500\Dc6.exe
              Deleted !! : C:\RECYCLER\S-1-5-21-515967899-484061587-1801674531-500\Dc7.lnk
              Deleted !! : C:\RECYCLER\S-1-5-21-515967899-484061587-1801674531-500\Dc8.lnk
              Deleted !! : C:\RECYCLER\S-1-5-21-515967899-484061587-1801674531-500\Dc9.exe

              ==============
              host file OK !
              ==============

              ========
              Registry
              ========

              Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Run\SearchSettings
              Deleted : "HKLM\SOFTWARE\Paladin Antivirus"
              Deleted : HKCU\SOFTWARE\_VOID
              Deleted : HKLM\SOFTWARE\_VOID
              Deleted : HKLM\SYSTEM\CurrentControlSet\Enum\Root\Legacy_SSHNAS
              Deleted : HKLM\SYSTEM\CurrentControlSet\Services\bcm4sbxp
              =================
              Internet Explorer
              =================

              [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
              Start Page REG_SZ https://www.msn.com/fr-fr/?ocid=iehp
              Local Page REG_SZ C:\WINDOWS\system32\blank.htm
              Default_Search_URL REG_SZ https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              Default_Page_URL REG_SZ https://www.msn.com/fr-fr/?ocid=iehp
              Search Page REG_SZ https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF

              [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
              Start Page REG_SZ https://www.google.com/?gws_rd=ssl
              Local Page REG_SZ C:\WINDOWS\system32\blank.htm
              Search Page REG_SZ http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch

              ===============
              Security Center
              ===============

              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
              FirstRunDisabled REG_DWORD 1 (0x1)
              AntiVirusDisableNotify REG_DWORD 0 (0x0)
              FirewallDisableNotify REG_DWORD 0 (0x0)
              UpdatesDisableNotify REG_DWORD 0 (0x0)
              AntiVirusOverride REG_DWORD 1 (0x1)
              FirewallOverride REG_DWORD 1 (0x1)
              ========
              Services
              =========

              Ndisuio : Start = 3
              EapHost : Start = 2
              Ip6Fw : Start = 2
              SharedAccess : Start = 2
              wuauserv : Start = 2
              wscsvc : Start = 2

              ============
              Disk Cleaned
              ============

              =================
              anti-ver blaster : OK !!
              =================

              ================
              Prefetch cleaned
              ================

              ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
              0
            2. en passant, AntiVir m'a détecté des trojan et autres merdes lors des scan
              je supprime tout à mesure...
              0
          • 1
          • 2