Vista antispyware 2010

Bonjour,

Depuis hier je n'ai plus acces a internet sur mon deuxieme ordi. En effet, vista antispyware 2010 emepeche l'acces a internet. Pourriez vous m'aidez svp

voici le rapport rkill :
*This log file is located at C:\rkill.log.
Please post this only if requested to by the person helping you.
Otherwise you can close this log when you wish.
Ran as boha on 24/02/2010 at 11:31:14.

Processes terminated by Rkill or while it was running:

Rkill completed on 24/02/2010 at 11:31:19.

27 réponses

Résumé de la discussion

Un utilisateur signale une perte d’accès à Internet sur un second ordinateur sous Windows Vista, attribuée à Vista antispyware 2010 qui bloque la connexion. Les échanges privilégient des outils de nettoyage et de sécurité comme Rkill, ATF Cleaner et CCleaner, associant aussi des mises à jour Java et des vérifications disque. Des étapes concrètes décrivent l’exécution des programmes en mode administrateur, la suppression de faux positifs, la vérification et la réparation des erreurs système, puis le redémarrage et le test de connexion. D’autres recommandations orientent vers un pare-feu fiable, la gestion des mots de passe et des paramètres navigateur pour réduire les risques futurs et prévenir de nouveaux blocages.

Bobot (l’IA à votre service)
  1. salut rkill sert a tuer des processus et non eradiquer des infections

    Desactive ton antivirus le temps de la manip ainsi que ton parefeu si présent(car il est detecté a tort comme infection)

    ▶ Télécharge List_Kill'em et enregistre le sur ton bureau

    ▶ Branche clés usb , disques durs externes , mp3 , mp4 , etc..

    double clique ( clic droit "executer en tant qu'administrateur" pour Vista/7 ) sur le raccourci sur ton bureau pour lancer l'installation

    coche la case "creer une icone sur le bureau"

    une fois terminée , clic sur "terminer" et le programme se lancera seul

    choisis la langue puis choisis l'option 1 = Mode Recherche

    ▶ laisse travailler l'outil

    à l'apparition de la fenetre blanche , c'est un peu long , c'est normal , le programme n'est pas bloqué.

    un rapport du nom de catchme apparait sur ton bureau , ignore-le,ne le poste pas , , il s'auto supprimera a la fin du scan

    ▶ Poste le contenu du rapport qui s'ouvre aux 100 % du scan à l'ecran "COMPLETED"

    0
    1. merci de ta reponse aussi rapide
      voila le rapport :

      List'em by g3n-h@ckm@n 1.2.7.0
      User : boha (Administrateurs)
      Update on 23/02/2010 by g3n-h@ckm@n ::::: 16.30
      Start at: 19:34:19 | 24/02/2010
      Contact : https://forums.commentcamarche.net/forum/virus-securite-7
      Intel(R) Core(TM)2 Duo CPU T5670 @ 1.80GHz
      Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6001 32-bit) # Service Pack 1
      Internet Explorer 7.0.6001.18000
      Windows Firewall Status : Disabled
      C:\ -> Disque fixe local | 111,57 Go (65,32 Go free) [ACER] | NTFS
      D:\ -> Disque fixe local | 111,55 Go (111,46 Go free) [DATA] | NTFS
      E:\ -> Disque CD-ROM
      F:\ -> Disque amovible | 242,58 Mo (230,77 Mo free) | FAT
      ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running
      C:\Windows\System32\smss.exe
      C:\Windows\system32\csrss.exe
      C:\Windows\system32\wininit.exe
      C:\Windows\system32\csrss.exe
      C:\Windows\system32\services.exe
      C:\Windows\system32\lsass.exe
      C:\Windows\system32\lsm.exe
      C:\Windows\system32\winlogon.exe
      C:\Windows\system32\svchost.exe
      C:\Windows\system32\svchost.exe
      C:\Windows\System32\svchost.exe
      C:\Windows\System32\svchost.exe
      C:\Windows\System32\svchost.exe
      C:\Windows\system32\svchost.exe
      C:\Windows\system32\SLsvc.exe
      C:\Windows\system32\svchost.exe
      C:\Windows\system32\svchost.exe
      C:\Windows\System32\spoolsv.exe
      C:\Program Files\Avira\AntiVir Desktop\sched.exe
      C:\Windows\system32\svchost.exe
      C:\Program Files\Avira\AntiVir Desktop\avguard.exe
      C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
      C:\Windows\system32\svchost.exe
      C:\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
      C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe
      C:\Acer\Empowering Technology\eNet\eNet Service.exe
      C:\Windows\system32\taskeng.exe
      C:\Windows\system32\FsUsbExService.Exe
      C:\Windows\system32\Dwm.exe
      C:\Windows\Explorer.EXE
      C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
      C:\Program Files\Common Files\LightScribe\LSSrvc.exe
      C:\Acer\Mobility Center\MobilityService.exe
      C:\Windows\system32\taskeng.exe
      C:\Windows\system32\svchost.exe
      C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
      C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
      C:\Windows\system32\svchost.exe
      C:\Windows\System32\svchost.exe
      C:\Program Files\Windows Defender\MSASCui.exe
      C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
      C:\Windows\RtHDVCpl.exe
      C:\Program Files\Synaptics\SynTP\SynTPStart.exe
      C:\Windows\System32\igfxtray.exe
      C:\Windows\System32\hkcmd.exe
      C:\Windows\System32\igfxpers.exe
      C:\Windows\PLFSetL.exe
      C:\Windows\PLFSetI.exe
      C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
      C:\Acer\Empowering Technology\eDataSecurity\x86\eDSLoader.exe
      C:\Windows\system32\SearchIndexer.exe
      C:\Windows\system32\DRIVERS\xaudio.exe
      C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
      C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
      C:\Acer\Empowering Technology\ePower\ePowerSvc.exe
      C:\Windows\system32\wbem\wmiprvse.exe
      C:\Windows\system32\wbem\wmiprvse.exe
      C:\Windows\system32\wbem\unsecapp.exe
      C:\Windows\system32\igfxsrvc.exe
      C:\Users\boha\AppData\Local\Temp\RtkBtMnt.exe
      C:\Program Files\Launch Manager\LManager.exe
      C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
      C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe
      C:\Program Files\Java\jre6\bin\jusched.exe
      C:\Program Files\Windows Sidebar\sidebar.exe
      C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe
      C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
      C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
      C:\Windows\system32\igfxext.exe
      C:\Windows\system32\igfxsrvc.exe
      C:\Acer\Empowering Technology\ENET\ENMTRAY.EXE
      C:\Acer\Empowering Technology\EPOWER\EPOWER_DMC.EXE
      C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE
      C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
      C:\Program Files\Windows Media Player\wmpnetwk.exe
      C:\Windows\system32\wuauclt.exe
      C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
      C:\Windows\system32\WUDFHost.exe
      C:\Program Files\Internet Explorer\ieuser.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe
      C:\Program Files\List_Kill'em\List_Kill'em.scr
      C:\Windows\system32\conime.exe
      C:\Windows\system32\cmd.exe
      C:\Users\boha\AppData\Local\Temp\AD01.tmp\pv.exe
      ======================
      Keys "Run"
      ======================
      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      Sidebar REG_SZ C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
      WindowsWelcomeCenter REG_SZ rundll32.exe oobefldr.dll,ShowWelcomeCenter
      NBJ REG_SZ "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
      WMPNSCFG REG_SZ C:\Program Files\Windows Media Player\WMPNSCFG.exe
      AutoStartNPSAgent REG_SZ C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe
      swg REG_SZ "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
      msnmsgr REG_SZ "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      Windows Defender REG_EXPAND_SZ %ProgramFiles%\Windows Defender\MSASCui.exe -hide
      IAAnotif REG_SZ "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
      RtHDVCpl REG_SZ RtHDVCpl.exe
      SynTPStart REG_SZ C:\Program Files\Synaptics\SynTP\SynTPStart.exe
      Adobe Reader Speed Launcher REG_SZ "c:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
      IgfxTray REG_SZ C:\Windows\system32\igfxtray.exe
      HotKeysCmds REG_SZ C:\Windows\system32\hkcmd.exe
      Persistence REG_SZ C:\Windows\system32\igfxpers.exe
      PLFSetL REG_SZ C:\Windows\PLFSetL.exe
      PLFSetI REG_SZ C:\Windows\PLFSetI.exe
      RemoteControl REG_SZ "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
      LanguageShortcut REG_SZ "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
      eDataSecurity Loader REG_SZ C:\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe
      LManager REG_SZ C:\PROGRA~1\LAUNCH~1\LManager.exe
      WarReg_PopUp REG_SZ C:\Program Files\Acer\WR_PopUp\WarReg_PopUp.exe
      NeroFilterCheck REG_SZ C:\Windows\system32\NeroCheck.exe
      avgnt REG_SZ "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
      Google Quick Search Box REG_SZ "C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe" /autorun
      SunJavaUpdateSched REG_SZ "C:\Program Files\Java\jre6\bin\jusched.exe"

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]
      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
      =====================
      Other Keys
      =====================
      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
      ConsentPromptBehaviorAdmin REG_DWORD 2 (0x2)
      ConsentPromptBehaviorUser REG_DWORD 1 (0x1)
      EnableInstallerDetection REG_DWORD 1 (0x1)
      EnableLUA REG_DWORD 1 (0x1)
      EnableSecureUIAPaths REG_DWORD 1 (0x1)
      EnableVirtualization REG_DWORD 1 (0x1)
      PromptOnSecureDesktop REG_DWORD 1 (0x1)
      ValidateAdminCodeSignatures REG_DWORD 0 (0x0)
      dontdisplaylastusername REG_DWORD 0 (0x0)
      legalnoticecaption REG_SZ
      legalnoticetext REG_SZ
      scforceoption REG_DWORD 0 (0x0)
      shutdownwithoutlogon REG_DWORD 1 (0x1)
      undockwithoutlogon REG_DWORD 1 (0x1)
      FilterAdministratorToken REG_DWORD 0 (0x0)
      EnableUIADesktopToggle REG_DWORD 0 (0x0)
      ===============
      [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
      NoDriveTypeAutoRun REG_DWORD 145 (0x91)
      NoDrives REG_DWORD 0 (0x0)
      ===============
      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
      NoDrives REG_DWORD 0 (0x0)
      ===============
      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
      ===============
      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
      ReportBootOk REG_SZ 1
      Shell REG_SZ Explorer.exe
      Userinit REG_SZ C:\Windows\system32\userinit.exe,
      VmApplet REG_SZ rundll32 shell32,Control_RunDLL "sysdm.cpl"
      AutoRestartShell REG_DWORD 1 (0x1)
      LegalNoticeCaption REG_SZ
      LegalNoticeText REG_SZ
      PowerdownAfterShutdown REG_SZ 0
      ShutdownWithoutLogon REG_SZ 0
      cachedlogonscount REG_SZ 10
      forceunlocklogon REG_DWORD 0 (0x0)
      passwordexpirywarning REG_DWORD 14 (0xe)
      Background REG_SZ 0 0 0
      DebugServerCommand REG_SZ no
      WinStationsDisabled REG_SZ 0
      DisableCAD REG_DWORD 1 (0x1)
      scremoveoption REG_SZ 0
      ShutdownFlags REG_DWORD 40 (0x28)
      SFCDisable REG_DWORD 0 (0x0)
      System REG_SZ
      ===============
      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\igfxcui]
      ===============
      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
      {AEB6717E-7E19-11d0-97EE-00C04FD91972} REG_SZ
      ===============
      [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
      [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
      ===============
      ActivX controls
      ===============
      HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{233C1507-6A77-46A4-9443-F871F945D258}
      HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{67DABFBF-D0AB-41FA-9C46-CC0F21721616}
      HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{8100D56A-5661-482C-BEE8-AFECE305D968}
      HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{8AD9C840-044E-11D1-B3E9-00805F499D93}
      HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
      HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
      HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
      HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{E77F23EB-E7AB-4502-8F37-247DBAF1A147}
      ===============
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{26923b43-4d38-484f-9b9e-de460746276c}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{08B0E5C0-4FCB-11CF-AAA5-00401C608500}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2179C5D3-EBFF-11CF-B6FD-00AA00B4E220}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{3af36230-a269-11d1-b5bf-0000f8051515}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA848-CC51-11CF-AAFA-00AA00B6015C}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA855-CC51-11CF-AAFA-00AA00B6015F}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{45ea75a0-a269-11d1-b5bf-0000f8051515}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4f645220-306d-11d2-995d-00c04f98bbc9}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5fd399c0-a70a-11d1-9948-00c04f98bbc9}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{630b1da0-b465-11d1-9948-00c04f98bbc9}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6fab99d0-bab8-11d1-994a-00c04f98bbc9}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7790769C-0471-11d2-AF11-00C04FA35D02}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7C028AF8-F614-47B3-82DA-BA94E41B1089}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4340}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4383}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9381D8F2-0288-11D0-9501-00AA00B911A5}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C6BAF60B-6E91-453F-BFF9-D3789CFEFCDD}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C9E9A340-D1F1-11D0-821E-444553540600}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CDD7975E-60F8-41d5-8149-19E51D6F71D0}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{D27CDB6E-AE6D-11CF-96B8-444553540000}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{de5aed00-a4bf-11d1-9948-00c04f98bbc9}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{E92B03AB-B707-11d2-9CBD-0000F87A369E}
      ==============
      BHO :
      ======
      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]
      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]
      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{83A2F9B1-01A2-4AA5-87D1-45B6B8505E96}]
      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
      ============
      Recherche DNS
      ============
      HKLM\SYSTEM\CCS\Services\Tcpip\..\{3E7113C7-9540-4C1F-8509-7B8E3EB94765}: DhcpNameServer=192.168.1.1
      HKLM\SYSTEM\CS1\Services\Tcpip\..\{3E7113C7-9540-4C1F-8509-7B8E3EB94765}: DhcpNameServer=192.168.1.1
      HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
      HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
      ================
      Internet Explorer :
      ================
      [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
      Start Page REG_SZ http://www.tropal.net/
      [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
      Start Page REG_SZ http://www.findstuff.biz/home.html
      ========
      Services
      ========
      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services]
      Ndisuio : 0x3 ( OK = 3 )
      EapHost : 0x3 ( OK = 2 )
      Wlansvc : 0x2 ( OK = 2 )
      SharedAccess : 0x2 ( OK = 2 )
      windefend : 0x2 ( OK = 2 )
      wuauserv : 0x2 ( OK = 2 )
      wscsvc : 0x2 ( OK = 2 )
      =========
      Atapi.sys
      =========
      %%%% HASHDEEP-1.0
      %%%% size,md5,sha256,filename
      ## Invoked from: C:\Users\boha\AppData\Local\Temp\AD01.tmp
      ## C:\> hashdeep.exe C:\Windows\ERDNT\cache\atapi.sys
      ##
      21560,2d9c903dc76a66813d350a562de40ed9,82609f01a08c6842e4c17c077bb641c1429c0e6657964b7f2d114035e1bdcbf3,C:\Windows\ERDNT\cache\atapi.sys
      %%%% HASHDEEP-1.0
      %%%% size,md5,sha256,filename
      ## Invoked from: C:\Users\boha\AppData\Local\Temp\AD01.tmp
      ## C:\> hashdeep.exe C:\Windows\SoftwareDistribution\Download\cd2b15b1a90e884578188440a1660b12\x86_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_df23a1261eab99e8\atapi.sys
      ##
      19944,1f05b78ab91c9075565a9d8a4b880bc4,737be9f9376dab0ccdfed93ea6d67f0c432367ea63cd772a453485be769af3bd,C:\Windows\SoftwareDistribution\Download\cd2b15b1a90e884578188440a1660b12\x86_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_df23a1261eab99e8\atapi.sys
      %%%% HASHDEEP-1.0
      %%%% size,md5,sha256,filename
      ## Invoked from: C:\Users\boha\AppData\Local\Temp\AD01.tmp
      ## C:\> hashdeep.exe C:\Windows\System32\drivers\atapi.sys
      ##
      21560,2d9c903dc76a66813d350a562de40ed9,82609f01a08c6842e4c17c077bb641c1429c0e6657964b7f2d114035e1bdcbf3,C:\Windows\System32\drivers\atapi.sys
      %%%% HASHDEEP-1.0
      %%%% size,md5,sha256,filename
      ## Invoked from: C:\Users\boha\AppData\Local\Temp\AD01.tmp
      ## C:\> hashdeep.exe C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys
      ##
      19048,4f4fcb8b6ea06784fb6d475b7ec7300f,6202d85c9a75e3f01f5f94f069c4cd8a2b9295a182301eae5940ec3bc2c1d896,C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys
      %%%% HASHDEEP-1.0
      %%%% size,md5,sha256,filename
      ## Invoked from: C:\Users\boha\AppData\Local\Temp\AD01.tmp
      ## C:\> hashdeep.exe C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_cc18792d\atapi.sys
      ##
      21560,2d9c903dc76a66813d350a562de40ed9,82609f01a08c6842e4c17c077bb641c1429c0e6657964b7f2d114035e1bdcbf3,C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_cc18792d\atapi.sys
      %%%% HASHDEEP-1.0
      %%%% size,md5,sha256,filename
      ## Invoked from: C:\Users\boha\AppData\Local\Temp\AD01.tmp
      ## C:\> hashdeep.exe C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a2189ce9c\atapi.sys
      ##
      21560,2d9c903dc76a66813d350a562de40ed9,82609f01a08c6842e4c17c077bb641c1429c0e6657964b7f2d114035e1bdcbf3,C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a2189ce9c\atapi.sys
      Référence :
      ==========
      Win 2000_SP2 : ff953a8f08ca3f822127654375786bbe
      Win XP_32b : a64013e98426e1877cb653685c5c0009
      Win XP_SP2_32b : CDFE4411A69C224BD1D11B2DA92DAC51
      Win XP_SP3_32b : 9F3A2F5AA6875C72BF062C712CFA2674
      Vista_32b : e03e8c99d15d0381e02743c36afc7c6f
      Vista_SP1_32b : 2d9c903dc76a66813d350a562de40ed9
      Vista_SP2_32b : 1F05B78AB91C9075565A9D8A4B880BC4
      Vista_SP2_64b : 1898FAE8E07D97F2F6C2D5326C633FAC
      Windows 7_32b : 80C40F7FDFC376E4C5FEEC28B41C119E
      Windows 7_64b : 02062C0B390B7729EDC9E69C680A6F3C

      F:\Autorun.inf :
      ----------------
      [AutoRun]
      open=nu.cmd
      shell\open\Command=nu.cmd
      =======
      Drive :
      =======
      Défragmenteur de disque Windows
      Copyright (c) 2006 Microsoft Corp.
      Rapport d'analyse pour le volume C: ACER
      Taille du volume = 112 Go
      Espace libre = 65.34 Go
      Étendue d'espace libre la plus grande = 40.25 Go
      Pourcentage de fragmentation des fichiers = 2 %
      Remarque : sur les volumes NTFS, les fragments de fichiers de plus de 64 Mo ne sont pas inclus dans les statistiques de fragmentation.
      Il n'est pas nécessaire de défragmenter ce volume.
      ¤¤¤¤¤¤¤¤¤¤ Files/folders :
      Present !! : C:\Windows\System32\ACER.exe
      Present !! : C:\Windows\System32\x64
      Present !! : C:\Users\boha\Local Settings\Temp\log.txt
      Present !! : C:\Users\boha\LOCAL Settings\Temp\RtkBtMnt.exe

      ¤¤¤¤¤¤¤¤¤¤ Keys :
      Present !! : HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDrives
      Present !! : HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDrives
      Present !! : HKEY_USERS\S-1-5-21-3959540449-1512332365-2940282886-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDrives
      Present !! : HKCR\CLSID\{9afb8248-617f-460d-9366-d71cdeda3179}
      Present !! : HKCU\SOFTWARE\AppDataLow\software\MyWebSearch
      Present !! : HKLM\Software\Classes\CLSID\{9AFB8248-617F-460D-9366-D71CDEDA3179}
      ============
      catchme 0.3.1398.3 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
      Rootkit scan 2010-02-24 19:54:31
      Windows 6.0.6001 Service Pack 1 NTFS
      scanning hidden processes ...
      scanning hidden services & system hive ...
      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\001f3ad37688]
      "0025e5248c70"=hex:20,c3,9c,38,fb,51,96,4c,66,17,fc,9e,9e,d2,3c,8b
      [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\001f3ad37688]
      "0025e5248c70"=hex:20,c3,9c,38,fb,51,96,4c,66,17,fc,9e,9e,d2,3c,8b
      scanning hidden registry entries ...
      scanning hidden files ...
      scan completed successfully
      hidden processes: 0
      hidden services: 0
      hidden files: 0

      Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
      device: opened successfully
      user: MBR read successfully
      called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll ataport.SYS intelide.sys PCIIDEX.SYS atapi.sys
      kernel: MBR read successfully
      user & kernel MBR OK
      ==========
      Programs
      ==========
      Acer
      Acer Inc
      Activation Assistant for the 2007 Microsoft Office suites
      Adobe
      Ahead
      Anuman Interactive
      Avira
      Broadcom
      Common Files
      CONEXANT
      CyberLink
      desktop.ini
      DIFX
      DivX
      Electronic Arts
      Fichiers communs
      Google
      InstallShield Installation Information
      Intel
      Internet Explorer
      Java
      JRE
      K-Lite Codec Pack
      Launch Manager
      Lavasoft
      LG Electronics
      LimeWire
      List_Kill'em
      Malwarebytes' Anti-Malware
      MarkAny
      Messenger Plus! Live
      Micro Application
      Microsoft
      Microsoft Games
      Microsoft Office
      Microsoft Office Outlook Connector
      Microsoft Silverlight
      Microsoft Small Business
      Microsoft SQL Server
      Microsoft SQL Server Compact Edition
      Microsoft Visual Studio
      Microsoft Works
      Microsoft.NET
      Movie Maker
      MSBuild
      MSECache
      MSXML 4.0
      NewTech Infosystems
      OpenOffice.org 3
      PC Connectivity Solution
      PhotoFiltre
      Realtek
      Reference Assemblies
      Samsung
      Synaptics
      Uninstall Information
      WIDCOMM
      Windows Calendar
      Windows Collaboration
      Windows Defender
      Windows Journal
      Windows Live
      Windows Live SkyDrive
      Windows Mail
      Windows Media Player
      Windows NT
      Windows Photo Gallery
      Windows Sidebar
      WinRAR
      Yahoo!
      ============
      Drive C:
      ============
      $RECYCLE.BIN
      Acer
      autoexec.bat
      Book
      Boot
      bootmgr
      BOOTSECT.BAK
      ComboFix
      config.sys
      Documents and Settings
      Elements
      hiberfil.sys
      Kill'em
      List'em.txt
      MSOCache
      orange.bmp
      pagefile.sys
      Patch.rev
      Patch2.rev
      PDVD.iss
      PerfLogs
      preload.rev
      Program Files
      ProgramData
      Qoobox
      rapport.txt
      rkill.log
      Sounds
      System Volume Information
      UsbFix
      UsbFix.txt
      Users
      Windows

      ¤¤¤¤¤¤¤¤¤¤ Cracks | Keygens | Serials

      ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
      End of scan : 20:07:36,06
      0
      1. ▶ Relance List_Kill'em(soit en clic droit pour vista/7),avec le raccourci sur ton bureau.
        mais cette fois-ci :

        ▶ choisis l'option 2 = Mode Suppression

        laisse travailler l'outil.

        en fin de scan un rapport s'ouvre

        ▶ colle le contenu dans ta reponse
        0
        1. voila le rapport :

          Kill'em by g3n-h@ckm@n 1.2.7.0

          User : boha (Administrateurs)
          Update on 23/02/2010 by g3n-h@ckm@n ::::: 16.30
          Start at: 20:26:08 | 24/02/2010
          Contact : https://forums.commentcamarche.net/forum/virus-securite-7
          Intel(R) Core(TM)2 Duo CPU T5670 @ 1.80GHz
          Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6001 32-bit) # Service Pack 1
          Internet Explorer 7.0.6001.18000
          Windows Firewall Status : Disabled
          C:\ -> Disque fixe local | 111,57 Go (65,32 Go free) [ACER] | NTFS
          D:\ -> Disque fixe local | 111,55 Go (111,46 Go free) [DATA] | NTFS
          E:\ -> Disque CD-ROM

          ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running

          C:\Windows\System32\smss.exe
          C:\Windows\system32\csrss.exe
          C:\Windows\system32\wininit.exe
          C:\Windows\system32\csrss.exe
          C:\Windows\system32\services.exe
          C:\Windows\system32\lsass.exe
          C:\Windows\system32\lsm.exe
          C:\Windows\system32\winlogon.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\System32\svchost.exe
          C:\Windows\System32\svchost.exe
          C:\Windows\System32\svchost.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\system32\SLsvc.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\System32\spoolsv.exe
          C:\Program Files\Avira\AntiVir Desktop\sched.exe
          C:\Windows\system32\svchost.exe
          C:\Program Files\Avira\AntiVir Desktop\avguard.exe
          C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
          C:\Windows\system32\svchost.exe
          C:\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
          C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe
          C:\Acer\Empowering Technology\eNet\eNet Service.exe
          C:\Windows\system32\taskeng.exe
          C:\Windows\system32\FsUsbExService.Exe
          C:\Windows\system32\Dwm.exe
          C:\Windows\Explorer.EXE
          C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
          C:\Program Files\Common Files\LightScribe\LSSrvc.exe
          C:\Acer\Mobility Center\MobilityService.exe
          C:\Windows\system32\taskeng.exe
          C:\Windows\system32\svchost.exe
          C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
          C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\System32\svchost.exe
          C:\Program Files\Windows Defender\MSASCui.exe
          C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
          C:\Windows\RtHDVCpl.exe
          C:\Program Files\Synaptics\SynTP\SynTPStart.exe
          C:\Windows\System32\igfxtray.exe
          C:\Windows\System32\hkcmd.exe
          C:\Windows\System32\igfxpers.exe
          C:\Windows\PLFSetL.exe
          C:\Windows\PLFSetI.exe
          C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
          C:\Acer\Empowering Technology\eDataSecurity\x86\eDSLoader.exe
          C:\Windows\system32\SearchIndexer.exe
          C:\Windows\system32\DRIVERS\xaudio.exe
          C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
          C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
          C:\Acer\Empowering Technology\ePower\ePowerSvc.exe
          C:\Windows\system32\wbem\wmiprvse.exe
          C:\Windows\system32\wbem\wmiprvse.exe
          C:\Windows\system32\wbem\unsecapp.exe
          C:\Windows\system32\igfxsrvc.exe
          C:\Users\boha\AppData\Local\Temp\RtkBtMnt.exe
          C:\Program Files\Launch Manager\LManager.exe
          C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
          C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe
          C:\Program Files\Java\jre6\bin\jusched.exe
          C:\Program Files\Windows Sidebar\sidebar.exe
          C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe
          C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
          C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
          C:\Windows\system32\igfxext.exe
          C:\Windows\system32\igfxsrvc.exe
          C:\Acer\Empowering Technology\ENET\ENMTRAY.EXE
          C:\Acer\Empowering Technology\EPOWER\EPOWER_DMC.EXE
          C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
          C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE
          C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
          C:\Program Files\Windows Media Player\wmpnetwk.exe
          C:\Windows\system32\wuauclt.exe
          C:\Windows\system32\conime.exe
          C:\Windows\system32\taskeng.exe
          C:\Program Files\List_Kill'em\List_Kill'em.scr
          C:\Windows\system32\cmd.exe
          C:\Users\boha\AppData\Local\Temp\F769.tmp\ERUNT.EXE
          C:\Users\boha\AppData\Local\Temp\F769.tmp\pv.exe

          Detections :
          ==========

          ¤¤¤¤¤¤¤¤¤¤ Files/folders :

          Quarantined & Deleted !! : C:\Windows\System32\ACER.exe
          Quarantined & Deleted !! : C:\Windows\system32\x64
          Quarantined & Deleted !! : C:\Users\boha\Local Settings\Temp\log.txt
          Quarantined & Deleted !! : C:\Users\boha\LOCAL Settings\Temp\RtkBtMnt.exe

          ==============
          host file OK !
          ==============
          ========
          Registry
          ========
          Deleted : HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDrives
          Deleted : HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDrives
          Deleted : HKCR\CLSID\{9afb8248-617f-460d-9366-d71cdeda3179}
          Deleted : HKCU\SOFTWARE\AppDataLow\software\MyWebSearch
          ========
          Services
          =========
          Ndisuio : Start = 3
          EapHost : Start = 2
          Wlansvc : Start = 2
          SharedAccess : Start = 2
          windefend : Start = 2
          wuauserv : Start = 2
          wscsvc : Start = 2
          ============
          Disk Cleaned
          ============

          =================
          anti-ver blaster : OK !!
          =================
          ================
          Prefetch cleaned
          ================

          ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
          0
          1. as-tu lancé la suppression avec le clic droit "executer en tant qu'....." ???

            tu te servais d'internet pendant la suppression ?
            0
            1. Quand je clique droit sur le raccourci il n'a pas en tant qu'administrateur, donc j'ai fais un double clique
              0
              1. Quand je clique droit sur le raccourci il n'a pas en tant qu'administrateur, donc j'ai fais un double clique
                0
                1. Quand je clique droit sur le raccourci il n'a pas en tant qu'administrateur,

                  ????????????????????????????????????????????????????????

                  "en tant qu'..... non ?

                  donc j'ai fais un double clique

                  un rapport pour lire ?
                  0
                  1. J'ai relancé l'option 2 en tant qu'administrateur.
                    Je posterai le rapport à la fin

                    Ps:j'ai de nouveau acces a internet
                    0
                    1. J'espere que c'est bon cette fois ci :)

                      User : boha (Administrateurs)
                      Update on 23/02/2010 by g3n-h@ckm@n ::::: 16.30
                      Start at: 21:36:20 | 24/02/2010
                      Contact : https://forums.commentcamarche.net/forum/virus-securite-7
                      Intel(R) Core(TM)2 Duo CPU T5670 @ 1.80GHz
                      Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6001 32-bit) # Service Pack 1
                      Internet Explorer 7.0.6001.18000
                      Windows Firewall Status : Disabled
                      C:\ -> Disque fixe local | 111,57 Go (65,38 Go free) [ACER] | NTFS
                      D:\ -> Disque fixe local | 111,55 Go (111,46 Go free) [DATA] | NTFS
                      E:\ -> Disque CD-ROM

                      ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running

                      C:\Windows\System32\smss.exe
                      C:\Windows\system32\csrss.exe
                      C:\Windows\system32\wininit.exe
                      C:\Windows\system32\csrss.exe
                      C:\Windows\system32\services.exe
                      C:\Windows\system32\lsass.exe
                      C:\Windows\system32\lsm.exe
                      C:\Windows\system32\winlogon.exe
                      C:\Windows\system32\svchost.exe
                      C:\Windows\system32\svchost.exe
                      C:\Windows\System32\svchost.exe
                      C:\Windows\System32\svchost.exe
                      C:\Windows\System32\svchost.exe
                      C:\Windows\system32\svchost.exe
                      C:\Windows\system32\SLsvc.exe
                      C:\Windows\system32\svchost.exe
                      C:\Windows\system32\svchost.exe
                      C:\Windows\System32\spoolsv.exe
                      C:\Program Files\Avira\AntiVir Desktop\sched.exe
                      C:\Windows\system32\svchost.exe
                      C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                      C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
                      C:\Windows\system32\svchost.exe
                      C:\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
                      C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe
                      C:\Acer\Empowering Technology\eNet\eNet Service.exe
                      C:\Windows\system32\taskeng.exe
                      C:\Windows\system32\FsUsbExService.Exe
                      C:\Windows\system32\Dwm.exe
                      C:\Windows\Explorer.EXE
                      C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
                      C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                      C:\Acer\Mobility Center\MobilityService.exe
                      C:\Windows\system32\taskeng.exe
                      C:\Windows\system32\svchost.exe
                      C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
                      C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
                      C:\Windows\system32\svchost.exe
                      C:\Windows\System32\svchost.exe
                      C:\Program Files\Windows Defender\MSASCui.exe
                      C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
                      C:\Windows\RtHDVCpl.exe
                      C:\Program Files\Synaptics\SynTP\SynTPStart.exe
                      C:\Windows\System32\igfxtray.exe
                      C:\Windows\System32\hkcmd.exe
                      C:\Windows\System32\igfxpers.exe
                      C:\Windows\PLFSetL.exe
                      C:\Windows\PLFSetI.exe
                      C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
                      C:\Acer\Empowering Technology\eDataSecurity\x86\eDSLoader.exe
                      C:\Windows\system32\SearchIndexer.exe
                      C:\Windows\system32\DRIVERS\xaudio.exe
                      C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
                      C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
                      C:\Acer\Empowering Technology\ePower\ePowerSvc.exe
                      C:\Windows\system32\wbem\wmiprvse.exe
                      C:\Windows\system32\wbem\wmiprvse.exe
                      C:\Windows\system32\wbem\unsecapp.exe
                      C:\Windows\system32\igfxsrvc.exe
                      C:\Users\boha\AppData\Local\Temp\RtkBtMnt.exe
                      C:\Program Files\Launch Manager\LManager.exe
                      C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
                      C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe
                      C:\Program Files\Java\jre6\bin\jusched.exe
                      C:\Program Files\Windows Sidebar\sidebar.exe
                      C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe
                      C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                      C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
                      C:\Windows\system32\igfxext.exe
                      C:\Windows\system32\igfxsrvc.exe
                      C:\Acer\Empowering Technology\ENET\ENMTRAY.EXE
                      C:\Acer\Empowering Technology\EPOWER\EPOWER_DMC.EXE
                      C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                      C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE
                      C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
                      C:\Program Files\Windows Media Player\wmpnetwk.exe
                      C:\Windows\system32\wuauclt.exe
                      C:\Windows\system32\conime.exe
                      C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
                      C:\Program Files\Internet Explorer\ieuser.exe
                      C:\Windows\system32\SearchProtocolHost.exe
                      C:\Windows\system32\SearchFilterHost.exe
                      C:\Program Files\List_Kill'em\List_Kill'em.scr
                      C:\Windows\system32\cmd.exe
                      C:\Users\boha\AppData\Local\Temp\958D.tmp\ERUNT.EXE
                      C:\Users\boha\AppData\Local\Temp\958D.tmp\pv.exe

                      Detections :
                      ==========

                      ¤¤¤¤¤¤¤¤¤¤ Files/folders :

                      ==============
                      host file OK !
                      ==============
                      ========
                      Registry
                      ========
                      ========
                      Services
                      =========
                      Ndisuio : Start = 3
                      EapHost : Start = 2
                      Wlansvc : Start = 2
                      SharedAccess : Start = 2
                      windefend : Start = 2
                      wuauserv : Start = 2
                      wscsvc : Start = 2
                      ============
                      Disk Cleaned
                      ============

                      =================
                      anti-ver blaster : OK !!
                      =================
                      ================
                      Prefetch cleaned
                      ================

                      ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
                      0
                      1. J'espere que c'est bon cette fois ci :)

                        User : boha (Administrateurs)
                        Update on 23/02/2010 by g3n-h@ckm@n ::::: 16.30
                        Start at: 21:36:20 | 24/02/2010
                        Contact : https://forums.commentcamarche.net/forum/virus-securite-7
                        Intel(R) Core(TM)2 Duo CPU T5670 @ 1.80GHz
                        Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6001 32-bit) # Service Pack 1
                        Internet Explorer 7.0.6001.18000
                        Windows Firewall Status : Disabled
                        C:\ -> Disque fixe local | 111,57 Go (65,38 Go free) [ACER] | NTFS
                        D:\ -> Disque fixe local | 111,55 Go (111,46 Go free) [DATA] | NTFS
                        E:\ -> Disque CD-ROM

                        ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running

                        C:\Windows\System32\smss.exe
                        C:\Windows\system32\csrss.exe
                        C:\Windows\system32\wininit.exe
                        C:\Windows\system32\csrss.exe
                        C:\Windows\system32\services.exe
                        C:\Windows\system32\lsass.exe
                        C:\Windows\system32\lsm.exe
                        C:\Windows\system32\winlogon.exe
                        C:\Windows\system32\svchost.exe
                        C:\Windows\system32\svchost.exe
                        C:\Windows\System32\svchost.exe
                        C:\Windows\System32\svchost.exe
                        C:\Windows\System32\svchost.exe
                        C:\Windows\system32\svchost.exe
                        C:\Windows\system32\SLsvc.exe
                        C:\Windows\system32\svchost.exe
                        C:\Windows\system32\svchost.exe
                        C:\Windows\System32\spoolsv.exe
                        C:\Program Files\Avira\AntiVir Desktop\sched.exe
                        C:\Windows\system32\svchost.exe
                        C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                        C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
                        C:\Windows\system32\svchost.exe
                        C:\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
                        C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe
                        C:\Acer\Empowering Technology\eNet\eNet Service.exe
                        C:\Windows\system32\taskeng.exe
                        C:\Windows\system32\FsUsbExService.Exe
                        C:\Windows\system32\Dwm.exe
                        C:\Windows\Explorer.EXE
                        C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
                        C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                        C:\Acer\Mobility Center\MobilityService.exe
                        C:\Windows\system32\taskeng.exe
                        C:\Windows\system32\svchost.exe
                        C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
                        C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
                        C:\Windows\system32\svchost.exe
                        C:\Windows\System32\svchost.exe
                        C:\Program Files\Windows Defender\MSASCui.exe
                        C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
                        C:\Windows\RtHDVCpl.exe
                        C:\Program Files\Synaptics\SynTP\SynTPStart.exe
                        C:\Windows\System32\igfxtray.exe
                        C:\Windows\System32\hkcmd.exe
                        C:\Windows\System32\igfxpers.exe
                        C:\Windows\PLFSetL.exe
                        C:\Windows\PLFSetI.exe
                        C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
                        C:\Acer\Empowering Technology\eDataSecurity\x86\eDSLoader.exe
                        C:\Windows\system32\SearchIndexer.exe
                        C:\Windows\system32\DRIVERS\xaudio.exe
                        C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
                        C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
                        C:\Acer\Empowering Technology\ePower\ePowerSvc.exe
                        C:\Windows\system32\wbem\wmiprvse.exe
                        C:\Windows\system32\wbem\wmiprvse.exe
                        C:\Windows\system32\wbem\unsecapp.exe
                        C:\Windows\system32\igfxsrvc.exe
                        C:\Users\boha\AppData\Local\Temp\RtkBtMnt.exe
                        C:\Program Files\Launch Manager\LManager.exe
                        C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
                        C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe
                        C:\Program Files\Java\jre6\bin\jusched.exe
                        C:\Program Files\Windows Sidebar\sidebar.exe
                        C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe
                        C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                        C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
                        C:\Windows\system32\igfxext.exe
                        C:\Windows\system32\igfxsrvc.exe
                        C:\Acer\Empowering Technology\ENET\ENMTRAY.EXE
                        C:\Acer\Empowering Technology\EPOWER\EPOWER_DMC.EXE
                        C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                        C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE
                        C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
                        C:\Program Files\Windows Media Player\wmpnetwk.exe
                        C:\Windows\system32\wuauclt.exe
                        C:\Windows\system32\conime.exe
                        C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
                        C:\Program Files\Internet Explorer\ieuser.exe
                        C:\Windows\system32\SearchProtocolHost.exe
                        C:\Windows\system32\SearchFilterHost.exe
                        C:\Program Files\List_Kill'em\List_Kill'em.scr
                        C:\Windows\system32\cmd.exe
                        C:\Users\boha\AppData\Local\Temp\958D.tmp\ERUNT.EXE
                        C:\Users\boha\AppData\Local\Temp\958D.tmp\pv.exe

                        Detections :
                        ==========

                        ¤¤¤¤¤¤¤¤¤¤ Files/folders :

                        ==============
                        host file OK !
                        ==============
                        ========
                        Registry
                        ========
                        ========
                        Services
                        =========
                        Ndisuio : Start = 3
                        EapHost : Start = 2
                        Wlansvc : Start = 2
                        SharedAccess : Start = 2
                        windefend : Start = 2
                        wuauserv : Start = 2
                        wscsvc : Start = 2
                        ============
                        Disk Cleaned
                        ============

                        =================
                        anti-ver blaster : OK !!
                        =================
                        ================
                        Prefetch cleaned
                        ================

                        ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
                        0
                        1. Télécharge OTL de OLDTimer

                          ▶ enregistre le sur ton Bureau.

                          ▶ Double clic ( pour vista / 7 => clic droit "executer en tant qu'administrateur") sur OTL.exe pour le lancer.

                          ▶ Coche les 2 cases Lop et Purity

                          ▶ Coche la case devant scan all users

                          ▶ règle-le sur "60 Days"

                          ▶ dans la colonne de gauche , mets tout sur "all"

                          ne modifie pas ceci :

                          "files created whithin" et "files modified whithin"


                          ▶Clic sur Run Scan.

                          A la fin du scan, le Bloc-Notes va s'ouvrir avec le rapport (OTL.txt).

                          Ce fichier est sur ton Bureau (en général C:\Documents and settings\le_nom_de_ta_session\OTL.txt)

                          ▶▶▶ NE LE POSTE PAS SUR LE FORUM

                          Pour me le transmettre clique sur ce lien : http://www.cijoint.fr/

                          ▶ Clique sur Parcourir et cherche le fichier ci-dessus.

                          ▶ Clique sur Ouvrir.

                          ▶ Clique sur "Cliquez ici pour déposer le fichier".

                          Un lien de cette forme :

                          http://www.cijoint.fr/cjlink.php?file=cjge368/cijSKAP5fU.txt

                          est ajouté dans la page.

                          ▶ Copie ce lien dans ta réponse.

                          ▶▶ Tu feras la meme chose avec le "Extra.txt" qui logiquement sera aussi sur ton bureau.
                          0
                          1. voici les liens :

                            http://www.cijoint.fr/cjlink.php?file=cj201002/cijpNuLWiB.txt

                            http://www.cijoint.fr/cjlink.php?file=cj201002/cijRZGYd7w.txt
                            0
                            1. Bonjour,

                              Que dois je faire maintenant ?
                              0
                              1. ▶ clic droit "executer en tant qu'administrateur" sur OTL.exe pour le lancer.

                                ▶Copie la liste qui se trouve en gras ci-dessous,

                                ▶ colle-la dans la zone sous Customs Scans/Fixes :


                                :processes
                                explorer.exe
                                iexplore.exe
                                firefox.exe
                                msnmsgr.exe
                                Teatimer.exe

                                :OTL
                                O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
                                O3 - HKLM\..\Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - No CLSID value found.
                                IE - HKU\.DEFAULT\..\URLSearchHook: {00A6FAF6-072E-44cf-8957-5838F569A31D} - Reg Error: Key error. File not found
                                IE - HKU\S-1-5-18\..\URLSearchHook: {00A6FAF6-072E-44cf-8957-5838F569A31D} - Reg Error: Key error. File not found
                                O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab (Reg Error: Key error.)
                                O33 - MountPoints2\{34801310-212f-11df-adff-000000000000}\Shell\AutoRun\command - "" = nu.cmd
                                O33 - MountPoints2\{34801310-212f-11df-adff-000000000000}\Shell\open\Command - "" = nu.cmd

                                :Reg
                                [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
                                "Adobe Reader Speed Launcher"=-
                                "LanguageShortcut"=-
                                "NeroFilterCheck"=-
                                "RemoteControl"=-

                                :commands
                                [emptytemp]
                                [start explorer]
                                [reboot]


                                ▶ Clique sur RunFix pour lancer la suppression.

                                ▶ Poste le rapport.
                                0
                                1. Merci de ta reponse, voila le rapport :

                                  All processes killed
                                  ========== PROCESSES ==========
                                  No active process named explorer.exe was found!
                                  No active process named iexplore.exe was found!
                                  No active process named firefox.exe was found!
                                  Process msnmsgr.exe killed successfully!
                                  No active process named Teatimer.exe was found!
                                  ========== OTL ==========
                                  Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}\ deleted successfully.
                                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5C255C8A-E604-49b4-9D64-90988571CECB}\ not found.
                                  Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{0BF43445-2F28-4351-9252-17FE6E806AA0} deleted successfully.
                                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0BF43445-2F28-4351-9252-17FE6E806AA0}\ not found.
                                  Registry value HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\URLSearchHooks\\{00A6FAF6-072E-44cf-8957-5838F569A31D} deleted successfully.
                                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00A6FAF6-072E-44cf-8957-5838F569A31D}\ not found.
                                  Registry value HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\URLSearchHooks\\{00A6FAF6-072E-44cf-8957-5838F569A31D} not found.
                                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00A6FAF6-072E-44cf-8957-5838F569A31D}\ not found.
                                  Starting removal of ActiveX control {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
                                  C:\Windows\Downloaded Program Files\erma.inf moved successfully.
                                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ deleted successfully.
                                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
                                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
                                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
                                  Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{34801310-212f-11df-adff-000000000000}\ deleted successfully.
                                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{34801310-212f-11df-adff-000000000000}\ not found.
                                  File nu.cmd not found.
                                  Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{34801310-212f-11df-adff-000000000000}\ not found.
                                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{34801310-212f-11df-adff-000000000000}\ not found.
                                  File nu.cmd not found.
                                  ========== REGISTRY ==========
                                  Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\Adobe Reader Speed Launcher deleted successfully.
                                  Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\LanguageShortcut deleted successfully.
                                  Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\NeroFilterCheck deleted successfully.
                                  Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\RemoteControl deleted successfully.
                                  ========== COMMANDS ==========

                                  [EMPTYTEMP]

                                  User: All Users

                                  User: boha
                                  ->Temp folder emptied: 442991 bytes
                                  ->Temporary Internet Files folder emptied: 24631984 bytes
                                  ->Java cache emptied: 12118723 bytes

                                  User: Default
                                  ->Temp folder emptied: 0 bytes
                                  ->Temporary Internet Files folder emptied: 67 bytes

                                  User: Default User
                                  ->Temp folder emptied: 0 bytes
                                  ->Temporary Internet Files folder emptied: 0 bytes

                                  User: Public
                                  ->Temp folder emptied: 0 bytes

                                  User: sarah
                                  ->Temp folder emptied: 0 bytes
                                  ->Temporary Internet Files folder emptied: 5229730 bytes
                                  ->Java cache emptied: 38069160 bytes

                                  %systemdrive% .tmp files removed: 0 bytes
                                  %systemroot% .tmp files removed: 0 bytes
                                  %systemroot%\System32 .tmp files removed: 0 bytes
                                  %systemroot%\System32\drivers .tmp files removed: 0 bytes
                                  Windows Temp folder emptied: 192 bytes
                                  RecycleBin emptied: 0 bytes

                                  Total Files Cleaned = 77,00 mb

                                  OTL by OldTimer - Version 3.1.30.1 log created on 02252010_192354
                                  Files\Folders moved on Reboot...
                                  Registry entries deleted on Reboot...
                                  0
                                  1. Imprime ces instructions car il faudra fermer toutes les fenêtres et applications lors de l'installation et de l'analyse.

                                    ▶ Télécharge :

                                    Malwarebytes

                                    ou :

                                    Malwarebytes

                                    ▶ Installe le ( choisis bien "francais" ; ne modifie pas les paramètres d'installe ) et mets le à jour .

                                    (NB : Si tu as un message d'erreur t'indiquant qu'il te manque "COMCTL32.OCX" lors de l'installe, alors télécharge le ici : COMCTL32.OCX

                                    ▶ Potasses le Tuto pour te familiariser avec le prg :

                                    ( cela dit, il est très simple d'utilisation ).

                                    relance malwarebytes en suivant scrupuleusement ces consignes :

                                    ! Déconnecte toi et ferme toutes applications en cours !

                                    ▶ Lance Malwarebyte's .

                                    Fais un examen dit "Complet" .

                                    ▶ Laisse le programme travailler ( et ne rien faire d'autre avec le PC durant le scan ).
                                    ▶ à la fin tu cliques sur "résultat" .
                                    ▶ Vérifie que tous les objets infectés soient validés, puis clique sur " suppression " .

                                    ▶ Note : si il faut redémarrer ton PC pour finir le nettoyage, fais le !

                                    ▶ Poste le rapport sauvegardé après la suppression des objets infectés (dans l'onglet "rapport/log"de Malwarebytes, le dernier en date)

                                    0
                                    1. voila le rapport :

                                      Malwarebytes' Anti-Malware 1.44
                                      Version de la base de données: 3792
                                      Windows 6.0.6001 Service Pack 1
                                      Internet Explorer 7.0.6001.18000
                                      25/02/2010 22:34:52
                                      mbam-log-2010-02-25 (22-34-52).txt
                                      Type de recherche: Examen complet (C:\|D:\|)
                                      Eléments examinés: 219441
                                      Temps écoulé: 1 hour(s), 21 minute(s), 48 second(s)
                                      Processus mémoire infecté(s): 0
                                      Module(s) mémoire infecté(s): 0
                                      Clé(s) du Registre infectée(s): 0
                                      Valeur(s) du Registre infectée(s): 0
                                      Elément(s) de données du Registre infecté(s): 0
                                      Dossier(s) infecté(s): 0
                                      Fichier(s) infecté(s): 0
                                      Processus mémoire infecté(s):
                                      (Aucun élément nuisible détecté)
                                      Module(s) mémoire infecté(s):
                                      (Aucun élément nuisible détecté)
                                      Clé(s) du Registre infectée(s):
                                      (Aucun élément nuisible détecté)
                                      Valeur(s) du Registre infectée(s):
                                      (Aucun élément nuisible détecté)
                                      Elément(s) de données du Registre infecté(s):
                                      (Aucun élément nuisible détecté)
                                      Dossier(s) infecté(s):
                                      (Aucun élément nuisible détecté)
                                      Fichier(s) infecté(s):
                                      (Aucun élément nuisible détecté)
                                      0
                                      1. je pense plus que tu aies de soucis.....on peut passer au menage ?
                                        0
                                        • 1
                                        • 2