Virus backdoor.bot sous xp

Résolu
Bonjour,
J'ai cliqué comme un naze sur le lien d'un pote sur messenger et j'ai attrapé un virus (backdoor.bot)

Voici le Rapport hijackthis :

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:01:47, on 04/03/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16981)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Caphyon\Advanced Web Ranking\AWRServer.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\msnmgr.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe
C:\Program Files\EeePC\ACPI\AsEPCMon.exe
C:\Program Files\EeePC\ACPI\AsTray.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\ASUS\Eee Docking\Eee Docking.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\igfxext.exe
C:\Program Files\ASUS\EeePC\Super Hybrid Engine\SuperHybridEngine.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Mike\Mes documents\Téléchargements\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://runonce.msn.com/runonce3.aspx
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\msnmgr.exe,
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SynAsusAcpi] C:\Program Files\Synaptics\SynTP\SynAsusAcpi.exe
O4 - HKLM\..\Run: [AsusACPIServer] C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe
O4 - HKLM\..\Run: [AsusEPCMonitor] C:\Program Files\EeePC\ACPI\AsEPCMon.exe
O4 - HKLM\..\Run: [AsusTray] C:\Program Files\EeePC\ACPI\AsTray.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [AdobeCS4ServiceManager] "C:\Program Files\Fichiers communs\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [sysconfig32] C:\WINDOWS\system32\sysconfig32.exe
O4 - HKCU\..\Run: [Eee Docking] C:\Program Files\ASUS\Eee Docking\Eee Docking.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: SuperHybridEngine.lnk = ?
O4 - Global Startup: BTTray.lnk = ?
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Envoyer au périphérique &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Envoyer à Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\Aibelive\VOICEC~1\SKYPE4~1.DLL
O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Advanced Web Ranking Server (AWRServer) - Caphyon - C:\Program Files\Caphyon\Advanced Web Ranking\AWRServer.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

--
End of file - 9330 bytes

Merci de m'aider svp

Mikemorrison
Configuration: Windows XP / Firefox 3.5.8

19 réponses

  1. Contributeur sécurité
    Salut :

    Desactive ton antivirus le temps de la manip ainsi que ton parefeu si présent(car il est detecté a tort comme infection)

    Télécharge et installe List&Kill'em et enregistre le sur ton bureau

    http://sd-1.archive-host.com/membres/up/829108531491024/List_Killem_Install.exe

    Branche clés usb , disques durs externes , mp3 , mp4 , etc..

    double clique ( clic droit "exécuter en tant qu'administrateur" pour Vista/7 ) sur le raccourci sur ton bureau pour lancer l'installation

    coche la case "créer une icône sur le bureau"

    une fois terminée , clic sur "terminer" et le programme se lancera seul

    choisis la langue puis choisis l'option 1 = Mode Recherche

    laisse travailler l'outil

    à l'apparition de la fenêtre blanche , c'est un peu long , c'est normal , le programme n'est pas bloqué.

    un rapport du nom de catchme apparait sur ton bureau , ignore-le,ne le poste pas , mais ne le supprime pas pour l instant, le scan n'est pas fini.

    Poste le contenu du rapport qui s'ouvre aux 100 % du scan à l'écran "COMPLETED"
    0
    1. hello !
      voici le rapport !

      List'em by g3n-h@ckm@n 1.2.8.5

      User : Mike (Administrateurs)
      Update on 03/03/2010 by g3n-h@ckm@n ::::: 18.30
      Start at: 17:34:40 | 04/03/2010
      Contact : https://forums.commentcamarche.net/forum/virus-securite-7

      Intel(R) Atom(TM) CPU N280 @ 1.66GHz
      Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
      Internet Explorer 7.0.5730.13
      Windows Firewall Status : Enabled
      AV : AntiVir Desktop 9.0.1.32 [ (!) Disabled | Updated ]

      C:\ -> Disque fixe local | 149,05 Go (125,23 Go free) | NTFS
      D:\ -> Disque CD-ROM | 5,46 Mo (0 Mo free) [U3 System] | CDFS
      E:\ -> Disque amovible | 1,9 Go (1,56 Go free) | FAT
      F:\ -> Disque fixe local | 931,28 Go (631,56 Go free) [My Book] | FAT32

      Boot: Normal

      ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running

      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\csrss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Avira\AntiVir Desktop\sched.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\Avira\AntiVir Desktop\avguard.exe
      C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      C:\Program Files\Caphyon\Advanced Web Ranking\AWRServer.exe
      C:\Program Files\Bonjour\mDNSResponder.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\msnmgr.exe
      C:\WINDOWS\system32\igfxtray.exe
      C:\WINDOWS\system32\hkcmd.exe
      C:\WINDOWS\RTHDCPL.EXE
      C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      C:\WINDOWS\system32\igfxsrvc.exe
      C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe
      C:\Program Files\EeePC\ACPI\AsEPCMon.exe
      C:\Program Files\EeePC\ACPI\AsTray.exe
      C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
      C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
      C:\Program Files\iTunes\iTunesHelper.exe
      C:\Program Files\ASUS\Eee Docking\Eee Docking.exe
      C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\WINDOWS\system32\igfxext.exe
      C:\Program Files\ASUS\EeePC\Super Hybrid Engine\SuperHybridEngine.exe
      C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
      C:\Program Files\iPod\bin\iPodService.exe
      C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
      C:\WINDOWS\System32\alg.exe
      C:\Program Files\Mozilla Firefox\firefox.exe
      C:\Documents and Settings\Mike\Mes documents\Téléchargements\HiJackThis.exe
      C:\WINDOWS\system32\wscntfy.exe
      C:\Documents and Settings\Mike\Application Data\U3\0000184CF4711AE6\LaunchPad.exe
      C:\Program Files\List_Kill'em\List_Kill'em.scr
      C:\WINDOWS\system32\cmd.exe
      C:\WINDOWS\system32\wbem\wmiprvse.exe
      C:\Documents and Settings\Mike\Local Settings\Temp\9D.tmp\pv.exe

      ======================
      Keys "Run"
      ======================
      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      Eee Docking REG_SZ C:\Program Files\ASUS\Eee Docking\Eee Docking.exe
      ctfmon.exe REG_SZ C:\WINDOWS\system32\ctfmon.exe
      HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run\AdobeUpdater

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      IgfxTray REG_SZ C:\WINDOWS\system32\igfxtray.exe
      HotKeysCmds REG_SZ C:\WINDOWS\system32\hkcmd.exe
      Persistence REG_SZ C:\WINDOWS\system32\igfxpers.exe
      RTHDCPL REG_SZ RTHDCPL.EXE
      SynTPEnh REG_SZ C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      SynAsusAcpi REG_SZ C:\Program Files\Synaptics\SynTP\SynAsusAcpi.exe
      AsusACPIServer REG_SZ C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe
      AsusEPCMonitor REG_SZ C:\Program Files\EeePC\ACPI\AsEPCMon.exe
      AsusTray REG_SZ C:\Program Files\EeePC\ACPI\AsTray.exe
      GrooveMonitor REG_SZ "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
      AdobeCS4ServiceManager REG_SZ "C:\Program Files\Fichiers communs\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
      avgnt REG_SZ "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
      Adobe Reader Speed Launcher REG_SZ "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
      Adobe ARM REG_SZ "C:\Program Files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe"
      QuickTime Task REG_SZ "C:\Program Files\QuickTime\QTTask.exe" -atboottime
      iTunesHelper REG_SZ "C:\Program Files\iTunes\iTunesHelper.exe"
      Malwarebytes Anti-Malware (reboot) REG_SZ "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]

      =====================
      Other Keys
      =====================
      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
      dontdisplaylastusername REG_DWORD 0 (0x0)
      legalnoticecaption REG_SZ
      legalnoticetext REG_SZ
      shutdownwithoutlogon REG_DWORD 1 (0x1)
      undockwithoutlogon REG_DWORD 1 (0x1)

      ===============
      [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
      NoDriveTypeAutoRun REG_DWORD 145 (0x91)

      ===============
      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
      HonorAutoRunSetting REG_DWORD 1 (0x1)

      ===============
      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
      AppInit_DLLS REG_SZ

      ===============
      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
      AutoRestartShell REG_DWORD 1 (0x1)
      DefaultDomainName REG_SZ WINXP
      DefaultUserName REG_SZ Mike
      LegalNoticeCaption REG_SZ
      LegalNoticeText REG_SZ
      PowerdownAfterShutdown REG_SZ 0
      ReportBootOk REG_SZ 1
      Shell REG_SZ Explorer.exe
      ShutdownWithoutLogon REG_SZ 0
      System REG_SZ
      Userinit REG_SZ C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\msnmgr.exe,
      VmApplet REG_SZ rundll32 shell32,Control_RunDLL "sysdm.cpl"
      SfcQuota REG_DWORD -1 (0xffffffff)
      allocatecdroms REG_SZ 0
      allocatedasd REG_SZ 0
      allocatefloppies REG_SZ 0
      cachedlogonscount REG_SZ 10
      forceunlocklogon REG_DWORD 0 (0x0)
      passwordexpirywarning REG_DWORD 14 (0xe)
      scremoveoption REG_SZ 0
      AllowMultipleTSSessions REG_DWORD 1 (0x1)
      UIHost REG_EXPAND_SZ logonui.exe
      LogonType REG_DWORD 1 (0x1)
      Background REG_SZ 0 0 0
      DebugServerCommand REG_SZ no
      SFCDisable REG_DWORD 0 (0x0)
      WinStationsDisabled REG_SZ 0
      DefaultPassword REG_SZ
      HibernationPreviouslyEnabled REG_DWORD 1 (0x1)
      ShowLogonOptions REG_DWORD 0 (0x0)
      AltDefaultUserName REG_SZ Mike
      AltDefaultDomainName REG_SZ WINXP

      ===============
      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\crypt32chain]
      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cryptnet]
      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cscdll]
      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\dimsntfy]
      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\igfxcui]
      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ScCertProp]
      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Schedule]
      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\sclgntfy]
      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\SensLogn]
      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\termsrv]
      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WgaLogon]
      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wlballoon]

      ===============
      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
      {AEB6717E-7E19-11d0-97EE-00C04FD91972} REG_SZ
      {B5A7F190-DDA6-4420-B3BA-52453494E6CD} REG_SZ Groove GFS Stub Execution Hook

      ===============
      [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
      %windir%\Network Diagnostic\xpnetdiag.exe REG_SZ %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
      %windir%\system32\sessmgr.exe REG_SZ %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
      C:\Program Files\Windows Live\Messenger\wlcsdk.exe REG_SZ C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call
      C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe REG_SZ C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync
      C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE REG_SZ C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote
      C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe REG_SZ C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger
      C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE REG_SZ C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook
      C:\Program Files\Microsoft Office\Office12\GROOVE.EXE REG_SZ C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove
      C:\Program Files\Fichiers communs\Adobe\CS4ServiceManager\CS4ServiceManager.exe REG_SZ C:\Program Files\Fichiers communs\Adobe\CS4ServiceManager\CS4ServiceManager.exe:*:Enabled:Adobe CSI CS4
      C:\Program Files\Messenger\msmsgs.exe REG_SZ C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger
      C:\Program Files\Windows Live\Messenger\msnmsgr.exe REG_SZ C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger
      C:\Program Files\Caphyon\Advanced Web Ranking\AdvancedWebRanking.exe REG_SZ C:\Program Files\Caphyon\Advanced Web Ranking\AdvancedWebRanking.exe:*:Enabled:Advanced Web Ranking
      C:\Program Files\Caphyon\Advanced Web Ranking\AdvancedLinkManager.exe REG_SZ C:\Program Files\Caphyon\Advanced Web Ranking\AdvancedLinkManager.exe:*:Enabled:Advanced Link Manager
      C:\Program Files\Caphyon\Advanced Web Ranking\AWRServer.exe REG_SZ C:\Program Files\Caphyon\Advanced Web Ranking\AWRServer.exe:*:Enabled:AWR Server
      C:\Documents and Settings\Mike\Local Settings\Temp\7zS50D2\setup\HPZnui01.exe REG_SZ C:\Documents and Settings\Mike\Local Settings\Temp\7zS50D2\setup\HPZnui01.exe:*:Enabled:hpznui01.exe
      C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe REG_SZ C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe:*:Enabled:hpiscnapp.exe
      C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe REG_SZ C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe
      C:\Program Files\Bonjour\mDNSResponder.exe REG_SZ C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour
      C:\Program Files\iTunes\iTunes.exe REG_SZ C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes
      C:\Program Files\Skype\Phone\Skype.exe REG_SZ C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype
      C:\Documents and Settings\Mike\Mes documents\Téléchargements\PIC01842010-JPG-www-facebook-com.scr REG_SZ C:\Documents and Settings\Mike\Mes documents\Téléchargements\PIC01842010-JPG-www-facebook-com.scr:*:Enabled:Userinit

      [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
      %windir%\Network Diagnostic\xpnetdiag.exe REG_SZ %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
      %windir%\system32\sessmgr.exe REG_SZ %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
      C:\Program Files\Windows Live\Messenger\wlcsdk.exe REG_SZ C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call
      C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe REG_SZ C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync
      C:\Program Files\Windows Live\Messenger\msnmsgr.exe REG_SZ C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger

      ===============
      ActivX controls
      ===============

      ===============
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\<{12d0ed0d-0ee0-4f90-8827-78cefb8f4988}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{26923b43-4d38-484f-9b9e-de460746276c}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10072CEC-8CC1-11D1-986E-00A0C955B42F}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2179C5D3-EBFF-11CF-B6FD-00AA00B4E220}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{283807B5-2C60-11D0-A31D-00AA00B92C03}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{36f8ec70-c29a-11d1-b5c7-0000f8051515}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{3af36230-a269-11d1-b5bf-0000f8051515}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{3bf42070-b3b1-11d1-b5c5-0000f8051515}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4278c270-a269-11d1-b5bf-0000f8051515}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA848-CC51-11CF-AAFA-00AA00B6015C}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA855-CC51-11CF-AAFA-00AA00B6015F}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{45ea75a0-a269-11d1-b5bf-0000f8051515}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4f216970-c90c-11d1-b5c7-0000f8051515}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4f645220-306d-11d2-995d-00c04f98bbc9}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5945c046-1e7d-11d1-bc44-00c04fd912be}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5A8D6EE0-3E18-11D0-821E-444553540000}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5fd399c0-a70a-11d1-9948-00c04f98bbc9}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{630b1da0-b465-11d1-9948-00c04f98bbc9}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6fab99d0-bab8-11d1-994a-00c04f98bbc9}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{73fa19d0-2d75-11d2-995d-00c04f98bbc9}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7790769C-0471-11d2-AF11-00C04FA35D02}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4340}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4383}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9381D8F2-0288-11D0-9501-00AA00B911A5}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{ACC563BC-4266-43f0-B6ED-9D38C4202C7E}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C9E9A340-D1F1-11D0-821E-444553540600}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CC2A9BA0-3BDD-11D0-821E-444553540000}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CDD7975E-60F8-41d5-8149-19E51D6F71D0}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{D27CDB6E-AE6D-11cf-96B8-444553540000}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{de5aed00-a4bf-11d1-9948-00c04f98bbc9}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{E5D12C4E-7B4F-11D3-B5C9-0050045C3C96}
      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{E92B03AB-B707-11d2-9CBD-0000F87A369E}

      ==============
      BHO :
      ======
      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{22BF413B-C6D2-4d91-82A9-A0F997BA588C}]
      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]
      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10}]

      ===
      DNS
      ===

      HKLM\SYSTEM\CCS\Services\Tcpip\..\{A6653D0E-2DE4-403E-885F-4EE32152699C}: DhcpNameServer=192.168.1.254
      HKLM\SYSTEM\CS1\Services\Tcpip\..\{A6653D0E-2DE4-403E-885F-4EE32152699C}: DhcpNameServer=192.168.1.254
      HKLM\SYSTEM\CS2\Services\Tcpip\..\{A6653D0E-2DE4-403E-885F-4EE32152699C}: DhcpNameServer=192.168.1.254
      HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.254
      HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.254
      HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.254

      ================
      Internet Explorer :
      ================
      [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
      Start Page REG_SZ https://www.msn.com/fr-fr/?ocid=iehp

      [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
      Start Page REG_SZ https://www.google.fr/?gws_rd=ssl

      ========
      Services
      ========
      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services]

      Ndisuio : 0x3 ( OK = 3 )
      EapHost : 0x3 ( OK = 2 )
      SharedAccess : 0x2 ( OK = 2 )
      wuauserv : 0x2 ( OK = 2 )

      =========
      Atapi.sys
      =========

      %%%% HASHDEEP-1.0
      %%%% size,md5,sha256,filename
      ## Invoked from: C:\Documents and Settings\Mike\Local Settings\Temp\9D.tmp
      ## C:\> hashdeep.exe C:\WINDOWS\system32\dllcache\atapi.sys
      ##
      96512,9f3a2f5aa6875c72bf062c712cfa2674,b4df1d2c56a593c6b54de57395e3b51d288f547842893b32b0f59228a0cf70b9,C:\WINDOWS\system32\dllcache\atapi.sys
      %%%% HASHDEEP-1.0
      %%%% size,md5,sha256,filename
      ## Invoked from: C:\Documents and Settings\Mike\Local Settings\Temp\9D.tmp
      ## C:\> hashdeep.exe C:\WINDOWS\system32\drivers\atapi.sys
      ##
      96512,9f3a2f5aa6875c72bf062c712cfa2674,b4df1d2c56a593c6b54de57395e3b51d288f547842893b32b0f59228a0cf70b9,C:\WINDOWS\system32\drivers\atapi.sys
      %%%% HASHDEEP-1.0
      %%%% size,md5,sha256,filename
      ## Invoked from: C:\Documents and Settings\Mike\Local Settings\Temp\9D.tmp
      ## C:\> hashdeep.exe C:\WINDOWS\system32\ReinstallBackups\0005\DriverFiles\i386\atapi.sys
      ##
      96512,9f3a2f5aa6875c72bf062c712cfa2674,b4df1d2c56a593c6b54de57395e3b51d288f547842893b32b0f59228a0cf70b9,C:\WINDOWS\system32\ReinstallBackups\0005\DriverFiles\i386\atapi.sys

      Référence :
      ==========

      Win 2000_SP2 : ff953a8f08ca3f822127654375786bbe
      Win XP_32b : a64013e98426e1877cb653685c5c0009
      Win XP_SP2_32b : CDFE4411A69C224BD1D11B2DA92DAC51
      Win XP_SP3_32b : 9F3A2F5AA6875C72BF062C712CFA2674
      Vista_32b : e03e8c99d15d0381e02743c36afc7c6f
      Vista_SP1_32b : 2d9c903dc76a66813d350a562de40ed9
      Vista_SP2_32b : 1F05B78AB91C9075565A9D8A4B880BC4
      Vista_SP2_64b : 1898FAE8E07D97F2F6C2D5326C633FAC
      Windows 7_32b : 80C40F7FDFC376E4C5FEEC28B41C119E
      Windows 7_64b : 02062C0B390B7729EDC9E69C680A6F3C

      =======
      Drive :
      =======

      D‚fragmenteur de disque Windows
      Copyright (c) 2001 Microsoft Corp. et Executive Software International Inc.

      Rapport d'analyse
      149 Go total, 125 Go libre (84%), 20% fragment‚ (fragmentation du fichier 40%)

      Vous devriez d‚fragmenter ce volume.

      ¤¤¤¤¤¤¤¤¤¤ Files/folders :

      Present !! : C:\WINDOWS\MsnMgr.exe
      Present !! : C:\WINDOWS\System32\sysconfig32.exe
      Present !! : C:\Documents and Settings\Mike\Local Settings\Temp\afl.log
      Present !! : C:\Documents and Settings\Mike\Local Settings\Temp\alm.log
      Present !! : C:\Documents and Settings\Mike\Local Settings\Temp\amt.log
      Present !! : C:\Documents and Settings\Mike\Local Settings\Temp\dw.log
      Present !! : C:\Documents and Settings\Mike\LOCAL Settings\Temp\AdobeUpdater12345.exe
      Present !! : C:\Documents and Settings\Mike\LOCAL Settings\Temp\converter.exe
      Present !! : C:\Documents and Settings\Mike\LOCAL Settings\Temp\firefoxjre_exe.exe
      Present !! : C:\Documents and Settings\Mike\LOCAL Settings\Temp\FP_PL_PFS_INSTALLER.exe
      Present !! : C:\Documents and Settings\Mike\LOCAL Settings\Temp\patch57617.exe
      Present !! : C:\Documents and Settings\Mike\LOCAL Settings\Temp\patch6506.exe
      Present !! : C:\Documents and Settings\Mike\LOCAL Settings\Temp\patch7474586251835770292.exe
      Present !! : C:\Documents and Settings\Mike\LOCAL Settings\Temp\SIntf16.dll
      Present !! : C:\Documents and Settings\Mike\LOCAL Settings\Temp\SIntf32.dll
      Present !! : C:\Documents and Settings\Mike\LOCAL Settings\Temp\SIntfNT.dll

      ¤¤¤¤¤¤¤¤¤¤ Keys :

      Present !! : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Install.exe"
      Present !! : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Setup.exe"
      Present !! : HKLM\Software\Classes\TypeLib\{937936AF-28CA-4973-B8AE-F250406149A2}

      ============

      catchme 0.3.1398.3 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
      Rootkit scan 2010-03-04 17:45:46
      Windows 5.1.2600 Service Pack 3 NTFS

      scanning hidden processes ...

      scanning hidden services & system hive ...

      scanning hidden registry entries ...

      scanning hidden files ...

      scan completed successfully
      hidden processes: 0
      hidden services: 0
      hidden files: 0

      Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

      device: opened successfully
      user: MBR read successfully
      called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll iaStor.sys
      kernel: MBR read successfully
      user & kernel MBR OK

      ¤¤¤¤¤¤¤¤¤¤ Cracks | Keygens | Serials

      ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

      End of scan : 17:55:56,85
      0
      1. Contributeur sécurité
        ▶ Relance List&Kill'em(soit en clic droit pour vista),avec le raccourci sur ton bureau.
        mais cette fois-ci :

        ▶ choisis l'option 2 = Mode Suppression

        laisse travailler l'outil.

        en fin de scan un rapport s'ouvre

        ▶ colle le contenu dans ta réponse

        ensuite :

        ▶ Relance List&Kill'em(soit en clic droit pour vista),avec le raccourci sur ton bureau.
        mais cette fois-ci :

        ▶ choisis l'option 6 = Restore MBR

        laisse travailler l'outil.

        en fin de scan un rapport s'ouvre

        ▶ colle le contenu dans ta réponse
        0
        1. Rapport après suppression :

          Kill'em by g3n-h@ckm@n 1.2.8.5

          User : Mike (Administrateurs)
          Update on 03/03/2010 by g3n-h@ckm@n ::::: 18.30
          Start at: 18:49:26 | 04/03/2010
          Contact : https://forums.commentcamarche.net/forum/virus-securite-7

          Intel(R) Atom(TM) CPU N280 @ 1.66GHz
          Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
          Internet Explorer 7.0.5730.13
          Windows Firewall Status : Enabled
          AV : AntiVir Desktop 9.0.1.32 [ (!) Disabled | Updated ]

          C:\ -> Disque fixe local | 149,05 Go (125,22 Go free) | NTFS
          D:\ -> Disque CD-ROM | 5,46 Mo (0 Mo free) [U3 System] | CDFS
          E:\ -> Disque amovible | 1,9 Go (1,56 Go free) | FAT
          F:\ -> Disque fixe local | 931,28 Go (631,56 Go free) [My Book] | FAT32

          ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running

          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\csrss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\spoolsv.exe
          C:\Program Files\Avira\AntiVir Desktop\sched.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\Explorer.EXE
          C:\Program Files\Avira\AntiVir Desktop\avguard.exe
          C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
          C:\Program Files\Caphyon\Advanced Web Ranking\AWRServer.exe
          C:\Program Files\Bonjour\mDNSResponder.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\msnmgr.exe
          C:\WINDOWS\system32\igfxtray.exe
          C:\WINDOWS\system32\hkcmd.exe
          C:\WINDOWS\RTHDCPL.EXE
          C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
          C:\WINDOWS\system32\igfxsrvc.exe
          C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe
          C:\Program Files\EeePC\ACPI\AsEPCMon.exe
          C:\Program Files\EeePC\ACPI\AsTray.exe
          C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
          C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
          C:\Program Files\iTunes\iTunesHelper.exe
          C:\Program Files\ASUS\Eee Docking\Eee Docking.exe
          C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
          C:\WINDOWS\system32\ctfmon.exe
          C:\WINDOWS\system32\igfxext.exe
          C:\Program Files\ASUS\EeePC\Super Hybrid Engine\SuperHybridEngine.exe
          C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
          C:\Program Files\iPod\bin\iPodService.exe
          C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
          C:\WINDOWS\System32\alg.exe
          C:\WINDOWS\system32\wscntfy.exe
          C:\Documents and Settings\Mike\Application Data\U3\0000184CF4711AE6\LaunchPad.exe
          C:\Program Files\List_Kill'em\List_Kill'em.scr
          C:\WINDOWS\system32\cmd.exe
          C:\WINDOWS\system32\wbem\wmiprvse.exe
          C:\Documents and Settings\Mike\Local Settings\Temp\B6.tmp\ERUNT.EXE
          C:\Documents and Settings\Mike\Local Settings\Temp\B6.tmp\pv.exe

          Detections :
          ==========

          ¤¤¤¤¤¤¤¤¤¤ Files/folders :

          Quarantined & Deleted !! : C:\WINDOWS\MsnMgr.exe

          Quarantined & Deleted !! : C:\WINDOWS\System32\sysconfig32.exe
          Quarantined & Deleted !! : C:\Documents and Settings\Mike\Local Settings\Temp\afl.log
          Quarantined & Deleted !! : C:\Documents and Settings\Mike\Local Settings\Temp\alm.log
          Quarantined & Deleted !! : C:\Documents and Settings\Mike\Local Settings\Temp\amt.log
          Quarantined & Deleted !! : C:\Documents and Settings\Mike\Local Settings\Temp\dw.log
          Quarantined & Deleted !! : C:\Documents and Settings\Mike\LOCAL Settings\Temp\AdobeUpdater12345.exe
          Quarantined & Deleted !! : C:\Documents and Settings\Mike\LOCAL Settings\Temp\converter.exe
          Quarantined & Deleted !! : C:\Documents and Settings\Mike\LOCAL Settings\Temp\firefoxjre_exe.exe
          Quarantined & Deleted !! : C:\Documents and Settings\Mike\LOCAL Settings\Temp\FP_PL_PFS_INSTALLER.exe
          Quarantined & Deleted !! : C:\Documents and Settings\Mike\LOCAL Settings\Temp\patch57617.exe
          Quarantined & Deleted !! : C:\Documents and Settings\Mike\LOCAL Settings\Temp\patch6506.exe
          Quarantined & Deleted !! : C:\Documents and Settings\Mike\LOCAL Settings\Temp\patch7474586251835770292.exe
          Quarantined & Deleted !! : C:\Documents and Settings\Mike\LOCAL Settings\Temp\SIntf16.dll
          Quarantined & Deleted !! : C:\Documents and Settings\Mike\LOCAL Settings\Temp\SIntf32.dll
          Quarantined & Deleted !! : C:\Documents and Settings\Mike\LOCAL Settings\Temp\SIntfNT.dll

          ==============
          host file OK !
          ==============

          ========
          Registry
          ========

          Deleted : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Install.exe"
          Deleted : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Setup.exe"
          Deleted : HKLM\Software\Classes\TypeLib\{937936AF-28CA-4973-B8AE-F250406149A2}
          ========
          Services
          =========

          Ndisuio : Start = 3
          EapHost : Start = 2
          Ip6Fw : Start = 2
          SharedAccess : Start = 2
          wuauserv : Start = 2
          wscsvc : Start = 2

          ============
          Disk Cleaned
          ============

          =================
          anti-ver blaster : OK !!
          =================

          ================
          Prefetch cleaned
          ================

          ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

          Rapport après menu 6

          Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

          device: opened successfully
          user: MBR read successfully
          kernel: MBR read successfully
          user & kernel MBR OK
          0
          1. Contributeur sécurité
            Télécharge UsbFix de C_XX & Chiquitine29

            http://pagesperso-orange.fr/NosTools/Chiquitine29/UsbFix.exe

            (!) Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptible d'avoir été infectées sans les ouvrir

            • Double clic sur "UsbFix.exe" présent sur ton bureau ( clic droit "exécuter en tant qu'administrateur" pour Vista & 7 )

            • Choisis l'option F pour français et tape sur [entrée] .

            • Choisis l'option 1 ( Recherche ) et tape sur [entrée] .

            • Laisse travailler l'outil.

            • Ensuite poste le rapport UsbFix.txt qui apparaitra.

            • Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque. ( C:\UsbFix.txt )

            ( CTRL+A Pour tout sélectionner , CTRL+C pour copier et CTRL+V pour coller )

            • Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
            Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
            Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.
            0
            1. Et voici le rapport usbfix :

              ############################## | UsbFix V6.098 |

              User : Mike (Administrateurs) # WINXP
              Update on 03/03/2010 by El Desaparecido , C_XX & Chimay8
              Start at: 19:46:15 | 04/03/2010
              Website : http://pagesperso-orange.fr/NosTools/index.html
              Contact : FindyKill.Contact@gmail.com

              Intel(R) Atom(TM) CPU N280 @ 1.66GHz
              Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
              Internet Explorer 7.0.5730.13
              Windows Firewall Status : Enabled
              AV : AntiVir Desktop 9.0.1.32 [ (!) Disabled | Updated ]

              C:\ -> Disque fixe local # 149,05 Go (125,26 Go free) # NTFS
              D:\ -> Disque CD-ROM # 5,46 Mo (0 Mo free) [U3 System] # CDFS
              E:\ -> Disque amovible # 1,9 Go (1,56 Go free) # FAT
              F:\ -> Disque fixe local # 931,28 Go (631,56 Go free) [My Book] # FAT32

              ################## | Elements infectieux |

              D:\autorun.inf
              E:\AUTORUN.FCB
              E:\SYSTEM
              F:\autorun.inf

              ################## | Registre |

              ################## | Mountpoints2 |

              HKCU\..\..\Explorer\MountPoints2\{7b2bcff4-ebc3-11de-abb9-002243f225b6}
              Shell\AutoRun\command =D:\LaunchU3.exe -a

              HKCU\..\..\Explorer\MountPoints2\{e6d4b30c-e00a-11de-aba5-002243f225b6}
              Shell\AutoRun\command =setup.exe

              ################## | Vaccin |

              ################## | ! Fin du rapport # UsbFix V6.098 ! |
              0
              1. Contributeur sécurité
                Suppression

                Branche tes sources de données externes à ton PC, (clé USB, disque dur externe......) susceptibles d'avoir été infectés sans les ouvrir

                (1) Double clic sur le raccourci UsbFix présent sur ton bureau

                (2) Choisi l option 2 ( Suppression )

                Ton bureau disparaitra et le pc redémarrera .

                Au redémarrage , UsbFix scannera ton pc , laisse travailler l outil.

                Ensuite poste le rapport UsbFix.txt qui apparaitra avec le bureau .

                Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque.( C:\UsbFix.txt )

                ( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )
                0
                1. Et voila :

                  ############################## | UsbFix V6.098 |

                  User : Mike (Administrateurs) # WINXP
                  Update on 03/03/2010 by El Desaparecido , C_XX & Chimay8
                  Start at: 20:06:05 | 04/03/2010
                  Website : http://pagesperso-orange.fr/NosTools/index.html
                  Contact : FindyKill.Contact@gmail.com

                  Intel(R) Atom(TM) CPU N280 @ 1.66GHz
                  Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
                  Internet Explorer 7.0.5730.13
                  Windows Firewall Status : Enabled
                  AV : AntiVir Desktop 9.0.1.32 [ Enabled | Updated ]

                  C:\ -> Disque fixe local # 149,05 Go (125,23 Go free) # NTFS
                  D:\ -> Disque CD-ROM # 5,46 Mo (0 Mo free) [U3 System] # CDFS
                  E:\ -> Disque amovible # 1,9 Go (1,56 Go free) # FAT
                  F:\ -> Disque fixe local # 931,28 Go (631,56 Go free) [My Book] # FAT32

                  ################## | Elements infectieux |

                  Supprimé ! C:\Recycler\S-1-5-21-2685954273-1787027159-2705462737-1005
                  (!) Non supprimé ! D:\autorun.inf
                  Supprimé ! E:\AUTORUN.FCB
                  Supprimé ! E:\SYSTEM
                  Supprimé ! F:\autorun.inf

                  ################## | Registre |

                  ################## | Mountpoints2 |

                  ################## | Listing des fichiers présent |

                  [04/03/2010 14:50|--ah-----|0] C:\a.txt
                  [04/03/2010 19:07|--a------|4] C:\AUTOEXEC.BAT
                  [11/01/2010 11:31|--a------|47725474] C:\awrj-almj-bundle.exe
                  [19/01/2010 10:11|-rahs----|216] C:\boot.ini
                  [14/04/2008 13:00|-rahs----|4952] C:\Bootfont.bin
                  [12/05/2010 21:45|--a------|0] C:\CONFIG.SYS
                  [16/12/2009 19:53|--a------|69632] C:\Contrat DiscrŠte-envie 2010.doc
                  [12/05/2010 21:45|-rahs----|0] C:\IO.SYS
                  [04/03/2010 19:07|--a------|5226] C:\Kill'em.txt
                  [08/01/2010 14:15|--a------|30720] C:\Lettre France T‚l‚com.doc
                  [07/01/2010 00:19|--a------|23040] C:\Lettre Orange.doc
                  [08/01/2010 14:50|--a------|30720] C:\Lettre URSSAFF.doc
                  [04/03/2010 17:55|--a------|24252] C:\List'em.txt
                  [12/05/2010 21:45|-rahs----|0] C:\MSDOS.SYS
                  [14/04/2008 13:00|-rahs----|47564] C:\NTDETECT.COM
                  [14/04/2008 13:00|-rahs----|252240] C:\ntldr
                  [?|?|?] C:\pagefile.sys
                  [04/03/2010 20:11|--a------|2022] C:\UsbFix.txt
                  [12/02/2007 20:53|-r-------|277] D:\autorun.inf
                  [13/02/2007 02:33|-r-------|1110016] D:\LaunchU3.exe
                  [13/02/2007 03:23|-r-------|4558081] D:\LaunchPad.zip
                  [14/09/2009 09:13|--a------|166] E:\cl‚ wifi.txt
                  [12/02/2007 18:33|-ra------|1110016] E:\LaunchU3.exe
                  [19/09/2009 15:41|--a------|54956472] E:\awrj-almj-bundle.exe
                  [13/02/2010 14:17|--a------|35878] E:\config-1.xml
                  [15/09/2009 15:17|--a------|29] E:\cle d'activation windows 7.txt
                  [14/10/2009 14:08|--ah-----|4096] E:\._.Trashes
                  [07/04/2008 00:19|--a------|41] E:\pmp_usb.ini
                  [27/01/2009 20:53|--a------|27] E:\cle_transfert.txt
                  [18/10/2009 11:01|--a------|3236] E:\BOOTEX.LOG
                  [05/02/2009 06:54|--a------|27630] E:\Acronis Disk Director Suite10.nzb
                  [31/03/2008 11:57|--a------|87] F:\Install.ini
                  [12/09/2009 00:34|--a------|78] F:\Install.log
                  [26/10/2009 16:29|--a------|23040] F:\CV Mickael MARIE.doc
                  [26/11/2009 21:10|--a------|27136] F:\Best practices SEO.xls
                  [20/11/2009 18:32|--a------|78848] F:\CheckListe-BestPracticesSEO.xls
                  [01/12/2009 15:18|--a------|91136] F:\Copie de Netlinking_DDI_291109 compl‚t‚ BF PTh AF IH et BdK.xls
                  [24/11/2009 23:12|--a------|57] F:\discrete.txt
                  [10/02/2007 18:47|--a------|18007] F:\COPYING
                  [05/11/2009 16:31|--a------|234697] F:\grub.exe
                  [06/11/2009 21:09|--a------|1974] F:\makeboot.bat
                  [06/11/2009 21:06|--a------|1839104] F:\memtest86+-4.00.iso
                  [06/11/2009 21:21|--a------|489] F:\menu.lst
                  [05/11/2009 17:08|--a------|39] F:\syslinux.cfg
                  [02/12/2009 23:43|-rahs----|11493] F:\ldlinux.sys

                  ################## | Vaccination |

                  # C:\autorun.inf -> Dossier créé par UsbFix (El Desaparecido).
                  # F:\autorun.inf -> Dossier créé par UsbFix (El Desaparecido).

                  ################## | Upload |

                  Veuillez envoyer le fichier : C:\UsbFix_Upload_Me_WINXP.zip : https://www.ionos.fr/?affiliate_id=77097
                  Merci pour votre contribution .

                  ################## | ! Fin du rapport # UsbFix V6.098 ! |
                  0
                  1. Contributeur sécurité
                    tu peut faire scan hijackthis stp
                    0
                    1. Logfile of Trend Micro HijackThis v2.0.2
                      Scan saved at 20:26:02, on 04/03/2010
                      Platform: Windows XP SP3 (WinNT 5.01.2600)
                      MSIE: Internet Explorer v7.00 (7.00.6000.16981)
                      Boot mode: Normal

                      Running processes:
                      C:\WINDOWS\System32\smss.exe
                      C:\WINDOWS\system32\winlogon.exe
                      C:\WINDOWS\system32\services.exe
                      C:\WINDOWS\system32\lsass.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\WINDOWS\system32\spoolsv.exe
                      C:\Program Files\Avira\AntiVir Desktop\sched.exe
                      C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                      C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                      C:\Program Files\Caphyon\Advanced Web Ranking\AWRServer.exe
                      C:\Program Files\Bonjour\mDNSResponder.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
                      C:\WINDOWS\explorer.exe
                      C:\Program Files\Mozilla Firefox\firefox.exe
                      C:\Documents and Settings\Mike\Mes documents\Téléchargements\HiJackThis.exe

                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
                      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
                      R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005
                      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer
                      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                      O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                      O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
                      O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
                      O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
                      O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
                      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                      O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                      O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                      O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
                      O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
                      O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
                      O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
                      O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                      O4 - HKLM\..\Run: [SynAsusAcpi] C:\Program Files\Synaptics\SynTP\SynAsusAcpi.exe
                      O4 - HKLM\..\Run: [AsusACPIServer] C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe
                      O4 - HKLM\..\Run: [AsusEPCMonitor] C:\Program Files\EeePC\ACPI\AsEPCMon.exe
                      O4 - HKLM\..\Run: [AsusTray] C:\Program Files\EeePC\ACPI\AsTray.exe
                      O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
                      O4 - HKLM\..\Run: [AdobeCS4ServiceManager] "C:\Program Files\Fichiers communs\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
                      O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
                      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                      O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe"
                      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                      O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
                      O4 - HKCU\..\Run: [Eee Docking] C:\Program Files\ASUS\Eee Docking\Eee Docking.exe
                      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                      O4 - Global Startup: SuperHybridEngine.lnk = ?
                      O4 - Global Startup: BTTray.lnk = ?
                      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
                      O8 - Extra context menu item: Envoyer au périphérique &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
                      O8 - Extra context menu item: Envoyer à Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
                      O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                      O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                      O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
                      O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
                      O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
                      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
                      O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
                      O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
                      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                      O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
                      O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\Aibelive\VOICEC~1\SKYPE4~1.DLL
                      O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
                      O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                      O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                      O23 - Service: Advanced Web Ranking Server (AWRServer) - Caphyon - C:\Program Files\Caphyon\Advanced Web Ranking\AWRServer.exe
                      O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                      O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
                      O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
                      O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                      0
                      1. Contributeur sécurité
                        relance usbfix et choisie l'option 5 ( Désinstaller ) ....

                        relance List&Kill'em et choisie l'option 3 ( Désinstaller ) ....

                        pour nettoyer les fix qui ont servit

                        Ferme toutes les applications en cours, puis télécharge ToolsCleaner2 sur ton Bureau.
                        http://pc-system.fr/

                        Double clique sur ToolsCleaner2.exe >
                        puis Recherche
                        et sur Suppression
                        Note : ton bureau va disparaître, c'est normal. S'il n'apparaît pas à la fin du scan, fais la manip suivante :

                        CTRL+ALT+SUPP pour ouvrir le Gestionnaire des tâches.
                        Puis rends toi à l'onglet "Processus". Clique en haut à gauche sur Fichiers et choisis "Exécuter"

                        Tape explorer.exe et valide. Cela fera re-apparaître le Bureau

                        tu poste le rapport générer après suppression
                        0
                        1. [ Rapport ToolsCleaner version 2.3.11 (par A.Rothstein & dj QUIOU) ]

                          --> Recherche:

                          C:\UsbFix: trouvé !
                          C:\Documents and Settings\Mike\Bureau\UsbFix.txt: trouvé !
                          C:\Documents and Settings\Mike\Local Settings\Temp\12.tmp\catchme.exe: trouvé !
                          C:\Documents and Settings\Mike\Local Settings\Temp\12.tmp\mbr.exe: trouvé !
                          C:\Documents and Settings\Mike\Local Settings\Temp\9D.tmp\catchme.exe: trouvé !
                          C:\Documents and Settings\Mike\Local Settings\Temp\9D.tmp\mbr.log: trouvé !
                          C:\Documents and Settings\Mike\Local Settings\Temp\9D.tmp\mbr.exe: trouvé !
                          C:\Documents and Settings\Mike\Local Settings\Temp\BA.tmp\catchme.exe: trouvé !
                          C:\Documents and Settings\Mike\Local Settings\Temp\BA.tmp\mbr.log: trouvé !
                          C:\Documents and Settings\Mike\Local Settings\Temp\BA.tmp\mbr.exe: trouvé !
                          C:\Documents and Settings\Mike\Mes documents\Téléchargements\HijackThis.exe: trouvé !
                          C:\Documents and Settings\Mike\Mes documents\Téléchargements\hijackthis.log: trouvé !
                          C:\Documents and Settings\Mike\Mes documents\Téléchargements\UsbFix.exe: trouvé !

                          ---------------------------------
                          --> Suppression:

                          C:\Documents and Settings\Mike\Local Settings\Temp\12.tmp\catchme.exe: supprimé !
                          C:\Documents and Settings\Mike\Local Settings\Temp\9D.tmp\catchme.exe: supprimé !
                          C:\Documents and Settings\Mike\Local Settings\Temp\BA.tmp\catchme.exe: supprimé !
                          C:\Documents and Settings\Mike\Mes documents\Téléchargements\HijackThis.exe: supprimé !
                          C:\Documents and Settings\Mike\Bureau\UsbFix.txt: supprimé !
                          C:\Documents and Settings\Mike\Local Settings\Temp\12.tmp\mbr.exe: supprimé !
                          C:\Documents and Settings\Mike\Local Settings\Temp\9D.tmp\mbr.log: supprimé !
                          C:\Documents and Settings\Mike\Local Settings\Temp\9D.tmp\mbr.exe: supprimé !
                          C:\Documents and Settings\Mike\Local Settings\Temp\BA.tmp\mbr.log: supprimé !
                          C:\Documents and Settings\Mike\Local Settings\Temp\BA.tmp\mbr.exe: supprimé !
                          C:\Documents and Settings\Mike\Mes documents\Téléchargements\hijackthis.log: supprimé !
                          C:\Documents and Settings\Mike\Mes documents\Téléchargements\UsbFix.exe: supprimé !
                          C:\UsbFix: ERREUR DE SUPPRESSION !!
                          0
                          1. Contributeur sécurité
                            Ok

                            tu va télécharger Ccleaner http://dl.commentcamarche.net/www.commentcamarche.net/download/files/ccsetup227_slim.exe

                            ouvre "Ccleaner" vas dans l'onglet "Option" puis "Avancé" puis décoches "Effacer uniquement les fichiers, du dossier temp de Windows, plus vieux que 48 heures."

                            . Puis vas dans l'onglet "Nettoyeur" fais "Analyse" puis "Lancer le nettoyage".
                            Puis vas dans l'onglet "Registre" puis fait "Chercher des erreurs" puis "Réparer les erreurs sélectionnée"
                            . Tu refais tous ca 4-5 fois (le nettoyage et le registre).

                            Puis reste dans "Ccleaner" puis va dans "Option" puis "Propriété" puis coches "Nettoyer automatiquement l'ordinateur au démarrage".

                            içi mode d'emploi pour ccleaner

                            https://www.malekal.com/tutoriel-ccleaner/

                            ensuite redémarre et fait un scan avec antivir
                            0
                            1. Ca a l'air plutot pas mal non ?

                              Malwarebytes' Anti-Malware 1.44
                              Version de la base de données: 3823
                              Windows 5.1.2600 Service Pack 3
                              Internet Explorer 7.0.5730.13

                              04/03/2010 22:15:10
                              mbam-log-2010-03-04 (22-15-10).txt

                              Type de recherche: Examen complet (C:\|)
                              Eléments examinés: 228677
                              Temps écoulé: 1 hour(s), 6 minute(s), 58 second(s)

                              Processus mémoire infecté(s): 0
                              Module(s) mémoire infecté(s): 0
                              Clé(s) du Registre infectée(s): 0
                              Valeur(s) du Registre infectée(s): 0
                              Elément(s) de données du Registre infecté(s): 0
                              Dossier(s) infecté(s): 0
                              Fichier(s) infecté(s): 0

                              Processus mémoire infecté(s):
                              (Aucun élément nuisible détecté)

                              Module(s) mémoire infecté(s):
                              (Aucun élément nuisible détecté)

                              Clé(s) du Registre infectée(s):
                              (Aucun élément nuisible détecté)

                              Valeur(s) du Registre infectée(s):
                              (Aucun élément nuisible détecté)

                              Elément(s) de données du Registre infecté(s):
                              (Aucun élément nuisible détecté)

                              Dossier(s) infecté(s):
                              (Aucun élément nuisible détecté)

                              Fichier(s) infecté(s):
                              (Aucun élément nuisible détecté)
                              0
                              1. Contributeur sécurité
                                oui c'est propre avec mbam

                                moi je voulai un scan avec ton antivirus antivir
                                0
                                1. Avira AntiVir Personal
                                  Date de création du fichier de rapport : jeudi 4 mars 2010 22:23

                                  La recherche porte sur 1814435 souches de virus.

                                  Détenteur de la licence : Avira AntiVir Personal - FREE Antivirus
                                  Numéro de série : 0000149996-ADJIE-0000001
                                  Plateforme : Windows XP
                                  Version de Windows : (Service Pack 3) [5.1.2600]
                                  Mode Boot : Démarré normalement
                                  Identifiant : SYSTEM
                                  Nom de l'ordinateur : WINXP

                                  Informations de version :
                                  BUILD.DAT : 9.0.0.75 21698 Bytes 22/01/2010 23:14:00
                                  AVSCAN.EXE : 9.0.3.10 466689 Bytes 15/12/2009 11:17:03
                                  AVSCAN.DLL : 9.0.3.0 49409 Bytes 03/03/2009 10:21:02
                                  LUKE.DLL : 9.0.3.2 209665 Bytes 20/02/2009 11:35:11
                                  LUKERES.DLL : 9.0.2.0 13569 Bytes 03/03/2009 10:21:31
                                  VBASE000.VDF : 7.10.0.0 19875328 Bytes 06/11/2009 11:17:02
                                  VBASE001.VDF : 7.10.1.0 1372672 Bytes 19/11/2009 11:17:02
                                  VBASE002.VDF : 7.10.3.1 3143680 Bytes 20/01/2010 21:44:05
                                  VBASE003.VDF : 7.10.3.75 996864 Bytes 26/01/2010 16:18:01
                                  VBASE004.VDF : 7.10.3.76 2048 Bytes 26/01/2010 16:18:01
                                  VBASE005.VDF : 7.10.3.77 2048 Bytes 26/01/2010 16:18:01
                                  VBASE006.VDF : 7.10.3.78 2048 Bytes 26/01/2010 16:18:01
                                  VBASE007.VDF : 7.10.3.79 2048 Bytes 26/01/2010 16:18:01
                                  VBASE008.VDF : 7.10.3.80 2048 Bytes 26/01/2010 16:18:01
                                  VBASE009.VDF : 7.10.3.81 2048 Bytes 26/01/2010 16:18:01
                                  VBASE010.VDF : 7.10.3.82 2048 Bytes 26/01/2010 16:18:02
                                  VBASE011.VDF : 7.10.3.83 2048 Bytes 26/01/2010 16:18:02
                                  VBASE012.VDF : 7.10.3.84 2048 Bytes 26/01/2010 16:18:02
                                  VBASE013.VDF : 7.10.3.85 2048 Bytes 26/01/2010 16:18:02
                                  VBASE014.VDF : 7.10.3.122 172544 Bytes 29/01/2010 15:45:48
                                  VBASE015.VDF : 7.10.3.149 79872 Bytes 01/02/2010 15:45:55
                                  VBASE016.VDF : 7.10.3.174 68608 Bytes 03/02/2010 15:46:58
                                  VBASE017.VDF : 7.10.3.199 76800 Bytes 04/02/2010 15:46:00
                                  VBASE018.VDF : 7.10.3.222 64512 Bytes 05/02/2010 20:02:02
                                  VBASE019.VDF : 7.10.3.243 75776 Bytes 08/02/2010 20:02:04
                                  VBASE020.VDF : 7.10.4.6 81920 Bytes 09/02/2010 20:02:06
                                  VBASE021.VDF : 7.10.4.30 78848 Bytes 11/02/2010 21:07:35
                                  VBASE022.VDF : 7.10.4.50 107520 Bytes 15/02/2010 21:07:40
                                  VBASE023.VDF : 7.10.4.62 105472 Bytes 15/02/2010 21:07:41
                                  VBASE024.VDF : 7.10.4.85 111616 Bytes 17/02/2010 21:07:29
                                  VBASE025.VDF : 7.10.4.109 122368 Bytes 21/02/2010 21:07:14
                                  VBASE026.VDF : 7.10.4.128 109056 Bytes 23/02/2010 21:07:17
                                  VBASE027.VDF : 7.10.4.151 111104 Bytes 26/02/2010 21:07:22
                                  VBASE028.VDF : 7.10.4.170 132608 Bytes 01/03/2010 10:44:57
                                  VBASE029.VDF : 7.10.4.184 100864 Bytes 02/03/2010 10:44:57
                                  VBASE030.VDF : 7.10.4.185 2048 Bytes 02/03/2010 10:44:57
                                  VBASE031.VDF : 7.10.4.194 87040 Bytes 04/03/2010 10:44:59
                                  Version du moteur : 8.2.1.180
                                  AEVDF.DLL : 8.1.1.3 106868 Bytes 22/01/2010 21:07:41
                                  AESCRIPT.DLL : 8.1.3.17 1032570 Bytes 25/02/2010 21:07:22
                                  AESCN.DLL : 8.1.5.0 127347 Bytes 25/02/2010 21:07:21
                                  AESBX.DLL : 8.1.2.0 254323 Bytes 25/02/2010 21:07:23
                                  AERDL.DLL : 8.1.4.2 479602 Bytes 13/02/2010 21:07:38
                                  AEPACK.DLL : 8.2.1.0 426356 Bytes 03/03/2010 10:44:58
                                  AEOFFICE.DLL : 8.1.0.39 196987 Bytes 19/02/2010 21:15:59
                                  AEHEUR.DLL : 8.1.1.7 2326902 Bytes 19/02/2010 21:15:55
                                  AEHELP.DLL : 8.1.10.1 237942 Bytes 25/02/2010 21:07:21
                                  AEGEN.DLL : 8.1.2.0 373107 Bytes 25/02/2010 21:07:20
                                  AEEMU.DLL : 8.1.1.0 393587 Bytes 15/12/2009 11:17:02
                                  AECORE.DLL : 8.1.12.2 188790 Bytes 03/03/2010 10:44:58
                                  AEBB.DLL : 8.1.0.3 53618 Bytes 09/10/2008 14:32:40
                                  AVWINLL.DLL : 9.0.0.3 18177 Bytes 12/12/2008 08:47:30
                                  AVPREF.DLL : 9.0.3.0 44289 Bytes 15/12/2009 11:17:03
                                  AVREP.DLL : 8.0.0.7 159784 Bytes 17/02/2010 21:07:51
                                  AVREG.DLL : 9.0.0.0 36609 Bytes 07/11/2008 15:24:42
                                  AVARKT.DLL : 9.0.0.3 292609 Bytes 24/03/2009 15:05:22
                                  AVEVTLOG.DLL : 9.0.0.7 167169 Bytes 30/01/2009 10:36:37
                                  SQLITE3.DLL : 3.6.1.0 326401 Bytes 28/01/2009 15:03:49
                                  SMTPLIB.DLL : 9.2.0.25 28417 Bytes 02/02/2009 08:20:57
                                  NETNT.DLL : 9.0.0.0 11521 Bytes 07/11/2008 15:40:59
                                  RCIMAGE.DLL : 9.0.0.25 2438913 Bytes 15/12/2009 11:17:00
                                  RCTEXT.DLL : 9.0.73.0 88321 Bytes 15/12/2009 11:17:00

                                  Configuration pour la recherche actuelle :
                                  Nom de la tâche...............................: Contrôle intégral du système
                                  Fichier de configuration......................: c:\program files\avira\antivir desktop\sysscan.avp
                                  Documentation.................................: bas
                                  Action principale.............................: interactif
                                  Action secondaire.............................: ignorer
                                  Recherche sur les secteurs d'amorçage maître..: marche
                                  Recherche sur les secteurs d'amorçage.........: marche
                                  Secteurs d'amorçage...........................: C:, F:,
                                  Recherche dans les programmes actifs..........: marche
                                  Recherche en cours sur l'enregistrement.......: marche
                                  Recherche de Rootkits.........................: marche
                                  Contrôle d'intégrité de fichiers système......: arrêt
                                  Fichier mode de recherche.....................: Tous les fichiers
                                  Recherche sur les archives....................: marche
                                  Limiter la profondeur de récursivité..........: 20
                                  Archive Smart Extensions......................: marche
                                  Heuristique de macrovirus.....................: marche
                                  Heuristique fichier...........................: moyen

                                  Début de la recherche : jeudi 4 mars 2010 22:23

                                  La recherche d'objets cachés commence.
                                  '39860' objets ont été contrôlés, '0' objets cachés ont été trouvés.

                                  La recherche sur les processus démarrés commence :
                                  Processus de recherche 'avscan.exe' - '1' module(s) sont contrôlés
                                  Processus de recherche 'avcenter.exe' - '1' module(s) sont contrôlés
                                  Processus de recherche 'firefox.exe' - '1' module(s) sont contrôlés
                                  Processus de recherche 'iPodService.exe' - '1' module(s) sont contrôlés
                                  Processus de recherche 'BTSTAC~1.EXE' - '1' module(s) sont contrôlés
                                  Processus de recherche 'alg.exe' - '1' module(s) sont contrôlés
                                  Processus de recherche 'BTTray.exe' - '1' module(s) sont contrôlés
                                  Processus de recherche 'SuperHybridEngine.exe' - '1' module(s) sont contrôlés
                                  Processus de recherche 'ctfmon.exe' - '1' module(s) sont contrôlés
                                  Processus de recherche 'Eee Docking.exe' - '1' module(s) sont contrôlés
                                  Processus de recherche 'iTunesHelper.exe' - '1' module(s) sont contrôlés
                                  Processus de recherche 'igfxext.exe' - '1' module(s) sont contrôlés
                                  Processus de recherche 'avgnt.exe' - '1' module(s) sont contrôlés
                                  Processus de recherche 'GrooveMonitor.exe' - '1' module(s) sont contrôlés
                                  Processus de recherche 'AsTray.exe' - '1' module(s) sont contrôlés
                                  Processus de recherche 'AsEPCMon.exe' - '1' module(s) sont contrôlés
                                  Processus de recherche 'AsAcpiSvr.exe' - '1' module(s) sont contrôlés
                                  Processus de recherche 'btwdins.exe' - '1' module(s) sont contrôlés
                                  Processus de recherche 'SynTPEnh.exe' - '1' module(s) sont contrôlés
                                  Processus de recherche 'RTHDCPL.EXE' - '1' module(s) sont contrôlés
                                  Processus de recherche 'igfxsrvc.exe' - '1' module(s) sont contrôlés
                                  Processus de recherche 'hkcmd.exe' - '1' module(s) sont contrôlés
                                  Processus de recherche 'igfxtray.exe' - '1' module(s) sont contrôlés
                                  Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
                                  Processus de recherche 'SeaPort.exe' - '1' module(s) sont contrôlés
                                  Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
                                  Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
                                  Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
                                  Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
                                  Processus de recherche 'mDNSResponder.exe' - '1' module(s) sont contrôlés
                                  Processus de recherche 'AWRServer.exe' - '1' module(s) sont contrôlés
                                  Processus de recherche 'AppleMobileDeviceService.exe' - '1' module(s) sont contrôlés
                                  Processus de recherche 'avguard.exe' - '1' module(s) sont contrôlés
                                  Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
                                  Processus de recherche 'explorer.exe' - '1' module(s) sont contrôlés
                                  Processus de recherche 'sched.exe' - '1' module(s) sont contrôlés
                                  Processus de recherche 'spoolsv.exe' - '1' module(s) sont contrôlés
                                  Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
                                  Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
                                  Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
                                  Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
                                  Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
                                  Processus de recherche 'lsass.exe' - '1' module(s) sont contrôlés
                                  Processus de recherche 'services.exe' - '1' module(s) sont contrôlés
                                  Processus de recherche 'winlogon.exe' - '1' module(s) sont contrôlés
                                  Processus de recherche 'csrss.exe' - '1' module(s) sont contrôlés
                                  Processus de recherche 'smss.exe' - '1' module(s) sont contrôlés
                                  '47' processus ont été contrôlés avec '47' modules

                                  La recherche sur les secteurs d'amorçage maître commence :
                                  Secteur d'amorçage maître HD0
                                  [INFO] Aucun virus trouvé !
                                  Secteur d'amorçage maître HD1
                                  [INFO] Aucun virus trouvé !
                                  Secteur d'amorçage maître HD2
                                  [INFO] Aucun virus trouvé !

                                  La recherche sur les secteurs d'amorçage commence :
                                  Secteur d'amorçage 'C:\'
                                  [INFO] Aucun virus trouvé !
                                  Secteur d'amorçage 'F:\'
                                  [INFO] Aucun virus trouvé !

                                  La recherche sur les renvois aux fichiers exécutables (registre) commence :
                                  Le registre a été contrôlé ( '75' fichiers).

                                  La recherche sur les fichiers sélectionnés commence :

                                  Recherche débutant dans 'C:\'
                                  C:\pagefile.sys
                                  [AVERTISSEMENT] Impossible d'ouvrir le fichier !
                                  [REMARQUE] Ce fichier est un fichier système Windows.
                                  [REMARQUE] Il est correct que ce fichier ne puisse pas être ouvert pour la recherche.
                                  Recherche débutant dans 'F:\'
                                  Impossible d'ouvrir le chemin à contrôler F:\ !
                                  Erreur système [3]: Le chemin d'accès spécifié est introuvable.

                                  Fin de la recherche : jeudi 4 mars 2010 23:14
                                  Temps nécessaire: 50:53 Minute(s)

                                  La recherche a été effectuée intégralement

                                  11346 Les répertoires ont été contrôlés
                                  403819 Des fichiers ont été contrôlés
                                  0 Des virus ou programmes indésirables ont été trouvés
                                  0 Des fichiers ont été classés comme suspects
                                  0 Des fichiers ont été supprimés
                                  0 Des virus ou programmes indésirables ont été réparés
                                  0 Les fichiers ont été déplacés dans la quarantaine
                                  0 Les fichiers ont été renommés
                                  1 Impossible de contrôler des fichiers
                                  403818 Fichiers non infectés
                                  7509 Les archives ont été contrôlées
                                  1 Avertissements
                                  1 Consignes
                                  39860 Des objets ont été contrôlés lors du Rootkitscan
                                  0 Des objets cachés ont été trouvés
                                  0
                                  1. Contributeur sécurité
                                    excellent

                                    de ton coté comment va le pc?
                                    0
                                    1. et bien çà va, le problème que provoque ce virus est qu'il contrôle messenger envoyant des liens vers le virus à tes contacts, je viens de réessayer messenger et çà a l'air de fonctionner parfaitement.
                                      Merci beaucoup pour ton aide, vraiment sympa !
                                      Bonne soirée
                                      Mike
                                      0
                                      1. Contributeur sécurité
                                        bye et bon surf
                                        0