Cheval de troie

bonjour, jai besoin d aide s il vous plait !!! apparement il y aurait un cheval de troie dans mon disque dur externe.. que j aurais refilé a un ami, aie.. mon pc n a rien, jai utilisé un scan d avast, qui a revelé 30 fichiers infectés (de la musique) jai tout est supprimé. puis lancer ccleaner (ras a son tour). je n ai jamais vu ecris "cheval de troie" puis je considérer que le probleme est resolut ? et quoi faire pour m en assurer s il vous plait...
merci d avance,
Bonne journée...

37 réponses

Résumé de la discussion

Un cheval de troie est soupçonné sur un disque dur externe après qu’un scan Avast a détecté une trentaine de fichiers infectés (principalement de la musique), l’utilisateur ayant tout supprimé puis lancé CCleaner. Plusieurs solutions de vérification et de nettoyage sont proposées, notamment RSIT pour un diagnostic, USBFix pour scanner les supports externes et Malwarebytes Anti-Malware pour un balayage approfondi. D'autres échanges suggèrent de vérifier les périphériques USB, d’analyser les rapports générés et de nettoyer les éléments d’auto-démarrage ou les clés de registre potentiellement modifiées. Pour compléter, des rapports techniques et les listes d’éléments détectés permettent de repérer des entrées rémanentes et d’évaluer la nécessité d’un nettoyage plus large ou d’une réinstallation du système si des résidus persistent.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    bonjour

    on va regarder...

    * Télécharge Random's System Information Tool (RSIT) de Random/Random.

    (outil de diagnostic)

    http://images.malwareremoval.com/random/RSIT.exe

    * Enregistre le sur ton Bureau.

    * Double clique sur RSIT.exe pour lancer l'outil.

    * Clique sur "Continue" à l'écran Disclaimer.

    * Si l'outil HijackThis n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu s'il te le demande)

    et tu devras accepter la licence.

    * Une fois le scan terminé, deux rapports vont apparaître : poste les dans deux messages séparés stp

    Les rapports se trouvent à cet endroit:
    C:\rsit\info.txt
    C:\rsit\log.txt

    1. info.txt logfile of random's system information tool 1.06 2010-03-21 20:23:18

      ======Uninstall list======

      -->C:\Program Files\Nero\Nero8\\nero\uninstall\UNNERO.exe /UNINSTALL
      -->C:\Windows\system32\Macromed\Flash\uninstall_plugin.exe
      -->C:\Windows\UNNeroBackItUp.exe /UNINSTALL
      -->C:\Windows\UNNeroMediaHome.exe /UNINSTALL
      -->C:\Windows\UNNeroShowTime.exe /UNINSTALL
      -->C:\Windows\UNNeroVision.exe /UNINSTALL
      -->C:\Windows\UNRecode.exe /UNINSTALL
      Adobe Flash Player 10 ActiveX-->C:\Windows\system32\Macromed\Flash\uninstall_activeX.exe
      Adobe Flash Player 10 Plugin-->MsiExec.exe /X{ECA1A3B6-898F-4DCE-9F04-714CF3BA126B}
      Adobe Photoshop Elements 6.0-->msiexec /I {F54AC413-D2C6-4A24-B324-370C223C6250}
      Adobe Photoshop Elements 6-->"C:\Program Files\Packard Bell\Smart Restore\SmartRestore.exe" /MSADDREM *AdobePE6*
      Adobe Reader 8.1.3 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A81300000003}
      Adobe Reader 8-->"C:\Program Files\Packard Bell\Smart Restore\SmartRestore.exe" /MSADDREM *AdobeReader*
      Adobe Shockwave Player-->C:\Windows\System32\Macromed\SHOCKW~1\UNWISE.EXE C:\Windows\System32\Macromed\SHOCKW~1\Install.log
      ADSL Neuf-->"C:\Program Files\Packard Bell\Smart Restore\SmartRestore.exe" /MSADDREM *NEUF_FR*
      AMD USB Audio Driver Filter-->MsiExec.exe /X{E6DB139F-DE64-4F3A-AFBD-5ABF7E434F12}
      Archiveur WinRAR-->C:\Program Files\WinRAR\uninstall.exe
      Assistant de connexion Windows Live-->MsiExec.exe /I{D3116CC7-24DC-4CA3-9CE1-23FED836E9F2}
      AUDIO DRIVER V6.0.1.5653-->"C:\Program Files\Packard Bell\Smart Restore\SmartRestore.exe" /MSADDREM *AUDIO*
      avast! Free Antivirus-->C:\Program Files\Alwil Software\Avast5\aswRunDll.exe "C:\Program Files\Alwil Software\Avast5\Setup\setiface.dll" RunSetup
      Browser Address Error Redirector-->regsvr32 /u /s "C:\Program Files\Google\Google_BAE\BAE.dll"
      Carbonite-->"C:\Program Files\Packard Bell\Smart Restore\SmartRestore.exe" /MSADDREM *Carbonite*
      Carbonite-->C:\Program Files\Carbonite\Carbonite Backup\CarboniteSetup.exe /remove
      cardreader Driver V1.0.10.4-->"C:\Program Files\Packard Bell\Smart Restore\SmartRestore.exe" /MSADDREM *CARDREADER*
      CCleaner-->"C:\Program Files\CCleaner\uninst.exe"
      eMule-->"C:\Program Files\eMule\Uninstall.exe"
      Favorit-->c:\users\marion\appdata\local\zfsek.bat
      Full Pack Codecs-->C:\Program Files\Full Pack Codecs\uninst.exe
      Galerie de photos Windows Live-->MsiExec.exe /X{B131E59D-202C-43C6-84C9-68F0C37541F1}
      Google BAE-->"C:\Program Files\Packard Bell\Smart Restore\SmartRestore.exe" /MSADDREM *GoogleBAE*
      Google Desktop-->C:\Program Files\Google\Google Desktop Search\GoogleDesktopSetup.exe -uninstall
      Google Earth-->"C:\Program Files\Packard Bell\Smart Restore\SmartRestore.exe" /MSADDREM *GOOGLE_EARTH*
      Google Earth-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3DE5E7D4-7B88-403C-A3FD-2017A8240C5B}\setup.exe" -l0x40c -removeonly
      Google Toolbar for Internet Explorer-->"C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_0531C63A913CC9D1.exe" /uninstall
      GoogleDesktop-->"C:\Program Files\Packard Bell\Smart Restore\SmartRestore.exe" /MSADDREM *GoogleDesktop*
      GoogleToolbar-->"C:\Program Files\Packard Bell\Smart Restore\SmartRestore.exe" /MSADDREM *GoogleToolbar*
      HDReg France-->MsiExec.exe /I{0ED40D2A-7131-4FE7-941E-5C329336F712}
      HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
      Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
      Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
      Infocentre Rev. 2.0.0.1-->"C:\Program Files\Packard Bell\Smart Restore\SmartRestore.exe" /MSADDREM *Infocentre*
      Installation Windows Live-->C:\Program Files\Windows Live\Installer\wlarp.exe
      Installation Windows Live-->MsiExec.exe /I{46ABBC54-1872-4AA3-95E2-F2C063A63F31}
      ITECIR Driver-->C:\Program Files\InstallShield Installation Information\{FCED9B62-34FF-4C15-8A23-F65221F7874D}\setup.exe -runfromtemp -l0x0009 -removeonly
      ITECIR Infrared Receiver V5.0.4.5-->"C:\Program Files\Packard Bell\Smart Restore\SmartRestore.exe" /MSADDREM *CIR*
      Java(TM) 6 Update 17-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216011FF}
      JMicron JMB38X Flash Media Controller-->"C:\Program Files\InstallShield Installation Information\{26604C7E-A313-4D12-867F-7C6E7820BE4C}\setup.exe" delpkg
      Junk Mail filter update-->MsiExec.exe /I{E2DFE069-083E-4631-9B6C-43C48E991DE5}
      Metaboli-->"C:\Program Files\Packard Bell\Smart Restore\SmartRestore.exe" /MSADDREM *METABOLI*
      Microsoft .NET Framework 3.5 Language Pack SP1 - fra-->MsiExec.exe /I{3E31821C-7917-367E-938E-E65FC413EA31}
      Microsoft .NET Framework 3.5 SP1-->C:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
      Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
      Microsoft Choice Guard-->MsiExec.exe /X{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}
      Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0016-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
      Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0018-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
      Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001B-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
      Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-006E-040C-0000-0000000FF1CE} /uninstall {B165D3C2-40AE-4D39-86F7-E5C87C4264C0}
      Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-00A1-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
      Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}
      Microsoft Office Excel MUI (French) 2007-->MsiExec.exe /X{90120000-0016-040C-0000-0000000FF1CE}
      Microsoft Office Home and Student 2007-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall HOMESTUDENTR /dll OSETUP.DLL
      Microsoft Office Home and Student 2007-->MsiExec.exe /X{91120000-002F-0000-0000-0000000FF1CE}
      Microsoft Office Live Add-in 1.3-->MsiExec.exe /I{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}
      Microsoft Office OneNote MUI (French) 2007-->MsiExec.exe /X{90120000-00A1-040C-0000-0000000FF1CE}
      Microsoft Office PowerPoint MUI (French) 2007-->MsiExec.exe /X{90120000-0018-040C-0000-0000000FF1CE}
      Microsoft Office PowerPoint Viewer 2007 (French)-->MsiExec.exe /X{95120000-00AF-040C-0000-0000000FF1CE}
      Microsoft Office Proof (Arabic) 2007-->MsiExec.exe /X{90120000-001F-0401-0000-0000000FF1CE}
      Microsoft Office Proof (Dutch) 2007-->MsiExec.exe /X{90120000-001F-0413-0000-0000000FF1CE}
      Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
      Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
      Microsoft Office Proof (German) 2007-->MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}
      Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
      Microsoft Office Proofing (French) 2007-->MsiExec.exe /X{90120000-002C-040C-0000-0000000FF1CE}
      Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0401-0000-0000000FF1CE} /uninstall {14809F99-C601-4D4A-9391-F1E8FAA964C5}
      Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0407-0000-0000000FF1CE} /uninstall {A0516415-ED61-419A-981D-93596DA74165}
      Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {ABDDE972-355B-4AF1-89A8-DA50B7B5C045}
      Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-040C-0000-0000000FF1CE} /uninstall {F580DDD5-8D37-4998-968E-EBB76BB86787}
      Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0413-0000-0000000FF1CE} /uninstall {D66D5A44-E480-4BA4-B4F2-C554F6B30EBB}
      Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0C0A-0000-0000000FF1CE} /uninstall {187308AB-5FA7-4F14-9AB9-D290383A10D9}
      Microsoft Office Shared MUI (French) 2007-->MsiExec.exe /X{90120000-006E-040C-0000-0000000FF1CE}
      Microsoft Office Suite Activation Assistant-->MsiExec.exe /X{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}
      Microsoft Office Word MUI (French) 2007-->MsiExec.exe /X{90120000-001B-040C-0000-0000000FF1CE}
      Microsoft Search Enhancement Pack-->MsiExec.exe /X{4CBA3D4C-8F51-4D60-B27E-F6B641C571E7}
      Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
      Microsoft SQL Server 2005 Compact Edition [ENU]-->MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
      Microsoft Sync Framework Runtime Native v1.0 (x86)-->MsiExec.exe /I{8A74E887-8F0F-4017-AF53-CBA42211AAA5}
      Microsoft Sync Framework Services Native v1.0 (x86)-->MsiExec.exe /I{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}
      Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053-->MsiExec.exe /X{770657D0-A123-3C07-8E44-1C83EC895118}
      Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
      Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148-->MsiExec.exe /X{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}
      Microsoft Works 9 SE-->"C:\Program Files\Packard Bell\Smart Restore\SmartRestore.exe" /MSADDREM *works9se*
      Microsoft Works-->MsiExec.exe /I{0214A441-A4AB-43A8-8DEF-2F73C5364673}
      Microsoft® Office Trial 2007-->"C:\Program Files\Packard Bell\Smart Restore\SmartRestore.exe" /MSADDREM *OFF2k7_FR*
      Mise à jour Microsoft Office Excel 2007 Help (KB963678)-->msiexec /package {90120000-0016-040C-0000-0000000FF1CE} /uninstall {B761869A-B85C-40E2-994C-A1CE78AC8F2C}
      Mise à jour Microsoft Office Powerpoint 2007 Help (KB963669)-->msiexec /package {90120000-0018-040C-0000-0000000FF1CE} /uninstall {C3DCA38E-005E-41BA-A52A-7C3429F351C3}
      Mise à jour Microsoft Office Word 2007 Help (KB963665)-->msiexec /package {90120000-001B-040C-0000-0000000FF1CE} /uninstall {81536A04-DBFB-4DB3-978F-0F284590C223}
      Module de compatibilité pour Microsoft Office System 2007-->MsiExec.exe /X{90120000-0020-040C-0000-0000000FF1CE}
      Module linguistique Microsoft .NET Framework 3.5 SP1- fra-->C:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 Language Pack SP1 - fra\setup.exe
      Mozilla Firefox (3.0.5)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
      MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
      MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
      MSXML 4.0 SP2 (KB973688)-->MsiExec.exe /I{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
      Nero 8 Essentials-->"C:\Program Files\Packard Bell\Smart Restore\SmartRestore.exe" /MSADDREM *Nero8*
      Nero 8 Essentials-->MsiExec.exe /X{980B9958-1239-4FC5-8C88-AC5650321036}
      neroxml-->MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B}
      Neuf - Kit de connexion-->C:\Program Files\Neuf\Kit\uninstall.exe
      Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
      P2P_Torrent Toolbar-->C:\PROGRA~1\P2P_TO~1\UNWISE.EXE C:\PROGRA~1\P2P_TO~1\INSTALL.LOG
      Package de pilotes Windows - ITE Tech.Inc. (itecir) HIDClass (10/03/2007 5.0.0004.5)-->C:\PROGRA~1\DIFX\F46A63020E122F0A\DPInst.exe /u C:\Windows\System32\DriverStore\FileRepository\itecir.inf_dce1c9f8\itecir.inf
      Packard Bell ImageWriter-->"C:\Program Files\Packard Bell\Smart Restore\SmartRestore.exe" /MSADDREM *ImageWriter*
      Packard Bell LCD Test-->"C:\Program Files\Packard Bell\Smart Restore\SmartRestore.exe" /MSADDREM *LCDTest*
      Packard Bell Updator-->"C:\Program Files\Packard Bell\Smart Restore\SmartRestore.exe" /MSADDREM *Updator*
      Picasa 2-->"C:\Program Files\Picasa2\Uninstall.exe"
      Picasa2-->"C:\Program Files\Packard Bell\Smart Restore\SmartRestore.exe" /MSADDREM *Picasa_2*
      Protégez vos données-->"C:\Program Files\Packard Bell\Carbonite\CarboniteSetupLitePBPreInstaller.exe" /preinstalled /uninstall
      Realtek 8169 8168 8101E 8102E Ethernet Driver-->C:\Program Files\InstallShield Installation Information\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}\setup.exe -runfromtemp -l0x040c -removeonly
      Realtek High Definition Audio Driver-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\Setup.exe" -removeonly
      Realtek RTL8102 Driver V6.203.214.2008-->"C:\Program Files\Packard Bell\Smart Restore\SmartRestore.exe" /MSADDREM *LAN*
      SeaTools for Windows-->MsiExec.exe /I{98613C99-1399-416C-A07C-1EE1C585D872}
      Security Update for 2007 Microsoft Office System (KB969559)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {69F52148-9BF6-4CDC-BF76-103DEAF3DD08}
      Security Update for 2007 Microsoft Office System (KB978380)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {667A88D1-0369-4070-A62A-70672D68A9BF}
      Security Update for Microsoft Office Excel 2007 (KB978382)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {6DE3DABF-0203-426B-B330-7287D1003E86}
      Security Update for Microsoft Office PowerPoint 2007 (KB957789)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {7559E742-FF9F-4FAE-B279-008ED296CB4D}
      Security Update for Microsoft Office system 2007 (972581)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {3D019598-7B59-447A-80AE-815B703B84FF}
      Security Update for Microsoft Office system 2007 (KB969613)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {5ECEB317-CBE9-4E08-AB10-756CB6F0FB6C}
      Security Update for Microsoft Office system 2007 (KB974234)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {FCD742B9-7A55-44BC-A776-F795F21FEDDC}
      Security Update for Microsoft Office Visio Viewer 2007 (KB973709)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {71127777-8B2C-4F97-AF7A-6CF8CAC8224D}
      SetUp My PC-->"C:\Program Files\Packard Bell\Smart Restore\SmartRestore.exe" /MSADDREM *SETUPMYPC_FR*
      Skype 3.6.2.248-->"C:\Program Files\Packard Bell\Smart Restore\SmartRestore.exe" /MSADDREM *SKYPE*
      Skype(TM) 3.6-->MsiExec.exe /X{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}
      Synaptics Pointing Device Driver-->rundll32.exe "C:\Program Files\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall
      TOUCHPAD DRIVER V10.0.1.0-->"C:\Program Files\Packard Bell\Smart Restore\SmartRestore.exe" /MSADDREM *TOUCHPAD*
      Update for 2007 Microsoft Office System (KB967642)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {C444285D-5E4F-48A4-91DD-47AAAA68E92D}
      Update for 2007 Microsoft Office System (KB977724)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {CC0E469C-5006-48B9-BBDC-D11B562499B4}
      Update for Microsoft .NET Framework 3.5 SP1 (KB963707)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {B2AE9C82-DC7B-3641-BFC8-87275C4F3607} /qb+ REBOOTPROMPT=""
      Update for Microsoft Office InfoPath 2007 (KB976416)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {432C5EE4-8096-4FF1-95E1-65219365DFF7}
      Update for Microsoft Office Word 2007 (KB974561)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {0CDDBAA2-2111-4A0E-A1B0-76C40C635331}
      VCRedistSetup-->MsiExec.exe /I{3921A67A-5AB1-4E48-9444-C71814CF3027}
      VGA DRIVERS V8.479-->"C:\Program Files\Packard Bell\Smart Restore\SmartRestore.exe" /MSADDREM *VGA*
      VLC media player 0.9.8a-->C:\Program Files\VideoLAN\VLC\uninstall.exe
      Windows Live Call-->MsiExec.exe /I{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}
      Windows Live Communications Platform-->MsiExec.exe /I{ED00D08A-3C5F-488D-93A0-A04F21F23956}
      Windows Live Contrôle parental-->MsiExec.exe /X{D5D81435-B8DE-4CAF-867F-7998F2B92CFC}
      Windows Live FolderShare-->MsiExec.exe /X{2075CB0A-D26F-4DAA-B424-5079296B43BA}
      Windows Live Mail-->MsiExec.exe /I{5DD76286-9BE7-4894-A990-E905E91AC818}
      Windows Live Messenger-->MsiExec.exe /X{770F1BEC-2871-4E70-B837-FB8525FFA3B1}
      Windows Live Movie Maker-->MsiExec.exe /X{53B20C18-D8D4-4588-8737-9BBFE303C354}
      Windows Live Toolbar-->MsiExec.exe /X{F7D27C70-90F5-49B9-B188-0A133C0CE353}
      Windows Live Writer-->MsiExec.exe /X{4634B21A-CC07-4396-890C-2B8168661FEA}

      ======Security center information======

      AS: Windows Defender

      ======System event log======

      Computer Name: PC-de-marion
      Event Code: 7000
      Message: Le service Parallel port driver n'a pas pu démarrer en raison de l'erreur :
      Le service ne peut pas être démarré parce qu'il est désactivé ou qu'aucun périphérique activé ne lui est associé.
      Record Number: 127997
      Source Name: Service Control Manager
      Time Written: 20100321151143.000000-000
      Event Type: Erreur
      User:

      Computer Name: PC-de-marion
      Event Code: 4001
      Message: Le Service d'autoconfiguration WLAN s'est arrêté correctement.

      Record Number: 128068
      Source Name: Microsoft-Windows-WLAN-AutoConfig
      Time Written: 20100321163115.375200-000
      Event Type: Avertissement
      User: AUTORITE NT\SYSTEM

      Computer Name: PC-de-marion
      Event Code: 15016
      Message: Impossible d'initialiser le package de sécurité Kerberos pour l'authentification côté serveur. Le champ de données contient le numéro de l'erreur.
      Record Number: 128083
      Source Name: Microsoft-Windows-HttpEvent
      Time Written: 20100321190020.694352-000
      Event Type: Erreur
      User:

      Computer Name: PC-de-marion
      Event Code: 7000
      Message: Le service Parallel port driver n'a pas pu démarrer en raison de l'erreur :
      Le service ne peut pas être démarré parce qu'il est désactivé ou qu'aucun périphérique activé ne lui est associé.
      Record Number: 128127
      Source Name: Service Control Manager
      Time Written: 20100321190152.000000-000
      Event Type: Erreur
      User:

      Computer Name: PC-de-marion
      Event Code: 4226
      Message: TCP/IP a atteint la limite de sécurité imposée sur le nombre de tentatives de connexion TCP simultanées.
      Record Number: 128180
      Source Name: Tcpip
      Time Written: 20100321190719.009752-000
      Event Type: Avertissement
      User:

      =====Application event log=====

      Computer Name: PC-de-marion
      Event Code: 10
      Message: Le filtre d'événement avec la requête « SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99 » n'a pas pu être réactivé dans l'espace de noms « //./root/CIMV2 » à cause de l'erreur 0x80041003. Les événements ne peuvent pas être délivrés à travers ce filtre tant que le problème ne sera pas corrigé.
      Record Number: 27247
      Source Name: Microsoft-Windows-WMI
      Time Written: 20100319203411.000000-000
      Event Type: Erreur
      User:

      Computer Name: PC-de-marion
      Event Code: 10
      Message: Le filtre d'événement avec la requête « SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99 » n'a pas pu être réactivé dans l'espace de noms « //./root/CIMV2 » à cause de l'erreur 0x80041003. Les événements ne peuvent pas être délivrés à travers ce filtre tant que le problème ne sera pas corrigé.
      Record Number: 27271
      Source Name: Microsoft-Windows-WMI
      Time Written: 20100321085048.000000-000
      Event Type: Erreur
      User:

      Computer Name: PC-de-marion
      Event Code: 10
      Message: Le filtre d'événement avec la requête « SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99 » n'a pas pu être réactivé dans l'espace de noms « //./root/CIMV2 » à cause de l'erreur 0x80041003. Les événements ne peuvent pas être délivrés à travers ce filtre tant que le problème ne sera pas corrigé.
      Record Number: 27303
      Source Name: Microsoft-Windows-WMI
      Time Written: 20100321125542.000000-000
      Event Type: Erreur
      User:

      Computer Name: PC-de-marion
      Event Code: 10
      Message: Le filtre d'événement avec la requête « SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99 » n'a pas pu être réactivé dans l'espace de noms « //./root/CIMV2 » à cause de l'erreur 0x80041003. Les événements ne peuvent pas être délivrés à travers ce filtre tant que le problème ne sera pas corrigé.
      Record Number: 27326
      Source Name: Microsoft-Windows-WMI
      Time Written: 20100321151143.000000-000
      Event Type: Erreur
      User:

      Computer Name: PC-de-marion
      Event Code: 10
      Message: Le filtre d'événement avec la requête « SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99 » n'a pas pu être réactivé dans l'espace de noms « //./root/CIMV2 » à cause de l'erreur 0x80041003. Les événements ne peuvent pas être délivrés à travers ce filtre tant que le problème ne sera pas corrigé.
      Record Number: 27355
      Source Name: Microsoft-Windows-WMI
      Time Written: 20100321190151.000000-000
      Event Type: Erreur
      User:

      =====Security event log=====

      Computer Name: PC-de-marion
      Event Code: 4647
      Message: Fermeture de session initiée par l'utilisateur :

      Sujet :
      ID de sécurité : S-1-5-21-167161423-2884399284-2469616292-1000
      Nom du compte : marion
      Domaine du compte : PC-de-marion
      ID d'ouverture de session : 0x34dfa

      Cet événement est généré lorsqu'une fermeture de session est initiée, mais que le nombre de références du jeton n'étant pas zéro, la session ouverte ne peut pas être supprimée. Aucune autre activité initiée par l'utilisateur ne peut se produire. Cet événement peut être interprété comme un événement de fermeture de session.
      Record Number: 20699
      Source Name: Microsoft-Windows-Security-Auditing
      Time Written: 20091001023609.911328-000
      Event Type: Succès de l'audit
      User:

      Computer Name: PC-de-marion
      Event Code: 4648
      Message: Tentative d'ouverture de session en utilisant des informations d'identification explicites.

      Sujet :
      ID de sécurité : S-1-5-18
      Nom du compte : PC-DE-MARION$
      Domaine du compte : WORKGROUP
      ID d'ouverture de session : 0x3e7
      GUID d'ouverture de session : {00000000-0000-0000-0000-000000000000}

      Compte dont les informations d'identification ont été utilisées :
      Nom du compte : SYSTEM
      Domaine du compte : AUTORITE NT
      GUID d'ouverture de session : {00000000-0000-0000-0000-000000000000}

      Serveur cible :
      Nom du serveur cible : localhost
      Informations supplémentaires : localhost

      Informations sur le processus :
      ID du processus : 0x2b4
      Nom du processus : C:\Windows\System32\services.exe

      Informations sur le réseau :
      Adresse du réseau : -
      Port : -

      Cet événement est généré lorsqu'un processus tente d'ouvrir une session pour un compte en spécifiant explicitement les informations d'identification de ce compte. Ceci se produit le plus souvent dans les configurations par lot comme les tâches planifiées, ou avec l'utilisation de la commande RUNAS.
      Record Number: 20700
      Source Name: Microsoft-Windows-Security-Auditing
      Time Written: 20091001023611.440128-000
      Event Type: Succès de l'audit
      User:

      Computer Name: PC-de-marion
      Event Code: 4624
      Message: L'ouverture de session d'un compte s'est correctement déroulée.

      Sujet :
      ID de sécurité : S-1-5-18
      Nom du compte : PC-DE-MARION$
      Domaine du compte : WORKGROUP
      ID d'ouverture de session : 0x3e7

      Type d'ouverture de session : 5

      Nouvelle ouverture de session :
      ID de sécurité : S-1-5-18
      Nom du compte : SYSTEM
      Domaine du compte : AUTORITE NT
      ID d'ouverture de session : 0x3e7
      GUID d'ouverture de session : {00000000-0000-0000-0000-000000000000}

      Informations sur le processus :
      ID du processus : 0x2b4
      Nom du processus : C:\Windows\System32\services.exe

      Informations sur le réseau :
      Nom de la station de travail :
      Adresse du réseau source : -
      Port source : -

      Informations détaillées sur l'authentification :
      Processus d'ouverture de session : Advapi
      Package d'authentification : Negotiate
      Services en transit : -
      Nom du package (NTLM uniquement) : -
      Longueur de la clé : 0

      Cet événement est généré lors de la création d'une ouverture de session. Il est généré sur l'ordinateur sur lequel l'ouverture de session a été effectuée.

      Le champ Objet indique le compte sur le système local qui a demandé l'ouverture de session. Il s'agit le plus souvent d'un service, comme le service Serveur, ou un processus local tel que Winlogon.exe ou Services.exe.

      Le champ Type d'ouverture de session indique le type d'ouverture de session qui s'est produit. Les types les plus courants sont 2 (interactif) et 3 (réseau).

      Le champ Nouvelle ouverture de session indique le compte pour lequel la nouvelle ouverture de session a été créée, par exemple, le compte qui s'est connecté.

      Les champs relatifs au réseau indiquent la provenance d'une demande d'ouverture de session à distance. Le nom de la station de travail n'étant pas toujours disponible, peut être laissé vide dans certains cas.

      Les champs relatifs aux informations d'authentification fournissent des détails sur cette demande d'ouverture de session spécifique.
      - Le GUID d'ouverture de session est un identificateur unique pouvant servir à associer cet événement à un événement KDC .
      - Les services en transit indiquent les services intermédiaires qui ont participé à cette demande d'ouverture de session.
      - Nom du package indique quel est le sous-protocole qui a été utilisé parmi les protocoles NTLM.
      - La longueur de la clé indique la longueur de la clé de session générée. Elle a la valeur 0 si aucune clé de session n'a été demandée.
      Record Number: 20701
      Source Name: Microsoft-Windows-Security-Auditing
      Time Written: 20091001023611.440128-000
      Event Type: Succès de l'audit
      User:

      Computer Name: PC-de-marion
      Event Code: 4672
      Message: Privilèges spéciaux attribués à la nouvelle ouverture de session.

      Sujet :
      ID de sécurité : S-1-5-18
      Nom du compte : SYSTEM
      Domaine du compte : AUTORITE NT
      ID d'ouverture de session : 0x3e7

      Privilèges : SeAssignPrimaryTokenPrivilege
      SeTcbPrivilege
      SeSecurityPrivilege
      SeTakeOwnershipPrivilege
      SeLoadDriverPrivilege
      SeBackupPrivilege
      SeRestorePrivilege
      SeDebugPrivilege
      SeAuditPrivilege
      SeSystemEnvironmentPrivilege
      SeImpersonatePrivilege
      Record Number: 20702
      Source Name: Microsoft-Windows-Security-Auditing
      Time Written: 20091001023611.440128-000
      Event Type: Succès de l'audit
      User:

      Computer Name: PC-de-marion
      Event Code: 1100
      Message: Le service d'enregistrement des événements a été arrêté.
      Record Number: 20703
      Source Name: Microsoft-Windows-Eventlog
      Time Written: 20091001023623.935000-000
      Event Type: Succès de l'audit
      User:

      ======Environment variables======

      "ComSpec"=%SystemRoot%\system32\cmd.exe
      "FP_NO_HOST_CHECK"=NO
      "OS"=Windows_NT
      "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\ATI Technologies\ATI.ACE\Core-Static
      "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
      "PROCESSOR_ARCHITECTURE"=x86
      "TEMP"=%SystemRoot%\TEMP
      "TMP"=%SystemRoot%\TEMP
      "USERNAME"=SYSTEM
      "windir"=%SystemRoot%
      "PROCESSOR_LEVEL"=17
      "PROCESSOR_IDENTIFIER"=x86 Family 17 Model 3 Stepping 1, AuthenticAMD
      "PROCESSOR_REVISION"=0301
      "NUMBER_OF_PROCESSORS"=2
      "TRACE_FORMAT_SEARCH_PATH"=\\NTREL202.ntdev.corp.microsoft.com\4F18C3A5-CA09-4DBD-B6FC-219FDD4C6BE0\TraceFormat
      "DFSTRACINGON"=FALSE

      -----------------EOF-----------------
      1. Contributeur sécurité
        vu

        il me faudrait celui ci aussi

        C:\rsit\log.txt
        1. Logfile of random's system information tool 1.06 (written by random/random)
          Run by marion at 2010-03-21 20:09:05
          Microsoft® Windows Vista(TM) Édition Familiale Premium Service Pack 1
          System drive C: has 26 GB (18%) free of 140 GB
          Total RAM: 3070 MB (64% free)

          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 20:23:16, on 21/03/2010
          Platform: Windows Vista SP1 (WinNT 6.00.1905)
          MSIE: Internet Explorer v7.00 (7.00.6001.18385)
          Boot mode: Normal

          Running processes:
          C:\Windows\system32\taskeng.exe
          C:\Windows\system32\Dwm.exe
          C:\Windows\Explorer.EXE
          C:\Program Files\Windows Defender\MSASCui.exe
          C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
          C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
          C:\Windows\RtHDVCpl.exe
          C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
          C:\Program Files\Carbonite\Carbonite Backup\CarboniteUI.exe
          C:\Program Files\Alwil Software\Avast5\AvastUI.exe
          C:\Program Files\Java\jre6\bin\jusched.exe
          C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe
          C:\Program Files\Windows Live\Messenger\msnmsgr.exe
          C:\Program Files\Messenger\msmsgs.exe
          C:\Users\marion\AppData\Local\frdfqcd.exe
          C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
          C:\Program Files\Windows Media Player\wmpnscfg.exe
          C:\Program Files\Internet Explorer\ieuser.exe
          C:\Program Files\Internet Explorer\iexplore.exe
          C:\Program Files\Google\Google Toolbar\GoogleToolbarUser.exe
          C:\Program Files\Windows Live\Toolbar\wltuser.exe
          C:\Windows\system32\wuauclt.exe
          C:\Windows\system32\Macromed\Flash\FlashUtil10b.exe
          C:\Users\marion\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\702UCLZ9\RSIT[1].exe
          C:\Program Files\trend micro\marion.exe

          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.google.com/?gws_rd=ssl
          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://actus.sfr.fr
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = https://actus.sfr.fr
          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
          R3 - URLSearchHook: P2P Torrent Toolbar - {bc4be15d-6a34-4356-9e97-79e43da32b1d} - C:\Program Files\P2P_Torrent\tbP2P_.dll
          O1 - Hosts: ::1 localhost
          O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
          O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
          O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
          O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
          O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
          O2 - BHO: P2P Torrent Toolbar - {bc4be15d-6a34-4356-9e97-79e43da32b1d} - C:\Program Files\P2P_Torrent\tbP2P_.dll
          O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
          O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Google\Google_BAE\BAE.dll
          O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
          O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
          O3 - Toolbar: P2P Torrent Toolbar - {bc4be15d-6a34-4356-9e97-79e43da32b1d} - C:\Program Files\P2P_Torrent\tbP2P_.dll
          O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
          O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
          O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
          O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
          O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
          O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
          O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
          O4 - HKLM\..\Run: [toolbar_eula_launcher] C:\Program Files\Packard Bell\GOOGLE_EULA\EULALauncher.exe
          O4 - HKLM\..\Run: [Carbonite Backup] C:\Program Files\Carbonite\Carbonite Backup\CarboniteUI.exe
          O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
          O4 - HKLM\..\Run: [avast5] C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui
          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
          O4 - HKCU\..\Run: [SmpcSys] C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe
          O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
          O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
          O4 - HKCU\..\Run: [frdfqcd] "c:\users\marion\appdata\local\frdfqcd.exe" frdfqcd
          O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
          O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
          O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
          O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
          O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
          O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
          O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
          O13 - Gopher Prefix:
          O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
          O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
          O23 - Service: Adobe Active File Monitor V6 (AdobeActiveFileMonitor6.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
          O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
          O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
          O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
          O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
          O23 - Service: CarboniteService - Carbonite, Inc. (www.carbonite.com) - C:\Program Files\Carbonite\Carbonite Backup\carboniteservice.exe
          O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
          O23 - Service: Google Desktop Manager 5.9.909.30391 (GoogleDesktopManager-093009-130223) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
          O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
          O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
          O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\Windows\system32\IoctlSvc.exe
          1. Contributeur sécurité
            ok

            pas d'infection usb àpriori (on verifiera ton DD externe ensuite)

            en revanche, une toolbar néfaste et une infection navipromo (pub)

            1)

            Infection Navipromo....Pour info :

            Il s'installe via certains programmes, dont ceux-ci qu'il faut éviter à tout prix:
            * Funky Emoticons
            * go-astro
            * Games Attack
            * GoRecord
            * HotTVPlayer / HotTVPlayer & Paris Hilton
            * Live-Player
            * MailSkinner
            * Messenger Skinner
            * Instant Access
            * InternetGameBox
            * Officiale Emule (Version d'Emule modifiée)
            * Original Solitaire
            * SuperSexPlayer
            * Speed Downloading
            * Sudoplanet
            * Webmediaplayer

            il faudrait télécharge navilog1 sur le bureau :
            http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe

            Certaines infections bloquent les téléchargements d' outils de désinfection utilisez ce lien alternatif:
            http://ww38.toofiles.com/fr/oip/documents/exe/yop3.html

            /!\ Utilisateur de VISTA: il faudrait désactiver l'UAC juste le temps de désinfection de votre pc, Vous le réactiverez plus tard :

            Tuto : https://www.commentcamarche.net/faq/8343-vista-desactiver-l-uac

            1°Double-clique sur navilog1.exe présent sur ton bureau
            2°Sélectionnez la langue désirée dans le menu puis valide le choix par la touche « entrer »
            3°Petit message d'avertissement, appuyez sur une touche pour passe à la suite
            4°un nouveau avertissement, appuie sur une touche pour suivre
            5°Vérification de l'installation de Navilog1 : si tout est bon, appuyez sur une touche pour continuer
            6°Choisir option 1 : recherche/désinfection automatique
            7°La recherche va se lancer automatiquement et peut durée quelques minutes, patientez
            8°Une fois l'analyse terminé, fermez et enregistrez votre travail en cours, puis appuiez sur une touche pour que votre pc puisse démarrer
            9°Au redémarrage du pc, Navilog va supprimer ce qu'il a trouvé, patientez quelques instants.

            Un rapport est gèneré par l'outil. Il se trouve à cette emplacement :
            XP : demarrer/poste de travail/c:/cleannavi.txt
            Vista : logo « demarrer »/ordinateur/c:/ cleannavi.txt

            .......................................

            2)

            Desactive ton antivirus le temps de la manip ainsi que ton parefeu si présent(car il est detecté a tort comme infection)

            ? Télécharge et installe List&Kill'em et enregistre le sur ton bureau
            http://sd-1.archive-host.com/...

            double clique ( clic droit "executer en tant qu'administrateur" pour Vista/7 ) sur le raccourci sur ton bureau pour lancer l'installation

            coche la case "creer une icone sur le bureau"

            une fois terminée , clic sur "terminer" et le programme se lancer seul

            choisis la langue puis choisis l'option SEARCH

            laisse travailler l'outil

            à l'apparition de la fenetre blanche , c'est un peu long , c'est normal , le programme n'est pas bloqué.

            un rapport du nom de catchme apparait sur ton bureau , ignore-le,ne le poste pas , mais ne le supprime pas pour l instant, le scan n'est pas fini.

            ? Poste le contenu du rapport qui s'ouvre aux 100 % du scan à l'ecran "COMPLETED"

            tu peux supprimer le rapport catchme.log de ton bureau maintenant.


            Je cherche beaucoup...et maintenant je trouve !
            (sourire)
            1. bonjour,
              merci pour tte c infos,
              jvais tenter ttes les manipes..
              et jte dis quoi.., il est donc preferable que je n utilise plus emul ?
              bonne journée
              1. Contributeur sécurité
                je t'en reparlerai à la fin de ton sujet

                en attendant tes rapports...

                @+
                1. Fix Navipromo version 4.0.8 commencé le 22/03/2010 9:42:05,02

                  !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
                  !!! Postez ce rapport sur le forum pour le faire analyser !!!

                  Outil exécuté depuis C:\navilog1

                  Mise à jour le 09.03.2010 à 18h00 par IL-MAFIOSO

                  Microsoft® Windows Vista(TM) Édition Familiale Premium ( v6.0.6001 ) Service Pack 1
                  X86-based PC ( Multiprocessor Free : AMD Turion(tm) X2 Ultra Dual-Core Mobile ZM-80 )
                  BIOS : Ver 1.00PARTTBLv
                  USER : marion ( Administrator )
                  BOOT : Normal boot

                  C:\ (Local Disk) - NTFS - Total:137 Go (Free:25 Go)
                  D:\ (Local Disk) - NTFS - Total:298 Go (Free:297 Go)
                  E:\ (CD or DVD)

                  Recherche executée en mode normal

                  Nettoyage exécuté au redémarrage de l'ordinateur

                  C:\Windows\prefetch\frdfqcd*.pf supprimé !
                  C:\Users\marion\AppData\Local\frdfqcd.exe supprimé !
                  C:\Users\marion\AppData\Local\frdfqcd.dat supprimé !
                  C:\Users\marion\AppData\Local\frdfqcd_nav.dat supprimé !
                  C:\Users\marion\AppData\Local\frdfqcd_navps.dat supprimé !

                  Nettoyage contenu C:\Windows\Temp effectué !
                  Nettoyage contenu C:\Users\marion\AppData\Local\Temp effectué !

                  *** Sauvegarde du Registre vers dossier Safebackup ***

                  sauvegarde du Registre réalisée avec succès !

                  *** Nettoyage Registre ***

                  Nettoyage Registre Ok

                  *** Scan terminé 22/03/2010 9:46:54,96 ***
                  1. List'em by g3n-h@ckm@n 1.6.0.3

                    User : marion (Administrateurs)
                    Update on 21/03/2010 by g3n-h@ckm@n ::::: 18.30
                    Start at: 09:54:53 | 22/03/2010

                    AMD Turion(tm) X2 Ultra Dual-Core Mobile ZM-80
                    Microsoft® Windows Vista(TM) Édition Familiale Premium (6.0.6001 32-bit) # Service Pack 1
                    Internet Explorer 7.0.6001.18000
                    Windows Firewall Status : Enabled

                    C:\ -> Disque fixe local | 137,05 Go (24,62 Go free) [HDD] | NTFS
                    D:\ -> Disque fixe local | 298,09 Go (297,62 Go free) | NTFS
                    E:\ -> Disque CD-ROM

                    Boot: Normal

                    ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running

                    C:\Windows\System32\smss.exe
                    C:\Windows\system32\csrss.exe
                    C:\Windows\system32\csrss.exe
                    C:\Windows\system32\wininit.exe
                    C:\Windows\system32\services.exe
                    C:\Windows\system32\lsass.exe
                    C:\Windows\system32\lsm.exe
                    C:\Windows\system32\winlogon.exe
                    C:\Windows\system32\svchost.exe
                    C:\Windows\system32\svchost.exe
                    C:\Windows\System32\svchost.exe
                    C:\Windows\system32\Ati2evxx.exe
                    C:\Windows\System32\svchost.exe
                    C:\Windows\System32\svchost.exe
                    C:\Windows\system32\svchost.exe
                    C:\Windows\system32\SLsvc.exe
                    C:\Windows\system32\svchost.exe
                    C:\Windows\system32\Ati2evxx.exe
                    C:\Windows\system32\svchost.exe
                    C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
                    C:\Windows\System32\spoolsv.exe
                    C:\Windows\system32\svchost.exe
                    C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
                    C:\Program Files\Carbonite\Carbonite Backup\carboniteservice.exe
                    C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
                    C:\Windows\system32\IoctlSvc.exe
                    C:\Windows\system32\svchost.exe
                    C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                    C:\Windows\system32\svchost.exe
                    C:\Windows\System32\svchost.exe
                    C:\Windows\system32\SearchIndexer.exe
                    C:\Windows\system32\taskeng.exe
                    C:\Windows\system32\taskeng.exe
                    C:\Windows\system32\Dwm.exe
                    C:\Windows\Explorer.EXE
                    C:\Windows\system32\conime.exe
                    C:\Windows\notepad.exe
                    C:\Program Files\Windows Defender\MSASCui.exe
                    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                    C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
                    C:\Windows\RtHDVCpl.exe
                    C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                    C:\Program Files\Carbonite\Carbonite Backup\CarboniteUI.exe
                    C:\Program Files\Alwil Software\Avast5\AvastUI.exe
                    C:\Program Files\Java\jre6\bin\jusched.exe
                    C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe
                    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                    C:\Program Files\Messenger\msmsgs.exe
                    C:\Program Files\Windows Media Player\wmpnscfg.exe
                    C:\Program Files\Windows Media Player\wmpnetwk.exe
                    C:\Program Files\Internet Explorer\iexplore.exe
                    C:\Program Files\Windows Live\Toolbar\wltuser.exe
                    C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
                    C:\Windows\system32\wuauclt.exe
                    C:\Windows\system32\SearchProtocolHost.exe
                    C:\Windows\system32\SearchFilterHost.exe
                    C:\Program Files\List_Kill'em\List_Kill'em.exe
                    C:\Windows\system32\cmd.exe
                    C:\Windows\system32\wbem\wmiprvse.exe
                    C:\Windows\system32\DllHost.exe
                    C:\Program Files\List_Kill'em\pv.exe

                    ======================
                    Keys "Run"
                    ======================
                    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                    SmpcSys REG_SZ C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe
                    MsnMsgr REG_SZ "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                    MSMSGS REG_SZ "C:\Program Files\Messenger\msmsgs.exe" /background

                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                    Windows Defender REG_EXPAND_SZ %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                    StartCCC REG_SZ "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
                    SynTPEnh REG_SZ C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                    RtHDVCpl REG_SZ RtHDVCpl.exe
                    Google Desktop Search REG_SZ "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
                    toolbar_eula_launcher REG_SZ C:\Program Files\Packard Bell\GOOGLE_EULA\EULALauncher.exe
                    Carbonite Backup REG_SZ C:\Program Files\Carbonite\Carbonite Backup\CarboniteUI.exe
                    Adobe Reader Speed Launcher REG_SZ "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                    avast5 REG_SZ C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui
                    SunJavaUpdateSched REG_SZ "C:\Program Files\Java\jre6\bin\jusched.exe"

                    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]

                    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]

                    =====================
                    Other Keys
                    =====================
                    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
                    ConsentPromptBehaviorAdmin REG_DWORD 2 (0x2)
                    ConsentPromptBehaviorUser REG_DWORD 1 (0x1)
                    EnableInstallerDetection REG_DWORD 1 (0x1)
                    EnableLUA REG_DWORD 0 (0x0)
                    EnableSecureUIAPaths REG_DWORD 1 (0x1)
                    EnableVirtualization REG_DWORD 1 (0x1)
                    PromptOnSecureDesktop REG_DWORD 1 (0x1)
                    ValidateAdminCodeSignatures REG_DWORD 0 (0x0)
                    dontdisplaylastusername REG_DWORD 0 (0x0)
                    legalnoticecaption REG_SZ
                    legalnoticetext REG_SZ
                    scforceoption REG_DWORD 0 (0x0)
                    shutdownwithoutlogon REG_DWORD 1 (0x1)
                    undockwithoutlogon REG_DWORD 1 (0x1)
                    FilterAdministratorToken REG_DWORD 0 (0x0)
                    EnableUIADesktopToggle REG_DWORD 0 (0x0)

                    ===============
                    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]

                    ===============
                    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]

                    ===============
                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
                    AppInit_DLLS REG_SZ C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL

                    ===============
                    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
                    ReportBootOk REG_SZ 1
                    Shell REG_SZ explorer.exe
                    Userinit REG_SZ C:\Windows\system32\userinit.exe,
                    VmApplet REG_SZ rundll32 shell32,Control_RunDLL "sysdm.cpl"
                    AutoRestartShell REG_DWORD 1 (0x1)
                    LegalNoticeCaption REG_SZ
                    LegalNoticeText REG_SZ
                    PowerdownAfterShutdown REG_SZ 0
                    ShutdownWithoutLogon REG_SZ 0
                    cachedlogonscount REG_SZ 10
                    forceunlocklogon REG_DWORD 0 (0x0)
                    passwordexpirywarning REG_DWORD 14 (0xe)
                    Background REG_SZ 0 0 0
                    DebugServerCommand REG_SZ no
                    WinStationsDisabled REG_SZ 0
                    DisableCAD REG_DWORD 1 (0x1)
                    scremoveoption REG_SZ 0
                    ShutdownFlags REG_DWORD 5 (0x5)

                    ===============

                    ===============
                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]

                    ===============
                    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

                    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

                    ===============
                    ActivX controls
                    ===============
                    [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{8AD9C840-044E-11D1-B3E9-00805F499D93}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}]

                    ===============
                    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{26923b43-4d38-484f-9b9e-de460746276c}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{08B0E5C0-4FCB-11CF-AAA5-00401C608500}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2179C5D3-EBFF-11CF-B6FD-00AA00B4E220}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{233C1507-6A77-46A4-9443-F871F945D258}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2A202491-F00D-11cf-87CC-0020AFEECF20}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{3af36230-a269-11d1-b5bf-0000f8051515}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA848-CC51-11CF-AAFA-00AA00B6015C}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA855-CC51-11CF-AAFA-00AA00B6015F}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{45ea75a0-a269-11d1-b5bf-0000f8051515}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4f645220-306d-11d2-995d-00c04f98bbc9}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5fd399c0-a70a-11d1-9948-00c04f98bbc9}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{630b1da0-b465-11d1-9948-00c04f98bbc9}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6fab99d0-bab8-11d1-994a-00c04f98bbc9}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7C028AF8-F614-47B3-82DA-BA94E41B1089}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4340}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4383}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9381D8F2-0288-11D0-9501-00AA00B911A5}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C6BAF60B-6E91-453F-BFF9-D3789CFEFCDD}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C9E9A340-D1F1-11D0-821E-444553540600}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CDD7975E-60F8-41d5-8149-19E51D6F71D0}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{D27CDB6E-AE6D-11CF-96B8-444553540000}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{de5aed00-a4bf-11d1-9948-00c04f98bbc9}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{E92B03AB-B707-11d2-9CBD-0000F87A369E}]

                    ==============
                    BHO :
                    ======
                    [<NO NAME> REG_SZ ]
                    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{bc4be15d-6a34-4356-9e97-79e43da32b1d}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{C84D72FE-E17D-4195-BB24-76C02E2E7C4E}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{CA6319C0-31B7-401E-A518-A07C3DB8F777}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10}]

                    ===
                    DNS
                    ===

                    HKLM\SYSTEM\CCS\Services\Tcpip\..\{B27DA94F-ED12-447C-A8FD-CDBDEFF2F303}: DhcpNameServer=192.168.1.1

                    ================
                    Internet Explorer :
                    ================
                    [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
                    Start Page REG_SZ https://www.msn.com/fr-fr/?ocid=iehp

                    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                    Start Page REG_SZ https://www.google.fr/?gws_rd=ssl

                    ========
                    Services
                    ========
                    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services]

                    Ndisuio : 0x3 ( OK = 3 )
                    EapHost : 0x3 ( OK = 2 )
                    Wlansvc : 0x2 ( OK = 2 )
                    SharedAccess : 0x4 ( OK = 2 )
                    windefend : 0x2 ( OK = 2 )
                    wuauserv : 0x2 ( OK = 2 )
                    wscsvc : 0x2 ( OK = 2 )

                    =========
                    Atapi.sys
                    =========

                    %%%% HASHDEEP-1.0
                    %%%% size,md5,sha256,filename
                    ## Invoked from: C:\Program Files\List_Kill'em
                    ## C:\> hashdeep.exe C:\Windows\SoftwareDistribution\Download\cd2b15b1a90e884578188440a1660b12\x86_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_df23a1261eab99e8\atapi.sys
                    ##
                    19944,1f05b78ab91c9075565a9d8a4b880bc4,737be9f9376dab0ccdfed93ea6d67f0c432367ea63cd772a453485be769af3bd,C:\Windows\SoftwareDistribution\Download\cd2b15b1a90e884578188440a1660b12\x86_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_df23a1261eab99e8\atapi.sys
                    %%%% HASHDEEP-1.0
                    %%%% size,md5,sha256,filename
                    ## Invoked from: C:\Program Files\List_Kill'em
                    ## C:\> hashdeep.exe C:\Windows\System32\drivers\atapi.sys
                    ##
                    21560,2d9c903dc76a66813d350a562de40ed9,82609f01a08c6842e4c17c077bb641c1429c0e6657964b7f2d114035e1bdcbf3,C:\Windows\System32\drivers\atapi.sys
                    %%%% HASHDEEP-1.0
                    %%%% size,md5,sha256,filename
                    ## Invoked from: C:\Program Files\List_Kill'em
                    ## C:\> hashdeep.exe C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys
                    ##
                    19048,4f4fcb8b6ea06784fb6d475b7ec7300f,6202d85c9a75e3f01f5f94f069c4cd8a2b9295a182301eae5940ec3bc2c1d896,C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys
                    %%%% HASHDEEP-1.0
                    %%%% size,md5,sha256,filename
                    ## Invoked from: C:\Program Files\List_Kill'em
                    ## C:\> hashdeep.exe C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_cc18792d\atapi.sys
                    ##
                    21560,2d9c903dc76a66813d350a562de40ed9,82609f01a08c6842e4c17c077bb641c1429c0e6657964b7f2d114035e1bdcbf3,C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_cc18792d\atapi.sys
                    %%%% HASHDEEP-1.0
                    %%%% size,md5,sha256,filename
                    ## Invoked from: C:\Program Files\List_Kill'em
                    ## C:\> hashdeep.exe C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a2189ce9c\atapi.sys
                    ##
                    21560,2d9c903dc76a66813d350a562de40ed9,82609f01a08c6842e4c17c077bb641c1429c0e6657964b7f2d114035e1bdcbf3,C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a2189ce9c\atapi.sys

                    Référence :
                    ==========

                    Win 2000_SP2 : ff953a8f08ca3f822127654375786bbe
                    Win 2000_SP4 : 8c718aa8c77041b3285d55a0ce980867
                    Win XP_32b : a64013e98426e1877cb653685c5c0009
                    Win XP_SP2_32b : CDFE4411A69C224BD1D11B2DA92DAC51
                    Win XP_SP3_32b : 9F3A2F5AA6875C72BF062C712CFA2674
                    Vista_32b : e03e8c99d15d0381e02743c36afc7c6f
                    Vista_SP1_32b : 2d9c903dc76a66813d350a562de40ed9
                    Vista_SP2_32b : 1F05B78AB91C9075565A9D8A4B880BC4
                    Vista_SP2_64b : 1898FAE8E07D97F2F6C2D5326C633FAC
                    Windows 7_32b : 80C40F7FDFC376E4C5FEEC28B41C119E
                    Windows 7_64b : 02062C0B390B7729EDC9E69C680A6F3C
                    Windows 7_32b_Ultimate : 338c86357871c167a96ab976519bf59e

                    =======
                    Drive :
                    =======

                    D'fragmenteur de disque Windows
                    Copyright (c) 2006 Microsoft Corp.

                    Rapport d'analyse pour le volume C: HDD

                    Taille du volume = 137 Go
                    Espace libre = 24.63 Go
                    tendue d'espace libre la plus grande = 1.36 Go
                    Pourcentage de fragmentation des fichiers = 1 %

                    Remarqueÿ: sur les volumes NTFS, les fragments de fichiers de plus de 64ÿMo ne sont pas inclus dans les statistiques de fragmentation.

                    Il n'est pas n'cessaire de d'fragmenter ce volume.

                    ¤¤¤¤¤¤¤¤¤¤ Files/folders :

                    Present !! : C:\Program Files\Carbonite
                    Present !! : C:\Program Files\P2P_Torrent
                    Present !! : File

                    ¤¤¤¤¤¤¤¤¤¤ Keys :

                    Present !! : "HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}"
                    Present !! : "HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}"
                    Present !! : HKCR\BitDownload
                    Present !! : HKLM\SOFTWARE\Classes\BitDownload

                    ============

                    catchme 0.3.1398.3 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                    Rootkit scan 2010-03-22 10:09:17
                    Windows 6.0.6001 Service Pack 1 FAT NTAPI

                    scanning hidden processes ...

                    scanning hidden services ...

                    scanning hidden autostart entries ...

                    scanning hidden files ...

                    scan completed successfully
                    hidden processes: 0
                    hidden services: 0
                    hidden files: 0

                    Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

                    device: opened successfully
                    user: MBR read successfully
                    called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll ataport.SYS pciide.sys PCIIDEX.SYS atapi.sys
                    kernel: MBR read successfully
                    user & kernel MBR OK

                    ¤¤¤¤¤¤¤¤¤¤ Cracks | Keygens | Serials

                    ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

                    End of scan : 10:09:50,84
                    1. alors jespere avoir tout bien respecté,
                      apresent je redemarre le pc,
                      ca me fais stresser de savoir mon ordi sans protection..(lol..)
                      a tt a l hr...

                      moment de grace.. lol bien trouvé !!
                      1. Contributeur sécurité
                        (sourire)

                        coupes internet pendant killem et les protections désactivées
                        mais opération inverse pour revenir ici

                        ? Relance List_Kill'em(soit en clic droit pour vista/7),avec le raccourci sur ton bureau.
                        mais cette fois-ci :

                        ? choisis l'option CLEAN
                        ton PC va redemarrer,

                        laisse travailler l'outil.

                        en fin de scan la fenetre se ferme , et tu as un rapport du nom de Kill'em.txt sur ton bureau ,

                        ? colle le contenu dans ta reponse

                        Tu peux le désinstaller ensuite
                        1. ... tu envoies souvent (sourire), tu te moques ? lol..
                          Bah la tu vas avoir l occass...
                          alors, jpense avoir attein mes limites.. desolée
                          jai mis internet en hors connection (jsais pas faire antrement..)
                          puis jai lancé List_Kill'em via un raccourci sur mon bureau
                          puis jai choisi clean, comme je pense avoir compris,
                          mon pc a redemarré,
                          jai du repeté loperation a 2 reprise, car je ne trouve pas de rapport a te renvoyer..
                          il y a bien un dossier a ce nom mais il reste vide..
                          il y a un seconde icone sur mon bureau avec cette fois ci , List_Kill'em uninstall que je n ai pas utilisé ( cest bon ?)
                          et qu entend tu par "protection desactivé"
                          1. mais je retente !!!
                            car jviens de penser que jai reactivé l ULC ???
                            et mon anti virus..
                            Ca peut jouer?
                            1. Contributeur sécurité
                              oui ce sont celles tes protections

                              quant aux rapports ils se trouve en general sur ta partition C
                              1. Kill'em by g3n-h@ckm@n 1.6.0.3

                                User : marion (Administrateurs)
                                Update on 21/03/2010 by g3n-h@ckm@n ::::: 18.30
                                Start at: 11:17:28 | 22/03/2010

                                AMD Turion(tm) X2 Ultra Dual-Core Mobile ZM-80
                                Microsoft® Windows Vista(TM) Édition Familiale Premium (6.0.6001 32-bit) # Service Pack 1
                                Internet Explorer 7.0.6001.18000
                                Windows Firewall Status : Enabled

                                C:\ -> Disque fixe local | 137,05 Go (24,92 Go free) [HDD] | NTFS
                                D:\ -> Disque fixe local | 298,09 Go (297,62 Go free) | NTFS
                                E:\ -> Disque CD-ROM

                                ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running

                                C:\Windows\System32\smss.exe
                                C:\Windows\system32\csrss.exe
                                C:\Windows\system32\csrss.exe
                                C:\Windows\system32\wininit.exe
                                C:\Windows\system32\services.exe
                                C:\Windows\system32\lsass.exe
                                C:\Windows\system32\lsm.exe
                                C:\Windows\system32\winlogon.exe
                                C:\Windows\system32\svchost.exe
                                C:\Windows\system32\svchost.exe
                                C:\Windows\System32\svchost.exe
                                C:\Windows\system32\Ati2evxx.exe
                                C:\Windows\System32\svchost.exe
                                C:\Windows\System32\svchost.exe
                                C:\Windows\system32\svchost.exe
                                C:\Windows\system32\LogonUI.exe
                                C:\Windows\system32\SLsvc.exe
                                C:\Windows\system32\svchost.exe
                                C:\Windows\system32\Ati2evxx.exe
                                C:\Windows\system32\svchost.exe
                                C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
                                C:\Windows\System32\spoolsv.exe
                                C:\Windows\system32\svchost.exe
                                C:\Windows\system32\taskeng.exe
                                C:\Windows\system32\userinit.exe
                                C:\Windows\system32\Dwm.exe
                                C:\Windows\Explorer.EXE
                                C:\Windows\system32\runonce.exe
                                C:\Windows\system32\taskeng.exe
                                C:\Windows\system32\cmd.exe
                                C:\Windows\system32\conime.exe
                                C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
                                C:\Program Files\Carbonite\Carbonite Backup\carboniteservice.exe
                                C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
                                C:\Windows\system32\IoctlSvc.exe
                                C:\Windows\system32\svchost.exe
                                C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                                C:\Windows\system32\svchost.exe
                                C:\Windows\System32\svchost.exe
                                C:\Windows\system32\SearchIndexer.exe
                                C:\Windows\system32\wbem\wmiprvse.exe
                                C:\Program Files\List_Kill'em\ERUNT.EXE
                                C:\Program Files\List_Kill'em\pv.exe

                                Detections :
                                ==========

                                ¤¤¤¤¤¤¤¤¤¤ Files/folders :

                                Quarantined & Deleted !! : C:\Program Files\Carbonite
                                Quarantined & Deleted !! : C:\Program Files\P2P_Torrent

                                Quarantined & Deleted !! : File
                                Deleted !! : C:\$Recycle.bin\S-1-5-21-167161423-2884399284-2469616292-1000\$I6VNO1N.dat
                                Deleted !! : C:\$Recycle.bin\S-1-5-21-167161423-2884399284-2469616292-1000\$R6VNO1N.dat

                                ==============
                                host file OK !
                                ==============

                                ========
                                Registry
                                ========

                                Deleted : "HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}"
                                Deleted : "HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}"
                                Deleted : HKCR\BitDownload
                                ========
                                Services
                                =========

                                Ndisuio : Start = 3
                                EapHost : Start = 2
                                Wlansvc : Start = 2
                                SharedAccess : Start = 2
                                windefend : Start = 2
                                wuauserv : Start = 2
                                wscsvc : Start = 2

                                ============
                                Disk Cleaned
                                ============

                                =================
                                anti-ver blaster : OK !!
                                =================

                                ================
                                Prefetch cleaned
                                ================

                                ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
                                1. Contributeur sécurité
                                  tres bien

                                  Téléchargez MalwareByte's Anti-Malware (que tu pourras garder)

                                  http://www.malwarebytes.org/mbam/program/mbam-setup.exe

                                  . Enregistres le sur le bureau
                                  . Double cliques sur le fichier téléchargé pour lancer le processus d'installation.
                                  . Dans l'onglet "mise à jour", cliques sur le bouton Recherche de mise à jour
                                  . Si le pare-feu demande l'autorisation de se connecter pour malwarebytes, accepte
                                  . Une fois la mise à jour terminé
                                  . Rend-toi dans l'onglet, Recherche
                                  . Sélectionnes Exécuter un examen complet (examen assez long)
                                  . Cliques sur Rechercher
                                  . Le scan démarre.
                                  . A la fin de l'analyse, un message s'affiche : L'examen s'est terminé normalement. Cliquez sur 'Afficher les résultats' pour afficher tous les objets trouvés.
                                  . Cliques sur Ok pour poursuivre.
                                  . Si des malwares ont été détectés, clique sur Afficher les résultats
                                  . Sélectionnes tout (ou laisses cochés) et cliques sur Supprimer la sélection Malwarebytes va détruire les fichiers et clés de registre et en mettre une copie dans la quarantaine.
                                  . Malwarebytes va ouvrir le bloc-notes et y copier le rapport d'analyse.
                                  . Rends toi dans l'onglet rapport/log
                                  . Tu cliques dessus pour l'afficher, une fois affiché
                                  . Tu cliques sur edition en haut du boc notes, et puis sur sélectionner tous
                                  . Tu recliques sur edition et puis sur copier et tu reviens sur le forum et dans ta réponse
                                  . tu cliques droit dans le cadre de la reponse et coller

                                  Si tu as besoin d'aide regarde ces tutoriels :
                                  Aide: https://www.malekal.com/tutoriel-malwarebyte-anti-malware/
                                  http://www.infos-du-net.com/forum/278396-11-tuto-malwarebytes-anti-malware-mbam

                                  1. ok, le scan est lancer,
                                    mais je releve que mon disque dur externe nest pas conserné..
                                    cest normal nest pas ? tu as bien dis precedement que lon verrait ca plus tard..
                                    1. Contributeur sécurité
                                      oui je te le confirme...plus tard

                                      apres MBAM que tu as lancé
                                      • 1
                                      • 2