Trojan

apres que avira aie decouvert dans un scan le trojan Tr/crypt.xpack.gen

je l'ai effacé selon une methode trouvée sur internet
https://www.clubic.com/forum/t/trojan-tr-crypt-xpack-gen/394052

le pb c'est que sur mon lecteur Mp3 un samsung U5, il réaparait a chaque fois sous la forme d'un fichier completement chelou intitulé svchost.exe
avira ne veut pas l'analyser disant que l'analyse a été in terompue comment faire ?

27 réponses

Résumé de la discussion

Un utilisateur signale qu'Avira détecte le Trojan Tr/crypt.xpack.gen et qu'après suppression, un fichier malveillant nommé svchost.exe réapparaît systématiquement sur un lecteur MP3 USB. Plusieurs réponses proposent des outils et méthodes pour nettoyer les supports externes, notamment USBFix pour analyser et nettoyer les clés USB et obtenir un rapport, et l'outil mbr.exe pour détecter les rootkits sur le MBR. Des avertissements apparaissent sur la nécessité de désactiver temporairement les protections et de brancher les supports non ouverts, puis de partager le rapport UsbFix.txt pour confirmer le nettoyage. Certains évoquent aussi le risque de faux positifs et recommandent de vérifier avec des outils complémentaires et de contacter les développeurs pour clarifier les résultats.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    bonjour

    * Télécharge Random's System Information Tool (RSIT) de Random/Random.

    (outil de diagnostic)

    http://images.malwareremoval.com/random/RSIT.exe

    * Enregistre le sur ton Bureau.

    * Double clique sur RSIT.exe pour lancer l'outil.

    * Clique sur "Continue" à l'écran Disclaimer.

    * Si l'outil HijackThis n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu s'il te le demande)

    et tu devras accepter la licence.

    * Une fois le scan terminé, deux rapports vont apparaître : poste les dans deux messages séparés stp

    Les rapports se trouvent à cet endroit:
    C:\rsit\info.txt
    C:\rsit\log.txt
    1. info.txt logfile of random's system information tool 1.06 2010-04-01 17:08:22

      ======Uninstall list======

      -->C:\Program Files\Ahead\nero\uninstall\UNNERO.exe /UNINSTALL
      -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
      7-Zip 4.65-->"C:\Program Files\7-Zip\Uninstall.exe"
      Adobe Acrobat 5.0-->C:\WINDOWS\ISUNINST.EXE -f"C:\Program Files\Fichiers communs\Adobe\Acrobat 5.0\NT\Uninst.isu" -c"C:\Program Files\Fichiers communs\Adobe\Acrobat 5.0\NT\Uninst.dll"
      Adobe After Effects CS3 Presets-->MsiExec.exe /I{193EAFD0-1BAF-4FB4-B18F-79D5D6A4B285}
      Adobe After Effects CS3-->MsiExec.exe /I{EB0202F7-016A-410C-ADE4-40F848CCC661}
      Adobe Anchor Service CS3-->MsiExec.exe /I{90176341-0A8B-4CCC-A78D-F862228A6B95}
      Adobe Asset Services CS3-->MsiExec.exe /I{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}
      Adobe Bridge CS3-->MsiExec.exe /I{9C9824D9-9000-4373-A6A5-D0E5D4831394}
      Adobe Bridge Start Meeting-->MsiExec.exe /I{08B32819-6EEF-4057-AEDA-5AB681A36A23}
      Adobe BridgeTalk Plugin CS3-->MsiExec.exe /I{B73CFB12-C814-4638-AFFD-7E3AAFAF0B4E}
      Adobe Camera Raw 4.0-->MsiExec.exe /I{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}
      Adobe CMaps-->MsiExec.exe /I{A2B242BD-FF8D-4840-9DAA-9170EABEC59C}
      Adobe Color - Photoshop Specific-->MsiExec.exe /I{A2D81E70-2A98-4A08-A628-94388B063C5E}
      Adobe Color Common Settings-->MsiExec.exe /I{DADD7B8A-BCB0-44F5-967A-ECB6B4F2ECD9}
      Adobe Color EU Recommended Settings-->MsiExec.exe /I{73B5D990-04EA-4751-B10F-5534770B91F2}
      Adobe Color JA Extra Settings-->MsiExec.exe /I{DD7DB3C5-6FA3-4FA3-8A71-C2F2940EB029}
      Adobe Color NA Extra Settings-->MsiExec.exe /I{FF29A7E2-FF40-4D07-B7E4-2093DE59E10A}
      Adobe Contribute CS3-->MsiExec.exe /I{F84ADE4E-9220-4324-994D-801EDD9DD251}
      Adobe Creative Suite 3 Master Collection-->MsiExec.exe /I{5D2398DF-3022-4820-93BA-F1175FBEA9CA}
      Adobe Default Language CS3-->MsiExec.exe /I{B9B35331-B7E4-4E5C-BF4C-7BC87856124D}
      Adobe Device Central CS3-->MsiExec.exe /I{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}
      Adobe Dreamweaver CS3-->MsiExec.exe /I{4BDB76C6-902E-41D5-9064-68768E02886B}
      Adobe Encore CS3 Codecs-->MsiExec.exe /I{B8B7A4D8-80E1-4DAE-BD33-7FD535BA3931}
      Adobe Encore CS3-->MsiExec.exe /I{54B2EAD9-A110-43F7-B010-2859A1BD2AFE}
      Adobe ExtendScript Toolkit 2-->MsiExec.exe /I{C2D69781-F392-4118-A5A7-C7E9C38DBFC2}
      Adobe Extension Manager CS3-->MsiExec.exe /I{BE5F3842-8309-4754-92D5-83E02E6077A3}
      Adobe Fireworks CS3-->MsiExec.exe /I{21C4D775-368A-46C4-8DC3-4207165B7115}
      Adobe Flash CS3-->MsiExec.exe /I{80FD3971-8482-49C8-BA8C-B6464A15882F}
      Adobe Flash Player 10 Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
      Adobe Flash Player 9 ActiveX-->MsiExec.exe /X{BC4F8E84-5E29-49EC-B4E7-E6F9CB50986C}
      Adobe Flash Video Encoder-->MsiExec.exe /I{1B0BCA28-1F11-4D60-8A2F-DEBE04B5341E}
      Adobe Fonts All-->MsiExec.exe /I{6ABE0BEE-D572-4FE8-B434-9E72A289431B}
      Adobe Help Viewer CS3-->MsiExec.exe /I{7ACFB90E-8FD0-4397-AD3A-5195412623A3}
      Adobe Illustrator CS3-->MsiExec.exe /I{6E08CE13-C2AB-4749-9335-5900B958929E}
      Adobe InDesign CS3 Icon Handler-->MsiExec.exe /I{EA7B3CC4-366D-4CF6-8350-FD7A7034116E}
      Adobe InDesign CS3-->MsiExec.exe /I{FE8327F9-3AC1-4586-8C7E-3DEE2BC92441}
      Adobe Linguistics CS3-->MsiExec.exe /I{54793AA1-5001-42F4-ABB6-C364617C6078}
      Adobe MotionPicture Color Files-->MsiExec.exe /I{6B708481-748A-4EB4-97C1-CD386244FF77}
      Adobe PDF Library Files-->MsiExec.exe /I{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}
      Adobe Photoshop CS3-->MsiExec.exe /I{C1FA4B3B-1625-4922-9C9D-780E8FCE161A}
      Adobe Premiere Pro CS3 Functional Content-->MsiExec.exe /I{50F102CA-4BE2-41A9-9810-5BB05EB91B9A}
      Adobe Premiere Pro CS3 Third Party Content-->MsiExec.exe /I{485ACF57-F364-440A-8496-E1E81C8FA1AA}
      Adobe Premiere Pro CS3-->MsiExec.exe /I{58DCEEE5-532E-44F4-B1D7-A146EF9E9FDA}
      Adobe Setup-->MsiExec.exe /I{1628F6BD-5ED1-4FD1-B90F-C106AF4E00F0}
      Adobe SING CS3-->MsiExec.exe /I{B671CBFD-4109-4D35-9252-3062D3CCB7B2}
      Adobe Soundbooth CS3 Codecs-->MsiExec.exe /I{0327FA9D-975C-448C-A086-577D57BB25B8}
      Adobe Soundbooth CS3-->MsiExec.exe /I{A6B23EFA-6590-482C-A11F-5ACE1B91F5B9}
      Adobe Stock Photos CS3-->MsiExec.exe /I{29E5EA97-5F74-4A57-B8B2-D4F169117183}
      Adobe Type Support-->MsiExec.exe /I{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}
      Adobe Update Manager CS3-->MsiExec.exe /I{E69AE897-9E0B-485C-8552-7841F48D42D8}
      Adobe Version Cue CS3 Client-->MsiExec.exe /I{D0DFF92A-492E-4C40-B862-A74A173C25C5}
      Adobe Version Cue CS3 Server-->MsiExec.exe /I{1D58229F-C505-45CA-8223-F35F3A34B963}
      Adobe Video Profiles-->MsiExec.exe /I{845A8DB9-8802-4FD3-9FE3-938A6C46A2EC}
      Adobe WAS CS3-->MsiExec.exe /I{C5BD220A-EFE8-48A5-B70E-9503D535FACE}
      Adobe WinSoft Linguistics Plugin-->MsiExec.exe /I{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}
      Adobe XMP DVA Panels CS3-->MsiExec.exe /I{0224CACC-994D-45F8-B973-D65056EA9C2F}
      Adobe XMP Panels CS3-->MsiExec.exe /I{D5A31AB1-345D-47C7-A87B-036A669F6DF1}
      AHV content for Acrobat and Flash-->MsiExec.exe /I{6BBAA81D-6A7E-43AD-8889-2F002DCAAFDD}
      Ajouter ou supprimer Adobe Creative Suite 3 Master Collection-->C:\Program Files\Fichiers communs\Adobe\Installers\b5d5789539ea1f004a4defceea74312\Setup.exe
      Assistant de connexion Windows Live-->MsiExec.exe /I{DCE8CD14-FBF5-4464-B9A4-E18E473546C7}
      Avira AntiVir Personal - Free Antivirus-->C:\Program Files\Avira\AntiVir PersonalEdition Classic\SETUP.EXE /REMOVE
      BSPlayer-->"C:\Program Files\Webteh\BSplayer\uninstall.exe"
      CCleaner-->"C:\Program Files\CCleaner\uninst.exe"
      C-Media 3D Audio-->C:\WINDOWS\CMIUnInstall.exe
      Counter-Strike: Source-->"C:\Program Files\Steam\steam.exe" steam://uninstall/240
      DAEMON Tools-->MsiExec.exe /I{3DED3A72-61A8-4B87-98A5-EF0BC8038AA0}
      EASEUS Data Recovery Wizard 4.3.6-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{46D61287-50D4-46B9-B10B-B6DBCD023873}\setup.exe" -l0x9 -removeonly
      eMule-->"C:\Program Files\eMule\Uninstall.exe"
      foobar2000 v1.0.1-->"C:\Program Files\foobar2000\uninstall.exe" _?=C:\Program Files\foobar2000
      Half-Life 2-->"C:\Program Files\Steam\steam.exe" steam://uninstall/220
      HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
      Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
      Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
      Hotfix for Windows XP (KB915865)-->"C:\WINDOWS\$NtUninstallKB915865$\spuninst\spuninst.exe"
      Intel(R) Extreme Graphics 2 Driver-->RUNDLL32.EXE C:\WINDOWS\system32\ialmrem.dll,UninstallW2KIGfx PCI\VEN_8086&DEV_2572
      Java(TM) 6 Update 18-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216013FF}
      Microsoft .NET Framework 2.0 Service Pack 2-->MsiExec.exe /I{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}
      Microsoft .NET Framework 3.0 Service Pack 2-->MsiExec.exe /I{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}
      Microsoft .NET Framework 3.5 SP1-->C:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
      Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
      Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
      Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB938127-v2)-->"C:\WINDOWS\ie7updates\KB938127-v2-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB978207)-->"C:\WINDOWS\ie7updates\KB978207-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB923789)-->C:\WINDOWS\system32\MacroMed\Flash\genuinst.exe C:\WINDOWS\system32\MacroMed\Flash\KB923789.inf
      Mise à jour de sécurité pour Windows XP (KB944338-v2)-->"C:\WINDOWS\$NtUninstallKB944338-v2$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB975713)-->"C:\WINDOWS\$NtUninstallKB975713$\spuninst\spuninst.exe"
      Mise à jour pour Windows XP (KB978207)-->"C:\WINDOWS\$NtUninstallKB978207$\spuninst\spuninst.exe"
      Mozilla Firefox (3.6)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
      MSXML 6 Service Pack 2 (KB973686)-->MsiExec.exe /I{56EA8BC0-3751-4B93-BC9D-6651CC36E5AA}
      Nero Suite-->C:\Program Files\Fichiers communs\Ahead\Uninstall\setup.exe /uninstall ExtraUninstallID=""
      NVIDIA Display Control Panel-->C:\Program Files\NVIDIA Corporation\Uninstall\nvuninst.exe DisplayControlPanel
      NVIDIA Drivers-->C:\Program Files\NVIDIA Corporation\Uninstall\nvuninst.exe UninstallGUI
      NVIDIA nView Desktop Manager-->C:\Program Files\NVIDIA Corporation\nView\nViewSetup.exe -uninstall
      Oblivion - Horse Armor Pack-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3ABEBD00-299D-4DCA-967F-B912163AB5EA}\setup.exe" -l0x9 -removeonly
      Oblivion - Knights of the Nine-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{14C87AA7-08E6-419F-A165-998EBE5023D7}\setup.exe" -l0x9 -removeonly
      Oblivion - Mehrunes Razor-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{EF295F5C-7B57-47AA-8889-6B3E8E214E89}\setup.exe" -l0x9 -removeonly
      Oblivion - Orrery-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{EC425CFC-EE78-4A91-AA25-3BFA65B75364}\setup.exe" -l0x9 -removeonly
      Oblivion - Spell Tomes-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{16D919E6-F019-4E15-BFBE-4A85EF19DA57}\setup.exe" -l0x9 -removeonly
      Oblivion - The Fighter's Stronghold-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A0A20753-92DF-4631-82B4-9CACE2FCED6A}\setup.exe" -l0x9 -removeonly
      Oblivion - Thieves Den-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FFFFFD17-B460-41EB-93F1-C48ABAD63828}\setup.exe" -l0x9 -removeonly
      Oblivion - Vile Lair-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{520F4B09-3A51-47A2-82B0-9FF1DC2D20FA}\setup.exe" -l0x9 -removeonly
      Oblivion - Wizard's Tower-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2F2E3D62-8B8C-448F-8900-451325E50948}\setup.exe" -l0x9 -removeonly
      Oblivion-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{35CB6715-41F8-4F99-8881-6FC75BF054B0}\setup.exe" -l0x40c -removeonly
      OpenOffice.org 3.1-->MsiExec.exe /I{0FA44E79-CD7D-4E8D-A2EE-26FE05F509B6}
      Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
      PDF Settings-->MsiExec.exe /I{AC5B0C19-D851-42F4-BDA0-410ECF7F70A5}
      PhotoFiltre-->"C:\Program Files\PhotoFiltre\Uninst.exe"
      Realtek AC'97 Audio-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FB08F381-6533-4108-B7DD-039E11FBC27E}\setup.exe" -l0x40c -removeonly
      RTLSetup for Realtek RTL8139/810x Family NIC 3.00-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{97AA0C55-AFAD-4126-B21C-F1318FB6DADA}\SETUP.EXE" -l0x9 REMOVE
      Sacred Underworld-->"C:\Program Files\Ascaron Entertainment\Sacred Underworld\unins000.exe"
      Sacred-->"C:\Program Files\Ascaron Entertainment\Sacred\unins000.exe"
      Satsuki Decoder Pack-->C:\Program Files\Satsuki Decoder Pack\Uninstall.exe
      Scribus 1.3.3.13-->C:\Program Files\Scribus 1.3.3.13\uninst.exe
      SpellForce 2 - Shadow Wars-->MsiExec.exe /I{1A4E47DC-6701-4A85-AA16-C1F99A44598C}
      SpellForce 2 - Shadow Wars-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{27223691-82E0-4C93-87D9-02C0B0D3D783}\setup.exe" -l0x40c -removeonly
      SpellForce 2 Update v1.02-->C:\PROGRA~1\SPELLF~1\SPELLF~1\\UNWISE.EXE C:\PROGRA~1\SPELLF~1\SPELLF~1\\INSTALL.LOG
      Spybot - Search & Destroy-->"C:\Program Files\Spybot - Search & Destroy\unins000.exe"
      Steam-->MsiExec.exe /X{048298C9-A4D3-490B-9FF9-AB023A9238F3}
      SuperCopier2-->"C:\Program Files\SuperCopier2\SC2Uninst.exe"
      TuneUp Utilities 2009-->MsiExec.exe /I{55A29068-F2CE-456C-9148-C869879E2357}
      UltraISO Premium V9.32-->"C:\Program Files\UltraISO\unins000.exe"
      Unlocker 1.8.8-->C:\Program Files\Unlocker\uninst.exe
      Update for Microsoft .NET Framework 3.5 SP1 (KB963707)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {B2AE9C82-DC7B-3641-BFC8-87275C4F3607} /qb+ REBOOTPROMPT=""
      VideoLAN VLC media player 0.8.6d-->C:\Program Files\VideoLAN\VLC\uninstall.exe
      Winamp-->"C:\Program Files\Winamp\UninstWA.exe"
      Windows Imaging Component-->"C:\WINDOWS\$NtUninstallWIC$\spuninst\spuninst.exe"
      Windows Installer 3.1 (KB893803)-->"C:\WINDOWS\$MSI31Uninstall_KB893803v2$\spuninst\spuninst.exe"
      Windows Internet Explorer 7-->"C:\WINDOWS\ie7\spuninst\spuninst.exe"
      Windows Media Player Firefox Plugin-->MsiExec.exe /I{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}
      WinRAR Archiveur-->C:\Program Files\WinRAR\uninstall.exe
      Xfire (remove only)-->"C:\Program Files\Xfire\uninst.exe"

      ======Security center information======

      AV: Avira AntiVir PersonalEdition Classic

      ======System event log======

      Computer Name: CHABBY-E5158331
      Event Code: 1001
      Message: Le réseau n'a attribué aucune adresse à votre ordinateur (par le serveur
      DHCP) pour la carte réseau avec l'adresse réseau 00265A7F05BE. Il s'est produit
      l'erreur suivante :
      L'opération a été annulée par l'utilisateur.
      .
      Votre ordinateur va continuer à essayer d'obtenir sa propre adresse auprès du
      serveur d'adresse réseau (DHCP).

      Record Number: 49394
      Source Name: Dhcp
      Time Written: 20100313181745.000000+060
      Event Type: erreur
      User:

      Computer Name: CHABBY-E5158331
      Event Code: 4201
      Message: Le système a détecté que la carte réseau \DEVICE\TCPIP_{B6DE4B07-494B-4CA3-A3AC-407DCF12077E} était connectée au réseau,
      et a lancé une opération normale sur la carte réseau.

      Record Number: 49393
      Source Name: Tcpip
      Time Written: 20100313181745.000000+060
      Event Type: Informations
      User:

      Computer Name: CHABBY-E5158331
      Event Code: 29
      Message: Le fournisseur de temps NtpClient est configuré pour acquérir le temps à partir d'une
      ou plusieurs sources de temps, cependant aucune source n'est actuellement accessible.
      Aucune tentative pour en contacter une ne sera effectuée d'ici 14 minutes.
      NtpClient n'a pas de source de temps précis.

      Record Number: 49392
      Source Name: W32Time
      Time Written: 20100313181713.000000+060
      Event Type: erreur
      User:

      Computer Name: CHABBY-E5158331
      Event Code: 17
      Message: Fournisseur de temps NtpClient : une erreur s'est produite lors de la recherche DNS de
      l'homologue manuellement configuré 'time.windows.com,0x1'. NtpClient va essayer à nouveau
      la recherche DNS dans 15 minutes.
      L'erreur était : Une opération a été tentée sur un hôte impossible à atteindre. (0x80072751)

      Record Number: 49391
      Source Name: W32Time
      Time Written: 20100313181713.000000+060
      Event Type: erreur
      User:

      Computer Name: CHABBY-E5158331
      Event Code: 1007
      Message: Votre ordinateur a automatiquement configuré l'adresse IP pour la
      carte avec l'adresse réseau 00265A7F05BE. L'adresse IP utilisée est 169.254.22.164.

      Record Number: 49390
      Source Name: Dhcp
      Time Written: 20100313181713.000000+060
      Event Type: Avertissement
      User:

      =====Application event log=====

      Computer Name: CHABBY-E5158331
      Event Code: 103
      Message: wuaueng.dll (3600) SUS20ClientDataStore: Le moteur de base de données a arrêté une instance (0).

      Record Number: 1244
      Source Name: ESENT
      Time Written: 20090621153906.000000+120
      Event Type: Informations
      User:

      Computer Name: CHABBY-E5158331
      Event Code: 102
      Message: wuaueng.dll (3600) SUS20ClientDataStore: Le moteur de base de données a démarré une nouvelle instance (0).

      Record Number: 1243
      Source Name: ESENT
      Time Written: 20090621153405.000000+120
      Event Type: Informations
      User:

      Computer Name: CHABBY-E5158331
      Event Code: 100
      Message: wuauclt (3600) Le moteur de base de données 5.01.2600.2180 est démarré.

      Record Number: 1242
      Source Name: ESENT
      Time Written: 20090621153405.000000+120
      Event Type: Informations
      User:

      Computer Name: CHABBY-E5158331
      Event Code: 1800
      Message: Le service Centre de sécurité Windows a démarré.

      Record Number: 1241
      Source Name: SecurityCenter
      Time Written: 20090621153322.000000+120
      Event Type: Informations
      User:

      Computer Name: CHABBY-E5158331
      Event Code: 4096
      Message:
      Record Number: 1240
      Source Name: H+BEDV AntiVir
      Time Written: 20090621153316.000000+120
      Event Type: Informations
      User: AUTORITE NT\SYSTEM

      ======Environment variables======

      "ComSpec"=%SystemRoot%\system32\cmd.exe
      "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem
      "windir"=%SystemRoot%
      "FP_NO_HOST_CHECK"=NO
      "OS"=Windows_NT
      "PROCESSOR_ARCHITECTURE"=x86
      "PROCESSOR_LEVEL"=15
      "PROCESSOR_IDENTIFIER"=x86 Family 15 Model 4 Stepping 1, GenuineIntel
      "PROCESSOR_REVISION"=0401
      "NUMBER_OF_PROCESSORS"=2
      "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
      "TEMP"=%SystemRoot%\TEMP
      "TMP"=%SystemRoot%\TEMP

      -----------------EOF-----------------
      1. Logfile of random's system information tool 1.06 (written by random/random)
        Run by Chabby at 2010-04-01 17:07:31
        Microsoft Windows XP Professionnel Service Pack 2
        System drive C: has 34 GB (45%) free of 75 GB
        Total RAM: 2047 MB (71% free)

        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 17:08:18, on 01/04/2010
        Platform: Windows XP SP2 (WinNT 5.01.2600)
        MSIE: Internet Explorer v7.00 (7.00.6000.16981)
        Boot mode: Normal

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\nvsvc32.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
        C:\WINDOWS\Explorer.EXE
        C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
        C:\Program Files\Bonjour\mDNSResponder.exe
        C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
        C:\Program Files\Java\jre6\bin\jqs.exe
        C:\WINDOWS\System32\TUProgSt.exe
        C:\Program Files\Mozilla Firefox\firefox.exe
        C:\WINDOWS\system32\wuauclt.exe
        C:\Program Files\Mozilla Firefox\firefox.exe
        C:\Program Files\Unlocker\UnlockerAssistant.exe
        C:\WINDOWS\system32\igfxsrvc.exe
        C:\Documents and Settings\Chabby\Bureau\RSIT.exe
        C:\Program Files\trend micro\Chabby.exe

        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
        R3 - Default URLSearchHook is missing
        O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
        O2 - BHO: ContributeBHO Class - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll
        O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
        O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
        O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
        O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
        O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
        O3 - Toolbar: Contribute Toolbar - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll
        O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
        O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
        O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
        O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
        O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
        O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
        O23 - Service: Adobe Version Cue CS3 {fr_FR} (Adobe Version Cue CS3) - Adobe Systems Incorporated - C:\Program Files\Fichiers communs\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe
        O23 - Service: Planificateur Avira AntiVir Personal - Free Antivirus (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
        O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
        O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
        O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
        O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
        O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
        O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software - C:\WINDOWS\System32\TuneUpDefragService.exe
        O23 - Service: TuneUp Program Statistics Service (TuneUp.ProgramStatisticsSvc) - TuneUp Software - C:\WINDOWS\System32\TUProgSt.exe
        1. Contributeur sécurité
          ok

          1)
          as tu le rapport avira de cette alerte st

          2)

          Desactive ton antivirus le temps de la manip ainsi que ton parefeu si présent(car il est detecté a tort comme infection)

          Télécharge et installe List&Kill'em et enregistre le sur ton bureau

          http://sd-1.archive-host.com/...

          double clique ( clic droit "executer en tant qu'administrateur" pour Vista/7 ) sur le raccourci sur ton bureau pour lancer l'installation

          coche la case "creer une icone sur le bureau"

          une fois terminée , clic sur "terminer" et le programme se lancer seul

          choisis la langue puis choisis l'option SEARCH

          laisse travailler l'outil

          à l'apparition de la fenetre blanche , c'est un peu long , c'est normal , le programme n'est pas bloqué.

          un rapport du nom de catchme apparait sur ton bureau , ignore-le,ne le poste pas , mais ne le supprime pas pour l instant, le scan n'est pas fini.

          Poste le contenu du rapport qui s'ouvre aux 100 % du scan à l'ecran "COMPLETED"

          tu peux supprimer le rapport catchme.log de ton bureau maintenant.

          1. voici le rapport Avira

            sinon a noter que tt d'un coup mon fond d'ecran, a disparu une partie de mes icones aussi et ma config windows
            j'ai reboot le PC et la surprise le truc demare comme si il demarait pour la premiere fois ( il me propose de dfaire une visite guidée et tout ), mes parametres de dossier et d'affichage tous disparus, et impossible de repasser en mode d'affichage windows classique

            Avira AntiVir Personal
            Date de création du fichier de rapport : jeudi 1 avril 2010 13:20

            La recherche porte sur 1951744 souches de virus.

            Détenteur de la licence :Avira AntiVir Personal - FREE Antivirus
            Numéro de série : 0000149996-ADJIE-0000001
            Plateforme : Windows XP
            Version de Windows :(Service Pack 2) [5.1.2600]
            Mode Boot : Démarré normalement
            Identifiant : SYSTEM
            Nom de l'ordinateur :CHABBY-E5158331

            Informations de version :
            BUILD.DAT : 8.2.0.62 17752 Bytes 23/10/2009 13:16:00
            AVSCAN.EXE : 8.1.4.10 315649 Bytes 18/11/2008 07:21:00
            AVSCAN.DLL : 8.1.4.1 49921 Bytes 21/07/2008 12:44:27
            LUKE.DLL : 8.1.4.5 164097 Bytes 12/06/2008 11:44:16
            LUKERES.DLL : 8.1.4.0 13057 Bytes 04/07/2008 06:30:27
            ANTIVIR0.VDF : 7.10.0.0 19875328 Bytes 06/11/2009 10:59:48
            ANTIVIR1.VDF : 7.10.4.211 7108976 Bytes 05/03/2010 11:00:02
            ANTIVIR2.VDF : 7.10.6.3 1849760 Bytes 30/03/2010 11:00:06
            ANTIVIR3.VDF : 7.10.6.13 109568 Bytes 01/04/2010 11:00:07
            Version du moteur: 8.2.1.204
            AEVDF.DLL : 8.1.1.3 106868 Bytes 01/04/2010 11:00:21
            AESCRIPT.DLL : 8.1.3.23 1278331 Bytes 01/04/2010 11:00:19
            AESCN.DLL : 8.1.5.0 127347 Bytes 01/04/2010 11:00:18
            AESBX.DLL : 8.1.2.1 254323 Bytes 01/04/2010 11:00:18
            AERDL.DLL : 8.1.4.3 541043 Bytes 01/04/2010 11:00:17
            AEPACK.DLL : 8.2.1.1 426358 Bytes 01/04/2010 11:00:16
            AEOFFICE.DLL : 8.1.0.41 201083 Bytes 01/04/2010 11:00:15
            AEHEUR.DLL : 8.1.1.16 2503031 Bytes 01/04/2010 11:00:14
            AEHELP.DLL : 8.1.10.2 237941 Bytes 01/04/2010 11:00:10
            AEGEN.DLL : 8.1.3.2 373108 Bytes 01/04/2010 11:00:10
            AEEMU.DLL : 8.1.1.0 393587 Bytes 01/04/2010 11:00:09
            AECORE.DLL : 8.1.12.3 188789 Bytes 01/04/2010 11:00:08
            AEBB.DLL : 8.1.0.3 53618 Bytes 14/10/2008 09:05:56
            AVWINLL.DLL : 1.0.0.12 15105 Bytes 09/07/2008 07:40:02
            AVPREF.DLL : 8.0.2.0 38657 Bytes 16/05/2008 08:27:58
            AVREP.DLL : 8.0.0.7 159784 Bytes 01/04/2010 11:00:07
            AVREG.DLL : 8.0.0.1 33537 Bytes 09/05/2008 10:26:37
            AVARKT.DLL : 1.0.0.23 307457 Bytes 12/02/2008 07:29:19
            AVEVTLOG.DLL : 8.0.0.16 119041 Bytes 12/06/2008 11:27:46
            SQLITE3.DLL : 3.3.17.1 339968 Bytes 22/01/2008 16:28:02
            SMTPLIB.DLL : 1.2.0.23 28929 Bytes 12/06/2008 11:49:36
            NETNT.DLL : 8.0.0.1 7937 Bytes 25/01/2008 11:05:07
            RCIMAGE.DLL : 8.0.0.51 2371841 Bytes 04/07/2008 06:23:16
            RCTEXT.DLL : 8.0.52.1 86273 Bytes 17/07/2008 09:08:43

            Configuration pour la recherche actuelle :
            Nom de la tâche..................: Contrôle intégral du système
            Fichier de configuration.........: c:\program files\avira\antivir personaledition classic\sysscan.avp
            Documentation....................: bas
            Action principale................: interactif
            Action secondaire................: ignorer
            Recherche sur les secteurs d'amorçage maître: marche
            Recherche sur les secteurs d'amorçage: marche
            Secteurs d'amorçage..............: C:, D:, H:,
            Recherche dans les programmes actifs: marche
            Recherche en cours sur l'enregistrement: marche
            Recherche de Rootkits............: marche
            Fichier mode de recherche........: Tous les fichiers
            Recherche sur les archives.......: marche
            Limiter la profondeur de récursivité: 20
            Archive Smart Extensions.........: marche
            Heuristique de macrovirus........: marche
            Heuristique fichier..............: moyen

            Début de la recherche : jeudi 1 avril 2010 13:20

            La recherche d'objets cachés commence.
            '41240' objets ont été contrôlés, '0' objets cachés ont été trouvés.

            La recherche sur les processus démarrés commence :
            Processus de recherche 'avscan.exe' - '1' module(s) sont contrôlés
            Processus de recherche 'wuauclt.exe' - '1' module(s) sont contrôlés
            Processus de recherche 'avcenter.exe' - '1' module(s) sont contrôlés
            Processus de recherche 'alg.exe' - '1' module(s) sont contrôlés
            Processus de recherche 'firefox.exe' - '1' module(s) sont contrôlés
            Processus de recherche 'TUProgSt.exe' - '1' module(s) sont contrôlés
            Processus de recherche 'jqs.exe' - '1' module(s) sont contrôlés
            Processus de recherche 'avgnt.exe' - '1' module(s) sont contrôlés
            Processus de recherche 'mDNSResponder.exe' - '1' module(s) sont contrôlés
            Processus de recherche 'avguard.exe' - '1' module(s) sont contrôlés
            Processus de recherche 'explorer.exe' - '1' module(s) sont contrôlés
            Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
            Processus de recherche 'sched.exe' - '1' module(s) sont contrôlés
            Processus de recherche 'spoolsv.exe' - '1' module(s) sont contrôlés
            Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
            Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
            Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
            Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
            Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
            Processus de recherche 'nvsvc32.exe' - '1' module(s) sont contrôlés
            Processus de recherche 'lsass.exe' - '1' module(s) sont contrôlés
            Processus de recherche 'services.exe' - '1' module(s) sont contrôlés
            Processus de recherche 'winlogon.exe' - '1' module(s) sont contrôlés
            Processus de recherche 'csrss.exe' - '1' module(s) sont contrôlés
            Processus de recherche 'smss.exe' - '1' module(s) sont contrôlés
            '25' processus ont été contrôlés avec '25' modules

            La recherche sur les secteurs d'amorçage maître commence :
            Secteur d'amorçage maître HD0
            [INFO] Aucun virus trouvé !
            Secteur d'amorçage maître HD1
            [INFO] Aucun virus trouvé !

            La recherche sur les secteurs d'amorçage commence :
            Secteur d'amorçage 'C:\'
            [INFO] Aucun virus trouvé !
            Secteur d'amorçage 'D:\'
            [INFO] Aucun virus trouvé !
            Secteur d'amorçage 'H:\'
            [INFO] Aucun virus trouvé !

            La recherche sur les renvois aux fichiers exécutables (registre) commence.
            C:\WINDOWS\smss.exe
            [RESULTAT] Contient le cheval de Troie TR/Crypt.XPACK.Gen
            [REMARQUE] TR/Crypt.XPACK.Gen:[HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN]:<Windows Media Center>=sz:smss.exe
            [REMARQUE] Le fichier a été déplacé dans le répertoire de quarantaine sous le nom '4c2782d5.qua' !

            Le registre a été contrôlé ( '49' fichiers).

            La recherche sur les fichiers sélectionnés commence :

            Recherche débutant dans 'C:\'
            C:\pagefile.sys
            [AVERTISSEMENT] Impossible d'ouvrir le fichier !
            C:\System Volume Information\_restore{14AA1E58-C888-4B68-A0FA-D11FE1E365C8}\RP297\A0051000.exe
            [RESULTAT] Contient le cheval de Troie TR/Crypt.XPACK.Gen
            [REMARQUE] Le fichier a été déplacé dans le répertoire de quarantaine sous le nom '4be49524.qua' !
            Recherche débutant dans 'D:\'
            Recherche débutant dans 'H:\' <My Book>

            Fin de la recherche : jeudi 1 avril 2010 15:46
            Temps nécessaire: 2:25:30 Heure(s)

            La recherche a été effectuée intégralement

            14622 Les répertoires ont été contrôlés
            748859 Des fichiers ont été contrôlés
            2 Des virus ou programmes indésirables ont été trouvés
            0 Des fichiers ont été classés comme suspects
            0 Des fichiers ont été supprimés
            0 Des virus ou programmes indésirables ont été réparés
            2 Les fichiers ont été déplacés dans la quarantaine
            0 Les fichiers ont été renommés
            1 Impossible de contrôler des fichiers
            748856 Fichiers non infectés
            5240 Les archives ont été contrôlées
            1 Avertissements
            2 Consignes
            41240 Des objets ont été contrôlés lors du Rootkitscan
            0 Des objets cachés ont été trouvés
            1. voici le le rapport demande

              sinon uya mon mp3 qui s'est mis se connecter deconnecter a toute vitesse alors que je n'y touchait pas
              je l'ai retiré il n'estplus reconnu par le pc et ne veut meme plus s'allumer en tant que mp3

              List'em by g3n-h@ckm@n 1.7.0.1

              User : Chabby (Administrateurs)
              Update on 30/03/2010 by g3n-h@ckm@n ::::: 19.50
              Start at: 17:36:06 | 01/04/2010

              Intel(R) Pentium(R) 4 CPU 3.00GHz
              Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 2
              Internet Explorer 7.0.5730.13
              Windows Firewall Status : Disabled
              AV : Avira AntiVir PersonalEdition Classic 8.0.1.30 [ (!) Disabled | Updated ]

              A:\ -> Lecteur de disquettes 3 ½ pouces
              C:\ -> Disque fixe local | 73,24 Go (32,98 Go free) | NTFS
              D:\ -> Disque fixe local | 75,8 Go (23,85 Go free) | NTFS
              E:\ -> Disque CD-ROM
              F:\ -> Disque CD-ROM
              G:\ -> Disque amovible | 1,77 Go (1,77 Go free) [U 5] | FAT32
              H:\ -> Disque fixe local | 1396,61 Go (800,17 Go free) [My Book] | NTFS

              Boot: Normal

              ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running

              C:\WINDOWS\System32\smss.exe
              C:\WINDOWS\system32\csrss.exe
              C:\WINDOWS\system32\winlogon.exe
              C:\WINDOWS\system32\services.exe
              C:\WINDOWS\system32\lsass.exe
              C:\WINDOWS\system32\nvsvc32.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\system32\spoolsv.exe
              C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
              C:\WINDOWS\system32\svchost.exe
              C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
              C:\Program Files\Bonjour\mDNSResponder.exe
              C:\Program Files\Java\jre6\bin\jqs.exe
              C:\WINDOWS\System32\TUProgSt.exe
              C:\WINDOWS\Explorer.EXE
              C:\WINDOWS\System32\alg.exe
              C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
              C:\WINDOWS\system32\igfxsrvc.exe
              C:\WINDOWS\system32\wuauclt.exe
              C:\Program Files\Mozilla Firefox\firefox.exe
              C:\WINDOWS\system32\wuauclt.exe
              C:\WINDOWS\system32\wscntfy.exe
              C:\WINDOWS\system32\wbem\wmiprvse.exe
              C:\Program Files\List_Kill'em\List_Kill'em.exe
              C:\WINDOWS\system32\cmd.exe
              C:\WINDOWS\system32\wbem\wmiprvse.exe
              C:\WINDOWS\system32\cmd.exe
              C:\WINDOWS\system32\cmd.exe
              C:\WINDOWS\system32\findstr.exe
              C:\WINDOWS\system32\cmd.exe
              C:\Program Files\List_Kill'em\pv.exe

              ======================
              Keys "Run"
              ======================

              [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
              <NO NAME> REG_SZ
              Cmaudio REG_SZ RunDll32 cmicnfg.cpl,CMICtrlWnd
              NvCplDaemon REG_SZ RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
              avgnt REG_SZ "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min

              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]

              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]

              =====================
              Other Keys
              =====================
              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
              dontdisplaylastusername REG_DWORD 0 (0x0)
              legalnoticecaption REG_SZ
              legalnoticetext REG_SZ
              shutdownwithoutlogon REG_DWORD 1 (0x1)
              undockwithoutlogon REG_DWORD 1 (0x1)

              ===============
              [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
              NoDriveTypeAutoRun REG_DWORD 145 (0x91)

              ===============
              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
              HonorAutoRunSetting REG_DWORD 1 (0x1)

              ===============
              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
              AppInit_DLLS REG_SZ

              ===============

              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
              AutoRestartShell REG_DWORD 1 (0x1)
              DefaultDomainName REG_SZ CHABBY-E5158331
              DefaultUserName REG_SZ Chabby
              LegalNoticeCaption REG_SZ
              LegalNoticeText REG_SZ
              PowerdownAfterShutdown REG_SZ 0
              ReportBootOk REG_SZ 1
              Shell REG_SZ Explorer.exe
              ShutdownWithoutLogon REG_SZ 0
              System REG_SZ
              Userinit REG_SZ C:\WINDOWS\system32\userinit.exe,
              VmApplet REG_SZ rundll32 shell32,Control_RunDLL "sysdm.cpl"
              SfcQuota REG_DWORD -1 (0xffffffff)
              allocatecdroms REG_SZ 0
              allocatedasd REG_SZ 0
              allocatefloppies REG_SZ 0
              cachedlogonscount REG_SZ 10
              forceunlocklogon REG_DWORD 0 (0x0)
              passwordexpirywarning REG_DWORD 14 (0xe)
              scremoveoption REG_SZ 0
              AllowMultipleTSSessions REG_DWORD 1 (0x1)
              UIHost REG_EXPAND_SZ logonui.exe
              LogonType REG_DWORD 1 (0x1)
              Background REG_SZ 0 0 0
              DebugServerCommand REG_SZ no
              SFCDisable REG_DWORD 0 (0x0)
              WinStationsDisabled REG_SZ 0
              HibernationPreviouslyEnabled REG_DWORD 1 (0x1)
              ShowLogonOptions REG_DWORD 0 (0x0)
              AltDefaultUserName REG_SZ Chabby
              AltDefaultDomainName REG_SZ CHABBY-E5158331

              ===============

              [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\crypt32chain]
              [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cryptnet]
              [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cscdll]
              [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\igfxcui]
              [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ScCertProp]
              [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Schedule]
              [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\sclgntfy]
              [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\SensLogn]
              [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\termsrv]
              [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wlballoon]

              ===============

              [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]

              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
              {AEB6717E-7E19-11d0-97EE-00C04FD91972} REG_SZ

              ===============
              [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
              %windir%\system32\sessmgr.exe REG_SZ %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
              C:\Program Files\Alwil Software\Avast4\ashAvast.exe REG_SZ C:\Program Files\Alwil Software\Avast4\ashAvast.exe:*:Enabled:avast! Antivirus
              C:\Program Files\Ascaron Entertainment\Sacred Underworld\sacred.exe REG_SZ C:\Program Files\Ascaron Entertainment\Sacred Underworld\sacred.exe:*:Enabled:Sacred Underworld
              C:\Program Files\Messenger\msmsgs.exe REG_SZ C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger
              C:\Program Files\Satsuki Decoder Pack\filtres\ac3config.exe REG_SZ C:\Program Files\Satsuki Decoder Pack\filtres\ac3config.exe:*:Enabled:Ac3 filter
              C:\Program Files\Steam\Steam.exe REG_SZ C:\Program Files\Steam\Steam.exe:*:Enabled:Steam
              C:\Program Files\Valve Lan\hl.exe REG_SZ C:\Program Files\Valve Lan\hl.exe:*:Enabled:Half-Life Launcher
              C:\Program Files\Fichiers communs\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe REG_SZ C:\Program Files\Fichiers communs\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe:*:Enabled:Adobe Version Cue CS3 Server
              C:\Program Files\eMule\emule.exe REG_SZ C:\Program Files\eMule\emule.exe:*:Enabled:eMule
              C:\Program Files\Steam\SteamApps\sigmun\counter-strike source\hl2.exe REG_SZ C:\Program Files\Steam\SteamApps\sigmun\counter-strike source\hl2.exe:*:Enabled:hl2
              C:\Program Files\Bonjour\mDNSResponder.exe REG_SZ C:\Program Files\Bonjour\mDNSResponder.exe:*:Disabled:Bonjour

              [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
              %windir%\system32\sessmgr.exe REG_SZ %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019

              ===============
              ActivX controls
              ===============
              [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{8AD9C840-044E-11D1-B3E9-00805F499D93}]
              [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}]
              [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}]

              ===============
              [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\<{12d0ed0d-0ee0-4f90-8827-78cefb8f4988}]
              [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
              [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{26923b43-4d38-484f-9b9e-de460746276c}]
              [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
              [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS]
              [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
              [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{08B0E5C0-4FCB-11CF-AAA5-00401C608500}]
              [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10072CEC-8CC1-11D1-986E-00A0C955B42F}]
              [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2179C5D3-EBFF-11CF-B6FD-00AA00B4E220}]
              [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
              [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{283807B5-2C60-11D0-A31D-00AA00B92C03}]
              [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
              [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{36f8ec70-c29a-11d1-b5c7-0000f8051515}]
              [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{3af36230-a269-11d1-b5bf-0000f8051515}]
              [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{3bf42070-b3b1-11d1-b5c5-0000f8051515}]
              [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4278c270-a269-11d1-b5bf-0000f8051515}]
              [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
              [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
              [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA848-CC51-11CF-AAFA-00AA00B6015C}]
              [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA855-CC51-11CF-AAFA-00AA00B6015F}]
              [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{45ea75a0-a269-11d1-b5bf-0000f8051515}]
              [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4f216970-c90c-11d1-b5c7-0000f8051515}]
              [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4f645220-306d-11d2-995d-00c04f98bbc9}]
              [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5056b317-8d4c-43ee-8543-b9d1e234b8f4}]
              [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]
              [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5A8D6EE0-3E18-11D0-821E-444553540000}]
              [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5fd399c0-a70a-11d1-9948-00c04f98bbc9}]
              [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{630b1da0-b465-11d1-9948-00c04f98bbc9}]
              [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
              [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6fab99d0-bab8-11d1-994a-00c04f98bbc9}]
              [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}]
              [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
              [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4340}]
              [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4383}]
              [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}]
              [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9381D8F2-0288-11D0-9501-00AA00B911A5}]
              [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{ACC563BC-4266-43f0-B6ED-9D38C4202C7E}]
              [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}]
              [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C9E9A340-D1F1-11D0-821E-444553540600}]
              [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CC2A9BA0-3BDD-11D0-821E-444553540000}]
              [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CDD7975E-60F8-41d5-8149-19E51D6F71D0}]
              [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
              [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{de5aed00-a4bf-11d1-9948-00c04f98bbc9}]
              [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{E92B03AB-B707-11d2-9CBD-0000F87A369E}]

              ==============
              BHO :
              ======
              [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
              [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{074C1DC5-9320-4A9A-947D-C042949C6216}]
              [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
              [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{AE7CD045-E861-484f-8273-0445EE161910}]
              [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
              [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]

              ===
              DNS
              ===

              HKLM\SYSTEM\CCS\Services\Tcpip\..\{0F3FC40C-236C-4400-938F-F843A2AFFD77}: DhcpNameServer=212.27.40.240 212.27.40.241
              HKLM\SYSTEM\CS1\Services\Tcpip\..\{0F3FC40C-236C-4400-938F-F843A2AFFD77}: DhcpNameServer=212.27.40.240 212.27.40.241
              HKLM\SYSTEM\CS2\Services\Tcpip\..\{0F3FC40C-236C-4400-938F-F843A2AFFD77}: DhcpNameServer=212.27.40.240 212.27.40.241
              HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=212.27.40.240 212.27.40.241
              HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=212.27.40.240 212.27.40.241
              HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=212.27.40.240 212.27.40.241

              ================
              Internet Explorer :
              ================
              [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
              Start Page REG_SZ https://www.msn.com/fr-fr/?ocid=iehp

              [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
              Start Page REG_SZ https://www.msn.com/fr-fr/?ocid=iehp

              ========
              Services
              ========
              [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services]

              Ndisuio : 0x3 ( OK = 3 )
              SharedAccess : 0x2 ( OK = 2 )
              wuauserv : 0x2 ( OK = 2 )

              =========
              Atapi.sys
              =========

              %%%% HASHDEEP-1.0
              %%%% size,md5,sha256,filename
              ## Invoked from: C:\Program Files\List_Kill'em
              ## C:\> hashdeep.exe C:\WINDOWS\system32\dllcache\atapi.sys
              ##
              95360,cdfe4411a69c224bd1d11b2da92dac51,0e6b23a80f171550575bebc56f7500cd87a5cf03b2b9fdc49bc3de96282cd69d,C:\WINDOWS\system32\dllcache\atapi.sys
              %%%% HASHDEEP-1.0
              %%%% size,md5,sha256,filename
              ## Invoked from: C:\Program Files\List_Kill'em
              ## C:\> hashdeep.exe C:\WINDOWS\system32\drivers\atapi.sys
              ##
              95360,cdfe4411a69c224bd1d11b2da92dac51,0e6b23a80f171550575bebc56f7500cd87a5cf03b2b9fdc49bc3de96282cd69d,C:\WINDOWS\system32\drivers\atapi.sys
              %%%% HASHDEEP-1.0
              %%%% size,md5,sha256,filename
              ## Invoked from: C:\Program Files\List_Kill'em
              ## C:\> hashdeep.exe C:\WINDOWS\system32\ReinstallBackups\0001\DriverFiles\i386\atapi.sys
              ##
              95360,cdfe4411a69c224bd1d11b2da92dac51,0e6b23a80f171550575bebc56f7500cd87a5cf03b2b9fdc49bc3de96282cd69d,C:\WINDOWS\system32\ReinstallBackups\0001\DriverFiles\i386\atapi.sys
              %%%% HASHDEEP-1.0
              %%%% size,md5,sha256,filename
              ## Invoked from: C:\Program Files\List_Kill'em
              ## C:\> hashdeep.exe C:\WINDOWS\system32\ReinstallBackups\0005\DriverFiles\i386\atapi.sys
              ##
              95360,cdfe4411a69c224bd1d11b2da92dac51,0e6b23a80f171550575bebc56f7500cd87a5cf03b2b9fdc49bc3de96282cd69d,C:\WINDOWS\system32\ReinstallBackups\0005\DriverFiles\i386\atapi.sys

              Référence :
              ==========

              Win 2000_SP2 : ff953a8f08ca3f822127654375786bbe
              Win 2000_SP4 : 8c718aa8c77041b3285d55a0ce980867
              Win XP_32b : a64013e98426e1877cb653685c5c0009
              Win XP_SP2_32b : CDFE4411A69C224BD1D11B2DA92DAC51
              Win XP_SP3_32b : 9F3A2F5AA6875C72BF062C712CFA2674
              Vista_32b : e03e8c99d15d0381e02743c36afc7c6f
              Vista_SP1_32b : 2d9c903dc76a66813d350a562de40ed9
              Vista_SP2_32b : 1F05B78AB91C9075565A9D8A4B880BC4
              Vista_SP2_64b : 1898FAE8E07D97F2F6C2D5326C633FAC
              Windows 7_32b : 80C40F7FDFC376E4C5FEEC28B41C119E
              Windows 7_64b : 02062C0B390B7729EDC9E69C680A6F3C
              Windows 7_32b_Ultimate : 338c86357871c167a96ab976519bf59e

              =======
              Drive :
              =======

              D'fragmenteur de disque Windows
              Copyright (c) 2001 Microsoft Corp. et Executive Software International Inc.

              Rapport d'analyse
              73,24 Go total, 32,98 Go libre (45%), 0% fragment' (fragmentation du fichier 0%)

              Il ne vous est pas n'cessaire de d'fragmenter ce volume.

              ¤¤¤¤¤¤¤¤¤¤ Files/folders :

              Present !! : C:\WINDOWS\System32\aniwzcsusername
              Present !! : C:\Program Files\Mozilla FireFox\Components\AskSearch.js
              Present !! : C:\WINDOWS\SET3.tmp
              Present !! : C:\WINDOWS\SET4.tmp
              Present !! : C:\WINDOWS\SET8.tmp
              Present !! : C:\WINDOWS\System32\aniwzcsusername
              Present !! : C:\Documents and Settings\Chabby\Application Data\Desktopicon
              Present !! : C:\Documents and Settings\Chabby\Application Data\Microsoft\svchost.exe
              Present !! : C:\Documents and Settings\Chabby\Local Settings\Temp\amt.log
              Present !! : C:\Documents and Settings\Chabby\LOCAL Settings\Temp\uerjoiq2w.exe
              Present !! : C:\Documents and Settings\Chabby\LOCAL Settings\Temp\update.exe
              Present !! : C:\Documents and Settings\Chabby\LOCAL Settings\Temp\NTUSER.DAT_BAK_67880
              Present !! : C:\Documents and Settings\Chabby\LOCAL Settings\Temp\NTUSER.DAT_BAK_44254
              Present !! : C:\Documents and Settings\Chabby\LOCAL Settings\Temp\NTUSER.DAT_BAK_95902
              Present !! : C:\Documents and Settings\Chabby\LOCAL Settings\Temp\UsrClass.dat_BAK_28149
              Present !! : C:\Documents and Settings\Chabby\LOCAL Settings\Temp\UsrClass.dat_BAK_49532
              Present !! : C:\Documents and Settings\Chabby\LOCAL Settings\Temp\UsrClass.dat_BAK_91788

              ¤¤¤¤¤¤¤¤¤¤ Keys :

              Present !! : C:\Documents and Settings\Chabby\Application Data\Desktopicon
              Present !! : C:\Documents and Settings\Chabby\Application Data\Microsoft\svchost.exe
              Present !! : C:\Documents and Settings\Chabby\Local Settings\Temp\amt.log
              Present !! : C:\Documents and Settings\Chabby\LOCAL Settings\Temp\uerjoiq2w.exe
              Present !! : C:\Documents and Settings\Chabby\LOCAL Settings\Temp\update.exe
              Present !! : C:\Documents and Settings\Chabby\LOCAL Settings\Temp\NTUSER.DAT_BAK_67880
              Present !! : C:\Documents and Settings\Chabby\LOCAL Settings\Temp\NTUSER.DAT_BAK_44254
              Present !! : C:\Documents and Settings\Chabby\LOCAL Settings\Temp\NTUSER.DAT_BAK_95902
              Present !! : C:\Documents and Settings\Chabby\LOCAL Settings\Temp\UsrClass.dat_BAK_28149
              Present !! : C:\Documents and Settings\Chabby\LOCAL Settings\Temp\UsrClass.dat_BAK_49532
              Present !! : C:\Documents and Settings\Chabby\LOCAL Settings\Temp\UsrClass.dat_BAK_91788

              ¤¤¤¤¤¤¤¤¤¤ Keys :

              Present !! : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Install.exe"
              Present !! : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Setup.exe"
              Present !! : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File execution Options\taskmgr.exe"
              Present !! : HKCR\CLSID\{9afb8248-617f-460d-9366-d71cdeda3179}
              Present !! : HKLM\Software\Classes\CLSID\{9AFB8248-617F-460D-9366-D71CDEDA3179}
              Present !! : HKLM\SYSTEM\ControlSet001\Enum\Root\Legacy_Irmon
              Present !! : HKLM\SYSTEM\ControlSet001\Services\Irmon
              Present !! : HKLM\SYSTEM\ControlSet002\Enum\Root\Legacy_Irmon
              Present !! : HKLM\SYSTEM\ControlSet002\Services\Irmon
              Present !! : HKLM\SYSTEM\CurrentControlSet\Enum\Root\Legacy_Irmon
              Present !! : HKLM\SYSTEM\CurrentControlSet\Services\Irmon

              ============

              catchme 0.3.1398.3 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
              Rootkit scan 2010-04-01 17:58:13
              Windows 5.1.2600 Service Pack 2 FAT NTAPI

              scanning hidden processes ...

              scanning hidden services ...

              scanning hidden autostart entries ...

              scanning hidden files ...

              scan completed successfully
              hidden processes: 0
              hidden services: 0
              hidden files: 0

              Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

              device: opened successfully
              user: MBR read successfully
              called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x899CD328]<<
              kernel: MBR read successfully
              detected MBR rootkit hooks:
              \Driver\atapi -> 0x899cd328
              Warning: possible MBR rootkit infection !
              user & kernel MBR OK
              Use "Recovery Console" command "fixmbr" to clear infection !

              ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

              End of scan : 17:58:14,60
              1. Contributeur sécurité
                Relance List_Kill'em(soit en clic droit pour vista/7),avec le raccourci sur ton bureau.
                mais cette fois-ci :

                choisis l'option CLEAN
                ton PC va redemarrer,

                laisse travailler l'outil.

                en fin de scan la fenetre se ferme , et tu as un rapport du nom de Kill'em.txt sur ton bureau ,

                colle le contenu dans ta reponse

                ..................

                relances le ensuite

                option restore mbr

                postes le rapport


                Je cherche beaucoup...et maintenant je trouve !
                (sourire)
                1. Kill'em by g3n-h@ckm@n 1.7.0.1

                  User : Chabby (Administrateurs)
                  Update on 30/03/2010 by g3n-h@ckm@n ::::: 19.50
                  Start at: 18:38:00 | 01/04/2010

                  Intel(R) Pentium(R) 4 CPU 3.00GHz
                  Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 2
                  Internet Explorer 7.0.5730.13
                  Windows Firewall Status : Enabled
                  AV : Avira AntiVir PersonalEdition Classic 8.0.1.30 [ (!) Disabled | Updated ]

                  A:\ -> Lecteur de disquettes 3 ½ pouces
                  C:\ -> Disque fixe local | 73,24 Go (32,99 Go free) | NTFS
                  D:\ -> Disque fixe local | 75,8 Go (23,85 Go free) | NTFS
                  E:\ -> Disque CD-ROM
                  F:\ -> Disque CD-ROM

                  ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running

                  C:\WINDOWS\System32\smss.exe
                  C:\WINDOWS\system32\csrss.exe
                  C:\WINDOWS\system32\winlogon.exe
                  C:\WINDOWS\system32\services.exe
                  C:\WINDOWS\system32\lsass.exe
                  C:\WINDOWS\system32\nvsvc32.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\system32\logonui.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\system32\spoolsv.exe
                  C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\Program Files\Avira\AntiVir PersonalEdition Classic\avwsc.exe
                  C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                  C:\Program Files\Bonjour\mDNSResponder.exe
                  C:\Program Files\Java\jre6\bin\jqs.exe
                  C:\WINDOWS\System32\TUProgSt.exe
                  C:\WINDOWS\system32\wuauclt.exe
                  C:\WINDOWS\system32\userinit.exe
                  C:\WINDOWS\Explorer.EXE
                  C:\WINDOWS\system32\cmd.exe
                  C:\WINDOWS\system32\wbem\wmiprvse.exe
                  C:\Program Files\List_Kill'em\ERUNT.EXE
                  C:\Program Files\List_Kill'em\pv.exe

                  Detections :
                  ==========

                  ¤¤¤¤¤¤¤¤¤¤ Files/folders :

                  Quarantined & Deleted !! : C:\Program Files\Mozilla FireFox\Components\AskSearch.js
                  Quarantined & Deleted !! : C:\WINDOWS\SET3.tmp
                  Quarantined & Deleted !! : C:\WINDOWS\SET4.tmp
                  Quarantined & Deleted !! : C:\WINDOWS\SET8.tmp

                  Quarantined & Deleted !! : C:\WINDOWS\System32\aniwzcsusername
                  Quarantined & Deleted !! : C:\Documents and Settings\Chabby\Application Data\Desktopicon
                  Quarantined & Deleted !! : C:\Documents and Settings\Chabby\Application Data\Microsoft\svchost.exe
                  Quarantined & Deleted !! : C:\Documents and Settings\Chabby\Local Settings\Temp\amt.log
                  Quarantined & Deleted !! : C:\Documents and Settings\Chabby\LOCAL Settings\Temp\uerjoiq2w.exe
                  Quarantined & Deleted !! : C:\Documents and Settings\Chabby\LOCAL Settings\Temp\update.exe
                  Quarantined & Deleted !! : C:\Documents and Settings\Chabby\LOCAL Settings\Temp\NTUSER.DAT_BAK_67880
                  Quarantined & Deleted !! : C:\Documents and Settings\Chabby\LOCAL Settings\Temp\NTUSER.DAT_BAK_44254
                  Quarantined & Deleted !! : C:\Documents and Settings\Chabby\LOCAL Settings\Temp\NTUSER.DAT_BAK_95902
                  Quarantined & Deleted !! : C:\Documents and Settings\Chabby\LOCAL Settings\Temp\UsrClass.dat_BAK_28149
                  Quarantined & Deleted !! : C:\Documents and Settings\Chabby\LOCAL Settings\Temp\UsrClass.dat_BAK_49532
                  Quarantined & Deleted !! : C:\Documents and Settings\Chabby\LOCAL Settings\Temp\UsrClass.dat_BAK_91788

                  ==============
                  host file OK !
                  ==============

                  ========
                  Registry
                  ========

                  Deleted : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Install.exe"
                  Deleted : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Setup.exe"
                  Deleted : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File execution Options\taskmgr.exe"
                  Deleted : HKCR\CLSID\{9afb8248-617f-460d-9366-d71cdeda3179}
                  Deleted : HKLM\SYSTEM\ControlSet001\Enum\Root\Legacy_Irmon
                  Deleted : HKLM\SYSTEM\ControlSet001\Services\Irmon
                  Deleted : HKLM\SYSTEM\ControlSet002\Enum\Root\Legacy_Irmon
                  Deleted : HKLM\SYSTEM\ControlSet002\Services\Irmon
                  ========
                  Services
                  =========

                  Ndisuio : Start = 3
                  Ip6Fw : Start = 2
                  SharedAccess : Start = 2
                  wuauserv : Start = 2
                  wscsvc : Start = 2

                  ============
                  Disk Cleaned
                  ============

                  =================
                  anti-ver blaster : OK !!
                  =================

                  ================
                  Prefetch cleaned
                  ================

                  ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
                  1. par contre pour faire restore mbr
                    ca me dit impossible de trouver le fichier mbr.log

                    et ca me propose de creer un nouveau fichier

                    que faut il faire ?
                    1. Contributeur sécurité
                      /!\ Il faut impérativement désactiver tous tes logiciels de protection pour utiliser ce programme/!\

                      * Télécharge mbr.exe de Gmer ici : http://www2.gmer.net/mbr/mbr.exe et enregistre le fichier sur le Bureau.
                      * Merci à Malekal pour le tutoriel
                      * Désactive tes protections et coupe la connexion. (Antivirus et antispywares, HIPS et autre résident)
                      * Double clique sur mbr.exe
                      * Un rapport sera généré : mbr.log
                      * En cas d'infection, ce message "MBR rootkit code detected" va apparaitre.
                      * Pour supprimer le rootkit aller dans le menu Démarrer=> Exécuter et tapez la commande en gras: "%userprofile%\Bureau\mbr" -f
                      * (veuillez à bien respecter les guillemets)
                      * Dans le mbr.log cette ligne apparaitra "original MBR restored successfully !"
                      * Réactive tes protections .Poste ce rapport et supprime le ensuite.

                      o Pour vérifier désactive tes protections et coupe la connexion. (Antivirus et antispywares, HIPS et autre résident)
                      o Relance mbr.exe
                      o Réactive tes protections.
                      o Le nouveau mbr.log devrait être celui-ci :
                      o Stealth MBR rootkit detector 0.2.4 by Gmer, http://www.gmer.net
                      o device: opened successfully
                      user: MBR read successfully
                      kernel: MBR read successfully
                      user & kernel MBR OK
                      1. j'ai directement ce rapport

                        apres avoir fait la manip indiquée ci dessus

                        Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

                        device: opened successfully
                        user: MBR read successfully
                        kernel: MBR read successfully
                        user & kernel MBR OK

                        est ce a dire que c'est bon ?

                        par contre je peux tjrs pa retrouver le theme windows classique
                        et je voualis savoir si il n'y a a pas de risque que la chose se trouv sur mon DD externe
                        et comment faire pour netoyer mon mp 3
                        1. Contributeur sécurité
                          pour tes supports usb, selon RSIT il n'y a pas de soucis...

                          pour le mbr, c'est ok

                          on continue

                          Téléchargez MalwareByte's Anti-Malware (que tu pourras garder ensuite)

                          http://www.malwarebytes.org/mbam/program/mbam-setup.exe

                          . Enregistres le sur le bureau
                          . Double cliques sur le fichier téléchargé pour lancer le processus d'installation.
                          . Dans l'onglet "mise à jour", cliques sur le bouton Recherche de mise à jour
                          . Si le pare-feu demande l'autorisation de se connecter pour malwarebytes, accepte
                          . Une fois la mise à jour terminé
                          . Rend-toi dans l'onglet, Recherche
                          . Sélectionnes Exécuter un examen complet (examen assez long)
                          . Cliques sur Rechercher
                          . Le scan démarre.
                          . A la fin de l'analyse, un message s'affiche : L'examen s'est terminé normalement. Cliquez sur 'Afficher les résultats' pour afficher tous les objets trouvés.
                          . Cliques sur Ok pour poursuivre.
                          . Si des malwares ont été détectés, clique sur Afficher les résultats
                          . Sélectionnes tout (ou laisses cochés) et cliques sur Supprimer la sélection Malwarebytes va détruire les fichiers et clés de registre et en mettre une copie dans la quarantaine.
                          . Malwarebytes va ouvrir le bloc-notes et y copier le rapport d'analyse.
                          . Rends toi dans l'onglet rapport/log
                          . Tu cliques dessus pour l'afficher, une fois affiché
                          . Tu cliques sur edition en haut du boc notes, et puis sur sélectionner tous
                          . Tu recliques sur edition et puis sur copier et tu reviens sur le forum et dans ta réponse
                          . tu cliques droit dans le cadre de la reponse et coller

                          Si tu as besoin d'aide regarde ces tutoriels :
                          Aide: https://www.malekal.com/tutoriel-malwarebyte-anti-malware/
                          http://www.infos-du-net.com/forum/278396-11-tuto-malwarebytes-anti-malware-mbam
                          1. j'ai utilisé malwarebyte comme indiqué il a suprimé 2 trucs
                            vla le rapport
                            j'ai aussi pu enlever l'exe chelou sur mon mp3

                            Malwarebytes' Anti-Malware 1.45
                            www.malwarebytes.org

                            Version de la base de données: 3943

                            Windows 5.1.2600 Service Pack 2
                            Internet Explorer 7.0.5730.13

                            01/04/2010 21:37:42
                            mbam-log-2010-04-01 (21-37-42).txt

                            Type d'examen: Examen complet (C:\|D:\|G:\|H:\|)
                            Elément(s) analysé(s): 259502
                            Temps écoulé: 1 heure(s), 49 minute(s), 59 seconde(s)

                            Processus mémoire infecté(s): 0
                            Module(s) mémoire infecté(s): 0
                            Clé(s) du Registre infectée(s): 0
                            Valeur(s) du Registre infectée(s): 0
                            Elément(s) de données du Registre infecté(s): 2
                            Dossier(s) infecté(s): 0
                            Fichier(s) infecté(s): 0

                            Processus mémoire infecté(s):
                            (Aucun élément nuisible détecté)

                            Module(s) mémoire infecté(s):
                            (Aucun élément nuisible détecté)

                            Clé(s) du Registre infectée(s):
                            (Aucun élément nuisible détecté)

                            Valeur(s) du Registre infectée(s):
                            (Aucun élément nuisible détecté)

                            Elément(s) de données du Registre infecté(s):
                            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken.
                            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken.

                            Dossier(s) infecté(s):
                            (Aucun élément nuisible détecté)

                            Fichier(s) infecté(s):
                            (Aucun élément nuisible détecté)
                            1. Contributeur sécurité
                              No action taken. supprimes ce qu'il a trouvé

                              redemarres le pc et dis moi comment il se comporte
                              1. ca a l'air de marcher comme il faut après redemarage

                                je te remercie pour ton aide
                                1. Contributeur sécurité
                                  ok

                                  pour enlever tout doute pour tes supports usb , branches les au pc sans les ouvrir et fais ceci

                                  Téléchargez USBFIX de El Desaparecido, C_xx

                                  http://pagesperso-orange.fr/NosTools/Chiquitine29/UsbFix.exe
                                  ou
                                  https://www.ionos.fr/?affiliate_id=77097

                                  /!\ Utilisateur de vista et windows 7 :
                                  ne pas oublier de désactiver Le contrôle des comptes utilisateurs
                                  https://www.commentcamarche.net/faq/8343-vista-desactiver-l-uac

                                  /!\ Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptible d'avoir été infectées sans les ouvrir

                                  * Double clic sur le raccourci UsbFix présent sur le bureau .

                                  * Choisir l'option 1 (Recherche)
                                  (d'autres options disponibles, voir le tutoriel).
                                  * Laissez travailler l'outil.

                                  * Ensuite postez le rapport UsbFix.txt qui apparaîtra.

                                  * Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque. ( C:\UsbFix.txt )

                                  ( CTRL+A Pour tout sélectionner , CTRL+C pour copier et CTRL+V pour coller )

                                  * Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
                                  Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
                                  Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.

                                  * Tuto : http://pagesperso-orange.fr/NosTools/usbfix.html
                                  1. ############################## | UsbFix V6.100 |

                                    User : Chabby (Administrateurs) # CHABBY-E5158331
                                    Update on 18/03/2010 by El Desaparecido , C_XX & Chimay8
                                    Start at: 12:57:45 | 02/04/2010
                                    Website : http://pagesperso-orange.fr/NosTools/index.html
                                    Contact : FindyKill.Contact@gmail.com

                                    Intel(R) Pentium(R) 4 CPU 3.00GHz
                                    Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 3
                                    Internet Explorer 7.0.5730.13
                                    Windows Firewall Status : Enabled
                                    AV : Avira AntiVir PersonalEdition Classic 8.0.1.30 [ Enabled | Updated ]

                                    A:\ -> Lecteur de disquettes 3 ½ pouces
                                    C:\ -> Disque fixe local # 73,24 Go (31,33 Go free) # NTFS
                                    D:\ -> Disque fixe local # 75,8 Go (20,36 Go free) # NTFS
                                    E:\ -> Disque CD-ROM
                                    F:\ -> Disque CD-ROM
                                    G:\ -> Disque amovible # 1,77 Go (1,77 Go free) [U 5] # FAT32
                                    H:\ -> Disque fixe local # 1396,61 Go (800,19 Go free) [My Book] # NTFS

                                    ################## | Elements infectieux |

                                    G:\SYSTEM

                                    ################## | Registre |

                                    ################## | Mountpoints2 |

                                    ################## | Vaccin |

                                    (!) Cet ordinateur n'est pas vacciné !

                                    ################## | ! Fin du rapport # UsbFix V6.100 ! |
                                    1. j'ai lu le tuto que tu as joint a ce logiciel et utilisé comme indiqué
                                      le g:/systmem dans elements infectieux n'apparait plus sur le rapport
                                      apres un netoyage

                                      mais quand je debranche et rebranche mon mp3, le dossier g:/system apparait de nouveau comme element infectieux

                                      a tu une idée du pkoi?
                                      1. Contributeur sécurité
                                        tu a été plus vite que moi

                                        je voulais vérifier avant de nettoyer

                                        je pense que c'est faux positif, je vais voir avec le concepteur de l'outil, mais je ne suis pas inquiet

                                        en attendant l'info, comment va le pc

                                        relances RSIT et postes le rapport log stp
                                        1. Logfile of random's system information tool 1.06 (written by random/random)
                                          Run by Chabby at 2010-04-02 15:55:19
                                          Microsoft Windows XP Professionnel Service Pack 3
                                          System drive C: has 32 GB (43%) free of 75 GB
                                          Total RAM: 2047 MB (81% free)

                                          Logfile of Trend Micro HijackThis v2.0.2
                                          Scan saved at 15:55:25, on 02/04/2010
                                          Platform: Windows XP SP3 (WinNT 5.01.2600)
                                          MSIE: Internet Explorer v7.00 (7.00.6000.17023)
                                          Boot mode: Normal

                                          Running processes:
                                          C:\WINDOWS\System32\smss.exe
                                          C:\WINDOWS\system32\winlogon.exe
                                          C:\WINDOWS\system32\services.exe
                                          C:\WINDOWS\system32\lsass.exe
                                          C:\WINDOWS\system32\nvsvc32.exe
                                          C:\WINDOWS\system32\svchost.exe
                                          C:\WINDOWS\System32\svchost.exe
                                          C:\WINDOWS\system32\spoolsv.exe
                                          C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                                          C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                                          C:\Program Files\Bonjour\mDNSResponder.exe
                                          C:\Program Files\Java\jre6\bin\jqs.exe
                                          C:\WINDOWS\System32\TUProgSt.exe
                                          C:\WINDOWS\explorer.exe
                                          C:\WINDOWS\system32\wuauclt.exe
                                          C:\WINDOWS\system32\igfxsrvc.exe
                                          C:\Documents and Settings\Chabby\Bureau\RSIT.exe
                                          C:\Program Files\trend micro\Chabby.exe

                                          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
                                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
                                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
                                          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
                                          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer
                                          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                                          O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                                          O2 - BHO: ContributeBHO Class - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll
                                          O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                                          O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
                                          O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                                          O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
                                          O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
                                          O3 - Toolbar: Contribute Toolbar - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll
                                          O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
                                          O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                                          O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                                          O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                                          O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                                          O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                                          O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                                          O4 - Startup: OpenOffice.org 3.1.lnk.disabled
                                          O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                                          O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                                          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                          O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
                                          O23 - Service: Adobe Version Cue CS3 {fr_FR} (Adobe Version Cue CS3) - Adobe Systems Incorporated - C:\Program Files\Fichiers communs\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe
                                          O23 - Service: Planificateur Avira AntiVir Personal - Free Antivirus (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                                          O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                                          O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                                          O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
                                          O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
                                          O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                                          O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software - C:\WINDOWS\System32\TuneUpDefragService.exe
                                          O23 - Service: TuneUp Program Statistics Service (TuneUp.ProgramStatisticsSvc) - TuneUp Software - C:\WINDOWS\System32\TUProgSt.exe
                                          • 1
                                          • 2