Virus svp

Résolu
Bonjour j'ai voulu telecharger prorat 2.0 (Je sais c pas bien) et j'ai chopé plusieur chevaux de troie bloquer par avast mais je pense que plusieur son passer par les maille du filée svp aidez moi
mon scan hitjack :
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:12:09, on 22/04/2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18904)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe
C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\TOSHIBA\TECO\TEco.exe
C:\Program Files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe
C:\Program Files\TOSHIBA\TPHM\TPCHWMsg.exe
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\RocketDock\RocketDock.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Larousse\Encyclopédie Universelle Larousse 2009\bin\hyperappel.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Users\Collégien\AppData\Local\Google\Update\1.2.183.23\GoogleCrashHandler.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\system32\igfxext.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Windows\system32\conime.exe
C:\Users\Collégien\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Collégien\Documents\Downloads\Downloader_4Story_fr_3.3.37.exe
C:\Users\COLLGI~1\AppData\Local\Temp\is-IA3OT.tmp\Downloader_4Story_fr_3.3.37.tmp
C:\Users\Collégien\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Collégien\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Collégien\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Collégien\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\services.exe
C:\Users\Collégien\Documents\Downloads\HiJackThis.exe
C:\Users\Collégien\AppData\Local\Google\Chrome\Application\chrome.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
F2 - REG:system.ini: Shell=Explorer.exe C:\Windows\system32\fservice.exe
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
O4 - HKLM\..\Run: [KeNotify] C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
O4 - HKLM\..\Run: [TosSENotify] C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
O4 - HKLM\..\Run: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe
O4 - HKLM\..\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
O4 - HKLM\..\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Teco] "%ProgramFiles%\TOSHIBA\TECO\Teco.exe" /r
O4 - HKLM\..\Run: [ToshibaServiceStation] "C:\Program Files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" /hide:60
O4 - HKLM\..\Run: [TPCHWMsg] %ProgramFiles%\TOSHIBA\TPHM\TPCHWMsg.exe
O4 - HKLM\..\Run: [avast5] C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [RocketDock] "C:\Program Files\RocketDock\RocketDock.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [Hyperappel de l'Encyclopédie Universelle Larousse] "C:\Program Files\Larousse\Encyclopédie Universelle Larousse 2009\bin\Hyperappel.exe"
O4 - HKCU\..\Run: [Google Update] "C:\Users\Collégien\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKLM\..\Policies\Explorer\Run: [DirectX For Microsoft® Windows] C:\Windows\system32\fservice.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O4 - .DEFAULT User Startup: Bienvenue.lnk = C:\Program Files\Oise\Graphique\Ordi60\Bienvenue.exe (User 'Default user')
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O13 - Gopher Prefix:
O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: TOSHIBA Web Camera Service (camsvc) - TOSHIBA - C:\Program Files\TOSHIBA\TOSHIBA Web Camera Application\TWebCameraSrv.exe
O23 - Service: Service Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Moon Secure Antivirus Core (msav) - Unknown owner - C:\Program Files\Moon Secure Antivirus\msavcore.exe (file missing)
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: TMachInfo - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
O23 - Service: TOSHIBA Navi Support Service (TNaviSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe
O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
O23 - Service: TOSHIBA eco Utility Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TECO\TecoService.exe
O23 - Service: Service TOSHIBA HDD SSD Alert (TOSHIBA HDD SSD Alert Service) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
O23 - Service: TPCH Service (TPCHSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe

End of file - 8792 bytes

29 réponses

Résumé de la discussion

Le message décrit le téléchargement de Prorat 2.0 et la détection par Avast de plusieurs chevaux de Troie, avec l’inquiétude d’une propagation potentielle par les courriels et le réseau. Des réponses recommandent de partager le rapport et d’analyser le HijackThis log et les résultats The Avenger pour isoler les éléments suspects et les services actifs. Elles évoquent aussi la vérification des programmes au démarrage, des processus système et des clés de registre, puis l’utilisation d’antivirus et d’outils de nettoyage pour éliminer les menaces. En complément, des extraits apportent un inventaire du système et des composants tels qu’ Avast, Google Update et des éléments TOSHIBA, ainsi que des détails sur des fichiers comme atapi.sys, signe de la complexité du diagnostic.

Bobot (l’IA à votre service)
  1. Contributeur
    Je veux faire du hacking mais je savais pas qu'il fallait choper des virus pour ça ...
    0
    1. Non il faut pas choper des virus !!
      C'est en telechargent que le virus c introduis et sa a desactiver mon service de sécurité de windows et j'etait obliger de le restaurer s'est pour te dire la puissance du Virus apparament je n'ai plus rien
      0
      1. Contributeur sécurité
        bonjour

        * Télécharge Random's System Information Tool (RSIT) de Random/Random.

        (outil de diagnostic)

        http://images.malwareremoval.com/random/RSIT.exe

        * Enregistre le sur ton Bureau.

        * Double clique sur RSIT.exe pour lancer l'outil.

        * Clique sur "Continue" à l'écran Disclaimer.

        * Si l'outil HijackThis n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu s'il te le demande)

        et tu devras accepter la licence.

        * Une fois le scan terminé, deux rapports vont apparaître : poste les (par "j'ai une réponse") dans deux messages séparés stp

        Les rapports se trouvent à cet endroit:
        C:\rsit\info.txt
        C:\rsit\log.txt


        0
        1. Logfile of random's system information tool 1.06 (written by random/random)
          Run by Collégien at 2010-04-23 13:21:19
          Microsoft® Windows Vista(TM) Édition Familiale Premium Service Pack 2
          System drive C: has 38 GB (51%) free of 76 GB
          Total RAM: 1912 MB (52% free)

          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 13:22:13, on 23/04/2010
          Platform: Windows Vista SP2 (WinNT 6.00.1906)
          MSIE: Internet Explorer v8.00 (8.00.6001.18904)
          Boot mode: Normal

          Running processes:
          C:\Windows\system32\taskeng.exe
          C:\Windows\system32\Dwm.exe
          C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe
          C:\Windows\Explorer.EXE
          C:\Program Files\Windows Defender\MSASCui.exe
          C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
          C:\Windows\system32\taskeng.exe
          C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
          C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe
          C:\Windows\System32\igfxtray.exe
          C:\Windows\System32\hkcmd.exe
          C:\Windows\System32\igfxpers.exe
          C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
          C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe
          C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
          C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
          C:\Program Files\TOSHIBA\TECO\TEco.exe
          C:\Program Files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe
          C:\Program Files\TOSHIBA\TPHM\TPCHWMsg.exe
          C:\Program Files\Alwil Software\Avast5\AvastUI.exe
          C:\Program Files\Common Files\Java\Java Update\jusched.exe
          C:\Program Files\RocketDock\RocketDock.exe
          C:\Program Files\Windows Sidebar\sidebar.exe
          C:\Program Files\Larousse\Encyclopédie Universelle Larousse 2009\bin\hyperappel.exe
          C:\Program Files\Windows Media Player\wmpnscfg.exe
          C:\Users\Collégien\AppData\Local\Google\Update\1.2.183.23\GoogleCrashHandler.exe
          C:\Windows\system32\igfxsrvc.exe
          C:\Windows\system32\igfxext.exe
          C:\Program Files\Windows Sidebar\sidebar.exe
          C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
          C:\Windows\system32\conime.exe
          C:\Users\Collégien\AppData\Local\Google\Chrome\Application\chrome.exe
          C:\Users\Collégien\AppData\Local\Google\Chrome\Application\chrome.exe
          C:\Users\Collégien\Documents\Downloads\RSIT.exe
          C:\Program Files\trend micro\Collégien.exe

          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
          R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
          O1 - Hosts: ::1 localhost
          O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
          O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
          O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
          O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
          O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
          O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
          O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
          O4 - HKLM\..\Run: [KeNotify] C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
          O4 - HKLM\..\Run: [TosSENotify] C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe
          O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
          O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
          O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
          O4 - HKLM\..\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
          O4 - HKLM\..\Run: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe
          O4 - HKLM\..\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
          O4 - HKLM\..\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
          O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
          O4 - HKLM\..\Run: [Teco] "%ProgramFiles%\TOSHIBA\TECO\Teco.exe" /r
          O4 - HKLM\..\Run: [ToshibaServiceStation] "C:\Program Files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" /hide:60
          O4 - HKLM\..\Run: [TPCHWMsg] %ProgramFiles%\TOSHIBA\TPHM\TPCHWMsg.exe
          O4 - HKLM\..\Run: [avast5] C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui
          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
          O4 - HKCU\..\Run: [RocketDock] "C:\Program Files\RocketDock\RocketDock.exe"
          O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
          O4 - HKCU\..\Run: [Hyperappel de l'Encyclopédie Universelle Larousse] "C:\Program Files\Larousse\Encyclopédie Universelle Larousse 2009\bin\Hyperappel.exe"
          O4 - HKCU\..\Run: [Google Update] "C:\Users\Collégien\AppData\Local\Google\Update\GoogleUpdate.exe" /c
          O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
          O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
          O4 - .DEFAULT User Startup: Bienvenue.lnk = C:\Program Files\Oise\Graphique\Ordi60\Bienvenue.exe (User 'Default user')
          O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
          O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
          O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
          O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
          O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
          O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
          O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
          O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
          O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
          O13 - Gopher Prefix:
          O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
          O16 - DPF: {4DD20514-9520-40A7-9CD6-66883643A20B} (UviLaunch Control) - http://www.boaki.com/download/uviLaunch.cab
          O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/MessengerGamesContent/GameContent/fr/uno1/GAME_UNO1.cab
          O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
          O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
          O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
          O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
          O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
          O23 - Service: TOSHIBA Web Camera Service (camsvc) - TOSHIBA - C:\Program Files\TOSHIBA\TOSHIBA Web Camera Application\TWebCameraSrv.exe
          O23 - Service: Service Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
          O23 - Service: Moon Secure Antivirus Core (msav) - Unknown owner - C:\Program Files\Moon Secure Antivirus\msavcore.exe (file missing)
          O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
          O23 - Service: TMachInfo - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
          O23 - Service: TOSHIBA Navi Support Service (TNaviSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe
          O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe
          O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
          O23 - Service: TOSHIBA eco Utility Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TECO\TecoService.exe
          O23 - Service: Service TOSHIBA HDD SSD Alert (TOSHIBA HDD SSD Alert Service) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
          O23 - Service: TPCH Service (TPCHSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
          0
          1. Voici la suite du rapport log:

            [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
            "RocketDock"=C:\Program Files\RocketDock\RocketDock.exe [2007-09-02 495616]
            "Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2009-04-11 1233920]
            "Hyperappel de l'Encyclopédie Universelle Larousse"=C:\Program Files\Larousse\Encyclopédie Universelle Larousse 2009\bin\Hyperappel.exe [2008-06-30 229376]
            "Google Update"=C:\Users\Collégien\AppData\Local\Google\Update\GoogleUpdate.exe [2010-04-08 136176]
            "WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe [2008-01-21 202240]

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
            C:\Windows\system32\igfxdev.dll [2009-03-03 221184]

            [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]

            [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]

            [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]

            [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]

            [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
            "LogonHoursAction"=2
            "DontDisplayLogonHoursWarnings"=1

            [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
            "dontdisplaylastusername"=0
            "legalnoticecaption"=
            "legalnoticetext"=
            "shutdownwithoutlogon"=1
            "undockwithoutlogon"=1
            "EnableUIADesktopToggle"=0

            [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
            "NoDriveTypeAutoRun"=145
            "NoRun"=0

            [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
            "BindDirectlyToPropertySetStorage"=
            "NoRun"=

            [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

            [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

            ======File associations======

            .js - edit - C:\Windows\System32\Notepad.exe %1
            .js - open - C:\Windows\System32\WScript.exe "%1" %*

            ======List of files/folders created in the last 1 months======

            2010-04-23 13:21:19 ----D---- C:\rsit
            2010-04-23 13:21:19 ----D---- C:\Program Files\trend micro
            2010-04-21 15:37:40 ----D---- C:\Program Files\2BrightSparks
            2010-04-15 10:52:59 ----A---- C:\Windows\system32\iphlpsvc.dll
            2010-04-15 10:47:20 ----A---- C:\Windows\system32\ntoskrnl.exe
            2010-04-15 10:47:19 ----A---- C:\Windows\system32\ntkrnlpa.exe
            2010-04-15 10:47:14 ----A---- C:\Windows\system32\vbscript.dll
            2010-04-14 11:09:10 ----D---- C:\ProgramData\agi
            2010-04-14 10:13:30 ----A---- C:\Windows\system32\wintrust.dll
            2010-04-14 10:13:28 ----A---- C:\Windows\system32\cabview.dll
            2010-04-13 17:27:17 ----D---- C:\Program Files\Common Files\Java
            2010-04-13 17:26:44 ----A---- C:\Windows\system32\javaws.exe
            2010-04-13 17:26:44 ----A---- C:\Windows\system32\javaw.exe
            2010-04-13 17:26:44 ----A---- C:\Windows\system32\java.exe
            2010-04-13 14:34:26 ----A---- C:\ZHPExportRegistry-13-04-2010-14-34-26.txt
            2010-04-12 14:53:28 ----D---- C:\ProgramData\Malwarebytes
            2010-04-12 14:53:27 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
            2010-04-12 14:50:56 ----A---- C:\ZHPExportRegistry-12-04-2010-14-50-56.txt
            2010-04-12 11:30:14 ----D---- C:\Program Files\ZHPDiag
            2010-04-11 15:26:20 ----D---- C:\Program Files\HyperCam Toolbar
            2010-04-11 15:26:02 ----D---- C:\Program Files\HyCam2
            2010-04-11 15:23:48 ----D---- C:\Program Files\WinRAR
            2010-04-06 15:25:18 ----D---- C:\Program Files\Compil Games
            2010-04-05 18:25:28 ----D---- C:\ProgramData\Yahoo! Companion
            2010-04-05 18:25:27 ----D---- C:\Program Files\Yahoo!
            2010-04-03 14:54:06 ----D---- C:\Program Files\Glary Utilities
            2010-04-02 18:47:52 ----D---- C:\ProgramData\SUPERAntiSpyware.com
            2010-04-02 18:47:36 ----D---- C:\Program Files\SUPERAntiSpyware
            2010-04-01 19:56:17 ----D---- C:\ProgramData\IObit
            2010-04-01 19:48:34 ----D---- C:\Users\utilisateur\AppData\Roaming\IObit
            2010-04-01 19:37:06 ----D---- C:\Program Files\IObit
            2010-03-31 18:31:17 ----D---- C:\Program Files\ScreenMates
            2010-03-31 13:45:23 ----D---- C:\ProgramData\eMule
            2010-03-31 13:44:54 ----D---- C:\Program Files\eMule
            2010-03-31 13:12:36 ----A---- C:\Windows\system32\mshtml.dll
            2010-03-31 13:12:34 ----A---- C:\Windows\system32\ieframe.dll
            2010-03-31 13:12:32 ----A---- C:\Windows\system32\iertutil.dll
            2010-03-31 13:12:31 ----A---- C:\Windows\system32\wininet.dll
            2010-03-31 13:12:31 ----A---- C:\Windows\system32\urlmon.dll
            2010-03-31 13:12:31 ----A---- C:\Windows\system32\occache.dll
            2010-03-31 13:12:31 ----A---- C:\Windows\system32\msfeeds.dll
            2010-03-31 13:12:30 ----A---- C:\Windows\system32\mstime.dll
            2010-03-31 13:12:30 ----A---- C:\Windows\system32\iedkcs32.dll
            2010-03-31 13:12:29 ----A---- C:\Windows\system32\msfeedsbs.dll
            2010-03-31 13:12:29 ----A---- C:\Windows\system32\jsproxy.dll
            2010-03-31 13:12:29 ----A---- C:\Windows\system32\ieUnatt.exe
            2010-03-31 13:12:29 ----A---- C:\Windows\system32\ieui.dll
            2010-03-31 13:12:29 ----A---- C:\Windows\system32\iesysprep.dll
            2010-03-31 13:12:29 ----A---- C:\Windows\system32\iepeers.dll
            2010-03-31 13:12:22 ----A---- C:\Windows\system32\msfeedssync.exe
            2010-03-31 13:12:22 ----A---- C:\Windows\system32\iesetup.dll
            2010-03-31 13:12:22 ----A---- C:\Windows\system32\iernonce.dll
            2010-03-31 13:12:22 ----A---- C:\Windows\system32\ie4uinit.exe
            2010-03-29 14:29:23 ----D---- C:\Windows\Sun
            2010-03-28 09:45:55 ----D---- C:\Program Files\Wanted Guns
            2010-03-27 18:26:55 ----D---- C:\Program Files\SDLL
            2010-03-24 10:03:10 ----D---- C:\Program Files\Gibcom

            ======List of files/folders modified in the last 1 months======

            2011-03-08 12:00:52 ----D---- C:\Program Files\Oise
            2011-03-08 10:31:00 ----D---- C:\Program Files\Larousse
            2011-03-08 10:09:11 ----D---- C:\Program Files\cbgeofr
            2010-04-23 13:21:26 ----D---- C:\Windows\Temp
            2010-04-23 13:21:19 ----RD---- C:\Program Files
            2010-04-23 13:20:45 ----D---- C:\Windows\System32
            2010-04-23 13:20:45 ----D---- C:\Windows\inf
            2010-04-23 13:20:45 ----A---- C:\Windows\system32\PerfStringBackup.INI
            2010-04-23 07:22:48 ----SHD---- C:\System Volume Information
            2010-04-22 19:03:37 ----HD---- C:\ProgramData
            2010-04-22 18:56:29 ----D---- C:\Windows\system32\Msdtc
            2010-04-22 18:56:25 ----D---- C:\Windows\system32\wbem
            2010-04-22 18:56:25 ----D---- C:\Windows
            2010-04-22 18:55:48 ----D---- C:\Windows\system32\config
            2010-04-22 18:55:36 ----SD---- C:\Windows\Downloaded Program Files
            2010-04-22 18:55:36 ----D---- C:\Windows\Tasks
            2010-04-22 18:55:36 ----D---- C:\Windows\system32\spool
            2010-04-22 18:55:36 ----D---- C:\Windows\system32\drivers
            2010-04-22 18:55:36 ----D---- C:\Windows\system32\catroot2
            2010-04-22 18:55:35 ----D---- C:\Program Files\RocketDock
            2010-04-22 18:55:34 ----D---- C:\Windows\registration
            2010-04-22 18:51:50 ----D---- C:\Windows\system
            2010-04-21 14:49:04 ----D---- C:\Windows\Debug
            2010-04-16 13:26:57 ----SHD---- C:\Windows\Installer
            2010-04-16 13:25:28 ----D---- C:\Program Files\Google
            2010-04-15 13:04:32 ----D---- C:\Windows\winsxs
            2010-04-15 12:53:55 ----D---- C:\Windows\system32\catroot
            2010-04-15 12:50:41 ----D---- C:\Program Files\Windows Mail
            2010-04-15 10:41:58 ----D---- C:\Windows\Prefetch
            2010-04-14 18:47:03 ----A---- C:\Windows\system32\aswBoot.exe
            2010-04-13 17:27:17 ----D---- C:\Program Files\Common Files
            2010-04-13 17:26:25 ----A---- C:\Windows\system32\deploytk.dll
            2010-04-13 17:18:36 ----D---- C:\Program Files\Messenger_Plus_Live
            2010-04-12 14:50:45 ----HD---- C:\ProgramData\{924B45CC-9477-41E9-808B-6F623B920F1E}
            2010-04-08 13:33:53 ----D---- C:\Windows\system32\Tasks
            2010-04-07 13:56:11 ----D---- C:\Program Files\Spybot - Search & Destroy
            2010-04-07 13:54:58 ----D---- C:\ProgramData\Spybot - Search & Destroy
            2010-04-07 12:18:13 ----D---- C:\Program Files\Mozilla Firefox
            2010-04-06 19:52:54 ----A---- C:\Windows\system32\mrt.exe
            2010-04-05 18:25:24 ----D---- C:\Program Files\CCleaner
            2010-04-05 14:10:24 ----D---- C:\Program Files\uTorrent
            2010-04-05 11:06:35 ----D---- C:\Program Files\Bridge Construction Set Demo
            2010-04-05 11:06:24 ----D---- C:\Program Files\CaTrain
            2010-04-04 19:24:14 ----D---- C:\Windows\system32\sysprep
            2010-04-04 19:24:14 ----D---- C:\Windows\system32\CodeIntegrity
            2010-04-04 19:24:14 ----D---- C:\Windows\pss
            2010-04-04 19:15:17 ----D---- C:\Program Files\Metin2
            2010-04-04 15:30:38 ----HD---- C:\ProgramData\{C9221463-F18B-4A58-9384-77F6E3552EDB}
            2010-04-04 15:30:38 ----HD---- C:\ProgramData\{0145F9DA-C702-4614-9CCB-04D1279C9CB2}
            2010-04-04 15:30:24 ----SHD---- C:\Boot
            2010-04-04 15:30:24 ----D---- C:\Program Files\Regressi Junior
            2010-04-04 15:30:24 ----D---- C:\Program Files\KompoZer 0.7.10
            2010-04-04 15:30:24 ----D---- C:\Program Files\CDex_150
            2010-04-03 18:32:25 ----D---- C:\Windows\LiveKernelReports
            2010-04-03 14:35:39 ----D---- C:\Users\utilisateur\AppData\Roaming\skypePM
            2010-03-31 15:28:50 ----D---- C:\Windows\system32\migration
            2010-03-31 15:28:50 ----D---- C:\Program Files\Internet Explorer
            2010-03-27 18:26:55 ----HD---- C:\Program Files\InstallShield Installation Information

            ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

            R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr.sys [2010-04-14 23376]
            R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2010-04-14 162768]
            R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2010-04-14 46672]
            R1 RtlProt;Realtke RtlProt WLAN Utility Protocol Driver; C:\Windows\system32\DRIVERS\rtlprot.sys [2007-04-23 25896]
            R2 aswFsBlk;aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [2010-04-14 19024]
            R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2010-04-14 51792]
            R2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver; C:\Windows\system32\DRIVERS\TVALZFL.sys [2009-03-21 12920]
            R3 CmBatt;Pilote pour Batterie à méthode de contrôle ACPI Microsoft; C:\Windows\system32\DRIVERS\CmBatt.sys [2008-01-21 14208]
            R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys [2009-03-03 2476544]
            R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2009-03-30 2350624]
            R3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI; C:\Windows\system32\drivers\IntcHdmi.sys [2008-09-22 112128]
            R3 PGEffect;Pangu effect driver; C:\Windows\system32\DRIVERS\pgeffect.sys [2009-03-18 22272]
            R3 RTL8169;Realtek 8169 NT Driver; C:\Windows\system32\DRIVERS\Rtlh86.sys [2009-04-24 163840]
            R3 rtl8192se;Realtek Wireless LAN 802.11n PCI-E NIC NT Driver; C:\Windows\system32\DRIVERS\rtl8192se.sys [2010-02-24 522784]
            R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2009-03-20 208688]
            R3 tdcmdpst;TOSHIBA Writing Engine Filter Driver; C:\Windows\system32\DRIVERS\tdcmdpst.sys [2006-10-18 16128]
            R3 usbvideo;Périphérique vidéo USB (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2008-01-21 134016]
            S3 drmkaud;Filtre de décodeur DRM (Noyau Microsoft); C:\Windows\system32\drivers\drmkaud.sys [2008-01-21 5632]
            S3 FsUsbExDisk;FsUsbExDisk; \??\C:\Windows\system32\FsUsbExDisk.SYS [2009-04-07 36608]
            S3 HdAudAddService;Pilote de fonction UAA 1.1 Microsoft pour le service High Definition Audio; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
            S3 MSKSSRV;Proxy de service de répartition Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-21 8192]
            S3 MSPCLOCK;Proxy d'horloge de répartition Microsoft; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-21 5888]
            S3 MSPQM;Proxy de gestion de qualité de répartition Microsoft; C:\Windows\system32\drivers\MSPQM.sys [2008-01-21 5504]
            S3 MSTEE;Convertisseur en T/site-à-site de répartition Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2008-01-21 6016]
            S3 NuidFltr;NUID filter driver; C:\Windows\system32\DRIVERS\NuidFltr.sys [2009-05-09 14736]
            S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfd.sys [2007-09-17 21632]
            S3 RTHDMIAzAudService;Service for HDMI; C:\Windows\system32\drivers\RtHDMIV.sys [2008-11-11 154272]
            S3 RTSTOR;Realtek USB 2.0 Card Reader; C:\Windows\system32\drivers\RTSTOR.SYS [2009-04-08 64000]
            S3 sscdbus;SAMSUNG USB Composite Device driver (WDM); C:\Windows\system32\DRIVERS\sscdbus.sys [2007-07-03 80552]
            S3 sscdmdfl;SAMSUNG Mobile Modem Filter; C:\Windows\system32\DRIVERS\sscdmdfl.sys [2007-07-03 11944]
            S3 sscdmdm;SAMSUNG Mobile Modem Drivers; C:\Windows\system32\DRIVERS\sscdmdm.sys [2007-07-03 106792]
            S3 teamviewervpn;TeamViewer VPN Adapter; C:\Windows\system32\DRIVERS\teamviewervpn.sys [2009-11-09 25088]
            S3 usbaudio;Pilote USB audio (WDM); C:\Windows\system32\drivers\usbaudio.sys [2009-04-11 73216]
            S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-21 83328]
            S4 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys [2008-01-21 6656]
            S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-01-21 386616]
            S4 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\drivers\wmiacpi.sys [2008-01-21 11264]

            ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

            R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-04-14 40384]
            R2 camsvc;TOSHIBA Web Camera Service; C:\Program Files\TOSHIBA\TOSHIBA Web Camera Application\TWebCameraSrv.exe [2009-04-16 20544]
            R2 TMachInfo;TMachInfo; C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [2009-04-01 62776]
            R2 TNaviSrv;TOSHIBA Navi Support Service; C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe [2009-03-30 83312]
            R2 TODDSrv;TOSHIBA Optical Disc Drive Service; C:\Windows\system32\TODDSrv.exe [2007-11-21 129632]
            R2 TosCoSrv;TOSHIBA Power Saver; C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe [2009-03-06 464224]
            R2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service; C:\Program Files\TOSHIBA\TECO\TecoService.exe [2009-04-24 176128]
            R2 TOSHIBA HDD SSD Alert Service;Service TOSHIBA HDD SSD Alert; C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [2009-03-17 73728]
            R2 TPCHSrv;TPCH Service; C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe [2009-04-15 656752]
            R3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-04-14 40384]
            R3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-04-14 40384]
            S2 gupdate;Service Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-03-12 133104]
            S2 msav;Moon Secure Antivirus Core; C:\Program Files\Moon Secure Antivirus\msavcore.exe []
            S3 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-01-21 21504]
            S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
            S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2008-04-07 430592]

            -----------------EOF-----------------
            0
            1. Contributeur sécurité
              effectivement, tu sembles ne plus rien avoir...

              Desactive ton antivirus le temps de la manip ainsi que ton parefeu si présent(car il est detecté a tort comme infection)

              Télécharge et installe List&Kill'em et enregistre le sur ton bureau

              http://sd-1.archive-host.com/...

              double clique ( clic droit "executer en tant qu'administrateur" pour Vista/7 ) sur le raccourci sur ton bureau pour lancer l'installation

              coche la case "creer une icone sur le bureau"

              une fois terminée , clic sur "terminer" et le programme se lancer seul

              choisis la langue puis choisis l'option SEARCH

              laisse travailler l'outil

              à l'apparition de la fenetre blanche , c'est un peu long , c'est normal , le programme n'est pas bloqué.

              un rapport du nom de catchme apparait sur ton bureau , ignore-le,ne le poste pas , mais ne le supprime pas pour l instant, le scan n'est pas fini.

              Poste le contenu du rapport qui s'ouvre aux 100 % du scan à l'ecran "COMPLETED"

              tu peux supprimer le rapport catchme.log de ton bureau maintenant.


              Je cherche beaucoup...et maintenant je trouve !
              (sourire)
              0
              1. Voici le rapport info maintenant !!! :

                info.txt logfile of random's system information tool 1.06 2010-04-23 13:22:18

                ======Uninstall list======

                -->C:\PROGRA~1\Yahoo!\Common\UNYT_W~1.EXE
                µTorrent-->"C:\Program Files\uTorrent\uTorrent.exe" /UNINSTALL
                Adobe AIR-->c:\Program Files\Common Files\Adobe AIR\Versions\1.0\Resources\Adobe AIR Updater.exe -arp:uninstall
                Adobe AIR-->MsiExec.exe /I{A2BCA9F1-566C-4805-97D1-7FDC93386723}
                Adobe Flash Player 10 ActiveX-->C:\Windows\system32\Macromed\Flash\uninstall_activeX.exe
                Adobe Flash Player 10 Plugin-->C:\Windows\system32\Macromed\Flash\uninstall_plugin.exe
                Adobe Reader 9 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A90000000001}
                Adobe Shockwave Player 11.5-->"C:\Windows\system32\Adobe\Shockwave 11\uninstaller.exe"
                Advanced SystemCare 3-->"C:\Program Files\IObit\Advanced SystemCare 3\unins000.exe"
                Analyseur et SDK MSXML 4.0 SP2-->MsiExec.exe /I{716E0306-8318-4364-8B8F-0CC4E9376BAC}
                Apple Application Support-->MsiExec.exe /I{0C34B801-6AEC-4667-B053-03A67E2D0415}
                Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
                Assistant de connexion Windows Live-->MsiExec.exe /I{DCE8CD14-FBF5-4464-B9A4-E18E473546C7}
                Audacity 1.2.6-->"C:\Program Files\Audacity\unins000.exe"
                avast! Free Antivirus-->C:\Program Files\Alwil Software\Avast5\aswRunDll.exe "C:\Program Files\Alwil Software\Avast5\Setup\setiface.dll" RunSetup
                Bibliothèques GTK+ 2.14.7 rev a (supprimer uniquement)-->C:\Program Files\Common Files\GTK\2.0\uninst.exe
                Blender (remove only)-->"C:\Program Files\Blender Foundation\Blender\uninstall.exe"
                cbgeo-->C:\Program Files\cbgeoMonde\uninstall.exe
                cbgeofr-->C:\Program Files\cbgeofr\uninstall.exe
                cbgeoit-->C:\Program Files\cbgeoit\uninstall.exe
                CCleaner-->"C:\Program Files\CCleaner\uninst.exe"
                CDex extraction audio-->"C:\Program Files\CDex_150\uninstall.exe"
                Celestia 1.6.0-->"C:\Program Files\Celestia\unins000.exe"
                Chroma v.2.5-->"C:\Program Files\Serge_LAGIER\Chroma\unins000.exe"
                Coeur-->"C:\Program Files\Coeur\unins000.exe"
                Collatinus 8-->"C:\Program Files\collatinus8\unins000.exe"
                Collins 1.2-->"C:\Program Files\Le Robert & Collins\Le Robert & Collins Maxi anglais\unins000.exe"
                Cosmo Player 2.1 (38329)-->C:\Windows\IsUn040c.exe -f"C:\Program Files\CosmoSoftware\CosmoPlayer\CosmoPlayer21.isu"
                Déclic Métiers 1-->C:\Program Files\onisep\Déclic Métiers 1\uninstall.exe
                Déclic Métiers 2-->C:\Program Files\onisep\Déclic Métiers 2\uninstall.exe
                Defraggler-->"C:\Program Files\Defraggler\uninst.exe"
                Destination métiers 3.0-->"C:\Program Files\Destination métiers\metiers parc\uninstall.exe"
                Dia (supprimer uniquement)-->C:\Program Files\Dia\dia-0.97-uninstall.exe
                Dofus-->msiexec /qb /x {BCF3E8EF-5965-FDC5-6AD3-506FEE376C2B}
                Dofus-->MsiExec.exe /I{BCF3E8EF-5965-FDC5-6AD3-506FEE376C2B}
                eMule-->"C:\Program Files\eMule\Uninstall.exe"
                Encyclopédie Universelle Larousse 2009-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D334AC80-9E0E-426D-9931-9DE779779422}\Setup.exe" -l0x40c
                Enigma-->"C:\Program Files\Enigma\uninstall.exe"
                FreeMind-->"C:\Program Files\FreeMind\unins000.exe"
                GeoGebra-->"C:\Program Files\GeoGebra\UninstallerData\Uninstaller.exe"
                GIMP 2.6.7-->"C:\Program Files\GIMP-2.0\setup\unins000.exe"
                GNU Solfege 3.14.9-->"C:\Program Files\GNU Solfege\unins000.exe"
                Google Update Helper-->MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
                Google Earth-->MsiExec.exe /X{08C0729E-3E50-11DF-9D81-005056806466}
                GPL Ghostscript 8.70-->C:\Program Files\gs\uninstgs.exe "C:\Program Files\gs\gs8.70\uninstal.txt"
                HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
                Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
                Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
                HotPotatoes v 6.3.0.3-->"C:\Program Files\HotPotatoes6\unins000.exe"
                HyperCam 2-->"C:\Program Files\HyCam2\UnHyCam2.exe"
                HyperCam Toolbar-->C:\Program Files\HyperCam Toolbar\UninstallToolbar.exe
                IMBooster4Web-->"C:\ProgramData\{924B45CC-9477-41E9-808B-6F623B920F1E}\IMBooster4Web.Setup.exe" REMOVE=TRUE MODIFY=FALSE
                IMBooster4Web-->C:\ProgramData\{924B45CC-9477-41E9-808B-6F623B920F1E}\IMBooster4Web.Setup.exe
                Inkscape 0.46-->C:\Program Files\Inkscape\Uninstall.exe
                Installation Windows Live-->C:\Program Files\Windows Live\Installer\wlarp.exe
                Installation Windows Live-->MsiExec.exe /I{46ABBC54-1872-4AA3-95E2-F2C063A63F31}
                Intel(R) Graphics Media Accelerator Driver-->C:\Windows\system32\igxpun.exe -uninstall
                Intel® Matrix Storage Manager-->C:\Program Files\Intel\Intel Matrix Storage Manager\Uninstall\imsmudlg.exe -uninstall
                Java(TM) 6 Update 19-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216019FF}
                Larousse Multilingue-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A0E8792C-11E1-42EF-844C-EB87E3AADD19}\setup.exe" -l0x40c
                Le Petit Robert 2010-->"C:\Program Files\Le Robert\Le Petit Robert 2010\Uninstall.exe"
                Le Robert & Collins Maxi allemand-->C:\Program Files\Le Robert & Collins\Le Robert & Collins Maxi allemand\Setup.exe /u
                Le Robert & Collins Maxi espagnol-->C:\Program Files\Le Robert & Collins\Le Robert & Collins Maxi espagnol\Setup.exe /u
                Logiciel d'archivage WinRAR-->C:\Program Files\WinRAR\uninstall.exe
                Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
                Manuels TOSHIBA-->C:\Program Files\InstallShield Installation Information\{5B0202A8-CC6B-4443-AD73-FE9DF1FC1622}\setup.exe -runfromtemp -l0x040c -removeonly
                Messenger Plus! Live-->"C:\Program Files\Messenger Plus! Live\Uninstall.exe"
                Messenger_Plus_Live Toolbar-->C:\PROGRA~1\MESSEN~2\UNWISE.EXE /U C:\PROGRA~1\MESSEN~2\INSTALL.LOG
                Microsoft .NET Framework 3.5 Language Pack SP1 - fra-->MsiExec.exe /I{3E31821C-7917-367E-938E-E65FC413EA31}
                Microsoft .NET Framework 3.5 SP1-->C:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
                Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
                Microsoft Choice Guard-->MsiExec.exe /X{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}
                Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
                Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053-->MsiExec.exe /X{770657D0-A123-3C07-8E44-1C83EC895118}
                Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{837b34e3-7c30-493c-8f6a-2b0f04e2912c}
                Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148-->MsiExec.exe /X{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}
                Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022.218-->MsiExec.exe /X{E503B4BF-F7BB-3D5F-8BC8-F694B1CFF942}
                Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17-->MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475}
                Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148-->MsiExec.exe /X{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}
                Module linguistique Microsoft .NET Framework 3.5 SP1- fra-->C:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 Language Pack SP1 - fra\setup.exe
                Mozilla Firefox (3.6.3)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
                Mozilla Sunbird (0.9)-->C:\Program Files\Mozilla Sunbird\uninstall\uninst.exe
                Mozilla Thunderbird (2.0.0.23)-->C:\Program Files\Mozilla Thunderbird\uninstall\helper.exe
                MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
                MSXML 4.0 SP2 (KB941833)-->MsiExec.exe /I{C523D256-313D-4866-B36A-F3DE528246EF}
                MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
                MSXML 4.0 SP2 (KB973688)-->MsiExec.exe /I{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
                OpenAL-->"C:\Program Files\OpenAL\oalinst.exe" /U /S
                OpenAlchemist 0.3-->"C:\Program Files\OpenAlchemist\unins000.exe"
                OpenOffice.org 3.2-->MsiExec.exe /I{4EE2EF4B-25D3-4D44-8384-A2B96F811F55}
                Optikos v.1.1-->"C:\Program Files\Serge_LAGIER\Optikos\unins000.exe"
                Oscillo v.3.5-->"C:\Program Files\Serge_LAGIER\Oscillo\unins000.exe"
                Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
                Package de pilotes Windows - Nokia pccsmcfd (10/12/2007 6.85.4.0)-->C:\PROGRA~1\DIFX\270581355A767BF1\dpinst.exe /u C:\Windows\system32\DRVSTORE\pccsmcfd_4A1E30386F4D0DEC8F5DF262CFBD8845EEBAB175\pccsmcfd.inf
                PC Connectivity Solution-->MsiExec.exe /I{AC599724-5755-48C1-ABE7-ABB857652930}
                PDFCreator-->C:\Program Files\PDFCreator\unins000.exe
                Pidgin-->C:\Program Files\Pidgin\pidgin-uninst.exe
                PlayReady PC runtime-->MsiExec.exe /X{B0E5D7E7-A106-458F-BA7B-2F8CAEA3BF16}
                Python 2.6.4-->MsiExec.exe /I{E7394A0F-3F80-45B1-87FC-ABCD51893246}
                QuickTime-->MsiExec.exe /I{A429C2AE-EBF1-4F81-A221-1C115CAADDAD}
                Realtek 8136 8168 8169 Ethernet Driver-->C:\Program Files\InstallShield Installation Information\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}\setup.exe -runfromtemp -removeonly
                Realtek High Definition Audio Driver-->C:\Program Files\Realtek\Audio\HDA\RtlUpd.exe -r -m -nrg2709
                Realtek USB 2.0 Card Reader-->C:\Program Files\InstallShield Installation Information\{DC24971E-1946-445D-8A82-CE685433FA7D}\setup.exe -runfromtemp -l0x040c -removeonly
                Realtek WiFi Protected Setup Library-->C:\Program Files\InstallShield Installation Information\{02CA24DD-C8B0-4280-BE53-7862869C2EB1}\Install.exe -uninst -l0x40C
                Realtek WLAN Driver-->MsiExec.exe /X{0FB630AB-7BD8-40AE-B223-60397D57C3C9}
                Reg (DOFUS Audio Subsystem)-->msiexec /qb /x {CE111B5C-27F5-B74D-C15A-CAFDD2E21837}
                Reg (DOFUS Audio Subsystem)-->MsiExec.exe /I{CE111B5C-27F5-B74D-C15A-CAFDD2E21837}
                RocketDock 1.3.5-->"C:\Program Files\RocketDock\unins000.exe"
                SAMSUNG Mobile Composite Device Software-->C:\Windows\system32\Samsung_USB_Drivers\6_old\SSBCUninstall.exe
                Samsung Mobile Modem Device Software-->C:\Windows\system32\Samsung_USB_Drivers\7\SSECUninstall.exe
                SAMSUNG Mobile Modem Driver Set-->C:\Windows\system32\Samsung_USB_Drivers\3\SSCDUninstall.exe
                Samsung Mobile phone USB driver Software-->C:\Windows\system32\Samsung_USB_Drivers\5\SSSDUninstall.exe
                SAMSUNG Mobile USB Modem 1.0 Software-->C:\Windows\system32\Samsung_USB_Drivers\1\SS_Uninstall.exe
                SAMSUNG Mobile USB Modem Software-->C:\Windows\system32\Samsung_USB_Drivers\2\SSM_Uninstall.exe
                SAMSUNG SYMBIAN USB Download Driver-->C:\Program Files\SAMSUNG\SYMBIAN USB Download Driver\Uninstall.exe
                SAMSUNG USB Mobile Device Software-->C:\Windows\system32\Samsung_USB_Drivers\6\SS_BUninstall.exe
                SamsungConnectivityCableDriver-->MsiExec.exe /X{7E84FAC8-C518-40F9-9807-7455301D6D25}
                Scribus 1.3.3.13-->C:\Program Files\Scribus 1.3.3.13\uninst.exe
                Shockwave-->C:\Windows\System32\Macromed\SHOCKW~1\UNWISE.EXE C:\Windows\System32\Macromed\SHOCKW~1\Install.log
                Skype Toolbars-->MsiExec.exe /I{981029E0-7FC9-4CF3-AB39-6F133621921A}
                Skype(TM) 4.2-->MsiExec.exe /X{D103C4BA-F905-437A-8049-DB24763BBE36}
                smartision ScreenCopy 2.3-->"C:\Program Files\smartision\ScreenCopy\unins000.exe"
                Stellarium 0.10.2-->"C:\Program Files\Stellarium\unins000.exe"
                Sweet Home 3D version 2.1-->"C:\Program Files\Sweet Home 3D\unins000.exe"
                Synaptics Pointing Device Driver-->rundll32.exe "C:\Program Files\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall
                TOSHIBA Disc Creator-->MsiExec.exe /X{5DA0E02F-970B-424B-BF41-513A5018E4C0}
                TOSHIBA DVD PLAYER-->C:\Program Files\InstallShield Installation Information\{6C5F3BDC-0A1B-4436-A696-5939629D5C31}\setup.exe -runfromtemp -l0x040c -ADDREMOVE -removeonly
                TOSHIBA eco Utility-->C:\Program Files\InstallShield Installation Information\{53536479-DFB0-47ED-9D10-43F3708C222D}\setup.exe -runfromtemp -l0x040c
                TOSHIBA eco Utility-->C:\Program Files\InstallShield Installation Information\{53536479-DFB0-47ED-9D10-43F3708C222D}\setup.exe -runfromtemp -l0x040c
                TOSHIBA Extended Tiles for Windows Mobility Center-->C:\Program Files\InstallShield Installation Information\{617C36FD-0CBE-4600-84B2-441CEB12FADF}\setup.exe -runfromtemp -l0x040c
                TOSHIBA Flash Cards Support Utility-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{620BBA5E-F848-4D56-8BDA-584E44584C5E}
                TOSHIBA Flash Cards Support Utility-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{620BBA5E-F848-4D56-8BDA-584E44584C5E}
                TOSHIBA HDD/SSD Alert-->C:\Program Files\InstallShield Installation Information\{D4322448-B6AF-4316-B859-D8A0E84DCB38}\setup.exe -runfromtemp -l0x040c
                TOSHIBA HDD/SSD Alert-->C:\Program Files\InstallShield Installation Information\{D4322448-B6AF-4316-B859-D8A0E84DCB38}\setup.exe -runfromtemp -l0x040c
                TOSHIBA PC Health Monitor-->MsiExec.exe /X{9DECD0F9-D3E8-48B0-A390-1CF09F54E3A4}
                TOSHIBA SD Memory Utilities-->MsiExec.exe /X{EBFF48F5-3CFA-436F-8FD5-94FB01D3A0A7}
                TOSHIBA Service Station-->C:\Program Files\InstallShield Installation Information\{AC6569FA-6919-442A-8552-073BE69E247A}\setup.exe -runfromtemp -l0x040c -removeonly
                TOSHIBA Value Added Package-->C:\Program Files\TOSHIBA\TVAP\Setup.exe
                TOSHIBA Web Camera Application-->C:\Program Files\InstallShield Installation Information\{5E6F6CF3-BACC-4144-868C-E14622C658F3}\setup.exe -runfromtemp -l0x040c -removeonly
                Tout sur les verbes Français-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{CBF3E9B0-41C6-4B87-8448-CFF53B4CB1FF}\setup.exe" -l0x40c
                Update for Microsoft .NET Framework 3.5 SP1 (KB963707)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {B2AE9C82-DC7B-3641-BFC8-87275C4F3607} /qb+ REBOOTPROMPT=""
                VLC media player 1.0.3-->C:\Program Files\VideoLAN\VLC\uninstall.exe
                Widestream6-->MsiExec.exe /X{835525BE-63BD-4EC4-9425-00CEAD4849C2}
                Windows Live Call-->MsiExec.exe /I{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}
                Windows Live Communications Platform-->MsiExec.exe /I{ED00D08A-3C5F-488D-93A0-A04F21F23956}
                Windows Live Messenger-->MsiExec.exe /X{770F1BEC-2871-4E70-B837-FB8525FFA3B1}
                Windows Live OneCare safety scanner-->"C:\Program Files\Windows Live Safety Center\UnInstall.exe"
                Windows Live OneCare safety scanner-->MsiExec.exe /X{FE0646A7-19D0-41B4-A2BB-2C35D644270D}
                XnView 1.96.5-->"C:\Program Files\XnView\unins000.exe"
                Yahoo! Toolbar-->C:\PROGRA~1\Yahoo!\Common\UNYT_W~1.EXE
                0
                1. La suite de info :
                  ======Hosts File======

                  127.0.0.1 www.007guard.com
                  127.0.0.1 007guard.com
                  127.0.0.1 008i.com
                  127.0.0.1 www.008k.com
                  127.0.0.1 008k.com
                  127.0.0.1 www.00hq.com
                  127.0.0.1 00hq.com
                  127.0.0.1 010402.com
                  127.0.0.1 www.032439.com
                  127.0.0.1 032439.com

                  ======Security center information======

                  AS: Windows Defender

                  ======System event log======

                  Computer Name: Ordi60
                  Event Code: 1003
                  Message: Votre ordinateur n'a pas pu renouveler son adresse à partir du réseau (à partir du serveur DHCP) pour la carte réseau dont l'adresse réseau est 705AB66D14B9. Il s'est produit l'erreur suivante :
                  L'opération a été annulée par l'utilisateur.. Votre ordinateur va continuer à essayer d'obtenir sa propre adresse auprès du serveur d'adresse réseau (DHCP).
                  Record Number: 38457
                  Source Name: Microsoft-Windows-Dhcp-Client
                  Time Written: 20100204164535.000000-000
                  Event Type: Avertissement
                  User:

                  Computer Name: Ordi60
                  Event Code: 134
                  Message: NtpClient n'a pas pu définir d'homologue manuel à utiliser comme source de temps en raison d'une erreur de résolution DNS sur " time.windows.com,0x9 ". NtpClient réessaiera dans 15 minutes, et à nouveau une fois le double de l'intervalle de nouvelle tentative écoulé. L'erreur était : Hôte inconnu. (0x80072AF9)
                  Record Number: 38450
                  Source Name: Microsoft-Windows-Time-Service
                  Time Written: 20100204164513.000000-000
                  Event Type: Avertissement
                  User:

                  Computer Name: Ordi60
                  Event Code: 134
                  Message: NtpClient n'a pas pu définir d'homologue manuel à utiliser comme source de temps en raison d'une erreur de résolution DNS sur " time.windows.com,0x9 ". NtpClient réessaiera dans 15 minutes, et à nouveau une fois le double de l'intervalle de nouvelle tentative écoulé. L'erreur était : Hôte inconnu. (0x80072AF9)
                  Record Number: 38441
                  Source Name: Microsoft-Windows-Time-Service
                  Time Written: 20100204164427.000000-000
                  Event Type: Avertissement
                  User:

                  Computer Name: Ordi60
                  Event Code: 134
                  Message: NtpClient n'a pas pu définir d'homologue manuel à utiliser comme source de temps en raison d'une erreur de résolution DNS sur " time.windows.com,0x9 ". NtpClient réessaiera dans 15 minutes, et à nouveau une fois le double de l'intervalle de nouvelle tentative écoulé. L'erreur était : Hôte inconnu. (0x80072AF9)
                  Record Number: 38413
                  Source Name: Microsoft-Windows-Time-Service
                  Time Written: 20100204164415.000000-000
                  Event Type: Avertissement
                  User:

                  Computer Name: Ordi60
                  Event Code: 4001
                  Message: Le Service d'autoconfiguration WLAN s'est arrêté correctement.

                  Record Number: 38398
                  Source Name: Microsoft-Windows-WLAN-AutoConfig
                  Time Written: 20100104210946.921764-000
                  Event Type: Avertissement
                  User: AUTORITE NT\SYSTEM

                  =====Application event log=====

                  Computer Name: WIN-6W4T16VRKO8
                  Event Code: 4354
                  Message: Le système d'événements de COM+ n'a pas pu déclencher la méthode ConnectionMadeNoQOCInfo de l'abonnement {63BB664F-869E-4C0E-90E4-EDF4948919C8}-{00000000-0000-0000-0000-000000000000}-{00000000-0000-0000-0000-000000000000}. L'abonné a renvoyé HRESULT 80040210.
                  Record Number: 5019
                  Source Name: Microsoft-Windows-EventSystem
                  Time Written: 20100227114640.000000-000
                  Event Type: Avertissement
                  User:

                  Computer Name: WIN-6W4T16VRKO8
                  Event Code: 4354
                  Message: Le système d'événements de COM+ n'a pas pu déclencher la méthode ConnectionMadeNoQOCInfo de l'abonnement {02C1B6C0-46D7-47C8-90C1-D916E72424EA}-{00000000-0000-0000-0000-000000000000}-{00000000-0000-0000-0000-000000000000}. L'abonné a renvoyé HRESULT 80040210.
                  Record Number: 5018
                  Source Name: Microsoft-Windows-EventSystem
                  Time Written: 20100227114640.000000-000
                  Event Type: Avertissement
                  User:

                  Computer Name: WIN-6W4T16VRKO8
                  Event Code: 4354
                  Message: Le système d'événements de COM+ n'a pas pu déclencher la méthode ConnectionMadeNoQOCInfo de l'abonnement {EB26C728-035F-4F7E-A67B-ABD5E3ADAC78}-{00000000-0000-0000-0000-000000000000}-{00000000-0000-0000-0000-000000000000}. L'abonné a renvoyé HRESULT 80040210.
                  Record Number: 5017
                  Source Name: Microsoft-Windows-EventSystem
                  Time Written: 20100227114640.000000-000
                  Event Type: Avertissement
                  User:

                  Computer Name: WIN-6W4T16VRKO8
                  Event Code: 10
                  Message: Le filtre d'événement avec la requête « SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99 » n'a pas pu être réactivé dans l'espace de noms « //./root/CIMV2 » à cause de l'erreur 0x80041003. Les événements ne peuvent pas être délivrés à travers ce filtre tant que le problème ne sera pas corrigé.
                  Record Number: 5006
                  Source Name: Microsoft-Windows-WMI
                  Time Written: 20100227114404.000000-000
                  Event Type: Erreur
                  User:

                  Computer Name: Ordi60
                  Event Code: 1008
                  Message: Le service Windows Search tente de supprimer l'ancien catalogue.

                  Record Number: 4904
                  Source Name: Microsoft-Windows-Search
                  Time Written: 20100204164553.000000-000
                  Event Type: Avertissement
                  User:

                  =====Security event log=====

                  Computer Name: Ordi60
                  Event Code: 4648
                  Message: Tentative d'ouverture de session en utilisant des informations d'identification explicites.

                  Sujet :
                  ID de sécurité : S-1-5-18
                  Nom du compte : ORDI60$
                  Domaine du compte : WORKGROUP
                  ID d'ouverture de session : 0x3e7
                  GUID d'ouverture de session : {00000000-0000-0000-0000-000000000000}

                  Compte dont les informations d'identification ont été utilisées :
                  Nom du compte : SYSTEM
                  Domaine du compte : AUTORITE NT
                  GUID d'ouverture de session : {00000000-0000-0000-0000-000000000000}

                  Serveur cible :
                  Nom du serveur cible : localhost
                  Informations supplémentaires : localhost

                  Informations sur le processus :
                  ID du processus : 0x2bc
                  Nom du processus : C:\Windows\System32\services.exe

                  Informations sur le réseau :
                  Adresse du réseau : -
                  Port : -

                  Cet événement est généré lorsqu'un processus tente d'ouvrir une session pour un compte en spécifiant explicitement les informations d'identification de ce compte. Ceci se produit le plus souvent dans les configurations par lot comme les tâches planifiées, ou avec l'utilisation de la commande RUNAS.
                  Record Number: 8014
                  Source Name: Microsoft-Windows-Security-Auditing
                  Time Written: 20100104210817.939564-000
                  Event Type: Succès de l'audit
                  User:

                  Computer Name: Ordi60
                  Event Code: 4672
                  Message: Privilèges spéciaux attribués à la nouvelle ouverture de session.

                  Sujet :
                  ID de sécurité : S-1-5-18
                  Nom du compte : SYSTEM
                  Domaine du compte : AUTORITE NT
                  ID d'ouverture de session : 0x3e7

                  Privilèges : SeAssignPrimaryTokenPrivilege
                  SeTcbPrivilege
                  SeSecurityPrivilege
                  SeTakeOwnershipPrivilege
                  SeLoadDriverPrivilege
                  SeBackupPrivilege
                  SeRestorePrivilege
                  SeDebugPrivilege
                  SeAuditPrivilege
                  SeSystemEnvironmentPrivilege
                  SeImpersonatePrivilege
                  Record Number: 8013
                  Source Name: Microsoft-Windows-Security-Auditing
                  Time Written: 20100104210814.742564-000
                  Event Type: Succès de l'audit
                  User:

                  Computer Name: Ordi60
                  Event Code: 4624
                  Message: L'ouverture de session d'un compte s'est correctement déroulée.

                  Sujet :
                  ID de sécurité : S-1-5-18
                  Nom du compte : ORDI60$
                  Domaine du compte : WORKGROUP
                  ID d'ouverture de session : 0x3e7

                  Type d'ouverture de session : 5

                  Nouvelle ouverture de session :
                  ID de sécurité : S-1-5-18
                  Nom du compte : SYSTEM
                  Domaine du compte : AUTORITE NT
                  ID d'ouverture de session : 0x3e7
                  GUID d'ouverture de session : {00000000-0000-0000-0000-000000000000}

                  Informations sur le processus :
                  ID du processus : 0x2bc
                  Nom du processus : C:\Windows\System32\services.exe

                  Informations sur le réseau :
                  Nom de la station de travail :
                  Adresse du réseau source : -
                  Port source : -

                  Informations détaillées sur l'authentification :
                  Processus d'ouverture de session : Advapi
                  Package d'authentification : Negotiate
                  Services en transit : -
                  Nom du package (NTLM uniquement) : -
                  Longueur de la clé : 0

                  Cet événement est généré lors de la création d'une ouverture de session. Il est généré sur l'ordinateur sur lequel l'ouverture de session a été effectuée.

                  Le champ Objet indique le compte sur le système local qui a demandé l'ouverture de session. Il s'agit le plus souvent d'un service, comme le service Serveur, ou un processus local tel que Winlogon.exe ou Services.exe.

                  Le champ Type d'ouverture de session indique le type d'ouverture de session qui s'est produit. Les types les plus courants sont 2 (interactif) et 3 (réseau).

                  Le champ Nouvelle ouverture de session indique le compte pour lequel la nouvelle ouverture de session a été créée, par exemple, le compte qui s'est connecté.

                  Les champs relatifs au réseau indiquent la provenance d'une demande d'ouverture de session à distance. Le nom de la station de travail n'étant pas toujours disponible, peut être laissé vide dans certains cas.

                  Les champs relatifs aux informations d'authentification fournissent des détails sur cette demande d'ouverture de session spécifique.
                  - Le GUID d'ouverture de session est un identificateur unique pouvant servir à associer cet événement à un événement KDC .
                  - Les services en transit indiquent les services intermédiaires qui ont participé à cette demande d'ouverture de session.
                  - Nom du package indique quel est le sous-protocole qui a été utilisé parmi les protocoles NTLM.
                  - La longueur de la clé indique la longueur de la clé de session générée. Elle a la valeur 0 si aucune clé de session n'a été demandée.
                  Record Number: 8012
                  Source Name: Microsoft-Windows-Security-Auditing
                  Time Written: 20100104210814.742564-000
                  Event Type: Succès de l'audit
                  User:

                  Computer Name: Ordi60
                  Event Code: 4648
                  Message: Tentative d'ouverture de session en utilisant des informations d'identification explicites.

                  Sujet :
                  ID de sécurité : S-1-5-18
                  Nom du compte : ORDI60$
                  Domaine du compte : WORKGROUP
                  ID d'ouverture de session : 0x3e7
                  GUID d'ouverture de session : {00000000-0000-0000-0000-000000000000}

                  Compte dont les informations d'identification ont été utilisées :
                  Nom du compte : SYSTEM
                  Domaine du compte : AUTORITE NT
                  GUID d'ouverture de session : {00000000-0000-0000-0000-000000000000}

                  Serveur cible :
                  Nom du serveur cible : localhost
                  Informations supplémentaires : localhost

                  Informations sur le processus :
                  ID du processus : 0x2bc
                  Nom du processus : C:\Windows\System32\services.exe

                  Informations sur le réseau :
                  Adresse du réseau : -
                  Port : -

                  Cet événement est généré lorsqu'un processus tente d'ouvrir une session pour un compte en spécifiant explicitement les informations d'identification de ce compte. Ceci se produit le plus souvent dans les configurations par lot comme les tâches planifiées, ou avec l'utilisation de la commande RUNAS.
                  Record Number: 8011
                  Source Name: Microsoft-Windows-Security-Auditing
                  Time Written: 20100104210814.742564-000
                  Event Type: Succès de l'audit
                  User:

                  Computer Name: Ordi60
                  Event Code: 1102
                  Message: Le journal d'audit a été effacé.
                  Objet :
                  ID de sécurité : S-1-5-21-4018714082-2724234979-3037645356-500
                  Nom de compte : Administrateur
                  Nom de domaine : Ordi60
                  ID de connexion : 0x26199
                  Record Number: 8010
                  Source Name: Microsoft-Windows-Eventlog
                  Time Written: 20100104210803.261564-000
                  Event Type: Succès de l'audit
                  User:

                  ======Environment variables======

                  "ComSpec"=%SystemRoot%\system32\cmd.exe
                  "FP_NO_HOST_CHECK"=NO
                  "OS"=Windows_NT
                  "Path"=C:\Program Files\PC Connectivity Solution\;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\QuickTime\QTSystem\
                  "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
                  "PROCESSOR_ARCHITECTURE"=x86
                  "TEMP"=%SystemRoot%\TEMP
                  "TMP"=%SystemRoot%\TEMP
                  "USERNAME"=SYSTEM
                  "windir"=%SystemRoot%
                  "PROCESSOR_LEVEL"=6
                  "PROCESSOR_IDENTIFIER"=x86 Family 6 Model 23 Stepping 10, GenuineIntel
                  "PROCESSOR_REVISION"=170a
                  "NUMBER_OF_PROCESSORS"=2
                  "TRACE_FORMAT_SEARCH_PATH"=\\NTREL202.ntdev.corp.microsoft.com\4F18C3A5-CA09-4DBD-B6FC-219FDD4C6BE0\TraceFormat
                  "DFSTRACINGON"=FALSE
                  "CLASSPATH"=.;C:\Program Files\Java\jre6\lib\ext\QTJava.zip
                  "QTJAVA"=C:\Program Files\Java\jre6\lib\ext\QTJava.zip

                  -----------------EOF-----------------
                  0
                  1. Moi j'ai eu que sa a 100% et il s'appelle List'em.log:

                    HKLM\SYSTEM\CCS\Services\Tcpip\..\{C8C4B60B-7FB5-4391-9543-4C5B7BA02502}: DhcpNameServer=192.168.1.1
                    HKLM\SYSTEM\CCS\Services\Tcpip\..\{E53D5466-FB08-4222-A13D-D7077430E6C4}: DhcpNameServer=192.168.1.1
                    HKLM\SYSTEM\CS1\Services\Tcpip\..\{C8C4B60B-7FB5-4391-9543-4C5B7BA02502}: DhcpNameServer=192.168.1.1
                    HKLM\SYSTEM\CS1\Services\Tcpip\..\{E53D5466-FB08-4222-A13D-D7077430E6C4}: DhcpNameServer=192.168.1.1
                    HKLM\SYSTEM\CS2\Services\Tcpip\..\{E53D5466-FB08-4222-A13D-D7077430E6C4}: DhcpNameServer=192.168.1.1
                    HKLM\SYSTEM\CS3\Services\Tcpip\..\{C8C4B60B-7FB5-4391-9543-4C5B7BA02502}: DhcpNameServer=192.168.1.1
                    HKLM\SYSTEM\CS3\Services\Tcpip\..\{E53D5466-FB08-4222-A13D-D7077430E6C4}: DhcpNameServer=192.168.1.1
                    HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
                    HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
                    HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
                    0
                    1. Contributeur sécurité
                      désactives provisoirement toutes tes protections

                      fait clic droit "executer en tant qu'administrateur" pour Vista
                      0
                    2. d'accord je le refais ??
                      0
                    3. Contributeur sécurité
                      oui comme indiqué juste au dessus
                      0
                    4. Tien voici le rapport Catchme (Il ma l'air très court mais bon)

                      catchme 0.3.1398.3 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                      Rootkit scan 2010-04-23 17:50:06
                      Windows 6.0.6002 Service Pack 2 FAT NTAPI

                      scanning hidden processes ...

                      scanning hidden services ...

                      scanning hidden autostart entries ...

                      scanning hidden files ...

                      scan completed successfully
                      hidden processes: 0
                      hidden services: 0
                      hidden files: 0
                      0
                    5. Contributeur sécurité
                      non

                      cherches un killem.txt sur le bureau
                      0
                  2. C'est bon le voici (il etait dans le disque dur "Vista")

                    List'em by g3n-h@ckm@n 1.7.2.1

                    User : Collégien (Utilisateurs)
                    Update on 22/04/2010 by g3n-h@ckm@n ::::: 16.15
                    Start at: 17:38:46 | 23/04/2010

                    Celeron(R) Dual-Core CPU T3100 @ 1.90GHz
                    Microsoft® Windows Vista(TM) Édition Familiale Premium (6.0.6002 32-bit) # Service Pack 2
                    Internet Explorer 8.0.6001.18904
                    Windows Firewall Status : Enabled

                    C:\ -> Disque fixe local | 74,22 Go (37,41 Go free) [Vista] | NTFS
                    D:\ -> Disque fixe local | 9,76 Go (6,56 Go free) [Jeux] | NTFS
                    E:\ -> Disque fixe local | 63,6 Go (63,5 Go free) [Data] | NTFS
                    F:\ -> Disque CD-ROM

                    Boot: Normal

                    ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running

                    C:\Windows\System32\smss.exe
                    C:\Windows\system32\csrss.exe
                    C:\Windows\system32\wininit.exe
                    C:\Windows\system32\csrss.exe
                    C:\Windows\system32\services.exe
                    C:\Windows\system32\winlogon.exe
                    C:\Windows\system32\lsass.exe
                    C:\Windows\system32\lsm.exe
                    C:\Windows\system32\svchost.exe
                    C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
                    C:\Windows\system32\svchost.exe
                    C:\Windows\System32\svchost.exe
                    C:\Windows\System32\svchost.exe
                    C:\Windows\System32\svchost.exe
                    C:\Windows\system32\svchost.exe
                    C:\Windows\system32\svchost.exe
                    C:\Windows\system32\SLsvc.exe
                    C:\Windows\system32\svchost.exe
                    C:\Windows\system32\svchost.exe
                    C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
                    C:\Windows\System32\spoolsv.exe
                    C:\Windows\system32\svchost.exe
                    C:\Windows\system32\taskeng.exe
                    C:\Windows\system32\Dwm.exe
                    C:\Windows\system32\taskeng.exe
                    C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe
                    C:\Windows\Explorer.EXE
                    C:\Program Files\TOSHIBA\TOSHIBA Web Camera Application\TWebCameraSrv.exe
                    C:\Windows\system32\svchost.exe
                    C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
                    C:\Program Files\Windows Defender\MSASCui.exe
                    C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe
                    C:\Windows\system32\TODDSrv.exe
                    C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
                    C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
                    C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe
                    C:\Windows\System32\igfxtray.exe
                    C:\Windows\System32\hkcmd.exe
                    C:\Windows\System32\igfxpers.exe
                    C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
                    C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
                    C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe
                    C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
                    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                    C:\Program Files\TOSHIBA\TECO\TEco.exe
                    C:\Program Files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe
                    C:\Program Files\TOSHIBA\TECO\TecoService.exe
                    C:\Program Files\TOSHIBA\TPHM\TPCHWMsg.exe
                    C:\Program Files\Alwil Software\Avast5\AvastUI.exe
                    C:\Program Files\Common Files\Java\Java Update\jusched.exe
                    C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
                    C:\Program Files\RocketDock\RocketDock.exe
                    C:\Program Files\Windows Sidebar\sidebar.exe
                    C:\Program Files\Larousse\Encyclopédie Universelle Larousse 2009\bin\hyperappel.exe
                    C:\Windows\System32\svchost.exe
                    C:\Program Files\Windows Media Player\wmpnscfg.exe
                    C:\Windows\system32\SearchIndexer.exe
                    C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
                    C:\Windows\system32\wbem\wmiprvse.exe
                    C:\Windows\system32\igfxsrvc.exe
                    C:\Users\Collégien\AppData\Local\Google\Update\1.2.183.23\GoogleCrashHandler.exe
                    C:\Windows\system32\igfxext.exe
                    C:\Program Files\Windows Sidebar\sidebar.exe
                    C:\Program Files\Windows Media Player\wmpnetwk.exe
                    C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
                    C:\Windows\system32\SearchProtocolHost.exe
                    C:\Windows\system32\conime.exe
                    C:\Windows\system32\ctfmon.exe
                    C:\Windows\system32\SearchFilterHost.exe
                    C:\Program Files\List_Kill'em\List_Kill'em.exe
                    C:\Windows\system32\cmd.exe
                    C:\Windows\system32\DllHost.exe
                    C:\Program Files\List_Kill'em\pv.exe

                    ======================
                    Keys "Run"
                    ======================

                    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                    RocketDock REG_SZ "C:\Program Files\RocketDock\RocketDock.exe"
                    Sidebar REG_SZ C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                    Hyperappel de l'Encyclopédie Universelle Larousse REG_EXPAND_SZ "C:\Program Files\Larousse\Encyclopédie Universelle Larousse 2009\bin\Hyperappel.exe"
                    Google Update REG_SZ "C:\Users\Collégien\AppData\Local\Google\Update\GoogleUpdate.exe" /c
                    WMPNSCFG REG_SZ C:\Program Files\Windows Media Player\WMPNSCFG.exe

                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                    Windows Defender REG_EXPAND_SZ %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                    RtHDVCpl REG_SZ C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
                    KeNotify REG_SZ C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
                    TosSENotify REG_SZ C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe
                    IgfxTray REG_SZ C:\Windows\system32\igfxtray.exe
                    HotKeysCmds REG_SZ C:\Windows\system32\hkcmd.exe
                    Persistence REG_SZ C:\Windows\system32\igfxpers.exe
                    TPwrMain REG_EXPAND_SZ %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
                    HSON REG_EXPAND_SZ %ProgramFiles%\TOSHIBA\TBS\HSON.exe
                    SmoothView REG_EXPAND_SZ %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
                    00TCrdMain REG_EXPAND_SZ %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
                    SynTPEnh REG_SZ C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                    Teco REG_EXPAND_SZ "%ProgramFiles%\TOSHIBA\TECO\Teco.exe" /r
                    ToshibaServiceStation REG_SZ "C:\Program Files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" /hide:60
                    TPCHWMsg REG_EXPAND_SZ %ProgramFiles%\TOSHIBA\TPHM\TPCHWMsg.exe
                    avast5 REG_SZ C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui
                    SunJavaUpdateSched REG_SZ "C:\Program Files\Common Files\Java\Java Update\jusched.exe"

                    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]

                    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]

                    =====================
                    Other Keys
                    =====================

                    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
                    ConsentPromptBehaviorAdmin REG_DWORD 2 (0x2)
                    ConsentPromptBehaviorUser REG_DWORD 1 (0x1)
                    EnableInstallerDetection REG_DWORD 1 (0x1)
                    EnableLUA REG_DWORD 0 (0x0)
                    EnableSecureUIAPaths REG_DWORD 1 (0x1)
                    EnableVirtualization REG_DWORD 1 (0x1)
                    PromptOnSecureDesktop REG_DWORD 1 (0x1)
                    ValidateAdminCodeSignatures REG_DWORD 0 (0x0)
                    dontdisplaylastusername REG_DWORD 0 (0x0)
                    legalnoticecaption REG_SZ
                    legalnoticetext REG_SZ
                    scforceoption REG_DWORD 0 (0x0)
                    shutdownwithoutlogon REG_DWORD 1 (0x1)
                    undockwithoutlogon REG_DWORD 1 (0x1)
                    FilterAdministratorToken REG_DWORD 0 (0x0)
                    EnableUIADesktopToggle REG_DWORD 0 (0x0)

                    ===============

                    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
                    NoDriveTypeAutoRun REG_DWORD 145 (0x91)
                    NoRun REG_DWORD 0 (0x0)

                    ===============

                    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
                    BindDirectlyToPropertySetStorage REG_DWORD 0 (0x0)
                    NoRun REG_DWORD 0 (0x0)

                    ===============

                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
                    AppInit_DLLS REG_SZ

                    ===============

                    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
                    ReportBootOk REG_SZ 1
                    Shell REG_SZ explorer.exe
                    Userinit REG_SZ C:\Windows\system32\userinit.exe,
                    VmApplet REG_SZ rundll32 shell32,Control_RunDLL "sysdm.cpl"
                    AutoRestartShell REG_DWORD 1 (0x1)
                    LegalNoticeCaption REG_SZ
                    LegalNoticeText REG_SZ
                    PowerdownAfterShutdown REG_SZ 0
                    ShutdownWithoutLogon REG_SZ 0
                    cachedlogonscount REG_SZ 10
                    forceunlocklogon REG_DWORD 0 (0x0)
                    passwordexpirywarning REG_DWORD 14 (0xe)
                    Background REG_SZ 0 0 0
                    DebugServerCommand REG_SZ no
                    WinStationsDisabled REG_SZ 0
                    DisableCAD REG_DWORD 1 (0x1)
                    scremoveoption REG_SZ 0
                    ShutdownFlags REG_DWORD 39 (0x27)
                    DefaultDomainName REG_SZ
                    DefaultUserName REG_SZ Admin Parents
                    AutoAdminLogon REG_SZ 0

                    ===============

                    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\igfxcui]

                    ===============

                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]

                    ===============

                    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

                    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

                    ===============
                    ActivX controls
                    ===============

                    [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\CabBuilder]
                    [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{4DD20514-9520-40A7-9CD6-66883643A20B}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{5D6F45B3-9043-443D-A792-115447494D24}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{8AD9C840-044E-11D1-B3E9-00805F499D93}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{C3F79A2B-B9B4-4A66-B012-3EE46475B072}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}]

                    ===============
                    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{26923b43-4d38-484f-9b9e-de460746276c}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{08B0E5C0-4FCB-11CF-AAA5-00401C608500}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{166B1BCA-3F9C-11CF-8075-444553540000}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2179C5D3-EBFF-11CF-B6FD-00AA00B4E220}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2A202491-F00D-11cf-87CC-0020AFEECF20}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{3af36230-a269-11d1-b5bf-0000f8051515}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA848-CC51-11CF-AAFA-00AA00B6015C}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA855-CC51-11CF-AAFA-00AA00B6015F}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{45ea75a0-a269-11d1-b5bf-0000f8051515}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4f645220-306d-11d2-995d-00c04f98bbc9}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5fd399c0-a70a-11d1-9948-00c04f98bbc9}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{630b1da0-b465-11d1-9948-00c04f98bbc9}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6fab99d0-bab8-11d1-994a-00c04f98bbc9}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7C028AF8-F614-47B3-82DA-BA94E41B1089}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4340}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4383}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9381D8F2-0288-11D0-9501-00AA00B911A5}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C6BAF60B-6E91-453F-BFF9-D3789CFEFCDD}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C9E9A340-D1F1-11D0-821E-444553540600}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CDD7975E-60F8-41d5-8149-19E51D6F71D0}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{D27CDB6E-AE6D-11CF-96B8-444553540000}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{de5aed00-a4bf-11d1-9948-00c04f98bbc9}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{E92B03AB-B707-11d2-9CBD-0000F87A369E}]

                    ==============
                    BHO :
                    ======

                    [<NO NAME> REG_SZ ]
                    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
                    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}]

                    ===
                    DNS
                    ===

                    HKLM\SYSTEM\CS1\Services\Tcpip\..\{E53D5466-FB08-4222-A13D-D7077430E6C4}: DhcpNameServer=192.168.1.1
                    HKLM\SYSTEM\CS2\Services\Tcpip\..\{E53D5466-FB08-4222-A13D-D7077430E6C4}: DhcpNameServer=192.168.1.1
                    HKLM\SYSTEM\CS3\Services\Tcpip\..\{C8C4B60B-7FB5-4391-9543-4C5B7BA02502}: DhcpNameServer=192.168.1.1
                    HKLM\SYSTEM\CS3\Services\Tcpip\..\{E53D5466-FB08-4222-A13D-D7077430E6C4}: DhcpNameServer=192.168.1.1
                    HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
                    HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
                    HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1

                    ================
                    Internet Explorer :
                    ================

                    [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
                    Start Page REG_SZ https://www.msn.com/fr-fr
                    Local Page REG_SZ C:\Windows\System32\blank.htm
                    Default_Search_URL REG_SZ http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                    Default_Page_URL REG_SZ http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
                    Search Page REG_SZ http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch

                    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                    Start Page REG_SZ https://www.msn.com/fr-fr
                    Local Page REG_SZ C:\Windows\system32\blank.htm

                    ========
                    Services
                    ========

                    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services]

                    Ndisuio : 0x3 ( OK = 3 )
                    EapHost : 0x3 ( OK = 2 )
                    Wlansvc : 0x2 ( OK = 2 )
                    SharedAccess : 0x4 ( OK = 2 )
                    windefend : 0x2 ( OK = 2 )
                    wuauserv : 0x2 ( OK = 2 )
                    wscsvc : 0x2 ( OK = 2 )

                    ========
                    Safemode
                    ========

                    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot : OK !!
                    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal : OK !!
                    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network : OK !!

                    =========
                    Atapi.sys
                    =========

                    C:\Windows\System32\drivers\atapi.sys :
                    MD5 :: [9c0e70031905adbf94edb9ea14af943b]
                    SHA256 :: [88e4a250c22e919decedf1d59566265c473cdfac97440f25a6d05e6200223194]

                    C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_7f3e4ed9\atapi.sys :
                    MD5 :: [9c0e70031905adbf94edb9ea14af943b]
                    SHA256 :: [88e4a250c22e919decedf1d59566265c473cdfac97440f25a6d05e6200223194]

                    C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_b12d8e84\atapi.sys :
                    MD5 :: [1f05b78ab91c9075565a9d8a4b880bc4]
                    SHA256 :: [737be9f9376dab0ccdfed93ea6d67f0c432367ea63cd772a453485be769af3bd]

                    C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_b7393fc6\atapi.sys :
                    MD5 :: [e26ddfe464b464daf1c739122978d1d6]
                    SHA256 :: [e21bf50a64beb5eafdc1d6ba1aa559a75fd31ffb4a85ceb074884c58903c9b68]

                    C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys :
                    MD5 :: [4f4fcb8b6ea06784fb6d475b7ec7300f]
                    SHA256 :: [6202d85c9a75e3f01f5f94f069c4cd8a2b9295a182301eae5940ec3bc2c1d896]

                    C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_cc18792d\atapi.sys :
                    MD5 :: [2d9c903dc76a66813d350a562de40ed9]
                    SHA256 :: [82609f01a08c6842e4c17c077bb641c1429c0e6657964b7f2d114035e1bdcbf3]

                    C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.20847_none_dbb74a7b3d9afbc1\atapi.sys :
                    MD5 :: [e26ddfe464b464daf1c739122978d1d6]
                    SHA256 :: [e21bf50a64beb5eafdc1d6ba1aa559a75fd31ffb4a85ceb074884c58903c9b68]

                    C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a2189ce9c\atapi.sys :
                    MD5 :: [2d9c903dc76a66813d350a562de40ed9]
                    SHA256 :: [82609f01a08c6842e4c17c077bb641c1429c0e6657964b7f2d114035e1bdcbf3]

                    C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.22193_none_dd6376773aedb5e4\atapi.sys :
                    MD5 :: [9c0e70031905adbf94edb9ea14af943b]
                    SHA256 :: [88e4a250c22e919decedf1d59566265c473cdfac97440f25a6d05e6200223194]

                    C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_df23a1261eab99e8\atapi.sys :
                    MD5 :: [1f05b78ab91c9075565a9d8a4b880bc4]
                    SHA256 :: [737be9f9376dab0ccdfed93ea6d67f0c432367ea63cd772a453485be769af3bd]

                    Référence :
                    ==========

                    Win 2000_SP2 : ff953a8f08ca3f822127654375786bbe
                    Win 2000_SP4 : 8c718aa8c77041b3285d55a0ce980867
                    Win XP_32b : a64013e98426e1877cb653685c5c0009
                    Win XP_SP2_32b : CDFE4411A69C224BD1D11B2DA92DAC51
                    Win XP_SP3_32b : 9F3A2F5AA6875C72BF062C712CFA2674
                    Vista_32b : e03e8c99d15d0381e02743c36afc7c6f
                    Vista_SP1_32b : 2d9c903dc76a66813d350a562de40ed9
                    Vista_SP2_32b : 1F05B78AB91C9075565A9D8A4B880BC4
                    Vista_SP2_64b : 1898FAE8E07D97F2F6C2D5326C633FAC
                    Windows 7_32b : 80C40F7FDFC376E4C5FEEC28B41C119E
                    Windows 7_64b : 02062C0B390B7729EDC9E69C680A6F3C
                    Windows 7_32b_Ultimate : 338c86357871c167a96ab976519bf59e

                    =======
                    Drive :
                    =======

                    D'fragmenteur de disque Windows
                    Copyright (c) 2006 Microsoft Corp.

                    Rapport d'analyse pour le volume C: Vista

                    Taille du volume = 74.22 Go
                    Espace libre = 37.39 Go
                    tendue d'espace libre la plus grande = 23.91 Go
                    Pourcentage de fragmentation des fichiers = 3 %

                    Remarqueÿ: sur les volumes NTFS, les fragments de fichiers de plus de 64ÿMo ne sont pas inclus dans les statistiques de fragmentation.

                    Il n'est pas n'cessaire de d'fragmenter ce volume.

                    ¤¤¤¤¤¤¤¤¤¤ Files/folders :

                    Present !! : C:\Windows\System32\drivers\etc\hosts.msn
                    Present !! : C:\Windows\System32\drivers\wudfpf.sys
                    Present !! : C:\Windows\System32\drivers\wudfrd.sys"
                    Present !! : C:\Users\Coll'gien\AppData\Local\GDIPFONTCACHEV1.DAT
                    Present !! : C:\Users\Coll'gien\Local Settings\Temp\upx.exe
                    Present !! : C:\Users\Coll'gien\LOCAL Settings\Temp\igraal.exe
                    Present !! : C:\Users\Coll'gien\LOCAL Settings\Temp\KiweeToolbarSetup.exe
                    Present !! : C:\Users\Coll'gien\LOCAL Settings\Temp\UPX-3.04.46112.exe
                    Present !! : C:\Users\Coll'gien\LOCAL Settings\Temp\upx.exe

                    ¤¤¤¤¤¤¤¤¤¤ Keys :

                    Present !! : HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoRun
                    Present !! : HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoRun
                    Present !! : HKEY_USERS\S-1-5-21-4105654460-3376347969-2524529642-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoRun
                    Present !! : HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoRun
                    Present !! : HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoRun
                    Present !! : HKEY_USERS\S-1-5-21-4105654460-3376347969-2524529642-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoRun
                    Present !! : "HKCU\software\microsoft\internet explorer\searchscopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}"
                    Present !! : HKCR\CLSID\{ca3eb689-8f09-4026-aa10-b9534c691ce0}
                    Present !! : HKCR\Interface\{4897bba6-48d9-468c-8efa-846275d7701b}
                    Present !! : HKCR\TypeLib\{4509d3cc-b642-4745-b030-645b79522c6d}
                    Present !! : HKLM\software\Iminent

                    ============

                    catchme 0.3.1398.3 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                    Rootkit scan 2010-04-23 17:50:06
                    Windows 6.0.6002 Service Pack 2 FAT NTAPI

                    scanning hidden processes ...

                    scanning hidden services ...

                    scanning hidden autostart entries ...

                    scanning hidden files ...

                    scan completed successfully
                    hidden processes: 0
                    hidden services: 0
                    hidden files: 0

                    Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

                    device: opened successfully
                    user: MBR read successfully
                    called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys iaStor.sys hal.dll
                    kernel: MBR read successfully
                    user & kernel MBR OK

                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
                    cval REG_DWORD 1 (0x1)
                    UacDisableNotify REG_DWORD 1 (0x1)

                    ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

                    End of scan : 17:50:07,65
                    0
                    1. Contributeur sécurité
                      Relance List_Kill'em(soit en clic droit pour vista/7),avec le raccourci sur ton bureau.
                      mais cette fois-ci :

                      choisis l'option CLEAN
                      ton PC va redemarrer,

                      laisse travailler l'outil.

                      en fin de scan la fenetre se ferme , et tu as un rapport du nom de Kill'em.txt sur ton bureau ,

                      colle le contenu dans ta reponse

                      Tu peux le désinstaller ensuite

                      0
                      1. Kill'em by g3n-h@ckm@n 1.7.2.1

                        User : Collégien (Utilisateurs)
                        Update on 22/04/2010 by g3n-h@ckm@n ::::: 16.15
                        Start at: 18:48:08 | 23/04/2010

                        Celeron(R) Dual-Core CPU T3100 @ 1.90GHz
                        Microsoft® Windows Vista(TM) Édition Familiale Premium (6.0.6002 32-bit) # Service Pack 2
                        Internet Explorer 8.0.6001.18904
                        Windows Firewall Status : Enabled

                        C:\ -> Disque fixe local | 74,22 Go (37,31 Go free) [Vista] | NTFS
                        D:\ -> Disque fixe local | 9,76 Go (6,56 Go free) [Jeux] | NTFS
                        E:\ -> Disque fixe local | 63,6 Go (63,5 Go free) [Data] | NTFS
                        F:\ -> Disque CD-ROM

                        ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running

                        C:\Windows\System32\smss.exe
                        C:\Windows\system32\csrss.exe
                        C:\Windows\system32\csrss.exe
                        C:\Windows\system32\wininit.exe
                        C:\Windows\system32\services.exe
                        C:\Windows\system32\lsass.exe
                        C:\Windows\system32\lsm.exe
                        C:\Windows\system32\winlogon.exe
                        C:\Windows\system32\svchost.exe
                        C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
                        C:\Windows\system32\svchost.exe
                        C:\Windows\System32\svchost.exe
                        C:\Windows\System32\svchost.exe
                        C:\Windows\System32\svchost.exe
                        C:\Windows\system32\svchost.exe
                        C:\Windows\system32\svchost.exe
                        C:\Windows\system32\SLsvc.exe
                        C:\Windows\system32\svchost.exe
                        C:\Windows\system32\svchost.exe
                        C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
                        C:\Windows\system32\Dwm.exe
                        C:\Windows\Explorer.EXE
                        C:\Windows\system32\runonce.exe
                        C:\Windows\system32\cmd.exe
                        C:\Windows\System32\spoolsv.exe
                        C:\Windows\system32\taskeng.exe
                        C:\Windows\system32\svchost.exe
                        C:\Windows\system32\taskeng.exe
                        C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe
                        C:\Program Files\TOSHIBA\TOSHIBA Web Camera Application\TWebCameraSrv.exe
                        C:\Windows\system32\svchost.exe
                        C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
                        C:\Program Files\Google\Update\GoogleUpdate.exe
                        C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe
                        C:\Windows\system32\TODDSrv.exe
                        C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
                        C:\Program Files\TOSHIBA\TECO\TecoService.exe
                        C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
                        C:\Windows\System32\svchost.exe
                        C:\Windows\system32\SearchIndexer.exe
                        C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
                        C:\Windows\system32\wbem\wmiprvse.exe
                        C:\Windows\system32\PresentationSettings.exe
                        C:\Program Files\List_Kill'em\ERUNT.EXE
                        C:\Program Files\List_Kill'em\pv.exe

                        ¤¤¤¤¤¤¤¤¤¤ Files/folders :

                        Quarantined & Deleted !! : C:\Windows\System32\drivers\etc\hosts.msn
                        Quarantined & Deleted !! : C:\Windows\system32\drivers\wudfpf.sys
                        Quarantined & Deleted !! : C:\Windows\system32\drivers\wudfrd.sys
                        Quarantined & Deleted !! : C:\Users\Coll'gien\AppData\Local\GDIPFONTCACHEV1.DAT
                        Quarantined & Deleted !! : C:\Users\Coll'gien\Local Settings\Temp\upx.exe
                        Quarantined & Deleted !! : C:\Users\Coll'gien\LOCAL Settings\Temp\igraal.exe
                        Quarantined & Deleted !! : C:\Users\Coll'gien\LOCAL Settings\Temp\KiweeToolbarSetup.exe
                        Quarantined & Deleted !! : C:\Users\Coll'gien\LOCAL Settings\Temp\UPX-3.04.46112.exe
                        Quarantined & Deleted !! : C:\Users\Coll'gien\LOCAL Settings\Temp\catchme.dll
                        Deleted !! : C:\$Recycle.bin\S-1-5-21-4105654460-3376347969-2524529642-1006\$IMUE88F.exe
                        Deleted !! : C:\$Recycle.bin\S-1-5-21-4105654460-3376347969-2524529642-1006\$ISE1NJ1.9

                        ==============
                        host file OK !
                        ==============

                        ========
                        Registry
                        ========

                        Deleted : HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoRun
                        Deleted : HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoRun
                        Deleted : "HKCU\software\microsoft\internet explorer\searchscopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}"
                        Deleted : HKCR\CLSID\{ca3eb689-8f09-4026-aa10-b9534c691ce0}
                        Deleted : HKCR\Interface\{4897bba6-48d9-468c-8efa-846275d7701b}
                        Deleted : HKCR\TypeLib\{4509d3cc-b642-4745-b030-645b79522c6d}
                        Deleted : HKLM\software\Iminent
                        =================
                        Internet Explorer
                        =================

                        [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
                        Start Page REG_SZ https://www.msn.com/fr-fr/?ocid=iehp
                        Local Page REG_SZ C:\WINDOWS\system32\blank.htm
                        Default_Search_URL REG_SZ https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                        Default_Page_URL REG_SZ https://www.msn.com/fr-fr/?ocid=iehp
                        Search Page REG_SZ https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF

                        [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                        Start Page REG_SZ https://www.google.com/?gws_rd=ssl
                        Local Page REG_SZ C:\WINDOWS\system32\blank.htm
                        Search Page REG_SZ http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch

                        ===============
                        Security Center
                        ===============

                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
                        cval REG_DWORD 1 (0x1)
                        UacDisableNotify REG_DWORD 1 (0x1)
                        FirstRunDisabled REG_DWORD 1 (0x1)
                        AntiVirusDisableNotify REG_DWORD 0 (0x0)
                        FirewallDisableNotify REG_DWORD 0 (0x0)
                        UpdatesDisableNotify REG_DWORD 0 (0x0)
                        AntiVirusOverride REG_DWORD 1 (0x1)
                        FirewallOverride REG_DWORD 1 (0x1)

                        ========
                        Services
                        =========

                        Ndisuio : Start = 3
                        EapHost : Start = 2
                        Wlansvc : Start = 2
                        SharedAccess : Start = 2
                        windefend : Start = 2
                        wuauserv : Start = 2
                        wscsvc : Start = 2

                        ============
                        Disk Cleaned
                        anti-ver blaster : OK
                        Prefetch cleaned
                        ================

                        ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
                        0
                        1. Contributeur sécurité
                          (message précédent édité)

                          ok

                          ouvre l'explorateur Windows, cherche

                          C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_b12d8e84\atapi.sys

                          clic droit et Copier

                          mets toi dans C:\ et clic droit et Coller.

                          Clix droit sur le nouveau fichier et Renommer.

                          Tu l'appelles truc.bak

                          Tu ignores l'alerte.

                          ===

                          1. Télécharge The Avenger par Swandog46 sur le Bureau

                          http://www.geekstogo.com/forum/files/file/393-the-avenger-by-swandog46/

                          Clique sur Avenger.zip pour ouvrir le fichier
                          Extraire avenger.exe sur le bureau

                          2. Copier tout le texte en gras ci-dessous : mettre en surbrillance et appuyer sur les touches(Ctrl+C):

                          Begin copying here:

                          Files to move:
                          c:\truc.bak | c:\windows\system32\drivers\atapi.sys


                          IMPORTANT: Le code ci-dessus a été intentionnellement rédigé pour CET utilisateur.
                          si vous n'êtes pas CET utilisateur, NE PAS appliquer ces directives : elles pourraient endommager votre système.

                          Ferme toutes les applications et ton navigateur

                          3. Maintenant, lance The Avenger en cliquant sur son icône du bureau.

                          Vérifie que la case devant "Automatically disable any rootkits found" n'est pas cochée.

                          Cclique sur l'icone de droite (en rose et bleu). Le texte va se copier dans la fenêtre.

                          Clique sur Execute

                          4. The Avenger va automatiquement faire ce qui suit:

                          Il va Re-démarrer le système.


                          Je cherche beaucoup...et maintenant je trouve !
                          (sourire)
                          0
                          1. Je n'ai pas compris le premier il faut renommer atapi.sys en truc.bak ?? Mais comment tu dis de renommer le nouveau fichier il y en a pas
                            0
                        2. Contributeur sécurité
                          tu vas là

                          C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_b12d8e84\atapi.sys

                          cet atapi en gras tu en fait une copie sur C (copier coller)

                          ensuite cet atapi copié sur C tu le renommes en clic droit et tu l'appelles truc.bak

                          apres ca , faire la manip Avenger
                          0
                          1. Sa veut dire quoi une copie sur C:/
                            0
                            1. Contributeur sécurité
                              lis bien ce qui est écrit

                              ouvre l'explorateur Windows, cherche

                              C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_b12d8e84\atapi.sys

                              sur cet atapi tu fais clic droit et Copier

                              ensuite mets toi dans poste de travail\C:\ et clic droit et Coller.
                              0
                            2. D'accord en faite je mais ATAPI.SYS a l'entrée du disque dur C:/ (Vista)
                              0
                            3. Contributeur sécurité
                              une copie oui c'est ca...que tu renommes ensuite truc.bak

                              (vista, j'oubliais)
                              0
                            4. Et après c le quelle de fichier que je m'est en BAK celui dans C:/ ou celui dans C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_b12d8e84\
                              0
                            5. Contributeur sécurité
                              celui que tu as mis sur C pas l'autre
                              0
                          2. Bon voua la j'ai fini je f'ai quoi mtn ??
                            0
                            1. M'est mtn impossible d'ecrire sur commentcamarche avec google chrome c normal ?? (Il me dit Activer javascript)
                              0
                          3. Contributeur sécurité
                            as tu fais Avenger ?
                            0
                            1. Oui je les fais m'est mtn impossible d'utiliser Google Chrome
                              0
                              1. Contributeur sécurité
                                postes moi le rapport stp c:\avenger.txt

                                0
                                • 1
                                • 2