Virus de violation de droits d'auteur

Résolu
bonjour,

j'ai eu un virus qui m'a empeché d'avoir accès à mon bureau, avec une page "violation de droits d'auteurs...", j'ai réussi à avoir de nouveau accès au bureau, mais dès que j'allume mon ordinateur, le virus revient.

que dois je faire pour l'enlever totalement?

merci de votre aide.

30 réponses

Résumé de la discussion

Un utilisateur signale un virus qui affiche une page "violation de droits d'auteur" et réapparaît au démarrage, après avoir retrouvé l'accès au bureau. Plusieurs solutions techniques ont été proposées, notamment l'utilisation d'un outil de suppression spécialisé et des manipulations système décrites pour éliminer les composants malveillants et générer un rapport d'activité. Des éléments de réponse additionnels évoquent l'usage de journaux de sécurité et d'outils d'analyse comme HijackThis, tout en notant que les méthodes proposées dépendent du système et du contexte. D'autres mentions évoquent que les résultats varient et conseillent de vérifier les sources des outils et de réaliser des sauvegardes avant toute manipulation.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    ok

    pas mal de boulot

    ouvre l'explorateur Windows, cherche

    C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_cc18792d\atapi.sys

    fais clic droit dessus et Copier

    mets toi dans C:\ et clic droit et Coller.

    Clix droit sur le nouveau fichier et Renommer.

    Tu l'appelles truc.bak

    Tu ignores l'alerte.


    ===

    1. Télécharge The Avenger par Swandog46 sur le Bureau

    http://www.geekstogo.com/forum/files/file/393-the-avenger-by-swandog46/

    Clique sur Avenger.zip pour ouvrir le fichier
    Extraire avenger.exe sur le bureau

    2. Copier tout le texte en gras ci-dessous : mettre en surbrillance et appuyer sur les touches(Ctrl+C):

    Begin copying here:

    Files to move:
    c:\truc.bak | c:\windows\system32\drivers\atapi.sys


    IMPORTANT: Le code ci-dessus a été intentionnellement rédigé pour CET utilisateur.
    si vous n'êtes pas CET utilisateur, NE PAS appliquer ces directives : elles pourraient endommager votre système.

    Ferme toutes les applications et ton navigateur

    3. Maintenant, lance The Avenger en cliquant sur son icône du bureau.

    Vérifie que la case devant "Automatically disable any rootkits found" n'est pas cochée.

    Cclique sur l'icone de droite (en rose et bleu). Le texte va se copier dans la fenêtre.

    Clique sur Execute

    4. The Avenger va automatiquement faire ce qui suit:

    Il va Re-démarrer le système.
    Pendant le re-démarrage, il apparaitra brièvement une fenêtre de commande de windows noire sur le bureau, ceci est NORMAL.
    Après le re-démarrage, il crée un fichier log qui s'ouvrira, faisant apparaitre les actions exécutées par The Avenger. Ce fichier log se trouve ici : C:\avenger.txt
    The Avenger aura également sauvegardé tous les fichiers, etc., que tu lui as demandé de supprimer, les aura compactés (zipped) et tranféré l'archive zip ici C:\avenger\backup.zip.

    5. Pour finir copier/coller le contenu du ficher c:\avenger.txt dans ta réponse

    1
    1. Contributeur sécurité
      bonjour

      Télécharge ZHPDiag ( de Nicolas coolman ).
      https://www.zebulon.fr/telechargements/securite/systeme/zhpdiag.html

      (outil de diagnostic)

      Double clique sur le fichier d'installation, puis installe le avec les paramètres par défaut ( N'oublie pas de cocher " Créer une icône sur le bureau " )

      Lance ZHPDiag en double cliquant sur l'icône présente sur ton bureau (Clique droit -> Executer en tant qu'admin pour vista )

      Clique sur la loupe en haut à gauche, puis laisse l'outil scanner.

      Une fois le scan terminé, clique sur l'icône en forme de disquette et enregistre le fichier sur ton bureau.

      Rend toi sur Cjoint : http://www.cijoint.fr/

      Clique sur "Parcourir " dans la partie " Joindre un fichier[...] "

      Sélectionne le rapport ZHPdiag.txt qui se trouve sur ton bureau

      Clique ensuite sur "Cliquez ici pour déposer le fichier " et copie/colle le lien dans ton prochain message

      si soucis avec ci joint. fr => utiliser https://www.cjoint.com/
      0
      1. il faut que je "copie/colle" tout ce que m'a donné ZHPdiag.txt ?
        0
      2. Contributeur sécurité
        Rend toi sur Cjoint : http://www.cijoint.fr/

        Clique sur "Parcourir " dans la partie " Joindre un fichier[...] "

        Sélectionne le rapport ZHPdiag.txt qui se trouve sur ton bureau

        Clique ensuite sur "Cliquez ici pour déposer le fichier " et copie/colle le lien dans ton prochain message

        si soucis avec ci joint. fr => utiliser https://www.cjoint.com/
        0
    2. je n'arrive pas à valider le commentaire avec le fichier.
      en plus mon pc n'arrête pas de redémarrer.
      0
      1. Contributeur sécurité
        ok

        essaies ceci

        Desactive ton antivirus le temps de la manip ainsi que ton parefeu si présent(car il est detecté a tort comme infection)

        Télécharge et installe List&Kill'em et enregistre le sur ton bureau

        http://sd-1.archive-host.com/...

        double clique ( clic droit "executer en tant qu'administrateur" pour Vista/7 ) sur le raccourci sur ton bureau pour lancer l'installation

        coche la case "creer une icone sur le bureau"

        une fois terminée , clic sur "terminer" et le programme se lancer seul

        choisis la langue puis choisis l'option SEARCH

        laisse travailler l'outil

        à l'apparition de la fenetre blanche , c'est un peu long , c'est normal , le programme n'est pas bloqué.

        un rapport du nom de catchme apparait sur ton bureau , ignore-le,ne le poste pas , mais ne le supprime pas pour l instant, le scan n'est pas fini.

        Poste le contenu du rapport qui s'ouvre aux 100 % du scan à l'ecran "COMPLETED"

        tu peux supprimer le rapport catchme.log de ton bureau maintenant.

        0
        1. je viens de rallumer mon ordi, et le virus ne s'affiche plus.
          je n'ai pas encore essayer le dernier condeil que tu m'as donné.

          il est passé où? je dois continuer à m'inquiéter?
          0
          1. Contributeur sécurité
            continues...
            0
          2. ok ...
            0
          3. ;)
            0
        2. List'em by g3n-h@ckm@n 1.7.2.4

          User : anne-laure (Administrateurs)
          Update on 28/04/2010 by g3n-h@ckm@n ::::: 10.45
          Start at: 13:37:21 | 28/04/2010

          Intel(R) Core(TM)2 Duo CPU P8600 @ 2.40GHz
          Microsoft® Windows Vista(TM) Édition Familiale Premium (6.0.6001 32-bit) # Service Pack 1
          Internet Explorer 8.0.6001.18904
          Windows Firewall Status : Enabled

          C:\ -> Disque fixe local | 222,29 Go (136,07 Go free) [OS] | NTFS
          D:\ -> Disque fixe local | 232,88 Go (232,79 Go free) [DATA] | NTFS
          E:\ -> Disque fixe local | 10,59 Go (1,79 Go free) [RECOVERY] | NTFS
          F:\ -> Disque CD-ROM

          Boot: Normal

          ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running

          C:\Windows\System32\smss.exe
          C:\Windows\system32\csrss.exe
          C:\Windows\system32\wininit.exe
          C:\Windows\system32\csrss.exe
          C:\Windows\system32\services.exe
          C:\Windows\system32\lsass.exe
          C:\Windows\system32\lsm.exe
          C:\Windows\system32\winlogon.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\System32\svchost.exe
          C:\Windows\system32\Ati2evxx.exe
          C:\Windows\System32\svchost.exe
          C:\Windows\System32\svchost.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_52c73ccb\STacSV.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\system32\SLsvc.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\system32\Hpservice.exe
          C:\Windows\system32\Ati2evxx.exe
          C:\Windows\system32\vfsFPService.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\System32\spoolsv.exe
          C:\Program Files\DigitalPersona\Bin\DpHostW.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_52c73ccb\aestsrv.exe
          C:\Program Files\Common Files\LightScribe\LSSrvc.exe
          C:\Windows\system32\svchost.exe
          C:\Program Files\SMINST\BLService.exe
          C:\Windows\system32\svchost.exe
          C:\Program Files\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe
          C:\Program Files\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe
          C:\Windows\System32\svchost.exe
          C:\Windows\system32\SearchIndexer.exe
          C:\Windows\system32\taskeng.exe
          C:\Windows\system32\Dwm.exe
          C:\Windows\Explorer.EXE
          C:\Windows\system32\taskeng.exe
          C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
          C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
          C:\Program Files\IDT\WDM\sttray.exe
          C:\Program Files\Hewlett-Packard\Media\DVD\DVDAgent.exe
          C:\Program Files\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe
          C:\Program Files\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe
          C:\Program Files\Hewlett-Packard\Media\TV\TVAgent.exe
          C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe
          C:\Program Files\DigitalPersona\Bin\DpAgent.exe
          C:\Program Files\Windows Defender\MSASCui.exe
          C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
          C:\Program Files\Java\jre6\bin\jusched.exe
          C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
          C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
          C:\Program Files\DivX\DivX Update\DivXUpdate.exe
          C:\Program Files\Windows Sidebar\sidebar.exe
          C:\Windows\ehome\ehtray.exe
          C:\Windows\ehome\ehmsas.exe
          C:\Users\anne-laure\AppData\Local\dawtjgc.exe
          C:\Program Files\McAfee Security Scan\1.0.150\SSScheduler.exe
          C:\Users\anne-laure\AppData\Roaming\Microsoft\Notification de cadeaux MSN\lsnfier.exe
          C:\Program Files\OpenOffice.org 3\program\soffice.exe
          C:\Program Files\OpenOffice.org 3\program\soffice.bin
          C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
          C:\Windows\system32\wbem\wmiprvse.exe
          C:\Program Files\Windows Sidebar\sidebar.exe
          C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
          C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
          C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
          C:\Program Files\Hewlett-Packard\Shared\hpqToaster.exe
          C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
          C:\Program Files\Internet Explorer\iexplore.exe
          C:\Program Files\Internet Explorer\iexplore.exe
          C:\Windows\system32\wuauclt.exe
          C:\Windows\system32\conime.exe
          C:\Program Files\List_Kill'em\List_Kill'em.exe
          C:\Windows\system32\DllHost.exe
          C:\Windows\system32\cmd.exe
          C:\Windows\system32\SearchProtocolHost.exe
          C:\Windows\system32\SearchFilterHost.exe
          C:\Windows\system32\wbem\wmiprvse.exe
          C:\Program Files\List_Kill'em\pv.exe

          ======================
          Keys "Run"
          ======================

          [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
          Sidebar REG_SZ C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
          ehTray.exe REG_SZ C:\Windows\ehome\ehTray.exe
          dawtjgc REG_SZ "c:\users\anne-laure\appdata\local\dawtjgc.exe" dawtjgc

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
          StartCCC REG_SZ "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
          SynTPEnh REG_SZ C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
          SysTrayApp REG_EXPAND_SZ %ProgramFiles%\IDT\WDM\sttray.exe
          DVDAgent REG_SZ "C:\Program Files\Hewlett-Packard\Media\DVD\DVDAgent.exe"
          TSMAgent REG_SZ "C:\Program Files\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe"
          CLMLServer for HP TouchSmart REG_SZ "C:\Program Files\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe"
          TVAgent REG_SZ "C:\Program Files\Hewlett-Packard\Media\TV\TVAgent.exe"
          UCam_Menu REG_SZ "C:\Program Files\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\Hewlett-Packard\Media\Webcam" update "Software\Hewlett-Packard\Media\Webcam"
          SmartMenu REG_EXPAND_SZ %ProgramFiles%\Hewlett-Packard\HP MediaSmart\SmartMenu.exe
          DpAgent REG_SZ C:\Program Files\DigitalPersona\Bin\dpagent.exe
          Windows Defender REG_EXPAND_SZ %ProgramFiles%\Windows Defender\MSASCui.exe -hide
          QlbCtrl.exe REG_SZ C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
          Adobe Reader Speed Launcher REG_SZ "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
          SunJavaUpdateSched REG_SZ "C:\Program Files\Java\jre6\bin\jusched.exe"
          HP Health Check Scheduler REG_SZ c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
          HP Software Update REG_SZ C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
          WirelessAssistant REG_SZ C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
          DivXUpdate REG_SZ "C:\Program Files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW

          [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]

          [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]

          =====================
          Other Keys
          =====================

          [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
          ConsentPromptBehaviorAdmin REG_DWORD 2 (0x2)
          ConsentPromptBehaviorUser REG_DWORD 1 (0x1)
          EnableInstallerDetection REG_DWORD 1 (0x1)
          EnableLUA REG_DWORD 0 (0x0)
          EnableSecureUIAPaths REG_DWORD 1 (0x1)
          EnableVirtualization REG_DWORD 1 (0x1)
          PromptOnSecureDesktop REG_DWORD 1 (0x1)
          ValidateAdminCodeSignatures REG_DWORD 0 (0x0)
          dontdisplaylastusername REG_DWORD 0 (0x0)
          legalnoticecaption REG_SZ
          legalnoticetext REG_SZ
          scforceoption REG_DWORD 0 (0x0)
          shutdownwithoutlogon REG_DWORD 1 (0x1)
          undockwithoutlogon REG_DWORD 1 (0x1)
          FilterAdministratorToken REG_DWORD 0 (0x0)
          EnableUIADesktopToggle REG_DWORD 0 (0x0)

          ===============

          [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]

          ===============

          [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]

          ===============

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
          AppInit_DLLS REG_SZ

          ===============

          [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
          ReportBootOk REG_SZ 1
          Shell REG_SZ explorer.exe
          Userinit REG_SZ C:\Windows\system32\userinit.exe,
          VmApplet REG_SZ rundll32 shell32,Control_RunDLL "sysdm.cpl"
          AutoRestartShell REG_DWORD 1 (0x1)
          LegalNoticeCaption REG_SZ
          LegalNoticeText REG_SZ
          PowerdownAfterShutdown REG_SZ 0
          ShutdownWithoutLogon REG_SZ 0
          cachedlogonscount REG_SZ 10
          forceunlocklogon REG_DWORD 0 (0x0)
          passwordexpirywarning REG_DWORD 14 (0xe)
          Background REG_SZ 0 0 0
          DebugServerCommand REG_SZ no
          WinStationsDisabled REG_SZ 0
          DisableCAD REG_DWORD 1 (0x1)
          scremoveoption REG_SZ 0
          ShutdownFlags REG_DWORD 43 (0x2b)

          ===============

          ===============

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]

          ===============

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

          ===============
          ActivX controls
          ===============

          [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{20A60F0D-9AFA-4515-A0FD-83BD84642501}]
          [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{5D6F45B3-9043-443D-A792-115447494D24}]
          [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{8AD9C840-044E-11D1-B3E9-00805F499D93}]
          [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{C3F79A2B-B9B4-4A66-B012-3EE46475B072}]
          [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}]
          [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}]
          [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}]
          [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}]
          [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{F5A7706B-B9C0-4C89-A715-7A0C6B05DD48}]

          ===============
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{26923b43-4d38-484f-9b9e-de460746276c}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{08B0E5C0-4FCB-11CF-AAA5-00401C608500}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{166B1BCA-3F9C-11CF-8075-444553540000}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2179C5D3-EBFF-11CF-B6FD-00AA00B4E220}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2A202491-F00D-11cf-87CC-0020AFEECF20}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{3af36230-a269-11d1-b5bf-0000f8051515}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA848-CC51-11CF-AAFA-00AA00B6015C}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA855-CC51-11CF-AAFA-00AA00B6015F}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{45ea75a0-a269-11d1-b5bf-0000f8051515}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4f645220-306d-11d2-995d-00c04f98bbc9}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5fd399c0-a70a-11d1-9948-00c04f98bbc9}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{630b1da0-b465-11d1-9948-00c04f98bbc9}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6fab99d0-bab8-11d1-994a-00c04f98bbc9}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7C028AF8-F614-47B3-82DA-BA94E41B1089}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4340}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4383}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9381D8F2-0288-11D0-9501-00AA00B911A5}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C6BAF60B-6E91-453F-BFF9-D3789CFEFCDD}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C9E9A340-D1F1-11D0-821E-444553540600}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CDD7975E-60F8-41d5-8149-19E51D6F71D0}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{D27CDB6E-AE6D-11CF-96B8-444553540000}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{de5aed00-a4bf-11d1-9948-00c04f98bbc9}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{E92B03AB-B707-11d2-9CBD-0000F87A369E}]
          0
          1. suite:

            ==============
            BHO :
            ======

            [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
            [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]
            [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
            [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]

            ===
            DNS
            ===

            HKLM\SYSTEM\CCS\Services\Tcpip\..\{03599396-2158-40DF-8E0E-698D675E3EBD}: DhcpNameServer=212.27.40.240 212.27.40.241
            HKLM\SYSTEM\CCS\Services\Tcpip\..\{49CF6C8C-4349-4B48-9D73-9DACFED0A61D}: DhcpNameServer=212.27.40.240 212.27.40.241
            HKLM\SYSTEM\CS1\Services\Tcpip\..\{03599396-2158-40DF-8E0E-698D675E3EBD}: DhcpNameServer=212.27.40.240 212.27.40.241
            HKLM\SYSTEM\CS1\Services\Tcpip\..\{49CF6C8C-4349-4B48-9D73-9DACFED0A61D}: DhcpNameServer=212.27.40.240 212.27.40.241
            HKLM\SYSTEM\CS3\Services\Tcpip\..\{03599396-2158-40DF-8E0E-698D675E3EBD}: DhcpNameServer=212.27.40.240 212.27.40.241
            HKLM\SYSTEM\CS3\Services\Tcpip\..\{49CF6C8C-4349-4B48-9D73-9DACFED0A61D}: DhcpNameServer=212.27.40.240 212.27.40.241
            HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=212.27.40.240 212.27.40.241
            HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=212.27.40.240 212.27.40.241
            HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=212.27.40.240 212.27.40.241

            ================
            Internet Explorer :
            ================

            [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
            Start Page REG_SZ https://www.msn.com/fr-fr?cobrand=hp-notebook.msn.com&ocid=HPDHP&pc=HPNTDF
            Local Page REG_SZ C:\Windows\System32\blank.htm
            Default_Search_URL REG_SZ https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            Default_Page_URL REG_SZ https://www.msn.com/fr-fr?cobrand=hp-notebook.msn.com&ocid=HPDHP&pc=HPNTDF
            Search Page REG_SZ https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF

            [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
            Start Page REG_SZ https://www.google.fr/?gws_rd=ssl
            Local Page REG_SZ C:\Windows\system32\blank.htm
            Search Page REG_SZ https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF

            ========
            Services
            ========

            [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services]

            Ndisuio : 0x3 ( OK = 3 )
            EapHost : 0x3 ( OK = 2 )
            Wlansvc : 0x2 ( OK = 2 )
            SharedAccess : 0x4 ( OK = 2 )
            windefend : 0x2 ( OK = 2 )
            wuauserv : 0x2 ( OK = 2 )
            wscsvc : 0x2 ( OK = 2 )

            ========
            Safemode
            ========

            HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot : OK !!
            HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal : OK !!
            HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network : OK !!

            =========
            Atapi.sys
            =========

            C:\Windows\SoftwareDistribution\Download\cde11068f5b77b180111333ef9781925\x86_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_df23a1261eab99e8\atapi.sys :
            MD5 :: [1f05b78ab91c9075565a9d8a4b880bc4]
            SHA256 :: [737be9f9376dab0ccdfed93ea6d67f0c432367ea63cd772a453485be769af3bd]

            C:\Windows\System32\drivers\atapi.sys :
            MD5 :: [9c0e70031905adbf94edb9ea14af943b]
            SHA256 :: [88e4a250c22e919decedf1d59566265c473cdfac97440f25a6d05e6200223194]

            C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_7f3e4ed9\atapi.sys :
            MD5 :: [9c0e70031905adbf94edb9ea14af943b]
            SHA256 :: [88e4a250c22e919decedf1d59566265c473cdfac97440f25a6d05e6200223194]

            C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_b7393fc6\atapi.sys :
            MD5 :: [e26ddfe464b464daf1c739122978d1d6]
            SHA256 :: [e21bf50a64beb5eafdc1d6ba1aa559a75fd31ffb4a85ceb074884c58903c9b68]

            C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys :
            MD5 :: [4f4fcb8b6ea06784fb6d475b7ec7300f]
            SHA256 :: [6202d85c9a75e3f01f5f94f069c4cd8a2b9295a182301eae5940ec3bc2c1d896]

            C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_cc18792d\atapi.sys :
            MD5 :: [2d9c903dc76a66813d350a562de40ed9]
            SHA256 :: [82609f01a08c6842e4c17c077bb641c1429c0e6657964b7f2d114035e1bdcbf3]

            C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.20847_none_dbb74a7b3d9afbc1\atapi.sys :
            MD5 :: [e26ddfe464b464daf1c739122978d1d6]
            SHA256 :: [e21bf50a64beb5eafdc1d6ba1aa559a75fd31ffb4a85ceb074884c58903c9b68]

            C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a2189ce9c\atapi.sys :
            MD5 :: [2d9c903dc76a66813d350a562de40ed9]
            SHA256 :: [82609f01a08c6842e4c17c077bb641c1429c0e6657964b7f2d114035e1bdcbf3]

            C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.22193_none_dd6376773aedb5e4\atapi.sys :
            MD5 :: [9c0e70031905adbf94edb9ea14af943b]
            SHA256 :: [88e4a250c22e919decedf1d59566265c473cdfac97440f25a6d05e6200223194]

            Référence :
            ==========

            Win 2000_SP2 : ff953a8f08ca3f822127654375786bbe
            Win 2000_SP4 : 8c718aa8c77041b3285d55a0ce980867
            Win XP_32b : a64013e98426e1877cb653685c5c0009
            Win XP_SP2_32b : CDFE4411A69C224BD1D11B2DA92DAC51
            Win XP_SP3_32b : 9F3A2F5AA6875C72BF062C712CFA2674
            Vista_32b : e03e8c99d15d0381e02743c36afc7c6f
            Vista_SP1_32b : 2d9c903dc76a66813d350a562de40ed9
            Vista_SP2_32b : 1F05B78AB91C9075565A9D8A4B880BC4
            Vista_SP2_64b : 1898FAE8E07D97F2F6C2D5326C633FAC
            Windows 7_32b : 80C40F7FDFC376E4C5FEEC28B41C119E
            Windows 7_64b : 02062C0B390B7729EDC9E69C680A6F3C
            Windows 7_32b_Ultimate : 338c86357871c167a96ab976519bf59e

            =======
            Drive :
            =======

            D'fragmenteur de disque Windows
            Copyright (c) 2006 Microsoft Corp.

            Rapport d'analyse pour le volume C: OS

            Taille du volume = 222 Go
            Espace libre = 136 Go
            tendue d'espace libre la plus grande = 62.43 Go
            Pourcentage de fragmentation des fichiers = 1 %

            Remarqueÿ: sur les volumes NTFS, les fragments de fichiers de plus de 64ÿMo ne sont pas inclus dans les statistiques de fragmentation.

            Il n'est pas n'cessaire de d'fragmenter ce volume.

            ¤¤¤¤¤¤¤¤¤¤ Files/folders :

            Present !! : C:\ProgramData\{051B9612-4D82-42AC-8C63-CD2DCEDC1CB3}.log
            Present !! : C:\ProgramData\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}.log
            Present !! : C:\ProgramData\{23F3DA62-2D9E-4A69-B8D5-BE8E9E148092}.log
            Present !! : C:\ProgramData\{40BF1E83-20EB-11D8-97C5-0009C5020658}.log
            Present !! : C:\ProgramData\{4FC670EB-5F02-4B07-90DB-022B86BFEFD0}.log
            Present !! : C:\ProgramData\{9867824A-C86D-4A83-8F3C-E7A86BE0AFD3}.log
            Present !! : C:\ProgramData\{C59C179C-668D-49A9-B6EA-0121CCFC1243}.log
            Present !! : C:\ProgramData\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}.log
            Present !! : C:\ProgramData\{d36dd326-7280-11d8-97c8-000129760cbe}.log
            Present !! : C:\ProgramData\HPWALog.txt
            Present !! : C:\ProgramData\{051B9612-4D82-42AC-8C63-CD2DCEDC1CB3}.log
            Present !! : C:\ProgramData\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}.log
            Present !! : C:\ProgramData\{23F3DA62-2D9E-4A69-B8D5-BE8E9E148092}.log
            Present !! : C:\ProgramData\{40BF1E83-20EB-11D8-97C5-0009C5020658}.log
            Present !! : C:\ProgramData\{4FC670EB-5F02-4B07-90DB-022B86BFEFD0}.log
            Present !! : C:\ProgramData\{9867824A-C86D-4A83-8F3C-E7A86BE0AFD3}.log
            Present !! : C:\ProgramData\{C59C179C-668D-49A9-B6EA-0121CCFC1243}.log
            Present !! : C:\ProgramData\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}.log
            Present !! : C:\ProgramData\{d36dd326-7280-11d8-97c8-000129760cbe}.log
            Present !! : C:\ProgramData\HPWALog.txt
            Present !! : C:\ProgramData\{051B9612-4D82-42AC-8C63-CD2DCEDC1CB3}.log
            Present !! : C:\ProgramData\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}.log
            Present !! : C:\ProgramData\{23F3DA62-2D9E-4A69-B8D5-BE8E9E148092}.log
            Present !! : C:\ProgramData\{40BF1E83-20EB-11D8-97C5-0009C5020658}.log
            Present !! : C:\ProgramData\{4FC670EB-5F02-4B07-90DB-022B86BFEFD0}.log
            Present !! : C:\ProgramData\{9867824A-C86D-4A83-8F3C-E7A86BE0AFD3}.log
            Present !! : C:\ProgramData\{C59C179C-668D-49A9-B6EA-0121CCFC1243}.log
            Present !! : C:\ProgramData\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}.log
            Present !! : C:\ProgramData\{d36dd326-7280-11d8-97c8-000129760cbe}.log
            Present !! : C:\ProgramData\HPWALog.txt
            Present !! : C:\ProgramData\{051B9612-4D82-42AC-8C63-CD2DCEDC1CB3}.log
            Present !! : C:\ProgramData\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}.log
            Present !! : C:\ProgramData\{23F3DA62-2D9E-4A69-B8D5-BE8E9E148092}.log
            Present !! : C:\ProgramData\{40BF1E83-20EB-11D8-97C5-0009C5020658}.log
            Present !! : C:\ProgramData\{4FC670EB-5F02-4B07-90DB-022B86BFEFD0}.log
            Present !! : C:\ProgramData\{9867824A-C86D-4A83-8F3C-E7A86BE0AFD3}.log
            Present !! : C:\ProgramData\{C59C179C-668D-49A9-B6EA-0121CCFC1243}.log
            Present !! : C:\ProgramData\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}.log
            Present !! : C:\ProgramData\{d36dd326-7280-11d8-97c8-000129760cbe}.log
            Present !! : C:\ProgramData\HPWALog.txt
            Present !! : C:\ProgramData\{051B9612-4D82-42AC-8C63-CD2DCEDC1CB3}.log
            Present !! : C:\ProgramData\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}.log
            Present !! : C:\ProgramData\{23F3DA62-2D9E-4A69-B8D5-BE8E9E148092}.log
            Present !! : C:\ProgramData\{40BF1E83-20EB-11D8-97C5-0009C5020658}.log
            Present !! : C:\ProgramData\{4FC670EB-5F02-4B07-90DB-022B86BFEFD0}.log
            Present !! : C:\ProgramData\{9867824A-C86D-4A83-8F3C-E7A86BE0AFD3}.log
            Present !! : C:\ProgramData\{C59C179C-668D-49A9-B6EA-0121CCFC1243}.log
            Present !! : C:\ProgramData\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}.log
            Present !! : C:\ProgramData\{d36dd326-7280-11d8-97c8-000129760cbe}.log
            Present !! : C:\Program Files\Mozilla Firefox\components\nsFFxSHot.xpt
            Present !! : C:\Windows\AutoRun.INI
            Present !! : C:\Windows\System32\drivers\Fdc.sys
            Present !! : C:\Windows\Temp\448a696b42ef94b4cd6a1419.tmp
            Present !! : C:\Windows\Temp\464eb186f01b7fb11903569e.tmp
            Present !! : C:\Windows\Temp\481d0ace591293261368a5f.tmp
            Present !! : C:\Windows\Temp\52d86e33241832f8d16c5e0.tmp
            Present !! : C:\Windows\Temp\5bfbea72c79e5d3977c10dd4.tmp
            Present !! : C:\Windows\Temp\62fb93b75add1cb4bf475b77.tmp
            Present !! : C:\Windows\Temp\6a160ced185144c14e459a4e.tmp
            Present !! : C:\Windows\Temp\832c0f50d76266a1f38f0263.tmp
            Present !! : C:\Windows\Temp\8a65133313642a9cb333bcb2.tmp
            Present !! : C:\Windows\Temp\d2dcbdddb8ee85f872b0ed18.tmp
            Present !! : C:\Windows\Temp\de22a1e7cc7b84a1c5821574.tmp
            Present !! : C:\Windows\Temp\DMI3BA8.tmp
            Present !! : C:\Windows\Temp\DMI4D25.tmp
            Present !! : C:\Windows\Temp\DMI4E0F.tmp
            Present !! : C:\Windows\Temp\DMIFB.tmp
            Present !! : C:\Windows\Temp\e79929f4c35977ff687a326f.tmp
            Present !! : C:\Windows\Temp\hnobnvtmjyd.tmp
            Present !! : C:\Windows\Temp\jmojfigevf.tmp
            Present !! : C:\Users\anne-laure\AppData\Local\qtdgcmxb.bat
            Present !! : C:\Users\anne-laure\AppData\Local\yqkuneib.bat
            Present !! : C:\Users\anne-laure\AppData\Local\d3d9caps.dat
            Present !! : C:\Users\anne-laure\AppData\Local\dawtjgc.dat
            Present !! : C:\Users\anne-laure\AppData\Local\dawtjgc_nav.dat
            Present !! : C:\Users\anne-laure\AppData\Local\dawtjgc_navps.dat
            Present !! : C:\Users\anne-laure\AppData\Local\GDIPFONTCACHEV1.DAT
            Present !! : C:\Users\anne-laure\AppData\Local\dawtjgc_nav.dat
            Present !! : C:\Users\anne-laure\AppData\Local\dawtjgc_navps.dat
            Present !! : C:\Users\anne-laure\AppData\Local\dawtjgc_nav.dat
            Present !! : C:\Users\anne-laure\Local Settings\Temp\db.dat
            Present !! : C:\Users\anne-laure\Local Settings\Temp\w.log
            Present !! : C:\Users\anne-laure\LOCAL Settings\Temp\8BD54F3E-DD19-4a69-93D8-5C6A5BBBE20E.exe
            Present !! : C:\Users\anne-laure\LOCAL Settings\Temp\HPQSi.exe
            Present !! : C:\Users\anne-laure\LOCAL Settings\Temp\igraal.exe
            Present !! : C:\Users\anne-laure\LOCAL Settings\Temp\jre-6u15-windows-i586-iftw_17a8e122.exe
            Present !! : C:\Users\anne-laure\LOCAL Settings\Temp\Visionneuse-PowerPoint-2007.exe
            Present !! : C:\Users\anne-laure\LOCAL Settings\Temp\db.dat
            Present !! : C:\Users\anne-laure\LOCAL Settings\Temp\liveplayer_exe.dat
            Present !! : C:\Users\anne-laure\LOCAL Settings\Temp\liveplayer_skin.dat
            Present !! : C:\Users\anne-laure\LOCAL Settings\Temp\skin_dll.dat
            Present !! : C:\Users\anne-laure\LOCAL Settings\Temp\sqlite_dll.dat
            Present !! : C:\Users\anne-laure\Local Settings\Temp\jisfije9fjoiee.tmp

            ¤¤¤¤¤¤¤¤¤¤ Keys :

            Present !! : HKCU\SOFTWARE\fcn
            Present !! : HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb}

            ============

            catchme 0.3.1398.3 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
            Rootkit scan 2010-04-28 13:45:03
            Windows 6.0.6001 Service Pack 1 FAT NTAPI

            scanning hidden processes ...

            scanning hidden services ...

            scanning hidden autostart entries ...

            scanning hidden files ...

            scan completed successfully
            hidden processes: 0
            hidden services: 0
            hidden files: 0

            Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

            device: opened successfully
            user: MBR read successfully
            called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys hpdskflt.sys hal.dll acpi.sys ataport.SYS PCIIDEX.SYS msahci.sys
            kernel: MBR read successfully
            user & kernel MBR OK

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
            cval REG_DWORD 1 (0x1)

            ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

            End of scan : 13:45:04,24
            0
            1. Logfile of The Avenger Version 2.0, (c) by Swandog46
              http://swandog46.geekstogo.com

              Platform: Windows Vista

              *******************

              Script file opened successfully.
              Script file read successfully.

              Backups directory opened successfully at C:\Avenger

              *******************

              Beginning to process script file:

              Rootkit scan active.
              No rootkits found!

              File move operation "c:\truc.bak|c:\windows\system32\drivers\atapi.sys" completed successfully.

              Completed script processing.

              *******************

              Finished! Terminate.
              0
              1. Contributeur sécurité
                ok

                plusieurs choses maintenant, postes les rapports au fur et à mesure

                finir killem et repasser derriere lui

                1)

                Relance List_Kill'em(soit en clic droit pour vista/7),avec le raccourci sur ton bureau.
                mais cette fois-ci :

                choisis l'option CLEAN
                ton PC va redemarrer,

                laisse travailler l'outil.

                en fin de scan la fenetre se ferme , et tu as un rapport du nom de Kill'em.txt sur ton bureau ,

                colle le contenu dans ta reponse

                Tu peux le désinstaller ensuite

                ....................................

                2)

                Infection Navipromo....Pour info :

                Il s'installe via certains programmes, dont ceux-ci qu'il faut éviter à tout prix:
                * Funky Emoticons
                * go-astro
                * Games Attack
                * GoRecord
                * HotTVPlayer / HotTVPlayer & Paris Hilton
                * Live-Player
                * MailSkinner
                * Messenger Skinner
                * Instant Access
                * InternetGameBox
                * Officiale Emule (Version d'Emule modifiée)
                * Original Solitaire
                * SuperSexPlayer
                * Speed Downloading
                * Sudoplanet
                * Webmediaplayer

                il faudrait télécharge navilog1 sur le bureau :
                http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe

                Certaines infections bloquent les téléchargements d' outils de désinfection utilisez ce lien alternatif:
                http://ww38.toofiles.com/fr/oip/documents/exe/yop3.html

                /!\ Utilisateur de VISTA: il faudrait désactiver l'UAC juste le temps de désinfection de votre pc, Vous le réactiverez plus tard :

                Tuto : https://www.commentcamarche.net/faq/8343-vista-desactiver-l-uac

                1°Double-clique sur navilog1.exe présent sur ton bureau
                2°Sélectionnez la langue désirée dans le menu puis valide le choix par la touche « entrer »
                3°Petit message d'avertissement, appuyez sur une touche pour passe à la suite
                4°un nouveau avertissement, appuie sur une touche pour suivre
                5°Vérification de l'installation de Navilog1 : si tout est bon, appuyez sur une touche pour continuer
                6°Choisir option 1 : recherche/désinfection automatique
                7°La recherche va se lancer automatiquement et peut durée quelques minutes, patientez
                8°Une fois l'analyse terminé, fermez et enregistrez votre travail en cours, puis appuiez sur une touche pour que votre pc puisse démarrer
                9°Au redémarrage du pc, Navilog va supprimer ce qu'il a trouvé, patientez quelques instants.

                Un rapport est gèneré par l'outil. Il se trouve à cette emplacement :
                XP : demarrer/poste de travail/c:/cleannavi.txt
                Vista : logo « demarrer »/ordinateur/c:/ cleannavi.txt

                .......................

                3)

                Téléchargez USBFIX de El Desaparecido, C_xx

                http://pagesperso-orange.fr/NosTools/Chiquitine29/UsbFix.exe
                ou
                https://www.ionos.fr/?affiliate_id=77097

                /!\ Utilisateur de vista et windows 7 :
                ne pas oublier de désactiver Le contrôle des comptes utilisateurs
                https://www.commentcamarche.net/faq/8343-vista-desactiver-l-uac

                /!\ Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptible d'avoir été infectées sans les ouvrir

                * Double clic sur le raccourci UsbFix présent sur le bureau .

                * Choisir l'option2 suppression
                (d'autres options disponibles, voir le tutoriel).
                * Laissez travailler l'outil.
                Le menu démarrer et les icônes vont disparaître.. c'est normal.

                Si un message te demande de redémarrer l'ordinateur fais le ...

                ? Au redémarrage, le fix se relance... laisses l'opération s'effectuer.

                ? Le bloc note s'ouvre avec un rapport, envoies le dans la prochaine réponse

                * Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque. ( C:\UsbFix.txt )

                ( CTRL+A Pour tout sélectionner , CTRL+C pour copier et CTRL+V pour coller )

                * Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
                Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
                Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.

                * Tuto : http://pagesperso-orange.fr/NosTools/usbfix.html

                UsbFix peut te demander d'uploader un dossier compressé à cette adresse : https://www.ionos.fr/?affiliate_id=77097

                Il est enregistré sur ton bureau.

                Merci de l'envoyer à l'adresse indiquée afin d'aider l'auteur de UsbFix dans ses recherches.

                ................................

                4)

                Télécharge ZHPDiag ( de Nicolas coolman ).
                https://www.zebulon.fr/telechargements/securite/systeme/zhpdiag.html

                (outil de diagnostic)

                Double clique sur le fichier d'installation, puis installe le avec les paramètres par défaut ( N'oublie pas de cocher " Créer une icône sur le bureau " )

                Lance ZHPDiag en double cliquant sur l'icône présente sur ton bureau (Clique droit -> Executer en tant qu'admin pour vista )

                Clique sur la loupe en haut à gauche, puis laisse l'outil scanner.

                Une fois le scan terminé, clique sur l'icône en forme de disquette et enregistre le fichier sur ton bureau.

                Rend toi sur Cjoint : http://www.cijoint.fr/

                Clique sur "Parcourir " dans la partie " Joindre un fichier[...] "

                Sélectionne le rapport ZHPdiag.txt qui se trouve sur ton bureau

                Clique ensuite sur "Cliquez ici pour déposer le fichier " et copie/colle le lien dans ton prochain message

                si soucis avec ci joint. fr => utiliser https://www.cjoint.com/


                Je cherche beaucoup...et maintenant je trouve !
                (sourire)
                0
                1. 1)

                  Kill'em by g3n-h@ckm@n 1.7.2.4

                  User : anne-laure (Administrateurs)
                  Update on 28/04/2010 by g3n-h@ckm@n ::::: 10.45
                  Start at: 15:38:18 | 28/04/2010

                  Intel(R) Core(TM)2 Duo CPU P8600 @ 2.40GHz
                  Microsoft® Windows Vista(TM) Édition Familiale Premium (6.0.6001 32-bit) # Service Pack 1
                  Internet Explorer 8.0.6001.18904
                  Windows Firewall Status : Enabled

                  C:\ -> Disque fixe local | 222,29 Go (136,09 Go free) [OS] | NTFS
                  D:\ -> Disque fixe local | 232,88 Go (232,79 Go free) [DATA] | NTFS
                  E:\ -> Disque fixe local | 10,59 Go (1,79 Go free) [RECOVERY] | NTFS
                  F:\ -> Disque CD-ROM

                  ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running

                  C:\Windows\System32\smss.exe
                  C:\Windows\system32\csrss.exe
                  C:\Windows\system32\wininit.exe
                  C:\Windows\system32\csrss.exe
                  C:\Windows\system32\services.exe
                  C:\Windows\system32\lsass.exe
                  C:\Windows\system32\lsm.exe
                  C:\Windows\system32\winlogon.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\System32\svchost.exe
                  C:\Windows\system32\LogonUI.exe
                  C:\Windows\system32\Ati2evxx.exe
                  C:\Windows\System32\svchost.exe
                  C:\Windows\System32\svchost.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_52c73ccb\STacSV.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\system32\SLsvc.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\system32\Hpservice.exe
                  C:\Windows\system32\vfsFPService.exe
                  C:\Windows\system32\Ati2evxx.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\System32\spoolsv.exe
                  C:\Program Files\DigitalPersona\Bin\DpHostW.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_52c73ccb\aestsrv.exe
                  C:\Program Files\Google\Update\GoogleUpdate.exe
                  C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                  C:\Windows\system32\svchost.exe
                  C:\Program Files\SMINST\BLService.exe
                  C:\Windows\system32\svchost.exe
                  C:\Program Files\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe
                  C:\Program Files\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe
                  C:\Windows\System32\svchost.exe
                  C:\Windows\system32\SearchIndexer.exe
                  C:\Windows\system32\wbem\wmiprvse.exe
                  C:\Windows\system32\taskeng.exe
                  C:\Windows\system32\DllHost.exe
                  C:\Windows\system32\userinit.exe
                  C:\Windows\system32\Dwm.exe
                  C:\Program Files\Google\Update\GoogleUpdate.exe
                  C:\Windows\system32\taskeng.exe
                  C:\Windows\Explorer.EXE
                  C:\Windows\system32\runonce.exe
                  C:\Windows\system32\cmd.exe
                  C:\Windows\system32\conime.exe
                  C:\Program Files\List_Kill'em\ERUNT.EXE
                  C:\Program Files\List_Kill'em\pv.exe

                  ¤¤¤¤¤¤¤¤¤¤ Files/folders :

                  Quarantined & Deleted !! : C:\ProgramData\{051B9612-4D82-42AC-8C63-CD2DCEDC1CB3}.log
                  Quarantined & Deleted !! : C:\ProgramData\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}.log
                  Quarantined & Deleted !! : C:\ProgramData\{23F3DA62-2D9E-4A69-B8D5-BE8E9E148092}.log
                  Quarantined & Deleted !! : C:\ProgramData\{40BF1E83-20EB-11D8-97C5-0009C5020658}.log
                  Quarantined & Deleted !! : C:\ProgramData\{4FC670EB-5F02-4B07-90DB-022B86BFEFD0}.log
                  Quarantined & Deleted !! : C:\ProgramData\{9867824A-C86D-4A83-8F3C-E7A86BE0AFD3}.log
                  Quarantined & Deleted !! : C:\ProgramData\{C59C179C-668D-49A9-B6EA-0121CCFC1243}.log
                  Quarantined & Deleted !! : C:\ProgramData\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}.log
                  Quarantined & Deleted !! : C:\ProgramData\{d36dd326-7280-11d8-97c8-000129760cbe}.log
                  Quarantined & Deleted !! : C:\ProgramData\HPWALog.txt
                  Quarantined & Deleted !! : C:\Program Files\Mozilla Firefox\components\nsFFxSHot.xpt
                  Quarantined & Deleted !! : C:\Windows\AutoRun.INI

                  Quarantined & Deleted !! : C:\Windows\system32\drivers\Fdc.sys
                  Quarantined & Deleted !! : C:\Windows\Temp\448a696b42ef94b4cd6a1419.tmp
                  Quarantined & Deleted !! : C:\Windows\Temp\464eb186f01b7fb11903569e.tmp
                  Quarantined & Deleted !! : C:\Windows\Temp\481d0ace591293261368a5f.tmp
                  Quarantined & Deleted !! : C:\Windows\Temp\52d86e33241832f8d16c5e0.tmp
                  Quarantined & Deleted !! : C:\Windows\Temp\5bfbea72c79e5d3977c10dd4.tmp
                  Quarantined & Deleted !! : C:\Windows\Temp\62fb93b75add1cb4bf475b77.tmp
                  Quarantined & Deleted !! : C:\Windows\Temp\6a160ced185144c14e459a4e.tmp
                  Quarantined & Deleted !! : C:\Windows\Temp\832c0f50d76266a1f38f0263.tmp
                  Quarantined & Deleted !! : C:\Windows\Temp\8a65133313642a9cb333bcb2.tmp
                  Quarantined & Deleted !! : C:\Windows\Temp\d2dcbdddb8ee85f872b0ed18.tmp
                  Quarantined & Deleted !! : C:\Windows\Temp\de22a1e7cc7b84a1c5821574.tmp
                  Quarantined & Deleted !! : C:\Windows\Temp\DMI3BA8.tmp
                  Quarantined & Deleted !! : C:\Windows\Temp\DMI4D25.tmp
                  Quarantined & Deleted !! : C:\Windows\Temp\DMI4E0F.tmp
                  Quarantined & Deleted !! : C:\Windows\Temp\DMIFB.tmp
                  Quarantined & Deleted !! : C:\Windows\Temp\e79929f4c35977ff687a326f.tmp
                  Quarantined & Deleted !! : C:\Windows\Temp\hnobnvtmjyd.tmp
                  Quarantined & Deleted !! : C:\Windows\Temp\jmojfigevf.tmp
                  Quarantined & Deleted !! : C:\Users\anne-laure\AppData\Local\qtdgcmxb.bat
                  Quarantined & Deleted !! : C:\Users\anne-laure\AppData\Local\yqkuneib.bat
                  Quarantined & Deleted !! : C:\Users\anne-laure\AppData\Local\d3d9caps.dat
                  Quarantined & Deleted !! : C:\Users\anne-laure\AppData\Local\dawtjgc.dat
                  Quarantined & Deleted !! : C:\Users\anne-laure\AppData\Local\dawtjgc_nav.dat
                  Quarantined & Deleted !! : C:\Users\anne-laure\AppData\Local\dawtjgc_navps.dat
                  Quarantined & Deleted !! : C:\Users\anne-laure\AppData\Local\GDIPFONTCACHEV1.DAT
                  Quarantined & Deleted !! : C:\Users\anne-laure\Local Settings\Temp\db.dat
                  Quarantined & Deleted !! : C:\Users\anne-laure\Local Settings\Temp\w.log
                  Quarantined & Deleted !! : C:\Users\anne-laure\LOCAL Settings\Temp\8BD54F3E-DD19-4a69-93D8-5C6A5BBBE20E.exe
                  Quarantined & Deleted !! : C:\Users\anne-laure\LOCAL Settings\Temp\HPQSi.exe
                  Quarantined & Deleted !! : C:\Users\anne-laure\LOCAL Settings\Temp\igraal.exe
                  Quarantined & Deleted !! : C:\Users\anne-laure\LOCAL Settings\Temp\jre-6u15-windows-i586-iftw_17a8e122.exe
                  Quarantined & Deleted !! : C:\Users\anne-laure\LOCAL Settings\Temp\Visionneuse-PowerPoint-2007.exe
                  Quarantined & Deleted !! : C:\Users\anne-laure\LOCAL Settings\Temp\liveplayer_exe.dat
                  Quarantined & Deleted !! : C:\Users\anne-laure\LOCAL Settings\Temp\liveplayer_skin.dat
                  Quarantined & Deleted !! : C:\Users\anne-laure\LOCAL Settings\Temp\skin_dll.dat
                  Quarantined & Deleted !! : C:\Users\anne-laure\LOCAL Settings\Temp\sqlite_dll.dat
                  Quarantined & Deleted !! : C:\Users\anne-laure\Local Settings\Temp\jisfije9fjoiee.tmp
                  Deleted !! : C:\$Recycle.bin\S-1-5-21-2948082535-1301169793-1211081312-1000\$I2NQOBE.url
                  Deleted !! : C:\$Recycle.bin\S-1-5-21-2948082535-1301169793-1211081312-1000\$I4I2EMI.url
                  Deleted !! : C:\$Recycle.bin\S-1-5-21-2948082535-1301169793-1211081312-1000\$I70LIL8
                  Deleted !! : C:\$Recycle.bin\S-1-5-21-2948082535-1301169793-1211081312-1000\$I8L5YMX.url
                  Deleted !! : C:\$Recycle.bin\S-1-5-21-2948082535-1301169793-1211081312-1000\$IBLG4GI.lnk
                  Deleted !! : C:\$Recycle.bin\S-1-5-21-2948082535-1301169793-1211081312-1000\$IFNVE0H.lnk
                  Deleted !! : C:\$Recycle.bin\S-1-5-21-2948082535-1301169793-1211081312-1000\$IL98UPF.exe
                  Deleted !! : C:\$Recycle.bin\S-1-5-21-2948082535-1301169793-1211081312-1000\$IN4OKUL.url
                  Deleted !! : C:\$Recycle.bin\S-1-5-21-2948082535-1301169793-1211081312-1000\$IO62FUM.xspf
                  Deleted !! : C:\$Recycle.bin\S-1-5-21-2948082535-1301169793-1211081312-1000\$IX4GIR5.odt
                  Deleted !! : C:\$Recycle.bin\S-1-5-21-2948082535-1301169793-1211081312-1000\$IYG1KGT.lnk
                  Deleted !! : C:\$Recycle.bin\S-1-5-21-2948082535-1301169793-1211081312-1000\$R2NQOBE.url
                  Deleted !! : C:\$Recycle.bin\S-1-5-21-2948082535-1301169793-1211081312-1000\$R4I2EMI.url
                  Deleted !! : C:\$Recycle.bin\S-1-5-21-2948082535-1301169793-1211081312-1000\$R8L5YMX.url
                  Deleted !! : C:\$Recycle.bin\S-1-5-21-2948082535-1301169793-1211081312-1000\$RFNVE0H.lnk
                  Deleted !! : C:\$Recycle.bin\S-1-5-21-2948082535-1301169793-1211081312-1000\$RN4OKUL.url
                  Deleted !! : C:\$Recycle.bin\S-1-5-21-2948082535-1301169793-1211081312-1000\$RO62FUM.xspf
                  Deleted !! : C:\$Recycle.bin\S-1-5-21-2948082535-1301169793-1211081312-1000\$RX4GIR5.odt
                  Deleted !! : C:\$Recycle.bin\S-1-5-21-2948082535-1301169793-1211081312-1000\$RYG1KGT.lnk

                  =======
                  Hosts :
                  =======

                  127.0.0.1 localhost

                  ========
                  Registry
                  ========

                  Deleted : HKCU\SOFTWARE\fcn
                  Deleted : HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb}
                  =================
                  Internet Explorer
                  =================

                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
                  Start Page REG_SZ https://www.msn.com/fr-fr/?ocid=iehp
                  Local Page REG_SZ C:\WINDOWS\system32\blank.htm
                  Default_Search_URL REG_SZ https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  Default_Page_URL REG_SZ https://www.msn.com/fr-fr/?ocid=iehp
                  Search Page REG_SZ https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF

                  [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                  Start Page REG_SZ https://www.google.com/?gws_rd=ssl
                  Local Page REG_SZ C:\WINDOWS\system32\blank.htm
                  Search Page REG_SZ http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch

                  ===============
                  Security Center
                  ===============

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
                  cval REG_DWORD 1 (0x1)
                  FirstRunDisabled REG_DWORD 1 (0x1)
                  AntiVirusDisableNotify REG_DWORD 0 (0x0)
                  FirewallDisableNotify REG_DWORD 0 (0x0)
                  UpdatesDisableNotify REG_DWORD 0 (0x0)
                  AntiVirusOverride REG_DWORD 1 (0x1)
                  FirewallOverride REG_DWORD 1 (0x1)

                  ========
                  Services
                  =========

                  Ndisuio : Start = 3
                  EapHost : Start = 2
                  Wlansvc : Start = 2
                  SharedAccess : Start = 2
                  windefend : Start = 2
                  wuauserv : Start = 2
                  wscsvc : Start = 2

                  ============
                  Disk Cleaned
                  anti-ver blaster : OK
                  Prefetch cleaned
                  ================

                  ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
                  0
                  1. 2)

                    Fix Navipromo version 4.0.8 commencé le 28/04/2010 15:54:37,67

                    !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
                    !!! Postez ce rapport sur le forum pour le faire analyser !!!

                    Outil exécuté depuis C:\navilog1

                    Mise à jour le 09.03.2010 à 18h00 par IL-MAFIOSO

                    Microsoft® Windows Vista(TM) Édition Familiale Premium ( v6.0.6001 ) Service Pack 1
                    X86-based PC ( Multiprocessor Free : Intel(R) Core(TM)2 Duo CPU P8600 @ 2.40GHz )
                    BIOS : Default System BIOS
                    USER : anne-laure ( Administrator )
                    BOOT : Normal boot

                    C:\ (Local Disk) - NTFS - Total:222 Go (Free:135 Go)
                    D:\ (Local Disk) - NTFS - Total:232 Go (Free:232 Go)
                    E:\ (Local Disk) - NTFS - Total:10 Go (Free:1 Go)
                    F:\ (CD or DVD)

                    Recherche executée en mode normal

                    Nettoyage exécuté au redémarrage de l'ordinateur

                    C:\Users\anne-laure\AppData\Local\syejoaa.exe supprimé !
                    C:\Users\anne-laure\AppData\Local\syejoaa.dat supprimé !
                    C:\Users\anne-laure\AppData\Local\syejoaa_navps.dat supprimé !

                    Nettoyage contenu C:\Windows\Temp effectué !
                    Nettoyage contenu C:\Users\ANNE-L~1\AppData\Local\Temp effectué !

                    *** Sauvegarde du Registre vers dossier Safebackup ***

                    sauvegarde du Registre réalisée avec succès !

                    *** Nettoyage Registre ***

                    Nettoyage Registre Ok

                    *** Scan terminé 28/04/2010 15:57:18,68 ***
                    0
                    1. ############################## | UsbFix V6.109 |

                      User : anne-laure (Administrateurs) # PC-ANNE-LAURE
                      Update on 26/04/2010 by El Desaparecido , C_XX & Chimay8
                      Start at: 16:06:09 | 28/04/2010
                      Website : http://pagesperso-orange.fr/NosTools/index.html
                      Contact : FindyKill.Contact@gmail.com

                      Intel(R) Core(TM)2 Duo CPU P8600 @ 2.40GHz
                      Microsoft® Windows Vista(TM) Édition Familiale Premium (6.0.6001 32-bit) # Service Pack 1
                      Internet Explorer 8.0.6001.18904
                      Windows Firewall Status : Enabled

                      C:\ -> Disque fixe local # 222,29 Go (135,38 Go free) [OS] # NTFS
                      D:\ -> Disque fixe local # 232,88 Go (232,79 Go free) [DATA] # NTFS
                      E:\ -> Disque fixe local # 10,59 Go (1,79 Go free) [RECOVERY] # NTFS
                      F:\ -> Disque CD-ROM

                      ################## | Elements infectieux |

                      Supprimé ! C:\$Recycle.Bin\S-1-5-21-2948082535-1301169793-1211081312-1000
                      Supprimé ! C:\$Recycle.Bin\S-1-5-21-2948082535-1301169793-1211081312-500
                      Supprimé ! C:\$Recycle.Bin\S-1-5-21-3541030145-2230641323-1226403519-500
                      D:\autorun.inf -> fichier appelé : "D:\fun.xls.exe" ( Présent ! )
                      Supprimé ! D:\fun.xls.exe
                      Supprimé ! D:\autorun.inf
                      Supprimé ! D:\$Recycle.Bin\S-1-5-21-2948082535-1301169793-1211081312-1000
                      Supprimé ! D:\$Recycle.Bin\S-1-5-21-2948082535-1301169793-1211081312-500
                      Supprimé ! E:\$Recycle.Bin\S-1-5-21-2948082535-1301169793-1211081312-1000
                      Supprimé ! E:\$Recycle.Bin\S-1-5-21-2948082535-1301169793-1211081312-500

                      ################## | Registre |

                      ################## | Mountpoints2 |

                      Supprimé ! HKCU\...\Explorer\MountPoints2\{4c349995-afeb-11de-8e33-00238baf6e52}\Shell\Auto\Command
                      Supprimé ! HKCU\...\Explorer\MountPoints2\{869ad528-96cf-11de-8137-00238baf6e52}\Shell\Auto\Command

                      ################## | Listing des fichiers présent |

                      [28/04/2010 15:48|--a------|4] C:\autoexec.bat
                      [28/04/2010 15:26|--a------|1086] C:\avenger.txt
                      [21/01/2008 04:24|-rahs----|333203] C:\bootmgr
                      [28/04/2010 15:57|--a------|1348] C:\cleannavi.txt
                      [18/09/2006 23:43|--a------|10] C:\config.sys
                      [?|?|?] C:\hiberfil.sys
                      [03/10/2009 10:53|-rahs----|0] C:\IO.SYS
                      [28/04/2010 13:45|--a------|27448] C:\List'em.txt
                      [28/04/2010 13:36|--a------|37024] C:\more.txt
                      [03/10/2009 10:53|-rahs----|0] C:\MSDOS.SYS
                      [?|?|?] C:\pagefile.sys
                      [28/04/2010 16:09|--a------|2263] C:\UsbFix.txt
                      [12/08/2009 12:08|---hs----|13] E:\BLOCK.RIN
                      [03/10/2006 23:02|---hs----|438328] E:\bootmgr
                      [04/11/2008 17:37|---hs----|1199] E:\Desktop.ini
                      [10/09/2002 16:14|---hs----|8134] E:\Folder.htt
                      [28/04/2010 16:05|--ahs----|196] E:\MASTER.LOG
                      [12/09/2008 17:17|---hs----|381873] E:\protect.arabic
                      [15/09/2008 15:57|---hs----|182624] E:\protect.bulgarian
                      [16/09/2002 14:37|---hs----|181898] E:\protect.chinese hong kong
                      [16/09/2002 14:37|---hs----|181916] E:\protect.chinese simplified
                      [16/09/2002 14:37|---hs----|181898] E:\protect.chinese traditional
                      [27/04/2006 16:19|---hs----|181865] E:\protect.czech
                      [03/11/2005 15:21|---hs----|181726] E:\protect.danish
                      [10/09/2002 13:56|---hs----|181605] E:\protect.dutch
                      [10/09/2002 13:50|---hs----|181651] E:\protect.ed
                      [22/11/2004 15:28|---hs----|181648] E:\protect.english
                      [03/11/2005 15:20|---hs----|181673] E:\protect.finnish
                      [03/11/2005 15:19|---hs----|181736] E:\protect.french
                      [03/11/2005 15:18|---hs----|181669] E:\protect.german
                      [23/11/2005 15:56|---hs----|182689] E:\protect.greek
                      [23/01/2006 09:18|---hs----|182605] E:\protect.hebrew
                      [28/08/2007 14:58|---hs----|181696] E:\protect.hungarian
                      [03/11/2005 15:17|---hs----|181554] E:\protect.italian
                      [19/06/2007 15:22|---hs----|182351] E:\protect.japanese
                      [24/11/2005 11:24|---hs----|218295] E:\protect.korean
                      [03/11/2005 15:15|---hs----|181578] E:\protect.norwegian
                      [25/04/2006 14:44|---hs----|181789] E:\protect.polish
                      [03/11/2005 15:13|---hs----|181624] E:\protect.portuguese
                      [27/10/2005 19:24|---hs----|181882] E:\protect.portuguese brazilian
                      [15/09/2008 15:57|---hs----|181735] E:\protect.romanian
                      [28/06/2004 08:52|---hs----|211936] E:\protect.russian
                      [04/07/2007 11:46|---hs----|181954] E:\protect.slovak
                      [03/11/2005 15:11|---hs----|181586] E:\protect.spanish
                      [10/09/2002 14:15|---hs----|181602] E:\protect.swedish
                      [12/08/2003 10:37|---hs----|181783] E:\protect.turkish

                      ################## | Vaccination |

                      # C:\autorun.inf -> Dossier créé par UsbFix (El Desaparecido).
                      # D:\autorun.inf -> Dossier créé par UsbFix (El Desaparecido).
                      # E:\autorun.inf -> Dossier créé par UsbFix (El Desaparecido).

                      ################## | Upload |

                      Veuillez envoyer le fichier : C:\UsbFix_Upload_Me_PC-anne-laure.zip : https://www.ionos.fr/?affiliate_id=77097
                      Merci pour votre contribution .

                      ################## | ! Fin du rapport # UsbFix V6.109 ! |
                      0
                      1. http://www.cijoint.fr/cjlink.php?file=cj201004/cijnKNEWU0.txt
                        0
                        1. Contributeur sécurité
                          tu as tu laissé désactivé ton pare feu et antivirus je pense

                          sinon le rapport ZHO est bien

                          comment va le pc ?
                          0
                          1. oui mon pare feu est désactivé.

                            et le PC me semble bien. MERCI !!!!
                            donc c'est bon, on a fini??
                            0
                        2. Contributeur sécurité
                          selon le rapport l'antivirus aussi vérifies stp

                          sinon on finalise ton affaire

                          télécharges Hijackthis
                          https://www.commentcamarche.net/telecharger/securite/11747-hijackthis/
                          Lancer HijackThis en double-cliquant sur l'icône du logiciel
                          Au menu principal, cliquer sur Do a system Scan only and Save a Logfile
                          Un rapport sera alors généré dans un fichier bloc-notes, il sera situé dans le dossier désinfection initialement créé pour l'installation.
                          Postes le ici
                          0
                          1. Logfile of Trend Micro HijackThis v2.0.2
                            Scan saved at 18:36:26, on 28/04/2010
                            Platform: Windows Vista SP1 (WinNT 6.00.1905)
                            MSIE: Internet Explorer v8.00 (8.00.6001.18904)
                            Boot mode: Normal

                            Running processes:
                            C:\Windows\system32\Dwm.exe
                            C:\Windows\system32\taskeng.exe
                            C:\Windows\system32\conime.exe
                            C:\Windows\explorer.exe
                            C:\Program Files\McAfee Security Scan\1.0.150\SSScheduler.exe
                            C:\Users\anne-laure\AppData\Roaming\Microsoft\Notification de cadeaux MSN\lsnfier.exe
                            C:\Program Files\OpenOffice.org 3\program\soffice.exe
                            C:\Program Files\OpenOffice.org 3\program\soffice.bin
                            C:\Windows\system32\wuauclt.exe
                            C:\Program Files\Internet Explorer\iexplore.exe
                            C:\Program Files\Internet Explorer\iexplore.exe
                            C:\Windows\System32\notepad.exe
                            C:\Windows\system32\SearchFilterHost.exe
                            C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/...
                            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
                            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
                            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
                            R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                            R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer
                            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                            O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
                            O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
                            O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                            O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                            O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
                            O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                            O4 - HKLM\..\Run: [SysTrayApp] %ProgramFiles%\IDT\WDM\sttray.exe
                            O4 - HKLM\..\Run: [DVDAgent] "C:\Program Files\Hewlett-Packard\Media\DVD\DVDAgent.exe"
                            O4 - HKLM\..\Run: [TSMAgent] "C:\Program Files\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe"
                            O4 - HKLM\..\Run: [CLMLServer for HP TouchSmart] "C:\Program Files\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe"
                            O4 - HKLM\..\Run: [TVAgent] "C:\Program Files\Hewlett-Packard\Media\TV\TVAgent.exe"
                            O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\Hewlett-Packard\Media\Webcam" update "Software\Hewlett-Packard\Media\Webcam"
                            O4 - HKLM\..\Run: [SmartMenu] %ProgramFiles%\Hewlett-Packard\HP MediaSmart\SmartMenu.exe
                            O4 - HKLM\..\Run: [DpAgent] C:\Program Files\DigitalPersona\Bin\dpagent.exe
                            O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                            O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
                            O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
                            O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                            O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
                            O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
                            O4 - HKLM\..\Run: [WirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
                            O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
                            O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                            O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                            O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                            O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                            O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                            O4 - Startup: Notification de cadeaux MSN.lnk = C:\Users\anne-laure\AppData\Roaming\Microsoft\Notification de cadeaux MSN\lsnfier.exe
                            O4 - Startup: OpenOffice.org 3.1.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
                            O4 - Global Startup: McAfee Security Scan.lnk = ?
                            O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
                            O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                            O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                            O13 - Gopher Prefix:
                            O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
                            O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_52c73ccb\aestsrv.exe
                            O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
                            O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
                            O23 - Service: @C:\Program Files\DigitalPersona\Bin\DpHostW.exe,-128 (DpHost) - DigitalPersona, Inc. - C:\Program Files\DigitalPersona\Bin\DpHostW.exe
                            O23 - Service: Service Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
                            O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
                            O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
                            O23 - Service: HP Service (hpsrv) - Hewlett-Packard Corporation - C:\Windows\system32\Hpservice.exe
                            O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                            O23 - Service: Norton Internet Security - Unknown owner - C:\Program Files\Norton Internet Security\Engine\16.0.0.125\ccSvcHst.exe (file missing)
                            O23 - Service: Recovery Service for Windows - Unknown owner - C:\Program Files\SMINST\BLService.exe
                            O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_52c73ccb\STacSV.exe
                            O23 - Service: TV Background Capture Service (TVBCS) (TVCapSvc) - Unknown owner - C:\Program Files\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe
                            O23 - Service: TV Task Scheduler (TVTS) (TVSched) - Unknown owner - C:\Program Files\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe
                            O23 - Service: Validity Fingerprint Service (vfsFPService) - Validity Sensors, Inc. - C:\Windows\system32\vfsFPService.exe
                            0
                        3. quant à l'antivirus, je ne le trouve pas, donc je finis par croire que je n'en ai pas.
                          je m'occupe de ça ce soir..
                          0
                          1. Contributeur sécurité
                            effectivement

                            télécharges antivir
                            et règles le en mode expert
                            cocher recherche de rootkit au demarrage

                            http://www.commentcamarche.net/telecharger/telecharger-55-antivir
                            0
                            1. je n'ai pas trouvé la case recherche de rootkit au démarrage
                              0
                            2. Contributeur sécurité
                              https://www.commentcamarche.net/faq/16831-tutoriel-configuration-optimale-d-antivir-personal
                              0
                            3. ok merci,
                              c'est fait
                              0
                          2. Contributeur sécurité
                            1)
                            Relances hijackthis
                            Au menu principal, choisir do a scan only, puis cocher la case devant les lignes suivantes à corriger et cliquer en bas sur Fix Checked (s'il manque des lignes...pas grave)

                            O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
                            O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
                            O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                            O4 - Startup: OpenOffice.org 3.1.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
                            O4 - Global Startup: McAfee Security Scan.lnk = ?
                            O13 - Gopher Prefix:

                            ..........................

                            2)
                            Mettre à jour VISTA

                            http://www.windowsupdate.com/windowsupdate/v6/default.aspx

                            .........................

                            3)

                            Vérifier la Console Java ? :
                            https://www.java.com/fr/download/uninstalltool.jsp

                            et installer la nouvelle version si besoin est (dans ce cas désinstalle avant l'ancienne version).

                            voici pour desinstaller :

                            JavaRa
                            http://raproducts.org/click/click.php?id=1

                            Décompresse le fichier sur le Bureau (Clic droit > Extraire tout).
                            * Double-clique (clic droit "en tant qu'administrateur" pour Vista) sur le répertoire JavaRa.
                            * Puis double-clique sur le fichier JavaRa.exe (le exe peut ne pas s'afficher).
                            * Choisis Français puis clique sur Select.
                            * Clique sur Recherche de mises à jour.
                            * Sélectionne Mettre à jour via jucheck.exe puis clique sur Rechercher.
                            * Autorise le processus à se connecter s'il le demande, clique sur Installer et suis les instructions d'installation qui prennent quelques minutes.
                            * L'installation est terminée, reviens à l'écran de JavaRa et clique sur Effacer les anciennes versions.
                            * Clique sur Oui pour confirmer. Laisse travailler et clique ensuite sur OK, puis une deuxième fois sur OK.
                            * Un rapport va s'ouvrir. Poste-le dans ta prochaine réponse.
                            * Ferme l'application.

                            Note : le rapport se trouve aussi dans C:\ sous le nom JavaRa.log.

                            .............

                            4)

                            Supprimer ce qu'il reste de Mc Afee et de Norton

                            https://www.commentcamarche.net/faq/7367-desinstaller-proprement-liens-et-astuces#mcafee-virusscan-8-ou-9

                            https://www.commentcamarche.net/faq/2453-supprimer-desinstaller-norton-antivirus-norton-internet-security

                            ....................................

                            5)

                            * Lancez Adobe Reader
                            * Cliquez sur Edition --> Préférences --> JavaScript
                            * Décochez "Activer Acrobat JavaScript"
                            * Validez

                            ....................

                            6)
                            IMPORTANT

                            Purger la restauration systeme vista
                            https://www.commentcamarche.net/faq/13214-vista-desactiver-reactiver-la-restauration-systeme-de-vista

                            .................

                            7)
                            Clique droit sur l'icône ZHPFix.exe sur ton Bureau,
                            puis sélectionne 'Exécuter en tant qu'administrateur'.

                            Clique sur le A rouge (Nettoyeur de Tools).

                            Clique sur Nettoyer.

                            Fais redémarrer l'ordi pour terminer le nettoyage.

                            ..............................................

                            Recommandations pour l'avenir

                            Tu es la meilleure protection pour ton pc que tout autre antivirus, si tu admets un minimum de rigueur dans son utilisation...Les virus sont vigilants et pénètrent ta machine par toutes les portes que tu laisseras ouvertes...
                            - logiciels non à jour (windows, internet explorer, java, adobe reader etc)
                            - installation de toolbar
                            - fréquentation de sites piégés
                            - P2P
                            - Application de cracks
                            - Supports usb

                            Pour t'aider dans cette tâche, voici quelques pistes

                            Pour naviguer sur internet plus en sécurité et à l'abri des publicités, je te conseille vivement d'installer et d'utiliser le navigateur firefox
                            http://www.mozilla-europe.org/fr/firefox/

                            Une fois que c'est fait, lances le et installe l'extension de sécurité adblock plus
                            pour bloquer les publicités
                            https://addons.mozilla.org/fr/mobile/addon/1865

                            ............................

                            WOT - Extension pour ton navigateur internet :
                            Voici une extension à télécharger qui te permettra, en faisant tes recherches sur google, de savoir si le site proposé lors de tes recherches est un site de confiance ou un site à éviter car il pourrait infecter ton PC :
                            Pour Firefox : https://addons.mozilla.org/fr/firefox/addon/wot-safe-browsing-tool/
                            Pour internet explorer : https://chrome.google.com/webstore/detail/wot-web-of-trust-website/bhmmomiinigofkjcapegjjndpbikblnp

                            ........................

                            Tu dois aussi mettre à jour tous tes autres programmes pour combler des failles de sécurité... Vérifie les mises disponibles à l'aide de ce petit programme (choisis la version sans installation) : Update Checker
                            https://www.commentcamarche.net/telecharger/utilitaires/9771-filehippo-app-manager/
                            Et particulièrement Internet explorer, même s'il n'est pas ton navigateur, car les MAJ sécurité Windows ne s'opèrent que par ce chemin là

                            ......................................

                            Pour éviter une infection toolbar, il faut tout lire attentivement lorsque tu installes un programme gratuit, et décocher tous les programmes additionnels qui sont proposés, en particulier les barres d'outils !

                            ..........................

                            Vaccines tes disques amovibles à l'aide de USBFix (de Chiquitine29 et C_XX)
                            http://pagesperso-orange.fr/NosTools/Chiquitine29/UsbFix.exe
                            Au menu principal, choisis l'option 3 (Vaccination).
                            ............................
                            garder Malwarebytes et faire un examen de temps en temps ton PC, avec mise à jour avant chaque scan
                            .......................

                            Télécharge et installe CCleaner (N'installe pas la Yahoo Toolbar) :
                            https://www.commentcamarche.net/telecharger/utilitaires/5647-ccleaner/

                            * Lance-le.(clic droit "en tant qu'administrateur" pour Vista) Va dans Options puis Avancé et décoche la case Effacer uniquement les fichiers etc....
                            * Va dans Nettoyeur, choisis Analyse. Une fois terminé, lance le nettoyage.
                            * Ensuite, choisis Registre, puis Chercher des erreurs. Une fois terminé, répare toutes les erreurs tant de fois qu il en trouve a l analyse

                            ..........................
                            utilitaire pour défragmenter , utilises pour ce faire Defraggler https://www.clubic.com/telecharger-fiche44314-defraggler.html

                            ........................
                            A lire pour mieux comprendre l'environnement qui t'entoure
                            http://assiste.com.free.fr/p/abc/a/zombies_et_botnets.html
                            https://www.malekal.com/fichiers/projetantimalwares/ProjetAntiMalware-courte.pdf

                            http://www.libellules.ch/...

                            0
                            1. wahou ça fait du boulot..
                              allé c'est parti!

                              merci
                              0
                          3. java: rapport

                            JavaRa 1.15 Removal Log.

                            Report follows after line.

                            ------------------------------------

                            The JavaRa removal process was started on Wed Apr 28 19:50:45 2010

                            Found and removed: C:\Program Files\Java\jre1.6.0_07

                            Found and removed: C:\Users\anne-laure\AppData\LocalLow\Sun\Java\jre1.6.0_15

                            Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0000-0000-ABCDEFFEDCBA}

                            Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0000-0001-ABCDEFFEDCBA}

                            Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0000-0002-ABCDEFFEDCBA}

                            Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0000-0003-ABCDEFFEDCBA}

                            Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0000-0004-ABCDEFFEDCBA}

                            Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA}

                            Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0001-ABCDEFFEDCBA}

                            Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA}

                            Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0003-ABCDEFFEDCBA}

                            Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA}

                            Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA}

                            Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}

                            Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0007-ABCDEFFEDCBA}

                            Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0008-ABCDEFFEDCBA}

                            Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA}

                            Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA}

                            Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA}

                            Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0012-ABCDEFFEDCBA}

                            Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0013-ABCDEFFEDCBA}

                            Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0014-ABCDEFFEDCBA}

                            Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA}

                            Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}

                            Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}

                            Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}

                            Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA}

                            Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}

                            Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA}

                            Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBB}

                            Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBB}

                            Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBB}

                            Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBB}

                            Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBB}

                            Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBB}

                            Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBB}

                            Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBC}

                            Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBC}

                            Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBC}

                            Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBC}

                            Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBC}

                            Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBC}

                            Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBC}

                            Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0001-0000-ABCDEFFEDCBA}

                            Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0001-0001-ABCDEFFEDCBA}

                            Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA}

                            Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0001-0003-ABCDEFFEDCBA}

                            Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0001-0004-ABCDEFFEDCBA}

                            Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0001-0005-ABCDEFFEDCBA}

                            Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0001-0006-ABCDEFFEDCBA}

                            Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0001-0007-ABCDEFFEDCBA}

                            Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0001-0000-ABCDEFFEDCBB}

                            Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0001-0001-ABCDEFFEDCBB}

                            Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0001-0002-ABCDEFFEDCBB}

                            Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0001-0003-ABCDEFFEDCBB}

                            Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0001-0004-ABCDEFFEDCBB}

                            Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0001-0005-ABCDEFFEDCBB}

                            Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0001-0006-ABCDEFFEDCBB}

                            Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0001-0007-ABCDEFFEDCBB}

                            Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA}

                            Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0001-ABCDEFFEDCBA}

                            Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0002-ABCDEFFEDCBA}

                            Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA}

                            Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0004-ABCDEFFEDCBA}

                            Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0005-ABCDEFFEDCBA}

                            Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0006-ABCDEFFEDCBA}

                            Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0007-ABCDEFFEDCBA}

                            Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0008-ABCDEFFEDCBA}

                            Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0009-ABCDEFFEDCBA}

                            Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0010-ABCDEFFEDCBA}

                            Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0011-ABCDEFFEDCBA}

                            Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0012-ABCDEFFEDCBA}

                            Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0013-ABCDEFFEDCBA}

                            Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0014-ABCDEFFEDCBA}

                            Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0015-ABCDEFFEDCBA}

                            Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0016-ABCDEFFEDCBA}

                            Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0000-ABCDEFFEDCBB}

                            Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0001-ABCDEFFEDCBB}

                            Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0002-ABCDEFFEDCBB}

                            Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBB}

                            Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0004-ABCDEFFEDCBB}

                            Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0005-ABCDEFFEDCBB}

                            Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0006-ABCDEFFEDCBB}

                            Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0007-ABCDEFFEDCBB}

                            Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0008-ABCDEFFEDCBB}

                            Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0009-ABCDEFFEDCBB}

                            Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0010-ABCDEFFEDCBB}

                            Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0011-ABCDEFFEDCBB}

                            Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0012-ABCDEFFEDCBB}

                            Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0013-ABCDEFFEDCBB}

                            Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0014-ABCDEFFEDCBB}

                            Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0015-ABCDEFFEDCBB}

                            Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0016-ABCDEFFEDCBB}

                            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0003-ABCDEFFEDCBA}

                            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0004-ABCDEFFEDCBA}

                            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0005-ABCDEFFEDCBA}

                            Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1

                            Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_02

                            Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_03

                            Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_04

                            Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2

                            Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2.0_01

                            Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0015-ABCDEFFEDCBA}

                            Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0016-ABCDEFFEDCBA}

                            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA}

                            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBA}

                            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBB}

                            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA}

                            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBB}

                            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBA}

                            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBB}

                            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBA}

                            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBB}

                            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBA}

                            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBB}

                            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBA}

                            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBB}

                            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBA}

                            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBB}

                            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBA}

                            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBB}

                            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBA}

                            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBB}

                            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBA}

                            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBB}

                            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBA}

                            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBB}

                            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBA}

                            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBB}

                            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBA}

                            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBB}

                            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBA}

                            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBB}

                            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBA}

                            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBB}

                            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBA}

                            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBB}

                            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBA}

                            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBB}

                            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBA}

                            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBB}

                            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBA}

                            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBB}

                            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBA}

                            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBB}

                            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBA}

                            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBB}

                            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBA}

                            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBB}

                            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBA}

                            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBB}

                            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBA}

                            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBB}

                            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBA}

                            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBB}

                            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBA}

                            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBB}

                            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBA}

                            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBB}

                            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBA}

                            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBB}

                            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBA}

                            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBB}

                            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBA}

                            Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBB}

                            Found and removed: SOFTWARE\JavaSoft\Java Plug-in\1.6.0_07

                            Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.6.0_07

                            Found and removed: SOFTWARE\Microsoft\Active Setup\Installed Components\{08B0E5C0-4FCB-11CF-AAA5-00401C608500}

                            Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ACBB9B2318A96D117A58000B0D610007

                            Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8A0F842331866D117AB7000B0D610007

                            Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3248F0A8-6813-11D6-A77B-00B0D0160070}

                            Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.6.0_07\bin\

                            ------------------------------------

                            Finished reporting.
                            0
                            1. Contributeur sécurité
                              ok

                              cela s'arrête ici pour moi

                              si tout est ok pour toi

                              => résolu

                              bonne continuation

                              (sourire)
                              0
                              1. oui pour le moment tout se passe bien

                                une gros gros merci!!!!!

                                bonne soirée
                                0
                            • 1
                            • 2