Snif, un trojan Win32:Gida

Bonjour,
C'est incroyable j'ai eu pas mal de problemes auparavant et voila rebelotte avec le trojan Win32:Gida, chopé sur Yahoo, en lisant les nouvelles du jour... Je suis désespérée... Effectivement avast m'a informé comme il se doit de la venue de se cheval de Troie, je le vois également dans le journal d'avast mais j'arrive plus a mettre la main dessus; cad j'ai fais scan sur scan avec avast et adware et il ne me signal rien!!! Si quelqu'un peut m'expliquer ce que je peux ou dois faire?
Merci à celui qui pourra me conseiller...
--Pourtant j'ai l'impression de prendre toutes les précautions pour ne pas choper ces "trucs" car j'en avair déjà eu, rrrrr!!
Configuration: Windows XP
Internet Explorer 7.0

25 réponses

  1. Salut

    Clique sur ce lien
    http://www.trendsecure.com/portal/en-US/threat_analytics/HJTInstall.exe
    pour télécharger le fichier d'installation d'HijackThis.

    Enregistre HJTInstall.exe sur ton bureau.
    Double-clique sur HJTInstall.exe pour lancer le programme
    Installe le programmme sur c:\ et lance le
    Choisis l'option "Do a system scan and save a log file"
    Clique sur "Save log" pour enregistrer le rapport qui s'ouvrira avec le bloc-note
    Clique sur "Edition -> Sélectionner tout", puis sur "Edition -> Copier" pour copier tout le contenu du rapport
    Colle le rapport

    A+
    0
    1. MERCI de vouloir m'aider...

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 22:53:36, on 08/02/2008
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.16574)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\Ati2evxx.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\Ati2evxx.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      C:\Program Files\Alwil Software\Avast4\ashServ.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
      C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      C:\Program Files\Java\jre1.5.0\bin\jusched.exe
      C:\Program Files\Orange HSS\Systray\SystrayApp.exe
      C:\WINDOWS\SOUNDMAN.EXE
      C:\Program Files\Winamp\winampa.exe
      C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      C:\Program Files\iTunes\iTunesHelper.exe
      C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
      C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
      C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe
      C:\Program Files\Google\Google Updater\GoogleUpdater.exe
      C:\Program Files\SAGEM WiFi manager\WLANUTL.exe
      C:\Program Files\iPod\bin\iPodService.exe
      C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\wscntfy.exe
      C:\Program Files\Windows Live\Messenger\usnsvc.exe
      C:\Program Files\Internet Explorer\IEXPLORE.EXE
      C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
      C:\Documents and Settings\Mam's\Mes documents\BitComet\BitComet.exe
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://home.sweetim.com/
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\Orange HSS\SearchURLHook\SearchPageURL.dll
      O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
      O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Documents and Settings\Mam's\Mes documents\BitComet\tools\BitCometBHO_1.2.1.2.dll
      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
      O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0\bin\jusched.exe
      O4 - HKLM\..\Run: [SystrayORAHSS] "C:\Program Files\Orange HSS\Systray\SystrayApp.exe"
      O4 - HKLM\..\Run: [ORAHSSSessionManager] C:\Program Files\Orange HSS\SessionManager\SessionManager.exe
      O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
      O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
      O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
      O4 - HKLM\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
      O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
      O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      O4 - HKCU\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
      O4 - HKCU\..\Run: [BitComet] "C:\Documents and Settings\Mam's\Mes documents\BitComet\BitComet.exe" /tray
      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
      O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
      O4 - Global Startup: Utilitaire réseau pour SAGEM Wi-Fi 11g USB adapter.lnk = ?
      O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Documents and Settings\Mam's\Mes documents\BitComet\BitComet.exe/AddLink.htm
      O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Documents and Settings\Mam's\Mes documents\BitComet\BitComet.exe/AddVideo.htm
      O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Documents and Settings\Mam's\Mes documents\BitComet\BitComet.exe/AddAllLink.htm
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
      O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Documents and Settings\Mam's\Mes documents\BitComet\tools\BitCometBHO_1.2.1.2.dll/206 (file missing)
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
      O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
      O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - http://charon777.free.fr/plugins/hardwaredetection_2_0_4_12.cab
      O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
      O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
      O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
      O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
      O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
      O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
      0
      1. C'est une cata, j'arrive pas aller sur certain site ça "bugg"!!!
        Notamment quelque uns que tu m'as donné...
        donc c'est du au parefeu? si je comprends bien. Je vais commencer à etre au "top" a cause/grâce a ts ces problême informatique!!!

        Quand je pourrai y aller je vais suivre tes conseils et prendre Kerio par contre pr l'Antivirus il ne veut pas!!
        0
        1. Re
          Tente ces sites :

          BITDEFENDER
          * Fait un scan antivirus en ligne avec Internet Explorer
          https://www.bitdefender.fr/
          et copie colle le résultat ici
          * En bas, à gauche de la fenêtre, clique sur BitDefender SCAN ONLINE
          * Dans la nouvelle fenêtre, clique sur I agree
          * La fenêtre change encore, clique sur Click here to scan
          * Les signatures se chargent, etc.
          tuto en image
          http://pageperso.aol.fr/rginformatique/mapage/defender.htm

          KASPERSKY
          analyse en ligne sur kaspersky et colle un rapport
          https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr

          A+
          0
          1. Re
            Si tu peux télécharger ça :

            CCleaner
            http://french.icrfast.com/lv/group/view/kl25623/CCleaner.htm
            Lors de son installation décoche la case devant : Ajouter la Barre d'Outils Yahoo! CCleaner
            un tuto pour l'aide
            https://forums.cnetfrance.fr

            A+
            0
            1. J'espere que c'est ce dont tu as besoin...

              Alors celui c'est avec Bitdefenders:

              Info d'analyse

              Fichiers scannés
              107514

              Infectés Fichiers
              0

              Virus Détectés

              Aucun virus trouvé.

              Ca l'air un peu long pr l'autre, je travail demain, donc je vais le laisser travailler cette nuit!

              CCleaner as bien été installé...

              A +
              0
              1. Rien ici non plus... Pourtant il y a bien quelque chose !?!!! Je comprends pas

                KASPERSKY ON-LINE SCANNER REPORT
                Saturday, February 09, 2008 7:25:30 AM
                Système d'exploitation : Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
                Kaspersky On-line Scanner version : 5.0.83.0
                Dernière mise à jour de la base antivirus Kaspersky : 8/02/2008
                Enregistrements dans la base antivirus Kaspersky : 514980

                Paramètres d'analyse
                Analyser avec la base antivirus suivante standard
                Analyser les archives vrai
                Analyser les bases de messagerie vrai

                Cible de l'analyse Zones critiques
                C:\WINDOWS
                C:\DOCUME~1\Mam's\LOCALS~1\Temp\

                Statistiques de l'analyse
                Total d'objets analysés 13882
                Nombre de virus trouvés 0
                Nombre d'objets infectés 0 / 0
                Nombre d'objets suspects 0
                Durée de l'analyse 00:14:47

                Nom de l'objet infecté Nom du virus Dernière action
                C:\WINDOWS\Debug\PASSWD.LOG L'objet est verrouillé ignoré

                C:\WINDOWS\SchedLgU.Txt L'objet est verrouillé ignoré

                C:\WINDOWS\SoftwareDistribution\EventCache\{1998EF9E-CAB5-4441-B18D-CE21A3108CB7}.bin L'objet est verrouillé ignoré

                C:\WINDOWS\SoftwareDistribution\ReportingEvents.log L'objet est verrouillé ignoré

                C:\WINDOWS\Sti_Trace.log L'objet est verrouillé ignoré

                C:\WINDOWS\system32\CatRoot2\edb.log L'objet est verrouillé ignoré

                C:\WINDOWS\system32\CatRoot2\edbtmp.log L'objet est verrouillé ignoré

                C:\WINDOWS\system32\CatRoot2\tmp.edb L'objet est verrouillé ignoré

                C:\WINDOWS\system32\config\ACEEvent.evt L'objet est verrouillé ignoré

                C:\WINDOWS\system32\config\Antivirus.Evt L'objet est verrouillé ignoré

                C:\WINDOWS\system32\config\AppEvent.Evt L'objet est verrouillé ignoré

                C:\WINDOWS\system32\config\default L'objet est verrouillé ignoré

                C:\WINDOWS\system32\config\default.LOG L'objet est verrouillé ignoré

                C:\WINDOWS\system32\config\Internet.evt L'objet est verrouillé ignoré

                C:\WINDOWS\system32\config\SAM L'objet est verrouillé ignoré

                C:\WINDOWS\system32\config\SAM.LOG L'objet est verrouillé ignoré

                C:\WINDOWS\system32\config\SecEvent.Evt L'objet est verrouillé ignoré

                C:\WINDOWS\system32\config\SECURITY L'objet est verrouillé ignoré

                C:\WINDOWS\system32\config\SECURITY.LOG L'objet est verrouillé ignoré

                C:\WINDOWS\system32\config\software L'objet est verrouillé ignoré

                C:\WINDOWS\system32\config\software.LOG L'objet est verrouillé ignoré

                C:\WINDOWS\system32\config\SysEvent.Evt L'objet est verrouillé ignoré

                C:\WINDOWS\system32\config\system L'objet est verrouillé ignoré

                C:\WINDOWS\system32\config\system.LOG L'objet est verrouillé ignoré

                C:\WINDOWS\system32\h323log.txt L'objet est verrouillé ignoré

                C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR L'objet est verrouillé ignoré

                C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP L'objet est verrouillé ignoré

                C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER L'objet est verrouillé ignoré

                C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP L'objet est verrouillé ignoré

                C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP L'objet est verrouillé ignoré

                C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA L'objet est verrouillé ignoré

                C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP L'objet est verrouillé ignoré

                C:\WINDOWS\Temp\Perflib_Perfdata_7a4.dat L'objet est verrouillé ignoré

                C:\WINDOWS\wiadebug.log L'objet est verrouillé ignoré

                C:\WINDOWS\wiaservc.log L'objet est verrouillé ignoré

                C:\WINDOWS\WindowsUpdate.log L'objet est verrouillé ignoré

                Analyse terminée.
                0
                1. RE
                  J'espère que tu as quand même passé un bon week-end ...
                  Ou en est tu ?
                  As tu lancer Ccleaner ?
                  Avast te signale-t-il toujours un virus ?
                  Je te propose d'essayer (même si je n'y crois pas trop !)
                  Navilog
                  Fais un clic droit sur ce lien : (IL-MAFIOSO)
                  http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe
                  Enregistrer la cible (du lien) sous... et enregistre-le sur ton bureau.
                  Ensuite double clique sur navilog1.exe pour lancer l'installation.
                  Une fois l'installation terminée, le fix s'exécutera automatiquement.
                  (Si ce n'est pas le cas, double-clique sur le raccourci Navilog1 présent sur le bureau).

                  Laisse-toi guider. Au menu principal, choisis 1 et valides.
                  Patiente jusqu'au message :
                  *** Analyse Termine le ..... ***
                  Appuie sur une touche comme demandé, le blocnote va s'ouvrir.
                  Copie-colle l'intégralité dans une réponse. Referme le blocnote.
                  Le rapport est en outre sauvegardé à la racine du disque (fixnavi.txt)

                  As tu arrêté ton antivirus lors des scan en ligne ?
                  Refais les manips si ce n'est pas le cas !
                  A+
                  0
                  1. Oui Merci jai passé un bon WE. Alors je viens juste de m'en choper un autre, je comprends pas coment je les attrapes je vais sur les mêmes sites pratiquements ts les jours Win32:Inject-EV, si tas une astuce pr plus que je les attire ; ) ! J'ai l'impression que mon ordi devient une passoire...

                    donc du coup jai eu peur et jai arrêté Navilog je vais refaire un scan vu que jai un trojan de plus, je t'aurai bien fais un imprime ecran pr te montrer le visualisateur du journal d'Avast mais j'y arrive pas!

                    oui jai stoppé avast pendant le scan online...

                    Et je vais relancer CCleaner.

                    Bon bé Bonne journée
                    0
                    1. Questions : Pr le dernier trojan j'ai réussi à le mettre en quarantaine sur Avast, CCleaner ne l'a pas trouvé je crois, qu'est-ce que je dois faire le laisser en quarantaine ou le supprimer???

                      Peux-tu me refaire un lien pr installer un parefeu ? Car j'arrive tjrs pas a aller sur les précedents liens
                      Et tu sais pourquoi par ex qd je vais sur le site d'Allociné Internet beug? Je me sens seule sans ce site ; )

                      Peux-t-on désinstaller Internet et le réinstaller?? J'en doute mais bon ...

                      Thank you
                      0
                      1. Salut

                        Quel bug as tu avec IE ?
                        Quelle erreur ?

                        Pour ton virus en quarantaine ... tu peux supprimer !

                        A+
                        0
                        1. Re
                          Tente d'installer celui-ci :
                          http://www.commentcamarche.net/telecharger/telecharger 192 sygate personal firewall
                          Télécharge le fichier, ensuite déconnecte toi d'internet
                          Désactive le parefeu d'XP (si activé)
                          Installe Sygate
                          Reconnecte toi
                          Accepte les connexions sortantes (qui te paraissent légitimes comme Avast, Sygate, windows ...)
                          Au fur et à mesure que tu lanceras des applications, tu auras à répondre à cette question de sygate.

                          A+
                          0
                          1. lorsque je vais sur internet et que j'ouvre certain site, je suis obligé de fermer internet car impossible de ne plus rien faire, a l'instant jai du redemarrer l'ordi pr avoir acces a commentcamarche ! M'enfin...

                            Merci pr le firewall !
                            0
                            1. Re
                              Dès que tu en auras l'occasion :
                              Télécharge SmitfraudFix de S!Ri, balltrap34 et moe31

                              http://siri.urz.free.fr/Fix/SmitfraudFix.zip
                              Dézippe le puis

                              * Installe le à la racine de C

                              Tu crees un nouveau dossier, via clic droit "créer /nouveau dossier que tu nommes SmitfraudFix --> C:\SmitfraudFix

                              Regarde un exemple a E ) « Faire un répertoire dédié » https://forum.pcastuces.com/sujet.asp?f=25&s=3902

                              * double clic sur l'exe pour le décompresser et lancer le fix.
                              Utilisation ----- option 1 - Recherche :
                              * Double clique sur smitfraudfix.cmd
                              * Sélectionne 1 pour créer un rapport des fichiers responsables de l'infection.
                              * Poste le rapport ici

                              A+
                              0
                              1. Hi, j'étais en déplassement et en revenant j'ai la bonne surprise; qd j'essaie d'aller sur CE site, IE bloque. Donc je suis sur un autre ordi!
                                J'ai une amie qui m'a pris l'ordi durant mon absence et elle m'a fais un scan avec STOPzilla qui trouve 25 infection dont qlques trojan mais pr les supprimer faut payer biensur, est-il fiable ou c'est de l'arnaque??

                                Et puis je vois qu'elle a également installer Trojanremover, jai fais un scan et voici le résultat, j'espere que ca t'embête pas de regarder rapidement et me dire si déja Trojan Remover est fiable et s'il a trouvé qlque chose??

                                Pr smitfraudfix impossible d'y arriver je ne sais pas si ça vient de moi ; ) ou de l'ordi!!!

                                Thanks
                                Je suis désolé je vois que c'est assez volumineux

                                ***** NORMAL SCAN FOR ACTIVE MALWARE *****
                                Trojan Remover Ver 6.5.9, Build 2457. For information, email simplysupsupport@aol.com
                                [Unregistered version]
                                Scan started at: 15/02/2008 11:19:09
                                Using Database v6759
                                Operating System: Windows XP Home Edition Service Pack 2 (Build 2600)
                                Using data directory: C:\Documents and Settings\Mam's\Application Data\Simply Super Software\Trojan Remover\
                                Logfile directory: C:\Documents and Settings\Mam's\Mes documents\Simply Super Software\Trojan Remover Logfiles\
                                Running with Administrator privileges

                                ******************************
                                11:19:09: Scanning ----------WIN.INI-----------
                                WIN.INI found in C:\WINDOWS

                                ******************************
                                11:19:09: Scanning --------SYSTEM.INI---------
                                SYSTEM.INI found in C:\WINDOWS

                                ******************************
                                11:19:09: ----- SCANNING FOR ROOTKIT SERVICES -----
                                No hidden Services were detected.

                                ******************************
                                11:19:10: Scanning -----WINDOWS REGISTRY-----
                                --------------------
                                Checking HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WinLogon
                                --------------------
                                Checking HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WinLogon
                                This key's "Shell" value calls the following program(s):
                                Explorer.exe - this entry has been left in place
                                ----------
                                This key's "Userinit" value calls the following program(s):
                                C:\WINDOWS\system32\userinit.exe - this entry has been left in place
                                ----------
                                --------------------
                                Checking HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
                                --------------------
                                Checking HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
                                Value Name = load
                                The Data Value for this entry appears to be blank
                                --------------------
                                --------------------
                                Checking HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
                                This Registry Key attempts to run the following program(s):
                                Value Name = SunJavaUpdateSched
                                Value Data = C:\Program Files\Java\jre1.5.0\bin\jusched.exe - this command has been left in place
                                --------------------
                                Value Name = SystrayORAHSS
                                Value Data = C:\Program Files\Orange HSS\Systray\SystrayApp.exe - this command has been left in place
                                --------------------
                                Value Name = ORAHSSSessionManager
                                Value Data = C:\Program Files\Orange HSS\SessionManager\SessionManager.exe - this command has been left in place
                                --------------------
                                Value Name = SoundMan
                                Value Data = SOUNDMAN.EXE - this command has been left in place
                                --------------------
                                Value Name = StartCCC
                                Value Data = C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe - this command has been left in place
                                --------------------
                                Value Name = WinampAgent
                                Value Data = C:\Program Files\Winamp\winampa.exe - this command has been left in place
                                --------------------
                                Value Name = avast!
                                Value Data = C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe - this command has been left in place
                                --------------------
                                Value Name = Adobe Reader Speed Launcher
                                Value Data = C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe - this command has been left in place
                                --------------------
                                Value Name = SweetIM
                                Value Data = C:\Program Files\Macrogaming\SweetIM\SweetIM.exe - this command has been left in place
                                --------------------
                                Value Name = NeroFilterCheck
                                Value Data = C:\WINDOWS\system32\NeroCheck.exe - this command has been left in place
                                --------------------
                                Value Name = TrojanScanner
                                Value Data = C:\Program Files\Trojan Remover\Trjscan.exe - this program is Trojan Remover's own scan file
                                --------------------
                                Value Name = QuickTime Task
                                Value Data = C:\Program Files\QuickTime\qttask.exe" -atboottime - this command has been left in place
                                --------------------
                                Value Name = iTunesHelper
                                Value Data = C:\Program Files\iTunes\iTunesHelper.exe - this command has been left in place
                                --------------------
                                --------------------
                                Checking HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
                                This Registry Key appears to be empty
                                --------------------
                                Checking HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
                                This Registry Key appears to be empty
                                --------------------
                                Checking HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce
                                This Registry Key appears to be empty
                                --------------------
                                Checking HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx
                                This Registry Key appears to be empty
                                --------------------
                                Checking HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
                                This Registry Key appears to be empty
                                --------------------
                                Checking HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
                                This Registry Key attempts to run the following program(s):
                                Value Name = CTFMON.EXE
                                Value Data = C:\WINDOWS\system32\ctfmon.exe - this command has been left in place
                                --------------------
                                Value Name = MsnMsgr
                                Value Data = C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background - this command has been left in place
                                --------------------
                                Value Name = swg
                                Value Data = C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe - this command has been left in place
                                --------------------
                                Value Name = SweetIM
                                Value Data = C:\Program Files\Macrogaming\SweetIM\SweetIM.exe - this command has been left in place
                                --------------------
                                Value Name = BitComet
                                Value Data = C:\Documents and Settings\Mam's\Mes documents\BitComet\BitComet.exe" /tray - this command has been left in place
                                --------------------
                                Value Name = AdobeUpdater
                                Value Data = C:\Program Files\Fichiers communs\Adobe\Updater5\AdobeUpdater.exe - this command has been left in place
                                --------------------
                                --------------------
                                Checking HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce
                                This Registry Key appears to be empty
                                --------------------
                                Checking HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunServices
                                This Registry Key appears to be empty
                                --------------------
                                Checking HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
                                This Registry Key appears to be empty
                                --------------------
                                Checking HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
                                This Registry Key appears to be empty
                                --------------------
                                Checking HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
                                This Registry Key appears to be empty

                                ******************************
                                11:19:13: Scanning -----SHELLEXECUTEHOOKS-----
                                ValueName: {AEB6717E-7E19-11d0-97EE-00C04FD91972}
                                File: shell32.dll - this file is expected and has been left in place
                                ----------

                                ******************************
                                11:19:13: Scanning -----HIDDEN REGISTRY ENTRIES-----
                                Taskdir check completed
                                ----------
                                No Registry Run Keys Hidden Entries found
                                ----------

                                ******************************
                                11:19:13: Scanning -----ACTIVE SCREENSAVER-----
                                ScreenSaver=C:\WINDOWS\system32\ssmypics.scr - this command has been left in place
                                --------------------

                                ******************************
                                11:19:13: Scanning ----- REGISTRY ACTIVE SETUP KEYS -----
                                Checking the StubPath calls in the Active Setup\Installed Components registry keys:
                                Key=<{12d0ed0d-0ee0-4f90-8827-78cefb8f4988}
                                StubPath=C:\WINDOWS\system32\ieudinit.exe - this reference has been left in place
                                ----------
                                Key=>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}
                                StubPath=C:\WINDOWS\inf\unregmp2.exe - this reference has been left in place
                                ----------
                                Key=>{26923b43-4d38-484f-9b9e-de460746276c}
                                StubPath=C:\WINDOWS\system32\ie4uinit.exe - this reference has been left in place
                                ----------
                                Key=>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}
                                StubPath=C:\WINDOWS\system32\shmgrate.exe - this reference has been left in place
                                ----------
                                Key={2C7339CF-2B09-4501-B3F3-F3508C9228ED}
                                StubPath=C:\WINDOWS\system32\regsvr32.exe - this reference has been left in place
                                ----------
                                Key={44BBA840-CC51-11CF-AAFA-00AA00B6015C}
                                StubPath=C:\Program Files\Outlook Express\setup50.exe - this reference has been left in place
                                ----------
                                Key={7790769C-0471-11d2-AF11-00C04FA35D02}
                                StubPath=C:\Program Files\Outlook Express\setup50.exe - this reference has been left in place
                                ----------
                                Key={89820200-ECBD-11cf-8B85-00AA005B4340}
                                StubPath=regsvr32.exe - this reference has been left in place
                                ----------
                                Key={89820200-ECBD-11cf-8B85-00AA005B4383}
                                StubPath=C:\WINDOWS\system32\ie4uinit.exe - this reference has been left in place
                                ----------

                                ******************************
                                11:19:16: Scanning ----- SERVICEDLL REGISTRY KEYS -----
                                Checking DLL files called from the CurrentControlSet\Services Keys:
                                --------------------
                                Key=Alerter
                                ServiceDLL=%SystemRoot%\system32\alrsvc.dll - this reference has been left in place
                                --------------------
                                Key=AppMgmt
                                ServiceDLL=%SystemRoot%\System32\appmgmts.dll - this file is globally excluded (file cannot be found)
                                --------------------
                                Key=AudioSrv
                                ServiceDLL=%SystemRoot%\System32\audiosrv.dll - this reference has been left in place
                                --------------------
                                Key=BITS
                                ServiceDLL=C:\WINDOWS\system32\qmgr.dll - this reference has been left in place
                                --------------------
                                Key=Browser
                                ServiceDLL=%SystemRoot%\System32\browser.dll - this reference has been left in place
                                --------------------
                                Key=CryptSvc
                                ServiceDLL=%SystemRoot%\System32\cryptsvc.dll - this reference has been left in place
                                --------------------
                                Key=DcomLaunch
                                ServiceDLL=%SystemRoot%\system32\rpcss.dll - this reference has been left in place
                                --------------------
                                Key=Dhcp
                                ServiceDLL=%SystemRoot%\System32\dhcpcsvc.dll - this reference has been left in place
                                --------------------
                                Key=dmserver
                                ServiceDLL=%SystemRoot%\System32\dmserver.dll - this reference has been left in place
                                --------------------
                                Key=Dnscache
                                ServiceDLL=%SystemRoot%\System32\dnsrslvr.dll - this reference has been left in place
                                --------------------
                                Key=ERSvc
                                ServiceDLL=%SystemRoot%\System32\ersvc.dll - this reference has been left in place
                                --------------------
                                Key=EventSystem
                                ServiceDLL=C:\WINDOWS\system32\es.dll - this reference has been left in place
                                --------------------
                                Key=FastUserSwitchingCompatibility
                                ServiceDLL=%SystemRoot%\System32\shsvcs.dll - this reference has been left in place
                                --------------------
                                Key=helpsvc
                                ServiceDLL=%WINDIR%\PCHealth\HelpCtr\Binaries\pchsvc.dll - this reference has been left in place
                                --------------------
                                Key=HidServ
                                ServiceDLL=%SystemRoot%\System32\hidserv.dll - this file is globally excluded (file cannot be found)
                                --------------------
                                Key=HTTPFilter
                                ServiceDLL=%SystemRoot%\System32\w3ssl.dll - this reference has been left in place
                                --------------------
                                Key=lanmanserver
                                ServiceDLL=%SystemRoot%\System32\srvsvc.dll - this reference has been left in place
                                --------------------
                                Key=lanmanworkstation
                                ServiceDLL=%SystemRoot%\System32\wkssvc.dll - this reference has been left in place
                                --------------------
                                Key=LmHosts
                                ServiceDLL=%SystemRoot%\System32\lmhsvc.dll - this reference has been left in place
                                --------------------
                                Key=Messenger
                                ServiceDLL=%SystemRoot%\System32\msgsvc.dll - this reference has been left in place
                                --------------------
                                Key=Netman
                                ServiceDLL=%SystemRoot%\System32\netman.dll - this reference has been left in place
                                --------------------
                                Key=Nla
                                ServiceDLL=%SystemRoot%\System32\mswsock.dll - this reference has been left in place
                                --------------------
                                Key=NtmsSvc
                                ServiceDLL=%SystemRoot%\system32\ntmssvc.dll - this reference has been left in place
                                --------------------
                                Key=RasAuto
                                ServiceDLL=%SystemRoot%\System32\rasauto.dll - this reference has been left in place
                                --------------------
                                Key=RasMan
                                ServiceDLL=%SystemRoot%\System32\rasmans.dll - this reference has been left in place
                                --------------------
                                Key=RemoteAccess
                                ServiceDLL=%SystemRoot%\System32\mprdim.dll - this reference has been left in place
                                --------------------
                                Key=RpcSs
                                ServiceDLL=%SystemRoot%\system32\rpcss.dll - this reference has been left in place
                                --------------------
                                Key=Schedule
                                ServiceDLL=%SystemRoot%\system32\schedsvc.dll - this reference has been left in place
                                --------------------
                                Key=seclogon
                                ServiceDLL=%SystemRoot%\System32\seclogon.dll - this reference has been left in place
                                --------------------
                                Key=SENS
                                ServiceDLL=%SystemRoot%\system32\sens.dll - this reference has been left in place
                                --------------------
                                Key=SharedAccess
                                ServiceDLL=%SystemRoot%\System32\ipnathlp.dll - this reference has been left in place
                                --------------------
                                Key=ShellHWDetection
                                ServiceDLL=%SystemRoot%\System32\shsvcs.dll - this reference has been left in place
                                --------------------
                                Key=srservice
                                ServiceDLL=C:\WINDOWS\system32\srsvc.dll - this reference has been left in place
                                --------------------
                                Key=SSDPSRV
                                ServiceDLL=%SystemRoot%\System32\ssdpsrv.dll - this reference has been left in place
                                --------------------
                                Key=stisvc
                                ServiceDLL=%SystemRoot%\system32\wiaservc.dll - this reference has been left in place
                                --------------------
                                Key=TapiSrv
                                ServiceDLL=%SystemRoot%\System32\tapisrv.dll - this reference has been left in place
                                --------------------
                                Key=TermService
                                ServiceDLL=%SystemRoot%\System32\termsrv.dll - this reference has been left in place
                                --------------------
                                Key=Themes
                                ServiceDLL=%SystemRoot%\System32\shsvcs.dll - this reference has been left in place
                                --------------------
                                Key=TrkWks
                                ServiceDLL=%SystemRoot%\system32\trkwks.dll - this reference has been left in place
                                --------------------
                                Key=upnphost
                                ServiceDLL=%SystemRoot%\System32\upnphost.dll - this reference has been left in place
                                --------------------
                                Key=W32Time
                                ServiceDLL=C:\WINDOWS\system32\w32time.dll - this reference has been left in place
                                --------------------
                                Key=WebClient
                                ServiceDLL=%SystemRoot%\System32\webclnt.dll - this reference has been left in place
                                --------------------
                                Key=winmgmt
                                ServiceDLL=%SystemRoot%\system32\wbem\WMIsvc.dll - this reference has been left in place
                                --------------------
                                Key=WmdmPmSN
                                ServiceDLL=C:\WINDOWS\system32\MsPMSNSv.dll - this reference has been left in place
                                --------------------
                                Key=wscsvc
                                ServiceDLL=%SYSTEMROOT%\system32\wscsvc.dll - this reference has been left in place
                                --------------------
                                Key=wuauserv
                                ServiceDLL=C:\WINDOWS\system32\wuauserv.dll - this reference has been left in place
                                --------------------
                                Key=WZCSVC
                                ServiceDLL=%SystemRoot%\System32\wzcsvc.dll - this reference has been left in place
                                --------------------
                                Key=xmlprov
                                ServiceDLL=%SystemRoot%\System32\xmlprov.dll - this reference has been left in place

                                ******************************
                                11:19:22: Scanning ----- SERVICES REGISTRY KEYS -----
                                Checking files called from the CurrentControlSet\Services Keys:
                                Key=aawservice
                                ImagePath="C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe" - this reference has been left in place
                                ----------
                                Key=ACPI
                                ImagePath=system32\DRIVERS\ACPI.sys - this reference has been left in place
                                ----------
                                Key=ACPIEC
                                ImagePath=system32\DRIVERS\ACPIEC.sys - this reference has been left in place
                                ----------
                                Key=aec
                                ImagePath=system32\drivers\aec.sys - this reference has been left in place
                                ----------
                                Key=AFD
                                ImagePath=\SystemRoot\System32\drivers\afd.sys - this reference has been left in place
                                ----------
                                Key=ALCXWDM
                                ImagePath=system32\drivers\ALCXWDM.SYS - this reference has been left in place
                                ----------
                                Key=ALG
                                ImagePath=%SystemRoot%\System32\alg.exe - this reference has been left in place
                                ----------
                                Key=AmdK8
                                ImagePath=system32\DRIVERS\AmdK8.sys - this reference has been left in place
                                ----------
                                Key=Apple Mobile Device
                                ImagePath="C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe" - this reference has been left in place
                                ----------
                                Key=Arp1394
                                ImagePath=system32\DRIVERS\arp1394.sys - this reference has been left in place
                                ----------
                                Key=aspnet_state
                                ImagePath=%SystemRoot%\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe - this reference has been left in place
                                ----------
                                Key=aswUpdSv
                                ImagePath="C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe" - this reference has been left in place
                                ----------
                                Key=AsyncMac
                                ImagePath=system32\DRIVERS\asyncmac.sys - this reference has been left in place
                                ----------
                                Key=atapi
                                ImagePath=system32\DRIVERS\atapi.sys - this reference has been left in place
                                ----------
                                Key=Ati HotKey Poller
                                ImagePath=%SystemRoot%\system32\Ati2evxx.exe - this reference has been left in place
                                ----------
                                Key=ATI Smart
                                ImagePath=C:\WINDOWS\system32\ati2sgag.exe - this reference has been left in place
                                ----------
                                Key=ati2mtag
                                ImagePath=system32\DRIVERS\ati2mtag.sys - this reference has been left in place
                                ----------
                                Key=Atmarpc
                                ImagePath=system32\DRIVERS\atmarpc.sys - this reference has been left in place
                                ----------
                                Key=audstub
                                ImagePath=system32\DRIVERS\audstub.sys - this reference has been left in place
                                ----------
                                Key=avast! Antivirus
                                ImagePath="C:\Program Files\Alwil Software\Avast4\ashServ.exe" - this reference has been left in place
                                ----------
                                Key=avast! Mail Scanner
                                ImagePath="C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service - this reference has been left in place
                                ----------
                                Key=avast! Web Scanner
                                ImagePath="C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service - this reference has been left in place
                                ----------
                                Key=Cdrom
                                ImagePath=system32\DRIVERS\cdrom.sys - this reference has been left in place
                                ----------
                                Key=CiSvc
                                ImagePath=%SystemRoot%\system32\cisvc.exe - this reference has been left in place
                                ----------
                                Key=ClipSrv
                                ImagePath=%SystemRoot%\system32\clipsrv.exe - this reference has been left in place
                                ----------
                                Key=clr_optimization_v2.0.50727_32
                                ImagePath=C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe - this reference has been left in place
                                ----------
                                Key=CmBatt
                                ImagePath=system32\DRIVERS\CmBatt.sys - this reference has been left in place
                                ----------
                                Key=Compbatt
                                ImagePath=system32\DRIVERS\compbatt.sys - this reference has been left in place
                                ----------
                                Key=COMSysApp
                                ImagePath=C:\WINDOWS\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235} - this reference has been left in place
                                ----------
                                Key=Disk
                                ImagePath=system32\DRIVERS\disk.sys - this reference has been left in place
                                ----------
                                Key=dmadmin
                                ImagePath=%SystemRoot%\System32\dmadmin.exe /com - this reference has been left in place
                                ----------
                                Key=dmboot
                                ImagePath=System32\drivers\dmboot.sys - this reference has been left in place
                                ----------
                                Key=dmio
                                ImagePath=System32\drivers\dmio.sys - this reference has been left in place
                                ----------
                                Key=dmload
                                ImagePath=System32\drivers\dmload.sys - this reference has been left in place
                                ----------
                                Key=DMusic
                                ImagePath=system32\drivers\DMusic.sys - this reference has been left in place
                                ----------
                                Key=drmkaud
                                ImagePath=system32\drivers\drmkaud.sys - this reference has been left in place
                                ----------
                                Key=Eventlog
                                ImagePath=%SystemRoot%\system32\services.exe - this reference has been left in place
                                ----------
                                Key=FltMgr
                                ImagePath=system32\DRIVERS\fltMgr.sys - this reference has been left in place
                                ----------
                                Key=Ftdisk
                                ImagePath=system32\DRIVERS\ftdisk.sys - this reference has been left in place
                                ----------
                                Key=FTRTSVC
                                ImagePath="C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe" - this reference has been left in place
                                ----------
                                Key=GEARAspiWDM
                                ImagePath=System32\Drivers\GEARAspiWDM.sys - this reference has been left in place
                                ----------
                                Key=Gpc
                                ImagePath=system32\DRIVERS\msgpc.sys - this reference has been left in place
                                ----------
                                Key=gusvc
                                ImagePath="C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe" - this reference has been left in place
                                ----------
                                Key=HTTP
                                ImagePath=System32\Drivers\HTTP.sys - this reference has been left in place
                                ----------
                                Key=i8042prt
                                ImagePath=system32\DRIVERS\i8042prt.sys - this reference has been left in place
                                ----------
                                Key=IDriverT
                                ImagePath="C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe" - this reference has been left in place
                                ----------
                                Key=Imapi
                                ImagePath=system32\DRIVERS\imapi.sys - this reference has been left in place
                                ----------
                                Key=ImapiService
                                ImagePath=C:\WINDOWS\system32\imapi.exe - this reference has been left in place
                                ----------
                                Key=Ip6Fw
                                ImagePath=system32\DRIVERS\Ip6Fw.sys - this reference has been left in place
                                ----------
                                Key=IpFilterDriver
                                ImagePath=system32\DRIVERS\ipfltdrv.sys - this reference has been left in place
                                ----------
                                Key=IpInIp
                                ImagePath=system32\DRIVERS\ipinip.sys - this reference has been left in place
                                ----------
                                Key=IpNat
                                ImagePath=system32\DRIVERS\ipnat.sys - this reference has been left in place
                                ----------
                                Key=iPod Service
                                ImagePath="C:\Program Files\iPod\bin\iPodService.exe" - this reference has been left in place
                                ----------
                                Key=IPSec
                                ImagePath=system32\DRIVERS\ipsec.sys - this reference has been left in place
                                ----------
                                Key=IRENUM
                                ImagePath=system32\DRIVERS\irenum.sys - this reference has been left in place
                                ----------
                                Key=isapnp
                                ImagePath=system32\DRIVERS\isapnp.sys - this reference has been left in place
                                ----------
                                Key=Kbdclass
                                ImagePath=system32\DRIVERS\kbdclass.sys - this reference has been left in place
                                ----------
                                Key=kmixer
                                ImagePath=system32\drivers\kmixer.sys - this reference has been left in place
                                ----------
                                Key=MDC8021X
                                ImagePath=system32\DRIVERS\mdc8021x.sys - this reference has been left in place
                                ----------
                                Key=mnmsrvc
                                ImagePath=C:\WINDOWS\system32\mnmsrvc.exe - this reference has been left in place
                                ----------
                                Key=Mouclass
                                ImagePath=system32\DRIVERS\mouclass.sys - this reference has been left in place
                                ----------
                                Key=MRxDAV
                                ImagePath=system32\DRIVERS\mrxdav.sys - this reference has been left in place
                                ----------
                                Key=MRxSmb
                                ImagePath=system32\DRIVERS\mrxsmb.sys - this reference has been left in place
                                ----------
                                Key=MSDTC
                                ImagePath=C:\WINDOWS\system32\msdtc.exe - this reference has been left in place
                                ----------
                                Key=MSIServer
                                ImagePath=C:\WINDOWS\system32\msiexec.exe /V - this reference has been left in place
                                ----------
                                Key=MSKSSRV
                                ImagePath=system32\drivers\MSKSSRV.sys - this reference has been left in place
                                ----------
                                Key=MSPCLOCK
                                ImagePath=system32\drivers\MSPCLOCK.sys - this reference has been left in place
                                ----------
                                Key=MSPQM
                                ImagePath=system32\drivers\MSPQM.sys - this reference has been left in place
                                ----------
                                Key=mssmbios
                                ImagePath=system32\DRIVERS\mssmbios.sys - this reference has been left in place
                                ----------
                                Key=NdisTapi
                                ImagePath=system32\DRIVERS\ndistapi.sys - this reference has been left in place
                                ----------
                                Key=Ndisuio
                                ImagePath=system32\DRIVERS\ndisuio.sys - this reference has been left in place
                                ----------
                                Key=NdisWan
                                ImagePath=system32\DRIVERS\ndiswan.sys - this reference has been left in place
                                ----------
                                Key=NetBIOS
                                ImagePath=system32\DRIVERS\netbios.sys - this reference has been left in place
                                ----------
                                Key=NetBT
                                ImagePath=system32\DRIVERS\netbt.sys - this reference has been left in place
                                ----------
                                Key=NetDDE
                                ImagePath=%SystemRoot%\system32\netdde.exe - this reference has been left in place
                                ----------
                                Key=NetDDEdsdm
                                ImagePath=%SystemRoot%\system32\netdde.exe - this reference has been left in place
                                ----------
                                Key=Netlogon
                                ImagePath=%SystemRoot%\system32\lsass.exe - this reference has been left in place
                                ----------
                                Key=NIC1394
                                ImagePath=system32\DRIVERS\nic1394.sys - this reference has been left in place
                                ----------
                                Key=NtLmSsp
                                ImagePath=%SystemRoot%\system32\lsass.exe - this reference has been left in place
                                ----------
                                Key=NwlnkFlt
                                ImagePath=system32\DRIVERS\nwlnkflt.sys - this reference has been left in place
                                ----------
                                Key=NwlnkFwd
                                ImagePath=system32\DRIVERS\nwlnkfwd.sys - this reference has been left in place
                                ----------
                                Key=ohci1394
                                ImagePath=system32\DRIVERS\ohci1394.sys - this reference has been left in place
                                ----------
                                Key=PCAMPR5
                                ImagePath=\??\C:\WINDOWS\system32\PCAMPR5.SYS - this reference has been left in place
                                ----------
                                Key=PCANDIS5
                                ImagePath=\??\C:\WINDOWS\system32\PCANDIS5.SYS - this reference has been left in place
                                ----------
                                Key=PCI
                                ImagePath=system32\DRIVERS\pci.sys - this reference has been left in place
                                ----------
                                Key=PCIIde
                                ImagePath=system32\DRIVERS\pciide.sys - this reference has been left in place
                                ----------
                                Key=Pcmcia
                                ImagePath=system32\DRIVERS\pcmcia.sys - this reference has been left in place
                                ----------
                                Key=PlugPlay
                                ImagePath=%SystemRoot%\system32\services.exe - this reference has been left in place
                                ----------
                                Key=PolicyAgent
                                ImagePath=%SystemRoot%\system32\lsass.exe - this reference has been left in place
                                ----------
                                Key=PptpMiniport
                                ImagePath=system32\DRIVERS\raspptp.sys - this reference has been left in place
                                ----------
                                Key=Processor
                                ImagePath=system32\DRIVERS\processr.sys - this reference has been left in place
                                ----------
                                Key=ProtectedStorage
                                ImagePath=%SystemRoot%\system32\lsass.exe - this reference has been left in place
                                ----------
                                Key=PSched
                                ImagePath=system32\DRIVERS\psched.sys - this reference has been left in place
                                ----------
                                Key=Ptilink
                                ImagePath=system32\DRIVERS\ptilink.sys - this reference has been left in place
                                ----------
                                Key=PxHelp20
                                ImagePath=System32\Drivers\PxHelp20.sys - this reference has been left in place
                                ----------
                                Key=RasAcd
                                ImagePath=system32\DRIVERS\rasacd.sys - this reference has been left in place
                                ----------
                                Key=Rasl2tp
                                ImagePath=system32\DRIVERS\rasl2tp.sys - this reference has been left in place
                                ----------
                                Key=RasPppoe
                                ImagePath=system32\DRIVERS\raspppoe.sys - this reference has been left in place
                                ----------
                                Key=Raspti
                                ImagePath=system32\DRIVERS\raspti.sys - this reference has been left in place
                                ----------
                                Key=Rdbss
                                ImagePath=system32\DRIVERS\rdbss.sys - this reference has been left in place
                                ----------
                                Key=RDPCDD
                                ImagePath=System32\DRIVERS\RDPCDD.sys - this reference has been left in place
                                ----------
                                Key=RDSessMgr
                                ImagePath=C:\WINDOWS\system32\sessmgr.exe - this reference has been left in place
                                ----------
                                Key=redbook
                                ImagePath=system32\DRIVERS\redbook.sys - this reference has been left in place
                                ----------
                                Key=RpcLocator
                                ImagePath=%SystemRoot%\system32\locator.exe - this reference has been left in place
                                ----------
                                Key=RSVP
                                ImagePath=%SystemRoot%\system32\rsvp.exe - this reference has been left in place
                                ----------
                                Key=rtl8139
                                ImagePath=system32\DRIVERS\RTL8139.SYS - this reference has been left in place
                                ----------
                                Key=SamSs
                                ImagePath=%SystemRoot%\system32\lsass.exe - this reference has been left in place
                                ----------
                                Key=SCardSvr
                                ImagePath=%SystemRoot%\System32\SCardSvr.exe - this reference has been left in place
                                ----------
                                Key=Secdrv
                                ImagePath=system32\DRIVERS\secdrv.sys - this reference has been left in place
                                ----------
                                Key=splitter
                                ImagePath=system32\drivers\splitter.sys - this reference has been left in place
                                ----------
                                Key=Spooler
                                ImagePath=%SystemRoot%\system32\spoolsv.exe - this reference has been left in place
                                ----------
                                Key=sr
                                ImagePath=system32\DRIVERS\sr.sys - this reference has been left in place
                                ----------
                                Key=Srv
                                ImagePath=system32\DRIVERS\srv.sys - this reference has been left in place
                                ----------
                                Key=swenum
                                ImagePath=system32\DRIVERS\swenum.sys - this reference has been left in place
                                ----------
                                Key=swmidi
                                ImagePath=system32\drivers\swmidi.sys - this reference has been left in place
                                ----------
                                Key=SwPrv
                                ImagePath=C:\WINDOWS\system32\dllhost.exe /Processid:{51AC2961-FEE7-4977-9DDB-AD04B6BF255B} - this reference has been left in place
                                ----------
                                Key=sysaudio
                                ImagePath=system32\drivers\sysaudio.sys - this reference has been left in place
                                ----------
                                Key=SysmonLog
                                ImagePath=%SystemRoot%\system32\smlogsvc.exe - this reference has been left in place
                                ----------
                                Key=szkg5
                                ImagePath=system32\DRIVERS\szkg.sys - this reference has been left in place
                                ----------
                                Key=szserver
                                ImagePath="C:\Program Files\Fichiers communs\iS3\Anti-Spyware\SZServer.exe" - this reference has been left in place
                                ----------
                                Key=Tcpip
                                ImagePath=system32\DRIVERS\tcpip.sys - this reference has been left in place
                                ----------
                                Key=TermDD
                                ImagePath=system32\DRIVERS\termdd.sys - this reference has been left in place
                                ----------
                                Key=UMWdf
                                ImagePath=C:\WINDOWS\system32\wdfmgr.exe - this reference has been left in place
                                ----------
                                Key=Update
                                ImagePath=system32\DRIVERS\update.sys - this reference has been left in place
                                ----------
                                Key=UPS
                                ImagePath=%SystemRoot%\System32\ups.exe - this reference has been left in place
                                ----------
                                Key=usbehci
                                ImagePath=system32\DRIVERS\usbehci.sys - this reference has been left in place
                                ----------
                                Key=usbhub
                                ImagePath=system32\DRIVERS\usbhub.sys - this reference has been left in place
                                ----------
                                Key=usbohci
                                ImagePath=system32\DRIVERS\usbohci.sys - this reference has been left in place
                                ----------
                                Key=usbscan
                                ImagePath=system32\DRIVERS\usbscan.sys - this reference has been left in place
                                ----------
                                Key=usbstor
                                ImagePath=system32\DRIVERS\USBSTOR.SYS - this reference has been left in place
                                ----------
                                Key=usnjsvc
                                ImagePath="C:\Program Files\Windows Live\Messenger\usnsvc.exe" - this reference has been left in place
                                ----------
                                Key=VgaSave
                                ImagePath=\SystemRoot\System32\drivers\vga.sys - this reference has been left in place
                                ----------
                                Key=VSS
                                ImagePath=%SystemRoot%\System32\vssvc.exe - this reference has been left in place
                                ----------
                                Key=Wanarp
                                ImagePath=system32\DRIVERS\wanarp.sys - this reference has been left in place
                                ----------
                                Key=wdmaud
                                ImagePath=system32\drivers\wdmaud.sys - this reference has been left in place
                                ----------
                                Key=WlanUIG
                                ImagePath=system32\DRIVERS\WlanUIG.sys - this reference has been left in place
                                ----------
                                Key=WLSetupSvc
                                ImagePath="C:\Program Files\Windows Live\installer\WLSetupSvc.exe" - this reference has been left in place
                                ----------
                                Key=WmiAcpi
                                ImagePath=system32\DRIVERS\wmiacpi.sys - this reference has been left in place
                                ----------
                                Key=WmiApSrv
                                ImagePath=C:\WINDOWS\system32\wbem\wmiapsrv.exe - this reference has been left in place
                                ----------
                                Key=WpdUsb
                                ImagePath=System32\Drivers\wpdusb.sys - this reference has been left in place
                                ----------
                                Key=WS2IFSL
                                ImagePath=\SystemRoot\System32\drivers\ws2ifsl.sys - this reference has been left in place
                                ----------

                                ******************************
                                11:19:53: Scanning -----VXD ENTRIES-----
                                No static VxD keys found to check
                                Checking VMM32 VxD files being loaded

                                ******************************
                                11:19:53: Scanning ----- WINLOGON\NOTIFY DLLS -----
                                Checking DLLs called from the Winlogon\Notify key:
                                Key=AtiExtEvent
                                DLLName=Ati2evxx.dll - this reference has been left in place
                                ----------
                                Key=crypt32chain
                                DLLName=crypt32.dll - this reference has been left in place
                                ----------
                                Key=cryptnet
                                DLLName=cryptnet.dll - this reference has been left in place
                                ----------
                                Key=cscdll
                                DLLName=cscdll.dll - this reference has been left in place
                                ----------
                                Key=ScCertProp
                                DLLName=wlnotify.dll - this reference has been left in place
                                ----------
                                Key=Schedule
                                DLLName=wlnotify.dll - this reference has been left in place
                                ----------
                                Key=sclgntfy
                                DLLName=sclgntfy.dll - this reference has been left in place
                                ----------
                                Key=SensLogn
                                DLLName=WlNotify.dll - this reference has been left in place
                                ----------
                                Key=termsrv
                                DLLName=wlnotify.dll - this reference has been left in place
                                ----------
                                Key=wlballoon
                                DLLName=wlnotify.dll - this reference has been left in place
                                ----------

                                ******************************
                                11:19:55: Scanning ----- CONTEXTMENUHANDLERS -----
                                Key = avast
                                CLSID = {472083B0-C522-11CF-8763-00608CC02F24}
                                C:\Program Files\Alwil Software\Avast4\ashShell.dll - this ContextMenuHandler has been left in place
                                ----------
                                Key = Fichiers hors connexion
                                CLSID = {750fdf0e-2a26-11d1-a3ea-080036587f03}
                                %SystemRoot%\System32\cscui.dll - this ContextMenuHandler has been left in place
                                ----------
                                Key = Open With
                                CLSID = {09799AFB-AD67-11d1-ABCD-00C04FC30936}
                                %SystemRoot%\system32\SHELL32.dll - this ContextMenuHandler has been left in place
                                ----------
                                Key = Open With EncryptionMenu
                                CLSID = {A470F8CF-A1E8-4f65-8335-227475AA5C46}
                                %SystemRoot%\system32\SHELL32.dll - this ContextMenuHandler has been left in place
                                ----------
                                Key = Trojan Remover
                                CLSID = {52B87208-9CCF-42C9-B88E-069281105805}
                                C:\PROGRA~1\TROJAN~1\Trshlex.dll - this ContextMenuHandler has been left in place
                                ----------
                                Key = {a2a9545d-a0c2-42b4-9708-a0b2badd77c8}
                                %SystemRoot%\system32\SHELL32.dll - this ContextMenuHandler has been left in place
                                ----------

                                ******************************
                                11:19:56: Scanning ----- FOLDER\COLUMNHANDLERS -----
                                Key = {0D2E74C4-3C34-11d2-A27E-00C04FC30871}
                                %SystemRoot%\system32\SHELL32.dll - this Folder\ColumnHandler has been left in place
                                ----------
                                Key = {24F14F01-7B1C-11d1-838f-0000F80461CF}
                                %SystemRoot%\system32\SHELL32.dll - this Folder\ColumnHandler has been left in place
                                ----------
                                Key = {24F14F02-7B1C-11d1-838f-0000F80461CF}
                                %SystemRoot%\system32\SHELL32.dll - this Folder\ColumnHandler has been left in place
                                ----------
                                Key = {66742402-F9B9-11D1-A202-0000F81FEDEE}
                                %SystemRoot%\system32\SHELL32.dll - this Folder\ColumnHandler has been left in place
                                ----------
                                Key = {F9DB5320-233E-11D1-9F84-707F02C10627}
                                C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\PDFShell.dll - this Folder\ColumnHandler has been left in place
                                ----------

                                ******************************
                                11:19:56: Scanning ----- BROWSER HELPER OBJECTS -----
                                Key = {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
                                C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll - this Browser Helper Object has been left in place
                                ----------
                                Key = {1827766B-9F49-4854-8034-F6EE26FCB1EC}
                                C:\Program Files\STOPzilla!\SZSG.dll - this Browser Helper Object has been left in place
                                ----------
                                Key = {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60}
                                C:\Documents and Settings\Mam's\Mes documents\BitComet\tools\BitCometBHO_1.2.1.2.dll - this Browser Helper Object has been left in place
                                ----------
                                Key = {9030D464-4C02-4ABF-8ECC-5164760863C6}
                                C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll - this Browser Helper Object has been left in place
                                ----------
                                Key = {AA58ED58-01DD-4d91-8333-CF10577473F7}
                                c:\program files\google\googletoolbar2.dll - this Browser Helper Object has been left in place
                                ----------
                                Key = {AF69DE43-7D58-4638-B6FA-CE66B5AD205D}
                                C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll - this Browser Helper Object has been left in place
                                ----------
                                Key = {E3215F20-3212-11D6-9F8B-00D0B743919D}
                                C:\Program Files\STOPzilla!\SZIEBHO.dll - this Browser Helper Object has been left in place
                                ----------

                                ******************************
                                11:19:58: Scanning ----- SHELLSERVICEOBJECTS -----
                                Key = PostBootReminder
                                %SystemRoot%\system32\SHELL32.dll - this ShellServiceObject has been left in place
                                ----------
                                Key = CDBurn
                                %SystemRoot%\system32\SHELL32.dll - this ShellServiceObject has been left in place
                                ----------
                                Key = WebCheck
                                C:\WINDOWS\system32\webcheck.dll - this ShellServiceObject has been left in place
                                ----------
                                Key = SysTray
                                C:\WINDOWS\system32\stobject.dll - this ShellServiceObject has been left in place
                                ----------

                                ******************************
                                11:19:58: Scanning ----- SHAREDTASKSCHEDULER ENTRIES -----
                                Value = {438755C2-A8BA-11D1-B96B-00A0C90312E1}
                                Comment = Pré-chargeur Browseui
                                File: %SystemRoot%\system32\browseui.dll - this SharedTaskScheduler entry has been left in place
                                ----------
                                Value = {8C7461EF-2B13-11d2-BE35-3078302C2030}
                                Comment = Démon de cache des catégories de composant
                                File: %SystemRoot%\system32\browseui.dll - this SharedTaskScheduler entry has been left in place
                                ----------

                                ******************************
                                11:19:58: Scanning ----- IMAGEFILE DEBUGGERS -----
                                No "Debugger" entries found.

                                ******************************
                                11:19:58: Scanning ----- APPINIT_DLLS -----
                                The AppInit_DLLs value is blank

                                ******************************
                                11:19:58: Scanning ------ COMMON STARTUP GROUP ------
                                [C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage]
                                The Common Startup Group attempts to load the following file(s) at boot time:
                                desktop.ini - this file is expected and has been left in place
                                --------------------
                                Outil de mise à jour Google.lnk - this links to C:\Program Files\Google\Google Updater\GoogleUpdater.exe and has been left in place
                                --------------------
                                Utilitaire réseau pour SAGEM Wi-Fi 11g USB adapter.lnk - this links to C:\Program Files\SAGEM WiFi manager\WLANUTL.exe and has been left in place
                                --------------------

                                ******************************
                                No User Startup Groups were located to check

                                ******************************
                                11:19:59: Scanning ----- SCHEDULED TASKS -----

                                ******************************
                                11:19:59: ----- EXTRA CHECKS -----
                                PE386 rootkit checks completed
                                ----------
                                Winlogon registry rootkit checks completed
                                ----------
                                Heuristic checks for hidden files/drivers completed
                                ----------

                                ******************************
                                11:19:59: Scanning ------ DOWNLOADED PROGRAM FILES ------
                                The following files are located in the DOWNLOADED PROGRAM FILES directory:
                                C:\WINDOWS\Downloaded Program Files\bdcore.dll - this file has been left in place
                                C:\WINDOWS\Downloaded Program Files\bdupd.dll - this file has been left in place
                                C:\WINDOWS\Downloaded Program Files\desktop.ini - this file is expected and has been left in place
                                C:\WINDOWS\Downloaded Program Files\hardwaredetection.inf - this file has been left in place
                                C:\WINDOWS\Downloaded Program Files\ipsupd.dll - this file has been left in place
                                C:\WINDOWS\Downloaded Program Files\lang.ini - this file has been left in place
                                C:\WINDOWS\Downloaded Program Files\libfn.dll - this file has been left in place
                                C:\WINDOWS\Downloaded Program Files\live.ini - this file has been left in place
                                C:\WINDOWS\Downloaded Program Files\oscan8.inf - this file has been left in place
                                C:\WINDOWS\Downloaded Program Files\oscan8.ocx - this file has been left in place
                                C:\WINDOWS\Downloaded Program Files\scanoptions.tsi - this file has been left in place
                                C:\WINDOWS\Downloaded Program Files\wuweb.inf - this file has been left in place

                                ******************************
                                11:20:03: Scanning ----- RUNNING PROCESSES -----

                                C:\WINDOWS\System32\smss.exe
                                --------------------
                                C:\WINDOWS\system32\csrss.exe
                                --------------------
                                C:\WINDOWS\system32\winlogon.exe
                                --------------------
                                C:\WINDOWS\system32\services.exe
                                --------------------
                                C:\WINDOWS\system32\lsass.exe
                                --------------------
                                C:\WINDOWS\system32\Ati2evxx.exe
                                --------------------
                                C:\WINDOWS\system32\svchost.exe
                                --------------------
                                C:\Program Files\Fichiers communs\iS3\Anti-Spyware\SZServer.exe
                                --------------------
                                C:\WINDOWS\system32\svchost.exe
                                --------------------
                                C:\WINDOWS\System32\svchost.exe
                                --------------------
                                C:\WINDOWS\system32\Ati2evxx.exe
                                --------------------
                                C:\WINDOWS\system32\svchost.exe
                                --------------------
                                C:\WINDOWS\system32\svchost.exe
                                --------------------
                                C:\WINDOWS\Explorer.EXE
                                --------------------
                                C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                                --------------------
                                C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                --------------------
                                C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                --------------------
                                C:\Program Files\STOPzilla!\STOPzilla.exe
                                --------------------
                                C:\WINDOWS\system32\spoolsv.exe
                                --------------------
                                C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                --------------------
                                C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
                                --------------------
                                C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                --------------------
                                C:\WINDOWS\system32\svchost.exe
                                --------------------
                                C:\WINDOWS\system32\wdfmgr.exe
                                --------------------
                                C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                                --------------------
                                C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                                --------------------
                                C:\WINDOWS\System32\alg.exe
                                --------------------
                                C:\Program Files\Java\jre1.5.0\bin\jusched.exe
                                --------------------
                                C:\Program Files\Orange HSS\Systray\SystrayApp.exe
                                --------------------
                                C:\WINDOWS\SOUNDMAN.EXE
                                --------------------
                                C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe
                                --------------------
                                C:\Program Files\Winamp\winampa.exe
                                --------------------
                                C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
                                --------------------
                                C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                                --------------------
                                C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
                                --------------------
                                C:\Program Files\iTunes\iTunesHelper.exe
                                --------------------
                                C:\WINDOWS\system32\ctfmon.exe
                                --------------------
                                C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                                --------------------
                                C:\Program Files\Google\Google Updater\GoogleUpdater.exe
                                --------------------
                                C:\Program Files\SAGEM WiFi manager\WLANUTL.exe
                                --------------------
                                C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
                                --------------------
                                C:\Program Files\iPod\bin\iPodService.exe
                                --------------------
                                C:\Program Files\Windows Live\Messenger\usnsvc.exe
                                --------------------
                                C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
                                --------------------
                                C:\Program Files\Internet Explorer\iexplore.exe
                                --------------------
                                C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe
                                --------------------
                                C:\Documents and Settings\Mam's\Application Data\Simply Super Software\Trojan Remover\yptD.exe
                                FileSize: 1 782 336
                                [This is a Trojan Remover component]
                                --------------------

                                ******************************
                                11:20:12: Checking AUTOEXEC.BAT file
                                AUTOEXEC.BAT found in C:\
                                No malicious entries were found in the AUTOEXEC.BAT file

                                ******************************
                                11:20:12: Checking AUTOEXEC.NT file
                                AUTOEXEC.NT found in C:\WINDOWS\system32
                                No malicious entries were found in the AUTOEXEC.NT file

                                ******************************
                                ------ INTERNET EXPLORER HOME/START/SEARCH SETTINGS ------
                                HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\"Start Page":
                                https://home.sweetim.com/
                                HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\"Local Page":
                                %SystemRoot%\system32\blank.htm
                                HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\"Search Page":
                                https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\"Default_Page_URL":
                                https://www.google.com/?gws_rd=ssl
                                HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\"Default_Search_URL":
                                https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search\"CustomizeSearch":
                                https://www.bing.com/?toHttps=1&redig=8F3F334EA60E4B1CB4D040DCFE393A89{SUB_RFC1766}/srchasst/srchcust.htm
                                HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search\"SearchAssistant":
                                This value is blank
                                HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\"Start Page":
                                https://www.google.com/?gws_rd=ssl
                                HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\"Local Page":
                                C:\WINDOWS\system32\blank.htm
                                HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\"Search Page":
                                https://www.google.com/?gws_rd=ssl
                                HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\"Default_Page_URL":
                                https://www.google.com/?gws_rd=ssl
                                HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search\"CustomizeSearch":
                                https://www.bing.com/?toHttps=1&redig=8F3F334EA60E4B1CB4D040DCFE393A89{SUB_RFC1766}/srchasst/srchcust.htm
                                HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search\"SearchAssistant":
                                http://www.google.com/toolbar/ie8/sidebar.html

                                ******************************
                                === NO CHANGES HAVE BEEN MADE TO YOUR SYSTEM FILES ===
                                Scan completed at: 15/02/2008 11:20:12
                                ************************************************************

                                ***** NORMAL SCAN FOR ACTIVE MALWARE *****
                                Trojan Remover Ver 6.5.9, Build 2457. For information, email simplysupsupport@aol.com
                                [Unregistered version]
                                Scan started at: 14/02/2008 14:43:06
                                Using Database v6759
                                Operating System: Windows XP Home Edition Service Pack 2 (Build 2600)
                                Using data directory: C:\Documents and Settings\Mam's\Application Data\Simply Super Software\Trojan Remover\
                                Logfile directory: C:\Documents and Settings\Mam's\Mes documents\Simply Super Software\Trojan Remover Logfiles\
                                Running with Administrator privileges

                                **************************************************
                                Checking Registry exefile command for modifications
                                Checking Registry comfile command for modifications
                                Checking Registry piffile command for modifications
                                Checking Registry batfile command for modifications
                                Checking Registry regfile command for modifications
                                Checking Registry cmdfile command for modifications
                                Checking Registry scrfile command for modifications

                                ******************************
                                14:43:06: Scanning ----------WIN.INI-----------
                                WIN.INI found in C:\WINDOWS

                                ******************************
                                14:43:06: Scanning --------SYSTEM.INI---------
                                SYSTEM.INI found in C:\WINDOWS

                                ******************************
                                14:43:06: ----- SCANNING FOR ROOTKIT SERVICES -----
                                No hidden Services were detected.

                                ******************************
                                14:43:06: Scanning -----WINDOWS REGISTRY-----
                                --------------------
                                Checking HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WinLogon
                                --------------------
                                Checking HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WinLogon
                                This key's "Shell" value calls the following program(s):
                                Explorer.exe - this entry has been left in place
                                ----------
                                This key's "Userinit" value calls the following program(s):
                                C:\WINDOWS\system32\userinit.exe - this entry has been left in place
                                ----------
                                --------------------
                                Checking HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
                                --------------------
                                Checking HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
                                Value Name = load
                                The Data Value for this entry appears to be blank
                                --------------------
                                --------------------
                                Checking HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
                                This Registry Key attempts to run the following program(s):
                                Value Name = SunJavaUpdateSched
                                Value Data = C:\Program Files\Java\jre1.5.0\bin\jusched.exe - this command has been left in place
                                --------------------
                                Value Name = SystrayORAHSS
                                Value Data = C:\Program Files\Orange HSS\Systray\SystrayApp.exe - this command has been left in place
                                --------------------
                                Value Name = ORAHSSSessionManager
                                Value Data = C:\Program Files\Orange HSS\SessionManager\SessionManager.exe - this command has been left in place
                                --------------------
                                Value Name = SoundMan
                                Value Data = SOUNDMAN.EXE - this command has been left in place
                                --------------------
                                Value Name = StartCCC
                                Value Data = C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe - this command has been left in place
                                --------------------
                                Value Name = WinampAgent
                                Value Data = C:\Program Files\Winamp\winampa.exe - this command has been left in place
                                --------------------
                                Value Name = avast!
                                Value Data = C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe - this command has been left in place
                                --------------------
                                Value Name = Adobe Reader Speed Launcher
                                Value Data = C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe - this command has been left in place
                                --------------------
                                Value Name = SweetIM
                                Value Data = C:\Program Files\Macrogaming\SweetIM\SweetIM.exe - this command has been left in place
                                --------------------
                                Value Name = NeroFilterCheck
                                Value Data = C:\WINDOWS\system32\NeroCheck.exe - this command has been left in place
                                --------------------
                                Value Name = TrojanScanner
                                Value Data = C:\Program Files\Trojan Remover\Trjscan.exe - this program is Trojan Remover's own scan file
                                --------------------
                                Value Name = QuickTime Task
                                Value Data = C:\Program Files\QuickTime\qttask.exe" -atboottime - this command has been left in place
                                --------------------
                                Value Name = iTunesHelper
                                Value Data = C:\Program Files\iTunes\iTunesHelper.exe - this command has been left in place
                                --------------------
                                --------------------
                                Checking HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
                                This Registry Key appears to be empty
                                --------------------
                                Checking HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
                                This Registry Key appears to be empty
                                --------------------
                                Checking HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce
                                This Registry Key appears to be empty
                                --------------------
                                Checking HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx
                                This Registry Key appears to be empty
                                --------------------
                                Checking HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
                                This Registry Key appears to be empty
                                --------------------
                                Checking HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
                                This Registry Key attempts to run the following program(s):
                                Value Name = CTFMON.EXE
                                Value Data = C:\WINDOWS\system32\ctfmon.exe - this command has been left in place
                                --------------------
                                Value Name = MsnMsgr
                                Value Data = C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background - this command has been left in place
                                --------------------
                                Value Name = swg
                                Value Data = C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe - this command has been left in place
                                --------------------
                                Value Name = SweetIM
                                Value Data = C:\Program Files\Macrogaming\SweetIM\SweetIM.exe - this command has been left in place
                                --------------------
                                Value Name = BitComet
                                Value Data = C:\Documents and Settings\Mam's\Mes documents\BitComet\BitComet.exe" /tray - this command has been left in place
                                --------------------
                                Value Name = AdobeUpdater
                                Value Data = C:\Program Files\Fichiers communs\Adobe\Updater5\AdobeUpdater.exe - this command has been left in place
                                --------------------
                                --------------------
                                Checking HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce
                                This Registry Key appears to be empty
                                --------------------
                                Checking HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunServices
                                This Registry Key appears to be empty
                                --------------------
                                Checking HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
                                This Registry Key appears to be empty
                                --------------------
                                Checking HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
                                This Registry Key appears to be empty
                                --------------------
                                Checking HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
                                This Registry Key appears to be empty

                                ******************************
                                14:43:08: Scanning -----SHELLEXECUTEHOOKS-----
                                ValueName: {AEB6717E-7E19-11d0-97EE-00C04FD91972}
                                File: shell32.dll - this file is expected and has been left in place
                                ----------

                                ******************************
                                14:43:08: Scanning -----HIDDEN REGISTRY ENTRIES-----
                                Taskdir check completed
                                ----------
                                No Registry Run Keys Hidden Entries found
                                ----------

                                ******************************
                                14:43:09: Scanning -----ACTIVE SCREENSAVER-----
                                ScreenSaver=C:\WINDOWS\system32\ssmypics.scr - this command has been left in place
                                --------------------

                                ******************************
                                14:43:09: Scanning ----- REGISTRY ACTIVE SETUP KEYS -----
                                Checking the StubPath calls in the Active Setup\Installed Components registry keys:
                                Key=<{12d0ed0d-0ee0-4f90-8827-78cefb8f4988}
                                StubPath=C:\WINDOWS\system32\ieudinit.exe - this reference has been left in place
                                ----------
                                Key=>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}
                                StubPath=C:\WINDOWS\inf\unregmp2.exe - this reference has been left in place
                                ----------
                                Key=>{26923b43-4d38-484f-9b9e-de460746276c}
                                StubPath=C:\WINDOWS\system32\ie4uinit.exe - this reference has been left in place
                                ----------
                                Key=>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}
                                StubPath=C:\WINDOWS\system32\shmgrate.exe - this reference has been left in place
                                ----------
                                Key={2C7339CF-2B09-4501-B3F3-F3508C9228ED}
                                StubPath=C:\WINDOWS\system32\regsvr32.exe - this reference has been left in place
                                ----------
                                Key={44BBA840-CC51-11CF-AAFA-00AA00B6015C}
                                StubPath=C:\Program Files\Outlook Express\setup50.exe - this reference has been left in place
                                ----------
                                Key={7790769C-0471-11d2-AF11-00C04FA35D02}
                                StubPath=C:\Program Files\Outlook Express\setup50.exe - this reference has been left in place
                                ----------
                                Key={89820200-ECBD-11cf-8B85-00AA005B4340}
                                StubPath=regsvr32.exe - this reference has been left in place
                                ----------
                                Key={89820200-ECBD-11cf-8B85-00AA005B4383}
                                StubPath=C:\WINDOWS\system32\ie4uinit.exe - this reference has been left in place
                                ----------

                                ******************************
                                14:43:10: Scanning ----- SERVICEDLL REGISTRY KEYS -----
                                Checking DLL files called from the CurrentControlSet\Services Keys:
                                --------------------
                                Key=Alerter
                                ServiceDLL=%SystemRoot%\system32\alrsvc.dll - this reference has been left in place
                                --------------------
                                Key=AppMgmt
                                ServiceDLL=%SystemRoot%\System32\appmgmts.dll - this file is globally excluded (file cannot be found)
                                --------------------
                                Key=AudioSrv
                                ServiceDLL=%SystemRoot%\System32\audiosrv.dll - this reference has been left in place
                                --------------------
                                Key=BITS
                                ServiceDLL=C:\WINDOWS\system32\qmgr.dll - this reference has been left in place
                                --------------------
                                Key=Browser
                                ServiceDLL=%SystemRoot%\System32\browser.dll - this reference has been left in place
                                --------------------
                                Key=CryptSvc
                                ServiceDLL=%SystemRoot%\System32\cryptsvc.dll - this reference has been left in place
                                --------------------
                                Key=DcomLaunch
                                ServiceDLL=%SystemRoot%\system32\rpcss.dll - this reference has been left in place
                                --------------------
                                Key=Dhcp
                                ServiceDLL=%SystemRoot%\System32\dhcpcsvc.dll - this reference has been left in place
                                --------------------
                                Key=dmserver
                                ServiceDLL=%SystemRoot%\System32\dmserver.dll - this reference has been left in place
                                --------------------
                                Key=Dnscache
                                ServiceDLL=%SystemRoot%\System32\dnsrslvr.dll - this reference has been left in place
                                --------------------
                                Key=ERSvc
                                ServiceDLL=%SystemRoot%\System32\ersvc.dll - this reference has been left in place
                                --------------------
                                Key=EventSystem
                                ServiceDLL=C:\WINDOWS\system32\es.dll - this reference has been left in place
                                --------------------
                                Key=FastUserSwitchingCompatibility
                                ServiceDLL=%SystemRoot%\System32\shsvcs.dll - this reference has been left in place
                                --------------------
                                Key=helpsvc
                                ServiceDLL=%WINDIR%\PCHealth\HelpCtr\Binaries\pchsvc.dll - this reference has been left in place
                                --------------------
                                Key=HidServ
                                ServiceDLL=%SystemRoot%\System32\hidserv.dll - this file is globally excluded (file cannot be found)
                                --------------------
                                Key=HTTPFilter
                                ServiceDLL=%SystemRoot%\System32\w3ssl.dll - this reference has been left in place
                                --------------------
                                Key=lanmanserver
                                ServiceDLL=%SystemRoot%\System32\srvsvc.dll - this reference has been left in place
                                --------------------
                                Key=lanmanworkstation
                                ServiceDLL=%SystemRoot%\System32\wkssvc.dll - this reference has been left in place
                                --------------------
                                Key=LmHosts
                                ServiceDLL=%SystemRoot%\System32\lmhsvc.dll - this reference has been left in place
                                --------------------
                                Key=Messenger
                                ServiceDLL=%SystemRoot%\System32\msgsvc.dll - this reference has been left in place
                                --------------------
                                Key=Netman
                                ServiceDLL=%SystemRoot%\System32\netman.dll - this reference has been left in place
                                --------------------
                                Key=Nla
                                ServiceDLL=%SystemRoot%\System32\mswsock.dll - this reference has been left in place
                                --------------------
                                Key=NtmsSvc
                                ServiceDLL=%SystemRoot%\system32\ntmssvc.dll - this reference has been left in place
                                --------------------
                                Key=RasAuto
                                ServiceDLL=%SystemRoot%\System32\rasauto.dll - this reference has been left in place
                                --------------------
                                Key=RasMan
                                ServiceDLL=%SystemRoot%\System32\rasmans.dll - this reference has been left in place
                                --------------------
                                Key=RemoteAccess
                                ServiceDLL=%SystemRoot%\System32\mprdim.dll - this reference has been left in place
                                --------------------
                                Key=RpcSs
                                ServiceDLL=%SystemRoot%\system32\rpcss.dll - this reference has been left in place
                                --------------------
                                Key=Schedule
                                ServiceDLL=%SystemRoot%\system32\schedsvc.dll - this reference has been left in place
                                --------------------
                                Key=seclogon
                                ServiceDLL=%SystemRoot%\System32\seclogon.dll - this reference has been left in place
                                --------------------
                                Key=SENS
                                ServiceDLL=%SystemRoot%\system32\sens.dll - this reference has been left in place
                                --------------------
                                Key=SharedAccess
                                ServiceDLL=%SystemRoot%\System32\ipnathlp.dll - this reference has been left in place
                                --------------------
                                Key=ShellHWDetection
                                ServiceDLL=%SystemRoot%\System32\shsvcs.dll - this reference has been left in place
                                --------------------
                                Key=srservice
                                ServiceDLL=C:\WINDOWS\system32\srsvc.dll - this reference has been left in place
                                --------------------
                                Key=SSDPSRV
                                ServiceDLL=%SystemRoot%\System32\ssdpsrv.dll - this reference has been left in place
                                --------------------
                                Key=stisvc
                                ServiceDLL=%SystemRoot%\system32\wiaservc.dll - this reference has been left in place
                                --------------------
                                Key=TapiSrv
                                ServiceDLL=%SystemRoot%\System32\tapisrv.dll - this reference has been left in place
                                --------------------
                                Key=TermService
                                ServiceDLL=%SystemRoot%\System32\termsrv.dll - this reference has been left in place
                                --------------------
                                Key=Themes
                                ServiceDLL=%SystemRoot%\System32\shsvcs.dll - this reference has been left in place
                                --------------------
                                Key=TrkWks
                                ServiceDLL=%SystemRoot%\system32\trkwks.dll - this reference has been left in place
                                --------------------
                                Key=upnphost
                                ServiceDLL=%SystemRoot%\System32\upnphost.dll - this reference has been left in place
                                --------------------
                                Key=W32Time
                                ServiceDLL=C:\WINDOWS\system32\w32time.dll - this reference has been left in place
                                --------------------
                                Key=WebClient
                                ServiceDLL=%SystemRoot%\System32\webclnt.dll - this reference has been left in place
                                --------------------
                                Key=winmgmt
                                ServiceDLL=%SystemRoot%\system32\wbem\WMIsvc.dll - this reference has been left in place
                                --------------------
                                Key=WmdmPmSN
                                ServiceDLL=C:\WINDOWS\system32\MsPMSNSv.dll - this reference has been l
                                0
                                1. Salut
                                  ça peut servir comme rapport ...
                                  Reposte un log Hijack pour voir ...
                                  A+
                                  0
                                  1. Re
                                    AVG antispyware
                                    https://www.01net.com/telecharger/
                                    Tuto :
                                    https://www.pcparadise.fr

                                    ->Relance AVG AS -> "Analyse" ->"Paramètres"
                                    Sous la question "Comment réagir ?" :
                                    -> clique sur "Actions recommandées" et choisis "Quarantaines"
                                    -> Re-clique sur l'onglet "Analyse" puis réalise une "Analyse complète du système"

                                    Si un fichier est infecté en fin d'analyse
                                    ->Clique sur "Appliquer toutes les actions "
                                    ->Clique sur "Enregistrer le rapport" puis sur "Enregistrer le rapport sous".
                                    ->Enregistre ce fichier texte sur ton bureau ensuite colle le rapport

                                    A+
                                    0
                                    1. Voici pr Hijack :

                                      Logfile of Trend Micro HijackThis v2.0.2
                                      Scan saved at 18:15:49, on 15/02/2008
                                      Platform: Windows XP SP2 (WinNT 5.01.2600)
                                      MSIE: Internet Explorer v7.00 (7.00.6000.16608)
                                      Boot mode: Normal

                                      Running processes:
                                      C:\WINDOWS\System32\smss.exe
                                      C:\WINDOWS\system32\winlogon.exe
                                      C:\WINDOWS\system32\services.exe
                                      C:\WINDOWS\system32\lsass.exe
                                      C:\WINDOWS\system32\Ati2evxx.exe
                                      C:\WINDOWS\system32\svchost.exe
                                      C:\Program Files\Fichiers communs\iS3\Anti-Spyware\SZServer.exe
                                      C:\WINDOWS\System32\svchost.exe
                                      C:\WINDOWS\system32\Ati2evxx.exe
                                      C:\WINDOWS\Explorer.EXE
                                      C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                                      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                      C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                      C:\Program Files\STOPzilla!\STOPzilla.exe
                                      C:\WINDOWS\system32\spoolsv.exe
                                      C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                      C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
                                      C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                      C:\WINDOWS\system32\svchost.exe
                                      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                                      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                                      C:\Program Files\Java\jre1.5.0\bin\jusched.exe
                                      C:\Program Files\Orange HSS\Systray\SystrayApp.exe
                                      C:\WINDOWS\SOUNDMAN.EXE
                                      C:\Program Files\Winamp\winampa.exe
                                      C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                                      C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe
                                      C:\Program Files\iTunes\iTunesHelper.exe
                                      C:\WINDOWS\system32\ctfmon.exe
                                      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                                      C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
                                      C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
                                      C:\Program Files\Google\Google Updater\GoogleUpdater.exe
                                      C:\Program Files\SAGEM WiFi manager\WLANUTL.exe
                                      C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
                                      C:\Program Files\iPod\bin\iPodService.exe
                                      C:\WINDOWS\system32\wscntfy.exe
                                      C:\Program Files\Windows Live\Messenger\usnsvc.exe
                                      C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe
                                      C:\WINDOWS\System32\svchost.exe
                                      C:\Program Files\eChanblard\emule.exe
                                      C:\Program Files\Winamp\winamp.exe
                                      C:\Program Files\Internet Explorer\IEXPLORE.EXE
                                      C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
                                      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                                      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ustart.org
                                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ustart.org
                                      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                                      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                                      R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\Orange HSS\SearchURLHook\SearchPageURL.dll
                                      O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                                      O2 - BHO: SITEguard BHO - {1827766B-9F49-4854-8034-F6EE26FCB1EC} - C:\Program Files\STOPzilla!\SZSG.dll
                                      O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Documents and Settings\Mam's\Mes documents\BitComet\tools\BitCometBHO_1.2.1.2.dll
                                      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                                      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                                      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
                                      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
                                      O2 - BHO: STOPzilla Browser Helper Object - {E3215F20-3212-11D6-9F8B-00D0B743919D} - C:\Program Files\STOPzilla!\SZIEBHO.dll
                                      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
                                      O3 - Toolbar: STOPzilla - {98828DED-A591-462F-83BA-D2F62A68B8B8} - C:\Program Files\STOPzilla!\SZSG.dll
                                      O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0\bin\jusched.exe
                                      O4 - HKLM\..\Run: [SystrayORAHSS] "C:\Program Files\Orange HSS\Systray\SystrayApp.exe"
                                      O4 - HKLM\..\Run: [ORAHSSSessionManager] C:\Program Files\Orange HSS\SessionManager\SessionManager.exe
                                      O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
                                      O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
                                      O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
                                      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                                      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                                      O4 - HKLM\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
                                      O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
                                      O4 - HKLM\..\Run: [TrojanScanner] C:\Program Files\Trojan Remover\Trjscan.exe
                                      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                                      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                                      O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                                      O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                                      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                                      O4 - HKCU\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
                                      O4 - HKCU\..\Run: [BitComet] "C:\Documents and Settings\Mam's\Mes documents\BitComet\BitComet.exe" /tray
                                      O4 - HKCU\..\Run: [AdobeUpdater] C:\Program Files\Fichiers communs\Adobe\Updater5\AdobeUpdater.exe
                                      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                                      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                                      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                                      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                                      O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
                                      O4 - Global Startup: Utilitaire réseau pour SAGEM Wi-Fi 11g USB adapter.lnk = ?
                                      O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Documents and Settings\Mam's\Mes documents\BitComet\BitComet.exe/AddLink.htm
                                      O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Documents and Settings\Mam's\Mes documents\BitComet\BitComet.exe/AddVideo.htm
                                      O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Documents and Settings\Mam's\Mes documents\BitComet\BitComet.exe/AddAllLink.htm
                                      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
                                      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
                                      O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                                      O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                                      O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Documents and Settings\Mam's\Mes documents\BitComet\tools\BitCometBHO_1.2.1.2.dll/206 (file missing)
                                      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                                      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                                      O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
                                      O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
                                      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                      O10 - Unknown file in Winsock LSP: c:\program files\fichiers communs\is3\anti-spyware\is3lsp.dll
                                      O10 - Unknown file in Winsock LSP: c:\program files\fichiers communs\is3\anti-spyware\is3lsp.dll
                                      O10 - Unknown file in Winsock LSP: c:\program files\fichiers communs\is3\anti-spyware\is3lsp.dll
                                      O10 - Unknown file in Winsock LSP: c:\program files\fichiers communs\is3\anti-spyware\is3lsp.dll
                                      O10 - Unknown file in Winsock LSP: c:\program files\fichiers communs\is3\anti-spyware\is3lsp.dll
                                      O10 - Unknown file in Winsock LSP: c:\program files\fichiers communs\is3\anti-spyware\is3lsp.dll
                                      O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
                                      O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
                                      O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - http://charon777.free.fr/plugins/hardwaredetection_2_0_4_12.cab
                                      O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                                      O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                      O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                                      O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
                                      O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                      O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                                      O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                                      O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
                                      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
                                      O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                                      O23 - Service: STOPzilla Service (szserver) - iS3, Inc. - C:\Program Files\Fichiers communs\iS3\Anti-Spyware\SZServer.exe
                                      0
                                      • 1
                                      • 2