Probleme avast "message suspect"

Bonjour à tous,
je commence à regarder les forums sur ce sujet car je n'arrive pas a régler mon soucis, jai' fait une image de mon disque dur que je viens de réinstaller et à ma grande surprise des "messages suspects" d'avast apparaissent sur mon bureau, j'ai également il y a qqes semaines le compte a rebours autorite NT system (j ai du modifier l heure de mon horloge pour eviter le rebootage: comment peut on avoir ce probleme avec XP SP3 d'installer???!!!)

bref je vous contacte pour l autre probleme "message suspect" j'ai utiliser ad-aware, spybot, avast et je ne trouve absolument rien d anormal, d'ou vient ce probleme ? de messenger? j'ai meme recréer un nouveau compte hotmail et toujours le meme probleme.

et cela ralenti également l ouverture de mes fentres d internet explorer

pourriez vous m'assister sur ce sujet?
merci d'avance
Configuration: Windows XP SP3
Internet Explorer 7.0
avast free edition
zone alarm
spybot

23 réponses

Résumé de la discussion

Des alertes suspectes liées à Avast apparaissent après réinstallation et un compte à rebours NT AUTHORITY NT SYSTEM est évoqué, suscitant des doutes sur une infection sur Windows XP SP3. Plusieurs outils antivirus et antispyware ont été testés — Ad-Aware, Spybot, Avast et ZoneAlarm — mais les résultats restent mitigés, avec des rapports HijackThis révélant de nombreuses entrées de démarrage. Des analyses complémentaires ont donné des pistes variées, mentionnant des éléments suspects ou des composants gravitant autour d’outils comme MSNFix et ComboFix, sans consensus clair sur une désinfection complète. Certains éléments des logs et des analyses restent à interpréter et indiquent qu’une correction plus poussée ou une réinstallation propre pourrait être nécessaire pour stabiliser durablement le système.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    slt le compte a rebours peut venir d'une infection ou d'un conflit logiciel ou materiel

    avais tu mis le sp3 avant d'aller sur le net ou est tu allé avec windows non proteger pour teleharger le sp3? si c'est le deuxieme cas alors tu as pu etre infecté avant l'installation du sp3

    si tu viens de mettre un nouveau materiel ou logiciel vire le pour voir si cela persiste

    sinon pour voir si infécté:

    colle un rapport hijackthis

    http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis/download

    manuel :

    https://leblogdeclaude.blogspot.com/2006/10/informatique-section-hijackthis.html

    Je conseille de renomer Hijackthis, pour contrer une éventuelle infection de Vundo.

    ex:Renomme le fichier HijackThis.exe en eden.exe pour cela, fais un clic droit sur le fichier HijackThis.exe et choisis renommer dans la liste

    Ensuite avec Explorer créer un dossier c:\hijackthis
    Décompresser Hijackthis dans ce dossier.
    C'est important pour les sauvegardes."
    0
    1. merci beaucoup pour ta réponse aussi rapide, en fait après avoir réinstaller l image de mon disque dur je n'ai plus ce compte a rebours, mais en fait le PC est tout neuf , je l'ai fait monté a mongallet et il fonctionne très bien à part ces 2 ptits soucis.

      bon je fais ce que tu me dis dès que je finis le boulot mais pas avant 21h30.

      par contre le soucis des"messages suspect" c est beaucoup plus ennuyeux acutellement....

      tu as une idée?
      merci.
      0
  2. Contributeur sécurité
    je verrai plus avec hijackhtis, ton image etait peut etre infectée!

    et si pas dispo colle aussi un scan en ligne:

    bitdefender en ligne :
    http://www.bitdefender.fr/scan_fr/scan8/ie.html

    Panda en ligne :
    http://pandasoftware.fr
    0
    1. ok je fais ça ce soir, je colle le scan hijackthis + panda
      merci
      0
  3. Contributeur sécurité
    ok désactive avast le temps de faire le scan en ligne
    0
    1. ok , j ai désactivé avast zone alarm + spybot,
      voici en premier le rapport hijackthis, si tu es encore la ça te laisse le temps de regarder ça pendant que je prépare l analyse avec panda:

      Logfile of HijackThis v1.99.1
      Scan saved at 17:44:20, on 15/07/2008
      Platform: Windows XP SP3 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.16674)

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\ZoneLabs\vsmon.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      C:\Program Files\Alwil Software\Avast4\ashServ.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\ASUS\GamerOSD\GamerOSD.exe
      C:\WINDOWS\RTHDCPL.EXE
      C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      C:\WINDOWS\system32\RUNDLL32.EXE
      C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
      C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
      C:\Program Files\Fichiers communs\Acronis\Schedule2\schedhlp.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
      C:\Program Files\Fichiers communs\Acronis\Schedule2\schedul2.exe
      C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      C:\WINDOWS\ATKKBService.exe
      C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
      C:\WINDOWS\system32\nvsvc32.exe
      C:\Program Files\Spyware Terminator\sp_rsser.exe
      C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
      C:\Program Files\Fichiers communs\Acronis\Fomatik\TrueImageTryStartService.exe
      C:\WINDOWS\system32\wscntfy.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
      C:\Program Files\Hijackthis Version Française\VERSION TRADUITE ORIGINALE.EXE

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
      O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
      O4 - HKLM\..\Run: [ASUSGamerOSD] C:\Program Files\ASUS\GamerOSD\GamerOSD.exe
      O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
      O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
      O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\WINDOWS\RaidTool\xInsIDE.exe
      O4 - HKLM\..\Run: [36X Raid Configurer] C:\WINDOWS\system32\xRaidSetup.exe boot
      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
      O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
      O4 - HKLM\..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
      O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
      O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Fichiers communs\Acronis\Schedule2\schedhlp.exe"
      O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
      O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.1_01\bin\npjpi141_01.dll
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.1_01\bin\npjpi141_01.dll
      O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
      O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O11 - Options group: [INTERNATIONAL] International*
      O14 - IERESET.INF: START_PAGE_URL=https://www.free.fr/freebox/index.html
      O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
      O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
      O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
      O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)
      O20 - Winlogon Notify: dsauth32 - C:\WINDOWS\SYSTEM32\dsauth32.dll
      O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
      O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Fichiers communs\Acronis\Schedule2\schedul2.exe
      O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
      O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
      O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
      O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
      O23 - Service: GhostStartService - Symantec Corporation - C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
      O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
      O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
      O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
      O23 - Service: Acronis Try And Decide Service (TryAndDecideService) - Unknown owner - C:\Program Files\Fichiers communs\Acronis\Fomatik\TrueImageTryStartService.exe
      O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
      0
  4. Contributeur sécurité
    ok

    tu as spyware terminator et spybot avec le tea timer! désactivel e tea timer de spybot sinon l'ordi va ramer

    _____________

    mets a jour java car ta version est obsolète

    ____________

    analyse ceci sur virus total et colle le rapport: https://www.virustotal.com/gui/
    C:\WINDOWS\SYSTEM32\dsauth32.dll

    _____________

    tu as ad aware 2007: la version 2008 est sortie...

    mais il serait préferable de le virer et de mettre malwarebyte's a la place , plus efficace et ne consommant pas de ressource hors pendant le scan:

    scan avec et vire ce qui est trouvé et colle le rapport:

    https://www.malekal.com/tutoriel-malwarebyte-anti-malware/
    0
    1. je viens de faire l anaylise rapide avec panda, voila le résultat, t en penses quoi?

      ;***********************************************************************************************************************************************************************************
      ANALYSIS: 2008-07-15 17:55:57
      PROTECTIONS: 1
      MALWARE: 11
      SUSPECTS: 0
      ;***********************************************************************************************************************************************************************************
      PROTECTIONS
      Description Version Active Updated
      ;===================================================================================================================================================================================
      Zone Alarm Security Suite 7.0.473.000 No No
      ;===================================================================================================================================================================================
      MALWARE
      Id Description Type Active Severity Disinfectable Disinfected Location
      ;===================================================================================================================================================================================
      00145405 Cookie/RealMedia TrackingCookie No 0 Yes No C:\Documents and Settings\reverend\Cookies\reverend@247realmedia[2].txt
      00167642 Cookie/Com.com TrackingCookie No 0 Yes No C:\Documents and Settings\reverend\Cookies\reverend@com[1].txt
      00167647 Cookie/Yadro TrackingCookie No 0 Yes No C:\Documents and Settings\reverend\Cookies\reverend@yadro[2].txt
      00167704 Cookie/Xiti TrackingCookie No 0 Yes No C:\Documents and Settings\reverend\Cookies\reverend@xiti[1].txt
      00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\reverend\Cookies\reverend@serving-sys[1].txt
      00168093 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\reverend\Cookies\reverend@bs.serving-sys[2].txt
      00168106 Cookie/Weborama TrackingCookie No 0 Yes No C:\Documents and Settings\reverend\Cookies\reverend@weborama[2].txt
      00168109 Cookie/Adtech TrackingCookie No 0 Yes No C:\Documents and Settings\reverend\Cookies\reverend@adtech[1].txt
      00168116 Cookie/Comclick TrackingCookie No 0 Yes No C:\Documents and Settings\reverend\Cookies\reverend@fl01.ct2.comclick[1].txt
      00170554 Cookie/Overture TrackingCookie No 0 Yes No C:\Documents and Settings\reverend\Cookies\reverend@overture[1].txt
      00273339 Cookie/Smartadserver TrackingCookie No 0 Yes No C:\Documents and Settings\reverend\Cookies\reverend@smartadserver[2].txt
      ;===================================================================================================================================================================================
      SUSPECTS
      Sent Location :
      ;===================================================================================================================================================================================
      ;===================================================================================================================================================================================
      VULNERABILITIES
      Id Severity Description :
      ;===================================================================================================================================================================================
      ;===================================================================================================================================================================================
      0
      1. Contributeur sécurité
        tu as spyware terminator et spybot avec le tea timer! désactivel e tea timer de spybot sinon l'ordi va ramer

        _____________

        mets a jour java car ta version est obsolète

        ____________

        analyse ceci sur virus total et colle le rapport: https://www.virustotal.com/gui/
        C:\WINDOWS\SYSTEM32\dsauth32.dll

        _____________

        tu as ad aware 2007: la version 2008 est sortie...

        mais il serait préferable de le virer et de mettre malwarebyte's a la place , plus efficace et ne consommant pas de ressource hors pendant le scan:

        scan avec et vire ce qui est trouvé et colle le rapport:

        https://www.malekal.com/tutoriel-malwarebyte-anti-malware/
        0
        1. ci dessous l analyse par virus total:

          Antivirus Version Dernière mise à jour Résultat
          AhnLab-V3 2008.7.11.0 2008.07.15 -
          AntiVir 7.8.0.68 2008.07.15 TR/Crypt.FKM.Gen
          Authentium 5.1.0.4 2008.07.15 -
          Avast 4.8.1195.0 2008.07.15 -
          AVG 7.5.0.516 2008.07.15 -
          BitDefender 7.2 2008.07.15 Trojan.Crypt.EN
          CAT-QuickHeal 9.50 2008.07.14 -
          ClamAV 0.93.1 2008.07.15 -
          DrWeb 4.44.0.09170 2008.07.15 -
          eSafe 7.0.17.0 2008.07.14 Suspicious File
          eTrust-Vet 31.6.5956 2008.07.15 -
          Ewido 4.0 2008.07.15 -
          F-Prot 4.4.4.56 2008.07.14 -
          F-Secure 7.60.13501.0 2008.07.15 -
          Fortinet 3.14.0.0 2008.07.15 -
          GData 2.0.7306.1023 2008.07.15 -
          Ikarus T3.1.1.26.0 2008.07.15 -
          Kaspersky 7.0.0.125 2008.07.15 -
          McAfee 5338 2008.07.14 -
          Microsoft 1.3704 2008.07.15 -
          NOD32v2 3269 2008.07.15 -
          Norman 5.80.02 2008.07.15 -
          Panda 9.0.0.4 2008.07.14 -
          Prevx1 V2 2008.07.15 -
          Rising 20.53.12.00 2008.07.15 -
          Sophos 4.31.0 2008.07.15 Sus/Behav-1021
          Sunbelt 3.1.1536.1 2008.07.15 -
          Symantec 10 2008.07.15 -
          TheHacker 6.2.96.379 2008.07.14 -
          TrendMicro 8.700.0.1004 2008.07.15 -
          VBA32 3.12.8.0 2008.07.15 -
          VirusBuster 4.5.11.0 2008.07.15 -
          Webwasher-Gateway 6.6.2 2008.07.15 Trojan.Crypt.FKM.Gen
          Information additionnelle
          File size: 11264 bytes
          MD5...: c901dbc851e111decf8a1f961383c971
          SHA1..: 9fb8c713bacfdaa4803b3564c2451db1ead07a67
          SHA256: abc415fa5390a4563c4a4effa9d69a12c94df435e1e1dbc8295c678f2609db91
          SHA512: f97001bae2801a07c1554fd5d1fe83520765aae4f9865c6d278610aa32252b7e
          2d6833be391a8c3dd17f6cf1bdf849e3d34aefec061b1278fe057d1b156ec055
          PEiD..: -
          PEInfo: PE Structure information

          ( base data )
          entrypointaddress.: 0x1000af00
          timedatestamp.....: 0x480cab41 (Mon Apr 21 14:57:05 2008)
          machinetype.......: 0x14c (I386)

          ( 3 sections )
          name viradd virsiz rawdsiz ntrpy md5
          UPX0 0x1000 0x8000 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e
          UPX1 0x9000 0x3000 0x2200 7.78 f9c3fe9b1720694ab6cf106aa97dd2a1
          .rsrc 0xc000 0x1000 0x600 2.82 368fec73d1edc74ab746e9d7354d12ef

          ( 1 imports )
          > KERNEL32.DLL: LoadLibraryA, GetProcAddress, VirtualProtect, VirtualAlloc, VirtualFree

          ( 1 exports )
          ulyd

          packers (F-Prot): UPX
          packers (Kaspersky): PE_Patch.UPX, UPX
          0
          1. Contributeur sécurité
            ok

            scan avec malwarebyte's: et vire ce qui est trouvé et colle le rapport:

            https://www.malekal.com/tutoriel-malwarebyte-anti-malware/

            _________________

            Télécharge Combofix de sUBs : Renomme le avant toute installation, par exemple, nomme le "KillBagle". aide ici : https://forum.pcastuces.com/sujet.asp?f=25&s=37315

            http://download.bleepingcomputer.com/sUBs/ComboFix.exe
            Sauvegarde le sur ton bureau et pas ailleurs !

            Aide à l’utilisation de combofix ici: http://bibou0007.forumpro.fr/tutos-f45/tutorial-combofix-t12­1.htm

            Double-clic sur combofix, Il va te poser une question, réponds par la touche 1 et entrée pour valider, laisse toi guider.
            Attends que combofix ait terminé, un rapport sera créé. Poste le rapport.

            ____________________

            recolle un nouvel hijackhtis et dis tes soucis
            0
            1. le rapport du dernier lien que t as envoyé:

              Malwarebytes' Anti-Malware 1.20
              Version de la base de données: 953
              Windows 5.1.2600 Service Pack 3

              18:15:10 15/07/2008
              mbam-log-7-15-2008 (18-15-10).txt

              Type de recherche: Examen rapide
              Eléments examinés: 42481
              Temps écoulé: 1 minute(s), 26 second(s)

              Processus mémoire infecté(s): 0
              Module(s) mémoire infecté(s): 0
              Clé(s) du Registre infectée(s): 0
              Valeur(s) du Registre infectée(s): 0
              Elément(s) de données du Registre infecté(s): 0
              Dossier(s) infecté(s): 0
              Fichier(s) infecté(s): 0

              Processus mémoire infecté(s):
              (Aucun élément nuisible détecté)

              Module(s) mémoire infecté(s):
              (Aucun élément nuisible détecté)

              Clé(s) du Registre infectée(s):
              (Aucun élément nuisible détecté)

              Valeur(s) du Registre infectée(s):
              (Aucun élément nuisible détecté)

              Elément(s) de données du Registre infecté(s):
              (Aucun élément nuisible détecté)

              Dossier(s) infecté(s):
              (Aucun élément nuisible détecté)

              Fichier(s) infecté(s):
              (Aucun élément nuisible détecté)

              il voit rien.....
              0
              1. Contributeur sécurité
                il faut faire un scan complet avec malwarebyte's et pas un rapide

                puis

                Télécharge Combofix de sUBs : Renomme le avant toute installation, par exemple, nomme le "KillBagle". aide ici : https://forum.pcastuces.com/sujet.asp?f=25&s=37315

                http://download.bleepingcomputer.com/sUBs/ComboFix.exe
                Sauvegarde le sur ton bureau et pas ailleurs !

                Aide à l’utilisation de combofix ici: http://bibou0007.forumpro.fr/tutos-f45/tutorial-combofix-t12­­1.htm

                Double-clic sur combofix, Il va te poser une question, réponds par la touche 1 et entrée pour valider, laisse toi guider.
                Attends que combofix ait terminé, un rapport sera créé. Poste le rapport.

                ____________________

                recolle un nouvel hijackhtis et dis tes soucis
                0
                1. voila le rapport combofix, spybot s'était déclenché après le rebootage mais je l'ai désactivé.pour info l'affichage des pages internet rame acutellemebnt, c est du a cette merde?

                  ComboFix 08-07-14.2 - reverend 2008-07-15 18:30:37.2 - NTFSx86
                  Microsoft Windows XP Professionnel 5.1.2600.3.1252.1.1036.18.1580 [GMT 2:00]
                  Endroit: C:\Documents and Settings\reverend\Bureau\garda.exe

                  [color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/b][/color]
                  .

                  (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
                  .
                  .
                  ---- Previous Run -------
                  .
                  C:\WINDOWS\system32\MSINET.oca

                  .
                  ((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-06-15 to 2008-07-15 ))))))))))))))))))))))))))))))))))))
                  .

                  2008-07-15 18:10 . 2008-07-15 18:10 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
                  2008-07-15 18:10 . 2008-07-15 18:10 <REP> d-------- C:\Documents and Settings\reverend\Application Data\Malwarebytes
                  2008-07-15 18:10 . 2008-07-15 18:10 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
                  2008-07-15 18:10 . 2008-07-07 17:35 34,296 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
                  2008-07-15 18:10 . 2008-07-07 17:35 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys
                  2008-07-15 17:51 . 2008-07-15 17:51 <REP> d-------- C:\Program Files\Panda Security
                  2008-07-15 17:51 . 2008-06-19 17:24 28,544 --a------ C:\WINDOWS\system32\drivers\pavboot.sys
                  2008-07-15 17:39 . 2008-07-15 17:46 <REP> d-------- C:\Program Files\Hijackthis Version Fran‡aise
                  2008-07-15 08:08 . 2008-07-15 08:08 <REP> d-------- C:\Games
                  2008-07-14 22:58 . 2008-07-14 22:58 268 --ah----- C:\sqmdata02.sqm
                  2008-07-14 22:58 . 2008-07-14 22:58 244 --ah----- C:\sqmnoopt02.sqm
                  2008-07-14 22:48 . 2008-07-15 18:22 <REP> d-------- C:\Documents and Settings\reverend\Bureau
                  2008-07-14 22:47 . 2008-07-14 22:47 268 --ah----- C:\sqmdata01.sqm
                  2008-07-14 22:47 . 2008-07-14 22:47 244 --ah----- C:\sqmnoopt01.sqm
                  2008-07-14 22:08 . 2008-06-14 19:33 272,768 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
                  2008-07-14 22:02 . 2008-05-08 16:02 203,136 -----c--- C:\WINDOWS\system32\dllcache\rmcast.sys
                  2008-07-14 22:01 . 2008-07-15 08:22 <REP> d-------- C:\Program Files\Spyware Terminator
                  2008-07-14 22:01 . 2008-07-14 22:02 <REP> d-------- C:\Program Files\Spybot - Search & Destroy
                  2008-07-14 22:01 . 2008-07-15 08:22 <REP> d-------- C:\Documents and Settings\reverend\Application Data\Spyware Terminator
                  2008-07-14 22:01 . 2008-07-14 22:16 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Spyware Terminator
                  2008-07-14 22:01 . 2008-07-14 22:16 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
                  2008-07-14 22:01 . 2008-07-14 22:01 141,312 --a------ C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
                  2008-07-14 20:24 . 2008-07-14 20:24 <REP> d-------- C:\Documents and Settings\All Users\Application Data\nView_Profiles

                  .
                  (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                  .
                  2008-07-15 16:32 43,244 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
                  2008-07-15 16:32 4,130,848 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
                  2008-07-15 16:10 --------- d-----w C:\Program Files\Lavasoft
                  2008-07-15 15:46 --------- d-----w C:\Program Files\Hijackthis Version Française
                  2008-07-15 11:41 196,608 ----a-w C:\WINDOWS\system32\drivers\nStandard.bin
                  2008-07-15 06:08 0 ----a-w C:\Program Files\Installed.hid
                  2008-07-14 20:03 --------- d-----w C:\Documents and Settings\reverend\Application Data\Lavasoft
                  2008-06-14 17:33 272,768 ------w C:\WINDOWS\system32\drivers\bthport.sys
                  2008-05-31 15:33 2,893,312 ----a-w C:\WINDOWS\Internet Logs\xDB2.tmp
                  2008-05-31 15:33 1,420,288 ----a-w C:\WINDOWS\Internet Logs\xDB3.tmp
                  2008-05-31 15:29 --------- d-----w C:\Documents and Settings\LocalService\Application Data\Acronis
                  2008-05-31 15:27 --------- d-----w C:\Program Files\PowerQuest
                  2008-05-31 15:26 441,760 ----a-w C:\WINDOWS\system32\drivers\timntr.sys
                  2008-05-31 15:26 44,384 ----a-w C:\WINDOWS\system32\drivers\tifsfilt.sys
                  2008-05-31 15:26 368,736 ----a-w C:\WINDOWS\system32\drivers\tdrpman.sys
                  2008-05-31 15:26 129,248 ----a-w C:\WINDOWS\system32\drivers\snapman.sys
                  2008-05-31 15:26 --------- d-----w C:\Program Files\Fichiers communs\Acronis
                  2008-05-31 15:26 --------- d-----w C:\Documents and Settings\All Users\Application Data\Acronis
                  2008-05-31 15:25 --------- d-----w C:\Program Files\Acronis
                  2008-05-31 15:23 --------- d-----w C:\Program Files\Fichiers communs\Adobe
                  2008-05-31 15:22 --------- d--h--w C:\Program Files\InstallShield Installation Information
                  2008-05-31 15:19 --------- d-----w C:\Documents and Settings\All Users\Application Data\PowerQuest
                  2008-05-31 09:21 27,262,976 ----a-w C:\VIRTPART.DAT
                  2008-05-31 08:14 1,425,408 ----a-w C:\WINDOWS\Internet Logs\xDB1.tmp
                  2008-05-31 07:54 --------- d-----w C:\Documents and Settings\All Users\Application Data\PokerAcademyPro2
                  2008-05-31 07:50 --------- d-----w C:\Documents and Settings\reverend\Application Data\PokerAcademyPro2
                  2008-05-31 07:04 --------- d-----w C:\Documents and Settings\reverend\Application Data\GrabIt
                  2008-05-30 22:22 --------- d-----w C:\Program Files\Ubisoft
                  2008-05-30 21:54 43,520 ----a-w C:\WINDOWS\system32\CmdLineExt03.dll
                  2008-05-30 21:34 --------- d-----w C:\Documents and Settings\reverend\Application Data\InterTrust
                  2008-05-30 21:26 --------- d-----w C:\Program Files\Alcohol Soft
                  2008-05-30 21:08 737,280 ----a-w C:\WINDOWS\iun6002.exe
                  2008-05-30 20:19 --------- d-----w C:\Program Files\QuickPar
                  2008-05-30 20:18 --------- d-----w C:\Program Files\GrabIt
                  2008-05-30 20:13 715,248 ----a-w C:\WINDOWS\system32\drivers\sptd.sys
                  2008-05-30 19:20 --------- d-----w C:\Program Files\Symantec
                  2008-05-30 19:20 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
                  2008-05-30 19:19 --------- d-----w C:\Program Files\Fichiers communs\Symantec Shared
                  2008-05-30 19:19 --------- d-----w C:\Documents and Settings\reverend\Application Data\Symantec
                  2008-05-30 19:15 --------- d-----w C:\Program Files\Google
                  2008-05-30 18:42 --------- d-----w C:\Program Files\Windows Live
                  2008-05-30 18:41 --------- dcsh--w C:\Program Files\Fichiers communs\WindowsLiveInstaller
                  2008-05-30 18:38 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
                  2008-05-30 18:37 --------- d-----w C:\Documents and Settings\All Users\Application Data\MailFrontier
                  2008-05-30 15:29 --------- d-----w C:\Program Files\Zone Labs
                  2008-05-30 15:28 --------- d-----w C:\Program Files\SLD Codec Pack
                  2008-05-30 15:27 --------- d-----w C:\Program Files\Jasc Software Inc
                  2008-05-30 15:27 --------- d-----w C:\Program Files\Fichiers communs\Jasc Software Inc
                  2008-05-30 15:27 --------- d-----w C:\Program Files\Fichiers communs\InstallShield
                  2008-05-30 15:27 --------- d-----w C:\Documents and Settings\reverend\Application Data\Jasc Software Inc
                  2008-05-30 15:27 --------- d-----w C:\Documents and Settings\All Users\Application Data\InstallShield
                  2008-05-30 15:22 --------- d-----w C:\Program Files\Java Web Start
                  2008-05-30 15:22 --------- d-----w C:\Program Files\Java
                  2008-05-30 15:21 --------- d-----w C:\Program Files\Free.fr
                  2008-05-30 15:06 --------- d-----w C:\Program Files\Winamp
                  2008-05-30 15:04 --------- d-----w C:\Program Files\QuickTime
                  2008-05-30 15:04 --------- d-----w C:\Program Files\iTunes
                  2008-05-30 15:04 --------- d-----w C:\Program Files\iPod
                  2008-05-30 15:04 --------- d-----w C:\Documents and Settings\reverend\Application Data\Apple Computer
                  2008-05-30 15:04 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
                  2008-05-30 15:03 --------- d-----w C:\Program Files\Fichiers communs\Apple
                  2008-05-30 15:03 --------- d-----w C:\Program Files\Apple Software Update
                  2008-05-30 15:03 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple
                  2008-05-30 15:02 --------- d-----w C:\Program Files\RamBoost XP
                  2008-05-30 15:02 --------- d-----w C:\Program Files\Easy CD-DA Extractor 10
                  2008-05-30 15:01 --------- d-----w C:\Program Files\Alwil Software
                  2008-05-30 15:00 --------- d-----w C:\Program Files\VideoLAN
                  2008-05-30 15:00 --------- d-----w C:\Documents and Settings\reverend\Application Data\vlc
                  2008-05-30 14:47 --------- d-----w C:\Program Files\Attansic
                  2008-05-30 14:44 315,392 ----a-w C:\WINDOWS\HideWin.exe
                  2008-05-30 14:44 --------- d-----w C:\Program Files\Realtek
                  2008-05-30 14:37 --------- d-----w C:\Program Files\Intel
                  2008-05-30 14:34 12,288 ----a-w C:\WINDOWS\system32\drivers\EIO64_xp.sys
                  2008-05-30 14:34 --------- d-----w C:\Program Files\ASUS
                  2008-05-30 12:36 --------- d-----w C:\Program Files\microsoft frontpage
                  2008-05-30 12:34 --------- d-----w C:\Program Files\Services en ligne
                  2008-05-09 10:55 90,112 ----a-w C:\WINDOWS\system32\wshext.dll
                  2008-05-09 10:55 430,080 ----a-w C:\WINDOWS\system32\vbscript.dll
                  2008-05-09 10:55 180,224 ----a-w C:\WINDOWS\system32\scrobj.dll
                  2008-05-09 10:55 172,032 ----a-w C:\WINDOWS\system32\scrrun.dll
                  2008-05-08 11:24 155,648 ----a-w C:\WINDOWS\system32\wscript.exe
                  2008-05-07 09:07 135,168 ----a-w C:\WINDOWS\system32\cscript.exe
                  2008-05-07 05:11 1,294,336 ----a-w C:\WINDOWS\system32\quartz.dll
                  2008-04-30 15:27 442,368 ----a-w C:\WINDOWS\system32\NVUNINST.EXE
                  2008-04-23 04:16 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
                  2006-06-23 22:48 32,768 ----a-r C:\WINDOWS\inf\UpdateUSB.exe
                  .

                  ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
                  .
                  .
                  REGEDIT4
                  *Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s

                  [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                  "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 04:33 15360]
                  "msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 11:34 5724184]
                  "SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                  "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2008-05-03 05:46 13529088]
                  "ASUSGamerOSD"="C:\Program Files\ASUS\GamerOSD\GamerOSD.exe" [2007-10-23 17:48 380928]
                  "JMB36X IDE Setup"="C:\WINDOWS\RaidTool\xInsIDE.exe" [2007-03-20 16:36 36864]
                  "36X Raid Configurer"="C:\WINDOWS\system32\xRaidSetup.exe" [2007-03-21 18:23 1953792]
                  "ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-04-02 21:07 919016]
                  "NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2008-05-03 05:46 86016]
                  "TrueImageMonitor.exe"="C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe" [2007-10-07 17:01 2620336]
                  "AcronisTimounterMonitor"="C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe" [2007-10-07 17:36 904880]
                  "Acronis Scheduler2 Service"="C:\Program Files\Fichiers communs\Acronis\Schedule2\schedhlp.exe" [2007-10-07 17:08 140568]
                  "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-11-14 23:43 286720]
                  "nwiz"="nwiz.exe" [2008-05-03 05:46 1630208 C:\WINDOWS\system32\nwiz.exe]
                  "RTHDCPL"="RTHDCPL.EXE" [2007-03-21 16:49 16126464 C:\WINDOWS\RTHDCPL.exe]

                  [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
                  "CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2008-04-14 04:33 15360]

                  [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\dsauth32]
                  2004-05-31 11:54 11264 C:\WINDOWS\system32\dsauth32.dll

                  [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
                  "msacm.l3acm"= l3codecp.acm
                  "vidc.asv2"= asusasv2.dll

                  [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
                  Authentication Packages REG_MULTI_SZ msv1_0 relog_ap

                  [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
                  @=""

                  [HKLM\~\startupfolder\C:^Documents and Settings^reverend^Menu Démarrer^Programmes^Démarrage^Ubisoft register.lnk]
                  path=C:\Documents and Settings\reverend\Menu Démarrer\Programmes\Démarrage\Ubisoft register.lnk
                  backup=C:\WINDOWS\pss\Ubisoft register.lnkStartup

                  [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcoholAutomount]
                  --a------ 2007-12-22 09:20 222080 C:\Program Files\Alcohol Soft\Alcohol 120\AxCmd.exe

                  [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUS SmartDoctor]
                  --a------ 2008-01-22 11:52 1126400 C:\Program Files\ASUS\SmartDoctor\SmartDoctor.exe

                  [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
                  --a------ 2007-11-15 13:11 267048 C:\Program Files\iTunes\iTunesHelper.exe

                  [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
                  --a------ 2007-10-18 11:34 5724184 C:\Program Files\Windows Live\Messenger\msnmsgr.exe

                  [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
                  --a------ 2007-11-14 23:43 286720 C:\Program Files\QuickTime\QTTask.exe

                  [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
                  "DisableMonitoring"=dword:00000001

                  [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
                  "EnableFirewall"= 0 (0x0)

                  [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
                  "%windir%\\system32\\sessmgr.exe"=
                  "C:\\Program Files\\iTunes\\iTunes.exe"=
                  "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
                  "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
                  "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=

                  [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
                  "7423:TCP"= 7423:TCP:messenger
                  "2831:TCP"= 2831:TCP:messenger

                  R0 pavboot;pavboot;C:\WINDOWS\system32\drivers\pavboot.sys [2008-06-19 17:24]
                  R0 tdrpman;Acronis Try&Decide and Restore Points filter;C:\WINDOWS\system32\DRIVERS\tdrpman.sys [2008-05-31 17:26]
                  R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-05-16 01:20]
                  R1 EIO_XP;EIO_XP;C:\WINDOWS\system32\drivers\EIO_XP.sys [2006-06-14 13:44]
                  R1 GhPciScan;GhostPciScanner;C:\Program Files\Symantec\Norton Ghost 2003\ghpciscan.sys [2002-08-14 15:11]
                  R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-05-16 01:16]
                  R2 TryAndDecideService;Acronis Try And Decide Service;C:\Program Files\Fichiers communs\Acronis\Fomatik\TrueImageTryStartService.exe [2007-10-08 11:19]
                  R3 asusgsb;ASUS Virtual Video Capture Device Driver;C:\WINDOWS\system32\drivers\asusgsb.sys [2007-10-23 17:48]
                  R3 ASUSVRC;ASUSTeK Virtual Capture Device;C:\WINDOWS\system32\DRIVERS\AsusVRC.sys [2007-01-29 17:12]
                  R3 AtcL001;NDIS Miniport Driver for Attansic L1 Gigabit Ethernet Controller;C:\WINDOWS\system32\DRIVERS\atl01_xp.sys [2007-03-15 16:12]
                  R3 Video3D;ASUS Video3D Service;C:\WINDOWS\system32\Drivers\Video3D32.sys [2007-10-23 17:48]

                  .
                  **************************************************************************

                  catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                  Rootkit scan 2008-07-15 18:33:38
                  Windows 5.1.2600 Service Pack 3 NTFS

                  Balayage processus cach‚s ...

                  Balayage cach‚ autostart entries ...

                  Balayage des fichiers cach‚s ...

                  C:\Documents and Settings\reverend\Local Settings\temp\WERdebb.dir00
                  C:\garda\notifykeys.dat
                  C:\garda\temp01
                  C:\garda\wlgn.dat

                  Scan termin‚ avec succŠs
                  Les fichiers cach‚s: 4

                  **************************************************************************
                  .
                  ------------------------ Other Running Processes ------------------------
                  .
                  C:\WINDOWS\system32\ZoneLabs\vsmon.exe
                  C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                  C:\Program Files\Alwil Software\Avast4\ashServ.exe
                  C:\WINDOWS\system32\rundll32.exe
                  C:\Program Files\Fichiers communs\Acronis\Schedule2\schedul2.exe
                  C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                  C:\WINDOWS\ATKKBService.exe
                  C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
                  C:\WINDOWS\system32\nvsvc32.exe
                  C:\Program Files\Spyware Terminator\sp_rsser.exe
                  C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
                  C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                  C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                  .
                  **************************************************************************
                  .
                  Temps d'accomplissement: 2008-07-15 18:36:33 - machine was rebooted [reverend]
                  ComboFix-quarantined-files.txt 2008-07-15 16:35:49

                  Pre-Run: 85,301,985,280 octets libres
                  Post-Run: 85,275,209,728 octets libres

                  235 --- E O F --- 2008-07-15 05:54:44
                  0
                  1. Contributeur sécurité
                    désactive le tea timer de spybot car tu as déjà spyware terminator qui fais l'analyse en temps réel:

                    dans spybot va: MODE puis MODE AVANCE puis OUTILS puis RESIDENT

                    _____________

                    Ferme tout tes navigateurs (donc copie ou imprime les instructions avant)

                    Crée un nouveau document texte : clic droit de souris sur le bureau > Nouveau > Document Texte, et copie dedans les lignes suivantes :

                    File::
                    C:\WINDOWS\system32\dsauth32.dll

                    Registry::
                    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\dsauth32]

                    Enregistre ce fichier sous le nom CFscript

                    Fait un glisser/déposer de ce fichier CFscrïpt sur le fichier ComboFix.exe

                    Clique sur le fichier CFScript, maintient le doigt enfoncé et glisse la souris pour que l'icône du CFScript vienne recouvrir l'icône de Combofix. Relache la souris. Combofix va démarrer.

                    Une fenêtre bleue va apparaître: au message qui apparaît ( Type 1 to continue, or 2 to abort) , tape 1 puis valide.

                    Patiente le temps du scan.Le bureau va disparaître à plusieurs reprises: c'est normal!

                    Ne touche à rien tant que le scan n'est pas terminé.

                    Une fois le scan achevé, un rapport va s'afficher: poste son contenu.

                    Remets aussi un rapport Hijackthis et dis tes soucis

                    Si le fichier ne s'ouvre pas, il se trouve ici > C:\ComboFix.txt
                    0
                    1. le fichier s est ouvert, par contre la connexion internet est beaucoup plus rapide, c est du a quoi?

                      ComboFix 08-07-14.2 - reverend 2008-07-15 19:31:28.3 - NTFSx86
                      Microsoft Windows XP Professionnel 5.1.2600.3.1252.1.1036.18.1583 [GMT 2:00]
                      Endroit: C:\Documents and Settings\reverend\Bureau\garda.exe
                      Command switches used :: C:\Documents and Settings\reverend\Bureau\CFscript.txt
                      * Création d'un nouveau point de restauration

                      [color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/b][/color]

                      FILE ::
                      C:\WINDOWS\system32\dsauth32.dll
                      .

                      (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
                      .

                      C:\WINDOWS\system32\dsauth32.dll

                      .
                      ((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-06-15 to 2008-07-15 ))))))))))))))))))))))))))))))))))))
                      .

                      2008-07-15 19:09 . 2008-07-15 19:09 <REP> d-------- C:\WINDOWS\ERUNT
                      2008-07-15 18:10 . 2008-07-15 18:10 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
                      2008-07-15 18:10 . 2008-07-15 18:10 <REP> d-------- C:\Documents and Settings\reverend\Application Data\Malwarebytes
                      2008-07-15 18:10 . 2008-07-15 18:10 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
                      2008-07-15 18:10 . 2008-07-07 17:35 34,296 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
                      2008-07-15 18:10 . 2008-07-07 17:35 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys
                      2008-07-15 17:51 . 2008-07-15 17:51 <REP> d-------- C:\Program Files\Panda Security
                      2008-07-15 17:51 . 2008-06-19 17:24 28,544 --a------ C:\WINDOWS\system32\drivers\pavboot.sys
                      2008-07-15 17:39 . 2008-07-15 17:46 <REP> d-------- C:\Program Files\Hijackthis Version Fran‡aise
                      2008-07-15 08:08 . 2008-07-15 08:08 <REP> d-------- C:\Games
                      2008-07-14 22:58 . 2008-07-14 22:58 268 --ah----- C:\sqmdata02.sqm
                      2008-07-14 22:58 . 2008-07-14 22:58 244 --ah----- C:\sqmnoopt02.sqm
                      2008-07-14 22:48 . 2008-07-15 19:31 <REP> d-------- C:\Documents and Settings\reverend\Bureau
                      2008-07-14 22:47 . 2008-07-14 22:47 268 --ah----- C:\sqmdata01.sqm
                      2008-07-14 22:47 . 2008-07-14 22:47 244 --ah----- C:\sqmnoopt01.sqm
                      2008-07-14 22:08 . 2008-06-14 19:33 272,768 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
                      2008-07-14 22:02 . 2008-05-08 16:02 203,136 -----c--- C:\WINDOWS\system32\dllcache\rmcast.sys
                      2008-07-14 22:01 . 2008-07-15 08:22 <REP> d-------- C:\Program Files\Spyware Terminator
                      2008-07-14 22:01 . 2008-07-14 22:02 <REP> d-------- C:\Program Files\Spybot - Search & Destroy
                      2008-07-14 22:01 . 2008-07-15 08:22 <REP> d-------- C:\Documents and Settings\reverend\Application Data\Spyware Terminator
                      2008-07-14 22:01 . 2008-07-14 22:16 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Spyware Terminator
                      2008-07-14 22:01 . 2008-07-14 22:16 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
                      2008-07-14 22:01 . 2008-07-14 22:01 141,312 --a------ C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
                      2008-07-14 20:24 . 2008-07-14 20:24 <REP> d-------- C:\Documents and Settings\All Users\Application Data\nView_Profiles

                      .
                      (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                      .
                      2008-07-15 17:33 713,301 ----a-w C:\WINDOWS\Internet Logs\tvDebug.zip
                      2008-07-15 17:32 44,204 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
                      2008-07-15 17:32 4,130,848 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
                      2008-07-15 17:06 142,336 ----a-w C:\WINDOWS\Internet Logs\xDB4.tmp
                      2008-07-15 16:10 --------- d-----w C:\Program Files\Lavasoft
                      2008-07-15 15:46 --------- d-----w C:\Program Files\Hijackthis Version Française
                      2008-07-15 11:41 196,608 ----a-w C:\WINDOWS\system32\drivers\nStandard.bin
                      2008-07-15 06:08 0 ----a-w C:\Program Files\Installed.hid
                      2008-07-14 20:03 --------- d-----w C:\Documents and Settings\reverend\Application Data\Lavasoft
                      2008-06-14 17:33 272,768 ------w C:\WINDOWS\system32\drivers\bthport.sys
                      2008-05-31 15:33 2,893,312 ----a-w C:\WINDOWS\Internet Logs\xDB2.tmp
                      2008-05-31 15:33 1,420,288 ----a-w C:\WINDOWS\Internet Logs\xDB3.tmp
                      2008-05-31 15:29 --------- d-----w C:\Documents and Settings\LocalService\Application Data\Acronis
                      2008-05-31 15:27 --------- d-----w C:\Program Files\PowerQuest
                      2008-05-31 15:26 441,760 ----a-w C:\WINDOWS\system32\drivers\timntr.sys
                      2008-05-31 15:26 44,384 ----a-w C:\WINDOWS\system32\drivers\tifsfilt.sys
                      2008-05-31 15:26 368,736 ----a-w C:\WINDOWS\system32\drivers\tdrpman.sys
                      2008-05-31 15:26 129,248 ----a-w C:\WINDOWS\system32\drivers\snapman.sys
                      2008-05-31 15:26 --------- d-----w C:\Program Files\Fichiers communs\Acronis
                      2008-05-31 15:26 --------- d-----w C:\Documents and Settings\All Users\Application Data\Acronis
                      2008-05-31 15:25 --------- d-----w C:\Program Files\Acronis
                      2008-05-31 15:23 --------- d-----w C:\Program Files\Fichiers communs\Adobe
                      2008-05-31 15:22 --------- d--h--w C:\Program Files\InstallShield Installation Information
                      2008-05-31 15:19 --------- d-----w C:\Documents and Settings\All Users\Application Data\PowerQuest
                      2008-05-31 09:21 27,262,976 ----a-w C:\VIRTPART.DAT
                      2008-05-31 08:14 1,425,408 ----a-w C:\WINDOWS\Internet Logs\xDB1.tmp
                      2008-05-31 07:54 --------- d-----w C:\Documents and Settings\All Users\Application Data\PokerAcademyPro2
                      2008-05-31 07:50 --------- d-----w C:\Documents and Settings\reverend\Application Data\PokerAcademyPro2
                      2008-05-31 07:04 --------- d-----w C:\Documents and Settings\reverend\Application Data\GrabIt
                      2008-05-30 22:22 --------- d-----w C:\Program Files\Ubisoft
                      2008-05-30 21:34 --------- d-----w C:\Documents and Settings\reverend\Application Data\InterTrust
                      2008-05-30 21:26 --------- d-----w C:\Program Files\Alcohol Soft
                      2008-05-30 21:08 737,280 ----a-w C:\WINDOWS\iun6002.exe
                      2008-05-30 20:19 --------- d-----w C:\Program Files\QuickPar
                      2008-05-30 20:18 --------- d-----w C:\Program Files\GrabIt
                      2008-05-30 20:13 715,248 ----a-w C:\WINDOWS\system32\drivers\sptd.sys
                      2008-05-30 19:20 --------- d-----w C:\Program Files\Symantec
                      2008-05-30 19:20 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
                      2008-05-30 19:19 --------- d-----w C:\Program Files\Fichiers communs\Symantec Shared
                      2008-05-30 19:19 --------- d-----w C:\Documents and Settings\reverend\Application Data\Symantec
                      2008-05-30 19:15 --------- d-----w C:\Program Files\Google
                      2008-05-30 18:42 --------- d-----w C:\Program Files\Windows Live
                      2008-05-30 18:41 --------- dcsh--w C:\Program Files\Fichiers communs\WindowsLiveInstaller
                      2008-05-30 18:38 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
                      2008-05-30 18:37 --------- d-----w C:\Documents and Settings\All Users\Application Data\MailFrontier
                      2008-05-30 15:29 --------- d-----w C:\Program Files\Zone Labs
                      2008-05-30 15:28 --------- d-----w C:\Program Files\SLD Codec Pack
                      2008-05-30 15:27 --------- d-----w C:\Program Files\Jasc Software Inc
                      2008-05-30 15:27 --------- d-----w C:\Program Files\Fichiers communs\Jasc Software Inc
                      2008-05-30 15:27 --------- d-----w C:\Program Files\Fichiers communs\InstallShield
                      2008-05-30 15:27 --------- d-----w C:\Documents and Settings\reverend\Application Data\Jasc Software Inc
                      2008-05-30 15:27 --------- d-----w C:\Documents and Settings\All Users\Application Data\InstallShield
                      2008-05-30 15:22 --------- d-----w C:\Program Files\Java Web Start
                      2008-05-30 15:22 --------- d-----w C:\Program Files\Java
                      2008-05-30 15:21 --------- d-----w C:\Program Files\Free.fr
                      2008-05-30 15:06 --------- d-----w C:\Program Files\Winamp
                      2008-05-30 15:04 --------- d-----w C:\Program Files\QuickTime
                      2008-05-30 15:04 --------- d-----w C:\Program Files\iTunes
                      2008-05-30 15:04 --------- d-----w C:\Program Files\iPod
                      2008-05-30 15:04 --------- d-----w C:\Documents and Settings\reverend\Application Data\Apple Computer
                      2008-05-30 15:04 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
                      2008-05-30 15:03 --------- d-----w C:\Program Files\Fichiers communs\Apple
                      2008-05-30 15:03 --------- d-----w C:\Program Files\Apple Software Update
                      2008-05-30 15:03 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple
                      2008-05-30 15:02 --------- d-----w C:\Program Files\RamBoost XP
                      2008-05-30 15:02 --------- d-----w C:\Program Files\Easy CD-DA Extractor 10
                      2008-05-30 15:01 --------- d-----w C:\Program Files\Alwil Software
                      2008-05-30 15:00 --------- d-----w C:\Program Files\VideoLAN
                      2008-05-30 15:00 --------- d-----w C:\Documents and Settings\reverend\Application Data\vlc
                      2008-05-30 14:47 --------- d-----w C:\Program Files\Attansic
                      2008-05-30 14:44 315,392 ----a-w C:\WINDOWS\HideWin.exe
                      2008-05-30 14:44 --------- d-----w C:\Program Files\Realtek
                      2008-05-30 14:37 --------- d-----w C:\Program Files\Intel
                      2008-05-30 14:34 12,288 ----a-w C:\WINDOWS\system32\drivers\EIO64_xp.sys
                      2008-05-30 14:34 --------- d-----w C:\Program Files\ASUS
                      2008-05-30 12:36 --------- d-----w C:\Program Files\microsoft frontpage
                      2008-05-30 12:34 --------- d-----w C:\Program Files\Services en ligne
                      2006-06-23 22:48 32,768 ----a-r C:\WINDOWS\inf\UpdateUSB.exe
                      .

                      ((((((((((((((((((((((((((((( snapshot@2008-07-15_18.35.38.57 )))))))))))))))))))))))))))))))))))))))))
                      .
                      + 2008-07-14 21:41:58 163,328 ----a-w C:\WINDOWS\ERUNT\SDFIX\ERDNT.EXE
                      + 2008-07-15 17:09:40 3,645,440 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\[u]0[/u]0000001\NTUSER.DAT
                      + 2008-07-15 17:09:40 352,256 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\[u]0[/u]0000002\UsrClass.dat
                      + 2008-07-14 21:41:58 163,328 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\ERDNT.EXE
                      + 2008-07-15 17:09:31 3,645,440 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\[u]0[/u]0000001\NTUSER.DAT
                      + 2008-07-15 17:09:31 352,256 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\[u]0[/u]0000002\UsrClass.dat
                      + 2008-07-15 17:34:02 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_754.dat
                      .
                      ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
                      .
                      .
                      REGEDIT4
                      *Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s

                      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                      "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 04:33 15360]
                      "msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 11:34 5724184]
                      "SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]

                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                      "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2008-05-03 05:46 13529088]
                      "ASUSGamerOSD"="C:\Program Files\ASUS\GamerOSD\GamerOSD.exe" [2007-10-23 17:48 380928]
                      "JMB36X IDE Setup"="C:\WINDOWS\RaidTool\xInsIDE.exe" [2007-03-20 16:36 36864]
                      "36X Raid Configurer"="C:\WINDOWS\system32\xRaidSetup.exe" [2007-03-21 18:23 1953792]
                      "ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-04-02 21:07 919016]
                      "NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2008-05-03 05:46 86016]
                      "TrueImageMonitor.exe"="C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe" [2007-10-07 17:01 2620336]
                      "AcronisTimounterMonitor"="C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe" [2007-10-07 17:36 904880]
                      "Acronis Scheduler2 Service"="C:\Program Files\Fichiers communs\Acronis\Schedule2\schedhlp.exe" [2007-10-07 17:08 140568]
                      "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-11-14 23:43 286720]
                      "nwiz"="nwiz.exe" [2008-05-03 05:46 1630208 C:\WINDOWS\system32\nwiz.exe]
                      "RTHDCPL"="RTHDCPL.EXE" [2007-03-21 16:49 16126464 C:\WINDOWS\RTHDCPL.exe]

                      [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
                      "CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2008-04-14 04:33 15360]

                      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
                      "msacm.l3acm"= l3codecp.acm
                      "vidc.asv2"= asusasv2.dll

                      [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
                      Authentication Packages REG_MULTI_SZ msv1_0 relog_ap

                      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
                      @=""

                      [HKLM\~\startupfolder\C:^Documents and Settings^reverend^Menu Démarrer^Programmes^Démarrage^Ubisoft register.lnk]
                      path=C:\Documents and Settings\reverend\Menu Démarrer\Programmes\Démarrage\Ubisoft register.lnk
                      backup=C:\WINDOWS\pss\Ubisoft register.lnkStartup

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcoholAutomount]
                      --a------ 2007-12-22 09:20 222080 C:\Program Files\Alcohol Soft\Alcohol 120\AxCmd.exe

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUS SmartDoctor]
                      --a------ 2008-01-22 11:52 1126400 C:\Program Files\ASUS\SmartDoctor\SmartDoctor.exe

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
                      --a------ 2007-11-15 13:11 267048 C:\Program Files\iTunes\iTunesHelper.exe

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
                      --a------ 2007-10-18 11:34 5724184 C:\Program Files\Windows Live\Messenger\msnmsgr.exe

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
                      --a------ 2007-11-14 23:43 286720 C:\Program Files\QuickTime\QTTask.exe

                      [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
                      "DisableMonitoring"=dword:00000001

                      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
                      "EnableFirewall"= 0 (0x0)

                      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
                      "%windir%\\system32\\sessmgr.exe"=
                      "C:\\Program Files\\iTunes\\iTunes.exe"=
                      "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
                      "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
                      "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=

                      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
                      "7423:TCP"= 7423:TCP:messenger
                      "2831:TCP"= 2831:TCP:messenger

                      R0 pavboot;pavboot;C:\WINDOWS\system32\drivers\pavboot.sys [2008-06-19 17:24]
                      R0 tdrpman;Acronis Try&Decide and Restore Points filter;C:\WINDOWS\system32\DRIVERS\tdrpman.sys [2008-05-31 17:26]
                      R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-05-16 01:20]
                      R1 EIO_XP;EIO_XP;C:\WINDOWS\system32\drivers\EIO_XP.sys [2006-06-14 13:44]
                      R1 GhPciScan;GhostPciScanner;C:\Program Files\Symantec\Norton Ghost 2003\ghpciscan.sys [2002-08-14 15:11]
                      R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-05-16 01:16]
                      R2 TryAndDecideService;Acronis Try And Decide Service;C:\Program Files\Fichiers communs\Acronis\Fomatik\TrueImageTryStartService.exe [2007-10-08 11:19]
                      R3 asusgsb;ASUS Virtual Video Capture Device Driver;C:\WINDOWS\system32\drivers\asusgsb.sys [2007-10-23 17:48]
                      R3 ASUSVRC;ASUSTeK Virtual Capture Device;C:\WINDOWS\system32\DRIVERS\AsusVRC.sys [2007-01-29 17:12]
                      R3 AtcL001;NDIS Miniport Driver for Attansic L1 Gigabit Ethernet Controller;C:\WINDOWS\system32\DRIVERS\atl01_xp.sys [2007-03-15 16:12]
                      R3 Video3D;ASUS Video3D Service;C:\WINDOWS\system32\Drivers\Video3D32.sys [2007-10-23 17:48]

                      .
                      - - - - ORPHANS REMOVED - - - -

                      Notify-dsauth32 - dsauth32.dll

                      **************************************************************************

                      catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                      Rootkit scan 2008-07-15 19:33:49
                      Windows 5.1.2600 Service Pack 3 NTFS

                      Balayage processus cach‚s ...

                      Balayage cach‚ autostart entries ...

                      Balayage des fichiers cach‚s ...

                      C:\garda\notifykeys.dat 176 bytes

                      Scan termin‚ avec succŠs
                      Les fichiers cach‚s: 1

                      **************************************************************************
                      .
                      ------------------------ Other Running Processes ------------------------
                      .
                      C:\WINDOWS\system32\ZoneLabs\vsmon.exe
                      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                      C:\Program Files\Alwil Software\Avast4\ashServ.exe
                      C:\WINDOWS\system32\rundll32.exe
                      C:\Program Files\Fichiers communs\Acronis\Schedule2\schedul2.exe
                      C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                      C:\WINDOWS\ATKKBService.exe
                      C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
                      C:\WINDOWS\system32\nvsvc32.exe
                      C:\Program Files\Spyware Terminator\sp_rsser.exe
                      C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
                      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                      .
                      **************************************************************************
                      .
                      Temps d'accomplissement: 2008-07-15 19:37:00 - machine was rebooted
                      ComboFix-quarantined-files.txt 2008-07-15 17:36:17
                      ComboFix2.txt 2008-07-15 16:36:34

                      Pre-Run: 85,163,376,640 octets libres
                      Post-Run: 85,173,137,408 octets libres

                      237 --- E O F --- 2008-07-15 05:54:44
                      0
                      1. Contributeur sécurité
                        Remets aussi un rapport Hijackthis et dis tes soucis
                        0
                        1. voila le rapport:

                          Logfile of HijackThis v1.99.1
                          Scan saved at 19:54:29, on 15/07/2008
                          Platform: Windows XP SP3 (WinNT 5.01.2600)
                          MSIE: Internet Explorer v7.00 (7.00.6000.16674)

                          Running processes:
                          C:\WINDOWS\System32\smss.exe
                          C:\WINDOWS\system32\winlogon.exe
                          C:\WINDOWS\system32\services.exe
                          C:\WINDOWS\system32\lsass.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\WINDOWS\system32\ZoneLabs\vsmon.exe
                          C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                          C:\Program Files\Alwil Software\Avast4\ashServ.exe
                          C:\Program Files\ASUS\GamerOSD\GamerOSD.exe
                          C:\WINDOWS\RTHDCPL.EXE
                          C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
                          C:\WINDOWS\system32\RUNDLL32.EXE
                          C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
                          C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
                          C:\Program Files\Fichiers communs\Acronis\Schedule2\schedhlp.exe
                          C:\WINDOWS\system32\ctfmon.exe
                          C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                          C:\WINDOWS\system32\spoolsv.exe
                          C:\Program Files\Fichiers communs\Acronis\Schedule2\schedul2.exe
                          C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                          C:\WINDOWS\ATKKBService.exe
                          C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
                          C:\WINDOWS\system32\nvsvc32.exe
                          C:\Program Files\Spyware Terminator\sp_rsser.exe
                          C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
                          C:\Program Files\Fichiers communs\Acronis\Fomatik\TrueImageTryStartService.exe
                          C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                          C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                          C:\WINDOWS\explorer.exe
                          C:\Program Files\internet explorer\iexplore.exe
                          C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
                          H:\Program Files\eMule\emule.exe
                          C:\Program Files\Hijackthis Version Française\VERSION TRADUITE ORIGINALE.EXE

                          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                          O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
                          O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                          O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                          O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                          O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                          O4 - HKLM\..\Run: [ASUSGamerOSD] C:\Program Files\ASUS\GamerOSD\GamerOSD.exe
                          O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
                          O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\WINDOWS\RaidTool\xInsIDE.exe
                          O4 - HKLM\..\Run: [36X Raid Configurer] C:\WINDOWS\system32\xRaidSetup.exe boot
                          O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
                          O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
                          O4 - HKLM\..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
                          O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
                          O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Fichiers communs\Acronis\Schedule2\schedhlp.exe"
                          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                          O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                          O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                          O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                          O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.1_01\bin\npjpi141_01.dll
                          O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.1_01\bin\npjpi141_01.dll
                          O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                          O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                          O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                          O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
                          O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
                          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                          O11 - Options group: [INTERNATIONAL] International*
                          O14 - IERESET.INF: START_PAGE_URL=https://www.free.fr/freebox/index.html
                          O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
                          O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                          O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
                          O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
                          O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)
                          O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Fichiers communs\Acronis\Schedule2\schedul2.exe
                          O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                          O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                          O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
                          O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                          O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
                          O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
                          O23 - Service: GhostStartService - Symantec Corporation - C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
                          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
                          O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                          O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                          O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
                          O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
                          O23 - Service: Acronis Try And Decide Service (TryAndDecideService) - Unknown owner - C:\Program Files\Fichiers communs\Acronis\Fomatik\TrueImageTryStartService.exe
                          O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
                          0
                        2. t es encore la? ça donne quoi ce rapport?
                          0
                        3. @herby2475jviens de refaire un dernier scann avec ad aware, ci dessous le rapport , il a trouvé des tracking cokkie et une clé de registre modifiée, je les supprime

                          Ad-Aware Build
                          Log File Created on: 2008-07-15 20:35:58
                          Using Definitions File: C:\Documents and Settings\All Users\Application Data\Lavasoft\Ad-Aware\core.aawdef
                          Computer name: REVEREND-XXXX
                          Name of user performing scan: SYSTEM

                          System information
                          ===========================
                          Number of processors: 2
                          Processor type: Intel(R) Core(TM)2 Duo CPU E8400 @ 3.00GHz
                          Memory Available: 66%
                          Total Physical Memory: 2146480128 Bytes
                          Available Physical Memory: 1402396672 Bytes
                          Total Page File Size: 4129751040 Bytes
                          Available On Page File: 3489042432 Bytes
                          Total Virtual Memory: 2147352576 Bytes
                          Available Virtual Memory: 1910849536 Bytes
                          OS: Microsoft Windows XP Service Pack 3 (Build 2600)

                          Ad-Aware Settings
                          ===========================
                          Skipping files larger than 1048576 kB
                          Ignoring infections with lower TAI than: 3

                          Extended Ad-Aware Settings
                          ===========================
                          Unloading known modules during scan
                          Ignoring spanned files when scanning cab archives
                          Reanalyzing results after scanning before displaying results
                          Trying to unload modules prior to removal
                          Let Windows remove files currently in use at next reboot
                          Removing quarantined objects after restore
                          Deactivating Ad-Watch during scans
                          Writeprotecting system files after repairs
                          Include info about ignored objects in log file
                          Including basic settings in log file
                          Including advanced settings in log file
                          Including user and computer name in log file
                          Create and save WebUpdate log file

                          Databaseinfo
                          ===========================
                          Version number: 103
                          Build Number: 0
                          Build Date and Time: 2008/07/15 07:23:00

                          Scan Statistics
                          ===========================
                          Method: Smart
                          Scan tracking cookies.............................: On
                          Scan ADS filestreams..............................: Off

                          Item Scanned: 130850
                          Infections Detected: 48
                          Infections Ignored: 0

                          Scan detailed statistics
                          ===========================
                          Type Critical Total
                          Process Scan....: 0 0
                          Registry Scan...: 0 0
                          Registry PE Scan: 0 0
                          Hosts File Scan.: 0 0
                          File Scan.......: 0 0
                          Folder Scan.....: 0 0
                          LSP Scan........: 0 0
                          ADS Scan........: 0 0
                          Cookie Scan.....: 46 46
                          File Hash Scan..: 0 0

                          Infections Found
                          ===========================
                          Family Id: 725 Name: Tracking Cookie Category: DataMiner TAI:3
                          Item Id: 600000083 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\reverend\Cookies\index.dat 247realmedia.com RMID /
                          Item Id: 600000083 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\reverend\Cookies\index.dat 247realmedia.com RMFD /
                          Item Id: 600000083 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\reverend\Cookies\index.dat 247realmedia.com 3suisses /
                          Item Id: 600000083 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\reverend\Cookies\index.dat 247realmedia.com spartoo /
                          Item Id: 600000083 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\reverend\Cookies\index.dat 247realmedia.com priceminister /
                          Item Id: 600000212 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\reverend\Cookies\index.dat msnportal.112.2o7.net s_vi /
                          Item Id: 600000408 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\reverend\Cookies\index.dat serving-sys.com U /
                          Item Id: 600000408 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\reverend\Cookies\index.dat serving-sys.com A2 /
                          Item Id: 600000408 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\reverend\Cookies\index.dat serving-sys.com B2 /
                          Item Id: 600000408 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\reverend\Cookies\index.dat serving-sys.com C3 /
                          Item Id: 600000408 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\reverend\Cookies\index.dat serving-sys.com D3 /
                          Item Id: 600000408 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\reverend\Cookies\index.dat serving-sys.com E2 /
                          Item Id: 600000001 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\reverend\Cookies\index.dat smartadserver.com TestIfCookieP /
                          Item Id: 600000001 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\reverend\Cookies\index.dat smartadserver.com pbw /
                          Item Id: 600000001 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\reverend\Cookies\index.dat smartadserver.com pid /
                          Item Id: 600000001 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\reverend\Cookies\index.dat smartadserver.com pbwmaj /
                          Item Id: 600000171 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\reverend\Cookies\index.dat bs.serving-sys.com eyeblaster /
                          Item Id: 600000142 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\reverend\Cookies\index.dat estat.com e /
                          Item Id: 600000225 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\reverend\Cookies\index.dat cetelem.solution.weborama.fr _adpe /
                          Item Id: 600000225 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\reverend\Cookies\index.dat cetelem.solution.weborama.fr _adpp /
                          Item Id: 600000225 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\reverend\Cookies\index.dat cetelem.solution.weborama.fr _adpcr /
                          Item Id: 600000225 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\reverend\Cookies\index.dat cetelem.solution.weborama.fr _adpc /
                          Item Id: 600000225 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\reverend\Cookies\index.dat boursoramabanque.solution.weborama.fr _adpe /
                          Item Id: 600000225 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\reverend\Cookies\index.dat boursoramabanque.solution.weborama.fr _adpp /
                          Item Id: 600000225 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\reverend\Cookies\index.dat boursoramabanque.solution.weborama.fr _adpcr /
                          Item Id: 600000225 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\reverend\Cookies\index.dat boursoramabanque.solution.weborama.fr _adpc /
                          Item Id: 600000295 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\reverend\Cookies\index.dat adtech.de JEB2 /
                          Item Id: 600000101 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\reverend\Cookies\index.dat overture.com CMUserData /
                          Item Id: 600000212 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\reverend\Cookies\index.dat himedia.112.2o7.net s_vi /
                          Item Id: 600000225 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\reverend\Cookies\index.dat weborama.fr AFFICHE_W /
                          Item Id: 600000225 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\reverend\Cookies\index.dat weborama.fr wous /
                          Item Id: 600000225 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\reverend\Cookies\index.dat weborama.fr wous_c /
                          Item Id: 600000225 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\reverend\Cookies\index.dat weborama.fr oo240953 /
                          Item Id: 600000363 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\reverend\Cookies\index.dat fl01.ct2.comclick.com comTrackIdSurfeur /
                          Item Id: 600000363 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\reverend\Cookies\index.dat fl01.ct2.comclick.com CKA /
                          Item Id: 600000363 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\reverend\Cookies\index.dat fl01.ct2.comclick.com CKA_SIZE /
                          Item Id: 600000212 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\reverend\Cookies\index.dat 2o7.net s_vi_x7Cbx7Fx7Ctcrdbeprx60acx7Eu /
                          Item Id: 600000225 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\reverend\Cookies\index.dat aimfar.solution.weborama.fr _cslidef /
                          Item Id: 600000225 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\reverend\Cookies\index.dat aimfar.solution.weborama.fr _cp /
                          Item Id: 600000212 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\reverend\Cookies\index.dat pandasoftware.112.2o7.net s_vi /
                          Item Id: 600000457 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\reverend\Cookies\index.dat adopt.euroclick.com DMEXP /
                          Item Id: 600000457 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\reverend\Cookies\index.dat adopt.euroclick.com CTCI /
                          Item Id: 600000457 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\reverend\Cookies\index.dat adopt.euroclick.com HS /
                          Item Id: 600000457 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\reverend\Cookies\index.dat adopt.euroclick.com LO /
                          Item Id: 600000457 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\reverend\Cookies\index.dat adopt.euroclick.com UI /
                          Item Id: 600000457 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\reverend\Cookies\index.dat adopt.euroclick.com NSC_mc-bepqu.fvspdmjdl.dpn-iuuq /
                          Family Id: 9999 Name: MRU Object Category: MRU Object TAI:0
                          Item Id: 1 Value: MRU Path: C:\Documents and Settings\reverend\Recent Count: 19
                          Item Id: 3 Value: MRU Registry Key: S-1-5-21-57989841-1844237615-839522115-1003\Software\Microsoft\Internet Explorer\TypedURLs Count: 2

                          Items Ignored During Scan
                          ===========================

                          Listing of running processes
                          ===========================
                          C:\WINDOWS\SYSTEM32\SMSS.EXE
                          c:\windows\system32\smss.exe

                          c:\windows\system32\ntdll.dll

                          C:\WINDOWS\SYSTEM32\CSRSS.EXE
                          c:\windows\system32\csrss.exe

                          c:\windows\system32\ntdll.dll

                          c:\windows\system32\csrsrv.dll

                          c:\windows\system32\basesrv.dll

                          c:\windows\system32\winsrv.dll

                          c:\windows\system32\gdi32.dll

                          c:\windows\system32\kernel32.dll

                          c:\windows\system32\user32.dll

                          c:\windows\system32\sxs.dll

                          c:\windows\system32\advapi32.dll

                          c:\windows\system32\rpcrt4.dll

                          c:\windows\system32\secur32.dll

                          C:\WINDOWS\SYSTEM32\WINLOGON.EXE
                          c:\windows\system32\winlogon.exe

                          c:\windows\system32\ntdll.dll

                          c:\windows\system32\kernel32.dll

                          c:\windows\system32\advapi32.dll

                          c:\windows\system32\rpcrt4.dll

                          c:\windows\system32\secur32.dll

                          c:\windows\system32\authz.dll

                          c:\windows\system32\msvcrt.dll

                          c:\windows\system32\crypt32.dll

                          c:\windows\system32\msasn1.dll

                          c:\windows\system32\user32.dll

                          c:\windows\system32\gdi32.dll

                          c:\windows\system32\nddeapi.dll

                          c:\windows\system32\profmap.dll

                          c:\windows\system32\netapi32.dll

                          c:\windows\system32\userenv.dll

                          c:\windows\system32\psapi.dll

                          c:\windows\system32\regapi.dll

                          c:\windows\system32\setupapi.dll

                          c:\windows\system32\version.dll

                          c:\windows\system32\winsta.dll

                          c:\windows\system32\wintrust.dll

                          c:\windows\system32\imagehlp.dll

                          c:\windows\system32\ws2_32.dll

                          c:\windows\system32\ws2help.dll

                          c:\windows\system32\imm32.dll

                          c:\windows\system32\msgina.dll

                          c:\windows\system32\comctl32.dll

                          c:\windows\system32\odbc32.dll

                          c:\windows\system32\comdlg32.dll

                          c:\windows\system32\shell32.dll

                          c:\windows\system32\shlwapi.dll

                          c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll

                          c:\windows\system32\odbcint.dll

                          c:\windows\system32\shsvcs.dll

                          c:\windows\system32\sfc.dll

                          c:\windows\system32\sfc_os.dll

                          c:\windows\system32\ole32.dll

                          c:\windows\system32\apphelp.dll

                          c:\windows\system32\msctfime.ime

                          c:\windows\system32\winscard.dll

                          c:\windows\system32\wtsapi32.dll

                          c:\windows\system32\sxs.dll

                          c:\windows\system32\uxtheme.dll

                          c:\windows\system32\winmm.dll

                          c:\windows\system32\cscdll.dll

                          c:\windows\system32\dimsntfy.dll

                          c:\windows\system32\wlnotify.dll

                          c:\windows\system32\mpr.dll

                          c:\windows\system32\winspool.drv

                          c:\windows\system32\rsaenh.dll

                          c:\windows\system32\samlib.dll

                          c:\windows\system32\cscui.dll

                          c:\windows\system32\xpsp2res.dll

                          c:\windows\system32\ntmarta.dll

                          c:\windows\system32\wldap32.dll

                          c:\windows\system32\msv1_0.dll

                          c:\windows\system32\iphlpapi.dll

                          c:\windows\system32\comres.dll

                          c:\windows\system32\oleaut32.dll

                          c:\windows\system32\clbcatq.dll

                          c:\windows\system32\wdmaud.drv

                          c:\windows\system32\msacm32.drv

                          c:\windows\system32\msacm32.dll

                          c:\windows\system32\midimap.dll

                          C:\WINDOWS\SYSTEM32\SERVICES.EXE
                          c:\windows\system32\services.exe

                          c:\windows\system32\ntdll.dll

                          c:\windows\system32\kernel32.dll

                          c:\windows\system32\advapi32.dll

                          c:\windows\system32\rpcrt4.dll

                          c:\windows\system32\secur32.dll

                          c:\windows\system32\msvcrt.dll

                          c:\windows\system32\ncobjapi.dll

                          c:\windows\system32\msvcp60.dll

                          c:\windows\system32\scesrv.dll

                          c:\windows\system32\authz.dll

                          c:\windows\system32\user32.dll

                          c:\windows\system32\gdi32.dll

                          c:\windows\system32\userenv.dll

                          c:\windows\system32\umpnpmgr.dll

                          c:\windows\system32\winsta.dll

                          c:\windows\system32\netapi32.dll

                          c:\windows\system32\shimeng.dll

                          c:\windows\apppatch\acadproc.dll

                          c:\windows\system32\imm32.dll

                          c:\windows\system32\apphelp.dll

                          c:\windows\system32\version.dll

                          c:\windows\system32\eventlog.dll

                          c:\windows\system32\psapi.dll

                          c:\windows\system32\ws2_32.dll

                          c:\windows\system32\ws2help.dll

                          c:\windows\system32\wtsapi32.dll

                          C:\WINDOWS\SYSTEM32\LSASS.EXE
                          c:\windows\system32\lsass.exe

                          c:\windows\system32\ntdll.dll

                          c:\windows\system32\kernel32.dll

                          c:\windows\system32\advapi32.dll

                          c:\windows\system32\rpcrt4.dll

                          c:\windows\system32\secur32.dll

                          c:\windows\system32\lsasrv.dll

                          c:\windows\system32\mpr.dll

                          c:\windows\system32\user32.dll

                          c:\windows\system32\gdi32.dll

                          c:\windows\system32\msasn1.dll

                          c:\windows\system32\msvcrt.dll

                          c:\windows\system32\netapi32.dll

                          c:\windows\system32\ntdsapi.dll

                          c:\windows\system32\dnsapi.dll

                          c:\windows\system32\ws2_32.dll

                          c:\windows\system32\ws2help.dll

                          c:\windows\system32\wldap32.dll

                          c:\windows\system32\samlib.dll

                          c:\windows\system32\samsrv.dll

                          c:\windows\system32\cryptdll.dll

                          c:\windows\system32\shimeng.dll

                          c:\windows\apppatch\acgenral.dll

                          c:\windows\system32\winmm.dll

                          c:\windows\system32\ole32.dll

                          c:\windows\system32\oleaut32.dll

                          c:\windows\system32\msacm32.dll

                          c:\windows\system32\version.dll

                          c:\windows\system32\shell32.dll

                          c:\windows\system32\shlwapi.dll

                          c:\windows\system32\userenv.dll

                          c:\windows\system32\uxtheme.dll

                          c:\windows\system32\imm32.dll

                          c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll

                          c:\windows\system32\comctl32.dll

                          c:\windows\system32\msprivs.dll

                          c:\windows\system32\kerberos.dll

                          c:\windows\system32\msv1_0.dll

                          c:\windows\system32\iphlpapi.dll

                          c:\windows\system32\netlogon.dll

                          c:\windows\system32\w32time.dll

                          c:\windows\system32\msvcp60.dll

                          c:\windows\system32\schannel.dll

                          c:\windows\system32\crypt32.dll

                          c:\windows\system32\wdigest.dll

                          c:\windows\system32\rsaenh.dll

                          c:\windows\system32\relog_ap.dll

                          c:\windows\system32\setupapi.dll

                          c:\windows\system32\scecli.dll

                          c:\windows\system32\ipsecsvc.dll

                          c:\windows\system32\authz.dll

                          c:\windows\system32\oakley.dll

                          c:\windows\system32\winipsec.dll

                          c:\windows\system32\pstorsvc.dll

                          c:\windows\system32\psbase.dll

                          c:\windows\system32\mswsock.dll

                          c:\windows\system32\hnetcfg.dll

                          c:\windows\system32\wshtcpip.dll

                          c:\windows\system32\dssenh.dll

                          C:\WINDOWS\SYSTEM32\SVCHOST.EXE
                          c:\windows\system32\svchost.exe

                          c:\windows\system32\ntdll.dll

                          c:\windows\system32\kernel32.dll

                          c:\windows\system32\advapi32.dll

                          c:\windows\system32\rpcrt4.dll

                          c:\windows\system32\secur32.dll

                          c:\windows\system32\shimeng.dll

                          c:\windows\apppatch\acgenral.dll

                          c:\windows\system32\user32.dll

                          c:\windows\system32\gdi32.dll

                          c:\windows\system32\winmm.dll

                          c:\windows\system32\ole32.dll

                          c:\windows\system32\msvcrt.dll

                          c:\windows\system32\oleaut32.dll

                          c:\windows\system32\msacm32.dll

                          c:\windows\system32\version.dll

                          c:\windows\system32\shell32.dll

                          c:\windows\system32\shlwapi.dll

                          c:\windows\system32\userenv.dll

                          c:\windows\system32\uxtheme.dll

                          c:\windows\system32\imm32.dll

                          c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll

                          c:\windows\system32\comctl32.dll

                          c:\windows\system32\ntmarta.dll

                          c:\windows\system32\samlib.dll

                          c:\windows\system32\wldap32.dll

                          c:\windows\system32\rpcss.dll

                          c:\windows\system32\ws2_32.dll

                          c:\windows\system32\ws2help.dll

                          c:\windows\system32\xpsp2res.dll

                          c:\windows\system32\clbcatq.dll

                          c:\windows\system32\comres.dll

                          c:\windows\system32\termsrv.dll

                          c:\windows\system32\icaapi.dll

                          c:\windows\system32\setupapi.dll

                          c:\windows\system32\wintrust.dll

                          c:\windows\system32\crypt32.dll

                          c:\windows\system32\msasn1.dll

                          c:\windows\system32\imagehlp.dll

                          c:\windows\system32\authz.dll

                          c:\windows\system32\mstlsapi.dll

                          c:\windows\system32\activeds.dll

                          c:\windows\system32\adsldpc.dll

                          c:\windows\system32\netapi32.dll

                          c:\windows\system32\atl.dll

                          c:\windows\system32\regapi.dll

                          c:\windows\system32\rsaenh.dll

                          c:\windows\system32\apphelp.dll

                          c:\windows\system32\svchost.exe

                          c:\windows\system32\ntdll.dll

                          c:\windows\system32\kernel32.dll

                          c:\windows\system32\advapi32.dll

                          c:\windows\system32\rpcrt4.dll

                          c:\windows\system32\secur32.dll

                          c:\windows\system32\shimeng.dll

                          c:\windows\apppatch\acgenral.dll

                          c:\windows\system32\user32.dll

                          c:\windows\system32\gdi32.dll

                          c:\windows\system32\winmm.dll

                          c:\windows\system32\ole32.dll

                          c:\windows\system32\msvcrt.dll

                          c:\windows\system32\oleaut32.dll

                          c:\windows\system32\msacm32.dll

                          c:\windows\system32\version.dll

                          c:\windows\system32\shell32.dll

                          c:\windows\system32\shlwapi.dll

                          c:\windows\system32\userenv.dll

                          c:\windows\system32\uxtheme.dll

                          c:\windows\system32\imm32.dll

                          c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll

                          c:\windows\system32\comctl32.dll

                          c:\windows\system32\rpcss.dll

                          c:\windows\system32\ws2_32.dll

                          c:\windows\system32\ws2help.dll

                          c:\windows\system32\xpsp2res.dll

                          c:\windows\system32\rsaenh.dll

                          c:\windows\system32\mswsock.dll

                          c:\windows\system32\hnetcfg.dll

                          c:\windows\system32\wshtcpip.dll

                          c:\windows\system32\dnsapi.dll

                          c:\windows\system32\iphlpapi.dll

                          c:\windows\system32\winrnr.dll

                          c:\windows\system32\wldap32.dll

                          c:\windows\system32\rasadhlp.dll

                          c:\windows\system32\clbcatq.dll

                          c:\windows\system32\comres.dll

                          c:\windows\system32\svchost.exe

                          c:\windows\system32\ntdll.dll

                          c:\windows\system32\kernel32.dll

                          c:\windows\system32\advapi32.dll

                          c:\windows\system32\rpcrt4.dll

                          c:\windows\system32\secur32.dll

                          c:\windows\system32\shimeng.dll

                          c:\windows\apppatch\acgenral.dll

                          c:\windows\system32\user32.dll

                          c:\windows\system32\gdi32.dll

                          c:\windows\system32\winmm.dll

                          c:\windows\system32\ole32.dll

                          c:\windows\system32\msvcrt.dll

                          c:\windows\system32\oleaut32.dll

                          c:\windows\system32\msacm32.dll

                          c:\windows\system32\version.dll

                          c:\windows\system32\shell32.dll

                          c:\windows\system32\shlwapi.dll

                          c:\windows\system32\userenv.dll

                          c:\windows\system32\uxtheme.dll

                          c:\windows\system32\imm32.dll

                          c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll

                          c:\windows\system32\comctl32.dll

                          c:\windows\system32\ntmarta.dll

                          c:\windows\system32\samlib.dll

                          c:\windows\system32\wldap32.dll

                          c:\windows\system32\xpsp2res.dll

                          c:\windows\system32\shsvcs.dll

                          c:\windows\system32\winsta.dll

                          c:\windows\system32\netapi32.dll

                          c:\windows\system32\dhcpcsvc.dll

                          c:\windows\system32\dnsapi.dll

                          c:\windows\system32\ws2_32.dll

                          c:\windows\system32\ws2help.dll

                          c:\windows\system32\iphlpapi.dll

                          c:\windows\system32\mswsock.dll

                          c:\windows\system32\hnetcfg.dll

                          c:\windows\system32\wshtcpip.dll

                          c:\windows\system32\rsaenh.dll

                          c:\windows\system32\wzcsvc.dll

                          c:\windows\system32\rtutils.dll

                          c:\windows\system32\wmi.dll

                          c:\windows\system32\crypt32.dll

                          c:\windows\system32\msasn1.dll

                          c:\windows\system32\eapolqec.dll

                          c:\windows\system32\atl.dll

                          c:\windows\system32\qutil.dll

                          c:\windows\system32\msvcp60.dll

                          c:\windows\system32\dot3api.dll

                          c:\windows\system32\wtsapi32.dll

                          c:\windows\system32\esent.dll

                          c:\windows\system32\clbcatq.dll

                          c:\windows\system32\comres.dll

                          c:\windows\system32\rastls.dll

                          c:\windows\system32\cryptui.dll

                          c:\windows\system32\wininet.dll

                          c:\windows\system32\normaliz.dll

                          c:\windows\system32\iertutil.dll

                          c:\windows\system32\wintrust.dll

                          c:\windows\system32\imagehlp.dll

                          c:\windows\system32\mprapi.dll

                          c:\windows\system32\activeds.dll

                          c:\windows\system32\adsldpc.dll

                          c:\windows\system32\setupapi.dll

                          c:\windows\system32\rasapi32.dll

                          c:\windows\system32\rasman.dll

                          c:\windows\system32\tapi32.dll

                          c:\windows\system32\schannel.dll

                          c:\windows\system32\winscard.dll

                          c:\windows\system32\psapi.dll

                          c:\windows\system32\raschap.dll

                          c:\windows\system32\msv1_0.dll

                          c:\windows\system32\schedsvc.dll

                          c:\windows\system32\ntdsapi.dll

                          c:\windows\system32\msidle.dll

                          c:\windows\system32\audiosrv.dll

                          c:\windows\system32\wkssvc.dll

                          c:\windows\system32\qmgr.dll

                          c:\windows\system32\mpr.dll

                          c:\windows\system32\shfolder.dll

                          c:\windows\system32\winhttp.dll

                          c:\windows\system32\dmserver.dll

                          c:\windows\system32\cryptsvc.dll

                          c:\windows\system32\certcli.dll

                          c:\windows\system32\ersvc.dll

                          c:\windows\system32\es.dll

                          c:\windows\pchealth\helpctr\binaries\pchsvc.dll

                          c:\windows\system32\hidserv.dll

                          c:\windows\system32\hid.dll

                          c:\windows\system32\srvsvc.dll

                          c:\windows\system32\netman.dll

                          c:\windows\system32\netshell.dll

                          c:\windows\system32\credui.dll

                          c:\windows\system32\dot3dlg.dll

                          c:\windows\system32\onex.dll

                          c:\windows\system32\eappcfg.dll

                          c:\windows\system32\eappprxy.dll

                          c:\windows\system32\wzcsapi.dll

                          c:\windows\system32\seclogon.dll

                          c:\windows\system32\srsvc.dll

                          c:\windows\system32\powrprof.dll

                          c:\windows\system32\trkwks.dll

                          c:\windows\system32\w32time.dll

                          c:\windows\system32\wbem\wmisvc.dll

                          c:\windows\system32\vssapi.dll

                          c:\windows\system32\browser.dll

                          c:\windows\system32\sens.dll

                          c:\windows\system32\wuauserv.dll

                          c:\windows\system32\ipnathlp.dll

                          c:\windows\system32\authz.dll

                          c:\windows\system32\wuaueng.dll

                          c:\windows\system32\winspool.drv

                          c:\windows\system32\cabinet.dll

                          c:\windows\system32\mspatcha.dll

                          c:\windows\system32\wscsvc.dll

                          c:\windows\system32\msi.dll

                          c:\windows\system32\wbem\wbemcomn.dll

                          c:\windows\system32\wbem\wbemcore.dll

                          c:\windows\system32\wbem\esscli.dll

                          c:\windows\system32\wbem\fastprox.dll

                          c:\windows\system32\sxs.dll

                          c:\windows\system32\sfc.dll

                          c:\windows\system32\sfc_os.dll

                          c:\windows\system32\comsvcs.dll

                          c:\windows\system32\colbact.dll

                          c:\windows\system32\mtxclu.dll

                          c:\windows\system32\wsock32.dll

                          c:\windows\system32\clusapi.dll

                          c:\windows\system32\resutils.dll

                          c:\windows\system32\wbem\wmiutils.dll

                          c:\windows\system32\wbem\repdrvfs.dll

                          c:\windows\system32\wbem\wmiprvsd.dll

                          c:\windows\system32\ncobjapi.dll

                          c:\windows\system32\wbem\wbemess.dll

                          c:\windows\system32\tapisrv.dll

                          c:\windows\system32\rasmans.dll

                          c:\windows\system32\winipsec.dll

                          c:\windows\system32\netcfgx.dll

                          c:\windows\system32\rastapi.dll

                          c:\windows\system32\unimdm.tsp

                          c:\windows\system32\uniplat.dll

                          c:\windows\system32\rasadhlp.dll

                          c:\windows\system32\kmddsp.tsp

                          c:\windows\system32\ndptsp.tsp

                          c:\windows\system32\ipconf.tsp

                          c:\windows\system32\wbem\ncprov.dll

                          c:\windows\system32\h323.tsp

                          c:\windows\system32\hidphone.tsp

                          c:\windows\system32\rasppp.dll

                          c:\windows\system32\ntlsapi.dll

                          c:\windows\system32\kerberos.dll

                          c:\windows\system32\cryptdll.dll

                          c:\windows\system32\rasdlg.dll

                          c:\windows\system32\rasqec.dll

                          c:\windows\system32\msxml3.dll

                          c:\windows\system32\apphelp.dll

                          c:\windows\system32\dssenh.dll

                          c:\windows\system32\winrnr.dll

                          c:\windows\system32\catsrvut.dll

                          c:\windows\system32\catsrv.dll

                          c:\windows\system32\mfcsubs.dll

                          c:\windows\system32\urlmon.dll

                          c:\windows\system32\wbem\wbemcons.dll

                          c:\windows\system32\svchost.exe

                          c:\windows\system32\ntdll.dll

                          c:\windows\system32\kernel32.dll

                          c:\windows\system32\advapi32.dll

                          c:\windows\system32\rpcrt4.dll

                          c:\windows\system32\secur32.dll

                          c:\windows\system32\shimeng.dll

                          c:\windows\apppatch\acgenral.dll

                          c:\windows\system32\user32.dll

                          c:\windows\system32\gdi32.dll

                          c:\windows\system32\winmm.dll

                          c:\windows\system32\ole32.dll

                          c:\windows\system32\msvcrt.dll

                          c:\windows\system32\oleaut32.dll

                          c:\windows\system32\msacm32.dll

                          c:\windows\system32\version.dll

                          c:\windows\system32\shell32.dll

                          c:\windows\system32\shlwapi.dll

                          c:\windows\system32\userenv.dll

                          c:\windows\system32\uxtheme.dll

                          c:\windows\system32\imm32.dll

                          c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll

                          c:\windows\system32\comctl32.dll

                          c:\windows\system32\dnsrslvr.dll

                          c:\windows\system32\dnsapi.dll

                          c:\windows\system32\ws2_32.dll

                          c:\windows\system32\ws2help.dll

                          c:\windows\system32\iphlpapi.dll

                          c:\windows\system32\rsaenh.dll

                          c:\windows\system32\mswsock.dll

                          c:\windows\system32\hnetcfg.dll

                          c:\windows\system32\wshtcpip.dll

                          c:\windows\system32\svchost.exe

                          c:\windows\system32\ntdll.dll

                          c:\windows\system32\kernel32.dll

                          c:\windows\system32\advapi32.dll

                          c:\windows\system32\rpcrt4.dll

                          c:\windows\system32\secur32.dll

                          c:\windows\system32\shimeng.dll

                          c:\windows\apppatch\acgenral.dll

                          c:\windows\system32\user32.dll

                          c:\windows\system32\gdi32.dll

                          c:\windows\system32\winmm.dll

                          c:\windows\system32\ole32.dll

                          c:\windows\system32\msvcrt.dll

                          c:\windows\system32\oleaut32.dll

                          c:\windows\system32\msacm32.dll

                          c:\windows\system32\version.dll

                          c:\windows\system32\shell32.dll

                          c:\windows\system32\shlwapi.dll

                          c:\windows\system32\userenv.dll

                          c:\windows\system32\uxtheme.dll

                          c:\windows\system32\imm32.dll

                          c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll

                          c:\windows\system32\comctl32.dll

                          c:\windows\system32\ntmarta.dll

                          c:\windows\system32\samlib.dll

                          c:\windows\system32\wldap32.dll

                          c:\windows\system32\xpsp2res.dll

                          c:\windows\system32\lmhsvc.dll

                          c:\windows\system32\iphlpapi.dll

                          c:\windows\system32\ws2_32.dll

                          c:\windows\system32\ws2help.dll

                          c:\windows\system32\webclnt.dll

                          c:\windows\system32\wininet.dll

                          c:\windows\system32\normaliz.dll

                          c:\windows\system32\iertutil.dll

                          c:\windows\system32\regsvc.dll

                          C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASWUPDSV.EXE
                          c:\program files\alwil software\avast4\aswupdsv.exe

                          c:\windows\system32\ntdll.dll

                          c:\windows\system32\kernel32.dll

                          c:\program files\alwil software\avast4\aswcmns.dll

                          c:\program files\alwil software\avast4\aswcmnos.dll

                          c:\windows\system32\user32.dll

                          c:\windows\system32\gdi32.dll

                          c:\windows\system32\advapi32.dll

                          c:\windows\system32\rpcrt4.dll

                          c:\windows\system32\secur32.dll

                          c:\windows\system32\msvcp71.dll

                          c:\windows\system32\msvcr71.dll

                          c:\windows\system32\wsock32.dll

                          c:\windows\system32\ws2_32.dll

                          c:\windows\system32\msvcrt.dll

                          c:\windows\system32\ws2help.dll

                          c:\program files\alwil software\avast4\aswcmnb.dll

                          c:\windows\system32\imm32.dll

                          C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHSERV.EXE
                          c:\program files\alwil software\avast4\ashserv.exe

                          c:\windows\system32\ntdll.dll

                          c:\windows\system32\kernel32.dll

                          c:\windows\system32\rpcrt4.dll

                          c:\windows\system32\advapi32.dll

                          c:\windows\system32\secur32.dll

                          c:\program files\alwil software\avast4\aswaux.dll

                          c:\windows\system32\msvcp71.dll

                          c:\windows\system32\msvcr71.dll

                          c:\program files\alwil software\avast4\aswcmnb.dll

                          c:\program files\alwil software\avast4\aswcmnos.dll

                          c:\windows\system32\user32.dll

                          c:\windows\system32\gdi32.dll

                          c:\windows\system32\wsock32.dll

                          c:\windows\system32\ws2_32.dll

                          c:\windows\system32\msvcrt.dll

                          c:\windows\system32\ws2help.dll

                          c:\program files\alwil software\avast4\aswengin.dll

                          c:\program files\alwil software\avast4\aswscan.dll

                          c:\program files\alwil software\avast4\aswcmns.dll

                          c:\program files\alwil software\avast4\ashbase.dll

                          c:\windows\system32\version.dll

                          c:\program files\alwil software\avast4\ashtask.dll

                          c:\program files\alwil software\avast4\aswinteg.dll

                          c:\program files\alwil software\avast4\aswidle.dll

                          c:\program files\alwil software\avast4\aavm4h.dll

                          c:\windows\system32\imm32.dll

                          c:\windows\system32\dbghelp.dll

                          c:\program files\alwil software\avast4\french\base.dll

                          c:\windows\system32\wtsapi32.dll

                          c:\windows\system32\winsta.dll

                          c:\windows\system32\netapi32.dll

                          c:\program files\alwil software\avast4\ahresmai.dll

                          c:\program files\alwil software\avast4\ahresmes.dll

                          c:\program files\alwil software\avast4\ahresns.dll

                          c:\program files\alwil software\avast4\ahresout.dll

                          c:\program files\alwil software\avast4\ahresp2p.dll

                          c:\program files\alwil software\avast4\ahresstd.dll

                          c:\program files\alwil software\avast4\ahresws.dll

                          c:\program files\alwil software\avast4\ashsodbc.dll

                          c:\windows\system32\ole32.dll

                          c:\windows\system32\odbc32.dll

                          c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll

                          c:\windows\system32\shlwapi.dll

                          c:\windows\system32\comdlg32.dll

                          c:\windows\system32\shell32.dll

                          c:\windows\system32\odbcint.dll

                          c:\windows\system32\uxtheme.dll

                          c:\windows\system32\odbccp32.dll

                          c:\windows\system32\odbcjt32.dll

                          c:\windows\system32\msjet40.dll

                          c:\windows\system32\mswstr10.dll

                          c:\windows\system32\oleaut32.dll

                          c:\windows\system32\odbcji32.dll

                          c:\windows\system32\msjter40.dll

                          c:\windows\system32\msjint40.dll

                          c:\windows\system32\clbcatq.dll

                          c:\windows\system32\comres.dll

                          c:\windows\system32\msjtes40.dll

                          c:\windows\system32\vbajet32.dll

                          c:\windows\system32\expsrv.dll

                          c:\windows\system32\wbem\wbemprox.dll

                          c:\windows\system32\wbem\wbemcomn.dll

                          c:\windows\system32\xpsp2res.dll

                          c:\windows\system32\msctfime.ime

                          c:\windows\system32\perfos.dll

                          c:\windows\system32\wbem\wbemsvc.dll

                          c:\windows\system32\wbem\fastprox.dll

                          c:\windows\system32\msvcp60.dll

                          c:\windows\system32\ntdsapi.dll

                          c:\windows\system32\dnsapi.dll

                          c:\windows\system32\wldap32.dll

                          c:\program files\alwil software\avast4\aswres.dll

                          C:\PROGRAM FILES\ASUS\GAMEROSD\GAMEROSD.EXE
                          c:\program files\asus\gamerosd\gamerosd.exe

                          c:\windows\system32\ntdll.dll

                          c:\windows\system32\kernel32.dll

                          c:\windows\system32\winmm.dll

                          c:\windows\system32\advapi32.dll

                          c:\windows\system32\rpcrt4.dll

                          c:\windows\system32\secur32.dll

                          c:\windows\system32\gdi32.dll

                          c:\windows\system32\user32.dll

                          c:\windows\system32\ws2_32.dll

                          c:\windows\system32\msvcrt.dll

                          c:\windows\system32\ws2help.dll

                          c:\windows\system32\setupapi.dll

                          c:\windows\system32\mfc42.dll

                          c:\windows\system32\shell32.dll

                          c:\windows\system32\shlwapi.dll

                          c:\windows\system32\ole32.dll

                          c:\windows\system32\oleaut32.dll

                          c:\windows\system32\imm32.dll

                          c:\windows\system32\mfc42loc.dll

                          c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll

                          c:\windows\system32\comctl32.dll

                          c:\windows\system32\uxtheme.dll

                          c:\windows\system32\apphelp.dll

                          c:\windows\system32\msctfime.ime

                          c:\windows\system32\xpsp2res.dll

                          c:\windows\system32\clbcatq.dll

                          c:\windows\system32\comres.dll

                          c:\windows\system32\version.dll

                          c:\windows\system32\devenum.dll

                          c:\windows\system32\wintrust.dll

                          c:\windows\system32\crypt32.dll

                          c:\windows\system32\msasn1.dll

                          c:\windows\system32\imagehlp.dll

                          c:\windows\system32\msdmo.dll

                          c:\windows\system32\wdmaud.drv

                          c:\windows\system32\msacm32.drv

                          c:\windows\system32\msacm32.dll

                          c:\windows\system32\midimap.dll

                          c:\windows\system32\qcap.dll

                          c:\windows\system32\msvfw32.dll

                          c:\program files\asus\gamerosd\imagetransform.dll

                          c:\windows\system32\quartz.dll

                          c:\windows\system32\msctf.dll

                          c:\windows\system32\ksproxy.ax

                          c:\windows\system32\ksuser.dll

                          c:\windows\system32\vidcap.ax

                          c:\windows\system32\atl.dll

                          c:\windows\system32\imaadp32.acm

                          c:\windows\system32\msadp32.acm

                          c:\windows\system32\msg711.acm

                          c:\windows\system32\msgsm32.acm

                          c:\windows\system32\tssoft32.acm

                          c:\windows\system32\tsd32.dll

                          c:\windows\system32\msg723.acm

                          c:\windows\system32\msaud32.acm

                          c:\windows\system32\sl_anet.acm

                          c:\windows\system32\iac25_32.ax

                          c:\windows\system32\l3codecp.acm

                          c:\windows\system32\sirenacm.dll

                          c:\windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\msvcr80.dll

                          c:\windows\system32\dsound.dll

                          c:\windows\system32\ddraw.dll

                          c:\windows\system32\dciman32.dll

                          c:\windows\system32\d3dim700.dll

                          C:\WINDOWS\RTHDCPL.EXE
                          c:\windows\rthdcpl.exe

                          c:\windows\system32\ntdll.dll

                          c:\windows\system32\kernel32.dll

                          c:\windows\system32\dsound.dll

                          c:\windows\system32\advapi32.dll

                          c:\windows\system32\rpcrt4.dll

                          c:\windows\system32\secur32.dll

                          c:\windows\system32\msvcrt.dll

                          c:\windows\system32\ole32.dll

                          c:\windows\system32\gdi32.dll

                          c:\windows\system32\user32.dll

                          c:\windows\system32\version.dll

                          c:\windows\system32\winmm.dll

                          c:\windows\system32\hhctrl.ocx

                          c:\windows\system32\shell32.dll

                          c:\windows\system32\shlwapi.dll

                          c:\windows\system32\comctl32.dll

                          c:\windows\system32\oleaut32.dll

                          c:\windows\system32\setupapi.dll

                          c:\windows\system32\mpr.dll

                          c:\windows\system32\winspool.drv

                          c:\windows\system32\comdlg32.dll

                          c:\windows\system32\imm32.dll

                          c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll

                          c:\windows\system32\mui\000c\hhctrlui.dll

                          c:\windows\system32\uxtheme.dll

                          c:\windows\system32\msctfime.ime

                          c:\windows\system32\wintrust.dll

                          c:\windows\system32\crypt32.dll

                          c:\windows\system32\msasn1.dll

                          c:\windows\system32\imagehlp.dll

                          c:\windows\system32\wdmaud.drv

                          c:\windows\system32\msacm32.drv

                          c:\windows\system32\msacm32.dll

                          c:\windows\system32\midimap.dll

                          c:\windows\system32\msctf.dll

                          c:\windows\system32\ksuser.dll

                          C:\WINDOWS\SYSTEM32\RUNDLL32.EXE
                          c:\windows\system32\rundll32.exe

                          c:\windows\system32\ntdll.dll

                          c:\windows\system32\kernel32.dll

                          c:\windows\system32\msvcrt.dll

                          c:\windows\system32\gdi32.dll

                          c:\windows\system32\user32.dll

                          c:\windows\system32\imagehlp.dll

                          c:\windows\system32\shimeng.dll

                          c:\windows\apppatch\acgenral.dll

                          c:\windows\system32\advapi32.dll

                          c:\windows\system32\rpcrt4.dll

                          c:\windows\system32\secur32.dll

                          c:\windows\system32\winmm.dll

                          c:\windows\system32\ole32.dll

                          c:\windows\system32\oleaut32.dll

                          c:\windows\system32\msacm32.dll

                          c:\windows\system32\version.dll

                          c:\windows\system32\shell32.dll

                          c:\windows\system32\shlwapi.dll

                          c:\windows\system32\userenv.dll

                          c:\windows\system32\uxtheme.dll

                          c:\windows\system32\imm32.dll

                          c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll

                          c:\windows\system32\comctl32.dll

                          c:\windows\system32\nvmctray.dll

                          c:\windows\system32\nvapi.dll

                          c:\windows\system32\setupapi.dll

                          c:\windows\system32\msctfime.ime

                          c:\windows\system32\nvrsfr.dll

                          c:\windows\system32\msctf.dll

                          C:\PROGRAM FILES\ACRONIS\TRUEIMAGEHOME\TRUEIMAGEMONITOR.EXE
                          c:\program files\acronis\trueimagehome\trueimagemonitor.exe

                          c:\windows\system32\ntdll.dll

                          c:\windows\system32\kernel32.dll

                          c:\windows\system32\advapi32.dll

                          c:\windows\system32\rpcrt4.dll

                          c:\windows\system32\secur32.dll

                          c:\windows\system32\user32.dll

                          c:\windows\system32\gdi32.dll

                          c:\windows\system32\shell32.dll

                          c:\windows\system32\msvcrt.dll

                          c:\windows\system32\shlwapi.dll

                          c:\windows\system32\comdlg32.dll

                          c:\windows\system32\comctl32.dll

                          c:\windows\system32\mpr.dll

                          c:\windows\system32\ole32.dll

                          c:\windows\system32\version.dll

                          c:\windows\system32\msvcp71.dll

                          c:\windows\system32\msvcr71.dll

                          c:\windows\system32\snapapi.dll

                          c:\windows\system32\oleaut32.dll

                          c:\windows\system32\imm32.dll

                          c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll

                          c:\program files\fichiers communs\acronis\common\resource.dll

                          c:\program files\fichiers communs\acronis\common\gc.dll

                          c:\windows\system32\uxtheme.dll

                          c:\windows\system32\apphelp.dll

                          c:\windows\system32\msctfime.ime

                          c:\windows\system32\rsaenh.dll

                          c:\windows\system32\msctf.dll

                          c:\program files\fichiers communs\acronis\fomatik\tdrpapi.dll

                          c:\windows\system32\ntmarta.dll

                          c:\windows\system32\samlib.dll

                          c:\windows\system32\wldap32.dll

                          c:\program files\fichiers communs\acronis\common\rpc_client.dll

                          C:\PROGRAM FILES\ACRONIS\TRUEIMAGEHOME\TIMOUNTERMONITOR.EXE
                          c:\program files\acronis\trueimagehome\timountermonitor.exe

                          c:\windows\system32\ntdll.dll

                          c:\windows\system32\kernel32.dll

                          c:\program files\acronis\trueimagehome\fox.dll

                          c:\windows\system32\advapi32.dll

                          c:\windows\system32\rpcrt4.dll

                          c:\windows\system32\secur32.dll

                          c:\windows\system32\user32.dll

                          c:\windows\system32\gdi32.dll

                          c:\windows\system32\comctl32.dll

                          c:\windows\system32\shell32.dll

                          c:\windows\system32\msvcrt.dll

                          c:\windows\system32\shlwapi.dll

                          c:\windows\system32\comdlg32.dll

                          c:\windows\system32\msvcp71.dll

                          c:\windows\system32\msvcr71.dll

                          c:\windows\system32\mpr.dll

                          c:\windows\system32\ole32.dll

                          c:\windows\system32\version.dll

                          c:\windows\system32\imm32.dll

                          c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll

                          c:\windows\system32\hhctrl.ocx

                          c:\windows\system32\oleaut32.dll

                          c:\windows\system32\mui\000c\hhctrlui.dll

                          c:\windows\system32\msimg32.dll

                          c:\program files\fichiers communs\acronis\common\icu34.dll

                          c:\program files\fichiers communs\acronis\common\icudt34.dll

                          c:\windows\system32\uxtheme.dll

                          c:\windows\system32\apphelp.dll

                          c:\windows\system32\msctfime.ime

                          c:\windows\system32\msctf.dll

                          C:\PROGRAM FILES\FICHIERS COMMUNS\ACRONIS\SCHEDULE2\SCHEDHLP.EXE
                          c:\program files\fichiers communs\acronis\schedule2\schedhlp.exe

                          c:\windows\system32\ntdll.dll

                          c:\windows\system32\kernel32.dll

                          c:\windows\system32\rpcrt4.dll

                          c:\windows\system32\advapi32.dll

                          c:\windows\system32\secur32.dll

                          c:\windows\system32\user32.dll

                          c:\windows\system32\gdi32.dll

                          c:\windows\system32\shell32.dll

                          c:\windows\system32\msvcrt.dll

                          c:\windows\system32\shlwapi.dll

                          c:\windows\system32\comdlg32.dll

                          c:\windows\system32\comctl32.dll

                          c:\windows\system32\version.dll

                          c:\windows\system32\imm32.dll

                          c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll

                          c:\windows\system32\uxtheme.dll

                          c:\windows\system32\apphelp.dll

                          c:\windows\system32\msctfime.ime

                          c:\windows\system32\ole32.dll

                          c:\windows\system32\msctf.dll

                          C:\WINDOWS\SYSTEM32\CTFMON.EXE
                          c:\windows\system32\ctfmon.exe

                          c:\windows\system32\ntdll.dll

                          c:\windows\system32\kernel32.dll

                          c:\windows\system32\msvcrt.dll

                          c:\windows\system32\advapi32.dll

                          c:\windows\system32\rpcrt4.dll

                          c:\windows\system32\secur32.dll

                          c:\windows\system32\user32.dll

                          c:\windows\system32\gdi32.dll

                          c:\windows\system32\msctf.dll

                          c:\windows\system32\msutb.dll

                          c:\windows\system32\shimeng.dll

                          c:\windows\apppatch\acgenral.dll

                          c:\windows\system32\winmm.dll

                          c:\windows\system32\ole32.dll

                          c:\windows\system32\oleaut32.dll

                          c:\windows\system32\msacm32.dll

                          c:\windows\system32\version.dll

                          c:\windows\system32\shell32.dll

                          c:\windows\system32\shlwapi.dll

                          c:\windows\system32\userenv.dll

                          c:\windows\system32\uxtheme.dll

                          c:\windows\system32\imm32.dll

                          c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll

                          c:\windows\system32\msctfime.ime

                          C:\PROGRAM FILES\WINDOWS LIVE\MESSENGER\MSNMSGR.EXE
                          c:\program files\windows live\messenger\msnmsgr.exe

                          c:\windows\system32\ntdll.dll

                          c:\windows\system32\kernel32.dll

                          c:\windows\system32\advapi32.dll

                          c:\windows\system32\rpcrt4.dll

                          c:\windows\system32\secur32.dll

                          c:\windows\system32\gdi32.dll

                          c:\windows\system32\user32.dll

                          c:\windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\msvcr80.dll

                          c:\windows\system32\msvcrt.dll

                          c:\windows\system32\wsock32.dll

                          c:\windows\system32\ws2_32.dll

                          c:\windows\system32\ws2help.dll

                          c:\windows\system32\shell32.dll

                          c:\windows\system32\shlwapi.dll

                          c:\windows\system32\ole32.dll

                          c:\windows\system32\oleaut32.dll

                          c:\windows\system32\msimg32.dll

                          c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.2600.5512_x-ww_dfb54e0c\gdiplus.dll

                          c:\program files\windows live\messenger\msncore.dll

                          c:\windows\system32\urlmon.dll

                          c:\windows\system32\iertutil.dll

                          c:\windows\system32\wininet.dll

                          c:\windows\system32\normaliz.dll

                          c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll

                          c:\windows\system32\oleacc.dll

                          c:\windows\system32\msvcp60.dll

                          c:\windows\system32\uxtheme.dll

                          c:\windows\system32\imm32.dll

                          c:\windows\system32\crypt32.dll

                          c:\windows\system32\msasn1.dll

                          c:\windows\system32\version.dll

                          c:\windows\system32\winmm.dll

                          c:\windows\system32\iphlpapi.dll

                          c:\windows\system32\msacm32.dll

                          c:\program files\windows live\messenger\msidcrl40.dll

                          c:\windows\system32\sensapi.dll

                          c:\windows\system32\psapi.dll

                          c:\windows\system32\wintrust.dll

                          c:\windows\system32\imagehlp.dll

                          c:\program files\windows live\messenger\contactsux.dll

                          c:\windows\system32\setupapi.dll

                          c:\windows\system32\cryptnet.dll

                          c:\windows\system32\userenv.dll

                          c:\windows\system32\winhttp.dll

                          c:\windows\system32\wldap32.dll

                          c:\windows\system32\msctf.dll

                          c:\windows\system32\xpsp2res.dll

                          c:\windows\system32\rsaenh.dll

                          c:\windows\system32\inetcomm.dll

                          c:\windows\system32\msoert2.dll

                          c:\windows\system32\inetres.dll

                          c:\windows\system32\clbcatq.dll

                          c:\windows\system32\comres.dll

                          c:\program files\windows live\messenger\msgslang.8.5.1302.1018.dll

                          c:\program files\windows live\messenger\msgsres.dll

                          c:\windows\system32\apphelp.dll

                          c:\windows\system32\msctfime.ime

                          c:\windows\system32\wtsapi32.dll

                          c:\windows\system32\winsta.dll

                          c:\windows\system32\netapi32.dll

                          c:\windows\system32\es.dll

                          c:\windows\system32\sxs.dll

                          c:\program files\windows live\messenger\msgswcam.dll

                          c:\windows\system32\sirenacm.dll

                          c:\windows\system32\devenum.dll

                          c:\windows\system32\msdmo.dll

                          c:\windows\system32\ksproxy.ax

                          c:\windows\system32\ksuser.dll

                          c:\windows\system32\vidcap.ax

                          c:\windows\system32\atl.dll

                          c:\windows\system32\riched20.dll

                          c:\windows\system32\msimtf.dll

                          C:\WINDOWS\SYSTEM32\SPOOLSV.EXE
                          c:\windows\system32\spoolsv.exe

                          c:\windows\system32\ntdll.dll

                          c:\windows\system32\kernel32.dll

                          c:\windows\system32\advapi32.dll

                          c:\windows\system32\rpcrt4.dll

                          c:\windows\system32\secur32.dll

                          c:\windows\system32\gdi32.dll

                          c:\windows\system32\user32.dll

                          c:\windows\system32\msvcrt.dll

                          c:\windows\system32\shimeng.dll

                          c:\windows\apppatch\acgenral.dll

                          c:\windows\system32\winmm.dll

                          c:\windows\system32\ole32.dll

                          c:\windows\system32\oleaut32.dll

                          c:\windows\system32\msacm32.dll

                          c:\windows\system32\version.dll

                          c:\windows\system32\shell32.dll

                          c:\windows\system32\shlwapi.dll

                          c:\windows\system32\userenv.dll

                          c:\windows\system32\uxtheme.dll

                          c:\windows\system32\imm32.dll

                          c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll

                          c:\windows\system32\comctl32.dll

                          c:\windows\system32\spoolss.dll

                          c:\windows\system32\ws2_32.dll

                          c:\windows\system32\ws2help.dll

                          c:\windows\system32\dnsapi.dll

                          c:\windows\system32\rasadhlp.dll

                          c:\windows\system32\localspl.dll

                          c:\windows\system32\sfc_os.dll

                          c:\windows\system32\wintrust.dll

                          c:\windows\system32\crypt32.dll

                          c:\windows\system32\msasn1.dll

                          c:\windows\system32\imagehlp.dll

                          c:\windows\system32\winspool.drv

                          c:\windows\system32\netapi32.dll

                          c:\windows\system32\cnbjmon.dll

                          c:\windows\system32\mdimon.dll

                          c:\windows\system32\msi.dll

                          c:\windows\system32\pjlmon.dll

                          c:\windows\system32\tcpmon.dll

                          c:\windows\system32\usbmon.dll

                          c:\windows\system32\spool\prtprocs\w32x86\mdippr.dll

                          c:\windows\system32\mswsock.dll

                          c:\windows\system32\winrnr.dll

                          c:\windows\system32\wldap32.dll

                          c:\windows\system32\win32spl.dll

                          c:\windows\system32\netrap.dll

                          c:\windows\system32\ntdsapi.dll

                          c:\windows\system32\clbcatq.dll

                          c:\windows\system32\comres.dll

                          c:\windows\system32\inetpp.dll

                          c:\windows\system32\xpsp2res.dll

                          C:\PROGRAM FILES\FICHIERS COMMUNS\ACRONIS\SCHEDULE2\SCHEDUL2.EXE
                          c:\program files\fichiers communs\acronis\schedule2\schedul2.exe

                          c:\windows\system32\ntdll.dll

                          c:\windows\system32\kernel32.dll

                          c:\windows\system32\rpcrt4.dll

                          c:\windows\system32\advapi32.dll

                          c:\windows\system32\secur32.dll

                          c:\windows\system32\user32.dll

                          c:\windows\system32\gdi32.dll

                          c:\windows\system32\shell32.dll

                          c:\windows\system32\msvcrt.dll

                          c:\windows\system32\shlwapi.dll

                          c:\windows\system32\comdlg32.dll

                          c:\windows\system32\comctl32.dll

                          c:\windows\system32\mpr.dll

                          c:\windows\system32\ole32.dll

                          c:\windows\system32\version.dll

                          c:\windows\system32\imm32.dll

                          c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll

                          c:\windows\system32\ntmarta.dll

                          c:\windows\system32\samlib.dll

                          c:\windows\system32\wldap32.dll

                          C:\PROGRAM FILES\FICHIERS COMMUNS\APPLE\MOBILE DEVICE SUPPORT\BIN\APPLEMOBILEDEVICESERVICE.EXE
                          c:\program files\fichiers communs\apple\mobile device support\bin\applemobiledeviceservice.exe

                          c:\windows\system32\ntdll.dll

                          c:\windows\system32\kernel32.dll

                          c:\windows\system32\wsock32.dll

                          c:\windows\system32\ws2_32.dll

                          c:\windows\system32\advapi32.dll

                          c:\windows\system32\rpcrt4.dll

                          c:\windows\system32\secur32.dll

                          c:\windows\system32\msvcrt.dll

                          c:\windows\system32\ws2help.dll

                          c:\windows\system32\setupapi.dll

                          c:\windows\system32\gdi32.dll

                          c:\windows\system32\user32.dll

                          c:\windows\system32\imm32.dll

                          c:\windows\system32\mswsock.dll

                          c:\windows\system32\hnetcfg.dll

                          c:\windows\system32\wshtcpip.dll

                          c:\windows\system32\wintrust.dll

                          c:\windows\system32\crypt32.dll

                          c:\windows\system32\msasn1.dll

                          c:\windows\system32\imagehlp.dll

                          C:\WINDOWS\ATKKBSERVICE.EXE
                          c:\windows\atkkbservice.exe

                          c:\windows\system32\ntdll.dll

                          c:\windows\system32\kernel32.dll

                          c:\windows\system32\advapi32.dll

                          c:\windows\system32\rpcrt4.dll

                          c:\windows\system32\secur32.dll

                          c:\windows\system32\gdi32.dll

                          c:\windows\system32\user32.dll

                          c:\windows\system32\setupapi.dll

                          c:\windows\system32\msvcrt.dll

                          c:\windows\system32\imm32.dll

                          c:\windows\system32\uxtheme.dll

                          c:\windows\system32\msctfime.ime

                          c:\windows\system32\ole32.dll

                          c:\windows\system32\nvapi.dll

                          c:\windows\system32\oleaut32.dll

                          c:\windows\system32\shlwapi.dll

                          c:\windows\system32\shell32.dll

                          c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll

                          c:\windows\system32\comctl32.dll

                          C:\PROGRAM FILES\SYMANTEC\NORTON GHOST 2003\GHOSTSTARTSERVICE.EXE
                          c:\program files\symantec\norton ghost 2003\ghoststartservice.exe

                          c:\windows\system32\ntdll.dll

                          c:\windows\system32\kernel32.dll

                          c:\windows\system32\user32.dll

                          c:\windows\system32\gdi32.dll

                          c:\windows\system32\advapi32.dll

                          c:\windows\system32\rpcrt4.dll

                          c:\windows\system32\secur32.dll

                          c:\windows\system32\ole32.dll

                          c:\windows\system32\msvcrt.dll

                          c:\windows\system32\oleaut32.dll

                          c:\windows\system32\imm32.dll

                          c:\windows\system32\uxtheme.dll

                          c:\windows\system32\xpsp2res.dll

                          c:\windows\system32\clbcatq.dll

                          c:\windows\system32\comres.dll

                          c:\windows\system32\version.dll

                          C:\WINDOWS\SYSTEM32\NVSVC32.EXE
                          c:\windows\system32\nvsvc32.exe

                          c:\windows\system32\ntdll.dll

                          c:\windows\system32\kernel32.dll

                          c:\windows\system32\user32.dll

                          c:\windows\system32\gdi32.dll

                          c:\windows\system32\advapi32.dll

                          c:\windows\system32\rpcrt4.dll

                          c:\windows\system32\secur32.dll

                          c:\windows\system32\userenv.dll

                          c:\windows\system32\msvcrt.dll

                          c:\windows\system32\powrprof.dll

                          c:\windows\system32\imm32.dll

                          c:\windows\system32\wtsapi32.dll

                          c:\windows\system32\winsta.dll

                          c:\windows\system32\netapi32.dll

                          c:\windows\system32\shell32.dll

                          c:\windows\system32\shlwapi.dll

                          c:\windows\system32\ole32.dll

                          c:\windows\system32\comctl32.dll

                          c:\windows\system32\oleaut32.dll

                          c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll

                          c:\windows\system32\nvapi.dll

                          c:\windows\system32\setupapi.dll

                          c:\windows\system32\uxtheme.dll

                          c:\windows\system32\msctfime.ime

                          c:\windows\system32\wintrust.dll

                          c:\windows\system32\crypt32.dll

                          c:\windows\system32\msasn1.dll

                          c:\windows\system32\imagehlp.dll

                          c:\windows\system32\msv1_0.dll

                          c:\windows\system32\iphlpapi.dll

                          c:\windows\system32\ws2_32.dll

                          c:\windows\system32\ws2help.dll

                          c:\windows\system32\apphelp.dll

                          c:\windows\system32\version.dll

                          c:\windows\system32\ntmarta.dll

                          c:\windows\system32\samlib.dll

                          c:\windows\system32\wldap32.dll

                          C:\PROGRAM FILES\SPYWARE TERMINATOR\SP_RSSER.EXE
                          c:\program files\spyware terminator\sp_rsser.exe

                          c:\windows\system32\ntdll.dll

                          c:\windows\system32\kernel32.dll

                          c:\windows\system32\oleaut32.dll
                          0
                      2. Contributeur sécurité
                        fix cette ligne:
                        O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)

                        tu n'as pas désactivé le tea timer? cela va ramer avec spyware terminator!
                        0
                        1. je la répare comment???
                          0
                      3. Contributeur sécurité
                        Relance HijackThis, choisis "do a scan only" coche la case devant les lignes ci-dessous et clic en bas sur "fix checked".

                        O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)

                        ________

                        tu n'as pas désactivé le tea timer? cela va ramer avec spyware terminator!

                        encore des soucis???
                        0
                        1. si j ai supprimé spybot, ok je lance hijackthis

                          c était tout ce qui n'allait pas ce fichier?
                          0
                        2. @herby2475voila je l ai supprimé et mantenant ? c est réglé?
                          0
                      4. c était quoi finalement un vers msn? ou quoi?
                        je dois refaire une image du disque dur ou pas besoin?
                        0
                        1. Contributeur sécurité
                          tu pouvais gardé spybot mais désactiver le tea timer qui fais une analyse en temps réel et donc avec spyware terminator c'est lours!!

                          un souci avec msn?

                          Télécharge MSNFix de Laurent
                          http://sosvirus.changelog.fr/MSNFix.zip

                          Décompresse-le et double clic sur le fichier MSNFix.bat.
                          - Exécute l'option R.
                          --Si l'infection est détectée, exécute l'option N
                          - Sauvegarde ce rapport puis fais un copier/coller de ce rapport sur le forum.

                          Note :
                          Si une erreur de suppression est détectée un message s'affichera demandant de redémarrer l'ordinateur afin de terminer les opérations. Dans ce cas il suffit de redémarrer l'ordinateur en mode normal
                          Sauvegarder et fermer le rapport pour que Windows termine de se lancer normalement.

                          envoyer le fichier [b] C:\DOCUME~1\florian\Bureau\Upload_Me.zip /b sur http://upload.changelog.fr pour faire evoluer msnfix
                          0
                          1. voici le message
                            MSNFix 1.732

                            C:\Documents and Settings\reverend\Bureau\MSNFix
                            Fix exécuté le 15/07/2008 - 22:44:56,00 By reverend
                            mode normal

                            ************************ Recherche les fichiers présents

                            Aucun Fichier trouvé

                            ************************ Recherche les dossiers présents

                            Aucun dossier trouvé

                            ************************ Fichiers suspects

                            Aucun Fichier trouvé

                            ************************ HKLM\...\Winlogon\Userinit

                            Userinit = C:\WINDOWS\system32\userinit.exe,

                            Important : http://msnfix.changelog.fr/index.php/2008/05/18/32-alerte

                            ------------------------------------------------------------------------
                            Auteur : !aur3n7 Contact: https://www.ionos.fr/
                            ------------------------------------------------------------------------

                            --------------------------------------------- END ---------------------------------------------
                            0
                          2. slt jlpjlp,

                            peux tu juste me confirmer si après tout ces scan le pc est normalement desinfecté au vu de rapport que je t ai envoyé? car tout semble bien marcher a présent internet fonctionne très bien et plus de messages suspect, je souhaite vraiment si c est le cas faire une copie de mon disque dur,

                            merci encore pour ton aide
                            a+
                            0
                        2. ok merci pour ta réponse , je n'ai pour l instant plus aucun messages suspect, est que ça eux dire que le pc est sain maintenant?
                          dois je refaire une image du pc? ou l'ancienne ne comportait sans doute aucun probleme?
                          0
                          1. Contributeur sécurité
                            ok c'est bon

                            désactive ta restauration puis redemarre puis réactive la pour purger ce qu'il y a dedans:
                            http://service1.symantec.com/SUPPORT/INTER/tsgeninfointl.nsf/fdocid/20020830101856924

                            ____

                            utlisie tools cleaner pour virer ce que l'on a utilisé et après tu peux refaire une image disque

                            http://www.commentcamarche.net/telecharger/telecharger 34055291 toolscleaner
                            0
                            1. slt jlp jlp,

                              bon je tiens tout d abord a te remercier pour le temps que tu as passé a analyser tout mes problemes, vraiment sympa de ta part, je saurais pour la prochaine fois ou trouver des solution a mes problemes PC,

                              bonne journée et merci encore,

                              PS: le probleme venait d ou en fait? messenger? ou ailleurs?

                              a+++
                              0
                          • 1
                          • 2