Euh... c'est chaud la je crois...!

Bonjour,

et bien je fais appel a vous car j'ai vu qu'il semblait y avoir plein de gens calés en virus etc...!
Moi, je suis sur que j'en ai pleins car mon ordi galere de plus en plus!!!
Mais je ne sais pas comment faire, quel scan utiliser et je sais encore moins les interpreter...

Voila voila quoi, si quelqu'un pourrait m'aider a resoudres ces problemes de virus a la con ca serait bien cool!
Configuration: Windows XP
Firefox 2.0.0.17

17 réponses

  1. Telecharge malwarebytes

    Tu l´instale; le programme va se mettre automatiquement a jour.

    Une fois a jour, le programme va se lancer; click sur l´onglet parametre, et coche la case : "Arreter internet explorer pendant la suppression".

    Click maintenant sur l´onglet recherche et coche la case : "executer un examen complet".

    Puis click sur "rechercher".

    Laisse le scanner le pc...

    Si des elements on ete trouvés > click sur supprimer la selection.

    si il t´es demandé de redemarrer > click sur "yes".

    A la fin un rapport va s´ouvrir; sauvegarde le de maniere a le retrouver en vu de le poster sur le forum.

    Copie et colle le rapport stp.

    PS : les rapport sont aussi rangé dans l onglet rapport/log
    1
    1. ok. quand je veux ouvrir hijack ca me met un message comme quoi l'application n'est pas une application valide win32, donc je ne peux pas ouvrir hijack...
      0
      1. ok, merci, voila ce que ca donne:

        ----------------- FindyKill V4.005 ------------------

        * User : ben - XPSP2-85BA31B6A
        * Emplacement : C:\Program Files\FindyKill
        * Outils Mis a jours le 17/10/08 par Chiquitine29
        * Recherche effectuée à 0:30:04 le 19/10/2008
        * Windows XP - Internet Explorer 6.0.2900.2180

        ((((((((((((((((( *** Recherche *** ))))))))))))))))))

        --------------- [ Processus actifs ] ----------------

        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\csrss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
        C:\Acer\Empowering Technology\admServ.exe
        C:\WINDOWS\system32\nvsvc32.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\wanmpsvc.exe
        C:\WINDOWS\Explorer.EXE
        C:\PROGRA~1\LAUNCH~1\LManager.exe
        C:\Program Files\Fichiers communs\AOL\1203807828\ee\aolsoftware.exe
        C:\Acer\Empowering Technology\admtray.exe
        C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
        C:\WINDOWS\system32\RUNDLL32.EXE
        C:\WINDOWS\system32\svchost.exe
        C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
        C:\WINDOWS\system32\drivers\hldrrr.exe
        C:\Program Files\Kiwee Toolbar2\1.5.131\kwtbaim.exe
        C:\Program Files\Real\RealPlayer\RealPlay.exe
        C:\Program Files\Windows Live\Messenger\msnmsgr.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe
        C:\WINDOWS\system32\drivers\hldrrr.exe
        C:\Program Files\AOL 9.0b\aoltray.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\wintems.exe
        C:\Documents and Settings\ben\Application Data\m\flec006.exe
        C:\Program Files\Mozilla Firefox\firefox.exe
        C:\WINDOWS\system32\msiexec.exe
        C:\WINDOWS\RTHDCPL.EXE
        C:\DOCUME~1\ben\LOCALS~1\Temp\RtkBtMnt.exe
        C:\WINDOWS\Explorer.EXE
        C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
        C:\WINDOWS\system32\wbem\wmiprvse.exe
        C:\Program Files\Fichiers communs\Intel\WirelessCommon\RegSrvc.exe
        C:\Program Files\Intel\WiFi\bin\EvtEng.exe
        C:\Program Files\Intel\WiFi\bin\S24EvMon.exe
        C:\Program Files\Intel\WiFi\bin\ZCfgsvc.exe
        C:\WINDOWS\system32\wbem\unsecapp.exe
        C:\Program Files\Fichiers communs\Intel\WirelessCommon\ifrmewrk.exe
        C:\WINDOWS\system32\wbem\wmiprvse.exe

        --------------- [ Processus infectieux stoppés ] ----------------

        "C:\WINDOWS\system32\drivers\hldrrr.exe" (2088)
        "C:\WINDOWS\system32\drivers\hldrrr.exe" (2496)
        "C:\WINDOWS\system32\wintems.exe" (2976)
        "C:\Documents and Settings\ben\Application Data\m\flec006.exe" (4068)

        --------------- [ Fichiers/Dossiers infectieux ] ----------------

        »»»» Presence des fichiers dans C:

        Présent ! - C:\InfoSat.txt

        »»»» Presence des fichiers dans C:\WINDOWS

        »»»» Presence des fichiers dans C:\WINDOWS\Prefetch

        Present ! - C:\WINDOWS\prefetch\HLDRRR.EXE-106798BB.pf

        »»»» Presence des fichiers dans C:\WINDOWS\system32

        Présent ! - C:\WINDOWS\system32\mdelk.exe
        Présent ! - C:\WINDOWS\system32\wintems.exe
        Présent ! - C:\WINDOWS\system32\ban_list.txt

        »»»» Presence des fichiers dans C:\WINDOWS\system32\drivers

        Présent ! - C:\WINDOWS\system32\drivers\srosa.sys
        Présent ! - C:\WINDOWS\system32\drivers\hldrrr.exe
        Présent ! - "C:\WINDOWS\system32\drivers\downld"
        Present ! - C:\WINDOWS\system32\drivers\downld\182640.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\202750.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\208250.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\314140.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\323500.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\339750.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\345000.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\347140.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\397140.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\41358890.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\41467750.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\580500.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\142531.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\169781.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\177671.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\180171.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\197421.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\241781.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\246031.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\248781.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\253171.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\301281.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\309531.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\331171.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\361671.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\41394671.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\41431671.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\41443171.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\41447671.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\134812.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\187562.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\277312.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\321312.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\480312.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\142703.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\195703.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\209593.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\227843.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\298343.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\331453.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\346703.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\41396593.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\41415343.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\41568093.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\622453.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\198984.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\243984.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\300734.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\41332484.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\176765.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\205265.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\206265.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\217015.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\256515.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\270015.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\316875.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\368765.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\41366515.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\41421765.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\41491265.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\550765.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\121546.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\151406.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\154046.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\183046.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\196046.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\199406.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\206406.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\229906.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\267656.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\41313656.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\41452156.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\451906.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\539156.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\593656.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\177687.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\182187.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\212187.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\41280937.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\41353937.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\138578.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\155468.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\167578.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\183078.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\195218.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\223328.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\224468.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\248328.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\249468.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\267078.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\291968.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\41281828.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\41316218.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\41341328.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\41346218.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\41592468.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\632718.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\117359.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\158359.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\165859.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\232609.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\270359.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\425859.exe
        Present ! - C:\WINDOWS\system32\drivers\downld\515109.exe

        »»»» Presence des fichiers dans C:\Documents and Settings\ben\Application Data

        Présent ! - "C:\Documents and Settings\ben\Application Data\m\flec006.exe"
        Présent ! - "C:\Documents and Settings\ben\Application Data\m\list.oct"
        Présent ! - "C:\Documents and Settings\ben\Application Data\m\data.oct"
        Présent ! - "C:\Documents and Settings\ben\Application Data\m\srvlist.oct"
        Présent ! - "C:\Documents and Settings\ben\Application Data\m\shared"
        Présent ! - "C:\Documents and Settings\ben\Application Data\m"

        »»»» Presence des fichiers dans C:\DOCUME~1\ben\LOCALS~1\Temp

        --------------- [ Registre / Startup ] ----------------

        ! REG.EXE VERSION 3.0

        HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
        AOLSAV REG_SZ C:\PROGRA~1\TECHCI~1\AOLSAV\AOLAgent.exe
        AOLDialer REG_SZ "C:\Program Files\Fichiers communs\AOL\ACS\AOLDial.exe"
        LManager REG_SZ C:\PROGRA~1\LAUNCH~1\LManager.exe
        ADMTray.exe REG_SZ "C:\Acer\Empowering Technology\admtray.exe"
        SynTPEnh REG_SZ "C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
        NvCplDaemon REG_SZ "RUNDLL32.EXE" C:\WINDOWS\system32\NvCpl.dll,NvStartup
        nwiz REG_SZ "nwiz.exe" /install
        NvMediaCenter REG_SZ "RUNDLL32.EXE" C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
        RTHDCPL REG_SZ RTHDCPL.EXE
        SkyTel REG_SZ SkyTel.EXE
        AzMixerSel REG_SZ "C:\Program Files\Realtek\InstallShield\AzMixerSel.exe"
        eDataSecurity Loader REG_SZ "C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe"
        HostManager REG_SZ "C:\Program Files\Fichiers communs\AOL\1203807828\ee\AOLSoftware.exe"
        SunJavaUpdateSched REG_SZ "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
        QuickTime Task REG_SZ "C:\Program Files\QuickTime\QTTask.exe" -atboottime
        KiweeHook REG_SZ "C:\Program Files\Kiwee Toolbar2\1.5.131\kwtbaim.exe"
        Adobe Reader Speed Launcher REG_SZ "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
        RealTray REG_SZ C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
        BVRPLiveUpdate REG_SZ C:\Program Files\Avanquest update\Engine\Setup.exe -s /PATCH,/SRCUPDATEC:\DOCUME~1\ALLUSE~1\APPLIC~1\SONYER~1\SONYER~1\LIVEUP~1\LISTOF~1.DAT
        NBKeyScan REG_SZ "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
        avast! REG_SZ C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
        IntelZeroConfig REG_SZ "C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe"
        IntelWireless REG_SZ "C:\Program Files\Fichiers communs\Intel\WirelessCommon\iFrmewrk.exe" /tf Intel Wireless Tray

        HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents

        ! REG.EXE VERSION 3.0

        HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
        MsnMsgr REG_SZ "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
        ares REG_SZ "C:\Program Files\Ares\Ares.exe" -h
        ctfmon.exe REG_SZ C:\WINDOWS\system32\ctfmon.exe
        Sony Ericsson PC Suite REG_SZ "C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe" /systray /nologon
        BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} REG_SZ "C:\Program Files\Fichiers communs\Nero\Lib\NMBgMonitor.exe"
        Google Update REG_SZ "C:\Documents and Settings\ben\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c

        --------------- [ Registre / Clés infectieuses ] ----------------

        Présent ! - HKEY_USERS\S-1-5-21-796845957-1123561945-725345543-1003\Software\Local AppWizard-Generated Applications\hldrrr
        Présent ! - HKEY_USERS\S-1-5-21-796845957-1123561945-725345543-1003\Software\bisoft
        Présent ! - HKEY_USERS\S-1-5-21-796845957-1123561945-725345543-1003\Software\DateTime4
        Présent ! - HKEY_USERS\S-1-5-21-796845957-1123561945-725345543-1003\Software\FirtR
        Présent ! - HKEY_USERS\S-1-5-21-796845957-1123561945-725345543-1003\Software\MuleAppData
        Présent ! - HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\hldrrr
        Présent ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\srosa
        Présent ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\srosa
        Présent ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\srosa
        Présent ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA
        Présent ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_SROSA
        Présent ! - HKEY_CURRENT_USER\Software\bisoft
        Présent ! - HKEY_CURRENT_USER\Software\DateTime4
        Présent ! - HKEY_CURRENT_USER\Software\FirtR

        --------------- [ Etat / Services ] ----------------

        +- Services : [ Auto=2 Demande=3 Désactivé=4 ]

        /!\ Ndisuio - Type de démarrage = 4

        /!\ Ip6Fw - Type de démarrage = 4

        /!\ SharedAccess - Type de démarrage = 4

        /!\ wuauserv - Type de démarrage = 4

        /!\ wscsvc - Type de démarrage = 4

        --------------- [ Recherche dans supports amovibles] ----------------

        +- Informations :

        C: - Lecteur fixe

        +- presence des fichiers :

        --------------- [ Registre / Moutpoint2 ] ----------------

        -> Recherche négative.

        ------------------- ! Fin du rapport ! --------------------
        0
        1. euh ca ne marche pas...
          en fait il me dit d'appuyer sur une touche pour commencer l'elimination et que ca va redemarrer *2 fois.
          donc la j'appuie sur une touche, et puis tu sais ca me fait comme un bug, c'est a dire qu'une page bleue avec des ecritures blanches s'affiche une demi seconde et ca fai redemarrer l'ordi, mais a la normale pas avec findy kill. genre l'ordi a bugé et redemarre quoi? tu vois ce que je veux dire?

          j'ai pu apercevoir sur cette page bleue un message qui dit que le probleme peut etre causé par le fichier srosa.sys
          0
          1. Salut,

            ça peux arriver srosa.sys fait partie de l infection , réitère l option 2 stp

            @+
            0
            1. Modérateur
              Merci t'chiki.
              -1
          2. ouai je reessaye d'accord. mais j'ai deja réessayé deux fois et ca a fait pareil snifffffffff... je suis desesperé. allez je reessaye encore une fois et je te dis quoi
            0
            1. ca me met que j'ai supprimé un fichier et que findykill ne peut donc plus fonctionner
              0
              1. Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.554 [GMT 2:00]
                Lancé depuis: C:\Documents and Settings\ben\Bureau\killbagle.exe
                .

                (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
                .
                .
                ---- Previous Run -------
                .
                C:\Documents and Settings\ben\Application Data\m
                C:\Documents and Settings\ben\Application Data\m\data.oct
                C:\Documents and Settings\ben\Application Data\m\flec006.exe
                C:\Documents and Settings\ben\Application Data\m\list.oct
                C:\Documents and Settings\ben\Application Data\m\shared\4U_Video_Converter_2.1.47.zip
                C:\Documents and Settings\ben\Application Data\m\shared\A1Monitor_Network_Monitoring_&_Server_Monitor_7.0.1.zip
                C:\Documents and Settings\ben\Application Data\m\shared\Advanced Mailbox Processor 3.0.zip
                C:\Documents and Settings\ben\Application Data\m\shared\Advanced Shell for UPX 2.03.zip
                C:\Documents and Settings\ben\Application Data\m\shared\America Online (Windows 2000) 6.0.zip
                C:\Documents and Settings\ben\Application Data\m\shared\Anime Smileys 1.0.zip
                C:\Documents and Settings\ben\Application Data\m\shared\Anonymous_Friend_2.7.zip
                C:\Documents and Settings\ben\Application Data\m\shared\Anti_Tracks_6.9.23.zip
                C:\Documents and Settings\ben\Application Data\m\shared\AquaButton Control 2.0.zip
                C:\Documents and Settings\ben\Application Data\m\shared\ArcSoft_PhotoBase_4.5.zip
                C:\Documents and Settings\ben\Application Data\m\shared\AudioSyncer 1.3.zip
                C:\Documents and Settings\ben\Application Data\m\shared\Avast.antivirus.mise.a.jour.04-2006special.adeware.zip
                C:\Documents and Settings\ben\Application Data\m\shared\AVI_to_DivX_3.1.5.zip
                C:\Documents and Settings\ben\Application Data\m\shared\Avignon Font 1.0.zip
                C:\Documents and Settings\ben\Application Data\m\shared\Baby_Diary_2.5.500_Key+Serial.zip
                C:\Documents and Settings\ben\Application Data\m\shared\BARONIAL_MONOGRAMS_1.0.zip
                C:\Documents and Settings\ben\Application Data\m\shared\BingoTrack_5.3.zip
                C:\Documents and Settings\ben\Application Data\m\shared\Brain_Builder_1.12.zip
                C:\Documents and Settings\ben\Application Data\m\shared\BRUTUS toolbar for IE 4.5.131.0.zip
                C:\Documents and Settings\ben\Application Data\m\shared\CAD_Viewer_4.5_[KeyGen].zip
                C:\Documents and Settings\ben\Application Data\m\shared\Cfont_Pro_2.5.zip
                C:\Documents and Settings\ben\Application Data\m\shared\Club_Accounting_3.0.1.zip
                C:\Documents and Settings\ben\Application Data\m\shared\ColorCache_4.0.0.1_KeyGen.zip
                C:\Documents and Settings\ben\Application Data\m\shared\CompuCram_Series_7_6_rev_4_(Patch).zip
                C:\Documents and Settings\ben\Application Data\m\shared\Custo 3.0.4.zip
                C:\Documents and Settings\ben\Application Data\m\shared\Database Designer for MySQL 1.9.3.zip
                C:\Documents and Settings\ben\Application Data\m\shared\Delete_Add_or_Remove_Programs_List_Entries_Software_7.0_(Serial).zip
                C:\Documents and Settings\ben\Application Data\m\shared\DO SEX toolbar for IE 4.5.132.0.zip
                C:\Documents and Settings\ben\Application Data\m\shared\Domain Name Tools 1.3.1.zip
                C:\Documents and Settings\ben\Application Data\m\shared\Drupal.org_RSS_Feed_1.0.zip
                C:\Documents and Settings\ben\Application Data\m\shared\DéKiBulle_3.24.zip
                C:\Documents and Settings\ben\Application Data\m\shared\Easy Vista Manager 1.8.1.zip
                C:\Documents and Settings\ben\Application Data\m\shared\Easy_Registry_Optimizer_2.0.zip
                C:\Documents and Settings\ben\Application Data\m\shared\ebComposer_UBL_1.0.4_(Serial).zip
                C:\Documents and Settings\ben\Application Data\m\shared\eLoft_Database_2.0.zip
                C:\Documents and Settings\ben\Application Data\m\shared\eMyPasswords Organizer 1.05.zip
                C:\Documents and Settings\ben\Application Data\m\shared\Ewido.Security.Suite.4+serial.zip
                C:\Documents and Settings\ben\Application Data\m\shared\eXPert_PDF_Reader_1.zip
                C:\Documents and Settings\ben\Application Data\m\shared\FastChords_Lite_3.zip
                C:\Documents and Settings\ben\Application Data\m\shared\Ferrets Screensaver 1.0.6.2634.zip
                C:\Documents and Settings\ben\Application Data\m\shared\Flash SlideShow Maker 4.75.zip
                C:\Documents and Settings\ben\Application Data\m\shared\Flight_Simulator_2000_Professional_Edition_Update_2.0b.zip
                C:\Documents and Settings\ben\Application Data\m\shared\For Sale By Owner Kit 1.0.zip
                C:\Documents and Settings\ben\Application Data\m\shared\Forge_for_SwordSearcher_1.0.2.5.zip
                C:\Documents and Settings\ben\Application Data\m\shared\Freespace XP 1.0.10.zip
                C:\Documents and Settings\ben\Application Data\m\shared\Full Map 2.1.zip
                C:\Documents and Settings\ben\Application Data\m\shared\Garden Australia Screen Saver 1.0.zip
                C:\Documents and Settings\ben\Application Data\m\shared\Google_Ranking_Search_Engine_Optimization_Tool_1.1.zip
                C:\Documents and Settings\ben\Application Data\m\shared\Grand_Theft_Auto_Vice_City_Multi_Theft_Auto_mod_0.5.zip
                C:\Documents and Settings\ben\Application Data\m\shared\HD-X-Lock_1.40.zip
                C:\Documents and Settings\ben\Application Data\m\shared\Health_Tracker_3.0.0_[Cracked].zip
                C:\Documents and Settings\ben\Application Data\m\shared\Hide Drive 1.5.1.zip
                C:\Documents and Settings\ben\Application Data\m\shared\HideDesktop 1.0.zip
                C:\Documents and Settings\ben\Application Data\m\shared\History_of_The_Nations_and_Empires_Involved_and_a_Study_of_the_Events.zip
                C:\Documents and Settings\ben\Application Data\m\shared\iDo_Wedding_Couple_Edition_7.8.zip
                C:\Documents and Settings\ben\Application Data\m\shared\ImageRing_1.0.zip
                C:\Documents and Settings\ben\Application Data\m\shared\Imagery_3D_0.1.4.zip
                C:\Documents and Settings\ben\Application Data\m\shared\InFormEnter 0.5.5.2.zip
                C:\Documents and Settings\ben\Application Data\m\shared\InnerSoft CAD for AutoCAD 2006 1.2b.zip
                C:\Documents and Settings\ben\Application Data\m\shared\iPod VideoConstructor FREE 2.2.0.28.zip
                C:\Documents and Settings\ben\Application Data\m\shared\IPxWorkX 0.1.zip
                C:\Documents and Settings\ben\Application Data\m\shared\Jingle 4.02.zip
                C:\Documents and Settings\ben\Application Data\m\shared\JoyToKey 3.7.9.zip
                C:\Documents and Settings\ben\Application Data\m\shared\Just_Another_Analog_Clock_1.1.zip
                C:\Documents and Settings\ben\Application Data\m\shared\JustFTP 3.0.zip
                C:\Documents and Settings\ben\Application Data\m\shared\Karnaugh_Minimizer_2.0.zip
                C:\Documents and Settings\ben\Application Data\m\shared\LoanAmortizer Professional Edition 3.1.zip
                C:\Documents and Settings\ben\Application Data\m\shared\Love Screensaver 1.0.zip
                C:\Documents and Settings\ben\Application Data\m\shared\LTC_Manager_5.3.zip
                C:\Documents and Settings\ben\Application Data\m\shared\Master Hammond B3 VSTi 2.1.zip
                C:\Documents and Settings\ben\Application Data\m\shared\Math Foundation 3.zip
                C:\Documents and Settings\ben\Application Data\m\shared\Meta_Image_Search_2.00_(Crack).zip
                C:\Documents and Settings\ben\Application Data\m\shared\MoveOnBoot_1.95_(Cracked).zip
                C:\Documents and Settings\ben\Application Data\m\shared\MS_Access_Split_Fields_Software_7.0.zip
                C:\Documents and Settings\ben\Application Data\m\shared\Myjewchat_1.zip
                C:\Documents and Settings\ben\Application Data\m\shared\MyLinkTool 1.10.zip
                C:\Documents and Settings\ben\Application Data\m\shared\NexTag Toolbar 1.0.20.zip
                C:\Documents and Settings\ben\Application Data\m\shared\NxV 0.43.zip
                C:\Documents and Settings\ben\Application Data\m\shared\Orbital's_SQL_Decryptor_2.2.zip
                C:\Documents and Settings\ben\Application Data\m\shared\OsenXPSuite 2006 Enterprise Edition 11.24.0.90.zip
                C:\Documents and Settings\ben\Application Data\m\shared\Oven Fresh HTML Button Maker 2.0.zip
                C:\Documents and Settings\ben\Application Data\m\shared\Ovusoft_Fertility_Software_1.6.zip
                C:\Documents and Settings\ben\Application Data\m\shared\OZEXE_3.10_With_Crack.zip
                C:\Documents and Settings\ben\Application Data\m\shared\PerfX_Prints_1.0.20.zip
                C:\Documents and Settings\ben\Application Data\m\shared\Personal C Sharp 1.51.zip
                C:\Documents and Settings\ben\Application Data\m\shared\Personal_Notepad_2.1.23.zip
                C:\Documents and Settings\ben\Application Data\m\shared\Planet_Photo_Screensaver_1.0.zip
                C:\Documents and Settings\ben\Application Data\m\shared\PostView_1.3.zip
                C:\Documents and Settings\ben\Application Data\m\shared\Print Tracker 5.7.4.zip
                C:\Documents and Settings\ben\Application Data\m\shared\Proficient_Blackjack_1.0.zip
                C:\Documents and Settings\ben\Application Data\m\shared\R2V 1.25.zip
                C:\Documents and Settings\ben\Application Data\m\shared\Rainbow_5.07_[Key].zip
                C:\Documents and Settings\ben\Application Data\m\shared\Redsauce Post Master 1.0.0.7.zip
                C:\Documents and Settings\ben\Application Data\m\shared\Repro_2.3_(Patch).zip
                C:\Documents and Settings\ben\Application Data\m\shared\Scripture Challenge 5.11.zip
                C:\Documents and Settings\ben\Application Data\m\shared\Sea_Lion_Family_1.0.zip
                C:\Documents and Settings\ben\Application Data\m\shared\Silver Pilot 1.12.zip
                C:\Documents and Settings\ben\Application Data\m\shared\SimGangster_Free_Edition_1.0.2481.zip
                C:\Documents and Settings\ben\Application Data\m\shared\Sirana SpamCenter 2.0 Patch.zip
                C:\Documents and Settings\ben\Application Data\m\shared\Small Business Break-Even Analyzer 1.6.zip
                C:\Documents and Settings\ben\Application Data\m\shared\Sophos.Antivirus.v5.2.5.Win2kXP2k3.Multilingual.Retail-ARN.zip
                C:\Documents and Settings\ben\Application Data\m\shared\SPac_1.6.0.28_KeyGen.zip
                C:\Documents and Settings\ben\Application Data\m\shared\SpellServer.NET_2.0.zip
                C:\Documents and Settings\ben\Application Data\m\shared\SQLClean 2.3.76.zip
                C:\Documents and Settings\ben\Application Data\m\shared\SSSP.zip
                C:\Documents and Settings\ben\Application Data\m\shared\Stardust_Impressionist_Paintings_Screen_Saver_3.0.149.zip
                C:\Documents and Settings\ben\Application Data\m\shared\String Checker 1.0.zip
                C:\Documents and Settings\ben\Application Data\m\shared\Swiftpage for Excel 1.0.8.zip
                C:\Documents and Settings\ben\Application Data\m\shared\Symantec.-.WinFax.Pro.10.04.update.from.10.03.zip
                C:\Documents and Settings\ben\Application Data\m\shared\teardrop_screensaver_01.zip
                C:\Documents and Settings\ben\Application Data\m\shared\Text to Speech Maker 1.5.2.zip
                C:\Documents and Settings\ben\Application Data\m\shared\Think_Ink_Tattoo_Screen_Saver_Collection_2.0_[KeyGen].zip
                C:\Documents and Settings\ben\Application Data\m\shared\Tims Movie Site V 2 1.0.0.0.zip
                C:\Documents and Settings\ben\Application Data\m\shared\TNT_Buttons_2.0.zip
                C:\Documents and Settings\ben\Application Data\m\shared\TweakNow_PowerPack_2006_Standard_1.6.0.zip
                C:\Documents and Settings\ben\Application Data\m\shared\txt2palm 1.6.zip
                C:\Documents and Settings\ben\Application Data\m\shared\Ultimate_Screen_Clock_2.0a_Patch_36_(Patch).zip
                C:\Documents and Settings\ben\Application Data\m\shared\UltimateMenu_1.0_KeyGen.zip
                C:\Documents and Settings\ben\Application Data\m\shared\VPN-X Server 2.2.1.24.zip
                C:\Documents and Settings\ben\Application Data\m\shared\Warcraft_III_-_Fall_of_the_Lion_Episode_IV_map.zip
                C:\Documents and Settings\ben\Application Data\m\shared\Water_Lily_Screensaver_v2_5.07.zip
                C:\Documents and Settings\ben\Application Data\m\shared\WebTester_5.0.zip
                C:\Documents and Settings\ben\Application Data\m\shared\Winsole_2.1_Standalone_2.1.zip
                C:\Documents and Settings\ben\Application Data\m\shared\Word_Frequency_Count_Software_7.0_Key.zip
                C:\Documents and Settings\ben\Application Data\m\shared\Wsnap_1.3.79.zip
                C:\Documents and Settings\ben\Application Data\m\shared\XSS_IP_Monitor_1.8.zip
                C:\Documents and Settings\ben\Application Data\m\shared\yLend_1.0.2.zip
                C:\Documents and Settings\ben\Application Data\m\shared\ZeemMD5 1.1.zip
                C:\Documents and Settings\ben\Application Data\m\srvlist.oct
                C:\Documents and Settings\ben\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNSD.XML
                C:\Documents and Settings\ben\Local Settings\Temporary Internet Files\bestwiner.stt
                C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNSD.XML
                C:\InfoSat.txt
                C:\PROGRA~1\TECHCI~1\AOLSAV\AOLAgent.exe
                C:\WINDOWS\IE4 Error Log.txt
                C:\WINDOWS\Install.txt
                C:\WINDOWS\system32\ban_list.txt
                C:\WINDOWS\system32\drivers\downld
                C:\WINDOWS\system32\drivers\downld\117359.exe
                C:\WINDOWS\system32\drivers\downld\121546.exe
                C:\WINDOWS\system32\drivers\downld\134812.exe
                C:\WINDOWS\system32\drivers\downld\134828.exe
                C:\WINDOWS\system32\drivers\downld\138578.exe
                C:\WINDOWS\system32\drivers\downld\142531.exe
                C:\WINDOWS\system32\drivers\downld\142703.exe
                C:\WINDOWS\system32\drivers\downld\151406.exe
                C:\WINDOWS\system32\drivers\downld\153843.exe
                C:\WINDOWS\system32\drivers\downld\154046.exe
                C:\WINDOWS\system32\drivers\downld\155468.exe
                C:\WINDOWS\system32\drivers\downld\158359.exe
                C:\WINDOWS\system32\drivers\downld\162781.exe
                C:\WINDOWS\system32\drivers\downld\165859.exe
                C:\WINDOWS\system32\drivers\downld\167578.exe
                C:\WINDOWS\system32\drivers\downld\167890.exe
                C:\WINDOWS\system32\drivers\downld\169781.exe
                C:\WINDOWS\system32\drivers\downld\176765.exe
                C:\WINDOWS\system32\drivers\downld\177671.exe
                C:\WINDOWS\system32\drivers\downld\177687.exe
                C:\WINDOWS\system32\drivers\downld\180062.exe
                C:\WINDOWS\system32\drivers\downld\180156.exe
                C:\WINDOWS\system32\drivers\downld\180171.exe
                C:\WINDOWS\system32\drivers\downld\182187.exe
                C:\WINDOWS\system32\drivers\downld\182640.exe
                C:\WINDOWS\system32\drivers\downld\183046.exe
                C:\WINDOWS\system32\drivers\downld\183078.exe
                C:\WINDOWS\system32\drivers\downld\187562.exe
                C:\WINDOWS\system32\drivers\downld\189968.exe
                C:\WINDOWS\system32\drivers\downld\195218.exe
                C:\WINDOWS\system32\drivers\downld\195703.exe
                C:\WINDOWS\system32\drivers\downld\196046.exe
                C:\WINDOWS\system32\drivers\downld\197421.exe
                C:\WINDOWS\system32\drivers\downld\198984.exe
                C:\WINDOWS\system32\drivers\downld\199406.exe
                C:\WINDOWS\system32\drivers\downld\202750.exe
                C:\WINDOWS\system32\drivers\downld\205265.exe
                C:\WINDOWS\system32\drivers\downld\206265.exe
                C:\WINDOWS\system32\drivers\downld\206406.exe
                C:\WINDOWS\system32\drivers\downld\208250.exe
                C:\WINDOWS\system32\drivers\downld\209593.exe
                C:\WINDOWS\system32\drivers\downld\212187.exe
                C:\WINDOWS\system32\drivers\downld\212625.exe
                C:\WINDOWS\system32\drivers\downld\214109.exe
                C:\WINDOWS\system32\drivers\downld\217015.exe
                C:\WINDOWS\system32\drivers\downld\223328.exe
                C:\WINDOWS\system32\drivers\downld\224468.exe
                C:\WINDOWS\system32\drivers\downld\227843.exe
                C:\WINDOWS\system32\drivers\downld\229906.exe
                C:\WINDOWS\system32\drivers\downld\232609.exe
                C:\WINDOWS\system32\drivers\downld\235437.exe
                C:\WINDOWS\system32\drivers\downld\241781.exe
                C:\WINDOWS\system32\drivers\downld\243984.exe
                C:\WINDOWS\system32\drivers\downld\246031.exe
                C:\WINDOWS\system32\drivers\downld\247109.exe
                C:\WINDOWS\system32\drivers\downld\248328.exe
                C:\WINDOWS\system32\drivers\downld\248781.exe
                C:\WINDOWS\system32\drivers\downld\249468.exe
                C:\WINDOWS\system32\drivers\downld\253171.exe
                C:\WINDOWS\system32\drivers\downld\256515.exe
                C:\WINDOWS\system32\drivers\downld\257859.exe
                C:\WINDOWS\system32\drivers\downld\262078.exe
                C:\WINDOWS\system32\drivers\downld\267078.exe
                C:\WINDOWS\system32\drivers\downld\267656.exe
                C:\WINDOWS\system32\drivers\downld\270015.exe
                C:\WINDOWS\system32\drivers\downld\270359.exe
                C:\WINDOWS\system32\drivers\downld\272484.exe
                C:\WINDOWS\system32\drivers\downld\277312.exe
                C:\WINDOWS\system32\drivers\downld\288921.exe
                C:\WINDOWS\system32\drivers\downld\291968.exe
                C:\WINDOWS\system32\drivers\downld\297406.exe
                C:\WINDOWS\system32\drivers\downld\298343.exe
                C:\WINDOWS\system32\drivers\downld\300734.exe
                C:\WINDOWS\system32\drivers\downld\301281.exe
                C:\WINDOWS\system32\drivers\downld\306734.exe
                C:\WINDOWS\system32\drivers\downld\309531.exe
                C:\WINDOWS\system32\drivers\downld\312968.exe
                C:\WINDOWS\system32\drivers\downld\314140.exe
                C:\WINDOWS\system32\drivers\downld\316875.exe
                C:\WINDOWS\system32\drivers\downld\320718.exe
                C:\WINDOWS\system32\drivers\downld\321312.exe
                C:\WINDOWS\system32\drivers\downld\323500.exe
                C:\WINDOWS\system32\drivers\downld\331171.exe
                C:\WINDOWS\system32\drivers\downld\331453.exe
                C:\WINDOWS\system32\drivers\downld\339750.exe
                C:\WINDOWS\system32\drivers\downld\345000.exe
                C:\WINDOWS\system32\drivers\downld\346703.exe
                C:\WINDOWS\system32\drivers\downld\347140.exe
                C:\WINDOWS\system32\drivers\downld\359093.exe
                C:\WINDOWS\system32\drivers\downld\361671.exe
                C:\WINDOWS\system32\drivers\downld\368765.exe
                C:\WINDOWS\system32\drivers\downld\375500.exe
                C:\WINDOWS\system32\drivers\downld\397140.exe
                C:\WINDOWS\system32\drivers\downld\398578.exe
                C:\WINDOWS\system32\drivers\downld\41280937.exe
                C:\WINDOWS\system32\drivers\downld\41281828.exe
                C:\WINDOWS\system32\drivers\downld\41313656.exe
                C:\WINDOWS\system32\drivers\downld\41316218.exe
                C:\WINDOWS\system32\drivers\downld\41332484.exe
                C:\WINDOWS\system32\drivers\downld\41341328.exe
                C:\WINDOWS\system32\drivers\downld\41346218.exe
                C:\WINDOWS\system32\drivers\downld\41353937.exe
                C:\WINDOWS\system32\drivers\downld\41358890.exe
                C:\WINDOWS\system32\drivers\downld\41366515.exe
                C:\WINDOWS\system32\drivers\downld\41394671.exe
                C:\WINDOWS\system32\drivers\downld\41396593.exe
                C:\WINDOWS\system32\drivers\downld\41415343.exe
                C:\WINDOWS\system32\drivers\downld\41421765.exe
                C:\WINDOWS\system32\drivers\downld\41431671.exe
                C:\WINDOWS\system32\drivers\downld\41443171.exe
                C:\WINDOWS\system32\drivers\downld\41447671.exe
                C:\WINDOWS\system32\drivers\downld\41452156.exe
                C:\WINDOWS\system32\drivers\downld\41467750.exe
                C:\WINDOWS\system32\drivers\downld\41491265.exe
                C:\WINDOWS\system32\drivers\downld\41568093.exe
                C:\WINDOWS\system32\drivers\downld\41592468.exe
                C:\WINDOWS\system32\drivers\downld\416703.exe
                C:\WINDOWS\system32\drivers\downld\425859.exe
                C:\WINDOWS\system32\drivers\downld\451906.exe
                C:\WINDOWS\system32\drivers\downld\480312.exe
                C:\WINDOWS\system32\drivers\downld\515109.exe
                C:\WINDOWS\system32\drivers\downld\539156.exe
                C:\WINDOWS\system32\drivers\downld\550765.exe
                C:\WINDOWS\system32\drivers\downld\580500.exe
                C:\WINDOWS\system32\drivers\downld\593656.exe
                C:\WINDOWS\system32\drivers\downld\622453.exe
                C:\WINDOWS\system32\drivers\downld\632718.exe
                C:\WINDOWS\system32\drivers\hldrrr.exe
                C:\WINDOWS\system32\drivers\srosa.sys
                C:\WINDOWS\system32\Install.txt
                C:\WINDOWS\system32\mdelk.exe
                C:\WINDOWS\system32\tmp0_349841824778.bk
                C:\WINDOWS\system32\tmp0_371238598482.bk
                C:\WINDOWS\system32\tmp0_662801634402.bk
                C:\WINDOWS\system32\tmp1_810319751072.bk
                C:\WINDOWS\system32\tmp5_64452449317.bk
                C:\WINDOWS\system32\tpszxyd.sys
                C:\WINDOWS\system32\wintems.exe
                0
                1. ((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
                  .

                  -------\Legacy_AFINDING
                  -------\Legacy_AFISICX
                  -------\Legacy_MABIDWE
                  -------\Legacy_MACIDWE
                  -------\Legacy_MSBRND
                  -------\Legacy_NOBICYT
                  -------\Legacy_NOXTCYR
                  -------\Legacy_NOYTCYR
                  -------\Legacy_PERFMONS
                  -------\Legacy_PERFS
                  -------\Legacy_ROUTING
                  -------\Legacy_ROXTCTM
                  -------\Legacy_ROYTCTM
                  -------\Legacy_SOBICYT
                  -------\Legacy_SOTPECA
                  -------\Legacy_SOXPECA
                  -------\Legacy_TDXDOWKC
                  -------\Legacy_TDYDOWKC
                  -------\Legacy_WSERVING
                  -------\Legacy_WSLDOEKD
                  -------\Service_msbrnd

                  ((((((((((((((((((((((((((((( Fichiers créés du 2008-09-18 au 2008-10-18 ))))))))))))))))))))))))))))))))))))
                  .

                  2008-10-19 01:20 . 2008-10-19 01:20 <REP> d-------- C:\WINDOWS\LastGood
                  2008-10-19 00:29 . 2008-10-19 00:30 <REP> d-------- C:\Program Files\FindyKill
                  2008-10-19 00:26 . 2008-10-19 00:26 <REP> d-------- C:\Documents and Settings\NetworkService\Application Data\Intel
                  2008-10-19 00:26 . 2008-10-19 00:26 <REP> d-------- C:\Documents and Settings\LocalService.AUTORITE NT\Application Data\Intel
                  2008-10-19 00:26 . 2008-10-19 00:26 <REP> d-------- C:\Documents and Settings\LocalService.AUTORITE NT.003\Application Data\Intel
                  2008-10-19 00:26 . 2008-10-19 00:26 <REP> d-------- C:\Documents and Settings\LocalService.AUTORITE NT.002\Application Data\Intel
                  2008-10-19 00:26 . 2008-10-19 00:26 <REP> d-------- C:\Documents and Settings\LocalService.AUTORITE NT.001\Application Data\Intel
                  2008-10-19 00:26 . 2008-10-19 00:26 <REP> d-------- C:\Documents and Settings\LocalService.AUTORITE NT.000\Application Data\Intel
                  2008-10-19 00:26 . 2008-10-19 00:26 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\Intel
                  2008-10-19 00:25 . 2008-08-28 23:34 3,632,384 --a------ C:\WINDOWS\system32\drivers\NETw5x32.sys
                  2008-10-19 00:25 . 2008-06-20 10:33 2,756,608 --a------ C:\WINDOWS\system32\NETw5r32.dll
                  2008-10-19 00:25 . 2008-06-20 10:32 663,552 --a------ C:\WINDOWS\system32\NETw5c32.dll
                  2008-10-19 00:22 . 2008-10-19 00:22 <REP> d-------- C:\Program Files\Fichiers communs\Intel
                  2008-10-19 00:08 . 2008-10-19 00:08 <REP> d-------- C:\Program Files\Trend Micro
                  2008-10-18 23:37 . 2008-10-18 23:37 <REP> d-------- C:\Program Files\ma-config.com
                  2008-10-18 23:37 . 2008-10-18 23:37 <REP> d-------- C:\Documents and Settings\All Users\Application Data\ma-config.com
                  2008-10-18 01:49 . 2008-10-18 01:50 <REP> d-------- C:\Program Files\splus
                  2008-10-18 01:49 . 2005-10-17 18:13 447,488 --a------ C:\WINDOWS\system32\splus.cpl
                  2008-10-17 23:28 . 2008-10-17 23:28 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
                  2008-10-17 23:28 . 2008-10-17 23:28 <REP> d-------- C:\Documents and Settings\ben\Application Data\Malwarebytes
                  2008-10-17 23:28 . 2008-10-17 23:28 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
                  2008-10-17 23:28 . 2008-10-16 20:25 38,496 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
                  2008-10-17 23:28 . 2008-10-16 20:25 15,504 --a------ C:\WINDOWS\system32\drivers\mbam.sys
                  2008-10-17 23:22 . 2008-06-19 17:24 28,544 --a------ C:\WINDOWS\system32\drivers\pavboot.sys
                  2008-10-17 23:20 . 2008-10-18 02:01 <REP> d-------- C:\Program Files\Panda Security
                  2008-10-17 23:00 . 2008-10-17 23:00 <REP> d-------- C:\Program Files\Alwil Software
                  2008-10-17 02:44 . 2008-10-17 02:47 <REP> d-------- C:\Program Files\DrWeb
                  2008-10-17 01:15 . 2008-10-17 01:15 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
                  2008-10-17 00:41 . 2008-10-17 00:47 46 --ah----- C:\WINDOWS\system32\InternetAccelerator_sysquict.dat
                  2008-10-17 00:40 . 2008-10-17 00:51 <REP> d-------- C:\Program Files\Okoker Internet Accelerator
                  2008-10-16 00:53 . 2008-10-16 00:53 <REP> d-------- C:\Program Files\Lavasoft
                  2008-10-16 00:53 . 2008-10-16 00:56 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
                  2008-10-15 23:03 . 2008-10-16 12:06 <REP> d-------- C:\Program Files\ESET
                  2008-10-15 13:16 . 2007-09-06 00:22 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
                  2008-10-15 13:16 . 2006-04-27 17:49 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
                  2008-10-15 13:16 . 2008-05-29 09:35 86,528 --a------ C:\WINDOWS\system32\VACFix.exe
                  2008-10-15 13:16 . 2008-05-18 21:40 82,944 --a------ C:\WINDOWS\system32\IEDFix.exe
                  2008-10-15 13:16 . 2008-06-23 23:34 82,432 --a------ C:\WINDOWS\system32\IEDFix.C.exe
                  2008-10-15 13:16 . 2008-05-23 18:21 81,920 --a------ C:\WINDOWS\system32\404Fix.exe
                  2008-10-15 13:16 . 2003-06-05 21:13 53,248 --a------ C:\WINDOWS\system32\Process.exe
                  2008-10-15 13:16 . 2004-07-31 18:50 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
                  2008-10-15 13:16 . 2007-10-04 00:36 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
                  2008-10-09 07:09 . 2008-10-09 07:09 244 --ah----- C:\sqmnoopt18.sqm
                  2008-10-09 07:09 . 2008-10-09 07:09 232 --ah----- C:\sqmdata18.sqm
                  2008-09-29 14:25 . 2008-09-29 14:25 <REP> d--hs---- C:\found.000
                  2008-09-23 17:54 . 2008-09-23 17:54 244 --ah----- C:\sqmnoopt17.sqm
                  2008-09-23 17:54 . 2008-09-23 17:54 232 --ah----- C:\sqmdata17.sqm
                  2008-09-23 14:20 . 2008-09-23 14:20 268 --ah----- C:\sqmdata16.sqm
                  2008-09-23 14:20 . 2008-09-23 14:20 244 --ah----- C:\sqmnoopt16.sqm
                  2008-09-22 20:49 . 2008-09-22 20:49 268 --ah----- C:\sqmdata15.sqm
                  2008-09-22 20:49 . 2008-09-22 20:49 244 --ah----- C:\sqmnoopt15.sqm
                  2008-09-22 20:48 . 2008-09-22 20:48 268 --ah----- C:\sqmdata14.sqm
                  2008-09-22 20:48 . 2008-09-22 20:48 244 --ah----- C:\sqmnoopt14.sqm

                  .
                  (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                  .
                  2008-10-18 22:22 --------- d-----w C:\Program Files\Intel
                  2008-10-18 21:38 --------- d-----w C:\Program Files\eMule
                  2008-10-17 23:56 --------- d--h--w C:\Program Files\InstallShield Installation Information
                  2008-10-17 22:50 --------- d-----w C:\Program Files\PE
                  2008-10-17 22:50 --------- d-----w C:\Program Files\nsj4C1
                  2008-10-17 00:24 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
                  2008-10-15 22:16 --------- d-----w C:\Program Files\epson
                  2008-10-15 21:26 4,906 ----a-w C:\WINDOWS\system32\tmp.reg
                  2008-10-01 13:47 --------- d-----w C:\Documents and Settings\ben\Application Data\dvdcss
                  2008-09-20 21:35 --------- d-----w C:\Program Files\Everest Poker
                  2008-08-27 22:18 --------- d-----w C:\Program Files\Alcohol Soft
                  2008-08-20 14:15 208,896 ----a-w C:\WINDOWS\system32\NetProvCredMan.dll
                  2008-08-03 12:49 107,888 ----a-w C:\WINDOWS\system32\CmdLineExt.dll
                  2008-08-03 11:41 53,248 ----a-w C:\WINDOWS\system32\comrepl.exe
                  2008-07-18 20:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
                  2008-07-18 20:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
                  2008-07-18 20:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
                  2008-07-18 20:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll
                  2008-07-18 20:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
                  2008-07-18 20:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
                  2008-07-18 20:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
                  2008-07-18 20:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
                  2008-07-18 20:07 270,880 ----a-w C:\WINDOWS\system32\mucltui.dll
                  2008-07-18 20:07 210,976 ----a-w C:\WINDOWS\system32\muweb.dll
                  2008-02-21 01:27 278,528 ----a-w C:\Program Files\Fichiers communs\FDEUnInstaller.exe
                  2007-02-09 17:34 420,816 ----a-w C:\Documents and Settings\ben\Application Data\wunauclt.exe
                  .

                  ((((((((((((((((((((((((((((( snapshot_2008-10-19_ 1.19.12.15 )))))))))))))))))))))))))))))))))))))))))
                  .
                  - 2008-10-18 22:27:16 64,706 ----a-w C:\WINDOWS\system32\perfc009.dat
                  + 2008-10-18 23:20:46 64,706 ----a-w C:\WINDOWS\system32\perfc009.dat
                  - 2008-10-18 22:27:17 78,354 ----a-w C:\WINDOWS\system32\perfc00C.dat
                  + 2008-10-18 23:20:46 78,354 ----a-w C:\WINDOWS\system32\perfc00C.dat
                  - 2008-10-18 22:27:16 409,566 ----a-w C:\WINDOWS\system32\perfh009.dat
                  + 2008-10-18 23:20:46 409,566 ----a-w C:\WINDOWS\system32\perfh009.dat
                  - 2008-10-18 22:27:17 477,728 ----a-w C:\WINDOWS\system32\perfh00C.dat
                  + 2008-10-18 23:20:46 477,728 ----a-w C:\WINDOWS\system32\perfh00C.dat
                  .
                  -- Instantané actualisé --
                  .
                  ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
                  .
                  .
                  *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
                  REGEDIT4

                  [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
                  "{6638A9DE-0745-4292-8A2E-AE530E7B9B3F}"= "C:\Program Files\Kiwee Toolbar2\1.5.131\KiweeIEToolbar.dll" [2008-04-03 265360]

                  [HKEY_CLASSES_ROOT\clsid\{6638a9de-0745-4292-8a2e-ae530e7b9b3f}]
                  [HKEY_CLASSES_ROOT\KiweeIEToolbar.KiweeToolbar.1]
                  [HKEY_CLASSES_ROOT\TypeLib\{259EEB17-79AA-44DF-8410-8E55F82A902A}]
                  [HKEY_CLASSES_ROOT\KiweeIEToolbar.KiweeToolbar]

                  [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6638A9DE-0745-4292-8A2E-AE530E7B9B3F}]
                  2008-04-03 10:52 265360 --a------ C:\Program Files\Kiwee Toolbar2\1.5.131\KiweeIEToolbar.dll

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
                  "{6638A9DE-0745-4292-8A2E-AE530E7B9B3F}"= "C:\Program Files\Kiwee Toolbar2\1.5.131\KiweeIEToolbar.dll" [2008-04-03 265360]

                  [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
                  "{6638A9DE-0745-4292-8A2E-AE530E7B9B3F}"= "C:\Program Files\Kiwee Toolbar2\1.5.131\KiweeIEToolbar.dll" [2008-04-03 265360]

                  [HKEY_CLASSES_ROOT\clsid\{6638a9de-0745-4292-8a2e-ae530e7b9b3f}]
                  [HKEY_CLASSES_ROOT\KiweeIEToolbar.KiweeToolbar.1]
                  [HKEY_CLASSES_ROOT\TypeLib\{259EEB17-79AA-44DF-8410-8E55F82A902A}]
                  [HKEY_CLASSES_ROOT\KiweeIEToolbar.KiweeToolbar]

                  [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                  "MsnMsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]
                  "ares"="C:\Program Files\Ares\Ares.exe" [BU]
                  "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-19 15360]
                  "Sony Ericsson PC Suite"="C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe" [2008-02-20 360448]
                  "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Fichiers communs\Nero\Lib\NMBgMonitor.exe" [BU]
                  "Google Update"="C:\Documents and Settings\ben\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-10-12 133104]

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                  "AOLSAV"="C:\PROGRA~1\TECHCI~1\AOLSAV\AOLAgent.exe" [BU]
                  "AOLDialer"="C:\Program Files\Fichiers communs\AOL\ACS\AOLDial.exe" [2007-06-21 70952]
                  "LManager"="C:\PROGRA~1\LAUNCH~1\LManager.exe" [2006-07-20 593920]
                  "ADMTray.exe"="C:\Acer\Empowering Technology\admtray.exe" [2005-10-24 2462208]
                  "SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-03 761946]
                  "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-06-12 7577600]
                  "NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-06-12 86016]
                  "AzMixerSel"="C:\Program Files\Realtek\InstallShield\AzMixerSel.exe" [2006-08-16 53248]
                  "eDataSecurity Loader"="C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe" [2005-12-27 69632]
                  "HostManager"="C:\Program Files\Fichiers communs\AOL\1203807828\ee\AOLSoftware.exe" [2006-09-26 50736]
                  "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
                  "QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-02-01 385024]
                  "KiweeHook"="C:\Program Files\Kiwee Toolbar2\1.5.131\kwtbaim.exe" [2008-04-03 56456]
                  "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
                  "RealTray"="C:\Program Files\Real\RealPlayer\RealPlay.exe" [2008-03-16 26112]
                  "BVRPLiveUpdate"="C:\Program Files\Avanquest update\Engine\Setup.exe" [BU]
                  "NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [BU]
                  "IntelZeroConfig"="C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe" [2008-08-20 1368064]
                  "IntelWireless"="C:\Program Files\Fichiers communs\Intel\WirelessCommon\iFrmewrk.exe" [2008-08-20 1191936]
                  "nwiz"="nwiz.exe" [2006-06-12 C:\WINDOWS\system32\nwiz.exe]
                  "RTHDCPL"="RTHDCPL.EXE" [2006-08-16 C:\WINDOWS\RTHDCPL.exe]
                  "SkyTel"="SkyTel.EXE" [2006-08-16 C:\WINDOWS\SkyTel.exe]

                  [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
                  "nlsf"="move" [X]
                  "Config"="C:\WINDOWS\system32\run.cmd" [2006-02-14 248]
                  "tscuninstall"="C:\WINDOWS\system32\tscupgrd.exe" [2004-08-19 44544]

                  C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
                  AOL 9.0 Ic“ne AOL.lnk - C:\Program Files\AOL 9.0b\aoltray.exe [2008-03-16 156784]
                  AOL Compagnon.lnk - C:\Program Files\AOL Compagnon\companion.exe [2008-02-21 255088]
                  Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 65588]

                  [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
                  "NoSMHelp"= 1 (0x1)
                  "MemCheckBoxInRunDlg"= 1 (0x1)
                  "NoSMBalloonTip"= 1 (0x1)
                  "NoDesktopCleanupWizard"= 1 (0x1)
                  "NoWelcomeScreen"= 1 (0x1)
                  "NoAutoUpdate"= 1 (0x1)

                  [HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
                  "NoSMHelp"= 1 (0x1)
                  "MemCheckBoxInRunDlg"= 1 (0x1)
                  "NoSMBalloonTip"= 1 (0x1)
                  "NoDesktopCleanupWizard"= 1 (0x1)
                  "NoWelcomeScreen"= 1 (0x1)
                  "NoAutoUpdate"= 1 (0x1)

                  [HKEY_LOCAL_MACHINE\software\microsoft\security center]
                  "AntiVirusOverride"=dword:00000001
                  "FirewallOverride"=dword:00000001
                  "AntiVirusDisableNotify"=dword:00000001
                  "UpdatesDisableNotify"=dword:00000001

                  [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
                  "DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)

                  [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
                  "%windir%\\system32\\sessmgr.exe"=
                  "C:\\Program Files\\Fichiers communs\\AOL\\ACS\\AOLDial.exe"=
                  "C:\\Program Files\\Fichiers communs\\AOL\\ACS\\AOLacsd.exe"=
                  "C:\\Program Files\\AOL 9.0\\waol.exe"=
                  "C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
                  "C:\\Program Files\\Fichiers communs\\AOL\\1203807828\\ee\\aolsoftware.exe"=
                  "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
                  "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
                  "C:\\Program Files\\AOL 9.0a\\waol.exe"=
                  "C:\\Program Files\\AOL 9.0b\\waol.exe"=
                  "C:\\Program Files\\eMule\\emule.exe"=

                  R0 pavboot;pavboot;C:\WINDOWS\system32\drivers\pavboot.sys [2008-06-19 28544]
                  R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 78416]
                  R1 OsaFsLoc;OsaFsLoc;C:\WINDOWS\system32\drivers\OsaFsLoc.sys [2005-10-15 12106]
                  R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 20560]
                  R2 EpmPsd;Acer EPM Power Scheme Driver;C:\WINDOWS\system32\drivers\epm-psd.sys [2006-01-23 4096]
                  R2 EpmShd;Acer EPM System Hardware Driver;C:\WINDOWS\system32\drivers\epm-shd.sys [2006-01-23 78208]
                  R2 osaio;osaio;C:\WINDOWS\system32\drivers\osaio.sys [2005-06-30 7296]
                  R2 osanbm;osanbm;C:\WINDOWS\system32\drivers\osanbm.sys [2005-01-14 4010]
                  R3 NdisFilt;OSA NdisFilter Protocol;C:\WINDOWS\system32\Drivers\NdisFilt.sys [2005-09-13 4392]
                  R3 NETw5x32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows XP 32 Bit;C:\WINDOWS\system32\DRIVERS\NETw5x32.sys [2008-08-28 3632384]
                  S3 maconfservice;Ma-Config Service;C:\Program Files\ma-config.com\maconfservice.exe [2008-09-02 191656]
                  .
                  Contenu du dossier 'Tâches planifiées'

                  2008-09-22 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
                  - C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 15:57]

                  2008-10-18 C:\WINDOWS\Tasks\GoogleUpdateTaskUser.job
                  - C:\Documents and Settings\ben\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-10-12 00:31]
                  .
                  - - - - ORPHELINS SUPPRIMES - - - -

                  Toolbar-{EEE6C35B-6118-11DC-9C72-001320C79847} - (no file)

                  .
                  ------- Examen supplémentaire -------
                  .
                  FireFox -: Profile - C:\Documents and Settings\ben\Application Data\Mozilla\Firefox\Profiles\h96vxtmc.default\
                  .

                  **************************************************************************

                  catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                  Rootkit scan 2008-10-19 01:27:41
                  Windows 5.1.2600 Service Pack 2 NTFS

                  Recherche de processus cachés ...

                  Recherche d'éléments en démarrage automatique cachés ...

                  Recherche de fichiers cachés ...

                  Scan terminé avec succès
                  Fichiers cachés: 0

                  **************************************************************************
                  .
                  Heure de fin: 2008-10-19 1:30:48
                  ComboFix-quarantined-files.txt 2008-10-18 23:30:45
                  ComboFix2.txt 2008-08-05 22:20:39

                  Avant-CF: 24,956,530,688 octets libres
                  Après-CF: 24,629,547,008 octets libres

                  544 --- E O F --- 2008-09-10 15:44:46
                  0
                  1. Modérateur
                    T'en es où avec ton problème ?
                    0
                    1. Modérateur
                      Salut,
                      - Télécharge HijackThis Version 2.02 :
                      http://www.trendsecure.com/portal/en-US/_download/HJTInstall.exe

                      - Enregistre HJTInstall.exe sur ton bureau.
                      - Fais un double-clic sur HJTInstall.exe afin de lancer l'installation
                      - Clique sur Install ensuite sur I Accept
                      - Clique sur Do a scan system and save log file
                      - Le bloc-notes s'ouvrira, fais un copier-coller de tout son contenu ici dans ta prochaine réponse.
                      Petit tuto si besoin : http://pageperso.aol.fr/balltrap34/demohijack.htm
                      -1
                      1. Modérateur
                        ok.
                        Télécharge FindyKill (Merci à Chiquitine29 !!)

                        Fais un clic droit sur le lien, enregister sous .....sur le bureau
                        => http://sd-1.archive-host.com/membres/up/116615172019703188/FindyKill.exe

                        Dézippe le sur le bureau

                        Entre dans le dossier FindyKill
                        Double clique sur FindyKill.exe
                        Choisis l'option 1 (recherche)
                        Un rapport va s'ouvrir, poste le dans ta prochaine réponse stp

                        Note : le rapport FindyKill.txt est sauvegardé a la racine du disque (C:\FindyKill.txt)
                        -1
                        1. Modérateur
                          Parfait.

                          Nettoyage :

                          --> Double clic sur le raccourci FindyKill sur ton bureau

                          --> Au menu principal, choisis l’option 2 (Suppression)

                          /!\ il y aura 2 redémarrages, laisse travailler l’outil jusqu’à l’apparition du message "nettoyage effectué"

                          /!\ Ne te sers pas du pc durant la suppression, ton bureau ne sera pas accessible c’est normal !

                          -------> ensuite poste le rapport FindyKill.txt

                          Note : le rapport FindyKill.txt est sauvegardé a la racine du disque
                          Note : Si le Bureau ne réapparait pas presse Ctrl + Alt + Suppr, Onglet "Fichier", "Nouvelle tâche", tapes explorer.exe et valides
                          -1
                          1. tente ceci stp

                            va dans menu demarre / programmefile

                            entre dans le dossier findykill puis fixreg et supprime fixsrosa.reg

                            ensuite refais l option 2
                            -1
                            1. Télécharge combofix : http://download.bleepingcomputer.com/sUBs/ComboFix.exe

                              Avant de telecharger clic sur enregistrer renome le en killbagle et enregistre le sur le bureau

                              -> Double clique sur killbagle.exe.
                              -> Tape sur la touche 1 (Yes) pour démarrer le scan.
                              -> Lorsque le scan sera complété, un rapport apparaîtra. Copie/colle ce rapport dans ta prochaine réponse.

                              NOTE : Le rapport se trouve également ici : C:\Combofix.txt

                              Avant d'utiliser ComboFix :

                              -> Déconnecte toi d'internet et referme les fenêtres de tous les programmes en cours.

                              Une fois fait, sur ton bureau double-clic sur killbagle.exe.

                              - Répond oui au message d'avertissement, pour que le programme commence à procéder à l'analyse du pc.

                              /!\ Pendant la durée de cette étape, ne te sert pas du pc et n'ouvre aucun programmes.

                              - En fin de scan il est possible que ComboFix ait besoin de redemarrer le pc pour finaliser la désinfection\recherche, laisses-le faire.

                              - Un rapport s'ouvrira ensuite dans le bloc notes, ce fichier rapport Combofix.txt, est automatiquement sauvegardé et rangé à C:\Combofix.txt)

                              -> Reviens sur le forum, et copie et colle la totalité du contenu de C:\Combofix.txt dans ton prochain message.
                              -1