Cheval de troie purityscan

Résolu
Bonjour,

Je viens de recuperer l'ordi de ma mere dans un triste etat: je lui avait installe l'antivirus d'avira mais ca n'a pas suffit a l'empecher de faire des betises et d'attraper un tas de trucs avec:

le rapport d'avira:


Avira AntiVir Personal
Date de création du fichier de rapport : lundi 2 février 2009 18:08

La recherche porte sur 1309221 souches de virus.

Détenteur de la licence :Avira AntiVir PersonalEdition Classic
Numéro de série : 0000149996-ADJIE-0001
Plateforme : Windows XP
Version de Windows :(Service Pack 2) [5.1.2600]
Mode Boot : Démarré normalement
Identifiant : SYSTEM
Nom de l'ordinateur :ACER-79F6FF2248

Informations de version :
BUILD.DAT : 8.2.0.52 16931 Bytes 02/12/2008 14:55:00
AVSCAN.EXE : 8.1.4.10 315649 Bytes 18/11/2008 08:21:02
AVSCAN.DLL : 8.1.4.1 49921 Bytes 21/07/2008 13:44:28
LUKE.DLL : 8.1.4.5 164097 Bytes 12/06/2008 12:44:18
LUKERES.DLL : 8.1.4.0 13057 Bytes 04/07/2008 07:30:28
ANTIVIR0.VDF : 7.1.0.0 15603712 Bytes 27/10/2008 11:30:38
ANTIVIR1.VDF : 7.1.1.113 2817536 Bytes 14/01/2009 17:02:00
ANTIVIR2.VDF : 7.1.1.207 1359360 Bytes 30/01/2009 17:02:24
ANTIVIR3.VDF : 7.1.1.215 102400 Bytes 02/02/2009 17:02:26
Version du moteur: 8.2.0.71
AEVDF.DLL : 8.1.1.0 106868 Bytes 02/02/2009 17:03:00
AESCRIPT.DLL : 8.1.1.39 344443 Bytes 02/02/2009 17:02:58
AESCN.DLL : 8.1.1.6 127348 Bytes 02/02/2009 17:02:56
AERDL.DLL : 8.1.1.3 438645 Bytes 04/11/2008 13:58:40
AEPACK.DLL : 8.1.3.6 393589 Bytes 02/02/2009 17:02:54
AEOFFICE.DLL : 8.1.0.33 196987 Bytes 02/02/2009 17:02:50
AEHEUR.DLL : 8.1.0.89 1569143 Bytes 02/02/2009 17:02:46
AEHELP.DLL : 8.1.2.0 119159 Bytes 02/02/2009 17:02:34
AEGEN.DLL : 8.1.1.12 328053 Bytes 02/02/2009 17:02:32
AEEMU.DLL : 8.1.0.9 393588 Bytes 14/10/2008 10:05:58
AECORE.DLL : 8.1.6.4 176501 Bytes 02/02/2009 17:02:30
AEBB.DLL : 8.1.0.3 53618 Bytes 14/10/2008 10:05:58
AVWINLL.DLL : 1.0.0.12 15105 Bytes 09/07/2008 08:40:04
AVPREF.DLL : 8.0.2.0 38657 Bytes 16/05/2008 09:28:00
AVREP.DLL : 8.0.0.2 98344 Bytes 31/07/2008 12:02:16
AVREG.DLL : 8.0.0.1 33537 Bytes 09/05/2008 11:26:38
AVARKT.DLL : 1.0.0.23 307457 Bytes 12/02/2008 08:29:20
AVEVTLOG.DLL : 8.0.0.16 119041 Bytes 12/06/2008 12:27:48
SQLITE3.DLL : 3.3.17.1 339968 Bytes 22/01/2008 17:28:04
SMTPLIB.DLL : 1.2.0.23 28929 Bytes 12/06/2008 12:49:38
NETNT.DLL : 8.0.0.1 7937 Bytes 25/01/2008 12:05:08
RCIMAGE.DLL : 8.0.0.51 2371841 Bytes 04/07/2008 07:23:18
RCTEXT.DLL : 8.0.52.1 86273 Bytes 17/07/2008 10:08:44

Configuration pour la recherche actuelle :
Nom de la tâche..................: Contrôle intégral du système
Fichier de configuration.........: c:\program files\avira\antivir personaledition classic\sysscan.avp
Documentation....................: bas
Action principale................: interactif
Action secondaire................: ignorer
Recherche sur les secteurs d'amorçage maître: marche
Recherche sur les secteurs d'amorçage: marche
Secteurs d'amorçage..............: C:, D:,
Recherche dans les programmes actifs: marche
Recherche en cours sur l'enregistrement: marche
Recherche de Rootkits............: arrêt
Fichier mode de recherche........: Sélection de fichiers intelligente
Recherche sur les archives.......: marche
Limiter la profondeur de récursivité: 20
Archive Smart Extensions.........: marche
Heuristique de macrovirus........: marche
Heuristique fichier..............: moyen

Début de la recherche : lundi 2 février 2009 18:08

La recherche sur les processus démarrés commence :
Processus de recherche 'avscan.exe' - '1' module(s) sont contrôlés
Processus de recherche 'avcenter.exe' - '1' module(s) sont contrôlés
Processus de recherche 'avgnt.exe' - '1' module(s) sont contrôlés
Processus de recherche 'avguard.exe' - '1' module(s) sont contrôlés
Processus de recherche 'sched.exe' - '1' module(s) sont contrôlés
Processus de recherche 'jucheck.exe' - '1' module(s) sont contrôlés
Processus de recherche 'WUAUCLT.EXE' - '1' module(s) sont contrôlés
Processus de recherche 'wоwexec.exe' - '1' module(s) sont contrôlés
Processus de recherche 'wmiapsrv.exe' - '1' module(s) sont contrôlés
Processus de recherche 'userinit.exe' - '1' module(s) sont contrôlés
Module infecté -> 'C:\DOCUME~1\Laura\APPLIC~1\YSTEM~1\userinit.exe'
Processus de recherche 'SVCHOST.EXE' - '1' module(s) sont contrôlés
Processus de recherche 'SISTRAY.EXE' - '1' module(s) sont contrôlés
Processus de recherche 'JUSCHED.EXE' - '1' module(s) sont contrôlés
Processus de recherche 'SOUNDMAN.EXE' - '1' module(s) sont contrôlés
Processus de recherche 'QtZgAcer.EXE' - '1' module(s) sont contrôlés
Processus de recherche 'Monitor.exe' - '1' module(s) sont contrôlés
Processus de recherche 'SynTPEnh.exe' - '1' module(s) sont contrôlés
Processus de recherche 'SynTPLpr.exe' - '1' module(s) sont contrôlés
Processus de recherche 'Keyhook.exe' - '1' module(s) sont contrôlés
Processus de recherche 'CTFMON.EXE' - '1' module(s) sont contrôlés
Processus de recherche 'EXPLORER.EXE' - '1' module(s) sont contrôlés
Processus de recherche 'ALG.EXE' - '1' module(s) sont contrôlés
Processus de recherche 'mDNSResponder.exe' - '1' module(s) sont contrôlés
Processus de recherche 'AppleMobileDeviceService.exe' - '1' module(s) sont contrôlés
Processus de recherche 'anbmServ.exe' - '1' module(s) sont contrôlés
Processus de recherche 'SPOOLSV.EXE' - '1' module(s) sont contrôlés
Processus de recherche 'aawservice.exe' - '1' module(s) sont contrôlés
Processus de recherche 'SVCHOST.EXE' - '1' module(s) sont contrôlés
Processus de recherche 'SVCHOST.EXE' - '1' module(s) sont contrôlés
Processus de recherche 'SVCHOST.EXE' - '1' module(s) sont contrôlés
Processus de recherche 'SVCHOST.EXE' - '1' module(s) sont contrôlés
Processus de recherche 'SVCHOST.EXE' - '1' module(s) sont contrôlés
Processus de recherche 'LSASS.EXE' - '1' module(s) sont contrôlés
Processus de recherche 'SERVICES.EXE' - '1' module(s) sont contrôlés
Processus de recherche 'WINLOGON.EXE' - '1' module(s) sont contrôlés
Processus de recherche 'CSRSS.EXE' - '1' module(s) sont contrôlés
Processus de recherche 'SMSS.EXE' - '1' module(s) sont contrôlés
Le processus 'userinit.exe' est arrêté
C:\DOCUME~1\Laura\APPLIC~1\YSTEM~1\userinit.exe
[RESULTAT] Contient le cheval de Troie TR/Dldr.PurityScan.FK
[REMARQUE] Le fichier a été déplacé dans le répertoire de quarantaine sous le nom '49ec299c.qua' !

'38' processus ont été contrôlés avec '37' modules

La recherche sur les secteurs d'amorçage maître commence :
Secteur d'amorçage maître HD0
[INFO] Aucun virus trouvé !
Secteur d'amorçage maître HD1
[INFO] Aucun virus trouvé !

La recherche sur les secteurs d'amorçage commence :
Secteur d'amorçage 'C:\'
[INFO] Aucun virus trouvé !
Secteur d'amorçage 'D:\'
[INFO] Aucun virus trouvé !

La recherche sur les renvois aux fichiers exécutables (registre) commence.

Le registre a été contrôlé ( '67' fichiers).

La recherche sur les fichiers sélectionnés commence :

Recherche débutant dans 'C:\' <ACER>
C:\hiberfil.sys
[AVERTISSEMENT] Impossible d'ouvrir le fichier !
C:\PAGEFILE.SYS
[AVERTISSEMENT] Impossible d'ouvrir le fichier !
C:\WINDOWS\system32\fdid.dll
[RESULTAT] Contient le modèle de détection d'un programme de numérotation générant des coûts DIAL/Generic (dialer)
[REMARQUE] Le fichier a été déplacé dans le répertoire de quarantaine sous le nom '49f02b19.qua' !
C:\Documents and Settings\Laura\Local Settings\Temp\!update.exe
[RESULTAT] Contient le cheval de Troie TR/Dldr.PurityScan.FK
[REMARQUE] Le fichier a été déplacé dans le répertoire de quarantaine sous le nom '49f73dc3.qua' !
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\T4AVGKQ6\!update-4495[1].0000
[RESULTAT] Contient le cheval de Troie TR/Dldr.PurityScan.FK
[REMARQUE] Le fichier a été déplacé dans le répertoire de quarantaine sous le nom '49f73dcb.qua' !
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\ME3YVGGT\!update-4495[1].0000
[RESULTAT] Contient le cheval de Troie TR/Dldr.PurityScan.FK
[REMARQUE] Fichier supprimé.
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\6TXASAF3\OINAn-106[1].0000
[RESULTAT] Contient le cheval de Troie TR/Agent.60000.A
[REMARQUE] Le fichier a été déplacé dans le répertoire de quarantaine sous le nom '49d53fe7.qua' !
C:\Documents and Settings\Laura\Local Settings\Temporary Internet Files\Content.IE5\6TXASAF3\ctxad-582[1].0000
[RESULTAT] Contient le modèle de détection du programme backdoor (dangereux) BDS/Small.gij
[REMARQUE] Le fichier a été déplacé dans le répertoire de quarantaine sous le nom '49ff4016.qua' !
C:\Program Files\Outerinfo\OiUninstaller.exe
[RESULTAT] Contient le cheval de Troie TR/Agent.92392.A
[REMARQUE] Le fichier a été déplacé dans le répertoire de quarantaine sous le nom '49dc420d.qua' !
C:\System Volume Information\_restore{3FFD409C-A779-4E68-83FD-8EA2CEAF0EFF}\RP45\A0028636.exe
[RESULTAT] Contient le cheval de Troie TR/Dldr.PurityScan.FK
[REMARQUE] Le fichier a été déplacé dans le répertoire de quarantaine sous le nom '49b7471e.qua' !
C:\System Volume Information\_restore{3FFD409C-A779-4E68-83FD-8EA2CEAF0EFF}\RP45\A0028637.dll
[RESULTAT] Contient le modèle de détection d'un programme de numérotation générant des coûts DIAL/Generic (dialer)
[REMARQUE] Le fichier a été déplacé dans le répertoire de quarantaine sous le nom '49b74721.qua' !
C:\System Volume Information\_restore{3FFD409C-A779-4E68-83FD-8EA2CEAF0EFF}\RP45\A0028639.exe
[RESULTAT] Contient le cheval de Troie TR/Agent.92392.A
[REMARQUE] Le fichier a été déplacé dans le répertoire de quarantaine sous le nom '49b74725.qua' !
Recherche débutant dans 'D:\' <ACERDATA>

Fin de la recherche : lundi 2 février 2009 20:21
Temps nécessaire: 2:13:13 Heure(s)

La recherche a été effectuée intégralement

4425 Les répertoires ont été contrôlés
237870 Des fichiers ont été contrôlés
12 Des virus ou programmes indésirables ont été trouvés
0 Des fichiers ont été classés comme suspects
1 Des fichiers ont été supprimés
0 Des virus ou programmes indésirables ont été réparés
10 Les fichiers ont été déplacés dans la quarantaine
0 Les fichiers ont été renommés
2 Impossible de contrôler des fichiers
237856 Fichiers non infectés
6552 Les archives ont été contrôlées
2 Avertissements
11 Consignes

Celui qui me pose vraiment des problemes c'est TR/Dldr.PurityScan.FK
J'ai deja essaye adaware qui la trouve et l'elimine mais le petit malin est de retour au redemarrage de l'ordi...
J'ai donc fait un petit tour sur les forums et tout le monde conseille de telecharger hijackthis, ce que j'ai fait et le scan donne ca:


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:42:20, on 04/02/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Acer\eManager\anbmServ.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\keyhook.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Acer\Empowering Technology\eRecovery\Monitor.exe
C:\Program Files\Launch Manager\QtZgAcer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\sistray.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\Laura\Application Data\?ystem\w?wexec.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\hijackthis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1FD79A1C-09AB-0A5C-8C3D-50C0705881C8} - C:\WINDOWS\system32\fdid.dll (file missing)
O2 - BHO: (no name) - {33E3FF63-388C-3804-A34D-68E33CEDFA91} - C:\WINDOWS\system32\lcey.dll (file missing)
O2 - BHO: (no name) - {398DF3BE-6F0E-39DA-2975-3BB6094DA4C1} - C:\WINDOWS\system32\ejcydgb.dll (file missing)
O2 - BHO: (no name) - {418E1354-DAB8-F539-C52A-89CD5519DE9B} - C:\WINDOWS\system32\opntlhi.dll (file missing)
O2 - BHO: (no name) - {671FD78E-483B-45B9-4CF3-13D4CEC2A993} - C:\WINDOWS\system32\ptmauvma.dll (file missing)
O2 - BHO: OIN Analytics - {6B221E01-F517-4959-8C41-81948E7F2F17} - C:\Program Files\OINAnalytics\OINAnalytics2.dll
O2 - BHO: (no name) - {7011EE4A-29AE-7D22-897F-7B129343B5CE} - C:\WINDOWS\system32\vrcm.dll (file missing)
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [LaunchApp] Alaunch
O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\system32\keyhook.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [LManager] C:\Program Files\Launch Manager\QtZgAcer.EXE
O4 - HKLM\..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\Monitor.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Nphb] "C:\DOCUME~1\Laura\MESDOC~1\CROSOF~1.NET\mshta.exe" -vt yazb
O4 - HKCU\..\Run: [Bxjfk] C:\Documents and Settings\Laura\Application Data\s?stem\??rvices.exe
O4 - HKCU\..\Run: [Czapd] C:\WINDOWS\F?nts\??chost.exe
O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\WANADOO\Shell.exe appLaunchClientZone.shl|DEFAULT=cnx|PARAM=
O4 - HKCU\..\Run: [updateMgr] c:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_1_0
O4 - HKCU\..\Run: [Euec] "C:\DOCUME~1\Laura\APPLIC~1\YSTEM~1\userinit.exe" -vt ndrv
O4 - HKCU\..\Run: [Rll] "C:\Documents and Settings\Laura\Application Data\?ystem\w?wexec.exe"
O4 - HKCU\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\FlashUtil9f.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Notebook Manager Service (anbmService) - OSA Technologies Inc. - C:\Acer\eManager\anbmServ.exe
O23 - Service: Planificateur Avira AntiVir Personal - Free Antivirus (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

--
End of file - 8034 bytes

a partir de la c'est du chinois pour moi, je sais qu'il faut eliminer cetain de ces fichiers mais lesquels?
son ordi n'est deja pas tres rapide alors avec les pubs qui s'ouvrent tout le temps...
merci d'avance pour votre aide!!!!
Configuration: Windows XP
Firefox 2.0.0.14

32 réponses

Résumé de la discussion

La discussion porte sur un ordinateur infecté par le cheval de Troie TR/Dldr.PurityScan.FK et persistant après analyse antivirus, malgré Avira et les tentatives avec Ad-Aware. Avira a détecté de nombreuses traces, des fichiers ont été mis en quarantaine et le rapport HijackThis révèle de multiples entrées au démarrage et des composants malveillants infiltrant le navigateur. Ces éléments incluent des modifications du registre, des programmes autorun et des modules chargés dans les processus système, avec des chemins falsifiés et des DLL suspects signalés par les scans. En cas de persistance après quarantaine et suppression manuelle des éléments malveillants, le fil suggère une approche plus poussée, éventuellement restauration système ou réinstallation pour retrouver un fonctionnement sûr.

Bobot (l’IA à votre service)
  1. J'ai un peu attendu pour verifier que mon cheval de troie ne revenait pas mais ca a l'air bon!!
    merci a V-X pour son aide!
    0
    1. Merci beaucoup V-X!!!

      J'ai refait une analyse antivirus et plus de purity scan!!!!
      Par contre j'ai un autre cheval de troie...trash.gen, je dois commencer une autre discussion?

      mon rapport avira


      Avira AntiVir Personal
      Date de création du fichier de rapport : mercredi 11 février 2009 09:47

      La recherche porte sur 1330286 souches de virus.

      Détenteur de la licence :Avira AntiVir PersonalEdition Classic
      Numéro de série : 0000149996-ADJIE-0001
      Plateforme : Windows XP
      Version de Windows :(Service Pack 2) [5.1.2600]
      Mode Boot : Démarré normalement
      Identifiant : SYSTEM
      Nom de l'ordinateur :ACER-79F6FF2248

      Informations de version :
      BUILD.DAT : 8.2.0.52 16931 Bytes 02/12/2008 14:55:00
      AVSCAN.EXE : 8.1.4.10 315649 Bytes 18/11/2008 08:21:02
      AVSCAN.DLL : 8.1.4.1 49921 Bytes 21/07/2008 13:44:28
      LUKE.DLL : 8.1.4.5 164097 Bytes 12/06/2008 12:44:18
      LUKERES.DLL : 8.1.4.0 13057 Bytes 04/07/2008 07:30:28
      ANTIVIR0.VDF : 7.1.0.0 15603712 Bytes 27/10/2008 11:30:38
      ANTIVIR1.VDF : 7.1.1.113 2817536 Bytes 14/01/2009 17:02:00
      ANTIVIR2.VDF : 7.1.1.240 1659904 Bytes 07/02/2009 14:29:00
      ANTIVIR3.VDF : 7.1.2.6 96256 Bytes 11/02/2009 08:36:24
      Version du moteur: 8.2.0.76
      AEVDF.DLL : 8.1.1.0 106868 Bytes 02/02/2009 17:03:00
      AESCRIPT.DLL : 8.1.1.43 344442 Bytes 07/02/2009 08:59:02
      AESCN.DLL : 8.1.1.6 127348 Bytes 02/02/2009 17:02:56
      AERDL.DLL : 8.1.1.3 438645 Bytes 04/11/2008 13:58:40
      AEPACK.DLL : 8.1.3.8 397684 Bytes 07/02/2009 08:58:58
      AEOFFICE.DLL : 8.1.0.33 196987 Bytes 02/02/2009 17:02:50
      AEHEUR.DLL : 8.1.0.90 1573237 Bytes 07/02/2009 08:58:56
      AEHELP.DLL : 8.1.2.0 119159 Bytes 02/02/2009 17:02:34
      AEGEN.DLL : 8.1.1.14 332148 Bytes 07/02/2009 08:58:44
      AEEMU.DLL : 8.1.0.9 393588 Bytes 14/10/2008 10:05:58
      AECORE.DLL : 8.1.6.4 176501 Bytes 02/02/2009 17:02:30
      AEBB.DLL : 8.1.0.3 53618 Bytes 14/10/2008 10:05:58
      AVWINLL.DLL : 1.0.0.12 15105 Bytes 09/07/2008 08:40:04
      AVPREF.DLL : 8.0.2.0 38657 Bytes 16/05/2008 09:28:00
      AVREP.DLL : 8.0.0.2 98344 Bytes 31/07/2008 12:02:16
      AVREG.DLL : 8.0.0.1 33537 Bytes 09/05/2008 11:26:38
      AVARKT.DLL : 1.0.0.23 307457 Bytes 12/02/2008 08:29:20
      AVEVTLOG.DLL : 8.0.0.16 119041 Bytes 12/06/2008 12:27:48
      SQLITE3.DLL : 3.3.17.1 339968 Bytes 22/01/2008 17:28:04
      SMTPLIB.DLL : 1.2.0.23 28929 Bytes 12/06/2008 12:49:38
      NETNT.DLL : 8.0.0.1 7937 Bytes 25/01/2008 12:05:08
      RCIMAGE.DLL : 8.0.0.51 2371841 Bytes 04/07/2008 07:23:18
      RCTEXT.DLL : 8.0.52.1 86273 Bytes 17/07/2008 10:08:44

      Configuration pour la recherche actuelle :
      Nom de la tâche..................: Contrôle intégral du système
      Fichier de configuration.........: c:\program files\avira\antivir personaledition classic\sysscan.avp
      Documentation....................: bas
      Action principale................: interactif
      Action secondaire................: ignorer
      Recherche sur les secteurs d'amorçage maître: marche
      Recherche sur les secteurs d'amorçage: marche
      Secteurs d'amorçage..............: C:, D:,
      Recherche dans les programmes actifs: marche
      Recherche en cours sur l'enregistrement: marche
      Recherche de Rootkits............: arrêt
      Fichier mode de recherche........: Sélection de fichiers intelligente
      Recherche sur les archives.......: marche
      Limiter la profondeur de récursivité: 20
      Archive Smart Extensions.........: marche
      Heuristique de macrovirus........: marche
      Heuristique fichier..............: moyen

      Début de la recherche : mercredi 11 février 2009 09:47

      La recherche sur les processus démarrés commence :
      Processus de recherche 'avscan.exe' - '1' module(s) sont contrôlés
      Processus de recherche 'avscan.exe' - '1' module(s) sont contrôlés
      Processus de recherche 'update.exe' - '1' module(s) sont contrôlés
      Processus de recherche 'avcenter.exe' - '1' module(s) sont contrôlés
      Processus de recherche 'WUAUCLT.EXE' - '1' module(s) sont contrôlés
      Processus de recherche 'WUAUCLT.EXE' - '1' module(s) sont contrôlés
      Processus de recherche 'SISTRAY.EXE' - '1' module(s) sont contrôlés
      Processus de recherche 'avgnt.exe' - '1' module(s) sont contrôlés
      Processus de recherche 'jusched.exe' - '1' module(s) sont contrôlés
      Processus de recherche 'QTTask.exe' - '1' module(s) sont contrôlés
      Processus de recherche 'SOUNDMAN.EXE' - '1' module(s) sont contrôlés
      Processus de recherche 'QtZgAcer.EXE' - '1' module(s) sont contrôlés
      Processus de recherche 'SynTPEnh.exe' - '1' module(s) sont contrôlés
      Processus de recherche 'SVCHOST.EXE' - '1' module(s) sont contrôlés
      Processus de recherche 'SynTPLpr.exe' - '1' module(s) sont contrôlés
      Processus de recherche 'Keyhook.exe' - '1' module(s) sont contrôlés
      Processus de recherche 'ctfmon.exe' - '1' module(s) sont contrôlés
      Processus de recherche 'Monitor.exe' - '1' module(s) sont contrôlés
      Processus de recherche 'WUAUCLT.EXE' - '1' module(s) sont contrôlés
      Processus de recherche 'explorer.exe' - '1' module(s) sont contrôlés
      Processus de recherche 'WMIAPSRV.EXE' - '1' module(s) sont contrôlés
      Processus de recherche 'ALG.EXE' - '1' module(s) sont contrôlés
      Processus de recherche 'JQS.EXE' - '1' module(s) sont contrôlés
      Processus de recherche 'mDNSResponder.exe' - '1' module(s) sont contrôlés
      Processus de recherche 'AppleMobileDeviceService.exe' - '1' module(s) sont contrôlés
      Processus de recherche 'AVGUARD.EXE' - '1' module(s) sont contrôlés
      Processus de recherche 'anbmServ.exe' - '1' module(s) sont contrôlés
      Processus de recherche 'SCHED.EXE' - '1' module(s) sont contrôlés
      Processus de recherche 'SPOOLSV.EXE' - '1' module(s) sont contrôlés
      Processus de recherche 'SVCHOST.EXE' - '1' module(s) sont contrôlés
      Processus de recherche 'SVCHOST.EXE' - '1' module(s) sont contrôlés
      Processus de recherche 'SVCHOST.EXE' - '1' module(s) sont contrôlés
      Processus de recherche 'SVCHOST.EXE' - '1' module(s) sont contrôlés
      Processus de recherche 'SVCHOST.EXE' - '1' module(s) sont contrôlés
      Processus de recherche 'LSASS.EXE' - '1' module(s) sont contrôlés
      Processus de recherche 'SERVICES.EXE' - '1' module(s) sont contrôlés
      Processus de recherche 'WINLOGON.EXE' - '1' module(s) sont contrôlés
      Processus de recherche 'CSRSS.EXE' - '1' module(s) sont contrôlés
      Processus de recherche 'SMSS.EXE' - '1' module(s) sont contrôlés
      '39' processus ont été contrôlés avec '39' modules

      La recherche sur les secteurs d'amorçage maître commence :
      Secteur d'amorçage maître HD0
      [INFO] Aucun virus trouvé !

      La recherche sur les secteurs d'amorçage commence :
      Secteur d'amorçage 'C:\'
      [INFO] Aucun virus trouvé !
      Secteur d'amorçage 'D:\'
      [INFO] Aucun virus trouvé !

      La recherche sur les renvois aux fichiers exécutables (registre) commence.
      Le registre a été contrôlé ( '66' fichiers).

      La recherche sur les fichiers sélectionnés commence :

      Recherche débutant dans 'C:\' <ACER>
      C:\hiberfil.sys
      [AVERTISSEMENT] Impossible d'ouvrir le fichier !
      C:\PAGEFILE.SYS
      [AVERTISSEMENT] Impossible d'ouvrir le fichier !
      C:\System Volume Information\_restore{3FFD409C-A779-4E68-83FD-8EA2CEAF0EFF}\RP51\A0030372.dll
      [RESULTAT] Contient le cheval de Troie TR/Trash.Gen
      [REMARQUE] Le fichier a été déplacé dans le répertoire de quarantaine sous le nom '49c29c69.qua' !
      C:\System Volume Information\_restore{3FFD409C-A779-4E68-83FD-8EA2CEAF0EFF}\RP51\A0030373.exe
      [RESULTAT] Contient le cheval de Troie TR/Trash.Gen
      [REMARQUE] Le fichier a été déplacé dans le répertoire de quarantaine sous le nom '49c29c6e.qua' !
      Recherche débutant dans 'D:\' <ACERDATA>

      Fin de la recherche : mercredi 11 février 2009 10:41
      Temps nécessaire: 54:38 Minute(s)

      La recherche a été effectuée intégralement

      4798 Les répertoires ont été contrôlés
      246532 Des fichiers ont été contrôlés
      2 Des virus ou programmes indésirables ont été trouvés
      0 Des fichiers ont été classés comme suspects
      0 Des fichiers ont été supprimés
      0 Des virus ou programmes indésirables ont été réparés
      2 Les fichiers ont été déplacés dans la quarantaine
      0 Les fichiers ont été renommés
      2 Impossible de contrôler des fichiers
      246528 Fichiers non infectés
      6471 Les archives ont été contrôlées
      2 Avertissements
      2 Consignes
      0
      1. Re,

        ▶ Relance hijack et clique sur "Do a system scan only"

        ▶ Ensuite recherche ces lignes et coches les cases

        R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
        O2 - BHO: (no name) - {1FD79A1C-09AB-0A5C-8C3D-50C0705881C8} - C:\WINDOWS\system32\fdid.dll (file missing)
        O2 - BHO: (no name) - {33E3FF63-388C-3804-A34D-68E33CEDFA91} - C:\WINDOWS\system32\lcey.dll (file missing)
        O2 - BHO: (no name) - {398DF3BE-6F0E-39DA-2975-3BB6094DA4C1} - C:\WINDOWS\system32\ejcydgb.dll (file missing)
        O2 - BHO: (no name) - {418E1354-DAB8-F539-C52A-89CD5519DE9B} - C:\WINDOWS\system32\opntlhi.dll (file missing)
        O2 - BHO: (no name) - {7011EE4A-29AE-7D22-897F-7B129343B5CE} - C:\WINDOWS\system32\vrcm.dll (file missing)
        O4 - HKCU\..\Run: [Czapd] C:\WINDOWS\F?nts\??chost.exe

        ▶ Ensuite clique sur "Fix checked"
        xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
        ▶ Télécharge RegCleaner

        ▶ Une fois installé, double-clique sur son icône pour l'exécuter

        ▶ Dans la barre de menu, clique sur Options puis sélectionne Language => Choose the language

        ▶ recherche French.rlg et double-clique dessus pour appliquer la langue

        ▶ Clique ensuite sur Outils dans la barre de menu

        ▶ Sélectionne Nettoyage du registre => Nettoyeur de registre automatique

        ▶ RegCleaner va alors lancer le nettoyage automatiquement

        ▶ Coche ensuite les entrées invalides et clique sur Supprimer sélections => Terminer => Quitter

        Tutoriel REG-CLEANER
        0
        1. log rsit merci encore!

          Logfile of random's system information tool 1.05 (written by random/random)
          Run by Laura at 2009-02-09 16:22:36
          Microsoft Windows XP Édition familiale Service Pack 2
          System drive C: has 8 GB (49%) free of 17 GB
          Total RAM: 445 MB (32% free)

          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 16:22:43, on 09/02/2009
          Platform: Windows XP SP2 (WinNT 5.01.2600)
          MSIE: Internet Explorer v7.00 (7.00.6000.16762)
          Boot mode: Normal

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
          C:\WINDOWS\system32\spoolsv.exe
          C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
          C:\Acer\eManager\anbmServ.exe
          C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
          C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
          C:\Program Files\Bonjour\mDNSResponder.exe
          C:\Program Files\Java\jre6\bin\jqs.exe
          C:\WINDOWS\system32\wbem\wmiapsrv.exe
          C:\WINDOWS\Explorer.EXE
          C:\WINDOWS\system32\keyhook.exe
          C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
          C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
          C:\Acer\Empowering Technology\eRecovery\Monitor.exe
          C:\Program Files\Launch Manager\QtZgAcer.EXE
          C:\WINDOWS\SOUNDMAN.EXE
          C:\Program Files\Java\jre6\bin\jusched.exe
          C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\ctfmon.exe
          C:\WINDOWS\system32\wuauclt.exe
          C:\WINDOWS\system32\sistray.exe
          C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
          C:\WINDOWS\system32\wuauclt.exe
          C:\Documents and Settings\Laura\Bureau\RSIT.exe
          C:\hijackthis\Laura.exe

          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
          R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
          R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
          O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
          O2 - BHO: (no name) - {1FD79A1C-09AB-0A5C-8C3D-50C0705881C8} - C:\WINDOWS\system32\fdid.dll (file missing)
          O2 - BHO: (no name) - {33E3FF63-388C-3804-A34D-68E33CEDFA91} - C:\WINDOWS\system32\lcey.dll (file missing)
          O2 - BHO: (no name) - {398DF3BE-6F0E-39DA-2975-3BB6094DA4C1} - C:\WINDOWS\system32\ejcydgb.dll (file missing)
          O2 - BHO: (no name) - {418E1354-DAB8-F539-C52A-89CD5519DE9B} - C:\WINDOWS\system32\opntlhi.dll (file missing)
          O2 - BHO: (no name) - {7011EE4A-29AE-7D22-897F-7B129343B5CE} - C:\WINDOWS\system32\vrcm.dll (file missing)
          O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
          O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
          O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
          O4 - HKLM\..\Run: [LaunchApp] Alaunch
          O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
          O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\system32\keyhook.exe
          O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
          O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
          O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
          O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
          O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
          O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
          O4 - HKLM\..\Run: [LManager] C:\Program Files\Launch Manager\QtZgAcer.EXE
          O4 - HKLM\..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\Monitor.exe
          O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
          O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
          O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
          O4 - HKCU\..\Run: [Czapd] C:\WINDOWS\F?nts\??chost.exe
          O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\WANADOO\Shell.exe appLaunchClientZone.shl|DEFAULT=cnx|PARAM=
          O4 - HKCU\..\Run: [updateMgr] c:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_1_0
          O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
          O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
          O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe
          O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
          O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
          O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
          O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
          O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
          O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
          O23 - Service: Notebook Manager Service (anbmService) - OSA Technologies Inc. - C:\Acer\eManager\anbmServ.exe
          O23 - Service: Planificateur Avira AntiVir Personal - Free Antivirus (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
          O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
          O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
          O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
          O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
          0
          1. Re,

            Supprime bien la quarantaine de malwarebyte.

            Redémarre ton PC normalement et refait un log avec RSIT.

            merci
            0
            1. rapport malawarebytes

              Malwarebytes' Anti-Malware 1.33
              Version de la base de données: 1654
              Windows 5.1.2600 Service Pack 2

              09/02/2009 16:14:20
              mbam-log-2009-02-09 (16-14-20).txt

              Type de recherche: Examen rapide
              Eléments examinés: 51003
              Temps écoulé: 4 minute(s), 57 second(s)

              Processus mémoire infecté(s): 0
              Module(s) mémoire infecté(s): 0
              Clé(s) du Registre infectée(s): 7
              Valeur(s) du Registre infectée(s): 2
              Elément(s) de données du Registre infecté(s): 0
              Dossier(s) infecté(s): 1
              Fichier(s) infecté(s): 2

              Processus mémoire infecté(s):
              (Aucun élément nuisible détecté)

              Module(s) mémoire infecté(s):
              (Aucun élément nuisible détecté)

              Clé(s) du Registre infectée(s):
              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{671fd78e-483b-45b9-4cf3-13d4cec2a993} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\CLSID\{671fd78e-483b-45b9-4cf3-13d4cec2a993} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\oincs.oinanalytics (Adware.BHO) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\oincs.oinanalytics.1 (Adware.BHO) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\AppID\{f7fa36a4-3177-4b57-b9c1-e9c5b2e0d3a9} (Adware.BHO) -> Quarantined and deleted successfully.
              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\oinanalytics (Trojan.Agent) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\AppID\OINAnalytics.DLL (Adware.BHO) -> Quarantined and deleted successfully.

              Valeur(s) du Registre infectée(s):
              HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\Extensions\{59a40ac9-e67d-4155-b31d-4b7330fcd2d6} (Adware.Agent) -> Quarantined and deleted successfully.
              HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\nphb (Trojan.Agent) -> Quarantined and deleted successfully.

              Elément(s) de données du Registre infecté(s):
              (Aucun élément nuisible détecté)

              Dossier(s) infecté(s):
              C:\Program Files\OINAnalytics (Trojan.Agent) -> Quarantined and deleted successfully.

              Fichier(s) infecté(s):
              C:\Program Files\OINAnalytics\OINAnalytics2.dll (Trojan.Agent) -> Quarantined and deleted successfully.
              C:\Program Files\OINAnalytics\Uninstall.exe (Trojan.Agent) -> Quarantined and deleted successfully.
              0
              1. Re,

                ▶ Télécharge et installe MalwareByte's Anti-Malware
                Malwarebyte

                ▶ Mets le à jour

                ▶ Double clique sur le raccourci de MalwareByte's Anti-Malware qui est sur le bureau.

                ▶ Sélectionne Exécuter un examen RAPIDE si ce n'est pas déjà fait

                ▶ clique sur Rechercher

                ▶ Une fois le scan terminé, une fenêtre s'ouvre, clique sur sur Ok

                ▶ Si MalwareByte's n'a rien détecté, clique sur Ok Un rapport va apparaître ferme-le.

                ▶ Si MalwareByte's a détecté des infections, clique sur Afficher les résultats ensuite sur Supprimer la sélection

                ▶ Enregistre le rapport sur ton Bureau comme cela il sera plus facile à retrouver, poste ensuite ce rapport.

                Note : Si MalwareByte's a besoin de redémarrer pour terminer la suppression, accepte en cliquant sur Ok

                Si un rapport ne passe pas faire une alerte à la conciergerie avec le /!\ jaune.

                Tutoriel pour MalwareByte's
                0
                1. Bonjour!
                  et voila le rapport combofix

                  ComboFix 09-02-03.01 - Laura 2009-02-09 15:24:28.2 - [color=red][b]FAT32[/b][/color]x86
                  Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.445.186 [GMT 1:00]
                  Lancé depuis: c:\documents and settings\Laura\Bureau\C-Fix.exe
                  AV: Avira AntiVir PersonalEdition Classic *On-access scanning disabled* (Updated)

                  AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
                  .

                  (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
                  .
                  .
                  ---- Exécution préalable -------
                  .
                  c:\documents and settings\Laura\Application Data\MANTEC~1
                  c:\documents and settings\Laura\Application Data\RACLE~1
                  c:\documents and settings\Laura\Application Data\SSTEM~1
                  c:\documents and settings\Laura\Application Data\YSTEM~1
                  c:\documents and settings\Laura\Application Data\YSTEM~1\?ystem\
                  c:\documents and settings\Laura\Application Data\YSTEM~1\w?wexec.exe
                  c:\documents and settings\Laura\Menu Démarrer\Programmes\Outerinfo
                  c:\documents and settings\Laura\Menu Démarrer\Programmes\Outerinfo\Terms.lnk
                  c:\documents and settings\Laura\Menu Démarrer\Programmes\Outerinfo\Uninstall.lnk
                  c:\documents and settings\Laura\Menu Démarrer\Programmes\ucmore - the search accelerator
                  c:\documents and settings\Laura\Menu Démarrer\Programmes\ucmore - the search accelerator\How To Uninstall.lnk
                  c:\documents and settings\Laura\Menu Démarrer\Programmes\ucmore - the search accelerator\UCmore - The Search Accelerator.lnk
                  c:\documents and settings\Laura\Menu Démarrer\Programmes\ucmore - the search accelerator\UCmore Tour.lnk
                  c:\documents and settings\Laura\Mes documents\CROSOF~1.NET
                  c:\documents and settings\Laura\Mes documents\CROSOF~1.NET\??crosoft.NET\
                  c:\documents and settings\Laura\Mes documents\STEM~1
                  c:\program files\dobe~1
                  c:\program files\outerinfo
                  c:\program files\outerinfo\FF\chrome.manifest
                  c:\program files\outerinfo\FF\components\FF.dll
                  c:\program files\outerinfo\FF\components\OuterinfoAds.xpt
                  c:\program files\outerinfo\FF\install.rdf
                  c:\program files\outerinfo\outerinfo.ico
                  c:\program files\outerinfo\Terms.rtf
                  c:\program files\pppatc~1
                  c:\windows\crosof~1
                  c:\windows\fnts~1
                  c:\windows\fnts~1\??chost.exe
                  c:\windows\hosts
                  c:\windows\icroso~1
                  c:\windows\system\oeminfo.ini
                  c:\windows\system32\asks~1
                  c:\windows\system32\ppatch~1
                  c:\windows\system32\sks~1
                  c:\windows\system32\wnsapisv.exe

                  .
                  ((((((((((((((((((((((((((((( Fichiers créés du 2009-01-09 au 2009-02-09 ))))))))))))))))))))))))))))))))))))
                  .

                  2009-02-07 10:02 . 2009-02-07 10:02 <REP> d-------- C:\_OTMoveIt
                  2009-02-05 10:11 . 2009-02-05 10:11 <REP> d-------- C:\rsit
                  2009-02-04 10:39 . 2009-02-04 10:39 <REP> d-------- C:\hijackthis
                  2009-02-02 20:45 . 2009-02-02 20:45 <REP> d-------- c:\windows\system32\CatRoot_bak
                  2009-02-02 20:43 . 2008-06-14 18:59 272,768 --------- c:\windows\system32\drivers\bthport.sys
                  2009-02-02 20:43 . 2008-06-14 18:59 272,768 --------- c:\windows\system32\dllcache\bthport.sys
                  2009-02-02 20:26 . 2009-02-02 20:26 410,984 --a------ c:\windows\system32\deploytk.dll
                  2009-02-02 17:51 . 2009-02-02 17:51 <REP> d-------- c:\program files\Avira
                  2009-02-02 17:51 . 2009-02-02 17:51 <REP> d-------- c:\documents and settings\All Users\Application Data\Avira
                  2009-02-02 17:29 . 2009-02-02 17:29 <REP> d-------- c:\program files\OINAnalytics
                  2009-02-02 17:04 . 2009-02-02 17:04 <REP> d-------- c:\documents and settings\Coco\Application Data\Apple Computer

                  .
                  (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                  .
                  2008-12-13 06:37 3,593,216 ----a-w c:\windows\system32\dllcache\mshtml.dll
                  2008-12-11 11:57 333,184 ----a-w c:\windows\system32\drivers\srv.sys
                  2008-12-11 11:57 333,184 ----a-w c:\windows\system32\dllcache\srv.sys
                  2006-08-31 19:59 93,663 --sha-w c:\program files\Fichiers communs\Y1220OU.exe
                  2006-08-28 21:46 278,528 ----a-w c:\program files\Fichiers communs\FDEUnInstaller.exe
                  2008-04-25 09:23 67,696 ----a-w c:\program files\mozilla firefox\components\jar50.dll
                  2008-04-25 09:23 54,376 ----a-w c:\program files\mozilla firefox\components\jsd3250.dll
                  2008-04-25 09:23 34,952 ----a-w c:\program files\mozilla firefox\components\myspell.dll
                  2008-04-25 09:23 46,720 ----a-w c:\program files\mozilla firefox\components\spellchk.dll
                  2008-04-25 09:23 172,144 ----a-w c:\program files\mozilla firefox\components\xpinstal.dll
                  .

                  ((((((((((((((((((((((((((((( snapshot@2009-02-04_12.27.33,59 )))))))))))))))))))))))))))))))))))))))))
                  .
                  + 2008-03-01 13:58:06 124,928 ------w c:\windows\ie7updates\KB958215-IE7\advpack.dll
                  + 2008-03-01 13:58:06 347,136 ------w c:\windows\ie7updates\KB958215-IE7\dxtmsft.dll
                  + 2008-03-01 13:58:06 214,528 ------w c:\windows\ie7updates\KB958215-IE7\dxtrans.dll
                  + 2008-03-01 13:58:06 133,120 ------w c:\windows\ie7updates\KB958215-IE7\extmgr.dll
                  + 2008-03-01 13:58:06 63,488 ------w c:\windows\ie7updates\KB958215-IE7\icardie.dll
                  + 2008-02-29 09:56:42 70,656 ------w c:\windows\ie7updates\KB958215-IE7\ie4uinit.exe
                  + 2008-03-01 13:58:06 153,088 ------w c:\windows\ie7updates\KB958215-IE7\ieakeng.dll
                  + 2008-03-01 13:58:06 230,400 ------w c:\windows\ie7updates\KB958215-IE7\ieaksie.dll
                  + 2008-02-15 06:44:26 161,792 ------w c:\windows\ie7updates\KB958215-IE7\ieakui.dll
                  + 2008-03-01 13:58:08 383,488 ------w c:\windows\ie7updates\KB958215-IE7\ieapfltr.dll
                  + 2008-03-01 13:58:08 384,512 ------w c:\windows\ie7updates\KB958215-IE7\iedkcs32.dll
                  + 2008-03-01 13:58:08 6,066,176 ------w c:\windows\ie7updates\KB958215-IE7\ieframe.dll
                  + 2008-03-01 13:58:08 44,544 ------w c:\windows\ie7updates\KB958215-IE7\iernonce.dll
                  + 2008-03-01 13:58:08 267,776 ------w c:\windows\ie7updates\KB958215-IE7\iertutil.dll
                  + 2008-02-22 11:00:52 13,824 ------w c:\windows\ie7updates\KB958215-IE7\ieudinit.exe
                  + 2008-02-29 09:57:06 625,664 ------w c:\windows\ie7updates\KB958215-IE7\iexplore.exe
                  + 2008-03-01 13:58:08 27,648 ------w c:\windows\ie7updates\KB958215-IE7\jsproxy.dll
                  + 2008-03-01 13:58:08 459,264 ------w c:\windows\ie7updates\KB958215-IE7\msfeeds.dll
                  + 2008-03-01 13:58:08 52,224 ------w c:\windows\ie7updates\KB958215-IE7\msfeedsbs.dll
                  + 2008-03-01 13:58:10 478,208 ------w c:\windows\ie7updates\KB958215-IE7\mshtmled.dll
                  + 2008-03-01 13:58:10 193,024 ------w c:\windows\ie7updates\KB958215-IE7\msrating.dll
                  + 2008-03-01 13:58:10 671,232 ------w c:\windows\ie7updates\KB958215-IE7\mstime.dll
                  + 2008-03-01 13:58:10 102,912 ------w c:\windows\ie7updates\KB958215-IE7\occache.dll
                  + 2008-03-01 13:58:10 44,544 ------w c:\windows\ie7updates\KB958215-IE7\pngfilt.dll
                  + 2007-03-06 01:34:38 216,800 ------w c:\windows\ie7updates\KB958215-IE7\spuninst\spuninst.exe
                  + 2007-03-06 01:35:48 394,976 ------w c:\windows\ie7updates\KB958215-IE7\spuninst\updspapi.dll
                  + 2008-03-01 13:58:10 105,984 ------w c:\windows\ie7updates\KB958215-IE7\url.dll
                  + 2008-03-01 13:58:10 1,159,680 ------w c:\windows\ie7updates\KB958215-IE7\urlmon.dll
                  + 2008-03-01 13:58:12 233,472 ------w c:\windows\ie7updates\KB958215-IE7\webcheck.dll
                  + 2008-03-01 13:58:12 826,368 ------w c:\windows\ie7updates\KB958215-IE7\wininet.dll
                  + 2008-03-01 17:28:10 3,591,680 ------w c:\windows\ie7updates\KB960714-IE7\mshtml.dll
                  + 2007-03-06 01:34:38 216,800 ------w c:\windows\ie7updates\KB960714-IE7\spuninst\spuninst.exe
                  + 2007-03-06 01:35:48 394,976 ------w c:\windows\ie7updates\KB960714-IE7\spuninst\updspapi.dll
                  + 2009-02-04 12:16:38 32,768 ----a-r c:\windows\Installer\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}\icon.exe
                  - 2008-03-01 13:58:06 124,928 ----a-w c:\windows\system32\advpack.dll
                  + 2008-10-16 20:18:32 124,928 ----a-w c:\windows\system32\advpack.dll
                  - 2008-03-01 13:58:06 124,928 ----a-w c:\windows\system32\dllcache\advpack.dll
                  + 2008-10-16 20:18:32 124,928 ----a-w c:\windows\system32\dllcache\advpack.dll
                  - 2004-08-19 18:56:22 138,496 ----a-w c:\windows\system32\dllcache\afd.sys
                  + 2008-08-14 09:51:44 138,368 ------w c:\windows\system32\dllcache\afd.sys
                  - 2008-02-20 06:35:06 148,992 ----a-w c:\windows\system32\dllcache\dnsapi.dll
                  + 2008-06-20 17:41:06 148,992 ----a-w c:\windows\system32\dllcache\dnsapi.dll
                  - 2008-03-01 13:58:06 347,136 ----a-w c:\windows\system32\dllcache\dxtmsft.dll
                  + 2008-10-16 20:18:32 347,136 ----a-w c:\windows\system32\dllcache\dxtmsft.dll
                  - 2008-03-01 13:58:06 214,528 ----a-w c:\windows\system32\dllcache\dxtrans.dll
                  + 2008-10-16 20:18:32 214,528 ----a-w c:\windows\system32\dllcache\dxtrans.dll
                  - 2005-07-26 05:39:58 243,200 ----a-w c:\windows\system32\dllcache\es.dll
                  + 2008-07-07 20:31:48 253,952 ----a-w c:\windows\system32\dllcache\es.dll
                  - 2008-03-01 13:58:06 133,120 ----a-w c:\windows\system32\dllcache\extmgr.dll
                  + 2008-10-16 20:18:32 133,120 ----a-w c:\windows\system32\dllcache\extmgr.dll
                  - 2008-02-20 07:51:00 282,624 ----a-w c:\windows\system32\dllcache\gdi32.dll
                  + 2008-10-23 13:00:16 283,648 ----a-w c:\windows\system32\dllcache\gdi32.dll
                  - 2008-03-01 13:58:06 63,488 ------w c:\windows\system32\dllcache\icardie.dll
                  + 2008-10-16 20:18:32 63,488 ------w c:\windows\system32\dllcache\icardie.dll
                  - 2008-02-29 09:56:42 70,656 ----a-w c:\windows\system32\dllcache\ie4uinit.exe
                  + 2008-10-16 13:12:20 70,656 ----a-w c:\windows\system32\dllcache\ie4uinit.exe
                  - 2008-03-01 13:58:06 153,088 ----a-w c:\windows\system32\dllcache\ieakeng.dll
                  + 2008-10-16 20:18:32 153,088 ----a-w c:\windows\system32\dllcache\ieakeng.dll
                  - 2008-03-01 13:58:06 230,400 ----a-w c:\windows\system32\dllcache\ieaksie.dll
                  + 2008-10-16 20:18:32 230,400 ----a-w c:\windows\system32\dllcache\ieaksie.dll
                  - 2008-02-15 06:44:26 161,792 ----a-w c:\windows\system32\dllcache\ieakui.dll
                  + 2008-10-15 07:04:54 161,792 ----a-w c:\windows\system32\dllcache\ieakui.dll
                  - 2008-03-01 13:58:08 383,488 ------w c:\windows\system32\dllcache\ieapfltr.dll
                  + 2008-10-16 20:18:32 383,488 ------w c:\windows\system32\dllcache\ieapfltr.dll
                  - 2008-03-01 13:58:08 384,512 ----a-w c:\windows\system32\dllcache\iedkcs32.dll
                  + 2008-10-16 20:18:32 384,512 ----a-w c:\windows\system32\dllcache\iedkcs32.dll
                  - 2008-03-01 13:58:08 6,066,176 ------w c:\windows\system32\dllcache\ieframe.dll
                  + 2008-10-16 20:18:36 6,066,176 ------w c:\windows\system32\dllcache\ieframe.dll
                  - 2008-03-01 13:58:08 44,544 ----a-w c:\windows\system32\dllcache\iernonce.dll
                  + 2008-10-16 20:18:36 44,544 ----a-w c:\windows\system32\dllcache\iernonce.dll
                  - 2008-03-01 13:58:08 267,776 ------w c:\windows\system32\dllcache\iertutil.dll
                  + 2008-10-16 20:18:36 267,776 ------w c:\windows\system32\dllcache\iertutil.dll
                  - 2008-02-22 11:00:52 13,824 ------w c:\windows\system32\dllcache\ieudinit.exe
                  + 2008-10-16 13:11:10 13,824 ------w c:\windows\system32\dllcache\ieudinit.exe
                  - 2008-02-29 09:57:06 625,664 ----a-w c:\windows\system32\dllcache\iexplore.exe
                  + 2008-10-15 07:06:26 633,632 ----a-w c:\windows\system32\dllcache\iexplore.exe
                  - 2007-08-21 07:17:24 683,520 ----a-w c:\windows\system32\dllcache\inetcomm.dll
                  + 2008-04-11 18:51:06 683,520 ----a-w c:\windows\system32\dllcache\inetcomm.dll
                  - 2008-03-01 13:58:08 27,648 ----a-w c:\windows\system32\dllcache\jsproxy.dll
                  + 2008-10-16 20:18:36 27,648 ----a-w c:\windows\system32\dllcache\jsproxy.dll
                  - 2006-10-18 19:03:58 100,864 ----a-w c:\windows\system32\dllcache\logagent.exe
                  + 2008-06-18 00:09:22 100,864 ----a-w c:\windows\system32\dllcache\logagent.exe
                  - 2006-05-05 10:41:46 453,120 ------w c:\windows\system32\dllcache\mrxsmb.sys
                  + 2008-10-24 11:10:42 453,632 ------w c:\windows\system32\dllcache\mrxsmb.sys
                  - 2004-08-05 04:00:00 331,776 ----a-w c:\windows\system32\dllcache\msadce.dll
                  + 2008-05-01 14:31:48 331,776 ----a-w c:\windows\system32\dllcache\msadce.dll
                  - 2005-06-29 02:49:42 74,240 ----a-w c:\windows\system32\dllcache\mscms.dll
                  + 2008-06-24 16:23:56 74,240 ----a-w c:\windows\system32\dllcache\mscms.dll
                  - 2008-03-01 13:58:08 459,264 ------w c:\windows\system32\dllcache\msfeeds.dll
                  + 2008-10-16 20:18:38 459,264 ------w c:\windows\system32\dllcache\msfeeds.dll
                  - 2008-03-01 13:58:08 52,224 ------w c:\windows\system32\dllcache\msfeedsbs.dll
                  + 2008-10-16 20:18:38 52,224 ------w c:\windows\system32\dllcache\msfeedsbs.dll
                  - 2008-03-01 13:58:10 478,208 ----a-w c:\windows\system32\dllcache\mshtmled.dll
                  + 2008-10-16 20:18:40 477,696 ----a-w c:\windows\system32\dllcache\mshtmled.dll
                  - 2008-03-01 13:58:10 193,024 ----a-w c:\windows\system32\dllcache\msrating.dll
                  + 2008-10-16 20:18:40 193,024 ----a-w c:\windows\system32\dllcache\msrating.dll
                  - 2008-03-01 13:58:10 671,232 ----a-w c:\windows\system32\dllcache\mstime.dll
                  + 2008-10-16 20:18:42 671,232 ----a-w c:\windows\system32\dllcache\mstime.dll
                  - 2004-08-19 19:02:00 72,704 ----a-w c:\windows\system32\dllcache\msw3prt.dll
                  + 2008-08-28 08:03:22 74,752 ----a-w c:\windows\system32\dllcache\msw3prt.dll
                  - 2004-08-19 19:02:02 247,808 ----a-w c:\windows\system32\dllcache\mswsock.dll
                  + 2008-06-20 17:41:06 247,808 ----a-w c:\windows\system32\dllcache\mswsock.dll
                  - 2007-06-26 07:09:14 1,104,896 ----a-w c:\windows\system32\dllcache\msxml3.dll
                  + 2008-09-04 16:45:12 1,106,944 ----a-w c:\windows\system32\dllcache\msxml3.dll
                  - 2006-08-17 13:29:50 332,288 ----a-w c:\windows\system32\dllcache\netapi32.dll
                  + 2008-10-15 16:59:28 332,800 ----a-w c:\windows\system32\dllcache\netapi32.dll
                  - 2007-02-28 17:02:22 2,138,112 ------w c:\windows\system32\dllcache\ntkrnlmp.exe
                  + 2008-08-14 13:44:36 2,138,112 ------w c:\windows\system32\dllcache\ntkrnlmp.exe
                  - 2007-02-28 17:02:36 2,059,648 ------w c:\windows\system32\dllcache\ntkrnlpa.exe
                  + 2008-08-14 13:44:40 2,059,776 ------w c:\windows\system32\dllcache\ntkrnlpa.exe
                  - 2007-02-28 17:02:22 2,017,792 ------w c:\windows\system32\dllcache\ntkrpamp.exe
                  + 2008-08-14 13:44:34 2,017,792 ------w c:\windows\system32\dllcache\ntkrpamp.exe
                  - 2007-02-28 17:02:36 2,182,400 ------w c:\windows\system32\dllcache\ntoskrnl.exe
                  + 2008-08-14 13:44:38 2,182,400 ------w c:\windows\system32\dllcache\ntoskrnl.exe
                  - 2008-03-01 13:58:10 102,912 ----a-w c:\windows\system32\dllcache\occache.dll
                  + 2008-10-16 20:18:42 102,912 ----a-w c:\windows\system32\dllcache\occache.dll
                  - 2008-03-01 13:58:10 44,544 ----a-w c:\windows\system32\dllcache\pngfilt.dll
                  + 2008-10-16 20:18:42 44,544 ----a-w c:\windows\system32\dllcache\pngfilt.dll
                  - 2007-10-29 23:43:32 1,293,824 ----a-w c:\windows\system32\dllcache\quartz.dll
                  + 2008-05-07 05:15:36 1,293,824 ----a-w c:\windows\system32\dllcache\quartz.dll
                  - 2006-07-13 09:48:58 202,240 ----a-w c:\windows\system32\dllcache\rmcast.sys
                  + 2008-05-08 12:28:50 202,752 ----a-w c:\windows\system32\dllcache\rmcast.sys
                  - 2006-08-24 12:19:40 246,814 ----a-w c:\windows\system32\dllcache\strmdll.dll
                  + 2008-10-03 10:17:02 247,326 ----a-w c:\windows\system32\dllcache\strmdll.dll
                  - 2007-10-30 18:20:56 360,064 ----a-w c:\windows\system32\dllcache\tcpip.sys
                  + 2008-06-20 10:45:14 360,320 ----a-w c:\windows\system32\dllcache\tcpip.sys
                  - 2006-08-16 10:37:30 225,664 ----a-w c:\windows\system32\dllcache\tcpip6.sys
                  + 2008-06-20 09:52:06 225,920 ----a-w c:\windows\system32\dllcache\tcpip6.sys
                  - 2008-03-01 13:58:10 105,984 ----a-w c:\windows\system32\dllcache\url.dll
                  + 2008-10-16 20:18:42 105,984 ----a-w c:\windows\system32\dllcache\url.dll
                  - 2008-03-01 13:58:10 1,159,680 ----a-w c:\windows\system32\dllcache\urlmon.dll
                  + 2008-10-16 20:18:42 1,160,192 ----a-w c:\windows\system32\dllcache\urlmon.dll
                  - 2008-03-01 13:58:12 233,472 ----a-w c:\windows\system32\dllcache\webcheck.dll
                  + 2008-10-16 20:18:42 233,472 ----a-w c:\windows\system32\dllcache\webcheck.dll
                  - 2008-03-20 09:09:22 1,845,376 ----a-w c:\windows\system32\dllcache\win32k.sys
                  + 2008-09-15 15:39:16 1,846,144 ----a-w c:\windows\system32\dllcache\win32k.sys
                  - 2004-08-19 19:10:34 102,400 ----a-w c:\windows\system32\dllcache\win32spl.dll
                  + 2008-08-28 08:03:22 104,960 ----a-w c:\windows\system32\dllcache\win32spl.dll
                  - 2008-03-01 13:58:12 826,368 ----a-w c:\windows\system32\dllcache\wininet.dll
                  + 2008-10-16 20:18:44 826,368 ----a-w c:\windows\system32\dllcache\wininet.dll
                  - 2006-10-18 20:47:20 937,984 ----a-w c:\windows\system32\dllcache\WMNetMgr.dll
                  + 2008-06-18 04:03:08 938,496 ----a-w c:\windows\system32\dllcache\WMNetmgr.dll
                  - 2006-10-18 20:47:22 2,450,944 ----a-w c:\windows\system32\dllcache\wmvcore.dll
                  + 2008-06-18 04:03:14 2,458,112 ----a-w c:\windows\system32\dllcache\WMVCore.dll
                  - 2008-02-20 06:35:06 148,992 ----a-w c:\windows\system32\dnsapi.dll
                  + 2008-06-20 17:41:06 148,992 ----a-w c:\windows\system32\dnsapi.dll
                  - 2004-08-19 18:56:22 138,496 ----a-w c:\windows\system32\drivers\afd.sys
                  + 2008-08-14 09:51:44 138,368 ----a-w c:\windows\system32\drivers\afd.sys
                  - 2006-05-05 10:41:46 453,120 ----a-w c:\windows\system32\drivers\mrxsmb.sys
                  + 2008-10-24 11:10:42 453,632 ----a-w c:\windows\system32\drivers\mrxsmb.sys
                  - 2006-07-13 09:48:58 202,240 ----a-w c:\windows\system32\drivers\RMCast.sys
                  + 2008-05-08 12:28:50 202,752 ----a-w c:\windows\system32\drivers\RMCast.sys
                  - 2007-10-30 18:20:56 360,064 ----a-w c:\windows\system32\drivers\tcpip.sys
                  + 2008-06-20 10:45:14 360,320 ----a-w c:\windows\system32\drivers\tcpip.sys
                  - 2006-08-16 10:37:30 225,664 ----a-w c:\windows\system32\drivers\tcpip6.sys
                  + 2008-06-20 09:52:06 225,920 ----a-w c:\windows\system32\drivers\tcpip6.sys
                  - 2008-03-01 13:58:06 347,136 ----a-w c:\windows\system32\dxtmsft.dll
                  + 2008-10-16 20:18:32 347,136 ----a-w c:\windows\system32\dxtmsft.dll
                  - 2008-03-01 13:58:06 214,528 ----a-w c:\windows\system32\dxtrans.dll
                  + 2008-10-16 20:18:32 214,528 ----a-w c:\windows\system32\dxtrans.dll
                  - 2005-07-26 05:39:58 243,200 ----a-w c:\windows\system32\es.dll
                  + 2008-07-07 20:31:48 253,952 ----a-w c:\windows\system32\es.dll
                  - 2008-03-01 13:58:06 133,120 ----a-w c:\windows\system32\extmgr.dll
                  + 2008-10-16 20:18:32 133,120 ----a-w c:\windows\system32\extmgr.dll
                  - 2009-02-02 15:53:22 258,248 ----a-w c:\windows\system32\FNTCACHE.DAT
                  + 2009-02-05 09:03:06 258,248 ----a-w c:\windows\system32\FNTCACHE.DAT
                  - 2008-02-20 07:51:00 282,624 ----a-w c:\windows\system32\gdi32.dll
                  + 2008-10-23 13:00:16 283,648 ----a-w c:\windows\system32\gdi32.dll
                  - 2008-03-01 13:58:06 63,488 ----a-w c:\windows\system32\icardie.dll
                  + 2008-10-16 20:18:32 63,488 ----a-w c:\windows\system32\icardie.dll
                  - 2008-02-29 09:56:42 70,656 ----a-w c:\windows\system32\ie4uinit.exe
                  + 2008-10-16 13:12:20 70,656 ----a-w c:\windows\system32\ie4uinit.exe
                  - 2008-03-01 13:58:06 153,088 ----a-w c:\windows\system32\ieakeng.dll
                  + 2008-10-16 20:18:32 153,088 ----a-w c:\windows\system32\ieakeng.dll
                  - 2008-03-01 13:58:06 230,400 ----a-w c:\windows\system32\ieaksie.dll
                  + 2008-10-16 20:18:32 230,400 ----a-w c:\windows\system32\ieaksie.dll
                  - 2008-02-15 06:44:26 161,792 ----a-w c:\windows\system32\ieakui.dll
                  + 2008-10-15 07:04:54 161,792 ----a-w c:\windows\system32\ieakui.dll
                  - 2008-03-01 13:58:08 383,488 ----a-w c:\windows\system32\ieapfltr.dll
                  + 2008-10-16 20:18:32 383,488 ----a-w c:\windows\system32\ieapfltr.dll
                  - 2008-03-01 13:58:08 384,512 ----a-w c:\windows\system32\iedkcs32.dll
                  + 2008-10-16 20:18:32 384,512 ----a-w c:\windows\system32\iedkcs32.dll
                  - 2008-03-01 13:58:08 6,066,176 ----a-w c:\windows\system32\ieframe.dll
                  + 2008-10-16 20:18:36 6,066,176 ----a-w c:\windows\system32\ieframe.dll
                  - 2008-03-01 13:58:08 44,544 ----a-w c:\windows\system32\iernonce.dll
                  + 2008-10-16 20:18:36 44,544 ----a-w c:\windows\system32\iernonce.dll
                  - 2008-03-01 13:58:08 267,776 ----a-w c:\windows\system32\iertutil.dll
                  + 2008-10-16 20:18:36 267,776 ----a-w c:\windows\system32\iertutil.dll
                  - 2008-02-22 11:00:52 13,824 ----a-w c:\windows\system32\ieudinit.exe
                  + 2008-10-16 13:11:10 13,824 ----a-w c:\windows\system32\ieudinit.exe
                  - 2007-08-21 07:17:24 683,520 ----a-w c:\windows\system32\inetcomm.dll
                  + 2008-04-11 18:51:06 683,520 ----a-w c:\windows\system32\inetcomm.dll
                  - 2008-03-01 13:58:08 27,648 ----a-w c:\windows\system32\jsproxy.dll
                  + 2008-10-16 20:18:36 27,648 ----a-w c:\windows\system32\jsproxy.dll
                  - 2006-10-18 19:03:58 100,864 ----a-w c:\windows\system32\logagent.exe
                  + 2008-06-18 00:09:22 100,864 ----a-w c:\windows\system32\logagent.exe
                  - 2008-05-09 13:35:06 16,863,864 ----a-w c:\windows\system32\MRT.exe
                  + 2009-01-09 16:35:30 20,853,704 ----a-w c:\windows\system32\MRT.exe
                  - 2005-06-29 02:49:42 74,240 ----a-w c:\windows\system32\mscms.dll
                  + 2008-06-24 16:23:56 74,240 ----a-w c:\windows\system32\mscms.dll
                  - 2008-03-01 13:58:08 459,264 ----a-w c:\windows\system32\msfeeds.dll
                  + 2008-10-16 20:18:38 459,264 ----a-w c:\windows\system32\msfeeds.dll
                  - 2008-03-01 13:58:08 52,224 ----a-w c:\windows\system32\msfeedsbs.dll
                  + 2008-10-16 20:18:38 52,224 ----a-w c:\windows\system32\msfeedsbs.dll
                  - 2008-03-01 17:28:10 3,591,680 ----a-w c:\windows\system32\mshtml.dll
                  + 2008-12-13 06:37:56 3,593,216 ----a-w c:\windows\system32\mshtml.dll
                  - 2008-03-01 13:58:10 478,208 ----a-w c:\windows\system32\mshtmled.dll
                  + 2008-10-16 20:18:40 477,696 ----a-w c:\windows\system32\mshtmled.dll
                  - 2008-03-01 13:58:10 193,024 ----a-w c:\windows\system32\msrating.dll
                  + 2008-10-16 20:18:40 193,024 ----a-w c:\windows\system32\msrating.dll
                  - 2008-03-01 13:58:10 671,232 ----a-w c:\windows\system32\mstime.dll
                  + 2008-10-16 20:18:42 671,232 ----a-w c:\windows\system32\mstime.dll
                  - 2004-08-19 19:02:00 72,704 ----a-w c:\windows\system32\msw3prt.dll
                  + 2008-08-28 08:03:22 74,752 ----a-w c:\windows\system32\msw3prt.dll
                  - 2004-08-19 19:02:02 247,808 ----a-w c:\windows\system32\mswsock.dll
                  + 2008-06-20 17:41:06 247,808 ----a-w c:\windows\system32\mswsock.dll
                  - 2007-06-26 07:09:14 1,104,896 ----a-w c:\windows\system32\msxml3.dll
                  + 2008-09-04 16:45:12 1,106,944 ----a-w c:\windows\system32\msxml3.dll
                  - 2007-05-08 14:03:04 1,275,392 ----a-w c:\windows\system32\msxml4.dll
                  + 2008-09-30 15:43:34 1,286,152 ----a-w c:\windows\system32\msxml4.dll
                  - 2007-05-15 14:43:10 1,320,800 ----a-w c:\windows\system32\msxml6.dll
                  + 2008-08-29 19:06:44 1,350,664 ----a-w c:\windows\system32\msxml6.dll
                  - 2006-08-17 13:29:50 332,288 ----a-w c:\windows\system32\netapi32.dll
                  + 2008-10-15 16:59:28 332,800 ----a-w c:\windows\system32\netapi32.dll
                  - 2007-02-28 17:02:36 2,059,648 ----a-w c:\windows\system32\ntkrnlpa.exe
                  + 2008-08-14 13:44:40 2,059,776 ----a-w c:\windows\system32\ntkrnlpa.exe
                  - 2007-02-28 17:02:36 2,182,400 ----a-w c:\windows\system32\ntoskrnl.exe
                  + 2008-08-14 13:44:38 2,182,400 ----a-w c:\windows\system32\ntoskrnl.exe
                  - 2008-03-01 13:58:10 102,912 ----a-w c:\windows\system32\occache.dll
                  + 2008-10-16 20:18:42 102,912 ----a-w c:\windows\system32\occache.dll
                  - 2008-03-01 13:58:10 44,544 ----a-w c:\windows\system32\pngfilt.dll
                  + 2008-10-16 20:18:42 44,544 ----a-w c:\windows\system32\pngfilt.dll
                  - 2007-10-29 23:43:32 1,293,824 ----a-w c:\windows\system32\quartz.dll
                  + 2008-05-07 05:15:36 1,293,824 ----a-w c:\windows\system32\quartz.dll
                  - 2006-10-16 15:10:58 14,640 ------w c:\windows\system32\spmsg.dll
                  + 2007-11-30 11:19:06 18,296 ------w c:\windows\system32\spmsg.dll
                  - 2006-08-24 12:19:40 246,814 ----a-w c:\windows\system32\strmdll.dll
                  + 2008-10-03 10:17:02 247,326 ----a-w c:\windows\system32\strmdll.dll
                  - 2007-11-13 12:31:12 60,416 ------w c:\windows\system32\tzchange.exe
                  + 2008-10-22 09:47:08 62,976 ------w c:\windows\system32\tzchange.exe
                  - 2008-03-01 13:58:10 105,984 ----a-w c:\windows\system32\url.dll
                  + 2008-10-16 20:18:42 105,984 ----a-w c:\windows\system32\url.dll
                  - 2008-03-01 13:58:10 1,159,680 ----a-w c:\windows\system32\urlmon.dll
                  + 2008-10-16 20:18:42 1,160,192 ----a-w c:\windows\system32\urlmon.dll
                  - 2008-03-01 13:58:12 233,472 ----a-w c:\windows\system32\webcheck.dll
                  + 2008-10-16 20:18:42 233,472 ----a-w c:\windows\system32\webcheck.dll
                  - 2008-03-20 09:09:22 1,845,376 ----a-w c:\windows\system32\win32k.sys
                  + 2008-09-15 15:39:16 1,846,144 ----a-w c:\windows\system32\win32k.sys
                  - 2004-08-19 19:10:34 102,400 ----a-w c:\windows\system32\win32spl.dll
                  + 2008-08-28 08:03:22 104,960 ----a-w c:\windows\system32\win32spl.dll
                  - 2008-03-01 13:58:12 826,368 ----a-w c:\windows\system32\wininet.dll
                  + 2008-10-16 20:18:44 826,368 ----a-w c:\windows\system32\wininet.dll
                  - 2006-10-18 20:47:20 937,984 ----a-w c:\windows\system32\WMNetMgr.dll
                  + 2008-06-18 04:03:08 938,496 ----a-w c:\windows\system32\WMNetmgr.dll
                  - 2006-10-18 20:47:20 295,936 ------w c:\windows\system32\wmpeffects.dll
                  + 2008-06-24 17:12:58 295,936 ------w c:\windows\system32\wmpeffects.dll
                  - 2006-10-18 20:47:22 2,450,944 ----a-w c:\windows\system32\wmvcore.dll
                  + 2008-06-18 04:03:14 2,458,112 ----a-w c:\windows\system32\WMVCore.dll
                  + 2009-02-09 14:13:34 16,384 ----a-w c:\windows\Temp\Perflib_Perfdata_750.dat
                  + 2008-09-30 15:42:08 1,286,152 ----a-w c:\windows\WinSxS\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9870.0_x-ww_a32d74cf\msxml4.dll
                  + 2008-09-30 15:45:12 91,656 ----a-w c:\windows\WinSxS\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.1.0_x-ww_2a41bceb\msxml4r.dll
                  + 2008-04-15 17:57:00 1,724,416 ----a-w c:\windows\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.3352_x-ww_81af8e88\GdiPlus.dll
                  .
                  -- Instantané actualisé --
                  .
                  ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
                  .
                  .
                  *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
                  REGEDIT4

                  [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1FD79A1C-09AB-0A5C-8C3D-50C0705881C8}]
                  c:\windows\system32\fdid.dll [BU]

                  [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{33E3FF63-388C-3804-A34D-68E33CEDFA91}]
                  c:\windows\system32\lcey.dll [BU]

                  [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{398DF3BE-6F0E-39DA-2975-3BB6094DA4C1}]
                  c:\windows\system32\ejcydgb.dll [BU]

                  [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{418E1354-DAB8-F539-C52A-89CD5519DE9B}]
                  c:\windows\system32\opntlhi.dll [BU]

                  [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{671FD78E-483B-45B9-4CF3-13D4CEC2A993}]
                  c:\windows\system32\ptmauvma.dll [BU]

                  [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7011EE4A-29AE-7D22-897F-7B129343B5CE}]
                  c:\windows\system32\vrcm.dll [BU]

                  [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                  "Czapd"="c:\windows\F?nts\??chost.exe" [?]
                  "CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-19 15360]
                  "Nphb"="c:\docume~1\Laura\MESDOC~1\CROSOF~1.NET\mshta.exe" [BU]
                  "WOOKIT"="c:\progra~1\WANADOO\Shell.exe" [BU]
                  "updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                  "LaunchApp"="Alaunch" [X]
                  "SiS Windows KeyHook"="c:\windows\system32\keyhook.exe" [2005-03-04 32768]
                  "SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2004-10-07 98394]
                  "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2004-10-07 688218]
                  "IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-05 208952]
                  "MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-19 59392]
                  "PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-19 455168]
                  "PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-19 455168]
                  "LManager"="c:\program files\Launch Manager\QtZgAcer.EXE" [2005-03-28 315392]
                  "eRecoveryService"="c:\acer\Empowering Technology\eRecovery\Monitor.exe" [2005-11-16 393216]
                  "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-03-28 413696]
                  "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-02-02 136600]
                  "avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
                  "SiSPower"="SiSPower.dll" [2005-02-25 c:\windows\system32\SiSPower.dll]
                  "SoundMan"="SOUNDMAN.EXE" [2005-02-23 c:\windows\SOUNDMAN.EXE]

                  [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
                  "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-19 15360]

                  c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
                  Utility Tray.lnk - c:\windows\system32\sistray.exe [2005-01-04 331776]
                  Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-04-23 29696]

                  [HKEY_LOCAL_MACHINE\software\microsoft\security center]
                  "AntiVirusDisableNotify"=dword:00000001

                  [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
                  "EnableFirewall"= 0 (0x0)

                  [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
                  "%windir%\\system32\\sessmgr.exe"=
                  "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
                  "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=

                  R2 osaio;osaio;c:\windows\system32\drivers\osaio.sys [2005-06-30 7296]
                  R2 osanbm;osanbm;c:\windows\system32\drivers\osanbm.sys [2005-01-14 4010]
                  R3 HSFHWSIS;HSFHWSIS;c:\windows\system32\drivers\HSFHWSIS.sys [2004-12-15 200576]
                  S3 SIS163u;SiS163 usb Wireless LAN Adapter Driver;c:\windows\system32\drivers\SIS163u.SYS [2005-06-20 215040]

                  --- Autres Services/Pilotes en mémoire ---

                  *NewlyCreated* - INT15.SYS
                  .
                  Contenu du dossier 'Tâches planifiées'

                  2009-02-04 c:\windows\Tasks\AppleSoftwareUpdate.job
                  - c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 14:57]
                  .
                  .
                  ------- Examen supplémentaire -------
                  .
                  uStart Page = hxxp://www.wanadoo.fr/
                  uInternet Settings,ProxyOverride = *.local
                  uSearchURL,(Default) = hxxp://g.msn.fr/0SEFRFR/SAOS01?FORM=TOOLBR
                  IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                  FF - ProfilePath - c:\documents and settings\Laura\Application Data\Mozilla\Firefox\Profiles\tzcrje39.default\
                  FF - prefs.js: browser.search.defaulturl - hxxp://fr.search.yahoo.com/search?ei=UTF-8&fr=ytff-sunm&p=
                  FF - prefs.js: browser.search.selectedEngine - Yahoo
                  FF - prefs.js: keyword.URL - hxxp://fr.search.yahoo.com/search?ei=UTF-8&fr=ytff-sunm&p=
                  FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll
                  .

                  **************************************************************************

                  catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                  Rootkit scan 2009-02-09 15:25:53
                  Windows 5.1.2600 Service Pack 2 FAT NTAPI

                  Recherche de processus cachés ...

                  Recherche d'éléments en démarrage automatique cachés ...

                  Recherche de fichiers cachés ...

                  Scan terminé avec succès
                  Fichiers cachés: 0

                  **************************************************************************
                  .
                  Heure de fin: 2009-02-09 15:27:02
                  ComboFix-quarantined-files.txt 2009-02-09 14:27:02

                  Avant-CF: 8,675,622,912 octets libres
                  Après-CF: 8,686,403,584 octets libres

                  432 --- E O F --- 2009-02-09 14:18:11
                  0
                  1. merci a toi!

                    rsit m'a juste sorti un rapport log, le rapport info n'a pas ete modifie

                    Logfile of random's system information tool 1.05 (written by random/random)
                    Run by Laura at 2009-02-08 09:02:34
                    Microsoft Windows XP Édition familiale Service Pack 2
                    System drive C: has 8 GB (50%) free of 17 GB
                    Total RAM: 445 MB (16% free)

                    Logfile of Trend Micro HijackThis v2.0.2
                    Scan saved at 09:02, on 2009-02-08
                    Platform: Windows XP SP2 (WinNT 5.01.2600)
                    MSIE: Internet Explorer v7.00 (7.00.6000.16762)
                    Boot mode: Normal

                    Running processes:
                    C:\WINDOWS\System32\smss.exe
                    C:\WINDOWS\system32\winlogon.exe
                    C:\WINDOWS\system32\services.exe
                    C:\WINDOWS\system32\lsass.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                    C:\WINDOWS\system32\spoolsv.exe
                    C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                    C:\Acer\eManager\anbmServ.exe
                    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                    C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                    C:\Program Files\Bonjour\mDNSResponder.exe
                    C:\Program Files\Java\jre6\bin\jqs.exe
                    C:\WINDOWS\Explorer.EXE
                    C:\WINDOWS\system32\keyhook.exe
                    C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
                    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                    C:\WINDOWS\system32\wbem\wmiapsrv.exe
                    C:\Program Files\Launch Manager\QtZgAcer.EXE
                    C:\Acer\Empowering Technology\eRecovery\Monitor.exe
                    C:\WINDOWS\SOUNDMAN.EXE
                    C:\Program Files\Java\jre6\bin\jusched.exe
                    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                    C:\WINDOWS\system32\ctfmon.exe
                    C:\WINDOWS\system32\sistray.exe
                    C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\WINDOWS\system32\wuauclt.exe
                    C:\Program Files\Mozilla Firefox\firefox.exe
                    C:\WINDOWS\system32\wuauclt.exe
                    C:\Documents and Settings\Laura\Bureau\RSIT.exe
                    C:\hijackthis\Laura.exe

                    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
                    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                    O2 - BHO: (no name) - {1FD79A1C-09AB-0A5C-8C3D-50C0705881C8} - C:\WINDOWS\system32\fdid.dll (file missing)
                    O2 - BHO: (no name) - {33E3FF63-388C-3804-A34D-68E33CEDFA91} - C:\WINDOWS\system32\lcey.dll (file missing)
                    O2 - BHO: (no name) - {398DF3BE-6F0E-39DA-2975-3BB6094DA4C1} - C:\WINDOWS\system32\ejcydgb.dll (file missing)
                    O2 - BHO: (no name) - {418E1354-DAB8-F539-C52A-89CD5519DE9B} - C:\WINDOWS\system32\opntlhi.dll (file missing)
                    O2 - BHO: (no name) - {671FD78E-483B-45B9-4CF3-13D4CEC2A993} - C:\WINDOWS\system32\ptmauvma.dll (file missing)
                    O2 - BHO: (no name) - {7011EE4A-29AE-7D22-897F-7B129343B5CE} - C:\WINDOWS\system32\vrcm.dll (file missing)
                    O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
                    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
                    O4 - HKLM\..\Run: [LaunchApp] Alaunch
                    O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
                    O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\system32\keyhook.exe
                    O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
                    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                    O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
                    O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
                    O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
                    O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
                    O4 - HKLM\..\Run: [LManager] C:\Program Files\Launch Manager\QtZgAcer.EXE
                    O4 - HKLM\..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\Monitor.exe
                    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
                    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                    O4 - HKCU\..\Run: [Nphb] "C:\DOCUME~1\Laura\MESDOC~1\CROSOF~1.NET\mshta.exe" -vt yazb
                    O4 - HKCU\..\Run: [Czapd] C:\WINDOWS\F?nts\??chost.exe
                    O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\WANADOO\Shell.exe appLaunchClientZone.shl|DEFAULT=cnx|PARAM=
                    O4 - HKCU\..\Run: [updateMgr] c:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_1_0
                    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                    O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe
                    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                    O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
                    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
                    O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                    O23 - Service: Notebook Manager Service (anbmService) - OSA Technologies Inc. - C:\Acer\eManager\anbmServ.exe
                    O23 - Service: Planificateur Avira AntiVir Personal - Free Antivirus (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                    O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                    O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
                    0
                    1. Re,

                      Redémarre ton pc et refait un rapport avec rsit.

                      merci
                      0
                      1. Voila!!!

                        ========== PROCESSES ==========
                        Process explorer.exe killed successfully.
                        ========== REGISTRY ==========
                        Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\Bxjfk deleted successfully.
                        Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\Euec deleted successfully.
                        Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\Rll deleted successfully.
                        ========== FILES ==========
                        File/Folder c:\documents and settings\laura\application data\s?stem\??rvices.exe not found.
                        File/Folder c:\program files\ystem~1\userinit.exe not found.
                        File/Folder c:\documents and settings\laura\application data\?ystem\w?wexec.exe not found.
                        File/Folder c:\documents and settings\laura\application data\s?stem\??rvices.exe not found.
                        File/Folder c:\documents and settings\laura\application data\?ystem\w?wexec.exe not found.
                        ========== COMMANDS ==========
                        User's Temp folder emptied.
                        User's Temporary Internet Files folder emptied.
                        User's Internet Explorer cache folder emptied.
                        Local Service Temp folder emptied.
                        Local Service Temporary Internet Files folder emptied.
                        Windows Temp folder emptied.
                        FireFox cache emptied.
                        Temp folders emptied.

                        OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 02072009_100229

                        ca a l'air beaucoup mieux, je n'ai plus les icones de pubs qui se reinstallent a chaque fois...
                        0
                        1. Re,

                          ---> Télécharge OTMoveIt3 (OldTimer) sur ton Bureau :
                          http://oldtimer.geekstogo.com/OTMoveIt3.exe

                          ---> Double-clique sur OTMoveIt3.exe afin de le lancer.

                          ---> Copie (Ctrl+C) le texte suivant en gras ci-dessous :

                          :processes
                          explorer.exe

                          :reg
                          [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
                          "Bxjfk"=-
                          [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
                          "Euec"=-
                          [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
                          "Rll"=-

                          :files
                          c:\documents and settings\laura\application data\s?stem\??rvices.exe /U
                          c:\program files\ystem~1\userinit.exe
                          c:\documents and settings\laura\application data\?ystem\w?wexec.exe /U
                          c:\documents and settings\laura\application data\s?stem\??rvices.exe /U
                          c:\documents and settings\laura\application data\?ystem\w?wexec.exe /U

                          :commands
                          [purity]
                          [emptytemp]
                          [reboot]


                          ---> Colle (Ctrl+V) le texte précédemment copié dans le cadre Paste Instructions for Items to be Moved.

                          ---> Clique maintenant sur le bouton MoveIt! puis ferme OTMoveIt3.

                          Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
                          Accepte en cliquant sur YES.

                          ---> Poste le rapport situé dans ce dossier : C:\_OTMoveIt\MovedFiles\
                          Le nom du rapport correspond au moment de sa création : date_heure.log
                          0
                          1. info.txt logfile of random's system information tool 1.05 2009-02-05 10:13:39

                            ======Uninstall list======

                            -->C:\WINDOWS\IsUninst.exe -f"C:\Program Files\Acer Inc.\Acer French Guide Link\Uninst.isu"
                            -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E06E4F4E-72D6-4497-BFFD-BCB43077C2F4}\setup.exe" -l0x40c -uninst
                            -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
                            802.11 USB Wireless LAN Adapter-->C:\WINDOWS\system32\unwlsdrv.exe SiS163u
                            Acer eManager for Notebook-->C:\Program Files\Fichiers communs\InstallShield\Driver\8\Intel 32\IDriver.exe /M{827289F5-B44F-4E49-9993-840741585A62}
                            Acer GridVista-->C:\WINDOWS\UnInst32.exe GridV.UNI
                            Ad-Aware 2007-->MsiExec.exe /I{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}
                            Adobe Flash Player ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
                            Adobe Flash Player Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
                            Adobe Reader 7.1.0-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A71000000002}
                            AFPL Ghostscript 8.54-->C:\Program Files\gs\uninstgs.exe "C:\Program Files\gs\gs8.54\uninstal.txt"
                            AFPL Ghostscript Fonts-->C:\Program Files\gs\uninstgs.exe "C:\Program Files\gs\fonts\uninstal.txt"
                            Apple Mobile Device Support-->MsiExec.exe /I{44734179-8A79-4DEE-BB08-73037F065543}
                            Apple Software Update-->MsiExec.exe /I{B74F042E-E1B9-4A5B-8D46-387BB172F0A4}
                            Aspell German Dictionary-0.50-2-->"C:\Program Files\Aspell\unins001.exe"
                            Avira AntiVir Personal - Free Antivirus-->C:\Program Files\Avira\AntiVir PersonalEdition Classic\SETUP.EXE /REMOVE
                            Bonjour-->MsiExec.exe /I{47BF1BD6-DCAC-468F-A0AD-E5DECC2211C3}
                            Correctif pour Lecteur Windows Media 11 (KB939683)-->"C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
                            Correctif pour Windows Internet Explorer 7 (KB947864)-->"C:\WINDOWS\ie7updates\KB947864-IE7\spuninst\spuninst.exe"
                            Correctif pour Windows XP (KB914440)-->"C:\WINDOWS\$NtUninstallKB914440$\spuninst\spuninst.exe"
                            Correctif pour Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
                            Correctif Windows XP - KB873339-->C:\WINDOWS\$NtUninstallKB873339$\spuninst\spuninst.exe
                            Correctif Windows XP - KB885835-->C:\WINDOWS\$NtUninstallKB885835$\spuninst\spuninst.exe
                            Correctif Windows XP - KB885836-->C:\WINDOWS\$NtUninstallKB885836$\spuninst\spuninst.exe
                            Correctif Windows XP - KB886185-->C:\WINDOWS\$NtUninstallKB886185$\spuninst\spuninst.exe
                            Correctif Windows XP - KB888302-->C:\WINDOWS\$NtUninstallKB888302$\spuninst\spuninst.exe
                            Correctif Windows XP - KB890859-->"C:\WINDOWS\$NtUninstallKB890859$\spuninst\spuninst.exe"
                            Correctif Windows XP - KB891781-->C:\WINDOWS\$NtUninstallKB891781$\spuninst\spuninst.exe
                            GNU Aspell 0.50-3-->"C:\Program Files\Aspell\unins000.exe"
                            Google Earth-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3DE5E7D4-7B88-403C-A3FD-2017A8240C5B}\setup.exe" -l0x40c -removeonly
                            HijackThis 2.0.2-->"C:\hijackthis\HijackThis.exe" /uninstall
                            Hotfix for Microsoft .NET Framework 3.0 (KB932471)-->C:\WINDOWS\system32\msiexec.exe /promptrestart /uninstall {ECD292A0-0347-4244-8C24-5DBCE990FB40} /package {BAF78226-3200-4DB4-BE33-4D922A799840}
                            Hotfix for Windows Media Format 11 SDK (KB929399)-->"C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
                            Hotfix for Windows XP (KB915865)-->"C:\WINDOWS\$NtUninstallKB915865$\spuninst\spuninst.exe"
                            Hotfix for Windows XP (KB926239)-->"C:\WINDOWS\$NtUninstallKB926239$\spuninst\spuninst.exe"
                            Java(TM) 6 Update 11-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216011FF}
                            Java(TM) 6 Update 5-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160050}
                            K-Lite Codec Pack 2.81 Full-->"C:\Program Files\K-Lite Codec Pack\unins000.exe"
                            Launch Manager-->C:\WINDOWS\UnInst32.exe QtZgAcer.UNI
                            Lecteur Windows Media 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
                            Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
                            Microsoft .NET Framework 1.1 French Language Pack-->MsiExec.exe /X{9A394342-4A68-4EBA-85A6-55B559F4E700}
                            Microsoft .NET Framework 1.1 Hotfix (KB928366)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"
                            Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
                            Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
                            Microsoft .NET Framework 2.0 Service Pack 1-->MsiExec.exe /I{B508B3F1-A24A-32C0-B310-85786919EF28}
                            Microsoft .NET Framework 3.0 French Language Pack-->MsiExec.exe /X{E3C080B0-23F5-49AF-89F8-8E8DBC89E659}
                            Microsoft .NET Framework 3.0-->c:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\setup.exe
                            Microsoft .NET Framework 3.0-->MsiExec.exe /X{15095BF3-A3D7-4DDF-B193-3A496881E003}
                            Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
                            Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
                            Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
                            Microsoft Office Professional Edition 2003-->MsiExec.exe /I{9111040C-6000-11D3-8CFE-0150048383C9}
                            Microsoft User-Mode Driver Framework Feature Pack 1.0-->"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Lecteur Windows Media (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Lecteur Windows Media 11 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Lecteur Windows Media 11 (KB954154)-->"C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Lecteur Windows Media 9 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP9$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows Internet Explorer 7 (KB937143)-->"C:\WINDOWS\ie7updates\KB937143-IE7\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows Internet Explorer 7 (KB938127)-->"C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows Internet Explorer 7 (KB958215)-->"C:\WINDOWS\ie7updates\KB958215-IE7\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows Internet Explorer 7 (KB960714)-->"C:\WINDOWS\ie7updates\KB960714-IE7\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB890046)-->"C:\WINDOWS\$NtUninstallKB890046$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB893756)-->"C:\WINDOWS\$NtUninstallKB893756$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB896358)-->"C:\WINDOWS\$NtUninstallKB896358$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB896423)-->"C:\WINDOWS\$NtUninstallKB896423$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB896428)-->"C:\WINDOWS\$NtUninstallKB896428$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB899587)-->"C:\WINDOWS\$NtUninstallKB899587$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB899591)-->"C:\WINDOWS\$NtUninstallKB899591$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB900725)-->"C:\WINDOWS\$NtUninstallKB900725$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB901017)-->"C:\WINDOWS\$NtUninstallKB901017$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB901190)-->"C:\WINDOWS\$NtUninstallKB901190$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB901214)-->"C:\WINDOWS\$NtUninstallKB901214$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB902400)-->"C:\WINDOWS\$NtUninstallKB902400$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB904706)-->"C:\WINDOWS\$NtUninstallKB904706$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB905414)-->"C:\WINDOWS\$NtUninstallKB905414$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB905749)-->"C:\WINDOWS\$NtUninstallKB905749$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB908519)-->"C:\WINDOWS\$NtUninstallKB908519$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB911562)-->"C:\WINDOWS\$NtUninstallKB911562$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB911927)-->"C:\WINDOWS\$NtUninstallKB911927$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB913580)-->"C:\WINDOWS\$NtUninstallKB913580$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB914388)-->"C:\WINDOWS\$NtUninstallKB914388$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB914389)-->"C:\WINDOWS\$NtUninstallKB914389$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB917344)-->"C:\WINDOWS\$NtUninstallKB917344$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB917953)-->"C:\WINDOWS\$NtUninstallKB917953$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB918118)-->"C:\WINDOWS\$NtUninstallKB918118$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB918439)-->"C:\WINDOWS\$NtUninstallKB918439$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB919007)-->"C:\WINDOWS\$NtUninstallKB919007$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB920213)-->"C:\WINDOWS\$NtUninstallKB920213$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB920670)-->"C:\WINDOWS\$NtUninstallKB920670$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB920683)-->"C:\WINDOWS\$NtUninstallKB920683$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB920685)-->"C:\WINDOWS\$NtUninstallKB920685$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB921503)-->"C:\WINDOWS\$NtUninstallKB921503$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB922819)-->"C:\WINDOWS\$NtUninstallKB922819$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB923191)-->"C:\WINDOWS\$NtUninstallKB923191$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB923414)-->"C:\WINDOWS\$NtUninstallKB923414$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB923689)-->"C:\WINDOWS\$NtUninstallKB923689$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB923980)-->"C:\WINDOWS\$NtUninstallKB923980$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB924270)-->"C:\WINDOWS\$NtUninstallKB924270$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB924496)-->"C:\WINDOWS\$NtUninstallKB924496$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB924667)-->"C:\WINDOWS\$NtUninstallKB924667$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB925902)-->"C:\WINDOWS\$NtUninstallKB925902$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB926255)-->"C:\WINDOWS\$NtUninstallKB926255$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB926436)-->"C:\WINDOWS\$NtUninstallKB926436$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB927779)-->"C:\WINDOWS\$NtUninstallKB927779$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB927802)-->"C:\WINDOWS\$NtUninstallKB927802$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB928255)-->"C:\WINDOWS\$NtUninstallKB928255$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB928843)-->"C:\WINDOWS\$NtUninstallKB928843$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB929123)-->"C:\WINDOWS\$NtUninstallKB929123$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB930178)-->"C:\WINDOWS\$NtUninstallKB930178$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB931261)-->"C:\WINDOWS\$NtUninstallKB931261$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB931784)-->"C:\WINDOWS\$NtUninstallKB931784$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB932168)-->"C:\WINDOWS\$NtUninstallKB932168$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB933729)-->"C:\WINDOWS\$NtUninstallKB933729$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB935839)-->"C:\WINDOWS\$NtUninstallKB935839$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB935840)-->"C:\WINDOWS\$NtUninstallKB935840$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB936021)-->"C:\WINDOWS\$NtUninstallKB936021$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB937143)-->"C:\WINDOWS\$NtUninstallKB937143$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB938127)-->"C:\WINDOWS\$NtUninstallKB938127$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB938829)-->"C:\WINDOWS\$NtUninstallKB938829$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB941202)-->"C:\WINDOWS\$NtUninstallKB941202$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB941568)-->"C:\WINDOWS\$NtUninstallKB941568$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB941644)-->"C:\WINDOWS\$NtUninstallKB941644$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB941693)-->"C:\WINDOWS\$NtUninstallKB941693$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB943055)-->"C:\WINDOWS\$NtUninstallKB943055$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB943460)-->"C:\WINDOWS\$NtUninstallKB943460$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB943485)-->"C:\WINDOWS\$NtUninstallKB943485$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB944653)-->"C:\WINDOWS\$NtUninstallKB944653$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB945553)-->"C:\WINDOWS\$NtUninstallKB945553$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB946026)-->"C:\WINDOWS\$NtUninstallKB946026$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB948590)-->"C:\WINDOWS\$NtUninstallKB948590$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB948881)-->"C:\WINDOWS\$NtUninstallKB948881$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB950749)-->"C:\WINDOWS\$NtUninstallKB950749$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB953155)-->"C:\WINDOWS\$NtUninstallKB953155$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB954211)-->"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB954600)-->"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB956391)-->"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB956841)-->"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB958687)-->"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
                            Mise à jour pour Windows XP (KB894391)-->"C:\WINDOWS\$NtUninstallKB894391$\spuninst\spuninst.exe"
                            Mise à jour pour Windows XP (KB900485)-->"C:\WINDOWS\$NtUninstallKB900485$\spuninst\spuninst.exe"
                            Mise à jour pour Windows XP (KB904942)-->"C:\WINDOWS\$NtUninstallKB904942$\spuninst\spuninst.exe"
                            Mise à jour pour Windows XP (KB908531)-->"C:\WINDOWS\$NtUninstallKB908531$\spuninst\spuninst.exe"
                            Mise à jour pour Windows XP (KB910437)-->"C:\WINDOWS\$NtUninstallKB910437$\spuninst\spuninst.exe"
                            Mise à jour pour Windows XP (KB911280)-->"C:\WINDOWS\$NtUninstallKB911280$\spuninst\spuninst.exe"
                            Mise à jour pour Windows XP (KB916595)-->"C:\WINDOWS\$NtUninstallKB916595$\spuninst\spuninst.exe"
                            Mise à jour pour Windows XP (KB920342)-->"C:\WINDOWS\$NtUninstallKB920342$\spuninst\spuninst.exe"
                            Mise à jour pour Windows XP (KB920872)-->"C:\WINDOWS\$NtUninstallKB920872$\spuninst\spuninst.exe"
                            Mise à jour pour Windows XP (KB922582)-->"C:\WINDOWS\$NtUninstallKB922582$\spuninst\spuninst.exe"
                            Mise à jour pour Windows XP (KB925720)-->"C:\WINDOWS\$NtUninstallKB925720$\spuninst\spuninst.exe"
                            Mise à jour pour Windows XP (KB925876)-->"C:\WINDOWS\$NtUninstallKB925876$\spuninst\spuninst.exe"
                            Mise à jour pour Windows XP (KB927891)-->"C:\WINDOWS\$NtUninstallKB927891$\spuninst\spuninst.exe"
                            Mise à jour pour Windows XP (KB930916)-->"C:\WINDOWS\$NtUninstallKB930916$\spuninst\spuninst.exe"
                            Mise à jour pour Windows XP (KB932823-v3)-->"C:\WINDOWS\$NtUninstallKB932823-v3$\spuninst\spuninst.exe"
                            Mise à jour pour Windows XP (KB933360)-->"C:\WINDOWS\$NtUninstallKB933360$\spuninst\spuninst.exe"
                            Mise à jour pour Windows XP (KB936357)-->"C:\WINDOWS\$NtUninstallKB936357$\spuninst\spuninst.exe"
                            Mise à jour pour Windows XP (KB938828)-->"C:\WINDOWS\$NtUninstallKB938828$\spuninst\spuninst.exe"
                            Mise à jour pour Windows XP (KB942763)-->"C:\WINDOWS\$NtUninstallKB942763$\spuninst\spuninst.exe"
                            Mise à jour pour Windows XP (KB955839)-->"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
                            Module de prise en charge linguistique de Microsoft .NET Framework 2.0 - FRA-->C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0 Language Pack - FRA\install.exe
                            Module de prise en charge linguistique du français de Microsoft .NET Framework 3.0-->c:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0 French Language Pack\setup.exe
                            Mozilla Firefox (2.0.0.14)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
                            MSXML 4.0 SP2 (KB927978)-->MsiExec.exe /I{37477865-A3F1-4772-AD43-AAFC6BCFF99F}
                            MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
                            MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
                            MSXML 4.0 SP2 Parser and SDK-->MsiExec.exe /I{716E0306-8318-4364-8B8F-0CC4E9376BAC}
                            MSXML 6 Service Pack 2 (KB954459)-->MsiExec.exe /I{1A528690-6A2D-4BC5-B143-8C4AE8D19D96}
                            NTI Backup NOW! 4-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{385979FE-DC4F-4140-8EAD-A59625000D72} /l1036 BUN4
                            NTI CD & DVD-Maker-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{1577A05B-EE62-4BBC-9DB7-FE748FA44EC2} /l1036 CDM7
                            OIN Analytics-->C:\Program Files\OINAnalytics\Uninstall.exe
                            Package de base Microsoft de service de chiffrement pour cartes à puce-->"C:\WINDOWS\$NtUninstallbasecsp$\spuninst\spuninst.exe"
                            QuickTime-->MsiExec.exe /I{1838C5A2-AB32-4145-85C1-BB9B8DFA24CD}
                            Realtek AC'97 Audio-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FB08F381-6533-4108-B7DD-039E11FBC27E}\setup.exe" REMOVE
                            SiS 900 PCI Fast Ethernet Adapter Driver-->C:\WINDOWS\SiS\900\Uninst.exe
                            SiS VGA Utilities-->Rundll32 SiSInst.dll,Uninstall VGA,R,oem3.inf
                            SiSAGP driver-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{DC226AC9-0314-496C-BE6A-B6A132628466}\setup.exe" -l0x40c
                            SoftV90 Data Fax Modem with SmartCP-->C:\Program Files\CONEXANT\CNXT_MODEM_PCI_VEN_1039&DEV_7013&SUBSYS_00821025\HXFSETUP.EXE -U -IAcrSisK.inf
                            Synaptics Pointing Device Driver-->rundll32.exe "C:\Program Files\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall
                            Windows Communication Foundation-->MsiExec.exe /X{491DD792-AD81-429C-9EB4-86DD3D22E333}
                            Windows Imaging Component-->"C:\WINDOWS\$NtUninstallWIC$\spuninst\spuninst.exe"
                            Windows Installer 3.1 (KB893803)-->"C:\WINDOWS\$MSI31Uninstall_KB893803v2$\spuninst\spuninst.exe"
                            Windows Internet Explorer 7-->"C:\WINDOWS\ie7\spuninst\spuninst.exe"
                            Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
                            Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
                            Windows Media Format SDK Hotfix - KB891122-->"C:\WINDOWS\$NtUninstallKB891122$\spuninst\spuninst.exe"
                            Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
                            Windows Presentation Foundation Language Pack (FRA)-->MsiExec.exe /X{6901DD22-527A-41EF-9059-E81FEDE9E494}
                            Windows Presentation Foundation-->MsiExec.exe /X{BAF78226-3200-4DB4-BE33-4D922A799840}
                            Windows Workflow Foundation FR Language Pack-->MsiExec.exe /I{B84C141C-9A13-44BE-9A69-301D7B11D836}
                            Windows Workflow Foundation-->MsiExec.exe /I{7D1B85BD-AA07-48B8-808D-67A4067FC6BD}
                            XML Paper Specification Shared Components Language Pack 1.0-->"C:\WINDOWS\$NtUninstallXPSEPSCLP$\spuninst\spuninst.exe"
                            Yazzle by OIN-->"C:\Program Files\Fichiers communs\Y1220OU.exe"

                            ======Security center information======

                            AV: Avira AntiVir PersonalEdition Classic

                            System event log

                            Computer Name: ACER-79F6FF2248
                            Event Code: 7035
                            Message: Un contrôle Démarrer a correctement été envoyé au service Service de l'iPod.

                            Record Number: 18877
                            Source Name: Service Control Manager
                            Time Written: 20080502102823.000000+120
                            Event Type: Informations
                            User: AUTORITE NT\SYSTEM

                            Computer Name: ACER-79F6FF2248
                            Event Code: 7036
                            Message: Le service Service COM de gravage de CD IMAPI est entré dans l'état : arrêté.

                            Record Number: 18876
                            Source Name: Service Control Manager
                            Time Written: 20080502102817.000000+120
                            Event Type: Informations
                            User:

                            Computer Name: ACER-79F6FF2248
                            Event Code: 17
                            Message: AVGNTFLT successfully loaded

                            Record Number: 18875
                            Source Name: avgntflt
                            Time Written: 20080502102813.000000+120
                            Event Type: Informations
                            User:

                            Computer Name: ACER-79F6FF2248
                            Event Code: 10
                            Message: Ce lecteur ne semble pas prendre en charge la lecture audio numérique.

                            Record Number: 18874
                            Source Name: redbook
                            Time Written: 20080502102813.000000+120
                            Event Type: Informations
                            User:

                            Computer Name: ACER-79F6FF2248
                            Event Code: 7036
                            Message: Le service Service COM de gravage de CD IMAPI est entré dans l'état : en cours d'exécution.

                            Record Number: 18873
                            Source Name: Service Control Manager
                            Time Written: 20080502102810.000000+120
                            Event Type: Informations
                            User:

                            Application event log

                            Computer Name: ACER-79F6FF2248
                            Event Code: 1
                            Message:
                            Record Number: 635
                            Source Name: ccEvtMgr
                            Time Written: 20061203161205.000000+060
                            Event Type: Informations
                            User: AUTORITE NT\SYSTEM

                            Computer Name: ACER-79F6FF2248
                            Event Code: 26
                            Message:
                            Record Number: 634
                            Source Name: ccEvtMgr
                            Time Written: 20061203161205.000000+060
                            Event Type: Informations
                            User: AUTORITE NT\SYSTEM

                            Computer Name: ACER-79F6FF2248
                            Event Code: 1
                            Message:
                            Record Number: 633
                            Source Name: ccSetMgr
                            Time Written: 20061203161205.000000+060
                            Event Type: Informations
                            User: AUTORITE NT\SYSTEM

                            Computer Name: ACER-79F6FF2248
                            Event Code: 26
                            Message:
                            Record Number: 632
                            Source Name: ccSetMgr
                            Time Written: 20061203161204.000000+060
                            Event Type: Informations
                            User: AUTORITE NT\SYSTEM

                            Computer Name: ACER-79F6FF2248
                            Event Code: 4097
                            Message: L'application, C:\PROGRA~1\WANADOO\WOOBrowser\WOOBrowser.exe, a généré une erreur d'application
                            L'erreur s'est produite le 12/02/2006 à 21:07:59.812
                            L'exception générée était c0000005 à l'adresse 003959F2 (StyleIHM!CSTY_Wnd_Bmp__CreerSkin)

                            Record Number: 631
                            Source Name: DrWatson
                            Time Written: 20061202210759.000000+060
                            Event Type: Informations
                            User:

                            ======Environment variables======

                            "ComSpec"=%SystemRoot%\system32\cmd.exe
                            "Path"=%systemroot%\system32;%systemroot%;%systemroot%\system32\wbem;C:\Program Files\MiKTeX 2.5\miktex\bin;C:\Program Files\QuickTime\QTSystem
                            "windir"=%SystemRoot%
                            "FP_NO_HOST_CHECK"=NO
                            "OS"=Windows_NT
                            "PROCESSOR_ARCHITECTURE"=x86
                            "PROCESSOR_LEVEL"=6
                            "PROCESSOR_IDENTIFIER"=x86 Family 6 Model 13 Stepping 8, GenuineIntel
                            "PROCESSOR_REVISION"=0d08
                            "NUMBER_OF_PROCESSORS"=1
                            "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
                            "TEMP"=%SystemRoot%\TEMP
                            "TMP"=%SystemRoot%\TEMP
                            "CLASSPATH"=.;C:\Program Files\QuickTime\QTSystem\QTJava.zip
                            "QTJAVA"=C:\Program Files\QuickTime\QTSystem\QTJava.zip

                            -----------------EOF-----------------
                            0
                            1. Logfile of random's system information tool 1.05 (written by random/random)
                              Run by Laura at 2009-02-05 10:11:55
                              Microsoft Windows XP Édition familiale Service Pack 2
                              System drive C: has 8 GB (50%) free of 17 GB
                              Total RAM: 445 MB (21% free)

                              Logfile of Trend Micro HijackThis v2.0.2
                              Scan saved at 10:12, on 2009-02-05
                              Platform: Windows XP SP2 (WinNT 5.01.2600)
                              MSIE: Internet Explorer v7.00 (7.00.6000.16762)
                              Boot mode: Normal

                              Running processes:
                              C:\WINDOWS\System32\smss.exe
                              C:\WINDOWS\system32\winlogon.exe
                              C:\WINDOWS\system32\services.exe
                              C:\WINDOWS\system32\lsass.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\System32\svchost.exe
                              C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                              C:\WINDOWS\system32\spoolsv.exe
                              C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                              C:\Acer\eManager\anbmServ.exe
                              C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                              C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                              C:\Program Files\Bonjour\mDNSResponder.exe
                              C:\Program Files\Java\jre6\bin\jqs.exe
                              C:\WINDOWS\Explorer.EXE
                              C:\WINDOWS\system32\keyhook.exe
                              C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
                              C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                              C:\Program Files\Launch Manager\QtZgAcer.EXE
                              C:\Acer\Empowering Technology\eRecovery\Monitor.exe
                              C:\WINDOWS\SOUNDMAN.EXE
                              C:\Program Files\Java\jre6\bin\jusched.exe
                              C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                              C:\WINDOWS\system32\ctfmon.exe
                              C:\WINDOWS\system32\sistray.exe
                              C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                              C:\WINDOWS\system32\wuauclt.exe
                              C:\WINDOWS\system32\wuauclt.exe
                              C:\Documents and Settings\Laura\Bureau\RSIT.exe
                              C:\hijackthis\Laura.exe

                              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                              R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
                              R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                              O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                              O2 - BHO: (no name) - {1FD79A1C-09AB-0A5C-8C3D-50C0705881C8} - C:\WINDOWS\system32\fdid.dll (file missing)
                              O2 - BHO: (no name) - {33E3FF63-388C-3804-A34D-68E33CEDFA91} - C:\WINDOWS\system32\lcey.dll (file missing)
                              O2 - BHO: (no name) - {398DF3BE-6F0E-39DA-2975-3BB6094DA4C1} - C:\WINDOWS\system32\ejcydgb.dll (file missing)
                              O2 - BHO: (no name) - {418E1354-DAB8-F539-C52A-89CD5519DE9B} - C:\WINDOWS\system32\opntlhi.dll (file missing)
                              O2 - BHO: (no name) - {671FD78E-483B-45B9-4CF3-13D4CEC2A993} - C:\WINDOWS\system32\ptmauvma.dll (file missing)
                              O2 - BHO: (no name) - {7011EE4A-29AE-7D22-897F-7B129343B5CE} - C:\WINDOWS\system32\vrcm.dll (file missing)
                              O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
                              O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                              O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
                              O4 - HKLM\..\Run: [LaunchApp] Alaunch
                              O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
                              O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\system32\keyhook.exe
                              O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
                              O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                              O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
                              O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
                              O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
                              O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
                              O4 - HKLM\..\Run: [LManager] C:\Program Files\Launch Manager\QtZgAcer.EXE
                              O4 - HKLM\..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\Monitor.exe
                              O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
                              O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                              O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                              O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                              O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                              O4 - HKCU\..\Run: [Nphb] "C:\DOCUME~1\Laura\MESDOC~1\CROSOF~1.NET\mshta.exe" -vt yazb
                              O4 - HKCU\..\Run: [Bxjfk] C:\Documents and Settings\Laura\Application Data\s?stem\??rvices.exe
                              O4 - HKCU\..\Run: [Czapd] C:\WINDOWS\F?nts\??chost.exe
                              O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\WANADOO\Shell.exe appLaunchClientZone.shl|DEFAULT=cnx|PARAM=
                              O4 - HKCU\..\Run: [updateMgr] c:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_1_0
                              O4 - HKCU\..\Run: [Euec] "C:\DOCUME~1\Laura\APPLIC~1\YSTEM~1\userinit.exe" -vt ndrv
                              O4 - HKCU\..\Run: [Rll] "C:\Documents and Settings\Laura\Application Data\?ystem\w?wexec.exe"
                              O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                              O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                              O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe
                              O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                              O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                              O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                              O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                              O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                              O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
                              O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
                              O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                              O23 - Service: Notebook Manager Service (anbmService) - OSA Technologies Inc. - C:\Acer\eManager\anbmServ.exe
                              O23 - Service: Planificateur Avira AntiVir Personal - Free Antivirus (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                              O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                              O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                              O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                              O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
                              0
                              1. Merci encore pour ton aide, voila les deux rapports
                                1log
                                2info
                                0
                                1. Re,

                                  ▶ Télécharge random's system information tool (RSIT) et enregistre le sur ton bureau.

                                  ▶ Double clique sur RSIT.exe pour lancer l'outil.

                                  ▶ Clique sur ' continue ' à l'écran Disclaimer.

                                  ▶ Si l'outil HIjackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera et tu devras accepter la licence.

                                  ▶ Une fois le scan fini , 2 rapports vont apparaitre. Poste le contenu des 2 rapports séparément.
                                  ( log.txt & info.txt )

                                  (CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

                                  Si un rapport ne passe pas faire une alerte à la conciergerie avec le /!\ jaune.
                                  0
                                  1. voila!!!!

                                    ComboFix 09-02-03.01 - Laura 2009-02-04 12:25:47.1 - [color=red][b]FAT32[/b][/color]x86
                                    Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.445.173 [GMT 1:00]
                                    Lancé depuis: C:\Documents and Settings\Laura\Bureau\C-Fix.exe
                                    AV: Avira AntiVir PersonalEdition Classic *On-access scanning disabled* (Updated)
                                    * Un nouveau point de restauration a été créé

                                    .

                                    (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
                                    .

                                    C:\Documents and Settings\Laura\Application Data\MANTEC~1
                                    C:\Documents and Settings\Laura\Application Data\RACLE~1
                                    C:\Documents and Settings\Laura\Application Data\SSTEM~1
                                    C:\Documents and Settings\Laura\Application Data\YSTEM~1
                                    C:\Documents and Settings\Laura\Application Data\YSTEM~1\?ystem\
                                    C:\Documents and Settings\Laura\Application Data\YSTEM~1\w?wexec.exe
                                    C:\Documents and Settings\Laura\Menu Démarrer\Programmes\Outerinfo
                                    C:\Documents and Settings\Laura\Menu Démarrer\Programmes\Outerinfo\Terms.lnk
                                    C:\Documents and Settings\Laura\Menu Démarrer\Programmes\Outerinfo\Uninstall.lnk
                                    C:\Documents and Settings\Laura\Menu Démarrer\Programmes\ucmore - the search accelerator
                                    C:\Documents and Settings\Laura\Menu Démarrer\Programmes\ucmore - the search accelerator\How To Uninstall.lnk
                                    C:\Documents and Settings\Laura\Menu Démarrer\Programmes\ucmore - the search accelerator\UCmore - The Search Accelerator.lnk
                                    C:\Documents and Settings\Laura\Menu Démarrer\Programmes\ucmore - the search accelerator\UCmore Tour.lnk
                                    C:\Documents and Settings\Laura\Mes documents\CROSOF~1.NET
                                    C:\Documents and Settings\Laura\Mes documents\CROSOF~1.NET\??crosoft.NET\
                                    C:\Documents and Settings\Laura\Mes documents\STEM~1
                                    C:\Program Files\dobe~1
                                    C:\Program Files\outerinfo
                                    C:\Program Files\outerinfo\FF\chrome.manifest
                                    C:\Program Files\outerinfo\FF\components\FF.dll
                                    C:\Program Files\outerinfo\FF\components\OuterinfoAds.xpt
                                    C:\Program Files\outerinfo\FF\install.rdf
                                    C:\Program Files\outerinfo\outerinfo.ico
                                    C:\Program Files\outerinfo\Terms.rtf
                                    C:\Program Files\pppatc~1
                                    C:\WINDOWS\crosof~1
                                    C:\WINDOWS\fnts~1
                                    C:\WINDOWS\fnts~1\??chost.exe
                                    C:\WINDOWS\hosts
                                    C:\WINDOWS\icroso~1
                                    C:\WINDOWS\system\oeminfo.ini
                                    C:\WINDOWS\system32\asks~1
                                    C:\WINDOWS\system32\ppatch~1
                                    C:\WINDOWS\system32\sks~1
                                    C:\WINDOWS\system32\wnsapisv.exe

                                    .
                                    ((((((((((((((((((((((((((((( Fichiers créés du 2009-01-04 au 2009-02-04 ))))))))))))))))))))))))))))))))))))
                                    .

                                    2009-02-04 10:39 . 2009-02-04 10:39 <REP> d-------- C:\hijackthis
                                    2009-02-02 20:45 . 2009-02-02 20:45 <REP> d-------- C:\WINDOWS\system32\CatRoot_bak
                                    2009-02-02 20:31 . 2009-02-02 20:31 <REP> d-------- C:\WINDOWS\LastGood
                                    2009-02-02 20:26 . 2009-02-02 20:26 410,984 --a------ C:\WINDOWS\system32\deploytk.dll
                                    2009-02-02 17:51 . 2009-02-02 17:51 <REP> d-------- C:\Program Files\Avira
                                    2009-02-02 17:51 . 2009-02-02 17:51 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Avira
                                    2009-02-02 17:29 . 2009-02-02 17:29 <REP> d-------- C:\Program Files\OINAnalytics
                                    2009-02-02 17:04 . 2009-02-02 17:04 <REP> d-------- C:\Documents and Settings\Coco\Application Data\Apple Computer

                                    .
                                    (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                                    .
                                    2006-08-31 19:59 93,663 --sha-w C:\Program Files\Fichiers communs\Y1220OU.exe
                                    2006-08-28 21:46 278,528 ----a-w C:\Program Files\Fichiers communs\FDEUnInstaller.exe
                                    2008-04-25 09:23 67,696 ----a-w C:\Program Files\mozilla firefox\components\jar50.dll
                                    2008-04-25 09:23 54,376 ----a-w C:\Program Files\mozilla firefox\components\jsd3250.dll
                                    2008-04-25 09:23 34,952 ----a-w C:\Program Files\mozilla firefox\components\myspell.dll
                                    2008-04-25 09:23 46,720 ----a-w C:\Program Files\mozilla firefox\components\spellchk.dll
                                    2008-04-25 09:23 172,144 ----a-w C:\Program Files\mozilla firefox\components\xpinstal.dll
                                    .

                                    ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
                                    .
                                    .
                                    *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
                                    REGEDIT4

                                    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                    "Bxjfk"="C:\Documents and Settings\Laura\Application Data\s?stem\??rvices.exe" [?]
                                    "Czapd"="C:\WINDOWS\F?nts\??chost.exe" [?]
                                    "Rll"="C:\Documents and Settings\Laura\Application Data\?ystem\w?wexec.exe" [?]
                                    "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-19 19:57 15360]
                                    "updateMgr"="c:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 16:45 313472]

                                    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
                                    "FlashPlayerUpdate"="C:\WINDOWS\system32\Macromed\Flash\FlashUtil9f.exe" [2008-03-25 04:32 218496]

                                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                    "LaunchApp"="Alaunch" [X]
                                    "SiS Windows KeyHook"="C:\WINDOWS\system32\keyhook.exe" [2005-03-04 13:13 32768]
                                    "SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2004-10-07 23:44 98394]
                                    "SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2004-10-07 23:43 688218]
                                    "IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" [2004-08-05 05:00 208952]
                                    "MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-19 21:59 59392]
                                    "PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-19 21:59 455168]
                                    "PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-19 21:59 455168]
                                    "LManager"="C:\Program Files\Launch Manager\QtZgAcer.EXE" [2005-03-28 12:30 315392]
                                    "eRecoveryService"="C:\Acer\Empowering Technology\eRecovery\Monitor.exe" [2005-11-16 16:41 393216]
                                    "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-03-28 23:37 413696]
                                    "SunJavaUpdateSched"="C:\Program Files\Java\jre6\bin\jusched.exe" [2009-02-02 20:26 136600]
                                    "avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 13:28 266497]
                                    "SiSPower"="SiSPower.dll" [2005-02-25 04:35 49152 C:\WINDOWS\system32\SiSPower.dll]
                                    "SoundMan"="SOUNDMAN.EXE" [2005-02-23 03:13 77824 C:\WINDOWS\SOUNDMAN.EXE]

                                    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
                                    "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-19 19:57 15360]

                                    C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
                                    Utility Tray.lnk - C:\WINDOWS\system32\sistray.exe [2005-01-04 16:52:52 331776]
                                    Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-04-23 03:38:16 29696]

                                    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
                                    "AntiVirusDisableNotify"=dword:00000001

                                    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
                                    "EnableFirewall"= 0 (0x0)

                                    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
                                    "%windir%\\system32\\sessmgr.exe"=
                                    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
                                    "C:\\Program Files\\Bonjour\\mDNSResponder.exe"=

                                    R2 osaio;osaio;C:\WINDOWS\system32\drivers\osaio.sys [2005-06-30 16:58:24 7296]
                                    R2 osanbm;osanbm;C:\WINDOWS\system32\drivers\osanbm.sys [2005-01-14 15:57:16 4010]
                                    R3 HSFHWSIS;HSFHWSIS;C:\WINDOWS\system32\drivers\HSFHWSIS.sys [2004-12-15 00:18:34 200576]
                                    S3 SIS163u;SiS163 usb Wireless LAN Adapter Driver;C:\WINDOWS\system32\drivers\SIS163u.SYS [2005-06-20 11:12:00 215040]

                                    --- Autres Services/Pilotes en mémoire ---

                                    *NewlyCreated* - ANTIVIRSCHEDULER
                                    *NewlyCreated* - ANTIVIRSERVICE
                                    *NewlyCreated* - AVGIO
                                    *NewlyCreated* - AVGNTFLT
                                    *NewlyCreated* - AVIPBB
                                    *NewlyCreated* - INT15.SYS
                                    *NewlyCreated* - JAVAQUICKSTARTERSERVICE
                                    *NewlyCreated* - WMIAPSRV
                                    .
                                    Contenu du dossier 'Tâches planifiées'

                                    2009-02-04 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
                                    - C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 14:57]
                                    .
                                    - - - - ORPHELINS SUPPRIMES - - - -

                                    BHO-{1FD79A1C-09AB-0A5C-8C3D-50C0705881C8} - C:\WINDOWS\system32\fdid.dll
                                    BHO-{33E3FF63-388C-3804-A34D-68E33CEDFA91} - C:\WINDOWS\system32\lcey.dll
                                    BHO-{398DF3BE-6F0E-39DA-2975-3BB6094DA4C1} - C:\WINDOWS\system32\ejcydgb.dll
                                    BHO-{418E1354-DAB8-F539-C52A-89CD5519DE9B} - C:\WINDOWS\system32\opntlhi.dll
                                    BHO-{671FD78E-483B-45B9-4CF3-13D4CEC2A993} - C:\WINDOWS\system32\ptmauvma.dll
                                    BHO-{7011EE4A-29AE-7D22-897F-7B129343B5CE} - C:\WINDOWS\system32\vrcm.dll
                                    HKCU-Run-Nphb - C:\DOCUME~1\Laura\MESDOC~1\CROSOF~1.NET\mshta.exe
                                    HKCU-Run-WOOKIT - C:\PROGRA~1\WANADOO\Shell.exe
                                    HKCU-Run-Euec - C:\DOCUME~1\Laura\APPLIC~1\YSTEM~1\userinit.exe

                                    .
                                    ------- Examen supplémentaire -------
                                    .
                                    uStart Page = hxxp://www.wanadoo.fr/
                                    uInternet Settings,ProxyOverride = *.local
                                    uSearchURL,(Default) = hxxp://g.msn.fr/0SEFRFR/SAOS01?FORM=TOOLBR
                                    IE: E&xporter vers Microsoft Excel - C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                                    FF - ProfilePath - C:\Documents and Settings\Laura\Application Data\Mozilla\Firefox\Profiles\tzcrje39.default\
                                    FF - prefs.js: browser.search.defaulturl - hxxp://fr.search.yahoo.com/search?ei=UTF-8&fr=ytff-sunm&p=
                                    FF - prefs.js: browser.search.selectedEngine - Yahoo
                                    FF - prefs.js: keyword.URL - hxxp://fr.search.yahoo.com/search?ei=UTF-8&fr=ytff-sunm&p=
                                    FF - component: C:\Program Files\Mozilla Firefox\components\xpinstal.dll
                                    .
                                    0
                                    1. ok console de recup installee et envoyee dans combofix, je deconnecte l'ordi infecte
                                      0
                                      1. Re,

                                        OKI.

                                        Suit bien les consignes.

                                        Ferme tout déconnecte toi de l'internet et désactive antivirus et anti-spyware.
                                        0
                                        • 1
                                        • 2