Virus impossible à supprimer

Résolu
Bonjour,
Voila, je suis sure d'avoir un virus. Malheureusement il bloque mon antivirus et tout autre logiciel me permettant de le supprimé. Quand j'essaie de le supprimé manuellement il me dit qu'il est impossible de le supprimé car le dossier n'est pas vide.
Merci de votre aide.
Configuration: Windows XP
Firefox 3.5.7

57 réponses

Résumé de la discussion

Une infection présumée est signalée sur Windows XP avec Firefox 3.5.7, le virus bloquant l’antivirus et empêchant la suppression manuelle car le dossier est indiqué comme non vide. Des éléments de diagnostic (Rapport système, HijackThis) et une liste de processus, services et programmes démarrent, suggérant une compromission multiple et de nombreux BHO et entrées en démarrage. Cela pointe vers une installation progressive de logiciels potentiellement indésirables et des programmes ajoutés au démarrage, ainsi que des téléchargements récents non fiables sur l'ordinateur. En pratique, des mesures complémentaires consistent à analyser les démarrages et services, puis à nettoyer les éléments suspects avec des outils spécialisés et, si nécessaire, à restaurer le système à partir d’un support externe.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    ok

    au point de vue virus on a fait le tour....

    redemarres le pc

    relances ensuite RSIT et postes le rapport log

    si le pc rame encore

    il faudra voir de ce côté je pense

    System drive C: has 3 GB (7%) free of 40 GB
    Total RAM: 447 MB (23% free)


    +

    un scan ligne pour se donner une dernière assurance

    0
    1. 19:42:57:625 1596 TDSS rootkit removing tool 2.2.8.1 Mar 22 2010 10:43:04
      19:42:57:625 1596 ================================================================================
      19:42:57:625 1596 SystemInfo:

      19:42:57:625 1596 OS Version: 5.1.2600 ServicePack: 3.0
      19:42:57:625 1596 Product type: Workstation
      19:42:57:625 1596 ComputerName: REQUIER-1C9D4F7
      19:42:57:625 1596 UserName: Propriétaire
      19:42:57:625 1596 Windows directory: C:\WINDOWS
      19:42:57:625 1596 Processor architecture: Intel x86
      19:42:57:625 1596 Number of processors: 1
      19:42:57:625 1596 Page size: 0x1000
      19:42:57:625 1596 Boot type: Normal boot
      19:42:57:625 1596 ================================================================================
      19:42:57:703 1596 UnloadDriverW: NtUnloadDriver error 2
      19:42:57:703 1596 ForceUnloadDriverW: UnloadDriverW(klmd21) error 2
      19:42:57:890 1596 wfopen_ex: Trying to open file C:\WINDOWS\system32\config\system
      19:42:57:890 1596 wfopen_ex: MyNtCreateFileW error 32 (C0000043)
      19:42:57:890 1596 wfopen_ex: Trying to KLMD file open
      19:42:57:890 1596 wfopen_ex: File opened ok (Flags 2)
      19:42:57:890 1596 wfopen_ex: Trying to open file C:\WINDOWS\system32\config\software
      19:42:57:890 1596 wfopen_ex: MyNtCreateFileW error 32 (C0000043)
      19:42:57:890 1596 wfopen_ex: Trying to KLMD file open
      19:42:57:890 1596 wfopen_ex: File opened ok (Flags 2)
      19:42:57:906 1596 Initialize success
      19:42:57:906 1596
      19:42:57:906 1596 Scanning Services ...
      19:42:58:359 1596 Raw services enum returned 348 services
      19:42:58:375 1596
      19:42:58:375 1596 Scanning Kernel memory ...
      19:42:58:375 1596 Devices to scan: 3
      19:42:58:375 1596
      19:42:58:375 1596 Driver Name: Disk
      19:42:58:375 1596 IRP_MJ_CREATE : F760CBB0
      19:42:58:375 1596 IRP_MJ_CREATE_NAMED_PIPE : 804F355A
      19:42:58:375 1596 IRP_MJ_CLOSE : F760CBB0
      19:42:58:375 1596 IRP_MJ_READ : F7606D1F
      19:42:58:375 1596 IRP_MJ_WRITE : F7606D1F
      19:42:58:375 1596 IRP_MJ_QUERY_INFORMATION : 804F355A
      19:42:58:375 1596 IRP_MJ_SET_INFORMATION : 804F355A
      19:42:58:375 1596 IRP_MJ_QUERY_EA : 804F355A
      19:42:58:375 1596 IRP_MJ_SET_EA : 804F355A
      19:42:58:375 1596 IRP_MJ_FLUSH_BUFFERS : F76072E2
      19:42:58:375 1596 IRP_MJ_QUERY_VOLUME_INFORMATION : 804F355A
      19:42:58:375 1596 IRP_MJ_SET_VOLUME_INFORMATION : 804F355A
      19:42:58:375 1596 IRP_MJ_DIRECTORY_CONTROL : 804F355A
      19:42:58:375 1596 IRP_MJ_FILE_SYSTEM_CONTROL : 804F355A
      19:42:58:375 1596 IRP_MJ_DEVICE_CONTROL : F76073BB
      19:42:58:375 1596 IRP_MJ_INTERNAL_DEVICE_CONTROL : F760AF28
      19:42:58:375 1596 IRP_MJ_SHUTDOWN : F76072E2
      19:42:58:375 1596 IRP_MJ_LOCK_CONTROL : 804F355A
      19:42:58:375 1596 IRP_MJ_CLEANUP : 804F355A
      19:42:58:375 1596 IRP_MJ_CREATE_MAILSLOT : 804F355A
      19:42:58:375 1596 IRP_MJ_QUERY_SECURITY : 804F355A
      19:42:58:375 1596 IRP_MJ_SET_SECURITY : 804F355A
      19:42:58:375 1596 IRP_MJ_POWER : F7608C82
      19:42:58:375 1596 IRP_MJ_SYSTEM_CONTROL : F760D99E
      19:42:58:375 1596 IRP_MJ_DEVICE_CHANGE : 804F355A
      19:42:58:375 1596 IRP_MJ_QUERY_QUOTA : 804F355A
      19:42:58:375 1596 IRP_MJ_SET_QUOTA : 804F355A
      19:42:58:390 1596 C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: 1
      19:42:58:390 1596
      19:42:58:390 1596 Driver Name: Disk
      19:42:58:390 1596 IRP_MJ_CREATE : F760CBB0
      19:42:58:390 1596 IRP_MJ_CREATE_NAMED_PIPE : 804F355A
      19:42:58:390 1596 IRP_MJ_CLOSE : F760CBB0
      19:42:58:390 1596 IRP_MJ_READ : F7606D1F
      19:42:58:390 1596 IRP_MJ_WRITE : F7606D1F
      19:42:58:390 1596 IRP_MJ_QUERY_INFORMATION : 804F355A
      19:42:58:390 1596 IRP_MJ_SET_INFORMATION : 804F355A
      19:42:58:390 1596 IRP_MJ_QUERY_EA : 804F355A
      19:42:58:390 1596 IRP_MJ_SET_EA : 804F355A
      19:42:58:390 1596 IRP_MJ_FLUSH_BUFFERS : F76072E2
      19:42:58:390 1596 IRP_MJ_QUERY_VOLUME_INFORMATION : 804F355A
      19:42:58:390 1596 IRP_MJ_SET_VOLUME_INFORMATION : 804F355A
      19:42:58:390 1596 IRP_MJ_DIRECTORY_CONTROL : 804F355A
      19:42:58:390 1596 IRP_MJ_FILE_SYSTEM_CONTROL : 804F355A
      19:42:58:406 1596 IRP_MJ_DEVICE_CONTROL : F76073BB
      19:42:58:406 1596 IRP_MJ_INTERNAL_DEVICE_CONTROL : F760AF28
      19:42:58:406 1596 IRP_MJ_SHUTDOWN : F76072E2
      19:42:58:406 1596 IRP_MJ_LOCK_CONTROL : 804F355A
      19:42:58:406 1596 IRP_MJ_CLEANUP : 804F355A
      19:42:58:406 1596 IRP_MJ_CREATE_MAILSLOT : 804F355A
      19:42:58:406 1596 IRP_MJ_QUERY_SECURITY : 804F355A
      19:42:58:406 1596 IRP_MJ_SET_SECURITY : 804F355A
      19:42:58:406 1596 IRP_MJ_POWER : F7608C82
      19:42:58:406 1596 IRP_MJ_SYSTEM_CONTROL : F760D99E
      19:42:58:406 1596 IRP_MJ_DEVICE_CHANGE : 804F355A
      19:42:58:406 1596 IRP_MJ_QUERY_QUOTA : 804F355A
      19:42:58:406 1596 IRP_MJ_SET_QUOTA : 804F355A
      19:42:58:406 1596 C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: 1
      19:42:58:406 1596
      19:42:58:406 1596 Driver Name: atapi
      19:42:58:406 1596 IRP_MJ_CREATE : F74486F2
      19:42:58:406 1596 IRP_MJ_CREATE_NAMED_PIPE : 804F355A
      19:42:58:406 1596 IRP_MJ_CLOSE : F74486F2
      19:42:58:406 1596 IRP_MJ_READ : 804F355A
      19:42:58:406 1596 IRP_MJ_WRITE : 804F355A
      19:42:58:406 1596 IRP_MJ_QUERY_INFORMATION : 804F355A
      19:42:58:406 1596 IRP_MJ_SET_INFORMATION : 804F355A
      19:42:58:406 1596 IRP_MJ_QUERY_EA : 804F355A
      19:42:58:406 1596 IRP_MJ_SET_EA : 804F355A
      19:42:58:406 1596 IRP_MJ_FLUSH_BUFFERS : 804F355A
      19:42:58:406 1596 IRP_MJ_QUERY_VOLUME_INFORMATION : 804F355A
      19:42:58:406 1596 IRP_MJ_SET_VOLUME_INFORMATION : 804F355A
      19:42:58:406 1596 IRP_MJ_DIRECTORY_CONTROL : 804F355A
      19:42:58:406 1596 IRP_MJ_FILE_SYSTEM_CONTROL : 804F355A
      19:42:58:406 1596 IRP_MJ_DEVICE_CONTROL : F7448712
      19:42:58:406 1596 IRP_MJ_INTERNAL_DEVICE_CONTROL : F75D78B4
      19:42:58:406 1596 IRP_MJ_SHUTDOWN : 804F355A
      19:42:58:406 1596 IRP_MJ_LOCK_CONTROL : 804F355A
      19:42:58:406 1596 IRP_MJ_CLEANUP : 804F355A
      19:42:58:406 1596 IRP_MJ_CREATE_MAILSLOT : 804F355A
      19:42:58:406 1596 IRP_MJ_QUERY_SECURITY : 804F355A
      19:42:58:406 1596 IRP_MJ_SET_SECURITY : 804F355A
      19:42:58:406 1596 IRP_MJ_POWER : F744873C
      19:42:58:406 1596 IRP_MJ_SYSTEM_CONTROL : F744F336
      19:42:58:406 1596 IRP_MJ_DEVICE_CHANGE : 804F355A
      19:42:58:406 1596 IRP_MJ_QUERY_QUOTA : 804F355A
      19:42:58:406 1596 IRP_MJ_SET_QUOTA : 804F355A
      19:42:58:406 1596 C:\WINDOWS\system32\DRIVERS\atapi.sys - Verdict: 1
      19:42:58:406 1596
      19:42:58:406 1596 Completed
      19:42:58:406 1596
      19:42:58:406 1596 Results:
      19:42:58:406 1596 Memory objects infected / cured / cured on reboot: 0 / 0 / 0
      19:42:58:406 1596 Registry objects infected / cured / cured on reboot: 0 / 0 / 0
      19:42:58:406 1596 File objects infected / cured / cured on reboot: 0 / 0 / 0
      19:42:58:406 1596
      19:42:58:406 1596 fclose_ex: Trying to close file C:\WINDOWS\system32\config\system
      19:42:58:406 1596 fclose_ex: Trying to close file C:\WINDOWS\system32\config\software
      19:42:58:406 1596 KLMD(ARK) unloaded successfully
      0
      1. Contributeur sécurité
        enfin pour vérifier l'absence de rootkit TDSS

        * Télécharge load_tdsskiller (de Loup Blanc) sur ton Bureau

        http://fradesch.perso.cegetel.net/transf/Load_tdsskiller.exe

        * Lance load_tdsskiller en faisant un double-clic dessus / Lance par un clic-droit dessus ? Exécuter en temps qu'administrateur
        * L'outil va se connecter pour télécharger une copie à jour de TDSSKiller, puis va lancer une analyse
        * A la fin, il te sera demandé d'appuyer sur une touche, puis le rapport s'affichera automatiquement : copie-colle son contenu dans ta prochaine réponse (C:\tdsskiller\report.txt)
        0
        1. ZHPFix v1.12.3079 by Nicolas Coolman - Rapport de suppression du 23/03/2010 19:17:18
          Fichier d'export Registre : C:\ZHPExportRegistry-23-03-2010-19-17-18.txt
          Web site : http://www.premiumorange.com/zeb-help-process/zhpfix.html

          Processus mémoire :
          (Néant)

          Module mémoire :
          (Néant)

          Clé du Registre :
          O42 - Logiciel: RON Tool Mxlivemedia => Clé supprimée avec succès

          Valeur du Registre :
          O3 - Toolbar: (no name) - {1E796980-9CC5-11D1-A83F-00C04FC99D61} => Valeur supprimée avec succès

          Elément de données du Registre :
          (Néant)

          Dossier :
          (Néant)

          Fichier :
          (Néant)

          Logiciel :
          O42 - Logiciel: RON Tool Mxlivemedia => Logiciel supprimé avec succès

          Script Registre :
          (Néant)

          Autre :
          http://www.cijoint.fr/cjlink.php?file=cj201003/cijmjhRnvh.txt => Format Non supporté

          Récapitulatif :
          Processus mémoire : 0
          Module mémoire : 0
          Clé du Registre : 1
          Valeur du Registre : 1
          Elément de données du Registre : 0
          Dossier : 0
          Fichier : 0
          Logiciel : 1
          Autre : 1

          End of the scan
          0
          1. Contributeur sécurité
            ok quelques bricoles encore et les traces de rootkits..

            Relance ZHPDiag ( Clic droit " Executer en tant qu'administrateur " sous vista ) , fais un scan puis cette fois-ci cliques sur l'icone en forme d'écusson vert " ZHPFix ".

            ZHPFix se lancera, clique maintenant sur le " H " bleu ( coller les lignes helper ) puis copie/colle ces lignes

            O3 - Toolbar: (no name) - {1E796980-9CC5-11D1-A83F-00C04FC99D61}
            O42 - Logiciel: RON Tool Mxlivemedia


            Clique sur " Ok " , puis " Tous " et enfin " Nettoyer ".

            Copie/Colle le rapport à l'écran dans ton prochain message
            0
            1. http://www.cijoint.fr/cjlink.php?file=cj201003/cijmjhRnvh.txt
              0
              1. Contributeur sécurité
                pas de présence de lignes rouges j'imagine ?

                voyons voir un peu plus loin

                Télécharge ZHPDiag ( de? Nicolas coolman ).
                https://www.zebulon.fr/telechargements/securite/systeme/zhpdiag.html

                Double clique sur le fichier d'installation, puis installe le avec les? paramètres par défaut ( N'oublie pas de cocher " Créer une icône sur le bureau " )

                Lance ZHPDiag en double cliquant sur l'icône présente sur ton bureau (Clique droit -> Executer en tant qu'admin ( vista )

                Clique sur la loupe? en haut à gauche, puis laisse l'outil scanner.

                Une fois le scan terminé, clique sur l'icône en forme de disquette et enregistre le fichier sur ton bureau.

                Rend toi sur Cjoint :? http://www.cijoint.fr/

                Clique sur "Parcourir " dans la partie " Joindre un fichier[...] "

                Sélectionne le rapport ZHPdiag.txt qui se trouve sur ton bureau

                Clique ensuite sur "Créer le lien cjoint " et copie/colle le dans ton prochain message
                0
                1. GMER 1.0.15.15281 - http://www.gmer.net
                  Rootkit scan 2010-03-23 15:33:07
                  Windows 5.1.2600 Service Pack 3
                  Running: i9izlem3.exe; Driver: C:\DOCUME~1\PROPRI~1\LOCALS~1\Temp\fwqiqfod.sys

                  ---- System - GMER 1.0.15 ----

                  SSDT F7BC31D6 ZwCreateKey
                  SSDT F7BC31CC ZwCreateThread
                  SSDT F7BC31DB ZwDeleteKey
                  SSDT F7BC31E5 ZwDeleteValueKey
                  SSDT F7BC31EA ZwLoadKey
                  SSDT F7BC31B8 ZwOpenProcess
                  SSDT F7BC31BD ZwOpenThread
                  SSDT F7BC31F4 ZwReplaceKey
                  SSDT F7BC31EF ZwRestoreKey
                  SSDT F7BC31E0 ZwSetValueKey
                  SSDT F7BC31C7 ZwTerminateProcess

                  ---- Kernel code sections - GMER 1.0.15 ----

                  .text ntkrnlpa.exe!ZwCallbackReturn + 24EC 80501D24 4 Bytes JMP 3AF7BC31

                  ---- User code sections - GMER 1.0.15 ----

                  .text C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe[656] kernel32.dll!LoadResource 7C80A055 7 Bytes JMP 28001E20 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
                  .text C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe[656] kernel32.dll!FindResourceExW 7C80AD28 7 Bytes JMP 28001C60 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
                  .text C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe[656] kernel32.dll!FindResourceW 7C80BC6E 7 Bytes JMP 28001BE0 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
                  .text C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe[656] kernel32.dll!SizeofResource 7C80BD09 7 Bytes JMP 28001EE0 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
                  .text C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe[656] kernel32.dll!FindResourceA 7C80BF29 7 Bytes JMP 28001CF0 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
                  .text C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe[656] kernel32.dll!LockResource 7C80CD37 5 Bytes JMP 28001F50 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
                  .text C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe[656] kernel32.dll!CreateEventA 7C8308B5 5 Bytes JMP 28001840 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
                  .text C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe[656] kernel32.dll!FindResourceExA 7C835FA8 7 Bytes JMP 28001D80 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
                  .text C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe[656] ADVAPI32.dll!CryptDeriveKey 77DB9FFD 7 Bytes JMP 28001000 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
                  .text C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe[656] ADVAPI32.dll!CryptDecrypt 77DBA129 7 Bytes JMP 28001060 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
                  .text C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe[656] USER32.dll!GetWindowLongW 7E3988A6 7 Bytes JMP 28006A70 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
                  .text C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe[656] USER32.dll!PeekMessageW 7E39929B 5 Bytes JMP 28004630 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
                  .text C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe[656] USER32.dll!SetWindowPlacement 7E39DE46 5 Bytes JMP 28005E10 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
                  .text C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe[656] USER32.dll!CreateDialogParamW 7E39EA3B 5 Bytes JMP 28006090 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
                  .text C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe[656] USER32.dll!LoadImageW 7E3A7B97 5 Bytes JMP 280066E0 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
                  .text C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe[656] USER32.dll!CreateWindowExW 7E3AD0A3 5 Bytes JMP 28003C60 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
                  .text C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe[656] USER32.dll!SetWindowRgn 7E3AE528 7 Bytes JMP 28005F50 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
                  .text C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe[656] USER32.dll!LoadIconW 7E3AE8BC 5 Bytes JMP 280068D0 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
                  .text C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe[656] USER32.dll!MessageBoxIndirectW 7E3E64D5 5 Bytes JMP 28006280 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
                  .text C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe[656] USER32.dll!TrackPopupMenuEx 7E3ECF62 5 Bytes JMP 28004F10 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
                  .text C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe[656] WS2_32.dll!closesocket 719F3E2B 5 Bytes JMP 2800B8C0 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
                  .text C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe[656] WS2_32.dll!send 719F4C27 5 Bytes JMP 2800B4A0 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
                  .text C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe[656] WS2_32.dll!WSARecv 719F4CB5 5 Bytes JMP 2800B280 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
                  .text C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe[656] WS2_32.dll!recv 719F676F 5 Bytes JMP 2800B0E0 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
                  .text C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe[656] WS2_32.dll!WSASend 719F68FA 5 Bytes JMP 2800B680 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
                  .text C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe[656] SHELL32.dll!Shell_NotifyIconW 7CA3A5BF 5 Bytes JMP 280033B0 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
                  .text C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe[656] ole32.dll!CoInitializeEx 774BEF7B 5 Bytes JMP 28002260 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
                  .text C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe[656] ole32.dll!CoCreateInstance 774C057E 5 Bytes JMP 28002600 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
                  .text C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe[656] ole32.dll!CoRegisterClassObject 774D7E90 5 Bytes JMP 28002360 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
                  .text C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe[656] WININET.dll!InternetReadFile 404B654B 5 Bytes JMP 2800A090 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
                  .text C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe[656] WININET.dll!InternetCloseHandle 404B9088 5 Bytes JMP 2800A240 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
                  .text C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe[656] WININET.dll!HttpOpenRequestA 404BD508 5 Bytes JMP 28009F00 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
                  .text C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe[656] WININET.dll!HttpSendRequestA 404CEE89 5 Bytes JMP 2800A170 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
                  .text C:\Program Files\Mozilla Firefox\firefox.exe[2324] ntdll.dll!LdrLoadDll 7C9263C3 5 Bytes JMP 004013F0 C:\Program Files\Mozilla Firefox\firefox.exe (Firefox/Mozilla Corporation)

                  ---- Devices - GMER 1.0.15 ----

                  Device \Driver\atapi \Device\Ide\IdePort0 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
                  Device \Driver\atapi \Device\Ide\IdePort1 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
                  Device \Driver\atapi \Device\Ide\IdePort2 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
                  Device \Driver\atapi \Device\Ide\IdePort3 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
                  Device \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-12 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
                  Device \Driver\atapi \Device\Ide\IdeDeviceP3T0L0-7 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
                  Device \Driver\USBSTOR \Device\00000080 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
                  Device \Driver\USBSTOR \Device\00000083 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)

                  ---- EOF - GMER 1.0.15 ----
                  0
                  1. Contributeur sécurité
                    /!\ Il faut impérativement désactiver tous tes logiciels de protection pour utiliser ce programme/!\

                    ? Télécharge : Gmer (by Przemyslaw Gmerek)

                    http://www.gmer.net/

                    ? Dezippe gmer ,cliques sur l'onglet rootkit,lances le scan,des lignes rouges vont apparaitre.

                    ? Les lignes rouges indiquent la presence d'un rootkit.Postes moi le rapport gmer (cliques sur copy,puis vas dans demarrer ,puis ouvres le bloc note,vas dans edition et cliques sur coller,le rapport gmer va apparaitre,postes moi le)
                    0
                    1. Le logiciel SDFix ne fonctionne pas. Après avoir redémarrer mon pc en mode sans échec puis cliqué sur le logiciel, rien ne se passe le logiciel ne s'ouvre pas.
                      0
                      1. Contributeur sécurité
                        Télécharge SDFix (créé par AndyManchesta) et sauvegarde le sur ton Bureau.

                        http://downloads.andymanchesta.com/RemovalTools/SDFix.exe

                        Double clique sur SDFix.exe et choisis Install pour l'extraire dans un dossier dédié dans C:\
                        * Redémarre ton ordinateur en mode sans échec en suivant la procédure que voici :
                        1)Redémarre ton ordinateur
                        2) Après avoir entendu l'ordinateur biper lors du démarrage, mais avant que l'icône Windows apparaisse, tapote la touche F8 (une pression par seconde).
                        3)A la place du chargement normal de Windows, un menu avec différentes options devrait apparaître.
                        4)Choisis la première option, pour exécuter Windows en mode sans échec, puis appuie sur "Entrée".
                        5)Choisis ton compte.

                        Déroule la liste des instructions ci-dessous :
                        * Ouvre le dossier SDFix qui vient d'être créé dans le répertoire C:\ et double clique sur RunThis.bat pour lancer le script.
                        * Appuie sur Y pour commencer le processus de nettoyage.
                        * Il va supprimer les services et les entrées du Registre de certains trojans trouvés puis te demandera d'appuyer sur une touche pour redémarrer.
                        * Appuie sur une touche pour redémarrer le PC.
                        * Ton système sera plus long pour redémarrer qu'à l'accoutumée car l'outil va continuer à s'exécuter et supprimer des fichiers.
                        * Après le chargement du Bureau, l'outil terminera son travail et affichera Finished.
                        * Appuie sur une touche pour finir l'exécution du scrïpt et charger les icônes de ton Bureau.
                        * Les icônes du Bureau affichées, le rapport SDFix s'ouvrira à l'écran et s'enregistrera aussi dans le dossier SDFix sous le nom Report.txt.
                        * Enfin, copie/colle le contenu du fichier Report.txt dans ta prochaine réponse sur le forum

                        Tuto pour t'aider
                        https://www.tayo.fr/sdfix-tutoriel.php

                        0
                        1. MD5: e4bdf223cd75478bf44567b4d5c2634d
                          First received: 2009.02.12 09:20:26 UTC
                          Date 2010.03.22 15:26:24 UTC [<1D]
                          Résultats 0/42
                          Permalink: analisis/6234155d6c02c67689744d21380b17db5fe395bc8622c71b046e40ca1767785a-1269271584
                          0
                          1. Contributeur sécurité
                            Rends toi sur ce site :

                            https://www.virustotal.com/gui/

                            Clique sur parcourir et cherche ce fichier :

                            C:\WINDOWS\system32\drivers\svchost.exe

                            Clique sur Send File.

                            Un rapport va s'élaborer ligne à ligne.

                            Attends la fin. Il doit comprendre la taille du fichier envoyé.

                            Sauvegarde le rapport avec le bloc-note.

                            Copie le dans ta réponse.

                            Si tu ne trouves pas le fichier alors

                            Affiche tous les fichiers et dossiers :

                            Pour cela :
                            Clique sur démarrer/panneau de configuration/option des dossiers/affichage

                            Cocher afficher les dossiers cachés

                            Décoche la case "Masquer les fichiers protégés du système d'exploitation (recommandé)"

                            Décocher masquer les extensions dont le type est connu

                            Puis fais «appliquer» pour valider les changements.

                            Et OK
                            0
                            1. Le pc va bien, le problème c'est qu'il ram de plus en plus. Je ne sais pas si c'est à cause de tout ces virus ou alors de la place qu'il y a sur mon pc.

                              Voici le rapport :

                              Logfile of random's system information tool 1.06 (written by random/random)
                              Run by Propriétaire at 2010-03-23 11:33:32
                              Microsoft Windows XP Édition familiale Service Pack 3
                              System drive C: has 3 GB (7%) free of 40 GB
                              Total RAM: 447 MB (23% free)

                              Logfile of Trend Micro HijackThis v2.0.2
                              Scan saved at 20:42:00, on 19/03/2009
                              Platform: Windows XP SP3 (WinNT 5.01.2600)
                              MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                              Boot mode: Normal

                              Running processes:
                              C:\WINDOWS\System32\smss.exe
                              C:\WINDOWS\system32\winlogon.exe
                              C:\WINDOWS\system32\services.exe
                              C:\WINDOWS\system32\lsass.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\System32\svchost.exe
                              C:\Program Files\Ahead\InCD\InCDsrv.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\Explorer.EXE
                              C:\WINDOWS\system32\spoolsv.exe
                              C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                              C:\WINDOWS\system32\S3trayp.exe
                              C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                              C:\Program Files\Panicware\Pop-Up Stopper\dpps2.exe
                              C:\Program Files\iTunes\iTunesHelper.exe
                              C:\Program Files\ZTE Corporation\ZXDSL852\CnxDslTb.exe
                              C:\WINDOWS\system32\VTTimer.exe
                              C:\WINDOWS\RTHDCPL.EXE
                              C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                              C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                              C:\Program Files\Java\jre6\bin\jusched.exe
                              C:\WINDOWS\system32\ctfmon.exe
                              C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
                              C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                              C:\Program Files\Bonjour\mDNSResponder.exe
                              C:\WINDOWS\System32\svchost.exe
                              C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                              C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\wkcalrem.exe
                              C:\Program Files\Java\jre6\bin\jqs.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
                              C:\Program Files\iPod\bin\iPodService.exe
                              C:\WINDOWS\system32\wbem\wmiapsrv.exe
                              C:\WINDOWS\system32\wscntfy.exe
                              C:\Program Files\Windows Live\Contacts\wlcomm.exe
                              C:\WINDOWS\system32\wuauclt.exe
                              C:\Program Files\Windows Media Player\wmplayer.exe
                              C:\Program Files\Mozilla Firefox\firefox.exe
                              C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
                              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                              O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
                              O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
                              O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                              O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
                              O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
                              O2 - BHO: MegaIEMn - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - C:\Program Files\Megaupload\Mega Manager\MegaIEMn.dll
                              O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
                              O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                              O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
                              O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
                              O4 - HKLM\..\Run: [S3Trayp] S3trayp.exe
                              O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                              O4 - HKLM\..\Run: [Pop-Up Stopper] "C:\Program Files\Panicware\Pop-Up Stopper\dpps2.exe"
                              O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                              O4 - HKLM\..\Run: [CnxDslTaskBar] "C:\Program Files\ZTE Corporation\ZXDSL852\CnxDslTb.exe" "ZTE Corporation\ZXDSL852"
                              O4 - HKLM\..\Run: [Adobe Photo Downloader] "D:\3.2\Apps\apdproxy.exe"
                              O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
                              O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
                              O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
                              O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
                              O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                              O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                              O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
                              O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                              O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                              O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                              O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                              O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                              O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                              O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                              O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                              O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                              O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
                              O4 - Global Startup: Rappels du Calendrier Microsoft Works.lnk = ?
                              O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
                              O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                              O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                              O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                              O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                              O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                              O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                              O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
                              O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.mail.live.com/mail/w1/resources/MSNPUpld.cab
                              O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
                              O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
                              O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/...
                              O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - https://www.touslesdrivers.com/index.php?v_page=29
                              O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game06.zylom.com/activex/zylomgamesplayer.cab
                              O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
                              O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
                              O23 - Service: Planificateur Avira AntiVir Personal - Free Antivirus (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                              O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                              O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                              O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
                              O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                              O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
                              O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                              O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
                              O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
                              0
                              1. Contributeur sécurité
                                attention aux cracks...ils sont piégés

                                tu as eu déjà bagle ainsi !!!

                                vides la quarantaine de mbam

                                comment va le pc ?

                                relances RSIT et postes le rapport log stp
                                0
                                1. Malwarebytes' Anti-Malware 1.44
                                  Version de la base de données: 3895
                                  Windows 5.1.2600 Service Pack 3
                                  Internet Explorer 8.0.6001.18702

                                  23/03/2010 11:09:10
                                  mbam-log-2010-03-23 (11-09-10).txt

                                  Type de recherche: Examen complet (C:\|D:\|)
                                  Eléments examinés: 235319
                                  Temps écoulé: 2 hour(s), 19 minute(s), 39 second(s)

                                  Processus mémoire infecté(s): 0
                                  Module(s) mémoire infecté(s): 0
                                  Clé(s) du Registre infectée(s): 2
                                  Valeur(s) du Registre infectée(s): 2
                                  Elément(s) de données du Registre infecté(s): 0
                                  Dossier(s) infecté(s): 0
                                  Fichier(s) infecté(s): 3

                                  Processus mémoire infecté(s):
                                  (Aucun élément nuisible détecté)

                                  Module(s) mémoire infecté(s):
                                  (Aucun élément nuisible détecté)

                                  Clé(s) du Registre infectée(s):
                                  HKEY_CURRENT_USER\Software\YVIBBBHA8C (Trojan.Agent) -> Quarantined and deleted successfully.
                                  HKEY_CURRENT_USER\Software\WEK9EMDHI9 (Trojan.Agent) -> Quarantined and deleted successfully.

                                  Valeur(s) du Registre infectée(s):
                                  HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\yvibbbha8c (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                                  HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\wek9emdhi9 (Trojan.Agent) -> Quarantined and deleted successfully.

                                  Elément(s) de données du Registre infecté(s):
                                  (Aucun élément nuisible détecté)

                                  Dossier(s) infecté(s):
                                  (Aucun élément nuisible détecté)

                                  Fichier(s) infecté(s):
                                  D:\Da sims 2\Les Sims 2 La Bonne Affaire\Keygen\Keygen.exe (Trojan.Orsam) -> Quarantined and deleted successfully.
                                  C:\Documents and Settings\Propriétaire\Local Settings\Temp\sshnas21.dll (Trojan.Downloader) -> Quarantined and deleted successfully.
                                  C:\WINDOWS\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job (Trojan.Downloader) -> Quarantined and deleted successfully.
                                  0
                                  1. Contributeur sécurité
                                    Vu

                                    ==> MBAM
                                    0
                                    1. Kill'em by g3n-h@ckm@n 1.6.0.2

                                      User : Propriétaire (Administrateurs)
                                      Update on 18/03/2010 by g3n-h@ckm@n ::::: 12.30
                                      Start at: 20:41:43 | 21/03/2010
                                      Contact : https://forums.commentcamarche.net/forum/virus-securite-7

                                      AMD Sempron(tm) Processor 3000+
                                      Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
                                      Internet Explorer 8.0.6001.18702
                                      Windows Firewall Status : Enabled
                                      AV : AntiVir Desktop 9.0.1.32 [ Enabled | Updated ]
                                      FW : Look 'n' Stop 2.06p3 (Soft4Ever)[ (!) Disabled ]2.06p3

                                      C:\ -> Disque fixe local | 39,07 Go (2,67 Go free) | NTFS
                                      D:\ -> Disque fixe local | 109,97 Go (64,92 Go free) | NTFS
                                      E:\ -> Disque CD-ROM
                                      G:\ -> Disque amovible

                                      ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running

                                      C:\WINDOWS\System32\smss.exe
                                      C:\WINDOWS\system32\csrss.exe
                                      C:\WINDOWS\system32\winlogon.exe
                                      C:\WINDOWS\system32\services.exe
                                      C:\WINDOWS\system32\lsass.exe
                                      C:\WINDOWS\system32\svchost.exe
                                      C:\WINDOWS\system32\svchost.exe
                                      C:\WINDOWS\System32\svchost.exe
                                      C:\Program Files\Ahead\InCD\InCDsrv.exe
                                      C:\WINDOWS\system32\svchost.exe
                                      C:\WINDOWS\Explorer.EXE
                                      C:\WINDOWS\system32\svchost.exe
                                      C:\WINDOWS\system32\svchost.exe
                                      C:\WINDOWS\system32\spoolsv.exe
                                      C:\WINDOWS\system32\cmd.exe
                                      C:\Program Files\Avira\AntiVir Desktop\sched.exe
                                      C:\DOCUME~1\PROPRI~1\LOCALS~1\Temp\Idx.exe
                                      C:\WINDOWS\system32\svchost.exe
                                      C:\WINDOWS\Iwutea.exe
                                      C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                                      C:\Program Files\Bonjour\mDNSResponder.exe
                                      C:\WINDOWS\System32\svchost.exe
                                      C:\Program Files\Java\jre6\bin\jqs.exe
                                      C:\WINDOWS\system32\HPZipm12.exe
                                      C:\WINDOWS\system32\svchost.exe
                                      C:\WINDOWS\system32\wbem\wmiprvse.exe
                                      C:\WINDOWS\system32\wbem\wmiapsrv.exe
                                      C:\WINDOWS\System32\alg.exe
                                      C:\WINDOWS\system32\wbem\wmiprvse.exe
                                      C:\Program Files\List_Kill'em\ERUNT.EXE
                                      C:\Program Files\List_Kill'em\pv.exe

                                      Detections :
                                      ==========

                                      ¤¤¤¤¤¤¤¤¤¤ Files/folders :

                                      Quarantined & Deleted !! : C:\Program Files\Circle Dvelopement
                                      Quarantined & Deleted !! : C:\Program Files\GamesBar
                                      Quarantined & Deleted !! : C:\WINDOWS\002928_.tmp
                                      Quarantined & Deleted !! : C:\WINDOWS\003061_.tmp
                                      Quarantined & Deleted !! : C:\WINDOWS\SET3.tmp
                                      Quarantined & Deleted !! : C:\WINDOWS\SET4.tmp
                                      Quarantined & Deleted !! : C:\WINDOWS\SET77.tmp
                                      Quarantined & Deleted !! : C:\WINDOWS\SET7A.tmp
                                      Quarantined & Deleted !! : C:\WINDOWS\SET8.tmp
                                      Quarantined & Deleted !! : C:\WINDOWS\SET86.tmp
                                      Quarantined & Deleted !! : C:\WINDOWS\SETB9.tmp

                                      Quarantined & Deleted !! : C:\WINDOWS\System32\sshnas21.dll
                                      Quarantined & Deleted !! : C:\WINDOWS\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
                                      Quarantined & Deleted !! : C:\WINDOWS\tasks\{66BA574B-1E11-49b8-909C-8CC9E0E8E015}.job
                                      Quarantined & Deleted !! : C:\Documents and Settings\Propri'taire\Application Data\awyqivusez.ban
                                      Quarantined & Deleted !! : C:\Documents and Settings\Propri'taire\Application Data\ademimoq.dat
                                      Quarantined & Deleted !! : C:\Documents and Settings\Propri'taire\Application Data\GDIPFONTCACHEV1.DAT
                                      Quarantined & Deleted !! : C:\Documents and Settings\Propri'taire\Application Data\ozokusebyt.dat
                                      Quarantined & Deleted !! : C:\Documents and Settings\Propri'taire\Application Data\HPSU_48BitScanUpdate.log
                                      Quarantined & Deleted !! : C:\Documents and Settings\Propri'taire\Application Data\PatchUpdate_HP_CounterReport_Update_HPSU.log
                                      Quarantined & Deleted !! : C:\Documents and Settings\Propri'taire\Application Data\Update_HP_RedboxHprblog_HPSU.log
                                      Quarantined & Deleted !! : C:\Documents and Settings\Propri'taire\Application Data\drivers
                                      Quarantined & Deleted !! : C:\Documents and Settings\Propri'taire\Local Settings\Temp\a.dat
                                      Quarantined & Deleted !! : C:\Documents and Settings\Propri'taire\Local Settings\Temp\b.dat
                                      Quarantined & Deleted !! : C:\Documents and Settings\Propri'taire\Local Settings\Temp\Id0.exe
                                      Quarantined & Deleted !! : C:\Documents and Settings\Propri'taire\Local Settings\Temp\Idv.exe
                                      Quarantined & Deleted !! : C:\Documents and Settings\Propri'taire\Local Settings\Temp\Idw.exe
                                      Quarantined & Deleted !! : C:\Documents and Settings\Propri'taire\Local Settings\Temp\Idx.exe
                                      Quarantined & Deleted !! : C:\Documents and Settings\Propri'taire\Local Settings\Temp\Idy.exe
                                      Quarantined & Deleted !! : C:\Documents and Settings\Propri'taire\Local Settings\Temp\Idz.exe
                                      Quarantined & Deleted !! : C:\Documents and Settings\Propri'taire\LOCAL Settings\Temp\8BD54F3E-DD19-4a69-93D8-5C6A5BBBE20E.exe
                                      Quarantined & Deleted !! : C:\Documents and Settings\Propri'taire\LOCAL Settings\Temp\eauninstall.exe
                                      Quarantined & Deleted !! : C:\Documents and Settings\Propri'taire\LOCAL Settings\Temp\lsnfier.exe
                                      Quarantined & Deleted !! : C:\Documents and Settings\Propri'taire\LOCAL Settings\Temp\msizapMG.exe
                                      Quarantined & Deleted !! : C:\Documents and Settings\Propri'taire\LOCAL Settings\Temp\The Sims 2_uninst.exe
                                      Quarantined & Deleted !! : C:\Documents and Settings\Propri'taire\LOCAL Settings\Temp\sshnas21.dll

                                      ==============
                                      host file OK !
                                      ==============

                                      ========
                                      Registry
                                      ========

                                      Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{0E5CBF21-D15F-11D0-8301-00AA005B4383}
                                      Deleted : HKCU\Software\bisoft
                                      Deleted : HKCU\Software\Lanconfig
                                      Deleted : HKCU\Software\livesvc
                                      Deleted : HKCU\SOFTWARE\Microsoft\Handle
                                      Deleted : HKCU\SOFTWARE\XML
                                      Deleted : HKLM\SYSTEM\ControlSet001\Enum\Root\Legacy_SSHNAS
                                      Deleted : HKLM\SYSTEM\ControlSet001\Services\SSHNAS
                                      ========
                                      Services
                                      =========

                                      Ndisuio : Start = 3
                                      EapHost : Start = 2
                                      Ip6Fw : Start = 2
                                      SharedAccess : Start = 2
                                      wuauserv : Start = 2
                                      wscsvc : Start = 2

                                      ============
                                      Disk Cleaned
                                      ============

                                      =================
                                      anti-ver blaster : OK !!
                                      =================

                                      ================
                                      Prefetch cleaned
                                      ================

                                      ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
                                      0
                                      1. Contributeur sécurité
                                        1)

                                        ? Relance List_Kill'em(soit en clic droit pour vista/7),avec le raccourci sur ton bureau.
                                        mais cette fois-ci :

                                        ? choisis l'option 2 = Mode Suppression

                                        ton PC va redemarrer,

                                        laisse travailler l'outil.

                                        en fin de scan la fenetre se ferme , et tu as un rapport du nom de Kill'em.txt sur ton bureau ,

                                        ? colle le contenu dans ta reponse

                                        Tu peux le désinstaller ensuite

                                        .....................

                                        2)

                                        lances MalwareByte's Anti-Malware
                                        mets le à jour
                                        examen complet
                                        supprimer ce qu'il trouve
                                        poster le rapport

                                        0
                                        1. List'em by g3n-h@ckm@n 1.6.0.2

                                          User : Propriétaire (Administrateurs)
                                          Update on 18/03/2010 by g3n-h@ckm@n ::::: 12.30
                                          Start at: 17:42:14 | 21/03/2010
                                          Contact : https://forums.commentcamarche.net/forum/virus-securite-7

                                          AMD Sempron(tm) Processor 3000+
                                          Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
                                          Internet Explorer 8.0.6001.18702
                                          Windows Firewall Status : Enabled
                                          AV : AntiVir Desktop 9.0.1.32 [ (!) Disabled | Updated ]
                                          FW : Look 'n' Stop 2.06p3 (Soft4Ever)[ (!) Disabled ]2.06p3

                                          C:\ -> Disque fixe local | 39,07 Go (2,74 Go free) | NTFS
                                          D:\ -> Disque fixe local | 109,97 Go (64,92 Go free) | NTFS
                                          E:\ -> Disque CD-ROM
                                          G:\ -> Disque amovible

                                          Boot: Normal

                                          ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running

                                          C:\WINDOWS\System32\smss.exe
                                          C:\WINDOWS\system32\csrss.exe
                                          C:\WINDOWS\system32\winlogon.exe
                                          C:\WINDOWS\system32\services.exe
                                          C:\WINDOWS\system32\lsass.exe
                                          C:\WINDOWS\system32\svchost.exe
                                          C:\WINDOWS\system32\svchost.exe
                                          C:\WINDOWS\System32\svchost.exe
                                          C:\Program Files\Ahead\InCD\InCDsrv.exe
                                          C:\WINDOWS\system32\svchost.exe
                                          C:\WINDOWS\Explorer.EXE
                                          C:\WINDOWS\system32\svchost.exe
                                          C:\WINDOWS\system32\svchost.exe
                                          C:\WINDOWS\system32\spoolsv.exe
                                          C:\Program Files\Avira\AntiVir Desktop\sched.exe
                                          C:\WINDOWS\system32\svchost.exe
                                          C:\WINDOWS\system32\S3trayp.exe
                                          C:\Program Files\Panicware\Pop-Up Stopper\dpps2.exe
                                          C:\WINDOWS\system32\VTTimer.exe
                                          C:\WINDOWS\RTHDCPL.EXE
                                          C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                                          C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
                                          C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                                          C:\WINDOWS\PixArt\PAC207\Monitor.exe
                                          C:\Program Files\Java\jre6\bin\jusched.exe
                                          C:\WINDOWS\system32\ctfmon.exe
                                          C:\Program Files\Bonjour\mDNSResponder.exe
                                          C:\Program Files\DNA\btdna.exe
                                          C:\WINDOWS\System32\svchost.exe
                                          C:\Program Files\Java\jre6\bin\jqs.exe
                                          C:\WINDOWS\system32\HPZipm12.exe
                                          C:\WINDOWS\system32\svchost.exe
                                          C:\Program Files\Neuf\Kit\9props.exe
                                          C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\wkcalrem.exe
                                          C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe
                                          C:\WINDOWS\System32\alg.exe
                                          C:\WINDOWS\system32\wbem\wmiapsrv.exe
                                          C:\Program Files\Windows Media Player\wmplayer.exe
                                          C:\Program Files\eMule\emule.exe
                                          C:\WINDOWS\Iwutea.exe
                                          C:\Program Files\Fichiers communs\Adobe\Updater6\Adobe_Updater.exe
                                          C:\DOCUME~1\PROPRI~1\LOCALS~1\Temp\Idx.exe
                                          C:\Program Files\List_Kill'em\List_Kill'em.exe
                                          C:\WINDOWS\system32\wscntfy.exe
                                          C:\Program Files\Mozilla Firefox\firefox.exe
                                          C:\WINDOWS\system32\cmd.exe
                                          C:\WINDOWS\system32\wbem\wmiprvse.exe
                                          C:\Program Files\List_Kill'em\pv.exe

                                          ======================
                                          Keys "Run"
                                          ======================
                                          [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                          CTFMON.EXE REG_SZ C:\WINDOWS\system32\ctfmon.exe
                                          msnmsgr REG_SZ "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                                          BitTorrent DNA REG_SZ "C:\Program Files\DNA\btdna.exe"
                                          Uniblue RegistryBooster 2009 REG_SZ D:\Logiciel pour carte graphique\Uniblue\RegistryBooster\RegistryBooster.exe /S
                                          Connexion SFR 9props.exe REG_SZ "C:\Program Files\Neuf\Kit\9props.exe" /trayicon
                                          YVIBBBHA8C REG_SZ C:\DOCUME~1\PROPRI~1\LOCALS~1\Temp\Idx.exe
                                          WEK9EMDHI9 REG_SZ C:\WINDOWS\Iwutea.exe

                                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                          S3Trayp REG_SZ S3trayp.exe
                                          Pop-Up Stopper REG_SZ "C:\Program Files\Panicware\Pop-Up Stopper\dpps2.exe"
                                          Adobe Photo Downloader REG_SZ "D:\3.2\Apps\apdproxy.exe"
                                          VTTimer REG_SZ VTTimer.exe
                                          RTHDCPL REG_SZ RTHDCPL.EXE
                                          SkyTel REG_SZ SkyTel.EXE
                                          Alcmtr REG_SZ ALCMTR.EXE
                                          TkBellExe REG_SZ "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                                          Adobe Reader Speed Launcher REG_SZ "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
                                          QuickTime Task REG_SZ "D:\QuickTime\qttask.exe" -atboottime
                                          avgnt REG_SZ "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
                                          Monitor REG_SZ C:\WINDOWS\PixArt\PAC207\Monitor.exe
                                          SunJavaUpdateSched REG_SZ "C:\Program Files\Java\jre6\bin\jusched.exe"

                                          [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]

                                          [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]

                                          =====================
                                          Other Keys
                                          =====================
                                          [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
                                          dontdisplaylastusername REG_DWORD 0 (0x0)
                                          legalnoticecaption REG_SZ
                                          legalnoticetext REG_SZ
                                          shutdownwithoutlogon REG_DWORD 1 (0x1)
                                          undockwithoutlogon REG_DWORD 1 (0x1)
                                          EnableLUA REG_DWORD 0 (0x0)

                                          ===============
                                          [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
                                          NoDriveTypeAutoRun REG_BINARY 95000000
                                          HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run

                                          ===============
                                          [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
                                          HonorAutoRunSetting REG_DWORD 1 (0x1)

                                          ===============
                                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
                                          AppInit_DLLS REG_SZ

                                          ===============
                                          [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
                                          AutoRestartShell REG_DWORD 1 (0x1)
                                          DefaultDomainName REG_SZ REQUIER-1C9D4F7
                                          DefaultUserName REG_SZ Propriétaire
                                          LegalNoticeCaption REG_SZ
                                          LegalNoticeText REG_SZ
                                          PowerdownAfterShutdown REG_SZ 0
                                          ReportBootOk REG_SZ 1
                                          Shell REG_SZ Explorer.exe
                                          ShutdownWithoutLogon REG_SZ 0
                                          System REG_SZ
                                          Userinit REG_SZ C:\WINDOWS\system32\userinit.exe,
                                          VmApplet REG_SZ rundll32 shell32,Control_RunDLL "sysdm.cpl"
                                          SfcQuota REG_DWORD -1 (0xffffffff)
                                          allocatecdroms REG_SZ 0
                                          allocatedasd REG_SZ 0
                                          allocatefloppies REG_SZ 0
                                          cachedlogonscount REG_SZ 10
                                          forceunlocklogon REG_DWORD 0 (0x0)
                                          passwordexpirywarning REG_DWORD 14 (0xe)
                                          scremoveoption REG_SZ 0
                                          AllowMultipleTSSessions REG_DWORD 1 (0x1)
                                          UIHost REG_EXPAND_SZ logonui.exe
                                          LogonType REG_DWORD 1 (0x1)
                                          DebugServerCommand REG_SZ no
                                          SFCDisable REG_DWORD 0 (0x0)
                                          WinStationsDisabled REG_SZ 0
                                          HibernationPreviouslyEnabled REG_DWORD 1 (0x1)
                                          ShowLogonOptions REG_DWORD 0 (0x0)
                                          AltDefaultUserName REG_SZ Propriétaire
                                          AltDefaultDomainName REG_SZ REQUIER-1C9D4F7
                                          ChangePasswordUseKerberos REG_DWORD 1 (0x1)
                                          AutoAdminLogon REG_SZ 0
                                          Background REG_SZ 0 0 0
                                          SfcScan REG_DWORD 0 (0x0)

                                          ===============
                                          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\crypt32chain]
                                          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cryptnet]
                                          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cscdll]
                                          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\dimsntfy]
                                          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ScCertProp]
                                          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Schedule]
                                          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\sclgntfy]
                                          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\SensLogn]
                                          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\termsrv]
                                          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WgaLogon]
                                          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wlballoon]

                                          ===============
                                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
                                          {AEB6717E-7E19-11d0-97EE-00C04FD91972} REG_SZ

                                          ===============
                                          [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
                                          %windir%\system32\sessmgr.exe REG_SZ %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
                                          %windir%\Network Diagnostic\xpnetdiag.exe REG_SZ %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
                                          C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe REG_SZ C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe:*:Enabled:Kaspersky Anti-Virus
                                          C:\Program Files\eMule\emule.exe REG_SZ C:\Program Files\eMule\emule.exe:*:Enabled:eMule
                                          C:\Program Files\Vendetta\Vendetta.exe REG_SZ C:\Program Files\Vendetta\Vendetta.exe:*:Enabled:Vendetta
                                          C:\Documents and Settings\Propriétaire\Bureau\LimeWire\LimeWire.exe REG_SZ C:\Documents and Settings\Propriétaire\Bureau\LimeWire\LimeWire.exe:*:Enabled:LimeWire
                                          C:\DOCUME~1\PROPRI~1\LOCALS~1\Temp\services.exe REG_SZ C:\DOCUME~1\PROPRI~1\LOCALS~1\Temp\services.exe:*:Enabled:Flash Player2
                                          C:\Program Files\Bonjour\mDNSResponder.exe REG_SZ C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour
                                          D:\LimeWire\LimeWire.exe REG_SZ D:\LimeWire\LimeWire.exe:*:Enabled:LimeWire
                                          D:\Mes documents\eMule\emule.exe REG_SZ D:\Mes documents\eMule\emule.exe:*:Enabled:eMule
                                          C:\Program Files\MySpace\IM\MySpaceIM.exe REG_SZ C:\Program Files\MySpace\IM\MySpaceIM.exe:*:Enabled:MySpace Instant Messenger
                                          C:\WINDOWS\system32\dpvsetup.exe REG_SZ C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test
                                          C:\WINDOWS\system32\rundll32.exe REG_SZ C:\WINDOWS\system32\rundll32.exe:*:Enabled:Exécuter une DLL en tant qu'application
                                          C:\WINDOWS\system32\drivers\svchost.exe REG_SZ C:\WINDOWS\system32\drivers\svchost.exe:*:Disabled:svchost
                                          C:\Program Files\ma-config.com\maconfservice.exe REG_SZ C:\Program Files\ma-config.com\maconfservice.exe:LocalSubNet:Enabled:maconfservice
                                          C:\Program Files\DNA\btdna.exe REG_SZ C:\Program Files\DNA\btdna.exe:*:Enabled:DNA
                                          C:\Program Files\BitTorrent\bittorrent.exe REG_SZ C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent
                                          C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe REG_SZ C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe
                                          C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe REG_SZ C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe
                                          C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe REG_SZ C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe
                                          C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe REG_SZ C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe
                                          C:\Program Files\HP\Digital Imaging\bin\hposid01.exe REG_SZ C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe
                                          C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe REG_SZ C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe:*:Enabled:hpqcopy.exe
                                          C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe REG_SZ C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe:*:Enabled:hpfccopy.exe
                                          C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe REG_SZ C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe
                                          C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe REG_SZ C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe:*:Enabled:hpqphunl.exe
                                          C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe REG_SZ C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe:*:Enabled:hpqdia.exe
                                          C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe REG_SZ C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe
                                          C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe REG_SZ C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live FolderShare
                                          C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe REG_SZ C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe:*:Enabled:hpqscnvw.exe
                                          C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe REG_SZ C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe
                                          C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe REG_SZ C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe:*:Enabled:hpqnrs08.exe
                                          C:\Program Files\Messenger\msmsgs.exe REG_SZ C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger
                                          C:\Program Files\Windows Live\Messenger\msnmsgr.exe REG_SZ C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger

                                          [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
                                          %windir%\system32\sessmgr.exe REG_SZ %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
                                          %windir%\Network Diagnostic\xpnetdiag.exe REG_SZ %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
                                          C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe REG_SZ C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live FolderShare
                                          C:\Program Files\Windows Live\Messenger\msnmsgr.exe REG_SZ C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger

                                          ===============
                                          ActivX controls
                                          ===============
                                          [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{0CCA191D-13A6-4E29-B746-314DEE697D83}]
                                          [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{166B1BCA-3F9C-11CF-8075-444553540000}]
                                          [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{20A60F0D-9AFA-4515-A0FD-83BD84642501}]
                                          [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{233C1507-6A77-46A4-9443-F871F945D258}]
                                          [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{4F1E5B1A-2A80-42CA-8532-2D05CB959537}]
                                          [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{5D6F45B3-9043-443D-A792-115447494D24}]
                                          [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{6414512B-B978-451D-A0D8-FCFDF33E833C}]
                                          [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{6E32070A-766D-4EE6-879C-DC1FA91D2FC3}]
                                          [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{867E13F2-7F31-44FB-AC97-CD38E0DC46EF}]
                                          [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{8AD9C840-044E-11D1-B3E9-00805F499D93}]
                                          [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}]
                                          [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B}]
                                          [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{C3F79A2B-B9B4-4A66-B012-3EE46475B072}]
                                          [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA}]
                                          [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}]
                                          [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}]
                                          [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{D27CDB6E-AE6D-11CF-96B8-444553540000}]
                                          [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}]
                                          [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{F5A7706B-B9C0-4C89-A715-7A0C6B05DD48}]

                                          ===============
                                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\<{12d0ed0d-0ee0-4f90-8827-78cefb8f4988}]
                                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
                                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{26923b43-4d38-484f-9b9e-de460746276c}]
                                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
                                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS]
                                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
                                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{ED3DF1A7-E9AD-41C7-A62A-1CDA6E33F517}]
                                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\Microsoft Base Smart Card Crypto Provider Package]
                                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{08B0E5C0-4FCB-11CF-AAA5-00401C608500}]
                                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10072CEC-8CC1-11D1-986E-00A0C955B42F}]
                                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2179C5D3-EBFF-11CF-B6FD-00AA00B4E220}]
                                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
                                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{233C1507-6A77-46A4-9443-F871F945D258}]
                                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{283807B5-2C60-11D0-A31D-00AA00B92C03}]
                                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2A202491-F00D-11cf-87CC-0020AFEECF20}]
                                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2BF024F4-FEA1-E6F6-4D88-2B624839AB85}]
                                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
                                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{36f8ec70-c29a-11d1-b5c7-0000f8051515}]
                                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{3af36230-a269-11d1-b5bf-0000f8051515}]
                                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{3bf42070-b3b1-11d1-b5c5-0000f8051515}]
                                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{3EB7DEA8-CAE0-B143-B016-F0F3C48BBBCE}]
                                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{411EDCF7-755D-414E-A74B-3DCD6583F589}]
                                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4278c270-a269-11d1-b5bf-0000f8051515}]
                                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
                                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
                                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA848-CC51-11CF-AAFA-00AA00B6015C}]
                                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA855-CC51-11CF-AAFA-00AA00B6015F}]
                                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{45ea75a0-a269-11d1-b5bf-0000f8051515}]
                                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4f216970-c90c-11d1-b5c7-0000f8051515}]
                                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4f645220-306d-11d2-995d-00c04f98bbc9}]
                                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5056b317-8d4c-43ee-8543-b9d1e234b8f4}]
                                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]
                                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5A8D6EE0-3E18-11D0-821E-444553540000}]
                                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5fd399c0-a70a-11d1-9948-00c04f98bbc9}]
                                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{630b1da0-b465-11d1-9948-00c04f98bbc9}]
                                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
                                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6fab99d0-bab8-11d1-994a-00c04f98bbc9}]
                                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}]
                                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{729A8BE0-FC8F-B46B-85C3-6CBC63A548E8}]
                                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{73FA19D0-2D75-11D2-995D-00C04F98BBC9}]
                                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
                                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4340}]
                                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4383}]
                                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}]
                                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9331AFAF-D6C1-E0A5-21FB-266572A249F1}]
                                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9381D8F2-0288-11D0-9501-00AA00B911A5}]
                                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9A394342-4A68-4EBA-85A6-55B559F4E700}]
                                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{B508B3F1-A24A-32C0-B310-85786919EF28}]
                                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{B61F7032-38D5-17DD-0E76-BCB2A3C093E2}]
                                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}]
                                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C9E9A340-D1F1-11D0-821E-444553540600}]
                                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}]
                                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CC2A9BA0-3BDD-11D0-821E-444553540000}]
                                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CDD7975E-60F8-41d5-8149-19E51D6F71D0}]
                                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
                                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{DAA94A2A-2A8D-4D3B-9DB8-56FBECED082D}]
                                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{de5aed00-a4bf-11d1-9948-00c04f98bbc9}]
                                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{E92B03AB-B707-11d2-9CBD-0000F87A369E}]
                                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{EB88F089-A126-0812-CF4E-CCC61FB1A7B7}]
                                          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{F196AC50-7C95-42E1-9947-BDAB18BF3C8C}]

                                          ==============
                                          BHO :
                                          ======
                                          [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
                                          [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
                                          [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
                                          [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
                                          [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{bf00e119-21a3-4fd1-b178-3b8537e75c92}]
                                          [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
                                          [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]

                                          ===
                                          DNS
                                          ===

                                          HKLM\SYSTEM\CCS\Services\Tcpip\..\{9426CA9E-0EAE-452C-B0BB-DC29DD1B35C7}: DhcpNameServer=192.168.1.1
                                          HKLM\SYSTEM\CS1\Services\Tcpip\..\{9426CA9E-0EAE-452C-B0BB-DC29DD1B35C7}: DhcpNameServer=192.168.1.1
                                          HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
                                          HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1

                                          ================
                                          Internet Explorer :
                                          ================
                                          [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
                                          Start Page REG_SZ https://www.msn.com/fr-fr/?ocid=iehp

                                          [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                                          Start Page REG_SZ https://www.msn.com/fr-fr

                                          ========
                                          Services
                                          ========
                                          [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services]

                                          Ndisuio : 0x3 ( OK = 3 )
                                          EapHost : 0x2 ( OK = 2 )
                                          SharedAccess : 0x2 ( OK = 2 )
                                          wuauserv : 0x2 ( OK = 2 )

                                          =========
                                          Atapi.sys
                                          =========

                                          %%%% HASHDEEP-1.0
                                          %%%% size,md5,sha256,filename
                                          ## Invoked from: C:\Program Files\List_Kill'em
                                          ## C:\> hashdeep.exe C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
                                          ##
                                          95360,cdfe4411a69c224bd1d11b2da92dac51,0e6b23a80f171550575bebc56f7500cd87a5cf03b2b9fdc49bc3de96282cd69d,C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
                                          %%%% HASHDEEP-1.0
                                          %%%% size,md5,sha256,filename
                                          ## Invoked from: C:\Program Files\List_Kill'em
                                          ## C:\> hashdeep.exe C:\WINDOWS\ServicePackFiles\i386\atapi.sys
                                          ##
                                          96512,9f3a2f5aa6875c72bf062c712cfa2674,b4df1d2c56a593c6b54de57395e3b51d288f547842893b32b0f59228a0cf70b9,C:\WINDOWS\ServicePackFiles\i386\atapi.sys
                                          %%%% HASHDEEP-1.0
                                          %%%% size,md5,sha256,filename
                                          ## Invoked from: C:\Program Files\List_Kill'em
                                          ## C:\> hashdeep.exe C:\WINDOWS\system32\drivers\atapi.sys
                                          ##
                                          96512,9f3a2f5aa6875c72bf062c712cfa2674,b4df1d2c56a593c6b54de57395e3b51d288f547842893b32b0f59228a0cf70b9,C:\WINDOWS\system32\drivers\atapi.sys

                                          Référence :
                                          ==========

                                          Win 2000_SP2 : ff953a8f08ca3f822127654375786bbe
                                          Win 2000_SP4 : 8c718aa8c77041b3285d55a0ce980867
                                          Win XP_32b : a64013e98426e1877cb653685c5c0009
                                          Win XP_SP2_32b : CDFE4411A69C224BD1D11B2DA92DAC51
                                          Win XP_SP3_32b : 9F3A2F5AA6875C72BF062C712CFA2674
                                          Vista_32b : e03e8c99d15d0381e02743c36afc7c6f
                                          Vista_SP1_32b : 2d9c903dc76a66813d350a562de40ed9
                                          Vista_SP2_32b : 1F05B78AB91C9075565A9D8A4B880BC4
                                          Vista_SP2_64b : 1898FAE8E07D97F2F6C2D5326C633FAC
                                          Windows 7_32b : 80C40F7FDFC376E4C5FEEC28B41C119E
                                          Windows 7_64b : 02062C0B390B7729EDC9E69C680A6F3C
                                          Windows 7_32b_Ultimate : 338c86357871c167a96ab976519bf59e

                                          =======
                                          Drive :
                                          =======

                                          D'fragmenteur de disque Windows
                                          Copyright (c) 2001 Microsoft Corp. et Executive Software International Inc.

                                          Rapport d'analyse
                                          39,07 Go total, 2,74 Go libre (7%), 29% fragment' (fragmentation du fichier 52%)

                                          Vous devriez d'fragmenter ce volume.

                                          ¤¤¤¤¤¤¤¤¤¤ Files/folders :

                                          Present !! : C:\Program Files\Circle Dvelopement
                                          Present !! : C:\Program Files\GamesBar
                                          Present !! : C:\WINDOWS\002928_.tmp
                                          Present !! : C:\WINDOWS\003061_.tmp
                                          Present !! : C:\WINDOWS\SET3.tmp
                                          Present !! : C:\WINDOWS\SET4.tmp
                                          Present !! : C:\WINDOWS\SET77.tmp
                                          Present !! : C:\WINDOWS\SET7A.tmp
                                          Present !! : C:\WINDOWS\SET8.tmp
                                          Present !! : C:\WINDOWS\SET86.tmp
                                          Present !! : C:\WINDOWS\SETB9.tmp
                                          Present !! : C:\WINDOWS\System32\sshnas??.dll
                                          Present !! : C:\WINDOWS\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
                                          Present !! : C:\WINDOWS\tasks\{66BA574B-1E11-49b8-909C-8CC9E0E8E015}.job
                                          Present !! : C:\Documents and Settings\Propri'taire\Application Data\awyqivusez.ban
                                          Present !! : C:\Documents and Settings\Propri'taire\Application Data\ademimoq.dat
                                          Present !! : C:\Documents and Settings\Propri'taire\Application Data\GDIPFONTCACHEV1.DAT
                                          Present !! : C:\Documents and Settings\Propri'taire\Application Data\ozokusebyt.dat
                                          Present !! : C:\Documents and Settings\Propri'taire\Application Data\HPSU_48BitScanUpdate.log
                                          Present !! : C:\Documents and Settings\Propri'taire\Application Data\PatchUpdate_HP_CounterReport_Update_HPSU.log
                                          Present !! : C:\Documents and Settings\Propri'taire\Application Data\Update_HP_RedboxHprblog_HPSU.log
                                          Present !! : C:\Documents and Settings\Propri'taire\Application Data\ademimoq.dat
                                          Present !! : C:\Documents and Settings\Propri'taire\Application Data\GDIPFONTCACHEV1.DAT
                                          Present !! : C:\Documents and Settings\Propri'taire\Application Data\ozokusebyt.dat
                                          Present !! : C:\Documents and Settings\Propri'taire\Application Data\drivers
                                          Present !! : C:\Documents and Settings\Propri'taire\Local Settings\Temp\a.dat
                                          Present !! : C:\Documents and Settings\Propri'taire\Local Settings\Temp\b.dat
                                          Present !! : C:\Documents and Settings\Propri'taire\Local Settings\Temp\Id0.exe
                                          Present !! : C:\Documents and Settings\Propri'taire\Local Settings\Temp\Idv.exe
                                          Present !! : C:\Documents and Settings\Propri'taire\Local Settings\Temp\Idw.exe
                                          Present !! : C:\Documents and Settings\Propri'taire\Local Settings\Temp\Idx.exe
                                          Present !! : C:\Documents and Settings\Propri'taire\Local Settings\Temp\Idy.exe
                                          Present !! : C:\Documents and Settings\Propri'taire\Local Settings\Temp\Idz.exe
                                          Present !! : C:\Documents and Settings\Propri'taire\LOCAL Settings\Temp\8BD54F3E-DD19-4a69-93D8-5C6A5BBBE20E.exe
                                          Present !! : C:\Documents and Settings\Propri'taire\LOCAL Settings\Temp\eauninstall.exe
                                          Present !! : C:\Documents and Settings\Propri'taire\LOCAL Settings\Temp\Id0.exe
                                          Present !! : C:\Documents and Settings\Propri'taire\LOCAL Settings\Temp\Idv.exe
                                          Present !! : C:\Documents and Settings\Propri'taire\LOCAL Settings\Temp\Idw.exe
                                          Present !! : C:\Documents and Settings\Propri'taire\LOCAL Settings\Temp\Idx.exe
                                          Present !! : C:\Documents and Settings\Propri'taire\LOCAL Settings\Temp\Idy.exe
                                          Present !! : C:\Documents and Settings\Propri'taire\LOCAL Settings\Temp\Idz.exe
                                          Present !! : C:\Documents and Settings\Propri'taire\LOCAL Settings\Temp\lsnfier.exe
                                          Present !! : C:\Documents and Settings\Propri'taire\LOCAL Settings\Temp\msizapMG.exe
                                          Present !! : C:\Documents and Settings\Propri'taire\LOCAL Settings\Temp\The Sims 2_uninst.exe
                                          Present !! : C:\Documents and Settings\Propri'taire\LOCAL Settings\Temp\a.dat
                                          Present !! : C:\Documents and Settings\Propri'taire\LOCAL Settings\Temp\b.dat
                                          Present !! : C:\Documents and Settings\Propri'taire\LOCAL Settings\Temp\sshnas21.dll

                                          ¤¤¤¤¤¤¤¤¤¤ Keys :

                                          Present !! : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{0E5CBF21-D15F-11D0-8301-00AA005B4383}
                                          Present !! : HKCU\Software\bisoft
                                          Present !! : HKCU\Software\Lanconfig
                                          Present !! : HKCU\Software\livesvc
                                          Present !! : HKCU\SOFTWARE\Microsoft\Handle
                                          Present !! : HKCU\SOFTWARE\XML
                                          Present !! : HKLM\SYSTEM\ControlSet001\Enum\Root\Legacy_SSHNAS
                                          Present !! : HKLM\SYSTEM\ControlSet001\Enum\Root\LEGACY_tdssserv.sys
                                          Present !! : HKLM\SYSTEM\ControlSet001\Services\SSHNAS
                                          Present !! : HKLM\SYSTEM\CurrentControlSet\Enum\Root\Legacy_SSHNAS
                                          Present !! : HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_tdssserv.sys
                                          Present !! : HKLM\SYSTEM\CurrentControlSet\Services\SSHNAS

                                          ============

                                          catchme 0.3.1398.3 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                                          Rootkit scan 2010-03-21 18:18:13
                                          Windows 5.1.2600 Service Pack 3 FAT NTAPI

                                          scanning hidden processes ...

                                          scanning hidden services ...

                                          scanning hidden autostart entries ...

                                          scanning hidden files ...

                                          scan completed successfully
                                          hidden processes: 0
                                          hidden services: 0
                                          hidden files: 0

                                          Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

                                          device: opened successfully
                                          user: MBR read successfully
                                          called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll sfsync02.sys atapi.sys viaide.sys
                                          kernel: MBR read successfully
                                          user & kernel MBR OK

                                          ¤¤¤¤¤¤¤¤¤¤ Cracks | Keygens | Serials

                                          D:\Da sims 2\Les Sims 2 La Bonne Affaire\Keygen\Keygen.exe

                                          ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

                                          End of scan : 18:23:40,37
                                          0
                                          • 1
                                          • 2
                                          • 3