Mon System32 (Vista) a un ADWARE

Résolu
Bonjour,

Hier j'ai scanné mes fichiers avec Avast, et il a trouver plusieurs virus sur des musiques et films.
Je les ai donc supprimer. Mais mon system32 est infecté et je ne sais pas si je dois aussi le supprimer ou pas.

(C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Tempory Internet Files\Content.IE5\5QLYB2V7)

Merci d'avance pour votre aide.
Configuration: Windows Vista
Firefox 3.5.6

63 réponses

Résumé de la discussion

Le problème décrit est la détection de malwares sur des fichiers musicaux et films par Avast, avec une infection potentielle du System32 sous Windows Vista. La solution préconisée consiste à installer Malwarebytes Anti-Malware, le mettre à jour, lancer un examen complet, supprimer les éléments détectés et générer un rapport à partager. D'autres conseils évoquent l'usage complémentaire de tutoriels et le fait que des scans préalables sans résultats ne suffisent pas, d'où l'importance d'une procédure pas à pas et de l'analyse du rapport. Certaines réponses montrent aussi que des outils tels que CCleaner n'apportent pas toujours de résultat et que le recours à des outils spécialisés reste nécessaire pour nettoyer et sécuriser le système.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    pas grave

    on fera sans....
    0
    1. Contributeur sécurité
      (sourire)
      0
      1. Je ne trouve pas comment résoudre mon probléme ? Je n'ai pas donner d'adresse mail et je ne trouve pas l'icone.
        0
    2. Contributeur sécurité
      non c'est tout bon...
      0
      1. D'accord. Merci pour tout.
        0
    3. Contributeur sécurité
      tu as été bien vite

      n'oublies pas les mises à jour et la purge c'est important

      pour le reste si c'est ok pour toi

      tu peux mettre le topic en resolu
      https://www.commentcamarche.net/infos/25917-marquer-un-fil-de-discussion-comme-etant-resolu/

      Bonne continuation et surtout , prudence et bon surf :)
      0
      1. Les mises a jour et la purge c'est fait. Pour internet je supprime l'exploreur 8 ?
        0
    4. Contributeur sécurité
      (sourire)

      15 posts de trop à mon goût

      mais ne pas oublier le post 81
      0
      1. [ Rapport ToolsCleaner version 2.3.11 (par A.Rothstein & dj QUIOU) ]

        --> Recherche:

        C:\cleannavi.txt: trouvé !
        C:\TB.txt: trouvé !
        C:\UsbFix.txt: trouvé !
        C:\Toolbar SD: trouvé !
        C:\UsbFix: trouvé !
        C:\Rsit: trouvé !
        C:\Ad-remover: trouvé !
        C:\Ad-Remover\BACKUP\Ad-R.exe: trouvé !
        C:\Program Files\Navilog1: trouvé !
        C:\Program Files\Navilog1\Navilog1.bat: trouvé !
        C:\Program Files\trend micro\HijackThis.exe: trouvé !
        C:\Program Files\trend micro\hijackthis.log: trouvé !
        C:\Program Files\trend micro\HijackThis: trouvé !
        C:\Program Files\trend micro\HijackThis\HijackThis.exe: trouvé !
        C:\Program Files\trend micro\HijackThis\hijackthis.log: trouvé !
        C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HijackThis: trouvé !
        C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HijackThis\HijackThis.lnk: trouvé !
        C:\Users\Alizée\AppData\Local\Temp\389E.tmp\catchme.exe: trouvé !
        C:\Users\Alizée\AppData\Local\Temp\389E.tmp\mbr.exe: trouvé !
        C:\Users\Alizée\AppData\Local\Temp\BDE3.tmp\mbr.log: trouvé !

        ---------------------------------
        --> Suppression:

        C:\Ad-Remover\BACKUP\Ad-R.exe: supprimé !
        C:\Program Files\Navilog1\Navilog1.bat: supprimé !
        C:\Program Files\trend micro\HijackThis.exe: supprimé !
        C:\Program Files\trend micro\HijackThis\HijackThis.exe: supprimé !
        C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HijackThis\HijackThis.lnk: supprimé !
        C:\Users\Alizée\AppData\Local\Temp\389E.tmp\catchme.exe: supprimé !
        C:\cleannavi.txt: supprimé !
        C:\TB.txt: supprimé !
        C:\UsbFix.txt: supprimé !
        C:\Program Files\trend micro\hijackthis.log: supprimé !
        C:\Program Files\trend micro\HijackThis\hijackthis.log: supprimé !
        C:\Users\Alizée\AppData\Local\Temp\389E.tmp\mbr.exe: supprimé !
        C:\Users\Alizée\AppData\Local\Temp\BDE3.tmp\mbr.log: supprimé !
        C:\Toolbar SD: supprimé !
        C:\UsbFix: supprimé !
        C:\Rsit: supprimé !
        C:\Ad-remover: supprimé !
        C:\Program Files\Navilog1: supprimé !
        C:\Program Files\trend micro\HijackThis: supprimé !
        C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HijackThis: supprimé !

        Corbeille vidée!
        Fichiers temporaires nettoyés !
        0
      2. Pour internet explorer 8 il me dit quil est pas pris en charge sur ce systéme d'exploitation
        0
    5. Contributeur
      un grand merci à moment de grace il a fait un sacré travail.
      0
      1. Ah excuse j'avais pas vu le pseudo. Je pensais parler a moment de grace justement.
        0
    6. Contributeur sécurité
      NETTOYAGE

      Mettre à jour VISTA
      https://www.01net.com/telecharger/windows/Utilitaire/dll_librairies/fiches/46736.html

      Et internet explorer
      https://support.microsoft.com/fr-fr/allproducts

      .....................

      IMPORTANT

      Purger la restauration systeme vista
      https://www.commentcamarche.net/faq/13214-vista-desactiver-reactiver-la-restauration-systeme-de-vista

      ......................
      Télécharge ToolsCleaner2sur ton Bureau.
      https://www.commentcamarche.net/telecharger/securite/22061-toolscleaner/

      * Double-clique (clic droit "en tant qu'administrateur" pour Vista) sur ToolsCleaner2.exe pour le lancer.
      * Clique sur Recherche et laisse le scan agir.
      * Clique sur Suppression pour finaliser.
      * Tu peux, si tu le souhaites, te servir des Options Facultatives.
      * Clique sur Quitter pour obtenir le rapport.
      * Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\).

      Tu peux supprimer ToolCleaner ensuite

      0
      1. Contributeur
        c'est tout bon, ton pc est guéri ?
        0
        1. Oui, ça a l'air. Il rame plus. Les pubs ont disparues.

          Alors je te remercie énormément pour tout. Tu ma bien rendu service.
          Merci beaucoup.

          Bonne soirée et bonne continuation.
          0
      2. Contributeur sécurité
        ok j'ai peut etre trouvé ce qui te fait de la pub (en tout cas c'est néfaste)

        supprimes manuellement Winamp Toolbar

        C:\Program Files\Winamp Toolbar
        0
        1. C'est supprimer. Merci de ton aide pour tout. C'est trés gentil
          0
      3. Contributeur sécurité
        relances hijackthis

        Au menu principal, choisir do a scan only, puis cocher la case devant les lignes suivantes à corriger et cliquer en bas sur Fix Checked

        O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
        O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
        O8 - Extra context menu item: &Winamp Search - C:\ProgramData\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
        O9 - Extra button: (no name) - cmdmapping - (no file) (HKCU)
        O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
        O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
        O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe


        0
        1. Ok c'est fait.
          0
      4. Contributeur sécurité
        ok

        je suppose que tu as toujours ces pubs ?

        télécharges Hijackthis
        https://www.commentcamarche.net/telecharger/securite/11747-hijackthis/
        Lancer HijackThis en double-cliquant sur l'icône du logiciel
        Au menu principal, cliquer sur Do a system Scan only and Save a Logfile
        Un rapport sera alors généré dans un fichier bloc-notes, il sera situé dans le dossier désinfection initialement créé pour l'installation.
        Postes le ici

        0
        1. Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 20:50:29, on 19/01/2010
          Platform: Windows Vista SP1 (WinNT 6.00.1905)
          MSIE: Internet Explorer v7.00 (7.00.6001.18349)
          Boot mode: Normal

          Running processes:
          C:\Windows\system32\taskeng.exe
          C:\Windows\system32\Dwm.exe
          C:\Windows\Explorer.EXE
          C:\Program Files\ASUS\ASUS Live Update\ALU.exe
          C:\Program Files\ASUS\SmartLogon\sensorsrv.exe
          C:\Windows\system32\conime.exe
          C:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\AsGHost.exe
          C:\Program Files\Windows Defender\MSASCui.exe
          C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe
          C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
          C:\Program Files\ASUS\ATK Hotkey\HControlUser.exe
          C:\Program Files\ASUS\ATKOSD2\ATKOSD2.exe
          C:\Windows\System32\rundll32.exe
          C:\Windows\RtHDVCpl.exe
          C:\Program Files\ASUS\ATK Media\DMedia.exe
          C:\Windows\AsScrPro.exe
          C:\Program Files\Alwil Software\Avast4\ashDisp.exe
          C:\Program Files\Java\jre6\bin\jusched.exe
          C:\Program Files\Winamp\winampa.exe
          C:\Program Files\iTunes\iTunesHelper.exe
          C:\Program Files\Windows Sidebar\sidebar.exe
          C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
          C:\Windows\ehome\ehtray.exe
          C:\Program Files\Windows Live\Messenger\msnmsgr.exe
          C:\Program Files\Ares\Ares.exe
          C:\Program Files\Windows Media Player\wmpnscfg.exe
          C:\Windows\ehome\ehmsas.exe
          C:\Program Files\Mozilla Firefox\firefox.exe
          C:\Windows\system32\wuauclt.exe
          C:\Program Files\Windows Live\Contacts\wlcomm.exe
          C:\Windows\system32\rundll32.exe
          C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://go.microsoft.com/fwlink/?linkid=54896
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer
          R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
          R3 - URLSearchHook: Winamp Search Class - {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Program Files\Winamp Toolbar\winamptb.dll
          O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
          O2 - BHO: Windows Live Family Safety Browser Helper - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll
          O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
          O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
          O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
          O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
          O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
          O2 - BHO: ASUS Security Protect Manager - {DF21F1DB-80C6-11D3-9483-B03D0EC10000} - C:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\ItIEAddIn.dll
          O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
          O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
          O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
          O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
          O4 - HKLM\..\Run: [CLMLServer] "C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe"
          O4 - HKLM\..\Run: [P2Go_Menu] "C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
          O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
          O4 - HKLM\..\Run: [HControlUser] C:\Program Files\ASUS\ATK Hotkey\HControlUser.exe
          O4 - HKLM\..\Run: [ATKOSD2] C:\Program Files\ASUS\ATKOSD2\ATKOSD2.exe
          O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
          O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
          O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
          O4 - HKLM\..\Run: [CognizanceTS] rundll32.exe C:\PROGRA~1\ASUSSE~1\ASUSSE~1\Bin\ASTSVCC.dll,RegisterModule
          O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files\ASUS\ATK Media\DMedia.exe
          O4 - HKLM\..\Run: [ASUS Screen Saver Protector] C:\Windows\AsScrPro.exe
          O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
          O4 - HKLM\..\Run: [fssui] "C:\Program Files\Windows Live\Family Safety\fsui.exe" -autorun
          O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
          O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
          O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
          O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
          O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
          O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
          O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
          O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
          O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
          O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
          O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
          O8 - Extra context menu item: &Winamp Search - C:\ProgramData\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
          O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
          O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
          O9 - Extra button: ASUS Security Protect Manager e-Wallet - {1009C944-97D5-44A9-9E32-DFF54F498968} - C:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\ASWallet.dll
          O9 - Extra 'Tools' menuitem: ASUS Security Protect Manager e-&Wallet - {1009C944-97D5-44A9-9E32-DFF54F498968} - C:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\ASWallet.dll
          O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
          O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
          O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
          O9 - Extra button: (no name) - cmdmapping - (no file) (HKCU)
          O13 - Gopher Prefix:
          O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL APSHook.dll
          O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
          O23 - Service: ASLDR Service (ASLDRService) - Unknown owner - C:\Program Files\ASUS\ATK Hotkey\ASLDRSrv.exe
          O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
          O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - Unknown owner - C:\Program Files\ATKGFNEX\GFNEXSrv.exe
          O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
          O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
          O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
          O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
          O23 - Service: Google Desktop Manager 5.8.809.23506 (GoogleDesktopManager-092308-165331) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
          O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
          O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
          O23 - Service: Norton Internet Security - Unknown owner - C:\Program Files\Norton Internet Security\Engine\16.0.0.125\ccSvcHst.exe (file missing)
          O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
          O23 - Service: spmgr - Unknown owner - C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
          0
      5. Contributeur sécurité
        poste de travail
        C
        program file
        un dossier nommé trend micro
        un fichier nommé Alizée.exe
        0
        1. J'ai beau chercher dans tout les sens, je trouve pas ces fichiers.
          0
      6. Contributeur sécurité
        oui tu peux vider avast

        de plus

        Cherches et cliques sur C:\Program Files\trend micro\Alizée.exe
        Au menu principal, choisir do a scan only, puis cocher la case devant les lignes suivantes à corriger et cliquer en bas sur Fix Checked

        O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
        O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe
        O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
        O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
        O8 - Extra context menu item: &Winamp Search - C:\ProgramData\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
        O9 - Extra button: (no name) - cmdmapping - (no file) (HKCU)
        O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL APSHook.dll
        O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe


        ...............

        as tu fais le scan en ligne

        et je suppose que tu as toujours ces pubs
        0
        1. Je ne trouve pas C:\Program Files\trend micro\Alizée.exe
          0
      7. Contributeur sécurité
        même operation avec

        C:\Users\Alizée\AppData\Roaming\VitySoft

        de plus

        Téléchargez USBFIX de El Desaparecido, C_xx

        http://pagesperso-orange.fr/NosTools/Chiquitine29/UsbFix.exe
        ou
        https://www.ionos.fr/?affiliate_id=77097

        /!\ Utilisateur de vista et windows 7 :
        ne pas oublier de désactiver Le contrôle des comptes utilisateurs
        https://www.commentcamarche.net/faq/8343-vista-desactiver-l-uac

        /!\ Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptible d'avoir été infectées sans les ouvrir

        • Double clic sur le raccourci UsbFix présent sur le bureau .

        • Choisir l'option2 suppression
        (d’autres options disponibles, voir le tutoriel).
        • Laissez travailler l'outil.
        Le menu démarrer et les icônes vont disparaître.. c'est normal.

        Si un message te demande de redémarrer l'ordinateur fais le ...

        ● Au redémarrage, le fix se relance... laisses l'opération s'effectuer.

        ● Le bloc note s'ouvre avec un rapport, envoies le dans la prochaine réponse

        • Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque. ( C:\UsbFix.txt )

        ( CTRL+A Pour tout sélectionner , CTRL+C pour copier et CTRL+V pour coller )

        • Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
        Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
        Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.

        • Tuto : http://pagesperso-orange.fr/NosTools/usbfix.html

        UsbFix peut te demander d'uploader un dossier compressé à cette adresse : https://www.ionos.fr/?affiliate_id=77097

        Il est enregistré sur ton bureau.

        Merci de l'envoyer à l'adresse indiquée afin d'aider l'auteur de UsbFix dans ses recherches.

        Merci

        0
        1. ############################## | UsbFix V6.075 |

          User : Alizée (Administrateurs) # PC-DE-ALIZÉE
          Update on 19/01/2010 by El Desaparecido , C_XX & Chimay8
          Start at: 16:51:29 | 19/01/2010
          Website : http://pagesperso-orange.fr/NosTools/index.html
          Contact : FindyKill.Contact@gmail.com

          Pentium(R) Dual-Core CPU T4200 @ 2.00GHz
          Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6001 32-bit) # Service Pack 1
          Internet Explorer 7.0.6001.18000
          Windows Firewall Status : Enabled

          C:\ -> Disque fixe local # 116,44 Go (57,24 Go free) [VistaOS] # NTFS
          D:\ -> Disque fixe local # 104,73 Go (104,5 Go free) [DATA] # NTFS
          E:\ -> Disque CD-ROM
          H:\ -> Disque amovible # 3,72 Go (3,72 Go free) [USB2] # FAT32

          ############################## | Processus actifs |

          C:\Windows\System32\smss.exe 568
          C:\Windows\system32\csrss.exe 640
          C:\Windows\system32\wininit.exe 692
          C:\Windows\system32\csrss.exe 704
          C:\Windows\system32\services.exe 744
          C:\Windows\system32\lsass.exe 756
          C:\Windows\system32\lsm.exe 768
          C:\Windows\system32\svchost.exe 912
          C:\Windows\System32\svchost.exe 972
          C:\Windows\system32\nvvsvc.exe 1008
          C:\Windows\system32\svchost.exe 1040
          C:\Windows\System32\svchost.exe 1080
          C:\Windows\System32\svchost.exe 1132
          C:\Windows\System32\svchost.exe 1164
          C:\Windows\system32\svchost.exe 1180
          C:\Windows\system32\svchost.exe 1288
          C:\Windows\system32\SLsvc.exe 1308
          C:\Windows\system32\svchost.exe 1352
          C:\Windows\system32\winlogon.exe 1448
          C:\Windows\system32\svchost.exe 1532
          C:\Program Files\ASUS\ATK Hotkey\ASLDRSrv.exe 1664
          C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe 1688
          C:\Program Files\ATKGFNEX\GFNEXSrv.exe 1712
          C:\Program Files\Alwil Software\Avast4\ashServ.exe 1736
          C:\Windows\system32\WLANExt.exe 1744
          C:\Windows\system32\LogonUI.exe 1868
          C:\Windows\system32\rundll32.exe 1960
          C:\Program Files\ASUS\SmartLogon\smartlogon.exe 1988
          C:\Windows\system32\taskeng.exe 1300
          C:\Windows\System32\spoolsv.exe 1416
          C:\Windows\system32\svchost.exe 1724
          C:\Windows\System32\lpksetup.exe 2060
          C:\Windows\system32\userinit.exe 2520
          C:\Windows\system32\taskeng.exe 2536
          C:\Windows\system32\Dwm.exe 2564
          C:\Windows\Explorer.EXE 2632
          C:\Program Files\ASUS\ASUS Live Update\ALU.exe 2644
          C:\Program Files\ASUS\SmartLogon\sensorsrv.exe 2656
          C:\Windows\system32\runonce.exe 2696
          C:\Windows\system32\conime.exe 2832
          C:\Program Files\ASUS\ATK Hotkey\MsgTranAgt.exe 3260
          C:\Program Files\ASUS\ATK Hotkey\HControl.exe 3268
          C:\Program Files\Wireless Console 2\wcourier.exe 3284
          C:\Program Files\ASUS\ASUS CopyProtect\aspg.exe 3292
          C:\Program Files\P4G\BatteryLife.exe 3300
          C:\Program Files\ASUS\Splendid\ACMON.exe 3308
          C:\Windows\System32\ACEngSvr.exe 3384
          C:\Program Files\ASUS\ATK Hotkey\ATKOSD.exe 3440
          C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe 3460
          C:\Program Files\ASUS\ATK Hotkey\KBFiltr.exe 3500
          C:\Program Files\Bonjour\mDNSResponder.exe 3496
          C:\Program Files\ASUS\ATK Hotkey\WDC.exe 3520
          C:\Program Files\Common Files\LightScribe\LSSrvc.exe 3568
          C:\Windows\system32\svchost.exe 3640
          C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe 3668
          C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe 3756
          C:\Windows\system32\svchost.exe 3812
          C:\Windows\System32\svchost.exe 3876
          C:\Windows\system32\SearchIndexer.exe 3952
          C:\Windows\system32\WUDFHost.exe 2244
          C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe 2292
          C:\Program Files\Alwil Software\Avast4\ashWebSv.exe 516
          C:\Windows\servicing\TrustedInstaller.exe 2548
          C:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\AsGHost.exe 2980
          C:\Windows\system32\wbem\wmiprvse.exe 1368
          C:\Windows\system32\wbem\wmiprvse.exe 740

          ################## | Elements infectieux |

          Supprimé ! C:\$Recycle.Bin\S-1-5-21-1257243831-2304017613-39374301-1000
          Supprimé ! D:\$Recycle.Bin\S-1-5-21-1257243831-2304017613-39374301-1000

          ################## | Registre |

          ################## | Mountpoints2 |

          ################## | Listing des fichiers présent |

          [17/01/2010 19:39|--a------|80454] C:\Ad-Report-CLEAN[1].log
          [06/10/2008 04:46|--a------|21] C:\app3.LOG
          [18/01/2010 22:04|--a------|4] C:\autoexec.bat
          [21/01/2008 03:24|-rahs----|333203] C:\bootmgr
          [16/04/2008 12:27|-ra-s----|8192] C:\BOOTSECT.BAK
          [04/04/2007 20:01|--a------|19] C:\CA21.txt
          [17/01/2010 19:22|--a------|1400] C:\cleannavi.txt
          [18/09/2006 22:43|--a------|10] C:\config.sys
          [17/12/2009 16:29|--a------|0] C:\conmgr.log
          [17/03/2009 09:19|--a------|19440] C:\devlist.txt
          [17/03/2009 09:19|--a------|9] C:\Finish.log
          [?|?|?] C:\hiberfil.sys
          [17/03/2009 08:13|--a------|481] C:\igoogle_log.txt
          [17/03/2009 08:30|--a------|18808832] C:\inject.log
          [17/03/2009 08:30|--a------|16145830] C:\inject.log.txt
          [18/01/2010 22:04|--a------|5075] C:\Kill'em.txt
          [18/01/2010 21:28|--a------|18280] C:\List'em.txt
          [11/08/2008 14:50|-rah-----|1048576] C:\M50V.BIN
          [16/09/2008 07:48|--a------|14] C:\M50VN_M50VM_M50VC_VISTA.30
          [08/08/2008 08:22|--a------|30] C:\NERO.LOG
          [07/01/2009 10:16|--a------|30] C:\NIS2009.TXT
          [16/03/2007 00:18|--a------|25] C:\OFFICE2007_A.TXT
          [?|?|?] C:\pagefile.sys
          [16/03/2009 20:23|--a------|105] C:\Pass.txt
          [21/01/2009 06:49|--a------|3116] C:\Patch.LOG
          [29/04/2008 15:30|--a------|20] C:\READER_A.TXT
          [16/09/2008 07:48|--a------|21] C:\RECOVERY.DAT
          [17/03/2009 08:44|--a------|560] C:\RHDSetup.log
          [17/03/2009 09:09|--a------|159] C:\setup.log
          [16/05/2006 01:22|--a------|5] C:\store.log
          [17/03/2009 07:44|--a------|166] C:\SumHidd.txt
          [17/03/2009 07:43|--a------|98] C:\SumOS.txt
          [17/01/2010 19:00|--a------|2057] C:\TB.txt
          [19/01/2010 16:54|--a------|5685] C:\UsbFix.txt
          [12/02/2009 19:24|--a------|25] C:\V554.txt

          ################## | Vaccination |

          # C:\autorun.inf -> Dossier créé par UsbFix.
          # D:\autorun.inf -> Dossier créé par UsbFix.

          ################## | Upload |

          Veuillez envoyer le fichier : C:\Users\ALIZE~1\Desktop\UsbFix_Upload_Me_PC-de-Aliz‚e.zip : https://www.ionos.fr/?affiliate_id=77097
          Merci pour votre contribution .

          ################## | ! Fin du rapport # UsbFix V6.075 ! |
          0
        2. J'ai poster le rapport UsbFix.
          Petite question : Dans ma quarantaine Avast, il y a toujours mon system 32 qui est infecté. Est ce que je dois le supprimer ou ça me planterai mon PC ? On m'a dit que c'étais ce qui faisait fonctionner internet et tout. Donc je n'ose pas y toucher. Qu'en pense tu toi ?
          0
      8. Contributeur sécurité
        non

        je cherche l'origine de tes pubs

        Rends toi sur ce site :

        https://www.virustotal.com/gui/

        Clique sur parcourir et cherche ce fichier : C:\Windows\AsScrPro.exe

        Clique sur Send File.

        Un rapport va s'élaborer ligne à ligne.

        Attends la fin. Il doit comprendre la taille du fichier envoyé.

        Sauvegarde le rapport avec le bloc-note.

        Copie le dans ta réponse.

        Si tu ne trouves pas le fichier alors

        Affiche tous les fichiers et dossiers :

        Pour cela :
        Clique sur démarrer/panneau de configuration/option des dossiers/affichage

        Cocher afficher les dossiers cachés

        Décoche la case "Masquer les fichiers protégés du système d'exploitation (recommandé)"

        Décocher masquer les extensions dont le type est connu

        Puis fais «appliquer» pour valider les changements.

        Et OK
        0
        1. Excuse moi mais je ne comprend pas ce que je dois coller dans ma réponse .. ?
          0
        2. @Lilou22http://www.virustotal.com/fr/analisis/fbfcb69f66c54a82ef29ae2f376eed58bccb095b089efd8420032449fe3b41af-1258793845

          Voila ce que le rapport donne
          0
        3. Je vais au lit, demain je me léve tot.
          J'espére que tu seras la demain, pour finir tout ça.

          En tout cas je te remercie encore pour ton aide.
          Bonne soirée.
          0
      9. Contributeur sécurité
        en suivant le chemin

        poste de travail
        C
        Program Files
        Media Access Startup

        pareil pour l'autre
        0
        1. Non, ils ne sont plus la. Bonne nouvelle ?
          0
      10. Contributeur sécurité
        ▶ Relance List&Kill'em avec le raccourci sur ton bureau ,

        mais cette fois-ci :

        ▶ choisis l'option 2 = Mode Suppression

        laisse travailler l'outil.

        en fin de scan un rapport s'ouvre

        ▶ colle le contenu dans ta reponse

        ...........

        as tu encore ceci dans ton pc

        "C:\Program Files\Media Access Startup
        C:\Program Files\System Search Dispatcher
        0
        1. Kill'em by g3n-h@ckm@n 1.1.8.4

          User : Alizée (Administrateurs)
          Update on 17/01/2010 by g3n-h@ckm@n ::::: 00:10
          Start at: 22:01:00 | 18/01/2010
          Contact : g3n-h@ckm@n sur CCM

          Pentium(R) Dual-Core CPU T4200 @ 2.00GHz
          Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6001 32-bit) # Service Pack 1
          Internet Explorer 7.0.6001.18000
          Windows Firewall Status : Disabled

          C:\ -> Disque fixe local | 116,44 Go (57,42 Go free) [VistaOS] | NTFS
          D:\ -> Disque fixe local | 104,73 Go (104,5 Go free) [DATA] | NTFS
          E:\ -> Disque CD-ROM

          ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running

          C:\Windows\System32\smss.exe
          C:\Windows\system32\csrss.exe
          C:\Windows\system32\wininit.exe
          C:\Windows\system32\csrss.exe
          C:\Windows\system32\services.exe
          C:\Windows\system32\lsass.exe
          C:\Windows\system32\lsm.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\System32\svchost.exe
          C:\Windows\system32\nvvsvc.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\System32\svchost.exe
          C:\Windows\System32\svchost.exe
          C:\Windows\System32\svchost.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\system32\SLsvc.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\system32\winlogon.exe
          C:\Windows\system32\svchost.exe
          C:\Program Files\ASUS\ATK Hotkey\ASLDRSrv.exe
          C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
          C:\Windows\system32\WLANExt.exe
          C:\Program Files\ATKGFNEX\GFNEXSrv.exe
          C:\Program Files\Alwil Software\Avast4\ashServ.exe
          C:\Windows\system32\rundll32.exe
          C:\Program Files\ASUS\SmartLogon\smartlogon.exe
          C:\Windows\System32\spoolsv.exe
          C:\Windows\system32\taskeng.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\system32\Dwm.exe
          C:\Windows\system32\taskeng.exe
          C:\Windows\Explorer.EXE
          C:\Program Files\ASUS\ASUS Live Update\ALU.exe
          C:\Program Files\ASUS\SmartLogon\sensorsrv.exe
          C:\Program Files\Windows Defender\MSASCui.exe
          C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe
          C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
          C:\Program Files\ASUS\ATK Hotkey\MsgTranAgt.exe
          C:\Program Files\ASUS\ATK Hotkey\HControl.exe
          C:\Program Files\Wireless Console 2\wcourier.exe
          C:\Program Files\ASUS\ASUS CopyProtect\aspg.exe
          C:\Program Files\P4G\BatteryLife.exe
          C:\Program Files\ASUS\ATK Hotkey\HControlUser.exe
          C:\Program Files\ASUS\Splendid\ACMON.exe
          C:\Program Files\ASUS\ATKOSD2\ATKOSD2.exe
          C:\Windows\System32\ACEngSvr.exe
          C:\Windows\System32\rundll32.exe
          C:\Windows\RtHDVCpl.exe
          C:\Program Files\ASUS\ATK Media\DMedia.exe
          C:\Windows\AsScrPro.exe
          C:\Program Files\Alwil Software\Avast4\ashDisp.exe
          C:\Program Files\Java\jre6\bin\jusched.exe
          C:\Program Files\Winamp\winampa.exe
          C:\Program Files\iTunes\iTunesHelper.exe
          C:\Program Files\Windows Sidebar\sidebar.exe
          C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
          C:\Windows\ehome\ehtray.exe
          C:\Program Files\ASUS\ATK Hotkey\ATKOSD.exe
          C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
          C:\Program Files\Bonjour\mDNSResponder.exe
          C:\Program Files\Common Files\LightScribe\LSSrvc.exe
          C:\Windows\system32\svchost.exe
          C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
          C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\System32\svchost.exe
          C:\Windows\system32\SearchIndexer.exe
          C:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\AsGHost.exe
          C:\Program Files\Ares\Ares.exe
          C:\Windows\ehome\ehmsas.exe
          C:\Program Files\Windows Media Player\wmpnscfg.exe
          C:\Program Files\iPod\bin\iPodService.exe
          C:\Program Files\ASUS\ATK Hotkey\KBFiltr.exe
          C:\Program Files\Windows Media Player\wmpnetwk.exe
          C:\Program Files\ASUS\ATK Hotkey\WDC.exe
          C:\Windows\system32\rundll32.exe
          C:\Windows\system32\wuauclt.exe
          C:\Windows\system32\conime.exe
          \\?\C:\Windows\system32\wbem\WMIADAP.EXE
          C:\Windows\system32\wbem\wmiprvse.exe
          C:\Windows\system32\SearchProtocolHost.exe
          C:\Windows\system32\SearchFilterHost.exe
          C:\Program Files\List_Kill'em\List_Kill'em.exe
          C:\Windows\system32\cmd.exe
          C:\Windows\system32\wbem\wmiprvse.exe
          C:\Users\Alizée\AppData\Local\Temp\429F.tmp\pv.exe

          Detections :
          ==========

          ¤¤¤¤¤¤¤¤¤¤ Files/folders :

          Quarantined & Deleted !! : C:\Windows\system32\MSWINSCK.OCX

          ==============
          host file OK !
          ==============

          ========
          Registry
          ========
          Deleted : HKCR\CLSID\{248dd896-bb45-11cf-9abc-0080c7e7b78d}
          Deleted : HKCR\CLSID\{248dd897-bb45-11cf-9abc-0080c7e7b78d}
          Deleted : HKCR\Interface\{248dd892-bb45-11cf-9abc-0080c7e7b78d}
          Deleted : HKCR\Interface\{248dd893-bb45-11cf-9abc-0080c7e7b78d}
          Deleted : HKCR\Interface\{4897bba6-48d9-468c-8efa-846275d7701b}
          Deleted : HKCR\TypeLib\{248dd890-bb45-11cf-9abc-0080c7e7b78d}
          Deleted : HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{83ff80f4-8c74-4b80-b5ba-c8ddd434e5c4}

          ============
          Disk Cleaned
          ============

          ================
          Prefetch cleaned
          ================

          ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
          0
        2. C:\Program Files\Media Access Startup
          C:\Program Files\System Search Dispatcher

          Comment je fais pour savoir si j'ai toujours ces deux fichiers ?
          0
      11. List'em by g3n-h@ckm@n 1.1.8.4

        thx to CCM team.....
        User : Alizée (Administrateurs)
        Update on 17/01/2010 by g3n-h@ckm@n ::::: 00:10
        Start at: 20:05:37 | 18/01/2010
        Contact : g3n-h@ckm@n sur CCM

        Pentium(R) Dual-Core CPU T4200 @ 2.00GHz
        Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6001 32-bit) # Service Pack 1
        Internet Explorer 7.0.6001.18000
        Windows Firewall Status : Disabled

        C:\ -> Disque fixe local | 116,44 Go (57,39 Go free) [VistaOS] | NTFS
        D:\ -> Disque fixe local | 104,73 Go (104,5 Go free) [DATA] | NTFS
        E:\ -> Disque CD-ROM

        ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running

        C:\Windows\System32\smss.exe
        C:\Windows\system32\csrss.exe
        C:\Windows\system32\wininit.exe
        C:\Windows\system32\csrss.exe
        C:\Windows\system32\services.exe
        C:\Windows\system32\lsass.exe
        C:\Windows\system32\lsm.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\System32\svchost.exe
        C:\Windows\system32\nvvsvc.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\System32\svchost.exe
        C:\Windows\System32\svchost.exe
        C:\Windows\System32\svchost.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\system32\SLsvc.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\system32\winlogon.exe
        C:\Windows\system32\svchost.exe
        C:\Program Files\ASUS\ATK Hotkey\ASLDRSrv.exe
        C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        C:\Windows\system32\WLANExt.exe
        C:\Program Files\ATKGFNEX\GFNEXSrv.exe
        C:\Program Files\Alwil Software\Avast4\ashServ.exe
        C:\Windows\system32\rundll32.exe
        C:\Program Files\ASUS\SmartLogon\smartlogon.exe
        C:\Windows\System32\spoolsv.exe
        C:\Windows\system32\taskeng.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\system32\Dwm.exe
        C:\Windows\system32\taskeng.exe
        C:\Windows\Explorer.EXE
        C:\Program Files\ASUS\ASUS Live Update\ALU.exe
        C:\Program Files\ASUS\SmartLogon\sensorsrv.exe
        C:\Program Files\Windows Defender\MSASCui.exe
        C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe
        C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
        C:\Program Files\ASUS\ATK Hotkey\MsgTranAgt.exe
        C:\Program Files\ASUS\ATK Hotkey\HControl.exe
        C:\Program Files\Wireless Console 2\wcourier.exe
        C:\Program Files\ASUS\ASUS CopyProtect\aspg.exe
        C:\Program Files\P4G\BatteryLife.exe
        C:\Program Files\ASUS\ATK Hotkey\HControlUser.exe
        C:\Program Files\ASUS\Splendid\ACMON.exe
        C:\Program Files\ASUS\ATKOSD2\ATKOSD2.exe
        C:\Windows\System32\ACEngSvr.exe
        C:\Windows\System32\rundll32.exe
        C:\Windows\RtHDVCpl.exe
        C:\Program Files\ASUS\ATK Media\DMedia.exe
        C:\Windows\AsScrPro.exe
        C:\Program Files\Alwil Software\Avast4\ashDisp.exe
        C:\Program Files\Java\jre6\bin\jusched.exe
        C:\Program Files\Winamp\winampa.exe
        C:\Program Files\iTunes\iTunesHelper.exe
        C:\Program Files\Windows Sidebar\sidebar.exe
        C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
        C:\Windows\ehome\ehtray.exe
        C:\Program Files\ASUS\ATK Hotkey\ATKOSD.exe
        C:\Program Files\Windows Live\Messenger\msnmsgr.exe
        C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
        C:\Program Files\Bonjour\mDNSResponder.exe
        C:\Program Files\Common Files\LightScribe\LSSrvc.exe
        C:\Windows\system32\svchost.exe
        C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
        C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\System32\svchost.exe
        C:\Windows\system32\SearchIndexer.exe
        C:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\AsGHost.exe
        C:\Program Files\Ares\Ares.exe
        C:\Windows\ehome\ehmsas.exe
        C:\Program Files\Windows Media Player\wmpnscfg.exe
        C:\Program Files\iPod\bin\iPodService.exe
        C:\Program Files\ASUS\ATK Hotkey\KBFiltr.exe
        C:\Program Files\Windows Media Player\wmpnetwk.exe
        C:\Program Files\ASUS\ATK Hotkey\WDC.exe
        C:\Program Files\Windows Live\Contacts\wlcomm.exe
        C:\Program Files\Mozilla Firefox\firefox.exe
        C:\Windows\system32\rundll32.exe
        C:\Windows\system32\wuauclt.exe
        C:\Windows\system32\conime.exe
        C:\Windows\system32\SearchProtocolHost.exe
        C:\Windows\system32\SearchFilterHost.exe
        C:\Program Files\List_Kill'em\List_Kill'em.exe
        C:\Windows\system32\cmd.exe
        C:\Windows\system32\wbem\wmiprvse.exe
        C:\Users\Alizée\AppData\Local\Temp\BDE3.tmp\pv.exe

        ======================
        Keys "Run"
        ======================
        [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
        Sidebar REG_SZ C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
        LightScribe Control Panel REG_SZ C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
        ehTray.exe REG_SZ C:\Windows\ehome\ehTray.exe
        swg REG_SZ C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
        msnmsgr REG_SZ "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
        ares REG_SZ "C:\Program Files\Ares\Ares.exe" -h
        WMPNSCFG REG_SZ C:\Program Files\Windows Media Player\WMPNSCFG.exe

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
        Windows Defender REG_EXPAND_SZ %ProgramFiles%\Windows Defender\MSASCui.exe -hide
        CLMLServer REG_SZ "C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe"
        P2Go_Menu REG_SZ "C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
        Google Desktop Search REG_SZ "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
        HControlUser REG_SZ C:\Program Files\ASUS\ATK Hotkey\HControlUser.exe
        ATKOSD2 REG_SZ C:\Program Files\ASUS\ATKOSD2\ATKOSD2.exe
        NvCplDaemon REG_SZ RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
        NvMediaCenter REG_SZ RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
        RtHDVCpl REG_SZ RtHDVCpl.exe
        CognizanceTS REG_SZ rundll32.exe C:\PROGRA~1\ASUSSE~1\ASUSSE~1\Bin\ASTSVCC.dll,RegisterModule
        ATKMEDIA REG_SZ C:\Program Files\ASUS\ATK Media\DMedia.exe
        ASUS Screen Saver Protector REG_SZ C:\Windows\AsScrPro.exe
        Adobe Reader Speed Launcher REG_SZ "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
        fssui REG_SZ "C:\Program Files\Windows Live\Family Safety\fsui.exe" -autorun
        avast! REG_SZ C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
        SunJavaUpdateSched REG_SZ "C:\Program Files\Java\jre6\bin\jusched.exe"
        WinampAgent REG_SZ "C:\Program Files\Winamp\winampa.exe"
        QuickTime Task REG_SZ "C:\Program Files\QuickTime\QTTask.exe" -atboottime
        iTunesHelper REG_SZ "C:\Program Files\iTunes\iTunesHelper.exe"

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]

        =====================
        Other Keys
        =====================
        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
        ConsentPromptBehaviorAdmin REG_DWORD 2 (0x2)
        ConsentPromptBehaviorUser REG_DWORD 1 (0x1)
        EnableInstallerDetection REG_DWORD 1 (0x1)
        EnableLUA REG_DWORD 0 (0x0)
        EnableSecureUIAPaths REG_DWORD 1 (0x1)
        EnableVirtualization REG_DWORD 1 (0x1)
        PromptOnSecureDesktop REG_DWORD 1 (0x1)
        ValidateAdminCodeSignatures REG_DWORD 0 (0x0)
        dontdisplaylastusername REG_DWORD 0 (0x0)
        legalnoticecaption REG_SZ
        legalnoticetext REG_SZ
        scforceoption REG_DWORD 0 (0x0)
        shutdownwithoutlogon REG_DWORD 1 (0x1)
        undockwithoutlogon REG_DWORD 1 (0x1)
        FilterAdministratorToken REG_DWORD 1 (0x1)
        EnableUIADesktopToggle REG_DWORD 0 (0x0)

        ===============
        [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]

        ===============
        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]

        ===============
        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
        AppInit_DLLS REG_SZ C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL APSHook.dll

        ===============

        ===============
        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]

        ===============
        [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

        [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

        ===============
        ActivX controls
        ===============
        HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{5D6F45B3-9043-443D-A792-115447494D24}
        HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{8100D56A-5661-482C-BEE8-AFECE305D968}
        HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{8AD9C840-044E-11D1-B3E9-00805F499D93}
        HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{C3F79A2B-B9B4-4A66-B012-3EE46475B072}
        HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
        HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}

        ===============
        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}
        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{26923b43-4d38-484f-9b9e-de460746276c}
        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}
        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{08B0E5C0-4FCB-11CF-AAA5-00401C608500}
        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}
        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2179C5D3-EBFF-11CF-B6FD-00AA00B4E220}
        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}
        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}
        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{3af36230-a269-11d1-b5bf-0000f8051515}
        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}
        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA848-CC51-11CF-AAFA-00AA00B6015C}
        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA855-CC51-11CF-AAFA-00AA00B6015F}
        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{45ea75a0-a269-11d1-b5bf-0000f8051515}
        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4f645220-306d-11d2-995d-00c04f98bbc9}
        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5fd399c0-a70a-11d1-9948-00c04f98bbc9}
        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{630b1da0-b465-11d1-9948-00c04f98bbc9}
        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}
        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6fab99d0-bab8-11d1-994a-00c04f98bbc9}
        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{73FA19D0-2D75-11D2-995D-00C04F98BBC9}
        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7790769C-0471-11d2-AF11-00C04FA35D02}
        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7C028AF8-F614-47B3-82DA-BA94E41B1089}
        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4340}
        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4383}
        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}
        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9381D8F2-0288-11D0-9501-00AA00B911A5}
        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C6BAF60B-6E91-453F-BFF9-D3789CFEFCDD}
        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C9E9A340-D1F1-11D0-821E-444553540600}
        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CDD7975E-60F8-41d5-8149-19E51D6F71D0}
        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{de5aed00-a4bf-11d1-9948-00c04f98bbc9}
        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{E92B03AB-B707-11d2-9CBD-0000F87A369E}

        ==============
        BHO :
        ======
        [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{25CEE8EC-5730-41bc-8B58-22DDC8AB8C20}]
        [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{4f3ed5cd-0726-42a9-87f5-d13f3d2976ac}]
        [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
        [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
        [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
        [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
        [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{C84D72FE-E17D-4195-BB24-76C02E2E7C4E}]
        [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
        [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{DF21F1DB-80C6-11D3-9483-B03D0EC10000}]
        [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10}]

        ================
        Internet Explorer :
        ================
        [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
        Start Page REG_SZ https://www.msn.com/fr-fr

        [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
        Start Page REG_SZ https://www.msn.com/fr-fr

        ========
        Services
        ========
        [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services]

        Ndisuio : 0x3
        EapHost : 0x3
        Wlansvc : 0x2
        SharedAccess : 0x4
        windefend : 0x2
        wuauserv : 0x2
        wscsvc : 0x2

        =========

        =======
        Drive :
        =======

        D‚fragmenteur de disque Windows
        Copyright (c) 2006 Microsoft Corp.

        Rapport d'analyse pour le volume C: VistaOS

        Taille du volume = 116 Go
        Espace libre = 57.40 Go
        tendue d'espace libre la plus grande = 35.32 Go
        Pourcentage de fragmentation des fichiers = 1 %

        Remarqueÿ: sur les volumes NTFS, les fragments de fichiers de plus de 64ÿMo ne sont pas inclus dans les statistiques de fragmentation.

        Il n'est pas n‚cessaire de d‚fragmenter ce volume.

        ¤¤¤¤¤¤¤¤¤¤ Files/folders :

        C:\Windows\system32\MSWINSCK.OCX

        ¤¤¤¤¤¤¤¤¤¤ Keys :

        HKCR\CLSID\{248dd896-bb45-11cf-9abc-0080c7e7b78d}
        HKCR\CLSID\{248dd897-bb45-11cf-9abc-0080c7e7b78d}
        HKCR\Interface\{248dd892-bb45-11cf-9abc-0080c7e7b78d}
        HKCR\Interface\{248dd893-bb45-11cf-9abc-0080c7e7b78d}
        HKCR\Interface\{4897bba6-48d9-468c-8efa-846275d7701b}
        HKCR\TypeLib\{248dd890-bb45-11cf-9abc-0080c7e7b78d}
        HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{83ff80f4-8c74-4b80-b5ba-c8ddd434e5c4}

        ================
        Other infections
        ================

        catchme 0.3.1398.3 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
        Rootkit scan 2010-01-18 20:10:34
        Windows 6.0.6001 Service Pack 1 NTFS

        scanning hidden processes ...

        scanning hidden services & system hive ...

        scanning hidden registry entries ...

        scanning hidden files ...

        scan completed successfully
        hidden processes: 0
        hidden services: 0
        hidden files: 0

        Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

        device: opened successfully
        user: MBR read successfully
        kernel: MBR read successfully
        user & kernel MBR OK

        ==========
        Programs
        ==========

        Adobe
        Alwil Software
        Apple Software Update
        Ares
        ASUS
        ASUS Security Center
        Atheros
        ATKGFNEX
        Audacity 1.3 Beta (Unicode)
        Bonjour
        CCleaner
        Cisco
        Common Files
        CyberLink
        desktop.ini
        devolo
        DialFlirt
        Dolby
        Downloaded Installations
        Fingerprint Sensor
        Google
        InstallShield Installation Information
        Intel
        Internet Explorer
        iPod
        iTunes
        Java
        List_Kill'em
        Malwarebytes' Anti-Malware
        Messenger Plus! Live
        Microsoft
        Microsoft Games
        Microsoft Office
        Microsoft Office Outlook Connector
        Microsoft Silverlight
        Microsoft SQL Server Compact Edition
        Microsoft Sync Framework
        Microsoft Works
        Microsoft.NET
        Movie Maker
        Mozilla Firefox
        MSBuild
        MSXML 4.0
        Navilog1
        Open office
        OpenOffice.org 3.zip
        P4G
        Picasa2
        QuickTime
        Realtek
        Reference Assemblies
        trend micro
        Uninstall Information
        Utilitaire de configuration iPhone
        VideoLAN
        Winamp
        Winamp Toolbar
        Windows Calendar
        Windows Collaboration
        Windows Defender
        Windows Journal
        Windows Live
        Windows Live SkyDrive
        Windows Mail
        Windows Media Player
        Windows NT
        Windows Photo Gallery
        Windows Sidebar
        WinRAR
        Wireless Console 2

        ============
        Lecteur C:
        ============

        $RECYCLE.BIN
        Ad-Remover
        Ad-Report-CLEAN[1].log
        app3.LOG
        ASUS.SYS
        autoexec.bat
        Boot
        bootmgr
        BOOTSECT.BAK
        CA21.txt
        cleannavi.txt
        config.sys
        conmgr.log
        devlist.txt
        Documents and Settings
        Finish.log
        hiberfil.sys
        igoogle_log.txt
        inject.log
        inject.log.txt
        Kill'em
        List'em.txt
        M50V.BIN
        M50VN_M50VM_M50VC_VISTA.30
        NERO.LOG
        NIS2009.TXT
        OFFICE2007_A.TXT
        pagefile.sys
        Pass.txt
        Patch.LOG
        Program Files
        ProgramData
        READER_A.TXT
        RECOVERY.DAT
        RHDSetup.log
        rsit
        setup.log
        store.log
        SumHidd.txt
        SumOS.txt
        System Volume Information
        TB.txt
        ToolBar SD
        Users
        V554.txt
        Windows

        ¤¤¤¤¤¤¤¤¤¤ Cracks | Keygens | Serials

        C:\Patch.LOG
        C:\Program Files\Google\Google Earth Pro\Crack.exe

        ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
        0
        1. Contributeur sécurité
          ok

          apparement navilog en a oublié en route...

          Desactive ton antivirus le temps de la manip ainsi que ton parefeu si présent(car il est detecté a tort comme infection)

          ▶ Télécharge et installe List&Kill'em et enregistre le sur ton bureau
          http://sd-1.archive-host.com/membres/up/829108531491024/List_Killem_Install.exe

          double clique ( clic droit "executer en tant qu'administrateur" pour Vista/7 ) sur le raccourci sur ton bureau pour lancer l'installation

          coche la case "creer une icone sur le bureau"

          une fois terminée , clic sur "terminer" et le programme se lancer seul

          choisis la langue puis choisis l'option 1 = Mode Recherche

          ▶ laisse travailler l'outil

          à l'apparition de la fenetre blanche , c'est un peu long , c'est normal , le programme n'est pas bloqué.

          un rapport du nom de catchme apparait sur ton bureau , ignore-le,ne le poste pas , mais ne le supprime pas pour l instant, le scan n'est pas fini.

          ▶ Poste le contenu du rapport qui s'ouvre aux 100 % du scan à l'ecran "COMPLETED"

          tu peux supprimer le rapport catchme.log de ton bureau maintenant.
          0
          1. Quand l'écran blanc affiche "Tests infections .... Patience ....." (90%)
            Je dois le fermer ou j'attend ?
            0
        • 1
        • 2
        • 3
        • 4