Trojan Alemod

Résolu
Salut à tous

Voilà j'ai un souci avec un virus (Trojan Alemod). Que mon antivirus Norton à détecté. Et je sais sur quel fichier il s'est mis (Pas moyen de le supprimer).

Norton me propose de faire la manip suivante : https://www.broadcom.com/support/security-center Mais le 4ème point je ne suis pas sûr de réussir à le faire est ce vraiment nécessaire ?

Ou y a t'il un autre moyen plus simple de m'en débarrasser ?

Merci d'avance.
Configuration: Windows Vista
Firefox 3.5.4

53 réponses

Résumé de la discussion

La discussion porte sur un ordinateur infecté par un Trojan Alemod détecté par Norton, et sur les manipulations proposées pour éliminer le malware sur Windows Vista. Plusieurs réponses préconisent des outils de nettoyage et des vérifications complémentaires tels que Spybot S&D pour désactiver TeaTimer, puis UsbFix et Malwarebytes pour analyser et supprimer les malwares. Des conseils techniques supplémentaires évoquent la désactivation de l'UAC sur Vista/7, l'utilisation de Toolbar-S&D, l'exécution de rapports et la sauvegarde du registre avant toute modification. D'autres interventions suggèrent d'adopter un antivirus plus performant que Norton et d'éventuellement passer par des outils comme Ad Remover ou des solutions de nettoyage complémentaires pour éviter les récidives.

Bobot (l’IA à votre service)
  1. Voila analyse terminée est tout est nickel !!!

    Merciiiii beaucoup à toi moment de grace :)
    0
    1. Contributeur sécurité
      ok

      j'attends ton retour
      0
      1. Voila le rapport

        [ Rapport ToolsCleaner version 2.3.11 (par A.Rothstein & dj QUIOU) ]

        --> Recherche:

        C:\UsbFix.txt: trouvé !
        C:\UsbFix: trouvé !
        C:\Rsit: trouvé !
        C:\Ad-remover: trouvé !
        C:\Ad-Remover\BACKUP\Ad-R.exe: trouvé !
        C:\Program Files\Hijackthis Version Française\hijackthis.log: trouvé !
        C:\Program Files\trend micro\HijackThis.exe: trouvé !
        C:\Program Files\trend micro\hijackthis.log: trouvé !
        C:\Users\Bénédicte\AppData\Local\Temp\22DD.tmp\catchme.exe: trouvé !
        C:\Users\Bénédicte\AppData\Local\Temp\22DD.tmp\mbr.log: trouvé !
        C:\Users\Bénédicte\AppData\Local\Temp\22DD.tmp\mbr.exe: trouvé !
        C:\Users\Bénédicte\AppData\Roaming\Microsoft\Windows\Recent\UsbFix.lnk: trouvé !
        C:\Users\Bénédicte\Desktop\Ad-R.exe: trouvé !
        C:\Users\Bénédicte\Desktop\UsbFix.exe: trouvé !
        C:\Users\Bénédicte\Desktop\Rsit.exe: trouvé !

        ---------------------------------
        --> Suppression:

        C:\Ad-Remover\BACKUP\Ad-R.exe: supprimé !
        C:\Program Files\trend micro\HijackThis.exe: supprimé !
        C:\Users\Bénédicte\AppData\Local\Temp\22DD.tmp\catchme.exe: supprimé !
        C:\Users\Bénédicte\Desktop\Ad-R.exe: supprimé !
        C:\UsbFix.txt: supprimé !
        C:\Program Files\Hijackthis Version Française\hijackthis.log: supprimé !
        C:\Program Files\trend micro\hijackthis.log: supprimé !
        C:\Users\Bénédicte\AppData\Local\Temp\22DD.tmp\mbr.log: supprimé !
        C:\Users\Bénédicte\AppData\Local\Temp\22DD.tmp\mbr.exe: supprimé !
        C:\Users\Bénédicte\AppData\Roaming\Microsoft\Windows\Recent\UsbFix.lnk: supprimé !
        C:\Users\Bénédicte\Desktop\UsbFix.exe: supprimé !
        C:\Users\Bénédicte\Desktop\Rsit.exe: supprimé !
        C:\UsbFix: supprimé !
        C:\Rsit: supprimé !
        C:\Ad-remover: supprimé !

        Un grand MERCI à toi pour ton aide :) ;)

        Je vais lancer une analyse avec mon antivirus et je te tiens au courant ;)
        0
        1. Cool super. Merci.

          Je commence le nettoyage ;)
          0
          1. Contributeur sécurité
            Le pc me va bien maintenant

            On nettoie

            1)
            Cherches et cliques sur C:\Program Files\trend micro\Bénédicte.exe
            Au menu principal, choisir do a scan only, puis cocher la case devant les lignes suivantes à corriger et cliquer en bas sur Fix Checked (s’il manque des lignes…pas grave)

            R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
            O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
            O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll (file missing)
            O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
            O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
            O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
            O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
            O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe


            ……………………..

            2)
            Mets à jour Adobe Reader si ce n'est pas le cas (désinstalle avant la version antérieure)
            https://get2.adobe.com/reader/otherversions/

            3)
            IMPORTANT

            Purger la restauration systeme vista
            https://www.commentcamarche.net/faq/13214-vista-desactiver-reactiver-la-restauration-systeme-de-vista

            ……………..

            4)
            Télécharge ToolsCleaner2sur ton Bureau.
            https://www.commentcamarche.net/telecharger/securite/22061-toolscleaner/

            * Double-clique (clic droit "en tant qu'administrateur" pour Vista) sur ToolsCleaner2.exe pour le lancer.
            * Clique sur Recherche et laisse le scan agir.
            * Clique sur Suppression pour finaliser.
            * Tu peux, si tu le souhaites, te servir des Options Facultatives.
            * Clique sur Quitter pour obtenir le rapport.
            * Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\).

            Tu peux supprimer ToolCleaner ensuite
            0
            1. Tu voulais dire c:\Kill'em.txt Je pense ;)

              voilà :

              Kill'em by g3n-h@ckm@n 1.2.1.2

              User : Bénédicte (Administrateurs)
              Update on 29/01/2010 by g3n-h@ckm@n ::::: 11:50
              Start at: 13:07:51 | 31/01/2010
              Contact : g3n-h@ckm@n sur CCM

              Genuine Intel(R) CPU 2140 @ 1.60GHz
              Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6002 32-bit) # Service Pack 2
              Internet Explorer 8.0.6001.18882
              Windows Firewall Status : Disabled
              AV : Norton Internet Security 15.5.0.23 [ (!) Disabled | Updated ]
              FW : Norton Internet Security[ (!) Disabled ]15.5.0.23

              C:\ -> Disque fixe local | 224,88 Go (59,31 Go free) [HDD] | NTFS
              D:\ -> Disque CD-ROM
              E:\ -> Disque fixe local | 596,17 Go (65,62 Go free) [My Book] | NTFS
              H:\ -> Disque CD-ROM

              ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running

              C:\Windows\System32\smss.exe
              C:\Windows\system32\csrss.exe
              C:\Windows\system32\wininit.exe
              C:\Windows\system32\csrss.exe
              C:\Windows\system32\services.exe
              C:\Windows\system32\lsass.exe
              C:\Windows\system32\lsm.exe
              C:\Windows\system32\winlogon.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\system32\nvvsvc.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\System32\svchost.exe
              C:\Windows\System32\svchost.exe
              C:\Windows\System32\svchost.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\system32\SLsvc.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\system32\nvvsvc.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\System32\spoolsv.exe
              C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
              C:\Windows\system32\svchost.exe
              C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
              C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
              C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
              C:\Program Files\CyberLink\Shared Files\RichVideo.exe
              C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
              C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
              C:\Windows\system32\svchost.exe
              C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
              C:\Windows\System32\svchost.exe
              C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
              C:\Windows\system32\SearchIndexer.exe
              C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
              C:\Windows\system32\Dwm.exe
              C:\Windows\Explorer.EXE
              C:\Windows\RtHDVCpl.exe
              C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
              C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
              C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
              C:\Program Files\CyberLink\PCM4Everio\EverioService.exe
              C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe
              C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
              C:\Program Files\Java\jre6\bin\jusched.exe
              C:\Program Files\Windows Sidebar\sidebar.exe
              C:\Windows\ehome\ehtray.exe
              C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe
              C:\Program Files\Eraser\Eraser.exe
              C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
              C:\Windows\ehome\ehmsas.exe
              C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
              C:\Program Files\Windows Sidebar\sidebar.exe
              C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
              C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
              C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
              C:\Windows\system32\svchost.exe
              C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
              C:\Windows\system32\taskeng.exe
              C:\Program Files\Windows Live\Photo Gallery\WLXPhotoGallery.exe
              C:\Program Files\List_Kill'em\List_Kill'em.scr
              C:\Windows\system32\cmd.exe
              C:\Windows\system32\SearchProtocolHost.exe
              C:\Windows\system32\SearchFilterHost.exe
              C:\Windows\system32\wbem\wmiprvse.exe
              C:\Users\Bénédicte\AppData\Local\Temp\8604.tmp\ERUNT.EXE
              C:\Users\Bénédicte\AppData\Local\Temp\8604.tmp\pv.exe

              Detections :
              ==========

              ¤¤¤¤¤¤¤¤¤¤ Files/folders :

              Quarantined & Deleted !! : C:\ProgramData\.zreglib
              Quarantined & Deleted !! : C:\Program Files\DAEMON Tools Toolbar
              Quarantined & Deleted !! : C:\Windows\Installer\{E1B94435-241E-4519-B1C3-C4DD9EB352A2}

              Quarantined & Deleted !! : C:\Windows\system32\XInput9_1_0.dll
              Quarantined & Deleted !! : C:\Windows\System32\drivers\lvuvc.hs
              Quarantined & Deleted !! : C:\Users\B‚n‚dicte\Local Settings\Temp\alm.log
              Quarantined & Deleted !! : C:\Users\B‚n‚dicte\Local Settings\Temp\amt.log
              Quarantined & Deleted !! : C:\Users\B‚n‚dicte\LOCAL Settings\Temp\tmp673E.tmp

              ==============
              host file OK !
              ==============

              ========
              Registry
              ========
              Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{BC4FFE41-DE9F-46FA-B455-AAD49B9F9938}
              0
              1. Contributeur sécurité
                regardes si le rapport killem est ici

                C:\List'em.txt --

                Je cherche beaucoup...et maintenant je trouve ! 
                (sourire)
                0
                1. Voilà le rapport :

                  Logfile of random's system information tool 1.06 (written by random/random)
                  Run by Bénédicte at 2010-01-31 13:56:06
                  Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 2
                  System drive C: has 61 GB (26%) free of 230 GB
                  Total RAM: 2046 MB (48% free)

                  Logfile of Trend Micro HijackThis v2.0.2
                  Scan saved at 13:56:26, on 31/01/2010
                  Platform: Windows Vista SP2 (WinNT 6.00.1906)
                  MSIE: Internet Explorer v8.00 (8.00.6001.18882)
                  Boot mode: Normal

                  Running processes:
                  C:\Windows\system32\Dwm.exe
                  C:\Windows\Explorer.EXE
                  C:\Windows\RtHDVCpl.exe
                  C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
                  C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                  C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                  C:\Program Files\CyberLink\PCM4Everio\EverioService.exe
                  C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe
                  C:\Program Files\Java\jre6\bin\jusched.exe
                  C:\Program Files\Windows Sidebar\sidebar.exe
                  C:\Windows\ehome\ehtray.exe
                  C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe
                  C:\Program Files\Eraser\Eraser.exe
                  C:\Windows\ehome\ehmsas.exe
                  C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
                  C:\Program Files\Windows Sidebar\sidebar.exe
                  C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
                  C:\Users\Bénédicte\Desktop\RSIT.exe
                  C:\Program Files\trend micro\Bénédicte.exe

                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://go.microsoft.com/fwlink/?linkid=54896
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                  R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.fr/0SEFRFR/SAOS01?FORM=TOOLBR
                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                  O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
                  O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                  O2 - BHO: Windows Live Family Safety Browser Helper - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll
                  O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
                  O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.5\coIEPlg.dll
                  O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
                  O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
                  O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                  O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
                  O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll
                  O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Google\Google_BAE\BAE.dll
                  O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                  O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                  O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
                  O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.5\CoIEPlg.dll
                  O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                  O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll (file missing)
                  O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
                  O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                  O4 - HKLM\..\Run: [toolbar_eula_launcher] C:\Program Files\Packard Bell\GOOGLE_EULA\EULALauncher.exe
                  O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                  O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
                  O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
                  O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
                  O4 - HKLM\..\Run: [fssui] "C:\Program Files\Windows Live\Family Safety\fsui.exe" -autorun
                  O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
                  O4 - HKLM\..\Run: [EverioService] "C:\Program Files\CyberLink\PCM4Everio\EverioService.exe"
                  O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe" /hide
                  O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                  O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
                  O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                  O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
                  O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
                  O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                  O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                  O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe"
                  O4 - HKCU\..\Run: [Eraser] C:\Program Files\Eraser\Eraser.exe -hide
                  O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                  O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                  O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                  O4 - Startup: GigaTribe.lnk = C:\Program Files\GigaTribe\gigatribe.exe
                  O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
                  O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
                  O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
                  O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
                  O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
                  O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                  O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                  O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
                  O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
                  O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
                  O10 - Broken Internet access because of LSP provider 'c:\program files\bonjour\mdnsnsp.dll' missing
                  O13 - Gopher Prefix:
                  O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://download.divx.com/player/DivXBrowserPlugin.cab
                  O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
                  O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
                  O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
                  O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
                  O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
                  O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                  O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                  O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                  O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
                  O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
                  O23 - Service: Google Desktop Manager 5.9.911.3589 (GoogleDesktopManager-110309-193829) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                  O23 - Service: Service Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
                  O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                  O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                  O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
                  O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                  O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
                  O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
                  O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
                  O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
                  O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
                  O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                  O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
                  O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
                  O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
                  O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
                  O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
                  O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
                  O23 - Service: TomTomHOMEService - TomTom - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
                  O23 - Service: SAMSUNG WiselinkPro Service (WiselinkPro) - Unknown owner - C:\Program Files\Samsung\SAMSUNG PC Share Manager\WiselinkPro.exe
                  0
                  1. Voilà c'est fait, mais je n'ai pas eu de rapport.
                    0
                    1. Contributeur sécurité
                      ▶ Relance List&Kill'em avec le raccourci sur ton bureau ,

                      mais cette fois-ci :

                      ▶ choisis l'option 2 = Mode Suppression

                      laisse travailler l'outil.

                      en fin de scan un rapport s'ouvre

                      ▶ colle le contenu dans ta reponse

                      Tu peux le désinstaller ensuite

                      ..................

                      ensuite

                      Relances RSIT et postes le rappport log
                      0
                      1. Bonjour moment de Grace

                        Voilà le rapport :

                        List'em by g3n-h@ckm@n 1.2.1.2
                        User : Bénédicte (Administrateurs)
                        Update on 29/01/2010 by g3n-h@ckm@n ::::: 11:50
                        Start at: 11:23:44 | 31/01/2010
                        Contact : g3n-h@ckm@n sur CCM

                        Genuine Intel(R) CPU 2140 @ 1.60GHz
                        Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6002 32-bit) # Service Pack 2
                        Internet Explorer 8.0.6001.18882
                        Windows Firewall Status : Disabled
                        AV : Norton Internet Security 15.5.0.23 [ (!) Disabled | Updated ]
                        FW : Norton Internet Security[ (!) Disabled ]15.5.0.23

                        C:\ -> Disque fixe local | 224,88 Go (59,32 Go free) [HDD] | NTFS
                        D:\ -> Disque CD-ROM
                        E:\ -> Disque fixe local | 596,17 Go (65,62 Go free) [My Book] | NTFS
                        H:\ -> Disque CD-ROM

                        ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running

                        C:\Windows\System32\smss.exe
                        C:\Windows\system32\csrss.exe
                        C:\Windows\system32\wininit.exe
                        C:\Windows\system32\csrss.exe
                        C:\Windows\system32\services.exe
                        C:\Windows\system32\lsass.exe
                        C:\Windows\system32\lsm.exe
                        C:\Windows\system32\winlogon.exe
                        C:\Windows\system32\svchost.exe
                        C:\Windows\system32\nvvsvc.exe
                        C:\Windows\system32\svchost.exe
                        C:\Windows\System32\svchost.exe
                        C:\Windows\System32\svchost.exe
                        C:\Windows\System32\svchost.exe
                        C:\Windows\system32\svchost.exe
                        C:\Windows\system32\svchost.exe
                        C:\Windows\system32\SLsvc.exe
                        C:\Windows\system32\svchost.exe
                        C:\Windows\system32\nvvsvc.exe
                        C:\Windows\system32\svchost.exe
                        C:\Windows\System32\spoolsv.exe
                        C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                        C:\Windows\system32\svchost.exe
                        C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
                        C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
                        C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
                        C:\Program Files\CyberLink\Shared Files\RichVideo.exe
                        C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
                        C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                        C:\Windows\system32\svchost.exe
                        C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
                        C:\Windows\System32\svchost.exe
                        C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
                        C:\Windows\system32\SearchIndexer.exe
                        C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
                        C:\Windows\system32\Dwm.exe
                        C:\Windows\Explorer.EXE
                        C:\Windows\RtHDVCpl.exe
                        C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
                        C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                        C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                        C:\Program Files\CyberLink\PCM4Everio\EverioService.exe
                        C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe
                        C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
                        C:\Program Files\Java\jre6\bin\jusched.exe
                        C:\Program Files\Windows Sidebar\sidebar.exe
                        C:\Windows\ehome\ehtray.exe
                        C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe
                        C:\Program Files\Eraser\Eraser.exe
                        C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
                        C:\Windows\ehome\ehmsas.exe
                        C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
                        C:\Program Files\Windows Sidebar\sidebar.exe
                        C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
                        C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
                        C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
                        C:\Windows\system32\svchost.exe
                        C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
                        C:\Windows\system32\taskeng.exe
                        C:\Program Files\Windows Live\Photo Gallery\WLXPhotoGallery.exe
                        C:\Windows\system32\SearchProtocolHost.exe
                        C:\Windows\system32\SearchFilterHost.exe
                        C:\Program Files\List_Kill'em\List_Kill'em.scr
                        C:\Windows\system32\cmd.exe
                        C:\Windows\system32\wbem\wmiprvse.exe
                        C:\Users\Bénédicte\AppData\Local\Temp\22DD.tmp\pv.exe

                        ======================
                        Keys "Run"
                        ======================
                        [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                        swg REG_SZ "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
                        Sidebar REG_SZ C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                        ehTray.exe REG_SZ C:\Windows\ehome\ehTray.exe
                        TomTomHOME.exe REG_SZ "C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe"
                        Eraser REG_SZ C:\Program Files\Eraser\Eraser.exe -hide
                        HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run\AdobeUpdater

                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                        <NO NAME> REG_SZ
                        Windows Defender REG_SZ %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                        toolbar_eula_launcher REG_SZ C:\Program Files\Packard Bell\GOOGLE_EULA\EULALauncher.exe
                        RtHDVCpl REG_SZ RtHDVCpl.exe
                        RoxWatchTray REG_SZ "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
                        NBKeyScan REG_SZ "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
                        Google Desktop Search REG_SZ "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
                        fssui REG_SZ "C:\Program Files\Windows Live\Family Safety\fsui.exe" -autorun
                        ccApp REG_SZ "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
                        EverioService REG_SZ "C:\Program Files\CyberLink\PCM4Everio\EverioService.exe"
                        LogitechQuickCamRibbon REG_SZ "C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe" /hide
                        SunJavaUpdateSched REG_SZ "C:\Program Files\Java\jre6\bin\jusched.exe"
                        NeroFilterCheck REG_SZ C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
                        Adobe Reader Speed Launcher REG_SZ "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                        Adobe ARM REG_SZ "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

                        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]

                        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]

                        =====================
                        Other Keys
                        =====================
                        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
                        ConsentPromptBehaviorAdmin REG_DWORD 2 (0x2)
                        ConsentPromptBehaviorUser REG_DWORD 1 (0x1)
                        EnableInstallerDetection REG_DWORD 1 (0x1)
                        EnableLUA REG_DWORD 0 (0x0)
                        EnableSecureUIAPaths REG_DWORD 1 (0x1)
                        EnableVirtualization REG_DWORD 1 (0x1)
                        PromptOnSecureDesktop REG_DWORD 1 (0x1)
                        ValidateAdminCodeSignatures REG_DWORD 0 (0x0)
                        dontdisplaylastusername REG_DWORD 0 (0x0)
                        legalnoticecaption REG_SZ
                        legalnoticetext REG_SZ
                        scforceoption REG_DWORD 0 (0x0)
                        shutdownwithoutlogon REG_DWORD 1 (0x1)
                        undockwithoutlogon REG_DWORD 1 (0x1)
                        FilterAdministratorToken REG_DWORD 0 (0x0)
                        EnableUIADesktopToggle REG_DWORD 0 (0x0)

                        ===============
                        [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
                        NoLowDiskSpaceChecks REG_DWORD 1 (0x1)
                        NoDriveAutoRun REG_DWORD 128 (0x80)
                        NoDriveTypeAutoRun REG_DWORD 128 (0x80)
                        HonorAutoRunSetting REG_DWORD 0 (0x0)

                        ===============
                        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
                        BindDirectlyToPropertySetStorage REG_DWORD 0 (0x0)
                        NoDriveAutoRun REG_DWORD 128 (0x80)
                        NoDriveTypeAutoRun REG_DWORD 128 (0x80)
                        HonorAutoRunSetting REG_DWORD 0 (0x0)

                        ===============
                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
                        AppInit_DLLS REG_SZ C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL

                        ===============

                        ===============
                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]

                        ===============
                        [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

                        [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

                        ===============
                        ActivX controls
                        ===============
                        HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{67DABFBF-D0AB-41FA-9C46-CC0F21721616}
                        HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{8AD9C840-044E-11D1-B3E9-00805F499D93}
                        HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
                        HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
                        HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
                        HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
                        HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
                        HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}

                        ===============
                        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{1B320010-9D3D-429F-B71B-A4A30EA1E956}
                        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}
                        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{26923b43-4d38-484f-9b9e-de460746276c}
                        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}
                        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{E54A439F-A4B0-4526-A16B-B4E2ECE95B3D}
                        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{08B0E5C0-4FCB-11CF-AAA5-00401C608500}
                        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{166B1BCA-3F9C-11CF-8075-444553540000}
                        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2179C5D3-EBFF-11CF-B6FD-00AA00B4E220}
                        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}
                        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2318C2B1-4965-11d4-9B18-009027A5CD4F}
                        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{233C1507-6A77-46A4-9443-F871F945D258}
                        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2A202491-F00D-11cf-87CC-0020AFEECF20}
                        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}
                        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{3af36230-a269-11d1-b5bf-0000f8051515}
                        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{411EDCF7-755D-414E-A74B-3DCD6583F589}
                        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}
                        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA848-CC51-11CF-AAFA-00AA00B6015C}
                        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA855-CC51-11CF-AAFA-00AA00B6015F}
                        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{45ea75a0-a269-11d1-b5bf-0000f8051515}
                        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4f645220-306d-11d2-995d-00c04f98bbc9}
                        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{553C7FBC-16AB-3045-29D7-46428DC220C3}
                        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5fd399c0-a70a-11d1-9948-00c04f98bbc9}
                        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{630b1da0-b465-11d1-9948-00c04f98bbc9}
                        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}
                        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6fab99d0-bab8-11d1-994a-00c04f98bbc9}
                        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7790769C-0471-11d2-AF11-00C04FA35D02}
                        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7C028AF8-F614-47B3-82DA-BA94E41B1089}
                        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4340}
                        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4383}
                        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}
                        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8D8A528B-BA3D-A34E-EAC1-359648FDF864}
                        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9381D8F2-0288-11D0-9501-00AA00B911A5}
                        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C6BAF60B-6E91-453F-BFF9-D3789CFEFCDD}
                        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C9E9A340-D1F1-11D0-821E-444553540600}
                        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
                        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CDD7975E-60F8-41d5-8149-19E51D6F71D0}
                        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{D141DF32-1DD9-2118-1D40-922C86640E81}
                        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{D27CDB6E-AE6D-11CF-96B8-444553540000}
                        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{DAA94A2A-2A8D-4D3B-9DB8-56FBECED082D}
                        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{de5aed00-a4bf-11d1-9948-00c04f98bbc9}
                        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{E92B03AB-B707-11d2-9CBD-0000F87A369E}
                        HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{F4B2380F-9F83-482B-B51F-FD18C7EDD923}

                        ==============
                        BHO :
                        ======
                        [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]
                        [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
                        [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{4f3ed5cd-0726-42a9-87f5-d13f3d2976ac}]
                        [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{53707962-6F74-2D53-2644-206D7942484F}]
                        [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
                        [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
                        [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
                        [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
                        [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
                        [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
                        [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{CA6319C0-31B7-401E-A518-A07C3DB8F777}]
                        [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
                        [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10}]

                        ================
                        Internet Explorer :
                        ================
                        [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
                        Start Page REG_SZ https://www.msn.com/fr-fr

                        [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                        Start Page REG_SZ https://www.msn.com/fr-fr

                        ========
                        Services
                        ========
                        [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services]

                        Ndisuio : 0x3
                        EapHost : 0x3
                        Wlansvc : 0x3
                        SharedAccess : 0x2
                        windefend : 0x2
                        wuauserv : 0x2
                        wscsvc : 0x2

                        =========
                        Atapi.sys
                        =========

                        %%%% HASHDEEP-1.0
                        %%%% size,md5,sha256,filename
                        ## Invoked from: C:\Users\Bénédicte\AppData\Local\Temp\22DD.tmp
                        ## C:\> hashdeep C:\Windows\System32\Drivers\atapi.sys
                        ##
                        19944,1f05b78ab91c9075565a9d8a4b880bc4,737be9f9376dab0ccdfed93ea6d67f0c432367ea63cd772a453485be769af3bd,C:\Windows\System32\Drivers\atapi.sys

                        Sources
                        =======

                        C:\Windows\System32\drivers\atapi.sys
                        C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_7de13c21\atapi.sys
                        C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_b12d8e84\atapi.sys
                        C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys
                        C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_cc18792d\atapi.sys
                        C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.16632_none_db337a442479c42c\atapi.sys
                        C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.20757_none_dbac78a93da31a8b\atapi.sys
                        C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a2189ce9c\atapi.sys
                        C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_df23a1261eab99e8\atapi.sys

                        Référence :
                        ==========

                        Win XP_SP2_32b : CDFE4411A69C224BD1D11B2DA92DAC51
                        Win XP_SP3_32b : 9F3A2F5AA6875C72BF062C712CFA2674
                        Vista_SP1_32b : 2d9c903dc76a66813d350a562de40ed9
                        Vista_SP2_32b : 1F05B78AB91C9075565A9D8A4B880BC4
                        Vista_SP2_64b : 1898FAE8E07D97F2F6C2D5326C633FAC
                        Windows 7_32b : 80C40F7FDFC376E4C5FEEC28B41C119E
                        Windows 7_64b : 02062C0B390B7729EDC9E69C680A6F3C

                        =======
                        Drive :
                        =======

                        D‚fragmenteur de disque Windows
                        Copyright (c) 2006 Microsoft Corp.

                        Rapport d'analyse pour le volume C: HDD

                        Taille du volume = 225 Go
                        Espace libre = 59.33 Go
                        tendue d'espace libre la plus grande = 17.25 Go
                        Pourcentage de fragmentation des fichiers = 0 %

                        Remarqueÿ: sur les volumes NTFS, les fragments de fichiers de plus de 64ÿMo ne sont pas inclus dans les statistiques de fragmentation.

                        Il n'est pas n‚cessaire de d‚fragmenter ce volume.

                        ¤¤¤¤¤¤¤¤¤¤ Files/folders :

                        Present !! : C:\ProgramData\.zreglib
                        Present !! : C:\Program Files\DAEMON Tools Toolbar
                        Present !! : C:\Windows\Installer\{E1B94435-241E-4519-B1C3-C4DD9EB352A2}
                        Present !! : C:\Windows\system32\XInput9_1_0.dll
                        Present !! : C:\Windows\System32\drivers\lvuvc.hs
                        Present !! : C:\Users\B‚n‚dicte\Local Settings\Temp\alm.log
                        Present !! : C:\Users\B‚n‚dicte\Local Settings\Temp\amt.log
                        Present !! : C:\Users\B‚n‚dicte\LOCAL Settings\Temp\tmp673E.tmp

                        ¤¤¤¤¤¤¤¤¤¤ Keys :

                        Present !! : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{BC4FFE41-DE9F-46FA-B455-AAD49B9F9938}
                        Present !! : "HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}"
                        Present !! : "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}"
                        Present !! : HKCR\CLSID\{9afb8248-617f-460d-9366-d71cdeda3179}
                        Present !! : HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1A0AADCD-3A72-4B5F-900F-E3BB5A838E2A}
                        Present !! : HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{BC4FFE41-DE9F-46fa-B455-AAD49B9F9938}
                        Present !! : HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEE6C35B-6118-11DC-9C72-001320C79847}
                        Present !! : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEE6C35C-6118-11DC-9C72-001320C79847}
                        Present !! : HKCU\SOFTWARE\SWEETIE
                        Present !! : HKCU\Software\SweetIM
                        Present !! : HKLM\Software\Classes\CLSID\{9AFB8248-617F-460D-9366-D71CDEDA3179}
                        Present !! : HKLM\Software\Classes\Interface\{DB885111-F39F-4D88-9EE5-C88460B6DF7B}
                        Present !! : HKLM\software\Iminent
                        Present !! : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\980289C22F80A7C4BB9323DC61255E4E
                        Present !! : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\FA96423FE2B98E248A3B23548D1E22D9
                        Present !! : HKLM\SOFTWARE\SweetIM
                        Present !! : HKU\.DEFAULT\Software\AGI

                        ============

                        catchme 0.3.1398.3 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                        Rootkit scan 2010-01-31 11:35:22
                        Windows 6.0.6002 Service Pack 2 NTFS

                        scanning hidden processes ...

                        scanning hidden services & system hive ...

                        [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg]
                        "s1"=dword:2df9c43f
                        "s2"=dword:110480d0
                        "h0"=dword:00000001

                        [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
                        "p0"="C:\Program Files\DAEMON Tools Lite\"
                        "h0"=dword:00000000
                        "khjeh"=hex:a9,a5,64,be,57,9e,4f,2b,50,80,64,f0,3d,67,b0,a1,76,63,66,a2,d2,..

                        [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
                        "a0"=hex:20,01,00,00,66,a9,d3,ef,0f,8f,54,f2,9a,50,98,16,f6,f4,cf,3b,08,..
                        "khjeh"=hex:6d,bb,e0,0e,05,8f,6e,6c,7f,1e,b7,ad,38,d6,4f,e4,bd,2a,54,cd,6f,..

                        [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
                        "khjeh"=hex:4b,4a,b4,00,6e,ee,4e,2b,36,fe,57,70,52,79,31,8b,47,e3,8e,07,d4,..
                        [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
                        "p0"="C:\Program Files\DAEMON Tools Lite\"
                        "h0"=dword:00000000
                        "khjeh"=hex:a9,a5,64,be,57,9e,4f,2b,50,80,64,f0,3d,67,b0,a1,76,63,66,a2,d2,..

                        [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
                        "a0"=hex:20,01,00,00,66,a9,d3,ef,0f,8f,54,f2,9a,50,98,16,f6,f4,cf,3b,08,..
                        "khjeh"=hex:6d,bb,e0,0e,05,8f,6e,6c,7f,1e,b7,ad,38,d6,4f,e4,bd,2a,54,cd,6f,..

                        [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
                        "khjeh"=hex:4b,4a,b4,00,6e,ee,4e,2b,36,fe,57,70,52,79,31,8b,47,e3,8e,07,d4,..

                        scanning hidden registry entries ...

                        scanning hidden files ...

                        scan completed successfully
                        hidden processes: 0
                        hidden services: 0
                        hidden files: 0

                        Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

                        device: opened successfully
                        user: MBR read successfully
                        kernel: MBR read successfully
                        user & kernel MBR OK
                        ============
                        Drive C:
                        ============

                        $Recycle.Bin
                        Ad-Remover
                        Ad-Report-CLEAN[1].log
                        Ad-Report-CLEAN[2].log
                        ArcSoft
                        autoexec.bat
                        autorun.inf
                        boot
                        bootmgr
                        config.sys
                        Documents and Settings
                        drivers
                        DVDFabPlatinum_Temp
                        DVDimport0.jpg
                        DVDimport1.jpg
                        error.log
                        EuropeSoftwares
                        hansel
                        IO.SYS
                        Kill'em
                        List'em.txt
                        moby
                        MSDOS.SYS
                        MSOCache
                        NVIDIA
                        pagefile.sys
                        PerfLogs
                        Philips
                        Program Files
                        ProgramData
                        rsit
                        System Volume Information
                        temp
                        UsbFix
                        UsbFix.txt
                        Users
                        WAUUPGRD
                        Windows

                        ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
                        0
                        1. Ok merci, je ferais tout ça demain.

                          Bonne nuit à toi.

                          @+++
                          0
                          1. Contributeur sécurité
                            tu as bien fait...

                            cette toolbar nous résiste

                            Desactive ton antivirus le temps de la manip ainsi que ton parefeu si présent(car il est detecté a tort comme infection)

                            ▶ Télécharge et installe List&Kill'em et enregistre le sur ton bureau
                            http://sd-1.archive-host.com/membres/up/829108531491024/List_Killem_Install.exe

                            double clique ( clic droit "executer en tant qu'administrateur" pour Vista/7 ) sur le raccourci sur ton bureau pour lancer l'installation

                            coche la case "creer une icone sur le bureau"

                            une fois terminée , clic sur "terminer" et le programme se lancer seul

                            choisis la langue puis choisis l'option 1 = Mode Recherche

                            ▶ laisse travailler l'outil

                            à l'apparition de la fenetre blanche , c'est un peu long , c'est normal , le programme n'est pas bloqué.

                            un rapport du nom de catchme apparait sur ton bureau , ignore-le,ne le poste pas , mais ne le supprime pas pour l instant, le scan n'est pas fini.

                            ▶ Poste le contenu du rapport qui s'ouvre aux 100 % du scan à l'ecran "COMPLETED"

                            tu peux supprimer le rapport catchme.log de ton bureau maintenant.

                            0
                            1. J'ai tenté de lancer Ad Remover et après 2h00 rien ne bougé ça restais à 4%. Je sais pas si j'ai bien fait mais j'ai tout arrêté.
                              0
                              1. Contributeur sécurité
                                je te remets la procedure

                                Note importante :
                                Pour les ordinateurs équipés de Windows Vista et Windows 7, la désactivation du Contrôle des comptes utilisateurs est obligatoire
                                sous peine de ne pas pouvoir faire fonctionner correctement l'outil.
                                Tuto : https://www.commentcamarche.net/faq/8343-vista-desactiver-l-uac

                                Téléchargez et enregistrez le fichier d installation sur le bureau
                                http://pagesperso-orange.fr/NosTools/C_XX/AD-R.exe

                                Double cliquez sur le fichier d'installation de AD-Remover, le programme s'installera automatiquement.
                                Sous Vista : clic droit sur AD-Remover et sélectionner "Exécuter en tant qu'administrateur"
                                Au menu principal choisir Option L Lancer le nettoyage
                                et tapez sur [entrée] .
                                Laissez travailler l'outil et ne touchez à rien ...
                                Postez le rapport qui apparait à la fin.

                                ( le rapport est sauvegardé aussi sous C:\Ad-report.log )

                                (CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

                                Note :Process.exe est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
                                Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
                                Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.

                                0
                                1. dsl de t'embêter mais je le trouve ou ?
                                  0
                                  1. Contributeur sécurité
                                    fais Ad Remover alors
                                    0
                                    • 1
                                    • 2
                                    • 3