Centre de sécurité

Bonjour,

Donc un jours j'ai eu un prorat ( trojan ) et je l'ais supprimé ave avast bien sur mais depuis se jours le centre de sécurité et désactiver et je ne peut pas le réactiver sa me met un message d'erreur ::

Impossible de démarrer le service du centre de sécurité !

Merci de m'aider , je suis sous Vista !
Configuration: Windows Vista / Safari 532.5

20 réponses

  1. Contributeur sécurité
    il reste quelque cochonneries

    Désactiver le TeaTimer de Spybot (Merci à Nico et nathandre):
    Pour désactiver le TeaTimer :
    => Ouvrir Spybot S&D
    => Dans le menu "Mode", séléctionner le mode avancé.
    => Une fenêtre demande confirmation cliquer sur "oui".
    => Une fois le mode avancé actif, ouvrir l'onglet "Outils".
    => Cliquer sur Résident.
    => La partie Résident comporte deux lignes qui sont normalement cochées :
    *Résident "SDHelper" (bloqueur de téléchargements nuisibles pour Internet Explorer) actif.
    * Résident "TeaTimer" (Protection des réglages système fondamentaux) actif
    => Décocher la ligne TeaTimer.
    => Redémarrer Spybot (le fermer et le réouvrir)
    => Retourner dans le menu Résident et vérifier qu'il soit bien désactivé

    Spybot va géner les outils

    .........................

    redemarres en mode sans echec

    https://www.micro-astuce.com/depannage/demarrer-mode-sans-echec.php

    et relances Ad Remover
    option L lancer le nettoyage
    poster le rapport
    0
    1. Logfile of random's system information tool 1.06 (written by random/random)
      Run by Fabien at 2010-02-28 03:28:36
      Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 2
      System drive C: has 95 GB (42%) free of 226 GB
      Total RAM: 3071 MB (49% free)

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 03:28:40, on 28/02/2010
      Platform: Windows Vista SP2 (WinNT 6.00.1906)
      MSIE: Internet Explorer v8.00 (8.00.6001.18882)
      Boot mode: Normal

      Running processes:
      C:\Windows\system32\taskeng.exe
      C:\Windows\system32\Dwm.exe
      C:\Windows\Explorer.EXE
      C:\Windows\System32\mobsync.exe
      C:\Program Files\Windows Defender\MSASCui.exe
      C:\Windows\RtHDVCpl.exe
      C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
      C:\Windows\System32\rundll32.exe
      C:\Program Files\Java\jre6\bin\jusched.exe
      C:\Program Files\Alwil Software\Avast4\ashDisp.exe
      C:\Windows\FixCamera.exe
      C:\Program Files\Windows Media Player\wmpnscfg.exe
      C:\Windows\vsnp325.exe
      C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe
      C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
      C:\Windows\ehome\ehtray.exe
      C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
      C:\Program Files\Free Music Zilla\FMZilla.exe
      C:\Windows\ehome\ehmsas.exe
      C:\Users\Fabien\AppData\Local\Google\Update\1.2.183.17\GoogleCrashHandler.exe
      C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
      C:\Program Files\MessengerDiscovery 2\MessengerDiscovery 2.exe
      C:\Windows\system32\conime.exe
      C:\Program Files\Java\jre6\bin\jucheck.exe
      C:\Program Files\Windows Live\Contacts\wlcomm.exe
      C:\Users\Fabien\AppData\Local\Google\Chrome\Application\chrome.exe
      C:\Users\Fabien\AppData\Local\Google\Chrome\Application\chrome.exe
      C:\Windows\system32\SearchFilterHost.exe
      C:\Users\Fabien\AppData\Local\Google\Chrome\Application\chrome.exe
      C:\Users\Fabien\Desktop\RSIT.exe
      C:\Program Files\trend micro\Fabien.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://go.microsoft.com/fwlink/?linkid=54896
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
      R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/ymj/*https://fr.yahoo.com/?p=us
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
      O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
      O2 - BHO: Windows Live Family Safety Browser Helper - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll
      O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll
      O2 - BHO: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
      O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
      O2 - BHO: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - (no file)
      O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
      O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
      O4 - HKLM\..\Run: [fssui] "C:\Program Files\Windows Live\Family Safety\fsui.exe" -autorun
      O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      O4 - HKLM\..\Run: [FixCamera] C:\Windows\FixCamera.exe
      O4 - HKLM\..\Run: [tsnp325] C:\Windows\tsnp325.exe
      O4 - HKLM\..\Run: [snp325] C:\Windows\vsnp325.exe
      O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
      O4 - HKCU\..\Run: [SmpcSys] C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe
      O4 - HKCU\..\Run: [Google Update] "C:\Users\Fabien\AppData\Local\Google\Update\GoogleUpdate.exe" /c
      O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
      O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
      O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
      O4 - HKCU\..\Run: [Free Download Manager] "C:\Program Files\Free Download Manager\fdm.exe" -autorun
      O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
      O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
      O4 - Startup: Free Music Zilla.lnk = C:\Program Files\Free Music Zilla\FMZilla.exe
      O4 - Startup: Free Music Zilla.lnk.disabled
      O4 - Startup: OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
      O4 - Startup: Ubisoft register.lnk = C:\Program Files\UBISOFT\Register\schedule.exe
      O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
      O8 - Extra context menu item: Tout télécharger avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
      O8 - Extra context menu item: Télécharger avec Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
      O8 - Extra context menu item: Télécharger la sélection avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
      O8 - Extra context menu item: Télécharger la vidéo avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlfvideo.htm
      O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
      O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
      O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
      O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
      O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
      O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
      O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
      O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
      O13 - Gopher Prefix:
      O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://download.divx.com/player/DivXBrowserPlugin.cab
      O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} (Java Plug-in 1.6.0_13) -
      O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
      O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
      O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      O23 - Service: Google Updater Service (gusvc) - Unknown owner - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (file missing)
      O23 - Service: NMIndexingService - Unknown owner - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe (file missing)
      O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
      O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\Windows\system32\IoctlSvc.exe
      O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
      0
      1. Contributeur sécurité
        on nettoie

        relances RSIT et postes le rapport log stp
        0
        1. bien merci beaucoup tu est super
          0
          1. Contributeur sécurité
            ok

            redemarres le pc pour que les suppressions soient effectives

            vides ensuite sa quarantaine

            comment va le pc apres le redemarrage?
            0
            1. 2e rap :

              Malwarebytes' Anti-Malware 1.44
              Version de la base de données: 3510
              Windows 6.0.6002 Service Pack 2
              Internet Explorer 8.0.6001.18882

              27/02/2010 17:52:21
              mbam-log-2010-02-27 (17-52-21).txt

              Type de recherche: Examen complet (C:\|)
              Eléments examinés: 279339
              Temps écoulé: 1 hour(s), 0 minute(s), 36 second(s)

              Processus mémoire infecté(s): 0
              Module(s) mémoire infecté(s): 1
              Clé(s) du Registre infectée(s): 1
              Valeur(s) du Registre infectée(s): 0
              Elément(s) de données du Registre infecté(s): 2
              Dossier(s) infecté(s): 1
              Fichier(s) infecté(s): 10

              Processus mémoire infecté(s):
              (Aucun élément nuisible détecté)

              Module(s) mémoire infecté(s):
              C:\Windows\System32\diagperf32.dll (Trojan.Tracur) -> Delete on reboot.

              Clé(s) du Registre infectée(s):
              HKEY_CURRENT_USER\SOFTWARE\Microsoft\Active Setup\Installed Components\{5y99ae78-58tt-11dw-be53-y67078979y} (Backdoor.ProRat) -> Quarantined and deleted successfully.

              Valeur(s) du Registre infectée(s):
              (Aucun élément nuisible détecté)

              Elément(s) de données du Registre infecté(s):
              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Tracur) -> Data: c:\windows\system32\diagperf32.dll -> Quarantined and deleted successfully.
              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Tracur) -> Data: system32\diagperf32.dll -> Quarantined and deleted successfully.

              Dossier(s) infecté(s):
              C:\Windows\System32\SysWoW32 (Worm.Archive) -> Quarantined and deleted successfully.

              Fichier(s) infecté(s):
              C:\Windows\System32\diagperf32.dll (Trojan.Tracur) -> Delete on reboot.
              C:\Ad-Remover\QUARANTINE\PROGRA~1\Zwunzi\zwunzi.exe.vir (Adware.Agent) -> Quarantined and deleted successfully.
              C:\Users\Fabien\AppData\Local\Temp\nsgD0BD.tmp\uninstall.exe (Adware.Agent) -> Quarantined and deleted successfully.
              C:\Users\Fabien\AppData\Local\Temp\nsgD0BD.tmp\zwunzi.exe (Adware.Agent) -> Quarantined and deleted successfully.
              C:\Users\Fabien\AppData\Roaming\3223.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
              C:\Users\Fabien\AppData\Roaming\847.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
              C:\Users\Fabien\AppData\Roaming\8ECE.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
              C:\Users\Fabien\AppData\Roaming\A482.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
              C:\Users\Fabien\AppData\Roaming\EBE2.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
              C:\Windows\System32\davclnt32.dll (Trojan.Tracur) -> Quarantined and deleted successfully.
              0
              1. Contributeur sécurité
                vu
                ==> MalwareByte's Anti-Malware
                0
                1. 1er rap :

                  Kill'em by g3n-h@ckm@n 1.2.8.1

                  User : Fabien (Administrateurs)
                  Update on 26/02/2010 by g3n-h@ckm@n ::::: 14.30
                  Start at: 13:45:08 | 27/02/2010
                  Contact : https://forums.commentcamarche.net/forum/virus-securite-7

                  Intel(R) Core(TM)2 Quad CPU Q6600 @ 2.40GHz
                  Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6002 32-bit) # Service Pack 2
                  Internet Explorer 8.0.6001.18882
                  Windows Firewall Status : Enabled

                  C:\ -> Disque fixe local | 220,88 Go (90,58 Go free) [HDD] | NTFS
                  D:\ -> Disque CD-ROM
                  E:\ -> Disque amovible
                  F:\ -> Disque amovible
                  G:\ -> Disque amovible
                  H:\ -> Disque amovible
                  L:\ -> Disque CD-ROM | 6,31 Mo (0 Mo free) [U3 System] | CDFS
                  M:\ -> Disque amovible | 7,47 Go (388,75 Mo free) | FAT32

                  ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running

                  C:\Windows\System32\smss.exe
                  C:\Windows\system32\csrss.exe
                  C:\Windows\system32\wininit.exe
                  C:\Windows\system32\csrss.exe
                  C:\Windows\system32\services.exe
                  C:\Windows\system32\lsass.exe
                  C:\Windows\system32\lsm.exe
                  C:\Windows\system32\winlogon.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\system32\nvvsvc.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\System32\svchost.exe
                  C:\Windows\System32\svchost.exe
                  C:\Windows\System32\svchost.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\system32\SLsvc.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\system32\rundll32.exe
                  C:\Windows\system32\svchost.exe
                  C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
                  C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                  C:\Program Files\Alwil Software\Avast4\ashServ.exe
                  C:\Windows\System32\spoolsv.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\system32\taskeng.exe
                  C:\Windows\system32\Dwm.exe
                  C:\Windows\Explorer.EXE
                  C:\Windows\system32\conime.exe
                  C:\Windows\system32\taskeng.exe
                  C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\System32\svchost.exe
                  C:\Windows\system32\IoctlSvc.exe
                  C:\Windows\System32\svchost.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\System32\svchost.exe
                  C:\Windows\system32\SearchIndexer.exe
                  C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
                  C:\Windows\system32\WUDFHost.exe
                  C:\Windows\System32\rundll32.exe
                  C:\Program Files\Windows Defender\MSASCui.exe
                  C:\Windows\RtHDVCpl.exe
                  C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
                  C:\Windows\System32\rundll32.exe
                  C:\Program Files\Java\jre6\bin\jusched.exe
                  C:\Program Files\Alwil Software\Avast4\ashDisp.exe
                  C:\Windows\FixCamera.exe
                  C:\Windows\vsnp325.exe
                  C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe
                  C:\Windows\ehome\ehtray.exe
                  C:\Program Files\Windows Media Player\wmpnscfg.exe
                  C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                  C:\Program Files\Windows Media Player\wmpnetwk.exe
                  C:\Windows\ehome\ehmsas.exe
                  C:\Users\Fabien\AppData\Local\Google\Update\1.2.183.17\GoogleCrashHandler.exe
                  C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
                  C:\Program Files\Java\jre6\bin\jucheck.exe
                  C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                  C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                  C:\Users\Fabien\AppData\Local\Google\Chrome\Application\chrome.exe
                  C:\Users\Fabien\AppData\Local\Google\Chrome\Application\chrome.exe
                  C:\Users\Fabien\AppData\Local\Google\Chrome\Application\chrome.exe
                  C:\Users\Fabien\AppData\Local\Google\Chrome\Application\chrome.exe
                  C:\Program Files\List_Kill'em\List_Kill'em.scr
                  C:\Windows\system32\cmd.exe
                  C:\Windows\system32\msfeedssync.exe
                  C:\Windows\system32\SearchProtocolHost.exe
                  C:\Windows\system32\SearchFilterHost.exe
                  C:\Windows\system32\wbem\wmiprvse.exe
                  C:\Users\Fabien\AppData\Local\Temp\341D.tmp\ERUNT.EXE
                  C:\Users\Fabien\AppData\Local\Temp\341D.tmp\pv.exe

                  Detections :
                  ==========

                  ¤¤¤¤¤¤¤¤¤¤ Files/folders :

                  Quarantined & Deleted !! : C:\ProgramData\.zreglib
                  Quarantined & Deleted !! : C:\Program Files\Mozilla Firefox\extensions\{8CE11043-9A15-4207-A565-0C94C42D590D}

                  Quarantined & Deleted !! : C:\Windows\System32\MSINET.oca
                  Quarantined & Deleted !! : C:\Windows\System32\SysWoW32
                  Quarantined & Deleted !! : C:\Windows\System32\unrar.exe
                  Quarantined & Deleted !! : C:\Windows\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
                  Quarantined & Deleted !! : C:\Windows\tasks\{66BA574B-1E11-49b8-909C-8CC9E0E8E015}.job
                  Quarantined & Deleted !! : C:\Users\Fabien\AppData\Roaming\2170.tmp
                  Quarantined & Deleted !! : C:\Users\Fabien\AppData\Roaming\21FD.tmp
                  Quarantined & Deleted !! : C:\Users\Fabien\AppData\Roaming\3404.tmp
                  Quarantined & Deleted !! : C:\Users\Fabien\AppData\Roaming\3CB8.tmp
                  Quarantined & Deleted !! : C:\Users\Fabien\AppData\Roaming\61D1.tmp
                  Quarantined & Deleted !! : C:\Users\Fabien\AppData\Roaming\6210.tmp
                  Quarantined & Deleted !! : C:\Users\Fabien\AppData\Roaming\6B85.tmp
                  Quarantined & Deleted !! : C:\Users\Fabien\AppData\Roaming\8400.tmp
                  Quarantined & Deleted !! : C:\Users\Fabien\AppData\Roaming\A078.tmp
                  Quarantined & Deleted !! : C:\Users\Fabien\AppData\Roaming\A70.tmp
                  Quarantined & Deleted !! : C:\Users\Fabien\AppData\Roaming\ABF2.tmp
                  Quarantined & Deleted !! : C:\Users\Fabien\AppData\Roaming\AEE.tmp
                  Quarantined & Deleted !! : C:\Users\Fabien\AppData\Roaming\B359.tmp
                  Quarantined & Deleted !! : C:\Users\Fabien\AppData\Roaming\D119.tmp
                  Quarantined & Deleted !! : C:\Users\Fabien\AppData\Roaming\D14E.tmp
                  Quarantined & Deleted !! : C:\Users\Fabien\AppData\Roaming\D19D.tmp
                  Quarantined & Deleted !! : C:\Users\Fabien\AppData\Roaming\D7AF.tmp
                  Quarantined & Deleted !! : C:\Users\Fabien\AppData\Roaming\SystemProc
                  Quarantined & Deleted !! : C:\Users\Fabien\Local Settings\Temp\amt.log
                  Quarantined & Deleted !! : C:\Users\Fabien\LOCAL Settings\Temp\GoogleUpdateSetup.exe549d351
                  Quarantined & Deleted !! : C:\Users\Fabien\LOCAL Settings\Temp\jre-6u17-windows-i586-iftw-rv.exe

                  ==============
                  host file OK !
                  ==============

                  ========
                  Registry
                  ========

                  Deleted : "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}"
                  Deleted : "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}"
                  Deleted : HKCR\.fsharproj
                  Deleted : HKCR\CLSID\{248dd896-bb45-11cf-9abc-0080c7e7b78d}
                  Deleted : HKCR\CLSID\{248dd897-bb45-11cf-9abc-0080c7e7b78d}
                  Deleted : HKCR\Interface\{248dd892-bb45-11cf-9abc-0080c7e7b78d}
                  Deleted : HKCR\Interface\{248dd893-bb45-11cf-9abc-0080c7e7b78d}
                  Deleted : HKCR\TypeLib\{248dd890-bb45-11cf-9abc-0080c7e7b78d}
                  Deleted : HKCU\SOFTWARE\Microsoft\Handle
                  ========
                  Services
                  =========

                  Ndisuio : Start = 3
                  EapHost : Start = 2
                  Wlansvc : Start = 2
                  SharedAccess : Start = 2
                  windefend : Start = 2
                  wuauserv : Start = 2
                  wscsvc : Start = 2

                  ============
                  Disk Cleaned
                  ============

                  =================
                  anti-ver blaster : OK !!
                  =================

                  ================
                  Prefetch cleaned
                  ================

                  ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
                  0
                  1. Contributeur sécurité
                    C'est un trojan ton 2eme truc

                    (sourire)

                    non d'où l'utilité de déactiver provisoirement tes protections...

                    1)

                    ▶ Relance List&Kill'em avec le raccourci sur ton bureau ,

                    mais cette fois-ci :

                    ▶ choisis l'option 2 = Mode Suppression

                    laisse travailler l'outil.

                    en fin de scan un rapport s'ouvre

                    ▶ colle le contenu dans ta reponse

                    Tu peux le désinstaller ensuite

                    ..................

                    2)

                    Téléchargez MalwareByte's Anti-Malware

                    http://www.malwarebytes.org/mbam/program/mbam-setup.exe

                    . Enregistres le sur le bureau
                    . Double cliques sur le fichier téléchargé pour lancer le processus d'installation.
                    . Dans l'onglet "mise à jour", cliques sur le bouton Recherche de mise à jour
                    . Si le pare-feu demande l'autorisation de se connecter pour malwarebytes, accepte
                    . Une fois la mise à jour terminé
                    . Rend-toi dans l'onglet, Recherche
                    . Sélectionnes Exécuter un examen complet (examen assez long)
                    . Cliques sur Rechercher
                    . Le scan démarre.
                    . A la fin de l'analyse, un message s'affiche : L'examen s'est terminé normalement. Cliquez sur 'Afficher les résultats' pour afficher tous les objets trouvés.
                    . Cliques sur Ok pour poursuivre.
                    . Si des malwares ont été détectés, clique sur Afficher les résultats
                    . Sélectionnes tout (ou laisses cochés) et cliques sur Supprimer la sélection Malwarebytes va détruire les fichiers et clés de registre et en mettre une copie dans la quarantaine.
                    . Malwarebytes va ouvrir le bloc-notes et y copier le rapport d'analyse.
                    . Rends toi dans l'onglet rapport/log
                    . Tu cliques dessus pour l'afficher, une fois affiché
                    . Tu cliques sur edition en haut du boc notes, et puis sur sélectionner tous
                    . Tu recliques sur edition et puis sur copier et tu reviens sur le forum et dans ta réponse
                    . tu cliques droit dans le cadre de la reponse et coller

                    Si tu as besoin d'aide regarde ces tutoriels :
                    Aide: https://www.malekal.com/tutoriel-malwarebyte-anti-malware/
                    http://www.infos-du-net.com/forum/278396-11-tuto-malwarebytes-anti-malware-mbam

                    0
                    1. List'em by g3n-h@ckm@n 1.2.8.1

                      User : Fabien (Administrateurs)
                      Update on 26/02/2010 by g3n-h@ckm@n ::::: 14.30
                      Start at: 21:02:16 | 26/02/2010
                      Contact : https://forums.commentcamarche.net/forum/virus-securite-7

                      Intel(R) Core(TM)2 Quad CPU Q6600 @ 2.40GHz
                      Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6002 32-bit) # Service Pack 2
                      Internet Explorer 8.0.6001.18882
                      Windows Firewall Status : Disabled

                      C:\ -> Disque fixe local | 220,88 Go (90,67 Go free) [HDD] | NTFS
                      D:\ -> Disque CD-ROM
                      E:\ -> Disque amovible
                      F:\ -> Disque amovible
                      G:\ -> Disque amovible
                      H:\ -> Disque amovible
                      L:\ -> Disque CD-ROM | 6,31 Mo (0 Mo free) [U3 System] | CDFS
                      M:\ -> Disque amovible | 7,47 Go (388,75 Mo free) | FAT32

                      Boot: Normal

                      ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running

                      C:\Windows\System32\smss.exe
                      C:\Windows\system32\csrss.exe
                      C:\Windows\system32\wininit.exe
                      C:\Windows\system32\csrss.exe
                      C:\Windows\system32\services.exe
                      C:\Windows\system32\lsass.exe
                      C:\Windows\system32\lsm.exe
                      C:\Windows\system32\winlogon.exe
                      C:\Windows\system32\svchost.exe
                      C:\Windows\system32\nvvsvc.exe
                      C:\Windows\system32\svchost.exe
                      C:\Windows\System32\svchost.exe
                      C:\Windows\System32\svchost.exe
                      C:\Windows\System32\svchost.exe
                      C:\Windows\system32\svchost.exe
                      C:\Windows\system32\svchost.exe
                      C:\Windows\system32\SLsvc.exe
                      C:\Windows\system32\svchost.exe
                      C:\Windows\system32\rundll32.exe
                      C:\Windows\system32\svchost.exe
                      C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
                      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                      C:\Program Files\Alwil Software\Avast4\ashServ.exe
                      C:\Windows\System32\spoolsv.exe
                      C:\Windows\system32\svchost.exe
                      C:\Windows\system32\taskeng.exe
                      C:\Windows\system32\Dwm.exe
                      C:\Windows\Explorer.EXE
                      C:\Windows\system32\conime.exe
                      C:\Windows\system32\taskeng.exe
                      C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                      C:\Windows\system32\svchost.exe
                      C:\Windows\System32\svchost.exe
                      C:\Windows\system32\IoctlSvc.exe
                      C:\Windows\System32\svchost.exe
                      C:\Windows\system32\svchost.exe
                      C:\Windows\system32\svchost.exe
                      C:\Windows\System32\svchost.exe
                      C:\Windows\system32\SearchIndexer.exe
                      C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
                      C:\Windows\system32\WUDFHost.exe
                      C:\Windows\System32\rundll32.exe
                      C:\Program Files\Windows Defender\MSASCui.exe
                      C:\Windows\RtHDVCpl.exe
                      C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
                      C:\Windows\System32\rundll32.exe
                      C:\Program Files\Java\jre6\bin\jusched.exe
                      C:\Program Files\Alwil Software\Avast4\ashDisp.exe
                      C:\Windows\FixCamera.exe
                      C:\Windows\vsnp325.exe
                      C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe
                      C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                      C:\Windows\ehome\ehtray.exe
                      C:\Program Files\Windows Media Player\wmpnscfg.exe
                      C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                      C:\Program Files\Windows Media Player\wmpnetwk.exe
                      C:\Windows\ehome\ehmsas.exe
                      C:\Users\Fabien\AppData\Local\Google\Update\1.2.183.17\GoogleCrashHandler.exe
                      C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
                      C:\Users\Fabien\AppData\Local\Google\Chrome\Application\chrome.exe
                      C:\Users\Fabien\AppData\Local\Google\Chrome\Application\chrome.exe
                      C:\Program Files\List_Kill'em\List_Kill'em.scr
                      C:\Windows\system32\cmd.exe
                      C:\Users\Fabien\AppData\Local\Google\Chrome\Application\chrome.exe
                      C:\Users\Fabien\AppData\Local\Google\Chrome\Application\chrome.exe
                      C:\Program Files\Java\jre6\bin\jucheck.exe
                      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                      C:\Program Files\MessengerDiscovery 2\MessengerDiscovery 2.exe
                      C:\Program Files\Windows Live\Contacts\wlcomm.exe
                      C:\Windows\system32\taskeng.exe
                      C:\Windows\system32\SearchProtocolHost.exe
                      C:\Windows\system32\SearchFilterHost.exe
                      C:\Windows\system32\wbem\wmiprvse.exe
                      C:\Users\Fabien\AppData\Local\Temp\2A3B.tmp\pv.exe

                      ======================
                      Keys "Run"
                      ======================
                      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                      WindowsWelcomeCenter REG_SZ rundll32.exe oobefldr.dll,ShowWelcomeCenter
                      SmpcSys REG_SZ C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe
                      Google Update REG_SZ "C:\Users\Fabien\AppData\Local\Google\Update\GoogleUpdate.exe" /c
                      SpybotSD TeaTimer REG_SZ C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                      msnmsgr REG_SZ "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                      ehTray.exe REG_SZ C:\Windows\ehome\ehTray.exe
                      Free Download Manager REG_SZ "C:\Program Files\Free Download Manager\fdm.exe" -autorun
                      WMPNSCFG REG_SZ C:\Program Files\Windows Media Player\WMPNSCFG.exe

                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                      Windows Defender REG_EXPAND_SZ %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                      RtHDVCpl REG_SZ RtHDVCpl.exe
                      Adobe Reader Speed Launcher REG_SZ "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                      fssui REG_SZ "C:\Program Files\Windows Live\Family Safety\fsui.exe" -autorun
                      HP Software Update REG_SZ C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                      NvCplDaemon REG_SZ RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
                      NvMediaCenter REG_SZ RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
                      SunJavaUpdateSched REG_SZ "C:\Program Files\Java\jre6\bin\jusched.exe"
                      avast! REG_SZ C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                      FixCamera REG_SZ C:\Windows\FixCamera.exe
                      tsnp325 REG_SZ C:\Windows\tsnp325.exe
                      snp325 REG_SZ C:\Windows\vsnp325.exe

                      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]

                      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]

                      =====================
                      Other Keys
                      =====================
                      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
                      ConsentPromptBehaviorAdmin REG_DWORD 2 (0x2)
                      ConsentPromptBehaviorUser REG_DWORD 1 (0x1)
                      EnableInstallerDetection REG_DWORD 1 (0x1)
                      EnableLUA REG_DWORD 0 (0x0)
                      EnableSecureUIAPaths REG_DWORD 1 (0x1)
                      EnableVirtualization REG_DWORD 1 (0x1)
                      PromptOnSecureDesktop REG_DWORD 1 (0x1)
                      ValidateAdminCodeSignatures REG_DWORD 0 (0x0)
                      dontdisplaylastusername REG_DWORD 0 (0x0)
                      legalnoticecaption REG_SZ
                      legalnoticetext REG_SZ
                      scforceoption REG_DWORD 0 (0x0)
                      shutdownwithoutlogon REG_DWORD 1 (0x1)
                      undockwithoutlogon REG_DWORD 1 (0x1)
                      FilterAdministratorToken REG_DWORD 1 (0x1)
                      EnableUIADesktopToggle REG_DWORD 0 (0x0)
                      UacDisableNotify REG_DWORD 0 (0x0)

                      ===============
                      [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
                      NoLowDiskSpaceChecks REG_DWORD 1 (0x1)

                      ===============
                      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
                      BindDirectlyToPropertySetStorage REG_DWORD 0 (0x0)

                      ===============
                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
                      AppInit_DLLS REG_SZ C:\Windows\System32\diagperf32.dll

                      ===============
                      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
                      ReportBootOk REG_SZ 1
                      Shell REG_SZ Explorer.exe
                      Userinit REG_SZ C:\Windows\system32\userinit.exe,
                      VmApplet REG_SZ rundll32 shell32,Control_RunDLL "sysdm.cpl"
                      AutoRestartShell REG_DWORD 1 (0x1)
                      LegalNoticeCaption REG_SZ
                      LegalNoticeText REG_SZ
                      PowerdownAfterShutdown REG_SZ 0
                      ShutdownWithoutLogon REG_SZ 0
                      cachedlogonscount REG_SZ 10
                      forceunlocklogon REG_DWORD 0 (0x0)
                      passwordexpirywarning REG_DWORD 14 (0xe)
                      Background REG_SZ 0 0 0
                      DebugServerCommand REG_SZ no
                      WinStationsDisabled REG_SZ 0
                      DisableCAD REG_DWORD 1 (0x1)
                      scremoveoption REG_SZ 0
                      ShutdownFlags REG_DWORD 39 (0x27)
                      Administrateur REG_DWORD 1 (0x1)

                      ===============

                      ===============
                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]

                      ===============
                      [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
                      C:\Program Files\Free Music Zilla\FMZilla.exe REG_SZ C:\Program Files\Free Music Zilla\FMZilla.exe:*:Enabled:FMZilla

                      [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

                      ===============
                      ActivX controls
                      ===============
                      HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{67DABFBF-D0AB-41FA-9C46-CC0F21721616}
                      HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
                      HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}

                      ===============
                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}
                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{26923b43-4d38-484f-9b9e-de460746276c}
                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}
                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{08B0E5C0-4FCB-11CF-AAA5-00401C608500}
                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2179C5D3-EBFF-11CF-B6FD-00AA00B4E220}
                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}
                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{233C1507-6A77-46A4-9443-F871F945D258}
                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2A202491-F00D-11cf-87CC-0020AFEECF20}
                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}
                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{3af36230-a269-11d1-b5bf-0000f8051515}
                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{411EDCF7-755D-414E-A74B-3DCD6583F589}
                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}
                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA848-CC51-11CF-AAFA-00AA00B6015C}
                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA855-CC51-11CF-AAFA-00AA00B6015F}
                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{45ea75a0-a269-11d1-b5bf-0000f8051515}
                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4f645220-306d-11d2-995d-00c04f98bbc9}
                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{57EC5BFE-7CB7-3057-8385-C9D72918511C}
                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5fd399c0-a70a-11d1-9948-00c04f98bbc9}
                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{630b1da0-b465-11d1-9948-00c04f98bbc9}
                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}
                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6fab99d0-bab8-11d1-994a-00c04f98bbc9}
                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7790769C-0471-11d2-AF11-00C04FA35D02}
                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7C028AF8-F614-47B3-82DA-BA94E41B1089}
                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4340}
                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4383}
                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}
                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9381D8F2-0288-11D0-9501-00AA00B911A5}
                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C6BAF60B-6E91-453F-BFF9-D3789CFEFCDD}
                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C9E9A340-D1F1-11D0-821E-444553540600}
                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{D27CDB6E-AE6D-11CF-96B8-444553540000}
                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{DAA94A2A-2A8D-4D3B-9DB8-56FBECED082D}
                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{de5aed00-a4bf-11d1-9948-00c04f98bbc9}
                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{E92B03AB-B707-11d2-9CBD-0000F87A369E}

                      ==============
                      BHO :
                      ======
                      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
                      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{4f3ed5cd-0726-42a9-87f5-d13f3d2976ac}]
                      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{53707962-6F74-2D53-2644-206D7942484F}]
                      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
                      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
                      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{CC59E0F9-7E43-44FA-9FAA-8377850BF205}]
                      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
                      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
                      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}]

                      ===
                      DNS
                      ===

                      HKLM\SYSTEM\CCS\Services\Tcpip\..\{631DE62C-0FE2-44AC-9B82-E958128C0179}: DhcpNameServer=192.168.1.1 192.168.1.1
                      HKLM\SYSTEM\CS1\Services\Tcpip\..\{631DE62C-0FE2-44AC-9B82-E958128C0179}: DhcpNameServer=192.168.1.1 192.168.1.1
                      HKLM\SYSTEM\CS3\Services\Tcpip\..\{631DE62C-0FE2-44AC-9B82-E958128C0179}: DhcpNameServer=192.168.1.1 192.168.1.1
                      HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1 192.168.1.1
                      HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1 192.168.1.1
                      HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1 192.168.1.1

                      ================
                      Internet Explorer :
                      ================
                      [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
                      Start Page REG_SZ https://www.msn.com/fr-fr

                      [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                      Start Page REG_SZ https://www.msn.com/fr-fr

                      ========
                      Services
                      ========
                      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services]

                      Ndisuio : 0x3 ( OK = 3 )
                      EapHost : 0x2 ( OK = 2 )
                      Wlansvc : 0x2 ( OK = 2 )
                      SharedAccess : 0x2 ( OK = 2 )
                      windefend : 0x2 ( OK = 2 )
                      wuauserv : 0x2 ( OK = 2 )
                      wscsvc : 0x2 ( OK = 2 )

                      =========
                      Atapi.sys
                      =========

                      %%%% HASHDEEP-1.0
                      %%%% size,md5,sha256,filename
                      ## Invoked from: C:\Users\Fabien\AppData\Local\Temp\2A3B.tmp
                      ## C:\> hashdeep.exe C:\Windows\System32\drivers\atapi.sys
                      ##
                      19944,1f05b78ab91c9075565a9d8a4b880bc4,737be9f9376dab0ccdfed93ea6d67f0c432367ea63cd772a453485be769af3bd,C:\Windows\System32\drivers\atapi.sys
                      %%%% HASHDEEP-1.0
                      %%%% size,md5,sha256,filename
                      ## Invoked from: C:\Users\Fabien\AppData\Local\Temp\2A3B.tmp
                      ## C:\> hashdeep.exe C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_b12d8e84\atapi.sys
                      ##
                      19944,1f05b78ab91c9075565a9d8a4b880bc4,737be9f9376dab0ccdfed93ea6d67f0c432367ea63cd772a453485be769af3bd,C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_b12d8e84\atapi.sys
                      %%%% HASHDEEP-1.0
                      %%%% size,md5,sha256,filename
                      ## Invoked from: C:\Users\Fabien\AppData\Local\Temp\2A3B.tmp
                      ## C:\> hashdeep.exe C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys
                      ##
                      19048,4f4fcb8b6ea06784fb6d475b7ec7300f,6202d85c9a75e3f01f5f94f069c4cd8a2b9295a182301eae5940ec3bc2c1d896,C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys
                      %%%% HASHDEEP-1.0
                      %%%% size,md5,sha256,filename
                      ## Invoked from: C:\Users\Fabien\AppData\Local\Temp\2A3B.tmp
                      ## C:\> hashdeep.exe C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_cc18792d\atapi.sys
                      ##
                      21560,2d9c903dc76a66813d350a562de40ed9,82609f01a08c6842e4c17c077bb641c1429c0e6657964b7f2d114035e1bdcbf3,C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_cc18792d\atapi.sys
                      %%%% HASHDEEP-1.0
                      %%%% size,md5,sha256,filename
                      ## Invoked from: C:\Users\Fabien\AppData\Local\Temp\2A3B.tmp
                      ## C:\> hashdeep.exe C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a2189ce9c\atapi.sys
                      ##
                      21560,2d9c903dc76a66813d350a562de40ed9,82609f01a08c6842e4c17c077bb641c1429c0e6657964b7f2d114035e1bdcbf3,C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a2189ce9c\atapi.sys
                      %%%% HASHDEEP-1.0
                      %%%% size,md5,sha256,filename
                      ## Invoked from: C:\Users\Fabien\AppData\Local\Temp\2A3B.tmp
                      ## C:\> hashdeep.exe C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_df23a1261eab99e8\atapi.sys
                      ##
                      19944,1f05b78ab91c9075565a9d8a4b880bc4,737be9f9376dab0ccdfed93ea6d67f0c432367ea63cd772a453485be769af3bd,C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_df23a1261eab99e8\atapi.sys

                      Référence :
                      ==========

                      Win 2000_SP2 : ff953a8f08ca3f822127654375786bbe
                      Win XP_32b : a64013e98426e1877cb653685c5c0009
                      Win XP_SP2_32b : CDFE4411A69C224BD1D11B2DA92DAC51
                      Win XP_SP3_32b : 9F3A2F5AA6875C72BF062C712CFA2674
                      Vista_32b : e03e8c99d15d0381e02743c36afc7c6f
                      Vista_SP1_32b : 2d9c903dc76a66813d350a562de40ed9
                      Vista_SP2_32b : 1F05B78AB91C9075565A9D8A4B880BC4
                      Vista_SP2_64b : 1898FAE8E07D97F2F6C2D5326C633FAC
                      Windows 7_32b : 80C40F7FDFC376E4C5FEEC28B41C119E
                      Windows 7_64b : 02062C0B390B7729EDC9E69C680A6F3C

                      L:\Autorun.inf :
                      ----------------
                      [AutoRun]
                      open=LaunchU3.exe -a
                      icon=LaunchU3.exe,0

                      [Definitions]
                      Launchpad=LaunchPad.exe
                      Vtype=2

                      [CopyFiles]
                      FileNumber=1
                      File1=LaunchPad.zip

                      [Update]
                      URL=http://u3.sandisk.com/download/lp_installer.asp?custom=1.6.1.1&brand=cruzer

                      [Comment]
                      brand=cruzer
                      =======
                      Drive :
                      =======

                      D‚fragmenteur de disque Windows
                      Copyright (c) 2006 Microsoft Corp.

                      Rapport d'analyse pour le volume C: HDD

                      Taille du volume = 221 Go
                      Espace libre = 90.68 Go
                      tendue d'espace libre la plus grande = 30.87 Go
                      Pourcentage de fragmentation des fichiers = 0 %

                      Remarqueÿ: sur les volumes NTFS, les fragments de fichiers de plus de 64ÿMo ne sont pas inclus dans les statistiques de fragmentation.

                      Il n'est pas n‚cessaire de d‚fragmenter ce volume.

                      ¤¤¤¤¤¤¤¤¤¤ Files/folders :

                      Present !! : C:\ProgramData\.zreglib
                      Present !! : C:\Program Files\Mozilla Firefox\extensions\{8CE11043-9A15-4207-A565-0C94C42D590D}
                      Present !! : C:\Windows\System32\MSINET.oca
                      Present !! : C:\Windows\System32\SysWoW32
                      Present !! : C:\Windows\System32\unrar.exe
                      Present !! : C:\Windows\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
                      Present !! : C:\Windows\tasks\{66BA574B-1E11-49b8-909C-8CC9E0E8E015}.job
                      Present !! : C:\Users\Fabien\AppData\Roaming\2170.tmp
                      Present !! : C:\Users\Fabien\AppData\Roaming\21FD.tmp
                      Present !! : C:\Users\Fabien\AppData\Roaming\3404.tmp
                      Present !! : C:\Users\Fabien\AppData\Roaming\3CB8.tmp
                      Present !! : C:\Users\Fabien\AppData\Roaming\61D1.tmp
                      Present !! : C:\Users\Fabien\AppData\Roaming\6210.tmp
                      Present !! : C:\Users\Fabien\AppData\Roaming\6B85.tmp
                      Present !! : C:\Users\Fabien\AppData\Roaming\8400.tmp
                      Present !! : C:\Users\Fabien\AppData\Roaming\A078.tmp
                      Present !! : C:\Users\Fabien\AppData\Roaming\A70.tmp
                      Present !! : C:\Users\Fabien\AppData\Roaming\ABF2.tmp
                      Present !! : C:\Users\Fabien\AppData\Roaming\AEE.tmp
                      Present !! : C:\Users\Fabien\AppData\Roaming\B359.tmp
                      Present !! : C:\Users\Fabien\AppData\Roaming\D119.tmp
                      Present !! : C:\Users\Fabien\AppData\Roaming\D14E.tmp
                      Present !! : C:\Users\Fabien\AppData\Roaming\D19D.tmp
                      Present !! : C:\Users\Fabien\AppData\Roaming\D7AF.tmp
                      Present !! : C:\Users\Fabien\AppData\Roaming\SystemProc
                      Present !! : C:\Users\Fabien\Local Settings\Temp\amt.log
                      Present !! : C:\Users\Fabien\LOCAL Settings\Temp\GoogleUpdateSetup.exe549d351
                      Present !! : C:\Users\Fabien\LOCAL Settings\Temp\jre-6u17-windows-i586-iftw-rv.exe

                      ¤¤¤¤¤¤¤¤¤¤ Keys :

                      Present !! : "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}"
                      Present !! : "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}"
                      Present !! : HKCR\.fsharproj
                      Present !! : HKCR\CLSID\{248dd896-bb45-11cf-9abc-0080c7e7b78d}
                      Present !! : HKCR\CLSID\{248dd897-bb45-11cf-9abc-0080c7e7b78d}
                      Present !! : HKCR\Interface\{248dd892-bb45-11cf-9abc-0080c7e7b78d}
                      Present !! : HKCR\Interface\{248dd893-bb45-11cf-9abc-0080c7e7b78d}
                      Present !! : HKCR\TypeLib\{248dd890-bb45-11cf-9abc-0080c7e7b78d}
                      Present !! : HKCU\SOFTWARE\Microsoft\Handle

                      ============

                      catchme 0.3.1398.3 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                      Rootkit scan 2010-02-26 21:14:50
                      Windows 6.0.6002 Service Pack 2 NTFS

                      scanning hidden processes ...

                      scanning hidden services & system hive ...

                      scanning hidden registry entries ...

                      [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{980BE066-FF37-CB30-3158-D9FAC5C47076}]
                      "majillcpmhfpdpedblfjenmihn"=hex:6b,61,68,61,61,69,61,66,6d,6c,64,65,62,6c,68,68,64,6e,64,66,65,..
                      "naljbbacdihgdigmfnbepdniogli"=hex:6b,61,68,61,61,69,61,66,6d,6c,64,65,62,6c,68,68,64,6e,64,66,65,..
                      "abhgcjholohjgjbnbfhelbhdcicmbcnmge"=hex:68,61,6f,68,6c,62,61,69,62,70,66,6c,69,69,65,6e,00,ff
                      "mamghcfkoefpjoaeeonkfaoado"=hex:68,61,6c,61,69,6a,6f,70,61,65,66,63,62,6a,63,66,00,ff

                      scanning hidden files ...

                      scan completed successfully
                      hidden processes: 0
                      hidden services: 0
                      hidden files: 0

                      Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

                      device: opened successfully
                      user: MBR read successfully
                      called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll ataport.SYS
                      kernel: MBR read successfully
                      user & kernel MBR OK

                      ==========
                      Programs
                      ==========

                      Activation Assistant for the 2007 Microsoft Office suites
                      Adobe
                      Aimersoft
                      Alwil Software
                      Apple Software Update
                      AshongSoft
                      Audacity
                      AutoIt3
                      AviSynth 2.5
                      CCleaner
                      Cirle Developement
                      Club-Internet
                      Common Files
                      Conduit
                      desktop.ini
                      DivX
                      Electronic Arts
                      eRightSoft
                      Fichiers communs
                      FileZilla FTP Client
                      Free Audio Pack
                      Free Download Manager
                      Free Music Zilla
                      freestar
                      Google
                      HDReg
                      Hewlett-Packard
                      HP
                      HyCam2
                      InstallShield Installation Information
                      Internet Explorer
                      iTripoli
                      Java
                      JitBit
                      JRE
                      K-Lite Codec Pack
                      Lavasoft
                      LimeWire
                      List_Kill'em
                      Malwarebytes' Anti-Malware
                      Messenger Plus! Live
                      MessengerDiscovery 2
                      Microsoft
                      Microsoft Games
                      Microsoft Office
                      Microsoft SDKs
                      Microsoft Silverlight
                      Microsoft SQL Server Compact Edition
                      Microsoft Visual Studio 9.0
                      Microsoft Works
                      Microsoft WSE
                      Microsoft.NET
                      Movie Maker
                      Mozilla Firefox
                      MSBuild
                      MSXML 4.0
                      Navilog1
                      Nero
                      NeroInstall.bak
                      Notepad++
                      OpenOffice.org 3
                      Packard Bell
                      Panicware
                      Piratrax
                      QuickMediaConverter
                      Real
                      Realtek
                      Reference Assemblies
                      Seagate
                      SlySoft
                      Spybot - Search & Destroy
                      SystemRequirementsLab
                      TeamSpeak3
                      Trend Micro
                      UBISOFT
                      UnFREEz
                      Uninstall Information
                      Unlocker
                      VideoLAN
                      Windows Calendar
                      Windows Collaboration
                      Windows Defender
                      Windows Journal
                      Windows Live
                      Windows Live Safety Center
                      Windows Live SkyDrive
                      Windows Mail
                      Windows Media Player
                      Windows NT
                      Windows Photo Gallery
                      Windows Portable Devices
                      Windows Sidebar
                      WinHTTrack
                      WinRAR
                      WinZip
                      World of Warcraft
                      WowCartographe
                      Yahoo!

                      ============
                      Drive C:
                      ============

                      $Recycle.Bin
                      Ad-Remover
                      Ad-Report-CLEAN[1].log
                      autoexec.bat
                      boot
                      bootmgr
                      BOOTSECT.BAK
                      common.ini
                      Config.Msi
                      config.sys
                      ConvImages
                      Documents and Settings
                      downloads
                      drivers
                      egd.txt
                      FindyKill_Upload_Me_PC-de-Fabien.zip
                      FyK
                      FyK.txt
                      hiberfil.sys
                      img2-001.raw
                      img2-002.raw
                      IO.SYS
                      Kill'em
                      List'em.txt
                      Mes Sites Web
                      MSDOS.SYS
                      MSOCache
                      My Videos
                      pagefile.sys
                      PerfLogs
                      Program Files
                      ProgramData
                      rsit
                      System Volume Information
                      TB.txt
                      ToolBar SD
                      Users
                      Windows
                      YServer.txt

                      ¤¤¤¤¤¤¤¤¤¤ Cracks | Keygens | Serials

                      ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

                      End of scan : 22:20:20,27
                      0
                      1. 1er rap !

                        .
                        ======= RAPPORT D'AD-REMOVER 1.1.4.6_J | UNIQUEMENT XP/VISTA/7 =======
                        .
                        Mis à jour par C_XX le 05.02.2010 à 17:34
                        Contact: AdRemover.contact@gmail.com
                        Site web: http://pagesperso-orange.fr/NosTools/ad_remover.html
                        .
                        Lancé à: 20:42:53, 26/02/2010 | Mode Normal | Option: CLEAN
                        Exécuté de: C:\Ad-Remover\
                        Système d'exploitation: Microsoft® Windows Vista™ HomePremium Service Pack 2 v6.0.6002
                        Nom du PC: PC-DE-FABIEN | Utilisateur actuel: Fabien
                        .
                        ============== ÉLÉMENT(S) NEUTRALISÉ(S) ==============
                        .
                        Service: *Zwunzi Service*

                        C:\Users\Fabien\AppData\Roaming\Mozilla\FireFox\Profiles\jsmywp2s.default\searchplugins\askcom.xml
                        C:\Users\Fabien\AppData\Roaming\Mozilla\FireFox\Profiles\jsmywp2s.default\searchplugins\sweetim.xml
                        C:\Windows\Installer\{E1B94435-241E-4519-B1C3-C4DD9EB352A2}
                        C:\Program Files\Mozilla FireFox\Components\AskHPRFF.js
                        C:\Program Files\Mozilla FireFox\extensions\{F270F1AF-34D6-41CB-A9F5-8200EF7DB41F}
                        C:\PROGRA~2\MICROS~1\Windows\STARTM~1\Programs\FunkyEmoticons
                        C:\Program Files\FunkyEmoticons
                        C:\Program Files\Search Settings
                        C:\Program Files\Zwunzi
                        C:\Users\Fabien\AppData\Roaming\Desktopicon
                        C:\Users\Fabien\AppData\Roaming\FunkyEmoticons
                        C:\Users\Fabien\AppData\LocalLow\Search Settings
                        C:\Windows\Installer\9acdf34.msi
                        C:\Users\Christine\AppData\Roaming\FunkyEmoticons
                        C:\Users\Christine\AppData\LocalLow\Search Settings
                        C:\Users\Christine\AppData\LocalLow\SweetIM
                        C:\Program Files\Mozilla FireFox\searchplugins\zwunzi141.xml
                        C:\Users\Fabien\AppData\Local\egaki.bat
                        C:\Users\Fabien\AppData\Local\waega.bat

                        (!) -- Fichiers temporaires supprimés.

                        .
                        HKCU\software\appdatalow\AskBarDis
                        HKCU\software\appdatalow\AskHomepage
                        HKCU\software\FunkyEmoticons
                        HKCU\software\Iminent
                        HKCU\Software\Microsoft\Internet Explorer\InternetRegistry\Registry\User\S-1-5-21-2783407152-786704312-2644869086-1000\Software\Sweetim
                        HKCU\Software\Microsoft\Internet Explorer\LowRegistry\Search Settings
                        HKCU\software\microsoft\internet explorer\searchscopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}
                        HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D4027C7F-154A-4066-A1AD-4243D8127440}
                        HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{E67C74F4-A00A-4F2C-9FEC-FD9DC004A67F}
                        HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}
                        HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEE6C35B-6118-11DC-9C72-001320C79847}
                        HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEE6C35C-6118-11DC-9C72-001320C79847}
                        HKLM\Software\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874}
                        HKLM\software\classes\appid\GenericAskToolbar.DLL
                        HKLM\Software\Classes\CLSID\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}
                        HKLM\software\classes\installer\Products\79CAA1B036589D14EA74856E2A220F1E
                        HKLM\Software\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92}
                        HKLM\Software\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E}
                        HKLM\Software\Classes\Interface\{D5A1EF9A-7948-435D-8B87-D6A598317288}
                        HKLM\software\classes\SearchSettings.BHO
                        HKLM\software\classes\SearchSettings.BHO.1
                        HKLM\Software\Classes\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}
                        HKLM\Software\Classes\TypeLib\{CD082CCA-086F-4FD8-8FD7-247A0DBBD1CC}
                        HKLM\software\FunkyEmoticons
                        HKLM\software\Iminent
                        HKLM\Software\Microsoft\Internet Explorer\Toolbar\\{D4027C7F-154A-4066-A1AD-4243D8127440}
                        HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}
                        HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\0292226F570267D459357AF78015E534
                        HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\03285961954D5824C85975D955031EE8
                        HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\6AC3985F4D64C2245A96D31569D1BF40
                        HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\855847FA0E25FBA46B8516389DFDD4B3
                        HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\94E65EF7E080DDA4AA2F1DEDCE74AC5B
                        HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\9DC2844D0E3E8924C8973C3B3BAE1F58
                        HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\AFEB575AA30ACB243B748619F62F0782
                        HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\F461B8DD96FF5AA41A52D14E1D7B69C7
                        HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Products\79CAA1B036589D14EA74856E2A220F1E
                        HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\SearchSettings
                        HKLM\software\Search Settings
                        HKLM\software\Zwunzi
                        .
                        ============== Scan additionnel ==============
                        .
                        .
                        * Mozilla FireFox Version 3.5.8 [fr] *
                        .
                        Nom du profil: jsmywp2s.default (Fabien)
                        .
                        (Fabien, prefs.js) Browser.download.lastDir, C:\Users\Fabien\Pictures\Photoshop\Guerre-Soldat
                        (Fabien, prefs.js) Browser.search.defaultenginename, Ask.com
                        (Fabien, prefs.js) Browser.search.defaulturl, hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT273466&SearchSource=3&q={searchTerms}
                        (Fabien, prefs.js) Browser.search.selectedEngine, Google
                        (Fabien, prefs.js) Browser.startup.homepage, hxxp://google.com/
                        (Fabien, prefs.js) Extensions.enabledItems, {bab31fc4-cb97-46f4-9565-26d65225cc2c}:2.3.0.4,fdm_ffext@freedownloadmanager.org:1.3.4,{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13,{20a82645-c095-46ed-80e3-08825760534b}:1.1,{7786e093-cb4d-4ccb-90d1-cdefd84fde20}:1.0,{F270F1AF-34D6-41CB-A9F5-8200EF7DB41F}:1.0,{972ce4c6-7e08-4474-a285-3208198ce6fd}:3.5.8
                        (Fabien, prefs.js) Keyword.URL, hxxp://www.bing.com/search?mkt=fr-FR&form=MIAWB1&q=
                        .
                        (Fabien, prefs.js) EFFACE - Browser.search.defaultengine, Ask.com
                        (Fabien, prefs.js) EFFACE - Browser.search.defaultenginename, Ask.com
                        (Fabien, prefs.js) EFFACE - Browser.search.defaultthis.engineName, FearFM Customized Web Search
                        (Fabien, prefs.js) EFFACE - Browser.search.order.1, Ask.com
                        .
                        .
                        * Internet Explorer Version 8.0.6001.18882 *
                        .
                        [HKEY_CURRENT_USER\..\Internet Explorer\Main]
                        .
                        Do404Search: 01000000
                        Local Page: C:\Windows\system32\blank.htm
                        Show_ToolBar: yes
                        Enable Browser Extensions: yes
                        Start Page: hxxp://fr.msn.com/
                        Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
                        Search Bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
                        Use Custom Search URL: 1 (0x1)
                        SearchAssistant:
                        Use Search Asst:
                        Default_search_url: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                        .
                        [HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]
                        .
                        Start Page: hxxp://fr.msn.com/
                        Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
                        Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                        Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                        Delete_Temp_Files_On_Exit: yes
                        Local Page: C:\Windows\System32\blank.htm
                        Search Bar: hxxp://search.msn.com/spbasic.htm
                        .
                        [HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]
                        .
                        Tabs: res://ieframe.dll/tabswelcome.htm
                        .
                        ============== Suspect (Cracks, Serials, ...) ==============
                        .
                        C:\Users\Fabien\AppData\Local\piratrax\data_patch.tmp.doc.zip
                        C:\Users\Fabien\AppData\Local\VirtualStore\Program Files\Audiosurf\patchfile.zip
                        C:\Users\Fabien\Desktop\World of Warcraft\world_of_warcraft_patch_v3.2.0.10314_francais_297522.exe
                        C:\Users\Fabien\Desktop\World of Warcraft\WoW-3.2.0-frFR-patch.exe
                        C:\Users\Fabien\Desktop\World of Warcraft\Updates\wow-3.2.2-to-3.3.0-frFR-Win-patch\Blizzard Updater.exe
                        C:\Users\Fabien\Desktop\World of Warcraft\wow-3.2.2-to-3.3.0-frFR-Win-patch\Blizzard Updater.exe
                        C:\Users\Fabien\Documents\LimeWire\Incomplete\WQMSPDPGLUKBKEPADXJNOK5GU5CAVTF6\Audiosurf + Crack.rar
                        C:\Users\Public\Documents\Blizzard Entertainment\World of Warcraft\WoW-3.2.2.10482-to-3.2.2.10505-frFR-patch.exe
                        .
                        ===================================
                        .
                        7980 Octet(s) - C:\Ad-Report-CLEAN[1].log
                        .
                        155 Fichier(s) - C:\Users\Fabien\AppData\Local\Temp
                        19 Fichier(s) - C:\Windows\Temp
                        10 Fichier(s) - C:\Windows\Prefetch
                        .
                        20 Fichier(s) - C:\Ad-Remover\BACKUP
                        57 Fichier(s) - C:\Ad-Remover\QUARANTINE
                        .
                        Fin à: 20:46:08 | 26/02/2010 - CLEAN[1]
                        .
                        ============== E.O.F ==============
                        .
                        0
                        1. Contributeur sécurité
                          pas d'info personnelles sur ces rapports

                          plusieurs infections

                          1)
                          Note importante :
                          Pour les ordinateurs équipés de Windows Vista et Windows 7, la désactivation du Contrôle des comptes utilisateurs est obligatoire
                          sous peine de ne pas pouvoir faire fonctionner correctement l'outil.
                          Tuto : https://www.commentcamarche.net/faq/8343-vista-desactiver-l-uac

                          Téléchargez et enregistrez le fichier d installation sur le bureau
                          http://pagesperso-orange.fr/NosTools/C_XX/AD-R.exe

                          Double cliquez sur le fichier d'installation de AD-Remover, le programme s'installera automatiquement.
                          Sous Vista : clic droit sur AD-Remover et sélectionner "Exécuter en tant qu'administrateur"
                          Au menu principal choisir
                          Option L Lancer le nettoyage
                          et tapez sur [entrée] .
                          Laissez travailler l'outil et ne touchez à rien ...
                          Postez le rapport qui apparait à la fin.

                          ( le rapport est sauvegardé aussi sous C:\Ad-report.log )

                          (CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

                          Note :Process.exe est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
                          Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
                          Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.

                          .........................

                          2)

                          Desactive ton antivirus le temps de la manip ainsi que ton parefeu si présent(car il est detecté a tort comme infection)

                          ▶ Télécharge et installe List&Kill'em et enregistre le sur ton bureau
                          http://sd-1.archive-host.com/membres/up/829108531491024/List_Killem_Install.exe

                          double clique ( clic droit "executer en tant qu'administrateur" pour Vista/7 ) sur le raccourci sur ton bureau pour lancer l'installation

                          coche la case "creer une icone sur le bureau"

                          une fois terminée , clic sur "terminer" et le programme se lancer seul

                          choisis la langue puis choisis l'option 1 = Mode Recherche

                          ▶ laisse travailler l'outil

                          à l'apparition de la fenetre blanche , c'est un peu long , c'est normal , le programme n'est pas bloqué.

                          un rapport du nom de catchme apparait sur ton bureau , ignore-le,ne le poste pas , mais ne le supprime pas pour l instant, le scan n'est pas fini.

                          ▶ Poste le contenu du rapport qui s'ouvre aux 100 % du scan à l'ecran "COMPLETED"

                          tu peux supprimer le rapport catchme.log de ton bureau maintenant.

                          0
                          1. 3eme :

                            info.txt logfile of random's system information tool 1.06 2010-02-26 20:14:52

                            ======Uninstall list======

                            AutoIt v3.3.4.0-->C:\Program Files\AutoIt3\Uninstall.exe
                            HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
                            MessengerDiscovery 2.1.79-->"C:\Program Files\MessengerDiscovery 2\unins000.exe"
                            Mozilla Firefox (3.5.8)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
                            Notepad++-->C:\Program Files\Notepad++\uninstall.exe
                            Windows Live OneCare safety scanner-->"C:\Program Files\Windows Live Safety Center\UnInstall.exe"
                            Windows Live OneCare safety scanner-->MsiExec.exe /X{FE0646A7-19D0-41B4-A2BB-2C35D644270D}
                            WinHTTrack Website Copier 3.43-9-->"C:\Program Files\WinHTTrack\unins000.exe"

                            ======Security center information======

                            AS: Spybot - Search and Destroy (outdated)
                            AS: AVG Anti-Spyware (disabled) (outdated)
                            AS: Windows Defender

                            ======System event log======

                            Computer Name: PC-de-Fabien
                            Event Code: 4374
                            Message: Windows Servicing a déterminé que ce package Microsoft-Windows-DGT-Package-Package-fi-fi-MiniLP(Feature Pack) n’est pas applicable à ce système.
                            Record Number: 93804
                            Source Name: Microsoft-Windows-Servicing
                            Time Written: 20091204074431.000000-000
                            Event Type: Avertissement
                            User: AUTORITE NT\SYSTEM

                            Computer Name: PC-de-Fabien
                            Event Code: 4374
                            Message: Windows Servicing a déterminé que ce package Microsoft-Windows-DGT-Package-Package-th-th-MiniLP(Feature Pack) n’est pas applicable à ce système.
                            Record Number: 93803
                            Source Name: Microsoft-Windows-Servicing
                            Time Written: 20091204074431.000000-000
                            Event Type: Avertissement
                            User: AUTORITE NT\SYSTEM

                            Computer Name: PC-de-Fabien
                            Event Code: 4376
                            Message: Servicing a requis un redémarrage pour terminer la définition du package KB971514_fr-FR(Language Pack) à l’état Installation demandée(Install Requested)
                            Record Number: 93792
                            Source Name: Microsoft-Windows-Servicing
                            Time Written: 20091204074425.000000-000
                            Event Type: Avertissement
                            User: AUTORITE NT\SYSTEM

                            Computer Name: PC-de-Fabien
                            Event Code: 4376
                            Message: Servicing a requis un redémarrage pour terminer la définition du package KB971514_fr-FR(Language Pack) à l’état Installation demandée(Install Requested)
                            Record Number: 93790
                            Source Name: Microsoft-Windows-Servicing
                            Time Written: 20091204074425.000000-000
                            Event Type: Avertissement
                            User: AUTORITE NT\SYSTEM

                            Computer Name: PC-de-Fabien
                            Event Code: 4376
                            Message: Servicing a requis un redémarrage pour terminer la définition du package Microsoft-Windows-WPD7IP-Package-Package-fr-FR-MiniLP(Update) à l’état Installation demandée(Install Requested)
                            Record Number: 93788
                            Source Name: Microsoft-Windows-Servicing
                            Time Written: 20091204074425.000000-000
                            Event Type: Avertissement
                            User: AUTORITE NT\SYSTEM

                            =====Application event log=====

                            Computer Name: PC-de-Fabien
                            Event Code: 10
                            Message: Le filtre d’événement avec la requête « SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99 » n’a pas pu être réactivé dans l’espace de noms « //./root/CIMV2 » à cause de l’erreur 0x80041003. Les événements ne peuvent pas être délivrés à travers ce filtre tant que le problème ne sera pas corrigé.
                            Record Number: 568
                            Source Name: Microsoft-Windows-WMI
                            Time Written: 20081220091120.000000-000
                            Event Type: Erreur
                            User:

                            Computer Name: PC-de-Fabien
                            Event Code: 1008
                            Message: Le service Windows Search tente de supprimer l’ancien catalogue.

                            Record Number: 550
                            Source Name: Microsoft-Windows-Search
                            Time Written: 20081220091036.000000-000
                            Event Type: Avertissement
                            User:

                            Computer Name: PC-de-Fabien
                            Event Code: 1002
                            Message: Le programme Launcher.exe version 0.0.0.0 a cessé d’interagir avec Windows et a été fermé. Pour déterminer si des informations supplémentaires sont disponibles, consultez l’historique du problème dans l’application Rapports et solutions aux problèmes du Panneau de configuration. ID de processus : 11ec Heure de début : 01c96206e73e880c Heure de fin : 5
                            Record Number: 474
                            Source Name: Application Hang
                            Time Written: 20081219182401.000000-000
                            Event Type: Erreur
                            User:

                            Computer Name: PC-de-Fabien
                            Event Code: 10
                            Message: Le filtre d’événement avec la requête « SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99 » n’a pas pu être réactivé dans l’espace de noms « //./root/CIMV2 » à cause de l’erreur 0x80041003. Les événements ne peuvent pas être délivrés à travers ce filtre tant que le problème ne sera pas corrigé.
                            Record Number: 377
                            Source Name: Microsoft-Windows-WMI
                            Time Written: 20081219165844.000000-000
                            Event Type: Erreur
                            User:

                            Computer Name: PC-de-Fabien
                            Event Code: 1008
                            Message: Le service Windows Search tente de supprimer l’ancien catalogue.

                            Record Number: 373
                            Source Name: Microsoft-Windows-Search
                            Time Written: 20081219165841.000000-000
                            Event Type: Avertissement
                            User:

                            =====Security event log=====

                            Computer Name: PC-de-Fabien
                            Event Code: 4624
                            Message: L’ouverture de session d’un compte s’est correctement déroulée.

                            Sujet :
                            ID de sécurité : S-1-5-18
                            Nom du compte : PC-DE-FABIEN$
                            Domaine du compte : WORKGROUP
                            ID d’ouverture de session : 0x3e7

                            Type d’ouverture de session : 5

                            Nouvelle ouverture de session :
                            ID de sécurité : S-1-5-18
                            Nom du compte : SYSTEM
                            Domaine du compte : AUTORITE NT
                            ID d’ouverture de session : 0x3e7
                            GUID d’ouverture de session : {00000000-0000-0000-0000-000000000000}

                            Informations sur le processus :
                            ID du processus : 0x25c
                            Nom du processus : C:\Windows\System32\services.exe

                            Informations sur le réseau :
                            Nom de la station de travail :
                            Adresse du réseau source : -
                            Port source : -

                            Informations détaillées sur l’authentification :
                            Processus d’ouverture de session : Advapi
                            Package d’authentification : Negotiate
                            Services en transit : -
                            Nom du package (NTLM uniquement) : -
                            Longueur de la clé : 0

                            Cet événement est généré lors de la création d’une ouverture de session. Il est généré sur l’ordinateur sur lequel l’ouverture de session a été effectuée.

                            Le champ Objet indique le compte sur le système local qui a demandé l’ouverture de session. Il s’agit le plus souvent d’un service, comme le service Serveur, ou un processus local tel que Winlogon.exe ou Services.exe.

                            Le champ Type d’ouverture de session indique le type d’ouverture de session qui s’est produit. Les types les plus courants sont 2 (interactif) et 3 (réseau).

                            Le champ Nouvelle ouverture de session indique le compte pour lequel la nouvelle ouverture de session a été créée, par exemple, le compte qui s’est connecté.

                            Les champs relatifs au réseau indiquent la provenance d’une demande d’ouverture de session à distance. Le nom de la station de travail n’étant pas toujours disponible, peut être laissé vide dans certains cas.

                            Les champs relatifs aux informations d’authentification fournissent des détails sur cette demande d’ouverture de session spécifique.
                            - Le GUID d’ouverture de session est un identificateur unique pouvant servir à associer cet événement à un événement KDC .
                            - Les services en transit indiquent les services intermédiaires qui ont participé à cette demande d’ouverture de session.
                            - Nom du package indique quel est le sous-protocole qui a été utilisé parmi les protocoles NTLM.
                            - La longueur de la clé indique la longueur de la clé de session générée. Elle a la valeur 0 si aucune clé de session n’a été demandée.
                            Record Number: 10278
                            Source Name: Microsoft-Windows-Security-Auditing
                            Time Written: 20090405135033.623900-000
                            Event Type: Succès de l'audit
                            User:

                            Computer Name: PC-de-Fabien
                            Event Code: 4648
                            Message: Tentative d’ouverture de session en utilisant des informations d’identification explicites.

                            Sujet :
                            ID de sécurité : S-1-5-18
                            Nom du compte : PC-DE-FABIEN$
                            Domaine du compte : WORKGROUP
                            ID d’ouverture de session : 0x3e7
                            GUID d’ouverture de session : {00000000-0000-0000-0000-000000000000}

                            Compte dont les informations d’identification ont été utilisées :
                            Nom du compte : SYSTEM
                            Domaine du compte : AUTORITE NT
                            GUID d’ouverture de session : {00000000-0000-0000-0000-000000000000}

                            Serveur cible :
                            Nom du serveur cible : localhost
                            Informations supplémentaires : localhost

                            Informations sur le processus :
                            ID du processus : 0x25c
                            Nom du processus : C:\Windows\System32\services.exe

                            Informations sur le réseau :
                            Adresse du réseau : -
                            Port : -

                            Cet événement est généré lorsqu’un processus tente d’ouvrir une session pour un compte en spécifiant explicitement les informations d’identification de ce compte. Ceci se produit le plus souvent dans les configurations par lot comme les tâches planifiées, ou avec l’utilisation de la commande RUNAS.
                            Record Number: 10277
                            Source Name: Microsoft-Windows-Security-Auditing
                            Time Written: 20090405135033.623900-000
                            Event Type: Succès de l'audit
                            User:

                            Computer Name: PC-de-Fabien
                            Event Code: 4672
                            Message: Privilèges spéciaux attribués à la nouvelle ouverture de session.

                            Sujet :
                            ID de sécurité : S-1-5-18
                            Nom du compte : SYSTEM
                            Domaine du compte : AUTORITE NT
                            ID d’ouverture de session : 0x3e7

                            Privilèges : SeAssignPrimaryTokenPrivilege
                            SeTcbPrivilege
                            SeSecurityPrivilege
                            SeTakeOwnershipPrivilege
                            SeLoadDriverPrivilege
                            SeBackupPrivilege
                            SeRestorePrivilege
                            SeDebugPrivilege
                            SeAuditPrivilege
                            SeSystemEnvironmentPrivilege
                            SeImpersonatePrivilege
                            Record Number: 10276
                            Source Name: Microsoft-Windows-Security-Auditing
                            Time Written: 20090405135033.608300-000
                            Event Type: Succès de l'audit
                            User:

                            Computer Name: PC-de-Fabien
                            Event Code: 4624
                            Message: L’ouverture de session d’un compte s’est correctement déroulée.

                            Sujet :
                            ID de sécurité : S-1-5-18
                            Nom du compte : PC-DE-FABIEN$
                            Domaine du compte : WORKGROUP
                            ID d’ouverture de session : 0x3e7

                            Type d’ouverture de session : 5

                            Nouvelle ouverture de session :
                            ID de sécurité : S-1-5-18
                            Nom du compte : SYSTEM
                            Domaine du compte : AUTORITE NT
                            ID d’ouverture de session : 0x3e7
                            GUID d’ouverture de session : {00000000-0000-0000-0000-000000000000}

                            Informations sur le processus :
                            ID du processus : 0x25c
                            Nom du processus : C:\Windows\System32\services.exe

                            Informations sur le réseau :
                            Nom de la station de travail :
                            Adresse du réseau source : -
                            Port source : -

                            Informations détaillées sur l’authentification :
                            Processus d’ouverture de session : Advapi
                            Package d’authentification : Negotiate
                            Services en transit : -
                            Nom du package (NTLM uniquement) : -
                            Longueur de la clé : 0

                            Cet événement est généré lors de la création d’une ouverture de session. Il est généré sur l’ordinateur sur lequel l’ouverture de session a été effectuée.

                            Le champ Objet indique le compte sur le système local qui a demandé l’ouverture de session. Il s’agit le plus souvent d’un service, comme le service Serveur, ou un processus local tel que Winlogon.exe ou Services.exe.

                            Le champ Type d’ouverture de session indique le type d’ouverture de session qui s’est produit. Les types les plus courants sont 2 (interactif) et 3 (réseau).

                            Le champ Nouvelle ouverture de session indique le compte pour lequel la nouvelle ouverture de session a été créée, par exemple, le compte qui s’est connecté.

                            Les champs relatifs au réseau indiquent la provenance d’une demande d’ouverture de session à distance. Le nom de la station de travail n’étant pas toujours disponible, peut être laissé vide dans certains cas.

                            Les champs relatifs aux informations d’authentification fournissent des détails sur cette demande d’ouverture de session spécifique.
                            - Le GUID d’ouverture de session est un identificateur unique pouvant servir à associer cet événement à un événement KDC .
                            - Les services en transit indiquent les services intermédiaires qui ont participé à cette demande d’ouverture de session.
                            - Nom du package indique quel est le sous-protocole qui a été utilisé parmi les protocoles NTLM.
                            - La longueur de la clé indique la longueur de la clé de session générée. Elle a la valeur 0 si aucune clé de session n’a été demandée.
                            Record Number: 10275
                            Source Name: Microsoft-Windows-Security-Auditing
                            Time Written: 20090405135033.608300-000
                            Event Type: Succès de l'audit
                            User:

                            Computer Name: PC-de-Fabien
                            Event Code: 4648
                            Message: Tentative d’ouverture de session en utilisant des informations d’identification explicites.

                            Sujet :
                            ID de sécurité : S-1-5-18
                            Nom du compte : PC-DE-FABIEN$
                            Domaine du compte : WORKGROUP
                            ID d’ouverture de session : 0x3e7
                            GUID d’ouverture de session : {00000000-0000-0000-0000-000000000000}

                            Compte dont les informations d’identification ont été utilisées :
                            Nom du compte : SYSTEM
                            Domaine du compte : AUTORITE NT
                            GUID d’ouverture de session : {00000000-0000-0000-0000-000000000000}

                            Serveur cible :
                            Nom du serveur cible : localhost
                            Informations supplémentaires : localhost

                            Informations sur le processus :
                            ID du processus : 0x25c
                            Nom du processus : C:\Windows\System32\services.exe

                            Informations sur le réseau :
                            Adresse du réseau : -
                            Port : -

                            Cet événement est généré lorsqu’un processus tente d’ouvrir une session pour un compte en spécifiant explicitement les informations d’identification de ce compte. Ceci se produit le plus souvent dans les configurations par lot comme les tâches planifiées, ou avec l’utilisation de la commande RUNAS.
                            Record Number: 10274
                            Source Name: Microsoft-Windows-Security-Auditing
                            Time Written: 20090405135033.608300-000
                            Event Type: Succès de l'audit
                            User:

                            ======Environment variables======

                            "ComSpec"=%SystemRoot%\system32\cmd.exe
                            "FP_NO_HOST_CHECK"=NO
                            "OS"=Windows_NT
                            "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem
                            "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
                            "PROCESSOR_ARCHITECTURE"=x86
                            "TEMP"=%SystemRoot%\TEMP
                            "TMP"=%SystemRoot%\TEMP
                            "USERNAME"=SYSTEM
                            "windir"=%SystemRoot%
                            "PROCESSOR_LEVEL"=6
                            "PROCESSOR_IDENTIFIER"=x86 Family 6 Model 15 Stepping 11, GenuineIntel
                            "PROCESSOR_REVISION"=0f0b
                            "NUMBER_OF_PROCESSORS"=4
                            "TRACE_FORMAT_SEARCH_PATH"=\\NTREL202.ntdev.corp.microsoft.com\4F18C3A5-CA09-4DBD-B6FC-219FDD4C6BE0\TraceFormat
                            "DFSTRACINGON"=FALSE

                            -----------------EOF-----------------
                            0
                            1. 2eme ; ps c koi RSIT ? Et ce rapport donne bc d'infos sur mon PC --'

                              Logfile of random's system information tool 1.06 (written by random/random)
                              Run by Fabien at 2010-02-26 20:14:17
                              Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 2
                              System drive C: has 89 GB (39%) free of 226 GB
                              Total RAM: 3071 MB (55% free)

                              Logfile of Trend Micro HijackThis v2.0.2
                              Scan saved at 20:14:50, on 26/02/2010
                              Platform: Windows Vista SP2 (WinNT 6.00.1906)
                              MSIE: Internet Explorer v8.00 (8.00.6001.18882)
                              Boot mode: Normal

                              Running processes:
                              C:\Windows\system32\taskeng.exe
                              C:\Windows\system32\Dwm.exe
                              C:\Windows\Explorer.EXE
                              C:\Windows\system32\conime.exe
                              C:\Program Files\Windows Defender\MSASCui.exe
                              C:\Windows\RtHDVCpl.exe
                              C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
                              C:\Windows\System32\rundll32.exe
                              C:\Program Files\Java\jre6\bin\jusched.exe
                              C:\Program Files\Alwil Software\Avast4\ashDisp.exe
                              C:\Windows\FixCamera.exe
                              C:\Windows\tsnp325.exe
                              C:\Windows\vsnp325.exe
                              C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe
                              C:\Users\Fabien\AppData\Local\Google\Update\1.2.183.17\GoogleCrashHandler.exe
                              C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                              C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                              C:\Windows\ehome\ehtray.exe
                              C:\Program Files\Free Download Manager\fdm.exe
                              C:\Program Files\Windows Media Player\wmpnscfg.exe
                              C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                              C:\Program Files\Free Music Zilla\FMZilla.exe
                              C:\Program Files\OpenOffice.org 3\program\soffice.exe
                              C:\Windows\ehome\ehmsas.exe
                              C:\Program Files\OpenOffice.org 3\program\soffice.bin
                              C:\Program Files\MessengerDiscovery 2\MessengerDiscovery 2.exe
                              C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
                              C:\Program Files\Windows Live\Contacts\wlcomm.exe
                              C:\Users\Fabien\AppData\Local\Google\Chrome\Application\chrome.exe
                              C:\Users\Fabien\AppData\Local\Google\Chrome\Application\chrome.exe
                              C:\Users\Fabien\AppData\Local\Google\Chrome\Application\chrome.exe
                              C:\Windows\system32\taskeng.exe
                              C:\Windows\system32\SearchFilterHost.exe
                              C:\Users\Fabien\Desktop\RSIT.exe
                              C:\Program Files\trend micro\Fabien.exe

                              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://format.packardbell.com/cgi-bin/redirect/?country=FR&range=AD&phase=8&key=IESTART
                              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/?gws_rd=ssl
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://fr.yahoo.com/?p=us
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaults/su/ymj/*https://fr.yahoo.com/?p=us
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/ymj/*http://www.yahoo.com/ext/search/search.html
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/ymj/*https://fr.yahoo.com/?p=us
                              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://home.sweetim.com/
                              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                              R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/ymj/*https://fr.yahoo.com/?p=us
                              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                              R3 - URLSearchHook: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - (no file)
                              O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                              O2 - BHO: Windows Live Family Safety Browser Helper - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll
                              O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
                              O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
                              O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                              O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll
                              O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
                              O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                              O2 - BHO: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - (no file)
                              O3 - Toolbar: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
                              O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                              O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                              O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                              O4 - HKLM\..\Run: [fssui] "C:\Program Files\Windows Live\Family Safety\fsui.exe" -autorun
                              O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                              O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
                              O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
                              O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                              O4 - HKLM\..\Run: [SearchSettings] C:\Program Files\Search Settings\SearchSettings.exe
                              O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                              O4 - HKLM\..\Run: [FixCamera] C:\Windows\FixCamera.exe
                              O4 - HKLM\..\Run: [tsnp325] C:\Windows\tsnp325.exe
                              O4 - HKLM\..\Run: [snp325] C:\Windows\vsnp325.exe
                              O4 - HKLM\..\Run: [Skytel] Skytel.exe
                              O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
                              O4 - HKCU\..\Run: [SmpcSys] C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe
                              O4 - HKCU\..\Run: [Google Update] "C:\Users\Fabien\AppData\Local\Google\Update\GoogleUpdate.exe" /c
                              O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                              O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                              O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                              O4 - HKCU\..\Run: [Free Download Manager] "C:\Program Files\Free Download Manager\fdm.exe" -autorun
                              O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                              O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                              O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                              O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                              O4 - Startup: Free Music Zilla.lnk = C:\Program Files\Free Music Zilla\FMZilla.exe
                              O4 - Startup: Free Music Zilla.lnk.disabled
                              O4 - Startup: OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
                              O4 - Startup: Ubisoft register.lnk = C:\Program Files\UBISOFT\Register\schedule.exe
                              O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                              O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
                              O8 - Extra context menu item: Tout télécharger avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
                              O8 - Extra context menu item: Télécharger avec Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
                              O8 - Extra context menu item: Télécharger la sélection avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
                              O8 - Extra context menu item: Télécharger la vidéo avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlfvideo.htm
                              O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                              O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                              O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
                              O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
                              O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
                              O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
                              O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
                              O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
                              O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
                              O13 - Gopher Prefix:
                              O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://download.divx.com/player/DivXBrowserPlugin.cab
                              O20 - AppInit_DLLs: C:\Windows\System32\diagperf32.dll
                              O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
                              O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                              O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                              O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                              O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                              O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                              O23 - Service: Google Updater Service (gusvc) - Unknown owner - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (file missing)
                              O23 - Service: NMIndexingService - Unknown owner - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe (file missing)
                              O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
                              O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\Windows\system32\IoctlSvc.exe
                              O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
                              O23 - Service: Zwunzi Service - Unknown owner - C:\ProgramData\Zwunzi\zwunzi141.exe (file missing)
                              0
                              1. Contributeur sécurité
                                vu

                                ==> RSIT
                                1
                                1. 1er scan avec FyK :

                                  ############################## | FindyKill V5.037 |

                                  # User : Fabien (Administrateurs) # PC-DE-FABIEN
                                  # Update on 18/02/2010 by El Desaparecido
                                  # Start at: 18:24:46 | 26/02/2010
                                  # Website : http://pagesperso-orange.fr/NosTools/index.html
                                  # Contact : FindyKill.Contact@gmail.com

                                  # Intel(R) Core(TM)2 Quad CPU Q6600 @ 2.40GHz
                                  # Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6002 32-bit) # Service Pack 2
                                  # Internet Explorer 8.0.6001.18882
                                  # Windows Firewall Status : Enabled

                                  # C:\ # Disque fixe local # 220,88 Go (87,56 Go free) [HDD] # NTFS
                                  # D:\ # Disque CD-ROM
                                  # E:\ # Disque amovible
                                  # F:\ # Disque amovible
                                  # G:\ # Disque amovible
                                  # H:\ # Disque amovible
                                  # L:\ # Disque CD-ROM # 6,31 Mo (0 Mo free) [U3 System] # CDFS
                                  # M:\ # Disque amovible # 7,47 Go (388,75 Mo free) # FAT32

                                  ############################## | Processus actifs |

                                  C:\Windows\System32\smss.exe
                                  C:\Windows\system32\csrss.exe
                                  C:\Windows\system32\wininit.exe
                                  C:\Windows\system32\csrss.exe
                                  C:\Windows\system32\services.exe
                                  C:\Windows\system32\lsass.exe
                                  C:\Windows\system32\lsm.exe
                                  C:\Windows\system32\winlogon.exe
                                  C:\Windows\system32\svchost.exe
                                  C:\Windows\system32\nvvsvc.exe
                                  C:\Windows\system32\svchost.exe
                                  C:\Windows\System32\svchost.exe
                                  C:\Windows\system32\LogonUI.exe
                                  C:\Windows\System32\svchost.exe
                                  C:\Windows\System32\svchost.exe
                                  C:\Windows\system32\svchost.exe
                                  C:\Windows\system32\svchost.exe
                                  C:\Windows\system32\SLsvc.exe
                                  C:\Windows\system32\svchost.exe
                                  C:\Windows\system32\rundll32.exe
                                  C:\Windows\system32\svchost.exe
                                  C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
                                  C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                  C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                  C:\Windows\System32\spoolsv.exe
                                  C:\Windows\system32\svchost.exe
                                  C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                  C:\Windows\system32\svchost.exe
                                  C:\Windows\System32\svchost.exe
                                  C:\Windows\system32\IoctlSvc.exe
                                  C:\Windows\System32\svchost.exe
                                  C:\Windows\system32\svchost.exe
                                  C:\Windows\system32\svchost.exe
                                  C:\Windows\System32\svchost.exe
                                  C:\Windows\system32\SearchIndexer.exe
                                  C:\Windows\system32\taskeng.exe
                                  C:\Windows\system32\WUDFHost.exe
                                  C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                                  C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                                  C:\Windows\system32\userinit.exe
                                  C:\Windows\system32\taskeng.exe
                                  C:\Windows\system32\Dwm.exe
                                  C:\Windows\Explorer.EXE
                                  C:\Windows\system32\taskeng.exe
                                  C:\Windows\system32\runonce.exe
                                  C:\Windows\system32\conime.exe
                                  C:\Windows\system32\wbem\wmiprvse.exe

                                  ################## | C: |

                                  (!) Non supprimé ! L:\autorun.inf

                                  ################## | C:\Windows |

                                  ################## | C:\Windows\Prefetch |

                                  ################## | C:\Windows\system32 |

                                  ################## | C:\Windows\system32\drivers |

                                  ################## | C:\Users\Fabien\AppData\Roaming |

                                  ################## | MD5 ... |

                                  ################## | CRC32 ... |

                                  ################## | Temporary Internet Files |

                                  ################## | Registre |

                                  ################## | Etat |

                                  # Mode sans echec : OK

                                  # Affichage des fichiers cachés : OK

                                  # Uac : OK

                                  # Ndisuio -> Start = 3 ( Good = 3 | Bad = 4 )
                                  # EapHost -> Start = 2 ( Good = 2 | Bad = 4 )
                                  # Wlansvc -> Start = 2 ( Good = 2 | Bad = 4 )
                                  # SharedAccess -> Start = 2 ( Good = 2 | Bad = 4 )
                                  # windefend -> Start = 2 ( Good = 2 | Bad = 4 )
                                  # wuauserv -> Start = 2 ( Good = 2 | Bad = 4 )
                                  # wscsvc -> Start = 2 ( Good = 2 | Bad = 4 )

                                  ################## | Fichiers corrompus # Réinstallation requise |

                                  ... OK !

                                  ################## | Upload |

                                  Veuillez envoyer le fichier : C:\FindyKill_Upload_Me_PC-de-Fabien.zip : https://www.ionos.fr/?affiliate_id=77097
                                  Merci pour votre contribution .

                                  ################## | ! Fin du rapport # FindyKill V5.037 ! |
                                  0
                                  1. Contributeur sécurité
                                    effectivement

                                    te rappelles tu quel virus a tu supprimé dernièrement ?

                                    1)

                                    ! Déconnecte toi et ferme toutes application en cours (navigateur compris ) .

                                    • Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...

                                    • Double clique sur setup.exe présent sur ton bureau pour lancer l’outil.

                                    • Au menu principal choisis l'option " F " pour français et tape sur [entrée] .

                                    • Au second menu choisis l'option 2 (suppression) et tape sur [entrée]

                                    • Le pc va redémarrer automatiquement ...

                                    ▶ le programme va travailler, ne touche à rien ... , ton bureau ne sera pas accessible c est normal !

                                    ► Poste le rapport qui apparaît à la fin ( le rapport est sauvegardé aussi sous C:\FindyKill.txt)

                                    Si le Bureau ne réapparaît pas, presse Ctrl + Alt + Suppr , Onglet "Fichier" , "Nouvelle tâche" , tape explorer.exe et valide

                                    ..................

                                    2)

                                    • Télécharge Random's System Information Tool (RSIT) de Random/Random.

                                    http://images.malwareremoval.com/random/RSIT.exe

                                    • Enregistre le sur ton Bureau.

                                    • Double clique sur RSIT.exe pour lancer l'outil.

                                    • Clique sur "Continue" à l'écran Disclaimer.

                                    • Si l'outil HijackThis n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu s'il te le demande)

                                    et tu devras accepter la licence.

                                    • Une fois le scan terminé, deux rapports vont apparaître : poste les dans deux messages séparés stp

                                    Les rapports se trouvent à cet endroit:
                                    C:\rsit\info.txt
                                    C:\rsit\log.txt

                                    1
                                    1. Tien le rapport :

                                      ############################## | FindyKill V5.037 |

                                      # User : Fabien (Administrateurs) # PC-DE-FABIEN
                                      # Update on 18/02/2010 by El Desaparecido
                                      # Start at: 18:05:21 | 26/02/2010
                                      # Website : http://pagesperso-orange.fr/NosTools/index.html
                                      # Contact : FindyKill.Contact@gmail.com

                                      # Intel(R) Core(TM)2 Quad CPU Q6600 @ 2.40GHz
                                      # Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6002 32-bit) # Service Pack 2
                                      # Internet Explorer 8.0.6001.18882
                                      # Windows Firewall Status : Enabled

                                      # C:\ # Disque fixe local # 220,88 Go (87,65 Go free) [HDD] # NTFS
                                      # D:\ # Disque CD-ROM
                                      # E:\ # Disque amovible
                                      # F:\ # Disque amovible
                                      # G:\ # Disque amovible
                                      # H:\ # Disque amovible

                                      ############################## | Processus actifs |

                                      C:\Windows\System32\smss.exe
                                      C:\Windows\system32\csrss.exe
                                      C:\Windows\system32\wininit.exe
                                      C:\Windows\system32\csrss.exe
                                      C:\Windows\system32\services.exe
                                      C:\Windows\system32\lsass.exe
                                      C:\Windows\system32\lsm.exe
                                      C:\Windows\system32\winlogon.exe
                                      C:\Windows\system32\svchost.exe
                                      C:\Windows\system32\nvvsvc.exe
                                      C:\Windows\system32\svchost.exe
                                      C:\Windows\System32\svchost.exe
                                      C:\Windows\System32\svchost.exe
                                      C:\Windows\System32\svchost.exe
                                      C:\Windows\system32\svchost.exe
                                      C:\Windows\system32\svchost.exe
                                      C:\Windows\system32\SLsvc.exe
                                      C:\Windows\system32\svchost.exe
                                      C:\Windows\system32\rundll32.exe
                                      C:\Windows\system32\svchost.exe
                                      C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
                                      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                      C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                      C:\Windows\System32\spoolsv.exe
                                      C:\Windows\system32\svchost.exe
                                      C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                      C:\Windows\system32\svchost.exe
                                      C:\Windows\System32\svchost.exe
                                      C:\Windows\system32\IoctlSvc.exe
                                      C:\Windows\System32\svchost.exe
                                      C:\Windows\system32\svchost.exe
                                      C:\Windows\system32\svchost.exe
                                      C:\Windows\System32\svchost.exe
                                      C:\Windows\system32\SearchIndexer.exe
                                      C:\Windows\system32\WUDFHost.exe
                                      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                                      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                                      C:\Windows\system32\taskeng.exe
                                      C:\Windows\system32\taskeng.exe
                                      C:\Windows\system32\Dwm.exe
                                      C:\Windows\Explorer.EXE
                                      C:\Program Files\Windows Defender\MSASCui.exe
                                      C:\Windows\RtHDVCpl.exe
                                      C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
                                      C:\Windows\System32\rundll32.exe
                                      C:\Program Files\Java\jre6\bin\jusched.exe
                                      C:\Program Files\Search Settings\SearchSettings.exe
                                      C:\Program Files\Alwil Software\Avast4\ashDisp.exe
                                      C:\Windows\FixCamera.exe
                                      C:\Windows\vsnp325.exe
                                      C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe
                                      C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                                      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                                      C:\Windows\ehome\ehtray.exe
                                      C:\Program Files\Free Download Manager\fdm.exe
                                      C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                                      C:\Program Files\OpenOffice.org 3\program\soffice.exe
                                      C:\Program Files\Windows Media Player\wmpnscfg.exe
                                      C:\Program Files\Windows Media Player\wmpnetwk.exe
                                      C:\Program Files\OpenOffice.org 3\program\soffice.bin
                                      C:\Users\Fabien\AppData\Local\Google\Update\1.2.183.17\GoogleCrashHandler.exe
                                      C:\Windows\ehome\ehmsas.exe
                                      C:\Program Files\MessengerDiscovery 2\MessengerDiscovery 2.exe
                                      C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
                                      C:\Program Files\Windows Live\Contacts\wlcomm.exe
                                      C:\Windows\system32\conime.exe
                                      C:\Windows\System32\mobsync.exe
                                      C:\Users\Fabien\AppData\Local\Google\Chrome\Application\chrome.exe
                                      C:\Users\Fabien\AppData\Local\Google\Chrome\Application\chrome.exe
                                      C:\Users\Fabien\AppData\Local\Google\Chrome\Application\chrome.exe
                                      C:\Users\Fabien\AppData\Local\Google\Chrome\Application\chrome.exe
                                      C:\Windows\system32\taskeng.exe
                                      C:\Windows\system32\SearchProtocolHost.exe
                                      C:\Windows\system32\SearchFilterHost.exe
                                      C:\Windows\system32\wbem\wmiprvse.exe

                                      ################## | C: |

                                      ################## | C:\Windows |

                                      ################## | C:\Windows\Prefetch |

                                      ################## | C:\Windows\system32 |

                                      ################## | C:\Windows\system32\drivers |

                                      ################## | C:\Users\Fabien\AppData\Roaming |

                                      ################## | Temporary Internet Files |

                                      ################## | Registre |

                                      ################## | Etat |

                                      # Affichage des fichiers cachés : OK

                                      # Mode sans echec : OK

                                      # Uac : OK

                                      # Ndisuio -> Start = 3 ( Good = 3 | Bad = 4 )
                                      # EapHost -> Start = 3 ( Good = 2 | Bad = 4 )
                                      # Wlansvc -> Start = 3 ( Good = 2 | Bad = 4 )
                                      # (!) SharedAccess -> Start = 4 ( Good = 2 | Bad = 4 )
                                      # windefend -> Start = 2 ( Good = 2 | Bad = 4 )
                                      # wuauserv -> Start = 2 ( Good = 2 | Bad = 4 )
                                      # (!) wscsvc -> Start = 4 ( Good = 2 | Bad = 4 )

                                      ################## | ! Fin du rapport # FindyKill V5.037 ! |
                                      1
                                      1. Contributeur sécurité
                                        bonjour

                                        • Téléchargez FindyKill sur le Bureau.

                                        http://pagesperso-orange.fr/NosTools/Chiquitine29/Setup.exe

                                        Mirroir :

                                        http://findykill.changelog.fr/Setup.exe

                                        • Double-cliquez sur FindyKill présent sur le Bureau.

                                        • Choisissez l'option 1 (Recherche).

                                        • Laissez travailler l'outil.

                                        • Ensuite postez le rapport FindyKill.txt qui apparaîtra (si vous avez créé un sujet sur un forum pour vous faire aider).

                                        • Note : Le rapport FindyKill.txt est sauvegardé à la racine du disque (C:\FindyKill.txt).

                                        (CTRL+A pour tout sélectionner , CTRL+C pour copier et CTRL+V pour coller)

                                        • Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
                                        Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
                                        Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.

                                        • Tuto : http://pagesperso-orange.fr/NosTools/index.html
                                        0