Google infecté

Résolu
Bonjour,

Depuis quelques jours, mes recherches sur google me redirigent vers d'autres sites, souvent les memes, pour antivirus par ex
La raison etant que j'ai telecharger un lien d'un ami sur facebook et depuis c'est l'horreur
J'ai un deuxieme probleme qui s'est cree suite à cela c'est que la navigation sur internet explorer est devenu assez lente

Apres de nombreuses recherches sur le forum je n'ai pas reussi à reparer le probleme tout seul. Je ne suis pas un génie de l'informatique mais je connais quelques termes
Je vous remercie par avance pour votre aide

46 réponses

Résumé de la discussion

La discussion porte sur des redirections de recherches Google et une lenteur de navigation après avoir cliqué sur un lien reçu, sous Windows Vista et Internet Explorer 7. Plusieurs propositions suggèrent d’éliminer des éléments indésirables et d’analyser le système avec des outils de sécurité tels que HijackThis, ToolsCleaner ou UsbFix pour déceler les redirections et les extensions indésirables. D'autres conseils évoquent de nettoyer les programmes suspects, désactiver les barres d'outils ou réinitialiser les paramètres de navigation, et de vérifier les rapports générés pour écarter malware ou adware. Une nuance utile : les symptômes peuvent provenir de plusieurs extensions ou programmes résidents en démarrage, et il peut être pertinent d’analyser les processus et les téléchargements récents pour cibler les sources.

Bobot (l’IA à votre service)
  1. Voilà, je viens de tester et jusque là, plus de redirection google.
    ouf.
    merci pour la ligne de conduite donnée lors du dernier cas, ça marche!
    amicalement.
    0
    1. Voilà pour la partie Log Txt, c'est fini... :-)

      mais dans tous les cas, je tiens à vous remercier si vous savez y jeter un coup d'oeil.
      0
      1. Part VI:

        ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

        R0 PxHelp20;PxHelp20; C:\Windows\System32\Drivers\PxHelp20.sys [2009-01-10 43528]
        R2 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796};{49DE1C67-83F8-4102-99E0-C16DCC7EEC796}; \??\C:\Program Files\CyberLink\PlayMovie\000.fcl [2008-03-31 41456]
        R2 int15;int15; \??\C:\Windows\system32\drivers\int15.sys [2008-07-16 15392]
        R2 NPF;NetGroup Packet Filter Driver; C:\Windows\system32\drivers\npf.sys [2009-10-21 50704]
        R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2009-05-18 26600]
        R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys [2008-07-11 2381312]
        R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2008-08-04 2161496]
        R3 netr73;RT73 USB Wireless LAN Card Driver for Vista; C:\Windows\system32\DRIVERS\netr73.sys [2008-03-04 489984]
        R3 RTL8169;Realtek 8169 NT Driver; C:\Windows\system32\DRIVERS\Rtlh86.sys [2008-08-06 124928]
        R3 RTSTOR;Realtek USB 2.0 Card Reader; C:\Windows\system32\drivers\RTSTOR.SYS [2008-02-20 60416]
        R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2007-06-08 187448]
        R3 usbvideo;Périphérique vidéo USB (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2008-01-21 134016]
        S1 SRTSP;SRTSP; \??\C:\Windows\system32\drivers\NIS\1000000.07D\SRTSP.SYS []
        S1 SRTSPX;SRTSPX; \??\C:\Windows\system32\drivers\NIS\1000000.07D\SRTSPX.SYS []
        S3 ACSSCR;ACR38 Smart Card Reader; C:\Windows\system32\DRIVERS\a38usbxp.sys [2004-04-30 24832]
        S3 ActionReplayDS;ActionReplayDS; C:\Windows\System32\Drivers\ActionReplayDS.sys [2007-02-08 29184]
        S3 AVFSFilter;AVFSFilter; C:\Windows\system32\DRIVERS\avfsfilter.sys [2010-03-11 10264]
        S3 BthAvrcp;Profil AVRCP Bluetooth; C:\Windows\system32\DRIVERS\BthAvrcp.sys [2008-07-10 15872]
        S3 BthEnum;Service d'énumérateur Bluetooth; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-04-11 22528]
        S3 BthPan;Périphérique Bluetooth (réseau personnel); C:\Windows\system32\DRIVERS\bthpan.sys [2008-01-21 92160]
        S3 BTHPORT;Pilote de port Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2009-04-11 507904]
        S3 BTHUSB;Pilote USB radio Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2009-04-11 29696]
        S3 Dot4;Pilote MS IEEE-1284.4; C:\Windows\system32\DRIVERS\Dot4.sys [2008-01-21 131584]
        S3 Dot4Print;Pilote de classe Imprimante pour IEEE-1284.4; C:\Windows\system32\DRIVERS\Dot4Prt.sys [2008-01-21 16384]
        S3 dot4usb;MS Dot4USB Filter Dot4USB Filter; C:\Windows\system32\DRIVERS\dot4usb.sys [2008-01-21 36864]
        S3 drmkaud;Filtre de décodeur DRM (Noyau Microsoft); C:\Windows\system32\drivers\drmkaud.sys [2008-01-21 5632]
        S3 HdAudAddService;Pilote de fonction UAA 1.1 Microsoft pour le service High Definition Audio; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
        S3 MSKSSRV;Proxy de service de répartition Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-21 8192]
        S3 MSPCLOCK;Proxy d'horloge de répartition Microsoft; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-21 5888]
        S3 MSPQM;Proxy de gestion de qualité de répartition Microsoft; C:\Windows\system32\drivers\MSPQM.sys [2008-01-21 5504]
        S3 MSTEE;Convertisseur en T/site-à-site de répartition Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2008-01-21 6016]
        S3 NAVENG;NAVENG; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20080829.024\NAVENG.SYS []
        S3 NAVEX15;NAVEX15; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20080829.024\NAVEX15.SYS []
        S3 NETw5v32;Pilote de carte Intel(R) Wireless WiFi Link pour Windows Vista 32 bits ; C:\Windows\system32\DRIVERS\NETw5v32.sys [2008-04-28 3658752]
        S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfd.sys [2008-08-26 18816]
        S3 PIXMCV;Victor Communication PIX-MCV Driver; C:\Windows\System32\Drivers\pixmcvc.sys [2004-06-03 33792]
        S3 PIXMCVA;Victor PIX-MCV Audio Capture; C:\Windows\System32\Drivers\pixmcva.sys [2004-03-20 38144]
        S3 PIXMCVV;Victor PIX-MCV Video Capture; C:\Windows\System32\Drivers\pixmcvv.sys [2004-03-27 32768]
        S3 RFCOMM;Périphérique Bluetooth (TDI protocole RFCOMM); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-04-11 148992]
        S3 StillCam;Pilote d'appareil photo numérique série; C:\Windows\system32\DRIVERS\serscan.sys [2008-01-21 9216]
        S3 USBAAPL;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl.sys [2010-04-19 41984]
        S3 usbaudio;Pilote USB audio (WDM); C:\Windows\system32\drivers\usbaudio.sys [2009-04-11 73216]
        S3 USBCCID;Lecteur de cartes à puce USB; C:\Windows\system32\DRIVERS\usbccid.sys [2009-04-11 30208]
        S3 usbscan;Pilote de scanneur USB; C:\Windows\system32\DRIVERS\usbscan.sys [2008-01-21 35328]
        S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-21 83328]
        S4 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys [2008-01-21 6656]
        S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-01-21 386616]

        ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

        R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2010-06-10 144176]
        R2 Bonjour Service;Service Bonjour; C:\Program Files\Bonjour\mDNSResponder.exe [2010-05-18 345376]
        R2 BthServ;@%SystemRoot%\System32\bthserv.dll,-101; C:\Windows\system32\svchost.exe [2008-01-21 21504]
        R2 Common Toolkit Service;Common Toolkit Service; C:\Program Files\Common Files\Common Toolkit Suite\FighterSuiteService.exe [2010-02-18 684680]
        R2 ETService;Empowering Technology Service; C:\Program Files\Packard Bell\Packard Bell Recovery Management\Service\ETService.exe [2008-07-16 24576]
        R2 ezSharedSvc;Easybits Shared Services for Windows; C:\Windows\system32\svchost.exe [2008-01-21 21504]
        R2 hpqddsvc;Service HP CUE DeviceDiscovery; C:\Windows\system32\svchost.exe [2008-01-21 21504]
        R2 HPSLPSVC;HP Network Devices Support; C:\Windows\system32\svchost.exe [2008-01-21 21504]
        R2 Nero BackItUp Scheduler 3;Nero BackItUp Scheduler 3; C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe [2008-02-18 877864]
        R2 Net Driver HPZ12;Net Driver HPZ12; C:\Windows\System32\svchost.exe [2008-01-21 21504]
        R2 PLFlash DeviceIoControl Service;PLFlash DeviceIoControl Service; C:\Windows\system32\IoctlSvc.exe [2006-12-19 81920]
        R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\Windows\System32\svchost.exe [2008-01-21 21504]
        R2 SPAMfighter Update Service;SPAMfighter Update Service; C:\Program Files\Fighters\SPAMfighter\sfus.exe [2010-02-18 189064]
        R3 hpqcxs08;hpqcxs08; C:\Windows\system32\svchost.exe [2008-01-21 21504]
        R3 ServiceLayer;ServiceLayer; C:\Program Files\Nokia\PC Connectivity Solution\ServiceLayer.exe [2010-02-26 652800]
        S2 AV Engine Scanning Service;AV Engine Scanning Service; C:/Program Files/Common Files/Common Toolkit Suite/AVEngine/AVScanningService.exe []
        S2 gupdate1c9e2b02172f5b6;Service Google Update (gupdate1c9e2b02172f5b6); C:\Program Files\Google\Update\GoogleUpdate.exe [2009-06-01 133104]
        S2 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-08-12 190448]
        S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2009-01-10 654848]
        S3 GoogleDesktopManager-110309-193829;Google Desktop Manager 5.9.911.3589; C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [2010-03-23 30192]
        S3 iPod Service;Service de l'iPod; C:\Program Files\iPod\bin\iPodService.exe [2010-07-21 540968]
        S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2008-10-25 65888]
        S3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe [2008-04-28 529704]
        S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
        S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]

        -----------------EOF-----------------
        0
        1. Part V

          C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
          HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

          C:\Users\Christophe\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
          LimeWire On Startup.lnk - C:\Program Files\LimeWire\LimeWire.exe

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
          "AppInit_DLLs"="C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL"

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet32]
          cryptnet32.dll []

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
          C:\Windows\system32\igfxdev.dll [2008-07-11 208896]

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
          "{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]

          [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]

          [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]

          [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]

          [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]

          [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
          "ConsentPromptBehaviorAdmin"=0
          "EnableLUA"=0
          "dontdisplaylastusername"=0
          "legalnoticecaption"=
          "legalnoticetext"=
          "shutdownwithoutlogon"=1
          "undockwithoutlogon"=1
          "EnableUIADesktopToggle"=0

          [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
          "NoDriveAutoRun"=0
          "NoDriveTypeAutoRun"=0

          [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
          "BindDirectlyToPropertySetStorage"=0
          "NoDriveAutoRun"=0
          "NoDriveTypeAutoRun"=0

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

          ======File associations======

          .js - edit - C:\Windows\System32\Notepad.exe %1
          .js - open - C:\Windows\System32\WScript.exe "%1" %*

          ======List of files/folders created in the last 3 months======

          2010-08-10 10:02:45 ----D---- C:\Program Files\trend micro
          2010-08-10 10:02:44 ----D---- C:\rsit
          2010-08-10 10:02:15 ----D---- C:\Users\Christophe\AppData\Roaming\HPAppData
          2010-08-09 23:00:11 ----D---- C:\Users\Christophe\AppData\Roaming\Malwarebytes
          2010-08-09 23:00:04 ----A---- C:\Windows\system32\drivers\mbamswissarmy.sys
          2010-08-09 23:00:03 ----D---- C:\ProgramData\Malwarebytes
          2010-08-09 23:00:03 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
          2010-08-09 23:00:03 ----A---- C:\Windows\system32\drivers\mbam.sys
          2010-08-09 22:36:14 ----RASHD---- C:\Autorun.inf
          2010-08-09 22:33:45 ----A---- C:\UsbFix.txt
          2010-08-09 22:15:29 ----D---- C:\UsbFix
          2010-08-04 17:08:30 ----D---- C:\Program Files\iPod
          2010-07-14 15:35:05 ----A---- C:\Windows\system32\xinput1_1.dll
          2010-07-14 15:35:03 ----A---- C:\Windows\system32\xactengine2_1.dll
          2010-07-14 15:34:57 ----A---- C:\Windows\system32\xactengine2_0.dll
          2010-07-14 15:34:57 ----A---- C:\Windows\system32\x3daudio1_0.dll
          2010-07-14 15:34:57 ----A---- C:\Windows\system32\d3dx9_29.dll
          2010-07-14 15:34:56 ----A---- C:\Windows\system32\d3dx9_27.dll
          2010-07-14 15:34:56 ----A---- C:\Windows\system32\d3dx9_26.dll
          2010-07-14 15:34:56 ----A---- C:\Windows\system32\d3dx9_25.dll
          2010-07-14 15:34:56 ----A---- C:\Windows\system32\d3dx9_24.dll
          2010-07-14 15:29:00 ----D---- C:\Program Files\Ubisoft
          2010-06-27 14:32:42 ----A---- C:\Windows\system32\drivers\pccsmcfd.sys
          2010-06-12 16:36:36 ----D---- C:\Windows\system32\Adobe
          2010-05-27 16:17:51 ----A---- C:\Windows\system32\drivers\ActionReplayDS.sys
          2010-05-27 16:16:23 ----D---- C:\Program Files\Datel
          2010-05-26 22:57:16 ----A---- C:\Windows\system32\javaws.exe
          2010-05-26 22:57:16 ----A---- C:\Windows\system32\javaw.exe
          2010-05-26 22:57:16 ----A---- C:\Windows\system32\java.exe
          2010-05-26 22:57:16 ----A---- C:\Windows\system32\deployJava1.dll
          2010-05-25 05:38:36 ----D---- C:\Program Files\Ask.com
          2010-05-19 14:21:07 ----D---- C:\Users\Christophe\AppData\Roaming\Dofus.C9ECCBDBA4E09304DEEFB106465BC17F6D6749B9.1
          2010-05-19 14:18:37 ----D---- C:\Users\Christophe\AppData\Roaming\Reg.C9ECCBDBA4E09304DEEFB106465BC17F6D6749B9.1
          2010-05-19 14:18:37 ----D---- C:\Users\Christophe\AppData\Roaming\app
          2010-05-19 14:18:34 ----D---- C:\Users\Christophe\AppData\Roaming\Dofus-2.C9ECCBDBA4E09304DEEFB106465BC17F6D6749B9.1
          2010-05-19 14:18:34 ----D---- C:\Users\Christophe\AppData\Roaming\Dofus 2
          2010-05-18 22:09:22 ----D---- C:\Program Files\Dofus 2
          2010-05-18 22:09:21 ----D---- C:\Program Files\Common Files\Adobe AIR
          2010-05-18 16:35:16 ----A---- C:\Windows\system32\dns-sd.exe
          2010-05-18 16:35:16 ----A---- C:\Windows\system32\dnssd.dll

          ======List of files/folders modified in the last 3 months======

          2010-08-10 10:02:59 ----D---- C:\Users\Christophe\AppData\Roaming\LimeWire
          2010-08-10 10:02:55 ----D---- C:\Windows\Prefetch
          2010-08-10 10:02:47 ----D---- C:\Windows\Temp
          2010-08-10 10:02:45 ----D---- C:\Program Files
          2010-08-10 10:00:38 ----SHD---- C:\Windows\Installer
          2010-08-10 09:58:55 ----D---- C:\Windows\Tasks
          2010-08-10 09:56:49 ----D---- C:\Program Files\Common Files\Common Toolkit Suite
          2010-08-10 09:56:24 ----D---- C:\Windows\system32\drivers
          2010-08-10 09:56:24 ----D---- C:\Windows\System32
          2010-08-10 09:55:21 ----D---- C:\Windows\Performance
          2010-08-10 09:46:59 ----HD---- C:\ProgramData
          2010-08-10 09:46:58 ----D---- C:\Windows
          2010-08-10 08:13:58 ----SHD---- C:\System Volume Information
          2010-08-09 22:36:11 ----SHD---- C:\$Recycle.Bin
          2010-08-09 22:35:52 ----D---- C:\Windows\inf
          2010-08-09 22:35:52 ----A---- C:\Windows\system32\PerfStringBackup.INI
          2010-08-09 10:45:47 ----SD---- C:\Windows\Downloaded Program Files
          2010-08-07 22:52:18 ----A---- C:\Windows\NeroDigital.ini
          2010-08-04 17:09:03 ----D---- C:\Program Files\iTunes
          2010-08-04 17:08:29 ----D---- C:\Program Files\Common Files\Apple
          2010-07-14 20:17:35 ----HD---- C:\Program Files\InstallShield Installation Information
          2010-07-14 20:06:08 ----D---- C:\ProgramData\Google
          2010-07-14 15:35:03 ----RSD---- C:\Windows\assembly
          2010-07-14 15:35:00 ----D---- C:\Windows\Microsoft.NET
          2010-07-13 18:39:12 ----D---- C:\Users\Christophe\AppData\Roaming\HpUpdate
          2010-06-29 00:00:16 ----D---- C:\Windows\system32\catroot2
          2010-06-27 21:13:16 ----D---- C:\Windows\system32\catroot
          2010-06-27 14:34:58 ----D---- C:\Windows\SoftwareDistribution
          2010-06-27 14:34:55 ----D---- C:\Windows\system32\drivers\UMDF
          2010-06-27 14:34:21 ----D---- C:\Windows\Globalization
          2010-06-27 14:34:18 ----D---- C:\Program Files\Nokia
          2010-06-27 14:34:02 ----RSD---- C:\Windows\Fonts
          2010-06-27 14:33:39 ----D---- C:\Program Files\Common Files\Nokia
          2010-06-27 14:33:10 ----D---- C:\Windows\winsxs
          2010-06-27 14:32:42 ----DC---- C:\Windows\system32\DRVSTORE
          2010-06-27 09:07:49 ----D---- C:\ProgramData\Adobe
          2010-06-27 09:07:49 ----D---- C:\Program Files\Common Files\Adobe
          2010-06-27 09:07:43 ----D---- C:\Program Files\Adobe
          2010-06-20 13:36:43 ----A---- C:\Windows\win.ini
          2010-06-20 13:35:52 ----D---- C:\Windows\twain_32
          2010-06-20 13:32:34 ----D---- C:\Users\Christophe\AppData\Roaming\Apple Computer
          2010-06-20 11:02:38 ----D---- C:\Program Files\Bonjour
          2010-06-16 12:55:35 ----D---- C:\Windows\LiveKernelReports
          2010-06-12 16:37:21 ----D---- C:\Windows\system32\Macromed
          2010-06-02 20:16:04 ----SD---- C:\Users\Christophe\AppData\Roaming\Microsoft
          2010-05-30 09:02:14 ----D---- C:\ProgramData\Common Toolkit Suite
          2010-05-26 22:57:13 ----D---- C:\Program Files\Java
          2010-05-25 05:38:41 ----D---- C:\Windows\system32\Tasks
          2010-05-25 05:38:12 ----D---- C:\Program Files\LimeWire
          2010-05-18 22:09:22 ----D---- C:\Users\Christophe\AppData\Roaming\Adobe
          2010-05-18 22:09:21 ----D---- C:\Program Files\Common Files
          2010-05-13 10:01:50 ----A---- C:\Windows\DVDShrink.txt
          2010-05-13 09:55:33 ----D---- C:\Program Files\Google
          0
          1. Part IV

            ======Scheduled tasks folder======

            C:\Windows\tasks\Google Software Updater.job
            C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
            C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
            C:\Windows\tasks\ParetoLogic Registration.job
            C:\Windows\tasks\Registry_Doktor.job

            ======Registry dump======

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0347C33E-8762-4905-BF09-768834316C61}]
            HP Print Enhancer - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2009-10-22 328248]

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
            Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-06-19 75200]

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
            Groove GFS Browser Helper - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
            Programme d'aide de l'Assistant de connexion Windows Live - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-02-17 408440]

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
            Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2010-07-14 278192]

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
            Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll [2010-07-14 814648]

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
            LimeWire Toolbar - C:\Program Files\Ask.com\GenericAskToolbar.dll [2010-03-28 1196936]

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
            Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-05-03 41760]

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856}]
            HP Smart BHO Class - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2009-10-22 517688]

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
            {D4027C7F-154A-4066-A1AD-4243D8127440} - LimeWire Toolbar - C:\Program Files\Ask.com\GenericAskToolbar.dll [2010-03-28 1196936]
            {2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2010-07-14 278192]

            [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
            "Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-21 1008184]
            "SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2007-06-08 894512]
            "Google Desktop Search"=C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [2010-03-23 30192]
            "SmpcSys"=C:\Program Files\Packard Bell\SetupMyPC\SmpSys.exe [2008-07-07 1038136]
            "RtHDVCpl"=C:\Windows\RtHDVCpl.exe [2008-08-04 6265376]
            "IgfxTray"=C:\Windows\system32\igfxtray.exe [2008-08-12 150040]
            "HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2008-08-12 170520]
            "Persistence"=C:\Windows\system32\igfxpers.exe [2008-08-12 145944]
            "eRecoveryService"= []
            "PCMAgent"=C:\Program Files\CyberLink\PowerCinema\PCMAgent.exe [2008-03-21 143360]
            "CLMLServer"=C:\Program Files\CyberLink\PowerCinema\Kernel\CLML\CLMLSvc.exe [2008-04-11 196608]
            "PlayMovie"=C:\Program Files\CyberLink\PlayMovie\PMVService.exe [2008-03-31 172032]
            "GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2008-10-25 31072]
            "beid"=C:\Program Files\Belgium Identity Card\beid35gui.exe [2009-06-04 2056192]
            "AppleSyncNotifier"=C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe [2010-03-16 47392]
            "NokiaMusic FastStart"=C:\Program Files\Nokia\Ovi Player\NokiaOviPlayer.exe [2010-03-04 2192672]
            "HP Software Update"=C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2010-06-09 49208]
            ""= []
            "SWPROguard"=C:\Program Files\Fighters\SPYWAREfighter\SWPROTray.exe [2010-03-11 586376]
            "VFPROguard"=C:\Program Files\Fighters\VIRUSfighter\VFPROTray.exe [2010-03-11 684680]
            "sfagent"=C:\Program Files\Fighters\SPAMfighter\sfagent.exe [2010-02-18 386696]
            "QuickTime Task"=C:\Program Files\QuickTime Alternative\QTTask.exe [2010-03-17 421888]
            "Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-06-20 35760]
            "Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-06-09 976832]
            "NokiaMServer"=C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles startup []
            "iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2010-07-21 141608]

            [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
            "SmpcSys"=C:\Program Files\PACKARD BELL\SetUpMyPC\SmpSys.exe [2008-07-07 1038136]
            "IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe [2008-04-28 1828136]
            "swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2009-05-29 68856]
            "PC Suite Tray"=C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe [2009-06-25 1414144]
            "RegDokFRScheduler"=C:\Program Files\RegistryDoktor 4.1\RegistryDoktor.exe SCHEDULER []
            "WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe [2008-01-21 202240]
            0
            1. Part III

              O23 - Service: Easybits Shared Services for Windows (ezSharedSvc) - Unknown owner - C:\Windows\system32\svchost.exe
              O23 - Service: @%systemroot%\system32\fdPHost.dll,-100 (fdPHost) - Unknown owner - C:\Windows\system32\svchost.exe
              O23 - Service: @%systemroot%\system32\fdrespub.dll,-100 (FDResPub) - Unknown owner - C:\Windows\system32\svchost.exe
              O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
              O23 - Service: Google Desktop Manager 5.9.911.3589 (GoogleDesktopManager-110309-193829) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
              O23 - Service: @gpapi.dll,-112 (gpsvc) - Unknown owner - C:\Windows\system32\svchost.exe
              O23 - Service: Service Google Update (gupdate1c9e2b02172f5b6) (gupdate1c9e2b02172f5b6) - Unknown owner - C:\Program Files\Google\Update\GoogleUpdate.exe
              O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
              O23 - Service: @%SystemRoot%\System32\hidserv.dll,-101 (hidserv) - Unknown owner - C:\Windows\system32\svchost.exe
              O23 - Service: @%SystemRoot%\system32\kmsvc.dll,-6 (hkmsvc) - Unknown owner - C:\Windows\System32\svchost.exe
              O23 - Service: hpqcxs08 - Unknown owner - C:\Windows\system32\svchost.exe
              O23 - Service: Service HP CUE DeviceDiscovery (hpqddsvc) - Unknown owner - C:\Windows\system32\svchost.exe
              O23 - Service: HP Network Devices Support (HPSLPSVC) - Unknown owner - C:\Windows\system32\svchost.exe
              O23 - Service: @%SystemRoot%\system32\ikeext.dll,-501 (IKEEXT) - Unknown owner - C:\Windows\system32\svchost.exe
              O23 - Service: @%systemroot%\system32\IPBusEnum.dll,-102 (IPBusEnum) - Unknown owner - C:\Windows\system32\svchost.exe
              O23 - Service: @%SystemRoot%\system32\iphlpsvc.dll,-200 (iphlpsvc) - Unknown owner - C:\Windows\System32\svchost.exe
              O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
              O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe
              O23 - Service: @comres.dll,-2946 (KtmRm) - Unknown owner - C:\Windows\System32\svchost.exe
              O23 - Service: @%systemroot%\system32\srvsvc.dll,-100 (LanmanServer) - Unknown owner - C:\Windows\system32\svchost.exe
              O23 - Service: @%systemroot%\system32\wkssvc.dll,-100 (LanmanWorkstation) - Unknown owner - C:\Windows\System32\svchost.exe
              O23 - Service: @%SystemRoot%\system32\lltdres.dll,-1 (lltdsvc) - Unknown owner - C:\Windows\System32\svchost.exe
              O23 - Service: @%SystemRoot%\system32\lmhsvc.dll,-101 (lmhosts) - Unknown owner - C:\Windows\system32\svchost.exe
              O23 - Service: @%systemroot%\system32\mmcss.dll,-100 (MMCSS) - Unknown owner - C:\Windows\system32\svchost.exe
              O23 - Service: @%SystemRoot%\system32\FirewallAPI.dll,-23090 (MpsSvc) - Unknown owner - C:\Windows\system32\svchost.exe
              O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe
              O23 - Service: @%SystemRoot%\system32\iscsidsc.dll,-5000 (MSiSCSI) - Unknown owner - C:\Windows\system32\svchost.exe
              O23 - Service: @%SystemRoot%\system32\msimsg.dll,-27 (msiserver) - Unknown owner - C:\Windows\system32\msiexec.exe
              O23 - Service: @%SystemRoot%\system32\qagentrt.dll,-6 (napagent) - Unknown owner - C:\Windows\System32\svchost.exe
              O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
              O23 - Service: Net Driver HPZ12 - Unknown owner - C:\Windows\System32\svchost.exe
              O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe
              O23 - Service: @%SystemRoot%\system32\netman.dll,-109 (Netman) - Unknown owner - C:\Windows\System32\svchost.exe
              O23 - Service: @%SystemRoot%\system32\netprof.dll,-246 (netprofm) - Unknown owner - C:\Windows\System32\svchost.exe
              O23 - Service: @%SystemRoot%\System32\nlasvc.dll,-1 (NlaSvc) - Unknown owner - C:\Windows\System32\svchost.exe
              O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
              O23 - Service: Norton Internet Security - Nero AG - (no file)
              O23 - Service: @%SystemRoot%\system32\nsisvc.dll,-200 (nsi) - Unknown owner - C:\Windows\system32\svchost.exe
              O23 - Service: @%SystemRoot%\system32\p2psvc.dll,-8004 (p2pimsvc) - Unknown owner - C:\Windows\System32\svchost.exe
              O23 - Service: @%SystemRoot%\system32\p2psvc.dll,-8006 (p2psvc) - Unknown owner - C:\Windows\System32\svchost.exe
              O23 - Service: @%SystemRoot%\system32\pcasvc.dll,-1 (PcaSvc) - Unknown owner - C:\Windows\system32\svchost.exe
              O23 - Service: @%systemroot%\system32\pla.dll,-500 (pla) - Unknown owner - C:\Windows\System32\svchost.exe
              O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\Windows\system32\IoctlSvc.exe
              O23 - Service: @%SystemRoot%\system32\umpnpmgr.dll,-100 (PlugPlay) - Unknown owner - C:\Windows\system32\svchost.exe
              O23 - Service: Pml Driver HPZ12 - Unknown owner - C:\Windows\System32\svchost.exe
              O23 - Service: @%SystemRoot%\system32\p2psvc.dll,-8002 (PNRPAutoReg) - Unknown owner - C:\Windows\System32\svchost.exe
              O23 - Service: @%SystemRoot%\system32\p2psvc.dll,-8000 (PNRPsvc) - Unknown owner - C:\Windows\System32\svchost.exe
              O23 - Service: @%SystemRoot%\System32\polstore.dll,-5010 (PolicyAgent) - Unknown owner - C:\Windows\system32\svchost.exe
              O23 - Service: @%systemroot%\system32\profsvc.dll,-300 (ProfSvc) - Unknown owner - C:\Windows\system32\svchost.exe
              O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe
              O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - C:\Windows\system32\svchost.exe
              O23 - Service: @%Systemroot%\system32\rasauto.dll,-200 (RasAuto) - Unknown owner - C:\Windows\system32\svchost.exe
              O23 - Service: @%Systemroot%\system32\rasmans.dll,-200 (RasMan) - Unknown owner - C:\Windows\system32\svchost.exe
              O23 - Service: @regsvc.dll,-1 (RemoteRegistry) - Unknown owner - C:\Windows\system32\svchost.exe
              O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe
              O23 - Service: @oleres.dll,-5010 (RpcSs) - Unknown owner - C:\Windows\system32\svchost.exe
              O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe
              O23 - Service: @%SystemRoot%\System32\SCardSvr.dll,-1 (SCardSvr) - Unknown owner - C:\Windows\system32\svchost.exe
              O23 - Service: @%SystemRoot%\system32\schedsvc.dll,-100 (Schedule) - Unknown owner - C:\Windows\system32\svchost.exe
              O23 - Service: @%SystemRoot%\System32\certprop.dll,-13 (SCPolicySvc) - Unknown owner - C:\Windows\system32\svchost.exe
              O23 - Service: @%SystemRoot%\system32\sdrsvc.dll,-107 (SDRSVC) - Unknown owner - C:\Windows\system32\svchost.exe
              O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - C:\Windows\system32\svchost.exe
              O23 - Service: @%SystemRoot%\system32\Sens.dll,-200 (SENS) - Unknown owner - C:\Windows\system32\svchost.exe
              O23 - Service: ServiceLayer - Nokia - C:\Program Files\Nokia\PC Connectivity Solution\ServiceLayer.exe
              O23 - Service: @%SystemRoot%\System32\SessEnv.dll,-1026 (SessionEnv) - Unknown owner - C:\Windows\System32\svchost.exe
              O23 - Service: @%SystemRoot%\System32\shsvcs.dll,-12288 (ShellHWDetection) - Unknown owner - C:\Windows\System32\svchost.exe
              O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe
              O23 - Service: @%SystemRoot%\system32\SLUINotify.dll,-103 (SLUINotify) - Unknown owner - C:\Windows\system32\svchost.exe
              O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe
              O23 - Service: SPAMfighter Update Service - SPAMfighter ApS - C:\Program Files\Fighters\SPAMfighter\sfus.exe
              O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe
              O23 - Service: @%systemroot%\system32\ssdpsrv.dll,-100 (SSDPSRV) - Unknown owner - C:\Windows\system32\svchost.exe
              O23 - Service: @%SystemRoot%\system32\sstpsvc.dll,-200 (SstpSvc) - Unknown owner - C:\Windows\system32\svchost.exe
              O23 - Service: @%SystemRoot%\system32\wiaservc.dll,-9 (stisvc) - Unknown owner - C:\Windows\system32\svchost.exe
              O23 - Service: @%SystemRoot%\System32\swprv.dll,-103 (swprv) - Unknown owner - C:\Windows\System32\svchost.exe
              O23 - Service: @%SystemRoot%\system32\sysmain.dll,-1000 (SysMain) - Unknown owner - C:\Windows\system32\svchost.exe
              O23 - Service: @%SystemRoot%\system32\TabSvc.dll,-100 (TabletInputService) - Unknown owner - C:\Windows\System32\svchost.exe
              O23 - Service: @%SystemRoot%\system32\tapisrv.dll,-10100 (TapiSrv) - Unknown owner - C:\Windows\System32\svchost.exe
              O23 - Service: @%SystemRoot%\system32\tbssvc.dll,-100 (TBS) - Unknown owner - C:\Windows\System32\svchost.exe
              O23 - Service: @%SystemRoot%\System32\termsrv.dll,-268 (TermService) - Unknown owner - C:\Windows\System32\svchost.exe
              O23 - Service: @%SystemRoot%\System32\shsvcs.dll,-8192 (Themes) - Unknown owner - C:\Windows\System32\svchost.exe
              O23 - Service: @%systemroot%\system32\mmcss.dll,-102 (THREADORDER) - Unknown owner - C:\Windows\system32\svchost.exe
              O23 - Service: @%SystemRoot%\system32\trkwks.dll,-1 (TrkWks) - Unknown owner - C:\Windows\System32\svchost.exe
              O23 - Service: @%SystemRoot%\servicing\TrustedInstaller.exe,-100 (TrustedInstaller) - Unknown owner - C:\Windows\servicing\TrustedInstaller.exe
              O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe
              O23 - Service: @%systemroot%\system32\upnphost.dll,-213 (upnphost) - Unknown owner - C:\Windows\system32\svchost.exe
              O23 - Service: @%SystemRoot%\system32\dwm.exe,-2000 (UxSms) - Unknown owner - C:\Windows\System32\svchost.exe
              O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe
              O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe
              O23 - Service: @%SystemRoot%\system32\w32time.dll,-200 (W32Time) - Unknown owner - C:\Windows\system32\svchost.exe
              O23 - Service: @%SystemRoot%\system32\wcncsvc.dll,-3 (wcncsvc) - Unknown owner - C:\Windows\System32\svchost.exe
              O23 - Service: @%SystemRoot%\system32\WcsPlugInService.dll,-200 (WcsPlugInService) - Unknown owner - C:\Windows\system32\svchost.exe
              O23 - Service: @%systemroot%\system32\wdi.dll,-502 (WdiServiceHost) - Unknown owner - C:\Windows\System32\svchost.exe
              O23 - Service: @%systemroot%\system32\wdi.dll,-500 (WdiSystemHost) - Unknown owner - C:\Windows\System32\svchost.exe
              O23 - Service: @%systemroot%\system32\webclnt.dll,-100 (WebClient) - Unknown owner - C:\Windows\system32\svchost.exe
              O23 - Service: @%SystemRoot%\system32\wecsvc.dll,-200 (Wecsvc) - Unknown owner - C:\Windows\system32\svchost.exe
              O23 - Service: @%SystemRoot%\System32\wercplsupport.dll,-101 (wercplsupport) - Unknown owner - C:\Windows\System32\svchost.exe
              O23 - Service: @%SystemRoot%\System32\wersvc.dll,-100 (WerSvc) - Unknown owner - C:\Windows\System32\svchost.exe
              O23 - Service: @%ProgramFiles%\Windows Defender\MsMpRes.dll,-103 (WinDefend) - Unknown owner - C:\Windows\System32\svchost.exe
              O23 - Service: @%SystemRoot%\system32\winhttp.dll,-100 (WinHttpAutoProxySvc) - Unknown owner - C:\Windows\system32\svchost.exe
              O23 - Service: @%Systemroot%\system32\wbem\wmisvc.dll,-205 (Winmgmt) - Unknown owner - C:\Windows\system32\svchost.exe
              O23 - Service: @%Systemroot%\system32\wsmsvc.dll,-101 (WinRM) - Unknown owner - C:\Windows\System32\svchost.exe
              O23 - Service: @%SystemRoot%\System32\wlansvc.dll,-257 (Wlansvc) - Unknown owner - C:\Windows\system32\svchost.exe
              O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe
              O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files\Windows Media Player\wmpnetwk.exe
              O23 - Service: @%SystemRoot%\system32\wpcsvc.dll,-100 (WPCSvc) - Unknown owner - C:\Windows\system32\svchost.exe
              O23 - Service: @%SystemRoot%\system32\wpdbusenum.dll,-100 (WPDBusEnum) - Unknown owner - C:\Windows\system32\svchost.exe
              O23 - Service: @%SystemRoot%\System32\wscsvc.dll,-200 (wscsvc) - Unknown owner - C:\Windows\System32\svchost.exe
              O23 - Service: @%systemroot%\system32\SearchIndexer.exe,-103 (WSearch) - Unknown owner - C:\Windows\system32\SearchIndexer.exe
              O23 - Service: @%systemroot%\system32\wuaueng.dll,-105 (wuauserv) - Unknown owner - C:\Windows\system32\svchost.exe
              O23 - Service: @%SystemRoot%\system32\wudfsvc.dll,-1000 (wudfsvc) - Unknown owner - C:\Windows\system32\svchost.exe
              0
              1. part II

                O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
                O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
                O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
                O9 - Extra button: Afficher ou masquer l'HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
                O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
                O16 - DPF: {C1FDEE68-98D5-4F42-A4DD-D0BECF5077EB} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-31-0.cab
                O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
                O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
                O20 - Winlogon Notify: cryptnet32 - cryptnet32.dll (file missing)
                O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
                O23 - Service: @%SystemRoot%\system32\aelupsvc.dll,-1 (AeLookupSvc) - Unknown owner - C:\Windows\system32\svchost.exe
                O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe
                O23 - Service: @%systemroot%\system32\appinfo.dll,-100 (Appinfo) - Unknown owner - C:\Windows\system32\svchost.exe
                O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
                O23 - Service: @%SystemRoot%\system32\audiosrv.dll,-204 (AudioEndpointBuilder) - Unknown owner - C:\Windows\System32\svchost.exe
                O23 - Service: @%SystemRoot%\system32\audiosrv.dll,-200 (Audiosrv) - Unknown owner - C:\Windows\System32\svchost.exe
                O23 - Service: AV Engine Scanning Service - Preventon Technologies Limited - C:/Program Files/Common Files/Common Toolkit Suite/AVEngine/AVScanningService.exe
                O23 - Service: @%SystemRoot%\system32\bfe.dll,-1001 (BFE) - Unknown owner - C:\Windows\system32\svchost.exe
                O23 - Service: @%SystemRoot%\system32\qmgr.dll,-1000 (BITS) - Unknown owner - C:\Windows\System32\svchost.exe
                O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                O23 - Service: @%systemroot%\system32\browser.dll,-100 (Browser) - Unknown owner - C:\Windows\System32\svchost.exe
                O23 - Service: @%SystemRoot%\System32\bthserv.dll,-101 (BthServ) - Unknown owner - C:\Windows\system32\svchost.exe
                O23 - Service: @%SystemRoot%\System32\certprop.dll,-11 (CertPropSvc) - Unknown owner - C:\Windows\system32\svchost.exe
                O23 - Service: Common Toolkit Service - SPAMfighter - C:\Program Files\Common Files\Common Toolkit Suite\FighterSuiteService.exe
                O23 - Service: @%SystemRoot%\system32\cryptsvc.dll,-1001 (CryptSvc) - Unknown owner - C:\Windows\system32\svchost.exe
                O23 - Service: @oleres.dll,-5012 (DcomLaunch) - Unknown owner - C:\Windows\system32\svchost.exe
                O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe
                O23 - Service: @%SystemRoot%\system32\dhcpcsvc.dll,-100 (Dhcp) - Unknown owner - C:\Windows\system32\svchost.exe
                O23 - Service: @%SystemRoot%\System32\dnsapi.dll,-101 (Dnscache) - Unknown owner - C:\Windows\system32\svchost.exe
                O23 - Service: @%systemroot%\system32\dot3svc.dll,-1102 (dot3svc) - Unknown owner - C:\Windows\system32\svchost.exe
                O23 - Service: @%systemroot%\system32\dps.dll,-500 (DPS) - Unknown owner - C:\Windows\System32\svchost.exe
                O23 - Service: @%systemroot%\system32\eapsvc.dll,-1 (EapHost) - Unknown owner - C:\Windows\System32\svchost.exe
                O23 - Service: @%SystemRoot%\system32\emdmgmt.dll,-1000 (EMDMgmt) - Unknown owner - C:\Windows\system32\svchost.exe
                O23 - Service: Empowering Technology Service (ETService) - Unknown owner - C:\Program Files\Packard Bell\Packard Bell Recovery Management\Service\ETService.exe
                O23 - Service: @%SystemRoot%\system32\wevtsvc.dll,-200 (Eventlog) - Unknown owner - C:\Windows\System32\svchost.exe
                O23 - Service: @comres.dll,-2450 (EventSystem) - Unknown owner - C:\Windows\system32\svchost.exe
                0
                1. voici maintenant le rapport Log txt de Hijack this:

                  Logfile of random's system information tool 1.08 (written by random/random)
                  Run by Christophe at 2010-08-10 10:02:44
                  Microsoft® Windows Vista(TM) Édition Familiale Basique Service Pack 2
                  System drive C: has 216 GB (47%) free of 464 GB
                  Total RAM: 3000 MB (57% free)

                  Logfile of Trend Micro HijackThis v2.0.4
                  Scan saved at 10:03:17, on 10/08/2010
                  Platform: Windows Vista SP2 (WinNT 6.00.1906)
                  MSIE: Internet Explorer v8.00 (8.00.6001.18882)
                  Boot mode: Normal

                  Running processes:
                  C:\Windows\system32\Dwm.exe
                  C:\Windows\system32\taskeng.exe
                  C:\Windows\Explorer.EXE
                  C:\Program Files\Windows Defender\MSASCui.exe
                  C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                  C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                  C:\Program Files\PACKARD BELL\SetUpMyPC\SmpSys.exe
                  C:\Windows\RtHDVCpl.exe
                  C:\Windows\System32\igfxtray.exe
                  C:\Windows\System32\hkcmd.exe
                  C:\Windows\System32\igfxpers.exe
                  C:\Program Files\CyberLink\PowerCinema\PCMAgent.exe
                  C:\Program Files\CyberLink\PowerCinema\Kernel\CLML\CLMLSvc.exe
                  C:\Program Files\CyberLink\PlayMovie\PMVService.exe
                  C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
                  C:\Program Files\Belgium Identity Card\beid35gui.exe
                  C:\Program Files\HP\HP Software Update\hpwuschd2.exe
                  C:\Program Files\Fighters\VIRUSfighter\vfproTray.exe
                  C:\Program Files\Fighters\SPAMfighter\sfagent.exe
                  C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe
                  C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer.exe
                  C:\Program Files\Windows Media Player\wmpnscfg.exe
                  C:\Windows\system32\wbem\unsecapp.exe
                  C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                  C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe
                  C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                  C:\Program Files\LimeWire\LimeWire.exe
                  C:\Windows\system32\igfxsrvc.exe
                  C:\Program Files\Internet Explorer\iexplore.exe
                  C:\Program Files\Internet Explorer\iexplore.exe
                  C:\Program Files\Nokia\PC Connectivity Solution\Transports\NclMSBTSrvEx.exe
                  C:\Program Files\HP\Digital Imaging\smart web printing\hpswp_clipbook.exe
                  C:\Windows\system32\wuauclt.exe
                  C:\Users\Christophe\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\G342BN0G\RSIT[1].exe
                  C:\Program Files\trend micro\Christophe.exe

                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.be/?gws_rd=ssl
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                  R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                  R3 - URLSearchHook: UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll
                  O1 - Hosts: ::1 localhost
                  O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
                  O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
                  O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
                  O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
                  O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                  O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
                  O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll
                  O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
                  O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                  O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
                  O3 - Toolbar: LimeWire Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
                  O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
                  O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                  O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                  O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
                  O4 - HKLM\..\Run: [SmpcSys] C:\Program Files\Packard Bell\SetupMyPC\SmpSys.exe
                  O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                  O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
                  O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
                  O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
                  O4 - HKLM\..\Run: [PCMAgent] "C:\Program Files\CyberLink\PowerCinema\PCMAgent.exe"
                  O4 - HKLM\..\Run: [CLMLServer] "C:\Program Files\CyberLink\PowerCinema\Kernel\CLML\CLMLSvc.exe"
                  O4 - HKLM\..\Run: [PlayMovie] "C:\Program Files\CyberLink\PlayMovie\PMVService.exe"
                  O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
                  O4 - HKLM\..\Run: [beid] "C:\Program Files\Belgium Identity Card\beid35gui.exe" /startup
                  O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
                  O4 - HKLM\..\Run: [NokiaMusic FastStart] "C:\Program Files\Nokia\Ovi Player\NokiaOviPlayer.exe" /command:faststart
                  O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                  O4 - HKLM\..\Run: [SWPROguard] C:\Program Files\Fighters\SPYWAREfighter\SWPROTray.exe
                  O4 - HKLM\..\Run: [VFPROguard] C:\Program Files\Fighters\VIRUSfighter\VFPROTray.exe
                  O4 - HKLM\..\Run: [sfagent] C:\Program Files\Fighters\SPAMfighter\sfagent.exe
                  O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime Alternative\QTTask.exe" -atboottime
                  O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
                  O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
                  O4 - HKLM\..\Run: [NokiaMServer] C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles startup
                  O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                  O4 - HKCU\..\Run: [SmpcSys] C:\Program Files\PACKARD BELL\SetUpMyPC\SmpSys.exe
                  O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
                  O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
                  O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
                  O4 - HKCU\..\Run: [RegDokFRScheduler] C:\Program Files\RegistryDoktor 4.1\RegistryDoktor.exe SCHEDULER
                  O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                  O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                  O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                  O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                  O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
                  O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                  O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
                  O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
                  O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
                  0
                  1. voilà ai réussi à trouver malwarebytes, voici le résultat:
                    32 fichiers infectés, j'ai supprimé ces fichiers.


                    Ci-dessous le rapport:
                    Malwarebytes' Anti-Malware 1.46
                    www.malwarebytes.org

                    Version de la base de données: 4411

                    Windows 6.0.6002 Service Pack 2
                    Internet Explorer 8.0.6001.18882

                    10/08/2010 9:46:59
                    mbam-log-2010-08-10 (09-46-59).txt

                    Type d'examen: Examen complet (C:\|E:\|)
                    Elément(s) analysé(s): 326381
                    Temps écoulé: 1 heure(s), 16 minute(s), 17 seconde(s)

                    Processus mémoire infecté(s): 0
                    Module(s) mémoire infecté(s): 1
                    Clé(s) du Registre infectée(s): 6
                    Valeur(s) du Registre infectée(s): 1
                    Elément(s) de données du Registre infecté(s): 0
                    Dossier(s) infecté(s): 8
                    Fichier(s) infecté(s): 76

                    Processus mémoire infecté(s):
                    (Aucun élément nuisible détecté)

                    Module(s) mémoire infecté(s):
                    c:\Windows\System32\erokosvc.dll (Worm.KoobFace) -> Delete on reboot.

                    Clé(s) du Registre infectée(s):
                    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\cpqoko6 (Worm.KoobFace) -> Quarantined and deleted successfully.
                    HKEY_CURRENT_USER\SOFTWARE\RegistryDoktorFrNE (Rogue.RegistryDoctor) -> Quarantined and deleted successfully.
                    HKEY_CURRENT_USER\SOFTWARE\SmartShopper (Adware.SmartShopper) -> Quarantined and deleted successfully.
                    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\RegistryDoktor_is1 (Rogue.RegistryDoktor) -> Quarantined and deleted successfully.
                    HKEY_LOCAL_MACHINE\SOFTWARE\SmartShopper (Adware.SmartShopper) -> Quarantined and deleted successfully.
                    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\apto6ko (Worm.KoobFace) -> Quarantined and deleted successfully.

                    Valeur(s) du Registre infectée(s):
                    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\tapisrvs (Worm.KoobFace) -> Quarantined and deleted successfully.

                    Elément(s) de données du Registre infecté(s):
                    (Aucun élément nuisible détecté)

                    Dossier(s) infecté(s):
                    C:\ProgramData\15636021 (Rogue.Multiple) -> Quarantined and deleted successfully.
                    C:\Program Files\RegistryDoktor 4.1 (Rogue.RegistryDoktor) -> Quarantined and deleted successfully.
                    C:\Program Files\RegistryDoktor 4.1\definitions (Rogue.RegistryDoktor) -> Quarantined and deleted successfully.
                    C:\Program Files\smartshopper (Adware.SmartShopper) -> Quarantined and deleted successfully.
                    C:\Program Files\smartshopper\Bin (Adware.SmartShopper) -> Quarantined and deleted successfully.
                    C:\Program Files\smartshopper\Bin\2.5.0 (Adware.SmartShopper) -> Quarantined and deleted successfully.
                    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RegistryDoktor 4.1 (Rogue.RegistryDoktor) -> Quarantined and deleted successfully.
                    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SmartShopper (Adware.SmartShopper) -> Quarantined and deleted successfully.

                    Fichier(s) infecté(s):
                    c:\Windows\System32\erokosvc.dll (Worm.KoobFace) -> Delete on reboot.
                    C:\Program Files\RegistryDoktor 4.1\Cl.exe (Rogue.Multiple) -> Quarantined and deleted successfully.
                    C:\Program Files\RegistryDoktor 4.1\RegistryDoktor.exe (Rogue.AntiMalwarePro) -> Quarantined and deleted successfully.
                    C:\Users\Christophe\AppData\Local\rdr_1268943333.exe (Worm.KoobFace) -> Quarantined and deleted successfully.
                    C:\Users\Christophe\AppData\Local\rdr_1269383642.exe (Worm.KoobFace) -> Quarantined and deleted successfully.
                    C:\Users\Christophe\AppData\Local\Temp\_2B17.tmp (Trojan.Lukicsel) -> Quarantined and deleted successfully.
                    C:\Users\Christophe\Desktop\o.dat (Trojan.Agent) -> Quarantined and deleted successfully.
                    C:\Users\Christophe\Documents\programme\WinRAR.3.30-fr\WinRAR.3.30.FR\patch-WinRAR 3.30\WinRAR 3.30.exe (Trojan.Agent.CK) -> Quarantined and deleted successfully.
                    C:\Windows\bill104.exe (Worm.KoobFace) -> Quarantined and deleted successfully.
                    C:\Windows\System32\drivers\imapioko.sys (Worm.KoobFace) -> Quarantined and deleted successfully.
                    C:\Program Files\RegistryDoktor 4.1\EngineAP.dll (Rogue.RegistryDoktor) -> Quarantined and deleted successfully.
                    C:\Program Files\RegistryDoktor 4.1\FolderPaths.txt (Rogue.RegistryDoktor) -> Quarantined and deleted successfully.
                    C:\Program Files\RegistryDoktor 4.1\ScheduleAP.txt (Rogue.RegistryDoktor) -> Quarantined and deleted successfully.
                    C:\Program Files\RegistryDoktor 4.1\Task.dat (Rogue.RegistryDoktor) -> Quarantined and deleted successfully.
                    C:\Program Files\RegistryDoktor 4.1\task.xml (Rogue.RegistryDoktor) -> Quarantined and deleted successfully.
                    C:\Program Files\RegistryDoktor 4.1\unins000.dat (Rogue.RegistryDoktor) -> Quarantined and deleted successfully.
                    C:\Program Files\RegistryDoktor 4.1\unins000.exe (Rogue.RegistryDoktor) -> Quarantined and deleted successfully.
                    C:\Program Files\RegistryDoktor 4.1\definitions\200812.cab (Rogue.RegistryDoktor) -> Quarantined and deleted successfully.
                    C:\Program Files\RegistryDoktor 4.1\definitions\200901.cab (Rogue.RegistryDoktor) -> Quarantined and deleted successfully.
                    C:\Program Files\RegistryDoktor 4.1\definitions\200902.cab (Rogue.RegistryDoktor) -> Quarantined and deleted successfully.
                    C:\Program Files\RegistryDoktor 4.1\definitions\200903.cab (Rogue.RegistryDoktor) -> Quarantined and deleted successfully.
                    C:\Program Files\RegistryDoktor 4.1\definitions\200904.cab (Rogue.RegistryDoktor) -> Quarantined and deleted successfully.
                    C:\Program Files\RegistryDoktor 4.1\definitions\200905.cab (Rogue.RegistryDoktor) -> Quarantined and deleted successfully.
                    C:\Program Files\RegistryDoktor 4.1\definitions\20090601.cab (Rogue.RegistryDoktor) -> Quarantined and deleted successfully.
                    C:\Program Files\RegistryDoktor 4.1\definitions\20090602.cab (Rogue.RegistryDoktor) -> Quarantined and deleted successfully.
                    C:\Program Files\RegistryDoktor 4.1\definitions\20090603.cab (Rogue.RegistryDoktor) -> Quarantined and deleted successfully.
                    C:\Program Files\RegistryDoktor 4.1\definitions\20090706.cab (Rogue.RegistryDoktor) -> Quarantined and deleted successfully.
                    C:\Program Files\RegistryDoktor 4.1\definitions\20090714.cab (Rogue.RegistryDoktor) -> Quarantined and deleted successfully.
                    C:\Program Files\RegistryDoktor 4.1\definitions\20090721.cab (Rogue.RegistryDoktor) -> Quarantined and deleted successfully.
                    C:\Program Files\RegistryDoktor 4.1\definitions\20090729.cab (Rogue.RegistryDoktor) -> Quarantined and deleted successfully.
                    C:\Program Files\RegistryDoktor 4.1\definitions\20090805.cab (Rogue.RegistryDoktor) -> Quarantined and deleted successfully.
                    C:\Program Files\RegistryDoktor 4.1\definitions\20090819.cab (Rogue.RegistryDoktor) -> Quarantined and deleted successfully.
                    C:\Program Files\RegistryDoktor 4.1\definitions\20090901.cab (Rogue.RegistryDoktor) -> Quarantined and deleted successfully.
                    C:\Program Files\RegistryDoktor 4.1\definitions\20090921.cab (Rogue.RegistryDoktor) -> Quarantined and deleted successfully.
                    C:\Program Files\RegistryDoktor 4.1\definitions\20091006.cab (Rogue.RegistryDoktor) -> Quarantined and deleted successfully.
                    C:\Program Files\RegistryDoktor 4.1\definitions\20091023.cab (Rogue.RegistryDoktor) -> Quarantined and deleted successfully.
                    C:\Program Files\RegistryDoktor 4.1\definitions\20091104.cab (Rogue.RegistryDoktor) -> Quarantined and deleted successfully.
                    C:\Program Files\RegistryDoktor 4.1\definitions\20091114.cab (Rogue.RegistryDoktor) -> Quarantined and deleted successfully.
                    C:\Program Files\RegistryDoktor 4.1\definitions\20091130.cab (Rogue.RegistryDoktor) -> Quarantined and deleted successfully.
                    C:\Program Files\RegistryDoktor 4.1\definitions\20091218.cab (Rogue.RegistryDoktor) -> Quarantined and deleted successfully.
                    C:\Program Files\RegistryDoktor 4.1\definitions\20091231.cab (Rogue.RegistryDoktor) -> Quarantined and deleted successfully.
                    C:\Program Files\RegistryDoktor 4.1\definitions\20100118.cab (Rogue.RegistryDoktor) -> Quarantined and deleted successfully.
                    C:\Program Files\RegistryDoktor 4.1\definitions\20100130.cab (Rogue.RegistryDoktor) -> Quarantined and deleted successfully.
                    C:\Program Files\RegistryDoktor 4.1\definitions\20100212.cab (Rogue.RegistryDoktor) -> Quarantined and deleted successfully.
                    C:\Program Files\RegistryDoktor 4.1\definitions\20100302.cab (Rogue.RegistryDoktor) -> Quarantined and deleted successfully.
                    C:\Program Files\RegistryDoktor 4.1\definitions\20100323.cab (Rogue.RegistryDoktor) -> Quarantined and deleted successfully.
                    C:\Program Files\RegistryDoktor 4.1\definitions\20100416.cab (Rogue.RegistryDoktor) -> Quarantined and deleted successfully.
                    C:\Program Files\RegistryDoktor 4.1\definitions\20100506.cab (Rogue.RegistryDoktor) -> Quarantined and deleted successfully.
                    C:\Program Files\RegistryDoktor 4.1\definitions\20100527.cab (Rogue.RegistryDoktor) -> Quarantined and deleted successfully.
                    C:\Program Files\RegistryDoktor 4.1\definitions\20100621.cab (Rogue.RegistryDoktor) -> Quarantined and deleted successfully.
                    C:\Program Files\RegistryDoktor 4.1\definitions\20100630.cab (Rogue.RegistryDoktor) -> Quarantined and deleted successfully.
                    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RegistryDoktor 4.1\Désinstaller Registry Doktor 4.1.lnk (Rogue.RegistryDoktor) -> Quarantined and deleted successfully.
                    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RegistryDoktor 4.1\Registry Doktor 4.1.lnk (Rogue.RegistryDoktor) -> Quarantined and deleted successfully.
                    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SmartShopper\SmartShopper - Comapre product prices.lnk (Adware.SmartShopper) -> Quarantined and deleted successfully.
                    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SmartShopper\SmartShopper - Compare travel rate.lnk (Adware.SmartShopper) -> Quarantined and deleted successfully.
                    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SmartShopper\SmartShopper Help.lnk (Adware.SmartShopper) -> Quarantined and deleted successfully.
                    C:\Users\Public\Desktop\Registry Doktor 4.1.lnk (Rogue.RegistryDoctor) -> Quarantined and deleted successfully.
                    C:\Windows\System32\crt.dat (Malware.Trace) -> Quarantined and deleted successfully.
                    C:\Windows\System32\cryptnet32.dll (Trojan.Tracur) -> Quarantined and deleted successfully.
                    C:\Windows\System32\shimg.dll (Trojan.Agent) -> Quarantined and deleted successfully.
                    C:\Users\Christophe\Local Settings\Application Data\rdr_1268930579.exe (Worm.KoobFace) -> Quarantined and deleted successfully.
                    C:\Users\Christophe\Local Settings\Application Data\rdr_1268930584.exe (Worm.KoobFace) -> Quarantined and deleted successfully.
                    C:\Users\Christophe\Local Settings\Application Data\rdr_1268943333.exe (Worm.KoobFace) -> Quarantined and deleted successfully.
                    C:\Users\Christophe\Local Settings\Application Data\rdr_1268943638.exe (Worm.KoobFace) -> Quarantined and deleted successfully.
                    C:\Users\Christophe\Local Settings\Application Data\rdr_1268943642.exe (Worm.KoobFace) -> Quarantined and deleted successfully.
                    C:\Users\Christophe\Local Settings\Application Data\rdr_1269274834.exe (Worm.KoobFace) -> Quarantined and deleted successfully.
                    C:\Users\Christophe\Local Settings\Application Data\rdr_1269287305.exe (Worm.KoobFace) -> Quarantined and deleted successfully.
                    C:\Users\Christophe\Local Settings\Application Data\rdr_1269287311.exe (Worm.KoobFace) -> Quarantined and deleted successfully.
                    C:\Users\Christophe\Local Settings\Application Data\rdr_1269287315.exe (Worm.KoobFace) -> Quarantined and deleted successfully.
                    C:\Users\Christophe\Local Settings\Application Data\rdr_1269287319.exe (Worm.KoobFace) -> Quarantined and deleted successfully.
                    C:\Users\Christophe\Local Settings\Application Data\rdr_1269287323.exe (Worm.KoobFace) -> Quarantined and deleted successfully.
                    C:\Users\Christophe\Local Settings\Application Data\rdr_1269383642.exe (Worm.KoobFace) -> Quarantined and deleted successfully.
                    C:\Windows\bk20856.dat (KoobFace.Trace) -> Quarantined and deleted successfully.
                    C:\Windows\bk23567.dat (KoobFace.Trace) -> Quarantined and deleted successfully.
                    C:\Windows\fdgg34353edfgdfdf (KoobFace.Trace) -> Quarantined and deleted successfully.
                    C:\Windows\ligh (Koobface.Trace) -> Quarantined and deleted successfully.
                    0
                    1. Impossible de faire la suite, télécharger malwarebytes

                      Petit problème... Internet Explorer n'est pas parvenu à trouver la page www.malwarebytes.org.
                      Suggestions :
                      *Rechercher sur Google :


                      vais essayer de trouver ailleur...
                      0
                      1. Et voici après la suppression...

                        ############################## | UsbFix 7.019 | [Suppression]

                        Utilisateur: Christophe (Administrateur) # PC-DE-COACH [PACKARD BELL BV EasyNote MH45]
                        Mis à jour le 03/08/10 par El Desaparecido / C_XX
                        Lancé à 22:33:45 | 09/08/2010
                        Site Web: http://pagesperso-orange.fr/NosTools/index.html
                        Contact: FindyKill.Contact@gmail.com

                        CPU: Pentium(R) Dual-Core CPU T4200 @ 2.00GHz
                        CPU 2: Pentium(R) Dual-Core CPU T4200 @ 2.00GHz
                        Microsoft® Windows Vista(TM) Édition Familiale Basique (6.0.6002 32-Bit) # Service Pack 2
                        Internet Explorer 8.0.6001.18882

                        Pare-feu Windows: Activé
                        RAM -> 3000 Mo
                        C:\ (%systemdrive%) -> Disque fixe # 453 Go (207 Go libre(s) - 46%) [OS] # NTFS
                        D:\ -> CD-ROM
                        E:\ -> Disque fixe # 466 Go (257 Go libre(s) - 55%) [Intenso] # FAT32

                        ################## | Éléments infectieux |

                        ################## | Registre |

                        ################## | Mountpoints2 |

                        Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{afdf8d3d-ba1a-11de-a056-00238b86c625}
                        Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{bbddb0d8-20ea-11df-a313-00238b86c625}
                        Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{cffa498c-1114-11df-ac82-00238b86c625}

                        ################## | Listing |

                        [09/08/2010 - 22:36:11 | SHD ] C:\$Recycle.Bin
                        [29/05/2009 - 21:21:40 | HD ] C:\ACER
                        [01/06/2009 - 22:36:00 | A | 61762560] C:\audio0.ac3
                        [01/06/2009 - 22:37:02 | A | 370575404] C:\audio0.wav
                        [18/09/2006 - 23:43:36 | A | 24] C:\autoexec.bat
                        [05/12/2009 - 10:04:11 | SHD ] C:\Boot
                        [11/04/2009 - 08:36:36 | RASH | 333257] C:\bootmgr
                        [10/01/2009 - 22:13:08 | RAS | 8192] C:\BOOTSECT.BAK
                        [31/08/2009 - 07:53:11 | D ] C:\c53dc37fd9ef829eb2650e4e3a55
                        [18/09/2006 - 23:43:37 | A | 10] C:\config.sys
                        [02/11/2006 - 14:59:44 | SHD ] C:\Documents and Settings
                        [01/06/2009 - 22:30:48 | A | 347] C:\finfos.txt
                        [10/01/2009 - 14:26:47 | D ] C:\Intel
                        [01/06/2009 - 11:16:11 | RASH | 0] C:\IO.SYS
                        [01/06/2009 - 11:16:11 | RASH | 0] C:\MSDOS.SYS
                        [27/06/2009 - 16:45:04 | RHD ] C:\MSOCache
                        [01/06/2009 - 12:29:16 | D ] C:\MWASPI
                        [29/02/2004 - 17:44:34 | A | 52576] C:\orange.bmp
                        [02/08/2010 - 06:35:02 | ASH | 3460280320] C:\pagefile.sys
                        [21/01/2008 - 04:43:50 | D ] C:\PerfLogs
                        [11/06/2009 - 16:46:13 | D ] C:\platodvdripper
                        [04/08/2010 - 17:08:30 | D ] C:\Program Files
                        [22/04/2010 - 21:35:35 | HD ] C:\ProgramData
                        [01/06/2009 - 18:44:49 | D ] C:\Ri4m_TMP
                        [22/03/2010 - 22:30:42 | A | 333] C:\rollback.ini
                        [09/08/2010 - 15:49:02 | SHD ] C:\System Volume Information
                        [09/08/2010 - 22:36:11 | D ] C:\UsbFix
                        [09/08/2010 - 22:33:55 | A | 2524] C:\UsbFix.txt
                        [29/05/2009 - 16:23:12 | RD ] C:\Users
                        [01/06/2009 - 20:43:14 | A | 140090] C:\VTS_01_1.d2v
                        [09/08/2010 - 21:45:56 | D ] C:\Windows
                        [02/06/2009 - 01:22:09 | A | 771944] C:\zumba test 3.avi.A.index
                        [02/06/2009 - 01:22:09 | A | 772144] C:\zumba test 3.avi.index

                        ################## | Vaccin |

                        C:\Autorun.inf -> Dossier créé par UsbFix (El Desaparecido & C_XX)

                        ################## | E.O.F |
                        0
                        1. coucou,
                          je vois qu'il y a moyen de trouver une solution avec des pro comme vous!
                          alors j'ai identiquement le même problème. Google me redirectionne vers d'autres sites etc etc ensuite pub pour un anti virus! attention votre pc est infecté etc etc.
                          donc voici mon rapport usbfix:

                          ############################## | UsbFix 7.019 | [Recherche]

                          Utilisateur: Christophe (Administrateur) # PC-DE-COACH [PACKARD BELL BV EasyNote MH45]
                          Mis à jour le 03/08/10 par El Desaparecido / C_XX
                          Lancé à 22:16:10 | 09/08/2010
                          Site Web: http://pagesperso-orange.fr/NosTools/index.html
                          Contact: FindyKill.Contact@gmail.com

                          CPU: Pentium(R) Dual-Core CPU T4200 @ 2.00GHz
                          CPU 2: Pentium(R) Dual-Core CPU T4200 @ 2.00GHz
                          Microsoft® Windows Vista(TM) Édition Familiale Basique (6.0.6002 32-Bit) # Service Pack 2
                          Internet Explorer 8.0.6001.18882

                          Pare-feu Windows: Activé
                          RAM -> 3000 Mo
                          C:\ (%systemdrive%) -> Disque fixe # 453 Go (183 Go libre(s) - 40%) [OS] # NTFS
                          D:\ -> CD-ROM

                          ################## | Éléments infectieux |

                          ################## | Registre |

                          ################## | Mountpoints2 |

                          HKCU\.\.\.\.\Explorer\MountPoints2\{afdf8d3d-ba1a-11de-a056-00238b86c625}
                          Shell\AutoRun\Command = E:\setup_vmc_lite.exe /checkApplicationPresence

                          HKCU\.\.\.\.\Explorer\MountPoints2\{bbddb0d8-20ea-11df-a313-00238b86c625}
                          Shell\AutoRun\Command = E:\Setup.exe

                          HKCU\.\.\.\.\Explorer\MountPoints2\{cffa498c-1114-11df-ac82-00238b86c625}
                          Shell\AutoRun\Command = E:\DPFMate.exe

                          ################## | Vaccin |

                          (!) Cet ordinateur n'est pas vacciné!

                          ################## | E.O.F |
                          0
                          1. Contributeur sécurité
                            Salut yohanaldo

                            Bien de rien, bon Week end

                            @++ :)
                            0
                            1. Salut dédétraqué je vais poster le probleme comme résolu, je conserve ton dernier post en favori pour le consulter de temps en temps, et surtout

                              un grand MERCIIIIIIIIIIIIIIIIIIIIIIIIIIII !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
                              0
                              1. Contributeur sécurité
                                Salut yohanaldo

                                Bien de rien, je te donne quelques consignes de sécurité :

                                - Windows Update parfaitement à jour http://www.windowsupdate.com/windowsupdate/v6/default.aspx (catégories critique, Services Pack et Services Release)
                                - pare-feu bien paramétré, je te conseil ZoneAlarm :
                                https://www.malekal.com/tutoriel-zonealarm-firewall/
                                - antivirus bien paramétré et mis à jour régulièrement (quotidiennement s'il le faut) avec un scan complet régulier (journalier s'il le faut).
                                - une attitude prudente vis à vis de la navigation (pas de sites douteux : cracks, warez, sexe...) et vis à vis de la messagerie (fichiers joints aux messages doivent être scannés avant d'être ouverts)
                                - pas de téléchargement illégal, qui est le principal facteur d'infection (µTorrent, BitTorrent, eMule, Limewire, etc..) https://forum.malekal.com/viewtopic.php?t=893&start=
                                - une attitude vigilante (être à l'affût d'un fonctionnement inhabituel de son système)
                                - nettoyage hebdomadaire du système (suppression des fichiers inutiles, nettoyage de la base de registre, scandisk, defrag)
                                - scan hebdomadaire antispyware, je conseil MalwareByte's Anti-Malware :
                                https://www.malekal.com/tutoriel-malwarebyte-anti-malware/
                                - un contrôle régulier de la console JAVA pour s'assurer qu'elle est à jour :
                                https://www.java.com/en/download/uninstalltool.jsp
                                - faire régulièrement un scan de vulnérabilités afin de vérifier que tes logiciels soit à jour sans failles de sécurités :
                                https://www.malekal.com/tester-la-vulnerabilite-de-son-systeme-2/

                                De bonne lecture si tu veux en savoir plus sur la sécurité et le fonctionnement de Windows :
                                http://www.malekal.com/menu_windows_general.php
                                http://www.malekal.com/menu_windows_securite.php

                                Si tu considères ton problème comme résolu, tu pourras mettre en résolu :
                                https://www.commentcamarche.net/infos/25917-marquer-un-fil-de-discussion-comme-etant-resolu/

                                Bonne journée/soirée et bon surf

                                @++ :)
                                0
                                1. Bonjour dédétraqué, voici le rapport de ToolsCleaner, j'ai egalement effectué toutes les operations que tu m'as indiqué

                                  merci :)

                                  [ Rapport ToolsCleaner version 2.3.11 (par A.Rothstein & dj QUIOU) ]

                                  --> Recherche:

                                  C:\Combofix.txt: trouvé !
                                  C:\UsbFix.txt: trouvé !
                                  C:\Combofix: trouvé !
                                  C:\Qoobox: trouvé !
                                  C:\UsbFix: trouvé !
                                  C:\Rsit: trouvé !
                                  C:\Program Files\Trend Micro\HijackThis.exe: trouvé !
                                  C:\Program Files\Trend Micro\hijackthis.log: trouvé !
                                  C:\Qoobox\Quarantine\catchme.log: trouvé !
                                  C:\UsbFix\UsbFix.txt: trouvé !
                                  C:\Users\yohan\Desktop\Rsit.exe: trouvé !
                                  C:\Users\yohan\Documents\Downloads\Programs\ComboFix.exe: trouvé !
                                  C:\Windows\msnfix.txt: trouvé !
                                  C:\Windows\mbr.exe: trouvé !

                                  ---------------------------------
                                  --> Suppression:

                                  C:\Program Files\Trend Micro\HijackThis.exe: supprimé !
                                  C:\Users\yohan\Documents\Downloads\Programs\ComboFix.exe: ERREUR DE SUPPRESSION !!
                                  C:\Combofix.txt: supprimé !
                                  C:\UsbFix.txt: supprimé !
                                  C:\Program Files\Trend Micro\hijackthis.log: supprimé !
                                  C:\Qoobox\Quarantine\catchme.log: supprimé !
                                  C:\UsbFix\UsbFix.txt: supprimé !
                                  C:\Users\yohan\Desktop\Rsit.exe: supprimé !
                                  C:\Windows\msnfix.txt: supprimé !
                                  C:\Windows\mbr.exe: supprimé !
                                  C:\Combofix: supprimé !
                                  C:\Qoobox: supprimé !
                                  C:\UsbFix: supprimé !
                                  C:\Rsit: supprimé !
                                  0
                                  1. Contributeur sécurité
                                    Salut yohanaldo

                                    Bien de rien, pour des raisons de sécurité et surtout pour garder ton PC propre, on va désactiver la restauration système sur tous les lecteurs :

                                    Tutoriel Vista : https://www.commentcamarche.net/faq/13214-vista-desactiver-reactiver-la-restauration-systeme-de-vista

                                    -----

                                    On va faire un ménage des outils téléchargés pour la désinfection, télécharge Tools Cleaner sur le bureau :

                                    http://pc-system.fr/

                                    - Faire un clic droit sur ToolsCleaner2.exe sur le bureau et choisi "Exécuter en tant qu'administrateur".
                                    - Clique sur Recherche et laisse le scan agir.
                                    - Clique sur Suppression pour finaliser.
                                    - Tu peux, si tu le souhaites, te servir des Options facultatives.
                                    - Clique sur Quitter pour obtenir le rapport.
                                    - Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\).
                                    - Si des outils restes après le passage de Tools Cleaner, tu pourras les supprimer manuellement ainsi que tous les rapports qui on été généré lors de la désinfection.

                                    -----

                                    Important de mettre à jour Windows et tes logiciels :
                                    Mettre Windows(catégories critique, Services Pack et Services Release) à jour : http://www.windowsupdate.com/windowsupdate/v6/default.aspx

                                    Faire un scan de vulnérabilités afin de vérifier que tes logiciels soit à jour sans failles de sécurités et mettre à jour :
                                    https://www.malekal.com/tester-la-vulnerabilite-de-son-systeme-2/

                                    Faire un ménage des fichiers inutiles et de la base de registre :
                                    https://www.malekal.com/tutoriel-ccleaner/

                                    Dis moi quand cela est fais où si tu as des soucis et on passe à la résolution du sujet par la suite.

                                    @++ :)
                                    0
                                    1. Re dédétraqué

                                      il va bcp mieux, c'est génial je vois pas comment je pourrai te rendre l'appareil mais je te suis vraiment tres reconnaissant

                                      Tu va aider plein de gens avec ton savoir

                                      Merci encore
                                      0
                                      1. Contributeur sécurité
                                        Salut yohanaldo

                                        Comment va le PC maintenant...

                                        @++ :)
                                        0
                                        1. **************************************************************************

                                          catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                                          Rootkit scan 2010-05-11 17:15
                                          Windows 6.0.6002 Service Pack 2 NTFS

                                          Recherche de processus cachés ...

                                          Recherche d'éléments en démarrage automatique cachés ...

                                          Recherche de fichiers cachés ...

                                          Scan terminé avec succès
                                          Fichiers cachés: 0

                                          **************************************************************************
                                          .
                                          --------------------- CLES DE REGISTRE BLOQUEES ---------------------

                                          [HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
                                          @Denied: (2) (LocalSystem)
                                          "88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
                                          d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,40,ea,73,67,bf,83,9f,41,a8,fa,f6,\
                                          "2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
                                          d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,40,ea,73,67,bf,83,9f,41,a8,fa,f6,\

                                          [HKEY_USERS\S-1-5-21-2881880658-3555428079-2209020445-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
                                          "??"=hex:23,37,f5,99,51,aa,ef,0b,25,59,a1,d1,7a,71,d9,86,41,cf,68,9f,47,80,75,
                                          5a,29,d3,0f,e0,ca,5f,81,03,e4,ea,2d,16,44,98,f4,8f,a9,31,5e,94,8f,6c,7c,0e,\
                                          "??"=hex:04,35,44,e7,7f,61,2a,34,d3,f0,20,a9,b2,d9,12,0d

                                          [HKEY_USERS\S-1-5-21-2881880658-3555428079-2209020445-1000\Software\SecuROM\License information*]
                                          @Allowed: (Read) (RestrictedCode)
                                          "datasecu"=hex:58,4a,f2,18,36,5c,c1,ce,33,00,35,97,f7,17,99,ef,00,96,3e,cc,e8,
                                          be,ed,dd,ca,26,1b,dc,64,d4,85,43,5d,88,ec,54,d8,ee,f9,7d,0d,04,f2,c3,6b,67,\
                                          "rkeysecu"=hex:51,ba,a5,5f,f1,6e,0d,dd,91,7a,5f,be,a6,52,d6,a3

                                          [HKEY_USERS\S-1-5-21-2881880658-3555428079-2209020445-1000_Classes\CLSID\{3caa67b9-aa67-4c61-bb45-4ac0ac5f65ab}]
                                          @Denied: (Full) (Everyone)
                                          @Allowed: (Read) (RestrictedCode)
                                          "Model"=dword:00000081
                                          "Therad"=dword:00000008

                                          [HKEY_USERS\S-1-5-21-2881880658-3555428079-2209020445-1000_Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
                                          @Denied: (Full) (Everyone)
                                          @Allowed: (Read) (RestrictedCode)
                                          "scansk"=hex(0):5e,a0,40,d4,63,37,5b,c6,f6,91,86,88,c3,57,e4,6e,53,e8,41,17,fc,
                                          1b,b8,e2,0d,08,40,c5,cd,e6,ce,19,4d,20,2f,86,c0,36,16,fc,00,00,00,00,00,00,\

                                          [HKEY_LOCAL_MACHINE\system\ControlSet003\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
                                          @Denied: (A) (Users)
                                          @Denied: (A) (Everyone)
                                          @Allowed: (B 1 2 3 4 5) (S-1-5-20)
                                          "BlindDial"=dword:00000000

                                          [HKEY_LOCAL_MACHINE\system\ControlSet003\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
                                          @Denied: (A) (Users)
                                          @Denied: (A) (Everyone)
                                          @Allowed: (B 1 2 3 4 5) (S-1-5-20)
                                          "BlindDial"=dword:00000000

                                          [HKEY_LOCAL_MACHINE\system\ControlSet003\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
                                          @Denied: (A) (Users)
                                          @Denied: (A) (Everyone)
                                          @Allowed: (B 1 2 3 4 5) (S-1-5-20)
                                          "BlindDial"=dword:00000000

                                          [HKEY_LOCAL_MACHINE\system\ControlSet003\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
                                          @Denied: (A) (Users)
                                          @Denied: (A) (Everyone)
                                          @Allowed: (B 1 2 3 4 5) (S-1-5-20)
                                          "BlindDial"=dword:00000000

                                          [HKEY_LOCAL_MACHINE\system\ControlSet003\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
                                          @Denied: (A) (Users)
                                          @Denied: (A) (Everyone)
                                          @Allowed: (B 1 2 3 4 5) (S-1-5-20)
                                          "BlindDial"=dword:00000000

                                          [HKEY_LOCAL_MACHINE\system\ControlSet003\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
                                          @Denied: (A) (Users)
                                          @Denied: (A) (Everyone)
                                          @Allowed: (B 1 2 3 4 5) (S-1-5-20)
                                          "BlindDial"=dword:00000000
                                          .
                                          Heure de fin: 2010-05-11 17:20:37
                                          ComboFix-quarantined-files.txt 2010-05-11 15:20

                                          Avant-CF: 27 887 693 824 octets libres
                                          Après-CF: 28 018 249 728 octets libres

                                          - - End Of File - - 91D81194489F3032CA37A609754580BF
                                          0
                                          • 1
                                          • 2
                                          • 3