Virus svp

Résolu
Bonjour j'ai voulu telecharger prorat 2.0 (Je sais c pas bien) et j'ai chopé plusieur chevaux de troie bloquer par avast mais je pense que plusieur son passer par les maille du filée svp aidez moi
mon scan hitjack :
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:12:09, on 22/04/2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18904)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe
C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\TOSHIBA\TECO\TEco.exe
C:\Program Files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe
C:\Program Files\TOSHIBA\TPHM\TPCHWMsg.exe
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\RocketDock\RocketDock.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Larousse\Encyclopédie Universelle Larousse 2009\bin\hyperappel.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Users\Collégien\AppData\Local\Google\Update\1.2.183.23\GoogleCrashHandler.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\system32\igfxext.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Windows\system32\conime.exe
C:\Users\Collégien\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Collégien\Documents\Downloads\Downloader_4Story_fr_3.3.37.exe
C:\Users\COLLGI~1\AppData\Local\Temp\is-IA3OT.tmp\Downloader_4Story_fr_3.3.37.tmp
C:\Users\Collégien\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Collégien\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Collégien\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Collégien\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\services.exe
C:\Users\Collégien\Documents\Downloads\HiJackThis.exe
C:\Users\Collégien\AppData\Local\Google\Chrome\Application\chrome.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
F2 - REG:system.ini: Shell=Explorer.exe C:\Windows\system32\fservice.exe
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
O4 - HKLM\..\Run: [KeNotify] C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
O4 - HKLM\..\Run: [TosSENotify] C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
O4 - HKLM\..\Run: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe
O4 - HKLM\..\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
O4 - HKLM\..\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Teco] "%ProgramFiles%\TOSHIBA\TECO\Teco.exe" /r
O4 - HKLM\..\Run: [ToshibaServiceStation] "C:\Program Files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" /hide:60
O4 - HKLM\..\Run: [TPCHWMsg] %ProgramFiles%\TOSHIBA\TPHM\TPCHWMsg.exe
O4 - HKLM\..\Run: [avast5] C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [RocketDock] "C:\Program Files\RocketDock\RocketDock.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [Hyperappel de l'Encyclopédie Universelle Larousse] "C:\Program Files\Larousse\Encyclopédie Universelle Larousse 2009\bin\Hyperappel.exe"
O4 - HKCU\..\Run: [Google Update] "C:\Users\Collégien\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKLM\..\Policies\Explorer\Run: [DirectX For Microsoft® Windows] C:\Windows\system32\fservice.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O4 - .DEFAULT User Startup: Bienvenue.lnk = C:\Program Files\Oise\Graphique\Ordi60\Bienvenue.exe (User 'Default user')
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O13 - Gopher Prefix:
O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: TOSHIBA Web Camera Service (camsvc) - TOSHIBA - C:\Program Files\TOSHIBA\TOSHIBA Web Camera Application\TWebCameraSrv.exe
O23 - Service: Service Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Moon Secure Antivirus Core (msav) - Unknown owner - C:\Program Files\Moon Secure Antivirus\msavcore.exe (file missing)
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: TMachInfo - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
O23 - Service: TOSHIBA Navi Support Service (TNaviSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe
O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
O23 - Service: TOSHIBA eco Utility Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TECO\TecoService.exe
O23 - Service: Service TOSHIBA HDD SSD Alert (TOSHIBA HDD SSD Alert Service) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
O23 - Service: TPCH Service (TPCHSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe

End of file - 8792 bytes

29 réponses

Résumé de la discussion

Le message décrit le téléchargement de Prorat 2.0 et la détection par Avast de plusieurs chevaux de Troie, avec l’inquiétude d’une propagation potentielle par les courriels et le réseau. Des réponses recommandent de partager le rapport et d’analyser le HijackThis log et les résultats The Avenger pour isoler les éléments suspects et les services actifs. Elles évoquent aussi la vérification des programmes au démarrage, des processus système et des clés de registre, puis l’utilisation d’antivirus et d’outils de nettoyage pour éliminer les menaces. En complément, des extraits apportent un inventaire du système et des composants tels qu’ Avast, Google Update et des éléments TOSHIBA, ainsi que des détails sur des fichiers comme atapi.sys, signe de la complexité du diagnostic.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    vu

    pour la suite tu n'as plus besoin de moi, j'imagine

    si tout est ok, tu peux mettre comme "résolu"...maintenant
    (sourire)

    bonne continuation

    @+
    0
    1. Merci bocoup et bonne continuations a toi aussi
      0
  2. Bon vous a la le rapport ZHP Fix: (Java est a jour,J'ai deja Ccleanner,J'ai aussi Deflagger,Et je vais mettre m'est pilote a jour)

    ZHPFix v1.12.3093 by Nicolas Coolman - Rapport de suppression du 25/04/2010 10:20:02
    Fichier d'export Registre : C:\ZHPExportRegistry-25-04-2010-10-20-02.txt
    Web site : http://www.premiumorange.com/zeb-help-process/zhpfix.html

    Processus mémoire :
    (Néant)

    Module mémoire :
    (Néant)

    Clé du Registre :
    O42 - Logiciel: IMBooster4Web - (.IMinent.) [HKLM] => Clé supprimée avec succès

    Valeur du Registre :
    (Néant)

    Elément de données du Registre :
    [HKLM\SOFTWARE\Microsoft\Security Center] AntiVirusOverride: Modified => Donnée supprimée avec succès
    [HKLM\SOFTWARE\Microsoft\Security Center] FirewallOverride: Modified => Donnée supprimée avec succès

    Dossier :
    (Néant)

    Fichier :
    (Néant)

    Logiciel :
    O42 - Logiciel: IMBooster4Web - (.IMinent.) [HKLM] => Logiciel supprimé avec succès

    Script Registre :
    (Néant)

    Master Boot Record :
    (Néant)

    Autre :
    (Néant)

    Récapitulatif :
    Processus mémoire : 0
    Module mémoire : 0
    Clé du Registre : 1
    Valeur du Registre : 0
    Elément de données du Registre : 2
    Dossier : 0
    Fichier : 0
    Logiciel : 1
    Master Boot Record : 1
    Autre : 0

    End of the scan
    0
    1. Contributeur sécurité
      Relance ZHPDiag ( Clic droit " Executer en tant qu'administrateur " sous vista ) , fais un scan puis cette fois-ci cliques sur l'icone en forme d'écusson vert " ZHPFix ".

      ZHPFix se lancera, clique maintenant sur le " H " bleu ( coller les lignes helper ) puis copie/colle ces lignes

      [HKLM\SOFTWARE\Microsoft\Security Center] AntiVirusOverride: Modified
      [HKLM\SOFTWARE\Microsoft\Security Center] FirewallOverride: Modified
      O42 - Logiciel: IMBooster4Web - (.IMinent.) [HKLM]


      Clique sur " Ok " , puis " Tous " et enfin " Nettoyer ".

      Copie/Colle le rapport à l'écran dans ton prochain message

      ( ce rapport est sauvegardé dans ce dossier C:\Program files\ZHPDiag\ZHPFixReport.txt )

      .....................................

      1)
      Relances hijackthis
      Au menu principal, choisir do a scan only, puis cocher la case devant les lignes suivantes à corriger et cliquer en bas sur Fix Checked (s'il manque des lignes...pas grave)

      O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab


      ..........................

      2)
      Mettre à jour la Console Java ? :
      https://www.java.com/fr/download/uninstalltool.jsp

      et installer la nouvelle version si besoin est (dans ce cas désinstalle avant l'ancienne version).

      voici pour desinstaller :

      JavaRa
      http://raproducts.org/click/click.php?id=1

      Décompresse le fichier sur le Bureau (Clic droit > Extraire tout).
      * Double-clique (clic droit "en tant qu'administrateur" pour Vista) sur le répertoire JavaRa.
      * Puis double-clique sur le fichier JavaRa.exe (le exe peut ne pas s'afficher).
      * Choisis Français puis clique sur Select.
      * Clique sur Recherche de mises à jour.
      * Sélectionne Mettre à jour via jucheck.exe puis clique sur Rechercher.
      * Autorise le processus à se connecter s'il le demande, clique sur Installer et suis les instructions d'installation qui prennent quelques minutes.
      * L'installation est terminée, reviens à l'écran de JavaRa et clique sur Effacer les anciennes versions.
      * Clique sur Oui pour confirmer. Laisse travailler et clique ensuite sur OK, puis une deuxième fois sur OK.
      * Un rapport va s'ouvrir. Poste-le dans ta prochaine réponse.
      * Ferme l'application.

      Note : le rapport se trouve aussi dans C:\ sous le nom JavaRa.log.

      .............

      3)

      * Lancez Adobe Reader
      * Cliquez sur Edition --> Préférences --> JavaScript
      * Décochez "Activer Acrobat JavaScript"
      * Validez

      ....................

      4)

      IMPORTANT

      Purger la restauration systeme vista
      https://www.commentcamarche.net/faq/13214-vista-desactiver-reactiver-la-restauration-systeme-de-vista
      ......................

      5)
      Clique droit sur l'icône ZHPFix.exe sur ton Bureau,
      puis sélectionne 'Exécuter en tant qu'administrateur'.

      Clique sur le A rouge (Nettoyeur de Tools).

      Clique sur Nettoyer.

      Fais redémarrer l'ordi pour terminer le nettoyage.

      .................................................

      Recommandations pour l'avenir

      Tu es la meilleure protection pour ton pc que tout autre antivirus, si tu admets un minimum de rigueur dans son utilisation...Les virus sont vigilants et pénètrent ta machine par toutes les portes que tu laisseras ouvertes...
      - logiciels non à jour (windows, internet explorer, java, adobe reader etc)
      - installation de toolbar
      - fréquentation de sites piégés
      - P2P
      - Application de cracks
      - Supports usb

      Pour t'aider dans cette tâche, voici quelques pistes

      Pour naviguer sur internet plus en sécurité et à l'abri des publicités, je te conseille vivement d'installer et d'utiliser le navigateur firefox
      http://www.mozilla-europe.org/fr/firefox/

      Une fois que c'est fait, lances le et installe l'extension de sécurité adblock plus
      pour bloquer les publicités
      https://addons.mozilla.org/fr/mobile/addon/1865

      ............................

      WOT - Extension pour ton navigateur internet :
      Voici une extension à télécharger qui te permettra, en faisant tes recherches sur google, de savoir si le site proposé lors de tes recherches est un site de confiance ou un site à éviter car il pourrait infecter ton PC :
      Pour Firefox : https://addons.mozilla.org/fr/firefox/addon/wot-safe-browsing-tool/
      Pour internet explorer : https://chrome.google.com/webstore/detail/wot-web-of-trust-website/bhmmomiinigofkjcapegjjndpbikblnp

      ........................

      Tu dois aussi mettre à jour tous tes autres programmes pour combler des failles de sécurité... Vérifie les mises disponibles à l'aide de ce petit programme (choisis la version sans installation) : Update Checker
      https://www.commentcamarche.net/telecharger/utilitaires/9771-filehippo-app-manager/
      Et particulièrement Internet explorer, même s'il n'est pas ton navigateur, car les MAJ sécurité Windows ne s'opèrent que par ce chemin là

      ......................................

      Pour éviter une infection toolbar, il faut tout lire attentivement lorsque tu installes un programme gratuit, et décocher tous les programmes additionnels qui sont proposés, en particulier les barres d'outils !

      ..........................

      Vaccines tes disques amovibles à l'aide de USBFix (de Chiquitine29 et C_XX)
      http://pagesperso-orange.fr/NosTools/Chiquitine29/UsbFix.exe
      Au menu principal, choisis l'option 3 (Vaccination).
      ............................
      garder Malwarebytes et faire un examen de temps en temps ton PC, avec mise à jour avant chaque scan
      .......................

      Télécharge et installe CCleaner (N'installe pas la Yahoo Toolbar) :
      https://www.commentcamarche.net/telecharger/utilitaires/5647-ccleaner/

      * Lance-le.(clic droit "en tant qu'administrateur" pour Vista) Va dans Options puis Avancé et décoche la case Effacer uniquement les fichiers etc....
      * Va dans Nettoyeur, choisis Analyse. Une fois terminé, lance le nettoyage.
      * Ensuite, choisis Registre, puis Chercher des erreurs. Une fois terminé, répare toutes les erreurs tant de fois qu il en trouve a l analyse

      ..........................
      utilitaire pour défragmenter , utilises pour ce faire Defraggler https://www.clubic.com/telecharger-fiche44314-defraggler.html

      ........................
      A lire pour mieux comprendre l'environnement qui t'entoure
      http://assiste.com.free.fr/p/abc/a/zombies_et_botnets.html
      https://www.malekal.com/fichiers/projetantimalwares/ProjetAntiMalware-courte.pdf

      http://www.libellules.ch/...

      0
      1. Par contre mon ordi c eteint tout seule c normal ?
        0
        1. Rapport ZHPdiag:
          http://www.cijoint.fr/cjlink.php?file=cj201004/cijMRHMWqW.txt

          Rapport Hitjackthis :

          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 09:52:13, on 24/04/2010
          Platform: Windows Vista SP2 (WinNT 6.00.1906)
          MSIE: Internet Explorer v8.00 (8.00.6001.18904)
          Boot mode: Normal

          Running processes:
          C:\Windows\system32\taskeng.exe
          C:\Windows\system32\Dwm.exe
          C:\Windows\Explorer.EXE
          C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe
          C:\Program Files\Windows Defender\MSASCui.exe
          C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
          C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
          C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe
          C:\Windows\System32\igfxtray.exe
          C:\Windows\System32\hkcmd.exe
          C:\Windows\System32\igfxpers.exe
          C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
          C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe
          C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
          C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
          C:\Program Files\TOSHIBA\TECO\TEco.exe
          C:\Program Files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe
          C:\Program Files\TOSHIBA\TPHM\TPCHWMsg.exe
          C:\Program Files\Alwil Software\Avast5\AvastUI.exe
          C:\Program Files\Common Files\Java\Java Update\jusched.exe
          C:\Program Files\RocketDock\RocketDock.exe
          C:\Program Files\Windows Sidebar\sidebar.exe
          C:\Program Files\Larousse\Encyclopédie Universelle Larousse 2009\bin\hyperappel.exe
          C:\Windows\system32\igfxsrvc.exe
          C:\Program Files\Windows Media Player\wmpnscfg.exe
          C:\Windows\system32\igfxext.exe
          C:\Program Files\Windows Sidebar\sidebar.exe
          C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
          C:\Windows\system32\conime.exe
          C:\Program Files\Mozilla Firefox\firefox.exe
          C:\Users\Collégien\AppData\Local\Google\Update\1.2.183.23\GoogleCrashHandler.exe
          C:\Users\Collégien\AppData\Local\Google\Chrome\Application\chrome.exe
          C:\Users\Collégien\AppData\Local\Google\Chrome\Application\chrome.exe
          C:\Users\Collégien\AppData\Local\Google\Chrome\Application\chrome.exe
          C:\Users\Collégien\AppData\Local\Google\Chrome\Application\chrome.exe
          C:\Windows\system32\SearchFilterHost.exe
          C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
          R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
          O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
          O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
          O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
          O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
          O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
          O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
          O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
          O4 - HKLM\..\Run: [KeNotify] C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
          O4 - HKLM\..\Run: [TosSENotify] C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe
          O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
          O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
          O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
          O4 - HKLM\..\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
          O4 - HKLM\..\Run: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe
          O4 - HKLM\..\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
          O4 - HKLM\..\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
          O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
          O4 - HKLM\..\Run: [Teco] "%ProgramFiles%\TOSHIBA\TECO\Teco.exe" /r
          O4 - HKLM\..\Run: [ToshibaServiceStation] "C:\Program Files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" /hide:60
          O4 - HKLM\..\Run: [TPCHWMsg] %ProgramFiles%\TOSHIBA\TPHM\TPCHWMsg.exe
          O4 - HKLM\..\Run: [avast5] C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui
          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
          O4 - HKCU\..\Run: [RocketDock] "C:\Program Files\RocketDock\RocketDock.exe"
          O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
          O4 - HKCU\..\Run: [Hyperappel de l'Encyclopédie Universelle Larousse] "C:\Program Files\Larousse\Encyclopédie Universelle Larousse 2009\bin\Hyperappel.exe"
          O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
          O4 - HKCU\..\Run: [Google Update] "C:\Users\Collégien\AppData\Local\Google\Update\GoogleUpdate.exe" /c
          O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
          O4 - .DEFAULT User Startup: Bienvenue.lnk = C:\Program Files\Oise\Graphique\Ordi60\Bienvenue.exe (User 'Default user')
          O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
          O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
          O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
          O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
          O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
          O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
          O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
          O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
          O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
          O13 - Gopher Prefix:
          O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
          O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
          O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
          O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
          O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
          O23 - Service: TOSHIBA Web Camera Service (camsvc) - TOSHIBA - C:\Program Files\TOSHIBA\TOSHIBA Web Camera Application\TWebCameraSrv.exe
          O23 - Service: Service Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
          O23 - Service: Moon Secure Antivirus Core (msav) - Unknown owner - C:\Program Files\Moon Secure Antivirus\msavcore.exe (file missing)
          O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
          O23 - Service: TMachInfo - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
          O23 - Service: TOSHIBA Navi Support Service (TNaviSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe
          O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe
          O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
          O23 - Service: TOSHIBA eco Utility Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TECO\TecoService.exe
          O23 - Service: Service TOSHIBA HDD SSD Alert (TOSHIBA HDD SSD Alert Service) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
          O23 - Service: TPCH Service (TPCHSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
          0
          1. Contributeur sécurité
            excellent, tu étais bien infecté

            pour finaliser proprement ton sujet

            refais un nouveau rapport ZHPdiag et postes le lien stp
            postes également un nouveau rapport hijackthis

            => réponse dans la journée, d'où je suis je ne peux....
            0
            1. Contributeur sécurité
              Sa fait 4 fois que tu m'aides

              qu'est ce que tu fais avec ton pc ?

              sujet mis en résolu...depuis le temps tu dois savoir qu'une désinfection ne se finit pas ainsi (voir ci dessus)
              0
          2. Mon PC vas très mieux vas 10x plus vite aucune alerte d'avast toute les 2sec J'ai reinstaller google chrome et il vas mieux apparament
            0
            1. Je te remercie de ton aide (Sa fait 4 fois que tu m'aides et je suis très heureux a chaque fois)
              0
          3. Contributeur sécurité
            ok redemarres le pc

            si google chrome est toujours hs tu le désinstalles et réinstalles

            tu me dis ensuite comment va le pc et tes soucis de départ
            0
            1. Logfile of The Avenger Version 2.0, (c) by Swandog46
              http://swandog46.geekstogo.com

              Platform: Windows Vista

              *******************

              Script file opened successfully.
              Script file read successfully.

              Backups directory opened successfully at C:\Avenger

              *******************

              Beginning to process script file:

              Rootkit scan active.
              No rootkits found!

              File move operation "c:\truc.bak|c:\windows\system32\drivers\atapi.sys" completed successfully.

              Completed script processing.

              *******************

              Finished! Terminate.
              0
              1. Contributeur sécurité
                postes moi le rapport stp c:\avenger.txt

                0
                1. Oui je les fais m'est mtn impossible d'utiliser Google Chrome
                  0
                  1. Contributeur sécurité
                    as tu fais Avenger ?
                    0
                    1. Bon voua la j'ai fini je f'ai quoi mtn ??
                      0
                      1. M'est mtn impossible d'ecrire sur commentcamarche avec google chrome c normal ?? (Il me dit Activer javascript)
                        0
                    2. Sa veut dire quoi une copie sur C:/
                      0
                      1. Contributeur sécurité
                        lis bien ce qui est écrit

                        ouvre l'explorateur Windows, cherche

                        C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_b12d8e84\atapi.sys

                        sur cet atapi tu fais clic droit et Copier

                        ensuite mets toi dans poste de travail\C:\ et clic droit et Coller.
                        0
                      2. D'accord en faite je mais ATAPI.SYS a l'entrée du disque dur C:/ (Vista)
                        0
                      3. Contributeur sécurité
                        une copie oui c'est ca...que tu renommes ensuite truc.bak

                        (vista, j'oubliais)
                        0
                      4. Et après c le quelle de fichier que je m'est en BAK celui dans C:/ ou celui dans C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_b12d8e84\
                        0
                      5. Contributeur sécurité
                        celui que tu as mis sur C pas l'autre
                        0
                    3. Contributeur sécurité
                      tu vas là

                      C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_b12d8e84\atapi.sys

                      cet atapi en gras tu en fait une copie sur C (copier coller)

                      ensuite cet atapi copié sur C tu le renommes en clic droit et tu l'appelles truc.bak

                      apres ca , faire la manip Avenger
                      0
                      1. Contributeur sécurité
                        (message précédent édité)

                        ok

                        ouvre l'explorateur Windows, cherche

                        C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_b12d8e84\atapi.sys

                        clic droit et Copier

                        mets toi dans C:\ et clic droit et Coller.

                        Clix droit sur le nouveau fichier et Renommer.

                        Tu l'appelles truc.bak

                        Tu ignores l'alerte.

                        ===

                        1. Télécharge The Avenger par Swandog46 sur le Bureau

                        http://www.geekstogo.com/forum/files/file/393-the-avenger-by-swandog46/

                        Clique sur Avenger.zip pour ouvrir le fichier
                        Extraire avenger.exe sur le bureau

                        2. Copier tout le texte en gras ci-dessous : mettre en surbrillance et appuyer sur les touches(Ctrl+C):

                        Begin copying here:

                        Files to move:
                        c:\truc.bak | c:\windows\system32\drivers\atapi.sys


                        IMPORTANT: Le code ci-dessus a été intentionnellement rédigé pour CET utilisateur.
                        si vous n'êtes pas CET utilisateur, NE PAS appliquer ces directives : elles pourraient endommager votre système.

                        Ferme toutes les applications et ton navigateur

                        3. Maintenant, lance The Avenger en cliquant sur son icône du bureau.

                        Vérifie que la case devant "Automatically disable any rootkits found" n'est pas cochée.

                        Cclique sur l'icone de droite (en rose et bleu). Le texte va se copier dans la fenêtre.

                        Clique sur Execute

                        4. The Avenger va automatiquement faire ce qui suit:

                        Il va Re-démarrer le système.


                        Je cherche beaucoup...et maintenant je trouve !
                        (sourire)
                        0
                        1. Je n'ai pas compris le premier il faut renommer atapi.sys en truc.bak ?? Mais comment tu dis de renommer le nouveau fichier il y en a pas
                          0
                      2. Kill'em by g3n-h@ckm@n 1.7.2.1

                        User : Collégien (Utilisateurs)
                        Update on 22/04/2010 by g3n-h@ckm@n ::::: 16.15
                        Start at: 18:48:08 | 23/04/2010

                        Celeron(R) Dual-Core CPU T3100 @ 1.90GHz
                        Microsoft® Windows Vista(TM) Édition Familiale Premium (6.0.6002 32-bit) # Service Pack 2
                        Internet Explorer 8.0.6001.18904
                        Windows Firewall Status : Enabled

                        C:\ -> Disque fixe local | 74,22 Go (37,31 Go free) [Vista] | NTFS
                        D:\ -> Disque fixe local | 9,76 Go (6,56 Go free) [Jeux] | NTFS
                        E:\ -> Disque fixe local | 63,6 Go (63,5 Go free) [Data] | NTFS
                        F:\ -> Disque CD-ROM

                        ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running

                        C:\Windows\System32\smss.exe
                        C:\Windows\system32\csrss.exe
                        C:\Windows\system32\csrss.exe
                        C:\Windows\system32\wininit.exe
                        C:\Windows\system32\services.exe
                        C:\Windows\system32\lsass.exe
                        C:\Windows\system32\lsm.exe
                        C:\Windows\system32\winlogon.exe
                        C:\Windows\system32\svchost.exe
                        C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
                        C:\Windows\system32\svchost.exe
                        C:\Windows\System32\svchost.exe
                        C:\Windows\System32\svchost.exe
                        C:\Windows\System32\svchost.exe
                        C:\Windows\system32\svchost.exe
                        C:\Windows\system32\svchost.exe
                        C:\Windows\system32\SLsvc.exe
                        C:\Windows\system32\svchost.exe
                        C:\Windows\system32\svchost.exe
                        C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
                        C:\Windows\system32\Dwm.exe
                        C:\Windows\Explorer.EXE
                        C:\Windows\system32\runonce.exe
                        C:\Windows\system32\cmd.exe
                        C:\Windows\System32\spoolsv.exe
                        C:\Windows\system32\taskeng.exe
                        C:\Windows\system32\svchost.exe
                        C:\Windows\system32\taskeng.exe
                        C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe
                        C:\Program Files\TOSHIBA\TOSHIBA Web Camera Application\TWebCameraSrv.exe
                        C:\Windows\system32\svchost.exe
                        C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
                        C:\Program Files\Google\Update\GoogleUpdate.exe
                        C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe
                        C:\Windows\system32\TODDSrv.exe
                        C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
                        C:\Program Files\TOSHIBA\TECO\TecoService.exe
                        C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
                        C:\Windows\System32\svchost.exe
                        C:\Windows\system32\SearchIndexer.exe
                        C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
                        C:\Windows\system32\wbem\wmiprvse.exe
                        C:\Windows\system32\PresentationSettings.exe
                        C:\Program Files\List_Kill'em\ERUNT.EXE
                        C:\Program Files\List_Kill'em\pv.exe

                        ¤¤¤¤¤¤¤¤¤¤ Files/folders :

                        Quarantined & Deleted !! : C:\Windows\System32\drivers\etc\hosts.msn
                        Quarantined & Deleted !! : C:\Windows\system32\drivers\wudfpf.sys
                        Quarantined & Deleted !! : C:\Windows\system32\drivers\wudfrd.sys
                        Quarantined & Deleted !! : C:\Users\Coll'gien\AppData\Local\GDIPFONTCACHEV1.DAT
                        Quarantined & Deleted !! : C:\Users\Coll'gien\Local Settings\Temp\upx.exe
                        Quarantined & Deleted !! : C:\Users\Coll'gien\LOCAL Settings\Temp\igraal.exe
                        Quarantined & Deleted !! : C:\Users\Coll'gien\LOCAL Settings\Temp\KiweeToolbarSetup.exe
                        Quarantined & Deleted !! : C:\Users\Coll'gien\LOCAL Settings\Temp\UPX-3.04.46112.exe
                        Quarantined & Deleted !! : C:\Users\Coll'gien\LOCAL Settings\Temp\catchme.dll
                        Deleted !! : C:\$Recycle.bin\S-1-5-21-4105654460-3376347969-2524529642-1006\$IMUE88F.exe
                        Deleted !! : C:\$Recycle.bin\S-1-5-21-4105654460-3376347969-2524529642-1006\$ISE1NJ1.9

                        ==============
                        host file OK !
                        ==============

                        ========
                        Registry
                        ========

                        Deleted : HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoRun
                        Deleted : HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoRun
                        Deleted : "HKCU\software\microsoft\internet explorer\searchscopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}"
                        Deleted : HKCR\CLSID\{ca3eb689-8f09-4026-aa10-b9534c691ce0}
                        Deleted : HKCR\Interface\{4897bba6-48d9-468c-8efa-846275d7701b}
                        Deleted : HKCR\TypeLib\{4509d3cc-b642-4745-b030-645b79522c6d}
                        Deleted : HKLM\software\Iminent
                        =================
                        Internet Explorer
                        =================

                        [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
                        Start Page REG_SZ https://www.msn.com/fr-fr/?ocid=iehp
                        Local Page REG_SZ C:\WINDOWS\system32\blank.htm
                        Default_Search_URL REG_SZ https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                        Default_Page_URL REG_SZ https://www.msn.com/fr-fr/?ocid=iehp
                        Search Page REG_SZ https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF

                        [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                        Start Page REG_SZ https://www.google.com/?gws_rd=ssl
                        Local Page REG_SZ C:\WINDOWS\system32\blank.htm
                        Search Page REG_SZ http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch

                        ===============
                        Security Center
                        ===============

                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
                        cval REG_DWORD 1 (0x1)
                        UacDisableNotify REG_DWORD 1 (0x1)
                        FirstRunDisabled REG_DWORD 1 (0x1)
                        AntiVirusDisableNotify REG_DWORD 0 (0x0)
                        FirewallDisableNotify REG_DWORD 0 (0x0)
                        UpdatesDisableNotify REG_DWORD 0 (0x0)
                        AntiVirusOverride REG_DWORD 1 (0x1)
                        FirewallOverride REG_DWORD 1 (0x1)

                        ========
                        Services
                        =========

                        Ndisuio : Start = 3
                        EapHost : Start = 2
                        Wlansvc : Start = 2
                        SharedAccess : Start = 2
                        windefend : Start = 2
                        wuauserv : Start = 2
                        wscsvc : Start = 2

                        ============
                        Disk Cleaned
                        anti-ver blaster : OK
                        Prefetch cleaned
                        ================

                        ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
                        0
                        1. Contributeur sécurité
                          Relance List_Kill'em(soit en clic droit pour vista/7),avec le raccourci sur ton bureau.
                          mais cette fois-ci :

                          choisis l'option CLEAN
                          ton PC va redemarrer,

                          laisse travailler l'outil.

                          en fin de scan la fenetre se ferme , et tu as un rapport du nom de Kill'em.txt sur ton bureau ,

                          colle le contenu dans ta reponse

                          Tu peux le désinstaller ensuite

                          0
                          1. C'est bon le voici (il etait dans le disque dur "Vista")

                            List'em by g3n-h@ckm@n 1.7.2.1

                            User : Collégien (Utilisateurs)
                            Update on 22/04/2010 by g3n-h@ckm@n ::::: 16.15
                            Start at: 17:38:46 | 23/04/2010

                            Celeron(R) Dual-Core CPU T3100 @ 1.90GHz
                            Microsoft® Windows Vista(TM) Édition Familiale Premium (6.0.6002 32-bit) # Service Pack 2
                            Internet Explorer 8.0.6001.18904
                            Windows Firewall Status : Enabled

                            C:\ -> Disque fixe local | 74,22 Go (37,41 Go free) [Vista] | NTFS
                            D:\ -> Disque fixe local | 9,76 Go (6,56 Go free) [Jeux] | NTFS
                            E:\ -> Disque fixe local | 63,6 Go (63,5 Go free) [Data] | NTFS
                            F:\ -> Disque CD-ROM

                            Boot: Normal

                            ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running

                            C:\Windows\System32\smss.exe
                            C:\Windows\system32\csrss.exe
                            C:\Windows\system32\wininit.exe
                            C:\Windows\system32\csrss.exe
                            C:\Windows\system32\services.exe
                            C:\Windows\system32\winlogon.exe
                            C:\Windows\system32\lsass.exe
                            C:\Windows\system32\lsm.exe
                            C:\Windows\system32\svchost.exe
                            C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
                            C:\Windows\system32\svchost.exe
                            C:\Windows\System32\svchost.exe
                            C:\Windows\System32\svchost.exe
                            C:\Windows\System32\svchost.exe
                            C:\Windows\system32\svchost.exe
                            C:\Windows\system32\svchost.exe
                            C:\Windows\system32\SLsvc.exe
                            C:\Windows\system32\svchost.exe
                            C:\Windows\system32\svchost.exe
                            C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
                            C:\Windows\System32\spoolsv.exe
                            C:\Windows\system32\svchost.exe
                            C:\Windows\system32\taskeng.exe
                            C:\Windows\system32\Dwm.exe
                            C:\Windows\system32\taskeng.exe
                            C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe
                            C:\Windows\Explorer.EXE
                            C:\Program Files\TOSHIBA\TOSHIBA Web Camera Application\TWebCameraSrv.exe
                            C:\Windows\system32\svchost.exe
                            C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
                            C:\Program Files\Windows Defender\MSASCui.exe
                            C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe
                            C:\Windows\system32\TODDSrv.exe
                            C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
                            C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
                            C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe
                            C:\Windows\System32\igfxtray.exe
                            C:\Windows\System32\hkcmd.exe
                            C:\Windows\System32\igfxpers.exe
                            C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
                            C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
                            C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe
                            C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
                            C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                            C:\Program Files\TOSHIBA\TECO\TEco.exe
                            C:\Program Files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe
                            C:\Program Files\TOSHIBA\TECO\TecoService.exe
                            C:\Program Files\TOSHIBA\TPHM\TPCHWMsg.exe
                            C:\Program Files\Alwil Software\Avast5\AvastUI.exe
                            C:\Program Files\Common Files\Java\Java Update\jusched.exe
                            C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
                            C:\Program Files\RocketDock\RocketDock.exe
                            C:\Program Files\Windows Sidebar\sidebar.exe
                            C:\Program Files\Larousse\Encyclopédie Universelle Larousse 2009\bin\hyperappel.exe
                            C:\Windows\System32\svchost.exe
                            C:\Program Files\Windows Media Player\wmpnscfg.exe
                            C:\Windows\system32\SearchIndexer.exe
                            C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
                            C:\Windows\system32\wbem\wmiprvse.exe
                            C:\Windows\system32\igfxsrvc.exe
                            C:\Users\Collégien\AppData\Local\Google\Update\1.2.183.23\GoogleCrashHandler.exe
                            C:\Windows\system32\igfxext.exe
                            C:\Program Files\Windows Sidebar\sidebar.exe
                            C:\Program Files\Windows Media Player\wmpnetwk.exe
                            C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
                            C:\Windows\system32\SearchProtocolHost.exe
                            C:\Windows\system32\conime.exe
                            C:\Windows\system32\ctfmon.exe
                            C:\Windows\system32\SearchFilterHost.exe
                            C:\Program Files\List_Kill'em\List_Kill'em.exe
                            C:\Windows\system32\cmd.exe
                            C:\Windows\system32\DllHost.exe
                            C:\Program Files\List_Kill'em\pv.exe

                            ======================
                            Keys "Run"
                            ======================

                            [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                            RocketDock REG_SZ "C:\Program Files\RocketDock\RocketDock.exe"
                            Sidebar REG_SZ C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                            Hyperappel de l'Encyclopédie Universelle Larousse REG_EXPAND_SZ "C:\Program Files\Larousse\Encyclopédie Universelle Larousse 2009\bin\Hyperappel.exe"
                            Google Update REG_SZ "C:\Users\Collégien\AppData\Local\Google\Update\GoogleUpdate.exe" /c
                            WMPNSCFG REG_SZ C:\Program Files\Windows Media Player\WMPNSCFG.exe

                            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                            Windows Defender REG_EXPAND_SZ %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                            RtHDVCpl REG_SZ C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
                            KeNotify REG_SZ C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
                            TosSENotify REG_SZ C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe
                            IgfxTray REG_SZ C:\Windows\system32\igfxtray.exe
                            HotKeysCmds REG_SZ C:\Windows\system32\hkcmd.exe
                            Persistence REG_SZ C:\Windows\system32\igfxpers.exe
                            TPwrMain REG_EXPAND_SZ %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
                            HSON REG_EXPAND_SZ %ProgramFiles%\TOSHIBA\TBS\HSON.exe
                            SmoothView REG_EXPAND_SZ %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
                            00TCrdMain REG_EXPAND_SZ %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
                            SynTPEnh REG_SZ C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                            Teco REG_EXPAND_SZ "%ProgramFiles%\TOSHIBA\TECO\Teco.exe" /r
                            ToshibaServiceStation REG_SZ "C:\Program Files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" /hide:60
                            TPCHWMsg REG_EXPAND_SZ %ProgramFiles%\TOSHIBA\TPHM\TPCHWMsg.exe
                            avast5 REG_SZ C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui
                            SunJavaUpdateSched REG_SZ "C:\Program Files\Common Files\Java\Java Update\jusched.exe"

                            [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]

                            [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]

                            =====================
                            Other Keys
                            =====================

                            [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
                            ConsentPromptBehaviorAdmin REG_DWORD 2 (0x2)
                            ConsentPromptBehaviorUser REG_DWORD 1 (0x1)
                            EnableInstallerDetection REG_DWORD 1 (0x1)
                            EnableLUA REG_DWORD 0 (0x0)
                            EnableSecureUIAPaths REG_DWORD 1 (0x1)
                            EnableVirtualization REG_DWORD 1 (0x1)
                            PromptOnSecureDesktop REG_DWORD 1 (0x1)
                            ValidateAdminCodeSignatures REG_DWORD 0 (0x0)
                            dontdisplaylastusername REG_DWORD 0 (0x0)
                            legalnoticecaption REG_SZ
                            legalnoticetext REG_SZ
                            scforceoption REG_DWORD 0 (0x0)
                            shutdownwithoutlogon REG_DWORD 1 (0x1)
                            undockwithoutlogon REG_DWORD 1 (0x1)
                            FilterAdministratorToken REG_DWORD 0 (0x0)
                            EnableUIADesktopToggle REG_DWORD 0 (0x0)

                            ===============

                            [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
                            NoDriveTypeAutoRun REG_DWORD 145 (0x91)
                            NoRun REG_DWORD 0 (0x0)

                            ===============

                            [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
                            BindDirectlyToPropertySetStorage REG_DWORD 0 (0x0)
                            NoRun REG_DWORD 0 (0x0)

                            ===============

                            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
                            AppInit_DLLS REG_SZ

                            ===============

                            [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
                            ReportBootOk REG_SZ 1
                            Shell REG_SZ explorer.exe
                            Userinit REG_SZ C:\Windows\system32\userinit.exe,
                            VmApplet REG_SZ rundll32 shell32,Control_RunDLL "sysdm.cpl"
                            AutoRestartShell REG_DWORD 1 (0x1)
                            LegalNoticeCaption REG_SZ
                            LegalNoticeText REG_SZ
                            PowerdownAfterShutdown REG_SZ 0
                            ShutdownWithoutLogon REG_SZ 0
                            cachedlogonscount REG_SZ 10
                            forceunlocklogon REG_DWORD 0 (0x0)
                            passwordexpirywarning REG_DWORD 14 (0xe)
                            Background REG_SZ 0 0 0
                            DebugServerCommand REG_SZ no
                            WinStationsDisabled REG_SZ 0
                            DisableCAD REG_DWORD 1 (0x1)
                            scremoveoption REG_SZ 0
                            ShutdownFlags REG_DWORD 39 (0x27)
                            DefaultDomainName REG_SZ
                            DefaultUserName REG_SZ Admin Parents
                            AutoAdminLogon REG_SZ 0

                            ===============

                            [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\igfxcui]

                            ===============

                            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]

                            ===============

                            [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

                            [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

                            ===============
                            ActivX controls
                            ===============

                            [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\CabBuilder]
                            [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{4DD20514-9520-40A7-9CD6-66883643A20B}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{5D6F45B3-9043-443D-A792-115447494D24}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{8AD9C840-044E-11D1-B3E9-00805F499D93}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{C3F79A2B-B9B4-4A66-B012-3EE46475B072}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}]

                            ===============
                            [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{26923b43-4d38-484f-9b9e-de460746276c}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{08B0E5C0-4FCB-11CF-AAA5-00401C608500}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{166B1BCA-3F9C-11CF-8075-444553540000}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2179C5D3-EBFF-11CF-B6FD-00AA00B4E220}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2A202491-F00D-11cf-87CC-0020AFEECF20}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{3af36230-a269-11d1-b5bf-0000f8051515}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA848-CC51-11CF-AAFA-00AA00B6015C}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA855-CC51-11CF-AAFA-00AA00B6015F}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{45ea75a0-a269-11d1-b5bf-0000f8051515}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4f645220-306d-11d2-995d-00c04f98bbc9}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5fd399c0-a70a-11d1-9948-00c04f98bbc9}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{630b1da0-b465-11d1-9948-00c04f98bbc9}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6fab99d0-bab8-11d1-994a-00c04f98bbc9}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7C028AF8-F614-47B3-82DA-BA94E41B1089}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4340}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4383}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9381D8F2-0288-11D0-9501-00AA00B911A5}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C6BAF60B-6E91-453F-BFF9-D3789CFEFCDD}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C9E9A340-D1F1-11D0-821E-444553540600}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CDD7975E-60F8-41d5-8149-19E51D6F71D0}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{D27CDB6E-AE6D-11CF-96B8-444553540000}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{de5aed00-a4bf-11d1-9948-00c04f98bbc9}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{E92B03AB-B707-11d2-9CBD-0000F87A369E}]

                            ==============
                            BHO :
                            ======

                            [<NO NAME> REG_SZ ]
                            [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
                            [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}]

                            ===
                            DNS
                            ===

                            HKLM\SYSTEM\CS1\Services\Tcpip\..\{E53D5466-FB08-4222-A13D-D7077430E6C4}: DhcpNameServer=192.168.1.1
                            HKLM\SYSTEM\CS2\Services\Tcpip\..\{E53D5466-FB08-4222-A13D-D7077430E6C4}: DhcpNameServer=192.168.1.1
                            HKLM\SYSTEM\CS3\Services\Tcpip\..\{C8C4B60B-7FB5-4391-9543-4C5B7BA02502}: DhcpNameServer=192.168.1.1
                            HKLM\SYSTEM\CS3\Services\Tcpip\..\{E53D5466-FB08-4222-A13D-D7077430E6C4}: DhcpNameServer=192.168.1.1
                            HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
                            HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
                            HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1

                            ================
                            Internet Explorer :
                            ================

                            [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
                            Start Page REG_SZ https://www.msn.com/fr-fr
                            Local Page REG_SZ C:\Windows\System32\blank.htm
                            Default_Search_URL REG_SZ http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                            Default_Page_URL REG_SZ http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
                            Search Page REG_SZ http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch

                            [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                            Start Page REG_SZ https://www.msn.com/fr-fr
                            Local Page REG_SZ C:\Windows\system32\blank.htm

                            ========
                            Services
                            ========

                            [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services]

                            Ndisuio : 0x3 ( OK = 3 )
                            EapHost : 0x3 ( OK = 2 )
                            Wlansvc : 0x2 ( OK = 2 )
                            SharedAccess : 0x4 ( OK = 2 )
                            windefend : 0x2 ( OK = 2 )
                            wuauserv : 0x2 ( OK = 2 )
                            wscsvc : 0x2 ( OK = 2 )

                            ========
                            Safemode
                            ========

                            HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot : OK !!
                            HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal : OK !!
                            HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network : OK !!

                            =========
                            Atapi.sys
                            =========

                            C:\Windows\System32\drivers\atapi.sys :
                            MD5 :: [9c0e70031905adbf94edb9ea14af943b]
                            SHA256 :: [88e4a250c22e919decedf1d59566265c473cdfac97440f25a6d05e6200223194]

                            C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_7f3e4ed9\atapi.sys :
                            MD5 :: [9c0e70031905adbf94edb9ea14af943b]
                            SHA256 :: [88e4a250c22e919decedf1d59566265c473cdfac97440f25a6d05e6200223194]

                            C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_b12d8e84\atapi.sys :
                            MD5 :: [1f05b78ab91c9075565a9d8a4b880bc4]
                            SHA256 :: [737be9f9376dab0ccdfed93ea6d67f0c432367ea63cd772a453485be769af3bd]

                            C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_b7393fc6\atapi.sys :
                            MD5 :: [e26ddfe464b464daf1c739122978d1d6]
                            SHA256 :: [e21bf50a64beb5eafdc1d6ba1aa559a75fd31ffb4a85ceb074884c58903c9b68]

                            C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys :
                            MD5 :: [4f4fcb8b6ea06784fb6d475b7ec7300f]
                            SHA256 :: [6202d85c9a75e3f01f5f94f069c4cd8a2b9295a182301eae5940ec3bc2c1d896]

                            C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_cc18792d\atapi.sys :
                            MD5 :: [2d9c903dc76a66813d350a562de40ed9]
                            SHA256 :: [82609f01a08c6842e4c17c077bb641c1429c0e6657964b7f2d114035e1bdcbf3]

                            C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.20847_none_dbb74a7b3d9afbc1\atapi.sys :
                            MD5 :: [e26ddfe464b464daf1c739122978d1d6]
                            SHA256 :: [e21bf50a64beb5eafdc1d6ba1aa559a75fd31ffb4a85ceb074884c58903c9b68]

                            C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a2189ce9c\atapi.sys :
                            MD5 :: [2d9c903dc76a66813d350a562de40ed9]
                            SHA256 :: [82609f01a08c6842e4c17c077bb641c1429c0e6657964b7f2d114035e1bdcbf3]

                            C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.22193_none_dd6376773aedb5e4\atapi.sys :
                            MD5 :: [9c0e70031905adbf94edb9ea14af943b]
                            SHA256 :: [88e4a250c22e919decedf1d59566265c473cdfac97440f25a6d05e6200223194]

                            C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_df23a1261eab99e8\atapi.sys :
                            MD5 :: [1f05b78ab91c9075565a9d8a4b880bc4]
                            SHA256 :: [737be9f9376dab0ccdfed93ea6d67f0c432367ea63cd772a453485be769af3bd]

                            Référence :
                            ==========

                            Win 2000_SP2 : ff953a8f08ca3f822127654375786bbe
                            Win 2000_SP4 : 8c718aa8c77041b3285d55a0ce980867
                            Win XP_32b : a64013e98426e1877cb653685c5c0009
                            Win XP_SP2_32b : CDFE4411A69C224BD1D11B2DA92DAC51
                            Win XP_SP3_32b : 9F3A2F5AA6875C72BF062C712CFA2674
                            Vista_32b : e03e8c99d15d0381e02743c36afc7c6f
                            Vista_SP1_32b : 2d9c903dc76a66813d350a562de40ed9
                            Vista_SP2_32b : 1F05B78AB91C9075565A9D8A4B880BC4
                            Vista_SP2_64b : 1898FAE8E07D97F2F6C2D5326C633FAC
                            Windows 7_32b : 80C40F7FDFC376E4C5FEEC28B41C119E
                            Windows 7_64b : 02062C0B390B7729EDC9E69C680A6F3C
                            Windows 7_32b_Ultimate : 338c86357871c167a96ab976519bf59e

                            =======
                            Drive :
                            =======

                            D'fragmenteur de disque Windows
                            Copyright (c) 2006 Microsoft Corp.

                            Rapport d'analyse pour le volume C: Vista

                            Taille du volume = 74.22 Go
                            Espace libre = 37.39 Go
                            tendue d'espace libre la plus grande = 23.91 Go
                            Pourcentage de fragmentation des fichiers = 3 %

                            Remarqueÿ: sur les volumes NTFS, les fragments de fichiers de plus de 64ÿMo ne sont pas inclus dans les statistiques de fragmentation.

                            Il n'est pas n'cessaire de d'fragmenter ce volume.

                            ¤¤¤¤¤¤¤¤¤¤ Files/folders :

                            Present !! : C:\Windows\System32\drivers\etc\hosts.msn
                            Present !! : C:\Windows\System32\drivers\wudfpf.sys
                            Present !! : C:\Windows\System32\drivers\wudfrd.sys"
                            Present !! : C:\Users\Coll'gien\AppData\Local\GDIPFONTCACHEV1.DAT
                            Present !! : C:\Users\Coll'gien\Local Settings\Temp\upx.exe
                            Present !! : C:\Users\Coll'gien\LOCAL Settings\Temp\igraal.exe
                            Present !! : C:\Users\Coll'gien\LOCAL Settings\Temp\KiweeToolbarSetup.exe
                            Present !! : C:\Users\Coll'gien\LOCAL Settings\Temp\UPX-3.04.46112.exe
                            Present !! : C:\Users\Coll'gien\LOCAL Settings\Temp\upx.exe

                            ¤¤¤¤¤¤¤¤¤¤ Keys :

                            Present !! : HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoRun
                            Present !! : HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoRun
                            Present !! : HKEY_USERS\S-1-5-21-4105654460-3376347969-2524529642-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoRun
                            Present !! : HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoRun
                            Present !! : HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoRun
                            Present !! : HKEY_USERS\S-1-5-21-4105654460-3376347969-2524529642-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoRun
                            Present !! : "HKCU\software\microsoft\internet explorer\searchscopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}"
                            Present !! : HKCR\CLSID\{ca3eb689-8f09-4026-aa10-b9534c691ce0}
                            Present !! : HKCR\Interface\{4897bba6-48d9-468c-8efa-846275d7701b}
                            Present !! : HKCR\TypeLib\{4509d3cc-b642-4745-b030-645b79522c6d}
                            Present !! : HKLM\software\Iminent

                            ============

                            catchme 0.3.1398.3 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                            Rootkit scan 2010-04-23 17:50:06
                            Windows 6.0.6002 Service Pack 2 FAT NTAPI

                            scanning hidden processes ...

                            scanning hidden services ...

                            scanning hidden autostart entries ...

                            scanning hidden files ...

                            scan completed successfully
                            hidden processes: 0
                            hidden services: 0
                            hidden files: 0

                            Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

                            device: opened successfully
                            user: MBR read successfully
                            called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys iaStor.sys hal.dll
                            kernel: MBR read successfully
                            user & kernel MBR OK

                            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
                            cval REG_DWORD 1 (0x1)
                            UacDisableNotify REG_DWORD 1 (0x1)

                            ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

                            End of scan : 17:50:07,65
                            0
                            1. Moi j'ai eu que sa a 100% et il s'appelle List'em.log:

                              HKLM\SYSTEM\CCS\Services\Tcpip\..\{C8C4B60B-7FB5-4391-9543-4C5B7BA02502}: DhcpNameServer=192.168.1.1
                              HKLM\SYSTEM\CCS\Services\Tcpip\..\{E53D5466-FB08-4222-A13D-D7077430E6C4}: DhcpNameServer=192.168.1.1
                              HKLM\SYSTEM\CS1\Services\Tcpip\..\{C8C4B60B-7FB5-4391-9543-4C5B7BA02502}: DhcpNameServer=192.168.1.1
                              HKLM\SYSTEM\CS1\Services\Tcpip\..\{E53D5466-FB08-4222-A13D-D7077430E6C4}: DhcpNameServer=192.168.1.1
                              HKLM\SYSTEM\CS2\Services\Tcpip\..\{E53D5466-FB08-4222-A13D-D7077430E6C4}: DhcpNameServer=192.168.1.1
                              HKLM\SYSTEM\CS3\Services\Tcpip\..\{C8C4B60B-7FB5-4391-9543-4C5B7BA02502}: DhcpNameServer=192.168.1.1
                              HKLM\SYSTEM\CS3\Services\Tcpip\..\{E53D5466-FB08-4222-A13D-D7077430E6C4}: DhcpNameServer=192.168.1.1
                              HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
                              HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
                              HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
                              0
                              1. Contributeur sécurité
                                désactives provisoirement toutes tes protections

                                fait clic droit "executer en tant qu'administrateur" pour Vista
                                0
                              2. d'accord je le refais ??
                                0
                              3. Contributeur sécurité
                                oui comme indiqué juste au dessus
                                0
                              4. Tien voici le rapport Catchme (Il ma l'air très court mais bon)

                                catchme 0.3.1398.3 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                                Rootkit scan 2010-04-23 17:50:06
                                Windows 6.0.6002 Service Pack 2 FAT NTAPI

                                scanning hidden processes ...

                                scanning hidden services ...

                                scanning hidden autostart entries ...

                                scanning hidden files ...

                                scan completed successfully
                                hidden processes: 0
                                hidden services: 0
                                hidden files: 0
                                0
                              5. Contributeur sécurité
                                non

                                cherches un killem.txt sur le bureau
                                0
                            • 1
                            • 2