[Virus] impossible d'écrire... virus

Résolu
Bonjour,
je rencontre un problème je pense classique... j'ai été un peu imprudent.

Mon PC fixe est infecté par un virus qui m'empêche de taper le mot virus...
Impossible de scanner en ligne, de télcharger hijackthis ou quoi que ce soit.
J'écris ce message depuis mon portable, c'est le fixe qui est infecté.

(config XP Pro)

je ne sais pas quoi faire... merci d'avance pour l'aide

24 réponses

Résumé de la discussion

Problème central : un PC fixe sous Windows XP Professionnel est infecté par un virus qui empêche de taper le mot virus et bloque l’accès aux outils de détection en ligne, rendant tout scan impossible. La solution préconisée consiste à télécharger PCA d’Evosla, l’extraire dans un répertoire dédié, lancer le diagnostic puis enregistrer le rapport PCA_LOG.txt pour l’analyser et le partager lors de l’assistance. D’autres échanges évoquent également l’installation d’antivirus et l’analyse des rapports pour clarifier les éléments malveillants et la persistance des infections, notamment les entrées autorun et les services indésirables.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    Re,

    AVGantispyware est complémentaire à Antivir. Il perd une partie de ses fonctonnalités au bout d'un mois mais reste un bon outil.

    Le bouton "résolu" doit se trouver tout en bas ou tout en haut (au niveau du 1er post).

    Bon surf !

    FillPCA
    1. Tout à l'air de bien se passer.
      J'installe antivir de ce pas.

      Est-il nécessaie de garder en plus avg antispyware ou y a-t-il double emploi ?

      Où est-ce que je clique pour marquer le sujet résolu ?

      Merci beaucoup pour toute ton aide en tout cas.

      antoine
      1. Contributeur sécurité
        Re,

        C'est tout bon.

        1/
        Télécharge OTMoveIt (de Old_Timer) sur ton bureau : http://download.bleepingcomputer.com/oldtimer/OTMoveIt.exe
        * Lance OTmoveIT.
        * Clique sur CleanUp! (le programme va télécharger un fichier texte qui servira a nettoyer les programmes que l'on a téléchargés).

        NOTE : Normalement, ton firewall (parefeu) devrait te demander si OTmoveIT peut accéder à internet, Autorise le.

        * Une liste apparaît dans la partie gauche d'OTmoveIT.
        * Un message apparaît pour confirmer le nettoyage. Confirme.
        * Les fichiers infectés qui se trouvent dans les quarantaines seront supprimés aussi.

        2/ Vide ta corbeille.

        3/ Tu dois désactiver la restauration système. Pour cela, fais un clic droit sur « poste de travail ». Dans l’onglet « restauration du système », coche la case « désactiver la restauration système ». Clique sur appliquer>OK.
        Décoche cette case, clique sur "aapliquer">OK et redémarre le PC.

        4/ Installe Antivir. Il y a une version gratuite performante. Tu la trouveras ici : https://www.avira.com/

        5/ Dis-moi comment le pc se porte.

        6/ Je t'invite aussi à améliorer la protection de ton pc. Ca semble nécessaire.
        Tu peux lire ceci : http://perso.orange.fr/Le-site-de-Fill/S%E9curit%E9/Presentationsecurite.html

        Si tu n'as plus de problème, tu peux cliquer sur "résolu".

        FillPCA
        1. re-

          je ne peux aps te mettre tout le rappport de kaspersky, il fait 820ko en .txt.

          toute la fin du rapport est semblable à l'exmple que je mets ci-dessous

          D:\System Volume Information\_restore{943FDD4F-7540-4AB2-8D85-F9606EFEF2FC}\RP3\A0002772.dll Object is locked skipped
          D:\System Volume Information\_restore{943FDD4F-7540-4AB2-8D85-F9606EFEF2FC}\RP3\A0002773.ver Object is locked skipped
          D:\System Volume Information\_restore{943FDD4F-7540-4AB2-8D85-F9606EFEF2FC}\RP3\A0002774.inf Object is locked skipped
          D:\System Volume Information\_restore{943FDD4F-7540-4AB2-8D85-F9606EFEF2FC}\RP3\A0002775.exe Object is locked skipped
          D:\System Volume Information\_restore{943FDD4F-7540-4AB2-8D85-F9606EFEF2FC}\RP3\A0002776.exe Object is locked skipped
          D:\System Volume Information\_restore{943FDD4F-7540-4AB2-8D85-F9606EFEF2FC}\RP3\A0002777.dll Object is locked skipped
          D:\System Volume Information\_restore{C91BECE4-364E-419D-8A7E-2457E6AC1105}\RP2\A0002160.exe/Gain_Trickler.exe Infected: not-a-virus:AdWare.Win32.Gator.3102 skipped
          D:\System Volume Information\_restore{C91BECE4-364E-419D-8A7E-2457E6AC1105}\RP2\A0002160.exe Vise: infected - 1 skipped
          D:\System Volume Information\_restore{D4A0FC35-A3B6-4EB3-B17F-AA7ADFB39999}\RP2\A0001088.exe Object is locked skipped
          D:\System Volume Information\_restore{D4A0FC35-A3B6-4EB3-B17F-AA7ADFB39999}\RP2\A0001089.dll Object is locked skipped
          D:\System Volume Information\_restore{D4A0FC35-A3B6-4EB3-B17F-AA7ADFB39999}\RP2\A0001090.dll Object is locked skipped
          D:\System Volume Information\_restore{D4A0FC35-A3B6-4EB3-B17F-AA7ADFB39999}\RP2\A0001091.exe Object is locked skipped
          D:\System Volume Information\_restore{D4A0FC35-A3B6-4EB3-B17F-AA7ADFB39999}\RP2\A0001092.dll Object is locked skipped
          D:\System Volume Information\_restore{D4A0FC35-A3B6-4EB3-B17F-AA7ADFB39999}\RP2\A0001093.exe Object is locked skipped
          D:\System Volume Information\_restore{D4A0FC35-A3B6-4EB3-B17F-AA7ADFB39999}\RP2\A0001094.dll Object is locked skipped
          D:\System Volume Information\_restore{D4A0FC35-A3B6-4EB3-B17F-AA7ADFB39999}\RP2\A0001095.exe Object is locked skipped
          D:\System Volume Information\_restore{D4A0FC35-A3B6-4EB3-B17F-AA7ADFB39999}\RP2\A0001096.ver Object is locked skipped
          D:\System Volume Information\_restore{D4A0FC35-A3B6-4EB3-B17F-AA7ADFB39999}\RP2\A0001097.inf Object is locked skipped
          D:\System Volume Information\_restore{D4A0FC35-A3B6-4EB3-B17F-AA7ADFB39999}\RP2\A0001098.cat Object is locked skipped
          D:\System Volume Information\_restore{D4A0FC35-A3B6-4EB3-B17F-AA7ADFB39999}\RP2\A0001099.dll Object is locked skipped
          D:\System Volume Information\_restore{D4A0FC35-A3B6-4EB3-B17F-AA7ADFB39999}\RP2\A0001100.dll Object is locked skipped
          D:\System Volume Information\_restore{D4A0FC35-A3B6-4EB3-B17F-AA7ADFB39999}\RP2\A0001101.dll Object is locked skipped
          D:\System Volume Information\_restore{D4A0FC35-A3B6-4EB3-B17F-AA7ADFB39999}\RP2\A0001102.ver Object is locked skipped
          D:\System Volume Information\_restore{D4A0FC35-A3B6-4EB3-B17F-AA7ADFB39999}\RP2\A0001103.inf Object is locked skipped
          D:\System Volume Information\_restore{D4A0FC35-A3B6-4EB3-B17F-AA7ADFB39999}\RP2\A0001104.cat Object is locked skipped
          D:\System Volume Information\_restore{D4A0FC35-A3B6-4EB3-B17F-AA7ADFB39999}\RP2\A0001105.dll Object is locked skipped
          D:\System Volume Information\_restore{D4A0FC35-A3B6-4EB3-B17F-AA7ADFB39999}\RP2\A0001106.dll Object is locked skipped
          D:\System Volume Information\_restore{D4A0FC35-A3B6-4EB3-B17F-AA7ADFB39999}\RP2\A0001107.dll Object is locked skipped
          D:\System Volume Information\_restore{D4A0FC35-A3B6-4EB3-B17F-AA7ADFB39999}\RP2\A0001108.exe Object is locked skipped
          D:\System Volume Information\_restore{D4A0FC35-A3B6-4EB3-B17F-AA7ADFB39999}\RP2\A0001109.exe Object is locked skipped
          D:\System Volume Information\_restore{D4A0FC35-A3B6-4EB3-B17F-AA7ADFB39999}\RP2\A0001110.dll Object is locked skipped
          D:\System Volume Information\_restore{D4A0FC35-A3B6-4EB3-B17F-AA7ADFB39999}\RP2\A0001111.dll Object is locked skipped
          D:\System Volume Information\_restore{D4A0FC35-A3B6-4EB3-B17F-AA7ADFB39999}\RP2\A0001112.exe Object is locked skipped

          Scan process completed.
          1. -------------------------------------------------------------------------------
            KASPERSKY ONLINE SCANNER REPORT
            Wednesday, August 22, 2007 5:01:20 PM
            Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
            Kaspersky Online Scanner version: 5.0.93.0
            Kaspersky Anti-Virus database last update: 22/08/2007
            Kaspersky Anti-Virus database records: 387142
            -------------------------------------------------------------------------------

            Scan Settings:
            Scan using the following antivirus database: extended
            Scan Archives: true
            Scan Mail Bases: true

            Scan Target - My Computer:
            A:\
            C:\
            D:\
            E:\

            Scan Statistics:
            Total number of scanned objects: 42618
            Number of viruses found: 1
            Number of infected objects: 2
            Number of suspicious objects: 0
            Duration of the scan process: 00:45:29

            Infected Object Name / Virus Name / Last Action
            C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
            C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
            C:\Documents and Settings\Antoine\Cookies\index.dat Object is locked skipped
            C:\Documents and Settings\Antoine\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
            C:\Documents and Settings\Antoine\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
            C:\Documents and Settings\Antoine\Local Settings\Historique\History.IE5\index.dat Object is locked skipped
            C:\Documents and Settings\Antoine\Local Settings\Historique\History.IE5\MSHist012007082220070823\index.dat Object is locked skipped
            C:\Documents and Settings\Antoine\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
            C:\Documents and Settings\Antoine\NTUSER.DAT Object is locked skipped
            C:\Documents and Settings\Antoine\ntuser.dat.LOG Object is locked skipped
            C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
            C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
            C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
            C:\Documents and Settings\LocalService\Local Settings\Historique\History.IE5\index.dat Object is locked skipped
            C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
            C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
            C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
            C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
            C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
            C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
            C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
            C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
            C:\System Volume Information\_restore{3DD1D970-D8FE-4408-ABB1-CC28A694D6F6}\RP121\change.log Object is locked skipped
            C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
            C:\WINDOWS\Internet Logs\BEAUCHART.ldb Object is locked skipped
            C:\WINDOWS\Internet Logs\fwdbglog.txt Object is locked skipped
            C:\WINDOWS\Internet Logs\fwpktlog.txt Object is locked skipped
            C:\WINDOWS\Internet Logs\IAMDB.RDB Object is locked skipped
            C:\WINDOWS\Internet Logs\tvDebug.log Object is locked skipped
            C:\WINDOWS\SchedLgU.Txt Object is locked skipped
            C:\WINDOWS\SoftwareDistribution\EventCache\{9909C28C-2ACC-45F1-B514-AAB282235593}.bin Object is locked skipped
            C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
            C:\WINDOWS\Sti_Trace.log Object is locked skipped
            C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
            C:\WINDOWS\system32\CatRoot2\edbtmp.log Object is locked skipped
            C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
            C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
            C:\WINDOWS\system32\config\default Object is locked skipped
            C:\WINDOWS\system32\config\default.LOG Object is locked skipped
            C:\WINDOWS\system32\config\SAM Object is locked skipped
            C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
            C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
            C:\WINDOWS\system32\config\SECURITY Object is locked skipped
            C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
            C:\WINDOWS\system32\config\software Object is locked skipped
            C:\WINDOWS\system32\config\software.LOG Object is locked skipped
            C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
            C:\WINDOWS\system32\config\system Object is locked skipped
            C:\WINDOWS\system32\config\system.LOG Object is locked skipped
            C:\WINDOWS\system32\drivers\fidbox.dat Object is locked skipped
            C:\WINDOWS\system32\drivers\fidbox.idx Object is locked skipped
            C:\WINDOWS\system32\drivers\fidbox2.dat Object is locked skipped
            C:\WINDOWS\system32\drivers\fidbox2.idx Object is locked skipped
            C:\WINDOWS\system32\h323log.txt Object is locked skipped
            C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
            C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
            C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
            C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
            C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
            C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
            C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
            C:\WINDOWS\temp\ZLT01858.TMP Object is locked skipped
            C:\WINDOWS\temp\ZLT0185c.TMP Object is locked skipped
            C:\WINDOWS\wiadebug.log Object is locked skipped
            C:\WINDOWS\wiaservc.log Object is locked skipped
            C:\WINDOWS\WindowsUpdate.log Object is locked skipped
            D:\4d917f98e6eeaa54daba9a637db0\common\eula.txt Object is locked skipped
            D:\4d917f98e6eeaa54daba9a637db0\common\spcustom.dll Object is locked skipped
            D:\4d917f98e6eeaa54daba9a637db0\common\spmsg.dll Object is locked skipped
            D:\4d917f98e6eeaa54daba9a637db0\common\spuninst.exe Object is locked skipped
            D:\4d917f98e6eeaa54daba9a637db0\common\update.exe Object is locked skipped
            D:\4d917f98e6eeaa54daba9a637db0\sp1\ole32.dll Object is locked skipped
            D:\4d917f98e6eeaa54daba9a637db0\sp1\rpcrt4.dll Object is locked skipped
            D:\4d917f98e6eeaa54daba9a637db0\sp1\rpcss.dll Object is locked skipped
            D:\4d917f98e6eeaa54daba9a637db0\sp1\update\KB824146.cat Object is locked skipped
            D:\4d917f98e6eeaa54daba9a637db0\sp1\update\update.inf Object is locked skipped
            D:\4d917f98e6eeaa54daba9a637db0\sp1\update\update.ver Object is locked skipped
            D:\4d917f98e6eeaa54daba9a637db0\sp2\ole32.dll Object is locked skipped
            D:\4d917f98e6eeaa54daba9a637db0\sp2\rpcrt4.dll Object is locked skipped
            D:\4d917f98e6eeaa54daba9a637db0\sp2\rpcss.dll Object is locked skipped
            D:\4d917f98e6eeaa54daba9a637db0\sp2\spmsg.dll Object is locked skipped
            D:\4d917f98e6eeaa54daba9a637db0\sp2\spuninst.exe Object is locked skipped
            D:\4d917f98e6eeaa54daba9a637db0\sp2\update\eula.txt Object is locked skipped
            D:\4d917f98e6eeaa54daba9a637db0\sp2\update\KB824146.cat Object is locked skipped
            D:\4d917f98e6eeaa54daba9a637db0\sp2\update\spcustom.dll Object is locked skipped
            D:\4d917f98e6eeaa54daba9a637db0\sp2\update\update.exe Object is locked skipped
            D:\4d917f98e6eeaa54daba9a637db0\sp2\update\update.inf Object is locked skipped
            D:\4d917f98e6eeaa54daba9a637db0\sp2\update\update.ver Object is locked skipped
            D:\RECYCLER\NPROTECT\00000000.exe Object is locked skipped
            D:\RECYCLER\NPROTECT\00000001.exe Object is locked skipped
            D:\RECYCLER\NPROTECT\00000002._P Object is locked skipped
            D:\RECYCLER\NPROTECT\00000003._P Object is locked skipped
            D:\RECYCLER\NPROTECT\00000004._P Object is locked skipped
            D:\RECYCLER\NPROTECT\00000005._P Object is locked skipped
            D:\RECYCLER\NPROTECT\00000006._P Object is locked skipped
            D:\RECYCLER\NPROTECT\00000007._P Object is locked skipped
            D:\RECYCLER\NPROTECT\00000008._P Object is locked skipped
            D:\RECYCLER\NPROTECT\00000009._P Object is locked skipped
            D:\RECYCLER\NPROTECT\00000010._P Object is locked skipped
            D:\RECYCLER\NPROTECT\00000011._P Object is locked skipped
            D:\RECYCLER\NPROTECT\00000012._P Object is locked skipped
            D:\RECYCLER\NPROTECT\00000013._P Object is locked skipped
            D:\RECYCLER\NPROTECT\00000014._P Object is locked skipped
            D:\RECYCLER\NPROTECT\00000015._P Object is locked skipped
            D:\RECYCLER\NPROTECT\00000016._P Object is locked skipped
            D:\RECYCLER\NPROTECT\00000017._P Object is locked skipped
            D:\RECYCLER\NPROTECT\00000018._P Object is locked skipped
            D:\RECYCLER\NPROTECT\00000019._P Object is locked skipped
            D:\RECYCLER\NPROTECT\00000020._P Object is locked skipped
            D:\RECYCLER\NPROTECT\00000021._P Object is locked skipped
            D:\RECYCLER\NPROTECT\00000022._P Object is locked skipped
            D:\RECYCLER\NPROTECT\00000023._P Object is locked skipped
            D:\RECYCLER\NPROTECT\00000024._P Object is locked skipped
            D:\RECYCLER\NPROTECT\00000025._P Object is locked skipped
            D:\RECYCLER\NPROTECT\00000026._P Object is locked skipped
            D:\RECYCLER\NPROTECT\00000027._P Object is locked skipped
            D:\RECYCLER\NPROTECT\00000028._P Object is locked skipped
            D:\RECYCLER\NPROTECT\00000029._P Object is locked skipped
            D:\RECYCLER\NPROTECT\00000030._P Object is locked skipped
            D:\RECYCLER\NPROTECT\00000031._P Object is locked skipped
            D:\RECYCLER\NPROTECT\00000032._P Object is locked skipped
            D:\RECYCLER\NPROTECT\00000033._P Object is locked skipped
            D:\RECYCLER\NPROTECT\00000034._P Object is locked skipped
            D:\RECYCLER\NPROTECT\00000035._P Object is locked skipped
            D:\RECYCLER\NPROTECT\00000036._P Object is locked skipped
            D:\RECYCLER\NPROTECT\00000037._P Object is locked skipped
            D:\RECYCLER\NPROTECT\00000038._P Object is locked skipped
            D:\RECYCLER\NPROTECT\00000039._P Object is locked skipped
            D:\RECYCLER\NPROTECT\00000040._P Object is locked skipped
            D:\RECYCLER\NPROTECT\00000041._P Object is locked skipped
            D:\RECYCLER\NPROTECT\00000042._P Object is locked skipped
            D:\RECYCLER\NPROTECT\00000043._P Object is locked skipped
            D:\RECYCLER\NPROTECT\00000044._P Object is locked skipped
            D:\RECYCLER\NPROTECT\00000045._P Object is locked skipped
            D:\RECYCLER\NPROTECT\00000046.dll Object is locked skipped
            D:\RECYCLER\NPROTECT\00000047.dll Object is locked skipped
            D:\RECYCLER\NPROTECT\00000048.exe Object is locked skipped
            D:\RECYCLER\NPROTECT\00000049.dll Object is locked skipped
            D:\RECYCLER\NPROTECT\00000050.exe Object is locked skipped
            D:\RECYCLER\NPROTECT\00000051.txt Object is locked skipped
            D:\RECYCLER\NPROTECT\00000052.dll Object is locked skipped
            D:\RECYCLER\NPROTECT\00000053.dll Object is locked skipped
            D:\RECYCLER\NPROTECT\00000054.tsp Object is locked skipped
            D:\RECYCLER\NPROTECT\00000055.exe Object is locked skipped
            D:\RECYCLER\NPROTECT\00000056.dll Object is locked skipped
            D:\RECYCLER\NPROTECT\00000057.dll Object is locked skipped
            D:\RECYCLER\NPROTECT\00000058.dll Object is locked skipped
            D:\RECYCLER\NPROTECT\00000059.ver Object is locked skipped
            D:\RECYCLER\NPROTECT\00000060.dll Object is locked skipped
            D:\RECYCLER\NPROTECT\00000061.TSP Object is locked skipped
            D:\RECYCLER\NPROTECT\00000062.exe Object is locked skipped
            D:\RECYCLER\NPROTECT\00000063.dll Object is locked skipped
            D:\RECYCLER\NPROTECT\00000064.dll Object is locked skipped
            D:\RECYCLER\NPROTECT\00000065.dll Object is locked skipped
            D:\RECYCLER\NPROTECT\00000066.dll Object is locked skipped
            D:\RECYCLER\NPROTECT\00000067.dll Object is locked skipped
            D:\RECYCLER\NPROTECT\00000068.dll Object is locked skipped
            D:\RECYCLER\NPROTECT\00000069.dll Object is locked skipped
            D:\RECYCLER\NPROTECT\00000070.dll Object is locked skipped
            D:\RECYCLER\NPROTECT\00000071.txt Object is locked skipped
            D:\RECYCLER\NPROTECT\00000072.dll Object is locked skipped
            D:\RECYCLER\NPROTECT\00000073.dll Object is locked skipped
            D:\RECYCLER\NPROTECT\00000074.dll Object is locked skipped
            D:\RECYCLER\NPROTECT\00000075.dll Object is locked skipped
            D:\RECYCLER\NPROTECT\00000076.dll Object is locked skipped
            D:\RECYCLER\NPROTECT\00000077.dll Object is locked skipped
            D:\RECYCLER\NPROTECT\00000078.dll Object is locked skipped
            D:\RECYCLER\NPROTECT\00000079.dll Object is locked skipped
            D:\RECYCLER\NPROTECT\00000080.dll Object is locked skipped
            D:\RECYCLER\NPROTECT\00000081.dll Object is locked skipped
            D:\RECYCLER\NPROTECT\00000082.dll Object is locked skipped
            D:\RECYCLER\NPROTECT\00000083.dll Object is locked skipped
            D:\RECYCLER\NPROTECT\00000084.dll Object is locked skipped
            D:\RECYCLER\NPROTECT\00000085.dll Object is locked skipped
            D:\RECYCLER\NPROTECT\00000086.dll Object is locked skipped
            D:\RECYCLER\NPROTECT\00000087.dll Object is locked skipped
            D:\RECYCLER\NPROTECT\00000088.dll Object is locked skipped
            D:\RECYCLER\NPROTECT\00000089.cat Object is locked skipped
            D:\RECYCLER\NPROTECT\00000090.cat Object is locked skipped
            D:\RECYCLER\NPROTECT\00000091.exe Object is locked skipped
            D:\RECYCLER\NPROTECT\00000092.exe Object is locked skipped
            D:\RECYCLER\NPROTECT\00000093.inf Object is locked skipped
            D:\RECYCLER\NPROTECT\00000094.inf Object is locked skipped
            D:\RECYCLER\NPROTECT\00000095.exe Object is locked skipped
            D:\RECYCLER\NPROTECT\00000096.ver Object is locked skipped
            D:\RECYCLER\NPROTECT\00000097.dll Object is locked skipped
            D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped

            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092112.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092113.sys Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092114.hta Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092115.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092116.inf Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092117.exe Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092118.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092119.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092120.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092121.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092122.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092123.exe Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092124.inf Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092125.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092126.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092127.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092128.mfl Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092129.cmd Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092130.exe Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092131.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092132.exe Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092133.exe Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092134.sys Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092135.sys Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092136.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092137.sys Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092138.sys Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092139.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092140.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092141.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092142.sys Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092143.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092144.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092145.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092146.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092147.exe Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092148.sys Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092149.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092150.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092151.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092152.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092153.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092154.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092155.sys Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092156.sys Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092157.exe Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092158.exe Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092159.sys Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092160.sys Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092161.sys Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092162.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092163.cpl Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092164.ttf Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092165.sys Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092166.ocx Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092167.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092168.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092169.exe Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092170.sys Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092171.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092172.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092173.sys Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092174.sys Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092175.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092176.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092177.sys Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092178.sys Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092179.sys Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092180.sys Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092181.sys Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092182.sys Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092183.sys Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092184.sys Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092185.sys Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092186.sys Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092187.inf Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092188.ax Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092189.ax Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092190.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092191.sys Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092192.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092193.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092194.exe Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092195.exe Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092196.exe Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092197.sys Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092198.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092199.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092200.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092201.sys Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092202.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092203.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092204.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092205.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092206.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092207.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092208.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092209.sys Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092210.sys Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092211.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092212.sys Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092213.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092214.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092215.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092216.exe Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092217.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092218.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092219.sys Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092220.exe Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092221.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092222.sys Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092223.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092224.exe Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092225.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092226.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092227.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092228.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092229.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092230.exe Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092231.exe Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092232.acs Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092233.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092234.sys Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092235.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092236.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092237.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092238.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092239.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092240.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092241.exe Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092242.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092243.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092244.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092245.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092246.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092247.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092248.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092249.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092250.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092251.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092252.exe Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092253.cpl Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092254.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092255.exe Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092256.exe Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092257.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092258.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092259.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092260.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092261.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092262.ocx Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092263.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092264.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092265.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092266.sys Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092267.sys Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092268.exe Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092269.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092270.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092271.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092272.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092273.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092274.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092275.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092276.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092277.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092278.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092279.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092280.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092281.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092282.exe Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092283.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092284.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092285.sys Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092286.sys Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092287.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092288.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092289.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092290.ax Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092291.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092292.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092293.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092294.exe Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092295.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092296.exe Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092297.exe Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092298.sys Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092299.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092300.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092301.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092302.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092303.acs Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092304.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092305.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092306.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092307.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092308.sys Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092309.exe Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092310.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092311.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092312.exe Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092313.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092314.sys Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092315.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092316.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092317.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092318.sys Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092319.exe Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092320.cat Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092321.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092322.inf Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092323.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092324.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092325.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092326.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092327.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092328.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092329.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092330.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092331.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092332.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092333.exe Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092334.exe Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092335.exe Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092336.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092337.exe Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092338.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092339.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092340.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092341.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092342.exe Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092343.exe Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092344.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092345.exe Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092346.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092347.exe Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092348.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092349.exe Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092350.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092351.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092352.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092353.inf Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092354.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092355.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092356.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092357.exe Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092358.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092359.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092360.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092361.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092362.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092363.inf Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092364.sys Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092365.sys Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092366.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092367.ttf Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092368.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092369.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092370.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092371.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092372.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092373.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092374.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092375.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092376.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092377.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092378.exe Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092379.exe Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092380.exe Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092381.ocx Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092382.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092383.sys Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092384.sys Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092385.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092386.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092387.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092388.inf Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092389.sys Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092390.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092391.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092392.exe Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092393.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092394.exe Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092395.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092396.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092397.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092398.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092399.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092400.inf Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092401.exe Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092402.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092403.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092404.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092405.exe Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092406.sys Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092407.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092408.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092409.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092410.inf Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092411.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092412.cpl Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092413.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092414.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092415.sys Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092416.cpl Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092417.inf Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092418.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092419.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092420.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092421.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092422.exe Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092423.inf Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092424.inf Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092425.inf Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092426.inf Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092427.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092428.inf Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092429.inf Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092430.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092431.inf Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092432.inf Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092433.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092434.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092435.exe Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092436.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092437.inf Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092438.inf Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092439.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092440.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092441.inf Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092442.inf Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092443.inf Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092444.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092445.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092446.inf Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092447.inf Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092448.sys Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092449.inf Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092450.inf Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092451.inf Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092452.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092453.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092454.sys Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092455.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092456.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092457.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092458.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092459.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092460.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092461.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092462.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092463.inf Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092464.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092465.inf Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092466.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092467.inf Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092468.inf Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092469.inf Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092470.inf Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092471.cat Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092472.inf Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092473.sys Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092474.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092475.inf Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092476.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092477.inf Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092478.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092479.exe Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092480.inf Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092481.exe Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092482.exe Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092483.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092484.inf Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092485.inf Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092486.inf Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092487.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092488.cat Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092489.inf Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092490.inf Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092491.exe Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092492.exe Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092493.exe Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092494.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092495.exe Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092496.inf Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092497.inf Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092498.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092499.exe Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092500.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092501.exe Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092502.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092503.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092504.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092505.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092506.sys Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092507.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092508.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092509.sys Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092510.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092511.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092512.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092513.exe Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092514.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092515.sys Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092516.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092517.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092518.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092519.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092520.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092521.dll Object is locked skipped
            D:\System Volume Information\_restore{32A28C02-8B68-4BF3-9908-C0CE037A4F3F}\RP90\A0092
            1. Salut,
              j'ai fait ce que tu as indiqué.
              Ci-dessous les 2 rapports combofix et jijackthis. Kaspersky suit.

              ComboFix 07-08-17.2 - "Antoine" 2007-08-22 15:32:24.3 - NTFSx86
              Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.63 [GMT 2:00]
              Command switches used :: C:\Documents and Settings\Antoine\Bureau\CFScript.txt
              * Created a new restore point

              FILE::
              C:\WINDOWS\System32\dllcache\mlqm.exe

              ((((((((((((((((((((((((( Files Created from 2007-07-22 to 2007-08-22 )))))))))))))))))))))))))))))))

              2007-08-21 22:24 <REP> d-------- C:\WINDOWS\LastGood
              2007-08-21 22:24 <REP> d-------- C:\DOCUME~1\LOCALS~1\Menu D‚marrer
              2007-08-21 22:23 <REP> d-------- C:\WINDOWS\Prefetch
              2007-08-21 21:44 <REP> d-------- C:\WINDOWS\provisioning
              2007-08-21 21:44 <REP> d-------- C:\WINDOWS\peernet
              2007-08-21 21:37 <REP> d-------- C:\WINDOWS\system32\ReinstallBackups
              2007-08-21 20:38 <REP> d-------- C:\WINDOWS\system32\ActiveScan
              2007-08-21 20:06 4,569 --------- C:\WINDOWS\system32\secupd.dat
              2007-08-21 20:06 11,776 --------- C:\WINDOWS\system32\spnpinst.exe
              2007-08-21 18:54 1,097,728 --a------ C:\WINDOWS\system32\esent.dll
              2007-08-20 22:50 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
              2007-08-20 22:47 <REP> d-------- C:\WINDOWS\system32\PreInstall
              2007-08-20 22:46 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe
              2007-08-20 22:46 <REP> d--h----- C:\WINDOWS\$hf_mig$
              2007-08-20 22:42 <REP> d-------- C:\test
              2007-08-20 22:33 75,932 --a------ C:\WINDOWS\system32\drivers\klick.dat
              2007-08-20 22:33 75,248 --a------ C:\WINDOWS\zllsputility.exe
              2007-08-20 22:33 74,396 --a------ C:\WINDOWS\system32\drivers\klin.dat
              2007-08-20 22:33 54,672 --a------ C:\WINDOWS\system32\vsutil_loc040c.dll
              2007-08-20 22:33 42,384 --a------ C:\WINDOWS\zllsputility_loc040c.dll
              2007-08-20 22:33 4,212 ---h----- C:\WINDOWS\system32\zllictbl.dat
              2007-08-20 22:33 21,904 --a------ C:\WINDOWS\system32\imsinstall_loc040c.dll
              2007-08-20 22:33 17,808 --a------ C:\WINDOWS\system32\imslsp_install_loc040c.dll
              2007-08-20 22:33 12,320 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
              2007-08-20 22:33 110,360 --a------ C:\WINDOWS\system32\drivers\kl1.sys
              2007-08-20 22:33 11,264 --a------ C:\WINDOWS\system32\SpOrder.dll
              2007-08-20 22:33 1,568 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat
              2007-08-20 22:33 <REP> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\MailFrontier
              2007-08-20 22:32 1,086,952 --a------ C:\WINDOWS\system32\zpeng24.dll
              2007-08-20 22:32 <REP> d-------- C:\WINDOWS\system32\ZoneLabs
              2007-08-20 22:31 <REP> d-------- C:\WINDOWS\Internet Logs
              2007-08-20 22:23 <REP> d-------- C:\Program Files\CCleaner
              2007-08-20 21:10 853 --a------ C:\reboot.cmd
              2007-08-20 21:10 68,096 --a------ C:\diff.exe
              2007-08-20 21:10 103,424 --a------ C:\grep.exe
              2007-08-20 20:49 <REP> d-a------ C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
              2007-08-20 20:34 241,664 --a------ C:\WINDOWS\system32\srrstr.dll
              2007-08-20 20:29 <REP> d-------- C:\WINDOWS\ERUNT
              2007-08-20 20:25 51,200 --a------ C:\WINDOWS\nircmd.exe
              2007-08-20 20:00 <REP> dr------- C:\DOCUME~1\LOCALS~1\Favoris
              2007-08-20 20:00 <REP> d-------- C:\pca
              2007-08-20 17:37 <REP> d-------- C:\Program Files\Alwil Software
              2007-08-19 22:04 <REP> d-------- C:\DOCUME~1\Antoine\APPLIC~1\Media Player Classic
              2007-08-19 22:03 765,952 --a------ C:\WINDOWS\system32\xvidcore.dll
              2007-08-19 22:03 73,728 --a------ C:\WINDOWS\system32\dpl100.dll
              2007-08-19 22:03 7,680 --a------ C:\WINDOWS\system32\ff_vfw.dll
              2007-08-19 22:03 348,160 --a------ C:\WINDOWS\system32\msvcr71.dll
              2007-08-19 22:03 3,596,288 --a------ C:\WINDOWS\system32\qt-dx331.dll
              2007-08-19 22:03 217,088 --a------ C:\WINDOWS\system32\yv12vfw.dll
              2007-08-19 22:03 180,224 --a------ C:\WINDOWS\system32\xvidvfw.dll
              2007-08-19 22:03 163,840 --a------ C:\WINDOWS\system32\unrar.dll
              2007-08-19 22:03 <REP> d-------- C:\Program Files\K-Lite Codec Pack
              2007-08-19 21:39 <REP> d-------- C:\DOCUME~1\Antoine\APPLIC~1\vlc
              2007-08-19 21:27 48,640 --a------ C:\WINDOWS\system32\INETWH32.DLL
              2007-08-19 21:27 317,952 --a------ C:\WINDOWS\system32\Roboex32.dll
              2007-08-19 21:27 1,712,128 --a------ C:\WINDOWS\system32\gdiplus.dll
              2007-08-19 21:27 <REP> d-------- C:\Program Files\Qualcomm
              2007-08-19 21:23 <REP> d----c--- C:\WINDOWS\system32\DRVSTORE
              2007-08-19 21:23 <REP> d-------- C:\DOCUME~1\Antoine\Contacts
              2007-08-19 21:15 <REP> d-------- C:\Program Files\MSN Messenger
              2007-08-19 21:13 <REP> d--hs---- C:\RECYCLER
              2007-08-19 21:09 <REP> d-------- C:\Program Files\Winamp
              2007-08-19 21:08 <REP> d-------- C:\Program Files\VideoLAN
              2007-08-19 20:43 97,280 --a------ C:\WINDOWS\system32\dpcdll.dll
              2007-08-19 20:41 95,744 --a------ C:\WINDOWS\system32\mqsec.dll
              2007-08-19 20:41 938,496 --------- C:\WINDOWS\system32\winbrand.dll
              2007-08-19 20:41 870,784 --------- C:\WINDOWS\system32\ati3d1ag.dll
              2007-08-19 20:41 80,384 --a------ C:\WINDOWS\system32\tlntsess.exe
              2007-08-19 20:41 76,288 --a------ C:\WINDOWS\system32\fdeploy.dll
              2007-08-19 20:41 75,264 --a------ C:\WINDOWS\system32\tlntsvr.exe
              2007-08-19 20:41 73,216 --------- C:\WINDOWS\system32\drivers\atintuxx.sys
              2007-08-19 20:41 72,960 --a------ C:\WINDOWS\system32\drivers\mqac.sys
              2007-08-19 20:41 701,440 --------- C:\WINDOWS\system32\drivers\ati2mtag.sys
              2007-08-19 20:41 7,168 --a------ C:\WINDOWS\system32\tlntsvrp.dll
              2007-08-19 20:41 7,168 --------- C:\WINDOWS\system32\hccoin.dll
              2007-08-19 20:41 660,992 --a------ C:\WINDOWS\system32\mqqm.dll
              2007-08-19 20:41 65,024 --a------ C:\WINDOWS\system32\nwwks.dll
              2007-08-19 20:41 63,488 --a------ C:\WINDOWS\system32\tlntadmn.exe
              2007-08-19 20:41 63,488 --------- C:\WINDOWS\system32\drivers\atinxsxx.sys
              2007-08-19 20:41 614,400 --a------ C:\WINDOWS\system32\wsecedit.dll
              2007-08-19 20:41 57,856 --------- C:\WINDOWS\system32\drivers\atinbtxx.sys
              2007-08-19 20:41 527,360 --a------ C:\WINDOWS\system32\mqutil.dll
              2007-08-19 20:41 52,224 --------- C:\WINDOWS\system32\drivers\atinraxx.sys
              2007-08-19 20:41 517,632 --a------ C:\WINDOWS\system32\mqsnap.dll
              2007-08-19 20:41 40,832 --------- C:\WINDOWS\system32\drivers\irbus.sys
              2007-08-19 20:41 4,096 --------- C:\WINDOWS\system32\dsprpres.dll
              2007-08-19 20:41 377,984 --------- C:\WINDOWS\system32\ati2dvaa.dll
              2007-08-19 20:41 327,168 --------- C:\WINDOWS\system32\drivers\ati2mtaa.sys
              2007-08-19 20:41 32,768 --------- C:\WINDOWS\system32\asr_pfu.exe
              2007-08-19 20:41 31,744 --------- C:\WINDOWS\system32\drivers\atinxbxx.sys
              2007-08-19 20:41 302,592 --a------ C:\WINDOWS\system32\appmgr.dll
              2007-08-19 20:41 28,672 --------- C:\WINDOWS\system32\drivers\atinsnxx.sys
              2007-08-19 20:41 270,848 --------- C:\WINDOWS\system32\sbe.dll
              2007-08-19 20:41 260,096 --a------ C:\WINDOWS\system32\tracerpt.exe
              2007-08-19 20:41 26,624 --------- C:\WINDOWS\system32\drivers\usbehci.sys
              2007-08-19 20:41 201,728 --------- C:\WINDOWS\system32\ati2dvag.dll
              2007-08-19 20:41 201,216 --a------ C:\WINDOWS\system32\gptext.dll
              2007-08-19 20:41 20,992 --------- C:\WINDOWS\system32\faxpatch.exe
              2007-08-19 20:41 20,480 --------- C:\WINDOWS\system32\encapi.dll
              2007-08-19 20:41 197,632 --------- C:\WINDOWS\system32\xpsp1res.dll

              (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

              2007-08-21 21:49 2724 --a------ C:\WINDOWS\pchealth\HELPCTR\PackageStore\SkuStore.bin
              2007-08-21 21:46 8972 --a------ C:\WINDOWS\pchealth\HELPCTR\Config\Cntstore.bin
              2007-08-20 22:37 1220 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.idx
              2007-08-20 22:37 1220 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx

              ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

              *Note* empty entries & legit default entries are not shown

              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
              "NvCplDaemon"="C:\WINDOWS\System32\NvCpl.dll" [2005-04-01 16:16]
              "nwiz"="nwiz.exe" [2005-04-01 16:16 C:\WINDOWS\system32\nwiz.exe]
              "NvMediaCenter"="C:\WINDOWS\System32\NvMcTray.dll" [2005-04-01 16:16]
              "WinampAgent"="C:\Program Files\Winamp\Winampa.exe" []
              "ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-06-21 21:54]
              "!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 11:25]

              [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
              "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-20 01:09]

              [HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
              "ICQ Agent"=C:\WINDOWS\System32\icq6.exe

              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
              "{EDB0E980-90BD-11D4-8599-0008C7D3B6F8}"= C:\Program Files\Qualcomm\Eudora\EuShlExt.dll [2002-09-30 18:36 86016]

              R1 VIAPFD;VIAPFD;C:\WINDOWS\system32\Drivers\VIAPFD.SYS
              R2 Dnscache;Client DNS;C:\WINDOWS\System32\svchost.exe -k NetworkService
              R3 WFsys;WinFox Control I/O Driver;C:\WINDOWS\system32\DRIVERS\wfsys.sys
              S3 AN983;Carte Fast Ethernet 10/100 Mbps ADMtek AN983/AN985/ADM951X;C:\WINDOWS\system32\DRIVERS\AN983.sys

              **************************************************************************

              catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
              Rootkit scan 2007-08-22 15:34:27
              Windows 5.1.2600 Service Pack 2 NTFS

              scanning hidden processes ...

              scanning hidden autostart entries ...

              scanning hidden files ...

              C:\WINDOWS\KB920872.log
              **************************************************************************

              Completion time: 2007-08-22 15:36:05
              C:\ComboFix-quarantined-files.txt ... 2007-08-22 15:35
              C:\ComboFix2.txt ... 2007-08-20 20:26

              --- E O F ---

              Logfile of Trend Micro HijackThis v2.0.2
              Scan saved at 17:02:36, on 22/08/2007
              Platform: Windows XP SP2 (WinNT 5.01.2600)
              MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
              Boot mode: Normal

              Running processes:
              C:\WINDOWS\System32\smss.exe
              C:\WINDOWS\system32\winlogon.exe
              C:\WINDOWS\system32\services.exe
              C:\WINDOWS\system32\lsass.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\system32\ZoneLabs\vsmon.exe
              C:\WINDOWS\system32\spoolsv.exe
              C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
              C:\WINDOWS\System32\nvsvc32.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\system32\RUNDLL32.EXE
              C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
              C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
              C:\WINDOWS\system32\ctfmon.exe
              C:\Program Files\Internet Explorer\iexplore.exe
              C:\WINDOWS\explorer.exe
              C:\WINDOWS\system32\wuauclt.exe
              C:\Documents and Settings\Antoine\Bureau\HiJackThis\HijackThis.exe

              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
              O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
              O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
              O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
              O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\Winampa.exe"
              O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
              O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
              O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
              O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
              O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
              O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
              O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
              O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/71365/kavwebscan_unicode.cab
              O16 - DPF: {1E2941E3-8E63-11D4-9D5A-00902742D6E0} (iNotes Class) - https://portail.inetpsa.com/http://mailz1.domino.inetpsa.com/iNotes.cab
              O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
              O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
              O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
              O23 - Service: NVIDIA Display Driver Service (nvSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
              O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
              1. Contributeur sécurité
                Re,

                1/ Supprime Avenger puis vide ta corbeille.
                2/ Clique sur démarrer>Exécuter>Services.msc -> Valide
                Dans la liste de services, choisis cette ligne et double-clique dessus :

                Logitech QuickCam Manager

                Dans démarrage, tu choisis "désactivé".

                Clique sur "arrêter" -> appliquer -> OK.

                Ouvre Hijackthis>"open the misc tool section">"delete a NT service"
                Dans l'invite de commande, tape ceci : Logitech QuickCam Manager

                2/ * Sélectionne le texte suivant :

                Registry::
                [-HKEY_LOCAL_MACHINE \SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]

                File::
                C:\WINDOWS\System32\dllcache\mlqm.exe


                * Copie le texte sélectionné (CTRL+C).
                * Ouvre le bloc-note (programme>Accessoire>bloc-note).
                * Colle le texte copié dans ce bloc-note (CTRL+V).
                * Sauvegarde ce fichier sous le nom de CFScript.txt
                * Fais un glisser/déposer de ce fichier CFScript sur le fichier ComboFix.exe

                * Une fenêtre bleue va apparaître: au message qui apparaît ( Type 1 to continue, or 2 to abort) , tape 1 puis valide.
                * Patiente le temps du scan. Le bureau va disparaître à plusieurs reprises: c'est normal!
                Ne touche à rien tant que le scan n'est pas terminé.
                * Une fois le scan achevé, un rapport va s'afficher: Poste son contenu.
                * Si le fichier ne s'ouvre pas, il se trouve ici > C:\ComboFix.txt

                3/ Ouvre Ccleaner, clique sur "lancer le nettoyage".

                4/ Vu ce qu'il y avait, on fait un autre scan de vérification.
                * Fais un scan en ligne en cliquant ici : http://assiste.com.free.fr/...
                * Choisis Kaspersky.
                * Tu dois réaliser le scan en utilisant Internet explorer. Une information apparait en haut, près de la barre d'état. Tu dois accepter et installer l'activeX proposé. La mise à jour de l'antivirus se lance.
                * Réalise un scan complet du système.
                * Sauvegarde le rapport en mode texte à l'issue du scan.

                5/ Edite le rapport Combofix, Kaspersky et un autre rapport Hijackthis. Ensuite, on termine.

                FillPCA
                1. re-
                  niveau symptomes du PC, pour l'instant, plus aucun problème.
                  Pour preuve, j'ai pas rebooté depuis au moins deux heures ! lol
                  1. hum, toujours pas complet en fait, donc voilà la 3ème partie du rapport panda
                    Désolé pour le morcellement :

                    Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\icserror\icsdc.htm
                    Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\icserror\vcejlxkt.exe
                    Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\isperror\hkenntsl.exe
                    Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\isperror\ispcnerr.htm
                    Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\isperror\ispdtone.htm
                    Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\isperror\isphdshk.htm
                    Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\isperror\ispins.htm
                    Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\isperror\ispnoanw.htm
                    Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\isperror\isppberr.htm
                    Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\isperror\ispphbsy.htm
                    Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\isperror\ispsbusy.htm
                    Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\isperror\jjtrkbnj.exe
                    Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\isperror\knkbrnbn.exe
                    Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\isperror\ktkbeknl.exe
                    Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\isperror\rkeetqew.exe
                    Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\isperror\skqbvxsq.exe
                    Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\isperror\tsjhshcj.exe
                    Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\isperror\ztceskls.exe
                    Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\krcxzncj.exe
                    Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\msobshel.htm
                    Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\qjeejeej.exe
                    Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\regerror\cetrjwtt.exe
                    Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\regerror\ehxzeshx.exe
                    Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\regerror\etnwxxnv.exe
                    Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\regerror\kjtzrlbb.exe
                    Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\regerror\rcnterr.htm
                    Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\regerror\rcwnttzv.exe
                    Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\regerror\rdtone.htm
                    Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\regerror\rhndshk.htm
                    Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\regerror\rnoansw.htm
                    Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\regerror\rnomdm.htm
                    Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\regerror\rpberr.htm
                    Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\regerror\rpulse.htm
                    Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\regerror\rtoobusy.htm
                    Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\regerror\wlkbbnrq.exe
                    Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\regerror\wtkkxrlr.exe
                    Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\regerror\xcjnkske.exe
                    Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\setup\acterror.htm
                    Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\setup\activate.htm
                    Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\setup\act_plcy.htm
                    Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\setup\badeula.htm
                    Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\setup\badpkey.htm
                    Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\setup\bknkjheh.exe
                    Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\setup\bvqncler.exe
                    Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\setup\compname.htm
                    Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\setup\crjrhltv.exe
                    Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\setup\dialup.htm
                    Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\setup\drdyisp.htm
                    Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\setup\drdymig.htm
                    Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\setup\drdyoem.htm
                    Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\setup\drdyref.htm
                    Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\setup\dtiwait.htm
                    Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\setup\enbsjwre.exe
                    Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\setup\esjhxblq.exe
                    Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\setup\eskcxkhr.exe
                    Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\setup\fini.htm
                    Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\setup\hlqstwxz.exe
                    Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\setup\hnhkkene.exe
                    Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\setup\hnwprmpt.htm
                    Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\setup\hwncrnhh.exe
                    Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\setup\hxckwnzl.exe
                    Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\setup\hxxttskn.exe
                    Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\setup\iconn.htm
                    Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\setup\ics.htm
                    Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\setup\ident1.htm
                    Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\setup\ident2.htm
                    Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\setup\isp.htm
                    Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\setup\ispwait.htm
                    Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\setup\jejrhnvh.exe
                    Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\setup\jndomain.htm
                    Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\setup\jndom_a.htm
                    Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\setup\jtxsbxwn.exe
                    Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\setup\keybd.htm
                    Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\setup\keybdcmt.htm
                    Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\setup\kjqkxtnz.exe
                    Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\setup\kksksesr.exe
                    Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\setup\knkhrczb.exe
                    Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\setup\lhkhbjzl.exe
                    Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\setup\lkjtrhks.exe
                    Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\setup\migdial.htm
                    Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\setup\miglist.htm
                    Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\setup\migpage.htm
                    Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\setup\neweula.htm
                    Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\setup\neweula2.htm
                    Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\setup\nkhlvlzt.exe
                    Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\setup\nleevxqj.exe
                    Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\setup\nstnnnkk.exe
                    Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\setup\ntwbjnxv.exe
                    Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\setup\nvbbshss.exe
                    Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\setup\nwqjkkhn.exe
                    Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\setup\oempriv.htm
                    Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\setup\prodkey.htm
                    Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\setup\prvcyms.htm
                    Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\setup\refdial.htm
                    Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\setup\reg1.htm
                    Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\setup\reg3.htm
                    Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\setup\regdial.htm
                    Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\setup\rresnsct.exe
                    Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\setup\rserkten.exe
                    Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\setup\security.htm
                    Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\setup\sejkhevn.exe
                    Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\setup\seqtjbee.exe
                    Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\setup\shbqjhcl.exe
                    Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\setup\timezone.htm
                    Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\setup\tnqsbljb.exe
                    Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\setup\tqkbrhnx.exe
                    Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\setup\tthzxntk.exe
                    Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\setup\username.htm
                    Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\setup\vjbssbhj.exe
                    Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\setup\vkckxhbn.exe
                    Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\setup\welcome.htm
                    Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\setup\wnklretl.exe
                    Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\setup\wrbbnjss.exe
                    Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\setup\wtenslnj.exe
                    Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\setup\zeblsxxw.exe
                    Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\setup\zhhrrltb.exe
                    Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\setup\zhzsnhje.exe
                    Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\tttnwshl.exe
                    Virus:HTML/Instancob.A Disinfected C:\WINDOWS\Web\tip.htm
                    Virus:W32/Rahack.gen Disinfected D:\65e0d8d728cb0d4298fa54b88621\i386\shzsczzs.exe
                    Virus:HTML/Instancob.A Disinfected D:\65e0d8d728cb0d4298fa54b88621\i386\smartnav.htm
                    Virus:W32/Rahack.gen Disinfected D:\Logiciels\Money\kqkshlnq.exe
                    Virus:HTML/Instancob.A Disinfected D:\Logiciels\Money\moreinfo.htm
                    Virus:HTML/Instancob.A Disinfected D:\Mes documents\Mails eudora\attach\actualite.htm
                    Virus:HTML/Instancob.A Disinfected D:\Mes documents\Mails eudora\attach\ac_lfbt_new.php.htm
                    Virus:W32/Rahack.gen Disinfected D:\Mes documents\Mails eudora\attach\bsshkzvs.exe
                    Virus:HTML/Instancob.A Disinfected D:\Mes documents\Mails eudora\attach\cr-mail-doc.htm
                    Virus:HTML/Instancob.A Disinfected D:\Mes documents\Mails eudora\attach\Drone.php.htm
                    Virus:HTML/Instancob.A Disinfected D:\Mes documents\Mails eudora\attach\Firesout.php.htm
                    Virus:HTML/Instancob.A Disinfected D:\Mes documents\Mails eudora\attach\free.fravionsp=petitduc.htm
                    Virus:HTML/Instancob.A Disinfected D:\Mes documents\Mails eudora\attach\Helios.php.htm
                    Virus:W32/Rahack.gen Disinfected D:\Mes documents\Mails eudora\attach\hjlzersq.exe
                    Virus:W32/Rahack.gen Disinfected D:\Mes documents\Mails eudora\attach\hnrsnekc.exe
                    Virus:W32/Rahack.gen Disinfected D:\Mes documents\Mails eudora\attach\hrjtkvlk.exe
                    Virus:W32/Rahack.gen Disinfected D:\Mes documents\Mails eudora\attach\hrnxhswn.exe
                    Virus:W32/Rahack.gen Disinfected D:\Mes documents\Mails eudora\attach\jnvsvwjr.exe
                    Virus:W32/Rahack.gen Disinfected D:\Mes documents\Mails eudora\attach\knbtjnhb.exe
                    Virus:W32/Rahack.gen Disinfected D:\Mes documents\Mails eudora\attach\nwslscbk.exe
                    Virus:HTML/Instancob.A Disinfected D:\Mes documents\Mails eudora\attach\Page_English_Duc.htm
                    Virus:HTML/Instancob.A Disinfected D:\Mes documents\Mails eudora\attach\Pegasus.php.htm
                    Virus:HTML/Instancob.A Disinfected D:\Mes documents\Mails eudora\attach\Predator.php.htm
                    Virus:W32/Rahack.gen Disinfected D:\Mes documents\Mails eudora\attach\sbxllhzr.exe
                    Virus:HTML/Instancob.A Disinfected D:\Mes documents\Mails eudora\attach\Shadow.php.htm
                    Virus:HTML/Instancob.A Disinfected D:\Mes documents\Mails eudora\attach\test.scr.htm
                    Virus:W32/Rahack.gen Disinfected D:\Mes documents\Mails eudora\attach\thzjnrse.exe
                    Virus:W32/Rahack.gen Disinfected D:\Mes documents\Mails eudora\attach\wtxexcsb.exe
                    Virus:HTML/Instancob.A Disinfected D:\Mes documents\Mails eudora\attach\X-45.php.htm
                    Virus:W32/Rahack.gen Disinfected D:\Mes documents\Mails eudora\attach\zhjjtetw.exe
                    Virus:W32/Rahack.gen Disinfected D:\Mes documents\Mails eudora\attach\zkbvljee.exe
                    Potentially unwanted tool:Application/Processor Not disinfected D:\MSNFix\MSNFix\incl\Process.exe
                    Adware:Adware/Gator Not disinfected D:\System Volume Information\_restore{C91BECE4-364E-419D-8A7E-2457E6AC1105}\RP2\A0002160.exe
                    1. Contributeur sécurité
                      Re,
                      Peux-tu éditer aussi le rapport Hijackthis et dis-moi comment le pc se porte.

                      FillPCA
                      Edite : on s'est croisé. J'examine ceci.
                      1. salut,
                        je peux malheureusement pas rester plus longtemps ce soir sur le PC.
                        je lirai ton verdict demain (bon j'espère) et je finirai de faire ce qu'il faut dans l'après-midi.

                        merci encore et bonne soirée

                        antoine
                    2. et voici le hijackthis

                      Logfile of Trend Micro HijackThis v2.0.2
                      Scan saved at 21:27:02, on 21/08/2007
                      Platform: Windows XP SP1 (WinNT 5.01.2600)
                      MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
                      Boot mode: Normal

                      Running processes:
                      C:\WINDOWS\System32\smss.exe
                      C:\WINDOWS\system32\winlogon.exe
                      C:\WINDOWS\system32\services.exe
                      C:\WINDOWS\system32\lsass.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\WINDOWS\system32\ZoneLabs\vsmon.exe
                      C:\WINDOWS\Explorer.EXE
                      C:\WINDOWS\System32\RUNDLL32.EXE
                      C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
                      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
                      C:\WINDOWS\System32\ctfmon.exe
                      C:\WINDOWS\system32\spoolsv.exe
                      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                      C:\WINDOWS\System32\nvsvc32.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\Program Files\Internet Explorer\iexplore.exe
                      C:\Program Files\MSN Messenger\usnsvc.exe
                      C:\WINDOWS\System32\wuauclt.exe
                      C:\Documents and Settings\Antoine\Bureau\HiJackThis\HijackThis.exe

                      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
                      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                      O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
                      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
                      O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                      O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
                      O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\Winampa.exe"
                      O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
                      O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
                      O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
                      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
                      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
                      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
                      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
                      O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
                      O16 - DPF: {1E2941E3-8E63-11D4-9D5A-00902742D6E0} (iNotes Class) - https://portail.inetpsa.com/http://mailz1.domino.inetpsa.com/iNotes.cab
                      O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
                      O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
                      O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                      O23 - Service: Logitech QuickCam Manager - Unknown owner - C:\WINDOWS\System32\dllcache\mlqm.exe (file missing)
                      O23 - Service: NVIDIA Display Driver Service (nvSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
                      O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
                      1. re-
                        ouais, le rapport est tellement long que tout est pas passé dans la réponse (450 fichiers trouvés de mémoire)

                        voici la fin

                        Virus:W32/Rahack.gen Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\sysinfo\cjrhtnee.exe
                        Virus:W32/Rahack.gen Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\sysinfo\cszbbkjb.exe
                        Virus:W32/Rahack.gen Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\sysinfo\hzenbhql.exe
                        Virus:W32/Rahack.gen Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\sysinfo\kenjxzsk.exe
                        Virus:HTML/Instancob.A Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\sysinfo\msinfo.htm
                        Virus:W32/Rahack.gen Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\sysinfo\qnkstrhn.exe
                        Virus:W32/Rahack.gen Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\sysinfo\selznkbn.exe
                        Virus:HTML/Instancob.A Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\sysinfo\sysComponentInfo.htm
                        Virus:HTML/Instancob.A Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\sysinfo\sysEvtLogInfo.htm
                        Virus:HTML/Instancob.A Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\sysinfo\sysHealthInfo.htm
                        Virus:HTML/Instancob.A Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\sysinfo\sysinfosum.htm
                        Virus:HTML/Instancob.A Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\sysinfo\sysRemoteInfo.htm
                        Virus:HTML/Instancob.A Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\sysinfo\sysServicesInfo.htm
                        Virus:HTML/Instancob.A Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\sysinfo\sysSoftwareInfo.htm
                        Virus:W32/Rahack.gen Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\sysinfo\tehbbexs.exe
                        Virus:W32/Rahack.gen Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\sysinfo\trvnbvzr.exe
                        Virus:HTML/Instancob.A Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\UpdateCtr\AboutWU.htm
                        Virus:W32/Rahack.gen Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\UpdateCtr\ecrvhvjh.exe
                        Virus:W32/Rahack.gen Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\UpdateCtr\ewznktww.exe
                        Virus:W32/Rahack.gen Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\UpdateCtr\hnshlbtv.exe
                        Virus:W32/Rahack.gen Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\UpdateCtr\hsxenjvk.exe
                        Virus:HTML/Instancob.A Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\UpdateCtr\Learn.htm
                        Virus:HTML/Instancob.A Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\UpdateCtr\LearnInternet.htm
                        Virus:HTML/Instancob.A Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\UpdateCtr\learnWU.htm
                        Virus:W32/Rahack.gen Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\UpdateCtr\necxlsbh.exe
                        Virus:HTML/Instancob.A Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\UpdateCtr\updatecenter.htm
                        Virus:HTML/Instancob.A Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Connection.htm
                        Virus:W32/Rahack.gen Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\estewkrn.exe
                        Virus:HTML/Instancob.A Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\OfflineDC.htm
                        Virus:HTML/Instancob.A Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\OfflineOptions.htm
                        Virus:W32/Rahack.gen Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\btlekkxb.exe
                        Virus:W32/Rahack.gen Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Common\btlekkxb.exe
                        Virus:HTML/Instancob.A Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Common\ConnIssue.htm
                        Virus:HTML/Instancob.A Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Common\LearnInternet.htm
                        Virus:HTML/Instancob.A Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Common\RCMoreInfo.htm
                        Virus:HTML/Instancob.A Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\confirm.htm
                        Virus:W32/Rahack.gen Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Common\btlekkxb.exe
                        Virus:HTML/Instancob.A Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Common\rcConnection.htm
                        Virus:HTML/Instancob.A Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Common\rcscreen1.htm
                        Virus:HTML/Instancob.A Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Common\rcscreen2.htm
                        Virus:HTML/Instancob.A Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Common\rcscreen3.htm
                        Virus:W32/Rahack.gen Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Email\btlekkxb.exe
                        Virus:HTML/Instancob.A Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Email\rcDetails.htm
                        Virus:HTML/Instancob.A Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Email\rcInviteStatus.htm
                        Virus:HTML/Instancob.A Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Email\rcscreen4.htm
                        Virus:HTML/Instancob.A Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Email\rcscreen5.htm
                        Virus:HTML/Instancob.A Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Email\rcscreen6.htm
                        Virus:HTML/Instancob.A Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Email\rcscreen6_head.htm
                        Virus:HTML/Instancob.A Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Email\rcscreen7.htm
                        Virus:HTML/Instancob.A Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Email\rcscreen8.htm
                        Virus:HTML/Instancob.A Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Email\rcscreen9.htm
                        Virus:HTML/Instancob.A Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\rcstatus.htm
                        Virus:W32/Rahack.gen Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\tlrrsvlj.exe
                        Virus:W32/Rahack.gen Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\zejthvxk.exe
                        Virus:HTML/Instancob.A Disinfected C:\WINDOWS\ServicePackFiles\i386\activ.htm
                        Virus:HTML/Instancob.A Disinfected C:\WINDOWS\ServicePackFiles\i386\activsvc.htm
                        Virus:HTML/Instancob.A Disinfected C:\WINDOWS\ServicePackFiles\i386\actlan.htm
                        Virus:HTML/Instancob.A Disinfected C:\WINDOWS\ServicePackFiles\i386\actshell.htm
                        Virus:HTML/Instancob.A Disinfected C:\WINDOWS\ServicePackFiles\i386\adeskerr.htm
                        Virus:W32/Rahack.gen Disinfected C:\WINDOWS\ServicePackFiles\i386\bkssenst.exe
                        Virus:W32/Rahack.gen Disinfected C:\WINDOWS\ServicePackFiles\i386\brnkzltb.exe
                        Virus:W32/Rahack.gen Disinfected C:\WINDOWS\ServicePackFiles\i386\ctjbrrsw.exe
                        Virus:HTML/Instancob.A Disinfected C:\WINDOWS\ServicePackFiles\i386\msobshel.htm
                        Virus:HTML/Instancob.A Disinfected C:\WINDOWS\ServicePackFiles\i386\neweula.htm
                        Virus:W32/Rahack.gen Disinfected C:\WINDOWS\ServicePackFiles\i386\rcvrjrrh.exe
                        Virus:W32/Rahack.gen Disinfected C:\WINDOWS\ServicePackFiles\i386\tqbknlnb.exe
                        Virus:HTML/Instancob.A Disinfected C:\WINDOWS\ServicePackFiles\i386\tsweb1.htm
                        Virus:W32/Rahack.gen Disinfected C:\WINDOWS\ServicePackFiles\i386\tznzcrkl.exe
                        Virus:W32/Rahack.gen Disinfected C:\WINDOWS\ServicePackFiles\i386\zejkxcwb.exe
                        Virus:W32/Rahack.gen Disinfected C:\WINDOWS\ServicePackFiles\i386\znbbsjsk.exe
                        Virus:Generic Malware Disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\04O3Q4V7\84785_redworld[1].exe
                        Virus:W32/Spybot.AIE.worm Disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\04O3Q4V7\84785_winhtb[2].exe
                        Virus:W32/Spybot.AIE.worm Disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\04O3Q4V7\84785_winhtb[4].exe
                        Virus:W32/Spybot.AIE.worm Disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\04O3Q4V7\84785_winhtb[5].exe
                        Virus:Trj/Diazom.AU Disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\04O3Q4V7\edcv[1].jpg
                        Virus:Trj/Diazom.AU Disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\04O3Q4V7\edcv[2].jpg
                        Virus:W32/Spybot.AIE.worm Disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3YNSY7MI\84785_winhtb[1].exe
                        Virus:W32/Spybot.AIE.worm Disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3YNSY7MI\84785_winhtb[2].exe
                        Virus:W32/Spybot.AIE.worm Disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3YNSY7MI\84785_winhtb[3].exe
                        Virus:W32/Sdbot.KQD.worm Disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3YNSY7MI\84785_winsrp[1].exe
                        Virus:W32/Sdbot.KQD.worm Disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3YNSY7MI\84785_winsrp[2].exe
                        Virus:Generic Malware Disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\OW73WBHC\84785_redworld[1].exe
                        Virus:Generic Malware Disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\OW73WBHC\84785_redworld[2].exe
                        Virus:W32/Spybot.AIE.worm Disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\OW73WBHC\84785_winhtb[1].exe
                        Virus:W32/Spybot.AIE.worm Disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\OW73WBHC\84785_winhtb[2].exe
                        Virus:W32/Sdbot.KQD.worm Disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\OW73WBHC\84785_winsrp[1].exe
                        Virus:Trj/Diazom.AU Disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\OW73WBHC\edcv[1].jpg
                        Virus:W32/Spybot.AIE.worm Disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\SW936MKX\84785_winhtb[1].exe
                        Virus:W32/Sdbot.KQD.worm Disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\SW936MKX\84785_winsrp[1].exe
                        Virus:W32/Sdbot.KQD.worm Disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\SW936MKX\84785_winsrp[2].exe
                        Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\actsetup\actconn.htm
                        Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\actsetup\actdone.htm
                        Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\actsetup\activ.htm
                        Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\actsetup\activerr.htm
                        Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\actsetup\activsvc.htm
                        Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\actsetup\actlan.htm
                        Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\actsetup\adeskerr.htm
                        Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\actsetup\adrdyreg.htm
                        Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\actsetup\apolicy.htm
                        Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\actsetup\aprvcyms.htm
                        Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\actsetup\areg1.htm
                        Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\actsetup\aregdial.htm
                        Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\actsetup\aregdone.htm
                        Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\actsetup\ausrinfo.htm
                        Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\actsetup\blvccbsx.exe
                        Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\actsetup\brvecwcs.exe
                        Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\actsetup\btesnnel.exe
                        Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\actsetup\btqkxenz.exe
                        Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\actsetup\cwbbnetr.exe
                        Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\actsetup\hlrrerkq.exe
                        Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\actsetup\knkskthw.exe
                        Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\actsetup\lrlzztll.exe
                        Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\actsetup\nzzwhebn.exe
                        Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\actsetup\rkjenssc.exe
                        Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\actsetup\rrthsntk.exe
                        Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\actsetup\tchekrqt.exe
                        Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\actsetup\vrrkkhbn.exe
                        Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\actsetup\zvswnlev.exe
                        Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\actshell.htm
                        Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\dtsgnup.htm
                        Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\error\cnncterr.htm
                        Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\error\dialtone.htm
                        Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\error\ektltnch.exe
                        Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\error\erettxjr.exe
                        Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\error\hndshake.htm
                        Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\error\isp2busy.htm
                        Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\error\jkhehnjn.exe
                        Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\error\kbwnhlkk.exe
                        Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\error\lktkttrb.exe
                        Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\error\neehnzxl.exe
                        Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\error\noanswer.htm
                        Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\error\pberr.htm
                        Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\error\pulse.htm
                        Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\error\sswzlttc.exe
                        Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\error\toobusy.htm
                        Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\error\xenjnbqe.exe
                        Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\html\dslmain\dslmain.htm
                        Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\html\dslmain\dsl_a.htm
                        Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\html\dslmain\dsl_b.htm
                        Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\html\dslmain\nevttblh.exe
                        Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\html\dslmain\qxztllwj.exe
                        Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\html\dslmain\slhcezwb.exe
                        Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\html\iconnect\icntlast.htm
                        Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\html\iconnect\iconnect.htm
                        Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\html\iconnect\jsnsljzh.exe
                        Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\html\iconnect\shrtrsbs.exe
                        Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\html\isptype\isptype.htm
                        Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\html\isptype\lnvlnzbq.exe
                        Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\html\mouse\bccxejnc.exe
                        Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\html\mouse\bzrbbsrn.exe
                        Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\html\mouse\cjxsjlbr.exe
                        Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\html\mouse\hcvxrtwz.exe
                        Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\html\mouse\jjlhknhh.exe
                        Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\html\mouse\jlkshlvl.exe
                        Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\html\mouse\khkvhhsb.exe
                        Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\html\mouse\klkhkrts.exe
                        Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\html\mouse\lbzcxver.exe
                        Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\html\mouse\mouse.htm
                        Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\html\mouse\mouse_a.htm
                        Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\html\mouse\mouse_b.htm
                        Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\html\mouse\mouse_c.htm
                        Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\html\mouse\mouse_d.htm
                        Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\html\mouse\mouse_e.htm
                        Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\html\mouse\mouse_f.htm
                        Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\html\mouse\mouse_g.htm
                        Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\html\mouse\mouse_h.htm
                        Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\html\mouse\mouse_i.htm
                        Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\html\mouse\mouse_j.htm
                        Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\html\mouse\mouse_k.htm
                        Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\html\mouse\nrlcnzsh.exe
                        Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\html\mouse\qetvqlnw.exe
                        Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\html\mouse\rbnrnnxt.exe
                        Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\html\sconnect\jkhjlhbb.exe
                        Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\html\sconnect\scntlast.htm
                        Virus:HTML/Instancob.A Disinfected C:\WINDOWS\system32\oobe\html\sconnect\sconnect.htm
                        Virus:W32/Rahack.gen Disinfected C:\WINDOWS\system32\oobe\html\sconnect\vznnebet.exe
                        1. Contributeur sécurité
                          Bonsoir,

                          Lol !

                          En vitesse de crosière, tu vas passer du MO5 ou quadri-core !

                          Je crois que le rapport Panda est incomplet !

                          FillPCA
                          1. salut,
                            ça a été assez long en effet de tout faire, comme annoncé
                            Voici les rapports, qu'en penses-tu ?

                            SDFix: Version 1.99

                            Run by Antoine on 20/08/2007 at 22:43

                            Microsoft Windows XP [version 5.1.2600]

                            Running From: C:\test\SDFix

                            Safe Mode:
                            Checking Services:

                            Name:
                            M1crosoft Agant
                            Sony Network Analysis Tool

                            ImagePath:
                            "C:\WINDOWS\System32\dllcache\qhotsew.exe"
                            "C:\WINDOWS\System32\dllcache\winsony.exe"

                            M1crosoft Agant - Deleted
                            Sony Network Analysis Tool - Deleted

                            Restoring Windows Registry Values
                            Restoring Windows Default Hosts File

                            Rebooting...

                            Normal Mode:
                            Checking Files:

                            Trojan Files Found:

                            C:\WINDOWS\system32\dllcache\qhotsew.exe - Deleted
                            C:\WINDOWS\system32\dllcache\winsony.exe - Deleted

                            Removing Temp Files...

                            ADS Check:

                            C:\WINDOWS
                            No streams found.

                            C:\WINDOWS\system32
                            No streams found.

                            C:\WINDOWS\system32\svchost.exe
                            No streams found.

                            C:\WINDOWS\system32\ntoskrnl.exe
                            No streams found.

                            Final Check:

                            Remaining Services:
                            ------------------

                            Authorized Application Key Export:

                            [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
                            "C:\\WINDOWS\\System32\\dllcache\\mlqm.exe"="C:\\WINDOWS\\System32\\dllcache\\mlqm.exe:*:Enabled:Logitech QuickCam Manager"

                            [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

                            Remaining Files:
                            ---------------

                            File Backups: - C:\test\SDFix\backups\backups.zip
                            Registry Backups: - C:\test\SDFix\backups\backupreg.zip
                            Full Registry Backup: - C:\WINDOWS\ERUNT\SDFIX\ERDNT.EXE

                            Files with Hidden Attributes:

                            Finished

                            ---------------------------------------------------------
                            AVG Anti-Spyware - Rapport d'analyse
                            ---------------------------------------------------------

                            + Créé à: 20:35:30 21/08/2007

                            + Résultat de l'analyse:

                            C:\avenger\backup-20.08.2007-22.27.18,13.zip/avenger/iea.dll -> Adware.BHO : Nettoyé et sauvegardé (mise en quarantaine).
                            C:\SDFix\backups\backups.zip/backups/winegne.exe -> Backdoor.IRCBot.aaq : Nettoyé et sauvegardé (mise en quarantaine).
                            C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\SW936MKX\84785_winsptr[1].exe -> Backdoor.IRCBot.aaq : Nettoyé et sauvegardé (mise en quarantaine).
                            C:\Documents and Settings\Antoine\Cookies\antoine@atdmt[1].txt -> TrackingCookie.Atdmt : Nettoyé.

                            Fin du rapport

                            Incident Status Location

                            Virus:W32/Spybot.AIE.worm Disinfected C:\avenger\backup.zip[avenger/mlqm.exe]
                            Virus:W32/RAHack.II.worm Disinfected C:\avenger\backup.zip[avenger/wms.exe]
                            Potentially unwanted tool:Application/NirCmd.A Not disinfected C:\Documents and Settings\Antoine\Bureau\ComboFix.exe[nircmd.exe]
                            Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Antoine\Bureau\SDFix.exe[SDFix\apps\Process.exe]
                            Spyware:Cookie/Xiti Not disinfected C:\Documents and Settings\Antoine\Cookies\antoine@xiti[1].txt
                            Virus:Trj/Diazom.AU Disinfected C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\0DE3WLI3\cv_3.0[1].exe
                            Virus:W32/Sdbot.KZS.worm Disinfected C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\WDUJ4XMZ\mxv22t[1].jpg
                            Virus:HTML/Instancob.A Disinfected C:\Program Files\Fichiers communs\Microsoft Shared\Papier à lettres\Belle journée.htm
                            Virus:W32/Rahack.gen Disinfected C:\Program Files\Fichiers communs\Microsoft Shared\Papier à lettres\bxjsjwkl.exe
                            Virus:HTML/Instancob.A Disinfected C:\Program Files\Fichiers communs\Microsoft Shared\Papier à lettres\Camemberts.htm
                            Virus:W32/Rahack.gen Disinfected C:\Program Files\Fichiers communs\Microsoft Shared\Papier à lettres\cvhrrnkr.exe
                            Virus:HTML/Instancob.A Disinfected C:\Program Files\Fichiers communs\Microsoft Shared\Papier à lettres\Céramique.htm
                            Virus:W32/Rahack.gen Disinfected C:\Program Files\Fichiers communs\Microsoft Shared\Papier à lettres\ekzwrrrn.exe
                            Virus:HTML/Instancob.A Disinfected C:\Program Files\Fichiers communs\Microsoft Shared\Papier à lettres\Feuilles.htm
                            Virus:HTML/Instancob.A Disinfected C:\Program Files\Fichiers communs\Microsoft Shared\Papier à lettres\Fiesta.htm
                            Virus:HTML/Instancob.A Disinfected C:\Program Files\Fichiers communs\Microsoft Shared\Papier à lettres\Glacier.htm
                            Virus:W32/Rahack.gen Disinfected C:\Program Files\Fichiers communs\Microsoft Shared\Papier à lettres\hvxbzklt.exe
                            Virus:W32/Rahack.gen Disinfected C:\Program Files\Fichiers communs\Microsoft Shared\Papier à lettres\jekrcktb.exe
                            Virus:W32/Rahack.gen Disinfected C:\Program Files\Fichiers communs\Microsoft Shared\Papier à lettres\lhlksbkv.exe
                            Virus:HTML/Instancob.A Disinfected C:\Program Files\Fichiers communs\Microsoft Shared\Papier à lettres\Lierre.htm
                            Virus:W32/Rahack.gen Disinfected C:\Program Files\Fichiers communs\Microsoft Shared\Papier à lettres\llvbnekb.exe
                            Virus:HTML/Instancob.A Disinfected C:\Program Files\Fichiers communs\Microsoft Shared\Papier à lettres\Nature.htm
                            Virus:W32/Rahack.gen Disinfected C:\Program Files\Fichiers communs\Microsoft Shared\Papier à lettres\nshxrvsz.exe
                            Virus:HTML/Instancob.A Disinfected C:\Program Files\Fichiers communs\Microsoft Shared\Papier à lettres\Punch aux agrumes.htm
                            Virus:W32/Rahack.gen Disinfected C:\Program Files\Fichiers communs\Microsoft Shared\Papier à lettres\reehbqsr.exe
                            Virus:W32/Rahack.gen Disinfected C:\Program Files\Fichiers communs\Microsoft Shared\Papier à lettres\reeqntbt.exe
                            Virus:HTML/Instancob.A Disinfected C:\Program Files\Fichiers communs\Microsoft Shared\Papier à lettres\Réseau.htm
                            Virus:HTML/Instancob.A Disinfected C:\Program Files\Fichiers communs\Microsoft Shared\Papier à lettres\Sucreries.htm
                            Virus:W32/Rahack.gen Disinfected C:\Program Files\Fichiers communs\Microsoft Shared\Papier à lettres\tcsbtese.exe
                            Virus:HTML/Instancob.A Disinfected C:\Program Files\Fichiers communs\Microsoft Shared\Papier à lettres\Technique.htm
                            Virus:HTML/Instancob.A Disinfected C:\Program Files\Fichiers communs\Microsoft Shared\Papier à lettres\Tournesol.htm
                            Virus:W32/Rahack.gen Disinfected C:\Program Files\Fichiers communs\Microsoft Shared\Papier à lettres\vhsbbknz.exe
                            Virus:HTML/Instancob.A Disinfected C:\Program Files\Fichiers communs\Microsoft Shared\Papier à lettres\Vierge.htm
                            Virus:W32/Rahack.gen Disinfected C:\Program Files\Fichiers communs\Microsoft Shared\Papier à lettres\xcrhcljj.exe
                            Virus:W32/Rahack.gen Disinfected C:\Program Files\Fichiers communs\Microsoft Shared\Papier à lettres\zqkrvsre.exe
                            Virus:HTML/Instancob.A Disinfected C:\Program Files\Fichiers communs\System\ado\MDACReadme.htm
                            Virus:W32/Rahack.gen Disinfected C:\Program Files\Fichiers communs\System\ado\svsllkjj.exe
                            Virus:W32/Rahack.gen Disinfected C:\Program Files\K-Lite Codec Pack\info\eeneszvj.exe
                            Virus:HTML/Instancob.A Disinfected C:\Program Files\K-Lite Codec Pack\info\faq.htm
                            Virus:HTML/Instancob.A Disinfected C:\Program Files\MSN\MSNCoreFiles\msnread.htm
                            Virus:W32/Rahack.gen Disinfected C:\Program Files\MSN\MSNCoreFiles\tlbhnrlv.exe
                            Virus:HTML/Instancob.A Disinfected C:\Program Files\NetMeeting\netmeet.htm
                            Virus:W32/Rahack.gen Disinfected C:\Program Files\NetMeeting\rsewzjqn.exe
                            Virus:HTML/Instancob.A Disinfected C:\Program Files\Qualcomm\Eudora\eudora.htm
                            Virus:W32/Rahack.gen Disinfected C:\Program Files\Qualcomm\Eudora\xkkwlkwr.exe
                            Virus:HTML/Instancob.A Disinfected C:\Program Files\VideoLAN\VLC\http\old\admin\browse.html
                            Virus:W32/Rahack.gen Disinfected C:\Program Files\VideoLAN\VLC\http\old\admin\lznelksn.exe
                            Virus:HTML/Instancob.A Disinfected C:\Program Files\VideoLAN\VLC\http\old\info.html
                            Virus:W32/Rahack.gen Disinfected C:\Program Files\VideoLAN\VLC\http\old\wjnhtlje.exe
                            Virus:HTML/Instancob.A Disinfected C:\Program Files\Winamp\winampmb.htm
                            Virus:W32/Rahack.gen Disinfected C:\Program Files\Winamp\xkchlkhn.exe
                            Virus:Trj/Diazom.AU Disinfected C:\QooBox\Quarantine\C\c.exe.vir
                            Virus:Trj/Diazom.AU Disinfected C:\QooBox\Quarantine\C\WINDOWS\system32\a.exe.vir
                            Potentially unwanted tool:Application/Processor Not disinfected C:\SDFix\apps\Process.exe
                            Potentially unwanted tool:Application/Processor Not disinfected C:\test\SDFix\apps\Process.exe
                            Virus:Generic Malware Disinfected C:\test\SDFix\backups\backups.zip[backups/qhotsew.exe]
                            Virus:W32/Sdbot.KQD.worm Disinfected C:\test\SDFix\backups\backups.zip[backups/winsony.exe]
                            Virus:HTML/Instancob.A Disinfected C:\WINDOWS\$NtServicePackUninstall$\activ.htm
                            Virus:HTML/Instancob.A Disinfected C:\WINDOWS\$NtServicePackUninstall$\activsvc.htm
                            Virus:HTML/Instancob.A Disinfected C:\WINDOWS\$NtServicePackUninstall$\actlan.htm
                            Virus:HTML/Instancob.A Disinfected C:\WINDOWS\$NtServicePackUninstall$\actshell.htm
                            Virus:HTML/Instancob.A Disinfected C:\WINDOWS\$NtServicePackUninstall$\adeskerr.htm
                            Virus:W32/Rahack.gen Disinfected C:\WINDOWS\$NtServicePackUninstall$\bjhkxjjz.exe
                            Virus:W32/Rahack.gen Disinfected C:\WINDOWS\$NtServicePackUninstall$\eklnhrej.exe
                            Virus:W32/Rahack.gen Disinfected C:\WINDOWS\$NtServicePackUninstall$\hhellnvw.exe
                            Virus:W32/Rahack.gen Disinfected C:\WINDOWS\$NtServicePackUninstall$\ltknjbsx.exe
                            Virus:HTML/Instancob.A Disinfected C:\WINDOWS\$NtServicePackUninstall$\msobshel.htm
                            Virus:W32/Rahack.gen Disinfected C:\WINDOWS\$NtServicePackUninstall$\nbkcnwsv.exe
                            Virus:HTML/Instancob.A Disinfected C:\WINDOWS\$NtServicePackUninstall$\neweula.htm
                            Virus:W32/Rahack.gen Disinfected C:\WINDOWS\$NtServicePackUninstall$\rthejeet.exe
                            Virus:W32/Rahack.gen Disinfected C:\WINDOWS\$NtServicePackUninstall$\tthtelsk.exe
                            Virus:W32/Rahack.gen Disinfected C:\WINDOWS\Help\bzehxvnz.exe
                            Virus:HTML/Instancob.A Disinfected C:\WINDOWS\Help\ciadmin.htm
                            Virus:HTML/Instancob.A Disinfected C:\WINDOWS\Help\ciquery.htm
                            Virus:W32/Rahack.gen Disinfected C:\WINDOWS\Help\hwexrtne.exe
                            Virus:HTML/Instancob.A Disinfected C:\WINDOWS\Help\ixqlang.htm
                            Virus:W32/Rahack.gen Disinfected C:\WINDOWS\Help\jbnshhqj.exe
                            Virus:W32/Rahack.gen Disinfected C:\WINDOWS\Help\jjlenkbt.exe
                            Virus:HTML/Instancob.A Disinfected C:\WINDOWS\Help\migwiz.htm
                            Virus:HTML/Instancob.A Disinfected C:\WINDOWS\Help\migwiz2.htm
                            Virus:W32/Rahack.gen Disinfected C:\WINDOWS\Help\Tours\WindowsMediaPlayer\Audio\lllknblj.exe
                            Virus:HTML/Instancob.A Disinfected C:\WINDOWS\Help\Tours\WindowsMediaPlayer\Audio\snd.htm
                            Virus:HTML/Instancob.A Disinfected C:\WINDOWS\Help\Tours\WindowsMediaPlayer\Cnt\contents.htm
                            Virus:W32/Rahack.gen Disinfected C:\WINDOWS\Help\Tours\WindowsMediaPlayer\Cnt\tjnbzhbh.exe
                            Virus:W32/Rahack.gen Disinfected C:\WINDOWS\Help\tsbjbtvn.exe
                            Potentially unwanted tool:Application/NirCmd.A Not disinfected C:\WINDOWS\nircmd.exe
                            Virus:HTML/Instancob.A Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\CompatCtr\AboutCompat.htm
                            Virus:W32/Rahack.gen Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\CompatCtr\brvhkxjh.exe
                            Virus:HTML/Instancob.A Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\CompatCtr\CompatMode.htm
                            Virus:HTML/Instancob.A Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\CompatCtr\CompatOffline.htm
                            Virus:W32/Rahack.gen Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\CompatCtr\eqlrejrl.exe
                            Virus:HTML/Instancob.A Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\CompatCtr\LearnCompat.htm
                            Virus:W32/Rahack.gen Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\CompatCtr\nrbhslcz.exe
                            Virus:W32/Rahack.gen Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\CompatCtr\tcjqbtst.exe
                            Virus:W32/Rahack.gen Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\DFS\hhktjkel.exe
                            Virus:W32/Rahack.gen Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\DFS\jlskvkjt.exe
                            Virus:HTML/Instancob.A Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\DFS\privacy.htm
                            Virus:HTML/Instancob.A Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\DFS\uplddrvinfo.htm
                            Virus:HTML/Instancob.A Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\DFS\xmldialog.htm
                            Virus:W32/Rahack.gen Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\DFS\zwjcbxql.exe
                            Virus:HTML/Instancob.A Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\DVDUpgrd\dvdupgrd.htm
                            Virus:W32/Rahack.gen Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\DVDUpgrd\kvzexhbs.exe
                            Virus:HTML/Instancob.A Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\ErrMsg\ErrorMessagesOffline.htm
                            Virus:W32/Rahack.gen Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\ErrMsg\nvsbqtlx.exe
                            Virus:HTML/Instancob.A Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\errors\connection.htm
                            Virus:W32/Rahack.gen Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\errors\xnejeese.exe
                            Virus:W32/Rahack.gen Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\NetDiag\bnkrcrqq.exe
                            Virus:HTML/Instancob.A Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\NetDiag\dglogshelp.htm
                            Virus:W32/Rahack.gen Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\NetDiag\stleqtrb.exe
                            Virus:HTML/Instancob.A Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\panels\blank.htm
                            Virus:W32/Rahack.gen Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\panels\tjsnlncx.exe
                            Virus:W32/Rahack.gen Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\panels\zeektjlr.exe
                            Virus:HTML/Instancob.A Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\rc\rcRequest.htm
                            Virus:W32/Rahack.gen Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\rc\rjzhtwer.exe
                            Virus:HTML/Instancob.A Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\Remote Assistance\Common\ConnIssue.htm
                            Virus:W32/Rahack.gen Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\Remote Assistance\Common\jqnsbclx.exe
                            Virus:W32/Rahack.gen Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\Remote Assistance\Common\jzrjzkke.exe
                            Virus:HTML/Instancob.A Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\Remote Assistance\Common\LearnInternet.htm
                            Virus:HTML/Instancob.A Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\Remote Assistance\Common\RCMoreInfo.htm
                            Virus:W32/Rahack.gen Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\Remote Assistance\Common\vtxbneqq.exe
                            Virus:HTML/Instancob.A Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\Remote Assistance\helpeeaccept.htm
                            Virus:W32/Rahack.gen Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\Remote Assistance\Interaction\Client\cqlwbrtn.exe
                            Virus:HTML/Instancob.A Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\Remote Assistance\Interaction\Client\DividerBar.htm
                            Virus:W32/Rahack.gen Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\Remote Assistance\Interaction\Client\hlnbkbjt.exe
                            Virus:W32/Rahack.gen Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\Remote Assistance\Interaction\Client\jllrjejn.exe
                            Virus:W32/Rahack.gen Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\Remote Assistance\Interaction\Client\kcqrjjel.exe
                            Virus:HTML/Instancob.A Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\Remote Assistance\Interaction\Client\RAChatClient.htm
                            Virus:HTML/Instancob.A Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\Remote Assistance\Interaction\Client\RAClient.htm
                            Virus:HTML/Instancob.A Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\Remote Assistance\Interaction\Client\RAStatusBar.htm
                            Virus:HTML/Instancob.A Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\Remote Assistance\Interaction\Client\rcscreen6_head.htm
                            Virus:W32/Rahack.gen Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\Remote Assistance\Interaction\Client\resrzjkr.exe
                            Virus:W32/Rahack.gen Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\Remote Assistance\Interaction\Client\rlkctexe.exe
                            Virus:HTML/Instancob.A Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\Remote Assistance\Interaction\Client\setting.htm
                            Virus:HTML/Instancob.A Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\Remote Assistance\Interaction\Common\ErrorMsgs.htm
                            Virus:W32/Rahack.gen Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\Remote Assistance\Interaction\Common\jjtkbtsb.exe
                            Virus:HTML/Instancob.A Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\Remote Assistance\Interaction\Common\RCFileXfer.htm
                            Virus:W32/Rahack.gen Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\Remote Assistance\Interaction\Common\slkweqkr.exe
                            Virus:HTML/Instancob.A Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\Remote Assistance\Interaction\Common\VOIPMsgs.htm
                            Virus:W32/Rahack.gen Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\Remote Assistance\Interaction\Common\xxrlrrck.exe
                            Virus:W32/Rahack.gen Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\Remote Assistance\Interaction\Server\bbcrvske.exe
                            Virus:W32/Rahack.gen Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\Remote Assistance\Interaction\Server\brbjhjhb.exe
                            Virus:HTML/Instancob.A Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\Remote Assistance\Interaction\Server\DividerBar1.htm
                            Virus:HTML/Instancob.A Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\Remote Assistance\Interaction\Server\DividerBar2.htm
                            Virus:W32/Rahack.gen Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\Remote Assistance\Interaction\Server\ejjtwclz.exe
                            Virus:W32/Rahack.gen Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\Remote Assistance\Interaction\Server\heclkcje.exe
                            Virus:HTML/Instancob.A Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\Remote Assistance\Interaction\Server\RAChatServer.htm
                            Virus:HTML/Instancob.A Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\Remote Assistance\Interaction\Server\SettingServer.htm
                            Virus:HTML/Instancob.A Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\Remote Assistance\Interaction\Server\TakeControlMsgs.htm
                            Virus:W32/Rahack.gen Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\Remote Assistance\Interaction\Server\vhzlshll.exe
                            Virus:W32/Rahack.gen Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\Remote Assistance\lbncltew.exe
                            Virus:W32/Rahack.gen Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\Remote Assistance\lenvstcw.exe
                            Virus:HTML/Instancob.A Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\Remote Assistance\RAStartPage.htm
                            Virus:HTML/Instancob.A Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\Remote Assistance\rcBuddy.htm
                            Virus:W32/Rahack.gen Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\Remote Assistance\sljktqsl.exe
                            Virus:W32/Rahack.gen Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\sysinfo\cjrhtnee.exe
                            Virus:W32/Rahack.gen Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\sysinfo\cszbbkjb.exe
                            Virus:W32/Rahack.gen Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\sysinfo\hzenbhql.exe
                            Virus:W32/Rahack.gen Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\sysinfo\kenjxzsk.exe
                            Virus:HTML/Instancob.A Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\sysinfo\msinfo.htm
                            Virus:W32/Rahack.gen Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\sysinfo\qnkstrhn.exe
                            Virus:W32/Rahack.gen Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\sysinfo\selznkbn.exe
                            Virus:HTML/Instancob.A Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\sysinfo\sysComponentInfo.htm
                            Virus:HTML/Instancob.A Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\sysinfo\sysEvtLogInfo.htm
                            Virus:HTML/Instancob.A Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\sysinfo\sysHealthInfo.htm
                            Virus:HTML/Instancob.A Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\sysinfo\sysinfosum.htm
                            Virus:HTML/Instancob.A Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\sysinfo\sysRemoteInfo.htm
                            Virus:HTML/Instancob.A Disinfected C:\WINDOWS\PCHEALTH\HELPCTR\System\sysinfo\sysServicesInfo.htm
                            1. Ok, je commence tout ça ce soir. Je finirai demain.
                              Merci beaucoup en tout cas pour ton aide et bonne fin de soirée.

                              antoine
                              1. Contributeur sécurité
                                Re,

                                Rassure-toi, on en parlera. Effectivement, ça va mieux.

                                1/ Installe un firewall car il y a eu ré-infection. Ceci est dû au fait que ton système n'est pas à jour.
                                Tu peux installer zone alarm qui est assez simple à utiliser : https://www.zonealarm.com/software

                                Télécharge la version free.

                                2/ # Imprime ceci (sauf si tu as conservé l'impression).
                                # Redémarre ton ordinateur en mode sans échec en suivant la procédure que voici :

                                * Redémarre ton ordinateur.
                                * Après avoir entendu l'ordinateur biper lors du démarrage, mais avant que l'icône Windows apparaisse, tapote la touche F8 (ou F5).
                                * A la place du chargement normal de Windows, un menu avec différentes options devrait apparaître.
                                * Choisis la première option, pour exécuter Windows en mode sans échec, puis appuie sur "Entrée".
                                * Choisis ton compte.

                                # Déroule la liste des instructions ci-dessous :

                                * En mode sans échec, double-clique sur le fichier SDFix.exe et clique sur install,
                                * Ouvre le dossier SDFix qui vient d'être créé dans le répertoire C:\ et double clique sur RunThis.bat pour lancer le script.
                                * Appuie sur Y pour commencer le script.
                                * Il va supprimer les services de certains trojans, effectuera aussi quelques réparations du Registre et il te demandera d'appuyer sur une touche pour redémarrer.
                                * Appuie sur une touche pour redémarrer le PC.
                                * Ton système sera plus long pour redémarrer qu'à l'accoutumée car l'outil va continuer à s'exécuter et supprimer des fichiers.
                                * Après le chargement du Bureau, l'outil terminera son travail et affichera Finished
                                * Appuie sur une touche pour finir l'exécution du script et charger les icônes de ton Bureau.
                                * Enfin, ouvre le dossier de SDFix sur ton Bureau et copie/colle le contenu du fichier Report.txt dans ta prochaine réponse sur le forum

                                3/ Télécharge Ccleaner Basic https://www.ccleaner.com/ccleaner/download

                                Ouvre Ccleaner, clique sur "lancer le nettoyage".

                                4/ Télécharge AVGantispyware : https://www.avg.com/en-ww/free-antivirus-download
                                Tu l'installes.
                                Lance AVG Anti-Spyware et clique sur le bouton Mise à jour. Patiente.

                                Clique sur le bouton Analyse (de la barre d'outils)
                                Puis sur l'onglets Comment réagir, clique sur Actions recommandées. Sélectionne Quarantaine.
                                Reviens à l'onglet Analyse. Clique sur Analyse complète du système.
                                A la fin du scan, choisis l'option " Appliquer toutes les actions " en bas. Ensuite.
                                Clique sur "Enregistrer le rapport". Ceci génère un rapport en fichier texte qui se trouve dans le dossier Reports du dossier d'AVG Anti-Spyware.

                                5/ * Fais un scan en ligne en cliquant ici : http://assiste.com.free.fr/...
                                * Choisis Panda
                                * Tu dois réaliser le scan en utilisant Internet explorer. Une information apparait en haut, près de la barre d'état. Tu dois accepter et installer l'activeX proposé. La mise à jour de l'antivirus se lance.
                                * Réalise un scan complet du système.
                                * Sauvegarde le rapport en mode texte à l'issue du scan.

                                6/ Edite les rapports suivants :
                                SDfix, AVGantispyware, Panda et un nouveau rapport Hijackthis.

                                Cela risque de prendre du temps mais je serai là demain pour achever le nettoyage de ton PC.

                                FillPCA
                                1. Re
                                  ça a l'air déjà beaucoup mieux... merci beaucoup

                                  (pour après, tu as des conseils pour protéger le PC à l'avenir ? :-) )

                                  voici les rapports :

                                  Logfile of The Avenger version 1, by Swandog46
                                  Running from registry key:
                                  \Registry\Machine\System\CurrentControlSet\Services\eunfmvog

                                  *******************

                                  Script file located at: \??\C:\WINDOWS\System32\gdjugxqm.txt
                                  Script file opened successfully.

                                  Script file read successfully

                                  Backups directory opened successfully at C:\Avenger

                                  *******************

                                  Beginning to process script file:

                                  Driver wms unloaded successfully.

                                  File C:\1.vbs not found!
                                  Deletion of file C:\1.vbs failed!

                                  Could not process line:
                                  C:\1.vbs
                                  Status: 0xc0000034

                                  File C:\WINDOWS\System32\iea.dll deleted successfully.
                                  File C:\WINDOWS\system32\divx.dll deleted successfully.
                                  File C:\WINDOWS\web\wcxnjhhj.exe deleted successfully.
                                  File C:\WINDOWS\system32\gyaqpsgo.exe deleted successfully.
                                  File C:\WINDOWS\system32\dllcache\mlqm.exe deleted successfully.
                                  File C:\WINDOWS\System32\1.tmp deleted successfully.
                                  File C:\WINDOWS\System32\def.vpc deleted successfully.
                                  File C:\WINDOWS\System32\wms.exe deleted successfully.
                                  Registry key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B08D32DE-64B2-4137-8345-87293E70D40B} deleted successfully.

                                  Completed script processing.

                                  *******************

                                  Finished! Terminate.

                                  Logfile of Trend Micro HijackThis v2.0.2
                                  Scan saved at 22:02:32, on 20/08/2007
                                  Platform: Windows XP SP1 (WinNT 5.01.2600)
                                  MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
                                  Boot mode: Normal

                                  Running processes:
                                  C:\WINDOWS\System32\smss.exe
                                  C:\WINDOWS\system32\winlogon.exe
                                  C:\WINDOWS\system32\services.exe
                                  C:\WINDOWS\system32\lsass.exe
                                  C:\WINDOWS\system32\svchost.exe
                                  C:\WINDOWS\System32\svchost.exe
                                  C:\WINDOWS\Explorer.EXE
                                  C:\WINDOWS\system32\spoolsv.exe
                                  C:\WINDOWS\System32\dllcache\qhotsew.exe
                                  C:\WINDOWS\System32\nvsvc32.exe
                                  C:\WINDOWS\System32\dllcache\winsony.exe
                                  C:\WINDOWS\System32\svchost.exe
                                  C:\WINDOWS\System32\RUNDLL32.EXE
                                  C:\WINDOWS\System32\ctfmon.exe
                                  C:\WINDOWS\system32\NOTEPAD.EXE
                                  C:\Program Files\Internet Explorer\iexplore.exe
                                  C:\Documents and Settings\Antoine\Bureau\HiJackThis\HijackThis.exe

                                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
                                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                                  O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                                  O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
                                  O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
                                  O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                                  O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
                                  O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\Winampa.exe"
                                  O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
                                  O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
                                  O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                                  O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
                                  O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
                                  O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
                                  O23 - Service: Logitech QuickCam Manager - Unknown owner - C:\WINDOWS\System32\dllcache\mlqm.exe (file missing)
                                  O23 - Service: M1crosoft Agant - Unknown owner - C:\WINDOWS\System32\dllcache\qhotsew.exe
                                  O23 - Service: NVIDIA Display Driver Service (nvSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
                                  O23 - Service: Sony Network Analysis Tool - Unknown owner - C:\WINDOWS\System32\dllcache\winsony.exe
                                  1. Contributeur sécurité
                                    Re,

                                    C'est déjà une bonne nouvelle : tu n'as pas à priori Gromozon/Link Optimizer.

                                    A/
                                    1. Télécharger The Avenger par Swandog46 sur votre Bureau :
                                    http://www.geekstogo.com/forum/files/file/393-the-avenger-by-swandog46/
                                    · Click sur Avenger.zip pour ouvrir le fichier
                                    · Extraire avenger.exe sur votre bureau

                                    2. Copier tout le texte de la boîte ci-dessous : mettre en surbrillance et appuyer sur les touches(Ctrl+C):

                                    Drivers to unload:
                                    wms

                                    Registry keys to delete:
                                    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B08D32DE-64B2-4137-8345-87293E70D40B}

                                    Files to delete:
                                    C:\1.vbs
                                    C:\WINDOWS\System32\iea.dll
                                    C:\WINDOWS\system32\divx.dll
                                    C:\WINDOWS\web\wcxnjhhj.exe
                                    C:\WINDOWS\system32\gyaqpsgo.exe
                                    C:\WINDOWS\system32\dllcache\mlqm.exe
                                    C:\WINDOWS\System32\1.tmp
                                    C:\WINDOWS\System32\def.vpc
                                    C:\WINDOWS\System32\wms.exe


                                    Note: Le code ci-dessus a été intentionnellement rédigé pour CET utilisateur.
                                    si vous n'êtes pas CET utilisateur, NE PAS appliquer ces directives : elles pourraient endommager votre système.

                                    3. Maintenant, lancer The Avenger en cliquant sur son icône du bureau.
                                    · Sous "Script file to execute" choisir "Input Script Manually".
                                    · Puis cliquer sur l'icône en forme de loupe qui va ouvrir une nouvelle fenêtre "View/edit script"
                                    · Dans cette fenêtre, coller le texte précedemment copié sur le bureau par les touches (Ctrl+V).
                                    · Cliquer Done
                                    · ensuite cliquer sur l'icône en forme de Feu Vert pour démarrer l'exécution du script
                                    · Répondre "Yes" deux fois quand demandé.
                                    4. The Avenger va automatiquement faire ce qui suit:
                                    · Il va Re-démarrer le système. ( Dans les cas où le script contient un/des "Drivers to Unload", The Avenger re-démarrera votre système 2 fois.)
                                    · Pendant le re-démarrage, il apparaitra brièvement une fenêtre de commande de windows noire sur votre bureau, ceci est NORMAL.
                                    · Après le re-démarrage, il crée un fichier log qui s'ouvrira, faisant apparaitre les actions exécutées par The Avenger. Ce fichier log se trouve ici : C:\avenger.txt
                                    · The Avenger aura également sauvegardé tous les fichiers, etc., que vous lui avez demandé de supprimer, les aura compactés (zipped) et tranféré l'archive zip ici C:\avenger\backup.zip.
                                    5. Pour finir copier/coller le contenu du ficher c:\avenger.txt dans votre réponse avec un nouveau log HijackThis en utilisant REPONDRE

                                    B/ Edite un rapport Hijackthis et un rapport SREng. Si Hijackthis ne passe pas, édite un rapport PCA.
                                    Il me faut aussi le rapport Avenger.

                                    Ca devrait aller déjà mieux, mais il reste au moins allaple.

                                    Fill
                                    1. re
                                      non sans quelques difficultés, voici la suite
                                      (pas de redémarrage demandé par DiagHelp)

                                      Removal tool loaded into memory
                                      Gromozon rootkit component not detected - searching for other components
                                      Scanning: C:\WINDOWS
                                      Scanning: C:\Program Files\Fichiers communs

                                      Trojan.Gromozon does not exist - your system is clean.

                                      [CODE]

                                      2007-08-20,21:07:50

                                      System Repair Engineer 2.5.16.900
                                      Smallfrogs (http://www.KZTechs.com)

                                      Windows XP Professional Service Pack 1 (Build 2600) - Administrative User - Completed Functions Allowed

                                      Follow item(s) have been choosed:
                                      All Boot Items (Including Registry, Startup Folders, Services and so on)
                                      Browser Add-ons
                                      Runing Processes (Including process model information)
                                      File Associations
                                      Winsock Provider
                                      Autorun.Inf
                                      HOSTS File
                                      Process Privileges Scan

                                      Boot Items
                                      Registry
                                      [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
                                      <CTFMON.EXE><C:\WINDOWS\System32\ctfmon.exe> [(Verified)Microsoft Windows XP Publisher]
                                      [HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
                                      <load><> [N/A]
                                      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
                                      <NvCplDaemon><RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup> [(Verified)Microsoft Windows Hardware Compatibility Publisher]
                                      <nwiz><nwiz.exe /install> [NVIDIA Corporation]
                                      <NvMediaCenter><RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit> [(Verified)Microsoft Windows XP Publisher]
                                      <WinampAgent><"C:\Program Files\Winamp\Winampa.exe"> [N/A]
                                      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
                                      <shell><Explorer.exe> [(Verified)Microsoft Windows XP Publisher]
                                      <Userinit><C:\WINDOWS\system32\userinit.exe,> [(Verified)Microsoft Windows XP Publisher]
                                      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
                                      <AppInit_DLLs><> [N/A]
                                      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
                                      <UIHost><logonui.exe> [(Verified)Microsoft Windows XP Publisher]
                                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
                                      <{EDB0E980-90BD-11D4-8599-0008C7D3B6F8}><C:\Program Files\Qualcomm\Eudora\EuShlExt.dll> [Qualcomm Inc.]
                                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]
                                      <Internet Explorer><%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE> [N/A]
                                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
                                      <Outlook Express><%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE> [N/A]
                                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
                                      <Lecteur Windows Media Microsoft 6.4><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\mplayer2.inf,PerUserStub.NT> [(Verified)Microsoft Windows XP Publisher]
                                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
                                      <Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll> [N/A]
                                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{306D6C21-C1B6-4629-986C-E59E1875B8AF}]
                                      <N/A><"C:\WINDOWS\System32\rundll32.exe" "C:\Program Files\Messenger\msgsc.dll",ShowIconsUser> [(Verified)Microsoft Windows XP Publisher]
                                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
                                      <Microsoft Outlook Express 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install> [N/A]
                                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
                                      <NetMeeting 3.01><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT> [(Verified)Microsoft Windows XP Publisher]
                                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]
                                      <Windows Messenger><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.Install.PerUser> [(Verified)Microsoft Windows XP Publisher]
                                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
                                      <Microsoft Windows Media Player 8><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp.inf,PerUserStub> [(Verified)Microsoft Windows XP Publisher]
                                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
                                      <Carnet d'adresses 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install> [N/A]

                                      ==================================
                                      Startup Folders
                                      N/A

                                      ==================================
                                      Services
                                      [Accès du périphérique d'interface utilisateur / HidServ][Stopped/Disabled]
                                      <C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
                                      [Logitech QuickCam Manager / Logitech QuickCam Manager][Running/Auto Start]
                                      <"C:\WINDOWS\System32\dllcache\mlqm.exe"><N/A>
                                      [NVIDIA Display Driver Service / nvSvc][Running/Auto Start]
                                      <C:\WINDOWS\System32\nvsvc32.exe><NVIDIA Corporation>
                                      [Windows Management Service / wms][Running/Auto Start]
                                      <C:\WINDOWS\System32\wms.exe><N/A>

                                      ==================================
                                      Drivers
                                      [Carte Fast Ethernet 10/100 Mbps ADMtek AN983/AN985/ADM951X / AN983][Stopped/Manual Start]
                                      <System32\DRIVERS\AN983.sys><ADMtek Incorporated.>
                                      [catchme / catchme][Stopped/Manual Start]
                                      <\??\C:\DOCUME~1\Antoine\LOCALS~1\Temp\catchme.sys><N/A>
                                      [Creative AudioPCI (ES1371,ES1373) (WDM) / es1371][Running/Manual Start]
                                      <system32\drivers\es1371mp.sys><Creative Technology Ltd.>
                                      [Logitech USB Monitor Filter / LVUSBSta][Running/Manual Start]
                                      <System32\DRIVERS\LVUSBSta.sys><Logitech Inc.>
                                      [nv / nv][Running/Manual Start]
                                      <System32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
                                      [nv4 / nv4][Stopped/Manual Start]
                                      <System32\DRIVERS\nv4_mini.sys><NVIDIA Corporation>
                                      [Logitech QuickCam Express(PID_0928) / PID_0928][Running/Manual Start]
                                      <System32\DRIVERS\LV561AV.SYS><Logitech Inc.>
                                      [Pilote de liaison parallèle directe / Ptilink][Running/Manual Start]
                                      <System32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
                                      [Secdrv / Secdrv][Stopped/Manual Start]
                                      <System32\DRIVERS\secdrv.sys><N/A>
                                      [VIAPFD / VIAPFD][Running/System Start]
                                      <\SystemRoot\System32\Drivers\VIAPFD.SYS><VIA Technologies. Inc.>
                                      [WinFox Control I/O Driver / WFsys][Running/Manual Start]
                                      <System32\DRIVERS\wfsys.sys><Leadtek Research Inc.>
                                      [Codec Teletext standard / WSTCODEC][Stopped/Manual Start]
                                      <System32\DRIVERS\WSTCODEC.SYS><Microsoft Corporation>

                                      ==================================
                                      Browser Add-ons
                                      [Assistant Class]
                                      {B08D32DE-64B2-4137-8345-87293E70D40B} <C:\WINDOWS\System32\iea.dll, TODO: <Company name>>
                                      [&Radio]
                                      {8E718888-423F-11D2-876E-00A0C9082467} <C:\WINDOWS\System32\msdxm.ocx, Microsoft Corporation>
                                      [WUWebControl Class]
                                      {6414512B-B978-451D-A0D8-FCFDF33E833C} <C:\WINDOWS\System32\wuweb.dll, Microsoft Corporation>
                                      [Shockwave Flash Object]
                                      {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\System32\Macromed\Flash\Flash9d.ocx, Adobe Systems, Inc.>

                                      ==================================
                                      Running Processes
                                      [PID: 368 / SYSTEM][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
                                      [PID: 436 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
                                      [PID: 620 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
                                      [C:\WINDOWS\System32\wdmaud.drv] [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
                                      [C:\WINDOWS\System32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
                                      [PID: 664 / SYSTEM][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
                                      [PID: 676 / SYSTEM][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
                                      [PID: 852 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
                                      [PID: 932 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
                                      [PID: 1072 / SERVICE RÉSEAU][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
                                      [PID: 1092 / SERVICE LOCAL][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
                                      [PID: 1396 / Antoine][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2800.1106 (xpsp1.020828-1920)]
                                      [C:\Program Files\Qualcomm\Eudora\EuShlExt.dll] [Qualcomm Inc., 1, 0, 1, 1]
                                      [PID: 1444 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
                                      [PID: 1588 / SYSTEM][C:\WINDOWS\System32\dllcache\mlqm.exe] [N/A, ]
                                      [C:\WINDOWS\System32\dllcache\WS2_32.dll] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
                                      [C:\WINDOWS\System32\dllcache\WS2HELP.dll] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
                                      [C:\WINDOWS\System32\dllcache\rasadhlp.dll] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
                                      [PID: 1744 / SYSTEM][C:\WINDOWS\System32\nvsvc32.exe] [NVIDIA Corporation, 6.14.10.7189]
                                      [C:\WINDOWS\System32\NVRSFR.DLL] [NVIDIA Corporation, 6.14.10.7189]
                                      [PID: 1812 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
                                      [PID: 1868 / SYSTEM][C:\WINDOWS\System32\wms.exe] [N/A, ]
                                      [PID: 2016 / Antoine][C:\WINDOWS\System32\RUNDLL32.EXE] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
                                      [C:\WINDOWS\System32\NvMcTray.dll] [NVIDIA Corporation, 6.14.10.7189]
                                      [C:\WINDOWS\System32\NVRSFR.DLL] [NVIDIA Corporation, 6.14.10.7189]
                                      [PID: 2024 / Antoine][C:\WINDOWS\System32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
                                      [PID: 2452 / Antoine][C:\Documents and Settings\Antoine\Bureau\SREng2\SREngPS.EXE] [Smallfrogs Studio, 2.5.16.900]
                                      [C:\Documents and Settings\Antoine\Bureau\SREng2\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15]

                                      ==================================
                                      File Associations
                                      .TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
                                      .EXE OK. ["%1" %*]
                                      .COM OK. ["%1" %*]
                                      .PIF OK. ["%1" %*]
                                      .REG OK. [regedit.exe "%1"]
                                      .BAT OK. ["%1" %*]
                                      .SCR OK. ["%1" /S]
                                      .CHM OK. ["C:\WINDOWS\hh.exe" %1]
                                      .HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
                                      .INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
                                      .INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
                                      .VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
                                      .JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
                                      .LNK OK. [{00021401-0000-0000-C000-000000000046}]

                                      ==================================
                                      Winsock Provider
                                      N/A

                                      ==================================
                                      Autorun.Inf
                                      N/A

                                      ==================================
                                      HOSTS File
                                      127.0.0.1 localhost

                                      ==================================
                                      Process Privileges Scan
                                      N/A

                                      ==================================
                                      API HOOK
                                      N/A

                                      ==================================
                                      Hidden Process
                                      N/A

                                      ==================================

                                      [/CODE]

                                      DiagHelp version v1.1.2 - http://www.malekal.com
                                      excute le 20/08/2007 à 21:11:27,38

                                      Liste des derniers fichies modifies/crees dans windir\system32
                                      C:\WINDOWS\System32/drivers\nv4_mini.sys -->01/04/2005 16:16:00
                                      C:\WINDOWS\System32/drivers\LV561AV.SYS -->31/01/2005 12:20:03
                                      C:\WINDOWS\System32/drivers\LVUSBSta.sys -->31/01/2005 12:12:46
                                      C:\WINDOWS\System32/drivers\srv.sys -->20/12/2002 12:36:00
                                      C:\WINDOWS\System32/drivers\rdpwd.sys -->29/08/2002 11:45:24
                                      C:\WINDOWS\System32/drivers\termdd.sys -->29/08/2002 11:45:22
                                      C:\WINDOWS\System32/drivers\dxg.sys -->29/08/2002 11:44:46

                                      C:\WINDOWS\System32\nvapps.xml -->20/08/2007 21:06:02
                                      C:\WINDOWS\System32\1.tmp -->20/08/2007 20:53:22
                                      C:\WINDOWS\System32\wms.exe -->20/08/2007 20:52:56
                                      C:\WINDOWS\System32\def.vpc -->20/08/2007 20:06:27
                                      C:\WINDOWS\System32\iea.dll -->20/08/2007 20:00:33
                                      C:\WINDOWS\System32\wpa.dbl -->19/08/2007 22:00:08
                                      C:\WINDOWS\System32\perfh00C.dat -->19/08/2007 21:10:53
                                      C:\WINDOWS\System32\perfh009.dat -->19/08/2007 21:10:53
                                      C:\WINDOWS\System32\perfc00C.dat -->19/08/2007 21:10:53
                                      C:\WINDOWS\System32\perfc009.dat -->19/08/2007 21:10:53
                                      C:\WINDOWS\System32\PerfStringBackup.INI -->19/08/2007 21:10:52
                                      C:\WINDOWS\System32\FNTCACHE.DAT -->19/08/2007 20:57:29
                                      C:\WINDOWS\System32\lvcoinst.log -->19/08/2007 19:32:22
                                      C:\WINDOWS\System32\h323log.txt -->19/08/2007 17:33:11
                                      C:\WINDOWS\System32\wmpscheme.xml -->19/08/2007 16:48:36
                                      C:\WINDOWS\System32\$winnt$.inf -->19/08/2007 16:42:17
                                      C:\WINDOWS\System32\CONFIG.NT -->19/08/2007 16:39:36
                                      C:\WINDOWS\System32\nscompat.tlb -->19/08/2007 16:39:33
                                      C:\WINDOWS\System32\amcompat.tlb -->19/08/2007 16:39:33
                                      C:\WINDOWS\System32\WindowsLogon.manifest -->19/08/2007 16:38:27
                                      C:\WINDOWS\System32\logonui.exe.manifest -->19/08/2007 16:38:27
                                      C:\WINDOWS\System32\wuaucpl.cpl.manifest -->19/08/2007 16:38:22
                                      C:\WINDOWS\System32\sapi.cpl.manifest -->19/08/2007 16:38:22
                                      C:\WINDOWS\System32\nwc.cpl.manifest -->19/08/2007 16:38:22
                                      C:\WINDOWS\System32\ncpa.cpl.manifest -->19/08/2007 16:38:22

                                      C:\WINDOWS\0.log -->20/08/2007 21:06:00
                                      C:\WINDOWS\wiadebug.log -->20/08/2007 21:05:57
                                      C:\WINDOWS\wiaservc.log -->20/08/2007 21:05:56
                                      C:\WINDOWS\bootstat.dat -->20/08/2007 21:05:53
                                      C:\WINDOWS\SchedLgU.Txt -->20/08/2007 20:50:16
                                      C:\WINDOWS\Q810577.log -->20/08/2007 20:36:17
                                      C:\WINDOWS\WindowsUpdate.log -->20/08/2007 20:36:16
                                      C:\WINDOWS\setupapi.log -->20/08/2007 20:36:15
                                      C:\WINDOWS\xpsp1hfm.log -->20/08/2007 20:35:59
                                      C:\WINDOWS\tsoc.log -->20/08/2007 20:35:59
                                      C:\WINDOWS\tabletoc.log -->20/08/2007 20:35:59
                                      C:\WINDOWS\Q810833.log -->20/08/2007 20:35:59
                                      C:\WINDOWS\ocmsn.log -->20/08/2007 20:35:59
                                      C:\WINDOWS\ocgen.log -->20/08/2007 20:35:59
                                      C:\WINDOWS\ntdtcsetup.log -->20/08/2007 20:35:59

                                      Le volume dans le lecteur C n'a pas de nom.
                                      Le numéro de série du volume est A079-2A8F

                                      Répertoire de C:\WINDOWS\system32

                                      28/08/2001 14:00 4 096 csrss.exe
                                      1 fichier(s) 4 096 octets
                                      0 Rép(s) 7 286 730 752 octets libres

                                      Contenu de Downloaded Program Files
                                      Le volume dans le lecteur C n'a pas de nom.
                                      Le numéro de série du volume est A079-2A8F

                                      Répertoire de C:\WINDOWS\Downloaded Program Files

                                      19/08/2007 21:21 <REP> .
                                      19/08/2007 21:21 <REP> ..
                                      19/08/2007 16:38 65 desktop.ini
                                      11/06/2007 12:21 5 021 swflash.inf
                                      16/04/2007 22:50 293 wuweb.inf
                                      3 fichier(s) 5 379 octets

                                      Total des fichiers listés :
                                      3 fichier(s) 5 379 octets
                                      2 Rép(s) 7 286 730 752 octets libres

                                      Recherche de rootkit! (Merci S!Ri)

                                      Recherche d'infections connues

                                      Export des clefs sensibles..

                                      Liste des fichiers en exception sur le pare-feu XP SP2

                                      "C:\\WINDOWS\\System32\\dllcache\\mlqm.exe"="C:\\WINDOWS\\System32\\dllcache\\mlqm.exe:*:Enabled:Logitech QuickCam Manager"

                                      Export de la clef SharedTaskScheduler

                                      [SharedTaskScheduler]
                                      "{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Pré-chargeur Browseui"
                                      "{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Démon de cache des catégories de composant"

                                      Rechercher adresses sensibles dans le fichier HOSTS...

                                      catchme 0.3.1066 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                                      Rootkit scan 2007-08-20 21:11:35
                                      Windows 5.1.2600 Service Pack 1 NTFS

                                      scanning hidden services & system hive ...

                                      scanning hidden registry entries ...

                                      scanning hidden files ...

                                      scan completed successfully
                                      hidden files: 0

                                      KProcCheck Version 0.2-beta1 Proof-of-Concept by SIG^2 (www.security.org.sg)

                                      Process list by traversal of KiWaitListHead

                                      4 - System
                                      436 - csrss.exe
                                      620 - winlogon.exe
                                      664 - services.exe
                                      676 - lsass.exe
                                      852 - svchost.exe
                                      932 - svchost.exe
                                      1072 - svchost.exe
                                      1092 - svchost.exe
                                      1396 - explorer.exe
                                      1588 - mlqm.exe
                                      1812 - svchost.exe
                                      1868 - wms.exe
                                      2024 - ctfmon.exe
                                      9624 - winsony.exe
                                      14828 - cmd.exe

                                      Total number of processes = 16
                                      NOTE: Under WinXP, this will not show all processes.

                                      KProcCheck Version 0.2-beta1 Proof-of-Concept by SIG^2 (www.security.org.sg)

                                      Driver/Module list by traversal of PsLoadedModuleList

                                      804D4000 - \WINDOWS\system32\ntoskrnl.exe
                                      806C8000 - \WINDOWS\system32\hal.dll
                                      F9F32000 - \WINDOWS\system32\KDCOM.DLL
                                      F9E42000 - \WINDOWS\system32\BOOTVID.dll
                                      F99E5000 - ACPI.sys
                                      F9F34000 - \WINDOWS\System32\DRIVERS\WMILIB.SYS
                                      F9A32000 - pci.sys
                                      F9A42000 - isapnp.sys
                                      F9F36000 - viaide.sys
                                      F9CB2000 - \WINDOWS\System32\DRIVERS\PCIIDEX.SYS
                                      F9A52000 - MountMgr.sys
                                      F99C6000 - ftdisk.sys
                                      F9F38000 - dmload.sys
                                      F99A2000 - dmio.sys
                                      F9CBA000 - PartMgr.sys
                                      F9A62000 - VolSnap.sys
                                      F998C000 - atapi.sys
                                      F9A72000 - disk.sys
                                      F9A82000 - \WINDOWS\System32\DRIVERS\CLASSPNP.SYS
                                      F997B000 - sr.sys
                                      F9967000 - KSecDD.sys
                                      F98DD000 - Ntfs.sys
                                      F98B4000 - NDIS.sys
                                      F9CC2000 - viaagp.sys
                                      F989A000 - Mup.sys
                                      F9B02000 - \SystemRoot\System32\DRIVERS\processr.sys
                                      F94EF000 - \SystemRoot\System32\DRIVERS\nv4_mini.sys
                                      F94DD000 - \SystemRoot\System32\DRIVERS\VIDEOPRT.SYS
                                      F9B22000 - \SystemRoot\system32\drivers\es1371mp.sys
                                      F94BC000 - \SystemRoot\system32\drivers\portcls.sys
                                      F9B32000 - \SystemRoot\system32\drivers\drmk.sys
                                      F949B000 - \SystemRoot\system32\drivers\ks.sys
                                      F9B42000 - \SystemRoot\System32\Drivers\Imapi.SYS
                                      F9B52000 - \SystemRoot\System32\DRIVERS\cdrom.sys
                                      F9B62000 - \SystemRoot\System32\DRIVERS\redbook.sys
                                      F9CF2000 - \SystemRoot\System32\DRIVERS\usbuhci.sys
                                      F9479000 - \SystemRoot\System32\DRIVERS\USBPORT.SYS
                                      F9CFA000 - \SystemRoot\System32\DRIVERS\fdc.sys
                                      F9B72000 - \SystemRoot\System32\DRIVERS\serial.sys
                                      F9ED6000 - \SystemRoot\System32\DRIVERS\serenum.sys
                                      F9466000 - \SystemRoot\System32\DRIVERS\parport.sys
                                      F9B82000 - \SystemRoot\System32\DRIVERS\i8042prt.sys
                                      F9D02000 - \SystemRoot\System32\DRIVERS\mouclass.sys
                                      F9D0A000 - \SystemRoot\System32\DRIVERS\kbdclass.sys
                                      FA0DF000 - \SystemRoot\System32\DRIVERS\audstub.sys
                                      F9BF2000 - \SystemRoot\System32\DRIVERS\rasl2tp.sys
                                      F9EDA000 - \SystemRoot\System32\DRIVERS\ndistapi.sys
                                      F943F000 - \SystemRoot\System32\DRIVERS\ndiswan.sys
                                      F9C02000 - \SystemRoot\System32\DRIVERS\raspppoe.sys
                                      F9C12000 - \SystemRoot\System32\DRIVERS\raspptp.sys
                                      F9EDE000 - \SystemRoot\System32\DRIVERS\TDI.SYS
                                      F942E000 - \SystemRoot\System32\DRIVERS\psched.sys
                                      F9C22000 - \SystemRoot\System32\DRIVERS\msgpc.sys
                                      F9D22000 - \SystemRoot\System32\DRIVERS\ptilink.sys
                                      F9D2A000 - \SystemRoot\System32\DRIVERS\raspti.sys
                                      F93F0000 - \SystemRoot\System32\DRIVERS\rdpdr.sys
                                      F9C32000 - \SystemRoot\System32\DRIVERS\termdd.sys
                                      FA136000 - \SystemRoot\System32\DRIVERS\swenum.sys
                                      F9306000 - \SystemRoot\System32\DRIVERS\update.sys
                                      F9EFE000 - \SystemRoot\System32\DRIVERS\wfsys.sys
                                      F9C42000 - \SystemRoot\System32\Drivers\NDProxy.SYS
                                      F9F2A000 - \SystemRoot\System32\DRIVERS\gameenum.sys
                                      F9C82000 - \SystemRoot\System32\DRIVERS\usbhub.sys
                                      F9F6A000 - \SystemRoot\System32\DRIVERS\USBD.SYS
                                      F9D42000 - \SystemRoot\System32\DRIVERS\flpydisk.sys
                                      F9F76000 - \SystemRoot\System32\Drivers\Fs_Rec.SYS
                                      FA166000 - \SystemRoot\System32\Drivers\Null.SYS
                                      F9F78000 - \SystemRoot\System32\Drivers\Beep.SYS
                                      FA167000 - \SystemRoot\System32\Drivers\VIAPFD.SYS
                                      F9D52000 - \SystemRoot\System32\drivers\vga.sys
                                      F9F7A000 - \SystemRoot\System32\Drivers\mnmdd.SYS
                                      F9F7C000 - \SystemRoot\System32\DRIVERS\RDPCDD.sys
                                      F9D5A000 - \SystemRoot\System32\Drivers\Msfs.SYS
                                      F9D62000 - \SystemRoot\System32\Drivers\Npfs.SYS
                                      F986E000 - \SystemRoot\System32\DRIVERS\rasacd.sys
                                      F9CA2000 - \SystemRoot\System32\DRIVERS\ipsec.sys
                                      F814C000 - \SystemRoot\System32\DRIVERS\tcpip.sys
                                      F8125000 - \SystemRoot\System32\DRIVERS\netbt.sys
                                      F9AB2000 - \SystemRoot\System32\DRIVERS\netbios.sys
                                      F80FD000 - \SystemRoot\System32\DRIVERS\rdbss.sys
                                      F8099000 - \SystemRoot\System32\DRIVERS\mrxsmb.sys
                                      F9AC2000 - \SystemRoot\System32\Drivers\Fips.SYS
                                      F9AD2000 - \SystemRoot\System32\DRIVERS\wanarp.sys
                                      F9D7A000 - \SystemRoot\System32\DRIVERS\USBSTOR.SYS
                                      F9AE2000 - \SystemRoot\System32\DRIVERS\LVUSBSta.sys
                                      F803D000 - \SystemRoot\System32\DRIVERS\LV561AV.SYS
                                      F9AF2000 - \SystemRoot\System32\DRIVERS\STREAM.SYS
                                      F9B12000 - \SystemRoot\System32\Drivers\Cdfs.SYS
                                      F93E8000 - \SystemRoot\System32\DRIVERS\usb8023.sys
                                      F9D82000 - \SystemRoot\System32\DRIVERS\RNDISMP.SYS
                                      F7F87000 - \SystemRoot\System32\Drivers\dump_atapi.sys
                                      F9F82000 - \SystemRoot\System32\Drivers\dump_WMILIB.SYS
                                      BF800000 - \SystemRoot\System32\win32k.sys
                                      F93C8000 - \SystemRoot\System32\watchdog.sys
                                      F9302000 - \SystemRoot\System32\drivers\Dxapi.sys
                                      BFF80000 - \SystemRoot\System32\drivers\dxg.sys
                                      FA067000 - \SystemRoot\System32\drivers\dxgthk.sys
                                      BF9BB000 - \SystemRoot\System32\nv4_disp.dll
                                      F7006000 - \SystemRoot\System32\drivers\afd.sys
                                      F709B000 - \SystemRoot\System32\DRIVERS\ndisuio.sys
                                      F5DD3000 - \SystemRoot\System32\DRIVERS\mrxdav.sys
                                      F9FC0000 - \SystemRoot\System32\Drivers\ParVdm.SYS
                                      F5D34000 - \SystemRoot\System32\DRIVERS\srv.sys
                                      F5D10000 - \SystemRoot\System32\Drivers\Fastfat.SYS
                                      F5ACD000 - \SystemRoot\system32\drivers\wdmaud.sys
                                      F5C40000 - \SystemRoot\system32\drivers\sysaudio.sys
                                      FA149000 - \SystemRoot\System32\DRIVERS\KProcCheck.sys

                                      Total number of drivers = 107

                                      Liste des programmes installes

                                      Ad-Aware SE Personal
                                      Adobe Acrobat 4.0
                                      Adobe Flash Player 9 ActiveX
                                      Correctif Windows XP - KB823980
                                      Correctif Windows XP - KB835732
                                      Correctif Windows XP - KB842773
                                      Correctif Windows XP (SP2) Q329170
                                      Correctif Windows XP (SP2) Q329441
                                      Correctif Windows XP (SP2) Q810833
                                      Correctif Windows XP (SP2) Q815021
                                      Eudora
                                      K-Lite Codec Pack 3.3.0 Full
                                      Language pack for Ad-Aware SE
                                      NVIDIA Drivers
                                      Package du correctif Windows XP [voir Q329115 pour plus de détails]
                                      Package du correctif Windows XP [voir Q329390 pour plus de détails]
                                      Service Pack 1a pour Windows XP
                                      VideoLAN VLC media player 0.8.6b
                                      WebFldrs XP
                                      Winamp (remove only)
                                      Windows Genuine Advantage Validation Tool (KB892130)
                                      Windows Genuine Advantage Validation Tool (KB892130)
                                      Windows Live Messenger
                                      WinFast GeForce2 MX Display Driver
                                      WinFast GeForce256 Display Driver
                                      WinFast(R) Display Driver
                                      WinFast(R) Display Driver

                                      Le volume dans le lecteur C n'a pas de nom.
                                      Le numéro de série du volume est A079-2A8F

                                      Répertoire de C:\Program Files

                                      20/08/2007 17:37 <REP> .
                                      20/08/2007 17:37 <REP> ..
                                      19/08/2007 16:55 <REP> Adobe
                                      20/08/2007 17:37 <REP> Alwil Software
                                      19/08/2007 16:36 <REP> ComPlus Applications
                                      19/08/2007 16:58 <REP> directx
                                      19/08/2007 16:56 <REP> Fichiers communs
                                      19/08/2007 20:41 <REP> Internet Explorer
                                      19/08/2007 22:03 <REP> K-Lite Codec Pack
                                      19/08/2007 17:59 <REP> Lavasoft
                                      19/08/2007 20:57 <REP> Messenger
                                      19/08/2007 16:39 <REP> microsoft frontpage
                                      19/08/2007 20:41 <REP> Movie Maker
                                      19/08/2007 16:36 <REP> MSN
                                      19/08/2007 16:36 <REP> MSN Gaming Zone
                                      19/08/2007 21:23 <REP> MSN Messenger
                                      20/08/2007 18:01 <REP> NetMeeting
                                      19/08/2007 20:41 <REP> Outlook Express
                                      19/08/2007 21:27 <REP> Qualcomm
                                      19/08/2007 16:38 <REP> Services en ligne
                                      19/08/2007 21:08 <REP> VideoLAN
                                      20/08/2007 18:01 <REP> Winamp
                                      19/08/2007 20:41 <REP> Windows Media Player
                                      19/08/2007 16:36 <REP> Windows NT
                                      19/08/2007 16:39 <REP> xerox
                                      0 fichier(s) 0 octets
                                      25 Rép(s) 7 286 718 464 octets libres
                                      Le volume dans le lecteur C n'a pas de nom.
                                      Le numéro de série du volume est A079-2A8F

                                      Répertoire de C:\Program Files\fichiers communs

                                      19/08/2007 16:56 <REP> .
                                      19/08/2007 16:56 <REP> ..
                                      19/08/2007 16:55 <REP> Adobe
                                      19/08/2007 17:51 <REP> InstallShield
                                      19/08/2007 16:48 <REP> Microsoft Shared
                                      19/08/2007 16:37 <REP> MSSoap
                                      19/08/2007 17:29 <REP> ODBC
                                      19/08/2007 16:37 <REP> Services
                                      19/08/2007 17:29 <REP> SpeechEngines
                                      19/08/2007 20:41 <REP> System
                                      0 fichier(s) 0 octets
                                      10 Rép(s) 7 286 718 464 octets libres
                                      Le volume dans le lecteur C n'a pas de nom.
                                      Le numéro de série du volume est A079-2A8F

                                      Répertoire de C:\Program Files\fichiers communs\Microsoft Shared\Web Folders

                                      19/08/2007 16:48 <REP> .
                                      19/08/2007 16:48 <REP> ..
                                      18/05/2001 17:57 561 209 MSONSEXT.DLL
                                      03/06/1999 14:09 122 937 MSOWS409.DLL
                                      07/03/2001 09:00 127 033 MSOWS40c.DLL
                                      3 fichier(s) 811 179 octets
                                      2 Rép(s) 7 286 718 464 octets libres
                                      Le volume dans le lecteur C n'a pas de nom.
                                      Le numéro de série du volume est A079-2A8F

                                      Répertoire de C:\

                                      12/05/2007 18:22 68 096 diff.exe
                                      12/05/2007 18:22 103 424 grep.exe
                                      20/08/2007 21:09 491 520 winsony.exe
                                      3 fichier(s) 663 040 octets
                                      0 Rép(s) 7 286 718 464 octets libres
                                      c:\Documents and Settings\Antoine\Bureau\ComboFix.exe
                                      c:\Documents and Settings\Antoine\Bureau\D22174F.exe
                                      c:\Documents and Settings\Antoine\Bureau\klcodec330f.exe
                                      c:\Documents and Settings\Antoine\Bureau\SDFix.exe
                                      c:\Documents and Settings\Antoine\Bureau\stinger.exe
                                      c:\Documents and Settings\Antoine\Bureau\WindowsXP-KB822603-x86-FRA.exe
                                      c:\Documents and Settings\Antoine\Bureau\WindowsXP-KB835935-SP2-FRA.exe
                                      c:\Documents and Settings\Antoine\Bureau\xpsp1a_fr_x86.exe
                                      c:\Documents and Settings\Antoine\Bureau\DiagHelp\DiagHelp\catchme.exe
                                      c:\Documents and Settings\Antoine\Bureau\DiagHelp\DiagHelp\diff.exe
                                      c:\Documents and Settings\Antoine\Bureau\DiagHelp\DiagHelp\dumphive.exe
                                      c:\Documents and Settings\Antoine\Bureau\DiagHelp\DiagHelp\FilesInfoCmd.exe
                                      c:\Documents and Settings\Antoine\Bureau\DiagHelp\DiagHelp\find2.exe
                                      c:\Documents and Settings\Antoine\Bureau\DiagHelp\DiagHelp\Fport.exe
                                      c:\Documents and Settings\Antoine\Bureau\DiagHelp\DiagHelp\grep.exe
                                      c:\Documents and Settings\Antoine\Bureau\DiagHelp\DiagHelp\KProcCheck.exe
                                      c:\Documents and Settings\Antoine\Bureau\DiagHelp\DiagHelp\LFiles.exe
                                      c:\Documents and Settings\Antoine\Bureau\DiagHelp\DiagHelp\LISTDLLS.exe
                                      c:\Documents and Settings\Antoine\Bureau\DiagHelp\DiagHelp\pslist.exe
                                      c:\Documents and Settings\Antoine\Bureau\DiagHelp\DiagHelp\streams.exe
                                      c:\Documents and Settings\Antoine\Bureau\DiagHelp\DiagHelp\swreg.exe
                                      c:\Documents and Settings\Antoine\Bureau\SREng2\SREngPS.EXE
                                      c:\Documents and Settings\Antoine\Local Settings\Temporary Internet Files\Content.IE5\G52FST2R\4EC48EA[1].exe
                                      c:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\0DE3WLI3\cv_3.0[1].exe
                                      c:\Documents and Settings\All Users\Application Data\Microsoft\IdentityCRL\production\ppcrlconfig.dll

                                      ****** Fin du rapport DiagHelp
                                      1. Contributeur sécurité
                                        Re,

                                        Je pense que c'est du lourd.

                                        J'examine ces rapports. Je voudrais aussi vérifer quelquechose.

                                        Pourrais-tu faire ceci en attendant :
                                        1/ Télécharge fix gromozon : http://info.prevx.com/gromozon.asp
                                        Exécute-le et édite le rapport généré.

                                        2/ * Télécharge SREng (de Smallfrogs) : http://www.kztechs.com/eng/download.html
                                        * Dézippe tout son contenu sur ton bureau (clic droit >Extraire ici).
                                        * Ouvre le dossier SReng2 et double-clique sur SREng.exe.
                                        * Clique sur "smart scan".
                                        * Clique sur le bouton "scan".
                                        * Quand l'analyse est terminée, clique sur le bouton "save reports".
                                        * Sauvegarde alors le rapport sur ton bureau.
                                        * Copie/colle le contenu du rapport SREnglLOG.log dans ta prochaine réponse.

                                        3/ * Télécharge DiagHelp.zip sur ton bureau(Merci Malekal) :
                                        http://www.malekal.com/download/DiagHelp.zip
                                        Tuto : http://www.malekal.com/DiagHelp/DiagHelp.php
                                        * Ne double-clique pas dessus !! Fais un clic droit sur le fichier et extraire tout.
                                        * Un nouveau dossier chercher va être créé.
                                        * Ouvre le et double-clic sur go.cmd (le .cmd peut ne pas apparaître)
                                        * Une fenêtre va s'ouvrir, choisis l'option 1
                                        * L'analyse va commencer, ceci peut durer quelques minutes, laisse faire et appuie sur une touche quand on te le demande.
                                        * A la fin de l'analyse, le programme de dmeande de redémarrer ton PC. Fais-le.
                                        * Une fenêtre avec le rapport s'ouvre alors. Copie/colle son contenu. (Il se trouve aussi ici : c:\resultat.txt)
                                        * Double-clique sur ce fichier, Fais CTRL+A puis CTRL+C.
                                        * Dans ta prochaine réponse, colle le rapport en faisant CTRL+V.

                                        FillPCA
                                        • 1
                                        • 2