Mon ordi bug

bonjour

je me vois dans l'obligation de recoller mon rapport HijackThis, vu que l'on a pensé que mon appel à l'aide était en double et qu'on l'a suppprimé. je suis désolé mais je n'ai pas réussi à modifier mon premier message pour l'y ajouté.
voila mon ordi bug et un scan internet chez bitDefender a trouvé des fichiers infecté
merci de votre aide

Logfile of HijackThis v1.99.1
Scan saved at 13:48:11, on 02/09/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\keyhook.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\WINDOWS\system32\Rundll32.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\PROGRA~1\SUPERC~1\SUPERC~1.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Fichiers communs\Logitech\KHAL\KHALMNPR.EXE
C:\Program Files\MSN Messenger\usnsvc.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\MSN Messenger\livecall.exe
C:\Program Files\Hijackthis Version Française\VERSION TRADUITE ORIGINALE.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.free.fr/freebox/index.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: e-Carte Bleue Browser Helper Object - {2E03C0FD-4C48-43A7-9A54-00240C70FF16} - C:\WINDOWS\system32\BhoECart.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\system32\keyhook.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [SUPERC~1.EXE] C:\PROGRA~1\SUPERC~1\SUPERC~1.EXE
O4 - HKCU\..\Run: [fsc-reminder.exe] C:\WINDOWS\reminder\fsc-reminder.exe 2453603 14
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe (file missing)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: OdysseyClient - C:\WINDOWS\
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Norman ZANDA - Unknown owner - C:\Norman\NVC\BIN\Zanda.exe (file missing)
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
Configuration: Windows XP
Internet Explorer 6.0

31 réponses

Résumé de la discussion

Le fil relate un ordinateur sous Windows XP qui ralenti considérablement et où une infection est soupçonnée après un scan BitDefender et un relevé HijackThis présentant de nombreuses entrées suspectes. Plusieurs éléments de réponse évoquent des symptômes de lenteur intermittente, des profils d'exécution et de menu démarrage chargés, et des rapports d'un HijackThis qui liste des BHO, des entrées O9/O18 et des services suspects. D'autres messages rapportent des scans complémentaires (Ad-Aware 2007 et restauration système) et remarquent des objets répertoriés ou des fichiers manquants, sans apporter de solution claire ni suppression effective. Des indices pointent vers une infection complexe nécessitant une coordination entre outils et procédures, ce qui peut impliquer une réinstallation du système ou une restauration avancée.

Bobot (l’IA à votre service)
  1. salut

    comment faire pour effacer ce message qui commence à dater sérieusement???
    1. salut, oui c'est fait pour le post "26"
      comment ça je n'ai pas de pare feu?? j'ai le parefeu windows par défaut, explique toi stp

      sinon , je me suis rendu compte d'autres symptômes, je dois à chaque fois refaire : affichage,... dans mes dossiers, parce qu' à chaque fois l'ordi ne garde pas la config que je lui demande, sinon j'ai les icones du bureau qui partent et reviennent et des fois ne reviennent pas
      louche, non???

      crois-tu que mon problèmes est résolus???
      en tout cas merci pour ton aide, mon ordi marche très bien pour le moment
      a bientôt sur la toile...
      1. re yao,

        le post "26" s'est 3 messages plus haut "salut yao, merci pour la lecture :coche ceci avec hijack this :O20 - Winlogon Notify: OdysseyClient - C:\WINDOWS\quitte tes application et navigateur et fix la ligne ci dessus, redémarre le pc et dis moi comment ça va

        tu n´as pas de par feu, alors pour eviter que tes problemes ne recommence :

        tu peux télécharger :

        kerio ou zone alarm :

        https://kerio.probb.fr/

        (merci a boulepate pour le site!!!)

        sur cette page tu as le choix entre kerio et zone alarm, zone alarm est plus facile a configurer que kerio mais un peu moins performant, a toi de voir...

        tutorials :

        zone alarm :

        http://forum.telecharger.01net.com/forum/

        kerio 4.2.

        https://kerio.probb.fr/

        kerio autre version 4.5.

        https://kerio.probb.fr/

        puis tu peux installer ca aussi :

        http://www.brightfort.com/spywareblaster.html

        c´est un resident, il suffit de le mettre a jour de temps en temps car la version gratuite ne le fait pas toute seul , une fois installé et mis a jour tu mets toutes les protections sur "enable"

        a+ et bon surf
        1. re

          fixation, extinction, redémmarage. c'est fait
          et oui, ça va bien

          c'est quoi le post "26", comprends pas
          1. je ne suis pas un expert, mais les scan ne doivent pas être très concluant, si tu me demande de téléchargé des logiciels à chaque fois
            j'ai été infecté par le virus deamon tool, il n'y a pas si longtemps et je crois qu'il reste des résidus dans l'ordi, ne pense tu pas que ça pourrait être la cause de tous mes soucis??
            c'est une piste, pour t'aider, je ne suis pas un érudit d'informatique, mais en général, j'arrive à me débrouiller seul quand j'ai des problèmes.
            fait moi par de tes découvertes...
            stp a+
            1. salut yao, merci pour la lecture :

              coche ceci avec hijack this :

              O20 - Winlogon Notify: OdysseyClient - C:\WINDOWS\

              quitte tes application et navigateur et fix la ligne ci dessus

              redémarre le pc et dis moi comment ça va

              a+
              1. et voici le petit dernier, c'est à n'y rien comprendre.....

                Logfile of HijackThis v1.99.1
                Scan saved at 12:07:54, on 03/09/2007
                Platform: Windows XP SP2 (WinNT 5.01.2600)
                MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

                Running processes:
                C:\WINDOWS\System32\smss.exe
                C:\WINDOWS\system32\csrss.exe
                C:\WINDOWS\system32\winlogon.exe
                C:\WINDOWS\system32\services.exe
                C:\WINDOWS\system32\lsass.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\System32\svchost.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\system32\svchost.exe
                C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                C:\Program Files\Alwil Software\Avast4\ashServ.exe
                C:\WINDOWS\system32\spoolsv.exe
                C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\system32\cisvc.exe
                C:\WINDOWS\system32\slserv.exe
                C:\WINDOWS\Explorer.EXE
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\system32\keyhook.exe
                C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
                C:\WINDOWS\system32\Rundll32.exe
                C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                C:\WINDOWS\system32\rundll32.exe
                C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
                C:\WINDOWS\system32\ctfmon.exe
                C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                C:\WINDOWS\System32\alg.exe
                C:\Program Files\MSN Messenger\msnmsgr.exe
                C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                C:\Program Files\Messenger\msmsgs.exe
                C:\Program Files\Logitech\SetPoint\SetPoint.exe
                C:\Program Files\Fichiers communs\Logitech\KHAL\KHALMNPR.EXE
                C:\WINDOWS\system32\cidaemon.exe
                C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                C:\Program Files\Internet Explorer\IEXPLORE.EXE
                C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
                C:\Program Files\SuperCopier2\SuperCopier2.exe
                C:\WINDOWS\system32\fxssvc.exe
                C:\Program Files\Hijackthis Version Française\VERSION TRADUITE ORIGINALE.EXE

                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = mon ordi bug
                R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/
                R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                O2 - BHO: e-Carte Bleue Browser Helper Object - {2E03C0FD-4C48-43A7-9A54-00240C70FF16} - C:\WINDOWS\system32\BhoECart.dll
                O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
                O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\system32\keyhook.exe
                O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
                O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
                O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
                O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
                O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
                O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
                O4 - HKLM\..\Run: [AAWTray] C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe
                O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
                O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
                O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
                O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
                O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
                O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
                O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
                O20 - Winlogon Notify: OdysseyClient - C:\WINDOWS\
                O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
                O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
                O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
                O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
                O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                O23 - Service: Norman ZANDA - Unknown owner - C:\Norman\NVC\BIN\Zanda.exe (file missing)
                O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
                1. et voici le 2nd, bonne lecture...

                  # PCA Sécurité V 1.0.2, (fichier LOG).
                  # Rapport du :03/09/2007 11:57:26
                  Microsoft Windows XP Service Pack 2

                  ==>> Processus <==
                  \SystemRoot\System32\smss.exe
                  \??\C:\WINDOWS\system32\csrss.exe
                  \??\C:\WINDOWS\system32\winlogon.exe
                  C:\WINDOWS\system32\services.exe
                  C:\WINDOWS\system32\lsass.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                  C:\Program Files\Alwil Software\Avast4\ashServ.exe
                  C:\WINDOWS\system32\spoolsv.exe
                  C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\system32\cisvc.exe
                  C:\WINDOWS\system32\slserv.exe
                  C:\WINDOWS\Explorer.EXE
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\system32\keyhook.exe
                  C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                  C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
                  C:\WINDOWS\system32\Rundll32.exe
                  C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                  C:\WINDOWS\system32\rundll32.exe
                  C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
                  C:\WINDOWS\system32\ctfmon.exe
                  C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                  C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                  C:\WINDOWS\System32\alg.exe
                  C:\Program Files\MSN Messenger\msnmsgr.exe
                  C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                  C:\Program Files\Messenger\msmsgs.exe
                  C:\Program Files\Logitech\SetPoint\SetPoint.exe
                  C:\Program Files\Fichiers communs\Logitech\KHAL\KHALMNPR.EXE
                  C:\WINDOWS\system32\cidaemon.exe
                  C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                  C:\Program Files\Internet Explorer\IEXPLORE.EXE
                  C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
                  C:\Program Files\SuperCopier2\SuperCopier2.exe
                  C:\Program Files\Windows Media Player\wmplayer.exe
                  C:\DOCUME~1\NYUIAD~1\LOCALS~1\Temp\Répertoire temporaire 1 pour pca[1].zip\pca.exe

                  //pages de démarrage et de recherche d'Internet Explorer
                  RO - HKLM\Software\Microsoft\Internet Explorer\Main\Start Page = https://fr.yahoo.com/
                  RO - HKLM\Software\Microsoft\Internet Explorer\Main\Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
                  RO - HKCU\Software\Microsoft\Internet Explorer\Main\Start Page = mon ordi bug
                  RO - HKCU\Software\Microsoft\Internet Explorer\Toolbar\LinksFolderName = Liens
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main\Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main\Default_Search_URL = http://www.google.com/toolbar/ie8/sidebar.html
                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main\Search Page = https://www.google.com/?gws_rd=ssl
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Search\CustomizeSearch = https://www.bing.com/?toHttps=1&redig=8F3F334EA60E4B1CB4D040DCFE393A89{SUB_RFC1766}/srchasst/srchcust.htm
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Search\SearchAssistant = http://www.google.com/toolbar/ie8/sidebar.html
                  R1 - HKCU\Software\Microsoft\Internet Explorer\Search\SearchAssistant = http://www.google.com/toolbar/ie8/sidebar.html
                  //applications lancées depuis system.ini,win.ini
                  //03 - Browser Helper Objects (BHOs)
                  02 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                  02 - BHO: ECarteBleueBrowserHelper Class - {2E03C0FD-4C48-43A7-9A54-00240C70FF16} - C:\WINDOWS\system32\BhoECart.dll
                  02 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                  02 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                  02 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
                  O3 - Toolbar : &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                  //04 - applications chargées automatiquement
                  04 - HKLM\..\RUN: [SiS Windows KeyHook] - C:\WINDOWS\system32\keyhook.exe
                  04 - HKLM\..\RUN: [NeroFilterCheck] - C:\WINDOWS\system32\NeroCheck.exe
                  04 - HKLM\..\RUN: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                  04 - HKLM\..\RUN: [SynTPLpr] - C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
                  04 - HKLM\..\RUN: [SiSPower] - Rundll32.exe SiSPower.dll,ModeAgent
                  04 - HKLM\..\RUN: [avast!] - C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                  04 - HKLM\..\RUN: [BluetoothAuthenticationAgent] - rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
                  04 - HKLM\..\RUN: [Logitech Hardware Abstraction Layer] - KHALMNPR.EXE
                  04 - HKLM\..\RUN: [!AVG Anti-Spyware] - "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
                  04 - HKLM\..\RUN: [AAWTray] - C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe
                  04 - HKLU\..\RUN: [CTFMON.EXE] - C:\WINDOWS\system32\ctfmon.exe
                  04 - HKLU\..\RUN: [msnmsgr] - "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
                  04 - HKLU\..\RUN: [swg] - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                  04 - HKLU\..\RUN: [MSMSGS] - "C:\Program Files\Messenger\msmsgs.exe" /background
                  04 - HKLM\..\RunServices: [CTFMON.EXE] - C:\WINDOWS\system32\ctfmon.exe
                  04 - HKLM\..\RunServices: [msnmsgr] - "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
                  04 - HKLM\..\RunServices: [swg] - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                  04 - HKLM\..\RunServices: [MSMSGS] - "C:\Program Files\Messenger\msmsgs.exe" /background
                  04 - HKLU\..\RunServices: [CTFMON.EXE] - C:\WINDOWS\system32\ctfmon.exe
                  04 - HKLU\..\RunServices: [msnmsgr] - "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
                  04 - HKLU\..\RunServices: [swg] - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                  04 - HKLU\..\RunServices: [MSMSGS] - "C:\Program Files\Messenger\msmsgs.exe" /background
                  04 - HKUS\S-1-5-18\..\RUN: [CTFMON.EXE] - C:\WINDOWS\system32\keyhook.exe
                  04 - HKUS\S-1-5-18\..\RUN: [MySpaceIM] - C:\WINDOWS\system32\NeroCheck.exe
                  04 - HKUS\S-1-5-19\..\RUN: [CTFMON.EXE] - C:\WINDOWS\system32\keyhook.exe
                  04 - HKUS\S-1-5-20\..\RUN: [CTFMON.EXE] - C:\WINDOWS\system32\keyhook.exe
                  04 - HKUS\S-1-5-21-1890995607-336724566-898250518-1006\..\RUN: [CTFMON.EXE] - C:\WINDOWS\system32\keyhook.exe
                  04 - HKUS\S-1-5-21-1890995607-336724566-898250518-1006\..\RUN: [msnmsgr] - C:\WINDOWS\system32\NeroCheck.exe
                  04 - HKUS\S-1-5-21-1890995607-336724566-898250518-1006\..\RUN: [swg] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                  04 - HKUS\S-1-5-21-1890995607-336724566-898250518-1006\..\RUN: [MSMSGS] - C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
                  04 - Global Startup: Logitech SetPoint.lnk= C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Logitech SetPoint.lnk
                  //05 - Accès au panneau de contrôle d'Internet Explorer (control.ini)
                  //06- interdiction à l' accès au options (Internet Explorer)
                  //07 - blocage de l'exécution de Regedit
                  //08 - lignes supplémentaires dans le menu contextuel d'Internet Explorer
                  08 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
                  //09 - boutons situés sur la barre d'outils principale d'Internet Explorer
                  09 - Extra button: - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe
                  09 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe
                  09 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  09 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  //O10 - Pirates de Winsock
                  O10 - fichier inconnu - winsock lsp : Espace de noms Bluetooth - %SystemRoot%\system32\wshbth.dll
                  //O11 - Onglet supplémentaire dans les options avancées d'Internet Explorer)
                  //O12 - IE plugins
                  //013 : DefaultPrefix
                  //014 - Option : (Rétablir les paramètres Web)
                  //015 - Zone de confiance d'Internet Explorer
                  //O16 - Objets ActiveX
                  O16 - DPF : CKAVWebScan Object - {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} - C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavwebscan.dll
                  O16 - DPF : BDSCANONLINE Control - {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - C:\WINDOWS\DOWNLO~1\oscan8.ocx
                  O16 - DPF : Shockwave Flash Object - {D27CDB6E-AE6D-11CF-96B8-444553540000} - C:\WINDOWS\system32\Macromed\Flash\Flash9d.ocx
                  //O17 - piratage de domaine Lop.com
                  //O18 - protocoles additionnels
                  O18 - Protocol: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Program Files\Fichiers communs\Microsoft Shared\Web Folders\PKMCDO.DLL
                  O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
                  O18 - Protocol: mhtml - {05300401-BCBC-11d0-85E3-00C04FD85AB4} -
                  O18 - Protocol: ms-its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll
                  O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
                  O18 - Protocol: mso-offdap - {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\PROGRA~1\FICHIE~1\MICROS~1\WEBCOM~1\10\OWC10.DLL
                  //O19 - feuille de style de l'utilisateur
                  //O20 - valeur de Registre AppInit_DLLs et les sous-clés Winlogon Notify
                  //O21 - ShellServiceObjectDelayLoad
                  O21 - SSODL: Objet PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} -
                  O21 - SSODL: Dossier du Bureau pour l'écriture de CD - {fbeb8a05-beee-4442-804e-409d6c4515e9} -
                  O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} -
                  O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - C:\WINDOWS\system32\stobject.dll
                  O21 - SSODL: WPDShServiceObj Class - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
                  //O22 - SharedTaskScheduler
                  O22 - SharedTaskScheduler: Pré-chargeur Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - %SystemRoot%\system32\browseui.dll
                  O22 - SharedTaskScheduler: Démon de cache des catégories de composant - {8C7461EF-2B13-11d2-BE35-3078302C2030} - %SystemRoot%\system32\browseui.dll
                  //O23 - services de XP,NT, 2000, et 2003
                  O23 - Service: [Ad-Aware 2007 Service] - "C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe"
                  O23 - Service: [Service de la passerelle de la couche Application] - %SystemRoot%\System32\alg.exe
                  O23 - Service: [ASP.NET State Service] - %SystemRoot%\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe
                  O23 - Service: [avast! iAVS4 Control Service] - "C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe"
                  O23 - Service: [avast! Antivirus] - "C:\Program Files\Alwil Software\Avast4\ashServ.exe"
                  O23 - Service: [avast! Mail Scanner] - "C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service
                  O23 - Service: [avast! Web Scanner] - "C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service
                  O23 - Service: [AVG Anti-Spyware Guard] - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                  O23 - Service: [Gestionnaire de l'Album] - %SystemRoot%\system32\clipsrv.exe
                  O23 - Service: [Application système COM+] - C:\WINDOWS\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}
                  O23 - Service: [Fax] - %systemroot%\system32\fxssvc.exe
                  O23 - Service: [Google Updater Service] - "C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe"
                  O23 - Service: [Service COM de gravage de CD IMAPI] -
                  O23 - Service: [Partage de Bureau à distance NetMeeting] - C:\WINDOWS\system32\mnmsrvc.exe
                  O23 - Service: [Distributed Transaction Coordinator] - C:\WINDOWS\system32\msdtc.exe
                  O23 - Service: [Norman ZANDA] - C:\Norman\NVC\BIN\Zanda.exe
                  O23 - Service: [Gestionnaire de session d'aide sur le Bureau à distance] - C:\WINDOWS\system32\sessmgr.exe
                  O23 - Service: [Localisateur d'appels de procédure distante (RPC)] - %SystemRoot%\system32\locator.exe
                  O23 - Service: [QoS RSVP] - %SystemRoot%\system32\rsvp.exe
                  O23 - Service: [SmartLinkService] - slserv.exe
                  O23 - Service: [Spouleur d'impression] - %SystemRoot%\system32\spoolsv.exe
                  O23 - Service: [MS Software Shadow Copy Provider] - C:\WINDOWS\system32\dllhost.exe /Processid:{15F5A9F3-6A33-4ED8-BDC6-A67D4196A359}
                  O23 - Service: [Journaux et alertes de performance] - %SystemRoot%\system32\smlogsvc.exe
                  O23 - Service: [Onduleur] - %SystemRoot%\System32\ups.exe
                  O23 - Service: [Service Messenger Sharing Folders USN Journal Reader] - "C:\Program Files\MSN Messenger\usnsvc.exe"
                  O23 - Service: [Cliché instantané de volume] - %SystemRoot%\System32\vssvc.exe
                  O23 - Service: [Carte de performance WMI] - C:\WINDOWS\system32\wbem\wmiapsrv.exe
                  O23 - Service: [Service Partage réseau du Lecteur Windows Media] - "C:\Program Files\Windows Media Player\WMPNetwk.exe"
                  1. voici le premier rapport:

                    # PCA Sécurité V 1.0.2, (fichier LOG).
                    # Rapport du :03/09/2007 11:57:26
                    Microsoft Windows XP Service Pack 2

                    ==>> Processus <==
                    \SystemRoot\System32\smss.exe
                    \??\C:\WINDOWS\system32\csrss.exe
                    \??\C:\WINDOWS\system32\winlogon.exe
                    C:\WINDOWS\system32\services.exe
                    C:\WINDOWS\system32\lsass.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                    C:\Program Files\Alwil Software\Avast4\ashServ.exe
                    C:\WINDOWS\system32\spoolsv.exe
                    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\system32\cisvc.exe
                    C:\WINDOWS\system32\slserv.exe
                    C:\WINDOWS\Explorer.EXE
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\system32\keyhook.exe
                    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                    C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
                    C:\WINDOWS\system32\Rundll32.exe
                    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                    C:\WINDOWS\system32\rundll32.exe
                    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
                    C:\WINDOWS\system32\ctfmon.exe
                    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                    C:\WINDOWS\System32\alg.exe
                    C:\Program Files\MSN Messenger\msnmsgr.exe
                    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                    C:\Program Files\Messenger\msmsgs.exe
                    C:\Program Files\Logitech\SetPoint\SetPoint.exe
                    C:\Program Files\Fichiers communs\Logitech\KHAL\KHALMNPR.EXE
                    C:\WINDOWS\system32\cidaemon.exe
                    C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                    C:\Program Files\Internet Explorer\IEXPLORE.EXE
                    C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
                    C:\Program Files\SuperCopier2\SuperCopier2.exe
                    C:\Program Files\Windows Media Player\wmplayer.exe
                    C:\DOCUME~1\NYUIAD~1\LOCALS~1\Temp\Répertoire temporaire 1 pour pca[1].zip\pca.exe

                    //pages de démarrage et de recherche d'Internet Explorer
                    RO - HKLM\Software\Microsoft\Internet Explorer\Main\Start Page = https://fr.yahoo.com/
                    RO - HKLM\Software\Microsoft\Internet Explorer\Main\Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
                    RO - HKCU\Software\Microsoft\Internet Explorer\Main\Start Page = mon ordi bug
                    RO - HKCU\Software\Microsoft\Internet Explorer\Toolbar\LinksFolderName = Liens
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main\Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main\Default_Search_URL = http://www.google.com/toolbar/ie8/sidebar.html
                    R1 - HKCU\Software\Microsoft\Internet Explorer\Main\Search Page = https://www.google.com/?gws_rd=ssl
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Search\CustomizeSearch = https://www.bing.com/?toHttps=1&redig=8F3F334EA60E4B1CB4D040DCFE393A89{SUB_RFC1766}/srchasst/srchcust.htm
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Search\SearchAssistant = http://www.google.com/toolbar/ie8/sidebar.html
                    R1 - HKCU\Software\Microsoft\Internet Explorer\Search\SearchAssistant = http://www.google.com/toolbar/ie8/sidebar.html
                    //applications lancées depuis system.ini,win.ini
                    //03 - Browser Helper Objects (BHOs)
                    02 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                    02 - BHO: ECarteBleueBrowserHelper Class - {2E03C0FD-4C48-43A7-9A54-00240C70FF16} - C:\WINDOWS\system32\BhoECart.dll
                    02 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                    02 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                    02 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
                    O3 - Toolbar : &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                    //04 - applications chargées automatiquement
                    04 - HKLM\..\RUN: [SiS Windows KeyHook] - C:\WINDOWS\system32\keyhook.exe
                    04 - HKLM\..\RUN: [NeroFilterCheck] - C:\WINDOWS\system32\NeroCheck.exe
                    04 - HKLM\..\RUN: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                    04 - HKLM\..\RUN: [SynTPLpr] - C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
                    04 - HKLM\..\RUN: [SiSPower] - Rundll32.exe SiSPower.dll,ModeAgent
                    04 - HKLM\..\RUN: [avast!] - C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                    04 - HKLM\..\RUN: [BluetoothAuthenticationAgent] - rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
                    04 - HKLM\..\RUN: [Logitech Hardware Abstraction Layer] - KHALMNPR.EXE
                    04 - HKLM\..\RUN: [!AVG Anti-Spyware] - "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
                    04 - HKLM\..\RUN: [AAWTray] - C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe
                    04 - HKLU\..\RUN: [CTFMON.EXE] - C:\WINDOWS\system32\ctfmon.exe
                    04 - HKLU\..\RUN: [msnmsgr] - "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
                    04 - HKLU\..\RUN: [swg] - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                    04 - HKLU\..\RUN: [MSMSGS] - "C:\Program Files\Messenger\msmsgs.exe" /background
                    04 - HKLM\..\RunServices: [CTFMON.EXE] - C:\WINDOWS\system32\ctfmon.exe
                    04 - HKLM\..\RunServices: [msnmsgr] - "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
                    04 - HKLM\..\RunServices: [swg] - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                    04 - HKLM\..\RunServices: [MSMSGS] - "C:\Program Files\Messenger\msmsgs.exe" /background
                    04 - HKLU\..\RunServices: [CTFMON.EXE] - C:\WINDOWS\system32\ctfmon.exe
                    04 - HKLU\..\RunServices: [msnmsgr] - "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
                    04 - HKLU\..\RunServices: [swg] - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                    04 - HKLU\..\RunServices: [MSMSGS] - "C:\Program Files\Messenger\msmsgs.exe" /background
                    04 - HKUS\S-1-5-18\..\RUN: [CTFMON.EXE] - C:\WINDOWS\system32\keyhook.exe
                    04 - HKUS\S-1-5-18\..\RUN: [MySpaceIM] - C:\WINDOWS\system32\NeroCheck.exe
                    04 - HKUS\S-1-5-19\..\RUN: [CTFMON.EXE] - C:\WINDOWS\system32\keyhook.exe
                    04 - HKUS\S-1-5-20\..\RUN: [CTFMON.EXE] - C:\WINDOWS\system32\keyhook.exe
                    04 - HKUS\S-1-5-21-1890995607-336724566-898250518-1006\..\RUN: [CTFMON.EXE] - C:\WINDOWS\system32\keyhook.exe
                    04 - HKUS\S-1-5-21-1890995607-336724566-898250518-1006\..\RUN: [msnmsgr] - C:\WINDOWS\system32\NeroCheck.exe
                    04 - HKUS\S-1-5-21-1890995607-336724566-898250518-1006\..\RUN: [swg] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                    04 - HKUS\S-1-5-21-1890995607-336724566-898250518-1006\..\RUN: [MSMSGS] - C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
                    04 - Global Startup: Logitech SetPoint.lnk= C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Logitech SetPoint.lnk
                    //05 - Accès au panneau de contrôle d'Internet Explorer (control.ini)
                    //06- interdiction à l' accès au options (Internet Explorer)
                    //07 - blocage de l'exécution de Regedit
                    //08 - lignes supplémentaires dans le menu contextuel d'Internet Explorer
                    08 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
                    //09 - boutons situés sur la barre d'outils principale d'Internet Explorer
                    09 - Extra button: - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe
                    09 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe
                    09 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                    09 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                    //O10 - Pirates de Winsock
                    O10 - fichier inconnu - winsock lsp : Espace de noms Bluetooth - %SystemRoot%\system32\wshbth.dll
                    //O11 - Onglet supplémentaire dans les options avancées d'Internet Explorer)
                    //O12 - IE plugins
                    //013 : DefaultPrefix
                    //014 - Option : (Rétablir les paramètres Web)
                    //015 - Zone de confiance d'Internet Explorer
                    //O16 - Objets ActiveX
                    O16 - DPF : CKAVWebScan Object - {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} - C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavwebscan.dll
                    O16 - DPF : BDSCANONLINE Control - {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - C:\WINDOWS\DOWNLO~1\oscan8.ocx
                    O16 - DPF : Shockwave Flash Object - {D27CDB6E-AE6D-11CF-96B8-444553540000} - C:\WINDOWS\system32\Macromed\Flash\Flash9d.ocx
                    //O17 - piratage de domaine Lop.com
                    //O18 - protocoles additionnels
                    O18 - Protocol: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Program Files\Fichiers communs\Microsoft Shared\Web Folders\PKMCDO.DLL
                    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
                    O18 - Protocol: mhtml - {05300401-BCBC-11d0-85E3-00C04FD85AB4} -
                    O18 - Protocol: ms-its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll
                    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
                    O18 - Protocol: mso-offdap - {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\PROGRA~1\FICHIE~1\MICROS~1\WEBCOM~1\10\OWC10.DLL
                    //O19 - feuille de style de l'utilisateur
                    //O20 - valeur de Registre AppInit_DLLs et les sous-clés Winlogon Notify
                    //O21 - ShellServiceObjectDelayLoad
                    O21 - SSODL: Objet PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} -
                    O21 - SSODL: Dossier du Bureau pour l'écriture de CD - {fbeb8a05-beee-4442-804e-409d6c4515e9} -
                    O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} -
                    O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - C:\WINDOWS\system32\stobject.dll
                    O21 - SSODL: WPDShServiceObj Class - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
                    //O22 - SharedTaskScheduler
                    O22 - SharedTaskScheduler: Pré-chargeur Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - %SystemRoot%\system32\browseui.dll
                    O22 - SharedTaskScheduler: Démon de cache des catégories de composant - {8C7461EF-2B13-11d2-BE35-3078302C2030} - %SystemRoot%\system32\browseui.dll
                    //O23 - services de XP,NT, 2000, et 2003
                    O23 - Service: [Ad-Aware 2007 Service] - "C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe"
                    O23 - Service: [Service de la passerelle de la couche Application] - %SystemRoot%\System32\alg.exe
                    O23 - Service: [ASP.NET State Service] - %SystemRoot%\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe
                    O23 - Service: [avast! iAVS4 Control Service] - "C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe"
                    O23 - Service: [avast! Antivirus] - "C:\Program Files\Alwil Software\Avast4\ashServ.exe"
                    O23 - Service: [avast! Mail Scanner] - "C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service
                    O23 - Service: [avast! Web Scanner] - "C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service
                    O23 - Service: [AVG Anti-Spyware Guard] - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                    O23 - Service: [Gestionnaire de l'Album] - %SystemRoot%\system32\clipsrv.exe
                    O23 - Service: [Application système COM+] - C:\WINDOWS\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}
                    O23 - Service: [Fax] - %systemroot%\system32\fxssvc.exe
                    O23 - Service: [Google Updater Service] - "C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe"
                    O23 - Service: [Service COM de gravage de CD IMAPI] -
                    O23 - Service: [Partage de Bureau à distance NetMeeting] - C:\WINDOWS\system32\mnmsrvc.exe
                    O23 - Service: [Distributed Transaction Coordinator] - C:\WINDOWS\system32\msdtc.exe
                    O23 - Service: [Norman ZANDA] - C:\Norman\NVC\BIN\Zanda.exe
                    O23 - Service: [Gestionnaire de session d'aide sur le Bureau à distance] - C:\WINDOWS\system32\sessmgr.exe
                    O23 - Service: [Localisateur d'appels de procédure distante (RPC)] - %SystemRoot%\system32\locator.exe
                    O23 - Service: [QoS RSVP] - %SystemRoot%\system32\rsvp.exe
                    O23 - Service: [SmartLinkService] - slserv.exe
                    O23 - Service: [Spouleur d'impression] - %SystemRoot%\system32\spoolsv.exe
                    O23 - Service: [MS Software Shadow Copy Provider] - C:\WINDOWS\system32\dllhost.exe /Processid:{15F5A9F3-6A33-4ED8-BDC6-A67D4196A359}
                    O23 - Service: [Journaux et alertes de performance] - %SystemRoot%\system32\smlogsvc.exe
                    O23 - Service: [Onduleur] - %SystemRoot%\System32\ups.exe
                    O23 - Service: [Service Messenger Sharing Folders USN Journal Reader] - "C:\Program Files\MSN Messenger\usnsvc.exe"
                    O23 - Service: [Cliché instantané de volume] - %SystemRoot%\System32\vssvc.exe
                    O23 - Service: [Carte de performance WMI] - C:\WINDOWS\system32\wbem\wmiapsrv.exe
                    O23 - Service: [Service Partage réseau du Lecteur Windows Media] - "C:\Program Files\Windows Media Player\WMPNetwk.exe"
                    1. ok, super

                      •Télécharge PCA (d'Evosla) < http://ww25.evosla.com/pca_cpt.php?agr=pca_securite > ,
                      •Décompresse-le sur ton " Bureau " au moyen d'un clic-droit (Extraire ici...),
                      Double-clic sur l'icône "pca.exe" ( en forme de grenade qui est sur le bureau ) pour le lancer.

                      1°- •Clique sur l'onglet "diagnostic du PC" puis "analyser".
                      •Laisse l'analyse se dérouler. Cela ne prend que quelques secondes.
                      •Clique sur "enregistrer le rapport" en bas à droite et sauvegarde-le sur le bureau.
                      •Le rapport va être positionné sur ton bureau "PCA_LOG.txt"
                      • Poste-le et supprime-le de ton bureau.

                      2°- Ensuite relance "pca.exe" ( qui est sur ton bureau )
                      - •Clique sur l'onglet " Analyse antivirus " ---> lance l'analyse "scanner"
                      - Enregistre le rapport ( en bas à droite ) sur le bureau
                      Clic sur [Nettoyer]
                      Poste le rapport mis sur ton bureau " PCA_SCAN-LOG.txt " »

                      peux tu remettre un hijack this stp,
                      1. j'ai effectué le scan avec la restauration, ça a pris 20min, voici le rapport

                        Ad-Aware 2007 Build
                        Log File Created on: 2007-09-03 10:50:27
                        Using Definitions File: C:\Documents and Settings\All Users\Application Data\Lavasoft\Ad-Aware 2007\core.aawdef
                        Computer name: DAMIEN
                        Name of user performing scan: SYSTEM

                        System information
                        ===========================
                        Number of processors: 1
                        Processor type: AMD Turion(tm) 64 Mobile Technology MT-28
                        Memory Available: 22%
                        Total Physical Memory: 469090304 Bytes
                        Available Physical Memory: 98877440 Bytes
                        Total Page File Size: 1155784704 Bytes
                        Available On Page File: 748584960 Bytes
                        Total Virtual Memory: 2147352576 Bytes
                        Available Virtual Memory: 1995874304 Bytes
                        OS: Microsoft Windows XP Service Pack 2 (Build 2600)

                        Ad-Aware 2007 Settings
                        ===========================
                        Skipping files larger than 1048576 kB
                        Ignoring infections with lower TAI than: 3

                        Extended Ad-Aware 2007 Settings
                        ===========================
                        Unloading known modules during scan
                        Ignoring spanned files when scanning cab archives
                        Scanning registry for all users
                        Using permanent archive caching
                        Reanalyzing results after scanning before displaying results
                        Trying to unload modules prior to removal
                        Let Windows remove files currently in use at next reboot
                        Removing quarantined objects after restore
                        Logging Ad-Aware events
                        Blocking Pop-Ups aggressively
                        Deactivating Ad-Watch during scans
                        Writeprotecting system files after repairs
                        Including Ad-aware command line parameters in log file
                        Include info about ignored objects in log file
                        Including basic settings in log file
                        Including advanced settings in log file
                        Including user and computer name in log file
                        Include reference summary in log file
                        Creating log file for removal operations
                        Including module info in log file
                        Include Alternate Data Stream details in log file
                        Create and save WebUpdate log file

                        Databaseinfo
                        ===========================
                        Version number: 18
                        Build Number: 0
                        Build Date and Time: 2007/08/27 12:12:44

                        Scan Statistics
                        ===========================
                        Method: Full
                        Scan tracking cookies.............................: On
                        Scan ADS filestreams..............................: Off

                        Item Scanned: 146066
                        Infections Detected: 3
                        Infections Ignored: 0

                        Scan detailed statistics
                        ===========================
                        Type Critical Total
                        Process Scan....: 0 0
                        Registry Scan...: 0 0
                        Registry PE Scan: 0 0
                        Hosts File Scan.: 0 0
                        File Scan.......: 0 0
                        Folder Scan.....: 0 0
                        LSP Scan........: 0 0
                        ADS Scan........: 0 0
                        Cookie Scan.....: 1 1
                        File Hash Scan..: 0 0

                        Infections Found
                        ===========================
                        Family Id: 725 Name: Tracking Cookie Category: DataMiner TAI:3
                        Item Id: 600000173 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\NYUIADZI damien\Cookies\index.dat bluestreak.com id /
                        Family Id: 9999 Name: MRU Object Category: MRU Object TAI:0
                        Item Id: 1 Value: MRU Path: C:\Documents and Settings\NYUIADZI damien\Recent Count: 22
                        Item Id: 2 Value: MRU Registry Key: S-1-5-21-1890995607-336724566-898250518-1006\Software\Microsoft\Search Assistant\ACMru\5603 Count: 1

                        Items Ignored During Scan
                        ===========================

                        Listing of running processes
                        ===========================
                        C:\WINDOWS\SYSTEM32\SMSS.EXE
                        c:\windows\system32\smss.exe

                        c:\windows\system32\ntdll.dll

                        C:\WINDOWS\SYSTEM32\CSRSS.EXE
                        c:\windows\system32\csrss.exe

                        c:\windows\system32\ntdll.dll

                        c:\windows\system32\csrsrv.dll

                        c:\windows\system32\basesrv.dll

                        c:\windows\system32\winsrv.dll

                        c:\windows\system32\gdi32.dll

                        c:\windows\system32\kernel32.dll

                        c:\windows\system32\user32.dll

                        c:\windows\system32\sxs.dll

                        c:\windows\system32\advapi32.dll

                        c:\windows\system32\rpcrt4.dll

                        C:\WINDOWS\SYSTEM32\WINLOGON.EXE
                        c:\windows\system32\winlogon.exe

                        c:\windows\system32\ntdll.dll

                        c:\windows\system32\kernel32.dll

                        c:\windows\system32\advapi32.dll

                        c:\windows\system32\rpcrt4.dll

                        c:\windows\system32\authz.dll

                        c:\windows\system32\msvcrt.dll

                        c:\windows\system32\crypt32.dll

                        c:\windows\system32\user32.dll

                        c:\windows\system32\gdi32.dll

                        c:\windows\system32\msasn1.dll

                        c:\windows\system32\nddeapi.dll

                        c:\windows\system32\profmap.dll

                        c:\windows\system32\netapi32.dll

                        c:\windows\system32\userenv.dll

                        c:\windows\system32\psapi.dll

                        c:\windows\system32\regapi.dll

                        c:\windows\system32\secur32.dll

                        c:\windows\system32\setupapi.dll

                        c:\windows\system32\version.dll

                        c:\windows\system32\winsta.dll

                        c:\windows\system32\wintrust.dll

                        c:\windows\system32\imagehlp.dll

                        c:\windows\system32\ws2_32.dll

                        c:\windows\system32\ws2help.dll

                        c:\windows\system32\msgina.dll

                        c:\windows\system32\shell32.dll

                        c:\windows\system32\shlwapi.dll

                        c:\windows\system32\comctl32.dll

                        c:\windows\system32\odbc32.dll

                        c:\windows\system32\comdlg32.dll

                        c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll

                        c:\windows\system32\odbcint.dll

                        c:\windows\system32\shsvcs.dll

                        c:\windows\system32\sfc.dll

                        c:\windows\system32\sfc_os.dll

                        c:\windows\system32\ole32.dll

                        c:\windows\system32\apphelp.dll

                        c:\windows\system32\winscard.dll

                        c:\windows\system32\wtsapi32.dll

                        c:\windows\system32\sxs.dll

                        c:\windows\system32\uxtheme.dll

                        c:\windows\system32\winmm.dll

                        c:\windows\system32\serwvdrv.dll

                        c:\windows\system32\umdmxfrm.dll

                        c:\windows\system32\cscdll.dll

                        c:\windows\system32\wlnotify.dll

                        c:\windows\system32\winspool.drv

                        c:\windows\system32\mpr.dll

                        c:\windows\system32\rsaenh.dll

                        c:\windows\system32\wgalogon.dll

                        c:\windows\system32\oleaut32.dll

                        c:\windows\system32\ntmarta.dll

                        c:\windows\system32\wldap32.dll

                        c:\windows\system32\samlib.dll

                        c:\windows\system32\clbcatq.dll

                        c:\windows\system32\comres.dll

                        c:\windows\system32\msv1_0.dll

                        c:\windows\system32\iphlpapi.dll

                        c:\windows\system32\cscui.dll

                        c:\windows\system32\xpsp2res.dll

                        c:\windows\system32\wdmaud.drv

                        c:\windows\system32\msacm32.drv

                        c:\windows\system32\msacm32.dll

                        c:\windows\system32\midimap.dll

                        C:\WINDOWS\SYSTEM32\SERVICES.EXE
                        c:\windows\system32\services.exe

                        c:\windows\system32\ntdll.dll

                        c:\windows\system32\kernel32.dll

                        c:\windows\system32\msvcrt.dll

                        c:\windows\system32\advapi32.dll

                        c:\windows\system32\rpcrt4.dll

                        c:\windows\system32\user32.dll

                        c:\windows\system32\gdi32.dll

                        c:\windows\system32\userenv.dll

                        c:\windows\system32\scesrv.dll

                        c:\windows\system32\authz.dll

                        c:\windows\system32\umpnpmgr.dll

                        c:\windows\system32\winsta.dll

                        c:\windows\system32\netapi32.dll

                        c:\windows\system32\ncobjapi.dll

                        c:\windows\system32\msvcp60.dll

                        c:\windows\system32\shimeng.dll

                        c:\windows\apppatch\acadproc.dll

                        c:\windows\system32\secur32.dll

                        c:\windows\system32\apphelp.dll

                        c:\windows\system32\version.dll

                        c:\windows\system32\eventlog.dll

                        c:\windows\system32\ws2_32.dll

                        c:\windows\system32\ws2help.dll

                        c:\windows\system32\psapi.dll

                        c:\windows\system32\wtsapi32.dll

                        C:\WINDOWS\SYSTEM32\LSASS.EXE
                        c:\windows\system32\lsass.exe

                        c:\windows\system32\ntdll.dll

                        c:\windows\system32\kernel32.dll

                        c:\windows\system32\advapi32.dll

                        c:\windows\system32\rpcrt4.dll

                        c:\windows\system32\lsasrv.dll

                        c:\windows\system32\mpr.dll

                        c:\windows\system32\user32.dll

                        c:\windows\system32\gdi32.dll

                        c:\windows\system32\msasn1.dll

                        c:\windows\system32\msvcrt.dll

                        c:\windows\system32\netapi32.dll

                        c:\windows\system32\ntdsapi.dll

                        c:\windows\system32\dnsapi.dll

                        c:\windows\system32\ws2_32.dll

                        c:\windows\system32\ws2help.dll

                        c:\windows\system32\wldap32.dll

                        c:\windows\system32\secur32.dll

                        c:\windows\system32\samlib.dll

                        c:\windows\system32\samsrv.dll

                        c:\windows\system32\cryptdll.dll

                        c:\windows\system32\shimeng.dll

                        c:\windows\apppatch\acgenral.dll

                        c:\windows\system32\winmm.dll

                        c:\windows\system32\ole32.dll

                        c:\windows\system32\oleaut32.dll

                        c:\windows\system32\msacm32.dll

                        c:\windows\system32\version.dll

                        c:\windows\system32\shell32.dll

                        c:\windows\system32\shlwapi.dll

                        c:\windows\system32\userenv.dll

                        c:\windows\system32\uxtheme.dll

                        c:\windows\system32\serwvdrv.dll

                        c:\windows\system32\umdmxfrm.dll

                        c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll

                        c:\windows\system32\comctl32.dll

                        c:\windows\system32\msprivs.dll

                        c:\windows\system32\kerberos.dll

                        c:\windows\system32\msv1_0.dll

                        c:\windows\system32\iphlpapi.dll

                        c:\windows\system32\netlogon.dll

                        c:\windows\system32\w32time.dll

                        c:\windows\system32\msvcp60.dll

                        c:\windows\system32\schannel.dll

                        c:\windows\system32\crypt32.dll

                        c:\windows\system32\wdigest.dll

                        c:\windows\system32\rsaenh.dll

                        c:\windows\system32\scecli.dll

                        c:\windows\system32\setupapi.dll

                        c:\windows\system32\ipsecsvc.dll

                        c:\windows\system32\authz.dll

                        c:\windows\system32\oakley.dll

                        c:\windows\system32\winipsec.dll

                        c:\windows\system32\pstorsvc.dll

                        c:\windows\system32\psbase.dll

                        c:\windows\system32\mswsock.dll

                        c:\windows\system32\hnetcfg.dll

                        c:\windows\system32\wshtcpip.dll

                        c:\windows\system32\dssenh.dll

                        C:\WINDOWS\SYSTEM32\SVCHOST.EXE
                        c:\windows\system32\svchost.exe

                        c:\windows\system32\ntdll.dll

                        c:\windows\system32\kernel32.dll

                        c:\windows\system32\advapi32.dll

                        c:\windows\system32\rpcrt4.dll

                        c:\windows\system32\shimeng.dll

                        c:\windows\apppatch\acgenral.dll

                        c:\windows\system32\user32.dll

                        c:\windows\system32\gdi32.dll

                        c:\windows\system32\winmm.dll

                        c:\windows\system32\ole32.dll

                        c:\windows\system32\msvcrt.dll

                        c:\windows\system32\oleaut32.dll

                        c:\windows\system32\msacm32.dll

                        c:\windows\system32\version.dll

                        c:\windows\system32\shell32.dll

                        c:\windows\system32\shlwapi.dll

                        c:\windows\system32\userenv.dll

                        c:\windows\system32\uxtheme.dll

                        c:\windows\system32\serwvdrv.dll

                        c:\windows\system32\umdmxfrm.dll

                        c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll

                        c:\windows\system32\comctl32.dll

                        c:\windows\system32\ntmarta.dll

                        c:\windows\system32\wldap32.dll

                        c:\windows\system32\samlib.dll

                        c:\windows\system32\rpcss.dll

                        c:\windows\system32\secur32.dll

                        c:\windows\system32\ws2_32.dll

                        c:\windows\system32\ws2help.dll

                        c:\windows\system32\xpsp2res.dll

                        c:\windows\system32\termsrv.dll

                        c:\windows\system32\icaapi.dll

                        c:\windows\system32\setupapi.dll

                        c:\windows\system32\wintrust.dll

                        c:\windows\system32\crypt32.dll

                        c:\windows\system32\msasn1.dll

                        c:\windows\system32\imagehlp.dll

                        c:\windows\system32\authz.dll

                        c:\windows\system32\mstlsapi.dll

                        c:\windows\system32\activeds.dll

                        c:\windows\system32\adsldpc.dll

                        c:\windows\system32\netapi32.dll

                        c:\windows\system32\atl.dll

                        c:\windows\system32\regapi.dll

                        c:\windows\system32\rsaenh.dll

                        c:\windows\system32\clbcatq.dll

                        c:\windows\system32\comres.dll

                        c:\windows\system32\apphelp.dll

                        c:\windows\system32\svchost.exe

                        c:\windows\system32\ntdll.dll

                        c:\windows\system32\kernel32.dll

                        c:\windows\system32\advapi32.dll

                        c:\windows\system32\rpcrt4.dll

                        c:\windows\system32\shimeng.dll

                        c:\windows\apppatch\acgenral.dll

                        c:\windows\system32\user32.dll

                        c:\windows\system32\gdi32.dll

                        c:\windows\system32\winmm.dll

                        c:\windows\system32\ole32.dll

                        c:\windows\system32\msvcrt.dll

                        c:\windows\system32\oleaut32.dll

                        c:\windows\system32\msacm32.dll

                        c:\windows\system32\version.dll

                        c:\windows\system32\shell32.dll

                        c:\windows\system32\shlwapi.dll

                        c:\windows\system32\userenv.dll

                        c:\windows\system32\uxtheme.dll

                        c:\windows\system32\serwvdrv.dll

                        c:\windows\system32\umdmxfrm.dll

                        c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll

                        c:\windows\system32\comctl32.dll

                        c:\windows\system32\rpcss.dll

                        c:\windows\system32\secur32.dll

                        c:\windows\system32\ws2_32.dll

                        c:\windows\system32\ws2help.dll

                        c:\windows\system32\xpsp2res.dll

                        c:\windows\system32\rsaenh.dll

                        c:\windows\system32\mswsock.dll

                        c:\windows\system32\hnetcfg.dll

                        c:\windows\system32\wshtcpip.dll

                        c:\windows\system32\dnsapi.dll

                        c:\windows\system32\iphlpapi.dll

                        c:\windows\system32\winrnr.dll

                        c:\windows\system32\wldap32.dll

                        c:\windows\system32\wshbth.dll

                        c:\windows\system32\setupapi.dll

                        c:\windows\system32\rasadhlp.dll

                        c:\windows\system32\clbcatq.dll

                        c:\windows\system32\comres.dll

                        c:\windows\system32\svchost.exe

                        c:\windows\system32\ntdll.dll

                        c:\windows\system32\kernel32.dll

                        c:\windows\system32\advapi32.dll

                        c:\windows\system32\rpcrt4.dll

                        c:\windows\system32\shimeng.dll

                        c:\windows\apppatch\acgenral.dll

                        c:\windows\system32\user32.dll

                        c:\windows\system32\gdi32.dll

                        c:\windows\system32\winmm.dll

                        c:\windows\system32\ole32.dll

                        c:\windows\system32\msvcrt.dll

                        c:\windows\system32\oleaut32.dll

                        c:\windows\system32\msacm32.dll

                        c:\windows\system32\version.dll

                        c:\windows\system32\shell32.dll

                        c:\windows\system32\shlwapi.dll

                        c:\windows\system32\userenv.dll

                        c:\windows\system32\uxtheme.dll

                        c:\windows\system32\serwvdrv.dll

                        c:\windows\system32\umdmxfrm.dll

                        c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll

                        c:\windows\system32\comctl32.dll

                        c:\windows\system32\ntmarta.dll

                        c:\windows\system32\wldap32.dll

                        c:\windows\system32\samlib.dll

                        c:\windows\system32\xpsp2res.dll

                        c:\windows\system32\shsvcs.dll

                        c:\windows\system32\winsta.dll

                        c:\windows\system32\netapi32.dll

                        c:\windows\system32\dhcpcsvc.dll

                        c:\windows\system32\dnsapi.dll

                        c:\windows\system32\ws2_32.dll

                        c:\windows\system32\ws2help.dll

                        c:\windows\system32\iphlpapi.dll

                        c:\windows\system32\secur32.dll

                        c:\windows\system32\mswsock.dll

                        c:\windows\system32\hnetcfg.dll

                        c:\windows\system32\wshtcpip.dll

                        c:\windows\system32\rsaenh.dll

                        c:\windows\system32\wzcsvc.dll

                        c:\windows\system32\rtutils.dll

                        c:\windows\system32\wmi.dll

                        c:\windows\system32\crypt32.dll

                        c:\windows\system32\msasn1.dll

                        c:\windows\system32\wtsapi32.dll

                        c:\windows\system32\esent.dll

                        c:\windows\system32\atl.dll

                        c:\windows\system32\irmon.dll

                        c:\windows\system32\msv1_0.dll

                        c:\windows\system32\rastls.dll

                        c:\windows\system32\cryptui.dll

                        c:\windows\system32\wintrust.dll

                        c:\windows\system32\imagehlp.dll

                        c:\windows\system32\wininet.dll

                        c:\windows\system32\mprapi.dll

                        c:\windows\system32\activeds.dll

                        c:\windows\system32\adsldpc.dll

                        c:\windows\system32\setupapi.dll

                        c:\windows\system32\rasapi32.dll

                        c:\windows\system32\rasman.dll

                        c:\windows\system32\tapi32.dll

                        c:\windows\system32\schannel.dll

                        c:\windows\system32\winscard.dll

                        c:\windows\system32\raschap.dll

                        c:\windows\system32\wshirda.dll

                        c:\windows\system32\clbcatq.dll

                        c:\windows\system32\comres.dll

                        c:\windows\system32\schedsvc.dll

                        c:\windows\system32\ntdsapi.dll

                        c:\windows\system32\msidle.dll

                        c:\windows\system32\audiosrv.dll

                        c:\windows\system32\wkssvc.dll

                        c:\windows\system32\qmgr.dll

                        c:\windows\system32\mpr.dll

                        c:\windows\system32\shfolder.dll

                        c:\windows\system32\winhttp.dll

                        c:\windows\system32\cryptsvc.dll

                        c:\windows\system32\certcli.dll

                        c:\windows\system32\netman.dll

                        c:\windows\system32\netshell.dll

                        c:\windows\system32\credui.dll

                        c:\windows\system32\wzcsapi.dll

                        c:\windows\system32\srvsvc.dll

                        c:\windows\system32\hidserv.dll

                        c:\windows\system32\hid.dll

                        c:\windows\pchealth\helpctr\binaries\pchsvc.dll

                        c:\windows\system32\es.dll

                        c:\windows\system32\ersvc.dll

                        c:\windows\system32\seclogon.dll

                        c:\windows\system32\srsvc.dll

                        c:\windows\system32\powrprof.dll

                        c:\windows\system32\wuauserv.dll

                        c:\windows\system32\wbem\wmisvc.dll

                        c:\windows\system32\vssapi.dll

                        c:\windows\system32\wuaueng.dll

                        c:\windows\system32\winspool.drv

                        c:\windows\system32\cabinet.dll

                        c:\windows\system32\mspatcha.dll

                        c:\windows\system32\w32time.dll

                        c:\windows\system32\msvcp60.dll

                        c:\windows\system32\trkwks.dll

                        c:\windows\system32\tapisrv.dll

                        c:\windows\system32\psapi.dll

                        c:\windows\system32\sens.dll

                        c:\windows\system32\browser.dll

                        c:\windows\system32\wscsvc.dll

                        c:\windows\system32\msi.dll

                        c:\windows\system32\sfc.dll

                        c:\windows\system32\sfc_os.dll

                        c:\windows\system32\ipnathlp.dll

                        c:\windows\system32\authz.dll

                        c:\windows\system32\sxs.dll

                        c:\windows\system32\wbem\wbemcomn.dll

                        c:\windows\system32\wbem\wbemcore.dll

                        c:\windows\system32\wbem\esscli.dll

                        c:\windows\system32\wbem\fastprox.dll

                        c:\windows\system32\comsvcs.dll

                        c:\windows\system32\colbact.dll

                        c:\windows\system32\mtxclu.dll

                        c:\windows\system32\wsock32.dll

                        c:\windows\system32\clusapi.dll

                        c:\windows\system32\resutils.dll

                        c:\windows\system32\wbem\wmiutils.dll

                        c:\windows\system32\wbem\repdrvfs.dll

                        c:\windows\system32\wbem\wmiprvsd.dll

                        c:\windows\system32\ncobjapi.dll

                        c:\windows\system32\wbem\wbemess.dll

                        c:\windows\system32\wbem\ncprov.dll

                        c:\windows\system32\upnp.dll

                        c:\windows\system32\ssdpapi.dll

                        c:\windows\system32\netcfgx.dll

                        c:\windows\system32\rasmans.dll

                        c:\windows\system32\winipsec.dll

                        c:\windows\system32\rasadhlp.dll

                        c:\windows\system32\rastapi.dll

                        c:\windows\system32\unimdm.tsp

                        c:\windows\system32\uniplat.dll

                        c:\windows\system32\unimdmat.dll

                        c:\windows\system32\modemui.dll

                        c:\windows\system32\kmddsp.tsp

                        c:\windows\system32\ndptsp.tsp

                        c:\windows\system32\ipconf.tsp

                        c:\windows\system32\h323.tsp

                        c:\windows\system32\hidphone.tsp

                        c:\windows\system32\rasppp.dll

                        c:\windows\system32\ntlsapi.dll

                        c:\windows\system32\kerberos.dll

                        c:\windows\system32\cryptdll.dll

                        c:\windows\system32\rasdlg.dll

                        c:\windows\system32\msxml3.dll

                        c:\windows\system32\apphelp.dll

                        c:\windows\system32\wups2.dll

                        c:\windows\system32\dssenh.dll

                        c:\windows\system32\winrnr.dll

                        c:\windows\system32\wshbth.dll

                        c:\windows\system32\advpack.dll

                        c:\windows\system32\catsrvut.dll

                        c:\windows\system32\catsrv.dll

                        c:\windows\system32\mfcsubs.dll

                        c:\windows\system32\urlmon.dll

                        c:\windows\system32\mlang.dll

                        c:\windows\system32\xmlprovi.dll

                        c:\windows\system32\svchost.exe

                        c:\windows\system32\ntdll.dll

                        c:\windows\system32\kernel32.dll

                        c:\windows\system32\advapi32.dll

                        c:\windows\system32\rpcrt4.dll

                        c:\windows\system32\shimeng.dll

                        c:\windows\apppatch\acgenral.dll

                        c:\windows\system32\user32.dll

                        c:\windows\system32\gdi32.dll

                        c:\windows\system32\winmm.dll

                        c:\windows\system32\ole32.dll

                        c:\windows\system32\msvcrt.dll

                        c:\windows\system32\oleaut32.dll

                        c:\windows\system32\msacm32.dll

                        c:\windows\system32\version.dll

                        c:\windows\system32\shell32.dll

                        c:\windows\system32\shlwapi.dll

                        c:\windows\system32\userenv.dll

                        c:\windows\system32\uxtheme.dll

                        c:\windows\system32\serwvdrv.dll

                        c:\windows\system32\umdmxfrm.dll

                        c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll

                        c:\windows\system32\comctl32.dll

                        c:\windows\system32\dnsrslvr.dll

                        c:\windows\system32\dnsapi.dll

                        c:\windows\system32\ws2_32.dll

                        c:\windows\system32\ws2help.dll

                        c:\windows\system32\iphlpapi.dll

                        c:\windows\system32\mswsock.dll

                        c:\windows\system32\hnetcfg.dll

                        c:\windows\system32\wshtcpip.dll

                        c:\windows\system32\svchost.exe

                        c:\windows\system32\ntdll.dll

                        c:\windows\system32\kernel32.dll

                        c:\windows\system32\advapi32.dll

                        c:\windows\system32\rpcrt4.dll

                        c:\windows\system32\shimeng.dll

                        c:\windows\apppatch\acgenral.dll

                        c:\windows\system32\user32.dll

                        c:\windows\system32\gdi32.dll

                        c:\windows\system32\winmm.dll

                        c:\windows\system32\ole32.dll

                        c:\windows\system32\msvcrt.dll

                        c:\windows\system32\oleaut32.dll

                        c:\windows\system32\msacm32.dll

                        c:\windows\system32\version.dll

                        c:\windows\system32\shell32.dll

                        c:\windows\system32\shlwapi.dll

                        c:\windows\system32\userenv.dll

                        c:\windows\system32\uxtheme.dll

                        c:\windows\system32\serwvdrv.dll

                        c:\windows\system32\umdmxfrm.dll

                        c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll

                        c:\windows\system32\comctl32.dll

                        c:\windows\system32\ntmarta.dll

                        c:\windows\system32\wldap32.dll

                        c:\windows\system32\samlib.dll

                        c:\windows\system32\xpsp2res.dll

                        c:\windows\system32\lmhsvc.dll

                        c:\windows\system32\iphlpapi.dll

                        c:\windows\system32\ws2_32.dll

                        c:\windows\system32\ws2help.dll

                        c:\windows\system32\webclnt.dll

                        c:\windows\system32\wininet.dll

                        c:\windows\system32\crypt32.dll

                        c:\windows\system32\msasn1.dll

                        c:\windows\system32\secur32.dll

                        c:\windows\system32\wsock32.dll

                        c:\windows\system32\alrsvc.dll

                        c:\windows\system32\netapi32.dll

                        c:\windows\system32\ssdpsrv.dll

                        c:\windows\system32\hnetcfg.dll

                        c:\windows\system32\clbcatq.dll

                        c:\windows\system32\comres.dll

                        c:\windows\system32\mswsock.dll

                        c:\windows\system32\wshtcpip.dll

                        C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASWUPDSV.EXE
                        c:\program files\alwil software\avast4\aswupdsv.exe

                        c:\windows\system32\ntdll.dll

                        c:\windows\system32\kernel32.dll

                        c:\program files\alwil software\avast4\aswcmns.dll

                        c:\program files\alwil software\avast4\aswcmnos.dll

                        c:\windows\system32\user32.dll

                        c:\windows\system32\gdi32.dll

                        c:\windows\system32\advapi32.dll

                        c:\windows\system32\rpcrt4.dll

                        c:\windows\system32\msvcp71.dll

                        c:\windows\system32\msvcr71.dll

                        c:\windows\system32\wsock32.dll

                        c:\windows\system32\ws2_32.dll

                        c:\windows\system32\msvcrt.dll

                        c:\windows\system32\ws2help.dll

                        c:\program files\alwil software\avast4\aswcmnb.dll

                        C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHSERV.EXE
                        c:\program files\alwil software\avast4\ashserv.exe

                        c:\windows\system32\ntdll.dll

                        c:\windows\system32\kernel32.dll

                        c:\windows\system32\rpcrt4.dll

                        c:\windows\system32\advapi32.dll

                        c:\program files\alwil software\avast4\aswaux.dll

                        c:\windows\system32\msvcp71.dll

                        c:\windows\system32\msvcr71.dll

                        c:\program files\alwil software\avast4\aswcmnb.dll

                        c:\program files\alwil software\avast4\aswcmnos.dll

                        c:\windows\system32\user32.dll

                        c:\windows\system32\gdi32.dll

                        c:\windows\system32\wsock32.dll

                        c:\windows\system32\ws2_32.dll

                        c:\windows\system32\msvcrt.dll

                        c:\windows\system32\ws2help.dll

                        c:\program files\alwil software\avast4\aswengin.dll

                        c:\windows\system32\shell32.dll

                        c:\windows\system32\shlwapi.dll

                        c:\windows\system32\ole32.dll

                        c:\program files\alwil software\avast4\aswscan.dll

                        c:\program files\alwil software\avast4\aswcmns.dll

                        c:\windows\system32\oleaut32.dll

                        c:\program files\alwil software\avast4\ashbase.dll

                        c:\windows\system32\version.dll

                        c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll

                        c:\program files\alwil software\avast4\ashtask.dll

                        c:\program files\alwil software\avast4\aswinteg.dll

                        c:\program files\alwil software\avast4\aswidle.dll

                        c:\program files\alwil software\avast4\aavm4h.dll

                        c:\windows\system32\dbghelp.dll

                        c:\program files\alwil software\avast4\french\base.dll

                        c:\program files\alwil software\avast4\unacev2.dll

                        c:\windows\system32\wtsapi32.dll

                        c:\windows\system32\winsta.dll

                        c:\windows\system32\netapi32.dll

                        c:\program files\alwil software\avast4\ahresmai.dll

                        c:\program files\alwil software\avast4\ahresmes.dll

                        c:\program files\alwil software\avast4\ahresns.dll

                        c:\program files\alwil software\avast4\ahresout.dll

                        c:\program files\alwil software\avast4\ahresp2p.dll

                        c:\program files\alwil software\avast4\ahresstd.dll

                        c:\program files\alwil software\avast4\ahresws.dll

                        c:\program files\alwil software\avast4\ashssqlt.dll

                        c:\windows\system32\clbcatq.dll

                        c:\windows\system32\comres.dll

                        c:\windows\system32\xpsp2res.dll

                        c:\windows\system32\iphlpapi.dll

                        c:\windows\system32\mswsock.dll

                        c:\windows\system32\dnsapi.dll

                        c:\windows\system32\winrnr.dll

                        c:\windows\system32\wldap32.dll

                        c:\windows\system32\wshbth.dll

                        c:\windows\system32\setupapi.dll

                        c:\windows\system32\uxtheme.dll

                        c:\windows\system32\rasadhlp.dll

                        c:\windows\system32\perfos.dll

                        c:\program files\alwil software\avast4\aswres.dll

                        c:\windows\system32\secur32.dll

                        C:\WINDOWS\SYSTEM32\SPOOLSV.EXE
                        c:\windows\system32\spoolsv.exe

                        c:\windows\system32\ntdll.dll

                        c:\windows\system32\kernel32.dll

                        c:\windows\system32\advapi32.dll

                        c:\windows\system32\rpcrt4.dll

                        c:\windows\system32\gdi32.dll

                        c:\windows\system32\user32.dll

                        c:\windows\system32\msvcrt.dll

                        c:\windows\system32\shimeng.dll

                        c:\windows\apppatch\acgenral.dll

                        c:\windows\system32\winmm.dll

                        c:\windows\system32\ole32.dll

                        c:\windows\system32\oleaut32.dll

                        c:\windows\system32\msacm32.dll

                        c:\windows\system32\version.dll

                        c:\windows\system32\shell32.dll

                        c:\windows\system32\shlwapi.dll

                        c:\windows\system32\userenv.dll

                        c:\windows\system32\uxtheme.dll

                        c:\windows\system32\serwvdrv.dll

                        c:\windows\system32\umdmxfrm.dll

                        c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll

                        c:\windows\system32\comctl32.dll

                        c:\windows\system32\spoolss.dll

                        c:\windows\system32\ws2_32.dll

                        c:\windows\system32\ws2help.dll

                        c:\windows\system32\dnsapi.dll

                        c:\windows\system32\rasadhlp.dll

                        c:\windows\system32\localspl.dll

                        c:\windows\system32\secur32.dll

                        c:\windows\system32\sfc_os.dll

                        c:\windows\system32\wintrust.dll

                        c:\windows\system32\crypt32.dll

                        c:\windows\system32\msasn1.dll

                        c:\windows\system32\imagehlp.dll

                        c:\windows\system32\winspool.drv

                        c:\windows\system32\netapi32.dll

                        c:\windows\system32\cnbjmon.dll

                        c:\windows\system32\mswsock.dll

                        c:\windows\system32\fxsmon.dll

                        c:\windows\system32\fxsevent.dll

                        c:\windows\system32\pjlmon.dll

                        c:\windows\system32\tcpmon.dll

                        c:\windows\system32\usbmon.dll

                        c:\windows\system32\winrnr.dll

                        c:\windows\system32\wldap32.dll

                        c:\windows\system32\wshbth.dll

                        c:\windows\system32\setupapi.dll

                        c:\windows\system32\win32spl.dll

                        c:\windows\system32\netrap.dll

                        c:\windows\system32\ntdsapi.dll

                        c:\windows\system32\clbcatq.dll

                        c:\windows\system32\comres.dll

                        c:\windows\system32\inetpp.dll

                        c:\windows\system32\xpsp2res.dll

                        C:\WINDOWS\SYSTEM32\SVCHOST.EXE
                        c:\windows\system32\svchost.exe

                        c:\windows\system32\ntdll.dll

                        c:\windows\system32\kernel32.dll

                        c:\windows\system32\advapi32.dll

                        c:\windows\system32\rpcrt4.dll

                        c:\windows\system32\shimeng.dll

                        c:\windows\apppatch\acgenral.dll

                        c:\windows\system32\user32.dll

                        c:\windows\system32\gdi32.dll

                        c:\windows\system32\winmm.dll

                        c:\windows\system32\ole32.dll

                        c:\windows\system32\msvcrt.dll

                        c:\windows\system32\oleaut32.dll

                        c:\windows\system32\msacm32.dll

                        c:\windows\system32\version.dll

                        c:\windows\system32\shell32.dll

                        c:\windows\system32\shlwapi.dll

                        c:\windows\system32\userenv.dll

                        c:\windows\system32\uxtheme.dll

                        c:\windows\system32\serwvdrv.dll

                        c:\windows\system32\umdmxfrm.dll

                        c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll

                        c:\windows\system32\comctl32.dll

                        c:\windows\system32\bthserv.dll

                        c:\windows\system32\setupapi.dll

                        c:\windows\system32\wintrust.dll

                        c:\windows\system32\crypt32.dll

                        c:\windows\system32\msasn1.dll

                        c:\windows\system32\imagehlp.dll

                        c:\windows\system32\secur32.dll

                        c:\windows\system32\msv1_0.dll

                        c:\windows\system32\ws2_32.dll

                        c:\windows\system32\ws2help.dll

                        c:\windows\system32\iphlpapi.dll

                        C:\WINDOWS\SYSTEM32\CISVC.EXE
                        c:\windows\system32\cisvc.exe

                        c:\windows\system32\ntdll.dll

                        c:\windows\system32\kernel32.dll

                        c:\windows\system32\query.dll

                        c:\windows\system32\msvcrt.dll

                        c:\windows\system32\user32.dll

                        c:\windows\system32\gdi32.dll

                        c:\windows\system32\rpcrt4.dll

                        c:\windows\system32\advapi32.dll

                        c:\windows\system32\oleaut32.dll

                        c:\windows\system32\ole32.dll

                        c:\windows\system32\shell32.dll

                        c:\windows\system32\shlwapi.dll

                        c:\windows\system32\shimeng.dll

                        c:\windows\apppatch\acgenral.dll

                        c:\windows\system32\winmm.dll

                        c:\windows\system32\msacm32.dll

                        c:\windows\system32\version.dll

                        c:\windows\system32\userenv.dll

                        c:\windows\system32\uxtheme.dll

                        c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll

                        c:\windows\system32\comctl32.dll

                        c:\windows\system32\serwvdrv.dll

                        c:\windows\system32\umdmxfrm.dll

                        c:\windows\system32\clbcatq.dll

                        c:\windows\system32\comres.dll

                        c:\windows\system32\ntmarta.dll

                        c:\windows\system32\wldap32.dll

                        c:\windows\system32\samlib.dll

                        c:\windows\system32\apphelp.dll

                        C:\WINDOWS\SYSTEM32\SLSERV.EXE
                        c:\windows\system32\slserv.exe

                        c:\windows\system32\ntdll.dll

                        c:\windows\system32\kernel32.dll

                        c:\windows\system32\advapi32.dll

                        c:\windows\system32\rpcrt4.dll

                        C:\WINDOWS\EXPLORER.EXE
                        c:\windows\explorer.exe

                        c:\windows\system32\ntdll.dll

                        c:\windows\system32\kernel32.dll

                        c:\windows\system32\advapi32.dll

                        c:\windows\system32\rpcrt4.dll

                        c:\windows\system32\browseui.dll

                        c:\windows\system32\gdi32.dll

                        c:\windows\system32\user32.dll

                        c:\windows\system32\msvcrt.dll

                        c:\windows\system32\ole32.dll

                        c:\windows\system32\shlwapi.dll

                        c:\windows\system32\oleaut32.dll

                        c:\windows\system32\shdocvw.dll

                        c:\windows\system32\crypt32.dll

                        c:\windows\system32\msasn1.dll

                        c:\windows\system32\cryptui.dll

                        c:\windows\system32\wintrust.dll

                        c:\windows\system32\imagehlp.dll

                        c:\windows\system32\netapi32.dll

                        c:\windows\system32\wininet.dll

                        c:\windows\system32\wldap32.dll

                        c:\windows\system32\version.dll

                        c:\windows\system32\shell32.dll

                        c:\windows\system32\uxtheme.dll

                        c:\windows\system32\shimeng.dll

                        c:\windows\apppatch\acgenral.dll

                        c:\windows\system32\winmm.dll

                        c:\windows\system32\msacm32.dll

                        c:\windows\system32\userenv.dll

                        c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll

                        c:\windows\system32\comctl32.dll

                        c:\windows\system32\serwvdrv.dll

                        c:\windows\system32\umdmxfrm.dll

                        c:\windows\system32\apphelp.dll

                        c:\windows\system32\clbcatq.dll

                        c:\windows\system32\comres.dll

                        c:\windows\system32\cscui.dll

                        c:\windows\system32\cscdll.dll

                        c:\windows\system32\themeui.dll

                        c:\windows\system32\secur32.dll

                        c:\windows\system32\msimg32.dll

                        c:\windows\system32\xpsp2res.dll

                        c:\windows\system32\msutb.dll

                        c:\windows\system32\msctf.dll

                        c:\windows\system32\samlib.dll

                        c:\windows\system32\mlang.dll

                        c:\windows\system32\linkinfo.dll

                        c:\windows\system32\ntshrui.dll

                        c:\windows\system32\atl.dll

                        c:\windows\system32\setupapi.dll

                        c:\windows\system32\mpr.dll

                        c:\windows\system32\drprov.dll

                        c:\windows\system32\ntlanman.dll

                        c:\windows\system32\netui0.dll

                        c:\windows\system32\netui1.dll

                        c:\windows\system32\netrap.dll

                        c:\windows\system32\davclnt.dll

                        c:\windows\system32\msi.dll

                        c:\windows\system32\winsta.dll

                        c:\windows\system32\webcheck.dll

                        c:\windows\system32\wsock32.dll

                        c:\windows\system32\ws2_32.dll

                        c:\windows\system32\ws2help.dll

                        c:\windows\system32\stobject.dll

                        c:\windows\system32\batmeter.dll

                        c:\windows\system32\powrprof.dll

                        c:\windows\system32\wtsapi32.dll

                        c:\windows\system32\urlmon.dll

                        c:\windows\system32\wpdshserviceobj.dll

                        c:\windows\system32\winhttp.dll

                        c:\windows\system32\portabledevicetypes.dll

                        c:\windows\system32\portabledeviceapi.dll

                        c:\windows\system32\wdmaud.drv

                        c:\windows\system32\msacm32.drv

                        c:\windows\system32\midimap.dll

                        c:\windows\system32\netshell.dll

                        c:\windows\system32\rtutils.dll

                        c:\windows\system32\credui.dll

                        c:\windows\system32\iphlpapi.dll

                        c:\windows\system32\wzcsapi.dll

                        c:\windows\system32\fxsst.dll

                        c:\windows\system32\winspool.drv

                        c:\windows\system32\fxsapi.dll

                        c:\windows\system32\ntmarta.dll

                        c:\windows\system32\rsaenh.dll

                        c:\program files\logitech\setpoint\lgscroll.dll

                        c:\windows\system32\msvcr71.dll

                        c:\windows\system32\msvcp71.dll

                        c:\windows\system32\sishook.dll

                        c:\windows\system32\sisapcom.dll

                        c:\windows\system32\ddraw.dll

                        c:\windows\system32\dciman32.dll

                        c:\windows\system32\sisbase.dll

                        c:\windows\system32\mfc42.dll

                        c:\windows\system32\msvcirt.dll

                        c:\windows\system32\mfc42loc.dll

                        c:\windows\system32\wzcdlg.dll

                        c:\windows\system32\browselc.dll

                        c:\windows\system32\imm32.dll

                        c:\windows\system32\sxs.dll

                        c:\windows\system32\rasdlg.dll

                        c:\windows\system32\mprapi.dll

                        c:\windows\system32\activeds.dll

                        c:\windows\system32\adsldpc.dll

                        c:\windows\system32\rasapi32.dll

                        c:\windows\system32\rasman.dll

                        c:\windows\system32\tapi32.dll

                        c:\windows\system32\duser.dll

                        c:\program files\adobe\acrobat 7.0\activex\pdfshell.dll

                        c:\windows\system32\shdoclc.dll

                        c:\program files\grisoft\avg anti-spyware 7.5\shellexecutehook.dll

                        c:\windows\system32\msgina.dll

                        c:\windows\system32\odbc32.dll

                        c:\windows\system32\comdlg32.dll

                        c:\windows\system32\odbcint.dll

                        c:\program files\adobe\acrobat 7.0\activex\acroiehelper.dll

                        c:\windows\system32\zipfldr.dll

                        c:\windows\system32\wuapi.dll

                        c:\windows\system32\cabinet.dll

                        C:\WINDOWS\SYSTEM32\SVCHOST.EXE
                        c:\windows\system32\svchost.exe

                        c:\windows\system32\ntdll.dll

                        c:\windows\system32\kernel32.dll

                        c:\windows\system32\advapi32.dll

                        c:\windows\system32\rpcrt4.dll

                        c:\windows\system32\shimeng.dll

                        c:\windows\apppatch\acgenral.dll

                        c:\windows\system32\user32.dll

                        c:\windows\system32\gdi32.dll

                        c:\windows\system32\winmm.dll

                        c:\windows\system32\ole32.dll

                        c:\windows\system32\msvcrt.dll

                        c:\windows\system32\oleaut32.dll

                        c:\windows\system32\msacm32.dll

                        c:\windows\system32\version.dll

                        c:\windows\system32\shell32.dll

                        c:\windows\system32\shlwapi.dll

                        c:\windows\system32\userenv.dll

                        c:\windows\system32\uxtheme.dll

                        c:\windows\system32\serwvdrv.dll

                        c:\windows\system32\umdmxfrm.dll

                        c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll

                        c:\windows\system32\comctl32.dll

                        c:\windows\system32\wiaservc.dll

                        c:\windows\system32\cfgmgr32.dll

                        c:\windows\system32\setupapi.dll

                        c:\windows\system32\mscms.dll

                        c:\windows\system32\winspool.drv

                        c:\windows\system32\winsta.dll

                        c:\windows\system32\netapi32.dll

                        c:\windows\system32\xpsp2res.dll

                        c:\windows\system32\clbcatq.dll

                        c:\windows\system32\comres.dll

                        c:\windows\system32\wintrust.dll

                        c:\windows\system32\crypt32.dll

                        c:\windows\system32\msasn1.dll

                        c:\windows\system32\imagehlp.dll

                        c:\windows\system32\actxprxy.dll

                        C:\WINDOWS\SYSTEM32\KEYHOOK.EXE
                        c:\windows\system32\keyhook.exe

                        c:\windows\system32\ntdll.dll

                        c:\windows\system32\kernel32.dll

                        c:\windows\system32\sisapcom.dll

                        c:\windows\system32\ddraw.dll

                        c:\windows\system32\msvcrt.dll

                        c:\windows\system32\user32.dll

                        c:\windows\system32\gdi32.dll

                        c:\windows\system32\dciman32.dll

                        c:\windows\system32\advapi32.dll

                        c:\windows\system32\rpcrt4.dll

                        c:\windows\system32\version.dll

                        c:\windows\system32\sisbase.dll

                        c:\windows\system32\mfc42.dll

                        c:\windows\system32\msvcirt.dll

                        c:\windows\system32\sishook.dll

                        c:\windows\system32\mfc42loc.dll

                        c:\windows\system32\uxtheme.dll

                        c:\windows\system32\msctf.dll

                        c:\program files\logitech\setpoint\lgscroll.dll

                        c:\windows\system32\msvcr71.dll

                        c:\windows\system32\msvcp71.dll

                        C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPENH.EXE
                        c:\program files\synaptics\syntp\syntpenh.exe

                        c:\windows\system32\ntdll.dll

                        c:\windows\system32\kernel32.dll

                        c:\windows\system32\user32.dll

                        c:\windows\system32\gdi32.dll

                        c:\windows\system32\comdlg32.dll

                        c:\windows\system32\shlwapi.dll

                        c:\windows\system32\advapi32.dll

                        c:\windows\system32\rpcrt4.dll

                        c:\windows\system32\msvcrt.dll

                        c:\windows\system32\comctl32.dll

                        c:\windows\system32\shell32.dll

                        c:\windows\system32\ole32.dll

                        c:\windows\system32\oleaut32.dll

                        c:\windows\system32\version.dll

                        c:\windows\system32\winmm.dll

                        c:\windows\system32\shimeng.dll

                        c:\windows\apppatch\acgenral.dll

                        c:\windows\system32\msacm32.dll

                        c:\windows\system32\userenv.dll

                        c:\windows\system32\uxtheme.dll

                        c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll

                        c:\windows\system32\serwvdrv.dll

                        c:\windows\system32\umdmxfrm.dll

                        c:\windows\system32\clbcatq.dll

                        c:\windows\system32\comres.dll

                        c:\windows\system32\syncom.dll

                        c:\windows\system32\syntpapi.dll

                        c:\windows\system32\netapi32.dll

                        c:\windows\system32\setupapi.dll

                        c:\windows\system32\apphelp.dll

                        c:\program files\grisoft\avg anti-spyware 7.5\shellexecutehook.dll

                        c:\windows\system32\urlmon.dll

                        c:\windows\system32\secur32.dll

                        c:\windows\system32\msctf.dll

                        c:\program files\logitech\setpoint\lgscroll.dll

                        c:\windows\system32\msvcr71.dll

                        c:\windows\system32\msvcp71.dll

                        C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPLPR.EXE
                        c:\program files\synaptics\syntp\syntplpr.exe

                        c:\windows\system32\ntdll.dll

                        c:\windows\system32\kernel32.dll

                        c:\windows\system32\user32.dll

                        c:\windows\system32\gdi32.dll

                        c:\windows\system32\advapi32.dll

                        c:\windows\system32\rpcrt4.dll

                        c:\windows\system32\ole32.dll

                        c:\windows\system32\msvcrt.dll

                        c:\windows\system32\version.dll

                        c:\windows\system32\shimeng.dll

                        c:\windows\apppatch\acgenral.dll

                        c:\windows\system32\winmm.dll

                        c:\windows\system32\oleaut32.dll

                        c:\windows\system32\msacm32.dll

                        c:\windows\system32\shell32.dll

                        c:\windows\system32\shlwapi.dll

                        c:\windows\system32\userenv.dll

                        c:\windows\system32\uxtheme.dll

                        c:\windows\system32\serwvdrv.dll

                        c:\windows\system32\umdmxfrm.dll

                        c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll

                        c:\windows\system32\comctl32.dll

                        c:\windows\system32\clbcatq.dll

                        c:\windows\system32\comres.dll

                        c:\windows\system32\syncom.dll

                        c:\windows\system32\msctf.dll

                        c:\program files\logitech\setpoint\lgscroll.dll

                        c:\windows\system32\msvcr71.dll

                        c:\windows\system32\msvcp71.dll

                        C:\WINDOWS\SYSTEM32\RUNDLL32.EXE
                        c:\windows\system32\rundll32.exe

                        c:\windows\system32\ntdll.dll

                        c:\windows\system32\kernel32.dll

                        c:\windows\system32\msvcrt.dll

                        c:\windows\system32\gdi32.dll

                        c:\windows\system32\user32.dll

                        c:\windows\system32\imagehlp.dll

                        c:\windows\system32\shimeng.dll

                        c:\windows\apppatch\acgenral.dll

                        c:\windows\system32\advapi32.dll

                        c:\windows\system32\rpcrt4.dll

                        c:\windows\system32\winmm.dll

                        c:\windows\system32\ole32.dll

                        c:\windows\system32\oleaut32.dll

                        c:\windows\system32\msacm32.dll

                        c:\windows\system32\version.dll

                        c:\windows\system32\shell32.dll

                        c:\windows\system32\shlwapi.dll

                        c:\windows\system32\userenv.dll

                        c:\windows\system32\uxtheme.dll

                        c:\windows\system32\serwvdrv.dll

                        c:\windows\system32\umdmxfrm.dll

                        c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll

                        c:\windows\system32\comctl32.dll

                        c:\windows\system32\sispower.dll

                        c:\windows\system32\powrprof.dll

                        c:\windows\system32\mfc42.dll

                        c:\windows\system32\mfc42loc.dll

                        c:\windows\system32\msctf.dll

                        c:\program files\logitech\setpoint\lgscroll.dll

                        c:\windows\system32\msvcr71.dll

                        c:\windows\system32\msvcp71.dll

                        C:\PROGRA~1\ALWILS~1\AVAST4\ASHDISP.EXE
                        c:\progra~1\alwils~1\avast4\ashdisp.exe

                        c:\windows\system32\ntdll.dll

                        c:\windows\system32\kernel32.dll

                        c:\windows\system32\rpcrt4.dll

                        c:\windows\system32\advapi32.dll

                        c:\progra~1\alwils~1\avast4\aswcmnos.dll

                        c:\windows\system32\user32.dll

                        c:\windows\system32\gdi32.dll

                        c:\windows\system32\msvcp71.dll

                        c:\windows\system32\msvcr71.dll

                        c:\windows\system32\wsock32.dll

                        c:\windows\system32\ws2_32.dll

                        c:\windows\system32\msvcrt.dll

                        c:\windows\system32\ws2help.dll

                        c:\progra~1\alwils~1\avast4\ashbase.dll

                        c:\windows\system32\version.dll

                        c:\windows\system32\ole32.dll

                        c:\windows\system32\oleaut32.dll

                        c:\progra~1\alwils~1\avast4\aswcmnb.dll

                        c:\progra~1\alwils~1\avast4\aswcmns.dll

                        c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll

                        c:\windows\system32\shlwapi.dll

                        c:\progra~1\alwils~1\avast4\ashtask.dll

                        c:\progra~1\alwils~1\avast4\aswaux.dll

                        c:\windows\system32\shell32.dll

                        c:\progra~1\alwils~1\avast4\aavm4h.dll

                        c:\windows\system32\shimeng.dll

                        c:\windows\apppatch\acgenral.dll

                        c:\windows\system32\winmm.dll

                        c:\windows\system32\msacm32.dll

                        c:\windows\system32\userenv.dll

                        c:\windows\system32\uxtheme.dll

                        c:\windows\system32\serwvdrv.dll

                        c:\windows\system32\umdmxfrm.dll

                        c:\windows\system32\dbghelp.dll

                        c:\program files\alwil software\avast4\french\base.dll

                        c:\program files\alwil software\avast4\french\lang.dll

                        c:\windows\system32\mfc71.dll

                        c:\progra~1\alwils~1\avast4\aavmrpch.dll

                        c:\program files\alwil software\avast4\ahruimai.dll

                        c:\progra~1\alwils~1\avast4\ashuint.dll

                        c:\progra~1\alwils~1\avast4\xt1922.dll

                        c:\program files\alwil software\avast4\ahruimes.dll

                        c:\program files\alwil software\avast4\ahruins.dll

                        c:\program files\alwil software\avast4\ahruiout.dll

                        c:\windows\system32\mapi32.dll

                        c:\program files\alwil software\avast4\ahruip2p.dll

                        c:\program files\alwil software\avast4\ahruistd.dll

                        c:\program files\alwil software\avast4\ahruiws.dll

                        c:\windows\system32\msctf.dll

                        c:\windows\system32\secur32.dll

                        c:\program files\logitech\setpoint\lgscroll.dll

                        C:\WINDOWS\SYSTEM32\RUNDLL32.EXE
                        c:\windows\system32\rundll32.exe

                        c:\windows\system32\ntdll.dll

                        c:\windows\system32\kernel32.dll

                        c:\windows\system32\msvcrt.dll

                        c:\windows\system32\gdi32.dll

                        c:\windows\system32\user32.dll

                        c:\windows\system32\imagehlp.dll

                        c:\windows\system32\shimeng.dll

                        c:\windows\apppatch\acgenral.dll

                        c:\windows\system32\advapi32.dll

                        c:\windows\system32\rpcrt4.dll

                        c:\windows\system32\winmm.dll

                        c:\windows\system32\ole32.dll

                        c:\windows\system32\oleaut32.dll

                        c:\windows\system32\msacm32.dll

                        c:\windows\system32\version.dll

                        c:\windows\system32\shell32.dll

                        c:\windows\system32\shlwapi.dll

                        c:\windows\system32\userenv.dll

                        c:\windows\system32\uxtheme.dll

                        c:\windows\system32\serwvdrv.dll

                        c:\windows\system32\umdmxfrm.dll

                        c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll

                        c:\windows\system32\comctl32.dll

                        c:\windows\system32\bthprops.cpl

                        c:\windows\system32\devmgr.dll

                        c:\windows\system32\setupapi.dll

                        c:\windows\system32\wmi.dll

                        c:\windows\system32\mpr.dll

                        c:\windows\system32\wintrust.dll

                        c:\windows\system32\crypt32.dll

                        c:\windows\system32\msasn1.dll

                        c:\windows\system32\msctf.dll

                        c:\program files\logitech\setpoint\lgscroll.dll

                        c:\windows\system32\msvcr71.dll

                        c:\windows\system32\msvcp71.dll

                        C:\PROGRAM FILES\GRISOFT\AVG ANTI-SPYWARE 7.5\AVGAS.EXE
                        c:\program files\grisoft\avg anti-spyware 7.5\avgas.exe

                        c:\windows\system32\ntdll.dll

                        c:\windows\system32\kernel32.dll

                        c:\windows\system32\psapi.dll

                        c:\windows\system32\shlwapi.dll

                        c:\windows\system32\advapi32.dll

                        c:\windows\system32\rpcrt4.dll

                        c:\windows\system32\gdi32.dll

                        c:\windows\system32\user32.dll

                        c:\windows\system32\msvcrt.dll

                        c:\program files\grisoft\avg anti-spyware 7.5\engine.dll

                        c:\windows\system32\shfolder.dll

                        c:\windows\system32\winmm.dll

                        c:\windows\system32\msimg32.dll

                        c:\windows\system32\comdlg32.dll

                        c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll

                        c:\windows\system32\shell32.dll

                        c:\windows\system32\ole32.dll

                        c:\windows\system32\wsock32.dll

                        c:\windows\system32\ws2_32.dll

                        c:\windows\system32\ws2help.dll

                        c:\windows\system32\version.dll

                        c:\windows\system32\shimeng.dll

                        c:\windows\apppatch\acgenral.dll

                        c:\windows\system32\oleaut32.dll

                        c:\windows\system32\msacm32.dll

                        c:\windows\system32\userenv.dll

                        c:\windows\system32\uxtheme.dll

                        c:\windows\system32\serwvdrv.dll

                        c:\windows\system32\umdmxfrm.dll

                        c:\windows\system32\msctf.dll

                        c:\windows\system32\apphelp.dll

                        c:\windows\system32\clbcatq.dll

                        c:\windows\system32\comres.dll

                        c:\windows\system32\cscui.dll

                        c:\windows\system32\cscdll.dll

                        c:\windows\system32\setupapi.dll

                        c:\windows\system32\linkinfo.dll

                        c:\windows\system32\ntshrui.dll

                        c:\windows\system32\atl.dll

                        c:\windows\system32\netapi32.dll

                        c:\windows\system32\shdocvw.dll

                        c:\windows\system32\crypt32.dll

                        c:\windows\system32\msasn1.dll

                        c:\windows\system32\cryptui.dll

                        c:\windows\system32\wintrust.dll

                        c:\windows\system32\imagehlp.dll

                        c:\windows\system32\wininet.dll

                        c:\windows\system32\wldap32.dll

                        c:\windows\system32\ntmarta.dll

                        c:\windows\system32\samlib.dll

                        c:\program files\logitech\setpoint\lgscroll.dll

                        c:\windows\system32\msvcr71.dll

                        c:\windows\system32\msvcp71.dll

                        c:\windows\system32\mswsock.dll

                        c:\windows\system32\hnetcfg.dll

                        c:\windows\system32\wshtcpip.dll

                        c:\windows\system32\dnsapi.dll

                        c:\windows\system32\winrnr.dll

                        c:\windows\system32\wshbth.dll

                        c:\windows\system32\rasadhlp.dll

                        C:\WINDOWS\SYSTEM32\CTFMON.EXE
                        c:\windows\system32\ctfmon.exe

                        c:\windows\system32\ntdll.dll

                        c:\windows\system32\kernel32.dll

                        c:\windows\system32\msvcrt.dll

                        c:\windows\system32\advapi32.dll

                        c:\windows\system32\rpcrt4.dll

                        c:\windows\system32\user32.dll

                        c:\windows\system32\gdi32.dll

                        c:\windows\system32\msctf.dll

                        c:\windows\system32\msutb.dll

                        c:\windows\system32\shimeng.dll

                        c:\windows\apppatch\acgenral.dll

                        c:\windows\system32\winmm.dll

                        c:\windows\system32\ole32.dll

                        c:\windows\system32\oleaut32.dll

                        c:\windows\system32\msacm32.dll

                        c:\windows\system32\version.dll

                        c:\windows\system32\shell32.dll

                        c:\windows\system32\shlwapi.dll

                        c:\windows\system32\userenv.dll

                        c:\windows\system32\uxtheme.dll

                        c:\windows\system32\serwvdrv.dll

                        c:\windows\system32\umdmxfrm.dll

                        c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll

                        c:\program files\logitech\setpoint\lgscroll.dll

                        c:\windows\system32\msvcr71.dll

                        c:\windows\system32\msvcp71.dll

                        C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHMAISV.EXE
                        c:\program files\alwil software\avast4\ashmaisv.exe

                        c:\windows\system32\ntdll.dll

                        c:\windows\system32\kernel32.dll

                        c:\windows\system32\wsock32.dll

                        c:\windows\system32\ws2_32.dll

                        c:\windows\system32\msvcrt.dll

                        c:\windows\system32\ws2help.dll

                        c:\windows\system32\advapi32.dll

                        c:\windows\system32\rpcrt4.dll

                        c:\program files\alwil software\avast4\ashbase.dll

                        c:\windows\system32\version.dll

                        c:\windows\system32\user32.dll

                        c:\windows\system32\gdi32.dll

                        c:\windows\system32\ole32.dll

                        c:\windows\system32\oleaut32.dll

                        c:\windows\system32\msvcp71.dll

                        c:\windows\system32\msvcr71.dll

                        c:\program files\alwil software\avast4\aswcmnos.dll

                        c:\program files\alwil software\avast4\aswcmnb.dll

                        c:\program files\alwil software\avast4\aswcmns.dll

                        c:\windows\system32\comctl32.dll

                        c:\program files\alwil software\avast4\aavm4h.dll

                        c:\program files\alwil software\avast4\ashtask.dll

                        c:\program files\alwil software\avast4\aswaux.dll

                        c:\windows\system32\shell32.dll

                        c:\windows\system32\shlwapi.dll

                        c:\program files\alwil software\avast4\ahresmai.dll

                        c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll

                        c:\windows\system32\dbghelp.dll

                        c:\program files\alwil software\avast4\french\base.dll

                        c:\program files\alwil software\avast4\aswengin.dll

                        c:\program files\alwil software\avast4\aswscan.dll

                        c:\windows\system32\mswsock.dll

                        c:\windows\system32\dnsapi.dll

                        c:\windows\system32\winrnr.dll

                        c:\windows\system32\wldap32.dll

                        c:\windows\system32\wshbth.dll

                        c:\windows\system32\setupapi.dll

                        c:\windows\system32\rasadhlp.dll

                        c:\program files\alwil software\avast4\ashuint.dll

                        c:\program files\alwil software\avast4\xt1922.dll

                        c:\windows\system32\mfc71.dll

                        c:\windows\system32\riched20.dll

                        c:\program files\alwil software\avast4\french\lang.dll

                        c:\windows\system32\uxtheme.dll

                        c:\program files\alwil software\avast4\french\langmai.dll

                        c:\windows\system32\psapi.dll

                        c:\windows\system32\hnetcfg.dll

                        c:\windows\system32\wshtcpip.dll

                        C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHWEBSV.EXE
                        c:\program files\alwil software\avast4\ashwebsv.exe

                        c:\windows\system32\ntdll.dll

                        c:\windows\system32\kernel32.dll

                        c:\windows\system32\ws2_32.dll

                        c:\windows\system32\msvcrt.dll

                        c:\windows\system32\ws2help.dll

                        c:\windows\system32\advapi32.dll

                        c:\windows\system32\rpcrt4.dll

                        c:\program files\alwil software\avast4\ashbase.dll

                        c:\windows\system32\wsock32.dll

                        c:\windows\system32\version.dll

                        c:\windows\system32\user32.dll

                        c:\windows\system32\gdi32.dll

                        c:\windows\system32\ole32.dll

                        c:\windows\system32\oleaut32.dll

                        c:\windows\system32\msvcp71.dll

                        c:\windows\system32\msvcr71.dll

                        c:\program files\alwil software\avast4\aswcmnos.dll

                        c:\program files\alwil software\avast4\aswcmnb.dll

                        c:\program files\alwil software\avast4\aswcmns.dll

                        c:\windows\system32\comctl32.dll

                        c:\program files\alwil software\avast4\aavm4h.dll

                        c:\program files\alwil software\avast4\ashtask.dll

                        c:\program files\alwil software\avast4\aswaux.dll

                        c:\windows\system32\shell32.dll

                        c:\windows\system32\shlwapi.dll

                        c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll

                        c:\windows\system32\dbghelp.dll

                        c:\program files\alwil software\avast4\french\base.dll

                        c:\windows\system32\psapi.dll

                        c:\windows\system32\mswsock.dll

                        c:\windows\system32\hnetcfg.dll

                        c:\windows\system32\wshtcpip.dll

                        c:\windows\system32\security.dll

                        c:\windows\system32\secur32.dll

                        c:\program files\alwil software\avast4\ashwsftr.dll

                        c:\program files\alwil software\avast4\aswscan.dll

                        c:\windows\system32\oleacc.dll

                        c:\windows\system32\msvcp60.dll

                        c:\windows\system32\winspool.drv

                        c:\progra~1\alwils~1\avast4\ahresws.dll

                        c:\program files\alwil software\avast4\aswengin.dll

                        C:\WINDOWS\SYSTEM32\ALG.EXE
                        c:\windows\system32\alg.exe

                        c:\windows\system32\ntdll.dll

                        c:\windows\system32\kernel32.dll

                        c:\windows\system32\msvcrt.dll

                        c:\windows\system32\atl.dll

                        c:\windows\system32\user32.dll

                        c:\windows\system32\gdi32.dll

                        c:\windows\system32\advapi32.dll

                        c:\windows\system32\rpcrt4.dll

                        c:\windows\system32\ole32.dll

                        c:\windows\system32\oleaut32.dll

                        c:\windows\system32\wsock32.dll

                        c:\windows\system32\ws2_32.dll

                        c:\windows\system32\ws2help.dll

                        c:\windows\system32\mswsock.dll

                        c:\windows\system32\shimeng.dll

                        c:\windows\apppatch\acgenral.dll

                        c:\windows\system32\winmm.dll

                        c:\windows\system32\msacm32.dll

                        c:\windows\system32\version.dll

                        c:\windows\system32\shell32.dll

                        c:\windows\system32\shlwapi.dll

                        c:\windows\system32\userenv.dll

                        c:\windows\system32\uxtheme.dll

                        c:\windows\system32\serwvdrv.dll

                        c:\windows\system32\umdmxfrm.dll

                        c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll

                        c:\windows\system32\comctl32.dll

                        c:\windows\system32\clbcatq.dll

                        c:\windows\system32\comres.dll

                        c:\windows\system32\xpsp2res.dll

                        c:\windows\system32\hnetcfg.dll

                        c:\windows\system32\wshtcpip.dll

                        C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE
                        c:\program files\msn messenger\msnmsgr.exe

                        c:\windows\system32\ntdll.dll

                        c:\windows\system32\kernel32.dll

                        c:\windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.163_x-ww_681e29fb\msvcr80.dll

                        c:\windows\system32\msvcrt.dll

                        c:\windows\system32\advapi32.dll

                        c:\windows\system32\rpcrt4.dll

                        c:\windows\system32\gdi32.dll

                        c:\windows\system32\user32.dll

                        c:\windows\system32\wsock32.dll

                        c:\windows\system32\ws2_32.dll

                        c:\windows\system32\ws2help.dll

                        c:\windows\system32\shell32.dll

                        c:\windows\system32\shlwapi.dll

                        c:\windows\system32\ole32.dll

                        c:\windows\system32\oleaut32.dll

                        c:\windows\system32\msimg32.dll

                        c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.2600.2180_x-ww_522f9f82\gdiplus.dll

                        c:\program files\msn messenger\msncore.dll

                        c:\windows\system32\wininet.dll

                        c:\windows\system32\crypt32.dll

                        c:\windows\system32\msasn1.dll

                        c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll

                        c:\windows\system32\uxtheme.dll

                        c:\windows\system32\imm32.dll

                        c:\windows\system32\version.dll

                        c:\wind
                        1. salut web66, tu est bien matinal.
                          j'ai pas trés bien compris, je dois scanné l'ordi avec la restauration désactivé ou je la réactive avant??
                          sinon téléchargement réussi
                          1. bonjour yao49,

                            on continue,
                            Fais ceci:
                            tapes ceci dans Démarrer/Exécuter:
                            %SystemRoot%\System32\restore\rstrui.exe
                            Paramètres de restauration/Désactivé la restauration sur tous les lecteurs.
                            Reboot.
                            Ensuite refais l'inverse, réactive.

                            comment faire :

                            ¤Désactive ta restauration système:
                            Clic droit sur poste de travail puis,
                            propriété, tu clique sur onglet restauration système
                            tu coche la case désactiver la restauration et applique

                            puis :

                            telecharge et fais marcher ceci :

                            ad aware

                            tutoriel :

                            http://usa.lucretius-ada.com/zcvisitor/8782d344-4821-11ea-83ce-0a2cdf2c6be7?campaignid=0d1dff40-82d7-11e9-9533-0a157bfa6bfc

                            post le rapport si posible ou dis moi ce qu´il a detecté et si il a supprimé les infections
                            1. sinon j'ai ça dans results

                              File/Folder C:\WINDOWS\system32\vp6vsccb.dll not found.
                              File/Folder C:\WINDOWS\system32\umanwiav.dll not found.
                              File/Folder C:\WINDOWS\sys_rsc.exe -s not found.

                              Created on 09/03/2007 00:19:12
                              1. j'ai téléchargé et exécuté OTmoveIT, mais il n'enregistre pas le rapport il dit:
                                "cannot create file C:\_OTmoveIT\moved files 09032007_001912.log."
                                1. re

                                  * lance hijackthis puis coche :

                                  O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                                  O4 - HKCU\..\Run: [SUPERC~1.EXE] C:\PROGRA~1\SUPERC~1\SUPERC~1.EXE
                                  O4 - HKCU\..\Run: [fsc-reminder.exe] C:\WINDOWS\reminder\fsc-reminder.exe 2453603 14
                                  O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe (file missing)
                                  O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe (file missing

                                  * ferme toutes les applications ouvertes y compris Internet Explorer et clique sur "fixer objet"

                                  puis

                                  Télécharge OTMoveIt (de Old_Timer) sur ton Bureau.
                                  http://download.bleepingcomputer.com/oldtimer/OTMoveIt.exe

                                  double-clique sur OTMoveIt.exe pour le lancer.
                                  copie la liste qui se trouve en citation ci-dessous,
                                  et colle-la dans le cadre de gauche de OTMoveIt :Paste List of Files/Folders to be moved.

                                  C:\WINDOWS\system32\vp6vsccb.dll
                                  C:\WINDOWS\system32\umanwiav.dll
                                  C:\WINDOWS\sys_rsc.exe -s

                                  clique sur MoveIt! pour lancer la suppression.
                                  le résultat apparaitra dans le cadre Results.
                                  clique sur Exit pour fermer.
                                  poste le rapport situé dans C:\_OTMoveIt\MovedFiles.

                                  il te sera peut-être demander de redémarrer le pc pour achever la suppression.
                                  si c'est le cas accepte par Yes.

                                  * relance AVG AS pour un scan complet, action ----------quarantaine.
                                  tu reposteras le rapport ainsi qu'un nouveau rapport hijackthis + celui d'OTMoveIt
                                  1. voilà ce que tu veut

                                    Logfile of HijackThis v1.99.1
                                    Scan saved at 13:48:11, on 02/09/2007
                                    Platform: Windows XP SP2 (WinNT 5.01.2600)
                                    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

                                    Running processes:
                                    C:\WINDOWS\System32\smss.exe
                                    C:\WINDOWS\system32\csrss.exe
                                    C:\WINDOWS\system32\winlogon.exe
                                    C:\WINDOWS\system32\services.exe
                                    C:\WINDOWS\system32\lsass.exe
                                    C:\WINDOWS\system32\svchost.exe
                                    C:\WINDOWS\system32\svchost.exe
                                    C:\WINDOWS\System32\svchost.exe
                                    C:\WINDOWS\system32\svchost.exe
                                    C:\WINDOWS\system32\svchost.exe
                                    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                    C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                    C:\WINDOWS\system32\spoolsv.exe
                                    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                                    C:\WINDOWS\system32\svchost.exe
                                    C:\WINDOWS\system32\cisvc.exe
                                    C:\WINDOWS\system32\slserv.exe
                                    C:\WINDOWS\system32\svchost.exe
                                    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                                    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                                    C:\WINDOWS\System32\alg.exe
                                    C:\WINDOWS\system32\keyhook.exe
                                    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                                    C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
                                    C:\WINDOWS\system32\Rundll32.exe
                                    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                                    C:\WINDOWS\system32\rundll32.exe
                                    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
                                    C:\PROGRA~1\SUPERC~1\SUPERC~1.EXE
                                    C:\WINDOWS\system32\ctfmon.exe
                                    C:\Program Files\MSN Messenger\msnmsgr.exe
                                    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                                    C:\Program Files\Messenger\msmsgs.exe
                                    C:\Program Files\Logitech\SetPoint\SetPoint.exe
                                    C:\Program Files\Fichiers communs\Logitech\KHAL\KHALMNPR.EXE
                                    C:\Program Files\MSN Messenger\usnsvc.exe
                                    C:\WINDOWS\system32\cidaemon.exe
                                    C:\WINDOWS\explorer.exe
                                    C:\Program Files\Internet Explorer\IEXPLORE.EXE
                                    C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
                                    C:\Program Files\MSN Messenger\livecall.exe
                                    C:\Program Files\Hijackthis Version Française\VERSION TRADUITE ORIGINALE.EXE

                                    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.free.fr/freebox/index.html
                                    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/
                                    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                                    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                                    O2 - BHO: e-Carte Bleue Browser Helper Object - {2E03C0FD-4C48-43A7-9A54-00240C70FF16} - C:\WINDOWS\system32\BhoECart.dll
                                    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                                    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                                    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                                    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
                                    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                                    O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\system32\keyhook.exe
                                    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
                                    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                                    O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
                                    O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
                                    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                                    O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
                                    O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
                                    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
                                    O4 - HKCU\..\Run: [SUPERC~1.EXE] C:\PROGRA~1\SUPERC~1\SUPERC~1.EXE
                                    O4 - HKCU\..\Run: [fsc-reminder.exe] C:\WINDOWS\reminder\fsc-reminder.exe 2453603 14
                                    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                                    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
                                    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                                    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                                    O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
                                    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
                                    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                                    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                                    O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe (file missing)
                                    O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe (file missing)
                                    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                    O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
                                    O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
                                    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
                                    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
                                    O20 - Winlogon Notify: OdysseyClient - C:\WINDOWS\
                                    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
                                    O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
                                    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                    O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
                                    O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
                                    O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                                    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                    O23 - Service: Norman ZANDA - Unknown owner - C:\Norman\NVC\BIN\Zanda.exe (file missing)
                                    O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
                                    • 1
                                    • 2