Virtumonde

Bonjour,je crois que je suis infecté par virtumonde.Quelqu'un peut il vérifier mon hijack?j'ai téléchargé vundofix.exe

Logfile of HijackThis v1.99.1
Scan saved at 17:02:24, on 02/10/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Fichiers communs\Logitech\QCDriver3\LVCOMS.EXE
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
C:\Program Files\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
C:\Program Files\MSI\BToes Logiciel Bluetooth\bin\btwdins.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Hummingbird\Connectivity\11.00\NFS Maestro\HumGSS.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\Creative\Creative Media Lite\CTZDetec.exe
C:\Program Files\MSI\BToes Logiciel Bluetooth\BTTray.exe
C:\Program Files\Creative\Shared Files\CTDevSrv.exe
C:\WINDOWS\system32\Hummingbird\Connectivity\11.00\NFS Maestro\expserv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Downloads\eMule0.48a\emule.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Winamp\winamp.exe
C:\PROGRA~1\Mozilla Firefox\firefox.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Antipub\antipub.exe
C:\Documents and Settings\steven\Bureau\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.neuf.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://home.neuf.fr
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DXM6Patch_981116] C:\WINDOWS\p_981116.exe /Q:A
O4 - HKLM\..\Run: [LVComs] C:\Program Files\Fichiers communs\Logitech\QCDriver3\LVCOMS.EXE
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [USB2Check] RUNDLL32.EXE "C:\WINDOWS\system32\PCLECoInst.dll",CheckUSBController
O4 - HKLM\..\Run: [USBToolTip] "C:\Program Files\Pinnacle\Shared Files\\Programs\USBTip\USBTip.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [LogitechGalleryRepair] C:\Program Files\Logitech\ImageStudio\ISStart.exe
O4 - HKLM\..\Run: [LogitechImageStudioTray] C:\Program Files\Logitech\ImageStudio\LogiTray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [NFSUserSIDGSSLink] C:\Program Files\Hummingbird\Connectivity\11.00\NFS Maestro\HumGSS.exe REG
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [Gadwin PrintScreen 3.1] C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe /nosplash
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - HKCU\..\Run: [CTZDetec.exe] C:\Program Files\Creative\Creative Media Lite\CTZDetec.exe
O4 - HKCU\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE
O4 - Startup: Anti-Pub.lnk = C:\Program Files\Antipub\antipub.exe
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Envoyer à &Bluetooth - C:\Program Files\MSI\BToes Logiciel Bluetooth\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: BitComet Search - {461CC20B-FB6E-4f16-8FE8-C29359DB100E} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.8.30.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\MSI\BToes Logiciel Bluetooth\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\MSI\BToes Logiciel Bluetooth\btsendto_ie.htm
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst20040510.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.mail.live.com/mail/w1/resources/MSNPUpld.cab
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - http://drivers1.free.fr/telecharger.php?id=2&version=
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O21 - SSODL: gimmicks - {40dcff6e-af8d-4183-8ebe-a82270ac449e} - (no file)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - ATI Technologies Inc. - (no file)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG7 Resident Shield Service (AvgCoreSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: AVG Firewall (AVGFwSrv) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgfwsrv.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\MSI\BToes Logiciel Bluetooth\bin\btwdins.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: CT Device Query service (CTDevice_Srv) - Creative Technology Ltd - C:\Program Files\Creative\Shared Files\CTDevSrv.exe
O23 - Service: Hummingbird Export (HCLExport) - Hummingbird Ltd. - C:\WINDOWS\system32\Hummingbird\Connectivity\11.00\NFS Maestro\expserv.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: MSSQL$PINNACLESYS - Unknown owner - C:\Program Files\Pinnacle\MediaServer\Microsoft SQL Server\MSSQL$PINNACLESYS\Binn\sqlservr.exe" -sPINNACLESYS (file missing)
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Pinnacle Systems Media Service (PinnacleSys.MediaServer) - Pinnacle Systems - c:\program files\pinnacle\shared files\programs\mediaserver\pmshost.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SQLAgent$PINNACLESYS - Unknown owner - C:\Program Files\Pinnacle\MediaServer\Microsoft SQL Server\MSSQL$PINNACLESYS\Binn\sqlagent.EXE" -i PINNACLESYS (file missing)
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\SSScsiSV.exe
Configuration: Windows XP
Firefox 2.0.0.7

49 réponses

Résumé de la discussion

Question relève une suspicion d'infection par Virtumonde et demande une vérification du hijack et des symptômes observés après l'exécution de vundofix.exe sur un PC Windows XP SP2. Plusieurs éléments du log HijackThis et des services listés indiquent des programmes légitimes et des composants potentiellement indésirables, notamment des entrées de démarrage et des connexions associées à Yahoo et BitComet. D'autres éléments décrivent des nettoyages en mode sans échec, des scripts de suppression et l'utilisation d'OTMoveIt pour nettoyer les outils suspects. En cas de vérification, les rapports VirusTotal pour les fichiers analysés affichent des détections mixtes et une certitude limitée, suggérant la nécessité d'une analyse approfondie et de nettoyages ciblés.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    Salut Steven,

    Non, je ne vois rien de spécial.
    Il faut que soit bien configuré ton BitDefender Antivirus Plus v10
    Tu dois l'aider à faire son "apprentissage" ==> il ne reconnait pas certains outils que nous utilisons ==> c'est donc à toi d'autoriser ces applications pour ne pas que BitDefender Antivirus Plus v10 te les bloque.

    Fais un nettoyage de ces outils comme ceci:

    A)- Supprimer les outils utilisés devenus inutiles, ainsi que les quarantaines éventuelles; comme ceci:
    •- Clique sur "Démarrer" - Clic droit sur le "Poste de Travail" > dans "Propriétés" > onglet "Restauration du système" - Cocher la case "Désactiver la restauration du système" et cliquer sur "Appliquer".
    •- Télécharger _OTMoveIt sur ton bureau > < http://download.bleepingcomputer.com/oldtimer/OTMoveIt.exe >
    •- Lance OTMoveIt.exe par double-clic
    [*]Clique sur CleanUp! (le programme va télécharger un fichier texte qui servira à nettoyer les programmes que l'on a téléchargés).
    NOTE : Normalement, ton Firewall (parefeu) devrait te demander si _OTMoveIt peut accéder à Internet. Autorise-le.
    [*]Une liste apparaît dans la partie gauche d' _OTMoveIt.
    [*]Un message apparaît pour confirmer le nettoyage. Confirme
    Ce programme supprime les outils utilisés ainsi que les quarantaines éventuelles.
    •- Clique sur "Démarrer" - Clic droit sur le "Poste de Travail" > dans "Propriétés" > onglet "Restauration du système" - Décocher la case "Désactiver la restauration du système" et cliquer sur "Appliquer".

    La manoeuvre nécessitera un reboot (=redémarrage) initié par le programme.

    Et si DrWeb subsiste encore, tu peux le supprimer manuellement.

    Bonne continuation
    Al.

    1. bonsoir albert,
      voici le rapport Dr Web:

      pskill.exe C:\Documents and Settings\steven\Bureau\clean Tool.ProcessKill.7 Irréparable.Quarantaine.
      Fport.exe C:\Documents and Settings\steven\Bureau\DiagHelp\DiagHelp Program.FPort.20 Irréparable.Quarantaine.
      pslist.exe C:\Documents and Settings\steven\Bureau\DiagHelp\DiagHelp Program.PsList.126 Irréparable.Quarantaine.
      Process.exe C:\Documents and Settings\steven\Bureau\SmitfraudFix Tool.Prockill Irréparable.Quarantaine.
      restart.exe C:\Documents and Settings\steven\Bureau\SmitfraudFix Tool.ShutDown.11 Irréparable.Quarantaine.
      LIU_PROD.dll C:\Program Files\Fichiers communs\Logitech\Internet Update Adware.SmartShow.origin Irréparable.Quarantaine.
      Process.exe C:\Program Files\Navilog1 Tool.Prockill Irréparable.Quarantaine.
      A0001102.exe C:\System Volume Information\_restore{98890A81-76DE-4A2B-AACA-E063DE298DBF}\RP1 Tool.Prockill Irréparable.Quarantaine.

      a++
      1. Contributeur sécurité
        Bonsoir Steven

        Essaie de faire ceci complètement SVP :
        (je vais maintenant au lit, à+..)

        Télécharge DrWeb
        ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe
        La version est automatiquement à jour.
        Installe le.
        ==> branche les USB et Disque dur externes .

        Ensuite clique sur « cureit.exe » http://img210.imageshack.us/img210/3301/screenshot137xp7.png pour commencer le scan.

        • Clique Ok à l'invite de l'analyse rapide. Ce scan permet l'analyse des processus chargés en mémoire ; s'il trouve des processus infectés, clique le bouton Oui pour tout à l'invite.
        **Note : une fenêtre s'ouvrira avec options pour "Commander" ou "50% de réduction" ; clique sur le "X" pour fermer la fenêtre

        • Lorsque le scan rapide est terminé, Clique sur le menu Options >> Changer la configuration;
        • Choisis l'onglet "Scanner", et décoche "Analyse heuristique". Clique sur "Ok"
        • De retour à la fenêtre principale : clique sur le bouton radio "Analyse complète".
        • Clique sur la flèche verte sur la droite, et le scan débutera.
        • Clique Oui pour tout à l'invite "Désinfecter ?" lorsqu'un fichier est détecté, et ensuite clique sur "Désinfecter".

        • Lorsque le scan sera complété, regarde si tu peux cliquer sur cette icône, adjacente aux fichiers détectés : http://img230.imageshack.us/img230/8729/screenshot138yh4.png
        • Si oui, alors clique dessus et ensuite clique sur l'icône "Suivant", au dessous, et choisis Déplacer en quarantaine l'objet indésirable

        • Du menu principal de l'outil, au haut à gauche, clique sur le menu Fichier et choisis Enregistrer le rapport
        • Sauvegarde le rapport sur ton Bureau. Ce dernier se nommera DrWeb.csv
        • Ferme Dr.Web Cureit
        •
        • Redémarre ton ordi (*très important*), car certains fichiers peuvent être déplacés/réparés au redémarrage.
        • Suite au redémarrage, poste (Copie/Colle) le contenu du rapport de l'outil Dr.Web dans ta prochaine réponse.

        Bonne chance
        Al.

        1. bonsoir afideg,

          le problème a lieu lorsque j'ouvre la fenêtre de la partition D:\ de mon disque dur.

          a+++
          1. Contributeur sécurité
            Bonjour vinoth91

            Cit. « J'ai un autre souci,lorsque j'ouvre certaines fenêtres windows j'ai ce message qui apparaît : "Pour protéger votre ordinateur,Windows a fermé ce programme". Ca vient de l'explorateur windows. Je ferme le message et ensuite la fenêtre se ferme.C'est assez embêtant et je pense que c'est lié aux infections qui étaient présentes sur le PC. Qu'en pense tu? »

            « ... lorsque j'ouvre certaines fenêtres windows ... »

            Peux-tu refaire l'essai et me dire avec quelles fenêtre Windows cela arrive?

            Merci
            Al
            1. Contributeur sécurité
              (suite)

              A)- Cit. « J'ai un autre souci,lorsque j'ouvre certaines fenêtres windows j'ai ce message qui apparaît : "Pour protéger votre ordinateur,Windows a fermé ce programme". Ca vient de l'explorateur windows. Je ferme le message et ensuite la fenêtre se ferme.C'est assez embêtant et je pense que c'est lié aux infections qui étaient présentes sur le PC. Qu'en pense tu? »

              Je ne sais pas.
              Mais il me semble que ton <gras>BitDefender Antivirus Plus v10 est la version payante (Payer ± 40 €/an est le meilleur choix), donc protection totale</gras>. (J'ai Kaspersky Internet Security) .
              Ce qui signifie que le pare-feu Windows devrait être désactivé.
              Vérifie-le comme ceci: clique sur [Démarrer], puis sur "Panneau de configuration" et là, ouvre le "Centre de sécurité" (icône du bouclier) comme ceci : clic-droit puis "Ouvrir" dans le petit menu contextuel affiché.
              Assure-toi que le pare-feu est désactivé comme ceci < http://img337.imageshack.us/img337/2798/screenshot115oe8.png >
              Je vais me renseigner pour en connaître d'autres causes.

              B)- Cit. « ... pour éviter que les autres utilisateurs ... »

              C'est bien pourquoi je te proposais de passer par le planificateur de tâches; comme ceci : "Démarrer" > "Panneau de configuration" -> Tâches planifiées > Ouvrir > Clic-droit sur "Création d'une tâche planifiée > Ouvrir > Suivant > Parcourir > Recherche ATF-Cleaner.exe (là où tu l'as téléchargé) > etc .....selon ton souhait.

              ===> c'est-à-dire que c'est toi seul qui sais où tu l'as installé dans ton PC.
              Regarde ici; chez moi, ATF-Cleaner est installé sur le bureau (ce n'est pas un raccourci).
              Donc tu recherches l'exécutable comme tu le ferais avec VirusTotal, ou avec l'explorateur Windows, ou avec un hébergeur de captures d'écran.
              Après quoi tu cliques [Ouvrir] et tu remplis le formulaire .....selon ton souhait de planification.

              Bon W-E
              Avec une petite pensée pour Lineve26.
              Bonne chance
              Al.
              1. bonsoir afideg,

                A)Oui j'ai supprimé spywaresecure_trial comme tu me l'avais indiqué,j'ai relancé jv16 pour voir si il était encore dans le registre: il n'y est plus.

                B) Moi j'y penserais à faire le nettoyage mais les autres utilisateurs du PC... ATF-cleaner.exe n'apparaît pas dans le planificateur de tâches.

                C)Ce qui s'est passé c'est qu'au post 30 tu m'avais demandé de "démasquer" les fichiers cachés pour une manip. Après la manip,pour éviter que les autres utilisateurs n'effacent de fichiers systèmes, je les ai "masqués".C'est pourquoi je ne voyais pas le RECYCLER. NON je n'ai pas utilisé le MSE pour le trouver. Je savais que dans chaque dossier il y a une sorte de corbeille en fichier caché (ça fait partir des certaines choses que je connais dans windows) mais je ne savais pas que c'était le RECYCLER dont tu me parlais. Ces poubelles sont toujours cachées (réglage par défaut), à mon avis c'est pas le genre de dossier comme "program files" que l'utilisateur "lambda" doit voir.

                D) (sauf si tu me l'impose)==> J'ai un peu hésité avant de l'écrire cette parenthèse, je me doutais que j'aurai le droit à un paragraphe en retour. Le mot "suggère" correspond mieux en effet.
                Ok je vais l'essayer l'AVG anti-spyware. le "Ad-watch" qui tourne en permanence, c'est vrai qu'il fait ramer le PC,je vais le désactiver.
                Je ferais l'analyse plus tard.

                E) C'est bon l'analyse est faite.

                J'ai un autre souci,lorsque j'ouvre certaines fenêtres windows j'ai ce message qui apparaît : "Pour protéger votre ordinateur,Windows a fermé ce programme". Ca vient de l'explorateur windows. Je ferme le message et ensuite la fenêtre se ferme.C'est assez embêtant et je pense que c'est lié aux infections qui étaient présentes sur le PC. Qu'en pense tu?

                "Merci pour ta collaboration" ==> merci à toi surtout de me consacrer de ton temps sachant que t'as une famille. C'est à toi que revient tout le mérite d'avoir nettoyé mon PC,je n'ai qu'appliquer tes consignes.

                Bon weekend à toi cordialement,
                steven
                1. Contributeur sécurité
                  Bonsoir vinoth91,

                  A)- Cit. « oui j'ai appliqué la procédure pour supprimer spyware trial. SpywareSecure_trial a été installé à mon insu. »

                  L'as-tu bien supprimé à l'aide de la procédure indiquée au post # 32 § 4° A)- , s'il te plaît?

                  B)- Attention:
                  Je vois encore de trop nombreux cookies dans l'analyse d' Ad-Aware 2007

                  Il faut que tu adoptes le réflexe de supprimer chaque jour à la sortie de session les fichiers inutiles .
                  Je le fais avec ATF-Cleaner comme indiqué au post # 32 § 3°-
                  Mais le lien pour le tuto n'avait pas été mis à jour; il faut le remplacer par un de ceux-ci:
                  < http://mickael.barroux.free.fr/securite/atf_cleaner.php >
                  < http://www.dualforum.com/viewtopic15681.html >
                  < http://www.infos-du-net.com/forum/272638-11-nettoyer-cleaner >.

                  Ou alors, tu vas dans le planificateur de tâches; comme ceci : Panneau de configuration -> Tâches planifiées > Ouvrir > Clic-droit sur "Création d'une tâche planifiée > Ouvrir > Suivant > Parcourir > Recherche ATF-Cleaner.exe (là où tu l'as téléchargé) > etc .....selon ton souhait.

                  C)- Cit. « 1° C'est bon j'ai enfin trouvé ce dossier C:\RECYCLER. Je le voyais pas parce qu'il était en fichier caché.Je l'ai vidé en grande partie mais il y a un dossier que windows refuse de supprimer. »

                  •- ce dossier RECYCLER, tu l'as trouvé grâce au MSE comme proposé au post # 41 § 1°- ?
                  •- Je ne comprends pas bien pourquoi cette poubelle était cachée.
                  •- Comment as-tu "découvert"/"décaché" RECYCLER ?

                  D)- Cit. « Je ne souhaite pas installer AVG (sauf si tu me l'impose) car je possède déja spybot search & destroy et ad-aware pour neutraliser les spyware »

                  •- Je n'ai jamais pu imposer quoi que ce soit , ni à mon épouse, ni à nos enfants, ni à notre personnel.
                  Je n'en ai jamais eu la prétention.
                  C'eût été le plus mauvais choix !
                  •- Je te suggère de mettre de côté Ad-Aware et Spybot S&D y compris son Tea-Timer résident durant quelques jours, le temps de tester AVG Anti-Spyware ( ne pas mettre en service son bouclier résident ==> tu as assez de protection avec BitDefender Antivirus Plus v10).
                  •- Il me plaîrait que tu puisses faire une analyse avec comme indiqué post # 41 § 2°-
                  •- Garde-le en réserve; il peut d'être utile.

                  E)- Cit. « ==>Comme tu le sais bitdefender scanne en permanence le disque dur,c'est comme ça qu'il a trouvé une infection sur le fichier nommé Cfiles.dat situé à l'intérieur du dossier C:\Combofix.==>je viens de me rendre compte que ce fichier a disparu,c'est peut être à cause de l'analyse bitdefender. »

                  Oui, BitDefender Antivirus Plus v10 a désigné ComboFix comme une infection et a supprimé un fichier ( on appelle ça un "faux-positif" qu'il est inutile et par malvenu de supprimer ) .

                  Ici, pas de problème puisque tu vas supprimer ComboFix totalement, ainsi que "clean" et SDFix comme ceci :
                  •- Télécharger _OTMoveIt sur ton bureau > < http://download.bleepingcomputer.com/oldtimer/OTMoveIt.exe >
                  •- Lance OTMoveIt.exe par double-clic
                  [*]Clique sur CleanUp! (le programme va télécharger un fichier texte qui servira a nettoyer les programmes que l'on a téléchargé).
                  NOTE : Normalement, ton Firewall (parefeu) devrait te demander si _OTMoveIt peut accéder a Internet. Autorise-le.
                  [*]Une liste apparaît dans la partie gauche d' _OTMoveIt.
                  [*]Un message apparaît pour confirmer le nettoyage. Confirme
                  Ce programme supprime les outils utilisés ainsi que les quarantaines éventuelles.

                  J'espère que le PC te donne maintenant satisfaction.
                  Reviens quand tu veux.
                  Merci pour ta collaboration.
                  Bon W-E
                  Al
                  1. bonjour afideg,
                    oui j'ai appliqué la procédure pour supprimer spyware trial.

                    1° C'est bon j'ai enfin trouvé ce dossier C:\RECYCLER. Je le voyais pas parce qu'il était en fichier caché.Je l'ai vidé en grande partie mais il y a un dossier que windows refuse de supprimer.

                    2° SpywareSecure_trial a été installé à mon insu. Je ne souhaite pas installer AVG (sauf si tu me l'impose) car je possède déja spybot search & destroy et ad-aware pour neutraliser les spyware.

                    4° c'est bon j'ai installé le patch adobe.

                    j'ai fait une analyse spybot search & destroy : aucun mouchard trouvé (j'ai pas mis le rapport, trop long...)

                    J'ai aussi fait une analyse avec ad-aware,voici le rapport (aucun problèmes à signaler):


                    Ad-Aware 2007 Build
                    Log File Created on: 2007-10-26 15:57:06
                    Using Definitions File: C:\Documents and Settings\All Users\Application Data\Lavasoft\Ad-Aware 2007\core.aawdef
                    Computer name: SCANNAYA
                    Name of user performing scan: SYSTEM

                    System information
                    ===========================
                    Number of processors: 1
                    Processor type: AMD Athlon(tm) 64 Processor 3500+
                    Memory Available: 63%
                    Total Physical Memory: 2146942976 Bytes
                    Available Physical Memory: 1337548800 Bytes
                    Total Page File Size: 3596910592 Bytes
                    Available On Page File: 2788052992 Bytes
                    Total Virtual Memory: 2147352576 Bytes
                    Available Virtual Memory: 1997524992 Bytes
                    OS: Microsoft Windows XP Service Pack 2 (Build 2600)

                    Ad-Aware 2007 Settings
                    ===========================
                    Skipping files larger than 1048576 kB
                    Ignoring infections with lower TAI than: 3

                    Extended Ad-Aware 2007 Settings
                    ===========================
                    Unloading known modules during scan
                    Ignoring spanned files when scanning cab archives
                    Reanalyzing results after scanning before displaying results
                    Trying to unload modules prior to removal
                    Let Windows remove files currently in use at next reboot
                    Removing quarantined objects after restore
                    Deactivating Ad-Watch during scans
                    Writeprotecting system files after repairs
                    Include info about ignored objects in log file
                    Including basic settings in log file
                    Including advanced settings in log file
                    Including user and computer name in log file
                    Create and save WebUpdate log file

                    Databaseinfo
                    ===========================
                    Version number: 28
                    Build Number: 0
                    Build Date and Time: 2007/10/24 13:36:54

                    Scan Statistics
                    ===========================
                    Method: Smart
                    Scan tracking cookies.............................: On
                    Scan ADS filestreams..............................: Off

                    Item Scanned: 132566
                    Infections Detected: 3
                    Infections Ignored: 1

                    Scan detailed statistics
                    ===========================
                    Type Critical Total
                    Process Scan....: 0 0
                    Registry Scan...: 0 0
                    Registry PE Scan: 0 0
                    Hosts File Scan.: 0 0
                    File Scan.......: 0 0
                    Folder Scan.....: 0 0
                    LSP Scan........: 0 0
                    ADS Scan........: 0 0
                    Cookie Scan.....: 0 0
                    File Hash Scan..: 0 0

                    Infections Found
                    ===========================
                    Family Id: 9999 Name: MRU Object Category: MRU Object TAI:0
                    Item Id: 1 Value: MRU Path: C:\Documents and Settings\steven\Recent Count: 90
                    Item Id: 2 Value: MRU Registry Key: S-1-5-21-1708537768-484763869-725345543-1003\Software\Microsoft\Search Assistant\ACMru\5603 Count: 3
                    Item Id: 3 Value: MRU Registry Key: S-1-5-21-1708537768-484763869-725345543-1003\Software\Microsoft\Internet Explorer\TypedURLs Count: 11

                    Items Ignored During Scan
                    ===========================
                    Family Id: 725 Name: Tracking Cookie Category: DataMiner TAI:3
                    Item Id: 600000173 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\steven\Cookies\index.dat bluestreak.com id /
                    Item Id: 600000225 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\steven\Cookies\index.dat weborama.fr oo136131 /
                    Item Id: 600000225 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\steven\Cookies\index.dat weborama.fr AFFICHE_W /
                    Item Id: 600000179 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\steven\Cookies\index.dat atdmt.com AA002 /
                    Item Id: 600000234 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt tradedoubler.com TradeDoublerGUID /
                    Item Id: 600000234 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt tradedoubler.com TD_EH_0 /
                    Item Id: 600000234 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt tradedoubler.com TD_POOL /
                    Item Id: 600000234 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt tradedoubler.com TD_UNIQUE_IMP /
                    Item Id: 600000234 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt tradedoubler.com TD_PIC /
                    Item Id: 600000126 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt ehg-neuftelecom.hitbox.com DM570526I6WFV6 /
                    Item Id: 600000126 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt ehg-neuftelecom.hitbox.com DM56041199AAV6 /
                    Item Id: 600000126 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt ehg-neuftelecom.hitbox.com DM5511289ODMV6 /
                    Item Id: 600000126 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt hitbox.com CTG /
                    Item Id: 600000126 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt hitbox.com WSS_GW /
                    Item Id: 600000225 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt weborama.fr AFFICHE_W /
                    Item Id: 600000225 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt weborama.fr aimfarcapping /
                    Item Id: 600000225 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt weborama.fr wbo_temps_reel /
                    Item Id: 600000225 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt weborama.fr wous /
                    Item Id: 600000142 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt fr.sitestat.com c1 /gdf/
                    Item Id: 600000142 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt fr.sitestat.com s1 /gdf/test/
                    Item Id: 600000173 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt bluestreak.com id /
                    Item Id: 600000001 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt smartadserver.com pid /
                    Item Id: 600000001 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt smartadserver.com pbw /
                    Item Id: 600000001 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt smartadserver.com pbwmaj /
                    Item Id: 600000001 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt smartadserver.com TestIfCookieP /
                    Item Id: 600000138 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt fastclick.net m3 /
                    Item Id: 600000138 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt fastclick.net pjw /
                    Item Id: 600000138 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt fastclick.net pluto /
                    Item Id: 600000138 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt fastclick.net adv_ic /
                    Item Id: 600000138 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt fastclick.net vt /
                    Item Id: 600000408 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt serving-sys.com E2 /
                    Item Id: 600000408 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt serving-sys.com A2 /
                    Item Id: 600000171 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt bs.serving-sys.com eyeblaster /
                    Item Id: 600000408 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt serving-sys.com C3 /
                    Item Id: 600000408 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt serving-sys.com B2 /
                    Item Id: 600000408 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt serving-sys.com D3 /
                    Item Id: 600000144 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt doubleclick.net id /
                    Item Id: 600000212 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt msnportal.112.2o7.net s_vi /
                    Item Id: 600000212 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt 2o7.net s_vi_atamox7Ecaihem /
                    Item Id: 600000212 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt 2o7.net s_vi_x7Cbx7Fx7Ctcrdbeprx60acx7Eu /
                    Item Id: 600000212 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt 2o7.net s_vi_jtiedhj /
                    Item Id: 600000031 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt www.cibleclick.com CIBLE_CLICK_BAN /
                    Item Id: 600000031 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt www.cibleclick.com CIDENT_ID /
                    Item Id: 600000176 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt bfast.com UID /
                    Item Id: 600000142 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt estat.com pc244044148691 /
                    Item Id: 600000142 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt estat.com e /
                    Item Id: 600000101 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt overture.com UserData /
                    Item Id: 600000101 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt overture.com CMUserData /
                    Item Id: 600000101 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt overture.com ConvData /
                    Item Id: 600000179 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt atdmt.com AA002 /
                    Item Id: 600000263 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt mediaplex.com svid /
                    Item Id: 600000263 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt mediaplex.com mojo2 /
                    Item Id: 600000225 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt static.weborama.fr rmCookiesChecked /
                    Item Id: 600000225 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt static.weborama.fr flashInstalled /
                    Item Id: 600000190 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt www.googleadservices.com Conversion /pagead/conversion/1071827017/
                    Item Id: 600000225 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt blackbox.weborama.fr AFFICHE_W /
                    Item Id: 600000187 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt advertising.com ROLL /
                    Item Id: 600000187 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt advertising.com F1 /
                    Item Id: 600000187 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt advertising.com BASE /
                    Item Id: 600000187 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt advertising.com C2 /
                    Item Id: 600000187 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt advertising.com ACID /
                    Item Id: 600000000 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt zedo.com PCA319390 /
                    Item Id: 600000000 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt zedo.com ZEDOIDX /
                    Item Id: 600000000 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt zedo.com geo /
                    Item Id: 600000000 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt zedo.com PCA327219 /
                    Item Id: 600000000 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt zedo.com ZEDOIDA /
                    Item Id: 600000460 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt ad.yieldmanager.com ih /
                    Item Id: 600000460 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt ad.yieldmanager.com bh /
                    Item Id: 600000460 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt ad.yieldmanager.com uid /
                    Item Id: 600000212 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt sfr.122.2o7.net s_vi /
                    Item Id: 600000262 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt metriweb.be MetriWeb /
                    Item Id: 600000165 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt www.casinotropez.com SaneID /
                    Item Id: 600000165 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt www.casinotropez.com TRACK /
                    Item Id: 600000073 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt specificclick.net smc /
                    Item Id: 600000073 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt specificclick.net dmc /
                    Item Id: 600000073 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt specificclick.net smk /
                    Item Id: 600000073 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt specificclick.net dmk /
                    Item Id: 600000447 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt apmebf.com LCLK /
                    Item Id: 600000447 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt apmebf.com S /
                    Item Id: 600000293 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt adviva.net ansv4_uid /
                    Item Id: 600000201 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt adrevolver.com prefs /
                    Item Id: 600000201 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt media.adrevolver.com uid /adrevolver/
                    Item Id: 600000201 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt media.adrevolver.com freq /adrevolver/
                    Item Id: 600000201 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt media.adrevolver.com adrevid /adrevolver/
                    Item Id: 600000476 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt statcounter.com session_1204799 /
                    Item Id: 600000476 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt statcounter.com session_743333 /
                    Item Id: 600000476 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt statcounter.com session_2374146 /
                    Item Id: 600000295 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt adtech.de CfP /
                    Item Id: 600000295 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt adtech.de JEB2 /
                    Item Id: 600000142 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt fr.sitestat.com s1 /becquet/becquet/
                    Item Id: 600000083 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt 247realmedia.com RMFD /
                    Item Id: 600000083 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt 247realmedia.com RMID /
                    Item Id: 600000212 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt aolfr.122.2o7.net s_vi /
                    Item Id: 600000001 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt adserver.aol.fr CfP /
                    Item Id: 600000001 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt adserver.aol.fr JEB2 /
                    Item Id: 600000212 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt numericable.112.2o7.net s_vi /
                    Item Id: 600000142 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt fr.sitestat.com s1 /gdf/france/
                    Item Id: 600000142 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt fr.sitestat.com s1 /gdf/distributeur/
                    Item Id: 600000142 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt fr.sitestat.com s1 /paris-touristoffice/paris-touristoffice/
                    Item Id: 600000190 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt www.googleadservices.com Conversion /pagead/conversion/1067268239/
                    Item Id: 600000190 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt www.googleadservices.com Conversion /pagead/conversion/1071845428/
                    Item Id: 600000142 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt fr.sitestat.com s1 /bayard/pelerin/
                    Item Id: 600000142 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt fr.sitestat.com c1 /bayard/
                    Item Id: 600000363 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt fl01.ct2.comclick.com CKA /
                    Item Id: 600000363 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt fl01.ct2.comclick.com comTrackIdSurfeur /
                    Item Id: 600000363 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt fl01.ct2.comclick.com CKA_SIZE /
                    Item Id: 600000142 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt www8.addfreestats.com NC1U /cgi-bin
                    Item Id: 600000122 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt instadia.net UID /
                    Item Id: 600000126 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt ehg-telecomitalia.hitbox.com DM56062648VEV6 /
                    Item Id: 600000050 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt tribalfusion.com ANON_ID /
                    Item Id: 600000513 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt adbrite.com Apache /
                    Item Id: 600000513 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt adbrite.com b /
                    Item Id: 600000400 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt tacoda.net TID /
                    Item Id: 600000400 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt tacoda.net TData /
                    Item Id: 600000400 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt tacoda.net Tcc /
                    Item Id: 600000403 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt stat.dealtime.com VOTF /
                    Item Id: 600000190 Value: Browser: Firefox Cookie: C:\Documents and Settings\papa\Application Data\Mozilla\Firefox\Profiles/gl2y871s.default\cookies.txt www.googleadservices.com Conversion /pagead/conversion/1069820447/

                    Listing of running processes
                    ===========================
                    C:\WINDOWS\SYSTEM32\SMSS.EXE
                    c:\windows\system32\smss.exe

                    c:\windows\system32\ntdll.dll

                    C:\WINDOWS\SYSTEM32\CSRSS.EXE
                    c:\windows\system32\csrss.exe

                    c:\windows\system32\ntdll.dll

                    c:\windows\system32\csrsrv.dll

                    c:\windows\system32\basesrv.dll

                    c:\windows\system32\winsrv.dll

                    c:\windows\system32\gdi32.dll

                    c:\windows\system32\kernel32.dll

                    c:\windows\system32\user32.dll

                    c:\windows\system32\sxs.dll

                    c:\windows\system32\advapi32.dll

                    c:\windows\system32\rpcrt4.dll

                    c:\windows\system32\apphelp.dll

                    c:\windows\system32\version.dll

                    C:\WINDOWS\SYSTEM32\WINLOGON.EXE
                    c:\windows\system32\winlogon.exe

                    c:\windows\system32\ntdll.dll

                    c:\windows\system32\kernel32.dll

                    c:\windows\system32\advapi32.dll

                    c:\windows\system32\rpcrt4.dll

                    c:\windows\system32\authz.dll

                    c:\windows\system32\msvcrt.dll

                    c:\windows\system32\crypt32.dll

                    c:\windows\system32\user32.dll

                    c:\windows\system32\gdi32.dll

                    c:\windows\system32\msasn1.dll

                    c:\windows\system32\nddeapi.dll

                    c:\windows\system32\profmap.dll

                    c:\windows\system32\netapi32.dll

                    c:\windows\system32\userenv.dll

                    c:\windows\system32\psapi.dll

                    c:\windows\system32\regapi.dll

                    c:\windows\system32\secur32.dll

                    c:\windows\system32\setupapi.dll

                    c:\windows\system32\version.dll

                    c:\windows\system32\winsta.dll

                    c:\windows\system32\wintrust.dll

                    c:\windows\system32\imagehlp.dll

                    c:\windows\system32\ws2_32.dll

                    c:\windows\system32\ws2help.dll

                    c:\windows\system32\sockspy.dll

                    c:\windows\system32\msgina.dll

                    c:\windows\system32\shell32.dll

                    c:\windows\system32\shlwapi.dll

                    c:\windows\system32\comctl32.dll

                    c:\windows\system32\odbc32.dll

                    c:\windows\system32\comdlg32.dll

                    c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll

                    c:\windows\system32\odbcint.dll

                    c:\windows\system32\shsvcs.dll

                    c:\windows\system32\sfc.dll

                    c:\windows\system32\sfc_os.dll

                    c:\windows\system32\ole32.dll

                    c:\windows\system32\apphelp.dll

                    c:\windows\system32\winscard.dll

                    c:\windows\system32\wtsapi32.dll

                    c:\windows\system32\sxs.dll

                    c:\windows\system32\uxtheme.dll

                    c:\windows\system32\winmm.dll

                    c:\windows\system32\rsaenh.dll

                    c:\windows\system32\ati2evxx.dll

                    c:\windows\system32\oleaut32.dll

                    c:\windows\system32\cscdll.dll

                    c:\windows\system32\wlnotify.dll

                    c:\windows\system32\winspool.drv

                    c:\windows\system32\mpr.dll

                    c:\windows\system32\samlib.dll

                    c:\windows\system32\msv1_0.dll

                    c:\windows\system32\iphlpapi.dll

                    c:\windows\system32\wldap32.dll

                    c:\windows\system32\hcnfsclt.dll

                    c:\windows\system32\hnutil11.dll

                    c:\windows\system32\msvcp60.dll

                    c:\windows\system32\hnnfsd11.dll

                    c:\windows\system32\hnrpc11.dll

                    c:\windows\system32\hcldes11.dll

                    c:\windows\system32\hnip11.dll

                    c:\windows\system32\hnfsconn.dll

                    c:\windows\system32\hnfscore.dll

                    c:\windows\system32\hndsvc11.dll

                    c:\windows\system32\hclnis11.dll

                    c:\windows\system32\hnsrch11.dll

                    c:\windows\system32\hnldap11.dll

                    c:\windows\system32\activeds.dll

                    c:\windows\system32\adsldpc.dll

                    c:\windows\system32\atl.dll

                    c:\windows\system32\clbcatq.dll

                    c:\windows\system32\comres.dll

                    c:\windows\system32\msi.dll

                    c:\windows\system32\hcnfsmpr.fra.nls

                    c:\windows\system32\mswsock.dll

                    c:\windows\system32\dnsapi.dll

                    c:\windows\system32\winrnr.dll

                    c:\windows\system32\wshbth.dll

                    c:\windows\system32\netman.dll

                    c:\windows\system32\mprapi.dll

                    c:\windows\system32\rtutils.dll

                    c:\windows\system32\netshell.dll

                    c:\windows\system32\credui.dll

                    c:\windows\system32\rasapi32.dll

                    c:\windows\system32\rasman.dll

                    c:\windows\system32\tapi32.dll

                    c:\windows\system32\wininet.dll

                    c:\windows\system32\wzcsapi.dll

                    c:\windows\system32\wzcsvc.dll

                    c:\windows\system32\wmi.dll

                    c:\windows\system32\dhcpcsvc.dll

                    c:\windows\system32\esent.dll

                    c:\windows\system32\cscui.dll

                    c:\windows\system32\xpsp2res.dll

                    c:\windows\system32\ntmarta.dll

                    c:\windows\system32\wdmaud.drv

                    c:\windows\system32\msacm32.drv

                    c:\windows\system32\msacm32.dll

                    c:\windows\system32\midimap.dll

                    C:\WINDOWS\SYSTEM32\SERVICES.EXE
                    c:\windows\system32\services.exe

                    c:\windows\system32\ntdll.dll

                    c:\windows\system32\kernel32.dll

                    c:\windows\system32\msvcrt.dll

                    c:\windows\system32\advapi32.dll

                    c:\windows\system32\rpcrt4.dll

                    c:\windows\system32\user32.dll

                    c:\windows\system32\gdi32.dll

                    c:\windows\system32\userenv.dll

                    c:\windows\system32\scesrv.dll

                    c:\windows\system32\authz.dll

                    c:\windows\system32\umpnpmgr.dll

                    c:\windows\system32\winsta.dll

                    c:\windows\system32\netapi32.dll

                    c:\windows\system32\ncobjapi.dll

                    c:\windows\system32\msvcp60.dll

                    c:\windows\system32\shimeng.dll

                    c:\windows\apppatch\acadproc.dll

                    c:\windows\system32\sockspy.dll

                    c:\windows\system32\secur32.dll

                    c:\windows\system32\apphelp.dll

                    c:\windows\system32\version.dll

                    c:\windows\system32\eventlog.dll

                    c:\windows\system32\ws2_32.dll

                    c:\windows\system32\ws2help.dll

                    c:\windows\system32\psapi.dll

                    c:\windows\system32\wtsapi32.dll

                    C:\WINDOWS\SYSTEM32\LSASS.EXE
                    c:\windows\system32\lsass.exe

                    c:\windows\system32\ntdll.dll

                    c:\windows\system32\kernel32.dll

                    c:\windows\system32\advapi32.dll

                    c:\windows\system32\rpcrt4.dll

                    c:\windows\system32\lsasrv.dll

                    c:\windows\system32\mpr.dll

                    c:\windows\system32\user32.dll

                    c:\windows\system32\gdi32.dll

                    c:\windows\system32\msasn1.dll

                    c:\windows\system32\msvcrt.dll

                    c:\windows\system32\netapi32.dll

                    c:\windows\system32\ntdsapi.dll

                    c:\windows\system32\dnsapi.dll

                    c:\windows\system32\ws2_32.dll

                    c:\windows\system32\ws2help.dll

                    c:\windows\system32\wldap32.dll

                    c:\windows\system32\secur32.dll

                    c:\windows\system32\samlib.dll

                    c:\windows\system32\samsrv.dll

                    c:\windows\system32\cryptdll.dll

                    c:\windows\system32\shimeng.dll

                    c:\windows\apppatch\acgenral.dll

                    c:\windows\system32\winmm.dll

                    c:\windows\system32\ole32.dll

                    c:\windows\system32\oleaut32.dll

                    c:\windows\system32\msacm32.dll

                    c:\windows\system32\version.dll

                    c:\windows\system32\shell32.dll

                    c:\windows\system32\shlwapi.dll

                    c:\windows\system32\userenv.dll

                    c:\windows\system32\uxtheme.dll

                    c:\windows\system32\sockspy.dll

                    c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll

                    c:\windows\system32\comctl32.dll

                    c:\windows\system32\msprivs.dll

                    c:\windows\system32\kerberos.dll

                    c:\windows\system32\msv1_0.dll

                    c:\windows\system32\iphlpapi.dll

                    c:\windows\system32\netlogon.dll

                    c:\windows\system32\w32time.dll

                    c:\windows\system32\msvcp60.dll

                    c:\windows\system32\schannel.dll

                    c:\windows\system32\crypt32.dll

                    c:\windows\system32\wdigest.dll

                    c:\windows\system32\rsaenh.dll

                    c:\windows\system32\scecli.dll

                    c:\windows\system32\setupapi.dll

                    c:\windows\system32\ipsecsvc.dll

                    c:\windows\system32\authz.dll

                    c:\windows\system32\oakley.dll

                    c:\windows\system32\winipsec.dll

                    c:\windows\system32\pstorsvc.dll

                    c:\windows\system32\mswsock.dll

                    c:\windows\system32\hnetcfg.dll

                    c:\windows\system32\wshtcpip.dll

                    c:\windows\system32\dssenh.dll

                    c:\windows\system32\psbase.dll

                    C:\WINDOWS\SYSTEM32\ATI2EVXX.EXE
                    c:\windows\system32\ati2evxx.exe

                    c:\windows\system32\ntdll.dll

                    c:\windows\system32\kernel32.dll

                    c:\windows\system32\user32.dll

                    c:\windows\system32\gdi32.dll

                    c:\windows\system32\ole32.dll

                    c:\windows\system32\advapi32.dll

                    c:\windows\system32\rpcrt4.dll

                    c:\windows\system32\msvcrt.dll

                    c:\windows\system32\oleaut32.dll

                    c:\windows\system32\userenv.dll

                    c:\windows\system32\psapi.dll

                    c:\windows\system32\setupapi.dll

                    c:\windows\system32\sockspy.dll

                    c:\windows\system32\wtsapi32.dll

                    c:\windows\system32\winsta.dll

                    c:\windows\system32\netapi32.dll

                    c:\windows\system32\powrprof.dll

                    c:\windows\system32\cfgmgr32.dll

                    c:\windows\system32\secur32.dll

                    c:\windows\system32\wintrust.dll

                    c:\windows\system32\crypt32.dll

                    c:\windows\system32\msasn1.dll

                    c:\windows\system32\imagehlp.dll

                    c:\windows\system32\msv1_0.dll

                    c:\windows\system32\ws2_32.dll

                    c:\windows\system32\ws2help.dll

                    c:\windows\system32\iphlpapi.dll

                    c:\windows\system32\ati2edxx.dll

                    c:\windows\system32\atipdlxx.dll

                    c:\windows\system32\uxtheme.dll

                    C:\WINDOWS\SYSTEM32\SVCHOST.EXE
                    c:\windows\system32\svchost.exe

                    c:\windows\system32\ntdll.dll

                    c:\windows\system32\kernel32.dll

                    c:\windows\system32\advapi32.dll

                    c:\windows\system32\rpcrt4.dll

                    c:\windows\system32\shimeng.dll

                    c:\windows\apppatch\acgenral.dll

                    c:\windows\system32\user32.dll

                    c:\windows\system32\gdi32.dll

                    c:\windows\system32\winmm.dll

                    c:\windows\system32\ole32.dll

                    c:\windows\system32\msvcrt.dll

                    c:\windows\system32\oleaut32.dll

                    c:\windows\system32\msacm32.dll

                    c:\windows\system32\version.dll

                    c:\windows\system32\shell32.dll

                    c:\windows\system32\shlwapi.dll

                    c:\windows\system32\userenv.dll

                    c:\windows\system32\uxtheme.dll

                    c:\windows\system32\sockspy.dll

                    c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll

                    c:\windows\system32\comctl32.dll

                    c:\windows\system32\ntmarta.dll

                    c:\windows\system32\wldap32.dll

                    c:\windows\system32\samlib.dll

                    c:\windows\system32\rpcss.dll

                    c:\windows\system32\secur32.dll

                    c:\windows\system32\ws2_32.dll

                    c:\windows\system32\ws2help.dll

                    c:\windows\system32\xpsp2res.dll

                    c:\windows\system32\termsrv.dll

                    c:\windows\system32\icaapi.dll

                    c:\windows\system32\setupapi.dll

                    c:\windows\system32\wintrust.dll

                    c:\windows\system32\crypt32.dll

                    c:\windows\system32\msasn1.dll

                    c:\windows\system32\imagehlp.dll

                    c:\windows\system32\authz.dll

                    c:\windows\system32\mstlsapi.dll

                    c:\windows\system32\activeds.dll

                    c:\windows\system32\adsldpc.dll

                    c:\windows\system32\netapi32.dll

                    c:\windows\system32\atl.dll

                    c:\windows\system32\regapi.dll

                    c:\windows\system32\rsaenh.dll

                    c:\windows\system32\clbcatq.dll

                    c:\windows\system32\comres.dll

                    c:\windows\system32\apphelp.dll

                    c:\windows\system32\svchost.exe

                    c:\windows\system32\ntdll.dll

                    c:\windows\system32\kernel32.dll

                    c:\windows\system32\advapi32.dll

                    c:\windows\system32\rpcrt4.dll

                    c:\windows\system32\shimeng.dll

                    c:\windows\apppatch\acgenral.dll

                    c:\windows\system32\user32.dll

                    c:\windows\system32\gdi32.dll

                    c:\windows\system32\winmm.dll

                    c:\windows\system32\ole32.dll

                    c:\windows\system32\msvcrt.dll

                    c:\windows\system32\oleaut32.dll

                    c:\windows\system32\msacm32.dll

                    c:\windows\system32\version.dll

                    c:\windows\system32\shell32.dll

                    c:\windows\system32\shlwapi.dll

                    c:\windows\system32\userenv.dll

                    c:\windows\system32\uxtheme.dll

                    c:\windows\system32\sockspy.dll

                    c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll

                    c:\windows\system32\comctl32.dll

                    c:\windows\system32\rpcss.dll

                    c:\windows\system32\secur32.dll

                    c:\windows\system32\ws2_32.dll

                    c:\windows\system32\ws2help.dll

                    c:\windows\system32\xpsp2res.dll

                    c:\windows\system32\rsaenh.dll

                    c:\windows\system32\mswsock.dll

                    c:\windows\system32\hnetcfg.dll

                    c:\windows\system32\wshtcpip.dll

                    c:\windows\system32\dnsapi.dll

                    c:\windows\system32\iphlpapi.dll

                    c:\windows\system32\winrnr.dll

                    c:\windows\system32\wldap32.dll

                    c:\windows\system32\wshbth.dll

                    c:\windows\system32\setupapi.dll

                    c:\windows\system32\rasadhlp.dll

                    c:\windows\system32\clbcatq.dll

                    c:\windows\system32\comres.dll

                    c:\windows\system32\svchost.exe

                    c:\windows\system32\ntdll.dll

                    c:\windows\system32\kernel32.dll

                    c:\windows\system32\advapi32.dll

                    c:\windows\system32\rpcrt4.dll

                    c:\windows\system32\shimeng.dll

                    c:\windows\apppatch\acgenral.dll

                    c:\windows\system32\user32.dll

                    c:\windows\system32\gdi32.dll

                    c:\windows\system32\winmm.dll

                    c:\windows\system32\ole32.dll

                    c:\windows\system32\msvcrt.dll

                    c:\windows\system32\oleaut32.dll

                    c:\windows\system32\msacm32.dll

                    c:\windows\system32\version.dll

                    c:\windows\system32\shell32.dll

                    c:\windows\system32\shlwapi.dll

                    c:\windows\system32\userenv.dll

                    c:\windows\system32\uxtheme.dll

                    c:\windows\system32\sockspy.dll

                    c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll

                    c:\windows\system32\comctl32.dll

                    c:\windows\system32\ntmarta.dll

                    c:\windows\system32\wldap32.dll

                    c:\windows\system32\samlib.dll

                    c:\windows\system32\xpsp2res.dll

                    c:\windows\system32\shsvcs.dll

                    c:\windows\system32\winsta.dll

                    c:\windows\system32\netapi32.dll

                    c:\windows\system32\rsaenh.dll

                    c:\windows\system32\dhcpcsvc.dll

                    c:\windows\system32\dnsapi.dll

                    c:\windows\system32\ws2_32.dll

                    c:\windows\system32\ws2help.dll

                    c:\windows\system32\iphlpapi.dll

                    c:\windows\system32\secur32.dll

                    c:\windows\system32\wzcsvc.dll

                    c:\windows\system32\rtutils.dll

                    c:\windows\system32\wmi.dll

                    c:\windows\system32\crypt32.dll

                    c:\windows\system32\msasn1.dll

                    c:\windows\system32\wtsapi32.dll

                    c:\windows\system32\esent.dll

                    c:\windows\system32\atl.dll

                    c:\windows\system32\rastls.dll

                    c:\windows\system32\cryptui.dll

                    c:\windows\system32\wintrust.dll

                    c:\windows\system32\imagehlp.dll

                    c:\windows\system32\wininet.dll

                    c:\windows\system32\mprapi.dll

                    c:\windows\system32\activeds.dll

                    c:\windows\system32\adsldpc.dll

                    c:\windows\system32\setupapi.dll

                    c:\windows\system32\rasapi32.dll

                    c:\windows\system32\rasman.dll

                    c:\windows\system32\tapi32.dll

                    c:\windows\system32\schannel.dll

                    c:\windows\system32\winscard.dll

                    c:\windows\system32\raschap.dll

                    c:\windows\system32\msv1_0.dll

                    c:\windows\system32\clbcatq.dll

                    c:\windows\system32\comres.dll

                    c:\windows\system32\msvcp60.dll

                    c:\windows\system32\wzcsapi.dll

                    c:\windows\system32\schedsvc.dll

                    c:\windows\system32\ntdsapi.dll

                    c:\windows\system32\msidle.dll

                    c:\windows\system32\audiosrv.dll

                    c:\windows\system32\wkssvc.dll

                    c:\windows\system32\cryptsvc.dll

                    c:\windows\system32\certcli.dll

                    c:\windows\system32\dmserver.dll

                    c:\windows\system32\ersvc.dll

                    c:\windows\system32\es.dll

                    c:\windows\pchealth\helpctr\binaries\pchsvc.dll

                    c:\windows\system32\srvsvc.dll

                    c:\windows\system32\hnetcfg.dll

                    c:\windows\system32\netman.dll

                    c:\windows\system32\netshell.dll

                    c:\windows\system32\credui.dll

                    c:\windows\system32\mprdim.dll

                    c:\windows\system32\wsock32.dll

                    c:\windows\system32\srsvc.dll

                    c:\windows\system32\powrprof.dll

                    c:\windows\system32\sens.dll

                    c:\windows\system32\seclogon.dll

                    c:\windows\system32\mswsock.dll

                    c:\windows\system32\wshtcpip.dll

                    c:\windows\system32\rasppp.dll

                    c:\windows\system32\ntlsapi.dll

                    c:\windows\system32\rasmans.dll

                    c:\windows\system32\winipsec.dll

                    c:\windows\system32\netcfgx.dll

                    c:\windows\system32\clusapi.dll

                    c:\windows\system32\trkwks.dll

                    c:\windows\system32\w32time.dll

                    c:\windows\system32\wbem\wmisvc.dll

                    c:\windows\system32\vssapi.dll

                    c:\windows\system32\wuauserv.dll

                    c:\windows\system32\wuaueng.dll

                    c:\windows\system32\advpack.dll

                    c:\windows\system32\shfolder.dll

                    c:\windows\system32\winspool.drv

                    c:\windows\system32\winhttp.dll

                    c:\windows\system32\cabinet.dll

                    c:\windows\system32\mspatcha.dll

                    c:\windows\system32\sfc.dll

                    c:\windows\system32\sfc_os.dll

                    c:\windows\system32\sxs.dll

                    c:\windows\system32\comsvcs.dll

                    c:\windows\system32\colbact.dll

                    c:\windows\system32\mtxclu.dll

                    c:\windows\system32\resutils.dll

                    c:\windows\system32\browser.dll

                    c:\windows\system32\ipnathlp.dll

                    c:\windows\system32\authz.dll

                    c:\windows\system32\wscsvc.dll

                    c:\windows\system32\msi.dll

                    c:\windows\system32\wbem\wbemcomn.dll

                    c:\windows\system32\wbem\wbemcore.dll

                    c:\windows\system32\wbem\esscli.dll

                    c:\windows\system32\wbem\fastprox.dll

                    c:\windows\system32\wbem\wbemsvc.dll

                    c:\windows\system32\wbem\wmiutils.dll

                    c:\windows\system32\wbem\repdrvfs.dll

                    c:\windows\system32\wbem\wmiprvsd.dll

                    c:\windows\system32\ncobjapi.dll

                    c:\windows\system32\wbem\wbemess.dll

                    c:\windows\system32\wbem\ncprov.dll

                    c:\windows\system32\tapisrv.dll

                    c:\windows\system32\psapi.dll

                    c:\windows\system32\rasadhlp.dll

                    c:\windows\system32\kerberos.dll

                    c:\windows\system32\cryptdll.dll

                    c:\windows\system32\rastapi.dll

                    c:\windows\system32\unimdm.tsp

                    c:\windows\system32\uniplat.dll

                    c:\windows\system32\kmddsp.tsp

                    c:\windows\system32\ndptsp.tsp

                    c:\windows\system32\ipconf.tsp

                    c:\windows\system32\h323.tsp

                    c:\windows\system32\hidphone.tsp

                    c:\windows\system32\hid.dll

                    c:\windows\system32\upnp.dll

                    c:\windows\system32\ssdpapi.dll

                    c:\windows\system32\rasdlg.dll

                    c:\windows\system32\apphelp.dll

                    c:\windows\system32\msxml3.dll

                    c:\windows\system32\winrnr.dll

                    c:\windows\system32\wshbth.dll

                    c:\windows\system32\licdll.dll

                    c:\windows\system32\dssenh.dll

                    c:\windows\system32\svchost.exe

                    c:\windows\system32\ntdll.dll

                    c:\windows\system32\kernel32.dll

                    c:\windows\system32\advapi32.dll

                    c:\windows\system32\rpcrt4.dll

                    c:\windows\system32\shimeng.dll

                    c:\windows\apppatch\acgenral.dll

                    c:\windows\system32\user32.dll

                    c:\windows\system32\gdi32.dll

                    c:\windows\system32\winmm.dll

                    c:\windows\system32\ole32.dll

                    c:\windows\system32\msvcrt.dll

                    c:\windows\system32\oleaut32.dll

                    c:\windows\system32\msacm32.dll

                    c:\windows\system32\version.dll

                    c:\windows\system32\shell32.dll

                    c:\windows\system32\shlwapi.dll

                    c:\windows\system32\userenv.dll

                    c:\windows\system32\uxtheme.dll

                    c:\windows\system32\sockspy.dll

                    c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll

                    c:\windows\system32\comctl32.dll

                    c:\windows\system32\wudfsvc.dll

                    c:\windows\system32\setupapi.dll

                    c:\windows\system32\wudfplatform.dll

                    c:\windows\system32\secur32.dll

                    c:\windows\system32\wintrust.dll

                    c:\windows\system32\crypt32.dll

                    c:\windows\system32\msasn1.dll

                    c:\windows\system32\imagehlp.dll

                    C:\WINDOWS\SYSTEM32\ATI2EVXX.EXE
                    c:\windows\system32\ati2evxx.exe

                    c:\windows\system32\ntdll.dll

                    c:\windows\system32\kernel32.dll

                    c:\windows\system32\user32.dll

                    c:\windows\system32\gdi32.dll

                    c:\windows\system32\ole32.dll

                    c:\windows\system32\advapi32.dll

                    c:\windows\system32\rpcrt4.dll

                    c:\windows\system32\msvcrt.dll

                    c:\windows\system32\oleaut32.dll

                    c:\windows\system32\userenv.dll

                    c:\windows\system32\psapi.dll

                    c:\windows\system32\setupapi.dll

                    c:\windows\system32\sockspy.dll

                    c:\windows\system32\wtsapi32.dll

                    c:\windows\system32\winsta.dll

                    c:\windows\system32\netapi32.dll

                    c:\windows\system32\powrprof.dll

                    c:\windows\system32\cfgmgr32.dll

                    c:\windows\system32\secur32.dll

                    c:\windows\system32\uxtheme.dll

                    c:\windows\system32\wintrust.dll

                    c:\windows\system32\crypt32.dll

                    c:\windows\system32\msasn1.dll

                    c:\windows\system32\imagehlp.dll

                    c:\windows\system32\xpsp2res.dll

                    c:\windows\system32\msv1_0.dll

                    c:\windows\system32\ws2_32.dll

                    c:\windows\system32\ws2help.dll

                    c:\windows\system32\iphlpapi.dll

                    c:\windows\system32\ati2edxx.dll

                    c:\windows\system32\atipdlxx.dll

                    c:\windows\system32\ati2evxx.dll

                    c:\windows\system32\winspool.drv

                    C:\WINDOWS\SYSTEM32\SVCHOST.EXE
                    c:\windows\system32\svchost.exe

                    c:\windows\system32\ntdll.dll

                    c:\windows\system32\kernel32.dll

                    c:\windows\system32\advapi32.dll

                    c:\windows\system32\rpcrt4.dll

                    c:\windows\system32\shimeng.dll

                    c:\windows\apppatch\acgenral.dll

                    c:\windows\system32\user32.dll

                    c:\windows\system32\gdi32.dll

                    c:\windows\system32\winmm.dll

                    c:\windows\system32\ole32.dll

                    c:\windows\system32\msvcrt.dll

                    c:\windows\system32\oleaut32.dll

                    c:\windows\system32\msacm32.dll

                    c:\windows\system32\version.dll

                    c:\windows\system32\shell32.dll

                    c:\windows\system32\shlwapi.dll

                    c:\windows\system32\userenv.dll

                    c:\windows\system32\uxtheme.dll

                    c:\windows\system32\sockspy.dll

                    c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll

                    c:\windows\system32\comctl32.dll

                    c:\windows\system32\dnsrslvr.dll

                    c:\windows\system32\dnsapi.dll

                    c:\windows\system32\ws2_32.dll

                    c:\windows\system32\ws2help.dll

                    c:\windows\system32\iphlpapi.dll

                    c:\windows\system32\mswsock.dll

                    c:\windows\system32\hnetcfg.dll

                    c:\windows\system32\wshtcpip.dll

                    c:\windows\system32\svchost.exe

                    c:\windows\system32\ntdll.dll

                    c:\windows\system32\kernel32.dll

                    c:\windows\system32\advapi32.dll

                    c:\windows\system32\rpcrt4.dll

                    c:\windows\system32\shimeng.dll

                    c:\windows\apppatch\acgenral.dll

                    c:\windows\system32\user32.dll

                    c:\windows\system32\gdi32.dll

                    c:\windows\system32\winmm.dll

                    c:\windows\system32\ole32.dll

                    c:\windows\system32\msvcrt.dll

                    c:\windows\system32\oleaut32.dll

                    c:\windows\system32\msacm32.dll

                    c:\windows\system32\version.dll

                    c:\windows\system32\shell32.dll

                    c:\windows\system32\shlwapi.dll

                    c:\windows\system32\userenv.dll

                    c:\windows\system32\uxtheme.dll

                    c:\windows\system32\sockspy.dll

                    c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll

                    c:\windows\system32\comctl32.dll

                    c:\windows\system32\ntmarta.dll

                    c:\windows\system32\wldap32.dll

                    c:\windows\system32\samlib.dll

                    c:\windows\system32\xpsp2res.dll

                    c:\windows\system32\lmhsvc.dll

                    c:\windows\system32\iphlpapi.dll

                    c:\windows\system32\ws2_32.dll

                    c:\windows\system32\ws2help.dll

                    c:\windows\system32\webclnt.dll

                    c:\windows\system32\wininet.dll

                    c:\windows\system32\crypt32.dll

                    c:\windows\system32\msasn1.dll

                    c:\windows\system32\secur32.dll

                    c:\windows\system32\wsock32.dll

                    c:\windows\system32\regsvc.dll

                    c:\windows\system32\ssdpsrv.dll

                    c:\windows\system32\hnetcfg.dll

                    c:\windows\system32\clbcatq.dll

                    c:\windows\system32\comres.dll

                    c:\windows\system32\mswsock.dll

                    c:\windows\system32\wshtcpip.dll

                    C:\WINDOWS\SYSTEM32\SPOOLSV.EXE
                    c:\windows\system32\spoolsv.exe

                    c:\windows\system32\ntdll.dll

                    c:\windows\system32\kernel32.dll

                    c:\windows\system32\advapi32.dll

                    c:\windows\system32\rpcrt4.dll

                    c:\windows\system32\gdi32.dll

                    c:\windows\system32\user32.dll

                    c:\windows\system32\msvcrt.dll

                    c:\windows\system32\shimeng.dll

                    c:\windows\apppatch\acgenral.dll

                    c:\windows\system32\winmm.dll

                    c:\windows\system32\ole32.dll

                    c:\windows\system32\oleaut32.dll

                    c:\windows\system32\msacm32.dll

                    c:\windows\system32\version.dll

                    c:\windows\system32\shell32.dll

                    c:\windows\system32\shlwapi.dll

                    c:\windows\system32\userenv.dll

                    c:\windows\system32\uxtheme.dll

                    c:\windows\system32\sockspy.dll

                    c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll

                    c:\windows\system32\comctl32.dll

                    c:\windows\system32\spoolss.dll

                    c:\windows\system32\ws2_32.dll

                    c:\windows\system32\ws2help.dll

                    c:\windows\system32\dnsapi.dll

                    c:\windows\system32\iphlpapi.dll

                    c:\windows\system32\rasadhlp.dll

                    c:\windows\system32\localspl.dll

                    c:\windows\system32\secur32.dll

                    c:\windows\system32\sfc_os.dll

                    c:\windows\system32\wintrust.dll

                    c:\windows\system32\crypt32.dll

                    c:\windows\system32\msasn1.dll

                    c:\windows\system32\imagehlp.dll

                    c:\windows\system32\winspool.drv

                    c:\windows\system32\netapi32.dll

                    c:\windows\system32\cnbjmon.dll

                    c:\windows\system32\hpflpm13.dll

                    c:\windows\system32\spool\drivers\w32x86\hpfcom13.dll

                    c:\windows\system32\spool\drivers\w32x86\hpfiop13.dll

                    c:\windows\system32\spool\drivers\w32x86\hpfmlc13.dll

                    c:\windows\system32\spool\drivers\w32x86\hpfmem13.dll

                    c:\windows\system32\mdimon.dll

                    c:\windows\system32\msi.dll

                    c:\windows\system32\pjlmon.dll

                    c:\windows\system32\bthcrp.dll

                    c:\windows\system32\widcommsdk.dll

                    c:\windows\system32\wbtapi.dll

                    c:\windows\system32\setupapi.dll

                    c:\windows\system32\mfc42.dll

                    c:\windows\system32\msvcp60.dll

                    c:\windows\system32\mfc42loc.dll

                    c:\windows\system32\tcpmon.dll

                    c:\windows\system32\usbmon.dll

                    c:\windows\system32\spool\prtprocs\w32x86\mdippr.dll

                    c:\windows\system32\mswsock.dll

                    c:\windows\system32\winrnr.dll

                    c:\windows\system32\wldap32.dll

                    c:\windows\system32\wshbth.dll

                    c:\windows\system32\hcnfsprn.dll

                    c:\windows\system32\mpr.dll

                    c:\windows\system32\hndsvc11.dll

                    c:\windows\system32\hcldes11.dll

                    c:\windows\system32\hnrpc11.dll

                    c:\windows\system32\hnutil11.dll

                    c:\windows\system32\hnip11.dll

                    c:\windows\system32\hclnis11.dll

                    c:\windows\system32\hnsrch11.dll

                    c:\windows\system32\hnldap11.dll

                    c:\windows\system32\activeds.dll

                    c:\windows\system32\adsldpc.dll

                    c:\windows\system32\atl.dll

                    c:\windows\system32\humlpr.dll

                    c:\windows\system32\hnnfsd11.dll

                    c:\windows\system32\hnfscore.dll

                    c:\windows\system32\hcnfslog11.dll

                    c:\windows\system32\hcnfsprt.fra.nls

                    c:\windows\system32\hcnfsmpr.fra.nls

                    c:\windows\system32\clbcatq.dll

                    c:\windows\system32\comres.dll

                    c:\windows\system32\win32spl.dll

                    c:\windows\system32\netrap.dll

                    c:\windows\system32\ntdsapi.dll

                    c:\windows\system32\inetpp.dll

                    c:\windows\system32\xpsp2res.dll

                    C:\WINDOWS\SYSTEM32\ACS.EXE
                    c:\windows\system32\acs.exe

                    c:\windows\system32\ntdll.dll

                    c:\windows\system32\kernel32.dll

                    c:\windows\system32\user32.dll

                    c:\windows\system32\gdi32.dll

                    c:\windows\system32\advapi32.dll

                    c:\windows\system32\rpcrt4.dll

                    c:\windows\system32\athcfg11.dll

                    c:\windows\system32\athcfg11res.dll

                    c:\windows\system32\mfc42.dll

                    c:\windows\system32\msvcrt.dll

                    c:\windows\system32\cfgmgr32.dll

                    c:\windows\system32\setupapi.dll

                    c:\windows\system32\iphlpapi.dll

                    c:\windows\system32\ws2_32.dll

                    c:\windows\system32\ws2help.dll

                    c:\windows\system32\version.dll

                    c:\windows\system32\shlwapi.dll

                    c:\windows\system32\crypt32.dll

                    c:\windows\system32\msasn1.dll

                    c:\windows\system32\netapi32.dll

                    c:\windows\system32\userenv.dll

                    c:\windows\system32\ole32.dll

                    c:\windows\system32\oleaut32.dll

                    c:\windows\system32\msvcp60.dll

                    c:\windows\system32\msvcirt.dll

                    c:\windows\system32\sockspy.dll

                    c:\windows\system32\mfc42loc.dll

                    c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll

                    c:\windows\system32\psapi.dll

                    c:\windows\system32\uxtheme.dll

                    c:\windows\system32\xpsp2res.dll

                    c:\windows\system32\wintrust.dll

                    c:\windows\system32\imagehlp.dll

                    c:\windows\system32\secur32.dll

                    c:\windows\system32\aegise5.dll

                    c:\windows\system32\winscard.dll

                    c:\windows\system32\wtsapi32.dll

                    c:\windows\system32\winsta.dll

                    c:\windows\system32\rsaenh.dll

                    C:\PROGRAM FILES\LAVASOFT\AD-AWARE 2007\AAWSERVICE.EXE
                    c:\program files\lavasoft\ad-aware 2007\aawservice.exe

                    c:\windows\system32\ntdll.dll

                    c:\windows\system32\kernel32.dll

                    c:\program files\lavasoft\ad-aware 2007\ceapi.dll

                    c:\windows\system32\advapi32.dll

                    c:\windows\system32\rpcrt4.dll

                    c:\program files\lavasoft\ad-aware 2007\pkarchive84cb.dll

                    c:\windows\system32\shell32.dll

                    c:\windows\system32\gdi32.dll

                    c:\windows\system32\user32.dll

                    c:\windows\system32\msvcrt.dll

                    c:\windows\system32\shlwapi.dll

                    c:\windows\system32\ole32.dll

                    c:\windows\system32\crypt32.dll

                    c:\windows\system32\msasn1.dll

                    c:\windows\system32\wldap32.dll

                    c:\windows\system32\psapi.dll

                    c:\windows\system32\version.dll

                    c:\windows\system32\wininet.dll

                    c:\windows\system32\oleaut32.dll

                    c:\program files\lavasoft\ad-aware 2007\update.dll

                    c:\windows\system32\wsock32.dll

                    c:\windows\system32\ws2_32.dll

                    c:\windows\system32\ws2help.dll

                    c:\windows\system32\sockspy.dll

                    c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll

                    c:\windows\system32\comctl32.dll

                    c:\windows\system32\rsaenh.dll

                    c:\windows\system32\uxtheme.dll

                    c:\windows\system32\mswsock.dll

                    c:\windows\system32\dnsapi.dll

                    c:\windows\system32\winrnr.dll

                    c:\windows\system32\wshbth.dll

                    c:\windows\system32\setupapi.dll

                    c:\windows\system32\rasadhlp.dll

                    c:\windows\system32\hnetcfg.dll

                    c:\windows\system32\wshtcpip.dll

                    c:\windows\system32\apphelp.dll

                    C:\WINDOWS\SYSTEM32\SVCHOST.EXE
                    c:\windows\system32\svchost.exe

                    c:\windows\system32\ntdll.dll

                    c:\windows\system32\kernel32.dll

                    c:\windows\system32\advapi32.dll

                    c:\windows\system32\rpcrt4.dll

                    c:\windows\system32\shimeng.dll

                    c:\windows\apppatch\acgenral.dll

                    c:\windows\system32\user32.dll

                    c:\windows\system32\gdi32.dll

                    c:\windows\system32\winmm.dll

                    c:\windows\system32\ole32.dll

                    c:\windows\system32\msvcrt.dll

                    c:\windows\system32\oleaut32.dll

                    c:\windows\system32\msacm32.dll

                    c:\windows\system32\version.dll

                    c:\windows\system32\shell32.dll

                    c:\windows\system32\shlwapi.dll

                    c:\windows\system32\userenv.dll

                    c:\windows\system32\uxtheme.dll

                    c:\windows\system32\sockspy.dll

                    c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll

                    c:\windows\system32\comctl32.dll

                    c:\windows\system32\bthserv.dll

                    c:\windows\system32\setupapi.dll

                    c:\windows\system32\wintrust.dll

                    c:\windows\system32\crypt32.dll

                    c:\windows\system32\msasn1.dll

                    c:\windows\system32\imagehlp.dll

                    c:\windows\system32\secur32.dll

                    c:\windows\system32\msv1_0.dll

                    c:\windows\system32\ws2_32.dll

                    c:\windows\system32\ws2help.dll

                    c:\windows\system32\iphlpapi.dll

                    C:\PROGRAM FILES\MSI\BTOES LOGICIEL BLUETOOTH\BIN\BTWDINS.EXE
                    c:\program files\msi\btoes logiciel bluetooth\bin\btwdins.exe

                    c:\windows\system32\ntdll.dll

                    c:\windows\system32\kernel32.dll

                    c:\windows\system32\ws2_32.dll

                    c:\windows\system32\msvcrt.dll

                    c:\windows\system32\ws2help.dll

                    c:\windows\system32\advapi32.dll

                    c:\windows\system32\rpcrt4.dll

                    c:\windows\system32\user32.dll

                    c:\windows\system32\gdi32.dll

                    c:\windows\system32\ole32.dll

                    c:\windows\system32\oleaut32.dll

                    c:\windows\system32\sockspy.dll

                    c:\windows\system32\uxtheme.dll

                    c:\windows\system32\xpsp2res.dll

                    c:\windows\system32\rsaenh.dll

                    c:\windows\system32\shell32.dll

                    c:\windows\system32\shlwapi.dll

                    c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll

                    c:\windows\system32\comctl32.dll

                    c:\windows\system32\crypt32.dll

                    c:\windows\system32\msasn1.dll

                    c:\windows\system32\hid.dll

                    c:\windows\system32\wintrust.dll

                    c:\windows\system32\imagehlp.dll

                    C:\WINDOWS\SYSTEM32\CTSVCCDA.EXE
                    c:\windows\system32\ctsvccda.exe

                    c:\windows\system32\ntdll.dll

                    c:\windows\system32\kernel32.dll

                    c:\windows\system32\user32.dll

                    c:\windows\system32\gdi32.dll

                    c:\windows\system32\advapi32.dll

                    c:\windows\system32\rpcrt4.dll

                    c:\windows\system32\sockspy.dll

                    C:\PROGRAM FILES\CREATIVE\SHARED FILES\CTDEVSRV.EXE
                    c:\program files\creative\shared files\ctdevsrv.exe

                    c:\windows\system32\ntdll.dll

                    c:\windows\system32\kernel32.dll

                    c:\windows\system32\user32.dll

                    c:\windows\system32\gdi32.dll

                    c:\windows\system32\advapi32.dll

                    c:\windows\system32\rpcrt4.dll

                    c:\windows\system32\sockspy.dll

                    C:\WINDOWS\SYSTEM32\HUMMINGBIRD\CONNECTIVITY\11.00\NFS MAESTRO\EXPSERV.EXE
                    c:\windows\system32\hummingbird\connectivity\11.00\nfs maestro\expserv.exe

                    c:\windows\system32\ntdll.dll

                    c:\windows\system32\kernel32.dll

                    c:\windows\system32\ws2_32.dll

                    c:\windows\system32\msvcrt.dll

                    c:\windows\system32\ws2help.dll

                    c:\windows\system32\advapi32
                    1. Contributeur sécurité
                      Re,

                      Avais-tu appliqué ceci du post # 32 ?

                      « 4°- Ce qui reste à faire:

                      A)- Il faut supprimer ce SpywareSecure_trial (cracké).
                      Prends ce logiciel JV16 gratuit ici: http://telechargement.zebulon.fr/201-jv16-powertools.html
                      (ATTENTION: à ne pas mettre à jour, car perte de gratuité)

                      Tu vas dans "outils"/"chercheur de registre",et tu entres le mot SpywareSecure
                      Tu supprimes tout ce qui se relie à SpywareSecure (tu auras une sauvegarde en cas de pépins)
                      Ensuite retourne dans "outils"/"chercheur de registre",et tu entres le mot SpywareSecure_trial, et tu fais pareil.
                      Pour terminer, tu lances la fonction "Nettoyage" et tu supprimes toutes les lignes vertes.

                      B)- Vas dans "Poste de travail" > C:\ > RECYCLER\ et là, tu vides tout le contenu de la poubelle .
                      »

                      1°- Pour vider RECYCLER, si ça ne va pas , essaie après avoir redémarré en Mode sans échec.

                      2°- Tu peux remplacer avantageusement SpywareSecure_trial par un gratuit AVG Anti-Spyware; comme ceci:

                      Télécharge et installe AVG Anti-Spyware - ici: < http://www.grisoft.com/doc/downloads-results/lng/fr/tpl/tpl01?prd=triasw >
                      -
                      - Si tu as besoin d'aide AVG-antispyware regarde ces tutoriels:
                      ---> < http://www.kachouri.com/tuto/tuto-161-avg-anti-spyware-75-pour-votre-securite.html >
                      --- > < http://www.malekal.com/tutorial_AVG_AntiSpyware.html >
                      -Tu enregistres le fichier dans Bureau.
                      -A la fin du téléchargement, tu vois l’icône « avgas-setup… » sur le bureau.
                      -
                      -Ensuite tu te déconnectes du Net, et tu fermes les sessions en cours.
                      -
                      -Tu ouvres le fichier en faisant double-clic l’icône "avgas-setup-7.5.503.exe" ( autres chiffres si c'est une version plus récente ).
                      -Une page s’ouvre ; tu clic sur « Exécuter » Tu suis les instructions.
                      -Tu notes au passage que l’installation va se faire en :
                      -C:\Program Files\Grisoft\AVG Anti-Spyware 7.5
                      -Tu peux choisir le raccourci dans le menu « Démarrage »
                      -
                      -Si on te demande de redémarrer ton ordinateur, tu le fais.
                      -
                      -Pour lancer AVG anti spyware tu doubles click sur l'icone qui s'est créé sur le bureau.
                      -
                      -La première fois que tu l'utilises, tu configures le logiciel.
                      -
                      -Sur la page "état", tu choisis inactif pour le bouclier résident ( clic sur « Modifier l’état » ).
                      -Sur la page "mise à jour", tu fais une mise à jour manuelle (version 7.5.503) - (clic sur « Commencer la mise à jour »).
                      -Tu redémarres l'ordinateur si nécessaire.
                      -
                      -- <souligne>Sur la page "Analyse",
                      tu choisis d'abord l'onglet "Paramètres" > « Comment réagir »
                      -- clic sur « Action recommandées » et dans le menu déroulant, choisir « Supprimer »
                      --< http://bp3.blogger.com/... >
                      -
                      -Tu coches à droite "générer un rapport après chaque analyse" et "uniquement en cas de menaces".
                      -Tu choisis ensuite l'onglet analyser, analyse complète du système.
                      -
                      -A la fin de l'analyse, tu cliques sur "Action", "Appliquer toutes les actions" puis "enregistrer le rapport" puis "enregistrer le rapport sous".
                      -Tu suis les instructions dans la fenêtre qui s'ouvre.
                      -
                      -Ensuite, tu ouvres le rapport avec le bloc-notes pour le copier/coller avec ta réponse.
                      -- PS Pour les autres fois, pour lancer AVG, tu double-clic sur la deuxième icône bureau créée.
                      / Il n'est pas nécessaire de désinstaller AVG Antispyware après sa période d'essai puisque même après cela, il reste un excellent outil de scan qui est très souvent utilisé dans des procédures de désinfection. Après la période d'essai (30 jours), le bouclier résident se désactive ainsi que les mises à jour automatiques. Les autres fonctions restent opérationnelles entre autres, les mises à jour "manuelles" ainsi que les scans.

                      3°- Cit. « ==>Comme tu le sais bitdefender scanne en permanence le disque dur,c'est comme ça qu'il a trouvé une infection sur le fichier nommé Cfiles.dat situé à l'intérieur du dossier C:\Combofix.==>je viens de me rendre compte que ce fichier a disparu,c'est peut être à cause de l'analyse bitdefender. »
                      Merci.

                      4°- ATTENTION: Adobe a sorti un patch pour Adobe Reader 8.1.1 pour fixer une faille :
                      < https://www.adobe.com/support/security/bulletins/apsb07-18.html >
                      Des mails de spam contenants des pièces jointes PDF sont actuellement envoyés exploitant cette faille.
                      source : https://cisrt.org/read-php/?181
                      N'OUVREZ PAS CES PDF
                      Pensez à installer le patch de sécurité, si vous possédez cette version d'Adobe Reader.
                      C'est pourquoi, je ne mets aucune mise à jour en automatique! (sauf pour mon Kis6).
                      Pour maintenir vos logiciels à jour, vous pouvez faire un Scan de vulnérabilités < https://www.malekal.com/tester-la-vulnerabilite-de-son-systeme-2/ >

                      5°- "la valeur de l'UC utilisée varie entre 2 et 18%"
                      "la valeur du processus est de 48"
                      Soit 48% de 18 = ± 8.5% ; c'est normal.
                      Par contre, je n'ai aucun avis sur ceci :« C'est dû à un "processus inactif" (SYSTEM) »;
                      et encore mois sur ceci: « Quand je lance le jeu OBLIVION ... »
                      Peut-être une question de configuration ou de paramètres ?; inconnus pour moi. ==> voir forum Windows.
                      Désolé

                      J'espère qu'ainsi ce PC sera dépollué.
                      Al.

                      1. salut,

                        les étapes E) et F) se sont passées normalement

                        voici le dernier rapport bitdefender:

                        //-----------------------------------------------------------------
                        //
                        // Product BitDefender Antivirus Plus v10
                        // Product 10.2
                        //
                        // Created on: 25/10/2007 21:29:39
                        //
                        //-----------------------------------------------------------------

                        Virus Statistics

                        Scan path : C:\
                        D:\
                        E:\
                        Folders : 10612
                        Files : 286829
                        Memory processes scanned : 48
                        Archives : 3601
                        Runtime packers : 9352
                        Identified viruses : 3
                        Infected files : 34
                        Memory processes infected : 0
                        Suspect files : 0
                        Warnings : 0
                        Disinfected files : 0
                        Deleted files : 0
                        Moved files : 1
                        I/O errors : 151
                        Scan time : 00:47:10
                        Scan speed (files/sec) : 101

                        Spyware Statistics

                        Registry keys scanned : 1830
                        Registry keys infected : 0
                        Cookies scanned : 0
                        Cookies infected : 0
                        Spyware files infected : 0
                        Spyware threats detected : 0

                        Virus definitions : 935271
                        Scan plugins : 16
                        Archive plugins : 41
                        Unpack plugins : 7
                        Mail plugins : 6
                        System plugins : 5

                        Virus scan options

                        Detection
                        [X] Scan boot sectors
                        [X] Memory Processes
                        [X] Scan archives
                        [X] Scan runtime packers
                        [X] Scan email

                        File mask
                        [ ] Programs
                        [X] All files
                        [ ] User defined extensions:
                        [ ] Exclude extensions: ;

                        Action

                        Infected objects
                        [ ] Ignore
                        [X] Disinfect
                        [ ] Delete
                        [ ] Move to quarantine
                        [ ] Prompt user

                        Second action
                        [ ] Ignore
                        [ ] Delete
                        [X] Move to quarantine
                        [ ] Prompt user

                        Virus scan options
                        [X] Enable warnings
                        [X] Enable heuristics
                        [ ] Show all files in log
                        [X] Report file: C:\Documents and Settings\All Users\Application Data\Bitdefender\Desktop\Profiles\Logs\full_scan\1193340579.log

                        Spyware scan options

                        [X] Scan for riskware
                        [ ] Skip dial and applications from scan
                        [X] Registry keys
                        [X] Cookies

                        Summary:

                        C:\ComboFix\Cfiles.dat Infected: Generic.NetAdware.5051323D
                        C:\ComboFix\Cfiles.dat Disinfection failed
                        C:\ComboFix\Cfiles.dat Moved
                        C:\Documents and Settings\élodie\Bureau\SpywareSecure_trial_setup(2).exe=>(NSIS 2o)=>lzma_solid_nsis0005 Detected: Adware.Navipromo.GO
                        C:\Documents and Settings\élodie\Bureau\SpywareSecure_trial_setup(2).exe=>(NSIS 2o)=>lzma_solid_nsis0005 Disinfection failed
                        C:\Documents and Settings\élodie\Bureau\SpywareSecure_trial_setup(2).exe=>(NSIS 2o)=>lzma_solid_nsis0005 Move failed
                        C:\Documents and Settings\élodie\Bureau\SpywareSecure_trial_setup(2).exe=>(NSIS 2o)=>lzma_solid_nsis0009 Detected: Adware.Navipromo.BXQ
                        C:\Documents and Settings\élodie\Bureau\SpywareSecure_trial_setup(2).exe=>(NSIS 2o)=>lzma_solid_nsis0009 Disinfection failed
                        C:\Documents and Settings\élodie\Bureau\SpywareSecure_trial_setup(2).exe=>(NSIS 2o)=>lzma_solid_nsis0009 Move failed
                        C:\Documents and Settings\élodie\Bureau\SpywareSecure_trial_setup(2).exe=>(NSIS 2o)=>lzma_solid_nsis0013=>(NSIS g)=>lzma_solid_nsis0002 Detected: Adware.Navipromo.GO
                        C:\Documents and Settings\élodie\Bureau\SpywareSecure_trial_setup(2).exe=>(NSIS 2o)=>lzma_solid_nsis0013=>(NSIS g)=>lzma_solid_nsis0002 Disinfection failed
                        C:\Documents and Settings\élodie\Bureau\SpywareSecure_trial_setup(2).exe=>(NSIS 2o)=>lzma_solid_nsis0013=>(NSIS g)=>lzma_solid_nsis0002 Move failed
                        C:\Documents and Settings\élodie\Bureau\SpywareSecure_trial_setup(3).exe=>(NSIS 2o)=>lzma_solid_nsis0005 Detected: Adware.Navipromo.GO
                        C:\Documents and Settings\élodie\Bureau\SpywareSecure_trial_setup(3).exe=>(NSIS 2o)=>lzma_solid_nsis0005 Disinfection failed
                        C:\Documents and Settings\élodie\Bureau\SpywareSecure_trial_setup(3).exe=>(NSIS 2o)=>lzma_solid_nsis0005 Move failed
                        C:\Documents and Settings\élodie\Bureau\SpywareSecure_trial_setup(3).exe=>(NSIS 2o)=>lzma_solid_nsis0009 Detected: Adware.Navipromo.BXQ
                        C:\Documents and Settings\élodie\Bureau\SpywareSecure_trial_setup(3).exe=>(NSIS 2o)=>lzma_solid_nsis0009 Disinfection failed
                        C:\Documents and Settings\élodie\Bureau\SpywareSecure_trial_setup(3).exe=>(NSIS 2o)=>lzma_solid_nsis0009 Move failed
                        C:\Documents and Settings\élodie\Bureau\SpywareSecure_trial_setup(3).exe=>(NSIS 2o)=>lzma_solid_nsis0013=>(NSIS g)=>lzma_solid_nsis0002 Detected: Adware.Navipromo.GO
                        C:\Documents and Settings\élodie\Bureau\SpywareSecure_trial_setup(3).exe=>(NSIS 2o)=>lzma_solid_nsis0013=>(NSIS g)=>lzma_solid_nsis0002 Disinfection failed
                        C:\Documents and Settings\élodie\Bureau\SpywareSecure_trial_setup(3).exe=>(NSIS 2o)=>lzma_solid_nsis0013=>(NSIS g)=>lzma_solid_nsis0002 Move failed
                        C:\Documents and Settings\élodie\Bureau\SpywareSecure_trial_setup(4).exe=>(NSIS 2o)=>lzma_solid_nsis0005 Detected: Adware.Navipromo.GO
                        C:\Documents and Settings\élodie\Bureau\SpywareSecure_trial_setup(4).exe=>(NSIS 2o)=>lzma_solid_nsis0005 Disinfection failed
                        C:\Documents and Settings\élodie\Bureau\SpywareSecure_trial_setup(4).exe=>(NSIS 2o)=>lzma_solid_nsis0005 Move failed
                        C:\Documents and Settings\élodie\Bureau\SpywareSecure_trial_setup(4).exe=>(NSIS 2o)=>lzma_solid_nsis0009 Detected: Adware.Navipromo.BXQ
                        C:\Documents and Settings\élodie\Bureau\SpywareSecure_trial_setup(4).exe=>(NSIS 2o)=>lzma_solid_nsis0009 Disinfection failed
                        C:\Documents and Settings\élodie\Bureau\SpywareSecure_trial_setup(4).exe=>(NSIS 2o)=>lzma_solid_nsis0009 Move failed
                        C:\Documents and Settings\élodie\Bureau\SpywareSecure_trial_setup(4).exe=>(NSIS 2o)=>lzma_solid_nsis0013=>(NSIS g)=>lzma_solid_nsis0002 Detected: Adware.Navipromo.GO
                        C:\Documents and Settings\élodie\Bureau\SpywareSecure_trial_setup(4).exe=>(NSIS 2o)=>lzma_solid_nsis0013=>(NSIS g)=>lzma_solid_nsis0002 Disinfection failed
                        C:\Documents and Settings\élodie\Bureau\SpywareSecure_trial_setup(4).exe=>(NSIS 2o)=>lzma_solid_nsis0013=>(NSIS g)=>lzma_solid_nsis0002 Move failed
                        C:\Documents and Settings\élodie\Bureau\SpywareSecure_trial_setup.exe=>(NSIS 2o)=>lzma_solid_nsis0005 Detected: Adware.Navipromo.GO
                        C:\Documents and Settings\élodie\Bureau\SpywareSecure_trial_setup.exe=>(NSIS 2o)=>lzma_solid_nsis0005 Disinfection failed
                        C:\Documents and Settings\élodie\Bureau\SpywareSecure_trial_setup.exe=>(NSIS 2o)=>lzma_solid_nsis0005 Move failed
                        C:\Documents and Settings\élodie\Bureau\SpywareSecure_trial_setup.exe=>(NSIS 2o)=>lzma_solid_nsis0009 Detected: Adware.Navipromo.BXQ
                        C:\Documents and Settings\élodie\Bureau\SpywareSecure_trial_setup.exe=>(NSIS 2o)=>lzma_solid_nsis0009 Disinfection failed
                        C:\Documents and Settings\élodie\Bureau\SpywareSecure_trial_setup.exe=>(NSIS 2o)=>lzma_solid_nsis0009 Move failed
                        C:\Documents and Settings\élodie\Bureau\SpywareSecure_trial_setup.exe=>(NSIS 2o)=>lzma_solid_nsis0013=>(NSIS g)=>lzma_solid_nsis0002 Detected: Adware.Navipromo.GO
                        C:\Documents and Settings\élodie\Bureau\SpywareSecure_trial_setup.exe=>(NSIS 2o)=>lzma_solid_nsis0013=>(NSIS g)=>lzma_solid_nsis0002 Disinfection failed
                        C:\Documents and Settings\élodie\Bureau\SpywareSecure_trial_setup.exe=>(NSIS 2o)=>lzma_solid_nsis0013=>(NSIS g)=>lzma_solid_nsis0002 Move failed
                        C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc77.exe=>(NSIS 2o)=>lzma_solid_nsis0005 Detected: Adware.Navipromo.GO
                        C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc77.exe=>(NSIS 2o)=>lzma_solid_nsis0005 Disinfection failed
                        C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc77.exe=>(NSIS 2o)=>lzma_solid_nsis0005 Move failed
                        C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc77.exe=>(NSIS 2o)=>lzma_solid_nsis0009 Detected: Adware.Navipromo.BXQ
                        C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc77.exe=>(NSIS 2o)=>lzma_solid_nsis0009 Disinfection failed
                        C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc77.exe=>(NSIS 2o)=>lzma_solid_nsis0009 Move failed
                        C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc77.exe=>(NSIS 2o)=>lzma_solid_nsis0013=>(NSIS g)=>lzma_solid_nsis0002 Detected: Adware.Navipromo.GO
                        C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc77.exe=>(NSIS 2o)=>lzma_solid_nsis0013=>(NSIS g)=>lzma_solid_nsis0002 Disinfection failed
                        C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc77.exe=>(NSIS 2o)=>lzma_solid_nsis0013=>(NSIS g)=>lzma_solid_nsis0002 Move failed
                        C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc78.exe=>(NSIS 2o)=>lzma_solid_nsis0005 Detected: Adware.Navipromo.GO
                        C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc78.exe=>(NSIS 2o)=>lzma_solid_nsis0005 Disinfection failed
                        C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc78.exe=>(NSIS 2o)=>lzma_solid_nsis0005 Move failed
                        C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc78.exe=>(NSIS 2o)=>lzma_solid_nsis0009 Detected: Adware.Navipromo.BXQ
                        C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc78.exe=>(NSIS 2o)=>lzma_solid_nsis0009 Disinfection failed
                        C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc78.exe=>(NSIS 2o)=>lzma_solid_nsis0009 Move failed
                        C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc78.exe=>(NSIS 2o)=>lzma_solid_nsis0013=>(NSIS g)=>lzma_solid_nsis0002 Detected: Adware.Navipromo.GO
                        C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc78.exe=>(NSIS 2o)=>lzma_solid_nsis0013=>(NSIS g)=>lzma_solid_nsis0002 Disinfection failed
                        C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc78.exe=>(NSIS 2o)=>lzma_solid_nsis0013=>(NSIS g)=>lzma_solid_nsis0002 Move failed
                        C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc79.exe=>(NSIS 2o)=>lzma_solid_nsis0005 Detected: Adware.Navipromo.GO
                        C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc79.exe=>(NSIS 2o)=>lzma_solid_nsis0005 Disinfection failed
                        C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc79.exe=>(NSIS 2o)=>lzma_solid_nsis0005 Move failed
                        C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc79.exe=>(NSIS 2o)=>lzma_solid_nsis0009 Detected: Adware.Navipromo.BXQ
                        C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc79.exe=>(NSIS 2o)=>lzma_solid_nsis0009 Disinfection failed
                        C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc79.exe=>(NSIS 2o)=>lzma_solid_nsis0009 Move failed
                        C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc79.exe=>(NSIS 2o)=>lzma_solid_nsis0013=>(NSIS g)=>lzma_solid_nsis0002 Detected: Adware.Navipromo.GO
                        C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc79.exe=>(NSIS 2o)=>lzma_solid_nsis0013=>(NSIS g)=>lzma_solid_nsis0002 Disinfection failed
                        C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc79.exe=>(NSIS 2o)=>lzma_solid_nsis0013=>(NSIS g)=>lzma_solid_nsis0002 Move failed
                        C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc80.exe=>(NSIS 2o)=>lzma_solid_nsis0005 Detected: Adware.Navipromo.GO
                        C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc80.exe=>(NSIS 2o)=>lzma_solid_nsis0005 Disinfection failed
                        C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc80.exe=>(NSIS 2o)=>lzma_solid_nsis0005 Move failed
                        C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc80.exe=>(NSIS 2o)=>lzma_solid_nsis0009 Detected: Adware.Navipromo.BXQ
                        C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc80.exe=>(NSIS 2o)=>lzma_solid_nsis0009 Disinfection failed
                        C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc80.exe=>(NSIS 2o)=>lzma_solid_nsis0009 Move failed
                        C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc80.exe=>(NSIS 2o)=>lzma_solid_nsis0013=>(NSIS g)=>lzma_solid_nsis0002 Detected: Adware.Navipromo.GO
                        C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc80.exe=>(NSIS 2o)=>lzma_solid_nsis0013=>(NSIS g)=>lzma_solid_nsis0002 Disinfection failed
                        C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc80.exe=>(NSIS 2o)=>lzma_solid_nsis0013=>(NSIS g)=>lzma_solid_nsis0002 Move failed
                        C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc81.exe=>(NSIS 2o)=>lzma_solid_nsis0005 Detected: Adware.Navipromo.GO
                        C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc81.exe=>(NSIS 2o)=>lzma_solid_nsis0005 Disinfection failed
                        C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc81.exe=>(NSIS 2o)=>lzma_solid_nsis0005 Move failed
                        C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc81.exe=>(NSIS 2o)=>lzma_solid_nsis0009 Detected: Adware.Navipromo.BXQ
                        C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc81.exe=>(NSIS 2o)=>lzma_solid_nsis0009 Disinfection failed
                        C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc81.exe=>(NSIS 2o)=>lzma_solid_nsis0009 Move failed
                        C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc81.exe=>(NSIS 2o)=>lzma_solid_nsis0013=>(NSIS g)=>lzma_solid_nsis0002 Detected: Adware.Navipromo.GO
                        C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc81.exe=>(NSIS 2o)=>lzma_solid_nsis0013=>(NSIS g)=>lzma_solid_nsis0002 Disinfection failed
                        C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc81.exe=>(NSIS 2o)=>lzma_solid_nsis0013=>(NSIS g)=>lzma_solid_nsis0002 Move failed
                        C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc82.exe=>(NSIS 2o)=>lzma_solid_nsis0005 Detected: Adware.Navipromo.GO
                        C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc82.exe=>(NSIS 2o)=>lzma_solid_nsis0005 Disinfection failed
                        C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc82.exe=>(NSIS 2o)=>lzma_solid_nsis0005 Move failed
                        C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc82.exe=>(NSIS 2o)=>lzma_solid_nsis0009 Detected: Adware.Navipromo.BXQ
                        C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc82.exe=>(NSIS 2o)=>lzma_solid_nsis0009 Disinfection failed
                        C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc82.exe=>(NSIS 2o)=>lzma_solid_nsis0009 Move failed
                        C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc82.exe=>(NSIS 2o)=>lzma_solid_nsis0013=>(NSIS g)=>lzma_solid_nsis0002 Detected: Adware.Navipromo.GO
                        C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc82.exe=>(NSIS 2o)=>lzma_solid_nsis0013=>(NSIS g)=>lzma_solid_nsis0002 Disinfection failed
                        C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc82.exe=>(NSIS 2o)=>lzma_solid_nsis0013=>(NSIS g)=>lzma_solid_nsis0002 Move failed
                        C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc83.exe=>(NSIS 2o)=>lzma_solid_nsis0005 Detected: Adware.Navipromo.GO
                        C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc83.exe=>(NSIS 2o)=>lzma_solid_nsis0005 Disinfection failed
                        C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc83.exe=>(NSIS 2o)=>lzma_solid_nsis0005 Move failed
                        C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc83.exe=>(NSIS 2o)=>lzma_solid_nsis0009 Detected: Adware.Navipromo.BXQ
                        C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc83.exe=>(NSIS 2o)=>lzma_solid_nsis0009 Disinfection failed
                        C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc83.exe=>(NSIS 2o)=>lzma_solid_nsis0009 Move failed
                        C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc83.exe=>(NSIS 2o)=>lzma_solid_nsis0013=>(NSIS g)=>lzma_solid_nsis0002 Detected: Adware.Navipromo.GO
                        C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc83.exe=>(NSIS 2o)=>lzma_solid_nsis0013=>(NSIS g)=>lzma_solid_nsis0002 Disinfection failed
                        C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc83.exe=>(NSIS 2o)=>lzma_solid_nsis0013=>(NSIS g)=>lzma_solid_nsis0002 Move failed

                        Cit. « L'analyse du fichier sur virustotal n'a pas fonctionné, c'est l'upload du fichier qui échoue.j'ai ce message qui s'affiche:0 bytes size received »
                        Cit. « Il semblerait qu'un fichier de combofix soit infecté (Cfiles.dat) »


                        ==>Comme tu le sais bitdefender scanne en permanence le disque dur,c'est comme ça qu'il a trouvé une infection sur le fichier nommé Cfiles.dat situé à l'intérieur du dossier C:\Combofix.==>je viens de me rendre compte que ce fichier a disparu,c'est peut être à cause de l'analyse bitdefender.

                        Le PC se comporte pas trop mal,il semblerait que j'ai plus de pop-up spyware secure. Mais vu que qu'aujourd'hui j'ai passé la journée à faire des scans et des redémarrages je garantis rien. Quand je lance le jeu OBLIVION avec la configuration détectée par le celui-ci (1024*768) ça rame beaucoup!Je suis obligé de changer les réglages (640*480) pour pouvoir jouer (j'ai un athlon 3500+ avec 2Go de RAM et une carte graphique ATI radeon X1300). Quand je vais dans le gestionnaires des tâches windows (ctrl+alt+suppr), la valeur de l'UC utilisée varie entre 2 et 18% (à peu près normal),la charge dédiée est d'environ 425 MO mais ce que je trouve bizarre c'est que la valeur du processus est de 48. C'est élevé.C'est dû à un "processus inactif" (SYSTEM).
                        1. Contributeur sécurité
                          (suite)

                          Cit. « L'analyse du fichier sur virustotal n'a pas fonctionné, c'est l'upload du fichier qui échoue.j'ai ce message qui s'affiche:0 bytes size received »
                          Cit. « Il semblerait qu'un fichier de combofix soit infecté (Cfiles.dat) »

                          ==> lequel ? Comment se dénomme-t-il ?
                          À te lire il semblerait que ce fichier "fantôme" existe; mais qu'il soit vide.
                          Peux-tu le confirmer, SVP ?

                          Ces deux-ci me turlupinent encore; mais je n'ai aucun élément qui m'oblige à les faire supprimer.
                          2006-05-28 16:46 397,306 --sha-r C:\Program Files\wunauclt.zip
                          2006-05-28 16:46 397,306 --sha-r C:\Program Files\wunauclt.tbe
                          Il faudra y rester attentif si tu as des soucis ultérieurement.

                          Comment se comporte maintenant le PC ?
                          Merci
                          Al.
                          1. D) voici le rapport Navilog:

                            Search Navipromo version 3.3.2 commencé le 25/10/2007 à 21:15:36,62

                            !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
                            !!! Postez ce rapport sur le forum pour le faire analyser !!!
                            !!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

                            Outil exécuté depuis C:\Program Files\navilog1
                            Mise à jour le 22.10.2007 à 19h00 par IL-MAFIOSO

                            Microsoft Windows XP [version 5.1.2600]
                            Internet Explorer : 6.0.2900.2180

                            *** Recherche Programmes installés ***

                            *** Recherche dossiers dans C:\WINDOWS ***

                            *** Recherche dossiers dans C:\Program Files ***

                            *** Recherche dossiers dans C:\Documents and Settings\All Users\Application Data ***

                            *** Recherche dossiers dans C:\Documents and Settings\steven\Application Data ***

                            *** Recherche dossiers dans C:\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1 ***

                            *** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
                            pour + d'infos : http://www.gmer.net

                            Aucun fichier trouvé dans :

                            - C:\WINDOWS\system32
                            - C:\DOCUME~1\STEVEN\LOCALS~1\APPLIC~1

                            *** Recherche avec GenericNaviSearch ***
                            !!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
                            !!! A vérifier impérativement avant toute suppression manuelle !!!

                            * Recherche dans C:\WINDOWS\system32 *

                            * Recherche dans C:\DOCUME~1\STEVEN\LOCALS~1\APPLIC~1 *

                            *** Recherche fichiers ***

                            *** Recherche clés spécifiques dans le Registre ***

                            *** Module de Recherche complémentaire ***
                            (Recherche fichiers spécifiques)

                            1)Recherche fichiers connus:

                            2)Recherche Heuristique :

                            3)Recherche Certificats :

                            Certificat Egroup absent !

                            *** Analyse terminée le 25/10/2007 à 21:16:10,60 ***
                            1. C) voici le rapport Clean:

                              Script execute en mode sans echec
                              Rapport clean par Malekal_morte - http://www.malekal.com
                              Script execute en mode sans echec 25/10/2007 a 21:04:55,37

                              Microsoft Windows XP [version 5.1.2600]

                              *** Suppression des fichiers dans C:

                              *** Suppression des fichiers dans C:\WINDOWS\

                              *** Suppression des fichiers dans C:\WINDOWS\system32

                              *** Suppression des fichiers dans C:\Program Files

                              *** Suppression des clefs du registre effectuee..
                              *** Fin du rapport !
                              1. bonsoir afideg,

                                réponse au post 32

                                1° J'avais bien fait la manip sur la restauration système; par contre j'ai fait le redémarrage manuellement.

                                2° L'analyse du fichier sur virustotal n'a pas fonctionné, c'est l'upload du fichier qui échoue.j'ai ce message qui s'affiche:0 bytes size received / Se ha recibido un archivo vacio
                                Je retenterai ça plus tard.
                                la suite arrive ...
                                1. Contributeur sécurité
                                  Salut Yo,

                                  Pourrais-tu nous laisser travailler tranquillement ici, SVP ?

                                  Il serait préférable que tu fasses ton message personnel, cela rendra les postes plus compréhensibles et la réponse à ton problème sera plus efficace
                                  Procède comme ceci :
                                  http://pageperso.aol.fr/balltrap34/demofairesontmessage.htm
                                  http://perso.orange.fr/rginformatique/section%20virus/demofairesontmessage.htm

                                  Guide du forum < https://www.commentcamarche.net/infos/25843-guide-d-utilisation-du-forum-de-commentcamarche-net/ >

                                  Inscription CCM < http://www.commentcamarche.net/communaute/inscription.php3 >

                                  Merci
                                  Al.

                                  1. Contributeur sécurité
                                    Bonjour vinoth91,

                                    Beau travail
                                    Merci pour ta collaboration

                                    1°- Avais-tu bien terminé ceci en C)- ?
                                    « Attention•- Clique sur "Démarrer" - Clic droit sur le "Poste de Travail" > dans "Propriétés" > onglet "Restauration du système" - Décocher la case "Désactiver la restauration du système" et cliquer sur "Appliquer".
                                    •- La manoeuvre nécessitera un reboot (=redémarrage) initié par le programme.
                                    »

                                    NOTE: Si tu ne l'avais pas fait, ce n'est rien; mais fais-le alors à la fin des procédures ci-dessous.

                                    2°- Citation « Il semblerait qu'un fichier de combofix soit infecté (Cfiles.dat) »
                                    ==> lequel ? ==> Fais-le analyser par VirusTotal.

                                    3°- Tu as la possibilité de vider le cache Internet de tous ses fichiers temporaires avec ce petit logiciel que tu lances tous les jours à la fin de ta session de travail
                                    Télécharge : ATF-Cleaner < http://www.atribune.org/ccount/click.php?id=1 >
                                    - ATTENTION,cette fois-ci particulièrement, redémarre en mode sans échec avant de le lancer
                                    < http://cybersecurite.xooit.com/t88-Demarrer-en-Mode-sans-echec.htm >
                                    Choisir sa session habituelle, (pas le compte "Administrateur" ou une autre).
                                    Tuto < http://mickael.barroux.free.fr/securite/tutoatfcleaner.html >

                                    4°- Ce qui reste à faire:

                                    A)- Il faut supprimer ce SpywareSecure_trial (cracké).
                                    Prends ce logiciel JV16 gratuit ici: http://telechargement.zebulon.fr/201-jv16-powertools.html
                                    (ATTENTION: à ne pas mettre à jour, car perte de gratuité)

                                    Tu vas dans "outils"/"chercheur de registre",et tu entres le mot SpywareSecure
                                    Tu supprimes tout ce qui se relie à SpywareSecure (tu auras une sauvegarde en cas de pépins)
                                    Ensuite retourne dans "outils"/"chercheur de registre",et tu entres le mot SpywareSecure_trial, et tu fais pareil.
                                    Pour terminer, tu lances la fonction "Nettoyage" et tu supprimes toutes les lignes vertes.

                                    B)- Vas dans "Poste de travail" > C:\ > RECYCLER\ et là, tu vides tout le contenu de la poubelle .

                                    Ensuite, j'ai des doutes sur ceci :
                                    2006-05-28 16:46 397,306 --sha-r C:\Program Files\wunauclt.zip
                                    2006-05-28 16:46 397,306 --sha-r C:\Program Files\wunauclt.tbe
                                    Donc, je préconise ces deux applications qui devrait en venir à bout le cas échéant.

                                    C)- Désinfection 1 :

                                    1)- Télécharge « clean.zip »
                                    < http://www.malekal.com/download/clean.zip >
                                    •- Décompresse-le sur ton bureau (clic droit / extraire tout), tu dois obtenir un dossier dénommé "clean ".
                                    < http://img227.imageshack.us/img227/9384/screenshot149ih1.gif >
                                    2)- •Redémarre en mode sans échec.
                                    Tuto : http://cybersecurite.xooit.com/t88-Demarrer-en-Mode-sans-echec.htm
                                    ( note bien ce que tu as à faire, parce que tu n'auras plus accès à IE durant cette procédure ).
                                    3)- ••- Ouvre le dossier « clean » qui se trouve sur ton bureau.
                                    - Double-clic sur « clean.cmd ».
                                    < http://img525.imageshack.us/img525/6053/screenshot059mn7.png >
                                    Une fenêtre noire va apparaître, suis les consignes
                                    < http://img483.imageshack.us/img483/6285/screenshot210io7.gif >
                                    Choisis l’option 2.
                                    Clean va travailler. Il va produire un rapport.
                                    Redémarre normalement le PC
                                    4)- Il se trouve ici : Clic sur « Poste de travail » , double-clic sur disque « C / » double-clic sur « rapport_clean.txt » en faire un copier/coller.

                                    D)- Désinfection 2 :

                                    Clic sur "Téléchargement du fix en .exe (Last Update): Navilog1.exe"
                                    C'est-à-dire < http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe >
                                    et enregistre-le sur ton bureau.

                                    Ensuite double clique sur l’icône "Navilog1.exe " pour lancer l'installation.
                                    Une fois l'installation terminée, le fix s'exécutera automatiquement.

                                    (Si ce n'est pas le cas, vas dans le poste de travail, en double-cliquant sur le fichier « navilog1.bat » se trouvant dans %program files%Navilog1).

                                    Laisse-toi guider.
                                    Au menu principal, choisis 1 et valide.
                                    (ne fais pas le choix 2,3 ou 4 sans notre avis/accord)

                                    Patiente jusqu'au message :
                                    *** Analyse Termine le ..... ***
                                    Appuie sur une touche comme demandé, le bloc-notes va s'ouvrir.
                                    Copie-colle l'intégralité dans une réponse
                                    . Referme le bloc-notes.

                                    Le rapport est en outre sauvegardé à la racine du disque (fixnavi.txt)

                                    E)- Pour cette valeur à supprimer,
                                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                    "I downloaded pirated Software from P2P "

                                    1°- Sauvegarde de toute la base de registre :
                                    • Cliquez sur Démarrer / Exécuter
                                    • Dans le champ « Ouvrir » tapez : « regedit » et cliquez sur « OK ».
                                    • Ne sélectionnez rien d'autre que ( = mettre en surbrillance ) le « Poste de travail ».
                                    ( Ici, dans la suite logique, le Poste de travail , est celui en tête de la liste des clés du registre ; puisqu’à cette étape, on est dans l’éditeur de registres )
                                    • Dans le menu « Fichier » cliquez sur « Exporter.... »
                                    • Dans « Enregistrer dans », choisissez le dossier de sauvegarde. C’est-à-dire : BUREAU.
                                    • Dans le champ "Nom de fichier" : tapez le nom de votre fichier de sauvegarde. (ex : registre1)
                                    • Dans le champ déroulant Type , choisissez "Fichiers d’enregistrement (*.reg)".
                                    < http://img252.imageshack.us/img252/8522/screenshot258es5.gif >
                                    • Cochez la case ( le bouton ratio ) « Tout ».
                                    • Cliquez sur [Enregistrer]. Puis Quitter le registre.
                                    L'icône du fichier de sauvegarde du Registre est sur le bureau.

                                    2°- Clic "Démarrer" > "Exécuter" > saisir REGEDIT dans "Ouvrir" et valider par [OK]
                                    Dans la colonne de gauche de la page , tu parcoures l'arborescence sous HKLM, (en cliquant sur la case "+" devant HKLM) ==> c'est-à-dire \SOFTWARE > Microsoft > Windows > CurrentVersion > Run
                                    Une fois arrivé à la sous-clé "Run", tu regardes dans la panneau de droite, et tu supprimes (par clic-droit > supprimer) la valeur "I downloaded pirated Software from P2P" (éventuellement sa données "Need for Speed Carbon").
                                    3°- Quitte la BdR (base de registres) et arrête puis redémarre le PC.

                                    F)- Relance SVP une analyse BitDefender Antivirus Plus v10

                                    Merci
                                    Al.
                                    1. Bonjour afideg,
                                      Mon PC se porte mieux,il rame moins.Merci à toi.Voici ce que j'ai fait suite à ton post 30:

                                      A)quarantaine bitdefender vidée
                                      B) OTMoveIt n'a pas pu créer un rapport.
                                      voici ce qu'il y avait d'affiché dans la case "results" de OTMoveIt:

                                      File/Folder C:\WINDOWS\system32\sttss.tmp not found.
                                      File/Folder C:\WINDOWS\system32\sttss.tmp2 not found.
                                      File/Folder C:\Documents and Settings\papa\Mes documents\~WRL0001.tmp not found.
                                      File/Folder C:\Documents and Settings\papa\Mes documents\~WRL{F423F12C-376D-4F06-90A5-FC9D2500A70F}.tmp not found.
                                      File/Folder C:\Documents and Settings\All Users\DRM\Cache\Indiv02.tmp not found.
                                      File/Folder C:\Documents and Settings\élodie\Local Settings\Temp\ttstv.tmp not found.
                                      File/Folder C:\Documents and Settings\élodie\Application Data\Microsoft\Word\~WRL2443.tmp not found.
                                      File/Folder C:\ Documents and Settings\steven\ Local Settings\Temp\~DFA81B.tmp not found.
                                      File/Folder C:\WINDOWS\Temp\tmp00001af8 not found.

                                      Created on 10/25/2007 10:37:37

                                      D)voici les résultats des analyses virustotal:
                                      Fichier wunauclt.zip:

                                      Fichier wunauclt.zip reçu le 2007.10.25 10:46:25 (CET)
                                      Résultat: 3/31 (9.68%)

                                      Antivirus Version Dernière mise à jour Résultat
                                      AhnLab-V3 2007.10.25.0 2007.10.25 -
                                      AntiVir 7.6.0.27 2007.10.25 -
                                      Authentium 4.93.8 2007.10.24 -
                                      Avast 4.7.1074.0 2007.10.25 -
                                      AVG 7.5.0.488 2007.10.24 -
                                      BitDefender 7.2 2007.10.25 -
                                      CAT-QuickHeal 9.00 2007.10.23 -
                                      ClamAV 0.91.2 2007.10.25 -
                                      DrWeb 4.44.0.09170 2007.10.25 -
                                      eSafe 7.0.15.0 2007.10.22 -
                                      eTrust-Vet 31.2.5241 2007.10.25 -
                                      Ewido 4.0 2007.10.24 -
                                      FileAdvisor 1 2007.10.25 -
                                      Fortinet 3.11.0.0 2007.10.19 W32/Istbar.ZE!tr.dldr
                                      F-Prot 4.3.2.48 2007.10.24 -
                                      F-Secure 6.70.13030.0 2007.10.25 -
                                      Ikarus T3.1.1.12 2007.10.25 -
                                      Kaspersky 7.0.0.125 2007.10.25 -
                                      McAfee 5148 2007.10.24 -
                                      Microsoft 1.2908 2007.10.25 -
                                      NOD32v2 2614 2007.10.24 error - password-protected file
                                      Norman 5.80.02 2007.10.24 -
                                      Panda 9.0.0.4 2007.10.25 -
                                      Prevx1 V2 2007.10.25 Prevx Database Unreachable
                                      Rising 19.46.31.00 2007.10.25 -
                                      Sophos 4.22.0 2007.10.25 -
                                      Sunbelt 2.2.907.0 2007.10.24 -
                                      Symantec 10 2007.10.25 -
                                      TheHacker 6.2.9.107 2007.10.25 -
                                      VBA32 3.12.2.4 2007.10.24 -
                                      VirusBuster 4.3.26:9 2007.10.24 -

                                      Information additionnelle
                                      File size: 397306 bytes
                                      MD5: 6d4eb20dfacbd62c0db9ec6c14a9dfe1
                                      SHA1: 5139a39415d9acc369f3cab5459f39e271517060

                                      le fichier IEXPLORE.EXE:

                                      Fichier IEXPLORE.EXE reçu le 2007.10.25 10:58:07 (CET)
                                      Situation actuelle: en cours de chargement ... mis en file d'attente en attente en cours d'analyse terminé
                                      Résultat: 0/32 (0%)

                                      Antivirus Version Dernière mise à jour Résultat
                                      AhnLab-V3 2007.10.25.0 2007.10.25 -
                                      AntiVir 7.6.0.27 2007.10.25 -
                                      Authentium 4.93.8 2007.10.24 -
                                      Avast 4.7.1074.0 2007.10.25 -
                                      AVG 7.5.0.488 2007.10.24 -
                                      BitDefender 7.2 2007.10.25 -
                                      CAT-QuickHeal 9.00 2007.10.23 -
                                      ClamAV 0.91.2 2007.10.25 -
                                      DrWeb 4.44.0.09170 2007.10.25 -
                                      eSafe 7.0.15.0 2007.10.22 -
                                      eTrust-Vet 31.2.5241 2007.10.25 -
                                      Ewido 4.0 2007.10.24 -
                                      FileAdvisor 1 2007.10.25 -
                                      Fortinet 3.11.0.0 2007.10.19 -
                                      F-Prot 4.3.2.48 2007.10.24 -
                                      F-Secure 6.70.13030.0 2007.10.25 -
                                      Ikarus T3.1.1.12 2007.10.25 -
                                      Kaspersky 7.0.0.125 2007.10.25 -
                                      McAfee 5148 2007.10.24 -
                                      Microsoft 1.2908 2007.10.25 -
                                      NOD32v2 2614 2007.10.24 -
                                      Norman 5.80.02 2007.10.24 -
                                      Panda 9.0.0.4 2007.10.25 -
                                      Prevx1 V2 2007.10.25 -
                                      Rising 19.46.31.00 2007.10.25 -
                                      Sophos 4.22.0 2007.10.25 -
                                      Sunbelt 2.2.907.0 2007.10.24 -
                                      Symantec 10 2007.10.25 -
                                      TheHacker 6.2.9.107 2007.10.25 -
                                      VBA32 3.12.2.4 2007.10.24 -
                                      VirusBuster 4.3.26:9 2007.10.24 -
                                      Webwasher-Gateway 6.6.1 2007.10.25 -

                                      Information additionnelle
                                      File size: 93184 bytes
                                      MD5: 833e2b3f0e2484c0f2b804ae871b4381
                                      SHA1: 94379b749122578362e923e5039b0c43820b3c0f

                                      et pour finir le fichier DRMv1.bak:

                                      Fichier DRMv1.bak reçu le 2007.10.25 11:05:20 (CET)
                                      Situation actuelle: en cours de chargement ... mis en file d'attente en attente en cours d'analyse terminé
                                      Résultat: 0/32 (0%)

                                      Antivirus Version Dernière mise à jour Résultat
                                      AhnLab-V3 2007.10.25.0 2007.10.25 -
                                      AntiVir 7.6.0.27 2007.10.25 -
                                      Authentium 4.93.8 2007.10.24 -
                                      Avast 4.7.1074.0 2007.10.25 -
                                      AVG 7.5.0.488 2007.10.24 -
                                      BitDefender 7.2 2007.10.25 -
                                      CAT-QuickHeal 9.00 2007.10.23 -
                                      ClamAV 0.91.2 2007.10.25 -
                                      DrWeb 4.44.0.09170 2007.10.25 -
                                      eSafe 7.0.15.0 2007.10.22 -
                                      eTrust-Vet 31.2.5241 2007.10.25 -
                                      Ewido 4.0 2007.10.24 -
                                      FileAdvisor 1 2007.10.25 -
                                      Fortinet 3.11.0.0 2007.10.19 -
                                      F-Prot 4.3.2.48 2007.10.24 -
                                      F-Secure 6.70.13030.0 2007.10.25 -
                                      Ikarus T3.1.1.12 2007.10.25 -
                                      Kaspersky 7.0.0.125 2007.10.25 -
                                      McAfee 5148 2007.10.24 -
                                      Microsoft 1.2908 2007.10.25 -
                                      NOD32v2 2614 2007.10.24 -
                                      Norman 5.80.02 2007.10.24 -
                                      Panda 9.0.0.4 2007.10.25 -
                                      Prevx1 V2 2007.10.25 -
                                      Rising 19.46.31.00 2007.10.25 -
                                      Sophos 4.22.0 2007.10.25 -
                                      Sunbelt 2.2.907.0 2007.10.24 -
                                      Symantec 10 2007.10.25 -
                                      TheHacker 6.2.9.107 2007.10.25 -
                                      VBA32 3.12.2.4 2007.10.24 -
                                      VirusBuster 4.3.26:9 2007.10.24 -
                                      Webwasher-Gateway 6.6.1 2007.10.25 -

                                      Information additionnelle
                                      File size: 4348 bytes
                                      MD5: 3e892a1151da6eda2deb7c6dbd26a98e
                                      SHA1: 95dbe44543e7ea321d989538bd34512bfc2f8170

                                      E)le rapport du "Full system scan" (différent du Deep scan) bitdefender:

                                      //-----------------------------------------------------------------
                                      //
                                      // Product BitDefender Antivirus Plus v10
                                      // Product 10.2
                                      //
                                      // Created on: 25/10/2007 11:12:40
                                      //
                                      //-----------------------------------------------------------------

                                      Virus Statistics

                                      Scan path : C:\
                                      D:\
                                      E:\
                                      Folders : 10776
                                      Files : 299967
                                      Memory processes scanned : 49
                                      Archives : 4020
                                      Runtime packers : 10040
                                      Identified viruses : 2
                                      Infected files : 33
                                      Memory processes infected : 0
                                      Suspect files : 0
                                      Warnings : 0
                                      Disinfected files : 0
                                      Deleted files : 0
                                      Moved files : 0
                                      I/O errors : 151
                                      Scan time : 00:52:37
                                      Scan speed (files/sec) : 95

                                      Spyware Statistics

                                      Registry keys scanned : 1827
                                      Registry keys infected : 0
                                      Cookies scanned : 101
                                      Cookies infected : 0
                                      Spyware files infected : 0
                                      Spyware threats detected : 0

                                      Virus definitions : 935253
                                      Scan plugins : 16
                                      Archive plugins : 41
                                      Unpack plugins : 7
                                      Mail plugins : 6
                                      System plugins : 5

                                      Virus scan options

                                      Detection
                                      [X] Scan boot sectors
                                      [X] Memory Processes
                                      [X] Scan archives
                                      [X] Scan runtime packers
                                      [X] Scan email

                                      File mask
                                      [ ] Programs
                                      [X] All files
                                      [ ] User defined extensions:
                                      [ ] Exclude extensions: ;

                                      Action

                                      Infected objects
                                      [ ] Ignore
                                      [X] Disinfect
                                      [ ] Delete
                                      [ ] Move to quarantine
                                      [ ] Prompt user

                                      Second action
                                      [ ] Ignore
                                      [ ] Delete
                                      [X] Move to quarantine
                                      [ ] Prompt user

                                      Virus scan options
                                      [X] Enable warnings
                                      [X] Enable heuristics
                                      [ ] Show all files in log
                                      [X] Report file: C:\Documents and Settings\All Users\Application Data\Bitdefender\Desktop\Profiles\Logs\full_scan\1193303560.log

                                      Spyware scan options

                                      [X] Scan for riskware
                                      [ ] Skip dial and applications from scan
                                      [X] Registry keys
                                      [X] Cookies

                                      Summary:

                                      C:\Documents and Settings\élodie\Bureau\SpywareSecure_trial_setup(2).exe=>(NSIS 2o)=>lzma_solid_nsis0005 Detected: Adware.Navipromo.GO
                                      C:\Documents and Settings\élodie\Bureau\SpywareSecure_trial_setup(2).exe=>(NSIS 2o)=>lzma_solid_nsis0005 Disinfection failed
                                      C:\Documents and Settings\élodie\Bureau\SpywareSecure_trial_setup(2).exe=>(NSIS 2o)=>lzma_solid_nsis0005 Move failed
                                      C:\Documents and Settings\élodie\Bureau\SpywareSecure_trial_setup(2).exe=>(NSIS 2o)=>lzma_solid_nsis0009 Detected: Adware.Navipromo.BXQ
                                      C:\Documents and Settings\élodie\Bureau\SpywareSecure_trial_setup(2).exe=>(NSIS 2o)=>lzma_solid_nsis0009 Disinfection failed
                                      C:\Documents and Settings\élodie\Bureau\SpywareSecure_trial_setup(2).exe=>(NSIS 2o)=>lzma_solid_nsis0009 Move failed
                                      C:\Documents and Settings\élodie\Bureau\SpywareSecure_trial_setup(2).exe=>(NSIS 2o)=>lzma_solid_nsis0013=>(NSIS g)=>lzma_solid_nsis0002 Detected: Adware.Navipromo.GO
                                      C:\Documents and Settings\élodie\Bureau\SpywareSecure_trial_setup(2).exe=>(NSIS 2o)=>lzma_solid_nsis0013=>(NSIS g)=>lzma_solid_nsis0002 Disinfection failed
                                      C:\Documents and Settings\élodie\Bureau\SpywareSecure_trial_setup(2).exe=>(NSIS 2o)=>lzma_solid_nsis0013=>(NSIS g)=>lzma_solid_nsis0002 Move failed
                                      C:\Documents and Settings\élodie\Bureau\SpywareSecure_trial_setup(3).exe=>(NSIS 2o)=>lzma_solid_nsis0005 Detected: Adware.Navipromo.GO
                                      C:\Documents and Settings\élodie\Bureau\SpywareSecure_trial_setup(3).exe=>(NSIS 2o)=>lzma_solid_nsis0005 Disinfection failed
                                      C:\Documents and Settings\élodie\Bureau\SpywareSecure_trial_setup(3).exe=>(NSIS 2o)=>lzma_solid_nsis0005 Move failed
                                      C:\Documents and Settings\élodie\Bureau\SpywareSecure_trial_setup(3).exe=>(NSIS 2o)=>lzma_solid_nsis0009 Detected: Adware.Navipromo.BXQ
                                      C:\Documents and Settings\élodie\Bureau\SpywareSecure_trial_setup(3).exe=>(NSIS 2o)=>lzma_solid_nsis0009 Disinfection failed
                                      C:\Documents and Settings\élodie\Bureau\SpywareSecure_trial_setup(3).exe=>(NSIS 2o)=>lzma_solid_nsis0009 Move failed
                                      C:\Documents and Settings\élodie\Bureau\SpywareSecure_trial_setup(3).exe=>(NSIS 2o)=>lzma_solid_nsis0013=>(NSIS g)=>lzma_solid_nsis0002 Detected: Adware.Navipromo.GO
                                      C:\Documents and Settings\élodie\Bureau\SpywareSecure_trial_setup(3).exe=>(NSIS 2o)=>lzma_solid_nsis0013=>(NSIS g)=>lzma_solid_nsis0002 Disinfection failed
                                      C:\Documents and Settings\élodie\Bureau\SpywareSecure_trial_setup(3).exe=>(NSIS 2o)=>lzma_solid_nsis0013=>(NSIS g)=>lzma_solid_nsis0002 Move failed
                                      C:\Documents and Settings\élodie\Bureau\SpywareSecure_trial_setup(4).exe=>(NSIS 2o)=>lzma_solid_nsis0005 Detected: Adware.Navipromo.GO
                                      C:\Documents and Settings\élodie\Bureau\SpywareSecure_trial_setup(4).exe=>(NSIS 2o)=>lzma_solid_nsis0005 Disinfection failed
                                      C:\Documents and Settings\élodie\Bureau\SpywareSecure_trial_setup(4).exe=>(NSIS 2o)=>lzma_solid_nsis0005 Move failed
                                      C:\Documents and Settings\élodie\Bureau\SpywareSecure_trial_setup(4).exe=>(NSIS 2o)=>lzma_solid_nsis0009 Detected: Adware.Navipromo.BXQ
                                      C:\Documents and Settings\élodie\Bureau\SpywareSecure_trial_setup(4).exe=>(NSIS 2o)=>lzma_solid_nsis0009 Disinfection failed
                                      C:\Documents and Settings\élodie\Bureau\SpywareSecure_trial_setup(4).exe=>(NSIS 2o)=>lzma_solid_nsis0009 Move failed
                                      C:\Documents and Settings\élodie\Bureau\SpywareSecure_trial_setup(4).exe=>(NSIS 2o)=>lzma_solid_nsis0013=>(NSIS g)=>lzma_solid_nsis0002 Detected: Adware.Navipromo.GO
                                      C:\Documents and Settings\élodie\Bureau\SpywareSecure_trial_setup(4).exe=>(NSIS 2o)=>lzma_solid_nsis0013=>(NSIS g)=>lzma_solid_nsis0002 Disinfection failed
                                      C:\Documents and Settings\élodie\Bureau\SpywareSecure_trial_setup(4).exe=>(NSIS 2o)=>lzma_solid_nsis0013=>(NSIS g)=>lzma_solid_nsis0002 Move failed
                                      C:\Documents and Settings\élodie\Bureau\SpywareSecure_trial_setup.exe=>(NSIS 2o)=>lzma_solid_nsis0005 Detected: Adware.Navipromo.GO
                                      C:\Documents and Settings\élodie\Bureau\SpywareSecure_trial_setup.exe=>(NSIS 2o)=>lzma_solid_nsis0005 Disinfection failed
                                      C:\Documents and Settings\élodie\Bureau\SpywareSecure_trial_setup.exe=>(NSIS 2o)=>lzma_solid_nsis0005 Move failed
                                      C:\Documents and Settings\élodie\Bureau\SpywareSecure_trial_setup.exe=>(NSIS 2o)=>lzma_solid_nsis0009 Detected: Adware.Navipromo.BXQ
                                      C:\Documents and Settings\élodie\Bureau\SpywareSecure_trial_setup.exe=>(NSIS 2o)=>lzma_solid_nsis0009 Disinfection failed
                                      C:\Documents and Settings\élodie\Bureau\SpywareSecure_trial_setup.exe=>(NSIS 2o)=>lzma_solid_nsis0009 Move failed
                                      C:\Documents and Settings\élodie\Bureau\SpywareSecure_trial_setup.exe=>(NSIS 2o)=>lzma_solid_nsis0013=>(NSIS g)=>lzma_solid_nsis0002 Detected: Adware.Navipromo.GO
                                      C:\Documents and Settings\élodie\Bureau\SpywareSecure_trial_setup.exe=>(NSIS 2o)=>lzma_solid_nsis0013=>(NSIS g)=>lzma_solid_nsis0002 Disinfection failed
                                      C:\Documents and Settings\élodie\Bureau\SpywareSecure_trial_setup.exe=>(NSIS 2o)=>lzma_solid_nsis0013=>(NSIS g)=>lzma_solid_nsis0002 Move failed
                                      C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc77.exe=>(NSIS 2o)=>lzma_solid_nsis0005 Detected: Adware.Navipromo.GO
                                      C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc77.exe=>(NSIS 2o)=>lzma_solid_nsis0005 Disinfection failed
                                      C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc77.exe=>(NSIS 2o)=>lzma_solid_nsis0005 Move failed
                                      C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc77.exe=>(NSIS 2o)=>lzma_solid_nsis0009 Detected: Adware.Navipromo.BXQ
                                      C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc77.exe=>(NSIS 2o)=>lzma_solid_nsis0009 Disinfection failed
                                      C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc77.exe=>(NSIS 2o)=>lzma_solid_nsis0009 Move failed
                                      C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc77.exe=>(NSIS 2o)=>lzma_solid_nsis0013=>(NSIS g)=>lzma_solid_nsis0002 Detected: Adware.Navipromo.GO
                                      C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc77.exe=>(NSIS 2o)=>lzma_solid_nsis0013=>(NSIS g)=>lzma_solid_nsis0002 Disinfection failed
                                      C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc77.exe=>(NSIS 2o)=>lzma_solid_nsis0013=>(NSIS g)=>lzma_solid_nsis0002 Move failed
                                      C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc78.exe=>(NSIS 2o)=>lzma_solid_nsis0005 Detected: Adware.Navipromo.GO
                                      C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc78.exe=>(NSIS 2o)=>lzma_solid_nsis0005 Disinfection failed
                                      C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc78.exe=>(NSIS 2o)=>lzma_solid_nsis0005 Move failed
                                      C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc78.exe=>(NSIS 2o)=>lzma_solid_nsis0009 Detected: Adware.Navipromo.BXQ
                                      C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc78.exe=>(NSIS 2o)=>lzma_solid_nsis0009 Disinfection failed
                                      C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc78.exe=>(NSIS 2o)=>lzma_solid_nsis0009 Move failed
                                      C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc78.exe=>(NSIS 2o)=>lzma_solid_nsis0013=>(NSIS g)=>lzma_solid_nsis0002 Detected: Adware.Navipromo.GO
                                      C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc78.exe=>(NSIS 2o)=>lzma_solid_nsis0013=>(NSIS g)=>lzma_solid_nsis0002 Disinfection failed
                                      C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc78.exe=>(NSIS 2o)=>lzma_solid_nsis0013=>(NSIS g)=>lzma_solid_nsis0002 Move failed
                                      C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc79.exe=>(NSIS 2o)=>lzma_solid_nsis0005 Detected: Adware.Navipromo.GO
                                      C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc79.exe=>(NSIS 2o)=>lzma_solid_nsis0005 Disinfection failed
                                      C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc79.exe=>(NSIS 2o)=>lzma_solid_nsis0005 Move failed
                                      C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc79.exe=>(NSIS 2o)=>lzma_solid_nsis0009 Detected: Adware.Navipromo.BXQ
                                      C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc79.exe=>(NSIS 2o)=>lzma_solid_nsis0009 Disinfection failed
                                      C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc79.exe=>(NSIS 2o)=>lzma_solid_nsis0009 Move failed
                                      C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc79.exe=>(NSIS 2o)=>lzma_solid_nsis0013=>(NSIS g)=>lzma_solid_nsis0002 Detected: Adware.Navipromo.GO
                                      C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc79.exe=>(NSIS 2o)=>lzma_solid_nsis0013=>(NSIS g)=>lzma_solid_nsis0002 Disinfection failed
                                      C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc79.exe=>(NSIS 2o)=>lzma_solid_nsis0013=>(NSIS g)=>lzma_solid_nsis0002 Move failed
                                      C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc80.exe=>(NSIS 2o)=>lzma_solid_nsis0005 Detected: Adware.Navipromo.GO
                                      C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc80.exe=>(NSIS 2o)=>lzma_solid_nsis0005 Disinfection failed
                                      C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc80.exe=>(NSIS 2o)=>lzma_solid_nsis0005 Move failed
                                      C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc80.exe=>(NSIS 2o)=>lzma_solid_nsis0009 Detected: Adware.Navipromo.BXQ
                                      C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc80.exe=>(NSIS 2o)=>lzma_solid_nsis0009 Disinfection failed
                                      C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc80.exe=>(NSIS 2o)=>lzma_solid_nsis0009 Move failed
                                      C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc80.exe=>(NSIS 2o)=>lzma_solid_nsis0013=>(NSIS g)=>lzma_solid_nsis0002 Detected: Adware.Navipromo.GO
                                      C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc80.exe=>(NSIS 2o)=>lzma_solid_nsis0013=>(NSIS g)=>lzma_solid_nsis0002 Disinfection failed
                                      C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc80.exe=>(NSIS 2o)=>lzma_solid_nsis0013=>(NSIS g)=>lzma_solid_nsis0002 Move failed
                                      C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc81.exe=>(NSIS 2o)=>lzma_solid_nsis0005 Detected: Adware.Navipromo.GO
                                      C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc81.exe=>(NSIS 2o)=>lzma_solid_nsis0005 Disinfection failed
                                      C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc81.exe=>(NSIS 2o)=>lzma_solid_nsis0005 Move failed
                                      C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc81.exe=>(NSIS 2o)=>lzma_solid_nsis0009 Detected: Adware.Navipromo.BXQ
                                      C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc81.exe=>(NSIS 2o)=>lzma_solid_nsis0009 Disinfection failed
                                      C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc81.exe=>(NSIS 2o)=>lzma_solid_nsis0009 Move failed
                                      C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc81.exe=>(NSIS 2o)=>lzma_solid_nsis0013=>(NSIS g)=>lzma_solid_nsis0002 Detected: Adware.Navipromo.GO
                                      C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc81.exe=>(NSIS 2o)=>lzma_solid_nsis0013=>(NSIS g)=>lzma_solid_nsis0002 Disinfection failed
                                      C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc81.exe=>(NSIS 2o)=>lzma_solid_nsis0013=>(NSIS g)=>lzma_solid_nsis0002 Move failed
                                      C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc82.exe=>(NSIS 2o)=>lzma_solid_nsis0005 Detected: Adware.Navipromo.GO
                                      C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc82.exe=>(NSIS 2o)=>lzma_solid_nsis0005 Disinfection failed
                                      C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc82.exe=>(NSIS 2o)=>lzma_solid_nsis0005 Move failed
                                      C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc82.exe=>(NSIS 2o)=>lzma_solid_nsis0009 Detected: Adware.Navipromo.BXQ
                                      C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc82.exe=>(NSIS 2o)=>lzma_solid_nsis0009 Disinfection failed
                                      C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc82.exe=>(NSIS 2o)=>lzma_solid_nsis0009 Move failed
                                      C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc82.exe=>(NSIS 2o)=>lzma_solid_nsis0013=>(NSIS g)=>lzma_solid_nsis0002 Detected: Adware.Navipromo.GO
                                      C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc82.exe=>(NSIS 2o)=>lzma_solid_nsis0013=>(NSIS g)=>lzma_solid_nsis0002 Disinfection failed
                                      C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc82.exe=>(NSIS 2o)=>lzma_solid_nsis0013=>(NSIS g)=>lzma_solid_nsis0002 Move failed
                                      C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc83.exe=>(NSIS 2o)=>lzma_solid_nsis0005 Detected: Adware.Navipromo.GO
                                      C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc83.exe=>(NSIS 2o)=>lzma_solid_nsis0005 Disinfection failed
                                      C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc83.exe=>(NSIS 2o)=>lzma_solid_nsis0005 Move failed
                                      C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc83.exe=>(NSIS 2o)=>lzma_solid_nsis0009 Detected: Adware.Navipromo.BXQ
                                      C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc83.exe=>(NSIS 2o)=>lzma_solid_nsis0009 Disinfection failed
                                      C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc83.exe=>(NSIS 2o)=>lzma_solid_nsis0009 Move failed
                                      C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc83.exe=>(NSIS 2o)=>lzma_solid_nsis0013=>(NSIS g)=>lzma_solid_nsis0002 Detected: Adware.Navipromo.GO
                                      C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc83.exe=>(NSIS 2o)=>lzma_solid_nsis0013=>(NSIS g)=>lzma_solid_nsis0002 Disinfection failed
                                      C:\RECYCLER\S-1-5-21-1708537768-484763869-725345543-1004\Dc83.exe=>(NSIS 2o)=>lzma_solid_nsis0013=>(NSIS g)=>lzma_solid_nsis0002 Move failed

                                      F) et enfin le rapport combofix:
                                      Il semblerait qu'un fichier de combofix soit infecté (Cfiles.dat)

                                      ComboFix 07-10-20.6 - steven 2007-10-25 12:12:12.2 - NTFSx86
                                      Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.1447 [GMT 2:00]
                                      Running from: C:\Documents and Settings\steven\Bureau\ComboFix.exe
                                      .

                                      ((((((((((((((((((((((((((((( Fichiers créés 2007-09-25 to 2007-10-25 ))))))))))))))))))))))))))))))))))))
                                      .

                                      2007-10-25 12:10 51,200 --a------ C:\WINDOWS\NirCmd.exe
                                      2007-10-24 20:57 2,614,322 --a------ C:\upload_moi.zip
                                      2007-10-24 19:44 <REP> d-------- C:\WINDOWS\ERUNT
                                      2007-10-20 10:34 <REP> d-------- C:\[DVD-R]Top 50 of HARIHARAN [Compress]
                                      2007-10-19 18:59 0 --a------ C:\WINDOWS\ativpsrm.bin
                                      2007-10-19 18:55 593,920 --------- C:\WINDOWS\system32\ati2sgag.exe
                                      2007-10-13 00:09 <REP> d-------- C:\Program Files\SpywareBlaster
                                      2007-10-12 19:40 <REP> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
                                      2007-10-12 19:36 626,688 --a------ C:\WINDOWS\system32\msvcr80.dll
                                      2007-10-12 19:33 164 --a------ C:\install.dat
                                      2007-10-12 19:30 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Prevx
                                      2007-10-10 21:28 <REP> d-------- C:\Program Files\Hitman Pro
                                      2007-10-05 18:56 470,048 --a------ C:\WINDOWS\system32\drivers\ar5211.sys
                                      2007-10-05 18:56 470,048 --a------ C:\WINDOWS\system32\ar5211.sys
                                      2007-10-05 18:40 <REP> d-------- C:\Program Files\RALINK
                                      2007-10-05 18:40 <REP> d-------- C:\Documents and Settings\steven\Application Data\InstallShield
                                      2007-10-05 17:44 385,024 --a------ C:\WINDOWS\system32\athcfg11.dll
                                      2007-10-05 17:44 249,856 --a------ C:\WINDOWS\system32\wgapi.dll
                                      2007-10-05 17:44 237,568 --a------ C:\WINDOWS\system32\wcapi.dll
                                      2007-10-05 17:44 77,824 --a------ C:\WINDOWS\system32\athcfg11res.dll
                                      2007-10-05 17:44 36,864 --a------ C:\WINDOWS\system32\acs.exe
                                      2007-10-05 17:44 21,419 --a------ C:\WINDOWS\system32\drivers\AegisP.sys
                                      2007-10-05 16:45 1,396,835 --a------ C:\WINDOWS\system32\AegisE5.dll
                                      2007-10-05 16:45 315,392 --a------ C:\WINDOWS\system32\AegisI5.exe
                                      2007-10-03 20:30 <REP> d-------- C:\Program Files\Neuf
                                      2007-10-02 22:11 <REP> d-------- C:\Documents and Settings\delphine\Application Data\Bitdefender
                                      2007-10-02 21:41 <REP> d-------- C:\Documents and Settings\papa\Application Data\Bitdefender
                                      2007-10-02 21:02 81,984 --a------ C:\WINDOWS\system32\bdod.bin
                                      2007-10-02 20:35 <REP> d-------- C:\Documents and Settings\steven\Application Data\Bitdefender
                                      2007-10-02 20:34 <REP> d-------- C:\Documents and Settings\All Users\Application Data\BitDefender
                                      2007-10-02 20:32 <REP> d-------- C:\bitdefender
                                      2007-10-02 20:26 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Avg7
                                      2007-10-02 18:49 4,130 --a------ C:\WINDOWS\system32\tmp.reg
                                      2007-10-02 18:48 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
                                      2007-10-02 18:48 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
                                      2007-10-02 18:48 53,248 --a------ C:\WINDOWS\system32\Process.exe
                                      2007-10-02 18:48 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
                                      2007-10-02 18:48 25,088 --a------ C:\WINDOWS\system32\WS2Fix.exe
                                      2007-09-30 15:39 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
                                      2007-09-30 10:38 <REP> d-------- C:\Documents and Settings\steven\Application Data\Samsung
                                      2007-09-30 10:35 174,592 --a------ C:\WINDOWS\system32\framedyn.dll
                                      2007-09-30 10:34 5,632 --a------ C:\WINDOWS\system32\drivers\StarOpen.sys
                                      2007-09-30 10:33 <REP> d-------- C:\WINDOWS\system32\Samsung_USB_Drivers
                                      2007-09-30 10:33 <REP> d-------- C:\Program Files\Samsung
                                      2007-09-30 10:33 94,000 --a------ C:\WINDOWS\system32\drivers\ssm_mdm.sys
                                      2007-09-30 10:33 58,320 --a------ C:\WINDOWS\system32\drivers\ssm_bus.sys
                                      2007-09-30 10:33 8,336 --a------ C:\WINDOWS\system32\drivers\ssm_mdfl.sys
                                      2007-09-30 10:33 6,176 --a------ C:\WINDOWS\system32\drivers\ssm_cmnt.sys
                                      2007-09-30 10:33 6,176 --a------ C:\WINDOWS\system32\drivers\ssm_cm.sys
                                      2007-09-30 10:33 5,840 --a------ C:\WINDOWS\system32\drivers\ssm_whnt.sys
                                      2007-09-30 10:33 5,840 --a------ C:\WINDOWS\system32\drivers\ssm_wh.sys
                                      2007-09-29 09:56 <REP> d-------- C:\Documents and Settings\steven\Application Data\CyberLink
                                      2007-09-29 09:52 <REP> d-------- C:\Documents and Settings\All Users\Application Data\CyberLink
                                      2007-09-29 05:21 9,854,976 --a------ C:\WINDOWS\system32\atioglx2.dll
                                      2007-09-29 05:07 356,352 --a------ C:\WINDOWS\system32\ATIDEMGX.dll
                                      2007-09-29 04:58 143,360 --a------ C:\WINDOWS\system32\atipdlxx.dll
                                      2007-09-29 04:58 26,112 --a------ C:\WINDOWS\system32\Ati2mdxx.exe
                                      2007-09-29 04:55 53,248 --a------ C:\WINDOWS\system32\ATIDDC.DLL
                                      2007-09-29 04:49 307,200 --a------ C:\WINDOWS\system32\atiiiexx.dll
                                      2007-09-29 04:47 172,032 --a------ C:\WINDOWS\system32\atiok3x2.dll
                                      2007-09-29 04:36 3,107,788 --a------ C:\WINDOWS\system32\ativvaxx.dat
                                      2007-09-29 04:36 3,107,788 --a------ C:\WINDOWS\system32\ativva5x.dat
                                      2007-09-29 04:36 972,072 --a------ C:\WINDOWS\system32\ativva6x.dat
                                      2007-09-29 04:23 5,435,392 --a------ C:\WINDOWS\system32\atioglxx.dll
                                      2007-09-29 04:20 17,408 --a------ C:\WINDOWS\system32\atitvo32.dll
                                      2007-09-28 22:02 <REP> d-------- C:\Program Files\CyberLink
                                      2007-09-28 21:42 <REP> d-------- C:\Cyberlink.PowerDVD.Ultra.Deluxe.v7.3.Multilingual.Incl.Keygen-ViRiLiTY
                                      2007-09-28 19:11 2,560 --a------ C:\WINDOWS\system32\bitcometres.dll
                                      2007-09-26 22:29 <REP> d-------- C:\divx

                                      .
                                      (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                                      .
                                      2007-10-21 17:59 5,767,168 ----a-w C:\Documents and Settings\élodie\NTUSER.DAT
                                      2007-10-21 10:00 --------- d-----w C:\Program Files\Java
                                      2007-10-21 09:53 --------- d-----w C:\Program Files\Fichiers communs\Adobe
                                      2007-10-19 20:30 --------- d-----w C:\Program Files\Logitech
                                      2007-10-19 16:57 --------- d-----w C:\Program Files\ATI Technologies
                                      2007-10-19 16:56 --------- d--h--w C:\Program Files\InstallShield Installation Information
                                      2007-10-12 23:19 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
                                      2007-10-12 22:13 --------- d-----w C:\Documents and Settings\steven\Application Data\Lavasoft
                                      2007-10-12 22:09 --------- d-----w C:\Program Files\Lavasoft
                                      2007-10-12 19:23 --------- d-----w C:\Documents and Settings\steven\Application Data\Winamp
                                      2007-10-11 12:58 --------- d-----w C:\Documents and Settings\delphine\Application Data\Winamp
                                      2007-10-10 20:46 --------- d-----w C:\Program Files\MSI
                                      2007-10-10 19:15 --------- d-----w C:\Program Files\Winamp
                                      2007-10-02 13:31 --------- d-----w C:\Documents and Settings\All Users\Application Data\Grisoft
                                      2007-09-30 15:58 78,415 ----a-w C:\WINDOWS\system32\drivers\klif.cab
                                      2007-09-30 07:56 --------- d-----w C:\Program Files\Fichiers communs\Wise Installation Wizard
                                      2007-09-30 07:29 --------- d-----w C:\Program Files\Antipub
                                      2007-09-29 14:55 --------- d-----w C:\Program Files\BitComet
                                      2007-09-29 09:58 359,808 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
                                      2007-09-29 05:46 47,376 ----a-w C:\WINDOWS\system32\drivers\ativvpxx.vp
                                      2007-09-29 03:06 268,800 ----a-w C:\WINDOWS\system32\ati2dvag.dll
                                      2007-09-29 03:05 2,456,064 ----a-w C:\WINDOWS\system32\drivers\ati2mtag.sys
                                      2007-09-29 02:58 43,520 ----a-w C:\WINDOWS\system32\ati2edxx.dll
                                      2007-09-29 02:58 122,880 ----a-w C:\WINDOWS\system32\Oemdspif.dll
                                      2007-09-29 02:57 122,880 ----a-w C:\WINDOWS\system32\ati2evxx.dll
                                      2007-09-29 02:56 483,328 ----a-w C:\WINDOWS\system32\ati2evxx.exe
                                      2007-09-29 02:47 3,130,720 ----a-w C:\WINDOWS\system32\ati3duag.dll
                                      2007-09-29 02:36 1,593,600 ----a-w C:\WINDOWS\system32\ativvaxx.dll
                                      2007-09-29 02:22 376,832 ----a-w C:\WINDOWS\system32\atikvmag.dll
                                      2007-09-29 02:19 49,152 ----a-w C:\WINDOWS\system32\drivers\ati2erec.dll
                                      2007-09-29 02:14 499,712 ----a-w C:\WINDOWS\system32\ati2cqag.dll
                                      2007-09-28 17:55 --------- d-----w C:\Program Files\DivX
                                      2007-09-28 15:23 --------- d-----w C:\Program Files\eMule
                                      2007-09-17 18:23 823,296 ----a-w C:\WINDOWS\system32\divx_xx0c.dll
                                      2007-09-17 18:23 823,296 ----a-w C:\WINDOWS\system32\divx_xx07.dll
                                      2007-09-17 18:22 802,816 ----a-w C:\WINDOWS\system32\divx_xx11.dll
                                      2007-09-17 18:22 739,840 ----a-w C:\WINDOWS\system32\DivX.dll
                                      2007-09-11 23:14 156,992 ----a-w C:\WINDOWS\system32\DivXCodecVersionChecker.exe
                                      2007-08-21 00:26 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll
                                      2007-08-21 00:26 196,608 ----a-w C:\WINDOWS\system32\dtu100.dll
                                      2007-08-15 22:33 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe
                                      2007-08-15 22:33 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
                                      2007-08-15 22:33 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
                                      2007-08-15 22:33 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
                                      2007-08-15 22:31 593,920 ----a-w C:\WINDOWS\system32\dpuGUI11.dll
                                      2007-08-15 22:31 57,344 ----a-w C:\WINDOWS\system32\dpv11.dll
                                      2007-08-15 22:31 53,248 ----a-w C:\WINDOWS\system32\dpuGUI10.dll
                                      2007-08-15 22:31 344,064 ----a-w C:\WINDOWS\system32\dpus11.dll
                                      2007-08-15 22:31 294,912 ----a-w C:\WINDOWS\system32\dpu11.dll
                                      2007-08-15 22:31 294,912 ----a-w C:\WINDOWS\system32\dpu10.dll
                                      2007-08-15 22:30 12,288 ----a-w C:\WINDOWS\system32\DivXWMPExtType.dll
                                      2007-07-26 23:06 129,784 ------w C:\WINDOWS\system32\pxafs.dll
                                      2007-07-26 23:06 120,056 ------w C:\WINDOWS\system32\pxcpyi64.exe
                                      2007-07-26 23:06 118,520 ------w C:\WINDOWS\system32\pxinsi64.exe
                                      2007-04-22 10:34 390 ----a-w C:\Documents and Settings\steven\kill-fluent-SCANNAYA-1280.bat
                                      2006-11-05 14:54 390 ----a-w C:\Documents and Settings\steven\kill-fluent-SCANNAYA-6028.bat
                                      2006-07-18 13:41 1,019,094 --sha-r C:\Program Files\serial.tde
                                      2006-05-28 16:46 397,306 --sha-r C:\Program Files\wunauclt.zip
                                      2006-05-28 16:46 397,306 --sha-r C:\Program Files\wunauclt.tbe
                                      2002-07-26 16:02 153,088 ----a-w C:\Program Files\UNWISE.EXE
                                      2006-08-26 13:29:58 12,208 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
                                      .

                                      ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
                                      .
                                      .
                                      *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés

                                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                      "BluetoothAuthenticationAgent"="rundll32.exe" [2004-08-04 00:55 C:\WINDOWS\system32\rundll32.exe]
                                      "SsAAD.exe"="C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe" [2006-01-07 02:36]
                                      "PinnacleDriverCheck"="C:\WINDOWS\system32\PSDrvCheck.exe" [2004-03-11 00:26]
                                      "USB2Check"="RUNDLL32.exe" [2004-08-04 00:55 C:\WINDOWS\system32\rundll32.exe]
                                      "USBToolTip"="C:\Program Files\Pinnacle\Shared Files\\Programs\USBTip\USBTip.exe" [2006-01-23 16:42]
                                      "SoundMan"="SOUNDMAN.EXE" [2006-06-21 06:42 C:\WINDOWS\soundman.exe]
                                      "VirtualCloneDrive"="C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2004-08-20 12:28]
                                      "I downloaded pirated Software from P2P "="Need for Speed Carbon" []
                                      "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11]
                                      "NFSUserSIDGSSLink"="C:\Program Files\Hummingbird\Connectivity\11.00\NFS Maestro\HumGSS.exe" [2005-09-21 07:47]
                                      "RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2007-02-07 16:24]
                                      "LanguageShortcut"="C:\Program Files\CyberLink\PowerDVD\Language\Language.exe" [2007-02-07 16:21]
                                      "BDMCon"="C:\Program Files\Softwin\BitDefender10\bdmcon.exe" [2007-10-12 19:31]
                                      "BDAgent"="C:\Program Files\Softwin\BitDefender10\bdagent.exe" [2007-03-26 15:49]
                                      "Autoconfigurateur WiFi Neuf"="C:\Program Files\Neuf\Kit\WiFi\9wifi.exe" [2007-09-09 01:05]
                                      "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 03:06]
                                      "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-06-17 20:25]

                                      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                      "Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2006-09-13 14:17]
                                      "CTZDetec.exe"="C:\Program Files\Creative\Creative Media Lite\CTZDetec.exe" [2007-05-15 20:25]

                                      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
                                      "appinit_dlls"=sockspy.dll

                                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
                                      "AVGEMS"=2 (0x2)
                                      "Avg7UpdSvc"=2 (0x2)
                                      "Avg7Alrt"=2 (0x2)

                                      R2 {95808DC4-FA4A-4c74-92FE-5B863F82066B};{95808DC4-FA4A-4c74-92FE-5B863F82066B};\??\C:\Program Files\CyberLink\PowerDVD\[u]0[/u]00.fcl
                                      R2 CTDevice_Srv;CT Device Query service;C:\Program Files\Creative\Shared Files\CTDevSrv.exe
                                      R2 HCLExport;Hummingbird Export;"C:\WINDOWS\system32\Hummingbird\Connectivity\11.00\NFS Maestro\expserv.exe"
                                      R2 HCLNFS;HCLNFS;\??\C:\WINDOWS\system32\drivers\hclnfs.sys
                                      R2 HPFECP13;HPFECP13;C:\WINDOWS\system32\drivers\HPFECP13.sys
                                      R3 PCASp50;PCASp50 NDIS Protocol Driver;C:\WINDOWS\system32\Drivers\PCASp50.sys
                                      R3 PPPoEWin;PPPoEWin Miniport;C:\WINDOWS\system32\DRIVERS\PPPoEWin.SYS

                                      [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8c86cab5-f40b-11da-a7df-806d6172696f}]
                                      AutoRun\command - F:\ASUSACPI.exe

                                      [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{FE827D64-FD1F-40B4-86B1-F3683B7D7959}]
                                      "C:\Program Files\Hummingbird\Connectivity\11.00\Accessories\HumSettings.exe" INSTALL=ALL
                                      .
                                      **************************************************************************

                                      catchme 0.3.1232 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                                      Rootkit scan 2007-10-25 12:17:12
                                      Windows 5.1.2600 Service Pack 2 NTFS

                                      scanning hidden processes ...

                                      scanning hidden autostart entries ...

                                      scanning hidden files ...

                                      scan completed successfully
                                      hidden files: 0

                                      **************************************************************************
                                      .
                                      Completion time: 2007-10-25 12:18:39 - machine was rebooted
                                      .
                                      --- E O F ---
                                      1. Contributeur sécurité
                                        Bonsoir vinoth91,

                                        Merci et bravo.
                                        Mais le rapport HJT est incomplet.
                                        Ce n'est rien, poursuis comme ceci:

                                        A)- Vide toute la quarantaine de BitDefender Antivirus Plus v10

                                        B)- •- Clique sur "Démarrer" - Clic droit sur le "Poste de Travail" > dans "Propriétés" > onglet "Restauration du système" - Cocher la case "Désactiver la restauration du système" et cliquer sur "Appliquer". Arrêter puis redémarrer le PC.

                                        a)- Télécharger _OTMoveIt (de Old_Timer) sur ton Bureau.
                                        http://download.bleepingcomputer.com/oldtimer/OTMoveIt.exe

                                        b)- Double-cliquer sur OTMoveIt.exe pour le lancer.
                                        --copier/coller la liste suivante (=le chemin exact du fichier que tu veux supprimer); à savoir :

                                        C:\WINDOWS\system32\sttss.tmp
                                        C:\WINDOWS\system32\sttss.tmp2
                                        C:\Documents and Settings\papa\Mes documents\~WRL0001.tmp
                                        C:\Documents and Settings\papa\Mes documents\~WRL{F423F12C-376D-4F06-90A5-FC9D2500A70F}.tmp
                                        C:\Documents and Settings\All Users\DRM\Cache\Indiv02.tmp
                                        C:\Documents and Settings\‚lodie\Local Settings\Temp\ttstv.tmp
                                        C:\Documents and Settings\‚lodie\Application Data\Microsoft\Word\~WRL2443.tmp
                                        C:\ Documents and Settings\steven\ Local Settings\Temp\~DFA81B.tmp
                                        C:\WINDOWS\Temp\tmp00001af8


                                        - colle donc dans le cadre de gauche de _OTMoveIt: " Paste List of Files/Folders to be moved ".

                                        3)- -clique sur MoveIt! pour lancer la suppression.
                                        -le résultat apparaitra dans le cadre "Results".
                                        -clique sur "Exit" pour fermer.

                                        -un rapport est situé dans C:\_OTMoveIt\MovedFiles.
                                        Poste-le SVP, merci

                                        NOTE: Il te sera peut-être demandé de redémarrer le pc pour achever la suppression.
                                        Si c'est le cas accepte par Yes.
                                        •- Le rapport se trouve en C:\_OTMoveIt\MovedFiles; tu ouvres le dossier et tu trouveras le rapport.

                                        C)- Supprimer les outils utilisés devenus inutiles, ainsi que les quarantaines éventuelles; comme ceci:

                                        •- Relancer OTMoveIt.exe par double-clic
                                        [*]Clique sur CleanUp! (le programme va télécharger un fichier texte qui servira a nettoyer les programmes que l'on a téléchargé).
                                        NOTE : Normalement, ton Firewall (parefeu) devrait te demander si _OTMoveIt peut accéder a Internet. Autorise-le.
                                        [*]Une liste apparaît dans la partie gauche d' _OTMoveIt.
                                        [*]Un message apparaît pour confirmer le nettoyage. Confirme
                                        Ce programme supprime les outils utilisés ainsi que les quarantaines éventuelles.

                                        Attention•- Clique sur "Démarrer" - Clic droit sur le "Poste de Travail" > dans "Propriétés" > onglet "Restauration du système" - Décocher la case "Désactiver la restauration du système" et cliquer sur "Appliquer".
                                        •- La manoeuvre nécessitera un reboot (=redémarrage) initié par le programme.

                                        D)- Faire analyser ces trois fichiers (en gras ci-dessous) chez VirusTotal, comme ceci :

                                        C:\Program Files\wunauclt.zip
                                        C:\Program Files\Internet Explorer\IEXPLORE.EXE
                                        C:\Documents and Settings\All Users\DRM\DRMv1.bak

                                        1°- Assure toi d'avoir accès aux dossiers/fichiers cachés :
                                        Soit en faisant : Ouvrir un dossier, n'importe lequel. Aller dans "Outils" >"Options des dossiers" > "Affichage"
                                        Soit en faisant « Démarrer »/ »PanneauConfiguration/OptionsDossiers /onglet « Affichage »
                                        et là :
                                        cocher la case devant les lignes:
                                        - afficher les fichiers et dossier cachés
                                        - afficher contenu dossier système
                                        décocher la case devant les lignes:
                                        - masquer fichiers protégés du dossier système
                                        Tu vas recevoir un message qui te dit que cela peut endommager le système,
                                        n'en tiens pas compte.
                                        Puis cliquer APPLIQUER à TOUS les Dossiers > [OK]
                                        Si tu n'es pas à l'aise dans la navigation des dossiers, je t'invite à suivre ce tutorial : < http://www.malekal.com/rechercher_fichiers.php >

                                        2°- Ensuite vas là :< https://www.virustotal.com/gui/ >
                                        •- sur la page qui s'affiche tu cliques sur "parcourir"
                                        •- ensuite sur la nouvelle page qui s'affiche, tu suis le chemin du premier fichier wunauclt.zip
                                        c'est-à-dire via « Poste de travail » > C:\Program Files\
                                        •- quand tu as trouvé le premier fichier wunauclt.zip</gras, tu fais "ouvrir" ( sur cette dernière page affichée)
                                        •- le fichier <gras> wunauclt.zip
                                        se retrouve alors ainsi dans la fenêtre de Virustotal, pour l'analyse
                                        •- là, tu cliques sur "send file" ( de la page de Virustotal )
                                        •- et tu attends le résultat (il faut parfois patienter)
                                        •- que tu postes sur le forum ( par un copier/coller de tout le texte de l’analyse )

                                        DONC, tu refais la manipulation fichier par fichier dont tu postes le rapport à chaque fois.
                                        C:\Program Files\Internet Explorer\IEXPLORE.EXE
                                        C:\Documents and Settings\All Users\DRM\DRMv1.bak


                                        Merci pour ta collaboration

                                        E)- Relance maintenant une analyse complète avec BitDefender Antivirus Plus v10.
                                        Poste son rapport complet .

                                        F)- Télécharge ComboFix.exe (par sUBs) sur ton Bureau:
                                        < http://download.bleepingcomputer.com/sUBs/ComboFix.exe > -1,41 Mo (1.483.997 octets)
                                        - Double clique sur l'icône de ComboFix.exe du bureau, [Exécuter] et suis les invites.
                                        Tape 1 puis [Enter] . Accepter les alertes éventuelles. Laisse se dérouler le scan.
                                        Lorsque le scan sera complété, un rapport apparaîtra sur le bureau. ==>Tu copies et colles ce rapport sur le forum

                                        Courage, un gros travail est déjà fait.
                                        Bravo pour tes manips.
                                        Bonne nuit
                                        Al.
                                        • 1
                                        • 2
                                        • 3