Cheval de troie

Résolu
Bonjour a tous je retente ma chance car j'ai postéun message il y a quelque jour qui semble t il est passé a la trappe..
j'ai un cheval de troie sur mon ordi qui est en train de se repandre partout en gros l'ordi est ralenti et des pub intempestive apparaissent sans cesse je viens de changer d'antivirus suite a une recommandation sur un forum j'ai donc installé antivir ( avant j'avasi avast) je vous poste le rapport aprezs analyse d'antivir... j'espereque qqn pourra m'aider car je viens d'aller rue montgallet et on me demande 60 euro pour reformatter l'ordi d'apres eux c est la seule chose a faire contre un cheval de trois... merci de votre aide

AntiVir PersonalEdition Classic
Report file date: 2007-11-03 13:15

Scanning for 1036370 virus strains and unwanted programs.

Licensed to: Avira AntiVir PersonalEdition Classic
Serial number: 0000149996-ADJIE-0001
Platform: Windows XP
Windows version: (Service Pack 2) [5.1.2600]
Username: SYSTEM
Computer name: BEGNY-GA1A4CHG2

Version information:
BUILD.DAT : 269 15604 Bytes 2007-09-10 14:31:00
AVSCAN.EXE : 7.0.6.1 290856 Bytes 2007-08-23 13:16:29
AVSCAN.DLL : 7.0.6.0 49192 Bytes 2007-08-16 12:23:51
LUKE.DLL : 7.0.5.3 147496 Bytes 2007-08-14 15:32:47
LUKERES.DLL : 7.0.6.1 10280 Bytes 2007-08-21 12:35:20
ANTIVIR0.VDF : 6.35.0.1 7371264 Bytes 2006-05-31 12:32:40
ANTIVIR1.VDF : 6.39.0.129 7251968 Bytes 2007-07-10 12:32:46
ANTIVIR2.VDF : 6.39.1.43 1542656 Bytes 2007-08-25 17:21:02
ANTIVIR3.VDF : 6.39.1.51 29696 Bytes 2007-08-28 07:22:36
AVEWIN32.DLL : 7.6.0.5 2789888 Bytes 2007-08-29 17:09:10
AVWINLL.DLL : 1.0.0.7 14376 Bytes 2007-02-26 10:36:26
AVPREF.DLL : 7.0.2.2 25640 Bytes 2007-07-18 07:39:17
AVREP.DLL : 7.0.0.1 155688 Bytes 2007-04-16 13:16:24
AVPACK32.DLL : 7.3.0.15 360488 Bytes 2007-08-03 08:46:00
AVREG.DLL : 7.0.1.6 30760 Bytes 2007-07-18 07:17:06
AVARKT.DLL : 1.0.0.20 278568 Bytes 2007-08-28 12:26:33
AVEVTLOG.DLL : 7.0.0.20 86056 Bytes 2007-07-18 07:10:18
NETNT.DLL : 7.0.0.0 7720 Bytes 2007-03-08 11:09:42
RCIMAGE.DLL : 7.0.1.30 2342952 Bytes 2007-08-07 12:38:13
RCTEXT.DLL : 7.0.62.0 86056 Bytes 2007-08-21 12:50:37
SQLITE3.DLL : 3.3.17.1 339968 Bytes 2007-07-23 09:37:21

Configuration settings for the scan:
Jobname..........................: Complete system scan
Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
Logging..........................: low
Primary action...................: interactive
Secondary action.................: ignore
Scan master boot sector..........: off
Scan boot sector.................: on
Boot sectors.....................: C:,
Scan memory......................: on
Process scan.....................: on
Scan registry....................: on
Search for rootkits..............: off
Scan all files...................: Intelligent file selection
Scan archives....................: on
Recursion depth..................: 20
Smart extensions.................: on
Macro heuristic..................: on
File heuristic...................: medium

Start of the scan: 2007-11-03 13:15

The scan of running processes will be started
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'avcenter.exe' - '1' Module(s) have been scanned
Scan process 'avcenter.exe' - '1' Module(s) have been scanned
Scan process 'guardgui.exe' - '1' Module(s) have been scanned
Scan process 'guardgui.exe' - '1' Module(s) have been scanned
Scan process 'guardgui.exe' - '1' Module(s) have been scanned
Scan process 'guardgui.exe' - '1' Module(s) have been scanned
Scan process 'guardgui.exe' - '1' Module(s) have been scanned
Scan process 'guardgui.exe' - '1' Module(s) have been scanned
Scan process 'guardgui.exe' - '1' Module(s) have been scanned
Scan process 'guardgui.exe' - '1' Module(s) have been scanned
Scan process 'guardgui.exe' - '1' Module(s) have been scanned
Scan process 'guardgui.exe' - '1' Module(s) have been scanned
Scan process 'guardgui.exe' - '1' Module(s) have been scanned
Scan process 'avnotify.exe' - '1' Module(s) have been scanned
Scan process 'guardgui.exe' - '1' Module(s) have been scanned
Scan process 'avgnt.exe' - '1' Module(s) have been scanned
Scan process 'avguard.exe' - '1' Module(s) have been scanned
Scan process 'sched.exe' - '1' Module(s) have been scanned
Scan process 'iexplore.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'ATKOSD.exe' - '1' Module(s) have been scanned
Scan process 'msnmsgr.exe' - '1' Module(s) have been scanned
Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
Scan process 'GoogleToolbarNotifier.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'jusched.exe' - '1' Module(s) have been scanned
Scan process 'sm56hlpr.exe' - '1' Module(s) have been scanned
Scan process 'RTHDCPL.exe' - '1' Module(s) have been scanned
Scan process 'HControl.exe' - '1' Module(s) have been scanned
Scan process 'alg.exe' - '1' Module(s) have been scanned
Scan process 'Tablet.exe' - '1' Module(s) have been scanned
Scan process 'TabUserW.exe' - '1' Module(s) have been scanned
Scan process 'explorer.exe' - '1' Module(s) have been scanned
Scan process 'Tablet.exe' - '1' Module(s) have been scanned
Scan process 'StkCSrv.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'NMSAccessU.exe' - '1' Module(s) have been scanned
Scan process 'LSSrvc.exe' - '1' Module(s) have been scanned
Scan process 'GoogleUpdaterService.exe' - '1' Module(s) have been scanned
Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'ati2evxx.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'ati2evxx.exe' - '1' Module(s) have been scanned
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Scan process 'services.exe' - '1' Module(s) have been scanned
Scan process 'winlogon.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'smss.exe' - '1' Module(s) have been scanned
53 processes with 53 modules were scanned

Start scanning boot sectors:
Boot sector 'C:\'
[NOTE] No virus was found!

Starting to scan the registry.
The registry was scanned ( '24' files ).

Starting the file scan:

Begin scan in 'C:\'
C:\pagefile.sys
[WARNING] The file could not be opened!
C:\Documents and Settings\BEGNY\Local Settings\Temporary Internet Files\Content.IE5\2EDF7FFG\17PHolmes[1].cmt
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '477c6725.qua'!
C:\Documents and Settings\BEGNY\Local Settings\Temporary Internet Files\Content.IE5\5TVFVLU4\mosx1024[1]
[DETECTION] Contains suspicious code HEUR/Malware
[INFO] The file was moved to '479f6776.qua'!
C:\Documents and Settings\BEGNY\Local Settings\Temporary Internet Files\Content.IE5\Y2E0NSE5\isearch[1].htm
[DETECTION] Contains suspicious code HEUR/Exploit.HTML
[INFO] The file was moved to '4791678c.qua'!
C:\qoobox\Quarantine\C\Program Files\Fichiers communs\Yazzle1560OinAdmin.exe.vir
[DETECTION] Contains suspicious code HEUR/Malware
[INFO] The file was moved to '47a66e4f.qua'!
C:\qoobox\Quarantine\C\WINDOWS\system32\cucpfbcc.dll.vir
[DETECTION] Contains suspicious code HEUR/Malware
[INFO] The file was moved to '478f6e63.qua'!
C:\qoobox\Quarantine\C\WINDOWS\system32\rslxxpph.dll.vir
[DETECTION] Contains suspicious code HEUR/Malware
[INFO] The file was moved to '47986e62.qua'!
C:\qoobox\Quarantine\C\WINDOWS\system32\uaqifxbv.dll.vir
[DETECTION] Contains suspicious code HEUR/Malware
[INFO] The file was moved to '479d6e50.qua'!
C:\qoobox\Quarantine\C\WINDOWS\system32\__c00198CA.dat.vir
[DETECTION] Contains suspicious code HEUR/Malware
[INFO] The file was moved to '478f6e4e.qua'!
C:\qoobox\Quarantine\C\WINDOWS\system32\u4\c124wvr.exe.vir
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '475e6e21.qua'!
C:\qoobox\Quarantine\C\WINDOWS\system32\u4\wr31drs.exe.vir
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '475f6e62.qua'!
C:\RECYCLER\S-1-5-21-484763869-884357618-725345543-1003\Dc78.zip
[0] Archive type: ZIP
--> __c001EC51.dat
[DETECTION] Contains suspicious code HEUR/Malware
[INFO] The file was moved to '47636e63.qua'!
C:\System Volume Information\_restore{1A8E027C-D601-467A-ABBC-00C5EF01FCC8}\RP19\A0006877.exe
[DETECTION] Is the Trojan horse TR/Agent.RIR.135
[INFO] The file was moved to '475c6e48.qua'!
C:\System Volume Information\_restore{1A8E027C-D601-467A-ABBC-00C5EF01FCC8}\RP29\A0008577.dll
[DETECTION] Contains detection pattern of the dropper DR/Agent.141853.A
[INFO] The file was moved to '475c6e89.qua'!
C:\System Volume Information\_restore{1A8E027C-D601-467A-ABBC-00C5EF01FCC8}\RP60\A0013533.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '475c6f0a.qua'!
C:\System Volume Information\_restore{1A8E027C-D601-467A-ABBC-00C5EF01FCC8}\RP61\A0014704.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '475c6f0e.qua'!
C:\System Volume Information\_restore{1A8E027C-D601-467A-ABBC-00C5EF01FCC8}\RP61\A0014707.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '46c12e57.qua'!
C:\System Volume Information\_restore{1A8E027C-D601-467A-ABBC-00C5EF01FCC8}\RP62\A0014854.exe
[DETECTION] Contains suspicious code HEUR/Malware
[INFO] The file was moved to '475c6f11.qua'!
C:\System Volume Information\_restore{1A8E027C-D601-467A-ABBC-00C5EF01FCC8}\RP62\A0014861.dll
[DETECTION] Contains suspicious code HEUR/Malware
[INFO] The file was moved to '475c6f12.qua'!
C:\System Volume Information\_restore{1A8E027C-D601-467A-ABBC-00C5EF01FCC8}\RP62\A0014863.dll
[DETECTION] Contains suspicious code HEUR/Malware
[INFO] The file was moved to '46c12e4b.qua'!
C:\System Volume Information\_restore{1A8E027C-D601-467A-ABBC-00C5EF01FCC8}\RP62\A0014865.dll
[DETECTION] Contains suspicious code HEUR/Malware
[INFO] The file was moved to '475c6f14.qua'!
C:\System Volume Information\_restore{1A8E027C-D601-467A-ABBC-00C5EF01FCC8}\RP62\A0014871.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '475c6f13.qua'!
C:\System Volume Information\_restore{1A8E027C-D601-467A-ABBC-00C5EF01FCC8}\RP62\A0014872.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '46c12e4c.qua'!
C:\System Volume Information\_restore{1A8E027C-D601-467A-ABBC-00C5EF01FCC8}\RP62\A0014930.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '46c12e4d.qua'!
C:\System Volume Information\_restore{1A8E027C-D601-467A-ABBC-00C5EF01FCC8}\RP62\A0014931.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '475c6f15.qua'!
C:\System Volume Information\_restore{1A8E027C-D601-467A-ABBC-00C5EF01FCC8}\RP63\A0014989.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '475c6f18.qua'!
C:\System Volume Information\_restore{1A8E027C-D601-467A-ABBC-00C5EF01FCC8}\RP64\A0015109.dll
[DETECTION] Contains suspicious code HEUR/Malware
[INFO] The file was moved to '475c6f1b.qua'!
C:\System Volume Information\_restore{1A8E027C-D601-467A-ABBC-00C5EF01FCC8}\RP64\A0015220.dll
[DETECTION] Contains detection pattern of the Windows virus W95/Blumblebee.1738
[INFO] The file was moved to '475c6f1e.qua'!
C:\System Volume Information\_restore{1A8E027C-D601-467A-ABBC-00C5EF01FCC8}\RP65\A0015446.dll
[DETECTION] Is the Trojan horse TR/Trash.Gen
[INFO] The file was moved to '475c6f23.qua'!
C:\WINDOWS\mrofinu1000106.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '479b6f77.qua'!
C:\WINDOWS\mrofinu1000106.exe.tmp
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '46005930.qua'!
C:\WINDOWS\mrofinu1188.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '479b6f79.qua'!
C:\WINDOWS\mrofinu1188.exe.tmp
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '479b6f78.qua'!
C:\WINDOWS\system32\lejygeds.dll
[DETECTION] Contains suspicious code HEUR/Malware
[INFO] The file was moved to '479671b9.qua'!
C:\WINDOWS\system32\nkiupqwt.dll
[DETECTION] Contains suspicious code HEUR/Malware
[INFO] The file was moved to '479571ca.qua'!
C:\WINDOWS\system32\spudscv.exe
[DETECTION] Is the Trojan horse TR/Spy.Banker.Gen
[INFO] The file was moved to '47a171d9.qua'!
C:\WINDOWS\system32\__c009ADE2.dat
[DETECTION] Contains suspicious code HEUR/Malware
[WARNING] An error has occurred and the file was not deleted. ErrorID: 16003
[WARNING] The file could not be deleted!
C:\WINDOWS\system32\b3\rarndrll2.exe
[DETECTION] Is the Trojan horse TR/Dldr.Small.buy.1
[INFO] The file was moved to '479e72ab.qua'!
C:\WINDOWS\system32\u4\wr31drs.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '475f7308.qua'!

End of the scan: 2007-11-03 14:07
Used time: 52:21 min

The scan has been done completely.

6463 Scanning directories
397755 Files were scanned
22 viruses and/or unwanted programs were found
16 Files were classified as suspicious:
0 files were deleted
0 files were repaired
37 files were moved to quarantine
0 files were renamed
1 Files cannot be scanned
397733 Files not concerned
6422 Archives were scanned
2 Warnings
50 Notes
Configuration: Windows XP
Internet Explorer 7.0
firefox

42 réponses

Résumé de la discussion

Un cheval de Troie est détecté sur le PC, provoquant ralentissements et affichage intempestif de publicités, avec un rapport AntiVir décrivant de nombreuses détections et des éléments déplacés en quarantaine. La réponse propose OTMoveIt pour supprimer des fichiers indésirables, CCleaner pour nettoyer le système et AVG Anti-Spyware pour une analyse complète et la mise en quarantaine des menaces. En parallèle, un scan en ligne Bitdefender est conseillé pour vérifier l'étendue de l'infection et générer un rapport, puis il est recommandé de redémarrer selon les instructions et de sauvegarder les rapports. Le rapport affiche 22 menaces détectées et 37 fichiers mis en quarantaine après un balayage de près de 397 755 fichiers, ce qui confirme l'infection et l'efficacité des mesures préconisées.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    Bonjour,

    Content d'avoir pu t'aider. Il faut en effet réactiver la restauration système et redémarrer le pc.
    La protection d'un pc est nécessaire mais il faut surtout être prudent dans son surf : ne pas ouvrir de mails d'expéditeurs inconnus, pas de p2p, pas de cracks , ne pas installer n'importe quel programme et toujours le télécharger sur le site de l'éditeur s'il est fiable => 95 % des problèmes sont éliminés.

    Pense à faire des sauvegardes régulières de tes documents. Enfin, un logiciels de restauration d'image système peut être utile en cas de gros pépin ou de plantage.

    Bon surf !

    FillPCA
    1. bonsoir,
      j'ai suivis toutes vos indication, et j'ai installé le nouveau parefeu...le pc ronronne a nouveau et je n'ai , semble il, plus de pbm... j'ai une derniere question cependant: quand dois-je reactiver la restauration systeme? je pense que je peux le faire maintenant car j'ai redemarré le pc en mode "restauration systeme desactivé"
      je souhaite vous remercier tout spécialement d'avoir pris autant de votre temps pour m'aider, les gens comme vous se font rare de nos jours... vous n'imaginez pas de quelle situation vous m'avez sorti... je bosse depuis deux mois sur un projet flash a raison de 12 a 15 H par jour et je n'ai , bêtement pas pensé a sauvegarder mes donnés ailleurs... imaginez l'angoisse ce matin quand j'ai appris que je devais tout effacer... ce que vous m'avez fait faire relève a mes yeux plus du tour de passe passe qu'autre chose et j'admire la facilité avec laquelle vous êtes parvenu a me faire effectuer toutes ces manips complexes...
      encore un immense merci pour votre bienveillance...
      1. Contributeur sécurité
        Re,

        Si tu n'as plus de problème, je te conseille d'installer au minimum un firewall. Je te conseille Comodo, mais il y en a d'autres qui sont aussi très bien.

        Tu trouveras des liens intéressants ici : http://perso.orange.fr/Le-site-de-Fill/S%E9curit%E9/Logiciels%20de%20protection.html

        N'oublie pas d'indiquer ton sujet comme "résolu" si tu n'as plus de problème, et avec les 60 € économisés, tu t'achèteras quelques bonnes bouteilles !

        Boone nuit !

        FillPCA
        1. Contributeur sécurité
          Re,

          1/ Supprime ceci : C:\upload_moi_BEGNY-GA1A4CHG2.tar.gz
          Puis vide ta corbeille.

          2/ Tu dois désactiver puis réactiver la restauration système. Pour cela, fais un clic droit sur « poste de travail ». Dans l’onglet « restauration du système », coche la case « désactiver la restauration système ». Clique sur appliquer.
          Décoche cette case, clique sur appliquer>OK et redémarre le PC.

          As-tu toujours des soucis ? Sinon, je te donne les derniers conseils.

          FillPCA
          1. j oubliais le hijack this...
            Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 22:11:02, on 03/11/2007
            Platform: Windows XP SP2 (WinNT 5.01.2600)
            MSIE: Internet Explorer v7.00 (7.00.6000.16544)
            Boot mode: Normal

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\System32\Ati2evxx.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\system32\Ati2evxx.exe
            C:\WINDOWS\system32\spoolsv.exe
            C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
            C:\WINDOWS\Explorer.EXE
            C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
            C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
            C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
            C:\Program Files\CDBurnerXP\NMSAccessU.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\System32\StkCSrv.exe
            C:\WINDOWS\system32\Tablet.exe
            C:\WINDOWS\system32\WTablet\TabUserW.exe
            C:\WINDOWS\system32\Tablet.exe
            C:\WINDOWS\ATK0100\HControl.exe
            C:\WINDOWS\RTHDCPL.EXE
            C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
            C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
            C:\WINDOWS\System32\svchost.exe
            C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
            C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
            C:\WINDOWS\system32\ctfmon.exe
            C:\WINDOWS\ATK0100\ATKOSD.exe
            C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
            C:\Program Files\internet explorer\iexplore.exe
            C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
            C:\Documents and Settings\BEGNY\Bureau\HijackThis.exe

            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
            O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.8.30.dll
            O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
            O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
            O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
            O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
            O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
            O4 - HKLM\..\Run: [HControl] C:\WINDOWS\ATK0100\HControl.exe
            O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
            O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
            O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
            O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
            O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
            O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
            O4 - HKLM\..\Run: [Easy-PrintToolBox] C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE /logon
            O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
            O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
            O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
            O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
            O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
            O4 - HKCU\..\Run: [msnmsgr] ; "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
            O4 - HKCU\..\Run: [BitComet] "C:\Program Files\BitComet\BitComet.exe" /tray
            O4 - HKCU\..\Run: [Skype] ; "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
            O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
            O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
            O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
            O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
            O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
            O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
            O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
            O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
            O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
            O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
            O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
            O9 - Extra button: BitComet Search - {461CC20B-FB6E-4f16-8FE8-C29359DB100E} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.8.30.dll
            O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
            O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
            O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
            O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
            O17 - HKLM\System\CCS\Services\Tcpip\..\{B8B7581F-45BC-462C-8D2B-15CB7C159F03}: NameServer = 213.36.80.1
            O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
            O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
            O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
            O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
            O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
            O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
            O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
            O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
            O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
            O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
            O23 - Service: Syntek AVStream USB2.0 WebCam Service (StkSSrv) - Syntek America Inc. - C:\WINDOWS\System32\StkCSrv.exe
            O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\system32\Tablet.exe
            1. et voila le rapport bitdefender... merci et bonne soiree ;)

              BitDefender Online Scanner

              Scan report generated at: Sat, Nov 03, 2007 - 22:00:47

              Scan path: C:\;D:\;E:\;F:\;

              Statistics

              Time

              00:53:24

              Files

              304202

              Folders

              6467

              Boot Sectors

              2

              Archives

              2296

              Packed Files

              15899

              Results

              Identified Viruses

              1

              Infected Files

              4

              Suspect Files

              0

              Warnings

              0

              Disinfected

              0

              Deleted Files

              4

              Engines Info

              Virus Definitions

              860168

              Engine build

              AVCORE v1.0 (build 2422) (i386) (Sep 25 2007 08:26:36)

              Scan plugins

              14

              Archive plugins

              38

              Unpack plugins

              7

              E-mail plugins

              6

              System plugins

              1

              Scan Settings

              First Action

              Disinfect

              Second Action

              Delete

              Heuristics

              Yes

              Enable Warnings

              Yes

              Scanned Extensions

              *;

              Exclude Extensions

              Scan Emails

              Yes

              Scan Archives

              Yes

              Scan Packed

              Yes

              Scan Files

              Yes

              Scan Boot

              Yes

              Scanned File

              Status

              C:\System Volume Information\_restore{1A8E027C-D601-467A-ABBC-00C5EF01FCC8}\RP61\A0014706.exe=>(NSIS o)=>zlib_nsis0003

              Detected with: Adware.TTC.B

              C:\System Volume Information\_restore{1A8E027C-D601-467A-ABBC-00C5EF01FCC8}\RP61\A0014706.exe=>(NSIS o)=>zlib_nsis0003

              Disinfection failed

              C:\System Volume Information\_restore{1A8E027C-D601-467A-ABBC-00C5EF01FCC8}\RP61\A0014706.exe=>(NSIS o)=>zlib_nsis0003

              Deleted

              C:\System Volume Information\_restore{1A8E027C-D601-467A-ABBC-00C5EF01FCC8}\RP61\A0014706.exe=>(NSIS o)

              Update failed

              C:\System Volume Information\_restore{1A8E027C-D601-467A-ABBC-00C5EF01FCC8}\RP62\A0014870.exe=>(NSIS o)=>zlib_nsis0003

              Detected with: Adware.TTC.B

              C:\System Volume Information\_restore{1A8E027C-D601-467A-ABBC-00C5EF01FCC8}\RP62\A0014870.exe=>(NSIS o)=>zlib_nsis0003

              Disinfection failed

              C:\System Volume Information\_restore{1A8E027C-D601-467A-ABBC-00C5EF01FCC8}\RP62\A0014870.exe=>(NSIS o)=>zlib_nsis0003

              Deleted

              C:\System Volume Information\_restore{1A8E027C-D601-467A-ABBC-00C5EF01FCC8}\RP62\A0014870.exe=>(NSIS o)

              Update failed

              C:\System Volume Information\_restore{1A8E027C-D601-467A-ABBC-00C5EF01FCC8}\RP65\A0015553.exe=>(NSIS o)=>zlib_nsis0003

              Detected with: Adware.TTC.B

              C:\System Volume Information\_restore{1A8E027C-D601-467A-ABBC-00C5EF01FCC8}\RP65\A0015553.exe=>(NSIS o)=>zlib_nsis0003

              Disinfection failed

              C:\System Volume Information\_restore{1A8E027C-D601-467A-ABBC-00C5EF01FCC8}\RP65\A0015553.exe=>(NSIS o)=>zlib_nsis0003

              Deleted

              C:\System Volume Information\_restore{1A8E027C-D601-467A-ABBC-00C5EF01FCC8}\RP65\A0015553.exe=>(NSIS o)

              Update failed

              C:\upload_moi_BEGNY-GA1A4CHG2.tar.gz=>upload_moi.tar=>qoobox/Quarantine/C/WINDOWS/system32/e1/caws83122.exe.vir=>(NSIS o)=>zlib_nsis0003

              Detected with: Adware.TTC.B

              C:\upload_moi_BEGNY-GA1A4CHG2.tar.gz=>upload_moi.tar=>qoobox/Quarantine/C/WINDOWS/system32/e1/caws83122.exe.vir=>(NSIS o)=>zlib_nsis0003

              Disinfection failed

              C:\upload_moi_BEGNY-GA1A4CHG2.tar.gz=>upload_moi.tar=>qoobox/Quarantine/C/WINDOWS/system32/e1/caws83122.exe.vir=>(NSIS o)=>zlib_nsis0003

              Deleted

              C:\upload_moi_BEGNY-GA1A4CHG2.tar.gz=>upload_moi.tar=>qoobox/Quarantine/C/WINDOWS/system32/e1/caws83122.exe.vir=>(NSIS o)

              Update failed
              1. ---------------------------------------------------------
                AVG Anti-Spyware - Rapport d'analyse
                ---------------------------------------------------------

                + Créé à: 19:33:34 03/11/2007

                + Résultat de l'analyse:

                C:\Documents and Settings\BEGNY\Cookies\begny@atdmt[1].txt -> TrackingCookie.Atdmt : Nettoyé.

                Fin du rapport
                1. Contributeur sécurité
                  Re,
                  Inutile. Normalement, bit defender et Antivir sont compatibles.

                  Je reviens plus tard.

                  FillPCA
                  1. j'ai plein de message d'antivir qui apparaissent tou a coup : cest du au scan d'avg a votre avis ???
                    1. Contributeur sécurité
                      Re,

                      Les dernières étapes seront assez longues (notamment AVGantispyware et surtout le scan en ligne bit defender qui peut durer plusieurs heures, selon la taille du disque dur).

                      Je pense qu'il serait intéressant que tu réalises les scan d'AVGantispyware et de bit defender avec le disque dur externe branché.

                      On ne fait jamais de sauvegarde en cas d'infection. Il faut les faire avant...

                      Pour les conseils, je t'en donnerai quand tout sera propre. Le firewall de XP est minimaliste.

                      FillPCA
                      1. c'est en cours mais c'est assez long pour ccleaner ( pas de soucis je patiente )
                        juste une question technique en attendant...
                        - dans la panique j'ai écouté les conseils du vendeur rue montgallet ce matin et j'ai sauvegardé par copier coller tous mes fichiers important sur mon disque dur externe... le pbm maintenant c'est que si je rebranche ce disque dur externe sur mon ordi ( juste pour supprimer ces fichiers sauvegardés qui du coup ne me servent plus a rien) il y a un risque que les virus reviennent en courant le temps de la supppression non?
                        - pour le moment j'ai antivir ( que je viens d'installer avant j'avais avast) et le pare feu windows... est ce que ca vous semble convenable comme config pour parer aux eventuels prochaines attaques de virus ou me conseillez vous d'installer autre chose??
                        mille merci...
                        1. Contributeur sécurité
                          Re,

                          Ne t'inquiète pas, on va sauver ton pc. Peux-tu passer à la suite (Ccleaner + AVGantispyware +bit defender) ?

                          FillPCA
                          1. bcp mieux j'ai l'impression... je n'ai pas compris un foutu mot de ce que vous avez pu faire mais je pense que ca lui afait plus que du bien .... ;) si ca peut m'eviter de perdre toute mes donnees ca serait fantastique...avec mon boulot, j'utilise enormement de dossier flash ...
                            1. C:\WINDOWS\System32\bvxshpsx.ini moved successfully.
                              C:\WINDOWS\System32\jlxhesna.ini moved successfully.
                              File/Folder not found.

                              Created on 11/03/2007 17:23:55
                              1. merde j'ai ait une erreur ... j'ai appuye sur clean up apres avoir collé les dossier:
                                C:\WINDOWS\System32\bvxshpsx.ini
                                C:\WINDOWS\System32\jlxhesna.ini
                                dsl :(
                                1. Contributeur sécurité
                                  Re,

                                  Ca me semble pas mal. Comment le pc se porte-t-il ?

                                  Fais ensuite ceci :

                                  1/ * Télécharge OTMoveIt (de Old_Timer) sur ton bureau : http://download.bleepingcomputer.com/oldtimer/OTMoveIt.exe
                                  * Double-clique sur OTMoveIt.exe pour lancer le programme,
                                  * Copie la liste de fichiers ou de dossiers ci-dessous et colle-la dans la fenêtre du programme "Paste List Of Files/Folders to be moved" :

                                  C:\WINDOWS\System32\bvxshpsx.ini
                                  C:\WINDOWS\System32\jlxhesna.ini


                                  * Clique sur MoveIt! pour lancer la suppression,
                                  * Le résultat appraraîtra dans le cadre Results.
                                  * Clique sur Exit pour fermer le programme.
                                  * Poste le rapport qui est situé ici : C:\\\_OTMoveIt\MovedFiles
                                  * Il te sera peut-être demandé de redémarrer ton PC. Dans ce cas, clique sur Yes.

                                  2/ Télécharge Ccleaner Basic https://www.ccleaner.com/ccleaner/download

                                  Ouvre Ccleaner, clique sur "lancer le nettoyage".

                                  3/ Télécharge AVGantispyware : https://www.avg.com/en-ww/free-antivirus-download
                                  Tu l'installes.
                                  Lance AVG Anti-Spyware et clique sur le bouton Mise à jour. Patiente.

                                  Clique sur le bouton Analyse (de la barre d'outils)
                                  Puis sur l'onglets Comment réagir, clique sur Actions recommandées. Sélectionne Quarantaine.
                                  Reviens à l'onglet Analyse. Clique sur Analyse complète du système.
                                  A la fin du scan, choisis l'option " Appliquer toutes les actions " en bas. Ensuite.
                                  Clique sur "Enregistrer le rapport". Ceci génère un rapport en fichier texte qui se trouve dans le dossier Reports du dossier d'AVG Anti-Spyware.

                                  4/ * Fais un scan en ligne en cliquant ici : https://www.bitdefender.com/toolbox/
                                  * Tu dois réaliser le scan en utilisant Internet explorer. Une information apparait en haut, près de la barre d'état. Tu dois accepter et installer l'activeX proposé. La mise à jour de l'antivirus se lance.
                                  * Réalise un scan complet du système.
                                  * Sauvegarde le rapport en mode texte à l'issue du scan.

                                  5/ Edite ces rapports : AVGantispyware, Bit defender et un nouveau rapport Hijackthis.

                                  FillPCA
                                  1. le dernier hijackthis... pas trop ras le bol j'espère ;-) mille merci en tout cas ...
                                    Logfile of Trend Micro HijackThis v2.0.2
                                    Scan saved at 17:02:56, on 03/11/2007
                                    Platform: Windows XP SP2 (WinNT 5.01.2600)
                                    MSIE: Internet Explorer v7.00 (7.00.6000.16544)
                                    Boot mode: Normal

                                    Running processes:
                                    C:\WINDOWS\System32\smss.exe
                                    C:\WINDOWS\system32\winlogon.exe
                                    C:\WINDOWS\system32\services.exe
                                    C:\WINDOWS\system32\lsass.exe
                                    C:\WINDOWS\System32\Ati2evxx.exe
                                    C:\WINDOWS\system32\svchost.exe
                                    C:\WINDOWS\System32\svchost.exe
                                    C:\WINDOWS\system32\Ati2evxx.exe
                                    C:\WINDOWS\system32\spoolsv.exe
                                    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                                    C:\WINDOWS\Explorer.EXE
                                    C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                                    C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                    C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
                                    C:\Program Files\CDBurnerXP\NMSAccessU.exe
                                    C:\WINDOWS\System32\svchost.exe
                                    C:\WINDOWS\System32\StkCSrv.exe
                                    C:\WINDOWS\system32\Tablet.exe
                                    C:\WINDOWS\system32\WTablet\TabUserW.exe
                                    C:\WINDOWS\system32\Tablet.exe
                                    C:\WINDOWS\ATK0100\HControl.exe
                                    C:\WINDOWS\RTHDCPL.EXE
                                    C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
                                    C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
                                    C:\WINDOWS\System32\svchost.exe
                                    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                                    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                                    C:\WINDOWS\system32\ctfmon.exe
                                    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                                    C:\Program Files\BitComet\BitComet.exe
                                    C:\WINDOWS\ATK0100\ATKOSD.exe
                                    C:\Program Files\internet explorer\iexplore.exe
                                    C:\Documents and Settings\BEGNY\Bureau\HijackThis.exe

                                    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                                    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                                    O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.8.30.dll
                                    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                                    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                                    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                                    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
                                    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                                    O4 - HKLM\..\Run: [HControl] C:\WINDOWS\ATK0100\HControl.exe
                                    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
                                    O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
                                    O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
                                    O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
                                    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
                                    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                                    O4 - HKLM\..\Run: [Easy-PrintToolBox] C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE /logon
                                    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                                    O4 - HKLM\..\Run: [QuickTime Task] ; "C:\Program Files\QuickTime\qttask.exe" -atboottime
                                    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                                    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                                    O4 - HKCU\..\Run: [msnmsgr] ; "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
                                    O4 - HKCU\..\Run: [BitComet] ; "C:\Program Files\BitComet\BitComet.exe" /tray
                                    O4 - HKCU\..\Run: [Skype] ; "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
                                    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
                                    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                                    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
                                    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
                                    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
                                    O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
                                    O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
                                    O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
                                    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
                                    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                                    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                                    O9 - Extra button: BitComet Search - {461CC20B-FB6E-4f16-8FE8-C29359DB100E} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.8.30.dll
                                    O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
                                    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
                                    O17 - HKLM\System\CCS\Services\Tcpip\..\{B8B7581F-45BC-462C-8D2B-15CB7C159F03}: NameServer = 213.36.80.1
                                    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
                                    O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                                    O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                                    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
                                    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
                                    O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
                                    O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
                                    O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
                                    O23 - Service: Syntek AVStream USB2.0 WebCam Service (StkSSrv) - Syntek America Inc. - C:\WINDOWS\System32\StkCSrv.exe
                                    O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\system32\Tablet.exe
                                    1. [CODE]

                                      2007-11-03,17:01:40

                                      System Repair Engineer 2.5.16.900
                                      Smallfrogs (http://www.KZTechs.com)

                                      Windows XP Professional Service Pack 2 (Build 2600) - Administrative User - Completed Functions Allowed

                                      Follow item(s) have been choosed:
                                      All Boot Items (Including Registry, Startup Folders, Services and so on)
                                      Browser Add-ons
                                      Runing Processes (Including process model information)
                                      File Associations
                                      Winsock Provider
                                      Autorun.Inf
                                      HOSTS File
                                      Process Privileges Scan

                                      Boot Items
                                      Registry
                                      [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
                                      <swg><C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe> [(Verified)Google Inc]
                                      <ctfmon.exe><C:\WINDOWS\system32\ctfmon.exe> [(Verified)Microsoft Windows Publisher]
                                      <msnmsgr><"C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background> [(Verified)Microsoft Corporation]
                                      <BitComet><"C:\Program Files\BitComet\BitComet.exe" /tray> [(Verified)Comet Network Technology Co Ltd.]
                                      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
                                      <HControl><C:\WINDOWS\ATK0100\HControl.exe> [(Verified)Microsoft Windows Hardware Compatibility Publisher]
                                      <RTHDCPL><RTHDCPL.EXE> [(Verified)Microsoft Windows Hardware Compatibility Publisher]
                                      <SkyTel><SkyTel.EXE> [(Verified)Microsoft Windows Hardware Compatibility Publisher]
                                      <SMSERIAL><C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe> [(Verified)Microsoft Windows Hardware Compatibility Publisher]
                                      <NeroFilterCheck><C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe> [(Verified)Nero AG]
                                      <SunJavaUpdateSched><"C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"> [(Verified)"Sun Microsystems, Inc."]
                                      <Adobe Reader Speed Launcher><"C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"> [(Verified)"Adobe Systems, Incorporated"]
                                      <Easy-PrintToolBox><C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE /logon> [CANON INC.]
                                      <avgnt><"C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min> [Avira GmbH]
                                      <QuickTime Task><"C:\Program Files\QuickTime\qttask.exe" -atboottime> [Apple Computer, Inc.]
                                      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
                                      <shell><Explorer.exe> [(Verified)Microsoft Windows Publisher]
                                      <Userinit><C:\WINDOWS\system32\userinit.exe,> [(Verified)Microsoft Windows Publisher]
                                      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
                                      <AppInit_DLLs><> [N/A]
                                      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
                                      <UIHost><logonui.exe> [(Verified)Microsoft Windows Component Publisher]
                                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
                                      <WPDShServiceObj><C:\WINDOWS\system32\WPDShServiceObj.dll> [(Verified)Microsoft Windows Component Publisher]
                                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\<{12d0ed0d-0ee0-4f90-8827-78cefb8f4988}]
                                      <IE7 Uninstall Stub><C:\WINDOWS\system32\ieudinit.exe> [(Verified)Microsoft Windows Component Publisher]
                                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
                                      <Outlook Express><%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE> [N/A]
                                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
                                      <Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll> [N/A]
                                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
                                      <Microsoft Outlook Express 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install> [N/A]
                                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
                                      <NetMeeting 3.01><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT> [(Verified)Microsoft Windows Publisher]
                                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]
                                      <Windows Messenger 4.7><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser> [(Verified)Microsoft Windows Publisher]
                                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
                                      <Microsoft Windows Media Player><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp11.inf,PerUserStub> [(Verified)Microsoft Windows Component Publisher]
                                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
                                      <Carnet d'adresses 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install> [N/A]
                                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}]
                                      <N/A><C:\WINDOWS\system32\Rundll32.exe C:\WINDOWS\system32\mscories.dll,Install> [Microsoft Corporation]
                                      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                      <BitComet><; "C:\Program Files\BitComet\BitComet.exe" /tray> [(Verified)Comet Network Technology Co Ltd.]
                                      <MsnMsgr><; "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background> [(Verified)Microsoft Corporation]
                                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                      <QuickTime Task><; "C:\Program Files\QuickTime\qttask.exe" -atboottime> [Apple Computer, Inc.]
                                      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                      <Skype><; "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized> [(Verified)Skype Technologies SA]

                                      ==================================
                                      Startup Folders
                                      [Adobe Gamma Loader]
                                      <C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Adobe Gamma Loader.lnk --> C:\PROGRA~1\FICHIE~1\Adobe\CALIBR~1\ADOBEG~1.EXE [Adobe Systems, Inc.]><N>

                                      ==================================
                                      Services
                                      [Adobe LM Service / Adobe LM Service][Stopped/Manual Start]
                                      <"C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe"><Adobe Systems>
                                      [AntiVir PersonalEdition Classic Scheduler / AntiVirScheduler][Running/Auto Start]
                                      <"C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe"><Avira GmbH>
                                      [AntiVir PersonalEdition Classic Guard / AntiVirService][Running/Auto Start]
                                      <"C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe"><Avira GmbH>
                                      [Ati HotKey Poller / Ati HotKey Poller][Running/Auto Start]
                                      <C:\WINDOWS\System32\Ati2evxx.exe><ATI Technologies Inc.>
                                      [Google Updater Service / gusvc][Running/Auto Start]
                                      <"C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe"><Google>
                                      [LightScribeService Direct Disc Labeling Service / LightScribeService][Running/Auto Start]
                                      <"C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe"><Hewlett-Packard Company>
                                      [NBService / NBService][Stopped/Manual Start]
                                      <C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe><Nero AG>
                                      [NMIndexingService / NMIndexingService][Stopped/Manual Start]
                                      <"C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe"><Nero AG>
                                      [NMSAccessU / NMSAccessU][Running/Auto Start]
                                      <C:\Program Files\CDBurnerXP\NMSAccessU.exe><N/A>
                                      [Syntek AVStream USB2.0 WebCam Service / StkSSrv][Running/Auto Start]
                                      <C:\WINDOWS\System32\StkCSrv.exe><Syntek America Inc.>
                                      [TabletService / TabletService][Running/Auto Start]
                                      <C:\WINDOWS\system32\Tablet.exe><Wacom Technology, Corp.>

                                      ==================================
                                      Drivers
                                      [Atheros Wireless Network Adapter Service / AR5211][Running/Manual Start]
                                      <System32\DRIVERS\ar5211.sys><Atheros Communications, Inc.>
                                      [ASNDIS5 Protocol Driver / ASNDIS5][Running/Manual Start]
                                      <\??\C:\WINDOWS\ATK0100\ASNDIS5.SYS><Printing Communications Assoc., Inc. (PCAUSA)>
                                      [NDIS Miniport Driver for Attansic L2 Fast Ethernet Adapter / AtcL002][Stopped/Manual Start]
                                      <System32\DRIVERS\atl02_xp.sys><Attansic Technology corporation.>
                                      [ati2mtag / ati2mtag][Running/Manual Start]
                                      <System32\DRIVERS\ati2mtag.sys><ATI Technologies Inc.>
                                      [avgio / avgio][Running/System Start]
                                      <\??\C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgio.sys><Avira GmbH>
                                      [avgntflt / avgntflt][Running/Manual Start]
                                      <\??\C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgntflt.sys><Avira GmbH>
                                      [avipbb / avipbb][Running/System Start]
                                      <system32\DRIVERS\avipbb.sys><AVIRA GmbH>
                                      [BDFsDrv / BDFsDrv][Stopped/Manual Start]
                                      <\??\C:\Program Files\Softwin\BitDefender10\bdfsdrv.sys><N/A>
                                      [BDRsDrv / BDRsDrv][Stopped/Manual Start]
                                      <\??\C:\Program Files\Softwin\BitDefender10\bdrsdrv.sys><N/A>
                                      [catchme / catchme][Running/Manual Start]
                                      <\??\C:\DOCUME~1\BEGNY\LOCALS~1\Temp\catchme.sys><N/A>
                                      [Microsoft UAA Bus Driver for High Definition Audio / HDAudBus][Running/Manual Start]
                                      <system32\DRIVERS\HDAudBus.sys><Windows (R) Server 2003 DDK provider>
                                      [Service for Realtek HD Audio (WDM) / IntcAzAudAddService][Running/Manual Start]
                                      <system32\drivers\RtkHDAud.sys><Realtek Semiconductor Corp.>
                                      [ATK0100 ACPI UTILITY / MTsensor][Running/Manual Start]
                                      <System32\DRIVERS\ATKACPI.sys><>
                                      [Pilote de liaison parallèle directe / Ptilink][Running/Manual Start]
                                      <System32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
                                      [PxHelp20 / PxHelp20][Running/Boot Start]
                                      <\SystemRoot\System32\Drivers\PxHelp20.sys><Sonic Solutions>
                                      [USB Mass Stroage Device / RTSTOR][Running/Manual Start]
                                      <system32\drivers\RTSTOR.SYS><Realtek Semiconductor Corp.>
                                      [Secdrv / Secdrv][Stopped/Manual Start]
                                      <System32\DRIVERS\secdrv.sys><N/A>
                                      [smserial / smserial][Running/Manual Start]
                                      <system32\DRIVERS\smserial.sys><Motorola Inc.>
                                      [ssmdrv / ssmdrv][Running/System Start]
                                      <system32\DRIVERS\ssmdrv.sys><Avira GmbH>
                                      [Syntek AVStream USB2.0 1.3M WebCam / StkCMini][Running/Manual Start]
                                      <System32\Drivers\StkCMini.sys><Syntek>
                                      [Wacom Mouse Filter Driver / wacommousefilter][Running/Manual Start]
                                      <system32\DRIVERS\wacommousefilter.sys><Wacom Technology>
                                      [Wacom Virtual Hid Driver / wacomvhid][Running/Manual Start]
                                      <system32\DRIVERS\wacomvhid.sys><Wacom Technology>
                                      [Virtual Keyboard Driver / WacomVKHid][Running/Manual Start]
                                      <system32\DRIVERS\WacomVKHid.sys><Wacom Technology>
                                      [Codec Teletext standard / WSTCODEC][Stopped/Manual Start]
                                      <System32\DRIVERS\WSTCODEC.SYS><Microsoft Corporation>

                                      ==================================
                                      Browser Add-ons
                                      [BitComet Helper]
                                      {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} <C:\Program Files\BitComet\tools\BitCometBHO_1.1.8.30.dll, BitComet>
                                      [SSVHelper Class]
                                      {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} <C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll, Sun Microsystems, Inc.>
                                      [Google Toolbar Helper]
                                      {AA58ED58-01DD-4d91-8333-CF10577473F7} <c:\program files\google\googletoolbar1.dll, Google Inc.>
                                      [Google Toolbar Notifier BHO]
                                      {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} <C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll, Google Inc.>
                                      [Java Plug-in 1.6.0_03]
                                      {08B0E5C0-4FCB-11CF-AAA5-00401C608501} <C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll, Sun Microsystems, Inc.>
                                      [BitComet Button]
                                      {461CC20B-FB6E-4f16-8FE8-C29359DB100E} <C:\Program Files\BitComet\tools\BitCometBHO_1.1.8.30.dll, BitComet>
                                      [&Rechercher]
                                      {92780B25-18CC-41C8-B9BE-3C9C571A8263} <C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL, Microsoft Corporation>
                                      [Messenger]
                                      {FB5F1910-F110-11d2-BB9E-00C04F795683} <C:\Program Files\Messenger\msmsgs.exe, Microsoft Corporation>
                                      [&Google]
                                      {2318C2B1-4965-11d4-9B18-009027A5CD4F} <c:\program files\google\googletoolbar1.dll, Google Inc.>
                                      [Windows Genuine Advantage Validation Tool]
                                      {17492023-C23A-453E-A040-C7C580BBF700} <C:\WINDOWS\system32\LegitCheckControl.DLL, Microsoft Corporation>
                                      [Java Plug-in 1.6.0_03]
                                      {8AD9C840-044E-11D1-B3E9-00805F499D93} <C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll, Sun Microsystems, Inc.>
                                      [Java Plug-in 1.6.0_02]
                                      {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} <C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll, Sun Microsystems, Inc.>
                                      [Java Plug-in 1.6.0_03]
                                      {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} <C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll, Sun Microsystems, Inc.>
                                      [Java Plug-in 1.6.0_03]
                                      {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} <C:\Program Files\Java\jre1.6.0_03\bin\npjpi160_03.dll, Sun Microsystems, Inc.>
                                      [Shockwave Flash Object]
                                      {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9d.ocx, Adobe Systems, Inc.>
                                      [Google Script Object]
                                      {00EF2092-6AC5-47C0-BD25-CF2D5D657FEB} <c:\program files\google\googletoolbar1.dll, Google Inc.>
                                      [QuickTime Object]
                                      {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} <C:\Program Files\QuickTime\QTPlugin.ocx, Apple Computer, Inc.>
                                      [Aide pour le lien d'Adobe PDF Reader]
                                      {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated>
                                      [Windows Genuine Advantage Validation Tool]
                                      {17492023-C23A-453E-A040-C7C580BBF700} <C:\WINDOWS\system32\LegitCheckControl.DLL, Microsoft Corporation>
                                      [InformationCardSigninHelper Class]
                                      {19916E01-B44E-4E31-94A4-4696DF46157B} <C:\WINDOWS\system32\icardie.dll, Microsoft Corporation>
                                      [Windows Media Player]
                                      {22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
                                      [&Google]
                                      {2318C2B1-4965-11D4-9B18-009027A5CD4F} <c:\program files\google\googletoolbar1.dll, Google Inc.>
                                      [HTML Document]
                                      {25336920-03F9-11CF-8FD0-00AA00686F13} <C:\WINDOWS\system32\mshtml.dll, Microsoft Corporation>
                                      []
                                      {28AEAED5-E434-468F-85BD-3D1A1BCCF761} <C:\WINDOWS\system32\xvfjpwqx.dll, N/A>
                                      [XML DOM Document]
                                      {2933BF90-7B36-11D2-B20E-00C04F983E60} <C:\WINDOWS\system32\msxml3.dll, Microsoft Corporation>
                                      [XSL Template]
                                      {2933BF94-7B36-11D2-B20E-00C04F983E60} <C:\WINDOWS\system32\msxml3.dll, Microsoft Corporation>
                                      [DHTML Edit Control Safe for Scripting for IE5]
                                      {2D360201-FFF5-11D1-8D03-00A0C959BC0A} <C:\Program Files\Fichiers communs\Microsoft Shared\Triedit\dhtmled.ocx, Microsoft Corporation>
                                      [HtmlDlgSafeHelper Class]
                                      {3050F819-98B5-11CF-BB82-00AA00BDCE0B} <C:\WINDOWS\system32\mshtmled.dll, Microsoft Corporation>
                                      [Tabular Data Control]
                                      {333C7BC4-460F-11D0-BC04-0080C7055A83} <C:\WINDOWS\system32\tdc.ocx, Microsoft Corporation>
                                      [BitComet Helper]
                                      {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} <C:\Program Files\BitComet\tools\BitCometBHO_1.1.8.30.dll, BitComet>
                                      [QuickTime Object]
                                      {4063BE15-3B08-470D-A0D5-B37161CFFD69} <C:\Program Files\QuickTime\QTPlugin.ocx, Apple Computer, Inc.>
                                      [Microsoft Office Control]
                                      {4453D895-F2A1-4A38-A285-1EF9BD3F6D5D} <C:\PROGRA~1\MICROS~3\OFFICE11\AUTHZAX.DLL, Microsoft Corporation>
                                      [XML Document]
                                      {48123BC4-99D9-11D1-A6B3-00C04FD91555} <C:\WINDOWS\system32\msxml3.dll, Microsoft Corporation>
                                      []
                                      {4F07F79F-087F-42CF-8B36-7A88D06088E9} <C:\PROGRA~1\MSNMES~1\MSGSC8~1.DLL, Microsoft Corporation>
                                      [Shell Name Space]
                                      {55136805-B2DE-11D1-B9F2-00A0C98BC547} <C:\WINDOWS\system32\ieframe.dll, Microsoft Corporation>
                                      [isInstalled Class]
                                      {5852F5ED-8BF4-11D4-A245-0080C6F74284} <C:\Program Files\Java\jre1.6.0_03\bin\wsdetect.dll, Sun Microsystems, Inc.>
                                      [Windows Media Player]
                                      {6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
                                      [Active Desktop Mover]
                                      {72267F6A-A6F9-11D0-BC94-00C04FB67863} <%SystemRoot%\system32\SHELL32.dll, N/A>
                                      [SSVHelper Class]
                                      {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} <C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll, Sun Microsystems, Inc.>
                                      [Microsoft Web Browser]
                                      {8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\ieframe.dll, Microsoft Corporation>
                                      [Java Plug-in 1.6.0_03]
                                      {8AD9C840-044E-11D1-B3E9-00805F499D93} <C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll, Sun Microsystems, Inc.>
                                      [Google Toolbar Helper]
                                      {AA58ED58-01DD-4D91-8333-CF10577473F7} <c:\program files\google\googletoolbar1.dll, Google Inc.>
                                      [Google Toolbar Notifier BHO]
                                      {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} <C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll, Google Inc.>
                                      [SearchAssistantOC]
                                      {B45FF030-4447-11D2-85DE-00C04FA35C89} <%SystemRoot%\System32\shdocvw.dll, N/A>
                                      [RDS.DataSpace]
                                      {BD96C556-65A3-11D0-983A-00C04FC29E36} <C:\Program Files\Fichiers communs\System\msadc\msadco.dll, Microsoft Corporation>
                                      [Java Plug-in 1.6.0_02]
                                      {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} <C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll, Sun Microsystems, Inc.>
                                      [Java Plug-in 1.6.0_02]
                                      {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBB} <C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll, Sun Microsystems, Inc.>
                                      [Java Plug-in 1.6.0_02]
                                      {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBC} <C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll, Sun Microsystems, Inc.>
                                      [Java Plug-in 1.6.0_03]
                                      {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} <C:\Program Files\Java\jre1.6.0_03\bin\npjpi160_03.dll, Sun Microsystems, Inc.>
                                      [AUDIO__MID Moniker Class]
                                      {CD3AFA74-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
                                      [AUDIO__MP3 Moniker Class]
                                      {CD3AFA76-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
                                      [VIDEO__X_MS_WMV Moniker Class]
                                      {CD3AFA94-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
                                      [Shockwave Flash Object]
                                      {D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9d.ocx, Adobe Systems, Inc.>
                                      [QuickTimeCheck Class]
                                      {DE4AF3B0-F4D4-11D3-B41A-0050DA2E6C21} <C:\Program Files\QuickTime\QTSystem\QuickTimeCheck.ocx, Apple Computer, Inc.>
                                      []
                                      {E1771B7F-98BE-407F-BA67-AA16ADA5D0C5} <C:\PROGRA~1\MSNMES~1\MSGSC8~1.DLL, Microsoft Corporation>
                                      [XML HTTP Request]
                                      {ED8C108E-4349-11D2-91A4-00C04F7969E8} <C:\WINDOWS\system32\msxml3.dll, Microsoft Corporation>
                                      []
                                      {F06608C7-1874-4EEA-B3B2-DF99EBB144B8} <C:\PROGRA~1\MSNMES~1\MSGSC8~1.DLL, Microsoft Corporation>
                                      [XML DOM Document 3.0]
                                      {F5078F32-C551-11D3-89B9-0000F81FE221} <C:\WINDOWS\system32\msxml3.dll, Microsoft Corporation>
                                      [Free Threaded XML DOM Document 3.0]
                                      {F5078F33-C551-11D3-89B9-0000F81FE221} <C:\WINDOWS\system32\msxml3.dll, Microsoft Corporation>
                                      [XML Schema Cache 3.0]
                                      {F5078F34-C551-11D3-89B9-0000F81FE221} <C:\WINDOWS\system32\msxml3.dll, Microsoft Corporation>
                                      [XML HTTP 3.0]
                                      {F5078F35-C551-11D3-89B9-0000F81FE221} <C:\WINDOWS\system32\msxml3.dll, Microsoft Corporation>
                                      [XSL Template 3.0]
                                      {F5078F36-C551-11D3-89B9-0000F81FE221} <C:\WINDOWS\system32\msxml3.dll, Microsoft Corporation>
                                      [XML Data Source Object 3.0]
                                      {F5078F39-C551-11D3-89B9-0000F81FE221} <C:\WINDOWS\system32\msxml3.dll, Microsoft Corporation>
                                      [Free Threaded XML DOM Document]
                                      {F6D90F12-9C73-11D3-B32E-00C04F990BB4} <C:\WINDOWS\system32\msxml3.dll, Microsoft Corporation>
                                      [XML Data Source Object]
                                      {F6D90F14-9C73-11D3-B32E-00C04F990BB4} <C:\WINDOWS\system32\msxml3.dll, Microsoft Corporation>
                                      [XML HTTP]
                                      {F6D90F16-9C73-11D3-B32E-00C04F990BB4} <C:\WINDOWS\system32\msxml3.dll, Microsoft Corporation>
                                      [&D&ownload &with BitComet]
                                      <res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm, N/A>
                                      [&D&ownload all video with BitComet]
                                      <res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm, N/A>
                                      [&D&ownload all with BitComet]
                                      <res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm, N/A>
                                      [E&xporter vers Microsoft Excel]
                                      <res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000, N/A>

                                      ==================================
                                      Running Processes
                                      [PID: 516 / SYSTEM][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
                                      [PID: 568 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
                                      [PID: 600 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
                                      [C:\WINDOWS\system32\Ati2evxx.dll] [ATI Technologies Inc., 6.14.10.4158]
                                      [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
                                      [PID: 644 / SYSTEM][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
                                      [C:\WINDOWS\AppPatch\AcAdProc.dll] [Microsoft Corporation, 5.1.2600.3008 (xpsp.061004-0027)]
                                      [PID: 660 / SYSTEM][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
                                      [PID: 812 / SYSTEM][C:\WINDOWS\System32\Ati2evxx.exe] [ATI Technologies Inc., 6.14.10.4158]
                                      [C:\WINDOWS\System32\Ati2edxx.dll] [ATI Technologies, Inc., 6, 14, 10, 2510]
                                      [C:\WINDOWS\System32\atipdlxx.dll] [ATI Technologies, Inc., 6, 14, 10, 2515]
                                      [PID: 828 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
                                      [PID: 892 / SERVICE RÉSEAU][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
                                      [PID: 932 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
                                      [C:\WINDOWS\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
                                      [C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16544 (vista_gdr.070814-1500)]
                                      [C:\WINDOWS\system32\wups2.dll] [Microsoft Corporation, 7.0.6000.381 (winmain(wmbla).070730-1740)]
                                      [PID: 1000 / SERVICE RÉSEAU][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
                                      [PID: 1032 / SERVICE LOCAL][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
                                      [C:\WINDOWS\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
                                      [C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16544 (vista_gdr.070814-1500)]
                                      [PID: 1220 / SYSTEM][C:\WINDOWS\system32\Ati2evxx.exe] [ATI Technologies Inc., 6.14.10.4158]
                                      [C:\WINDOWS\system32\Ati2edxx.dll] [ATI Technologies, Inc., 6, 14, 10, 2510]
                                      [C:\WINDOWS\system32\atipdlxx.dll] [ATI Technologies, Inc., 6, 14, 10, 2515]
                                      [C:\WINDOWS\system32\ati2evxx.dll] [ATI Technologies Inc., 6.14.10.4158]
                                      [PID: 1400 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
                                      [C:\WINDOWS\system32\CNMLM78.DLL] [CANON INC., 1.90.2.61]
                                      [C:\WINDOWS\system32\mdimon.dll] [Microsoft Corporation, 11.3.1897.0]
                                      [C:\WINDOWS\System32\spool\PRTPROCS\W32X86\CNMPD78.DLL] [CANON INC., 1.90.2.61]
                                      [C:\WINDOWS\System32\spool\PRTPROCS\W32X86\mdippr.dll] [Microsoft Corporation, 11.3.1897.0]
                                      [PID: 1524 / SYSTEM][C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe] [Avira GmbH, 7.00.00.82]
                                      [C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgio.dll] [Avira GmbH, 7.00.00.01]
                                      [C:\Program Files\Avira\AntiVir PersonalEdition Classic\avevtlog.dll] [Avira GmbH, 7.00.00.20]
                                      [C:\Program Files\Avira\AntiVir PersonalEdition Classic\guardmsg.dll] [Avira GmbH, 7.00.11.00]
                                      [C:\Program Files\Avira\AntiVir PersonalEdition Classic\sqlite3.dll] [, 3, 3, 17, 1]
                                      [C:\Program Files\Avira\AntiVir PersonalEdition Classic\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
                                      [C:\Program Files\Avira\AntiVir PersonalEdition Classic\AVPREF.DLL] [Avira GmbH, 7.00.02.02]
                                      [C:\Program Files\Avira\AntiVir PersonalEdition Classic\SMTPLIB.DLL] [Avira GmbH, 1.02.00.17]
                                      [C:\Program Files\Avira\AntiVir PersonalEdition Classic\AVPACK32.DLL] [Avira GmbH, 7.03.00.15]
                                      [C:\Program Files\Avira\AntiVir PersonalEdition Classic\unacev2.dll] [N/A, ]
                                      [C:\Program Files\Avira\AntiVir PersonalEdition Classic\AVEWIN32.DLL] [Avira GmbH, 7.6.0.30]
                                      [C:\Program Files\Avira\AntiVir PersonalEdition Classic\avipc.dll] [Avira GmbH, 1.00.00.04]
                                      [PID: 1664 / BEGNY][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.3156 (xpsp_sp2_gdr.070613-1234)]
                                      [C:\WINDOWS\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
                                      [C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16544 (vista_gdr.070814-1500)]
                                      [C:\WINDOWS\system32\ieframe.dll] [Microsoft Corporation, 7.00.6000.16544 (vista_gdr.070814-1500)]
                                      [C:\WINDOWS\system32\WPDShServiceObj.dll] [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
                                      [C:\WINDOWS\system32\PortableDeviceTypes.dll] [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
                                      [C:\WINDOWS\system32\PortableDeviceApi.dll] [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
                                      [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
                                      [C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\PDFShell.dll] [Adobe Systems, Inc., 8.1.0.0]
                                      [C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\PDFShell.FRA] [Adobe Systems, Inc., 8.0.0.0]
                                      [C:\Program Files\WinRAR\rarext.dll] [N/A, ]
                                      [C:\Program Files\Nero\Nero 7\Nero BackItUp\NBShell.dll] [Nero AG, 2, 7, 3, 0]
                                      [C:\Program Files\Nero\Nero 7\Nero BackItUp\MFC71U.DLL] [Microsoft Corporation, 7.10.3077.0]
                                      [C:\Program Files\Nero\Nero 7\Nero BackItUp\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
                                      [C:\Program Files\Nero\Nero 7\Nero BackItUp\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
                                      [C:\Program Files\Avira\AntiVir PersonalEdition Classic\shlext.dll] [Avira GmbH, 7.00.00.10]
                                      [C:\WINDOWS\System32\StkCWIA.dll] [Syntek America Inc., 1.0.0.2]
                                      [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll] [Microsoft Corporation, 11.0.5510]
                                      [PID: 404 / SYSTEM][C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe] [Avira GmbH, 7.00.00.62]
                                      [C:\Program Files\Avira\AntiVir PersonalEdition Classic\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
                                      [C:\Program Files\Avira\AntiVir PersonalEdition Classic\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
                                      [C:\Program Files\Avira\AntiVir PersonalEdition Classic\schedr.dll] [Avira GmbH, 7.00.24.00]
                                      [C:\Program Files\Avira\AntiVir PersonalEdition Classic\avevtlog.dll] [Avira GmbH, 7.00.00.20]
                                      [C:\Program Files\Avira\AntiVir PersonalEdition Classic\sqlite3.dll] [, 3, 3, 17, 1]
                                      [C:\Program Files\Avira\AntiVir PersonalEdition Classic\avipc.dll] [Avira GmbH, 1.00.00.04]
                                      [PID: 436 / SYSTEM][C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe] [Google, 2.2.824.5515.beta]
                                      [PID: 356 / SYSTEM][C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe] [Hewlett-Packard Company, 1.4.142.1]
                                      [C:\Program Files\Fichiers communs\LightScribe\LSSProxy.dll] [Hewlett-Packard Company, 1.4.142.1]
                                      [C:\Program Files\Fichiers communs\LightScribe\LSLog.dll] [Hewlett-Packard Company, 1.4.142.1]
                                      [PID: 772 / SYSTEM][C:\Program Files\CDBurnerXP\NMSAccessU.exe] [N/A, ]
                                      [PID: 1080 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
                                      [PID: 1152 / SYSTEM][C:\WINDOWS\System32\StkCSrv.exe] [Syntek America Inc., 1.0.0.2]
                                      [PID: 1164 / SYSTEM][C:\WINDOWS\system32\Tablet.exe] [Wacom Technology, Corp., 6.0.4-4]
                                      [PID: 1516 / BEGNY][C:\WINDOWS\system32\WTablet\TabUserW.exe] [Wacom Technology, Corp., 6.0.4-4]
                                      [PID: 164 / SYSTEM][C:\WINDOWS\system32\Tablet.exe] [Wacom Technology, Corp., 6.0.4-4]
                                      [PID: 1568 / SERVICE LOCAL][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
                                      [PID: 2856 / BEGNY][C:\WINDOWS\ATK0100\HControl.exe] [, 1043, 2, 15, 65]
                                      [C:\WINDOWS\ATK0100\CMSSC.dll] [N/A, ]
                                      [C:\WINDOWS\ATK0100\inter_f2.dll] [ATK, 1043, 2, 15, 52]
                                      [C:\WINDOWS\ATK0100\ATKWLIOC.DLL] [ACTIONTEC Electronics,Inc, 2.01.02]
                                      [C:\WINDOWS\ATK0100\SiSPkt.dll] [Silicon Integrated Systems Corp., 1, 0, 0, 45]
                                      [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
                                      [C:\WINDOWS\ATK0100\ASUSNET.dll] [, 1, 9, 9, 2]
                                      [C:\WINDOWS\ATK0100\ASW32N50.dll] [Printing Communications Assoc., Inc. (PCAUSA), 5.00.13.50]
                                      [PID: 2888 / BEGNY][C:\WINDOWS\RTHDCPL.EXE] [Realtek Semiconductor Corp., 2.1.5.7]
                                      [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
                                      [PID: 2964 / BEGNY][C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe] [Motorola Inc., 6.12.04]
                                      [C:\Program Files\Motorola\SMSERIAL\sm56eng.dll] [Motorola Inc., 6.12.04]
                                      [C:\Program Files\Motorola\SMSERIAL\sm56fra.dll] [, ]
                                      [C:\Program Files\Motorola\SMSERIAL\sm56brz.dll] [, ]
                                      [C:\Program Files\Motorola\SMSERIAL\sm56chs.dll] [, ]
                                      [C:\Program Files\Motorola\SMSERIAL\sm56cht.dll] [, ]
                                      [C:\Program Files\Motorola\SMSERIAL\sm56ger.dll] [, ]
                                      [C:\Program Files\Motorola\SMSERIAL\sm56ita.dll] [, ]
                                      [C:\Program Files\Motorola\SMSERIAL\sm56jpn.dll] [, ]
                                      [C:\Program Files\Motorola\SMSERIAL\sm56esp.dll] [, ]
                                      [C:\Program Files\Motorola\SMSERIAL\sm56kor.dll] [, ]
                                      [C:\Program Files\Motorola\SMSERIAL\sm56dnk.dll] [, ]
                                      [PID: 2992 / BEGNY][C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe] [Sun Microsystems, Inc., 6.0.30.5]
                                      [C:\WINDOWS\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
                                      [C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16544 (vista_gdr.070814-1500)]
                                      [PID: 3036 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
                                      [PID: 3084 / BEGNY][C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe] [Avira GmbH, 7.02.00.16]
                                      [C:\Program Files\Avira\AntiVir PersonalEdition Classic\MFC71U.DLL] [Microsoft Corporation, 7.10.3077.0]
                                      [C:\Program Files\Avira\AntiVir PersonalEdition Classic\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
                                      [C:\Program Files\Avira\AntiVir PersonalEdition Classic\cclib.dll] [Avira GmbH, 7.02.00.03]
                                      [C:\Program Files\Avira\AntiVir PersonalEdition Classic\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
                                      [c:\program files\avira\antivir personaledition classic\ccgen.dll] [Avira GmbH, 7.02.00.10]
                                      [c:\program files\avira\antivir personaledition classic\ccgenrc.dll] [Avira GmbH, 7.02.04.02]
                                      [c:\program files\avira\antivir personaledition classic\ccguard.dll] [Avira GmbH, 7.00.01.35]
                                      [c:\program files\avira\antivir personaledition classic\ccgrdrc.dll] [Avira GmbH, 7.00.06.00]
                                      [C:\Program Files\Avira\AntiVir PersonalEdition Classic\avipc.dll] [Avira GmbH, 1.00.00.04]
                                      [c:\program files\avira\antivir personaledition classic\ccupdate.dll] [Avira GmbH, 7.02.00.04]
                                      [c:\program files\avira\antivir personaledition classic\ccupdrc.dll] [Avira GmbH, 7.02.01.00]
                                      [c:\program files\avira\antivir personaledition classic\cclic.dll] [Avira GmbH, 7.02.00.04]
                                      [c:\program files\avira\antivir personaledition classic\cclicrc.dll] [Avira GmbH, 7.02.01.00]
                                      [c:\program files\avira\antivir personaledition classic\ccmsg.dll] [Avira GmbH, 7.00.00.00]
                                      [C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16544 (vista_gdr.070814-1500)]
                                      [PID: 3100 / BEGNY][C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe] [Google Inc., 2, 0, 301, 1654]
                                      [C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\gtn.dll] [Google Inc., 2, 1, 615, 5858]
                                      [C:\WINDOWS\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
                                      [C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16544 (vista_gdr.070814-1500)]
                                      [C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll] [Google Inc., 2, 1, 615, 5858]
                                      [PID: 3128 / BEGNY][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
                                      [PID: 3156 / BEGNY][C:\Program Files\Windows Live\Messenger\msnmsgr.exe] [Microsoft Corporation, 8.5.1235.0517]
                                      [C:\Program Files\Windows Live\Messenger\MSNCore.dll] [Microsoft Corporation, 8.5.1235.0517]
                                      [C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16544 (vista_gdr.070814-1500)]
                                      [C:\WINDOWS\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
                                      [C:\Program Files\Windows Live\Messenger\msidcrl40.dll] [Microsoft Corporation, 4.100.313.1]
                                      [C:\Program Files\Windows Live\Messenger\ContactsUX.dll] [Microsoft Corporation, 8.5.1235.0517]
                                      [C:\Program Files\Windows Live\Messenger\msgslang.8.5.1235.0517.dll] [Microsoft Corporation, 8.5.1235.0517]
                                      [C:\Program Files\Windows Live\Messenger\msgsres.dll] [Microsoft Corporation, 8.5.1235.0517]
                                      [C:\Program Files\Windows Live\Messenger\lcapi.dll] [Microsoft Corporation, 1.7.256.0 (RTC Version 4.3.5371.0) built by: msn8.0(rtbldlab)]
                                      [C:\WINDOWS\system32\msdmo.dll] [, ]
                                      [C:\Program Files\Windows Live\Messenger\lcres.dll] [Microsoft Corp., 1.7.109.0 (RTC Version 4.3.5371.0) built by: msn8.0(rtbldlab)]
                                      [C:\Program Files\Windows Live\Messenger\RTMPLTFM.dll] [Microsoft Corporation, 3.0.5774.0 built by: media_msn80]
                                      [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
                                      [C:\Program Files\Windows Live\Messenger\MSGSWCAM.dll] [Microsoft Corporation, 8.5.1235.0517]
                                      [C:\WINDOWS\system32\sirenacm.dll] [Microsoft Corp., 8.1.0178.00]
                                      [C:\WINDOWS\system32\StkCProp.ax] [Syntek America Inc., 1.0.0.2]
                                      [PID: 3200 / BEGNY][C:\Program Files\BitComet\BitComet.exe] [www.BitComet.com, 0.93]
                                      [C:\WINDOWS\system32\ieframe.dll] [Microsoft Corporation, 7.00.6000.16544 (vista_gdr.070814-1500)]
                                      [C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16544 (vista_gdr.070814-1500)]
                                      [C:\WINDOWS\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
                                      [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
                                      [PID: 3404 / BEGNY][C:\WINDOWS\ATK0100\ATKOSD.exe] [, 1043, 2, 15, 63]
                                      [PID: 2580 / BEGNY][C:\Program Files\internet explorer\iexplore.exe] [Microsoft Corporation, 7.00.6000.16544 (vista_gdr.070814-1500)]
                                      [C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16544 (vista_gdr.070814-1500)]
                                      [C:\WINDOWS\system32\IEFRAME.dll] [Microsoft Corporation, 7.00.6000.16544 (vista_gdr.070814-1500)]
                                      [C:\WINDOWS\system32\IEUI.dll] [Microsoft Corporation, 7.00.5730.11 (winmain(wmbla).061017-1135)]
                                      [C:\WINDOWS\system32\xmllite.dll] [Microsoft Corporation, 1.00.1018.0]
                                      [C:\Program Files\Microsoft Office\OFFICE11\msohev.dll] [Microsoft Corporation, 11.0.5510]
                                      [C:\Program Files\Internet Explorer\ieproxy.dll] [Microsoft Corporation, 7.00.5730.11 (winmain(wmbla).061017-1135)]
                                      [C:\WINDOWS\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
                                      [c:\program files\google\googletoolbar1.dll] [Google Inc., 4, 0, 1601, 4978]
                                      [C:\Program Files\BitComet\tools\BitCometBHO_1.1.8.30.dll] [BitComet, 20070830]
                                      [C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll] [Sun Microsystems, Inc., 6.0.30.5]
                                      [C:\Program Files\Java\jre1.6.0_03\bin\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
                                      [C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll] [Google Inc., 2, 1, 615, 5858]
                                      [C:\WINDOWS\system32\ieapfltr.dll] [Microsoft Corporation, 7.0.6000.16461]
                                      [C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
                                      [C:\WINDOWS\system32\Macromed\Flash\Flash9d.ocx] [Adobe Systems, Inc., 9,0,47,0]
                                      [PID: 7224 / BEGNY][C:\Documents and Settings\BEGNY\Bureau\SREngPS.EXE] [Smallfrogs Studio, 2.5.16.900]
                                      [C:\WINDOWS\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
                                      [C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16544 (vista_gdr.070814-1500)]
                                      [C:\Documents and Settings\BEGNY\Bureau\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15]

                                      ==================================
                                      File Associations
                                      .TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
                                      .EXE OK. ["%1" %*]
                                      .COM OK. ["%1" %*]
                                      .PIF OK. ["%1" %*]
                                      .REG OK. [regedit.exe "%1"]
                                      .BAT OK. ["%1" %*]
                                      .SCR OK. ["%1" /S]
                                      .CHM OK. ["C:\WINDOWS\hh.exe" %1]
                                      .HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
                                      .INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
                                      .INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
                                      .VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
                                      .JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
                                      .LNK OK. [{00021401-0000-0000-C000-000000000046}]

                                      ==================================
                                      Winsock Provider
                                      N/A

                                      ==================================
                                      Autorun.Inf
                                      N/A

                                      ==================================
                                      HOSTS File
                                      127.0.0.1 localhost

                                      ==================================
                                      Process Privileges Scan
                                      Special Privilege Enabled: SeLoadDriverPrivilege [PID = 1524, C:\PROGRAM FILES\AVIRA\ANTIVIR PERSONALEDITION CLASSIC\AVGUARD.EXE]
                                      Special Privilege Enabled: SeLoadDriverPrivilege [PID = 3084, C:\PROGRAM FILES\AVIRA\ANTIVIR PERSONALEDITION CLASSIC\AVGNT.EXE]

                                      ==================================
                                      API HOOK
                                      N/A

                                      ==================================
                                      Hidden Process
                                      N/A

                                      ==================================

                                      [/CODE]
                                      • 1
                                      • 2
                                      • 3