Virus -Ultimate cleaner

Résolu/Fermé
Bonjour,

Je me suis fait vaoir comme un bleu et je n'arrive plus � me d�barasser de certaines cochonneries. Je ne sais pas si je vais y arriver mais si vous arrivez � m'aider, qui sait?

Voici le rapport HijackThis que j'obtiens.

Merci pour votre aide.

JC

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:41:02, on 11/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Network Associates\VirusScan\Avsynmgr.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
c:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\Program Files\Network Associates\VirusScan\VsStat.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Network Associates\VirusScan\Vshwin32.exe
C:\Program Files\Network Associates\VirusScan\Avconsol.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Fichiers communs\Network Associates\McShield\Mcshield.exe
C:\WINDOWS\ATK0100\HControl.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
C:\Program Files\PowerForPhone\PowerForPhone\PowerForPhone.exe
C:\Program Files\ASUS\ASUS Live Update\ALU.exe
C:\Program Files\ASUS\Splendid\ACMON.exe
C:\Program Files\Wireless Console 2\wcourier.exe
C:\Program Files\ASUS\ATK Media\DMEDIA.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\ACEngSvr.exe
C:\Program Files\ASUS\Power4 Gear\BatteryLife.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
C:\WINDOWS\emMON.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\ATK0100\ATKOSD.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ASUS\Net4Switch\Net4Switch.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\Microsoft ActiveSync\Wcescomm.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\PROGRA~1\MICROS~3\rapimgr.exe
C:\Program Files\ASUS\Asus MultiFrame\MultiFrame.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosBtProc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.crawler.com/search/dispatcher.aspx?tp=aus&qkw=%s&tbid=60327
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=60327
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://dnl.crawler.com/support/sa_customize.aspx?TbId=60327
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=60327
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://dnl.crawler.com/support/sa_customize.aspx?TbId=60327
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [HControl] C:\WINDOWS\ATK0100\HControl.exe
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
O4 - HKLM\..\Run: [PowerForPhone] C:\Program Files\PowerForPhone\PowerForPhone\PowerForPhone.exe
O4 - HKLM\..\Run: [ASUS Live Update] C:\Program Files\ASUS\ASUS Live Update\ALU.exe
O4 - HKLM\..\Run: [ACMON] C:\Program Files\ASUS\Splendid\ACMON.exe
O4 - HKLM\..\Run: [Wireless Console 2] C:\Program Files\Wireless Console 2\wcourier.exe
O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files\ASUS\ATK Media\DMEDIA.EXE
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ABLKSR] C:\WINDOWS\ABLKSR\ABLKSR.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Power_Gear] C:\Program Files\ASUS\Power4 Gear\BatteryLife.exe 1
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [VirtualCloneDrive] "C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
O4 - HKLM\..\Run: [emMON] emMON.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [pyhgdepy] rundll32.exe "C:\Program Files\pyhgdepy\nmtchkxy.dll",Init
O4 - HKLM\..\Run: [apqjojab] regsvr32 /u "C:\Documents and Settings\All Users\Application Data\apqjojab.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA41] command /c del "C:\WINDOWS\system32\gliaekib.exe_tobedeleted_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6677] cmd /c del "C:\WINDOWS\system32\gliaekib.exe_tobedeleted_old"
O4 - HKLM\..\RunOnce: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Net4Switch] C:\Program Files\ASUS\Net4Switch\Net4Switch.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\Wcescomm.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\RunOnce: [SpybotDeletingB3806] command /c del "C:\WINDOWS\system32\gliaekib.exe_tobedeleted_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1305] cmd /c del "C:\WINDOWS\system32\gliaekib.exe_tobedeleted_old"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE R�SEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: MultiFrame.lnk = ?
O4 - Global Startup: Bluetooth Manager.lnk = ?
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra 'Tools' menuitem: Cr�er un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=https://www.asus.com/fr/
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://appldnld.apple.com/QuickTime/qtactivex/qtplugin.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O23 - Service: AVSync Manager (AvSynMgr) - Unknown owner - C:\Program Files\Network Associates\VirusScan\Avsynmgr.exe
O23 - Service: Service d'indexation CiSvcSchedule (CiSvcSchedule) - Unknown owner - C:\WINDOWS\system32\c_437v.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
O23 - Service: McShield - Unknown owner - C:\Program Files\Fichiers communs\Network Associates\McShield\Mcshield.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Panda Process Protection Service (PavPrSrv) - Unknown owner - C:\Program Files\Fichiers communs\Panda Software\PavShld\pavprsrv.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe

--
End of file - 10878 bytes
Configuration: Windows XP mediacenter
Internet Explorer 7.0

40 réponses

  1. Re,

    J'ai l'impression que je ne peux pas clore la discussion car je n'en suis pas propiétaire. Peux-tu le faire pour moi?

    Merci
    JC
    0
    1. Salut Denis,

      Je crois que le temps des adieux est arrivé, sniff, je m'étais habitué à cette communication presque quotidienne. Merci encore pour le super boulot et les conseils. Je recommanderai le forum CMM à coup sûr!

      A une autre fois, peut-être...

      Jean-Christophe
      0
      1. salut jc,

        -c_1252s.exe Cliché instantané de volume VSSDnscache
        c_1252s.exe et VSSDnscache, rien trouvé là dessus, pas d'impact.

        -c_437v.exe Service d'indexation CiSvcSchedule, si c'est vraiment le processus original ou si c'est une imitation, c'est un processus qui peut être arrêté (ciscvc.exe).
        http://www.commentcamarche.net/processus/cisvc exe.php3

        -J'ai fait le clean avec ToolsCleaner2 (pas de log) et CCleaner.
        * Le rapport (TCleaner.txt) se trouve à la racine de votre disque dur (C:\)
        Tu peux le consulter, mais ne te casse pas la tête à le recopier ici.

        -J'aurais pu t'éviter certaines procédure inutile surtout avant de passer à combofix qui peu s'avérer dangereux si mal employé.

        -Tu pourras cocher problème résolu semble t-il.

        Bye bye

        Denis
        0
        1. Salut Denis,

          J'ai pu faire ce que tu me demandes avant de partir au boulot, je sens que la fin de notre collaboration arrive...

          HijackThis : le fix n'a rien fait, MAIS:
          Il a fallu que je désactive ces 2 services pour qu'ils disparaissent de HijackThis (de toutes façons, ils ne pouvaient pas démarrer). Tu les connais? Quel est l'impact s'ils ne fonctionnent pas?

          c_1252s.exe Cliché instantané de volume VSSDnscache
          c_437v.exe Service d'indexation CiSvcSchedule

          J'ai fait le clean avec ToolsCleaner2 (pas de log) et CCleaner.

          J'ai repassé Spybot, toujours rien à signaler. J'attends ta réponse pour cocher résolu.

          En tous cas, j'ai apprécié ta disponibilité et et ta méthode. J'ai vraiment eu l'impression que tu savais où tu allais. Toi et tes comparses sont très utiles et encore MERCI pour l'aide.

          Je ferai plus attention à l'avenir et des contrôles plus réguliers.

          A+

          PS: J'espère que tous les nettoyages ne sont pas aussi difficiles!
          0
          1. jc74,

            -Vu les symptômes et tes dernières analyses on peut dire que tout semble fini enfinnnn
            Bravo pour ta patience.

            -Tu as voulu te venger avec ton log sans fin Adaware hehe

            ------------------------
            -À propos de ces 2 fameuses lignes il faut tout d'abord stopper le service correspondant (merci jal) :
            Pour cela cliquer ICI
            Et rechercher c_437v.exe et c_1252s.exe puis les arrêter.

            Ensuite cocher les lignes
            O23 - Service: Service d'indexation CiSvcSchedule (CiSvcSchedule) - Unknown owner - C:\WINDOWS\system32\c_437v.exe (file missing)
            O23 - Service: Cliché instantané de volume VSSDnscache (VSSDnscache) - Unknown owner - C:\WINDOWS\system32\c_1252s.exe (file missing)

            Fermez toutes les applications et le navigateur et cliquer sur Fix Checked.

            ------------------------
            - ToolsCleaner de A.Rothstein
            Pour supprimer toutes les traces des logiciels qui ont servi à traiter les infections spécifiques

            Télécharge le http://pagesperso-orange.fr/AceRothstein/ToolsCleaner2.exe sur ton Bureau.
            * Double-clique sur ToolsCleaner2.bat et laisse le travailler
            * Clique sur Recherche et laisse le scan se terminer.
            * Clique sur Suppression pour finaliser.
            * Tu peux, si tu le souhaites, te servir des Options facultatives.
            * Clique sur Quitter, pour que le rapport puisse se créer.

            ------------------------
            - Ensuite, désactiver la restauration système attendre qu'il travail puis l’activer de nouveau
            Pour cela suivre les instructions du lien ICI

            ------------------------
            -Puis passer une dernière fois CCleaner (Bouton Registre et Nettoyeur)

            Je penses sans trop m'avancer tu pourras cocher le problème comme résolu en haut de ton tout premier message.

            A+
            1
            1. Re,

              J'ai encore fait qq tests...

              ad-aware a pu enfin passer sans planter, tu peux voir le log ci-dessous au cas où.

              A bientôt pour de bonnes nouvelles?

              JC

              **********************************************************************************
              Ad-Aware 2007 Build
              Log File Created on: 2008-02-04 22:56:21
              Using Definitions File: C:\Documents and Settings\All Users\Application Data\Lavasoft\Ad-Aware 2007\core.aawdef
              Computer name: ASUS_JC
              Name of user performing scan: SYSTEM

              System information
              ===========================
              Number of processors: 2
              Processor type: Intel(R) Core(TM)2 CPU T5500 @ 1.66GHz
              Memory Available: 65%
              Total Physical Memory: 2146742272 Bytes
              Available Physical Memory: 1377959936 Bytes
              Total Page File Size: 4131627008 Bytes
              Available On Page File: 3459801088 Bytes
              Total Virtual Memory: 2147352576 Bytes
              Available Virtual Memory: 1889366016 Bytes
              OS: Microsoft Windows XP Service Pack 2 (Build 2600)

              Ad-Aware 2007 Settings
              ===========================
              Skipping files larger than 1048576 kB
              Ignoring infections with lower TAI than: 3

              Extended Ad-Aware 2007 Settings
              ===========================
              Unloading known modules during scan
              Ignoring spanned files when scanning cab archives
              Reanalyzing results after scanning before displaying results
              Trying to unload modules prior to removal
              Let Windows remove files currently in use at next reboot
              Removing quarantined objects after restore
              Deactivating Ad-Watch during scans
              Writeprotecting system files after repairs
              Include info about ignored objects in log file
              Including basic settings in log file
              Including advanced settings in log file
              Including user and computer name in log file
              Create and save WebUpdate log file

              Databaseinfo
              ===========================
              Version number: 49
              Build Number: 0
              Build Date and Time: 2008/02/04 09:59:53

              Scan Statistics
              ===========================
              Method: Full
              Scan tracking cookies.............................: On
              Scan ADS filestreams..............................: Off

              Item Scanned: 246092
              Infections Detected: 56
              Infections Ignored: 0

              Scan detailed statistics
              ===========================
              Type Critical Total
              Process Scan....: 0 0
              Registry Scan...: 0 0
              Registry PE Scan: 0 0
              Hosts File Scan.: 0 0
              File Scan.......: 0 0
              Folder Scan.....: 0 0
              LSP Scan........: 0 0
              ADS Scan........: 0 0
              Cookie Scan.....: 53 53
              File Hash Scan..: 0 0

              Infections Found
              ===========================
              Family Id: 725 Name: Tracking Cookie Category: DataMiner TAI:3
              Item Id: 600000437 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\NetworkService\Cookies\index.dat bizrate.com sessionid /
              Item Id: 600000437 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\NetworkService\Cookies\index.dat bizrate.com br /
              Item Id: 600000437 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\NetworkService\Cookies\index.dat bizrate.com shown_welcome_text /
              Item Id: 600000437 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\NetworkService\Cookies\index.dat bizrate.com _data /
              Item Id: 600000437 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\NetworkService\Cookies\index.dat bizrate.com s_nr /
              Item Id: 600000437 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\NetworkService\Cookies\index.dat bizrate.com s_vi /
              Item Id: 600000119 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\NetworkService\Cookies\index.dat mp.kelkoo.com kelkooID /
              Item Id: 600000101 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\Jean-Christophe\Cookies\index.dat overture.com CMUserData /
              Item Id: 600000142 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\Jean-Christophe\Cookies\index.dat estat.com e /
              Item Id: 600000001 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\Mylène\Cookies\index.dat adserver.aol.fr CfP /
              Item Id: 600000001 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\Mylène\Cookies\index.dat adserver.aol.fr JEB2 /
              Item Id: 600000458 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\Mylène\Cookies\index.dat adlegend.com PrefID /
              Item Id: 600000190 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\Mylène\Cookies\index.dat www.googleadservices.com Conversion /pagead/conversion/1069870899/
              Item Id: 600000073 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\Mylène\Cookies\index.dat specificclick.net dmc /
              Item Id: 600000073 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\Mylène\Cookies\index.dat specificclick.net dmk /
              Item Id: 600000073 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\Mylène\Cookies\index.dat specificclick.net smc /
              Item Id: 600000073 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\Mylène\Cookies\index.dat specificclick.net smk /
              Item Id: 600000523 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\Mylène\Cookies\index.dat m1.webstats.motigo.com w4u_tv /
              Item Id: 600000461 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\Mylène\Cookies\index.dat ad.uk.tangozebra.com TZID /a
              Item Id: 600000437 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\Mylène\Cookies\index.dat bizrate.com sessionid /
              Item Id: 600000437 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\Mylène\Cookies\index.dat bizrate.com br /
              Item Id: 600000437 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\Mylène\Cookies\index.dat bizrate.com _data /
              Item Id: 600000437 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\Mylène\Cookies\index.dat bizrate.com s_nr /
              Item Id: 600000437 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\Mylène\Cookies\index.dat bizrate.com s_vi /
              Item Id: 600000142 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\Mylène\Cookies\index.dat fr.sitestat.com s1 /n-d/nd-com/
              Item Id: 600000142 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\Mylène\Cookies\index.dat fr.sitestat.com c1 /n-d/
              Item Id: 600000461 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\Lilian\Cookies\index.dat ad.uk.tangozebra.com TZID /a
              Item Id: 600000363 Value: Browser: Firefox Cookie: C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles/7c6qer0n.default\cookies.txt fl01.ct2.comclick.com CKA /
              Item Id: 600000295 Value: Browser: Firefox Cookie: C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles/7c6qer0n.default\cookies.txt adtech.de JEB2 /
              Item Id: 600000363 Value: Browser: Firefox Cookie: C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles/7c6qer0n.default\cookies.txt fl01.ct2.comclick.com CKA_SIZE /
              Item Id: 600000363 Value: Browser: Firefox Cookie: C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles/7c6qer0n.default\cookies.txt fl01.ct2.comclick.com comTrackIdSurfeur /
              Item Id: 600000001 Value: Browser: Firefox Cookie: C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles/7c6qer0n.default\cookies.txt smartadserver.com pid /
              Item Id: 600000001 Value: Browser: Firefox Cookie: C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles/7c6qer0n.default\cookies.txt smartadserver.com TestIfCookieP /
              Item Id: 600000001 Value: Browser: Firefox Cookie: C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles/7c6qer0n.default\cookies.txt smartadserver.com pbwmaj /
              Item Id: 600000001 Value: Browser: Firefox Cookie: C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles/7c6qer0n.default\cookies.txt smartadserver.com pbw /
              Item Id: 600000001 Value: Browser: Firefox Cookie: C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles/7c6qer0n.default\cookies.txt adserver.aol.fr JEB2 /
              Item Id: 600000505 Value: Browser: Firefox Cookie: C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles/7c6qer0n.default\cookies.txt www.bullguard.com fpc1000639991288 /
              Item Id: 600000488 Value: Browser: Firefox Cookie: C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles/7c6qer0n.default\cookies.txt indextools.com itvisitorid1000639991288 /
              Item Id: 600000488 Value: Browser: Firefox Cookie: C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles/7c6qer0n.default\cookies.txt indextools.com itsessionid1000639991288 /
              Item Id: 600000488 Value: Browser: Firefox Cookie: C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles/7c6qer0n.default\cookies.txt indextools.com itvisitorid10001177276537 /
              Item Id: 600000142 Value: Browser: Firefox Cookie: C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles/7c6qer0n.default\cookies.txt fr.sitestat.com s1 /madeinsport/ol/
              Item Id: 600000142 Value: Browser: Firefox Cookie: C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles/7c6qer0n.default\cookies.txt fr.sitestat.com c1 /madeinsport/
              Item Id: 600000171 Value: Browser: Firefox Cookie: C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles/7c6qer0n.default\cookies.txt bs.serving-sys.com eyeblaster /
              Item Id: 600000408 Value: Browser: Firefox Cookie: C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles/7c6qer0n.default\cookies.txt serving-sys.com A2 /
              Item Id: 600000101 Value: Browser: Firefox Cookie: C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles/7c6qer0n.default\cookies.txt overture.com CMUserData /
              Item Id: 600000408 Value: Browser: Firefox Cookie: C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles/7c6qer0n.default\cookies.txt serving-sys.com E2 /
              Item Id: 600000408 Value: Browser: Firefox Cookie: C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles/7c6qer0n.default\cookies.txt serving-sys.com U /
              Item Id: 600000408 Value: Browser: Firefox Cookie: C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles/7c6qer0n.default\cookies.txt serving-sys.com C3 /
              Item Id: 600000408 Value: Browser: Firefox Cookie: C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles/7c6qer0n.default\cookies.txt serving-sys.com B2 /
              Item Id: 600000408 Value: Browser: Firefox Cookie: C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles/7c6qer0n.default\cookies.txt serving-sys.com D3 /
              Item Id: 600000179 Value: Browser: Firefox Cookie: C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles/7c6qer0n.default\cookies.txt atdmt.com AA002 /
              Item Id: 600000142 Value: Browser: Firefox Cookie: C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles/7c6qer0n.default\cookies.txt estat.com e /
              Item Id: 600000425 Value: Browser: Firefox Cookie: C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles/7c6qer0n.default\cookies.txt indexstats.com itvisitorid10001005898704 /
              Family Id: 9999 Name: MRU Object Category: MRU Object TAI:0
              Item Id: 1 Value: MRU Path: C:\Documents and Settings\Jean-Christophe\Recent Count: 14
              Item Id: 2 Value: MRU Registry Key: S-1-5-21-561207044-3630880846-3111129202-1005\Software\Microsoft\Search Assistant\ACMru\5603 Count: 1
              Item Id: 3 Value: MRU Registry Key: S-1-5-21-561207044-3630880846-3111129202-1005\Software\Microsoft\Internet Explorer\TypedURLs Count: 1

              Items Ignored During Scan
              ===========================

              Listing of running processes
              ===========================
              C:\WINDOWS\SYSTEM32\SMSS.EXE
              c:\windows\system32\smss.exe

              c:\windows\system32\ntdll.dll

              C:\WINDOWS\SYSTEM32\CSRSS.EXE
              c:\windows\system32\csrss.exe

              c:\windows\system32\ntdll.dll

              c:\windows\system32\csrsrv.dll

              c:\windows\system32\basesrv.dll

              c:\windows\system32\winsrv.dll

              c:\windows\system32\gdi32.dll

              c:\windows\system32\kernel32.dll

              c:\windows\system32\user32.dll

              c:\windows\system32\sxs.dll

              c:\windows\system32\advapi32.dll

              c:\windows\system32\rpcrt4.dll

              C:\WINDOWS\SYSTEM32\WINLOGON.EXE
              c:\windows\system32\winlogon.exe

              c:\windows\system32\ntdll.dll

              c:\windows\system32\kernel32.dll

              c:\windows\system32\advapi32.dll

              c:\windows\system32\rpcrt4.dll

              c:\windows\system32\authz.dll

              c:\windows\system32\msvcrt.dll

              c:\windows\system32\crypt32.dll

              c:\windows\system32\user32.dll

              c:\windows\system32\gdi32.dll

              c:\windows\system32\msasn1.dll

              c:\windows\system32\nddeapi.dll

              c:\windows\system32\profmap.dll

              c:\windows\system32\netapi32.dll

              c:\windows\system32\userenv.dll

              c:\windows\system32\psapi.dll

              c:\windows\system32\regapi.dll

              c:\windows\system32\secur32.dll

              c:\windows\system32\setupapi.dll

              c:\windows\system32\version.dll

              c:\windows\system32\winsta.dll

              c:\windows\system32\wintrust.dll

              c:\windows\system32\imagehlp.dll

              c:\windows\system32\ws2_32.dll

              c:\windows\system32\ws2help.dll

              c:\windows\system32\imm32.dll

              c:\windows\system32\msgina.dll

              c:\windows\system32\comctl32.dll

              c:\windows\system32\odbc32.dll

              c:\windows\system32\shell32.dll

              c:\windows\system32\shlwapi.dll

              c:\windows\system32\comdlg32.dll

              c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll

              c:\windows\system32\odbcint.dll

              c:\windows\system32\shsvcs.dll

              c:\windows\system32\sfc.dll

              c:\windows\system32\sfc_os.dll

              c:\windows\system32\ole32.dll

              c:\windows\system32\apphelp.dll

              c:\windows\system32\msctfime.ime

              c:\windows\system32\winscard.dll

              c:\windows\system32\wtsapi32.dll

              c:\windows\system32\sxs.dll

              c:\windows\system32\uxtheme.dll

              c:\windows\system32\winmm.dll

              c:\windows\system32\serwvdrv.dll

              c:\windows\system32\umdmxfrm.dll

              c:\windows\system32\cscdll.dll

              c:\windows\system32\wlnotify.dll

              c:\windows\system32\winspool.drv

              c:\windows\system32\mpr.dll

              c:\windows\system32\wgalogon.dll

              c:\windows\system32\oleaut32.dll

              c:\windows\system32\rsaenh.dll

              c:\windows\system32\ntmarta.dll

              c:\windows\system32\wldap32.dll

              c:\windows\system32\samlib.dll

              c:\windows\system32\clbcatq.dll

              c:\windows\system32\comres.dll

              c:\windows\system32\msv1_0.dll

              c:\windows\system32\iphlpapi.dll

              c:\windows\system32\cscui.dll

              c:\windows\system32\xpsp2res.dll

              c:\windows\system32\wdmaud.drv

              c:\windows\system32\msacm32.drv

              c:\windows\system32\msacm32.dll

              c:\windows\system32\midimap.dll

              C:\WINDOWS\SYSTEM32\SERVICES.EXE
              c:\windows\system32\services.exe

              c:\windows\system32\ntdll.dll

              c:\windows\system32\kernel32.dll

              c:\windows\system32\msvcrt.dll

              c:\windows\system32\advapi32.dll

              c:\windows\system32\rpcrt4.dll

              c:\windows\system32\user32.dll

              c:\windows\system32\gdi32.dll

              c:\windows\system32\userenv.dll

              c:\windows\system32\scesrv.dll

              c:\windows\system32\authz.dll

              c:\windows\system32\umpnpmgr.dll

              c:\windows\system32\winsta.dll

              c:\windows\system32\netapi32.dll

              c:\windows\system32\ncobjapi.dll

              c:\windows\system32\msvcp60.dll

              c:\windows\system32\shimeng.dll

              c:\windows\apppatch\acadproc.dll

              c:\windows\system32\imm32.dll

              c:\windows\system32\secur32.dll

              c:\windows\system32\apphelp.dll

              c:\windows\system32\version.dll

              c:\windows\system32\eventlog.dll

              c:\windows\system32\ws2_32.dll

              c:\windows\system32\ws2help.dll

              c:\windows\system32\psapi.dll

              c:\windows\system32\wtsapi32.dll

              C:\WINDOWS\SYSTEM32\LSASS.EXE
              c:\windows\system32\lsass.exe

              c:\windows\system32\ntdll.dll

              c:\windows\system32\kernel32.dll

              c:\windows\system32\advapi32.dll

              c:\windows\system32\rpcrt4.dll

              c:\windows\system32\lsasrv.dll

              c:\windows\system32\mpr.dll

              c:\windows\system32\user32.dll

              c:\windows\system32\gdi32.dll

              c:\windows\system32\msasn1.dll

              c:\windows\system32\msvcrt.dll

              c:\windows\system32\netapi32.dll

              c:\windows\system32\ntdsapi.dll

              c:\windows\system32\dnsapi.dll

              c:\windows\system32\ws2_32.dll

              c:\windows\system32\ws2help.dll

              c:\windows\system32\wldap32.dll

              c:\windows\system32\secur32.dll

              c:\windows\system32\samlib.dll

              c:\windows\system32\samsrv.dll

              c:\windows\system32\cryptdll.dll

              c:\windows\system32\shimeng.dll

              c:\windows\apppatch\acgenral.dll

              c:\windows\system32\winmm.dll

              c:\windows\system32\ole32.dll

              c:\windows\system32\oleaut32.dll

              c:\windows\system32\msacm32.dll

              c:\windows\system32\version.dll

              c:\windows\system32\shell32.dll

              c:\windows\system32\shlwapi.dll

              c:\windows\system32\userenv.dll

              c:\windows\system32\uxtheme.dll

              c:\windows\system32\imm32.dll

              c:\windows\system32\serwvdrv.dll

              c:\windows\system32\umdmxfrm.dll

              c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll

              c:\windows\system32\comctl32.dll

              c:\windows\system32\msprivs.dll

              c:\windows\system32\kerberos.dll

              c:\windows\system32\msv1_0.dll

              c:\windows\system32\iphlpapi.dll

              c:\windows\system32\netlogon.dll

              c:\windows\system32\w32time.dll

              c:\windows\system32\msvcp60.dll

              c:\windows\system32\schannel.dll

              c:\windows\system32\crypt32.dll

              c:\windows\system32\wdigest.dll

              c:\windows\system32\rsaenh.dll

              c:\windows\system32\setupapi.dll

              c:\windows\system32\scecli.dll

              c:\windows\system32\ipsecsvc.dll

              c:\windows\system32\authz.dll

              c:\windows\system32\oakley.dll

              c:\windows\system32\winipsec.dll

              c:\windows\system32\pstorsvc.dll

              c:\windows\system32\psbase.dll

              c:\windows\system32\mswsock.dll

              c:\windows\system32\hnetcfg.dll

              c:\windows\system32\wshtcpip.dll

              c:\windows\system32\dssenh.dll

              C:\WINDOWS\SYSTEM32\SVCHOST.EXE
              c:\windows\system32\svchost.exe

              c:\windows\system32\ntdll.dll

              c:\windows\system32\kernel32.dll

              c:\windows\system32\advapi32.dll

              c:\windows\system32\rpcrt4.dll

              c:\windows\system32\shimeng.dll

              c:\windows\apppatch\acgenral.dll

              c:\windows\system32\user32.dll

              c:\windows\system32\gdi32.dll

              c:\windows\system32\winmm.dll

              c:\windows\system32\ole32.dll

              c:\windows\system32\msvcrt.dll

              c:\windows\system32\oleaut32.dll

              c:\windows\system32\msacm32.dll

              c:\windows\system32\version.dll

              c:\windows\system32\shell32.dll

              c:\windows\system32\shlwapi.dll

              c:\windows\system32\userenv.dll

              c:\windows\system32\uxtheme.dll

              c:\windows\system32\imm32.dll

              c:\windows\system32\serwvdrv.dll

              c:\windows\system32\umdmxfrm.dll

              c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll

              c:\windows\system32\comctl32.dll

              c:\windows\system32\ntmarta.dll

              c:\windows\system32\wldap32.dll

              c:\windows\system32\samlib.dll

              c:\windows\system32\rpcss.dll

              c:\windows\system32\secur32.dll

              c:\windows\system32\ws2_32.dll

              c:\windows\system32\ws2help.dll

              c:\windows\system32\xpsp2res.dll

              c:\windows\system32\clbcatq.dll

              c:\windows\system32\comres.dll

              c:\windows\system32\wtsapi32.dll

              c:\windows\system32\winsta.dll

              c:\windows\system32\netapi32.dll

              c:\windows\system32\msv1_0.dll

              c:\windows\system32\iphlpapi.dll

              c:\windows\system32\termsrv.dll

              c:\windows\system32\icaapi.dll

              c:\windows\system32\setupapi.dll

              c:\windows\system32\wintrust.dll

              c:\windows\system32\crypt32.dll

              c:\windows\system32\msasn1.dll

              c:\windows\system32\imagehlp.dll

              c:\windows\system32\authz.dll

              c:\windows\system32\mstlsapi.dll

              c:\windows\system32\activeds.dll

              c:\windows\system32\adsldpc.dll

              c:\windows\system32\atl.dll

              c:\windows\system32\regapi.dll

              c:\windows\system32\apphelp.dll

              c:\windows\system32\rsaenh.dll

              c:\windows\system32\svchost.exe

              c:\windows\system32\ntdll.dll

              c:\windows\system32\kernel32.dll

              c:\windows\system32\advapi32.dll

              c:\windows\system32\rpcrt4.dll

              c:\windows\system32\shimeng.dll

              c:\windows\apppatch\acgenral.dll

              c:\windows\system32\user32.dll

              c:\windows\system32\gdi32.dll

              c:\windows\system32\winmm.dll

              c:\windows\system32\ole32.dll

              c:\windows\system32\msvcrt.dll

              c:\windows\system32\oleaut32.dll

              c:\windows\system32\msacm32.dll

              c:\windows\system32\version.dll

              c:\windows\system32\shell32.dll

              c:\windows\system32\shlwapi.dll

              c:\windows\system32\userenv.dll

              c:\windows\system32\uxtheme.dll

              c:\windows\system32\imm32.dll

              c:\windows\system32\serwvdrv.dll

              c:\windows\system32\umdmxfrm.dll

              c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll

              c:\windows\system32\comctl32.dll

              c:\windows\system32\rpcss.dll

              c:\windows\system32\secur32.dll

              c:\windows\system32\ws2_32.dll

              c:\windows\system32\ws2help.dll

              c:\windows\system32\xpsp2res.dll

              c:\windows\system32\rsaenh.dll

              c:\windows\system32\mswsock.dll

              c:\windows\system32\hnetcfg.dll

              c:\windows\system32\wshtcpip.dll

              c:\windows\system32\dnsapi.dll

              c:\windows\system32\iphlpapi.dll

              c:\windows\system32\winrnr.dll

              c:\windows\system32\wldap32.dll

              c:\windows\system32\rasadhlp.dll

              c:\windows\system32\clbcatq.dll

              c:\windows\system32\comres.dll

              c:\windows\system32\svchost.exe

              c:\windows\system32\ntdll.dll

              c:\windows\system32\kernel32.dll

              c:\windows\system32\advapi32.dll

              c:\windows\system32\rpcrt4.dll

              c:\windows\system32\shimeng.dll

              c:\windows\apppatch\acgenral.dll

              c:\windows\system32\user32.dll

              c:\windows\system32\gdi32.dll

              c:\windows\system32\winmm.dll

              c:\windows\system32\ole32.dll

              c:\windows\system32\msvcrt.dll

              c:\windows\system32\oleaut32.dll

              c:\windows\system32\msacm32.dll

              c:\windows\system32\version.dll

              c:\windows\system32\shell32.dll

              c:\windows\system32\shlwapi.dll

              c:\windows\system32\userenv.dll

              c:\windows\system32\uxtheme.dll

              c:\windows\system32\imm32.dll

              c:\windows\system32\serwvdrv.dll

              c:\windows\system32\umdmxfrm.dll

              c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll

              c:\windows\system32\comctl32.dll

              c:\windows\system32\ntmarta.dll

              c:\windows\system32\wldap32.dll

              c:\windows\system32\samlib.dll

              c:\windows\system32\xpsp2res.dll

              c:\windows\system32\shsvcs.dll

              c:\windows\system32\winsta.dll

              c:\windows\system32\netapi32.dll

              c:\windows\system32\rsaenh.dll

              c:\windows\system32\dhcpcsvc.dll

              c:\windows\system32\dnsapi.dll

              c:\windows\system32\ws2_32.dll

              c:\windows\system32\ws2help.dll

              c:\windows\system32\iphlpapi.dll

              c:\windows\system32\secur32.dll

              c:\windows\system32\wzcsvc.dll

              c:\windows\system32\rtutils.dll

              c:\windows\system32\wmi.dll

              c:\windows\system32\crypt32.dll

              c:\windows\system32\msasn1.dll

              c:\windows\system32\wtsapi32.dll

              c:\windows\system32\esent.dll

              c:\windows\system32\atl.dll

              c:\windows\system32\rastls.dll

              c:\windows\system32\cryptui.dll

              c:\windows\system32\wintrust.dll

              c:\windows\system32\imagehlp.dll

              c:\windows\system32\wininet.dll

              c:\windows\system32\normaliz.dll

              c:\windows\system32\iertutil.dll

              c:\windows\system32\mprapi.dll

              c:\windows\system32\activeds.dll

              c:\windows\system32\adsldpc.dll

              c:\windows\system32\setupapi.dll

              c:\windows\system32\rasapi32.dll

              c:\windows\system32\rasman.dll

              c:\windows\system32\tapi32.dll

              c:\windows\system32\schannel.dll

              c:\windows\system32\winscard.dll

              c:\windows\system32\clbcatq.dll

              c:\windows\system32\comres.dll

              c:\windows\system32\raschap.dll

              c:\windows\system32\msvcp60.dll

              c:\windows\system32\wzcsapi.dll

              c:\windows\system32\msv1_0.dll

              c:\windows\system32\schedsvc.dll

              c:\windows\system32\ntdsapi.dll

              c:\windows\system32\msidle.dll

              c:\windows\system32\audiosrv.dll

              c:\windows\system32\wkssvc.dll

              c:\windows\system32\cryptsvc.dll

              c:\windows\system32\certcli.dll

              c:\windows\system32\dmserver.dll

              c:\windows\system32\ersvc.dll

              c:\windows\pchealth\helpctr\binaries\pchsvc.dll

              c:\windows\system32\es.dll

              c:\windows\system32\srvsvc.dll

              c:\windows\system32\hnetcfg.dll

              c:\windows\system32\netman.dll

              c:\windows\system32\netshell.dll

              c:\windows\system32\credui.dll

              c:\windows\system32\sens.dll

              c:\windows\system32\seclogon.dll

              c:\windows\system32\srsvc.dll

              c:\windows\system32\powrprof.dll

              c:\windows\system32\sxs.dll

              c:\windows\system32\trkwks.dll

              c:\windows\system32\w32time.dll

              c:\windows\system32\wbem\wmisvc.dll

              c:\windows\system32\vssapi.dll

              c:\windows\system32\wuauserv.dll

              c:\windows\system32\wuaueng.dll

              c:\windows\system32\winspool.drv

              c:\windows\system32\winhttp.dll

              c:\windows\system32\cabinet.dll

              c:\windows\system32\mspatcha.dll

              c:\windows\system32\browser.dll

              c:\windows\system32\mswsock.dll

              c:\windows\system32\wshtcpip.dll

              c:\windows\system32\sfc.dll

              c:\windows\system32\sfc_os.dll

              c:\windows\system32\ipnathlp.dll

              c:\windows\system32\authz.dll

              c:\windows\system32\comsvcs.dll

              c:\windows\system32\colbact.dll

              c:\windows\system32\mtxclu.dll

              c:\windows\system32\wsock32.dll

              c:\windows\system32\clusapi.dll

              c:\windows\system32\resutils.dll

              c:\windows\system32\wscsvc.dll

              c:\windows\system32\msi.dll

              c:\windows\system32\wbem\wbemcomn.dll

              c:\windows\system32\wbem\wbemcore.dll

              c:\windows\system32\wbem\esscli.dll

              c:\windows\system32\wbem\fastprox.dll

              c:\windows\system32\wbem\wbemsvc.dll

              c:\windows\system32\wbem\wmiutils.dll

              c:\windows\system32\wbem\repdrvfs.dll

              c:\windows\system32\wbem\wmiprvsd.dll

              c:\windows\system32\ncobjapi.dll

              c:\windows\system32\wbem\wbemess.dll

              c:\windows\system32\wbem\ncprov.dll

              c:\windows\system32\tapisrv.dll

              c:\windows\system32\psapi.dll

              c:\windows\system32\rasmans.dll

              c:\windows\system32\winipsec.dll

              c:\windows\system32\netcfgx.dll

              c:\windows\system32\rastapi.dll

              c:\windows\system32\unimdm.tsp

              c:\windows\system32\uniplat.dll

              c:\windows\system32\unimdmat.dll

              c:\windows\system32\modemui.dll

              c:\windows\system32\kmddsp.tsp

              c:\windows\system32\ndptsp.tsp

              c:\windows\system32\ipconf.tsp

              c:\windows\system32\h323.tsp

              c:\windows\system32\hidphone.tsp

              c:\windows\system32\hid.dll

              c:\windows\system32\rasadhlp.dll

              c:\windows\system32\rasppp.dll

              c:\windows\system32\ntlsapi.dll

              c:\windows\system32\kerberos.dll

              c:\windows\system32\cryptdll.dll

              c:\windows\system32\rasdlg.dll

              c:\windows\system32\apphelp.dll

              c:\windows\system32\winrnr.dll

              c:\windows\system32\wdmaud.drv

              c:\windows\system32\msacm32.drv

              c:\windows\system32\midimap.dll

              c:\windows\system32\wbem\wbemcons.dll

              c:\windows\system32\msxml3.dll

              c:\windows\system32\catsrvut.dll

              c:\windows\system32\catsrv.dll

              c:\windows\system32\mfcsubs.dll

              c:\windows\system32\mpr.dll

              c:\windows\system32\urlmon.dll

              C:\PROGRAM FILES\INTEL\WIRELESS\BIN\EVTENG.EXE
              c:\program files\intel\wireless\bin\evteng.exe

              c:\windows\system32\ntdll.dll

              c:\windows\system32\kernel32.dll

              c:\program files\intel\wireless\bin\pfmgrapi.dll

              c:\program files\intel\wireless\bin\traceapi.dll

              c:\program files\intel\wireless\bin\psregapi.dll

              c:\windows\system32\setupapi.dll

              c:\windows\system32\advapi32.dll

              c:\windows\system32\rpcrt4.dll

              c:\windows\system32\gdi32.dll

              c:\windows\system32\user32.dll

              c:\windows\system32\msvcrt.dll

              c:\windows\system32\comdlg32.dll

              c:\windows\system32\shlwapi.dll

              c:\windows\system32\comctl32.dll

              c:\windows\system32\shell32.dll

              c:\windows\system32\winspool.drv

              c:\windows\system32\ole32.dll

              c:\windows\system32\oleaut32.dll

              c:\windows\system32\secur32.dll

              c:\windows\system32\oleacc.dll

              c:\windows\system32\msvcp60.dll

              c:\windows\system32\version.dll

              c:\program files\intel\wireless\bin\dbengine.dll

              c:\program files\intel\wireless\bin\libeay32.dll

              c:\windows\system32\wsock32.dll

              c:\windows\system32\ws2_32.dll

              c:\windows\system32\ws2help.dll

              c:\program files\intel\wireless\bin\intstngs.dll

              c:\program files\intel\wireless\bin\murocapi.dll

              c:\program files\intel\wireless\bin\s24mudll.dll

              c:\windows\system32\imm32.dll

              c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll

              c:\windows\system32\uxtheme.dll

              c:\windows\system32\xpsp2res.dll

              c:\windows\system32\clbcatq.dll

              c:\windows\system32\comres.dll

              c:\program files\fichiers communs\system\ado\msado15.dll

              c:\windows\system32\msdart.dll

              c:\program files\fichiers communs\system\ole db\oledb32.dll

              c:\program files\fichiers communs\system\ole db\oledb32r.dll

              c:\program files\fichiers communs\system\ole db\msdasql.dll

              c:\program files\fichiers communs\system\ole db\msdatl3.dll

              c:\windows\system32\odbc32.dll

              c:\windows\system32\odbcint.dll

              c:\program files\fichiers communs\system\ole db\msdasqlr.dll

              c:\windows\system32\mswstr10.dll

              c:\windows\system32\comsvcs.dll

              c:\windows\system32\colbact.dll

              c:\windows\system32\mtxclu.dll

              c:\windows\system32\netapi32.dll

              c:\windows\system32\clusapi.dll

              c:\windows\system32\resutils.dll

              c:\windows\system32\userenv.dll

              c:\windows\system32\odbcjt32.dll

              c:\windows\system32\msjet40.dll

              c:\windows\system32\odbcji32.dll

              c:\windows\system32\msjter40.dll

              c:\windows\system32\msjint40.dll

              c:\windows\system32\odbccp32.dll

              c:\program files\fichiers communs\system\msadc\msadce.dll

              c:\program files\fichiers communs\system\msadc\msadcer.dll

              c:\windows\system32\wbem\wbemprox.dll

              c:\windows\system32\wbem\wbemcomn.dll

              c:\windows\system32\wbem\wbemsvc.dll

              c:\windows\system32\wbem\fastprox.dll

              c:\windows\system32\ntdsapi.dll

              c:\windows\system32\dnsapi.dll

              c:\windows\system32\wldap32.dll

              C:\PROGRAM FILES\INTEL\WIRELESS\BIN\S24EVMON.EXE
              c:\program files\intel\wireless\bin\s24evmon.exe

              c:\windows\system32\ntdll.dll

              c:\windows\system32\kernel32.dll

              c:\windows\system32\setupapi.dll

              c:\windows\system32\advapi32.dll

              c:\windows\system32\rpcrt4.dll

              c:\windows\system32\gdi32.dll

              c:\windows\system32\user32.dll

              c:\windows\system32\msvcrt.dll

              c:\program files\intel\wireless\bin\traceapi.dll

              c:\program files\intel\wireless\bin\psregapi.dll

              c:\windows\system32\comdlg32.dll

              c:\windows\system32\shlwapi.dll

              c:\windows\system32\comctl32.dll

              c:\windows\system32\shell32.dll

              c:\windows\system32\winspool.drv

              c:\windows\system32\ole32.dll

              c:\windows\system32\oleaut32.dll

              c:\windows\system32\secur32.dll

              c:\windows\system32\oleacc.dll

              c:\windows\system32\msvcp60.dll

              c:\windows\system32\iphlpapi.dll

              c:\windows\system32\ws2_32.dll

              c:\windows\system32\ws2help.dll

              c:\windows\system32\netapi32.dll

              c:\program files\intel\wireless\bin\libeay32.dll

              c:\windows\system32\wsock32.dll

              c:\program files\intel\wireless\bin\intstngs.dll

              c:\windows\system32\version.dll

              c:\program files\intel\wireless\bin\iwmsprov.dll

              c:\windows\system32\imm32.dll

              c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll

              c:\windows\system32\uxtheme.dll

              c:\windows\system32\clbcatq.dll

              c:\windows\system32\comres.dll

              c:\windows\system32\netcfgx.dll

              c:\windows\system32\clusapi.dll

              c:\windows\system32\dnsapi.dll

              c:\windows\system32\msctfime.ime

              c:\program files\fichiers communs\system\ado\msado15.dll

              c:\windows\system32\msdart.dll

              c:\windows\system32\xpsp2res.dll

              c:\program files\fichiers communs\system\ole db\oledb32.dll

              c:\program files\fichiers communs\system\ole db\oledb32r.dll

              c:\program files\fichiers communs\system\ole db\msdasql.dll

              c:\program files\fichiers communs\system\ole db\msdatl3.dll

              c:\windows\system32\odbc32.dll

              c:\windows\system32\odbcint.dll

              c:\program files\fichiers communs\system\ole db\msdasqlr.dll

              c:\windows\system32\mswstr10.dll

              c:\windows\system32\comsvcs.dll

              c:\windows\system32\colbact.dll

              c:\windows\system32\mtxclu.dll

              c:\windows\system32\resutils.dll

              c:\windows\system32\userenv.dll

              c:\windows\system32\odbcjt32.dll

              c:\windows\system32\msjet40.dll

              c:\windows\system32\odbcji32.dll

              c:\windows\system32\msjter40.dll

              c:\windows\system32\msjint40.dll

              c:\windows\system32\odbccp32.dll

              c:\program files\fichiers communs\system\msadc\msadce.dll

              c:\program files\fichiers communs\system\msadc\msadcer.dll

              c:\windows\system32\sssensor.dll

              c:\windows\system32\netman.dll

              c:\windows\system32\mprapi.dll

              c:\windows\system32\activeds.dll

              c:\windows\system32\adsldpc.dll

              c:\windows\system32\wldap32.dll

              c:\windows\system32\atl.dll

              c:\windows\system32\rtutils.dll

              c:\windows\system32\samlib.dll

              c:\windows\system32\netshell.dll

              c:\windows\system32\credui.dll

              c:\windows\system32\rasapi32.dll

              c:\windows\system32\rasman.dll

              c:\windows\system32\tapi32.dll

              c:\windows\system32\winmm.dll

              c:\windows\system32\wininet.dll

              c:\windows\system32\normaliz.dll

              c:\windows\system32\iertutil.dll

              c:\windows\system32\wzcsapi.dll

              c:\windows\system32\wzcsvc.dll

              c:\windows\system32\wmi.dll

              c:\windows\system32\dhcpcsvc.dll

              c:\windows\system32\crypt32.dll

              c:\windows\system32\msasn1.dll

              c:\windows\system32\wtsapi32.dll

              c:\windows\system32\winsta.dll

              c:\windows\system32\esent.dll

              c:\windows\system32\serwvdrv.dll

              c:\windows\system32\umdmxfrm.dll

              c:\windows\system32\wintrust.dll

              c:\windows\system32\imagehlp.dll

              c:\windows\system32\rsaenh.dll

              C:\PROGRAM FILES\SYGATE\SPF\SMC.EXE
              c:\program files\sygate\spf\smc.exe

              c:\windows\system32\ntdll.dll

              c:\windows\system32\kernel32.dll

              c:\program files\sygate\spf\trident.dll

              c:\program files\sygate\spf\tfman.dll

              c:\windows\system32\user32.dll

              c:\windows\system32\gdi32.dll

              c:\windows\system32\advapi32.dll

              c:\windows\system32\rpcrt4.dll

              c:\windows\system32\shlwapi.dll

              c:\windows\system32\msvcrt.dll

              c:\program files\sygate\spf\tse.dll

              c:\program files\sygate\spf\dataman.dll

              c:\windows\system32\ole32.dll

              c:\windows\system32\oleaut32.dll

              c:\program files\sygate\spf\pssensor.dll

              c:\windows\system32\sssensor.dll

              c:\program files\sygate\spf\spnet.dll

              c:\windows\system32\ws2_32.dll

              c:\windows\system32\ws2help.dll

              c:\windows\system32\shell32.dll

              c:\windows\system32\comdlg32.dll

              c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll

              c:\windows\system32\winspool.drv

              c:\windows\system32\version.dll

              c:\program files\sygate\spf\idstrafficpipe.dll

              c:\program files\sygate\spf\wpsman.dll

              c:\program files\sygate\spf\wsman.dll

              c:\windows\system32\snmpapi.dll

              c:\program files\sygate\spf\sylog.dll

              c:\program files\sygate\spf\netport.dll

              c:\windows\system32\wsock32.dll

              c:\program files\sygate\spf\wgman.dll

              c:\program files\sygate\spf\sylink.dll

              c:\windows\system32\netapi32.dll

              c:\windows\system32\wininet.dll

              c:\windows\system32\normaliz.dll

              c:\windows\system32\iertutil.dll

              c:\windows\system32\oledlg.dll

              c:\windows\system32\olepro32.dll

              c:\windows\system32\imm32.dll

              c:\windows\system32\uxtheme.dll

              c:\windows\system32\clbcatq.dll

              c:\windows\system32\comres.dll

              c:\windows\system32\psapi.dll

              c:\windows\system32\iphlpapi.dll

              c:\windows\system32\rasapi32.dll

              c:\windows\system32\rasman.dll

              c:\windows\system32\tapi32.dll

              c:\windows\system32\rtutils.dll

              c:\windows\system32\winmm.dll

              c:\windows\system32\serwvdrv.dll

              c:\windows\system32\umdmxfrm.dll

              c:\windows\system32\mprapi.dll

              c:\windows\system32\activeds.dll

              c:\windows\system32\adsldpc.dll

              c:\windows\system32\wldap32.dll

              c:\windows\system32\atl.dll

              c:\windows\system32\samlib.dll

              c:\windows\system32\setupapi.dll

              c:\windows\system32\userenv.dll

              c:\windows\system32\secur32.dll

              c:\windows\system32\msv1_0.dll

              c:\windows\system32\mswsock.dll

              c:\windows\system32\dnsapi.dll

              c:\windows\system32\winrnr.dll

              c:\windows\system32\rasadhlp.dll

              c:\windows\system32\hnetcfg.dll

              c:\windows\system32\wshtcpip.dll

              c:\windows\system32\vdmdbg.dll

              c:\windows\system32\msctfime.ime

              c:\windows\system32\riched32.dll

              c:\windows\system32\riched20.dll

              C:\WINDOWS\SYSTEM32\SVCHOST.EXE
              c:\windows\system32\svchost.exe

              c:\windows\system32\ntdll.dll

              c:\windows\system32\kernel32.dll

              c:\windows\system32\advapi32.dll

              c:\windows\system32\rpcrt4.dll

              c:\windows\system32\shimeng.dll

              c:\windows\apppatch\acgenral.dll

              c:\windows\system32\user32.dll

              c:\windows\system32\gdi32.dll

              c:\windows\system32\winmm.dll

              c:\windows\system32\ole32.dll

              c:\windows\system32\msvcrt.dll

              c:\windows\system32\oleaut32.dll

              c:\windows\system32\msacm32.dll

              c:\windows\system32\version.dll

              c:\windows\system32\shell32.dll

              c:\windows\system32\shlwapi.dll

              c:\windows\system32\userenv.dll

              c:\windows\system32\uxtheme.dll

              c:\windows\system32\imm32.dll

              c:\windows\system32\serwvdrv.dll

              c:\windows\system32\umdmxfrm.dll

              c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll

              c:\windows\system32\comctl32.dll

              c:\windows\system32\dnsrslvr.dll

              c:\windows\system32\dnsapi.dll

              c:\windows\system32\ws2_32.dll

              c:\windows\system32\ws2help.dll

              c:\windows\system32\iphlpapi.dll

              c:\windows\system32\mswsock.dll

              c:\windows\system32\hnetcfg.dll

              c:\windows\system32\wshtcpip.dll

              c:\windows\system32\svchost.exe

              c:\windows\system32\ntdll.dll

              c:\windows\system32\kernel32.dll

              c:\windows\system32\advapi32.dll

              c:\windows\system32\rpcrt4.dll

              c:\windows\system32\shimeng.dll

              c:\windows\apppatch\acgenral.dll

              c:\windows\system32\user32.dll

              c:\windows\system32\gdi32.dll

              c:\windows\system32\winmm.dll

              c:\windows\system32\ole32.dll

              c:\windows\system32\msvcrt.dll

              c:\windows\system32\oleaut32.dll

              c:\windows\system32\msacm32.dll

              c:\windows\system32\version.dll

              c:\windows\system32\shell32.dll

              c:\windows\system32\shlwapi.dll

              c:\windows\system32\userenv.dll

              c:\windows\system32\uxtheme.dll

              c:\windows\system32\imm32.dll

              c:\windows\system32\serwvdrv.dll

              c:\windows\system32\umdmxfrm.dll

              c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll

              c:\windows\system32\comctl32.dll

              c:\windows\system32\ntmarta.dll

              c:\windows\system32\wldap32.dll

              c:\windows\system32\samlib.dll

              c:\windows\system32\xpsp2res.dll

              c:\windows\system32\lmhsvc.dll

              c:\windows\system32\iphlpapi.dll

              c:\windows\system32\ws2_32.dll

              c:\windows\system32\ws2help.dll

              c:\windows\system32\webclnt.dll

              c:\windows\system32\wininet.dll

              c:\windows\system32\normaliz.dll

              c:\windows\system32\iertutil.dll

              c:\windows\system32\secur32.dll

              C:\PROGRAM FILES\LAVASOFT\AD-AWARE 2007\AAWSERVICE.EXE
              c:\program files\lavasoft\ad-aware 2007\aawservice.exe

              c:\windows\system32\ntdll.dll

              c:\windows\system32\kernel32.dll

              c:\program files\lavasoft\ad-aware 2007\ceapi.dll

              c:\windows\system32\advapi32.dll

              c:\windows\system32\rpcrt4.dll

              c:\windows\system32\shlwapi.dll

              c:\windows\system32\gdi32.dll

              c:\windows\system32\user32.dll

              c:\windows\system32\msvcrt.dll

              c:\windows\system32\ws2_32.dll

              c:\windows\system32\ws2help.dll

              c:\program files\lavasoft\ad-aware 2007\pkarchive85u.dll

              c:\windows\system32\shell32.dll

              c:\windows\system32\ole32.dll

              c:\windows\system32\crypt32.dll

              c:\windows\system32\msasn1.dll

              c:\windows\system32\wldap32.dll

              c:\windows\system32\psapi.dll

              c:\windows\system32\version.dll

              c:\windows\system32\wininet.dll

              c:\windows\system32\normaliz.dll

              c:\windows\system32\iertutil.dll

              c:\program files\lavasoft\ad-aware 2007\update.dll

              c:\windows\system32\wsock32.dll

              c:\windows\system32\userenv.dll

              c:\windows\system32\imm32.dll

              c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll

              c:\windows\system32\comctl32.dll

              c:\windows\system32\rsaenh.dll

              c:\windows\system32\oleaut32.dll

              c:\windows\system32\comdlg32.dll

              c:\windows\system32\inetmib1.dll

              c:\windows\system32\iphlpapi.dll

              c:\windows\system32\snmpapi.dll

              c:\windows\system32\mprapi.dll

              c:\windows\system32\activeds.dll

              c:\windows\system32\adsldpc.dll

              c:\windows\system32\netapi32.dll

              c:\windows\system32\atl.dll

              c:\windows\system32\rtutils.dll

              c:\windows\system32\samlib.dll

              c:\windows\system32\setupapi.dll

              c:\windows\system32\ntmarta.dll

              c:\windows\system32\uxtheme.dll

              c:\windows\system32\msctfime.ime

              c:\windows\system32\mswsock.dll

              c:\windows\system32\dnsapi.dll

              c:\windows\system32\winrnr.dll

              c:\windows\system32\rasadhlp.dll

              c:\windows\system32\hnetcfg.dll

              c:\windows\system32\wshtcpip.dll

              c:\windows\system32\secur32.dll

              C:\WINDOWS\SYSTEM32\SPOOLSV.EXE
              c:\windows\system32\spoolsv.exe

              c:\windows\system32\ntdll.dll

              c:\windows\system32\kernel32.dll

              c:\windows\system32\advapi32.dll

              c:\windows\system32\rpcrt4.dll

              c:\windows\system32\gdi32.dll

              c:\windows\system32\user32.dll

              c:\windows\system32\msvcrt.dll

              c:\windows\system32\shimeng.dll

              c:\windows\apppatch\acgenral.dll

              c:\windows\system32\winmm.dll

              c:\windows\system32\ole32.dll

              c:\windows\system32\oleaut32.dll

              c:\windows\system32\msacm32.dll

              c:\windows\system32\version.dll

              c:\windows\system32\shell32.dll

              c:\windows\system32\shlwapi.dll

              c:\windows\system32\userenv.dll

              c:\windows\system32\uxtheme.dll

              c:\windows\system32\imm32.dll

              c:\windows\system32\serwvdrv.dll

              c:\windows\system32\umdmxfrm.dll

              c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll

              c:\windows\system32\comctl32.dll

              c:\windows\system32\spoolss.dll

              c:\windows\system32\ws2_32.dll

              c:\windows\system32\ws2help.dll

              c:\windows\system32\dnsapi.dll

              c:\windows\system32\iphlpapi.dll

              c:\windows\system32\rasadhlp.dll

              c:\windows\system32\localspl.dll

              c:\windows\system32\secur32.dll

              c:\windows\system32\sfc_os.dll

              c:\windows\system32\wintrust.dll

              c:\windows\system32\crypt32.dll

              c:\windows\system32\msasn1.dll

              c:\windows\system32\imagehlp.dll

              c:\windows\system32\winspool.drv

              c:\windows\system32\netapi32.dll

              c:\windows\system32\cnbjmon.dll

              c:\windows\system32\cpwmon2k.dll

              c:\windows\system32\mdimon.dll

              c:\windows\system32\msi.dll

              c:\windows\system32\pjlmon.dll

              c:\windows\system32\tcpmon.dll

              c:\windows\system32\tbtmon.dll

              c:\windows\system32\tosbthcrpapi.dll

              c:\windows\system32\tosbtapi.dll

              c:\windows\system32\tosbdapi.dll

              c:\windows\system32\setupapi.dll

              c:\windows\system32\tbtmon98language.dll

              c:\windows\system32\usbmon.dll

              c:\windows\system32\spool\prtprocs\w32x86\mdippr.dll

              c:\windows\system32\mswsock.dll

              c:\windows\system32\winrnr.dll

              c:\windows\system32\wldap32.dll

              c:\windows\system32\win32spl.dll

              c:\windows\system32\netrap.dll

              c:\windows\system32\ntdsapi.dll

              c:\windows\system32\clbcatq.dll

              c:\windows\system32\comres.dll

              c:\windows\system32\xpsp2res.dll

              c:\windows\system32\inetpp.dll

              C:\PROGRAM FILES\AVIRA\ANTIVIR PERSONALEDITION CLASSIC\AVGUARD.EXE
              c:\program files\avira\antivir personaledition classic\avguard.exe

              c:\windows\system32\ntdll.dll

              c:\windows\system32\kernel32.dll

              c:\windows\system32\version.dll

              c:\windows\system32\netapi32.dll

              c:\windows\system32\advapi32.dll

              c:\windows\system32\rpcrt4.dll

              c:\windows\system32\msvcrt.dll

              c:\windows\system32\user32.dll

              c:\windows\system32\gdi32.dll

              c:\windows\system32\imm32.dll

              c:\windows\system32\wtsapi32.dll

              c:\windows\system32\winsta.dll

              c:\program files\avira\antivir personaledition classic\avgio.dll

              c:\program files\avira\antivir personaledition classic\avevtlog.dll

              c:\program files\avira\antivir personaledition classic\guardmsg.dll

              c:\program files\avira\antivir personaledition classic\sqlite3.dll

              c:\program files\avira\antivir personaledition classic\msvcr71.dll

              c:\program files\avira\antivir personaledition classic\avpref.dll

              c:\program files\avira\antivir personaledition classic\smtplib.dll

              c:\windows\system32\ws2_32.dll

              c:\windows\system32\ws2help.dll

              c:\program files\avira\antivir personaledition classic\avpack32.dll

              c:\program files\avira\antivir personaledition classic\unacev2.dll

              c:\windows\system32\shell32.dll

              c:\windows\system32\shlwapi.dll

              c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll

              c:\windows\system32\comctl32.dll

              c:\windows\system32\wintrust.dll

              c:\windows\system32\crypt32.dll

              c:\windows\system32\msasn1.dll

              c:\windows\system32\imagehlp.dll

              c:\program files\avira\antivir personaledition classic\avewin32.dll

              c:\program files\avira\antivir personaledition classic\avipc.dll

              c:\windows\system32\fltlib.dll

              c:\windows\system32\ntmarta.dll

              c:\windows\system32\wldap32.dll

              c:\windows\system32\ole32.dll

              c:\windows\system32\samlib.dll

              c:\windows\system32\secur32.dll

              C:\PROGRAM FILES\AVIRA\ANTIVIR PERSONALEDITION CLASSIC\SCHED.EXE
              c:\program files\avira\antivir personaledition classic\sched.exe

              c:\windows\system32\ntdll.dll

              c:\windows\system32\kernel32.dll

              c:\windows\system32\rpcrt4.dll

              c:\windows\system32\advapi32.dll

              c:\windows\system32\version.dll

              c:\windows\system32\user32.dll

              c:\windows\system32\gdi32.dll

              c:\windows\system32\ole32.dll

              c:\windows\system32\msvcrt.dll

              c:\windows\system32\oleaut32.dll

              c:\program files\avira\antivir personaledition classic\msvcr71.dll

              c:\program files\avira\antivir personaledition classic\msvcp71.dll

              c:\windows\system32\imm32.dll

              c:\program files\avira\antivir personaledition classic\schedr.dll

              c:\windows\system32\wtsapi32.dll

              c:\windows\system32\winsta.dll

              c:\windows\system32\netapi32.dll

              c:\windows\system32\rasapi32.dll

              c:\windows\system32\rasman.dll

              c:\windows\system32\ws2_32.dll

              c:\windows\system32\ws2help.dll

              c:\windows\system32\tapi32.dll

              c:\windows\system32\shlwapi.dll

              c:\windows\system32\rtutils.dll

              c:\windows\system32\winmm.dll

              c:\windows\system32\serwvdrv.dll

              c:\windows\system32\umdmxfrm.dll

              c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll

              c:\program files\avira\antivir personaledition classic\avevtlog.dll

              c:\program files\avira\antivir personaledition classic\sqlite3.dll

              c:\windows\system32\comctl32.dll

              c:\program files\avira\antivir personaledition classic\avipc.dll

              c:\windows\system32\xpsp2res.dll

              c:\windows\system32\clbcatq.dll

              c:\windows\system32\comres.dll

              C:\WINDOWS\EHOME\EHRECVR.EXE
              c:\windows\ehome\ehrecvr.exe

              c:\windows\system32\ntdll.dll

              c:\windows\system32\kernel32.dll

              c:\windows\system32\msvcrt.dll

              c:\windows\system32\atl.dll

              c:\windows\system32\user32.dll

              c:\windows\system32\gdi32.dll

              c:\windows\system32\advapi32.dll

              c:\windows\system32\rpcrt4.dll

              c:\windows\system32\ole32.dll

              c:\windows\system32\oleaut32.dll

              c:\windows\system32\faultrep.dll

              c:\windows\system32\version.dll

              c:\windows\system32\userenv.dll

              c:\windows\system32\winsta.dll

              c:\windows\system32\netapi32.dll

              c:\windows\system32\wtsapi32.dll

              c:\windows\system32\setupapi.dll

              c:\windows\system32\shlwapi.dll

              c:\windows\system32\psapi.dll

              c:\windows\ehome\ehtrace.dll

              c:\windows\system32\imm32.dll

              c:\windows\system32\uxtheme.dll

              c:\windows\system32\xpsp2res.dll

              c:\windows\system32\ntmarta.dll

              c:\windows\system32\wldap32.dll

              c:\windows\system32\samlib.dll

              c:\windows\system32\clbcatq.dll

              c:\windows\system32\comres.dll

              c:\windows\system32\sbe.dll

              c:\windows\system32\winmm.dll

              c:\windows\system32\serwvdrv.dll

              c:\windows\system32\umdmxfrm.dll

              c:\windows\system32\msvidctl.dll

              c:\windows\system32\quartz.dll

              c:\windows\system32\shell32.dll

              c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll

              c:\windows\system32\comctl32.dll

              c:\windows\system32\devenum.dll

              c:\windows\system32\wintrust.dll

              c:\windows\system32\crypt32.dll

              c:\windows\system32\msasn1.dll

              c:\windows\system32\imagehlp.dll

              c:\windows\system32\msdmo.dll

              C:\WINDOWS\EHOME\EHSCHED.EXE
              c:\windows\ehome\ehsched.exe

              c:\windows\system32\ntdll.dll

              c:\windows\system32\kernel32.dll

              c:\windows\system32\msvcrt.dll

              c:\windows\system32\atl.dll

              c:\windows\system32\user32.dll

              c:\windows\system32\gdi32.dll

              c:\windows\system32\advapi32.dll

              c:\windows\system32\rpcrt4.dll

              c:\windows\system32\ole32.dll

              c:\windows\system32\oleaut32.dll

              c:\windows\system32\imm32.dll

              c:\windows\system32\uxtheme.dll

              c:\windows\system32\xpsp2res.dll

              c:\windows\system32\clbcatq.dll

              c:\windows\system32\comres.dll

              c:\windows\system32\version.dll

              c:\windows\ehome\ehproxy.dll

              c:\windows\system32\tapi3.dll

              c:\windows\system32\wininet.dll

              c:\windows\system32\shlwapi.dll

              c:\windows\system32\normaliz.dll

              c:\windows\system32\iertutil.dll

              c:\windows\system32\winmm.dll

              c:\windows\system32\rtutils.dll

              c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll

              c:\windows\system32\serwvdrv.dll

              c:\windows\system32\umdmxfrm.dll

              c:\windows\system32\secur32.dll

              c:\windows\system32\wavemsp.dll

              c:\windows\system32\termmgr.dll

              c:\windows\system32\wdmaud.drv

              c:\windows\system32\wintrust.dll

              c:\windows\system32\crypt32.dll

              c:\windows\system32\msasn1.dll

              c:\windows\system32\imagehlp.dll

              c:\windows\system32\msacm32.drv

              c:\windows\system32\msacm32.dll

              c:\windows\system32\midimap.dll

              c:\windows\system32\confmsp.dll

              c:\windows\system32\ws2_32.dll

              c:\windows\system32\ws2help.dll

              c:\windows\system32\mswsock.dll

              c:\windows\system32\hnetcfg.dll

              c:\windows\system32\wshtcpip.dll

              c:\windows\system32\h323msp.dll

              c:\windows\system32\iphlpapi.dll

              C:\PROGRAM FILES\FICHIERS COMMUNS\LIGHTSCRIBE\LSSRVC.EXE
              c:\program files\fichiers communs\lightscribe\lssrvc.exe

              c:\windows\system32\ntdll.dll

              c:\windows\system32\kernel32.dll

              c:\windows\system32\shlwapi.dll

              c:\windows\system32\advapi32.dll

              c:\windows\system32\rpcrt4.dll

              c:\windows\system32\gdi32.dll

              c:\windows\system32\user32.dll

              c:\windows\system32\msvcrt.dll

              c:\windows\system32\psapi.dll

              c:\windows\system32\shell32.dll

              c:\program files\fichiers communs\lightscribe\msvcr71.dll

              c:\program files\fichiers communs\lightscribe\msvcp71.dll

              c:\windows\system32\imm32.dll

              c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll

              c:\windows\system32\comctl32.dll

              C:\WINDOWS\SYSTEM32\NVSVC32.EXE
              c:\windows\system32\nvsvc32.exe

              c:\windows\system32\ntdll.dll

              c:\windows\system32\kernel32.dll

              c:\windows\system32\user32.dll

              c:\windows\system32\gdi32.dll

              c:\windows\system32\advapi32.dll

              c:\windows\system32\rpcrt4.dll

              c:\windows\system32\userenv.dll

              c:\windows\system32\msvcrt.dll

              c:\windows\system32\powrprof.dll

              c:\windows\system32\imm32.dll

              c:\windows\system32\wtsapi32.dll

              c:\windows\system32\winsta.dll

              c:\windows\system32\netapi32.dll

              c:\windows\system32\winmm.dll

              c:\windows\system32\shlwapi.dll

              c:\windows\system32\comctl32.dll

              c:\windows\system32\serwvdrv.dll

              c:\windows\system32\umdmxfrm.dll

              c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll

              c:\windows\system32\ole32.dll

              c:\windows\system32\uxtheme.dll

              c:\windows\system32\msctfime.ime

              c:\windows\system32\wintrust.dll

              c:\windows\system32\crypt32.dll

              c:\windows\system32\msasn1.dll

              c:\windows\system32\imagehlp.dll

              c:\windows\system32\secur32.dll

              c:\windows\system32\msv1_0.dll

              c:\windows\system32\ws2_32.dll

              c:\windows\system32\ws2help.dll

              c:\windows\system32\iphlpapi.dll

              c:\windows\system32\apphelp.dll

              c:\windows\system32\version.dll

              c:\windows\system32\ntmarta.dll

              c:\windows\system32\wldap32.dll

              c:\windows\system32\samlib.dll

              c:\windows\system32\sssensor.dll

              C:\PROGRAM FILES\INTEL\WIRELESS\BIN\REGSRVC.EXE
              c:\program files\intel\wireless\bin\regsrvc.exe

              c:\windows\system32\ntdll.dll

              c:\windows\system32\kernel32.dll

              c:\windows\system32\setupapi.dll

              c:\windows\system32\advapi32.dll

              c:\windows\system32\rpcrt4.dll

              c:\windows\system32\gdi32.dll

              c:\windows\system32\user32.dll

              c:\windows\system32\msvcrt.dll

              c:\windows\system32\comdlg32.dll

              c:\windows\system32\shlwapi.dll

              c:\windows\system32\comctl32.dll

              c:\windows\system32\shell32.dll

              c:\windows\system32\winspool.drv

              c:\windows\system32\ole32.dll

              c:\windows\system32\oleaut32.dll

              c:\windows\system32\imm32.dll

              c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll

              c:\windows\system32\uxtheme.dll

              c:\windows\system32\xpsp2res.dll

              c:\windows\system32\clbcatq.dll

              c:\windows\system32\comres.dll

              c:\windows\system32\version.dll

              C:\WINDOWS\SYSTEM32\SVCHOST.EXE
              c:\windows\system32\svchost.exe

              c:\windows\system32\ntdll.dll

              c:\windows\system32\kernel32.dll

              c:\windows\system32\advapi32.dll

              c:\windows\system32\rpcrt4.dll

              c:\windows\system32\shimeng.dll

              c:\windows\apppatch\acgenral.dll

              c:\windows\system32\user32.dll

              c:\windows\system32\gdi32.dll

              c:\windows\system32\winmm.dll

              c:\windows\system32\ole32.dll

              c:\windows\system32\msvcrt.dll

              c:\windows\system32\oleaut32.dll

              c:\windows\system32\msacm32.dll

              c:\windows\system32\version.dll

              c:\windows\system32\shell32.dll

              c:\windows\system32\shlwapi.dll

              c:\windows\system32\userenv.dll

              c:\windows\system32\uxtheme.dll

              c:\windows\system32\imm32.dll

              c:\windows\system32\serwvdrv.dll

              c:\windows\s
              0
              1. Salut Denis,

                Apparemment il a trouvé qq chose...

                Voici le log SDFix:

                Report.txt
                =======

                *****************************************************************************************

                SDFix: Version 1.136

                Run by Jean-Christophe on 2008-02-04 at 21:13

                Microsoft Windows XP [version 5.1.2600]

                Running From: C:\SDFix

                Safe Mode:
                Checking Services:

                Restoring Windows Registry Values
                Restoring Windows Default Hosts File

                Rebooting...

                Service mp32 - Deleted after Reboot

                Normal Mode:
                Checking Files:

                Trojan Files Found:

                C:\175237~1 - Deleted
                C:\WINDOWS\system32\mp32s.sys - Deleted

                Removing Temp Files...

                ADS Check:

                Final Check:

                catchme 0.3.1344.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                Rootkit scan 2008-02-04 21:17:36
                Windows 5.1.2600 Service Pack 2 FAT NTAPI

                scanning hidden processes ...

                scanning hidden services ...

                scanning hidden autostart entries ...

                scanning hidden files ...

                scan completed successfully
                hidden processes: 0
                hidden services: 0
                hidden files: 0

                Remaining Services:
                ------------------

                Authorized Application Key Export:

                [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

                [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

                Remaining Files:
                ---------------

                File Backups: - C:\SDFix\backups\backups.zip

                Files with Hidden Attributes:

                Wed 13 Oct 2004 1,694,208 ..SH. --- "C:\Program Files\Messenger\msmsgs.exe"
                Fri 24 Mar 2006 60,416 A.SH. --- "C:\Program Files\Outlook Express\msimn.exe"
                Sat 24 Feb 2007 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"

                Finished!
                *****************************************************************************************

                Et le résultat de CleanZip:

                rapport_clean.txt
                ===========

                *****************************************************************************************
                2008-02-04 a 21:24:51.90

                *** Recherche des fichiers dans C:

                *** Recherche des fichiers dans C:\WINDOWS\

                *** Recherche des fichiers dans C:\WINDOWS\system32

                *****************************************************************************************

                Après coup, j'ai rebooté le PC, j'ai surfé un peu, j'ai rescanné avec Spybot et là, MIRACLE, plus rien du tout, ça a l'air propre. Qu'en penses-tu?

                A+
                JC
                0
                1. Salut,

                  -Ma faute, le forum déconne parfois il n'affiche pas bien les contenus des post je n'ai pas fait attention.

                  -Alors il va falloir passer par Sdfix car les trojans continuent de rentrer puis finir avec clean.zip

                  ---------------------
                  1-Télécharger SDFix (créé par AndyManchesta) et sauvegarde le sur ton Bureau.
                  Pour cela cliquer ICI
                  Double cliquer sur SDFix.exe et choisir Install pour l'extraire dans un dossier dédié sur le Bureau.
                  Redémarrer l’ordinateur en mode sans échec (voir la procédure ICI )

                  Choisir son compte, pas celui de l'Administrateur ou autre.
                  Dérouler la liste des instructions ci-dessous :
                  • Ouvrir le dossier SDFix qui vient d'être créé dans le répertoire C:\ et double clique sur RunThis.bat pour lancer le script.
                  • Appuyer sur Y pour commencer le processus de nettoyage.
                  • Il va supprimer les services et les entrées du Registre de certains trojans trouvés puis te demandera d'appuyer sur une touche pour redémarrer.
                  • Appuyer sur une touche pour redémarrer le PC.
                  • Le système sera plus long pour redémarrer qu'à l'accoutumée car l'outil va continuer à s'exécuter et supprimer des fichiers.
                  • Après le chargement du Bureau, l'outil terminera son travail et affichera Finished.
                  • Appuyer sur une touche pour finir l'exécution du script et charger les icônes du Bureau.
                  • Les icônes du Bureau affichées, le rapport SDFix s'ouvrira à l'écran et s'enregistrera aussi dans le dossier SDFix sous le nom Report.txt.
                  • Enfin, copier/coller le contenu du fichier Report.txt dans la prochaine réponse sur le forum

                  ---------------------
                  2-Clean.zip
                  * Télécharge clean zip de Malekal_Morte http://www.malekal.com/download/clean.zip

                  * Décompresse-le sur ton bureau (clic droit / extraire tout), tu dois obtenir un dossier clean.
                  * Ouvre le dossier Clean qui se trouve sur ton bureau.
                  * Double-clique sur clean.cmd.
                  Une fenêtre noire va apparaître,

                  Choisis l'option 1 laisses le travailler.
                  A là fin clic sur une touche pour continuer… comme indiquer.

                  Puis poste le rapport qui se trouve ici C:\rapport_clean.txt

                  A+
                  0
                  1. Denis,

                    Les fichiers n'existent pas. Par acquis de conscience je l'ai fait et voilà le résultat (j'ai fait un copier/coller car il n'a pas pu créer le fichier)

                    **************************************************
                    File/Folder C:\Program Files\pyhgdepy\nmtchkxy.dll not found.
                    File/Folder C:\Documents and Settings\All Users\Application Data\apqjojab.dll not found.

                    Created on 02-03-2008 15:48:44
                    **************************************************

                    En fait, tu me les avis déjà fait supprimer avec combofix (point 2 du message 13: http://www.commentcamarche.net/forum/affich 4292006 virus ultimate cleaner#13)

                    A+

                    JC
                    0
                    1. jc74,

                      -Les Antivirus ne détecte pas tout.

                      -Une dernière chose.
                      Je suis remonté dans les messages et je viens de tomber sur ton log HJThis initial.
                      On avait fixé 2 lignes mais j'ai oublié de te faire enlever les fichiers associés.

                      Ils sont peut être encore actif, recommences la procédure OTMoveIT avec les fichiers suivant:


                      C:\Program Files\pyhgdepy\nmtchkxy.dll
                      C:\Documents and Settings\All Users\Application Data\apqjojab.dll


                      Télécharger OTMoveIt (de Old_Timer) sur le Bureau. http://download.bleepingcomputer.com/oldtimer/OTMoveIt.exe
                      Ou ici http://lanceyien-info.com/download/otmoveit.exe

                      --> Poster le rapport d'OTMoveIt situé dans C:\_OTMoveIt\MovedFiles

                      A+
                      0
                      1. Denis,

                        Voici les 2 fichiers dans lesquels Spybot trouve Win32.Tiny.abk:

                        C:\WINDOWS\TEMP\7CF28762C38CA0D4.tmp 178 Ko (182,609 octets)
                        C:\WINDOWS\TEMP\AE8AB41F91F72503.tmp 68.3 Ko (70,007 octets)

                        Voici l'info que donne Spybot:

                        Société:
                        Produit: Win32.Tiny.abk
                        Menace: Trojan

                        Description
                        Win32.Tiny.abk installs a system service to get started each windows startup. Additionally it tries to contact to some malicious websites to download other malware.

                        JC
                        0
                        1. Denis,

                          Je crois que j'ai compris pour la protection, merci.

                          Pour adaware, j'ai fait comme tu m'as dit, mais toujours le même problème.

                          A mon avis, j'ai de nouveau un truc à la con: Win32.Tiny.abk détecté par Spybot dans 2 fichiers .tmp dans c:\Windows\Temp. Il me le détecte à chaque démarrage, je le fixe mais il revient toujours. J'ai fait une recherche sur le web et je suis tombé sur des posts parlant de ce Trojan, en particulier un qui dit que adaware plante le PC durant le scan (moi c'est systématiquemnt lorsqu'il arrive en fin de scan de la registry).

                          AntiVir et AVG AntiSpyware ne détectent rien dans ces 2 fichiers.

                          Qu'en penses-tu?

                          Veux-tu que je ferme ce post et en ouvre un nouveau spécifique à ce nouveau pbm?

                          Merci

                          JC
                          0
                          1. jc74,

                            -Dernière chose, vider la quarantaine Antivir.

                            ------------------------
                            - Comme rien n'a été détecté par Kaspersky et Antivir a tout bloqué, désactiver la restauration système attendre qu'il travail puis l’activer de nouveau
                            Pour cela suivre les instructions du lien ICI

                            ------------------------
                            -Recherches dans ton disque C:/qoobox/ et supprimes le répertoire (c'est la quarantaine de Combofix en particulier)
                            Puis si tu trouves Combofix supprimes le également.

                            ------------------------
                            -Pour adaware, il a du être installé alors que des infections étaient présente donc surement mal installé.
                            Désinstalles le puis passe CCleaner ensuite (Registre x2, Nettoyeur) et réinstalles le.

                            ------------------------
                            -En résumé donc pour la protection AntiVirus à jour, 2 ou 3 Antispyware à jour dont 1 seul en résident, Pare feu, Firefox, Windows update, IExplorer 7 quand firefox ne marche pas.

                            Ensuite je penses tu pourras cocher le problème comme résolu en haut de ton tout premier message.

                            A+
                            0
                            1. Salut DeNisCoOl,

                              J'ai bien fait tout ça, Kapersky n'a rien trouvé et ToolsCleaner n'a trouvé que HijackThis.

                              Cela sent bon la propreté, non?

                              Juste un problème (déjà évoqué sur la réponse 12): ad-aware ne passe pas, il me plante le PC qui reboote. C'est grave docteur?

                              Voilà, si tu me dis que tout est bon, j'espère bien ne plus avoir à t'embêter!

                              Encore merci pour tout, c'est un vrai boulot ce que vous faites pour aider les gens sur CMM.

                              A+

                              JC
                              0
                              1. Salut jc,

                                As tu exécuté les étapes suivantes ?

                                2- CCleaner (bouton Nettoyeur puis Registre x3)
                                4- Scan en ligne Kaspersky
                                5- ToolsCleaner

                                Quant tous sera propre tu pourras désactiver et réactiver la restauration système.

                                A+
                                0
                                1. Sakut DeNisCoOl,

                                  J'ai bien essayé de fixer les 2 lignes en mode sans échec mais j'ai bien l'impression que cela n'a pas fonctionné... (voir le log ci-dessous)

                                  Merci pour tes conseils, j'ai installé Antivir et fais le scan, il m'a fait un peu peur (il a trouvé les virus des fichiers en quarantaine, mais aussi les mêmes que McAfee appelait Puper.dll) mais je n'ai pas encore eu d'alerte ce soir. Je te mets aussi le log au cas où.

                                  Merci encore. S'il y a encore qq chose à faire, dis-le moi mais j'ai l'impression que tu m'as tiré d'affaire, non ? (à part ces 2 lignes, j'ai cherché des infos mais je n'ai rien trouvé dessus)

                                  En tout cas, je trouve que tu fais un super boulot.

                                  A+

                                  JC

                                  Log HijackThis
                                  ========
                                  **********************************************************************************
                                  Logfile of Trend Micro HijackThis v2.0.2
                                  Scan saved at 21:58, on 2008-01-29
                                  Platform: Windows XP SP2 (WinNT 5.01.2600)
                                  MSIE: Internet Explorer v7.00 (7.00.6000.16574)
                                  Boot mode: Normal

                                  Running processes:
                                  C:\WINDOWS\System32\smss.exe
                                  C:\WINDOWS\SYSTEM32\winlogon.exe
                                  C:\WINDOWS\system32\services.exe
                                  C:\WINDOWS\system32\lsass.exe
                                  C:\WINDOWS\system32\svchost.exe
                                  C:\WINDOWS\System32\svchost.exe
                                  C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
                                  C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
                                  C:\Program Files\Sygate\SPF\smc.exe
                                  C:\WINDOWS\system32\spoolsv.exe
                                  C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                                  C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                                  C:\WINDOWS\eHome\ehRecvr.exe
                                  C:\WINDOWS\eHome\ehSched.exe
                                  c:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
                                  C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
                                  C:\WINDOWS\system32\svchost.exe
                                  C:\WINDOWS\system32\dllhost.exe
                                  C:\WINDOWS\Explorer.EXE
                                  C:\WINDOWS\system32\RUNDLL32.EXE
                                  C:\WINDOWS\RTHDCPL.EXE
                                  C:\Program Files\ASUS\Splendid\ACMON.exe
                                  C:\Program Files\Wireless Console 2\wcourier.exe
                                  C:\Program Files\ASUS\ATK Media\DMEDIA.EXE
                                  C:\WINDOWS\system32\ACEngSvr.exe
                                  C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                                  C:\Program Files\ASUS\Power4 Gear\BatteryLife.exe
                                  C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
                                  C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
                                  C:\WINDOWS\emMON.exe
                                  C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
                                  C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                                  C:\Program Files\ASUS\Net4Switch\Net4Switch.exe
                                  C:\Program Files\Microsoft ActiveSync\Wcescomm.exe
                                  C:\WINDOWS\system32\ctfmon.exe
                                  C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                                  C:\PROGRA~1\MICROS~3\rapimgr.exe
                                  C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
                                  C:\Program Files\Mozilla Firefox\firefox.exe
                                  C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
                                  C:\Program Files\Trend Micro\HijackThis\eden.exe

                                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/
                                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=60327
                                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://dnl.crawler.com/support/sa_customize.aspx?TbId=60327
                                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                                  O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                                  O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                  O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                                  O4 - HKLM\..\Run: [ABLKSR] C:\WINDOWS\ABLKSR\ABLKSR.exe
                                  O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
                                  O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
                                  O4 - HKLM\..\Run: [ACMON] C:\Program Files\ASUS\Splendid\ACMON.exe
                                  O4 - HKLM\..\Run: [Wireless Console 2] C:\Program Files\Wireless Console 2\wcourier.exe
                                  O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files\ASUS\ATK Media\DMEDIA.EXE
                                  O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                                  O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
                                  O4 - HKLM\..\Run: [Power_Gear] C:\Program Files\ASUS\Power4 Gear\BatteryLife.exe 1
                                  O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
                                  O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
                                  O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
                                  O4 - HKLM\..\Run: [emMON] emMON.exe
                                  O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
                                  O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                                  O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                                  O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                                  O4 - HKCU\..\Run: [Net4Switch] C:\Program Files\ASUS\Net4Switch\Net4Switch.exe
                                  O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\Wcescomm.exe"
                                  O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                                  O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                                  O4 - Global Startup: MultiFrame.lnk.disabled
                                  O4 - Global Startup: Adobe Reader Speed Launch.lnk.disabled
                                  O4 - Global Startup: Bluetooth Manager.lnk.disabled
                                  O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                                  O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                  O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                  O14 - IERESET.INF: START_PAGE_URL=https://www.asus.com/fr/
                                  O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://appldnld.apple.com/QuickTime/qtactivex/qtplugin.cab
                                  O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                                  O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                                  O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                                  O23 - Service: Service d'indexation CiSvcSchedule (CiSvcSchedule) - Unknown owner - C:\WINDOWS\system32\c_437v.exe (file missing)
                                  O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
                                  O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
                                  O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                                  O23 - Service: Panda Process Protection Service (PavPrSrv) - Unknown owner - C:\Program Files\Fichiers communs\Panda Software\PavShld\pavprsrv.exe (file missing)
                                  O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
                                  O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
                                  O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
                                  O23 - Service: Cliché instantané de volume VSSDnscache (VSSDnscache) - Unknown owner - C:\WINDOWS\system32\c_1252s.exe (file missing)
                                  0
                                  1. Salut,

                                    Tout semble correct, on va commencer le reste du nettoyage pour améliorer ta protection.
                                    Mais il y a 2 lignes qui m'embêtes elles sont toujours là.

                                    -Comme vous n'aurez pas accès à internet pendant la procédure, enregistrez cette page sur le bureau, aller dans le menu fichier du navigateur puis choisir enregistrez sous...

                                    Sinon pour ne pas se tromper, Copier et coller la liste dans le bloc note : clic bouton droit de la souris sur le Bureau, Nouveau> Document texte>

                                    Redémarrer l’ordinateur en mode sans échec (voir la procédure ICI )

                                    Choisir son compte, pas celui de l'Administrateur ou autre.

                                    Ouvrir le texte avec la liste.
                                    Relancer HiJackthis cliquer sur Do a scan only et cocher les lignes en gras:


                                    O23 - Service: Service d'indexation CiSvcSchedule (CiSvcSchedule) - Unknown owner - C:\WINDOWS\system32\c_437v.exe (file missing)
                                    O23 - Service: Cliché instantané de volume VSSDnscache (VSSDnscache) - Unknown owner - C:\WINDOWS\system32\c_1252s.exe (file missing)


                                    Fermez toutes les applications et le navigateur et cliquer sur Fix Checked.
                                    Et redémarrez en mode normal.

                                    ------------------
                                    -Je te conseillerais Firefox, plus sure, plus rapide et plus souple que IE : http://www.mozilla-europe.org/fr/products/firefox/

                                    ------------------
                                    Un autre anti spyware utile pour Internet explorer en particulier.
                                    1a- Cliquer sur Spywareblaster pour le télécharger
                                    Après l’installation et la configuration, il suffit de faire les mises à jour il s’occupe du reste.
                                    Le tutorial très complet ICI (merci à 01net.com)
                                    ------------------------
                                    2- CCleaner (en français) pour nettoyer les fichiers temporaires, cookies... ainsi que les clefs de la base de registre inutile.

                                    Pendant l'installation décocher l'ajout de la barre yahoo.
                                    Son tutorial ICI
                                    Une fois installé, aller dans Options/Propriétés/ Effacement sécurisé du fichier (lent) Type NSA (7 Passages).
                                    Ensuite dans Options/Avancés, décocher : effacer uniquement les fichiers du répertoires temp de Windows de plus vieux que 48h.
                                    C'est la meilleure config.
                                    Bouton Nettoyer, cliquer sur Analyse laisser travailler cela peut être très long ensuite cliquer sur Lancer le nettoyage.
                                    Ensuite sur le bouton Registre répéter 2 fois les étapes suivantes:
                                    Chercher les erreurs- Réparer les erreurs sélectionnées
                                    Ne pas oublier de sauvegarder au cas où il supprimerait une mauvaise clef (peu probable).
                                    À effacer ensuite s’il n’y a pas de problème par la suite.

                                    ------------------------
                                    3- Ad-aware2007
                                    Un très bon complément entre Spybot et CCleaner.
                                    Nouvelle version en anglais uniquement, mais très simple (appuyer sur cancel quand il demande les numéros de série pour avoir la version gratuite).
                                    La première fois, appuyer sur le bouton update il va demander si vous voulez exécuter update cliquer Yes.
                                    Ensuite appuyer sur scan et la première fois, cocher full scan et appuyer sur scan (la fois suivante, cocher smart scan, il fera un scan des zones principales).
                                    Cliquer sur les 2 onglets Critical et Privacy objects, cocher les objets trouvés et cliquer sur Remove

                                    ------------------------
                                    4- Faire un scan en ligne (sous IE uniquement, cliquer sur la barre qui s'affiche un peu en dessous de la barre d'adresse et accepter le module activeX) :
                                    Kaspersky https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr (Utile à rajouter dans ses favoris)

                                    ------------------------
                                    5- ToolsCleaner de A.Rothstein
                                    Pour supprimer toutes les traces des logiciels qui ont servi à traiter les infections spécifiques

                                    Télécharge le http://pagesperso-orange.fr/AceRothstein/ToolsCleaner2.exe sur ton Bureau.
                                    * Double-clique sur ToolsCleaner2.bat et laisse le travailler
                                    * Clique sur Recherche et laisse le scan se terminer.
                                    * Clique sur Suppression pour finaliser.
                                    * Tu peux, si tu le souhaites, te servir des Options facultatives.
                                    * Clique sur Quitter, pour que le rapport puisse se créer.

                                    ------------------------
                                    6- Mises à jours pour voir si tu as les dernières versions des Plugs in, Navigateur, Windows, Flash...
                                    C’est en anglais mais il y a juste 1 ou 2 boutons à cliquer.
                                    https://www.flexera.com/products/operations/software-vulnerability-management.html
                                    Une petite explication dans ce lien (merci malekal).
                                    Et bien entendu windows update: http://www.update.microsoft.com/microsoftupdate/v6/default.aspx?ln=fr

                                    ------------------------
                                    7-Tu as déjà un parefeu Sygate c'est bien, je te conseillerais plutôt Sunbelt (ex Kerio), mais rien d'urgent.

                                    ------------------------
                                    8- Comme anti virus gratuit Avast est dépassé par les rootkit et les virus du type msn, je te conseilles Antivir de Avira, bien meilleur que Avast qui lui n’a que peu, voir pas évolué depuis 2ans.

                                    Un comparatif intéressant Avast-Antivir ICI

                                    Et un autre comparatif complet: https://www.av-comparatives.org/

                                    -Avant d'arrêter et d'enlever ton McAfee:
                                    télécharger Antivir de Avira ICI: le sauvegarder dans votre bureau
                                    voir tutoriel de Antivir ICI :
                                    Il est en anglais mais cela ne change rien car les AV en français utilisent tous des mots anglais également.

                                    Ensuite installer Antivir.
                                    Après qu'il vous ait été demandé de redémarrer, faire la mise à jour de Antivir

                                    Ensuite lancer une Analyse complète.

                                    Pendant ce temps là fermer McAfee, puis dans le panneau de configuration, ajout/suppr. de programme enlever McAfee

                                    A+
                                    0
                                    1. Salut,

                                      Le processus normal dont je parlais est le "Processus inactif du système". Je t'avais dit qu'il me prenait pas mal de cpu mais j'ai vu plus tard que c'était un processus normal de Windows.

                                      Puper.dll ne m'a toujours pas embêté aujourd'hui.

                                      J'ai refait un scan Spybot et il n'a rien retrouvé (j'avais bien vacciné). Depuis que j'ai installé Spybot 1.5 (à la place de 1.4), il est super long à se charger, as-tu des infos à ce sujet?

                                      D'autre part, que me conseilles-tu comme anti-virus. Je pensais à Avast mais dans les avis j'ai vu un post dans lequel tu le critiquais... Alors lequel choisir, en freeware de préférence?
                                      Pour l'instant j'ai VirusScan de McAfee v4.5.1 SP1 (moteur d'analyse 5.2.00) associé à Spybot 1.5

                                      Pour mes touches de fonction qui ne fonctionnent plus (associées à la touche Fn), ce n'est pas grave, je règlerai ça à l'occasion...

                                      Question subsidiaire: j'ai commencé à désinstaller différents outils que tu m'as fait installer pour la désinfection. Est-ce que je peux tout enlever ou me conseilles-tu d'en garder certains ? Je réinstallerai le cas échéant.

                                      Voici les rapports pour vérif:

                                      HijackThis
                                      ======

                                      **********************************************************************************
                                      Logfile of Trend Micro HijackThis v2.0.2
                                      Scan saved at 21:48:05, on 25/01/2008
                                      Platform: Windows XP SP2 (WinNT 5.01.2600)
                                      MSIE: Internet Explorer v7.00 (7.00.6000.16574)
                                      Boot mode: Normal

                                      Running processes:
                                      C:\WINDOWS\System32\smss.exe
                                      C:\WINDOWS\SYSTEM32\winlogon.exe
                                      C:\WINDOWS\system32\services.exe
                                      C:\WINDOWS\system32\lsass.exe
                                      C:\WINDOWS\system32\svchost.exe
                                      C:\WINDOWS\System32\svchost.exe
                                      C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
                                      C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
                                      C:\Program Files\Sygate\SPF\smc.exe
                                      C:\WINDOWS\system32\spoolsv.exe
                                      C:\Program Files\Network Associates\VirusScan\Avsynmgr.exe
                                      C:\WINDOWS\eHome\ehRecvr.exe
                                      C:\WINDOWS\eHome\ehSched.exe
                                      c:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
                                      C:\WINDOWS\system32\nvsvc32.exe
                                      C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
                                      C:\WINDOWS\system32\svchost.exe
                                      C:\Program Files\Network Associates\VirusScan\VsStat.exe
                                      C:\WINDOWS\system32\dllhost.exe
                                      C:\Program Files\Network Associates\VirusScan\Vshwin32.exe
                                      C:\Program Files\Fichiers communs\Network Associates\McShield\Mcshield.exe
                                      C:\Program Files\Network Associates\VirusScan\Avconsol.exe
                                      C:\Program Files\Network Associates\VirusScan\Webscanx.exe
                                      C:\WINDOWS\Explorer.EXE
                                      C:\WINDOWS\system32\RUNDLL32.EXE
                                      C:\WINDOWS\RTHDCPL.EXE
                                      C:\Program Files\ASUS\Splendid\ACMON.exe
                                      C:\Program Files\Wireless Console 2\wcourier.exe
                                      C:\Program Files\ASUS\ATK Media\DMEDIA.EXE
                                      C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                                      C:\Program Files\ASUS\Power4 Gear\BatteryLife.exe
                                      C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
                                      C:\WINDOWS\system32\ACEngSvr.exe
                                      C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
                                      C:\WINDOWS\emMON.exe
                                      C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
                                      C:\Program Files\ASUS\Net4Switch\Net4Switch.exe
                                      C:\Program Files\Microsoft ActiveSync\Wcescomm.exe
                                      C:\WINDOWS\system32\ctfmon.exe
                                      C:\PROGRA~1\MICROS~3\rapimgr.exe
                                      C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
                                      C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                                      C:\WINDOWS\system32\taskmgr.exe
                                      C:\Program Files\Internet Explorer\iexplore.exe
                                      C:\Program Files\Trend Micro\HijackThis\aidoforum.exe

                                      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/
                                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=60327
                                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://dnl.crawler.com/support/sa_customize.aspx?TbId=60327
                                      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                                      O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                                      O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                                      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                                      O4 - HKLM\..\Run: [ABLKSR] C:\WINDOWS\ABLKSR\ABLKSR.exe
                                      O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
                                      O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
                                      O4 - HKLM\..\Run: [ACMON] C:\Program Files\ASUS\Splendid\ACMON.exe
                                      O4 - HKLM\..\Run: [Wireless Console 2] C:\Program Files\Wireless Console 2\wcourier.exe
                                      O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files\ASUS\ATK Media\DMEDIA.EXE
                                      O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                                      O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
                                      O4 - HKLM\..\Run: [Power_Gear] C:\Program Files\ASUS\Power4 Gear\BatteryLife.exe 1
                                      O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
                                      O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
                                      O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
                                      O4 - HKLM\..\Run: [emMON] emMON.exe
                                      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
                                      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                                      O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
                                      O4 - HKCU\..\Run: [Net4Switch] C:\Program Files\ASUS\Net4Switch\Net4Switch.exe
                                      O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\Wcescomm.exe"
                                      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                                      O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                                      O4 - Global Startup: MultiFrame.lnk.disabled
                                      O4 - Global Startup: Adobe Reader Speed Launch.lnk.disabled
                                      O4 - Global Startup: Bluetooth Manager.lnk.disabled
                                      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                                      O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                      O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                      O14 - IERESET.INF: START_PAGE_URL=https://www.asus.com/fr/
                                      O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://appldnld.apple.com/QuickTime/qtactivex/qtplugin.cab
                                      O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                                      O23 - Service: AVSync Manager (AvSynMgr) - Unknown owner - C:\Program Files\Network Associates\VirusScan\Avsynmgr.exe
                                      O23 - Service: Service d'indexation CiSvcSchedule (CiSvcSchedule) - Unknown owner - C:\WINDOWS\system32\c_437v.exe (file missing)
                                      O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
                                      O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
                                      O23 - Service: McShield - Unknown owner - C:\Program Files\Fichiers communs\Network Associates\McShield\Mcshield.exe
                                      O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                                      O23 - Service: Panda Process Protection Service (PavPrSrv) - Unknown owner - C:\Program Files\Fichiers communs\Panda Software\PavShld\pavprsrv.exe (file missing)
                                      O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
                                      O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
                                      O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
                                      O23 - Service: Cliché instantané de volume VSSDnscache (VSSDnscache) - Unknown owner - C:\WINDOWS\system32\c_1252s.exe (file missing)
                                      0
                                      1. Re,

                                        -Désolé un des 2 fichiers, je te l'avais fait effacer avec OTMoveIT au début, donc c'était normal ;-)
                                        Je n'étais pas remonté assez haut dans tes rapports.

                                        -Quel processus est normal, Pupper.dll?

                                        -Spybot ce n'était pas grand chose mais as tu vacciné ensuite sinon ces attaques reviendront probablement?

                                        -Oui repost un log HJThis et Combofix également.

                                        -On a rien touché concernant ta carte son mais rien ne peut être sure à 100% bien entendu.
                                        Essayes de désinstaller et réinstaller les pilotes de la carte son ou est ce le clavier ?

                                        A+
                                        0
                                        • 1
                                        • 2