Pub + rame virus ?

Bonjour, depuis que j'ai formaté mon ordi, il y a toutes sortes de pubs qui apparaisse à l'écran, sa rame a fond j'crois que j'ai choppée un virus coment pourais je faire pour que mon ordi retrouve ces capacitées initiales ?
Configuration: Windows Vista
Internet Explorer 7.0

28 réponses

Résumé de la discussion

Des publicités intempestives et un ralentissement système surviennent sur Windows Vista et Internet Explorer 7 après une réinstallation, suscitant la crainte d’un virus et de perte de performances initiales. Plusieurs réponses proposent des outils et procédures de décontamination comme Navilog, Navilog1, Clean.zip, et OTMoveIt pour identifier et supprimer des éléments suspects dans ProgramData et les dossiers temporaires. D'autres réponses suggèrent des analyses plus fines via des scans d'outils comme HijackThis/Lop S&D, Catchme et GMER, vérifiant le registre, le fichier Hosts et les éléments Run pour éviter de supprimer des composants légitimes. Le fil montre aussi des rapports Navilog et DiagHelp qui nécessitent une analyse par un spécialiste avant toute suppression, et note que les résultats peuvent révéler des fichiers légitimes.

Bobot (l’IA à votre service)
  1. Contributeur
    Bonsoir

    Va dans "demarrer" "tous les programmes" tu vas sur spybot tu ouvres le dossier et la tu as 3 choix: "spybot S&D", "uninstall" et "update" tu cliques droit sur le premier et tu as "executer en tant qu'administrateur" tu cliques dessus et la tu peux tout controler
    1. Quand je clique sur corriger les probleme il me dit que l'action ne peut pas s'effectuer car je ne suis pas administrateur.J'comprend pas pourtant je le suis !
      1. Contributeur
        Très bien

        Télécharge ATF Cleaner par Atribune.
        http://www.atribune.org/ccount/click.php?id=1

        Double-clique ATF-Cleaner.exe afin de lancer le programme.
        Sous l'onglet Main, choisis : Select All
        Clique sur le bouton Empty Selected

        Si tu utilises le navigateur Firefox :

        Clique Firefox au haut et choisis : Select All
        Clique le bouton Empty Selected
        NOTE : Si tu veux conserver tes mots de passe sauvegardés, clique No à l'invite.

        Si tu utilises le navigateur Opera :

        Clique Opera au haut et choisis : Select All
        Clique le bouton Empty Selected
        NOTE : Si tu veux conserver tes mots de passe sauvegardés, clique No à l'invite.

        Clique Exit, du menu prinicipal, afin de fermer le programme.
        Pour obtenir du Support technique, double-clique l'adresse électronique située au bas de chacun des menus.


        ensuite


        Télécharge sur ton Bureau ==> SpyBot-S&D => https://www.safer-networking.org/download/

        Pour son installation regarde ==> ici =>https://www.malekal.com/spybot-search-destroy-proteger-desinfecter-pc-virus/

        - Fais un double clique sur Spybot-S&D afin de lancer le programme.

        - Clique sur le bouton Vérifier tout.
        - Une fois le balayage terminé, Spybot affichera tous les mouchards, dialers et autres indésirables en rouge.
        - Assure-toi qu'ils soient tous cochés, puis clique sur Corriger les problèmes.
        - Clique sur Oui pour autoriser Spybot à nettoyer les mouchards.
        - Clique sur le menu vaccination à gauche et ensuite sur ok
        - Clique sur le bouton + Vacciner

        Passe c'est outils et refais un nouveau hijack pour vérif stp

        et dit moi si tu as encore des soucis
        1. -----------------------[ Lop S&D 4.2.1-6 XP/Vista ]---------------------

          [ Windows 'Longhorn' (NT 6.0) Workstation Build 6000 ]
          [ USER : Sophie ] [ "C:\Lop SD" ] [ Selection : 2 ]
          [ 17/06/2008 | 23:02:58,43 ] [ PC : PC-DE-SOPHIE ]
          [ MAJ : 16-06-2008 | 23:01 ]
          [ UAC => 0 ]

          \\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ SUPPRESSION /////////////////////////////

          Supprimé! - C:\ProgramData\Long slow road itch\Does Camp.exe
          Supprimé! - C:\Program Files\Circle Developement\Uninstall.exe
          Supprimé! - C:\ProgramData\idle enc enc.ex9ysx7
          Supprimé! - C:\ProgramData\idle enc enc.gglux4
          Supprimé! - C:\ProgramData\idle enc enc.tkngbb8
          Supprimé! - C:\ProgramData\idle enc enc.y2m2w6x
          Supprimé! - C:\ProgramData\Long slow road itch
          Supprimé! - C:\Program Files\Circle Developement
          Restauré! - Fichier Hosts

          //////////////////////////////////////-\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\

          -------------[ Listing des dossiers dans Application Data ]------------

          [14/05/2008|12:37] C:\Users\Sophie\AppData\Roaming\Adobe\Flash Player
          [12/05/2008|21:34] C:\Users\Sophie\AppData\Roaming\Adobe\Acrobat

          [16/06/2008|17:54] C:\Users\Sophie\AppData\Roaming\Google\Local Search History

          [02/11/2006|15:03] C:\Users\Sophie\AppData\Roaming\Identities\{F09DEB20-C877-4C92-A4F4-B30EA5DF074C}

          [19/05/2008|12:50] C:\Users\Sophie\AppData\Roaming\InstallShield\ISEngine12.0

          [14/05/2008|10:27] C:\Users\Sophie\AppData\Roaming\LimeWire\xml
          [14/05/2008|10:25] C:\Users\Sophie\AppData\Roaming\LimeWire\.AppSpecialShare
          [14/05/2008|10:25] C:\Users\Sophie\AppData\Roaming\LimeWire\themes

          [15/06/2008|00:46] C:\Users\Sophie\AppData\Roaming\Macromedia\Flash Player

          [12/06/2008|15:29] C:\Users\Sophie\AppData\Roaming\Malwarebytes\Malwarebytes' Anti-Malware

          [14/06/2008|22:58] C:\Users\Sophie\AppData\Roaming\Microsoft\Windows Photo Gallery
          [10/06/2008|18:48] C:\Users\Sophie\AppData\Roaming\Microsoft\Credentials
          [05/06/2008|18:39] C:\Users\Sophie\AppData\Roaming\Microsoft\HTML Help
          [03/06/2008|12:14] C:\Users\Sophie\AppData\Roaming\Microsoft\MSN Messenger
          [30/05/2008|08:35] C:\Users\Sophie\AppData\Roaming\Microsoft\Windows
          [16/05/2008|20:44] C:\Users\Sophie\AppData\Roaming\Microsoft\Installer
          [13/05/2008|17:19] C:\Users\Sophie\AppData\Roaming\Microsoft\eHome
          [13/05/2008|17:12] C:\Users\Sophie\AppData\Roaming\Microsoft\Crypto
          [13/05/2008|17:03] C:\Users\Sophie\AppData\Roaming\Microsoft\IdentityCRL
          [13/05/2008|12:42] C:\Users\Sophie\AppData\Roaming\Microsoft\Internet Explorer
          [13/05/2008|12:42] C:\Users\Sophie\AppData\Roaming\Microsoft\Protect
          [12/05/2008|20:40] C:\Users\Sophie\AppData\Roaming\Microsoft\CLR Security Config
          [02/11/2006|15:04] C:\Users\Sophie\AppData\Roaming\Microsoft\SystemCertificates

          [14/05/2008|08:55] C:\Users\Sophie\AppData\Roaming\Microsoft Games\ZT2Launcher
          [12/05/2008|21:35] C:\Users\Sophie\AppData\Roaming\Microsoft Games\Vince
          [12/05/2008|21:02] C:\Users\Sophie\AppData\Roaming\Microsoft Games\Zoo Tycoon 2

          [27/05/2008|13:04] C:\Users\Sophie\AppData\Roaming\OpenOffice.org2\user

          [14/06/2008|21:05] C:\Users\Sophie\AppData\Roaming\Toshiba\TOPI

          ----------------[ Tâches planifiées dans C:\Windows\tasks ]---------------

          [16/06/2008 23:19][--ah-----] C:\Windows\tasks\SA.DAT
          [16/06/2008 23:17][--a------] C:\Windows\tasks\SCHEDLGU.TXT

          ------[ Listing des dossiers dans C:\ProgramData ]------

          [20/12/2006|14:27] C:\ProgramData\Adobe
          [02/11/2006|15:02] C:\ProgramData\Application Data
          [16/05/2008|19:09] C:\ProgramData\Avira
          [12/05/2008|20:36] C:\ProgramData\Bureau
          [02/11/2006|15:02] C:\ProgramData\Desktop
          [02/11/2006|15:02] C:\ProgramData\Documents
          [14/05/2008|20:35] C:\ProgramData\Downloaded Installations
          [12/05/2008|20:36] C:\ProgramData\Favoris
          [02/11/2006|15:02] C:\ProgramData\Favorites
          [13/05/2008|18:14] C:\ProgramData\Google
          [17/06/2008|11:48] C:\ProgramData\Logishrd
          [16/05/2008|20:39] C:\ProgramData\Logitech
          [12/06/2008|15:29] C:\ProgramData\Malwarebytes
          [12/05/2008|20:36] C:\ProgramData\Menu D‚marrer
          [13/05/2008|18:27] C:\ProgramData\Messenger Plus!
          [05/06/2008|18:39] C:\ProgramData\Microsoft
          [12/05/2008|20:51] C:\ProgramData\Microsoft Games
          [12/05/2008|20:36] C:\ProgramData\ModŠles
          [20/12/2006|14:47] C:\ProgramData\NVIDIA
          [12/06/2008|16:43] C:\ProgramData\SlowDownload
          [02/11/2006|15:02] C:\ProgramData\Start Menu
          [13/06/2008|20:33] C:\ProgramData\Symantec
          [02/11/2006|15:02] C:\ProgramData\Templates
          [20/12/2006|12:22] C:\ProgramData\Toshiba
          [12/05/2008|20:39] C:\ProgramData\ToshibaEurope
          [20/12/2006|13:17] C:\ProgramData\Ulead Systems
          [13/05/2008|16:55] C:\ProgramData\WLInstaller

          ---------------[ Listing des dossiers dans C:\Program Files ]--------------

          [20/12/2006|14:26] C:\Program Files\Adobe
          [16/05/2008|19:09] C:\Program Files\Avira
          [12/06/2008|15:14] C:\Program Files\CCleaner
          [17/06/2008|11:35] C:\Program Files\Common Files
          [20/12/2006|10:13] C:\Program Files\CONEXANT
          [14/05/2008|10:04] C:\Program Files\desktop.ini
          [12/05/2008|20:36] C:\Program Files\Fichiers communs [C:\Program Files\Common Files]
          [14/06/2008|20:37] C:\Program Files\Google
          [15/06/2008|00:44] C:\Program Files\happynote
          [04/06/2008|20:27] C:\Program Files\HP
          [19/05/2008|12:51] C:\Program Files\InstallShield Installation Information
          [12/06/2008|09:19] C:\Program Files\Internet Explorer
          [20/12/2006|13:18] C:\Program Files\InterVideo
          [29/05/2008|21:16] C:\Program Files\Java
          [13/05/2008|16:59] C:\Program Files\LimeWire
          [17/06/2008|11:35] C:\Program Files\Logitech
          [14/06/2008|23:56] C:\Program Files\Malwarebytes' Anti-Malware
          [13/06/2008|10:19] C:\Program Files\Messenger Plus! Live
          [14/05/2008|09:27] C:\Program Files\Microsoft CAPICOM 2.1.0.2
          [12/05/2008|20:42] C:\Program Files\Microsoft Games
          [02/11/2006|14:42] C:\Program Files\Movie Maker
          [02/11/2006|14:37] C:\Program Files\MSBuild
          [02/11/2006|14:37] C:\Program Files\MSN
          [14/05/2008|08:50] C:\Program Files\MSXML 4.0
          [20/12/2006|09:54] C:\Program Files\My Company Name
          [14/06/2008|21:50] C:\Program Files\Navilog1
          [15/06/2008|20:18] C:\Program Files\Neuf
          [26/05/2008|20:22] C:\Program Files\OneStopSoft.com
          [14/06/2008|22:32] C:\Program Files\OpenOffice.org 2.4
          [15/06/2008|00:23] C:\Program Files\PhotoScape
          [02/11/2006|14:37] C:\Program Files\Reference Assemblies
          [16/05/2008|22:40] C:\Program Files\Satsuki Decoder Pack
          [14/05/2008|16:02] C:\Program Files\Sibelius Software
          [20/12/2006|10:08] C:\Program Files\Synaptics
          [20/12/2006|16:01] C:\Program Files\TOSHIBA
          [14/06/2008|20:50] C:\Program Files\Trend Micro
          [08/06/2008|20:54] C:\Program Files\Trymedia
          [20/12/2006|13:15] C:\Program Files\Ulead Systems
          [02/11/2006|15:01] C:\Program Files\Uninstall Information
          [14/05/2008|09:58] C:\Program Files\Windows Calendar
          [02/11/2006|14:42] C:\Program Files\Windows Collaboration
          [14/05/2008|09:58] C:\Program Files\Windows Defender
          [02/11/2006|14:42] C:\Program Files\Windows Journal
          [13/05/2008|17:02] C:\Program Files\Windows Live
          [12/06/2008|09:19] C:\Program Files\Windows Mail
          [20/12/2006|13:18] C:\Program Files\Windows Media Components
          [14/05/2008|09:58] C:\Program Files\Windows Media Player
          [12/05/2008|20:36] C:\Program Files\Windows NT
          [02/11/2006|14:42] C:\Program Files\Windows Photo Gallery
          [14/05/2008|09:58] C:\Program Files\Windows Sidebar
          [31/05/2008|22:04] C:\Program Files\WinRAR

          ------[ Listing des dossiers dans C:\Program Files\Common Files ]------

          [20/12/2006|14:27] C:\Program Files\Common Files\Adobe
          [15/06/2008|00:49] C:\Program Files\Common Files\BitDefender
          [04/06/2008|20:27] C:\Program Files\Common Files\HP
          [20/12/2006|13:18] C:\Program Files\Common Files\InstallShield
          [20/12/2006|09:52] C:\Program Files\Common Files\Java
          [17/06/2008|11:43] C:\Program Files\Common Files\LogiShrd
          [17/06/2008|11:38] C:\Program Files\Common Files\Logitech
          [12/05/2008|20:51] C:\Program Files\Common Files\Microsoft Games
          [13/05/2008|17:05] C:\Program Files\Common Files\microsoft shared
          [02/11/2006|13:18] C:\Program Files\Common Files\Services
          [02/11/2006|13:18] C:\Program Files\Common Files\SpeechEngines
          [13/06/2008|22:15] C:\Program Files\Common Files\Symantec Shared
          [14/05/2008|09:58] C:\Program Files\Common Files\System
          [20/12/2006|13:18] C:\Program Files\Common Files\Ulead Systems
          [13/05/2008|17:02] C:\Program Files\Common Files\WindowsLiveInstaller

          ---------------------------[ Process ]--------------------------

          ... 75

          ... OK !

          ----------------------[ Recherche avec S_Lop ]---------------------

          Aucun fichier / dossier Lop trouvé !

          -----------------[ Recherche de Fichiers / Dossiers Lop ]-----------------

          Aucun fichier / dossier Lop trouvé !

          ----------------------[ Verification du Registre ]----------------------

          [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

          ..... OK !

          --------------------[ Verification du fichier Hosts ]---------------------

          Fichier Hosts PROPRE

          ----------------[ Recherche de fichiers avec Catchme ]-----------------

          catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
          Rootkit scan 2008-06-17 23:03:42
          Windows 6.0.6000 NTFS
          scanning hidden processes ...
          scanning hidden files ...
          scan completed successfully
          hidden processes: 0
          hidden files: 0

          --------------------[ Recherche d'autres infections ]---------------------

          Aucune autre infection trouvée !

          [F:266][D:50]-> C:\Users\Sophie\AppData\Local\Temp
          [F:787][D:1]-> C:\Users\Sophie\AppData\Roaming\MICROS~1\Windows\Cookies
          [F:801][D:7]-> C:\Users\Sophie\AppData\Local\MICROS~1\Windows\TEMPOR~1\content.IE5
          [F:3][D:3]-> C:\$Recycle.Bin

          [ UAC => 1 ]

          --------------------[ Fin du rapport a 23:04:17,91 ]----------------------
          1. Contributeur
            Télécharge LOP S&D d'Eric71 ici https://sites.google.com/site/eric71mespages/lop.sd.exe

            Double-clique dessus pour lancer l'installation.
            Puis double-clique sur le raccourci Lop S&D présent sur ton Bureau.
            Séléctionne la langue souhaitée , puis choisis l'Option 2 ( suppression )
            Patiente jusqu'à la fin du scan.
            Poste le rapport généré (situé aussi ici C:\lopR.txt )

            ( Si le Bureau ne réapparaît pas, lance le gestionnaire des tâches en cliquant sur Ctrl + Alt + Suppr , puis Onglet Fichier , Nouvelle tâche , tape explorer.exe et valide )
            1. voila lool

              DiagHelp version v1.4 - http://www.malekal.com
              excute le 17/06/2008 à 22:41:09,05

              Liste des derniers fichies modifies/crees dans windir\system32 et prefetch
              C:\Windows\prefetch\AVWSC.EXE-18A3FCA0.pf -->17/06/2008 22:33:08
              C:\Windows\prefetch\AURORA.SCR-082F40F8.pf -->17/06/2008 22:33:06
              C:\Windows\prefetch\AgGlFgAppHistory.db -->17/06/2008 22:12:55
              C:\Windows\prefetch\AgGlFaultHistory.db -->17/06/2008 22:12:54
              C:\Windows\prefetch\AgGlGlobalHistory.db -->17/06/2008 22:12:53
              C:\Windows\prefetch\AgRobust.db -->17/06/2008 22:12:52
              C:\Windows\prefetch\AgGlUAD_S-1-5-21-1097218276-1889954354-71906903-1000.db -->17/06/2008 22:08:40
              C:\Windows\prefetch\AgGlUAD_P_S-1-5-21-1097218276-1889954354-71906903-1000.db -->17/06/2008 22:08:40
              C:\Windows\prefetch\TASKENG.EXE-48D4E289.pf -->17/06/2008 22:04:50
              C:\Windows\prefetch\AgCx_SC1.db -->17/06/2008 20:44:09

              C:\Windows\System32\drivers\mbamcatchme.sys -->10/06/2008 19:02:44
              C:\Windows\System32\drivers\mbam.sys -->10/06/2008 19:02:40
              C:\Windows\System32\drivers\WdfLdr.sys -->16/05/2008 08:06:20
              C:\Windows\System32\drivers\Wdf01000.sys -->16/05/2008 08:06:20
              C:\Windows\System32\drivers\sermouse.sys -->16/05/2008 08:06:18
              C:\Windows\System32\drivers\mouclass.sys -->16/05/2008 08:06:18
              C:\Windows\System32\drivers\kbdclass.sys -->16/05/2008 08:06:18

              C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 -->17/06/2008 22:04:24
              C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 -->17/06/2008 22:04:24
              C:\Windows\System32\perfh00C.dat -->17/06/2008 12:34:35
              C:\Windows\System32\perfh009.dat -->17/06/2008 12:34:35
              C:\Windows\System32\perfc00C.dat -->17/06/2008 12:34:35
              C:\Windows\System32\perfc009.dat -->17/06/2008 12:34:35
              C:\Windows\System32\PerfStringBackup.INI -->17/06/2008 12:34:33
              C:\Windows\System32\lvcoinst.log -->17/06/2008 11:44:04
              C:\Windows\System32\GDIPFONTCACHEV1.DAT -->15/06/2008 10:17:55
              C:\Windows\System32\FNTCACHE.DAT -->15/06/2008 10:14:53
              C:\Windows\System32\coh.cache -->13/06/2008 20:17:51
              C:\Windows\System32\mrt.exe -->30/05/2008 01:35:11
              C:\Windows\System32\jupdate-1.6.0_05-b13.log -->29/05/2008 21:16:38
              C:\Windows\System32\jupdate-1.6.0_04-b12.log -->27/05/2008 12:56:48
              C:\Windows\System32\satsukidecodersettings.ini -->16/05/2008 22:40:51
              C:\Windows\System32\setupapi.dll -->16/05/2008 08:07:32
              C:\Windows\System32\srdelayed.exe -->16/05/2008 08:06:38
              C:\Windows\System32\srcore.dll -->16/05/2008 08:06:38
              C:\Windows\System32\srclient.dll -->16/05/2008 08:06:38
              C:\Windows\System32\rstrui.exe -->16/05/2008 08:06:38
              C:\Windows\System32\wpd_ci.dll -->16/05/2008 08:06:37
              C:\Windows\System32\winresume.exe -->16/05/2008 08:06:36
              C:\Windows\System32\kd1394.dll -->16/05/2008 08:06:36
              C:\Windows\System32\winload.exe -->16/05/2008 08:06:35
              C:\Windows\System32\ci.dll -->16/05/2008 08:06:32

              C:\Windows\WindowsUpdate.log -->17/06/2008 20:46:26
              C:\Windows\bootstat.dat -->17/06/2008 20:42:59
              C:\Windows\setupact.log -->17/06/2008 12:31:27
              C:\Windows\setuperr.log -->15/06/2008 12:20:49
              C:\Windows\Sol.ini -->14/05/2008 20:17:30
              C:\Windows\pp-oneclick-repertoire.ini -->14/05/2008 20:16:17
              C:\Windows\WindowsShell.Manifest -->14/05/2008 10:04:52
              C:\Windows\explorer.exe -->14/05/2008 09:44:01
              C:\Windows\bdoscandellang.ini -->09/01/2008 15:01:48
              C:\Windows\bdoscandel.exe -->09/01/2008 15:01:48
              C:\Windows\csup.txt -->22/12/2006 10:34:39
              C:\Windows\NDSTray.INI -->20/12/2006 12:22:22
              C:\Windows\oemlogo.bmp -->03/11/2006 14:30:08
              C:\Windows\win.ini -->02/11/2006 15:04:04
              C:\Windows\WMSysPr9.prx -->02/11/2006 14:35:57

              winlogon.exe
              Verified: Signed
              svchost.exe
              Verified: Signed
              ws2_32.dll
              Verified: Signed
              user32.dll
              Verified: Signed
              tcpip.sys
              Verified: Signed
              ndis.sys
              Verified: Signed
              null.sys
              Verified: Signed

              ListDLLs v2.25 - DLL lister for Win9x/NT
              Copyright (C) 1997-2004 Mark Russinovich
              Sysinternals - www.sysinternals.com

              ------------------------------------------------------------------------------
              explorer.exe pid: 1744
              Command line: C:\Windows\Explorer.EXE

              Base Size Version Path
              0x00600000 0x2cd000 6.00.6000.16549 C:\Windows\Explorer.EXE
              0x779b0000 0x11e000 6.00.6000.16386 C:\Windows\system32\ntdll.dll
              0x76a80000 0xd8000 6.00.6000.16386 C:\Windows\system32\kernel32.dll
              0x769c0000 0xbf000 6.00.6000.16386 C:\Windows\system32\ADVAPI32.dll
              0x77780000 0xc3000 6.00.6000.16525 C:\Windows\system32\RPCRT4.dll
              0x76270000 0x4b000 6.00.6000.16643 C:\Windows\system32\GDI32.dll
              0x76920000 0x9e000 6.00.6000.16438 C:\Windows\system32\USER32.dll
              0x763a0000 0xaa000 7.00.6000.16386 C:\Windows\system32\msvcrt.dll
              0x76770000 0x55000 6.00.6000.16386 C:\Windows\system32\SHLWAPI.dll
              0x76cb0000 0xace000 6.00.6000.16513 C:\Windows\system32\SHELL32.dll
              0x767d0000 0x144000 6.00.6000.16386 C:\Windows\system32\ole32.dll
              0x77b60000 0x8c000 6.00.6000.16609 C:\Windows\system32\OLEAUT32.dll
              0x735f0000 0x107000 6.00.6000.16386 C:\Windows\system32\SHDOCVW.dll
              0x75310000 0x3f000 6.00.6000.16386 C:\Windows\system32\UxTheme.dll
              0x755c0000 0x1a000 6.00.6000.16386 C:\Windows\system32\POWRPROF.dll
              0x739d0000 0xc000 6.00.6000.16386 C:\Windows\system32\dwmapi.dll
              0x74ac0000 0x1aa000 5.02.6000.16386 C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16386_none_9ea0ac9ec96e7127\gdiplus.dll
              0x75b90000 0x39000 6.00.6000.16509 C:\Windows\system32\slc.dll
              0x74900000 0xb7000 6.00.6000.16386 C:\Windows\system32\PROPSYS.dll
              0x734a0000 0x145000 6.00.6000.16386 C:\Windows\system32\BROWSEUI.dll
              0x77b00000 0x1e000 6.00.6000.16386 C:\Windows\system32\IMM32.dll
              0x778e0000 0xc7000 6.00.6000.16386 C:\Windows\system32\MSCTF.dll
              0x752e0000 0x30000 6.00.6000.16386 C:\Windows\system32\DUser.dll
              0x76390000 0x9000 6.00.6000.16386 C:\Windows\system32\LPK.DLL
              0x762c0000 0x7d000 1.626.6000.16386 C:\Windows\system32\USP10.dll
              0x75010000 0x194000 6.10.6000.16386 C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6000.16386_none_5d07289e07e1d100\comctl32.dll
              0x73f70000 0xb2000 6.00.6000.16493 C:\Windows\system32\WindowsCodecs.dll
              0x73480000 0x6000 6.00.6000.16386 C:\Windows\system32\IconCodecService.dll
              0x760a0000 0x2c000 6.00.6000.16386 C:\Windows\system32\apphelp.dll
              0x76100000 0x14000 6.00.6000.16386 C:\Windows\system32\Secur32.dll
              0x77850000 0x84000 2001.12.6930.16386 C:\Windows\system32\CLBCatQ.DLL
              0x75660000 0x38000 6.00.6000.16386 C:\Windows\system32\rsaenh.dll
              0x72ba0000 0xb2000 6.00.6000.16549 C:\Windows\system32\timedate.cpl
              0x74710000 0x14000 3.05.2284.0000 C:\Windows\system32\ATL.DLL
              0x75f70000 0x6a000 6.00.6000.16386 C:\Windows\system32\NETAPI32.dll
              0x76260000 0x7000 6.00.6000.16386 C:\Windows\system32\PSAPI.DLL
              0x74de0000 0x38000 4.02.5406.0000 C:\Windows\system32\OLEACC.dll
              0x72ae0000 0x53000 6.00.6000.16386 C:\Windows\system32\actxprxy.dll
              0x76120000 0x1e000 6.00.6000.16386 C:\Windows\system32\USERENV.dll
              0x75940000 0x8000 6.00.6000.16386 C:\Windows\system32\VERSION.dll
              0x72b40000 0x2b000 6.00.6000.16386 C:\Windows\system32\msutb.dll
              0x72b80000 0x1b000 11.00.6000.6324 C:\PROGRA~1\WI4EB4~1\wmpband.dll
              0x75cd0000 0x14000 6.00.6000.16386 C:\Windows\system32\MPR.dll
              0x75720000 0xd7000 6.00.6000.16386 C:\Windows\system32\WINBRAND.dll
              0x75d40000 0x11000 6.00.6000.16386 C:\Windows\System32\SAMLIB.dll
              0x72a60000 0x38000 6.00.6000.16386 C:\Windows\System32\msshsq.dll
              0x728c0000 0xc5000 6.00.6000.16386 C:\Windows\System32\NaturalLanguage6.dll
              0x75bd0000 0xf1000 6.00.6000.16425 C:\Windows\System32\CRYPT32.dll
              0x75d20000 0x12000 6.00.6000.16386 C:\Windows\System32\MSASN1.dll
              0x74e20000 0x1e7000 6.00.6000.16513 C:\Windows\system32\authui.dll
              0x755b0000 0x5000 6.00.6000.16386 C:\Windows\system32\MSIMG32.dll
              0x72720000 0x19f000 6.00.6000.16651 C:\Windows\System32\gameux.dll
              0x72e50000 0x5f000 6.00.6000.16386 C:\Windows\System32\WINHTTP.dll
              0x76b60000 0xd0000 7.00.6000.16681 C:\Windows\system32\WININET.dll
              0x764a0000 0x3000 6.00.6000.16386 C:\Windows\system32\Normaliz.dll
              0x76340000 0x45000 7.00.6000.16386 C:\Windows\system32\iertutil.dll
              0x737e0000 0x148000 6.10.1200.0000 C:\Windows\System32\msxml6.dll
              0x729c0000 0x4c000 1.00.0000.0001 C:\Windows\System32\Wpc.dll
              0x75400000 0x9000 6.00.6000.16553 C:\Windows\System32\WTSAPI32.dll
              0x76640000 0x127000 7.00.6000.16681 C:\Windows\system32\urlmon.dll
              0x72fa0000 0x8a000 6.00.6000.16386 C:\Windows\System32\fwpuclnt.dll
              0x75b50000 0x3e000 6.00.6000.16386 C:\Windows\System32\wevtapi.dll
              0x77ad0000 0x2d000 6.00.6000.16386 C:\Windows\system32\WS2_32.dll
              0x77b20000 0x6000 6.00.6000.16386 C:\Windows\system32\NSI.dll
              0x72f90000 0x7000 4.00.6000.16386 C:\Windows\system32\msiltcfg.dll
              0x72190000 0x204000 4.00.6000.16386 C:\Windows\system32\msi.dll
              0x755e0000 0x21000 6.00.6000.16386 C:\Windows\system32\NTMARTA.DLL
              0x76450000 0x49000 6.00.6000.16386 C:\Windows\system32\WLDAP32.dll
              0x72f80000 0x9000 6.00.6000.16386 C:\Windows\system32\LINKINFO.dll
              0x711d0000 0x5cd000 7.00.6000.16681 C:\Windows\system32\ieframe.dll
              0x74d30000 0x33000 6.00.6000.16386 C:\Windows\system32\WINMM.dll
              0x74870000 0x30000 6.00.6000.16386 C:\Windows\system32\wdmaud.drv
              0x74cc0000 0x4000 6.00.6000.16386 C:\Windows\system32\ksuser.dll
              0x74db0000 0x7000 6.00.6000.16386 C:\Windows\system32\AVRT.dll
              0x74cd0000 0x27000 6.00.6000.16386 C:\Windows\system32\MMDevAPI.DLL
              0x72eb0000 0xa000 6.00.6000.16386 C:\Windows\system32\cscapi.dll
              0x764b0000 0x189000 6.00.6000.16609 C:\Windows\system32\SETUPAPI.dll
              0x75410000 0x2d000 6.00.6000.16386 C:\Windows\system32\WINTRUST.dll
              0x77b30000 0x29000 6.00.6000.16470 C:\Windows\system32\imagehlp.dll
              0x72b70000 0x9000 6.00.6000.16386 C:\Windows\system32\ExplorerFrame.dll
              0x741d0000 0x21000 6.00.6000.16386 C:\Windows\System32\audioses.dll
              0x74070000 0x66000 6.00.6000.16386 C:\Windows\System32\audioeng.dll
              0x72990000 0x30000 6.00.6000.16386 C:\Windows\system32\MLANG.dll
              0x74860000 0x9000 6.00.6000.16386 C:\Windows\system32\msacm32.drv
              0x74180000 0x15000 6.00.6000.16386 C:\Windows\system32\MSACM32.dll
              0x74170000 0x7000 6.00.6000.16386 C:\Windows\system32\midimap.dll
              0x71da0000 0x92000 6.00.6000.16386 C:\Windows\system32\stobject.dll
              0x71080000 0xb6000 6.00.6000.16386 C:\Windows\system32\BatMeter.dll
              0x75950000 0x24000 6.00.6000.16386 C:\Windows\system32\WINSTA.dll
              0x73ed0000 0x45000 2001.12.6930.16386 C:\Windows\system32\es.dll
              0x70f20000 0x30000 6.00.6000.16386 C:\Windows\System32\SndVolSSO.dll
              0x70dc0000 0x21000 6.00.6000.16386 C:\Windows\ehome\ehSSO.dll
              0x748c0000 0x9000 6.00.6000.16386 C:\Windows\system32\HID.DLL
              0x754f0000 0x63000 6.00.6000.16501 C:\Windows\system32\FirewallAPI.dll
              0x70610000 0x30b000 6.00.6000.16386 C:\Windows\System32\netshell.dll
              0x75b30000 0x19000 6.00.6000.16386 C:\Windows\System32\IPHLPAPI.DLL
              0x75af0000 0x35000 6.00.6000.16512 C:\Windows\System32\dhcpcsvc.DLL
              0x75d60000 0x2b000 6.00.6000.16615 C:\Windows\System32\DNSAPI.dll
              0x75ae0000 0x7000 6.00.6000.16386 C:\Windows\System32\WINNSI.DLL
              0x75ac0000 0x20000 6.00.6000.16512 C:\Windows\System32\dhcpcsvc6.DLL
              0x748d0000 0xf000 6.00.6000.16386 C:\Windows\System32\nlaapi.dll
              0x70a70000 0x1bf000 6.00.6000.16386 C:\Windows\system32\pnidui.dll
              0x70e00000 0x17000 6.00.6000.16386 C:\Windows\system32\QUtil.dll
              0x73a80000 0x6000 6.00.6000.16386 C:\Windows\system32\wlanutil.dll
              0x75fe0000 0x5f000 6.00.6000.16386 C:\Windows\system32\SXS.DLL
              0x6ea40000 0x8000 6.00.6000.16386 C:\Windows\System32\npmproxy.dll
              0x01c80000 0x17000 C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll
              0x752d0000 0xe000 6.00.6000.16551 C:\Windows\system32\Wlanapi.dll
              0x73af0000 0x2d000 6.00.6000.16386 C:\Windows\system32\OneX.DLL
              0x73f20000 0xd000 6.00.6000.16386 C:\Windows\system32\eappprxy.dll
              0x73ac0000 0x28000 6.00.6000.16386 C:\Windows\system32\eappcfg.dll
              0x75a20000 0x44000 6.00.6000.16386 C:\Windows\system32\bcrypt.dll
              0x72610000 0xd000 6.00.6000.16386 C:\Windows\System32\AltTab.dll
              0x72570000 0x23000 6.00.6000.16386 C:\Windows\system32\wpdshserviceobj.dll
              0x724f0000 0x40000 6.00.6000.16386 C:\Windows\System32\srchadmin.dll
              0x724b0000 0x3c000 7.00.6000.16386 C:\Windows\system32\webcheck.dll
              0x6e300000 0x4a000 6.00.6000.16386 C:\Windows\system32\ntshrui.dll
              0x6ccf0000 0x21c000 6.00.6000.16386 C:\Windows\System32\SyncCenter.dll
              0x723f0000 0x51000 6.00.6000.16386 C:\Windows\system32\imapi2.dll
              0x72600000 0xb000 6.00.6000.16386 C:\Windows\system32\mssprxy.dll
              0x72540000 0x2b000 6.00.6000.16386 C:\Windows\system32\PortableDeviceTypes.dll
              0x6e830000 0x46000 6.00.6000.16386 C:\Windows\system32\PortableDeviceApi.dll
              0x72470000 0x39000 6.00.6000.16386 C:\Windows\system32\wscntfy.dll
              0x72620000 0xb000 6.00.6000.16386 C:\Windows\system32\WSCAPI.dll
              0x71ca0000 0xf9000 6.00.6000.16386 C:\Windows\system32\bthprops.cpl
              0x6ec00000 0x12000 6.00.6000.16386 C:\Windows\System32\ntlanman.dll
              0x6f1f0000 0x8000 6.00.6000.16386 C:\Windows\System32\drprov.dll
              0x6eea0000 0xf000 6.00.6000.16386 C:\Windows\System32\davclnt.dll
              0x6dac0000 0x2c000 6.00.6000.16386 C:\Windows\System32\QAgent.dll
              0x73450000 0xb000 6.00.6000.16386 C:\Windows\system32\wbem\wbemprox.dll
              0x72d80000 0x59000 6.00.6000.16553 C:\Windows\system32\wbem\wbemcomn.dll
              0x6e750000 0x10000 6.00.6000.16386 C:\Windows\system32\wbem\wbemsvc.dll
              0x6e3b0000 0x99000 6.00.6000.16386 C:\Windows\system32\wbem\fastprox.dll
              0x75d00000 0x18000 6.00.6000.16386 C:\Windows\system32\NTDSAPI.dll
              0x01b00000 0x1b000 11.05.0000.1158 C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll
              0x748e0000 0x14000 6.00.6000.16386 C:\Windows\system32\Cabinet.dll
              0x75a70000 0x32000 6.00.6000.16386 C:\Windows\system32\ncrypt.dll
              0x75640000 0x15000 6.00.6000.16386 C:\Windows\system32\GPAPI.dll
              0x72ac0000 0x19000 6.00.6000.16386 C:\Windows\system32\cryptnet.dll
              0x74d20000 0x6000 6.00.6000.16386 C:\Windows\system32\SensApi.dll
              0x70df0000 0x6000 6.00.6000.16386 C:\Windows\system32\dciman32.dll
              0x725d0000 0x24000 11.00.6000.6324 C:\Windows\System32\wmpps.dll
              0x6bab0000 0xa2f000 11.00.6000.6344 C:\Windows\system32\wmp.dll
              0x6d290000 0x23000 6.00.6000.16513 C:\Windows\system32\MSVFW32.dll
              0x74600000 0xdc000 6.00.6000.16386 C:\Windows\system32\dbghelp.dll
              0x6b2e0000 0x7c7000 11.00.6000.6344 C:\Windows\system32\wmploc.dll
              0x701b0000 0x78000 5.07.0000.6000 C:\Windows\system32\jscript.dll
              0x6b070000 0x26e000 6.00.6000.16386 C:\Windows\system32\wpdshext.dll
              0x74730000 0x18000 6.00.6000.16513 C:\Windows\system32\AVIFIL32.dll
              0x10000000 0x77d000 7.15.0010.9748 C:\Windows\system32\nvcpl.dll
              0x76c30000 0x74000 6.00.6000.16386 C:\Windows\system32\comdlg32.dll
              0x72ca0000 0x41000 6.00.6000.16386 C:\Windows\system32\WINSPOOL.DRV
              0x03880000 0x4c000 7.15.0010.9748 C:\Windows\system32\nvapi.dll
              0x70c30000 0x126000 8.90.1101.0000 C:\Windows\System32\msxml3.dll
              0x6aa40000 0x28c000 6.00.6000.16386 C:\Windows\System32\NLSData000c.dll
              0x69320000 0x5f4000 6.00.6000.16386 C:\Windows\System32\NLSLexicons000c.dll
              0x723d0000 0x12000 6.00.6000.16386 C:\Windows\system32\thumbcache.dll
              0x03060000 0x2e000 C:\Program Files\WinRAR\rarext.dll
              0x023f0000 0x8000 1.00.0000.0000 C:\Program Files\Malwarebytes' Anti-Malware\mbamext.dll
              0x02fe0000 0x13000 7.00.0000.0011 C:\Program Files\Avira\AntiVir PersonalEdition Classic\shlext.dll
              0x7c250000 0x102000 7.10.3077.0000 C:\Program Files\Avira\AntiVir PersonalEdition Classic\MFC71U.DLL
              0x03930000 0x56000 7.10.3052.0004 C:\Program Files\Avira\AntiVir PersonalEdition Classic\MSVCR71.dll
              0x7c3a0000 0x7b000 7.10.3077.0000 C:\Program Files\Avira\AntiVir PersonalEdition Classic\MSVCP71.dll
              0x5d360000 0xf000 7.10.3077.0000 C:\Windows\system32\MFC71FRA.DLL
              0x6f4c0000 0x2e000 6.00.6000.16386 C:\Windows\system32\syncui.dll
              0x717a0000 0x15000 6.00.6000.16386 C:\Windows\system32\SYNCENG.dll
              0x71960000 0x60000 6.00.6000.16386 C:\Program Files\Common Files\microsoft shared\ink\tiptsf.dll
              0x02560000 0xe000 7.00.0007.0142 C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
              0x75280000 0x22000 1.01.1002.0000 C:\Windows\system32\xmllite.dll

              ListDLLs v2.25 - DLL lister for Win9x/NT
              Copyright (C) 1997-2004 Mark Russinovich
              Sysinternals - www.sysinternals.com

              ------------------------------------------------------------------------------
              winlogon.exe pid: 680
              Command line: winlogon.exe

              Base Size Version Path
              0x00b70000 0x4e000 6.00.6000.16386 C:\Windows\system32\winlogon.exe
              0x779b0000 0x11e000 6.00.6000.16386 C:\Windows\system32\ntdll.dll
              0x76a80000 0xd8000 6.00.6000.16386 C:\Windows\system32\kernel32.dll
              0x769c0000 0xbf000 6.00.6000.16386 C:\Windows\system32\ADVAPI32.dll
              0x77780000 0xc3000 6.00.6000.16525 C:\Windows\system32\RPCRT4.dll
              0x76920000 0x9e000 6.00.6000.16438 C:\Windows\system32\USER32.dll
              0x76270000 0x4b000 6.00.6000.16643 C:\Windows\system32\GDI32.dll
              0x763a0000 0xaa000 7.00.6000.16386 C:\Windows\system32\msvcrt.dll
              0x76100000 0x14000 6.00.6000.16386 C:\Windows\system32\Secur32.dll
              0x75950000 0x24000 6.00.6000.16386 C:\Windows\system32\WINSTA.dll
              0x76260000 0x7000 6.00.6000.16386 C:\Windows\system32\PSAPI.DLL
              0x76120000 0x1e000 6.00.6000.16386 C:\Windows\system32\USERENV.dll
              0x77b00000 0x1e000 6.00.6000.16386 C:\Windows\system32\IMM32.DLL
              0x778e0000 0xc7000 6.00.6000.16386 C:\Windows\system32\MSCTF.dll
              0x76390000 0x9000 6.00.6000.16386 C:\Windows\system32\LPK.DLL
              0x762c0000 0x7d000 1.626.6000.16386 C:\Windows\system32\USP10.dll
              0x760a0000 0x2c000 6.00.6000.16386 C:\Windows\system32\apphelp.dll
              0x755e0000 0x21000 6.00.6000.16386 C:\Windows\system32\NTMARTA.DLL
              0x76450000 0x49000 6.00.6000.16386 C:\Windows\system32\WLDAP32.dll
              0x77ad0000 0x2d000 6.00.6000.16386 C:\Windows\system32\WS2_32.dll
              0x77b20000 0x6000 6.00.6000.16386 C:\Windows\system32\NSI.dll
              0x75d40000 0x11000 6.00.6000.16386 C:\Windows\system32\SAMLIB.dll
              0x767d0000 0x144000 6.00.6000.16386 C:\Windows\system32\ole32.dll
              0x74030000 0x3e000 6.00.6000.16386 C:\Windows\system32\SHSVCS.dll
              0x75310000 0x3f000 6.00.6000.16386 C:\Windows\system32\uxtheme.dll
              0x75660000 0x38000 6.00.6000.16386 C:\Windows\system32\rsaenh.dll
              0x73f70000 0xb2000 6.00.6000.16493 C:\Windows\system32\WindowsCodecs.dll
              0x75f70000 0x6a000 6.00.6000.16386 C:\Windows\system32\NETAPI32.dll
              0x75b90000 0x39000 6.00.6000.16509 C:\Windows\system32\slc.dll
              0x75cd0000 0x14000 6.00.6000.16386 C:\Windows\system32\MPR.dll
              0x760e0000 0x16000 6.00.6000.16386 C:\Windows\system32\AUTHZ.dll

              Le volume dans le lecteur C s'appelle Vista
              Le numéro de série du volume est 3E37-91A8

              Répertoire de C:\Windows\system32

              02/11/2006 11:45 7 680 csrss.exe
              1 fichier(s) 7 680 octets
              0 Rép(s) 56 625 868 800 octets libres

              Contenu de Downloaded Program Files
              Le volume dans le lecteur C s'appelle Vista
              Le numéro de série du volume est 3E37-91A8

              Répertoire de C:\Windows\Downloaded Program Files

              15/06/2008 00:47 <REP> .
              15/06/2008 00:47 <REP> ..
              09/01/2008 15:01 32 bdcore.dll
              09/01/2008 15:01 118 784 bdupd.dll
              18/09/2006 23:26 65 desktop.ini
              24/03/2008 19:33 1 527 056 FP_AX_CAB_INSTALLER.exe
              09/01/2008 15:01 53 248 ipsupd.dll
              26/02/2008 15:42 7 724 lang.ini
              09/01/2008 15:01 32 libfn.dll
              21/01/2008 17:43 130 live.ini
              07/02/2008 14:06 1 248 oscan8.inf
              26/02/2008 15:59 487 424 oscan82.ocx
              09/01/2008 15:01 6 828 scanoptions.tsi
              10/04/2008 10:21 185 SETUP.INF
              24/03/2008 19:18 247 swflash.inf
              13 fichier(s) 2 203 003 octets

              Total des fichiers listés :
              13 fichier(s) 2 203 003 octets
              2 Rép(s) 56 625 864 704 octets libres

              Recherche de rootkit! (Merci S!Ri)

              Recherche d'infections connues

              Export des clefs sensibles..

              Liste des fichiers en exception sur le pare-feu XP SP2

              Export de la clef SharedTaskScheduler

              [SharedTaskScheduler]

              exports des policies
              REGEDIT4

              [System]
              "ConsentPromptBehaviorAdmin"=dword:00000002
              "ConsentPromptBehaviorUser"=dword:00000001
              "EnableInstallerDetection"=dword:00000001
              "EnableLUA"=dword:00000000
              "EnableSecureUIAPaths"=dword:00000001
              "EnableVirtualization"=dword:00000001
              "PromptOnSecureDesktop"=dword:00000001
              "ValidateAdminCodeSignatures"=dword:00000000
              "dontdisplaylastusername"=dword:00000000
              "legalnoticecaption"=""
              "legalnoticetext"=""
              "scforceoption"=dword:00000000
              "shutdownwithoutlogon"=dword:00000001
              "undockwithoutlogon"=dword:00000001
              "FilterAdministratorToken"=dword:00000000

              [System\UIPI]

              [System\UIPI\Clipboard]

              [System\UIPI\Clipboard\ExceptionFormats]
              "CF_TEXT"=dword:00000001
              "CF_BITMAP"=dword:00000002
              "CF_OEMTEXT"=dword:00000007
              "CF_DIB"=dword:00000008
              "CF_PALETTE"=dword:00000009
              "CF_UNICODETEXT"=dword:0000000d
              "CF_DIBV5"=dword:00000011

              Export des clefs sensibles..
              Rechercher adresses sensibles dans le fichier HOSTS...
              catchme 0.3.1351 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
              Rootkit scan 2008-06-17 22:41:50
              Windows 6.0.6000 NTFS

              scanning hidden services & system hive ...

              scanning hidden registry entries ...

              scanning hidden files ...

              scan completed successfully
              hidden services: 0
              hidden files: 0

              KProcCheck Version 0.2-beta1 Proof-of-Concept by SIG^2 (www.security.org.sg)

              Sorry, this version supports only Win2K/XP

              KProcCheck Version 0.2-beta1 Proof-of-Concept by SIG^2 (www.security.org.sg)

              Sorry, this version supports only Win2K/XP

              Le volume dans le lecteur C s'appelle Vista
              Le numéro de série du volume est 3E37-91A8

              Répertoire de C:\Program Files

              17/06/2008 11:35 <REP> .
              17/06/2008 11:35 <REP> ..
              20/12/2006 14:26 <REP> Adobe
              16/05/2008 19:09 <REP> Avira
              12/06/2008 15:14 <REP> CCleaner
              30/05/2008 12:59 <REP> Circle Developement
              17/06/2008 11:35 <REP> Common Files
              20/12/2006 10:13 <REP> CONEXANT
              14/06/2008 20:37 <REP> Google
              15/06/2008 00:44 <REP> happynote
              04/06/2008 20:27 <REP> HP
              12/06/2008 09:19 <REP> Internet Explorer
              20/12/2006 13:18 <REP> InterVideo
              29/05/2008 21:16 <REP> Java
              13/05/2008 16:59 <REP> LimeWire
              17/06/2008 11:35 <REP> Logitech
              14/06/2008 23:56 <REP> Malwarebytes' Anti-Malware
              13/06/2008 10:19 <REP> Messenger Plus! Live
              14/05/2008 09:27 <REP> Microsoft CAPICOM 2.1.0.2
              12/05/2008 20:42 <REP> Microsoft Games
              02/11/2006 14:42 <REP> Movie Maker
              02/11/2006 14:37 <REP> MSBuild
              02/11/2006 14:37 <REP> MSN
              14/05/2008 08:50 <REP> MSXML 4.0
              20/12/2006 09:54 <REP> My Company Name
              14/06/2008 21:50 <REP> Navilog1
              15/06/2008 20:18 <REP> Neuf
              26/05/2008 20:22 <REP> OneStopSoft.com
              14/06/2008 22:32 <REP> OpenOffice.org 2.4
              15/06/2008 00:23 <REP> PhotoScape
              02/11/2006 14:37 <REP> Reference Assemblies
              16/05/2008 22:40 <REP> Satsuki Decoder Pack
              14/05/2008 16:02 <REP> Sibelius Software
              20/12/2006 10:08 <REP> Synaptics
              20/12/2006 16:01 <REP> TOSHIBA
              14/06/2008 20:50 <REP> Trend Micro
              08/06/2008 20:54 <REP> Trymedia
              20/12/2006 13:15 <REP> Ulead Systems
              14/05/2008 09:58 <REP> Windows Calendar
              02/11/2006 14:42 <REP> Windows Collaboration
              14/05/2008 09:58 <REP> Windows Defender
              02/11/2006 14:42 <REP> Windows Journal
              13/05/2008 17:02 <REP> Windows Live
              12/06/2008 09:19 <REP> Windows Mail
              20/12/2006 13:18 <REP> Windows Media Components
              14/05/2008 09:58 <REP> Windows Media Player
              12/05/2008 20:36 <REP> Windows NT
              02/11/2006 14:42 <REP> Windows Photo Gallery
              14/05/2008 09:58 <REP> Windows Sidebar
              31/05/2008 22:04 <REP> WinRAR
              0 fichier(s) 0 octets
              50 Rép(s) 56 611 074 048 octets libres
              Le volume dans le lecteur C s'appelle Vista
              Le numéro de série du volume est 3E37-91A8

              Répertoire de C:\Program Files\fichiers communs

              Le volume dans le lecteur C s'appelle Vista
              Le numéro de série du volume est 3E37-91A8

              Répertoire de C:\Program Files\common files

              17/06/2008 11:35 <REP> .
              17/06/2008 11:35 <REP> ..
              20/12/2006 14:27 <REP> Adobe
              15/06/2008 00:49 <REP> BitDefender
              04/06/2008 20:27 <REP> HP
              20/12/2006 13:18 <REP> InstallShield
              20/12/2006 09:52 <REP> Java
              17/06/2008 11:43 <REP> LogiShrd
              17/06/2008 11:38 <REP> Logitech
              12/05/2008 20:51 <REP> Microsoft Games
              13/05/2008 17:05 <REP> microsoft shared
              02/11/2006 13:18 <REP> Services
              02/11/2006 13:18 <REP> SpeechEngines
              13/06/2008 22:15 <REP> Symantec Shared
              14/05/2008 09:58 <REP> System
              20/12/2006 13:18 <REP> Ulead Systems
              0 fichier(s) 0 octets
              16 Rép(s) 56 611 074 048 octets libres

              ****** Fin du rapport DiagHelp
              Veuillez svp envoyer le fichier C:\upload_moi_PC-de-Sophie.tar.gz a l'adresse http://upload.malekal.com
              1. Contributeur
                Quand tu clique droit sur le dossier tu as un e possibilité de décompresser le dossier ?
                regarde bien ;-)
                1. Contributeur
                  ramage ??? pour maitre corbeau surement :-))

                  ok
                  pour le reste

                  on vérifie une dernière chose avec un nouveau scan

                  Télécharge DiagHelp.zip sur ton bureau http://www.malekal.com/download/DiagHelp.zip
                  ==> Ne double-clic pas dessus !! Fais un clic droit sur le fichier et extraire tout
                  ==> Un nouveau dossier chercher va être créé DiagHelp
                  ==> Ouvre le et double-clic sur go.cmd (le .cmd peut ne pas apparaître)
                  ==> Une fenêtre va s'ouvrir, choisis l'option 1
                  ==> L'analyse va commencer, ceci peut durer quelques minutes, laisse faire et appuie sur une touche quand on te le demande
                  ==> Copie/colle le contenu du bloc-note qui s'ouvre, pour cela :
                  ==> Dans le bloc-note, cliquez sur le menu Edition / Selectionner tout
                  ==> A nouveau menu Edition / copier
                  ==> Dans un nouveau message ici, faire un clic droit / coller
                  @+
                  1. bah la c'est vrai que je n'est pratiquement plus de pub, ni de ramage (j'sais pas si sa se dit lol )
                    donc voila ^^
                    1. Contributeur
                      Oui c'est vrai excuse

                      as tu passer aft cleaner
                      et as tu encore des soucis ?
                      @+
                      1. Sa fait au moins 3 fois que je fais le scan en ligne de Bitdefender il me donne plus le rapport =/
                        1. Contributeur
                          ok pour la suite

                          Télécharge ATF Cleaner par Atribune.
                          http://www.atribune.org/ccount/click.php?id=1

                          Double-clique ATF-Cleaner.exe afin de lancer le programme.
                          Sous l'onglet Main, choisis : Select All
                          Clique sur le bouton Empty Selected

                          Si tu utilises le navigateur Firefox :

                          Clique Firefox au haut et choisis : Select All
                          Clique le bouton Empty Selected
                          NOTE : Si tu veux conserver tes mots de passe sauvegardés, clique No à l'invite.

                          Si tu utilises le navigateur Opera :

                          Clique Opera au haut et choisis : Select All
                          Clique le bouton Empty Selected
                          NOTE : Si tu veux conserver tes mots de passe sauvegardés, clique No à l'invite.

                          Clique Exit, du menu prinicipal, afin de fermer le programme.

                          ensuite
                          fait un scan en ligne

                          avec bitdefender et colle le rapport

                          https://www.bitdefender.com/toolbox/

                          Scan à faire sous Internet Explorer

                          un tuto
                          http://pageperso.aol.fr/rginformatique/mapage/defender.htm

                          ensuite un nouveau rapport hijack stp
                          @+
                          1. C:\ProgramData\idle enc enc.oyyffvr moved successfully.
                            C:\ProgramData\Eggs Platform Seek.qoyin moved successfully.
                            < EmptyTemp >
                            File delete failed. C:\Users\Sophie\AppData\Local\Temp\~DFB25E.tmp scheduled to be deleted on reboot.
                            File delete failed. C:\Users\Sophie\AppData\Local\Temp\~DFB27A.tmp scheduled to be deleted on reboot.
                            File delete failed. C:\Users\Sophie\AppData\Local\Temp\~DFD331.tmp scheduled to be deleted on reboot.
                            File delete failed. C:\Users\Sophie\AppData\Local\Temp\~DFD350.tmp scheduled to be deleted on reboot.
                            File delete failed. C:\Users\Sophie\AppData\Local\Temp\~DFE301.tmp scheduled to be deleted on reboot.
                            File delete failed. C:\Users\Sophie\AppData\Local\Temp\~DFE312.tmp scheduled to be deleted on reboot.
                            File delete failed. C:\Users\Sophie\AppData\Local\Temp\~DFE41E.tmp scheduled to be deleted on reboot.
                            File delete failed. C:\Users\Sophie\AppData\Local\Temp\~DFE425.tmp scheduled to be deleted on reboot.
                            File delete failed. C:\Users\Sophie\AppData\Local\Temp\~DFEEA9.tmp scheduled to be deleted on reboot.
                            File delete failed. C:\Users\Sophie\AppData\Local\Temp\~DFEEB2.tmp scheduled to be deleted on reboot.
                            Temp folders emptied.
                            IE temp folders emptied.

                            OTMoveIt2 by OldTimer - Version 1.0.4.2 log created on 06162008_231357

                            Voilaaa
                            1. Contributeur
                              Bonsoir

                              Connais tu ces fichiers
                              C:\ProgramData\idle enc enc.oyyffvr
                              C:\ProgramData\Eggs Platform Seek.qoyin

                              si non

                              Relance hijack et clique sur "Do a system scan only"
                              Ensuite recherche ces lignes et coches les cases

                              O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                              O4 - HKCU\..\Run: [WindowReadme] "C:\ProgramData\idle enc enc.oyyffvr"
                              O4 - HKCU\..\Run: [ROAD ITCH AMOK PING] "C:\ProgramData\Eggs Platform Seek.qoyin"
                              O9 - Extra button: eBay - {C08CAF1D-C0A3-40D5-9970-06D067EAC017} - http://www.webtip.ch/cgi-bin/toshiba/tracker_url.pl?FR (file missing)

                              Ensuite clique sur "Fix checked"


                              Ensuite

                              Télécharge OTMoveIt (de OldTimer) sur ton Bureau.
                              http://download.bleepingcomputer.com/oldtimer/OTMoveIt2.exe
                              clic double sur OTMoveIt.exe pour le lancer.
                              copie la liste qui se trouve en citation ci-dessous,
                              et colle-la dans le cadre de gauche de OTMoveIt :
                              Paste List of Files/Folders to be moved.

                              C:\ProgramData\idle enc enc.oyyffvr
                              C:\ProgramData\Eggs Platform Seek.qoyin
                              EmptyTemp

                              clique sur MoveIt! pour lancer la suppression.
                              le résultat apparaîtra dans le cadre Results.
                              clique sur Exit pour fermer.
                              poste le rapport situé dans C:\_OTMoveIt\MovedFiles.

                              il te sera peut-être demandé de faire redémarrer le PC pour achever la suppression.

                              @+
                              1. voici le rapport de Bitdefender (désolée d'avoir été aussi longue mais j'ai eu un problemme d'internet --")

                                BitDefender Online Scanner - Real Time Virus Report

                                Generated at: Mon, Jun 16, 2008 - 14:28:38

                                --------------------------------------------------------------------------------

                                Scan Info

                                Scanned Files
                                256745

                                Infected Files
                                0

                                Virus Detected

                                No virus found.

                                --------------------------------------------------------------------------------

                                This summary of the scan process will be used by the BitDefender Antivirus Lab to create agregate statistics about virus activity around the world.

                                Et le raport Hijack :

                                Logfile of Trend Micro HijackThis v2.0.2
                                Scan saved at 14:30:14, on 16/06/2008
                                Platform: Windows Vista (WinNT 6.00.1904)
                                MSIE: Internet Explorer v7.00 (7.00.6000.16681)
                                Boot mode: Normal

                                Running processes:
                                C:\Windows\system32\Dwm.exe
                                C:\Windows\Explorer.EXE
                                C:\Windows\system32\taskeng.exe
                                C:\Program Files\Windows Defender\MSASCui.exe
                                C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
                                C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe
                                C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
                                C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                                C:\Program Files\TOSHIBA\Utilities\VolControl.exe
                                C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
                                C:\Program Files\TOSHIBA\Toshiba Online Product Information\TOPI.exe
                                C:\Program Files\TOSHIBA\Registration\ToshibaRegistration.exe
                                C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                                C:\Program Files\Common Files\Logitech\LComMgr\Communications_Helper.exe
                                C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe
                                C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
                                C:\Program Files\Windows Sidebar\sidebar.exe
                                C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
                                C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
                                C:\Program Files\Windows Media Player\wmpnscfg.exe
                                C:\Windows\System32\rundll32.exe
                                C:\Program Files\Internet Explorer\iexplore.exe
                                C:\Program Files\Synaptics\SynTP\SynToshiba.exe
                                C:\Program Files\Internet Explorer\iexplore.exe
                                C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe
                                C:\Windows\system32\wbem\unsecapp.exe
                                C:\Program Files\Internet Explorer\iexplore.exe
                                C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
                                C:\Windows\system32\conime.exe
                                C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                                C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                                C:\Program Files\Windows Media Player\wmplayer.exe
                                C:\Program Files\Internet Explorer\iexplore.exe
                                C:\Windows\System32\Adobe\SHOCKW~1\SWHELP~1.EXE
                                C:\Windows\system32\SearchFilterHost.exe
                                C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://actus.sfr.fr
                                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://actus.sfr.fr
                                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://actus.sfr.fr
                                R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                                R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = https://actus.sfr.fr
                                R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                                R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                                O1 - Hosts: ::1 localhost
                                O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                                O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                                O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                                O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                                O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
                                O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
                                O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                                O4 - HKLM\..\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
                                O4 - HKLM\..\Run: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe
                                O4 - HKLM\..\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
                                O4 - HKLM\..\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
                                O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                                O4 - HKLM\..\Run: [TOSHIBA Volume Indicator] "C:\Program Files\Toshiba\Utilities\VolControl.exe"
                                O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
                                O4 - HKLM\..\Run: [topi] C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe -startup
                                O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
                                O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
                                O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
                                O4 - HKLM\..\Run: [Toshiba Registration] C:\Program Files\Toshiba\Registration\ToshibaRegistration.exe
                                O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                                O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\Logitech\LComMgr\Communications_Helper.exe"
                                O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam10\QuickCam10.exe" /hide
                                O4 - HKLM\..\Run: [LVCOMSX] "C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe"
                                O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
                                O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                                O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
                                O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                                O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
                                O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                                O4 - HKCU\..\Run: [WindowReadme] "C:\ProgramData\idle enc enc.oyyffvr"
                                O4 - HKCU\..\Run: [ROAD ITCH AMOK PING] "C:\ProgramData\Eggs Platform Seek.qoyin"
                                O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                                O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                                O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                                O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                                O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                                O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
                                O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
                                O9 - Extra button: eBay - {C08CAF1D-C0A3-40D5-9970-06D067EAC017} - http://www.webtip.ch/cgi-bin/toshiba/tracker_url.pl?FR (file missing)
                                O13 - Gopher Prefix:
                                O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
                                O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/win/ActiveXPlugin.cab
                                O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                                O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                                O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                                O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
                                O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
                                O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
                                O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
                                O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\Logitech\SrvLnch\SrvLnch.exe
                                O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe
                                O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
                                O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
                                O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
                                O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
                                1. Snif m'abandonne pas :(
                              2. Le Scan avec Bitdefender n'a pas l'air pressé de se terminé donc desolée si je metrais d temps a t'envoyée le rapport
                                Mon ordi rame beaucoup moins deja mais j'ai toujours des pubs ...
                                J'te remercie de m'aidée je suis une nulle en informatique .
                                1. Contributeur
                                  Bon et bien tout ça et nickel

                                  pour vérif

                                  fait un scan en ligne

                                  avec bitdefender et colle le rapport

                                  https://www.bitdefender.com/toolbox/

                                  Scan à faire sous Internet Explorer

                                  un tuto
                                  http://pageperso.aol.fr/rginformatique/mapage/defender.htm

                                  ensuite un nouveau rapport hijack stp
                                  @+
                                  • 1
                                  • 2