Virus alerte! + plus de visu surC:

Résolu
Bonjour,
J'ai un vilain "VIRUS ALRTE!" sur mon ordi. Mais plus grave, je ne vois plus C: sous l'explorer ou mon poste de travail.... besoin d'aide la!!!
Mes icones partent, internet c'est n importe quoi et mon ordi est devenu méga lent!!!!

J'ai essayer pas mal de scan mais sans succès!
Merci a ceux qui me reponderons.
Voici un rapport smitfraud :

SmitFraudFix v2.325

Rapport fait à 23:10:05,63, 16/06/2008
Executé à partir de C:\Documents and Settings\mgrosjean\Bureau\SmitfraudFix
OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
Le type du système de fichiers est NTFS
Fix executé en mode normal

»»»»»»»»»»»»»»»»»»»»»»»» Process

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\IFXSPMGT.exe
C:\WINDOWS\system32\IFXTCS.exe
C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\Program Files\ProtectTools\Embedded Security Software\PSDsrvc.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\HPQ\IAM\bin\asghost.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\WINDOWS\system32\mqsvc.exe
C:\Program Files\ProtectTools\Embedded Security Software\PSDrt.exe
C:\WINDOWS\system32\mqtgsvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
C:\WINDOWS\SMINST\Scheduler.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\WIDCOMM\Logiciel Bluetooth\BTTray.exe
C:\PROGRA~1\WIDCOMM\LOGICI~1\BTSTAC~1.EXE
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\Program Files\AVG\AVG8\avgui.exe
C:\Program Files\AVG\AVG8\avgscanx.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\AVG\AVG8\aAvgApi.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\WINDOWS\system32\cmd.exe

»»»»»»»»»»»»»»»»»»»»»»»» hosts

»»»»»»»»»»»»»»»»»»»»»»»» C:\

»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles

»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\mgrosjean

»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\mgrosjean\Application Data

»»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\MGROSJ~1\Favoris

C:\DOCUME~1\MGROSJ~1\Favoris\Error Cleaner.url PRESENT !
C:\DOCUME~1\MGROSJ~1\Favoris\Privacy Protector.url PRESENT !
C:\DOCUME~1\MGROSJ~1\Favoris\Spyware?Malware Protection.url PRESENT !

»»»»»»»»»»»»»»»»»»»»»»»» Bureau

»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

»»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

»»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

»»»»»»»»»»»»»»»»»»»»»»»» IEDFix
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

IEDFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri

»»»»»»»»»»»»»»»»»»»»»»»» VACFix
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

VACFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri

»»»»»»»»»»»»»»»»»»»»»»»» 404Fix
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

404Fix
Credits: Malware Analysis & Diagnostic
Code: S!Ri

»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="avgrsstx.dll"
"LoadAppInit_DLLs"=dword:00000001

»»»»»»»»»»»»»»»»»»»»»»»» Winlogon
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
"System"=""

»»»»»»»»»»»»»»»»»»»»»»»» Rustock

»»»»»»»»»»»»»»»»»»»»»»»» DNS

Description: Broadcom NetLink (TM) Gigabit Ethernet - Miniport d'ordonnancement de paquets
DNS Server Search Order: 10.153.10.100

Description: Broadcom 802.11a/b/g WLAN - Miniport d'ordonnancement de paquets
DNS Server Search Order: 212.27.54.252
DNS Server Search Order: 212.27.53.252

HKLM\SYSTEM\CCS\Services\Tcpip\..\{3F014187-38EE-429F-85F7-01DBE368458F}: NameServer=10.153.10.100
HKLM\SYSTEM\CCS\Services\Tcpip\..\{95F136AB-7AE2-4A85-B0B7-F4965744C584}: NameServer=10.153.10.100
HKLM\SYSTEM\CCS\Services\Tcpip\..\{F7436E79-C546-4435-8B31-EE97803C436E}: DhcpNameServer=212.27.54.252 212.27.53.252
HKLM\SYSTEM\CS1\Services\Tcpip\..\{3F014187-38EE-429F-85F7-01DBE368458F}: NameServer=10.153.10.100
HKLM\SYSTEM\CS1\Services\Tcpip\..\{95F136AB-7AE2-4A85-B0B7-F4965744C584}: NameServer=10.153.10.100
HKLM\SYSTEM\CS1\Services\Tcpip\..\{F7436E79-C546-4435-8B31-EE97803C436E}: DhcpNameServer=212.27.54.252 212.27.53.252
HKLM\SYSTEM\CS2\Services\Tcpip\..\{3F014187-38EE-429F-85F7-01DBE368458F}: NameServer=10.153.10.100
HKLM\SYSTEM\CS2\Services\Tcpip\..\{95F136AB-7AE2-4A85-B0B7-F4965744C584}: NameServer=10.153.10.100
HKLM\SYSTEM\CS2\Services\Tcpip\..\{F7436E79-C546-4435-8B31-EE97803C436E}: DhcpNameServer=212.27.54.252 212.27.53.252
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=212.27.54.252 212.27.53.252
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=212.27.54.252 212.27.53.252
HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=212.27.54.252 212.27.53.252

»»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

»»»»»»»»»»»»»»»»»»»»»»»» Fin
Configuration: Windows XP
Internet Explorer 7.0

39 réponses

Résumé de la discussion

Infection détectée sous le nom 'VIRUS ALRTE!' provoquant l'absence de C: dans l'Explorateur, la disparition d'icônes, une navigation internet perturbée et une lenteur générale du système. Des conseils proposent démarrer en mode sans échec, relancer SmitFraudFix et sauvegarder le rapport, puis redémarrer en mode normal pour partager le nouveau résultat et poursuivre le diagnostic. D'autres proposent HijackThis pour générer des rapports détaillés et détecter des entrées de registre modifiées (par exemple AppInit_DLLs ou Winlogon), avec une étape de nettoyage guidée par les logs. En complément, la discussion mentionne des éléments comme des fichiers et paramètres supprimés ou déplacés (fichiers SmitFraudfix, OtMoveIt, ComboFix) et l'examen de rapports pour évaluer l'étendue de l'infection.

Bobot (l’IA à votre service)
  1. Salut,

    # Démarre en mode sans échec :
    Pour cela, tu tapotes la touche F8 dès le début de l’allumage du pc sans t’arrêter
    Une fenêtre va s’ouvrir tu te déplaces avec les flèches du clavier sur démarrer en mode sans échec puis tape entrée.
    Une fois sur le bureau s’il n’y a pas toutes les couleurs et autres c’est normal !
    (Si F8 ne marche pas utilise la touche F5).
    ----------------------------------------------------------------------------
    # Relance le programme Smitfraud :
    Cette fois choisit l’option 2, répond oui a tous ;
    Sauvegarde le rapport, Redémarre en mode normal, copie/colle le rapport sauvegardé sur le forum
    1. Et voila ...

      SmitFraudFix v2.325

      Rapport fait à 0:15:40,08, 17/06/2008
      Executé à partir de C:\Documents and Settings\mgrosjean\Bureau\SmitfraudFix
      OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
      Le type du système de fichiers est NTFS
      Fix executé en mode normal

      »»»»»»»»»»»»»»»»»»»»»»»» Process

      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\Ati2evxx.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
      C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\WINDOWS\System32\svchost.exe
      C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
      C:\WINDOWS\system32\Ati2evxx.exe
      C:\Program Files\HPQ\IAM\bin\asghost.exe
      C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe
      C:\Program Files\Symantec AntiVirus\DefWatch.exe
      C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\IFXSPMGT.exe
      C:\WINDOWS\system32\IFXTCS.exe
      C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
      C:\Program Files\ProtectTools\Embedded Security Software\PSDsrvc.EXE
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Symantec AntiVirus\Rtvscan.exe
      C:\WINDOWS\system32\MsPMSPSv.exe
      C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
      C:\WINDOWS\system32\mqsvc.exe
      C:\PROGRA~1\AVG\AVG8\avgrsx.exe
      C:\WINDOWS\system32\mqtgsvc.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\ProtectTools\Embedded Security Software\PSDrt.exe
      C:\Program Files\Analog Devices\Core\smax4pnp.exe
      C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
      C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
      C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
      C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
      C:\WINDOWS\SMINST\Scheduler.exe
      C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
      C:\PROGRA~1\SYMANT~1\VPTray.exe
      C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe
      C:\Program Files\iTunes\iTunesHelper.exe
      C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
      C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
      C:\WINDOWS\system32\rundll32.exe
      C:\Program Files\iPod\bin\iPodService.exe
      C:\PROGRA~1\AVG\AVG8\avgtray.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\WIDCOMM\Logiciel Bluetooth\BTTray.exe
      C:\Program Files\Adobe\Acrobat 7.0\Acrobat\Acrobat_sl.exe
      C:\PROGRA~1\WIDCOMM\LOGICI~1\BTSTAC~1.EXE
      C:\Program Files\Google\Google Updater\GoogleUpdater.exe
      C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\PROGRA~1\AVG\AVG8\aAvgApi.exe
      C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
      C:\WINDOWS\system32\cmd.exe
      C:\WINDOWS\system32\wbem\wmiapsrv.exe
      C:\Program Files\ATI Technologies\ATI.ACE\cli.exe

      »»»»»»»»»»»»»»»»»»»»»»»» hosts

      »»»»»»»»»»»»»»»»»»»»»»»» C:\

      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\mgrosjean

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\mgrosjean\Application Data

      »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

      »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\MGROSJ~1\Favoris

      C:\DOCUME~1\MGROSJ~1\Favoris\Error Cleaner.url PRESENT !
      C:\DOCUME~1\MGROSJ~1\Favoris\Privacy Protector.url PRESENT !
      C:\DOCUME~1\MGROSJ~1\Favoris\Spyware?Malware Protection.url PRESENT !

      »»»»»»»»»»»»»»»»»»»»»»»» Bureau

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

      »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

      »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

      »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      IEDFix
      Credits: Malware Analysis & Diagnostic
      Code: S!Ri

      »»»»»»»»»»»»»»»»»»»»»»»» VACFix
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      VACFix
      Credits: Malware Analysis & Diagnostic
      Code: S!Ri

      »»»»»»»»»»»»»»»»»»»»»»»» 404Fix
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      404Fix
      Credits: Malware Analysis & Diagnostic
      Code: S!Ri

      »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      SrchSTS.exe by S!Ri
      Search SharedTaskScheduler's .dll

      »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
      "AppInit_DLLs"="avgrsstx.dll"
      "LoadAppInit_DLLs"=dword:00000001

      »»»»»»»»»»»»»»»»»»»»»»»» Winlogon
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
      "Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
      "System"=""

      »»»»»»»»»»»»»»»»»»»»»»»» Rustock

      »»»»»»»»»»»»»»»»»»»»»»»» DNS

      Description: Broadcom NetLink (TM) Gigabit Ethernet - Miniport d'ordonnancement de paquets
      DNS Server Search Order: 10.153.10.100

      Description: Broadcom 802.11a/b/g WLAN - Miniport d'ordonnancement de paquets
      DNS Server Search Order: 212.27.54.252
      DNS Server Search Order: 212.27.53.252

      HKLM\SYSTEM\CCS\Services\Tcpip\..\{3F014187-38EE-429F-85F7-01DBE368458F}: NameServer=10.153.10.100
      HKLM\SYSTEM\CCS\Services\Tcpip\..\{95F136AB-7AE2-4A85-B0B7-F4965744C584}: NameServer=10.153.10.100
      HKLM\SYSTEM\CCS\Services\Tcpip\..\{F7436E79-C546-4435-8B31-EE97803C436E}: DhcpNameServer=212.27.54.252 212.27.53.252
      HKLM\SYSTEM\CS1\Services\Tcpip\..\{3F014187-38EE-429F-85F7-01DBE368458F}: NameServer=10.153.10.100
      HKLM\SYSTEM\CS1\Services\Tcpip\..\{95F136AB-7AE2-4A85-B0B7-F4965744C584}: NameServer=10.153.10.100
      HKLM\SYSTEM\CS1\Services\Tcpip\..\{F7436E79-C546-4435-8B31-EE97803C436E}: DhcpNameServer=212.27.54.252 212.27.53.252
      HKLM\SYSTEM\CS2\Services\Tcpip\..\{3F014187-38EE-429F-85F7-01DBE368458F}: NameServer=10.153.10.100
      HKLM\SYSTEM\CS2\Services\Tcpip\..\{95F136AB-7AE2-4A85-B0B7-F4965744C584}: NameServer=10.153.10.100
      HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=212.27.54.252 212.27.53.252
      HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=212.27.54.252 212.27.53.252

      »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

      »»»»»»»»»»»»»»»»»»»»»»»» Fin
  2. heu tu peux pas hi hi t es pas inscrit t punis lol

    ciao @++
    1. Ha ok

      bha super merci en tout cas!!!!

      et une derniere chose, on fait comment pour mettre le sujet en probleme résolu?
      1. cool

        Voila c est propre !!

        si tu n as pas d autres soucis change le statut du sujet en resolu stp

        1. oki

          pour demain :

          -> Télécharge Ccleaner (n'installe pas la barre d'outil Yahoo):

          https://www.01net.com/telecharger/windows/Utilitaire/nettoyeurs_et_installeurs/fiches/32599.html

          -> L´installer.

          -> Une fois installé et lancé :

          Dans la colonne de gauche, click sur :

          ->"registre" :

          Coches toutes les cases sous"l´integrité du registre", puis click en bas sur "chercher des erreurs" une fois terminé, clic sur "reparer les erreurs", tu auras un message pour sauvegarder ta base de registre, tu click "oui" puis tu recommence jusqu'à ce qu'il ne trouve plus rien.

          ps : les sauvegardes que tu auras faites, pourront etre supprimées ulterieurement si tout va bien.

          ->"nettoyeur"

          quitte ton navigateur avant de le lancer, dans les propriétés du nettoyeur de l´onglet "windows" et "applications"décoche la derniere case (Avancé si elle est cochée) puis click sur "lancer le nettoyage" qunand il aura terminé le scan click en bas a droite sur "lancer le nettoyage" et accepte par oui.

          -> Tutoriel en image :

          https://www.vulgarisation-informatique.com/nettoyer-windows-ccleaner.php

          -> Pour ceux qui voudraient aller plus loin en compagnie de jesses (fonctions avancés) :

          http://perso.orange.fr/jesses/Docs/Logiciels/CCleaner.htm

          ensuite :

          telecharge et instal regcleaner:

          http://www.01net.com/windows/Utilitaire/nettoyeurs_et_installeurs/fiches/4894.html

          tutorial :

          https://forums.cnetfrance.fr

          http://www.softastuces.com/tuto/maint/regcleaner/

          et pour finir :

          * pour supprimer les outils/fix utilisés :

          Télécharge ToolsCleaner sur ton bureau.
          -->
          http://pagesperso-orange.fr/AceRothstein/ToolsCleaner2.exe
          http://a-rothstein.changelog.fr/TC/ToolsCleaner2.exe

          # Clique sur Recherche et laisse le scan agir ...
          # Clique sur Suppression pour finaliser.
          # Tu peux, si tu le souhaites, te servir des Options facultatives.
          # Clique sur Quitter pour obtenir le rapport.
          # Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\).

          1. -->- Recherche:

            C:\Qoobox: trouvé !
            C:\_OtMoveIt: trouvé !
            C:\Documents and Settings\mgrosjean\Bureau\OtMoveIt2.exe: trouvé !
            C:\Documents and Settings\mgrosjean\Bureau\ComboFix.exe: trouvé !
            C:\Documents and Settings\mgrosjean\Bureau\HijackThis.exe: trouvé !
            C:\Documents and Settings\mgrosjean\Bureau\SmitFraudfix: trouvé !

            ---------------------------------
            -->- Suppression:

            C:\Documents and Settings\mgrosjean\Bureau\OtMoveIt2.exe: supprimé !
            C:\Documents and Settings\mgrosjean\Bureau\ComboFix.exe: supprimé !
            C:\Documents and Settings\mgrosjean\Bureau\HijackThis.exe: supprimé !
            C:\Qoobox: supprimé !
            C:\_OtMoveIt: supprimé !
            C:\Documents and Settings\mgrosjean\Bureau\SmitFraudfix: supprimé !

            Voila!
        2. et hop

          File/Folder C:\Documents and Settings\All Users\Application Data\Adsl Software Limited\WinSpywareProtect\WinSpywareProtect.exe not found.
          Folder C:\Documents and Settings\All Users\Application Data\Adsl Software Limited\ not found.

          OTMoveIt2 by OldTimer - Version 1.0.4.2 log created on 06182008_000502

          et

          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 00:06, on 2008-06-18
          Platform: Windows XP SP2 (WinNT 5.01.2600)
          MSIE: Internet Explorer v7.00 (7.00.6000.16674)
          Boot mode: Normal

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\Ati2evxx.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
          C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
          C:\WINDOWS\system32\spoolsv.exe
          C:\WINDOWS\system32\Ati2evxx.exe
          C:\WINDOWS\System32\svchost.exe
          C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
          C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe
          C:\Program Files\Symantec AntiVirus\DefWatch.exe
          C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\IFXSPMGT.exe
          C:\WINDOWS\system32\IFXTCS.exe
          C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
          C:\Program Files\ProtectTools\Embedded Security Software\PSDsrvc.EXE
          C:\WINDOWS\system32\svchost.exe
          C:\Program Files\Symantec AntiVirus\Rtvscan.exe
          C:\WINDOWS\system32\MsPMSPSv.exe
          C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
          C:\WINDOWS\system32\mqsvc.exe
          C:\WINDOWS\system32\mqtgsvc.exe
          C:\PROGRA~1\AVG\AVG8\avgrsx.exe
          C:\Program Files\Analog Devices\Core\smax4pnp.exe
          C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
          C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
          C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
          C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
          C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
          C:\WINDOWS\SMINST\Scheduler.exe
          C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
          C:\PROGRA~1\SYMANT~1\VPTray.exe
          C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe
          C:\Program Files\iTunes\iTunesHelper.exe
          C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
          C:\Program Files\iPod\bin\iPodService.exe
          C:\PROGRA~1\AVG\AVG8\avgtray.exe
          C:\WINDOWS\system32\ctfmon.exe
          C:\Program Files\WIDCOMM\Logiciel Bluetooth\BTTray.exe
          C:\Program Files\Google\Google Updater\GoogleUpdater.exe
          C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
          C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
          C:\WINDOWS\explorer.exe
          C:\PROGRA~1\WIDCOMM\LOGICI~1\BTSTAC~1.EXE
          C:\Program Files\Internet Explorer\iexplore.exe
          C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
          C:\WINDOWS\system32\msiexec.exe
          C:\Documents and Settings\mgrosjean\Bureau\HiJackThis.exe

          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://proxy.pw2.vinci-energies.net/proxy.pac
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
          O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
          O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
          O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
          O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
          O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
          O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
          O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
          O2 - BHO: HP Credential Manager for ProtectTools - {DF21F1DB-80C6-11D3-9483-B03D0EC10000} - C:\Program Files\HPQ\IAM\Bin\ItIeAddIN.dll
          O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
          O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
          O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
          O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
          O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
          O4 - HKLM\..\Run: [PTHOSTTR] C:\Program Files\HPQ\HP ProtectTools Security Manager\PTHOSTTR.EXE /Start
          O4 - HKLM\..\Run: [HP Software Update] c:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
          O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
          O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
          O4 - HKLM\..\Run: [CognizanceTS] rundll32.exe C:\PROGRA~1\HPQ\IAM\Bin\AsTsVcc.dll,RegisterModule
          O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
          O4 - HKLM\..\Run: [Cpqset] C:\Program Files\Hewlett-Packard\Default Settings\cpqset.exe
          O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\Sminst\Recguard.exe
          O4 - HKLM\..\Run: [Reminder] C:\WINDOWS\Creator\Remind_XP.exe
          O4 - HKLM\..\Run: [Scheduler] C:\WINDOWS\SMINST\Scheduler.exe
          O4 - HKLM\..\Run: [WatchDog] C:\Program Files\InterVideo\DVD Check\DVDCheck.exe
          O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
          O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
          O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
          O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Fichiers communs\Roxio Shared\System\EngUtil.exe"
          O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"
          O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
          O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
          O4 - HKLM\..\Run: [EPSON Stylus DX3800 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE /P26 "EPSON Stylus DX3800 Series" /O6 "USB001" /M "Stylus DX3800"
          O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
          O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
          O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
          O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
          O4 - Global Startup: BTTray.lnk = ?
          O4 - Global Startup: DVD Check.lnk = C:\Program Files\InterVideo\DVD Check\DVDCheck.exe
          O4 - Global Startup: Lancement rapide d'Adobe Acrobat.lnk = ?
          O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
          O8 - Extra context menu item: Convertir en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
          O8 - Extra context menu item: Convertir en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
          O8 - Extra context menu item: Convertir la cible du lien en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
          O8 - Extra context menu item: Convertir la cible du lien en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
          O8 - Extra context menu item: Convertir la sélection en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
          O8 - Extra context menu item: Convertir la sélection en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
          O8 - Extra context menu item: Convertir les liens sélectionnés en fichier Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
          O8 - Extra context menu item: Convertir les liens sélectionnés en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
          O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
          O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
          O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
          O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
          O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O14 - IERESET.INF: START_PAGE_URL=https://www8.hp.com/fr/fr/home.html
          O15 - Trusted Zone: http://www.secuser.com
          O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = atlantis.lan
          O17 - HKLM\Software\..\Telephony: DomainName = atlantis.lan
          O17 - HKLM\System\CCS\Services\Tcpip\..\{3F014187-38EE-429F-85F7-01DBE368458F}: NameServer = 10.153.10.100
          O17 - HKLM\System\CCS\Services\Tcpip\..\{95F136AB-7AE2-4A85-B0B7-F4965744C584}: NameServer = 10.153.10.100
          O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = atlantis.lan
          O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = atlantis.lan
          O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
          O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
          O20 - AppInit_DLLs: avgrsstx.dll
          O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
          O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
          O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
          O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe
          O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
          O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe
          O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
          O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
          O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
          O23 - Service: Security Platform Management Service (IFXSpMgtSrv) - Infineon Technologies AG - C:\WINDOWS\system32\IFXSPMGT.exe
          O23 - Service: Trusted Platform Core Service (IFXTCS) - Infineon Technologies AG - C:\WINDOWS\system32\IFXTCS.exe
          O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
          O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
          O23 - Service: PC Angel (PCA) - SoftThinks - C:\WINDOWS\SMINST\PCAngel.exe
          O23 - Service: Personal Secure Drive Service (PersonalSecureDriveService) - Infineon Technologies AG - C:\Program Files\ProtectTools\Embedded Security Software\PSDsrvc.EXE
          O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
          O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
          O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
          O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
          1. non va au dodo pas de soucis

            rien ne presse on a presque fini

            bonne nuite fais de beau reves .. h hi
            1. réouvre hijackthis
              fais scan only
              coche ces lignes :

              O3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)

              O4 - HKCU\..\Run: [C:\Documents and Settings\All Users\Application Data\Adsl Software Limited\WinSpywareProtect\WinSpywareProtect.exe] "C:\Documents and Settings\All Users\Application Data\Adsl Software Limited\WinSpywareProtect\WinSpywareProtect.exe" /autorun

              et clic sur fix checked

              ensuite désinstal java car pas a jours et telecharge et instal cette version :

              https://www.java.com/fr/download/manual.jsp

              ensuite si c est la version gratuite désinstal adobe reader acrobat car pas a jours et telecharge et instal cette version :

              https://get2.adobe.com/reader/otherversions/

              ensuite :

              télécharge OTMoveIt http://download.bleepingcomputer.com/oldtimer/OTMoveIt2.exe (de Old_Timer) sur ton Bureau.
              double-clique sur OTMoveIt.exe pour le lancer.
              copie la liste qui se trouve en gras ci-dessous,
              et colle-la dans le cadre de gauche de OTMoveIt :Paste List of Files/Folders to be moved.

              C:\Documents and Settings\All Users\Application Data\Adsl Software Limited\WinSpywareProtect\WinSpywareProtect.exe
              C:\Documents and Settings\All Users\Application Data\Adsl Software Limited\


              clique sur MoveIt! pour lancer la suppression.
              le résultat apparaitra dans le cadre "Results".
              clique sur Exit pour fermer.
              poste le rapport situé dans C:\_OTMoveIt\MovedFiles. + un nouveau rapport hijackthis stp

              il te sera peut-être demander de redémarrer le pc pour achever la suppression.si c'est le cas accepte par Yes.
              1. et voila un hitjack!!

                Logfile of Trend Micro HijackThis v2.0.2
                Scan saved at 23:46, on 2008-06-17
                Platform: Windows XP SP2 (WinNT 5.01.2600)
                MSIE: Internet Explorer v7.00 (7.00.6000.16674)
                Boot mode: Normal

                Running processes:
                C:\WINDOWS\System32\smss.exe
                C:\WINDOWS\system32\winlogon.exe
                C:\WINDOWS\system32\services.exe
                C:\WINDOWS\system32\lsass.exe
                C:\WINDOWS\system32\Ati2evxx.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\System32\svchost.exe
                C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
                C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
                C:\WINDOWS\system32\spoolsv.exe
                C:\WINDOWS\system32\Ati2evxx.exe
                C:\WINDOWS\System32\svchost.exe
                C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
                C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe
                C:\Program Files\Symantec AntiVirus\DefWatch.exe
                C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                C:\WINDOWS\System32\svchost.exe
                C:\WINDOWS\system32\IFXSPMGT.exe
                C:\WINDOWS\system32\IFXTCS.exe
                C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
                C:\Program Files\ProtectTools\Embedded Security Software\PSDsrvc.EXE
                C:\WINDOWS\system32\svchost.exe
                C:\Program Files\Symantec AntiVirus\Rtvscan.exe
                C:\WINDOWS\system32\MsPMSPSv.exe
                C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
                C:\WINDOWS\system32\mqsvc.exe
                C:\WINDOWS\system32\mqtgsvc.exe
                C:\PROGRA~1\AVG\AVG8\avgrsx.exe
                C:\Program Files\Analog Devices\Core\smax4pnp.exe
                C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
                C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
                C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
                C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
                C:\WINDOWS\SMINST\Scheduler.exe
                C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
                C:\PROGRA~1\SYMANT~1\VPTray.exe
                C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe
                C:\Program Files\iTunes\iTunesHelper.exe
                C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
                C:\Program Files\iPod\bin\iPodService.exe
                C:\PROGRA~1\AVG\AVG8\avgtray.exe
                C:\WINDOWS\system32\ctfmon.exe
                C:\Program Files\WIDCOMM\Logiciel Bluetooth\BTTray.exe
                C:\Program Files\Google\Google Updater\GoogleUpdater.exe
                C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
                C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
                C:\WINDOWS\explorer.exe
                C:\PROGRA~1\WIDCOMM\LOGICI~1\BTSTAC~1.EXE
                C:\Program Files\Internet Explorer\iexplore.exe
                C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
                C:\WINDOWS\system32\wuauclt.exe
                C:\Documents and Settings\mgrosjean\Bureau\HiJackThis.exe

                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://proxy.pw2.vinci-energies.net/proxy.pac
                R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
                O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
                O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
                O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
                O2 - BHO: HP Credential Manager for ProtectTools - {DF21F1DB-80C6-11D3-9483-B03D0EC10000} - C:\Program Files\HPQ\IAM\Bin\ItIeAddIN.dll
                O3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)
                O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
                O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
                O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
                O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
                O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
                O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
                O4 - HKLM\..\Run: [PTHOSTTR] C:\Program Files\HPQ\HP ProtectTools Security Manager\PTHOSTTR.EXE /Start
                O4 - HKLM\..\Run: [HP Software Update] c:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
                O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
                O4 - HKLM\..\Run: [CognizanceTS] rundll32.exe C:\PROGRA~1\HPQ\IAM\Bin\AsTsVcc.dll,RegisterModule
                O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
                O4 - HKLM\..\Run: [Cpqset] C:\Program Files\Hewlett-Packard\Default Settings\cpqset.exe
                O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\Sminst\Recguard.exe
                O4 - HKLM\..\Run: [Reminder] C:\WINDOWS\Creator\Remind_XP.exe
                O4 - HKLM\..\Run: [Scheduler] C:\WINDOWS\SMINST\Scheduler.exe
                O4 - HKLM\..\Run: [WatchDog] C:\Program Files\InterVideo\DVD Check\DVDCheck.exe
                O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
                O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
                O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
                O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Fichiers communs\Roxio Shared\System\EngUtil.exe"
                O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"
                O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                O4 - HKLM\..\Run: [EPSON Stylus DX3800 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE /P26 "EPSON Stylus DX3800 Series" /O6 "USB001" /M "Stylus DX3800"
                O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
                O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
                O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                O4 - HKCU\..\Run: [C:\Documents and Settings\All Users\Application Data\Adsl Software Limited\WinSpywareProtect\WinSpywareProtect.exe] "C:\Documents and Settings\All Users\Application Data\Adsl Software Limited\WinSpywareProtect\WinSpywareProtect.exe" /autorun
                O4 - Global Startup: BTTray.lnk = ?
                O4 - Global Startup: DVD Check.lnk = C:\Program Files\InterVideo\DVD Check\DVDCheck.exe
                O4 - Global Startup: Lancement rapide d'Adobe Acrobat.lnk = ?
                O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
                O8 - Extra context menu item: Convertir en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
                O8 - Extra context menu item: Convertir en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
                O8 - Extra context menu item: Convertir la cible du lien en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
                O8 - Extra context menu item: Convertir la cible du lien en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
                O8 - Extra context menu item: Convertir la sélection en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
                O8 - Extra context menu item: Convertir la sélection en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
                O8 - Extra context menu item: Convertir les liens sélectionnés en fichier Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
                O8 - Extra context menu item: Convertir les liens sélectionnés en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
                O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                O14 - IERESET.INF: START_PAGE_URL=https://www8.hp.com/fr/fr/home.html
                O15 - Trusted Zone: http://www.secuser.com
                O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = atlantis.lan
                O17 - HKLM\Software\..\Telephony: DomainName = atlantis.lan
                O17 - HKLM\System\CCS\Services\Tcpip\..\{3F014187-38EE-429F-85F7-01DBE368458F}: NameServer = 10.153.10.100
                O17 - HKLM\System\CCS\Services\Tcpip\..\{95F136AB-7AE2-4A85-B0B7-F4965744C584}: NameServer = 10.153.10.100
                O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = atlantis.lan
                O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = atlantis.lan
                O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
                O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
                O20 - AppInit_DLLs: avgrsstx.dll
                O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
                O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
                O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe
                O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
                O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe
                O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
                O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
                O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
                O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
                O23 - Service: Security Platform Management Service (IFXSpMgtSrv) - Infineon Technologies AG - C:\WINDOWS\system32\IFXSPMGT.exe
                O23 - Service: Trusted Platform Core Service (IFXTCS) - Infineon Technologies AG - C:\WINDOWS\system32\IFXTCS.exe
                O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
                O23 - Service: PC Angel (PCA) - SoftThinks - C:\WINDOWS\SMINST\PCAngel.exe
                O23 - Service: Personal Secure Drive Service (PersonalSecureDriveService) - Infineon Technologies AG - C:\Program Files\ProtectTools\Embedded Security Software\PSDsrvc.EXE
                O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
                O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
                O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
                O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
                1. ComboFix 08-06-16.5 - mgrosjean 2008-06-17 23:32:09.2 - NTFSx86
                  Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.297 [GMT 2:00]
                  Endroit: C:\Documents and Settings\mgrosjean\Bureau\ComboFix.exe
                  Command switches used :: C:\Documents and Settings\mgrosjean\Bureau\CFScript.txt
                  * Création d'un nouveau point de restauration

                  [color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/b][/color]

                  FILE ::
                  C:\Documents and Settings\All Users\Application Data\Adsl Software Limited\WinSpywareProtect\WinSpywareProtect.exe
                  C:\Program Files\HPQ\IAM\Bin\AsWlnPkg.dll
                  C:\upload_moi_ATLANTIS.tar.gz
                  C:\WINDOWS\LPT$VPN.345
                  C:\WINDOWS\PATCH.EXE
                  C:\WINDOWS\system32\IfxWlxEN.dll
                  C:\WINDOWS\system32\tmp.reg
                  .

                  (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
                  .

                  C:\Program Files\HPQ\IAM\Bin\AsWlnPkg.dll
                  C:\upload_moi_ATLANTIS.tar.gz
                  C:\WINDOWS\LPT$VPN.345
                  C:\WINDOWS\PATCH.EXE
                  C:\WINDOWS\system32\IfxWlxEN.dll
                  C:\WINDOWS\system32\tmp.reg

                  .
                  ((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-05-17 to 2008-06-17 ))))))))))))))))))))))))))))))))))))
                  .

                  2008-06-17 23:36 . 2008-06-17 23:36 114,688 --a------ C:\WINDOWS\system32\chg.exe
                  2008-06-17 23:00 . 2007-07-30 19:19 207,736 --a------ C:\WINDOWS\system32\muweb.dll
                  2008-06-17 20:45 . 2008-06-17 20:45 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
                  2008-06-17 20:45 . 2008-06-17 20:45 <REP> d-------- C:\Documents and Settings\mgrosjean\Application Data\Malwarebytes
                  2008-06-17 20:45 . 2008-06-17 20:45 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
                  2008-06-17 20:45 . 2008-06-10 19:02 34,296 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
                  2008-06-17 20:45 . 2008-06-10 19:02 15,864 --a------ C:\WINDOWS\system32\drivers\mbam.sys
                  2008-06-16 23:31 . 2007-01-16 19:22 <REP> d--h----- C:\Documents and Settings\mgrosjean.PCP-54\Voisinage r‚seau
                  2008-06-16 23:31 . 2007-01-16 19:22 <REP> d--h----- C:\Documents and Settings\mgrosjean.PCP-54\Voisinage d'impression
                  2008-06-16 23:31 . 2007-01-16 19:22 <REP> d--h----- C:\Documents and Settings\mgrosjean.PCP-54\ModŠles
                  2008-06-16 23:31 . 2007-01-16 19:22 <REP> dr------- C:\Documents and Settings\mgrosjean.PCP-54\Mes documents
                  2008-06-16 23:31 . 2007-01-16 19:22 <REP> dr------- C:\Documents and Settings\mgrosjean.PCP-54\Menu D‚marrer
                  2008-06-16 23:31 . 2007-01-16 19:22 <REP> dr------- C:\Documents and Settings\mgrosjean.PCP-54\Favoris
                  2008-06-16 23:31 . 2008-06-17 08:06 <REP> d-------- C:\Documents and Settings\mgrosjean.PCP-54\Bureau
                  2008-06-16 23:31 . 2007-01-16 19:22 <REP> d-------- C:\Documents and Settings\mgrosjean.PCP-54\Application Data\SampleView
                  2008-06-16 23:31 . 2007-01-16 19:22 <REP> d-------- C:\Documents and Settings\mgrosjean.PCP-54\Application Data\ATI
                  2008-06-16 23:31 . 2008-06-16 23:31 <REP> d-------- C:\Documents and Settings\mgrosjean.PCP-54
                  2008-06-16 22:36 . 2008-06-17 01:30 <REP> d--h----- C:\$AVG8.VAULT$
                  2008-06-16 22:28 . 2008-06-16 22:30 <REP> d-------- C:\WINDOWS\system32\drivers\Avg
                  2008-06-16 22:28 . 2008-06-16 22:52 <REP> d-------- C:\Documents and Settings\mgrosjean\Application Data\AVGTOOLBAR
                  2008-06-16 22:28 . 2008-06-16 22:28 96,520 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys
                  2008-06-16 22:28 . 2008-06-16 22:28 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll
                  2008-06-16 22:27 . 2008-06-16 22:27 <REP> d-------- C:\Program Files\AVG
                  2008-06-16 22:27 . 2008-06-16 22:27 <REP> d-------- C:\Documents and Settings\All Users\Application Data\avg8
                  2008-06-16 22:18 . 2008-06-16 22:18 <REP> d-------- C:\Program Files\CCleaner
                  2008-06-16 21:56 . 2008-06-16 21:56 <REP> d-------- C:\WINDOWS\AU_Temp
                  2008-06-16 19:48 . 2008-06-16 19:48 <REP> d-------- C:\Program Files\Enigma Software Group
                  2008-06-16 19:33 . 2008-06-16 19:59 <REP> d-------- C:\Program Files\Trojan Remover
                  2008-06-16 18:45 . 2008-06-16 23:29 <REP> d-------- C:\Program Files\Avast4
                  2008-06-16 18:22 . 2008-06-16 18:22 <REP> d-------- C:\WINDOWS\report
                  2008-06-16 18:22 . 2008-06-16 19:38 <REP> d-------- C:\WINDOWS\AU_Backup
                  2008-06-16 18:22 . 2008-06-16 18:22 1,959,409 --a------ C:\WINDOWS\tsc.ptn
                  2008-06-16 18:22 . 2008-06-16 19:38 1,213,784 --a------ C:\WINDOWS\vsapi32.dll
                  2008-06-16 18:22 . 2008-06-16 18:22 333,576 --a------ C:\WINDOWS\TSC.exe
                  2008-06-16 18:22 . 2008-06-16 19:38 91,744 --a------ C:\WINDOWS\BPMNT.dll
                  2008-06-16 18:22 . 2008-06-16 18:22 71,749 --a------ C:\WINDOWS\hcextoutput.dll
                  2008-06-16 18:22 . 2008-06-16 19:39 823 --a------ C:\WINDOWS\tsc.ini
                  2008-06-16 18:21 . 2008-06-16 18:22 34,759,765 --a------ C:\WINDOWS\VPTNFILE.345
                  2008-06-16 18:18 . 2008-06-16 18:18 <REP> d-------- C:\WINDOWS\AU_Log
                  2008-06-16 18:18 . 2008-06-16 18:18 507,904 --a------ C:\WINDOWS\TMUPDATE.DLL
                  2008-06-16 18:18 . 2008-06-16 18:18 69,689 --a------ C:\WINDOWS\UNZIP.DLL
                  2008-06-16 18:18 . 2008-06-16 21:56 170 --a------ C:\WINDOWS\GetServer.ini
                  2008-06-16 13:28 . 2008-06-16 13:28 <REP> d-------- C:\Documents and Settings\mgrosjean\Application Data\MSNInstaller
                  2008-06-16 12:12 . 2008-06-16 12:12 <REP> dr------- C:\Documents and Settings\NetworkService\Favoris
                  2008-06-10 20:39 . 2008-04-14 17:52 272,768 --------- C:\WINDOWS\system32\drivers\bthport.sys
                  2008-06-10 20:39 . 2008-04-14 17:52 272,768 --------- C:\WINDOWS\system32\dllcache\bthport.sys

                  .
                  (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                  .
                  2008-06-17 21:37 --------- d-----w C:\Program Files\Symantec AntiVirus
                  2008-06-17 11:55 --------- d-----w C:\Documents and Settings\All Users\Application Data\Google Updater
                  2008-06-16 10:55 --------- d-----w C:\Program Files\eMule
                  2008-06-16 10:05 --------- d-----w C:\Program Files\Microsoft ActiveSync
                  2008-06-11 15:54 --------- d-----w C:\Documents and Settings\mgrosjean\Application Data\Skype
                  2008-06-11 15:44 230,432 ----a-w C:\StiImg.dat
                  2008-06-11 14:57 --------- d-----w C:\Documents and Settings\mgrosjean\Application Data\skypePM
                  2008-05-28 17:08 --------- d-----w C:\Program Files\RDS
                  2008-05-15 01:06 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
                  2008-05-14 16:27 --------- d-----w C:\Documents and Settings\mgrosjean\Application Data\AdobeUM
                  2008-05-14 14:19 --------- d-----w C:\Program Files\Skype
                  2008-05-14 14:19 --------- d-----w C:\Program Files\Fichiers communs\Skype
                  2008-05-14 14:19 --------- d-----w C:\Documents and Settings\All Users\Application Data\Skype
                  2008-05-14 09:06 --------- d-----w C:\Program Files\DivX
                  2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
                  .

                  ((((((((((((((((((((((((((((( snapshot@2008-06-17_22.58.48.31 )))))))))))))))))))))))))))))))))))))))))
                  .
                  - 2008-06-17 20:53:52 2,048 --s-a-w C:\WINDOWS\bootstat.dat
                  + 2008-06-17 21:36:21 2,048 --s-a-w C:\WINDOWS\bootstat.dat
                  .
                  ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
                  .
                  .
                  REGEDIT4
                  *Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s

                  [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                  "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-28 10:26 68856]
                  "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 10:00 15360]
                  "FlyAway"="" []
                  "C:\Documents and Settings\All Users\Application Data\Adsl Software Limited\WinSpywareProtect\WinSpywareProtect.exe"="C:\Documents and Settings\All Users\Application Data\Adsl Software Limited\WinSpywareProtect\WinSpywareProtect.exe" [ ]

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                  "MsmqIntCert"="regsvr32 /s mqrt.dll" []
                  "SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2005-05-20 11:11 925696]
                  "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
                  "ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-05-10 11:12 90112]
                  "PTHOSTTR"="C:\Program Files\HPQ\HP ProtectTools Security Manager\PTHOSTTR.exe" [2006-02-14 11:56 122880]
                  "HP Software Update"="c:\Program Files\Hp\HP Software Update\HPWuSchd2.exe" [2005-02-16 23:11 49152]
                  "SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-31 18:01 761946]
                  "hpWirelessAssistant"="C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2006-03-28 14:13 454656]
                  "CognizanceTS"="C:\PROGRA~1\HPQ\IAM\Bin\AsTsVcc.dll" [2003-12-22 20:12 17920]
                  "QlbCtrl"="C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2006-03-23 11:38 131072]
                  "Cpqset"="C:\Program Files\Hewlett-Packard\Default Settings\cpqset.exe" [2006-04-21 09:30 40960]
                  "Recguard"="C:\WINDOWS\Sminst\Recguard.exe" [2005-12-20 16:51 1187840]
                  "Reminder"="C:\WINDOWS\Creator\Remind_XP.exe" [2006-03-09 17:38 806912]
                  "Scheduler"="C:\WINDOWS\SMINST\Scheduler.exe" [2006-02-15 17:43 892928]
                  "WatchDog"="C:\Program Files\InterVideo\DVD Check\DVDCheck.exe" [2006-03-31 14:58 184320]
                  "ccApp"="C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe" [2005-04-18 17:02 48752]
                  "vptray"="C:\PROGRA~1\SYMANT~1\VPTray.exe" [2005-05-09 11:47 85088]
                  "Synchronization Manager"="C:\WINDOWS\system32\mobsync.exe" [2004-08-05 10:00 144384]
                  "RoxioEngineUtility"="C:\Program Files\Fichiers communs\Roxio Shared\System\EngUtil.exe" [2003-05-01 19:44 65536]
                  "RoxioDragToDisc"="C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe" [2004-01-09 17:01 868352]
                  "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-03-14 19:05 257088]
                  "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51 39792]
                  "EPSON Stylus DX3800 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACE.exe" [ ]
                  "Acrobat Assistant 7.0"="C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2008-04-23 02:08 483328]
                  "AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-06-16 22:27 1177368]

                  [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
                  "AppInit_DLLs"=avgrsstx.dll

                  [HKEY_LOCAL_MACHINE\software\microsoft\security center]
                  "AntiVirusDisableNotify"=dword:00000001

                  [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
                  "DisableMonitoring"=dword:00000001

                  [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
                  "DisableMonitoring"=dword:00000001

                  [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
                  "EnableFirewall"= 0 (0x0)

                  [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
                  "%windir%\\system32\\sessmgr.exe"=
                  "C:\\WINDOWS\\system32\\mqsvc.exe"=
                  "C:\\WINDOWS\\SMINST\\Scheduler.exe"=
                  "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
                  "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
                  "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
                  "C:\\Program Files\\Skype\\Phone\\Skype.exe"=
                  "C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=

                  R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-06-16 22:28]
                  R1 PersonalSecureDrive;PersonalSecureDrive;C:\WINDOWS\system32\drivers\psd.sys [2005-11-29 18:56]
                  R2 ASChannel;Canal de communication local;C:\WINDOWS\System32\svchost.exe [2004-08-05 10:00]
                  R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-06-16 22:27]
                  R3 IFXTPM;IFXTPM;C:\WINDOWS\system32\DRIVERS\IFXTPM.SYS [2005-10-21 13:19]
                  R3 ROCKEYNT;Feitian ROCKEY4 Device Service;C:\WINDOWS\system32\DRIVERS\Rockey4.sys [2007-12-03 10:50]
                  S3 PAC207;SoC PC-Camer@;C:\WINDOWS\system32\DRIVERS\pfc027.sys [2005-02-24 12:29]
                  S3 Rockey_USB;Feitian ROCKEY4 USB Service;C:\WINDOWS\system32\DRIVERS\Rockey4USB.sys [2007-12-03 10:50]
                  S3 usbscan;Pilote de scanneur USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 22:58]
                  S3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-04 00:08]

                  [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
                  Cognizance REG_MULTI_SZ ASChannel

                  .
                  **************************************************************************

                  catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                  Rootkit scan 2008-06-17 23:38:01
                  Windows 5.1.2600 Service Pack 2 NTFS

                  Balayage processus cach‚s ...

                  Balayage cach‚ autostart entries ...

                  HKLM\Software\Microsoft\Windows\CurrentVersion\Run
                  Cpqset = C:\Program Files\Hewlett-Packard\Default Settings\cpqset.exe????????????,?@? ????Y??????R?@?????,?@

                  Balayage des fichiers cach‚s ...

                  Scan termin‚ avec succŠs
                  Les fichiers cach‚s: 0

                  **************************************************************************
                  .
                  ------------------------ Other Running Processes ------------------------
                  .
                  C:\WINDOWS\system32\ati2evxx.exe
                  C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
                  C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
                  C:\WINDOWS\system32\msdtc.exe
                  C:\WINDOWS\system32\ati2evxx.exe
                  C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe
                  C:\Program Files\Symantec AntiVirus\DefWatch.exe
                  C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                  C:\WINDOWS\system32\IFXSPMGT.exe
                  C:\WINDOWS\system32\IFXTCS.exe
                  C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
                  C:\Program Files\ProtectTools\Embedded Security Software\PSDsrvc.EXE
                  C:\Program Files\Symantec AntiVirus\Rtvscan.exe
                  C:\WINDOWS\system32\MsPMSPSv.exe
                  C:\Program Files\Windows Media Player\wmpnetwk.exe
                  C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
                  C:\WINDOWS\system32\mqsvc.exe
                  C:\WINDOWS\system32\mqtgsvc.exe
                  C:\Program Files\AVG\AVG8\avgrsx.exe
                  C:\Program Files\Symantec AntiVirus\DoScan.exe
                  C:\Program Files\iPod\bin\iPodService.exe
                  C:\Program Files\WIDCOMM\Logiciel Bluetooth\BTTray.exe
                  C:\Program Files\Google\Google Updater\GoogleUpdater.exe
                  C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
                  C:\WINDOWS\system32\wbem\wmiapsrv.exe
                  C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
                  .
                  **************************************************************************
                  .
                  Temps d'accomplissement: 2008-06-17 23:44:13 - machine was rebooted
                  ComboFix-quarantined-files.txt 2008-06-17 21:44:04
                  ComboFix2.txt 2008-06-17 20:59:15

                  Pre-Run: 42,113,900,544 octets libres
                  Post-Run: 42,125,049,856 octets libres

                  213 --- E O F --- 2008-06-10 20:09:45
                  1. Copie le texte ci-dessous :

                    File::
                    C:\upload_moi_ATLANTIS.tar.gz
                    C:\WINDOWS\system32\tmp.reg
                    C:\WINDOWS\LPT$VPN.345
                    C:\WINDOWS\PATCH.EXE
                    C:\Documents and Settings\All Users\Application Data\Adsl Software Limited\WinSpywareProtect\WinSpywareProtect.exe
                    C:\WINDOWS\system32\IfxWlxEN.dll
                    C:\Program Files\HPQ\IAM\Bin\AsWlnPkg.dll

                    Folder::
                    C:\Documents and Settings\All Users\Application Data\Adsl Software Limited

                    Registry::
                    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                    "C:\Documents and Settings\All Users\Application Data\Adsl Software Limited\WinSpywareProtect\WinSpywareProtect.exe"=-
                    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IfxWlxEN]
                    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\OneCard]

                    Ouvre le Bloc-Notes puis colle le texte copié.
                    (Démarrer\Tous les programmes\Accessoires\Bloc notes.)
                    Sauvegarde ce fichier sous le nom de CFScript.txt.

                    Glisse maintenant le fichier CFScript.txt dans Combofix.exe comme ci-dessous :

                    http://sd-1.archive-host.com/membres/up/1366464061/CFScript.gif

                    Cela va relancer Combofix,

                    Une fenêtre bleue va apparaître: au message qui apparaît ( Type 1 to continue, or 2 to abort) , tape 1 puis valide.

                    Patiente le temps du scan.Le bureau va disparaître à plusieurs reprises: c'est normal!

                    Ne touche à rien tant que le scan n'est pas terminé.

                    Après redémarrage, poste le contenu du rapport Combofix.txt accompagné d'un rapport Hijackthis.

                    S'il n'y a pas de rédémarrage, poste quand même les rapports.

                    1. Logfile of Trend Micro HijackThis v2.0.2
                      Scan saved at 23:09, on 2008-06-17
                      Platform: Windows XP SP2 (WinNT 5.01.2600)
                      MSIE: Internet Explorer v7.00 (7.00.6000.16674)
                      Boot mode: Normal

                      Running processes:
                      C:\WINDOWS\System32\smss.exe
                      C:\WINDOWS\system32\winlogon.exe
                      C:\WINDOWS\system32\services.exe
                      C:\WINDOWS\system32\lsass.exe
                      C:\WINDOWS\system32\Ati2evxx.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
                      C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
                      C:\WINDOWS\system32\spoolsv.exe
                      C:\WINDOWS\system32\Ati2evxx.exe
                      C:\Program Files\HPQ\IAM\bin\asghost.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
                      C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe
                      C:\Program Files\Symantec AntiVirus\DefWatch.exe
                      C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\WINDOWS\system32\IFXSPMGT.exe
                      C:\WINDOWS\system32\IFXTCS.exe
                      C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
                      C:\Program Files\ProtectTools\Embedded Security Software\PSDsrvc.EXE
                      C:\WINDOWS\system32\svchost.exe
                      C:\Program Files\Symantec AntiVirus\Rtvscan.exe
                      C:\WINDOWS\system32\MsPMSPSv.exe
                      C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
                      C:\WINDOWS\system32\mqsvc.exe
                      C:\WINDOWS\system32\mqtgsvc.exe
                      C:\PROGRA~1\AVG\AVG8\avgrsx.exe
                      C:\Program Files\ProtectTools\Embedded Security Software\PSDrt.exe
                      C:\Program Files\Analog Devices\Core\smax4pnp.exe
                      C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
                      C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
                      C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                      C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
                      C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
                      C:\WINDOWS\SMINST\Scheduler.exe
                      C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
                      C:\PROGRA~1\SYMANT~1\VPTray.exe
                      C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe
                      C:\Program Files\iTunes\iTunesHelper.exe
                      C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
                      C:\PROGRA~1\AVG\AVG8\avgtray.exe
                      C:\WINDOWS\system32\ctfmon.exe
                      C:\Program Files\iPod\bin\iPodService.exe
                      C:\Program Files\WIDCOMM\Logiciel Bluetooth\BTTray.exe
                      C:\Program Files\Google\Google Updater\GoogleUpdater.exe
                      C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
                      C:\WINDOWS\explorer.exe
                      C:\PROGRA~1\WIDCOMM\LOGICI~1\BTSTAC~1.EXE
                      C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
                      C:\Program Files\Internet Explorer\iexplore.exe
                      C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
                      C:\Documents and Settings\mgrosjean\Bureau\HiJackThis.exe

                      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://proxy.pw2.vinci-energies.net/proxy.pac
                      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                      O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                      O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
                      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                      O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
                      O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)
                      O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
                      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
                      O2 - BHO: HP Credential Manager for ProtectTools - {DF21F1DB-80C6-11D3-9483-B03D0EC10000} - C:\Program Files\HPQ\IAM\Bin\ItIeAddIN.dll
                      O3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)
                      O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
                      O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
                      O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
                      O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
                      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
                      O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
                      O4 - HKLM\..\Run: [PTHOSTTR] C:\Program Files\HPQ\HP ProtectTools Security Manager\PTHOSTTR.EXE /Start
                      O4 - HKLM\..\Run: [HP Software Update] c:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
                      O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                      O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
                      O4 - HKLM\..\Run: [CognizanceTS] rundll32.exe C:\PROGRA~1\HPQ\IAM\Bin\AsTsVcc.dll,RegisterModule
                      O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
                      O4 - HKLM\..\Run: [Cpqset] C:\Program Files\Hewlett-Packard\Default Settings\cpqset.exe
                      O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\Sminst\Recguard.exe
                      O4 - HKLM\..\Run: [Reminder] C:\WINDOWS\Creator\Remind_XP.exe
                      O4 - HKLM\..\Run: [Scheduler] C:\WINDOWS\SMINST\Scheduler.exe
                      O4 - HKLM\..\Run: [WatchDog] C:\Program Files\InterVideo\DVD Check\DVDCheck.exe
                      O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
                      O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
                      O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
                      O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Fichiers communs\Roxio Shared\System\EngUtil.exe"
                      O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"
                      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                      O4 - HKLM\..\Run: [EPSON Stylus DX3800 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE /P26 "EPSON Stylus DX3800 Series" /O6 "USB001" /M "Stylus DX3800"
                      O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
                      O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
                      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                      O4 - HKCU\..\Run: [C:\Documents and Settings\All Users\Application Data\Adsl Software Limited\WinSpywareProtect\WinSpywareProtect.exe] "C:\Documents and Settings\All Users\Application Data\Adsl Software Limited\WinSpywareProtect\WinSpywareProtect.exe" /autorun
                      O4 - Global Startup: BTTray.lnk = ?
                      O4 - Global Startup: DVD Check.lnk = C:\Program Files\InterVideo\DVD Check\DVDCheck.exe
                      O4 - Global Startup: Lancement rapide d'Adobe Acrobat.lnk = ?
                      O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
                      O8 - Extra context menu item: Convertir en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
                      O8 - Extra context menu item: Convertir en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
                      O8 - Extra context menu item: Convertir la cible du lien en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
                      O8 - Extra context menu item: Convertir la cible du lien en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
                      O8 - Extra context menu item: Convertir la sélection en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
                      O8 - Extra context menu item: Convertir la sélection en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
                      O8 - Extra context menu item: Convertir les liens sélectionnés en fichier Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
                      O8 - Extra context menu item: Convertir les liens sélectionnés en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
                      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                      O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                      O14 - IERESET.INF: START_PAGE_URL=https://www8.hp.com/fr/fr/home.html
                      O15 - Trusted Zone: http://www.secuser.com
                      O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = atlantis.lan
                      O17 - HKLM\Software\..\Telephony: DomainName = atlantis.lan
                      O17 - HKLM\System\CCS\Services\Tcpip\..\{3F014187-38EE-429F-85F7-01DBE368458F}: NameServer = 10.153.10.100
                      O17 - HKLM\System\CCS\Services\Tcpip\..\{95F136AB-7AE2-4A85-B0B7-F4965744C584}: NameServer = 10.153.10.100
                      O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = atlantis.lan
                      O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = atlantis.lan
                      O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
                      O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
                      O20 - AppInit_DLLs: avgrsstx.dll
                      O20 - Winlogon Notify: OneCard - C:\Program Files\HPQ\IAM\Bin\AsWlnPkg.dll
                      O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
                      O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                      O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
                      O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe
                      O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
                      O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe
                      O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
                      O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
                      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                      O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
                      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
                      O23 - Service: Security Platform Management Service (IFXSpMgtSrv) - Infineon Technologies AG - C:\WINDOWS\system32\IFXSPMGT.exe
                      O23 - Service: Trusted Platform Core Service (IFXTCS) - Infineon Technologies AG - C:\WINDOWS\system32\IFXTCS.exe
                      O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                      O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
                      O23 - Service: PC Angel (PCA) - SoftThinks - C:\WINDOWS\SMINST\PCAngel.exe
                      O23 - Service: Personal Secure Drive Service (PersonalSecureDriveService) - Infineon Technologies AG - C:\Program Files\ProtectTools\Embedded Security Software\PSDsrvc.EXE
                      O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
                      O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
                      O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
                      O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
                      • 1
                      • 2