Probleme avast "message suspect"

Bonjour à tous,
je commence à regarder les forums sur ce sujet car je n'arrive pas a régler mon soucis, jai' fait une image de mon disque dur que je viens de réinstaller et à ma grande surprise des "messages suspects" d'avast apparaissent sur mon bureau, j'ai également il y a qqes semaines le compte a rebours autorite NT system (j ai du modifier l heure de mon horloge pour eviter le rebootage: comment peut on avoir ce probleme avec XP SP3 d'installer???!!!)

bref je vous contacte pour l autre probleme "message suspect" j'ai utiliser ad-aware, spybot, avast et je ne trouve absolument rien d anormal, d'ou vient ce probleme ? de messenger? j'ai meme recréer un nouveau compte hotmail et toujours le meme probleme.

et cela ralenti également l ouverture de mes fentres d internet explorer

pourriez vous m'assister sur ce sujet?
merci d'avance
Configuration: Windows XP SP3
Internet Explorer 7.0
avast free edition
zone alarm
spybot

23 réponses

Résumé de la discussion

Des alertes suspectes liées à Avast apparaissent après réinstallation et un compte à rebours NT AUTHORITY NT SYSTEM est évoqué, suscitant des doutes sur une infection sur Windows XP SP3. Plusieurs outils antivirus et antispyware ont été testés — Ad-Aware, Spybot, Avast et ZoneAlarm — mais les résultats restent mitigés, avec des rapports HijackThis révélant de nombreuses entrées de démarrage. Des analyses complémentaires ont donné des pistes variées, mentionnant des éléments suspects ou des composants gravitant autour d’outils comme MSNFix et ComboFix, sans consensus clair sur une désinfection complète. Certains éléments des logs et des analyses restent à interpréter et indiquent qu’une correction plus poussée ou une réinstallation propre pourrait être nécessaire pour stabiliser durablement le système.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    oui c'est bon garde la version gratuite de MalwareByte's Anti-Malware sous la main pour scanner de temps en temps ton ordi car en recherche c'est actuellement le mieux pour les espion et en plus gratos et ne consommant pas de ressource en dehors du scan
    0
    1. ok merci beaucoup pour tes conseil précieux,

      ton premier lien ne fonctionne pas: https://www.commentcamarche.net/telecharger/ 4 securite.

      sinon de mon coté j'utilise maintenant spyware terminator + comodo firewall + avast.

      tu préconises quoi, cela suffit comme protection?
      0
      1. Contributeur sécurité
        le souci venait de ce fichier infécté:

        O20 - Winlogon Notify: dsauth32 - C:\WINDOWS\SYSTEM32\dsauth32.dll

        pour protéger gratos ton ordi

        https://www.commentcamarche.net/telecharger/ 4 securite

        mettre un antivirus

        AVAST en français ou ANTIVIR (en anglais mais très efficace)
        https://www.malekal.com/avira-free-security-antivirus-gratuit/ (merci Malekal)
        -------------
        des anti-espions :
        MalwareByte's Anti-Malware + SPYBOT
        +
        SPYWAREBLASTER pour immuniser le système contre vundo notamment mais en anglais (mais facile d'utilisation : il suffit de faire "update" pour mettre à jour tous les mois et ensuite" enable all protection" pour immuniser)...

        Rq : spybot et ad-aware ont sorti de nouvelles versions cette année vérifiez que vous avez la dernière version
        --------
        un pare feu :
        celui de (Windows) ou mieux Online armor ou KERIO ou JETICO ou ZONE ALARM (mettre que le parefeu gratuit)

        https://www.commentcamarche.net/telecharger/ 34055356 online armor personal firewall

        https://forum.pcastuces.com/sujet.asp?f=25&s=35606
        http://www.clubic.com/telecharger-fiche11071-sunbelt-persona­l-firewall-ex-kerio.html
        https://manuelsdaide.com/contact/
        http://www.open-files.com/forum/index.php?showtopic=29277
        https://www.commentcamarche.net/telecharger/ 157 zonealarm

        -----------
        CCLEANER pour effacer les traces de surf
        ---------
        naviguer avec firefox ou safari ou opera et non internet explorer plus touché par les virus
        http://www.mozilla-europe.org/fr/products/firefox/
        0
        1. Contributeur sécurité
          ok c'est bon

          désactive ta restauration puis redemarre puis réactive la pour purger ce qu'il y a dedans:
          http://service1.symantec.com/SUPPORT/INTER/tsgeninfointl.nsf/fdocid/20020830101856924

          ____

          utlisie tools cleaner pour virer ce que l'on a utilisé et après tu peux refaire une image disque

          http://www.commentcamarche.net/telecharger/telecharger 34055291 toolscleaner
          0
          1. slt jlp jlp,

            bon je tiens tout d abord a te remercier pour le temps que tu as passé a analyser tout mes problemes, vraiment sympa de ta part, je saurais pour la prochaine fois ou trouver des solution a mes problemes PC,

            bonne journée et merci encore,

            PS: le probleme venait d ou en fait? messenger? ou ailleurs?

            a+++
            0
        2. ok merci pour ta réponse , je n'ai pour l instant plus aucun messages suspect, est que ça eux dire que le pc est sain maintenant?
          dois je refaire une image du pc? ou l'ancienne ne comportait sans doute aucun probleme?
          0
          1. Contributeur sécurité
            tu pouvais gardé spybot mais désactiver le tea timer qui fais une analyse en temps réel et donc avec spyware terminator c'est lours!!

            un souci avec msn?

            Télécharge MSNFix de Laurent
            http://sosvirus.changelog.fr/MSNFix.zip

            Décompresse-le et double clic sur le fichier MSNFix.bat.
            - Exécute l'option R.
            --Si l'infection est détectée, exécute l'option N
            - Sauvegarde ce rapport puis fais un copier/coller de ce rapport sur le forum.

            Note :
            Si une erreur de suppression est détectée un message s'affichera demandant de redémarrer l'ordinateur afin de terminer les opérations. Dans ce cas il suffit de redémarrer l'ordinateur en mode normal
            Sauvegarder et fermer le rapport pour que Windows termine de se lancer normalement.

            envoyer le fichier [b] C:\DOCUME~1\florian\Bureau\Upload_Me.zip /b sur http://upload.changelog.fr pour faire evoluer msnfix
            0
            1. voici le message
              MSNFix 1.732

              C:\Documents and Settings\reverend\Bureau\MSNFix
              Fix exécuté le 15/07/2008 - 22:44:56,00 By reverend
              mode normal

              ************************ Recherche les fichiers présents

              Aucun Fichier trouvé

              ************************ Recherche les dossiers présents

              Aucun dossier trouvé

              ************************ Fichiers suspects

              Aucun Fichier trouvé

              ************************ HKLM\...\Winlogon\Userinit

              Userinit = C:\WINDOWS\system32\userinit.exe,

              Important : http://msnfix.changelog.fr/index.php/2008/05/18/32-alerte

              ------------------------------------------------------------------------
              Auteur : !aur3n7 Contact: https://www.ionos.fr/
              ------------------------------------------------------------------------

              --------------------------------------------- END ---------------------------------------------
              0
            2. slt jlpjlp,

              peux tu juste me confirmer si après tout ces scan le pc est normalement desinfecté au vu de rapport que je t ai envoyé? car tout semble bien marcher a présent internet fonctionne très bien et plus de messages suspect, je souhaite vraiment si c est le cas faire une copie de mon disque dur,

              merci encore pour ton aide
              a+
              0
          2. c était quoi finalement un vers msn? ou quoi?
            je dois refaire une image du disque dur ou pas besoin?
            0
            1. Contributeur sécurité
              Relance HijackThis, choisis "do a scan only" coche la case devant les lignes ci-dessous et clic en bas sur "fix checked".

              O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)

              ________

              tu n'as pas désactivé le tea timer? cela va ramer avec spyware terminator!

              encore des soucis???
              0
              1. si j ai supprimé spybot, ok je lance hijackthis

                c était tout ce qui n'allait pas ce fichier?
                0
              2. @herby2475voila je l ai supprimé et mantenant ? c est réglé?
                0
            2. Contributeur sécurité
              fix cette ligne:
              O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)

              tu n'as pas désactivé le tea timer? cela va ramer avec spyware terminator!
              0
              1. je la répare comment???
                0
            3. Contributeur sécurité
              Remets aussi un rapport Hijackthis et dis tes soucis
              0
              1. voila le rapport:

                Logfile of HijackThis v1.99.1
                Scan saved at 19:54:29, on 15/07/2008
                Platform: Windows XP SP3 (WinNT 5.01.2600)
                MSIE: Internet Explorer v7.00 (7.00.6000.16674)

                Running processes:
                C:\WINDOWS\System32\smss.exe
                C:\WINDOWS\system32\winlogon.exe
                C:\WINDOWS\system32\services.exe
                C:\WINDOWS\system32\lsass.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\System32\svchost.exe
                C:\WINDOWS\system32\ZoneLabs\vsmon.exe
                C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                C:\Program Files\Alwil Software\Avast4\ashServ.exe
                C:\Program Files\ASUS\GamerOSD\GamerOSD.exe
                C:\WINDOWS\RTHDCPL.EXE
                C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
                C:\WINDOWS\system32\RUNDLL32.EXE
                C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
                C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
                C:\Program Files\Fichiers communs\Acronis\Schedule2\schedhlp.exe
                C:\WINDOWS\system32\ctfmon.exe
                C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                C:\WINDOWS\system32\spoolsv.exe
                C:\Program Files\Fichiers communs\Acronis\Schedule2\schedul2.exe
                C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                C:\WINDOWS\ATKKBService.exe
                C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
                C:\WINDOWS\system32\nvsvc32.exe
                C:\Program Files\Spyware Terminator\sp_rsser.exe
                C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
                C:\Program Files\Fichiers communs\Acronis\Fomatik\TrueImageTryStartService.exe
                C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                C:\WINDOWS\explorer.exe
                C:\Program Files\internet explorer\iexplore.exe
                C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
                H:\Program Files\eMule\emule.exe
                C:\Program Files\Hijackthis Version Française\VERSION TRADUITE ORIGINALE.EXE

                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
                O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                O4 - HKLM\..\Run: [ASUSGamerOSD] C:\Program Files\ASUS\GamerOSD\GamerOSD.exe
                O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
                O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\WINDOWS\RaidTool\xInsIDE.exe
                O4 - HKLM\..\Run: [36X Raid Configurer] C:\WINDOWS\system32\xRaidSetup.exe boot
                O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
                O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
                O4 - HKLM\..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
                O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
                O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Fichiers communs\Acronis\Schedule2\schedhlp.exe"
                O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.1_01\bin\npjpi141_01.dll
                O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.1_01\bin\npjpi141_01.dll
                O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
                O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
                O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                O11 - Options group: [INTERNATIONAL] International*
                O14 - IERESET.INF: START_PAGE_URL=https://www.free.fr/freebox/index.html
                O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
                O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
                O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
                O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)
                O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Fichiers communs\Acronis\Schedule2\schedul2.exe
                O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
                O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
                O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
                O23 - Service: GhostStartService - Symantec Corporation - C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
                O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
                O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
                O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
                O23 - Service: Acronis Try And Decide Service (TryAndDecideService) - Unknown owner - C:\Program Files\Fichiers communs\Acronis\Fomatik\TrueImageTryStartService.exe
                O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
                0
              2. t es encore la? ça donne quoi ce rapport?
                0
              3. @herby2475jviens de refaire un dernier scann avec ad aware, ci dessous le rapport , il a trouvé des tracking cokkie et une clé de registre modifiée, je les supprime

                Ad-Aware Build
                Log File Created on: 2008-07-15 20:35:58
                Using Definitions File: C:\Documents and Settings\All Users\Application Data\Lavasoft\Ad-Aware\core.aawdef
                Computer name: REVEREND-XXXX
                Name of user performing scan: SYSTEM

                System information
                ===========================
                Number of processors: 2
                Processor type: Intel(R) Core(TM)2 Duo CPU E8400 @ 3.00GHz
                Memory Available: 66%
                Total Physical Memory: 2146480128 Bytes
                Available Physical Memory: 1402396672 Bytes
                Total Page File Size: 4129751040 Bytes
                Available On Page File: 3489042432 Bytes
                Total Virtual Memory: 2147352576 Bytes
                Available Virtual Memory: 1910849536 Bytes
                OS: Microsoft Windows XP Service Pack 3 (Build 2600)

                Ad-Aware Settings
                ===========================
                Skipping files larger than 1048576 kB
                Ignoring infections with lower TAI than: 3

                Extended Ad-Aware Settings
                ===========================
                Unloading known modules during scan
                Ignoring spanned files when scanning cab archives
                Reanalyzing results after scanning before displaying results
                Trying to unload modules prior to removal
                Let Windows remove files currently in use at next reboot
                Removing quarantined objects after restore
                Deactivating Ad-Watch during scans
                Writeprotecting system files after repairs
                Include info about ignored objects in log file
                Including basic settings in log file
                Including advanced settings in log file
                Including user and computer name in log file
                Create and save WebUpdate log file

                Databaseinfo
                ===========================
                Version number: 103
                Build Number: 0
                Build Date and Time: 2008/07/15 07:23:00

                Scan Statistics
                ===========================
                Method: Smart
                Scan tracking cookies.............................: On
                Scan ADS filestreams..............................: Off

                Item Scanned: 130850
                Infections Detected: 48
                Infections Ignored: 0

                Scan detailed statistics
                ===========================
                Type Critical Total
                Process Scan....: 0 0
                Registry Scan...: 0 0
                Registry PE Scan: 0 0
                Hosts File Scan.: 0 0
                File Scan.......: 0 0
                Folder Scan.....: 0 0
                LSP Scan........: 0 0
                ADS Scan........: 0 0
                Cookie Scan.....: 46 46
                File Hash Scan..: 0 0

                Infections Found
                ===========================
                Family Id: 725 Name: Tracking Cookie Category: DataMiner TAI:3
                Item Id: 600000083 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\reverend\Cookies\index.dat 247realmedia.com RMID /
                Item Id: 600000083 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\reverend\Cookies\index.dat 247realmedia.com RMFD /
                Item Id: 600000083 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\reverend\Cookies\index.dat 247realmedia.com 3suisses /
                Item Id: 600000083 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\reverend\Cookies\index.dat 247realmedia.com spartoo /
                Item Id: 600000083 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\reverend\Cookies\index.dat 247realmedia.com priceminister /
                Item Id: 600000212 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\reverend\Cookies\index.dat msnportal.112.2o7.net s_vi /
                Item Id: 600000408 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\reverend\Cookies\index.dat serving-sys.com U /
                Item Id: 600000408 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\reverend\Cookies\index.dat serving-sys.com A2 /
                Item Id: 600000408 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\reverend\Cookies\index.dat serving-sys.com B2 /
                Item Id: 600000408 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\reverend\Cookies\index.dat serving-sys.com C3 /
                Item Id: 600000408 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\reverend\Cookies\index.dat serving-sys.com D3 /
                Item Id: 600000408 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\reverend\Cookies\index.dat serving-sys.com E2 /
                Item Id: 600000001 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\reverend\Cookies\index.dat smartadserver.com TestIfCookieP /
                Item Id: 600000001 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\reverend\Cookies\index.dat smartadserver.com pbw /
                Item Id: 600000001 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\reverend\Cookies\index.dat smartadserver.com pid /
                Item Id: 600000001 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\reverend\Cookies\index.dat smartadserver.com pbwmaj /
                Item Id: 600000171 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\reverend\Cookies\index.dat bs.serving-sys.com eyeblaster /
                Item Id: 600000142 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\reverend\Cookies\index.dat estat.com e /
                Item Id: 600000225 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\reverend\Cookies\index.dat cetelem.solution.weborama.fr _adpe /
                Item Id: 600000225 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\reverend\Cookies\index.dat cetelem.solution.weborama.fr _adpp /
                Item Id: 600000225 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\reverend\Cookies\index.dat cetelem.solution.weborama.fr _adpcr /
                Item Id: 600000225 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\reverend\Cookies\index.dat cetelem.solution.weborama.fr _adpc /
                Item Id: 600000225 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\reverend\Cookies\index.dat boursoramabanque.solution.weborama.fr _adpe /
                Item Id: 600000225 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\reverend\Cookies\index.dat boursoramabanque.solution.weborama.fr _adpp /
                Item Id: 600000225 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\reverend\Cookies\index.dat boursoramabanque.solution.weborama.fr _adpcr /
                Item Id: 600000225 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\reverend\Cookies\index.dat boursoramabanque.solution.weborama.fr _adpc /
                Item Id: 600000295 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\reverend\Cookies\index.dat adtech.de JEB2 /
                Item Id: 600000101 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\reverend\Cookies\index.dat overture.com CMUserData /
                Item Id: 600000212 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\reverend\Cookies\index.dat himedia.112.2o7.net s_vi /
                Item Id: 600000225 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\reverend\Cookies\index.dat weborama.fr AFFICHE_W /
                Item Id: 600000225 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\reverend\Cookies\index.dat weborama.fr wous /
                Item Id: 600000225 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\reverend\Cookies\index.dat weborama.fr wous_c /
                Item Id: 600000225 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\reverend\Cookies\index.dat weborama.fr oo240953 /
                Item Id: 600000363 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\reverend\Cookies\index.dat fl01.ct2.comclick.com comTrackIdSurfeur /
                Item Id: 600000363 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\reverend\Cookies\index.dat fl01.ct2.comclick.com CKA /
                Item Id: 600000363 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\reverend\Cookies\index.dat fl01.ct2.comclick.com CKA_SIZE /
                Item Id: 600000212 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\reverend\Cookies\index.dat 2o7.net s_vi_x7Cbx7Fx7Ctcrdbeprx60acx7Eu /
                Item Id: 600000225 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\reverend\Cookies\index.dat aimfar.solution.weborama.fr _cslidef /
                Item Id: 600000225 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\reverend\Cookies\index.dat aimfar.solution.weborama.fr _cp /
                Item Id: 600000212 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\reverend\Cookies\index.dat pandasoftware.112.2o7.net s_vi /
                Item Id: 600000457 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\reverend\Cookies\index.dat adopt.euroclick.com DMEXP /
                Item Id: 600000457 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\reverend\Cookies\index.dat adopt.euroclick.com CTCI /
                Item Id: 600000457 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\reverend\Cookies\index.dat adopt.euroclick.com HS /
                Item Id: 600000457 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\reverend\Cookies\index.dat adopt.euroclick.com LO /
                Item Id: 600000457 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\reverend\Cookies\index.dat adopt.euroclick.com UI /
                Item Id: 600000457 Value: Browser: Internet Explorer Cookie: C:\Documents and Settings\reverend\Cookies\index.dat adopt.euroclick.com NSC_mc-bepqu.fvspdmjdl.dpn-iuuq /
                Family Id: 9999 Name: MRU Object Category: MRU Object TAI:0
                Item Id: 1 Value: MRU Path: C:\Documents and Settings\reverend\Recent Count: 19
                Item Id: 3 Value: MRU Registry Key: S-1-5-21-57989841-1844237615-839522115-1003\Software\Microsoft\Internet Explorer\TypedURLs Count: 2

                Items Ignored During Scan
                ===========================

                Listing of running processes
                ===========================
                C:\WINDOWS\SYSTEM32\SMSS.EXE
                c:\windows\system32\smss.exe

                c:\windows\system32\ntdll.dll

                C:\WINDOWS\SYSTEM32\CSRSS.EXE
                c:\windows\system32\csrss.exe

                c:\windows\system32\ntdll.dll

                c:\windows\system32\csrsrv.dll

                c:\windows\system32\basesrv.dll

                c:\windows\system32\winsrv.dll

                c:\windows\system32\gdi32.dll

                c:\windows\system32\kernel32.dll

                c:\windows\system32\user32.dll

                c:\windows\system32\sxs.dll

                c:\windows\system32\advapi32.dll

                c:\windows\system32\rpcrt4.dll

                c:\windows\system32\secur32.dll

                C:\WINDOWS\SYSTEM32\WINLOGON.EXE
                c:\windows\system32\winlogon.exe

                c:\windows\system32\ntdll.dll

                c:\windows\system32\kernel32.dll

                c:\windows\system32\advapi32.dll

                c:\windows\system32\rpcrt4.dll

                c:\windows\system32\secur32.dll

                c:\windows\system32\authz.dll

                c:\windows\system32\msvcrt.dll

                c:\windows\system32\crypt32.dll

                c:\windows\system32\msasn1.dll

                c:\windows\system32\user32.dll

                c:\windows\system32\gdi32.dll

                c:\windows\system32\nddeapi.dll

                c:\windows\system32\profmap.dll

                c:\windows\system32\netapi32.dll

                c:\windows\system32\userenv.dll

                c:\windows\system32\psapi.dll

                c:\windows\system32\regapi.dll

                c:\windows\system32\setupapi.dll

                c:\windows\system32\version.dll

                c:\windows\system32\winsta.dll

                c:\windows\system32\wintrust.dll

                c:\windows\system32\imagehlp.dll

                c:\windows\system32\ws2_32.dll

                c:\windows\system32\ws2help.dll

                c:\windows\system32\imm32.dll

                c:\windows\system32\msgina.dll

                c:\windows\system32\comctl32.dll

                c:\windows\system32\odbc32.dll

                c:\windows\system32\comdlg32.dll

                c:\windows\system32\shell32.dll

                c:\windows\system32\shlwapi.dll

                c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll

                c:\windows\system32\odbcint.dll

                c:\windows\system32\shsvcs.dll

                c:\windows\system32\sfc.dll

                c:\windows\system32\sfc_os.dll

                c:\windows\system32\ole32.dll

                c:\windows\system32\apphelp.dll

                c:\windows\system32\msctfime.ime

                c:\windows\system32\winscard.dll

                c:\windows\system32\wtsapi32.dll

                c:\windows\system32\sxs.dll

                c:\windows\system32\uxtheme.dll

                c:\windows\system32\winmm.dll

                c:\windows\system32\cscdll.dll

                c:\windows\system32\dimsntfy.dll

                c:\windows\system32\wlnotify.dll

                c:\windows\system32\mpr.dll

                c:\windows\system32\winspool.drv

                c:\windows\system32\rsaenh.dll

                c:\windows\system32\samlib.dll

                c:\windows\system32\cscui.dll

                c:\windows\system32\xpsp2res.dll

                c:\windows\system32\ntmarta.dll

                c:\windows\system32\wldap32.dll

                c:\windows\system32\msv1_0.dll

                c:\windows\system32\iphlpapi.dll

                c:\windows\system32\comres.dll

                c:\windows\system32\oleaut32.dll

                c:\windows\system32\clbcatq.dll

                c:\windows\system32\wdmaud.drv

                c:\windows\system32\msacm32.drv

                c:\windows\system32\msacm32.dll

                c:\windows\system32\midimap.dll

                C:\WINDOWS\SYSTEM32\SERVICES.EXE
                c:\windows\system32\services.exe

                c:\windows\system32\ntdll.dll

                c:\windows\system32\kernel32.dll

                c:\windows\system32\advapi32.dll

                c:\windows\system32\rpcrt4.dll

                c:\windows\system32\secur32.dll

                c:\windows\system32\msvcrt.dll

                c:\windows\system32\ncobjapi.dll

                c:\windows\system32\msvcp60.dll

                c:\windows\system32\scesrv.dll

                c:\windows\system32\authz.dll

                c:\windows\system32\user32.dll

                c:\windows\system32\gdi32.dll

                c:\windows\system32\userenv.dll

                c:\windows\system32\umpnpmgr.dll

                c:\windows\system32\winsta.dll

                c:\windows\system32\netapi32.dll

                c:\windows\system32\shimeng.dll

                c:\windows\apppatch\acadproc.dll

                c:\windows\system32\imm32.dll

                c:\windows\system32\apphelp.dll

                c:\windows\system32\version.dll

                c:\windows\system32\eventlog.dll

                c:\windows\system32\psapi.dll

                c:\windows\system32\ws2_32.dll

                c:\windows\system32\ws2help.dll

                c:\windows\system32\wtsapi32.dll

                C:\WINDOWS\SYSTEM32\LSASS.EXE
                c:\windows\system32\lsass.exe

                c:\windows\system32\ntdll.dll

                c:\windows\system32\kernel32.dll

                c:\windows\system32\advapi32.dll

                c:\windows\system32\rpcrt4.dll

                c:\windows\system32\secur32.dll

                c:\windows\system32\lsasrv.dll

                c:\windows\system32\mpr.dll

                c:\windows\system32\user32.dll

                c:\windows\system32\gdi32.dll

                c:\windows\system32\msasn1.dll

                c:\windows\system32\msvcrt.dll

                c:\windows\system32\netapi32.dll

                c:\windows\system32\ntdsapi.dll

                c:\windows\system32\dnsapi.dll

                c:\windows\system32\ws2_32.dll

                c:\windows\system32\ws2help.dll

                c:\windows\system32\wldap32.dll

                c:\windows\system32\samlib.dll

                c:\windows\system32\samsrv.dll

                c:\windows\system32\cryptdll.dll

                c:\windows\system32\shimeng.dll

                c:\windows\apppatch\acgenral.dll

                c:\windows\system32\winmm.dll

                c:\windows\system32\ole32.dll

                c:\windows\system32\oleaut32.dll

                c:\windows\system32\msacm32.dll

                c:\windows\system32\version.dll

                c:\windows\system32\shell32.dll

                c:\windows\system32\shlwapi.dll

                c:\windows\system32\userenv.dll

                c:\windows\system32\uxtheme.dll

                c:\windows\system32\imm32.dll

                c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll

                c:\windows\system32\comctl32.dll

                c:\windows\system32\msprivs.dll

                c:\windows\system32\kerberos.dll

                c:\windows\system32\msv1_0.dll

                c:\windows\system32\iphlpapi.dll

                c:\windows\system32\netlogon.dll

                c:\windows\system32\w32time.dll

                c:\windows\system32\msvcp60.dll

                c:\windows\system32\schannel.dll

                c:\windows\system32\crypt32.dll

                c:\windows\system32\wdigest.dll

                c:\windows\system32\rsaenh.dll

                c:\windows\system32\relog_ap.dll

                c:\windows\system32\setupapi.dll

                c:\windows\system32\scecli.dll

                c:\windows\system32\ipsecsvc.dll

                c:\windows\system32\authz.dll

                c:\windows\system32\oakley.dll

                c:\windows\system32\winipsec.dll

                c:\windows\system32\pstorsvc.dll

                c:\windows\system32\psbase.dll

                c:\windows\system32\mswsock.dll

                c:\windows\system32\hnetcfg.dll

                c:\windows\system32\wshtcpip.dll

                c:\windows\system32\dssenh.dll

                C:\WINDOWS\SYSTEM32\SVCHOST.EXE
                c:\windows\system32\svchost.exe

                c:\windows\system32\ntdll.dll

                c:\windows\system32\kernel32.dll

                c:\windows\system32\advapi32.dll

                c:\windows\system32\rpcrt4.dll

                c:\windows\system32\secur32.dll

                c:\windows\system32\shimeng.dll

                c:\windows\apppatch\acgenral.dll

                c:\windows\system32\user32.dll

                c:\windows\system32\gdi32.dll

                c:\windows\system32\winmm.dll

                c:\windows\system32\ole32.dll

                c:\windows\system32\msvcrt.dll

                c:\windows\system32\oleaut32.dll

                c:\windows\system32\msacm32.dll

                c:\windows\system32\version.dll

                c:\windows\system32\shell32.dll

                c:\windows\system32\shlwapi.dll

                c:\windows\system32\userenv.dll

                c:\windows\system32\uxtheme.dll

                c:\windows\system32\imm32.dll

                c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll

                c:\windows\system32\comctl32.dll

                c:\windows\system32\ntmarta.dll

                c:\windows\system32\samlib.dll

                c:\windows\system32\wldap32.dll

                c:\windows\system32\rpcss.dll

                c:\windows\system32\ws2_32.dll

                c:\windows\system32\ws2help.dll

                c:\windows\system32\xpsp2res.dll

                c:\windows\system32\clbcatq.dll

                c:\windows\system32\comres.dll

                c:\windows\system32\termsrv.dll

                c:\windows\system32\icaapi.dll

                c:\windows\system32\setupapi.dll

                c:\windows\system32\wintrust.dll

                c:\windows\system32\crypt32.dll

                c:\windows\system32\msasn1.dll

                c:\windows\system32\imagehlp.dll

                c:\windows\system32\authz.dll

                c:\windows\system32\mstlsapi.dll

                c:\windows\system32\activeds.dll

                c:\windows\system32\adsldpc.dll

                c:\windows\system32\netapi32.dll

                c:\windows\system32\atl.dll

                c:\windows\system32\regapi.dll

                c:\windows\system32\rsaenh.dll

                c:\windows\system32\apphelp.dll

                c:\windows\system32\svchost.exe

                c:\windows\system32\ntdll.dll

                c:\windows\system32\kernel32.dll

                c:\windows\system32\advapi32.dll

                c:\windows\system32\rpcrt4.dll

                c:\windows\system32\secur32.dll

                c:\windows\system32\shimeng.dll

                c:\windows\apppatch\acgenral.dll

                c:\windows\system32\user32.dll

                c:\windows\system32\gdi32.dll

                c:\windows\system32\winmm.dll

                c:\windows\system32\ole32.dll

                c:\windows\system32\msvcrt.dll

                c:\windows\system32\oleaut32.dll

                c:\windows\system32\msacm32.dll

                c:\windows\system32\version.dll

                c:\windows\system32\shell32.dll

                c:\windows\system32\shlwapi.dll

                c:\windows\system32\userenv.dll

                c:\windows\system32\uxtheme.dll

                c:\windows\system32\imm32.dll

                c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll

                c:\windows\system32\comctl32.dll

                c:\windows\system32\rpcss.dll

                c:\windows\system32\ws2_32.dll

                c:\windows\system32\ws2help.dll

                c:\windows\system32\xpsp2res.dll

                c:\windows\system32\rsaenh.dll

                c:\windows\system32\mswsock.dll

                c:\windows\system32\hnetcfg.dll

                c:\windows\system32\wshtcpip.dll

                c:\windows\system32\dnsapi.dll

                c:\windows\system32\iphlpapi.dll

                c:\windows\system32\winrnr.dll

                c:\windows\system32\wldap32.dll

                c:\windows\system32\rasadhlp.dll

                c:\windows\system32\clbcatq.dll

                c:\windows\system32\comres.dll

                c:\windows\system32\svchost.exe

                c:\windows\system32\ntdll.dll

                c:\windows\system32\kernel32.dll

                c:\windows\system32\advapi32.dll

                c:\windows\system32\rpcrt4.dll

                c:\windows\system32\secur32.dll

                c:\windows\system32\shimeng.dll

                c:\windows\apppatch\acgenral.dll

                c:\windows\system32\user32.dll

                c:\windows\system32\gdi32.dll

                c:\windows\system32\winmm.dll

                c:\windows\system32\ole32.dll

                c:\windows\system32\msvcrt.dll

                c:\windows\system32\oleaut32.dll

                c:\windows\system32\msacm32.dll

                c:\windows\system32\version.dll

                c:\windows\system32\shell32.dll

                c:\windows\system32\shlwapi.dll

                c:\windows\system32\userenv.dll

                c:\windows\system32\uxtheme.dll

                c:\windows\system32\imm32.dll

                c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll

                c:\windows\system32\comctl32.dll

                c:\windows\system32\ntmarta.dll

                c:\windows\system32\samlib.dll

                c:\windows\system32\wldap32.dll

                c:\windows\system32\xpsp2res.dll

                c:\windows\system32\shsvcs.dll

                c:\windows\system32\winsta.dll

                c:\windows\system32\netapi32.dll

                c:\windows\system32\dhcpcsvc.dll

                c:\windows\system32\dnsapi.dll

                c:\windows\system32\ws2_32.dll

                c:\windows\system32\ws2help.dll

                c:\windows\system32\iphlpapi.dll

                c:\windows\system32\mswsock.dll

                c:\windows\system32\hnetcfg.dll

                c:\windows\system32\wshtcpip.dll

                c:\windows\system32\rsaenh.dll

                c:\windows\system32\wzcsvc.dll

                c:\windows\system32\rtutils.dll

                c:\windows\system32\wmi.dll

                c:\windows\system32\crypt32.dll

                c:\windows\system32\msasn1.dll

                c:\windows\system32\eapolqec.dll

                c:\windows\system32\atl.dll

                c:\windows\system32\qutil.dll

                c:\windows\system32\msvcp60.dll

                c:\windows\system32\dot3api.dll

                c:\windows\system32\wtsapi32.dll

                c:\windows\system32\esent.dll

                c:\windows\system32\clbcatq.dll

                c:\windows\system32\comres.dll

                c:\windows\system32\rastls.dll

                c:\windows\system32\cryptui.dll

                c:\windows\system32\wininet.dll

                c:\windows\system32\normaliz.dll

                c:\windows\system32\iertutil.dll

                c:\windows\system32\wintrust.dll

                c:\windows\system32\imagehlp.dll

                c:\windows\system32\mprapi.dll

                c:\windows\system32\activeds.dll

                c:\windows\system32\adsldpc.dll

                c:\windows\system32\setupapi.dll

                c:\windows\system32\rasapi32.dll

                c:\windows\system32\rasman.dll

                c:\windows\system32\tapi32.dll

                c:\windows\system32\schannel.dll

                c:\windows\system32\winscard.dll

                c:\windows\system32\psapi.dll

                c:\windows\system32\raschap.dll

                c:\windows\system32\msv1_0.dll

                c:\windows\system32\schedsvc.dll

                c:\windows\system32\ntdsapi.dll

                c:\windows\system32\msidle.dll

                c:\windows\system32\audiosrv.dll

                c:\windows\system32\wkssvc.dll

                c:\windows\system32\qmgr.dll

                c:\windows\system32\mpr.dll

                c:\windows\system32\shfolder.dll

                c:\windows\system32\winhttp.dll

                c:\windows\system32\dmserver.dll

                c:\windows\system32\cryptsvc.dll

                c:\windows\system32\certcli.dll

                c:\windows\system32\ersvc.dll

                c:\windows\system32\es.dll

                c:\windows\pchealth\helpctr\binaries\pchsvc.dll

                c:\windows\system32\hidserv.dll

                c:\windows\system32\hid.dll

                c:\windows\system32\srvsvc.dll

                c:\windows\system32\netman.dll

                c:\windows\system32\netshell.dll

                c:\windows\system32\credui.dll

                c:\windows\system32\dot3dlg.dll

                c:\windows\system32\onex.dll

                c:\windows\system32\eappcfg.dll

                c:\windows\system32\eappprxy.dll

                c:\windows\system32\wzcsapi.dll

                c:\windows\system32\seclogon.dll

                c:\windows\system32\srsvc.dll

                c:\windows\system32\powrprof.dll

                c:\windows\system32\trkwks.dll

                c:\windows\system32\w32time.dll

                c:\windows\system32\wbem\wmisvc.dll

                c:\windows\system32\vssapi.dll

                c:\windows\system32\browser.dll

                c:\windows\system32\sens.dll

                c:\windows\system32\wuauserv.dll

                c:\windows\system32\ipnathlp.dll

                c:\windows\system32\authz.dll

                c:\windows\system32\wuaueng.dll

                c:\windows\system32\winspool.drv

                c:\windows\system32\cabinet.dll

                c:\windows\system32\mspatcha.dll

                c:\windows\system32\wscsvc.dll

                c:\windows\system32\msi.dll

                c:\windows\system32\wbem\wbemcomn.dll

                c:\windows\system32\wbem\wbemcore.dll

                c:\windows\system32\wbem\esscli.dll

                c:\windows\system32\wbem\fastprox.dll

                c:\windows\system32\sxs.dll

                c:\windows\system32\sfc.dll

                c:\windows\system32\sfc_os.dll

                c:\windows\system32\comsvcs.dll

                c:\windows\system32\colbact.dll

                c:\windows\system32\mtxclu.dll

                c:\windows\system32\wsock32.dll

                c:\windows\system32\clusapi.dll

                c:\windows\system32\resutils.dll

                c:\windows\system32\wbem\wmiutils.dll

                c:\windows\system32\wbem\repdrvfs.dll

                c:\windows\system32\wbem\wmiprvsd.dll

                c:\windows\system32\ncobjapi.dll

                c:\windows\system32\wbem\wbemess.dll

                c:\windows\system32\tapisrv.dll

                c:\windows\system32\rasmans.dll

                c:\windows\system32\winipsec.dll

                c:\windows\system32\netcfgx.dll

                c:\windows\system32\rastapi.dll

                c:\windows\system32\unimdm.tsp

                c:\windows\system32\uniplat.dll

                c:\windows\system32\rasadhlp.dll

                c:\windows\system32\kmddsp.tsp

                c:\windows\system32\ndptsp.tsp

                c:\windows\system32\ipconf.tsp

                c:\windows\system32\wbem\ncprov.dll

                c:\windows\system32\h323.tsp

                c:\windows\system32\hidphone.tsp

                c:\windows\system32\rasppp.dll

                c:\windows\system32\ntlsapi.dll

                c:\windows\system32\kerberos.dll

                c:\windows\system32\cryptdll.dll

                c:\windows\system32\rasdlg.dll

                c:\windows\system32\rasqec.dll

                c:\windows\system32\msxml3.dll

                c:\windows\system32\apphelp.dll

                c:\windows\system32\dssenh.dll

                c:\windows\system32\winrnr.dll

                c:\windows\system32\catsrvut.dll

                c:\windows\system32\catsrv.dll

                c:\windows\system32\mfcsubs.dll

                c:\windows\system32\urlmon.dll

                c:\windows\system32\wbem\wbemcons.dll

                c:\windows\system32\svchost.exe

                c:\windows\system32\ntdll.dll

                c:\windows\system32\kernel32.dll

                c:\windows\system32\advapi32.dll

                c:\windows\system32\rpcrt4.dll

                c:\windows\system32\secur32.dll

                c:\windows\system32\shimeng.dll

                c:\windows\apppatch\acgenral.dll

                c:\windows\system32\user32.dll

                c:\windows\system32\gdi32.dll

                c:\windows\system32\winmm.dll

                c:\windows\system32\ole32.dll

                c:\windows\system32\msvcrt.dll

                c:\windows\system32\oleaut32.dll

                c:\windows\system32\msacm32.dll

                c:\windows\system32\version.dll

                c:\windows\system32\shell32.dll

                c:\windows\system32\shlwapi.dll

                c:\windows\system32\userenv.dll

                c:\windows\system32\uxtheme.dll

                c:\windows\system32\imm32.dll

                c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll

                c:\windows\system32\comctl32.dll

                c:\windows\system32\dnsrslvr.dll

                c:\windows\system32\dnsapi.dll

                c:\windows\system32\ws2_32.dll

                c:\windows\system32\ws2help.dll

                c:\windows\system32\iphlpapi.dll

                c:\windows\system32\rsaenh.dll

                c:\windows\system32\mswsock.dll

                c:\windows\system32\hnetcfg.dll

                c:\windows\system32\wshtcpip.dll

                c:\windows\system32\svchost.exe

                c:\windows\system32\ntdll.dll

                c:\windows\system32\kernel32.dll

                c:\windows\system32\advapi32.dll

                c:\windows\system32\rpcrt4.dll

                c:\windows\system32\secur32.dll

                c:\windows\system32\shimeng.dll

                c:\windows\apppatch\acgenral.dll

                c:\windows\system32\user32.dll

                c:\windows\system32\gdi32.dll

                c:\windows\system32\winmm.dll

                c:\windows\system32\ole32.dll

                c:\windows\system32\msvcrt.dll

                c:\windows\system32\oleaut32.dll

                c:\windows\system32\msacm32.dll

                c:\windows\system32\version.dll

                c:\windows\system32\shell32.dll

                c:\windows\system32\shlwapi.dll

                c:\windows\system32\userenv.dll

                c:\windows\system32\uxtheme.dll

                c:\windows\system32\imm32.dll

                c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll

                c:\windows\system32\comctl32.dll

                c:\windows\system32\ntmarta.dll

                c:\windows\system32\samlib.dll

                c:\windows\system32\wldap32.dll

                c:\windows\system32\xpsp2res.dll

                c:\windows\system32\lmhsvc.dll

                c:\windows\system32\iphlpapi.dll

                c:\windows\system32\ws2_32.dll

                c:\windows\system32\ws2help.dll

                c:\windows\system32\webclnt.dll

                c:\windows\system32\wininet.dll

                c:\windows\system32\normaliz.dll

                c:\windows\system32\iertutil.dll

                c:\windows\system32\regsvc.dll

                C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASWUPDSV.EXE
                c:\program files\alwil software\avast4\aswupdsv.exe

                c:\windows\system32\ntdll.dll

                c:\windows\system32\kernel32.dll

                c:\program files\alwil software\avast4\aswcmns.dll

                c:\program files\alwil software\avast4\aswcmnos.dll

                c:\windows\system32\user32.dll

                c:\windows\system32\gdi32.dll

                c:\windows\system32\advapi32.dll

                c:\windows\system32\rpcrt4.dll

                c:\windows\system32\secur32.dll

                c:\windows\system32\msvcp71.dll

                c:\windows\system32\msvcr71.dll

                c:\windows\system32\wsock32.dll

                c:\windows\system32\ws2_32.dll

                c:\windows\system32\msvcrt.dll

                c:\windows\system32\ws2help.dll

                c:\program files\alwil software\avast4\aswcmnb.dll

                c:\windows\system32\imm32.dll

                C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHSERV.EXE
                c:\program files\alwil software\avast4\ashserv.exe

                c:\windows\system32\ntdll.dll

                c:\windows\system32\kernel32.dll

                c:\windows\system32\rpcrt4.dll

                c:\windows\system32\advapi32.dll

                c:\windows\system32\secur32.dll

                c:\program files\alwil software\avast4\aswaux.dll

                c:\windows\system32\msvcp71.dll

                c:\windows\system32\msvcr71.dll

                c:\program files\alwil software\avast4\aswcmnb.dll

                c:\program files\alwil software\avast4\aswcmnos.dll

                c:\windows\system32\user32.dll

                c:\windows\system32\gdi32.dll

                c:\windows\system32\wsock32.dll

                c:\windows\system32\ws2_32.dll

                c:\windows\system32\msvcrt.dll

                c:\windows\system32\ws2help.dll

                c:\program files\alwil software\avast4\aswengin.dll

                c:\program files\alwil software\avast4\aswscan.dll

                c:\program files\alwil software\avast4\aswcmns.dll

                c:\program files\alwil software\avast4\ashbase.dll

                c:\windows\system32\version.dll

                c:\program files\alwil software\avast4\ashtask.dll

                c:\program files\alwil software\avast4\aswinteg.dll

                c:\program files\alwil software\avast4\aswidle.dll

                c:\program files\alwil software\avast4\aavm4h.dll

                c:\windows\system32\imm32.dll

                c:\windows\system32\dbghelp.dll

                c:\program files\alwil software\avast4\french\base.dll

                c:\windows\system32\wtsapi32.dll

                c:\windows\system32\winsta.dll

                c:\windows\system32\netapi32.dll

                c:\program files\alwil software\avast4\ahresmai.dll

                c:\program files\alwil software\avast4\ahresmes.dll

                c:\program files\alwil software\avast4\ahresns.dll

                c:\program files\alwil software\avast4\ahresout.dll

                c:\program files\alwil software\avast4\ahresp2p.dll

                c:\program files\alwil software\avast4\ahresstd.dll

                c:\program files\alwil software\avast4\ahresws.dll

                c:\program files\alwil software\avast4\ashsodbc.dll

                c:\windows\system32\ole32.dll

                c:\windows\system32\odbc32.dll

                c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll

                c:\windows\system32\shlwapi.dll

                c:\windows\system32\comdlg32.dll

                c:\windows\system32\shell32.dll

                c:\windows\system32\odbcint.dll

                c:\windows\system32\uxtheme.dll

                c:\windows\system32\odbccp32.dll

                c:\windows\system32\odbcjt32.dll

                c:\windows\system32\msjet40.dll

                c:\windows\system32\mswstr10.dll

                c:\windows\system32\oleaut32.dll

                c:\windows\system32\odbcji32.dll

                c:\windows\system32\msjter40.dll

                c:\windows\system32\msjint40.dll

                c:\windows\system32\clbcatq.dll

                c:\windows\system32\comres.dll

                c:\windows\system32\msjtes40.dll

                c:\windows\system32\vbajet32.dll

                c:\windows\system32\expsrv.dll

                c:\windows\system32\wbem\wbemprox.dll

                c:\windows\system32\wbem\wbemcomn.dll

                c:\windows\system32\xpsp2res.dll

                c:\windows\system32\msctfime.ime

                c:\windows\system32\perfos.dll

                c:\windows\system32\wbem\wbemsvc.dll

                c:\windows\system32\wbem\fastprox.dll

                c:\windows\system32\msvcp60.dll

                c:\windows\system32\ntdsapi.dll

                c:\windows\system32\dnsapi.dll

                c:\windows\system32\wldap32.dll

                c:\program files\alwil software\avast4\aswres.dll

                C:\PROGRAM FILES\ASUS\GAMEROSD\GAMEROSD.EXE
                c:\program files\asus\gamerosd\gamerosd.exe

                c:\windows\system32\ntdll.dll

                c:\windows\system32\kernel32.dll

                c:\windows\system32\winmm.dll

                c:\windows\system32\advapi32.dll

                c:\windows\system32\rpcrt4.dll

                c:\windows\system32\secur32.dll

                c:\windows\system32\gdi32.dll

                c:\windows\system32\user32.dll

                c:\windows\system32\ws2_32.dll

                c:\windows\system32\msvcrt.dll

                c:\windows\system32\ws2help.dll

                c:\windows\system32\setupapi.dll

                c:\windows\system32\mfc42.dll

                c:\windows\system32\shell32.dll

                c:\windows\system32\shlwapi.dll

                c:\windows\system32\ole32.dll

                c:\windows\system32\oleaut32.dll

                c:\windows\system32\imm32.dll

                c:\windows\system32\mfc42loc.dll

                c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll

                c:\windows\system32\comctl32.dll

                c:\windows\system32\uxtheme.dll

                c:\windows\system32\apphelp.dll

                c:\windows\system32\msctfime.ime

                c:\windows\system32\xpsp2res.dll

                c:\windows\system32\clbcatq.dll

                c:\windows\system32\comres.dll

                c:\windows\system32\version.dll

                c:\windows\system32\devenum.dll

                c:\windows\system32\wintrust.dll

                c:\windows\system32\crypt32.dll

                c:\windows\system32\msasn1.dll

                c:\windows\system32\imagehlp.dll

                c:\windows\system32\msdmo.dll

                c:\windows\system32\wdmaud.drv

                c:\windows\system32\msacm32.drv

                c:\windows\system32\msacm32.dll

                c:\windows\system32\midimap.dll

                c:\windows\system32\qcap.dll

                c:\windows\system32\msvfw32.dll

                c:\program files\asus\gamerosd\imagetransform.dll

                c:\windows\system32\quartz.dll

                c:\windows\system32\msctf.dll

                c:\windows\system32\ksproxy.ax

                c:\windows\system32\ksuser.dll

                c:\windows\system32\vidcap.ax

                c:\windows\system32\atl.dll

                c:\windows\system32\imaadp32.acm

                c:\windows\system32\msadp32.acm

                c:\windows\system32\msg711.acm

                c:\windows\system32\msgsm32.acm

                c:\windows\system32\tssoft32.acm

                c:\windows\system32\tsd32.dll

                c:\windows\system32\msg723.acm

                c:\windows\system32\msaud32.acm

                c:\windows\system32\sl_anet.acm

                c:\windows\system32\iac25_32.ax

                c:\windows\system32\l3codecp.acm

                c:\windows\system32\sirenacm.dll

                c:\windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\msvcr80.dll

                c:\windows\system32\dsound.dll

                c:\windows\system32\ddraw.dll

                c:\windows\system32\dciman32.dll

                c:\windows\system32\d3dim700.dll

                C:\WINDOWS\RTHDCPL.EXE
                c:\windows\rthdcpl.exe

                c:\windows\system32\ntdll.dll

                c:\windows\system32\kernel32.dll

                c:\windows\system32\dsound.dll

                c:\windows\system32\advapi32.dll

                c:\windows\system32\rpcrt4.dll

                c:\windows\system32\secur32.dll

                c:\windows\system32\msvcrt.dll

                c:\windows\system32\ole32.dll

                c:\windows\system32\gdi32.dll

                c:\windows\system32\user32.dll

                c:\windows\system32\version.dll

                c:\windows\system32\winmm.dll

                c:\windows\system32\hhctrl.ocx

                c:\windows\system32\shell32.dll

                c:\windows\system32\shlwapi.dll

                c:\windows\system32\comctl32.dll

                c:\windows\system32\oleaut32.dll

                c:\windows\system32\setupapi.dll

                c:\windows\system32\mpr.dll

                c:\windows\system32\winspool.drv

                c:\windows\system32\comdlg32.dll

                c:\windows\system32\imm32.dll

                c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll

                c:\windows\system32\mui\000c\hhctrlui.dll

                c:\windows\system32\uxtheme.dll

                c:\windows\system32\msctfime.ime

                c:\windows\system32\wintrust.dll

                c:\windows\system32\crypt32.dll

                c:\windows\system32\msasn1.dll

                c:\windows\system32\imagehlp.dll

                c:\windows\system32\wdmaud.drv

                c:\windows\system32\msacm32.drv

                c:\windows\system32\msacm32.dll

                c:\windows\system32\midimap.dll

                c:\windows\system32\msctf.dll

                c:\windows\system32\ksuser.dll

                C:\WINDOWS\SYSTEM32\RUNDLL32.EXE
                c:\windows\system32\rundll32.exe

                c:\windows\system32\ntdll.dll

                c:\windows\system32\kernel32.dll

                c:\windows\system32\msvcrt.dll

                c:\windows\system32\gdi32.dll

                c:\windows\system32\user32.dll

                c:\windows\system32\imagehlp.dll

                c:\windows\system32\shimeng.dll

                c:\windows\apppatch\acgenral.dll

                c:\windows\system32\advapi32.dll

                c:\windows\system32\rpcrt4.dll

                c:\windows\system32\secur32.dll

                c:\windows\system32\winmm.dll

                c:\windows\system32\ole32.dll

                c:\windows\system32\oleaut32.dll

                c:\windows\system32\msacm32.dll

                c:\windows\system32\version.dll

                c:\windows\system32\shell32.dll

                c:\windows\system32\shlwapi.dll

                c:\windows\system32\userenv.dll

                c:\windows\system32\uxtheme.dll

                c:\windows\system32\imm32.dll

                c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll

                c:\windows\system32\comctl32.dll

                c:\windows\system32\nvmctray.dll

                c:\windows\system32\nvapi.dll

                c:\windows\system32\setupapi.dll

                c:\windows\system32\msctfime.ime

                c:\windows\system32\nvrsfr.dll

                c:\windows\system32\msctf.dll

                C:\PROGRAM FILES\ACRONIS\TRUEIMAGEHOME\TRUEIMAGEMONITOR.EXE
                c:\program files\acronis\trueimagehome\trueimagemonitor.exe

                c:\windows\system32\ntdll.dll

                c:\windows\system32\kernel32.dll

                c:\windows\system32\advapi32.dll

                c:\windows\system32\rpcrt4.dll

                c:\windows\system32\secur32.dll

                c:\windows\system32\user32.dll

                c:\windows\system32\gdi32.dll

                c:\windows\system32\shell32.dll

                c:\windows\system32\msvcrt.dll

                c:\windows\system32\shlwapi.dll

                c:\windows\system32\comdlg32.dll

                c:\windows\system32\comctl32.dll

                c:\windows\system32\mpr.dll

                c:\windows\system32\ole32.dll

                c:\windows\system32\version.dll

                c:\windows\system32\msvcp71.dll

                c:\windows\system32\msvcr71.dll

                c:\windows\system32\snapapi.dll

                c:\windows\system32\oleaut32.dll

                c:\windows\system32\imm32.dll

                c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll

                c:\program files\fichiers communs\acronis\common\resource.dll

                c:\program files\fichiers communs\acronis\common\gc.dll

                c:\windows\system32\uxtheme.dll

                c:\windows\system32\apphelp.dll

                c:\windows\system32\msctfime.ime

                c:\windows\system32\rsaenh.dll

                c:\windows\system32\msctf.dll

                c:\program files\fichiers communs\acronis\fomatik\tdrpapi.dll

                c:\windows\system32\ntmarta.dll

                c:\windows\system32\samlib.dll

                c:\windows\system32\wldap32.dll

                c:\program files\fichiers communs\acronis\common\rpc_client.dll

                C:\PROGRAM FILES\ACRONIS\TRUEIMAGEHOME\TIMOUNTERMONITOR.EXE
                c:\program files\acronis\trueimagehome\timountermonitor.exe

                c:\windows\system32\ntdll.dll

                c:\windows\system32\kernel32.dll

                c:\program files\acronis\trueimagehome\fox.dll

                c:\windows\system32\advapi32.dll

                c:\windows\system32\rpcrt4.dll

                c:\windows\system32\secur32.dll

                c:\windows\system32\user32.dll

                c:\windows\system32\gdi32.dll

                c:\windows\system32\comctl32.dll

                c:\windows\system32\shell32.dll

                c:\windows\system32\msvcrt.dll

                c:\windows\system32\shlwapi.dll

                c:\windows\system32\comdlg32.dll

                c:\windows\system32\msvcp71.dll

                c:\windows\system32\msvcr71.dll

                c:\windows\system32\mpr.dll

                c:\windows\system32\ole32.dll

                c:\windows\system32\version.dll

                c:\windows\system32\imm32.dll

                c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll

                c:\windows\system32\hhctrl.ocx

                c:\windows\system32\oleaut32.dll

                c:\windows\system32\mui\000c\hhctrlui.dll

                c:\windows\system32\msimg32.dll

                c:\program files\fichiers communs\acronis\common\icu34.dll

                c:\program files\fichiers communs\acronis\common\icudt34.dll

                c:\windows\system32\uxtheme.dll

                c:\windows\system32\apphelp.dll

                c:\windows\system32\msctfime.ime

                c:\windows\system32\msctf.dll

                C:\PROGRAM FILES\FICHIERS COMMUNS\ACRONIS\SCHEDULE2\SCHEDHLP.EXE
                c:\program files\fichiers communs\acronis\schedule2\schedhlp.exe

                c:\windows\system32\ntdll.dll

                c:\windows\system32\kernel32.dll

                c:\windows\system32\rpcrt4.dll

                c:\windows\system32\advapi32.dll

                c:\windows\system32\secur32.dll

                c:\windows\system32\user32.dll

                c:\windows\system32\gdi32.dll

                c:\windows\system32\shell32.dll

                c:\windows\system32\msvcrt.dll

                c:\windows\system32\shlwapi.dll

                c:\windows\system32\comdlg32.dll

                c:\windows\system32\comctl32.dll

                c:\windows\system32\version.dll

                c:\windows\system32\imm32.dll

                c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll

                c:\windows\system32\uxtheme.dll

                c:\windows\system32\apphelp.dll

                c:\windows\system32\msctfime.ime

                c:\windows\system32\ole32.dll

                c:\windows\system32\msctf.dll

                C:\WINDOWS\SYSTEM32\CTFMON.EXE
                c:\windows\system32\ctfmon.exe

                c:\windows\system32\ntdll.dll

                c:\windows\system32\kernel32.dll

                c:\windows\system32\msvcrt.dll

                c:\windows\system32\advapi32.dll

                c:\windows\system32\rpcrt4.dll

                c:\windows\system32\secur32.dll

                c:\windows\system32\user32.dll

                c:\windows\system32\gdi32.dll

                c:\windows\system32\msctf.dll

                c:\windows\system32\msutb.dll

                c:\windows\system32\shimeng.dll

                c:\windows\apppatch\acgenral.dll

                c:\windows\system32\winmm.dll

                c:\windows\system32\ole32.dll

                c:\windows\system32\oleaut32.dll

                c:\windows\system32\msacm32.dll

                c:\windows\system32\version.dll

                c:\windows\system32\shell32.dll

                c:\windows\system32\shlwapi.dll

                c:\windows\system32\userenv.dll

                c:\windows\system32\uxtheme.dll

                c:\windows\system32\imm32.dll

                c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll

                c:\windows\system32\msctfime.ime

                C:\PROGRAM FILES\WINDOWS LIVE\MESSENGER\MSNMSGR.EXE
                c:\program files\windows live\messenger\msnmsgr.exe

                c:\windows\system32\ntdll.dll

                c:\windows\system32\kernel32.dll

                c:\windows\system32\advapi32.dll

                c:\windows\system32\rpcrt4.dll

                c:\windows\system32\secur32.dll

                c:\windows\system32\gdi32.dll

                c:\windows\system32\user32.dll

                c:\windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\msvcr80.dll

                c:\windows\system32\msvcrt.dll

                c:\windows\system32\wsock32.dll

                c:\windows\system32\ws2_32.dll

                c:\windows\system32\ws2help.dll

                c:\windows\system32\shell32.dll

                c:\windows\system32\shlwapi.dll

                c:\windows\system32\ole32.dll

                c:\windows\system32\oleaut32.dll

                c:\windows\system32\msimg32.dll

                c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.2600.5512_x-ww_dfb54e0c\gdiplus.dll

                c:\program files\windows live\messenger\msncore.dll

                c:\windows\system32\urlmon.dll

                c:\windows\system32\iertutil.dll

                c:\windows\system32\wininet.dll

                c:\windows\system32\normaliz.dll

                c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll

                c:\windows\system32\oleacc.dll

                c:\windows\system32\msvcp60.dll

                c:\windows\system32\uxtheme.dll

                c:\windows\system32\imm32.dll

                c:\windows\system32\crypt32.dll

                c:\windows\system32\msasn1.dll

                c:\windows\system32\version.dll

                c:\windows\system32\winmm.dll

                c:\windows\system32\iphlpapi.dll

                c:\windows\system32\msacm32.dll

                c:\program files\windows live\messenger\msidcrl40.dll

                c:\windows\system32\sensapi.dll

                c:\windows\system32\psapi.dll

                c:\windows\system32\wintrust.dll

                c:\windows\system32\imagehlp.dll

                c:\program files\windows live\messenger\contactsux.dll

                c:\windows\system32\setupapi.dll

                c:\windows\system32\cryptnet.dll

                c:\windows\system32\userenv.dll

                c:\windows\system32\winhttp.dll

                c:\windows\system32\wldap32.dll

                c:\windows\system32\msctf.dll

                c:\windows\system32\xpsp2res.dll

                c:\windows\system32\rsaenh.dll

                c:\windows\system32\inetcomm.dll

                c:\windows\system32\msoert2.dll

                c:\windows\system32\inetres.dll

                c:\windows\system32\clbcatq.dll

                c:\windows\system32\comres.dll

                c:\program files\windows live\messenger\msgslang.8.5.1302.1018.dll

                c:\program files\windows live\messenger\msgsres.dll

                c:\windows\system32\apphelp.dll

                c:\windows\system32\msctfime.ime

                c:\windows\system32\wtsapi32.dll

                c:\windows\system32\winsta.dll

                c:\windows\system32\netapi32.dll

                c:\windows\system32\es.dll

                c:\windows\system32\sxs.dll

                c:\program files\windows live\messenger\msgswcam.dll

                c:\windows\system32\sirenacm.dll

                c:\windows\system32\devenum.dll

                c:\windows\system32\msdmo.dll

                c:\windows\system32\ksproxy.ax

                c:\windows\system32\ksuser.dll

                c:\windows\system32\vidcap.ax

                c:\windows\system32\atl.dll

                c:\windows\system32\riched20.dll

                c:\windows\system32\msimtf.dll

                C:\WINDOWS\SYSTEM32\SPOOLSV.EXE
                c:\windows\system32\spoolsv.exe

                c:\windows\system32\ntdll.dll

                c:\windows\system32\kernel32.dll

                c:\windows\system32\advapi32.dll

                c:\windows\system32\rpcrt4.dll

                c:\windows\system32\secur32.dll

                c:\windows\system32\gdi32.dll

                c:\windows\system32\user32.dll

                c:\windows\system32\msvcrt.dll

                c:\windows\system32\shimeng.dll

                c:\windows\apppatch\acgenral.dll

                c:\windows\system32\winmm.dll

                c:\windows\system32\ole32.dll

                c:\windows\system32\oleaut32.dll

                c:\windows\system32\msacm32.dll

                c:\windows\system32\version.dll

                c:\windows\system32\shell32.dll

                c:\windows\system32\shlwapi.dll

                c:\windows\system32\userenv.dll

                c:\windows\system32\uxtheme.dll

                c:\windows\system32\imm32.dll

                c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll

                c:\windows\system32\comctl32.dll

                c:\windows\system32\spoolss.dll

                c:\windows\system32\ws2_32.dll

                c:\windows\system32\ws2help.dll

                c:\windows\system32\dnsapi.dll

                c:\windows\system32\rasadhlp.dll

                c:\windows\system32\localspl.dll

                c:\windows\system32\sfc_os.dll

                c:\windows\system32\wintrust.dll

                c:\windows\system32\crypt32.dll

                c:\windows\system32\msasn1.dll

                c:\windows\system32\imagehlp.dll

                c:\windows\system32\winspool.drv

                c:\windows\system32\netapi32.dll

                c:\windows\system32\cnbjmon.dll

                c:\windows\system32\mdimon.dll

                c:\windows\system32\msi.dll

                c:\windows\system32\pjlmon.dll

                c:\windows\system32\tcpmon.dll

                c:\windows\system32\usbmon.dll

                c:\windows\system32\spool\prtprocs\w32x86\mdippr.dll

                c:\windows\system32\mswsock.dll

                c:\windows\system32\winrnr.dll

                c:\windows\system32\wldap32.dll

                c:\windows\system32\win32spl.dll

                c:\windows\system32\netrap.dll

                c:\windows\system32\ntdsapi.dll

                c:\windows\system32\clbcatq.dll

                c:\windows\system32\comres.dll

                c:\windows\system32\inetpp.dll

                c:\windows\system32\xpsp2res.dll

                C:\PROGRAM FILES\FICHIERS COMMUNS\ACRONIS\SCHEDULE2\SCHEDUL2.EXE
                c:\program files\fichiers communs\acronis\schedule2\schedul2.exe

                c:\windows\system32\ntdll.dll

                c:\windows\system32\kernel32.dll

                c:\windows\system32\rpcrt4.dll

                c:\windows\system32\advapi32.dll

                c:\windows\system32\secur32.dll

                c:\windows\system32\user32.dll

                c:\windows\system32\gdi32.dll

                c:\windows\system32\shell32.dll

                c:\windows\system32\msvcrt.dll

                c:\windows\system32\shlwapi.dll

                c:\windows\system32\comdlg32.dll

                c:\windows\system32\comctl32.dll

                c:\windows\system32\mpr.dll

                c:\windows\system32\ole32.dll

                c:\windows\system32\version.dll

                c:\windows\system32\imm32.dll

                c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll

                c:\windows\system32\ntmarta.dll

                c:\windows\system32\samlib.dll

                c:\windows\system32\wldap32.dll

                C:\PROGRAM FILES\FICHIERS COMMUNS\APPLE\MOBILE DEVICE SUPPORT\BIN\APPLEMOBILEDEVICESERVICE.EXE
                c:\program files\fichiers communs\apple\mobile device support\bin\applemobiledeviceservice.exe

                c:\windows\system32\ntdll.dll

                c:\windows\system32\kernel32.dll

                c:\windows\system32\wsock32.dll

                c:\windows\system32\ws2_32.dll

                c:\windows\system32\advapi32.dll

                c:\windows\system32\rpcrt4.dll

                c:\windows\system32\secur32.dll

                c:\windows\system32\msvcrt.dll

                c:\windows\system32\ws2help.dll

                c:\windows\system32\setupapi.dll

                c:\windows\system32\gdi32.dll

                c:\windows\system32\user32.dll

                c:\windows\system32\imm32.dll

                c:\windows\system32\mswsock.dll

                c:\windows\system32\hnetcfg.dll

                c:\windows\system32\wshtcpip.dll

                c:\windows\system32\wintrust.dll

                c:\windows\system32\crypt32.dll

                c:\windows\system32\msasn1.dll

                c:\windows\system32\imagehlp.dll

                C:\WINDOWS\ATKKBSERVICE.EXE
                c:\windows\atkkbservice.exe

                c:\windows\system32\ntdll.dll

                c:\windows\system32\kernel32.dll

                c:\windows\system32\advapi32.dll

                c:\windows\system32\rpcrt4.dll

                c:\windows\system32\secur32.dll

                c:\windows\system32\gdi32.dll

                c:\windows\system32\user32.dll

                c:\windows\system32\setupapi.dll

                c:\windows\system32\msvcrt.dll

                c:\windows\system32\imm32.dll

                c:\windows\system32\uxtheme.dll

                c:\windows\system32\msctfime.ime

                c:\windows\system32\ole32.dll

                c:\windows\system32\nvapi.dll

                c:\windows\system32\oleaut32.dll

                c:\windows\system32\shlwapi.dll

                c:\windows\system32\shell32.dll

                c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll

                c:\windows\system32\comctl32.dll

                C:\PROGRAM FILES\SYMANTEC\NORTON GHOST 2003\GHOSTSTARTSERVICE.EXE
                c:\program files\symantec\norton ghost 2003\ghoststartservice.exe

                c:\windows\system32\ntdll.dll

                c:\windows\system32\kernel32.dll

                c:\windows\system32\user32.dll

                c:\windows\system32\gdi32.dll

                c:\windows\system32\advapi32.dll

                c:\windows\system32\rpcrt4.dll

                c:\windows\system32\secur32.dll

                c:\windows\system32\ole32.dll

                c:\windows\system32\msvcrt.dll

                c:\windows\system32\oleaut32.dll

                c:\windows\system32\imm32.dll

                c:\windows\system32\uxtheme.dll

                c:\windows\system32\xpsp2res.dll

                c:\windows\system32\clbcatq.dll

                c:\windows\system32\comres.dll

                c:\windows\system32\version.dll

                C:\WINDOWS\SYSTEM32\NVSVC32.EXE
                c:\windows\system32\nvsvc32.exe

                c:\windows\system32\ntdll.dll

                c:\windows\system32\kernel32.dll

                c:\windows\system32\user32.dll

                c:\windows\system32\gdi32.dll

                c:\windows\system32\advapi32.dll

                c:\windows\system32\rpcrt4.dll

                c:\windows\system32\secur32.dll

                c:\windows\system32\userenv.dll

                c:\windows\system32\msvcrt.dll

                c:\windows\system32\powrprof.dll

                c:\windows\system32\imm32.dll

                c:\windows\system32\wtsapi32.dll

                c:\windows\system32\winsta.dll

                c:\windows\system32\netapi32.dll

                c:\windows\system32\shell32.dll

                c:\windows\system32\shlwapi.dll

                c:\windows\system32\ole32.dll

                c:\windows\system32\comctl32.dll

                c:\windows\system32\oleaut32.dll

                c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll

                c:\windows\system32\nvapi.dll

                c:\windows\system32\setupapi.dll

                c:\windows\system32\uxtheme.dll

                c:\windows\system32\msctfime.ime

                c:\windows\system32\wintrust.dll

                c:\windows\system32\crypt32.dll

                c:\windows\system32\msasn1.dll

                c:\windows\system32\imagehlp.dll

                c:\windows\system32\msv1_0.dll

                c:\windows\system32\iphlpapi.dll

                c:\windows\system32\ws2_32.dll

                c:\windows\system32\ws2help.dll

                c:\windows\system32\apphelp.dll

                c:\windows\system32\version.dll

                c:\windows\system32\ntmarta.dll

                c:\windows\system32\samlib.dll

                c:\windows\system32\wldap32.dll

                C:\PROGRAM FILES\SPYWARE TERMINATOR\SP_RSSER.EXE
                c:\program files\spyware terminator\sp_rsser.exe

                c:\windows\system32\ntdll.dll

                c:\windows\system32\kernel32.dll

                c:\windows\system32\oleaut32.dll
                0
            4. le fichier s est ouvert, par contre la connexion internet est beaucoup plus rapide, c est du a quoi?

              ComboFix 08-07-14.2 - reverend 2008-07-15 19:31:28.3 - NTFSx86
              Microsoft Windows XP Professionnel 5.1.2600.3.1252.1.1036.18.1583 [GMT 2:00]
              Endroit: C:\Documents and Settings\reverend\Bureau\garda.exe
              Command switches used :: C:\Documents and Settings\reverend\Bureau\CFscript.txt
              * Création d'un nouveau point de restauration

              [color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/b][/color]

              FILE ::
              C:\WINDOWS\system32\dsauth32.dll
              .

              (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
              .

              C:\WINDOWS\system32\dsauth32.dll

              .
              ((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-06-15 to 2008-07-15 ))))))))))))))))))))))))))))))))))))
              .

              2008-07-15 19:09 . 2008-07-15 19:09 <REP> d-------- C:\WINDOWS\ERUNT
              2008-07-15 18:10 . 2008-07-15 18:10 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
              2008-07-15 18:10 . 2008-07-15 18:10 <REP> d-------- C:\Documents and Settings\reverend\Application Data\Malwarebytes
              2008-07-15 18:10 . 2008-07-15 18:10 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
              2008-07-15 18:10 . 2008-07-07 17:35 34,296 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
              2008-07-15 18:10 . 2008-07-07 17:35 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys
              2008-07-15 17:51 . 2008-07-15 17:51 <REP> d-------- C:\Program Files\Panda Security
              2008-07-15 17:51 . 2008-06-19 17:24 28,544 --a------ C:\WINDOWS\system32\drivers\pavboot.sys
              2008-07-15 17:39 . 2008-07-15 17:46 <REP> d-------- C:\Program Files\Hijackthis Version Fran‡aise
              2008-07-15 08:08 . 2008-07-15 08:08 <REP> d-------- C:\Games
              2008-07-14 22:58 . 2008-07-14 22:58 268 --ah----- C:\sqmdata02.sqm
              2008-07-14 22:58 . 2008-07-14 22:58 244 --ah----- C:\sqmnoopt02.sqm
              2008-07-14 22:48 . 2008-07-15 19:31 <REP> d-------- C:\Documents and Settings\reverend\Bureau
              2008-07-14 22:47 . 2008-07-14 22:47 268 --ah----- C:\sqmdata01.sqm
              2008-07-14 22:47 . 2008-07-14 22:47 244 --ah----- C:\sqmnoopt01.sqm
              2008-07-14 22:08 . 2008-06-14 19:33 272,768 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
              2008-07-14 22:02 . 2008-05-08 16:02 203,136 -----c--- C:\WINDOWS\system32\dllcache\rmcast.sys
              2008-07-14 22:01 . 2008-07-15 08:22 <REP> d-------- C:\Program Files\Spyware Terminator
              2008-07-14 22:01 . 2008-07-14 22:02 <REP> d-------- C:\Program Files\Spybot - Search & Destroy
              2008-07-14 22:01 . 2008-07-15 08:22 <REP> d-------- C:\Documents and Settings\reverend\Application Data\Spyware Terminator
              2008-07-14 22:01 . 2008-07-14 22:16 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Spyware Terminator
              2008-07-14 22:01 . 2008-07-14 22:16 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
              2008-07-14 22:01 . 2008-07-14 22:01 141,312 --a------ C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
              2008-07-14 20:24 . 2008-07-14 20:24 <REP> d-------- C:\Documents and Settings\All Users\Application Data\nView_Profiles

              .
              (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
              .
              2008-07-15 17:33 713,301 ----a-w C:\WINDOWS\Internet Logs\tvDebug.zip
              2008-07-15 17:32 44,204 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
              2008-07-15 17:32 4,130,848 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
              2008-07-15 17:06 142,336 ----a-w C:\WINDOWS\Internet Logs\xDB4.tmp
              2008-07-15 16:10 --------- d-----w C:\Program Files\Lavasoft
              2008-07-15 15:46 --------- d-----w C:\Program Files\Hijackthis Version Française
              2008-07-15 11:41 196,608 ----a-w C:\WINDOWS\system32\drivers\nStandard.bin
              2008-07-15 06:08 0 ----a-w C:\Program Files\Installed.hid
              2008-07-14 20:03 --------- d-----w C:\Documents and Settings\reverend\Application Data\Lavasoft
              2008-06-14 17:33 272,768 ------w C:\WINDOWS\system32\drivers\bthport.sys
              2008-05-31 15:33 2,893,312 ----a-w C:\WINDOWS\Internet Logs\xDB2.tmp
              2008-05-31 15:33 1,420,288 ----a-w C:\WINDOWS\Internet Logs\xDB3.tmp
              2008-05-31 15:29 --------- d-----w C:\Documents and Settings\LocalService\Application Data\Acronis
              2008-05-31 15:27 --------- d-----w C:\Program Files\PowerQuest
              2008-05-31 15:26 441,760 ----a-w C:\WINDOWS\system32\drivers\timntr.sys
              2008-05-31 15:26 44,384 ----a-w C:\WINDOWS\system32\drivers\tifsfilt.sys
              2008-05-31 15:26 368,736 ----a-w C:\WINDOWS\system32\drivers\tdrpman.sys
              2008-05-31 15:26 129,248 ----a-w C:\WINDOWS\system32\drivers\snapman.sys
              2008-05-31 15:26 --------- d-----w C:\Program Files\Fichiers communs\Acronis
              2008-05-31 15:26 --------- d-----w C:\Documents and Settings\All Users\Application Data\Acronis
              2008-05-31 15:25 --------- d-----w C:\Program Files\Acronis
              2008-05-31 15:23 --------- d-----w C:\Program Files\Fichiers communs\Adobe
              2008-05-31 15:22 --------- d--h--w C:\Program Files\InstallShield Installation Information
              2008-05-31 15:19 --------- d-----w C:\Documents and Settings\All Users\Application Data\PowerQuest
              2008-05-31 09:21 27,262,976 ----a-w C:\VIRTPART.DAT
              2008-05-31 08:14 1,425,408 ----a-w C:\WINDOWS\Internet Logs\xDB1.tmp
              2008-05-31 07:54 --------- d-----w C:\Documents and Settings\All Users\Application Data\PokerAcademyPro2
              2008-05-31 07:50 --------- d-----w C:\Documents and Settings\reverend\Application Data\PokerAcademyPro2
              2008-05-31 07:04 --------- d-----w C:\Documents and Settings\reverend\Application Data\GrabIt
              2008-05-30 22:22 --------- d-----w C:\Program Files\Ubisoft
              2008-05-30 21:34 --------- d-----w C:\Documents and Settings\reverend\Application Data\InterTrust
              2008-05-30 21:26 --------- d-----w C:\Program Files\Alcohol Soft
              2008-05-30 21:08 737,280 ----a-w C:\WINDOWS\iun6002.exe
              2008-05-30 20:19 --------- d-----w C:\Program Files\QuickPar
              2008-05-30 20:18 --------- d-----w C:\Program Files\GrabIt
              2008-05-30 20:13 715,248 ----a-w C:\WINDOWS\system32\drivers\sptd.sys
              2008-05-30 19:20 --------- d-----w C:\Program Files\Symantec
              2008-05-30 19:20 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
              2008-05-30 19:19 --------- d-----w C:\Program Files\Fichiers communs\Symantec Shared
              2008-05-30 19:19 --------- d-----w C:\Documents and Settings\reverend\Application Data\Symantec
              2008-05-30 19:15 --------- d-----w C:\Program Files\Google
              2008-05-30 18:42 --------- d-----w C:\Program Files\Windows Live
              2008-05-30 18:41 --------- dcsh--w C:\Program Files\Fichiers communs\WindowsLiveInstaller
              2008-05-30 18:38 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
              2008-05-30 18:37 --------- d-----w C:\Documents and Settings\All Users\Application Data\MailFrontier
              2008-05-30 15:29 --------- d-----w C:\Program Files\Zone Labs
              2008-05-30 15:28 --------- d-----w C:\Program Files\SLD Codec Pack
              2008-05-30 15:27 --------- d-----w C:\Program Files\Jasc Software Inc
              2008-05-30 15:27 --------- d-----w C:\Program Files\Fichiers communs\Jasc Software Inc
              2008-05-30 15:27 --------- d-----w C:\Program Files\Fichiers communs\InstallShield
              2008-05-30 15:27 --------- d-----w C:\Documents and Settings\reverend\Application Data\Jasc Software Inc
              2008-05-30 15:27 --------- d-----w C:\Documents and Settings\All Users\Application Data\InstallShield
              2008-05-30 15:22 --------- d-----w C:\Program Files\Java Web Start
              2008-05-30 15:22 --------- d-----w C:\Program Files\Java
              2008-05-30 15:21 --------- d-----w C:\Program Files\Free.fr
              2008-05-30 15:06 --------- d-----w C:\Program Files\Winamp
              2008-05-30 15:04 --------- d-----w C:\Program Files\QuickTime
              2008-05-30 15:04 --------- d-----w C:\Program Files\iTunes
              2008-05-30 15:04 --------- d-----w C:\Program Files\iPod
              2008-05-30 15:04 --------- d-----w C:\Documents and Settings\reverend\Application Data\Apple Computer
              2008-05-30 15:04 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
              2008-05-30 15:03 --------- d-----w C:\Program Files\Fichiers communs\Apple
              2008-05-30 15:03 --------- d-----w C:\Program Files\Apple Software Update
              2008-05-30 15:03 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple
              2008-05-30 15:02 --------- d-----w C:\Program Files\RamBoost XP
              2008-05-30 15:02 --------- d-----w C:\Program Files\Easy CD-DA Extractor 10
              2008-05-30 15:01 --------- d-----w C:\Program Files\Alwil Software
              2008-05-30 15:00 --------- d-----w C:\Program Files\VideoLAN
              2008-05-30 15:00 --------- d-----w C:\Documents and Settings\reverend\Application Data\vlc
              2008-05-30 14:47 --------- d-----w C:\Program Files\Attansic
              2008-05-30 14:44 315,392 ----a-w C:\WINDOWS\HideWin.exe
              2008-05-30 14:44 --------- d-----w C:\Program Files\Realtek
              2008-05-30 14:37 --------- d-----w C:\Program Files\Intel
              2008-05-30 14:34 12,288 ----a-w C:\WINDOWS\system32\drivers\EIO64_xp.sys
              2008-05-30 14:34 --------- d-----w C:\Program Files\ASUS
              2008-05-30 12:36 --------- d-----w C:\Program Files\microsoft frontpage
              2008-05-30 12:34 --------- d-----w C:\Program Files\Services en ligne
              2006-06-23 22:48 32,768 ----a-r C:\WINDOWS\inf\UpdateUSB.exe
              .

              ((((((((((((((((((((((((((((( snapshot@2008-07-15_18.35.38.57 )))))))))))))))))))))))))))))))))))))))))
              .
              + 2008-07-14 21:41:58 163,328 ----a-w C:\WINDOWS\ERUNT\SDFIX\ERDNT.EXE
              + 2008-07-15 17:09:40 3,645,440 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\[u]0[/u]0000001\NTUSER.DAT
              + 2008-07-15 17:09:40 352,256 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\[u]0[/u]0000002\UsrClass.dat
              + 2008-07-14 21:41:58 163,328 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\ERDNT.EXE
              + 2008-07-15 17:09:31 3,645,440 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\[u]0[/u]0000001\NTUSER.DAT
              + 2008-07-15 17:09:31 352,256 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\[u]0[/u]0000002\UsrClass.dat
              + 2008-07-15 17:34:02 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_754.dat
              .
              ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
              .
              .
              REGEDIT4
              *Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s

              [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
              "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 04:33 15360]
              "msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 11:34 5724184]
              "SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]

              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
              "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2008-05-03 05:46 13529088]
              "ASUSGamerOSD"="C:\Program Files\ASUS\GamerOSD\GamerOSD.exe" [2007-10-23 17:48 380928]
              "JMB36X IDE Setup"="C:\WINDOWS\RaidTool\xInsIDE.exe" [2007-03-20 16:36 36864]
              "36X Raid Configurer"="C:\WINDOWS\system32\xRaidSetup.exe" [2007-03-21 18:23 1953792]
              "ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-04-02 21:07 919016]
              "NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2008-05-03 05:46 86016]
              "TrueImageMonitor.exe"="C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe" [2007-10-07 17:01 2620336]
              "AcronisTimounterMonitor"="C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe" [2007-10-07 17:36 904880]
              "Acronis Scheduler2 Service"="C:\Program Files\Fichiers communs\Acronis\Schedule2\schedhlp.exe" [2007-10-07 17:08 140568]
              "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-11-14 23:43 286720]
              "nwiz"="nwiz.exe" [2008-05-03 05:46 1630208 C:\WINDOWS\system32\nwiz.exe]
              "RTHDCPL"="RTHDCPL.EXE" [2007-03-21 16:49 16126464 C:\WINDOWS\RTHDCPL.exe]

              [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
              "CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2008-04-14 04:33 15360]

              [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
              "msacm.l3acm"= l3codecp.acm
              "vidc.asv2"= asusasv2.dll

              [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
              Authentication Packages REG_MULTI_SZ msv1_0 relog_ap

              [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
              @=""

              [HKLM\~\startupfolder\C:^Documents and Settings^reverend^Menu Démarrer^Programmes^Démarrage^Ubisoft register.lnk]
              path=C:\Documents and Settings\reverend\Menu Démarrer\Programmes\Démarrage\Ubisoft register.lnk
              backup=C:\WINDOWS\pss\Ubisoft register.lnkStartup

              [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcoholAutomount]
              --a------ 2007-12-22 09:20 222080 C:\Program Files\Alcohol Soft\Alcohol 120\AxCmd.exe

              [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUS SmartDoctor]
              --a------ 2008-01-22 11:52 1126400 C:\Program Files\ASUS\SmartDoctor\SmartDoctor.exe

              [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
              --a------ 2007-11-15 13:11 267048 C:\Program Files\iTunes\iTunesHelper.exe

              [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
              --a------ 2007-10-18 11:34 5724184 C:\Program Files\Windows Live\Messenger\msnmsgr.exe

              [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
              --a------ 2007-11-14 23:43 286720 C:\Program Files\QuickTime\QTTask.exe

              [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
              "DisableMonitoring"=dword:00000001

              [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
              "EnableFirewall"= 0 (0x0)

              [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
              "%windir%\\system32\\sessmgr.exe"=
              "C:\\Program Files\\iTunes\\iTunes.exe"=
              "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
              "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
              "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=

              [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
              "7423:TCP"= 7423:TCP:messenger
              "2831:TCP"= 2831:TCP:messenger

              R0 pavboot;pavboot;C:\WINDOWS\system32\drivers\pavboot.sys [2008-06-19 17:24]
              R0 tdrpman;Acronis Try&Decide and Restore Points filter;C:\WINDOWS\system32\DRIVERS\tdrpman.sys [2008-05-31 17:26]
              R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-05-16 01:20]
              R1 EIO_XP;EIO_XP;C:\WINDOWS\system32\drivers\EIO_XP.sys [2006-06-14 13:44]
              R1 GhPciScan;GhostPciScanner;C:\Program Files\Symantec\Norton Ghost 2003\ghpciscan.sys [2002-08-14 15:11]
              R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-05-16 01:16]
              R2 TryAndDecideService;Acronis Try And Decide Service;C:\Program Files\Fichiers communs\Acronis\Fomatik\TrueImageTryStartService.exe [2007-10-08 11:19]
              R3 asusgsb;ASUS Virtual Video Capture Device Driver;C:\WINDOWS\system32\drivers\asusgsb.sys [2007-10-23 17:48]
              R3 ASUSVRC;ASUSTeK Virtual Capture Device;C:\WINDOWS\system32\DRIVERS\AsusVRC.sys [2007-01-29 17:12]
              R3 AtcL001;NDIS Miniport Driver for Attansic L1 Gigabit Ethernet Controller;C:\WINDOWS\system32\DRIVERS\atl01_xp.sys [2007-03-15 16:12]
              R3 Video3D;ASUS Video3D Service;C:\WINDOWS\system32\Drivers\Video3D32.sys [2007-10-23 17:48]

              .
              - - - - ORPHANS REMOVED - - - -

              Notify-dsauth32 - dsauth32.dll

              **************************************************************************

              catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
              Rootkit scan 2008-07-15 19:33:49
              Windows 5.1.2600 Service Pack 3 NTFS

              Balayage processus cach‚s ...

              Balayage cach‚ autostart entries ...

              Balayage des fichiers cach‚s ...

              C:\garda\notifykeys.dat 176 bytes

              Scan termin‚ avec succŠs
              Les fichiers cach‚s: 1

              **************************************************************************
              .
              ------------------------ Other Running Processes ------------------------
              .
              C:\WINDOWS\system32\ZoneLabs\vsmon.exe
              C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
              C:\Program Files\Alwil Software\Avast4\ashServ.exe
              C:\WINDOWS\system32\rundll32.exe
              C:\Program Files\Fichiers communs\Acronis\Schedule2\schedul2.exe
              C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
              C:\WINDOWS\ATKKBService.exe
              C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
              C:\WINDOWS\system32\nvsvc32.exe
              C:\Program Files\Spyware Terminator\sp_rsser.exe
              C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
              C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
              C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
              .
              **************************************************************************
              .
              Temps d'accomplissement: 2008-07-15 19:37:00 - machine was rebooted
              ComboFix-quarantined-files.txt 2008-07-15 17:36:17
              ComboFix2.txt 2008-07-15 16:36:34

              Pre-Run: 85,163,376,640 octets libres
              Post-Run: 85,173,137,408 octets libres

              237 --- E O F --- 2008-07-15 05:54:44
              0
              1. Contributeur sécurité
                désactive le tea timer de spybot car tu as déjà spyware terminator qui fais l'analyse en temps réel:

                dans spybot va: MODE puis MODE AVANCE puis OUTILS puis RESIDENT

                _____________

                Ferme tout tes navigateurs (donc copie ou imprime les instructions avant)

                Crée un nouveau document texte : clic droit de souris sur le bureau > Nouveau > Document Texte, et copie dedans les lignes suivantes :

                File::
                C:\WINDOWS\system32\dsauth32.dll

                Registry::
                [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\dsauth32]

                Enregistre ce fichier sous le nom CFscript

                Fait un glisser/déposer de ce fichier CFscrïpt sur le fichier ComboFix.exe

                Clique sur le fichier CFScript, maintient le doigt enfoncé et glisse la souris pour que l'icône du CFScript vienne recouvrir l'icône de Combofix. Relache la souris. Combofix va démarrer.

                Une fenêtre bleue va apparaître: au message qui apparaît ( Type 1 to continue, or 2 to abort) , tape 1 puis valide.

                Patiente le temps du scan.Le bureau va disparaître à plusieurs reprises: c'est normal!

                Ne touche à rien tant que le scan n'est pas terminé.

                Une fois le scan achevé, un rapport va s'afficher: poste son contenu.

                Remets aussi un rapport Hijackthis et dis tes soucis

                Si le fichier ne s'ouvre pas, il se trouve ici > C:\ComboFix.txt
                0
                1. voila le rapport combofix, spybot s'était déclenché après le rebootage mais je l'ai désactivé.pour info l'affichage des pages internet rame acutellemebnt, c est du a cette merde?

                  ComboFix 08-07-14.2 - reverend 2008-07-15 18:30:37.2 - NTFSx86
                  Microsoft Windows XP Professionnel 5.1.2600.3.1252.1.1036.18.1580 [GMT 2:00]
                  Endroit: C:\Documents and Settings\reverend\Bureau\garda.exe

                  [color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/b][/color]
                  .

                  (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
                  .
                  .
                  ---- Previous Run -------
                  .
                  C:\WINDOWS\system32\MSINET.oca

                  .
                  ((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-06-15 to 2008-07-15 ))))))))))))))))))))))))))))))))))))
                  .

                  2008-07-15 18:10 . 2008-07-15 18:10 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
                  2008-07-15 18:10 . 2008-07-15 18:10 <REP> d-------- C:\Documents and Settings\reverend\Application Data\Malwarebytes
                  2008-07-15 18:10 . 2008-07-15 18:10 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
                  2008-07-15 18:10 . 2008-07-07 17:35 34,296 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
                  2008-07-15 18:10 . 2008-07-07 17:35 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys
                  2008-07-15 17:51 . 2008-07-15 17:51 <REP> d-------- C:\Program Files\Panda Security
                  2008-07-15 17:51 . 2008-06-19 17:24 28,544 --a------ C:\WINDOWS\system32\drivers\pavboot.sys
                  2008-07-15 17:39 . 2008-07-15 17:46 <REP> d-------- C:\Program Files\Hijackthis Version Fran‡aise
                  2008-07-15 08:08 . 2008-07-15 08:08 <REP> d-------- C:\Games
                  2008-07-14 22:58 . 2008-07-14 22:58 268 --ah----- C:\sqmdata02.sqm
                  2008-07-14 22:58 . 2008-07-14 22:58 244 --ah----- C:\sqmnoopt02.sqm
                  2008-07-14 22:48 . 2008-07-15 18:22 <REP> d-------- C:\Documents and Settings\reverend\Bureau
                  2008-07-14 22:47 . 2008-07-14 22:47 268 --ah----- C:\sqmdata01.sqm
                  2008-07-14 22:47 . 2008-07-14 22:47 244 --ah----- C:\sqmnoopt01.sqm
                  2008-07-14 22:08 . 2008-06-14 19:33 272,768 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
                  2008-07-14 22:02 . 2008-05-08 16:02 203,136 -----c--- C:\WINDOWS\system32\dllcache\rmcast.sys
                  2008-07-14 22:01 . 2008-07-15 08:22 <REP> d-------- C:\Program Files\Spyware Terminator
                  2008-07-14 22:01 . 2008-07-14 22:02 <REP> d-------- C:\Program Files\Spybot - Search & Destroy
                  2008-07-14 22:01 . 2008-07-15 08:22 <REP> d-------- C:\Documents and Settings\reverend\Application Data\Spyware Terminator
                  2008-07-14 22:01 . 2008-07-14 22:16 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Spyware Terminator
                  2008-07-14 22:01 . 2008-07-14 22:16 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
                  2008-07-14 22:01 . 2008-07-14 22:01 141,312 --a------ C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
                  2008-07-14 20:24 . 2008-07-14 20:24 <REP> d-------- C:\Documents and Settings\All Users\Application Data\nView_Profiles

                  .
                  (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                  .
                  2008-07-15 16:32 43,244 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
                  2008-07-15 16:32 4,130,848 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
                  2008-07-15 16:10 --------- d-----w C:\Program Files\Lavasoft
                  2008-07-15 15:46 --------- d-----w C:\Program Files\Hijackthis Version Française
                  2008-07-15 11:41 196,608 ----a-w C:\WINDOWS\system32\drivers\nStandard.bin
                  2008-07-15 06:08 0 ----a-w C:\Program Files\Installed.hid
                  2008-07-14 20:03 --------- d-----w C:\Documents and Settings\reverend\Application Data\Lavasoft
                  2008-06-14 17:33 272,768 ------w C:\WINDOWS\system32\drivers\bthport.sys
                  2008-05-31 15:33 2,893,312 ----a-w C:\WINDOWS\Internet Logs\xDB2.tmp
                  2008-05-31 15:33 1,420,288 ----a-w C:\WINDOWS\Internet Logs\xDB3.tmp
                  2008-05-31 15:29 --------- d-----w C:\Documents and Settings\LocalService\Application Data\Acronis
                  2008-05-31 15:27 --------- d-----w C:\Program Files\PowerQuest
                  2008-05-31 15:26 441,760 ----a-w C:\WINDOWS\system32\drivers\timntr.sys
                  2008-05-31 15:26 44,384 ----a-w C:\WINDOWS\system32\drivers\tifsfilt.sys
                  2008-05-31 15:26 368,736 ----a-w C:\WINDOWS\system32\drivers\tdrpman.sys
                  2008-05-31 15:26 129,248 ----a-w C:\WINDOWS\system32\drivers\snapman.sys
                  2008-05-31 15:26 --------- d-----w C:\Program Files\Fichiers communs\Acronis
                  2008-05-31 15:26 --------- d-----w C:\Documents and Settings\All Users\Application Data\Acronis
                  2008-05-31 15:25 --------- d-----w C:\Program Files\Acronis
                  2008-05-31 15:23 --------- d-----w C:\Program Files\Fichiers communs\Adobe
                  2008-05-31 15:22 --------- d--h--w C:\Program Files\InstallShield Installation Information
                  2008-05-31 15:19 --------- d-----w C:\Documents and Settings\All Users\Application Data\PowerQuest
                  2008-05-31 09:21 27,262,976 ----a-w C:\VIRTPART.DAT
                  2008-05-31 08:14 1,425,408 ----a-w C:\WINDOWS\Internet Logs\xDB1.tmp
                  2008-05-31 07:54 --------- d-----w C:\Documents and Settings\All Users\Application Data\PokerAcademyPro2
                  2008-05-31 07:50 --------- d-----w C:\Documents and Settings\reverend\Application Data\PokerAcademyPro2
                  2008-05-31 07:04 --------- d-----w C:\Documents and Settings\reverend\Application Data\GrabIt
                  2008-05-30 22:22 --------- d-----w C:\Program Files\Ubisoft
                  2008-05-30 21:54 43,520 ----a-w C:\WINDOWS\system32\CmdLineExt03.dll
                  2008-05-30 21:34 --------- d-----w C:\Documents and Settings\reverend\Application Data\InterTrust
                  2008-05-30 21:26 --------- d-----w C:\Program Files\Alcohol Soft
                  2008-05-30 21:08 737,280 ----a-w C:\WINDOWS\iun6002.exe
                  2008-05-30 20:19 --------- d-----w C:\Program Files\QuickPar
                  2008-05-30 20:18 --------- d-----w C:\Program Files\GrabIt
                  2008-05-30 20:13 715,248 ----a-w C:\WINDOWS\system32\drivers\sptd.sys
                  2008-05-30 19:20 --------- d-----w C:\Program Files\Symantec
                  2008-05-30 19:20 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
                  2008-05-30 19:19 --------- d-----w C:\Program Files\Fichiers communs\Symantec Shared
                  2008-05-30 19:19 --------- d-----w C:\Documents and Settings\reverend\Application Data\Symantec
                  2008-05-30 19:15 --------- d-----w C:\Program Files\Google
                  2008-05-30 18:42 --------- d-----w C:\Program Files\Windows Live
                  2008-05-30 18:41 --------- dcsh--w C:\Program Files\Fichiers communs\WindowsLiveInstaller
                  2008-05-30 18:38 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
                  2008-05-30 18:37 --------- d-----w C:\Documents and Settings\All Users\Application Data\MailFrontier
                  2008-05-30 15:29 --------- d-----w C:\Program Files\Zone Labs
                  2008-05-30 15:28 --------- d-----w C:\Program Files\SLD Codec Pack
                  2008-05-30 15:27 --------- d-----w C:\Program Files\Jasc Software Inc
                  2008-05-30 15:27 --------- d-----w C:\Program Files\Fichiers communs\Jasc Software Inc
                  2008-05-30 15:27 --------- d-----w C:\Program Files\Fichiers communs\InstallShield
                  2008-05-30 15:27 --------- d-----w C:\Documents and Settings\reverend\Application Data\Jasc Software Inc
                  2008-05-30 15:27 --------- d-----w C:\Documents and Settings\All Users\Application Data\InstallShield
                  2008-05-30 15:22 --------- d-----w C:\Program Files\Java Web Start
                  2008-05-30 15:22 --------- d-----w C:\Program Files\Java
                  2008-05-30 15:21 --------- d-----w C:\Program Files\Free.fr
                  2008-05-30 15:06 --------- d-----w C:\Program Files\Winamp
                  2008-05-30 15:04 --------- d-----w C:\Program Files\QuickTime
                  2008-05-30 15:04 --------- d-----w C:\Program Files\iTunes
                  2008-05-30 15:04 --------- d-----w C:\Program Files\iPod
                  2008-05-30 15:04 --------- d-----w C:\Documents and Settings\reverend\Application Data\Apple Computer
                  2008-05-30 15:04 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
                  2008-05-30 15:03 --------- d-----w C:\Program Files\Fichiers communs\Apple
                  2008-05-30 15:03 --------- d-----w C:\Program Files\Apple Software Update
                  2008-05-30 15:03 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple
                  2008-05-30 15:02 --------- d-----w C:\Program Files\RamBoost XP
                  2008-05-30 15:02 --------- d-----w C:\Program Files\Easy CD-DA Extractor 10
                  2008-05-30 15:01 --------- d-----w C:\Program Files\Alwil Software
                  2008-05-30 15:00 --------- d-----w C:\Program Files\VideoLAN
                  2008-05-30 15:00 --------- d-----w C:\Documents and Settings\reverend\Application Data\vlc
                  2008-05-30 14:47 --------- d-----w C:\Program Files\Attansic
                  2008-05-30 14:44 315,392 ----a-w C:\WINDOWS\HideWin.exe
                  2008-05-30 14:44 --------- d-----w C:\Program Files\Realtek
                  2008-05-30 14:37 --------- d-----w C:\Program Files\Intel
                  2008-05-30 14:34 12,288 ----a-w C:\WINDOWS\system32\drivers\EIO64_xp.sys
                  2008-05-30 14:34 --------- d-----w C:\Program Files\ASUS
                  2008-05-30 12:36 --------- d-----w C:\Program Files\microsoft frontpage
                  2008-05-30 12:34 --------- d-----w C:\Program Files\Services en ligne
                  2008-05-09 10:55 90,112 ----a-w C:\WINDOWS\system32\wshext.dll
                  2008-05-09 10:55 430,080 ----a-w C:\WINDOWS\system32\vbscript.dll
                  2008-05-09 10:55 180,224 ----a-w C:\WINDOWS\system32\scrobj.dll
                  2008-05-09 10:55 172,032 ----a-w C:\WINDOWS\system32\scrrun.dll
                  2008-05-08 11:24 155,648 ----a-w C:\WINDOWS\system32\wscript.exe
                  2008-05-07 09:07 135,168 ----a-w C:\WINDOWS\system32\cscript.exe
                  2008-05-07 05:11 1,294,336 ----a-w C:\WINDOWS\system32\quartz.dll
                  2008-04-30 15:27 442,368 ----a-w C:\WINDOWS\system32\NVUNINST.EXE
                  2008-04-23 04:16 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
                  2006-06-23 22:48 32,768 ----a-r C:\WINDOWS\inf\UpdateUSB.exe
                  .

                  ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
                  .
                  .
                  REGEDIT4
                  *Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s

                  [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                  "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 04:33 15360]
                  "msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 11:34 5724184]
                  "SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                  "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2008-05-03 05:46 13529088]
                  "ASUSGamerOSD"="C:\Program Files\ASUS\GamerOSD\GamerOSD.exe" [2007-10-23 17:48 380928]
                  "JMB36X IDE Setup"="C:\WINDOWS\RaidTool\xInsIDE.exe" [2007-03-20 16:36 36864]
                  "36X Raid Configurer"="C:\WINDOWS\system32\xRaidSetup.exe" [2007-03-21 18:23 1953792]
                  "ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-04-02 21:07 919016]
                  "NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2008-05-03 05:46 86016]
                  "TrueImageMonitor.exe"="C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe" [2007-10-07 17:01 2620336]
                  "AcronisTimounterMonitor"="C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe" [2007-10-07 17:36 904880]
                  "Acronis Scheduler2 Service"="C:\Program Files\Fichiers communs\Acronis\Schedule2\schedhlp.exe" [2007-10-07 17:08 140568]
                  "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-11-14 23:43 286720]
                  "nwiz"="nwiz.exe" [2008-05-03 05:46 1630208 C:\WINDOWS\system32\nwiz.exe]
                  "RTHDCPL"="RTHDCPL.EXE" [2007-03-21 16:49 16126464 C:\WINDOWS\RTHDCPL.exe]

                  [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
                  "CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2008-04-14 04:33 15360]

                  [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\dsauth32]
                  2004-05-31 11:54 11264 C:\WINDOWS\system32\dsauth32.dll

                  [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
                  "msacm.l3acm"= l3codecp.acm
                  "vidc.asv2"= asusasv2.dll

                  [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
                  Authentication Packages REG_MULTI_SZ msv1_0 relog_ap

                  [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
                  @=""

                  [HKLM\~\startupfolder\C:^Documents and Settings^reverend^Menu Démarrer^Programmes^Démarrage^Ubisoft register.lnk]
                  path=C:\Documents and Settings\reverend\Menu Démarrer\Programmes\Démarrage\Ubisoft register.lnk
                  backup=C:\WINDOWS\pss\Ubisoft register.lnkStartup

                  [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcoholAutomount]
                  --a------ 2007-12-22 09:20 222080 C:\Program Files\Alcohol Soft\Alcohol 120\AxCmd.exe

                  [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUS SmartDoctor]
                  --a------ 2008-01-22 11:52 1126400 C:\Program Files\ASUS\SmartDoctor\SmartDoctor.exe

                  [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
                  --a------ 2007-11-15 13:11 267048 C:\Program Files\iTunes\iTunesHelper.exe

                  [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
                  --a------ 2007-10-18 11:34 5724184 C:\Program Files\Windows Live\Messenger\msnmsgr.exe

                  [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
                  --a------ 2007-11-14 23:43 286720 C:\Program Files\QuickTime\QTTask.exe

                  [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
                  "DisableMonitoring"=dword:00000001

                  [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
                  "EnableFirewall"= 0 (0x0)

                  [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
                  "%windir%\\system32\\sessmgr.exe"=
                  "C:\\Program Files\\iTunes\\iTunes.exe"=
                  "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
                  "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
                  "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=

                  [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
                  "7423:TCP"= 7423:TCP:messenger
                  "2831:TCP"= 2831:TCP:messenger

                  R0 pavboot;pavboot;C:\WINDOWS\system32\drivers\pavboot.sys [2008-06-19 17:24]
                  R0 tdrpman;Acronis Try&Decide and Restore Points filter;C:\WINDOWS\system32\DRIVERS\tdrpman.sys [2008-05-31 17:26]
                  R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-05-16 01:20]
                  R1 EIO_XP;EIO_XP;C:\WINDOWS\system32\drivers\EIO_XP.sys [2006-06-14 13:44]
                  R1 GhPciScan;GhostPciScanner;C:\Program Files\Symantec\Norton Ghost 2003\ghpciscan.sys [2002-08-14 15:11]
                  R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-05-16 01:16]
                  R2 TryAndDecideService;Acronis Try And Decide Service;C:\Program Files\Fichiers communs\Acronis\Fomatik\TrueImageTryStartService.exe [2007-10-08 11:19]
                  R3 asusgsb;ASUS Virtual Video Capture Device Driver;C:\WINDOWS\system32\drivers\asusgsb.sys [2007-10-23 17:48]
                  R3 ASUSVRC;ASUSTeK Virtual Capture Device;C:\WINDOWS\system32\DRIVERS\AsusVRC.sys [2007-01-29 17:12]
                  R3 AtcL001;NDIS Miniport Driver for Attansic L1 Gigabit Ethernet Controller;C:\WINDOWS\system32\DRIVERS\atl01_xp.sys [2007-03-15 16:12]
                  R3 Video3D;ASUS Video3D Service;C:\WINDOWS\system32\Drivers\Video3D32.sys [2007-10-23 17:48]

                  .
                  **************************************************************************

                  catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                  Rootkit scan 2008-07-15 18:33:38
                  Windows 5.1.2600 Service Pack 3 NTFS

                  Balayage processus cach‚s ...

                  Balayage cach‚ autostart entries ...

                  Balayage des fichiers cach‚s ...

                  C:\Documents and Settings\reverend\Local Settings\temp\WERdebb.dir00
                  C:\garda\notifykeys.dat
                  C:\garda\temp01
                  C:\garda\wlgn.dat

                  Scan termin‚ avec succŠs
                  Les fichiers cach‚s: 4

                  **************************************************************************
                  .
                  ------------------------ Other Running Processes ------------------------
                  .
                  C:\WINDOWS\system32\ZoneLabs\vsmon.exe
                  C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                  C:\Program Files\Alwil Software\Avast4\ashServ.exe
                  C:\WINDOWS\system32\rundll32.exe
                  C:\Program Files\Fichiers communs\Acronis\Schedule2\schedul2.exe
                  C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                  C:\WINDOWS\ATKKBService.exe
                  C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
                  C:\WINDOWS\system32\nvsvc32.exe
                  C:\Program Files\Spyware Terminator\sp_rsser.exe
                  C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
                  C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                  C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                  .
                  **************************************************************************
                  .
                  Temps d'accomplissement: 2008-07-15 18:36:33 - machine was rebooted [reverend]
                  ComboFix-quarantined-files.txt 2008-07-15 16:35:49

                  Pre-Run: 85,301,985,280 octets libres
                  Post-Run: 85,275,209,728 octets libres

                  235 --- E O F --- 2008-07-15 05:54:44
                  0
                  1. Contributeur sécurité
                    il faut faire un scan complet avec malwarebyte's et pas un rapide

                    puis

                    Télécharge Combofix de sUBs : Renomme le avant toute installation, par exemple, nomme le "KillBagle". aide ici : https://forum.pcastuces.com/sujet.asp?f=25&s=37315

                    http://download.bleepingcomputer.com/sUBs/ComboFix.exe
                    Sauvegarde le sur ton bureau et pas ailleurs !

                    Aide à l’utilisation de combofix ici: http://bibou0007.forumpro.fr/tutos-f45/tutorial-combofix-t12­­1.htm

                    Double-clic sur combofix, Il va te poser une question, réponds par la touche 1 et entrée pour valider, laisse toi guider.
                    Attends que combofix ait terminé, un rapport sera créé. Poste le rapport.

                    ____________________

                    recolle un nouvel hijackhtis et dis tes soucis
                    0
                    1. le rapport du dernier lien que t as envoyé:

                      Malwarebytes' Anti-Malware 1.20
                      Version de la base de données: 953
                      Windows 5.1.2600 Service Pack 3

                      18:15:10 15/07/2008
                      mbam-log-7-15-2008 (18-15-10).txt

                      Type de recherche: Examen rapide
                      Eléments examinés: 42481
                      Temps écoulé: 1 minute(s), 26 second(s)

                      Processus mémoire infecté(s): 0
                      Module(s) mémoire infecté(s): 0
                      Clé(s) du Registre infectée(s): 0
                      Valeur(s) du Registre infectée(s): 0
                      Elément(s) de données du Registre infecté(s): 0
                      Dossier(s) infecté(s): 0
                      Fichier(s) infecté(s): 0

                      Processus mémoire infecté(s):
                      (Aucun élément nuisible détecté)

                      Module(s) mémoire infecté(s):
                      (Aucun élément nuisible détecté)

                      Clé(s) du Registre infectée(s):
                      (Aucun élément nuisible détecté)

                      Valeur(s) du Registre infectée(s):
                      (Aucun élément nuisible détecté)

                      Elément(s) de données du Registre infecté(s):
                      (Aucun élément nuisible détecté)

                      Dossier(s) infecté(s):
                      (Aucun élément nuisible détecté)

                      Fichier(s) infecté(s):
                      (Aucun élément nuisible détecté)

                      il voit rien.....
                      0
                      1. Contributeur sécurité
                        ok

                        scan avec malwarebyte's: et vire ce qui est trouvé et colle le rapport:

                        https://www.malekal.com/tutoriel-malwarebyte-anti-malware/

                        _________________

                        Télécharge Combofix de sUBs : Renomme le avant toute installation, par exemple, nomme le "KillBagle". aide ici : https://forum.pcastuces.com/sujet.asp?f=25&s=37315

                        http://download.bleepingcomputer.com/sUBs/ComboFix.exe
                        Sauvegarde le sur ton bureau et pas ailleurs !

                        Aide à l’utilisation de combofix ici: http://bibou0007.forumpro.fr/tutos-f45/tutorial-combofix-t12­1.htm

                        Double-clic sur combofix, Il va te poser une question, réponds par la touche 1 et entrée pour valider, laisse toi guider.
                        Attends que combofix ait terminé, un rapport sera créé. Poste le rapport.

                        ____________________

                        recolle un nouvel hijackhtis et dis tes soucis
                        0
                        1. ci dessous l analyse par virus total:

                          Antivirus Version Dernière mise à jour Résultat
                          AhnLab-V3 2008.7.11.0 2008.07.15 -
                          AntiVir 7.8.0.68 2008.07.15 TR/Crypt.FKM.Gen
                          Authentium 5.1.0.4 2008.07.15 -
                          Avast 4.8.1195.0 2008.07.15 -
                          AVG 7.5.0.516 2008.07.15 -
                          BitDefender 7.2 2008.07.15 Trojan.Crypt.EN
                          CAT-QuickHeal 9.50 2008.07.14 -
                          ClamAV 0.93.1 2008.07.15 -
                          DrWeb 4.44.0.09170 2008.07.15 -
                          eSafe 7.0.17.0 2008.07.14 Suspicious File
                          eTrust-Vet 31.6.5956 2008.07.15 -
                          Ewido 4.0 2008.07.15 -
                          F-Prot 4.4.4.56 2008.07.14 -
                          F-Secure 7.60.13501.0 2008.07.15 -
                          Fortinet 3.14.0.0 2008.07.15 -
                          GData 2.0.7306.1023 2008.07.15 -
                          Ikarus T3.1.1.26.0 2008.07.15 -
                          Kaspersky 7.0.0.125 2008.07.15 -
                          McAfee 5338 2008.07.14 -
                          Microsoft 1.3704 2008.07.15 -
                          NOD32v2 3269 2008.07.15 -
                          Norman 5.80.02 2008.07.15 -
                          Panda 9.0.0.4 2008.07.14 -
                          Prevx1 V2 2008.07.15 -
                          Rising 20.53.12.00 2008.07.15 -
                          Sophos 4.31.0 2008.07.15 Sus/Behav-1021
                          Sunbelt 3.1.1536.1 2008.07.15 -
                          Symantec 10 2008.07.15 -
                          TheHacker 6.2.96.379 2008.07.14 -
                          TrendMicro 8.700.0.1004 2008.07.15 -
                          VBA32 3.12.8.0 2008.07.15 -
                          VirusBuster 4.5.11.0 2008.07.15 -
                          Webwasher-Gateway 6.6.2 2008.07.15 Trojan.Crypt.FKM.Gen
                          Information additionnelle
                          File size: 11264 bytes
                          MD5...: c901dbc851e111decf8a1f961383c971
                          SHA1..: 9fb8c713bacfdaa4803b3564c2451db1ead07a67
                          SHA256: abc415fa5390a4563c4a4effa9d69a12c94df435e1e1dbc8295c678f2609db91
                          SHA512: f97001bae2801a07c1554fd5d1fe83520765aae4f9865c6d278610aa32252b7e
                          2d6833be391a8c3dd17f6cf1bdf849e3d34aefec061b1278fe057d1b156ec055
                          PEiD..: -
                          PEInfo: PE Structure information

                          ( base data )
                          entrypointaddress.: 0x1000af00
                          timedatestamp.....: 0x480cab41 (Mon Apr 21 14:57:05 2008)
                          machinetype.......: 0x14c (I386)

                          ( 3 sections )
                          name viradd virsiz rawdsiz ntrpy md5
                          UPX0 0x1000 0x8000 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e
                          UPX1 0x9000 0x3000 0x2200 7.78 f9c3fe9b1720694ab6cf106aa97dd2a1
                          .rsrc 0xc000 0x1000 0x600 2.82 368fec73d1edc74ab746e9d7354d12ef

                          ( 1 imports )
                          > KERNEL32.DLL: LoadLibraryA, GetProcAddress, VirtualProtect, VirtualAlloc, VirtualFree

                          ( 1 exports )
                          ulyd

                          packers (F-Prot): UPX
                          packers (Kaspersky): PE_Patch.UPX, UPX
                          0
                          1. Contributeur sécurité
                            tu as spyware terminator et spybot avec le tea timer! désactivel e tea timer de spybot sinon l'ordi va ramer

                            _____________

                            mets a jour java car ta version est obsolète

                            ____________

                            analyse ceci sur virus total et colle le rapport: https://www.virustotal.com/gui/
                            C:\WINDOWS\SYSTEM32\dsauth32.dll

                            _____________

                            tu as ad aware 2007: la version 2008 est sortie...

                            mais il serait préferable de le virer et de mettre malwarebyte's a la place , plus efficace et ne consommant pas de ressource hors pendant le scan:

                            scan avec et vire ce qui est trouvé et colle le rapport:

                            https://www.malekal.com/tutoriel-malwarebyte-anti-malware/
                            0
                            1. je viens de faire l anaylise rapide avec panda, voila le résultat, t en penses quoi?

                              ;***********************************************************************************************************************************************************************************
                              ANALYSIS: 2008-07-15 17:55:57
                              PROTECTIONS: 1
                              MALWARE: 11
                              SUSPECTS: 0
                              ;***********************************************************************************************************************************************************************************
                              PROTECTIONS
                              Description Version Active Updated
                              ;===================================================================================================================================================================================
                              Zone Alarm Security Suite 7.0.473.000 No No
                              ;===================================================================================================================================================================================
                              MALWARE
                              Id Description Type Active Severity Disinfectable Disinfected Location
                              ;===================================================================================================================================================================================
                              00145405 Cookie/RealMedia TrackingCookie No 0 Yes No C:\Documents and Settings\reverend\Cookies\reverend@247realmedia[2].txt
                              00167642 Cookie/Com.com TrackingCookie No 0 Yes No C:\Documents and Settings\reverend\Cookies\reverend@com[1].txt
                              00167647 Cookie/Yadro TrackingCookie No 0 Yes No C:\Documents and Settings\reverend\Cookies\reverend@yadro[2].txt
                              00167704 Cookie/Xiti TrackingCookie No 0 Yes No C:\Documents and Settings\reverend\Cookies\reverend@xiti[1].txt
                              00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\reverend\Cookies\reverend@serving-sys[1].txt
                              00168093 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\reverend\Cookies\reverend@bs.serving-sys[2].txt
                              00168106 Cookie/Weborama TrackingCookie No 0 Yes No C:\Documents and Settings\reverend\Cookies\reverend@weborama[2].txt
                              00168109 Cookie/Adtech TrackingCookie No 0 Yes No C:\Documents and Settings\reverend\Cookies\reverend@adtech[1].txt
                              00168116 Cookie/Comclick TrackingCookie No 0 Yes No C:\Documents and Settings\reverend\Cookies\reverend@fl01.ct2.comclick[1].txt
                              00170554 Cookie/Overture TrackingCookie No 0 Yes No C:\Documents and Settings\reverend\Cookies\reverend@overture[1].txt
                              00273339 Cookie/Smartadserver TrackingCookie No 0 Yes No C:\Documents and Settings\reverend\Cookies\reverend@smartadserver[2].txt
                              ;===================================================================================================================================================================================
                              SUSPECTS
                              Sent Location :
                              ;===================================================================================================================================================================================
                              ;===================================================================================================================================================================================
                              VULNERABILITIES
                              Id Severity Description :
                              ;===================================================================================================================================================================================
                              ;===================================================================================================================================================================================
                              0
                              1. Contributeur sécurité
                                ok

                                tu as spyware terminator et spybot avec le tea timer! désactivel e tea timer de spybot sinon l'ordi va ramer

                                _____________

                                mets a jour java car ta version est obsolète

                                ____________

                                analyse ceci sur virus total et colle le rapport: https://www.virustotal.com/gui/
                                C:\WINDOWS\SYSTEM32\dsauth32.dll

                                _____________

                                tu as ad aware 2007: la version 2008 est sortie...

                                mais il serait préferable de le virer et de mettre malwarebyte's a la place , plus efficace et ne consommant pas de ressource hors pendant le scan:

                                scan avec et vire ce qui est trouvé et colle le rapport:

                                https://www.malekal.com/tutoriel-malwarebyte-anti-malware/
                                0
                                • 1
                                • 2