Win 32

Bonjour,
Je possède XP et un jour en voulant regarder un film, je n'avais plus de son, je me suis redu compte aussi que avast ne tournait plus. Je l'ai désintaller et retélécharger mais en voulant le lancer j'ai le message comme quoi avast n'était pas une application win 32 valide. Je ne peu plus non plus télécharger les mises à jours windows. j'ai essayer un redémarage sur une dernière configuration bonne et une restauration système mais rien à faire.
Est-ce un virus?
Help me.
seb
Configuration: Windows XP
Internet Explorer 7.0

25 réponses

Résumé de la discussion

Problème central : sous Windows XP, l'absence de son et l'échec de Avast, avec impossibilité de mettre à jour Windows, suggèrent une infection ou un problème de sécurité. Plusieurs réponses proposent des outils de détection et de nettoyage, tels que FindyKill et ComboFix, avec instructions pas à pas et la génération de rapports à partager. D'autres propositions mettent en garde contre des sources non vérifiées et recommandent l'installation d'antivirus légitime, ainsi que des vérifications via des supports externes pour détecter des infections potentielles. Une nuance utile est que le fil évoque des outils potentiellement risqués et sans garantie fiable, ce qui justifie une approche prudente et l'utilisation d'antivirus reconnus et d'outils officiellement distribués.

Bobot (l’IA à votre service)
  1. Salut,

    Telecharge FindyKill sur ton bureau :

    Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) suceptible d avoir été infectés sans les ouvrir

    --> Lance l installation avec les parametres par default

    --> Double clic sur le raccourci FindyKill sur ton bureau

    --> Au menu principal,choisi l option 1 (Recherche)

    --> Post le rapport FindyKill.txt

    Note : le rapport FindyKill.txt est sauvegardé a la racine du disque

    1. ----------------- FindyKill V4.095 ------------------

      * User : SEB - 117668250316
      * Emplacement : C:\Program Files\FindyKill
      * Outils Mis a jours le 06/11/08 par Chiquitine29
      * Recherche effectuée à 21:02:18 le 06/11/2008
      * Windows XP - Internet Explorer 7.0.5730.11

      ((((((((((((((((( *** Recherche *** ))))))))))))))))))

      --------------- [ Processus actifs ] ----------------

      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\csrss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
      C:\WINDOWS\eHome\ehRecvr.exe
      C:\Program Files\Norton SystemWorks\Norton GoBack\GBPoll.exe
      C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
      C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
      C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
      C:\Apps\Softex\OmniPass\Omniserv.exe
      C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
      C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
      C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\USBDeviceService.exe
      C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
      C:\WINDOWS\ehome\mcrdsvc.exe
      C:\Program Files\Borland\InterBase\bin\ibserver.exe
      C:\WINDOWS\system32\dllhost.exe
      C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\Trust\MI-4500X WIRELESS OPTICAL MOUSE\Mouse32a.exe
      C:\PROGRA~1\GOTOSO~1\VADERE~1\Vaderetro_oe.exe
      C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
      C:\WINDOWS\RTHDCPL.EXE
      C:\Program Files\Picasa2\PicasaMediaDetector.exe
      C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIADE.EXE
      C:\WINDOWS\ehome\ehtray.exe
      C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\DetectorApp.exe
      C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
      C:\WINDOWS\eHome\ehmsas.exe
      C:\apps\ABoard\ABoard.exe
      C:\apps\ABoard\AOSD.exe
      C:\Program Files\Logitech\QuickCam\Quickcam.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
      C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      D:\documents and settings\seb\local settings\application data\kycqs.exe
      C:\Program Files\DNA\btdna.exe
      C:\WINDOWS\system32\drivers\winfilse.exe
      D:\Documents and Settings\SEB\Application Data\m\flec006.exe
      C:\Program Files\Fichiers communs\Logishrd\LQCVFX\COCIManager.exe
      C:\Program Files\Norton SystemWorks\Norton GoBack\GBTray.exe
      C:\Program Files\Hercules\WiFi Station\WifiStation.exe
      C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
      C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
      C:\Program Files\Fichiers communs\Teleca Shared\Generic.exe
      C:\WINDOWS\system32\wintems.exe
      C:\Program Files\Internet Explorer\iexplore.exe

      --------------- [ Processus infectieux stoppés ] ----------------

      "C:\WINDOWS\system32\wintems.exe" (184)
      "D:\Documents and Settings\SEB\Application Data\m\flec006.exe" (1556)
      "C:\WINDOWS\system32\drivers\winfilse.exe" (580)

      --------------- [ Fichiers/Dossiers infectieux ] ----------------

      »»»» Presence des fichiers dans C:

      »»»» Presence des fichiers dans C:\WINDOWS

      »»»» Presence des fichiers dans C:\WINDOWS\Prefetch

      Present ! - C:\WINDOWS\prefetch\141500.EXE-226784AF.pf
      Present ! - C:\WINDOWS\prefetch\142812.EXE-099D77D2.pf
      Present ! - C:\WINDOWS\prefetch\168500.EXE-22FAB258.pf
      Present ! - C:\WINDOWS\prefetch\195437.EXE-01C98277.pf
      Present ! - C:\WINDOWS\prefetch\201593.EXE-191E7E80.pf
      Present ! - C:\WINDOWS\prefetch\286765.EXE-08C82050.pf
      Present ! - C:\WINDOWS\prefetch\FLEC006.EXE-0C259194.pf
      Present ! - C:\WINDOWS\prefetch\MDELK.EXE-086F0B56.pf
      Present ! - C:\WINDOWS\prefetch\MDELK.EXE-0EF461CE.pf
      Present ! - C:\WINDOWS\prefetch\WINFILSE.EXE-0C5BAB91.pf
      Present ! - C:\WINDOWS\prefetch\WINTEMS.EXE-377E42D4.pf

      »»»» Presence des fichiers dans C:\WINDOWS\system32

      Présent ! [06/11/2008 20:14] - C:\WINDOWS\system32\mdelk.exe
      Présent ! [06/11/2008 20:14] - C:\WINDOWS\system32\wintems.exe
      Présent ! [06/11/2008 20:14] - C:\WINDOWS\system32\ban_list.txt

      »»»» Presence des fichiers dans C:\WINDOWS\system32\drivers

      Présent ! [06/11/2008 20:10] - C:\WINDOWS\system32\drivers\srosa.sys
      Présent ! [14/05/2005 08:01] - C:\WINDOWS\system32\drivers\winfilse.exe
      Présent ! [06/11/2008 20:16] - "C:\WINDOWS\system32\drivers\downld"
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\101616578.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\101632812.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\101633484.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\101661312.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\101667718.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\101671515.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\101673562.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\101709453.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\101770078.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\101780718.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\1247484.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\1260437.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\1262515.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\1286968.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\1294390.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\1297343.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\130127484.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\130128125.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\130133515.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\130141593.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\130145937.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\130149781.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\130153406.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\130156000.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\130192968.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\130240562.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\130248093.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\1335750.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\1412093.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\141687.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\1418781.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\1420453.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\142421.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\142812.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\144678406.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\144695765.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\144700203.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\144709890.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\144729796.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\144733625.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\144736000.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\144776343.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\144826796.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\144836015.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\14744500.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\14745250.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\14768500.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\14782250.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\14790734.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\14797812.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\14811609.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\14865953.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\14924937.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\14950406.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\14957312.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\150000.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\151328.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\151640.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\152765.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\158312.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\158953.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\159266546.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\159278531.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\159279781.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\159297484.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\159307234.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\159310625.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\159315140.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\159320343.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\159324593.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\159389031.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\159421.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\159449656.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\159462562.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\169546.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\170234.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\173905093.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\173919875.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\173921078.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\173960937.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\173969421.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\173972828.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\173975531.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\174022156.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\174088515.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\174106062.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\175859.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\177660000.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\177692703.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\177693218.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\177698843.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\177706171.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\177708703.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\177712531.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\177937.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\178656.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\178828.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\179578.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\179953.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\180062.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\181515.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\183718.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\184671.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\185906.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\187187.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\188554421.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\188571875.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\188577531.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\188587875.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\188596609.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\188599328.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\188603234.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\188606843.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\188609437.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\188646218.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\188843.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\188858000.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\188878406.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\192890.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\193843.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\195437.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\198578.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\201031.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\201593.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\205359.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\208875.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\211500.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\216687.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\220562.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\222859.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\226109.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\228078.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\228218.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\230265.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\247281.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\256392968.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\256408171.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\256408656.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\256421359.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\256430000.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\256436468.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\256439500.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\256443390.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\256488218.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\256569656.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\256576734.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\264015.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\266437.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\267187.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\267953.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\270734.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\271010078.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\271025640.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\271029156.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\271055312.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\271065984.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\271069640.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\271072984.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\271075390.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\271120656.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\271173546.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\271180156.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\273656.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\274828.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\2773703.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\2782328.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\2783140.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\279015.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\279156.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\2804406.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\280500.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\2813171.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\2816531.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\2820593.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\2823750.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\2826093.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\286765.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\2890250.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\290328.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\291500.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\2942437.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\2949078.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\296015.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\302812.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\303334890.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\303335453.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\303367484.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\303371484.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\303374015.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\303377046.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\303379578.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\303446671.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\303503156.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\303520140.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\305453.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\306671.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\307703.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\309625.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\310812.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\311984.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\312140.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\317971843.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\317976109.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\317999156.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\318009531.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\318012875.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\318017625.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\318021343.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\318026218.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\318066968.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\318121578.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\318131812.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\332561203.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\332642265.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\332643140.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\332656031.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\332672515.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\332677828.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\332682734.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\332726875.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\332779484.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\332790750.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\347248296.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\347250203.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\347262984.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\347272234.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\347277093.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\347281703.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\347287093.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\347290484.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\347334562.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\347392578.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\347401343.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\361824937.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\361832828.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\361833562.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\361839953.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\361848953.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\361851015.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\361856156.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\361858953.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\361861312.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\361895718.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\361941421.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\361948593.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\361949953.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\376376390.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\376391093.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\376392203.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\376398953.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\376407015.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\376413578.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\376416734.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\376422343.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\376461812.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\376523921.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\376534875.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\376537390.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\383078.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\396079796.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\396083656.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\396084468.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\396089000.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\396099312.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\396107062.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\396111390.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\396115531.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\396151984.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\396196687.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\396203046.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\396204250.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\400828.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\402828.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\410629812.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\410642156.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\410643703.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\410653625.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\410662062.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\410668890.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\410673187.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\410676328.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\410717015.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\410775046.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\410797703.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\410799796.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\425226656.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\425227843.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\425247046.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\425250093.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\425259484.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\425264421.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\425267859.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\425304015.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\425364265.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\425372875.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\425374906.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\43146250.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\43151656.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\43152203.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\43169750.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\43179359.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\43187312.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\43190265.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\43192609.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\43249250.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\43327250.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\43346515.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\439844437.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\439860609.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\439861625.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\439875578.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\439884968.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\439888359.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\439891890.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\439894562.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\439933531.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\439970906.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\439976890.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\439978000.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\4489281.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\4490156.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\4496593.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\4497234.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\4525437.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\4531656.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\4534359.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\454391703.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\454408109.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\454408687.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\454425625.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\454434093.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\454436500.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\454438875.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\454441406.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\454477937.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\454508781.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\454513796.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\4585484.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\4619843.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\4626046.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\4627265.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\480293031.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\480300390.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\480302906.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\480321156.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\480324640.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\480328109.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\480332953.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\480335562.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\480371890.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\480420968.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\480429609.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\480430937.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\57783187.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\57783906.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\57810218.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\57820937.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\57824843.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\57828203.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\57830796.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\57868656.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\57916203.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\57923250.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\64665500.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\64678984.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\64685750.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\72360156.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\72378593.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\72379187.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\72386312.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\72394703.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\72396828.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\72400875.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\72404062.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\72406343.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\72441796.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\72489296.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\72495703.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\86929906.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\86956421.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\86958234.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\86981859.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\86994390.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\87024343.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\87029640.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\87033609.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\87092765.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\87158250.exe
      Présent ! [06/11/2008 20:16] C:\WINDOWS\system32\drivers\downld\87168953.exe

      »»»» Presence des fichiers dans D:\Documents and Settings\SEB\Application Data

      Présent ! [05/11/2008 23:26] - "D:\Documents and Settings\SEB\Application Data\m\flec006.exe"
      Présent ! [06/11/2008 20:11] - "D:\Documents and Settings\SEB\Application Data\m\list.oct"
      Présent ! [06/11/2008 20:11] - "D:\Documents and Settings\SEB\Application Data\m\data.oct"
      Présent ! [06/11/2008 20:11] - "D:\Documents and Settings\SEB\Application Data\m\srvlist.oct"
      Présent ! [06/11/2008 20:12] - "D:\Documents and Settings\SEB\Application Data\m\shared"
      Présent ! [27/10/2008 19:48] - "D:\Documents and Settings\SEB\Application Data\m"

      »»»» Presence des fichiers dans D:\DOCUME~1\SEB\LOCALS~1\Temp

      Présent ! - D:\DOCUME~1\SEB\LOCALS~1\Temp\Fichiers Internet temporaires\Content.IE5\1WWAKYRI\addyn%7C3[1].0%7C224%7C1064650%7C0%7C1%7CADTECH;loc=100;target=_blank;KEY=A+81+14700+81A;grp=1;misc=1222320791269
      Présent ! - D:\DOCUME~1\SEB\LOCALS~1\Temp\Fichiers Internet temporaires\Content.IE5\1WWAKYRI\addyn%7C3[1].0%7C224%7C1064650%7C0%7C1%7CADTECH;loc=100;target=_blank;KEY=A+81+14700+81A;grp=1;misc=1222320797517
      Présent ! - D:\DOCUME~1\SEB\LOCALS~1\Temp\Fichiers Internet temporaires\Content.IE5\1WWAKYRI\addyn%7C3[1].0%7C224%7C1119089%7C0%7C165%7CADTECH;loc=100;target=_blank;KEY=key1+key2+key3+key4;grp=1;misc=1222320477920
      Présent ! - D:\DOCUME~1\SEB\LOCALS~1\Temp\Fichiers Internet temporaires\Content.IE5\1WWAKYRI\addyn%7C3[1].0%7C224%7C97019%7C0%7C165%7CADTECH;loc=100;target=_blank;KEY=A+81+14700+81A;grp=1;misc=1222320512237
      Présent ! - D:\DOCUME~1\SEB\LOCALS~1\Temp\Fichiers Internet temporaires\Content.IE5\1WWAKYRI\addyn%7C3[1].0%7C224%7C97019%7C0%7C165%7CADTECH;loc=100;target=_blank;KEY=A+81+14700+81A;grp=1;misc=1222320753391
      Présent ! - D:\DOCUME~1\SEB\LOCALS~1\Temp\Fichiers Internet temporaires\Content.IE5\1WWAKYRI\keylist_LaPoste_s_homme[1].xml
      Présent ! - D:\DOCUME~1\SEB\LOCALS~1\Temp\Fichiers Internet temporaires\Content.IE5\F3YH8A0I\addyn%7C3[1].0%7C224%7C1064650%7C0%7C1%7CADTECH;loc=100;target=_blank;KEY=A+81+14700+81A;grp=1;misc=1222320539869
      Présent ! - D:\DOCUME~1\SEB\LOCALS~1\Temp\Fichiers Internet temporaires\Content.IE5\F3YH8A0I\addyn%7C3[1].0%7C224%7C1064650%7C0%7C1%7CADTECH;loc=100;target=_blank;KEY=A+81+14700+81A;grp=1;misc=1222320558878
      Présent ! - D:\DOCUME~1\SEB\LOCALS~1\Temp\Fichiers Internet temporaires\Content.IE5\F3YH8A0I\addyn%7C3[1].0%7C224%7C1119091%7C0%7C1%7CADTECH;loc=100;target=_blank;KEY=key1+key2+key3+key4;grp=1;misc=1222320475671
      Présent ! - D:\DOCUME~1\SEB\LOCALS~1\Temp\Fichiers Internet temporaires\Content.IE5\F3YH8A0I\addyn%7C3[1].0%7C224%7C97019%7C0%7C165%7CADTECH;loc=100;target=_blank;KEY=A+81+14700+81A;grp=1;misc=1222320572248
      Présent ! - D:\DOCUME~1\SEB\LOCALS~1\Temp\Fichiers Internet temporaires\Content.IE5\F3YH8A0I\addyn%7C3[1].0%7C224%7C97019%7C0%7C165%7CADTECH;loc=100;target=_blank;KEY=A+81+14700+81A;grp=1;misc=1222320797595
      Présent ! - D:\DOCUME~1\SEB\LOCALS~1\Temp\Fichiers Internet temporaires\Content.IE5\I5299ETJ\accesskey[1].htc
      Présent ! - D:\DOCUME~1\SEB\LOCALS~1\Temp\Fichiers Internet temporaires\Content.IE5\I5299ETJ\addyn%7C3[1].0%7C224%7C1064650%7C0%7C1%7CADTECH;loc=100;target=_blank;KEY=A+81+14700+81A;grp=1;misc=1222320512237
      Présent ! - D:\DOCUME~1\SEB\LOCALS~1\Temp\Fichiers Internet temporaires\Content.IE5\I5299ETJ\addyn%7C3[1].0%7C224%7C1064650%7C0%7C1%7CADTECH;loc=100;target=_blank;KEY=A+81+14700+81A;grp=1;misc=1222320572264
      Présent ! - D:\DOCUME~1\SEB\LOCALS~1\Temp\Fichiers Internet temporaires\Content.IE5\I5299ETJ\addyn%7C3[1].0%7C224%7C1064650%7C0%7C1%7CADTECH;loc=100;target=_blank;KEY=A+81+14700+81A;grp=1;misc=1222320752548
      Présent ! - D:\DOCUME~1\SEB\LOCALS~1\Temp\Fichiers Internet temporaires\Content.IE5\TTL7753E\accesskey[1].htc
      Présent ! - D:\DOCUME~1\SEB\LOCALS~1\Temp\Fichiers Internet temporaires\Content.IE5\TTL7753E\addyn%7C3[1].0%7C224%7C97019%7C0%7C165%7CADTECH;loc=100;target=_blank;KEY=A+81+14700+81A;grp=1;misc=1222320539962
      Présent ! - D:\DOCUME~1\SEB\LOCALS~1\Temp\Fichiers Internet temporaires\Content.IE5\TTL7753E\addyn%7C3[1].0%7C224%7C97019%7C0%7C165%7CADTECH;loc=100;target=_blank;KEY=A+81+14700+81A;grp=1;misc=1222320558893
      Présent ! - D:\DOCUME~1\SEB\LOCALS~1\Temp\Fichiers Internet temporaires\Content.IE5\TTL7753E\adlink%7C224%7C97019%7C0%7C165%7CAdId%3D1964230%3BBnId%3D2%3Bitime%3D320750284%3Bkey%3DA%2B81%2B14700%2B81A%3Blink%3D;ord=320750284[1]
      Présent ! - D:\DOCUME~1\SEB\LOCALS~1\Temp\Fichiers Internet temporaires\Content.IE5\UMXVCA1X\adlink%7C224%7C97019%7C0%7C165%7CAdId%3D1964230%3BBnId%3D2%3Bitime%3D320788742%3Bkey%3DA%2B81%2B14700%2B81A%3Blink%3D;ord=320788742[1]
      Présent ! - D:\DOCUME~1\SEB\LOCALS~1\Temp\Fichiers Internet temporaires\Content.IE5\XHH33VXI\accesskey[1].htc
      Présent ! - D:\DOCUME~1\SEB\LOCALS~1\Temp\Fichiers Internet temporaires\Content.IE5\XHH33VXI\addyn%7C3[1].0%7C224%7C97019%7C0%7C165%7CADTECH;loc=100;target=_blank;KEY=A+81+14700+81A;grp=1;misc=1222320791269

      »»»» Presence des fichiers dans D:\Documents and Settings\SEB\Local Settings\Temporary Internet Files\Content.IE5

      Présent ! - D:\Documents and Settings\SEB\Local Settings\Temporary Internet Files\Content.IE5\2MUR3R8N\b64_2[1].jpg
      Présent ! - D:\Documents and Settings\SEB\Local Settings\Temporary Internet Files\Content.IE5\2MUR3R8N\b64_3[1].jpg
      Présent ! - D:\Documents and Settings\SEB\Local Settings\Temporary Internet Files\Content.IE5\T66VFQY0\b64[2].jpg

      --------------- [ Registre / Startup ] ----------------

      ! REG.EXE VERSION 3.0

      HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
      FLMOFFICE4DMOUSE REG_SZ C:\Program Files\Trust\MI-4500X WIRELESS OPTICAL MOUSE\Mouse32a.exe
      Symantec PIF AlertEng REG_SZ "C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
      ccApp REG_SZ "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
      Vade Retro Outlook Express REG_SZ "C:\PROGRA~1\GOTOSO~1\VADERE~1\Vaderetro_oe.exe"
      SunJavaUpdateSched REG_SZ "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
      Sony Ericsson PC Suite REG_SZ "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
      RTHDCPL REG_SZ RTHDCPL.EXE
      Picasa Media Detector REG_SZ C:\Program Files\Picasa2\PicasaMediaDetector.exe
      PHIME2002ASync REG_SZ C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
      PHIME2002A REG_SZ C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
      OmniPass REG_SZ C:\Apps\Softex\OmniPass\scureapp.exe
      IMJPMIG8.1 REG_SZ "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32"
      High Definition Audio Property Page Shortcut REG_SZ HDAShCut.exe
      Google Desktop Search REG_SZ "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
      EPSON Stylus DX4800 Series REG_SZ C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIADE.EXE /P26 "EPSON Stylus DX4800 Series" /O6 "USB001" /M "Stylus DX4800"
      ehTray REG_SZ C:\WINDOWS\ehome\ehtray.exe
      DetectorApp REG_SZ C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\DetectorApp.exe
      ATICCC REG_SZ "c:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
      Alcmtr REG_SZ ALCMTR.EXE
      ACTIVBOARD REG_SZ c:\apps\ABoard\ABoard.exe
      wzremeqn REG_SZ c:\windows\system32\wzremeqn.exe wzremeqn
      LogitechVideo[inspector] REG_SZ C:\Program Files\Logitech\Video\InstallHelper.exe /inspect
      ISUSScheduler REG_SZ "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
      ISUSPM Startup REG_SZ C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
      Adobe Reader Speed Launcher REG_SZ "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
      LogitechCommunicationsManager REG_SZ "C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe"
      LogitechQuickCamRibbon REG_SZ "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
      Babylon Client REG_SZ C:\Program Files\Babylon\Babylon-Pro\Babylon.exe -AutoStart
      avast! REG_SZ C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      KernelFaultCheck REG_EXPAND_SZ %systemroot%\system32\dumprep 0 -k

      HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents

      ! REG.EXE VERSION 3.0

      HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
      ctfmon.exe REG_SZ C:\WINDOWS\system32\ctfmon.exe
      SmpcSys REG_SZ C:\APPS\SMP\SmpSys.exe
      LDM REG_SZ C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
      Instant Access REG_SZ C:\WINDOWS\system32\linkprd.exe /res
      swg REG_SZ C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      kycqs REG_SZ "d:\documents and settings\seb\local settings\application data\kycqs.exe" kycqs
      BitTorrent DNA REG_SZ "C:\Program Files\DNA\btdna.exe"

      --------------- [ Registre / Clés infectieuses ] ----------------

      Présent ! - HKEY_USERS\S-1-5-21-880680660-2609442243-2517767408-1005\Software\Local AppWizard-Generated Applications\winfilse
      Présent ! - HKEY_USERS\S-1-5-21-880680660-2609442243-2517767408-1005\Software\bisoft
      Présent ! - HKEY_USERS\S-1-5-21-880680660-2609442243-2517767408-1005\Software\DateTime4
      Présent ! - HKEY_USERS\S-1-5-21-880680660-2609442243-2517767408-1005\Software\FFC
      Présent ! - HKEY_USERS\S-1-5-21-880680660-2609442243-2517767408-1005\Software\FirtR
      Présent ! - HKEY_USERS\S-1-5-21-880680660-2609442243-2517767408-1005\Software\MuleAppData
      Présent ! - HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\winfilse
      Présent ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\srosa
      Présent ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\srosa
      Présent ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\srosa
      Présent ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\srosa
      Présent ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA
      Présent ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SROSA
      Présent ! - HKEY_CURRENT_USER\Software\bisoft
      Présent ! - HKEY_CURRENT_USER\Software\DateTime4
      Présent ! - HKEY_CURRENT_USER\Software\FirtR
      Présent ! - [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] | EnableLUA
      Présent ! - [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Security Center\Svc] | EnableLUA

      --------------- [ Etat / Services ] ----------------

      Clé manquante : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden

      -> Affichage des fichiers cachés non fonctionnel !!

      Clé manquante : HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot

      -> Mode sans echec non fonctionnel !!

      Clé manquante : HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal

      -> Mode sans echec non fonctionnel !!

      Clé manquante : HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network

      -> Mode sans echec non fonctionnel !!

      +- Services : [ Auto=2 / Demande=3 / Désactivé=4 ]

      /!\ Ndisuio - Type de démarrage = 4

      /!\ Ip6Fw - Type de démarrage = 4

      /!\ SharedAccess - Type de démarrage = 4

      /!\ wuauserv - Type de démarrage = 4

      /!\ wscsvc - Type de démarrage = 4

      --------------- [ Recherche dans supports amovibles] ----------------

      +- Informations :

      C: - Lecteur fixe

      D: - Lecteur fixe

      +- presence des fichiers :

      --------------- [ Registre / Moutpoint2 ] ----------------

      -> Recherche négative.

      ------------------- ! Fin du rapport ! --------------------
  2. comment va le pc lmis a part combofix ???
    1. Le PC va plutot bien, il tourne dejà plus vite sur internet, j'ai quand meme eu quelques soucis avec explorer (barre des taches) qui plante de temps en temps.

      Mais par contre je n'ai pas recuperer le son il doit falloir que je télécharge un pilote car si j'essaie de lancer dans aaccesoir/divertissement /control du volume, j'ai le message qu'aucun périphérique melangeur est disponible.

      Sinon si j'ai un rootkit cela veut dire que quelqu'un peu se servir des ressourses de" mon PC a mon inssu?
    2. @sebLe PC va plutot bien, il tourne dejà plus vite sur internet, j'ai quand meme eu quelques soucis avec explorer (barre des taches) qui plante de temps en temps.

      Mais par contre je n'ai pas recuperer le son il doit falloir que je télécharge un pilote car si j'essaie de lancer dans aaccesoir/divertissement /control du volume, j'ai le message qu'aucun périphérique melangeur est disponible.
  3. Telecharge FindyKill sur ton bureau :

    Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) suceptible d avoir été infectés sans les ouvrir

    --> Lance l installation avec les parametres par default

    --> Double clic sur le raccourci FindyKill sur ton bureau

    --> Au menu principal,choisi l option 1 (Recherche)

    --> Post le rapport FindyKill.txt

    Note : le rapport FindyKill.txt est sauvegardé a la racine du disque
    1. ----------------- FindyKill V4.600 ------------------

      * User : SEB - 117668250316
      * Emplacement : C:\Program Files\FindyKill
      * Outils Mis a jours le 12/11/08 par Chiquitine29
      * Recherche effectuée à 19:59:29 le 12/11/2008
      * Windows XP - Internet Explorer 7.0.5730.11

      ((((((((((((((((( *** Recherche *** ))))))))))))))))))

      --------------- [ Processus actifs ] ----------------

      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\csrss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
      C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
      C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
      C:\WINDOWS\eHome\ehRecvr.exe
      C:\WINDOWS\eHome\ehSched.exe
      C:\Program Files\Norton SystemWorks\Norton GoBack\GBPoll.exe
      C:\Program Files\Borland\InterBase\bin\ibguard.exe
      C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
      C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
      C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
      C:\Apps\Softex\OmniPass\Omniserv.exe
      C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
      C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
      C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\USBDeviceService.exe
      C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
      C:\WINDOWS\ehome\mcrdsvc.exe
      C:\Apps\Softex\OmniPass\OPXPApp.exe
      C:\Program Files\Borland\InterBase\bin\ibserver.exe
      C:\WINDOWS\system32\dllhost.exe
      C:\WINDOWS\System32\alg.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
      C:\Program Files\Trust\MI-4500X WIRELESS OPTICAL MOUSE\Mouse32a.exe
      C:\PROGRA~1\GOTOSO~1\VADERE~1\Vaderetro_oe.exe
      C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
      C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
      C:\WINDOWS\RTHDCPL.EXE
      C:\Program Files\Picasa2\PicasaMediaDetector.exe
      C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIADE.EXE
      C:\WINDOWS\ehome\ehtray.exe
      C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\DetectorApp.exe
      C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
      C:\apps\ABoard\ABoard.exe
      C:\WINDOWS\eHome\ehmsas.exe
      C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe
      C:\Program Files\Logitech\QuickCam\Quickcam.exe
      C:\Program Files\Babylon\Babylon-Pro\Babylon.exe
      C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
      C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      C:\apps\ABoard\AOSD.exe
      C:\Program Files\ArcSoft\Media Card Companion\MCC Monitor.exe
      C:\Program Files\Norton SystemWorks\Norton GoBack\GBTray.exe
      C:\WINDOWS\system32\wuauclt.exe
      C:\Program Files\Fichiers communs\Logishrd\LQCVFX\COCIManager.exe
      C:\Program Files\Hercules\WiFi Station\WifiStation.exe
      C:\Program Files\DNA\btdna.exe
      C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
      C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Fichiers communs\Teleca Shared\Generic.exe
      c:\program files\logitech\quickcam\lu\lulnchr.exe
      c:\program files\logitech\quickcam\lu\LogitechUpdate.exe

      --------------- [ Fichiers/Dossiers infectieux ] ----------------

      »»»» Presence des fichiers dans C:

      »»»» Presence des fichiers dans C:\WINDOWS

      »»»» Presence des fichiers dans C:\WINDOWS\Prefetch

      »»»» Presence des fichiers dans C:\WINDOWS\system32

      »»»» Presence des fichiers dans C:\WINDOWS\system32\drivers

      »»»» Presence des fichiers dans D:\Documents and Settings\SEB\Application Data

      »»»» Presence des fichiers dans D:\DOCUME~1\SEB\LOCALS~1\Temp

      »»»» Presence des fichiers dans D:\Documents and Settings\SEB\Local Settings\Temporary Internet Files\Content.IE5

      --------------- [ Registre / Startup ] ----------------

      ! REG.EXE VERSION 3.0

      HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
      FLMOFFICE4DMOUSE REG_SZ C:\Program Files\Trust\MI-4500X WIRELESS OPTICAL MOUSE\Mouse32a.exe
      Symantec PIF AlertEng REG_SZ "C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
      ccApp REG_SZ "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
      Vade Retro Outlook Express REG_SZ "C:\PROGRA~1\GOTOSO~1\VADERE~1\Vaderetro_oe.exe"
      SunJavaUpdateSched REG_SZ "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
      Sony Ericsson PC Suite REG_SZ "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
      RTHDCPL REG_SZ RTHDCPL.EXE
      Picasa Media Detector REG_SZ C:\Program Files\Picasa2\PicasaMediaDetector.exe
      PHIME2002ASync REG_SZ C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
      PHIME2002A REG_SZ C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
      OmniPass REG_SZ C:\Apps\Softex\OmniPass\scureapp.exe
      IMJPMIG8.1 REG_SZ "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32"
      High Definition Audio Property Page Shortcut REG_SZ HDAShCut.exe
      Google Desktop Search REG_SZ "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
      EPSON Stylus DX4800 Series REG_SZ C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIADE.EXE /P26 "EPSON Stylus DX4800 Series" /O6 "USB001" /M "Stylus DX4800"
      ehTray REG_SZ C:\WINDOWS\ehome\ehtray.exe
      DetectorApp REG_SZ C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\DetectorApp.exe
      ATICCC REG_SZ "c:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
      Alcmtr REG_SZ ALCMTR.EXE
      ACTIVBOARD REG_SZ c:\apps\ABoard\ABoard.exe
      LogitechVideo[inspector] REG_SZ C:\Program Files\Logitech\Video\InstallHelper.exe /inspect
      ISUSScheduler REG_SZ "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
      ISUSPM Startup REG_SZ C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
      Adobe Reader Speed Launcher REG_SZ "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
      LogitechCommunicationsManager REG_SZ "C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe"
      LogitechQuickCamRibbon REG_SZ "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
      Babylon Client REG_SZ C:\Program Files\Babylon\Babylon-Pro\Babylon.exe -AutoStart
      avast! REG_SZ C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      KernelFaultCheck REG_EXPAND_SZ %systemroot%\system32\dumprep 0 -k
      avgnt REG_SZ "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
      combofix REG_SZ "C:\WINDOWS\system32\CF14285.exe" /c "C:\killbagle\C.bat"

      HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents

      ! REG.EXE VERSION 3.0

      HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
      ctfmon.exe REG_SZ C:\WINDOWS\system32\ctfmon.exe
      SmpcSys REG_SZ C:\APPS\SMP\SmpSys.exe
      LDM REG_SZ C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
      swg REG_SZ C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      BitTorrent DNA REG_SZ "C:\Program Files\DNA\btdna.exe"

      --------------- [ Registre / Clés infectieuses ] ----------------

      --------------- [ Etat / Services ] ----------------

      +- Services : [ Auto=2 / Demande=3 / Désactivé=4 ]

      Ndisuio - Type de démarrage = 3

      Ip6Fw - Type de démarrage = 2

      SharedAccess - Type de démarrage = 2

      wuauserv - Type de démarrage = 2

      wscsvc - Type de démarrage = 2

      --------------- [ Recherche dans supports amovibles] ----------------

      +- Informations :

      C: - Lecteur fixe

      D: - Lecteur fixe

      +- presence des fichiers :

      --------------- [ Registre / Mountpoint2 ] ----------------

      -> Not found !

      ------------------- ! Fin du rapport ! --------------------
  4. supprime combofix de ton bureau

    Télécharge combofix : http://download.bleepingcomputer.com/sUBs/ComboFix.exe

    Avant de telecharger clic sur enregistrer renome le en killbagle et enregistre le sur le bureau

    -> Double clique sur killbagle.exe.
    -> Tape sur la touche 1 (Yes) pour démarrer le scan.
    -> Lorsque le scan sera complété, un rapport apparaîtra. Copie/colle ce rapport dans ta prochaine réponse.

    NOTE : Le rapport se trouve également ici : C:\Combofix.txt

    Avant d'utiliser ComboFix :

    -> Déconnecte toi d'internet et referme les fenêtres de tous les programmes en cours.

    Une fois fait, sur ton bureau double-clic sur killbagle.exe.

    - Répond oui au message d'avertissement, pour que le programme commence à procéder à l'analyse du pc.

    /!\ Pendant la durée de cette étape, ne te sert pas du pc et n'ouvre aucun programmes.

    - En fin de scan il est possible que ComboFix ait besoin de redemarrer le pc pour finaliser la désinfection\recherche, laisses-le faire.

    - Un rapport s'ouvrira ensuite dans le bloc notes, ce fichier rapport Combofix.txt, est automatiquement sauvegardé et rangé à C:\Combofix.txt)
    1. Le programe me detecte encore la présence d'un rootkit.
      seb
  5. Télécharge ToolsCleaner sur ton bureau.
    -->
    http://pc-system.fr/
    http://www.commentcamarche.net/telecharger/telecharger 34055291 toolscleaner

    # Clique sur Recherche et laisse le scan agir ...
    # Clique sur Suppression pour finaliser.
    # Tu peux, si tu le souhaites, te servir des Options facultatives.
    # Clique sur Quitter pour obtenir le rapport.
    # Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\).

    1. [ Rapport ToolsCleaner version 2.2.6 (par A.Rothstein & dj QUIOU) ]

      -->- Recherche:

      D:\Documents and Settings\All Users\Bureau\Navilog1.lnk: trouvé !
      D:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis: trouvé !
      D:\Documents and Settings\All Users\Menu Démarrer\Programmes\Navilog1: trouvé !
      D:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis\HijackThis.lnk: trouvé !
      D:\Documents and Settings\All Users\Menu Démarrer\Programmes\Navilog1\Navilog1.lnk: trouvé !
      D:\Documents and Settings\SEB\Bureau\SdFix.exe: trouvé !
      D:\Documents and Settings\SEB\Bureau\HijackThis.lnk: trouvé !
      D:\Documents and Settings\SEB\Bureau\Navilog1.exe: trouvé !
      D:\Documents and Settings\SEB\Bureau\ComboFix.exe: trouvé !
      D:\Documents and Settings\SEB\Bureau\HJTInstall.exe: trouvé !
      D:\Documents and Settings\SEB\Menu Démarrer\Programmes\FindyKill: trouvé !

      ---------------------------------
      -->- Suppression:

      D:\Documents and Settings\All Users\Bureau\Navilog1.lnk: supprimé !
      D:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis\HijackThis.lnk: supprimé !
      D:\Documents and Settings\All Users\Menu Démarrer\Programmes\Navilog1\Navilog1.lnk: supprimé !
      D:\Documents and Settings\SEB\Bureau\SdFix.exe: supprimé !
      D:\Documents and Settings\SEB\Bureau\HijackThis.lnk: supprimé !
      D:\Documents and Settings\SEB\Bureau\Navilog1.exe: supprimé !
      D:\Documents and Settings\SEB\Bureau\ComboFix.exe: ERREUR DE SUPPRESSION !!
      D:\Documents and Settings\SEB\Bureau\HJTInstall.exe: supprimé !
      D:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis: supprimé !
      D:\Documents and Settings\All Users\Menu Démarrer\Programmes\Navilog1: supprimé !
      D:\Documents and Settings\SEB\Menu Démarrer\Programmes\FindyKill: supprimé !
  6. Télécharges SDFix sur ton bureau :
    http://downloads.andymanchesta.com/RemovalTools/SDFix.exe.

    --->Double-cliques sur SDFix.exe et choisis "Install" .

    ( tuto ici : https://www.malekal.com/slenfbot-still-an-other-irc-bot/ )

    Puis une fois l'installe faite, redémarre en mode sans échec .

    Comment aller en Mode sans échec :
    1) Redémarre ton ordi
    2) Tapote la touche F8 immédiatement, (F5 sur certains PC) juste après le "Bip"
    3) Tu verras un écran avec options de démarrage apparaître
    4) Choisis la première option : Sans Échec, et valide avec "Entrée"
    5) Choisis ton compte habituel, et non Administrateur (si besoin ... )

    Ouvre le dossier SDFix qui vient d'être créé dans le répertoire C:\ et double clique sur RunThis.bat pour lancer le script.
    --->Tapes Y pour lancer le script ...
    Le Fix supprime les services du virus et nettoie le registre, de ce fait un redémarrage est nécessaire , donc :
    presse une touche pour redémarrer quand il te le sera demandé .

    Le PC va mettre du temps avant de démarrer ( c'est normal), après le chargement du Bureau presse une touche lorsque "Finished" s'affiche .

    Le rapport SDFix s'ouvrira à l'écran et s'enregistrera aussi dans le dossier C:\SDFix sous le nom "Report.txt".
    Poste ce dernier dans ta prochaine réponse.
    1. [b]SDFix: Version 1.240 [/b]
      Run by SEB on 10/11/2008 at 12:34

      Microsoft Windows XP [version 5.1.2600]
      Running From: C:\SDFix

      [b]Checking Services [/b]:

      Restoring Default Security Values
      Restoring Default Hosts File

      Rebooting

      [b]Checking Files [/b]:

      Trojan Files Found:

      C:\WINDOWS\TMLPWIN.EXE - Deleted

      Removing Temp Files

      [b]ADS Check [/b]:

      [b]Final Check [/b]:

      catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
      Rootkit scan 2008-11-10 12:45:57
      Windows 5.1.2600 Service Pack 2 NTFS

      scanning hidden processes ...

      scanning hidden services & system hive ...

      scanning hidden registry entries ...

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
      "AppInit_DLLs"="C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL"
      "DeviceNotSelectedTimeout"="15"
      "GDIProcessHandleQuota"=dword:00002710
      "Spooler"="yes"
      "swapdisk"=""
      "TransmissionRetryTimeout"="90"
      "USERProcessHandleQuota"=dword:00002710
      "LoadAppInit_DLLs"=dword:00000001

      scanning hidden files ...

      scan completed successfully
      hidden processes: 0
      hidden services: 0
      hidden files: 0

      [b]Remaining Services [/b]:

      Authorized Application Key Export:

      [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
      "%ProgramFiles%\\AOL 9.0\\aol.exe"="%ProgramFiles%\\AOL 9.0\\aol.exe:*:Enabled:AOL"
      "%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\logo_ubi.exe"="%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\logo_ubi.exe:*:Enabled:SPLINTER CELL PANDORA"
      "%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\pandora.exe"="%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\pandora.exe:*:Enabled:PANDORA"
      "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
      "C:\\APPS\\Inventime\\my.exe"="C:\\APPS\\Inventime\\my.exe:*:Enabled:INVENTIME"
      "C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
      "C:\\Program Files\\eMule\\emule.exe"="C:\\Program Files\\eMule\\emule.exe:*:Enabled:eMule"
      "C:\\Program Files\\AOL 9.0\\waol.exe"="C:\\Program Files\\AOL 9.0\\waol.exe:*:Enabled:AOL 9.0"
      "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.0"
      "C:\\Program Files\\MSN Messenger\\msncall.exe"="C:\\Program Files\\MSN Messenger\\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)"
      "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
      "C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"="C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger"
      "C:\\Program Files\\eMule\\emuleseb\\eMule\\emule.exe"="C:\\Program Files\\eMule\\emuleseb\\eMule\\emule.exe:*:Enabled:eMule"
      "C:\\Program Files\\IncrediMail\\bin\\IncMail.exe"="C:\\Program Files\\IncrediMail\\bin\\IncMail.exe:*:Disabled:IncrediMail"
      "C:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe"="C:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe:*:Disabled:IncrediMail"
      "C:\\Program Files\\IncrediMail\\bin\\ImApp.exe"="C:\\Program Files\\IncrediMail\\bin\\ImApp.exe:*:Disabled:IncrediMail"
      "C:\\APPS\\skype\\phone\\Skype.exe"="C:\\APPS\\skype\\phone\\Skype.exe:*:Disabled:Skype"
      "C:\\Program Files\\uTorrent\\uTorrent.exe"="C:\\Program Files\\uTorrent\\uTorrent.exe:*:Enabled:µTorrent"
      "C:\\Program Files\\DNA\\btdna.exe"="C:\\Program Files\\DNA\\btdna.exe:*:Enabled:DNA"
      "C:\\Program Files\\BitTorrent\\bittorrent.exe"="C:\\Program Files\\BitTorrent\\bittorrent.exe:*:Enabled:BitTorrent"

      [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
      "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
      "C:\\Program Files\\AOL 9.0\\waol.exe"="C:\\Program Files\\AOL 9.0\\waol.exe:*:Enabled:AOL 9.0"
      "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.0"
      "C:\\Program Files\\MSN Messenger\\msncall.exe"="C:\\Program Files\\MSN Messenger\\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)"
      "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
      "C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"="C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger"

      [b]Remaining Files [/b]:

      File Backups: - C:\SDFix\backups\backups.zip

      [b]Files with Hidden Attributes [/b]:

      Wed 2 Aug 2006 208 A.SHR --- "C:\BOOT.BAK"
      Mon 30 Jan 2006 4,789,792 ...H. --- "C:\Program Files\Picasa2\setup.exe"
      Mon 23 Oct 2006 9 A..H. --- "C:\WINDOWS\system32\wxmmin.dll"
      Sat 16 Aug 2008 96 A..H. --- "C:\System Volume Information\_restore{B3BF5352-B406-412E-936E-A9436F19C528}\RP411\A0091279.sys"
      Wed 10 Sep 2008 96 A..H. --- "C:\System Volume Information\_restore{B3BF5352-B406-412E-936E-A9436F19C528}\RP412\A0091321.sys"
      Thu 11 Sep 2008 96 A..H. --- "C:\System Volume Information\_restore{B3BF5352-B406-412E-936E-A9436F19C528}\RP420\A0093320.sys"
      Thu 25 Sep 2008 96 A..H. --- "C:\System Volume Information\_restore{B3BF5352-B406-412E-936E-A9436F19C528}\RP421\A0094316.sys"
      Thu 25 Sep 2008 96 A..H. --- "C:\System Volume Information\_restore{B3BF5352-B406-412E-936E-A9436F19C528}\RP423\A0095317.sys"
      Wed 1 Oct 2008 96 A..H. --- "C:\System Volume Information\_restore{B3BF5352-B406-412E-936E-A9436F19C528}\RP423\A0096331.sys"
      Thu 2 Oct 2008 96 A..H. --- "C:\System Volume Information\_restore{B3BF5352-B406-412E-936E-A9436F19C528}\RP427\A0096439.sys"
      Mon 20 Oct 2008 96 A..H. --- "C:\System Volume Information\_restore{B3BF5352-B406-412E-936E-A9436F19C528}\RP430\A0096477.sys"
      Sat 25 Oct 2008 96 A..H. --- "C:\System Volume Information\_restore{B3BF5352-B406-412E-936E-A9436F19C528}\RP430\A0097476.sys"
      Mon 27 Oct 2008 96 A..H. --- "C:\System Volume Information\_restore{B3BF5352-B406-412E-936E-A9436F19C528}\RP436\A0098471.sys"
      Sun 2 Nov 2008 96 A..H. --- "C:\System Volume Information\_restore{B3BF5352-B406-412E-936E-A9436F19C528}\RP436\A0098498.sys"
      Sun 2 Nov 2008 96 A..H. --- "C:\System Volume Information\_restore{B3BF5352-B406-412E-936E-A9436F19C528}\RP436\A0098520.sys"
      Sun 2 Nov 2008 96 A..H. --- "C:\System Volume Information\_restore{B3BF5352-B406-412E-936E-A9436F19C528}\RP439\A0098745.sys"
      Sun 2 Nov 2008 96 A..H. --- "C:\System Volume Information\_restore{B3BF5352-B406-412E-936E-A9436F19C528}\RP439\A0098766.sys"
      Tue 4 Nov 2008 96 A..H. --- "C:\System Volume Information\_restore{B3BF5352-B406-412E-936E-A9436F19C528}\RP440\A0098927.sys"
      Tue 4 Nov 2008 96 A..H. --- "C:\System Volume Information\_restore{B3BF5352-B406-412E-936E-A9436F19C528}\RP440\A0098949.sys"
      Tue 4 Nov 2008 96 A..H. --- "C:\System Volume Information\_restore{B3BF5352-B406-412E-936E-A9436F19C528}\RP441\A0099946.sys"
      Wed 5 Nov 2008 96 A..H. --- "C:\System Volume Information\_restore{B3BF5352-B406-412E-936E-A9436F19C528}\RP442\A0100472.sys"
      Wed 5 Nov 2008 96 A..H. --- "C:\System Volume Information\_restore{B3BF5352-B406-412E-936E-A9436F19C528}\RP443\A0100999.sys"
      Wed 5 Nov 2008 96 A..H. --- "C:\System Volume Information\_restore{B3BF5352-B406-412E-936E-A9436F19C528}\RP443\A0101032.sys"
      Wed 5 Nov 2008 96 A..H. --- "C:\System Volume Information\_restore{B3BF5352-B406-412E-936E-A9436F19C528}\RP443\A0101060.sys"
      Thu 6 Nov 2008 96 A..H. --- "C:\System Volume Information\_restore{B3BF5352-B406-412E-936E-A9436F19C528}\RP443\A0101081.sys"
      Thu 6 Nov 2008 96 A..H. --- "C:\System Volume Information\_restore{B3BF5352-B406-412E-936E-A9436F19C528}\RP444\A0101503.sys"
      Fri 7 Nov 2008 96 A..H. --- "C:\System Volume Information\_restore{B3BF5352-B406-412E-936E-A9436F19C528}\RP444\A0101527.sys"
      Fri 7 Nov 2008 96 A..H. --- "C:\System Volume Information\_restore{B3BF5352-B406-412E-936E-A9436F19C528}\RP444\A0101547.sys"
      Fri 7 Nov 2008 96 A..H. --- "C:\System Volume Information\_restore{B3BF5352-B406-412E-936E-A9436F19C528}\RP444\A0101596.sys"
      Fri 7 Nov 2008 96 A..H. --- "C:\System Volume Information\_restore{B3BF5352-B406-412E-936E-A9436F19C528}\RP444\A0101644.sys"
      Fri 7 Nov 2008 96 A..H. --- "C:\System Volume Information\_restore{B3BF5352-B406-412E-936E-A9436F19C528}\RP444\A0101713.sys"
      Sat 8 Nov 2008 96 A..H. --- "C:\System Volume Information\_restore{B3BF5352-B406-412E-936E-A9436F19C528}\RP445\A0101766.sys"
      Sat 8 Nov 2008 96 A..H. --- "C:\System Volume Information\_restore{B3BF5352-B406-412E-936E-A9436F19C528}\RP445\A0101784.sys"
      Sat 8 Nov 2008 96 A..H. --- "C:\System Volume Information\_restore{B3BF5352-B406-412E-936E-A9436F19C528}\RP445\A0101893.sys"
      Mon 10 Nov 2008 96 A..H. --- "C:\Program Files\Common Files\X10\Common\x10prod.sys"
      Tue 31 May 2005 106,496 A..H. --- "C:\Program Files\Fichiers communs\aolshare\shell\fr\shellext.dll"

      [b]Finished![/b]
  7. Contributeur sécurité
    désactive ton antivirus comme demandé avant de le telecharger puis lance le
    1. Mon antivir est desactivé et mon parfeu windows aussi !!
  8. ok seb

    @+
    1. Salut,
      Je n'arrive pas à lancer conbofix : il detecte la présence de rootkit et redemarre mon PC.
      seb
    2. @sebJe n'ai toujours pas reussi a lancer combofix
  9. Télécharge combofix : http://download.bleepingcomputer.com/sUBs/ComboFix.exe

    -> Double clique sur combofix.exe.
    -> Tape sur la touche 1 (Yes) pour démarrer le scan.
    -> Lorsque le scan sera complété, un rapport apparaîtra. Copie/colle ce rapport dans ta prochaine réponse.

    NOTE : Le rapport se trouve également ici : C:\Combofix.txt

    Avant d'utiliser ComboFix :

    -> Déconnecte toi d'internet et referme les fenêtres de tous les programmes en cours.

    -> Désactive provisoirement et seulement le temps de l'utilisation de ComboFix, la protection en temps réel de ton Antivirus et de tes Antispywares, qui peuvent géner fortement la procédure de recherche et de nettoyage de l'outil.

    Une fois fait, sur ton bureau double-clic sur Combofix.exe.

    - Répond oui au message d'avertissement, pour que le programme commence à procéder à l'analyse du pc.

    /!\ Pendant la durée de cette étape, ne te sert pas du pc et n'ouvre aucun programmes.

    - En fin de scan il est possible que ComboFix ait besoin de redemarrer le pc pour finaliser la désinfection\recherche, laisses-le faire.

    - Un rapport s'ouvrira ensuite dans le bloc notes, ce fichier rapport Combofix.txt, est automatiquement sauvegardé et rangé à C:\Combofix.txt)

    -> Réactive la protection en temps réel de ton Antivirus et de tes Antispywares, avant de te reconnecter à internet.

    -> Reviens sur le forum, et copie et colle la totalité du contenu de C:\Combofix.txt dans ton prochain message.
    1. Je n'arrive pas a le lancer malgré la désactivation de antivir et du parfeu windows : Combo veut sant cesse redemarrer le pc par ce qu'il detecte un programe qui ne lui plait pas.
      PS est-ce qu'il y a encore beaucoup de manipulations à faire par-ce-que je me lève pour aller travailler dans quelque heures. si cela etait, nous pourrions peut etre reprendre celles-ci plus tard.
      seb
    2. @sebJ'espers que nous pourrons continuer plus tard , il faut vraiment que j'assure à mon boulot demain.
      en tout cas encore merci pour le temps que tu m'aura consacrer ce soir .
      à bientot, je t'enverais un message dès que je revient sur le forum.
      seb
  10. Télécharge HijackThis (outils de dignostic) ici :

    -> Fais un clic droit sur un des liens et choisi enregistrer la cible sous .... le bureau
    -> http://www.trendsecure.com/portal/en-US/_download/HJTInstall.exe
    -> ftp://ftp.commentcamarche.com/download/HJTInstall.exe

    -> Fais un double-clic sur HJTInstall.exe afin de lancer l'installation

    -> Clique sur Install ensuite sur I Accept

    -> Clique sur Do a scan system and save log file

    -> Le bloc-notes s'ouvrira, fais un copier-coller de tout son contenu ici dans ta prochaine réponse
    1. Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 00:52:04, on 07/11/2008
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.16735)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
      C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
      C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
      C:\WINDOWS\eHome\ehRecvr.exe
      C:\WINDOWS\eHome\ehSched.exe
      C:\Program Files\Norton SystemWorks\Norton GoBack\GBPoll.exe
      C:\Program Files\Borland\InterBase\bin\ibguard.exe
      C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
      C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
      C:\Apps\Softex\OmniPass\Omniserv.exe
      C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
      C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\USBDeviceService.exe
      C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
      C:\Apps\Softex\OmniPass\OPXPApp.exe
      C:\Program Files\Borland\InterBase\bin\ibserver.exe
      C:\WINDOWS\system32\dllhost.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
      C:\Program Files\Trust\MI-4500X WIRELESS OPTICAL MOUSE\Mouse32a.exe
      C:\PROGRA~1\GOTOSO~1\VADERE~1\Vaderetro_oe.exe
      C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
      C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
      C:\WINDOWS\RTHDCPL.EXE
      C:\Program Files\Picasa2\PicasaMediaDetector.exe
      C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIADE.EXE
      C:\WINDOWS\ehome\ehtray.exe
      C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\DetectorApp.exe
      C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
      C:\apps\ABoard\ABoard.exe
      C:\WINDOWS\eHome\ehmsas.exe
      C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe
      C:\apps\ABoard\AOSD.exe
      C:\Program Files\Logitech\QuickCam\Quickcam.exe
      C:\Program Files\Babylon\Babylon-Pro\Babylon.exe
      C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
      C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      C:\Program Files\DNA\btdna.exe
      C:\Program Files\ArcSoft\Media Card Companion\MCC Monitor.exe
      C:\Program Files\Norton SystemWorks\Norton GoBack\GBTray.exe
      C:\Program Files\Hercules\WiFi Station\WifiStation.exe
      C:\Program Files\Fichiers communs\Logishrd\LQCVFX\COCIManager.exe
      C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
      C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
      C:\Program Files\Fichiers communs\Teleca Shared\Generic.exe
      C:\Program Files\Adobe\Reader 9.0\Reader\AcroRd32.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://home.neuf.fr
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/?gws_rd=ssl
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
      R3 - URLSearchHook: myBabylon English Toolbar - {b2e293ee-fd7e-4c71-a714-5f4750d8d7b7} - C:\Program Files\myBabylon_English\tbmyBa.dll
      O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
      O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
      O2 - BHO: myBabylon English Toolbar - {b2e293ee-fd7e-4c71-a714-5f4750d8d7b7} - C:\Program Files\myBabylon_English\tbmyBa.dll
      O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
      O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
      O3 - Toolbar: myBabylon English Toolbar - {b2e293ee-fd7e-4c71-a714-5f4750d8d7b7} - C:\Program Files\myBabylon_English\tbmyBa.dll
      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
      O4 - HKLM\..\Run: [FLMOFFICE4DMOUSE] C:\Program Files\Trust\MI-4500X WIRELESS OPTICAL MOUSE\Mouse32a.exe
      O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
      O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
      O4 - HKLM\..\Run: [Vade Retro Outlook Express] "C:\PROGRA~1\GOTOSO~1\VADERE~1\Vaderetro_oe.exe"
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
      O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
      O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
      O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
      O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
      O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
      O4 - HKLM\..\Run: [OmniPass] C:\Apps\Softex\OmniPass\scureapp.exe
      O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32"
      O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
      O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
      O4 - HKLM\..\Run: [EPSON Stylus DX4800 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIADE.EXE /P26 "EPSON Stylus DX4800 Series" /O6 "USB001" /M "Stylus DX4800"
      O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
      O4 - HKLM\..\Run: [DetectorApp] C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\DetectorApp.exe
      O4 - HKLM\..\Run: [ATICCC] "c:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
      O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
      O4 - HKLM\..\Run: [ACTIVBOARD] c:\apps\ABoard\ABoard.exe
      O4 - HKLM\..\Run: [LogitechVideo[inspector]] C:\Program Files\Logitech\Video\InstallHelper.exe /inspect
      O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
      O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
      O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe"
      O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
      O4 - HKLM\..\Run: [Babylon Client] C:\Program Files\Babylon\Babylon-Pro\Babylon.exe -AutoStart
      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
      O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [SmpcSys] C:\APPS\SMP\SmpSys.exe
      O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
      O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\RECYCLER\NPROTECT\00056696.rbf
      O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
      O4 - Global Startup: Monitor.lnk = C:\Program Files\ArcSoft\Media Card Companion\MCC Monitor.exe
      O4 - Global Startup: Norton GoBack.lnk = C:\Program Files\Norton SystemWorks\Norton GoBack\GBTray.exe
      O4 - Global Startup: WiFi Station.lnk = ?
      O8 - Extra context menu item: &Search - ?p=ZNxmk879YYFR
      O8 - Extra context menu item: Translate with &Babylon - res://C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Translate.htm
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
      O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/...
      O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
      O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
      O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
      O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
      O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
      O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
      O23 - Service: GoBack Polling Service (GBPoll) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton GoBack\GBPoll.exe
      O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: InterBase Guardian (InterBaseGuardian) - Borland Software Corporation - C:\Program Files\Borland\InterBase\bin\ibguard.exe
      O23 - Service: InterBase Server (InterBaseServer) - Borland Software Corporation - C:\Program Files\Borland\InterBase\bin\ibserver.exe
      O23 - Service: InterBase InterClient Server (InterServer) - InterBase - C:\Program Files\Borland\InterBase\InterClient\bin\interserver.exe
      O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
      O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
      O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
      O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
      O23 - Service: Softex OmniPass Service (omniserv) - Softex Inc. - C:\Apps\Softex\OmniPass\Omniserv.exe
      O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
      O23 - Service: USBDeviceService - Unknown owner - C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\USBDeviceService.exe
      O23 - Service: X10 Device Network Service (x10nets) - X10 - C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
  11. tu démarre en mode sans échec :
    Pour cela, tu tapotes la touche F8 dès le début de l’allumage du pc sans t’arrêter
    Une fenêtre va s’ouvrir tu te déplaces avec les flèches du clavier sur démarrer en mode sans échec puis tape entrée.
    Une fois sur le bureau s’il n’y a pas toutes les couleurs et autres c’est normal !
    (Si F8 ne marche pas utilise la touche F5).

    1)Double clique sur navilog1.bat
    Au menu principal, choisis 4 et valides.
    A la question posé, choisis "mode manuel" en tapant M ou m puis valides.
    Il va te demander de saisir le nom de fichier,
    saisies ce qui est en gras ci-dessous et rien d'autre puis valides:

    ysmtcb

    le fix va te demander de le resaisir, fais-le et valides
    Ton bureau va disparaitre, c'est normal.
    Laisses-toi guider
    Patientes jusqu'au message :
    *** Nettoyage Termine le ..... ***
    Appuies sur une touche comme demandé, le blocnote va s'ouvrir.
    Sauvegardes le rapport de manière à le retrouver
    Refermes le blocnote. Ton bureau va réapparaitre.
    Le rapport est en outre sauvegardé à la racine du disque (cleannavi.txt)
    1. Clean Navipromo version 3.6.9 commencé le 07/11/2008 à 0:23:33,07

      Outil exécuté depuis C:\Program Files\navilog1
      Session actuelle : "SEB"

      Mise à jour le 05.11.2008 à 21h00 par IL-MAFIOSO

      Microsoft Windows XP [version 5.1.2600]
      Internet Explorer : 7.0.5730.11
      Système de fichiers : NTFS

      Mode suppression par méthode manuelle

      Nom du fichier saisi : ysmtcb

      Nettoyage executé en mode sans échec

      *** Recherche, création sauvegardes et suppression ***

      * Suppression dans "C:\WINDOWS\system32" *

      ysmtcb.exe trouvé !
      Copie ysmtcb.exe réalisée avec succès !
      ysmtcb.exe supprimé !

      * Suppression dans "D:\Documents and Settings\SEB\locals~1\applic~1" *

      * Suppression dans "C:\DOCUME~1\AUTRES\locals~1\applic~1" *

      *** Suppression dossiers dans "C:\WINDOWS" ***

      *** Suppression dossiers dans "C:\Program Files" ***

      *** Suppression dossiers dans "D:\Documents and Settings\All Users\menudm~1\progra~1" ***

      *** Suppression dossiers dans "D:\Documents and Settings\All Users\menudm~1" ***

      *** Suppression dossiers dans "d:\docume~1\alluse~1\applic~1" ***

      *** Suppression dossiers dans "D:\Documents and Settings\SEB\applic~1" ***

      *** Suppression dossiers dans "C:\DOCUME~1\AUTRES\applic~1" ***

      *** Suppression dossiers dans "D:\Documents and Settings\SEB\locals~1\applic~1" ***

      *** Suppression dossiers dans "C:\DOCUME~1\AUTRES\locals~1\applic~1" ***

      *** Suppression dossiers dans "D:\Documents and Settings\SEB\menudm~1\progra~1" ***

      *** Suppression fichiers ***

      *** Suppression fichiers temporaires ***

      Nettoyage contenu C:\WINDOWS\Temp effectué !
      Nettoyage contenu D:\Documents and Settings\SEB\locals~1\Temp effectué !

      *** Traitement Recherche complémentaire ***
      (Recherche fichiers spécifiques)

      1)Suppression avec sauvegardes nouveaux fichiers Instant Access :

      2)Recherche, création sauvegardes et suppression Heuristique :

      * Dans "C:\WINDOWS\system32" *

      * Dans "D:\Documents and Settings\SEB\locals~1\applic~1" *

      * Dans "C:\DOCUME~1\AUTRES\locals~1\applic~1" *

      *** Sauvegarde du Registre vers dossier Safebackup ***

      sauvegarde du Registre réalisée avec succès !

      *** Nettoyage Registre ***

      Nettoyage Registre Ok

      *** Certificats ***

      Certificat Egroup absent !
      Certificat Electronic-Group absent !
      Certificat Montorgueil absent !
      Certificat OOO-Favorit absent !
      Certificat Sunny-Day-Design-Ltdt absent !

      *** Nettoyage terminé le 07/11/2008 à 0:27:19,62 ***
  12. Double cliques sur le raccourci Navilog1 présent sur le bureau et laisse-toi guider.
    Au menu principal, choisis 2 et valides.
    (ne fais pas le choix 3 ou 4 sans notre avis/accord)

    Le fix va t'informer qu'il va alors redémarrer ton PC
    Fermes toutes les fenêtres ouvertes et enregistre tes documents personnels ouverts
    Appuies sur une touche comme demandé.
    (si ton Pc ne redémarre pas automatiquement, fais le toi même)
    Au redémarrage de ton PC, choisis ta session habituelle.

    Patiente jusqu'au message :
    *** Nettoyage Termine le ..... ***
    Le bloc-notes va s'ouvrir.
    Sauvegarde le rapport de manière à le retrouver
    Referme le bloc-notes. Ton bureau va réapparaitre

    PS:Si ton bureau ne réapparait pas, fais CTRL+ALT+SUPP pour ouvrir le gestionnaire de tâches.
    Puis rends-toi à l'onglet "processus". Clique en haut à gauche sur fichiers et choisis "exécuter"
    Tape explorer et valide. Celà te fera apparaitre ton bureau.

    Postes le rapport içi.
    1. Clean Navipromo version 3.6.9 commencé le 07/11/2008 à 0:04:50,46

      Outil exécuté depuis C:\Program Files\navilog1
      Session actuelle : "SEB"

      Mise à jour le 05.11.2008 à 21h00 par IL-MAFIOSO

      Microsoft Windows XP [version 5.1.2600]
      Internet Explorer : 7.0.5730.11
      Système de fichiers : NTFS

      Mode suppression automatique
      avec prise en charge résultats Catchme et GNS

      Nettoyage exécuté au redémarrage de l'ordinateur

      *** fsbl1.txt non trouvé ***
      (Assurez-vous que Catchme n'avait rien trouvé lors de la recherche)

      *** Suppression avec sauvegardes résultats GenericNaviSearch ***

      * Suppression dans "C:\WINDOWS\System32" *

      kibywiadw.exe trouvé !
      Copie kibywiadw.exe réalisée avec succès !
      kibywiadw.exe supprimé !

      * Suppression dans "D:\Documents and Settings\SEB\locals~1\applic~1" *

      * Suppression dans "C:\DOCUME~1\AUTRES\locals~1\applic~1" *

      *** Suppression dossiers dans "C:\WINDOWS" ***

      *** Suppression dossiers dans "C:\Program Files" ***

      *** Suppression dossiers dans "D:\Documents and Settings\All Users\menudm~1\progra~1" ***

      *** Suppression dossiers dans "D:\Documents and Settings\All Users\menudm~1" ***

      *** Suppression dossiers dans "d:\docume~1\alluse~1\applic~1" ***

      *** Suppression dossiers dans "D:\Documents and Settings\SEB\applic~1" ***

      *** Suppression dossiers dans "C:\DOCUME~1\AUTRES\applic~1" ***

      *** Suppression dossiers dans "D:\Documents and Settings\SEB\locals~1\applic~1" ***

      *** Suppression dossiers dans "C:\DOCUME~1\AUTRES\locals~1\applic~1" ***

      *** Suppression dossiers dans "D:\Documents and Settings\SEB\menudm~1\progra~1" ***

      *** Suppression fichiers ***

      C:\WINDOWS\Downloaded Program Files\IaLdr32.inf supprimé !

      *** Suppression fichiers temporaires ***

      Nettoyage contenu C:\WINDOWS\Temp effectué !
      Nettoyage contenu D:\Documents and Settings\SEB\locals~1\Temp effectué !

      *** Traitement Recherche complémentaire ***
      (Recherche fichiers spécifiques)

      1)Suppression avec sauvegardes nouveaux fichiers Instant Access :

      2)Recherche, création sauvegardes et suppression Heuristique :

      * Dans "C:\WINDOWS\system32" *

      fmjsgo.dat trouvé !
      Copie fmjsgo.dat réalisée avec succès !
      fmjsgo.dat supprimé !

      golxtjugq.dat trouvé !
      Copie golxtjugq.dat réalisée avec succès !
      golxtjugq.dat supprimé !

      jlhfmsdtz.dat trouvé !
      Copie jlhfmsdtz.dat réalisée avec succès !
      jlhfmsdtz.dat supprimé !

      jtgqcb.dat trouvé !
      Copie jtgqcb.dat réalisée avec succès !
      jtgqcb.dat supprimé !

      lnnrru.dat trouvé !
      Copie lnnrru.dat réalisée avec succès !
      lnnrru.dat supprimé !

      mdovoujzg.dat trouvé !
      Copie mdovoujzg.dat réalisée avec succès !
      mdovoujzg.dat supprimé !

      othadwlfbc.dat trouvé !
      Copie othadwlfbc.dat réalisée avec succès !
      othadwlfbc.dat supprimé !

      rkhxvfqzz.dat trouvé !
      Copie rkhxvfqzz.dat réalisée avec succès !
      rkhxvfqzz.dat supprimé !

      rmreex.dat trouvé !
      Copie rmreex.dat réalisée avec succès !
      rmreex.dat supprimé !

      wzremeqn.dat trouvé !
      Copie wzremeqn.dat réalisée avec succès !
      wzremeqn.dat supprimé !

      xcfftxxovu.dat trouvé !
      Copie xcfftxxovu.dat réalisée avec succès !
      xcfftxxovu.dat supprimé !

      * Dans "D:\Documents and Settings\SEB\locals~1\applic~1" *

      * Dans "C:\DOCUME~1\AUTRES\locals~1\applic~1" *

      *** Sauvegarde du Registre vers dossier Safebackup ***

      sauvegarde du Registre réalisée avec succès !

      *** Nettoyage Registre ***

      Nettoyage Registre Ok

      *** Certificats ***

      Certificat Egroup supprimé !
      Certificat Electronic-Group supprimé !
      Certificat Montorgueil absent !
      Certificat OOO-Favorit supprimé !
      Certificat Sunny-Day-Design-Ltdt absent !

      *** Fichiers suspects non supprimés par Navilog1 ***
      !! Fichiers légitimes possibles, à contrôler avant suppression !!

      Fichiers suspects dans "C:\WINDOWS\system32" :

      ysmtcb.exe trouvé !
      ysmtcb.exe trouvé !

      *** Nettoyage terminé le 07/11/2008 à 0:08:47,68 ***
  13. ok parfait

    réouvre malewarebyte
    va sur quarantaine
    supprime tout

    Fais un clic droit sur ce lien : (IL-MAFIOSO)
    http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe
    Enregistrer la cible (du lien) sous... et enregistre-le sur ton bureau.
    Ensuite double clique sur navilog1.exe pour lancer l'installation.
    Une fois l'installation terminée, le fix s'exécutera automatiquement.
    (Si ce n'est pas le cas, double-clique sur le raccourci Navilog1 présent sur le bureau).

    Laisse-toi guider. Au menu principal, choisis 1 et valides.
    (ne fais pas le choix 2,3 ou 4 sans notre avis/accord)

    Patiente jusqu'au message :
    *** Analyse Termine le ..... ***
    Appuie sur une touche comme demandé, le blocnote va s'ouvrir.
    Copie-colle l'intégralité dans une réponse. Referme le blocnote.
    Le rapport est en outre sauvegardé à la racine du disque (fixnavi.txt)

    Tuto: http://www.malekal.com/Adware.Magic_Control.php
    1. Search Navipromo version 3.6.9 commencé le 06/11/2008 à 23:50:07,89

      !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
      !!! Postez ce rapport sur le forum pour le faire analyser !!!
      !!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

      Outil exécuté depuis C:\Program Files\navilog1
      Session actuelle : "SEB"

      Mise à jour le 05.11.2008 à 21h00 par IL-MAFIOSO

      Microsoft Windows XP [version 5.1.2600]
      Internet Explorer : 7.0.5730.11
      Système de fichiers : NTFS

      Recherche executé en mode normal

      *** Recherche Programmes installés ***

      Favorit
      WebMediaPlayer

      *** Recherche dossiers dans "C:\WINDOWS" ***

      *** Recherche dossiers dans "C:\Program Files" ***

      *** Recherche dossiers dans "D:\Documents and Settings\All Users\menudm~1\progra~1" ***

      *** Recherche dossiers dans "D:\Documents and Settings\All Users\menudm~1" ***

      *** Recherche dossiers dans "d:\docume~1\alluse~1\applic~1" ***

      *** Recherche dossiers dans "D:\Documents and Settings\SEB\applic~1" ***

      *** Recherche dossiers dans "C:\DOCUME~1\AUTRES\applic~1" ***

      *** Recherche dossiers dans "D:\Documents and Settings\SEB\locals~1\applic~1" ***

      *** Recherche dossiers dans "C:\DOCUME~1\AUTRES\locals~1\applic~1" ***

      *** Recherche dossiers dans "D:\Documents and Settings\SEB\menudm~1\progra~1" ***

      *** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
      pour + d'infos : http://www.gmer.net

      *** Recherche avec GenericNaviSearch ***
      !!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
      !!! A vérifier impérativement avant toute suppression manuelle !!!

      * Recherche dans "C:\WINDOWS\system32" *

      Fichiers trouvés :

      kibywiadw.exe trouvé !

      Fichiers suspects :

      ysmtcb.exe trouvé !

      * Recherche dans "D:\Documents and Settings\SEB\locals~1\applic~1" *

      * Recherche dans "C:\DOCUME~1\AUTRES\locals~1\applic~1" *

      *** Recherche fichiers ***

      C:\WINDOWS\Downloaded Program Files\IaLdr32.inf trouvé !

      *** Recherche clés spécifiques dans le Registre ***

      HKEY_CURRENT_USER\Software\Lanconfig trouvé !

      *** Module de Recherche complémentaire ***
      (Recherche fichiers spécifiques)

      1)Recherche nouveaux fichiers Instant Access :

      2)Recherche Heuristique :

      * Dans "C:\WINDOWS\system32" :

      fmjsgo.dat trouvé !
      golxtjugq.dat trouvé !
      jlhfmsdtz.dat trouvé !
      jtgqcb.dat trouvé !
      lnnrru.dat trouvé !
      mdovoujzg.dat trouvé !
      othadwlfbc.dat trouvé !
      rkhxvfqzz.dat trouvé !
      rmreex.dat trouvé !
      wzremeqn.dat trouvé !
      xcfftxxovu.dat trouvé !

      * Dans "D:\Documents and Settings\SEB\locals~1\applic~1" :

      * Dans "C:\DOCUME~1\AUTRES\locals~1\applic~1" :

      3)Recherche Certificats :

      Certificat Egroup trouvé !
      Certificat Electronic-Group trouvé !
      Certificat Montorgueil absent !
      Certificat OOO-Favorit trouvé !
      Certificat Sunny-Day-Design-Ltd absent !

      4)Recherche fichiers connus :

      *** Analyse terminée le 06/11/2008 à 23:53:33,37 ***
  14. Cela aura été long, mais j'ai été patient, lors de l'analyse, il m'a été demmandé un grand nombre de fois si je voulais interdir l'acces(denied acces ) par défaut , j'ais mis la plupart du temps supprimer (delete) et sur la fin , j'ais pris la chec box par défaut : denied acces.
    1. non ça c est le rappport de la mise a jours

      ok fait ceci :

      Telecharge malwarebytes

      Tu l´instale; le programme va se mettre automatiquement a jour.

      Une fois a jour, le programme va se lancer; click sur l´onglet parametre, et coche la case : "Arreter internet explorer pendant la suppression".

      Click maintenant sur l´onglet recherche et coche la case : "executer un examen complet".

      Puis click sur "rechercher".

      Laisse le scanner le pc...

      Si des elements on ete trouvés > click sur supprimer la selection.

      si il t´es demandé de redemarrer > click sur "yes".

      A la fin un rapport va s´ouvrir; sauvegarde le de maniere a le retrouver en vu de le poster sur le forum.

      Copie et colle le rapport stp.

      PS : les rapport sont aussi rangé dans l onglet rapport/log

      1. Malwarebytes' Anti-Malware 1.30
        Version de la base de données: 1370
        Windows 5.1.2600 Service Pack 2

        06/11/2008 23:34:05
        mbam-log-2008-11-06 (23-34-05).txt

        Type de recherche: Examen complet (C:\|D:\|)
        Eléments examinés: 166347
        Temps écoulé: 55 minute(s), 51 second(s)

        Processus mémoire infecté(s): 0
        Module(s) mémoire infecté(s): 0
        Clé(s) du Registre infectée(s): 23
        Valeur(s) du Registre infectée(s): 2
        Elément(s) de données du Registre infecté(s): 0
        Dossier(s) infecté(s): 4
        Fichier(s) infecté(s): 39

        Processus mémoire infecté(s):
        (Aucun élément nuisible détecté)

        Module(s) mémoire infecté(s):
        (Aucun élément nuisible détecté)

        Clé(s) du Registre infectée(s):
        HKEY_CLASSES_ROOT\CLSID\{9afb8248-617f-460d-9366-d71cdeda3179} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
        HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{2d2bee6e-3c9a-4d58-b9ec-458edb28d0f6} (Rogue.DriveCleaner) -> Quarantined and deleted successfully.
        HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18ea9-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
        HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18eab-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
        HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3dc201fb-e9c9-499c-a11f-23c360d7c3f8} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
        HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{9ff05104-b030-46fc-94b8-81276e4e27df} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
        HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00a6faf1-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
        HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
        HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{201b9b37-848f-40bd-90ea-7b8f0aa89d6a} (Adware.EGDAccess) -> Quarantined and deleted successfully.
        HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{aa59202c-5e41-48fc-af7d-324f5fd6a9f1} (Adware.EGDAccess) -> Quarantined and deleted successfully.
        HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{cb5d474e-a510-40a4-b5a4-838933bcba64} (Adware.EGDAccess) -> Quarantined and deleted successfully.
        HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{fa1d6d8f-c6ed-4752-8512-a33283240130} (Adware.EGDAccess) -> Quarantined and deleted successfully.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{09f1adac-76d8-4d0f-99a5-5c907dadb988} (Rogue.Multiple) -> Quarantined and deleted successfully.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{201b9b37-848f-40bd-90ea-7b8f0aa89d6a} (Adware.EGDAccess) -> Quarantined and deleted successfully.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{aa59202c-5e41-48fc-af7d-324f5fd6a9f1} (Adware.EGDAccess) -> Quarantined and deleted successfully.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{25560540-9571-4d7b-9389-0f166788785a} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3dc201fb-e9c9-499c-a11f-23c360d7c3f8} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{63d0ed2c-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{98d9753d-d73b-42d5-8c85-4469cda897ab} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{9ff05104-b030-46fc-94b8-81276e4e27df} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Instant Access (Adware.InstantAccess) -> Quarantined and deleted successfully.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\WebMediaPlayer.exe (Adware.EGDAccess) -> Quarantined and deleted successfully.

        Valeur(s) du Registre infectée(s):
        HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\kycqs (Adware.Navipromo.H) -> Quarantined and deleted successfully.
        HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Instant Access (Adware.InstantAccess) -> Quarantined and deleted successfully.

        Elément(s) de données du Registre infecté(s):
        (Aucun élément nuisible détecté)

        Dossier(s) infecté(s):
        C:\Program Files\WebMediaPlayer (Rogue.WebMediaPlayer) -> Quarantined and deleted successfully.
        C:\Program Files\WebMediaPlayer\resources (Rogue.WebMediaPlayer) -> Quarantined and deleted successfully.
        C:\Program Files\WebMediaPlayer\skins (Rogue.WebMediaPlayer) -> Quarantined and deleted successfully.
        C:\Program Files\WebMediaPlayer\updates (Rogue.WebMediaPlayer) -> Quarantined and deleted successfully.

        Fichier(s) infecté(s):
        D:\Documents and Settings\SEB\Local Settings\Application Data\kycqs_navps.dat (Adware.Navipromo.H) -> Quarantined and deleted successfully.
        D:\Documents and Settings\SEB\Local Settings\Application Data\kycqs_nav.dat (Adware.Navipromo.H) -> Quarantined and deleted successfully.
        D:\Documents and Settings\SEB\Local Settings\Application Data\kycqs.dat (Adware.Navipromo.H) -> Quarantined and deleted successfully.
        D:\Documents and Settings\SEB\Local Settings\Application Data\kycqs.exe (Adware.Navipromo.H) -> Quarantined and deleted successfully.
        C:\Program Files\MSN Messenger\riched20.dll (Adware.MyWeb.FunWeb) -> Quarantined and deleted successfully.
        C:\Program Files\WebMediaPlayer\Conditions générales.url (Rogue.WebMediaPlayer) -> Quarantined and deleted successfully.
        C:\Program Files\WebMediaPlayer\Confidentialité.url (Rogue.WebMediaPlayer) -> Quarantined and deleted successfully.
        C:\Program Files\WebMediaPlayer\sqlite3.dll (Rogue.WebMediaPlayer) -> Quarantined and deleted successfully.
        C:\Program Files\WebMediaPlayer\WebMediaPlayer.exe (Rogue.WebMediaPlayer) -> Quarantined and deleted successfully.
        C:\Program Files\WebMediaPlayer\Website.url (Rogue.WebMediaPlayer) -> Quarantined and deleted successfully.
        C:\Program Files\WebMediaPlayer\resources\languages_v2.xml (Rogue.WebMediaPlayer) -> Quarantined and deleted successfully.
        C:\Program Files\WebMediaPlayer\resources\webmedias (Rogue.WebMediaPlayer) -> Quarantined and deleted successfully.
        C:\Program Files\WebMediaPlayer\skins\classic.skn (Rogue.WebMediaPlayer) -> Quarantined and deleted successfully.
        C:\Program Files\setup.exe (Rogue.Installer) -> Quarantined and deleted successfully.
        C:\WINDOWS\tmlpcert2007 (Adware.EGDAccess) -> Quarantined and deleted successfully.
        C:\WINDOWS\system32\fmjsgo_navps.dat (Adware.NaviPromo) -> Quarantined and deleted successfully.
        C:\WINDOWS\system32\golxtjugq_navps.dat (Adware.NaviPromo) -> Quarantined and deleted successfully.
        C:\WINDOWS\system32\jlhfmsdtz_navps.dat (Adware.NaviPromo) -> Quarantined and deleted successfully.
        C:\WINDOWS\system32\jtgqcb_navps.dat (Adware.NaviPromo) -> Quarantined and deleted successfully.
        C:\WINDOWS\system32\lnnrru_navps.dat (Adware.NaviPromo) -> Quarantined and deleted successfully.
        C:\WINDOWS\system32\mdovoujzg_navps.dat (Adware.NaviPromo) -> Quarantined and deleted successfully.
        C:\WINDOWS\system32\othadwlfbc_navps.dat (Adware.NaviPromo) -> Quarantined and deleted successfully.
        C:\WINDOWS\system32\rkhxvfqzz_navps.dat (Adware.NaviPromo) -> Quarantined and deleted successfully.
        C:\WINDOWS\system32\rmreex_navps.dat (Adware.NaviPromo) -> Quarantined and deleted successfully.
        C:\WINDOWS\system32\wzremeqn_navps.dat (Adware.NaviPromo) -> Quarantined and deleted successfully.
        C:\WINDOWS\system32\xcfftxxovu_navps.dat (Adware.NaviPromo) -> Quarantined and deleted successfully.
        C:\WINDOWS\system32\fmjsgo_nav.dat (Adware.NaviPromo) -> Quarantined and deleted successfully.
        C:\WINDOWS\system32\golxtjugq_nav.dat (Adware.NaviPromo) -> Quarantined and deleted successfully.
        C:\WINDOWS\system32\jlhfmsdtz_nav.dat (Adware.NaviPromo) -> Quarantined and deleted successfully.
        C:\WINDOWS\system32\jtgqcb_nav.dat (Adware.NaviPromo) -> Quarantined and deleted successfully.
        C:\WINDOWS\system32\lnnrru_nav.dat (Adware.NaviPromo) -> Quarantined and deleted successfully.
        C:\WINDOWS\system32\mdovoujzg_nav.dat (Adware.NaviPromo) -> Quarantined and deleted successfully.
        C:\WINDOWS\system32\othadwlfbc_nav.dat (Adware.NaviPromo) -> Quarantined and deleted successfully.
        C:\WINDOWS\system32\rkhxvfqzz_nav.dat (Adware.NaviPromo) -> Quarantined and deleted successfully.
        C:\WINDOWS\system32\rmreex_nav.dat (Adware.NaviPromo) -> Quarantined and deleted successfully.
        C:\WINDOWS\system32\wzremeqn_nav.dat (Adware.NaviPromo) -> Quarantined and deleted successfully.
        C:\WINDOWS\system32\xcfftxxovu_nav.dat (Adware.NaviPromo) -> Quarantined and deleted successfully.
        C:\WINDOWS\system32\nvs2.inf (Adware.EGDAccess) -> Quarantined and deleted successfully.
        D:\Documents and Settings\SEB\Menu Démarrer\NoCreditCard.lnk (Dialer) -> Quarantined and deleted successfully.
    2. re

      tu as lancé antivir ??
      1. Oui, et je t'ai envoyé le resultat du scan
        seb
    3. Modérateur
      On sait juste que la session que tu utilises s'appelle Seb, rien de très grave.
      1. non elle suffit amplement

        on y ajoutera un complément (gratuit) par la suite
        1. Est-ce dangereux de laisser tous les informations que j'ai postés sur le forum?
          seb
        2. En tous cas merci de ton temps passé pour me dépanné
          seb
      2. supprime ceci :

        D:\Documents and Settings\SEB\Mes documents\Mes vid‚os\word\Microsoft Serial, Key, Crack all versions95, 98, 98 SE, 2000, XP, Corp, Visual C++, Visual Basic, Excel, Money, Office, publisher, word.rar
        D:\Documents and Settings\SEB\Mes documents\Mes vid‚os\word\password ultimate cracker (zip,word,excel).rar

        ensuite :

        instal un antivirus je te conseil antivir (gratuit)

        ->Antivir le telecharger

        met le a jours lance le scan et post son rapport stp
        1. 06.11.2008 21:48:59 - Installation Directory: C:\Program Files\Avira\AntiVir PersonalEdition Classic\
          06.11.2008 21:48:59 - Backup Directory: D:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\BACKUP\
          06.11.2008 21:48:59 - Temp Directory: D:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\Update\AVUPDATE_4913583a\
          06.11.2008 21:48:59 - Using System's global Proxy settings
          06.11.2008 21:48:59 - Launching GUI... display mode: 0
          06.11.2008 21:48:59 - selftest successful: C:\Program Files\Avira\AntiVir PersonalEdition Classic\updlib.dll
          06.11.2008 21:48:59 - selftest successful: C:\Program Files\Avira\AntiVir PersonalEdition Classic\updlibrc.dll
          06.11.2008 21:48:59 - Installation Directory: C:\Program Files\Avira\AntiVir PersonalEdition Classic\
          06.11.2008 21:48:59 - Backup Directory: D:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\BACKUP\
          06.11.2008 21:48:59 - Temp Directory: D:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\Update\AVUPDATE_4913583a\
          06.11.2008 21:48:59 - Using System's global Proxy settings
          06.11.2008 21:48:59 - Launching GUI... display mode: 0
          06.11.2008 21:48:59 - selftest successful: C:\Program Files\Avira\AntiVir PersonalEdition Classic\updlib.dll
          06.11.2008 21:48:59 - selftest successful: C:\Program Files\Avira\AntiVir PersonalEdition Classic\updlibrc.dll
          06.11.2008 21:48:59 - Avira AntiVir Personal - Free Antivirus
          06.11.2008 21:49:00 - Copy file D:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\Update\AVUPDATE_4913583a\idx/master.idx to D:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\IDX\master.idx
          06.11.2008 21:49:00 - Master IDX file has changed
          06.11.2008 21:49:01 - Downloading the product.info file from http://dl10.freeav.net/upd/idx/classic-nt-en.info.gz
          06.11.2008 21:49:01 - Copy file D:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\Update\AVUPDATE_4913583a\classic-nt-en.info to D:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\IDX\classic-nt-en.info
          06.11.2008 21:49:01 - Downloading the product.info file from http://dl10.freeav.net/upd/idx/vdf.info.gz
          06.11.2008 21:49:02 - Downloading the product.info file from http://dl10.freeav.net/upd/idx/specvir-nt.info.gz
          06.11.2008 21:49:02 - Downloading the product.info file from http://dl10.freeav.net/upd/idx/ave2.info.gz
          06.11.2008 21:49:03 - Downloading the product.info file from http://dl10.freeav.net/upd/idx/info-wks-classic-nt-en.info.gz
          06.11.2008 21:49:04 - Module: SELFUPDATE Source: winwks\en\ Destination: C:\Program Files\Avira\AntiVir PersonalEdition Classic\ Files: 15
          06.11.2008 21:49:04 - Module: MAIN Source: winwks\en\ Destination: C:\Program Files\Avira\AntiVir PersonalEdition Classic\ Files: 83
          06.11.2008 21:49:04 - Module: COMMAPPDATA_AV Source: winwks\en\ Destination: D:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\ Files: 1
          06.11.2008 21:49:04 - Module: COMMAPP Source: winwks\en\ Destination: D:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\JOBS\ Files: 4
          06.11.2008 21:49:04 - Module: COMMAPDATA_AV_PROFILES Source: winwks\en\ Destination: D:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\PROFILES\ Files: 2
          06.11.2008 21:49:04 - Module: TEXT Source: winwks\en\ Destination: C:\Program Files\Avira\AntiVir PersonalEdition Classic\ Files: 3
          06.11.2008 21:49:04 - Module: VDF Source: vdf\ Destination: C:\Program Files\Avira\AntiVir PersonalEdition Classic\ Files: 4
          06.11.2008 21:49:04 - C:\Program Files\Avira\AntiVir PersonalEdition Classic\antivir0.vdf 6.40.0.0 < 7.1.0.0
          06.11.2008 21:49:04 - C:\Program Files\Avira\AntiVir PersonalEdition Classic\antivir1.vdf 7.0.5.1 < 7.1.0.21
          06.11.2008 21:49:04 - C:\Program Files\Avira\AntiVir PersonalEdition Classic\antivir2.vdf 7.0.5.20 < 7.1.0.44
          06.11.2008 21:49:04 - C:\Program Files\Avira\AntiVir PersonalEdition Classic\antivir3.vdf 7.0.5.23 < 7.1.0.49
          06.11.2008 21:49:04 - Module: AVREP_NT Source: engine\nt\ Destination: C:\Program Files\Avira\AntiVir PersonalEdition Classic\ Files: 1
          06.11.2008 21:49:04 - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avrep.dll 7.0.0.1 < 8.0.0.2
          06.11.2008 21:49:04 - Module: AVE2 Source: ave2\ Destination: C:\Program Files\Avira\AntiVir PersonalEdition Classic\ Files: 14
          06.11.2008 21:49:04 - C:\Program Files\Avira\AntiVir PersonalEdition Classic\aecore.dll 8.1.2.6 < 8.1.2.9
          06.11.2008 21:49:04 - C:\Program Files\Avira\AntiVir PersonalEdition Classic\aegen.dll 8.1.0.41 < 8.1.0.43
          06.11.2008 21:49:04 - C:\Program Files\Avira\AntiVir PersonalEdition Classic\aeheur.dll 8.1.0.59 < 8.1.0.68
          06.11.2008 21:49:04 - C:\Program Files\Avira\AntiVir PersonalEdition Classic\aeoffice.dll 8.1.0.28 < 8.1.0.29
          06.11.2008 21:49:04 - C:\Program Files\Avira\AntiVir PersonalEdition Classic\aepack.dll 8.1.2.4 < 8.1.3.3
          06.11.2008 21:49:04 - C:\Program Files\Avira\AntiVir PersonalEdition Classic\aerdl.dll 8.1.1.2 < 8.1.1.3
          06.11.2008 21:49:04 - C:\Program Files\Avira\AntiVir PersonalEdition Classic\aescript.dll 8.1.1.8 < 8.1.1.13
          06.11.2008 21:49:04 - C:\Program Files\Avira\AntiVir PersonalEdition Classic\aeset.dat 8.2.0.4 < 8.2.0.26
          06.11.2008 21:49:04 - Module: DRV Source: winwks\en\ Destination: C:\WINDOWS\SYSTEM32\drivers\ Files: 4
          06.11.2008 21:49:04 - Module: PRODINFO Source: winwks\en\ Destination: C:\Program Files\Avira\AntiVir PersonalEdition Classic\ Files: 1
          06.11.2008 21:49:04 - Minifilter is installed
          06.11.2008 21:49:04 - Minifilter is possible
          06.11.2008 21:49:04 - Reading registry value successful: Software\Avira\AntiVir PersonalEdition Classic | FilterType
          06.11.2008 21:49:04 - Initialize avnotify.exe
          06.11.2008 21:49:05 - Starting avnotify.exe successful
          06.11.2008 21:49:05 - Preparing to download files
          06.11.2008 21:49:05 - 15 files need to be downloaded / copied from http://dl10.freeav.net/upd/
          06.11.2008 21:49:05 - #1: Downloading and extracting http://dl10.freeav.net/upd/winwks/en/classic-nt/filelist.ini.gz to D:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\Update\AVUPDATE_4913583a\winwks\en\classic-nt/filelist.ini
          06.11.2008 21:49:05 - #2: Downloading and extracting http://dl10.freeav.net/upd/winwks/en/classic-nt/product.ini.gz to D:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\Update\AVUPDATE_4913583a\winwks\en\classic-nt/product.ini
          06.11.2008 21:49:06 - #3: Downloading and extracting http://dl10.freeav.net/upd/vdf/antivir0.vdf.gz to D:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\Update\AVUPDATE_4913583a\vdf\antivir0.vdf
          06.11.2008 21:49:50 - #4: Downloading and extracting http://dl10.freeav.net/upd/vdf/antivir1.vdf.gz to D:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\Update\AVUPDATE_4913583a\vdf\antivir1.vdf
          06.11.2008 21:49:51 - #5: Downloading and extracting http://dl10.freeav.net/upd/vdf/antivir2.vdf.gz to D:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\Update\AVUPDATE_4913583a\vdf\antivir2.vdf
          06.11.2008 21:49:52 - #6: Downloading and extracting http://dl10.freeav.net/upd/vdf/antivir3.vdf.gz to D:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\Update\AVUPDATE_4913583a\vdf\antivir3.vdf
          06.11.2008 21:49:53 - #7: Downloading and extracting http://dl10.freeav.net/upd/engine/nt/avrep.dll.gz to D:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\Update\AVUPDATE_4913583a\engine\nt\avrep.dll
          06.11.2008 21:49:53 - #8: Downloading and extracting http://dl10.freeav.net/upd/ave2/aecore.dll.gz to D:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\Update\AVUPDATE_4913583a\ave2\aecore.dll
          06.11.2008 21:49:54 - #9: Downloading and extracting http://dl10.freeav.net/upd/ave2/aegen.dll.gz to D:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\Update\AVUPDATE_4913583a\ave2\aegen.dll
          06.11.2008 21:49:55 - #10: Downloading and extracting http://dl10.freeav.net/upd/ave2/aeheur.dll.gz to D:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\Update\AVUPDATE_4913583a\ave2\aeheur.dll
          06.11.2008 21:49:57 - #11: Downloading and extracting http://dl10.freeav.net/upd/ave2/aeoffice.dll.gz to D:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\Update\AVUPDATE_4913583a\ave2\aeoffice.dll
          06.11.2008 21:49:57 - #12: Downloading and extracting http://dl10.freeav.net/upd/ave2/aepack.dll.gz to D:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\Update\AVUPDATE_4913583a\ave2\aepack.dll
          06.11.2008 21:49:58 - #13: Downloading and extracting http://dl10.freeav.net/upd/ave2/aerdl.dll.gz to D:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\Update\AVUPDATE_4913583a\ave2\aerdl.dll
          06.11.2008 21:49:59 - #14: Downloading and extracting http://dl10.freeav.net/upd/ave2/aescript.dll.gz to D:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\Update\AVUPDATE_4913583a\ave2\aescript.dll
          06.11.2008 21:50:00 - #15: Downloading and extracting http://dl10.freeav.net/upd/ave2/aeset.dat.gz to D:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\Update\AVUPDATE_4913583a\ave2\aeset.dat
          06.11.2008 21:50:09 - Keyfile: OK [FULL Mode]
          06.11.2008 21:50:09 - Status of service AntiVirService is running
          06.11.2008 21:50:09 - Initialize avscan.exe
          06.11.2008 21:50:09 - Initialize avcenter.exe
          06.11.2008 21:50:09 - Initialize avgnt.exe
          06.11.2008 21:50:09 - avscan.exe closed.
          06.11.2008 21:50:10 - avgnt.exe closed.
          06.11.2008 21:50:10 - Starting to install
          06.11.2008 21:50:10 - File C:\Program Files\Avira\AntiVir PersonalEdition Classic\filelist.ini will not be backed up because it doesn't exist
          06.11.2008 21:50:10 - File C:\Program Files\Avira\AntiVir PersonalEdition Classic\product.ini will not be backed up because it doesn't exist
          06.11.2008 21:50:10 - Processing module MAIN Source: D:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\Update\AVUPDATE_4913583a\winwks\en\ Destination: C:\Program Files\Avira\AntiVir PersonalEdition Classic\
          06.11.2008 21:50:10 - Copy file D:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\Update\AVUPDATE_4913583a\winwks\en\classic-nt/filelist.ini to C:\Program Files\Avira\AntiVir PersonalEdition Classic\filelist.ini
          06.11.2008 21:50:10 - Copy file D:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\Update\AVUPDATE_4913583a\winwks\en\classic-nt/product.ini to C:\Program Files\Avira\AntiVir PersonalEdition Classic\product.ini
          06.11.2008 21:50:10 - Copy file C:\Program Files\Avira\AntiVir PersonalEdition Classic\antivir0.vdf to D:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\BACKUP\antivir0.vdf
          06.11.2008 21:50:10 - Copy file C:\Program Files\Avira\AntiVir PersonalEdition Classic\antivir1.vdf to D:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\BACKUP\antivir1.vdf
          06.11.2008 21:50:10 - Copy file C:\Program Files\Avira\AntiVir PersonalEdition Classic\antivir2.vdf to D:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\BACKUP\antivir2.vdf
          06.11.2008 21:50:10 - Copy file C:\Program Files\Avira\AntiVir PersonalEdition Classic\antivir3.vdf to D:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\BACKUP\antivir3.vdf
          06.11.2008 21:50:10 - Processing module VDF Source: D:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\Update\AVUPDATE_4913583a\vdf\ Destination: C:\Program Files\Avira\AntiVir PersonalEdition Classic\
          06.11.2008 21:50:12 - Copy file D:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\Update\AVUPDATE_4913583a\vdf\antivir0.vdf to C:\Program Files\Avira\AntiVir PersonalEdition Classic\antivir0.vdf
          06.11.2008 21:50:12 - Copy file D:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\Update\AVUPDATE_4913583a\vdf\antivir1.vdf to C:\Program Files\Avira\AntiVir PersonalEdition Classic\antivir1.vdf
          06.11.2008 21:50:12 - Copy file D:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\Update\AVUPDATE_4913583a\vdf\antivir2.vdf to C:\Program Files\Avira\AntiVir PersonalEdition Classic\antivir2.vdf
          06.11.2008 21:50:12 - Copy file D:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\Update\AVUPDATE_4913583a\vdf\antivir3.vdf to C:\Program Files\Avira\AntiVir PersonalEdition Classic\antivir3.vdf
          06.11.2008 21:50:12 - Copy file C:\Program Files\Avira\AntiVir PersonalEdition Classic\avrep.dll to D:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\BACKUP\avrep.dll
          06.11.2008 21:50:12 - Processing module AVREP_NT Source: D:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\Update\AVUPDATE_4913583a\engine\nt\ Destination: C:\Program Files\Avira\AntiVir PersonalEdition Classic\
          06.11.2008 21:50:12 - Copy file D:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\Update\AVUPDATE_4913583a\engine\nt\avrep.dll to C:\Program Files\Avira\AntiVir PersonalEdition Classic\avrep.dll
          06.11.2008 21:50:12 - Copy file C:\Program Files\Avira\AntiVir PersonalEdition Classic\aecore.dll to D:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\BACKUP\aecore.dll
          06.11.2008 21:50:12 - Copy file C:\Program Files\Avira\AntiVir PersonalEdition Classic\aegen.dll to D:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\BACKUP\aegen.dll
          06.11.2008 21:50:12 - Copy file C:\Program Files\Avira\AntiVir PersonalEdition Classic\aeheur.dll to D:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\BACKUP\aeheur.dll
          06.11.2008 21:50:12 - Copy file C:\Program Files\Avira\AntiVir PersonalEdition Classic\aeoffice.dll to D:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\BACKUP\aeoffice.dll
          06.11.2008 21:50:12 - Copy file C:\Program Files\Avira\AntiVir PersonalEdition Classic\aepack.dll to D:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\BACKUP\aepack.dll
          06.11.2008 21:50:12 - Copy file C:\Program Files\Avira\AntiVir PersonalEdition Classic\aerdl.dll to D:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\BACKUP\aerdl.dll
          06.11.2008 21:50:12 - Copy file C:\Program Files\Avira\AntiVir PersonalEdition Classic\aescript.dll to D:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\BACKUP\aescript.dll
          06.11.2008 21:50:12 - Copy file C:\Program Files\Avira\AntiVir PersonalEdition Classic\aeset.dat to D:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\BACKUP\aeset.dat
          06.11.2008 21:50:12 - Processing module AVE2 Source: D:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\Update\AVUPDATE_4913583a\ave2\ Destination: C:\Program Files\Avira\AntiVir PersonalEdition Classic\
          06.11.2008 21:50:13 - Copy file D:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\Update\AVUPDATE_4913583a\ave2\aecore.dll to C:\Program Files\Avira\AntiVir PersonalEdition Classic\aecore.dll
          06.11.2008 21:50:14 - Copy file D:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\Update\AVUPDATE_4913583a\ave2\aegen.dll to C:\Program Files\Avira\AntiVir PersonalEdition Classic\aegen.dll
          06.11.2008 21:50:16 - Copy file D:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\Update\AVUPDATE_4913583a\ave2\aeheur.dll to C:\Program Files\Avira\AntiVir PersonalEdition Classic\aeheur.dll
          06.11.2008 21:50:17 - Copy file D:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\Update\AVUPDATE_4913583a\ave2\aeoffice.dll to C:\Program Files\Avira\AntiVir PersonalEdition Classic\aeoffice.dll
          06.11.2008 21:50:18 - Copy file D:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\Update\AVUPDATE_4913583a\ave2\aepack.dll to C:\Program Files\Avira\AntiVir PersonalEdition Classic\aepack.dll
          06.11.2008 21:50:19 - Copy file D:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\Update\AVUPDATE_4913583a\ave2\aerdl.dll to C:\Program Files\Avira\AntiVir PersonalEdition Classic\aerdl.dll
          06.11.2008 21:50:20 - Copy file D:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\Update\AVUPDATE_4913583a\ave2\aescript.dll to C:\Program Files\Avira\AntiVir PersonalEdition Classic\aescript.dll
          06.11.2008 21:50:20 - Copy file D:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\Update\AVUPDATE_4913583a\ave2\aeset.dat to C:\Program Files\Avira\AntiVir PersonalEdition Classic\aeset.dat
          06.11.2008 21:50:20 - A total of 15 files were updated
          06.11.2008 21:50:20 - Initialize AVWSC.EXE
          06.11.2008 21:50:20 - Registry entry created successfully: Software\Avira\AntiVir PersonalEdition Classic |UpdateInProgress
          06.11.2008 21:50:20 - Status of service AntiVirService is running
          06.11.2008 21:50:22 - Reinitialization of AntiVirService carried out successfully.
          06.11.2008 21:50:22 - Starting avgnt.exe successful
          06.11.2008 21:50:22 - Dialup: 0
          06.11.2008 21:50:22 - Downloaded bytes: 17450427
          06.11.2008 21:50:22 - Downloaded file(s): 15
          06.11.2008 21:50:22 - Downloaded file(s): filelist.ini; product.ini; antivir0.vdf; antivir1.vdf; antivir2.vdf; antivir3.vdf; avrep.dll; aecore.dll; aegen.dll; aeheur.dll
          06.11.2008 21:50:22 - Downloaded file(s): aeoffice.dll; aepack.dll; aerdl.dll; aescript.dll; aeset.dat
          06.11.2008 21:50:22 - Required time: 01:23
          06.11.2008 21:50:22 - Registry entry created successfully: Software\Avira\AntiVir PersonalEdition Classic |LastUpdate
          06.11.2008 21:50:23 - Update finished successfully
        2. @sebLa version de antivir est une version gratuite, est-elle suffisante pour proteger mon PC ou faut-il impérativement acheter la version complete?
          seb
      • 1
      • 2