Virtumonde

Bonjour,
quand je passe spybot, je vois qu'il lit un assez long moment des lignes intitulées "virtumonde dll". j'ai regardé un peu dans le forum de comment ca marche et j'ai passé HijackThis après l'avoir renommé en CCMexe. Voilà le résultat de scan. Pouvez vous me dire si mon pc est infecté et comment m'en débarrasser. Merci beaucoup d'avance. Je suis sous xp.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:15:21, on 27/12/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Google\Update\1.2.183.13\GoogleCrashHandler.exe
C:\Program Files\Maxtor\Sync\SyncServices.exe
c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
C:\Program Files\CDBurnerXP\NMSAccessU.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\AxBx\VirusKeeper 2009 Pro\vk_service.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\system32\scvhost\svchost.exe
C:\WINDOWS\system32\wuauserv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
C:\WINDOWS\stsystra.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Vista Drive Icon\DrvIcon.exe
C:\Program Files\AxBx\VirusKeeper 2009 Pro\VirusKeeper.exe
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\IncrediMail\bin\IncMail.exe
C:\Program Files\X'nBeep 1.1\XnBeep.exe
C:\Program Files\CursorXP.exe
C:\PROGRA~1\Magentic\bin\MgApp.exe
C:\Program Files\RocketDock\RocketDock.exe
C:\Program Files\Calendrier\Cld2000.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Hercules\WiFi Station\WifiStation.exe
C:\Program Files\DateInTray\DateInTray.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\WINDOWS\BricoPacks\Crystal Clear\YzToolbar\YzToolBar.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\IncrediMail\bin\IMApp.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\AxBx\VirusKeeper 2009 Pro\vk_watchop.exe
C:\Documents and Settings\Laurent\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Laurent\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Laurent\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Laurent\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Laurent\Bureau\CCM.exe.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.cherche.us
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.cherche.us/keyword/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.cherche.us
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://mystart.incredimail.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.cherche.us
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.cherche.us/keyword/%s
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.cherche.us
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell.fr/myway
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;*.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - (no file)
F2 - REG:system.ini: UserInit=userinit.exe,C:\WINDOWS\system32\scvhost\svchost.exe,wuauserv.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - (no file)
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: GamesBarBHO Class - {CB0D163C-E9F4-4236-9496-0597E24B23A5} - C:\Program Files\GamesBar\oberontb.dll
O2 - BHO: SHOUTcast Loader - {ccec60fc-2608-4e58-9659-3ffc159e8ea9} - C:\Program Files\SHOUTcast Radio Toolbar\shoutcasttb.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Google Gears Helper - {E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.33.0\gears.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: SHOUTcast Radio Toolbar - {0457331d-8ca6-4f97-9c26-6a9ef2b2dba8} - C:\Program Files\SHOUTcast Radio Toolbar\shoutcasttb.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O3 - Toolbar: GamesBar - {6F282B65-56BF-4BD1-A8B2-A4449A05863D} - C:\Program Files\GamesBar\oberontb.dll
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [DrvIcon] C:\Program Files\Vista Drive Icon\DrvIcon.exe
O4 - HKLM\..\Run: [VirusKeeper] C:\Program Files\AxBx\VirusKeeper 2009 Pro\VirusKeeper.exe
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [Magentic] C:\PROGRA~1\Magentic\bin\Magentic.exe /c
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
O4 - HKCU\..\Run: [X'nBeep] C:\Program Files\X'nBeep 1.1\XnBeep.exe
O4 - HKCU\..\Run: [CursorXP] C:\Program Files\CursorXP.exe
O4 - HKCU\..\Run: [RocketDock] "C:\Program Files\RocketDock\RocketDock.exe"
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Laurent\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [Cld2000.exe] C:\Program Files\Calendrier\Cld2000.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - S-1-5-18 Startup: RocketDock.lnk = C:\WINDOWS\BricoPacks\Crystal Clear\RocketDock\RocketDock.exe (User 'SYSTEM')
O4 - S-1-5-18 Startup: UberIcon.lnk = C:\WINDOWS\BricoPacks\Crystal Clear\UberIcon\UberIcon Manager.exe (User 'SYSTEM')
O4 - S-1-5-18 Startup: Y'z Shadow.lnk = C:\WINDOWS\BricoPacks\Crystal Clear\YzShadow\YzShadow.exe (User 'SYSTEM')
O4 - S-1-5-18 Startup: Y'z Toolbar.lnk = C:\WINDOWS\BricoPacks\Crystal Clear\YzToolbar\YzToolBar.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: RocketDock.lnk = C:\WINDOWS\BricoPacks\Crystal Clear\RocketDock\RocketDock.exe (User 'Default user')
O4 - .DEFAULT Startup: UberIcon.lnk = C:\WINDOWS\BricoPacks\Crystal Clear\UberIcon\UberIcon Manager.exe (User 'Default user')
O4 - .DEFAULT Startup: Y'z Shadow.lnk = C:\WINDOWS\BricoPacks\Crystal Clear\YzShadow\YzShadow.exe (User 'Default user')
O4 - .DEFAULT Startup: Y'z Toolbar.lnk = C:\WINDOWS\BricoPacks\Crystal Clear\YzToolbar\YzToolBar.exe (User 'Default user')
O4 - Startup: DateInTray.lnk = C:\Program Files\DateInTray\DateInTray.exe
O4 - Startup: RocketDock.lnk = C:\WINDOWS\BricoPacks\Crystal Clear\RocketDock\RocketDock.exe
O4 - Startup: Y'z Toolbar.lnk = C:\WINDOWS\BricoPacks\Crystal Clear\YzToolbar\YzToolBar.exe
O4 - Global Startup: hp psc 1000 series.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: WiFi Station.lnk = ?
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Recherche avec cherche.us - C:\Documents and Settings\Laurent\scriptjava.html
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Barre de recherche Encarta - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Fichiers communs\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.chat-land.org
O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {09CC593B-E8A9-4491-927D-A3E33534DDD4} - http://m6video.m6.fr/1click/install/files/installer2.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1754A1BA-A1DF-4F10-B199-AA55AA1A120F} (InstallerBehaviorFactory Class) - https://signup.msn.com/pages/MsnInstC.cab
O16 - DPF: {1F83CD9E-505E-4F87-BECE-0832A763E36F} (Image Uploader 3.0 Control) - http://www.mypixmania.com/fr/fr/importer/MypixUploader.cab
O16 - DPF: {2250C29C-C5E9-4F55-BE4E-01E45A40FCF1} (CMediaMix Object) - http://musicmix.messenger.msn.com/Medialogic.CAB
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {3a4f9191-65a8-11d5-85c1-0001023952c1} (TE) - http://www.3dfunchal.com/resources/te/TE.cab
O16 - DPF: {4BFD075D-C36E-4F28-BB0A-5D472795197A} (PowerLoader Class) - http://www.powerchallenge.com/applet/PowerLoader.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,96/mcinsctl.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by109fd.bay109.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {56393399-041A-4650-94C7-13DFCB1F4665} (PSFormX Control) - http://www3.ca.com/securityadvisor/pestscan/pestscan.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) - http://metaboli.clubic.com/components/Metaboli.ocx
O16 - DPF: {745395C8-D0E1-4227-8586-624CA9A10A8D} (AxisMediaControl Class) - http://axis_680446.axiscam.net:9000/activex/AMC.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/...
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - http://drivers1.free.fr/hardwaredetection.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {9122D757-5A4F-4768-82C5-B4171D8556A7} (PhotoPickConvert Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/PhotoSwap/PhtPkMSN.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/mcgdmgr/1,0,0,26/mcgdmgr.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game08.zylom.com/activex/zylomgamesplayer.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://www.popcap.com/games/popcaploader_v6.cab
O16 - DPF: {DFB5BCF1-06AE-4ABB-BFA8-1E228F41C50A} (CamfrogWEB Advanced Unicode Control) - http://www.bobtv.fr/download/cfweb_www.bobtv.fr-download_instmodule.exe
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,1,0,4754/mcfscan.cab
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by109fd.bay109.hotmail.msn.com/activex/HMAtchmt.ocx
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab
O16 - DPF: {F8C5C0F1-D884-43EB-A5A0-9E1C4A102FA8} (GoPetsWeb Control) - https://secure.gopetslive.com/dev/GoPetsWeb.cab
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Google Update Service (gupdate1c981f2ac729e12) (gupdate1c981f2ac729e12) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
O23 - Service: Maxtor Service (Maxtor Sync Service) - Seagate Technology LLC - C:\Program Files\Maxtor\Sync\SyncServices.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: VirusKeeper antivirus/antispyware (vkservice) - AxBx - C:\Program Files\AxBx\VirusKeeper 2009 Pro\vk_service.exe

--
End of file - 20987 bytes
Configuration: Windows XP
Safari 532.0

30 réponses

Résumé de la discussion

Une suspicion d’infection est évoquée après l’analyse d’un rapport Spybot montrant des lignes liées à virtumonde dll et d’un HijackThis détaillé utilisé sur un PC Windows XP. Des éléments de solution essentiels sont discutés, notamment l’utilisation de ComboFix et des suppressions proposées pour les entrées suspectes, les services et les entrées de démarrage repérées dans le rapport. Plusieurs recommandations évoquent la désinfection pas à pas et la vigilance sur les extensions et barres d’outils, avec mise en garde sur des falsifications possibles et des combinaisons variables selon l’environnement. En cas de doute, des éléments comme des noms de fichiers et services Windows peuvent être bénins selon les installations, d’où l’importance d’analyser les chemins et de vérifier les signatures des composants.

Bobot (l’IA à votre service)
  1. ▶ Télécharge Ad-remover ( de C_XX ) sur ton bureau :

    ▶ Déconnecte toi et ferme toutes applications en cours !

    ▶ Double clique sur "Ad-R.exe" pour lancer l'installation et laisse les paramètres d'installation par défaut .

    ▶ Double-clique sur le raccourci Ad-remover qui est sur ton bureau pour lancer l'outil .

    ▶ Au menu principal choisis l'option "L" et tape sur [entrée] .

    ▶ Laisse travailler l'outil et ne touche à rien ...

    ▶ Poste le rapport qui apparait à la fin , sur le forum ...

    ( Le rapport est sauvegardé aussi sous C:\Ad-report.log )
    ( CTRL+A Pour tout sélectionner , CTRL+C pour copier et CTRL+V pour coller )

    ▶ Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
    Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
    Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.
    1. Contributeur sécurité
      Je laisse la main à gen-hackman :)

      Bonne continuation.

      1. re bonjour, merci beaucoup pour vos réponses très rapides. c'est sympa. Flo 91 m'a demandé de télécharger COMBOFIX et de mettre le rapport. Le voici ;
        ComboFix 09-12-26.04 - Laurent 27/12/2009 12:15:39.1.2 - x86
        Microsoft Windows XP Édition familiale 5.1.2600.3.1252.33.1036.18.1022.367 [GMT 1:00]
        Lancé depuis: c:\documents and settings\Laurent\Bureau\ComboFix.exe
        AV: VirusKeeper 2009 Pro antivirus *On-access scanning disabled* (Updated) {165EE528-D666-4745-B14E-AA998BBEC191}
        .

        (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
        .

        c:\documents and settings\David\eula.txt
        c:\documents and settings\David\Local Settings\Application Data\ygcgcuy.dat
        c:\documents and settings\David\Local Settings\Application Data\ygcgcuy_nav.dat
        c:\documents and settings\David\Local Settings\Application Data\ygcgcuy_navps.dat
        c:\documents and settings\David\Local Settings\Application Data\ygqcygq.dat
        c:\documents and settings\David\Local Settings\Application Data\ygqcygq_nav.dat
        c:\documents and settings\David\Local Settings\Temporary Internet Files\TR010127481036.gif
        c:\documents and settings\David\Local Settings\Temporary Internet Files\TR010178471036.gif
        c:\documents and settings\David\Local Settings\Temporary Internet Files\TR011218611036.gif
        c:\documents and settings\David\Local Settings\Temporary Internet Files\TR060894321036.gif
        c:\documents and settings\David\Local Settings\Temporary Internet Files\TR061893791036.gif
        c:\documents and settings\David\Local Settings\Temporary Internet Files\TT010127481036.gif
        c:\documents and settings\David\Local Settings\Temporary Internet Files\TT010127991036.gif
        c:\documents and settings\David\Local Settings\Temporary Internet Files\TT010128051036.gif
        c:\documents and settings\David\Local Settings\Temporary Internet Files\TT010178471036.gif
        c:\documents and settings\David\Local Settings\Temporary Internet Files\TT010219531036.gif
        c:\documents and settings\David\Local Settings\Temporary Internet Files\TT010808371036.gif
        c:\documents and settings\David\Local Settings\Temporary Internet Files\TT011218001036.gif
        c:\documents and settings\David\Local Settings\Temporary Internet Files\TT011218611036.gif
        c:\documents and settings\David\Local Settings\Temporary Internet Files\TT011433111036.gif
        c:\documents and settings\David\Local Settings\Temporary Internet Files\TT060894321036.gif
        c:\documents and settings\David\Local Settings\Temporary Internet Files\TT061061871036.gif
        c:\documents and settings\David\Local Settings\Temporary Internet Files\TT061893791036.gif
        c:\documents and settings\Laurent\Local Settings\Application Data\sgaflity.dat
        c:\documents and settings\Laurent\Local Settings\Application Data\sgaflity_nav.dat
        c:\documents and settings\Laurent\Local Settings\Application Data\sgaflity_navps.dat
        c:\documents and settings\Laurent\winternet.exe
        C:\LOG.TXT
        c:\program files\GamesBar\obERontb.dll
        c:\program files\INSTALL.LOG
        c:\program files\webmediaplayer
        c:\program files\webmediaplayer\resources\languages.xml
        c:\program files\webmediaplayer\resources\webmedias
        c:\program files\webmediaplayer\skins\classic.skn
        c:\program files\webmediaplayer\sqlite3.dll
        c:\program files\webmediaplayer\WebMediaPlayer.url
        c:\recycler\S-1-5-21-2328322012-3734155301-851506153-1006(2)
        c:\windows\Downloaded Program Files\popcaploader.inf
        c:\windows\Downloaded Program Files\Quarantine
        c:\windows\pack.epk
        c:\windows\patch.exe
        c:\windows\system32\kmfejasuhs.dat
        c:\windows\system32\kmfejasuhs_nav.dat
        c:\windows\system32\kmfejasuhs_navps.dat
        c:\windows\system32\reboot.txt
        c:\windows\system32\scvhost
        c:\windows\system32\scvhost\svchost.exe
        c:\windows\system32\usb2.exe
        c:\windows\unins000.dat
        c:\windows\unins000.exe

        .
        ((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
        .

        -------\Legacy_BOONTY_GAMES
        -------\Service_Boonty Games

        ((((((((((((((((((((((((((((( Fichiers créés du 2009-11-27 au 2009-12-27 ))))))))))))))))))))))))))))))))))))
        .

        2009-12-26 13:57 . 2009-12-26 13:57 -------- d-----w- c:\documents and settings\Laurent\Application Data\Malwarebytes
        2009-12-26 13:57 . 2009-12-03 15:14 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
        2009-12-26 13:57 . 2009-12-26 13:57 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
        2009-12-26 13:57 . 2009-12-03 15:13 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
        2009-12-26 13:57 . 2009-12-26 13:57 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
        2009-12-26 12:52 . 2009-12-26 12:54 -------- d-----w- c:\program files\BHODemon 2
        2009-12-26 10:10 . 2009-12-26 11:31 -------- d-----w- C:\VundoFix Backups
        2009-12-25 19:17 . 2009-12-25 19:17 -------- d-----w- c:\documents and settings\David\Application Data\MyPhoneExplorer
        2009-12-25 19:17 . 2009-12-25 19:17 -------- d-----w- c:\program files\MyPhoneExplorer
        2009-12-25 10:33 . 2008-03-21 12:57 14640 ------w- c:\windows\system32\spmsgXP_2k3.dll
        2009-12-23 08:43 . 2002-07-17 08:05 16512 ----a-w- c:\windows\system32\drivers\ASPI32.SYS
        2009-12-23 08:43 . 2001-03-17 21:34 22528 ----a-w- c:\windows\system32\WNASPI32.DLL
        2009-12-23 08:43 . 2009-12-23 08:44 -------- d-----w- c:\program files\4Musics MP3 Bitrate Changer
        2009-12-23 08:37 . 2009-02-03 17:01 364544 ----a-w- c:\windows\system32\MACDll.dll
        2009-12-23 08:37 . 2009-01-19 17:39 246424 ----a-w- c:\windows\system32\unicows.dll
        2009-12-23 08:37 . 2009-12-23 08:38 -------- d-----w- c:\program files\Monkey's Audio
        2009-12-17 15:35 . 2009-12-17 15:35 -------- d-s---w- c:\documents and settings\NetworkService\Favoris
        2009-12-16 16:34 . 2009-12-27 10:44 172 --sh--w- c:\windows\system32\bootrun.reg
        2009-12-16 16:34 . 2009-12-27 09:47 457 --sh--w- c:\windows\system32\boothide.reg
        2009-12-16 11:17 . 2009-12-25 20:16 -------- d-----w- c:\documents and settings\David\Application Data\vlc
        2009-12-09 10:56 . 2009-12-09 10:56 -------- d-----w- c:\documents and settings\All Users\Application Data\3DVIA
        2009-12-09 10:56 . 2009-12-09 10:56 -------- d-----w- c:\documents and settings\David\Local Settings\Application Data\3DVIA
        2009-12-09 10:53 . 2007-07-19 17:14 3727720 ----a-w- c:\windows\system32\d3dx9_35.dll
        2009-12-09 10:53 . 2006-09-28 15:05 2414360 ----a-w- c:\windows\system32\d3dx9_31.dll
        2009-12-09 10:53 . 2009-12-09 10:53 -------- d-----w- c:\windows\Logs
        2009-12-09 10:53 . 2009-12-09 10:53 -------- d-----w- c:\program files\Virtools
        2009-12-05 12:14 . 2009-12-05 12:14 25512 ----a-w- c:\windows\system32\drivers\ggsemc.sys
        2009-12-05 12:14 . 2009-12-05 12:14 13224 ----a-w- c:\windows\system32\drivers\ggflt.sys
        2009-12-05 12:14 . 2009-12-05 12:14 1112288 ----a-w- c:\windows\system32\WdfCoInstaller01007.dll
        2009-12-02 19:36 . 2009-12-25 12:36 -------- d-----w- c:\documents and settings\Laurent\Application Data\vlc
        2009-12-02 10:30 . 2009-12-02 10:30 -------- d-----w- c:\documents and settings\David\Application Data\Reg.C9ECCBDBA4E09304DEEFB106465BC17F6D6749B9.1
        2009-12-02 10:30 . 2009-12-02 10:30 -------- d-----w- c:\documents and settings\David\Application Data\app
        2009-12-02 10:29 . 2009-12-02 10:47 -------- d-----w- c:\documents and settings\David\Application Data\Dofus 2
        2009-12-02 10:29 . 2009-12-02 10:29 -------- d-----w- c:\documents and settings\David\Application Data\Dofus.C9ECCBDBA4E09304DEEFB106465BC17F6D6749B9.1
        2009-12-02 09:48 . 2009-12-02 09:48 -------- d-----w- c:\program files\Dofus 2
        2009-12-02 09:36 . 2009-12-02 09:36 -------- d-----w- c:\program files\Fichiers communs\MAGIX Shared
        2009-12-02 09:36 . 2009-12-02 09:36 -------- d-----w- c:\program files\MAGIX
        2009-12-02 09:36 . 2007-04-27 09:43 120200 ----a-w- c:\windows\system32\DLLDEV32i.dll
        2009-12-02 09:35 . 2009-12-02 09:36 -------- d-----w- c:\windows\system32\MAGIX
        2009-12-02 09:35 . 2007-06-19 15:26 667648 ----a-w- c:\windows\system32\mgxoschk.dll
        2009-12-02 09:27 . 2009-12-02 09:27 -------- d-----w- c:\documents and settings\All Users\Application Data\AVS4YOU
        2009-12-02 09:26 . 2009-12-02 09:31 -------- d-----w- c:\documents and settings\David\Application Data\AVS4YOU
        2009-12-02 09:26 . 2009-12-02 09:26 -------- d-----w- c:\program files\AVS4YOU
        2009-12-02 09:12 . 2009-12-05 12:13 -------- d-----w- c:\program files\Sony Ericsson

        .
        (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
        .
        2009-12-27 11:34 . 2009-06-04 18:02 -------- d-----w- c:\program files\GamesBar
        2009-12-26 09:26 . 2009-11-12 16:05 -------- d-----w- c:\program files\Mozilla Firefox 3.6 Beta 2
        2009-12-26 09:26 . 2009-11-02 11:02 -------- d-----w- c:\program files\Mozilla Firefox 3.6 Beta 1
        2009-12-25 19:19 . 2006-12-12 15:50 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
        2009-12-25 10:34 . 2009-12-25 10:34 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_ggsemc_01007.Wdf
        2009-12-25 10:33 . 2009-12-25 10:33 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
        2009-12-23 08:42 . 2008-03-12 14:58 -------- d-----w- c:\documents and settings\David\Application Data\foobar2000
        2009-12-23 08:39 . 2008-03-12 14:58 -------- d-----w- c:\program files\foobar2000
        2009-12-22 21:16 . 2006-02-04 10:51 -------- d-----w- c:\documents and settings\David\Application Data\Apple Computer
        2009-12-21 10:11 . 2009-06-29 14:19 -------- d-----w- c:\documents and settings\David\Application Data\dvdcss
        2009-12-16 16:41 . 2008-01-06 16:58 -------- d-----w- c:\program files\DivX
        2009-12-16 16:40 . 2009-10-17 16:11 -------- d-----w- c:\program files\Fichiers communs\DivX Shared
        2009-12-16 07:07 . 2005-12-11 09:12 530984 ----a-w- c:\documents and settings\David\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
        2009-12-16 07:05 . 2009-04-10 16:43 8224 ----a-w- c:\windows\system32\GDIPFONTCACHEV1.DAT
        2009-12-14 19:16 . 2005-11-09 19:02 530984 ----a-w- c:\documents and settings\Laurent\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
        2009-12-11 17:11 . 2004-08-20 10:24 592376 ----a-w- c:\windows\system32\perfh00C.dat
        2009-12-11 17:11 . 2004-08-20 10:24 118714 ----a-w- c:\windows\system32\perfc00C.dat
        2009-12-06 11:10 . 2008-12-07 19:38 -------- d-----w- c:\documents and settings\Laurent\Application Data\dvdcss
        2009-12-02 10:51 . 2008-03-29 10:27 308628 ---ha-w- c:\windows\system32\mlfcache.dat
        2009-12-02 09:26 . 2007-07-08 09:38 -------- d-----w- c:\program files\Fichiers communs\AVSMedia
        2009-11-28 16:18 . 2009-05-13 18:25 1118 ----a-w- c:\documents and settings\Laurent\errorlog.tmp
        2009-11-28 13:15 . 2009-06-24 17:08 664 ----a-w- c:\windows\system32\d3d9caps.dat
        2009-11-28 12:12 . 2005-11-05 17:35 -------- d--h--w- c:\program files\InstallShield Installation Information
        2009-11-27 17:45 . 2005-11-05 17:31 -------- d-----w- c:\program files\Java
        2009-11-25 16:48 . 2007-05-29 18:04 -------- d-----w- c:\program files\Opera
        2009-11-16 14:37 . 2009-01-24 14:00 -------- d-----w- c:\program files\Safari
        2009-11-16 14:31 . 2009-11-16 14:30 -------- d-----w- c:\program files\iTunes
        2009-11-16 14:31 . 2009-11-16 14:30 -------- d-----w- c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
        2009-11-16 14:30 . 2009-11-16 14:30 -------- d-----w- c:\program files\iPod
        2009-11-16 14:30 . 2007-08-12 16:05 -------- d-----w- c:\program files\Fichiers communs\Apple
        2009-11-16 14:26 . 2009-11-16 14:25 -------- d-----w- c:\program files\QuickTime
        2009-11-14 00:47 . 2009-11-14 00:47 90112 ----a-w- c:\windows\system32\dpl100.dll
        2009-11-14 00:47 . 2009-11-14 00:47 856064 ----a-w- c:\windows\system32\divx_xx0c.dll
        2009-11-14 00:47 . 2009-11-14 00:47 856064 ----a-w- c:\windows\system32\divx_xx07.dll
        2009-11-14 00:47 . 2009-11-14 00:47 847872 ----a-w- c:\windows\system32\divx_xx0a.dll
        2009-11-14 00:47 . 2009-11-14 00:47 843776 ----a-w- c:\windows\system32\divx_xx16.dll
        2009-11-14 00:47 . 2009-11-14 00:47 839680 ----a-w- c:\windows\system32\divx_xx11.dll
        2009-11-14 00:47 . 2009-11-14 00:47 696320 ----a-w- c:\windows\system32\DivX.dll
        2009-11-13 19:41 . 2009-11-11 14:05 -------- d-----w- c:\program files\Zylom Games
        2009-11-13 19:39 . 2009-11-13 19:36 -------- d-----w- c:\program files\Zumas Revenge! - Adventure
        2009-11-13 19:31 . 2007-03-28 14:27 -------- d-----w- c:\program files\RealArcade
        2009-11-11 14:05 . 2009-11-11 14:05 -------- d-----w- c:\documents and settings\Laurent\Application Data\Zylom
        2009-11-10 15:58 . 2009-11-10 15:58 -------- d-----w- c:\documents and settings\All Users\Application Data\PhotoMail
        2009-11-10 15:58 . 2009-11-10 15:58 -------- d-----w- c:\program files\PhotoMail Maker
        2009-11-10 15:56 . 2005-11-09 19:44 -------- d-----w- c:\program files\IncrediMail
        2009-11-09 16:07 . 2009-11-09 16:07 -------- d-----w- c:\program files\CFWebAdvancedU
        2009-11-09 15:59 . 2009-03-27 10:33 -------- d-----w- c:\program files\Messenger Plus! Live
        2009-11-04 08:20 . 2005-11-09 19:29 -------- d-----w- c:\program files\Google
        2009-11-01 20:19 . 2008-11-10 19:09 -------- d-----w- c:\program files\Radio Fr Solo
        2009-10-31 14:27 . 2005-11-15 17:11 -------- d-----w- c:\program files\Microsoft Games
        2009-10-31 14:26 . 2007-12-10 13:00 -------- d-----w- c:\program files\Dofus
        2009-10-31 14:24 . 2009-02-14 07:53 -------- d-----w- c:\documents and settings\All Users\Application Data\Skyline
        2009-10-31 14:21 . 2009-10-26 16:44 -------- d-----w- c:\documents and settings\Laurent\Application Data\MagicBall4
        2009-10-31 14:17 . 2006-08-14 13:29 -------- d-----w- c:\documents and settings\All Users\Application Data\PlayFirst
        2009-10-31 14:11 . 2005-11-30 18:19 -------- d-----w- c:\program files\BoontyGames
        2009-10-29 07:42 . 2004-08-20 10:24 916480 ----a-w- c:\windows\system32\wininet.dll
        2009-10-21 05:39 . 2004-08-20 10:24 75776 ----a-w- c:\windows\system32\strmfilt.dll
        2009-10-21 05:39 . 2004-08-20 10:23 25088 ----a-w- c:\windows\system32\httpapi.dll
        2009-10-20 16:20 . 2004-08-03 23:00 265728 ----a-w- c:\windows\system32\drivers\http.sys
        2009-10-17 08:42 . 2009-10-17 08:42 1607184 ----a-w- c:\windows\system32\Aquarium Exotique.scr
        2009-10-13 10:33 . 2004-08-20 10:23 271360 ----a-w- c:\windows\system32\oakley.dll
        2009-10-12 13:39 . 2004-08-20 10:24 79872 ----a-w- c:\windows\system32\raschap.dll
        2009-10-12 13:39 . 2004-08-20 10:24 150528 ----a-w- c:\windows\system32\rastls.dll
        2009-10-11 03:17 . 2008-11-28 09:21 411368 ----a-w- c:\windows\system32\deploytk.dll
        2009-08-11 05:50 . 2009-08-11 05:50 15098 ----a-w- c:\program files\license.rtf
        2009-08-11 05:30 . 2009-08-11 05:30 4012328 ----a-w- c:\program files\opera.dll
        2009-08-11 05:30 . 2009-08-11 05:30 121128 ----a-w- c:\program files\opera.exe
        2009-08-11 05:26 . 2009-08-11 05:26 20480 ----a-w- c:\program files\OUniAnsi.dll
        2009-08-11 05:26 . 2009-08-11 05:26 653419 ----a-w- c:\program files\encoding.bin
        2009-07-16 13:13 . 2009-06-18 17:15 168 ----a-w- c:\program files\operaprefs_default.ini
        2009-06-17 13:41 . 2009-06-17 13:41 3870 ----a-w- c:\program files\lngcode.txt
        2008-06-09 09:17 . 2008-06-09 09:17 301 ----a-w- c:\program files\c3nform.vxml
        2006-03-29 10:14 . 2002-12-08 18:04 108 ----a-w- c:\program files\Mess with MSN Messenger skins, nicknames, add-ons, bots and secrets.url
        2006-03-29 10:14 . 2001-10-03 20:22 161 ----a-w- c:\program files\read1st.txt
        2004-02-26 12:35 . 2004-02-26 12:35 7904 ----a-w- c:\program files\html40_entities.dtd
        1999-12-09 09:19 . 2006-01-02 15:34 147456 ----a-w- c:\program files\Zip32.dll
        2006-09-01 10:54 . 2006-09-02 12:44 7168 --sh--w- c:\windows\system32\wuauserv.exe
        .

        ------- Sigcheck -------

        [-] 2008-04-14 . 5158A1C542A355B3A67E59538BBD894D . 3200000 . . [6.00.2900.5512] . . c:\windows\explorer.exe
        [-] 2008-04-14 . 5158A1C542A355B3A67E59538BBD894D . 3200000 . . [6.00.2900.5512] . . c:\windows\ServicePackFiles\i386\explorer.exe
        [-] 2007-06-13 . D0288319660EDCFED07C7E74C4EA38A5 . 1037312 . . [6.00.2900.3156] . . c:\windows\$NtServicePackUninstall$\explorer.exe
        [-] 2007-06-13 . B795475444D6D57A572C14B9E1A29839 . 1037312 . . [6.00.2900.3156] . . c:\windows\$hf_mig$\KB938828\SP2QFE\explorer.exe
        [7] 2004-08-05 . 4C33E5B9A6197B6ED215F6CFBA0A2DAA . 1036288 . . [6.00.2900.2180] . . c:\windows\$NtUninstallKB938828$\explorer.exe
        .
        ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
        .
        .
        *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
        REGEDIT4

        [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
        2008-07-17 16:20 279944 ----a-w- c:\program files\AskBarDis\bar\bin\askBar.dll

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
        "{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-07-17 279944]

        [HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
        [HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

        [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
        "LDM"="c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" [2007-02-20 67128]
        "LogitechSoftwareUpdate"="c:\program files\Logitech\Video\ManifestEngine.exe" [2005-06-08 196608]
        "Magentic"="c:\progra~1\Magentic\bin\Magentic.exe" [2006-11-19 319532]
        "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-28 68856]
        "IncrediMail"="c:\program files\IncrediMail\bin\IncMail.exe" [2009-11-10 280008]
        "X'nBeep"="c:\program files\X'nBeep 1.1\XnBeep.exe" [2007-01-06 1067520]
        "CursorXP"="c:\program files\CursorXP.exe" [2005-01-19 128000]
        "RocketDock"="c:\program files\RocketDock\RocketDock.exe" [2007-03-18 630784]
        "Google Update"="c:\documents and settings\Laurent\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-04-27 133104]
        "Cld2000.exe"="c:\program files\Calendrier\Cld2000.exe" [2009-04-16 2993664]
        "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-11-03 204288]

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
        "ISUSPM Startup"="c:\progra~1\FICHIE~1\INSTAL~1\UPDATE~1\isuspm.exe" [2005-02-16 221184]
        "ISUSScheduler"="c:\program files\Fichiers communs\InstallShield\UpdateService\issch.exe" [2005-02-16 81920]
        "SigmatelSysTrayApp"="stsystra.exe" [2005-03-22 339968]
        "dla"="c:\windows\system32\dla\tfswctrl.exe" [2005-05-31 122941]
        "LVCOMSX"="c:\windows\system32\LVCOMSX.EXE" [2005-07-19 221184]
        "LogitechVideoRepair"="c:\program files\Logitech\Video\ISStart.exe" [2005-06-08 458752]
        "ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2006-02-09 344064]
        "DrvIcon"="c:\program files\Vista Drive Icon\DrvIcon.exe" [2007-07-04 45056]
        "VirusKeeper"="c:\program files\AxBx\VirusKeeper 2009 Pro\VirusKeeper.exe" [2009-09-22 3768688]
        "AppleSyncNotifier"="c:\program files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-08-13 177440]
        "StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-02-25 61440]
        "LogitechVideoTray"="c:\program files\Logitech\Video\LogiTray.exe" [2005-06-08 217088]
        "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
        "Adobe ARM"="c:\program files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
        "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-05 417792]
        "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-10-28 141600]
        "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]

        [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
        "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

        c:\documents and settings\David\Menu D‚marrer\Programmes\D‚marrage\
        RocketDock.lnk - c:\windows\BricoPacks\Crystal Clear\RocketDock\RocketDock.exe [2006-5-14 344064]
        UberIcon.lnk - c:\windows\BricoPacks\Crystal Clear\UberIcon\UberIcon Manager.exe [2006-2-5 180224]
        Y'z Shadow.lnk - c:\windows\BricoPacks\Crystal Clear\YzShadow\YzShadow.exe [2002-9-30 131072]
        Y'z Toolbar.lnk - c:\windows\BricoPacks\Crystal Clear\YzToolbar\YzToolBar.exe [2002-9-29 90112]

        c:\documents and settings\David\Menu D‚marrer\Programmes\D‚marrage\
        RocketDock.lnk - c:\windows\BricoPacks\Crystal Clear\RocketDock\RocketDock.exe [2006-5-14 344064]
        UberIcon.lnk - c:\windows\BricoPacks\Crystal Clear\UberIcon\UberIcon Manager.exe [2006-2-5 180224]
        Y'z Shadow.lnk - c:\windows\BricoPacks\Crystal Clear\YzShadow\YzShadow.exe [2002-9-30 131072]
        Y'z Toolbar.lnk - c:\windows\BricoPacks\Crystal Clear\YzToolbar\YzToolBar.exe [2002-9-29 90112]

        c:\documents and settings\David\Menu D‚marrer\Programmes\D‚marrage\
        RocketDock.lnk - c:\windows\BricoPacks\Crystal Clear\RocketDock\RocketDock.exe [2006-5-14 344064]
        UberIcon.lnk - c:\windows\BricoPacks\Crystal Clear\UberIcon\UberIcon Manager.exe [2006-2-5 180224]
        Y'z Shadow.lnk - c:\windows\BricoPacks\Crystal Clear\YzShadow\YzShadow.exe [2002-9-30 131072]
        Y'z Toolbar.lnk - c:\windows\BricoPacks\Crystal Clear\YzToolbar\YzToolBar.exe [2002-9-29 90112]

        c:\documents and settings\Laurent\Menu D‚marrer\Programmes\D‚marrage\
        DateInTray.lnk - c:\program files\DateInTray\DateInTray.exe [2005-12-12 78848]
        RocketDock.lnk - c:\windows\BricoPacks\Crystal Clear\RocketDock\RocketDock.exe [2006-5-14 344064]
        Y'z Toolbar.lnk - c:\windows\BricoPacks\Crystal Clear\YzToolbar\YzToolBar.exe [2002-9-29 90112]

        c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
        hp psc 1000 series.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe [2003-4-6 147456]
        hpoddt01.exe.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe [2003-4-6 28672]
        WiFi Station.lnk - c:\program files\Hercules\WiFi Station\WifiStation.exe [2009-10-8 654336]

        c:\documents and settings\David\Menu D‚marrer\Programmes\D‚marrage\
        RocketDock.lnk - c:\windows\BricoPacks\Crystal Clear\RocketDock\RocketDock.exe [2006-5-14 344064]
        UberIcon.lnk - c:\windows\BricoPacks\Crystal Clear\UberIcon\UberIcon Manager.exe [2006-2-5 180224]
        Y'z Shadow.lnk - c:\windows\BricoPacks\Crystal Clear\YzShadow\YzShadow.exe [2002-9-30 131072]
        Y'z Toolbar.lnk - c:\windows\BricoPacks\Crystal Clear\YzToolbar\YzToolBar.exe [2002-9-29 90112]

        [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
        "{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]

        [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
        @="Driver"

        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
        2009-10-28 19:21 141600 ----a-w- c:\program files\iTunes\iTunesHelper.exe

        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Magentic]
        2006-11-19 12:23 319532 ----a-w- c:\progra~1\Magentic\bin\Magentic.exe

        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mxomssmenu]
        2007-09-06 12:53 169264 ----a-w- c:\program files\Maxtor\OneTouch Status\MaxMenuMgr.exe

        [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
        "LogitechVideoTray"=c:\program files\Logitech\Video\LogiTray.exe
        "QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime

        [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
        "DisableMonitoring"=dword:00000001

        [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
        "DisableMonitoring"=dword:00000001

        [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
        "DisableMonitoring"=dword:00000001

        [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
        "EnableFirewall"= 0 (0x0)

        [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
        "%windir%\\system32\\sessmgr.exe"=
        "c:\\Program Files\\IncrediMail\\bin\\IMApp.exe"=
        "c:\\Program Files\\IncrediMail\\bin\\IncMail.exe"=
        "c:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe"=
        "c:\\Documents and Settings\\Laurent\\Menu Démarrer\\Programmes\\IncrediMail\\bin\\ImpCnt.exe"=
        "c:\\Program Files\\Messenger\\msmsgs.exe"=
        "c:\\Documents and Settings\\Laurent\\Menu Démarrer\\Programmes\\IncrediMail\\bin\\ImLc.exe"=
        "c:\\Documents and Settings\\Laurent\\Menu Démarrer\\Programmes\\IncrediMail\\bin\\ImPackr.exe"=
        "c:\\Program Files\\Magentic\\bin\\MgImp.exe"=
        "c:\\Program Files\\Magentic\\bin\\Magentic.exe"=
        "c:\\Program Files\\Magentic\\bin\\MgApp.exe"=
        "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
        "c:\\Documents and Settings\\Laurent\\Menu Démarrer\\Programmes\\IncrediMail\\bin\\IncrediMail_Install.exe"=
        "c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
        "c:\\Program Files\\Codemasters\\Worms 4 Mayhem Demo\\Worms 4 Mayhem Demo.exe"=
        "c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
        "c:\\Program Files\\Commandos II\\comm2.exe"=
        "c:\\Program Files\\The All-Seeing Eye\\eye.exe"=
        "c:\\Program Files\\Opera\\Opera.exe"=
        "c:\\WINDOWS\\system32\\dpvsetup.exe"=
        "c:\\WINDOWS\\system32\\java.exe"=
        "c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
        "c:\\Program Files\\SopCast\\SopCast.exe"=
        "c:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
        "c:\\Documents and Settings\\David\\Application Data\\PowerChallenge\\PowerSoccer\\PowerSoccer.exe"=
        "c:\\Program Files\\Pinnacle\\VideoSpin\\Programs\\RM.exe"=
        "c:\\Program Files\\Pinnacle\\VideoSpin\\Programs\\PMSRegisterFile.exe"=
        "c:\\Program Files\\Pinnacle\\VideoSpin\\Programs\\umi.exe"=
        "c:\\Program Files\\Pinnacle\\VideoSpin\\Programs\\VideoSpin.exe"=
        "c:\\WINDOWS\\pchealth\\helpctr\\binaries\\helpctr.exe"=
        "c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
        "c:\\Program Files\\Mindscape\\Mission Président - Geo-Political Simulator\\MISSION.EXE"=
        "c:\\Program Files\\Ivicam\\backsurvey.exe"=
        "c:\\Program Files\\Icecast2 Win32\\Icecast2win.exe"=
        "c:\\Program Files\\SHOUTcast\\sc_serv.exe"=
        "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
        "c:\\Program Files\\QuickTime\\QuickTimePlayer.exe"=
        "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
        "c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
        "c:\\WINDOWS\\system32\\rtcshare.exe"=
        "c:\\Program Files\\NetMeeting\\conf.exe"=
        "c:\\Program Files\\iTunes\\iTunes.exe"=
        "c:\\Program Files\\Sony Ericsson\\Update Service\\Update Service.exe"=
        "c:\\WINDOWS\\system32\\wuauserv.exe"=
        "c:\\WINDOWS\\system32\\tftp.exe"=

        R2 MSSQL$RADIONOMY536765;SQL Server (RADIONOMY536765);c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [27/05/2009 02:27 29262680]
        R2 vkservice;VirusKeeper antivirus/antispyware;c:\program files\AxBx\VirusKeeper 2009 Pro\vk_service.exe [22/05/2008 14:27 1119576]
        S2 gupdate1c981f2ac729e12;Google Update Service (gupdate1c981f2ac729e12);c:\program files\Google\Update\GoogleUpdate.exe [29/01/2009 10:19 133104]
        S3 ASPI;Advanced SCSI Programming Interface Driver;c:\windows\system32\drivers\ASPI32.SYS [23/12/2009 09:43 16512]
        S3 DCamUSBUVT;ICM532A;c:\windows\system32\drivers\usbuvt.sys [11/11/2005 10:13 95232]
        S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\drivers\ggflt.sys [05/12/2009 13:14 13224]
        S3 maconfservice;Ma-Config Service;c:\program files\ma-config.com\maconfservice.exe [23/09/2009 13:50 238960]
        S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [06/11/2007 21:22 34064]

        [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{E4066320-E4AE-11CF-B1B0-00AA00BBAD66}]
        2009-03-08 02:32 128512 ----a-w- c:\windows\system32\advpack.dll
        .
        ------- Examen supplémentaire -------
        .
        uStart Page = hxxp://mystart.incredimail.com/
        uSearchMigratedDefaultURL = hxxp://google.cherche.us/Result.php?client=pub-0420647136319153&cof=GIMP%3A009900%3BT%3A000000%3BALC%3A551a8b%3BGFNT%3AB7B7B7%3BLC%3A2200cc%3BBGC%3AFFFFFF%3BVLC%3A551a8b%3BGALT%3A008B45%3BFORID%3A11%3BDIV%3A%23FFFFF0%3B&ie=ISO-8859-1&q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
        uDefault_Search_URL = hxxp://www.cherche.us/keyword/
        uInternet Connection Wizard,ShellNext = hxxp://www.dell.fr/myway
        uInternet Settings,ProxyOverride = localhost;*.local
        uSearchURL,(Default) = hxxp://www.cherche.us/keyword/%s
        IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
        IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
        IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
        IE: Recherche avec cherche.us - c:\documents and settings\Laurent\scriptjava.html
        Trusted Zone: chat-land.org
        Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
        DPF: CabBuilder - hxxp://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
        DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
        DPF: {09CC593B-E8A9-4491-927D-A3E33534DDD4} - hxxp://m6video.m6.fr/1click/install/files/installer2.cab
        DPF: {1F83CD9E-505E-4F87-BECE-0832A763E36F} - hxxp://www.mypixmania.com/fr/fr/importer/MypixUploader.cab
        DPF: {3a4f9191-65a8-11d5-85c1-0001023952c1} - hxxp://www.3dfunchal.com/resources/te/TE.cab
        DPF: {4BFD075D-C36E-4F28-BB0A-5D472795197A} - hxxp://www.powerchallenge.com/applet/PowerLoader.cab
        DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} - hxxp://game08.zylom.com/activex/zylomgamesplayer.cab
        DPF: {DFB5BCF1-06AE-4ABB-BFA8-1E228F41C50A} - hxxp://www.bobtv.fr/download/cfweb_www.bobtv.fr-download_instmodule.exe
        DPF: {F8C5C0F1-D884-43EB-A5A0-9E1C4A102FA8} - hxxps://secure.gopetslive.com/dev/GoPetsWeb.cab
        FF - ProfilePath - c:\documents and settings\Laurent\Application Data\Mozilla\Firefox\Profiles\nhizwkb4.default\
        FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
        FF - prefs.js: browser.search.selectedEngine - Google
        FF - prefs.js: browser.startup.homepage - hxxp://mystart.incredimail.com/
        FF - prefs.js: keyword.URL - hxxp://mystart.incredimail.com/?loc=PMXMAS09FFAB&search=
        FF - plugin: c:\documents and settings\All Users\Application Data\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll
        FF - plugin: c:\documents and settings\Laurent\Local Settings\Application Data\Google\Update\1.2.183.13\npGoogleOneClick8.dll
        FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
        FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
        FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
        FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
        FF - plugin: c:\program files\ma-config.com\nphardwaredetection.dll
        FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
        FF - plugin: c:\program files\Mozilla Firefox 3 Beta 5\plugins\np32dsw.dll
        FF - plugin: c:\program files\Mozilla Firefox 3 Beta 5\plugins\npdeploytk.dll
        FF - plugin: c:\program files\Mozilla Firefox 3 Beta 5\plugins\npdivx32.dll
        FF - plugin: c:\program files\Mozilla Firefox 3 Beta 5\plugins\npDivxPlayerPlugin.dll
        FF - plugin: c:\program files\Mozilla Firefox 3 Beta 5\plugins\npgcplug.dll
        FF - plugin: c:\program files\Mozilla Firefox 3 Beta 5\plugins\NPOFFICE.DLL
        FF - plugin: c:\program files\Mozilla Firefox 3 Beta 5\plugins\nppdf32.dll
        FF - plugin: c:\program files\Mozilla Firefox 3 Beta 5\plugins\nppl3260.dll
        FF - plugin: c:\program files\Mozilla Firefox 3 Beta 5\plugins\npqtplugin.dll
        FF - plugin: c:\program files\Mozilla Firefox 3 Beta 5\plugins\npqtplugin2.dll
        FF - plugin: c:\program files\Mozilla Firefox 3 Beta 5\plugins\npqtplugin3.dll
        FF - plugin: c:\program files\Mozilla Firefox 3 Beta 5\plugins\npqtplugin4.dll
        FF - plugin: c:\program files\Mozilla Firefox 3 Beta 5\plugins\npqtplugin5.dll
        FF - plugin: c:\program files\Mozilla Firefox 3 Beta 5\plugins\npqtplugin6.dll
        FF - plugin: c:\program files\Mozilla Firefox 3 Beta 5\plugins\npqtplugin7.dll
        FF - plugin: c:\program files\Mozilla Firefox 3 Beta 5\plugins\nprjplug.dll
        FF - plugin: c:\program files\Mozilla Firefox 3 Beta 5\plugins\nprpjplug.dll
        FF - plugin: c:\program files\Mozilla Firefox 3 Beta 5\plugins\npyaxmpb.dll
        FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
        FF - plugin: c:\program files\Mozilla Firefox\plugins\npicdclient.dll
        FF - plugin: c:\program files\Mozilla Firefox\plugins\npmozax.dll
        FF - plugin: c:\program files\Mozilla Firefox\plugins\npredoute.dll
        FF - plugin: c:\program files\Mozilla Firefox\plugins\npzylomgamesplayer.dll
        FF - plugin: c:\program files\Opera\program\plugins\npgcplug.dll
        FF - plugin: c:\program files\Opera\program\plugins\npmio.dll
        FF - plugin: c:\program files\Opera\program\plugins\npqtplugin8.dll
        FF - plugin: c:\program files\Real\RealArcade\Plugins\Mozilla\npracplug.dll
        FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
        FF - plugin: c:\program files\Virtools\3D Life Player\npvirtools.dll
        FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
        FF - plugin: c:\windows\system32\Rawflow\npicdclient.dll
        FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

        ---- PARAMETRES FIREFOX ----
        FF - user.js: yahoo.homepage.dontask - truec:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDCE08D86A-A41A-410A-943C-13BABB7DC474", "AllAccess");
        c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDA9EDC9ED-603A-4F3F-BBEA-59C8853A3236", "AllAccess");
        c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID90D10942-D952-4863-9DD6-A2BDBBAD456E", "AllAccess");
        c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID0ECEE744-7B69-4912-AB91-AE76D61ECB04", "AllAccess");
        c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDF25635B2-1AB9-47B5-88D1-8877B22C86DE", "AllAccess");
        c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID27B7F812-4159-45B9-A389-B7A118A58DE4", "AllAccess");
        c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDF849DF29-393B-4F8B-99D1-117A70D66FC7", "AllAccess");
        c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDBF1E9C3D-637C-4171-BD12-28A7360B879A", "AllAccess");
        c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDDE1C0601-7947-4D7F-A6E5-E68BF6BA1E37", "AllAccess");
        c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID4EA0DCCE-4D98-4876-9C6A-E5C563D0820A", "AllAccess");
        c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID446462BA-2AAD-4C88-BC63-5210E2F31465", "AllAccess");
        c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID0862E368-A40E-4E55-83EB-FBC5571BABA4", "AllAccess");
        c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDD2A96E3C-FFB3-4D38-9AC3-B127527BEA35", "AllAccess");
        c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID4B05B39A-9DDC-4650-A7F8-D5B134E5FFE5", "AllAccess");
        c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDC8E2574A-7BCE-4B93-A22E-61831DFD6DB8", "AllAccess");
        c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID659796C0-8B5D-48D7-A4EB-7E6874E26274", "AllAccess");
        c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID78071AB5-E729-414E-8D02-9C1D034F82E7", "AllAccess");
        c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDCC3F71E1-17F3-4C5B-997D-44CA56943197", "AllAccess");
        c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDE67D5C78-B2D4-4BA0-8D69-1C7AF4BB08B5", "AllAccess");
        c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDFC5F3D7A-D321-412C-8A5D-9AD0C8041941", "AllAccess");
        c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID6EC5CD16-81BC-4515-9EDD-9265C906F56E", "AllAccess");
        c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID67CFB2C5-E491-4395-977B-CD45E4124655", "AllAccess");
        c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID73600569-52E6-4760-8BAB-B68202937D98", "AllAccess");
        c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDB02EBD42-6885-401A-9389-E089F7DDC872", "AllAccess");
        c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDBAE5CB8C-4075-4743-B2E4-78DA8D8CDC64", "AllAccess");
        c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID28B07B04-DA99-4FD3-BF27-4972F2B8142B", "AllAccess");
        c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID0D53448F-D12B-4102-8CE2-697DAE8D6643", "AllAccess");
        c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDE3266A47-A141-47B8-AAA8-5F16FB4F8CCD", "AllAccess");
        c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDB33AB7AF-76D7-4B1C-B709-5D6BF9E7B1C7", "AllAccess");
        c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID153B7451-0BB5-4B37-95C0-44D89E2F1F2B", "AllAccess");
        c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID3BBE8E21-0D3D-4BAA-AC6F-C7BCEF750849", "AllAccess");
        c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID9B5B4F2D-A7D9-4329-B0FE-92B301A8CAAD", "AllAccess");
        c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDA5C42921-8CD0-4924-97C3-01B5B0610BC6", "AllAccess");
        c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID06969252-F90F-4CF2-9074-33772EB64859", "AllAccess");
        c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDFBF37655-1236-4C0D-96C5-F94E1724841B", "AllAccess");
        c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDC1A3F035-B68F-4B2B-9FD5-E36DAAAF26DD", "AllAccess");
        c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID368F3685-543E-4812-9FDE-96E097E453FC", "AllAccess");
        c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID43969873-56AA-4113-84CB-4AB2AEB9AA31", "AllAccess");
        c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDA205DD80-63D4-4E41-B785-26EC3D90B97B", "AllAccess");
        c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID068D43E7-7551-4A2F-AE96-4A38A9AD1953", "AllAccess");
        c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDF443E9CB-9EEC-456E-8AE7-F3102D5CD47D", "AllAccess");
        c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDE36A7B16-645D-4261-BFF8-3A7E69C5F7A5", "AllAccess");
        c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID379805E3-E0E2-40DC-B51B-6DC1AE5802AA", "AllAccess");
        c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDF6240D69-A06D-44A1-8003-8496CCEF2C53", "AllAccess");
        c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID26C3113D-5A71-4F1B-A2CB-BE59E1279DDA", "AllAccess");
        c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID92B97F2B-7565-4CE9-9AC7-0598DFD731F8", "AllAccess");
        c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID2AA5E7CF-9696-42F0-B76A-8655296EADF2", "AllAccess");
        c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID0AAACE0B-ACEF-4781-83F4-BFB52EEC995A", "AllAccess");
        c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID0D56FF58-A39D-4E8C-A40B-2E3711251772", "AllAccess");
        c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID946121C2-11F1-49DD-A7E3-CF793DE827A4", "AllAccess");
        c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDB853303D-1BAB-43F3-9D7D-101D0DA8E7A5", "AllAccess");
        c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID9E578247-FE29-4F8C-8202-A24A5688CF2A", "AllAccess");
        c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID6D065A8F-FFC0-4A0F-B863-1D724B8C786B", "AllAccess");
        c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID4451D291-6940-42CE-9D3C-CA1D4C96549C", "AllAccess");
        c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID064B722D-079D-4EBB-B3CF-9FCBF64FFF5D", "AllAccess");
        c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID38F8AB0F-5DFB-43D9-889E-8717CC4AB59B", "AllAccess");
        c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID4EC68CD1-0EF1-4CB9-9EF1-3D64AB266149", "AllAccess");
        c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID44F96B27-CFAD-41E1-83A1-6B28040C3BDE", "AllAccess");
        .
        - - - - ORPHELINS SUPPRIMES - - - -

        MSConfigStartUp-TomTomHOME - c:\program files\TomTom HOME 2\TomTomHOMERunner.exe
        AddRemove-HijackThis - c:\documents and settings\Laurent\Bureau\HijackThis.exe
        AddRemove-Spybot - Search & Destroy_is1 - c:\windows\unins000.exe

        **************************************************************************

        catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
        Rootkit scan 2009-12-27 12:55
        Windows 5.1.2600 Service Pack 3 NTFS

        Recherche de processus cachés ...

        Recherche d'éléments en démarrage automatique cachés ...

        Recherche de fichiers cachés ...

        Scan terminé avec succès
        Fichiers cachés: 0

        **************************************************************************
        .
        --------------------- CLES DE REGISTRE BLOQUEES ---------------------

        [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø•€|ÿÿÿÿ•€|ù•9~*]
        "C040110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
        .
        --------------------- DLLs chargées dans les processus actifs ---------------------

        - - - - - - - > 'winlogon.exe'(944)
        c:\windows\system32\Ati2evxx.dll

        - - - - - - - > 'explorer.exe'(2732)
        c:\program files\RocketDock\RocketDock.dll
        c:\windows\BricoPacks\Crystal Clear\YzToolbar\YzToolBar.dll
        c:\windows\system32\ntshrui.dll
        c:\windows\system32\NETSHELL.dll
        c:\windows\system32\credui.dll
        c:\windows\system32\eappprxy.dll
        c:\program files\IncrediMail\bin\B4ImApp.dll
        c:\program files\CurXP0.dll
        c:\windows\system32\webcheck.dll
        c:\windows\system32\stobject.dll
        c:\windows\system32\WPDShServiceObj.dll
        c:\windows\system32\PortableDeviceTypes.dll
        c:\windows\system32\PortableDeviceApi.dll
        .
        ------------------------ Autres processus actifs ------------------------
        .
        c:\windows\system32\Ati2evxx.exe
        c:\windows\system32\Ati2evxx.exe
        c:\program files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
        c:\program files\Bonjour\mDNSResponder.exe
        c:\windows\system32\drivers\CDAC11BA.EXE
        c:\program files\Java\jre6\bin\jqs.exe
        c:\program files\Google\Update\1.2.183.13\GoogleCrashHandler.exe
        c:\program files\Maxtor\Sync\SyncServices.exe
        c:\program files\CDBurnerXP\NMSAccessU.exe
        c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
        c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
        c:\windows\system32\SearchIndexer.exe
        c:\program files\Windows Media Player\WMPNetwk.exe
        c:\program files\Canon\CAL\CALMAIN.exe
        c:\windows\system32\wscntfy.exe
        c:\windows\stsystra.exe
        c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
        c:\progra~1\Magentic\bin\MgApp.exe
        c:\program files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
        c:\windows\system32\HPZipm12.exe
        c:\program files\Logitech\Video\FxSvr2.exe
        c:\program files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
        c:\program files\IncrediMail\bin\IMApp.exe
        c:\program files\iPod\bin\iPodService.exe
        c:\program files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
        .
        **************************************************************************
        .
        Heure de fin: 2009-12-27 13:11:06 - La machine a redémarré
        ComboFix-quarantined-files.txt 2009-12-27 12:11

        Avant-CF: 74 687 811 584 octets libres
        Après-CF: 80 209 203 200 octets libres

        WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe
        [boot loader]
        timeout=2
        default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
        [operating systems]
        c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
        multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP dition familiale" /fastdetect /NoExecute=OptIn /bootlogo

        - - End Of File - - A99F3C0A9462297A2572057C292B05BA
        1. Voila maintenant le rapport après le scan de ad-remover, merci d'avance pour vos réponses.
          .
          ======= RAPPORT D'AD-REMOVER 1.1.4.6_F | UNIQUEMENT XP/VISTA/7 =======
          .
          Mit à jour par C_XX le 26.12.2009 à 20:47
          Contact: AdRemover.contact@gmail.com
          Site web: http://pagesperso-orange.fr/NosTools/ad_remover.html
          .
          Lancé à: 13:32:04, 27/12/2009 | Mode Normal | Option: CLEAN
          Exécuté de: C:\Program Files\Ad-Remover\
          Système d'exploitation: Microsoft® Windows XP™ Service Pack 3 v5.1.2600
          Nom du PC: FAMILLE | Utilisateur actuel: Laurent

          Bonnes fêtes de fin d'année à vous tous :)
          .
          ============== ÉLÉMENT(S) NEUTRALISÉ(S) ==============
          .

          C:\DOCUME~1\Laurent\APPLIC~1\Mozilla\FireFox\Profiles\nhizwkb4.default\searchplugins\ask.xml
          C:\Program Files\Mozilla FireFox\Components\AskSearch.js
          C:\Program Files\AskBarDis
          C:\Program Files\eoRezo
          C:\Program Files\GamesBar
          C:\Program Files\Trymedia
          C:\Program Files\Viewpoint
          C:\DOCUME~1\Laurent\APPLIC~1\EoRezo
          C:\DOCUME~1\Laurent\APPLIC~1\Viewpoint
          C:\DOCUME~1\ALLUSE~1\APPLIC~1\GamesBar
          C:\DOCUME~1\ALLUSE~1\APPLIC~1\Trymedia
          C:\DOCUME~1\ALLUSE~1\APPLIC~1\Viewpoint
          C:\Documents and Settings\David\Application Data\EoRezo
          C:\Documents and Settings\David\Local Settings\Application Data\SHOUTcast Radio Toolbar\ieToolbar
          C:\Documents and Settings\David\Menu D‚marrer\Programmes\WebMediaPlayer

          (!) -- Fichiers temporaires supprimés.

          .
          HKCU\software\appdatalow\AskBarDis
          HKCU\software\EoRezo
          HKCU\software\GamesBar
          HKCU\software\microsoft\internet explorer\searchscopes\{CF739809-1C6C-47C0-85B9-569DBB141420}
          HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\\{4D25F926-B9FE-4682-BF72-8AB8210D6D75}
          HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{64F56FC1-1272-44CD-BA6E-39723696E350}
          HKLM\software\AskBarDis
          HKLM\software\classes\AxMetaStream.MetaStreamCtl
          HKLM\software\classes\AxMetaStream.MetaStreamCtl.1
          HKLM\software\classes\AxMetaStream.MetaStreamCtlSecondary
          HKLM\software\classes\AxMetaStream.MetaStreamCtlSecondary.1
          HKLM\Software\Classes\CLSID\{03F998B2-0E00-11D3-A498-00104B6EB52E}
          HKLM\Software\Classes\CLSID\{0702a2b6-13aa-4090-9e01-bcdc85dd933f}
          HKLM\Software\Classes\CLSID\{1B00725B-C455-4DE6-BFB6-AD540AD427CD}
          HKLM\Software\Classes\CLSID\{201f27d4-3704-41d6-89c1-aa35e39143ed}
          HKLM\Software\Classes\CLSID\{3041d03e-fd4b-44e0-b742-2d9b88305f98}
          HKLM\Software\Classes\CLSID\{4260e0cc-0f75-462e-88a3-1e05c248bf4c}
          HKLM\Software\Classes\CLSID\{622fd888-4e91-4d68-84d4-7262fd0811bf}
          HKLM\Software\Classes\CLSID\{b0de3308-5d5a-470d-81b9-634fc078393b}
          HKLM\Software\Classes\TypeLib\{4B1C1E16-6B34-430E-B074-5928ECA4C150}
          HKLM\software\EoRezo
          HKLM\software\GamesBar
          HKLM\software\GamesBarSetup
          HKLM\software\MetaStream
          HKLM\Software\Microsoft\Active Setup\Installed Components\{03F998B2-0E00-11D3-A498-00104B6EB52E}
          HKLM\Software\Microsoft\Active Setup\Installed Components\{1B00725B-C455-4DE6-BFB6-AD540AD427CD}
          HKLM\Software\Microsoft\Code Store Database\Distribution Units\CabBuilder
          HKLM\Software\Microsoft\Internet Explorer\Toolbar\\{3041d03e-fd4b-44e0-b742-2d9b88305f98}
          HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}
          HKLM\software\Trymedia Systems
          HKLM\software\Viewpoint
          .
          ============== Scan additionnel ==============
          .
          .
          * Mozilla FireFox Version 3.5.6 [fr] *
          .
          Nom du profil: nhizwkb4.default (Laurent)
          .
          (Laurent, prefs.js) Browser.download.lastDir, C:\Documents and Settings\Laurent\Bureau
          (Laurent, prefs.js) Browser.search.defaultenginename, MyStart Rechercher
          (Laurent, prefs.js) Browser.search.defaulturl, hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
          (Laurent, prefs.js) Browser.search.selectedEngine, Google
          (Laurent, prefs.js) Browser.startup.homepage, hxxp://mystart.incredimail.com/
          (Laurent, prefs.js) Extensions.enabledItems, fsonlinescanner@f-secure.com:1.01,splash@aldreneo.com:2.0.2,{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}:6.0.01,{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}:6.0.02,{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}:6.0.03,{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}:6.0.05,{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13,{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}:6.0.14,{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}:6.0.15,{972ce4c6-7e08-4474-a285-3208198ce6fd}:3.5.6
          (Laurent, prefs.js) Keyword.URL, hxxp://mystart.incredimail.com/?loc=PMXMAS09FFAB&search=
          (Laurent, prefs.js) Privacy.popups.showBrowserMessage, false
          .
          (Laurent, prefs.js) EFFACE - Extensions.snipit.chromeURL, hxxp://toolbar.ask.com/toolbarv/askRedirect?o=10168&gct=&gc=1&q={searchTerms}&crm=1
          .
          .
          .
          * Internet Explorer Version 8.0.6001.18702 *
          .
          [HKEY_CURRENT_USER\..\Internet Explorer\Main]
          .
          Do404Search: 01000000
          Local Page: C:\WINDOWS\system32\blank.htm
          Show_ToolBar: yes
          Start Page: hxxp://mystart.incredimail.com/
          Use Search Asst: no
          Enable Browser Extensions: yes
          Start Page Redirect Cache: hxxp://fr.msn.com/?ocid=iehp
          Start Page Redirect Cache_TIMESTAMP: e6d4383bb91eca01
          Start Page Redirect Cache AcceptLangs: fr
          Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
          Default_page_url: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
          Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
          .
          [HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]
          .
          Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
          Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
          Search Page: hxxp://go.microsoft.com/fwlink/?LinkId=54896
          Delete_Temp_Files_On_Exit: yes
          Local Page: %SystemRoot%\system32\blank.htm
          Start Page: hxxp://fr.msn.com/
          Search bar: hxxp://search.msn.com/spbasic.htm
          HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\main\Start Page
          .
          [HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]
          .
          Tabs: res://ieframe.dll/tabswelcome.htm
          .
          ============== Suspect (Cracks, Serials, ...) ==============
          .
          C:\Documents and Settings\Laurent\Local Settings\Application Data\Opera\Opera\profile\cache4\temporary_download\flock_patch_v1_03.zip
          C:\Documents and Settings\Laurent\Mes documents\Mises … jour de programme t‚l‚charg‚es\Dell Paint Shop Photo Album 5\MyPublisher Update for Paint Shop Photo Album 5\PSPA_MyPublisherPatch_French.exe
          .
          ===================================
          .
          6261 Octet(s) - C:\Ad-Report-CLEAN[1].log
          .
          0 Fichier(s) - C:\DOCUME~1\Laurent\LOCALS~1\Temp
          2 Fichier(s) - C:\WINDOWS\Temp
          0 Fichier(s) - C:\WINDOWS\Prefetch
          .
          19 Fichier(s) - C:\Program Files\Ad-Remover\BACKUP
          224 Fichier(s) - C:\Program Files\Ad-Remover\QUARANTINE
          .
          Fin à: 13:57:35 | 27/12/2009 - CLEAN[1]
          .
          ============== E.O.F ==============
          .
          1. bien desinstalle AD-Remover

            ▶ télécharge LOP S&D sur ton Bureau.

            ▶ Double-clique dessus pour lancer l'installation
            ▶ Puis double-clique sur le raccourci Lop S&D présent sur ton Bureau
            ▶ Séléctionne la langue souhaitée , puis choisis l'option 1 (Recherche)
            ▶ Patiente jusqu'à la fin du scan

            ▶ Poste le rapport généré (C:\lopR.txt)
            1. Quand je clique sur ton lien voilà le message qui apparait :

              The bandwidth or page view limit for this site has been exceeded and the page cannot be viewed at this time. Once the site is below the limit, it will once again begin serving as normal.
              1. desactive ton antivirus pour le telecharger
                1. Excuse moi,

                  juste pour savoir, si tu as bien reçu le rapport LOP SD ? Merci beaucoup.
                2. Je ne sais pas si tu as reçu le rapport de LOP SD je te l'envoie :

                  --------------------\\ Lop S&D 4.2.5-0 XP/Vista

                  Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 3
                  X86-based PC ( Multiprocessor Free : Intel(R) Pentium(R) 4 CPU 3.00GHz )
                  BIOS : Phoenix ROM BIOS PLUS Version 1.10 A00
                  USER : Laurent ( Administrator )
                  BOOT : Normal boot
                  Antivirus : VirusKeeper 2009 Pro antivirus 9.0 (Not Activated)
                  A:\ (USB)
                  C:\ (Local Disk) - NTFS - Total:145 Go (Free:74 Go)
                  D:\ (CD or DVD)

                  "C:\Lop SD" ( MAJ : 19-12-2008|23:40 )
                  Option : [1] ( 27/12/2009|16:29 )

                  --------------------\\ Listing des dossiers dans APPLIC~1

                  [20/08/2004|11:41] C:\DOCUME~1\ADMINI~1\APPLIC~1\Identities
                  [05/11/2005|18:39] C:\DOCUME~1\ADMINI~1\APPLIC~1\Jasc Software Inc
                  [20/08/2004|11:30] C:\DOCUME~1\ADMINI~1\APPLIC~1\Microsoft
                  [05/11/2005|18:31] C:\DOCUME~1\ADMINI~1\APPLIC~1\Sun
                  [05/11/2005|18:37] C:\DOCUME~1\ADMINI~1\APPLIC~1\You've Got Pictures Screensaver

                  [19/04/2008|16:42] C:\DOCUME~1\ADMINI~2\APPLIC~1\21cnPPS

                  [03/06/2009|16:05] C:\DOCUME~1\ALLUSE~1\APPLIC~1\{55A29068-F2CE-456C-9148-C869879E2357}
                  [16/11/2009|15:31] C:\DOCUME~1\ALLUSE~1\APPLIC~1\{755AC846-7372-4AC8-8550-C52491DAA8BD}
                  [13/04/2009|14:42] C:\DOCUME~1\ALLUSE~1\APPLIC~1\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
                  [09/12/2009|11:56] C:\DOCUME~1\ALLUSE~1\APPLIC~1\3DVIA
                  [14/10/2009|19:01] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
                  [27/12/2005|17:31] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Ahead
                  [09/11/2005|20:16] C:\DOCUME~1\ALLUSE~1\APPLIC~1\AOL
                  [12/08/2007|17:05] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple
                  [12/08/2007|17:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
                  [10/04/2009|17:40] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ATI
                  [26/03/2009|18:15] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Avanquest
                  [16/05/2007|15:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\avg7
                  [16/06/2008|19:39] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Avira
                  [02/12/2009|10:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\AVS4YOU
                  [27/10/2009|20:23] C:\DOCUME~1\ALLUSE~1\APPLIC~1\BigFishGamesCache
                  [30/11/2005|19:42] C:\DOCUME~1\ALLUSE~1\APPLIC~1\BOONTY
                  [27/12/2005|18:50] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Buena Vista Games
                  [27/01/2008|15:55] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ENJOY Plus!
                  [22/06/2008|09:38] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ESET
                  [30/08/2009|10:01] C:\DOCUME~1\ALLUSE~1\APPLIC~1\F-Secure
                  [29/10/2007|09:24] C:\DOCUME~1\ALLUSE~1\APPLIC~1\GeoVid
                  [13/11/2008|13:39] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
                  [24/11/2008|19:50] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Hagel Technologies
                  [30/04/2007|18:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\HipSoft
                  [11/10/2009|14:05] C:\DOCUME~1\ALLUSE~1\APPLIC~1\humyo.com
                  [12/08/2008|10:13] C:\DOCUME~1\ALLUSE~1\APPLIC~1\IM
                  [12/08/2008|10:12] C:\DOCUME~1\ALLUSE~1\APPLIC~1\IncrediMail
                  [05/11/2005|18:39] C:\DOCUME~1\ALLUSE~1\APPLIC~1\InstallShield
                  [17/09/2006|11:56] C:\DOCUME~1\ALLUSE~1\APPLIC~1\iWin
                  [18/10/2009|11:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ma-config.com
                  [19/12/2005|13:44] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Macrovision
                  [26/12/2009|14:57] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Malwarebytes
                  [08/07/2008|20:18] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Maxtor
                  [08/02/2006|17:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com
                  [04/02/2006|17:18] C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com Personal Firewall
                  [03/07/2006|18:15] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Messenger Plus!
                  [20/12/2008|17:42] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Micro Application
                  [09/12/2009|08:54] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
                  [10/02/2007|09:47] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft Corporation
                  [27/02/2007|12:19] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft Help
                  [25/10/2006|19:52] C:\DOCUME~1\ALLUSE~1\APPLIC~1\MSScanAppDataDir
                  [06/06/2009|15:01] C:\DOCUME~1\ALLUSE~1\APPLIC~1\MumboJumbo
                  [12/03/2009|17:42] C:\DOCUME~1\ALLUSE~1\APPLIC~1\My Games
                  [18/07/2009|09:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\NCH Software
                  [10/04/2009|20:28] C:\DOCUME~1\ALLUSE~1\APPLIC~1\NCH Swift Sound
                  [29/10/2008|09:29] C:\DOCUME~1\ALLUSE~1\APPLIC~1\NOS
                  [10/11/2009|16:58] C:\DOCUME~1\ALLUSE~1\APPLIC~1\PhotoMail
                  [18/04/2008|21:11] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Pinnacle
                  [18/04/2008|21:38] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Pinnacle VideoSpin
                  [16/11/2005|13:31] C:\DOCUME~1\ALLUSE~1\APPLIC~1\pixelStorm
                  [31/10/2009|15:17] C:\DOCUME~1\ALLUSE~1\APPLIC~1\PlayFirst
                  [21/02/2007|14:12] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Playtonium Games
                  [30/11/2005|13:18] C:\DOCUME~1\ALLUSE~1\APPLIC~1\PopCap
                  [11/01/2006|16:13] C:\DOCUME~1\ALLUSE~1\APPLIC~1\QuickTime
                  [24/06/2009|11:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\RadioManager
                  [20/05/2007|17:22] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Sandlot Games
                  [20/08/2004|11:46] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SBSI
                  [12/02/2009|15:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SHOUTcast Radio Toolbar
                  [31/10/2009|15:24] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Skyline
                  [13/06/2008|17:40] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Skype
                  [18/12/2007|20:23] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
                  [18/08/2007|14:31] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SugarGames
                  [26/02/2008|17:57] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec
                  [02/02/2006|15:59] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TDK
                  [25/12/2009|20:19] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
                  [01/01/2009|19:43] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TomTom
                  [03/06/2009|16:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TuneUp Software
                  [09/02/2008|21:10] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TVU networks
                  [18/04/2008|21:34] C:\DOCUME~1\ALLUSE~1\APPLIC~1\VideoSpin
                  [10/11/2005|17:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
                  [06/10/2007|15:07] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Live Toolbar
                  [03/12/2007|14:12] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller
                  [07/01/2006|16:24] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Yahoo!
                  [19/01/2008|13:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ZoomBrowser
                  [14/10/2008|16:31] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Zylom

                  [15/08/2009|18:28] C:\DOCUME~1\David\APPLIC~1\Adobe
                  [10/04/2009|15:14] C:\DOCUME~1\David\APPLIC~1\Ahead
                  [02/12/2009|11:30] C:\DOCUME~1\David\APPLIC~1\app
                  [22/12/2009|22:16] C:\DOCUME~1\David\APPLIC~1\Apple Computer
                  [11/04/2009|12:48] C:\DOCUME~1\David\APPLIC~1\ATI
                  [27/03/2009|11:33] C:\DOCUME~1\David\APPLIC~1\Avanquest
                  [16/05/2007|15:45] C:\DOCUME~1\David\APPLIC~1\AVG7
                  [02/12/2009|10:31] C:\DOCUME~1\David\APPLIC~1\AVS4YOU
                  [08/07/2007|10:41] C:\DOCUME~1\David\APPLIC~1\AVSMedia
                  [18/03/2008|18:20] C:\DOCUME~1\David\APPLIC~1\CDBurnerXP_Soft
                  [29/10/2007|10:12] C:\DOCUME~1\David\APPLIC~1\CursorArts
                  [09/01/2006|19:37] C:\DOCUME~1\David\APPLIC~1\CyberLink
                  [20/03/2008|09:30] C:\DOCUME~1\David\APPLIC~1\DeepBurner
                  [24/02/2009|09:15] C:\DOCUME~1\David\APPLIC~1\DivX
                  [02/12/2009|11:47] C:\DOCUME~1\David\APPLIC~1\Dofus 2
                  [02/12/2009|11:29] C:\DOCUME~1\David\APPLIC~1\Dofus.C9ECCBDBA4E09304DEEFB106465BC17F6D6749B9.1
                  [21/12/2009|11:11] C:\DOCUME~1\David\APPLIC~1\dvdcss
                  [27/01/2008|15:55] C:\DOCUME~1\David\APPLIC~1\ENJOY Plus!
                  [22/06/2008|14:35] C:\DOCUME~1\David\APPLIC~1\ESET
                  [29/10/2008|12:54] C:\DOCUME~1\David\APPLIC~1\FastStone
                  [26/06/2008|08:58] C:\DOCUME~1\David\APPLIC~1\FileZilla
                  [23/12/2009|09:42] C:\DOCUME~1\David\APPLIC~1\foobar2000
                  [29/10/2007|09:25] C:\DOCUME~1\David\APPLIC~1\GeoVid
                  [10/11/2007|22:29] C:\DOCUME~1\David\APPLIC~1\GetRightToGo
                  [24/09/2006|17:41] C:\DOCUME~1\David\APPLIC~1\Google
                  [15/10/2009|20:30] C:\DOCUME~1\David\APPLIC~1\gtk-2.0
                  [31/12/2005|11:58] C:\DOCUME~1\David\APPLIC~1\Help
                  [11/12/2005|10:24] C:\DOCUME~1\David\APPLIC~1\Hewlett-Packard
                  [28/12/2005|12:02] C:\DOCUME~1\David\APPLIC~1\Identities
                  [19/03/2008|16:00] C:\DOCUME~1\David\APPLIC~1\InfraRecorder
                  [02/09/2007|16:56] C:\DOCUME~1\David\APPLIC~1\Inkscape
                  [24/12/2008|18:23] C:\DOCUME~1\David\APPLIC~1\KC Softwares
                  [04/01/2008|22:52] C:\DOCUME~1\David\APPLIC~1\KompoZer
                  [16/05/2007|15:41] C:\DOCUME~1\David\APPLIC~1\Lavasoft
                  [31/12/2007|11:58] C:\DOCUME~1\David\APPLIC~1\Leadertech
                  [04/02/2009|15:13] C:\DOCUME~1\David\APPLIC~1\LimeWire
                  [04/12/2005|11:08] C:\DOCUME~1\David\APPLIC~1\Macromedia
                  [04/12/2005|11:41] C:\DOCUME~1\David\APPLIC~1\McAfee.com Personal Firewall
                  [28/12/2008|21:39] C:\DOCUME~1\David\APPLIC~1\Microsoft
                  [20/11/2007|16:02] C:\DOCUME~1\David\APPLIC~1\mioObjects
                  [20/02/2008|10:44] C:\DOCUME~1\David\APPLIC~1\Momindum
                  [19/04/2008|16:19] C:\DOCUME~1\David\APPLIC~1\Mozilla
                  [05/01/2008|11:59] C:\DOCUME~1\David\APPLIC~1\MPEG Streamclip
                  [25/12/2009|20:17] C:\DOCUME~1\David\APPLIC~1\MyPhoneExplorer
                  [04/07/2008|12:21] C:\DOCUME~1\David\APPLIC~1\NCH Software
                  [04/07/2008|12:26] C:\DOCUME~1\David\APPLIC~1\NCH Swift Sound
                  [14/10/2007|19:13] C:\DOCUME~1\David\APPLIC~1\NetAppel
                  [06/04/2009|17:50] C:\DOCUME~1\David\APPLIC~1\Nosibay
                  [29/10/2007|10:26] C:\DOCUME~1\David\APPLIC~1\Notepad++
                  [08/10/2007|14:04] C:\DOCUME~1\David\APPLIC~1\Nvu
                  [06/02/2009|13:25] C:\DOCUME~1\David\APPLIC~1\OpenOffice.org
                  [27/06/2009|17:01] C:\DOCUME~1\David\APPLIC~1\Opera
                  [14/01/2008|14:25] C:\DOCUME~1\David\APPLIC~1\Participatory Culture Foundation
                  [26/10/2006|08:06] C:\DOCUME~1\David\APPLIC~1\PC Tools
                  [14/01/2008|15:05] C:\DOCUME~1\David\APPLIC~1\PCF-VLC
                  [06/05/2006|15:33] C:\DOCUME~1\David\APPLIC~1\Picajet.com
                  [14/08/2006|14:29] C:\DOCUME~1\David\APPLIC~1\PlayFirst
                  [08/03/2008|22:33] C:\DOCUME~1\David\APPLIC~1\PowerChallenge
                  [18/04/2007|11:07] C:\DOCUME~1\David\APPLIC~1\Real
                  [02/12/2009|11:30] C:\DOCUME~1\David\APPLIC~1\Reg.C9ECCBDBA4E09304DEEFB106465BC17F6D6749B9.1
                  [04/10/2006|17:50] C:\DOCUME~1\David\APPLIC~1\SecuROM
                  [31/05/2008|21:03] C:\DOCUME~1\David\APPLIC~1\Skype
                  [31/05/2008|21:02] C:\DOCUME~1\David\APPLIC~1\skypePM
                  [19/12/2005|14:58] C:\DOCUME~1\David\APPLIC~1\Sonic
                  [26/06/2007|12:17] C:\DOCUME~1\David\APPLIC~1\STOIK
                  [06/12/2005|19:48] C:\DOCUME~1\David\APPLIC~1\Sun
                  [26/02/2008|17:46] C:\DOCUME~1\David\APPLIC~1\Symantec
                  [23/04/2009|13:30] C:\DOCUME~1\David\APPLIC~1\TomTom
                  [09/02/2008|21:10] C:\DOCUME~1\David\APPLIC~1\TVU networks
                  [25/12/2009|21:16] C:\DOCUME~1\David\APPLIC~1\vlc
                  [03/09/2007|16:15] C:\DOCUME~1\David\APPLIC~1\VoipBuster
                  [18/02/2006|11:40] C:\DOCUME~1\David\APPLIC~1\Wallpaper
                  [18/02/2006|11:37] C:\DOCUME~1\David\APPLIC~1\Webshots
                  [16/07/2009|13:13] C:\DOCUME~1\David\APPLIC~1\Winamp
                  [11/04/2009|12:48] C:\DOCUME~1\David\APPLIC~1\Windows Desktop Search
                  [29/06/2009|18:53] C:\DOCUME~1\David\APPLIC~1\Windows Search
                  [01/02/2009|01:39] C:\DOCUME~1\David\APPLIC~1\WinRAR
                  [23/06/2008|14:41] C:\DOCUME~1\David\APPLIC~1\www.TheXSoft.com
                  [28/12/2005|12:02] C:\DOCUME~1\David\APPLIC~1\Zylom

                  [20/08/2004|11:41] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Identities
                  [05/11/2005|18:39] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Jasc Software Inc
                  [20/05/2009|21:12] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Macromedia
                  [20/08/2004|11:30] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft
                  [05/11/2005|18:31] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Sun
                  [05/11/2005|18:37] C:\DOCUME~1\DEFAUL~1\APPLIC~1\You've Got Pictures Screensaver

                  [17/05/2009|11:17] C:\DOCUME~1\INVIT~1\APPLIC~1\ATI
                  [20/08/2004|11:41] C:\DOCUME~1\INVIT~1\APPLIC~1\Identities
                  [05/11/2005|18:39] C:\DOCUME~1\INVIT~1\APPLIC~1\Jasc Software Inc
                  [17/05/2009|11:18] C:\DOCUME~1\INVIT~1\APPLIC~1\Microsoft
                  [17/05/2009|11:20] C:\DOCUME~1\INVIT~1\APPLIC~1\Opera
                  [22/02/2006|11:54] C:\DOCUME~1\INVIT~1\APPLIC~1\Real
                  [05/11/2005|18:31] C:\DOCUME~1\INVIT~1\APPLIC~1\Sun
                  [17/05/2009|11:17] C:\DOCUME~1\INVIT~1\APPLIC~1\Windows Desktop Search
                  [05/11/2005|18:37] C:\DOCUME~1\INVIT~1\APPLIC~1\You've Got Pictures Screensaver

                  [19/02/2006|12:28] C:\DOCUME~1\Laurent\APPLIC~1\7Wonders
                  [16/01/2008|19:54] C:\DOCUME~1\Laurent\APPLIC~1\Adobe
                  [15/02/2006|17:57] C:\DOCUME~1\Laurent\APPLIC~1\Ahead
                  [26/03/2006|11:01] C:\DOCUME~1\Laurent\APPLIC~1\alawar
                  [24/02/2009|20:38] C:\DOCUME~1\Laurent\APPLIC~1\Apple Computer
                  [10/04/2009|17:40] C:\DOCUME~1\Laurent\APPLIC~1\ATI
                  [27/03/2009|11:33] C:\DOCUME~1\Laurent\APPLIC~1\Avanquest
                  [16/05/2007|15:45] C:\DOCUME~1\Laurent\APPLIC~1\AVG7
                  [04/08/2007|16:08] C:\DOCUME~1\Laurent\APPLIC~1\AVSMedia
                  [16/09/2008|17:16] C:\DOCUME~1\Laurent\APPLIC~1\Beep Industries
                  [15/04/2009|19:36] C:\DOCUME~1\Laurent\APPLIC~1\Bump Technologies, Inc
                  [12/02/2007|17:04] C:\DOCUME~1\Laurent\APPLIC~1\CamfrogWEB
                  [19/01/2008|16:01] C:\DOCUME~1\Laurent\APPLIC~1\Canon
                  [11/11/2005|18:57] C:\DOCUME~1\Laurent\APPLIC~1\CyberLink
                  [03/05/2009|19:11] C:\DOCUME~1\Laurent\APPLIC~1\DeepBurner
                  [02/12/2005|10:19] C:\DOCUME~1\Laurent\APPLIC~1\Desktop Sidebar
                  [15/03/2008|16:39] C:\DOCUME~1\Laurent\APPLIC~1\DivX
                  [06/12/2009|12:10] C:\DOCUME~1\Laurent\APPLIC~1\dvdcss
                  [22/06/2008|09:39] C:\DOCUME~1\Laurent\APPLIC~1\ESET
                  [29/10/2008|18:51] C:\DOCUME~1\Laurent\APPLIC~1\FastStone
                  [22/01/2009|19:03] C:\DOCUME~1\Laurent\APPLIC~1\FireShot
                  [11/01/2006|16:16] C:\DOCUME~1\Laurent\APPLIC~1\FotoWire
                  [11/10/2009|15:32] C:\DOCUME~1\Laurent\APPLIC~1\funkitron
                  [12/03/2009|17:43] C:\DOCUME~1\Laurent\APPLIC~1\gemsweeperextractedgfx
                  [21/02/2009|15:33] C:\DOCUME~1\Laurent\APPLIC~1\GlarySoft
                  [20/09/2006|18:13] C:\DOCUME~1\Laurent\APPLIC~1\Google
                  [30/03/2009|17:44] C:\DOCUME~1\Laurent\APPLIC~1\gtk-2.0
                  [28/05/2007|09:12] C:\DOCUME~1\Laurent\APPLIC~1\Help
                  [10/11/2005|18:30] C:\DOCUME~1\Laurent\APPLIC~1\Hewlett-Packard
                  [11/11/2009|15:05] C:\DOCUME~1\Laurent\APPLIC~1\Identities
                  [08/10/2009|18:56] C:\DOCUME~1\Laurent\APPLIC~1\InstallShield
                  [14/09/2008|18:05] C:\DOCUME~1\Laurent\APPLIC~1\iWin
                  [05/11/2005|18:39] C:\DOCUME~1\Laurent\APPLIC~1\Jasc Software Inc
                  [17/04/2006|10:38] C:\DOCUME~1\Laurent\APPLIC~1\Lavasoft
                  [09/11/2005|20:00] C:\DOCUME~1\Laurent\APPLIC~1\Leadertech
                  [18/11/2005|19:11] C:\DOCUME~1\Laurent\APPLIC~1\Macromedia
                  [30/01/2006|18:34] C:\DOCUME~1\Laurent\APPLIC~1\Magic Match
                  [15/09/2008|18:56] C:\DOCUME~1\Laurent\APPLIC~1\MagicBall3
                  [31/10/2009|15:21] C:\DOCUME~1\Laurent\APPLIC~1\MagicBall4
                  [26/12/2009|14:57] C:\DOCUME~1\Laurent\APPLIC~1\Malwarebytes
                  [10/11/2005|16:45] C:\DOCUME~1\Laurent\APPLIC~1\McAfee.com Personal Firewall
                  [24/11/2008|12:19] C:\DOCUME~1\Laurent\APPLIC~1\Micro Application
                  [23/07/2009|17:25] C:\DOCUME~1\Laurent\APPLIC~1\Microsoft
                  [19/04/2008|12:42] C:\DOCUME~1\Laurent\APPLIC~1\Mozilla
                  [13/04/2006|19:32] C:\DOCUME~1\Laurent\APPLIC~1\MSNInstaller
                  [10/04/2009|20:28] C:\DOCUME~1\Laurent\APPLIC~1\NCH Swift Sound
                  [25/07/2009|07:44] C:\DOCUME~1\Laurent\APPLIC~1\Open Source Applications Foundation
                  [05/02/2009|22:52] C:\DOCUME~1\Laurent\APPLIC~1\OpenOffice.org2
                  [18/06/2009|18:16] C:\DOCUME~1\Laurent\APPLIC~1\Opera
                  [21/01/2006|09:50] C:\DOCUME~1\Laurent\APPLIC~1\OrphansRemover
                  [24/10/2006|19:24] C:\DOCUME~1\Laurent\APPLIC~1\PC Tools
                  [20/10/2008|16:55] C:\DOCUME~1\Laurent\APPLIC~1\PlayFirst
                  [25/07/2009|07:43] C:\DOCUME~1\Laurent\APPLIC~1\Python-Eggs
                  [27/06/2009|08:54] C:\DOCUME~1\Laurent\APPLIC~1\Real
                  [19/03/2007|16:49] C:\DOCUME~1\Laurent\APPLIC~1\Screenshot Sender
                  [13/06/2008|17:35] C:\DOCUME~1\Laurent\APPLIC~1\skypePM
                  [09/11/2005|20:00] C:\DOCUME~1\Laurent\APPLIC~1\Sonic
                  [23/12/2007|10:31] C:\DOCUME~1\Laurent\APPLIC~1\SpaceTime 3D
                  [05/11/2005|18:31] C:\DOCUME~1\Laurent\APPLIC~1\Sun
                  [26/02/2008|17:36] C:\DOCUME~1\Laurent\APPLIC~1\Symantec
                  [30/11/2005|10:22] C:\DOCUME~1\Laurent\APPLIC~1\Talkback
                  [09/11/2005|19:26] C:\DOCUME~1\Laurent\APPLIC~1\Template
                  [30/11/2005|10:22] C:\DOCUME~1\Laurent\APPLIC~1\Thunderbird
                  [23/12/2007|10:18] C:\DOCUME~1\Laurent\APPLIC~1\Todae
                  [01/01/2009|19:43] C:\DOCUME~1\Laurent\APPLIC~1\TomTom
                  [03/06/2009|16:07] C:\DOCUME~1\Laurent\APPLIC~1\TuneUp Software
                  [02/10/2009|19:32] C:\DOCUME~1\Laurent\APPLIC~1\Uniblue
                  [25/12/2009|13:36] C:\DOCUME~1\Laurent\APPLIC~1\vlc
                  [11/08/2006|08:54] C:\DOCUME~1\Laurent\APPLIC~1\Wallpaper
                  [23/04/2006|16:14] C:\DOCUME~1\Laurent\APPLIC~1\Wildfire
                  [10/04/2009|17:39] C:\DOCUME~1\Laurent\APPLIC~1\Windows Desktop Search
                  [10/04/2009|19:14] C:\DOCUME~1\Laurent\APPLIC~1\Windows Search
                  [28/12/2008|21:02] C:\DOCUME~1\Laurent\APPLIC~1\WinRAR
                  [17/03/2006|16:28] C:\DOCUME~1\Laurent\APPLIC~1\wxMozze
                  [05/11/2005|18:37] C:\DOCUME~1\Laurent\APPLIC~1\You've Got Pictures Screensaver
                  [19/01/2008|13:36] C:\DOCUME~1\Laurent\APPLIC~1\ZoomBrowser EX
                  [11/11/2009|15:05] C:\DOCUME~1\Laurent\APPLIC~1\Zylom

                  [10/01/2007|19:10] C:\DOCUME~1\LOCALS~1\APPLIC~1\AVG7
                  [09/11/2005|18:05] C:\DOCUME~1\LOCALS~1\APPLIC~1\McAfee.com Personal Firewall
                  [20/08/2004|11:30] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft
                  [30/05/2006|17:34] C:\DOCUME~1\LOCALS~1\APPLIC~1\Mozilla

                  [08/03/2009|19:28] C:\DOCUME~1\NETWOR~1\APPLIC~1\DivX
                  [17/12/2009|16:35] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft

                  [10/11/2005|20:53] C:\DOCUME~1\PROPRI~1\APPLIC~1\You've Got Pictures Screensaver

                  --------------------\\ Tâches planifiées dans C:\WINDOWS\tasks

                  [27/12/2009 15:50][--a------] C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2328322012-3734155301-851506153-1006UA.job
                  [25/12/2009 23:50][--a------] C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2328322012-3734155301-851506153-1006Core.job
                  [27/12/2009 16:22][--a------] C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2328322012-3734155301-851506153-1007UA.job
                  [25/12/2009 21:22][--a------] C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2328322012-3734155301-851506153-1007Core.job
                  [27/12/2009 16:20][--a------] C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
                  [27/12/2009 14:57][--a------] C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
                  [27/12/2009 16:08][--ah-----] C:\WINDOWS\tasks\User_Feed_Synchronization-{42B0BBB3-FCB6-43E5-AB31-CB35954FB4E3}.job
                  [27/12/2009 14:57][--a------] C:\WINDOWS\tasks\GlaryInitialize.job
                  [16/11/2009 15:12][--a------] C:\WINDOWS\tasks\AppleSoftwareUpdate.job
                  [27/12/2009 10:46][--a------] C:\WINDOWS\tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1167816979.job
                  [10/11/2005 21:30][--a------] C:\WINDOWS\tasks\Rappel d'abonnement 1 auprŠs de l'ISP.job
                  [27/12/2009 14:56][--ah-----] C:\WINDOWS\tasks\SA.DAT
                  [05/08/2004 13:00][-r-h-----] C:\WINDOWS\tasks\desktop.ini

                  --------------------\\ Listing des dossiers dans C:\Program Files

                  [20/04/2008|11:26] C:\Program Files\21cn
                  [14/08/2007|17:05] C:\Program Files\3DO
                  [23/12/2009|09:44] C:\Program Files\4Musics MP3 Bitrate Changer
                  [13/12/2006|13:51] C:\Program Files\A!K Research Labs
                  [11/11/2005|16:58] C:\Program Files\ACE Mega CoDecS Pack
                  [29/10/2007|10:24] C:\Program Files\ActivIcons
                  [28/11/2006|20:16] C:\Program Files\Activision
                  [09/10/2006|18:53] C:\Program Files\Activision Value
                  [28/10/2008|20:52] C:\Program Files\Adobe
                  [27/12/2009|16:15] C:\Program Files\Ad-Remover
                  [10/10/2009|11:36] C:\Program Files\adslTV
                  [15/02/2006|17:50] C:\Program Files\Ahead
                  [20/06/2008|20:19] C:\Program Files\AIDA32
                  [16/08/2007|11:05] C:\Program Files\AIST
                  [25/04/2008|16:19] C:\Program Files\Alice
                  [26/06/2007|12:32] C:\Program Files\ALO SOFT
                  [10/01/2007|19:14] C:\Program Files\Alwil Software
                  [02/09/2007|19:47] C:\Program Files\AmitySource
                  [19/12/2007|13:24] C:\Program Files\Ankama Games
                  [28/08/2008|12:48] C:\Program Files\Apple Software Update
                  [05/05/2009|16:36] C:\Program Files\Astonsoft
                  [10/04/2009|17:35] C:\Program Files\ATI Technologies
                  [29/09/2006|19:09] C:\Program Files\AticiaPlanning
                  [15/08/2007|12:57] C:\Program Files\ATP
                  [16/02/2008|16:33] C:\Program Files\Audacity
                  [26/03/2009|17:51] C:\Program Files\Avanquest
                  [23/02/2008|22:59] C:\Program Files\AviSynth 2.5
                  [02/12/2009|10:26] C:\Program Files\AVS4YOU
                  [08/07/2007|10:38] C:\Program Files\AVSMedia
                  [27/03/2009|11:59] C:\Program Files\AWicons Lite
                  [21/10/2008|19:25] C:\Program Files\AxBx
                  [08/03/2008|21:47] C:\Program Files\Axis Communications
                  [24/03/2006|14:43] C:\Program Files\BarreConfCMCIC
                  [30/11/2006|10:32] C:\Program Files\Batman
                  [24/04/2008|18:04] C:\Program Files\Beneton Movie GIF
                  [25/05/2007|18:55] C:\Program Files\Bethesda Softworks
                  [18/10/2009|13:33] C:\Program Files\bfgclient
                  [26/12/2009|13:54] C:\Program Files\BHODemon 2
                  [13/04/2009|14:39] C:\Program Files\Bonjour
                  [02/05/2008|14:16] C:\Program Files\Boonty
                  [31/10/2009|15:11] C:\Program Files\BoontyGames
                  [28/06/2007|14:59] C:\Program Files\Bullfrog
                  [15/04/2009|19:40] C:\Program Files\BumpTop
                  [12/03/2008|16:11] C:\Program Files\Buzz
                  [28/07/2009|16:40] C:\Program Files\Calendrier
                  [28/12/2008|13:41] C:\Program Files\CamStudio
                  [19/01/2008|13:32] C:\Program Files\Canon
                  [22/04/2009|14:29] C:\Program Files\CCleaner
                  [18/03/2008|18:20] C:\Program Files\CDBurnerXP
                  [09/11/2009|17:07] C:\Program Files\CFWebAdvancedU
                  [07/05/2007|14:34] C:\Program Files\CFWebAdvancedU_BOBTV.FR
                  [28/12/2008|13:41] C:\Program Files\Christmas Time 3D Screensaver
                  [13/07/2006|20:16] C:\Program Files\Classfoot Worldcup 2006
                  [21/06/2006|08:28] C:\Program Files\Codemasters
                  [04/03/2006|18:37] C:\Program Files\Commandos II
                  [14/10/2008|18:06] C:\Program Files\Common Files
                  [28/08/2009|19:28] C:\Program Files\CPUID
                  [04/10/2006|17:31] C:\Program Files\Cryer
                  [05/11/2005|18:35] C:\Program Files\CyberLink
                  [13/10/2008|16:18] C:\Program Files\DateInTray
                  [15/08/2009|19:52] C:\Program Files\defaults
                  [28/12/2008|13:41] C:\Program Files\Dell
                  [05/11/2005|18:39] C:\Program Files\Dell Inc
                  [23/12/2007|10:24] C:\Program Files\DesktopEyes
                  [08/05/2006|09:58] C:\Program Files\DIFX
                  [05/04/2006|18:07] C:\Program Files\directx
                  [16/12/2009|17:41] C:\Program Files\DivX
                  [23/02/2008|22:08] C:\Program Files\djDecks
                  [31/01/2008|19:55] C:\Program Files\Documalis Free
                  [31/10/2009|15:26] C:\Program Files\Dofus
                  [02/12/2009|10:48] C:\Program Files\Dofus 2
                  [12/11/2005|13:11] C:\Program Files\Doom 3 Demo
                  [26/01/2008|12:15] C:\Program Files\DVDVideoSoft
                  [12/08/2006|12:01] C:\Program Files\e.t
                  [22/04/2007|15:58] C:\Program Files\e-anim701
                  [04/04/2009|13:19] C:\Program Files\EBP
                  [22/01/2009|13:26] C:\Program Files\Eidos Interactive
                  [26/04/2006|12:24] C:\Program Files\Eko
                  [01/02/2009|00:47] C:\Program Files\eMule
                  [18/10/2008|09:05] C:\Program Files\ENJOY Plus!
                  [08/12/2005|20:58] C:\Program Files\Europress
                  [17/03/2006|16:27] C:\Program Files\Evermore
                  [15/08/2009|19:52] C:\Program Files\extra
                  [29/10/2008|12:53] C:\Program Files\FastStone Image Viewer
                  [15/08/2009|18:28] C:\Program Files\Feedio
                  [27/12/2009|12:25] C:\Program Files\Fichiers communs
                  [22/04/2009|14:27] C:\Program Files\filehippo.com
                  [24/06/2008|14:35] C:\Program Files\FileZilla Client
                  [22/04/2007|16:01] C:\Program Files\Flux_2
                  [26/01/2008|11:59] C:\Program Files\FLVPlayer
                  [05/06/2006|18:01] C:\Program Files\fond-ecran-wallpaper.com
                  [23/12/2009|09:39] C:\Program Files\foobar2000
                  [16/02/2008|16:30] C:\Program Files\Freecorder
                  [25/10/2009|10:05] C:\Program Files\Funkitron
                  [10/08/2007|17:20] C:\Program Files\Future Pinball
                  [01/07/2006|12:07] C:\Program Files\Gamenext
                  [09/12/2005|18:38] C:\Program Files\GameSpy Arcade
                  [28/12/2008|13:41] C:\Program Files\GenIconXP
                  [29/10/2007|09:24] C:\Program Files\GeoVid
                  [01/02/2006|12:38] C:\Program Files\Giant
                  [14/11/2008|19:14] C:\Program Files\GIMP-2.0
                  [21/02/2009|15:24] C:\Program Files\Glary Utilities
                  [04/11/2009|09:20] C:\Program Files\Google
                  [14/10/2008|17:34] C:\Program Files\Gpotato.eu
                  [18/09/2006|09:21] C:\Program Files\Graphex3
                  [16/05/2007|15:45] C:\Program Files\Grisoft
                  [07/07/2008|19:27] C:\Program Files\HardwareDetection
                  [08/10/2009|18:56] C:\Program Files\Hercules
                  [26/03/2009|14:13] C:\Program Files\Heredis 8
                  [13/10/2008|16:19] C:\Program Files\Hewlett-Packard
                  [09/08/2006|09:06] C:\Program Files\HomeSite
                  [17/05/2007|08:54] C:\Program Files\Horloge 2005
                  [12/02/2009|14:35] C:\Program Files\Icecast2 Win32
                  [12/08/2007|16:42] C:\Program Files\Ihsv
                  [14/08/2007|10:39] C:\Program Files\Illustrate
                  [26/10/2009|18:57] C:\Program Files\Incredijeux
                  [10/11/2009|16:56] C:\Program Files\IncrediMail
                  [11/11/2005|10:23] C:\Program Files\Infogrames
                  [19/03/2008|15:58] C:\Program Files\InfraRecorder
                  [02/09/2007|22:48] C:\Program Files\Inkscape
                  [28/11/2009|13:12] C:\Program Files\InstallShield Installation Information
                  [05/11/2005|18:34] C:\Program Files\Intel
                  [10/12/2009|20:21] C:\Program Files\Internet Explorer
                  [22/06/2008|17:55] C:\Program Files\Intuisphere
                  [16/11/2009|15:30] C:\Program Files\iPod
                  [20/01/2008|18:44] C:\Program Files\IrfanView
                  [16/11/2009|15:31] C:\Program Files\iTunes
                  [26/01/2009|14:56] C:\Program Files\IviCam
                  [09/01/2006|19:04] C:\Program Files\Jasc Software Inc
                  [27/11/2009|18:45] C:\Program Files\Java
                  [12/03/2008|16:11] C:\Program Files\Jeskola Buzz
                  [08/06/2009|18:10] C:\Program Files\JRE
                  [16/11/2005|11:16] C:\Program Files\JVTorrent
                  [20/05/2007|09:02] C:\Program Files\Kaspersky Lab
                  [24/12/2008|18:21] C:\Program Files\KC Softwares
                  [02/01/2006|16:34] C:\Program Files\Languages
                  [05/11/2005|18:37] C:\Program Files\Learn2.com
                  [13/07/2006|20:16] C:\Program Files\LeechFTP
                  [04/02/2009|14:46] C:\Program Files\LimeWire
                  [02/01/2007|20:37] C:\Program Files\LM Version-2.5-F
                  [15/08/2009|19:52] C:\Program Files\locale
                  [31/08/2008|13:34] C:\Program Files\Logitech
                  [21/12/2008|11:10] C:\Program Files\LucasArts
                  [28/06/2009|09:25] C:\Program Files\Luxor 2
                  [08/06/2009|15:01] C:\Program Files\M6 Jeux
                  [18/10/2009|11:21] C:\Program Files\ma-config.com
                  [08/12/2006|16:53] C:\Program Files\Magentic
                  [02/12/2009|10:36] C:\Program Files\MAGIX
                  [16/10/2007|18:54] C:\Program Files\Ma‹do Production
                  [26/12/2009|14:57] C:\Program Files\Malwarebytes' Anti-Malware
                  [01/07/2006|15:21] C:\Program Files\Maxis
                  [28/12/2008|13:39] C:\Program Files\Maxtor
                  [28/12/2008|13:39] C:\Program Files\Maxtor(2)
                  [10/04/2008|13:24] C:\Program Files\MediaCoder
                  [30/12/2006|13:54] C:\Program Files\MediaInfo
                  [31/03/2006|17:16] C:\Program Files\Mes Jeux T‚l‚charg‚s
                  [27/08/2008|17:19] C:\Program Files\Messenger
                  [09/11/2009|16:59] C:\Program Files\Messenger Plus! Live
                  [10/04/2009|14:06] C:\Program Files\Metal Gear Solid
                  [12/07/2009|08:47] C:\Program Files\Micro Application
                  [28/12/2008|19:07] C:\Program Files\Microsoft
                  [10/05/2007|14:21] C:\Program Files\Microsoft CAPICOM 2.1.0.2
                  [28/01/2007|12:48] C:\Program Files\Microsoft Encarta
                  [20/08/2004|11:37] C:\Program Files\microsoft frontpage
                  [27/05/2009|14:36] C:\Program Files\Microsoft FrontPage Express
                  [31/10/2009|15:27] C:\Program Files\Microsoft Games
                  [27/02/2007|12:17] C:\Program Files\Microsoft Office
                  [01/10/2009|18:07] C:\Program Files\Microsoft Office Outlook Connector
                  [25/08/2009|14:37] C:\Program Files\Microsoft Picture It! PhotoPub
                  [10/09/2009|16:14] C:\Program Files\Microsoft Silverlight
                  [16/10/2009|16:08] C:\Program Files\Microsoft SQL Server
                  [01/10/2009|18:04] C:\Program Files\Microsoft SQL Server Compact Edition
                  [17/12/2008|20:33] C:\Program Files\Microsoft Sync Framework
                  [27/02/2007|12:18] C:\Program Files\Microsoft Works
                  [24/06/2009|11:24] C:\Program Files\Microsoft.NET
                  [14/06/2008|16:44] C:\Program Files\Mindscape
                  [20/11/2007|16:02] C:\Program Files\Mioplanet
                  [23/12/2009|09:38] C:\Program Files\Monkey's Audio
                  [29/04/2006|17:31] C:\Program Files\Monte Cristo
                  [27/08/2008|17:58] C:\Program Files\Movie Maker
                  [26/12/2009|13:25] C:\Program Files\Mozilla Firefox
                  [19/08/2009|14:26] C:\Program Files\Mozilla Firefox 3 Beta 5
                  [19/08/2009|14:26] C:\Program Files\Mozilla Firefox 3.1 Beta 3
                  [19/08/2009|14:27] C:\Program Files\Mozilla Firefox 3.5 Beta 4
                  [19/08/2009|14:27] C:\Program Files\Mozilla Firefox 3.5 Preview
                  [26/12/2009|10:26] C:\Program Files\Mozilla Firefox 3.6 Beta 1
                  [26/12/2009|10:26] C:\Program Files\Mozilla Firefox 3.6 Beta 2
                  [30/11/2005|10:31] C:\Program Files\Mozilla Thunderbird
                  [08/05/2006|16:17] C:\Program Files\MP3 Player Utilities
                  [20/02/2008|11:57] C:\Program Files\MP3 Player Utilities 3.57
                  [05/01/2008|11:35] C:\Program Files\mp3DirectCut
                  [27/07/2009|09:00] C:\Program Files\MP3Gain
                  [05/01/2008|11:50] C:\Program Files\mp3splt-gtk
                  [10/04/2009|18:00] C:\Program Files\MSBuild
                  [13/06/2009|21:18] C:\Program Files\MSECache
                  [12/11/2005|14:11] C:\Program Files\MSN
                  [26/06/2006|10:03] C:\Program Files\MSN Games
                  [20/08/2004|11:34] C:\Program Files\MSN Gaming Zone
                  [16/12/2007|18:51] C:\Program Files\MSN Messenger
                  [14/08/2006|12:52] C:\Program Files\MSXML 4.0
                  [15/08/2007|09:33] C:\Program Files\MSXML 6.0
                  [24/12/2007|14:28] C:\Program Files\MyMPxPlayer.org
                  [25/12/2009|20:17] C:\Program Files\MyPhoneExplorer
                  [01/11/2006|09:32] C:\Program Files\MySight 2006
                  [28/12/2008|13:39] C:\Program Files\Navilog1
                  [18/07/2009|09:21] C:\Program Files\NCH Software
                  [10/04/2009|20:28] C:\Program Files\NCH Swift Sound
                  [15/02/2006|17:55] C:\Program Files\Nero
                  [27/08/2008|17:14] C:\Program Files\NetMeeting
                  [10/03/2009|18:54] C:\Program Files\Network Stumbler
                  [28/12/2008|18:27] C:\Program Files\nLite
                  [29/10/2008|09:29] C:\Program Files\NOS
                  [29/10/2007|10:26] C:\Program Files\Notepad++
                  [28/12/2008|13:42] C:\Program Files\Nvu
                  [14/10/2009|19:56] C:\Program Files\Oberon Media
                  [20/08/2004|11:34] C:\Program Files\Online Services
                  [06/02/2009|13:19] C:\Program Files\OpenOffice.org 2.4
                  [08/06/2009|18:10] C:\Program Files\OpenOffice.org 3
                  [25/11/2009|17:48] C:\Program Files\Opera
                  [08/06/2009|16:54] C:\Program Files\Opera 10 Preview
                  [04/06/2009|19:02] C:\Program Files\orange
                  [21/01/2006|09:50] C:\Program Files\OrphansRemover
                  [15/08/2009|22:53] C:\Program Files\Outlook Express
                  [21/10/2008|19:11] C:\Program Files\Panda Security
                  [13/05/2007|18:25] C:\Program Files\Panicware
                  [08/12/2008|19:04] C:\Program Files\PDFCreator
                  [14/08/2007|17:08] C:\Program Files\PeerTV
                  [09/06/2008|09:39] C:\Program Files\Photo Viewer
                  [10/11/2009|16:58] C:\Program Files\PhotoMail Maker
                  [01/02/2008|18:57] C:\Program Files\PhotoRapido
                  [06/05/2006|15:32] C:\Program Files\PicaFr
                  [18/04/2008|21:34] C:\Program Files\Pinnacle
                  [26/02/2006|11:46] C:\Program Files\Player Metaboli
                  [04/02/2006|16:56] C:\Program Files\Plus!
                  [18/06/2009|18:15] C:\Program Files\program
                  [16/11/2009|15:26] C:\Program Files\QuickTime
                  [10/08/2007|17:54] C:\Program Files\RacingPitch
                  [01/11/2009|21:19] C:\Program Files\Radio Fr Solo
                  [27/09/2009|11:03] C:\Program Files\Radio Stream Player
                  [24/06/2009|11:19] C:\Program Files\Radionomy
                  [01/05/2006|11:39] C:\Program Files\Ratajik Software
                  [04/08/2007|21:17] C:\Program Files\RawFlow
                  [11/11/2006|15:23] C:\Program Files\Real
                  [13/11/2009|20:31] C:\Program Files\RealArcade
                  [10/04/2009|18:00] C:\Program Files\Reference Assemblies
                  [13/12/2005|17:55] C:\Program Files\ReflexiveArcade
                  [25/10/2009|09:56] C:\Program Files\Retro64 Games
                  [18/04/2006|16:42] C:\Program Files\Ricochet Xtreme
                  [23/02/2008|22:56] C:\Program Files\Ripp-it_AM
                  [14/10/2009|16:00] C:\Program Files\RocketDock
                  [15/04/2006|16:54] C:\Program Files\Rockstar Games
                  [16/11/2009|15:37] C:\Program Files\Safari
                  [18/03/2006|13:47] C:\Program Files\SereneScreen
                  [20/08/2004|11:35] C:\Program Files\Services en ligne
                  [09/04/2009|13:44] C:\Program Files\Shareaza
                  [12/02/2009|15:27] C:\Program Files\SHOUTcast
                  [12/02/2009|15:30] C:\Program Files\SHOUTcast Radio Toolbar
                  [04/10/2006|17:41] C:\Program Files\Sierra
                  [05/11/2005|18:33] C:\Program Files\Sigmatel
                  [05/05/2007|20:41] C:\Program Files\Sim AQUARIUM 2
                  [03/02/2008|14:09] C:\Program Files\SimpleOCR
                  [15/08/2009|19:52] C:\Program Files\skin
                  [13/06/2008|17:40] C:\Program Files\Skype
                  [17/10/2009|13:46] C:\Program Files\Snowball
                  [12/04/2008|11:07] C:\Program Files\SoftChris
                  [08/02/2006|17:13] C:\Program Files\Softwin
                  [12/11/2005|16:45] C:\Program Files\Sonic
                  [05/12/2009|13:13] C:\Program Files\Sony Ericsson
                  [16/03/2008|19:12] C:\Program Files\SopCast
                  [18/10/2007|15:30] C:\Program Files\Sporever
                  [12/09/2009|09:07] C:\Program Files\Spybot - Search & Destroy
                  [21/03/2007|18:45] C:\Program Files\Spyware Doctor(2)
                  [02/01/2006|16:39] C:\Program Files\Stardock
                  [24/12/2007|17:14] C:\Program Files\STOIK Imaging
                  [15/08/2009|19:52] C:\Program Files\styles
                  [07/04/2006|19:05] C:\Program Files\Surreal
                  [18/07/2009|09:04] C:\Program Files\Sweet Home 3D
                  [02/05/2008|14:17] C:\Program Files\T‚l‚chargeur de Singles
                  [04/02/2006|17:18] C:\Program Files\TGTSoft
                  [31/10/2008|23:08] C:\Program Files\The All-Seeing Eye
                  [02/01/2006|16:34] C:\Program Files\Themes
                  [25/12/2007|15:42] C:\Program Files\THQ
                  [05/11/2005|18:40] C:\Program Files\Tiscali
                  [01/01/2009|19:39] C:\Program Files\TomTom DesktopSuite
                  [03/08/2006|16:33] C:\Program Files\TopDesk Trial
                  [10/04/2009|19:51] C:\Program Files\TubeMaster
                  [27/09/2009|11:04] C:\Program Files\TubeMaster++
                  [03/06/2009|16:59] C:\Program Files\TuneUp Utilities 2009
                  [17/05/2006|14:57] C:\Program Files\UberSoldier Demo
                  [14/08/2007|17:03] C:\Program Files\Ubi Soft
                  [15/08/2009|19:52] C:\Program Files\ui
                  [01/07/2006|16:17] C:\Program Files\Ulead Systems
                  [03/09/2007|10:00] C:\Program Files\Ultimate generator
                  [03/11/2006|15:23] C:\Program Files\Uninstall Information
                  [21/10/2006|11:24] C:\Program Files\Universal Interactive
                  [14/08/2007|17:09] C:\Program Files\URUSoft
                  [31/10/2007|11:39] C:\Program Files\VCW VicMan's Photo Editor
                  [31/10/2008|23:08] C:\Program Files\VideoCap
                  [27/11/2005|10:24] C:\Program Files\VideoLAN
                  [09/12/2009|11:53] C:\Program Files\Virtools
                  [14/08/2007|16:57] C:\Program Files\Vista Drive Icon
                  [20/09/2009|12:53] C:\Program Files\VivilProject SpeedTest
                  [14/10/2009|17:35] C:\Program Files\Wakfu
                  [31/10/2007|11:40] C:\Program Files\Web Photo Album
                  [16/07/2009|13:11] C:\Program Files\Winamp
                  [10/06/2009|16:18] C:\Program Files\Windows Desktop Search
                  [01/10/2009|18:05] C:\Program Files\Windows Live
                  [28/12/2008|19:03] C:\Program Files\Windows Live SkyDrive
                  [28/12/2008|19:06] C:\Program Files\Windows Live Toolbar
                  [08/03/2009|11:59] C:\Program Files\Windows Media Connect
                  [12/12/2006|20:06] C:\Program Files\Windows Media Connect 2
                  [26/03/2009|18:35] C:\Program Files\Windows Media Player
                  [27/08/2008|17:14] C:\Program Files\Windows NT
                  [29/09/2007|16:02] C:\Program Files\WindowsUpdate
                  [26/12/2007|13:06] C:\Program Files\WinMPG VideoConvert
                  [17/08/2009|12:45] C:\Program Files\WinPcap
                  [07/12/2008|09:51] C:\Program Files\WinRAR
                  [14/01/2006|10:31] C:\Program Files\WinZip
                  [26/03/2009|18:35] C:\Program Files\Worms
                  [20/08/2004|11:37] C:\Program Files\xerox
                  [20/02/2008|11:44] C:\Program Files\Xilisoft
                  [17/02/2007|11:03] C:\Program Files\X'nBeep 1.1
                  [24/03/2006|08:43] C:\Program Files\Yahoo!
                  [11/07/2009|09:46] C:\Program Files\YourWare Solutions
                  [13/11/2009|20:39] C:\Program Files\Zumas Revenge! - Adventure
                  [13/11/2009|20:41] C:\Program Files\Zylom Games

                  --------------------\\ Listing des dossiers dans C:\Program Files\Fichiers communs

                  [03/02/2007|13:45] C:\Program Files\Fichiers communs\3DO Shared
                  [14/10/2009|15:37] C:\Program Files\Fichiers communs\Adobe
                  [15/08/2009|18:28] C:\Program Files\Fichiers communs\Adobe AIR
                  [10/04/2009|15:15] C:\Program Files\Fichiers communs\Ahead
                  [27/03/2009|11:35] C:\Program Files\Fichiers communs\AntiVirus
                  [09/11/2005|20:16] C:\Program Files\Fichiers communs\AOL
                  [16/11/2009|15:30] C:\Program Files\Fichiers communs\Apple
                  [02/12/2009|10:26] C:\Program Files\Fichiers communs\AVSMedia
                  [30/11/2005|19:42] C:\Program Files\Fichiers communs\BOONTY Shared
                  [19/01/2008|13:24] C:\Program Files\Fichiers communs\Canon
                  [27/02/2007|19:21] C:\Program Files\Fichiers communs\DESIGNER
                  [16/12/2009|17:40] C:\Program Files\Fichiers communs\DivX Shared
                  [27/02/2008|17:00] C:\Program Files\Fichiers communs\DVDVideoSoft
                  [11/01/2006|16:16] C:\Program Files\Fichiers communs\FotoWire
                  [29/10/2007|09:24] C:\Program Files\Fichiers communs\GeoVid
                  [28/06/2007|13:41] C:\Program Files\Fichiers communs\GTK
                  [10/11/2005|18:21] C:\Program Files\Fichiers communs\Hewlett-Packard
                  [09/11/2005|19:11] C:\Program Files\Fichiers communs\InstallShield
                  [05/11/2005|18:31] C:\Program Files\Fichiers communs\Java
                  [11/01/2006|16:15] C:\Program Files\Fichiers communs\Logitech
                  [19/12/2005|13:44] C:\Program Files\Fichiers communs\Macrovision Shared
                  [02/12/2009|10:36] C:\Program Files\Fichiers communs\MAGIX Shared
                  [23/05/2006|17:46] C:\Program Files\Fichiers communs\Micro Application Shared
                  [24/06/2009|11:24] C:\Program Files\Fichiers communs\Microsoft Shared
                  [20/08/2004|11:35] C:\Program Files\Fichiers communs\MSSoap
                  [05/04/2009|17:40] C:\Program Files\Fichiers communs\Nosibay
                  [12/03/2008|17:42] C:\Program Files\Fichiers communs\NSV
                  [05/11/2005|18:37] C:\Program Files\Fichiers communs\Nullsoft
                  [04/06/2009|19:02] C:\Program Files\Fichiers communs\Oberon Media
                  [07/03/2006|19:36] C:\Program Files\Fichiers communs\ODBC
                  [21/03/2007|17:24] C:\Program Files\Fichiers communs\PC Tools
                  [01/07/2009|20:36] C:\Program Files\Fichiers communs\Real
                  [20/05/2007|17:22] C:\Program Files\Fichiers communs\Sandlot Shared
                  [20/08/2004|11:35] C:\Program Files\Fichiers communs\Services
                  [08/02/2006|17:13] C:\Program Files\Fichiers communs\Softwin
                  [27/05/2007|10:05] C:\Program Files\Fichiers communs\Sonic Shared
                  [20/08/2004|11:30] C:\Program Files\Fichiers communs\SpeechEngines
                  [02/01/2006|16:39] C:\Program Files\Fichiers communs\Stardock
                  [27/04/2009|07:05] C:\Program Files\Fichiers communs\Symantec Shared
                  [01/10/2009|18:07] C:\Program Files\Fichiers communs\System
                  [15/08/2007|11:36] C:\Program Files\Fichiers communs\Vbox
                  [16/12/2008|20:29] C:\Program Files\Fichiers communs\Windows Live
                  [03/12/2007|14:16] C:\Program Files\Fichiers communs\WindowsLiveInstaller
                  [01/07/2009|20:37] C:\Program Files\Fichiers communs\xing shared
                  [18/04/2008|21:34] C:\Program Files\Fichiers communs\Yahoo!

                  --------------------\\ Process

                  ( 72 Processes )

                  ... OK !

                  --------------------\\ Recherche avec S_Lop

                  Aucun fichier / dossier Lop trouvé !

                  --------------------\\ Recherche de Fichiers / Dossiers Lop

                  Aucun fichier / dossier Lop trouvé !

                  --------------------\\ Verification du Registre

                  ..... OK !

                  --------------------\\ Verification du fichier Hosts

                  Fichier Hosts PROPRE

                  --------------------\\ Recherche de fichiers avec Catchme

                  catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                  Rootkit scan 2009-12-27 16:30:21
                  Windows 5.1.2600 Service Pack 3 NTFS
                  scanning hidden processes ...
                  scanning hidden files ...
                  scan completed successfully
                  hidden processes: 0
                  hidden files: 0

                  --------------------\\ Recherche d'autres infections

                  C:\WINDOWS\System32\ntbifflrye.dat.ren
                  C:\WINDOWS\System32\ntbifflrye.exe.ren
                  C:\WINDOWS\System32\ntbifflrye_nav.dat.ren
                  C:\WINDOWS\System32\ntbifflrye_navps.dat.ren
                  [b]==> EGDACCESS <==/b

                  [F:32][D:8]-> C:\DOCUME~1\Laurent\LOCALS~1\Temp
                  [F:15][D:0]-> C:\DOCUME~1\Laurent\Cookies
                  [F:49][D:4]-> C:\DOCUME~1\Laurent\LOCALS~1\TEMPOR~1\content.IE5

                  1 - "C:\Lop SD\LopR_1.txt" - 27/12/2009|16:44 - Option : [1]

                  --------------------\\ Fin du rapport a 16:44:37
              2. Télécharge Navilog1 depuis-ce lien

                ▶ Enregistrer la cible (du lien) sous... et enregistre-le sur ton bureau.
                ▶ Ensuite double clique sur navilog1.exe pour lancer l'installation.

                Une fois l'installation terminée, le fix s'exécutera automatiquement.

                ▶ Au menu principal, Fais le choix 1 >> Recherche / suppression automatique

                Patiente jusqu'au message :
                *** Analyse Termine le ..... ***

                >>>>> Le fix peut durer une dizaine de minutes ;)

                ▶ Appuie sur une touche le bloc note va s'ouvrir.

                ▶ Copie-colle le rapport ici.

                1. Voilà le rapport de NAVILOG1 : As tu trouvé ce qui infeste mon pc ? merci beaucoup pour ton aide.

                  Fix Navipromo version 4.0.5 commencé le 27/12/2009 18:26:14,82

                  !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
                  !!! Postez ce rapport sur le forum pour le faire analyser !!!

                  Outil exécuté depuis C:\Program Files\navilog1

                  Mise à jour le 10.11.2009 à 18h00 par IL-MAFIOSO

                  Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 3
                  X86-based PC ( Multiprocessor Free : Intel(R) Pentium(R) 4 CPU 3.00GHz )
                  BIOS : Phoenix ROM BIOS PLUS Version 1.10 A00
                  USER : Laurent ( Administrator )
                  BOOT : Normal boot

                  Antivirus : VirusKeeper 2009 Pro antivirus 9.0 (Activated)

                  A:\ (USB)
                  C:\ (Local Disk) - NTFS - Total:145 Go (Free:74 Go)
                  D:\ (CD or DVD)

                  Recherche executée en mode normal

                  Nettoyage exécuté au redémarrage de l'ordinateur

                  C:\WINDOWS\system32\ntbifflrye.exe.ren supprimé !
                  C:\WINDOWS\system32\ntbifflrye.dat.ren supprimé !
                  C:\WINDOWS\system32\ntbifflrye_nav.dat.ren supprimé !
                  C:\WINDOWS\system32\ntbifflrye_navps.dat.ren supprimé !

                  Nettoyage contenu C:\WINDOWS\Temp effectué !
                  Nettoyage contenu C:\Documents and Settings\Laurent\locals~1\Temp effectué !

                  *** Sauvegarde du Registre vers dossier Safebackup ***

                  sauvegarde du Registre réalisée avec succès !

                  *** Nettoyage Registre ***

                  Nettoyage Registre Ok

                  *** Scan terminé 27/12/2009 18:29:24,03 ***
              3. Télécharge OTL de OLDTimer

                ▶ enregistre le sur ton Bureau.

                ▶ Double clic ( pour vista => clic droit "executer en tant qu'administrateur") sur OTL.exe pour le lancer.

                ▶ Coche les 2 cases Lop et Purity

                ▶ Coche la case devant scan all users

                ▶ règle-le sur "60 Days"

                ▶ dans la colonne de gauche , mets tout sur all

                ne modifie pas ceci :

                "files created whithin" et "files modified whithin"


                ▶Clic sur Run Scan.

                A la fin du scan, le Bloc-Notes va s'ouvrir avec le rapport (OTL.txt).

                Ce fichier est sur ton Bureau (en général C:\Documents and settings\le_nom_de_ta_session\OTL.txt)

                ▶▶▶ NE LE POSTE PAS SUR LE FORUM

                Pour me le transmettre clique sur ce lien : http://www.cijoint.fr/

                ▶ Clique sur Parcourir et cherche le fichier ci-dessus.

                ▶ Clique sur Ouvrir.

                ▶ Clique sur "Cliquez ici pour déposer le fichier".

                Un lien de cette forme :

                http://www.cijoint.fr/cjlink.php?file=cjge368/cijSKAP5fU.txt

                est ajouté dans la page.

                ▶ Copie ce lien dans ta réponse.

                ▶▶ Tu feras la meme chose avec le "Extra.txt".
                1. Salut gen-hackman,
                  voilà le résultat de otl.txt : http://www.cijoint.fr/cjlink.php?file=cj200912/cijQsvVH8z.txt

                  et celui pour extra.tnt : http://www.cijoint.fr/cjlink.php?file=cj200912/cijsZRozDQ.txt

                  Merci d'avance.
              4. peux-tu repasser AD-Remover option "L" en mode sans echec stp ?
                1. rapport d' AD-Remover en mode sans échec :
                  .
                  ======= RAPPORT D'AD-REMOVER 1.1.4.6_F | UNIQUEMENT XP/VISTA/7 =======
                  .
                  Mit à jour par C_XX le 26.12.2009 à 20:47
                  Contact: AdRemover.contact@gmail.com
                  Site web: http://pagesperso-orange.fr/NosTools/ad_remover.html
                  .
                  Lancé à: 11:31:18, 28/12/2009 | Mode sans echec | Option: CLEAN
                  Exécuté de: C:\Program Files\Ad-Remover\
                  Système d'exploitation: Microsoft® Windows XP™ Service Pack 3 v5.1.2600
                  Nom du PC: FAMILLE | Utilisateur actuel: Laurent

                  Bonnes fêtes de fin d'année à vous tous :)
                  .
                  ============== ÉLÉMENT(S) NEUTRALISÉ(S) ==============
                  .

                  (!) -- Fichiers temporaires supprimés.

                  .
                  .
                  ============== Scan additionnel ==============
                  .
                  .
                  * Mozilla FireFox Version 3.5.6 [fr] *
                  .
                  Nom du profil: nhizwkb4.default (Laurent)
                  .
                  (Laurent, prefs.js) Browser.download.lastDir, C:\Documents and Settings\Laurent\Bureau
                  (Laurent, prefs.js) Browser.search.defaultenginename, MyStart Rechercher
                  (Laurent, prefs.js) Browser.search.defaulturl, hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
                  (Laurent, prefs.js) Browser.search.selectedEngine, Google
                  (Laurent, prefs.js) Browser.startup.homepage, hxxp://mystart.incredimail.com/
                  (Laurent, prefs.js) Extensions.enabledItems, fsonlinescanner@f-secure.com:1.01,splash@aldreneo.com:2.0.2,{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}:6.0.01,{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}:6.0.02,{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}:6.0.03,{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}:6.0.05,{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13,{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}:6.0.14,{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}:6.0.15,{972ce4c6-7e08-4474-a285-3208198ce6fd}:3.5.6
                  (Laurent, prefs.js) Keyword.URL, hxxp://mystart.incredimail.com/?loc=PMXMAS09FFAB&search=
                  (Laurent, prefs.js) Privacy.popups.showBrowserMessage, false
                  .
                  .
                  .
                  * Internet Explorer Version 8.0.6001.18702 *
                  .
                  [HKEY_CURRENT_USER\..\Internet Explorer\Main]
                  .
                  Do404Search: 01000000
                  Local Page: C:\WINDOWS\system32\blank.htm
                  Show_ToolBar: yes
                  Start Page: hxxp://fr.msn.com/
                  Use Search Asst: no
                  Enable Browser Extensions: yes
                  Start Page Redirect Cache: hxxp://fr.msn.com/?ocid=iehp
                  Start Page Redirect Cache_TIMESTAMP: e6d4383bb91eca01
                  Start Page Redirect Cache AcceptLangs: fr
                  Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                  Default_page_url: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
                  Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
                  .
                  [HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]
                  .
                  Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
                  Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                  Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                  Delete_Temp_Files_On_Exit: yes
                  Local Page: %SystemRoot%\system32\blank.htm
                  Start Page: hxxp://fr.msn.com/
                  Search bar: hxxp://search.msn.com/spbasic.htm
                  HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\main\Start Page
                  .
                  [HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]
                  .
                  Tabs: res://ieframe.dll/tabswelcome.htm
                  .
                  ============== Suspect (Cracks, Serials, ...) ==============
                  .
                  C:\Documents and Settings\Laurent\Local Settings\Application Data\Opera\Opera\profile\cache4\temporary_download\flock_patch_v1_03.zip
                  C:\Documents and Settings\Laurent\Mes documents\Mises … jour de programme t‚l‚charg‚es\Dell Paint Shop Photo Album 5\MyPublisher Update for Paint Shop Photo Album 5\PSPA_MyPublisherPatch_French.exe
                  .
                  ===================================
                  .
                  6629 Octet(s) - C:\Ad-Report-CLEAN[1].log
                  3561 Octet(s) - C:\Ad-Report-CLEAN[2].log
                  .
                  0 Fichier(s) - C:\DOCUME~1\Laurent\LOCALS~1\Temp
                  0 Fichier(s) - C:\WINDOWS\Temp
                  0 Fichier(s) - C:\WINDOWS\Prefetch
                  .
                  36 Fichier(s) - C:\Program Files\Ad-Remover\BACKUP
                  224 Fichier(s) - C:\Program Files\Ad-Remover\QUARANTINE
                  .
                  Fin à: 11:56:20 | 28/12/2009 - CLEAN[2]
                  .
                  ============== E.O.F ==============
                  .
              5. Desactive ton antivirus le temps de la manip ainsi que ton parefeu si présent(car il est detecté a tort comme infection)

                ▶ Télécharge et installe List&Kill'em et enregistre le sur ton bureau

                double clique ( clic droit "executer en tant qu'administrateur" pour Vista/7 ) sur le raccourci sur ton bureau pour lancer l'installation

                coche la case "creer une icone sur le bureau"

                une fois terminée , clic sur "terminer" et le programme se lancera seul

                choisis la langue puis choisis l'option 1 = Mode Recherche

                ▶ laisse travailler l'outil

                à l'apparition de la fenetre blanche , c'est un peu long , c'est normal , le programme n'est pas bloqué.

                un rapport du nom de catchme apparait sur ton bureau , ignore-le,ne le poste pas , mais ne le supprime pas pour l instant, le scan n'est pas fini.

                ▶ Poste le contenu du rapport qui s'ouvre aux 100 % du scan à l'ecran "COMPLETED"

                tu peux supprimer le rapport catchme.log de ton bureau maintenant.

                1. voila le résultat :

                  List'em by g3n-h@ckm@n 1.1.6.2

                  Thx to Chiquitine29.....& CCM team

                  User : Laurent (Administrateurs) # FAMILLE
                  Update on 28/12/2009 by g3n-h@ckm@n ::::: 01:30
                  Start at: 13:40:03 | 28/12/2009
                  Contact : g3n-h@ckm@n sur CCM

                  Intel(R) Pentium(R) 4 CPU 3.00GHz
                  Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
                  Internet Explorer 8.0.6001.18702
                  Windows Firewall Status : Enabled
                  AV : VirusKeeper 2009 Pro antivirus 9.0 [ Enabled | Updated ]

                  A:\ -> Lecteur de disquettes 3 ½ pouces
                  C:\ -> Disque fixe local | 145,95 Go (74,26 Go free) [DISQUE DUR ] | NTFS
                  D:\ -> Disque CD-ROM

                  ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running

                  C:\WINDOWS\System32\smss.exe 420
                  C:\WINDOWS\system32\csrss.exe 844
                  C:\WINDOWS\system32\winlogon.exe 1012
                  C:\WINDOWS\system32\services.exe 1168
                  C:\WINDOWS\system32\lsass.exe 1180
                  C:\WINDOWS\system32\Ati2evxx.exe 1512
                  C:\WINDOWS\system32\svchost.exe 1548
                  C:\WINDOWS\system32\svchost.exe 1672
                  C:\WINDOWS\System32\svchost.exe 1784
                  C:\WINDOWS\system32\svchost.exe 1844
                  C:\WINDOWS\system32\Ati2evxx.exe 1888
                  C:\WINDOWS\system32\svchost.exe 2008
                  C:\WINDOWS\system32\svchost.exe 240
                  C:\WINDOWS\system32\spoolsv.exe 464
                  C:\WINDOWS\system32\svchost.exe 572
                  C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe 700
                  C:\Program Files\Bonjour\mDNSResponder.exe 768
                  C:\WINDOWS\system32\drivers\CDAC11BA.EXE 860
                  C:\WINDOWS\System32\svchost.exe 1428
                  C:\Program Files\Java\jre6\bin\jqs.exe 1484
                  C:\Program Files\Maxtor\Sync\SyncServices.exe 1748
                  C:\Program Files\Google\Update\1.2.183.13\GoogleCrashHandler.exe 1752
                  c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe 600
                  C:\WINDOWS\Explorer.EXE 1684
                  C:\Program Files\CDBurnerXP\NMSAccessU.exe 1944
                  C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe 344
                  c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe 752
                  C:\WINDOWS\system32\svchost.exe 684
                  C:\Program Files\AxBx\VirusKeeper 2009 Pro\vk_service.exe 1100
                  C:\WINDOWS\system32\SearchIndexer.exe 2072
                  C:\WINDOWS\system32\svchost.exe 2380
                  C:\Program Files\Windows Media Player\WMPNetwk.exe 2828
                  C:\Program Files\Canon\CAL\CALMAIN.exe 3100
                  C:\WINDOWS\System32\alg.exe 2740
                  C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe 2084
                  C:\WINDOWS\stsystra.exe 2160
                  C:\WINDOWS\system32\dla\tfswctrl.exe 1228
                  C:\WINDOWS\system32\LVCOMSX.EXE 2188
                  C:\Program Files\Vista Drive Icon\DrvIcon.exe 972
                  C:\Program Files\AxBx\VirusKeeper 2009 Pro\VirusKeeper.exe 2332
                  C:\Program Files\Logitech\Video\LogiTray.exe 2420
                  C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe 2504
                  C:\Program Files\iTunes\iTunesHelper.exe 3040
                  C:\Program Files\Java\jre6\bin\jusched.exe 3176
                  C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe 3276
                  C:\Program Files\IncrediMail\bin\IncMail.exe 3584
                  C:\Program Files\X'nBeep 1.1\XnBeep.exe 2324
                  C:\Program Files\CursorXP.exe 3928
                  C:\Program Files\RocketDock\RocketDock.exe 4040
                  C:\Program Files\Calendrier\Cld2000.exe 2116
                  C:\Program Files\Windows Media Player\WMPNSCFG.exe 2260
                  C:\WINDOWS\system32\ctfmon.exe 1852
                  C:\PROGRA~1\Magentic\bin\MgApp.exe 2352
                  C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe 2776
                  C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe 3364
                  C:\Program Files\Hercules\WiFi Station\WifiStation.exe 224
                  C:\Program Files\DateInTray\DateInTray.exe 3620
                  C:\WINDOWS\BricoPacks\Crystal Clear\YzToolbar\YzToolBar.exe 1608
                  C:\Program Files\Logitech\Video\FxSvr2.exe 3980
                  C:\Program Files\IncrediMail\bin\IMApp.exe 3456
                  C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe 2544
                  C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe 616
                  C:\WINDOWS\system32\HPZipm12.exe 1300
                  C:\Program Files\iPod\bin\iPodService.exe 3168
                  C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe 852
                  C:\Program Files\AxBx\VirusKeeper 2009 Pro\vk_watchop.exe 2932
                  C:\WINDOWS\system32\SearchProtocolHost.exe 2124
                  C:\WINDOWS\system32\SearchFilterHost.exe 1956
                  C:\Program Files\List_Kill'em\List_Kill'em.exe 2068
                  C:\WINDOWS\system32\cmd.exe 400
                  C:\WINDOWS\system32\wbem\wmiprvse.exe 3216
                  C:\Documents and Settings\Laurent\Local Settings\temp\4B.tmp\pv.exe 3212

                  ======================
                  Keys "Run"
                  ======================
                  [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                  LDM REG_SZ C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
                  LogitechSoftwareUpdate REG_SZ "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
                  Magentic REG_SZ C:\PROGRA~1\Magentic\bin\Magentic.exe /c
                  swg REG_SZ C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                  IncrediMail REG_SZ C:\Program Files\IncrediMail\bin\IncMail.exe /c
                  X'nBeep REG_SZ C:\Program Files\X'nBeep 1.1\XnBeep.exe
                  CursorXP REG_SZ C:\Program Files\CursorXP.exe
                  RocketDock REG_SZ "C:\Program Files\RocketDock\RocketDock.exe"
                  Google Update REG_SZ "C:\Documents and Settings\Laurent\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
                  Cld2000.exe REG_SZ C:\Program Files\Calendrier\Cld2000.exe
                  WMPNSCFG REG_SZ C:\Program Files\Windows Media Player\WMPNSCFG.exe
                  ctfmon.exe REG_SZ C:\WINDOWS\system32\ctfmon.exe

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                  ISUSPM Startup REG_SZ C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
                  ISUSScheduler REG_SZ "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
                  SigmatelSysTrayApp REG_SZ stsystra.exe
                  dla REG_SZ C:\WINDOWS\system32\dla\tfswctrl.exe
                  LVCOMSX REG_SZ C:\WINDOWS\system32\LVCOMSX.EXE
                  LogitechVideoRepair REG_SZ C:\Program Files\Logitech\Video\ISStart.exe
                  ATIPTA REG_SZ "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
                  DrvIcon REG_SZ C:\Program Files\Vista Drive Icon\DrvIcon.exe
                  VirusKeeper REG_SZ C:\Program Files\AxBx\VirusKeeper 2009 Pro\VirusKeeper.exe
                  AppleSyncNotifier REG_SZ C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
                  StartCCC REG_SZ "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
                  LogitechVideoTray REG_SZ C:\Program Files\Logitech\Video\LogiTray.exe
                  Adobe Reader Speed Launcher REG_SZ "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
                  Adobe ARM REG_SZ "C:\Program Files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe"
                  QuickTime Task REG_SZ "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                  iTunesHelper REG_SZ "C:\Program Files\iTunes\iTunesHelper.exe"
                  SunJavaUpdateSched REG_SZ "C:\Program Files\Java\jre6\bin\jusched.exe"

                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]

                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]

                  =====================
                  Other Keys
                  =====================
                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
                  dontdisplaylastusername REG_DWORD 0 (0x0)
                  legalnoticecaption REG_SZ
                  legalnoticetext REG_SZ
                  shutdownwithoutlogon REG_DWORD 1 (0x1)
                  undockwithoutlogon REG_DWORD 1 (0x1)
                  DisableRegistryTools REG_DWORD 0 (0x0)

                  ===============
                  [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
                  NoDriveTypeAutoRun REG_DWORD 323 (0x143)
                  NoDriveAutoRun REG_DWORD 67108863 (0x3ffffff)
                  NoDrives REG_DWORD 0 (0x0)

                  ===============
                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
                  HonorAutoRunSetting REG_DWORD 1 (0x1)
                  NoCDBurning REG_DWORD 0 (0x0)
                  NoDriveAutoRun REG_DWORD 67108863 (0x3ffffff)
                  NoDriveTypeAutoRun REG_DWORD 323 (0x143)
                  NoDrives REG_DWORD 0 (0x0)

                  ===============
                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]

                  ===============
                  [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\AtiExtEvent]
                  [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\crypt32chain]
                  [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cryptnet]
                  [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cscdll]
                  [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\dimsntfy]
                  [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ScCertProp]
                  [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Schedule]
                  [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\sclgntfy]
                  [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\SensLogn]
                  [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\termsrv]
                  [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WgaLogon]
                  [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wlballoon]

                  ===============
                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
                  {AEB6717E-7E19-11d0-97EE-00C04FD91972} REG_SZ
                  {56F9679E-7826-4C84-81F3-532071A8BCC5} REG_SZ

                  ===============
                  [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
                  %windir%\system32\sessmgr.exe REG_SZ %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
                  C:\Program Files\IncrediMail\bin\IMApp.exe REG_SZ C:\Program Files\IncrediMail\bin\IMApp.exe:*:Enabled:IncrediMail
                  C:\Program Files\IncrediMail\bin\IncMail.exe REG_SZ C:\Program Files\IncrediMail\bin\IncMail.exe:*:Enabled:IncrediMail
                  C:\Program Files\IncrediMail\bin\ImpCnt.exe REG_SZ C:\Program Files\IncrediMail\bin\ImpCnt.exe:*:Enabled:IncrediMail
                  C:\Documents and Settings\Laurent\Menu Démarrer\Programmes\IncrediMail\bin\ImpCnt.exe REG_SZ C:\Documents and Settings\Laurent\Menu Démarrer\Programmes\IncrediMail\bin\ImpCnt.exe:*:Enabled:IncrediMail
                  C:\Program Files\Messenger\msmsgs.exe REG_SZ C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger
                  C:\Documents and Settings\Laurent\Menu Démarrer\Programmes\IncrediMail\bin\ImLc.exe REG_SZ C:\Documents and Settings\Laurent\Menu Démarrer\Programmes\IncrediMail\bin\ImLc.exe:*:Enabled:IncrediMail
                  C:\Documents and Settings\Laurent\Menu Démarrer\Programmes\IncrediMail\bin\ImPackr.exe REG_SZ C:\Documents and Settings\Laurent\Menu Démarrer\Programmes\IncrediMail\bin\ImPackr.exe:*:Enabled:IncrediMail
                  C:\Program Files\Magentic\bin\MgImp.exe REG_SZ C:\Program Files\Magentic\bin\MgImp.exe:*:Enabled:Magentic
                  C:\Program Files\Magentic\bin\Magentic.exe REG_SZ C:\Program Files\Magentic\bin\Magentic.exe:*:Enabled:Magentic
                  C:\Program Files\Magentic\bin\MgApp.exe REG_SZ C:\Program Files\Magentic\bin\MgApp.exe:*:Enabled:Magentic
                  %windir%\Network Diagnostic\xpnetdiag.exe REG_SZ %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
                  C:\Documents and Settings\Laurent\Menu Démarrer\Programmes\IncrediMail\bin\IncrediMail_Install.exe REG_SZ C:\Documents and Settings\Laurent\Menu Démarrer\Programmes\IncrediMail\bin\IncrediMail_Install.exe:*:Enabled:IncrediMail Installer
                  C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe REG_SZ C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger
                  C:\Program Files\Codemasters\Worms 4 Mayhem Demo\Worms 4 Mayhem Demo.exe REG_SZ C:\Program Files\Codemasters\Worms 4 Mayhem Demo\Worms 4 Mayhem Demo.exe:*:Enabled:Worms 4 Mayhem Demo
                  C:\Program Files\Mozilla Firefox\firefox.exe REG_SZ C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Mozilla Browser
                  C:\Program Files\Commandos II\comm2.exe REG_SZ C:\Program Files\Commandos II\comm2.exe:*:Enabled:comm2
                  C:\Program Files\The All-Seeing Eye\eye.exe REG_SZ C:\Program Files\The All-Seeing Eye\eye.exe:*:Enabled:Yahoo! All-Seeing Eye
                  C:\Program Files\Opera\Opera.exe REG_SZ C:\Program Files\Opera\Opera.exe:*:Enabled:Opera Internet Browser
                  C:\WINDOWS\system32\dpvsetup.exe REG_SZ C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test
                  C:\WINDOWS\system32\java.exe REG_SZ C:\WINDOWS\system32\java.exe:*:Enabled:Java(TM) Platform SE binary
                  C:\Program Files\Real\RealPlayer\realplay.exe REG_SZ C:\Program Files\Real\RealPlayer\realplay.exe:*:Enabled:RealPlayer
                  C:\Program Files\SopCast\SopCast.exe REG_SZ C:\Program Files\SopCast\SopCast.exe:*:Enabled:SopCast Main Application
                  C:\Program Files\SopCast\adv\SopAdver.exe REG_SZ C:\Program Files\SopCast\adv\SopAdver.exe:*:Enabled:SopCast Adver
                  C:\Documents and Settings\David\Application Data\PowerChallenge\PowerSoccer\PowerSoccer.exe REG_SZ C:\Documents and Settings\David\Application Data\PowerChallenge\PowerSoccer\PowerSoccer.exe:*:Enabled:PowerSoccer
                  C:\Program Files\Pinnacle\VideoSpin\Programs\RM.exe REG_SZ C:\Program Files\Pinnacle\VideoSpin\Programs\RM.exe:*:Enabled:Render Manager
                  C:\Program Files\Pinnacle\VideoSpin\Programs\PMSRegisterFile.exe REG_SZ C:\Program Files\Pinnacle\VideoSpin\Programs\PMSRegisterFile.exe:*:Enabled:PMSRegisterFile
                  C:\Program Files\Pinnacle\VideoSpin\Programs\umi.exe REG_SZ C:\Program Files\Pinnacle\VideoSpin\Programs\umi.exe:*:Enabled:umi
                  C:\Program Files\Pinnacle\VideoSpin\Programs\VideoSpin.exe REG_SZ C:\Program Files\Pinnacle\VideoSpin\Programs\VideoSpin.exe:*:Enabled:Pinnacle VideoSpin
                  C:\WINDOWS\pchealth\helpctr\binaries\helpctr.exe REG_SZ C:\WINDOWS\pchealth\helpctr\binaries\helpctr.exe:*:Enabled:Assistance à distance - Windows Messenger et voix
                  C:\Program Files\VideoLAN\VLC\vlc.exe REG_SZ C:\Program Files\VideoLAN\VLC\vlc.exe:*:Enabled:VLC media player
                  C:\Program Files\Mindscape\Mission Président - Geo-Political Simulator\MISSION.EXE REG_SZ C:\Program Files\Mindscape\Mission Président - Geo-Political Simulator\MISSION.EXE:*:Enabled:Application _geolgps
                  C:\Program Files\Ivicam\backsurvey.exe REG_SZ C:\Program Files\Ivicam\backsurvey.exe:*:Enabled:Ivisible_BackSurvey
                  C:\Program Files\Icecast2 Win32\Icecast2win.exe REG_SZ C:\Program Files\Icecast2 Win32\Icecast2win.exe:*:Enabled:Icecast2win
                  C:\Program Files\SHOUTcast\sc_serv.exe REG_SZ C:\Program Files\SHOUTcast\sc_serv.exe:*:Enabled:sc_serv
                  C:\Program Files\Bonjour\mDNSResponder.exe REG_SZ C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour
                  C:\Program Files\QuickTime\QuickTimePlayer.exe REG_SZ C:\Program Files\QuickTime\QuickTimePlayer.exe:*:Enabled:QuickTime Player
                  C:\Program Files\Windows Live\Messenger\msnmsgr.exe REG_SZ C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger
                  C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe REG_SZ C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live FolderShare
                  C:\Program Files\ma-config.com\maconfservice.exe REG_SZ C:\Program Files\ma-config.com\maconfservice.exe:LocalSubNet:Enabled:maconfservice
                  C:\WINDOWS\system32\rtcshare.exe REG_SZ C:\WINDOWS\system32\rtcshare.exe:*:Enabled:Partage de l'application RTC
                  C:\Program Files\NetMeeting\conf.exe REG_SZ C:\Program Files\NetMeeting\conf.exe:*:Enabled:Windows® NetMeeting®
                  C:\Program Files\iTunes\iTunes.exe REG_SZ C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes
                  C:\Program Files\Sony Ericsson\Update Service\Update Service.exe REG_SZ C:\Program Files\Sony Ericsson\Update Service\Update Service.exe:*:Enabled:Update Service
                  C:\WINDOWS\system32\wuauserv.exe REG_SZ C:\WINDOWS\system32\wuauserv.exe:*:Enabled:TCP
                  C:\WINDOWS\system32\tftp.exe REG_SZ C:\WINDOWS\system32\tftp.exe:*:Enabled:Tftp

                  [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
                  %windir%\system32\sessmgr.exe REG_SZ %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
                  %windir%\Network Diagnostic\xpnetdiag.exe REG_SZ %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
                  C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe REG_SZ C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger
                  C:\Program Files\Windows Live\Messenger\msnmsgr.exe REG_SZ C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger
                  C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe REG_SZ C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live FolderShare

                  ===============
                  BHO :
                  ======
                  [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
                  [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
                  [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{53707962-6F74-2D53-2644-206D7942484F}]
                  [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
                  [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
                  [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
                  [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
                  [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{B56A7D7D-6927-48C8-A975-17DF180C71AC}]
                  [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{C84D72FE-E17D-4195-BB24-76C02E2E7C4E}]
                  [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{ccec60fc-2608-4e58-9659-3ffc159e8ea9}]
                  [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
                  [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53}]
                  [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10}]
                  [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]

                  ================
                  Internet Explorer :
                  ================
                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
                  Start Page REG_SZ https://www.msn.com/fr-fr

                  [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                  Start Page REG_SZ http://mystart.incredimail.com/

                  ========
                  Services
                  ========
                  [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services]

                  Ndisuio : 0x3
                  EapHost : 0x3
                  SharedAccess : 0x2
                  wuauserv : 0x2

                  =========

                  =======
                  Drive :
                  =======

                  D‚fragmenteur de disque Windows
                  Copyright (c) 2001 Microsoft Corp. et Executive Software International Inc.

                  Rapport d'analyse
                  146 Go total, 74,27 Go libre (50%), 5% fragment‚ (fragmentation du fichier 10%)

                  Il ne vous est pas n‚cessaire de d‚fragmenter ce volume.

                  ¤¤¤¤¤¤¤¤¤¤ Files/folders :

                  C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
                  C:\Program Files\WinPCap
                  C:\WINDOWS\aucfg.ini
                  C:\WINDOWS\Fonts\GRGAREF.TTF
                  C:\WINDOWS\iun6002.exe
                  C:\WINDOWS\System32\ACTSKN43.ocx
                  C:\WINDOWS\System32\drivers\etc\hosts.msn
                  C:\WINDOWS\System32\drivers\npf.sys
                  C:\WINDOWS\System32\MSINET.oca
                  C:\WINDOWS\System32\Packet.dll
                  C:\WINDOWS\System32\pthreadVC.dll
                  C:\WINDOWS\System32\WanPacket.dll
                  C:\WINDOWS\System32\wpcap.dll

                  ¤¤¤¤¤¤¤¤¤¤ Keys :

                  "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Install.exe"
                  "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Setup.exe"
                  HKCR\Install.Install
                  HKCR\Install.Install\CLSID
                  HKCR\Install.Install\CurVer
                  HKCR\Install.Install.1
                  HKCR\Install.Install.1\CLSID
                  HKCR\Interface\{daa37aad-f156-4c2c-ac48-3c22ef92ae2f}
                  HKLM\SYSTEM\ControlSet001\Enum\Root\LEGACY_NPF
                  HKLM\SYSTEM\ControlSet001\Services\npf
                  HKLM\SYSTEM\ControlSet002\Enum\Root\LEGACY_NPF
                  HKLM\SYSTEM\ControlSet002\Services\npf

                  ================
                  Other infections
                  ================

                  catchme 0.3.1398.3 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                  Rootkit scan 2009-12-28 13:44:03
                  Windows 5.1.2600 Service Pack 3 NTFS

                  scanning hidden processes ...

                  scanning hidden services & system hive ...

                  scanning hidden registry entries ...

                  scanning hidden files ...

                  scan completed successfully
                  hidden processes: 0
                  hidden services: 0
                  hidden files: 0

                  Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

                  device: opened successfully
                  user: MBR read successfully
                  kernel: MBR read successfully
                  user & kernel MBR OK

                  ==========
                  Programs
                  ==========

                  21cn
                  3DO
                  4Musics MP3 Bitrate Changer
                  A!K Research Labs
                  ACE Mega CoDecS Pack
                  ActivIcons
                  Activision
                  Activision Value
                  Ad-Remover
                  Adobe
                  adslTV
                  Ahead
                  AIDA32
                  AIST
                  Alice
                  ALO SOFT
                  Alwil Software
                  AmitySource
                  AniUtil.exe
                  Ankama Games
                  Apple Software Update
                  Astonsoft
                  ATI Technologies
                  AticiaPlanning
                  ATP
                  Audacity
                  Avanquest
                  AviSynth 2.5
                  AVS4YOU
                  AVSMedia
                  AWicons Lite
                  AxBx
                  Axis Communications
                  BarreConfCMCIC
                  Batman
                  Beneton Movie GIF
                  Bethesda Softworks
                  bfgclient
                  BHODemon 2
                  Bonjour
                  Boonty
                  BoontyGames
                  Bullfrog
                  BumpTop
                  Buzz c3nform.vxml
                  Calendrier
                  CamStudio
                  Canon
                  CCleaner
                  CDBurnerXP
                  CFWebAdvancedU
                  CFWebAdvancedU_BOBTV.FR
                  Christmas Time 3D Screensaver
                  Classfoot Worldcup 2006
                  Codemasters
                  Commandos II
                  Common Files
                  CPUID
                  Cryer
                  CursorXP.exe
                  CurXP0.dll
                  CurXP1.dll
                  CurXPCpl.dll
                  CurXPCpl.exe
                  CurXPUtil.exe
                  CyberLink
                  DateInTray
                  defaults
                  Dell
                  Dell Inc
                  DesktopEyes
                  DIFX
                  directx
                  DivX
                  djDecks
                  Documalis Free
                  Dofus
                  Dofus 2
                  Doom 3 Demo
                  DVDVideoSoft
                  e-anim701
                  e.t
                  EBP
                  Eidos Interactive
                  Eko
                  eMule
                  encoding.bin
                  ENJOY Plus!
                  eula.txt
                  Europress
                  Evermore
                  extra
                  FastStone Image Viewer
                  Feedio
                  Fichiers communs
                  filehippo.com
                  FileZilla Client
                  Flux_2
                  FLVPlayer
                  fond-ecran-wallpaper.com
                  foobar2000
                  Freecorder
                  Funkitron
                  Future Pinball
                  Gamenext
                  GameSpy Arcade
                  GenIconXP
                  GeoVid
                  Giant
                  GIMP-2.0
                  Glary Utilities
                  Google
                  Gpotato.eu
                  Graphex3
                  Grisoft
                  HardwareDetection
                  Hercules
                  Heredis 8
                  Hewlett-Packard
                  HomeSite
                  Horloge 2005
                  html40_entities.dtd
                  Icecast2 Win32
                  Ihsv
                  Illustrate
                  Incredijeux
                  IncrediMail
                  Infogrames
                  InfraRecorder
                  Inkscape
                  InstallShield Installation Information
                  Intel
                  Internet Explorer
                  Intuisphere
                  iPod
                  IrfanView
                  iTunes
                  IviCam
                  Jasc Software Inc
                  Java
                  Jeskola Buzz
                  JRE
                  JVTorrent
                  Kaspersky Lab
                  KC Softwares
                  Languages
                  Learn2.com
                  LeechFTP
                  license.rtf
                  LimeWire
                  List_Kill'em
                  LM Version-2.5-F
                  lngcode.txt
                  locale
                  Logitech
                  LucasArts
                  Luxor 2
                  M6 Jeux
                  ma-config.com
                  Magentic
                  MAGIX
                  Malwarebytes' Anti-Malware
                  Maxis
                  Maxtor
                  Maxtor(2)
                  Ma‹do Production
                  MediaCoder
                  MediaInfo
                  Mes Jeux T‚l‚charg‚s
                  Mess with MSN Messenger skins, nicknames, add-ons, bots and secrets.url
                  Messenger
                  Messenger Plus! Live
                  Metal Gear Solid
                  Micro Application
                  Microsoft
                  Microsoft CAPICOM 2.1.0.2
                  Microsoft Encarta
                  microsoft frontpage
                  Microsoft FrontPage Express
                  Microsoft Games
                  Microsoft Office
                  Microsoft Office Outlook Connector
                  Microsoft Picture It! PhotoPub
                  Microsoft Silverlight
                  Microsoft SQL Server
                  Microsoft SQL Server Compact Edition
                  Microsoft Sync Framework
                  Microsoft Works
                  Microsoft.NET
                  Mindscape
                  Mioplanet
                  Monkey's Audio
                  Monte Cristo
                  Movie Maker
                  Mozilla Firefox
                  Mozilla Firefox 3 Beta 5
                  Mozilla Firefox 3.1 Beta 3
                  Mozilla Firefox 3.5 Beta 4
                  Mozilla Firefox 3.5 Preview
                  Mozilla Firefox 3.6 Beta 1
                  Mozilla Firefox 3.6 Beta 2
                  Mozilla Thunderbird
                  MP3 Player Utilities
                  MP3 Player Utilities 3.57
                  mp3DirectCut
                  MP3Gain
                  mp3splt-gtk
                  MSBuild
                  MSECache
                  MSN
                  MSN Games
                  MSN Gaming Zone
                  MSN Messenger
                  MSXML 4.0
                  MSXML 6.0
                  MyMPxPlayer.org
                  MyPhoneExplorer
                  MySight 2006
                  Navilog1
                  NCH Software
                  NCH Swift Sound
                  Nero
                  NetMeeting
                  Network Stumbler
                  nLite
                  NOS
                  Notepad++
                  Nvu
                  Oberon Media
                  Online Services
                  OpenOffice.org 2.4
                  OpenOffice.org 3
                  Opera
                  Opera 10 Preview
                  opera.dll
                  opera.exe
                  operaprefs_default.ini
                  orange
                  OrphansRemover
                  OUniAnsi.dll
                  Outlook Express
                  Panda Security
                  Panicware
                  PDFCreator
                  PeerTV
                  Photo Viewer
                  PhotoMail Maker
                  PhotoRapido
                  PicaFr
                  Pinnacle
                  Player Metaboli
                  Plus!
                  program
                  QuickTime
                  RacingPitch
                  Radio Fr Solo
                  Radio Stream Player
                  Radionomy
                  Ratajik Software
                  RawFlow
                  read1st.txt
                  Readme.txt
                  Real
                  RealArcade
                  Reference Assemblies
                  ReflexiveArcade
                  Reset theme.lnk
                  Retro64 Games
                  Ricochet Xtreme
                  Ripp-it_AM
                  RngInterstitial.dll
                  RocketDock
                  Rockstar Games
                  Safari
                  SereneScreen
                  Services en ligne
                  Shareaza
                  SHOUTcast
                  SHOUTcast Radio Toolbar
                  Sierra
                  Sigmatel
                  Sim AQUARIUM 2
                  SimpleOCR
                  skin
                  Skype
                  Snowball
                  SoftChris
                  Softwin
                  Sonic
                  Sony Ericsson
                  SopCast
                  Sporever
                  Spybot - Search & Destroy
                  Spyware Doctor(2)
                  Stardock
                  STOIK Imaging
                  styles
                  Surreal
                  Sweet Home 3D
                  TGTSoft
                  The All-Seeing Eye
                  Themes
                  THQ
                  Tiscali
                  TomTom DesktopSuite
                  TopDesk Trial
                  TubeMaster
                  TubeMaster++
                  TuneUp Utilities 2009
                  T‚l‚chargeur de Singles
                  UberSoldier Demo
                  Ubi Soft
                  ui
                  Ulead Systems
                  Ultimate generator
                  Uninstall Information
                  Uninstall.lnk
                  Universal Interactive
                  Unzip32.dll
                  URUSoft
                  VCW VicMan's Photo Editor
                  VideoCap
                  VideoLAN
                  Virtools
                  Vista Drive Icon
                  VivilProject SpeedTest
                  Wakfu
                  Web Photo Album
                  Winamp
                  Windows Desktop Search
                  Windows Live
                  Windows Live SkyDrive
                  Windows Live Toolbar
                  Windows Media Connect
                  Windows Media Connect 2
                  Windows Media Player
                  Windows NT
                  WindowsUpdate
                  WinMPG VideoConvert
                  WinPcap
                  WinRAR
                  WinZip
                  Worms
                  X'nBeep 1.1
                  xerox
                  Xilisoft
                  Yahoo!
                  YourWare Solutions
                  Zip32.dll
                  Zumas Revenge! - Adventure
                  Zylom Games

                  ============
                  Lecteur C:
                  ============

                  projet
                  $VAULT$.AVG
                  5b65fb94b65b57c50b17538d
                  a67a334ca6418fa49cd78dda214627
                  Ad-Report-CLEAN[1].log
                  Ad-Report-CLEAN[2].log
                  ageofjapan_RADRMEx.dll
                  asoutput.log
                  ASY.log
                  ATI
                  AUTOEXEC.BAT
                  AVG7QT.DAT
                  bink_log.txt
                  Boot.bak
                  BOOT.BKK
                  boot.ini
                  boot.ini.back
                  boot.uni
                  Bootfont.bin
                  c
                  c7660d5d5134ab059248ac8db796d7a7
                  Cadre Photo Num‚rique
                  cannonblast_RADRMEx.dll
                  CAPTURE.AVI
                  cleannavi.txt
                  cmdcons
                  cmldr
                  CodeRED Alien Arena
                  ComboFix.txt
                  Config.Msi
                  CONFIG.SYS
                  debugInstaller.txt
                  Default.Bmp
                  default.txt
                  dell
                  dell.sdr
                  diamonddetective_RADRMEx.dll
                  Documents and Settings
                  DownloadLog.txt
                  Downloads
                  drivers
                  e8e1d80abd6e6a2e88
                  error.log
                  f02e2174e5e8740c4d
                  fizzball_RADRMEx.dll
                  flowershopbigcitybreak_RADRMEx.dll
                  found.000
                  found.001
                  giftshop_RADRMEx.dll
                  hpfr3420.xml
                  hpfr3425.log
                  i386
                  INFCACHE.1
                  Intel
                  IO.SYS
                  IPH.PH
                  Kill'em
                  LGSInst.Log
                  lifetimersvp_RADRMEx.dll
                  List'em.txt
                  LogiSetup.log
                  Lop SD
                  lopR.txt
                  magicball3_RADRMEx.dll
                  MAPISVC.INF
                  MAPISVC.PNF
                  Mes t‚l‚chargements
                  mpeg.txt
                  MSDOS.SYS
                  My Download Files
                  My Games
                  My Music
                  NTDETECT.COM
                  ntldr
                  orange.bmp
                  os466477.bin
                  pagefile.sys
                  picajet.log
                  PMAIL
                  Program Files
                  Qoobox
                  rainbowmystery_RADRMEx.dll
                  RECYCLER
                  Remote Programs
                  sandscripttm_RADRMEx.dll
                  sound_bank_log.txt
                  sqmdata00.sqm
                  sqmdata01.sqm
                  sqmnoopt00.sqm
                  sqmnoopt01.sqm
                  sqmnoopt02.sqm
                  sqmnoopt03.sqm
                  sqmnoopt04.sqm
                  sqmnoopt05.sqm
                  sqmnoopt06.sqm
                  sqmnoopt07.sqm
                  sqmnoopt08.sqm
                  sqmnoopt09.sqm
                  sqmnoopt10.sqm
                  sqmnoopt11.sqm
                  sqmnoopt12.sqm
                  sqmnoopt13.sqm
                  sqmnoopt14.sqm
                  sqmnoopt15.sqm
                  sqmnoopt16.sqm
                  sqmnoopt17.sqm
                  sqmnoopt18.sqm
                  sqmnoopt19.sqm
                  supergranny3_RADRMEx.dll
                  System Volume Information
                  team17
                  Temp
                  test.avi
                  test.jpg
                  TEST.XML
                  thelegendofeldorado_RADRMEx.dll
                  TLK GAMES
                  tmp
                  transparency
                  users
                  Video surveillance facile
                  VundoFix Backups
                  VundoFix.txt
                  WINDOWS
                  X-Plane
                  X-Plane Installer.prf
                  xscan.txt
                  zodiactower_RADRMEx.dll
                  _Backup
                  _Backup.RC
                  _table.txt

                  ¤¤¤¤¤¤¤¤¤¤ Cracks | Keygens | Serials

                  C:\Documents and Settings\David\Mes documents\A d‚plac‚ sur la cl‚\PortableGIMP\gimp\share\gimp\2.0\gimpressionist\Presets\Patchwork
                  C:\Documents and Settings\David\Mes documents\A d‚plac‚ sur la cl‚\PortableGIMP\gimp\share\gimp\2.0\patterns\cracked.pat
                  C:\Documents and Settings\Laurent\Mes documents\TomTom\HOME\Backup\ONE\Backup01\InternalMemory\France\PatchFilter.dat
                  C:\Program Files\GIMP-2.0\share\gimp\2.0\gimpressionist\Presets\Patchwork
                  C:\Program Files\GIMP-2.0\share\gimp\2.0\patterns\cracked.pat
                  C:\Program Files\Gpotato.eu\Flyff\PatchLog.txt
                  C:\Program Files\Heredis 8\Models\Patchwork.hm7
                  C:\Program Files\Inkscape\python\Lib\site-packages\numpy\f2py\crackfortran.py
                  C:\Program Files\Inkscape\python\Lib\site-packages\numpy\f2py\crackfortran.pyc
                  C:\Program Files\Inkscape\python\Lib\site-packages\numpy\f2py\crackfortran.pyo
                  C:\Program Files\Jeskola Buzz\Patcher.exe
                  C:\Program Files\Microsoft SQL Server\90\Setup Bootstrap\Patch
                  C:\Program Files\Microsoft SQL Server\90\Setup Bootstrap\Patch\Sql
                  C:\Program Files\Microsoft SQL Server\90\Setup Bootstrap\Patch\Sql\SqlRun_SLP_SQL.msp
                  C:\Documents and Settings\David\Mes documents\Autre\Install.exe
                  C:\Program Files\Ripp-it_AM\dlls\AACPatch.exe
                  C:\Program Files\Snowball\Install.exe

                  ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
              6. ▶ Relance List&Kill'em(soit en clic droit pour vista),avec le raccourci sur ton bureau.
                mais cette fois-ci :

                ▶ choisis l'option 2 = Mode Suppression

                laisse travailler l'outil.

                en fin de scan un rapport s'ouvre

                ▶ colle le contenu dans ta reponse
                1. resultat list&kill'em option 2 : mode suppression.

                  Kill'em by g3n-h@ckm@n 1.1.6.2

                  User : Laurent (Administrateurs) # FAMILLE
                  Update on 28/12/2009 by g3n-h@ckm@n ::::: 01:30
                  Start at: 16:55:32 | 28/12/2009
                  Contact : g3n-h@ckm@n sur CCM

                  Intel(R) Pentium(R) 4 CPU 3.00GHz
                  Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
                  Internet Explorer 8.0.6001.18702
                  Windows Firewall Status : Enabled
                  AV : VirusKeeper 2009 Pro antivirus 9.0 [ Enabled | Updated ]

                  A:\ -> Lecteur de disquettes 3 ½ pouces
                  C:\ -> Disque fixe local | 145,95 Go (74,26 Go free) [DISQUE DUR ] | NTFS
                  D:\ -> Disque CD-ROM

                  ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running

                  C:\WINDOWS\System32\smss.exe 420
                  C:\WINDOWS\system32\csrss.exe 844
                  C:\WINDOWS\system32\winlogon.exe 1012
                  C:\WINDOWS\system32\services.exe 1168
                  C:\WINDOWS\system32\lsass.exe 1180
                  C:\WINDOWS\system32\Ati2evxx.exe 1512
                  C:\WINDOWS\system32\svchost.exe 1548
                  C:\WINDOWS\system32\svchost.exe 1672
                  C:\WINDOWS\System32\svchost.exe 1784
                  C:\WINDOWS\system32\svchost.exe 1844
                  C:\WINDOWS\system32\Ati2evxx.exe 1888
                  C:\WINDOWS\system32\svchost.exe 2008
                  C:\WINDOWS\system32\svchost.exe 240
                  C:\WINDOWS\system32\spoolsv.exe 464
                  C:\WINDOWS\system32\svchost.exe 572
                  C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe 700
                  C:\Program Files\Bonjour\mDNSResponder.exe 768
                  C:\WINDOWS\system32\drivers\CDAC11BA.EXE 860
                  C:\WINDOWS\System32\svchost.exe 1428
                  C:\Program Files\Java\jre6\bin\jqs.exe 1484
                  C:\Program Files\Maxtor\Sync\SyncServices.exe 1748
                  C:\Program Files\Google\Update\1.2.183.13\GoogleCrashHandler.exe 1752
                  c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe 600
                  C:\WINDOWS\Explorer.EXE 1684
                  C:\Program Files\CDBurnerXP\NMSAccessU.exe 1944
                  C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe 344
                  c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe 752
                  C:\WINDOWS\system32\svchost.exe 684
                  C:\Program Files\AxBx\VirusKeeper 2009 Pro\vk_service.exe 1100
                  C:\WINDOWS\system32\SearchIndexer.exe 2072
                  C:\WINDOWS\system32\svchost.exe 2380
                  C:\Program Files\Windows Media Player\WMPNetwk.exe 2828
                  C:\Program Files\Canon\CAL\CALMAIN.exe 3100
                  C:\WINDOWS\System32\alg.exe 2740
                  C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe 2084
                  C:\WINDOWS\stsystra.exe 2160
                  C:\WINDOWS\system32\dla\tfswctrl.exe 1228
                  C:\WINDOWS\system32\LVCOMSX.EXE 2188
                  C:\Program Files\Vista Drive Icon\DrvIcon.exe 972
                  C:\Program Files\AxBx\VirusKeeper 2009 Pro\VirusKeeper.exe 2332
                  C:\Program Files\Logitech\Video\LogiTray.exe 2420
                  C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe 2504
                  C:\Program Files\iTunes\iTunesHelper.exe 3040
                  C:\Program Files\Java\jre6\bin\jusched.exe 3176
                  C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe 3276
                  C:\Program Files\X'nBeep 1.1\XnBeep.exe 2324
                  C:\Program Files\CursorXP.exe 3928
                  C:\Program Files\RocketDock\RocketDock.exe 4040
                  C:\Program Files\Calendrier\Cld2000.exe 2116
                  C:\Program Files\Windows Media Player\WMPNSCFG.exe 2260
                  C:\WINDOWS\system32\ctfmon.exe 1852
                  C:\PROGRA~1\Magentic\bin\MgApp.exe 2352
                  C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe 2776
                  C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe 3364
                  C:\Program Files\Hercules\WiFi Station\WifiStation.exe 224
                  C:\Program Files\DateInTray\DateInTray.exe 3620
                  C:\WINDOWS\BricoPacks\Crystal Clear\YzToolbar\YzToolBar.exe 1608
                  C:\Program Files\Logitech\Video\FxSvr2.exe 3980
                  C:\Program Files\IncrediMail\bin\IMApp.exe 3456
                  C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe 2544
                  C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe 616
                  C:\WINDOWS\system32\HPZipm12.exe 1300
                  C:\Program Files\iPod\bin\iPodService.exe 3168
                  C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe 852
                  C:\Program Files\AxBx\VirusKeeper 2009 Pro\vk_watchop.exe 2932
                  C:\Program Files\IncrediMail\Bin\IncMail.exe 3480
                  C:\Program Files\List_Kill'em\List_Kill'em.exe 1364
                  C:\WINDOWS\system32\cmd.exe 2216
                  C:\WINDOWS\system32\wbem\wmiprvse.exe 3612
                  C:\Documents and Settings\Laurent\Local Settings\temp\8A.tmp\pv.exe 2368

                  Detections :
                  ==========

                  ¤¤¤¤¤¤¤¤¤¤ Files/folders :

                  C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
                  "C:\Program Files\WinPCap"
                  "C:\WINDOWS\aucfg.ini"
                  "C:\WINDOWS\Fonts\GRGAREF.TTF"
                  "C:\WINDOWS\iun6002.exe"
                  "C:\WINDOWS\System32\ACTSKN43.ocx"
                  "C:\WINDOWS\System32\drivers\etc\hosts.msn"
                  "C:\WINDOWS\system32\drivers\npf.sys"
                  "C:\WINDOWS\system32\MSINET.oca"
                  "C:\WINDOWS\system32\Packet.dll"
                  "C:\WINDOWS\system32\pthreadVC.dll"
                  "C:\WINDOWS\system32\WanPacket.dll"
                  "C:\WINDOWS\system32\wpcap.dll"

                  ¤¤¤¤¤¤¤¤¤¤ Files/folders deleted :

                  Quarantine :

                  actskn43.ocx.Kill'em
                  aucfg.ini.Kill'em
                  GRGAREF.TTF.Kill'em
                  hosts.msn.Kill'em
                  iun6002.exe.Kill'em
                  MSINET.oca.Kill'em
                  npf.sys.Kill'em
                  Packet.dll.Kill'em
                  pthreadVC.dll.Kill'em
                  QTSBandwidthCache.Kill'em
                  WanPacket.dll.Kill'em
                  WinPcap.Kill'em
                  wpcap.dll.Kill'em

                  ==============
                  host file OK !
                  ==============

                  ========
                  Registry
                  ========
                  Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Install.exe
                  Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Setup.exe
                  Deleted : HKCR\Install.Install
                  Deleted : HKCR\Install.Install.1
                  Deleted : HKCR\Interface\{daa37aad-f156-4c2c-ac48-3c22ef92ae2f}
                  Deleted : HKLM\SYSTEM\ControlSet001\Services\npf
                  Deleted : HKLM\SYSTEM\ControlSet002\Services\npf

                  ============
                  Disk Cleaned
                  ============

                  ================
                  Prefetch cleaned
                  ================

                  ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
                2. Bonjour à tout le monde,

                  ce matin j'ai passé de nouveau spybot, et il lit encore des dizaines de lignes nommées virtumonde. Je pense qu'il infeste encore mon pc. Voyez vous d'autres choses pour s'en débarasser ? Merci d'avances pour vos réponses.
              7. ▶ Télécharge : Gmer (by Przemyslaw Gmerek)

                ▶ Dezippe gmer ,cliques sur l'onglet rootkit,lances le scan,des lignes rouges vont apparaitre.

                ▶ Les lignes rouges indiquent la presence d'un rootkit.Postes moi le rapport gmer (cliques sur copy,puis vas dans demarrer ,puis ouvres le bloc note,vas dans edition et cliques sur coller,le rapport gmer va apparaitre,postes moi le)

                Ensuite

                ▶ sur les lignes rouge:

                ▶ Services:cliques droit delete service
                ▶ Process:cliques droit kill process
                ▶ Adl ,file:cliques droit delete files
                1. Salut gen-hackman, merci encore pour ton aide.

                  Avec gmer, quelques petits soucis :

                  quand je dézippe comme tu me le demande, un scan se lance tout seul, sans que j'aie à cliquer sur l'onglet rootkit. au bout de 30 secondes environs, 4 lignes apparaissent, mais aucune en rouge. Et enfin je ne trouve pas le bloc notes dans démarrer. Excuse moi, mais je ne suis pas balaise !!!
                2. @fripouille68Bonjour, y a t'il encore quelqu'un pour s'occuper de mon soucis ? Merci beaucoup d'avance.
              8. salut

                desole pris par les travaux ^^

                Imprime ces instructions car il faudra fermer toutes les fenêtres et applications lors de l'installation et de l'analyse.

                ▶ Télécharge :

                Malwarebytes

                ou :

                Malwarebytes

                ▶ Installe le ( choisis bien "francais" ; ne modifie pas les paramètres d'installe ) et mets le à jour .

                (NB : Si tu as un message d'erreur t'indiquant qu'il te manque "COMCTL32.OCX" lors de l'installe, alors télécharge le ici : COMCTL32.OCX

                ▶ Potasses le Tuto pour te familiariser avec le prg :

                ( cela dit, il est très simple d'utilisation ).

                relance malwarebytes en suivant scrupuleusement ces consignes :

                ! Déconnecte toi et ferme toutes applications en cours !

                ▶ Lance Malwarebyte's .

                Fais un examen dit "Complet" .

                ▶ Laisse le programme travailler ( et ne rien faire d'autre avec le PC durant le scan ).
                ▶ à la fin tu cliques sur "résultat" .
                ▶ Vérifie que tous les objets infectés soient validés, puis clique sur " suppression " .

                ▶ Note : si il faut redémarrer ton PC pour finir le nettoyage, fais le !

                ▶ Poste le rapport sauvegardé après la suppression des objets infectés (dans l'onglet "rapport/log"de Malwarebytes, le dernier en date)

                1. Salut gen-hackman, tout d'abord merci beaucoup de m'aider, très sympa de ta part. Bonne soirée.
                  Voici le résultat du scan de malwarebytes :

                  Malwarebytes' Anti-Malware 1.43
                  Version de la base de données: 3480
                  Windows 5.1.2600 Service Pack 3
                  Internet Explorer 8.0.6001.18702

                  02/01/2010 23:10:19
                  mbam-log-2010-01-02 (23-10-19).txt

                  Type de recherche: Examen complet (C:\|)
                  Eléments examinés: 489772
                  Temps écoulé: 3 hour(s), 40 minute(s), 12 second(s)

                  Processus mémoire infecté(s): 0
                  Module(s) mémoire infecté(s): 0
                  Clé(s) du Registre infectée(s): 0
                  Valeur(s) du Registre infectée(s): 0
                  Elément(s) de données du Registre infecté(s): 0
                  Dossier(s) infecté(s): 0
                  Fichier(s) infecté(s): 1

                  Processus mémoire infecté(s):
                  (Aucun élément nuisible détecté)

                  Module(s) mémoire infecté(s):
                  (Aucun élément nuisible détecté)

                  Clé(s) du Registre infectée(s):
                  (Aucun élément nuisible détecté)

                  Valeur(s) du Registre infectée(s):
                  (Aucun élément nuisible détecté)

                  Elément(s) de données du Registre infecté(s):
                  (Aucun élément nuisible détecté)

                  Dossier(s) infecté(s):
                  (Aucun élément nuisible détecté)

                  Fichier(s) infecté(s):
                  C:\Program Files\OUniAnsi.dll (Spyware.OnlineGames) -> Quarantined and deleted successfully.
                2. re,
                  les lignes qui sont en quarantaines dans malwarebyte's, dois je les supprimer ou les laisser ? Merci.
                3. Bonjour tout le monde, suis encore infecté par virtumonde ? merci d'avance pour votre réponse.
              9. tu as reessayé des cracks entre temps ?
                1. Salut,

                  excuse moi mais je ne sais pas ce que c'est des craks. je n'ai rien fais depuis la dernière fois.

              10. __________________________________________________________
                =>/!\ ATTENTION /!\ Le script qui suit a été écrit spécialement cet ordinateur,<=
                =>il est fort déconseillé de le transposer sur un autre ordinateur !<=====|
                ---------------------------------------------------------------


                Toujours avec toutes les protections désactivées, fais ceci :

                ▶ Ouvre le bloc-notes (Menu démarrer --> programmes --> accessoires --> bloc-notes)
                ▶ Copie/colle dans le bloc-notes ce qui entre les lignes ci dessous (sans les lignes) :

                ----------------------------------------------------------
                KillAll::

                Registry::
                [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                "LDM"=-
                "LogitechSoftwareUpdate"=-
                "swg"=-
                "IncrediMail"=-
                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                "ISUSScheduler"=-
                "SigmatelSysTrayApp"=-
                "LVCOMSX"=-
                "Adobe Reader Speed Launcher"=-
                "QuickTime Task"=-
                "iTunesHelper"=-
                [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
                "NoDrives"=-
                "NoDriveTypeAutoRun"=145
                [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
                "NoDrives"=-
                "NoDriveTypeAutoRun"=145
                [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
                "C:\Program Files\Messenger\msmsgs.exe"=-
                [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_NPF]
                [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_NPF]

                ------------------------------------------------------------------

                ▶ Enregistre ce fichier sur ton Bureau (et pas ailleurs !) sous le nom CFScript.txt
                ▶ Quitte le Bloc Notes

                ▶ Fais un glisser/déposer de ce fichier CFScript sur le fichier combofix

                ▶ Patiente le temps du scan. Le Bureau va disparaître à plusieurs reprises : c'est normal ! Ne touche à rien tant que le scan n'est pas terminé.
                ▶ Une fois le scan achevé, un rapport va s'afficher: poste son contenu.
                ▶ Si le fichier ne s'ouvre pas, il se trouve ici => C:\ComboFix.txt

                1. Salut Gen-hackman,
                  Le rapport après combofix, merci d'avance :

                  ComboFix 10-01-04.01 - Laurent 05/01/2010 8:30.2.2 - x86
                  Microsoft Windows XP Édition familiale 5.1.2600.3.1252.33.1036.18.1022.338 [GMT 1:00]
                  Lancé depuis: c:\documents and settings\Laurent\Bureau\ComboFix.exe
                  Commutateurs utilisés :: c:\documents and settings\Laurent\Bureau\CFScript.txt
                  AV: VirusKeeper 2009 Pro antivirus *On-access scanning disabled* (Updated) {165EE528-D666-4745-B14E-AA998BBEC191}
                  .

                  (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
                  .

                  .
                  ((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
                  .

                  -------\Legacy_NPF

                  ((((((((((((((((((((((((((((( Fichiers créés du 2009-12-05 au 2010-01-05 ))))))))))))))))))))))))))))))))))))
                  .

                  2010-01-03 16:12 . 2010-01-04 10:35 -------- d-----w- c:\program files\trend micro
                  2010-01-03 16:12 . 2010-01-03 16:12 -------- d-----w- C:\rsit
                  2010-01-03 14:36 . 2010-01-03 14:36 -------- d-----w- c:\documents and settings\David\Application Data\AskToolbar
                  2010-01-03 14:36 . 2010-01-03 14:37 -------- d-----w- c:\documents and settings\David\Local Settings\Application Data\AskToolbar
                  2010-01-02 09:58 . 2010-01-02 09:58 -------- d-----w- c:\documents and settings\Laurent\Application Data\TeamViewer
                  2010-01-02 09:58 . 2010-01-02 09:58 -------- d-----w- c:\documents and settings\Laurent\temp
                  2009-12-31 10:28 . 2009-12-31 10:29 -------- dc-h--w- c:\windows\ie8
                  2009-12-31 10:09 . 2007-12-24 16:37 138384 ----a-w- c:\windows\system32\drivers\tmcomm.sys
                  2009-12-31 10:08 . 2009-12-31 10:16 -------- d-----w- c:\documents and settings\Laurent\Application Data\HouseCall 6.6
                  2009-12-31 10:03 . 2009-12-31 10:05 -------- d-----w- c:\documents and settings\Laurent\Local Settings\Application Data\AskToolbar
                  2009-12-30 09:23 . 2009-12-30 09:23 37440 ----a-w- c:\windows\system32\drivers\pssdklbf.drv
                  2009-12-30 09:23 . 2009-12-30 09:23 30272 ----a-w- c:\windows\system32\drivers\pssdk31.drv
                  2009-12-30 09:14 . 2009-12-30 09:14 -------- d-----w- c:\documents and settings\David\Application Data\Canneverbe_Limited
                  2009-12-30 09:14 . 2009-12-30 09:14 -------- d-----w- c:\documents and settings\All Users\Application Data\Canneverbe Limited
                  2009-12-29 22:11 . 2009-12-29 22:12 -------- d-----w- c:\documents and settings\All Users\Application Data\Nero
                  2009-12-29 22:11 . 2009-12-29 22:11 -------- d-----w- c:\program files\Fichiers communs\Nero
                  2009-12-29 22:04 . 2009-12-29 22:04 -------- d-----w- c:\program files\Ask.com
                  2009-12-29 11:16 . 1998-04-24 18:09 368912 ----a-w- c:\windows\system32\Vbar332.dll
                  2009-12-29 11:16 . 1998-04-24 17:40 123664 ----a-w- c:\windows\system32\Msjint35.dll
                  2009-12-29 11:16 . 1998-04-24 17:40 407312 ----a-w- c:\windows\system32\Msrepl35.dll
                  2009-12-29 11:16 . 1998-04-24 17:40 252176 ----a-w- c:\windows\system32\Msrd2x35.dll
                  2009-12-29 11:16 . 1998-04-24 17:40 24848 ----a-w- c:\windows\system32\Msjter35.dll
                  2009-12-29 11:16 . 1998-04-24 17:40 1045776 ----a-w- c:\windows\system32\Msjet35.dll
                  2009-12-29 11:16 . 2009-12-29 11:22 -------- d-----w- c:\program files\Virtuosa
                  2009-12-28 15:55 . 2009-12-28 15:55 -------- d-----w- C:\Kill'em
                  2009-12-28 12:39 . 2009-12-28 12:39 -------- d-----w- c:\program files\List_Kill'em
                  2009-12-27 15:28 . 2009-12-27 15:44 -------- d-----w- C:\Lop SD
                  2009-12-27 12:32 . 2010-01-04 09:50 -------- d-----w- c:\program files\Ad-Remover
                  2009-12-26 13:57 . 2009-12-26 13:57 -------- d-----w- c:\documents and settings\Laurent\Application Data\Malwarebytes
                  2009-12-26 13:57 . 2009-12-30 13:55 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
                  2009-12-26 13:57 . 2009-12-26 13:57 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
                  2009-12-26 13:57 . 2009-12-30 13:54 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
                  2009-12-26 13:57 . 2010-01-02 16:59 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
                  2009-12-26 12:52 . 2009-12-26 12:54 -------- d-----w- c:\program files\BHODemon 2
                  2009-12-26 10:10 . 2009-12-26 11:31 -------- d-----w- C:\VundoFix Backups
                  2009-12-25 19:17 . 2009-12-25 19:17 -------- d-----w- c:\documents and settings\David\Application Data\MyPhoneExplorer
                  2009-12-25 19:17 . 2009-12-25 19:17 -------- d-----w- c:\program files\MyPhoneExplorer
                  2009-12-25 10:33 . 2008-03-21 12:57 14640 ------w- c:\windows\system32\spmsgXP_2k3.dll
                  2009-12-23 08:43 . 2002-07-17 08:05 16512 ----a-w- c:\windows\system32\drivers\ASPI32.SYS
                  2009-12-23 08:43 . 2001-03-17 21:34 22528 ----a-w- c:\windows\system32\WNASPI32.DLL
                  2009-12-23 08:43 . 2009-12-23 08:44 -------- d-----w- c:\program files\4Musics MP3 Bitrate Changer
                  2009-12-23 08:37 . 2009-02-03 17:01 364544 ----a-w- c:\windows\system32\MACDll.dll
                  2009-12-23 08:37 . 2009-01-19 17:39 246424 ----a-w- c:\windows\system32\unicows.dll
                  2009-12-23 08:37 . 2009-12-23 08:38 -------- d-----w- c:\program files\Monkey's Audio
                  2009-12-17 15:35 . 2009-12-17 15:35 -------- d-s---w- c:\documents and settings\NetworkService\Favoris
                  2009-12-16 16:34 . 2009-12-27 10:44 172 --sh--w- c:\windows\system32\bootrun.reg
                  2009-12-16 16:34 . 2009-12-27 09:47 457 --sh--w- c:\windows\system32\boothide.reg
                  2009-12-16 11:17 . 2009-12-29 22:17 -------- d-----w- c:\documents and settings\David\Application Data\vlc
                  2009-12-09 10:56 . 2009-12-09 10:56 -------- d-----w- c:\documents and settings\All Users\Application Data\3DVIA
                  2009-12-09 10:56 . 2009-12-09 10:56 -------- d-----w- c:\documents and settings\David\Local Settings\Application Data\3DVIA
                  2009-12-09 10:53 . 2007-07-19 17:14 3727720 ----a-w- c:\windows\system32\d3dx9_35.dll
                  2009-12-09 10:53 . 2006-09-28 15:05 2414360 ----a-w- c:\windows\system32\d3dx9_31.dll
                  2009-12-09 10:53 . 2009-12-09 10:53 -------- d-----w- c:\windows\Logs
                  2009-12-09 10:53 . 2009-12-09 10:53 -------- d-----w- c:\program files\Virtools

                  .
                  (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                  .
                  2009-12-30 09:13 . 2008-03-18 17:20 -------- d-----w- c:\program files\CDBurnerXP
                  2009-12-30 09:04 . 2005-12-27 16:31 -------- d-----w- c:\program files\Ahead
                  2009-12-29 22:11 . 2006-02-15 16:55 -------- d-----w- c:\program files\Nero
                  2009-12-29 21:13 . 2005-12-27 16:31 -------- d-----w- c:\program files\Fichiers communs\Ahead
                  2009-12-29 21:11 . 2009-06-29 14:19 -------- d-----w- c:\documents and settings\David\Application Data\dvdcss
                  2009-12-29 11:16 . 2005-11-05 17:35 -------- d--h--w- c:\program files\InstallShield Installation Information
                  2009-12-27 21:03 . 2007-06-28 12:47 -------- d-----w- c:\documents and settings\David\Application Data\gtk-2.0
                  2009-12-27 17:30 . 2008-12-28 09:53 -------- d-----w- c:\program files\Navilog1
                  2009-12-26 09:26 . 2009-11-12 16:05 -------- d-----w- c:\program files\Mozilla Firefox 3.6 Beta 2
                  2009-12-26 09:26 . 2009-11-02 11:02 -------- d-----w- c:\program files\Mozilla Firefox 3.6 Beta 1
                  2009-12-25 19:19 . 2006-12-12 15:50 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
                  2009-12-25 12:36 . 2009-12-02 19:36 -------- d-----w- c:\documents and settings\Laurent\Application Data\vlc
                  2009-12-25 10:34 . 2009-12-25 10:34 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_ggsemc_01007.Wdf
                  2009-12-25 10:33 . 2009-12-25 10:33 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
                  2009-12-23 08:42 . 2008-03-12 14:58 -------- d-----w- c:\documents and settings\David\Application Data\foobar2000
                  2009-12-23 08:39 . 2008-03-12 14:58 -------- d-----w- c:\program files\foobar2000
                  2009-12-22 21:16 . 2006-02-04 10:51 -------- d-----w- c:\documents and settings\David\Application Data\Apple Computer
                  2009-12-16 16:41 . 2008-01-06 16:58 -------- d-----w- c:\program files\DivX
                  2009-12-16 16:40 . 2009-10-17 16:11 -------- d-----w- c:\program files\Fichiers communs\DivX Shared
                  2009-12-16 07:07 . 2005-12-11 09:12 530984 ----a-w- c:\documents and settings\David\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
                  2009-12-16 07:05 . 2009-04-10 16:43 8224 ----a-w- c:\windows\system32\GDIPFONTCACHEV1.DAT
                  2009-12-14 19:16 . 2005-11-09 19:02 530984 ----a-w- c:\documents and settings\Laurent\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
                  2009-12-11 17:11 . 2004-08-20 10:24 592376 ----a-w- c:\windows\system32\perfh00C.dat
                  2009-12-11 17:11 . 2004-08-20 10:24 118714 ----a-w- c:\windows\system32\perfc00C.dat
                  2009-12-06 11:10 . 2008-12-07 19:38 -------- d-----w- c:\documents and settings\Laurent\Application Data\dvdcss
                  2009-12-05 12:14 . 2009-12-05 12:14 25512 ----a-w- c:\windows\system32\drivers\ggsemc.sys
                  2009-12-05 12:14 . 2009-12-05 12:14 13224 ----a-w- c:\windows\system32\drivers\ggflt.sys
                  2009-12-05 12:14 . 2009-12-05 12:14 1112288 ----a-w- c:\windows\system32\WdfCoInstaller01007.dll
                  2009-12-05 12:13 . 2009-12-02 09:12 -------- d-----w- c:\program files\Sony Ericsson
                  2009-12-02 10:51 . 2008-03-29 10:27 308628 ---ha-w- c:\windows\system32\mlfcache.dat
                  2009-12-02 10:47 . 2009-12-02 10:29 -------- d-----w- c:\documents and settings\David\Application Data\Dofus 2
                  2009-12-02 10:30 . 2009-12-02 10:30 -------- d-----w- c:\documents and settings\David\Application Data\Reg.C9ECCBDBA4E09304DEEFB106465BC17F6D6749B9.1
                  2009-12-02 10:30 . 2009-12-02 10:30 -------- d-----w- c:\documents and settings\David\Application Data\app
                  2009-12-02 10:29 . 2009-12-02 10:29 -------- d-----w- c:\documents and settings\David\Application Data\Dofus.C9ECCBDBA4E09304DEEFB106465BC17F6D6749B9.1
                  2009-12-02 09:48 . 2009-12-02 09:48 -------- d-----w- c:\program files\Dofus 2
                  2009-12-02 09:36 . 2009-12-02 09:36 -------- d-----w- c:\program files\Fichiers communs\MAGIX Shared
                  2009-12-02 09:36 . 2009-12-02 09:36 -------- d-----w- c:\program files\MAGIX
                  2009-12-02 09:31 . 2009-12-02 09:26 -------- d-----w- c:\documents and settings\David\Application Data\AVS4YOU
                  2009-12-02 09:27 . 2009-12-02 09:27 -------- d-----w- c:\documents and settings\All Users\Application Data\AVS4YOU
                  2009-12-02 09:26 . 2007-07-08 09:38 -------- d-----w- c:\program files\Fichiers communs\AVSMedia
                  2009-12-02 09:26 . 2009-12-02 09:26 -------- d-----w- c:\program files\AVS4YOU
                  2009-11-28 16:18 . 2009-05-13 18:25 1118 ----a-w- c:\documents and settings\Laurent\errorlog.tmp
                  2009-11-28 13:15 . 2009-06-24 17:08 664 ----a-w- c:\windows\system32\d3d9caps.dat
                  2009-11-27 17:45 . 2005-11-05 17:31 -------- d-----w- c:\program files\Java
                  2009-11-25 16:48 . 2007-05-29 18:04 -------- d-----w- c:\program files\Opera
                  2009-11-16 14:37 . 2009-01-24 14:00 -------- d-----w- c:\program files\Safari
                  2009-11-16 14:31 . 2009-11-16 14:30 -------- d-----w- c:\program files\iTunes
                  2009-11-16 14:31 . 2009-11-16 14:30 -------- d-----w- c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
                  2009-11-16 14:30 . 2009-11-16 14:30 -------- d-----w- c:\program files\iPod
                  2009-11-16 14:30 . 2007-08-12 16:05 -------- d-----w- c:\program files\Fichiers communs\Apple
                  2009-11-16 14:26 . 2009-11-16 14:25 -------- d-----w- c:\program files\QuickTime
                  2009-11-14 00:47 . 2009-11-14 00:47 90112 ----a-w- c:\windows\system32\dpl100.dll
                  2009-11-14 00:47 . 2009-11-14 00:47 856064 ----a-w- c:\windows\system32\divx_xx0c.dll
                  2009-11-14 00:47 . 2009-11-14 00:47 856064 ----a-w- c:\windows\system32\divx_xx07.dll
                  2009-11-14 00:47 . 2009-11-14 00:47 847872 ----a-w- c:\windows\system32\divx_xx0a.dll
                  2009-11-14 00:47 . 2009-11-14 00:47 843776 ----a-w- c:\windows\system32\divx_xx16.dll
                  2009-11-14 00:47 . 2009-11-14 00:47 839680 ----a-w- c:\windows\system32\divx_xx11.dll
                  2009-11-14 00:47 . 2009-11-14 00:47 696320 ----a-w- c:\windows\system32\DivX.dll
                  2009-11-13 19:41 . 2009-11-11 14:05 -------- d-----w- c:\program files\Zylom Games
                  2009-11-13 19:39 . 2009-11-13 19:36 -------- d-----w- c:\program files\Zumas Revenge! - Adventure
                  2009-11-13 19:31 . 2007-03-28 14:27 -------- d-----w- c:\program files\RealArcade
                  2009-11-11 14:05 . 2009-11-11 14:05 -------- d-----w- c:\documents and settings\Laurent\Application Data\Zylom
                  2009-11-10 15:58 . 2009-11-10 15:58 -------- d-----w- c:\documents and settings\All Users\Application Data\PhotoMail
                  2009-11-10 15:58 . 2009-11-10 15:58 -------- d-----w- c:\program files\PhotoMail Maker
                  2009-11-10 15:56 . 2005-11-09 19:44 -------- d-----w- c:\program files\IncrediMail
                  2009-11-09 16:07 . 2009-11-09 16:07 -------- d-----w- c:\program files\CFWebAdvancedU
                  2009-11-09 15:59 . 2009-03-27 10:33 -------- d-----w- c:\program files\Messenger Plus! Live
                  2009-10-29 07:42 . 2004-08-20 10:24 916480 ----a-w- c:\windows\system32\wininet.dll
                  2009-10-21 05:39 . 2004-08-20 10:24 75776 ----a-w- c:\windows\system32\strmfilt.dll
                  2009-10-21 05:39 . 2004-08-20 10:23 25088 ----a-w- c:\windows\system32\httpapi.dll
                  2009-10-20 16:20 . 2004-08-03 23:00 265728 ----a-w- c:\windows\system32\drivers\http.sys
                  2009-10-17 08:42 . 2009-10-17 08:42 1607184 ----a-w- c:\windows\system32\Aquarium Exotique.scr
                  2009-10-13 10:33 . 2004-08-20 10:23 271360 ----a-w- c:\windows\system32\oakley.dll
                  2009-10-12 13:39 . 2004-08-20 10:24 79872 ----a-w- c:\windows\system32\raschap.dll
                  2009-10-12 13:39 . 2004-08-20 10:24 150528 ----a-w- c:\windows\system32\rastls.dll
                  2009-10-11 03:17 . 2008-11-28 09:21 411368 ----a-w- c:\windows\system32\deploytk.dll
                  2009-08-11 05:50 . 2009-08-11 05:50 15098 ----a-w- c:\program files\license.rtf
                  2009-08-11 05:30 . 2009-08-11 05:30 4012328 ----a-w- c:\program files\opera.dll
                  2009-08-11 05:30 . 2009-08-11 05:30 121128 ----a-w- c:\program files\opera.exe
                  2009-08-11 05:26 . 2009-08-11 05:26 653419 ----a-w- c:\program files\encoding.bin
                  2009-07-16 13:13 . 2009-06-18 17:15 168 ----a-w- c:\program files\operaprefs_default.ini
                  2009-06-17 13:41 . 2009-06-17 13:41 3870 ----a-w- c:\program files\lngcode.txt
                  2008-06-09 09:17 . 2008-06-09 09:17 301 ----a-w- c:\program files\c3nform.vxml
                  2006-03-29 10:14 . 2002-12-08 18:04 108 ----a-w- c:\program files\Mess with MSN Messenger skins, nicknames, add-ons, bots and secrets.url
                  2006-03-29 10:14 . 2001-10-03 20:22 161 ----a-w- c:\program files\read1st.txt
                  2004-02-26 12:35 . 2004-02-26 12:35 7904 ----a-w- c:\program files\html40_entities.dtd
                  1999-12-09 09:19 . 2006-01-02 15:34 147456 ----a-w- c:\program files\Zip32.dll
                  .

                  ------- Sigcheck -------

                  [-] 2008-04-14 . 5158A1C542A355B3A67E59538BBD894D . 3200000 . . [6.00.2900.5512] . . c:\windows\explorer.exe
                  [-] 2008-04-14 . 5158A1C542A355B3A67E59538BBD894D . 3200000 . . [6.00.2900.5512] . . c:\windows\ServicePackFiles\i386\explorer.exe
                  [-] 2007-06-13 . D0288319660EDCFED07C7E74C4EA38A5 . 1037312 . . [6.00.2900.3156] . . c:\windows\$NtServicePackUninstall$\explorer.exe
                  [-] 2007-06-13 . B795475444D6D57A572C14B9E1A29839 . 1037312 . . [6.00.2900.3156] . . c:\windows\$hf_mig$\KB938828\SP2QFE\explorer.exe
                  [7] 2004-08-05 . 4C33E5B9A6197B6ED215F6CFBA0A2DAA . 1036288 . . [6.00.2900.2180] . . c:\windows\$NtUninstallKB938828$\explorer.exe
                  .
                  ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
                  .
                  .
                  *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
                  REGEDIT4

                  [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
                  2009-09-30 09:40 1182088 ----a-w- c:\program files\Ask.com\GenericAskToolbar.dll

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
                  "{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2009-09-30 1182088]

                  [HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
                  [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
                  [HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
                  [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]

                  [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
                  "{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2009-09-30 1182088]

                  [HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
                  [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
                  [HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
                  [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]

                  [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                  "Magentic"="c:\progra~1\Magentic\bin\Magentic.exe" [2006-11-19 319532]
                  "X'nBeep"="c:\program files\X'nBeep 1.1\XnBeep.exe" [2007-01-06 1067520]
                  "CursorXP"="c:\program files\CursorXP.exe" [2005-01-19 128000]
                  "RocketDock"="c:\program files\RocketDock\RocketDock.exe" [2007-03-18 630784]
                  "Google Update"="c:\documents and settings\Laurent\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-04-27 133104]
                  "Cld2000.exe"="c:\program files\Calendrier\Cld2000.exe" [2009-04-16 2993664]
                  "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-11-03 204288]

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                  "ISUSPM Startup"="c:\progra~1\FICHIE~1\INSTAL~1\UPDATE~1\isuspm.exe" [2005-02-16 221184]
                  "dla"="c:\windows\system32\dla\tfswctrl.exe" [2005-05-31 122941]
                  "LogitechVideoRepair"="c:\program files\Logitech\Video\ISStart.exe" [2005-06-08 458752]
                  "ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2006-02-09 344064]
                  "DrvIcon"="c:\program files\Vista Drive Icon\DrvIcon.exe" [2007-07-04 45056]
                  "VirusKeeper"="c:\program files\AxBx\VirusKeeper 2009 Pro\VirusKeeper.exe" [2009-09-22 3768688]
                  "AppleSyncNotifier"="c:\program files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-08-13 177440]
                  "StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-02-25 61440]
                  "LogitechVideoTray"="c:\program files\Logitech\Video\LogiTray.exe" [2005-06-08 217088]
                  "Adobe ARM"="c:\program files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
                  "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]

                  [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
                  "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

                  c:\documents and settings\David\Menu D‚marrer\Programmes\D‚marrage\
                  RocketDock.lnk - c:\windows\BricoPacks\Crystal Clear\RocketDock\RocketDock.exe [2006-5-14 344064]
                  UberIcon.lnk - c:\windows\BricoPacks\Crystal Clear\UberIcon\UberIcon Manager.exe [2006-2-5 180224]
                  Y'z Shadow.lnk - c:\windows\BricoPacks\Crystal Clear\YzShadow\YzShadow.exe [2002-9-30 131072]
                  Y'z Toolbar.lnk - c:\windows\BricoPacks\Crystal Clear\YzToolbar\YzToolBar.exe [2002-9-29 90112]

                  c:\documents and settings\David\Menu D‚marrer\Programmes\D‚marrage\
                  RocketDock.lnk - c:\windows\BricoPacks\Crystal Clear\RocketDock\RocketDock.exe [2006-5-14 344064]
                  UberIcon.lnk - c:\windows\BricoPacks\Crystal Clear\UberIcon\UberIcon Manager.exe [2006-2-5 180224]
                  Y'z Shadow.lnk - c:\windows\BricoPacks\Crystal Clear\YzShadow\YzShadow.exe [2002-9-30 131072]
                  Y'z Toolbar.lnk - c:\windows\BricoPacks\Crystal Clear\YzToolbar\YzToolBar.exe [2002-9-29 90112]

                  c:\documents and settings\David\Menu D‚marrer\Programmes\D‚marrage\
                  RocketDock.lnk - c:\windows\BricoPacks\Crystal Clear\RocketDock\RocketDock.exe [2006-5-14 344064]
                  UberIcon.lnk - c:\windows\BricoPacks\Crystal Clear\UberIcon\UberIcon Manager.exe [2006-2-5 180224]
                  Y'z Shadow.lnk - c:\windows\BricoPacks\Crystal Clear\YzShadow\YzShadow.exe [2002-9-30 131072]
                  Y'z Toolbar.lnk - c:\windows\BricoPacks\Crystal Clear\YzToolbar\YzToolBar.exe [2002-9-29 90112]

                  c:\documents and settings\Laurent\Menu D‚marrer\Programmes\D‚marrage\
                  DateInTray.lnk - c:\program files\DateInTray\DateInTray.exe [2005-12-12 78848]
                  RocketDock.lnk - c:\windows\BricoPacks\Crystal Clear\RocketDock\RocketDock.exe [2006-5-14 344064]
                  Y'z Toolbar.lnk - c:\windows\BricoPacks\Crystal Clear\YzToolbar\YzToolBar.exe [2002-9-29 90112]

                  c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
                  hp psc 1000 series.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe [2003-4-6 147456]
                  hpoddt01.exe.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe [2003-4-6 28672]
                  WiFi Station.lnk - c:\program files\Hercules\WiFi Station\WifiStation.exe [2009-10-8 654336]

                  c:\documents and settings\David\Menu D‚marrer\Programmes\D‚marrage\
                  RocketDock.lnk - c:\windows\BricoPacks\Crystal Clear\RocketDock\RocketDock.exe [2006-5-14 344064]
                  UberIcon.lnk - c:\windows\BricoPacks\Crystal Clear\UberIcon\UberIcon Manager.exe [2006-2-5 180224]
                  Y'z Shadow.lnk - c:\windows\BricoPacks\Crystal Clear\YzShadow\YzShadow.exe [2002-9-30 131072]
                  Y'z Toolbar.lnk - c:\windows\BricoPacks\Crystal Clear\YzToolbar\YzToolBar.exe [2002-9-29 90112]

                  [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
                  "{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]

                  [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
                  @="Driver"

                  [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
                  2009-10-28 19:21 141600 ----a-w- c:\program files\iTunes\iTunesHelper.exe

                  [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Magentic]
                  2006-11-19 12:23 319532 ----a-w- c:\progra~1\Magentic\bin\Magentic.exe

                  [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mxomssmenu]
                  2007-09-06 12:53 169264 ----a-w- c:\program files\Maxtor\OneTouch Status\MaxMenuMgr.exe

                  [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
                  "LogitechVideoTray"=c:\program files\Logitech\Video\LogiTray.exe
                  "QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime

                  [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
                  "DisableMonitoring"=dword:00000001

                  [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
                  "DisableMonitoring"=dword:00000001

                  [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
                  "DisableMonitoring"=dword:00000001

                  [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
                  "EnableFirewall"= 0 (0x0)

                  [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
                  "%windir%\\system32\\sessmgr.exe"=
                  "c:\\Program Files\\IncrediMail\\bin\\IMApp.exe"=
                  "c:\\Program Files\\IncrediMail\\bin\\IncMail.exe"=
                  "c:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe"=
                  "c:\\Documents and Settings\\Laurent\\Menu Démarrer\\Programmes\\IncrediMail\\bin\\ImpCnt.exe"=
                  "c:\\Program Files\\Messenger\\msmsgs.exe"=
                  "c:\\Documents and Settings\\Laurent\\Menu Démarrer\\Programmes\\IncrediMail\\bin\\ImLc.exe"=
                  "c:\\Documents and Settings\\Laurent\\Menu Démarrer\\Programmes\\IncrediMail\\bin\\ImPackr.exe"=
                  "c:\\Program Files\\Magentic\\bin\\MgImp.exe"=
                  "c:\\Program Files\\Magentic\\bin\\Magentic.exe"=
                  "c:\\Program Files\\Magentic\\bin\\MgApp.exe"=
                  "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
                  "c:\\Documents and Settings\\Laurent\\Menu Démarrer\\Programmes\\IncrediMail\\bin\\IncrediMail_Install.exe"=
                  "c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
                  "c:\\Program Files\\Codemasters\\Worms 4 Mayhem Demo\\Worms 4 Mayhem Demo.exe"=
                  "c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
                  "c:\\Program Files\\Commandos II\\comm2.exe"=
                  "c:\\Program Files\\The All-Seeing Eye\\eye.exe"=
                  "c:\\Program Files\\Opera\\Opera.exe"=
                  "c:\\WINDOWS\\system32\\dpvsetup.exe"=
                  "c:\\WINDOWS\\system32\\java.exe"=
                  "c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
                  "c:\\Program Files\\SopCast\\SopCast.exe"=
                  "c:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
                  "c:\\Documents and Settings\\David\\Application Data\\PowerChallenge\\PowerSoccer\\PowerSoccer.exe"=
                  "c:\\Program Files\\Pinnacle\\VideoSpin\\Programs\\RM.exe"=
                  "c:\\Program Files\\Pinnacle\\VideoSpin\\Programs\\PMSRegisterFile.exe"=
                  "c:\\Program Files\\Pinnacle\\VideoSpin\\Programs\\umi.exe"=
                  "c:\\Program Files\\Pinnacle\\VideoSpin\\Programs\\VideoSpin.exe"=
                  "c:\\WINDOWS\\pchealth\\helpctr\\binaries\\helpctr.exe"=
                  "c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
                  "c:\\Program Files\\Mindscape\\Mission Président - Geo-Political Simulator\\MISSION.EXE"=
                  "c:\\Program Files\\Ivicam\\backsurvey.exe"=
                  "c:\\Program Files\\Icecast2 Win32\\Icecast2win.exe"=
                  "c:\\Program Files\\SHOUTcast\\sc_serv.exe"=
                  "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
                  "c:\\Program Files\\QuickTime\\QuickTimePlayer.exe"=
                  "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
                  "c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
                  "c:\\WINDOWS\\system32\\rtcshare.exe"=
                  "c:\\Program Files\\NetMeeting\\conf.exe"=
                  "c:\\Program Files\\iTunes\\iTunes.exe"=
                  "c:\\Program Files\\Sony Ericsson\\Update Service\\Update Service.exe"=
                  "c:\\WINDOWS\\system32\\tftp.exe"=

                  R2 MSSQL$RADIONOMY536765;SQL Server (RADIONOMY536765);c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [27/05/2009 02:27 29262680]
                  R2 vkservice;VirusKeeper antivirus/antispyware;c:\program files\AxBx\VirusKeeper 2009 Pro\vk_service.exe [22/05/2008 14:27 1119576]
                  S2 gupdate1c981f2ac729e12;Google Update Service (gupdate1c981f2ac729e12);c:\program files\Google\Update\GoogleUpdate.exe [29/01/2009 10:19 133104]
                  S3 ASPI;Advanced SCSI Programming Interface Driver;c:\windows\system32\drivers\ASPI32.SYS [23/12/2009 09:43 16512]
                  S3 DCamUSBUVT;ICM532A;c:\windows\system32\drivers\usbuvt.sys [11/11/2005 10:13 95232]
                  S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\drivers\ggflt.sys [05/12/2009 13:14 13224]
                  S3 maconfservice;Ma-Config Service;c:\program files\ma-config.com\maconfservice.exe [23/09/2009 13:50 238960]
                  S3 PsSdk31;PsSdk31;c:\windows\system32\drivers\pssdk31.drv [30/12/2009 10:23 30272]
                  S3 PsSdkLBF;PsSdkLBF;c:\windows\system32\drivers\pssdklbf.drv [30/12/2009 10:23 37440]

                  [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{E4066320-E4AE-11CF-B1B0-00AA00BBAD66}]
                  2009-03-08 03:32 128512 ----a-w- c:\windows\system32\advpack.dll
                  .
                  Contenu du dossier 'Tâches planifiées'

                  2009-12-28 c:\windows\Tasks\AppleSoftwareUpdate.job
                  - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]

                  2010-01-04 c:\windows\Tasks\FRU Task 2003-04-06 08:52ewlett-Packard2003-04-06 08:52p psc 1200 series5E771253C1676EBED677BF361FDFC537825E15B8167816979.job
                  - c:\program files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe [2003-04-05 23:52]

                  2010-01-05 c:\windows\Tasks\GlaryInitialize.job
                  - c:\program files\Glary Utilities\initialize.exe [2009-02-21 16:10]

                  2010-01-05 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
                  - c:\program files\Google\Update\GoogleUpdate.exe [2009-01-29 09:19]

                  2010-01-05 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
                  - c:\program files\Google\Update\GoogleUpdate.exe [2009-01-29 09:19]

                  2010-01-02 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2328322012-3734155301-851506153-1006Core.job
                  - c:\documents and settings\Laurent\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-04-27 09:17]

                  2010-01-05 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2328322012-3734155301-851506153-1006UA.job
                  - c:\documents and settings\Laurent\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-04-27 09:17]

                  2010-01-04 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2328322012-3734155301-851506153-1007Core.job
                  - c:\documents and settings\David\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-12-06 18:05]

                  2010-01-05 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2328322012-3734155301-851506153-1007UA.job
                  - c:\documents and settings\David\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-12-06 18:05]

                  2005-11-10 c:\windows\Tasks\Rappel d'abonnement 1 auprès de l'ISP.job
                  - c:\windows\system32\OOBE\oobebaln.exe [2004-08-20 02:34]

                  2010-01-05 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
                  - c:\program files\Ask.com\UpdateTask.exe [2009-09-30 09:40]
                  .
                  .
                  ------- Examen supplémentaire -------
                  .
                  uStart Page = hxxp://mystart.incredimail.com/
                  uSearchMigratedDefaultURL = hxxp://google.cherche.us/Result.php?client=pub-0420647136319153&cof=GIMP%3A009900%3BT%3A000000%3BALC%3A551a8b%3BGFNT%3AB7B7B7%3BLC%3A2200cc%3BBGC%3AFFFFFF%3BVLC%3A551a8b%3BGALT%3A008B45%3BFORID%3A11%3BDIV%3A%23FFFFF0%3B&ie=ISO-8859-1&q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
                  uSearch Page =
                  uInternet Connection Wizard,ShellNext = hxxp://www.dell.fr/myway
                  uInternet Settings,ProxyOverride = localhost;*.local
                  uSearchURL,(Default) = hxxp://www.cherche.us/keyword/%s
                  IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
                  IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
                  IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
                  IE: Recherche avec cherche.us - c:\documents and settings\Laurent\scriptjava.html
                  Trusted Zone: chat-land.org
                  Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
                  DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
                  DPF: {09CC593B-E8A9-4491-927D-A3E33534DDD4} - hxxp://m6video.m6.fr/1click/install/files/installer2.cab
                  DPF: {1F83CD9E-505E-4F87-BECE-0832A763E36F} - hxxp://www.mypixmania.com/fr/fr/importer/MypixUploader.cab
                  DPF: {3a4f9191-65a8-11d5-85c1-0001023952c1} - hxxp://www.3dfunchal.com/resources/te/TE.cab
                  DPF: {4BFD075D-C36E-4F28-BB0A-5D472795197A} - hxxp://www.powerchallenge.com/applet/PowerLoader.cab
                  DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} - hxxp://game08.zylom.com/activex/zylomgamesplayer.cab
                  DPF: {DFB5BCF1-06AE-4ABB-BFA8-1E228F41C50A} - hxxp://www.bobtv.fr/download/cfweb_www.bobtv.fr-download_instmodule.exe
                  DPF: {F8C5C0F1-D884-43EB-A5A0-9E1C4A102FA8} - hxxps://secure.gopetslive.com/dev/GoPetsWeb.cab
                  FF - ProfilePath - c:\documents and settings\Laurent\Application Data\Mozilla\Firefox\Profiles\nhizwkb4.default\
                  FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
                  FF - prefs.js: browser.search.selectedEngine - Google
                  FF - prefs.js: browser.startup.homepage - hxxp://mystart.incredimail.com/
                  FF - prefs.js: keyword.URL - hxxp://mystart.incredimail.com/?loc=PMXMAS09FFAB&search=
                  FF - plugin: c:\documents and settings\All Users\Application Data\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll
                  FF - plugin: c:\documents and settings\Laurent\Local Settings\Application Data\Google\Update\1.2.183.13\npGoogleOneClick8.dll
                  FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
                  FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
                  FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
                  FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
                  FF - plugin: c:\program files\ma-config.com\nphardwaredetection.dll
                  FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
                  FF - plugin: c:\program files\Mozilla Firefox 3 Beta 5\plugins\np32dsw.dll
                  FF - plugin: c:\program files\Mozilla Firefox 3 Beta 5\plugins\npdeploytk.dll
                  FF - plugin: c:\program files\Mozilla Firefox 3 Beta 5\plugins\npdivx32.dll
                  FF - plugin: c:\program files\Mozilla Firefox 3 Beta 5\plugins\npDivxPlayerPlugin.dll
                  FF - plugin: c:\program files\Mozilla Firefox 3 Beta 5\plugins\npgcplug.dll
                  FF - plugin: c:\program files\Mozilla Firefox 3 Beta 5\plugins\NPOFFICE.DLL
                  FF - plugin: c:\program files\Mozilla Firefox 3 Beta 5\plugins\nppdf32.dll
                  FF - plugin: c:\program files\Mozilla Firefox 3 Beta 5\plugins\nppl3260.dll
                  FF - plugin: c:\program files\Mozilla Firefox 3 Beta 5\plugins\npqtplugin.dll
                  FF - plugin: c:\program files\Mozilla Firefox 3 Beta 5\plugins\npqtplugin2.dll
                  FF - plugin: c:\program files\Mozilla Firefox 3 Beta 5\plugins\npqtplugin3.dll
                  FF - plugin: c:\program files\Mozilla Firefox 3 Beta 5\plugins\npqtplugin4.dll
                  FF - plugin: c:\program files\Mozilla Firefox 3 Beta 5\plugins\npqtplugin5.dll
                  FF - plugin: c:\program files\Mozilla Firefox 3 Beta 5\plugins\npqtplugin6.dll
                  FF - plugin: c:\program files\Mozilla Firefox 3 Beta 5\plugins\npqtplugin7.dll
                  FF - plugin: c:\program files\Mozilla Firefox 3 Beta 5\plugins\nprjplug.dll
                  FF - plugin: c:\program files\Mozilla Firefox 3 Beta 5\plugins\nprpjplug.dll
                  FF - plugin: c:\program files\Mozilla Firefox 3 Beta 5\plugins\npyaxmpb.dll
                  FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
                  FF - plugin: c:\program files\Mozilla Firefox\plugins\npicdclient.dll
                  FF - plugin: c:\program files\Mozilla Firefox\plugins\npmozax.dll
                  FF - plugin: c:\program files\Mozilla Firefox\plugins\npredoute.dll
                  FF - plugin: c:\program files\Mozilla Firefox\plugins\npzylomgamesplayer.dll
                  FF - plugin: c:\program files\Opera\program\plugins\npgcplug.dll
                  FF - plugin: c:\program files\Opera\program\plugins\npmio.dll
                  FF - plugin: c:\program files\Opera\program\plugins\npqtplugin8.dll
                  FF - plugin: c:\program files\Real\RealArcade\Plugins\Mozilla\npracplug.dll
                  FF - plugin: c:\program files\Virtools\3D Life Player\npvirtools.dll
                  FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
                  FF - plugin: c:\windows\system32\Rawflow\npicdclient.dll
                  FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

                  ---- PARAMETRES FIREFOX ----
                  FF - user.js: yahoo.homepage.dontask - truec:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDCE08D86A-A41A-410A-943C-13BABB7DC474", "AllAccess");
                  c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDA9EDC9ED-603A-4F3F-BBEA-59C8853A3236", "AllAccess");
                  c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID90D10942-D952-4863-9DD6-A2BDBBAD456E", "AllAccess");
                  c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID0ECEE744-7B69-4912-AB91-AE76D61ECB04", "AllAccess");
                  c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDF25635B2-1AB9-47B5-88D1-8877B22C86DE", "AllAccess");
                  c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID27B7F812-4159-45B9-A389-B7A118A58DE4", "AllAccess");
                  c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDF849DF29-393B-4F8B-99D1-117A70D66FC7", "AllAccess");
                  c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDBF1E9C3D-637C-4171-BD12-28A7360B879A", "AllAccess");
                  c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDDE1C0601-7947-4D7F-A6E5-E68BF6BA1E37", "AllAccess");
                  c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID4EA0DCCE-4D98-4876-9C6A-E5C563D0820A", "AllAccess");
                  c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID446462BA-2AAD-4C88-BC63-5210E2F31465", "AllAccess");
                  c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID0862E368-A40E-4E55-83EB-FBC5571BABA4", "AllAccess");
                  c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDD2A96E3C-FFB3-4D38-9AC3-B127527BEA35", "AllAccess");
                  c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID4B05B39A-9DDC-4650-A7F8-D5B134E5FFE5", "AllAccess");
                  c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDC8E2574A-7BCE-4B93-A22E-61831DFD6DB8", "AllAccess");
                  c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID659796C0-8B5D-48D7-A4EB-7E6874E26274", "AllAccess");
                  c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID78071AB5-E729-414E-8D02-9C1D034F82E7", "AllAccess");
                  c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDCC3F71E1-17F3-4C5B-997D-44CA56943197", "AllAccess");
                  c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDE67D5C78-B2D4-4BA0-8D69-1C7AF4BB08B5", "AllAccess");
                  c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDFC5F3D7A-D321-412C-8A5D-9AD0C8041941", "AllAccess");
                  c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID6EC5CD16-81BC-4515-9EDD-9265C906F56E", "AllAccess");
                  c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID67CFB2C5-E491-4395-977B-CD45E4124655", "AllAccess");
                  c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID73600569-52E6-4760-8BAB-B68202937D98", "AllAccess");
                  c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDB02EBD42-6885-401A-9389-E089F7DDC872", "AllAccess");
                  c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDBAE5CB8C-4075-4743-B2E4-78DA8D8CDC64", "AllAccess");
                  c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID28B07B04-DA99-4FD3-BF27-4972F2B8142B", "AllAccess");
                  c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID0D53448F-D12B-4102-8CE2-697DAE8D6643", "AllAccess");
                  c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDE3266A47-A141-47B8-AAA8-5F16FB4F8CCD", "AllAccess");
                  c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDB33AB7AF-76D7-4B1C-B709-5D6BF9E7B1C7", "AllAccess");
                  c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID153B7451-0BB5-4B37-95C0-44D89E2F1F2B", "AllAccess");
                  c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID3BBE8E21-0D3D-4BAA-AC6F-C7BCEF750849", "AllAccess");
                  c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID9B5B4F2D-A7D9-4329-B0FE-92B301A8CAAD", "AllAccess");
                  c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDA5C42921-8CD0-4924-97C3-01B5B0610BC6", "AllAccess");
                  c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID06969252-F90F-4CF2-9074-33772EB64859", "AllAccess");
                  c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDFBF37655-1236-4C0D-96C5-F94E1724841B", "AllAccess");
                  c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDC1A3F035-B68F-4B2B-9FD5-E36DAAAF26DD", "AllAccess");
                  c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID368F3685-543E-4812-9FDE-96E097E453FC", "AllAccess");
                  c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID43969873-56AA-4113-84CB-4AB2AEB9AA31", "AllAccess");
                  c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDA205DD80-63D4-4E41-B785-26EC3D90B97B", "AllAccess");
                  c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID068D43E7-7551-4A2F-AE96-4A38A9AD1953", "AllAccess");
                  c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDF443E9CB-9EEC-456E-8AE7-F3102D5CD47D", "AllAccess");
                  c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDE36A7B16-645D-4261-BFF8-3A7E69C5F7A5", "AllAccess");
                  c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID379805E3-E0E2-40DC-B51B-6DC1AE5802AA", "AllAccess");
                  c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDF6240D69-A06D-44A1-8003-8496CCEF2C53", "AllAccess");
                  c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID26C3113D-5A71-4F1B-A2CB-BE59E1279DDA", "AllAccess");
                  c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID92B97F2B-7565-4CE9-9AC7-0598DFD731F8", "AllAccess");
                  c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID2AA5E7CF-9696-42F0-B76A-8655296EADF2", "AllAccess");
                  c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID0AAACE0B-ACEF-4781-83F4-BFB52EEC995A", "AllAccess");
                  c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID0D56FF58-A39D-4E8C-A40B-2E3711251772", "AllAccess");
                  c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID946121C2-11F1-49DD-A7E3-CF793DE827A4", "AllAccess");
                  c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDB853303D-1BAB-43F3-9D7D-101D0DA8E7A5", "AllAccess");
                  c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID9E578247-FE29-4F8C-8202-A24A5688CF2A", "AllAccess");
                  c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID6D065A8F-FFC0-4A0F-B863-1D724B8C786B", "AllAccess");
                  c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID4451D291-6940-42CE-9D3C-CA1D4C96549C", "AllAccess");
                  c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID064B722D-079D-4EBB-B3CF-9FCBF64FFF5D", "AllAccess");
                  c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID38F8AB0F-5DFB-43D9-889E-8717CC4AB59B", "AllAccess");
                  c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID4EC68CD1-0EF1-4CB9-9EF1-3D64AB266149", "AllAccess");
                  c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID44F96B27-CFAD-41E1-83A1-6B28040C3BDE", "AllAccess");
                  .
                  - - - - ORPHELINS SUPPRIMES - - - -

                  AddRemove-Ask Toolbar_is1 - c:\program files\AskBarDis\unins000.exe
                  AddRemove-GamesBar - c:\program files\GamesBar\uninst.exe
                  AddRemove-ViewpointMediaPlayer - c:\program files\Viewpoint\Viewpoint Experience Technology\mtsAxInstaller.exe
                  AddRemove-WinPcapInst - c:\program files\WinPcap\uninstall.exe

                  **************************************************************************

                  catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                  Rootkit scan 2010-01-05 08:50
                  Windows 5.1.2600 Service Pack 3 NTFS

                  Recherche de processus cachés ...

                  Recherche d'éléments en démarrage automatique cachés ...

                  Recherche de fichiers cachés ...

                  Scan terminé avec succès
                  Fichiers cachés: 0

                  **************************************************************************

                  [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PsSdk31]
                  "ImagePath"="\??\c:\windows\system32\Drivers\pssdk31.drv"

                  [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PsSdkLBF]
                  "ImagePath"="\??\c:\windows\system32\Drivers\pssdklbf.drv"
                  .
                  --------------------- CLES DE REGISTRE BLOQUEES ---------------------

                  [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø•€|ÿÿÿÿ•€|ù•9~*]
                  "C040110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
                  .
                  --------------------- DLLs chargées dans les processus actifs ---------------------

                  - - - - - - - > 'winlogon.exe'(1032)
                  c:\windows\system32\Ati2evxx.dll

                  - - - - - - - > 'explorer.exe'(3232)
                  c:\program files\RocketDock\RocketDock.dll
                  c:\windows\system32\ntshrui.dll
                  c:\program files\CurXP0.dll
                  c:\windows\system32\NETSHELL.dll
                  c:\windows\system32\credui.dll
                  c:\windows\system32\eappprxy.dll
                  c:\windows\system32\webcheck.dll
                  c:\windows\system32\stobject.dll
                  c:\windows\system32\WPDShServiceObj.dll
                  c:\windows\system32\PortableDeviceTypes.dll
                  c:\windows\system32\PortableDeviceApi.dll
                  c:\progra~1\SPYBOT~1\SDHelper.dll
                  c:\program files\Fichiers communs\Adobe\Acrobat\ActiveX\PDFShell.FRA
                  c:\program files\Microsoft Office\OFFICE11\msohev.dll
                  c:\program files\Fichiers communs\Microsoft Shared\OFFICE11\MSOXEV.DLL
                  c:\program files\Fichiers communs\Adobe\Acrobat\ActiveX\PDFShell.dll
                  c:\progra~1\ACEMEG~1\SystemS\avimszh.dll
                  c:\progra~1\ACEMEG~1\SystemS\avizlib.dll
                  c:\progra~1\ACEMEG~1\SystemS\Qpeg32.dll
                  c:\progra~1\ACEMEG~1\SystemS\ASUS\asusasv1.dll
                  c:\progra~1\ACEMEG~1\SystemS\ASUS\asusasv2.dll
                  c:\progra~1\ACEMEG~1\SystemS\Aware\icmw_32.dll
                  c:\progra~1\ACEMEG~1\SystemS\BROOKT~1\btvvc32.drv
                  c:\progra~1\ACEMEG~1\SystemS\Core\COREPN~1.DLL
                  .
                  ------------------------ Autres processus actifs ------------------------
                  .
                  c:\windows\system32\Ati2evxx.exe
                  c:\program files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                  c:\windows\system32\Ati2evxx.exe
                  c:\program files\Bonjour\mDNSResponder.exe
                  c:\windows\system32\drivers\CDAC11BA.EXE
                  c:\program files\Java\jre6\bin\jqs.exe
                  c:\program files\Google\Update\1.2.183.13\GoogleCrashHandler.exe
                  c:\program files\Maxtor\Sync\SyncServices.exe
                  c:\program files\Fichiers communs\Nero\Nero BackItUp 4\NBService.exe
                  c:\program files\CDBurnerXP\NMSAccessU.exe
                  c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                  c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
                  c:\program files\Windows Media Player\WMPNetwk.exe
                  c:\windows\system32\SearchIndexer.exe
                  c:\windows\system32\wscntfy.exe
                  c:\program files\Canon\CAL\CALMAIN.exe
                  c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
                  c:\windows\system32\LVComsX.exe
                  c:\progra~1\Magentic\bin\MgApp.exe
                  c:\program files\Logitech\Video\FxSvr2.exe
                  c:\program files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
                  c:\program files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
                  c:\program files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
                  c:\program files\AxBx\VirusKeeper 2009 Pro\vk_watchop.exe
                  .
                  **************************************************************************
                  .
                  Heure de fin: 2010-01-05 09:06:35 - La machine a redémarré
                  ComboFix-quarantined-files.txt 2010-01-05 08:06
                  ComboFix2.txt 2009-12-27 12:11

                  Avant-CF: 75 408 936 960 octets libres
                  Après-CF: 77 320 470 528 octets libres

                  - - End Of File - - 4D03680E2ED4D2EDA5FE2B7B3A7C6919
              11. hello desinstalle ASToolbar , Ask.com puis

                Télécharge OTL de OLDTimer

                ▶ enregistre le sur ton Bureau.

                ▶ Double clic ( pour vista => clic droit "executer en tant qu'administrateur") sur OTL.exe pour le lancer.

                ▶ Coche les 2 cases Lop et Purity

                ▶ Coche la case devant scan all users

                ▶ règle-le sur "60 Days"

                ▶ dans la colonne de gauche , mets tout sur all

                ne modifie pas ceci :

                "files created whithin" et "files modified whithin"


                ▶Clic sur Run Scan.

                A la fin du scan, le Bloc-Notes va s'ouvrir avec le rapport (OTL.txt).

                Ce fichier est sur ton Bureau (en général C:\Documents and settings\le_nom_de_ta_session\OTL.txt)

                ▶▶▶ NE LE POSTE PAS SUR LE FORUM

                Pour me le transmettre clique sur ce lien : http://www.cijoint.fr/

                ▶ Clique sur Parcourir et cherche le fichier ci-dessus.

                ▶ Clique sur Ouvrir.

                ▶ Clique sur "Cliquez ici pour déposer le fichier".

                Un lien de cette forme :

                http://www.cijoint.fr/cjlink.php?file=cjge368/cijSKAP5fU.txt

                est ajouté dans la page.

                ▶ Copie ce lien dans ta réponse.

                ▶▶ Tu feras la meme chose avec le "Extra.txt".
                1. re,

                  je n'ai pas astoolbar, ni ask.com donc pas de désinstallation je te poste rapport OTL txt :

                  http://www.cijoint.fr/cjlink.php?file=cj201001/cijoaD1xc3.txt

                  Par contre je n'ai pas de fichier Extra.txt comme tu me le demande.

                  Merci d'avance.
                2. Salut gen-hackman, excuse moi j'avais chercher dans les programmes. Effectivement j'avais bien Ask.com dans programme files. Je l'ai supprimé et j'ai refais la manip avec OTL voilà le nouveau rapport :

                  http://www.cijoint.fr/cjlink.php?file=cj201001/cij7b5uK1A.txt

                  Merci beaucoup
                3. Salut gen hackman, voilà le rapport :

                  All processes killed
                  ========== PROCESSES ==========
                  No active process named explorer.exe was found!
                  No active process named iexplore.exe was found!
                  No active process named firefox.exe was found!
                  No active process named msnmsgr.exe was found!
                  No active process named Teatimer.exe was found!
                  ========== OTL ==========
                  Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{14f0d511-36a2-41ca-ae01-ba4f87282c97} deleted successfully.
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{14f0d511-36a2-41ca-ae01-ba4f87282c97}\ deleted successfully.
                  C:\Program Files\SHOUTcast Radio Toolbar\shoutcasttb.dll moved successfully.
                  Unable to set value : HKU\S-1-5-21-2328322012-3734155301-851506153-1006\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page_bak| /E!
                  Prefs.js: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}:6.0.01 removed from extensions.enabledItems
                  Prefs.js: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}:6.0.02 removed from extensions.enabledItems
                  Prefs.js: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}:6.0.03 removed from extensions.enabledItems
                  Prefs.js: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}:6.0.05 removed from extensions.enabledItems
                  Prefs.js: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13 removed from extensions.enabledItems
                  Prefs.js: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}:6.0.14 removed from extensions.enabledItems
                  Prefs.js: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}:6.0.15 removed from extensions.enabledItems
                  Prefs.js: "Ask" removed from browser.search.order.1
                  Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B56A7D7D-6927-48C8-A975-17DF180C71AC}\ deleted successfully.
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B56A7D7D-6927-48C8-A975-17DF180C71AC}\ deleted successfully.
                  Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}\ deleted successfully.
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ deleted successfully.
                  Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} deleted successfully.
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}\ not found.
                  Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{D4027C7F-154A-4066-A1AD-4243D8127440} deleted successfully.
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ not found.
                  Registry value HKEY_USERS\S-1-5-21-2328322012-3734155301-851506153-1006\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{0457331D-8CA6-4F97-9C26-6A9EF2B2DBA8} deleted successfully.
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0457331D-8CA6-4F97-9C26-6A9EF2B2DBA8}\ deleted successfully.
                  File C:\Program Files\SHOUTcast Radio Toolbar\shoutcasttb.dll not found.
                  Registry value HKEY_USERS\S-1-5-21-2328322012-3734155301-851506153-1006\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D4027C7F-154A-4066-A1AD-4243D8127440} deleted successfully.
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ not found.
                  Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDrives deleted successfully.
                  Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\DisableRegistryTools deleted successfully.
                  Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\Recherche avec cherche.us\ deleted successfully.
                  C:\Documents and Settings\Laurent\scriptjava.html moved successfully.
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{2D663D1A-8670-49D9-A1A5-4C56B4E14E84}\ deleted successfully.
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2D663D1A-8670-49D9-A1A5-4C56B4E14E84}\ not found.
                  Starting removal of ActiveX control {00000055-9980-0010-8000-00AA00389B71}
                  C:\WINDOWS\Downloaded Program Files\fhg.inf moved successfully.
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{00000055-9980-0010-8000-00AA00389B71}\ deleted successfully.
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00000055-9980-0010-8000-00AA00389B71}\ not found.
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{00000055-9980-0010-8000-00AA00389B71}\ not found.
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00000055-9980-0010-8000-00AA00389B71}\ not found.
                  Starting removal of ActiveX control {09CC593B-E8A9-4491-927D-A3E33534DDD4}
                  Registry error reading value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{09CC593B-E8A9-4491-927D-A3E33534DDD4}\DownloadInformation\\INF .
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{09CC593B-E8A9-4491-927D-A3E33534DDD4}\ deleted successfully.
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{09CC593B-E8A9-4491-927D-A3E33534DDD4}\ not found.
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{09CC593B-E8A9-4491-927D-A3E33534DDD4}\ not found.
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{09CC593B-E8A9-4491-927D-A3E33534DDD4}\ not found.
                  Starting removal of ActiveX control {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)\ not found.
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)\ not found.
                  Starting removal of ActiveX control {BCC0FF27-31D9-4614-A68E-C18E1ADA4389}
                  C:\WINDOWS\Downloaded Program Files\McGDMgr.inf moved successfully.
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{BCC0FF27-31D9-4614-A68E-C18E1ADA4389}\ deleted successfully.
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BCC0FF27-31D9-4614-A68E-C18E1ADA4389}\ not found.
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{BCC0FF27-31D9-4614-A68E-C18E1ADA4389}\ not found.
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BCC0FF27-31D9-4614-A68E-C18E1ADA4389}\ not found.
                  Starting removal of ActiveX control {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B}
                  C:\WINDOWS\Downloaded Program Files\ZylomGamesPlayer.inf moved successfully.
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B}\ deleted successfully.
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B}\ deleted successfully.
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B}\ not found.
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B}\ not found.
                  Starting removal of ActiveX control {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA}
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA}\ deleted successfully.
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA}\ not found.
                  Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA}\ deleted successfully.
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA}\ not found.
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA}\ not found.
                  Starting removal of ActiveX control {CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA}
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA}\ deleted successfully.
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA}\ not found.
                  Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA}\ deleted successfully.
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA}\ not found.
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA}\ not found.
                  Starting removal of ActiveX control {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}\ deleted successfully.
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}\ not found.
                  Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}\ deleted successfully.
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}\ not found.
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}\ not found.
                  Starting removal of ActiveX control {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA}
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA}\ deleted successfully.
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA}\ not found.
                  Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA}\ deleted successfully.
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA}\ not found.
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA}\ not found.
                  Starting removal of ActiveX control {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA}
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA}\ deleted successfully.
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA}\ not found.
                  Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA}\ deleted successfully.
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA}\ not found.
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA}\ not found.
                  Starting removal of ActiveX control {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA}
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA}\ deleted successfully.
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA}\ not found.
                  Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA}\ deleted successfully.
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA}\ not found.
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA}\ not found.
                  Starting removal of ActiveX control {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}\ deleted successfully.
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}\ not found.
                  Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}\ deleted successfully.
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}\ not found.
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}\ not found.
                  Starting removal of ActiveX control {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}\ deleted successfully.
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}\ not found.
                  Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}\ deleted successfully.
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}\ not found.
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}\ not found.
                  Starting removal of ActiveX control {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}\ deleted successfully.
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}\ not found.
                  Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}\ deleted successfully.
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}\ not found.
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}\ not found.
                  Starting removal of ActiveX control {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA}
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA}\ deleted successfully.
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA}\ not found.
                  Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA}\ deleted successfully.
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA}\ not found.
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA}\ not found.
                  Starting removal of ActiveX control {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}\ deleted successfully.
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}\ not found.
                  Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}\ deleted successfully.
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}\ not found.
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}\ not found.
                  Starting removal of ActiveX control {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}\ deleted successfully.
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}\ not found.
                  Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}\ deleted successfully.
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}\ not found.
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}\ not found.
                  File oft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab not found.
                  Starting removal of ActiveX control Microsoft XML Parser for Java
                  Registry error reading value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\Microsoft XML Parser for Java\DownloadInformation\\INF .
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\Microsoft XML Parser for Java\ deleted successfully.
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\Microsoft XML Parser for Java\ not found.
                  ADS C:\Documents and Settings\All Users\Application Data\TEMP:C3759076 deleted successfully.
                  ADS C:\Documents and Settings\All Users\Application Data\TEMP:8FF81EB0 deleted successfully.
                  ADS C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2 deleted successfully.
                  ADS C:\Documents and Settings\All Users\Application Data\TEMP:981884E7 deleted successfully.
                  ADS C:\Documents and Settings\All Users\Application Data\TEMP:20FFCF0B deleted successfully.
                  ADS C:\Documents and Settings\All Users\Application Data\TEMP:82C50600 deleted successfully.
                  ADS C:\Documents and Settings\All Users\Application Data\TEMP:0656FCD2 deleted successfully.
                  ADS C:\Documents and Settings\All Users\Application Data\TEMP:59846E5E deleted successfully.
                  ADS C:\Documents and Settings\All Users\Application Data\TEMP:00F7B10F deleted successfully.
                  ADS C:\Documents and Settings\All Users\Application Data\TEMP:33DB8278 deleted successfully.
                  ========== FILES ==========
                  C:\Documents and Settings\Laurent\Local Settings\Application Data\AskToolbar folder moved successfully.
                  C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}\x86\x86 folder moved successfully.
                  C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}\x86 folder moved successfully.
                  C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD} folder moved successfully.
                  C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job moved successfully.
                  C:\WINDOWS\System32\scvhost.ini moved successfully.
                  C:\Documents and Settings\Administrator\Application Data\21cnPPS folder moved successfully.
                  C:\Documents and Settings\All Users\Application Data\BOONTY\Licenses folder moved successfully.
                  C:\Documents and Settings\All Users\Application Data\BOONTY folder moved successfully.
                  C:\Documents and Settings\All Users\Application Data\humyo.com\humyo\logs folder moved successfully.
                  C:\Documents and Settings\All Users\Application Data\humyo.com\humyo folder moved successfully.
                  C:\Documents and Settings\All Users\Application Data\humyo.com folder moved successfully.
                  C:\Documents and Settings\All Users\Application Data\{55A29068-F2CE-456C-9148-C869879E2357} folder moved successfully.
                  C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}\x86 folder moved successfully.
                  C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906} folder moved successfully.
                  C:\Documents and Settings\David\Application Data\app folder moved successfully.
                  C:\Documents and Settings\David\Application Data\AskToolbar folder moved successfully.
                  C:\Documents and Settings\David\Application Data\www.TheXSoft.com\Radio Stream Player\1.5.0.10\FastTranslations folder moved successfully.
                  C:\Documents and Settings\David\Application Data\www.TheXSoft.com\Radio Stream Player\1.5.0.10 folder moved successfully.
                  C:\Documents and Settings\David\Application Data\www.TheXSoft.com\Radio Stream Player folder moved successfully.
                  C:\Documents and Settings\David\Application Data\www.TheXSoft.com folder moved successfully.
                  C:\Documents and Settings\Laurent\Application Data\gemsweeperextractedgfx\resources-processed.frc folder moved successfully.
                  C:\Documents and Settings\Laurent\Application Data\gemsweeperextractedgfx\resources-loadingwindow.frc folder moved successfully.
                  C:\Documents and Settings\Laurent\Application Data\gemsweeperextractedgfx\numerics.frc folder moved successfully.
                  C:\Documents and Settings\Laurent\Application Data\gemsweeperextractedgfx\highscoregems.frc folder moved successfully.
                  C:\Documents and Settings\Laurent\Application Data\gemsweeperextractedgfx\gems.frc folder moved successfully.
                  C:\Documents and Settings\Laurent\Application Data\gemsweeperextractedgfx\gem-fragments.frc folder moved successfully.
                  C:\Documents and Settings\Laurent\Application Data\gemsweeperextractedgfx\fonts.frc folder moved successfully.
                  C:\Documents and Settings\Laurent\Application Data\gemsweeperextractedgfx\bonusfonts.frc folder moved successfully.
                  C:\Documents and Settings\Laurent\Application Data\gemsweeperextractedgfx\boardfonts.frc folder moved successfully.
                  C:\Documents and Settings\Laurent\Application Data\gemsweeperextractedgfx\board-red-processed.frc folder moved successfully.
                  C:\Documents and Settings\Laurent\Application Data\gemsweeperextractedgfx\board-processed.frc folder moved successfully.
                  C:\Documents and Settings\Laurent\Application Data\gemsweeperextractedgfx\board-particles.frc folder moved successfully.
                  C:\Documents and Settings\Laurent\Application Data\gemsweeperextractedgfx\board-empty-processed.frc folder moved successfully.
                  C:\Documents and Settings\Laurent\Application Data\gemsweeperextractedgfx folder moved successfully.
                  ========== COMMANDS ==========

                  [EMPTYTEMP]

                  User: Administrateur
                  ->Temp folder emptied: 0 bytes
                  ->Temporary Internet Files folder emptied: 67 bytes

                  User: Administrator

                  User: All Users

                  User: David
                  ->Temp folder emptied: 224912 bytes
                  ->Temporary Internet Files folder emptied: 1656522 bytes
                  ->Java cache emptied: 71069584 bytes
                  ->FireFox cache emptied: 17386060 bytes
                  ->Google Chrome cache emptied: 6769710 bytes
                  ->Apple Safari cache emptied: 68411074 bytes
                  ->Opera cache emptied: 5197465 bytes

                  User: Default User
                  ->Temp folder emptied: 0 bytes
                  ->Temporary Internet Files folder emptied: 32902 bytes

                  User: Invité
                  ->Temp folder emptied: 0 bytes
                  ->Temporary Internet Files folder emptied: 67 bytes
                  ->Opera cache emptied: 358515 bytes

                  User: Laurent
                  ->Temp folder emptied: 19696409 bytes
                  ->Temporary Internet Files folder emptied: 1593250 bytes
                  ->Java cache emptied: 75075871 bytes
                  ->FireFox cache emptied: 151067741 bytes
                  ->Google Chrome cache emptied: 394176837 bytes
                  ->Apple Safari cache emptied: 750534 bytes
                  ->Opera cache emptied: 85444599 bytes

                  User: LocalService
                  ->Temp folder emptied: 65748 bytes
                  ->Temporary Internet Files folder emptied: 32902 bytes
                  ->FireFox cache emptied: 4095466 bytes

                  User: NetworkService
                  ->Temp folder emptied: 0 bytes
                  ->Temporary Internet Files folder emptied: 65670 bytes

                  User: Propriétaire
                  ->Temp folder emptied: 0 bytes

                  %systemdrive% .tmp files removed: 0 bytes
                  %systemroot% .tmp files removed: 0 bytes
                  %systemroot%\System32 .tmp files removed: 0 bytes
                  Windows Temp folder emptied: 664 bytes
                  %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
                  %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
                  RecycleBin emptied: 281556 bytes

                  Total Files Cleaned = 862,00 mb

                  OTL by OldTimer - Version 3.1.20.1 log created on 01062010_222622

                  Files\Folders moved on Reboot...

                  Registry entries deleted on Reboot...

                  D'après toi y aura t'il encore beaucoup de manip à faire ? Merci de ton aide.
              12. ▶ Télécharge Zeb-Restoreet enregistre ce fichier sur le bureau.

                ▶-Clic droit Zeb-Restore.zip ==> Extraire tout choisis comme lieu d'enregistrement le bureau.

                ▶-Ouvre le dossier ZR_1.0.0.37 ==> double clic sur Zeb-Restore.exe

                ▶- Coche la case devant : sites de confiance

                ▶- Ne coche aucune autre case

                ▶-Clique sur Restaurer

                ▶-Redémarre ton PC

                ensuite :

                ▶ Double clic sur OTL.exe pour le lancer.

                ▶Copie la liste qui se trouve en gras ci-dessous,

                ▶ colle-la dans la zone sous Customs Scans/Fixes :

                :processes
                explorer.exe
                iexplore.exe
                firefox.exe
                msnmsgr.exe
                Teatimer.exe

                :OTL
                IE - HKLM\..\URLSearchHook: {14f0d511-36a2-41ca-ae01-ba4f87282c97} - C:\Program Files\SHOUTcast Radio Toolbar\shoutcasttb.dll (AOL LLC)
                IE - HKU\S-1-5-21-2328322012-3734155301-851506153-1006\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page_bak = http://ww12.cherche.us
                FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}:6.0.01
                FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}:6.0.02
                FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}:6.0.03
                FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}:6.0.05
                FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13
                FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}:6.0.14
                FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}:6.0.15
                FF - prefs.js..browser.search.order.1: "Ask"
                O2 - BHO: (no name) - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - No CLSID value found.
                O2 - BHO: (Nero Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll File not found
                O3 - HKLM\..\Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
                O3 - HKLM\..\Toolbar: (Nero Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll File not found
                O3 - HKU\S-1-5-21-2328322012-3734155301-851506153-1006\..\Toolbar\WebBrowser: (SHOUTcast Radio Toolbar) - {0457331D-8CA6-4F97-9C26-6A9EF2B2DBA8} - C:\Program Files\SHOUTcast Radio Toolbar\shoutcasttb.dll (AOL LLC)
                O3 - HKU\S-1-5-21-2328322012-3734155301-851506153-1006\..\Toolbar\WebBrowser: (Nero Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll File not found
                O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
                O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
                O8 - Extra context menu item: Recherche avec cherche.us - C:\Documents and Settings\Laurent\scriptjava.html ()
                O9 - Extra Button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - Reg Error: Key error. File not found
                O16 - DPF: {00000055-9980-0010-8000-00AA00389B71} http://codecs.microsoft.com/codecs/i386/fhg.CAB (Reg Error: Key error.)
                O16 - DPF: {09CC593B-E8A9-4491-927D-A3E33534DDD4} http://m6video.m6.fr/1click/install/files/installer2.cab (Reg Error: Key error.)
                O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
                O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} http://download.mcafee.com/molbin/shared/mcgdmgr/1,0,0,26/mcgdmgr.cab (Reg Error: Key error.)
                O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} http://game08.zylom.com/activex/zylomgamesplayer.cab (Zylom Games Player)
                O16 - DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} https://www.oracle.com/java/technologies/ (Reg Error: Key error.)
                O16 - DPF: {CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-1_5_0_05-windows-i586.cab (Reg Error: Key error.)
                O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab (Reg Error: Key error.)
                O16 - DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-1_5_0_09-windows-i586.cab (Reg Error: Key error.)
                O16 - DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-1_5_0_10-windows-i586.cab (Reg Error: Key error.)
                O16 - DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab (Reg Error: Key error.)
                O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab (Reg Error: Key error.)
                O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab (Reg Error: Key error.)
                O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab (Reg Error: Key error.)
                O16 - DPF: {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_04-windows-i586.cab (Reg Error: Key error.)
                O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Reg Error: Key error.)
                O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Reg Error: Key error.)
                O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
                @Alternate Data Stream - 279 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:C3759076
                @Alternate Data Stream - 229 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:8FF81EB0
                @Alternate Data Stream - 164 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
                @Alternate Data Stream - 150 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:981884E7
                @Alternate Data Stream - 150 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:20FFCF0B
                @Alternate Data Stream - 138 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:82C50600
                @Alternate Data Stream - 137 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0656FCD2
                @Alternate Data Stream - 120 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:59846E5E
                @Alternate Data Stream - 117 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:00F7B10F
                @Alternate Data Stream - 116 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:33DB8278

                :files
                C:\Documents and Settings\Laurent\Local Settings\Application Data\AskToolbar
                C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
                C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
                C:\WINDOWS\System32\scvhost.ini
                C:\Documents and Settings\Administrator\Application Data\21cnPPS
                C:\Documents and Settings\All Users\Application Data\BOONTY
                C:\Documents and Settings\All Users\Application Data\humyo.com
                C:\Documents and Settings\All Users\Application Data\{55A29068-F2CE-456C-9148-C869879E2357}
                C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
                C:\Documents and Settings\David\Application Data\app
                C:\Documents and Settings\David\Application Data\AskToolbar
                C:\Documents and Settings\David\Application Data\www.TheXSoft.com
                C:\Documents and Settings\Laurent\Application Data\gemsweeperextractedgfx

                :commands
                [emptytemp]
                [start explorer]
                [reboot]


                ▶ Clique sur RunFix pour lancer la suppression.

                ▶ Poste le rapport.
                1. quels soucis persistent ?
                  1. Salut gen hackman, voilà ce matin j'ai passé spybot. Au début du scan il détecte 850000 lignes à scaner. De la ligne 150000 à la ligne 760000 il me lit (en bas à gauche) des lignes qui s'intitulent virtumonde, virtumonde dll, et virtumonde dll. Est ce normal, ou est ce encore le virus qui traine ?
                    A la fin du scan il m'a donné les problèmes suivant à corriger : Adviva, bluestreak, doubleclick, fastclick, Mediaplex et tradedoubler que j'ai corrigé.

                    Merci beaucoup, bonne journée.
                • 1
                • 2