Rapport hijackthis

Résolu
Salut les AS de l'informatique, voilà je viens vous soumettre mon rapport hijackthis. ça serait cool si vous me disiez comment se comporte ma bécane et si vous trouviez mon système de sécurité satisfaisant (bitdefender + spybot + malwarebytes) ? merci d'avance pour votre réponse.

Rapport:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 00:24:11, on 01/02/2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18882)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Program Files\BitDefender\BitDefender 2010\bdagent.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\BitDefender\BitDefender 2010\seccenter.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.packardbell.com/...
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.packardbell.com/...
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.packardbell.com/rdr.aspx?b=ACPW&l=040c&s=1&o=vp32&d=0209&m=imedia_d5322_fr
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\pdfforge Toolbar\SearchSettings.dll
F2 - REG:system.ini: UserInit=C:\Windows\system32\userinit.exe
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll
O2 - BHO: pdfforge Toolbar - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\WidgiToolbarIE.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O2 - BHO: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\pdfforge Toolbar\SearchSettings.dll
O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2010\IEToolbar.dll
O3 - Toolbar: pdfforge Toolbar - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\WidgiToolbarIE.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll
O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2010\bdagent.exe"
O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2010\IEShow.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O23 - Service: Adobe Active File Monitor V6 (AdobeActiveFileMonitor6.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
O23 - Service: BitDefender Serveur Arrakis (Arrakis3) - BitDefender S.R.L. https://www.bitdefender.fr/ - C:\Program Files\Common Files\BitDefender\BitDefender Arrakis Server\bin\arrakis3.exe
O23 - Service: Empowering Technology Service (ETService) - Unknown owner - C:\Program Files\Packard Bell\Packard Bell Recovery Management\Service\ETService.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Generic Service for HID Keyboard Input Collections (GenericHidService) - Packard Bell Services - c:\windows\system32\HidService.exe
O23 - Service: Google Desktop Manager 5.7.808.7150 (GoogleDesktopManager-080708-050100) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Service Google Update (gupdate1c9b3dbeda5d245) (gupdate1c9b3dbeda5d245) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Canon Inkjet Printer/Scanner/Fax Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender S.R.L. - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: Norton Internet Security - Unknown owner - C:\Program Files\Norton Internet Security\Engine\16.0.0.125\ccSvcHst.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\Windows\system32\IoctlSvc.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2010\vsserv.exe

--
End of file - 7889 bytes
Configuration: Windows Vista
Firefox 3.5.7

32 réponses

Résumé de la discussion

Le cœur de la discussion concerne l’interprétation d’un rapport HijackThis et l’évaluation de la sécurité d’un PC sous Windows Vista équipé de BitDefender 2010, Spybot et Malwarebytes, pour obtenir un avis fiable. Plusieurs réponses fournissent des outils de diagnostic et de nettoyage, notamment des liens vers OTL pour l’analyse des rapports, et listent les éléments détectés comme indésirables tout en précisant des services système légitimes. En cas de doute, la meilleure pratique consiste à suivre les recommandations des contributeurs et à effectuer les nettoyages proposés, tout en adoptant une approche multi-logiciels plutôt que de se fier à un seul outil.

Bobot (l’IA à votre service)
  1. salut :

    ▶ Désactivez le contrôle des comptes utilisateurs avant utilisation de cet outil:

    ▶ Allez dans "Démarrer" puis Panneau de configuration.
    ▶ Double Cliquez sur l'icône Comptes d'utilisateurs et sur "Activer ou désactiver le contrôle des comptes d'utilisateurs".
    ▶ Décochez la case Utiliser le contrôle des comptes d'utilisateurs pour vous aider à protéger votre ordinateur.
    ▶ Validez par OK et redémarrez .

    ensuite

    ▶ Télécharge Ad-remover ( de C_XX ) sur ton bureau :

    ▶ Déconnecte toi et ferme toutes applications en cours !

    ▶ clic droit sur "Ad-R.exe" en tant qu'administrateur pour lancer l'installation et laisse les paramètres d'installation par défaut .

    ▶ clic droit sur le raccourci Ad-remover en tant qu'administrateur qui est sur ton bureau pour lancer l'outil .

    ▶ Au menu principal choisis l'option "L" et tape sur [entrée] .

    ▶ Laisse travailler l'outil et ne touche à rien ...

    ▶ Poste le rapport qui apparait à la fin , sur le forum ...

    ( Le rapport est sauvegardé aussi sous C:\Ad-report.log )
    ( CTRL+A Pour tout sélectionner , CTRL+C pour copier et CTRL+V pour coller )

    ▶ Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
    Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
    Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.
    1. Contributeur
      Salut,
      "et si vous trouviez mon système de sécurité satisfaisant (bitdefender + spybot + malwarebytes) ? merci d'avance pour votre réponse. "

      et NORTON ???...

      // O23 - Service: Norton Internet Security - Unknown owner - C:\Program Files\Norton Internet Security\Engine\16.0.0.125\ccSvcHst.exe (file missing)

      Ton scan semble propre même si a mon gout tu as beaucoup trop de barres d'outils dans tes navigateurs internet ^^
      1. tout d'abord merci pour ta réponse rapide et désolé pour ma réponse tardive...

        Pour ce qui est de norton, ce logiciel était préinstallé sur l'ordi. J'ai du le désinstaller quand j'ai acheté bitdefender. Mais ce qui m'etonne, c'est qu'il apparait toujours dans le rapport. Est-ce qu'il toujours actif ou est-ce qu'il reste des dossiers/fichiers de norton non supprimés? pourtant j'utilise ccleaner pour nettoyer mon pc.

        pour ce qui de internet explorer, est-ce que c'est pénalisant a tout point de vue? d'autant plus que j'utilise firefox.

        enfin voici le rapport de ad-remover:
        .
        ======= RAPPORT D'AD-REMOVER 1.1.4.6_J | UNIQUEMENT XP/VISTA/7 =======
        .
        Mis à jour par C_XX le 03.02.2010 à 19:46
        Contact: AdRemover.contact@gmail.com
        Site web: http://pagesperso-orange.fr/NosTools/ad_remover.html
        .
        Lancé à: 18:25:10, 04/02/2010 | Mode Normal | Option: CLEAN
        Exécuté de: C:\Ad-Remover\
        Système d'exploitation: Microsoft® Windows Vista™ HomePremium Service Pack 2 v6.0.6002
        Nom du PC: PC | Utilisateur actuel: Bat
        .
        ============== ÉLÉMENT(S) NEUTRALISÉ(S) ==============
        .

        C:\Program Files\Mozilla FireFox\extensions\{B922D405-6D13-4A2B-AE89-08A030DA4402}
        C:\Program Files\Mozilla FireFox\extensions\search@searchsettings.com
        C:\Program Files\pdfforge Toolbar
        C:\Users\Bat\AppData\LocalLow\pdfforge
        C:\Users\Bat\AppData\LocalLow\Search Settings
        C:\Windows\Installer\6a8990.msi

        (!) -- Fichiers temporaires supprimés.

        .
        HKCU\software\appdatalow\software\pdfforge
        HKCU\Software\Microsoft\Internet Explorer\LowRegistry\Search Settings
        HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}
        HKCU\software\Search Settings
        HKLM\Software\Classes\CLSID\{B922D405-6D13-4A2B-AE89-08A030DA4402}
        HKLM\Software\Classes\CLSID\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}
        HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B922D405-6D13-4A2B-AE89-08A030DA4402}
        HKLM\Software\Microsoft\Internet Explorer\Toolbar\\{B922D405-6D13-4A2B-AE89-08A030DA4402}
        HKLM\software\microsoft\shared tools\msconfig\startupreg\SearchSettings
        HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B922D405-6D13-4A2B-AE89-08A030DA4402}
        HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}
        HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\76DA9915C36F3D742951F63351CF5C97
        HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\9B0B0584E80456A4FB98DA3973B1EB3F
        HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\A89F1E0FE544529429C8BF82FE74CE39
        HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\C9667115F6A9CE340B31B63B680FF26F
        HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\EFB70E89C3D6D354596520DE424F89D6
        HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\F49A213B5069AC348994D03F81B56C19
        HKLM\software\pdfforge
        HKLM\software\Search Settings
        .
        ============== Scan additionnel ==============
        .
        .
        * Mozilla FireFox Version 3.5.7 [fr] *
        .
        Nom du profil: 07mywi5j.default (Bat)
        .
        (Bat, prefs.js) Browser.download.dir, C:\Users\Bat\Desktop
        (Bat, prefs.js) Browser.download.lastDir, C:\Users\Bat\Desktop
        (Bat, prefs.js) Browser.startup.homepage, www.google.fr
        (Bat, prefs.js) Extensions.enabledItems, FFToolbar@bitdefender.com:2.0,{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}:6.0.07,{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13,{20a82645-c095-46ed-80e3-08825760534b}:1.1,firefox@tvunetworks.com:2,5,0,1,{972ce4c6-7e08-4474-a285-3208198ce6fd}:3.5.7
        .
        .
        .
        * Internet Explorer Version 8.0.6001.18882 *
        .
        [HKEY_CURRENT_USER\..\Internet Explorer\Main]
        .
        Enable Browser Extensions: yes
        Start Page: hxxp://fr.msn.com/
        Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
        Do404Search: 01000000
        Local Page: C:\Windows\system32\blank.htm
        Show_ToolBar: yes
        Default_search_url: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
        Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
        .
        [HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]
        .
        Start Page: hxxp://fr.msn.com/
        Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
        Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
        Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
        Delete_Temp_Files_On_Exit: yes
        Local Page: C:\Windows\System32\blank.htm
        Search bar: hxxp://search.msn.com/spbasic.htm
        .
        [HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]
        .
        Tabs: res://ieframe.dll/tabswelcome.htm
        .
        ===================================
        .
        4224 Octet(s) - C:\Ad-Report-CLEAN[1].log
        .
        1 Fichier(s) - C:\Users\Bat\AppData\Local\Temp
        2 Fichier(s) - C:\Windows\Temp
        7 Fichier(s) - C:\Windows\Prefetch
        .
        21 Fichier(s) - C:\Ad-Remover\BACKUP
        76 Fichier(s) - C:\Ad-Remover\QUARANTINE
        .
        Fin à: 19:06:19 | 04/02/2010 - CLEAN[1]
        .
        ============== E.O.F ==============
        .
        1. ok :) hello

          Télécharge OTL de OLDTimer

          ▶ enregistre le sur ton Bureau.

          ▶ Double clic ( pour vista / 7 => clic droit "executer en tant qu'administrateur") sur OTL.exe pour le lancer.

          ▶ Coche les 2 cases Lop et Purity

          ▶ Coche la case devant scan all users

          ▶ règle-le sur "60 Days"

          ▶ dans la colonne de gauche , mets tout sur all

          ne modifie pas ceci :

          "files created whithin" et "files modified whithin"


          ▶Clic sur Run Scan.

          A la fin du scan, le Bloc-Notes va s'ouvrir avec le rapport (OTL.txt).

          Ce fichier est sur ton Bureau (en général C:\Documents and settings\le_nom_de_ta_session\OTL.txt)

          ▶▶▶ NE LE POSTE PAS SUR LE FORUM

          Pour me le transmettre clique sur ce lien : http://www.cijoint.fr/

          ▶ Clique sur Parcourir et cherche le fichier ci-dessus.

          ▶ Clique sur Ouvrir.

          ▶ Clique sur "Cliquez ici pour déposer le fichier".

          Un lien de cette forme :

          http://www.cijoint.fr/cjlink.php?file=cjge368/cijSKAP5fU.txt

          est ajouté dans la page.

          ▶ Copie ce lien dans ta réponse.

          ▶▶ Tu feras la meme chose avec le "Extra.txt".
          1. ok voici les liens
            pour OTL:
            http://www.cijoint.fr/cjlink.php?file=cj201002/cijyHPpqG8.txt

            pour extra:
            http://www.cijoint.fr/cjlink.php?file=cj201002/cijC5UbzL3.txt
            1. Desactive ton antivirus le temps de la manip ainsi que ton parefeu si présent(car il est detecté a tort comme infection)

              ▶ Télécharge List&Kill'em et enregistre le sur ton bureau

              ▶ Branche clés usb , disques durs externes , mp3 , mp4 , etc..

              double clique ( clic droit "executer en tant qu'administrateur" pour Vista/7 ) sur le raccourci sur ton bureau pour lancer l'installation

              coche la case "creer une icone sur le bureau"

              une fois terminée , clic sur "terminer" et le programme se lancera seul

              choisis la langue puis choisis l'option 1 = Mode Recherche

              ▶ laisse travailler l'outil

              à l'apparition de la fenetre blanche , c'est un peu long , c'est normal , le programme n'est pas bloqué.

              un rapport du nom de catchme apparait sur ton bureau , ignore-le,ne le poste pas , mais ne le supprime pas pour l instant, le scan n'est pas fini.

              ▶ Poste le contenu du rapport qui s'ouvre aux 100 % du scan à l'ecran "COMPLETED"

              tu peux supprimer le rapport catchme.log de ton bureau maintenant.

              1. ton lien ne marche pas. et dis moi pourquoi tu me demandes de faire toutes ces analyses? est-ce que le pc infecté? est-ce que c'est grave docteur?
                1. List'em by g3n-h@ckm@n 1.2.2.1

                  User : Bat (Administrateurs)
                  Update on 04/02/2010 by g3n-h@ckm@n ::::: 16.00
                  Start at: 21:42:18 | 04/02/2010
                  Contact : https://forums.commentcamarche.net/forum/virus-securite-7

                  Intel(R) Pentium(R) Dual CPU E2220 @ 2.40GHz
                  Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6002 32-bit) # Service Pack 2
                  Internet Explorer 8.0.6001.18882
                  Windows Firewall Status : Enabled

                  C:\ -> Disque fixe local | 149,41 Go (120,15 Go free) [Système] | NTFS
                  D:\ -> Disque fixe local | 769,1 Go (730,48 Go free) [Datas] | NTFS
                  E:\ -> Disque CD-ROM

                  ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running

                  C:\Windows\System32\smss.exe
                  C:\Windows\system32\csrss.exe
                  C:\Windows\system32\wininit.exe
                  C:\Windows\system32\csrss.exe
                  C:\Windows\system32\services.exe
                  C:\Windows\system32\lsass.exe
                  C:\Windows\system32\lsm.exe
                  C:\Windows\system32\winlogon.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\system32\nvvsvc.exe
                  C:\Windows\system32\svchost.exe
                  C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
                  C:\Program Files\BitDefender\BitDefender 2010\vsserv.exe
                  C:\Windows\System32\svchost.exe
                  C:\Windows\System32\svchost.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\system32\SLsvc.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\system32\nvvsvc.exe
                  C:\Windows\System32\spoolsv.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\system32\taskeng.exe
                  C:\Program Files\BitDefender\BitDefender 2010\bdagent.exe
                  C:\Windows\system32\Dwm.exe
                  C:\Windows\Explorer.EXE
                  C:\Windows\system32\taskeng.exe
                  C:\Program Files\Windows Sidebar\sidebar.exe
                  C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                  C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
                  C:\Program Files\Packard Bell\Packard Bell Recovery Management\Service\ETService.exe
                  C:\Program Files\BitDefender\BitDefender 2010\seccenter.exe
                  c:\windows\system32\HidService.exe
                  C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
                  C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
                  C:\Windows\system32\IoctlSvc.exe
                  C:\Windows\system32\svchost.exe
                  C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                  C:\Windows\system32\svchost.exe
                  C:\Windows\System32\svchost.exe
                  C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
                  C:\Windows\system32\SearchIndexer.exe
                  C:\Program Files\Windows Media Player\wmpnscfg.exe
                  C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
                  C:\Program Files\Windows Media Player\wmpnetwk.exe
                  C:\Windows\system32\wbem\unsecapp.exe
                  C:\Windows\system32\wbem\wmiprvse.exe
                  C:\Windows\system32\NOTEPAD.EXE
                  C:\Windows\servicing\TrustedInstaller.exe
                  C:\Windows\system32\SearchProtocolHost.exe
                  C:\Windows\system32\SearchFilterHost.exe
                  C:\Program Files\List_Kill'em\List_Kill'em.scr
                  C:\Windows\system32\conime.exe
                  C:\Windows\system32\cmd.exe
                  C:\Windows\system32\wbem\wmiprvse.exe
                  C:\Users\Bat\AppData\Local\Temp\A14F.tmp\pv.exe

                  ======================
                  Keys "Run"
                  ======================
                  [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                  Sidebar REG_SZ C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                  swg REG_SZ "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                  eRecoveryService REG_SZ
                  BDAgent REG_SZ "C:\Program Files\BitDefender\BitDefender 2010\bdagent.exe"
                  BitDefender Antiphishing Helper REG_SZ "C:\Program Files\BitDefender\BitDefender 2010\IEShow.exe"

                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]

                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]

                  =====================
                  Other Keys
                  =====================
                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
                  ConsentPromptBehaviorAdmin REG_DWORD 2 (0x2)
                  ConsentPromptBehaviorUser REG_DWORD 1 (0x1)
                  EnableInstallerDetection REG_DWORD 1 (0x1)
                  EnableLUA REG_DWORD 1 (0x1)
                  EnableSecureUIAPaths REG_DWORD 1 (0x1)
                  EnableVirtualization REG_DWORD 1 (0x1)
                  PromptOnSecureDesktop REG_DWORD 1 (0x1)
                  ValidateAdminCodeSignatures REG_DWORD 0 (0x0)
                  dontdisplaylastusername REG_DWORD 0 (0x0)
                  legalnoticecaption REG_SZ
                  legalnoticetext REG_SZ
                  scforceoption REG_DWORD 0 (0x0)
                  shutdownwithoutlogon REG_DWORD 1 (0x1)
                  undockwithoutlogon REG_DWORD 1 (0x1)
                  FilterAdministratorToken REG_DWORD 0 (0x0)
                  EnableUIADesktopToggle REG_DWORD 0 (0x0)

                  ===============
                  [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]

                  ===============
                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
                  BindDirectlyToPropertySetStorage REG_DWORD 0 (0x0)

                  ===============
                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
                  AppInit_DLLS REG_SZ C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL

                  ===============
                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
                  ReportBootOk REG_SZ 1
                  Shell REG_SZ explorer.exe
                  Userinit REG_SZ C:\Windows\system32\userinit.exe
                  VmApplet REG_SZ rundll32 shell32,Control_RunDLL "sysdm.cpl"
                  AutoRestartShell REG_DWORD 1 (0x1)
                  LegalNoticeCaption REG_SZ
                  LegalNoticeText REG_SZ
                  PowerdownAfterShutdown REG_SZ 0
                  ShutdownWithoutLogon REG_SZ 0
                  cachedlogonscount REG_SZ 10
                  forceunlocklogon REG_DWORD 0 (0x0)
                  passwordexpirywarning REG_DWORD 14 (0xe)
                  Background REG_SZ 0 0 0
                  DebugServerCommand REG_SZ no
                  WinStationsDisabled REG_SZ 0
                  DisableCAD REG_DWORD 1 (0x1)
                  scremoveoption REG_SZ 0
                  ShutdownFlags REG_DWORD 39 (0x27)
                  Windows Shell (ezShellStart) REG_SZ C:\Windows\system32\userinit.exe,

                  ===============

                  ===============
                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]

                  ===============
                  [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

                  [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

                  ===============
                  ActivX controls
                  ===============
                  HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{8AD9C840-044E-11D1-B3E9-00805F499D93}
                  HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
                  HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
                  HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}

                  ===============
                  HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}
                  HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{26923b43-4d38-484f-9b9e-de460746276c}
                  HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}
                  HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{08B0E5C0-4FCB-11CF-AAA5-00401C608500}
                  HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2179C5D3-EBFF-11CF-B6FD-00AA00B4E220}
                  HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}
                  HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{233C1507-6A77-46A4-9443-F871F945D258}
                  HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2A202491-F00D-11cf-87CC-0020AFEECF20}
                  HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}
                  HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{3af36230-a269-11d1-b5bf-0000f8051515}
                  HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}
                  HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA848-CC51-11CF-AAFA-00AA00B6015C}
                  HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA855-CC51-11CF-AAFA-00AA00B6015F}
                  HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{45ea75a0-a269-11d1-b5bf-0000f8051515}
                  HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4f645220-306d-11d2-995d-00c04f98bbc9}
                  HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5fd399c0-a70a-11d1-9948-00c04f98bbc9}
                  HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{630b1da0-b465-11d1-9948-00c04f98bbc9}
                  HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}
                  HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6fab99d0-bab8-11d1-994a-00c04f98bbc9}
                  HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7790769C-0471-11d2-AF11-00C04FA35D02}
                  HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7C028AF8-F614-47B3-82DA-BA94E41B1089}
                  HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4340}
                  HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4383}
                  HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}
                  HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9381D8F2-0288-11D0-9501-00AA00B911A5}
                  HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C6BAF60B-6E91-453F-BFF9-D3789CFEFCDD}
                  HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C9E9A340-D1F1-11D0-821E-444553540600}
                  HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CDD7975E-60F8-41d5-8149-19E51D6F71D0}
                  HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{D27CDB6E-AE6D-11CF-96B8-444553540000}
                  HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{de5aed00-a4bf-11d1-9948-00c04f98bbc9}
                  HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{E92B03AB-B707-11d2-9CBD-0000F87A369E}

                  ==============
                  BHO :
                  ======
                  [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
                  [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{3785D0AD-BFFF-47F6-BF5B-A587C162FED9}]
                  [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
                  [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
                  [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
                  [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
                  [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
                  [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10}]

                  ================
                  Internet Explorer :
                  ================
                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
                  Start Page REG_SZ https://www.msn.com/fr-fr

                  [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                  Start Page REG_SZ https://www.msn.com/fr-fr

                  ========
                  Services
                  ========
                  [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services]

                  Ndisuio : 0x3
                  EapHost : 0x3
                  Wlansvc : 0x2
                  SharedAccess : 0x4
                  windefend : 0x2
                  wuauserv : 0x2
                  wscsvc : 0x2

                  =========
                  Atapi.sys
                  =========

                  %%%% HASHDEEP-1.0
                  %%%% size,md5,sha256,filename
                  ## Invoked from: C:\Users\Bat\AppData\Local\Temp\A14F.tmp
                  ## C:\> hashdeep C:\Windows\System32\Drivers\atapi.sys
                  ##
                  19944,1f05b78ab91c9075565a9d8a4b880bc4,737be9f9376dab0ccdfed93ea6d67f0c432367ea63cd772a453485be769af3bd,C:\Windows\System32\Drivers\atapi.sys

                  Sources
                  =======

                  C:\Windows\System32\drivers\atapi.sys
                  C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_b12d8e84\atapi.sys
                  C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys
                  C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_cc18792d\atapi.sys
                  C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a2189ce9c\atapi.sys
                  C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_df23a1261eab99e8\atapi.sys

                  Référence :
                  ==========

                  Win XP_32b : a64013e98426e1877cb653685c5c0009
                  Win XP_SP2_32b : CDFE4411A69C224BD1D11B2DA92DAC51
                  Win XP_SP3_32b : 9F3A2F5AA6875C72BF062C712CFA2674
                  Vista_32b : e03e8c99d15d0381e02743c36afc7c6f
                  Vista_SP1_32b : 2d9c903dc76a66813d350a562de40ed9
                  Vista_SP2_32b : 1F05B78AB91C9075565A9D8A4B880BC4
                  Vista_SP2_64b : 1898FAE8E07D97F2F6C2D5326C633FAC
                  Windows 7_32b : 80C40F7FDFC376E4C5FEEC28B41C119E
                  Windows 7_64b : 02062C0B390B7729EDC9E69C680A6F3C

                  =======
                  Drive :
                  =======

                  D‚fragmenteur de disque Windows
                  Copyright (c) 2006 Microsoft Corp.

                  Rapport d'analyse pour le volume C: SystŠme

                  Taille du volume = 149 Go
                  Espace libre = 120 Go
                  tendue d'espace libre la plus grande = 42.15 Go
                  Pourcentage de fragmentation des fichiers = 3 %

                  Remarqueÿ: sur les volumes NTFS, les fragments de fichiers de plus de 64ÿMo ne sont pas inclus dans les statistiques de fragmentation.

                  Il n'est pas n‚cessaire de d‚fragmenter ce volume.

                  ¤¤¤¤¤¤¤¤¤¤ Files/folders :

                  Present !! : C:\programdata\Partner
                  Present !! : C:\Windows\system32\x3daudio1_0.dll
                  Present !! : C:\Windows\system32\x3daudio1_1.dll
                  Present !! : C:\Windows\system32\X3DAudio1_2.dll
                  Present !! : C:\Windows\system32\X3DAudio1_3.dll
                  Present !! : C:\Windows\system32\X3DAudio1_4.dll
                  Present !! : C:\Windows\system32\X3DAudio1_5.dll
                  Present !! : C:\Windows\system32\X3DAudio1_6.dll
                  Present !! : C:\Windows\system32\XInput9_1_0.dll
                  Present !! : C:\Windows\System32\EZUPBH~1.DLL
                  Present !! : C:\Windows\System32\pc_drugs.dat
                  Present !! : C:\Windows\System32\pc_gambling.dat
                  Present !! : C:\Windows\System32\pc_games.dat
                  Present !! : C:\Windows\System32\pc_hate.dat
                  Present !! : C:\Windows\System32\pc_illegal.dat
                  Present !! : C:\Windows\System32\pc_im.dat
                  Present !! : C:\Windows\System32\pc_news.dat
                  Present !! : C:\Windows\System32\pc_onlinedating.dat
                  Present !! : C:\Windows\System32\pc_onlinepay.dat
                  Present !! : C:\Windows\System32\pc_onlineshop.dat
                  Present !! : C:\Windows\System32\pc_pornography.dat
                  Present !! : C:\Windows\System32\pc_regionaltlds.dat
                  Present !! : C:\Windows\System32\pc_searchengines.dat
                  Present !! : C:\Windows\System32\pc_socialnetworks.dat
                  Present !! : C:\Windows\System32\pc_tabloids.dat
                  Present !! : C:\Windows\System32\pc_video.dat
                  Present !! : C:\Windows\System32\pc_webproxy.dat
                  Present !! : C:\Windows\System32\rezumatenoi.dat
                  Present !! : C:\Users\Bat\Local Settings\Temp\Bat.bmp

                  ¤¤¤¤¤¤¤¤¤¤ Keys :

                  Present !! : HKCR\ezUPBHook.ShellObj
                  Present !! : HKCR\ezUPBHook.ShellObj.1
                  Present !! : HKCR\TypeLib\{478CAB91-9E28-11D4-97FF-0050047D51FB}
                  Present !! : HKCU\Software\mc
                  Present !! : HKLM\Software\Classes\Interface\{01009AEC-AFAA-4982-9F2B-6411C5C27E77}

                  ============

                  catchme 0.3.1398.3 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                  Rootkit scan 2010-02-04 21:51:24
                  Windows 6.0.6002 Service Pack 2 NTFS

                  scanning hidden processes ...

                  scanning hidden services & system hive ...

                  scanning hidden registry entries ...

                  scanning hidden files ...

                  scan completed successfully
                  hidden processes: 0
                  hidden services: 0
                  hidden files: 0

                  Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

                  device: opened successfully
                  user: MBR read successfully
                  kernel: MBR read successfully
                  user & kernel MBR OK

                  ==========
                  Programs
                  ==========

                  Adobe
                  BitDefender
                  BocekYazilim
                  Canon
                  CanonBJ
                  CCleaner
                  Common Files
                  desktop.ini
                  DIFX
                  Fichiers communs
                  FileZilla FTP Client
                  Google
                  HDReg
                  InstallShield Installation Information
                  Internet Explorer
                  Java
                  List_Kill'em
                  Malwarebytes' Anti-Malware
                  Micro Application
                  Microsoft
                  Microsoft Games
                  Microsoft Office
                  Microsoft Office Outlook Connector
                  Microsoft Silverlight
                  Microsoft SQL Server Compact Edition
                  Microsoft Sync Framework
                  Microsoft Visual Studio
                  Microsoft Visual Studio 8
                  Microsoft Works
                  Microsoft.NET
                  Movie Maker
                  Mozilla Firefox
                  MSBuild
                  MSXML 4.0
                  Nero
                  PACKARD BELL
                  PDFCreator
                  Philips
                  Philips_VLounge
                  Realtek
                  Reference Assemblies
                  Sony
                  SopCast
                  Spybot - Search & Destroy
                  Trend Micro
                  TVUPlayer
                  Uninstall Information
                  VideoLAN
                  Windows Calendar
                  Windows Collaboration
                  Windows Defender
                  Windows Journal
                  Windows Live
                  Windows Live SkyDrive
                  Windows Mail
                  Windows Media Player
                  Windows NT
                  Windows Photo Gallery
                  Windows Portable Devices
                  Windows Sidebar
                  WinRAR

                  ============
                  Drive C:
                  ============

                  $Recycle.Bin
                  ACER
                  Ad-Remover
                  Ad-Report-CLEAN[1].log
                  autoexec.bat
                  bdlog.txt
                  BdUninstallTool2009.12.01-02.34.07.reg
                  BdUninstallTool2009.12.14-06.15.10.reg
                  BdUninstallTool2009.12.14-08.00.09.reg
                  Boot
                  bootmgr
                  BOOTSECT.BAK
                  Config.Msi
                  config.sys
                  Documents and Settings
                  Kill'em
                  List'em.txt
                  MSOCache
                  pagefile.sys
                  PerfLogs
                  Program Files
                  ProgramData
                  RHDSetup.log
                  System Volume Information
                  Temp
                  Users
                  Windows

                  ¤¤¤¤¤¤¤¤¤¤ Cracks | Keygens | Serials

                  C:\ACER\Preload\PatchLog
                  C:\ACER\Preload\PatchLog\CodeTracer
                  C:\ACER\Preload\PatchLog\DecompressFM2009-02-13 09-59-26.log
                  C:\ACER\Preload\PatchLog\PAP0102W00000007.csv
                  C:\ACER\Preload\PatchLog\PAP01I3E04F0LC03.csv
                  C:\ACER\Preload\PatchLog\CodeTracer\CodeTracer2009-02-13 09-59-22.log
                  C:\Program Files\Adobe\Photoshop Elements 6.0\LMResources\SerializationWF.exv
                  C:\ProgramData\Adobe\Photoshop Elements\6.0\Locale\fr_FR\Photo Creations Metadata\filters\Patchwork.xml
                  C:\ProgramData\Adobe\Photoshop Elements\6.0\Photo Creations\filters\Patchwork.atn
                  C:\ProgramData\Adobe\Photoshop Elements\6.0\Photo Creations\filters\Patchwork.png
                  C:\Users\All Users\Adobe\Photoshop Elements\6.0\Locale\fr_FR\Photo Creations Metadata\filters\Patchwork.xml
                  C:\Users\All Users\Adobe\Photoshop Elements\6.0\Photo Creations\filters\Patchwork.atn
                  C:\Users\All Users\Adobe\Photoshop Elements\6.0\Photo Creations\filters\Patchwork.png
                  C:\Program Files\Microsoft Works\Install.exe

                  ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
                  1. hello

                    ▶ Relance List&Kill'em(soit en clic droit pour vista),avec le raccourci sur ton bureau.
                    mais cette fois-ci :

                    ▶ choisis l'option 2 = Mode Suppression

                    laisse travailler l'outil.

                    en fin de scan un rapport s'ouvre

                    ▶ colle le contenu dans ta reponse
                    1. Kill'em by g3n-h@ckm@n 1.2.2.1

                      User : Bat (Administrateurs)
                      Update on 04/02/2010 by g3n-h@ckm@n ::::: 16.00
                      Start at: 18:54:56 | 05/02/2010
                      Contact : https://forums.commentcamarche.net/forum/virus-securite-7

                      Intel(R) Pentium(R) Dual CPU E2220 @ 2.40GHz
                      Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6002 32-bit) # Service Pack 2
                      Internet Explorer 8.0.6001.18882
                      Windows Firewall Status : Enabled

                      C:\ -> Disque fixe local | 149,41 Go (120,16 Go free) [Système] | NTFS
                      D:\ -> Disque fixe local | 769,1 Go (730,48 Go free) [Datas] | NTFS
                      E:\ -> Disque CD-ROM

                      ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running

                      C:\Windows\System32\smss.exe
                      C:\Windows\system32\csrss.exe
                      C:\Windows\system32\wininit.exe
                      C:\Windows\system32\csrss.exe
                      C:\Windows\system32\services.exe
                      C:\Windows\system32\lsass.exe
                      C:\Windows\system32\lsm.exe
                      C:\Windows\system32\winlogon.exe
                      C:\Windows\system32\svchost.exe
                      C:\Windows\system32\nvvsvc.exe
                      C:\Windows\system32\svchost.exe
                      C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
                      C:\Program Files\BitDefender\BitDefender 2010\vsserv.exe
                      C:\Windows\System32\svchost.exe
                      C:\Windows\System32\svchost.exe
                      C:\Windows\system32\svchost.exe
                      C:\Windows\system32\svchost.exe
                      C:\Windows\system32\SLsvc.exe
                      C:\Windows\system32\svchost.exe
                      C:\Windows\system32\nvvsvc.exe
                      C:\Windows\system32\svchost.exe
                      C:\Program Files\BitDefender\BitDefender 2010\bdagent.exe
                      C:\Windows\System32\spoolsv.exe
                      C:\Windows\system32\svchost.exe
                      C:\Windows\system32\taskeng.exe
                      C:\Windows\system32\taskeng.exe
                      C:\Windows\system32\Dwm.exe
                      C:\Windows\Explorer.EXE
                      C:\Program Files\Windows Sidebar\sidebar.exe
                      C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                      C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
                      C:\Program Files\Packard Bell\Packard Bell Recovery Management\Service\ETService.exe
                      c:\windows\system32\HidService.exe
                      C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
                      C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
                      C:\Windows\system32\IoctlSvc.exe
                      C:\Windows\system32\svchost.exe
                      C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                      C:\Windows\system32\svchost.exe
                      C:\Windows\System32\svchost.exe
                      C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
                      C:\Windows\system32\SearchIndexer.exe
                      C:\Program Files\BitDefender\BitDefender 2010\seccenter.exe
                      C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
                      C:\Program Files\Windows Media Player\wmpnscfg.exe
                      C:\Program Files\Windows Media Player\wmpnetwk.exe
                      C:\Windows\system32\wbem\unsecapp.exe
                      C:\Windows\system32\wbem\wmiprvse.exe
                      C:\Windows\system32\taskeng.exe
                      C:\Windows\system32\taskeng.exe
                      C:\Program Files\List_Kill'em\List_Kill'em.scr
                      C:\Windows\system32\conime.exe
                      C:\Windows\system32\cmd.exe
                      C:\Windows\system32\wbem\wmiprvse.exe
                      C:\Users\Bat\AppData\Local\Temp\82A6.tmp\ERUNT.EXE
                      C:\Users\Bat\AppData\Local\Temp\82A6.tmp\pv.exe

                      Detections :
                      ==========

                      ¤¤¤¤¤¤¤¤¤¤ Files/folders :

                      Quarantined & Deleted !! : C:\programdata\Partner

                      Quarantined & Deleted !! : C:\Windows\system32\x3daudio1_0.dll
                      Quarantined & Deleted !! : C:\Windows\system32\x3daudio1_1.dll
                      Quarantined & Deleted !! : C:\Windows\system32\X3DAudio1_2.dll
                      Quarantined & Deleted !! : C:\Windows\system32\X3DAudio1_3.dll
                      Quarantined & Deleted !! : C:\Windows\system32\X3DAudio1_4.dll
                      Quarantined & Deleted !! : C:\Windows\system32\X3DAudio1_5.dll
                      Quarantined & Deleted !! : C:\Windows\system32\X3DAudio1_6.dll
                      Quarantined & Deleted !! : C:\Windows\system32\XInput9_1_0.dll
                      Quarantined & Deleted !! : C:\Windows\SYSTEM32\EZUPBH~1.DLL
                      Quarantined & Deleted !! : C:\Windows\System32\pc_drugs.dat
                      Quarantined & Deleted !! : C:\Windows\System32\pc_gambling.dat
                      Quarantined & Deleted !! : C:\Windows\System32\pc_games.dat
                      Quarantined & Deleted !! : C:\Windows\System32\pc_hate.dat
                      Quarantined & Deleted !! : C:\Windows\System32\pc_illegal.dat
                      Quarantined & Deleted !! : C:\Windows\System32\pc_im.dat
                      Quarantined & Deleted !! : C:\Windows\System32\pc_news.dat
                      Quarantined & Deleted !! : C:\Windows\System32\pc_onlinedating.dat
                      Quarantined & Deleted !! : C:\Windows\System32\pc_onlinepay.dat
                      Quarantined & Deleted !! : C:\Windows\System32\pc_onlineshop.dat
                      Quarantined & Deleted !! : C:\Windows\System32\pc_pornography.dat
                      Quarantined & Deleted !! : C:\Windows\System32\pc_regionaltlds.dat
                      Quarantined & Deleted !! : C:\Windows\System32\pc_searchengines.dat
                      Quarantined & Deleted !! : C:\Windows\System32\pc_socialnetworks.dat
                      Quarantined & Deleted !! : C:\Windows\System32\pc_tabloids.dat
                      Quarantined & Deleted !! : C:\Windows\System32\pc_video.dat
                      Quarantined & Deleted !! : C:\Windows\System32\pc_webproxy.dat
                      Quarantined & Deleted !! : C:\Windows\System32\rezumatenoi.dat
                      Quarantined & Deleted !! : C:\Users\Bat\Local Settings\Temp\Bat.bmp

                      ==============
                      host file OK !
                      ==============

                      ========
                      Registry
                      ========

                      ========
                      Services
                      =========

                      Ndisuio : Start = 3
                      EapHost : Start = 2
                      Wlansvc : Start = 2
                      SharedAccess : Start = 2
                      windefend : Start = 2
                      wuauserv : Start = 2
                      wscsvc : Start = 2

                      ============
                      Disk Cleaned
                      ============

                      ================
                      Prefetch cleaned
                      ================

                      ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
                      1. tu l'as executé en tant qu'administrateur avec le clic droit et antivirus desactivé ?
                        1. il n a pas supprimé les clés....desinstalle-le , retelecharge-le antivirus desactivé , et refais option 2 avec le clic droit "executer en tant qu'administrateur" stp
                          1. Kill'em by g3n-h@ckm@n 1.2.4.0

                            User : Bat (Administrateurs)
                            Update on 05/02/2010 by g3n-h@ckm@n ::::: 18.40
                            Start at: 20:23:55 | 05/02/2010
                            Contact : https://forums.commentcamarche.net/forum/virus-securite-7

                            Intel(R) Pentium(R) Dual CPU E2220 @ 2.40GHz
                            Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6002 32-bit) # Service Pack 2
                            Internet Explorer 8.0.6001.18882
                            Windows Firewall Status : Enabled

                            C:\ -> Disque fixe local | 149,41 Go (120,17 Go free) [Système] | NTFS
                            D:\ -> Disque fixe local | 769,1 Go (730,48 Go free) [Datas] | NTFS
                            E:\ -> Disque CD-ROM

                            ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running

                            C:\Windows\System32\smss.exe
                            C:\Windows\system32\csrss.exe
                            C:\Windows\system32\wininit.exe
                            C:\Windows\system32\csrss.exe
                            C:\Windows\system32\services.exe
                            C:\Windows\system32\lsass.exe
                            C:\Windows\system32\lsm.exe
                            C:\Windows\system32\winlogon.exe
                            C:\Windows\system32\svchost.exe
                            C:\Windows\system32\nvvsvc.exe
                            C:\Windows\system32\svchost.exe
                            C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
                            C:\Program Files\BitDefender\BitDefender 2010\vsserv.exe
                            C:\Windows\System32\svchost.exe
                            C:\Windows\System32\svchost.exe
                            C:\Windows\system32\svchost.exe
                            C:\Windows\system32\svchost.exe
                            C:\Windows\system32\SLsvc.exe
                            C:\Windows\system32\svchost.exe
                            C:\Windows\system32\nvvsvc.exe
                            C:\Windows\system32\svchost.exe
                            C:\Program Files\BitDefender\BitDefender 2010\bdagent.exe
                            C:\Windows\System32\spoolsv.exe
                            C:\Windows\system32\svchost.exe
                            C:\Windows\system32\taskeng.exe
                            C:\Windows\system32\taskeng.exe
                            C:\Windows\system32\Dwm.exe
                            C:\Windows\Explorer.EXE
                            C:\Program Files\Windows Sidebar\sidebar.exe
                            C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                            C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
                            C:\Program Files\Packard Bell\Packard Bell Recovery Management\Service\ETService.exe
                            c:\windows\system32\HidService.exe
                            C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
                            C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
                            C:\Windows\system32\IoctlSvc.exe
                            C:\Windows\system32\svchost.exe
                            C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                            C:\Windows\system32\svchost.exe
                            C:\Windows\System32\svchost.exe
                            C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
                            C:\Windows\system32\SearchIndexer.exe
                            C:\Program Files\BitDefender\BitDefender 2010\seccenter.exe
                            C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
                            C:\Program Files\Windows Media Player\wmpnscfg.exe
                            C:\Program Files\Windows Media Player\wmpnetwk.exe
                            C:\Windows\system32\wbem\unsecapp.exe
                            C:\Windows\system32\wbem\wmiprvse.exe
                            C:\Windows\system32\conime.exe
                            C:\Program Files\List_Kill'em\List_Kill'em.scr
                            C:\Windows\system32\cmd.exe
                            C:\Windows\system32\SearchProtocolHost.exe
                            C:\Windows\system32\SearchFilterHost.exe
                            C:\Windows\system32\wbem\wmiprvse.exe
                            C:\Users\Bat\AppData\Local\Temp\E31F.tmp\ERUNT.EXE
                            C:\Users\Bat\AppData\Local\Temp\E31F.tmp\pv.exe

                            Detections :
                            ==========

                            ¤¤¤¤¤¤¤¤¤¤ Files/folders :

                            ==============
                            host file OK !
                            ==============

                            ========
                            Registry
                            ========

                            Deleted : HKCR\ezUPBHook.ShellObj
                            Deleted : HKCR\ezUPBHook.ShellObj.1
                            Deleted : HKCR\TypeLib\{478CAB91-9E28-11D4-97FF-0050047D51FB}
                            Deleted : HKCU\Software\mc
                            Deleted : HKLM\Software\Classes\Interface\{01009AEC-AFAA-4982-9F2B-6411C5C27E77}
                            ========
                            Services
                            =========

                            Ndisuio : Start = 3
                            EapHost : Start = 2
                            Wlansvc : Start = 2
                            SharedAccess : Start = 2
                            windefend : Start = 2
                            wuauserv : Start = 2
                            wscsvc : Start = 2

                            ============
                            Disk Cleaned
                            ============

                            ================
                            Prefetch cleaned
                            ================

                            ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
                            1. lien otl:
                              http://www.cijoint.fr/cjlink.php?file=cj201002/cijHiXJhKZ.txt

                              lien extra:
                              http://www.cijoint.fr/cjlink.php?file=cj201002/cijeFl4B3W.txt
                              1. relance List_Kill'em option 3 = desinstaller

                                ensuite :

                                desinstalle AD-Remover

                                ensuite :


                                ▶ Télécharge Zeb-Restoreet enregistre ce fichier sur le bureau.

                                ▶-Clic droit Zeb-Restore.zip ==> Extraire tout choisis comme lieu d'enregistrement le bureau.

                                ▶-Ouvre le dossier ZR_1.0.0.37 ==> clic droit "executer en tant qu'administrateur" sur Zeb-Restore.exe

                                ▶- Coche la case devant : sites de confiance

                                ▶- Ne coche aucune autre case

                                ▶-Clique sur Restaurer

                                ▶-Redémarre ton PC

                                ensuite :

                                ▶ Clique sur le menu Demarrer /Panneau de configuration/Options des dossiers/ puis dans l'onglet Affichage
                                * - Coche Afficher les fichiers et dossiers cachés
                                * - Décoche Masquer les extensions des fichiers dont le type est connu
                                * - Décoche Masquer les fichiers protégés du système d'exploitation (recommandé)

                                ▶ clique sur Appliquer, puis OK.

                                N'oublie pas de recacher à nouveau les fichiers cachés et protégés du système d'exploitation en fin de désinfection, c'est important

                                Fais analyser le(s) fichier(s) suivants sur Virustotal :

                                Virus Total

                                * Clique sur Parcourir en haut, choisis Poste de travail et cherche ces fichiers :

                                C:\Windows\System32\drivers\SPC530.sys
                                C:\Windows\System32\drivers\SPC530m.sys
                                C:\Windows\System32\gpyapi.dll

                                * Clique maintenant sur Envoyer le fichier. et laisse travailler tant que "Situation actuelle : en cours d'analyse" est affiché.
                                * Il est possible que le fichier soit mis en file d'attente en raison d'un grand nombre de demandes d'analyses. En ce cas, il te faudra patienter sans actualiser la page.
                                * Lorsque l'analyse est terminée ("Situation actuelle: terminé"), clique sur Formaté
                                * Une nouvelle fenêtre de ton navigateur va apparaître
                                * Clique alors sur les deux fleches
                                * Fais un clic droit sur la page, et choisis Sélectionner tout, puis copier
                                * Enfin colle le résultat dans ta prochaine réponse.

                                Note : Pour analyser un autre fichier, clique en bas sur Autre fichier.

                                ensuite :

                                ▶ clic droit "executer en tant qu'administrateur" sur OTL.exe pour le lancer.

                                ▶Copie la liste qui se trouve en gras ci-dessous,

                                ▶ colle-la dans la zone sous Customs Scans/Fixes :

                                :processes
                                explorer.exe
                                iexplore.exe
                                firefox.exe
                                msnmsgr.exe
                                Teatimer.exe

                                :services
                                Norton Internet Security
                                NAVEX15
                                NAVENG

                                :OTL
                                FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}:6.0.07
                                FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13
                                FF - prefs.js..extensions.enabledItems: 5
                                FF - prefs.js..extensions.enabledItems: 0
                                FF - prefs.js..extensions.enabledItems: 1
                                O4 - HKLM..\Run: [eRecoveryService] File not found
                                O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13)

                                :commands
                                [emptytemp]
                                [start explorer]
                                [reboot]


                                ▶ Clique sur RunFix pour lancer la suppression.

                                ▶ Poste le rapport.
                                1. avant ça, tu peux quand même m'expliquer ce qu'on est en train de faire parce que la je vois pas du tout où on va
                                  • 1
                                  • 2