Se connecter avec
S'enregistrer | Connectez-vous

Google

Dernière réponse : dans Sécurité
Lassé par la pub ? Créez un compte

je veux dire que je n'arrive pas à lancer une recherche sur google que se soit avec IE, Mozilla et Opéra. Il ne lance pas la recherche mais j'ai tout fait niveau virus spyware et autres.
Merci de votre aide !

On va voir..

Télécharge Hijackthis (de Trend Micro) sur ton Bureau.

  • Double clique sur HJTInstall.exe pour lancer l'installation.
  • Clique sur Install.
  • Double clique sur le raccourci d'HijackThis qui vient d'être créé pour le lancer.
  • Accepte la licence en cliquant sur Yes.
  • Clique sur "Do a system scan and save a logfile".
  • Poste ici le rapport généré.

    Note : Le rapport se trouve également ici : C:\Program Files\Trend Micro\Hijackthis\Hijackthis.log

    Aide : Comment utiliser HijackThis.

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 18:20:30, on 02/06/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Windows Defender\MsMpEng.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
    C:\WINDOWS\system32\cisvc.exe
    C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
    C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
    C:\Program Files\Fichiers communs\Symantec Shared\AppCore\AppSvc32.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
    C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
    C:\WINDOWS\system32\Rundll32.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Real\RealPlayer\realplay.exe
    C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
    C:\Program Files\Symantec\LiveUpdate\AUPDATE.EXE
    C:\Program Files\Norton Internet Security\Norton AntiVirus\NAVW32.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
    C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://89.188.16.31/index.html/?cmp=aff&lid=pcrshareres...
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Fichiers communs\Symantec Shared\coShared\Browser\1.5\UIBHO.dll
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
    O4 - HKLM\..\Run: [LXCFCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCFtime.dll,_RunDLLEntry@16
    O4 - HKLM\..\Run: [ccApp] C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [BM3fa96d89] Rundll32.exe "C:\WINDOWS\system32\jbecpbvm.dll",s
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [DWQueuedReporting] "C:\PROGRA~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe" -t
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user')
    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
    O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
    O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
    O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
    O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/Install...
    O16 - DPF: Interface Chat Voila - http://chat4.x-echo.com/version8/Applet/vchatsign.cab
    O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} - http://downloads.ewido.net/ewidoOnlineScan.cab
    O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} - http://messenger.zone.msn.com/binary/msgrchkr.cab56986....
    O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.ca...
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Cont...
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Contro...
    O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} - http://ubsyle.spaces.live.com/PhotoUpload/MsnPUpld.cab
    O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - http://fichiers.touslesdrivers.com/fichiers/hardwaredet...
    O16 - DPF: {B020B534-4AA2-4B99-BD6D-5F6EE286DF5C} - http://espaceabonnes.club-internet.fr/services/symantec...
    O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} - http://messenger.msn.com/download/MsnMessengerSetupDown...
    O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game11.zylom.com/activex/zylomgamesplayer.cab
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - http://messenger.zone.msn.com/binary/MessengerStatsPACl...
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/fl...
    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
    O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
    O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\VAScanner\comHost.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
    O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
    O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
    O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
    O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
    O23 - Service: lxcf_device - - C:\WINDOWS\system32\lxcfcoms.exe
    O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
    O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
    O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
    O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
    O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\AppCore\AppSvc32.exe
    O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe

    --
    End of file - 10328 bytes

    Je vois.

    Télécharge ComboFix (de sUBs) sur ton Bureau.

  • Désactive temporairement toute protection résidente ! (Antivirus, antispywares..)
  • Double clique sur ComboFix.exe.
  • Accepte la licence en cliquant sur Oui.
  • Lorsque l'opération sera terminée, un rapport apparaîtra. Poste ce rapport dans ta prochaine réponse.

    Le rapport se trouve ici : %systemdrive%\ComboFix.txt (%systemdrive% étant la partition où est installée Windows; C:\ en général)

    Aide : Comment utiliser ComboFix.

    ComboFix 08-06-01.6 - 7Assal 2008-06-03 18:29:14.1 - NTFSx86
    Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.479 [GMT 2:00]
    Endroit: C:\Documents and Settings\7Assal\Bureau\ComboFix.exe
    * Création d'un nouveau point de restauration

    AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
    .

    (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
    .

    C:\check_LSA7.txt
    C:\Program Files\LiveProtect
    C:\Program Files\LiveProtect\LiveProtect.exe
    C:\WINDOWS\BM3fa96d89.xml
    C:\WINDOWS\cookies.ini
    C:\WINDOWS\Fonts\a.zip
    C:\WINDOWS\pack.epk
    C:\WINDOWS\pskt.ini
    C:\WINDOWS\system32\adssite-remove.exe
    C:\WINDOWS\system32\akoflrji.ini
    C:\WINDOWS\system32\alwptpas.ini
    C:\WINDOWS\system32\ancklgey.ini
    C:\WINDOWS\system32\anignjul.dll
    C:\WINDOWS\system32\ariqplia.ini
    C:\WINDOWS\system32\bcnhhhgr.dll
    C:\WINDOWS\system32\begryogq.ini
    C:\WINDOWS\system32\bvtfuvef.ini
    C:\WINDOWS\system32\byXOhGAp.dll
    C:\WINDOWS\system32\cbeeg.bak1
    C:\WINDOWS\system32\cbeeg.bak2
    C:\WINDOWS\system32\cbeeg.ini
    C:\WINDOWS\system32\cbeeg.ini2
    C:\WINDOWS\system32\cbeeg.tmp
    C:\WINDOWS\system32\cbeeg.tmp2
    C:\WINDOWS\system32\cbXqopQk.dll
    C:\WINDOWS\system32\cnsfxwoi.ini
    C:\WINDOWS\system32\ctoimlvk.ini
    C:\WINDOWS\system32\cylhjqjh.dll
    C:\WINDOWS\system32\dauremly.dll
    C:\WINDOWS\system32\dcads-remove.exe
    C:\WINDOWS\system32\DeOWxyxx.ini
    C:\WINDOWS\system32\DeOWxyxx.ini2
    C:\WINDOWS\system32\dflrcftj.dll
    C:\WINDOWS\system32\din.ip
    C:\WINDOWS\system32\doholdjx.ini
    C:\WINDOWS\system32\drivers\bg_bg.gif
    C:\WINDOWS\system32\drivers\blank.gif
    C:\WINDOWS\system32\drivers\box_1.gif
    C:\WINDOWS\system32\drivers\box_2.gif
    C:\WINDOWS\system32\drivers\box_3.gif
    C:\WINDOWS\system32\drivers\button_buynow.gif
    C:\WINDOWS\system32\drivers\button_freescan.gif
    C:\WINDOWS\system32\drivers\cell_bg.gif
    C:\WINDOWS\system32\drivers\cell_footer.gif
    C:\WINDOWS\system32\drivers\cell_header_block.gif
    C:\WINDOWS\system32\drivers\cell_header_remove.gif
    C:\WINDOWS\system32\drivers\cell_header_scan.gif
    C:\WINDOWS\system32\drivers\close_ico.gif
    C:\WINDOWS\system32\drivers\detect.htm
    C:\WINDOWS\system32\drivers\download_box.gif
    C:\WINDOWS\system32\drivers\download_btn.jpg
    C:\WINDOWS\system32\drivers\download_now_btn.gif
    C:\WINDOWS\system32\drivers\footer_back.jpg
    C:\WINDOWS\system32\drivers\header_1.gif
    C:\WINDOWS\system32\drivers\header_2.gif
    C:\WINDOWS\system32\drivers\header_3.gif
    C:\WINDOWS\system32\drivers\header_4.gif
    C:\WINDOWS\system32\drivers\header_red_bg.gif
    C:\WINDOWS\system32\drivers\header_red_free_scan.gif
    C:\WINDOWS\system32\drivers\header_red_free_scan_bg.gif
    C:\WINDOWS\system32\drivers\header_red_protect_your_pc.gif
    C:\WINDOWS\system32\drivers\icon_warning_big.gif
    C:\WINDOWS\system32\drivers\infected.gif
    C:\WINDOWS\system32\drivers\main_back.gif
    C:\WINDOWS\system32\drivers\perfect_cleaner_box.jpg
    C:\WINDOWS\system32\drivers\product_1_header.gif
    C:\WINDOWS\system32\drivers\product_1_name_small.gif
    C:\WINDOWS\system32\drivers\product_2_header.gif
    C:\WINDOWS\system32\drivers\product_2_name_small.gif
    C:\WINDOWS\system32\drivers\product_3_header.gif
    C:\WINDOWS\system32\drivers\product_3_name_small.gif
    C:\WINDOWS\system32\drivers\product_features.gif
    C:\WINDOWS\system32\drivers\pt.htm
    C:\WINDOWS\system32\drivers\rating.gif
    C:\WINDOWS\system32\drivers\s_detect.htm
    C:\WINDOWS\system32\drivers\screenshot.jpg
    C:\WINDOWS\system32\drivers\sep_hor.gif
    C:\WINDOWS\system32\drivers\sep_vert.gif
    C:\WINDOWS\system32\drivers\shadow.jpg
    C:\WINDOWS\system32\drivers\shadow_bg.gif
    C:\WINDOWS\system32\drivers\spacer.gif
    C:\WINDOWS\system32\drivers\star.gif
    C:\WINDOWS\system32\drivers\star_gray.gif
    C:\WINDOWS\system32\drivers\star_gray_small.gif
    C:\WINDOWS\system32\drivers\star_small.gif
    C:\WINDOWS\system32\drivers\style.css
    C:\WINDOWS\system32\drivers\v.gif
    C:\WINDOWS\system32\drivers\warning_ico.gif
    C:\WINDOWS\system32\drivers\warning_icon.gif
    C:\WINDOWS\system32\drivers\win_logo.gif
    C:\WINDOWS\system32\drivers\x.gif
    C:\WINDOWS\system32\drivers\yellow_warning_ico.gif
    C:\WINDOWS\system32\eivnmfev.ini
    C:\WINDOWS\system32\ersefkwr.ini
    C:\WINDOWS\system32\fbcjhwoe.ini
    C:\WINDOWS\system32\fdqtiids.ini
    C:\WINDOWS\system32\fhftjmtb.ini
    C:\WINDOWS\system32\fnwomyhm.dll
    C:\WINDOWS\system32\gbruwuab.ini
    C:\WINDOWS\system32\gtv_sd.bin
    C:\WINDOWS\system32\gwyadino.dll
    C:\WINDOWS\system32\hbywxghx.ini
    C:\WINDOWS\system32\hcvafuys.dll
    C:\WINDOWS\system32\hixrveaq.ini
    C:\WINDOWS\system32\hjkmp.bak1
    C:\WINDOWS\system32\hjkmp.ini
    C:\WINDOWS\system32\hocbwcbg.ini
    C:\WINDOWS\system32\hwetkrqp.ini
    C:\WINDOWS\system32\ifbuckir.ini
    C:\WINDOWS\system32\iifefeda.dll
    C:\WINDOWS\system32\itklvupq.ini
    C:\WINDOWS\system32\jbecpbvm.dll
    C:\WINDOWS\system32\jnmjthdg.ini
    C:\WINDOWS\system32\jtfcrlfd.ini
    C:\WINDOWS\system32\kfeiargn.ini
    C:\WINDOWS\system32\krcddlvs.dll
    C:\WINDOWS\system32\lgfqubox.ini
    C:\WINDOWS\system32\lhyabcbe.dll
    C:\WINDOWS\system32\LiveProtectSetup.exe
    C:\WINDOWS\system32\ljJDUklj.dll
    C:\WINDOWS\system32\mcrh.tmp
    C:\WINDOWS\system32\mhymownf.ini
    C:\WINDOWS\system32\mlorlntg.ini
    C:\WINDOWS\system32\MSINET.oca
    C:\WINDOWS\system32\mwaqwdpt.ini
    C:\WINDOWS\system32\ngonbdnj.ini
    C:\WINDOWS\system32\nhiwycnh.ini
    C:\WINDOWS\system32\nnalukpx.ini
    C:\WINDOWS\system32\nnnoOiij.dll
    C:\WINDOWS\system32\nuyrnpjy.dll
    C:\WINDOWS\system32\ofmanabq.ini
    C:\WINDOWS\system32\okiyakbq.ini
    C:\WINDOWS\system32\onnmp.bak1
    C:\WINDOWS\system32\onnmp.bak2
    C:\WINDOWS\system32\onnmp.ini
    C:\WINDOWS\system32\onnmp.ini2
    C:\WINDOWS\system32\onnmp.tmp
    C:\WINDOWS\system32\oojbbinh.ini
    C:\WINDOWS\system32\oqnzsj.dat
    C:\WINDOWS\system32\oqnzsj_nav.dat
    C:\WINDOWS\system32\oqnzsj_navps.dat
    C:\WINDOWS\system32\oxqugknf.ini
    C:\WINDOWS\system32\ppyplvym.ini
    C:\WINDOWS\system32\pxkmaxwy.ini
    C:\WINDOWS\system32\pYyIRqru.ini
    C:\WINDOWS\system32\pYyIRqru.ini2
    C:\WINDOWS\system32\qiybciik.ini
    C:\WINDOWS\system32\qjuajgmq.ini
    C:\WINDOWS\system32\qkdrnksj.ini
    C:\WINDOWS\system32\qoMccbaw.dll
    C:\WINDOWS\system32\rightonadz-uninst.exe
    C:\WINDOWS\system32\rnbeykex.ini
    C:\WINDOWS\system32\rqrwhncw.ini
    C:\WINDOWS\system32\sftvonvg.dll
    C:\WINDOWS\system32\srmispmm.ini
    C:\WINDOWS\system32\srwnxroi.ini
    C:\WINDOWS\system32\sznf.ascii
    C:\WINDOWS\system32\tcxwqjgu.ini
    C:\WINDOWS\system32\ugdqopie.dll
    C:\WINDOWS\system32\ukbboldx.ini
    C:\WINDOWS\system32\urqRIyYp.dll
    C:\WINDOWS\system32\veqpjxow.ini
    C:\WINDOWS\system32\vsiwjkup.ini
    C:\WINDOWS\system32\wabccMoq.ini
    C:\WINDOWS\system32\wabccMoq.ini2
    C:\WINDOWS\system32\wctytjxd.ini
    C:\WINDOWS\system32\wicdtvao.dll
    C:\WINDOWS\system32\wlxkukcn.ini
    C:\WINDOWS\system32\woaykosp.ini
    C:\WINDOWS\system32\woxjpqev.dll
    C:\WINDOWS\system32\xlelesct.dll
    C:\WINDOWS\system32\xmrqvibs.ini
    C:\WINDOWS\system32\xoltwjma.dll
    C:\WINDOWS\system32\xqqovbki.ini
    C:\WINDOWS\system32\xyimtwvt.ini
    C:\WINDOWS\system32\xyowapdk.ini
    C:\WINDOWS\system32\yayyYrqn.dll
    C:\WINDOWS\system32\ycivyjav.ini
    C:\WINDOWS\system32\ycobuhug.ini
    C:\WINDOWS\system32\yjpnryun.ini
    C:\WINDOWS\system32\ykwuctim.ini
    C:\WINDOWS\system32\yyxxlvtq.ini

    .
    ((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-05-03 to 2008-06-03 ))))))))))))))))))))))))))))))))))))
    .

    2008-06-03 18:15 . 2008-06-03 18:15 <REP> d-------- C:\Documents and Settings\7Assal\Application Data\ATI
    2008-06-03 18:14 . 2005-09-26 20:11 <REP> d--h----- C:\Documents and Settings\7Assal\Voisinage r‚seau
    2008-06-03 18:14 . 2005-09-26 20:11 <REP> d--h----- C:\Documents and Settings\7Assal\Voisinage d'impression
    2008-06-03 18:14 . 2008-03-24 22:07 <REP> d--h----- C:\Documents and Settings\7Assal\ModŠles
    2008-06-03 18:14 . 2008-06-03 18:17 <REP> d---s---- C:\Documents and Settings\7Assal\Mes documents
    2008-06-03 18:14 . 2005-09-26 20:11 <REP> dr------- C:\Documents and Settings\7Assal\Menu D‚marrer
    2008-06-03 18:14 . 2008-06-03 18:14 <REP> d---s---- C:\Documents and Settings\7Assal\Favoris
    2008-06-03 18:14 . 2008-06-03 18:25 <REP> d-------- C:\Documents and Settings\7Assal\Bureau
    2008-06-03 18:14 . 2008-06-03 18:14 <REP> d-------- C:\Documents and Settings\7Assal
    2008-06-01 21:03 . 2008-06-01 21:03 <REP> d-------- C:\Program Files\Alwil Software
    2008-06-01 20:44 . 2008-06-01 21:21 <REP> d-------- C:\Program Files\Opera
    2008-06-01 20:44 . 2008-06-01 20:44 <REP> d-------- C:\Documents and Settings\$7Assal$_2\Application Data\Opera
    2008-06-01 20:43 . 2008-06-01 20:43 <REP> d-------- C:\Documents and Settings\$7Assal$_2\Application Data\Talkback
    2008-06-01 20:38 . 2008-06-01 20:38 <REP> d-------- C:\Documents and Settings\$7Assal$_2\Application Data\Mozilla
    2008-06-01 19:51 . 2008-06-01 19:51 <REP> d-------- C:\Documents and Settings\$7Assal$_2\Application Data\TuneUp Software
    2008-06-01 19:51 . 2008-06-01 19:51 354,560 --a------ C:\WINDOWS\system32\TuneUpDefragService.exe
    2008-06-01 19:51 . 2008-04-04 14:51 28,416 --a------ C:\WINDOWS\system32\uxtuneup.dll
    2008-06-01 19:50 . 2008-06-01 19:51 <REP> d-------- C:\Program Files\TuneUp Utilities 2008
    2008-06-01 19:50 . 2008-06-01 19:50 <REP> d-------- C:\Documents and Settings\All Users\Application Data\TuneUp Software
    2008-06-01 19:49 . 2008-06-01 19:49 <REP> d-------- C:\Program Files\Fichiers communs\Wise Installation Wizard
    2008-06-01 19:48 . 2008-06-01 20:00 <REP> d-------- C:\Documents and Settings\$7Assal$_2\Application Data\BitTorrent
    2008-06-01 11:05 . 2008-06-01 11:05 230 --a------ C:\WINDOWS\system32\spupdsvc.inf
    2008-05-31 23:15 . 2008-05-31 23:15 <REP> d-------- C:\Program Files\Counter Strike Condition Zero
    2008-05-31 19:04 . 2008-06-02 19:25 <REP> d-------- C:\Documents and Settings\$7Assal$_2\Application Data\Winamp
    2008-05-31 15:23 . 2008-05-31 15:23 <REP> d-------- C:\Documents and Settings\$7Assal$_2\Application Data\DivX
    2008-05-31 15:23 . 2008-06-01 19:24 <REP> d-------- C:\Documents and Settings\$7Assal$_2\Application Data\Ahead
    2008-05-31 13:17 . 2008-05-31 13:17 <REP> d-------- C:\Documents and Settings\Souad.UVHC-1D\Application Data\ATI
    2008-05-31 13:11 . 2008-06-02 19:07 <REP> d--hs---- C:\Documents and Settings\$7Assal$_2\Recent
    2008-05-31 13:09 . 2005-09-26 20:11 <REP> d--h----- C:\Documents and Settings\Souad.UVHC-1D\Voisinage r‚seau
    2008-05-31 13:09 . 2005-09-26 20:11 <REP> d--h----- C:\Documents and Settings\Souad.UVHC-1D\Voisinage d'impression
    2008-05-31 13:09 . 2008-03-24 22:07 <REP> d--h----- C:\Documents and Settings\Souad.UVHC-1D\ModŠles
    2008-05-31 13:09 . 2008-05-31 13:17 <REP> d---s---- C:\Documents and Settings\Souad.UVHC-1D\Mes documents
    2008-05-31 13:09 . 2005-09-26 20:11 <REP> dr------- C:\Documents and Settings\Souad.UVHC-1D\Menu D‚marrer
    2008-05-31 13:09 . 2008-05-31 13:17 <REP> d---s---- C:\Documents and Settings\Souad.UVHC-1D\Favoris
    2008-05-31 13:09 . 2005-09-26 20:11 <REP> d-------- C:\Documents and Settings\Souad.UVHC-1D\Bureau
    2008-05-31 13:09 . 2008-06-01 10:16 <REP> d-------- C:\Documents and Settings\Souad.UVHC-1D
    2008-05-31 11:48 . 2008-05-31 11:48 <REP> d-------- C:\Documents and Settings\$7Assal$_2\Application Data\Google
    2008-05-31 11:48 . 2008-05-31 20:11 <REP> d-------- C:\Documents and Settings\$7Assal$_2\Application Data\Adobe
    2008-05-31 11:06 . 2008-05-31 11:06 <REP> d-------- C:\Documents and Settings\$7Assal$_2\Application Data\Apple Computer
    2008-05-31 10:37 . 2008-05-31 10:37 <REP> d-------- C:\Documents and Settings\$7Assal$_2\Application Data\Macromedia
    2008-05-31 09:54 . 2008-05-31 11:56 <REP> d-------- C:\Documents and Settings\$7Assal$_2\Application Data\Real
    2008-05-31 09:54 . 2008-05-31 09:54 <REP> d-------- C:\Documents and Settings\$7Assal$_2\Application Data\ATI
    2008-05-31 09:53 . 2005-09-26 20:11 <REP> d--h----- C:\Documents and Settings\$7Assal$_2\Voisinage r‚seau
    2008-05-31 09:53 . 2005-09-26 20:11 <REP> d--h----- C:\Documents and Settings\$7Assal$_2\Voisinage d'impression
    2008-05-31 09:53 . 2008-05-31 09:53 <REP> dr-h----- C:\Documents and Settings\$7Assal$_2\SendTo
    2008-05-31 09:53 . 2008-03-24 22:07 <REP> d--h----- C:\Documents and Settings\$7Assal$_2\ModŠles
    2008-05-31 09:53 . 2008-06-03 18:46 <REP> d--h----- C:\Documents and Settings\$7Assal$_2\Local Settings
    2008-05-31 09:53 . 2008-06-01 21:21 <REP> d---s---- C:\Documents and Settings\$7Assal$_2\Application Data\Microsoft
    2008-05-31 09:53 . 2008-06-01 20:44 <REP> dr-h----- C:\Documents and Settings\$7Assal$_2\Application Data
    2008-05-31 09:53 . 2008-06-03 18:22 <REP> d-------- C:\Documents and Settings\$7Assal$_2
    2008-05-31 09:53 . 2008-06-03 18:48 4,194,304 --a------ C:\Documents and Settings\$7Assal$_2\NTUSER.DAT
    2008-05-30 18:04 . 2008-05-30 18:08 <REP> d-------- C:\Program Files\iPod Music Liberator
    2008-05-29 20:26 . 2008-05-29 21:56 <REP> dr-hs---- C:\WINDOWS\Downloaded PROGRESSION Files
    2008-05-29 19:46 . 2008-05-29 19:46 0 --a------ C:\WINDS
    2008-05-29 19:46 . 2008-05-29 19:46 0 --a------ C:\COMS
    2008-05-29 19:39 . 2008-05-29 19:39 262,144 --------- C:\WINDOWS\Setup1.exe
    2008-05-29 19:39 . 2008-05-29 19:39 74,752 --a------ C:\WINDOWS\ST6UNST.EXE
    2008-05-25 12:50 . 2008-05-25 13:00 <REP> d-------- C:\Program Files\EA Sports
    2008-05-20 21:01 . 2004-02-04 10:27 49,536 --a------ C:\WINDOWS\system32\drivers\tiehdusb.sys
    2008-05-20 21:01 . 2004-01-28 15:03 21,456 --a------ C:\WINDOWS\system32\drivers\SilvrLnk.sys
    2008-05-20 20:55 . 2008-05-21 19:12 <REP> d-------- C:\Program Files\TI Education
    2008-05-18 21:28 . 2008-05-18 21:30 <REP> d-------- C:\WINDOWS\system32\CatRoot_bak
    2008-05-18 18:53 . 2008-05-29 11:26 <REP> d-------- C:\Program Files\Lx_cats
    2008-05-18 18:53 . 2008-05-18 18:53 12,675 --a------ C:\WINDOWS\system32\LexFiles.ulf
    2008-05-18 18:51 . 2008-05-20 19:27 <REP> d-------- C:\TEMP\{9F5FBC24-EFE2-4f90-B498-EC0FB7D47D15}
    2008-05-18 18:51 . 2008-05-18 18:53 <REP> d-------- C:\Program Files\Lexmark 730 Series
    2008-05-13 18:57 . 2008-05-13 18:57 <REP> d-------- C:\Program Files\Radical Games
    2008-05-12 15:33 . 2008-05-12 15:35 <REP> d-------- C:\Program Files\Fichiers communs\Ahead
    2008-05-08 12:52 . 2008-06-03 18:15 54,156 --ah----- C:\WINDOWS\QTFont.qfn
    2008-05-08 12:52 . 2008-06-02 18:47 1,409 --a------ C:\WINDOWS\QTFont.for
    2008-05-08 12:50 . 2008-05-08 12:50 <REP> d-------- C:\Program Files\iPod
    2008-05-07 20:12 . 2008-05-07 20:12 <REP> d-------- C:\Program Files\Visicom Media
    2008-05-07 20:12 . 2008-05-07 20:12 <REP> d-------- C:\Documents and Settings\All Users\Application Data\EmailNotifier
    2008-05-04 15:48 . 2008-05-04 15:49 <REP> d-------- C:\Program Files\Winamp
    2008-05-04 15:25 . 2008-05-04 15:25 <REP> d-------- C:\Program Files\Pegasys Inc
    2008-05-04 13:43 . 2008-05-31 11:10 1,374 --a------ C:\WINDOWS\imsins.BAK

    .
    (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2008-06-03 16:47 --------- d-----w C:\Program Files\Fichiers communs\Symantec Shared
    2008-06-02 17:27 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
    2008-06-01 09:19 --------- d-----w C:\Program Files\Spybot - Search & Destroy
    2008-06-01 09:13 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
    2008-06-01 09:07 --------- d-----w C:\Program Files\Google
    2008-06-01 09:00 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
    2008-05-31 09:21 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
    2008-05-21 17:10 --------- d--h--w C:\Program Files\InstallShield Installation Information
    2008-05-12 13:33 --------- d-----w C:\Program Files\Nero
    2008-05-12 13:33 --------- d-----w C:\Documents and Settings\All Users\Application Data\Nero
    2008-05-08 17:42 --------- dcsh--w C:\Program Files\Fichiers communs\WindowsLiveInstaller
    2008-05-08 17:35 --------- d-----w C:\Program Files\Windows Live
    2008-05-08 17:14 --------- d-----w C:\Program Files\Messenger Plus! Live
    2008-05-08 17:02 --------- d-----w C:\Program Files\Apple Software Update
    2008-05-08 11:32 --------- d-----w C:\Program Files\LimeWire
    2008-05-08 10:51 --------- d-----w C:\Program Files\iTunes
    2008-05-08 10:45 --------- d-----w C:\Program Files\QuickTime
    2008-05-07 18:06 --------- d-----w C:\Program Files\DivX
    2008-05-04 13:22 --------- d-----w C:\Program Files\Fichiers communs\Adobe
    2008-05-01 18:53 --------- d-----w C:\Program Files\Trend Micro
    2008-05-01 17:52 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
    2008-05-01 15:07 --------- d-----w C:\Program Files\Windows Defender
    2008-05-01 14:53 --------- d-----w C:\Program Files\Java
    2008-05-01 14:52 --------- d-----w C:\Program Files\Fichiers communs\Java
    2008-05-01 13:09 --------- d-----w C:\Program Files\Marvell
    2008-05-01 12:16 --------- d-----w C:\Program Files\Intel Desktop Board
    2008-05-01 00:59 --------- d-----w C:\Program Files\Belkin
    2008-04-30 23:19 --------- d-----w C:\Program Files\MSECACHE
    2008-04-30 23:15 --------- d-----w C:\Program Files\Yahoo!
    2008-04-30 23:15 --------- d-----w C:\Program Files\CCleaner
    2007-02-12 17:33 774,144 ----a-w C:\Program Files\RngInterstitial.dll
    2005-09-29 09:51 74,448 ----a-w C:\Program Files\DSETUP.dll
    2005-09-29 09:51 2,245,840 ----a-w C:\Program Files\dsetup32.dll
    2005-09-29 09:51 15,493,481 ----a-w C:\Program Files\DirectX.cab
    2005-09-29 09:51 1,351,430 ----a-w C:\Program Files\Aug2005_d3dx9_27_x64.cab
    2005-09-29 09:51 1,078,532 ----a-w C:\Program Files\Aug2005_d3dx9_27_x86.cab
    2007-03-30 19:37 56 --sha-r C:\WINDOWS\system32\2CD320BD30.sys
    2007-06-23 16:25 4,182 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
    .

    ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    REGEDIT4
    *Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 14:00 15360]
    "ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" [2004-12-01 00:25 32768]
    "DWQueuedReporting"="C:\PROGRA~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 16:38 39264]
    "msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 11:34 5724184]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
    "NeroFilterCheck"="C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe" [2007-03-01 15:57 153136]
    "LXCFCATS"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCFtime.dll" [2005-07-20 12:47 73728]
    "ccApp"="C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe" [2007-02-19 19:25 115816]
    "TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [2008-02-23 15:35 185896]
    "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-05 14:00 15360]
    "ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" [2004-12-01 00:25 32768]
    "DWQueuedReporting"="C:\PROGRA~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 16:38 39264]
    "msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 11:34 5724184]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
    "tscuninstall"="C:\WINDOWS\system32\tscupgrd.exe" [2004-08-05 14:00 44544]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winrge32]
    winrge32.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
    "VIDC.ACDV"= ACDV.dll
    "vidc.iv32"= C:\WINDOWS\system32\ir32_32.dll
    "vidc.iv31"= C:\WINDOWS\system32\ir32_32.dll

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
    @=""

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
    "ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime
    "ATIPTA"=C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    "WinampAgent"="C:\Program Files\Winamp\winampa.exe"
    "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe"
    "Symantec PIF AlertEng"="C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
    "Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" -hide
    "TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
    "ccApp"="C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
    "DisableMonitoring"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "C:\\TEMP\\CI_HITACHI\\MAJ_Hitachi.exe"=
    "C:\\Program Files\\LimeWire\\LimeWire.exe"=
    "C:\\Program Files\\BitTorrent\\bittorrent.exe"=
    "C:\\WINDOWS\\system32\\CTF\\wscntfyr.exe"=
    "C:\\WINDOWS\\system32\\CTF\\nvidiadrv.exe"=
    "C:\\Program Files\\Messenger\\msmsgs.exe"=
    "C:\Program Files\Microsoft ActiveSync\rapimgr.exe"= C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
    "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"= C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
    "C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"= C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
    "C:\\Program Files\\DNA\\btdna.exe"=
    "<NO NAME>"=
    "C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
    "C:\\Program Files\\Adobe\\Acrobat 5.0\\Distillr\\acrodist.exe"=
    "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
    "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
    "C:\\Program Files\\iTunes\\iTunes.exe"=

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "11430:TCP"= 11430:TCP:BitComet 11430 TCP
    "11430:UDP"= 11430:UDP:BitComet 11430 UDP
    "26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

    R0 iteraid;ITERAID_Service_Install;C:\WINDOWS\system32\DRIVERS\iteraid.sys [2004-07-16 11:12]
    R0 tffsport;M-Systems DiskOnChip 2000;C:\WINDOWS\system32\DRIVERS\tffsport.sys [2004-08-05 14:00]
    R2 UxTuneUp;TuneUp Extension de thème;C:\WINDOWS\System32\svchost.exe [2004-08-05 14:00]
    S3 ntportio;ntportio;C:\Documents and Settings\euro-info\Bureau\pbbse12_crippled\pbbse12_crippled\ntportio.sys []
    S3 PRISM_USB;Dell TrueMobile 1180 Wireless USB Adapter;C:\WINDOWS\system32\DRIVERS\DELUSB_51.sys [2002-08-09 08:46]
    S3 SkLaggProtocol;Marvell Link Aggregation Protocol;C:\WINDOWS\system32\DRIVERS\yk51x32l.sys [2007-12-14 10:10]
    S3 SkVlanProtocol;Marvell VLAN Protocol;C:\WINDOWS\system32\DRIVERS\yk51x32v.sys [2007-11-23 10:10]
    S3 sonypvs1;Sony Digital Imaging Video2;C:\WINDOWS\system32\DRIVERS\sonypvs1.sys []
    S3 TuneUp.Defrag;TuneUp Drive Defrag Service;C:\WINDOWS\System32\TuneUpDefragService.exe [2008-06-01 19:51]
    S3 UsbSagCom;SAGEM Full USB Driver;C:\WINDOWS\system32\DRIVERS\UsbSagCom.sys [2006-04-07 16:18]

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
    UxTuneUp

    .
    Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
    "2008-05-08 10:36:07 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
    - C:\Program Files\Apple Software Update\SoftwareUpdate.exe
    "2008-06-03 16:50:11 C:\WINDOWS\Tasks\Maintenance en 1 clic.job"
    - C:\Program Files\TuneUp Utilities 2008\OneClickStarter.exe
    "2008-06-03 16:52:45 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
    - C:\Program Files\Windows Defender\MpCmdRun.exe
    "2008-06-02 18:00:00 C:\WINDOWS\Tasks\Norton Internet Security Online - Analyse système complète - assaad.job"

    Re,

    Sélectionne l'intégralité du cadre ci-dessous :

    Collect::
    C:\WINDOWS\System32\winrge32.dll
    C:\WINDOWS\system32\spupdsvc.inf
    C:\WINDS
    C:\COMS

    Registry::
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Adobe Reader Speed Launcher"=-
    "NeroFilterCheck"=-
    "TkBellExe"=-
    "iTunesHelper"=-
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winrge32]
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
    "WinampAgent"=-
    "iTunesHelper"=-
    "TkBellExe"=-


    Cela va relancer Combofix. Après redémarrage, poste le contenu du rapport ComboFix.txt.
    S'il n'y a pas de rédémarrage, poste quand même le rapport.

  • Copie/colle le dans le Bloc Notes (Démarrer\Tous les programmes\Accessoires\Bloc notes.)
  • Enregistre le sous sur ton bureau sous le nom de CFScript.txt
  • Glisse maintenant le fichier CFScript.txt dans ComboFix.exe comme ci-dessous :

  • Cela va relancer Combofix. Poste le contenu du rapport ComboFix.txt après redémarrage s'il y en a un.

    ComboFix 08-06-01.6 - 7Assal 2008-06-07 21:59:22.2 - NTFSx86
    Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.504 [GMT 2:00]
    Endroit: C:\Documents and Settings\7Assal\Bureau\ComboFix.exe
    Command switches used :: C:\Documents and Settings\7Assal\Bureau\CFScript.txt
    * Création d'un nouveau point de restauration

    AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
    .

    (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
    .

    C:\COMS
    C:\Documents and Settings\$7Assal$_2\Local Settings\Temporary Internet Files\
    C:\WINDOWS\system32\spupdsvc.inf
    C:\WINDS
    .
    ---- Previous Run -------
    .
    C:\check_LSA7.txt
    C:\Program Files\LiveProtect
    C:\Program Files\LiveProtect\LiveProtect.exe
    C:\WINDOWS\BM3fa96d89.xml
    C:\WINDOWS\cookies.ini
    C:\WINDOWS\Fonts\a.zip
    C:\WINDOWS\pack.epk
    C:\WINDOWS\pskt.ini
    C:\WINDOWS\system32\adssite-remove.exe
    C:\WINDOWS\system32\akoflrji.ini
    C:\WINDOWS\system32\alwptpas.ini
    C:\WINDOWS\system32\ancklgey.ini
    C:\WINDOWS\system32\anignjul.dll
    C:\WINDOWS\system32\ariqplia.ini
    C:\WINDOWS\system32\bcnhhhgr.dll
    C:\WINDOWS\system32\begryogq.ini
    C:\WINDOWS\system32\bvtfuvef.ini
    C:\WINDOWS\system32\byXOhGAp.dll
    C:\WINDOWS\system32\cbeeg.bak1
    C:\WINDOWS\system32\cbeeg.bak2
    C:\WINDOWS\system32\cbeeg.ini
    C:\WINDOWS\system32\cbeeg.ini2
    C:\WINDOWS\system32\cbeeg.tmp
    C:\WINDOWS\system32\cbeeg.tmp2
    C:\WINDOWS\system32\cbXqopQk.dll
    C:\WINDOWS\system32\cnsfxwoi.ini
    C:\WINDOWS\system32\ctoimlvk.ini
    C:\WINDOWS\system32\cylhjqjh.dll
    C:\WINDOWS\system32\dauremly.dll
    C:\WINDOWS\system32\dcads-remove.exe
    C:\WINDOWS\system32\DeOWxyxx.ini
    C:\WINDOWS\system32\DeOWxyxx.ini2
    C:\WINDOWS\system32\dflrcftj.dll
    C:\WINDOWS\system32\din.ip
    C:\WINDOWS\system32\doholdjx.ini
    C:\WINDOWS\system32\drivers\bg_bg.gif
    C:\WINDOWS\system32\drivers\blank.gif
    C:\WINDOWS\system32\drivers\box_1.gif
    C:\WINDOWS\system32\drivers\box_2.gif
    C:\WINDOWS\system32\drivers\box_3.gif
    C:\WINDOWS\system32\drivers\button_buynow.gif
    C:\WINDOWS\system32\drivers\button_freescan.gif
    C:\WINDOWS\system32\drivers\cell_bg.gif
    C:\WINDOWS\system32\drivers\cell_footer.gif
    C:\WINDOWS\system32\drivers\cell_header_block.gif
    C:\WINDOWS\system32\drivers\cell_header_remove.gif
    C:\WINDOWS\system32\drivers\cell_header_scan.gif
    C:\WINDOWS\system32\drivers\close_ico.gif
    C:\WINDOWS\system32\drivers\detect.htm
    C:\WINDOWS\system32\drivers\download_box.gif
    C:\WINDOWS\system32\drivers\download_btn.jpg
    C:\WINDOWS\system32\drivers\download_now_btn.gif
    C:\WINDOWS\system32\drivers\footer_back.jpg
    C:\WINDOWS\system32\drivers\header_1.gif
    C:\WINDOWS\system32\drivers\header_2.gif
    C:\WINDOWS\system32\drivers\header_3.gif
    C:\WINDOWS\system32\drivers\header_4.gif
    C:\WINDOWS\system32\drivers\header_red_bg.gif
    C:\WINDOWS\system32\drivers\header_red_free_scan.gif
    C:\WINDOWS\system32\drivers\header_red_free_scan_bg.gif
    C:\WINDOWS\system32\drivers\header_red_protect_your_pc.gif
    C:\WINDOWS\system32\drivers\icon_warning_big.gif
    C:\WINDOWS\system32\drivers\infected.gif
    C:\WINDOWS\system32\drivers\main_back.gif
    C:\WINDOWS\system32\drivers\perfect_cleaner_box.jpg
    C:\WINDOWS\system32\drivers\product_1_header.gif
    C:\WINDOWS\system32\drivers\product_1_name_small.gif
    C:\WINDOWS\system32\drivers\product_2_header.gif
    C:\WINDOWS\system32\drivers\product_2_name_small.gif
    C:\WINDOWS\system32\drivers\product_3_header.gif
    C:\WINDOWS\system32\drivers\product_3_name_small.gif
    C:\WINDOWS\system32\drivers\product_features.gif
    C:\WINDOWS\system32\drivers\pt.htm
    C:\WINDOWS\system32\drivers\rating.gif
    C:\WINDOWS\system32\drivers\s_detect.htm
    C:\WINDOWS\system32\drivers\screenshot.jpg
    C:\WINDOWS\system32\drivers\sep_hor.gif
    C:\WINDOWS\system32\drivers\sep_vert.gif
    C:\WINDOWS\system32\drivers\shadow.jpg
    C:\WINDOWS\system32\drivers\shadow_bg.gif
    C:\WINDOWS\system32\drivers\spacer.gif
    C:\WINDOWS\system32\drivers\star.gif
    C:\WINDOWS\system32\drivers\star_gray.gif
    C:\WINDOWS\system32\drivers\star_gray_small.gif
    C:\WINDOWS\system32\drivers\star_small.gif
    C:\WINDOWS\system32\drivers\style.css
    C:\WINDOWS\system32\drivers\v.gif
    C:\WINDOWS\system32\drivers\warning_ico.gif
    C:\WINDOWS\system32\drivers\warning_icon.gif
    C:\WINDOWS\system32\drivers\win_logo.gif
    C:\WINDOWS\system32\drivers\x.gif
    C:\WINDOWS\system32\drivers\yellow_warning_ico.gif
    C:\WINDOWS\system32\eivnmfev.ini
    C:\WINDOWS\system32\ersefkwr.ini
    C:\WINDOWS\system32\fbcjhwoe.ini
    C:\WINDOWS\system32\fdqtiids.ini
    C:\WINDOWS\system32\fhftjmtb.ini
    C:\WINDOWS\system32\fnwomyhm.dll
    C:\WINDOWS\system32\gbruwuab.ini
    C:\WINDOWS\system32\gtv_sd.bin
    C:\WINDOWS\system32\gwyadino.dll
    C:\WINDOWS\system32\hbywxghx.ini
    C:\WINDOWS\system32\hcvafuys.dll
    C:\WINDOWS\system32\hixrveaq.ini
    C:\WINDOWS\system32\hjkmp.bak1
    C:\WINDOWS\system32\hjkmp.ini
    C:\WINDOWS\system32\hocbwcbg.ini
    C:\WINDOWS\system32\hwetkrqp.ini
    C:\WINDOWS\system32\ifbuckir.ini
    C:\WINDOWS\system32\iifefeda.dll
    C:\WINDOWS\system32\itklvupq.ini
    C:\WINDOWS\system32\jbecpbvm.dll
    C:\WINDOWS\system32\jnmjthdg.ini
    C:\WINDOWS\system32\jtfcrlfd.ini
    C:\WINDOWS\system32\kfeiargn.ini
    C:\WINDOWS\system32\krcddlvs.dll
    C:\WINDOWS\system32\lgfqubox.ini
    C:\WINDOWS\system32\lhyabcbe.dll
    C:\WINDOWS\system32\LiveProtectSetup.exe
    C:\WINDOWS\system32\ljJDUklj.dll
    C:\WINDOWS\system32\mcrh.tmp
    C:\WINDOWS\system32\mhymownf.ini
    C:\WINDOWS\system32\mlorlntg.ini
    C:\WINDOWS\system32\MSINET.oca
    C:\WINDOWS\system32\mwaqwdpt.ini
    C:\WINDOWS\system32\ngonbdnj.ini
    C:\WINDOWS\system32\nhiwycnh.ini
    C:\WINDOWS\system32\nnalukpx.ini
    C:\WINDOWS\system32\nnnoOiij.dll
    C:\WINDOWS\system32\nuyrnpjy.dll
    C:\WINDOWS\system32\ofmanabq.ini
    C:\WINDOWS\system32\okiyakbq.ini
    C:\WINDOWS\system32\onnmp.bak1
    C:\WINDOWS\system32\onnmp.bak2
    C:\WINDOWS\system32\onnmp.ini
    C:\WINDOWS\system32\onnmp.ini2
    C:\WINDOWS\system32\onnmp.tmp
    C:\WINDOWS\system32\oojbbinh.ini
    C:\WINDOWS\system32\oqnzsj.dat
    C:\WINDOWS\system32\oqnzsj_nav.dat
    C:\WINDOWS\system32\oqnzsj_navps.dat
    C:\WINDOWS\system32\oxqugknf.ini
    C:\WINDOWS\system32\ppyplvym.ini
    C:\WINDOWS\system32\pxkmaxwy.ini
    C:\WINDOWS\system32\pYyIRqru.ini
    C:\WINDOWS\system32\pYyIRqru.ini2
    C:\WINDOWS\system32\qiybciik.ini
    C:\WINDOWS\system32\qjuajgmq.ini
    C:\WINDOWS\system32\qkdrnksj.ini
    C:\WINDOWS\system32\qoMccbaw.dll
    C:\WINDOWS\system32\rightonadz-uninst.exe
    C:\WINDOWS\system32\rnbeykex.ini
    C:\WINDOWS\system32\rqrwhncw.ini
    C:\WINDOWS\system32\sftvonvg.dll
    C:\WINDOWS\system32\srmispmm.ini
    C:\WINDOWS\system32\srwnxroi.ini
    C:\WINDOWS\system32\sznf.ascii
    C:\WINDOWS\system32\tcxwqjgu.ini
    C:\WINDOWS\system32\ugdqopie.dll
    C:\WINDOWS\system32\ukbboldx.ini
    C:\WINDOWS\system32\urqRIyYp.dll
    C:\WINDOWS\system32\veqpjxow.ini
    C:\WINDOWS\system32\vsiwjkup.ini
    C:\WINDOWS\system32\wabccMoq.ini
    C:\WINDOWS\system32\wabccMoq.ini2
    C:\WINDOWS\system32\wctytjxd.ini
    C:\WINDOWS\system32\wicdtvao.dll
    C:\WINDOWS\system32\wlxkukcn.ini
    C:\WINDOWS\system32\woaykosp.ini
    C:\WINDOWS\system32\woxjpqev.dll
    C:\WINDOWS\system32\xlelesct.dll
    C:\WINDOWS\system32\xmrqvibs.ini
    C:\WINDOWS\system32\xoltwjma.dll
    C:\WINDOWS\system32\xqqovbki.ini
    C:\WINDOWS\system32\xyimtwvt.ini
    C:\WINDOWS\system32\xyowapdk.ini
    C:\WINDOWS\system32\yayyYrqn.dll
    C:\WINDOWS\system32\ycivyjav.ini
    C:\WINDOWS\system32\ycobuhug.ini
    C:\WINDOWS\system32\yjpnryun.ini
    C:\WINDOWS\system32\ykwuctim.ini
    C:\WINDOWS\system32\yyxxlvtq.ini

    .
    ((((((((((((((((((((((((((((( Fichiers créés 2008-05-07 to 2008-06-07 ))))))))))))))))))))))))))))))))))))
    .

    2008-06-07 20:58 . 2008-06-07 20:58 <REP> d-------- C:\Documents and Settings\7Assal\Application Data\RTPlayer
    2008-06-07 20:33 . 2008-06-07 20:33 <REP> d-------- C:\Program Files\PixiePack Codec Pack
    2008-06-07 20:32 . 2007-04-25 16:18 466,432 --------- C:\WINDOWS\system32\imapi2fs.dll
    2008-06-07 20:32 . 2007-04-25 16:18 466,432 -----c--- C:\WINDOWS\system32\dllcache\imapi2fs.dll
    2008-06-07 20:32 . 2007-04-25 16:18 320,000 --------- C:\WINDOWS\system32\imapi2.dll
    2008-06-07 20:32 . 2007-04-25 16:18 320,000 -----c--- C:\WINDOWS\system32\dllcache\imapi2.dll
    2008-06-07 20:32 . 2007-04-25 13:41 62,592 -----c--- C:\WINDOWS\system32\dllcache\cdrom.sys
    2008-06-07 20:31 . 2008-06-07 20:31 <REP> d-------- C:\Program Files\RapidSolution
    2008-06-07 20:31 . 2008-06-07 20:33 <REP> d-------- C:\Documents and Settings\All Users\Application Data\RapidSolution
    2008-06-07 12:15 . 2008-06-07 17:45 <REP> d-------- C:\Documents and Settings\ImAnE
    2008-06-07 00:31 . 2008-06-07 00:31 <REP> d-------- C:\Documents and Settings\Souad.UVHC-1D\Application Data\Apple Computer
    2008-06-06 22:16 . 2008-06-06 22:16 <REP> d-------- C:\Documents and Settings\7Assal\Application Data\TuneUp Software
    2008-06-06 22:00 . 2008-06-07 21:10 <REP> d-------- C:\Documents and Settings\7Assal\Application Data\LimeWire
    2008-06-06 18:17 . 2008-06-07 21:59 <REP> d-------- C:\Documents and Settings\7Assal\Application Data\BitTorrent
    2008-06-05 21:04 . 2008-06-06 22:26 <REP> d-------- C:\Documents and Settings\Souad.UVHC-1D\Contacts
    2008-06-05 20:02 . 2008-06-05 20:02 <REP> d-------- C:\Documents and Settings\7Assal\Application Data\DivX
    2008-06-05 20:02 . 2008-06-07 21:26 <REP> d-------- C:\Documents and Settings\7Assal\Application Data\Ahead
    2008-06-05 19:54 . 2008-06-05 19:54 <REP> d-------- C:\Program Files\Free Audio Pack
    2008-06-05 19:54 . 1998-06-17 00:00 516,173 --a------ C:\WINDOWS\system32\MSVCP60D.DLL
    2008-06-05 19:54 . 1998-06-17 00:00 385,100 --a------ C:\WINDOWS\system32\MSVCRTD.DLL
    2008-06-05 18:25 . 2008-06-07 12:23 <REP> d-------- C:\Documents and Settings\7Assal\Application Data\Winamp
    2008-06-04 20:09 . 2008-06-04 20:09 <REP> d-------- C:\Documents and Settings\7Assal\Application Data\Samsung
    2008-06-04 19:15 . 2008-06-04 19:15 <REP> d---s---- C:\Documents and Settings\7Assal\UserData
    2008-06-03 20:19 . 2008-06-06 21:17 <REP> d-------- C:\Documents and Settings\7Assal\Application Data\Apple Computer
    2008-06-03 20:15 . 2008-06-03 20:15 <REP> d-------- C:\Documents and Settings\7Assal\dwhelper
    2008-06-03 19:07 . 2008-06-05 20:27 <REP> d-------- C:\Documents and Settings\7Assal\Contacts
    2008-06-03 18:15 . 2008-06-03 18:15 <REP> d-------- C:\Documents and Settings\7Assal\Application Data\ATI
    2008-06-03 18:14 . 2005-09-26 20:11 <REP> d--h----- C:\Documents and Settings\7Assal\Voisinage réseau
    2008-06-03 18:14 . 2005-09-26 20:11 <REP> d--h----- C:\Documents and Settings\7Assal\Voisinage d'impression
    2008-06-03 18:14 . 2008-03-24 22:07 <REP> d--h----- C:\Documents and Settings\7Assal\Modèles
    2008-06-03 18:14 . 2008-06-07 21:50 <REP> d---s---- C:\Documents and Settings\7Assal\Mes documents
    2008-06-03 18:14 . 2005-09-26 20:11 <REP> dr------- C:\Documents and Settings\7Assal\Menu Démarrer
    2008-06-03 18:14 . 2008-06-03 18:14 <REP> d---s---- C:\Documents and Settings\7Assal\Favoris
    2008-06-03 18:14 . 2008-06-07 21:59 <REP> d-------- C:\Documents and Settings\7Assal\Bureau
    2008-06-03 18:14 . 2008-06-07 21:45 <REP> d-------- C:\Documents and Settings\7Assal
    2008-06-01 21:03 . 2008-06-01 21:03 <REP> d-------- C:\Program Files\Alwil Software
    2008-06-01 20:44 . 2008-06-01 21:21 <REP> d-------- C:\Program Files\Opera
    2008-06-01 19:51 . 2008-06-01 19:51 354,560 --a------ C:\WINDOWS\system32\TuneUpDefragService.exe
    2008-06-01 19:51 . 2008-04-04 14:51 28,416 --a------ C:\WINDOWS\system32\uxtuneup.dll
    2008-06-01 19:50 . 2008-06-01 19:51 <REP> d-------- C:\Program Files\TuneUp Utilities 2008
    2008-06-01 19:50 . 2008-06-01 19:50 <REP> d-------- C:\Documents and Settings\All Users\Application Data\TuneUp Software
    2008-06-01 19:49 . 2008-06-01 19:49 <REP> d-------- C:\Program Files\Fichiers communs\Wise Installation Wizard
    2008-05-31 23:15 . 2008-05-31 23:15 <REP> d-------- C:\Program Files\Counter Strike Condition Zero
    2008-05-31 13:17 . 2008-05-31 13:17 <REP> d-------- C:\Documents and Settings\Souad.UVHC-1D\Application Data\ATI
    2008-05-31 13:09 . 2005-09-26 20:11 <REP> d--h----- C:\Documents and Settings\Souad.UVHC-1D\Voisinage réseau
    2008-05-31 13:09 . 2005-09-26 20:11 <REP> d--h----- C:\Documents and Settings\Souad.UVHC-1D\Voisinage d'impression
    2008-05-31 13:09 . 2008-03-24 22:07 <REP> d--h----- C:\Documents and Settings\Souad.UVHC-1D\Modèles
    2008-05-31 13:09 . 2008-06-07 11:34 <REP> d---s---- C:\Documents and Settings\Souad.UVHC-1D\Mes documents
    2008-05-31 13:09 . 2005-09-26 20:11 <REP> dr------- C:\Documents and Settings\Souad.UVHC-1D\Menu Démarrer
    2008-05-31 13:09 . 2008-06-05 21:03 <REP> d---s---- C:\Documents and Settings\Souad.UVHC-1D\Favoris
    2008-05-31 13:09 . 2008-06-07 11:34 <REP> d-------- C:\Documents and Settings\Souad.UVHC-1D\Bureau
    2008-05-31 13:09 . 2008-06-07 11:36 <REP> d-------- C:\Documents and Settings\Souad.UVHC-1D
    2008-05-30 18:04 . 2008-05-30 18:08 <REP> d-------- C:\Program Files\iPod Music Liberator
    2008-05-29 20:26 . 2008-05-29 21:56 <REP> dr-hs---- C:\WINDOWS\Downloaded PROGRESSION Files
    2008-05-29 19:39 . 2008-05-29 19:39 262,144 --------- C:\WINDOWS\Setup1.exe
    2008-05-29 19:39 . 2008-05-29 19:39 74,752 --a------ C:\WINDOWS\ST6UNST.EXE
    2008-05-25 12:50 . 2008-05-25 13:00 <REP> d-------- C:\Program Files\EA Sports
    2008-05-20 21:01 . 2004-02-04 10:27 49,536 --a------ C:\WINDOWS\system32\drivers\tiehdusb.sys
    2008-05-20 21:01 . 2004-01-28 15:03 21,456 --a------ C:\WINDOWS\system32\drivers\SilvrLnk.sys
    2008-05-20 20:55 . 2008-05-21 19:12 <REP> d-------- C:\Program Files\TI Education
    2008-05-18 21:28 . 2008-05-18 21:30 <REP> d-------- C:\WINDOWS\system32\CatRoot_bak
    2008-05-18 18:53 . 2008-05-29 11:26 <REP> d-------- C:\Program Files\Lx_cats
    2008-05-18 18:53 . 2008-05-18 18:53 12,675 --a------ C:\WINDOWS\system32\LexFiles.ulf
    2008-05-18 18:51 . 2008-05-20 19:27 <REP> d-------- C:\TEMP\{9F5FBC24-EFE2-4f90-B498-EC0FB7D47D15}
    2008-05-18 18:51 . 2008-05-18 18:53 <REP> d-------- C:\Program Files\Lexmark 730 Series
    2008-05-13 18:57 . 2008-05-13 18:57 <REP> d-------- C:\Program Files\Radical Games
    2008-05-12 15:33 . 2008-05-12 15:35 <REP> d-------- C:\Program Files\Fichiers communs\Ahead
    2008-05-08 12:52 . 2008-06-07 21:50 54,156 --ah----- C:\WINDOWS\QTFont.qfn
    2008-05-08 12:52 . 2008-06-02 18:47 1,409 --a------ C:\WINDOWS\QTFont.for
    2008-05-08 12:50 . 2008-05-08 12:50 <REP> d-------- C:\Program Files\iPod
    2008-05-07 20:12 . 2008-05-07 20:12 <REP> d-------- C:\Program Files\Visicom Media
    2008-05-07 20:12 . 2008-05-07 20:12 <REP> d-------- C:\Documents and Settings\All Users\Application Data\EmailNotifier

    .
    (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2008-06-07 19:47 --------- d--h--w C:\Program Files\InstallShield Installation Information
    2008-06-07 18:56 --------- d-----w C:\Program Files\Fichiers communs\Symantec Shared
    2008-06-07 15:38 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
    2008-06-06 20:45 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
    2008-06-01 09:19 --------- d-----w C:\Program Files\Spybot - Search & Destroy
    2008-06-01 09:13 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
    2008-06-01 09:07 --------- d-----w C:\Program Files\Google
    2008-06-01 09:00 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
    2008-05-13 17:11 98,304 ----a-w C:\WINDOWS\system32\CmdLineExt.dll
    2008-05-12 13:33 --------- d-----w C:\Program Files\Nero
    2008-05-12 13:33 --------- d-----w C:\Documents and Settings\All Users\Application Data\Nero
    2008-05-08 17:42 --------- dcsh--w C:\Program Files\Fichiers communs\WindowsLiveInstaller
    2008-05-08 17:35 --------- d-----w C:\Program Files\Windows Live
    2008-05-08 17:14 --------- d-----w C:\Program Files\Messenger Plus! Live
    2008-05-08 17:02 --------- d-----w C:\Program Files\Apple Software Update
    2008-05-08 11:32 --------- d-----w C:\Program Files\LimeWire
    2008-05-08 10:51 --------- d-----w C:\Program Files\iTunes
    2008-05-08 10:45 --------- d-----w C:\Program Files\QuickTime
    2008-05-07 18:06 --------- d-----w C:\Program Files\DivX
    2008-05-04 13:49 --------- d-----w C:\Program Files\Winamp
    2008-05-04 13:25 --------- d-----w C:\Program Files\Pegasys Inc
    2008-05-04 13:22 --------- d-----w C:\Program Files\Fichiers communs\Adobe
    2008-05-01 18:53 --------- d-----w C:\Program Files\Trend Micro
    2008-05-01 17:52 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
    2008-05-01 15:07 --------- d-----w C:\Program Files\Windows Defender
    2008-05-01 14:53 --------- d-----w C:\Program Files\Java
    2008-05-01 14:52 --------- d-----w C:\Program Files\Fichiers communs\Java
    2008-05-01 13:09 --------- d-----w C:\Program Files\Marvell
    2008-05-01 12:16 --------- d-----w C:\Program Files\Intel Desktop Board
    2008-05-01 00:59 --------- d-----w C:\Program Files\Belkin
    2008-04-30 23:19 --------- d-----w C:\Program Files\MSECACHE
    2008-04-30 23:15 --------- d-----w C:\Program Files\Yahoo!
    2008-04-30 23:15 --------- d-----w C:\Program Files\CCleaner
    2008-03-31 21:25 831,488 ----a-w C:\WINDOWS\system32\divx_xx0a.dll
    2008-03-31 21:25 823,296 ----a-w C:\WINDOWS\system32\divx_xx0c.dll
    2008-03-31 21:25 823,296 ----a-w C:\WINDOWS\system32\divx_xx07.dll
    2008-03-31 21:25 802,816 ----a-w C:\WINDOWS\system32\divx_xx11.dll
    2008-03-31 21:25 682,496 ----a-w C:\WINDOWS\system32\DivX.dll
    2008-03-31 21:25 161,096 ----a-w C:\WINDOWS\system32\DivXCodecVersionChecker.exe
    2008-03-25 04:51 621,344 ----a-w C:\WINDOWS\system32\mswstr10.dll
    2008-03-25 04:51 194,144 ----a-w C:\WINDOWS\system32\msjint40.dll
    2008-03-21 20:30 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe
    2008-03-21 20:30 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
    2008-03-21 20:30 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
    2008-03-21 20:30 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
    2008-03-21 20:28 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll
    2008-03-21 20:28 593,920 ----a-w C:\WINDOWS\system32\dpuGUI11.dll
    2008-03-21 20:28 57,344 ----a-w C:\WINDOWS\system32\dpv11.dll
    2008-03-21 20:28 53,248 ----a-w C:\WINDOWS\system32\dpuGUI10.dll
    2008-03-21 20:28 344,064 ----a-w C:\WINDOWS\system32\dpus11.dll
    2008-03-21 20:28 294,912 ----a-w C:\WINDOWS\system32\dpu11.dll
    2008-03-21 20:28 294,912 ----a-w C:\WINDOWS\system32\dpu10.dll
    2008-03-21 20:28 196,608 ----a-w C:\WINDOWS\system32\dtu100.dll
    2008-03-21 20:28 12,288 ----a-w C:\WINDOWS\system32\DivXWMPExtType.dll
    2008-03-20 08:09 1,845,376 ----a-w C:\WINDOWS\system32\win32k.sys
    2008-03-11 06:47 60,800 ----a-w C:\WINDOWS\system32\S32EVNT1.DLL
    2008-03-07 13:03 625,032 ----a-w C:\WINDOWS\system32\SymNeti.dll
    2008-03-07 13:03 242,056 ----a-w C:\WINDOWS\system32\SymRedir.dll
    2007-02-12 17:33 774,144 ----a-w C:\Program Files\RngInterstitial.dll
    2005-09-29 09:51 74,448 ----a-w C:\Program Files\DSETUP.dll
    2005-09-29 09:51 2,245,840 ----a-w C:\Program Files\dsetup32.dll
    2005-09-29 09:51 15,493,481 ----a-w C:\Program Files\DirectX.cab
    2005-09-29 09:51 1,351,430 ----a-w C:\Program Files\Aug2005_d3dx9_27_x64.cab
    2005-09-29 09:51 1,078,532 ----a-w C:\Program Files\Aug2005_d3dx9_27_x86.cab
    2007-03-30 19:37 56 --sha-r C:\WINDOWS\system32\2CD320BD30.sys
    2007-06-23 16:25 4,182 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
    .

    ((((((((((((((((((((((((((((( snapshot@2008-06-03_18.58.28.75 )))))))))))))))))))))))))))))))))))))))))
    .
    + 2007-06-26 14:46:09 851,968 ----a-w C:\WINDOWS\$hf_mig$\KB938127\SP2QFE\vgx.dll
    + 2005-10-12 23:15:25 15,072 ----a-w C:\WINDOWS\$hf_mig$\KB938127\spmsg.dll
    + 2005-10-12 23:15:26 216,800 ----a-w C:\WINDOWS\$hf_mig$\KB938127\spuninst.exe
    + 2005-10-12 23:15:25 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB938127\update\spcustom.dll
    + 2005-10-12 23:15:28 727,776 ----a-w C:\WINDOWS\$hf_mig$\KB938127\update\update.exe
    + 2005-10-12 23:15:45 394,976 ----a-w C:\WINDOWS\$hf_mig$\KB938127\update\updspapi.dll
    + 2007-12-18 14:32:57 450,560 ----a-w C:\WINDOWS\$hf_mig$\KB944338\SP2QFE\jscript.dll
    + 2007-12-18 14:32:57 417,792 ----a-w C:\WINDOWS\$hf_mig$\KB944338\SP2QFE\vbscript.dll
    + 2007-03-06 01:34:33 15,072 ----a-w C:\WINDOWS\$hf_mig$\KB944338\spmsg.dll
    + 2007-03-06 01:34:38 216,800 ----a-w C:\WINDOWS\$hf_mig$\KB944338\spuninst.exe
    + 2007-03-06 01:34:31 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB944338\update\spcustom.dll
    + 2007-03-06 01:34:56 727,776 ----a-w C:\WINDOWS\$hf_mig$\KB944338\update\update.exe
    + 2007-03-06 01:35:48 394,976 ----a-w C:\WINDOWS\$hf_mig$\KB944338\update\updspapi.dll
    + 2008-02-16 09:31:57 1,024,512 ----a-w C:\WINDOWS\$hf_mig$\KB947864\SP2QFE\browseui.dll
    + 2008-02-16 09:31:57 152,064 ----a-w C:\WINDOWS\$hf_mig$\KB947864\SP2QFE\cdfview.dll
    + 2008-02-16 09:31:58 1,056,768 ----a-w C:\WINDOWS\$hf_mig$\KB947864\SP2QFE\danim.dll
    + 2008-02-16 09:31:58 357,888 ----a-w C:\WINDOWS\$hf_mig$\KB947864\SP2QFE\dxtmsft.dll
    + 2008-02-16 09:31:58 205,312 ----a-w C:\WINDOWS\$hf_mig$\KB947864\SP2QFE\dxtrans.dll
    + 2008-02-16 09:31:58 55,808 ----a-w C:\WINDOWS\$hf_mig$\KB947864\SP2QFE\extmgr.dll
    + 2008-02-15 09:07:53 18,432 ----a-w C:\WINDOWS\$hf_mig$\KB947864\SP2QFE\iedw.exe
    + 2008-02-16 09:31:58 251,904 ----a-w C:\WINDOWS\$hf_mig$\KB947864\SP2QFE\iepeers.dll
    + 2008-02-16 09:31:58 96,768 ----a-w C:\WINDOWS\$hf_mig$\KB947864\SP2QFE\inseng.dll
    + 2008-02-16 09:31:58 16,384 ----a-w C:\WINDOWS\$hf_mig$\KB947864\SP2QFE\jsproxy.dll
    + 2008-02-16 09:31:59 3,087,872 ----a-w C:\WINDOWS\$hf_mig$\KB947864\SP2QFE\mshtml.dll
    + 2008-02-16 09:31:59 449,024 ----a-w C:\WINDOWS\$hf_mig$\KB947864\SP2QFE\mshtmled.dll
    + 2008-02-16 09:31:59 146,432 ----a-w C:\WINDOWS\$hf_mig$\KB947864\SP2QFE\msrating.dll
    + 2008-02-16 09:31:59 532,480 ----a-w C:\WINDOWS\$hf_mig$\KB947864\SP2QFE\mstime.dll
    + 2008-02-16 09:31:59 39,424 ----a-w C:\WINDOWS\$hf_mig$\KB947864\SP2QFE\pngfilt.dll
    + 2008-02-16 09:32:00 1,499,648 ----a-w C:\WINDOWS\$hf_mig$\KB947864\SP2QFE\shdocvw.dll
    + 2008-02-16 09:32:00 474,624 ----a-w C:\WINDOWS\$hf_mig$\KB947864\SP2QFE\shlwapi.dll
    + 2008-02-15 23:03:14 370,176 ----a-w C:\WINDOWS\$hf_mig$\KB947864\SP2QFE\spru040c.dll
    + 2008-02-16 09:32:00 620,544 ----a-w C:\WINDOWS\$hf_mig$\KB947864\SP2QFE\urlmon.dll
    + 2008-02-16 09:32:00 670,208 ----a-w C:\WINDOWS\$hf_mig$\KB947864\SP2QFE\wininet.dll
    + 2007-03-06 01:34:33 15,072 ----a-w C:\WINDOWS\$hf_mig$\KB947864\spmsg.dll
    + 2007-03-06 01:34:38 216,800 ----a-w C:\WINDOWS\$hf_mig$\KB947864\spuninst.exe
    + 2007-03-06 01:34:31 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB947864\update\spcustom.dll
    + 2007-03-06 01:34:56 727,776 ----a-w C:\WINDOWS\$hf_mig$\KB947864\update\update.exe
    + 2007-03-06 01:35:48 394,976 ----a-w C:\WINDOWS\$hf_mig$\KB947864\update\updspapi.dll
    - 2008-06-03 16:49:27 2,048 --s-a-w C:\WINDOWS\bootstat.dat
    + 2008-06-07 19:47:28 2,048 --s-a-w C:\WINDOWS\bootstat.dat
    + 2007-04-25 11:41:02 62,592 ------w C:\WINDOWS\Driver Cache\i386\cdrom.sys
    - 2008-05-31 09:08:39 22,486 ----a-r C:\WINDOWS\Installer\{99052DB7-9592-4522-A558-5417BBAD48EE}\ARPPRODUCTICON.exe
    + 2008-06-04 17:42:10 22,486 ----a-r C:\WINDOWS\Installer\{99052DB7-9592-4522-A558-5417BBAD48EE}\ARPPRODUCTICON.exe
    - 2008-05-31 09:08:39 22,486 ----a-r C:\WINDOWS\Installer\{99052DB7-9592-4522-A558-5417BBAD48EE}\WCESMgrIcon.exe
    + 2008-06-04 17:42:10 22,486 ----a-r C:\WINDOWS\Installer\{99052DB7-9592-4522-A558-5417BBAD48EE}\WCESMgrIcon.exe
    + 2008-06-07 18:32:28 10,134 ----a-r C:\WINDOWS\Installer\{EF0E0146-8AF3-416E-8811-3ED96833FD7E}\SystemFolder_msiexec.exe
    - 2004-08-05 12:00:00 1,017,344 ----a-w C:\WINDOWS\system32\browseui.dll
    + 2008-02-16 09:02:34 1,024,000 ----a-w C:\WINDOWS\system32\browseui.dll
    - 2004-08-05 12:00:00 151,552 ----a-w C:\WINDOWS\system32\cdfview.dll
    + 2008-02-16 09:02:34 152,064 ----a-w C:\WINDOWS\system32\cdfview.dll
    - 2004-08-05 12:00:00 1,056,256 ----a-w C:\WINDOWS\system32\danim.dll
    + 2008-02-16 09:02:34 1,056,768 ----a-w C:\WINDOWS\system32\danim.dll
    - 2004-08-05 12:00:00 1,017,344 -c--a-w C:\WINDOWS\system32\dllcache\browseui.dll
    + 2008-02-16 09:02:34 1,024,000 -c--a-w C:\WINDOWS\system32\dllcache\browseui.dll
    - 2004-08-05 12:00:00 151,552 -c--a-w C:\WINDOWS\system32\dllcache\cdfview.dll
    + 2008-02-16 09:02:34 152,064 -c--a-w C:\WINDOWS\system32\dllcache\cdfview.dll
    - 2004-08-05 12:00:00 1,056,256 -c--a-w C:\WINDOWS\system32\dllcache\danim.dll
    + 2008-02-16 09:02:34 1,056,768 -c--a-w C:\WINDOWS\system32\dllcache\danim.dll
    - 2004-08-05 12:00:00 357,888 -c--a-w C:\WINDOWS\system32\dllcache\dxtmsft.dll
    + 2008-02-16 09:02:34 357,888 -c--a-w C:\WINDOWS\system32\dllcache\dxtmsft.dll
    - 2004-08-05 12:00:00 201,728 -c--a-w C:\WINDOWS\system32\dllcache\dxtrans.dll
    + 2008-02-16 09:02:35 205,312 -c--a-w C:\WINDOWS\system32\dllcache\dxtrans.dll
    - 2004-08-05 12:00:00 55,808 -c--a-w C:\WINDOWS\system32\dllcache\extmgr.dll
    + 2008-02-16 09:02:35 55,808 -c--a-w C:\WINDOWS\system32\dllcache\extmgr.dll
    - 2004-08-05 12:00:00 18,432 -c--a-w C:\WINDOWS\system32\dllcache\iedw.exe
    + 2008-02-15 09:23:37 18,432 -c--a-w C:\WINDOWS\system32\dllcache\iedw.exe
    - 2004-08-05 12:00:00 249,344 -c--a-w C:\WINDOWS\system32\dllcache\iepeers.dll
    + 2008-02-16 09:02:35 251,392 -c--a-w C:\WINDOWS\system32\dllcache\iepeers.dll
    - 2004-08-05 12:00:00 96,768 -c--a-w C:\WINDOWS\system32\dllcache\inseng.dll
    + 2008-02-16 09:02:35 96,768 -c--a-w C:\WINDOWS\system32\dllcache\inseng.dll
    - 2004-08-05 12:00:00 450,560 -c--a-w C:\WINDOWS\system32\dllcache\jscript.dll
    + 2007-12-18 14:41:58 450,560 -c--a-w C:\WINDOWS\system32\dllcache\jscript.dll
    - 2004-08-05 12:00:00 15,872 -c--a-w C:\WINDOWS\system32\dllcache\jsproxy.dll
    + 2008-02-16 09:02:35 16,384 -c--a-w C:\WINDOWS\system32\dllcache\jsproxy.dll
    - 2004-08-05 12:00:00 3,003,392 -c--a-w C:\WINDOWS\system32\dllcache\mshtml.dll
    + 2008-02-16 22:32:38 3,080,704 -c--a-w C:\WINDOWS\system32\dllcache\mshtml.dll
    - 2004-08-05 12:00:00 448,512 -c--a-w C:\WINDOWS\system32\dllcache\mshtmled.dll
    + 2008-02-16 09:02:36 449,024 -c--a-w C:\WINDOWS\system32\dllcache\mshtmled.dll
    - 2004-08-05 12:00:00 146,432 -c--a-w C:\WINDOWS\system32\dllcache\msrating.dll
    + 2008-02-16 09:02:37 146,432 -c--a-w C:\WINDOWS\system32\dllcache\msrating.dll
    - 2004-08-05 12:00:00 530,432 -c--a-w C:\WINDOWS\system32\dllcache\mstime.dll
    + 2008-02-16 09:02:37 532,480 -c--a-w C:\WINDOWS\system32\dllcache\mstime.dll
    - 2004-08-05 12:00:00 39,424 -c--a-w C:\WINDOWS\system32\dllcache\pngfilt.dll
    + 2008-02-16 09:02:37 39,424 -c--a-w C:\WINDOWS\system32\dllcache\pngfilt.dll
    - 2004-08-05 12:00:00 1,483,776 -c--a-w C:\WINDOWS\system32\dllcache\shdocvw.dll
    + 2008-02-16 09:02:38 1,495,040 -c--a-w C:\WINDOWS\system32\dllcache\shdocvw.dll
    - 2004-08-05 12:00:00 474,112 -c--a-w C:\WINDOWS\system32\dllcache\shlwapi.dll
    + 2008-02-16 09:02:38 474,624 -c--a-w C:\WINDOWS\system32\dllcache\shlwapi.dll
    - 2004-08-05 12:00:00 603,136 -c--a-w C:\WINDOWS\system32\dllcache\urlmon.dll
    + 2008-02-16 09:02:39 617,984 -c--a-w C:\WINDOWS\system32\dllcache\urlmon.dll
    - 2004-08-05 12:00:00 417,792 -c--a-w C:\WINDOWS\system32\dllcache\vbscript.dll
    + 2007-12-18 14:41:59 417,792 -c--a-w C:\WINDOWS\system32\dllcache\vbscript.dll
    - 2004-08-05 12:00:00 848,384 -c--a-w C:\WINDOWS\system32\dllcache\vgx.dll
    + 2007-06-26 13:56:54 851,968 -c--a-w C:\WINDOWS\system32\dllcache\vgx.dll
    - 2004-08-05 12:00:00 660,480 -c--a-w C:\WINDOWS\system32\dllcache\wininet.dll
    + 2008-02-16 09:02:39 663,552 -c--a-w C:\WINDOWS\system32\dllcache\wininet.dll
    - 2004-08-05 12:00:00 49,536 ----a-w C:\WINDOWS\system32\drivers\cdrom.sys
    + 2007-04-25 11:41:02 62,592 ----a-w C:\WINDOWS\system32\drivers\cdrom.sys
    - 2004-08-05 12:00:00 357,888 ----a-w C:\WINDOWS\system32\dxtmsft.dll
    + 2008-02-16 09:02:34 357,888 ----a-w C:\WINDOWS\system32\dxtmsft.dll
    - 2004-08-05 12:00:00 201,728 ----a-w C:\WINDOWS\system32\dxtrans.dll
    + 2008-02-16 09:02:35 205,312 ----a-w C:\WINDOWS\system32\dxtrans.dll
    - 2004-08-05 12:00:00 55,808 ----a-w C:\WINDOWS\system32\extmgr.dll
    + 2008-02-16 09:02:35 55,808 ----a-w C:\WINDOWS\system32\extmgr.dll
    + 2007-08-23 17:30:00 7,680 ----a-w C:\WINDOWS\system32\ff_vfw.dll
    - 2004-08-05 12:00:00 249,344 ----a-w C:\WINDOWS\system32\iepeers.dll
    + 2008-02-16 09:02:35 251,392 ----a-w C:\WINDOWS\system32\iepeers.dll
    - 2004-08-05 12:00:00 96,768 ----a-w C:\WINDOWS\system32\inseng.dll
    + 2008-02-16 09:02:35 96,768 ----a-w C:\WINDOWS\system32\inseng.dll
    - 2004-08-05 12:00:00 450,560 ----a-w C:\WINDOWS\system32\jscript.dll
    + 2007-12-18 14:41:58 450,560 ----a-w C:\WINDOWS\system32\jscript.dll
    - 2004-08-05 12:00:00 15,872 ----a-w C:\WINDOWS\system32\jsproxy.dll
    + 2008-02-16 09:02:35 16,384 ----a-w C:\WINDOWS\system32\jsproxy.dll
    - 2004-08-05 12:00:00 3,003,392 ----a-w C:\WINDOWS\system32\mshtml.dll
    + 2008-02-16 22:32:38 3,080,704 ----a-w C:\WINDOWS\system32\mshtml.dll
    - 2004-08-05 12:00:00 448,512 ----a-w C:\WINDOWS\system32\mshtmled.dll
    + 2008-02-16 09:02:36 449,024 ----a-w C:\WINDOWS\system32\mshtmled.dll
    - 2004-08-05 12:00:00 146,432 ----a-w C:\WINDOWS\system32\msrating.dll
    + 2008-02-16 09:02:37 146,432 ----a-w C:\WINDOWS\system32\msrating.dll
    - 2004-08-05 12:00:00 530,432 ----a-w C:\WINDOWS\system32\mstime.dll
    + 2008-02-16 09:02:37 532,480 ----a-w C:\WINDOWS\system32\mstime.dll
    - 2008-06-01 08:58:06 61,210 ----a-w C:\WINDOWS\system32\perfc009.dat
    + 2008-06-04 18:10:48 61,210 ----a-w C:\WINDOWS\system32\perfc009.dat
    - 2008-06-01 08:58:06 74,126 ----a-w C:\WINDOWS\system32\perfc00C.dat
    + 2008-06-04 18:10:48 74,126 ----a-w C:\WINDOWS\system32\perfc00C.dat
    - 2008-06-01 08:58:06 400,278 ----a-w C:\WINDOWS\system32\perfh009.dat
    + 2008-06-04 18:10:48 400,278 ----a-w C:\WINDOWS\system32\perfh009.dat
    - 2008-06-01 08:58:06 467,176 ----a-w C:\WINDOWS\system32\perfh00C.dat
    + 2008-06-04 18:10:48 467,176 ----a-w C:\WINDOWS\system32\perfh00C.dat
    - 2004-08-05 12:00:00 39,424 ----a-w C:\WINDOWS\system32\pngfilt.dll
    + 2008-02-16 09:02:37 39,424 ----a-w C:\WINDOWS\system32\pngfilt.dll
    + 2005-08-29 23:47:38 58,320 ----a-w C:\WINDOWS\system32\Samsung_USB_Drivers\2\ssm_bus.sys
    + 2005-08-29 23:49:28 6,176 ----a-w C:\WINDOWS\system32\Samsung_USB_Drivers\2\ssm_cmnt.sys
    + 2005-08-29 23:49:34 8,336 ----a-w C:\WINDOWS\system32\Samsung_USB_Drivers\2\ssm_mdfl.sys
    + 2005-08-29 23:49:38 94,000 ----a-w C:\WINDOWS\system32\Samsung_USB_Drivers\2\ssm_mdm.sys
    + 2005-08-29 23:46:16 81,920 ----a-w C:\WINDOWS\system32\Samsung_USB_Drivers\2\SSM_Uninstall.exe
    + 2005-08-29 23:47:34 5,840 ----a-w C:\WINDOWS\system32\Samsung_USB_Drivers\2\ssm_whnt.sys
    - 2004-08-05 12:00:00 1,483,776 ----a-w C:\WINDOWS\system32\shdocvw.dll
    + 2008-02-16 09:02:38 1,495,040 ----a-w C:\WINDOWS\system32\shdocvw.dll
    - 2004-08-05 12:00:00 474,112 ----a-w C:\WINDOWS\system32\shlwapi.dll
    + 2008-02-16 09:02:38 474,624 ----a-w C:\WINDOWS\system32\shlwapi.dll
    - 2004-08-05 12:00:00 603,136 ----a-w C:\WINDOWS\system32\urlmon.dll
    + 2008-02-16 09:02:39 617,984 ----a-w C:\WINDOWS\system32\urlmon.dll
    - 2004-08-05 12:00:00 417,792 ----a-w C:\WINDOWS\system32\vbscript.dll
    + 2007-12-18 14:41:59 417,792 ----a-w C:\WINDOWS\system32\vbscript.dll
    - 2004-08-05 12:00:00 660,480 ----a-w C:\WINDOWS\system32\wininet.dll
    + 2008-02-16 09:02:39 663,552 ----a-w C:\WINDOWS\system32\wininet.dll
    - 2007-10-29 14:35:14 121,856 ----a-w C:\WINDOWS\system32\xpsp3res.dll
    + 2008-02-15 23:03:14 370,176 ----a-w C:\WINDOWS\system32\xpsp3res.dll
    .
    -- Snapshot reset to current date --
    .
    ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    REGEDIT4
    *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 14:00 15360]
    "ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" [2004-12-01 00:25 32768]
    "DWQueuedReporting"="C:\PROGRA~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 16:38 39264]
    "msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 11:34 5724184]
    "Steam"="C:\Valve\Steam\Steam.exe" [2008-06-04 18:22 1271032]
    "H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 15:07 1289000]
    "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe" [2007-06-27 19:03 152872]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "LXCFCATS"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCFtime.dll" [2005-07-20 12:47 73728]
    "ccApp"="C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe" [2007-02-19 19:25 115816]
    "WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2008-04-01 20:49 36352]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-05 14:00 15360]
    "ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" [2004-12-01 00:25 32768]
    "DWQueuedReporting"="C:\PROGRA~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 16:38 39264]
    "msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 11:34 5724184]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
    "tscuninstall"="C:\WINDOWS\system32\tscupgrd.exe" [2004-08-05 14:00 44544]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
    "VIDC.ACDV"= ACDV.dll
    "vidc.iv32"= C:\WINDOWS\system32\ir32_32.dll
    "vidc.iv31"= C:\WINDOWS\system32\ir32_32.dll

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
    @=""

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
    "ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime
    "ATIPTA"=C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    "Symantec PIF AlertEng"="C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
    "Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" -hide
    "ccApp"="C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
    "DisableMonitoring"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "C:\\TEMP\\CI_HITACHI\\MAJ_Hitachi.exe"=
    "C:\\Program Files\\LimeWire\\LimeWire.exe"=
    "C:\\Program Files\\BitTorrent\\bittorrent.exe"=
    "C:\\WINDOWS\\system32\\CTF\\wscntfyr.exe"=
    "C:\\WINDOWS\\system32\\CTF\\nvidiadrv.exe"=
    "C:\Program Files\Microsoft ActiveSync\rapimgr.exe"= C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
    "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"= C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
    "C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"= C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
    "C:\\Program Files\\DNA\\btdna.exe"=
    "<NO NAME>"=
    "C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
    "C:\\Program Files\\Adobe\\Acrobat 5.0\\Distillr\\acrodist.exe"=
    "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
    "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
    "C:\\Program Files\\iTunes\\iTunes.exe"=
    "C:\\Program Files\\Messenger\\msmsgs.exe"=

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "11430:TCP"= 11430:TCP:BitComet 11430 TCP
    "11430:UDP"= 11430:UDP:BitComet 11430 UDP
    "26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

    R0 iteraid;ITERAID_Service_Install;C:\WINDOWS\system32\DRIVERS\iteraid.sys [2004-07-16 11:12]
    R0 tffsport;M-Systems DiskOnChip 2000;C:\WINDOWS\system32\DRIVERS\tffsport.sys [2004-08-05 14:00]
    R2 UxTuneUp;TuneUp Extension de thème;C:\WINDOWS\System32\svchost.exe [2004-08-05 14:00]
    S3 ntportio;ntportio;C:\Documents and Settings\euro-info\Bureau\pbbse12_crippled\pbbse12_crippled\ntportio.sys []
    S3 PRISM_USB;Dell TrueMobile 1180 Wireless USB Adapter;C:\WINDOWS\system32\DRIVERS\DELUSB_51.sys [2002-08-09 08:46]
    S3 SkLaggProtocol;Marvell Link Aggregation Protocol;C:\WINDOWS\system32\DRIVERS\yk51x32l.sys [2007-12-14 10:10]
    S3 SkVlanProtocol;Marvell VLAN Protocol;C:\WINDOWS\system32\DRIVERS\yk51x32v.sys [2007-11-23 10:10]
    S3 sonypvs1;Sony Digital Imaging Video2;C:\WINDOWS\system32\DRIVERS\sonypvs1.sys []
    S3 TuneUp.Defrag;TuneUp Drive Defrag Service;C:\WINDOWS\System32\TuneUpDefragService.exe [2008-06-01 19:51]
    S3 UsbSagCom;SAGEM Full USB Driver;C:\WINDOWS\system32\DRIVERS\UsbSagCom.sys [2006-04-07 16:18]

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
    UxTuneUp

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d2d0fc38-a5bd-11db-80a1-0011d8a06653}]
    \Shell\AutoRun\command - E:\setupSNK.exe


    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{621FCD24-4498-4324-A81E-07D331376EDF}]
    C:\Program Files\PixiePack Codec Pack\InstallerHelper.exe
    .
    Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
    "2008-05-08 10:36:07 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
    - C:\Program Files\Apple Software Update\SoftwareUpdate.exe
    "2008-06-07 20:00:00 C:\WINDOWS\Tasks\Maintenance en 1 clic.job"
    - C:\Program Files\TuneUp Utilities 2008\OneClickStarter.exe
    "2008-06-07 19:50:47 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
    - C:\Program Files\Windows Defender\MpCmdRun.exe
    "2008-06-02 18:00:00 C:\WINDOWS\Tasks\Norton Internet Security Online - Analyse système complète - assaad.job"
    - C:\Program Files\Norton Internet Security\Norton AntiVirus\Navw32.exeh/TASK:
    .
    **************************************************************************

    catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-06-07 22:03:13
    Windows 5.1.2600 Service Pack 2 NTFS

    Balayage processus cachés ...

    Balayage caché autostart entries ...

    Balayage des fichiers cachés ...

    Scan terminé avec succès
    Les fichiers cachés: 0

    **************************************************************************
    .
    Temps d'accomplissement: 2008-06-07 22:09:05
    ComboFix-quarantined-files.txt 2008-06-07 20:09:02

    Pre-Run: 46,965,559,296 octets libres
    Post-Run: 46,960,369,664 octets libres

    606 --- E O F --- 2008-06-06 15:58:47

    Re,

    Télécharge Navilog (de Il-Mafioso)

  • Enregistre-le sur ton Bureau.
  • Installe-le en double cliquant sur navilog.exe.
  • Une fois l'installation terminée, l'utilitaire s'exécutera automatiquement.
    (Si ce n'est pas le cas, double clique sur le raccourci présent sur le Bureau) [Clic droit -> "Exécuter en tant qu'administrateur". ( Pour Vista)]
  • Laisse-toi guider par l'utilitaire. Choisis l'option 1 puis valide.
    ! N'utilise pas l'option 2,3 et 4 sans notre accord !
  • Patiente jusqu'à l'apparition de ce message :
    "*** Analyse Termine le ..... ***"
  • Appuie sur une touche comme demandé. Le Bloc-notes va s'ouvrir. Poste le rapport ici.
  • Poste le rapport généré.

    Le rapport se trouve ici : C:\fixnavi.txt

    Si tu as Vista, fais ceci avant :
    Désactive l'UAC ( Menu Démarrer \ Panneau de Configuration \ Comptes d'utilisateurs et protection des utilisateurs \ Comptes d'utilisateurs \ Activer ou désactiver le contrôle des comptes d'utilisateurs \ décoche la case Utiliser le contrôle ... et valide par OK , il te sera demandé de redémarrer, fais le )
    Lassé par la pub ? Créez un compte
    • Contenus similaires :
    Tags :
    Tom's guide dans le monde