Virus qui désactive Avast ! Lecture de rapport SVP

Bonjour
Après quelques manipulations hasardeuses (!) en peer-to-peer, je me retrouve avec un virus (ou des virus ? ou un bagle ? je ne suis pas expert)…

  • Avast est depuis considéré comme une application non valide ;
  • Sur la barre des tâches (en bas à droite de l’écran), la petite icône “retirer le périphérique en toute sécurité” reste constamment allumée, alors qu’aucune clé usb n’est branchée !

Du coup j’ai suivi la méthode proposée par certains d’entre vous : j’ai téléchargé et lancé FindyKill, puis Malwarebytes. J’ai aussi désinstallé l’antivirus Avast.
Je poste les 2 rapports.
Si l’un d’entre vous pouvait m’aider ce serait super.
Merci d’avance à ceux qui voudront bien me consacrer un peu de leur temps !

Je suis sous vista

############################## | FindyKill V5.012 |

User : Stéphane (Administrateurs) # PC-DE-STÉPHANE

Update on 20/09/2009 by Chiquitine29

Start at: 23:24:51 | 05/10/2009

Website : pagesperso-orange.fr…

Intel® Pentium® Dual CPU E2220 @ 2.40GHz

Microsoft® Windows Vista™ Édition Familiale Basique (6.0.6001 32-bit) # Service Pack 1

Internet Explorer 8.0.6001.18813

Windows Firewall Status : Enabled

C:\ # Disque fixe local # 584,54 Go (413,49 Go free) [HP] # NTFS

D:\ # Disque fixe local # 11,63 Go (1,58 Go free) [FACTORY_IMAGE] # NTFS

E:\ # Disque CD-ROM

G:\ # Disque amovible

H:\ # Disque amovible

I:\ # Disque amovible

K:\ # Disque CD-ROM

L:\ # Disque amovible

############################## | Processus actifs |

C:\Windows\System32\smss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\rundll32.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\hp\support\hpsysdrv.exe
C:\Windows\System32\nvraidservice.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe
C:\Program Files\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe
C:\Program Files\Hewlett-Packard\Media\DVD\DVDAgent.exe
C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe
C:\Program Files\HP\HP Software Update\hpwuschd2.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\CDBurnerXP\NMSAccessU.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Hewlett-Packard\KBD\kbd.exe
c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
C:\Windows\system32\conime.exe
C:\Windows\system32\wbem\wmiprvse.exe

################## | C: |

################## | C:\Windows |

################## | C:\Windows\system32 |

Présent ! C:\Windows\system32\ban_list.txt
Présent ! C:\Windows\system32\mdelk.exe
Présent ! C:\Windows\system32\wintems.exe

################## | C:\Windows\system32\drivers |

################## | C:\Users\St?phane\AppData\Roaming |

Présent ! C:\Users\St?phane\AppData\Roaming\drivers
Présent ! C:\Users\St?phane\AppData\Roaming\drivers\downld
Présent ! C:\Users\St?phane\AppData\Roaming\drivers\srosa2.sys
Présent ! C:\Users\St?phane\AppData\Roaming\drivers\wfsintwq.sys
Présent ! C:\Users\St?phane\AppData\Roaming\drivers\winupgro.exe

################## | Temporary Internet Files |

Présent ! C:\Users\St?phane\Local Settings\Temporary Internet Files\Content.IE5\9UAQAVMK\b64_3[1].jpg
Présent ! C:\Users\St?phane\Local Settings\Temporary Internet Files\Content.IE5\M9NWPOFJ\b64_3[1].jpg
Présent ! C:\Users\St?phane\Local Settings\Temporary Internet Files\Content.IE5\M9NWPOFJ\file[1].txt

################## | Registre / Clés infectieuses |

Présent ! [HKLM\SYSTEM\CurrentControlSet\Services\sK9Ou0s]
Présent ! [HKLM\SYSTEM\ControlSet001\Services\sK9Ou0s]
Présent ! [HKLM\SYSTEM\ControlSet003\Services\sK9Ou0s]
Présent ! [HKLM\SYSTEM\CurrentControlSet\Services\srosa]
Présent ! [HKLM\SYSTEM\ControlSet001\Services\srosa]
Présent ! [HKLM\SYSTEM\ControlSet003\Services\srosa]
Présent ! [HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SK9OU0S]
Présent ! [HKLM\SYSTEM\ControlSet001\Enum\Root\LEGACY_SK9OU0S]
Présent ! [HKLM\SYSTEM\ControlSet003\Enum\Root\LEGACY_SK9OU0S]
Présent ! [HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA]
Présent ! [HKLM\SYSTEM\ControlSet001\Enum\Root\LEGACY_SROSA]
Présent ! [HKCU\Software\bisoft]
Présent ! [HKCU\Software\DateTime4]
Présent ! [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] “drvsyskit”
Présent ! [HKU\S-1-5-21-3889901446-2716675481-4253712499-1000\Software\Microsoft\Windows\CurrentVersion\Run] “drvsyskit”
Présent ! [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] “german.exe”
Présent ! [HKU\S-1-5-21-3889901446-2716675481-4253712499-1000\Software\Microsoft\Windows\CurrentVersion\Run] “german.exe”
Présent ! [HKU\S-1-5-21-3889901446-2716675481-4253712499-1000\Software\bisoft]
Présent ! [HKU\S-1-5-21-3889901446-2716675481-4253712499-1000\Software\DateTime4]
Présent ! [HKCU\Software\Local AppWizard-Generated Applications\patch]
Présent ! [HKCU\Software\Local AppWizard-Generated Applications\winupgro]
Présent ! [HKU\S-1-5-21-3889901446-2716675481-4253712499-1000\Software\Local AppWizard-Generated Applications\patch]
Présent ! [HKU\S-1-5-21-3889901446-2716675481-4253712499-1000\Software\Local AppWizard-Generated Applications\winupgro]
Présent ! [HKLM\software\microsoft\security center\Svc] “AntiVirusOverride”
Présent ! [HKLM\software\microsoft\security center\Svc] “FirewallOverride”
Présent ! [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System] “DisableTaskMgr”

################## | Etat / Services / Informations |

Affichage des fichiers cachés : OK

Mode sans echec : OK

(!) Uac = 0x0

(!) Ndisuio -> Start = 4 ( Good = 3 | Bad = 4 )

EapHost -> Start = 3 ( Good = 2 | Bad = 4 )

Wlansvc -> Start = 3 ( Good = 2 | Bad = 4 )

(!) SharedAccess -> Start = 4 ( Good = 2 | Bad = 4 )

(!) windefend -> Start = 4 ( Good = 2 | Bad = 4 )

(!) wuauserv -> Start = 4 ( Good = 2 | Bad = 4 )

(!) wscsvc -> Start = 4 ( Good = 2 | Bad = 4 )

################## | Cracks / Keygens / Serials |

“C:\Users\St?phane\Documents\LimeWire\Incomplete\UVQPCH4QHVZH2FKKRJ7B4RWKWKNBMCXY\Nero 9 + serial.(www.miragetorrent.com)“Nero-9.2.6.0.exe””
01/05/2009 23:47 |Size 0 |Crc32 00000000 |Md5 d41d8cd98f00b204e9800998ecf8427e

“C:\Users\St?phane\Downloads- Nero Burning Rom 6.6.0.6 Nero Vision Express 3.0.1.18 Nero Mediaplayer 1.4.0.27 Neromix 1.4.0.27 Neronet 1.2.0.2 By Doogyice Avec patch FR\Crack"NeroCrack_By_SuperRomu_AllNero.exe”"
20/01/2005 17:36 |Size 196608 |Crc32 185574a8 |Md5 cf180a8e83c48d89323c29af09158ca3

Malwarebytes’ Anti-Malware 1.41
Database version: 2910
Windows 6.0.6001 Service Pack 1 (Safe Mode)

06/10/2009 00:38:42
mbam-log-2009-10-06 (00-38-27).txt

Scan type: Full Scan (C:|D:|E:|G:|H:|I:|K:|L:|)
Objects scanned: 250367
Time elapsed: 26 minute(s), 44 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 2
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 10

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\sK9Ou0s (Worm.Bagle) -> No action taken.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\srosa (Worm.Bagle) -> No action taken.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Program Files\Steinberg\Cubase SX\UNWISE.EXE (Malware.Packer.Morphine) -> No action taken.
C:\Users\Stéphane\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\9UAQAVMK\b64_3[1].jpg (Worm.Bagle) -> No action taken.
C:\Users\Stéphane\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\M9NWPOFJ\b64_3[1].jpg (Worm.Bagle) -> No action taken.
C:\Users\Stéphane\AppData\Roaming\drivers\downld\53227.exe (Worm.Bagle) -> No action taken.
C:\Users\Stéphane\AppData\Roaming\drivers\downld\53289.exe (Worm.Bagle) -> No action taken.
C:\Users\Stéphane\AppData\Roaming\drivers\downld\70996.exe (Worm.Bagle) -> No action taken.
C:\Users\Stéphane\Downloads- Nero Burning Rom 6.6.0.6 Nero Vision Express 3.0.1.18 Nero Mediaplayer 1.4.0.27 Neromix 1.4.0.27 Neronet 1.2.0.2 By Doogyice Avec patch FR\Crack[KEYGEN] - Nero MediaPlayer 1.4.0.27.exe (Trojan.Agent) -> No action taken.
C:\Users\Stéphane\Downloads- Nero Burning Rom 6.6.0.6 Nero Vision Express 3.0.1.18 Nero Mediaplayer 1.4.0.27 Neromix 1.4.0.27 Neronet 1.2.0.2 By Doogyice Avec patch FR\Crack[KEYGEN] - Nero VisionExpress 3.0.1.18.exe (Trojan.Agent) -> No action taken.
C:\Windows\System32\mdelk.exe (Worm.Bagle) -> No action taken.
C:\Windows\System32\wintems.exe (Worm.Bagle) -> No action taken.

############################## | FindyKill V5.012 |

User : Stéphane (Administrateurs) # PC-DE-STÉPHANE

Update on 20/09/2009 by Chiquitine29

Start at: 23:24:51 | 05/10/2009

Website : pagesperso-orange.fr…

Intel® Pentium® Dual CPU E2220 @ 2.40GHz

Microsoft® Windows Vista™ Édition Familiale Basique (6.0.6001 32-bit) # Service Pack 1

Internet Explorer 8.0.6001.18813

Windows Firewall Status : Enabled

C:\ # Disque fixe local # 584,54 Go (413,49 Go free) [HP] # NTFS

D:\ # Disque fixe local # 11,63 Go (1,58 Go free) [FACTORY_IMAGE] # NTFS

E:\ # Disque CD-ROM

G:\ # Disque amovible

H:\ # Disque amovible

I:\ # Disque amovible

K:\ # Disque CD-ROM

L:\ # Disque amovible

############################## | Processus actifs |

C:\Windows\System32\smss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\rundll32.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\hp\support\hpsysdrv.exe
C:\Windows\System32\nvraidservice.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe
C:\Program Files\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe
C:\Program Files\Hewlett-Packard\Media\DVD\DVDAgent.exe
C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe
C:\Program Files\HP\HP Software Update\hpwuschd2.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\CDBurnerXP\NMSAccessU.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Hewlett-Packard\KBD\kbd.exe
c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
C:\Windows\system32\conime.exe
C:\Windows\system32\wbem\wmiprvse.exe

################## | C: |

################## | C:\Windows |

################## | C:\Windows\system32 |

Présent ! C:\Windows\system32\ban_list.txt
Présent ! C:\Windows\system32\mdelk.exe
Présent ! C:\Windows\system32\wintems.exe

################## | C:\Windows\system32\drivers |

################## | C:\Users\St?phane\AppData\Roaming |

Présent ! C:\Users\St?phane\AppData\Roaming\drivers
Présent ! C:\Users\St?phane\AppData\Roaming\drivers\downld
Présent ! C:\Users\St?phane\AppData\Roaming\drivers\srosa2.sys
Présent ! C:\Users\St?phane\AppData\Roaming\drivers\wfsintwq.sys
Présent ! C:\Users\St?phane\AppData\Roaming\drivers\winupgro.exe

################## | Temporary Internet Files |

Présent ! C:\Users\St?phane\Local Settings\Temporary Internet Files\Content.IE5\9UAQAVMK\b64_3[1].jpg
Présent ! C:\Users\St?phane\Local Settings\Temporary Internet Files\Content.IE5\M9NWPOFJ\b64_3[1].jpg
Présent ! C:\Users\St?phane\Local Settings\Temporary Internet Files\Content.IE5\M9NWPOFJ\file[1].txt

################## | Registre / Clés infectieuses |

Présent ! [HKLM\SYSTEM\CurrentControlSet\Services\sK9Ou0s]
Présent ! [HKLM\SYSTEM\ControlSet001\Services\sK9Ou0s]
Présent ! [HKLM\SYSTEM\ControlSet003\Services\sK9Ou0s]
Présent ! [HKLM\SYSTEM\CurrentControlSet\Services\srosa]
Présent ! [HKLM\SYSTEM\ControlSet001\Services\srosa]
Présent ! [HKLM\SYSTEM\ControlSet003\Services\srosa]
Présent ! [HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SK9OU0S]
Présent ! [HKLM\SYSTEM\ControlSet001\Enum\Root\LEGACY_SK9OU0S]
Présent ! [HKLM\SYSTEM\ControlSet003\Enum\Root\LEGACY_SK9OU0S]
Présent ! [HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA]
Présent ! [HKLM\SYSTEM\ControlSet001\Enum\Root\LEGACY_SROSA]
Présent ! [HKCU\Software\bisoft]
Présent ! [HKCU\Software\DateTime4]
Présent ! [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] “drvsyskit”
Présent ! [HKU\S-1-5-21-3889901446-2716675481-4253712499-1000\Software\Microsoft\Windows\CurrentVersion\Run] “drvsyskit”
Présent ! [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] “german.exe”
Présent ! [HKU\S-1-5-21-3889901446-2716675481-4253712499-1000\Software\Microsoft\Windows\CurrentVersion\Run] “german.exe”
Présent ! [HKU\S-1-5-21-3889901446-2716675481-4253712499-1000\Software\bisoft]
Présent ! [HKU\S-1-5-21-3889901446-2716675481-4253712499-1000\Software\DateTime4]
Présent ! [HKCU\Software\Local AppWizard-Generated Applications\patch]
Présent ! [HKCU\Software\Local AppWizard-Generated Applications\winupgro]
Présent ! [HKU\S-1-5-21-3889901446-2716675481-4253712499-1000\Software\Local AppWizard-Generated Applications\patch]
Présent ! [HKU\S-1-5-21-3889901446-2716675481-4253712499-1000\Software\Local AppWizard-Generated Applications\winupgro]
Présent ! [HKLM\software\microsoft\security center\Svc] “AntiVirusOverride”
Présent ! [HKLM\software\microsoft\security center\Svc] “FirewallOverride”
Présent ! [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System] “DisableTaskMgr”

################## | Etat / Services / Informations |

Affichage des fichiers cachés : OK

Mode sans echec : OK

(!) Uac = 0x0

(!) Ndisuio -> Start = 4 ( Good = 3 | Bad = 4 )

EapHost -> Start = 3 ( Good = 2 | Bad = 4 )

Wlansvc -> Start = 3 ( Good = 2 | Bad = 4 )

(!) SharedAccess -> Start = 4 ( Good = 2 | Bad = 4 )

(!) windefend -> Start = 4 ( Good = 2 | Bad = 4 )

(!) wuauserv -> Start = 4 ( Good = 2 | Bad = 4 )

(!) wscsvc -> Start = 4 ( Good = 2 | Bad = 4 )

################## | Cracks / Keygens / Serials |

“C:\Users\St?phane\Documents\LimeWire\Incomplete\UVQPCH4QHVZH2FKKRJ7B4RWKWKNBMCXY\Nero 9 + serial.(www.miragetorrent.com)“Nero-9.2.6.0.exe””
01/05/2009 23:47 |Size 0 |Crc32 00000000 |Md5 d41d8cd98f00b204e9800998ecf8427e

“C:\Users\St?phane\Downloads- Nero Burning Rom 6.6.0.6 Nero Vision Express 3.0.1.18 Nero Mediaplayer 1.4.0.27 Neromix 1.4.0.27 Neronet 1.2.0.2 By Doogyice Avec patch FR\Crack"NeroCrack_By_SuperRomu_AllNero.exe”"
20/01/2005 17:36 |Size 196608 |Crc32 185574a8 |Md5 cf180a8e83c48d89323c29af09158ca3

un grand merci à toi jeanmimigab de bien vouloir traiter aussi rapidement mon problème;

Je joins les 4 rapports demandés. En espérant que tu y liras les infos qu’il te faut pour me dépanner !

Merci encore

############################## | FindyKill V5.012 |

User : Stéphane (Administrateurs) # PC-DE-STÉPHANE

Update on 20/09/2009 by Chiquitine29

Start at: 07:56:44 | 07/10/2009

Website : pagesperso-orange.fr…

Intel® Pentium® Dual CPU E2220 @ 2.40GHz

Microsoft® Windows Vista™ Édition Familiale Basique (6.0.6001 32-bit) # Service Pack 1

Internet Explorer 8.0.6001.18813

Windows Firewall Status : Enabled

C:\ # Disque fixe local # 584,54 Go (413,08 Go free) [HP] # NTFS

D:\ # Disque fixe local # 11,63 Go (1,58 Go free) [FACTORY_IMAGE] # NTFS

E:\ # Disque CD-ROM

G:\ # Disque amovible

H:\ # Disque amovible

I:\ # Disque amovible

K:\ # Disque CD-ROM

L:\ # Disque amovible

############################## | Processus actifs |

C:\Windows\System32\smss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\LogonUI.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\rundll32.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\userinit.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\runonce.exe
C:\Windows\system32\conime.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\CDBurnerXP\NMSAccessU.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\wbem\wmiprvse.exe

################## | C: |

################## | C:\Windows |

################## | C:\Windows\system32 |

Supprimé ! C:\Windows\system32\ban_list.txt
Supprimé ! C:\Windows\system32\mdelk.exe
Supprimé ! C:\Windows\system32\wintems.exe

################## | C:\Windows\system32\drivers |

################## | C:\Users\St?phane\AppData\Roaming |

Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\101151.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\101463.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\101478.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\102180.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\103553.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\103896.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\104349.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\111587.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\112383.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\112804.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\113709.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\115549.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\115908.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\115924.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\118919.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\120183.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\120822.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\121228.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\121930.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\121961.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\122788.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\122819.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\123802.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\124067.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\124910.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\124972.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\125237.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\125736.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\126048.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\126095.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\126204.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\126875.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\126984.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\128622.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\133100.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\133458.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\133521.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\133864.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\134379.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\134519.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\135112.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\135518.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\135986.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\136126.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\136313.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\140962.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\142241.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\142444.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\143271.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\143302.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\143926.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\144160.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\144410.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\144566.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\145190.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\145470.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\145486.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\146375.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\146391.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\146484.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\146921.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\147436.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\147592.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\147608.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\147998.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\14803714.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\14804962.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\14804978.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\14832013.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\148325.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\14832668.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\14832684.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\148419.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\14903727.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\14905427.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\14906613.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\149074.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\149417.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\149636.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\14990869.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\14992569.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\14992788.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\14993443.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\14994036.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\14994051.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\15020634.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\15022646.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\15022755.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\150447.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\150587.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\150650.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\15117510.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\15120490.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\15121785.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\151523.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\15221641.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\15224964.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\15225806.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\15299579.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\15299642.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\153348.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\15342401.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\15342417.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\15429746.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\15431041.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\15432102.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\154581.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\154612.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\154799.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\154830.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\154877.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\15499479.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\15500384.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\15500555.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\15500961.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\15501210.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\15501226.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\155127.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\15527356.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\15529384.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\15529743.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\156359.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\15677710.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\15680924.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\15682546.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\157030.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\15775959.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\15779563.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\15780437.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\158559.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\158793.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\158933.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\159105.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\159183.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\159495.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\159745.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\159760.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\159776.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\162256.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\162615.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\162709.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\163021.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\163270.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\163286.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\163754.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\16575558.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\16575574.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\166016.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\166250.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\16649986.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\16652123.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\16653761.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\166655.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\166733.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\166874.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\167030.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\167061.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\16714805.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\16715335.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\16715600.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\16716099.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\16716115.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\167357.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\167373.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\16741652.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\16742058.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\16742152.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\16836314.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\16838841.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\16840261.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\169198.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\169229.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\169401.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\169588.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\169666.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\170009.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\170197.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\170212.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\17279544.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\17281743.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\17282539.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\173114.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\173239.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\173629.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\173691.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\173722.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\173863.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\174190.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\174424.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\174440.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\174705.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\175033.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\175282.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\175360.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\175688.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\175875.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\175891.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\176515.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\176951.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\177045.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\180134.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\180602.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\180680.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\181039.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\181241.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\181304.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\181538.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\181647.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\181709.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\182115.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\1822232.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\1822419.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\1822434.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\182443.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\182599.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\183503.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\183535.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\183847.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\183925.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\185297.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\187372.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\187450.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\188028.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\188293.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\188496.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\188620.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\188932.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\189198.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\189276.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\189385.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\189572.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\189759.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\189900.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\190290.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\1906082.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\1907424.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\1908282.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\191382.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\191943.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\192286.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\192661.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\192676.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\192770.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\193176.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\193191.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\193269.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\193644.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\193893.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\193909.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\193956.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\194049.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\194392.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\194626.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\194736.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\194751.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\1952243.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\1952758.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\1952836.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\1953163.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\1953475.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\196342.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\196764.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\196842.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\196888.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\197091.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\1973163.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\1973709.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\1973787.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\197778.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\197856.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\198183.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\198573.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\198589.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\200180.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\200367.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\200539.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\200601.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\200679.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\201085.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\201163.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\201506.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\201818.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\201834.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\202068.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\202177.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\202239.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\202504.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\202941.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\202957.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\203721.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\2043410.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\2044798.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\2045469.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\207730.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\208058.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\208604.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\209088.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\209166.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\2110568.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\2112050.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\2112425.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\212208.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\212442.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\213190.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\213253.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\215296.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\215468.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\216934.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\217122.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\217168.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\217340.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\217668.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\217980.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\219836.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\220367.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\220523.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\220616.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\220944.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\221022.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\221115.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\221318.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\221396.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\221552.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\221708.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\221786.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\221802.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\221958.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\221973.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\223502.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\224391.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\224625.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\225483.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\225561.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\226310.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\226482.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\226934.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\227199.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\227262.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\227402.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\227433.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\227636.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\227948.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\228260.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\228744.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\229430.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\237979.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\238369.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\238385.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\238431.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\238447.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\238931.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\239009.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\239102.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\239789.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\240179.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\240272.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\240662.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\240849.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\240912.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\240927.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\241115.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\241739.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\241832.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\242144.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\242394.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\245919.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\247011.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\247089.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\248213.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\249601.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\250272.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\250818.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\250896.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\254032.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\254468.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\254531.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\254734.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\254921.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\255170.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\256091.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\256762.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\259117.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\260818.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\261083.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\261161.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\261286.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\261442.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\264172.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\268087.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\268493.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\268555.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\268633.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\270287.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\271566.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\271628.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\271987.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\272018.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\272081.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\272284.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\273719.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\274265.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\274624.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\274639.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\274655.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\275107.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\275778.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\276152.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\276995.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\280271.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\281800.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\282486.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\284436.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\285949.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\286308.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\286979.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\288882.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\289272.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\289350.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\290645.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\291378.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\292189.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\296635.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\29707285.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\29709704.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\297618.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\29766597.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\29767143.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\29856204.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\29858404.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\29859558.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\298632.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\298757.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\299007.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\29916888.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\29918651.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\29918916.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\29919868.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\29920601.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\29951068.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\29952035.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\29952191.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\299771.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\300067.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\30026947.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\30028772.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\30029677.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\300411.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\301035.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\30111796.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\30113964.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\30114557.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\302111.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\302423.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\30246675.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\30246721.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\30270434.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\30270465.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\30374065.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\30376218.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\30377996.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\30423689.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\30424406.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\30424531.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\30425030.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\30425233.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\30425249.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\30444156.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\30444562.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\30444687.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\30583996.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\30585821.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\30586788.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\30680045.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\30685833.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\30687097.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\316479.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\317976.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\318335.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\321096.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\321954.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\322703.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\323140.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\323436.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\323858.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\325355.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\326042.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\341018.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\343701.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\345121.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\345791.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\348319.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\351376.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\352765.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\352827.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\352874.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\353108.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\354637.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\354980.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\360315.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\361703.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\362374.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\365182.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\366976.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\367709.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\374090.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\377038.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\378458.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\379144.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\379488.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\380845.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\381141.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\381500.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\382093.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\382436.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\382951.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\383076.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\383388.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\38547.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\387225.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\388302.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\392514.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\392935.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\392997.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\393309.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\393387.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\393699.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\393949.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\394058.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\394401.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\394994.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\395743.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\398707.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\399112.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\400891.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\401686.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\403059.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\404448.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\405743.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\407053.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\407381.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\410547.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\412232.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\412669.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\412919.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\414338.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\414681.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\414697.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\415118.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\415196.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\44574649.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\44576162.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\44610186.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\44611200.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\44686720.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\44689575.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\44692305.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\44748028.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\44748777.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\44748933.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\44749479.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\44749791.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\44788791.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\44790351.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\44790788.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\448924.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\44987069.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\44989034.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\44990111.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\45062963.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\45065475.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\45066395.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\45159356.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\45161946.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\45161961.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\45197623.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\45198013.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\45265562.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\45268416.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\45271006.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\45280257.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\45282394.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\45282675.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\453463.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\45400830.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\45401594.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\45401735.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\45402203.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\45402562.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\45402577.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\45431266.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\45432467.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\45432654.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\454883.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\45611447.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\45614427.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\45615831.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\456474.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\456552.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\456661.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\45703956.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\45706218.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\45706686.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\457566.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\458190.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\458596.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\459173.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\460655.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\460951.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\463744.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\465054.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\465522.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\466193.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\466567.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\466926.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\46722.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\467597.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\473385.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\473759.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\48453.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\489655.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\492963.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\493384.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\494445.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\495443.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\516425.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\517954.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\518126.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\520934.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\522494.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\522837.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\52509.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\53461.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\53508.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\535816.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\537688.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\538281.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\538421.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\539264.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\539326.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\539482.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\539966.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\540637.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\540871.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\541027.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\541619.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\541729.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\54491.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\547703.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\549170.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\549513.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\55629.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\56768.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\57299.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\57798.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\58266.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\58531.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\590276.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\592054.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\592429.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\59249.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\59517938.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\59519498.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\59563646.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\59563911.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\59563927.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\59654704.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\59657574.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\59660164.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\59733516.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\59734374.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\59734514.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\59734998.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\59735294.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\59759287.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\59760285.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\59760473.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\59904898.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\59907441.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\59908455.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\59997376.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\60000324.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\60000839.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\61947.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\62322.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\62930.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\62946.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\67111.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\67548.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\68500.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\685546.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\687324.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\688245.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\708150.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\711192.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\711832.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\71510.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\71651.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\71682.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\71698.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\71729.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\71994.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\72010.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\72446.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\72509.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\72790.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\72821.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\74459.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\74473629.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\74475516.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\74475610.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\74529540.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\74532410.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\74532426.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\74630410.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\74633717.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\74635090.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\74777815.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\74779391.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\74779625.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\74780249.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\74781029.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\74826971.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\74827860.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\74828141.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\74967403.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\74969182.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\74970133.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\75074794.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\75078382.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\75079193.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\75488.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\75785.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\75800.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\76440.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\76612.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\76690.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\76892.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\76908.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\773265.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\77470.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\775512.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\776120.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\77704.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\78577.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\78811.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\78827.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\79997.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\80231.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\80449.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\81136.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\82696.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\84365.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\85348.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\85738.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\85862.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\85878.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\86018.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\86096.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\86112.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\86284.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\86455.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\87485.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\87953.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\88826.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\88842.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\88904.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\89435.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\90823.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\90917.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\91650.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\91666.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\91806.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\92524.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\93163.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\97734.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\97828.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\97859.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\98140.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\98155.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\98592.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\98608.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld\99669.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\downld
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\srosa2.sys
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\wfsintwq.sys
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers\winupgro.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\drivers
Supprimé ! C:\Users\St?phane\AppData\Roaming\m\data.oct
Supprimé ! C:\Users\St?phane\AppData\Roaming\m\flec006.exe
Supprimé ! C:\Users\St?phane\AppData\Roaming\m\list.oct
Supprimé ! C:\Users\St?phane\AppData\Roaming\m\shared-Bitdefender.Antivirus.Plus.v.10.MULTiLANGUAGE.zip
Supprimé ! C:\Users\St?phane\AppData\Roaming\m\shared\1-abc.net Right Click Configurator 1.01.zip
Supprimé ! C:\Users\St?phane\AppData\Roaming\m\shared\1ClickPicGrabber_3.50.zip
Supprimé ! C:\Users\St?phane\AppData\Roaming\m\shared\1Z0-025_-Backup_and_Recovery_Practice_Test_Questions_1.0.zip
Supprimé ! C:\Users\St?phane\AppData\Roaming\m\shared\2Morrow Web Server Monitor 1.2.zip
Supprimé ! C:\Users\St?phane\AppData\Roaming\m\shared\3D_Newton_Pendulum_Screensaver_1.0.zip
Supprimé ! C:\Users\St?phane\AppData\Roaming\m\shared\55 Free Sample Recipes Ebook 1.zip
Supprimé ! C:\Users\St?phane\AppData\Roaming\m\shared\Abstrakt.zip
Supprimé ! C:\Users\St?phane\AppData\Roaming\m\shared\ACDSee_Mobile_for_Windows_Ce_1.2.zip
Supprimé ! C:\Users\St?phane\AppData\Roaming\m\shared\AcroPDF_2.00.zip
Supprimé ! C:\Users\St?phane\AppData\Roaming\m\shared\Add Shade Font 1.0.zip
Supprimé ! C:\Users\St?phane\AppData\Roaming\m\shared\All DVD to Zune Converter 1.2.zip
Supprimé ! C:\Users\St?phane\AppData\Roaming\m\shared\ALLESTA 1.3.zip
Supprimé ! C:\Users\St?phane\AppData\Roaming\m\shared\Allok Video Converter 4.4.0314.zip
Supprimé ! C:\Users\St?phane\AppData\Roaming\m\shared\Anxiety_Panic_Attack_1.3.zip
Supprimé ! C:\Users\St?phane\AppData\Roaming\m\shared\APOD_1.0.zip
Supprimé ! C:\Users\St?phane\AppData\Roaming\m\shared\AR Magic Packet ActiveX Library 1.0.zip
Supprimé ! C:\Users\St?phane\AppData\Roaming\m\shared\Ares_Tube_3.0.zip
Supprimé ! C:\Users\St?phane\AppData\Roaming\m\shared\Asman_Calendar_Maker_1.6
(With_Crack).zip
Supprimé ! C:\Users\St?phane\AppData\Roaming\m\shared\AspnetUpload 2.3.zip
Supprimé ! C:\Users\St?phane\AppData\Roaming\m\shared\autOKdj 1.0 Beta 1.4.zip
Supprimé ! C:\Users\St?phane\AppData\Roaming\m\shared\avast! Server Edition 4.7.726.zip
Supprimé ! C:\Users\St?phane\AppData\Roaming\m\shared\Back IS Close 1.4.zip
Supprimé ! C:\Users\St?phane\AppData\Roaming\m\shared\BeesWees_Imaging_Suite_1.0.zip
Supprimé ! C:\Users\St?phane\AppData\Roaming\m\shared\Blue_Iris_Full_1.55.05.zip
Supprimé ! C:\Users\St?phane\AppData\Roaming\m\shared\BookReader_4.4.zip
Supprimé ! C:\Users\St?phane\AppData\Roaming\m\shared\Bouvier’s_Law_Dictionary_for_Palm_OS_1.8.zip
Supprimé ! C:\Users\St?phane\AppData\Roaming\m\shared\Cajun Queen Font 1.0.zip
Supprimé ! C:\Users\St?phane\AppData\Roaming\m\shared\Caravaggio Art 1.0.zip
Supprimé ! C:\Users\St?phane\AppData\Roaming\m\shared\Channel Mixer Greyscale 1.1.zip
Supprimé ! C:\Users\St?phane\AppData\Roaming\m\shared\CHM OwnerGuard 8.3.0.0.zip
Supprimé ! C:\Users\St?phane\AppData\Roaming\m\shared\ClutterKiller 1.0.5.0.zip
Supprimé ! C:\Users\St?phane\AppData\Roaming\m\shared\Corel Grafigo 2.0.zip
Supprimé ! C:\Users\St?phane\AppData\Roaming\m\shared\Countdown to Digital Television 1.0.0.0.zip
Supprimé ! C:\Users\St?phane\AppData\Roaming\m\shared\Dave_4.0.zip
Supprimé ! C:\Users\St?phane\AppData\Roaming\m\shared\Digital_Image_Tool_1.zip
Supprimé ! C:\Users\St?phane\AppData\Roaming\m\shared\Document_Backup_3.6.zip
Supprimé ! C:\Users\St?phane\AppData\Roaming\m\shared\E-mail Talker 4.0.zip
Supprimé ! C:\Users\St?phane\AppData\Roaming\m\shared\E-Marketing_1.4_Key.zip
Supprimé ! C:\Users\St?phane\AppData\Roaming\m\shared\Editawy_1.0.zip
Supprimé ! C:\Users\St?phane\AppData\Roaming\m\shared\Europa Universalis II 1.01 to 1.02 patch.zip
Supprimé ! C:\Users\St?phane\AppData\Roaming\m\shared\EZ MP4 iPod Converter 1.0.zip
Supprimé ! C:\Users\St?phane\AppData\Roaming\m\shared\File_Splitter_1.1.028.zip
Supprimé ! C:\Users\St?phane\AppData\Roaming\m\shared\FinalData_Plus_2.0.zip
Supprimé ! C:\Users\St?phane\AppData\Roaming\m\shared\Fly!_II_map_pack_14.zip
Supprimé ! C:\Users\St?phane\AppData\Roaming\m\shared\Folder Manager 2003.0006.0020.zip
Supprimé ! C:\Users\St?phane\AppData\Roaming\m\shared\Folder Size 1.4.zip
Supprimé ! C:\Users\St?phane\AppData\Roaming\m\shared\FreeSMTP.Net 1.0.zip
Supprimé ! C:\Users\St?phane\AppData\Roaming\m\shared\FVM 1.0.zip
Supprimé ! C:\Users\St?phane\AppData\Roaming\m\shared\GeometryProof Professional Edition 5.10.zip
Supprimé ! C:\Users\St?phane\AppData\Roaming\m\shared\Glog_1.1.zip
Supprimé ! C:\Users\St?phane\AppData\Roaming\m\shared\GOGO_Photo_To_Movie_Converter_1.0.zip
Supprimé ! C:\Users\St?phane\AppData\Roaming\m\shared\Gorgeous Destinations Screensaver 1.0.zip
Supprimé ! C:\Users\St?phane\AppData\Roaming\m\shared\Grocery_List_Organizer_1.0_Key+Serial.zip
Supprimé ! C:\Users\St?phane\AppData\Roaming\m\shared\Helzberg_Diamond’s_Snow_Globe_1.0.zip
Supprimé ! C:\Users\St?phane\AppData\Roaming\m\shared\Honda Civic 2000 Screensaver 1.zip
Supprimé ! C:\Users\St?phane\AppData\Roaming\m\shared\HTML Notes 1.19.zip
Supprimé ! C:\Users\St?phane\AppData\Roaming\m\shared\HTTP E-mail MAPI Transport 1.3.5

Malwarebytes’ Anti-Malware 1.41
Version de la base de données: 2910
Windows 6.0.6001 Service Pack 1

07/10/2009 08:12:02
mbam-log-2009-10-07 (08-12-02).txt

Type de recherche: Examen rapide
Eléments examinés: 92196
Temps écoulé: 3 minute(s), 53 second(s)

Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 0
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 0

Processus mémoire infecté(s):
(Aucun élément nuisible détecté)

Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)

Clé(s) du Registre infectée(s):
(Aucun élément nuisible détecté)

Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)

Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)

Dossier(s) infecté(s):
(Aucun élément nuisible détecté)

Fichier(s) infecté(s):
(Aucun élément nuisible détecté)


ComboFix 09-10-06.03 - Stéphane 07/10/2009 8:22.1.2 - NTFSx86 Microsoft® Windows Vista™ Édition Familiale Basique 6.0.6001.1.1252.33.1036.18.2557.1679 [GMT 2:00] Lancé depuis: c:\users\Stéphane\Desktop\steph.exe SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} .

(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.

c:$recycle.bin\S-1-5-21-282585261-3185438259-2835640832-1000
c:$recycle.bin\S-1-5-21-3889901446-2716675481-4253712499-500
c:$recycle.bin\S-1-5-21-652066268-2905062793-1360979236-500
c:\programdata\Microsoft\Windows\Start Menu\Programs\Uninstall.lnk

.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_SK9OU0S

((((((((((((((((((((((((((((( Fichiers créés du 2009-09-07 au 2009-10-07 ))))))))))))))))))))))))))))))))))))
.

2009-10-07 06:03 . 2009-10-01 08:29 195440 ------w- c:\windows\system32\MpSigStub.exe
2009-10-05 21:47 . 2009-09-10 12:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-10-05 21:47 . 2009-10-05 21:47 -------- d-----w- c:\program files\Malwarebytes’ Anti-Malware
2009-10-05 21:47 . 2009-10-05 21:47 -------- d-----w- c:\programdata\Malwarebytes
2009-10-05 21:47 . 2009-09-10 12:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-10-05 21:21 . 2009-10-07 05:56 -------- d-----w- C:\FindyKill
2009-10-05 20:09 . 2009-10-05 20:09 -------- d-sh–w- c:\windows\system32%APPDATA%
2009-10-05 19:41 . 2009-10-05 20:15 -------- d-----w- c:\program files\Sonic Foundry
2009-10-05 19:40 . 2009-10-05 19:40 -------- d-----w- c:\program files\Sonic Foundry Setup
2009-10-03 17:05 . 2009-10-03 17:07 -------- d-----w- c:\program files\Unlocker
2009-09-14 16:36 . 2009-09-14 16:36 -------- d-----w- c:\program files\HP
2009-09-14 16:35 . 2009-09-14 16:35 -------- d-----w- c:\windows\Hewlett-Packard
2009-09-13 16:04 . 2009-09-13 16:05 -------- d-----w- c:\program files\CDBurnerXP
2009-09-12 22:22 . 2009-09-12 22:22 -------- d-----w- c:\programdata\AVS4YOU
2009-09-12 22:21 . 2009-09-12 22:27 -------- d-----w- c:\program files\Common Files\AVSMedia
2009-09-12 22:21 . 2008-08-13 09:22 974848 ----a-w- c:\windows\system32\mfc70.dll
2009-09-12 22:21 . 2008-08-13 09:22 487424 ----a-w- c:\windows\system32\msvcp70.dll
2009-09-12 22:21 . 2008-08-13 09:22 344064 ----a-w- c:\windows\system32\msvcr70.dll
2009-09-12 22:21 . 2008-08-13 09:22 1700352 ----a-w- c:\windows\system32\GdiPlus.dll
2009-09-12 22:21 . 2008-08-13 09:22 24576 ----a-w- c:\windows\system32\msxml3a.dll
2009-09-12 22:21 . 2009-09-12 22:27 -------- d-----w- c:\program files\AVS4YOU
2009-09-12 19:57 . 2009-09-12 19:57 -------- d-----w- c:\programdata\Canneverbe Limited
2009-09-09 07:49 . 2009-09-09 07:49 -------- d-----w- c:\program files\Common Files\Digidesign
2009-09-09 05:47 . 2009-08-14 17:07 897608 ----a-w- c:\windows\system32\drivers\tcpip.sys
2009-09-09 05:47 . 2009-08-14 16:29 104960 ----a-w- c:\windows\system32\netiohlp.dll
2009-09-09 05:47 . 2009-08-14 14:16 9728 ----a-w- c:\windows\system32\TCPSVCS.EXE
2009-09-09 05:47 . 2009-08-14 14:16 27136 ----a-w- c:\windows\system32\NETSTAT.EXE
2009-09-09 05:47 . 2009-08-14 14:16 19968 ----a-w- c:\windows\system32\ARP.EXE
2009-09-09 05:47 . 2009-08-14 16:29 17920 ----a-w- c:\windows\system32\netevent.dll
2009-09-09 05:47 . 2009-08-14 14:16 17920 ----a-w- c:\windows\system32\ROUTE.EXE
2009-09-09 05:47 . 2009-08-14 14:16 11264 ----a-w- c:\windows\system32\MRINFO.EXE
2009-09-09 05:47 . 2009-08-14 14:16 8704 ----a-w- c:\windows\system32\HOSTNAME.EXE
2009-09-09 05:47 . 2009-08-14 14:16 10240 ----a-w- c:\windows\system32\finger.exe
2009-09-09 05:45 . 2009-07-11 19:32 293376 ----a-w- c:\windows\system32\wlanmsm.dll
2009-09-09 05:45 . 2009-07-11 19:29 127488 ----a-w- c:\windows\system32\L2SecHC.dll
2009-09-09 05:45 . 2009-07-11 19:32 513024 ----a-w- c:\windows\system32\wlansvc.dll
2009-09-09 05:45 . 2009-07-11 19:32 302592 ----a-w- c:\windows\system32\wlansec.dll
2009-09-09 05:45 . 2009-06-10 12:11 2868224 ----a-w- c:\windows\system32\mf.dll

.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-06 20:17 . 2008-12-01 13:31 672084 ----a-w- c:\windows\system32\perfh00C.dat
2009-10-06 20:17 . 2008-12-01 13:31 124228 ----a-w- c:\windows\system32\perfc00C.dat
2009-09-25 16:54 . 2009-03-06 16:37 -------- d-----w- c:\program files\Steinberg
2009-09-14 16:37 . 2008-12-01 05:29 -------- d—a-w- c:\program files\Common Files\LightScribe
2009-09-14 05:44 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-09-14 05:44 . 2009-03-14 19:19 -------- d-----w- c:\programdata\Microsoft Help
2009-09-12 19:50 . 2009-03-16 22:31 -------- d-----w- c:\program files\Common Files\Nero
2009-09-12 19:49 . 2009-03-16 22:31 -------- d-----w- c:\programdata\Nero
2009-09-12 19:49 . 2009-03-16 22:31 -------- d-----w- c:\program files\Nero
2009-09-06 08:51 . 2009-09-06 08:51 -------- d-----w- c:\program files\Ahead
2009-09-06 08:50 . 2008-12-01 05:30 -------- d-----w- c:\program files\Java
2009-09-05 17:49 . 2009-03-07 14:49 -------- d-----w- c:\program files\NCH Software
2009-08-28 12:39 . 2009-09-05 16:38 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2009-08-28 10:15 . 2009-09-05 16:38 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2009-07-25 03:23 . 2009-04-23 16:10 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-07-21 21:52 . 2009-07-29 07:17 915456 ----a-w- c:\windows\system32\wininet.dll
2009-07-21 21:47 . 2009-07-29 07:17 109056 ----a-w- c:\windows\system32\iesysprep.dll
2009-07-21 21:47 . 2009-07-29 07:17 71680 ----a-w- c:\windows\system32\iesetup.dll
2009-07-21 20:13 . 2009-07-29 07:17 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2009-07-17 14:35 . 2009-08-14 14:12 71680 ----a-w- c:\windows\system32\atl.dll
2009-07-14 13:00 . 2009-08-14 14:12 313344 ----a-w- c:\windows\system32\wmpdxm.dll
2009-07-14 12:59 . 2009-08-14 14:12 4096 ----a-w- c:\windows\system32\dxmasf.dll
2009-07-14 12:58 . 2009-08-14 14:12 7680 ----a-w- c:\windows\system32\spwmp.dll
2009-07-14 10:59 . 2009-08-14 14:12 8147456 ----a-w- c:\windows\system32\wmploc.DLL
2008-12-01 13:55 . 2008-12-01 13:54 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.

((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
Note les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“AlcoholAutomount”=“c:\program files\Alcohol Soft\Alcohol 120\axcmd.exe” [2009-04-24 203928]
“WMPNSCFG”=“c:\program files\Windows Media Player\WMPNSCFG.exe” [2008-01-21 202240]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“Windows Defender”=“c:\program files\Windows Defender\MSASCui.exe” [2008-01-21 1008184]
“hpsysdrv”=“c:\hp\support\hpsysdrv.exe” [2007-04-18 65536]
“KBD”=“c:\program files\Hewlett-Packard\KBD\KbdStub.EXE” [2008-07-21 12288]
“NVRaidService”=“c:\windows\system32\nvraidservice.exe” [2008-10-03 203296]
“NvCplDaemon”=“c:\windows\system32\NvCpl.dll” [2008-10-25 13584928]
“NvMediaCenter”=“c:\windows\system32\NvMcTray.dll” [2008-10-25 92704]
“HP Health Check Scheduler”=“c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe” [2008-10-09 75008]
“UpdateP2GoShortCut”=“c:\program files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe” [2008-06-13 210216]
“UpdatePDIRShortCut”=“c:\program files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe” [2008-06-13 210216]
“UpdatePSTShortCut”=“c:\program files\CyberLink\CyberLink DVD Suite Deluxe\MUITransfer\MUIStartMenu.exe” [2008-09-11 210216]
“TSMAgent”=“c:\program files\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe” [2008-10-17 1152296]
“CLMLServer for HP TouchSmart”=“c:\program files\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe” [2008-10-17 189736]
“DVDAgent”=“c:\program files\Hewlett-Packard\Media\DVD\DVDAgent.exe” [2008-09-26 1148200]
“SmartMenu”=“c:\program files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe” [2008-09-23 912688]
“GrooveMonitor”=“c:\program files\Microsoft Office\Office12\GrooveMonitor.exe” [2008-10-25 31072]
“QuickTime Task”=“c:\program files\QuickTime\qttask.exe” [2009-04-15 413696]
“Adobe Reader Speed Launcher”=“c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe” [2009-02-27 35696]
“SunJavaUpdateSched”=“c:\program files\Java\jre6\bin\jusched.exe” [2009-07-25 149280]
“HP Software Update”=“c:\program files\HP\HP Software Update\HPWuSchd2.exe” [2008-12-08 54576]
“UnlockerAssistant”=“c:\program files\Unlocker\UnlockerAssistant.exe” [2009-10-07 15872]
“Malwarebytes Anti-Malware (reboot)”=“c:\program files\Malwarebytes’ Anti-Malware\mbam.exe” [2009-09-10 1312080]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
“EnableLUA”= 0 (0x0)
“EnableUIADesktopToggle”= 0 (0x0)
“HideFastUserSwitching”= 0 (0x0)
“UacDisableNotify”= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
“aux”=wdmaud.drv

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-3889901446-2716675481-4253712499-1000]
“EnableNotificationsRef”=dword:00000004

[HKLM~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
“{08E64F24-B609-4BEC-8FB1-929002495E1A}”= c:\program files\CyberLink\PowerDirector\PDR.EXE:CyberLink PowerDirector
“{327C57FA-2829-4FCA-931F-5E1C8E136470}”= c:\program files\Hewlett-Packard\TouchSmart\Media\HPTouchSmartMusic.exe:HP TouchSmart Music
“{A6337A4D-7FD8-49C3-8749-A99D09FC64A7}”= c:\program files\Hewlett-Packard\TouchSmart\Media\HPTouchSmartPhoto.exe:HP TouchSmart Photo
“{2CB2FD2B-A39E-4D1B-8045-C0105C3285B7}”= c:\program files\Hewlett-Packard\TouchSmart\Media\HPTouchSmartVideo.exe:HP TouchSmart Video
“{C0F251A3-B0AD-47E8-9DC0-5A354D58C6B4}”= c:\program files\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe:HP TouchSmart Media Resident Program
“{85B46F8A-8DA6-498F-A00C-415B956DEE93}”= c:\program files\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe:CyberLink Media Service
“{1CE1700B-D4BF-4A5C-B31E-BBD055476614}”= c:\program files\Hewlett-Packard\Media\DVD\HPTouchSmartMusic.exe:HP TouchSmart Music
“{3D48D6C1-0D17-40C3-9D98-07ED19E1A076}”= c:\program files\Hewlett-Packard\Media\DVD\HPTouchSmartPhoto.exe:HP TouchSmart Photo
“{7200C305-9B9B-41CE-8B02-259903AE597B}”= c:\program files\Hewlett-Packard\Media\DVD\HPTouchSmartVideo.exe:HP TouchSmart Video
“{3B63FF9E-9CA3-4AD7-83ED-043EC1C77D1C}”= c:\program files\Hewlett-Packard\Media\DVD\TSMAgent.exe:HP TouchSmart Media Resident Program
“{9E3D9482-BD46-4613-A658-8A163B4878E9}”= c:\program files\Hewlett-Packard\Media\DVD\Kernel\CLML\CLMLSvc.exe:CyberLink Media Service
“{8A90A436-8F54-4978-99AD-48CF741F0DD0}”= c:\program files\Hewlett-Packard\Media\DVD\HPDVDSmart.exe:HP MediaSmart DVD
“TCP Query User{BE64AE0F-BFBD-4C47-884B-D3E7F6F39F8D}c:\program files\emule\emule.exe”= UDP:c:\program files\emule\emule.exe:eMule
“UDP Query User{B20DC7D2-C8DD-4F21-BDBA-3C046AA511CC}c:\program files\emule\emule.exe”= TCP:c:\program files\emule\emule.exe:eMule
“{2E4D7E5E-8A7C-462A-835C-2C80F8E566F8}”= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
“{8DE06DF7-B0EF-4352-AC61-A7BD8335F96A}”= UDP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
“{6C9941BF-B71D-4D91-9DCF-0449577AEC29}”= TCP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
“{B33628AC-A456-4B13-A4A3-FA25D85EF852}”= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
“{A4CC8B7C-D357-4B95-9E2F-9CCC88B109AC}”= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
“{F9FCFF53-4F9C-4E53-B1E7-72737897932A}”= UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire
“{85B86A1D-99AB-4225-BC7C-A580C3138445}”= TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire
“{2240895B-AA4F-4EF3-8B7A-94F9C895D057}”= UDP:c:\program files\Lecteur CANALPLAY\CanalPlayer.exe:Lecteur CANALPLAY
“{AF28444A-B861-4881-B64D-EEA61214DDBB}”= TCP:c:\program files\Lecteur CANALPLAY\CanalPlayer.exe:Lecteur CANALPLAY
“{86B88DD3-4739-4891-964E-8930DB6CC119}”= UDP:c:\users\Stéphane\AppData\Local\Temp\7zSDC4A.tmp\SymNRT.exe:Norton Removal Tool
“{8424F56F-F2DB-432C-B074-7F2032304606}”= TCP:c:\users\Stéphane\AppData\Local\Temp\7zSDC4A.tmp\SymNRT.exe:Norton Removal Tool
“{B733FFAC-FAC1-455E-9C6E-1BD28A5F811C}”= UDP:c:\users\Stéphane\AppData\Local\Temp\7zSBB.tmp\SymNRT.exe:Norton Removal Tool
“{BDFB34F2-D5B4-4696-AD61-A398BBA82533}”= TCP:c:\users\Stéphane\AppData\Local\Temp\7zSBB.tmp\SymNRT.exe:Norton Removal Tool

R2 {55662437-DA8C-40c0-AADA-2C816A897A49};{55662437-DA8C-40c0-AADA-2C816A897A49};c:\program files\Hewlett-Packard\Media\DVD\000.fcl [26/09/2008 03:36 59376]
R2 ezSharedSvc;Easybits Shared Services for Windows;c:\windows\system32\svchost.exe -k netsvcs [21/01/2008 04:33 21504]
R2 SSPORT;SSPORT;c:\windows\System32\drivers\SSPORT.SYS [04/03/2009 17:20 5120]
S3 PCD5SRVC{BD6912E3-AC9D80E8-05040000};PCD5SRVC{BD6912E3-AC9D80E8-05040000} - PCDR Kernel Mode Service Helper Driver;c:\progra~1\PC-DOC~1\PCD5SRVC.pkms [10/09/2008 02:58 20640]
S3 Service CANALPLAY;Service CANALPLAY;c:\program files\Lecteur CANALPLAY\CanalPlayService.exe [28/05/2009 20:44 436096]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
ezSharedSvc

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
“c:\windows\System32\rundll32.exe” “c:\windows\System32\iedkcs32.dll”,BrandIEActiveSetup SIGNUP
.
Contenu du dossier ‘Tâches planifiées’

2009-10-01 c:\windows\Tasks\PCDRScheduledMaintenance.job

HKCU-Run-BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} - c:\program files\Common Files\Nero\Lib\NMBgMonitor.exe
HKLM-Run-CanalPlayerHelper - c:\program files\Lecteur CANALPLAY\CanalPlayerHelper.exe
HKLM-Run-NBKeyScan - c:\program files\Nero\Nero 8\Nero BackItUp\NBKeyScan.exe
AddRemove-Steinberg Cubase SX v2.01 - c:\progra~1\STEINB~1\CUBASE~1\UNWISE.EXE


catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, www.gmer.net…
Rootkit scan 2009-10-07 08:29
Windows 6.0.6001 Service Pack 1 NTFS

Recherche de processus cachés …

Recherche d’éléments en démarrage automatique cachés …

Recherche de fichiers cachés …

Scan terminé avec succès
Fichiers cachés: 0


[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PCD5SRVC{BD6912E3-AC9D80E8-05040000}]
“ImagePath”="??\c:\progra~1\PC-DOC~1\PCD5SRVC.pkms"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services{55662437-DA8C-40c0-AADA-2C816A897A49}]
“ImagePath”="??\c:\program files\Hewlett-Packard\Media\DVD\000.fcl"
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@=“FlashBroker”
“LocalizedString”="@c:\Windows\system32\Macromed\Flash\FlashUtil10c.exe,-101"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
“Enabled”=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@=“c:\Windows\system32\Macromed\Flash\FlashUtil10c.exe”

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@=“IFlashBroker3”

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
“Version”=“1.0”
.
------------------------ Autres processus actifs ------------------------
.
c:\windows\System32\nvvsvc.exe
c:\windows\System32\audiodg.exe
c:\windows\System32\rundll32.exe
c:\windows\System32\rundll32.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\CDBurnerXP\NMSAccessU.exe
c:\program files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\System32\wbem\unsecapp.exe
c:\windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
c:\program files\Hewlett-Packard\HP Health Check\HPHC_Service.exe
c:\program files\Hewlett-Packard\KBD\kbd.exe
.


.
Heure de fin: 2009-10-07 8:32 - La machine a redémarré
ComboFix-quarantined-files.txt 2009-10-07 06:32

Avant-CF: 443 941 318 656 octets libres
Après-CF: 443 570 847 744 octets libres

241 — E O F — 2009-10-07 06:10


Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 08:39:41, on 07/10/2009 Platform: Windows Vista SP1 (WinNT 6.00.1905) MSIE: Internet Explorer v8.00 (8.00.6001.18813) Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\hp\support\hpsysdrv.exe
C:\Windows\System32\nvraidservice.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
C:\Program Files\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe
C:\Program Files\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe
C:\Program Files\Hewlett-Packard\Media\DVD\DVDAgent.exe
C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\HP\HP Software Update\hpwuschd2.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\Hewlett-Packard\KBD\kbd.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = lemonde.fr…
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = go.microsoft.com…
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = go.microsoft.com…
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = go.microsoft.com…
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = ie.redirect.hp.com…
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM…\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM…\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
O4 - HKLM…\Run: [KBD] C:\Program Files\Hewlett-Packard\KBD\KbdStub.EXE
O4 - HKLM…\Run: [NVRaidService] C:\Windows\system32\nvraidservice.exe
O4 - HKLM…\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM…\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM…\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM…\Run: [UpdateP2GoShortCut] “c:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe” “c:\Program Files\CyberLink\Power2Go” UpdateWithCreateOnce “SOFTWARE\CyberLink\Power2Go\6.0”
O4 - HKLM…\Run: [UpdatePDIRShortCut] “c:\Program Files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe” “c:\Program Files\CyberLink\PowerDirector” UpdateWithCreateOnce “SOFTWARE\CyberLink\PowerDirector\7.0”
O4 - HKLM…\Run: [UpdatePSTShortCut] “c:\Program Files\CyberLink\CyberLink DVD Suite Deluxe\MUITransfer\MUIStartMenu.exe” “c:\Program Files\CyberLink\CyberLink DVD Suite Deluxe” UpdateWithCreateOnce “Software\CyberLink\PowerStarter”
O4 - HKLM…\Run: [TSMAgent] “c:\Program Files\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe”
O4 - HKLM…\Run: [CLMLServer for HP TouchSmart] “c:\Program Files\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe”
O4 - HKLM…\Run: [DVDAgent] “c:\Program Files\Hewlett-Packard\Media\DVD\DVDAgent.exe”
O4 - HKLM…\Run: [SmartMenu] %ProgramFiles%\Hewlett-Packard\HP MediaSmart\SmartMenu.exe
O4 - HKLM…\Run: [GrooveMonitor] “C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe”
O4 - HKLM…\Run: [QuickTime Task] “C:\Program Files\QuickTime\qttask.exe” -atboottime
O4 - HKLM…\Run: [Adobe Reader Speed Launcher] “C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe”
O4 - HKLM…\Run: [SunJavaUpdateSched] “C:\Program Files\Java\jre6\bin\jusched.exe”
O4 - HKLM…\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM…\Run: [UnlockerAssistant] C:\Program Files\Unlocker\UnlockerAssistant.exe
O4 - HKLM…\Run: [Malwarebytes Anti-Malware (reboot)] “C:\Program Files\Malwarebytes’ Anti-Malware\mbam.exe” /runcleanupscript
O4 - HKCU…\Run: [AlcoholAutomount] “C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe” /automount
O4 - HKCU…\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE…
O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra ‘Tools’ menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O15 - Trusted Zone: *.canalplay.com
O15 - Trusted Zone: *.canalplusactive.com
O15 - Trusted Zone: *.canalplay.com (HKLM)
O15 - Trusted Zone: *.canalplusactive.com (HKLM)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - fpdownload2.macromedia.com…
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Unknown owner - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe (file missing)
O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Service CANALPLAY - Canal+ Distribution - C:\Program Files\Lecteur CANALPLAY\CanalPlayService.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe


End of file - 7164 bytes

Bonsoir
merci de reprendre mon dossier en charge…

Pour répondre à ta première question concernant l’UAC : non, je n’ai rien installé pour le gérer (je ne sais même pas trop à quoi ça sert !)

Par contre, pour le moment, il y a plus inquitétant ! J’ai suivi à la lettre la première démarche : copier/coller texte dans nouveau document texte + glisser dans ComboFix qui vient de faire son rapport apparemment normalement. Le rapport a également été rédigé.
MAIS depuis que l’ordinateur a redémarré, je ne peux plus lancer la plupart des applications ! J’ai un message du genre :
“Tentative d’opération non autorisée sur une clé du Registre marquée pour suppression”.

  • Que dois-je faire Chef ?
  • je précise que je poste avec mon 2nd ordinateur !

Merci pour ta réponse.

Steph


Nouvelle info: ça va mieux !! J'ai tout simplement redémarré l'ordinateur : apparemment tout marche à nouveau ...

Voici pour commencer le rapport ComboFix

ComboFix 09-10-06.03 - Stéphane 07/10/2009 18:57.2.2 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Basique 6.0.6001.1.1252.33.1036.18.2557.1820 [GMT 2:00]
Lancé depuis: c:\users\Stéphane\Desktop\steph.exe
Commutateurs utilisés :: c:\users\Stéphane\Desktop\CFScript.txt
SP: Windows Defender enabled (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((((((( Fichiers créés du 2009-09-07 au 2009-10-07 ))))))))))))))))))))))))))))))))))))
.

2009-10-07 17:01 . 2009-10-07 17:01 -------- d-----w- c:\users\Public\AppData\Local\temp
2009-10-07 17:01 . 2009-10-07 17:01 -------- d-----w- c:\users\Default\AppData\Local\temp
2009-10-07 12:29 . 1994-09-16 12:00 20976 ----a-w- c:\windows\system\CTL3D.DLL
2009-10-07 06:39 . 2009-10-07 06:39 -------- d-----w- c:\program files\Trend Micro
2009-10-07 06:03 . 2009-10-01 08:29 195440 ------w- c:\windows\system32\MpSigStub.exe
2009-10-05 21:47 . 2009-09-10 12:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-10-05 21:47 . 2009-10-05 21:47 -------- d-----w- c:\program files\Malwarebytes’ Anti-Malware
2009-10-05 21:47 . 2009-10-05 21:47 -------- d-----w- c:\programdata\Malwarebytes
2009-10-05 21:47 . 2009-09-10 12:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-10-05 21:21 . 2009-10-07 05:56 -------- d-----w- C:\FindyKill
2009-10-05 20:09 . 2009-10-05 20:09 -------- d-sh–w- c:\windows\system32%APPDATA%
2009-10-03 17:05 . 2009-10-07 16:49 -------- d-----w- c:\program files\Unlocker
2009-09-14 16:36 . 2009-09-14 16:36 -------- d-----w- c:\program files\HP
2009-09-14 16:35 . 2009-09-14 16:35 -------- d-----w- c:\windows\Hewlett-Packard
2009-09-13 16:04 . 2009-09-13 16:05 -------- d-----w- c:\program files\CDBurnerXP
2009-09-12 22:22 . 2009-09-12 22:22 -------- d-----w- c:\programdata\AVS4YOU
2009-09-12 22:21 . 2009-09-12 22:27 -------- d-----w- c:\program files\Common Files\AVSMedia
2009-09-12 22:21 . 2008-08-13 09:22 974848 ----a-w- c:\windows\system32\mfc70.dll
2009-09-12 22:21 . 2008-08-13 09:22 487424 ----a-w- c:\windows\system32\msvcp70.dll
2009-09-12 22:21 . 2008-08-13 09:22 344064 ----a-w- c:\windows\system32\msvcr70.dll
2009-09-12 22:21 . 2008-08-13 09:22 1700352 ----a-w- c:\windows\system32\GdiPlus.dll
2009-09-12 22:21 . 2008-08-13 09:22 24576 ----a-w- c:\windows\system32\msxml3a.dll
2009-09-12 22:21 . 2009-09-12 22:27 -------- d-----w- c:\program files\AVS4YOU
2009-09-12 19:57 . 2009-09-12 19:57 -------- d-----w- c:\programdata\Canneverbe Limited
2009-09-09 07:49 . 2009-09-09 07:49 -------- d-----w- c:\program files\Common Files\Digidesign
2009-09-09 05:47 . 2009-08-14 17:07 897608 ----a-w- c:\windows\system32\drivers\tcpip.sys
2009-09-09 05:47 . 2009-08-14 16:29 104960 ----a-w- c:\windows\system32\netiohlp.dll
2009-09-09 05:47 . 2009-08-14 14:16 9728 ----a-w- c:\windows\system32\TCPSVCS.EXE
2009-09-09 05:47 . 2009-08-14 14:16 27136 ----a-w- c:\windows\system32\NETSTAT.EXE
2009-09-09 05:47 . 2009-08-14 14:16 19968 ----a-w- c:\windows\system32\ARP.EXE
2009-09-09 05:47 . 2009-08-14 16:29 17920 ----a-w- c:\windows\system32\netevent.dll
2009-09-09 05:47 . 2009-08-14 14:16 17920 ----a-w- c:\windows\system32\ROUTE.EXE
2009-09-09 05:47 . 2009-08-14 14:16 11264 ----a-w- c:\windows\system32\MRINFO.EXE
2009-09-09 05:47 . 2009-08-14 14:16 8704 ----a-w- c:\windows\system32\HOSTNAME.EXE
2009-09-09 05:47 . 2009-08-14 14:16 10240 ----a-w- c:\windows\system32\finger.exe
2009-09-09 05:45 . 2009-07-11 19:32 293376 ----a-w- c:\windows\system32\wlanmsm.dll
2009-09-09 05:45 . 2009-07-11 19:29 127488 ----a-w- c:\windows\system32\L2SecHC.dll
2009-09-09 05:45 . 2009-07-11 19:32 513024 ----a-w- c:\windows\system32\wlansvc.dll
2009-09-09 05:45 . 2009-07-11 19:32 302592 ----a-w- c:\windows\system32\wlansec.dll
2009-09-09 05:45 . 2009-06-10 12:11 2868224 ----a-w- c:\windows\system32\mf.dll

.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-06 20:17 . 2008-12-01 13:31 672084 ----a-w- c:\windows\system32\perfh00C.dat
2009-10-06 20:17 . 2008-12-01 13:31 124228 ----a-w- c:\windows\system32\perfc00C.dat
2009-09-25 16:54 . 2009-03-06 16:37 -------- d-----w- c:\program files\Steinberg
2009-09-14 16:37 . 2008-12-01 05:29 -------- d—a-w- c:\program files\Common Files\LightScribe
2009-09-14 05:44 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-09-14 05:44 . 2009-03-14 19:19 -------- d-----w- c:\programdata\Microsoft Help
2009-09-12 19:50 . 2009-03-16 22:31 -------- d-----w- c:\program files\Common Files\Nero
2009-09-12 19:49 . 2009-03-16 22:31 -------- d-----w- c:\programdata\Nero
2009-09-06 08:51 . 2009-09-06 08:51 -------- d-----w- c:\program files\Ahead
2009-09-06 08:50 . 2008-12-01 05:30 -------- d-----w- c:\program files\Java
2009-09-05 17:49 . 2009-03-07 14:49 -------- d-----w- c:\program files\NCH Software
2009-08-28 12:39 . 2009-09-05 16:38 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2009-08-28 10:15 . 2009-09-05 16:38 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2009-07-25 03:23 . 2009-04-23 16:10 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-07-21 21:52 . 2009-07-29 07:17 915456 ----a-w- c:\windows\system32\wininet.dll
2009-07-21 21:47 . 2009-07-29 07:17 109056 ----a-w- c:\windows\system32\iesysprep.dll
2009-07-21 21:47 . 2009-07-29 07:17 71680 ----a-w- c:\windows\system32\iesetup.dll
2009-07-21 20:13 . 2009-07-29 07:17 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2009-07-17 14:35 . 2009-08-14 14:12 71680 ----a-w- c:\windows\system32\atl.dll
2009-07-14 13:00 . 2009-08-14 14:12 313344 ----a-w- c:\windows\system32\wmpdxm.dll
2009-07-14 12:59 . 2009-08-14 14:12 4096 ----a-w- c:\windows\system32\dxmasf.dll
2009-07-14 12:58 . 2009-08-14 14:12 7680 ----a-w- c:\windows\system32\spwmp.dll
2009-07-14 10:59 . 2009-08-14 14:12 8147456 ----a-w- c:\windows\system32\wmploc.DLL
2008-12-01 13:55 . 2008-12-01 13:54 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.

(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
---- Directory of c:\windows\system32%APPDATA% ----

2009-10-05 20:09 . 2009-10-05 21:54 16384 --sha-w- c:\windows\system32%APPDATA%\Microsoft\Windows\IETldCache\index.dat

((((((((((((((((((((((((((((( SnapShot@2009-10-07_06.29.47 )))))))))))))))))))))))))))))))))))))))))
.

  • 1996-08-26 00:12 . 1996-08-26 00:12 93184 c:\windows\VIEW32.EXE
  • 2008-01-21 01:58 . 2009-10-07 15:25 47056 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
  • 2009-03-04 11:39 . 2009-10-07 15:25 10130 c:\windows\System32\WDI{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3889901446-2716675481-4253712499-1000_UserData.bin
  • 1996-08-26 00:12 . 1996-08-26 00:12 64512 c:\windows\System32\QTWMCI32.DLL
  • 1996-08-26 00:12 . 1996-08-26 00:12 93696 c:\windows\System32\QTOLE32.DLL
  • 1996-08-26 00:12 . 1996-08-26 00:12 18944 c:\windows\System32\HNDLR32.DLL
  • 2008-12-19 08:53 . 2009-10-07 06:20 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
  • 2008-12-19 08:53 . 2009-10-07 16:55 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
  • 2008-12-19 08:53 . 2009-10-07 06:20 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
  • 2008-12-19 08:53 . 2009-10-07 16:55 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
  • 2008-12-19 08:53 . 2009-10-07 06:20 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
  • 2008-12-19 08:53 . 2009-10-07 16:55 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
  • 1996-08-26 00:12 . 1996-08-26 00:12 32768 c:\windows\System32\CMGR32.DLL
  • 2009-06-06 11:48 . 2009-07-18 19:04 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
  • 2009-06-06 11:48 . 2009-10-07 12:04 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
  • 2009-06-06 11:48 . 2009-07-18 19:04 32768 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
  • 2009-06-06 11:48 . 2009-10-07 12:04 32768 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
  • 2009-06-06 11:48 . 2009-10-07 12:04 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
  • 2009-06-06 11:48 . 2009-07-18 19:04 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
  • 2009-03-04 18:25 . 2009-10-07 16:26 428548 c:\windows\System32\WDI\SuspendPerformanceDiagnostics_SystemData_FastS4.bin
  • 2006-11-02 13:02 . 2009-10-07 15:25 100986 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
  • 1996-08-26 00:12 . 1996-08-26 00:12 345600 c:\windows\System32\QTIM32.DLL
  • 2009-06-06 10:47 . 2009-10-07 05:56 245760 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
  • 2009-06-06 10:47 . 2009-10-07 11:41 245760 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
  • 1996-08-26 00:12 . 1996-08-26 00:12 169472 c:\windows\QTW32DEL.EXE
  • 1996-08-26 00:12 . 1996-08-26 00:12 107008 c:\windows\PLAY32.EXE
  • 2008-12-01 05:51 . 2009-10-07 06:28 2298528 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
  • 2008-12-01 05:51 . 2009-10-07 17:01 2298528 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
  • 1996-08-26 00:12 . 1996-08-26 00:12 2058752 c:\windows\QT32INST.EXE
    .
    ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    Note les éléments vides & les éléments initiaux légitimes ne sont pas listés
    REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“AlcoholAutomount”=“c:\program files\Alcohol Soft\Alcohol 120\axcmd.exe” [2009-04-24 203928]
“WMPNSCFG”=“c:\program files\Windows Media Player\WMPNSCFG.exe” [2008-01-21 202240]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“Windows Defender”=“c:\program files\Windows Defender\MSASCui.exe” [2008-01-21 1008184]
“hpsysdrv”=“c:\hp\support\hpsysdrv.exe” [2007-04-18 65536]
“KBD”=“c:\program files\Hewlett-Packard\KBD\KbdStub.EXE” [2008-07-21 12288]
“NVRaidService”=“c:\windows\system32\nvraidservice.exe” [2008-10-03 203296]
“NvCplDaemon”=“c:\windows\system32\NvCpl.dll” [2008-10-25 13584928]
“NvMediaCenter”=“c:\windows\system32\NvMcTray.dll” [2008-10-25 92704]
“HP Health Check Scheduler”=“c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe” [2008-10-09 75008]
“UpdateP2GoShortCut”=“c:\program files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe” [2008-06-13 210216]
“UpdatePDIRShortCut”=“c:\program files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe” [2008-06-13 210216]
“UpdatePSTShortCut”=“c:\program files\CyberLink\CyberLink DVD Suite Deluxe\MUITransfer\MUIStartMenu.exe” [2008-09-11 210216]
“TSMAgent”=“c:\program files\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe” [2008-10-17 1152296]
“CLMLServer for HP TouchSmart”=“c:\program files\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe” [2008-10-17 189736]
“DVDAgent”=“c:\program files\Hewlett-Packard\Media\DVD\DVDAgent.exe” [2008-09-26 1148200]
“SmartMenu”=“c:\program files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe” [2008-09-23 912688]
“GrooveMonitor”=“c:\program files\Microsoft Office\Office12\GrooveMonitor.exe” [2008-10-25 31072]
“QuickTime Task”=“c:\program files\QuickTime\qttask.exe” [2009-04-15 413696]
“Adobe Reader Speed Launcher”=“c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe” [2009-02-27 35696]
“SunJavaUpdateSched”=“c:\program files\Java\jre6\bin\jusched.exe” [2009-07-25 149280]
“HP Software Update”=“c:\program files\HP\HP Software Update\HPWuSchd2.exe” [2008-12-08 54576]
“UnlockerAssistant”=“c:\program files\Unlocker\UnlockerAssistant.exe” [2009-10-07 15872]
“Malwarebytes Anti-Malware (reboot)”=“c:\program files\Malwarebytes’ Anti-Malware\mbam.exe” [2009-09-10 1312080]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
“EnableLUA”= 0 (0x0)
“EnableUIADesktopToggle”= 0 (0x0)
“HideFastUserSwitching”= 0 (0x0)
“UacDisableNotify”= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
“aux”=wdmaud.drv

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-3889901446-2716675481-4253712499-1000]
“EnableNotificationsRef”=dword:00000004

[HKLM~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
“{08E64F24-B609-4BEC-8FB1-929002495E1A}”= c:\program files\CyberLink\PowerDirector\PDR.EXE:CyberLink PowerDirector
“{327C57FA-2829-4FCA-931F-5E1C8E136470}”= c:\program files\Hewlett-Packard\TouchSmart\Media\HPTouchSmartMusic.exe:HP TouchSmart Music
“{A6337A4D-7FD8-49C3-8749-A99D09FC64A7}”= c:\program files\Hewlett-Packard\TouchSmart\Media\HPTouchSmartPhoto.exe:HP TouchSmart Photo
“{2CB2FD2B-A39E-4D1B-8045-C0105C3285B7}”= c:\program files\Hewlett-Packard\TouchSmart\Media\HPTouchSmartVideo.exe:HP TouchSmart Video
“{C0F251A3-B0AD-47E8-9DC0-5A354D58C6B4}”= c:\program files\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe:HP TouchSmart Media Resident Program
“{85B46F8A-8DA6-498F-A00C-415B956DEE93}”= c:\program files\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe:CyberLink Media Service
“{1CE1700B-D4BF-4A5C-B31E-BBD055476614}”= c:\program files\Hewlett-Packard\Media\DVD\HPTouchSmartMusic.exe:HP TouchSmart Music
“{3D48D6C1-0D17-40C3-9D98-07ED19E1A076}”= c:\program files\Hewlett-Packard\Media\DVD\HPTouchSmartPhoto.exe:HP TouchSmart Photo
“{7200C305-9B9B-41CE-8B02-259903AE597B}”= c:\program files\Hewlett-Packard\Media\DVD\HPTouchSmartVideo.exe:HP TouchSmart Video
“{3B63FF9E-9CA3-4AD7-83ED-043EC1C77D1C}”= c:\program files\Hewlett-Packard\Media\DVD\TSMAgent.exe:HP TouchSmart Media Resident Program
“{9E3D9482-BD46-4613-A658-8A163B4878E9}”= c:\program files\Hewlett-Packard\Media\DVD\Kernel\CLML\CLMLSvc.exe:CyberLink Media Service
“{8A90A436-8F54-4978-99AD-48CF741F0DD0}”= c:\program files\Hewlett-Packard\Media\DVD\HPDVDSmart.exe:HP MediaSmart DVD
“TCP Query User{BE64AE0F-BFBD-4C47-884B-D3E7F6F39F8D}c:\program files\emule\emule.exe”= UDP:c:\program files\emule\emule.exe:eMule
“UDP Query User{B20DC7D2-C8DD-4F21-BDBA-3C046AA511CC}c:\program files\emule\emule.exe”= TCP:c:\program files\emule\emule.exe:eMule
“{2E4D7E5E-8A7C-462A-835C-2C80F8E566F8}”= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
“{8DE06DF7-B0EF-4352-AC61-A7BD8335F96A}”= UDP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
“{6C9941BF-B71D-4D91-9DCF-0449577AEC29}”= TCP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
“{B33628AC-A456-4B13-A4A3-FA25D85EF852}”= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
“{A4CC8B7C-D357-4B95-9E2F-9CCC88B109AC}”= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
“{F9FCFF53-4F9C-4E53-B1E7-72737897932A}”= UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire
“{85B86A1D-99AB-4225-BC7C-A580C3138445}”= TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire
“{2240895B-AA4F-4EF3-8B7A-94F9C895D057}”= UDP:c:\program files\Lecteur CANALPLAY\CanalPlayer.exe:Lecteur CANALPLAY
“{AF28444A-B861-4881-B64D-EEA61214DDBB}”= TCP:c:\program files\Lecteur CANALPLAY\CanalPlayer.exe:Lecteur CANALPLAY
“{86B88DD3-4739-4891-964E-8930DB6CC119}”= UDP:c:\users\Stéphane\AppData\Local\Temp\7zSDC4A.tmp\SymNRT.exe:Norton Removal Tool
“{8424F56F-F2DB-432C-B074-7F2032304606}”= TCP:c:\users\Stéphane\AppData\Local\Temp\7zSDC4A.tmp\SymNRT.exe:Norton Removal Tool
“{B733FFAC-FAC1-455E-9C6E-1BD28A5F811C}”= UDP:c:\users\Stéphane\AppData\Local\Temp\7zSBB.tmp\SymNRT.exe:Norton Removal Tool
“{BDFB34F2-D5B4-4696-AD61-A398BBA82533}”= TCP:c:\users\Stéphane\AppData\Local\Temp\7zSBB.tmp\SymNRT.exe:Norton Removal Tool

R2 {55662437-DA8C-40c0-AADA-2C816A897A49};{55662437-DA8C-40c0-AADA-2C816A897A49};c:\program files\Hewlett-Packard\Media\DVD\000.fcl [26/09/2008 03:36 59376]
R2 ezSharedSvc;Easybits Shared Services for Windows;c:\windows\system32\svchost.exe -k netsvcs [21/01/2008 04:33 21504]
R2 SSPORT;SSPORT;c:\windows\System32\drivers\SSPORT.SYS [04/03/2009 17:20 5120]
S3 PCD5SRVC{BD6912E3-AC9D80E8-05040000};PCD5SRVC{BD6912E3-AC9D80E8-05040000} - PCDR Kernel Mode Service Helper Driver;c:\progra~1\PC-DOC~1\PCD5SRVC.pkms [10/09/2008 02:58 20640]
S3 Service CANALPLAY;Service CANALPLAY;c:\program files\Lecteur CANALPLAY\CanalPlayService.exe [28/05/2009 20:44 436096]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
ezSharedSvc

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
“c:\windows\System32\rundll32.exe” “c:\windows\System32\iedkcs32.dll”,BrandIEActiveSetup SIGNUP
.
Contenu du dossier ‘Tâches planifiées’

2009-10-01 c:\windows\Tasks\PCDRScheduledMaintenance.job


catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, www.gmer.net…
Rootkit scan 2009-10-07 19:02
Windows 6.0.6001 Service Pack 1 NTFS

Recherche de processus cachés …

Recherche d’éléments en démarrage automatique cachés …

Recherche de fichiers cachés …

Scan terminé avec succès
Fichiers cachés: 0


[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PCD5SRVC{BD6912E3-AC9D80E8-05040000}]
“ImagePath”="??\c:\progra~1\PC-DOC~1\PCD5SRVC.pkms"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services{55662437-DA8C-40c0-AADA-2C816A897A49}]
“ImagePath”="??\c:\program files\Hewlett-Packard\Media\DVD\000.fcl"
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@=“FlashBroker”
“LocalizedString”="@c:\Windows\system32\Macromed\Flash\FlashUtil10c.exe,-101"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
“Enabled”=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@=“c:\Windows\system32\Macromed\Flash\FlashUtil10c.exe”

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@=“IFlashBroker3”

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
“Version”=“1.0”
.
------------------------ Autres processus actifs ------------------------
.
c:\windows\System32\nvvsvc.exe
c:\windows\System32\audiodg.exe
c:\windows\System32\rundll32.exe
c:\windows\System32\rundll32.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\CDBurnerXP\NMSAccessU.exe
c:\program files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\System32\wbem\unsecapp.exe
c:\windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
c:\program files\Hewlett-Packard\HP Health Check\HPHC_Service.exe
c:\program files\Hewlett-Packard\KBD\kbd.exe
.


.
Heure de fin: 2009-10-07 19:05 - La machine a redémarré
ComboFix-quarantined-files.txt 2009-10-07 17:05

Avant-CF: 443 407 523 840 octets libres
Après-CF: 443 495 727 104 octets libres

264 — E O F — 2009-10-07 06:10

2nd rapport

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:31:13, on 07/10/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18813)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\hp\support\hpsysdrv.exe
C:\Windows\System32\nvraidservice.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe
C:\Program Files\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe
C:\Program Files\Hewlett-Packard\Media\DVD\DVDAgent.exe
C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\HP\HP Software Update\hpwuschd2.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hewlett-Packard\KBD\kbd.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = lemonde.fr…
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = go.microsoft.com…
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = go.microsoft.com…
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = go.microsoft.com…
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = ie.redirect.hp.com…
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM…\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM…\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
O4 - HKLM…\Run: [KBD] C:\Program Files\Hewlett-Packard\KBD\KbdStub.EXE
O4 - HKLM…\Run: [NVRaidService] C:\Windows\system32\nvraidservice.exe
O4 - HKLM…\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM…\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM…\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM…\Run: [UpdateP2GoShortCut] “c:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe” “c:\Program Files\CyberLink\Power2Go” UpdateWithCreateOnce “SOFTWARE\CyberLink\Power2Go\6.0”
O4 - HKLM…\Run: [UpdatePDIRShortCut] “c:\Program Files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe” “c:\Program Files\CyberLink\PowerDirector” UpdateWithCreateOnce “SOFTWARE\CyberLink\PowerDirector\7.0”
O4 - HKLM…\Run: [UpdatePSTShortCut] “c:\Program Files\CyberLink\CyberLink DVD Suite Deluxe\MUITransfer\MUIStartMenu.exe” “c:\Program Files\CyberLink\CyberLink DVD Suite Deluxe” UpdateWithCreateOnce “Software\CyberLink\PowerStarter”
O4 - HKLM…\Run: [TSMAgent] “c:\Program Files\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe”
O4 - HKLM…\Run: [CLMLServer for HP TouchSmart] “c:\Program Files\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe”
O4 - HKLM…\Run: [DVDAgent] “c:\Program Files\Hewlett-Packard\Media\DVD\DVDAgent.exe”
O4 - HKLM…\Run: [SmartMenu] %ProgramFiles%\Hewlett-Packard\HP MediaSmart\SmartMenu.exe
O4 - HKLM…\Run: [GrooveMonitor] “C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe”
O4 - HKLM…\Run: [QuickTime Task] “C:\Program Files\QuickTime\qttask.exe” -atboottime
O4 - HKLM…\Run: [Adobe Reader Speed Launcher] “C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe”
O4 - HKLM…\Run: [SunJavaUpdateSched] “C:\Program Files\Java\jre6\bin\jusched.exe”
O4 - HKLM…\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM…\Run: [UnlockerAssistant] C:\Program Files\Unlocker\UnlockerAssistant.exe
O4 - HKLM…\Run: [Malwarebytes Anti-Malware (reboot)] “C:\Program Files\Malwarebytes’ Anti-Malware\mbam.exe” /runcleanupscript
O4 - HKCU…\Run: [AlcoholAutomount] “C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe” /automount
O4 - HKCU…\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE…
O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra ‘Tools’ menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O15 - Trusted Zone: *.canalplay.com
O15 - Trusted Zone: *.canalplusactive.com
O15 - Trusted Zone: *.canalplay.com (HKLM)
O15 - Trusted Zone: *.canalplusactive.com (HKLM)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - fpdownload2.macromedia.com…
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Unknown owner - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe (file missing)
O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Service CANALPLAY - Canal+ Distribution - C:\Program Files\Lecteur CANALPLAY\CanalPlayService.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe


End of file - 7091 bytes

…et c’est reparti pour un nouveau rapport :slight_smile:

Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
“ConsentPromptBehaviorAdmin”=dword:00000002
“ConsentPromptBehaviorUser”=dword:00000001
“EnableInstallerDetection”=dword:00000001
“EnableLUA”=dword:00000000
“EnableSecureUIAPaths”=dword:00000001
“EnableVirtualization”=dword:00000001
“PromptOnSecureDesktop”=dword:00000001
“ValidateAdminCodeSignatures”=dword:00000000
“dontdisplaylastusername”=dword:00000000
“legalnoticecaption”=""
“legalnoticetext”=""
“scforceoption”=dword:00000000
“shutdownwithoutlogon”=dword:00000001
“undockwithoutlogon”=dword:00000001
“FilterAdministratorToken”=dword:00000000
“EnableUIADesktopToggle”=dword:00000000
“HideFastUserSwitching”=dword:00000000
“UacDisableNotify”=dword:00000000
“DisableRegistryTools”=dword:00000000

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system\UIPI]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system\UIPI\Clipboard]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system\UIPI\Clipboard\ExceptionFormats]
“CF_TEXT”=dword:00000001
“CF_BITMAP”=dword:00000002
“CF_OEMTEXT”=dword:00000007
“CF_DIB”=dword:00000008
“CF_PALETTE”=dword:00000009
“CF_UNICODETEXT”=dword:0000000d
“CF_DIBV5”=dword:00000011

Avast n’a rien trouvé : tout semble ok !
Un énorme merci pour ton aide rapide et efficace !!
Qui peut dire encore qu’on vit dans une société purement individualiste ? Il se passe de très bonne chose sur le net !

Dernières questions comme je t’ai « sous la souris » :

j’ai installé Avast comme antivirus : bon choix ?
dois-je de temps en temps rescaner mon ordinateur avec les logiciels que tu m’as fait utiliser ?
est-utile d’avoir Ccleaner ?
Merci

@+

Et hop un dernier (?) rapport

[ Rapport ToolsCleaner version 2.3.11 (par A.Rothstein & dj QUIOU) ]

–> Recherche:

C:\Combofix.txt: trouvé !
C:\Qoobox: trouvé !
C:\FindyKill: trouvé !
C:\Program Files\Trend Micro\HijackThis: trouvé !
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: trouvé !
C:\Program Files\Trend Micro\HijackThis\hijackthis.log: trouvé !
C:\ProgramData\Microsoft\Windows\Start Menu\Programmes\HijackThis: trouvé !
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HijackThis: trouvé !
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HijackThis\HijackThis.lnk: trouvé !
C:\Qoobox\Quarantine\catchme.log: trouvé !
C:\Users\All Users\Microsoft\Windows\Start Menu\Programmes\HijackThis: trouvé !
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\HijackThis: trouvé !
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\HijackThis\HijackThis.lnk: trouvé !
C:\Users\Stéphane\Desktop\HijackThis.lnk: trouvé !
C:\Users\Stéphane\Downloads\fsbl.exe: trouvé !
C:\Users\Stéphane\Downloads\HijackThis.exe: trouvé !

“N’oublie pas de purger ta restauration système et de créer un nouveau points de restauration propre par sécurité.”

euh, comment on fait ça ?

merci, mon ordi est comme tout neuf à présent !

Quand je serai motivé, je m’attaquerai à mon second ordi qui doit trainer par mal de crasses !Je me permettrai de te solliciter à nouveau.:wink:

A une prochaine et merci encore

Stephaner35