PROBLEME programme suspect !!

Bonjour,

J'ai un petit soucis.
Ca fait plusieurs semaines que un programme nommé "k.exe" apparait à l'écran dans une fentre Vista.
En effet, une fenetre s'ouvre en disant :
"un probleme a fait que le programme a cessé de fonctionner correctement... Fermer le programme"
Donc si vous aviez une idée de ce que ca peut être ...
Je ne sais pas du tout ce qu'est ce programme et quand je recherche sur mon disque dur il ne le trouve pas ...
Serait il possible que ce soit un programme malveillant ?
J'utilise aantivir et spybot destroy...

Voilà
Merci de votre aide ! ;)
Configuration: Windows Vista
Firefox 3.0.5

37 réponses

Résumé de la discussion

Un souci lié à un programme nommé k.exe apparaît sur Windows Vista, avec une fenêtre indiquant que le programme a cessé de fonctionner et qu'il n'est pas facilement localisable sur le disque. Des réponses recommandent d'utiliser Random's System Information Tool (RSIT) pour analyser et générer des fichiers log (log.txt et info.txt), puis de les poster pour analyse. Il est conseillé de ne pas utiliser d’outils non demandés et de redémarrer après, avec des rapports qui peuvent aider à diagnostiquer une éventuelle infection malware et les mesures de désinfection. En parallèle, certains échanges détaillent les noms de processus et les emplacements typiques des fichiers suspects, notamment dans les dossiers AppData Roaming et le dossier Temp.

Bobot (l’IA à votre service)
  1. bonjour ,

    Télécharge Random's System Information Tool (RSIT) de random/random et enregistre l'exécutable sur ton Bureau.

    -> http://images.malwareremoval.com/random/RSIT.exe

    ! Déconnecte toi et ferme toutes tes applications en cours !

    Double-clique sur " RSIT.exe " pour le lancer .

    -> Une première fenêtre s'ouvre avec en titre : " Disclaimer of warranty " .

    * Devant l'option "List files/folders created ..." , tu choisis : 2 months

    * clique ensuite sur " Continue " pour lancer l'analyse ...

    -> laisse faire le scan et ne touche pas au PC ...

    Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront (probablement avec le bloc-note).

    Poste le contenu de " log.txt " (c'est celui qui apparait à l'écran), ainsi que de " info.txt " (que tu verras dans la barre des tâches), pour analyse et attends la suite ...

    Important : poste un rapport, puis l'autre dans la réponse suivante
    Si tu essaies de poster les deux en même temps, cela risque d'être trop long pour le forum

    ( Note : les rapports seront en outre sauvegardés dans ce dossier -> C:\rsit )

    1
    1. Okaii' Merci ! Je fais ca et je poste ca tout à l'heure ! ;)
      1
      1. ok je pars jouer de la musique dès que je rentre je te suis....patience
        0
        1. VOICI le premier rapport "info"

          info.txt logfile of random's system information tool 1.05 2009-01-10 18:33:19

          ======Uninstall list======

          -->C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
          -->C:\Program Files\OrangeHSS\Uninstall\Bas_Debit_CustoUpdate\Shell.exe MainUninstall.shl
          -->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{363435F2-7426-11D8-9966-00A0C9663221}\setup.exe" -l0x40c
          -->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5CDDF96A-BC34-4D72-9ABA-E1FFF0C39977}\setup.exe" -l0x40c
          32 Bit HP CIO Components Installer-->MsiExec.exe /I{F7B0E599-C114-4493-BC4D-D8FC7CBBABBB}
          Acer Arcade Live Main Page-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{EFBDC2B0-FAA8-4B78-8DE1-AEBE7958FA37}\SETUP.exe" -uninstall
          Acer DV Magician-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F6EFFB76-4A07-11DA-9D78-000129760D75}\SETUP.exe" -uninstall
          Acer DVDivine-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B145EC69-66F5-11D8-9D75-000129760D75}\SETUP.exe" -uninstall
          Acer eDataSecurity Management-->C:\Acer\Empowering Technology\eDataSecurity\eDSnstHelper.exe -Operation UNINSTALL
          Acer Empowering Technology-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{AB6097D9-D722-4987-BD9E-A076E2848EE2}\setup.exe" -l0x40c -removeonly
          Acer ePerformance Management-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D462BF9E-0C35-4705-BF9B-3DF9F3816643}\setup.exe" -l0x40c -removeonly
          Acer HomeMedia Connect-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{132888AE-EF67-41C5-BCA2-7D5D2488AB63}\SETUP.exe" -uninstall
          Acer HomeMedia-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{AA4BF92B-2AAF-11DA-9D78-000129760D75}\SETUP.exe" -uninstall
          Acer PlayMovie-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A450831D-25F6-4F42-9662-D000B25E0D82}\Setup.exe" -uninstall
          Acer ScreenSaver-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{79DD56FC-DB8B-47F5-9C80-78B62E05F9BC}\setup.exe" -l0x9 -removeonly
          Acer SlideShow DVD-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{41581EF5-45A7-11DA-9D78-000129760D75}\SETUP.exe" -uninstall
          Acer Tour-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{94389919-B0AA-4882-9BE8-9F0B004ECA35}\setup.exe" -l0x40c -removeonly
          Acer VideoMagician-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F79A208D-D929-11D9-9D77-000129760D75}\SETUP.exe" -uninstall
          Activation Assistant for the 2007 Microsoft Office suites-->"C:\ProgramData\{174892B1-CBE7-44F5-86FF-AB555EFD73A3}\Microsoft Office Activation Assistant.exe" REMOVE=TRUE MODIFY=FALSE
          Adobe AIR-->c:\Program Files\Common Files\Adobe AIR\Versions\1.0\Resources\Adobe AIR Updater.exe -arp:uninstall
          Adobe AIR-->MsiExec.exe /I{A2BCA9F1-566C-4805-97D1-7FDC93386723}
          Adobe Flash Player 10 Plugin-->C:\Windows\system32\Macromed\Flash\uninstall_plugin.exe
          Adobe Flash Player 9 ActiveX-->C:\Windows\system32\Macromed\Flash\FlashUtil9b.exe -uninstallDelete
          Adobe Flash Player ActiveX-->C:\Windows\system32\Macromed\Flash\uninstall_activeX.exe
          Adobe Reader 8.1.3 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A81300000003}
          Apple Mobile Device Support-->MsiExec.exe /I{44734179-8A79-4DEE-BB08-73037F065543}
          Apple Software Update-->MsiExec.exe /I{02DFF6B1-1654-411C-8D7B-FD6052EF016F}
          Archiveur WinRAR-->C:\Program Files\WinRAR\uninstall.exe
          Assistant de connexion Windows Live-->MsiExec.exe /I{AFA4E5FD-ED70-4D92-99D0-162FD56DC986}
          Audacity 1.2.6-->"C:\Program Files\Audacity\unins000.exe"
          Avira AntiVir Personal - Free Antivirus-->C:\Program Files\Avira\AntiVir PersonalEdition Classic\SETUP.EXE /REMOVE
          AviSynth 2.5-->"C:\Program Files\AviSynth 2.5\Uninstall.exe"
          Bonjour-->MsiExec.exe /I{47BF1BD6-DCAC-468F-A0AD-E5DECC2211C3}
          CamStudio 2.0 Fr-->"C:\Program Files\CamStudio\unins000.exe"
          CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
          Creative WebCam Center-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{363435F2-7426-11D8-9966-00A0C9663221}\setup.exe" -l0x40c /remove
          Creative WebCam Live! Driver (1.01.01.0730)-->C:\Windows\CtDrvIns.exe -uninstall -script Pd0630.uns -unsext NT -plugin P0630Pin.dll -pluginres P0630Pin.crl
          Empire of Sports 1.64-->C:\Program Files\Empire of Sports\Uninstall.exe
          eMule-->"C:\Program Files\eMule\Uninstall.exe"
          EPSON Logiciel imprimante-->C:\Windows\system32\spool\DRIVERS\W32X86\3\EPUPDATE.EXE /r
          EPSON PhotoQuicker3.2-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B2EFE303-A594-11D5-95EB-005004BC1C65}\setup.exe" uninst
          Favorit-->c:\users\maxime\appdata\local\kecfcxux.bat
          Free Video Converter V 1.4-->"C:\Program Files\Free Video Converter\unins000.exe"
          Free Video to iPod Converter version 3.1-->"C:\Program Files\DVDVideoSoft\Free Video to iPod Converter\unins000.exe"
          Free Video to Mp3 Converter version 2.7-->"C:\Program Files\DVDVIDEOSOFT\Free Video to Mp3 Converter\unins000.exe"
          Free YouTube to iPod Converter version 3.1-->"C:\Program Files\DVDVideoSoft\Free YouTube to iPod Converter\unins000.exe"
          Google Toolbar for Internet Explorer-->"C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_0531C63A913CC9D1.exe" /uninstall
          HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
          HP Imaging Device Functions 11.0-->C:\Program Files\HP\Digital Imaging\DeviceManagement\hpzscr01.exe -datfile hpqbud01.dat
          HP Photosmart C5300 All-In-One Driver Software 11.0 Rel .4-->C:\Program Files\HP\Digital Imaging\{69C57747-551F-4e4f-AB60-13358DC4F00A}\setup\hpzscr01.exe -datfile hposcr32.dat -onestop
          HP Photosmart Essential 3.0-->C:\Program Files\HP\Digital Imaging\PhotoSmartEssential\hpzscr01.exe -datfile hpqbud13.dat
          HP Smart Web Printing-->C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpzscr01.exe -datfile hpqbud15.dat
          HP Solution Center 11.0-->C:\Program Files\HP\Digital Imaging\eSupport\hpzscr01.exe -datfile hpqbud05.dat
          HP Update-->MsiExec.exe /X{FE57DE70-95DE-4B64-9266-84DA811053DB}
          iTunes-->MsiExec.exe /I{9F70BF98-003C-491D-81FC-FF9792206AF0}
          Jaquette Express 1.8.0.0-->"C:\Program Files\Jaquette Express\uninstall.exe"
          Java(TM) 6 Update 11-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216011FF}
          Java(TM) 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
          livebox-->C:\Program Files\InstallShield Installation Information\{17342E3B-0818-4A6F-BFF8-99476605ADD6}\Setup.exe -runfromtemp -l0x040c -removeonly
          Luxor 2-->"C:\Program Files\Acer GameZone\Luxor 2\Uninstall.exe" "C:\Program Files\Acer GameZone\Luxor 2\install.log"
          MCF Ravenhearst-->"C:\Program Files\Acer GameZone\MCF Ravenhearst\Uninstall.exe" "C:\Program Files\Acer GameZone\MCF Ravenhearst\install.log"
          Messenger Plus! Live-->"C:\Program Files\Messenger Plus! Live\Uninstall.exe"
          Microsoft Office Professional Edition 2003-->MsiExec.exe /I{9011040C-6000-11D3-8CFE-0150048383C9}
          Microsoft Silverlight-->MsiExec.exe /I{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
          Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
          Mozilla Firefox (3.0.5)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
          MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
          MSXML 4.0 SP2 (KB941833)-->MsiExec.exe /I{C523D256-313D-4866-B36A-F3DE528246EF}
          MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
          Navigateur Orange-->C:\Program Files\OrangeHSS\Uninstall\Browser\Shell.exe MainUninstall.shl
          NTI Backup NOW! 4.7-->"C:\Program Files\InstallShield Installation Information\{1598034D-7147-432C-8CA8-888E0632D124}\setup.exe" -removeonly
          NTI Backup NOW! 4.7-->C:\Program Files\InstallShield Installation Information\{1598034D-7147-432C-8CA8-888E0632D124}\setup.exe -runfromtemp -l0x040c
          NTI CD & DVD-Maker-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{1577A05B-EE62-4BBC-9DB7-FE748FA44EC2} /l1036 CDM7
          NVIDIA Drivers-->C:\Windows\system32\nvunrm.exe UninstallGUI
          Nvu 1.0-->"C:\Program Files\Nvu\unins000.exe"
          OCR Software by I.R.I.S. 11.0-->C:\Program Files\HP\Digital Imaging\OCR\hpzscr01.exe -datfile hpqbud11.dat
          OpenAL-->"C:\Program Files\OpenAL\oalinst.exe" /U
          OpenOffice.org 3.0 Language Pack (French)-->MsiExec.exe /I{2A0DB319-6365-4876-B7D8-994A79AA1329}
          OpenOffice.org 3.0-->MsiExec.exe /I{1572F66F-F9AD-4D45-B0D2-0F45A0D5A0F6}
          Orange - Logiciels Internet-->C:\Program Files\OrangeHSS\installation\core\Installgui.exe -u
          Pro Evolution Soccer 2009-->MsiExec.exe /X{A8DB611A-D80E-450D-85F6-3ACDD164BE31}
          QuickTime-->MsiExec.exe /I{08CA9554-B5FE-4313-938F-D4A417B81175}
          RealPlayer-->C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
          Realtek High Definition Audio Driver-->RtlUpd.exe -r -m
          SAMSUNG Mobile Modem Driver Set-->C:\Windows\system32\Samsung_USB_Drivers\3\SSCDUninstall.exe
          Samsung Mobile phone USB driver Software-->C:\Windows\system32\Samsung_USB_Drivers\5\SSSDUninstall.exe
          SAMSUNG Mobile USB Modem 1.0 Software-->C:\Windows\system32\Samsung_USB_Drivers\1\SS_Uninstall.exe
          SAMSUNG Mobile USB Modem Software-->C:\Windows\system32\Samsung_USB_Drivers\2\SSM_Uninstall.exe
          Samsung PC Studio 3 USB Driver Installer-->"C:\Program Files\InstallShield Installation Information\{EBA29752-DDD2-4B62-B2E3-9841F92A3E3A}\setup.exe" -runfromtemp -l0x040c -removeonly
          Samsung PC Studio 3-->"C:\Program Files\InstallShield Installation Information\{C4A4722E-79F9-417C-BD72-8D359A090C97}\setup.exe" -runfromtemp -l0x040c -removeonly
          Security Update for CAPICOM (KB931906)-->MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
          Security Update for CAPICOM (KB931906)-->MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
          Skype™ 3.8-->MsiExec.exe /X{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}
          SopCast 3.0.1-->C:\Program Files\SopCast\uninst.exe
          Spelling Dictionaries Support For Adobe Reader 8-->MsiExec.exe /I{AC76BA86-7AD7-5464-3428-800000000003}
          Spybot - Search & Destroy-->"C:\Program Files\Spybot - Search & Destroy\unins000.exe"
          TmNationsForever-->"C:\Program Files\TmNationsForever\unins000.exe"
          VideoLAN VLC media player 0.8.6h-->C:\Program Files\VideoLAN\VLC\uninstall.exe
          Virtual DJ - Atomix Productions-->C:\PROGRA~1\VIRTUA~1\UNWISE.EXE C:\PROGRA~1\VIRTUA~1\INSTALL.LOG
          Vista Codec Package-->MsiExec.exe /I{F9FD80CE-0448-4D4F-8BCD-77FC514C3F99}
          Windows Live installer-->MsiExec.exe /X{FD44E544-E7D0-4DBA-9FA0-8AE1A1300390}
          Windows Live Messenger-->MsiExec.exe /X{BADF6744-3787-48F6-B8C9-4C4995401D65}
          Windows Media Player Firefox Plugin-->MsiExec.exe /I{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}

          ======Hosts File======

          127.0.0.1 myomemo.com
          127.0.0.1 www.myomemo.com

          ======Security center information======

          AV: Avira AntiVir PersonalEdition
          AS: Windows Defender

          System event log

          Computer Name: PC-des-Moitel
          Event Code: 3004
          Message: L’agent de protection en temps réel Windows Defender a détecté des modifications. Microsoft vous recommande d’analyser les logiciels responsables de ces modifications, à la recherche de risques potentiels. Vous pouvez vous servir des informations relatives au fonctionnement de ces programmes pour autoriser ou non leur exécution, ou pour les supprimer de l’ordinateur. N’autorisez les modifications que si vous faites confiance au programme ou à l’éditeur de logiciel. Windows Defender ne peut pas annuler les modifications que vous autorisez.
          Pour plus d’informations, consultez les données suivantes :
          Non applicable
          ID d’analyse : {1D3F492A-DDB2-4721-A1B6-89D5F4AF73C4}
          Utilisateur : PC-DES-MOITEL\Maxime
          Nom : Unknown
          ID :
          ID de gravité :
          ID de catégorie :
          Chemin d’accès trouvé : file:C:\Users\Maxime\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StartUp\OpenOffice.org 3.0.lnk;file:C:\Program Files\OpenOffice.org 3\program\quickstart.exe;startup:C:\Users\Maxime\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StartUp\OpenOffice.org 3.0.lnk
          Type d’alerte : Logiciel non classifié
          Type de détection :
          Record Number: 62831
          Source Name: Microsoft-Windows-Windows Defender
          Time Written: 20090110133821.000000-000
          Event Type: Avertissement
          User:

          Computer Name: PC-des-Moitel
          Event Code: 3005
          Message: L’agent de protection en temps réel Windows Defender a pris des mesures pour protéger cet ordinateur contre les logiciels espions ou autres logiciels potentiellement indésirables.
          Pour plus d’informations, consultez les informations suivantes :
          Non applicable
          ID d’analyse : {1D3F492A-DDB2-4721-A1B6-89D5F4AF73C4}
          Utilisateur : PC-DES-MOITEL\Maxime
          Nom : Unknown
          ID :
          ID de gravité :
          ID de catégorie :
          Type d’alerte : Logiciel non classifié
          Action : Ignorer
          Record Number: 62832
          Source Name: Microsoft-Windows-Windows Defender
          Time Written: 20090110133821.000000-000
          Event Type: Information
          User:

          Computer Name: PC-des-Moitel
          Event Code: 7036
          Message: Le service Service de découverte automatique de Proxy Web pour les services HTTP Windows est entré dans l'état : en cours d'exécution.
          Record Number: 62833
          Source Name: Service Control Manager
          Time Written: 20090110133821.000000-000
          Event Type: Information
          User:

          Computer Name: PC-des-Moitel
          Event Code: 7036
          Message: Le service Service de découverte automatique de Proxy Web pour les services HTTP Windows est entré dans l'état : arrêté.
          Record Number: 62834
          Source Name: Service Control Manager
          Time Written: 20090110135451.000000-000
          Event Type: Information
          User:

          Computer Name: PC-des-Moitel
          Event Code: 7036
          Message: Le service Informations d'application est entré dans l'état : en cours d'exécution.
          Record Number: 62835
          Source Name: Service Control Manager
          Time Written: 20090110170524.000000-000
          Event Type: Information
          User:

          Application event log

          Computer Name: PC-des-Moitel
          Event Code: 1000
          Message: Application défaillante k.exe, version 0.0.0.0, horodatage 0x2eee229e, module défaillant ntdll.dll, version 6.0.6001.18000, horodatage 0x4791a7a6, code d’exception 0xc0000005, décalage d’erreur 0x0003d0cd, ID du processus 0x11c0, heure de début de l’application 0x01c97344ead52765.
          Record Number: 16666
          Source Name: Application Error
          Time Written: 20090110170019.000000-000
          Event Type: Erreur
          User:

          Computer Name: PC-des-Moitel
          Event Code: 1000
          Message: Application défaillante k.exe, version 0.0.0.0, horodatage 0x2eee229e, module défaillant ntdll.dll, version 6.0.6001.18000, horodatage 0x4791a7a6, code d’exception 0xc0000005, décalage d’erreur 0x0003d0cd, ID du processus 0x121c, heure de début de l’application 0x01c973463cd569c5.
          Record Number: 16667
          Source Name: Application Error
          Time Written: 20090110170946.000000-000
          Event Type: Erreur
          User:

          Computer Name: PC-des-Moitel
          Event Code: 1024
          Message: Le ou les disques ont TtT analysTs pour lÆTtat SMART.
          Record Number: 16668
          Source Name: NVRAIDSERVICE
          Time Written: 20090110171017.000000-000
          Event Type: Information
          User:

          Computer Name: PC-des-Moitel
          Event Code: 1001
          Message: Récipient d’erreurs 990707048, type 1
          Événement : APPCRASH
          Réponse : Aucun
          ID de CAB : 0

          Signature du problème :
          P1 : k.exe
          P2 : 0.0.0.0
          P3 : 2eee229e
          P4 : ntdll.dll
          P5 : 6.0.6001.18000
          P6 : 4791a7a6
          P7 : c0000005
          P8 : 0003d0cd
          P9 :
          P10 :

          Fichiers joints :
          C:\Users\Maxime\AppData\Local\Temp\WER54AE.tmp.version.txt

          Ces fichiers sont peut-être disponibles ici :
          C:\Users\Maxime\AppData\Local\Microsoft\Windows\WER\ReportArchive\Report162e947c
          Record Number: 16669
          Source Name: Windows Error Reporting
          Time Written: 20090110173259.000000-000
          Event Type: Information
          User:

          Computer Name: PC-des-Moitel
          Event Code: 5
          Message: Unsupported service control request (see data below)
          Record Number: 16670
          Source Name: LightScribeService
          Time Written: 20090110173319.000000-000
          Event Type: Information
          User:

          Security event log

          Computer Name: PC-des-Moitel
          Event Code: 5038
          Message: L’intégrité du code a déterminé que le hachage de l’image d’un fichier n’est pas valide. Le fichier peut être endommagé en raison d’une modification non autorisée ou le hachage non valide peut indiquer une erreur d’unité de disque potentielle.

          Nom du fichier : \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys
          Record Number: 22861
          Source Name: Microsoft-Windows-Security-Auditing
          Time Written: 20090110173317.101595-000
          Event Type: Échec de l'audit
          User:

          Computer Name: PC-des-Moitel
          Event Code: 5038
          Message: L’intégrité du code a déterminé que le hachage de l’image d’un fichier n’est pas valide. Le fichier peut être endommagé en raison d’une modification non autorisée ou le hachage non valide peut indiquer une erreur d’unité de disque potentielle.

          Nom du fichier : \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys
          Record Number: 22862
          Source Name: Microsoft-Windows-Security-Auditing
          Time Written: 20090110173317.132795-000
          Event Type: Échec de l'audit
          User:

          Computer Name: PC-des-Moitel
          Event Code: 5038
          Message: L’intégrité du code a déterminé que le hachage de l’image d’un fichier n’est pas valide. Le fichier peut être endommagé en raison d’une modification non autorisée ou le hachage non valide peut indiquer une erreur d’unité de disque potentielle.

          Nom du fichier : \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys
          Record Number: 22863
          Source Name: Microsoft-Windows-Security-Auditing
          Time Written: 20090110173317.148395-000
          Event Type: Échec de l'audit
          User:

          Computer Name: PC-des-Moitel
          Event Code: 5038
          Message: L’intégrité du code a déterminé que le hachage de l’image d’un fichier n’est pas valide. Le fichier peut être endommagé en raison d’une modification non autorisée ou le hachage non valide peut indiquer une erreur d’unité de disque potentielle.

          Nom du fichier : \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys
          Record Number: 22864
          Source Name: Microsoft-Windows-Security-Auditing
          Time Written: 20090110173317.179595-000
          Event Type: Échec de l'audit
          User:

          Computer Name: PC-des-Moitel
          Event Code: 5038
          Message: L’intégrité du code a déterminé que le hachage de l’image d’un fichier n’est pas valide. Le fichier peut être endommagé en raison d’une modification non autorisée ou le hachage non valide peut indiquer une erreur d’unité de disque potentielle.

          Nom du fichier : \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys
          Record Number: 22865
          Source Name: Microsoft-Windows-Security-Auditing
          Time Written: 20090110173317.210795-000
          Event Type: Échec de l'audit
          User:

          ======Environment variables======

          "ComSpec"=%SystemRoot%\system32\cmd.exe
          "FP_NO_HOST_CHECK"=NO
          "OS"=Windows_NT
          "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\QuickTime\QTSystem\;C:\Program Files\Common Files\GIS\Tools;C:\Program Files\Samsung\Samsung PC Studio 3\
          "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
          "PROCESSOR_ARCHITECTURE"=x86
          "TEMP"=%SystemRoot%\TEMP
          "TMP"=%SystemRoot%\TEMP
          "USERNAME"=SYSTEM
          "windir"=%SystemRoot%
          "PROCESSOR_LEVEL"=6
          "PROCESSOR_IDENTIFIER"=x86 Family 6 Model 15 Stepping 11, GenuineIntel
          "PROCESSOR_REVISION"=0f0b
          "NUMBER_OF_PROCESSORS"=4
          "CLASSPATH"=.;C:\Program Files\Java\jre1.6.0_06\lib\ext\QTJava.zip
          "QTJAVA"=C:\Program Files\Java\jre1.6.0_06\lib\ext\QTJava.zip

          -----------------EOF-----------------
          0
          1. Le deuxième rapport "log"

            Logfile of random's system information tool 1.05 (written by random/random)
            Run by Maxime at 2009-01-10 18:32:51
            Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 1
            System drive C: has 134 GB (57%) free of 234 GB
            Total RAM: 3070 MB (48% free)

            Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 18:33:18, on 10/01/2009
            Platform: Windows Vista SP1 (WinNT 6.00.1905)
            MSIE: Internet Explorer v7.00 (7.00.6001.18000)
            Boot mode: Normal

            Running processes:
            C:\Windows\system32\Dwm.exe
            C:\Windows\system32\taskeng.exe
            C:\Windows\Explorer.EXE
            C:\Program Files\Windows Defender\MSASCui.exe
            C:\Windows\RtHDVCpl.exe
            C:\Acer\Empowering Technology\SysMonitor.exe
            C:\Acer\Empowering Technology\eDataSecurity\eDSLoader.exe
            C:\Windows\System32\nvraidservice.exe
            C:\Program Files\Acer Arcade Live\Acer PlayMovie\PMVService.exe
            C:\Program Files\OrangeHSS\Systray\SystrayApp.exe
            C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
            C:\Program Files\iTunes\iTunesHelper.exe
            C:\Program Files\Common Files\Real\Update_OB\realsched.exe
            C:\Windows\System32\rundll32.exe
            C:\Program Files\Java\jre6\bin\jusched.exe
            C:\Windows\System32\rundll32.exe
            C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
            C:\Program Files\Windows Sidebar\sidebar.exe
            C:\Windows\ehome\ehtray.exe
            C:\Users\Maxime\AppData\Roaming\tmobd.exe
            C:\Users\Maxime\AppData\Roaming\finalssf\fssf.exe
            C:\Program Files\DAEMON Tools Lite\daemon.exe
            C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
            C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
            C:\Users\Maxime\AppData\Local\uiako.exe
            C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
            C:\Windows\system32\wbem\unsecapp.exe
            C:\Windows\ehome\ehmsas.exe
            C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
            C:\Program Files\Internet Explorer\iexplore.exe
            C:\Program Files\Internet Explorer\IEUser.exe
            C:\Program Files\Google\Google Toolbar\GoogleToolbarUser.exe
            C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
            C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_clipbook.exe
            C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe
            C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
            C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
            C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
            C:\Users\Maxime\AppData\Roaming\tmobd.exe
            C:\Program Files\OrangeHSS\Launcher\Launcher.exe
            C:\Program Files\OrangeHSS\connectivity\connectivitymanager.exe
            C:\Program Files\OrangeHSS\connectivity\CoreCom\CoreCom.exe
            C:\Program Files\OrangeHSS\connectivity\CoreCom\OraConfigRecover.exe
            C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\FTCOMModule\0\FTCOMModule.exe
            C:\Windows\System32\mobsync.exe
            C:\Program Files\OpenOffice.org 3\program\soffice.exe
            C:\Program Files\OpenOffice.org 3\program\soffice.bin
            C:\Windows\system32\conime.exe
            C:\Windows\system32\cmd.exe
            C:\Users\Maxime\AppData\Roaming\hdf\httpddos.exe
            C:\Program Files\Mozilla Firefox\firefox.exe
            C:\Users\Maxime\AppData\Roaming\msnf3\ms.exe
            C:\Windows\system32\SearchFilterHost.exe
            C:\Users\Maxime\Downloads\RSIT.exe
            C:\Program Files\trend micro\Maxime.exe

            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://fr.rd.yahoo.com/customize/ycomp/defaults/sp/*https://fr.yahoo.com/
            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://fr.yahoo.com/
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/
            R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
            R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
            R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://fr.rd.yahoo.com/customize/ycomp/defaults/su/*https://fr.yahoo.com/
            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
            R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\OrangeHSS\SearchURLHook\SearchPageURL.dll
            O1 - Hosts: ::1 localhost
            O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
            O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
            O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
            O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
            O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
            O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
            O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
            O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
            O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
            O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
            O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
            O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll
            O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
            O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
            O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
            O4 - HKLM\..\Run: [Acer Empowering Technology Monitor] C:\Acer\Empowering Technology\SysMonitor.exe
            O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
            O4 - HKLM\..\Run: [PCMMediaSharing] C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe
            O4 - HKLM\..\Run: [Apanel] C:\ACERSW\config\NewSetApanel.cmd
            O4 - HKLM\..\Run: [WarReg_PopUp] C:\Acer\WR_PopUp\WarReg_PopUp.exe
            O4 - HKLM\..\Run: [NVRaidService] C:\Windows\system32\nvraidservice.exe
            O4 - HKLM\..\Run: [Acer Tour Reminder] C:\Acer\AcerTour\Reminder.exe
            O4 - HKLM\..\Run: [PlayMovie] "C:\Program Files\Acer Arcade Live\Acer PlayMovie\PMVService.exe"
            O4 - HKLM\..\Run: [SystrayORAHSS] "C:\Program Files\OrangeHSS\Systray\SystrayApp.exe"
            O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
            O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
            O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
            O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
            O4 - HKLM\..\Run: [Skytel] Skytel.exe
            O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
            O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
            O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
            O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
            O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
            O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
            O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
            O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
            O4 - HKCU\..\Run: [Acer Tour Reminder] C:\Acer\AcerTour\Reminder.exe
            O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
            O4 - HKCU\..\Run: [tmobd] C:\Users\Maxime\AppData\Roaming\tmobd.exe
            O4 - HKCU\..\Run: [ssf] C:\Users\Maxime\AppData\Roaming\finalssf\fssf.exe
            O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
            O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
            O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
            O4 - HKCU\..\Run: [uiako] "c:\users\maxime\appdata\local\uiako.exe" uiako
            O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
            O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
            O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
            O4 - Startup: OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
            O4 - Global Startup: Empowering Technology Launcher.lnk = ?
            O4 - Global Startup: E_SPSU01.lnk = C:\Windows\System32\spool\drivers\w32x86\3\E_SPSU01.EXE
            O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
            O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
            O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
            O9 - Extra button: Sélection intelligente HP - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
            O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
            O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
            O13 - Gopher Prefix:
            O16 - DPF: {2250C29C-C5E9-4F55-BE4E-01E45A40FCF1} (CMediaMix Object) - http://musicmix.messenger.msn.com/Medialogic.CAB
            O16 - DPF: {9122D757-5A4F-4768-82C5-B4171D8556A7} (PhotoPickConvert Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/PhotoSwap/PhtPkMSN.cab
            O16 - DPF: {A1F2F2CE-06AF-483C-9F12-D3BAA72477D6} (BatchDownloader Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/PhotoSwap/DigWXMSN.cab
            O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
            O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
            O23 - Service: Acer HomeMedia Connect Service - CyberLink - C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe
            O23 - Service: ePerformance Service (AcerMemUsageCheckService) - Unknown owner - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
            O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
            O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
            O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
            O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
            O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
            O23 - Service: eDSService.exe (eDataSecurity Service) - HiTRSUT - C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
            O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
            O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
            O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
            O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
            O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
            O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
            0
            1. Pas de soucis Gen ! à Toute ;)

              Et au fait, si il y a d'autres choses anormalessignalez le ! :D
              0
              1. bonjour :

                Télécharge UsbFix (de Chiquitine29) sur ton Bureau :
                http://sd-1.archive-host.com/membres/up/116615172019703188/UsbFix.exe

                --> Lance l'installation avec les paramètres par défaut.

                --> Branche tes sources de données externes à ton PC (clé USB, disque dur externe, etc...) sans les ouvrir.

                --> Double-clique sur le raccourci UsbFix sur ton Bureau. choisis nettoyage

                --> Le PC va redémarrer.

                --> Après redémarrage, poste le rapport UsbFix.txt

                Note : le rapport UsbFix.txt est sauvegardé à la racine du disque.

                (Si le Bureau ne réapparait pas, presse Ctrl+Alt+Suppr, Onglet "Fichier", "Nouvelle tâche", tape explorer.exe et valide)
                0
                1. Okaii'
                  Il y a rien de spcécial dans ces rapports !?
                  Rien d'anormal ?
                  0
                  1. si c est pour cela qu il faut que tu effectues le post8

                    0
                    1. Okaii' Jfais ca jte donne tout de suite !
                      Mais quand tu dis à la racine du disque C'est ou que je dois aller chercher le rapport ?

                      Pourrais tu me dire les lgines qui sont bizarres pour que j'aprenne en même temps à detecter tout ca ... ?
                      0
                      1. [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{03ac2419-d1b7-11dd-89b1-001d926a1f57}]
                        shell\AutoRun\command - zcouwz.exe
                        shell\explore\command - zcouwz.exe
                        shell\open\command - zcouwz.exe


                        ceci est ennuyeux
                        0
                        1. Et il est ou le rapport de USBFIX donc ?
                          0
                          1. demarrer/poste de travail et c:\
                            0
                            1. 01/05/2009 18:55:39 Program Start
                              01/05/2009 18:55:39 Process hpwuSchd2.exe was found and terminated. Result = 1

                              01/05/2009 18:55:39 Process HPWUCli.exe was found and terminated. Result = 1

                              01/05/2009 18:55:39 Process HpuFunction.dll was found and terminated. Result = 1
                              01/05/2009 18:55:39 SetNameSecruityInfo on C:\Program Files\HP\HP Software Update\ returned 5

                              01/05/2009 18:55:39 Program exited with 5
                              01/05/2009 18:55:49 Program Start
                              01/05/2009 18:55:49 SetNameSecruityInfo on C:\Program Files\HP\HP Software Update\ returned 0

                              01/05/2009 18:55:49 Program exited with 0

                              C ca ?
                              0
                              1. fais une recherche avec F3 dans tout le pc
                                0
                                1. Est ce que c'est ca ?

                                  Changelog UsbFix établit le 2 decembre 2008
                                  outils créé par Chiquitine29 , aide aux mises a jours -> Chimay8

                                  >>>>>>in "ProgramFiles"<<<<<<<<<

                                  Internet Explorer\Connection Wizard\icwconn1\rada
                                  Internet Explorer\Connection Wizard\icwconn1\rade
                                  Internet Explorer\Connection Wizard\icwconn1\radf
                                  Internet Explorer\Connection Wizard\icwconn1\rad5
                                  Internet Explorer\Connection Wizard\icwconn1\rad0
                                  Internet Explorer\Connection Wizard\icwconn1\rad9
                                  Internet Explorer\Connection Wizard\icwconn1\rad4
                                  Internet Explorer\Connection Wizard\icwconn1\rad1
                                  Internet Explorer\Connection Wizard\icwconn1
                                  Movie Maker\explorer.exe
                                  Internet Explorer\explorer.exe

                                  >>>>>>in "Windows"<<<<<<<<<

                                  autorun.inf
                                  autorun.exe
                                  autorun.vbs
                                  autorun.reg
                                  autorun.ini
                                  autorun.fcb
                                  autorun.bat
                                  autorun.com
                                  AdobeR.exe
                                  Alecks.vbs
                                  bittorrent.exe
                                  cmd32.exe
                                  CwbRmDir.bat
                                  Fonts\Fonts.exe
                                  FS6519.dll.vbs
                                  funny.exe
                                  GMOGLFEO.exe
                                  hiqalowo.inf
                                  icapy.scr
                                  ilezyvu.bin
                                  Lany.vbs
                                  lumy.exe
                                  manulopa.reg
                                  MS32DLL.dll.vbs
                                  MyMP3.vbs
                                  nar.vbs
                                  osok.inf
                                  osotilasiq.pif
                                  oxafa.com
                                  qobo.dat
                                  rundll32.vbe
                                  sleep.vbe
                                  SysRes.vbs
                                  takice.lib
                                  tusoha.exe
                                  unahafiwik.exe
                                  waol.exe
                                  waziqepehi.ban
                                  WillPolo.vbs
                                  Win32DLL.vbs
                                  win.vbe
                                  window.exe
                                  wyzeha.com
                                  xcopy.exe
                                  yjilu.inf
                                  ylacupyb.dll

                                  RECYCLER\systems.com

                                  temp\039.tmp

                                  >>>>>>in "Windows\system32"<<<<<<<<<

                                  agucuri.vbs
                                  ahr.exe
                                  Alecks.vbs
                                  antinul.vbe
                                  amvo.exe
                                  amvo0.dll
                                  amvo1.dll
                                  amvo2.dll
                                  autorun.bat
                                  Autorun.com
                                  autorun.exe
                                  autorun.fcb
                                  autorun.inf
                                  autorun.ini
                                  autorun.reg
                                  autorun.vbs
                                  Autoruns.exe
                                  avpo.exe
                                  avpo0.dll
                                  avpo1.dll
                                  Bitkvo.exe
                                  Bitkv0.dll
                                  Bitkv1.dll
                                  cftmonn.exe
                                  Christina.jpg
                                  Christina.vbs
                                  ckvo.exe
                                  ckvo0.dll
                                  ckvo1.dll
                                  ckvo2.dll
                                  cradle_of_filth.vbe
                                  delself.bat
                                  FS6519.dll.vbs
                                  GMOGLFEO.exe
                                  icf.exe.exe
                                  ie.exe
                                  jvvo.exe
                                  jvvo0.dll
                                  jvvo1.dll
                                  jvvo2.dll
                                  jvvo3.dll
                                  j3ewro.exe
                                  jwedsfdo0.dll
                                  jwedsfdo1.dll
                                  jwedsfdo2.dll
                                  jwedsfdo3.dll
                                  jxnraqjxg.exe
                                  kavo.exe
                                  kamsoft.exe
                                  kav0.dll
                                  kav1.dll
                                  kav2.dll
                                  kav3.dll
                                  kavo0.dll
                                  kavo1.dll
                                  kavo2.dll
                                  kavo3.dll
                                  kdkfm.exe
                                  KEYBOARD.exe
                                  keygen.exe
                                  kulitut.bat
                                  kulitut.vbs
                                  kxvo.exe
                                  kxvo0.dll
                                  kxvo1.dll
                                  kxvo2.dll
                                  kxvo3.dll
                                  lExplore.exe
                                  loader.exe
                                  logoneui.exe
                                  LOVE-LETTER-FOR-YOU.HTM
                                  LOVE-LETTER-FOR-YOU.TXT.vbs
                                  msfun80.exe
                                  msime82.exe
                                  MSKernel32.vbs
                                  ne0kS.dll.wsf
                                  ne0kS.exe
                                  OeApi.vbs
                                  pubnet.vbs
                                  rs32net.exe
                                  SemiAntiVirus.vbs
                                  Sexy Girls.scr
                                  SpiderH.bmp
                                  SpiderH.jpeg
                                  SpiderH.vbs
                                  sys.vbs
                                  Syso.vbs
                                  SysRes.vbs
                                  syx.exe
                                  taso.exe
                                  tavo.exe
                                  tavo0.dll
                                  tavo1.dll
                                  tavo2.dll
                                  tavo3.dll
                                  temp1.exe
                                  temp2.exe
                                  temp?.exe
                                  text.txt
                                  Ecran.exe
                                  THe Girls
                                  tmp.reg
                                  tmp.txt
                                  t.txt
                                  vb@dock.vbs
                                  vl@dock.vbs
                                  Win32.vbs
                                  winudp64.exe

                                  dllcache\Default.exe

                                  >>>>>>in "Windows\system32\drivers"<<<<<<<<<

                                  ._Sanaa style-1 les formes.exe
                                  0hct8ybw.exe
                                  1ere partie du projet modifier.exe
                                  abdelali lahrach.exe
                                  Analyse transactionnelle.exe
                                  AutoRun.exe
                                  Bernoulli01215.exe"
                                  Cahiers français Quels modes de financement pour les entreprises - La Documentation française.exe
                                  Copie de Devoir I.exe
                                  e-ticket Juba Paris.exe
                                  fdfp2.exe
                                  fihi ghizlane Rapport de stage.exe
                                  graphic.exe
                                  intel.exe
                                  isew32.exe
                                  kheireddine.exe
                                  le_cadeau_du_sud(1).exe
                                  LEADERSHIP SKILLS FINAL.exe
                                  lettre de motivation.exe
                                  MSDS.exe
                                  Note.exe
                                  PREMIER CHAPITRE modifié.exe
                                  Raila Odinga.exe
                                  Rapport NADIA.exe
                                  spectro_masse1.exe
                                  td de reacteur.exe
                                  these-223.exe
                                  xyw9tmdj.exe

                                  >>>>>>in "Documents and Settings"<<<<<<<<<

                                  tazebama.dl_
                                  hook.dl_

                                  >>>>>>in "appdata"<<<<<<<<<

                                  fetomiv.vbs
                                  gumugy.vbs
                                  jicapikase.vbs
                                  mobyhikaja.vbs
                                  nebohozi.com
                                  orimuwy.exe
                                  sidymyvig.vbs
                                  tazebama\tazebama.log
                                  tazebama\zPharaoh.dat
                                  tazebama

                                  >>>>>>in "Temp files"<<<<<<<<<

                                  1.reg
                                  2.dll
                                  6257890.exe
                                  fq9.dll
                                  help.exe
                                  help1.rar
                                  inst.exe
                                  system.dll
                                  w2e.sys
                                  winhqqo.exe
                                  wintoift.exe
                                  xhjb.dll
                                  xxx6042.exe
                                  zb5ok.dll

                                  >>>>>>in "All Drives"<<<<<<<<<

                                  ._autorun.inf
                                  autorun.inf
                                  autorun.ini
                                  autorun.reg
                                  autorun.bat
                                  autorun.vbs
                                  autorun2.inf
                                  autosys.exe
                                  00hoeav.com
                                  096.bat
                                  0gjn3yw.exe
                                  0qx0sc6.bat
                                  0tmhoc.cmd
                                  0u.cmd
                                  0w.com
                                  0wk2.cmd
                                  108i.cmd
                                  1aq1obb.bat
                                  1bbvq96y.com
                                  1dg.exe
                                  1i.com
                                  1nkbd8h.bat
                                  1rfw8hjr.com
                                  1u0o8bnq.cmd
                                  1weicxa.com
                                  1XXEC.exe
                                  22xo.exe
                                  2ifetri.cmd
                                  2y8la.exe
                                  30ed3.exe
                                  33gmhso.bat
                                  39lpji.com
                                  3o.exe
                                  3wcxx91.cmd
                                  3xXx31.exe
                                  4vzjaw3o.sys
                                  62oop0ak.bat
                                  68.exe
                                  6tkoyhx.cmd
                                  6x8be16.cmd
                                  8e9gmih.bat
                                  8ng8w.com
                                  93vx0c.com
                                  9yqusig.bat
                                  22wcb21o.exe
                                  31n3b2h.exe
                                  39lpji.com
                                  80avp08.com
                                  82r9.cmd
                                  83fgj.com
                                  83l3v.cmd
                                  8df.exe >
                                  8h3hh3m.exe
                                  8tss2gwq.bat
                                  90imhpnc.exe
                                  92j11sm.com
                                  9es.com
                                  a1.bat
                                  a9.com
                                  abk.bat
                                  activexdebugger32.exe
                                  Administrateur_Fichiers.exe
                                  admp.exe
                                  adobeR.exe
                                  Akon.exe
                                  Alecks.vbs
                                  antihost.exe
                                  antinul.vbe
                                  aoutfq.exe
                                  ar.exe
                                  Atisetup.exe
                                  auto.exe
                                  autorum.exe
                                  AutoRun\Demo.exe
                                  autorun.exe
                                  autorun.pif
                                  autoruns.exe
                                  AutoScr.exe
                                  ay8p6v3.cmd
                                  Ayame.exe
                                  b3b9u.com
                                  bicsxk03.com
                                  bittorrent.exe
                                  bndafai.exe
                                  bo1dhu.bat
                                  bobm.exe
                                  boot.exe
                                  bootin.exe
                                  bplrl98.cmd
                                  buis.exe
                                  bwpncb6.com
                                  bxuup9r.bat c18vk.exe
                                  c9.com
                                  c9hehpa.bat
                                  camp.exe
                                  cayfq2.cmd
                                  cd8idoyl.com
                                  cdr.exe
                                  ceb6eu98.bat
                                  cekbru.pif
                                  clear.bat
                                  ClickMe.exe
                                  cftmonn.exe
                                  cfv90h.com
                                  Christina.vbs
                                  cjq.exe
                                  commands.txt
                                  comment.htt
                                  copetttt.com
                                  copy.exe
                                  cradle_of_filth.vbe
                                  cqdis.cmd
                                  cvqkuk.exe
                                  d3bn0j.exe
                                  ddyikr.cmd
                                  delautorun.bat
                                  DFD34719171.bat
                                  DFD34719375.bat
                                  DFD34719609.bat
                                  DFD34723328.bat
                                  DFD34723375.bat
                                  DFD34723781.bat
                                  DFD34724390.bat
                                  DFD34719609.bat
                                  DFD34724531.bat
                                  DFD34724656.bat
                                  DFD34725125.bat
                                  DFD34725218.bat
                                  DFD34726312.bat
                                  DFD34724390.bat
                                  DFD34726328.bat
                                  DFD34729609.bat
                                  DFD34730531.bat
                                  DFD34730937.bat
                                  DFD34734937.bat
                                  DFD34739859.bat
                                  DFD34741421.bat
                                  DFD34741734.bat
                                  DFD34741843.bat
                                  DFD*.bat
                                  dhv2u8.cmd
                                  DPFMate.exe
                                  dstart.exe
                                  dtqlv.exe
                                  dynrn6e.cmd
                                  e898.com
                                  e9ehn1m8.com
                                  eb9ehyh.exe
                                  Ecran.exe
                                  ek.com
                                  ekf6dbg0.com
                                  ekugb3.bat
                                  erdeIect.com
                                  esta ig.vbs
                                  ev60a2.cmd
                                  explorer.exe
                                  exqmmle.exe
                                  f0.cmd
                                  f2ir.com
                                  fe.bat
                                  ffojc.com
                                  fi.cmd
                                  FLIPART.EXE
                                  folder.exe
                                  Folder.htt
                                  fooool.exe
                                  Form5.exe
                                  forSV.exe
                                  FS6519.dll.vbs
                                  fucker.vbs
                                  fun.xls.exe
                                  g2p3s.exe
                                  g2pfnid.com
                                  g83816.com
                                  gdmae.bmp
                                  Ghost.pif
                                  gkyzcijfb.exe
                                  GMOGLFEO.exe
                                  gqsk.bat
                                  graphic.exe
                                  gsxlexd.cmd
                                  gxlxknou.exe
                                  gy.cmd
                                  h0s2.bat h2.com
                                  hfhludy.exe
                                  hgu.bat
                                  hni.cmd
                                  host.exe
                                  hsomklg.exe
                                  hxt9.bat
                                  i0.cmd
                                  i8.cmd
                                  ie.exe
                                  igxv.cmd
                                  ij.bat
                                  ilpg9ejd.com
                                  info.exe
                                  infrom.exe
                                  ino6.com
                                  install.exe
                                  intel.exe
                                  intro.exe
                                  ipy.cmd
                                  iq0ecwcj.cmd
                                  lsass.exe
                                  itsduel.exe
                                  iwjj.com
                                  j4c8t8b5l3a6.exe
                                  j8q8d.cmd
                                  jbfqv8j.cmd
                                  jdhc2x2.com
                                  jdwx.exe
                                  jfjsipw.exe
                                  jfvkcsy.bat
                                  jiwsxh39.exe
                                  JJJ.exe
                                  Jojo.exe
                                  jwwgtuh.exe
                                  jxnraqjxg.exe
                                  jxpiinstall.exe
                                  k6wkwon2.exe
                                  ka1nk.bat
                                  kaq86asx.bat
                                  kayira.bat
                                  kbqbptn.exe
                                  kdkfm.exe
                                  kdy.cmd
                                  kfmyoc.pif
                                  khbph.exe
                                  killVBS.vbs
                                  kk3.bat
                                  KM.exe
                                  kmd.exe
                                  kn6jhgc.cmd
                                  kqnns.exe
                                  kqsr.exe
                                  krg62.cmd
                                  kulitut.bat
                                  kulitut.vbs
                                  kxax.cmd
                                  l2f.cmd
                                  l9dwu8.bat
                                  lExplore.exe
                                  lgcadwx.bat
                                  lgrncie.bat
                                  lky.exe
                                  ln9.exe
                                  lo.exe
                                  loader.exe
                                  logoneui.exe
                                  Long.exe
                                  LOVE.PIF
                                  ltljrg.exe
                                  lumy.exe
                                  lurjlnps.exe
                                  lvxvo1xg.cmd
                                  m1t8ta.com
                                  m9j.com
                                  mail.exe
                                  manulopa.reg
                                  mcxa.exe
                                  Menu.exe
                                  mgjpcfdg.cm
                                  mnl6on3.com
                                  mp.bat
                                  mp.cmd
                                  mp.com
                                  Movie1.exe
                                  mrsne.bat
                                  MS-DOS.com
                                  MS32DLL.dll.vbs
                                  MSd040.vbs
                                  MSdC64.vbs
                                  MSdFB7.vbs
                                  MSd141.vbs
                                  MSd191.vbs
                                  MSd49A.vbs
                                  MSdE78.vbs
                                  MSd*.vbs
                                  mshta.exe
                                  MSKernel32.vbs
                                  muniu.exe
                                  MyMP3.vbs
                                  n1detect.com
                                  n2de.cmd
                                  n6j.com
                                  n6j6pc0.com
                                  n6t1h.cmd
                                  nansy ajram.vbs
                                  nar.vbs
                                  ne0kS.exe
                                  nemesis.exe
                                  nemesis.inf
                                  nfdmg.com
                                  nideiect.com
                                  niu.exe
                                  njibyekk.com
                                  nl.com
                                  nncu6kk.com
                                  NoLimit.exe
                                  np.exe
                                  nq0cq.cmd
                                  nqvarn.pif
                                  nriljal.exe
                                  ntde1ect.com
                                  ntdelect.com
                                  nq.bat
                                  nq0cq.cmd
                                  nqgcd.com
                                  nsv.bat
                                  nw0t1l0d.exe
                                  o2yf0w.bat
                                  o9o2u.bat
                                  o6opnro.bat
                                  OeApi.vbs
                                  oegbi.exe
                                  ogcikeq.com
                                  oka3yrf.bat
                                  oq.cmd
                                  oskkofa.exe
                                  osotilasiq.pif
                                  osy3.sys
                                  otyh.cmd
                                  oufddh.exe
                                  oxafa.com
                                  p3r1ud.exe
                                  p83gjy.exe
                                  p9.exe
                                  pa39xth.cmd
                                  pagefile.pif
                                  pbwkwj.com
                                  pefbutr.exe
                                  pkxfkrki.bat
                                  ph.com
                                  phgr1j.bat
                                  phim_nguoi_lon.exe
                                  pnc.exe
                                  prhyper.exe
                                  psqrhqn.exe
                                  pxka.exe
                                  q3v.com
                                  q83iwmgf.bat
                                  q8sywiva.cmd
                                  qcwpung.exe
                                  qd.cmd
                                  qjfl.exe
                                  qkarc.exe
                                  qquq.bat
                                  qqzjnhuoi.exe
                                  qpe6.com
                                  qobo.dat
                                  qrkugxtw.exe
                                  qxbx9blb.com
                                  r1y1.bat
                                  r2nl.com
                                  r6r.exe
                                  r813.bat
                                  Raila Odinga.exe
                                  Raila Odinga.gif
                                  ranvrgn.exe
                                  ravmon.exe
                                  ravmon.log
                                  ReadMe.exe
                                  RecInfo\RecInfo.exe
                                  Recycle.exe
                                  Recycled\ctfmon.exe
                                  RECYCLED\INFO.exe
                                  Recycled.exe
                                  RECYCLER\Lock Folder.exe
                                  RECYCLER\RECYCLER.exe
                                  RECYCLER\*.exe
                                  regxpcom.exe
                                  resycled\boot.com
                                  resycled\ctfmon.exe
                                  revo.exe
                                  rggbw.exe
                                  rjiybg.exe
                                  rn.exe
                                  rombkaewl.exe
                                  rosftpm.exe
                                  rqq2v.bat
                                  rs.cmd
                                  rt.exe
                                  Run.exe
                                  runaut~1\autorun.pif
                                  RunDll32.exe
                                  rxukgcm.exe
                                  s38k.exe
                                  sal.xls.exe
                                  sasyg1y8.com
                                  script.bat
                                  scriptlo.txt
                                  scvhosts.exe
                                  sdcvhost.exe
                                  SemiAntiVirus.vbs
                                  smkjd.cmd
                                  smss.exe
                                  semo2x.exe
                                  spq.bat
                                  serivces.exe
                                  server.exe
                                  server.inf
                                  Sex City.jpg.wsf
                                  sowar.vbs
                                  SpiderH.vbs
                                  sq.com
                                  sqlserv.exe
                                  SSVICHOSST.exe
                                  stwi.com
                                  svch0st.exe
                                  scvhosts.exe
                                  svdioajm.cmd
                                  sxs.exe
                                  sydp.exe
                                  sys.vbs
                                  Syso.vbs
                                  SysRes.vbs
                                  system.exe
                                  system32.exe
                                  systems.com
                                  systems.exe
                                  t82e2v.cmd
                                  TAE7ESLP.exe
                                  taipingtianguov1.1.exe
                                  takice.lib
                                  tel.xls.exe
                                  temp.bat
                                  temp.exe
                                  temp.temp
                                  temp1.exe
                                  temp2.exe
                                  test.exe
                                  testfile.bat
                                  testflo.bat
                                  tfk8.exe
                                  The_Cars.vbs
                                  THe Girls
                                  tknapl.exe
                                  tknn6.bat
                                  tmf3w3g0.com
                                  TMMDW8LP.exe
                                  Toy.exe
                                  tusoha.exe
                                  tyktjfww.exe
                                  u18vxqle.com
                                  u6k.cmd
                                  u9dyi.exe
                                  udnnnvq.exe
                                  UFO.exe
                                  ufuaugwq.exe
                                  uis.com
                                  uis.exe
                                  um.cmd
                                  un9.cmd
                                  unahafiwik.exe
                                  UnplugDrive.exe
                                  uorys.cmd
                                  update.exe
                                  uqhqx1.cmd
                                  usdeiect.com
                                  userinit.exe
                                  utdetect.com
                                  uxdeiect.com
                                  u?de?ect.com
                                  v2h3.exe
                                  v3pif.bat
                                  VB6FR.DLL
                                  vb@dock.vbs
                                  vfpkkbq.exe
                                  vksucydrh.exe
                                  vl@dock.vbs
                                  vmhr.bat
                                  vmyphd.bat
                                  vva0hc0p.cmd
                                  vxl.exe
                                  w0o.com
                                  w0owgn.bat
                                  w32sys.exe
                                  w3dn9f.bat
                                  waziqepehi.ban
                                  wa6.vbs
                                  Wallpaper.vbs
                                  WallpaperMEHDI.vbs
                                  wfhth.exe
                                  whi.com
                                  WillPolo.vbs
                                  WINDOWS.EXE
                                  Windows.scr
                                  winfile.exe
                                  winglogon.exe
                                  winrun.vbs
                                  winstall.exe
                                  wjlfhtfm.cmd
                                  wol.exe
                                  wsctf.exe
                                  wtbcccq.exe
                                  x0.cmd
                                  XAdeIect.com
                                  xcopy.exe
                                  xfoolavp.com
                                  xih9.cmd
                                  xj.bat
                                  xk2n.bat
                                  xlk9.com
                                  xlu8a8sy.exe
                                  xmnm2.cmd
                                  xn1i9x.com
                                  xnynrnh.exe
                                  xo8wr9.exe
                                  xp19.com
                                  xpbkh.com
                                  xqf.com
                                  xvlyb.exe
                                  xyhav.pif
                                  y82td3td.com
                                  ybj8df.exe
                                  yew.bat
                                  yg.cmd
                                  yjilu.inf
                                  ylacupyb.dl
                                  ylr.exe
                                  yjkjfuo.cmd
                                  yjvmtaa.exe
                                  ynfs9ks.cmd
                                  yssjnngm.cmd
                                  yvmkdwn.exe
                                  zPharaoh.exe
                                  0.cmd
                                  1.cmd
                                  2.cmd
                                  3.cmd
                                  4.cmd
                                  5.cmd
                                  6.cmd
                                  7.cmd
                                  8.cmd
                                  9.cmd
                                  0.bat
                                  1.bat
                                  2.bat
                                  3.bat
                                  4.bat
                                  5.bat
                                  6.bat
                                  7.bat
                                  8.bat
                                  9.bat
                                  0.exe
                                  1.exe
                                  2.exe
                                  3.exe
                                  4.exe
                                  5.exe
                                  6.exe
                                  7.exe
                                  8.exe
                                  9.exe
                                  0.com
                                  1.com
                                  2.com
                                  3.com
                                  4.com
                                  5.com
                                  6.com
                                  7.com
                                  8.com
                                  9.com
                                  0.vbs
                                  1.vbs
                                  2.vbs
                                  3.vbs
                                  4.vbs
                                  5.vbs
                                  6.vbs
                                  7.vbs
                                  8.vbs
                                  9.vbs
                                  a.com
                                  b.com
                                  c.com
                                  d.com
                                  e.com
                                  f.com
                                  g.com
                                  h.com
                                  i.com
                                  j.com
                                  k.com
                                  l.com
                                  m.com
                                  n.com
                                  o.com
                                  p.com
                                  q.com
                                  r.com
                                  s.com
                                  t.com
                                  u.com
                                  v.com
                                  w.com
                                  x.com
                                  y.com
                                  z.com
                                  a.bat
                                  b.bat
                                  c.bat
                                  d.bat
                                  e.bat
                                  f.bat
                                  g.bat
                                  h.bat
                                  i.bat
                                  j.bat
                                  k.bat
                                  l.bat
                                  m.bat
                                  n.bat
                                  o.bat
                                  p.bat
                                  q.bat
                                  r.bat
                                  s.bat
                                  t.bat
                                  u.bat
                                  v.bat
                                  w.bat
                                  x.bat
                                  y.bat
                                  z.bat
                                  a.cmd
                                  b.cmd
                                  c.cmd
                                  d.cmd
                                  e.cmd
                                  f.cmd
                                  g.cmd
                                  h.cmd
                                  i.cmd
                                  j.cmd
                                  k.cmd
                                  l.cmd
                                  m.cmd
                                  n.cmd
                                  o.cmd
                                  p.cmd
                                  q.cmd
                                  r.cmd
                                  s.cmd
                                  t.cmd
                                  u.cmd
                                  v.cmd
                                  w.cmd
                                  x.cmd
                                  y.cmd
                                  z.cmd
                                  a.exe
                                  b.exe
                                  c.exe
                                  d.exe
                                  e.exe
                                  f.exe
                                  g.exe
                                  h.exe
                                  i.exe
                                  j.exe
                                  k.exe
                                  l.exe
                                  m.exe
                                  n.exe
                                  o.exe
                                  p.exe
                                  q.exe
                                  r.exe
                                  s.exe
                                  t.exe
                                  u.exe
                                  v.exe
                                  w.exe
                                  x.exe
                                  y.exe
                                  z.exe
                                  a.vbs
                                  b.vbs
                                  c.vbs
                                  d.vbs
                                  e.vbs
                                  f.vbs
                                  g.vbs
                                  h.vbs
                                  i.vbs
                                  j.vbs
                                  k.vbs
                                  l.vbs
                                  m.vbs
                                  n.vbs
                                  o.vbs
                                  p.vbs
                                  q.vbs
                                  r.vbs
                                  s.vbs
                                  t.vbs
                                  u.vbs
                                  v.vbs
                                  w.vbs
                                  x.vbs
                                  y.vbs
                                  z.vbs
                                  *.dll.vbs

                                  >>Dossiers :

                                  AutoRun
                                  autorun.inf
                                  fsc.tmp
                                  RecInfo
                                  Recycled\Recycled
                                  Recycler\Recycler
                                  resycled
                                  runaut~1
                                  sdlflzoip

                                  >>>>>>"Registry"<<<<<<<<<

                                  [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                                  "Window Title"=-
                                  "Start Page"=-
                                  "Start Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
                                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN]
                                  "Start Page"="https://www.msn.com/fr-fr"

                                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
                                  "fucker"=-
                                  "SysDir"=-
                                  "ms32dll"=-
                                  "cftmonn"=-
                                  "Lany"=-
                                  "Zip"=-
                                  "RavAV"=-
                                  "cmd32"=-
                                  "Install.exe"=-
                                  "FIXEDFON.FON"=-
                                  "MS-RAD0"=-
                                  "MS-RAD1"=-
                                  "MS-RAD2"=-
                                  "MS-RAD3"=-
                                  "MS-RAD4"=-
                                  "MS-RAD5"=-
                                  "MS-RAD6"=-
                                  "MS-RAD7"=-
                                  "MS-RAD8"=-
                                  "MS-RAD9"=-
                                  "MS-RADA"=-
                                  "MS-RADB"=-
                                  "MS-RADC"=-
                                  "MS-RADD"=-
                                  "MS-RADE"=-
                                  "MS-RADF"=-
                                  "MS-RADG"=-
                                  "MS-RADH"=-
                                  "MS-RADI"=-
                                  "MS-RADJ"=-
                                  "MS-RADK"=-
                                  "MS-RADL"=-
                                  "MS-RADM"=-
                                  "MS-RADN"=-
                                  "MS-RADO"=-
                                  "MS-RADP"=-
                                  "MS-RADQ"=-
                                  "MS-RADR"=-
                                  "MS-RADS"=-
                                  "MS-RADT"=-
                                  "MS-RADU"=-
                                  "MS-RADV"=-
                                  "MS-RADW"=-
                                  "MS-RADX"=-
                                  "MS-RADY"=-
                                  "MS-RADZ"=-
                                  " "=-
                                  "winrun.dll"=-
                                  "loader.exe"=-
                                  "recinfo49"=-
                                  "System"=-
                                  "System Updater Machine"=-
                                  "SpiderH"=-
                                  "winudp64.exe"=-
                                  "System12"=-
                                  "System64"=-
                                  "IMJPMIG8.2"=-
                                  "CARPService"=-
                                  "039.tmp"=-
                                  "userd"=-
                                  "nar"=-
                                  "MSKernel32"=-
                                  "WillPolo"=-
                                  "MyMP3"=-
                                  "FS6519"=-
                                  "Windows\SysRes.vbs"=-
                                  "SysRes"=-
                                  "Raila Odinga"=-
                                  "reginit"=-
                                  "lnternet Update"=-
                                  "GMOGLFEO"=-
                                  "WintelUpdate"=-
                                  "Pubnet"=-
                                  "antihost"=-

                                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]
                                  "System Updater Machine"=-
                                  "Win32DLL"=-
                                  "lnternet Update"=-

                                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
                                  " "=-

                                  [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RavAV]

                                  [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                  "kamsoft"=-
                                  "amva"=-
                                  "kava"=-
                                  "tava"=-
                                  "avpa"=-
                                  "internet_explorer"=-
                                  "anti-virus 2007"=-
                                  "Mp3 player"=-
                                  "kxvo"=-
                                  "EXPLORER.EXE"=-
                                  "wsctf.exe"=-
                                  "loader.exe"=-
                                  "jvvo"=-
                                  "taso"=-
                                  "Avg_AntiHost"=-
                                  "jvsoft"=-
                                  "tasoft"=-
                                  "SpiderH"=-
                                  "MsServer"=-
                                  "MSFox"=-
                                  "msn"=-
                                  "????r"=-
                                  "Windows Update"=-
                                  "Microsoft Debug Manager"=-
                                  "protect_autorun"=-
                                  "Le Petit Robert Hyperappel"=-
                                  "firewall 2008"=-
                                  " "=-

                                  [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
                                  " "=-

                                  [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
                                  "test"=-
                                  "Msn"=-
                                  "MsnHost"=-
                                  "MsnLoad"=-
                                  "MsnConvert"=-
                                  "MsnMessendger"=-
                                  "sys"=-

                                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
                                  "DefaultUserName"=-
                                  "LegalNoticeCaption"=-
                                  "LegalNoticeText"=-

                                  [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ActiveDesktop\NoChangingWallPaper]

                                  -------------------------------------------------------------------------------------------------------------

                                  Mises a jours du 5 decembre 2008

                                  >>>>>>in "All Drives"<<<<<<<<<

                                  6xdgw26.com
                                  6xig.com
                                  8386nac.com
                                  8e.com
                                  8u.com
                                  8uot.exe
                                  arun.exe
                                  asneg.com
                                  bpu.exe
                                  br1e.com
                                  cdwfql2v.com
                                  ceqfqp.bat
                                  cm0.com
                                  d1y36.com
                                  dh66ln.cmd
                                  dpu1.exe
                                  dyr2j6mv.exe
                                  ermvu8.cmd
                                  fblfnthuh.exe
                                  fn20.exe
                                  fufb6tq3.cmd
                                  g2o1n.exe
                                  gx.com h3hi1k3.exe
                                  i8.com
                                  ivcvknr.bat
                                  jv.exe
                                  kernel32.dll.vbs
                                  kg2v.com
                                  klp8j6i.com
                                  ktnquo.exe
                                  l1.cmd
                                  lp3c.bat
                                  m0g8sqx.cmd
                                  m6dqm2vd.exe
                                  m8wafly.com
                                  m9as2c.cmd
                                  MicrosoftPowerPoint.exe
                                  MSd30D.vbs
                                  msnmsgr_plus.exe
                                  ncyrf.bat
                                  ntdeIect.com
                                  ntnq.exe
                                  ntphyy.com
                                  NTsys.exe
                                  o6pq1n8.com
                                  okhr.exe
                                  ous.exe
                                  ox.cmd
                                  p1f6b.exe
                                  program.exe
                                  qeoc6sj.exe
                                  qwultj1.bat
                                  rcukd.cmd
                                  rdsfk.com
                                  rjx0.exe
                                  rqb0v2ot.bat
                                  scene.exe
                                  Server082.exe
                                  tigi.cmd
                                  uh31.exe
                                  uwlmj.com
                                  uxkktr.cmd
                                  vd91t29.exe
                                  w2qagd.com
                                  welcome.exe
                                  WindowsXP.exe
                                  winsys3.exe
                                  ypjq1.cmd

                                  .MGT_reg32.dll.vbs
                                  achitasin.dll.vbs
                                  autoupdate.dll.vbs
                                  bat32.txt
                                  happy.vbs
                                  ie.vbs
                                  killgodzilla.vbs
                                  maskrider.dll.vbs
                                  maskrider2001.vbs
                                  msiexec.dll.vbs
                                  MsUpdate.sys.vbs
                                  nohack.vbs
                                  RUNDLL64.dll.vbs
                                  setup.dll.vbs
                                  VBRuntime32.dll.vbs
                                  viva.dll.vbs
                                  Win32.dll.vbs
                                  winconfig.dll.vbs
                                  xepet.html
                                  xepet.txt

                                  >>>>>>in "Windows"<<<<<<<<<

                                  .MGT_reg32.dll.vbs
                                  achitasin.dll.vbs
                                  autoupdate.dll.vbs
                                  bat32.txt
                                  boot.ini
                                  happy.vbs
                                  ie.vbs
                                  killgodzilla.vbs
                                  maskrider.dll.vbs
                                  maskrider2001.vbs
                                  msiexec.dll.vbs
                                  MsUpdate.sys.vbs
                                  nohack.vbs
                                  RUNDLL64.dll.vbs
                                  setup.dll.vbs
                                  VBRuntime32.dll.vbs
                                  viva.dll.vbs
                                  Win32.dll.vbs
                                  winconfig.dll.vbs
                                  xepet.html
                                  xepet.txt

                                  >>>>>>in "Windows\system32"<<<<<<<<<

                                  kdyul.exe
                                  gasretyw0.dll
                                  gasretyw1.dll
                                  gasretyw2.dll
                                  gasretyw3.dll
                                  DC4491.DLL

                                  >>>>>>"Registry"<<<<<<<<<

                                  [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                  "Winboot"=-

                                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
                                  "UC"=-
                                  "r4n694-24y"=-
                                  "kernel32"=-
                                  "MSConfigs"=-
                                  "Microsoft"=-
                                  "MGT_reg"=-
                                  "Winboot"=-
                                  "Winamp"=-
                                  "Macromedia"=-
                                  "WINFIX"=-
                                  "winconfig"=-
                                  "Achitasin"=-
                                  "mcafee"=-
                                  "wscript32dll"=-
                                  "Batch32"=-
                                  "maskrider"=-
                                  "autoupdate"=-
                                  "KILLMS32DLL"=-
                                  "WinExpress"=-
                                  "WinDebugger"=-
                                  "C:\WINDOWS\system32\kdyul.exe"=-

                                  mises a jours du 6 Décembre 2008

                                  >>>>>>in "All Drives"<<<<<<<<<

                                  lgrncie.bat
                                  info.bat
                                  iqosrtk.bat
                                  0oyl662q.cmd
                                  eb.bat
                                  New Folder.exe
                                  Setup_ver1.1779.2.exe
                                  Setup_ver*.exe

                                  >>>>>>in "Windows"<<<<<<<<<

                                  SSVICHOSST.exe

                                  >>>>>>in "Windows\system32"<<<<<<<<<

                                  SSVICHOSST.exe
                                  kdxkt.exe
                                  kdjay.exe
                                  kdwzh.exe
                                  msiconf.exe

                                  >>>>>>"Registry"<<<<<<<<<

                                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
                                  "MsUpdate"=-
                                  "C:\WINDOWS\system32\kdxkt.exe"=-
                                  "C:\WINDOWS\system32\kdjay.exe"=-
                                  "C:\WINDOWS\system32\kdwzh.exe"=-

                                  [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
                                  "msiexec.exe"=-
                                  "Yahoo Messengger"=-

                                  mises a jours du 11 Décembre 2008

                                  >>>>>>in "All Drives"<<<<<<<<<

                                  Secret.exe
                                  hupxj.bat
                                  fphj6j31.bat
                                  shell.exe
                                  Installer.exe
                                  fvbk.exe
                                  snaoc9i.exe
                                  bt8vuaw.com
                                  wjlc.exe
                                  6fnlpetp.exe
                                  g8rruyw.exe
                                  o1.com
                                  yannh.cmd
                                  1t6yxlxx.cmd
                                  2h60k.cmd
                                  3rl3lqbq.bat
                                  ewatr.cmd
                                  Maradona.exe
                                  iw.bat
                                  m2nl.bat
                                  ov.cmd
                                  pnt.com
                                  t1ypkh.exe
                                  grgarevn.inf
                                  microsvn.inf
                                  refsanvn.inf
                                  Zidan vs Tito.exe
                                  desktop.exe
                                  omsirutnarg.exe
                                  Alisa.exe
                                  blazzers.exe
                                  burimi.exe
                                  nfd.exe
                                  repppp.exe
                                  wax.exe
                                  wny.exe
                                  msv2008.exe
                                  GETBOOTD.BAT
                                  tbm9.bat
                                  08dgu.com

                                  >>>>>>in "Windows\system32"<<<<<<<<<

                                  vamsoft.exe
                                  vbsdfe0.dll
                                  vbsdfe1.dll
                                  vbsdfe2.dll
                                  vbsdfe3.dll
                                  syx.exe

                                  >>>>>>"Registry"<<<<<<<<<

                                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
                                  "Host Process for Windows Services"=-
                                  "Advanced DHTML Enable"=-

                                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\runServices]
                                  "Host Process for Windows Services"=-

                                  [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
                                  "Runonce"=-
                                  "vamsoft"=-

                                  mises a jours du 17 Décembre 2008

                                  >>>>>>in "Windows"<<<<<<<<<

                                  pagefile.sys.vbs
                                  backinf.tab
                                  session.exe
                                  startup.vbs
                                  KAT.vbs
                                  explorar.vbs

                                  help\destrukto.vbs
                                  inf\destrukto.vbs
                                  registration\destrukto.vbs

                                  >>>>>>in "Windows\system32"<<<<<<<<<

                                  filekan.exe
                                  socksa.exe
                                  KAT.vbs
                                  destrukto.vbs
                                  security.vbs
                                  explorar.vbs
                                  destrukto.html

                                  >>>>>>in "Windows\system32\drivers"<<<<<<<<<

                                  Memoire Jeff EYEGHE.exe

                                  >>>>>>in "All Drives"<<<<<<<<<

                                  .\Recycled\Driveinfo.exe
                                  m9ma.exe
                                  JIM.exe
                                  iri.exe
                                  lol.exe
                                  mpsn.exe
                                  pagefile.sys.vbs
                                  al.xls.exe
                                  MDM.EXE
                                  RavManE.exe
                                  iexp1ore.exe
                                  msvcr71.dll
                                  BSserver
                                  FileKan.exe
                                  ASocksrv.exe
                                  algsrv.exe
                                  BACKINF.TAB
                                  ufdata2000.log
                                  twunk32.exe
                                  windhcp.ocx
                                  algssl.exe
                                  msfir80.exe
                                  msime80.exe
                                  destrukto.vbs
                                  Xsfr.exe
                                  Zser.exe
                                  THUMBS.DB.COM
                                  KAT.vbs
                                  startup.vbs
                                  THUMBS.DB
                                  MrHelloween.scr
                                  mig2.exe
                                  Perso_Stress.exe
                                  msfun80.exe
                                  IMJPMIG8.2
                                  msime82.exe
                                  IMJPMIG8.1
                                  algsrvs.exe
                                  pr2.exe
                                  sdfgh.exe
                                  p1y2.cmd h3.bat
                                  session.exe
                                  explorar.vbs
                                  security.vbs

                                  >>>>>>"Registry"<<<<<<<<<

                                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
                                  "MSRegInfo"=-
                                  "ASocksrv"=-
                                  "Startup"=-
                                  "Explorer"=-

                                  [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                  "BSserver"=-

                                  Mises a jours de 21 decembre 2008

                                  >>>>>>"Registry"<<<<<<<<<

                                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
                                  "zakariag"=-

                                  >>>>>>in "Windows"<<<<<<<<<

                                  csrss.exe

                                  >>>>>>in "Windows\system32"<<<<<<<<<

                                  GG.bat
                                  install.exe

                                  >>>>>>in "All Drives"<<<<<<<<<

                                  yt8a.exe
                                  log.exe
                                  iri.exe
                                  okea.exe
                                  system43.exe
                                  system9.exe
                                  xx.exe
                                  recycled\sirc32.exe
                                  iky.bat
                                  GuelmimG.bat

                                  Mises a jours de 23 decembre 2008

                                  >>>>>>in "Windows"<<<<<<<<<

                                  help.exe
                                  mg.exe

                                  >>>>>>in "Windows\system32"<<<<<<<<<

                                  kav320.dll
                                  kav321.dll
                                  kav322.dll
                                  mldmm.exe
                                  spooIsv.exe
                                  system.exe

                                  >>>>>>in "Temp files"<<<<<<<<<

                                  help.rar
                                  nodB.tmp

                                  >>>>>>in "appdata"<<<<<<<<<

                                  addon.dat
                                  CISxCC.tmp
                                  ISxCB.tmp
                                  ISx97.tmp

                                  >>>>>>in "All Drives"<<<<<<<<<

                                  MSd355.vbs
                                  xrdygg.bat
                                  MSd48F.vbs
                                  bold.log
                                  qthqdso.exe
                                  mguvbfr.exe
                                  kxhvehm.exe
                                  msvsc.exe
                                  2w.cmd
                                  x0.com
                                  u2.cmd
                                  je26200.com
                                  lkxcqdb.bat
                                  gr06t.cmd
                                  xfl3hx.exe
                                  1gk8ha.bat
                                  sucksa.exe

                                  >>>>>>"Registry"<<<<<<<<<

                                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]
                                  "mmsass"=-
                                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
                                  "mmsass"=-
                                  "Spooler SubSystem App"=-

                                  Mises a jours de 24 decembre 2008 ( Feliz Navidad )

                                  >>>>>>in "Windows"<<<<<<<<<

                                  system32.exe

                                  >>>>>>in "Windows\system32"<<<<<<<<<

                                  dse235rgd1.dll
                                  kavo.exe
                                  kavo0.dll
                                  kavo1.dll
                                  kavo2.dll
                                  kavo3.dll
                                  wedasgads0.dll
                                  wedasgads1.dll
                                  wedasgads2.dll
                                  wedasgads3.dll
                                  WS2Fix.exe
                                  VCCLSID.exe
                                  VACFix.exe
                                  swxcacls.exe
                                  swsc.exe
                                  swreg.exe
                                  SrchSTS.exe
                                  Process.exe
                                  o4Patch.exe
                                  IEDFix.exe
                                  IEDFix.C.exe
                                  dumphive.exe
                                  Agent.OMZ.Fix.exe
                                  404Fix.exe

                                  >>>>>>in "All Drives"<<<<<<<<<

                                  6j2j.com
                                  iok.exe
                                  MSd05E.vbs
                                  MSd329.vbs
                                  wi.com
                                  ab31.exe

                                  >>>>>>"Registry"<<<<<<<<<

                                  [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                  "EXPLORER.EXE"=-
                                  "wsctf.exe"=-

                                  Mises a jours du 27 Décembre 2008

                                  >>>>>>in "Windows"<<<<<<<<<

                                  admintxt.txt
                                  u.bat
                                  u.vbe
                                  s.vbe

                                  >>>>>>in "Windows\system32"<<<<<<<<<

                                  temp#01.exe
                                  dse235rgd0.dll
                                  dse235rgd2.dll
                                  dse235rgd3.dll

                                  >>>>>>in "Temp files"<<<<<<<<<

                                  pa.exe

                                  >>>>>>in "All Drives"<<<<<<<<<

                                  reps.exe
                                  bud3.bat
                                  sjqkci.cmd
                                  hehe.exe
                                  oskie.exe
                                  u.vbe
                                  Knight.exe
                                  sss.exe
                                  x6.bat
                                  sokeie.exe
                                  sucker.exe
                                  fhrqdpi.exe
                                  plugin.exe
                                  s.vbe

                                  >>>>>>"Registry"<<<<<<<<<

                                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                  "vbe"=-

                                  Mises a jours du 09 Janvier 2009

                                  >>>>>>in "Windows"<<<<<<<<<

                                  wintask.exe
                                  svcwroot.exe
                                  smms.exe
                                  inf\csrss.exe
                                  inf\diskini.xp
                                  smms.bat
                                  k.txt

                                  >>>>>>in "Windows\system32"<<<<<<<<<

                                  kav323.dll
                                  blastclnnn.exe
                                  Bitkv2.dll
                                  ahtn.htm
                                  kdjpf.exe
                                  kdind.exe
                                  warning.gif
                                  jjj.exe
                                  frmwrk32.exe
                                  ciuytr3.dll
                                  ciuytr2.dll
                                  ciuytr1.dll
                                  ciuytr0.dll

                                  >>>>>>in "Windows\system32\Drivers"<<<<<<<<<

                                  av.exe
                                  RACHIDA.exe

                                  >>>>>>in "Temp files"<<<<<<<<<

                                  a3a4_appcompat.txt
                                  1AFC3.dmp

                                  >>>>>>in "Application Data"<<<<<<<<<

                                  autorun.inf
                                  gadcom\gadcom.exe
                                  gadcom

                                  >>>>>>in "All Drives"<<<<<<<<<

                                  e8kj.exe
                                  vfjc8mxm.exe
                                  iqe68o.bat
                                  fzqxyrlpa.exe
                                  Taskmgr.exe
                                  FullHouse
                                  Config\smss.exe
                                  Kurdish.exe
                                  desktop.dll

                                  escro.exe
                                  gdgd.exe
                                  ipyrs.exe
                                  spoolsn.exe
                                  300y.cmd
                                  cb.bat
                                  riky.exe
                                  VirusRemoval.vbs
                                  Pagefi1e.sys
                                  rox.exe
                                  yhiqadw.exe
                                  p2hhr.bat
                                  SCVHOST.exe
                                  yuqpba.exe
                                  vmsavzvx.exe
                                  8de.bat
                                  frslsryk.exe
                                  yb12j.cmd
                                  xcisvxl.com
                                  wqesvxa.exe
                                  inqfnq.exe
                                  qopitm.exe
                                  sjpj.exe
                                  vhmdq.exe
                                  RECYCLER\Lock Folder.exe
                                  1sertc.exe
                                  r8.bat
                                  knupkb.com

                                  >>>>>>"Registry"<<<<<<<<<

                                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                  "win32dll"=-
                                  "Framework Windows"=-
                                  "C:\WINDOWS\system32\kdjpf.exe"=-
                                  "C:\WINDOWS\system32\kdind.exe"=-
                                  "wintask"=-
                                  "MSN"=-
                                  "zzzHPSETUP"=-
                                  "I downloaded pirated Software from P2P and now I post my Hijack log whining"=-
                                  "Proyecto1"=-
                                  "svchost"=-

                                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
                                  "autorun"=-

                                  [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                  "Windows"=-
                                  "Cognac"=-

                                  [-HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\NoChangingWallpaper]
                                  [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\activedesktop\NoChangingWallpaper]
                                  [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetActiveDesktop]
                                  [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoActiveDesktopChanges]
                                  [-HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetActiveDesktop]
                                  [-HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoActiveDesktopChanges]

                                  [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explore\Run]
                                  "Manager Task"=-
                                  0
                                  1. non il date du 2 decembre

                                    renvoie-moi un nouveau log de rsit

                                    0
                                    • 1
                                    • 2