Rapport Findykill à analyser - Page 2

Résolu
  1. Contributeur sécurité
    Bonjour,

    non, je te le laisse.

    Je voulais seulement que tu saches.
    0
    1. Bonjour Destrio5,

      j'ai fait tt ce k tu m'as demande de faire. qu'est ce k j peu faire apres

      merci bien
      0
      1. Modérateur
        Réessaie cette manip' :

        --> Télécharge Random's System Information Tool (RSIT) (par random/random) sur ton Bureau.

        --> Double-clique sur RSIT.exe afin de lancer le programme.
        (Sous Vista, il faut cliquer droit sur RSIT.exe et choisir Exécuter en tant qu'administrateur)

        --> Clique sur Continue à l'écran Disclaimer.

        --> Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.

        --> Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront. Poste le contenu de log.txt (c'est celui qui apparaît à l'écran) ainsi que de info.txt (que tu verras dans la barre des tâches).

        Note : les rapports sont sauvegardés dans le dossier C:\rsit.
        0
        1. Bonjour

          log.txt

          Logfile of random's system information tool 1.05 (written by random/random)
          Run by Ahmed at 2009-03-04 07:17:14
          Microsoft Windows XP Édition familiale Service Pack 3
          System drive C: has 39 GB (41%) free of 95 GB
          Total RAM: 2046 MB (58% free)

          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 07:17:23, on 04/03/2009
          Platform: Windows XP SP3 (WinNT 5.01.2600)
          MSIE: Internet Explorer v7.00 (7.00.6000.16791)
          Boot mode: Normal

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\Ati2evxx.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
          C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
          C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
          C:\WINDOWS\system32\spoolsv.exe
          C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
          C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
          C:\WINDOWS\system32\Ati2evxx.exe
          C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\Explorer.EXE
          C:\Program Files\Toshiba\TOSHIBA Applet\TAPPSRV.exe
          C:\PROGRA~1\AVG\AVG8\avgam.exe
          C:\PROGRA~1\AVG\AVG8\avgrsx.exe
          C:\PROGRA~1\AVG\AVG8\avgnsx.exe
          C:\WINDOWS\system32\TDispVol.exe
          C:\WINDOWS\System32\DLA\DLACTRLW.EXE
          C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
          C:\Program Files\TOSHIBA\Utilitaire de zoom TOSHIBA\SmoothView.exe
          C:\Program Files\TOSHIBA\Tvs\TvsTray.exe
          C:\WINDOWS\system32\TPSMain.exe
          C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
          C:\Program Files\TOSHIBA\Commandes TOSHIBA\TFncKy.exe
          C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
          C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
          C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
          C:\WINDOWS\AGRSMMSG.exe
          C:\WINDOWS\PixArt\PAC7311\Monitor.exe
          C:\Program Files\Synaptics\SynTP\Toshiba.exe
          C:\PROGRA~1\AVG\AVG8\avgtray.exe
          C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
          C:\WINDOWS\system32\ctfmon.exe
          C:\Program Files\Internet Download Manager\IDMan.exe
          C:\WINDOWS\system32\TPSBattM.exe
          C:\Program Files\Skype\Phone\Skype.exe
          C:\Program Files\Windows Live\Messenger\msnmsgr.exe
          C:\Program Files\Internet Download Manager\IEMonitor.exe
          C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
          C:\Program Files\Messenger\msmsgs.exe
          C:\Program Files\Fichiers communs\Ahead\lib\NMBgMonitor.exe
          C:\Program Files\Skype\Plugin Manager\skypePM.exe
          C:\Program Files\Windows Live\Contacts\wlcomm.exe
          C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
          C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
          C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
          C:\Program Files\Mozilla Firefox\firefox.exe
          C:\Documents and Settings\Ahmed\Bureau\virus_softwares\RSIT.exe
          C:\Program Files\Trend Micro\HijackThis\Ahmed.exe

          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
          R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://support.norton.com/sp/fr/fr/home/current/solutions/kb20090121104844EN?abproduct=SymNRT&abversion=2009.0.0.41&build=Symantec&ced=true&entsrc=CED_pubweb&error=0&module=2009&src=_mi
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
          O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
          O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
          O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
          O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
          O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
          O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
          O4 - HKLM\..\Run: [TDispVol] TDispVol.exe
          O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
          O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
          O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\Utilitaire de zoom TOSHIBA\SmoothView.exe
          O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
          O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
          O4 - HKLM\..\Run: [Tvs] C:\Program Files\TOSHIBA\Tvs\TvsTray.exe
          O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
          O4 - HKLM\..\Run: [THotkey] C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
          O4 - HKLM\..\Run: [TFncKy] TFncKy.exe
          O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
          O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
          O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
          O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
          O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
          O4 - HKLM\..\Run: [Monitor] C:\WINDOWS\PixArt\PAC7311\Monitor.exe
          O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
          O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
          O4 - HKCU\..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot
          O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
          O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
          O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
          O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
          O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\lib\NMBgMonitor.exe"
          O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
          O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
          O8 - Extra context menu item: Download all links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm
          O8 - Extra context menu item: Download FLV video content with IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm
          O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm
          O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
          O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
          O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
          O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
          O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
          O17 - HKLM\System\CCS\Services\Tcpip\..\{F34E8A4D-DA5A-4E87-9352-87D82CF4FE91}: NameServer = 193.95.66.10
          O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
          O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
          O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
          O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
          O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
          O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
          O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
          O23 - Service: Google Desktop Manager 5.8.809.23506 (GoogleDesktopManager-092308-165331) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
          O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
          O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
          O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
          O23 - Service: TOSHIBA Application Service (TAPPSRV) - TOSHIBA Corp. - C:\Program Files\Toshiba\TOSHIBA Applet\TAPPSRV.exe
          0
          1. Modérateur
            Peux-tu me poster le rapport info qui se trouve dans C:\rsit ?

            ---> Désactive ton antivirus le temps de la manipulation car OTMoveIt3 est détecté comme une infection à tort.

            ---> Télécharge OTMoveIt3 (OldTimer) sur ton Bureau.

            ---> Double-clique sur OTMoveIt3.exe afin de le lancer.

            ---> Copie (Ctrl+C) le texte suivant ci-dessous :

            :processes
            explorer.exe

            :reg
            [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WindowsTelephony]
            [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WindowsTelephony]

            :commands
            [purity]
            [emptytemp]
            [reboot]

            ---> Colle (Ctrl+V) le texte précédemment copié dans le cadre Paste Instructions for Items to be Moved.

            ---> Clique maintenant sur le bouton MoveIt! puis ferme OTMoveIt3.

            Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
            Accepte en cliquant sur YES.

            ---> Poste le rapport situé dans ce dossier : C:\_OTMoveIt\MovedFiles\
            Le nom du rapport correspond au moment de sa création : date_heure.log
            0
            1. bonjour,

              voici info.txt en attendant k j effectue l'autre procedure

              info.txt logfile of random's system information tool 1.05 2009-03-04 07:17:25

              ======Uninstall list======

              -->C:\Program Files\Nero\Nero 7\nero\uninstall\UNNERO.exe /UNINSTALL
              -->C:\WINDOWS\IsUn040c.exe -fC:\WINDOWS\orun32.isu
              -->C:\WINDOWS\system32\\MSIEXEC.EXE /x {1206EF92-2E83-4859-ACCB-2048C3CB7DA6}
              -->C:\WINDOWS\system32\\MSIEXEC.EXE /x {9541FED0-327F-4df0-8B96-EF57EF622F19}
              -->C:\WINDOWS\UNNeroBackItUp.exe /UNINSTALL
              -->C:\WINDOWS\UNNeroMediaHome.exe /UNINSTALL
              -->C:\WINDOWS\UNNeroShowTime.exe /UNINSTALL
              -->C:\WINDOWS\UNNeroVision.exe /UNINSTALL
              -->C:\WINDOWS\UNRecode.exe /UNINSTALL
              -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
              2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {BEE75E01-DD3F-4D5F-B96C-609E6538D419}
              2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0015-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
              2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0016-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
              2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0018-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
              2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0019-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
              2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001A-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
              2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001B-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
              2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0401-0000-0000000FF1CE} /uninstall {5A2F65A4-808F-4A1E-973E-92E17824982D}
              2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0407-0000-0000000FF1CE} /uninstall {2AB528A5-BB1B-4EBE-8E51-AD0C4CD33CA9}
              2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {3EC77D26-799B-4CD8-914F-C1565E796173}
              2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-040C-0000-0000000FF1CE} /uninstall {430971B1-C31E-45DA-81E0-72C095BAB72C}
              2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0413-0000-0000000FF1CE} /uninstall {B3F4DC34-7F60-4B7C-A79F-1C13012D99D4}
              2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0C0A-0000-0000000FF1CE} /uninstall {F7A31780-33C4-4E39-951A-5EC9B91D7BF1}
              2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0044-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
              Ad-Aware-->"C:\Documents and Settings\All Users\Application Data\{2BAE6915-8510-4B9F-B498-02DA86258AA0}\Ad-AwareAE.exe" REMOVE=TRUE MODIFY=FALSE
              Ad-Aware-->C:\Documents and Settings\All Users\Application Data\{2BAE6915-8510-4B9F-B498-02DA86258AA0}\Ad-AwareAE.exe
              Adobe Flash Player Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
              Adobe Reader 7.0.5 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A70500000002}
              Adobe Reader Chinese Simplified Fonts-->MsiExec.exe /I{AC76BA86-7AD7-2447-0000-705000000001}
              Adobe Reader Japanese Fonts-->MsiExec.exe /I{AC76BA86-7AD7-5760-0000-705000000001}
              Archiveur WinRAR-->C:\Program Files\WinRAR\uninstall.exe
              Assist TOSHIBA-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{12B3A009-A080-4619-9A2A-C6DB151D8D67}\Setup.exe" -l0x40c
              Assistant de connexion Windows Live-->MsiExec.exe /I{DCE8CD14-FBF5-4464-B9A4-E18E473546C7}
              ATI - Utilitaire de désinstallation du logiciel-->C:\Program Files\ATI Technologies\UninstallAll\AtiCimUn.exe
              ATI Catalyst Control Center-->MsiExec.exe /I{06C71F80-0E30-4E2C-878F-8502AB5AE3BE}
              ATI Display Driver-->rundll32 C:\WINDOWS\system32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
              AVG 8.0-->C:\Program Files\AVG\AVG8\setup.exe /UNINSTALL
              Bluetooth Stack for Windows by Toshiba-->MsiExec.exe /X{CEBB6BFB-D708-4F99-A633-BC2600E01EF6}
              CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
              Choice Guard-->MsiExec.exe /I{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}
              Commandes TOSHIBA-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A6690C0E-B96E-4F0F-A8EB-D5B332454AC6}\Setup.exe" -l0x40c UNINSTALL
              Correctif pour Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
              Formatage de carte mémoire SD TOSHIBA-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{48CF9A66-5F03-4025-ABD0-B3A3FA095A59}\Setup.exe" -l0x40c
              Gestion d'énergie TOSHIBA-->C:\WINDOWS\IsUn040c.exe -f"C:\Program Files\TOSHIBA\Power Saver\Uninst.isu" -c"C:\WINDOWS\system32\TPSDel.dll"
              Google Desktop-->C:\Program Files\Google\Google Desktop Search\GoogleDesktopSetup.exe -uninstall
              High Definition Audio Driver Package - KB888111-->"C:\WINDOWS\$NtUninstallKB888111WXPSP2$\spuninst\spuninst.exe"
              HijackThis 2.0.2-->"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
              Installation Windows Live-->C:\Program Files\Windows Live\Installer\wlarp.exe
              Installation Windows Live-->MsiExec.exe /I{7370DF47-B4F9-4279-BFC3-3F09919F720D}
              Intel(R) PRO Network Connections Drivers-->Prounstl.exe
              Internet Download Manager-->C:\Program Files\Internet Download Manager\Uninstall.exe
              InterVideo WinDVD Creator 2-->"C:\Program Files\InstallShield Installation Information\{2FCE4FC5-6930-40E7-A4F1-F862207424EF}\setup.exe" REMOVEALL
              InterVideo WinDVD for TOSHIBA-->"C:\Program Files\InstallShield Installation Information\{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}\setup.exe" REMOVEALL
              J2SE Runtime Environment 5.0 Update 4-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150040}
              Java DB 10.3.1.4-->MsiExec.exe /X{CD49361E-3FE6-457E-90A1-9C59E29B5D02}
              Java(TM) 6 Update 6-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160060}
              Java(TM) SE Development Kit 6 Update 6-->MsiExec.exe /I{32A3A4F4-B792-11D6-A78A-00B0D0160060}
              jetAudio Basic-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{DF8195AF-8E6F-4487-A0EE-196F7E3F4B8A}\setup.exe" -l0xc0c -removeonly
              Kaspersky Online Scanner-->C:\WINDOWS\system32\KASPER~1\KASPER~1\kavuninstall.exe
              Kaspersky On-line Scanner-->C:\WINDOWS\system32\KASPER~1\KASPER~1\kavuninstall.exe
              K-Lite Codec Pack 3.5.0 Full-->"C:\Program Files\K-Lite Codec Pack\unins000.exe"
              Lecteur Windows Media 10-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
              Logiciel Intel(R) PROSet/Wireless-->C:\WINDOWS\Installer\iProInst.exe
              Macromedia Flash Player-->MsiExec.exe /X{0456ebd7-5f67-4ab6-852e-63781e3f389c}
              Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
              Manuels TOSHIBA-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3EB6332B-AF02-457C-A31C-835458C5B48B}\setup.exe" -l0x40c -removeonly
              mCore-->MsiExec.exe /I{E81667C6-2856-46D6-ABEA-6A2F42166779}
              mDrWiFi-->MsiExec.exe /I{F6090A17-0967-4A8A-B3C3-422A1B514D49}
              mHelp-->MsiExec.exe /I{8C6BB412-D3A8-4AAE-A01B-35B681789D68}
              Microsoft .NET Framework 1.1 French Language Pack-->MsiExec.exe /X{9A394342-4A68-4EBA-85A6-55B559F4E700}
              Microsoft .NET Framework 1.1 Hotfix (KB928366)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"
              Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
              Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
              Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
              Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
              Microsoft Office Access MUI (French) 2007-->MsiExec.exe /X{90120000-0015-040C-0000-0000000FF1CE}
              Microsoft Office Excel MUI (French) 2007-->MsiExec.exe /X{90120000-0016-040C-0000-0000000FF1CE}
              Microsoft Office InfoPath MUI (French) 2007-->MsiExec.exe /X{90120000-0044-040C-0000-0000000FF1CE}
              Microsoft Office Language Pack 2007 Service Pack 1 (SP1)-->msiexec /package {90120000-006E-040C-0000-0000000FF1CE} /uninstall {EC50B538-CBE1-42E6-B7FE-87AA540AADFB}
              Microsoft Office OneNote 2003-->MsiExec.exe /I{91A1040C-6000-11D3-8CFE-0150048383C9}
              Microsoft Office Outlook MUI (French) 2007-->MsiExec.exe /X{90120000-001A-040C-0000-0000000FF1CE}
              Microsoft Office PowerPoint MUI (French) 2007-->MsiExec.exe /X{90120000-0018-040C-0000-0000000FF1CE}
              Microsoft Office Professional Plus 2007-->"C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall PROPLUS /dll OSETUP.DLL
              Microsoft Office Professional Plus 2007-->MsiExec.exe /X{90120000-0011-0000-0000-0000000FF1CE}
              Microsoft Office Proof (Arabic) 2007-->MsiExec.exe /X{90120000-001F-0401-0000-0000000FF1CE}
              Microsoft Office Proof (Dutch) 2007-->MsiExec.exe /X{90120000-001F-0413-0000-0000000FF1CE}
              Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
              Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
              Microsoft Office Proof (German) 2007-->MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}
              Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
              Microsoft Office Proofing (French) 2007-->MsiExec.exe /X{90120000-002C-040C-0000-0000000FF1CE}
              Microsoft Office Publisher MUI (French) 2007-->MsiExec.exe /X{90120000-0019-040C-0000-0000000FF1CE}
              Microsoft Office Shared MUI (French) 2007-->MsiExec.exe /X{90120000-006E-040C-0000-0000000FF1CE}
              Microsoft Office Word MUI (French) 2007-->MsiExec.exe /X{90120000-001B-040C-0000-0000000FF1CE}
              Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
              Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
              Mise à jour de sécurité pour Lecteur Windows Media (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Lecteur Windows Media 10 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP10$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Step by Step Interactive Training (KB898458)-->"C:\WINDOWS\$NtUninstallKB898458$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Step by Step Interactive Training (KB923723)-->"C:\WINDOWS\$NtUninstallKB923723$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows Internet Explorer 7 (KB938127-v2)-->"C:\WINDOWS\ie7updates\KB938127-v2-IE7\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows Internet Explorer 7 (KB956390)-->"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows Internet Explorer 7 (KB961260)-->"C:\WINDOWS\ie7updates\KB961260-IE7\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB954211)-->"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB954459)-->"C:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB954600)-->"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB956391)-->"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB956841)-->"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB958215)-->"C:\WINDOWS\$NtUninstallKB958215$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB958687)-->"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB960714)-->"C:\WINDOWS\$NtUninstallKB960714$\spuninst\spuninst.exe"
              Mise à jour de sécurité pour Windows XP (KB960715)-->"C:\WINDOWS\$NtUninstallKB960715$\spuninst\spuninst.exe"
              Mise à jour pour Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
              Mise à jour pour Windows XP (KB955839)-->"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
              Mise à jour pour Windows XP (KB967715)-->"C:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe"
              mIWA-->MsiExec.exe /I{3E9D596A-61D4-4239-BD19-2DB984D2A16F}
              mLogView-->MsiExec.exe /I{0E2B0B41-7E08-4F9F-B21F-41C4133F43B7}
              mMHouse-->MsiExec.exe /I{F0BFC7EF-9CF8-44EE-91B0-158884CD87C5}
              Mozilla Firefox (3.0.6)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
              mPfMgr-->MsiExec.exe /I{8B928BA1-EDEC-4227-A2DA-DD83026C36F5}
              mPfWiz-->MsiExec.exe /I{90B0D222-8C21-4B35-9262-53B042F18AF9}
              mProSafe-->MsiExec.exe /I{23FB368F-1399-4EAC-817C-4B83ECBE3D83}
              MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
              MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
              mWlsSafe-->MsiExec.exe /I{FCA651F3-5BDA-4DDA-9E4A-5D87D6914CC4}
              mXML-->MsiExec.exe /I{9CC89556-3578-48DD-8408-04E66EBEF401}
              mZConfig-->MsiExec.exe /I{94658027-9F16-4509-BBD7-A59FE57C3023}
              Navilog1 3.7.5-->"C:\Program Files\Navilog1\unins000.exe"
              Nero 7 Demo-->MsiExec.exe /I{C93369CB-B4E9-E095-9289-E6B5AE941036}
              Outil de diagnostic PC TOSHIBA-->C:\WINDOWS\IsUn040c.exe -f"C:\Program Files\TOSHIBA\PCDiag\Uninst.isu"
              Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
              PDFCreator-->MsiExec.exe /I{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}
              R for Windows 2.8.1-->"C:\Program Files\R\R-2.8.1\unins000.exe"
              Real Alternative 1.9.0-->"C:\Program Files\Real Alternative\unins000.exe"
              Realtek High Definition Audio Driver-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\Setup.exe" -l0x40c -removeonly
              Réducteur de bruit lect. CD/DVD-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9FE35071-CAB2-4E79-93E7-BFC6A2DC5C5D}\Setup.exe" -l0x40c
              Security Update for 2007 Microsoft Office System (KB951550)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {B243E9A5-ED77-4F1B-B338-2486FD82DC85}
              Security Update for 2007 Microsoft Office System (KB951944)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {797AE457-BA17-4BBC-B501-25FB3A0103C7}
              Security Update for 2007 Microsoft Office System (KB958439)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {6491B8AA-D11C-4648-A461-6234B31EB7E2}
              Security Update for CAPICOM (KB931906)-->MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
              Security Update for CAPICOM (KB931906)-->MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
              Security Update for Microsoft Office Excel 2007 (KB958437)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {648FC016-2D6B-4A16-8D87-404533642F4B}
              Security Update for Microsoft Office PowerPoint 2007 (KB951338)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {558B709B-821B-4FC5-90FC-9A8890641E77}
              Security Update for Microsoft Office Publisher 2007 (KB950114)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {F9C3CDBA-1F00-4D4D-959D-75C9D3ACDD85}
              Security Update for Microsoft Office system 2007 (KB954326)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {5F7F6FFF-395D-480E-8450-64F385D82C5F}
              Security Update for Microsoft Office system 2007 (KB956828)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {885E081B-72BD-4E76-8E98-30B4BE468FAC}
              Security Update for Microsoft Office Word 2007 (KB956358)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {4551666D-0FD6-4C69-8A81-1C6F2E64517C}
              Segoe UI-->MsiExec.exe /I{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}
              Skype™ 3.8-->MsiExec.exe /X{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}
              Son virtuel TOSHIBA-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{8B12BA86-ADAC-4BA6-B441-FFC591087252}\Setup.exe" /uninstall
              Sonic DLA-->MsiExec.exe /I{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}
              Sonic RecordNow!-->MsiExec.exe /I{9541FED0-327F-4DF0-8B96-EF57EF622F19}
              SuperCopier2-->"C:\Program Files\SuperCopier2\SC2Uninst.exe"
              Synaptics Pointing Device Driver-->rundll32.exe "C:\Program Files\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall
              Texas Instruments PCIxx21/x515/xx12 drivers.-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{4497AFF6-98C4-4F49-B073-F48F42BCBF9E} /l1036
              TOSHIBA ConfigFree-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BDD83DC9-BEE9-4654-A5DA-CC46C250088D}\setup.exe" -l0x40c UNINSTALL
              TOSHIBA Hotkey Utility-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{64DD71BC-3109-4C88-9AD3-D5422644B722}\setup.exe" -l0x40c
              TOSHIBA Software Modem-->Tosmreg -U
              TOSHIBA TouchPad ON/Off Utility-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{69BE47C2-36FE-4397-8199-85D8EAE69982}\setup.exe" -l0x40c
              TOSHIBA Utilities-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{78C68CB9-3DF5-44F3-AB9D-FA305C5EB85C}\setup.exe" -l0x40c
              Update for Microsoft Office Outlook 2007 (KB952142)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {4AD3A076-427C-491F-A5B7-7D1DE788A756}
              Update for Office 2007 (KB946691)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {A420F522-7395-4872-9882-C591B4B92278}
              Update for Outlook 2007 Junk Email Filter (kb959634)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {50C77E2F-5C1C-467D-9BC8-3CA07D28C9F2}
              Utilitaire de zoom TOSHIBA-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{64212898-097F-4F3F-AECA-6D34A7EF82DF}\Setup.exe" -l0x40c
              VGA USB Camera-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{1DDF840B-A50A-491E-BF44-6D6964C451A8}\Setup.exe" -l0x40c
              VideoLAN VLC media player 0.8.6d-->C:\Program Files\VideoLAN\VLC\uninstall.exe
              Visual C++ 2008 x86 Runtime - (v9.0.30729)-->MsiExec.exe /X{F333A33D-125C-32A2-8DCE-5C5D14231E27}
              Visual C++ 2008 x86 Runtime - v9.0.30729.01-->C:\WINDOWS\system32\msiexec.exe /x {F333A33D-125C-32A2-8DCE-5C5D14231E27} /qb+ REBOOTPROMPT=""
              VobSub v2.23 (Remove Only)-->"C:\Program Files\Gabest\VobSub\uninstall.exe"
              Windows Internet Explorer 7-->"C:\WINDOWS\ie7\spuninst\spuninst.exe"
              Windows Live Call-->MsiExec.exe /I{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}
              Windows Live Communications Platform-->MsiExec.exe /I{3B4E636E-9D65-4D67-BA61-189800823F52}
              Windows Live Messenger-->MsiExec.exe /X{059C042E-796A-4ACC-A81A-ECC2010BB78C}
              Windows Media Format Runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
              Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"

              =====HijackThis Backups=====

              O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)

              ======Security center information======

              AV: AVG Anti-Virus
              AV: Lavasoft Ad-Watch Live! AntiVirus

              System event log

              Computer Name: MIDOO
              Event Code: 7036
              Message: Le service Carte de performance WMI est entré dans l'état : arrêté.

              Record Number: 2361
              Source Name: Service Control Manager
              Time Written: 20090226073204.000000+060
              Event Type: Informations
              User:

              Computer Name: MIDOO
              Event Code: 18
              Message: Prêt pour l'installation : les mises à jour suivantes ont été téléchargées et sont prêtes pour l'installation. L'installation de ces mises à jour est actuellement planifiée pour le ?jeudi ?26 ?février ?2009 à 20:00 :
              - Mise à jour de Microsoft Silverlight (KB960353)

              Record Number: 2360
              Source Name: Windows Update Agent
              Time Written: 20090226073019.000000+060
              Event Type: Informations
              User:

              Computer Name: MIDOO
              Event Code: 7035
              Message: Un contrôle Démarrer a correctement été envoyé au service Carte de performance WMI.

              Record Number: 2359
              Source Name: Service Control Manager
              Time Written: 20090226072959.000000+060
              Event Type: Informations
              User: MIDOO\Ahmed

              Computer Name: MIDOO
              Event Code: 7036
              Message: Le service Carte de performance WMI est entré dans l'état : en cours d'exécution.

              Record Number: 2358
              Source Name: Service Control Manager
              Time Written: 20090226072959.000000+060
              Event Type: Informations
              User:

              Computer Name: MIDOO
              Event Code: 4201
              Message: Le système a détecté que la carte réseau \DEVICE\TCPIP_{2D021112-4044-45E6-BFC3-EA86012989AE} était connectée au réseau,
              et a lancé une opération normale sur la carte réseau.

              Record Number: 2357
              Source Name: Tcpip
              Time Written: 20090226072903.000000+060
              Event Type: Informations
              User:

              Application event log

              Computer Name: MIDOO
              Event Code: 4097
              Message: L'application, C:\WINDOWS\system32\wuauclt.exe, a généré une erreur d'application
              L'erreur s'est produite le 02/04/2009 à 00:37:11.765
              L'exception générée était c0000005 à l'adresse 7C883001 (kernel32)

              Record Number: 212
              Source Name: DrWatson
              Time Written: 20090204003711.000000+060
              Event Type: Informations
              User:

              Computer Name: MIDOO
              Event Code: 4097
              Message: L'application, C:\Program Files\Skype\Phone\Skype.exe, a généré une erreur d'application
              L'erreur s'est produite le 02/04/2009 à 00:37:11.187
              L'exception générée était c0000005 à l'adresse 7C88300C (kernel32)

              Record Number: 211
              Source Name: DrWatson
              Time Written: 20090204003711.000000+060
              Event Type: Informations
              User:

              Computer Name: MIDOO
              Event Code: 1000
              Message: Application défaillante jusched.exe, version 6.0.60.2, module défaillant kernel32.dll, version 5.1.2600.2180, adresse de défaillance 0x0008300c.

              Record Number: 210
              Source Name: Application Error
              Time Written: 20090204003710.000000+060
              Event Type: erreur
              User:

              Computer Name: MIDOO
              Event Code: 4097
              Message: L'application, C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe, a généré une erreur d'application
              L'erreur s'est produite le 02/04/2009 à 00:37:10.265
              L'exception générée était c0000005 à l'adresse 7C883001 (kernel32)

              Record Number: 209
              Source Name: DrWatson
              Time Written: 20090204003710.000000+060
              Event Type: Informations
              User:

              Computer Name: MIDOO
              Event Code: 1002
              Message: L'environnement s'est arrêté de façon inattendue et Explorer.exe a redémarré.

              Record Number: 208
              Source Name: Winlogon
              Time Written: 20090204003710.000000+060
              Event Type: Informations
              User:

              ======Environment variables======

              "ComSpec"=%SystemRoot%\system32\cmd.exe
              "Path"=%systemroot%\system32;%systemroot%;%systemroot%\system32\wbem;C:\Program Files\ATI Technologies\ATI.ACE
              "windir"=%SystemRoot%
              "FP_NO_HOST_CHECK"=NO
              "OS"=Windows_NT
              "PROCESSOR_ARCHITECTURE"=x86
              "PROCESSOR_LEVEL"=6
              "PROCESSOR_IDENTIFIER"=x86 Family 6 Model 14 Stepping 8, GenuineIntel
              "PROCESSOR_REVISION"=0e08
              "NUMBER_OF_PROCESSORS"=2
              "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
              "TEMP"=%SystemRoot%\TEMP
              "TMP"=%SystemRoot%\TEMP

              -----------------EOF-----------------
              0
              1. Voici le rapport

                ========== PROCESSES ==========
                Process explorer.exe killed successfully.
                ========== REGISTRY ==========
                Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WindowsTelephony\\ deleted successfully.
                Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WindowsTelephony\\ deleted successfully.
                ========== COMMANDS ==========
                File delete failed. C:\DOCUME~1\Ahmed\LOCALS~1\Temp\etilqs_nGDUevtvmt6PftNvJZFS scheduled to be deleted on reboot.
                File delete failed. C:\DOCUME~1\Ahmed\LOCALS~1\Temp\Perflib_Perfdata_808.dat scheduled to be deleted on reboot.
                File delete failed. C:\DOCUME~1\Ahmed\LOCALS~1\Temp\Perflib_Perfdata_c80.dat scheduled to be deleted on reboot.
                File delete failed. C:\DOCUME~1\Ahmed\LOCALS~1\Temp\Perflib_Perfdata_cb4.dat scheduled to be deleted on reboot.
                File delete failed. C:\DOCUME~1\Ahmed\LOCALS~1\Temp\~DF3DBD.tmp scheduled to be deleted on reboot.
                File delete failed. C:\DOCUME~1\Ahmed\LOCALS~1\Temp\~DFF51E.tmp scheduled to be deleted on reboot.
                User's Temp folder emptied.
                User's Temporary Internet Files folder emptied.
                User's Internet Explorer cache folder emptied.
                File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
                File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat scheduled to be deleted on reboot.
                File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat scheduled to be deleted on reboot.
                Local Service Temp folder emptied.
                File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
                Local Service Temporary Internet Files folder emptied.
                File delete failed. C:\WINDOWS\temp\24e50817-74f0-41fe-9da0-a459e863e829.tmp scheduled to be deleted on reboot.
                File delete failed. C:\WINDOWS\temp\2d40f24c-5e75-4cf5-89c3-abe0e9838348.tmp scheduled to be deleted on reboot.
                File delete failed. C:\WINDOWS\temp\31242217-1e45-4e26-b4f9-4f1229b3d88d.tmp scheduled to be deleted on reboot.
                File delete failed. C:\WINDOWS\temp\338f4769-1316-4ab5-8389-d5cc4102d4cc.tmp scheduled to be deleted on reboot.
                File delete failed. C:\WINDOWS\temp\39b9f349-adfe-4fce-a059-cb0fe91a39fa.tmp scheduled to be deleted on reboot.
                File delete failed. C:\WINDOWS\temp\3ed87bac-7dd1-40f2-be14-93860a580d7e.tmp scheduled to be deleted on reboot.
                File delete failed. C:\WINDOWS\temp\43c62500-7e0a-442a-aac4-95f25dc8f4d8.tmp scheduled to be deleted on reboot.
                File delete failed. C:\WINDOWS\temp\44f4071a-f06f-4b11-b2f5-e55b19a81241.tmp scheduled to be deleted on reboot.
                File delete failed. C:\WINDOWS\temp\4efa2f12-557d-4207-8577-0ef2be9e2741.tmp scheduled to be deleted on reboot.
                File delete failed. C:\WINDOWS\temp\666f4c3e-7982-4a16-9872-f2bc304acc42.tmp scheduled to be deleted on reboot.
                File delete failed. C:\WINDOWS\temp\6724a2f6-bf89-4bf2-8257-7f813c377133.tmp scheduled to be deleted on reboot.
                File delete failed. C:\WINDOWS\temp\6ea3054b-e3cd-4937-960f-d429ec4972a8.tmp scheduled to be deleted on reboot.
                File delete failed. C:\WINDOWS\temp\701709b4-a3b6-4bd5-8cd7-56a5bf0c4668.tmp scheduled to be deleted on reboot.
                File delete failed. C:\WINDOWS\temp\75691334-6933-499a-9cab-aad4d39386c4.tmp scheduled to be deleted on reboot.
                File delete failed. C:\WINDOWS\temp\791dbcf0-10ac-4fb0-a4b2-3841460ab481.tmp scheduled to be deleted on reboot.
                File delete failed. C:\WINDOWS\temp\8c2a8f17-078d-464e-afeb-4b6422baaa22.tmp scheduled to be deleted on reboot.
                File delete failed. C:\WINDOWS\temp\8f7221fb-e62f-49e9-94fc-3626b362fe21.tmp scheduled to be deleted on reboot.
                File delete failed. C:\WINDOWS\temp\a410bf8c-87a3-4985-8a8f-7361b495d717.tmp scheduled to be deleted on reboot.
                File delete failed. C:\WINDOWS\temp\b8f09084-1c2c-42bc-ae0d-40e52be7791f.tmp scheduled to be deleted on reboot.
                File delete failed. C:\WINDOWS\temp\d55b0603-005c-41d6-b8e2-677e315f6e28.tmp scheduled to be deleted on reboot.
                File delete failed. C:\WINDOWS\temp\e4f56ac2-87fc-4cd2-81cf-4475257f9e69.tmp scheduled to be deleted on reboot.
                Windows Temp folder emptied.
                Java cache emptied.
                File delete failed. C:\Documents and Settings\Ahmed\Local Settings\Application Data\Mozilla\Firefox\Profiles\xbksflkg.default\Cache\_CACHE_001_ scheduled to be deleted on reboot.
                File delete failed. C:\Documents and Settings\Ahmed\Local Settings\Application Data\Mozilla\Firefox\Profiles\xbksflkg.default\Cache\_CACHE_002_ scheduled to be deleted on reboot.
                File delete failed. C:\Documents and Settings\Ahmed\Local Settings\Application Data\Mozilla\Firefox\Profiles\xbksflkg.default\Cache\_CACHE_003_ scheduled to be deleted on reboot.
                File delete failed. C:\Documents and Settings\Ahmed\Local Settings\Application Data\Mozilla\Firefox\Profiles\xbksflkg.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot.
                File delete failed. C:\Documents and Settings\Ahmed\Local Settings\Application Data\Mozilla\Firefox\Profiles\xbksflkg.default\urlclassifier3.sqlite scheduled to be deleted on reboot.
                FireFox cache emptied.
                Temp folders emptied.

                OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 03042009_183549

                Files moved on Reboot...
                File C:\DOCUME~1\Ahmed\LOCALS~1\Temp\etilqs_nGDUevtvmt6PftNvJZFS not found!
                File C:\DOCUME~1\Ahmed\LOCALS~1\Temp\Perflib_Perfdata_808.dat not found!
                File C:\DOCUME~1\Ahmed\LOCALS~1\Temp\Perflib_Perfdata_c80.dat not found!
                File C:\DOCUME~1\Ahmed\LOCALS~1\Temp\Perflib_Perfdata_cb4.dat not found!
                C:\DOCUME~1\Ahmed\LOCALS~1\Temp\~DF3DBD.tmp moved successfully.
                C:\DOCUME~1\Ahmed\LOCALS~1\Temp\~DFF51E.tmp moved successfully.
                File move failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot.
                File move failed. C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat scheduled to be moved on reboot.
                File move failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat scheduled to be moved on reboot.
                File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot.
                C:\WINDOWS\temp\24e50817-74f0-41fe-9da0-a459e863e829.tmp moved successfully.
                C:\WINDOWS\temp\2d40f24c-5e75-4cf5-89c3-abe0e9838348.tmp moved successfully.
                C:\WINDOWS\temp\31242217-1e45-4e26-b4f9-4f1229b3d88d.tmp moved successfully.
                C:\WINDOWS\temp\338f4769-1316-4ab5-8389-d5cc4102d4cc.tmp moved successfully.
                C:\WINDOWS\temp\39b9f349-adfe-4fce-a059-cb0fe91a39fa.tmp moved successfully.
                C:\WINDOWS\temp\3ed87bac-7dd1-40f2-be14-93860a580d7e.tmp moved successfully.
                C:\WINDOWS\temp\43c62500-7e0a-442a-aac4-95f25dc8f4d8.tmp moved successfully.
                C:\WINDOWS\temp\44f4071a-f06f-4b11-b2f5-e55b19a81241.tmp moved successfully.
                C:\WINDOWS\temp\4efa2f12-557d-4207-8577-0ef2be9e2741.tmp moved successfully.
                C:\WINDOWS\temp\666f4c3e-7982-4a16-9872-f2bc304acc42.tmp moved successfully.
                C:\WINDOWS\temp\6724a2f6-bf89-4bf2-8257-7f813c377133.tmp moved successfully.
                C:\WINDOWS\temp\6ea3054b-e3cd-4937-960f-d429ec4972a8.tmp moved successfully.
                C:\WINDOWS\temp\701709b4-a3b6-4bd5-8cd7-56a5bf0c4668.tmp moved successfully.
                C:\WINDOWS\temp\75691334-6933-499a-9cab-aad4d39386c4.tmp moved successfully.
                C:\WINDOWS\temp\791dbcf0-10ac-4fb0-a4b2-3841460ab481.tmp moved successfully.
                C:\WINDOWS\temp\8c2a8f17-078d-464e-afeb-4b6422baaa22.tmp moved successfully.
                C:\WINDOWS\temp\8f7221fb-e62f-49e9-94fc-3626b362fe21.tmp moved successfully.
                C:\WINDOWS\temp\a410bf8c-87a3-4985-8a8f-7361b495d717.tmp moved successfully.
                C:\WINDOWS\temp\b8f09084-1c2c-42bc-ae0d-40e52be7791f.tmp moved successfully.
                C:\WINDOWS\temp\d55b0603-005c-41d6-b8e2-677e315f6e28.tmp moved successfully.
                C:\WINDOWS\temp\e4f56ac2-87fc-4cd2-81cf-4475257f9e69.tmp moved successfully.
                C:\Documents and Settings\Ahmed\Local Settings\Application Data\Mozilla\Firefox\Profiles\xbksflkg.default\Cache\_CACHE_001_ moved successfully.
                C:\Documents and Settings\Ahmed\Local Settings\Application Data\Mozilla\Firefox\Profiles\xbksflkg.default\Cache\_CACHE_002_ moved successfully.
                C:\Documents and Settings\Ahmed\Local Settings\Application Data\Mozilla\Firefox\Profiles\xbksflkg.default\Cache\_CACHE_003_ moved successfully.
                C:\Documents and Settings\Ahmed\Local Settings\Application Data\Mozilla\Firefox\Profiles\xbksflkg.default\Cache\_CACHE_MAP_ moved successfully.
                C:\Documents and Settings\Ahmed\Local Settings\Application Data\Mozilla\Firefox\Profiles\xbksflkg.default\urlclassifier3.sqlite moved successfully.
                0
                1. Modérateur
                  ---> Désinstalle les programmes suivants :
                  - J2SE Runtime Environment 5.0 Update 4
                  - Java 6 Update 6

                  ---> Mets à jour Java.

                  ---> Mets à jour Adobe Reader.

                  ---> Mets à jour AVG Anti-Virus Free Edition.

                  ---> Refais un scan RSIT et poste le rapport log.
                  0
                  1. log.txt

                    Logfile of random's system information tool 1.05 (written by random/random)
                    Run by Ahmed at 2009-03-04 19:12:32
                    Microsoft Windows XP Édition familiale Service Pack 3
                    System drive C: has 38 GB (40%) free of 95 GB
                    Total RAM: 2046 MB (56% free)

                    Logfile of Trend Micro HijackThis v2.0.2
                    Scan saved at 19:12:40, on 04/03/2009
                    Platform: Windows XP SP3 (WinNT 5.01.2600)
                    MSIE: Internet Explorer v7.00 (7.00.6000.16791)
                    Boot mode: Normal

                    Running processes:
                    C:\WINDOWS\System32\smss.exe
                    C:\WINDOWS\system32\winlogon.exe
                    C:\WINDOWS\system32\services.exe
                    C:\WINDOWS\system32\lsass.exe
                    C:\WINDOWS\system32\Ati2evxx.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
                    C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
                    C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
                    C:\WINDOWS\system32\spoolsv.exe
                    C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
                    C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
                    C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
                    C:\WINDOWS\system32\Ati2evxx.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\Program Files\Toshiba\TOSHIBA Applet\TAPPSRV.exe
                    C:\WINDOWS\Explorer.EXE
                    C:\PROGRA~1\AVG\AVG8\avgam.exe
                    C:\PROGRA~1\AVG\AVG8\avgrsx.exe
                    C:\PROGRA~1\AVG\AVG8\avgnsx.exe
                    C:\WINDOWS\system32\TDispVol.exe
                    C:\WINDOWS\System32\DLA\DLACTRLW.EXE
                    C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                    C:\Program Files\TOSHIBA\Utilitaire de zoom TOSHIBA\SmoothView.exe
                    C:\Program Files\TOSHIBA\Tvs\TvsTray.exe
                    C:\WINDOWS\system32\TPSMain.exe
                    C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
                    C:\Program Files\TOSHIBA\Commandes TOSHIBA\TFncKy.exe
                    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                    C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
                    C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
                    C:\WINDOWS\AGRSMMSG.exe
                    C:\WINDOWS\PixArt\PAC7311\Monitor.exe
                    C:\PROGRA~1\AVG\AVG8\avgtray.exe
                    C:\WINDOWS\system32\ctfmon.exe
                    C:\Program Files\Internet Download Manager\IDMan.exe
                    C:\Program Files\Synaptics\SynTP\Toshiba.exe
                    C:\Program Files\Skype\Phone\Skype.exe
                    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                    C:\WINDOWS\system32\TPSBattM.exe
                    C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
                    C:\Program Files\Messenger\msmsgs.exe
                    C:\Program Files\Fichiers communs\Ahead\lib\NMBgMonitor.exe
                    C:\Program Files\Internet Download Manager\IEMonitor.exe
                    C:\Program Files\Skype\Plugin Manager\skypePM.exe
                    C:\Program Files\Windows Live\Contacts\wlcomm.exe
                    C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
                    C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
                    C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
                    C:\Program Files\Mozilla Firefox\firefox.exe
                    C:\WINDOWS\system32\rundll32.exe
                    C:\WINDOWS\system32\msiexec.exe
                    C:\Program Files\Screamer Radio\screamer.exe
                    C:\Program Files\Java\jre6\bin\jqs.exe
                    C:\WINDOWS\system32\wbem\wmiapsrv.exe
                    C:\Documents and Settings\Ahmed\Bureau\virus_softwares\RSIT.exe
                    C:\Program Files\Trend Micro\HijackThis\Ahmed.exe

                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://support.norton.com/sp/fr/fr/home/current/solutions/kb20090121104844EN?abproduct=SymNRT&abversion=2009.0.0.41&build=Symantec&ced=true&entsrc=CED_pubweb&error=0&module=2009&src=_mi
                    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                    O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
                    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
                    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
                    O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
                    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
                    O4 - HKLM\..\Run: [TDispVol] TDispVol.exe
                    O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
                    O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
                    O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\Utilitaire de zoom TOSHIBA\SmoothView.exe
                    O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
                    O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
                    O4 - HKLM\..\Run: [Tvs] C:\Program Files\TOSHIBA\Tvs\TvsTray.exe
                    O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
                    O4 - HKLM\..\Run: [THotkey] C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
                    O4 - HKLM\..\Run: [TFncKy] TFncKy.exe
                    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                    O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
                    O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
                    O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
                    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
                    O4 - HKLM\..\Run: [Monitor] C:\WINDOWS\PixArt\PAC7311\Monitor.exe
                    O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
                    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
                    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                    O4 - HKCU\..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot
                    O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
                    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                    O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
                    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                    O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\lib\NMBgMonitor.exe"
                    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                    O8 - Extra context menu item: Download all links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm
                    O8 - Extra context menu item: Download FLV video content with IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm
                    O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm
                    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
                    O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                    O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
                    O17 - HKLM\System\CCS\Services\Tcpip\..\{F34E8A4D-DA5A-4E87-9352-87D82CF4FE91}: NameServer = 193.95.66.10
                    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
                    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
                    O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
                    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                    O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
                    O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
                    O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
                    O23 - Service: Google Desktop Manager 5.8.809.23506 (GoogleDesktopManager-092308-165331) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
                    O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
                    O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
                    O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
                    O23 - Service: TOSHIBA Application Service (TAPPSRV) - TOSHIBA Corp. - C:\Program Files\Toshiba\TOSHIBA Applet\TAPPSRV.exe
                    0
                    1. Oui je pense que tt va bien. Thank you so much You are the best Destrio5 ;)
                      0
                      1. Modérateur
                        1/

                        ---> Désinstalle HijackThis.

                        ---> Télécharge ToolsCleaner2 sur ton Bureau.
                        * Double-clique sur ToolsCleaner2.exe pour le lancer.
                        * Clique sur Recherche et laisse le scan agir.
                        * Clique sur Suppression pour finaliser.
                        * Tu peux, si tu le souhaites, te servir des Options Facultatives.
                        * Clique sur Quitter pour obtenir le rapport.
                        * Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\).

                        2/

                        ---> Télécharge et installe CCleaner Slim.
                        * Lance-le. Va dans Options puis Avancé et décoche la case Effacer uniquement les fichiers etc....
                        * Va dans Nettoyeur, choisis Analyse. Une fois terminé, lance le nettoyage.
                        * Ensuite, choisis Registre, puis Chercher des erreurs. Une fois terminé, répare toutes les erreurs (Sauvegarde la base de registre).

                        3/

                        ---> Il est nécessaire de désactiver puis réactiver la restauration système pour la purger.

                        ---> Je te conseille de créer un point de restauration que tu pourras utiliser plus tard si tu as un problème.

                        ==Prévention==

                        Conserve MBAM. Il te servira à scanner les fichiers douteux en complément de l'antivirus et scanne le disque dur régulièrement.

                        Comme navigateur, utilise plutôt Mozilla Firefox qu'Internet Explorer. Tu peux utiliser l'extension NoScript pour plus de sécurité.

                        Vérifie que les mises à jour automatiques sont bien activées (Menu Démarrer, clique droit sur Poste de travail, onglet Mises à jour automatiques).

                        Tu peux aussi modifier le fichier Hosts pour améliorer la sécurité de ton PC : Lien

                        Par rapport au P2P : Lien

                        Voici un dossier complet (A lire avec Adobe Reader ou Foxit Reader) : Lien

                        Sois plus vigilant(e) sur Internet ;)
                        0
                        1. [ Rapport ToolsCleaner version 2.3.2 (par A.Rothstein & dj QUIOU) ]

                          -->- Recherche:

                          C:\VundoFix.txt: trouvé !
                          C:\Combofix.txt: trouvé !
                          C:\fixnavi.txt: trouvé !
                          C:\FindyKill.txt: trouvé !
                          C:\_OtMoveIt: trouvé !
                          C:\Rsit: trouvé !
                          C:\Documents and Settings\Ahmed\Bureau\OTMoveIt3.exe: trouvé !
                          C:\Documents and Settings\Ahmed\Bureau\virus_softwares\SdFix.exe: trouvé !
                          C:\Documents and Settings\Ahmed\Bureau\virus_softwares\VirtumundoBeGone.exe: trouvé !
                          C:\Documents and Settings\Ahmed\Bureau\virus_softwares\Navilog1.exe: trouvé !
                          C:\Documents and Settings\Ahmed\Bureau\virus_softwares\ComboFix.exe: trouvé !
                          C:\Documents and Settings\Ahmed\Bureau\virus_softwares\vundoFix.exe: trouvé !
                          C:\Documents and Settings\Ahmed\Bureau\virus_softwares\HijackThis.exe: trouvé !
                          C:\Documents and Settings\Ahmed\Bureau\virus_softwares\SmitFraudFix.exe: trouvé !
                          C:\Documents and Settings\Ahmed\Bureau\virus_softwares\Rsit.exe: trouvé !
                          C:\Documents and Settings\Ahmed\Bureau\virus_softwares\OTViewIt.exe: trouvé !
                          C:\Documents and Settings\All Users\Bureau\Navilog1.lnk: trouvé !
                          C:\Documents and Settings\All Users\Bureau\VBG.txt: trouvé !
                          C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Navilog1: trouvé !
                          C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Navilog1\Navilog1.lnk: trouvé !
                          C:\Program Files\Navilog1: trouvé !
                          C:\Program Files\FindyKill: trouvé !
                          C:\Program Files\Navilog1\Navilog1.bat: trouvé !
                          C:\Program Files\Trend Micro\HijackThis: trouvé !
                          C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: trouvé !
                          C:\Program Files\Trend Micro\HijackThis\hijackthis.log: trouvé !

                          ---------------------------------
                          -->- Suppression:

                          C:\Documents and Settings\Ahmed\Bureau\virus_softwares\SdFix.exe: supprimé !
                          C:\Documents and Settings\Ahmed\Bureau\virus_softwares\VirtumundoBeGone.exe: supprimé !
                          C:\Documents and Settings\Ahmed\Bureau\virus_softwares\Navilog1.exe: supprimé !
                          C:\Documents and Settings\Ahmed\Bureau\virus_softwares\ComboFix.exe: supprimé !
                          C:\Documents and Settings\Ahmed\Bureau\virus_softwares\vundoFix.exe: supprimé !
                          C:\Documents and Settings\Ahmed\Bureau\virus_softwares\HijackThis.exe: supprimé !
                          C:\Documents and Settings\Ahmed\Bureau\virus_softwares\SmitFraudFix.exe: supprimé !
                          C:\Documents and Settings\All Users\Bureau\Navilog1.lnk: supprimé !
                          C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Navilog1\Navilog1.lnk: supprimé !
                          C:\Program Files\Navilog1\Navilog1.bat: supprimé !
                          C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: supprimé !
                          C:\VundoFix.txt: supprimé !
                          C:\Combofix.txt: supprimé !
                          C:\fixnavi.txt: supprimé !
                          C:\FindyKill.txt: supprimé !
                          C:\Documents and Settings\Ahmed\Bureau\OTMoveIt3.exe: supprimé !
                          C:\Documents and Settings\Ahmed\Bureau\virus_softwares\Rsit.exe: supprimé !
                          C:\Documents and Settings\Ahmed\Bureau\virus_softwares\OTViewIt.exe: supprimé !
                          C:\Documents and Settings\All Users\Bureau\VBG.txt: supprimé !
                          C:\Program Files\Trend Micro\HijackThis\hijackthis.log: supprimé !
                          C:\_OtMoveIt: supprimé !
                          C:\Rsit: supprimé !
                          C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Navilog1: supprimé !
                          C:\Program Files\Navilog1: supprimé !
                          C:\Program Files\FindyKill: supprimé !
                          C:\Program Files\Trend Micro\HijackThis: supprimé !
                          0
                          1. Modérateur
                            Tu peux supprimer ToolsCleaner.
                            0
                            Précédent
                            • 1
                            • 2