Ordi tres lent impossible de travailler

Résolu
Bonjour a tous

Mon ordi est actuellement très lent et bien sur c'est le signe d'un dérangement cérébral de ses neurones windows!!
J'ai eu un problème avec ma clé usb que j'avais inséré dans un ordi d'un magasin de photocopie et un Td agent (je sais plus la suite) est sorti de celle ci lorsque je l'ai connecté a mon ordi.
J'ai eu aussi des .exe (MRT.exe.exe, mrtstub.exe) dont je ne connais pas l'influence

Merci a tous d'avance
Configuration: Windows XP
Firefox 3.0.10

25 réponses

  1. Contributeur sécurité
    Bonjour,

    Fais un rapport hijackthis pour que je puisse vérifier les infections de ton PC stp

    ▶ Télécharge hijackthis

    ▶ Tout est expliqué sur mon site web pour l'installer et l'utiliser correctement.

    ▶ Poste le rapport obtenu dans le bloc note dans ta prochaine réponse.

    Comment copier/coller le rapport :

    ▶ Quand tu as le rapport à l écran, tu fais ctrl A pour "sélectionner tout" puis ctrl C pour "copier".

    ▶ ensuite tu viens sur le forum pour me répondre et tu fais ctrl V pour "coller" le rapport.
    0
    1. salut et merci de ton aide

      Voici ci dessous le rapport Hijackthis
      @+

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 14:14:59, on 29/04/2009
      Platform: Windows XP SP3 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.16827)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
      C:\Program Files\Seagate\Basics\Service\SyncServicesBasics.exe
      C:\WINDOWS\system32\CSHelper.exe
      C:\Program Files\Java\jre6\bin\jqs.exe
      C:\Program Files\Sony\MD Simple Burner\NetMDSB.exe
      C:\WINDOWS\system32\nvsvc32.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\RUNDLL32.EXE
      C:\Program Files\Analog Devices\Core\smax4pnp.exe
      C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
      C:\Program Files\QuickTime\qttask.exe
      C:\Program Files\OmniPageSE\opware32.exe
      C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
      C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
      C:\Program Files\Google\Gmail Notifier\gnotify.exe
      C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe
      C:\Program Files\Seagate\Basics\Basics Status\MaxMenuMgrBasics.exe
      C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe
      C:\Program Files\Trust\Trust Keyboard 15036\PS2USBKbdDrv.exe
      C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
      C:\Program Files\Jetico\Jetico Personal Firewall\fwsrv.exe
      C:\Program Files\HomePlayer\HomePlayer.exe
      C:\Program Files\Java\jre6\bin\jusched.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\ATnotes\ATnotes.exe
      C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe
      C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICCE.EXE
      C:\Program Files\Messenger\msmsgs.exe
      C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
      C:\Program Files\OpenOffice.org 2.1\program\soffice.exe
      C:\Program Files\OpenOffice.org 2.1\program\soffice.BIN
      C:\Program Files\Avira\AntiVir PersonalEdition Classic\avscan.exe
      C:\Program Files\Mozilla Firefox\firefox.exe
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
      C:\Program Files\Trend Micro\HijackThis\HJT.exe

      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
      O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
      O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
      O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
      O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
      O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
      O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
      O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
      O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [Omnipage] C:\Program Files\OmniPageSE\opware32.exe
      O4 - HKLM\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
      O4 - HKLM\..\Run: [WireLessKeyboard] C:\Program Files\Trust\Trust Keyboard 15036\StartAutorun.exe PS2USBKbdDrv.exe
      O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
      O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
      O4 - HKLM\..\Run: [SMSTray] C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe
      O4 - HKLM\..\Run: [basicsmssmenu] "C:\Program Files\Seagate\Basics\Basics Status\MaxMenuMgrBasics.exe"
      O4 - HKLM\..\Run: [H2O] C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
      O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
      O4 - HKLM\..\Run: [JeticoPFStartup] "C:\Program Files\Jetico\Jetico Personal Firewall\fwsrv.exe"
      O4 - HKLM\..\Run: [HomePlayer] C:\Program Files\HomePlayer\HomePlayer.exe
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
      O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [ATnotes.exe] C:\Program Files\ATnotes\ATnotes.exe
      O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
      O4 - HKCU\..\Run: [DW6] "C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe"
      O4 - HKCU\..\Run: [EPSON Stylus D120 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICCE.EXE /FU "C:\WINDOWS\TEMP\E_S184.tmp" /EF "HKCU"
      O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
      O4 - Startup: OpenOffice.org 2.1.lnk = C:\Program Files\OpenOffice.org 2.1\program\quickstart.exe
      O4 - Startup: Outil de détection de support Picture Motion Browser.lnk = C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
      O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
      O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
      O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
      O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
      O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
      O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
      O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
      O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
      O23 - Service: Basics Service - Seagate Technology LLC - C:\Program Files\Seagate\Basics\Service\SyncServicesBasics.exe
      O23 - Service: CopySafe Helper Service (CSHelper) - Unknown owner - C:\WINDOWS\system32\CSHelper.exe
      O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
      O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Fichiers communs\Macromedia Shared\Service\Macromedia Licensing.exe
      O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\MSCSPTISRV.exe
      O23 - Service: MD Simple Burner Service (NetMDSB) - Sony Corporation - C:\Program Files\Sony\MD Simple Burner\NetMDSB.exe
      O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
      O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\PACSPTISVR.exe
      O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\SPTISRV.exe
      O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\SSScsiSV.exe
      0
      1. Contributeur sécurité
        Pas d'infections visibles dans le rapport Hijackthis... Nous allons vérifier plus en profondeur...

        ▶ Télécharge Random's System Information Tool (RSIT).

        ▶ Un tutoriel sera à ta disposition sur mon site web pour l'installer et l'utiliser correctement.

        ▶ Double clique sur RSIT.exe pour lancer l'outil.

        ▶ Clique sur 'Continue' à l'écran Disclaimer.

        ▶ Si l'outil Hijackthis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera et tu devras accepter la licence.

        ▶ Une fois le scan fini , 2 rapports vont apparaitre. Poste le contenu des 2 rapports.

        ( C:\RSIT\log.txt et C:\RSIT\info.txt )

        CTRL A pour sélectionner tout, CTRL C pour copier et puis CTRL V pour coller
        0
        1. Re,

          cidessous les 2 rapports rsit
          merci

          ---------------------------------------------------------------------------------------------------------------------

          info.txt logfile of random's system information tool 1.06 2009-04-29 15:27:10

          ======Uninstall list======

          -->C:\Program Files\Fichiers communs\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
          -->C:\WINDOWS\system32\\MSIEXEC.EXE /x {9541FED0-327F-4df0-8B96-EF57EF622F19}
          -->Dummy
          -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{88E5FCB8-5F25-11D5-B16F-0800460222F0}\setup.exe" -l0x40c UNINSTALL
          -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D76298C2-E532-4A11-BCFF-76F3F19DA84D}\setup.exe" UNINSTALL
          -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{22EB2FA7-1BA0-4FFB-972F-353EC6ABA9D5}\setup.exe" -l0x40c /removeonly -removeonly
          -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{28B97CAB-828F-49D8-A30A-675476F9BA92}\setup.exe" -l0x40c /cont /removeonly -removeonly
          -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{4E7DC12A-3597-4A94-9429-F6C6987361B1}\setup.exe" -l0x40c /removeonly -removeonly
          -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6813C983-427E-4511-8456-E98FCAA1A125}\setup.exe" -l0x40c /removeonly -removeonly
          -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7DADB304-AF20-48C3-A780-4B4133A08817}\setup.exe" -l0x40c /removeonly -removeonly
          -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9C423CF6-2DAA-4A37-94B8-59D7ECC7DB13}\setup.exe" -l0x40c /removeonly -removeonly
          -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{ACE66099-E18E-4037-83C8-9D182E5B9FA8}\setup.exe" -l0x40c /removeonly -removeonly
          -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B34B6E67-FCDD-4E03-8742-B5701427FAFB}\setup.exe" -l0x40c /removeonly -removeonly
          -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FA6CC4B4-7741-4F8D-8E81-15C4BAB9869B}\setup.exe" -l0x40c /removeonly -removeonly
          -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
          Accord-->C:\Program Files\Accord\uninstall.exe
          Ad-Aware-->MsiExec.exe /I{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}
          Adobe Flash Player 10 Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
          Adobe Flash Player ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
          Adobe Photoshop 7.0-->C:\WINDOWS\ISUN040C.EXE -f"C:\Program Files\Adobe\Photoshop 7.0\Uninst.isu" -c"C:\Program Files\Adobe\Photoshop 7.0\Uninst.dll"
          Adobe Reader 8.1.4 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A81300000003}
          Adobe Shockwave Player-->C:\WINDOWS\system32\Adobe\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Adobe\SHOCKW~1\Install.log
          Archiveur WinRAR-->C:\Program Files\WinRAR\uninstall.exe
          ArtistScope Plugin FX-->"C:\Program Files\Mozilla Firefox\plugins\uninstall.exe" "/U:C:\Program Files\Mozilla Firefox\plugins\Uninstall\uninstall.xml"
          AsusUpdate-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{587178E7-B1DF-494E-9838-FA4DD36E873C}\setup.exe" -l0x40c
          Athlon 64 Processor Driver-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C151CE54-E7EA-4804-854B-F515368B0798}\setup.exe" -l0x40c
          ATnotes Version 9.5-->"C:\Program Files\ATnotes\unins000.exe"
          Audacity 1.2.6-->"C:\Program Files\Audacity\unins000.exe"
          Audacity 1.3.5 (Unicode)-->"C:\Program Files\Audacity 1.3 Beta (Unicode)\unins000.exe"
          Avira AntiVir Personal - Free Antivirus-->C:\Program Files\Avira\AntiVir PersonalEdition Classic\SETUP.EXE /REMOVE
          Azureus Vuze-->C:\Program Files\Azureus\uninstall.exe
          BSPlayer-->"C:\Program Files\BSplayer\uninstall.exe"
          Canon Camera Support Core Library-->C:\Program Files\Fichiers communs\InstallShield\Driver\8\Intel 32\IDriver.exe /M{B9B9863A-32FD-4133-ADB7-46244ED77694} /l1036
          Canon Camera Window for ZoomBrowser EX-->C:\Program Files\Fichiers communs\InstallShield\Driver\8\Intel 32\IDriver.exe /M{F37942A8-B21B-4C5A-A1D2-B676BF55EAE0}
          Canon i850-->C:\WINDOWS\system32\CNMCP4b.exe "-PRINTERNAMECanon i850" "-HELPERDLLC:\BJPrinter\CNMWINDOWS\Canon i850 Installer\Inst2\cnmis.dll" "-RCDLLC:\BJPrinter\CNMWINDOWS\Canon i850 Installer\Inst2\cnmi040c.dll"
          Canon Internet Library for ZoomBrowser EX-->C:\Program Files\Fichiers communs\InstallShield\Driver\8\Intel 32\IDriver.exe /M{2F81FBFC-9A37-431F-9050-14B55485DF5A}
          Canon MovieEdit Task for ZoomBrowser EX-->C:\Program Files\Fichiers communs\InstallShield\Driver\8\Intel 32\IDriver.exe /M{DE286975-ACF1-45B8-9EF7-34E162B2C817}
          Canon PhotoRecord-->MsiExec.exe /X{BEF56F2D-56ED-4176-BF72-7B68D4A3B98D}
          Canon RAW Image Task for ZoomBrowser EX-->C:\Program Files\Fichiers communs\InstallShield\Driver\8\Intel 32\IDriver.exe /M{9518F764-C54D-47B2-9E73-154B21E79FD2}
          Canon RemoteCapture Task for ZoomBrowser EX-->C:\Program Files\Fichiers communs\InstallShield\Driver\8\Intel 32\IDriver.exe /M{2C164906-E68F-462A-9010-70DD022223EF}
          Canon Utilities ZoomBrowser EX-->MsiExec.exe /X{C1D76D7A-F3BB-47EA-A746-5B1E2FFC1DF2}
          CanoScan Toolbox 4.1-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BCE46757-7674-4416-BEDB-68205A60409E}\setup.exe" -l0x40c anything
          CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
          Correctif pour Lecteur Windows Media 11 (KB939683)-->"C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
          Correctif pour Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
          Disc2Phone-->MsiExec.exe /I{FFAB5ABB-8AAB-42E2-847F-1743E51E01E9}
          DR220A-->C:\WINDOWS\unin040c.exe -f"C:\Program Files\uxtobirza\DR220\DeIsL1.isu" -c"C:\Program Files\uxtobirza\DR220\_ISREG32.DLL"
          Drive Manager-->"C:\Program Files\InstallShield Installation Information\{48B0F38D-1913-44F3-99AA-D4C55A2B038E}\setup.exe" -runfromtemp -l0x040c -removeonly
          Drive Manager-->MsiExec.exe /I{48B0F38D-1913-44F3-99AA-D4C55A2B038E}
          DVDFab HD Decrypter 4.0.5.0-->"C:\Program Files\DVDFab HD Decrypter 4\unins000.exe"
          EasyPHP 1.8-->"C:\Program Files\EasyPHP1-8\unins000.exe"
          eMule-->"C:\Program Files\eMule\Uninstall.exe"
          EPSON Logiciel imprimante-->C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\EPUPDATE.EXE /R
          EPSON Stylus C110_D120 Manuel-->C:\Program Files\EPSON\TPMANUAL\ESC110_D120\FRA\USE_G\DOCUNINS.EXE
          EPSON Web-To-Page-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7F14F68C-17FA-4F88-B3FD-7F449C1EBF32}\SETUP.EXE" -l0x40c -anything
          ffdshow [rev 1703] [2007-12-15]-->"C:\Program Files\ffdshow\unins000.exe"
          Free FLV Converter V 6.23.0-->"C:\Program Files\Free FLV Converter\unins000.exe"
          GiveMeTac 1.1-->"C:\Program Files\GiveMeTac 1.1\unins000.exe"
          Google Earth-->MsiExec.exe /I{1E04F83B-2AB9-4301-9EF7-E86307F79C72}
          Google Gmail Notifier-->"C:\Program Files\Google\Gmail Notifier\UninstallGmail.exe"
          HijackThis 2.0.2-->"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
          HomePlayer 1.5.7d-->C:\Program Files\HomePlayer\uninst.exe
          Hotfix for Windows Media Format 11 SDK (KB929399)-->"C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
          IK Multimedia Sampletank XL v2.0.1.r1-->C:\PROGRA~1\SAMPLE~1\UNWISE.EXE C:\PROGRA~1\SAMPLE~1\INSTALL.LOG
          Java(TM) 6 Update 13-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216010FF}
          Java(TM) 6 Update 2-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160020}
          Java(TM) 6 Update 3-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160030}
          Java(TM) 6 Update 5-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160050}
          Java(TM) 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
          Java(TM) SE Runtime Environment 6 Update 1-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160010}
          jetAudio Basic-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{DF8195AF-8E6F-4487-A0EE-196F7E3F4B8A}\setup.exe" -l0xc0c -removeonly
          Jetico Personal Firewall 1.0-->"C:\WINDOWS\BCUnInstall.exe" C:\Program Files\Jetico\Jetico Personal Firewall\UnInstall.log
          Lame ACM MP3 Codec-->"C:\WINDOWS\IFinst26.exe" -UC:\Program Files\Lame MP3 Codec\IFUBA.inf
          Le Centre de Contrôle de Licences de Syncrosoft-->C:\PROGRA~1\SYNCRO~1\UNWISE.EXE C:\PROGRA~1\SYNCRO~1\INSTALL.LOG
          Lecteur Windows Media 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
          Macromedia Dreamweaver MX 2004-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{05BB2EC5-6BEF-4DDC-9E75-BEE7B161157A}\Setup.exe" -l0x40c mmUninstall
          Macromedia Extension Manager-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A5BA14E0-7384-11D4-BAE7-00409631A2C8}\setup.exe" -l0x40c mmUninstall
          Macromedia FreeHand MX-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{8B4AE751-7055-4518-87B0-E148A8D50D0A}\Setup.exe" -l0x40c UNINSTALL
          Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
          Manual CanoScan 3000,3000F-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E088AC54-7379-4C8F-A8B6-D2381E5A1172}\setup.exe" -l0x40c
          MD Simple Burner 2.0.05-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{47E09785-B2FB-11D5-B8EE-00B0D0D26B88}\setup.exe" -l0x40c UNINSTALL
          Microsoft .NET Framework 1.1 Hotfix (KB928366)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"
          Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
          Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
          Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
          Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
          Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
          Microsoft Office PowerPoint Viewer 2003-->MsiExec.exe /X{90AF040C-6000-11D3-8CFE-0150048383C9}
          Microsoft User-Mode Driver Framework Feature Pack 1.0-->"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
          Mise à jour critique pour Lecteur Windows Media 11 (KB959772)-->"C:\WINDOWS\$NtUninstallKB959772_WM11$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Lecteur Windows Media (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Lecteur Windows Media 11 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Lecteur Windows Media 11 (KB954154)-->"C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows Internet Explorer 7 (KB938127)-->"C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows Internet Explorer 7 (KB938127-v2)-->"C:\WINDOWS\ie7updates\KB938127-v2-IE7\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows Internet Explorer 7 (KB956390)-->"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows Internet Explorer 7 (KB958215)-->"C:\WINDOWS\ie7updates\KB958215-IE7\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows Internet Explorer 7 (KB960714)-->"C:\WINDOWS\ie7updates\KB960714-IE7\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows Internet Explorer 7 (KB961260)-->"C:\WINDOWS\ie7updates\KB961260-IE7\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows Internet Explorer 7 (KB963027)-->"C:\WINDOWS\ie7updates\KB963027-IE7\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB923561)-->"C:\WINDOWS\$NtUninstallKB923561$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB938464-v2)-->"C:\WINDOWS\$NtUninstallKB938464-v2$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB952004)-->"C:\WINDOWS\$NtUninstallKB952004$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB954211)-->"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB954459)-->"C:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB954600)-->"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB956391)-->"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB956572)-->"C:\WINDOWS\$NtUninstallKB956572$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB956841)-->"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB957095)-->"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB958687)-->"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB958690)-->"C:\WINDOWS\$NtUninstallKB958690$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB959426)-->"C:\WINDOWS\$NtUninstallKB959426$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB960225)-->"C:\WINDOWS\$NtUninstallKB960225$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB960715)-->"C:\WINDOWS\$NtUninstallKB960715$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB960803)-->"C:\WINDOWS\$NtUninstallKB960803$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB961373)-->"C:\WINDOWS\$NtUninstallKB961373$\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB951072-v2)-->"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB955839)-->"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB967715)-->"C:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe"
          Mozilla Firefox (3.0.10)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
          MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
          MSXML 6 Service Pack 2 (KB954459)-->MsiExec.exe /I{1A528690-6A2D-4BC5-B143-8C4AE8D19D96}
          MyFreeCodec-->C:\Program Files\MyFree Codec\09b beta\uninstall.exe
          NVIDIA Drivers-->C:\WINDOWS\system32\nvudisp.exe UninstallGUI
          OmniPage SE-->MsiExec.exe /I{6249C22D-E6A8-407B-BA8B-40298848ED94}
          OOBOX SynchroBox data 2.0-->C:\Program Files\OOBOX\Music\iTuner\uninst.exe
          OpenMG Limited Patch 4.4-06-13-19-01-->C:\Program Files\Fichiers communs\Sony Shared\OpenMG\HotFixes\HotFix4.4-06-13-19-01\HotFixSetup\setup.exe /u
          OpenMG Secure Module 4.4.00-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe /M{CFB17307-B244-4EAD-AE8E-CDAF440477C2} UNINSTALL
          OpenOffice.org 2.1-->MsiExec.exe /I{E5430A11-6799-41E0-A9D5-F68BDC67AAD8}
          PC Inspector smart recovery-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C9A87D86-FDFD-418B-BF96-EF09320973B3}\Setup.exe" -l0x40c
          PercussionStudio3-->C:\Program Files\PercussionStudio3\uninstall.exe
          Picture Package Music Transfer-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{CE2121C6-C94D-4A73-8EA4-6943F33EE335}\setup.exe" -l0x40c /removeonly -removeonly
          Quartz AudioMaster Freeware-->C:\WINDOWS\uninst.exe -f"C:\Program Files\DigitalSoundPlanet\Quartz AudioMaster Freeware 460E\DeIsL1.isu" -c"C:\Program Files\DigitalSoundPlanet\Quartz AudioMaster Freeware 460E\_ISREG32.DLL"
          QuickTime-->C:\WINDOWS\unvise32qt.exe C:\WINDOWS\system32\QuickTime\Uninstall.log
          RealPlayer-->C:\Program Files\Fichiers communs\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
          Samsung Media Studio-->C:\Program Files\InstallShield Installation Information\{C20CE592-B0F8-4D20-BF31-0151CA6331A6}\Setup.exe -runfromtemp -l0x040c -removeonly
          Skype™ 3.8-->MsiExec.exe /X{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}
          Sonic RecordNow!-->MsiExec.exe /I{9541FED0-327F-4DF0-8B96-EF57EF622F19}
          SonicStage 3.4-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A0EB195B-5876-48E6-879D-33D4B2102610}\setup.exe" -l0x40c UNINSTALL -removeonly
          Sony ACID XPress 5.0a-->MsiExec.exe /X{12F4BE69-6614-41D3-BB3B-DF7F921DF2BB}
          Sony Picture Utility-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D5068583-D569-468B-9755-5FBF5848F46F}\setup.exe" -l0x40c /removeonly uninstall -removeonly
          Sony USB Driver-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5C29CB8B-AC1E-4114-8D68-9CD080140D4A}\setup.exe" -l0x40c UNINSTALL -removeonly
          SoundMAX-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F0A37341-D692-11D4-A984-009027EC0A9C}\setup.exe" -l0x40c -removeonly
          Steinberg Cubase SX v3.1.1.944-->C:\PROGRA~1\STEINB~1\CUBASE~1\UNWISE.EXE C:\PROGRA~1\STEINB~1\CUBASE~1\INSTALL.LOG
          SUPER © Version 2008.bld.30 (Mar 22, 2008)-->C:\PROGRA~1\ERIGHT~1\SUPER\Setup.exe /remove /q0
          SyncroSoft Emu (Remove only)-->C:\Program Files\SyncroSoft\Pos\H2O\Uninst.exe
          The Weather Channel Desktop 6-->C:\Program Files\The Weather Channel FW\Desktop\TheWeatherChannelCustomUninstall.exe
          The Weather Channel Desktop-->C:\Program Files\The Weather Channel FW\Desktop Weather\TheWeatherChannelCustomUninstall.exe
          Traduction française pour jetAudio 6.2-->C:\Program Files\JetAudio\UnInstall_jetAudio.exe
          Trillian-->C:\Program Files\Trillian\trillian.exe /uninstall
          Trust Keyboard 15036-->C:\Program Files\Fichiers communs\InstallShield\Driver\8\Intel 32\IDriver.exe /M{64824474-AE1E-4BA9-AF44-F110272D10FE}
          VideoLAN VLC media player 0.8.6-->C:\Program Files\VLC\uninstall.exe
          VirtualDub 1.8.8 Fr-->"C:\Program Files\VirtualDub\unins000.exe"
          VirtualDub Plugin Pack 1.0.0.6 Fr-->"C:\Program Files\VirtualDub\unins001.exe"
          Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
          Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
          Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
          Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
          XviD MPEG-4 Video Codec-->"C:\Program Files\XviD\unins000.exe"

          ======Security center information======

          AV: Avira AntiVir PersonalEdition

          ======System event log======

          Computer Name: DIAZ-E439AB2F45
          Event Code: 51
          Message: Une erreur a été détectée sur le périphérique \Device\Harddisk2\D au cours d'une opération de pagination.

          Record Number: 15551
          Source Name: Disk
          Time Written: 20090320230546.000000+060
          Event Type: Avertissement
          User:

          Computer Name: DIAZ-E439AB2F45
          Event Code: 51
          Message: Une erreur a été détectée sur le périphérique \Device\Harddisk2\D au cours d'une opération de pagination.

          Record Number: 15550
          Source Name: Disk
          Time Written: 20090320220531.000000+060
          Event Type: Avertissement
          User:

          Computer Name: DIAZ-E439AB2F45
          Event Code: 51
          Message: Une erreur a été détectée sur le périphérique \Device\Harddisk2\D au cours d'une opération de pagination.

          Record Number: 15549
          Source Name: Disk
          Time Written: 20090320213413.000000+060
          Event Type: Avertissement
          User:

          Computer Name: DIAZ-E439AB2F45
          Event Code: 51
          Message: Une erreur a été détectée sur le périphérique \Device\Harddisk2\D au cours d'une opération de pagination.

          Record Number: 15548
          Source Name: Disk
          Time Written: 20090320200354.000000+060
          Event Type: Avertissement
          User:

          Computer Name: DIAZ-E439AB2F45
          Event Code: 7036
          Message: Le service Macromedia Licensing Service est entré dans l'état : arrêté.

          Record Number: 15547
          Source Name: Service Control Manager
          Time Written: 20090320193008.000000+060
          Event Type: Informations
          User:

          =====Application event log=====

          Computer Name: DIAZ-E439AB2F45
          Event Code: 1517
          Message: Windows a sauvegardé le Registre utilisateur DIAZ-E439AB2F45\Fred alors qu'une application ou un service utilisait toujours le Registre pendant la fermeture de la session. La mémoire utilisée par le Registre de l'utilisateur n'a pas été libérée. le Registre sera déchargé lorsqu'il ne sera plus utilisé.

          Cela est souvent causé par des services s'exécutant en tant que compte d'utilisateur, essayez de configurer les services pour s'exécuter dans le compte service réseau ou service local.

          Record Number: 435
          Source Name: Userenv
          Time Written: 20070620231142.000000+120
          Event Type: Avertissement
          User: AUTORITE NT\SYSTEM

          Computer Name: DIAZ-E439AB2F45
          Event Code: 1800
          Message: Le service Centre de sécurité Windows a démarré.

          Record Number: 434
          Source Name: SecurityCenter
          Time Written: 20070620091124.000000+120
          Event Type: Informations
          User:

          Computer Name: DIAZ-E439AB2F45
          Event Code: 1517
          Message: Windows a sauvegardé le Registre utilisateur DIAZ-E439AB2F45\Fred alors qu'une application ou un service utilisait toujours le Registre pendant la fermeture de la session. La mémoire utilisée par le Registre de l'utilisateur n'a pas été libérée. le Registre sera déchargé lorsqu'il ne sera plus utilisé.

          Cela est souvent causé par des services s'exécutant en tant que compte d'utilisateur, essayez de configurer les services pour s'exécuter dans le compte service réseau ou service local.

          Record Number: 433
          Source Name: Userenv
          Time Written: 20070619235419.000000+120
          Event Type: Avertissement
          User: AUTORITE NT\SYSTEM

          Computer Name: DIAZ-E439AB2F45
          Event Code: 1800
          Message: Le service Centre de sécurité Windows a démarré.

          Record Number: 432
          Source Name: SecurityCenter
          Time Written: 20070619085938.000000+120
          Event Type: Informations
          User:

          Computer Name: DIAZ-E439AB2F45
          Event Code: 1517
          Message: Windows a sauvegardé le Registre utilisateur DIAZ-E439AB2F45\Fred alors qu'une application ou un service utilisait toujours le Registre pendant la fermeture de la session. La mémoire utilisée par le Registre de l'utilisateur n'a pas été libérée. le Registre sera déchargé lorsqu'il ne sera plus utilisé.

          Cela est souvent causé par des services s'exécutant en tant que compte d'utilisateur, essayez de configurer les services pour s'exécuter dans le compte service réseau ou service local.

          Record Number: 431
          Source Name: Userenv
          Time Written: 20070618235138.000000+120
          Event Type: Avertissement
          User: AUTORITE NT\SYSTEM

          ======Environment variables======

          "ComSpec"=%SystemRoot%\system32\cmd.exe
          "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\Fichiers communs\Teleca Shared;C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322
          "windir"=%SystemRoot%
          "FP_NO_HOST_CHECK"=NO
          "OS"=Windows_NT
          "PROCESSOR_ARCHITECTURE"=x86
          "PROCESSOR_LEVEL"=15
          "PROCESSOR_IDENTIFIER"=x86 Family 15 Model 95 Stepping 2, AuthenticAMD
          "PROCESSOR_REVISION"=5f02
          "NUMBER_OF_PROCESSORS"=1
          "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
          "TEMP"=%SystemRoot%\TEMP
          "TMP"=%SystemRoot%\TEMP

          -----------------EOF-----------------
          -----------------------------------------------------------

          Logfile of random's system information tool 1.06 (written by random/random)
          Run by Fred at 2009-04-29 15:26:58
          Microsoft Windows XP Professionnel Service Pack 3
          System drive C: has 18 GB (48%) free of 38 GB
          Total RAM: 990 MB (15% free)

          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 15:27:07, on 29/04/2009
          Platform: Windows XP SP3 (WinNT 5.01.2600)
          MSIE: Internet Explorer v7.00 (7.00.6000.16827)
          Boot mode: Normal

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
          C:\WINDOWS\system32\spoolsv.exe
          C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
          C:\WINDOWS\Explorer.EXE
          C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
          C:\Program Files\Seagate\Basics\Service\SyncServicesBasics.exe
          C:\WINDOWS\system32\CSHelper.exe
          C:\Program Files\Java\jre6\bin\jqs.exe
          C:\Program Files\Sony\MD Simple Burner\NetMDSB.exe
          C:\WINDOWS\system32\nvsvc32.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\RUNDLL32.EXE
          C:\Program Files\Analog Devices\Core\smax4pnp.exe
          C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
          C:\Program Files\QuickTime\qttask.exe
          C:\Program Files\OmniPageSE\opware32.exe
          C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
          C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
          C:\Program Files\Google\Gmail Notifier\gnotify.exe
          C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe
          C:\Program Files\Seagate\Basics\Basics Status\MaxMenuMgrBasics.exe
          C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe
          C:\Program Files\Trust\Trust Keyboard 15036\PS2USBKbdDrv.exe
          C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
          C:\Program Files\Jetico\Jetico Personal Firewall\fwsrv.exe
          C:\Program Files\HomePlayer\HomePlayer.exe
          C:\Program Files\Java\jre6\bin\jusched.exe
          C:\WINDOWS\system32\ctfmon.exe
          C:\Program Files\ATnotes\ATnotes.exe
          C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe
          C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICCE.EXE
          C:\Program Files\Messenger\msmsgs.exe
          C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
          C:\Program Files\OpenOffice.org 2.1\program\soffice.exe
          C:\Program Files\OpenOffice.org 2.1\program\soffice.BIN
          C:\Program Files\Avira\AntiVir PersonalEdition Classic\avscan.exe
          C:\Program Files\Mozilla Firefox\firefox.exe
          C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
          C:\Documents and Settings\Fred\Bureau\RSIT.exe
          C:\Program Files\Trend Micro\HijackThis\Fred.exe

          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
          O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
          O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
          O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
          O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
          O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
          O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
          O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
          O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
          O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
          O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
          O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
          O4 - HKLM\..\Run: [Omnipage] C:\Program Files\OmniPageSE\opware32.exe
          O4 - HKLM\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
          O4 - HKLM\..\Run: [WireLessKeyboard] C:\Program Files\Trust\Trust Keyboard 15036\StartAutorun.exe PS2USBKbdDrv.exe
          O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
          O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
          O4 - HKLM\..\Run: [SMSTray] C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe
          O4 - HKLM\..\Run: [basicsmssmenu] "C:\Program Files\Seagate\Basics\Basics Status\MaxMenuMgrBasics.exe"
          O4 - HKLM\..\Run: [H2O] C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe
          O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
          O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
          O4 - HKLM\..\Run: [JeticoPFStartup] "C:\Program Files\Jetico\Jetico Personal Firewall\fwsrv.exe"
          O4 - HKLM\..\Run: [HomePlayer] C:\Program Files\HomePlayer\HomePlayer.exe
          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
          O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
          O4 - HKCU\..\Run: [ATnotes.exe] C:\Program Files\ATnotes\ATnotes.exe
          O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
          O4 - HKCU\..\Run: [DW6] "C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe"
          O4 - HKCU\..\Run: [EPSON Stylus D120 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICCE.EXE /FU "C:\WINDOWS\TEMP\E_S184.tmp" /EF "HKCU"
          O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
          O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
          O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
          O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
          O4 - Startup: OpenOffice.org 2.1.lnk = C:\Program Files\OpenOffice.org 2.1\program\quickstart.exe
          O4 - Startup: Outil de détection de support Picture Motion Browser.lnk = C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
          O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
          O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
          O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
          O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
          O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
          O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
          O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
          O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
          O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
          O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
          O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
          O23 - Service: Basics Service - Seagate Technology LLC - C:\Program Files\Seagate\Basics\Service\SyncServicesBasics.exe
          O23 - Service: CopySafe Helper Service (CSHelper) - Unknown owner - C:\WINDOWS\system32\CSHelper.exe
          O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
          O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Fichiers communs\Macromedia Shared\Service\Macromedia Licensing.exe
          O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\MSCSPTISRV.exe
          O23 - Service: MD Simple Burner Service (NetMDSB) - Sony Corporation - C:\Program Files\Sony\MD Simple Burner\NetMDSB.exe
          O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
          O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\PACSPTISVR.exe
          O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\SPTISRV.exe
          O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\SSScsiSV.exe
          0
          1. Contributeur sécurité
            ▶ Telecharge UsbFix de C_XX & Chiquitine29

            ▶ Lance l installation avec les parametres par default

            ▶ Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) suceptible d avoir été infectés sans les ouvrir

            ▶ Double clic sur le raccourci UsbFix sur ton bureau

            ▶ Choisi l'option 1 (recherche)

            ▶ Laisse travailler l'outil

            ▶ Ensuite post le rapport UsbFix.txt qui apparaîtra

            * Note : le rapport UsbFix.txt est sauvegardé a la racine du disque

            * Note : Si le Bureau ne réapparait pas presse Ctrl + Alt + Suppr , Onglet "Fichier" , "Nouvelle tâche" , tapes explorer.exe et valides

            * Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
            Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
            Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.
            0
            1. Re,
              Voici le rapport d'usbfix
              a+
              merci encore

              ############################## [ UsbFix V3.014 ]

              # User : Fred (Administrateurs) # DIAZ-E439AB2F45
              # Update on 27/04/09 by C_XX & Chiquitine29
              # Start at: 17:32:32 | 29/04/2009

              # AMD Athlon(tm) 64 Processor 3800+
              # Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 3
              # Internet Explorer 7.0.5730.11
              # Windows Firewall Status : Enabled
              # AV : Avira AntiVir PersonalEdition 8.0.1.30 [ Enabled | Updated ]

              # A:\ # Lecteur de disquettes 3 ½ pouces
              # C:\ # Disque fixe local # 37,26 Go (17,94 Go free) [SYSTEME] # NTFS
              # D:\ # Disque CD-ROM
              # E:\ # Disque CD-ROM # 0 Mo (0 Mo free) [Audio CD] # CDFS
              # F:\ # Disque fixe local # 465,76 Go (319,2 Go free) [FreeAgent Drive] # NTFS
              # G:\ # Disque fixe local # 233,7 Go (21,12 Go free) [DONNEES] # FAT32
              # H:\ # Disque amovible # 3,84 Go (1,71 Go free) [UDISK 2.0] # FAT32

              ############################## [ Processus actifs ]

              C:\WINDOWS\System32\smss.exe
              C:\WINDOWS\system32\csrss.exe
              C:\WINDOWS\system32\winlogon.exe
              C:\WINDOWS\system32\services.exe
              C:\WINDOWS\system32\lsass.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\system32\svchost.exe
              C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
              C:\WINDOWS\system32\spoolsv.exe
              C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
              C:\WINDOWS\Explorer.EXE
              C:\WINDOWS\system32\svchost.exe
              C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
              C:\Program Files\Seagate\Basics\Service\SyncServicesBasics.exe
              C:\WINDOWS\system32\CSHelper.exe
              C:\Program Files\Java\jre6\bin\jqs.exe
              C:\Program Files\Sony\MD Simple Burner\NetMDSB.exe
              C:\WINDOWS\system32\nvsvc32.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\system32\RUNDLL32.EXE
              C:\Program Files\Analog Devices\Core\smax4pnp.exe
              C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
              C:\Program Files\QuickTime\qttask.exe
              C:\Program Files\OmniPageSE\opware32.exe
              C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
              C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
              C:\Program Files\Google\Gmail Notifier\gnotify.exe
              C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe
              C:\Program Files\Seagate\Basics\Basics Status\MaxMenuMgrBasics.exe
              C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe
              C:\Program Files\Trust\Trust Keyboard 15036\PS2USBKbdDrv.exe
              C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
              C:\Program Files\Jetico\Jetico Personal Firewall\fwsrv.exe
              C:\Program Files\HomePlayer\HomePlayer.exe
              C:\Program Files\Java\jre6\bin\jusched.exe
              C:\WINDOWS\system32\ctfmon.exe
              C:\Program Files\ATnotes\ATnotes.exe
              C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe
              C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICCE.EXE
              C:\Program Files\Messenger\msmsgs.exe
              C:\WINDOWS\System32\alg.exe
              C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
              C:\Program Files\OpenOffice.org 2.1\program\soffice.exe
              C:\Program Files\OpenOffice.org 2.1\program\soffice.BIN
              C:\Program Files\Avira\AntiVir PersonalEdition Classic\avscan.exe
              C:\Program Files\Mozilla Firefox\firefox.exe
              C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
              C:\WINDOWS\system32\NOTEPAD.EXE
              C:\WINDOWS\system32\NOTEPAD.EXE
              C:\WINDOWS\system32\wbem\wmiprvse.exe

              ################## [ Registre # Startup ]

              HKCU_Main: "Local Page"="C:\\WINDOWS\\system32\\blank.htm"
              HKCU_Main: "Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
              HKCU_Main: "Start Page"="https://www.google.com/?gws_rd=ssl"
              HKLM_logon: "Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
              HKLM_logon: "DefaultUserName"="Fred"
              HKLM_logon: "AltDefaultUserName"="Fred"
              HKLM_logon: "LegalNoticeCaption"=""
              HKLM_logon: "LegalNoticeText"=""
              HKLM_Run: NvCplDaemon=RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
              HKLM_Run: nwiz=nwiz.exe /install
              HKLM_Run: NvMediaCenter=RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
              HKLM_Run: High Definition Audio Property Page Shortcut=HDAShCut.exe
              HKLM_Run: SoundMAXPnP=C:\Program Files\Analog Devices\Core\smax4pnp.exe
              HKLM_Run: SoundMAX="C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
              HKLM_Run: QuickTime Task="C:\Program Files\QuickTime\qttask.exe" -atboottime
              HKLM_Run: Omnipage=C:\Program Files\OmniPageSE\opware32.exe
              HKLM_Run: SsAAD.exe=C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
              HKLM_Run: WireLessKeyboard=C:\Program Files\Trust\Trust Keyboard 15036\StartAutorun.exe PS2USBKbdDrv.exe
              HKLM_Run: TkBellExe="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
              HKLM_Run: {0228e555-4f9c-4e35-a3ec-b109a192b4c2}=C:\Program Files\Google\Gmail Notifier\gnotify.exe
              HKLM_Run: SMSTray=C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe
              HKLM_Run: basicsmssmenu="C:\Program Files\Seagate\Basics\Basics Status\MaxMenuMgrBasics.exe"
              HKLM_Run: H2O=C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe
              HKLM_Run: Adobe Reader Speed Launcher="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
              HKLM_Run: avgnt="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
              HKLM_Run: JeticoPFStartup="C:\Program Files\Jetico\Jetico Personal Firewall\fwsrv.exe"
              HKLM_Run: HomePlayer=C:\Program Files\HomePlayer\HomePlayer.exe
              HKLM_Run: SunJavaUpdateSched="C:\Program Files\Java\jre6\bin\jusched.exe"
              HKLM_Run: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents=
              HKCU_Run: CTFMON.EXE=C:\WINDOWS\system32\ctfmon.exe
              HKCU_Run: ATnotes.exe=C:\Program Files\ATnotes\ATnotes.exe
              HKCU_Run: Skype="C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
              HKCU_Run: DW6="C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe"
              HKCU_Run: EPSON Stylus D120 Series=C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICCE.EXE /FU "C:\WINDOWS\TEMP\E_S184.tmp" /EF "HKCU"
              HKCU_Run: MSMSGS="C:\Program Files\Messenger\msmsgs.exe" /background

              ################## [ Informations ]

              ################## [ Fichiers # Dossiers infectieux ]

              Found ! F:\autorun.inf
              H:\autorun.inf # -> fichier appelé : "H:\1ogf.exe" ( absent ! )
              Found ! H:\autorun.inf

              ################## [ Registre # Clés Run infectieuses ]

              ################## [ Registre # Mountpoints2 ]

              HKCU\Software\Microsoft\....\MountPoints2\{e8c971be-4b69-11dc-8a14-0018f3452137}\Shell\AutoRun\command
              HKCU\Software\Microsoft\....\MountPoints2\{e8c971be-4b69-11dc-8a14-0018f3452137}\Shell\open\Command

              ################## [ ! Fin du rapport # UsbFix V3.014 ! ]
              0
              1. Contributeur sécurité
                ▶ Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptible d avoir été infectés sans les ouvrir

                ▶ Double clic sur le raccourci UsbFix présent sur ton bureau

                ▶ choisi l'option 2 ( Suppression )

                ▶ Ton bureau disparaîtra et le pc redémarrera .

                ▶ Au redémarrage , UsbFix scannera ton pc , laisse travailler l'outil.

                ▶ Ensuite post le rapport UsbFix.txt qui apparaîtra avec le bureau .

                ▶ Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque.( C:\UsbFix.txt )

                ( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )
                0
                1. Re

                  Ci dessous le rapport demandé

                  Merci

                  ############################## [ UsbFix V3.014 ]

                  # User : Fred (Administrateurs) # DIAZ-E439AB2F45
                  # Update on 27/04/09 by C_XX & Chiquitine29
                  # Start at: 00:11:57 | 30/04/2009

                  # AMD Athlon(tm) 64 Processor 3800+
                  # Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 3
                  # Internet Explorer 7.0.5730.11
                  # Windows Firewall Status : Enabled
                  # AV : Avira AntiVir PersonalEdition 8.0.1.30 [ Enabled | Updated ]

                  # A:\ # Lecteur de disquettes 3 ½ pouces
                  # C:\ # Disque fixe local # 37,26 Go (17,93 Go free) [SYSTEME] # NTFS
                  # D:\ # Disque CD-ROM
                  # E:\ # Disque CD-ROM # 0 Mo (0 Mo free) [Audio CD] # CDFS
                  # F:\ # Disque fixe local # 465,76 Go (319,2 Go free) [FreeAgent Drive] # NTFS
                  # G:\ # Disque fixe local # 233,7 Go (21,12 Go free) [DONNEES] # FAT32
                  # H:\ # Disque amovible # 3,84 Go (1,71 Go free) [UDISK 2.0] # FAT32

                  ############################## [ Processus actifs ]

                  C:\WINDOWS\System32\smss.exe
                  C:\WINDOWS\system32\csrss.exe
                  C:\WINDOWS\system32\winlogon.exe
                  C:\WINDOWS\system32\services.exe
                  C:\WINDOWS\system32\lsass.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\system32\logonui.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
                  C:\WINDOWS\system32\spoolsv.exe
                  C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                  C:\Program Files\Seagate\Basics\Service\SyncServicesBasics.exe
                  C:\WINDOWS\system32\CSHelper.exe
                  C:\Program Files\Java\jre6\bin\jqs.exe
                  C:\Program Files\Sony\MD Simple Burner\NetMDSB.exe
                  C:\WINDOWS\system32\nvsvc32.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\System32\alg.exe
                  C:\WINDOWS\system32\wbem\wmiapsrv.exe
                  C:\WINDOWS\system32\userinit.exe
                  C:\WINDOWS\Explorer.EXE
                  C:\WINDOWS\system32\wbem\wmiprvse.exe
                  C:\WINDOWS\system32\wbem\wmiprvse.exe

                  ################## [ Fichiers # Dossiers infectieux ]

                  Deleted ! F:\autorun.inf
                  H:\autorun.inf # -> fichier appelé : "H:\1ogf.exe" ( absent ! )
                  Deleted ! H:\autorun.inf

                  ################## [ Registre # Clés Run infectieuses ]

                  ################## [ Registre # Mountpoints2 ]

                  # -> Not Found !

                  ################## [ Listing des fichiers présent ]

                  [04/01/2007 13:08|--a------|0] - C:\AUTOEXEC.BAT
                  [04/01/2007 13:03|---hs----|212] - C:\boot.ini
                  [02/03/2006 14:00|-rahs----|4952] - C:\Bootfont.bin
                  [04/01/2007 13:08|--a------|0] - C:\CONFIG.SYS
                  [04/01/2007 13:08|-rahs----|0] - C:\IO.SYS
                  [04/01/2007 13:08|-rahs----|0] - C:\MSDOS.SYS
                  [02/03/2006 14:00|-rahs----|47564] - C:\NTDETECT.COM
                  [25/11/2008 00:37|-rahs----|252240] - C:\ntldr
                  [?|?|?] - C:\pagefile.sys
                  [30/04/2009 00:13|--a------|2808] - C:\UsbFix.txt
                  [01/01/1995 02:00|-r-------|44] - E:\Track01.cda
                  [01/01/1995 02:05|-r-------|44] - E:\Track02.cda
                  [01/01/1995 02:10|-r-------|44] - E:\Track03.cda
                  [01/01/1995 02:15|-r-------|44] - E:\Track04.cda
                  [01/01/1995 02:21|-r-------|44] - E:\Track05.cda
                  [01/01/1995 02:24|-r-------|44] - E:\Track06.cda
                  [01/01/1995 02:29|-r-------|44] - E:\Track07.cda
                  [01/01/1995 02:34|-r-------|44] - E:\Track08.cda
                  [01/01/1995 02:39|-r-------|44] - E:\Track09.cda
                  [01/01/1995 02:44|-r-------|44] - E:\Track10.cda
                  [01/01/1995 02:47|-r-------|44] - E:\Track11.cda
                  [01/01/1995 02:54|-r-------|44] - E:\Track12.cda
                  [31/10/2006 11:39|--a------|22486] - F:\FreeAgentDesktop.ico
                  [23/02/2008 02:42|--a------|132400] - F:\Launch.exe
                  [23/02/2008 02:42|--a------|388] - F:\Launch.ini
                  [23/02/2008 03:51|--a------|26214400] - F:\Mac Installer.dmg
                  [26/03/2006 23:12|--a------|140857] - G:\acceuilsite.jpg
                  [07/06/2007 18:05|--ah-----|3188] - G:\ZbThumbnail.info
                  [04/11/2008 18:18|--ahs----|5120] - G:\Thumbs.db
                  [12/04/2009 15:50|--a------|20894] - G:\video.pass
                  [07/04/2009 21:47|--a------|2550578] - H:\stage-auch-nbimpression.jpg
                  [07/04/2009 21:41|--a------|2763305] - H:\stage-auch-verso-nbimpression.jpg

                  ################## [ Vaccination ]

                  # C:\autorun.inf -> Folder created by UsbFix.
                  # F:\autorun.inf -> Folder created by UsbFix.
                  # G:\autorun.inf -> Folder created by UsbFix.
                  # H:\autorun.inf -> Folder created by UsbFix.

                  ################## [ Cracks / Keygens / Serials ]

                  # -> Nothing found !

                  ################## [ ! Fin du rapport # UsbFix V3.014 ! ]
                  0
                  1. Contributeur sécurité
                    Bonjour,

                    refais encore une fois l'option 1 de UsbFix pour vérifier stp
                    0
                    1. salut

                      voila pour ça
                      merci beaucoup pour ton temps

                      ############################## [ UsbFix V3.014 ]

                      # User : Fred (Administrateurs) # DIAZ-E439AB2F45
                      # Update on 27/04/09 by C_XX & Chiquitine29
                      # Start at: 12:41:07 | 30/04/2009

                      # AMD Athlon(tm) 64 Processor 3800+
                      # Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 3
                      # Internet Explorer 7.0.5730.11
                      # Windows Firewall Status : Enabled
                      # AV : Avira AntiVir PersonalEdition 8.0.1.30 [ Enabled | Updated ]

                      # A:\ # Lecteur de disquettes 3 ½ pouces
                      # C:\ # Disque fixe local # 37,26 Go (17,91 Go free) [SYSTEME] # NTFS
                      # D:\ # Disque CD-ROM # 4,32 Go (0 Mo free) [080531_1320] # UDF
                      # E:\ # Disque CD-ROM
                      # F:\ # Disque fixe local # 465,76 Go (319,13 Go free) [FreeAgent Drive] # NTFS
                      # G:\ # Disque fixe local # 233,7 Go (20,36 Go free) [DONNEES] # FAT32
                      # H:\ # Disque amovible # 3,84 Go (1,71 Go free) [UDISK 2.0] # FAT32

                      ############################## [ Processus actifs ]

                      C:\WINDOWS\System32\smss.exe
                      C:\WINDOWS\system32\csrss.exe
                      C:\WINDOWS\system32\winlogon.exe
                      C:\WINDOWS\system32\services.exe
                      C:\WINDOWS\system32\lsass.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
                      C:\WINDOWS\Explorer.EXE
                      C:\WINDOWS\system32\spoolsv.exe
                      C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                      C:\WINDOWS\system32\RUNDLL32.EXE
                      C:\Program Files\Analog Devices\Core\smax4pnp.exe
                      C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
                      C:\Program Files\QuickTime\qttask.exe
                      C:\Program Files\OmniPageSE\opware32.exe
                      C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
                      C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                      C:\Program Files\Google\Gmail Notifier\gnotify.exe
                      C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\Program Files\Seagate\Basics\Basics Status\MaxMenuMgrBasics.exe
                      C:\Program Files\Trust\Trust Keyboard 15036\PS2USBKbdDrv.exe
                      C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe
                      C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                      C:\Program Files\Java\jre6\bin\jusched.exe
                      C:\WINDOWS\system32\ctfmon.exe
                      C:\Program Files\HomePlayer\HomePlayer.exe
                      C:\Program Files\ATnotes\ATnotes.exe
                      C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe
                      C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICCE.EXE
                      C:\Program Files\Messenger\msmsgs.exe
                      C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                      C:\Program Files\Seagate\Basics\Service\SyncServicesBasics.exe
                      C:\Program Files\OpenOffice.org 2.1\program\soffice.exe
                      C:\Program Files\OpenOffice.org 2.1\program\soffice.BIN
                      C:\WINDOWS\system32\CSHelper.exe
                      C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
                      C:\Program Files\Java\jre6\bin\jqs.exe
                      C:\Program Files\Sony\MD Simple Burner\NetMDSB.exe
                      C:\WINDOWS\system32\nvsvc32.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\System32\alg.exe
                      C:\WINDOWS\system32\wbem\wmiapsrv.exe
                      C:\Program Files\Mozilla Firefox\firefox.exe
                      C:\Program Files\Trillian\trillian.exe
                      C:\Program Files\Adobe\Photoshop 7.0\Photoshop.exe
                      C:\Program Files\Jetico\Jetico Personal Firewall\fwsrv.exe
                      C:\WINDOWS\system32\wbem\wmiprvse.exe

                      ################## [ Registre # Startup ]

                      HKCU_Main: "Local Page"="C:\\WINDOWS\\system32\\blank.htm"
                      HKCU_Main: "Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
                      HKCU_Main: "Start Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
                      HKCU_Main: "Window Title"=""
                      HKLM_logon: "Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
                      HKLM_logon: "DefaultUserName"="Fred"
                      HKLM_logon: "AltDefaultUserName"="Fred"
                      HKLM_logon: "LegalNoticeCaption"=""
                      HKLM_logon: "LegalNoticeText"=""
                      HKLM_Run: NvCplDaemon=RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                      HKLM_Run: nwiz=nwiz.exe /install
                      HKLM_Run: NvMediaCenter=RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
                      HKLM_Run: High Definition Audio Property Page Shortcut=HDAShCut.exe
                      HKLM_Run: SoundMAXPnP=C:\Program Files\Analog Devices\Core\smax4pnp.exe
                      HKLM_Run: SoundMAX="C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
                      HKLM_Run: QuickTime Task="C:\Program Files\QuickTime\qttask.exe" -atboottime
                      HKLM_Run: Omnipage=C:\Program Files\OmniPageSE\opware32.exe
                      HKLM_Run: SsAAD.exe=C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
                      HKLM_Run: WireLessKeyboard=C:\Program Files\Trust\Trust Keyboard 15036\StartAutorun.exe PS2USBKbdDrv.exe
                      HKLM_Run: TkBellExe="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                      HKLM_Run: {0228e555-4f9c-4e35-a3ec-b109a192b4c2}=C:\Program Files\Google\Gmail Notifier\gnotify.exe
                      HKLM_Run: SMSTray=C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe
                      HKLM_Run: basicsmssmenu="C:\Program Files\Seagate\Basics\Basics Status\MaxMenuMgrBasics.exe"
                      HKLM_Run: H2O=C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe
                      HKLM_Run: Adobe Reader Speed Launcher="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                      HKLM_Run: avgnt="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                      HKLM_Run: JeticoPFStartup="C:\Program Files\Jetico\Jetico Personal Firewall\fwsrv.exe"
                      HKLM_Run: HomePlayer=C:\Program Files\HomePlayer\HomePlayer.exe
                      HKLM_Run: SunJavaUpdateSched="C:\Program Files\Java\jre6\bin\jusched.exe"
                      HKLM_Run: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents=
                      HKCU_Run: CTFMON.EXE=C:\WINDOWS\system32\ctfmon.exe
                      HKCU_Run: ATnotes.exe=C:\Program Files\ATnotes\ATnotes.exe
                      HKCU_Run: Skype="C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
                      HKCU_Run: DW6="C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe"
                      HKCU_Run: EPSON Stylus D120 Series=C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICCE.EXE /FU "C:\WINDOWS\TEMP\E_S184.tmp" /EF "HKCU"
                      HKCU_Run: MSMSGS="C:\Program Files\Messenger\msmsgs.exe" /background

                      ################## [ Informations ]

                      # C:\autorun.inf ( # Not infected ) -> Folder created by UsbFix.
                      # F:\autorun.inf ( # Not infected ) -> Folder created by UsbFix.
                      # G:\autorun.inf ( # Not infected ) -> Folder created by UsbFix.
                      # H:\autorun.inf ( # Not infected ) -> Folder created by UsbFix.

                      ################## [ Fichiers # Dossiers infectieux ]

                      ################## [ Registre # Clés Run infectieuses ]

                      ################## [ Registre # Mountpoints2 ]

                      # -> Not Found !

                      ################## [ ! Fin du rapport # UsbFix V3.014 ! ]
                      0
                      1. Contributeur sécurité
                        Ok maintenant :

                        ▶ Télécharge malwarebyte's anti-malware

                        ▶ Un tutoriel sera à ta disposition pour l'installer et l'utiliser correctement.

                        ▶ Fais la mise à jour du logiciel (elle se fait normalement à l'installation)

                        ▶ Lance une analyse complète en cliquant sur "Exécuter un examen complet"

                        ▶ Sélectionnes les disques que tu veux analyser et cliques sur "Lancer l'examen"

                        ▶ L'analyse peut durer un bon moment.....

                        ▶ Une fois l'analyse terminée, cliques sur "OK" puis sur "Afficher les résultats"

                        ▶ Vérifies que tout est bien coché et cliques sur "Supprimer la sélection" => et ensuite sur "OK"

                        ▶ Un rapport va s'ouvrir dans le bloc note... Fais un copié/collé du rapport dans ta prochaine réponse sur le forum

                        * Il se pourrait que certains fichiers devront être supprimés au redémarrage du PC... Faites le en cliquant sur "oui" à la question posée
                        0
                        1. Re,

                          Voila le rapport
                          merci

                          Malwarebytes' Anti-Malware 1.36
                          Version de la base de données: 2061
                          Windows 5.1.2600 Service Pack 3

                          30/04/2009 16:59:07
                          mbam-log-2009-04-30 (16-59-07).txt

                          Type de recherche: Examen complet (C:\|D:\|E:\|F:\|G:\|H:\|)
                          Eléments examinés: 350530
                          Temps écoulé: 2 hour(s), 34 minute(s), 32 second(s)

                          Processus mémoire infecté(s): 0
                          Module(s) mémoire infecté(s): 0
                          Clé(s) du Registre infectée(s): 0
                          Valeur(s) du Registre infectée(s): 0
                          Elément(s) de données du Registre infecté(s): 0
                          Dossier(s) infecté(s): 0
                          Fichier(s) infecté(s): 0

                          Processus mémoire infecté(s):
                          (Aucun élément nuisible détecté)

                          Module(s) mémoire infecté(s):
                          (Aucun élément nuisible détecté)

                          Clé(s) du Registre infectée(s):
                          (Aucun élément nuisible détecté)

                          Valeur(s) du Registre infectée(s):
                          (Aucun élément nuisible détecté)

                          Elément(s) de données du Registre infecté(s):
                          (Aucun élément nuisible détecté)

                          Dossier(s) infecté(s):
                          (Aucun élément nuisible détecté)

                          Fichier(s) infecté(s):
                          (Aucun élément nuisible détecté)
                          0
                          1. Contributeur sécurité
                            Fais une analyse complète avec Antivir et poste son rapport stp
                            0
                            1. re

                              voici le rapport antivir
                              merci

                              Avira AntiVir Personal
                              Report file date: jeudi 30 avril 2009 22:45

                              Scanning for 1373000 virus strains and unwanted programs.

                              Licensed to: Avira AntiVir PersonalEdition Classic
                              Serial number: 0000149996-ADJIE-0001
                              Platform: Windows XP
                              Windows version: (Service Pack 3) [5.1.2600]
                              Boot mode: Normally booted
                              Username: SYSTEM
                              Computer name: DIAZ-E439AB2F45

                              Version information:
                              BUILD.DAT : 8.2.0.348 16934 Bytes 23/03/2009 13:44:00
                              AVSCAN.EXE : 8.1.4.10 315649 Bytes 25/11/2008 15:09:44
                              AVSCAN.DLL : 8.1.4.0 40705 Bytes 26/05/2008 08:56:40
                              LUKE.DLL : 8.1.4.5 164097 Bytes 12/06/2008 13:44:19
                              LUKERES.DLL : 8.1.4.0 12033 Bytes 26/05/2008 08:58:52
                              ANTIVIR0.VDF : 7.1.0.0 15603712 Bytes 27/10/2008 15:08:48
                              ANTIVIR1.VDF : 7.1.2.12 3336192 Bytes 11/02/2009 21:51:48
                              ANTIVIR2.VDF : 7.1.3.137 1810944 Bytes 30/04/2009 20:43:45
                              ANTIVIR3.VDF : 7.1.3.139 8704 Bytes 30/04/2009 20:43:46
                              Engineversion : 8.2.0.160
                              AEVDF.DLL : 8.1.1.1 106868 Bytes 30/04/2009 20:43:47
                              AESCRIPT.DLL : 8.1.1.79 385403 Bytes 30/04/2009 20:43:46
                              AESCN.DLL : 8.1.1.10 127348 Bytes 03/04/2009 21:25:32
                              AERDL.DLL : 8.1.1.3 438645 Bytes 22/11/2008 15:08:55
                              AEPACK.DLL : 8.1.3.14 397685 Bytes 18/04/2009 17:45:42
                              AEOFFICE.DLL : 8.1.0.36 196987 Bytes 26/02/2009 22:24:15
                              AEHEUR.DLL : 8.1.0.122 1737080 Bytes 24/04/2009 17:46:10
                              AEHELP.DLL : 8.1.2.2 119158 Bytes 26/02/2009 22:24:10
                              AEGEN.DLL : 8.1.1.39 348532 Bytes 23/04/2009 17:46:42
                              AEEMU.DLL : 8.1.0.9 393588 Bytes 14/10/2008 11:05:56
                              AECORE.DLL : 8.1.6.9 176500 Bytes 14/04/2009 21:25:56
                              AEBB.DLL : 8.1.0.3 53618 Bytes 14/10/2008 11:05:56
                              AVWINLL.DLL : 1.0.0.12 15105 Bytes 09/07/2008 09:40:05
                              AVPREF.DLL : 8.0.2.0 38657 Bytes 16/05/2008 10:28:01
                              AVREP.DLL : 8.0.0.3 155688 Bytes 20/04/2009 17:45:31
                              AVREG.DLL : 8.0.0.1 33537 Bytes 09/05/2008 12:26:40
                              AVARKT.DLL : 1.0.0.23 307457 Bytes 12/02/2008 09:29:23
                              AVEVTLOG.DLL : 8.0.0.16 119041 Bytes 12/06/2008 13:27:49
                              SQLITE3.DLL : 3.3.17.1 339968 Bytes 22/01/2008 18:28:02
                              SMTPLIB.DLL : 1.2.0.23 28929 Bytes 12/06/2008 13:49:40
                              NETNT.DLL : 8.0.0.1 7937 Bytes 25/01/2008 13:05:10
                              RCIMAGE.DLL : 8.0.0.51 2371841 Bytes 12/06/2008 14:48:07
                              RCTEXT.DLL : 8.0.52.0 86273 Bytes 27/06/2008 14:34:37

                              Configuration settings for the scan:
                              Jobname..........................: Complete system scan
                              Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
                              Logging..........................: low
                              Primary action...................: interactive
                              Secondary action.................: ignore
                              Scan master boot sector..........: on
                              Scan boot sector.................: on
                              Boot sectors.....................: C:, F:, G:,
                              Process scan.....................: on
                              Scan registry....................: on
                              Search for rootkits..............: off
                              Scan all files...................: Intelligent file selection
                              Scan archives....................: on
                              Recursion depth..................: 20
                              Smart extensions.................: on
                              Macro heuristic..................: on
                              File heuristic...................: medium

                              Start of the scan: jeudi 30 avril 2009 22:45

                              The scan of running processes will be started
                              Scan process 'avscan.exe' - '1' Module(s) have been scanned
                              Scan process 'avcenter.exe' - '1' Module(s) have been scanned
                              Scan process 'avgnt.exe' - '1' Module(s) have been scanned
                              Scan process 'firefox.exe' - '1' Module(s) have been scanned
                              Scan process 'notepad.exe' - '1' Module(s) have been scanned
                              Scan process 'trillian.exe' - '1' Module(s) have been scanned
                              Scan process 'wmiapsrv.exe' - '1' Module(s) have been scanned
                              Scan process 'alg.exe' - '1' Module(s) have been scanned
                              Scan process 'svchost.exe' - '1' Module(s) have been scanned
                              Scan process 'nvsvc32.exe' - '1' Module(s) have been scanned
                              Scan process 'NetMDSB.exe' - '1' Module(s) have been scanned
                              Scan process 'jqs.exe' - '1' Module(s) have been scanned
                              Scan process 'SPUVolumeWatcher.exe' - '1' Module(s) have been scanned
                              Scan process 'CSHelper.exe' - '1' Module(s) have been scanned
                              Scan process 'soffice.bin' - '1' Module(s) have been scanned
                              Scan process 'soffice.exe' - '1' Module(s) have been scanned
                              Scan process 'SyncServicesBasics.exe' - '1' Module(s) have been scanned
                              Scan process 'avguard.exe' - '1' Module(s) have been scanned
                              Scan process 'msmsgs.exe' - '1' Module(s) have been scanned
                              Scan process 'E_FATICCE.EXE' - '1' Module(s) have been scanned
                              Scan process 'DesktopWeather.exe' - '1' Module(s) have been scanned
                              Scan process 'ATnotes.exe' - '1' Module(s) have been scanned
                              Scan process 'HomePlayer.exe' - '1' Module(s) have been scanned
                              Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
                              Scan process 'jusched.exe' - '1' Module(s) have been scanned
                              Scan process 'cledx.exe' - '1' Module(s) have been scanned
                              Scan process 'PS2USBKbdDrv.exe' - '1' Module(s) have been scanned
                              Scan process 'MaxMenuMgrBasics.exe' - '1' Module(s) have been scanned
                              Scan process 'svchost.exe' - '1' Module(s) have been scanned
                              Scan process 'SMSTray.exe' - '1' Module(s) have been scanned
                              Scan process 'realsched.exe' - '1' Module(s) have been scanned
                              Scan process 'SSAAD.exe' - '1' Module(s) have been scanned
                              Scan process 'opware32.exe' - '1' Module(s) have been scanned
                              Scan process 'qttask.exe' - '1' Module(s) have been scanned
                              Scan process 'SMax4.exe' - '1' Module(s) have been scanned
                              Scan process 'smax4pnp.exe' - '1' Module(s) have been scanned
                              Scan process 'rundll32.exe' - '1' Module(s) have been scanned
                              Scan process 'sched.exe' - '1' Module(s) have been scanned
                              Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
                              Scan process 'explorer.exe' - '1' Module(s) have been scanned
                              Scan process 'aawservice.exe' - '1' Module(s) have been scanned
                              Scan process 'svchost.exe' - '1' Module(s) have been scanned
                              Scan process 'svchost.exe' - '1' Module(s) have been scanned
                              Scan process 'svchost.exe' - '1' Module(s) have been scanned
                              Scan process 'svchost.exe' - '1' Module(s) have been scanned
                              Scan process 'svchost.exe' - '1' Module(s) have been scanned
                              Scan process 'svchost.exe' - '1' Module(s) have been scanned
                              Scan process 'lsass.exe' - '1' Module(s) have been scanned
                              Scan process 'services.exe' - '1' Module(s) have been scanned
                              Scan process 'winlogon.exe' - '1' Module(s) have been scanned
                              Scan process 'csrss.exe' - '1' Module(s) have been scanned
                              Scan process 'smss.exe' - '1' Module(s) have been scanned
                              52 processes with 52 modules were scanned

                              Starting master boot sector scan:
                              Master boot sector HD0
                              [INFO] No virus was found!
                              Master boot sector HD1
                              [INFO] No virus was found!
                              Master boot sector HD2
                              [INFO] No virus was found!

                              Start scanning boot sectors:
                              Boot sector 'C:\'
                              [INFO] No virus was found!
                              Boot sector 'F:\'
                              [INFO] No virus was found!
                              Boot sector 'G:\'
                              [INFO] No virus was found!

                              Starting to scan the registry.
                              The registry was scanned ( '61' files ).

                              Starting the file scan:

                              Begin scan in 'C:\' <SYSTEME>
                              C:\pagefile.sys
                              [WARNING] The file could not be opened!
                              Begin scan in 'F:\' <FreeAgent Drive>
                              Begin scan in 'G:\' <DONNEES>

                              End of the scan: vendredi 1 mai 2009 01:10
                              Used time: 2:25:13 Hour(s)

                              The scan has been done completely.

                              12216 Scanning directories
                              618183 Files were scanned
                              0 viruses and/or unwanted programs were found
                              0 Files were classified as suspicious:
                              0 files were deleted
                              0 files were repaired
                              0 files were moved to quarantine
                              0 files were renamed
                              1 Files cannot be scanned
                              618182 Files not concerned
                              4188 Archives were scanned
                              1 Warnings
                              0 Notes
                              0
                              1. Contributeur sécurité
                                Bonjour,

                                ton PC n'a pas l'air infecté...

                                ▶ Désactive ton antivirus

                                ▶ Rends toi sur ce site : https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr (avec Internet Explorer uniquement)

                                ▶ En bas à droite, clique sur Démarrer Online-scanner

                                ▶ Dans la nouvelle fenêtre qui s'affiche clique sur J'accepte

                                ▶ Accepte les Contrôle ActiveX

                                ▶ Choisis Poste de travail pour le scan.

                                ▶ Celui-ci terminé, sauvegarde le rapport (choisis fichier texte) et poste le dans ta prochaine réponse.

                                ▶ Pour t'aider à utiliser le scan en ligne, consulte ce tutoriel

                                NOTE : Si tu reçois le message "La licence de Kaspersky On-line Scanner est périmée", va dans Ajout/Suppression de programmes puis désinstalle On-Line Scanner, reconnecte toi sur le site de Kaspersky pour retenter le scan en ligne.
                                0
                                1. Re ,

                                  J'ai fait 2 analyses mais la première (analyse des zones critiques de l'ordi) je ne l'ai pas enregistré mais y'avait rien à signaler.
                                  Et la deuxieme de tous les disques(poste de travail) la voici ci dessous
                                  Merci

                                  -------------------------------------------------------------------------------
                                  KASPERSKY ON-LINE SCANNER REPORT
                                  Saturday, May 02, 2009 8:24:37 AM
                                  Système d'exploitation : Microsoft Windows XP Professional, Service Pack 3 (Build 2600)
                                  Kaspersky On-line Scanner version : 5.0.84.2
                                  Dernière mise à jour de la base antivirus Kaspersky : 1/05/2009
                                  Enregistrements dans la base antivirus Kaspersky : 2118498
                                  -------------------------------------------------------------------------------

                                  Paramètres d'analyse:
                                  Analyser avec la base antivirus suivante: étendue
                                  Analyser les archives: vrai
                                  Analyser les bases de messagerie: vrai

                                  Cible de l'analyse - Poste de travail:
                                  A:\
                                  C:\
                                  D:\
                                  E:\
                                  F:\
                                  G:\

                                  Statistiques de l'analyse:
                                  Total d'objets analysés: 258495
                                  Nombre de virus trouvés: 0
                                  Nombre d'objets infectés: 0 / 0
                                  Nombre d'objets suspects: 0
                                  Durée de l'analyse: 02:25:50

                                  Nom de l'objet infecté / Nom du virus / Dernière action
                                  C:\autorun.inf\lpt3.This folder was created by UsbFix L'objet est verrouillé ignoré
                                  C:\Documents and Settings\Fred\.homeplayer\homeplayer_log.txt L'objet est verrouillé ignoré
                                  C:\Documents and Settings\Fred\.homeplayer\hp_db\FreeBoxTV.sdb L'objet est verrouillé ignoré
                                  C:\Documents and Settings\Fred\.homeplayer\hp_db\HPDB_VERSION.sdb L'objet est verrouillé ignoré
                                  C:\Documents and Settings\Fred\.homeplayer\hp_db\MediaHistory.sdb L'objet est verrouillé ignoré
                                  C:\Documents and Settings\Fred\.homeplayer\hp_db\PlayListFreeBoxTV.sdb L'objet est verrouillé ignoré
                                  C:\Documents and Settings\Fred\.homeplayer\hp_db\PodcastChannel.sdb L'objet est verrouillé ignoré
                                  C:\Documents and Settings\Fred\.homeplayer\hp_db\RSSChannel.sdb L'objet est verrouillé ignoré
                                  C:\Documents and Settings\Fred\.homeplayer\hp_db\smallsql.master L'objet est verrouillé ignoré
                                  C:\Documents and Settings\Fred\.homeplayer\hp_db\TeleSite.sdb L'objet est verrouillé ignoré
                                  C:\Documents and Settings\Fred\.homeplayer\hp_db\TVChannel.sdb L'objet est verrouillé ignoré
                                  C:\Documents and Settings\Fred\.homeplayer\hp_db\TVProgram.lob L'objet est verrouillé ignoré
                                  C:\Documents and Settings\Fred\.homeplayer\hp_db\TVProgram.sdb L'objet est verrouillé ignoré
                                  C:\Documents and Settings\Fred\.homeplayer\hp_db\WEBClip.sdb L'objet est verrouillé ignoré
                                  C:\Documents and Settings\Fred\.homeplayer\hp_db\WEBRadio.sdb L'objet est verrouillé ignoré
                                  C:\Documents and Settings\Fred\.homeplayer\hp_db\WEBTV.sdb L'objet est verrouillé ignoré
                                  C:\Documents and Settings\Fred\.homeplayer\hp_db.lock L'objet est verrouillé ignoré
                                  C:\Documents and Settings\Fred\.homeplayer\webserver_access.log L'objet est verrouillé ignoré
                                  C:\Documents and Settings\Fred\Cookies\index.dat L'objet est verrouillé ignoré
                                  C:\Documents and Settings\Fred\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat L'objet est verrouillé ignoré
                                  C:\Documents and Settings\Fred\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat L'objet est verrouillé ignoré
                                  C:\Documents and Settings\Fred\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG L'objet est verrouillé ignoré
                                  C:\Documents and Settings\Fred\Local Settings\Historique\History.IE5\index.dat L'objet est verrouillé ignoré
                                  C:\Documents and Settings\Fred\Local Settings\Historique\History.IE5\MSHist012009050220090503\index.dat L'objet est verrouillé ignoré
                                  C:\Documents and Settings\Fred\Local Settings\Temp\hsperfdata_Fred\2724 L'objet est verrouillé ignoré
                                  C:\Documents and Settings\Fred\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat L'objet est verrouillé ignoré
                                  C:\Documents and Settings\Fred\Local Settings\Temporary Internet Files\Content.IE5\index.dat L'objet est verrouillé ignoré
                                  C:\Documents and Settings\Fred\NTUSER.DAT L'objet est verrouillé ignoré
                                  C:\Documents and Settings\Fred\ntuser.dat.LOG L'objet est verrouillé ignoré
                                  C:\Documents and Settings\LocalService\Cookies\index.dat L'objet est verrouillé ignoré
                                  C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat L'objet est verrouillé ignoré
                                  C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG L'objet est verrouillé ignoré
                                  C:\Documents and Settings\LocalService\Local Settings\Historique\History.IE5\index.dat L'objet est verrouillé ignoré
                                  C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat L'objet est verrouillé ignoré
                                  C:\Documents and Settings\LocalService\NTUSER.DAT L'objet est verrouillé ignoré
                                  C:\Documents and Settings\LocalService\ntuser.dat.LOG L'objet est verrouillé ignoré
                                  C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat L'objet est verrouillé ignoré
                                  C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG L'objet est verrouillé ignoré
                                  C:\Documents and Settings\NetworkService\NTUSER.DAT L'objet est verrouillé ignoré
                                  C:\Documents and Settings\NetworkService\ntuser.dat.LOG L'objet est verrouillé ignoré
                                  C:\System Volume Information\MountPointManagerRemoteDatabase L'objet est verrouillé ignoré
                                  C:\System Volume Information\_restore{2E54175D-AC0B-410B-8700-F76F872A8C43}\RP853\change.log L'objet est verrouillé ignoré
                                  C:\WINDOWS\Debug\PASSWD.LOG L'objet est verrouillé ignoré
                                  C:\WINDOWS\SchedLgU.Txt L'objet est verrouillé ignoré
                                  C:\WINDOWS\SoftwareDistribution\ReportingEvents.log L'objet est verrouillé ignoré
                                  C:\WINDOWS\Sti_Trace.log L'objet est verrouillé ignoré
                                  C:\WINDOWS\system32\CatRoot2\edb.log L'objet est verrouillé ignoré
                                  C:\WINDOWS\system32\CatRoot2\tmp.edb L'objet est verrouillé ignoré
                                  C:\WINDOWS\system32\config\AppEvent.Evt L'objet est verrouillé ignoré
                                  C:\WINDOWS\system32\config\default L'objet est verrouillé ignoré
                                  C:\WINDOWS\system32\config\DEFAULT.LOG L'objet est verrouillé ignoré
                                  C:\WINDOWS\system32\config\Internet.evt L'objet est verrouillé ignoré
                                  C:\WINDOWS\system32\config\SAM L'objet est verrouillé ignoré
                                  C:\WINDOWS\system32\config\SAM.LOG L'objet est verrouillé ignoré
                                  C:\WINDOWS\system32\config\SecEvent.Evt L'objet est verrouillé ignoré
                                  C:\WINDOWS\system32\config\SECURITY L'objet est verrouillé ignoré
                                  C:\WINDOWS\system32\config\SECURITY.LOG L'objet est verrouillé ignoré
                                  C:\WINDOWS\system32\config\software L'objet est verrouillé ignoré
                                  C:\WINDOWS\system32\config\SOFTWARE.LOG L'objet est verrouillé ignoré
                                  C:\WINDOWS\system32\config\SysEvent.Evt L'objet est verrouillé ignoré
                                  C:\WINDOWS\system32\config\system L'objet est verrouillé ignoré
                                  C:\WINDOWS\system32\config\SYSTEM.LOG L'objet est verrouillé ignoré
                                  C:\WINDOWS\system32\h323log.txt L'objet est verrouillé ignoré
                                  C:\WINDOWS\system32\LogFiles\WUDF\WUDFTrace.etl L'objet est verrouillé ignoré
                                  C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR L'objet est verrouillé ignoré
                                  C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP L'objet est verrouillé ignoré
                                  C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER L'objet est verrouillé ignoré
                                  C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP L'objet est verrouillé ignoré
                                  C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP L'objet est verrouillé ignoré
                                  C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA L'objet est verrouillé ignoré
                                  C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP L'objet est verrouillé ignoré
                                  C:\WINDOWS\Temp\Perflib_Perfdata_7fc.dat L'objet est verrouillé ignoré
                                  C:\WINDOWS\wiadebug.log L'objet est verrouillé ignoré
                                  C:\WINDOWS\wiaservc.log L'objet est verrouillé ignoré
                                  C:\WINDOWS\WindowsUpdate.log L'objet est verrouillé ignoré
                                  F:\autorun.inf\lpt3.This folder was created by UsbFix L'objet est verrouillé ignoré
                                  F:\System Volume Information\MountPointManagerRemoteDatabase L'objet est verrouillé ignoré
                                  G:\autorun.inf\lpt3.This folder was created by UsbFix L'objet est verrouillé ignoré

                                  Analyse terminée.
                                  0
                                  1. Contributeur sécurité
                                    Bonjour,

                                    ▶ Télécharger SDFix (créé par AndyManchesta) et sauvegarde le sur ton Bureau.

                                    ▶ Double cliquer sur SDFix.exe et choisir Install pour l'extraire dans un dossier dédié sur ton disque C:.

                                    /!\ Démarre en mode sans échec : après le bip et avant le logo windows tapoter sur la touche F8 (ou F5): menu M.S.E..

                                    ▶ Choisir son compte, pas celui de l'Administrateur ou autre.

                                    Dérouler la liste des instructions ci-dessous :

                                    • Ouvrir le dossier SDFix qui vient d'être créé dans le répertoire C:\ et double clique sur RunThis.bat pour lancer le script.
                                    • Appuyer sur Y pour commencer le processus de nettoyage.
                                    • Il va supprimer les services et les entrées du Registre de certains trojans trouvés puis te demandera d'appuyer sur une touche pour redémarrer.
                                    • Appuyer sur une touche pour redémarrer le PC.
                                    • Le système sera plus long pour redémarrer qu'à l'accoutumée car l'outil va continuer à s'exécuter et supprimer des fichiers.
                                    • Après le chargement du Bureau, l'outil terminera son travail et affichera Finished.
                                    • Appuyer sur une touche pour finir l'exécution du script et charger les icônes du Bureau.
                                    • Les icônes du Bureau affichées, le rapport SDFix s'ouvrira à l'écran et s'enregistrera aussi dans le dossier SDFix sous le nom Report.txt.
                                    • Enfin, copier/coller le contenu du fichier Report.txt dans la prochaine réponse sur le forum
                                    0
                                    1. Salut geoffrey

                                      Voila le rapport et j'ai comme l'impre'ssion que ça tourne pas mal?
                                      Merci
                                      A+

                                      [b]SDFix: Version 1.240 [/b]
                                      Run by Fred on 04/05/2009 at 01:06

                                      Microsoft Windows XP [version 5.1.2600]
                                      Running From: C:\SDFix

                                      [b]Checking Services [/b]:

                                      Restoring Default Security Values
                                      Restoring Default Hosts File

                                      Rebooting

                                      [b]Checking Files [/b]:

                                      No Trojan Files Found

                                      Removing Temp Files

                                      [b]ADS Check [/b]:

                                      [b]Final Check [/b]:

                                      catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                                      Rootkit scan 2009-05-04 01:13:42
                                      Windows 5.1.2600 Service Pack 3 NTFS

                                      scanning hidden processes ...

                                      scanning hidden services & system hive ...

                                      scanning hidden registry entries ...

                                      scanning hidden files ...

                                      scan completed successfully
                                      hidden processes: 0
                                      hidden services: 0
                                      hidden files: 0

                                      [b]Remaining Services [/b]:

                                      Authorized Application Key Export:

                                      [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
                                      "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
                                      "C:\\Program Files\\Trillian\\trillian.exe"="C:\\Program Files\\Trillian\\trillian.exe:*:Enabled:Trillian"
                                      "C:\\Program Files\\Macromedia\\Dreamweaver MX 2004\\Dreamweaver.exe"="C:\\Program Files\\Macromedia\\Dreamweaver MX 2004\\Dreamweaver.exe:*:Enabled:Dreamweaver MX 2004"
                                      "C:\\Program Files\\eMule\\emule.exe"="C:\\Program Files\\eMule\\emule.exe:*:Enabled:eMule"
                                      "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
                                      "C:\\Program Files\\Azureus\\Azureus.exe"="C:\\Program Files\\Azureus\\Azureus.exe:*:Enabled:Azureus"
                                      "C:\\Program Files\\OmniPageSE\\EregFre\\NAVBrowser.exe"="C:\\Program Files\\OmniPageSE\\EregFre\\NAVBrowser.exe:*:Enabled:NAVBrowser"
                                      "C:\\WINDOWS\\system32\\muzapp.exe"="C:\\WINDOWS\\system32\\muzapp.exe:*:Enabled:MUZ AOD APP player"
                                      "C:\\Documents and Settings\\Fred\\Local Settings\\Temp\\ImInstaller\\incredimail_installer.exe"="C:\\Documents and Settings\\Fred\\Local Settings\\Temp\\ImInstaller\\incredimail_installer.exe:*:Enabled:IncrediMail Installer"
                                      "C:\\Documents and Settings\\Fred\\Bureau\\Dames_-_DO_1.1.exe"="C:\\Documents and Settings\\Fred\\Bureau\\Dames_-_DO_1.1.exe:*:Enabled:Application MFC Dames"
                                      "C:\\Program Files\\HomePlayer\\HomePlayer.exe"="C:\\Program Files\\HomePlayer\\HomePlayer.exe:*:Enabled:HomePlayer"
                                      "C:\\Program Files\\HomePlayer\\VLC\\vlc.exe"="C:\\Program Files\\HomePlayer\\VLC\\vlc.exe:*:Enabled:VLC HomePlayer"
                                      "C:\\Program Files\\VLC\\vlc.exe"="C:\\Program Files\\VLC\\vlc.exe:*:Enabled:VLC media player"
                                      "C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype. The whole world can talk for free."

                                      [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
                                      "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
                                      "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

                                      [b]Remaining Files [/b]:

                                      [b]Files with Hidden Attributes [/b]:

                                      Wed 3 May 2006 163,328 ..SHR --- "C:\WINDOWS\system32\flvDX.dll"
                                      Sun 3 May 2009 10,022 A.SH. --- "C:\WINDOWS\system32\KGyGaAvL.sys"
                                      Wed 21 Feb 2007 31,232 ..SHR --- "C:\WINDOWS\system32\msfDX.dll"
                                      Mon 17 Dec 2007 27,648 ..SH. --- "C:\WINDOWS\system32\Smab0.dll"
                                      Mon 10 Mar 2008 4,348 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
                                      Sun 26 Jun 2005 616,448 ..SHR --- "C:\Program Files\eRightSoft\SUPER\cygwin1.dll"
                                      Tue 21 Jun 2005 45,568 ..SHR --- "C:\Program Files\eRightSoft\SUPER\cygz.dll"
                                      Fri 14 Mar 2008 13,824 A.SHR --- "C:\Program Files\eRightSoft\SUPER\DXdump.exe"
                                      Sat 9 Aug 2008 72,704 ..SHR --- "C:\Program Files\eRightSoft\SUPER\Setup.exe"
                                      Tue 2 Oct 2007 15,872 A.SHR --- "C:\Program Files\eRightSoft\SUPER\_Setup.dll"
                                      Wed 16 Jul 2008 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv02.tmp"
                                      Tue 4 Jun 2002 84,992 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\14_43260.dll"
                                      Tue 4 Jun 2002 44,032 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\28_83260.dll"
                                      Tue 10 Dec 2002 73,766 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\atrc3260.dll"
                                      Tue 10 Dec 2002 65,575 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\cook3260.dll"
                                      Sun 9 Jun 2002 36,864 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\ddnt3260.dll"
                                      Tue 4 Jun 2002 20,480 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\dnet3260.dll"
                                      Tue 10 Dec 2002 102,437 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\drv13260.dll"
                                      Tue 10 Dec 2002 176,165 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\drv23260.dll"
                                      Tue 10 Dec 2002 208,935 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\drv33260.dll"
                                      Tue 10 Dec 2002 217,127 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\drv43260.dll"
                                      Sun 9 Jun 2002 40,448 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\dspr3260.dll"
                                      Sun 4 Nov 2001 225,280 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\ivvideo.dll"
                                      Tue 10 Apr 2001 225,280 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\qtmlClient.dll"
                                      Fri 20 Feb 2004 232,960 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\raac.dll"
                                      Sun 9 Jun 2002 525,824 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\rnco3260.dll"
                                      Tue 10 Dec 2002 245,805 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\rnlt3260.dll"
                                      Tue 10 Dec 2002 45,093 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\rv103260.dll"
                                      Tue 10 Dec 2002 98,341 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\rv203260.dll"
                                      Tue 10 Dec 2002 94,247 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\rv303260.dll"
                                      Tue 10 Dec 2002 90,151 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\rv403260.dll"
                                      Tue 10 Dec 2002 102,439 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\sipr3260.dll"
                                      Sun 9 Jun 2002 49,152 ...HR --- "C:\Program Files\eRightSoft\SUPER\mencoder\tokr3260.dll"
                                      Thu 20 Mar 2008 5,632 ..SHR --- "C:\Program Files\eRightSoft\SUPER\spk\1stRun.exe"

                                      [b]Finished![/b]
                                      0
                                      1. Contributeur sécurité
                                        Est-ce que tu as le logiciel Spybot ??
                                        0
                                        1. salut

                                          Ca me dit quelque chose et j'ai du déjà l'installer mais je ne l'ai plus je pense
                                          En tout cas ni dans ajout et suppression de programmes ni dans program files
                                          J'ai adaware et Malwarebytes

                                          Merci
                                          0
                                          • 1
                                          • 2