Virus sur windows live "dear friend"

Bonjour,

voila le mail que j'ai recu et que TOUS mes contacts ont recu de ma part aujourd'hui.
C'est probablement un virus ? J'ai bit defender qui n'a pas l'air de réagir...
Que dois-je faire mis a part m'excuser aupres des tous mes contacts professionnels ;-) ...
Je précise que je n'y connais rien en ordinateur...

Le mail :
Dear friend:
We are an electronic products wholesale .Our products are of high quality and low price. If you want to do business , we can offer you the most reasonable discount to make you get more profits. We are expecting for your business.

Please visit our website: www.mydosell.com

Looking forward to your contact and long cooperation with us!
Our mainly products such the phones, PSP, display TV, notebook, video, computers, Mp4, GPS, xbox 360, digital cameras and so on.
Welcome to visit our website!
Mail : mydesell@vip.188.com
MSN : mydosell@hotmail.com

MERCI A VOUS, COMMUNAUTE COMPETENTE !
Configuration: Windows XP Edition Familiale 2002

25 réponses

Résumé de la discussion

Un utilisateur reçoit un mail suspect « Dear friend » qui semble être un virus, envoyé en masse à tous ses contacts, et l’antivirus Bitdefender ne réagit pas. Plusieurs réponses proposent des outils de désinfection et des tutoriels, notamment ComboFix et SDFix, avec avertissements sur la désactivation temporaire des protections et le fait de ne rien toucher pendant le scan. Des membres partagent ensuite des rapports et des extraits de ces outils (ComboFix, SDFix, GMER) montrant des fichiers suspects, des éléments d’autorisations et des traces de nettoyage, sans conclure sur une résolution. En cas de doute persistant, des discussions évoquent le recours à des nettoyages plus importants et le renforcement des mots de passe, mais aucune solution unique n’est évoquée.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    1
    1. Ben je suis désolée...J'ai creé un nouveau sujet car je n'avais plus d'infos...j'en ai tellement marre !
      J'ai passé plus de 6h et rien ne se passe. J'ai lancé ZapMessenger, mais il tourne depuis des heures et je ne sais pas si c'est normal...
      A chaque fois que je clique sur "nouveau" ou "repondre" le message commercial apparait. Je ne sais pas comment le faire disparaitre.
      0
  2. Contributeur sécurité
    tu vas passer combofix mais attention il est relativement puissant donc tu suis bien les consigne , tu ne touche pas au pc pendant qu'il travail sauf pour répondre , tu déactives tes protections car sinon il risque dev mal ou pas marché convenablement , tu prend le temps de lire le tutoriel officiels de fçon à mieux comprendre

    Télécharge Combofix.exe de sUBs sur ton Bureau;

    tutoriel officiel prend le temps de le lire : https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix

    http://download.bleepingcomputer.com/sUBs/ComboFix.exe

    Déconnectes toi d'internet et désactives ton antivirus pour que Combofix puisse s'exécuter normalement.

    Doubles clique sur Combofix.exe
    Mets le en langue française F
    Tape sur la touche 1 (Yes) pour démarrer le scan.

    tu Ne touches à rien tant que le scan n'est pas terminé.

    En fin de scan, il est possible que ComboFix ait besoin de redémarrer le PC pour finaliser la désinfection, laisse-le faire.

    Une fois le scan achevé, un rapport va s'afficher : Poste son contenu et un nouveau rapport HijackThis

    Réactives la protection en temps réel de ton Antivirus et de tes Antispywares, avant de te reconnecter à Internet.

    Note : Le rapport se trouve également là : C:\Combofix.txt
    1
    1. ComboFix 09-05-09.05 - Hélène Gautier 10/05/2009 18:04.1 - NTFSx86
      Microsoft Windows XP Édition familiale 5.1.2600.3.1252.33.1036.18.511.247 [GMT 2:00]
      Lancé depuis: c:\documents and settings\Hélène Gautier\Bureau\ComboFix.exe
      AV: Antivirus BitDefender *On-access scanning disabled* (Updated)
      FW: Pare-feu BitDefender *disabled*
      .

      (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
      .

      c:\program files\INSTALL.LOG
      c:\program files\webhancer
      c:\program files\webhancer\Programs\license.txt
      c:\program files\webhancer\Programs\whAgent.ini
      c:\windows\patch.exe
      c:\windows\system32\Lma.dll
      c:\windows\system32\Process.exe
      c:\windows\system32\UpMedia

      .
      ((((((((((((((((((((((((((((( Fichiers créés du 2009-04-10 au 2009-05-10 ))))))))))))))))))))))))))))))))))))
      .

      2009-05-09 19:52 . 2009-05-09 19:52 579584 -c--a-w c:\windows\system32\dllcache\user32.dll
      2009-05-09 19:48 . 2009-05-09 19:49 -------- d-----w c:\windows\ERUNT
      2009-05-09 19:44 . 2009-05-09 20:18 -------- d-----w C:\SDFix
      2009-05-09 17:55 . 2009-05-09 20:27 -------- d-----w c:\program files\trend micro
      2009-05-09 17:55 . 2009-05-09 17:56 -------- d-----w C:\rsit
      2009-04-27 15:23 . 2009-04-27 15:25 -------- d-----w C:\a3d0e4c57a646bda6b1b8698
      2009-04-14 17:07 . 2009-02-06 10:10 227840 -c----w c:\windows\system32\dllcache\wmiprvse.exe
      2009-04-14 17:07 . 2009-03-06 14:20 286720 -c----w c:\windows\system32\dllcache\pdh.dll
      2009-04-14 17:07 . 2009-02-09 11:23 111104 -c----w c:\windows\system32\dllcache\services.exe
      2009-04-14 17:07 . 2009-02-09 10:53 401408 -c----w c:\windows\system32\dllcache\rpcss.dll
      2009-04-14 17:07 . 2009-02-09 10:53 473600 -c----w c:\windows\system32\dllcache\fastprox.dll
      2009-04-14 17:07 . 2009-02-09 10:53 685568 -c----w c:\windows\system32\dllcache\advapi32.dll
      2009-04-14 17:07 . 2009-02-09 10:53 735744 -c----w c:\windows\system32\dllcache\lsasrv.dll
      2009-04-14 17:07 . 2009-02-09 10:53 453120 -c----w c:\windows\system32\dllcache\wmiprvsd.dll
      2009-04-14 17:07 . 2009-02-09 10:53 739840 -c----w c:\windows\system32\dllcache\ntdll.dll
      2009-04-14 17:06 . 2008-12-16 12:31 354304 -c----w c:\windows\system32\dllcache\winhttp.dll
      2009-04-14 17:05 . 2008-04-21 21:15 219136 -c----w c:\windows\system32\dllcache\wordpad.exe
      2009-04-11 12:46 . 2009-04-11 12:47 -------- d-----w c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
      2009-04-11 12:46 . 2009-04-11 12:47 -------- d-----w c:\program files\iTunes

      .
      (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
      .
      2009-05-10 14:12 . 2006-08-01 18:06 81984 ----a-w c:\windows\system32\bdod.bin
      2009-05-05 19:52 . 2006-01-12 13:56 87540 ----a-w c:\windows\system32\perfc00C.dat
      2009-05-05 19:52 . 2006-01-12 13:56 516210 ----a-w c:\windows\system32\perfh00C.dat
      2009-04-12 11:36 . 2006-10-29 18:42 -------- d-----w c:\program files\Incomplete
      2009-04-11 21:01 . 2006-10-10 08:48 -------- d-----w c:\program files\LimeWire
      2009-04-11 12:46 . 2007-08-27 09:32 -------- d-----w c:\program files\iPod
      2009-04-11 12:46 . 2007-06-29 21:14 -------- d-----w c:\program files\Fichiers communs\Apple
      2009-04-09 16:54 . 2009-03-11 20:07 5632 ----a-w c:\windows\system32\drivers\StarOpen.sys
      2009-04-09 16:34 . 2006-01-12 15:14 -------- d--h--w c:\program files\InstallShield Installation Information
      2009-04-06 18:00 . 2009-01-05 16:40 104328 ----a-w c:\windows\system32\drivers\bdfndisf.sys
      2009-03-20 14:25 . 2006-01-12 15:12 -------- d-----w c:\program files\Fichiers communs\Adobe
      2009-03-19 22:15 . 2009-03-19 22:15 -------- d-----w c:\program files\Bonjour
      2009-03-19 14:32 . 2008-01-29 10:01 23400 ----a-w c:\windows\system32\drivers\GEARAspiWDM.sys
      2009-03-13 14:00 . 2009-02-17 23:13 -------- d-----w c:\program files\Foxit Software
      2009-03-08 02:34 . 2006-01-12 13:56 914944 ----a-w c:\windows\system32\wininet.dll
      2009-03-08 02:34 . 2006-01-12 13:56 43008 ----a-w c:\windows\system32\licmgr10.dll
      2009-03-08 02:33 . 2006-01-12 13:56 18944 ----a-w c:\windows\system32\corpol.dll
      2009-03-08 02:33 . 2006-01-12 13:56 420352 ----a-w c:\windows\system32\vbscript.dll
      2009-03-08 02:32 . 2006-01-12 13:56 72704 ----a-w c:\windows\system32\admparse.dll
      2009-03-08 02:32 . 2006-01-12 13:56 71680 ----a-w c:\windows\system32\iesetup.dll
      2009-03-08 02:31 . 2006-01-12 13:56 34816 ----a-w c:\windows\system32\imgutil.dll
      2009-03-08 02:31 . 2006-01-12 13:56 48128 ----a-w c:\windows\system32\mshtmler.dll
      2009-03-08 02:31 . 2006-01-12 13:56 45568 ----a-w c:\windows\system32\mshta.exe
      2009-03-08 02:22 . 2006-01-12 13:56 156160 ----a-w c:\windows\system32\msls31.dll
      2009-03-06 14:20 . 2006-01-12 13:56 286720 ----a-w c:\windows\system32\pdh.dll
      2009-02-10 17:06 . 2004-08-04 00:48 2068096 ----a-w c:\windows\system32\ntkrnlpa.exe
      2009-04-06 18:00 . 2008-10-30 16:34 61440 ----a-w c:\program files\mozilla firefox\components\FFComm.dll
      2008-04-07 08:02 . 2008-05-09 12:14 67696 ----a-w c:\program files\mozilla firefox\components\jar50.dll
      2008-04-07 08:02 . 2008-05-09 12:14 54376 ----a-w c:\program files\mozilla firefox\components\jsd3250.dll
      2008-04-07 08:02 . 2008-05-09 12:14 34952 ----a-w c:\program files\mozilla firefox\components\myspell.dll
      2008-04-07 08:02 . 2008-05-09 12:14 46720 ----a-w c:\program files\mozilla firefox\components\spellchk.dll
      2008-04-07 08:02 . 2008-05-09 12:14 172144 ----a-w c:\program files\mozilla firefox\components\xpinstal.dll
      .

      ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
      .
      .
      *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
      REGEDIT4

      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
      "fsc-reminder.exe"="c:\windows\reminder\fsc-reminder.exe" [2005-01-19 28672]
      "LogitechSoftwareUpdate"="c:\program files\Logitech\Video\ManifestEngine.exe" [2005-06-08 196608]
      "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-25 68856]
      "MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-04-28 344064]
      "NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
      "trioService"="c:\program files\3D-Relax\Living Marine Aquarium 2.0 trial\trioService.exe" [2005-12-23 69632]
      "HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
      "LVCOMSX"="c:\windows\system32\LVCOMSX.EXE" [2005-07-19 221184]
      "LogitechVideoRepair"="c:\program files\Logitech\Video\ISStart.exe" [2005-06-08 458752]
      "LogitechVideoTray"="c:\program files\Logitech\Video\LogiTray.exe" [2005-06-08 217088]
      "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-06 136600]
      "BDAgent"="c:\program files\BitDefender\BitDefender 2009\bdagent.exe" [2009-04-06 778240]
      "BitDefender Antiphishing Helper"="c:\program files\BitDefender\BitDefender 2009\IEShow.exe" [2009-04-06 69632]
      "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696]
      "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
      "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-04-02 342312]
      "Raccourci vers la page des propriétés de High Definition Audio"="HDAShCut.exe" - c:\windows\system32\HdAShCut.exe [2005-01-07 61952]
      "SoundMan"="SOUNDMAN.EXE" - c:\windows\SOUNDMAN.EXE [2005-08-01 90112]
      "AlcWzrd"="ALCWZRD.EXE" - c:\windows\ALCWZRD.EXE [2005-08-01 2806272]

      [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
      "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
      "EnableFirewall"= 0 (0x0)

      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
      "c:\\Program Files\\LimeWire\\LimeWire.exe"=
      "c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
      "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
      "%windir%\\system32\\sessmgr.exe"=
      "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
      "c:\\Program Files\\iTunes\\iTunes.exe"=

      R2 BDVEDISK;BDVEDISK;c:\program files\BitDefender\BitDefender 2009\BDVEDISK.sys [04/09/2008 17:33 82696]
      R3 bdfm;BDFM;c:\windows\system32\drivers\bdfm.sys [18/09/2008 12:09 111112]
      R3 Bdfndisf;BitDefender Firewall NDIS Filter Service;c:\windows\system32\drivers\bdfndisf.sys [05/01/2009 18:40 104328]
      S3 Arrakis3;BitDefender Arrakis Server;c:\program files\Fichiers communs\BitDefender\BitDefender Arrakis Server\bin\Arrakis3.exe [17/07/2008 13:06 118784]

      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
      bdx REG_MULTI_SZ scan
      .
      Contenu du dossier 'Tâches planifiées'

      2009-05-07 c:\windows\Tasks\AppleSoftwareUpdate.job
      - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]

      2009-05-10 c:\windows\Tasks\User_Feed_Synchronization-{879C0CFE-5735-4E19-AD1C-E0259A3608EA}.job
      - c:\windows\system32\msfeedssync.exe [2006-10-17 02:31]
      .
      - - - - ORPHELINS SUPPRIMES - - - -

      HKCU-Run-lycosInside - c:\documents and settings\Hélène Gautier\Mes documents\Outils\lycos\Lyc_SysTray.exe
      HKCU-Run-Skype - c:\program files\Skype\Phone\Skype.exe
      HKLM-Run-Adobe Photo Downloader - c:\program files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe

      .
      ------- Examen supplémentaire -------
      .
      uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
      uStart Page = hxxp://www.google.fr/
      uInternet Settings,ProxyServer = http=hxxp://localhost:6080;https=http://localhost:6080
      uInternet Settings,ProxyOverride = <local>;*.local
      uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
      IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
      Trusted Zone: secuser.com\www
      Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
      DPF: {104B0A37-AB99-4F06-8032-8BBDC3B77DDB} - hxxp://www2.photoweb.fr/telechargement/Photoweb_uploader.cab
      DPF: {1F83CD9E-505E-4F87-BECE-0832A763E36F} - hxxp://www.mypixmania.com/be/fr/importer/MypixUploader.cab
      DPF: {68C1822F-F5C7-4404-A73F-03C10E0E94DA} - hxxp://www4.photoweb.fr/telechargement/Photoweb_uploader.cab
      DPF: {8F48147B-78D9-40F9-ACC0-BDDE59B246F4} - hxxp://abonnement.aliceadsl.fr/configurateur/AccountHelper.cab
      DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} - hxxp://game13.zylom.com/activex/zylomgamesplayer.cab
      DPF: {C36112BF-2FA3-4694-8603-3B510EA3B465} - hxxp://f001.mail.caramail.lycos.fr/app/uploader/FileUploader.cab
      DPF: {FB90BA05-66E6-4C56-BCD3-D65B0F7EBA39} - hxxp://fotobook.foto.com/activex/SpeedUploader.cab
      FF - ProfilePath -
      .

      **************************************************************************

      catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
      Rootkit scan 2009-05-10 18:11
      Windows 5.1.2600 Service Pack 3 NTFS

      Recherche de processus cachés ...

      Recherche d'éléments en démarrage automatique cachés ...

      Recherche de fichiers cachés ...

      Scan terminé avec succès
      Fichiers cachés: 0

      **************************************************************************
      .
      --------------------- CLES DE REGISTRE BLOQUEES ---------------------

      [HKEY_USERS\S-1-5-21-982364678-497367121-1916784087-1007\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{54F479AB-3EF4-14A6-0280-6050D2875F57}*]
      @Allowed: (Read) (RestrictedCode)
      @Allowed: (Read) (RestrictedCode)
      "naoigmmflccfioampfcnncfnnkop"=hex:6a,61,63,6e,63,6e,69,70,6e,6b,6c,6a,61,64,
      6e,62,6d,6f,69,6b,00,f7
      "maejimpckhmibndecfjcbidmob"=hex:6a,61,62,6e,6c,6d,70,70,63,6b,6e,6c,67,6f,61,
      65,65,6b,66,6e,00,00

      [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø•€|ÿÿÿÿ•€|ù•9~*]
      "C040311900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
      .
      --------------------- DLLs chargées dans les processus actifs ---------------------

      - - - - - - - > 'winlogon.exe'(1144)
      c:\windows\system32\Ati2evxx.dll
      .
      Heure de fin: 2009-05-10 18:16
      ComboFix-quarantined-files.txt 2009-05-10 16:16

      Avant-CF: 50 477 621 248 octets libres
      Après-CF: 50 585 583 616 octets libres

      WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe
      [boot loader]
      timeout=2
      default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
      [operating systems]
      c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
      multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP dition familiale" /noexecute=optin /fastdetect

      187 --- E O F --- 2009-04-30 10:29
      0
    2. @malolinePar contre, je ne sais pas comment faire un nouveau rapport HijackThis. faut-il lancer Rsit ? J'attends que tu me dises
      0
  3. slt

    pour voir ce qui se passe :

    ▶ Télécharge Random's System Information Tool (RSIT).

    ▶ Un tutoriel sera à ta disposition pour l'installer et l'utiliser correctement.

    ▶ Double clique sur RSIT.exe pour lancer l'outil.

    ▶ Clique sur 'Continue' à l'écran Disclaimer.

    ▶ Si l'outil Hijackthis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera et tu devras accepter la licence.

    ▶ Une fois le scan fini , 2 rapports vont apparaitre. Poste le contenu des 2 rapports.

    ( C:\RSIT\log.txt et C:\RSIT\info.txt )

    CTRL A pour sélectionner tout, CTRL C pour copier et puis CTRL V pour coller
    0
    1. Contributeur sécurité
      bonjour , perso je pense que tu tes fais pirater tes adresses , à des fin commercial car vu le message !!
      0
      1. re jacques

        en effet, sdfix est prevu mais j'aime bien jeter un oeil a une analyse rsit ou hjt pour verifier les progs de securité, teatimer de spybot par exemple, c'est pour cela que je demande toujours un rapport avant de commencer.

        a+ ;)
        0
        1. Contributeur sécurité
          bonjour je ne mettais pas du tout ta procédure en doute
          0
          1. Bonjour je ne mettais pas du tout ta procédure en doute

            non non je dis pas ca pour ca, c'est pour echanger, tu peux rester avec plaisir si tu veux
            a+
            0
            1. Contributeur sécurité
              ok je vais suivre
              0
              1. Merci de vous interesser à mon pb.
                Voici les 2 rapports :
                info.txt logfile of random's system information tool 1.06 2009-05-09 19:56:53

                ======Uninstall list======

                -->C:\WINDOWS\IsUn040c.exe -fC:\WINDOWS\orun32.isu
                -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
                Adobe Flash Player 10 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
                Adobe Reader 9.1 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A91000000001}
                Apple Mobile Device Support-->MsiExec.exe /I{AFA20D47-69C3-4030-8DF8-D37466E70F13}
                Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
                Art Deco Font Samples, Version 3.3-->"C:\Documents and Settings\Hélène Gautier\Mes documents\Outils\police\Art Deco Font Samples\unins000.exe"
                Assistant de connexion Windows Live-->MsiExec.exe /I{D3116CC7-24DC-4CA3-9CE1-23FED836E9F2}
                ATI Control Panel-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{0BEDBD4E-2D34-47B5-9973-57E62B29307C}\setup.exe"
                ATI Display Driver-->rundll32 C:\WINDOWS\system32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
                BitDefender Internet Security 2009-->MsiExec.exe /X{961CE74B-30C0-47D6-ACD9-0C887A5E23F5}
                CCleaner (remove only)-->"C:\Documents and Settings\Hélène Gautier\Mes documents\Outils\CCleaner\uninst.exe"
                Choice Guard-->MsiExec.exe /I{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}
                Comptes-->C:\WINDOWS\st6unst.exe -n "c:\Mes téléchargements\ST6UNST.LOG"
                Correctif pour Lecteur Windows Media 11 (KB939683)-->"C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
                Correctif pour Windows Internet Explorer 7 (KB947864)-->"C:\WINDOWS\ie7updates\KB947864-IE7\spuninst\spuninst.exe"
                Correctif pour Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
                Correctif pour Windows XP (KB961118)-->"C:\WINDOWS\$NtUninstallKB961118$\spuninst\spuninst.exe"
                Easy PDF to Text Converter v2.0-->"C:\Documents and Settings\Hélène Gautier\Mes documents\Outils\Convertisseur\Easy PDF to Text Converter\unins000.exe"
                EZface ActiveX 207-->C:\PROGRA~1\EZFace\ActiveX\uninst.bat 207 C:\PROGRA~1\EZFace\ActiveX
                GdiplusUpgrade-->MsiExec.exe /I{5421155F-B033-49DB-9B33-8F80F233D4D5}
                Google Toolbar for Internet Explorer-->"C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_BDA1448D3D255554.exe" /uninstall
                Google Toolbar for Internet Explorer-->MsiExec.exe /I{18455581-E099-4BA8-BC6B-F34B2F06600C}
                High Definition Audio - KB888111-->"C:\WINDOWS\$NtUninstallKB888111WXPSP2$\spuninst\spuninst.exe"
                Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
                Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
                Hotfix for Windows Media Format 11 SDK (KB929399)-->"C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
                HP Extended Capabilities 5.3-->C:\Program Files\HP\Digital Imaging\ExtCapUninstall\hpzscr01.exe -datfile hpqhsc01.dat
                HP Imaging Device Functions 5.3-->C:\Program Files\HP\Digital Imaging\DigitalImagingMonitor\hpzscr01.exe -datfile hpqbud01.dat
                HP Photosmart Essential-->MsiExec.exe /X{EB21A812-671B-4D08-B974-2A347F0D8F70}
                HP Product Assistant-->MsiExec.exe /I{36FDBE6E-6684-462B-AE98-9A39A1B200CC}
                HP PSC & OfficeJet 5.3.B-->"C:\Program Files\HP\Digital Imaging\{5B79CFD1-6845-4158-9D7D-6BE89DF2C135}\setup\hpzscr01.exe" -datfile hposcr07.dat
                HP Solution Center & Imaging Support Tools 5.3-->C:\Program Files\HP\Digital Imaging\eSupport\hpzscr01.exe -datfile hpqbud05.dat
                HP Update-->MsiExec.exe /X{FE57DE70-95DE-4B64-9266-84DA811053DB}
                Installation Windows Live-->C:\Program Files\Windows Live\Installer\wlarp.exe
                Installation Windows Live-->MsiExec.exe /I{7370DF47-B4F9-4279-BFC3-3F09919F720D}
                iPod System Software Updater 2.1-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{B02B8E30-EB28-49B0-A60F-696268BAE033} /l1036
                iTunes-->MsiExec.exe /I{5EFCBB42-36AB-4FF9-B90C-E78C7B9EE7B3}
                J2SE Runtime Environment 5.0 Update 11-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150110}
                Java(TM) 6 Update 11-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216011FF}
                Java(TM) SE Runtime Environment 6 Update 1-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160010}
                L'Album de Bébé-->MsiExec.exe /I{FF1A5077-C7E9-442A-B57A-37C23606AEE4}
                Lecteur Windows Media 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
                LimeWire 4.16.6-->"C:\Program Files\LimeWire\uninstall.exe"
                Logiciel QuickCam de Logitech-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C43048A9-742C-4DAD-90D2-E3B53C9DB825}\setup.exe" -l0x40c
                Microsoft .NET Framework 1.1 Hotfix (KB928366)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"
                Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
                Microsoft .NET Framework 2.0 Service Pack 2 Language Pack - FRA-->MsiExec.exe /I{72AD53CC-CCC0-3757-8480-9EE176866A7C}
                Microsoft .NET Framework 2.0 Service Pack 2-->MsiExec.exe /I{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}
                Microsoft .NET Framework 3.0 French Language Pack-->MsiExec.exe /X{E3C080B0-23F5-49AF-89F8-8E8DBC89E659}
                Microsoft .NET Framework 3.0 Service Pack 2 Language Pack - FRA-->MsiExec.exe /I{0BD83598-C2EF-3343-847B-7D2E84599128}
                Microsoft .NET Framework 3.0 Service Pack 2-->MsiExec.exe /I{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}
                Microsoft .NET Framework 3.5 Language Pack SP1 - fra-->MsiExec.exe /I{3E31821C-7917-367E-938E-E65FC413EA31}
                Microsoft .NET Framework 3.5 SP1-->C:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
                Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
                Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
                Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
                Microsoft Office Basic Edition 2003-->MsiExec.exe /I{9113040C-6000-11D3-8CFE-0150048383C9}
                Microsoft Office PowerPoint Viewer 2003-->MsiExec.exe /X{90AF040C-6000-11D3-8CFE-0150048383C9}
                Microsoft Search Enhancement Pack-->MsiExec.exe /I{9C9CEB9D-53FD-49A7-85D2-FE674F72F24E}
                Microsoft Sync Framework Runtime Native v1.0 (x86)-->MsiExec.exe /I{8A74E887-8F0F-4017-AF53-CBA42211AAA5}
                Microsoft Sync Framework Services Native v1.0 (x86)-->MsiExec.exe /I{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}
                Microsoft Works-->MsiExec.exe /I{A059DE09-1B49-4450-B340-7AE097EC3F04}
                Mise à jour critique pour Lecteur Windows Media 11 (KB959772)-->"C:\WINDOWS\$NtUninstallKB959772_WM11$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Lecteur Windows Media (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Lecteur Windows Media 10 (KB911565)-->"C:\WINDOWS\$NtUninstallKB911565$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Lecteur Windows Media 10 (KB917734)-->"C:\WINDOWS\$NtUninstallKB917734_WMP10$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Lecteur Windows Media 11 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Lecteur Windows Media 11 (KB954154)-->"C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Step by Step Interactive Training (KB898458)-->"C:\WINDOWS\$NtUninstallKB898458$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Step by Step Interactive Training (KB923723)-->"C:\WINDOWS\$NtUninstallKB923723$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows Internet Explorer 7 (KB928090)-->"C:\WINDOWS\ie7updates\KB928090-IE7\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows Internet Explorer 7 (KB931768)-->"C:\WINDOWS\ie7updates\KB931768-IE7\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows Internet Explorer 7 (KB933566)-->"C:\WINDOWS\ie7updates\KB933566-IE7\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows Internet Explorer 7 (KB937143)-->"C:\WINDOWS\ie7updates\KB937143-IE7\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows Internet Explorer 7 (KB938127)-->"C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows Internet Explorer 7 (KB939653)-->"C:\WINDOWS\ie7updates\KB939653-IE7\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows Internet Explorer 7 (KB942615)-->"C:\WINDOWS\ie7updates\KB942615-IE7\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows Internet Explorer 7 (KB944533)-->"C:\WINDOWS\ie7updates\KB944533-IE7\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows Internet Explorer 7 (KB950759)-->"C:\WINDOWS\ie7updates\KB950759-IE7\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows Internet Explorer 7 (KB953838)-->"C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows Internet Explorer 7 (KB956390)-->"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows Internet Explorer 7 (KB958215)-->"C:\WINDOWS\ie7updates\KB958215-IE7\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows Internet Explorer 7 (KB960714)-->"C:\WINDOWS\ie7updates\KB960714-IE7\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows Internet Explorer 7 (KB961260)-->"C:\WINDOWS\ie7updates\KB961260-IE7\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB923561)-->"C:\WINDOWS\$NtUninstallKB923561$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB938464-v2)-->"C:\WINDOWS\$NtUninstallKB938464-v2$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB950760)-->"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB951376)-->"C:\WINDOWS\$NtUninstallKB951376$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB952004)-->"C:\WINDOWS\$NtUninstallKB952004$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB953839)-->"C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB954211)-->"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB954459)-->"C:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB954600)-->"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB956391)-->"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB956572)-->"C:\WINDOWS\$NtUninstallKB956572$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB956841)-->"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB957095)-->"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB958687)-->"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB958690)-->"C:\WINDOWS\$NtUninstallKB958690$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB959426)-->"C:\WINDOWS\$NtUninstallKB959426$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB960225)-->"C:\WINDOWS\$NtUninstallKB960225$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB960715)-->"C:\WINDOWS\$NtUninstallKB960715$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB960803)-->"C:\WINDOWS\$NtUninstallKB960803$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB961373)-->"C:\WINDOWS\$NtUninstallKB961373$\spuninst\spuninst.exe"
                Mise à jour pour Windows Internet Explorer 8 (KB968220)-->"C:\WINDOWS\ie8updates\KB968220-IE8\spuninst\spuninst.exe"
                Mise à jour pour Windows XP (KB951072-v2)-->"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
                Mise à jour pour Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
                Mise à jour pour Windows XP (KB955839)-->"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
                Mise à jour pour Windows XP (KB961503)-->"C:\WINDOWS\$NtUninstallKB961503$\spuninst\spuninst.exe"
                Mise à jour pour Windows XP (KB967715)-->"C:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe"
                Module de prise en charge linguistique du français de Microsoft .NET Framework 3.0-->c:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0 French Language Pack\setup.exe
                Module linguistique Microsoft .NET Framework 3.5 SP1- fra-->c:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 Language Pack SP1 - fra\setup.exe
                Mozilla Firefox (2.0.0.14)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
                MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
                MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
                MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
                MSXML 6.0 Parser (KB925673)-->MsiExec.exe /I{FE9126DB-5F84-495A-BB46-3C724F1C2D08}
                Nero BurnRights-->C:\WINDOWS\UNNeroBurnRights.exe /UNINSTALL
                Nero OEM-->C:\Program Files\Ahead\nero\uninstall\UNNERO.exe /UNINSTALL
                NeroVision Express 3 SE-->C:\WINDOWS\UNNeroVision.exe /UNINSTALL
                NeroVision Express Content-->C:\WINDOWS\UNNVEContent.exe /UNINSTALL
                PhotoFiltre-->"C:\Documents and Settings\Hélène Gautier\Mes documents\PhotoFiltre\Uninst.exe"
                Picasa 3-->"C:\Program Files\Google\Picasa3\Uninstall.exe"
                Pochette Express 2-->C:\Documents and Settings\Hélène Gautier\Mes documents\Outils\pochette\Pochette Express 2\uninstall.exe
                Programme de gestion Camera de Logitech®-->"C:\Program Files\Fichiers communs\Logitech\QCDRV\BIN\SETUP.EXE" UNINSTALL REMOVEPROMPT
                QuickTime-->MsiExec.exe /I{216AB108-2AE1-4130-B3D5-20B2C4C80F8F}
                SAMSUNG CDMA Modem Driver Set-->C:\WINDOWS\system32\Samsung_USB_Drivers\3\SSCDUninstall.exe
                SAMSUNG Mobile Composite Device Software-->C:\WINDOWS\system32\Samsung_USB_Drivers\6\SSBCUninstall.exe
                Samsung Mobile phone USB driver Software-->C:\WINDOWS\system32\Samsung_USB_Drivers\5\SSSDUninstall.exe
                SAMSUNG Mobile USB Modem 1.0 Software-->C:\WINDOWS\system32\Samsung_USB_Drivers\1\SS_Uninstall.exe
                SAMSUNG Mobile USB Modem Software-->C:\WINDOWS\system32\Samsung_USB_Drivers\2\SSM_Uninstall.exe
                Samsung PC Studio 3-->"C:\Program Files\InstallShield Installation Information\{C4A4722E-79F9-417C-BD72-8D359A090C97}\setup.exe" -runfromtemp -l0x040c -removeonly
                Script Font Samples, Version 2.9-->"C:\Documents and Settings\Hélène Gautier\Mes documents\Outils\police\Script Font Samples\unins000.exe"
                Security Update for CAPICOM (KB931906)-->MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
                Security Update for CAPICOM (KB931906)-->MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
                Segoe UI-->MsiExec.exe /I{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}
                VideoLAN VLC media player 0.8.6f-->C:\Documents and Settings\Hélène Gautier\Mes documents\Outils\recuperer video\VLC\uninstall.exe
                Windows Internet Explorer 8-->"C:\WINDOWS\ie8\spuninst\spuninst.exe"
                Windows Live Call-->MsiExec.exe /I{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}
                Windows Live Communications Platform-->MsiExec.exe /I{3B4E636E-9D65-4D67-BA61-189800823F52}
                Windows Live Messenger-->MsiExec.exe /X{059C042E-796A-4ACC-A81A-ECC2010BB78C}
                Windows Live Toolbar-->MsiExec.exe /X{F7D27C70-90F5-49B9-B188-0A133C0CE353}
                Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
                Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
                Windows Media Format SDK Hotfix - KB891122-->"C:\WINDOWS\$NtUninstallKB891122$\spuninst\spuninst.exe"
                Windows Media Player 10 Hotfix - KB888656-->"C:\WINDOWS\$NtUninstallKB888656$\spuninst\spuninst.exe"
                Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
                Windows Presentation Foundation Language Pack (FRA)-->MsiExec.exe /X{6901DD22-527A-41EF-9059-E81FEDE9E494}
                Windows Presentation Foundation-->MsiExec.exe /X{BAF78226-3200-4DB4-BE33-4D922A799840}
                Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
                XML Paper Specification Shared Components Language Pack 1.0-->"C:\WINDOWS\$NtUninstallXPSEPSCLP$\spuninst\spuninst.exe"

                ======Security center information======

                AV: Antivirus BitDefender
                FW: Pare-feu BitDefender

                ======System event log======

                Computer Name: HÉLÈNE
                Event Code: 4201
                Message: Le système a détecté que la carte réseau \DEVICE\TCPIP_{C7F30C8B-A45B-4805-8961-3FAFE4825A2E} était connectée au réseau,
                et a lancé une opération normale sur la carte réseau.

                Record Number: 62836
                Source Name: Tcpip
                Time Written: 20090428174717.000000+120
                Event Type: Informations
                User:

                Computer Name: HÉLÈNE
                Event Code: 4201
                Message: Le système a détecté que la carte réseau \DEVICE\TCPIP_{C7F30C8B-A45B-4805-8961-3FAFE4825A2E} était connectée au réseau,
                et a lancé une opération normale sur la carte réseau.

                Record Number: 62835
                Source Name: Tcpip
                Time Written: 20090428174517.000000+120
                Event Type: Informations
                User:

                Computer Name: HÉLÈNE
                Event Code: 4201
                Message: Le système a détecté que la carte réseau \DEVICE\TCPIP_{C7F30C8B-A45B-4805-8961-3FAFE4825A2E} était connectée au réseau,
                et a lancé une opération normale sur la carte réseau.

                Record Number: 62834
                Source Name: Tcpip
                Time Written: 20090428174317.000000+120
                Event Type: Informations
                User:

                Computer Name: HÉLÈNE
                Event Code: 4201
                Message: Le système a détecté que la carte réseau \DEVICE\TCPIP_{C7F30C8B-A45B-4805-8961-3FAFE4825A2E} était connectée au réseau,
                et a lancé une opération normale sur la carte réseau.

                Record Number: 62833
                Source Name: Tcpip
                Time Written: 20090428174117.000000+120
                Event Type: Informations
                User:

                Computer Name: HÉLÈNE
                Event Code: 4201
                Message: Le système a détecté que la carte réseau \DEVICE\TCPIP_{C7F30C8B-A45B-4805-8961-3FAFE4825A2E} était connectée au réseau,
                et a lancé une opération normale sur la carte réseau.

                Record Number: 62832
                Source Name: Tcpip
                Time Written: 20090428173917.000000+120
                Event Type: Informations
                User:

                =====Application event log=====

                Computer Name: HÉLÈNE
                Event Code: 301
                Message: MsnMsgr (3108) \\.\C:\Documents and Settings\Hélène Gautier\Local Settings\Application Data\Microsoft\Messenger\h-gautier@hotmail.fr\SharingMetadata\Working\database_E4D8_C931_D8C9_332\dfsr.db: Le moteur de base de données commence la relecture du fichier journal \\.\C:\Documents and Settings\Hélène Gautier\Local Settings\Application Data\Microsoft\Messenger\h-gautier@hotmail.fr\SharingMetadata\Working\database_E4D8_C931_D8C9_332\fsr0011E.log.

                Record Number: 10595
                Source Name: ESENT
                Time Written: 20090118085823.000000+060
                Event Type: Informations
                User:

                Computer Name: HÉLÈNE
                Event Code: 301
                Message: MsnMsgr (3108) \\.\C:\Documents and Settings\Hélène Gautier\Local Settings\Application Data\Microsoft\Messenger\h-gautier@hotmail.fr\SharingMetadata\Working\database_E4D8_C931_D8C9_332\dfsr.db: Le moteur de base de données commence la relecture du fichier journal \\.\C:\Documents and Settings\Hélène Gautier\Local Settings\Application Data\Microsoft\Messenger\h-gautier@hotmail.fr\SharingMetadata\Working\database_E4D8_C931_D8C9_332\fsr0011D.log.

                Record Number: 10594
                Source Name: ESENT
                Time Written: 20090118085823.000000+060
                Event Type: Informations
                User:

                Computer Name: HÉLÈNE
                Event Code: 301
                Message: MsnMsgr (3108) \\.\C:\Documents and Settings\Hélène Gautier\Local Settings\Application Data\Microsoft\Messenger\h-gautier@hotmail.fr\SharingMetadata\Working\database_E4D8_C931_D8C9_332\dfsr.db: Le moteur de base de données commence la relecture du fichier journal \\.\C:\Documents and Settings\Hélène Gautier\Local Settings\Application Data\Microsoft\Messenger\h-gautier@hotmail.fr\SharingMetadata\Working\database_E4D8_C931_D8C9_332\fsr0011C.log.

                Record Number: 10593
                Source Name: ESENT
                Time Written: 20090118085823.000000+060
                Event Type: Informations
                User:

                Computer Name: HÉLÈNE
                Event Code: 300
                Message: MsnMsgr (3108) \\.\C:\Documents and Settings\Hélène Gautier\Local Settings\Application Data\Microsoft\Messenger\h-gautier@hotmail.fr\SharingMetadata\Working\database_E4D8_C931_D8C9_332\dfsr.db: Le moteur de base de données initialise la procédure de récupération.

                Record Number: 10592
                Source Name: ESENT
                Time Written: 20090118085822.000000+060
                Event Type: Informations
                User:

                Computer Name: HÉLÈNE
                Event Code: 102
                Message: MsnMsgr (3108) \\.\C:\Documents and Settings\Hélène Gautier\Local Settings\Application Data\Microsoft\Messenger\h-gautier@hotmail.fr\SharingMetadata\Working\database_E4D8_C931_D8C9_332\dfsr.db: Le moteur de base de données a démarré une nouvelle instance (0).

                Record Number: 10591
                Source Name: ESENT
                Time Written: 20090118085821.000000+060
                Event Type: Informations
                User:

                ======Environment variables======

                "ComSpec"=%SystemRoot%\system32\cmd.exe
                "FP_NO_HOST_CHECK"=NO
                "LANG"=fr
                "NUMBER_OF_PROCESSORS"=1
                "OS"=Windows_NT
                "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\ATI Technologies\ATI Control Panel;C:\Documents and Settings\Hélène Gautier\Mes documents\Outils\retouche\Gimp\2.0\bin;C:\Program Files\QuickTime\QTSystem\
                "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
                "PROCESSOR_ARCHITECTURE"=x86
                "PROCESSOR_IDENTIFIER"=x86 Family 6 Model 13 Stepping 8, GenuineIntel
                "PROCESSOR_LEVEL"=6
                "PROCESSOR_REVISION"=0d08
                "TEMP"=%SystemRoot%\TEMP
                "TMP"=%SystemRoot%\TEMP
                "windir"=%SystemRoot%
                "CLASSPATH"=.;C:\Program Files\Java\jre6\lib\ext\QTJava.zip
                "QTJAVA"=C:\Program Files\Java\jre6\lib\ext\QTJava.zip

                -----------------EOF-----------------

                Logfile of random's system information tool 1.06 (written by random/random)
                Run by Hélène Gautier at 2009-05-09 19:55:50
                Microsoft Windows XP Édition familiale Service Pack 3
                System drive C: has 48 GB (63%) free of 76 GB
                Total RAM: 511 MB (18% free)

                HijackThis download failed

                ======Scheduled tasks folder======

                C:\WINDOWS\tasks\AppleSoftwareUpdate.job
                C:\WINDOWS\tasks\User_Feed_Synchronization-{879C0CFE-5735-4E19-AD1C-E0259A3608EA}.job

                ======Registry dump======

                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
                Adobe PDF Link Helper - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]

                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]

                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
                Search Helper - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll [2009-01-14 92504]

                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
                SSVHelper Class - C:\Program Files\Java\jre6\bin\ssv.dll [2008-12-06 320920]

                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
                Programme d'aide de l'Assistant de connexion Windows Live - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-02-17 408440]

                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
                Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll [2009-04-23 259696]

                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
                Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll [2009-04-24 668656]

                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C84D72FE-E17D-4195-BB24-76C02E2E7C4E}]
                Google Dictionary Compression sdch - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll [2009-04-23 470512]

                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
                Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2008-12-06 34816]

                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10}]
                Windows Live Toolbar Helper - C:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-02-06 1068904]

                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
                JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2008-12-06 73728]

                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
                {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - BitDefender Toolbar - C:\Program Files\BitDefender\BitDefender 2009\IEToolbar.dll [2009-04-06 95536]
                {21FA44EF-376D-4D53-9B0F-8A89D3229068} - &Windows Live Toolbar - C:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-02-06 1068904]
                {2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll [2009-04-23 259696]

                [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
                "Raccourci vers la page des propriétés de High Definition Audio"=C:\WINDOWS\system32\HDAShCut.exe [2005-01-07 61952]
                "ATIPTA"=C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe [2005-04-28 344064]
                "SoundMan"=C:\WINDOWS\SOUNDMAN.EXE [2005-08-01 90112]
                "AlcWzrd"=C:\WINDOWS\ALCWZRD.EXE [2005-08-01 2806272]
                "Alcmtr"=C:\WINDOWS\ALCMTR.EXE [2005-08-01 69632]
                "NeroFilterCheck"=C:\WINDOWS\system32\NeroCheck.exe [2001-07-09 155648]
                "trioService"=C:\Program Files\3D-Relax\Living Marine Aquarium 2.0 trial\trioService.exe [2005-12-23 69632]
                "HP Software Update"=C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2007-05-08 54840]
                "LVCOMSX"=C:\WINDOWS\system32\LVCOMSX.EXE [2005-07-19 221184]
                "LogitechVideoRepair"=C:\Program Files\Logitech\Video\ISStart.exe [2005-06-08 458752]
                "LogitechVideoTray"=C:\Program Files\Logitech\Video\LogiTray.exe [2005-06-08 217088]
                "Adobe Photo Downloader"=C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe []
                "SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2008-12-06 136600]
                "BDAgent"=C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe [2009-04-06 778240]
                "BitDefender Antiphishing Helper"=C:\Program Files\BitDefender\BitDefender 2009\IEShow.exe [2009-04-06 69632]
                "QuickTime Task"=C:\Program Files\QuickTime\qttask.exe [2009-01-05 413696]
                "Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-02-27 35696]
                "iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2009-04-02 342312]

                [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
                "CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
                "fsc-reminder.exe"=C:\WINDOWS\reminder\fsc-reminder.exe [2005-01-19 28672]
                "lycosInside"=C:\Documents and Settings\Hélène Gautier\Mes documents\Outils\lycos\Lyc_SysTray.exe []
                "Skype"=C:\Program Files\Skype\Phone\Skype.exe /nosplash /minimized []
                "LogitechSoftwareUpdate"=C:\Program Files\Logitech\Video\ManifestEngine.exe [2005-06-08 196608]
                "MsnMsgr"=C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe [2009-02-06 3885408]
                "MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]
                "swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2007-07-25 68856]

                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
                C:\WINDOWS\system32\Ati2evxx.dll [2005-08-01 46080]

                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
                C:\WINDOWS\system32\WgaLogon.dll [2007-02-15 236928]

                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
                WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

                [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
                "dontdisplaylastusername"=0
                "legalnoticecaption"=
                "legalnoticetext"=
                "shutdownwithoutlogon"=1
                "undockwithoutlogon"=1

                [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
                "NoDriveTypeAutoRun"=145

                [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
                "HonorAutoRunSetting"=

                [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
                "C:\Program Files\LimeWire\LimeWire.exe"="C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire"
                "C:\Program Files\Mozilla Firefox\firefox.exe"="C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox"
                "%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
                "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
                "C:\Program Files\Windows Live\Messenger\wlcsdk.exe"="C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call"
                "C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
                "C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
                "C:\Program Files\iTunes\iTunes.exe"="C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes"

                [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
                "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
                "%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
                "C:\Program Files\Windows Live\Messenger\wlcsdk.exe"="C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call"
                "C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"

                ======List of files/folders created in the last 1 months======

                2009-05-09 19:55:55 ----D---- C:\Program Files\trend micro
                2009-05-09 19:55:50 ----D---- C:\rsit
                2009-05-09 16:34:55 ----A---- C:\WINDOWS\system32\OLD43.tmp
                2009-05-09 16:34:54 ----D---- C:\WINDOWS\LastGood
                2009-05-09 13:19:33 ----A---- C:\WINDOWS\msnfix.txt
                2009-04-30 12:28:34 ----HDC---- C:\WINDOWS\$NtUninstallKB961503$
                2009-04-28 23:21:38 ----HDC---- C:\WINDOWS\$NtUninstallKB961118$
                2009-04-27 17:23:51 ----D---- C:\a3d0e4c57a646bda6b1b8698
                2009-04-16 13:52:37 ----HDC---- C:\WINDOWS\$NtUninstallKB959426$
                2009-04-16 13:52:09 ----HDC---- C:\WINDOWS\$NtUninstallKB961373$
                2009-04-16 13:46:49 ----HDC---- C:\WINDOWS\$NtUninstallKB956572$
                2009-04-16 13:46:18 ----HDC---- C:\WINDOWS\$NtUninstallKB952004$
                2009-04-16 13:45:50 ----HDC---- C:\WINDOWS\$NtUninstallKB960803$
                2009-04-16 13:39:29 ----HDC---- C:\WINDOWS\$NtUninstallKB923561$
                2009-04-11 14:46:05 ----D---- C:\Program Files\iTunes
                2009-04-11 14:46:05 ----D---- C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}

                ======List of files/folders modified in the last 1 months======

                2009-05-09 19:56:15 ----D---- C:\WINDOWS\Prefetch
                2009-05-09 19:55:55 ----RD---- C:\Program Files
                2009-05-09 17:34:34 ----D---- C:\WINDOWS\Debug
                2009-05-09 17:34:34 ----D---- C:\WINDOWS
                2009-05-09 17:34:26 ----D---- C:\WINDOWS\Minidump
                2009-05-09 17:34:25 ----D---- C:\WINDOWS\Temp
                2009-05-09 17:05:43 ----SHD---- C:\WINDOWS\Installer
                2009-05-09 16:48:00 ----AC---- C:\WINDOWS\NeroDigital.ini
                2009-05-09 16:35:02 ----RSHDC---- C:\WINDOWS\system32\dllcache
                2009-05-09 16:34:56 ----AD---- C:\WINDOWS\system32
                2009-05-09 16:34:37 ----D---- C:\WINDOWS\system32\CatRoot2
                2009-05-09 15:20:40 ----N---- C:\WINDOWS\SchedLgU.Txt
                2009-05-06 23:20:33 ----D---- C:\WINDOWS\system32\FxsTmp
                2009-05-06 23:08:22 ----D---- C:\Documents and Settings\Hélène Gautier\Application Data\Image Zone Express
                2009-05-06 18:11:46 ----D---- C:\WINDOWS\network diagnostic
                2009-05-05 21:52:22 ----D---- C:\WINDOWS\system32\wbem
                2009-05-05 21:52:21 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
                2009-05-01 14:07:05 ----HD---- C:\WINDOWS\inf
                2009-04-30 12:27:08 ----HD---- C:\Config.Msi
                2009-04-29 17:01:17 ----SD---- C:\Documents and Settings\Hélène Gautier\Application Data\Microsoft
                2009-04-29 12:18:17 ----HD---- C:\WINDOWS\$hf_mig$
                2009-04-28 23:24:04 ----D---- C:\WINDOWS\system32\CatRoot
                2009-04-27 19:33:02 ----D---- C:\WINDOWS\Microsoft.NET
                2009-04-27 19:32:51 ----RSD---- C:\WINDOWS\assembly
                2009-04-27 17:56:08 ----D---- C:\WINDOWS\system32\XPSViewer
                2009-04-27 17:56:08 ----D---- C:\WINDOWS\system32\fr-fr
                2009-04-27 17:42:30 ----D---- C:\WINDOWS\WinSxS
                2009-04-27 17:27:36 ----D---- C:\WINDOWS\system32\en-us
                2009-04-27 17:27:19 ----RSD---- C:\WINDOWS\Fonts
                2009-04-16 14:08:21 ----D---- C:\WINDOWS\AppPatch
                2009-04-16 13:42:56 ----A---- C:\WINDOWS\win.ini
                2009-04-12 13:36:09 ----D---- C:\Program Files\Incomplete
                2009-04-11 23:01:33 ----D---- C:\Program Files\LimeWire
                2009-04-11 14:48:03 ----D---- C:\WINDOWS\system32\drivers
                2009-04-11 14:47:48 ----DC---- C:\WINDOWS\system32\DRVSTORE
                2009-04-11 14:46:44 ----D---- C:\Program Files\iPod
                2009-04-11 14:46:36 ----D---- C:\Program Files\Fichiers communs\Apple

                ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

                R1 bdftdif;bdftdif; \??\C:\Program Files\Fichiers communs\BitDefender\BitDefender Firewall\bdftdif.sys []
                R1 intelppm;Pilote de processeur Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40576]
                R1 StarOpen;StarOpen; C:\WINDOWS\system32\drivers\StarOpen.sys [2009-04-09 5632]
                R1 WmiAcpi;Interface de gestion Microsoft Windows pour ACPI; C:\WINDOWS\system32\DRIVERS\wmiacpi.sys [2008-04-13 8832]
                R1 WS2IFSL;Environnement de prise en charge de Fournisseur de services non-IFS Windows Sockets 2.0; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2004-08-05 12032]
                R2 BDVEDISK;BDVEDISK; \??\C:\Program Files\BitDefender\BitDefender 2009\BDVEDISK.sys []
                R3 Arp1394;Protocole client ARP 1394; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-13 60800]
                R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2005-08-01 1132544]
                R3 bdfm;BDFM; C:\WINDOWS\system32\drivers\bdfm.sys [2008-09-18 111112]
                R3 Bdfndisf;BitDefender Firewall NDIS Filter Service; C:\WINDOWS\system32\DRIVERS\bdfndisf.sys [2009-04-06 104328]
                R3 bdfsfltr;bdfsfltr; C:\WINDOWS\system32\drivers\bdfsfltr.sys [2009-01-19 242184]
                R3 BDSelfPr;BDSelfPr; \??\C:\Program Files\BitDefender\BitDefender 2009\bdselfpr.sys []
                R3 CmBatt;Pilote d'adaptateur secteur Microsoft; C:\WINDOWS\system32\DRIVERS\CmBatt.sys [2008-04-13 13952]
                R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys [2009-03-19 23400]
                R3 HDAudBus;Pilote de bus Microsoft UAA pour High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
                R3 HidUsb;Pilote de classe HID Microsoft; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
                R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2005-08-01 3851264]
                R3 mouhid;Pilote HID de souris; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-23 12288]
                R3 NIC1394;Pilote réseau 1394; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-13 61824]
                R3 Profos;Profos; \??\C:\Program Files\Fichiers communs\BitDefender\BitDefender Threat Scanner\profos.sys []
                R3 RTL8023xp;Realtek 10/100/1000 NIC Family all in one NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtlnicxp.sys [2005-08-01 74496]
                R3 Trufos;Trufos; \??\C:\Program Files\Fichiers communs\BitDefender\BitDefender Threat Scanner\trufos.sys []
                R3 usbehci;Pilote miniport de contrôleur d'hôte amélioré Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
                R3 usbhub;Concentrateur USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
                R3 usbuhci;Pilote miniport de contrôleur hôte universel USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
                R3 w29n51;Pilote de carte de connexion réseau Intel(R) PRO/Wireless 2200BG pour Windows XP; C:\WINDOWS\system32\DRIVERS\w29n51.sys [2005-08-01 3222784]
                S3 CCDECODE;Décodeur sous-titre fermé; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
                S3 HdAudAddService;Pilote de fonction Microsoft UAA pour Service High Definition Audio; C:\WINDOWS\system32\drivers\HdAudio.sys [2005-01-07 145920]
                S3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\system32\DRIVERS\HPZid412.sys [2005-03-08 51120]
                S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2005-03-08 16496]
                S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2005-03-08 21744]
                S3 LVUSBSta;Logitech USB Monitor Filter; C:\WINDOWS\system32\drivers\lvusbsta.sys [2005-05-27 22016]
                S3 MSTEE;Convertisseur en T/site-à-site de répartition Microsoft; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
                S3 NABTSFEC;Codec NABTS/FEC VBI; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
                S3 NdisIP;Connection TV/vidéo Microsoft; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
                S3 QCMerced;Logitech QuickCam Communicate; C:\WINDOWS\system32\DRIVERS\LVCM.sys [2005-05-27 1317152]
                S3 rtl8139;Pilote NT de carte Realtek PCI Fast Ethernet à base RTL8139(A/B/C); C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2004-08-04 20992]
                S3 SLIP;Détrameur décalage BDA; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
                S3 ssm_bus;SAMSUNG Mobile USB Device II 1.0 driver (WDM); C:\WINDOWS\system32\DRIVERS\ssm_bus.sys [2005-08-30 58320]
                S3 ssm_mdfl;SAMSUNG Mobile USB Modem II 1.0 Filter; C:\WINDOWS\system32\DRIVERS\ssm_mdfl.sys [2005-08-30 8336]
                S3 ssm_mdm;SAMSUNG Mobile USB Modem II 1.0 Drivers; C:\WINDOWS\system32\DRIVERS\ssm_mdm.sys [2005-08-30 94000]
                S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
                S3 usbaudio;Pilote USB audio (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2008-04-13 60032]
                S3 usbccgp;Pilote parent générique USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
                S3 usbprint;Classe d'imprimantes USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
                S3 usbscan;Pilote de scanneur USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
                S3 USBSTOR;Pilote de stockage de masse USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
                S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
                S3 WSTCODEC;Codec Teletext standard; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]

                ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

                R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2009-03-06 132424]
                R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2005-08-01 364544]
                R2 Bonjour Service;Service Bonjour; C:\Program Files\Bonjour\mDNSResponder.exe [2008-12-12 238888]
                R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2008-12-06 152984]
                R2 LIVESRV;BitDefender Desktop Update Service; C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe [2009-04-06 415024]
                R2 MDM;Machine Debug Manager; C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-20 322120]
                R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\system32\HPZipm12.exe [2007-08-09 73728]
                R2 SeaPort;SeaPort; C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-01-14 226656]
                R2 VSSERV;BitDefender Virus Shield; C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe [2009-04-06 1626112]
                R3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
                R3 iPod Service;Service de l’iPod; C:\Program Files\iPod\bin\iPodService.exe [2009-04-02 656168]
                S2 Fax;Fax; C:\WINDOWS\system32\fxssvc.exe [2008-04-14 268800]
                S3 Arrakis3;BitDefender Arrakis Server; C:\Program Files\Fichiers communs\BitDefender\BitDefender Arrakis Server\bin\Arrakis3.exe [2008-07-17 118784]
                S3 aspnet_state;Service d'état ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
                S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
                S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
                S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-04-24 182768]
                S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
                S3 ose;Office Source Engine; C:\Program Files\Fichiers communs\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
                S3 scan;BitDefender Threat Scanner; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
                S3 WMPNetworkSvc;Service Partage réseau du Lecteur Windows Media; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-11-03 918016]
                S4 NetTcpPortSharing;Service de partage de ports Net.Tcp; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

                -----------------EOF-----------------
                0
                1. tu t'es fais aidé ailleurs ? tu as utilisé msnfix y'a pas longtemps, sur conseil ou de ta propre initiative ?
                  a t'il trouvé quelquechose ??
                  si oui poste le rapport stp

                  sinon

                  ==> Télécharger et enregistre sur ton bureau SDFix(créé par AndyManchesta)

                  ==> Double cliquer sur SDFix.exe et choisir Install pour l'extraire dans un dossier dédié sur ton disque C:.

                  /!\ Démarre en mode sans échec : après le bip et avant le logo windows tapoter sur la touche F8 (ou F5): menu M.S.E..

                  ==> Choisir ta session, pas celui de l'Administrateur ou autre.

                  ==> Dérouler la liste des instructions ci-dessous :

                  Ouvrir le dossier SDFix qui vient d'être créé dans le répertoire C:\ et double clique sur RunThis.bat pour lancer le script.
                  Appuyer sur Y pour commencer le processus de nettoyage.
                  Il va supprimer les services et les entrées du Registre de certains trojans trouvés puis te demandera d'appuyer sur une touche pour redémarrer.
                  Appuyer sur une touche pour redémarrer le PC.
                  Le système sera plus long pour redémarrer qu'à l'accoutumée car l'outil va continuer à s'exécuter et supprimer des fichiers.
                  Après le chargement du Bureau, l'outil terminera son travail et affichera Finished.
                  Appuyer sur une touche pour finir l'exécution du script et charger les icônes du Bureau.
                  Les icônes du Bureau affichées, le rapport SDFix s'ouvrira à l'écran et s'enregistrera aussi dans le dossier SDFix sous le nom Report.txt.
                  Enfin, copier/coller le contenu du fichier Report.txt dans la prochaine réponse sur le forum
                  0
                  1. J'ai cherché toute la journée une solution, voila pourquoi tu vois ce fichier. Mais je crois que je ne suis pas allée juqu'au bout de son utilisation...
                    Comment redemarrer en mode sans echec pour effectuer ta manip ?
                    0
                    1. c'est marqué au dessus :

                      Démarre en mode sans échec :
                      Pour cela, tu tapotes la touche F8 dès le début de l’allumage du pc sans t’arrêter.
                      Une fenêtre va s’ouvrir tu te déplaces avec les flèches du clavier sur démarrer en mode sans échec puis tape entrée.
                      Une fois sur le bureau s’il n’y a pas toutes les couleurs et autres c’est normal !
                      (Si F8 ne marche pas utilise la touche F5).

                      AIDE
                      AIDE
                      0
                      1. Après avoir redemarrer en mode sans echec et de retour en "mode normal" apparait sur mon bureau un dossier "UpLaod_Me". En revanche, je ne vois pas de "report txt". Les seuls fichiers txt sont "dossier txt" "fichier txt" "RK txt" "MD5 txt" et "temp txt". Lequel dois-je copier ?... Et que faire de du dossier sur le bureau ?
                        0
                    2. Contributeur sécurité
                      bonjour si tu veux retrouver le rapport de sdfix tu te rends dans le dossier SDFix sous le nom Report.txt.

                      sinon perso je ne vois pas les deux rapports de rsit car tu nous as mis info.txt il nous manque le log.txt tu le trouveras dans C dossier RSIT

                      0
                      1. dsl entrain de manger ;))

                        le log y est bien jacques , c'est le hjt qui manque , le download a echoue : HijackThis download failed
                        0
                        1. Voici le rapport de rsit "log.txt"
                          En revanche, je ne trouve pas le dossier "report.txt"... Je cherche...

                          Run by Hélène Gautier at 2009-05-09 19:55:50
                          Microsoft Windows XP Édition familiale Service Pack 3
                          System drive C: has 48 GB (63%) free of 76 GB
                          Total RAM: 511 MB (18% free)

                          HijackThis download failed

                          ======Scheduled tasks folder======

                          C:\WINDOWS\tasks\AppleSoftwareUpdate.job
                          C:\WINDOWS\tasks\User_Feed_Synchronization-{879C0CFE-5735-4E19-AD1C-E0259A3608EA}.job

                          ======Registry dump======

                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
                          Adobe PDF Link Helper - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]

                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]

                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
                          Search Helper - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll [2009-01-14 92504]

                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
                          SSVHelper Class - C:\Program Files\Java\jre6\bin\ssv.dll [2008-12-06 320920]

                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
                          Programme d'aide de l'Assistant de connexion Windows Live - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-02-17 408440]

                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
                          Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll [2009-04-23 259696]

                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
                          Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll [2009-04-24 668656]

                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C84D72FE-E17D-4195-BB24-76C02E2E7C4E}]
                          Google Dictionary Compression sdch - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll [2009-04-23 470512]

                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
                          Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2008-12-06 34816]

                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10}]
                          Windows Live Toolbar Helper - C:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-02-06 1068904]

                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
                          JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2008-12-06 73728]

                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
                          {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - BitDefender Toolbar - C:\Program Files\BitDefender\BitDefender 2009\IEToolbar.dll [2009-04-06 95536]
                          {21FA44EF-376D-4D53-9B0F-8A89D3229068} - &Windows Live Toolbar - C:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-02-06 1068904]
                          {2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll [2009-04-23 259696]

                          [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
                          "Raccourci vers la page des propriétés de High Definition Audio"=C:\WINDOWS\system32\HDAShCut.exe [2005-01-07 61952]
                          "ATIPTA"=C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe [2005-04-28 344064]
                          "SoundMan"=C:\WINDOWS\SOUNDMAN.EXE [2005-08-01 90112]
                          "AlcWzrd"=C:\WINDOWS\ALCWZRD.EXE [2005-08-01 2806272]
                          "Alcmtr"=C:\WINDOWS\ALCMTR.EXE [2005-08-01 69632]
                          "NeroFilterCheck"=C:\WINDOWS\system32\NeroCheck.exe [2001-07-09 155648]
                          "trioService"=C:\Program Files\3D-Relax\Living Marine Aquarium 2.0 trial\trioService.exe [2005-12-23 69632]
                          "HP Software Update"=C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2007-05-08 54840]
                          "LVCOMSX"=C:\WINDOWS\system32\LVCOMSX.EXE [2005-07-19 221184]
                          "LogitechVideoRepair"=C:\Program Files\Logitech\Video\ISStart.exe [2005-06-08 458752]
                          "LogitechVideoTray"=C:\Program Files\Logitech\Video\LogiTray.exe [2005-06-08 217088]
                          "Adobe Photo Downloader"=C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe []
                          "SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2008-12-06 136600]
                          "BDAgent"=C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe [2009-04-06 778240]
                          "BitDefender Antiphishing Helper"=C:\Program Files\BitDefender\BitDefender 2009\IEShow.exe [2009-04-06 69632]
                          "QuickTime Task"=C:\Program Files\QuickTime\qttask.exe [2009-01-05 413696]
                          "Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-02-27 35696]
                          "iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2009-04-02 342312]

                          [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
                          "CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
                          "fsc-reminder.exe"=C:\WINDOWS\reminder\fsc-reminder.exe [2005-01-19 28672]
                          "lycosInside"=C:\Documents and Settings\Hélène Gautier\Mes documents\Outils\lycos\Lyc_SysTray.exe []
                          "Skype"=C:\Program Files\Skype\Phone\Skype.exe /nosplash /minimized []
                          "LogitechSoftwareUpdate"=C:\Program Files\Logitech\Video\ManifestEngine.exe [2005-06-08 196608]
                          "MsnMsgr"=C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe [2009-02-06 3885408]
                          "MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]
                          "swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2007-07-25 68856]

                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
                          C:\WINDOWS\system32\Ati2evxx.dll [2005-08-01 46080]

                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
                          C:\WINDOWS\system32\WgaLogon.dll [2007-02-15 236928]

                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
                          WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

                          [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
                          "dontdisplaylastusername"=0
                          "legalnoticecaption"=
                          "legalnoticetext"=
                          "shutdownwithoutlogon"=1
                          "undockwithoutlogon"=1

                          [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
                          "NoDriveTypeAutoRun"=145

                          [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
                          "HonorAutoRunSetting"=

                          [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
                          "C:\Program Files\LimeWire\LimeWire.exe"="C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire"
                          "C:\Program Files\Mozilla Firefox\firefox.exe"="C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox"
                          "%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
                          "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
                          "C:\Program Files\Windows Live\Messenger\wlcsdk.exe"="C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call"
                          "C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
                          "C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
                          "C:\Program Files\iTunes\iTunes.exe"="C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes"

                          [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
                          "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
                          "%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
                          "C:\Program Files\Windows Live\Messenger\wlcsdk.exe"="C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call"
                          "C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"

                          ======List of files/folders created in the last 1 months======

                          2009-05-09 19:55:55 ----D---- C:\Program Files\trend micro
                          2009-05-09 19:55:50 ----D---- C:\rsit
                          2009-05-09 16:34:55 ----A---- C:\WINDOWS\system32\OLD43.tmp
                          2009-05-09 16:34:54 ----D---- C:\WINDOWS\LastGood
                          2009-05-09 13:19:33 ----A---- C:\WINDOWS\msnfix.txt
                          2009-04-30 12:28:34 ----HDC---- C:\WINDOWS\$NtUninstallKB961503$
                          2009-04-28 23:21:38 ----HDC---- C:\WINDOWS\$NtUninstallKB961118$
                          2009-04-27 17:23:51 ----D---- C:\a3d0e4c57a646bda6b1b8698
                          2009-04-16 13:52:37 ----HDC---- C:\WINDOWS\$NtUninstallKB959426$
                          2009-04-16 13:52:09 ----HDC---- C:\WINDOWS\$NtUninstallKB961373$
                          2009-04-16 13:46:49 ----HDC---- C:\WINDOWS\$NtUninstallKB956572$
                          2009-04-16 13:46:18 ----HDC---- C:\WINDOWS\$NtUninstallKB952004$
                          2009-04-16 13:45:50 ----HDC---- C:\WINDOWS\$NtUninstallKB960803$
                          2009-04-16 13:39:29 ----HDC---- C:\WINDOWS\$NtUninstallKB923561$
                          2009-04-11 14:46:05 ----D---- C:\Program Files\iTunes
                          2009-04-11 14:46:05 ----D---- C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}

                          ======List of files/folders modified in the last 1 months======

                          2009-05-09 19:56:15 ----D---- C:\WINDOWS\Prefetch
                          2009-05-09 19:55:55 ----RD---- C:\Program Files
                          2009-05-09 17:34:34 ----D---- C:\WINDOWS\Debug
                          2009-05-09 17:34:34 ----D---- C:\WINDOWS
                          2009-05-09 17:34:26 ----D---- C:\WINDOWS\Minidump
                          2009-05-09 17:34:25 ----D---- C:\WINDOWS\Temp
                          2009-05-09 17:05:43 ----SHD---- C:\WINDOWS\Installer
                          2009-05-09 16:48:00 ----AC---- C:\WINDOWS\NeroDigital.ini
                          2009-05-09 16:35:02 ----RSHDC---- C:\WINDOWS\system32\dllcache
                          2009-05-09 16:34:56 ----AD---- C:\WINDOWS\system32
                          2009-05-09 16:34:37 ----D---- C:\WINDOWS\system32\CatRoot2
                          2009-05-09 15:20:40 ----N---- C:\WINDOWS\SchedLgU.Txt
                          2009-05-06 23:20:33 ----D---- C:\WINDOWS\system32\FxsTmp
                          2009-05-06 23:08:22 ----D---- C:\Documents and Settings\Hélène Gautier\Application Data\Image Zone Express
                          2009-05-06 18:11:46 ----D---- C:\WINDOWS\network diagnostic
                          2009-05-05 21:52:22 ----D---- C:\WINDOWS\system32\wbem
                          2009-05-05 21:52:21 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
                          2009-05-01 14:07:05 ----HD---- C:\WINDOWS\inf
                          2009-04-30 12:27:08 ----HD---- C:\Config.Msi
                          2009-04-29 17:01:17 ----SD---- C:\Documents and Settings\Hélène Gautier\Application Data\Microsoft
                          2009-04-29 12:18:17 ----HD---- C:\WINDOWS\$hf_mig$
                          2009-04-28 23:24:04 ----D---- C:\WINDOWS\system32\CatRoot
                          2009-04-27 19:33:02 ----D---- C:\WINDOWS\Microsoft.NET
                          2009-04-27 19:32:51 ----RSD---- C:\WINDOWS\assembly
                          2009-04-27 17:56:08 ----D---- C:\WINDOWS\system32\XPSViewer
                          2009-04-27 17:56:08 ----D---- C:\WINDOWS\system32\fr-fr
                          2009-04-27 17:42:30 ----D---- C:\WINDOWS\WinSxS
                          2009-04-27 17:27:36 ----D---- C:\WINDOWS\system32\en-us
                          2009-04-27 17:27:19 ----RSD---- C:\WINDOWS\Fonts
                          2009-04-16 14:08:21 ----D---- C:\WINDOWS\AppPatch
                          2009-04-16 13:42:56 ----A---- C:\WINDOWS\win.ini
                          2009-04-12 13:36:09 ----D---- C:\Program Files\Incomplete
                          2009-04-11 23:01:33 ----D---- C:\Program Files\LimeWire
                          2009-04-11 14:48:03 ----D---- C:\WINDOWS\system32\drivers
                          2009-04-11 14:47:48 ----DC---- C:\WINDOWS\system32\DRVSTORE
                          2009-04-11 14:46:44 ----D---- C:\Program Files\iPod
                          2009-04-11 14:46:36 ----D---- C:\Program Files\Fichiers communs\Apple

                          ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

                          R1 bdftdif;bdftdif; \??\C:\Program Files\Fichiers communs\BitDefender\BitDefender Firewall\bdftdif.sys []
                          R1 intelppm;Pilote de processeur Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40576]
                          R1 StarOpen;StarOpen; C:\WINDOWS\system32\drivers\StarOpen.sys [2009-04-09 5632]
                          R1 WmiAcpi;Interface de gestion Microsoft Windows pour ACPI; C:\WINDOWS\system32\DRIVERS\wmiacpi.sys [2008-04-13 8832]
                          R1 WS2IFSL;Environnement de prise en charge de Fournisseur de services non-IFS Windows Sockets 2.0; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2004-08-05 12032]
                          R2 BDVEDISK;BDVEDISK; \??\C:\Program Files\BitDefender\BitDefender 2009\BDVEDISK.sys []
                          R3 Arp1394;Protocole client ARP 1394; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-13 60800]
                          R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2005-08-01 1132544]
                          R3 bdfm;BDFM; C:\WINDOWS\system32\drivers\bdfm.sys [2008-09-18 111112]
                          R3 Bdfndisf;BitDefender Firewall NDIS Filter Service; C:\WINDOWS\system32\DRIVERS\bdfndisf.sys [2009-04-06 104328]
                          R3 bdfsfltr;bdfsfltr; C:\WINDOWS\system32\drivers\bdfsfltr.sys [2009-01-19 242184]
                          R3 BDSelfPr;BDSelfPr; \??\C:\Program Files\BitDefender\BitDefender 2009\bdselfpr.sys []
                          R3 CmBatt;Pilote d'adaptateur secteur Microsoft; C:\WINDOWS\system32\DRIVERS\CmBatt.sys [2008-04-13 13952]
                          R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys [2009-03-19 23400]
                          R3 HDAudBus;Pilote de bus Microsoft UAA pour High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
                          R3 HidUsb;Pilote de classe HID Microsoft; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
                          R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2005-08-01 3851264]
                          R3 mouhid;Pilote HID de souris; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-23 12288]
                          R3 NIC1394;Pilote réseau 1394; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-13 61824]
                          R3 Profos;Profos; \??\C:\Program Files\Fichiers communs\BitDefender\BitDefender Threat Scanner\profos.sys []
                          R3 RTL8023xp;Realtek 10/100/1000 NIC Family all in one NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtlnicxp.sys [2005-08-01 74496]
                          R3 Trufos;Trufos; \??\C:\Program Files\Fichiers communs\BitDefender\BitDefender Threat Scanner\trufos.sys []
                          R3 usbehci;Pilote miniport de contrôleur d'hôte amélioré Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
                          R3 usbhub;Concentrateur USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
                          R3 usbuhci;Pilote miniport de contrôleur hôte universel USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
                          R3 w29n51;Pilote de carte de connexion réseau Intel(R) PRO/Wireless 2200BG pour Windows XP; C:\WINDOWS\system32\DRIVERS\w29n51.sys [2005-08-01 3222784]
                          S3 CCDECODE;Décodeur sous-titre fermé; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
                          S3 HdAudAddService;Pilote de fonction Microsoft UAA pour Service High Definition Audio; C:\WINDOWS\system32\drivers\HdAudio.sys [2005-01-07 145920]
                          S3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\system32\DRIVERS\HPZid412.sys [2005-03-08 51120]
                          S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2005-03-08 16496]
                          S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2005-03-08 21744]
                          S3 LVUSBSta;Logitech USB Monitor Filter; C:\WINDOWS\system32\drivers\lvusbsta.sys [2005-05-27 22016]
                          S3 MSTEE;Convertisseur en T/site-à-site de répartition Microsoft; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
                          S3 NABTSFEC;Codec NABTS/FEC VBI; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
                          S3 NdisIP;Connection TV/vidéo Microsoft; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
                          S3 QCMerced;Logitech QuickCam Communicate; C:\WINDOWS\system32\DRIVERS\LVCM.sys [2005-05-27 1317152]
                          S3 rtl8139;Pilote NT de carte Realtek PCI Fast Ethernet à base RTL8139(A/B/C); C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2004-08-04 20992]
                          S3 SLIP;Détrameur décalage BDA; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
                          S3 ssm_bus;SAMSUNG Mobile USB Device II 1.0 driver (WDM); C:\WINDOWS\system32\DRIVERS\ssm_bus.sys [2005-08-30 58320]
                          S3 ssm_mdfl;SAMSUNG Mobile USB Modem II 1.0 Filter; C:\WINDOWS\system32\DRIVERS\ssm_mdfl.sys [2005-08-30 8336]
                          S3 ssm_mdm;SAMSUNG Mobile USB Modem II 1.0 Drivers; C:\WINDOWS\system32\DRIVERS\ssm_mdm.sys [2005-08-30 94000]
                          S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
                          S3 usbaudio;Pilote USB audio (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2008-04-13 60032]
                          S3 usbccgp;Pilote parent générique USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
                          S3 usbprint;Classe d'imprimantes USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
                          S3 usbscan;Pilote de scanneur USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
                          S3 USBSTOR;Pilote de stockage de masse USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
                          S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
                          S3 WSTCODEC;Codec Teletext standard; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]

                          ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

                          R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2009-03-06 132424]
                          R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2005-08-01 364544]
                          R2 Bonjour Service;Service Bonjour; C:\Program Files\Bonjour\mDNSResponder.exe [2008-12-12 238888]
                          R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2008-12-06 152984]
                          R2 LIVESRV;BitDefender Desktop Update Service; C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe [2009-04-06 415024]
                          R2 MDM;Machine Debug Manager; C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-20 322120]
                          R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\system32\HPZipm12.exe [2007-08-09 73728]
                          R2 SeaPort;SeaPort; C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-01-14 226656]
                          R2 VSSERV;BitDefender Virus Shield; C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe [2009-04-06 1626112]
                          R3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
                          R3 iPod Service;Service de l’iPod; C:\Program Files\iPod\bin\iPodService.exe [2009-04-02 656168]
                          S2 Fax;Fax; C:\WINDOWS\system32\fxssvc.exe [2008-04-14 268800]
                          S3 Arrakis3;BitDefender Arrakis Server; C:\Program Files\Fichiers communs\BitDefender\BitDefender Arrakis Server\bin\Arrakis3.exe [2008-07-17 118784]
                          S3 aspnet_state;Service d'état ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
                          S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
                          S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
                          S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-04-24 182768]
                          S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
                          S3 ose;Office Source Engine; C:\Program Files\Fichiers communs\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
                          S3 scan;BitDefender Threat Scanner; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
                          S3 WMPNetworkSvc;Service Partage réseau du Lecteur Windows Media; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-11-03 918016]
                          S4 NetTcpPortSharing;Service de partage de ports Net.Tcp; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

                          -----------------EOF-----------------
                          0
                          1. pour gagner du temps
                            demarrer
                            rechercher
                            report.txt

                            sinon il se trouve dans poste de travail puis C puis sdfix...
                            0
                            1. j'ai bien compris comment faire pour retrouver ce dossier, mais il n'est pas la...
                              J'ai fais les 2 methodes et rien... Je suis retourner en mode sans echec, j'ai refais la manip, mais toujours rien.
                              Je ne trouve pas ce fichier... Il est essentiel pour continuer d'avancer ?...
                              0
                          2. Contributeur sécurité
                            ton log texte ne resemble pas à ce qu'il devrait tu as bien accepter l'installation de hijackthis pendant l'utilisation regarde comment est le log.txt http://www.commentcamarche.net/forum/affich 12311258 rundll symptomes etranges?#2
                            0
                            1. Oh la la, merci pour votre patience !
                              voici le rapport :

                              [b]SDFix: Version 1.240 [/b]
                              Run by H‚lŠne Gautier on 09/05/2009 at 21:54

                              Microsoft Windows XP [version 5.1.2600]
                              Running From: C:\SDFix

                              [b]Checking Services [/b]:

                              Restoring Default Security Values
                              Restoring Default Hosts File

                              Rebooting

                              [b]Checking Files [/b]:

                              No Trojan Files Found

                              Removing Temp Files

                              [b]ADS Check [/b]:

                              [b]Final Check [/b]:

                              catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                              Rootkit scan 2009-05-09 22:12:56
                              Windows 5.1.2600 Service Pack 3 NTFS

                              scanning hidden processes ...

                              scanning hidden services & system hive ...

                              scanning hidden registry entries ...

                              [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{54F479AB-3EF4-14A6-0280-6050D2875F57}]
                              "naoigmmflccfioampfcnncfnnkop"=hex:6a,61,63,6e,63,6e,69,70,6e,6b,6c,6a,61,64,6e,62,6d,6f,69,6b,00,..
                              "maejimpckhmibndecfjcbidmob"=hex:6a,61,62,6e,6c,6d,70,70,63,6b,6e,6c,67,6f,61,65,65,6b,66,6e,00,..

                              scanning hidden files ...

                              scan completed successfully
                              hidden processes: 0
                              hidden services: 0
                              hidden files: 0

                              [b]Remaining Services [/b]:

                              Authorized Application Key Export:

                              [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
                              "C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"
                              "C:\\Program Files\\Mozilla Firefox\\firefox.exe"="C:\\Program Files\\Mozilla Firefox\\firefox.exe:*:Enabled:Firefox"
                              "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
                              "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
                              "C:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"="C:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe:*:Enabled:Windows Live Call"
                              "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
                              "C:\\Program Files\\Bonjour\\mDNSResponder.exe"="C:\\Program Files\\Bonjour\\mDNSResponder.exe:*:Enabled:Bonjour"
                              "C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"

                              [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
                              "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
                              "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
                              "C:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"="C:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe:*:Enabled:Windows Live Call"
                              "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"

                              [b]Remaining Files [/b]:

                              [b]Files with Hidden Attributes [/b]:

                              Fri 25 May 2007 4,348 A.SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
                              Thu 29 Jan 2009 9,934,392 A..H. --- "C:\Program Files\Google\Picasa3\setup.exe"
                              Sun 4 Feb 2007 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
                              Sun 7 Jan 2007 76,288 ...H. --- "C:\Documents and Settings\H‚lŠne Gautier\Mes documents\Formation\ASAP\~WRL0005.tmp"
                              Mon 26 Aug 2002 98,304 ...H. --- "C:\Documents and Settings\H‚lŠne Gautier\Mes documents\Psycho et CV\Stage1\~WRL0004.tmp"

                              [b]Finished![/b]

                              et je vais voir pourquoi l'autre truc ne ressemble pas a ce a quoi il devrait ressembler...
                              0
                            2. @malolinePeut-etre que ceci est mieux ?...

                              Logfile of random's system information tool 1.06 (written by random/random)
                              Run by Hélène Gautier at 2009-05-09 22:26:38
                              Microsoft Windows XP Édition familiale Service Pack 3
                              System drive C: has 48 GB (63%) free of 76 GB
                              Total RAM: 511 MB (27% free)

                              Logfile of Trend Micro HijackThis v2.0.2
                              Scan saved at 22:27:54, on 09/05/2009
                              Platform: Windows XP SP3 (WinNT 5.01.2600)
                              MSIE: Internet Explorer v8.00 (8.00.6001.18702)
                              Boot mode: Normal

                              Running processes:
                              C:\WINDOWS\System32\smss.exe
                              C:\WINDOWS\system32\winlogon.exe
                              C:\WINDOWS\system32\services.exe
                              C:\WINDOWS\system32\lsass.exe
                              C:\WINDOWS\system32\Ati2evxx.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
                              C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe
                              C:\WINDOWS\System32\svchost.exe
                              C:\WINDOWS\system32\spoolsv.exe
                              C:\WINDOWS\system32\Ati2evxx.exe
                              C:\WINDOWS\Explorer.EXE
                              C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                              C:\Program Files\Bonjour\mDNSResponder.exe
                              C:\Program Files\Java\jre6\bin\jqs.exe
                              C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
                              C:\WINDOWS\system32\HPZipm12.exe
                              C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\system32\wbem\wmiapsrv.exe
                              C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                              C:\WINDOWS\SOUNDMAN.EXE
                              C:\Program Files\3D-Relax\Living Marine Aquarium 2.0 trial\trioService.exe
                              C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                              C:\WINDOWS\system32\LVCOMSX.EXE
                              C:\Program Files\Logitech\Video\LogiTray.exe
                              C:\Program Files\Java\jre6\bin\jusched.exe
                              C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe
                              C:\Program Files\QuickTime\qttask.exe
                              C:\Program Files\iTunes\iTunesHelper.exe
                              C:\WINDOWS\system32\ctfmon.exe
                              C:\Program Files\BitDefender\BitDefender 2009\seccenter.exe
                              C:\Program Files\Internet Explorer\iexplore.exe
                              C:\Program Files\Logitech\Video\FxSvr2.exe
                              C:\Program Files\iPod\bin\iPodService.exe
                              C:\Program Files\Internet Explorer\iexplore.exe
                              C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
                              C:\Documents and Settings\Hélène Gautier\Bureau\RSIT.exe
                              C:\Program Files\trend micro\Hélène Gautier.exe

                              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://outlook.live.com/owa/
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                              R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=http://localhost:6080;https=http://localhost:6080
                              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                              O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
                              O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
                              O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
                              O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
                              O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                              O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
                              O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
                              O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
                              O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                              O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                              O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
                              O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2009\IEToolbar.dll
                              O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                              O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
                              O4 - HKLM\..\Run: [Raccourci vers la page des propriétés de High Definition Audio] HDAShCut.exe
                              O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                              O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
                              O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
                              O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
                              O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
                              O4 - HKLM\..\Run: [trioService] "C:\Program Files\3D-Relax\Living Marine Aquarium 2.0 trial\trioService.exe "
                              O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                              O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
                              O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
                              O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
                              O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe"
                              O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                              O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe"
                              O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2009\IEShow.exe"
                              O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                              O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
                              O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                              O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                              O4 - HKCU\..\Run: [fsc-reminder.exe] C:\WINDOWS\reminder\fsc-reminder.exe 2453884 14
                              O4 - HKCU\..\Run: [lycosInside] C:\Documents and Settings\Hélène Gautier\Mes documents\Outils\lycos\Lyc_SysTray.exe
                              O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
                              O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
                              O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                              O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                              O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                              O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                              O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                              O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
                              O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
                              O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
                              O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
                              O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                              O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                              O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                              O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                              O15 - Trusted Zone: http://www.secuser.com
                              O16 - DPF: {104B0A37-AB99-4F06-8032-8BBDC3B77DDB} (Telechargement Control) - http://www2.photoweb.fr/telechargement/Photoweb_uploader.cab
                              O16 - DPF: {1F83CD9E-505E-4F87-BECE-0832A763E36F} (Image Uploader 3.0 Control) - http://www.mypixmania.com/be/fr/importer/MypixUploader.cab
                              O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab
                              O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} (Image Uploader Control) - http://express.foto.com/ImageUploader5.cab
                              O16 - DPF: {68C1822F-F5C7-4404-A73F-03C10E0E94DA} (telechargement-photoweb) - http://www4.photoweb.fr/telechargement/Photoweb_uploader.cab
                              O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://www.new2.foto.com/ImageUploader4.cab
                              O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
                              O16 - DPF: {8F48147B-78D9-40F9-ACC0-BDDE59B246F4} (AccountHelper Class) - http://abonnement.aliceadsl.fr/configurateur/AccountHelper.cab
                              O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.5 Control) - http://photo.laredoute.fr/ImageUploader3.cab
                              O16 - DPF: {A73BAEFA-EE65-494D-BEDB-DD3E5A34FA98} (Image Uploader) - http://www.extrafilm.fr/ImageUploader4.cab
                              O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game13.zylom.com/activex/zylomgamesplayer.cab
                              O16 - DPF: {C36112BF-2FA3-4694-8603-3B510EA3B465} (Lycos File Upload Component) - http://f001.mail.caramail.lycos.fr/app/uploader/FileUploader.cab
                              O16 - DPF: {CE3409C4-9E26-4F8E-83E4-778498F9E7B4} (PB_Uploader Class) - https://www.photobox.fr/?channel=1005
                              O16 - DPF: {FB90BA05-66E6-4C56-BCD3-D65B0F7EBA39} (Foto.com SpeedUploader 1.0 Control) - http://fotobook.foto.com/activex/SpeedUploader.cab
                              O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
                              O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                              O23 - Service: BitDefender Arrakis Server (Arrakis3) - BitDefender S.R.L. https://www.bitdefender.fr/ - C:\Program Files\Fichiers communs\BitDefender\BitDefender Arrakis Server\bin\Arrakis3.exe
                              O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                              O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                              O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                              O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
                              O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                              O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
                              O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
                              O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
                              O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S. R. L. - C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe
                              0
                            3. @malolineAlors, j'ai téléchargé LiveKill qui est censé nettoyer windowslive, qui me dit que je n'ai aucune infection.
                              Pourtant, a chaque fois que j'ouvre un fenetre pour envoyer un mail (soit "nouveau", soit "repondre"), le message "dear friend....." s'affiche automatiquement. Je suis allée sur leur site en leur demandant de me supprimer de leur liste...
                              J'ai egalement changé de mot de passe et de question sur windows live...
                              Dois-je tout supprimer et tout rénstaller ?
                              Voyez vous qq chose de suspect dans mes comptes rendus ?
                              Merci de m'aider encore...
                              0
                          3. Contributeur sécurité
                            désolé si on n'a pas trouvé la réponse , as tu essaié avec msnfix ??
                            sinon on essaira avec un autre outil

                            Télécharger sur le bureau
                            https://www.malekal.com/supprimer-virus-desinfecter-pc/ "aide toi du tutoriel "
                            Cliques-Droit sur MSNFix.zip
                            Extraire ici ( ou extraire sans confirmation ou tout ou unzip)

                            Double-Clique sur le dossier MSNfix qui vient de se créer
                            Double-Clique MSNfix ==> Symbole roue dentée
                            Note: Avec vista pas de double-clic mais faire un clic-droit , puis exécuter en tant qu'administrateur

                            Choisir F pour français

                            Choisir R
                            Choisir ensuite A quand le choix se présent
                            Choisir ensuite N ( si infection)
                            Enregistrer le rapport sur le bureau de préférence
                            si besion d'aide tutoriels:
                            https://www.malekal.com/supprimer-virus-desinfecter-pc/
                            http://sosvirus.changelog.fr/
                            0
                            1. je ne veux pas paraitre impolie. j'en ai juste apres windows live, ca s'arrete la ! au contraire, je vous emercie de bien vouloir m'aider
                              j'ai fait la manip que vous m'indiquer hier. voici le rapport:

                              [b]SDFix: Version 1.240 [/b]
                              Run by H‚lŠne Gautier on 09/05/2009 at 21:54

                              Microsoft Windows XP [version 5.1.2600]
                              Running From: C:\SDFix

                              [b]Checking Services [/b]:

                              Restoring Default Security Values
                              Restoring Default Hosts File

                              Rebooting

                              [b]Checking Files [/b]:

                              No Trojan Files Found

                              Removing Temp Files

                              [b]ADS Check [/b]:

                              [b]Final Check [/b]:

                              catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                              Rootkit scan 2009-05-09 22:12:56
                              Windows 5.1.2600 Service Pack 3 NTFS

                              scanning hidden processes ...

                              scanning hidden services & system hive ...

                              scanning hidden registry entries ...

                              [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{54F479AB-3EF4-14A6-0280-6050D2875F57}]
                              "naoigmmflccfioampfcnncfnnkop"=hex:6a,61,63,6e,63,6e,69,70,6e,6b,6c,6a,61,64,6e,62,6d,6f,69,6b,00,..
                              "maejimpckhmibndecfjcbidmob"=hex:6a,61,62,6e,6c,6d,70,70,63,6b,6e,6c,67,6f,61,65,65,6b,66,6e,00,..

                              scanning hidden files ...

                              scan completed successfully
                              hidden processes: 0
                              hidden services: 0
                              hidden files: 0

                              [b]Remaining Services [/b]:

                              Authorized Application Key Export:

                              [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
                              "C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"
                              "C:\\Program Files\\Mozilla Firefox\\firefox.exe"="C:\\Program Files\\Mozilla Firefox\\firefox.exe:*:Enabled:Firefox"
                              "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
                              "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
                              "C:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"="C:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe:*:Enabled:Windows Live Call"
                              "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
                              "C:\\Program Files\\Bonjour\\mDNSResponder.exe"="C:\\Program Files\\Bonjour\\mDNSResponder.exe:*:Enabled:Bonjour"
                              "C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"

                              [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
                              "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
                              "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
                              "C:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"="C:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe:*:Enabled:Windows Live Call"
                              "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"

                              [b]Remaining Files [/b]:

                              [b]Files with Hidden Attributes [/b]:

                              Fri 25 May 2007 4,348 A.SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
                              Thu 29 Jan 2009 9,934,392 A..H. --- "C:\Program Files\Google\Picasa3\setup.exe"
                              Sun 4 Feb 2007 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
                              Sun 7 Jan 2007 76,288 ...H. --- "C:\Documents and Settings\H‚lŠne Gautier\Mes documents\Formation\ASAP\~WRL0005.tmp"
                              Mon 26 Aug 2002 98,304 ...H. --- "C:\Documents and Settings\H‚lŠne Gautier\Mes documents\Psycho et CV\Stage1\~WRL0004.tmp"

                              [b]Finished![/b]
                              0
                          4. Contributeur sécurité
                            essais avec msnfix et puis on passera combofix
                            0
                            1. j'ai fait la manip 3 ois, ainsi qu'en mode sans echec, mais aucun fichier report n'apparait ?...
                              0
                          5. bonjour,
                            regarde sur mon message hacker ou pas, comment le retirer?
                            0
                            • 1
                            • 2