Thayet myo hacking day

Bonjour,
Je vous expose mon problème,
Apparement dans l'apres midi j'ai chopé un virus nommé " thayet myo hacking day ".
J'ai pu constaté qu'il bloque le gestionnaire de tache ( logique :p ), qu'il me ralentit mon pc, qu'il y a une ptite barre " thayet myo hacking day " qui se balade sur mon bureau, et enfin la touche " Arret defil" s'active et se desactive sans cesse !

Quelqu'un aurai une solution pour suprimer ce virus?
J'ai essayé mon antivirus AVG + Spybots, sans succès :(
Merci de votre aide !
Configuration: Windows Vista
Firefox 3.0.10

13 réponses

  1. Contributeur sécurité
    slt,

    Télécharge ici :

    http://images.malwareremoval.com/random/RSIT.exe

    random's system information tool (RSIT) par andom/random et sauvegarde-le sur le Bureau.

    Double-clique sur RSIT.exe afin de lancer RSIT.

    Clique Continue à l'écran Disclaimer.

    Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.

    Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront.

    Poste le contenu de log.txt (<<qui sera affiché)
    ainsi que de info.txt (<<qui sera réduit dans la Barre des Tâches).

    NB : Les rapports sont sauvegardés dans le dossier C:\rsit
    1
    1. ou dois je poste ses rapports
      0
    2. tu pe m'aidé stl jss rentré dan le cite ke ta mi
      g fai " random's system information tool (RSIT) par andom/random et sauvegarde-le sur le Bureau."pr le reste c pa sur ke g fai tou bn é g u une imag ki aparé g laissé sur le bureau mai ya tjr c msg du verusss ki narret pa de défilé mai tomieu le clavier remarch a nouvo car il fesé ke d coneri et sa klinioté maiiiiiiii le pc é tjr aussi lng mai c msg m'enerv c vrai kil ya po plu ke dab mai ils sont tjr la tu pe m'aidé
      0
  2. Contributeur sécurité
    c'etait ici dans ton prochain message mais depuis un mois....
    1
    1. Salut ,

      copie colle le rapport log.txt de rsit stp , on t aidera ensuite
      1
      1. merci c bn g fai ske ta di et c bn merci pr le cou d main
        0
        1. Contributeur sécurité
          il faut que tu mettes les deux rapport sur le site dans ton prochain message !
          0
          1. vous expose mon problème,
            Apparement dans l'apres midi j'ai chopé un virus nommé " thayet myo hacking day et j'ai fait l'analyse et voila le resultat :

            Logfile of random's system information tool 1.06 (written by random/random)
            Run by king at 2009-08-01 00:41:08
            WIN_XP Service Pack 3
            System drive E: has 10 GB (51%) free of 19 GB
            Total RAM: 1022 MB (63% free)

            Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 00:41:08, on 01/08/2009
            Platform: Windows XP SP3 (WinNT 5.01.2600)
            MSIE: Internet Explorer v8.00 (8.00.6001.18702)
            Boot mode: Normal

            Running processes:
            E:\WINDOWS\System32\smss.exe
            E:\WINDOWS\system32\winlogon.exe
            E:\WINDOWS\system32\services.exe
            E:\WINDOWS\system32\lsass.exe
            E:\WINDOWS\system32\svchost.exe
            E:\WINDOWS\System32\svchost.exe
            E:\WINDOWS\system32\spoolsv.exe
            E:\WINDOWS\Explorer.EXE
            E:\WINDOWS\system32\RUNDLL32.EXE
            E:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe
            E:\Program Files\iTunes\iTunesHelper.exe
            E:\Program Files\Winamp\winampa.exe
            E:\WINDOWS\BackUp\explorer.exe
            E:\WINDOWS\system32\ctfmon.exe
            E:\Program Files\DNA\btdna.exe
            E:\Program Files\Internet Download Manager\IDMan.exe
            E:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
            E:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
            E:\Program Files\Bonjour\mDNSResponder.exe
            E:\WINDOWS\system32\nvsvc32.exe
            E:\Program Files\iPod\bin\iPodService.exe
            E:\Program Files\Internet Download Manager\IEMonitor.exe
            E:\WINDOWS\system32\wuauclt.exe
            E:\DOCUME~1\king\LOCALS~1\Temp\Rar$EX00.407\nasser135\mpcs.exe
            E:\DOCUME~1\king\LOCALS~1\Temp\Rar$EX00.407\nasser135\mpcs.exe
            E:\DOCUME~1\king\LOCALS~1\Temp\Rar$EX00.407\nasser135\mpcs.exe
            E:\DOCUME~1\king\LOCALS~1\Temp\Rar$EX00.407\nasser135\mpcs.exe
            E:\DOCUME~1\king\LOCALS~1\Temp\Rar$EX00.407\nasser135\mpcs.exe
            E:\DOCUME~1\king\LOCALS~1\Temp\Rar$EX00.407\nasser135\mpcs.exe
            E:\DOCUME~1\king\LOCALS~1\Temp\Rar$EX00.407\nasser135\mpcs.exe
            E:\DOCUME~1\king\LOCALS~1\Temp\Rar$EX00.407\nasser135\mpcs.exe
            E:\Program Files\Mozilla Firefox\firefox.exe
            E:\Program Files\Windows Live\Messenger\msnmsgr.exe
            E:\Documents and Settings\king\Mes documents\Downloads\Programs\RSIT.exe
            E:\Documents and Settings\king\Mes documents\Downloads\Programs\king.exe

            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
            O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - E:\Program Files\Internet Download Manager\IDMIECC.dll
            O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - E:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
            O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
            O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - E:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
            O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE E:\WINDOWS\system32\NvCpl.dll,NvStartup
            O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
            O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE E:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
            O4 - HKLM\..\Run: [HDAudDeck] E:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe 1
            O4 - HKLM\..\Run: [QuickTime Task] "E:\Program Files\QuickTime\qttask.exe" -atboottime
            O4 - HKLM\..\Run: [iTunesHelper] "E:\Program Files\iTunes\iTunesHelper.exe"
            O4 - HKLM\..\Run: [WinampAgent] "E:\Program Files\Winamp\winampa.exe"
            O4 - HKLM\..\Run: [explorer] E:\WINDOWS\BackUp\explorer.exe
            O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "E:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
            O4 - HKCU\..\Run: [CTFMON.EXE] E:\WINDOWS\system32\ctfmon.exe
            O4 - HKCU\..\Run: [BitTorrent DNA] "E:\Program Files\DNA\btdna.exe"
            O4 - HKCU\..\Run: [IDMan] E:\Program Files\Internet Download Manager\IDMan.exe /onboot
            O4 - HKCU\..\Run: [MsnMsgr] "E:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
            O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] E:\WINDOWS\system32\CTFMON.EXE (User '?')
            O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] E:\WINDOWS\system32\CTFMON.EXE (User '?')
            O4 - HKUS\S-1-5-21-861567501-57989841-1606980848-1002\..\Run: [CTFMON.EXE] E:\WINDOWS\system32\ctfmon.exe (User '?')
            O4 - HKUS\S-1-5-21-861567501-57989841-1606980848-1002\..\Run: [MsnMsgr] "E:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background (User '?')
            O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] E:\WINDOWS\system32\CTFMON.EXE (User '?')
            O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] E:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
            O8 - Extra context menu item: Télécharger avec IDM - E:\Program Files\Internet Download Manager\IEExt.htm
            O8 - Extra context menu item: Télécharger le contenu de video FLV avec IDM - E:\Program Files\Internet Download Manager\IEGetVL.htm
            O8 - Extra context menu item: Télécharger tous les liens avec IDM - E:\Program Files\Internet Download Manager\IEGetAll.htm
            O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - E:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - E:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
            O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
            O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
            O17 - HKLM\System\CCS\Services\Tcpip\..\{AE5C1D1A-130C-4637-A1AD-EEFBD290306D}: NameServer = 4.2.2.4 4.2.2.3
            O23 - Service: Apple Mobile Device - Apple, Inc. - E:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
            O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - E:\Program Files\Bonjour\mDNSResponder.exe
            O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - E:\Program Files\iPod\bin\iPodService.exe
            O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - E:\WINDOWS\system32\nvsvc32.exe
            0
            1. Contributeur sécurité
              Télécharge et install UsbFix de C_XX & Chiquitine29

              Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptible d'avoir été infectées sans les ouvrir
              http://sd-1.archive-host.com/membres/up/127028005715545653/UsbFix.exe

              # Double clic sur le raccourci UsbFix présent sur ton bureau .

              # Choisis l'option 1 ( Recherche )

              # Laisse travailler l'outil.

              # Ensuite post le rapport UsbFix.txt qui apparaitra.

              # Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque. ( C:\UsbFix.txt )

              ( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

              # Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
              Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
              Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.
              0
              1. salut bin apropos du logicielle que vs me avez envoyé j'ai fais l'analyse avec le UsbFix:

                ############################## | UsbFix V6.012 |

                User : Administrateur (Administrateurs) # SWEET-D071C2E67
                Update on 01/08/09 by Chiquitine29 & C_XX
                Start at: 20:12:34 | 02/08/2009
                Website : http://pagesperso-orange.fr/NosTools/index.html

                Intel(R) Pentium(R) 4 CPU 3.00GHz
                Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 3
                Internet Explorer 7.0.5730.13
                Windows Firewall Status : Enabled
                AV : avast! antivirus 4.8.1335 [VPS 090801-0] 4.8.1335 [ Enabled | Updated ]

                C:\ -> Disque fixe local # 23,82 Go (12,85 Go free) # NTFS
                D:\ -> Disque fixe local # 18,63 Go (10,99 Go free) # NTFS
                E:\ -> Disque fixe local # 18,63 Go (420,03 Mo free) [MUSIC et tofs] # NTFS
                F:\ -> Disque fixe local # 18,63 Go (6,43 Go free) [MUSIC+VIDEO] # NTFS
                G:\ -> Disque fixe local # 18,63 Go (270,41 Mo free) [COMPILATION DE MUSIC] # NTFS
                H:\ -> Disque fixe local # 9,77 Go (883,6 Mo free) # NTFS
                I:\ -> Disque CD-ROM
                J:\ -> Disque amovible # 1,88 Go (0,26 Mo free) [A-DATA UFD] # FAT32
                K:\ -> Disque amovible # 7,45 Go (5,39 Go free) [KINGSTON] # FAT32

                ############################## | Processus actifs |

                C:\WINDOWS\System32\smss.exe
                C:\WINDOWS\system32\csrss.exe
                C:\WINDOWS\system32\winlogon.exe
                C:\WINDOWS\system32\services.exe
                C:\WINDOWS\system32\lsass.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\System32\svchost.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\system32\svchost.exe
                C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                C:\Program Files\Alwil Software\Avast4\ashServ.exe
                C:\WINDOWS\Explorer.EXE
                C:\Program Files\XpertVision\TBPanel.exe
                C:\WINDOWS\system32\RUNDLL32.EXE
                C:\Program Files\Winamp\winampa.exe
                C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                C:\WINDOWS\system32\ctfmon.exe
                C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
                C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                C:\Program Files\Internet Download Manager\IDMan.exe
                C:\WINDOWS\system32\spoolsv.exe
                C:\WINDOWS\system32\svchost.exe
                C:\Program Files\Fichiers communs\Nero\Nero BackItUp 4\NBService.exe
                C:\WINDOWS\system32\nvsvc32.exe
                C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                C:\WINDOWS\System32\alg.exe
                C:\Program Files\Internet Download Manager\IEMonitor.exe
                C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX12.62640\nasser135\mpcs.exe
                C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX12.62640\nasser135\mpcs.exe
                C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX12.62640\nasser135\mpcs.exe
                C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX12.62640\nasser135\mpcs.exe
                C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX12.62640\nasser135\mpcs.exe
                C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX12.62640\nasser135\mpcs.exe
                C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX12.62640\nasser135\mpcs.exe
                C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX12.62640\nasser135\mpcs.exe
                C:\WINDOWS\system32\svchost.exe
                C:\Program Files\Windows Live\Messenger\usnsvc.exe
                C:\Program Files\Internet Explorer\iexplore.exe
                C:\WINDOWS\system32\wbem\wmiprvse.exe

                ################## | Fichiers # Dossiers infectieux |

                Présent ! C:\devcon.exe
                Présent ! C:\DPsFnshr.exe
                Présent ! C:\makePNF.exe
                Présent ! C:\mute.exe
                Présent ! C:\pmtimer.exe
                Présent ! J:\explorer.exe
                Présent ! J:\New Folder.exe
                Présent ! J:\SSVICHOSST.exe
                Présent ! J:\xih9.cmd
                Présent ! K:\explorer.exe

                ################## | Other |

                ################## | Registre # Clés Run infectieuses |

                Présent ! HKLM\software\microsoft\security center "AntiVirusOverride" ( 0x1 )

                ################## | Registre # Mountpoints2 |

                ################## | Cracks / Keygens / Serials |

                ################## | ! Fin du rapport # UsbFix V6.012 ! |

                ET AVEC LE 2EME LOGICIELLE RSIT:

                Logfile of random's system information tool 1.06 (written by random/random)
                Run by Administrateur at 2009-08-02 20:12:40
                Microsoft Windows XP Professionnel Service Pack 3
                System drive C: has 13 GB (54%) free of 24 GB
                Total RAM: 1022 MB (33% free)

                Logfile of Trend Micro HijackThis v2.0.2
                Scan saved at 20:12:42, on 02/08/2009
                Platform: Windows XP SP3 (WinNT 5.01.2600)
                MSIE: Internet Explorer v7.00 (7.00.6000.21073)
                Boot mode: Normal

                Running processes:
                C:\WINDOWS\System32\smss.exe
                C:\WINDOWS\system32\winlogon.exe
                C:\WINDOWS\system32\services.exe
                C:\WINDOWS\system32\lsass.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\System32\svchost.exe
                C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                C:\Program Files\Alwil Software\Avast4\ashServ.exe
                C:\WINDOWS\Explorer.EXE
                C:\Program Files\XpertVision\TBPanel.exe
                C:\WINDOWS\system32\RUNDLL32.EXE
                C:\Program Files\Winamp\winampa.exe
                C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                C:\WINDOWS\system32\ctfmon.exe
                C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
                C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                C:\Program Files\Internet Download Manager\IDMan.exe
                C:\WINDOWS\system32\spoolsv.exe
                C:\Program Files\Fichiers communs\Nero\Nero BackItUp 4\NBService.exe
                C:\WINDOWS\system32\nvsvc32.exe
                C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                C:\Program Files\Internet Download Manager\IEMonitor.exe
                C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX12.62640\nasser135\mpcs.exe
                C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX12.62640\nasser135\mpcs.exe
                C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX12.62640\nasser135\mpcs.exe
                C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX12.62640\nasser135\mpcs.exe
                C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX12.62640\nasser135\mpcs.exe
                C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX12.62640\nasser135\mpcs.exe
                C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX12.62640\nasser135\mpcs.exe
                C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX12.62640\nasser135\mpcs.exe
                C:\WINDOWS\system32\svchost.exe
                C:\Program Files\Windows Live\Messenger\usnsvc.exe
                C:\Program Files\Internet Explorer\iexplore.exe
                C:\WINDOWS\system32\cmd.exe
                C:\Documents and Settings\Administrateur\Mes documents\Downloads\Programs\RSIT.exe
                D:\Documents and Settings\king\Mes documents\Downloads\Programs\Administrateur.exe

                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
                O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
                O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.15642\swg.dll
                O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
                O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
                O4 - HKLM\..\Run: [Gainward] C:\Program Files\XpertVision\TBPanel.exe /A
                O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
                O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
                O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                O4 - HKCU\..\Run: [AROReminder] C:\Program Files\Advanced Registry Optimizer\ARO.exe -rem
                O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                O4 - HKCU\..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot
                O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                O4 - HKUS\S-1-5-19\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'SERVICE LOCAL')
                O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                O4 - HKUS\S-1-5-20\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'SERVICE RÉSEAU')
                O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                O4 - HKUS\S-1-5-18\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'SYSTEM')
                O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                O4 - HKUS\.DEFAULT\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'Default user')
                O8 - Extra context menu item: Télécharger avec IDM - C:\Program Files\Internet Download Manager\IEExt.htm
                O8 - Extra context menu item: Télécharger le contenu de video FLV avec IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm
                O8 - Extra context menu item: Télécharger tous les liens avec IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm
                O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - http://download.eset.com/special/eos/OnlineScanner.cab
                O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
                O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
                O17 - HKLM\System\CCS\Services\Tcpip\..\{E40AFA89-6FE2-4458-91D3-3786CFB54C9E}: NameServer = 4.2.2.4 4.2.2.3
                O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
                O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Fichiers communs\Nero\Nero BackItUp 4\NBService.exe
                O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                0
                1. Contributeur sécurité
                  ok colle un rapport avec usbfix option 2 . Puis remets un rapport rsit
                  0
                  1. Logfile of random's system information tool 1.06 (written by random/random)
                    Run by Windows at 2009-08-01 02:35:48
                    Microsoft Windows XP Professionnel Service Pack 2
                    System drive C: has 14 GB (74%) free of 18 GB
                    Total RAM: 95 MB (9% free)

                    Logfile of Trend Micro HijackThis v2.0.2
                    Scan saved at 2:36:24, on 01-08-2009
                    Platform: Windows XP SP2 (WinNT 5.01.2600)
                    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                    Boot mode: Normal

                    Running processes:
                    C:\WINDOWS\System32\smss.exe
                    C:\WINDOWS\system32\winlogon.exe
                    C:\WINDOWS\system32\services.exe
                    C:\WINDOWS\system32\lsass.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\WINDOWS\Explorer.EXE
                    C:\WINDOWS\system32\spoolsv.exe
                    C:\WINDOWS\soundman.exe
                    C:\WINDOWS\BackUp\explorer.exe
                    C:\WINDOWS\system32\E1608D\D46C8C.EXE
                    C:\WINDOWS\system32\ctfmon.exe
                    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                    C:\Program Files\MSN Messenger\MsnMsgr.Exe
                    C:\WINDOWS\system32\wuauclt.exe
                    C:\Program Files\Lavalys\EVEREST Home Edition\everest.exe
                    C:\Program Files\Lavalys\EVEREST Home Edition\everest.exe
                    C:\Program Files\Internet Explorer\iexplore.exe
                    C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
                    C:\Program Files\MSN Messenger\msnmsgr.exe
                    C:\Documents and Settings\Windows\Local Settings\Temporary Internet Files\Content.IE5\6XYRYZ6N\RSIT[1].exe
                    C:\Program Files\trend micro\Windows.exe

                    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
                    O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
                    O2 - BHO: UrlHelper Class - {74322BF9-DF26-493f-B0DA-6D2FC5E6429E} - C:\Program Files\BearShare Applications\BearShare\BearShareIEHelper.dll
                    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
                    O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                    O3 - Toolbar: BearShare MediaBar - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - C:\Program Files\BearShare Applications\BearShare MediaBar\BearShareMediaBar.dll
                    O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                    O4 - HKLM\..\Run: [SoundMan] soundman.exe
                    O4 - HKLM\..\Run: [UIUCU] C:\DOCUME~1\Windows\LOCALS~1\Temp\UIUCU.EXE -CLEAN_UP -S
                    O4 - HKLM\..\Run: [explorer] C:\WINDOWS\BackUp\explorer.exe
                    O4 - HKLM\..\Run: [D46C8C] C:\WINDOWS\system32\E1608D\D46C8C.EXE
                    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
                    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                    O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SERVICE LOCAL')
                    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RESEAU')
                    O4 - HKUS\S-1-5-20\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SERVICE RESEAU')
                    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                    O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
                    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                    O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
                    O4 - Startup: D46C8C.lnk = C:\WINDOWS\system32\E1608D\D46C8C.EXE
                    O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
                    O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
                    O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
                    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
                    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
                    O23 - Service: ÎÏãÉ ÊÍÏíË Google (gupdate1ca10407fbca880) (gupdate1ca10407fbca880) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
                    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                    0
                    1. Contributeur sécurité
                      merci de créer ton message!
                      0
                      1. Bonjour,
                        J'ai fait ce que vous avez demandé mais appAremment le virus n'a pas bougé ou bien il revient à chaque fois que je me connecte à internet, s'il vous plait aidez-moi car je ne peux rien faire sur mon pc, en plus il n'y a pas qu'un seul mais plusieurs qui se baladent à l'écran et m'empeche de travailler malgré que j'ai un antivirus.

                        info.txt logfile of random's system information tool 1.06 2009-08-01 02:36:32

                        ======Uninstall list======

                        -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
                        Adobe Acrobat 5.0-->C:\WINDOWS\ISUNINST.EXE -f"C:\Program Files\Fichiers communs\Adobe\Acrobat 5.0\NT\Uninst.isu" -c"C:\Program Files\Fichiers communs\Adobe\Acrobat 5.0\NT\Uninst.dll"
                        Adobe Acrobat eBook Reader-->C:\WINDOWS\IsUninst.exe -f"C:\Program Files\Adobe\Acrobat eBook Reader\Uninst.isu"
                        Adobe Flash Player 10 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
                        Avance AC'97 Audio-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FB08F381-6533-4108-B7DD-039E11FBC27E}\setup.exe" REMOVE
                        BearShare-->"C:\Program Files\BearShare Applications\BearShare\UninstallSurvey.exe" "C:\Program Files\BearShare Applications\BearShare\UnwiseLauncher.exe" /A "C:\Program Files\BearShare Applications\BearShare\INSTALL.LOG"
                        Correctif pour Lecteur Windows Media 11 (KB939683)-->"C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
                        Correctif pour Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
                        EVEREST Home Edition v2.20-->"C:\Program Files\Lavalys\EVEREST Home Edition\unins000.exe"
                        Exlib-->C:\WINDOWS\unvise32.exe C:\Program Files\NVD\Exlib\uninstal.log
                        GOM Player-->"C:\Program Files\GRETECH\GomPlayer\Uninstall.exe"
                        Google Chrome-->"C:\Program Files\Google\Chrome\Application\2.0.172.37\Installer\setup.exe" --uninstall --system-level
                        Google Earth-->MsiExec.exe /X{CC016F21-3970-11DE-B878-005056806466}
                        Google Toolbar for Internet Explorer-->regsvr32 /u /s "c:\program files\google\googletoolbar1.dll"
                        Google Update Helper-->MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
                        HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
                        MediaBar 2.0-->C:\Program Files\BearShare Applications\BearShare MediaBar\Uninstall.exe
                        Mise à jour critique pour Lecteur Windows Media 11 (KB959772)-->"C:\WINDOWS\$NtUninstallKB959772_WM11$\spuninst\spuninst.exe"
                        Mise à jour de sécurité pour Lecteur Windows Media (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
                        Mise à jour de sécurité pour Lecteur Windows Media 11 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
                        Mise à jour de sécurité pour Lecteur Windows Media 11 (KB954154)-->"C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
                        Mise à jour de sécurité pour Windows XP (KB923561)-->"C:\WINDOWS\$NtUninstallKB923561$\spuninst\spuninst.exe"
                        Mise à jour de sécurité pour Windows XP (KB923789)-->C:\WINDOWS\system32\MacroMed\Flash\genuinst.exe C:\WINDOWS\system32\MacroMed\Flash\KB923789.inf
                        Mise à jour de sécurité pour Windows XP (KB938464-v2)-->"C:\WINDOWS\$NtUninstallKB938464-v2$\spuninst\spuninst.exe"
                        Mise à jour de sécurité pour Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
                        Mise à jour de sécurité pour Windows XP (KB944338-v2)-->"C:\WINDOWS\$NtUninstallKB944338-v2$\spuninst\spuninst.exe"
                        Mise à jour de sécurité pour Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
                        Mise à jour de sécurité pour Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
                        Mise à jour de sécurité pour Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
                        Mise à jour de sécurité pour Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
                        Mise à jour de sécurité pour Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
                        Mise à jour de sécurité pour Windows XP (KB952004)-->"C:\WINDOWS\$NtUninstallKB952004$\spuninst\spuninst.exe"
                        Mise à jour de sécurité pour Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
                        Mise à jour de sécurité pour Windows XP (KB954600)-->"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
                        Mise à jour de sécurité pour Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
                        Mise à jour de sécurité pour Windows XP (KB956572)-->"C:\WINDOWS\$NtUninstallKB956572$\spuninst\spuninst.exe"
                        Mise à jour de sécurité pour Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
                        Mise à jour de sécurité pour Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
                        Mise à jour de sécurité pour Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
                        Mise à jour de sécurité pour Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
                        Mise à jour de sécurité pour Windows XP (KB958687)-->"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
                        Mise à jour de sécurité pour Windows XP (KB959426)-->"C:\WINDOWS\$NtUninstallKB959426$\spuninst\spuninst.exe"
                        Mise à jour de sécurité pour Windows XP (KB960225)-->"C:\WINDOWS\$NtUninstallKB960225$\spuninst\spuninst.exe"
                        Mise à jour de sécurité pour Windows XP (KB960803)-->"C:\WINDOWS\$NtUninstallKB960803$\spuninst\spuninst.exe"
                        Mise à jour de sécurité pour Windows XP (KB961371)-->"C:\WINDOWS\$NtUninstallKB961371$\spuninst\spuninst.exe"
                        Mise à jour de sécurité pour Windows XP (KB961501)-->"C:\WINDOWS\$NtUninstallKB961501$\spuninst\spuninst.exe"
                        Mise à jour de sécurité pour Windows XP (KB968537)-->"C:\WINDOWS\$NtUninstallKB968537$\spuninst\spuninst.exe"
                        Mise à jour de sécurité pour Windows XP (KB969897)-->"C:\WINDOWS\$NtUninstallKB969897$\spuninst\spuninst.exe"
                        Mise à jour de sécurité pour Windows XP (KB970238)-->"C:\WINDOWS\$NtUninstallKB970238$\spuninst\spuninst.exe"
                        Mise à jour de sécurité pour Windows XP (KB971633)-->"C:\WINDOWS\$NtUninstallKB971633$\spuninst\spuninst.exe"
                        Mise à jour de sécurité pour Windows XP (KB972260)-->"C:\WINDOWS\$NtUninstallKB972260$\spuninst\spuninst.exe"
                        Mise à jour de sécurité pour Windows XP (KB973346)-->"C:\WINDOWS\$NtUninstallKB973346$\spuninst\spuninst.exe"
                        Mise à jour pour Windows XP (KB898461)-->"C:\WINDOWS\$NtUninstallKB898461$\spuninst\spuninst.exe"
                        Mise à jour pour Windows XP (KB955839)-->"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
                        Mise à jour pour Windows XP (KB967715)-->"C:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe"
                        OneCare Advisor (Windows Live Toolbar)-->MsiExec.exe /X{DF821FC5-C198-452B-A0D4-82433EFEAE9B}
                        Outil de mise à jour Google-->"C:\Program Files\Google\Google Updater\GoogleUpdater.exe" -uninstall
                        Rhapsody Player Engine-->MsiExec.exe /I{8A62A068-3FD6-495A-9F66-26FE94F32EC9}
                        Silan netcard driver-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{377A506F-2228-4FDA-A99B-4E77A30BE400}\Setup.exe"
                        Skype 3.0-->"C:\Program Files\Skype\Phone\unins000.exe"
                        Skype add-on for IE-->rundll32 "C:\Program Files\Skype\Phone\IEPlugin\SkypeIEPlugin.dll",FriendlyUnregisterServer 0
                        Skype Plugin Manager-->MsiExec.exe /I{3D5E5C0A-5B36-4F98-99A7-287F7DBDCE03}
                        Smart Menus (Windows Live Toolbar)-->MsiExec.exe /X{95FC661A-A0C5-4B18-92CE-90347DA79CC9}
                        Sudden Strike-->C:\WINDOWS\SudUS\UNWISE.EXE C:\WINDOWS\SudUS\INSTALL.LOG
                        Windows Installer 3.1 (KB893803)-->"C:\WINDOWS\$MSI31Uninstall_KB893803v2$\spuninst\spuninst.exe"
                        Windows Live Favorites for Windows Live Toolbar-->MsiExec.exe /X{DCE65B11-710D-4C54-9DE5-1A6A0BD2186B}
                        Windows Live Messenger-->MsiExec.exe /I{571700F0-DB9D-4B3A-B03D-35A14BB5939F}
                        Windows Live Outlook Toolbar (Windows Live Toolbar)-->MsiExec.exe /X{A40D6757-B145-4FE7-B694-89180A9F3F64}
                        Windows Live Sign-in Assistant-->MsiExec.exe /I{49672EC2-171B-47B4-8CE7-50D7806360D7}
                        Windows Live Toolbar Extension (Windows Live Toolbar)-->MsiExec.exe /X{3727B920-F5A3-46A4-AC02-94F421A039C7}
                        Windows Live Toolbar Feed Detector (Windows Live Toolbar)-->MsiExec.exe /X{38024121-D084-4E7D-B1A2-1A04CB5C4CF3}
                        Windows Live Toolbar-->"C:\Program Files\Windows Live Toolbar\UnInstall.exe" {DA0FFF7B-DA9D-46A2-A329-87804ECA58EA}
                        Windows Live Toolbar-->MsiExec.exe /X{DA0FFF7B-DA9D-46A2-A329-87804ECA58EA}

                        Securitycenter WMI appears to be broken

                        ======System event log======

                        Computer Name: MICROPYR-B2B4F5
                        Event Code: 51
                        Message: Une erreur a été détectée sur le périphérique \Device\Harddisk1\D au cours d'une opération de pagination.

                        Record Number: 153
                        Source Name: Disk
                        Time Written: 20090708201008.000000+060
                        Event Type: warning
                        User:

                        Computer Name: MICROPYR-B2B4F5
                        Event Code: 51
                        Message: Une erreur a été détectée sur le périphérique \Device\Harddisk1\D au cours d'une opération de pagination.

                        Record Number: 152
                        Source Name: Disk
                        Time Written: 20090708201008.000000+060
                        Event Type: warning
                        User:

                        Computer Name: MICROPYR-B2B4F5
                        Event Code: 51
                        Message: Une erreur a été détectée sur le périphérique \Device\Harddisk1\D au cours d'une opération de pagination.

                        Record Number: 151
                        Source Name: Disk
                        Time Written: 20090708200953.000000+060
                        Event Type: warning
                        User:

                        Computer Name: MICROPYR-B2B4F5
                        Event Code: 51
                        Message: Une erreur a été détectée sur le périphérique \Device\Harddisk1\D au cours d'une opération de pagination.

                        Record Number: 150
                        Source Name: Disk
                        Time Written: 20090708200953.000000+060
                        Event Type: warning
                        User:

                        Computer Name: MICROPYR-B2B4F5
                        Event Code: 51
                        Message: Une erreur a été détectée sur le périphérique \Device\Harddisk1\D au cours d'une opération de pagination.

                        Record Number: 149
                        Source Name: Disk
                        Time Written: 20090708200951.000000+060
                        Event Type: warning
                        User:

                        =====Application event log=====

                        Computer Name: MICROPYR-B2B4F5
                        Event Code: 5603
                        Message: Un fournisseur, Rsop Planning Mode Provider, était inscrit dans l'espace de noms WMI, root\RSOP, mais n'a pas spécifié la propriété HostingModel. Ce fournisseur sera exécuté avec le compte LocalSystem. Ce compte bénéficie de privilèges et le fournisseur peut provoquer une violation de sécurité s'il ne représente pas correctement les demandes utilisateur. Vérifiez que le comportement sécuritaire du fournisseur a été contrôlé, et mettez à jour la propriété HostingModel de l'inscription du fournisseur vers un compte disposant du moins d'autorisations possible pour la fonctionnalité requise.

                        Record Number: 18
                        Source Name: WinMgmt
                        Time Written: 20090707203456.000000+060
                        Event Type: warning
                        User: AUTORITE NT\SYSTEM

                        Computer Name: MICROPYR-B2B4F5
                        Event Code: 5603
                        Message: Un fournisseur, Rsop Planning Mode Provider, était inscrit dans l'espace de noms WMI, root\RSOP, mais n'a pas spécifié la propriété HostingModel. Ce fournisseur sera exécuté avec le compte LocalSystem. Ce compte bénéficie de privilèges et le fournisseur peut provoquer une violation de sécurité s'il ne représente pas correctement les demandes utilisateur. Vérifiez que le comportement sécuritaire du fournisseur a été contrôlé, et mettez à jour la propriété HostingModel de l'inscription du fournisseur vers un compte disposant du moins d'autorisations possible pour la fonctionnalité requise.

                        Record Number: 17
                        Source Name: WinMgmt
                        Time Written: 20090707203456.000000+060
                        Event Type: warning
                        User: AUTORITE NT\SYSTEM

                        Computer Name: MICROPYR-B2B4F5
                        Event Code: 63
                        Message: Un fournisseur, CmdTriggerConsumer, a été enregistré dans l'espace de noms WMI, Root\cimv2, afin d'utiliser le compte LocalSystem. Ce compte bénéficie de privilèges et le fournisseur peut provoquer une violation de sécurité s'il ne représente pas correctement les demandes utilisateur.

                        Record Number: 13
                        Source Name: WinMgmt
                        Time Written: 20090707202955.000000+060
                        Event Type: warning
                        User: AUTORITE NT\SYSTEM

                        Computer Name: MICROPYR-B2B4F5
                        Event Code: 63
                        Message: Un fournisseur, CmdTriggerConsumer, a été enregistré dans l'espace de noms WMI, Root\cimv2, afin d'utiliser le compte LocalSystem. Ce compte bénéficie de privilèges et le fournisseur peut provoquer une violation de sécurité s'il ne représente pas correctement les demandes utilisateur.

                        Record Number: 12
                        Source Name: WinMgmt
                        Time Written: 20090707202955.000000+060
                        Event Type: warning
                        User: AUTORITE NT\SYSTEM

                        Computer Name: MICROPYR-B2B4F5
                        Event Code: 63
                        Message: Un fournisseur, HiPerfCooker_v1, a été enregistré dans l'espace de noms WMI, Root\WMI, afin d'utiliser le compte LocalSystem. Ce compte bénéficie de privilèges et le fournisseur peut provoquer une violation de sécurité s'il ne représente pas correctement les demandes utilisateur.

                        Record Number: 11
                        Source Name: WinMgmt
                        Time Written: 20090707202952.000000+060
                        Event Type: warning
                        User: AUTORITE NT\SYSTEM

                        ======Environment variables======

                        "ComSpec"=%SystemRoot%\system32\cmd.exe
                        "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem
                        "windir"=%SystemRoot%
                        "FP_NO_HOST_CHECK"=NO
                        "OS"=Windows_NT
                        "PROCESSOR_ARCHITECTURE"=x86
                        "PROCESSOR_LEVEL"=15
                        "PROCESSOR_IDENTIFIER"=x86 Family 15 Model 2 Stepping 9, GenuineIntel
                        "PROCESSOR_REVISION"=0209
                        "NUMBER_OF_PROCESSORS"=1
                        "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
                        "TEMP"=%SystemRoot%\TEMP
                        "TMP"=%SystemRoot%\TEMP
                        "DEVMGR_SHOW_DETAILS"=1

                        -----------------EOF-----------------

                        Logfile of random's system information tool 1.06 (written by random/random)
                        Run by Windows at 2009-08-01 02:35:48
                        Microsoft Windows XP Professionnel Service Pack 2
                        System drive C: has 14 GB (74%) free of 18 GB
                        Total RAM: 95 MB (9% free)

                        Logfile of Trend Micro HijackThis v2.0.2
                        Scan saved at 2:36:24, on 01-08-2009
                        Platform: Windows XP SP2 (WinNT 5.01.2600)
                        MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                        Boot mode: Normal

                        Running processes:
                        C:\WINDOWS\System32\smss.exe
                        C:\WINDOWS\system32\winlogon.exe
                        C:\WINDOWS\system32\services.exe
                        C:\WINDOWS\system32\lsass.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\WINDOWS\Explorer.EXE
                        C:\WINDOWS\system32\spoolsv.exe
                        C:\WINDOWS\soundman.exe
                        C:\WINDOWS\BackUp\explorer.exe
                        C:\WINDOWS\system32\E1608D\D46C8C.EXE
                        C:\WINDOWS\system32\ctfmon.exe
                        C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                        C:\Program Files\MSN Messenger\MsnMsgr.Exe
                        C:\WINDOWS\system32\wuauclt.exe
                        C:\Program Files\Lavalys\EVEREST Home Edition\everest.exe
                        C:\Program Files\Lavalys\EVEREST Home Edition\everest.exe
                        C:\Program Files\Internet Explorer\iexplore.exe
                        C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
                        C:\Program Files\MSN Messenger\msnmsgr.exe
                        C:\Documents and Settings\Windows\Local Settings\Temporary Internet Files\Content.IE5\6XYRYZ6N\RSIT[1].exe
                        C:\Program Files\trend micro\Windows.exe

                        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                        O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
                        O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
                        O2 - BHO: UrlHelper Class - {74322BF9-DF26-493f-B0DA-6D2FC5E6429E} - C:\Program Files\BearShare Applications\BearShare\BearShareIEHelper.dll
                        O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                        O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                        O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
                        O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                        O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                        O3 - Toolbar: BearShare MediaBar - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - C:\Program Files\BearShare Applications\BearShare MediaBar\BearShareMediaBar.dll
                        O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                        O4 - HKLM\..\Run: [SoundMan] soundman.exe
                        O4 - HKLM\..\Run: [UIUCU] C:\DOCUME~1\Windows\LOCALS~1\Temp\UIUCU.EXE -CLEAN_UP -S
                        O4 - HKLM\..\Run: [explorer] C:\WINDOWS\BackUp\explorer.exe
                        O4 - HKLM\..\Run: [D46C8C] C:\WINDOWS\system32\E1608D\D46C8C.EXE
                        O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                        O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                        O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
                        O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                        O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SERVICE LOCAL')
                        O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RESEAU')
                        O4 - HKUS\S-1-5-20\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SERVICE RESEAU')
                        O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                        O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
                        O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                        O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
                        O4 - Startup: D46C8C.lnk = C:\WINDOWS\system32\E1608D\D46C8C.EXE
                        O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
                        O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
                        O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
                        O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
                        O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
                        O23 - Service: ÎÏãÉ ÊÍÏíË Google (gupdate1ca10407fbca880) (gupdate1ca10407fbca880) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
                        O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                        0
                    2. Logfile of random's system information tool 1.06 (written by random/random)
                      Run by Lyes at 2009-11-01 01:49:37
                      Microsoft® Windows Vista™ Edition Intégrale Service Pack 1
                      System drive C: has 12 GB (40%) free of 30 GB
                      Total RAM: 1013 MB (13% free)

                      Logfile of Trend Micro HijackThis v2.0.2
                      Scan saved at 1:49:50 AM, on 11/1/2009
                      Platform: Windows Vista SP1 (WinNT 6.00.1905)
                      MSIE: Internet Explorer v7.00 (7.00.6001.18000)
                      Boot mode: Normal

                      Running processes:
                      C:\Windows\system32\taskeng.exe
                      C:\Windows\system32\Dwm.exe
                      C:\Windows\Explorer.EXE
                      C:\Program Files\Windows Defender\MSASCui.exe
                      C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe
                      C:\Windows\System32\igfxtray.exe
                      C:\Windows\System32\hkcmd.exe
                      C:\Windows\System32\igfxpers.exe
                      C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
                      C:\Windows\System32\ZCfgSvc.exe
                      C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                      C:\Windows\BackUp\explorer.exe
                      C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
                      C:\Program Files\Windows Sidebar\sidebar.exe
                      C:\Program Files\Internet Download Manager\IDMan.exe
                      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                      C:\Windows\ehome\ehtray.exe
                      C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
                      C:\Program Files\Camera Assistant Software for Toshiba\CEC_MAIN.exe
                      C:\Windows\System32\spool\drivers\w32x86\3\CAP3LAK.EXE
                      C:\Windows\system32\igfxsrvc.exe
                      C:\Windows\ehome\ehmsas.exe
                      C:\Windows\system32\wbem\unsecapp.exe
                      C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
                      C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
                      C:\Program Files\mobiConnect\mobiConnect.exe
                      C:\Program Files\Windows Media Player\wmpnscfg.exe
                      C:\Program Files\Mozilla Firefox\firefox.exe
                      C:\Windows\system32\conime.exe
                      C:\Program Files\Internet Explorer\iexplore.exe
                      C:\Users\Lyes\Documents\Downloads\Programs\RSIT.exe
                      C:\Program Files\trend micro\Lyes.exe
                      C:\Windows\system32\SearchFilterHost.exe

                      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                      R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
                      O1 - Hosts: ::1 localhost
                      O2 - BHO: IDMIEHlprObj Class - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
                      O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
                      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                      O2 - BHO: Ask Toolbar BHO - {FE063DB1-4EC0-403e-8DD8-394C54984B2C} - C:\Program Files\AskTBar\bar\3.bin\ASKTBAR.DLL
                      O3 - Toolbar: Ask Toolbar - {FE063DB9-4EC0-403e-8DD8-394C54984B2C} - C:\Program Files\AskTBar\bar\3.bin\ASKTBAR.DLL
                      O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                      O4 - HKLM\..\Run: [Camera Assistant Software] "C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe" /start
                      O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
                      O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
                      O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
                      O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
                      O4 - HKLM\..\Run: [ZCfgSvc.exe] C:\Windows\system32\ZCfgSvc.exe
                      O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
                      O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
                      O4 - HKLM\..\Run: [CAP3ON] C:\Windows\system32\spool\drivers\w32x86\3\CAP3ONN.EXE
                      O4 - HKLM\..\Run: [explorer] C:\Windows\BackUp\explorer.exe
                      O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
                      O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
                      O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                      O4 - HKCU\..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot
                      O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                      O4 - HKCU\..\Run: [fztmmsxoc] rundll32.exe "C:\Users\Lyes\AppData\Roaming\rsxdjc.dll",xtnxle
                      O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                      O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
                      O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                      O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                      O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RESEAU')
                      O4 - Global Startup: Canon LASER SHOT LBP-1120 Status Window.LNK = C:\Windows\System32\spool\drivers\w32x86\3\CAP3LAK.EXE
                      O8 - Extra context menu item: Download all links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm
                      O8 - Extra context menu item: Download FLV video content with IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm
                      O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm
                      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
                      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
                      O13 - Gopher Prefix:
                      O17 - HKLM\System\CCS\Services\Tcpip\..\{4DC363CD-95D9-4B18-B6AB-94EA19915821}: NameServer = 193.251.169.83 193.251.169.166
                      O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
                      O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
                      O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
                      O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                      O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
                      O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
                      O23 - Service: NBService - Nero AG - D:\document wab\Nero 7\Nero BackItUp\NBService.exe
                      O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
                      O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
                      0
                      1. Contributeur sécurité
                        Meme demarche que pour XP , si vous demandez de faire désactiver L'UAC avant utilisation de UsbFix.

                        Voici un tuto : http://pagesperso-orange.fr/FindyKill.Ad.Remover/uac_vista.html

                        Ceci dis UsbFix peut fonctionner avec l'Uac actif...... :

                        • Telecharge et install UsbFix par Chiquitine29

                        (!) Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) suceptible d avoir été infectés sans les ouvrir

                        • Fais un clic droit sur le raccourci UsbFix présent sur ton bureau et choisis "éxécuter en tant qu'administrateur" .

                        • Au menu principal choisis l'option " F " pour français et tape sur [entrée] .

                        • Au second menu Choisis l'option " 1 " (recherche) et tape sur [entrée]

                        • Laisse travailler l outil.

                        • Ensuite post le rapport UsbFix.txt qui apparaitra.

                        • Note : Le rapport UsbFix.txt est sauvegardé à la racine du disque. ( C:\UsbFix.txt )

                        ( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

                        • Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
                        Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
                        Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.

                        • Tuto : http://pagesperso-orange.fr/NosTools/usbfix.html
                        0