Problème pc au démarage(rapport hijackthis)

Résolu
Bonjour,
Depuis quelque temps j'ai des soucis pour démarrer mon pc lorsque j'essaye d'ouvrir une application tout se bloque et impossible de rien faire je suis obligée de débrancher le pc et de le redémarrer.Je joint a mon post un rapport hijackthis.
Merci d'avance a qui voudra bien m'aider.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:11:38, on 01/06/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\WINDOWS\arservice.exe
C:\WINDOWS\system32\ezNTSvc.exe
C:\Program Files\Windows Live\Family Safety\fsssvc.exe
C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\ARPWRMSG.EXE
C:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Windows Live\Family Safety\fsui.exe
C:\Program Files\Canon\MyPrinter\BJMyPrt.exe
C:\WINDOWS\ZSSnp211.exe
C:\WINDOWS\Domino.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
c:\windows\system\hpsysdrv.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://fr.search.yahoo.com/?fr=cb-hp06
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = https://fr.search.yahoo.com/?fr=cb-hp06
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Windows Live Family Safety Browser Helper - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [AlwaysReady Power Message APP] ARPWRMSG.EXE
O4 - HKLM\..\Run: [DMAScheduler] "c:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe"
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [fssui] "C:\Program Files\Windows Live\Family Safety\fsui.exe" -autorun
O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
O4 - HKLM\..\Run: [ZSSnp211] C:\WINDOWS\ZSSnp211.exe
O4 - HKLM\..\Run: [Domino] C:\WINDOWS\Domino.exe
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - .DEFAULT User Startup: PinMcLnk.lnk = C:\hp\bin\cloaker.exe (User 'Default user')
O4 - Global Startup: Contrôleur de calendrier Ulead.lnk = C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: STK017 PNP Monitor.lnk = C:\Program Files\STK017_V2.01\STK017D.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://jeuxenligne.orange.fr/Gameshell/GameHost/1.0/OberonGameHost.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {FC4CAF5F-91BD-4DD9-ADC1-F3C737E37BC4} (CPlayFirstSweetopiaControl Object) - file:///C:/Documents%20and%20Settings/HP_Administrateur.KYKY.000/Local%20Settings/Application%20Data/Oberon%20Media/Oberon%20Games%20Host/Sweetopia.1.0.0.46.cab
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: EasyBits Magic Desktop Services for Windows NT (ezntsvc) - EasyBits Software Corp. - C:\WINDOWS\system32\ezNTSvc.exe
O23 - Service: getPlus(R) Helper - Unknown owner - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe (file missing)
O23 - Service: Service Google Update (gupdate1c9e1855191ec6c) (gupdate1c9e1855191ec6c) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Inkjet Printer/Scanner Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
O23 - Service: LVSrvLauncher - Unknown owner - C:\Program Files\Fichiers communs\LogiShrd\SrvLnch\SrvLnch.exe (file missing)
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

--
End of file - 12515 bytes

.
Configuration: Windows XP
Firefox 3.0.10

28 réponses

Résumé de la discussion

Plusieurs symptômes indiquent un blocage lors du démarrage quand l'utilisateur lance une application, obligeant à débrancher l'ordinateur et à redémarrer, sur un PC fonctionnant sous Windows XP SP3. Le message inclut un log HijackThis et les réponses recommandent de compléter par un RSIT pour identifier des éléments malveillants et des conflits logiciels, afin d'expliquer les blocages. Réponses fournissent un outil de diagnostic RSIT et présentent une liste de uninstall de logiciels, notamment Avira, Google Update, RealPlayer et des composants de sécurité, suggérant des conflits potentiels. Des éléments suggèrent que des outils de sécurité et des composants système peuvent provoquer des conflits, nécessitant une analyse des logs RSIT et HijackThis pour hiérarchiser les actions sans conclure sur l'état du fil.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    bonjour , pour moi rien de visible sur ce rapport qui puisse expliquer cela mis si tu nous mets un RSIT qui lui nous en motre plus possible que l'on trouve quelque chose , Merci

    Télécharge ici : http://images.malwareremoval.com/random/RSIT.exe

    random's system information tool (RSIT) par random/random et sauvegarde-le sur le Bureau.

    Double-clique sur RSIT.exe afin de lancer RSIT.

    Lis le contenu de l'écran Disclaimer puis clique sur Continue (si tu acceptes les conditions).

    Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.

    Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront.

    Poste le contenu de log.txt (<<qui sera affiché)
    ainsi que de info.txt (<<qui sera réduit dans la Barre des Tâches).

    NB : Les rapports sont sauvegardés dans le dossier C:\rsit

    tuto: https://forum.pcastuces.com/randoms_system_information_tool_rsit-f31s31.htm
    0
    1. Re voila les rapports
      1er:

      Logfile of random's system information tool 1.06 (written by random/random)
      Run by HP_Administrateur at 2009-06-01 21:36:08
      Microsoft Windows XP Professionnel Service Pack 3
      System drive C: has 180 GB (78%) free of 232 GB
      Total RAM: 447 MB (39% free)

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 21:36:15, on 01/06/2009
      Platform: Windows XP SP3 (WinNT 5.01.2600)
      MSIE: Internet Explorer v8.00 (8.00.6001.18702)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\csrss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\Ati2evxx.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\Ati2evxx.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\system32\ZoneLabs\vsmon.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Avira\AntiVir Desktop\sched.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Google\Update\GoogleUpdate.exe
      C:\Program Files\Avira\AntiVir Desktop\avguard.exe
      C:\WINDOWS\arservice.exe
      C:\WINDOWS\system32\ezNTSvc.exe
      C:\Program Files\Windows Live\Family Safety\fsssvc.exe
      C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
      C:\Program Files\Java\jre6\bin\jqs.exe
      C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
      C:\Program Files\Spyware Doctor\pctsAuxs.exe
      C:\Program Files\Spyware Doctor\pctsSvc.exe
      C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
      C:\Program Files\Spyware Doctor\pctsTray.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\ehome\mcrdsvc.exe
      C:\WINDOWS\system32\wbem\wmiapsrv.exe
      C:\WINDOWS\System32\alg.exe
      C:\WINDOWS\ehome\ehtray.exe
      C:\WINDOWS\ARPWRMSG.EXE
      C:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Windows Live\Family Safety\fsui.exe
      C:\Program Files\Canon\MyPrinter\BJMyPrt.exe
      C:\WINDOWS\ZSSnp211.exe
      C:\WINDOWS\Domino.exe
      C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
      C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
      C:\Program Files\Java\jre6\bin\jusched.exe
      C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
      C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
      C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
      C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
      C:\HP\KBD\KBD.EXE
      C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
      c:\windows\system\hpsysdrv.exe
      C:\Program Files\Windows Live\Contacts\wlcomm.exe
      C:\Program Files\Mozilla Firefox\firefox.exe
      C:\WINDOWS\system32\wuauclt.exe
      C:\Documents and Settings\HP_Administrateur.KYKY.000\Bureau\RSIT.exe
      C:\WINDOWS\system32\wbem\wmiprvse.exe
      C:\Program Files\Trend Micro\HijackThis\HP_Administrateur.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://fr.search.yahoo.com/?fr=cb-hp06
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = https://fr.search.yahoo.com/?fr=cb-hp06
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
      O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
      O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
      O2 - BHO: Windows Live Family Safety Browser Helper - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll
      O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
      O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
      O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
      O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
      O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
      O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
      O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
      O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
      O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
      O4 - HKLM\..\Run: [AlwaysReady Power Message APP] ARPWRMSG.EXE
      O4 - HKLM\..\Run: [DMAScheduler] "c:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe"
      O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
      O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
      O4 - HKLM\..\Run: [fssui] "C:\Program Files\Windows Live\Family Safety\fsui.exe" -autorun
      O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
      O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
      O4 - HKLM\..\Run: [ZSSnp211] C:\WINDOWS\ZSSnp211.exe
      O4 - HKLM\..\Run: [Domino] C:\WINDOWS\Domino.exe
      O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
      O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
      O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
      O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
      O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
      O4 - .DEFAULT User Startup: PinMcLnk.lnk = C:\hp\bin\cloaker.exe (User 'Default user')
      O4 - Global Startup: Contrôleur de calendrier Ulead.lnk = C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
      O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
      O4 - Global Startup: STK017 PNP Monitor.lnk = C:\Program Files\STK017_V2.01\STK017D.exe
      O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
      O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
      O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
      O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
      O9 - Extra button: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
      O9 - Extra 'Tools' menuitem: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
      O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
      O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
      O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://jeuxenligne.orange.fr/Gameshell/GameHost/1.0/OberonGameHost.cab
      O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
      O16 - DPF: {FC4CAF5F-91BD-4DD9-ADC1-F3C737E37BC4} (CPlayFirstSweetopiaControl Object) - file:///C:/Documents%20and%20Settings/HP_Administrateur.KYKY.000/Local%20Settings/Application%20Data/Oberon%20Media/Oberon%20Games%20Host/Sweetopia.1.0.0.46.cab
      O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
      O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
      O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
      O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
      O23 - Service: EasyBits Magic Desktop Services for Windows NT (ezntsvc) - EasyBits Software Corp. - C:\WINDOWS\system32\ezNTSvc.exe
      O23 - Service: getPlus(R) Helper - Unknown owner - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe (file missing)
      O23 - Service: Service Google Update (gupdate1c9e1855191ec6c) (gupdate1c9e1855191ec6c) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
      O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
      O23 - Service: Inkjet Printer/Scanner Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
      O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
      O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
      O23 - Service: LVSrvLauncher - Unknown owner - C:\Program Files\Fichiers communs\LogiShrd\SrvLnch\SrvLnch.exe (file missing)
      O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
      O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
      O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
      O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
      0
      1. 2eme:

        info.txt logfile of random's system information tool 1.06 2009-06-01 21:36:31

        ======Uninstall list======

        -->C:\Program Files\Fichiers communs\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
        -->C:\WINDOWS\IsUn040c.exe -fC:\WINDOWS\orun32.isu
        -->c:\WINDOWS\system32\\MSIEXEC.EXE /x {075473F5-846A-448B-BCB3-104AA1760205}
        -->c:\WINDOWS\system32\\MSIEXEC.EXE /x {AB708C9B-97C8-4AC9-899B-DBF226AC9382}
        -->c:\WINDOWS\system32\\MSIEXEC.EXE /x {B12665F4-4E93-4AB4-B7FC-37053B524629}
        -->c:\WINDOWS\system32\\MSIEXEC.EXE /x {F80239D8-7811-4D5E-B033-0D0BBFE32920}
        -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
        Adobe Acrobat 5.0-->C:\WINDOWS\ISUN040C.EXE -f"C:\Program Files\Fichiers communs\Adobe\Acrobat 5.0\NT\Uninst.isu" -c"C:\Program Files\Fichiers communs\Adobe\Acrobat 5.0\NT\Uninst.dll"
        Adobe Acrobat and Reader 8.1.2 Security Update 1 (KB403742)-->MsiExec.exe /X{6846389C-BAC0-4374-808E-B120F86AF5D7}
        Adobe Flash Player 10 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
        Adobe Flash Player 10 Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
        Adobe Reader 9.1 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A91000000001}
        Amélioration de nos services-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\1050\INTEL3~1\IDriver.exe /M{23012310-3E05-46A5-88A9-C6CBCABCAC79} /l1036
        Assistant de connexion Windows Live-->MsiExec.exe /I{DCE8CD14-FBF5-4464-B9A4-E18E473546C7}
        ATI Display Driver-->rundll32 C:\WINDOWS\system32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
        Avira AntiVir Personal - Free Antivirus-->C:\Program Files\Avira\AntiVir Desktop\setup.exe /REMOVE
        Budget pour les nuls-->C:\WINDOWS\IsUn040c.exe -f"C:\Program Files\Anuman Interactive\Budget pour les nuls\Uninst.isu"
        Canon MP Navigator EX 1.2-->"C:\Program Files\Canon\MP Navigator EX 1.2\Maint.exe" /UninstallRemove C:\Program Files\Canon\MP Navigator EX 1.2\uninst.ini
        Canon MP190 series MP Drivers-->"C:\WINDOWS\system32\CanonIJ Uninstaller Information\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP190_series\DelDrv.exe" /U:{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP190_series /L0x000c
        Canon My Printer-->C:\Program Files\Canon\MyPrinter\uninst.exe uninst.ini
        Canon Utilities Easy-PhotoPrint EX-->C:\Program Files\Canon\Easy-PhotoPrint EX\uninst.exe uninst.ini
        Canon Utilities Solution Menu-->C:\Program Files\Canon\SolutionMenu\uninst.exe uninst.ini
        CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
        Choice Guard-->MsiExec.exe /I{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}
        Connexion Facile à Internet-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\1050\INTEL3~1\IDriver.exe /M{8105684D-8CA6-440D-8F58-7E5FD67A499D} /l1036
        Correctif pour Lecteur Windows Media 10 (KB910393)-->"C:\WINDOWS\$NtUninstallKB910393$\spuninst\spuninst.exe"
        Correctif pour Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
        DivX-->C:\Program Files\DivX\DivXCodecUninstall.exe /CODEC
        EasyBits Magic Desktop-->C:\WINDOWS\system32\ezMDUninstall.exe
        Enhanced Multimedia Keyboard Solution-->C:\HP\KBD\Install.exe /u
        Enregistrement utilisateur de Canon MP190 series-->C:\Program Files\Canon\IJEREG\MP190 series\UNINST.EXE
        Extension de Windows Live Toolbar (Windows Live Toolbar)-->MsiExec.exe /X{0CA6047C-D28B-4295-834A-07C52BA20C2D}
        Galerie de photos Windows Live-->MsiExec.exe /X{44E54A81-9D91-4AA1-9417-80AFF134F5FF}
        Games-Attack-->C:\Program Files\Games-Attack\Uninstall.exe
        GemMaster Mystic-->"C:\Program Files\GemMasterFrench\uninstallgemmaster.exe"
        Google Chrome-->"C:\Program Files\Google\Chrome\Application\1.0.154.65\Installer\setup.exe" --uninstall --system-level
        Google Earth-->MsiExec.exe /I{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}
        Google Toolbar for Internet Explorer-->"C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_BDA1448D3D255554.exe" /uninstall
        Google Toolbar for Internet Explorer-->MsiExec.exe /I{18455581-E099-4BA8-BC6B-F34B2F06600C}
        Google Update Helper-->MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
        High Definition Audio - KB888111-->"C:\WINDOWS\$NtUninstallKB888111WXPSP2$\spuninst\spuninst.exe"
        HijackThis 2.0.2-->"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
        HP Boot Optimizer-->MsiExec.exe /X{1341D838-719C-4A05-B50F-49420CA1B4BB}
        HP Customer Participation Program 7.0-->C:\Program Files\HP\Digital Imaging\ExtCapUninstall\hpzscr01.exe -datfile hpqhsc01.dat
        HP DigitalMedia Archive-->MsiExec.exe /X{F80239D8-7811-4D5E-B033-0D0BBFE32920}
        HP DVD Play 2.1-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{45D707E9-F3C4-11D9-A373-0050BAE317E1}\Setup.exe" -uninstall
        HP Imaging Device Functions 7.0-->C:\Program Files\HP\Digital Imaging\DeviceManagement\hpzscr01.exe -datfile hpqbud01.dat
        HP Photosmart Essential-->MsiExec.exe /X{6994491D-D491-48F1-AE1F-E179C1FFFC2F}
        HP Photosmart for Media Center PC-->c:\Program Files\HP\Digital Imaging\bin\mcpc\setupmcl.exe /u
        HP Photosmart Premier Software 6.5-->C:\Program Files\HP\Digital Imaging\uninstall\hpzscr01.exe -datfile hpqscr01.dat
        HP Photosmart, Officejet and Deskjet 7.0.A-->C:\Program Files\HP\Digital Imaging\{BDBE2F3E-42DB-4d4a-8CB1-19BA765DBC6C}\setup\hpzscr01.exe -datfile hposcr11.dat
        HP Solution Center 7.0-->C:\Program Files\HP\Digital Imaging\eSupport\hpzscr01.exe -datfile hpqbud05.dat
        HP Update-->MsiExec.exe /X{FE57DE70-95DE-4B64-9266-84DA811053DB}
        Inkjet Printer/Scanner Extended Survey Program-->C:\Program Files\Canon\IJPLM\SETUP.EXE -R
        Installation Windows Live-->C:\Program Files\Windows Live\Installer\wlarp.exe
        Installation Windows Live-->MsiExec.exe /I{7370DF47-B4F9-4279-BFC3-3F09919F720D}
        J2SE Runtime Environment 5.0 Update 6-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150060}
        Java(TM) 6 Update 13-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216011FF}
        Java(TM) 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
        Jewel Match Deluxe-->"C:\Program Files\Zylom Games\Jewel Match Deluxe\GameInstlr.exe" --uninstall UnInstall.log
        Junk Mail filter update-->MsiExec.exe /I{4DE3E3D9-AE81-45DE-9195-3015F7B1DBF3}
        Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
        Menus intelligents (Windows Live Toolbar)-->MsiExec.exe /X{0CC70FEF-5068-4CD5-B4DE-86FFD98EC929}
        Microsoft .NET Framework 1.1 French Language Pack-->MsiExec.exe /X{9A394342-4A68-4EBA-85A6-55B559F4E700}
        Microsoft .NET Framework 1.1 Hotfix (KB928366)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"
        Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
        Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
        Microsoft .NET Framework 2.0-->C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.exe
        Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
        Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
        Microsoft Search Enhancement Pack-->MsiExec.exe /X{4CBA3D4C-8F51-4D60-B27E-F6B641C571E7}
        Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
        Microsoft SQL Server 2005 Compact Edition [ENU]-->MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
        Microsoft Sync Framework Runtime Native v1.0 (x86)-->MsiExec.exe /I{8A74E887-8F0F-4017-AF53-CBA42211AAA5}
        Microsoft Sync Framework Services Native v1.0 (x86)-->MsiExec.exe /I{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}
        Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17-->MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475}
        Microsoft Works-->MsiExec.exe /I{A059DE09-1B49-4450-B340-7AE097EC3F04}
        Mise à jour de sécurité pour Lecteur Windows Media (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Lecteur Windows Media 10 (KB911565)-->"C:\WINDOWS\$NtUninstallKB911565$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Lecteur Windows Media 10 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP10$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Step by Step Interactive Training (KB923723)-->"C:\WINDOWS\$NtUninstallKB923723$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB938127-v2)-->"C:\WINDOWS\ie7updates\KB938127-v2-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB956390)-->"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB958215)-->"C:\WINDOWS\ie7updates\KB958215-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB960714)-->"C:\WINDOWS\ie7updates\KB960714-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB961260)-->"C:\WINDOWS\ie7updates\KB961260-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB923561)-->"C:\WINDOWS\$NtUninstallKB923561$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB923689)-->"C:\WINDOWS\$NtUninstallKB923689$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB938464-v2)-->"C:\WINDOWS\$NtUninstallKB938464-v2$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB952004)-->"C:\WINDOWS\$NtUninstallKB952004$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB954211)-->"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB954459)-->"C:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB954600)-->"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB956391)-->"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB956572)-->"C:\WINDOWS\$NtUninstallKB956572$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB956841)-->"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB957095)-->"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB958687)-->"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB958690)-->"C:\WINDOWS\$NtUninstallKB958690$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB959426)-->"C:\WINDOWS\$NtUninstallKB959426$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB960225)-->"C:\WINDOWS\$NtUninstallKB960225$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB960715)-->"C:\WINDOWS\$NtUninstallKB960715$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB960803)-->"C:\WINDOWS\$NtUninstallKB960803$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB961373)-->"C:\WINDOWS\$NtUninstallKB961373$\spuninst\spuninst.exe"
        Mise à jour pour Windows Internet Explorer 8 (KB968220)-->"C:\WINDOWS\ie8updates\KB968220-IE8\spuninst\spuninst.exe"
        Mise à jour pour Windows XP (KB898461)-->"C:\WINDOWS\$NtUninstallKB898461$\spuninst\spuninst.exe"
        Mise à jour pour Windows XP (KB951072-v2)-->"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
        Mise à jour pour Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
        Mise à jour pour Windows XP (KB955839)-->"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
        Mise à jour pour Windows XP (KB961503)-->"C:\WINDOWS\$NtUninstallKB961503$\spuninst\spuninst.exe"
        Mise à jour pour Windows XP (KB967715)-->"C:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe"
        Mozilla Firefox (3.0.10)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
        MP Manager-->MsiExec.exe /X{7DE4B31F-651E-4773-8DD4-399E7E58477E}
        MSN-->C:\Program Files\MSN\MsnInstaller\msninst.exe /Action:ARP
        MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
        MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
        MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
        muvee autoProducer 5.0-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FB4740B3-2530-452D-A825-F7AB246CA7DF}\setup.exe" -l0x40c
        muvee autoProducer unPlugged 2.0-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5FDD0538-C67A-4F67-B3F8-09D1AAF04D99}\setup.exe" -l0x40c
        MVision-->MsiExec.exe /I{35725FBC-A136-4A46-9F29-091759D9BB93}
        OpenOffice.org Installer 1.0-->MsiExec.exe /X{3A2AF807-9F9F-43C9-A24A-17B617238B74}
        Otto-->"C:\Program Files\FrenchOtto\uninstallotto.exe"
        Outil de mise à jour Google-->"C:\Program Files\Google\Google Updater\GoogleUpdater.exe" -uninstall
        Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
        Panneau de contrôle ATI-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{0BEDBD4E-2D34-47B5-9973-57E62B29307C}\setup.exe"
        PhotoFiltre-->"C:\Documents and Settings\HP_Administrateur.KYKY.000\Bureau\PhotoFiltre\Uninst.exe"
        Picasa 3-->"C:\Program Files\Google\Picasa3\Uninstall.exe"
        Pro Evolution Soccer 2008-->C:\Program Files\InstallShield Installation Information\{2FDFD600-7338-4738-90D5-FC4ACA08DC36}\setup.exe -runfromtemp -l0x040c
        Programme de gestion Camera de Logitech®-->"C:\Program Files\Fichiers communs\LogiShrd\QCDRV\BIN\SETUP.EXE" UNINSTALL REMOVEPROMPT
        Python 2.2 pywin32 extensions (build 203)-->"C:\Python22\Removepywin32.exe" -u "C:\Python22\pywin32-wininst.log"
        Python 2.2.3-->C:\Python22\UNWISE.EXE C:\Python22\INSTALL.LOG
        Rayman Raving Rabbids 2 -->"C:\Program Files\InstallShield Installation Information\{B864EBC6-9DB8-4A5E-9F08-B0CE286785EC}\setup.exe" -runfromtemp -l0x040c -removeonly
        RealPlayer-->C:\Program Files\Fichiers communs\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
        Realtek High Definition Audio Driver-->RtlUpd.exe -r -m
        Samsung Master-->C:\Program Files\InstallShield Installation Information\{AEC0CEBC-0FC7-4716-8222-1C4A742719B1}\Setup.exe -runfromtemp -l0x040c -removeonly
        Samsung USB Driver-->"C:\Program Files\InstallShield Installation Information\{86D6A20D-3910-4441-A3E5-EB6977251C86}\Setup.exe" -runfromtemp -l0x040c anything -removeonly
        Security Update for CAPICOM (KB931906)-->MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
        Security Update for CAPICOM (KB931906)-->MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
        Segoe UI-->MsiExec.exe /I{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}
        Services Internet-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\1050\INTEL3~1\IDriver.exe /M{5CFD7508-7774-48FE-8280-7A3C0AE71755} /l1036
        Sonic Express Labeler-->MsiExec.exe /X{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}
        Sonic MyDVD Plus-->MsiExec.exe /X{21657574-BD54-48A2-9450-EB03B2C7FC29}
        Sonic RecordNow Audio-->MsiExec.exe /X{AB708C9B-97C8-4AC9-899B-DBF226AC9382}
        Sonic RecordNow Copy-->MsiExec.exe /X{B12665F4-4E93-4AB4-B7FC-37053B524629}
        Sonic RecordNow Data-->MsiExec.exe /X{075473F5-846A-448B-BCB3-104AA1760205}
        Sonic Update Manager-->MsiExec.exe /X{30465B6C-B53F-49A1-9EBA-A3F187AD502E}
        Spyware Doctor 6.0-->C:\Program Files\Spyware Doctor\unins000.exe /LOG
        Surligneur (Windows Live Toolbar)-->MsiExec.exe /X{81B5F83F-2291-48B0-8375-36B63A9BF5B0}
        Taxi 3-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0700\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{729FF024-6898-4919-9962-772078AD1B76}\setup.exe" -l0x40c
        Treasure Island Deluxe-->"C:\Program Files\Zylom Games\Treasure Island Deluxe\GameInstlr.exe" --uninstall UnInstall.log
        USB PC Camera (ZS0211)-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{44D02D8B-FFB3-4245-8D26-68D10B4C4023}\setup.exe" -l0x40c
        Windows Internet Explorer 8-->"C:\WINDOWS\ie8\spuninst\spuninst.exe"
        Windows Live Call-->MsiExec.exe /I{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}
        Windows Live Communications Platform-->MsiExec.exe /I{3B4E636E-9D65-4D67-BA61-189800823F52}
        Windows Live Contrôle parental-->MsiExec.exe /X{D6A2DDE3-9D7C-412C-932A-756580D29919}
        Windows Live Favorites pour Windows Live Toolbar-->MsiExec.exe /X{786C4AD1-DCBA-49A6-B0EF-B317A344BD66}
        Windows Live Mail-->MsiExec.exe /I{63DC2DA0-2A6C-4C38-9249-B75395458657}
        Windows Live Messenger-->MsiExec.exe /X{059C042E-796A-4ACC-A81A-ECC2010BB78C}
        Windows Live Sync-->MsiExec.exe /X{9C5EB781-0D37-44B8-9A58-77B3E4BF5F5E}
        Windows Live Toolbar-->MsiExec.exe /X{F7D27C70-90F5-49B9-B188-0A133C0CE353}
        Windows Live Writer-->MsiExec.exe /X{2231CE39-B963-4B9D-823A-F412ECA637B1}
        Windows Media Format Runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
        Windows XP Media Center Edition 2005 KB912067-->"C:\WINDOWS\$NtUninstallKB912067$\spuninst\spuninst.exe"
        Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
        ZoneAlarm-->C:\Program Files\Zone Labs\ZoneAlarm\zauninst.exe

        ======Security center information======

        AV: ZoneAlarm Security Suite Antivirus
        AV: AntiVir Desktop
        FW: ZoneAlarm Firewall (disabled)

        ======System event log======

        Computer Name: KYKY
        Event Code: 7035
        Message: Un contrôle Démarrer a correctement été envoyé au service Pml Driver HPZ12.

        Record Number: 5931
        Source Name: Service Control Manager
        Time Written: 20090508164545.000000+120
        Event Type: Informations
        User: KYKY\HP_Administrateur

        Computer Name: KYKY
        Event Code: 7036
        Message: Le service Acquisition d'image Windows (WIA) est entré dans l'état : en cours d'exécution.

        Record Number: 5930
        Source Name: Service Control Manager
        Time Written: 20090508164545.000000+120
        Event Type: Informations
        User:

        Computer Name: KYKY
        Event Code: 7036
        Message: Le service Pml Driver HPZ12 est entré dans l'état : arrêté.

        Record Number: 5929
        Source Name: Service Control Manager
        Time Written: 20090508154240.000000+120
        Event Type: Informations
        User:

        Computer Name: KYKY
        Event Code: 7035
        Message: Un contrôle Démarrer a correctement été envoyé au service Pml Driver HPZ12.

        Record Number: 5928
        Source Name: Service Control Manager
        Time Written: 20090508154240.000000+120
        Event Type: Informations
        User: KYKY\HP_Administrateur

        Computer Name: KYKY
        Event Code: 7036
        Message: Le service Pml Driver HPZ12 est entré dans l'état : en cours d'exécution.

        Record Number: 5927
        Source Name: Service Control Manager
        Time Written: 20090508154240.000000+120
        Event Type: Informations
        User:

        =====Application event log=====

        Computer Name: KYKY
        Event Code: 4
        Message: The LightScribe Service started successfully.

        Record Number: 2822
        Source Name: LightScribeService
        Time Written: 20090105174708.000000+060
        Event Type: Informations
        User:

        Computer Name: KYKY
        Event Code: 0
        Message: Service started

        Record Number: 2821
        Source Name: fsssvc
        Time Written: 20090105174705.000000+060
        Event Type: Informations
        User:

        Computer Name: KYKY
        Event Code: 1
        Message: The service is started.

        Record Number: 2820
        Source Name: IJPLMSVC
        Time Written: 20090105174701.000000+060
        Event Type: Informations
        User:

        Computer Name: KYKY
        Event Code: 105
        Message: The service was started.

        Record Number: 2819
        Source Name: ARSVC
        Time Written: 20090105174659.000000+060
        Event Type: Informations
        User:

        Computer Name: KYKY
        Event Code: 110
        Message: The service was stopped because of shutdown.

        Record Number: 2818
        Source Name: ARSVC
        Time Written: 20090105150713.000000+060
        Event Type: Informations
        User:

        ======Environment variables======

        "ComSpec"=%SystemRoot%\system32\cmd.exe
        "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;c:\Python22;C:\Program Files\ATI Technologies\ATI Control Panel
        "windir"=%SystemRoot%
        "FP_NO_HOST_CHECK"=NO
        "OS"=Windows_NT
        "PROCESSOR_ARCHITECTURE"=x86
        "PROCESSOR_LEVEL"=15
        "PROCESSOR_IDENTIFIER"=x86 Family 15 Model 6 Stepping 4, GenuineIntel
        "PROCESSOR_REVISION"=0604
        "NUMBER_OF_PROCESSORS"=1
        "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
        "TEMP"=%SystemRoot%\TEMP
        "TMP"=%SystemRoot%\TEMP
        "SonicCentral"=c:\Program Files\Fichiers communs\Sonic Shared\Sonic Central\
        "tvdumpflags"=8

        -----------------EOF-----------------
        0
        1. Contributeur sécurité
          bon tu vas faire ce qui suis avec usbfix, merci

          ##################### | XP _ Instal & recherche | ########################

          # Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
          Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
          Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.


          Télécharge et install UsbFix de C_XX & Chiquitine29

          Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptible d'avoir été infectées sans les ouvrir

          # Double clic sur le raccourci UsbFix présent sur ton bureau .

          # Choisis l'option 1 ( Recherche )

          # Laisse travailler l'outil.

          # Ensuite post le rapport UsbFix.txt qui apparaitra.

          # Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque. ( C:\UsbFix.txt )

          ( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

          ##################### | XP _ Suppression | ########################

          Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptible d avoir été infectés sans les ouvrir

          # Double clic sur le raccourci UsbFix présent sur ton bureau

          # choisis l'option 2 ( Suppression )

          # Ton bureau disparaitra et le pc redémarrera .

          # Au redémarrage , UsbFix scannera ton pc , laisse travailler l'outil.

          # Ensuite post le rapport UsbFix.txt qui apparaitra avec le bureau .

          # Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque.( C:\UsbFix.txt )

          ( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

          ##################### | XP _ Désinstallation | ########################

          # Double clic sur le raccourci UsbFix présent sur ton bureau

          # Choisis l'option 5 ( Désinstaller ) ....
          0
          1. Re voila le 1er rapport je poste la suite plus tard
            Merci de ton aide

            ############################## [ UsbFix V3.027 | Scan ]

            # User : HP_Administrateur (Administrateurs) # KYKY
            # Update on 30/05/09 by Chiquitine29, C_XX & Chimay8
            # WebSite : http://pagesperso-orange.fr/NosTools/usbfix.html
            # Start at: 22:01:14 | 01/06/2009

            # Intel(R) Celeron(R) D CPU 3.20GHz
            # Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 3
            # Internet Explorer 8.0.6001.18702
            # Windows Firewall Status : Disabled
            # AV : ZoneAlarm Security Suite Antivirus 7.0.483.000 [ Enabled | Updated ]
            # AV : AntiVir Desktop 9.0.1.26 [ Enabled | Updated ]
            # FW : ZoneAlarm Firewall[ (!) Disabled ]7.0.483.000

            # C:\ # Disque fixe local # 226,14 Go (175,47 Go free) [HP_PAVILION] # NTFS
            # D:\ # Disque fixe local # 6,72 Go (6,72 Go free) [HP_RECOVERY] # FAT32
            # E:\ # Disque CD-ROM # 274,21 Mo (0 Mo free) [PyjamaHG] # CDFS
            # F:\ # Disque fixe local # 465,76 Go (465,27 Go free) # NTFS
            # G:\ # Disque amovible
            # H:\ # Disque amovible
            # I:\ # Disque amovible
            # J:\ # Disque amovible

            ############################## [ Processus actifs ]

            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\csrss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\Ati2evxx.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\Ati2evxx.exe
            C:\WINDOWS\Explorer.EXE
            C:\WINDOWS\system32\ZoneLabs\vsmon.exe
            C:\WINDOWS\system32\spoolsv.exe
            C:\Program Files\Avira\AntiVir Desktop\sched.exe
            C:\WINDOWS\system32\svchost.exe
            C:\Program Files\Google\Update\GoogleUpdate.exe
            C:\Program Files\Avira\AntiVir Desktop\avguard.exe
            C:\WINDOWS\arservice.exe
            C:\WINDOWS\system32\ezNTSvc.exe
            C:\Program Files\Windows Live\Family Safety\fsssvc.exe
            C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
            C:\Program Files\Java\jre6\bin\jqs.exe
            C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
            C:\Program Files\Spyware Doctor\pctsAuxs.exe
            C:\Program Files\Spyware Doctor\pctsSvc.exe
            C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
            C:\Program Files\Spyware Doctor\pctsTray.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\ehome\mcrdsvc.exe
            C:\WINDOWS\system32\wbem\wmiapsrv.exe
            C:\WINDOWS\System32\alg.exe
            C:\WINDOWS\ehome\ehtray.exe
            C:\WINDOWS\ARPWRMSG.EXE
            C:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe
            C:\WINDOWS\System32\svchost.exe
            C:\Program Files\Windows Live\Family Safety\fsui.exe
            C:\Program Files\Canon\MyPrinter\BJMyPrt.exe
            C:\WINDOWS\ZSSnp211.exe
            C:\WINDOWS\Domino.exe
            C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
            C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
            C:\Program Files\Java\jre6\bin\jusched.exe
            C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
            C:\WINDOWS\system32\ctfmon.exe
            C:\Program Files\Windows Live\Messenger\msnmsgr.exe
            C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
            C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
            C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
            C:\HP\KBD\KBD.EXE
            C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
            c:\windows\system\hpsysdrv.exe
            C:\Program Files\Windows Live\Contacts\wlcomm.exe
            C:\Program Files\Mozilla Firefox\firefox.exe
            C:\WINDOWS\system32\wbem\wmiprvse.exe

            ################## [ Registre Startup ]

            HKCU_Main: "Local Page"="C:\\WINDOWS\\system32\\blank.htm"
            HKCU_Main: "Search Page"=""
            HKCU_Main: "Start Page"="https://www.orange.fr/portail"
            HKLM_logon: "Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
            HKLM_logon: "Windows Shell (ezShellStart)"="C:\\WINDOWS\\system32\\userinit.exe,"
            HKLM_logon: "DefaultUserName"="HP_Administrateur"
            HKLM_logon: "AltDefaultUserName"="HP_Administrateur"
            HKLM_logon: "LegalNoticeCaption"=""
            HKLM_logon: "LegalNoticeText"=""
            HKLM_Run: ehTray=C:\WINDOWS\ehome\ehtray.exe
            HKLM_Run: AlwaysReady Power Message APP=ARPWRMSG.EXE
            HKLM_Run: DMAScheduler="c:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe"
            HKLM_Run: Recguard=C:\WINDOWS\SMINST\RECGUARD.EXE
            HKLM_Run: PCDrProfiler=
            HKLM_Run: HPBootOp="C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
            HKLM_Run: fssui="C:\Program Files\Windows Live\Family Safety\fsui.exe" -autorun
            HKLM_Run: CanonSolutionMenu=C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
            HKLM_Run: CanonMyPrinter=C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
            HKLM_Run: ZSSnp211=C:\WINDOWS\ZSSnp211.exe
            HKLM_Run: Domino=C:\WINDOWS\Domino.exe
            HKLM_Run: ISTray="C:\Program Files\Spyware Doctor\pctsTray.exe"
            HKLM_Run: ZoneAlarm Client="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
            HKLM_Run: TkBellExe="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
            HKLM_Run: SunJavaUpdateSched="C:\Program Files\Java\jre6\bin\jusched.exe"
            HKLM_Run: Adobe Reader Speed Launcher="C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
            HKLM_Run: avgnt="C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
            HKLM_Run: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents=
            HKCU_Run: ctfmon.exe=C:\WINDOWS\system32\ctfmon.exe
            HKCU_Run: swg=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
            HKCU_Run: msnmsgr="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background

            ################## [ Fichiers # Dossiers infectieux ]

            Found ! E:\autorun.inf
            Found ! F:\autorun.inf

            ################## [ Registre # Clés Run infectieuses ]

            Found ! HKLM\software\microsoft\security center "FirewallOverride" ( 0x1 )

            ################## [ Registre # Mountpoints2 ]

            HKCU\...\Explorer\MountPoints2\{6ae85e1e-a362-11dd-b794-0016ecd34fdd}\Shell\AutoRun\Command
            HKCU\...\Explorer\MountPoints2\{96f6d358-0a48-11de-9cd9-806d6172696f}\Shell\Auto\Command
            HKCU\...\Explorer\MountPoints2\{96f6d358-0a48-11de-9cd9-806d6172696f}\Shell\AutoRun\Command
            HKCU\...\Explorer\MountPoints2\{ad7d48d8-9ba4-11dd-b778-806d6172696f}\Shell\AutoRun\Command

            ################## [ Informations # Fichier Suspect ]

            ################## [ Cracks # Keygens # Serials ]

            # -> Nothing found !

            ################## [ ! Fin du rapport # UsbFix V3.027 ! ]
            0
            1. Me revoila j'ai eu un souci pendant l'execution de l'étape 2 tout c'est arreter aucune progression pendant 1heure j'ai tout éteint j'éspère ne pas avoir fait de betise .Du coup je ne sais pas si je doit refaire cette étape ou tout recommencer j'attend tes instructions.Une autre chose quand je l'ai rallumer mon pc il me met que mon pare feu est désactiver j'ai été regarder mais je n'est pas l'impression qu'il soit désactivé mais il me laisse l'alerte allumer,est ce normal? Merci
              0
              1. Contributeur sécurité
                c'est en bêtant de l'avoir arrêter tu me refais un nouveau RSIT tu postes le rapport il n'y en aura qu'un
                0
                1. Désolée je pensais que ca ne marchais plus il n'y avais vraiment plus rien qui bougeait.Donc voici le rapport demander.

                  Logfile of random's system information tool 1.06 (written by random/random)
                  Run by HP_Administrateur at 2009-06-01 23:39:14
                  Microsoft Windows XP Professionnel Service Pack 3
                  System drive C: has 180 GB (78%) free of 232 GB
                  Total RAM: 447 MB (8% free)

                  Logfile of Trend Micro HijackThis v2.0.2
                  Scan saved at 23:40:10, on 01/06/2009
                  Platform: Windows XP SP3 (WinNT 5.01.2600)
                  MSIE: Internet Explorer v8.00 (8.00.6001.18702)
                  Boot mode: Normal

                  Running processes:
                  C:\WINDOWS\System32\smss.exe
                  C:\WINDOWS\system32\csrss.exe
                  C:\WINDOWS\system32\winlogon.exe
                  C:\WINDOWS\system32\services.exe
                  C:\WINDOWS\system32\lsass.exe
                  C:\WINDOWS\system32\Ati2evxx.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\system32\Ati2evxx.exe
                  C:\WINDOWS\Explorer.EXE
                  C:\WINDOWS\system32\ZoneLabs\vsmon.exe
                  C:\WINDOWS\system32\spoolsv.exe
                  C:\Program Files\Avira\AntiVir Desktop\sched.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\Program Files\Google\Update\GoogleUpdate.exe
                  C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                  C:\WINDOWS\arservice.exe
                  C:\WINDOWS\system32\ezNTSvc.exe
                  C:\Program Files\Windows Live\Family Safety\fsssvc.exe
                  C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
                  C:\Program Files\Java\jre6\bin\jqs.exe
                  C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
                  C:\Program Files\Spyware Doctor\pctsAuxs.exe
                  C:\Program Files\Spyware Doctor\pctsSvc.exe
                  C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                  C:\Program Files\Spyware Doctor\pctsTray.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\ehome\mcrdsvc.exe
                  C:\WINDOWS\system32\wbem\wmiapsrv.exe
                  C:\WINDOWS\System32\alg.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\WINDOWS\ehome\ehtray.exe
                  C:\WINDOWS\ARPWRMSG.EXE
                  C:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe
                  C:\Program Files\Windows Live\Family Safety\fsui.exe
                  C:\Program Files\Mozilla Firefox\firefox.exe
                  C:\Program Files\Canon\MyPrinter\BJMyPrt.exe
                  C:\WINDOWS\ZSSnp211.exe
                  C:\WINDOWS\Domino.exe
                  C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
                  C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                  C:\Program Files\Java\jre6\bin\jusched.exe
                  C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
                  C:\WINDOWS\system32\ctfmon.exe
                  C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                  C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
                  C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                  C:\WINDOWS\system32\wscntfy.exe
                  C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
                  C:\Program Files\Windows Live\Contacts\wlcomm.exe
                  C:\Documents and Settings\HP_Administrateur.KYKY.000\Bureau\RSIT.exe
                  C:\WINDOWS\system32\wbem\wmiprvse.exe
                  C:\Program Files\Trend Micro\HijackThis\HP_Administrateur.exe

                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://fr.search.yahoo.com/?fr=cb-hp06
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = https://fr.search.yahoo.com/?fr=cb-hp06
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                  O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                  O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
                  O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
                  O2 - BHO: Windows Live Family Safety Browser Helper - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll
                  O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
                  O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
                  O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                  O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
                  O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
                  O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
                  O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                  O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                  O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
                  O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                  O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
                  O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
                  O4 - HKLM\..\Run: [AlwaysReady Power Message APP] ARPWRMSG.EXE
                  O4 - HKLM\..\Run: [DMAScheduler] "c:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe"
                  O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
                  O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
                  O4 - HKLM\..\Run: [fssui] "C:\Program Files\Windows Live\Family Safety\fsui.exe" -autorun
                  O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
                  O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
                  O4 - HKLM\..\Run: [ZSSnp211] C:\WINDOWS\ZSSnp211.exe
                  O4 - HKLM\..\Run: [Domino] C:\WINDOWS\Domino.exe
                  O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
                  O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
                  O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                  O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                  O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
                  O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
                  O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                  O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                  O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                  O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
                  O4 - .DEFAULT User Startup: PinMcLnk.lnk = C:\hp\bin\cloaker.exe (User 'Default user')
                  O4 - Global Startup: Contrôleur de calendrier Ulead.lnk = C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
                  O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                  O4 - Global Startup: STK017 PNP Monitor.lnk = C:\Program Files\STK017_V2.01\STK017D.exe
                  O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
                  O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
                  O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                  O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                  O9 - Extra button: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
                  O9 - Extra 'Tools' menuitem: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
                  O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                  O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                  O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
                  O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
                  O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
                  O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://jeuxenligne.orange.fr/Gameshell/GameHost/1.0/OberonGameHost.cab
                  O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                  O16 - DPF: {FC4CAF5F-91BD-4DD9-ADC1-F3C737E37BC4} (CPlayFirstSweetopiaControl Object) - file:///C:/Documents%20and%20Settings/HP_Administrateur.KYKY.000/Local%20Settings/Application%20Data/Oberon%20Media/Oberon%20Games%20Host/Sweetopia.1.0.0.46.cab
                  O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
                  O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
                  O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                  O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                  O23 - Service: EasyBits Magic Desktop Services for Windows NT (ezntsvc) - EasyBits Software Corp. - C:\WINDOWS\system32\ezNTSvc.exe
                  O23 - Service: getPlus(R) Helper - Unknown owner - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe (file missing)
                  O23 - Service: Service Google Update (gupdate1c9e1855191ec6c) (gupdate1c9e1855191ec6c) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
                  O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                  O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                  O23 - Service: Inkjet Printer/Scanner Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
                  O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
                  O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
                  O23 - Service: LVSrvLauncher - Unknown owner - C:\Program Files\Fichiers communs\LogiShrd\SrvLnch\SrvLnch.exe (file missing)
                  O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
                  O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
                  O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
                  O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
                  0
                  1. Contributeur sécurité
                    bon je ne retrouve pas ce qu'il y avais sur le premier donc il as du les virer tu me posteras un nouveau usbfix option 1 pour contrôler cela mais cela me semble bon , je regarderais demain car la dodo boulot dans 7h et te donnerais pour finir le nettoyage
                    0
                    1. ok le ferai demain moi aussi dodo je te souhaite une bonne nuit et merci encore pour ton aide a demain
                      0
                      1. Bonjour voila je te post le rapport

                        ############################## [ UsbFix V3.027 | Scan ]

                        # User : HP_Administrateur (Administrateurs) # KYKY
                        # Update on 30/05/09 by Chiquitine29, C_XX & Chimay8
                        # WebSite : http://pagesperso-orange.fr/NosTools/usbfix.html
                        # Start at: 13:12:07 | 02/06/2009

                        # Intel(R) Celeron(R) D CPU 3.20GHz
                        # Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 3
                        # Internet Explorer 8.0.6001.18702
                        # Windows Firewall Status : Disabled
                        # AV : ZoneAlarm Security Suite Antivirus 7.0.483.000 [ Enabled | Updated ]
                        # AV : AntiVir Desktop 9.0.1.26 [ Enabled | Updated ]
                        # FW : ZoneAlarm Firewall[ Enabled ]7.0.483.000

                        # C:\ # Disque fixe local # 226,14 Go (175,59 Go free) [HP_PAVILION] # NTFS
                        # D:\ # Disque fixe local # 6,72 Go (6,72 Go free) [HP_RECOVERY] # FAT32
                        # E:\ # Disque CD-ROM # 274,21 Mo (0 Mo free) [PyjamaHG] # CDFS
                        # G:\ # Disque amovible
                        # H:\ # Disque amovible
                        # I:\ # Disque amovible
                        # J:\ # Disque amovible

                        ############################## [ Processus actifs ]

                        C:\WINDOWS\System32\smss.exe
                        C:\WINDOWS\system32\csrss.exe
                        C:\WINDOWS\system32\winlogon.exe
                        C:\WINDOWS\system32\services.exe
                        C:\WINDOWS\system32\lsass.exe
                        C:\WINDOWS\system32\Ati2evxx.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\system32\Ati2evxx.exe
                        C:\WINDOWS\Explorer.EXE
                        C:\WINDOWS\system32\ZoneLabs\vsmon.exe
                        C:\WINDOWS\system32\spoolsv.exe
                        C:\Program Files\Avira\AntiVir Desktop\sched.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\Program Files\Google\Update\GoogleUpdate.exe
                        C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                        C:\WINDOWS\arservice.exe
                        C:\WINDOWS\system32\ezNTSvc.exe
                        C:\Program Files\Windows Live\Family Safety\fsssvc.exe
                        C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
                        C:\Program Files\Java\jre6\bin\jqs.exe
                        C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
                        C:\Program Files\Spyware Doctor\pctsAuxs.exe
                        C:\Program Files\Spyware Doctor\pctsSvc.exe
                        C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                        C:\Program Files\Spyware Doctor\pctsTray.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\ehome\mcrdsvc.exe
                        C:\WINDOWS\system32\wbem\wmiapsrv.exe
                        C:\WINDOWS\System32\alg.exe
                        C:\WINDOWS\ehome\ehtray.exe
                        C:\WINDOWS\ARPWRMSG.EXE
                        C:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe
                        C:\Program Files\Windows Live\Family Safety\fsui.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\Program Files\Canon\MyPrinter\BJMyPrt.exe
                        C:\WINDOWS\ZSSnp211.exe
                        C:\WINDOWS\Domino.exe
                        C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
                        C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                        C:\Program Files\Java\jre6\bin\jusched.exe
                        C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
                        C:\WINDOWS\system32\ctfmon.exe
                        C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                        C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
                        C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                        C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
                        C:\HP\KBD\KBD.EXE
                        C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                        c:\windows\system\hpsysdrv.exe
                        C:\Program Files\Mozilla Firefox\firefox.exe
                        C:\WINDOWS\system32\wbem\wmiprvse.exe

                        ################## [ Registre Startup ]

                        HKCU_Main: "Local Page"="C:\\WINDOWS\\system32\\blank.htm"
                        HKCU_Main: "Search Page"=""
                        HKCU_Main: "Start Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
                        HKCU_Main: "Window Title"=""
                        HKLM_logon: "Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
                        HKLM_logon: "Windows Shell (ezShellStart)"="C:\\WINDOWS\\system32\\userinit.exe,"
                        HKLM_logon: "DefaultUserName"="HP_Administrateur"
                        HKLM_logon: "AltDefaultUserName"="HP_Administrateur"
                        HKLM_logon: "LegalNoticeCaption"=""
                        HKLM_logon: "LegalNoticeText"=""
                        HKLM_Run: ehTray=C:\WINDOWS\ehome\ehtray.exe
                        HKLM_Run: AlwaysReady Power Message APP=ARPWRMSG.EXE
                        HKLM_Run: DMAScheduler="c:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe"
                        HKLM_Run: Recguard=C:\WINDOWS\SMINST\RECGUARD.EXE
                        HKLM_Run: PCDrProfiler=
                        HKLM_Run: HPBootOp="C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
                        HKLM_Run: fssui="C:\Program Files\Windows Live\Family Safety\fsui.exe" -autorun
                        HKLM_Run: CanonSolutionMenu=C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
                        HKLM_Run: CanonMyPrinter=C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
                        HKLM_Run: ZSSnp211=C:\WINDOWS\ZSSnp211.exe
                        HKLM_Run: Domino=C:\WINDOWS\Domino.exe
                        HKLM_Run: ISTray="C:\Program Files\Spyware Doctor\pctsTray.exe"
                        HKLM_Run: ZoneAlarm Client="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
                        HKLM_Run: TkBellExe="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                        HKLM_Run: SunJavaUpdateSched="C:\Program Files\Java\jre6\bin\jusched.exe"
                        HKLM_Run: Adobe Reader Speed Launcher="C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
                        HKLM_Run: avgnt="C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
                        HKLM_Run: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents=
                        HKCU_Run: ctfmon.exe=C:\WINDOWS\system32\ctfmon.exe
                        HKCU_Run: swg=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                        HKCU_Run: msnmsgr="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background

                        ################## [ Fichiers # Dossiers infectieux ]

                        Found ! E:\autorun.inf

                        ################## [ Registre # Clés Run infectieuses ]

                        ################## [ Registre # Mountpoints2 ]

                        ################## [ Informations # Fichier Suspect ]

                        ################## [ Cracks # Keygens # Serials ]

                        # -> Nothing found !

                        ################## [ ! Fin du rapport # UsbFix V3.027 ! ]
                        0
                        1. Contributeur sécurité
                          ################## [ Fichiers # Dossiers infectieux ]

                          Found ! E:\autorun.inf
                          il y a encore cela tu refais l'option 2 , merci
                          0
                          1. Re d'accord je ferais ca demain y aura t'il un rapport aussi?Si oui le post demain.Merci encore pour ton aide
                            0
                            1. Contributeur sécurité
                              oui il y aura un rapport et la essais de le laisser finir
                              0
                              1. oui d'accord c'est pour ca le ferais demain il pourras passer la journée si il le faut. Je t'envoie le rapport demain bonne soirée a toi et bonne nuit.
                                0
                                1. Bonjour,voici le rapport.Merci

                                  ############################## [ UsbFix V3.027 | Cleaning ]

                                  # User : HP_Administrateur (Administrateurs) # KYKY
                                  # Update on 30/05/09 by Chiquitine29, C_XX & Chimay8
                                  # WebSite : http://pagesperso-orange.fr/NosTools/usbfix.html
                                  # Start at: 09:51:13 | 03/06/2009

                                  # Intel(R) Celeron(R) D CPU 3.20GHz
                                  # Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 3
                                  # Internet Explorer 8.0.6001.18702
                                  # Windows Firewall Status : Enabled
                                  # AV : ZoneAlarm Security Suite Antivirus 7.0.483.000 [ Enabled | Updated ]
                                  # AV : AntiVir Desktop 9.0.1.26 [ Enabled | Updated ]
                                  # FW : ZoneAlarm Firewall[ (!) Disabled ]7.0.483.000

                                  # C:\ # Disque fixe local # 226,14 Go (175,6 Go free) [HP_PAVILION] # NTFS
                                  # D:\ # Disque fixe local # 6,72 Go (6,72 Go free) [HP_RECOVERY] # FAT32
                                  # E:\ # Disque CD-ROM # 274,21 Mo (0 Mo free) [PyjamaHG] # CDFS
                                  # F:\ # Disque fixe local # 465,76 Go (465,27 Go free) # NTFS
                                  # G:\ # Disque amovible
                                  # H:\ # Disque amovible
                                  # I:\ # Disque amovible
                                  # J:\ # Disque amovible

                                  ############################## [ Processus actifs ]

                                  C:\WINDOWS\System32\smss.exe
                                  C:\WINDOWS\system32\csrss.exe
                                  C:\WINDOWS\system32\winlogon.exe
                                  C:\WINDOWS\system32\services.exe
                                  C:\WINDOWS\system32\lsass.exe
                                  C:\WINDOWS\system32\Ati2evxx.exe
                                  C:\WINDOWS\system32\svchost.exe
                                  C:\WINDOWS\system32\svchost.exe
                                  C:\WINDOWS\System32\svchost.exe
                                  C:\WINDOWS\system32\svchost.exe
                                  C:\WINDOWS\system32\svchost.exe
                                  C:\WINDOWS\system32\Ati2evxx.exe
                                  C:\WINDOWS\Explorer.EXE
                                  C:\WINDOWS\system32\ZoneLabs\vsmon.exe
                                  C:\WINDOWS\system32\spoolsv.exe
                                  C:\Program Files\Avira\AntiVir Desktop\sched.exe
                                  C:\WINDOWS\system32\svchost.exe
                                  C:\Program Files\Google\Update\GoogleUpdate.exe
                                  C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                                  C:\WINDOWS\arservice.exe
                                  C:\WINDOWS\system32\ezNTSvc.exe
                                  C:\Program Files\Windows Live\Family Safety\fsssvc.exe
                                  C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
                                  C:\Program Files\Java\jre6\bin\jqs.exe
                                  C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
                                  C:\WINDOWS\system32\HPZipm12.exe
                                  C:\Program Files\Spyware Doctor\pctsAuxs.exe
                                  C:\Program Files\Spyware Doctor\pctsSvc.exe
                                  C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                                  C:\Program Files\Spyware Doctor\pctsTray.exe
                                  C:\WINDOWS\system32\svchost.exe
                                  C:\WINDOWS\system32\svchost.exe
                                  C:\WINDOWS\ehome\mcrdsvc.exe
                                  C:\WINDOWS\system32\wuauclt.exe
                                  C:\WINDOWS\system32\wbem\wmiprvse.exe
                                  C:\WINDOWS\system32\wbem\wmiapsrv.exe
                                  C:\WINDOWS\system32\wbem\wmiprvse.exe
                                  C:\WINDOWS\system32\wscntfy.exe
                                  C:\Program Files\Spyware Doctor\pctsTray.exe
                                  C:\WINDOWS\System32\alg.exe

                                  ################## [ Fichiers # Dossiers infectieux ]

                                  (!) Not Deleted ! E:\autorun.inf

                                  ################## [ Registre # Clés Run infectieuses ]

                                  ################## [ Registre # Mountpoints2 ]

                                  ################## [ Listing des fichiers présent ]

                                  [19/01/2008 02:04|--a------|584] - C:\albumTable.dbf
                                  [05/09/2006 00:16|--ah-----|100] - C:\AUTOEXEC.BAT
                                  [16/10/2008 19:14|-rahs----|211] - C:\BOOT.BAK
                                  [16/10/2008 19:22|-rahs----|291] - C:\boot.ini
                                  [09/08/2004 23:00|-rahs----|4952] - C:\Bootfont.bin
                                  [23/02/2007 19:51|--a------|5242880] - C:\CAPTURE.AVI
                                  [09/08/2004 23:00|-r-hs----|263488] - C:\cmldr
                                  [10/10/2005 13:34|--ah-----|0] - C:\CONFIG.SYS
                                  [02/01/2009 15:49|--a------|353] - C:\content_update_notification.xml
                                  [?|?|?] - C:\hiberfil.sys
                                  [10/10/2005 13:34|-rahs----|0] - C:\IO.SYS
                                  [09/09/2008 18:45|--ah-----|732] - C:\IPH.PH
                                  [10/10/2005 13:34|-rahs----|0] - C:\MSDOS.SYS
                                  [09/08/2004 23:00|-rahs----|47564] - C:\NTDETECT.COM
                                  [17/10/2008 20:13|-rahs----|252240] - C:\ntldr
                                  [?|?|?] - C:\pagefile.sys
                                  [04/05/2009 00:01|--a------|92650] - C:\playground.log
                                  [05/03/2009 20:52|--a------|1113] - C:\rollback.ini
                                  [05/06/2008 22:21|--a------|90] - C:\Setup.log
                                  [03/02/2007 09:42|--ah-----|268] - C:\sqmdata00.sqm
                                  [03/03/2007 21:49|--ah-----|268] - C:\sqmdata01.sqm
                                  [18/03/2007 00:52|--ah-----|268] - C:\sqmdata02.sqm
                                  [18/03/2007 13:26|--ah-----|268] - C:\sqmdata03.sqm
                                  [18/03/2007 21:57|--ah-----|280] - C:\sqmdata04.sqm
                                  [27/06/2007 15:15|--ah-----|136] - C:\sqmdata05.sqm
                                  [27/06/2007 16:40|--ah-----|232] - C:\sqmdata06.sqm
                                  [09/08/2007 19:41|--ah-----|268] - C:\sqmdata07.sqm
                                  [06/10/2007 20:05|--ah-----|268] - C:\sqmdata08.sqm
                                  [23/12/2007 16:25|--ah-----|268] - C:\sqmdata09.sqm
                                  [07/01/2008 18:32|--ah-----|268] - C:\sqmdata10.sqm
                                  [07/01/2008 22:00|--ah-----|268] - C:\sqmdata11.sqm
                                  [10/01/2008 23:23|--ah-----|232] - C:\sqmdata12.sqm
                                  [18/08/2008 18:18|--ah-----|232] - C:\sqmdata13.sqm
                                  [18/08/2008 18:20|--ah-----|232] - C:\sqmdata14.sqm
                                  [02/11/2008 16:55|--ah-----|268] - C:\sqmdata15.sqm
                                  [19/11/2008 16:12|--ah-----|268] - C:\sqmdata16.sqm
                                  [02/02/2007 18:41|--ah-----|136] - C:\sqmdata17.sqm
                                  [02/02/2007 19:00|--ah-----|268] - C:\sqmdata18.sqm
                                  [02/02/2007 19:00|--ah-----|232] - C:\sqmdata19.sqm
                                  [06/10/2007 20:05|--ah-----|244] - C:\sqmnoopt00.sqm
                                  [23/12/2007 16:25|--ah-----|244] - C:\sqmnoopt01.sqm
                                  [07/01/2008 18:32|--ah-----|244] - C:\sqmnoopt02.sqm
                                  [07/01/2008 22:00|--ah-----|244] - C:\sqmnoopt03.sqm
                                  [10/01/2008 23:23|--ah-----|244] - C:\sqmnoopt04.sqm
                                  [18/08/2008 18:18|--ah-----|244] - C:\sqmnoopt05.sqm
                                  [18/08/2008 18:20|--ah-----|244] - C:\sqmnoopt06.sqm
                                  [02/11/2008 16:55|--ah-----|244] - C:\sqmnoopt07.sqm
                                  [19/11/2008 16:12|--ah-----|244] - C:\sqmnoopt08.sqm
                                  [02/02/2007 19:00|--ah-----|244] - C:\sqmnoopt09.sqm
                                  [02/02/2007 19:00|--ah-----|244] - C:\sqmnoopt10.sqm
                                  [03/02/2007 09:42|--ah-----|244] - C:\sqmnoopt11.sqm
                                  [03/03/2007 21:49|--ah-----|244] - C:\sqmnoopt12.sqm
                                  [18/03/2007 00:52|--ah-----|244] - C:\sqmnoopt13.sqm
                                  [18/03/2007 13:26|--ah-----|244] - C:\sqmnoopt14.sqm
                                  [18/03/2007 21:57|--ah-----|244] - C:\sqmnoopt15.sqm
                                  [27/06/2007 15:15|--ah-----|136] - C:\sqmnoopt16.sqm
                                  [27/06/2007 15:15|--ah-----|136] - C:\sqmnoopt17.sqm
                                  [27/06/2007 16:40|--ah-----|244] - C:\sqmnoopt18.sqm
                                  [09/08/2007 19:41|--ah-----|244] - C:\sqmnoopt19.sqm
                                  [18/02/2009 14:33|--a------|2170] - C:\TCleaner.txt
                                  [17/10/2008 20:16|--a------|510] - C:\updatedatfix.log
                                  [03/06/2009 09:55|--a------|6055] - C:\UsbFix.txt
                                  [12/09/2000 17:41|-r-------|52] - E:\AUTORUN.INF
                                  [09/10/2000 11:25|-r-------|98304] - E:\AutoStart.EXE
                                  [25/09/2000 18:55|-r-------|284] - E:\AutoStart.INF
                                  [02/10/2000 13:43|-r-------|77306] - E:\AutoStart.pcx
                                  [27/09/2000 16:40|-r-------|176] - E:\Copyrite.txt
                                  [21/02/2008 13:56|--a------|2099] - F:\Adobe Photoshop Album Edition D‚couverte 3.2.lnk
                                  [04/11/2008 15:48|--a------|2020] - F:\certificat.pfx
                                  [29/06/2008 00:44|--a------|1803] - F:\Cradle of Rome.lnk
                                  [29/03/2008 12:00|--a------|71738] - F:\Maxtor_Desktop.ico
                                  [01/01/2008 23:33|--a------|677] - F:\Picasa2.lnk
                                  [12/09/2008 17:11|--a------|1818] - F:\Rayman Raving Rabbids 2 .lnk
                                  [06/10/2008 09:04|--a------|669] - F:\Virtualis.lnk
                                  [06/10/2008 09:03|--a------|652360] - F:\virtualiscmb.exe

                                  ################## [ Vaccination ]

                                  # C:\autorun.inf ( # Not infected ) -> Folder created by UsbFix.
                                  # D:\autorun.inf ( # Not infected ) -> Folder created by UsbFix.
                                  # F:\autorun.inf ( # Not infected ) -> Folder created by UsbFix.

                                  ################## [ Informations # Fichier Suspect ]

                                  ################## [ Cracks # Keygens # Serials ]

                                  # -> Nothing found !

                                  ################## [ ! Fin du rapport # UsbFix V3.027 ! ]
                                  0
                                  1. Contributeur sécurité
                                    bonjour, OK désolé pour ce contre temps je viens de voire que E est ton lecteur CD désolé normal qu'il ne puisse pas le désinfecter !! lol !! # E:\ # Disque CD-ROM

                                    tu passeras malwarebytes , Merci

                                    Télécharge Malwarebytes' Anti-Malware: https://www.malekal.com/tutoriel-malwarebyte-anti-malware/

                                    . sur la page cliques sur Télécharger Malwarebyte's Anti-Malware
                                    . enregistres le sur le bureau
                                    . Double cliques sur le fichier téléchargé pour lancer le processus d'installation.
                                    . si le pare-feu demande l'autorisation de se connecter pour malwarebytes, acceptes
                                    . Il va se mettre à jour une fois faite
                                    . rend-toi dans l'onglet, Recherche
                                    . Sélectionnes Exécuter un examen complet
                                    . Cliques sur Rechercher
                                    . Le scan démarre.
                                    . A la fin de l'analyse, un message s'affiche :
                                    L'examen s'est terminé normalement. Cliquez sur 'Afficher les résultats' pour afficher tous les objets trouvés.
                                    . Cliques sur Ok pour poursuivre.
                                    . Si des malwares ont été détectés, cliques sur Afficher les résultats
                                    . Sélectionnes tout (ou laisses cochés)

                                    . cliques sur Supprimer la sélection

                                    . Malwarebytes va détruire les fichiers et clés de registre et en mettre une copie dans la quarantaine.
                                    . Malwarebytes va ouvrir le bloc-notes et y copier le rapport d'analyse.
                                    . redemarre le pc
                                    . une fois redémarré double-cliques sur malwarebytes
                                    . rends toi dans l'onglet rapport/log
                                    . tu cliques dessus pour l'afficher une fois affiché
                                    . tu cliques sur edition en haut du boc notes,et puis sur sélectionner tous
                                    . tu recliques sur edition et puis sur copier et tu reviens sur le forum et dans ta réponse
                                    . tu cliques droit dans le cadre de la reponse et coller

                                    0
                                    1. Bonjour voila le rapport malwarebytes

                                      Malwarebytes' Anti-Malware 1.37
                                      Version de la base de données: 2227
                                      Windows 5.1.2600 Service Pack 3

                                      04/06/2009 12:58:12
                                      mbam-log-2009-06-04 (12-58-12).txt

                                      Type de recherche: Examen complet (C:\|D:\|E:\|F:\|G:\|H:\|I:\|J:\|)
                                      Eléments examinés: 283397
                                      Temps écoulé: 2 hour(s), 41 minute(s), 5 second(s)

                                      Processus mémoire infecté(s): 0
                                      Module(s) mémoire infecté(s): 0
                                      Clé(s) du Registre infectée(s): 0
                                      Valeur(s) du Registre infectée(s): 0
                                      Elément(s) de données du Registre infecté(s): 0
                                      Dossier(s) infecté(s): 0
                                      Fichier(s) infecté(s): 8

                                      Processus mémoire infecté(s):
                                      (Aucun élément nuisible détecté)

                                      Module(s) mémoire infecté(s):
                                      (Aucun élément nuisible détecté)

                                      Clé(s) du Registre infectée(s):
                                      (Aucun élément nuisible détecté)

                                      Valeur(s) du Registre infectée(s):
                                      (Aucun élément nuisible détecté)

                                      Elément(s) de données du Registre infecté(s):
                                      (Aucun élément nuisible détecté)

                                      Dossier(s) infecté(s):
                                      (Aucun élément nuisible détecté)

                                      Fichier(s) infecté(s):
                                      c:\documents and settings\hp_administrateur.kyky.000\local settings\application data\gsycsgo_navps.dat (Adware.Navipromo.H) -> Quarantined and deleted successfully.
                                      c:\documents and settings\hp_administrateur.kyky.000\local settings\application data\gsycsgo_nav.dat (Adware.Navipromo.H) -> Quarantined and deleted successfully.
                                      c:\documents and settings\hp_administrateur.kyky.000\local settings\application data\gsycsgo.dat (Adware.Navipromo.H) -> Quarantined and deleted successfully.
                                      c:\system volume information\_restore{512df77d-45b5-4ae1-9c2a-ec48b0f584c1}\RP250\A0081266.exe (Rogue.Installer) -> Quarantined and deleted successfully.
                                      c:\system volume information\_restore{512df77d-45b5-4ae1-9c2a-ec48b0f584c1}\RP257\A0087633.exe (Adware.Navipromo) -> Quarantined and deleted successfully.
                                      c:\system volume information\_restore{512df77d-45b5-4ae1-9c2a-ec48b0f584c1}\RP269\A0088125.exe (Adware.Navipromo) -> Quarantined and deleted successfully.
                                      c:\system volume information\_restore{512df77d-45b5-4ae1-9c2a-ec48b0f584c1}\RP269\A0088126.exe (Adware.Navipromo) -> Quarantined and deleted successfully.
                                      c:\system volume information\_restore{512df77d-45b5-4ae1-9c2a-ec48b0f584c1}\RP269\A0088127.exe (Adware.Navipromo) -> Quarantined and deleted successfully.
                                      0
                                      1. Contributeur sécurité
                                        bonjour , au vu de ce que malwarebytes nous a vireé tu me fais un rapport navilog , Merci

                                        Faire un clic droit sur ce lien : http://perso.orange.fr/il.mafioso/Navifix/Navilog1.zip
                                        enregistres le sur le bureau.
                                        Faire un clic droit sur navilog1.zip et choisir "tout extraire"
                                        Double-cliquez sur navilog1.exe
                                        Arriver au menu principal, choisir l'option 1 et valider.
                                        Patientez jusqu'au message : Analyse Termine le ...
                                        Le rapport sera en outre sauvegardé à la racine du disque C:(fixnavi.txt)

                                        avec des images pour l'installation : https://forums.cnetfrance.fr

                                        pour comprendre l'infection : http://www.malekal.com/Adware.Magic_Control.php

                                        0
                                        1. Bonjour, voila le rapport navilog.Merci

                                          Search Navipromo version 3.7.7 commencé le 04/06/2009 à 21:30:34,09

                                          !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
                                          !!! Postez ce rapport sur le forum pour le faire analyser !!!
                                          !!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

                                          Outil exécuté depuis C:\Program Files\navilog1

                                          Mise à jour le 12.05.2009 à 18h00 par IL-MAFIOSO

                                          Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 3
                                          X86-based PC ( Uniprocessor Free : Intel(R) Celeron(R) D CPU 3.20GHz )
                                          BIOS : BIOS Date: 07/26/2006 Ver: 08.00.12
                                          USER : HP_Administrateur ( Administrator )
                                          BOOT : Normal boot

                                          Antivirus : AntiVir Desktop 9.0.1.26 (Activated)
                                          Firewall : ZoneAlarm Firewall 7.0.483.000 (Activated)

                                          C:\ (Local Disk) - NTFS - Total:226 Go (Free:175 Go)
                                          D:\ (Local Disk) - FAT32 - Total:6 Go (Free:6 Go)
                                          E:\ (CD or DVD)
                                          F:\ (Local Disk) - NTFS - Total:465 Go (Free:465 Go)
                                          G:\ (USB)
                                          H:\ (USB)
                                          I:\ (USB)
                                          J:\ (USB)

                                          Recherche executé en mode normal

                                          *** Recherche dossiers dans "C:\WINDOWS" ***

                                          *** Recherche dossiers dans "C:\Program Files" ***

                                          *** Recherche dossiers dans "C:\Documents and Settings\All Users\menudm~1\progra~1" ***

                                          *** Recherche dossiers dans "C:\Documents and Settings\All Users\menudm~1" ***

                                          *** Recherche dossiers dans "c:\docume~1\alluse~1\applic~1" ***

                                          ...\Games-Attack trouvé !

                                          *** Recherche dossiers dans "C:\Documents and Settings\HP_Administrateur.KYKY.000\applic~1" ***

                                          ...\Games-Attack trouvé !

                                          *** Recherche dossiers dans "C:\DOCUME~1\ADMINI~1\applic~1" ***

                                          *** Recherche dossiers dans "C:\DOCUME~1\enfant\applic~1" ***

                                          *** Recherche dossiers dans "C:\Documents and Settings\HP_Administrateur.KYKY.000\locals~1\applic~1" ***

                                          *** Recherche dossiers dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" ***

                                          *** Recherche dossiers dans "C:\DOCUME~1\enfant\locals~1\applic~1" ***

                                          *** Recherche dossiers dans "C:\Documents and Settings\HP_Administrateur.KYKY.000\menudm~1\progra~1" ***

                                          *** Recherche dossiers dans "C:\DOCUME~1\enfant\menudm~1\progra~1" ***

                                          *** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
                                          pour + d'infos : http://www.gmer.net

                                          *** Recherche avec GenericNaviSearch ***
                                          !!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
                                          !!! A vérifier impérativement avant toute suppression manuelle !!!

                                          * Recherche dans "C:\WINDOWS\system32" *

                                          * Recherche dans "C:\Documents and Settings\HP_Administrateur.KYKY.000\locals~1\applic~1" *

                                          * Recherche dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" *

                                          * Recherche dans "C:\DOCUME~1\enfant\locals~1\applic~1" *

                                          *** Recherche fichiers ***

                                          *** Recherche clés spécifiques dans le Registre ***
                                          !! Les clés trouvées ne sont pas forcément infectées !!

                                          *** Module de Recherche complémentaire ***
                                          (Recherche fichiers spécifiques)

                                          1)Recherche nouveaux fichiers Instant Access :

                                          2)Recherche Heuristique :

                                          * Dans "C:\WINDOWS\system32" :

                                          * Dans "C:\Documents and Settings\HP_Administrateur.KYKY.000\locals~1\applic~1" :

                                          * Dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" :

                                          * Dans "C:\DOCUME~1\enfant\locals~1\applic~1" :

                                          3)Recherche Certificats :

                                          Certificat Egroup absent !
                                          Certificat Electronic-Group absent !
                                          Certificat Montorgueil absent !
                                          Certificat OOO-Favorit absent !
                                          Certificat Sunny-Day-Design-Ltd absent !

                                          4)Recherche autres dossiers et fichiers connus :

                                          *** Analyse terminée le 04/06/2009 à 21:54:05,64 ***
                                          0
                                          • 1
                                          • 2