Aide pour supprimer Navipromo svp

Bonjour,

Mon antivirus AVG détecte deux fichiers Navipromo (Navipromo. AA & AF) que je n'arrive pas à supprimer. Des fenêtres intempestives s'ouvrent en permanence dans mon navigateur ...

Quelqu'un peut-il m'aider svp ?

Merci.
Configuration: Windows XP Internet Explorer 7.0

12 réponses

  1. Modérateur
    Bonjour,

    - Télécharge Navilog1 (de IL-MAFIOSO) et enregistre-le sur le Bureau.

    - Double-clique sur Navilog1.exe afin de lancer l'installation.

    - Si le fix ne se lance pas automatiquement après son installation, double-clique sur Navilog1 présent sur le Bureau.
    (Sous Vista, il faut cliquer droit sur le raccourci de Navilog1 et choisir Exécuter en tant qu'administrateur)

    - Appuie sur F ou f puis valide par Entrée.

    - Appuie sur une touche de ton clavier à chaque fois que cela est demandé, tu arriveras au menu des options.

    - Choisis l'option 1 et appuie sur la touche Entrée pour valider ton choix.

    - Patiente jusqu'au message : *** Analyse terminée le ..... ***

    - Le scan fini, le Bloc-notes contenant le rapport sera affiché, poste le contenu de ce rapport dans ta prochaine réponse.

    - Si le résultat du scan ne s'affiche pas, tu le trouveras dans C:\fixnavi.txt

    N'utilise pas l'option 2, 3 et 4 sans notre accord, des fichiers légitimes peuvent être inclus dans ce scan.
    0
    1. Search Navipromo version 3.7.7 commencé le 04/06/2009 à 22:14:13,68

      !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
      !!! Postez ce rapport sur le forum pour le faire analyser !!!
      !!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

      Outil exécuté depuis C:\Program Files\navilog1

      Mise à jour le 12.05.2009 à 18h00 par IL-MAFIOSO

      Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 3
      X86-based PC ( Multiprocessor Free : Mobile Intel(R) Pentium(R) 4 CPU 3.06GHz )
      BIOS : Phoenix ROM BIOS PLUS Version 1.10 A06
      USER : Loïc ( Administrator )
      BOOT : Normal boot

      Antivirus : AVG Anti-Virus Free 8.5 (Activated)

      C:\ (Local Disk) - NTFS - Total:52 Go (Free:2 Go)
      D:\ (CD or DVD) - CDFS - Total:0 Go (Free:0 Go)

      Recherche executé en mode normal

      *** Recherche dossiers dans "C:\WINDOWS" ***

      *** Recherche dossiers dans "C:\Program Files" ***

      *** Recherche dossiers dans "C:\Documents and Settings\All Users\menudm~1\progra~1" ***

      *** Recherche dossiers dans "C:\Documents and Settings\All Users\menudm~1" ***

      *** Recherche dossiers dans "c:\docume~1\alluse~1\applic~1" ***

      *** Recherche dossiers dans "C:\Documents and Settings\Loïc\applic~1" ***

      ...\Live-Player trouvé !

      *** Recherche dossiers dans "C:\DOCUME~1\INVIT~1\applic~1" ***

      *** Recherche dossiers dans "C:\DOCUME~1\LOC~3\applic~1" ***

      *** Recherche dossiers dans "C:\DOCUME~1\PROPRI~1\applic~1" ***

      *** Recherche dossiers dans "C:\Documents and Settings\Loïc\locals~1\applic~1" ***

      *** Recherche dossiers dans "C:\DOCUME~1\INVIT~1\locals~1\applic~1" ***

      *** Recherche dossiers dans "C:\Documents and Settings\Loïc\menudm~1\progra~1" ***

      *** Recherche dossiers dans "C:\DOCUME~1\INVIT~1\menudm~1\progra~1" ***

      *** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
      pour + d'infos : http://www.gmer.net

      *** Recherche avec GenericNaviSearch ***
      !!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
      !!! A vérifier impérativement avant toute suppression manuelle !!!

      * Recherche dans "C:\WINDOWS\system32" *

      * Recherche dans "C:\Documents and Settings\Loïc\locals~1\applic~1" *

      * Recherche dans "C:\DOCUME~1\INVIT~1\locals~1\applic~1" *

      *** Recherche fichiers ***

      *** Recherche clés spécifiques dans le Registre ***
      !! Les clés trouvées ne sont pas forcément infectées !!

      HKEY_CURRENT_USER\Software\mc

      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "mqwwgie"="\"c:\\documents and settings\\lo‹c\\local settings\\application data\\mqwwgie.exe\" mqwwgie"

      *** Module de Recherche complémentaire ***
      (Recherche fichiers spécifiques)

      1)Recherche nouveaux fichiers Instant Access :

      2)Recherche Heuristique :

      * Dans "C:\WINDOWS\system32" :

      * Dans "C:\Documents and Settings\Loïc\locals~1\applic~1" :

      mqwwgie.exe trouvé !
      mqwwgie.dat trouvé !
      mqwwgie_nav.dat trouvé !
      mqwwgie_navps.dat trouvé !

      * Dans "C:\DOCUME~1\INVIT~1\locals~1\applic~1" :

      3)Recherche Certificats :

      Certificat Egroup absent !
      Certificat Electronic-Group absent !
      Certificat Montorgueil absent !
      Certificat OOO-Favorit absent !
      Certificat Sunny-Day-Design-Ltd absent !

      4)Recherche autres dossiers et fichiers connus :

      *** Analyse terminée le 04/06/2009 à 22:29:36,40 ***
      0
      1. Modérateur
        --> Relance Navilog1, fais l'option 2 et poste le rapport (C:\cleannavi.txt).

        Les programmes suivants installent cette infection :
        - Funky Emoticons
        - Games-Attack
        - Go-Astro
        - GoRecord
        - HotTVPlayer
        - Live-Player
        - MailSkinner
        - Messenger Skinner
        - Instant Access
        - InternetGameBox
        - Sudoplanet
        - WebMediaPlayer : sauf celui provenant du site suivant > http://www.azertysite.new.fr/
        0
        1. Clean Navipromo version 3.7.7 commencé le 04/06/2009 à 22:33:46,95

          Outil exécuté depuis C:\Program Files\navilog1

          Mise à jour le 12.05.2009 à 18h00 par IL-MAFIOSO

          Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 3
          X86-based PC ( Multiprocessor Free : Mobile Intel(R) Pentium(R) 4 CPU 3.06GHz )
          BIOS : Phoenix ROM BIOS PLUS Version 1.10 A06
          USER : Loïc ( Administrator )
          BOOT : Normal boot

          Antivirus : AVG Anti-Virus Free 8.5 (Activated)

          C:\ (Local Disk) - NTFS - Total:52 Go (Free:2 Go)
          D:\ (CD or DVD) - CDFS - Total:0 Go (Free:0 Go)

          Mode suppression automatique
          avec prise en charge résultats Catchme et GNS

          Nettoyage exécuté au redémarrage de l'ordinateur

          *** fsbl1.txt non trouvé ***
          (Assurez-vous que Catchme n'avait rien trouvé lors de la recherche)

          *** Suppression avec sauvegardes résultats GenericNaviSearch ***

          * Suppression dans "C:\WINDOWS\System32" *

          * Suppression dans "C:\Documents and Settings\Loïc\locals~1\applic~1" *

          * Suppression dans "C:\DOCUME~1\INVIT~1\locals~1\applic~1" *

          *** Suppression dossiers dans "C:\WINDOWS" ***

          *** Suppression dossiers dans "C:\Program Files" ***

          *** Suppression dossiers dans "C:\Documents and Settings\All Users\menudm~1\progra~1" ***

          *** Suppression dossiers dans "C:\Documents and Settings\All Users\menudm~1" ***

          *** Suppression dossiers dans "c:\docume~1\alluse~1\applic~1" ***

          *** Suppression dossiers dans "C:\Documents and Settings\Loïc\applic~1" ***

          ...\Live-Player ...suppression...
          ...\Live-Player supprimé !

          *** Suppression dossiers dans "C:\DOCUME~1\INVIT~1\applic~1" ***

          *** Suppression dossiers dans "C:\DOCUME~1\LOC~3\applic~1" ***

          *** Suppression dossiers dans "C:\DOCUME~1\PROPRI~1\applic~1" ***

          *** Suppression dossiers dans "C:\Documents and Settings\Loïc\locals~1\applic~1" ***

          *** Suppression dossiers dans "C:\DOCUME~1\INVIT~1\locals~1\applic~1" ***

          *** Suppression dossiers dans "C:\Documents and Settings\Loïc\menudm~1\progra~1" ***

          *** Suppression dossiers dans "C:\DOCUME~1\INVIT~1\menudm~1\progra~1" ***

          *** Suppression fichiers ***

          *** Suppression fichiers temporaires ***

          Nettoyage contenu C:\WINDOWS\Temp effectué !
          Nettoyage contenu C:\Documents and Settings\Lo‹c\locals~1\Temp effectué !

          *** Traitement Recherche complémentaire ***
          (Recherche fichiers spécifiques)

          1)Suppression avec sauvegardes nouveaux fichiers Instant Access :

          2)Recherche, création sauvegardes et suppression Heuristique :

          * Dans "C:\WINDOWS\system32" *

          C:\WINDOWS\prefetch\mqwwgie*.pf trouvé !
          Copie C:\WINDOWS\prefetch\mqwwgie*.pf réalisée avec succès !
          C:\WINDOWS\prefetch\mqwwgie*.pf supprimé !

          * Dans "C:\Documents and Settings\Loïc\locals~1\applic~1" *

          mqwwgie.exe trouvé !
          Copie mqwwgie.exe réalisée avec succès !
          mqwwgie.exe supprimé !

          mqwwgie.dat trouvé !
          Copie mqwwgie.dat réalisée avec succès !
          mqwwgie.dat supprimé !

          mqwwgie_nav.dat trouvé !
          Copie mqwwgie_nav.dat réalisée avec succès !
          mqwwgie_nav.dat supprimé !

          mqwwgie_navps.dat trouvé !
          Copie mqwwgie_navps.dat réalisée avec succès !
          mqwwgie_navps.dat supprimé !

          * Dans "C:\DOCUME~1\INVIT~1\locals~1\applic~1" *

          *** Sauvegarde du Registre vers dossier Safebackup ***

          sauvegarde du Registre réalisée avec succès !

          *** Nettoyage Registre ***

          Nettoyage Registre Ok

          *** Certificats ***

          Certificat Egroup absent !
          Certificat Electronic-Group absent !
          Certificat Montorgueil absent !
          Certificat OOO-Favorit absent !
          Certificat Sunny-Day-Design-Ltdt absent !

          *** Recherche autres dossiers et fichiers connus ***

          *** Nettoyage terminé le 04/06/2009 à 22:48:01,73 ***
          0
          1. Modérateur
            Navipromo est supprimé, désinstalle Navilog1.

            Je vais vérifier qu'il n'y a pas autre chose :

            --> Télécharge Random's System Information Tool (RSIT) (par random/random) sur ton Bureau.

            --> Double-clique sur RSIT.exe afin de lancer le programme.
            (Sous Vista, il faut cliquer droit sur RSIT.exe et choisir Exécuter en tant qu'administrateur)

            --> Clique sur Continue à l'écran Disclaimer.

            --> Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.

            --> Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront. Poste le contenu de log.txt (c'est celui qui apparaît à l'écran) ainsi que de info.txt (que tu verras dans la barre des tâches).

            Note : les rapports sont sauvegardés dans le dossier C:\rsit.
            0
            1. Logfile of random's system information tool 1.06 (written by random/random)
              Run by Loïc at 2009-06-04 22:56:22
              Microsoft Windows XP Édition familiale Service Pack 3
              System drive C: has 3 GB (6%) free of 54 GB
              Total RAM: 511 MB (22% free)

              Logfile of Trend Micro HijackThis v2.0.2
              Scan saved at 22:56:57, on 04/06/2009
              Platform: Windows XP SP3 (WinNT 5.01.2600)
              MSIE: Internet Explorer v7.00 (7.00.6000.16827)
              Boot mode: Normal

              Running processes:
              C:\WINDOWS\System32\smss.exe
              C:\WINDOWS\system32\winlogon.exe
              C:\WINDOWS\system32\services.exe
              C:\WINDOWS\system32\lsass.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\system32\spoolsv.exe
              C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
              C:\WINDOWS\system32\drivers\CDAC11BA.EXE
              C:\WINDOWS\system32\CTsvcCDA.exe
              C:\Program Files\Java\jre6\bin\jqs.exe
              C:\WINDOWS\System32\nvsvc32.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\Explorer.EXE
              C:\WINDOWS\system32\svchost.exe
              C:\PROGRA~1\AVG\AVG8\avgrsx.exe
              C:\PROGRA~1\AVG\AVG8\avgnsx.exe
              C:\WINDOWS\System32\wbem\wmiapsrv.exe
              C:\WINDOWS\notepad.exe
              C:\Program Files\Java\jre6\bin\jusched.exe
              C:\Program Files\Dell\AccessDirect\dadapp.exe
              C:\Program Files\Dell\QuickSet\quickset.exe
              C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
              C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
              C:\WINDOWS\system32\dla\tfswctrl.exe
              C:\Program Files\Dell\Media Experience\PCMService.exe
              C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
              C:\WINDOWS\system32\wuauclt.exe
              C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
              C:\WINDOWS\BCMSMMSG.exe
              C:\WINDOWS\system32\bcmwltry.exe
              C:\Program Files\ZTE Corporation\ZXDSL852\CnxDslTb.exe
              C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
              C:\PROGRA~1\AVG\AVG8\avgtray.exe
              C:\WINDOWS\system32\ctfmon.exe
              C:\Program Files\Messenger\msmsgs.exe
              C:\Program Files\Philips\GoGear ARIA Device Manager\GoGear_Aria_DeviceManager.exe
              C:\Program Files\TRENDnet\TRENDnet TEW-421PC_TEW-423PI\WlanCU.exe
              C:\Program Files\Internet Explorer\iexplore.exe
              C:\WINDOWS\system32\wuauclt.exe
              C:\Documents and Settings\Loïc\Bureau\RSIT.exe
              C:\Program Files\trend micro\Loïc.exe

              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
              R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.dell.com/en-ca
              R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 192.168.21.19:80
              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
              F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe, explorer.exe
              O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
              O2 - BHO: (no name) - {20F4FE52-4A52-E49C-5CC9-CE58839D85D2} - (no file)
              O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
              O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
              O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
              O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
              O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
              O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
              O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
              O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
              O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
              O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
              O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
              O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
              O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
              O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
              O4 - HKLM\..\Run: [DadApp] C:\Program Files\Dell\AccessDirect\dadapp.exe
              O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
              O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
              O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
              O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
              O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe" /r
              O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
              O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
              O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
              O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
              O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
              O4 - HKLM\..\Run: [bcmwltry] bcmwltry.exe
              O4 - HKLM\..\Run: [RemoveCpl] RemoveCpl.exe
              O4 - HKLM\..\Run: [CnxDslTaskBar] "C:\Program Files\ZTE Corporation\ZXDSL852\CnxDslTb.exe" "ZTE Corporation\ZXDSL852"
              O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
              O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
              O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
              O4 - HKLM\..\Run: [Barsaka] explorer.exe
              O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
              O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
              O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
              O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
              O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
              O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
              O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
              O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
              O4 - Global Startup: Philips GoGear ARIA Device Manager.lnk = ?
              O4 - Global Startup: Wireless Configuration Utility .lnk = C:\Program Files\TRENDnet\TRENDnet TEW-421PC_TEW-423PI\WlanCU.exe
              O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
              O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe (file missing)
              O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe (file missing)
              O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
              O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
              O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
              O16 - DPF: {05D96F71-87C6-11D3-9BE4-00902742D6E0} (QuickPlace Class) - http://e.groupe-igs.com/qp2.cab
              O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
              O16 - DPF: {5F0C30E4-1E72-4DCC-85E5-57810F1CA97B} (McUpdatePortalFactory Class) - https://mysupport.nai.com/amiuptodate/bin/1,0,0,7/McUpdatePortal.cab
              O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
              O16 - DPF: {87AF076E-D86D-4E87-ADDD-F05804E1F150} - https://www.virginmega.fr/DownloadManager/Release/Prod/DownMan.cab
              O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab
              O16 - DPF: {B9907873-6560-4A36-B76B-9DADE84A7F55} (FnacmusicDnl.DnlManager) - https://www.fnacmusic.com/telechargementFnacmusic/FnacmusicDnl.CAB
              O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/mcgdmgr/1,0,0,26/mcgdmgr.cab
              O16 - DPF: {D28C3640-A6D7-4668-A53C-07A9CF67D157} (CFnacComposantCtrl Object) - https://www.fnacmusic.com/telechargementFnacmusic/FnacComposant.cab
              O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
              O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
              O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
              O23 - Service: C-DillaCdaC11BA - C-Dilla Ltd - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
              O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
              O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
              O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
              O23 - Service: Macromedia Licensing Service - Macromedia - C:\Program Files\Fichiers communs\Macromedia Shared\Service\Macromedia Licensing.exe
              O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
              O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
              0
              1. info.txt logfile of random's system information tool 1.06 2009-06-04 22:57:00

                ======Uninstall list======

                -->"C:\Program Files\Creative Installation Information\CREATIVE_MEDIASOURCE_U\Setup.exe" /remove /l0x040c
                -->"C:\Program Files\Creative Installation Information\E-CENTER_NET_CONTENT_U\Setup.exe" /remove /l0x040c
                -->"C:\Program Files\Creative Installation Information\E-CENTER_PLUGIN_CDBURNER_U\Setup.exe" /remove /l0x040c
                -->"C:\Program Files\Creative Installation Information\E-CENTER_PLUGIN_MTP_U\Setup.exe" /remove /l0x040c
                -->"C:\Program Files\Creative Installation Information\MEDIASOURCE_PLAYER_SKINPACK_U\Setup.exe" /remove /l0x040c
                -->C:\Program Files\Fichiers communs\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
                -->C:\WINDOWS\IsUn040c.exe -fC:\WINDOWS\orun32.isu
                -->C:\WINDOWS\System32\\MSIEXEC.EXE /I {09DA4F91-2A09-4232-AB8C-6BC740096DE3} REMOVE=UpdateMgrFeature
                -->C:\WINDOWS\System32\\MSIEXEC.EXE /x {1206EF92-2E83-4859-ACCB-2048C3CB7DA6}
                -->C:\WINDOWS\System32\\MSIEXEC.EXE /x {9541FED0-327F-4df0-8B96-EF57EF622F19}
                -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{19822917-61F6-4221-B1D0-1C3B8A06BE60}\setup.exe" -l0x40c
                -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{19822917-61F6-4221-B1D0-1C3B8A06BE60}\setup.exe" -l0x40c /remove
                -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{57FA4E0F-82C9-417D-87BC-0186D6CB7A44}\setup.exe" -l0x40c
                -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{63A317D0-60A6-43FC-848A-9FE4A53B29CE}\setup.exe" -l0x40c
                -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{700932B3-A964-4878-82A2-96054622A1F7}\setup.exe" -l0x40c
                -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{700932B3-A964-4878-82A2-96054622A1F7}\setup.exe" -l0x40c /remove
                -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7C9F6AF4-E9D9-47FE-BE4B-E637C2FCB410}\setup.exe" -l0x40c
                -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7C9F6AF4-E9D9-47FE-BE4B-E637C2FCB410}\setup.exe" -l0x40c /remove
                -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{98181885-5B28-4280-9B56-452FF877D5B9}\setup.exe" -l0x40c
                -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{98181885-5B28-4280-9B56-452FF877D5B9}\setup.exe" -l0x40c /remove
                -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9A0B5225-B59B-4D72-B3FE-71AAA693A8E2}\setup.exe" -l0x40c
                -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9A0B5225-B59B-4D72-B3FE-71AAA693A8E2}\setup.exe" -l0x40c /remove
                -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A9BB081B-C020-4D02-A763-D32204D2563D}\setup.exe" -l0x40c
                -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A9BB081B-C020-4D02-A763-D32204D2563D}\setup.exe" -l0x40c /remove
                -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C029DB0E-C59F-417A-90F8-88FD5B2C4AE7}\setup.exe" -l0x40c
                -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
                AccessDirect-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{417B79C9-CDB4-477F-952D-840CEFC57A6C}\setup.exe" -l0x40c
                Adobe Acrobat - Reader 6.0.2 Update-->MsiExec.exe /I{AC76BA86-0000-0000-0000-6028747ADE01}
                Adobe Flash Player 10 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
                Adobe Flash Player Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
                Adobe Photoshop 7.0.1-->C:\WINDOWS\ISUN040C.EXE -f"C:\Program Files\Adobe\Photoshop 7.0\Uninst.isu" -c"C:\Program Files\Adobe\Photoshop 7.0\Uninst.dll"
                Adobe Reader 6.0.1 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A00000000001}
                ALZip-->"C:\Program Files\ESTsoft\ALZip\unins000.exe"
                Archiveur WinRAR-->C:\Program Files\WinRAR\uninstall.exe
                Assistant de connexion Windows Live-->MsiExec.exe /I{D3116CC7-24DC-4CA3-9CE1-23FED836E9F2}
                AudibleManager-->C:\Program Files\Audible\Bin\Upgrade.exe /Uninstall
                AVG Free 8.5-->C:\Program Files\AVG\AVG8\setup.exe /UNINSTALL
                BCM V.92 56K Modem-->C:\WINDOWS\BCMSMU.exe quiet
                Belkin Wireless Setup Utility-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{A0BBC906-9A33-4C79-A26A-758ED3503769} /l1036 REMOVEREMOVE
                Broadcom Management Programs-->C:\Program Files\Fichiers communs\InstallShield\Driver\8\Intel 32\IDriver.exe /M{2A6282FF-B75B-463F-90F5-0A43732F690D} /l1036
                CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
                Cda Product Service - shared component-->C:\WINDOWS\CdaC13BA.EXE /uninstall
                Ciel e-Commerce-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A7A09545-60C7-11D5-AFA8-00C04F8EC576}\install.exe" UNINSTALL
                Correctif pour Lecteur Windows Media 11 (KB939683)-->"C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
                Correctif pour Windows Internet Explorer 7 (KB947864)-->"C:\WINDOWS\ie7updates\KB947864-IE7\spuninst\spuninst.exe"
                Creative MediaSource 5-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BEEFC4F8-2909-48B3-AFAA-55D3533FDEDD}\SETUP.EXE" -l0x40c /remove
                Creative System Information-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{63A317D0-60A6-43FC-848A-9FE4A53B29CE}\setup.exe" -l0x40c /remove
                Creative ZEN V Series (R2)-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9862E0CB-4727-4FFC-963A-E22A9E9EC10C}\SETUP.EXE" -l0x40c /remove
                Dell Media Experience-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2637C347-9DAD-11D6-9EA2-00055D0CA761}\setup.exe" -uninstall
                Dell Solution Center-->MsiExec.exe /X{11F1920A-56A2-4642-B6E0-3B31A12C9288}
                Digidesign Shared Plug-Ins-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{DBCD674C-1751-4548-9005-980F03083187}\Setup.exe" -l0x9 FromUninstall
                DivX Player-->C:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYER
                DivX Web Player-->C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
                DivX-->C:\Program Files\DivX\DivXCodecUninstall.exe /CODEC
                eMule-->"C:\Program Files\eMule\Uninstall.exe"
                Fnacmusic - Gestionnaire de téléchargement-->MsiExec.exe /I{E0238B8A-F886-4F1E-B3FD-B946E74AC117}
                Gestionnaire de disques amovible Creative-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{57FA4E0F-82C9-417D-87BC-0186D6CB7A44}\setup.exe" -l0x40c /remove
                GoGear ARIA Device Manager-->C:\Program Files\InstallShield Installation Information\{43B0D334-9A1B-4257-9E51-D3813BD8B9D0}\setup.exe -runfromtemp -l0x040c -removeonly
                Guitar Pro 4.0-->C:\PROGRA~1\GUITAR~2\UNWISE.EXE C:\PROGRA~1\GUITAR~2\INSTALL.LOG
                HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
                HomePlayer 1.5.6b-->C:\Program Files\HomePlayer\uninst.exe
                Hotfix for Windows Media Format 11 SDK (KB929399)-->"C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
                HP Image Zone 4.2-->C:\Program Files\HP\Digital Imaging\uninstall\hpzscr01.exe -datfile hpqscr01.dat
                HP PSC & OfficeJet 4.2-->"C:\Program Files\HP\Digital Imaging\{A1062847-0846-427A-92A1-BB8251A91E91}\setup\hpzscr01.exe" -datfile hposcr04.dat
                HP Software Update-->MsiExec.exe /X{15EE79F4-4ED1-4267-9B0F-351009325D7D}
                Jasc Paint Shop Photo Album-->MsiExec.exe /I{CC000127-5E5D-4A1C-90CB-EEAAAC1E3AC0}
                Jasc Paint Shop Pro 8-->MsiExec.exe /I{81A34902-9D0B-4920-A25C-4CDC5D14B328}
                Java 2 Runtime Environment, SE v1.4.2_03-->MsiExec.exe /I{7148F0A8-6813-11D6-A77B-00B0D0142030}
                Java(TM) 6 Update 13-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216013FF}
                Lecteur Windows Media 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
                Macromedia Extension Manager-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A5BA14E0-7384-11D4-BAE7-00409631A2C8}\setup.exe" -l0x40c mmUninstall
                Macromedia Flash MX 2004-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2F353D44-73BB-4971-B31D-F7642E9E9531}\Setup.exe" -l0x40c UNINSTALL
                Macromedia Shockwave Player-->C:\WINDOWS\SYSTEM32\Macromed\SHOCKW~1\UNWISE.EXE C:\WINDOWS\SYSTEM32\Macromed\SHOCKW~1\Install.log
                Microsoft .NET Framework 1.1 French Language Pack-->MsiExec.exe /X{9A394342-4A68-4EBA-85A6-55B559F4E700}
                Microsoft .NET Framework 1.1 Hotfix (KB928366)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"
                Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
                Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
                Microsoft .NET Framework 2.0-->C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.exe
                Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
                Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
                Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
                Microsoft Office PowerPoint 2003 Template Pack 1-->MsiExec.exe /I{90AB040C-6000-11D3-8CFE-0150048383C9}
                Microsoft Office PowerPoint 2003 Template Pack 2-->MsiExec.exe /I{90AC040C-6000-11D3-8CFE-0150048383C9}
                Microsoft Office PowerPoint 2003 Template Pack 3-->MsiExec.exe /I{90AD040C-6000-11D3-8CFE-0150048383C9}
                Microsoft Office XP Professional avec FrontPage-->MsiExec.exe /I{9028040C-6000-11D3-8CFE-0050048383C9}
                Microsoft Office XP Professional-->MsiExec.exe /I{9011040C-6000-11D3-8CFE-0050048383C9}
                Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
                Microsoft User-Mode Driver Framework Feature Pack 1.0-->"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
                Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
                Microsoft Works 7.0-->MsiExec.exe /I{64D114CE-4234-45C2-B60A-2B07D5A48F72}
                Mise à jour critique pour Lecteur Windows Media 11 (KB959772)-->"C:\WINDOWS\$NtUninstallKB959772_WM11$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Lecteur Windows Media 11 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Lecteur Windows Media 11 (KB954154)-->"C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows Internet Explorer 7 (KB931768)-->"C:\WINDOWS\ie7updates\KB931768-IE7\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows Internet Explorer 7 (KB937143)-->"C:\WINDOWS\ie7updates\KB937143-IE7\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows Internet Explorer 7 (KB938127)-->"C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows Internet Explorer 7 (KB942615)-->"C:\WINDOWS\ie7updates\KB942615-IE7\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows Internet Explorer 7 (KB944533)-->"C:\WINDOWS\ie7updates\KB944533-IE7\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows Internet Explorer 7 (KB950759)-->"C:\WINDOWS\ie7updates\KB950759-IE7\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows Internet Explorer 7 (KB953838)-->"C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows Internet Explorer 7 (KB956390)-->"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows Internet Explorer 7 (KB958215)-->"C:\WINDOWS\ie7updates\KB958215-IE7\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows Internet Explorer 7 (KB960714)-->"C:\WINDOWS\ie7updates\KB960714-IE7\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows Internet Explorer 7 (KB961260)-->"C:\WINDOWS\ie7updates\KB961260-IE7\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows Internet Explorer 7 (KB963027)-->"C:\WINDOWS\ie7updates\KB963027-IE7\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
                Modem Helper-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7F142D56-3326-11D5-B229-002078017FBF}\setup.exe" -l0x40c ControlPanel
                Mozilla Firefox (1.0.6)-->C:\WINDOWS\UninstallFirefox.exe /ua "1.0.6 (fr-FR)"
                MSXML 4.0 SP2 (KB927978)-->MsiExec.exe /I{37477865-A3F1-4772-AD43-AAFC6BCFF99F}
                MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
                MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
                NVIDIA Drivers-->C:\WINDOWS\System32\nvudisp.exe UninstallGUI
                overland-->MsiExec.exe /I{766273C1-A39B-47EB-ACE8-DEBDD8094BCC}
                PACE System Files-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{28F58CDE-6241-4B11-8232-6A5D4FB06E8B}\Setup.exe" -l0x9 FromUninstall
                PowerDVD 5.1-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}\setup.exe" -uninstall
                QuickSet-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C5074CC4-0E26-4716-A307-960272A90040}\setup.exe" -l0x40c UNINSTALL
                QuickTime-->MsiExec.exe /I{8DC42D05-680B-41B0-8878-6C14D24602DB}
                RealPlayer-->C:\Program Files\Fichiers communs\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
                Security Update for CAPICOM (KB931906)-->MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
                Security Update for CAPICOM (KB931906)-->MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
                Sonic DLA-->MsiExec.exe /I{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}
                Sonic RecordNow!-->MsiExec.exe /I{9541FED0-327F-4DF0-8B96-EF57EF622F19}
                Sonic Update Manager-->MsiExec.exe /I{09DA4F91-2A09-4232-AB8C-6BC740096DE3}
                Spybot - Search & Destroy 1.4-->"C:\Program Files\Spybot - Search & Destroy\unins000.exe"
                Synaptics Pointing Device Driver-->rundll32.exe "C:\Program Files\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall
                TRENDnet TEW-421PC/TEW-423PI 802.11g Wireless Cardbus/PCI Adapter Driver and Utility-->C:\Program Files\InstallShield Installation Information\{F266A90C-3F4A-4F65-9901-3DBBB0D77D80}\setup.exe -runfromtemp -l0x0409
                VC80CRTRedist - 8.0.50727.762-->MsiExec.exe /I{767CC44C-9BBC-438D-BAD3-FD4595DD148B}
                Vuze-->C:\Program Files\Vuze\uninstall.exe
                Windows Live installer-->MsiExec.exe /X{FD44E544-E7D0-4DBA-9FA0-8AE1A1300390}
                Windows Live Messenger-->MsiExec.exe /X{BADF6744-3787-48F6-B8C9-4C4995401D65}
                Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
                Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
                Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
                Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
                Winkaa 1.0 1.0-->"C:\Program Files\Winkaa 1.0\uninstall.exe"
                WinZip-->"C:\Program Files\WinZip\WINZIP32.EXE" /uninstall
                ZENcast Organizer-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C029DB0E-C59F-417A-90F8-88FD5B2C4AE7}\setup.exe" -l0x40c /remove
                ZTE ZXDSL852-->"C:\Program Files\ZTE Corporation\ZXDSL852\setup.exe" -u

                Hosts File Missing
                ======Security center information======

                AV: AVG Anti-Virus Free

                ======System event log======

                Computer Name: LOIC
                Event Code: 4201
                Message: Le système a détecté que la carte réseau \DEVICE\TCPIP_{2D1E548E-AC84-4622-94AF-A8FBFDB27D7A} était connectée au réseau,
                et a lancé une opération normale sur la carte réseau.

                Record Number: 64682
                Source Name: Tcpip
                Time Written: 20090429192620.000000+060
                Event Type: Informations
                User:

                Computer Name: LOIC
                Event Code: 6005
                Message: Le service d'Enregistrement d'événement a démarré.

                Record Number: 64681
                Source Name: EventLog
                Time Written: 20090429192605.000000+060
                Event Type: Informations
                User:

                Computer Name: LOIC
                Event Code: 6009
                Message: Microsoft (R) Windows (R) 5.01. 2600 Service Pack 3 Multiprocessor Free.

                Record Number: 64680
                Source Name: EventLog
                Time Written: 20090429192605.000000+060
                Event Type: Informations
                User:

                Computer Name: LOIC
                Event Code: 6006
                Message: Le service d'Enregistrement d'événement a été arrêté.

                Record Number: 64679
                Source Name: EventLog
                Time Written: 20090429082259.000000+060
                Event Type: Informations
                User:

                Computer Name: LOIC
                Event Code: 7036
                Message: Le service Gestionnaire de connexions d'accès distant est entré dans l'état : en cours d'exécution.

                Record Number: 64678
                Source Name: Service Control Manager
                Time Written: 20090429081953.000000+060
                Event Type: Informations
                User:

                =====Application event log=====

                Computer Name: LOIC
                Event Code: 102
                Message: msnmsgr (3132) \\.\C:\Documents and Settings\Loïc\Local Settings\Application Data\Microsoft\Messenger\chokan95@hotmail.com\SharingMetadata\Working\database_5898_67CD_9867_A7E8\dfsr.db: Le moteur de base de données a démarré une nouvelle instance (0).

                Record Number: 5
                Source Name: ESENT
                Time Written: 20090502165616.000000+060
                Event Type: Informations
                User:

                Computer Name: LOIC
                Event Code: 100
                Message: msnmsgr (3132) Le moteur de base de données 5.01.2600.5512 est démarré.

                Record Number: 4
                Source Name: ESENT
                Time Written: 20090502165616.000000+060
                Event Type: Informations
                User:

                Computer Name: LOIC
                Event Code: 12001
                Message: The Messenger Sharing USN Journal Reader service started successfully.

                Record Number: 3
                Source Name: usnjsvc
                Time Written: 20090502165614.000000+060
                Event Type:
                User:

                Computer Name: LOIC
                Event Code: 1800
                Message: Le service Centre de sécurité Windows a démarré.

                Record Number: 2
                Source Name: SecurityCenter
                Time Written: 20090502165524.000000+060
                Event Type: Informations
                User:

                Computer Name: LOIC
                Event Code: 105
                Message: The service was started.

                Record Number: 1
                Source Name: Creative Service for CDROM Access
                Time Written: 20090502165515.000000+060
                Event Type: Informations
                User:

                ======Environment variables======

                "ComSpec"=%SystemRoot%\system32\cmd.exe
                "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\ESTsoft\ALZip\;C:\Program Files\QuickTime\QTSystem\
                "windir"=%SystemRoot%
                "OS"=Windows_NT
                "PROCESSOR_ARCHITECTURE"=x86
                "PROCESSOR_LEVEL"=15
                "PROCESSOR_IDENTIFIER"=x86 Family 15 Model 4 Stepping 1, GenuineIntel
                "PROCESSOR_REVISION"=0401
                "NUMBER_OF_PROCESSORS"=2
                "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
                "TEMP"=%SystemRoot%\TEMP
                "TMP"=%SystemRoot%\TEMP
                "FP_NO_HOST_CHECK"=NO
                "CLASSPATH"=.;C:\Program Files\Java\j2re1.4.2_03\lib\ext\QTJava.zip
                "QTJAVA"=C:\Program Files\Java\j2re1.4.2_03\lib\ext\QTJava.zip

                -----------------EOF-----------------
                0
                1. Modérateur
                  Tu as d'autres infections.

                  Je m'absente 30 minutes.

                  --> Télécharge UsbFix (de C_XX & Chiquitine29) sur ton Bureau.

                  --> Lance l'installation avec les paramètres par défaut.

                  --> Branche tes sources de données externes à ton PC (clé USB, disque dur externe, carte SD, etc...) sans les ouvrir.

                  --> Double-clique sur le raccourci UsbFix sur ton Bureau.

                  --> Choisis l'option 1 (Recherche).

                  --> Laisse travailler l'outil.

                  --> Poste le rapport UsbFix.txt.

                  Note : le rapport UsbFix.txt est sauvegardé à la racine du disque (C:\UsbFix.txt).

                  "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool. Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
                  0
                  1. ############################## [ UsbFix V3.028 | Scan ]

                    # User : Loïc (Administrateurs) # LOIC
                    # Update on 02/06/09 by Chiquitine29, C_XX & Chimay8
                    # WebSite : http://pagesperso-orange.fr/NosTools/usbfix.html
                    # Start at: 23:06:25 | 04/06/2009

                    # Mobile Intel(R) Pentium(R) 4 CPU 3.06GHz
                    # Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
                    # Internet Explorer 7.0.5730.11
                    # Windows Firewall Status : Enabled
                    # AV : AVG Anti-Virus Free 8.5 [ Enabled | Updated ]

                    # C:\ # Disque fixe local # 52,32 Go (2,96 Go free) [Disque dur] # NTFS
                    # D:\ # Disque CD-ROM # 189,31 Mo (0 Mo free) [Aria_02] # CDFS
                    # F:\ # Disque amovible # 979,7 Mo (431,62 Mo free) # FAT

                    ############################## [ Processus actifs ]

                    C:\WINDOWS\System32\smss.exe
                    C:\WINDOWS\system32\csrss.exe
                    C:\WINDOWS\system32\winlogon.exe
                    C:\WINDOWS\system32\services.exe
                    C:\WINDOWS\system32\lsass.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\WINDOWS\system32\spoolsv.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
                    C:\WINDOWS\system32\drivers\CDAC11BA.EXE
                    C:\WINDOWS\system32\CTsvcCDA.exe
                    C:\Program Files\Java\jre6\bin\jqs.exe
                    C:\WINDOWS\System32\nvsvc32.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\WINDOWS\Explorer.EXE
                    C:\WINDOWS\system32\svchost.exe
                    C:\PROGRA~1\AVG\AVG8\avgrsx.exe
                    C:\PROGRA~1\AVG\AVG8\avgnsx.exe
                    C:\WINDOWS\System32\alg.exe
                    C:\WINDOWS\System32\wbem\wmiapsrv.exe
                    C:\WINDOWS\notepad.exe
                    C:\Program Files\Java\jre6\bin\jusched.exe
                    C:\Program Files\Dell\AccessDirect\dadapp.exe
                    C:\Program Files\Dell\QuickSet\quickset.exe
                    C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
                    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                    C:\WINDOWS\system32\dla\tfswctrl.exe
                    C:\Program Files\Dell\Media Experience\PCMService.exe
                    C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
                    C:\WINDOWS\system32\wuauclt.exe
                    C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                    C:\WINDOWS\BCMSMMSG.exe
                    C:\WINDOWS\system32\bcmwltry.exe
                    C:\Program Files\ZTE Corporation\ZXDSL852\CnxDslTb.exe
                    C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                    C:\PROGRA~1\AVG\AVG8\avgtray.exe
                    C:\WINDOWS\system32\ctfmon.exe
                    C:\Program Files\Messenger\msmsgs.exe
                    C:\Program Files\Philips\GoGear ARIA Device Manager\GoGear_Aria_DeviceManager.exe
                    C:\Program Files\TRENDnet\TRENDnet TEW-421PC_TEW-423PI\WlanCU.exe
                    C:\Program Files\Internet Explorer\iexplore.exe
                    C:\WINDOWS\system32\NOTEPAD.EXE
                    C:\WINDOWS\system32\NOTEPAD.EXE
                    C:\WINDOWS\System32\wudfhost.exe
                    C:\WINDOWS\system32\wbem\wmiprvse.exe

                    ################## [ Registre Startup ]

                    HKCU_Main: "Local Page"="C:\\WINDOWS\\system32\\blank.htm"
                    HKCU_Main: "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
                    HKCU_Main: "Start Page"="https://www.google.fr/?gws_rd=ssl"
                    HKLM_logon: "Userinit"="C:\\WINDOWS\\system32\\userinit.exe, explorer.exe"
                    HKLM_logon: "DefaultUserName"="Lo‹c"
                    HKLM_logon: "AltDefaultUserName"="Lo‹c"
                    HKLM_logon: "LegalNoticeCaption"=""
                    HKLM_logon: "LegalNoticeText"=""
                    HKLM_Run: NvCplDaemon=RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
                    HKLM_Run: nwiz=nwiz.exe /installquiet
                    HKLM_Run: SunJavaUpdateSched="C:\Program Files\Java\jre6\bin\jusched.exe"
                    HKLM_Run: DadApp=C:\Program Files\Dell\AccessDirect\dadapp.exe
                    HKLM_Run: Dell QuickSet=C:\Program Files\Dell\QuickSet\quickset.exe
                    HKLM_Run: SynTPLpr=C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
                    HKLM_Run: SynTPEnh=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                    HKLM_Run: dla=C:\WINDOWS\system32\dla\tfswctrl.exe
                    HKLM_Run: UpdateManager="C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe" /r
                    HKLM_Run: PCMService="C:\Program Files\Dell\Media Experience\PCMService.exe"
                    HKLM_Run: DVDLauncher="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
                    HKLM_Run: HP Component Manager="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
                    HKLM_Run: HP Software Update=C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                    HKLM_Run: BCMSMMSG=BCMSMMSG.exe
                    HKLM_Run: bcmwltry=bcmwltry.exe
                    HKLM_Run: RemoveCpl=RemoveCpl.exe
                    HKLM_Run: CnxDslTaskBar="C:\Program Files\ZTE Corporation\ZXDSL852\CnxDslTb.exe" "ZTE Corporation\ZXDSL852"
                    HKLM_Run: QuickTime Task="C:\Program Files\QuickTime\qttask.exe" -atboottime
                    HKLM_Run: TkBellExe="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                    HKLM_Run: AVG8_TRAY=C:\PROGRA~1\AVG\AVG8\avgtray.exe
                    HKLM_Run: Barsaka=explorer.exe
                    HKLM_Run: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents=
                    HKCU_Run: CTFMON.EXE=C:\WINDOWS\system32\ctfmon.exe
                    HKCU_Run: MSMSGS="C:\Program Files\Messenger\msmsgs.exe" /background

                    ################## [ Fichiers # Dossiers infectieux ]

                    Found ! "C:\Documents and Settings\Lo‹c\RavMonLog"
                    Found ! C:\recycler\S-1-5-21-1724196937-1499937697-1016389991-1006\Dc2\autorun\Autorun.exe
                    Found ! D:\Installer.exe
                    Found ! D:\autorun.inf

                    ################## [ Registre # Clés Run infectieuses ]

                    ################## [ Registre # Mountpoints2 ]

                    HKCU\...\Explorer\MountPoints2\{75ad70a4-9374-11dc-9398-a51328e9875f}\Shell\AutoRun\Command
                    HKCU\...\Explorer\MountPoints2\{75ad70a4-9374-11dc-9398-a51328e9875f}\Shell\explore\Command
                    HKCU\...\Explorer\MountPoints2\{75ad70a4-9374-11dc-9398-a51328e9875f}\Shell\open\Command

                    ################## [ ! Fin du rapport # UsbFix V3.028 ! ]
                    0
                    1. Modérateur
                      --> Branche tes sources de données externes à ton PC (clé USB, disque dur externe, carte SD, etc...) sans les ouvrir.

                      --> Double-clique sur le raccourci UsbFix présent sur ton Bureau.

                      --> Choisis l'option 2 (Suppression).

                      --> Ton Bureau disparaîtra et le PC redémarrera.

                      --> Au redémarrage, UsbFix scannera ton PC, laisse travailler l'outil.

                      --> Ensuite, poste le rapport UsbFix.txt qui apparaîtra avec le Bureau .

                      Note : le rapport UsbFix.txt est sauvegardé à la racine du disque (C:\UsbFix.txt).
                      0
                      1. ############################## [ UsbFix V3.028 | Cleaning ]

                        # User : Loïc (Administrateurs) # LOIC
                        # Update on 02/06/09 by Chiquitine29, C_XX & Chimay8
                        # WebSite : http://pagesperso-orange.fr/NosTools/usbfix.html
                        # Start at: 23:27:52 | 04/06/2009

                        # Mobile Intel(R) Pentium(R) 4 CPU 3.06GHz
                        # Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
                        # Internet Explorer 7.0.5730.11
                        # Windows Firewall Status : Enabled
                        # AV : AVG Anti-Virus Free 8.5 [ Enabled | Updated ]

                        # C:\ # Disque fixe local # 52,32 Go (2,96 Go free) [Disque dur] # NTFS
                        # D:\ # Disque CD-ROM

                        ############################## [ Processus actifs ]

                        C:\WINDOWS\System32\smss.exe
                        C:\WINDOWS\system32\csrss.exe
                        C:\WINDOWS\system32\winlogon.exe
                        C:\WINDOWS\system32\services.exe
                        C:\WINDOWS\system32\lsass.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\WINDOWS\system32\spoolsv.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
                        C:\WINDOWS\system32\drivers\CDAC11BA.EXE
                        C:\WINDOWS\system32\CTsvcCDA.exe
                        C:\Program Files\Java\jre6\bin\jqs.exe
                        C:\WINDOWS\System32\nvsvc32.exe
                        C:\WINDOWS\system32\userinit.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\Explorer.EXE
                        C:\PROGRA~1\AVG\AVG8\avgrsx.exe
                        C:\PROGRA~1\AVG\AVG8\avgnsx.exe
                        C:\WINDOWS\System32\alg.exe
                        C:\WINDOWS\system32\wbem\wmiprvse.exe
                        C:\WINDOWS\System32\wbem\wmiapsrv.exe
                        C:\WINDOWS\system32\wbem\wmiprvse.exe

                        ################## [ Fichiers # Dossiers infectieux ]

                        Deleted ! "C:\Documents and Settings\Lo‹c\RavMonLog"
                        Deleted ! C:\recycler\S-1-5-21-1724196937-1499937697-1016389991-1006\Dc2\autorun\Autorun.exe

                        ################## [ Registre # Clés Run infectieuses ]

                        ################## [ Registre # Mountpoints2 ]

                        Deleted ! HKCU\...\Explorer\MountPoints2\{75ad70a4-9374-11dc-9398-a51328e9875f}\Shell\AutoRun\Command

                        ################## [ Listing des fichiers présent ]

                        [17/11/2008 19:52|--a------|622] - C:\autoAlbum.log
                        [18/09/2002 12:35|--a------|0] - C:\AUTOEXEC.BAT
                        [28/11/2004 22:42|-rahs----|216] - C:\BOOT.INI
                        [30/08/2002 08:00|-rahs----|4952] - C:\Bootfont.bin
                        [18/09/2002 12:18|--ahs----|512] - C:\BOOTSECT.DOS
                        [04/06/2009 22:48|--a------|3763] - C:\cleannavi.txt
                        [18/09/2002 12:35|--a------|0] - C:\CONFIG.SYS
                        [11/11/2004 16:38|-rah-----|4692] - C:\DELL.SDR
                        [04/06/2009 22:29|--a------|3410] - C:\fixnavi.txt
                        [04/06/2009 23:27|--a------|20] - C:\GINA.TEXT
                        [18/09/2002 12:35|--ah-----|0] - C:\IO.SYS
                        [11/11/2004 17:05|--ah-----|820] - C:\IPH.PH
                        [18/09/2002 12:35|--ah-----|0] - C:\MSDOS.SYS
                        [28/11/2004 22:32|-rahs----|47564] - C:\NTDETECT.COM
                        [14/06/2008 09:53|-rahs----|252240] - C:\NTLDR
                        [?|?|?] - C:\pagefile.sys
                        [11/03/2007 13:00|--ahs----|14336] - C:\Thumbs.db
                        [24/05/2001 13:59|--a------|162304] - C:\UNWISE.EXE
                        [04/06/2009 23:28|--a------|2974] - C:\UsbFix.txt
                        [04/06/2009 23:27|--a------|41] - C:\WLANCUGINA.TEXT

                        ################## [ Vaccination ]

                        # C:\autorun.inf ( # Not infected ) -> Folder created by UsbFix.

                        ################## [ ! Fin du rapport # UsbFix V3.028 ! ]
                        0
                        1. Modérateur
                          ---> Désinstalle UsbFix.

                          ---> Télécharge Malwarebytes' Anti-Malware (MBAM) sur ton Bureau.
                          ---> Double-clique sur le fichier téléchargé pour lancer le processus d'installation.
                          ---> Dans l'onglet Mise à jour, clique sur le bouton Recherche de mise à jour : si le pare-feu demande l'autorisation à MBAM de se connecter à Internet, accepte.
                          ---> Une fois la mise à jour terminée, rends-toi dans l'onglet Recherche.
                          ---> Sélectionne Exécuter un examen rapide.
                          ---> Clique sur Rechercher. L'analyse démarre.

                          A la fin de l'analyse, un message s'affiche :

                          L'examen s'est terminé normalement. Cliquez sur 'Afficher les résultats' pour afficher tous les objets trouvés.

                          ---> Clique sur OK pour poursuivre. Si MBAM n'a rien trouvé, il te le dira aussi.
                          ---> Ferme tes navigateurs.
                          Si des malwares ont été détectés, clique sur Afficher les résultats.
                          ---> Sélectionne tout (ou laisse coché) et clique sur Supprimer la sélection, MBAM va détruire les fichiers et clés de registre infectés et en mettre une copie dans la quarantaine.
                          ---> MBAM va ouvrir le Bloc-notes et y copier le rapport d'analyse. Copie-colle ce rapport dans ta prochaine réponse.
                          0