PC qui plante

Résolu
Bonjour,
Bonjour à tous!
Depuis peu, mon pc plante régulièrement...Tout se bloque et je dois redémarrer l' UC. De plus, je trouve qu'il rame de plus en plus...Quelqu'un peut il me dire si mon PC est sain?
Je suis sous XP, j'ai avast et jetico qui sont à jour.Les antivirus en ligne, comme avast ne trouvent rien.
Mes connaissances dans ce domaine étant très limitées...je m'en remet à une âme charitable qui voudra bien m' aider. Merci d'avance.
GP
Configuration: Windows XP
Safari 525.19

44 réponses

Résumé de la discussion

Le plantage fréquent et le ralentissement sous Windows XP posent une problématique de santé du PC, avec blocages nécessitant un redémarrage et un ralentissement persistant malgré des antivirus à jour. Des pistes évoluent vers le remplacement d'antivirus et d'antimalware, puis l'utilisation d'outils comme ComboFix et une analyse RSIT ou HijackThis pour diagnostiquer les malwares. En cas de résultats mitigés, des approches complémentaires s'envisagent, notamment la consultation de rapports détaillés et l'implémentation progressive des outils recommandés. Enfin, des éléments comme des services ou pilotes obsolètes et des démarrages automatiques intrusifs peuvent influencer significativement les performances et nécessiter une désactivation ciblée ou une suppression sélective.

Bobot (l’IA à votre service)
  1. Vu les conseils précieux que tu m'as donné jusqu'ici, je vais suivre tes recommandations et changer antivirus et antimalware...
    Je vais lire également entierement les liens que tu me présentes (peut etre pas tout d'un coup!!!)
    Bonne continuation
    Encore merci
    gp01
    1. Contributeur sécurité
      de rien

      a+

      Ps : lorsque tu changeras tes défenses , tu vires d'abors Spybot , puis Avast ... un coup de CCleaner ... tu installes en premier le nouvel AV (AntiVir ) puis SpywareTerminator ....

  2. Contributeur sécurité
    Salut,

    edit :
    je vois que tu est un habituer du forum .... parano non ? .... ^^

    on va regarder cela :

    1- Télécharge et installe le logiciel HijackThis :

    ici http://www.commentcamarche.net/telecharger/telecharger 159 hijackthis
    ou ici http://www.trendsecure.com/portal/en-US/_download/HJTInstall.exe
    ou ici https://www.clubic.com/telecharger-fiche17891-hijackthis.html

    -->Clique sur le setup pour lancer l'installe : laisse toi guider et ne modifie pas les paramètres d'installation .
    A la fin de l'installe , le prg se lance automatiquement : ferme le en cliquant sur la croix rouge .
    Au final, tu dois avoir un raccourci sur ton bureau et aussi un cheminement comme :
    "C:\ program files\Trend Micro\HijackThis\HijackThis.exe " .

    ( ne lance pas ce prg pour l'instant et fais la suite ... )

    2- Télécharge Random's System Information Tool (RSIT) de random/random et enregistre l'exécutable sur ton Bureau.

    -> http://images.malwareremoval.com/random/RSIT.exe

    ! Déconnecte toi et ferme toutes tes applications en cours !

    Double-clique sur " RSIT.exe " pour le lancer .

    -> Une première fenêtre s'ouvre avec en titre : " Disclaimer of warranty " .

    * Devant l'option "List files/folders created ..." , tu choisis : 2 months

    * clique ensuite sur " Continue " pour lancer l'analyse ...

    -> laisse faire le scan et ne touche pas au PC ...

    Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront (probablement avec le bloc-note).

    Poste le contenu de " log.txt " (c'est celui qui apparait à l'écran), ainsi que de " info.txt " (que tu verras dans la barre des tâches), pour analyse et attends la suite ...

    Important : poste un rapport, puis l'autre dans la réponse suivante ...
    Si tu essaies de poster les deux en même temps, cela risque d'être trop long pour le forum ...
    ( Et si "log.txt" seul, ne passe pas non plus , fais le en 2 fois ... merci ... )

    ( Note : les rapports seront en outre sauvegardés dans ce dossier -> C:\rsit )

    1. Salut et merci de prendre un moment pour me dépanner.
      Parano un peu, mais surtout embêter par ces plantages...
      voici le premier rapport (log)Logfile of random's system information tool 1.06 (written by random/random)
      Run by gil at 2009-06-10 17:10:31
      Microsoft Windows XP Édition familiale Service Pack 3
      System drive C: has 25 GB (35%) free of 73 GB
      Total RAM: 1022 MB (59% free)

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 17:10:48, on 10/06/2009
      Platform: Windows XP SP3 (WinNT 5.01.2600)
      MSIE: Internet Explorer v8.00 (8.00.6001.18702)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\Ati2evxx.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      C:\Program Files\Alwil Software\Avast4\ashServ.exe
      C:\WINDOWS\system32\Ati2evxx.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\system32\LEXBCES.EXE
      C:\WINDOWS\system32\spoolsv.exe
      C:\WINDOWS\system32\LEXPPS.EXE
      C:\Program Files\Google\Update\GoogleUpdate.exe
      C:\Program Files\Verdiem\Edison\edsvc.exe
      C:\WINDOWS\System32\FTRTSVC.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Java\jre6\bin\jqs.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      C:\Program Files\Analog Devices\Core\smax4pnp.exe
      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
      C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
      C:\WINDOWS\system32\dla\tfswctrl.exe
      C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      C:\Program Files\Jetico\Jetico Personal Firewall\fwsrv.exe
      C:\WINDOWS\VM305_STI.EXE
      C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Windows Media Player\WMPNSCFG.exe
      C:\WINDOWS\system32\NOTEPAD.EXE
      C:\Documents and Settings\gil\Bureau\RSIT.exe
      C:\Program Files\Trend Micro\HijackThis\gil.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Orange
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
      O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
      O2 - BHO: dsWebAllowBHO Class - {2F85D76C-0569-466F-A488-493E6BD0E955} - C:\Program Files\Windows Desktop Search\dsWebAllow.dll
      O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
      O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
      O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: BHO Barre de Confiance CM-CIC - {988B07F5-7392-455A-8A1F-64935CB8B6ED} - C:\Program Files\BarreConfCMCIC\TAPBar.dll
      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
      O2 - BHO: PDFCreator Toolbar Helper - {C451C08A-EC37-45DF-AAAD-18B51AB5E837} - C:\Program Files\PDFCreator Toolbar\v3.3.0.1\PDFCreator_Toolbar.dll
      O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
      O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
      O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
      O3 - Toolbar: Barre de confiance CM-CIC - {55BDF3B0-C0A8-481A-B8A6-01CD2BE0F3FD} - C:\Program Files\BarreConfCMCIC\TAPBar.dll
      O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
      O3 - Toolbar: PDFCreator Toolbar - {31CF9EBE-5755-4A1D-AC25-2834D952D9B4} - C:\Program Files\PDFCreator Toolbar\v3.3.0.1\PDFCreator_Toolbar.dll
      O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
      O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
      O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
      O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
      O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe" /r
      O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
      O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      O4 - HKLM\..\Run: [JeticoPFStartup] "C:\Program Files\Jetico\Jetico Personal Firewall\fwsrv.exe"
      O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\\PSDrvCheck.exe
      O4 - HKLM\..\Run: [BigDog305] C:\WINDOWS\VM305_STI.EXE VIMICRO USB PC Camera (ZC0305)
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
      O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
      O4 - HKCU\..\Run: [EPSON Stylus DX4400 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICAE.EXE /FU "C:\DOCUME~1\gil\LOCALS~1\Temp\E_S1C3.tmp" /EF "HKCU"
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
      O4 - HKUS\S-1-5-18\..\Run: [Nokia.PCSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [Nokia.PCSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'Default user')
      O8 - Extra context menu item: &ICQ Toolbar Search - res://C:\Program Files\ICQToolbar\toolbaru.dll/SEARCH.HTML
      O8 - Extra context menu item: &MSN Search - res://C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1105\fr-fr\msntb.dll/search.htm
      O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
      O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
      O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0000.1105\fr-fr\msntabres.dll/229?b3e1df636c6a408fb85f84ade9356ed8
      O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0000.1105\fr-fr\msntabres.dll/230?b3e1df636c6a408fb85f84ade9356ed8
      O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - https://support.euro.dell.com/systemprofiler/SysPro.CAB
      O16 - DPF: {029FDBA6-3547-11D7-AA4C-0050BF051A00} (Rawflow ICD Client) - http://s.tf1.fr/mmdia/static/rawflow/clients/5.3.1.0/Rawflow.cab
      O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
      O16 - DPF: {1F83CD9E-505E-4F87-BECE-0832A763E36F} (Image Uploader 3.0 Control) - http://www.mypixmania.com/fr/fr/importer/MypixUploader.cab
      O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
      O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
      O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
      O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://www.mypix.com/fr/fr/importer/ImageUploader4.cab
      O16 - DPF: {952F9A71-131A-11D5-8404-00500445A7D0} (ActiveMiniplug Class) - https://intranet.unss.org/plugins/mplugax.cab
      O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab
      O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
      O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
      O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\SYSTEM32\ati2sgag.exe
      O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
      O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      O23 - Service: Edison Power Management Service (edsvc) - Verdiem - C:\Program Files\Verdiem\Edison\edsvc.exe
      O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
      O23 - Service: Google Update Service (gupdate1c98c69280a00ee) (gupdate1c98c69280a00ee) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
      O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
      O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
      O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
      O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe
      1. et la suite: infoinfo.txt logfile of random's system information tool 1.06 2009-06-10 17:10:51

        ======Uninstall list======

        -->C:\Program Files\DivX\ConverterUninstall.exe /CONVERTER
        -->C:\Program Files\Fichiers communs\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
        -->C:\Program Files\Nero\Nero 7\nero\uninstall\UNNERO.exe /UNINSTALL
        -->C:\WINDOWS\IsUn040c.exe -fC:\WINDOWS\orun32.isu
        -->C:\WINDOWS\system32\\MSIEXEC.EXE /I {09DA4F91-2A09-4232-AB8C-6BC740096DE3} REMOVE=UpdateMgrFeature
        -->C:\WINDOWS\system32\\MSIEXEC.EXE /x {1206EF92-2E83-4859-ACCB-2048C3CB7DA6}
        -->C:\WINDOWS\system32\\MSIEXEC.EXE /x {9541FED0-327F-4df0-8B96-EF57EF622F19}
        -->C:\WINDOWS\UNNeroBackItUp.exe /UNINSTALL
        -->C:\WINDOWS\UNNeroMediaHome.exe /UNINSTALL
        -->C:\WINDOWS\UNNeroShowTime.exe /UNINSTALL
        -->C:\WINDOWS\UNNeroVision.exe /UNINSTALL
        -->C:\WINDOWS\UNRecode.exe /UNINSTALL
        -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
        2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0015-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
        2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0016-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
        2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0018-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
        2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0019-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
        2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001A-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
        2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001B-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7}
        2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0401-0000-0000000FF1CE} /uninstall {5A2F65A4-808F-4A1E-973E-92E17824982D}
        2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0407-0000-0000000FF1CE} /uninstall {2AB528A5-BB1B-4EBE-8E51-AD0C4CD33CA9}
        2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {3EC77D26-799B-4CD8-914F-C1565E796173}
        2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-040C-0000-0000000FF1CE} /uninstall {430971B1-C31E-45DA-81E0-72C095BAB72C}
        2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0413-0000-0000000FF1CE} /uninstall {B3F4DC34-7F60-4B7C-A79F-1C13012D99D4}
        2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0C0A-0000-0000000FF1CE} /uninstall {F7A31780-33C4-4E39-951A-5EC9B91D7BF1}
        2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {91120000-0014-0000-0000-0000000FF1CE} /uninstall {BEE75E01-DD3F-4D5F-B96C-609E6538D419}
        AC3Filter (remove only)-->C:\Program Files\AC3Filter\uninstall.exe
        Ad-Aware SE Personal-->C:\PROGRA~1\Lavasoft\AD-AWA~1\UNWISE.EXE C:\PROGRA~1\Lavasoft\AD-AWA~1\INSTALL.LOG
        Adobe Flash Player 10 Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
        Adobe Flash Player 9 ActiveX-->MsiExec.exe /X{8186E1B9-DDC6-45B6-B9EB-C28947CBC4CF}
        Adobe Flash Player ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
        Adobe Reader 8.1.5 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A81300000003}
        Adobe Shockwave Player-->C:\WINDOWS\SYSTEM32\Adobe\SHOCKW~1\UNWISE.EXE C:\WINDOWS\SYSTEM32\Adobe\SHOCKW~1\Install.log
        Adobe® Photoshop® Album Edition Découverte 3.2-->MsiExec.exe /I{A654A805-41D9-40C7-AA46-4AF04F044D61}
        Archiveur WinRAR-->C:\Program Files\WinRAR\uninstall.exe
        ArcSoft PhotoBase 3-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{40FD99B4-63C3-49EE-A3BE-5D87762F3F2D}\Setup.exe" -l0x40c -uninst
        ATI - Software Uninstall Utility-->C:\Program Files\ATI Technologies\UninstallAll\AtiCimUn.exe
        ATI Control Panel-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{0BEDBD4E-2D34-47B5-9973-57E62B29307C}\setup.exe"
        ATI Display Driver-->rundll32 C:\WINDOWS\system32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
        Audacity 1.2.6-->"C:\Program Files\Audacity\unins000.exe"
        avast! Antivirus-->C:\Program Files\Alwil Software\Avast4\aswRunDll.exe "C:\Program Files\Alwil Software\Avast4\Setup\setiface.dll",RunSetup
        AVIcodec (remove only)-->"C:\Program Files\AVIcodec\uninst.exe"
        Barre de confiance CM-CIC-->"C:\Program Files\BarreConfCMCIC\Setup.exe" -u
        Barre d'outils Outlook de Windows Live (Windows Live Toolbar)-->MsiExec.exe /X{6E15BEDF-7EB5-4010-998E-B430DB4EFE45}
        Bloqueur de fenêtres pop-up (Windows Live Toolbar)-->MsiExec.exe /X{A425C250-A0E1-4D78-B1C1-A5CBC7385E7C}
        Broadcom Management Programs-->C:\Program Files\Fichiers communs\InstallShield\Driver\8\Intel 32\IDriver.exe /M{2A6282FF-B75B-463F-90F5-0A43732F690D} /l1036
        Caere Scan Manager 5.0-->MsiExec.exe /I{81D62C32-0984-11D3-86CD-00105AD33021}
        Camera RAW Plug-In for EPSON Creativity Suite-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{8DAC1AE4-33D1-4A78-8A42-00E09EDECC3E}\SETUP.EXE" -l0x40c UNINST
        Canon Camera Support Core Library-->C:\Program Files\Fichiers communs\InstallShield\Driver\8\Intel 32\IDriver.exe /M{91F1A0D6-23AD-49FE-8D4E-379485652214} /l1036
        Canon Camera Window DS for ZoomBrowser EX-->C:\Program Files\Fichiers communs\InstallShield\Driver\8\Intel 32\IDriver.exe /M{91203BD3-6C3E-472F-ADBD-F60FDC7C4010}
        Canon Camera Window DVC for ZoomBrowser EX-->C:\Program Files\Fichiers communs\InstallShield\Driver\8\Intel 32\IDriver.exe /M{4C96958A-6562-4143-B820-FF4890D3B734}
        Canon Camera Window for ZoomBrowser EX-->C:\Program Files\Fichiers communs\InstallShield\Driver\8\Intel 32\IDriver.exe /M{C7281207-4AA4-425E-B57A-0E9EF8445635}
        Canon Internet Library for ZoomBrowser EX-->C:\Program Files\Fichiers communs\InstallShield\Driver\8\Intel 32\IDriver.exe /M{2F81FBFC-9A37-431F-9050-14B55485DF5A}
        Canon MovieEdit Task for ZoomBrowser EX-->C:\Program Files\Fichiers communs\InstallShield\Driver\8\Intel 32\IDriver.exe /M{8AF1E098-1A5C-4336-BBE2-D047ABB401ED}
        Canon PhotoRecord-->MsiExec.exe /X{0878E100-C0BB-41E8-B4C6-C486B61FDA7B}
        Canon RAW Image Task for ZoomBrowser EX-->C:\Program Files\Fichiers communs\InstallShield\Driver\8\Intel 32\IDriver.exe /M{45EF4EE3-F591-4B74-A477-0CAE12934CE7}
        Canon RemoteCapture Task for ZoomBrowser EX-->C:\Program Files\Fichiers communs\InstallShield\Driver\8\Intel 32\IDriver.exe /M{28291BD5-92D2-4685-82DC-CCA925C53CCA}
        Canon Utilities PhotoStitch 3.1-->C:\Program Files\Fichiers communs\InstallShield\Driver\8\Intel 32\IDriver.exe /M{218BBBE3-FE63-4BB2-81A8-7435575A84FA}
        Canon ZoomBrowser EX-->MsiExec.exe /X{C1D76D7A-F3BB-47EA-A746-5B1E2FFC1DF2}
        CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
        CDex extraction audio-->"C:\Program Files\CDex_170b2\uninstall.exe"
        Compatibility Pack for the 2007 Office system-->MsiExec.exe /X{90120000-0020-040C-0000-0000000FF1CE}
        Complément Microsoft Word pour Microsoft Works Suite-->MsiExec.exe /I{17E57E89-DDB3-4f76-9AF1-A8E01CC633E4}
        CoreVorbis Audio Decoder (remove only)-->"C:\WINDOWS\system32\CoreVorbis-uninstall.exe"
        Correctif pour Windows Internet Explorer 7 (KB947864)-->"C:\WINDOWS\ie7updates\KB947864-IE7\spuninst\spuninst.exe"
        CX4300_5500_DX4400 Manuel-->C:\Program Files\EPSON\TPMANUAL\CX4300_5500_DX4400\FRA\USE_G\DOCUNINS.EXE
        Dell Driver Reset Tool-->MsiExec.exe /I{5905F42D-3F5F-4916-ADA6-94A3646AEE76}
        Dell Media Experience Update-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{CDE4CC8B-134B-421E-943C-90799E56F664}\setup.exe" -l0x40c -L0x40c /SMAINT
        Dell Media Experience-->MsiExec.exe /I{AC0EE5B0-A8FB-4D0A-AF03-2EDC518F841B}
        Dell Photo Printer 720-->C:\WINDOWS\system32\spool\drivers\w32x86\3\DLBCUN5C.EXE -dDell Photo Printer 720
        Dell ResourceCD-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D78653C3-A8FF-415F-92E6-D774E634FF2D}\setup.exe"
        Dell Support 3.1-->MsiExec.exe /X{548EEA8E-8299-497F-8057-811D2D7097DC}
        Détecteur de flux Windows Live Toolbar (Windows Live Toolbar)-->MsiExec.exe /X{EFFCB0F1-CFEC-48D4-B793-EBFCAE852976}
        Direct Show Ogg Vorbis Filter (remove only)-->"C:\WINDOWS\system32\OggDSuninst.exe"
        DiscAPI (Studio 10)-->MsiExec.exe /X{A77F3C2D-50CC-4A29-A1FB-1E018BE4DCA2}
        DivX Content Uploader-->C:\Program Files\DivX\DivXContentUploaderUninstall.exe /CUPLOADER
        DivX Converter-->C:\Program Files\DivX\ConverterUninstall.exe /CONVERTER
        DivX Player-->C:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYER
        DivX Web Player-->C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
        DivX-->C:\Program Files\DivX\DivXCodecUninstall.exe /CODEC
        DVD de bonus Studio 10-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6A012D9C-2E2E-405A-B87C-E909F5297C3F}\Setup.exe" -l0x40c UNINSTALL
        DVD Decrypter (Remove Only)-->"C:\Program Files\DVD Decrypter\uninstall.exe"
        EA SPORTS online 2005-->C:\Program Files\EA SPORTS\EA SPORTS online\EASOUNInstaller.exe
        EasyCleaner-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F5346614-B7C4-4E94-826A-E2363155233D}\setup.exe" -l0x9 -removeonly
        Edison-->MsiExec.exe /X{9542A589-9E34-4D25-BBED-E4AFA039AF56}
        EPSON Attach To Email-->C:\Program Files\Fichiers communs\InstallShield\Driver\8\Intel 32\IDriver.exe /M{20C45B32-5AB6-46A4-94EF-58950CAF05E5} /l1033 ADDREMOVEDLG
        EPSON Copy Utility 3-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{67EDD823-135A-4D59-87BD-950616D6E857}\SETUP.EXE" -l0x40c -UnInstall
        EPSON Easy Photo Print-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B66E665A-DF96-4C38-9422-C7F74BC1B4E5}\SETUP.EXE" -l0x40c UNINST
        EPSON File Manager-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2EB81825-E9EE-44F4-8F51-1240C3898DC6}\Setup.exe" -l0x40c UNINST
        EPSON Logiciel imprimante-->C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\EPUPDATE.EXE /R
        EPSON Scan Assistant-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2A88F1BF-7041-4E42-84B1-6B4ACB83AC64}\Setup.exe" -l0x40c -u
        EPSON Scan-->C:\Program Files\epson\escndv\setup\setup.exe /r
        EPSON Web-To-Page-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7F14F68C-17FA-4F88-B3FD-7F449C1EBF32}\SETUP.EXE" -l0x40c -anything
        EVEREST Home Edition v2.20-->"C:\Program Files\Lavalys\EVEREST Home Edition\unins000.exe"
        Extension de Windows Live Toolbar (Windows Live Toolbar)-->MsiExec.exe /X{0CA6047C-D28B-4295-834A-07C52BA20C2D}
        Extension HighMAT pour l'Assistant Graver un CD de Microsoft Windows XP-->MsiExec.exe /X{FCE65C4E-B0E8-4FBD-AD16-EDCBE6CD591F}
        FAST Defrag Freeware 2.3-->"C:\Program Files\FDF\unins000.exe"
        ffdshow (remove only)-->"C:\Program Files\ffdshow\uninstall.exe"
        FIFA 2005-->C:\Program Files\EA SPORTS\FIFA 2005\EAUninstall.exe
        FileZilla Client 3.1.6-->C:\Program Files\FileZilla FTP Client\uninstall.exe
        FoxTarot version 4.1.7-->"C:\Program Files\FoxTarot4\unins000.exe"
        Gestionnaire Internet-->C:\PROGRA~1\Wanadoo\uninstall.exe
        GIMP 2.6.4-->"C:\Program Files\GIMP-2.0\setup\unins000.exe"
        Google Chrome-->"C:\Program Files\Google\Chrome\Application\1.0.154.65\Installer\setup.exe" --uninstall --system-level
        Google Update Helper-->MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
        Google Earth-->MsiExec.exe /X{CC016F21-3970-11DE-B878-005056806466}
        HijackThis 2.0.2-->"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
        INDEX EDUCATION - Client PRONOTE 2008-->C:\Program Files\InstallShield Installation Information\{CC5D63D4-BE70-432F-A9C8-2106B7AA72F0}\setup.exe -runfromtemp -l0x040c -uninst -removeonly
        INDEX EDUCATION - ProfNOTE 2008-->C:\Program Files\InstallShield Installation Information\{5DD31E03-4843-4352-9F8B-919430E80C98}\setup.exe -runfromtemp -l0x040c -uninst -removeonly
        Intel(R) 537EP V9x DF PCI Modem-->rundll32 IntelCci.dll,iSMUninstallation "Intel(R) 537EP V9x DF PCI Modem"
        IrfanView (remove only)-->C:\Program Files\IrfanView\iv_uninstall.exe
        IsoBuster 1.8-->"C:\Program Files\Smart Projects\IsoBuster\Uninst\unins000.exe"
        J2SE Runtime Environment 5.0 Update 10-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150100}
        J2SE Runtime Environment 5.0 Update 11-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150110}
        J2SE Runtime Environment 5.0 Update 2-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150020}
        J2SE Runtime Environment 5.0 Update 5-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150050}
        J2SE Runtime Environment 5.0 Update 6-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150060}
        J2SE Runtime Environment 5.0 Update 9-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150090}
        Jack Keane-->"C:\Program Files\10TACLE STUDIOS\Jack Keane\uninstall.exe"
        Jalbum 8.0-->C:\Program Files\JalbumWin\Uninstall.exe
        Java 2 Runtime Environment, SE v1.4.2_03-->MsiExec.exe /I{7148F0A8-6813-11D6-A77B-00B0D0142030}
        Java 2 Runtime Environment, SE v1.4.2_06-->MsiExec.exe /I{7148F0A8-6813-11D6-A77B-00B0D0142060}
        Java(TM) 6 Update 11-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216011FF}
        Java(TM) 6 Update 2-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160020}
        Java(TM) 6 Update 3-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160030}
        Java(TM) 6 Update 5-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160050}
        Java(TM) 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
        Java(TM) SE Runtime Environment 6 Update 1-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160010}
        Jetico Personal Firewall 1.0-->"C:\WINDOWS\BCUnInstall.exe" C:\Program Files\Jetico\Jetico Personal Firewall\UnInstall.log
        Kelly Slater's Pro Surfer(tm)-->MsiExec.exe /X{72B18B03-D495-4714-870B-F9BE680C43BD}
        Learn2 Player (Uninstall Only)-->C:\Program Files\Learn2.com\StRunner\stuninst.exe
        Lecteur Windows Media 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
        LeechFTP -->C:\WINDOWS\eraser.exe KILL "C:\Program Files\LeechFTP\uninstall.uif"
        Macromedia Flash Player 8-->RunDll32 advpack.dll,LaunchINFSection C:\WINDOWS\INF\swflash.inf,DefaultUninstall,5
        MailNavigator v.1.11-->"C:\Program Files\MailNavigator\uninstall.exe"
        Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
        Menus intelligents (Windows Live Toolbar)-->MsiExec.exe /X{0CC70FEF-5068-4CD5-B4DE-86FFD98EC929}
        Microsoft .NET Framework 1.1 French Language Pack-->MsiExec.exe /X{9A394342-4A68-4EBA-85A6-55B559F4E700}
        Microsoft .NET Framework 1.1 Hotfix (KB928366)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"
        Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
        Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
        Microsoft .NET Framework 2.0 Service Pack 1-->MsiExec.exe /I{B508B3F1-A24A-32C0-B310-85786919EF28}
        Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
        Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
        Microsoft Money-->c:\program files\microsoft money 2005\MNYCoreFiles\Setup\uninst.exe /s:120
        Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
        Microsoft Office Access MUI (French) 2007-->MsiExec.exe /X{90120000-0015-040C-0000-0000000FF1CE}
        Microsoft Office Excel MUI (French) 2007-->MsiExec.exe /X{90120000-0016-040C-0000-0000000FF1CE}
        Microsoft Office Language Pack 2007 Service Pack 1 (SP1)-->msiexec /package {90120000-006E-040C-0000-0000000FF1CE} /uninstall {EC50B538-CBE1-42E6-B7FE-87AA540AADFB}
        Microsoft Office Outlook MUI (French) 2007-->MsiExec.exe /X{90120000-001A-040C-0000-0000000FF1CE}
        Microsoft Office PowerPoint MUI (French) 2007-->MsiExec.exe /X{90120000-0018-040C-0000-0000000FF1CE}
        Microsoft Office Professional 2007-->"C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall PROR /dll OSETUP.DLL
        Microsoft Office Professional 2007-->MsiExec.exe /X{91120000-0014-0000-0000-0000000FF1CE}
        Microsoft Office Proof (Arabic) 2007-->MsiExec.exe /X{90120000-001F-0401-0000-0000000FF1CE}
        Microsoft Office Proof (Dutch) 2007-->MsiExec.exe /X{90120000-001F-0413-0000-0000000FF1CE}
        Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
        Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
        Microsoft Office Proof (German) 2007-->MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}
        Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
        Microsoft Office Proofing (French) 2007-->MsiExec.exe /X{90120000-002C-040C-0000-0000000FF1CE}
        Microsoft Office Publisher MUI (French) 2007-->MsiExec.exe /X{90120000-0019-040C-0000-0000000FF1CE}
        Microsoft Office Shared MUI (French) 2007-->MsiExec.exe /X{90120000-006E-040C-0000-0000000FF1CE}
        Microsoft Office Word MUI (French) 2007-->MsiExec.exe /X{90120000-001B-040C-0000-0000000FF1CE}
        Microsoft Silverlight-->MsiExec.exe /I{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
        Microsoft User-Mode Driver Framework Feature Pack 1.5-->"C:\WINDOWS\$NtUninstallWudf01005$\spuninst\spuninst.exe"
        Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
        Microsoft Windows Media Video 9 VCM-->RunDll32 advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmv9vcm.inf, Uninstall
        Microsoft Works-->MsiExec.exe /I{A059DE09-1B49-4450-B340-7AE097EC3F04}
        MIKSOFT Mobile 3GP converter-->"C:\Program Files\MIKSOFT\Mobile 3GP converter\unins000.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB928090)-->"C:\WINDOWS\ie7updates\KB928090-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB929969)-->"C:\WINDOWS\ie7updates\KB929969\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB931768)-->"C:\WINDOWS\ie7updates\KB931768-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB933566)-->"C:\WINDOWS\ie7updates\KB933566-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB937143)-->"C:\WINDOWS\ie7updates\KB937143-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB938127)-->"C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB939653)-->"C:\WINDOWS\ie7updates\KB939653-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB942615)-->"C:\WINDOWS\ie7updates\KB942615-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB944533)-->"C:\WINDOWS\ie7updates\KB944533-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB950759)-->"C:\WINDOWS\ie7updates\KB950759-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB953838)-->"C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB956390)-->"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB958215)-->"C:\WINDOWS\ie7updates\KB958215-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB960714)-->"C:\WINDOWS\ie7updates\KB960714-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB961260)-->"C:\WINDOWS\ie7updates\KB961260-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB963027)-->"C:\WINDOWS\ie7updates\KB963027-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 8 (KB969897)-->"C:\WINDOWS\ie8updates\KB969897-IE8\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB923561)-->"C:\WINDOWS\$NtUninstallKB923561$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB952004)-->"C:\WINDOWS\$NtUninstallKB952004$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB956572)-->"C:\WINDOWS\$NtUninstallKB956572$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB959426)-->"C:\WINDOWS\$NtUninstallKB959426$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB960803)-->"C:\WINDOWS\$NtUninstallKB960803$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB961373)-->"C:\WINDOWS\$NtUninstallKB961373$\spuninst\spuninst.exe"
        Mise à jour pour Windows Internet Explorer 8 (KB971180)-->"C:\WINDOWS\ie8updates\KB971180-IE8\spuninst\spuninst.exe"
        Modem Event Monitor-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7A0EFAFB-AC4B-4B88-8C6B-6731BE88DB68}\setup.exe" -l0x40c
        Modem Helper-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7F142D56-3326-11D5-B229-002078017FBF}\setup.exe" -l0x40c ControlPanel
        Modem On Hold-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3F92ABBB-6BBF-11D5-B229-002078017FBF}\setup.exe" -l0x40c ControlPanelAnyText
        Module de prise en charge linguistique de Microsoft .NET Framework 2.0 - FRA-->C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0 Language Pack - FRA\install.exe
        Morgan Stream Switcher-->"C:\Program Files\Morgan\mmswitch\uninst.exe"
        Mozilla Firefox (3.0.10)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
        MSVC80_x86-->MsiExec.exe /I{212748BB-0DA5-46DE-82A1-403736DC9F27}
        MSXML 4.0 SP2 (KB927978)-->MsiExec.exe /I{37477865-A3F1-4772-AD43-AAFC6BCFF99F}
        MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
        MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
        Navigateur Orange-->C:\PROGRA~1\Wanadoo\Shell.exe inst\uninst_FTBrowser.shl
        Nero 7 Demo-->MsiExec.exe /I{C67B64FA-E69E-E061-6516-F8E911671036}
        Nokia Connectivity Cable Driver-->MsiExec.exe /X{15AC0C5D-A6FB-4CE2-8CD0-28179EEB5625}
        Nokia PC Suite-->C:\Documents and Settings\All Users\Application Data\Installations\{58FB2F9A-5F2D-40E8-82DF-4987E60AD8BD}\Nokia_PC_Suite_7_1_18_0_fre.exe
        Nokia PC Suite-->MsiExec.exe /I{58FB2F9A-5F2D-40E8-82DF-4987E60AD8BD}
        Nokia Software Updater-->MsiExec.exe /X{3186AEAE-E104-424D-9152-1BF6A4404758}
        Nvu 1.0-->"C:\Program Files\Nvu\unins000.exe"
        OneCare Advisor (Windows Live Toolbar)-->MsiExec.exe /X{6D7F8D4B-D1A4-402A-973E-31E90940E585}
        Outil de mise à jour Google-->"C:\Program Files\Google\Google Updater\GoogleUpdater.exe" -uninstall
        Outlook Express Backup Wizard version 1.1-->"C:\Program Files\Outlook Express Backup Wizard\unins000.exe"
        Package de base Microsoft de service de chiffrement pour cartes à puce-->"C:\WINDOWS\$NtUninstallbasecsp$\spuninst\spuninst.exe"
        Package de pilotes Windows - Nokia Modem (02/15/2007 3.1)-->C:\PROGRA~1\DIFX\270581355A767BF1\dpinst.exe /u C:\WINDOWS\system32\DRVSTORE\pccs_bluet_F12A08B6F776984A95553486F64C541356F86E38\pccs_bluetooth.inf
        Package de pilotes Windows - Nokia Modem (05/24/2007 6.84.0.1)-->C:\PROGRA~1\DIFX\270581355A767BF1\dpinst.exe /u C:\WINDOWS\system32\DRVSTORE\nokbtmdm_5E1541AFF1E1EA3554CE566743CCAD323ED1C108\nokbtmdm.inf
        Package de pilotes Windows - Nokia Modem (08/03/2007 6.84.0.2)-->C:\PROGRA~1\DIFX\270581355A767BF1\dpinst.exe /u C:\WINDOWS\system32\DRVSTORE\nokbtmdm_1EB5F2E6F54A6BEDE9F436D1BA5D830FC71739BE\nokbtmdm.inf
        Package de pilotes Windows - Nokia Modem (08/08/2007 3.3)-->C:\PROGRA~1\DIFX\270581355A767BF1\dpinst.exe /u C:\WINDOWS\system32\DRVSTORE\pccs_bluet_32E2E448B53EE5B28E074D88802D0BAF984038DA\pccs_bluetooth.inf
        Package de pilotes Windows - Nokia Modem (10/27/2008 3.9)-->C:\PROGRA~1\DIFX\270581355A767BF1\dpinst.exe /u C:\WINDOWS\system32\DRVSTORE\nokia_blue_79486EC6AA0D1732FB17E5167077C07ECAE1B870\nokia_bluetooth.inf
        Package de pilotes Windows - Nokia Modem (10/27/2008 7.01.0.1)-->C:\PROGRA~1\DIFX\270581355A767BF1\dpinst.exe /u C:\WINDOWS\system32\DRVSTORE\nokbtmdm_247189AEBF39EB69A7C75429610DFED2F2EDC1B6\nokbtmdm.inf
        Package de pilotes Windows - Nokia Modem (11/03/2006 6.82.0.1)-->C:\PROGRA~1\DIFX\270581355A767BF1\dpinst.exe /u C:\WINDOWS\system32\DRVSTORE\nokbtmdm_4EFFAAE27A08EDFDE145390033D8EF099DA65567\nokbtmdm.inf
        Package de pilotes Windows - Nokia pccsmcfd (08/22/2008 7.0.0.0)-->C:\PROGRA~1\DIFX\270581355A767BF1\dpinst.exe /u C:\WINDOWS\system32\DRVSTORE\pccsmcfd_A3B3916E5D8138F59EE218321B27B044D3B18294\pccsmcfd.inf
        PC Connectivity Solution-->MsiExec.exe /I{D848D140-41C3-4A53-86D8-E866A100B4CD}
        PCFriendly-->C:\Program Files\PCFriendly\inuninst.exe
        PDFCreator Toolbar-->"C:\WINDOWS\PDFCreator_Toolbar_Uninstaller_5625.exe" _?=C:\Program Files\PDFCreator Toolbar
        PDFCreator-->C:\Program Files\PDFCreator\unins000.exe
        PhotoFiltre Studio-->"C:\Program Files\PhotoFiltre Studio\Uninst.exe"
        PhotoFiltre-->"C:\Program Files\PhotoFiltre\Uninst.exe"
        PIXresizer 1.0.9-->"C:\Program Files\PIXresizer\unins000.exe"
        Polar ProTrainer-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{DF7DBA84-0A55-11D6-A0A6-6A7573736972}\setup.exe" -l0x40c
        PowerDVD-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}\Setup.exe" -uninstall
        proDAD Heroglyph 2.5-->"C:\Program Files\proDAD\Heroglyph-2.5\uninstall.exe" uninstall spcp PATHVERSION 2.5 MAINNAME Heroglyph
        Quicksys RegDefrag 2.3-->"C:\Program Files\Quicksys\RegDefrag\unins000.exe"
        QuickTime Alternative 1.48-->"C:\Program Files\QuickTime Alternative\unins000.exe"
        QuickTime-->C:\WINDOWS\unvise32qt.exe C:\WINDOWS\system32\QuickTime\Uninstall.log
        RAPID (Studio 10)-->MsiExec.exe /X{EEECE229-49F6-4851-A73A-99B058221F8C}
        RealPlayer-->C:\Program Files\Fichiers communs\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
        Scrabble® 2003 Edition-->C:\PROGRA~1\UBISOF~1\SCRABB~1\UNWISE.EXE C:\PROGRA~1\UBISOF~1\SCRABB~1\INSTALL.LOG
        Security Update for 2007 Microsoft Office System (KB951550)-->msiexec /package {91120000-0014-0000-0000-0000000FF1CE} /uninstall {B243E9A5-ED77-4F1B-B338-2486FD82DC85}
        Security Update for 2007 Microsoft Office System (KB951944)-->msiexec /package {91120000-0014-0000-0000-0000000FF1CE} /uninstall {797AE457-BA17-4BBC-B501-25FB3A0103C7}
        Security Update for 2007 Microsoft Office System (KB960003)-->msiexec /package {91120000-0014-0000-0000-0000000FF1CE} /uninstall {F04F8702-18D0-458D-921E-146FB7CD38CF}
        Security Update for Microsoft Office Excel 2007 (KB959997)-->msiexec /package {91120000-0014-0000-0000-0000000FF1CE} /uninstall {9EAC3AEC-5C81-4856-A05B-DE9DC236D740}
        Security Update for Microsoft Office PowerPoint 2007 (KB957789)-->msiexec /package {91120000-0014-0000-0000-0000000FF1CE} /uninstall {7559E742-FF9F-4FAE-B279-008ED296CB4D}
        Security Update for Microsoft Office Publisher 2007 (KB950114)-->msiexec /package {91120000-0014-0000-0000-0000000FF1CE} /uninstall {F9C3CDBA-1F00-4D4D-959D-75C9D3ACDD85}
        Security Update for Microsoft Office system 2007 (KB954326)-->msiexec /package {91120000-0014-0000-0000-0000000FF1CE} /uninstall {5F7F6FFF-395D-480E-8450-64F385D82C5F}
        Security Update for Microsoft Office system 2007 (KB956828)-->msiexec /package {91120000-0014-0000-0000-0000000FF1CE} /uninstall {885E081B-72BD-4E76-8E98-30B4BE468FAC}
        Security Update for Microsoft Office Word 2007 (KB956358)-->msiexec /package {91120000-0014-0000-0000-0000000FF1CE} /uninstall {4551666D-0FD6-4C69-8A81-1C6F2E64517C}
        Sélecteur d'installation de Microsoft Works 2005-->C:\Program Files\Microsoft Works Suite 2005\Setup\Launcher.exe /ARP D:\
        Shockwave-->C:\WINDOWS\SYSTEM32\Macromed\SHOCKW~1\UNWISE.EXE C:\WINDOWS\SYSTEM32\Macromed\SHOCKW~1\Install.log
        SIW version 2008-06-04-->"C:\Program Files\SIW\unins000.exe"
        SketchUp 5-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B357C4B4-9024-4B64-9B3F-A6729031C3DD}\setup.exe" -l0x40c
        Skype™ 4.0-->MsiExec.exe /X{24D753CA-6AE9-4E30-8F5F-EFC93E08BF3D}
        SmartSound Quicktracks Plugin-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe /M{4A7FDA4D-F4D7-4A49-934A-066D59A43C7E}
        Sonic DLA-->MsiExec.exe /I{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}
        Sonic MyDVD-->MsiExec.exe /I{21657574-BD54-48A2-9450-EB03B2C7FC29}
        Sonic RecordNow!-->MsiExec.exe /I{9541FED0-327F-4DF0-8B96-EF57EF622F19}
        Sonic Update Manager-->MsiExec.exe /I{09DA4F91-2A09-4232-AB8C-6BC740096DE3}
        Spybot - Search & Destroy 1.5.2.20-->"C:\WINDOWS\unins000.exe"
        Spybot - Search & Destroy-->"C:\Program Files\Spybot - Search & Destroy\unins001.exe"
        Studio 10-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3CB05291-F546-458E-A796-B5BCF5A3CDC4}\Setup2.exe" -l0x40c UNINSTALL
        TerraExplorer-->C:\Program Files\Skyline\TerraExplorer\Setup.exe [OP]/U
        Total Recorder 6.1-->"C:\Program Files\HighCriteria\TotalRecorder\setup.exe" U
        Update for 2007 Microsoft Office System (KB967642)-->msiexec /package {91120000-0014-0000-0000-0000000FF1CE} /uninstall {C444285D-5E4F-48A4-91DD-47AAAA68E92D}
        Update for Microsoft Office Outlook 2007 (KB952142)-->msiexec /package {91120000-0014-0000-0000-0000000FF1CE} /uninstall {4AD3A076-427C-491F-A5B7-7D1DE788A756}
        Update for Outlook 2007 Junk Email Filter (kb968503)-->msiexec /package {91120000-0014-0000-0000-0000000FF1CE} /uninstall {5DD98950-4D10-4B79-8BF6-59726705207D}
        VideoLAN VLC media player 0.8.4a-->C:\Program Files\VideoLAN\VLC\uninstall.exe
        VIMICRO USB PC Camera V-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{8AD824A5-1CCC-4BB7-82C9-E6FB25CC0479}\setup.exe" -l0x9
        WebCyberCoach 3.2 Dell-->"C:\Program Files\WebCyberCoach\b_Dell\WCC_Wipe.exe" "WebCyberCoach ext\wtrb" /inf "engine.inf,RealUninstallSection,,4" /infcfg "enginecf.inf,RealUninstallSection,,4"
        Winamp-->"C:\Program Files\Winamp\UninstWA.exe"
        Windows Driver Package - Nokia Modem (02/15/2007 3.1)-->C:\PROGRA~1\DIFX\D6ACC4BE676423A2B130B78A4B627FC457D98997\dpinst.exe /u C:\WINDOWS\system32\DRVSTORE\pccs_bluet_8B37DC72918CCD58A6EC20373AF6242B037A293B\pccs_bluetooth.inf
        Windows Genuine Advantage v1.3.0254.0-->MsiExec.exe /I{63569CE9-FA00-469C-AF5C-E5D4D93ACF91}
        Windows Internet Explorer 8-->"C:\WINDOWS\ie8\spuninst\spuninst.exe"
        Windows Live Favorites pour Windows Live Toolbar-->MsiExec.exe /X{786C4AD1-DCBA-49A6-B0EF-B317A344BD66}
        Windows Live installer-->MsiExec.exe /I{A90D10BA-1E82-44E1-87DE-56A22BA151DA}
        Windows Live Mail-->MsiExec.exe /I{C514C594-23AA-4F13-A070-DB8BDB27594F}
        Windows Live Messenger-->MsiExec.exe /I{F6326B60-1B1D-4ABF-BFCD-7B7404F44411}
        Windows Live Sign-in Assistant-->MsiExec.exe /I{F652D238-5F29-42D5-BAF3-0115EF977EC2}
        Windows Live Toolbar-->"C:\Program Files\Windows Live Toolbar\UnInstall.exe" {0A8C97AD-DEED-4894-B446-3ABA95A77D0D}
        Windows Live Toolbar-->MsiExec.exe /X{0A8C97AD-DEED-4894-B446-3ABA95A77D0D}
        Windows Media Connect-->"C:\WINDOWS\$NtUninstallWMCSetup$\spuninst\spuninst.exe"
        Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
        Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
        Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
        Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
        WinZip-->"C:\Program Files\WinZip\WINZIP32.EXE" /uninstall
        XviD MPEG-4 Video Codec-->"C:\Program Files\XviD\unins000.exe"

        ======Hosts File======

        127.0.0.1 www.007guard.com
        127.0.0.1 007guard.com
        127.0.0.1 008i.com
        127.0.0.1 www.008k.com
        127.0.0.1 008k.com
        127.0.0.1 www.00hq.com
        127.0.0.1 00hq.com
        127.0.0.1 010402.com
        127.0.0.1 www.032439.com
        127.0.0.1 032439.com

        ======Security center information======

        AV: avast! antivirus 4.8.1335 [VPS 090609-0]

        ======System event log======

        Computer Name: GILCHRIS
        Event Code: 7035
        Message: Un contrôle Démarrer a correctement été envoyé au service Gestionnaire de connexions d'accès distant.

        Record Number: 158609
        Source Name: Service Control Manager
        Time Written: 20090527070545.000000+120
        Event Type: Informations
        User: GILCHRIS\gil

        Computer Name: GILCHRIS
        Event Code: 7035
        Message: Un contrôle Démarrer a correctement été envoyé au service Service COM de gravage de CD IMAPI.

        Record Number: 158608
        Source Name: Service Control Manager
        Time Written: 20090527070545.000000+120
        Event Type: Informations
        User: AUTORITE NT\SYSTEM

        Computer Name: GILCHRIS
        Event Code: 7036
        Message: Le service Compatibilité avec le Changement rapide d'utilisateur est entré dans l'état : en cours d'exécution.

        Record Number: 158607
        Source Name: Service Control Manager
        Time Written: 20090527070545.000000+120
        Event Type: Informations
        User:

        Computer Name: GILCHRIS
        Event Code: 7035
        Message: Un contrôle Arrêter a correctement été envoyé au service Fax.

        Record Number: 158606
        Source Name: Service Control Manager
        Time Written: 20090527070545.000000+120
        Event Type: Informations
        User: AUTORITE NT\SYSTEM

        Computer Name: GILCHRIS
        Event Code: 7035
        Message: Un contrôle Démarrer a correctement été envoyé au service Compatibilité avec le Changement rapide d'utilisateur.

        Record Number: 158605
        Source Name: Service Control Manager
        Time Written: 20090527070545.000000+120
        Event Type: Informations
        User: AUTORITE NT\SYSTEM

        =====Application event log=====

        Computer Name: GILCHRIS
        Event Code: 2002
        Message:
        Record Number: 19997
        Source Name: EAPOL
        Time Written: 20081031073033.000000+060
        Event Type: Informations
        User:

        Computer Name: GILCHRIS
        Event Code: 2003
        Message:
        Record Number: 19996
        Source Name: EAPOL
        Time Written: 20081031073033.000000+060
        Event Type: Informations
        User:

        Computer Name: GILCHRIS
        Event Code: 1800
        Message: Le service Centre de sécurité Windows a démarré.

        Record Number: 19995
        Source Name: SecurityCenter
        Time Written: 20081031073026.000000+060
        Event Type: Informations
        User:

        Computer Name: GILCHRIS
        Event Code: 0
        Message: Le service a démarré avec succès.

        Record Number: 19994
        Source Name: edsvc
        Time Written: 20081031072950.000000+060
        Event Type: Informations
        User:

        Computer Name: GILCHRIS
        Event Code: 105
        Message: The service was started.

        Record Number: 19993
        Source Name: ATI Smart
        Time Written: 20081031072942.000000+060
        Event Type: Informations
        User:

        ======Environment variables======

        "ComSpec"=%SystemRoot%\system32\cmd.exe
        "Path"=C:\Program Files\PC Connectivity Solution\;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\ATI Technologies\ATI Control Panel;C:\PROGRA~1\FICHIE~1\SONICS~1\;C:\Program Files\Fichiers communs\Sonic Shared;
        "windir"=%SystemRoot%
        "FP_NO_HOST_CHECK"=NO
        "OS"=Windows_NT
        "PROCESSOR_ARCHITECTURE"=x86
        "PROCESSOR_LEVEL"=15
        "PROCESSOR_IDENTIFIER"=x86 Family 15 Model 4 Stepping 1, GenuineIntel
        "PROCESSOR_REVISION"=0401
        "NUMBER_OF_PROCESSORS"=2
        "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
        "TEMP"=%SystemRoot%\TEMP
        "TMP"=%SystemRoot%\TEMP

        -----------------EOF-----------------
        a+
        1. Contributeur sécurité
          salut,

          tu es bien infecté ... ^^ par une clé usb vérolée ou autre support amovible du genre ...

          fais ceci :

          Télécharge UsbFix ( de C_XX, Chimay8 & Chiquitine29 ) sur ton bureau :

          > http://sd-1.archive-host.com/membres/up/127028005715545653/UsbFix.exe

          ! Déconnecte toi d'internet et ferme toutes applications en cours !

          --> Double-clique sur l' .exe pour lancer l'installation de l'outil ( ne touche pas aux paramètres d'installe ) .

          Impératif :
          Branche toutes tes unités externes à ton PC (clé USB, DD externe, flash disk, lecteur MP3,carte SD, etc...) succeptibles d'avoir été infectés ( mais sans les ouvrir ! ) .

          # Double clique sur le raccourci UsbFix présent sur ton bureau pour lancer l'outil.

          # Choisis l' option 1 ( Recherche )

          # Laisse travailler l'outil et ne touche à rien pendant le scan .

          # Une fois terminé, poste le rapport UsbFix.txt qui apparaitra.

          Le rapport est en outre sauvegardé à la racine du disque maitre ( C:\UsbFix.txt ).

          ( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

          Note :
          "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
          Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
          Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.

          Site de l'auteur > http://pagesperso-orange.fr/NosTools/usbfix.html

          1. Donc, pas si parano que ça!!!
            Voicic le rapport:
            ############################## [ UsbFix V3.029 | Scan ]

            # User : gil () # GILCHRIS
            # Update on 05/06/09 by Chiquitine29, C_XX & Chimay8
            # WebSite : http://pagesperso-orange.fr/NosTools/usbfix.html
            # Start at: 19:22:52 | 10/06/2009

            # Intel(R) Pentium(R) 4 CPU 3.20GHz
            # Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
            # Internet Explorer 8.0.6001.18702
            # Windows Firewall Status : Disabled
            # AV : avast! antivirus 4.8.1335 [VPS 090609-0] 4.8.1335 [ Enabled | Updated ]

            # A:\ # Lecteur de disquettes 3 ½ pouces
            # C:\ # Disque fixe local # 71,67 Go (24,86 Go free) # NTFS
            # D:\ # Disque CD-ROM # 1,63 Go (0 Mo free) [Jack Keane] # CDFS
            # E:\ # Disque amovible # 1,87 Go (925,94 Mo free) [KINGSTON] # FAT

            ############################## [ Processus actifs ]

            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\csrss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\Ati2evxx.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\svchost.exe
            C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
            C:\Program Files\Alwil Software\Avast4\ashServ.exe
            C:\WINDOWS\system32\Ati2evxx.exe
            C:\WINDOWS\Explorer.EXE
            C:\WINDOWS\system32\LEXBCES.EXE
            C:\WINDOWS\system32\spoolsv.exe
            C:\WINDOWS\system32\LEXPPS.EXE
            C:\WINDOWS\system32\svchost.exe
            C:\Program Files\Google\Update\GoogleUpdate.exe
            C:\Program Files\Verdiem\Edison\edsvc.exe
            C:\WINDOWS\System32\FTRTSVC.exe
            C:\WINDOWS\System32\svchost.exe
            C:\Program Files\Java\jre6\bin\jqs.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\svchost.exe
            C:\Program Files\Windows Media Player\WMPNetwk.exe
            C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
            C:\Program Files\Analog Devices\Core\smax4pnp.exe
            C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
            C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
            C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
            C:\WINDOWS\system32\dla\tfswctrl.exe
            C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
            C:\Program Files\Jetico\Jetico Personal Firewall\fwsrv.exe
            C:\WINDOWS\VM305_STI.EXE
            C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
            C:\WINDOWS\system32\ctfmon.exe
            C:\Program Files\Windows Media Player\WMPNSCFG.exe
            C:\WINDOWS\System32\wudfhost.exe
            C:\WINDOWS\system32\wbem\wmiprvse.exe

            ################## [ Registre Startup ]

            HKCU_Main: "Local Page"="C:\\WINDOWS\\system32\\blank.htm"
            HKCU_Main: "Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
            HKCU_Main: "Prev Search Page"="http://google.icq.com"
            HKCU_Main: "Start Page"="https://www.orange.fr/portail"
            HKCU_Main: "Secondary Start Pages"=hex(7):68,00,74,00,74,00,70,00,3a,00,2f,00,2f,00,77,00,\
            HKCU_Main: "Window Title"="Orange"
            HKLM_logon: "Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
            HKLM_logon: "DefaultUserName"="gil"
            HKLM_logon: "AltDefaultUserName"="gil"
            HKLM_logon: "LegalNoticeCaption"=""
            HKLM_logon: "LegalNoticeText"=""
            HKLM_Run: SoundMAXPnP=C:\Program Files\Analog Devices\Core\smax4pnp.exe
            HKLM_Run: ATIPTA="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
            HKLM_Run: IntelMeM=C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
            HKLM_Run: dla=C:\WINDOWS\system32\dla\tfswctrl.exe
            HKLM_Run: UpdateManager="C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe" /r
            HKLM_Run: WOOWATCH=C:\PROGRA~1\Wanadoo\Watch.exe
            HKLM_Run: WOOTASKBARICON=C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
            HKLM_Run: avast!=C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
            HKLM_Run: JeticoPFStartup="C:\Program Files\Jetico\Jetico Personal Firewall\fwsrv.exe"
            HKLM_Run: PinnacleDriverCheck=C:\WINDOWS\system32\\PSDrvCheck.exe
            HKLM_Run: BigDog305=C:\WINDOWS\VM305_STI.EXE VIMICRO USB PC Camera (ZC0305)
            HKLM_Run: Adobe Reader Speed Launcher="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
            HKLM_Run: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents=
            HKCU_Run: WOOKIT=C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
            HKCU_Run: EPSON Stylus DX4400 Series=C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICAE.EXE /FU "C:\DOCUME~1\gil\LOCALS~1\Temp\E_S1C3.tmp" /EF "HKCU"
            HKCU_Run: ctfmon.exe=C:\WINDOWS\system32\ctfmon.exe
            HKCU_Run: WMPNSCFG=C:\Program Files\Windows Media Player\WMPNSCFG.exe
            HKCU_Run: FAST Defrag=

            ################## [ Fichiers # Dossiers infectieux ]

            Found ! C:\WINDOWS\autorun.ini
            Found ! D:\autorun.inf
            Found ! E:\autorun.inf

            ################## [ Registre # Clés Run infectieuses ]

            Found ! HKLM\software\microsoft\security center "FirewallOverride" ( 0x1 )

            ################## [ Registre # Mountpoints2 ]

            HKCU\...\Explorer\MountPoints2\{29ed441c-5e2d-11dd-9f41-00038a000015}\Shell\AutoRun\Command
            HKCU\...\Explorer\MountPoints2\{546d9dc0-2f75-11da-95ef-806d6172696f}\Shell\AutoRun\Command
            HKCU\...\Explorer\MountPoints2\{6352ae4e-69ba-11dc-9c1d-00038a000015}\Shell\AutoRun\Command

            ################## [ ! Fin du rapport # UsbFix V3.029 ! ]

            Merci du coup de main...
            1. Contributeur sécurité
              la suite :

              1- ! Déconnecte toi d'internet et ferme toutes applications en cours !

              Impératif :
              Branche toutes tes unités externes à ton PC (clé USB, DD externe, flash disk, lecteur MP3,carte SD, etc...) succeptibles d'avoir été infectés ( mais sans les ouvrir ! ) .

              # Double clique sur le raccourci UsbFix présent sur ton bureau pour lancer l'outil .

              # Cette fois ci , tu choisis l' option 2 ( Suppression ) .

              > Ton bureau disparaitra et le pc redémarrera ( c'est normal ).

              # Au redémarrage , UsbFix scannera ton pc , laisse travailler l'outil et ne touche à rien .

              # Une fois terminé, poste le nouveau rapport UsbFix.txt qui apparaitra avec le bureau .

              ( Le rapport est en outre sauvegardé à la racine du disque maitre > C:\UsbFix.txt ).

              ==========================

              2- refais un scan RSIT , poste le nouveau "log.txt" obtenu et attends la suite ....

              1. ############################## [ UsbFix V3.029 | Cleaning ]

                # User : gil () # GILCHRIS
                # Update on 05/06/09 by Chiquitine29, C_XX & Chimay8
                # WebSite : http://pagesperso-orange.fr/NosTools/usbfix.html
                # Start at: 19:48:00 | 10/06/2009

                # Intel(R) Pentium(R) 4 CPU 3.20GHz
                # Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
                # Internet Explorer 8.0.6001.18702
                # Windows Firewall Status : Disabled
                # AV : avast! antivirus 4.8.1335 [VPS 090609-0] 4.8.1335 [ Enabled | Updated ]

                # A:\ # Lecteur de disquettes 3 ½ pouces
                # C:\ # Disque fixe local # 71,67 Go (24,86 Go free) # NTFS
                # D:\ # Disque CD-ROM # 1,63 Go (0 Mo free) [Jack Keane] # CDFS
                # E:\ # Disque amovible # 1,87 Go (925,94 Mo free) [KINGSTON] # FAT

                ############################## [ Processus actifs ]

                C:\WINDOWS\System32\smss.exe
                C:\WINDOWS\system32\csrss.exe
                C:\WINDOWS\system32\winlogon.exe
                C:\WINDOWS\system32\services.exe
                C:\WINDOWS\system32\lsass.exe
                C:\WINDOWS\system32\Ati2evxx.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\System32\svchost.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\system32\Ati2evxx.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\Explorer.EXE
                C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                C:\Program Files\Alwil Software\Avast4\ashServ.exe
                C:\WINDOWS\System32\wudfhost.exe
                C:\WINDOWS\system32\WgaTray.exe
                C:\WINDOWS\system32\LEXBCES.EXE
                C:\WINDOWS\system32\spoolsv.exe
                C:\WINDOWS\system32\LEXPPS.EXE
                C:\WINDOWS\system32\svchost.exe
                C:\Program Files\Verdiem\Edison\edsvc.exe
                C:\Program Files\Google\Update\GoogleUpdate.exe
                C:\Program Files\Google\Update\GoogleUpdate.exe
                C:\WINDOWS\System32\FTRTSVC.exe
                C:\Program Files\Google\Update\GoogleUpdate.exe
                C:\Program Files\Alwil Software\Avast4\setup\avast.setup
                C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                C:\WINDOWS\System32\svchost.exe
                C:\Program Files\Java\jre6\bin\jqs.exe
                C:\Program Files\Google\Update\GoogleUpdate.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\system32\svchost.exe
                C:\Program Files\Windows Media Player\WMPNetwk.exe
                C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                C:\WINDOWS\system32\wbem\wmiprvse.exe
                C:\WINDOWS\system32\wbem\wmiprvse.exe

                ################## [ Fichiers # Dossiers infectieux ]

                Deleted ! C:\WINDOWS\autorun.ini
                (!) Not Deleted ! D:\autorun.inf
                Deleted ! E:\autorun.inf

                ################## [ Registre # Clés Run infectieuses ]

                # HKLM\software\microsoft\security center\\ "FirewallOverride" # -> Reset sucessfully !

                ################## [ Registre # Mountpoints2 ]

                Deleted ! HKCU\...\Explorer\MountPoints2\{29ed441c-5e2d-11dd-9f41-00038a000015}\Shell\AutoRun\Command
                Deleted ! HKCU\...\Explorer\MountPoints2\{546d9dc0-2f75-11da-95ef-806d6172696f}\Shell\AutoRun\Command
                Deleted ! HKCU\...\Explorer\MountPoints2\{6352ae4e-69ba-11dc-9c1d-00038a000015}\Shell\AutoRun\Command

                ################## [ Listing des fichiers présent ]

                [06/03/2005 21:43|--a------|1048576] - C:\asse
                [11/05/2008 09:31|--a------|95] - C:\AUTOEXEC.BAT
                [19/12/2007 21:57|-rahs----|216] - C:\BOOT.INI
                [05/08/2004 14:00|-rahs----|4952] - C:\Bootfont.bin
                [01/10/2005 12:00|-ra------|1699] - C:\CLDMA.LOG
                [20/08/2004 12:37|--a------|0] - C:\CONFIG.SYS
                [24/02/2005 13:32|--a------|166892] - C:\debug.log
                [13/01/2005 04:05|-rah-----|4142] - C:\DELL.SDR
                [25/01/2005 22:51|--a------|0] - C:\error.txt
                [12/09/2007 12:57|--a------|2253] - C:\fixnavi.txt
                [29/04/2006 12:59|--a------|16] - C:\h.txt
                [?|?|?] - C:\hiberfil.sys
                [20/08/2004 12:48|--a------|4128] - C:\INFCACHE.1
                [20/08/2004 12:37|--ah-----|0] - C:\IO.SYS
                [15/06/2008 10:07|--a------|20180] - C:\lopR.txt
                [20/08/2004 12:37|--ah-----|0] - C:\MSDOS.SYS
                [05/08/2004 14:00|-rahs----|47564] - C:\NTDETECT.COM
                [28/08/2008 19:12|-rahs----|252240] - C:\NTLDR
                [?|?|?] - C:\pagefile.sys
                [09/03/2005 13:31|--a------|159087] - C:\PAILHES-BasePronote2Šmetrimestre2004-2005-03.npr
                [01/06/2005 16:41|--a------|231431] - C:\PAILHES-BasePronote3Šmetrimestre2004-2005-04.npr
                [12/09/2007 13:34|--a------|1840] - C:\rapport.txt
                [08/09/2007 09:53|--a------|728] - C:\rapport_clean.txt
                [03/02/2005 18:50|--a------|4] - C:\scrabble.acc
                [10/06/2009 08:43|--a------|1816] - C:\SMax.log
                [21/11/2007 15:10|--a------|1821] - C:\SMax.log.bak
                [27/12/2008 13:38|--a------|2297] - C:\TB.txt
                [10/06/2009 19:49|--a------|4469] - C:\UsbFix.txt
                [08/08/2007 12:07|--a------|64792185] - C:\xscan.txt
                [24/04/2006 09:32|--a------|8506] - C:\ZB20060424092903001.xml
                [27/05/2006 19:10|--a------|4370] - C:\ZB20060527190757001.xml
                [01/06/2006 18:50|--a------|2501] - C:\ZB20060601184845001.xml
                [02/06/2006 20:35|--a------|903] - C:\ZB20060602203456001.xml
                [08/06/2006 17:57|--a------|13206] - C:\ZB20060608175054001.xml
                [09/06/2006 19:18|--a------|2877] - C:\ZB20060609191643001.xml
                [11/06/2006 10:26|--a------|3065] - C:\ZB20060611102501001.xml
                [12/06/2006 13:54|--a------|527] - C:\ZB20060612135421001.xml
                [12/06/2006 21:11|--a------|1937] - C:\ZB20060612211048001.xml
                [14/06/2006 18:35|--a------|1843] - C:\ZB20060614183454001.xml
                [15/06/2006 19:14|--a------|1561] - C:\ZB20060615191403001.xml
                [16/06/2006 18:38|--a------|3065] - C:\ZB20060616183738001.xml
                [22/06/2006 18:26|--a------|5404] - C:\ZB20060622182428001.xml
                [26/06/2006 21:25|--a------|2689] - C:\ZB20060626212351001.xml
                [01/07/2006 20:32|--a------|3148] - C:\ZB20060701203050001.xml
                [18/07/2006 03:44|--a------|13864] - C:\ZB20060718033840001.xml
                [18/07/2006 15:11|--a------|1749] - C:\ZB20060718151031001.xml
                [29/07/2006 16:28|--a------|986] - C:\ZB20060729162833001.xml
                [02/08/2006 19:03|--a------|1749] - C:\ZB20060802190225001.xml
                [03/08/2006 19:26|--a------|1843] - C:\ZB20060803192548001.xml
                [07/08/2006 09:55|--a------|1185] - C:\ZB20060807095438001.xml
                [19/08/2006 17:48|--a------|2584] - C:\ZB20060819174655001.xml
                [08/09/2006 18:12|--a------|2313] - C:\ZB20060908181148001.xml
                [17/09/2006 18:02|--a------|2208] - C:\ZB20060917180126001.xml
                [19/09/2006 18:23|--a------|1373] - C:\ZB20060919182304001.xml
                [20/09/2006 17:38|--a------|1561] - C:\ZB20060920173822001.xml
                [21/09/2006 17:44|--a------|1843] - C:\ZB20060921174353001.xml
                [22/09/2006 18:36|--a------|1655] - C:\ZB20060922183539001.xml
                [23/09/2006 17:27|--a------|1937] - C:\ZB20060923172643001.xml
                [26/09/2006 18:07|--a------|621] - C:\ZB20060926180741001.xml
                [27/09/2006 18:18|--a------|1749] - C:\ZB20060927181737001.xml
                [02/10/2006 18:39|--a------|3148] - C:\ZB20061002183834001.xml
                [03/10/2006 17:52|--a------|2407] - C:\ZB20061003175136001.xml
                [08/10/2006 19:10|--a------|2020] - C:\ZB20061008191011001.xml
                [12/10/2006 20:20|--a------|1373] - C:\ZB20061012202020001.xml
                [13/10/2006 17:42|--a------|2783] - C:\ZB20061013174150001.xml
                [18/10/2006 10:58|--a------|1091] - C:\ZB20061018105804001.xml
                [19/10/2006 19:37|--a------|2125] - C:\ZB20061019193628001.xml
                [20/10/2006 15:59|--a------|1937] - C:\ZB20061020155857001.xml
                [21/10/2006 14:13|--a------|1467] - C:\ZB20061021141235001.xml
                [22/10/2006 20:39|--a------|2396] - C:\ZB20061022203818001.xml
                [23/10/2006 12:37|--a------|1185] - C:\ZB20061023123722001.xml
                [25/10/2006 13:21|--a------|997] - C:\ZB20061025132142001.xml
                [26/10/2006 19:25|--a------|2501] - C:\ZB20061026192455001.xml
                [03/11/2006 17:54|--a------|2584] - C:\ZB20061103165318001.xml
                [05/11/2006 19:25|--a------|1373] - C:\ZB20061105182451001.xml
                [07/11/2006 19:16|--a------|1279] - C:\ZB20061107181559001.xml
                [13/11/2006 19:17|--a------|7754] - C:\ZB20061113181405001.xml
                [15/11/2006 19:07|--a------|2595] - C:\ZB20061115180622001.xml
                [16/11/2006 18:42|--a------|1937] - C:\ZB20061116174158001.xml
                [17/11/2006 19:01|--a------|1467] - C:\ZB20061117180051001.xml
                [21/11/2006 19:49|--a------|2020] - C:\ZB20061121184821001.xml
                [22/11/2006 20:27|--a------|1749] - C:\ZB20061122192647001.xml
                [23/11/2006 18:33|--a------|2783] - C:\ZB20061123173212001.xml
                [25/11/2006 19:09|--a------|1843] - C:\ZB20061125180831001.xml
                [29/11/2006 17:48|--a------|3336] - C:\ZB20061129164642001.xml
                [30/11/2006 20:03|--a------|1091] - C:\ZB20061130190301001.xml
                [11/12/2006 21:31|--a------|715] - C:\ZB20061211203052001.xml
                [20/12/2006 20:17|--a------|997] - C:\ZB20061220191648001.xml
                [21/12/2006 20:05|--a------|1174] - C:\ZB20061221190543001.xml
                [31/01/2007 21:27|--a------|5310] - C:\ZB20070131202457001.xml
                [05/02/2007 19:23|--a------|1373] - C:\ZB20070205182300001.xml
                [19/02/2007 16:45|--a------|1644] - C:\ZB20070219154459001.xml
                [22/02/2007 11:52|--a------|527] - C:\ZB20070222105249001.xml
                [01/03/2007 18:06|--a------|433] - C:\ZB20070301170648001.xml
                [04/03/2007 19:03|--a------|527] - C:\ZB20070304180329001.xml
                [18/03/2007 12:15|--a------|4088] - C:\ZB20070318111314001.xml
                [27/03/2007 21:27|--a------|1279] - C:\ZB20070327212714001.xml
                [09/04/2007 19:24|--a------|3524] - C:\ZB20070409192315001.xml
                [05/05/2007 18:28|--a------|2208] - C:\ZB20070505182727001.xml
                [08/05/2007 19:32|--a------|2584] - C:\ZB20070508193042001.xml
                [20/05/2007 19:17|--a------|1268] - C:\ZB20070520191641001.xml
                [23/05/2007 16:46|--a------|433] - C:\ZB20070523164614001.xml
                [28/05/2007 08:36|--a------|4287] - C:\ZB20070528083429001.xml
                [16/06/2007 21:10|--a------|2678] - C:\ZB20070616210929001.xml
                [14/07/2007 08:27|--a------|3347] - C:\ZB20070714082543001.xml
                [30/07/2007 07:54|--a------|7660] - C:\ZB20070730075126001.xml
                [05/08/2007 18:29|--a------|809] - C:\ZB20070805182909001.xml
                [17/08/2007 22:09|--a------|1362] - C:\ZB20070817220853001.xml
                [20/08/2007 08:41|--a------|1080] - C:\ZB20070820084129001.xml
                [21/08/2007 08:28|--a------|1373] - C:\ZB20070821082753001.xml
                [28/08/2007 20:42|--a------|3065] - C:\ZB20070828204042001.xml
                [09/10/2007 18:57|--a------|3430] - C:\ZB20071009185646001.xml
                [27/10/2007 16:20|--a------|621] - C:\ZB20071027162038001.xml
                [29/10/2007 18:26|--a------|1174] - C:\ZB20071029172559001.xml
                [30/10/2007 20:20|--a------|621] - C:\ZB20071030192016001.xml
                [02/12/2007 20:46|--a------|516] - C:\ZB20071202194631001.xml
                [29/12/2007 08:10|--a------|704] - C:\ZB20071229071027001.xml
                [20/01/2008 19:35|--a------|5686] - C:\ZB20080120183323001.xml
                [03/02/2008 10:50|--a------|1268] - C:\ZB20080203094950001.xml
                [21/02/2008 12:37|--a------|1456] - C:\ZB20080221113713001.xml
                [27/02/2008 18:52|--a------|2490] - C:\ZB20080227175134001.xml
                [08/03/2008 12:21|--a------|3806] - C:\ZB20080308111947001.xml
                [08/03/2008 12:28|--a------|1013] - C:\ZB20080308112827001.xml
                [08/03/2008 12:32|--a------|621] - C:\ZB20080308113226001.xml
                [14/04/2008 14:36|--a------|2396] - C:\ZB20080414143551001.xml
                [29/05/2008 06:34|--a------|5028] - C:\ZB20080529063227001.xml
                [30/05/2008 07:26|--a------|1655] - C:\ZB20080530072609001.xml
                [02/06/2008 20:59|--a------|2208] - C:\ZB20080602205842001.xml
                [12/06/2008 10:35|--a------|2584] - C:\ZB20080612103455001.xml
                [12/06/2008 10:49|--a------|809] - C:\ZB20080612104916001.xml
                [25/06/2008 20:06|--a------|2020] - C:\ZB20080625200543001.xml
                [14/07/2008 09:47|--a------|2772] - C:\ZB20080714094623001.xml
                [16/07/2008 22:50|--a------|3806] - C:\ZB20080716224933001.xml
                [24/07/2008 09:56|--a------|1362] - C:\ZB20080724095536001.xml
                [27/07/2008 11:22|--a------|2866] - C:\ZB20080727112202001.xml
                [03/08/2008 09:40|--a------|1080] - C:\ZB20080803093949001.xml
                [20/08/2008 10:11|--a------|1738] - C:\ZB20080820101052001.xml
                [03/09/2008 14:29|--a------|2960] - C:\ZB20080903142848001.xml
                [01/10/2008 20:26|--a------|8600] - C:\ZB20081001202320001.xml
                [07/10/2008 11:54|--a------|621] - C:\ZB20081007115450001.xml
                [19/10/2008 09:57|--a------|809] - C:\ZB20081019095732001.xml
                [24/10/2008 10:02|--a------|1738] - C:\ZB20081024100146001.xml
                [18/11/2008 14:05|--a------|12924] - C:\ZB20081118125958001.xml
                [18/11/2008 22:24|--a------|339] - C:\ZB20081118212434001.xml
                [01/12/2008 19:14|--a------|3806] - C:\ZB20081201181334001.xml
                [09/12/2008 12:46|--a------|527] - C:\ZB20081209114630001.xml
                [31/12/2008 10:20|--a------|5216] - C:\ZB20081231091838001.xml
                [12/01/2009 11:25|--a------|1926] - C:\ZB20090112102450001.xml
                [25/01/2009 18:56|--a------|1926] - C:\ZB20090125175552001.xml
                [15/02/2009 11:34|--a------|3806] - C:\ZB20090215103302001.xml
                [24/02/2009 18:18|--a------|2396] - C:\ZB20090224171722001.xml
                [28/03/2009 18:59|--a------|1738] - C:\ZB20090328175854001.xml
                [28/03/2009 19:17|--a------|339] - C:\ZB20090328181710001.xml
                [06/04/2009 19:27|--a------|3054] - C:\ZB20090406192620001.xml
                [15/04/2009 17:00|--a------|4840] - C:\ZB20090415165746001.xml
                [26/04/2009 09:01|--a------|1080] - C:\ZB20090426090120001.xml
                [29/04/2009 16:53|--a------|433] - C:\ZB20090429165326001.xml
                [07/05/2009 10:57|--a------|809] - C:\ZB20090507105700001.xml
                [24/05/2009 20:17|--a------|2208] - C:\ZB20090524201614001.xml
                [29/05/2009 13:49|--a------|809] - C:\ZB20090529134912001.xml
                [13/06/2007 16:08|-r-------|4286] - D:\JackKeane.ico
                [28/08/2007 16:29|-r-------|1414105942] - D:\JackKeane-Setup-FRA.exe
                [30/08/2007 10:34|-r-------|23040] - D:\SetupStarter.exe
                [13/06/2007 16:08|-r-------|52] - D:\autorun.inf
                [07/10/2008 13:58|--a------|1526612] - E:\Composition2.pdf
                [01/10/2008 20:27|--a------|943617] - E:\raid30.10
                [10/10/2008 21:00|--a------|1895424] - E:\Composition2.pub
                [13/10/2008 21:23|--a------|4181] - E:\IDD.txt
                [17/12/2008 08:54|--a------|57856] - E:\fuul contact.doc
                [16/01/2009 10:29|--a------|1692] - E:\BOOTEX.LOG
                [27/03/2009 03:18|--a------|1904] - E:\retour1
                [27/03/2009 03:18|--a------|2249] - E:\retour2
                [30/03/2009 23:04|--a------|3029107] - E:\1d416052b23dc2d5153a8eccefa3-Notice g‚n‚rique Boxer France.pdf

                ################## [ Vaccination ]

                # C:\autorun.inf ( # Not infected ) -> Folder created by UsbFix.
                # E:\autorun.inf ( # Not infected ) -> Folder created by UsbFix.

                ################## [ ! Fin du rapport # UsbFix V3.029 ! ]
                Voila pour le premier!
                1. et la suite:
                  Logfile of random's system information tool 1.06 (written by random/random)
                  Run by gil at 2009-06-10 21:00:44
                  Microsoft Windows XP Édition familiale Service Pack 3
                  System drive C: has 25 GB (35%) free of 73 GB
                  Total RAM: 1022 MB (60% free)

                  Logfile of Trend Micro HijackThis v2.0.2
                  Scan saved at 21:00:51, on 10/06/2009
                  Platform: Windows XP SP3 (WinNT 5.01.2600)
                  MSIE: Internet Explorer v8.00 (8.00.6001.18702)
                  Boot mode: Normal

                  Running processes:
                  C:\WINDOWS\System32\smss.exe
                  C:\WINDOWS\system32\winlogon.exe
                  C:\WINDOWS\system32\services.exe
                  C:\WINDOWS\system32\lsass.exe
                  C:\WINDOWS\system32\Ati2evxx.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                  C:\Program Files\Alwil Software\Avast4\ashServ.exe
                  C:\WINDOWS\system32\Ati2evxx.exe
                  C:\WINDOWS\Explorer.EXE
                  C:\WINDOWS\system32\LEXBCES.EXE
                  C:\WINDOWS\system32\spoolsv.exe
                  C:\Program Files\Google\Update\GoogleUpdate.exe
                  C:\WINDOWS\system32\LEXPPS.EXE
                  C:\Program Files\Analog Devices\Core\smax4pnp.exe
                  C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                  C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
                  C:\WINDOWS\system32\dla\tfswctrl.exe
                  C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                  C:\Program Files\Jetico\Jetico Personal Firewall\fwsrv.exe
                  C:\WINDOWS\VM305_STI.EXE
                  C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
                  C:\WINDOWS\System32\FTRTSVC.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\Program Files\Java\jre6\bin\jqs.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\system32\fxssvc.exe
                  C:\WINDOWS\system32\ctfmon.exe
                  C:\Program Files\Windows Media Player\WMPNSCFG.exe
                  C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                  C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                  C:\WINDOWS\system32\wuauclt.exe
                  C:\WINDOWS\system32\wscntfy.exe
                  C:\Documents and Settings\gil\Bureau\RSIT.exe
                  C:\Program Files\Trend Micro\HijackThis\gil.exe

                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                  R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
                  O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                  O2 - BHO: dsWebAllowBHO Class - {2F85D76C-0569-466F-A488-493E6BD0E955} - C:\Program Files\Windows Desktop Search\dsWebAllow.dll
                  O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                  O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
                  O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
                  O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                  O2 - BHO: BHO Barre de Confiance CM-CIC - {988B07F5-7392-455A-8A1F-64935CB8B6ED} - C:\Program Files\BarreConfCMCIC\TAPBar.dll
                  O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
                  O2 - BHO: PDFCreator Toolbar Helper - {C451C08A-EC37-45DF-AAAD-18B51AB5E837} - C:\Program Files\PDFCreator Toolbar\v3.3.0.1\PDFCreator_Toolbar.dll
                  O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                  O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
                  O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
                  O3 - Toolbar: Barre de confiance CM-CIC - {55BDF3B0-C0A8-481A-B8A6-01CD2BE0F3FD} - C:\Program Files\BarreConfCMCIC\TAPBar.dll
                  O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
                  O3 - Toolbar: PDFCreator Toolbar - {31CF9EBE-5755-4A1D-AC25-2834D952D9B4} - C:\Program Files\PDFCreator Toolbar\v3.3.0.1\PDFCreator_Toolbar.dll
                  O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
                  O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
                  O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
                  O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
                  O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe" /r
                  O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
                  O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
                  O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                  O4 - HKLM\..\Run: [JeticoPFStartup] "C:\Program Files\Jetico\Jetico Personal Firewall\fwsrv.exe"
                  O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\\PSDrvCheck.exe
                  O4 - HKLM\..\Run: [BigDog305] C:\WINDOWS\VM305_STI.EXE VIMICRO USB PC Camera (ZC0305)
                  O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                  O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
                  O4 - HKCU\..\Run: [EPSON Stylus DX4400 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICAE.EXE /FU "C:\DOCUME~1\gil\LOCALS~1\Temp\E_S1C3.tmp" /EF "HKCU"
                  O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                  O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                  O4 - HKUS\S-1-5-18\..\Run: [Nokia.PCSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'SYSTEM')
                  O4 - HKUS\.DEFAULT\..\Run: [Nokia.PCSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'Default user')
                  O8 - Extra context menu item: &ICQ Toolbar Search - res://C:\Program Files\ICQToolbar\toolbaru.dll/SEARCH.HTML
                  O8 - Extra context menu item: &MSN Search - res://C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1105\fr-fr\msntb.dll/search.htm
                  O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
                  O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
                  O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
                  O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0000.1105\fr-fr\msntabres.dll/229?b3e1df636c6a408fb85f84ade9356ed8
                  O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0000.1105\fr-fr\msntabres.dll/230?b3e1df636c6a408fb85f84ade9356ed8
                  O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                  O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                  O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                  O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                  O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - https://support.euro.dell.com/systemprofiler/SysPro.CAB
                  O16 - DPF: {029FDBA6-3547-11D7-AA4C-0050BF051A00} (Rawflow ICD Client) - http://s.tf1.fr/mmdia/static/rawflow/clients/5.3.1.0/Rawflow.cab
                  O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
                  O16 - DPF: {1F83CD9E-505E-4F87-BECE-0832A763E36F} (Image Uploader 3.0 Control) - http://www.mypixmania.com/fr/fr/importer/MypixUploader.cab
                  O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
                  O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
                  O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
                  O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://www.mypix.com/fr/fr/importer/ImageUploader4.cab
                  O16 - DPF: {952F9A71-131A-11D5-8404-00500445A7D0} (ActiveMiniplug Class) - https://intranet.unss.org/plugins/mplugax.cab
                  O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab
                  O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                  O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
                  O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                  O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                  O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\SYSTEM32\ati2sgag.exe
                  O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                  O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                  O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                  O23 - Service: Edison Power Management Service (edsvc) - Verdiem - C:\Program Files\Verdiem\Edison\edsvc.exe
                  O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
                  O23 - Service: Google Update Service (gupdate1c98c69280a00ee) (gupdate1c98c69280a00ee) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
                  O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                  O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
                  O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
                  O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
                  O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe
                  1. Contributeur sécurité
                    j'ai un message alerte de windows qui me dit qu'aucun pare feu ne me protège...

                    bizard ... pourtant Jetico est là ... est-il à jour ? est-il bien activé au niveau de la guarde en temps réel ?

                    vérifie cela et fais la suite :

                    1- Avoir accès aux fichiers cachés :

                    Va dans Menu Démarrer->Poste de travail->Outils->Options des dossiers...->Affichage
                    * "Afficher les fichiers et dossiers cachés" ---> coché
                    * "Masquer les extensions des fichiers dont le type est connu" ---> décoché
                    * "masquer les fichiers du système" ---> décoché
                    -> valide la modif ( "appliquer" puis "ok" ).
                    ( tu remetteras les paramètres de départ une fois la désinfection terminée , pas avant ... )

                    2- Rends toi sur ce site :

                    https://www.virustotal.com/gui/

                    Copies ce qui suit et colles le dans l'espace pour la recherche ( ou clique sur "parcourir" et va jusqu'au fichier demandé ) :
                    C:\ZB20060424092903001.xml

                    Clique sur Send File ( = " Envoyer le fichier " ).

                    Un rapport va s'élaborer ligne à ligne.

                    Attends bien la fin ... Il doit comprendre la taille du fichier envoyé.

                    Sauvegarde le rapport avec le bloc-note.

                    Copie le dans ta prochaine réponse ...

                    ( Si VirusTotal indique que le fichier a déjà été analysé, clique sur le bouton Ré-analyse le fichier maintenant )

                    Fais de même pour :
                    C:\ZB20070222105249001.xml
                    C:\ZB20090524201614001.xml


                    Poste moi donc ces 3 rapports ( surtout le début avec le listing des AV , et en précisant bien au début de chacuns à quel fichier ils correspondent ) et attends la suite ...

                    1. Le premier:Fichier ZB20060424092903001.xml reçu le 2009.06.11 05:09:44 (UTC)
                      Situation actuelle: terminé
                      Résultat: 0/39 (0%)
                      Formaté
                      Impression des résultats
                      Antivirus Version Dernière mise à jour Résultat
                      a-squared 4.5.0.18 2009.06.11 -
                      AhnLab-V3 5.0.0.2 2009.06.11 -
                      AntiVir 7.9.0.183 2009.06.10 -
                      Antiy-AVL 2.0.3.1 2009.06.11 -
                      Authentium 5.1.2.4 2009.06.10 -
                      Avast 4.8.1335.0 2009.06.10 -
                      AVG 8.5.0.339 2009.06.10 -
                      BitDefender 7.2 2009.06.11 -
                      CAT-QuickHeal 10.00 2009.06.11 -
                      ClamAV 0.94.1 2009.06.10 -
                      Comodo 1310 2009.06.11 -
                      DrWeb 5.0.0.12182 2009.06.11 -
                      eSafe 7.0.17.0 2009.06.10 -
                      eTrust-Vet 31.6.6552 2009.06.11 -
                      F-Prot 4.4.4.56 2009.06.10 -
                      F-Secure 8.0.14470.0 2009.06.11 -
                      Fortinet 3.117.0.0 2009.06.11 -
                      GData 19 2009.06.11 -
                      Ikarus T3.1.1.59.0 2009.06.11 -
                      K7AntiVirus 7.10.760 2009.06.10 -
                      Kaspersky 7.0.0.125 2009.06.11 -
                      McAfee 5642 2009.06.10 -
                      McAfee+Artemis 5642 2009.06.10 -
                      McAfee-GW-Edition 6.7.6 2009.06.11 -
                      Microsoft 1.4701 2009.06.11 -
                      NOD32 4146 2009.06.11 -
                      Norman 6.01.09 2009.06.10 -
                      nProtect 2009.1.8.0 2009.06.11 -
                      Panda 10.0.0.14 2009.06.10 -
                      PCTools 4.4.2.0 2009.06.11 -
                      Prevx 3.0 2009.06.11 -
                      Rising 21.33.30.00 2009.06.11 -
                      Sophos 4.42.0 2009.06.11 -
                      Sunbelt 3.2.1858.2 2009.06.11 -
                      Symantec 1.4.4.12 2009.06.11 -
                      TheHacker 6.3.4.3.343 2009.06.10 -
                      TrendMicro 8.950.0.1092 2009.06.11 -
                      VBA32 3.12.10.7 2009.06.11 -
                      ViRobot 2009.6.10.1779 2009.06.10 -
                      Information additionnelle
                      File size: 8506 bytes
                      MD5...: 9fe656580fb6f8136def49c11d1e77c0
                      SHA1..: a02f094515cb79c712f7beb9b7c3fca66c2f80fd
                      SHA256: 0593605eb3ebd0255bec0334857d56d8ff9d7284deb7daee5197bbcb0ff7b4e9
                      ssdeep: -
                      PEiD..: -
                      TrID..: File type identification
                      Generic XML (ASCII) (100.0%)
                      PEInfo: -
                      PDFiD.: -
                      RDS...: NSRL Reference Data Set
                      -
                      1. Le second:Fichier ZB20070222105249001.xml reçu le 2009.06.11 05:14:41 (UTC)
                        Situation actuelle: terminé
                        Résultat: 0/39 (0%)
                        Formaté
                        Impression des résultats
                        Antivirus Version Dernière mise à jour Résultat
                        a-squared 4.5.0.18 2009.06.11 -
                        AhnLab-V3 5.0.0.2 2009.06.11 -
                        AntiVir 7.9.0.183 2009.06.10 -
                        Antiy-AVL 2.0.3.1 2009.06.11 -
                        Authentium 5.1.2.4 2009.06.10 -
                        Avast 4.8.1335.0 2009.06.10 -
                        AVG 8.5.0.339 2009.06.10 -
                        BitDefender 7.2 2009.06.11 -
                        CAT-QuickHeal 10.00 2009.06.11 -
                        ClamAV 0.94.1 2009.06.10 -
                        Comodo 1310 2009.06.11 -
                        DrWeb 5.0.0.12182 2009.06.11 -
                        eSafe 7.0.17.0 2009.06.10 -
                        eTrust-Vet 31.6.6552 2009.06.11 -
                        F-Prot 4.4.4.56 2009.06.10 -
                        F-Secure 8.0.14470.0 2009.06.11 -
                        Fortinet 3.117.0.0 2009.06.11 -
                        GData 19 2009.06.11 -
                        Ikarus T3.1.1.59.0 2009.06.11 -
                        K7AntiVirus 7.10.760 2009.06.10 -
                        Kaspersky 7.0.0.125 2009.06.11 -
                        McAfee 5642 2009.06.10 -
                        McAfee+Artemis 5642 2009.06.10 -
                        McAfee-GW-Edition 6.7.6 2009.06.11 -
                        Microsoft 1.4701 2009.06.11 -
                        NOD32 4146 2009.06.11 -
                        Norman 6.01.09 2009.06.10 -
                        nProtect 2009.1.8.0 2009.06.11 -
                        Panda 10.0.0.14 2009.06.10 -
                        PCTools 4.4.2.0 2009.06.11 -
                        Prevx 3.0 2009.06.11 -
                        Rising 21.33.30.00 2009.06.11 -
                        Sophos 4.42.0 2009.06.11 -
                        Sunbelt 3.2.1858.2 2009.06.11 -
                        Symantec 1.4.4.12 2009.06.11 -
                        TheHacker 6.3.4.3.343 2009.06.10 -
                        TrendMicro 8.950.0.1092 2009.06.11 -
                        VBA32 3.12.10.7 2009.06.11 -
                        ViRobot 2009.6.10.1779 2009.06.10 -
                        Information additionnelle
                        File size: 527 bytes
                        MD5...: 32b332d81012ef989025e8a57f4a7fbe
                        SHA1..: 29d3f586dde509711c4fb004341d7b81b8b33ed8
                        SHA256: 16294323244a9a5d13d4eb0aec517bf2b9a87b1d862baa89d27ef2b8d5938535
                        ssdeep: -
                        PEiD..: -
                        TrID..: File type identification
                        Generic XML (ASCII) (100.0%)
                        PEInfo: -
                        PDFiD.: -
                        RDS...: NSRL Reference Data Set
                        -
                        1. Le dernierFichier ZB20090524201614001.xml reçu le 2009.06.11 05:16:52 (UTC)
                          Situation actuelle: terminé
                          Résultat: 0/39 (0%)
                          Formaté
                          Impression des résultats
                          Antivirus Version Dernière mise à jour Résultat
                          a-squared 4.5.0.18 2009.06.11 -
                          AhnLab-V3 5.0.0.2 2009.06.11 -
                          AntiVir 7.9.0.183 2009.06.10 -
                          Antiy-AVL 2.0.3.1 2009.06.11 -
                          Authentium 5.1.2.4 2009.06.10 -
                          Avast 4.8.1335.0 2009.06.10 -
                          AVG 8.5.0.339 2009.06.10 -
                          BitDefender 7.2 2009.06.11 -
                          CAT-QuickHeal 10.00 2009.06.11 -
                          ClamAV 0.94.1 2009.06.10 -
                          Comodo 1310 2009.06.11 -
                          DrWeb 5.0.0.12182 2009.06.11 -
                          eSafe 7.0.17.0 2009.06.10 -
                          eTrust-Vet 31.6.6552 2009.06.11 -
                          F-Prot 4.4.4.56 2009.06.10 -
                          F-Secure 8.0.14470.0 2009.06.11 -
                          Fortinet 3.117.0.0 2009.06.11 -
                          GData 19 2009.06.11 -
                          Ikarus T3.1.1.59.0 2009.06.11 -
                          K7AntiVirus 7.10.760 2009.06.10 -
                          Kaspersky 7.0.0.125 2009.06.11 -
                          McAfee 5642 2009.06.10 -
                          McAfee+Artemis 5642 2009.06.10 -
                          McAfee-GW-Edition 6.7.6 2009.06.11 -
                          Microsoft 1.4701 2009.06.11 -
                          NOD32 4146 2009.06.11 -
                          Norman 6.01.09 2009.06.10 -
                          nProtect 2009.1.8.0 2009.06.11 -
                          Panda 10.0.0.14 2009.06.10 -
                          PCTools 4.4.2.0 2009.06.11 -
                          Prevx 3.0 2009.06.11 -
                          Rising 21.33.30.00 2009.06.11 -
                          Sophos 4.42.0 2009.06.11 -
                          Sunbelt 3.2.1858.2 2009.06.11 -
                          Symantec 1.4.4.12 2009.06.11 -
                          TheHacker 6.3.4.3.343 2009.06.10 -
                          TrendMicro 8.950.0.1092 2009.06.11 -
                          VBA32 3.12.10.7 2009.06.11 -
                          ViRobot 2009.6.10.1779 2009.06.10 -
                          Information additionnelle
                          File size: 2208 bytes
                          MD5...: e7c6bb868068d3884052c217d3ba2e22
                          SHA1..: 16ca4c251f955534f602d00614bd16cde43b6ba3
                          SHA256: 74ff3436a8c35ac868da5b1609547c468fd191e7d4efd2c57fd0c421f42555c4
                          ssdeep: -
                          PEiD..: -
                          TrID..: File type identification
                          Generic XML (ASCII) (100.0%)
                          PEInfo: -
                          PDFiD.: -
                          RDS...: NSRL Reference Data Set
                          -

                          Voila.
                          En fait jetico marchait. C'est juste l'avertissement de windows...J'ai coché que je gérais moi meme le pare feu.
                          1. Contributeur sécurité
                            salut,

                            J'ai coché que je gérais moi meme le pare feu.

                            > très bien ... mais il faut bien que le pare-feu de windows soit désactivé ! ...

                            rien du côté de VT ... on poursuit :

                            Télécharge MalwareByte's :
                            ici http://www.commentcamarche.net/telecharger/telecharger 34055379 malwarebytes anti malware
                            ou ici : http://www.malwarebytes.org/mbam.php

                            * Installe le ( choisis bien "francais" ; ne modifie pas les paramètres d'instale ) et mets le à jour .

                            (NB : S'il te manque "COMCTL32.OCX" lors de l'installe, alors télécharge le ici : https://www.malekal.com/tutorial-aboutbuster/ )

                            * Potasse le tuto pour te familiariser avec le prg :
                            https://forum.pcastuces.com/sujet.asp?f=31&s=3
                            ( cela dis, il est très simple d'utilisation ).

                            ! Déconnecte toi et ferme toutes applications en cours !

                            * Lance Malwarebyte's .

                            Fais un examen dit "Rapide" .

                            --> Laisse le programme travailler ( et ne rien faire d'autre avec le PC durant le scan ).
                            --> à la fin tu cliques sur "résultat" .
                            --> Vérifie que tous les objets infectés soient validés, puis clique sur " suppression " .

                            Note : si il faut redémarrer ton PC pour finir le nettoyage, fais le !

                            Poste le rapport sauvegardé après la suppression des objets infectés (dans l'onglet "rapport/log"de Malwarebytes, le dernier en date),
                            accompagné d'un nouveau rapport RSIT (log.txt) pour analyse ...

                            1. J'ai bien désactivé le pare feu de windows (le mien est actif puisqu'il m'a signalé que malwrebytes voulait se connecter au web)
                              Voici le rapport aprés analyse et nettoyage:Malwarebytes' Anti-Malware 1.37
                              Version de la base de données: 2261
                              Windows 5.1.2600 Service Pack 3

                              11/06/2009 11:28:03
                              mbam-log-2009-06-11 (11-28-03).txt

                              Type de recherche: Examen rapide
                              Eléments examinés: 91781
                              Temps écoulé: 4 minute(s), 23 second(s)

                              Processus mémoire infecté(s): 0
                              Module(s) mémoire infecté(s): 0
                              Clé(s) du Registre infectée(s): 6
                              Valeur(s) du Registre infectée(s): 0
                              Elément(s) de données du Registre infecté(s): 0
                              Dossier(s) infecté(s): 0
                              Fichier(s) infecté(s): 1

                              Processus mémoire infecté(s):
                              (Aucun élément nuisible détecté)

                              Module(s) mémoire infecté(s):
                              (Aucun élément nuisible détecté)

                              Clé(s) du Registre infectée(s):
                              HKEY_CLASSES_ROOT\TypeLib\{d724f038-df89-4a1a-83d1-fd9164b78077} (Rogue.BulletProofSpyware) -> Quarantined and deleted successfully.
                              HKEY_CLASSES_ROOT\Interface\{502f728b-67b8-409e-bceb-7ee8632f321a} (Rogue.BulletProofSpyware) -> Quarantined and deleted successfully.
                              HKEY_CLASSES_ROOT\Interface\{d2cd81e5-cc37-44b3-93b7-c52cb993ba34} (Rogue.BulletProofSpyware) -> Quarantined and deleted successfully.
                              HKEY_CLASSES_ROOT\Interface\{da295dae-fce7-4168-bcb8-edc3a433bd97} (Rogue.BulletProofSpyware) -> Quarantined and deleted successfully.
                              HKEY_CLASSES_ROOT\Interface\{ed40af28-f03f-492a-9542-e24945cd65aa} (Rogue.BulletProofSpyware) -> Quarantined and deleted successfully.
                              HKEY_CLASSES_ROOT\CLSID\{e6bb8b70-8ad2-43b6-a952-83e462ce80de} (Rogue.BulletProofSpyware) -> Quarantined and deleted successfully.

                              Valeur(s) du Registre infectée(s):
                              (Aucun élément nuisible détecté)

                              Elément(s) de données du Registre infecté(s):
                              (Aucun élément nuisible détecté)

                              Dossier(s) infecté(s):
                              (Aucun élément nuisible détecté)

                              Fichier(s) infecté(s):
                              c:\WINDOWS\SYSTEM32\bpssc1.1.dll (Rogue.BulletProofSpyware) -> Quarantined and deleted successfully.
                              1. Contributeur sécurité
                                bien ...

                                la suite dans l'ordre :

                                1- Supprime tout ce qui se trouve dans la quarantaine de Malwarebytes .

                                =======================

                                2- Télécharge CCleaner :
                                http://www.commentcamarche.net/telecharger/telecharger 168 ccleaner
                                ou https://www.pcastuces.com/logitheque/ccleaner.htm
                                Ce logiciel va permettre de supprimer tous les fichiers temporaires et de corriger ton registre .
                                Lors de l'installation:
                                -choisis bien "français" en langue .
                                -avant de cliquer sur le bouton "installer", décoche toutes les "options supplémentaires" sauf les 2 premières.

                                Un tuto ( aide ):
                                http://perso.orange.fr/jesses/Docs/Logiciels/CCleaner.htm

                                ---> Utilisation:
                                *Décocher dans le menu Options - sous-menu Avancé :
                                Effacer uniquement les fichiers, du dossier temp de Windows, plus vieux que 48 heures .

                                ! déconnecte toi et ferme toutes applications en cours !

                                * va dans "nettoyeur" : fais -analyse- puis -nettoyage-
                                * va dans "registre" : fais -chercher les erreurs- et -réparer toutes les erreurs-
                                ( plusieurs fois jusqu'à ce qu'il n'y est plus d'erreur ) .

                                ( CCleaner : soft à garder sur son PC , super utile pour de bons nettoyages ... )

                                ======================

                                3- Télécharge ComboFix (par sUBs) sur ton Bureau (et pas ailleurs !):

                                http://download.bleepingcomputer.com/sUBs/ComboFix.exe

                                --------------------------------- [ ! ATTENTION ! ] ------------------------------------------
                                !! Déconnecte toi,ferme tes applications en cours ( ainsi que ton navigateur ) et DESACTIVE TOUTES TES DEFENSES (anti-virus, guarde anti spy-ware, pare-feu) le temps de la manipe :
                                en effet , activés, ils pourraient gêner fortement la procédure de recherche et de nettoyage de l'outil ( voir planter le PC )...Tu les réactiveras donc après !!
                                --->Important : si tu rencontres des difficultés à ce niveau là, fais m'en part avant de poursuivre ...
                                Tuto ( aide ) ici : https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix
                                Note : pour XP, bien installer la Console de Récupération de Windows comme il est indiqué dans le tuto ci-dessus ...
                                --------------------------------------------------------------------------------------------

                                Ensuite :
                                double-clique sur l'icône "combofix.exe" pour lancer l'outil .

                                Appuie sur la touche Y (Yes) pour démarrer le scan .

                                Notes importantes :
                                -> n'utilise pas ta souris ni ton clavier (ni un autre système de pointage) pendant que le programme tourne. Cela pourrait figer l'ordi .
                                -> Il se peut que le PC redémarre de lui même ( pour finaliser le nettoyage ) , laisse le faire .
                                -> Si l'outil t'anonce ceci : "combofix a détecté la présence de rootkit et a besoin de faire redémarer votre machine", tu acceptes ...
                                -> si un message d'erreur windows apparait à un momment : clique sur la croix rouge en haut à droite de la fenêtre pour la fermer ( et pas sur autre chose ! sinon pas de rapport ... )

                                Le rapport sera crée ici : C:\Combofix.txt

                                Réactive bien tes défenses .

                                Poste le rapport Combofix pour analyse ...

                                1. le rapport:ComboFix 09-06-10.02 - gil 11/06/2009 12:03.1 - NTFSx86
                                  Microsoft Windows XP Édition familiale 5.1.2600.3.1252.33.1036.18.1022.565 [GMT 2:00]
                                  Lancé depuis: c:\documents and settings\gil\Bureau\ComboFix.exe
                                  AV: avast! antivirus 4.8.1335 [VPS 090610-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
                                  .

                                  (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
                                  .

                                  c:\windows\Downloaded Program Files\rave
                                  c:\windows\Downloaded Program Files\rave\avirexe.vdm
                                  c:\windows\Downloaded Program Files\rave\avirscr.vdm
                                  c:\windows\Downloaded Program Files\rave\base.vdm
                                  c:\windows\Downloaded Program Files\rave\daily.vdm
                                  c:\windows\Downloaded Program Files\rave\daily.vdt
                                  c:\windows\Downloaded Program Files\rave\filters.vdm
                                  c:\windows\Downloaded Program Files\rave\kernel.vdk
                                  c:\windows\Downloaded Program Files\rave\keyring.vdk
                                  c:\windows\Downloaded Program Files\rave\mapi_vdm.vdm
                                  c:\windows\Downloaded Program Files\rave\modules.vdk
                                  c:\windows\Downloaded Program Files\rave\rav8def.vdm
                                  c:\windows\Downloaded Program Files\rave\rufs.vdm
                                  c:\windows\Downloaded Program Files\rave\rufsplg.vdm
                                  c:\windows\Downloaded Program Files\rave\unarch.vdm
                                  c:\windows\Downloaded Program Files\rave\unmail.vdm
                                  c:\windows\Downloaded Program Files\rave\unpack.vdm
                                  c:\windows\patch.exe
                                  c:\windows\system32\dumphive.exe
                                  c:\windows\system32\SrchSTS.exe
                                  c:\windows\system32\tmp.reg
                                  c:\windows\system32\VCCLSID.exe

                                  .
                                  ((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
                                  .

                                  -------\Legacy_WINDOWS_LOG

                                  ((((((((((((((((((((((((((((( Fichiers créés du 2009-05-11 au 2009-06-11 ))))))))))))))))))))))))))))))))))))
                                  .

                                  2009-06-10 17:19 . 2009-06-10 17:52 -------- d-----w- C:\UsbFix
                                  2009-06-10 15:10 . 2009-06-10 15:10 -------- d-----w- C:\rsit
                                  2009-06-10 15:05 . 2009-06-10 15:05 -------- d-----w- c:\program files\Trend Micro
                                  2009-06-10 14:40 . 2009-06-10 14:40 -------- d-sh--w- c:\documents and settings\gil\PrivacIE
                                  2009-06-10 06:42 . 2009-06-10 06:42 -------- d-sh--w- c:\documents and settings\gil\IETldCache
                                  2009-06-10 06:32 . 2009-04-30 21:16 12800 ------w- c:\windows\system32\dllcache\xpshims.dll
                                  2009-06-10 06:32 . 2009-04-30 21:16 246272 ------w- c:\windows\system32\dllcache\ieproxy.dll
                                  2009-06-10 06:32 . 2009-06-10 06:33 -------- d-----w- c:\windows\ie8updates
                                  2009-06-10 06:31 . 2009-05-12 05:11 102912 ------w- c:\windows\system32\dllcache\iecompat.dll
                                  2009-06-10 06:28 . 2009-06-10 06:31 -------- dc-h--w- c:\windows\ie8
                                  2009-05-28 19:08 . 2009-05-28 19:08 -------- d-----w- c:\program files\10TACLE STUDIOS

                                  .
                                  (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                                  .
                                  2009-06-11 10:09 . 2007-01-10 17:50 -------- d-----w- c:\program files\Wanadoo
                                  2009-06-11 09:08 . 2008-12-29 06:47 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
                                  2009-06-10 09:25 . 2009-02-11 16:51 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater
                                  2009-06-01 13:50 . 2009-02-07 07:04 -------- d-----w- c:\program files\FoxTarot4
                                  2009-05-26 20:57 . 2006-01-02 17:54 31374 ----a-w- c:\documents and settings\gil\Application Data\wklnhst.dat
                                  2009-05-26 11:20 . 2008-12-29 06:47 40160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
                                  2009-05-26 11:19 . 2008-12-29 06:47 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
                                  2009-05-13 20:06 . 2008-06-20 13:09 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
                                  2009-05-13 05:04 . 2004-08-05 12:00 915456 ----a-w- c:\windows\system32\wininet.dll
                                  2009-04-17 04:37 . 2005-01-13 02:15 78786 ----a-w- c:\windows\system32\perfc00C.dat
                                  2009-04-17 04:37 . 2005-01-13 02:15 478622 ----a-w- c:\windows\system32\perfh00C.dat
                                  2008-06-05 14:17 . 2008-06-05 14:17 15397 ----a-w- c:\program files\settings.dat
                                  2008-04-14 02:33 . 2004-08-05 12:00 1028096 --sha-w- c:\windows\SYSTEM32\mfc42.dll
                                  2004-08-05 12:00 . 2004-08-05 12:00 57344 --sha-w- c:\windows\SYSTEM32\MFC42LOC.DLL
                                  2008-04-14 02:33 . 2004-08-05 12:00 413696 --sha-w- c:\windows\SYSTEM32\msvcp60.dll
                                  2008-04-14 02:33 . 2004-08-05 12:00 343040 --sha-w- c:\windows\SYSTEM32\msvcrt.dll
                                  2004-08-05 12:00 . 2004-08-05 12:00 253952 --sha-w- c:\windows\SYSTEM32\MSVCRT20.DLL
                                  2008-04-14 02:33 . 2004-08-05 12:00 30749 --sha-w- c:\windows\SYSTEM32\vbajet32.dll
                                  .

                                  ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
                                  .
                                  .
                                  *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
                                  REGEDIT4

                                  [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                  "WOOKIT"="c:\progra~1\Wanadoo\Shell.exe" [2004-08-23 122880]
                                  "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
                                  "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-11-03 204288]

                                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                  "SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2004-10-14 1404928]
                                  "ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-30 344064]
                                  "IntelMeM"="c:\program files\Intel\Modem Event Monitor\IntelMEM.exe" [2003-09-03 221184]
                                  "dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-08-13 122939]
                                  "UpdateManager"="c:\program files\Fichiers communs\Sonic\Update Manager\sgtray.exe" [2004-01-07 110592]
                                  "WOOWATCH"="c:\progra~1\Wanadoo\Watch.exe" [2004-08-23 20480]
                                  "WOOTASKBARICON"="c:\progra~1\Wanadoo\GestMaj.exe" [2004-10-14 32768]
                                  "avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
                                  "JeticoPFStartup"="c:\program files\Jetico\Jetico Personal Firewall\fwsrv.exe" [2005-07-19 118784]
                                  "PinnacleDriverCheck"="c:\windows\system32\\PSDrvCheck.exe" [2004-03-10 406016]
                                  "BigDog305"="c:\windows\VM305_STI.EXE" [2005-08-05 61440]
                                  "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]

                                  [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
                                  "{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2006-03-13 233472]

                                  [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
                                  "mixer"=DrvTrNTm.dll
                                  "wave"=DrvTrNTm.dll

                                  [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
                                  SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, zwebauth.dll

                                  [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Microsoft Office.lnk]
                                  path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Microsoft Office.lnk
                                  backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

                                  [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Windows Desktop Search.lnk]
                                  path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Windows Desktop Search.lnk
                                  backup=c:\windows\pss\Windows Desktop Search.lnkCommon Startup

                                  [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
                                  "Netman"=3 (0x3)

                                  [HKEY_LOCAL_MACHINE\software\microsoft\security center]
                                  "FirewallOverride"=dword:00000001

                                  [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
                                  "EnableFirewall"= 0 (0x0)

                                  [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
                                  "%windir%\\system32\\sessmgr.exe"=
                                  "c:\\Program Files\\Messenger\\MSMSGS.EXE"=
                                  "c:\\WINDOWS\\SYSTEM32\\RTCSHARE.EXE"=
                                  "c:\\WINDOWS\\PCHEALTH\\HELPCTR\\BINARIES\\HelpCtr.exe"=
                                  "c:\\Program Files\\NetMeeting\\CONF.EXE"=
                                  "c:\\Program Files\\Skype\\Phone\\Skype.exe"=
                                  "c:\\WINDOWS\\system32\\svchost.exe"=
                                  "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
                                  "c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
                                  "c:\\Program Files\\MSN Messenger\\livecall.exe"=

                                  R1 aswSP;avast! Self Protection;c:\windows\SYSTEM32\DRIVERS\aswSP.sys [05/04/2008 07:49 114768]
                                  R2 aswFsBlk;aswFsBlk;c:\windows\SYSTEM32\DRIVERS\aswFsBlk.sys [05/04/2008 07:49 20560]
                                  R2 edsvc;Edison Power Management Service;c:\program files\Verdiem\Edison\edsvc.exe [24/10/2008 11:00 75008]
                                  R3 ZSMC0305;VIMICRO USB PC Camera V;c:\windows\SYSTEM32\DRIVERS\usbVM305.sys [24/02/2007 11:30 392316]
                                  S2 gupdate1c98c69280a00ee;Google Update Service (gupdate1c98c69280a00ee);c:\program files\Google\Update\GoogleUpdate.exe [11/02/2009 18:52 133104]
                                  S3 alcan5ln;SpeedTouch(tm) USB ADSL RFC1483 Networking Driver (NDIS);c:\windows\SYSTEM32\DRIVERS\alcan5ln.sys [19/01/2005 19:30 36256]
                                  S3 Camdrv30;Philips ToUcam XS;c:\windows\SYSTEM32\DRIVERS\camdrv30.sys [16/03/2005 19:54 171264]
                                  S3 cel90xbe;cel90xbe;\??\c:\docume~1\gil\LOCALS~1\Temp\cel90xbe.sys --> c:\docume~1\gil\LOCALS~1\Temp\cel90xbe.sys [?]
                                  S3 phil2vid;Appareil photo VGA USB Philips PCVC690;c:\windows\SYSTEM32\DRIVERS\philcam2.sys [19/01/2005 20:13 173696]

                                  [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
                                  "c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
                                  .
                                  Contenu du dossier 'Tâches planifiées'

                                  2009-06-11 c:\windows\Tasks\Google Software Updater.job
                                  - c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-02-11 11:40]

                                  2009-06-11 c:\windows\Tasks\GoogleUpdateTaskMachine.job
                                  - c:\program files\Google\Update\GoogleUpdate.exe [2009-02-11 16:52]

                                  2005-01-20 c:\windows\Tasks\Rappel d'abonnement 1 auprès de l'ISP.job
                                  - c:\windows\system32\OOBE\OOBEBALN.EXE [2004-08-05 02:34]

                                  2009-06-11 c:\windows\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job
                                  - c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 10:20]
                                  .
                                  - - - - ORPHELINS SUPPRIMES - - - -

                                  HKCU-Run-FAST Defrag - (no file)
                                  HKU-Default-Run-Nokia.PCSync - c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe

                                  .
                                  ------- Examen supplémentaire -------
                                  .
                                  uSearchMigratedDefaultURL = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
                                  mWindow Title =
                                  uInternet Connection Wizard,ShellNext = iexplore
                                  IE: &ICQ Toolbar Search - c:\program files\ICQToolbar\toolbaru.dll/SEARCH.HTML
                                  IE: &MSN Search - c:\program files\MSN Toolbar Suite\TB\[u]0/u2.05.0000.1105\fr-fr\msntb.dll/search.htm
                                  IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
                                  IE: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
                                  IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
                                  IE: Ouvrir dans un nouvel onglet d'arrière-plan - c:\program files\MSN Toolbar Suite\TAB\[u]0/u2.05.0000.1105\fr-fr\msntabres.dll/229?b3e1df636c6a408fb85f84ade9356ed8
                                  IE: Ouvrir dans un nouvel onglet de premier plan - c:\program files\MSN Toolbar Suite\TAB\[u]0/u2.05.0000.1105\fr-fr\msntabres.dll/230?b3e1df636c6a408fb85f84ade9356ed8
                                  DPF: {1F83CD9E-505E-4F87-BECE-0832A763E36F} - hxxp://www.mypixmania.com/fr/fr/importer/MypixUploader.cab
                                  DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - hxxp://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
                                  DPF: {952F9A71-131A-11D5-8404-00500445A7D0} - hxxps://intranet.unss.org/plugins/mplugax.cab
                                  FF - ProfilePath -
                                  .

                                  **************************************************************************

                                  catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                                  Rootkit scan 2009-06-11 12:08
                                  Windows 5.1.2600 Service Pack 3 NTFS

                                  Recherche de processus cachés ...

                                  Recherche d'éléments en démarrage automatique cachés ...

                                  HKLM\Software\Microsoft\Windows\CurrentVersion\Run
                                  BigDog305 = c:\windows\VM305_STI.EXE VIMICRO USB PC Camera (ZC0305)???????????????????0?????????@??????????????

                                  Recherche de fichiers cachés ...

                                  Scan terminé avec succès
                                  Fichiers cachés: 0

                                  **************************************************************************
                                  .
                                  --------------------- CLES DE REGISTRE BLOQUEES ---------------------

                                  [HKEY_USERS\S-1-5-21-222213514-3847136095-315394647-1006\Software\Microsoft\SystemCertificates\AddressBook*]
                                  @Allowed: (Read) (RestrictedCode)
                                  @Allowed: (Read) (RestrictedCode)

                                  [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32*]
                                  "ThreadingModel"="Apartment"
                                  @="c:\\WINDOWS\\system32\\OLE32.DLL"
                                  "cd042efbbd7f7af1647644e76e06692b"=hex:2e,e8,e1,00,eb,16,2b,de,71,44,ea,1c,46,
                                  84,ca,a0,c8,28,51,af,b0,29,a3,98,16,29,89,3c,89,c1,fb,4b,e2,63,26,f1,3f,c8,\

                                  [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32*]
                                  "ThreadingModel"="Apartment"
                                  @="c:\\WINDOWS\\system32\\OLE32.DLL"
                                  "bca643cdc5c2726b20d2ecedcc62c59b"=hex:6a,9c,d6,61,af,45,84,18,26,d0,f9,b0,30,
                                  cf,64,e8,71,3b,04,66,8b,46,0d,96,20,5c,e1,f1,38,2b,e3,d6,6a,9c,d6,61,af,45,\

                                  [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32*]
                                  "ThreadingModel"="Apartment"
                                  @="c:\\WINDOWS\\system32\\OLE32.DLL"
                                  "2c81e34222e8052573023a60d06dd016"=hex:ff,7c,85,e0,43,d4,0e,fe,4e,bb,f9,da,f1,
                                  35,2e,86,25,da,ec,7e,55,20,c9,26,68,c6,da,fa,a9,c4,ae,1d,ff,7c,85,e0,43,d4,\

                                  [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32*]
                                  "ThreadingModel"="Apartment"
                                  @="c:\\WINDOWS\\system32\\OLE32.DLL"
                                  "2582ae41fb52324423be06337561aa48"=hex:3e,1e,9e,e0,57,5a,93,61,bb,80,c8,ed,12,
                                  31,c7,26,3e,1e,9e,e0,57,5a,93,61,ea,e8,ad,3b,51,46,ae,80,86,8c,21,01,be,91,\

                                  [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32*]
                                  "ThreadingModel"="Apartment"
                                  @="c:\\WINDOWS\\system32\\OLE32.DLL"
                                  "caaeda5fd7a9ed7697d9686d4b818472"=hex:cd,44,cd,b9,a6,33,6c,cd,81,66,2e,e5,5e,
                                  e4,c0,ec,cd,44,cd,b9,a6,33,6c,cd,ca,e2,a5,8d,37,4d,13,0b,f5,1d,4d,73,a8,13,\

                                  [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32*]
                                  "ThreadingModel"="Apartment"
                                  @="c:\\WINDOWS\\system32\\OLE32.DLL"
                                  "a4a1bcf2cc2b8bc3716b74b2b4522f5d"=hex:df,20,58,62,78,6b,cf,c8,55,bf,9a,07,23,
                                  67,10,c2,b0,18,ed,a7,3f,8d,37,a4,a1,0d,df,2f,e9,5b,c1,cf,df,20,58,62,78,6b,\

                                  [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32*]
                                  "ThreadingModel"="Apartment"
                                  @="c:\\WINDOWS\\system32\\OLE32.DLL"
                                  "4d370831d2c43cd13623e232fed27b7b"=hex:fb,a7,78,e6,12,2f,9a,ea,61,95,15,e0,4a,
                                  f1,46,08,31,77,e1,ba,b1,f8,68,02,9f,31,5f,1e,7f,03,bf,a2,fb,a7,78,e6,12,2f,\

                                  [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32*]
                                  "ThreadingModel"="Apartment"
                                  @="c:\\WINDOWS\\system32\\OLE32.DLL"
                                  "1d68fe701cdea33e477eb204b76f993d"=hex:01,3a,48,fc,e8,04,4a,f1,c6,97,73,0b,4d,
                                  a6,46,c4,83,6c,56,8b,a0,85,96,ab,ec,c1,f8,06,7f,a6,f7,db,01,3a,48,fc,e8,04,\

                                  [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32*]
                                  "ThreadingModel"="Apartment"
                                  @="c:\\WINDOWS\\system32\\OLE32.DLL"
                                  "1fac81b91d8e3c5aa4b0a51804d844a3"=hex:51,fa,6e,91,28,9e,14,cc,08,2c,5a,f7,9f,
                                  a9,6a,a9,51,fa,6e,91,28,9e,14,cc,e3,68,a9,15,d4,ae,27,fb,f6,0f,4e,58,98,5b,\

                                  [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32*]
                                  "ThreadingModel"="Apartment"
                                  @="c:\\WINDOWS\\system32\\OLE32.DLL"
                                  "f5f62a6129303efb32fbe080bb27835b"=hex:b1,cd,45,5a,a8,c4,f8,b9,6c,24,83,a9,22,
                                  5f,21,ae,b1,cd,45,5a,a8,c4,f8,b9,c9,d4,9f,d1,9b,d9,2f,06,3d,ce,ea,26,2d,45,\

                                  [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32*]
                                  "ThreadingModel"="Apartment"
                                  @="c:\\WINDOWS\\system32\\OLE32.DLL"
                                  "fd4e2e1a3940b94dceb5a6a021f2e3c6"=hex:2a,b7,cc,b5,b9,7f,41,e7,93,cf,46,e6,09,
                                  74,19,08,e3,0e,66,d5,eb,bc,2f,6b,06,ca,63,af,a4,e3,b7,14,2a,b7,cc,b5,b9,7f,\

                                  [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32*]
                                  "ThreadingModel"="Apartment"
                                  @="c:\\WINDOWS\\system32\\OLE32.DLL"
                                  "8a8aec57dd6508a385616fbc86791ec2"=hex:05,73,21,dd,54,d8,4a,c5,f3,5f,1a,67,2a,
                                  50,d5,98,fa,ea,66,7f,d4,3b,6b,70,0e,e0,4a,0b,7c,b7,31,9c,6c,43,2d,1e,aa,22,\
                                  .
                                  --------------------- DLLs chargées dans les processus actifs ---------------------

                                  - - - - - - - > 'winlogon.exe'(768)
                                  c:\windows\system32\Ati2evxx.dll

                                  - - - - - - - > 'explorer.exe'(3224)
                                  c:\windows\system32\eappprxy.dll
                                  c:\windows\system32\webcheck.dll
                                  c:\windows\system32\WPDShServiceObj.dll
                                  c:\program files\Nokia\Nokia PC Suite 7\PhoneBrowser.dll
                                  c:\program files\Nokia\Nokia PC Suite 7\NGSCM.DLL
                                  c:\program files\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_fre.nlr
                                  c:\program files\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr
                                  c:\windows\system32\PortableDeviceTypes.dll
                                  c:\windows\system32\PortableDeviceApi.dll
                                  .
                                  ------------------------ Autres processus actifs ------------------------
                                  .
                                  c:\windows\SYSTEM32\ati2evxx.exe
                                  c:\program files\Alwil Software\Avast4\aswUpdSv.exe
                                  c:\program files\Alwil Software\Avast4\ashServ.exe
                                  c:\windows\SYSTEM32\ati2evxx.exe
                                  c:\windows\SYSTEM32\LEXBCES.EXE
                                  c:\windows\SYSTEM32\LEXPPS.EXE
                                  c:\windows\SYSTEM32\FTRTSVC.exe
                                  c:\program files\Java\jre6\bin\jqs.exe
                                  c:\program files\Windows Media Player\wmpnetwk.exe
                                  c:\program files\Alwil Software\Avast4\ashMaiSv.exe
                                  c:\program files\Alwil Software\Avast4\ashWebSv.exe
                                  c:\progra~1\Wanadoo\TaskBarIcon.exe
                                  c:\windows\SYSTEM32\wscntfy.exe
                                  .
                                  **************************************************************************
                                  .
                                  Heure de fin: 2009-06-11 12:13 - La machine a redémarré
                                  ComboFix-quarantined-files.txt 2009-06-11 10:13

                                  Avant-CF: 26 730 233 856 octets libres
                                  Après-CF: 26 599 673 856 octets libres

                                  WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe
                                  [boot loader]
                                  timeout=2
                                  default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
                                  [operating systems]
                                  c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
                                  multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP dition familiale" /noexecute=optin /fastdetect

                                  284 --- E O F --- 2009-06-10 06:33
                                  1. Contributeur sécurité
                                    la suite :

                                    1-Créer un doc texte sur ton bureau :
                                    pointe ta souris sur ton bureau , clique droit : va dans "nouveau" et choisis "document texte" .

                                    Ensuite copie/colle le texte ci-dessous ( et rien d'autre!) dans le fichier texte que tu viens de créer :

                                    File::
                                    c:\docume~1\gil\LOCALS~1\Temp\cel90xbe.sys

                                    Driver::
                                    cel90xbe


                                    Puis va dans "fichier" et choisis "enregistrer sous ..." et tu le nommes exactement ainsi :
                                    CFScript puis valide ...

                                    2-Nettoyage :

                                    !! Déconnecte toi, ferme toutes tes applications et désactive TOUTES TES DEFENSES ( tu les réactiveras après ) !!

                                    --->Sur ton bureau, fais glisser avec ta souris le fichier CFScript sur l'icône de ComboFix.exe .

                                    (Regarde ici : http://img.photobucket.com/albums/v666/sUBs/CFScript.gif )

                                    Cette manipulation va relancer combofix .
                                    --> Une fenêtre bleue va apparaître: au message qui apparaît "Type 1 to continue, or 2 to abort" : tape 1 puis valide.

                                    Puis patiente le temps du scan.( Le Bureau va disparaître à plusieurs reprises : c'est normal!)

                                    !! Ne touches à rien tant que le scan n'est pas terminé !!

                                    Note : en fin de scan, il est possible que ComboFix ait besoin de redémarrer le PC pour finaliser la désinfection, laisse-le faire.

                                    Une fois le scan achevé, un rapport va s'afficher : poste le pour analyse ...

                                    ( Attention : cette manipe a été fait pour ce PC . Toute réutilisation peut endommager sévèrement le système d'exploitation )

                                    1. Je bloque a cette étape:
                                      "Une fenêtre bleue va apparaître: au message qui apparaît "Type 1 to continue, or 2 to abort" : tape 1 puis valide. "
                                      En fait, lorsque je fais glisser le fichier crée sur comboFix, le programme redemarre sur l'analyse et la creation du rapport fait dans l'étape précedente.
                                      je dois sans doute faire qlq chose de mal, mais je ne sais pas quoi (2 tentatives identiques)
                                      1. Contributeur sécurité
                                        re,

                                        non c'est bon ... ^^

                                        poste moi le rapport obtenu stp ....

                                        • 1
                                        • 2
                                        • 3