Infection par virus w32/winfixer.gen!a

marcugodelire -  
 marcugodelire -
Bonjour,
je n'arrive pas à me débarrasser d'un virus, lorsque je me connecte d'autres fenêtres s'ouvrent.
Voici le rapport
info.txt logfile of random's system information tool 1.06 2009-06-22 16:44:35

======Uninstall list======

-->"C:\Program Files\Creative Installation Information\CREATIVE_MEDIASOURCE_U\Setup.exe" /remove /l0x040c
-->"C:\Program Files\Creative Installation Information\CTCMSGO\Setup.exe" /remove /l0x040c
-->"C:\Program Files\Creative Installation Information\E-CENTER_NET_CONTENT_U\Setup.exe" /remove /l0x040c
-->"C:\Program Files\Creative Installation Information\E-CENTER_PLUGIN_CDBURNER_U\Setup.exe" /remove /l0x040c
-->"C:\Program Files\Creative Installation Information\E-CENTER_PLUGIN_MINIDISC_U\Setup.exe" /remove /l0x040c
-->"C:\Program Files\Creative Installation Information\E-CENTER_PLUGIN_ONLINESTORE_U\Setup.exe" /remove /l0x040c
-->"C:\Program Files\Creative Installation Information\MEDIASOURCE_PLAYER_SKINPACK_U\Setup.exe" /remove /l0x040c
-->"C:\Program Files\Creative\SBAudigy\Program\Setup.exe" /S /U /W /L:FRN
-->"C:\Program Files\Securitoo\av_fw\Uninstall\fsuninst.exe" /UninstRegKey:"F-Secure Anti-Spyware Scanner"
-->"C:\Program Files\Securitoo\av_fw\Uninstall\fsuninst.exe" /UninstRegKey:"F-Secure Anti-Spyware"
-->"C:\Program Files\Securitoo\av_fw\Uninstall\fsuninst.exe" /UninstRegKey:"F-Secure Anti-Virus Client Security Installer"
-->"C:\Program Files\Securitoo\av_fw\Uninstall\fsuninst.exe" /UninstRegKey:"F-Secure Anti-Virus"
-->"C:\Program Files\Securitoo\av_fw\Uninstall\fsuninst.exe" /UninstRegKey:"F-Secure Automatic Update Agent"
-->"C:\Program Files\Securitoo\av_fw\Uninstall\fsuninst.exe" /UninstRegKey:"F-Secure DAAS"
-->"C:\Program Files\Securitoo\av_fw\Uninstall\fsuninst.exe" /UninstRegKey:"F-Secure DAAS2"
-->"C:\Program Files\Securitoo\av_fw\Uninstall\fsuninst.exe" /UninstRegKey:"F-Secure Diagnostics"
-->"C:\Program Files\Securitoo\av_fw\Uninstall\fsuninst.exe" /UninstRegKey:"F-Secure E-mail Scanning"
-->"C:\Program Files\Securitoo\av_fw\Uninstall\fsuninst.exe" /UninstRegKey:"F-Secure FWES"
-->"C:\Program Files\Securitoo\av_fw\Uninstall\fsuninst.exe" /UninstRegKey:"F-Secure GateKeeper Interface"
-->"C:\Program Files\Securitoo\av_fw\Uninstall\fsuninst.exe" /UninstRegKey:"F-Secure Gemini"
-->"C:\Program Files\Securitoo\av_fw\Uninstall\fsuninst.exe" /UninstRegKey:"F-Secure GUI"
-->"C:\Program Files\Securitoo\av_fw\Uninstall\fsuninst.exe" /UninstRegKey:"F-Secure Help"
-->"C:\Program Files\Securitoo\av_fw\Uninstall\fsuninst.exe" /UninstRegKey:"F-Secure HIPS"
-->"C:\Program Files\Securitoo\av_fw\Uninstall\fsuninst.exe" /UninstRegKey:"F-Secure Internet Shield"
-->"C:\Program Files\Securitoo\av_fw\Uninstall\fsuninst.exe" /UninstRegKey:"F-Secure ISP News"
-->"C:\Program Files\Securitoo\av_fw\Uninstall\fsuninst.exe" /UninstRegKey:"F-Secure Localization API"
-->"C:\Program Files\Securitoo\av_fw\Uninstall\fsuninst.exe" /UninstRegKey:"F-Secure Management Agent"
-->"C:\Program Files\Securitoo\av_fw\Uninstall\fsuninst.exe" /UninstRegKey:"F-Secure ORSP Client"
-->"C:\Program Files\Securitoo\av_fw\Uninstall\fsuninst.exe" /UninstRegKey:"F-Secure Pegasus Engine"
-->"C:\Program Files\Securitoo\av_fw\Uninstall\fsuninst.exe" /UninstRegKey:"F-Secure Protocol Scanner"
-->"C:\Program Files\Securitoo\av_fw\Uninstall\fsuninst.exe" /UninstRegKey:"F-Secure Spam Control"
-->"C:\Program Files\Securitoo\av_fw\Uninstall\fsuninst.exe" /UninstRegKey:"F-Secure Spam Scanner"
-->"C:\Program Files\Securitoo\av_fw\Uninstall\fsuninst.exe" /UninstRegKey:"F-Secure TNB"
-->"C:\Program Files\Securitoo\av_fw\Uninstall\fsuninst.exe" /UninstRegKey:"F-Secure Uninstall"
-->"C:\Program Files\ViaVoice\Bin\vunFR.exe" ProdRunDictate Dc Fr_FR 'IBM ViaVoice™ Dictation Runtime' C:\WINDOWS\IsUn040c.exe -f"C:\Program Files\ViaVoice\RtDict_FR.isu"
-->"C:\Program Files\ViaVoice\Bin\vunFR.exe" ProdRunDictate Dc Fr_FR 'IBM ViaVoice™ Dictation Runtime' C:\WINDOWS\IsUn040c.exe -f"C:\Program Files\ViaVoice\RtDict_FR.isu"
-->C:\Program Files\Ahead\nero\uninstall\UNNERO.exe /UNINSTALL
-->C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
-->C:\WINDOWS\IsUn040c.exe -f"C:\Program Files\ViaVoice\tts\vvol50Fr_FR.isu" -c"C:\Program Files\ViaVoice\tts\\vo50u_FR.dll"
-->C:\WINDOWS\UNNeroVision.exe /UNINSTALL
-->C:\WINDOWS\UNNMP.exe /UNINSTALL
-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2670895A-4E6C-4450-B868-7B7DB80A3357}\setup.exe" -l0x40c
-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2670895A-4E6C-4450-B868-7B7DB80A3357}\setup.exe" -l0x40c /remove
-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{32B4B536-4443-42F0-9676-98373BE9114F}\setup.exe" -l0x40c
-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{32B4B536-4443-42F0-9676-98373BE9114F}\setup.exe" -l0x40c /remove
-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{34EBD418-B8E6-4E86-89C4-33B72CF5663F}\setup.exe" -l0x40c
-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{34EBD418-B8E6-4E86-89C4-33B72CF5663F}\setup.exe" -l0x40c /remove
-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{52338F65-A1C3-4CDC-B733-50051682B297}\setup.exe" -l0x40c
-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{52338F65-A1C3-4CDC-B733-50051682B297}\setup.exe" -l0x40c /remove
-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{63A317D0-60A6-43FC-848A-9FE4A53B29CE}\setup.exe" -l0x40c
-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{700932B3-A964-4878-82A2-96054622A1F7}\setup.exe" -l0x40c
-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{700932B3-A964-4878-82A2-96054622A1F7}\setup.exe" -l0x40c /remove
-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{73919E2B-725C-4FAA-8473-45E063A3575F}\setup.exe" -l0x40c
-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{73919E2B-725C-4FAA-8473-45E063A3575F}\setup.exe" -l0x40c /remove
-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{84F573D3-0F71-4768-978A-D35310E3FBA6}\setup.exe" -l0x40c
-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{84F573D3-0F71-4768-978A-D35310E3FBA6}\setup.exe" -l0x40c /remove
-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{88B1984E-36F0-47B8-B8DC-728966807A9C}\SETUP.EXE" -l0x40c
-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9194237B-7B58-40B4-A739-184AD59531A2}\setup.exe" -l0x40c
-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9194237B-7B58-40B4-A739-184AD59531A2}\setup.exe" -l0x40c /remove
-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A82F10CB-18B5-4EAC-AEF2-FA49CD565626}\setup.exe" -l0x40c
-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BD6928A2-9F8F-4AA7-9A3A-FD4A271712EE}\setup.exe" -l0x40c
-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BD6928A2-9F8F-4AA7-9A3A-FD4A271712EE}\setup.exe" -l0x40c /remove
-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C64409FA-42A7-49C6-837A-D2E5D813BD57}\setup.exe" -l0x40c
-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C64409FA-42A7-49C6-837A-D2E5D813BD57}\setup.exe" -l0x40c /remove
-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{DE4A4C48-2232-4CCB-AD61-490ACD29BA85}\setup.exe" -l0x40c
-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{DE4A4C48-2232-4CCB-AD61-490ACD29BA85}\setup.exe" -l0x40c /remove
-->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
Adobe Acrobat 4.0-->C:\WINDOWS\ISUN040C.EXE -f"C:\Program Files\Fichiers communs\Adobe\Acrobat 4.0\NT\Uninst.isu" -c"C:\Program Files\Fichiers communs\Adobe\Acrobat 4.0\NT\Uninst.dll"
Adobe Flash Player 10 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Photoshop 5.0-->C:\WINDOWS\UNIN040C.EXE -f"C:\Program Files\Adobe\Photoshop 5.0\DeIsL1.isu" -c"C:\Program Files\Adobe\Photoshop 5.0\Uninst.dll"
Adobe Reader 8.1.6 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A81300000003}
adsl TV-->C:\Program Files\adslTV\Uninstal.exe
Archiveur WinRAR-->C:\Program Files\WinRAR\uninstall.exe
Assistant de connexion Windows Live-->MsiExec.exe /I{D3116CC7-24DC-4CA3-9CE1-23FED836E9F2}
CC_ccStart-->MsiExec.exe /I{D6414CC7-F215-467F-88B1-546ED863F35B}
CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
Choice Guard-->MsiExec.exe /I{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}
CODEC(NogaTech)-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5DA1C66B-EAD2-4A2A-B277-5E8710C580F8}\setup.exe"
Coffret de pilotes Logitech Legacy USB Camera-->"C:\Program Files\Fichiers communs\LogiShrd\LogiDriverStore\legacyqcam\10.00.1438\LgDrvInst.exe" -remove -instdir"C:\Program Files\Fichiers communs\LogiShrd\LogiDriverStore\legacyqcam\" -enumdelay=2000 -enabledifx -forcedelete -usbhubsfirst -forceremove -cumulativeremove -promptuninstall -arpregkey"legacyqcam_10.00" /clone_wait /hide_progress
Coffret de pilotes Logitech QuickCam-->"C:\Program Files\Fichiers communs\LogiShrd\LogiDriverStore\lvdrivers\11.90.1262\LgDrvInst.exe" -remove -instdir"C:\Program Files\Fichiers communs\LogiShrd\LogiDriverStore\lvdrivers\" -enumdelay=200 -enabledifx -forcedelete -usbhubsfirst -forceremove -cumulativeremove -promptuninstall -arpregkey"lvdrivers_11.90" /clone_wait /hide_progress
Correctif pour Lecteur Windows Media 11 (KB939683)-->"C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
Correctif pour Windows Internet Explorer 7 (KB947864)-->"C:\WINDOWS\ie7updates\KB947864-IE7\spuninst\spuninst.exe"
Correctif pour Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
Correctif pour Windows XP (KB961118)-->"C:\WINDOWS\$NtUninstallKB961118$\spuninst\spuninst.exe"
Creative MediaSource 5-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BEEFC4F8-2909-48B3-AFAA-55D3533FDEDD}\SETUP.EXE" -l0x40c /remove
Creative Software AutoUpdate-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{88B1984E-36F0-47B8-B8DC-728966807A9C}\SETUP.EXE" -l0x40c /remove
Creative System Information-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{63A317D0-60A6-43FC-848A-9FE4A53B29CE}\setup.exe" -l0x40c /remove
CSV2ASC-->C:\Program Files\CSV2ASC\uninstall.exe
Digital Camera Driver-->C:\PROGRA~1\Actebis\UNWISE.EXE C:\PROGRA~1\Actebis\INSTALL.LOG
DiscAPI (Studio 10)-->MsiExec.exe /X{A77F3C2D-50CC-4A29-A1FB-1E018BE4DCA2}
DivX Codec-->C:\Program Files\DivX\DivXCodecUninstall.exe /CODEC
DivX Converter-->C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
DivX Player-->C:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYER
DivX Plus DirectShow Filters-->C:\Program Files\DivX\DivXDSFiltersUninstall.exe /DSFILTERS
DivX Web Player-->C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
DVD Shrink 3.2-->"C:\Program Files\DVD Shrink\unins000.exe"
EA SPORTS online 2007-->C:\Program Files\EA SPORTS\EA SPORTS online\EASOUNInstaller.exe
EMCO_MSI_TRIAL_PACKAGE - Fritz10.msi-->MsiExec.exe /X{162B1973-545B-4890-B078-86486F01EBA2}
eMule-->"C:\Program Files\eMule\Uninstall.exe"
EPSON Attach To Email-->C:\Program Files\Fichiers communs\InstallShield\Driver\8\Intel 32\IDriver.exe /M{20C45B32-5AB6-46A4-94EF-58950CAF05E5} /l1033 ADDREMOVEDLG
EPSON Easy Photo Print-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5DA7BC15-18D3-41A0-9F59-838DA3EAEF17}\SETUP.EXE" -l0x40c UNINST
EPSON File Manager-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E86BC406-944E-41F6-ADE6-2C136734C96B}\Setup.exe" -l0x40c UNINST
EPSON Logiciel imprimante-->C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\EPUPDATE.EXE /R
EPSON Scan Assistant-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2A88F1BF-7041-4E42-84B1-6B4ACB83AC64}\Setup.exe" -l0x40c -u
EPSON Web-To-Page-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7F14F68C-17FA-4F88-B3FD-7F449C1EBF32}\SETUP.EXE" -l0x40c -anything
ESD68 Guide d'utilisation-->C:\Program Files\EPSON\TPMANUAL\ESD68\USE_G\DOCUNINS.EXE
EssentialPIM-->C:\EssentialPIM\uninstall.exe
Extension Système de Microsoft Money-->MsiExec.exe /I{02CA7E66-1AD1-4DE9-BA9E-86A0EEB019C7}
Favorit-->"c:\documents and settings\marcs\local settings\application data\ugkuc.exe" -uninstall
FIFA 07-->C:\Program Files\EA SPORTS\FIFA 07\EAUninstall.exe
FileZilla (remove only)-->"C:\Program Files\FileZilla\uninstall.exe"
FoneSync-->C:\WINDOWS\IsUninst.exe -f"C:\Program Files\FoneSync\Uninst.isu" -c"C:\Program Files\FoneSync\UninstSupport.dll"
Free - Kit de connexion-->C:\Program Files\Free.fr\uninstall.exe
Free Mp3 Wma Converter V 1.6.3-->"C:\Program Files\Free Audio Pack\unins000.exe"
Freecorder Toolbar-->C:\PROGRA~1\FREECO~2\UNWISE.EXE C:\PROGRA~1\FREECO~2\INSTALL.LOG
Freeplayer-->C:\Program Files\Freeplayer\Uninstall.exe
Fritz10 Service Pack-->MsiExec.exe /I{E64B8C0B-9AD1-4C61-9CC4-5C36C02C5051}
Google Earth-->MsiExec.exe /I{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}
Grand Prix 3 Patch-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3F7F4660-83D7-11D4-BE68-0000B4A81FC5}\setup.exe"
Grand Prix 3-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E4961DB6-A3F3-11D3-BE67-0000B4A81FC5}\setup.exe"
HardwareDetection-->"C:\Program Files\HardwareDetection\Uninstall.exe" "C:\Program Files\HardwareDetection\install.log" -u
HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
IBM ViaVoice Standard 8.0 - Français-->"C:\Program Files\ViaVoice\Bin\uninst_FR.exe" DeleteProdVVFW80Basic_FR
IE7Pro-->C:\Program Files\IEPro\uninst.exe
Inline Search v1.5.0 for Internet Explorer (remove only)-->"C:\Program Files\IEForge\Inline Search\uninstall.exe"
Installation de Microsoft Works Suite 2001-->C:\Program Files\Microsoft Works Suite 2001\Setup\Launcher.exe E:\
Installation Windows Live-->C:\Program Files\Windows Live\Installer\wlarp.exe
Installation Windows Live-->MsiExec.exe /I{7370DF47-B4F9-4279-BFC3-3F09919F720D}
IsoBuster 1.8-->"C:\Program Files\Smart Projects\IsoBuster\Uninst\unins000.exe"
J2SE Runtime Environment 5.0 Update 10-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150100}
J2SE Runtime Environment 5.0 Update 6-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150060}
J2SE Runtime Environment 5.0 Update 9-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150090}
Java(TM) 6 Update 13-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216011FF}
Java(TM) 6 Update 2-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160020}
Java(TM) 6 Update 3-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160030}
Java(TM) 6 Update 5-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160050}
Java(TM) 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
Java(TM) SE Runtime Environment 6 Update 1-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160010}
Joost (tm) Beta 1.0.3-->C:\Program Files\Joost\uninst.exe
KeyMaestro Input Device Driver V1.0.1-01A2 MUL-->C:\WINDOWS\system32\KMUninst.exe
Lecteur Windows Media 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
LiveReg (Symantec Corporation)-->C:\Program Files\Fichiers communs\Symantec Shared\LiveReg\VcSetup.exe /REMOVE
Logitech Desktop Messenger-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{900B1197-53F5-4F46-A882-2CFFFE2EEDCB}\Setup.exe" -l0x40c UNINSTALL
Logitech Gaming Software-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B9242864-2841-4ADE-86E0-8F90F91B04DD}\setup.exe" -l0x40c
Logitech QuickCam-->MsiExec.exe /I{937B232D-9776-471E-92BD-D424E514EF14}
Microsoft .NET Framework 1.1 French Language Pack-->MsiExec.exe /X{9A394342-4A68-4EBA-85A6-55B559F4E700}
Microsoft .NET Framework 1.1 Hotfix (KB928366)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"
Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 2.0 Service Pack 2 Language Pack - FRA-->MsiExec.exe /I{72AD53CC-CCC0-3757-8480-9EE176866A7C}
Microsoft .NET Framework 2.0 Service Pack 2-->MsiExec.exe /I{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}
Microsoft .NET Framework 3.0 Service Pack 2 Language Pack - FRA-->MsiExec.exe /I{0BD83598-C2EF-3343-847B-7D2E84599128}
Microsoft .NET Framework 3.0 Service Pack 2-->MsiExec.exe /I{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}
Microsoft .NET Framework 3.5 Language Pack SP1 - fra-->MsiExec.exe /I{3E31821C-7917-367E-938E-E65FC413EA31}
Microsoft .NET Framework 3.5 SP1-->C:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
Microsoft Kernel-Mode Driver Framework Feature Pack 1.5-->"C:\WINDOWS\$NtUninstallWdf01005$\spuninst\spuninst.exe"
Microsoft Kernel-Mode Driver Framework Feature Pack 1.7-->"C:\WINDOWS\$NtUninstallWdf01007$\spuninst\spuninst.exe"
Microsoft Money-->MsiExec.exe /I{019210C1-32C8-423C-BEFD-763C8E7A188F}
Microsoft Office Professional Edition 2003-->MsiExec.exe /I{9011040C-6000-11D3-8CFE-0150048383C9}
Microsoft Office Visio Professional 2003-->MsiExec.exe /I{9051040C-6000-11D3-8CFE-0150048383C9}
Microsoft User-Mode Driver Framework Feature Pack 1.5-->"C:\WINDOWS\$NtUninstallWudf01005$\spuninst\spuninst.exe"
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Microsoft Windows Script Host-->rundll32 advpack.dll,LaunchINFSection C:\WINDOWS\INF\wsh.inf,Uninstall.NT
Microsoft Works 6.0-->MsiExec.exe /I{75DEB69B-4B6C-11D4-B0CE-00AA00BCC218}
Mio Technology Speedcam Synchronisation 1.1.16.04.06-->C:\PROGRA~1\MIOTEC~1\MioSync\Setup.exe /remove
Mio Technology SpeedCam Tool-->C:\PROGRA~1\MIOTEC~1\SPEEDC~1\Setup.exe /remove
MioMap v3 Updater-->MsiExec.exe /I{9C6E2ABE-B3E6-49BA-807C-BDFA54496DA5}
MioTransfer-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{49F00501-E02F-458F-8AED-85949AB9656F}\Setup.exe" -l0x9
Mise à jour critique pour Lecteur Windows Media 11 (KB959772)-->"C:\WINDOWS\$NtUninstallKB959772_WM11$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Lecteur Windows Media (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Lecteur Windows Media 11 (KB954154)-->"C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB928090)-->"C:\WINDOWS\ie7updates\KB928090-IE7\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB929969)-->"C:\WINDOWS\ie7updates\KB929969\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB931768)-->"C:\WINDOWS\ie7updates\KB931768-IE7\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB933566)-->"C:\WINDOWS\ie7updates\KB933566-IE7\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB937143)-->"C:\WINDOWS\ie7updates\KB937143-IE7\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB938127)-->"C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB939653)-->"C:\WINDOWS\ie7updates\KB939653-IE7\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB942615)-->"C:\WINDOWS\ie7updates\KB942615-IE7\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB944533)-->"C:\WINDOWS\ie7updates\KB944533-IE7\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB950759)-->"C:\WINDOWS\ie7updates\KB950759-IE7\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB953838)-->"C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB956390)-->"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB958215)-->"C:\WINDOWS\ie7updates\KB958215-IE7\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB960714)-->"C:\WINDOWS\ie7updates\KB960714-IE7\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB961260)-->"C:\WINDOWS\ie7updates\KB961260-IE7\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB963027)-->"C:\WINDOWS\ie7updates\KB963027-IE7\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows Internet Explorer 8 (KB969897)-->"C:\WINDOWS\ie8updates\KB969897-IE8\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB923561)-->"C:\WINDOWS\$NtUninstallKB923561$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB950760)-->"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB951376)-->"C:\WINDOWS\$NtUninstallKB951376$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB952004)-->"C:\WINDOWS\$NtUninstallKB952004$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB953839)-->"C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB954211)-->"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB954459)-->"C:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB954600)-->"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB956391)-->"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB956572)-->"C:\WINDOWS\$NtUninstallKB956572$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB956841)-->"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB957095)-->"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB958687)-->"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB958690)-->"C:\WINDOWS\$NtUninstallKB958690$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB959426)-->"C:\WINDOWS\$NtUninstallKB959426$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB960225)-->"C:\WINDOWS\$NtUninstallKB960225$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB960715)-->"C:\WINDOWS\$NtUninstallKB960715$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB960803)-->"C:\WINDOWS\$NtUninstallKB960803$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB961373)-->"C:\WINDOWS\$NtUninstallKB961373$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB961501)-->"C:\WINDOWS\$NtUninstallKB961501$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB968537)-->"C:\WINDOWS\$NtUninstallKB968537$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB969898)-->"C:\WINDOWS\$NtUninstallKB969898$\spuninst\spuninst.exe"
Mise à jour de sécurité pour Windows XP (KB970238)-->"C:\WINDOWS\$NtUninstallKB970238$\spuninst\spuninst.exe"
Mise à jour pour Windows Internet Explorer 8 (KB969497)-->"C:\WINDOWS\ie8updates\KB969497-IE8\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB951072-v2)-->"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB955839)-->"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB961503)-->"C:\WINDOWS\$NtUninstallKB961503$\spuninst\spuninst.exe"
Mise à jour pour Windows XP (KB967715)-->"C:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe"
Module de compatibilité pour Microsoft Office System 2007-->MsiExec.exe /X{90120000-0020-040C-0000-0000000FF1CE}
Module linguistique Microsoft .NET Framework 3.5 SP1- fra-->C:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 Language Pack SP1 - fra\setup.exe
Mozilla Firefox (2.0.0.17)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
MP3 Player Utilities 3.5.02-->MsiExec.exe /I{0DE7211B-A7CB-4112-8D62-142A0EBDFAD9}
MP3 Player Utilities 4.13-->MsiExec.exe /I{8B9852AF-B0B0-47B7-9BC5-89A95D77B6C9}
MSRedist-->MsiExec.exe /I{FC37ABD0-2108-4beb-B010-1254E0662B5A}
MSVC80_x86-->MsiExec.exe /I{212748BB-0DA5-46DE-82A1-403736DC9F27}
MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
MSXML 4.0 SP2 (KB927978)-->MsiExec.exe /I{37477865-A3F1-4772-AD43-AAFC6BCFF99F}
MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
Nero Suite-->C:\Program Files\Fichiers communs\Nero\Uninstall\setupx.exe /uninstall ExtraUninstallID=""
Nokia Connectivity Cable Driver-->MsiExec.exe /I{52D02A2B-03D2-4E34-A358-DC5D951FD296}
Nokia PC Suite-->C:\Documents and Settings\All Users\Application Data\Installations\{55495E65-7C5B-48E4-BC7D-DE54F3DE5ED6}\Nokia_PC_Suite_7_1_30_8_fre.exe
Nokia PC Suite-->MsiExec.exe /I{55495E65-7C5B-48E4-BC7D-DE54F3DE5ED6}
Norton AntiVirus-->MsiExec.exe /X{C6F5B6CF-609C-428E-876F-CA83176C021B}
Norton Utilities-->MsiExec.exe /I{6A7867BA-B7CA-4CC9-ACAB-85BA46865EE5}
NVIDIA Drivers-->C:\WINDOWS\system32\nvuninst.exe UninstallGUI
Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
Package de pilotes Windows - Nokia Modem (05/22/2008 3.8)-->C:\PROGRA~1\DIFX\270581355A767BF1\dpinst.exe /u C:\WINDOWS\system32\DRVSTORE\nokia_blue_6F90B0F4A73A2F780A1010B5D6CB5DDFB098181E\nokia_bluetooth.inf
Package de pilotes Windows - Nokia Modem (05/22/2008 7.00.0.1)-->C:\PROGRA~1\DIFX\270581355A767BF1\dpinst.exe /u C:\WINDOWS\system32\DRVSTORE\nokbtmdm_E68D50F7E25BFE399D47C864C3B52557346242A9\nokbtmdm.inf
Package de pilotes Windows - Nokia Modem (06/01/2009 4.1)-->C:\PROGRA~1\DIFX\270581355A767BF1\dpinst.exe /u C:\WINDOWS\system32\DRVSTORE\nokia_blue_C08496D7A0050438DFE13C55799AE2D4157A8E7A\nokia_bluetooth.inf
Package de pilotes Windows - Nokia Modem (06/01/2009 7.01.0.3)-->C:\PROGRA~1\DIFX\270581355A767BF1\dpinst.exe /u C:\WINDOWS\system32\DRVSTORE\nokbtmdm_9C48E34C57B7D4AAE5FFF5FB9B476B538394FD30\nokbtmdm.inf
Package de pilotes Windows - Nokia pccsmcfd (08/22/2008 7.0.0.0)-->C:\PROGRA~1\DIFX\B4723E9A0713E5B1\dpinst.exe /u C:\WINDOWS\system32\DRVSTORE\pccsmcfd_A3B3916E5D8138F59EE218321B27B044D3B18294\pccsmcfd.inf
PC Connectivity Solution-->MsiExec.exe /I{0C973594-7DDF-4BD0-84ED-3517F7622037}
PC Inspector smart recovery-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C9A87D86-FDFD-418B-BF96-EF09320973B3}\Setup.exe" -l0x40c
PL-2303 USB-to-Serial-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{ECC3713C-08A4-40E3-95F1-7D0704F1CE5E}\Setup.exe" -l0x9 Installed
POI Loader-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9B076678-4FDB-4EFD-A962-E5DF53A08DC5}\Setup.exe" -l0x40c
QuickTime-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\11\INTEL3~1\IDriver.exe /M{C21D5524-A970-42FA-AC8A-59B8C7CDCA31} /l1036
Radio Fr Solo 2.1-->C:\Program Files\Radio Fr Solo\Uninstall.exe
RAPID (Studio 10)-->MsiExec.exe /X{EEECE229-49F6-4851-A73A-99B058221F8C}
RayV-->C:\Program Files\RayV\RayV\uninstall.exe
Realtek High Definition Audio Driver-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\Setup.exe" -l0x40c -removeonly
Ri-li-->"C:\WINDOWS\system32\SpoonUninstall.exe" <uninstall>C:\WINDOWS\system32\SpoonUninstall-Ri-li.dat
Roxio PhotoSuite 5-->MsiExec.exe /I{607CE53B-0999-4F3B-8FF1-DB1AA47548A8}
Securitoo AntiVirus Firewall-->"C:\Program Files\Securitoo\av_fw\FSGUI\PostInstall.exe" /tUnInstall
Security Update for CAPICOM (KB931906)-->MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
Security Update for CAPICOM (KB931906)-->MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
Segoe UI-->MsiExec.exe /I{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}
Share Accelerator MM Toolbar-->C:\PROGRA~1\SHARE_~1\UNWISE.EXE C:\PROGRA~1\SHARE_~1\INSTALL.LOG
Shockwave-->C:\WINDOWS\system32\Macromed\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Macromed\SHOCKW~1\Install.log
SmartSound Quicktracks Plugin-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe /M{4A7FDA4D-F4D7-4A49-934A-066D59A43C7E}
Sound Blaster Audigy-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{1B1DDAD2-C704-49F8-8FC2-18DAAD9A87C5}\SETUP.EXE" -l0x40c /remove
Studio 10-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3CB05291-F546-458E-A796-B5BCF5A3CDC4}\Setup2.exe" -l0x40c UNINSTALL
System Requirements Lab-->C:\Program Files\SystemRequirementsLab\Uninstall.exe
Ulead Disc-Direct SDK-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0700\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{8D2C1E44-7685-4D05-8342-B0DC6422FA47}\Setup.exe" -l0x9
VC80CRTRedist - 8.0.50727.762-->MsiExec.exe /I{767CC44C-9BBC-438D-BAD3-FD4595DD148B}
VIA Platform Device Manager-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{20D4A895-748C-4D88-871C-FDB1695B0169}
VIA Rhine-Family Fast Ethernet Adapter-->Rundll32.exe vuins32.dll,vuins32Ex $Rhine $VIA
VibrateGameDeviceDriver-->MsiExec.exe /I{E6FC9938-1B6E-41F6-98BD-ECD70C371DBE}
VideoLAN VLC media player 0.8.5-->C:\Program Files\VideoLAN\VLC\uninstall.exe
Viewpoint Media Player-->C:\Program Files\Viewpoint\Viewpoint Media Player\mtsAxInstaller.exe /u
Windows Internet Explorer 8-->"C:\WINDOWS\ie8\spuninst\spuninst.exe"
Windows Live Call-->MsiExec.exe /I{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}
Windows Live Communications Platform-->MsiExec.exe /I{3B4E636E-9D65-4D67-BA61-189800823F52}
Windows Live Messenger-->MsiExec.exe /X{059C042E-796A-4ACC-A81A-ECC2010BB78C}
Windows Live Safety Scanner-->RunDll32.exe "C:\Program Files\Windows Live Safety Center\wlscCore.dll",UninstallFunction WLSC_SCANNER_PRODUCT
Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
Windows Media Player 10 Hotfix - KB888656-->"C:\WINDOWS\$NtUninstallKB888656$\spuninst\spuninst.exe"
Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
WinFast Entertainment Center(WDM Driver)-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BE4AA694-815A-4045-BD49-C94F2BED7458}\setup.exe"
WinPcap 3.1 beta4-->"C:\Program Files\WinPcap\Uninstall.exe" "C:\Program Files\WinPcap\install.log"
XML Paper Specification Shared Components Language Pack 1.0-->"C:\WINDOWS\$NtUninstallXPSEPSCLP$\spuninst\spuninst.exe"
XviD 1.1 final uninstall-->"C:\Program Files\XviD\unins000.exe"

======Hosts File======

127.0.0.1 bin.errorprotector.com ## added by CiD
127.0.0.1 br.errorsafe.com ## added by CiD
127.0.0.1 br.winantivirus.com ## added by CiD
127.0.0.1 br.winfixer.com ## added by CiD
127.0.0.1 cdn.drivecleaner.com ## added by CiD
127.0.0.1 cdn.errorsafe.com ## added by CiD
127.0.0.1 cdn.winsoftware.com ## added by CiD
127.0.0.1 de.errorsafe.com ## added by CiD
127.0.0.1 de.winantivirus.com ## added by CiD
127.0.0.1 download.cdn.drivecleaner.com ## added by CiD

======Security center information======

AV: Securitoo AntiVirus Firewall 8.00
FW: Securitoo AntiVirus Firewall 8.00

======System event log======

Computer Name: PC1
Event Code: 7036
Message: Le service F-Secure Anti-Virus Firewall Daemon est entré dans l'état : en cours d'exécution.

Record Number: 49269
Source Name: Service Control Manager
Time Written: 20090531205915.000000+120
Event Type: Informations
User:

Computer Name: PC1
Event Code: 7036
Message: Le service Carte de performance WMI est entré dans l'état : arrêté.

Record Number: 49268
Source Name: Service Control Manager
Time Written: 20090531205908.000000+120
Event Type: Informations
User:

Computer Name: PC1
Event Code: 7035
Message: Un contrôle Démarrer a correctement été envoyé au service Carte de performance WMI.

Record Number: 49267
Source Name: Service Control Manager
Time Written: 20090531205908.000000+120
Event Type: Informations
User: AUTORITE NT\SYSTEM

Computer Name: PC1
Event Code: 7036
Message: Le service Carte de performance WMI est entré dans l'état : en cours d'exécution.

Record Number: 49266
Source Name: Service Control Manager
Time Written: 20090531205908.000000+120
Event Type: Informations
User:

Computer Name: PC1
Event Code: 7036
Message: Le service Gestionnaire de connexions d'accès distant est entré dans l'état : en cours d'exécution.

Record Number: 49265
Source Name: Service Control Manager
Time Written: 20090531205908.000000+120
Event Type: Informations
User:

=====Application event log=====

Computer Name: PC1
Event Code: 1
Message:
Record Number: 194067
Source Name: nview_info
Time Written: 20090619125344.000000+120
Event Type: erreur
User:

Computer Name: PC1
Event Code: 1
Message:
Record Number: 194066
Source Name: nview_info
Time Written: 20090619125344.000000+120
Event Type: erreur
User:

Computer Name: PC1
Event Code: 1
Message:
Record Number: 194065
Source Name: nview_info
Time Written: 20090619125344.000000+120
Event Type: erreur
User:

Computer Name: PC1
Event Code: 1
Message:
Record Number: 194064
Source Name: nview_info
Time Written: 20090619125344.000000+120
Event Type: erreur
User:

Computer Name: PC1
Event Code: 1
Message:
Record Number: 194063
Source Name: nview_info
Time Written: 20090619125344.000000+120
Event Type: erreur
User:

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=C:\Program Files\PC Connectivity Solution\;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\Fichiers communs\Roxio Shared\DLLShared;C:\Program Files\QuickTime\QTSystem\;C:\Program Files\Fichiers communs\DivX Shared\
"windir"=%SystemRoot%
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=6
"PROCESSOR_IDENTIFIER"=x86 Family 6 Model 15 Stepping 2, GenuineIntel
"PROCESSOR_REVISION"=0f02
"NUMBER_OF_PROCESSORS"=2
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"FP_NO_HOST_CHECK"=NO
"PS5ROOT"=D:\PHOTOS\photosuite\
"CLASSPATH"=.;C:\Program Files\Java\jre1.5.0_06\lib\ext\QTJava.zip
"QTJAVA"=C:\Program Files\Java\jre1.5.0_06\lib\ext\QTJava.zip

-----------------EOF-----------------
Logfile of random's system information tool 1.06 (written by random/random)
Run by marcs at 2009-06-22 16:44:14
Microsoft Windows XP Édition familiale Service Pack 3
System drive C: has 20 GB (25%) free of 78 GB
Total RAM: 2047 MB (51% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:44:31, on 22/06/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\Securitoo\av_fw\Anti-Virus\fsgk32st.exe
C:\Program Files\Securitoo\av_fw\Common\FSMA32.EXE
C:\Program Files\Securitoo\av_fw\Anti-Virus\FSGK32.EXE
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Securitoo\av_fw\Common\FSMB32.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\Securitoo\av_fw\Common\FCH32.EXE
C:\Program Files\Securitoo\av_fw\Anti-Virus\fssm32.exe
C:\Program Files\Securitoo\av_fw\Anti-Virus\fsqh.exe
C:\Program Files\Securitoo\av_fw\Common\FAMEH32.EXE
C:\Program Files\Securitoo\av_fw\FSAUA\program\fsaua.exe
C:\Program Files\Securitoo\av_fw\FWES\Program\fsdfwd.exe
C:\Program Files\Securitoo\av_fw\FSAUA\program\fsus.exe
C:\Program Files\Securitoo\av_fw\Anti-Virus\fsav32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAAE.EXE
C:\Program Files\VibrateGameDeviceDriver\RFPIcon.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Securitoo\av_fw\Common\FSM32.EXE
C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\Securitoo\av_fw\FSGUI\fsguidll.exe
C:\Program Files\Logitech\QuickCam\Quickcam.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\documents and settings\marcs\local settings\application data\ugkuc.exe
C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe
C:\Program Files\Fichiers communs\Logishrd\LQCVFX\COCIManager.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Securitoo\av_fw\FSGUI\scanwizard.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\IEPro\MiniDM.exe
C:\DOCUME~1\marcs\LOCALS~1\Temp\RSIT.exe
C:\Program Files\trend micro\marcs.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.emule-france.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Share Accelerator MM Toolbar - {4596013b-6c31-408b-a266-deae5c086dc2} - C:\Program Files\Share_Accelerator_MM\tbSha1.dll
R3 - URLSearchHook: Freecorder Toolbar - {1392b8d2-5c05-419f-a8f6-b9f15a596612} - C:\Program Files\Freecorder\tbFre0.dll
O2 - BHO: IE7Pro - {00011268-E188-40DF-A514-835FCD78B1BF} - C:\Program Files\IEPro\iepro.dll
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Freecorder Toolbar - {1392b8d2-5c05-419f-a8f6-b9f15a596612} - C:\Program Files\Freecorder\tbFre0.dll
O2 - BHO: Share Accelerator MM Toolbar - {4596013b-6c31-408b-a266-deae5c086dc2} - C:\Program Files\Share_Accelerator_MM\tbSha1.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: InlineSearchHandleHotKey - {B6FFE2AE-4D12-451F-B457-FE6125FFB1CF} - C:\Program Files\IEForge\Inline Search\InlineSearch.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: Share Accelerator MM Toolbar - {4596013b-6c31-408b-a266-deae5c086dc2} - C:\Program Files\Share_Accelerator_MM\tbSha1.dll
O3 - Toolbar: Freecorder Toolbar - {1392b8d2-5c05-419f-a8f6-b9f15a596612} - C:\Program Files\Freecorder\tbFre0.dll
O4 - HKLM\..\Run: [EPSON Stylus D68 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAAE.EXE /P23 "EPSON Stylus D68 Series" /O6 "USB001" /M "Stylus D68"
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [RTBatteryMeter] C:\Program Files\VibrateGameDeviceDriver\RFPIcon.exe
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\\PSDrvCheck.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\Securitoo\av_fw\Common\FSM32.EXE" /splash
O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\Securitoo\av_fw\FSGUI\TNBUtil.exe" /CHECKALL /WAITFORSW
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [drvsyskit] C:\WINDOWS\system32\drivers\hidr.exe
O4 - HKCU\..\Run: [mule_st_key] C:\Documents and Settings\marcs\Application Data\m\flec006.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [ugkuc] "c:\documents and settings\marcs\local settings\application data\ugkuc.exe" ugkuc
O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
O4 - HKCU\..\Run: [eMuleAutoStart] C:\Program Files\eMule\emule.exe -AutoStart
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [WUAppSetup] C:\Program Files\Fichiers communs\logishrd\WUApp32.exe -v 0x046d -p 0x08ce -f video -m logitech -d 10.5.1.2023 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [WUAppSetup] C:\Program Files\Fichiers communs\logishrd\WUApp32.exe -v 0x046d -p 0x08ce -f video -m logitech -d 10.5.1.2023 (User 'Default user')
O8 - Extra context menu item: Add to AMV Converter... - C:\Program Files\MP3 Player Utilities 4.13\AMVConverter\grab.html
O8 - Extra context menu item: Compare Prices with &Dealio - C:\Documents and Settings\marcs\Application Data\Dealio\kb124\res\DealioSearch.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Program Files\MP3 Player Utilities 4.13\MediaManager\grab.html
O9 - Extra button: IE7Pro Grab and Drag - {000002a3-84fe-43f1-b958-f2c3ca804f1a} - C:\Program Files\IEPro\iepro.dll
O9 - Extra 'Tools' menuitem: IE7Pro Grab and Drag - {000002a3-84fe-43f1-b958-f2c3ca804f1a} - C:\Program Files\IEPro\iepro.dll
O9 - Extra button: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files\IEPro\iepro.dll
O9 - Extra 'Tools' menuitem: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files\IEPro\iepro.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=https://www.free.fr/freebox/index.html
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - https://www.nvidia.com/content/DriverDownload/srl/2.0.0.1/sysreqlab2.cab
O16 - DPF: {B9F79165-A264-4C4A-A211-133A5E8D647F} (F-Secure Health Check 1.1) - https://www.nordnet.com/securite
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - https://driveragent.com/files/driveragent.cab
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - C:\Program Files\Securitoo\av_fw\Anti-Virus\fsgk32st.exe
O23 - Service: F-Secure Automatic Update Agent (FSAUA) - F-Secure Corporation - C:\Program Files\Securitoo\av_fw\FSAUA\program\fsaua.exe
O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\Securitoo\av_fw\FWES\Program\fsdfwd.exe
O23 - Service: FSMA - F-Secure Corporation - C:\Program Files\Securitoo\av_fw\Common\FSMA32.EXE
O23 - Service: F-Secure ORSP Client (FSORSPClient) - F-Secure Corporation - C:\Program Files\Securitoo\av_fw\ORSP Client\fsorsp.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - NetGroup - Politecnico di Torino - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
O24 - Desktop Component 0: (no name) - http://mafreebox.freebox.fr/freeboxtv/playlist.m3u
A voir également:

43 réponses

Utilisateur anonyme
 
Bonjour,

1)
Télécharge LopSD.exe sur ton Bureau

https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/LopSD.exe?attachauth=ANoY7co3ntqUavpZ3q1BG-h4pc13vqDZmhcNeEPChtsyrgAykRbhE8bZzhk979EfQD4AgwtQUHCaQ7ZQwNYMo3_0kA8htAspckDJtu2K5t6J9z6dLW4fpZyH4FpFL1tVMBZ8H-KnN7afZ5vt-WxZRpnynk-a0XmV_Y0C0q6DxGEDKie1TnPT7gFoZnoCnspzBmbW6ZzxA4fNr3oEDlbelNZON-LjF8nOmQ%3D%3D&attredirects=2

Clique sur le raccourci LopSD présent sur le Bureau pour lancer LopSD.

Choisis la langue F pour Français puis valide par Entrée.

Choisis l'option Recherche en saisissant 1 puis valide par Entrée
.
* Patiente jusqu'à la fin du scan
* Poste le rapport généré qui se trouve ici => (C:\lopR.txt)

(Si le Bureau ne réapparait pas, presse Ctrl+Alt+Suppr, Onglet Fichier, Nouvelle tâche, tape explorer.exe et valide)

2)
Télécharge Navilog1 (par IL-MAFIOSO) sur ton bureau

http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe

Enregistrer la cible (du lien) sous... et enregistre-le sur ton bureau.
Ensuite double clique sur navilog1.exe pour lancer l'installation.
Une fois l'installation terminée, double-clique sur le raccourci Navilog1 présent sur le bureau.

Laisse-toi guider. Appuie sur une touche quand on te le demande.
Au menu principal, choisis 1 et valide.

< Ne fais pas le choix 2 >

Patiente le temps du scan. Il te sera peut-être demandé de redémarrer ton PC.
Laisse l'outil le faire automatiquement ; sinon, redémarre ton PC normalement si demandé.

Patiente jusqu'au message "Scan terminé le......"
Appuie sur une touche comme demandé ; le bloc-notes va s'ouvrir.
Copie-colle l'intégralité dans ta réponse. Referme le bloc-notes.

PS : le rapport est, aussi, sauvegardé à la racine du disque dur C:\cleannavi.txt

a+
0
marcugodelire
 
Voici le rapport :

--------------------\\ Lop S&D 4.2.5-0 XP/Vista

Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 3
X86-based PC ( Multiprocessor Free : Intel(R) Core(TM)2 CPU 4300 @ 1.80GHz )
BIOS : Default System BIOS
USER : marcs ( Administrator )
BOOT : Normal boot
Antivirus : Securitoo AntiVirus Firewall 8.00 8.00 (Activated)
Firewall : Securitoo AntiVirus Firewall 8.00 8.00 (Activated)
A:\ (USB)
C:\ (Local Disk) - NTFS - Total:76 Go (Free:19 Go)
D:\ (Local Disk) - NTFS - Total:31 Go (Free:23 Go)
E:\ (CD or DVD)

"C:\Lop SD" ( MAJ : 19-12-2008|23:40 )
Option : [1] ( 22/06/2009|17:22 )

--------------------\\ Listing des dossiers dans APPLIC~1


[18/10/2007|10:47] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[04/05/2007|21:04] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Ahead
[31/05/2009|14:04] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
[18/11/2007|09:24] C:\DOCUME~1\ALLUSE~1\APPLIC~1\AVS4YOU
[29/09/2006|17:51] C:\DOCUME~1\ALLUSE~1\APPLIC~1\BOONTY
[28/02/2009|20:41] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Creative
[12/04/2008|13:48] C:\DOCUME~1\ALLUSE~1\APPLIC~1\DVD Shrink
[22/11/2006|20:51] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Exetender
[28/03/2009|16:08] C:\DOCUME~1\ALLUSE~1\APPLIC~1\F-Secure
[28/03/2009|16:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\fssg
[21/06/2009|10:15] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Installations
[11/02/2008|22:51] C:\DOCUME~1\ALLUSE~1\APPLIC~1\InstallShield
[28/03/2009|13:17] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Logishrd
[20/11/2007|10:17] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Logitech
[28/08/2007|10:58] C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee
[28/03/2009|13:04] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[03/02/2008|19:53] C:\DOCUME~1\ALLUSE~1\APPLIC~1\MSScanAppDataDir
[02/06/2007|22:50] C:\DOCUME~1\ALLUSE~1\APPLIC~1\muvee Technologies
[04/05/2007|19:50] C:\DOCUME~1\ALLUSE~1\APPLIC~1\NVIDIA
[08/03/2008|10:07] C:\DOCUME~1\ALLUSE~1\APPLIC~1\nView_Profiles
[16/11/2008|10:18] C:\DOCUME~1\ALLUSE~1\APPLIC~1\PC Suite
[22/04/2007|10:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\PC Tools
[23/12/2006|23:11] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Pinnacle
[23/12/2006|23:29] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Pinnacle Studio
[23/12/2006|23:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SmartSound Software Inc
[01/09/2007|14:51] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
[28/08/2007|10:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec
[22/04/2007|11:58] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
[07/08/2006|21:03] C:\DOCUME~1\ALLUSE~1\APPLIC~1\UDL
[07/08/2006|21:25] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Ulead Systems
[22/04/2007|10:19] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Viewpoint
[08/08/2006|22:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[26/02/2008|22:48] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller


[09/12/2007|13:02] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft


[14/05/2007|17:33] C:\DOCUME~1\hugo\APPLIC~1\ATI
[07/08/2006|18:23] C:\DOCUME~1\hugo\APPLIC~1\Identities
[03/02/2007|21:46] C:\DOCUME~1\hugo\APPLIC~1\Macromedia
[14/05/2007|17:33] C:\DOCUME~1\hugo\APPLIC~1\Microsoft
[30/09/2006|20:14] C:\DOCUME~1\hugo\APPLIC~1\Symantec

[12/12/2006|17:18] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft

[18/10/2007|10:47] C:\DOCUME~1\marcs\APPLIC~1\Adobe
[09/05/2007|16:17] C:\DOCUME~1\marcs\APPLIC~1\AdobeUM
[21/03/2008|18:46] C:\DOCUME~1\marcs\APPLIC~1\Ahead
[13/08/2006|15:01] C:\DOCUME~1\marcs\APPLIC~1\Apple Computer
[12/05/2007|20:57] C:\DOCUME~1\marcs\APPLIC~1\ATI
[10/11/2006|21:35] C:\DOCUME~1\marcs\APPLIC~1\Azureus
[21/02/2007|22:46] C:\DOCUME~1\marcs\APPLIC~1\BitDownload
[19/06/2009|10:35] C:\DOCUME~1\marcs\APPLIC~1\ChessBase
[28/03/2009|08:16] C:\DOCUME~1\marcs\APPLIC~1\Creative
[23/12/2006|19:38] C:\DOCUME~1\marcs\APPLIC~1\CyberLink
[14/11/2007|09:33] C:\DOCUME~1\marcs\APPLIC~1\Dealio
[15/03/2007|16:24] C:\DOCUME~1\marcs\APPLIC~1\DivX
[24/12/2007|22:51] C:\DOCUME~1\marcs\APPLIC~1\dvdcss
[21/08/2007|20:43] C:\DOCUME~1\marcs\APPLIC~1\EPSON
[16/06/2009|09:39] C:\DOCUME~1\marcs\APPLIC~1\EssentialPIM
[11/02/2008|23:14] C:\DOCUME~1\marcs\APPLIC~1\EssentialPIM Pro
[09/11/2008|09:57] C:\DOCUME~1\marcs\APPLIC~1\FMZilla
[15/06/2008|18:56] C:\DOCUME~1\marcs\APPLIC~1\F-Secure
[31/05/2008|15:35] C:\DOCUME~1\marcs\APPLIC~1\GARMIN
[22/10/2008|20:52] C:\DOCUME~1\marcs\APPLIC~1\Google
[17/05/2007|08:25] C:\DOCUME~1\marcs\APPLIC~1\Goto.Games
[24/05/2007|21:51] C:\DOCUME~1\marcs\APPLIC~1\Help
[29/08/2007|12:13] C:\DOCUME~1\marcs\APPLIC~1\HouseCall 6.6
[07/08/2006|18:24] C:\DOCUME~1\marcs\APPLIC~1\Identities
[22/12/2008|15:43] C:\DOCUME~1\marcs\APPLIC~1\IEPro
[13/05/2007|10:23] C:\DOCUME~1\marcs\APPLIC~1\InstallShield
[01/09/2007|15:04] C:\DOCUME~1\marcs\APPLIC~1\ispnews
[13/12/2007|08:41] C:\DOCUME~1\marcs\APPLIC~1\Joost
[02/10/2006|22:08] C:\DOCUME~1\marcs\APPLIC~1\Lavasoft
[25/01/2009|11:49] C:\DOCUME~1\marcs\APPLIC~1\Leadertech
[08/08/2006|18:19] C:\DOCUME~1\marcs\APPLIC~1\Macromedia
[17/04/2009|20:40] C:\DOCUME~1\marcs\APPLIC~1\Microsoft
[07/08/2006|19:36] C:\DOCUME~1\marcs\APPLIC~1\Microsoft Web Folders
[28/03/2009|16:45] C:\DOCUME~1\marcs\APPLIC~1\MiniDm
[08/02/2008|23:24] C:\DOCUME~1\marcs\APPLIC~1\Mozilla
[21/06/2009|21:07] C:\DOCUME~1\marcs\APPLIC~1\Nokia
[01/09/2007|15:18] C:\DOCUME~1\marcs\APPLIC~1\ntr
[26/10/2008|11:34] C:\DOCUME~1\marcs\APPLIC~1\PC Suite
[20/04/2007|21:00] C:\DOCUME~1\marcs\APPLIC~1\PC Tools
[18/11/2006|17:38] C:\DOCUME~1\marcs\APPLIC~1\Roxio
[17/06/2007|08:50] C:\DOCUME~1\marcs\APPLIC~1\SecondLife
[08/08/2006|18:13] C:\DOCUME~1\marcs\APPLIC~1\SendPix
[09/08/2006|15:52] C:\DOCUME~1\marcs\APPLIC~1\Sun
[01/10/2006|15:30] C:\DOCUME~1\marcs\APPLIC~1\Symantec
[08/02/2008|23:25] C:\DOCUME~1\marcs\APPLIC~1\Talkback
[19/11/2007|13:07] C:\DOCUME~1\marcs\APPLIC~1\Uniblue
[22/04/2007|10:19] C:\DOCUME~1\marcs\APPLIC~1\Viewpoint
[13/09/2008|07:30] C:\DOCUME~1\marcs\APPLIC~1\vlc
[03/10/2006|17:17] C:\DOCUME~1\marcs\APPLIC~1\WholeSecurity

[27/10/2007|14:12] C:\DOCUME~1\nathalie\APPLIC~1\Adobe
[13/05/2007|08:34] C:\DOCUME~1\nathalie\APPLIC~1\ATI
[12/08/2008|22:38] C:\DOCUME~1\nathalie\APPLIC~1\Babylon
[18/11/2007|21:54] C:\DOCUME~1\nathalie\APPLIC~1\DivX
[03/10/2008|14:56] C:\DOCUME~1\nathalie\APPLIC~1\EssentialPIM
[13/09/2008|21:26] C:\DOCUME~1\nathalie\APPLIC~1\F-Secure
[29/10/2006|20:49] C:\DOCUME~1\nathalie\APPLIC~1\Help
[15/08/2006|09:14] C:\DOCUME~1\nathalie\APPLIC~1\Identities
[23/12/2008|22:30] C:\DOCUME~1\nathalie\APPLIC~1\IEPro
[06/09/2007|21:20] C:\DOCUME~1\nathalie\APPLIC~1\ispnews
[15/08/2006|18:29] C:\DOCUME~1\nathalie\APPLIC~1\Macromedia
[12/08/2008|15:09] C:\DOCUME~1\nathalie\APPLIC~1\Microsoft
[10/01/2009|17:05] C:\DOCUME~1\nathalie\APPLIC~1\PC Suite
[03/06/2007|09:07] C:\DOCUME~1\nathalie\APPLIC~1\Roxio
[26/10/2006|15:13] C:\DOCUME~1\nathalie\APPLIC~1\Sun
[02/08/2007|11:00] C:\DOCUME~1\nathalie\APPLIC~1\Symantec
[27/04/2007|10:19] C:\DOCUME~1\nathalie\APPLIC~1\Viewpoint
[13/12/2007|19:10] C:\DOCUME~1\nathalie\APPLIC~1\vlc

[07/08/2006|18:20] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft
[07/08/2006|19:34] C:\DOCUME~1\NETWOR~1\APPLIC~1\Symantec

[29/03/2009|18:24] C:\DOCUME~1\nina\APPLIC~1\Adobe
[27/12/2006|19:12] C:\DOCUME~1\nina\APPLIC~1\Identities
[29/03/2009|18:28] C:\DOCUME~1\nina\APPLIC~1\InstallShield
[07/02/2009|10:47] C:\DOCUME~1\nina\APPLIC~1\ispnews
[29/03/2009|18:28] C:\DOCUME~1\nina\APPLIC~1\Microsoft
[29/03/2009|18:22] C:\DOCUME~1\nina\APPLIC~1\PC Suite
[27/12/2006|19:12] C:\DOCUME~1\nina\APPLIC~1\Symantec

--------------------\\ Tâches planifiées dans C:\WINDOWS\tasks

[22/06/2009 15:08][--ah-----] C:\WINDOWS\tasks\User_Feed_Synchronization-{DC53D839-98D3-441F-A3EF-017C0B7C4F22}.job
[22/06/2009 15:01][--a------] C:\WINDOWS\tasks\Scheduled scanning task.job
[22/06/2009 15:00][--ah-----] C:\WINDOWS\tasks\SA.DAT
[24/04/2003 14:00][-r-h-----] C:\WINDOWS\tasks\desktop.ini

--------------------\\ Listing des dossiers dans C:\Program Files

[07/08/2006|19:44] C:\Program Files\Actebis
[19/11/2008|11:09] C:\Program Files\Adobe
[31/05/2009|13:56] C:\Program Files\adslTV
[04/05/2007|21:18] C:\Program Files\Ahead
[27/08/2007|12:11] C:\Program Files\Aleker
[14/08/2008|10:43] C:\Program Files\Auralog
[01/09/2007|11:38] C:\Program Files\CCleaner
[13/09/2008|13:41] C:\Program Files\ChessBase
[17/09/2008|17:49] C:\Program Files\Common Files
[07/08/2006|18:14] C:\Program Files\ComPlus Applications
[06/08/2008|20:46] C:\Program Files\Conduit
[09/08/2006|17:41] C:\Program Files\Convar
[28/02/2009|20:35] C:\Program Files\Creative
[28/02/2009|20:35] C:\Program Files\Creative Installation Information
[15/06/2009|11:35] C:\Program Files\CSV2ASC
[23/12/2006|22:55] C:\Program Files\CyberLink
[26/10/2008|11:27] C:\Program Files\DIFX
[12/12/2006|20:25] C:\Program Files\directx
[30/05/2009|15:39] C:\Program Files\DivoCodec
[09/06/2009|17:21] C:\Program Files\DivX
[11/03/2008|23:26] C:\Program Files\DMV
[17/06/2007|19:49] C:\Program Files\DVD Shrink
[19/01/2007|15:52] C:\Program Files\EA SPORTS
[22/06/2009|15:06] C:\Program Files\eMule
[07/08/2006|21:16] C:\Program Files\EPSON
[01/08/2007|08:50] C:\Program Files\EssentialPIM
[21/06/2009|10:18] C:\Program Files\Fichiers communs
[19/09/2006|21:09] C:\Program Files\FileZilla
[07/08/2006|20:41] C:\Program Files\FoneSync
[11/11/2007|11:26] C:\Program Files\Free Audio Pack
[07/08/2006|19:51] C:\Program Files\Free.fr
[06/02/2009|21:45] C:\Program Files\Freecorder
[07/06/2007|18:37] C:\Program Files\Freeplayer
[22/10/2008|20:51] C:\Program Files\Google
[09/11/2008|19:29] C:\Program Files\Goto.Games
[01/06/2007|17:23] C:\Program Files\HardwareDetection
[22/12/2008|15:43] C:\Program Files\IEForge
[22/12/2008|15:43] C:\Program Files\IEPro
[31/05/2009|20:58] C:\Program Files\InstallShield Installation Information
[13/06/2009|12:07] C:\Program Files\Internet Explorer
[01/04/2009|21:37] C:\Program Files\Java
[28/03/2009|13:17] C:\Program Files\Logitech
[03/09/2008|21:19] C:\Program Files\Messenger
[09/11/2008|19:29] C:\Program Files\Micro Scrabble
[28/03/2009|17:56] C:\Program Files\Microsoft
[27/02/2008|13:03] C:\Program Files\Microsoft CAPICOM 2.1.0.2
[07/08/2006|19:35] C:\Program Files\microsoft frontpage
[09/08/2006|14:38] C:\Program Files\Microsoft Money
[02/02/2007|20:08] C:\Program Files\Microsoft Office
[07/08/2006|20:47] C:\Program Files\Microsoft Windows Script
[07/08/2006|20:38] C:\Program Files\Microsoft Works
[07/08/2006|20:33] C:\Program Files\Microsoft Works Suite 2001
[09/08/2006|21:13] C:\Program Files\Microsoft.NET
[01/02/2008|19:19] C:\Program Files\Mio DigiWalker
[31/01/2008|22:17] C:\Program Files\Mio Technology
[03/09/2008|21:16] C:\Program Files\Movie Maker
[15/06/2009|11:40] C:\Program Files\Mozilla Firefox
[19/01/2008|18:14] C:\Program Files\MP3 Player Utilities 3.5.02
[19/01/2008|18:13] C:\Program Files\MP3 Player Utilities 4.13
[23/05/2009|22:05] C:\Program Files\MSBuild
[02/02/2007|20:07] C:\Program Files\MSECache
[07/08/2006|18:13] C:\Program Files\MSN
[07/08/2006|18:13] C:\Program Files\MSN Gaming Zone
[17/11/2006|18:10] C:\Program Files\MSXML 4.0
[08/09/2007|18:38] C:\Program Files\NetAnalyse
[03/09/2008|21:13] C:\Program Files\NetMeeting
[21/06/2009|10:18] C:\Program Files\Nokia
[09/08/2006|22:13] C:\Program Files\OfficeUpdate11
[03/09/2008|21:34] C:\Program Files\Outlook Express
[31/05/2009|14:04] C:\Program Files\Papi
[21/06/2009|10:17] C:\Program Files\PC Connectivity Solution
[23/12/2006|23:07] C:\Program Files\Pinnacle
[13/08/2006|14:55] C:\Program Files\QuickTime
[04/11/2008|17:42] C:\Program Files\Radio Fr Solo
[18/08/2007|08:26] C:\Program Files\RayV
[02/06/2007|19:50] C:\Program Files\Realtek
[23/05/2009|22:05] C:\Program Files\Reference Assemblies
[03/06/2008|18:38] C:\Program Files\Securitoo
[07/08/2006|18:13] C:\Program Files\Services en ligne
[26/10/2007|11:50] C:\Program Files\Share_Accelerator_MM
[09/08/2006|17:30] C:\Program Files\Smart Projects
[23/12/2006|23:06] C:\Program Files\SmartSound Software
[11/11/2007|02:01] C:\Program Files\SystemRequirementsLab
[22/06/2009|16:44] C:\Program Files\trend micro
[07/08/2006|21:25] C:\Program Files\Ulead Systems
[07/08/2006|18:23] C:\Program Files\Uninstall Information
[26/05/2009|18:17] C:\Program Files\Veoh Networks
[04/05/2007|18:32] C:\Program Files\VIA
[03/03/2007|18:43] C:\Program Files\VIA Technologies, INC
[07/08/2006|20:49] C:\Program Files\ViaVoice
[18/12/2006|23:09] C:\Program Files\VibrateGameDeviceDriver
[09/08/2006|18:21] C:\Program Files\VideoLAN
[22/04/2007|10:19] C:\Program Files\Viewpoint
[04/01/2007|18:16] C:\Program Files\Vqao
[28/03/2009|17:56] C:\Program Files\Windows Live
[14/10/2006|10:17] C:\Program Files\Windows Live Safety Center
[28/03/2009|17:56] C:\Program Files\Windows Live SkyDrive
[11/05/2007|16:59] C:\Program Files\Windows Media Connect 2
[03/09/2008|21:13] C:\Program Files\Windows Media Player
[03/09/2008|21:13] C:\Program Files\Windows NT
[07/08/2006|18:13] C:\Program Files\WindowsUpdate
[26/03/2009|12:01] C:\Program Files\WinFast
[08/09/2007|18:38] C:\Program Files\WinPcap
[13/09/2008|18:48] C:\Program Files\WinRAR
[07/08/2006|18:17] C:\Program Files\xerox
[13/08/2006|15:21] C:\Program Files\XviD
[13/09/2008|19:13] C:\Program Files\Your Company Name

--------------------\\ Listing des dossiers dans C:\Program Files\Fichiers communs

[07/08/2006|19:46] C:\Program Files\Fichiers communs\Adaptec Shared
[19/11/2008|11:09] C:\Program Files\Fichiers communs\Adobe
[07/08/2006|20:25] C:\Program Files\Fichiers communs\Ahead
[18/11/2007|09:25] C:\Program Files\Fichiers communs\AVSMedia
[29/09/2006|17:50] C:\Program Files\Fichiers communs\BOONTY Shared
[28/02/2009|20:33] C:\Program Files\Fichiers communs\Creative
[09/08/2006|21:12] C:\Program Files\Fichiers communs\DESIGNER
[09/06/2009|17:20] C:\Program Files\Fichiers communs\DivX Shared
[07/08/2006|21:03] C:\Program Files\Fichiers communs\InstallShield
[09/08/2006|15:49] C:\Program Files\Fichiers communs\Java
[28/03/2009|13:20] C:\Program Files\Fichiers communs\LogiShrd
[28/03/2009|08:16] C:\Program Files\Fichiers communs\Logitech
[28/03/2009|13:04] C:\Program Files\Fichiers communs\Microsoft Shared
[07/08/2006|18:15] C:\Program Files\Fichiers communs\MSSoap
[04/05/2007|21:14] C:\Program Files\Fichiers communs\Nero
[21/06/2009|10:18] C:\Program Files\Fichiers communs\Nokia
[07/08/2006|19:04] C:\Program Files\Fichiers communs\ODBC
[22/04/2007|10:28] C:\Program Files\Fichiers communs\PC Tools
[21/06/2009|10:18] C:\Program Files\Fichiers communs\PCSuite
[07/08/2006|19:47] C:\Program Files\Fichiers communs\Roxio Shared
[07/08/2006|18:15] C:\Program Files\Fichiers communs\Services
[20/04/2007|20:58] C:\Program Files\Fichiers communs\Softwin
[07/08/2006|19:04] C:\Program Files\Fichiers communs\SpeechEngines
[28/08/2007|23:28] C:\Program Files\Fichiers communs\Symantec Shared
[03/09/2008|21:13] C:\Program Files\Fichiers communs\System
[07/08/2006|21:25] C:\Program Files\Fichiers communs\Ulead Systems
[28/03/2009|12:07] C:\Program Files\Fichiers communs\Windows Live
[26/02/2008|22:48] C:\Program Files\Fichiers communs\WindowsLiveInstaller

--------------------\\ Process

( 62 Processes )

... OK !

--------------------\\ Recherche avec S_Lop

Aucun fichier / dossier Lop trouvé !

--------------------\\ Recherche de Fichiers / Dossiers Lop

C:\DOCUME~1\marcs\LOCALS~1\Temp\DivoCodec-1.1.0.0-setup.exe
C:\DOCUME~1\marcs\LOCALS~1\Temp\HtmlControl.dll
C:\DOCUME~1\marcs\LOCALS~1\Temp\codec_dv.bmp
C:\DOCUME~1\marcs\LOCALS~1\Temp\DivoCodec-1.1.0.0-setup.exe
C:\DOCUME~1\marcs\APPLIC~1\Bitdownload
C:\DOCUME~1\marcs\APPLIC~1\BitDownload
C:\DOCUME~1\marcs\APPLIC~1\BitDownload\Data
C:\Program Files\DivoCodec
C:\DOCUME~1\marcs\Cookies\marcs@advertstream[1].txt
C:\DOCUME~1\marcs\Cookies\marcs@euroclick[1].txt
C:\DOCUME~1\marcs\Cookies\marcs@32vegas[1].txt
C:\DOCUME~1\marcs\Cookies\marcs@serve.32vegas[1].txt
C:\DOCUME~1\marcs\Cookies\marcs@www.32vegas[1].txt
C:\DOCUME~1\marcs\Cookies\marcs@www.32vegas[2].txt
C:\DOCUME~1\marcs\Cookies\marcs@2xmoinscher[2].txt
C:\DOCUME~1\marcs\Cookies\marcs@cc.2xmoinscher[2].txt
C:\DOCUME~1\marcs\Cookies\marcs@www.2xmoinscher[1].txt

--------------------\\ Verification du Registre

..... OK !

--------------------\\ Verification du fichier Hosts

Fichier Hosts MODIFIE

127.0.0.1 bin.errorprotector.com ## added by CiD
127.0.0.1 br.errorsafe.com ## added by CiD
127.0.0.1 br.winantivirus.com ## added by CiD
127.0.0.1 br.winfixer.com ## added by CiD
127.0.0.1 cdn.drivecleaner.com ## added by CiD
127.0.0.1 cdn.errorsafe.com ## added by CiD
127.0.0.1 cdn.winsoftware.com ## added by CiD
127.0.0.1 de.errorsafe.com ## added by CiD
127.0.0.1 de.winantivirus.com ## added by CiD
127.0.0.1 download.cdn.drivecleaner.com ## added by CiD
127.0.0.1 download.cdn.errorsafe.com ## added by CiD
127.0.0.1 download.cdn.winsoftware.com ## added by CiD
127.0.0.1 download.errorsafe.com ## added by CiD
127.0.0.1 download.systemdoctor.com ## added by CiD
127.0.0.1 download.winantispyware.com ## added by CiD
127.0.0.1 download.windrivecleaner.com ## added by CiD
127.0.0.1 download.winfixer.com ## added by CiD
127.0.0.1 drivecleaner.com ## added by CiD
127.0.0.1 dynamique.drivecleaner.com ## added by CiD
127.0.0.1 errorprotector.com ## added by CiD
127.0.0.1 errorsafe.com ## added by CiD
127.0.0.1 es.winantivirus.com ## added by CiD
127.0.0.1 fr.winantivirus.com ## added by CiD
127.0.0.1 fr.winfixer.com ## added by CiD
127.0.0.1 go.drivecleaner.com ## added by CiD
127.0.0.1 go.errorsafe.com ## added by CiD
127.0.0.1 go.winantispyware.com ## added by CiD
127.0.0.1 go.winantivirus.com ## added by CiD
127.0.0.1 hk.winantivirus.com ## added by CiD
127.0.0.1 instlog.errorsafe.com ## added by CiD
127.0.0.1 instlog.winantivirus.com ## added by CiD
127.0.0.1 instlog.winfixer.com ## added by CiD
127.0.0.1 jsp.drivecleaner.com ## added by CiD
127.0.0.1 kb.errorsafe.com ## added by CiD
127.0.0.1 kb.winantivirus.com ## added by CiD
127.0.0.1 nl.errorsafe.com ## added by CiD
127.0.0.1 se.errorsafe.com ## added by CiD
127.0.0.1 secure.drivecleaner.com ## added by CiD
127.0.0.1 secure.errorsafe.com ## added by CiD
127.0.0.1 secure.winantispam.com ## added by CiD
127.0.0.1 secure.winantispy.com ## added by CiD
127.0.0.1 secure.winantivirus.com ## added by CiD
127.0.0.1 support.winantivirus.com ## added by CiD
127.0.0.1 trial.updates.winsoftware.com ## added by CiD
127.0.0.1 ulog.winantivirus.com ## added by CiD
127.0.0.1 utils.errorsafe.com ## added by CiD
127.0.0.1 utils.winantivirus.com ## added by CiD
127.0.0.1 utils.winfixer.com ## added by CiD
127.0.0.1 winantispyware.com ## added by CiD
127.0.0.1 winantivirus.com ## added by CiD
127.0.0.1 winfixer.com ## added by CiD
127.0.0.1 winfixer2006.com ## added by CiD
127.0.0.1 winsoftware.com ## added by CiD
127.0.0.1 [i]ww/iw.drivecleaner.com ## added by CiD
127.0.0.1 [i]ww/iw.errorprotector.com ## added by CiD
127.0.0.1 [i]ww/iw.errorsafe.com ## added by CiD
127.0.0.1 [i]ww/iw.systemdoctor.com ## added by CiD
127.0.0.1 [i]ww/iw.utils.winfixer.com ## added by CiD
127.0.0.1 [i]ww/iw.win-anti-virus-pro.com ## added by CiD
127.0.0.1 [i]ww/iw.win-virus-pro.com ## added by CiD
127.0.0.1 [i]ww/iw.winantispam.com ## added by CiD
127.0.0.1 [i]ww/iw.winantispy.com ## added by CiD
127.0.0.1 [i]ww/iw.winantispyware.com ## added by CiD
127.0.0.1 [i]ww/iw.winantivirus.com ## added by CiD
127.0.0.1 [i]ww/iw.winantiviruspro.com ## added by CiD
127.0.0.1 [i]ww/iw.windrivecleaner.com ## added by CiD
127.0.0.1 [i]ww/iw.windrivesafe.com ## added by CiD
127.0.0.1 [i]ww/iw.winfixer.com ## added by CiD
127.0.0.1 [i]ww/iw.winfixer2006.com ## added by CiD
127.0.0.1 [i]ww/iw.winsoftware.com ## added by CiD

-> 72 [ 70 ## added by CiD ]

--------------------\\ Recherche de fichiers avec Catchme

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-22 17:26:03
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 2

--------------------\\ Recherche d'autres infections

C:\WINDOWS\Pack.epk
C:\WINDOWS\System32\nvs2.inf

C:\DOCUME~1\marcs\LOCALS~1\APPLIC~1\ugkuc.dat
C:\DOCUME~1\marcs\LOCALS~1\APPLIC~1\ugkuc.exe
C:\DOCUME~1\marcs\LOCALS~1\APPLIC~1\ugkuc_nav.dat
C:\DOCUME~1\marcs\LOCALS~1\APPLIC~1\ugkuc_navps.dat
C:\WINDOWS\System32\spirxhelf.dat
C:\WINDOWS\System32\spirxhelf_nav.dat
C:\WINDOWS\System32\spirxhelf_navps.dat
C:\WINDOWS\System32\spirxhelf_navup.dat
C:\WINDOWS\System32\xbgrkaiv.dat
C:\WINDOWS\System32\xbgrkaiv_navup.dat
[b]==> EGDACCESS <==/b

C:\WINDOWS\exefld
[b]==> BAGLE <==/b

--------------------\\ ROOTKIT !!

Rootkit Bagle ! .. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SROSA]
Rootkit Bagle ! .. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_SROSA]
Rootkit Bagle ! .. [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA]
Rootkit Bagle ! .. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\srosa]
Rootkit Bagle ! .. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\srosa]
Rootkit Bagle ! .. [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\srosa]



[F:10599][D:556]-> C:\DOCUME~1\marcs\LOCALS~1\Temp
[F:1820][D:0]-> C:\DOCUME~1\marcs\Cookies
[F:20051][D:81]-> C:\DOCUME~1\marcs\LOCALS~1\TEMPOR~1\content.IE5

1 - "C:\Lop SD\LopR_1.txt" - 22/06/2009|17:29 - Option : [1]

--------------------\\ Fin du rapport a 17:29:33
Merci
0
Utilisateur anonyme
 
ok.....
La suite stp....

a+
0
marcugodelire
 
Voici le rapport :

--------------------\\ Lop S&D 4.2.5-0 XP/Vista

Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 3
X86-based PC ( Multiprocessor Free : Intel(R) Core(TM)2 CPU 4300 @ 1.80GHz )
BIOS : Default System BIOS
USER : marcs ( Administrator )
BOOT : Normal boot
Antivirus : Securitoo AntiVirus Firewall 8.00 8.00 (Activated)
Firewall : Securitoo AntiVirus Firewall 8.00 8.00 (Activated)
A:\ (USB)
C:\ (Local Disk) - NTFS - Total:76 Go (Free:19 Go)
D:\ (Local Disk) - NTFS - Total:31 Go (Free:23 Go)
E:\ (CD or DVD)

"C:\Lop SD" ( MAJ : 19-12-2008|23:40 )
Option : [1] ( 22/06/2009|17:22 )

--------------------\\ Listing des dossiers dans APPLIC~1


[18/10/2007|10:47] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[04/05/2007|21:04] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Ahead
[31/05/2009|14:04] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
[18/11/2007|09:24] C:\DOCUME~1\ALLUSE~1\APPLIC~1\AVS4YOU
[29/09/2006|17:51] C:\DOCUME~1\ALLUSE~1\APPLIC~1\BOONTY
[28/02/2009|20:41] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Creative
[12/04/2008|13:48] C:\DOCUME~1\ALLUSE~1\APPLIC~1\DVD Shrink
[22/11/2006|20:51] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Exetender
[28/03/2009|16:08] C:\DOCUME~1\ALLUSE~1\APPLIC~1\F-Secure
[28/03/2009|16:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\fssg
[21/06/2009|10:15] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Installations
[11/02/2008|22:51] C:\DOCUME~1\ALLUSE~1\APPLIC~1\InstallShield
[28/03/2009|13:17] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Logishrd
[20/11/2007|10:17] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Logitech
[28/08/2007|10:58] C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee
[28/03/2009|13:04] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[03/02/2008|19:53] C:\DOCUME~1\ALLUSE~1\APPLIC~1\MSScanAppDataDir
[02/06/2007|22:50] C:\DOCUME~1\ALLUSE~1\APPLIC~1\muvee Technologies
[04/05/2007|19:50] C:\DOCUME~1\ALLUSE~1\APPLIC~1\NVIDIA
[08/03/2008|10:07] C:\DOCUME~1\ALLUSE~1\APPLIC~1\nView_Profiles
[16/11/2008|10:18] C:\DOCUME~1\ALLUSE~1\APPLIC~1\PC Suite
[22/04/2007|10:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\PC Tools
[23/12/2006|23:11] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Pinnacle
[23/12/2006|23:29] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Pinnacle Studio
[23/12/2006|23:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SmartSound Software Inc
[01/09/2007|14:51] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
[28/08/2007|10:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec
[22/04/2007|11:58] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
[07/08/2006|21:03] C:\DOCUME~1\ALLUSE~1\APPLIC~1\UDL
[07/08/2006|21:25] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Ulead Systems
[22/04/2007|10:19] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Viewpoint
[08/08/2006|22:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[26/02/2008|22:48] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller


[09/12/2007|13:02] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft


[14/05/2007|17:33] C:\DOCUME~1\hugo\APPLIC~1\ATI
[07/08/2006|18:23] C:\DOCUME~1\hugo\APPLIC~1\Identities
[03/02/2007|21:46] C:\DOCUME~1\hugo\APPLIC~1\Macromedia
[14/05/2007|17:33] C:\DOCUME~1\hugo\APPLIC~1\Microsoft
[30/09/2006|20:14] C:\DOCUME~1\hugo\APPLIC~1\Symantec

[12/12/2006|17:18] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft

[18/10/2007|10:47] C:\DOCUME~1\marcs\APPLIC~1\Adobe
[09/05/2007|16:17] C:\DOCUME~1\marcs\APPLIC~1\AdobeUM
[21/03/2008|18:46] C:\DOCUME~1\marcs\APPLIC~1\Ahead
[13/08/2006|15:01] C:\DOCUME~1\marcs\APPLIC~1\Apple Computer
[12/05/2007|20:57] C:\DOCUME~1\marcs\APPLIC~1\ATI
[10/11/2006|21:35] C:\DOCUME~1\marcs\APPLIC~1\Azureus
[21/02/2007|22:46] C:\DOCUME~1\marcs\APPLIC~1\BitDownload
[19/06/2009|10:35] C:\DOCUME~1\marcs\APPLIC~1\ChessBase
[28/03/2009|08:16] C:\DOCUME~1\marcs\APPLIC~1\Creative
[23/12/2006|19:38] C:\DOCUME~1\marcs\APPLIC~1\CyberLink
[14/11/2007|09:33] C:\DOCUME~1\marcs\APPLIC~1\Dealio
[15/03/2007|16:24] C:\DOCUME~1\marcs\APPLIC~1\DivX
[24/12/2007|22:51] C:\DOCUME~1\marcs\APPLIC~1\dvdcss
[21/08/2007|20:43] C:\DOCUME~1\marcs\APPLIC~1\EPSON
[16/06/2009|09:39] C:\DOCUME~1\marcs\APPLIC~1\EssentialPIM
[11/02/2008|23:14] C:\DOCUME~1\marcs\APPLIC~1\EssentialPIM Pro
[09/11/2008|09:57] C:\DOCUME~1\marcs\APPLIC~1\FMZilla
[15/06/2008|18:56] C:\DOCUME~1\marcs\APPLIC~1\F-Secure
[31/05/2008|15:35] C:\DOCUME~1\marcs\APPLIC~1\GARMIN
[22/10/2008|20:52] C:\DOCUME~1\marcs\APPLIC~1\Google
[17/05/2007|08:25] C:\DOCUME~1\marcs\APPLIC~1\Goto.Games
[24/05/2007|21:51] C:\DOCUME~1\marcs\APPLIC~1\Help
[29/08/2007|12:13] C:\DOCUME~1\marcs\APPLIC~1\HouseCall 6.6
[07/08/2006|18:24] C:\DOCUME~1\marcs\APPLIC~1\Identities
[22/12/2008|15:43] C:\DOCUME~1\marcs\APPLIC~1\IEPro
[13/05/2007|10:23] C:\DOCUME~1\marcs\APPLIC~1\InstallShield
[01/09/2007|15:04] C:\DOCUME~1\marcs\APPLIC~1\ispnews
[13/12/2007|08:41] C:\DOCUME~1\marcs\APPLIC~1\Joost
[02/10/2006|22:08] C:\DOCUME~1\marcs\APPLIC~1\Lavasoft
[25/01/2009|11:49] C:\DOCUME~1\marcs\APPLIC~1\Leadertech
[08/08/2006|18:19] C:\DOCUME~1\marcs\APPLIC~1\Macromedia
[17/04/2009|20:40] C:\DOCUME~1\marcs\APPLIC~1\Microsoft
[07/08/2006|19:36] C:\DOCUME~1\marcs\APPLIC~1\Microsoft Web Folders
[28/03/2009|16:45] C:\DOCUME~1\marcs\APPLIC~1\MiniDm
[08/02/2008|23:24] C:\DOCUME~1\marcs\APPLIC~1\Mozilla
[21/06/2009|21:07] C:\DOCUME~1\marcs\APPLIC~1\Nokia
[01/09/2007|15:18] C:\DOCUME~1\marcs\APPLIC~1\ntr
[26/10/2008|11:34] C:\DOCUME~1\marcs\APPLIC~1\PC Suite
[20/04/2007|21:00] C:\DOCUME~1\marcs\APPLIC~1\PC Tools
[18/11/2006|17:38] C:\DOCUME~1\marcs\APPLIC~1\Roxio
[17/06/2007|08:50] C:\DOCUME~1\marcs\APPLIC~1\SecondLife
[08/08/2006|18:13] C:\DOCUME~1\marcs\APPLIC~1\SendPix
[09/08/2006|15:52] C:\DOCUME~1\marcs\APPLIC~1\Sun
[01/10/2006|15:30] C:\DOCUME~1\marcs\APPLIC~1\Symantec
[08/02/2008|23:25] C:\DOCUME~1\marcs\APPLIC~1\Talkback
[19/11/2007|13:07] C:\DOCUME~1\marcs\APPLIC~1\Uniblue
[22/04/2007|10:19] C:\DOCUME~1\marcs\APPLIC~1\Viewpoint
[13/09/2008|07:30] C:\DOCUME~1\marcs\APPLIC~1\vlc
[03/10/2006|17:17] C:\DOCUME~1\marcs\APPLIC~1\WholeSecurity

[27/10/2007|14:12] C:\DOCUME~1\nathalie\APPLIC~1\Adobe
[13/05/2007|08:34] C:\DOCUME~1\nathalie\APPLIC~1\ATI
[12/08/2008|22:38] C:\DOCUME~1\nathalie\APPLIC~1\Babylon
[18/11/2007|21:54] C:\DOCUME~1\nathalie\APPLIC~1\DivX
[03/10/2008|14:56] C:\DOCUME~1\nathalie\APPLIC~1\EssentialPIM
[13/09/2008|21:26] C:\DOCUME~1\nathalie\APPLIC~1\F-Secure
[29/10/2006|20:49] C:\DOCUME~1\nathalie\APPLIC~1\Help
[15/08/2006|09:14] C:\DOCUME~1\nathalie\APPLIC~1\Identities
[23/12/2008|22:30] C:\DOCUME~1\nathalie\APPLIC~1\IEPro
[06/09/2007|21:20] C:\DOCUME~1\nathalie\APPLIC~1\ispnews
[15/08/2006|18:29] C:\DOCUME~1\nathalie\APPLIC~1\Macromedia
[12/08/2008|15:09] C:\DOCUME~1\nathalie\APPLIC~1\Microsoft
[10/01/2009|17:05] C:\DOCUME~1\nathalie\APPLIC~1\PC Suite
[03/06/2007|09:07] C:\DOCUME~1\nathalie\APPLIC~1\Roxio
[26/10/2006|15:13] C:\DOCUME~1\nathalie\APPLIC~1\Sun
[02/08/2007|11:00] C:\DOCUME~1\nathalie\APPLIC~1\Symantec
[27/04/2007|10:19] C:\DOCUME~1\nathalie\APPLIC~1\Viewpoint
[13/12/2007|19:10] C:\DOCUME~1\nathalie\APPLIC~1\vlc

[07/08/2006|18:20] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft
[07/08/2006|19:34] C:\DOCUME~1\NETWOR~1\APPLIC~1\Symantec

[29/03/2009|18:24] C:\DOCUME~1\nina\APPLIC~1\Adobe
[27/12/2006|19:12] C:\DOCUME~1\nina\APPLIC~1\Identities
[29/03/2009|18:28] C:\DOCUME~1\nina\APPLIC~1\InstallShield
[07/02/2009|10:47] C:\DOCUME~1\nina\APPLIC~1\ispnews
[29/03/2009|18:28] C:\DOCUME~1\nina\APPLIC~1\Microsoft
[29/03/2009|18:22] C:\DOCUME~1\nina\APPLIC~1\PC Suite
[27/12/2006|19:12] C:\DOCUME~1\nina\APPLIC~1\Symantec

--------------------\\ Tâches planifiées dans C:\WINDOWS\tasks

[22/06/2009 15:08][--ah-----] C:\WINDOWS\tasks\User_Feed_Synchronization-{DC53D839-98D3-441F-A3EF-017C0B7C4F22}.job
[22/06/2009 15:01][--a------] C:\WINDOWS\tasks\Scheduled scanning task.job
[22/06/2009 15:00][--ah-----] C:\WINDOWS\tasks\SA.DAT
[24/04/2003 14:00][-r-h-----] C:\WINDOWS\tasks\desktop.ini

--------------------\\ Listing des dossiers dans C:\Program Files

[07/08/2006|19:44] C:\Program Files\Actebis
[19/11/2008|11:09] C:\Program Files\Adobe
[31/05/2009|13:56] C:\Program Files\adslTV
[04/05/2007|21:18] C:\Program Files\Ahead
[27/08/2007|12:11] C:\Program Files\Aleker
[14/08/2008|10:43] C:\Program Files\Auralog
[01/09/2007|11:38] C:\Program Files\CCleaner
[13/09/2008|13:41] C:\Program Files\ChessBase
[17/09/2008|17:49] C:\Program Files\Common Files
[07/08/2006|18:14] C:\Program Files\ComPlus Applications
[06/08/2008|20:46] C:\Program Files\Conduit
[09/08/2006|17:41] C:\Program Files\Convar
[28/02/2009|20:35] C:\Program Files\Creative
[28/02/2009|20:35] C:\Program Files\Creative Installation Information
[15/06/2009|11:35] C:\Program Files\CSV2ASC
[23/12/2006|22:55] C:\Program Files\CyberLink
[26/10/2008|11:27] C:\Program Files\DIFX
[12/12/2006|20:25] C:\Program Files\directx
[30/05/2009|15:39] C:\Program Files\DivoCodec
[09/06/2009|17:21] C:\Program Files\DivX
[11/03/2008|23:26] C:\Program Files\DMV
[17/06/2007|19:49] C:\Program Files\DVD Shrink
[19/01/2007|15:52] C:\Program Files\EA SPORTS
[22/06/2009|15:06] C:\Program Files\eMule
[07/08/2006|21:16] C:\Program Files\EPSON
[01/08/2007|08:50] C:\Program Files\EssentialPIM
[21/06/2009|10:18] C:\Program Files\Fichiers communs
[19/09/2006|21:09] C:\Program Files\FileZilla
[07/08/2006|20:41] C:\Program Files\FoneSync
[11/11/2007|11:26] C:\Program Files\Free Audio Pack
[07/08/2006|19:51] C:\Program Files\Free.fr
[06/02/2009|21:45] C:\Program Files\Freecorder
[07/06/2007|18:37] C:\Program Files\Freeplayer
[22/10/2008|20:51] C:\Program Files\Google
[09/11/2008|19:29] C:\Program Files\Goto.Games
[01/06/2007|17:23] C:\Program Files\HardwareDetection
[22/12/2008|15:43] C:\Program Files\IEForge
[22/12/2008|15:43] C:\Program Files\IEPro
[31/05/2009|20:58] C:\Program Files\InstallShield Installation Information
[13/06/2009|12:07] C:\Program Files\Internet Explorer
[01/04/2009|21:37] C:\Program Files\Java
[28/03/2009|13:17] C:\Program Files\Logitech
[03/09/2008|21:19] C:\Program Files\Messenger
[09/11/2008|19:29] C:\Program Files\Micro Scrabble
[28/03/2009|17:56] C:\Program Files\Microsoft
[27/02/2008|13:03] C:\Program Files\Microsoft CAPICOM 2.1.0.2
[07/08/2006|19:35] C:\Program Files\microsoft frontpage
[09/08/2006|14:38] C:\Program Files\Microsoft Money
[02/02/2007|20:08] C:\Program Files\Microsoft Office
[07/08/2006|20:47] C:\Program Files\Microsoft Windows Script
[07/08/2006|20:38] C:\Program Files\Microsoft Works
[07/08/2006|20:33] C:\Program Files\Microsoft Works Suite 2001
[09/08/2006|21:13] C:\Program Files\Microsoft.NET
[01/02/2008|19:19] C:\Program Files\Mio DigiWalker
[31/01/2008|22:17] C:\Program Files\Mio Technology
[03/09/2008|21:16] C:\Program Files\Movie Maker
[15/06/2009|11:40] C:\Program Files\Mozilla Firefox
[19/01/2008|18:14] C:\Program Files\MP3 Player Utilities 3.5.02
[19/01/2008|18:13] C:\Program Files\MP3 Player Utilities 4.13
[23/05/2009|22:05] C:\Program Files\MSBuild
[02/02/2007|20:07] C:\Program Files\MSECache
[07/08/2006|18:13] C:\Program Files\MSN
[07/08/2006|18:13] C:\Program Files\MSN Gaming Zone
[17/11/2006|18:10] C:\Program Files\MSXML 4.0
[08/09/2007|18:38] C:\Program Files\NetAnalyse
[03/09/2008|21:13] C:\Program Files\NetMeeting
[21/06/2009|10:18] C:\Program Files\Nokia
[09/08/2006|22:13] C:\Program Files\OfficeUpdate11
[03/09/2008|21:34] C:\Program Files\Outlook Express
[31/05/2009|14:04] C:\Program Files\Papi
[21/06/2009|10:17] C:\Program Files\PC Connectivity Solution
[23/12/2006|23:07] C:\Program Files\Pinnacle
[13/08/2006|14:55] C:\Program Files\QuickTime
[04/11/2008|17:42] C:\Program Files\Radio Fr Solo
[18/08/2007|08:26] C:\Program Files\RayV
[02/06/2007|19:50] C:\Program Files\Realtek
[23/05/2009|22:05] C:\Program Files\Reference Assemblies
[03/06/2008|18:38] C:\Program Files\Securitoo
[07/08/2006|18:13] C:\Program Files\Services en ligne
[26/10/2007|11:50] C:\Program Files\Share_Accelerator_MM
[09/08/2006|17:30] C:\Program Files\Smart Projects
[23/12/2006|23:06] C:\Program Files\SmartSound Software
[11/11/2007|02:01] C:\Program Files\SystemRequirementsLab
[22/06/2009|16:44] C:\Program Files\trend micro
[07/08/2006|21:25] C:\Program Files\Ulead Systems
[07/08/2006|18:23] C:\Program Files\Uninstall Information
[26/05/2009|18:17] C:\Program Files\Veoh Networks
[04/05/2007|18:32] C:\Program Files\VIA
[03/03/2007|18:43] C:\Program Files\VIA Technologies, INC
[07/08/2006|20:49] C:\Program Files\ViaVoice
[18/12/2006|23:09] C:\Program Files\VibrateGameDeviceDriver
[09/08/2006|18:21] C:\Program Files\VideoLAN
[22/04/2007|10:19] C:\Program Files\Viewpoint
[04/01/2007|18:16] C:\Program Files\Vqao
[28/03/2009|17:56] C:\Program Files\Windows Live
[14/10/2006|10:17] C:\Program Files\Windows Live Safety Center
[28/03/2009|17:56] C:\Program Files\Windows Live SkyDrive
[11/05/2007|16:59] C:\Program Files\Windows Media Connect 2
[03/09/2008|21:13] C:\Program Files\Windows Media Player
[03/09/2008|21:13] C:\Program Files\Windows NT
[07/08/2006|18:13] C:\Program Files\WindowsUpdate
[26/03/2009|12:01] C:\Program Files\WinFast
[08/09/2007|18:38] C:\Program Files\WinPcap
[13/09/2008|18:48] C:\Program Files\WinRAR
[07/08/2006|18:17] C:\Program Files\xerox
[13/08/2006|15:21] C:\Program Files\XviD
[13/09/2008|19:13] C:\Program Files\Your Company Name

--------------------\\ Listing des dossiers dans C:\Program Files\Fichiers communs

[07/08/2006|19:46] C:\Program Files\Fichiers communs\Adaptec Shared
[19/11/2008|11:09] C:\Program Files\Fichiers communs\Adobe
[07/08/2006|20:25] C:\Program Files\Fichiers communs\Ahead
[18/11/2007|09:25] C:\Program Files\Fichiers communs\AVSMedia
[29/09/2006|17:50] C:\Program Files\Fichiers communs\BOONTY Shared
[28/02/2009|20:33] C:\Program Files\Fichiers communs\Creative
[09/08/2006|21:12] C:\Program Files\Fichiers communs\DESIGNER
[09/06/2009|17:20] C:\Program Files\Fichiers communs\DivX Shared
[07/08/2006|21:03] C:\Program Files\Fichiers communs\InstallShield
[09/08/2006|15:49] C:\Program Files\Fichiers communs\Java
[28/03/2009|13:20] C:\Program Files\Fichiers communs\LogiShrd
[28/03/2009|08:16] C:\Program Files\Fichiers communs\Logitech
[28/03/2009|13:04] C:\Program Files\Fichiers communs\Microsoft Shared
[07/08/2006|18:15] C:\Program Files\Fichiers communs\MSSoap
[04/05/2007|21:14] C:\Program Files\Fichiers communs\Nero
[21/06/2009|10:18] C:\Program Files\Fichiers communs\Nokia
[07/08/2006|19:04] C:\Program Files\Fichiers communs\ODBC
[22/04/2007|10:28] C:\Program Files\Fichiers communs\PC Tools
[21/06/2009|10:18] C:\Program Files\Fichiers communs\PCSuite
[07/08/2006|19:47] C:\Program Files\Fichiers communs\Roxio Shared
[07/08/2006|18:15] C:\Program Files\Fichiers communs\Services
[20/04/2007|20:58] C:\Program Files\Fichiers communs\Softwin
[07/08/2006|19:04] C:\Program Files\Fichiers communs\SpeechEngines
[28/08/2007|23:28] C:\Program Files\Fichiers communs\Symantec Shared
[03/09/2008|21:13] C:\Program Files\Fichiers communs\System
[07/08/2006|21:25] C:\Program Files\Fichiers communs\Ulead Systems
[28/03/2009|12:07] C:\Program Files\Fichiers communs\Windows Live
[26/02/2008|22:48] C:\Program Files\Fichiers communs\WindowsLiveInstaller

--------------------\\ Process

( 62 Processes )

... OK !

--------------------\\ Recherche avec S_Lop

Aucun fichier / dossier Lop trouvé !

--------------------\\ Recherche de Fichiers / Dossiers Lop

C:\DOCUME~1\marcs\LOCALS~1\Temp\DivoCodec-1.1.0.0-setup.exe
C:\DOCUME~1\marcs\LOCALS~1\Temp\HtmlControl.dll
C:\DOCUME~1\marcs\LOCALS~1\Temp\codec_dv.bmp
C:\DOCUME~1\marcs\LOCALS~1\Temp\DivoCodec-1.1.0.0-setup.exe
C:\DOCUME~1\marcs\APPLIC~1\Bitdownload
C:\DOCUME~1\marcs\APPLIC~1\BitDownload
C:\DOCUME~1\marcs\APPLIC~1\BitDownload\Data
C:\Program Files\DivoCodec
C:\DOCUME~1\marcs\Cookies\marcs@advertstream[1].txt
C:\DOCUME~1\marcs\Cookies\marcs@euroclick[1].txt
C:\DOCUME~1\marcs\Cookies\marcs@32vegas[1].txt
C:\DOCUME~1\marcs\Cookies\marcs@serve.32vegas[1].txt
C:\DOCUME~1\marcs\Cookies\marcs@www.32vegas[1].txt
C:\DOCUME~1\marcs\Cookies\marcs@www.32vegas[2].txt
C:\DOCUME~1\marcs\Cookies\marcs@2xmoinscher[2].txt
C:\DOCUME~1\marcs\Cookies\marcs@cc.2xmoinscher[2].txt
C:\DOCUME~1\marcs\Cookies\marcs@www.2xmoinscher[1].txt

--------------------\\ Verification du Registre

..... OK !

--------------------\\ Verification du fichier Hosts

Fichier Hosts MODIFIE

127.0.0.1 bin.errorprotector.com ## added by CiD
127.0.0.1 br.errorsafe.com ## added by CiD
127.0.0.1 br.winantivirus.com ## added by CiD
127.0.0.1 br.winfixer.com ## added by CiD
127.0.0.1 cdn.drivecleaner.com ## added by CiD
127.0.0.1 cdn.errorsafe.com ## added by CiD
127.0.0.1 cdn.winsoftware.com ## added by CiD
127.0.0.1 de.errorsafe.com ## added by CiD
127.0.0.1 de.winantivirus.com ## added by CiD
127.0.0.1 download.cdn.drivecleaner.com ## added by CiD
127.0.0.1 download.cdn.errorsafe.com ## added by CiD
127.0.0.1 download.cdn.winsoftware.com ## added by CiD
127.0.0.1 download.errorsafe.com ## added by CiD
127.0.0.1 download.systemdoctor.com ## added by CiD
127.0.0.1 download.winantispyware.com ## added by CiD
127.0.0.1 download.windrivecleaner.com ## added by CiD
127.0.0.1 download.winfixer.com ## added by CiD
127.0.0.1 drivecleaner.com ## added by CiD
127.0.0.1 dynamique.drivecleaner.com ## added by CiD
127.0.0.1 errorprotector.com ## added by CiD
127.0.0.1 errorsafe.com ## added by CiD
127.0.0.1 es.winantivirus.com ## added by CiD
127.0.0.1 fr.winantivirus.com ## added by CiD
127.0.0.1 fr.winfixer.com ## added by CiD
127.0.0.1 go.drivecleaner.com ## added by CiD
127.0.0.1 go.errorsafe.com ## added by CiD
127.0.0.1 go.winantispyware.com ## added by CiD
127.0.0.1 go.winantivirus.com ## added by CiD
127.0.0.1 hk.winantivirus.com ## added by CiD
127.0.0.1 instlog.errorsafe.com ## added by CiD
127.0.0.1 instlog.winantivirus.com ## added by CiD
127.0.0.1 instlog.winfixer.com ## added by CiD
127.0.0.1 jsp.drivecleaner.com ## added by CiD
127.0.0.1 kb.errorsafe.com ## added by CiD
127.0.0.1 kb.winantivirus.com ## added by CiD
127.0.0.1 nl.errorsafe.com ## added by CiD
127.0.0.1 se.errorsafe.com ## added by CiD
127.0.0.1 secure.drivecleaner.com ## added by CiD
127.0.0.1 secure.errorsafe.com ## added by CiD
127.0.0.1 secure.winantispam.com ## added by CiD
127.0.0.1 secure.winantispy.com ## added by CiD
127.0.0.1 secure.winantivirus.com ## added by CiD
127.0.0.1 support.winantivirus.com ## added by CiD
127.0.0.1 trial.updates.winsoftware.com ## added by CiD
127.0.0.1 ulog.winantivirus.com ## added by CiD
127.0.0.1 utils.errorsafe.com ## added by CiD
127.0.0.1 utils.winantivirus.com ## added by CiD
127.0.0.1 utils.winfixer.com ## added by CiD
127.0.0.1 winantispyware.com ## added by CiD
127.0.0.1 winantivirus.com ## added by CiD
127.0.0.1 winfixer.com ## added by CiD
127.0.0.1 winfixer2006.com ## added by CiD
127.0.0.1 winsoftware.com ## added by CiD
127.0.0.1 [i]ww/iw.drivecleaner.com ## added by CiD
127.0.0.1 [i]ww/iw.errorprotector.com ## added by CiD
127.0.0.1 [i]ww/iw.errorsafe.com ## added by CiD
127.0.0.1 [i]ww/iw.systemdoctor.com ## added by CiD
127.0.0.1 [i]ww/iw.utils.winfixer.com ## added by CiD
127.0.0.1 [i]ww/iw.win-anti-virus-pro.com ## added by CiD
127.0.0.1 [i]ww/iw.win-virus-pro.com ## added by CiD
127.0.0.1 [i]ww/iw.winantispam.com ## added by CiD
127.0.0.1 [i]ww/iw.winantispy.com ## added by CiD
127.0.0.1 [i]ww/iw.winantispyware.com ## added by CiD
127.0.0.1 [i]ww/iw.winantivirus.com ## added by CiD
127.0.0.1 [i]ww/iw.winantiviruspro.com ## added by CiD
127.0.0.1 [i]ww/iw.windrivecleaner.com ## added by CiD
127.0.0.1 [i]ww/iw.windrivesafe.com ## added by CiD
127.0.0.1 [i]ww/iw.winfixer.com ## added by CiD
127.0.0.1 [i]ww/iw.winfixer2006.com ## added by CiD
127.0.0.1 [i]ww/iw.winsoftware.com ## added by CiD

-> 72 [ 70 ## added by CiD ]

--------------------\\ Recherche de fichiers avec Catchme

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-22 17:26:03
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 2

--------------------\\ Recherche d'autres infections

C:\WINDOWS\Pack.epk
C:\WINDOWS\System32\nvs2.inf

C:\DOCUME~1\marcs\LOCALS~1\APPLIC~1\ugkuc.dat
C:\DOCUME~1\marcs\LOCALS~1\APPLIC~1\ugkuc.exe
C:\DOCUME~1\marcs\LOCALS~1\APPLIC~1\ugkuc_nav.dat
C:\DOCUME~1\marcs\LOCALS~1\APPLIC~1\ugkuc_navps.dat
C:\WINDOWS\System32\spirxhelf.dat
C:\WINDOWS\System32\spirxhelf_nav.dat
C:\WINDOWS\System32\spirxhelf_navps.dat
C:\WINDOWS\System32\spirxhelf_navup.dat
C:\WINDOWS\System32\xbgrkaiv.dat
C:\WINDOWS\System32\xbgrkaiv_navup.dat
[b]==> EGDACCESS <==/b

C:\WINDOWS\exefld
[b]==> BAGLE <==/b

--------------------\\ ROOTKIT !!

Rootkit Bagle ! .. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SROSA]
Rootkit Bagle ! .. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_SROSA]
Rootkit Bagle ! .. [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA]
Rootkit Bagle ! .. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\srosa]
Rootkit Bagle ! .. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\srosa]
Rootkit Bagle ! .. [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\srosa]



[F:10599][D:556]-> C:\DOCUME~1\marcs\LOCALS~1\Temp
[F:1820][D:0]-> C:\DOCUME~1\marcs\Cookies
[F:20051][D:81]-> C:\DOCUME~1\marcs\LOCALS~1\TEMPOR~1\content.IE5

1 - "C:\Lop SD\LopR_1.txt" - 22/06/2009|17:29 - Option : [1]

--------------------\\ Fin du rapport a 17:29:33
Merci
_______________________________________________________
Pour répondre au message de marcugodelire, merci de cliquer sur le lien ci-dessous:
http://www.commentcamarche.net/forum/affich 13000780 infection par virus w32 winfixer gen a#2009 06 22%2017%3A06%3A27

Pour arrêter les envois de mails concernant cette discussion, veuillez cliquer sur le lien suivant:
https://forums.commentcamarche.net/forum/stopmail.php3?id=13000780&P=e3035a6665cb0672749a89896bb68703


--
CommentÇaMarche.net, Communautés d'assistance et de conseils
https://www.commentcamarche.net/
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
Utilisateur anonyme
 
Le rapport Navilog stp.....

a+
0
marcugodelire
 
Fix Navipromo version 4.0.0 commencé le 22/06/2009 à 18:08:21,67

!!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
!!! Postez ce rapport sur le forum pour le faire analyser !!!

Outil exécuté depuis C:\Program Files\navilog1

Mise à jour le 19.06.2009 à 20h00 par IL-MAFIOSO

Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 3
X86-based PC ( Multiprocessor Free : Intel(R) Core(TM)2 CPU 4300 @ 1.80GHz )
BIOS : Default System BIOS
USER : marcs ( Administrator )
BOOT : Normal boot

Antivirus : Securitoo AntiVirus Firewall 8.00 8.00 (Activated)
Firewall : Securitoo AntiVirus Firewall 8.00 8.00 (Activated)

A:\ (USB)
C:\ (Local Disk) - NTFS - Total:76 Go (Free:18 Go)
D:\ (Local Disk) - NTFS - Total:31 Go (Free:23 Go)
E:\ (CD or DVD)


Recherche exécutée en mode normal

Nettoyage exécuté au redémarrage de l'ordinateur


C:\WINDOWS\pack.epk supprimé !
C:\WINDOWS\system32\nvs2.inf supprimé !
C:\WINDOWS\system32\spirxhelf.dat supprimé !
C:\WINDOWS\system32\spirxhelf_nav.dat supprimé !
C:\WINDOWS\system32\spirxhelf_navps.dat supprimé !
C:\WINDOWS\system32\spirxhelf_navup.dat supprimé !
C:\WINDOWS\prefetch\ugkuc*.pf supprimé !
C:\WINDOWS\system32\xbgrkaiv.dat supprimé !
C:\WINDOWS\system32\xbgrkaiv_navup.dat supprimé !
C:\Documents and Settings\marcs\locals~1\applic~1\ugkuc.exe supprimé !
C:\Documents and Settings\marcs\locals~1\applic~1\ugkuc.dat supprimé !
C:\Documents and Settings\marcs\locals~1\applic~1\ugkuc_nav.dat supprimé !
C:\Documents and Settings\marcs\locals~1\applic~1\ugkuc_navps.dat supprimé !


Nettoyage contenu C:\WINDOWS\Temp effectué !
Nettoyage contenu C:\Documents and Settings\marcs\locals~1\Temp effectué !


*** Sauvegarde du Registre vers dossier Safebackup ***

sauvegarde du Registre réalisée avec succès !

*** Nettoyage Registre ***

Nettoyage Registre Ok




*** Scan terminé le 22/06/2009 à 18:35:00,29 ***
0
Utilisateur anonyme
 
Super....
Mais y'a encore du boulot......

1)
Reprends LopSD.exe
Choisis cette fois l'option:2
Ne fermes pas la fenètre pendant la suppression !
Postes le rapport généré.

*******

2)
Télécharges FindyKill de Chiquitine29 :

http://sd-1.archive-host.com/membres/up/116615172019703188/FindyKill.exe

->Enregistres le sur ton bureau et pas ailleurs !

!! Déconnectes toi et fermes toute applications en cours !!

( Si ton anti-virus s'affolle au moment de l'enregistrement ou de l'utilisation de l'outil , ignore l'alerte ...)

-> Cliques sur "FindyKill.exe" pour lancer l'installe de l'outil . Ne touche surtout pas aux paramètres d'installation.

--> Double cliques sur le raccourci " FindyKill " qui est sur ton bureau .

-->choisis l'option 1 ( recherche ) . Puis laisses travailler l'outil sans rien toucher ...

Une fois terminé, postes le rapport FindyKill.txt qui est généré ...

( Note : le rapport est sauvegardé à la racine du disque -> C:\FindyKill.txt )

a+
0
marcugodelire
 
Rapport lop avec option 2

--------------------\\ Lop S&D 4.2.5-0 XP/Vista

Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 3
X86-based PC ( Multiprocessor Free : Intel(R) Core(TM)2 CPU 4300 @ 1.80GHz )
BIOS : Default System BIOS
USER : marcs ( Administrator )
BOOT : Normal boot
Antivirus : Securitoo AntiVirus Firewall 8.00 8.00 (Activated)
Firewall : Securitoo AntiVirus Firewall 8.00 8.00 (Activated)
A:\ (USB)
C:\ (Local Disk) - NTFS - Total:76 Go (Free:20 Go)
D:\ (Local Disk) - NTFS - Total:31 Go (Free:23 Go)
E:\ (CD or DVD)

"C:\Lop SD" ( MAJ : 19-12-2008|23:40 )
Option : [2] ( 23/06/2009|15:41 )


\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ SUPPRESSION

Supprime! - C:\DOCUME~1\marcs\APPLIC~1\BitDownload\Data
Supprime! - C:\DOCUME~1\marcs\Cookies\marcs@advertstream[1].txt
Supprime! - C:\DOCUME~1\marcs\Cookies\marcs@euroclick[1].txt
Supprime! - C:\DOCUME~1\marcs\Cookies\marcs@32vegas[1].txt
Supprime! - C:\DOCUME~1\marcs\Cookies\marcs@serve.32vegas[1].txt
Supprime! - C:\DOCUME~1\marcs\Cookies\marcs@www.32vegas[1].txt
Supprime! - C:\DOCUME~1\marcs\Cookies\marcs@www.32vegas[2].txt
Supprime! - C:\DOCUME~1\marcs\Cookies\marcs@2xmoinscher[2].txt
Supprime! - C:\DOCUME~1\marcs\Cookies\marcs@cc.2xmoinscher[2].txt
Supprime! - C:\DOCUME~1\marcs\Cookies\marcs@www.2xmoinscher[1].txt
Supprime! - C:\DOCUME~1\marcs\APPLIC~1\Bitdownload
Supprime! - C:\Program Files\DivoCodec
-
[ Fichier Hosts ] .. Restaure!

\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\

Supprime! - C:\Program Files\Viewpoint
Supprime! - C:\DOCUME~1\marcs\APPLIC~1\Viewpoint
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\Viewpoint

\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\


--------------------\\ Listing des dossiers dans APPLIC~1


[18/10/2007|10:47] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[04/05/2007|21:04] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Ahead
[31/05/2009|14:04] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
[18/11/2007|09:24] C:\DOCUME~1\ALLUSE~1\APPLIC~1\AVS4YOU
[29/09/2006|17:51] C:\DOCUME~1\ALLUSE~1\APPLIC~1\BOONTY
[28/02/2009|20:41] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Creative
[12/04/2008|13:48] C:\DOCUME~1\ALLUSE~1\APPLIC~1\DVD Shrink
[22/11/2006|20:51] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Exetender
[28/03/2009|16:08] C:\DOCUME~1\ALLUSE~1\APPLIC~1\F-Secure
[28/03/2009|16:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\fssg
[21/06/2009|10:15] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Installations
[11/02/2008|22:51] C:\DOCUME~1\ALLUSE~1\APPLIC~1\InstallShield
[28/03/2009|13:17] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Logishrd
[20/11/2007|10:17] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Logitech
[28/08/2007|10:58] C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee
[28/03/2009|13:04] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[03/02/2008|19:53] C:\DOCUME~1\ALLUSE~1\APPLIC~1\MSScanAppDataDir
[02/06/2007|22:50] C:\DOCUME~1\ALLUSE~1\APPLIC~1\muvee Technologies
[04/05/2007|19:50] C:\DOCUME~1\ALLUSE~1\APPLIC~1\NVIDIA
[08/03/2008|10:07] C:\DOCUME~1\ALLUSE~1\APPLIC~1\nView_Profiles
[16/11/2008|10:18] C:\DOCUME~1\ALLUSE~1\APPLIC~1\PC Suite
[22/04/2007|10:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\PC Tools
[23/12/2006|23:11] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Pinnacle
[23/12/2006|23:29] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Pinnacle Studio
[23/12/2006|23:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SmartSound Software Inc
[01/09/2007|14:51] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
[28/08/2007|10:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec
[22/04/2007|11:58] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
[07/08/2006|21:03] C:\DOCUME~1\ALLUSE~1\APPLIC~1\UDL
[07/08/2006|21:25] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Ulead Systems
[08/08/2006|22:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[26/02/2008|22:48] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller


[09/12/2007|13:02] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft


[14/05/2007|17:33] C:\DOCUME~1\hugo\APPLIC~1\ATI
[07/08/2006|18:23] C:\DOCUME~1\hugo\APPLIC~1\Identities
[03/02/2007|21:46] C:\DOCUME~1\hugo\APPLIC~1\Macromedia
[14/05/2007|17:33] C:\DOCUME~1\hugo\APPLIC~1\Microsoft
[30/09/2006|20:14] C:\DOCUME~1\hugo\APPLIC~1\Symantec

[12/12/2006|17:18] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft

[18/10/2007|10:47] C:\DOCUME~1\marcs\APPLIC~1\Adobe
[09/05/2007|16:17] C:\DOCUME~1\marcs\APPLIC~1\AdobeUM
[21/03/2008|18:46] C:\DOCUME~1\marcs\APPLIC~1\Ahead
[13/08/2006|15:01] C:\DOCUME~1\marcs\APPLIC~1\Apple Computer
[12/05/2007|20:57] C:\DOCUME~1\marcs\APPLIC~1\ATI
[10/11/2006|21:35] C:\DOCUME~1\marcs\APPLIC~1\Azureus
[19/06/2009|10:35] C:\DOCUME~1\marcs\APPLIC~1\ChessBase
[28/03/2009|08:16] C:\DOCUME~1\marcs\APPLIC~1\Creative
[23/12/2006|19:38] C:\DOCUME~1\marcs\APPLIC~1\CyberLink
[14/11/2007|09:33] C:\DOCUME~1\marcs\APPLIC~1\Dealio
[15/03/2007|16:24] C:\DOCUME~1\marcs\APPLIC~1\DivX
[24/12/2007|22:51] C:\DOCUME~1\marcs\APPLIC~1\dvdcss
[21/08/2007|20:43] C:\DOCUME~1\marcs\APPLIC~1\EPSON
[16/06/2009|09:39] C:\DOCUME~1\marcs\APPLIC~1\EssentialPIM
[11/02/2008|23:14] C:\DOCUME~1\marcs\APPLIC~1\EssentialPIM Pro
[09/11/2008|09:57] C:\DOCUME~1\marcs\APPLIC~1\FMZilla
[15/06/2008|18:56] C:\DOCUME~1\marcs\APPLIC~1\F-Secure
[31/05/2008|15:35] C:\DOCUME~1\marcs\APPLIC~1\GARMIN
[22/10/2008|20:52] C:\DOCUME~1\marcs\APPLIC~1\Google
[17/05/2007|08:25] C:\DOCUME~1\marcs\APPLIC~1\Goto.Games
[24/05/2007|21:51] C:\DOCUME~1\marcs\APPLIC~1\Help
[29/08/2007|12:13] C:\DOCUME~1\marcs\APPLIC~1\HouseCall 6.6
[07/08/2006|18:24] C:\DOCUME~1\marcs\APPLIC~1\Identities
[22/12/2008|15:43] C:\DOCUME~1\marcs\APPLIC~1\IEPro
[13/05/2007|10:23] C:\DOCUME~1\marcs\APPLIC~1\InstallShield
[01/09/2007|15:04] C:\DOCUME~1\marcs\APPLIC~1\ispnews
[13/12/2007|08:41] C:\DOCUME~1\marcs\APPLIC~1\Joost
[02/10/2006|22:08] C:\DOCUME~1\marcs\APPLIC~1\Lavasoft
[25/01/2009|11:49] C:\DOCUME~1\marcs\APPLIC~1\Leadertech
[08/08/2006|18:19] C:\DOCUME~1\marcs\APPLIC~1\Macromedia
[17/04/2009|20:40] C:\DOCUME~1\marcs\APPLIC~1\Microsoft
[07/08/2006|19:36] C:\DOCUME~1\marcs\APPLIC~1\Microsoft Web Folders
[28/03/2009|16:45] C:\DOCUME~1\marcs\APPLIC~1\MiniDm
[08/02/2008|23:24] C:\DOCUME~1\marcs\APPLIC~1\Mozilla
[21/06/2009|21:07] C:\DOCUME~1\marcs\APPLIC~1\Nokia
[01/09/2007|15:18] C:\DOCUME~1\marcs\APPLIC~1\ntr
[26/10/2008|11:34] C:\DOCUME~1\marcs\APPLIC~1\PC Suite
[20/04/2007|21:00] C:\DOCUME~1\marcs\APPLIC~1\PC Tools
[18/11/2006|17:38] C:\DOCUME~1\marcs\APPLIC~1\Roxio
[17/06/2007|08:50] C:\DOCUME~1\marcs\APPLIC~1\SecondLife
[08/08/2006|18:13] C:\DOCUME~1\marcs\APPLIC~1\SendPix
[09/08/2006|15:52] C:\DOCUME~1\marcs\APPLIC~1\Sun
[01/10/2006|15:30] C:\DOCUME~1\marcs\APPLIC~1\Symantec
[08/02/2008|23:25] C:\DOCUME~1\marcs\APPLIC~1\Talkback
[19/11/2007|13:07] C:\DOCUME~1\marcs\APPLIC~1\Uniblue
[13/09/2008|07:30] C:\DOCUME~1\marcs\APPLIC~1\vlc
[03/10/2006|17:17] C:\DOCUME~1\marcs\APPLIC~1\WholeSecurity

[27/10/2007|14:12] C:\DOCUME~1\nathalie\APPLIC~1\Adobe
[13/05/2007|08:34] C:\DOCUME~1\nathalie\APPLIC~1\ATI
[12/08/2008|22:38] C:\DOCUME~1\nathalie\APPLIC~1\Babylon
[18/11/2007|21:54] C:\DOCUME~1\nathalie\APPLIC~1\DivX
[03/10/2008|14:56] C:\DOCUME~1\nathalie\APPLIC~1\EssentialPIM
[13/09/2008|21:26] C:\DOCUME~1\nathalie\APPLIC~1\F-Secure
[29/10/2006|20:49] C:\DOCUME~1\nathalie\APPLIC~1\Help
[15/08/2006|09:14] C:\DOCUME~1\nathalie\APPLIC~1\Identities
[23/12/2008|22:30] C:\DOCUME~1\nathalie\APPLIC~1\IEPro
[06/09/2007|21:20] C:\DOCUME~1\nathalie\APPLIC~1\ispnews
[15/08/2006|18:29] C:\DOCUME~1\nathalie\APPLIC~1\Macromedia
[12/08/2008|15:09] C:\DOCUME~1\nathalie\APPLIC~1\Microsoft
[10/01/2009|17:05] C:\DOCUME~1\nathalie\APPLIC~1\PC Suite
[03/06/2007|09:07] C:\DOCUME~1\nathalie\APPLIC~1\Roxio
[26/10/2006|15:13] C:\DOCUME~1\nathalie\APPLIC~1\Sun
[02/08/2007|11:00] C:\DOCUME~1\nathalie\APPLIC~1\Symantec
[27/04/2007|10:19] C:\DOCUME~1\nathalie\APPLIC~1\Viewpoint
[13/12/2007|19:10] C:\DOCUME~1\nathalie\APPLIC~1\vlc

[07/08/2006|18:20] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft
[07/08/2006|19:34] C:\DOCUME~1\NETWOR~1\APPLIC~1\Symantec

[29/03/2009|18:24] C:\DOCUME~1\nina\APPLIC~1\Adobe
[27/12/2006|19:12] C:\DOCUME~1\nina\APPLIC~1\Identities
[29/03/2009|18:28] C:\DOCUME~1\nina\APPLIC~1\InstallShield
[07/02/2009|10:47] C:\DOCUME~1\nina\APPLIC~1\ispnews
[29/03/2009|18:28] C:\DOCUME~1\nina\APPLIC~1\Microsoft
[29/03/2009|18:22] C:\DOCUME~1\nina\APPLIC~1\PC Suite
[27/12/2006|19:12] C:\DOCUME~1\nina\APPLIC~1\Symantec

--------------------\\ Tâches planifiées dans C:\WINDOWS\tasks

[23/06/2009 15:04][--ah-----] C:\WINDOWS\tasks\User_Feed_Synchronization-{DC53D839-98D3-441F-A3EF-017C0B7C4F22}.job
[23/06/2009 14:45][--a------] C:\WINDOWS\tasks\Scheduled scanning task.job
[23/06/2009 14:45][--ah-----] C:\WINDOWS\tasks\SA.DAT
[24/04/2003 14:00][-r-h-----] C:\WINDOWS\tasks\desktop.ini

--------------------\\ Listing des dossiers dans C:\Program Files

[07/08/2006|19:44] C:\Program Files\Actebis
[19/11/2008|11:09] C:\Program Files\Adobe
[31/05/2009|13:56] C:\Program Files\adslTV
[04/05/2007|21:18] C:\Program Files\Ahead
[27/08/2007|12:11] C:\Program Files\Aleker
[14/08/2008|10:43] C:\Program Files\Auralog
[01/09/2007|11:38] C:\Program Files\CCleaner
[13/09/2008|13:41] C:\Program Files\ChessBase
[17/09/2008|17:49] C:\Program Files\Common Files
[07/08/2006|18:14] C:\Program Files\ComPlus Applications
[06/08/2008|20:46] C:\Program Files\Conduit
[09/08/2006|17:41] C:\Program Files\Convar
[28/02/2009|20:35] C:\Program Files\Creative
[28/02/2009|20:35] C:\Program Files\Creative Installation Information
[15/06/2009|11:35] C:\Program Files\CSV2ASC
[23/12/2006|22:55] C:\Program Files\CyberLink
[26/10/2008|11:27] C:\Program Files\DIFX
[12/12/2006|20:25] C:\Program Files\directx
[09/06/2009|17:21] C:\Program Files\DivX
[11/03/2008|23:26] C:\Program Files\DMV
[17/06/2007|19:49] C:\Program Files\DVD Shrink
[19/01/2007|15:52] C:\Program Files\EA SPORTS
[23/06/2009|14:54] C:\Program Files\eMule
[07/08/2006|21:16] C:\Program Files\EPSON
[01/08/2007|08:50] C:\Program Files\EssentialPIM
[21/06/2009|10:18] C:\Program Files\Fichiers communs
[19/09/2006|21:09] C:\Program Files\FileZilla
[07/08/2006|20:41] C:\Program Files\FoneSync
[11/11/2007|11:26] C:\Program Files\Free Audio Pack
[07/08/2006|19:51] C:\Program Files\Free.fr
[06/02/2009|21:45] C:\Program Files\Freecorder
[07/06/2007|18:37] C:\Program Files\Freeplayer
[22/10/2008|20:51] C:\Program Files\Google
[09/11/2008|19:29] C:\Program Files\Goto.Games
[01/06/2007|17:23] C:\Program Files\HardwareDetection
[22/12/2008|15:43] C:\Program Files\IEForge
[22/12/2008|15:43] C:\Program Files\IEPro
[31/05/2009|20:58] C:\Program Files\InstallShield Installation Information
[13/06/2009|12:07] C:\Program Files\Internet Explorer
[01/04/2009|21:37] C:\Program Files\Java
[28/03/2009|13:17] C:\Program Files\Logitech
[03/09/2008|21:19] C:\Program Files\Messenger
[09/11/2008|19:29] C:\Program Files\Micro Scrabble
[28/03/2009|17:56] C:\Program Files\Microsoft
[27/02/2008|13:03] C:\Program Files\Microsoft CAPICOM 2.1.0.2
[07/08/2006|19:35] C:\Program Files\microsoft frontpage
[09/08/2006|14:38] C:\Program Files\Microsoft Money
[02/02/2007|20:08] C:\Program Files\Microsoft Office
[07/08/2006|20:47] C:\Program Files\Microsoft Windows Script
[07/08/2006|20:38] C:\Program Files\Microsoft Works
[07/08/2006|20:33] C:\Program Files\Microsoft Works Suite 2001
[09/08/2006|21:13] C:\Program Files\Microsoft.NET
[01/02/2008|19:19] C:\Program Files\Mio DigiWalker
[31/01/2008|22:17] C:\Program Files\Mio Technology
[03/09/2008|21:16] C:\Program Files\Movie Maker
[15/06/2009|11:40] C:\Program Files\Mozilla Firefox
[19/01/2008|18:14] C:\Program Files\MP3 Player Utilities 3.5.02
[19/01/2008|18:13] C:\Program Files\MP3 Player Utilities 4.13
[23/05/2009|22:05] C:\Program Files\MSBuild
[02/02/2007|20:07] C:\Program Files\MSECache
[07/08/2006|18:13] C:\Program Files\MSN
[07/08/2006|18:13] C:\Program Files\MSN Gaming Zone
[17/11/2006|18:10] C:\Program Files\MSXML 4.0
[22/06/2009|18:35] C:\Program Files\Navilog1
[08/09/2007|18:38] C:\Program Files\NetAnalyse
[03/09/2008|21:13] C:\Program Files\NetMeeting
[21/06/2009|10:18] C:\Program Files\Nokia
[09/08/2006|22:13] C:\Program Files\OfficeUpdate11
[03/09/2008|21:34] C:\Program Files\Outlook Express
[31/05/2009|14:04] C:\Program Files\Papi
[21/06/2009|10:17] C:\Program Files\PC Connectivity Solution
[23/12/2006|23:07] C:\Program Files\Pinnacle
[13/08/2006|14:55] C:\Program Files\QuickTime
[04/11/2008|17:42] C:\Program Files\Radio Fr Solo
[18/08/2007|08:26] C:\Program Files\RayV
[02/06/2007|19:50] C:\Program Files\Realtek
[23/05/2009|22:05] C:\Program Files\Reference Assemblies
[03/06/2008|18:38] C:\Program Files\Securitoo
[07/08/2006|18:13] C:\Program Files\Services en ligne
[26/10/2007|11:50] C:\Program Files\Share_Accelerator_MM
[09/08/2006|17:30] C:\Program Files\Smart Projects
[23/12/2006|23:06] C:\Program Files\SmartSound Software
[11/11/2007|02:01] C:\Program Files\SystemRequirementsLab
[22/06/2009|16:44] C:\Program Files\trend micro
[07/08/2006|21:25] C:\Program Files\Ulead Systems
[07/08/2006|18:23] C:\Program Files\Uninstall Information
[26/05/2009|18:17] C:\Program Files\Veoh Networks
[04/05/2007|18:32] C:\Program Files\VIA
[03/03/2007|18:43] C:\Program Files\VIA Technologies, INC
[07/08/2006|20:49] C:\Program Files\ViaVoice
[18/12/2006|23:09] C:\Program Files\VibrateGameDeviceDriver
[09/08/2006|18:21] C:\Program Files\VideoLAN
[04/01/2007|18:16] C:\Program Files\Vqao
[28/03/2009|17:56] C:\Program Files\Windows Live
[14/10/2006|10:17] C:\Program Files\Windows Live Safety Center
[28/03/2009|17:56] C:\Program Files\Windows Live SkyDrive
[11/05/2007|16:59] C:\Program Files\Windows Media Connect 2
[03/09/2008|21:13] C:\Program Files\Windows Media Player
[03/09/2008|21:13] C:\Program Files\Windows NT
[07/08/2006|18:13] C:\Program Files\WindowsUpdate
[26/03/2009|12:01] C:\Program Files\WinFast
[08/09/2007|18:38] C:\Program Files\WinPcap
[13/09/2008|18:48] C:\Program Files\WinRAR
[07/08/2006|18:17] C:\Program Files\xerox
[13/08/2006|15:21] C:\Program Files\XviD
[13/09/2008|19:13] C:\Program Files\Your Company Name

--------------------\\ Listing des dossiers dans C:\Program Files\Fichiers communs

[07/08/2006|19:46] C:\Program Files\Fichiers communs\Adaptec Shared
[19/11/2008|11:09] C:\Program Files\Fichiers communs\Adobe
[07/08/2006|20:25] C:\Program Files\Fichiers communs\Ahead
[18/11/2007|09:25] C:\Program Files\Fichiers communs\AVSMedia
[29/09/2006|17:50] C:\Program Files\Fichiers communs\BOONTY Shared
[28/02/2009|20:33] C:\Program Files\Fichiers communs\Creative
[09/08/2006|21:12] C:\Program Files\Fichiers communs\DESIGNER
[09/06/2009|17:20] C:\Program Files\Fichiers communs\DivX Shared
[07/08/2006|21:03] C:\Program Files\Fichiers communs\InstallShield
[09/08/2006|15:49] C:\Program Files\Fichiers communs\Java
[28/03/2009|13:20] C:\Program Files\Fichiers communs\LogiShrd
[28/03/2009|08:16] C:\Program Files\Fichiers communs\Logitech
[28/03/2009|13:04] C:\Program Files\Fichiers communs\Microsoft Shared
[07/08/2006|18:15] C:\Program Files\Fichiers communs\MSSoap
[04/05/2007|21:14] C:\Program Files\Fichiers communs\Nero
[21/06/2009|10:18] C:\Program Files\Fichiers communs\Nokia
[07/08/2006|19:04] C:\Program Files\Fichiers communs\ODBC
[22/04/2007|10:28] C:\Program Files\Fichiers communs\PC Tools
[21/06/2009|10:18] C:\Program Files\Fichiers communs\PCSuite
[07/08/2006|19:47] C:\Program Files\Fichiers communs\Roxio Shared
[07/08/2006|18:15] C:\Program Files\Fichiers communs\Services
[20/04/2007|20:58] C:\Program Files\Fichiers communs\Softwin
[07/08/2006|19:04] C:\Program Files\Fichiers communs\SpeechEngines
[28/08/2007|23:28] C:\Program Files\Fichiers communs\Symantec Shared
[03/09/2008|21:13] C:\Program Files\Fichiers communs\System
[07/08/2006|21:25] C:\Program Files\Fichiers communs\Ulead Systems
[28/03/2009|12:07] C:\Program Files\Fichiers communs\Windows Live
[26/02/2008|22:48] C:\Program Files\Fichiers communs\WindowsLiveInstaller

--------------------\\ Process

( 61 Processes )

... OK !

--------------------\\ Recherche avec S_Lop

Aucun fichier / dossier Lop trouvé !

--------------------\\ Recherche de Fichiers / Dossiers Lop

Aucun fichier / dossier Lop trouvé !

--------------------\\ Verification du Registre

..... OK !

--------------------\\ Verification du fichier Hosts

Fichier Hosts PROPRE


--------------------\\ Recherche de fichiers avec Catchme

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-23 15:44:54
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 2

--------------------\\ Recherche d'autres infections

C:\WINDOWS\exefld
[b]==> BAGLE <==/b

--------------------\\ ROOTKIT !!

Rootkit Bagle ! .. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SROSA]
Rootkit Bagle ! .. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_SROSA]
Rootkit Bagle ! .. [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA]
Rootkit Bagle ! .. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\srosa]
Rootkit Bagle ! .. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\srosa]
Rootkit Bagle ! .. [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\srosa]



[F:109][D:6]-> C:\DOCUME~1\marcs\LOCALS~1\Temp
[F:1814][D:0]-> C:\DOCUME~1\marcs\Cookies
[F:19376][D:81]-> C:\DOCUME~1\marcs\LOCALS~1\TEMPOR~1\content.IE5

1 - "C:\Lop SD\LopR_1.txt" - 22/06/2009|17:29 - Option : [1]
2 - "C:\Lop SD\LopR_2.txt" - 23/06/2009|15:47 - Option : [2]

--------------------\\ Fin du rapport a 15:47:41
0
Utilisateur anonyme
 
Super...

La suite stp...

a+
0
marcugodelire
 
Rapport Findykill :

############################## | FindyKill V5.002 |

# User : marcs (Administrateurs) # PC1
# Update on 12/06/09 by Chiquitine29
# Start at: 15:51:49 | 23/06/2009
# Website : http://pagesperso-orange.fr/NosTools/findykill.html

# Intel(R) Core(TM)2 CPU 4300 @ 1.80GHz
# Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
# Internet Explorer 8.0.6001.18702
# Windows Firewall Status : Disabled
# AV : Securitoo AntiVirus Firewall 8.00 8.00 [ Enabled | Updated ]
# FW : Securitoo AntiVirus Firewall 8.00[ Enabled ]8.00

# A:\ # Lecteur de disquettes 3 ½ pouces
# C:\ # Disque fixe local # 76,32 Go (20,85 Go free) # NTFS
# D:\ # Disque fixe local # 31,48 Go (23,45 Go free) [Photos et Echecs] # NTFS
# E:\ # Disque CD-ROM

############################## | Processus actifs |

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\Securitoo\av_fw\Anti-Virus\fsgk32st.exe
C:\Program Files\Securitoo\av_fw\Common\FSMA32.EXE
C:\Program Files\Securitoo\av_fw\Anti-Virus\FSGK32.EXE
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Program Files\Securitoo\av_fw\Common\FSMB32.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\Securitoo\av_fw\Common\FCH32.EXE
C:\Program Files\Securitoo\av_fw\Anti-Virus\fssm32.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Securitoo\av_fw\Anti-Virus\fsqh.exe
C:\Program Files\Securitoo\av_fw\FSAUA\program\fsaua.exe
C:\Program Files\Securitoo\av_fw\Common\FAMEH32.EXE
C:\Program Files\Securitoo\av_fw\ORSP Client\fsorsp.exe
C:\Program Files\Securitoo\av_fw\FWES\Program\fsdfwd.exe
C:\Program Files\Securitoo\av_fw\FSAUA\program\fsus.exe
C:\Program Files\Securitoo\av_fw\Anti-Virus\fsav32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAAE.EXE
C:\Program Files\VibrateGameDeviceDriver\RFPIcon.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Securitoo\av_fw\Common\FSM32.EXE
C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\Securitoo\av_fw\FSGUI\fsguidll.exe
C:\Program Files\Logitech\QuickCam\Quickcam.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\Fichiers communs\Logishrd\LQCVFX\COCIManager.exe
C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe
C:\Program Files\Securitoo\av_fw\FSGUI\scanwizard.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\IEPro\MiniDM.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\wbem\wmiprvse.exe

################## | C: |


################## | C:\WINDOWS |

Présent ! C:\WINDOWS\exefld

################## | C:\WINDOWS\system32 |


################## | C:\WINDOWS\system32\drivers |


################## | C:\Documents and Settings\marcs\Application Data |


################## | Autres ... |


################## | C:\Documents and Settings\marcs\Temporary Internet Files |


################## | Registre / Clés infectieuses |

Présent ! [HKLM\SYSTEM\CurrentControlSet\Services\srosa]
Présent ! [HKLM\SYSTEM\ControlSet001\Services\srosa]
Présent ! [HKLM\SYSTEM\ControlSet002\Services\srosa]
Présent ! [HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA]
Présent ! [HKLM\SYSTEM\ControlSet001\Enum\Root\LEGACY_SROSA]
Présent ! [HKLM\SYSTEM\ControlSet002\Enum\Root\LEGACY_SROSA]
Présent ! [HKCU\Software\FirstRRRun]
Présent ! [HKCU\Software\MuleAppData]
Présent ! [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] "drvsyskit"
Présent ! [HKU\S-1-5-21-796845957-562591055-839522115-1004\Software\Microsoft\Windows\CurrentVersion\Run] "drvsyskit"
Présent ! [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] "mule_st_key"
Présent ! [HKU\S-1-5-21-796845957-562591055-839522115-1004\Software\Microsoft\Windows\CurrentVersion\Run] "mule_st_key"
Présent ! [HKU\S-1-5-21-796845957-562591055-839522115-1004\Software\FirstRRRun]
Présent ! [HKU\S-1-5-21-796845957-562591055-839522115-1004\Software\MuleAppData]
Présent ! [HKLM\software\microsoft\security center] "AntiVirusOverride" 0x1

################## | Etat / Services / Informations |

# Affichage des fichiers cachés : OK

# Mode sans echec : OK

# (!) Ndisuio -> Start = 4 ( Good = 3 | Bad = 4 )
# EapHost -> Start = 3 ( Good = 2 | Bad = 4 )
# Ip6Fw -> Start = 3 ( Good = 2 | Bad = 4 )
# SharedAccess -> Start = 2 ( Good = 2 | Bad = 4 )
# wuauserv -> Start = 2 ( Good = 2 | Bad = 4 )
# wscsvc -> Start = 2 ( Good = 2 | Bad = 4 )


################## | ! Fin du rapport # FindyKill V5.002 ! |
0
Utilisateur anonyme
 
Branches tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) suceptibles d avoir été infectés sans les ouvrir


Double clic sur le raccourci FindyKill sur ton bureau

Au menu principal,choisi l option 2 (Suppression)

/!\ laisses travailler l outils jusqu a l apparition du message "nettoyage effectué"

/!\ Ne te sert pas du pc durant la suppression , ton bureau ne sera pas accessible c est normal !

ensuite post le rapport FindyKill.txt

* Note : le rapport FindyKill.txt est sauvegardé a la racine du disque
* Note : Si le Bureau ne réapparait pas presse Ctrl + Alt + Suppr , Onglet "Fichier" , "Nouvelle tâche" , tapes explorer.exe et valides

a+
0
marcugodelire
 
Merci de tous tes conseils. Je n'ai pas eu de chance cela fait 40h00 que l'ordi tournait pour faire l'opération que tu m'a demandé quand le courant à sauter.
Dois-je recommencer car il n'avait pas fini ?
Est ce normal que cela dure aussi longtemps ?
0
marcugodelire
 
En tout cas lorsque je suis sur internet le virus n'apparait plus.
Merci
0
Utilisateur anonyme
 
Est ce normal que cela dure aussi longtemps ?

Non ...pas du tout !!!
Ce log est normalement relativement rapide....(1/2 heure grand max)

Desinstalles et réinstalles...et lances a nouveau l'option :2

Si cela rame au bout de 30mn stop le et dis moi....


a+
0
marcugodelire
 
Eh bien j'ai du arreter le programme et même redémarrer l'ordi car il continuait de ramer.
0
Utilisateur anonyme
 
OK....

Fais ceci:

---> Télécharge ComboFix.exe de sUBs sur ton Bureau :
http://download.bleepingcomputer.com/sUBs/ComboFix.exe

/!\ Déconnecte-toi du net et ferme toutes les applications, antivirus et antispyware y compris /!\

---> Double-clique sur Combofix.exe
Un "pop-up" va apparaître qui dit que "ComboFix est utilisé à vos risques et avec aucune garantie...".
Accepte en cliquant sur "Oui"

---> Mets-le en langue française F
Tape sur la touche 1 (Yes) pour démarrer le scan.

/!\ Ne touche à rien tant que le scan n'est pas terminé. /!\

En fin de scan, il est possible que ComboFix ait besoin de redémarrer le PC pour finaliser la désinfection, laisse-le faire.

Une fois le scan achevé, un rapport va s'afficher : Poste son contenu

/!\ Réactive la protection en temps réel de ton antivirus et de ton antispyware avant de te reconnecter à Internet. /!\

Note : Le rapport se trouve également là : C:\ComboFix.txt

a+
0
marcugodelire
 
ok fait
ComboFix 09-06-25.01 - marcs 25/06/2009 20:58.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.33.1036.18.2047.1537 [GMT 2:00]
Lancé depuis: c:\docume~1\marcs\LOCALS~1\Temp\ComboFix.exe
AV: Securitoo AntiVirus Firewall 8.00 *On-access scanning disabled* (Updated) {E7512ED5-4245-4B4D-AF3A-382D3F313F15}
FW: Securitoo AntiVirus Firewall 8.00 *disabled* {D4747503-0346-49EB-9262-997542F79BF4}
.

(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\hugo\err.log
c:\documents and settings\marcs\err.log
c:\documents and settings\nathalie\err.log
c:\documents and settings\nina\err.log
c:\program files\WinPCap
c:\program files\WinPCap\daemon_mgm.exe
c:\program files\WinPCap\INSTALL.LOG
c:\program files\WinPCap\NetMonInstaller.exe
c:\program files\WinPCap\npf_mgm.exe
c:\program files\WinPCap\rpcapd.exe
c:\program files\WinPCap\Uninstall.exe
c:\recycler\NPROTECT\00648937.
C:\sys.txt
c:\windows\system32\drivers\ctoss2k.sys
c:\windows\system32\drivers\npf.sys
c:\windows\system32\Packet.dll
c:\windows\system32\pthreadVC.dll
c:\windows\system32\tmp.reg
c:\windows\system32\WanPacket.dll
c:\windows\system32\wpcap.dll
c:\windows\TEMP\logishrd\LVPrcInj01.dll

.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_BOONTY_GAMES
-------\Legacy_NPF
-------\Service_Boonty Games
-------\Service_NPF
-------\Legacy_ossrv
-------\Service_ossrv


((((((((((((((((((((((((((((( Fichiers créés du 2009-05-25 au 2009-06-25 ))))))))))))))))))))))))))))))))))))
.

2009-06-25 16:47 . 2009-06-25 16:48 3 ----a-w- c:\windows\sbacknt.bin
2009-06-25 16:26 . 2009-06-25 16:26 152904 ----a-w- c:\windows\system32\vghd.scr
2009-06-25 16:26 . 2009-06-25 17:41 -------- d-----w- c:\program files\vghd
2009-06-25 16:26 . 2009-06-25 16:48 -------- d-----w- c:\documents and settings\marcs\Application Data\vghd
2009-06-25 16:11 . 2009-06-25 16:11 -------- d-----w- c:\documents and settings\marcs\Application Data\Babylon
2009-06-25 16:11 . 2009-06-25 16:11 -------- d-----w- c:\documents and settings\All Users\Application Data\Babylon
2009-06-23 13:50 . 2009-06-25 17:45 -------- d-----w- C:\FindyKill
2009-06-22 16:06 . 2009-06-22 16:35 -------- d-----w- c:\program files\Navilog1
2009-06-22 15:22 . 2009-06-23 13:47 -------- d-----w- C:\Lop SD
2009-06-22 14:44 . 2009-06-22 14:44 -------- d-----w- c:\program files\trend micro
2009-06-22 14:44 . 2009-06-22 14:44 -------- d-----w- C:\rsit
2009-06-21 08:18 . 2009-06-21 08:18 -------- d-----w- c:\program files\Fichiers communs\PCSuite
2009-06-21 08:17 . 2008-08-26 08:26 18816 ----a-w- c:\windows\system32\drivers\pccsmcfd.sys
2009-06-21 08:17 . 2009-06-21 08:17 -------- d-----w- c:\program files\PC Connectivity Solution
2009-06-21 08:15 . 2009-06-21 08:12 33727728 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{55495E65-7C5B-48E4-BC7D-DE54F3DE5ED6}\Nokia_PC_Suite_7_1_30_8_fre.exe
2009-06-21 08:15 . 2009-06-21 08:15 95232 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{55495E65-7C5B-48E4-BC7D-DE54F3DE5ED6}\Installer\CommonCustomActions\pcswpcsi.exe
2009-06-21 08:15 . 2009-06-21 08:15 8192 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{55495E65-7C5B-48E4-BC7D-DE54F3DE5ED6}\Installer\CommonCustomActions\UninstCCD.exe
2009-06-21 08:15 . 2009-06-21 08:15 61440 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{55495E65-7C5B-48E4-BC7D-DE54F3DE5ED6}\Installer\CommonCustomActions\UninstPCSFEMsi.exe
2009-06-21 08:15 . 2009-06-21 08:15 10240 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{55495E65-7C5B-48E4-BC7D-DE54F3DE5ED6}\Installer\CommonCustomActions\UninstPCS.exe
2009-06-13 07:53 . 2009-04-30 21:16 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2009-06-13 07:53 . 2009-04-30 21:16 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2009-06-09 18:23 . 2009-06-09 18:23 436 ----a-w- c:\documents and settings\marcs\Delivery report.dat
2009-06-03 20:59 . 2009-06-03 20:59 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache
2009-05-31 09:53 . 2009-05-31 09:53 -------- d-sh--w- c:\documents and settings\nathalie\PrivacIE
2009-05-31 08:26 . 2009-05-31 08:26 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache

.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-25 19:05 . 2007-02-21 15:14 0 ----a-w- c:\windows\system32\drivers\lvuvc.hs
2009-06-25 19:05 . 2007-11-09 08:56 0 ----a-w- c:\windows\system32\drivers\logiflt.iad
2009-06-25 18:30 . 2006-08-09 13:26 -------- d-----w- c:\program files\eMule
2009-06-21 19:07 . 2008-10-26 09:31 -------- d-----w- c:\documents and settings\marcs\Application Data\Nokia
2009-06-21 08:18 . 2008-11-09 17:25 -------- d-----w- c:\program files\Nokia
2009-06-21 08:18 . 2007-02-12 16:31 -------- d-----w- c:\program files\Fichiers communs\Nokia
2009-06-21 08:15 . 2008-10-24 15:37 -------- d-----w- c:\documents and settings\All Users\Application Data\Installations
2009-06-19 08:35 . 2006-08-08 16:13 -------- d-----w- c:\documents and settings\marcs\Application Data\ChessBase
2009-06-16 07:39 . 2007-01-04 18:12 -------- d-----w- c:\documents and settings\marcs\Application Data\EssentialPIM
2009-06-15 09:35 . 2007-12-19 21:10 -------- d-----w- c:\program files\CSV2ASC
2009-06-09 15:21 . 2006-12-23 21:04 -------- d-----w- c:\program files\DivX
2009-06-09 15:20 . 2009-05-18 08:06 -------- d-----w- c:\program files\Fichiers communs\DivX Shared
2009-06-05 16:45 . 2006-08-15 07:14 66072 ----a-w- c:\documents and settings\nathalie\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-31 18:58 . 2006-08-07 19:00 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-05-31 12:04 . 2007-05-23 15:08 -------- d-----w- c:\program files\Papi
2009-05-31 12:04 . 2006-08-13 12:53 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer
2009-05-31 11:56 . 2008-09-13 05:30 -------- d-----w- c:\program files\adslTV
2009-05-26 16:17 . 2009-05-26 16:17 -------- d-----w- c:\program files\Veoh Networks
2009-05-25 13:03 . 2006-08-07 17:18 66072 ----a-w- c:\documents and settings\marcs\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-23 20:10 . 2003-04-24 12:00 89078 ----a-w- c:\windows\system32\perfc00C.dat
2009-05-23 20:10 . 2003-04-24 12:00 519756 ----a-w- c:\windows\system32\perfh00C.dat
2009-05-23 20:05 . 2009-05-23 20:05 -------- d-----w- c:\program files\MSBuild
2009-05-23 20:05 . 2009-05-23 20:05 -------- d-----w- c:\program files\Reference Assemblies
2009-05-13 05:04 . 2003-04-24 12:00 915456 ----a-w- c:\windows\system32\wininet.dll
2009-05-07 15:33 . 2003-04-24 12:00 348672 ----a-w- c:\windows\system32\localspl.dll
2009-05-01 21:02 . 2009-05-01 21:02 823296 ----a-w- c:\windows\system32\divx_xx0c.dll
2009-05-01 21:02 . 2009-05-01 21:02 823296 ----a-w- c:\windows\system32\divx_xx07.dll
2009-05-01 21:02 . 2009-05-01 21:02 815104 ----a-w- c:\windows\system32\divx_xx0a.dll
2009-05-01 21:02 . 2009-05-01 21:02 811008 ----a-w- c:\windows\system32\divx_xx16.dll
2009-05-01 21:02 . 2009-05-01 21:02 802816 ----a-w- c:\windows\system32\divx_xx11.dll
2009-05-01 21:02 . 2009-05-01 21:02 685056 ----a-w- c:\windows\system32\DivX.dll
2009-04-23 06:45 . 2009-04-23 06:45 61440 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Installer\CommonCustomActions\UninstPCSFEMsi.exe
2009-04-23 06:45 . 2009-04-23 06:45 10240 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Installer\CommonCustomActions\UninstPCS.exe
2009-04-23 06:45 . 2009-04-23 06:45 8192 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Installer\CommonCustomActions\UninstCCD.exe
2009-04-23 06:40 . 2009-04-23 06:46 34227512 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Nokia_PC_Suite_7_1_26_0_fre.exe
2009-04-19 19:50 . 2003-04-24 12:00 1847296 ----a-w- c:\windows\system32\win32k.sys
2009-04-15 14:53 . 2003-04-24 12:00 585216 ----a-w- c:\windows\system32\rpcrt4.dll
2009-04-01 19:35 . 2009-04-01 19:35 152576 ----a-w- c:\documents and settings\marcs\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2009-03-29 16:28 . 2009-03-29 16:28 192644 ----a-w- c:\documents and settings\nina\Application Data\InstallShield\Professional\RunTime\10\50\Intel32\iGdi.dll
2009-03-29 16:28 . 2009-03-29 16:28 323716 ----a-w- c:\documents and settings\nina\Application Data\InstallShield\Professional\RunTime\10\50\Intel32\setup.dll
2009-03-28 14:35 . 2009-03-28 14:35 33408 ----a-w- c:\windows\system32\drivers\fsbts.sys
2007-12-19 20:35 . 2007-12-19 20:35 9094120 ----a-w- c:\program files\SpeedCAM.exe
2008-11-10 09:03 . 2008-02-08 21:24 67696 ----a-w- c:\program files\mozilla firefox\components\jar50.dll
2008-11-10 09:03 . 2008-02-08 21:24 54376 ----a-w- c:\program files\mozilla firefox\components\jsd3250.dll
2008-11-10 09:03 . 2008-02-09 08:41 34952 ----a-w- c:\program files\mozilla firefox\components\myspell.dll
2008-11-10 09:03 . 2008-02-09 08:41 46720 ----a-w- c:\program files\mozilla firefox\components\spellchk.dll
2008-11-10 09:03 . 2008-02-08 21:24 172144 ----a-w- c:\program files\mozilla firefox\components\xpinstal.dll
2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
2006-12-27 18:12 . 2006-12-27 18:12 12208 --sha-w- c:\windows\system32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1392b8d2-5c05-419f-a8f6-b9f15a596612}]
2009-05-31 09:09 2094616 ----a-w- c:\program files\Freecorder\tbFre0.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"msnmsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2009-02-06 3885408]
"NBJ"="c:\program files\Ahead\Nero BackItUp\NBJ.exe" [2005-10-11 1961984]
"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" [2009-06-12 1414144]
"eMuleAutoStart"="c:\program files\eMule\emule.exe" [2008-08-02 5484544]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"EPSON Stylus D68 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATIAAE.EXE" [2005-01-25 98304]
"RTBatteryMeter"="c:\program files\VibrateGameDeviceDriver\RFPIcon.exe" [2003-01-16 49152]
"PinnacleDriverCheck"="c:\windows\system32\\PSDrvCheck.exe" [2004-03-10 406016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-02-01 8523776]
"WorksFUD"="c:\program files\Microsoft Works\wkfud.exe" [2000-07-12 24576]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-08-13 282624]
"ISUSPM Startup"="c:\progra~1\FICHIE~1\INSTAL~1\UPDATE~1\isuspm.exe" [2004-08-09 221184]
"ISUSScheduler"="c:\program files\Fichiers communs\InstallShield\UpdateService\issch.exe" [2004-08-09 81920]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-02-01 81920]
"F-Secure Manager"="c:\program files\Securitoo\av_fw\Common\FSM32.EXE" [2008-06-25 182936]
"F-Secure TNB"="c:\program files\Securitoo\av_fw\FSGUI\TNBUtil.exe" [2008-06-25 957024]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"CTSysVol"="c:\program files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe" [2005-10-31 57344]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2008-12-20 2656528]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2008-02-01 1626112]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2006-09-12 16264192]
"P17Helper"="P17.dll" - c:\windows\system32\P17.dll [2005-05-03 64512]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"WUAppSetup"="c:\program files\Fichiers communs\logishrd\WUApp32.exe" [2008-12-17 443664]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\eMule\\emule.exe"=
"c:\\Program Files\\Radio Fr Solo\\Radio_Fr_Solo.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Pinnacle\\Studio 10\\programs\\RM.exe"=
"c:\\Program Files\\Pinnacle\\Studio 10\\programs\\Studio.exe"=
"c:\\Program Files\\Pinnacle\\Studio 10\\programs\\PMSRegisterFile.exe"=
"c:\\Program Files\\Pinnacle\\Studio 10\\programs\\umi.exe"=
"c:\\Program Files\\FileZilla\\FileZilla.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\EA SPORTS\\FIFA 07\\fifa07.exe"=
"c:\\Program Files\\Freeplayer\\vlc\\vlc.exe"=
"c:\\Program Files\\RayV\\RayV\\RayV.exe"=
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"d:\\Fritz8\\ChessProgram8\\ChessProgram8.exe"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"c:\\Program Files\\adslTV\\vlc.exe"=
"c:\\Program Files\\adslTV\\adsltv.exe"=
"c:\\jeux\\gp3\\GP3.exe"=
"c:\\Program Files\\IEPro\\MiniDM.exe"=
"c:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\helpctr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"4662:TCP"= 4662:TCP:emule tcp entrant
"4672:UDP"= 4672:UDP:emule udp entrant

R0 fsbts;fsbts;c:\windows\system32\drivers\fsbts.sys [28/03/2009 16:35 33408]
R0 FSFW;F-Secure Firewall Driver;c:\windows\system32\drivers\fsdfw.sys [03/06/2008 18:40 79904]
R0 xfilt;VIA SATA IDE Hot-plug Driver;c:\windows\system32\drivers\xfilt.sys [02/06/2007 18:25 11264]
R1 F-Secure HIPS;F-Secure HIPS Driver;c:\program files\Securitoo\av_fw\HIPS\drivers\fshs.sys [28/03/2009 16:07 66720]
R3 F-Secure Gatekeeper;F-Secure Gatekeeper;c:\program files\Securitoo\av_fw\Anti-Virus\minifilter\fsgk.sys [03/06/2008 18:40 84608]
R3 FSORSPClient;F-Secure ORSP Client;c:\program files\Securitoo\av_fw\ORSP Client\fsorsp.exe [28/03/2009 16:07 55904]
S3 DynCal;Dynamic Calibration Service;c:\windows\system32\drivers\DynCal.sys [14/11/2003 04:46 8192]
S3 ES1370;Creative AudioPCI (ES1370), SB PCI 64/128 (WDM);c:\windows\system32\drivers\es1370mp.sys [07/08/2006 19:06 37504]
S3 WFIOCTL;WFIOCTL;\??\c:\program files\WinFast\WFTVFM\WFIOCTL.SYS --> c:\program files\WinFast\WFTVFM\WFIOCTL.SYS [?]
S4 F-Secure Filter;F-Secure File System Filter;c:\program files\Securitoo\av_fw\Anti-Virus\win2k\fsfilter.sys [03/06/2008 18:40 39776]
S4 F-Secure Recognizer;F-Secure File System Recognizer;c:\program files\Securitoo\av_fw\Anti-Virus\win2k\fsrec.sys [03/06/2008 18:40 25184]
S4 NProtectService;Norton Unerase Protection;c:\progra~1\NORTON~1\NORTON~2\NPROTECT.EXE --> c:\progra~1\NORTON~1\NORTON~2\NPROTECT.EXE [?]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contenu du dossier 'Tâches planifiées'

2009-06-25 c:\windows\Tasks\Scheduled scanning task.job
- c:\progra~1\SECURI~1\av_fw\ANTI-V~1\fsav.exe [2008-06-03 13:52]

2009-06-25 c:\windows\Tasks\User_Feed_Synchronization-{DC53D839-98D3-441F-A3EF-017C0B7C4F22}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 02:31]
.
- - - - ORPHELINS SUPPRIMES - - - -

HKCU-Run-Uniblue RegistryBooster 2 - c:\program files\Uniblue\RegistryBooster 2\RegistryBooster.exe
HKCU-Run-Start WingMan Profiler - (no file)
HKLM-Run-AtiPTA - atiptaxx.exe
HKU-Default-Run-ALUAlert - c:\program files\Symantec\LiveUpdate\ALUNotify.exe


.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.emule-france.com
uInternet Settings,ProxyOverride = <local>
IE: Add to AMV Converter... - c:\program files\MP3 Player Utilities 4.13\AMVConverter\grab.html
IE: Compare Prices with &Dealio - c:\documents and settings\marcs\Application Data\Dealio\kb124\res\DealioSearch.html
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: MediaManager tool grab multimedia file - c:\program files\MP3 Player Utilities 4.13\MediaManager\grab.html
LSP: c:\program files\Securitoo\av_fw\FSPS\program\FSLSP.DLL
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
DPF: {B9F79165-A264-4C4A-A211-133A5E8D647F} - hxxp://www.securitoo.com/pchc/fscax.cab
FF - ProfilePath -
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-25 21:06
Windows 5.1.2600 Service Pack 3 NTFS

Recherche de processus cachés ...

Recherche d'éléments en démarrage automatique cachés ...

Recherche de fichiers cachés ...

Scan terminé avec succès
Fichiers cachés: 0

**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"cd042efbbd7f7af1647644e76e06692b"=hex:e2,63,26,f1,3f,c8,ff,68,39,cb,9c,82,a8,
d1,4c,c2,e2,63,26,f1,3f,c8,ff,68,42,b1,6a,fe,bd,0c,ea,ce,e2,63,26,f1,3f,c8,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"bca643cdc5c2726b20d2ecedcc62c59b"=hex:6a,9c,d6,61,af,45,84,18,59,5f,48,f5,8a,
8f,96,a2,6a,9c,d6,61,af,45,84,18,54,40,e6,f9,1b,4f,f7,98,6a,9c,d6,61,af,45,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"2c81e34222e8052573023a60d06dd016"=hex:7a,45,05,fd,91,e8,6f,31,f0,b5,a7,12,ed,
7a,b5,79,ff,7c,85,e0,43,d4,0e,fe,60,07,ee,5a,d6,9f,38,78,ff,7c,85,e0,43,d4,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"2582ae41fb52324423be06337561aa48"=hex:6b,65,49,6a,7e,99,74,f7,a7,f5,08,6a,8a,
a8,f6,83,86,8c,21,01,be,91,eb,e7,40,91,58,a8,29,d2,dc,3a,86,8c,21,01,be,91,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"caaeda5fd7a9ed7697d9686d4b818472"=hex:cd,44,cd,b9,a6,33,6c,cd,52,81,c0,da,58,
c6,2c,fc,f5,1d,4d,73,a8,13,5c,05,cb,fd,80,27,61,21,9f,12,f5,1d,4d,73,a8,13,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"a4a1bcf2cc2b8bc3716b74b2b4522f5d"=hex:b0,18,ed,a7,3f,8d,37,a4,56,62,3b,07,30,
10,f7,63,df,20,58,62,78,6b,cf,c8,da,25,aa,57,37,69,76,c7,df,20,58,62,78,6b,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"4d370831d2c43cd13623e232fed27b7b"=hex:97,20,4e,9a,c7,f1,35,ee,c5,0c,eb,89,cd,
65,50,38,fb,a7,78,e6,12,2f,9a,ea,1c,46,a3,d6,b1,99,b1,50,fb,a7,78,e6,12,2f,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"1d68fe701cdea33e477eb204b76f993d"=hex:83,6c,56,8b,a0,85,96,ab,84,d0,47,71,ab,
59,91,76,01,3a,48,fc,e8,04,4a,f1,dd,43,81,dc,52,04,bf,0f,01,3a,48,fc,e8,04,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"1fac81b91d8e3c5aa4b0a51804d844a3"=hex:b2,46,9a,e2,1b,fe,1b,94,58,b1,27,6c,6a,
cd,6a,26,f6,0f,4e,58,98,5b,89,c9,33,5c,4c,fd,64,4b,89,ab,f6,0f,4e,58,98,5b,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"f5f62a6129303efb32fbe080bb27835b"=hex:37,a4,aa,c3,a6,15,56,0a,da,7f,d2,e9,3b,
82,ce,86,3d,ce,ea,26,2d,45,aa,78,1b,0a,3f,6f,c0,2c,47,1e,3d,ce,ea,26,2d,45,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"fd4e2e1a3940b94dceb5a6a021f2e3c6"=hex:e3,0e,66,d5,eb,bc,2f,6b,88,53,bb,91,b2,
0d,1b,a1,2a,b7,cc,b5,b9,7f,41,e7,4d,f4,e7,8a,c9,a5,b3,48,2a,b7,cc,b5,b9,7f,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"8a8aec57dd6508a385616fbc86791ec2"=hex:6c,43,2d,1e,aa,22,2f,9c,d7,b0,25,23,97,
09,fa,1b,6c,43,2d,1e,aa,22,2f,9c,d4,e8,55,23,87,6a,7f,9f,6c,43,2d,1e,aa,22,\

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø•€|ÿÿÿÿ•€|ù•9~*]
"C040110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
--------------------- DLLs chargées dans les processus actifs ---------------------

- - - - - - - > 'winlogon.exe'(700)
c:\windows\system32\Ati2evxx.dll
c:\program files\Securitoo\av_fw\FWES\Program\fsdc32.dll

- - - - - - - > 'lsass.exe'(756)
c:\program files\Securitoo\av_fw\FSPS\program\FSLSP.DLL
c:\program files\Securitoo\av_fw\FWES\Program\fsdc32.dll

- - - - - - - > 'explorer.exe'(1244)
c:\windows\TEMP\logishrd\LVPrcInj01.dll
c:\program files\Securitoo\av_fw\Spam Control\fsscoepl.dll
c:\windows\system32\nview.dll
c:\windows\system32\NVWRSFR.DLL
c:\windows\system32\eappprxy.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\Securitoo\av_fw\FSPS\program\FSLSP.DLL
c:\program files\securitoo\av_fw\scanner-interface\fsgkiapi.dll
c:\program files\Nokia\Nokia PC Suite 7\PhoneBrowser.dll
c:\program files\Nokia\Nokia PC Suite 7\NGSCM.DLL
c:\program files\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_fre.nlr
c:\program files\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll

- - - - - - - > 'csrss.exe'(676)
c:\program files\Securitoo\av_fw\FWES\Program\fsdc32.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\windows\system32\CTSVCCDA.EXE
c:\program files\Securitoo\av_fw\Anti-Virus\fsgk32st.exe
c:\program files\Securitoo\av_fw\Common\FSMA32.EXE
c:\program files\Securitoo\av_fw\Anti-Virus\fsgk32.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
c:\program files\Securitoo\av_fw\Common\FSMB32.EXE
c:\windows\system32\nvsvc32.exe
c:\program files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
c:\program files\Securitoo\av_fw\Common\FCH32.EXE
c:\program files\Securitoo\av_fw\Anti-Virus\fsqh.exe
c:\program files\Securitoo\av_fw\Common\FAMEH32.EXE
c:\program files\Securitoo\av_fw\FSAUA\program\fsaua.exe
c:\program files\Securitoo\av_fw\Anti-Virus\fssm32.exe
c:\program files\Securitoo\av_fw\FWES\program\fsdfwd.exe
c:\program files\Securitoo\av_fw\FSAUA\program\fsus.exe
c:\progra~1\SECURI~1\av_fw\ANTI-V~1\fsav32.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\rundll32.exe
c:\program files\Securitoo\av_fw\FSGUI\fsguidll.exe
c:\program files\Fichiers communs\LogiShrd\LQCVFX\COCIManager.exe
c:\program files\PC Connectivity Solution\ServiceLayer.exe
c:\program files\PC Connectivity Solution\Transports\NclUSBSrv.exe
c:\program files\PC Connectivity Solution\Transports\NclRSSrv.exe
c:\program files\Windows Live\Contacts\wlcomm.exe
.
**************************************************************************
.
Heure de fin: 2009-06-25 21:15 - La machine a redémarré
ComboFix-quarantined-files.txt 2009-06-25 19:15

Avant-CF: 23 049 719 808 octets libres
Après-CF: 25 945 866 240 octets libres

WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP dition familiale" /fastdetect /NoExecute=OptIn

373 --- E O F --- 2009-06-13 10:08
0
Utilisateur anonyme
 
Ok ressayes de relancer Findykill option 2 maintenant stp....

Ce pc est blindé de chez blindé....!!!!!!!

a+
0
marcugodelire
 
Désolé , même effet qu'auparavant.
Quand tu parles de blindé tu parles de virus ?
Saches que si je te réponds plus demain c'est par ce que je pars en week-end et que je répondrais lundi matin.
Aussi bon week-end si tu ne réponds plus ce soir.
0
Utilisateur anonyme
 
Pour blindé...je voulais dire dire que ton pc est un vrai boillon de culture!!!!

On continue:

---> Télécharge OTM (OldTimer) sur ton Bureau :
http: http://www.geekstogo.com/forum/files/file/402-otm-oldtimers-move-it/


---> Double-clique sur OTMoveIt3.exe afin de le lancer.

---> Copie (Ctrl+C) le texte suivant en gras ci-dessous :

:processes
explorer.exe

:files
C:\WINDOWS\exefld


:reg
[HKLM\SYSTEM\CurrentControlSet\Services\srosa]
[HKLM\SYSTEM\ControlSet001\Services\srosa]
[HKLM\SYSTEM\ControlSet002\Services\srosa]
[HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA]
[HKLM\SYSTEM\ControlSet001\Enum\Root\LEGACY_SROSA]
[HKLM\SYSTEM\ControlSet002\Enum\Root\LEGACY_SROSA]
[HKCU\Software\FirstRRRun]
[HKCU\Software\MuleAppData]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run] "drvsyskit"
[HKU\S-1-5-21-796845957-562591055-839522115-1004\Software\Microsoft\Windows\CurrentVersion\Run] "drvsyskit"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run] "mule_st_key"
[HKU\S-1-5-21-796845957-562591055-839522115-1004\Software\Microsoft\Windows\CurrentVersion\Run] "mule_st_key"
[HKU\S-1-5-21-796845957-562591055-839522115-1004\Software\FirstRRRun]
[HKU\S-1-5-21-796845957-562591055-839522115-1004\Software\MuleAppData]
[HKLM\software\microsoft\security center] "AntiVirusOverride" 0x1

:commands
[purity]
[emptytemp]
[start explorer]



---> Colle (Ctrl+V) le texte précédemment copié dans le cadre Paste Instructions for Items to be Moved.

---> Clique maintenant sur le bouton MoveIt! puis ferme OTMoveIt3.

Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
Accepte en cliquant sur YES.

---> Poste le rapport situé dans ce dossier : C:\_OTMoveIt\MovedFiles\
Le nom du rapport correspond au moment de sa création : date_heure.log

*****

Ensuite:

Fais un scan avec cet antispyware :Telecharges malwarebytes + tutoriel :

-> https://www.malekal.com/tutoriel-malwarebyte-anti-malware/

Tu l´installes; mets le a jour...(onglet mise a jour)
Click maintenant sur l´onglet recherche et coche la case : "executer un examen rapide".
Puis click sur "rechercher".
Laisses le scanner le pc...
Si des elements on ete trouvés > click sur supprimer la selection.si il t´es demandé de redemarrer > click sur "oui".
A la fin un rapport va s´ouvrir; sauvegarde le de maniere a le retrouver en vue de le poster sur le forum.
Copies et colles le rapport stp.

a+
0
marcugodelire
 
All processes killed
========== PROCESSES ==========
No active process named explorer.exe was found!
========== FILES ==========
File/Folder C:\WINDOWS\exefld not found.
========== REGISTRY ==========
========== COMMANDS ==========

[EMPTYTEMP]

User: administrator
->Temp folder emptied: 22843485 bytes

User: All Users

User: All Users.WINDOWS

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes

User: elgy

User: hugo
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes

User: LocalService
->Temp folder emptied: 0 bytes
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
->Temporary Internet Files folder emptied: 32902 bytes

User: marcs
->Temp folder emptied: 2170876 bytes
->Temporary Internet Files folder emptied: 161054277 bytes
->Java cache emptied: 50047247 bytes
->FireFox cache emptied: 13177072 bytes

User: nathalie
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 493907 bytes
->Java cache emptied: 43177 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes

User: nina
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes

%systemdrive% .tmp files removed: 0 bytes
C:\WINDOWS\msdownld.tmp folder deleted successfully.
C:\WINDOWS\NV13521356.TMP folder deleted successfully.
C:\WINDOWS\NV14883508.TMP folder deleted successfully.
C:\WINDOWS\NV16001604.TMP folder deleted successfully.
C:\WINDOWS\NV17081712.TMP folder deleted successfully.
C:\WINDOWS\NV2032288.TMP folder deleted successfully.
C:\WINDOWS\NV38042244.TMP folder deleted successfully.
C:\WINDOWS\NV44164420.TMP folder deleted successfully.
C:\WINDOWS\NV49644968.TMP folder deleted successfully.
C:\WINDOWS\NV51565616.TMP folder deleted successfully.
C:\WINDOWS\NV55365152.TMP folder deleted successfully.
%systemroot% .tmp files removed: 5550812 bytes
%systemroot%\System32 .tmp files removed: 35202560 bytes
Windows Temp folder emptied: 1157616 bytes

RecycleBin emptied: 0 bytes

Total Files Cleaned = 278,26 mb


OTM by OldTimer - Version 3.0.0.2 log created on 06262009_220439

Files moved on Reboot...

Registry entries deleted on Reboot...
0
marcugodelire
 
Malwarebytes' Anti-Malware 1.38
Version de la base de données: 2339
Windows 5.1.2600 Service Pack 3

26/06/2009 22:21:00
mbam-log-2009-06-26 (22-21-00).txt

Type de recherche: Examen rapide
Eléments examinés: 116180
Temps écoulé: 5 minute(s), 40 second(s)

Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 0
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 2

Processus mémoire infecté(s):
(Aucun élément nuisible détecté)

Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)

Clé(s) du Registre infectée(s):
(Aucun élément nuisible détecté)

Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)

Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)

Dossier(s) infecté(s):
(Aucun élément nuisible détecté)

Fichier(s) infecté(s):
c:\documents and settings\marcs\Cookies\MM2048.DAT (Trojan.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\marcs\Cookies\MM256.DAT (Trojan.Agent) -> Quarantined and deleted successfully.
0
Utilisateur anonyme
 
Télécharge AD-REMOVER
http://sd-1.archive-host.com/membres/up/16506160323759868/AD­-R.exe
(de Cyrildu17 / C_XX) sur ton Bureau.

Déconnecte-toi et ferme toutes applications en cours

[*]Double-clique sur le programme d'installation, installe-le dans son emplacement par défaut (C:\Program files).
[*]Double-clique sur l'icône AD-Remover située sur ton Bureau.
[*]Au menu principal, choisis l'option L.[*]
Poste le rapport qui apparaît à la fin.

(Le rapport est sauvegardé aussi sous C:\Ad-report(date).log)

(CTRL+A pour tout sélectionner, CTRL+C pour copier et CTRL+V pour coller)

: "Process.exe", une composante de l'outil, est détecté par certains antivirus comme une infection, ne pas en tenir compte, il s'agit d'un faux positif, continue la procédure
0
marcugodelire
 
J'ai arreter l'application après 50mn car c'était pas encore fini.
il avait indiqué 6 fois ligne 8 trop longue.
Dois-je recommencer ?
0
Utilisateur anonyme
 
N on laisses tomber...

Télécharges et installes USBFIX de C_XX & Chiquitine29
http://pagesperso-orange.fr/NosTools/usbfix.html


Branches tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptibles d'avoir été infectées sans les ouvrir
# Double clic sur le raccourci UsbFix présent sur ton bureau .

# Choisis l'option 1 ( Recherche ) # Laisse travailler l'outil.

# Ensuite post le rapport UsbFix.txt qui apparaitra.

# Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque. ( C:\UsbFix.txt )


# Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.

A+
0
marcugodelire
 
La page que tu m'as donné ne fonctionne pas (pas de démarrage de telechargement ni sur serveur 1 ni 2
0