DD externe

Bonjour,

Mon disque dur externe mets des plombes à s'installer sur mon ordinateur, est-il possible que celui-ci soit infecté d'un virus???
Configuration: Windows XP
Firefox 3.0.11

23 réponses

  1. oui
    Fait rsit sur ton dd externe.
    • Télécharge : http://images.malwareremoval.com/random/RSIT.exe

    /!\ Important (Sous Vista) /!\
    Vous devez exécuter RSIT avec les droits d'administrateur, pour cela Clique droit sur RSIT et "Lancer en tant qu'administrateur"
    • Double clique sur RSIT.exe pour lancer l'outil.
    • Clique sur 'Continue' à l'écran Disclaimer.
    • Si l'outil Hijackthis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera et tu devras accepter la licence.
    • Une fois le scan fini , 2 rapports vont apparaitre. Poste le contenu des 2 rapports.
    ( C:\RSIT\log.txt et C:\RSIT\info.txt )
    • CTRL A pour sélectionner tout, CTRL C pour copier et puis CTRL V pour coller
    • tuto: : https://www.androidworld.fr/
    0
    1. voila les deux rapports:
      info.txt logfile of random's system information tool 1.06 2009-07-01 18:36:18

      ======Uninstall list======

      -->C:\Program Files\Nero\Nero 7\nero\uninstall\UNNERO.exe /UNINSTALL
      -->C:\WINDOWS\UNNeroBackItUp.exe /UNINSTALL
      -->C:\WINDOWS\UNNeroMediaHome.exe /UNINSTALL
      -->C:\WINDOWS\UNNeroShowTime.exe /UNINSTALL
      -->C:\WINDOWS\UNNeroVision.exe /UNINSTALL
      -->C:\WINDOWS\UNRecode.exe /UNINSTALL
      -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
      2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0015-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
      2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0016-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
      2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0018-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
      2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0019-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
      2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001A-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
      2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001B-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
      2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {3EC77D26-799B-4CD8-914F-C1565E796173}
      2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-040C-0000-0000000FF1CE} /uninstall {430971B1-C31E-45DA-81E0-72C095BAB72C}
      2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0C0A-0000-0000000FF1CE} /uninstall {F7A31780-33C4-4E39-951A-5EC9B91D7BF1}
      2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {BEE75E01-DD3F-4D5F-B96C-609E6538D419}
      2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0044-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
      2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-006E-0409-0000-0000000FF1CE} /uninstall {FAD8A83E-9BAC-4179-9268-A35948034D85}
      2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-00A1-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
      2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-00BA-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
      2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0114-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
      2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0115-0409-0000-0000000FF1CE} /uninstall {FAD8A83E-9BAC-4179-9268-A35948034D85}
      2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0117-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
      Ad-Aware SE Personal-->C:\PROGRA~1\Lavasoft\AD-AWA~1\UNWISE.EXE C:\PROGRA~1\Lavasoft\AD-AWA~1\INSTALL.LOG
      Adobe Flash Player 10 Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
      Adobe Flash Player ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
      Adobe Reader 7.1.0 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A71000000002}
      ALUpdate-->"C:\Program Files\ESTsoft\ALUpdate\unins000.exe"
      ALZip-->"C:\Program Files\ESTsoft\ALZip\unins000.exe"
      Analyseur et SDK XML Microsoft-->MsiExec.exe /I{3E908702-AF35-4611-9518-955DA24B7E07}
      Apple Software Update-->MsiExec.exe /I{B74F042E-E1B9-4A5B-8D46-387BB172F0A4}
      Archiveur WinRAR-->C:\Program Files\WinRAR\uninstall.exe
      Assistant de connexion Windows Live-->MsiExec.exe /I{D3116CC7-24DC-4CA3-9CE1-23FED836E9F2}
      Azureus-->C:\Program Files\Azureus\Uninstall.exe
      Correctif pour Lecteur Windows Media 11 (KB939683)-->"C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
      Correctif pour Windows Internet Explorer 7 (KB947864)-->"C:\WINDOWS\ie7updates\KB947864-IE7\spuninst\spuninst.exe"
      Correctif pour Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
      Dead To Rights-->C:\PROGRA~1\DEADTO~1\UNWISE.EXE C:\PROGRA~1\DEADTO~1\INSTALL.LOG
      DivX Web Player-->C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
      DVD Shrink 3.2-->"C:\Program Files\DVD Shrink\unins000.exe"
      eMule-->"C:\Program Files\eMule\Uninstall.exe"
      ESET NOD32 Antivirus-->MsiExec.exe /I{57ECFB4D-FE11-491A-9AA0-0AF7C3ABC51D}
      Everest Poker (Remove Only)-->C:\Program Files\Everest Poker\cstart.exe /uninstall
      FIFA 2003-->C:\Program Files\EA SPORTS\FIFA 2003\EAUninstall.exe
      Global Operations-->C:\Program Files\InstallShield Installation Information\{ED5AACB5-F387-4DF0-961D-C2E5EA8702CF}\setup.exe -l0x40c Uninstall
      GOM Player-->"C:\Program Files\GRETECH\GomPlayer\Uninstall.exe"
      Google Toolbar for Internet Explorer-->"C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_BDA1448D3D255554.exe" /uninstall
      Google Toolbar for Internet Explorer-->MsiExec.exe /I{18455581-E099-4BA8-BC6B-F34B2F06600C}
      Google Update Helper-->MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
      Google Earth-->MsiExec.exe /X{CC016F21-3970-11DE-B878-005056806466}
      HijackThis 2.0.2-->"C:\Documents and Settings\Jé\Bureau\HijackThis.exe" /uninstall
      Hotfix for Microsoft .NET Framework 3.0 (KB932471)-->C:\WINDOWS\system32\msiexec.exe /promptrestart /uninstall {ECD292A0-0347-4244-8C24-5DBCE990FB40} /package {BAF78226-3200-4DB4-BE33-4D922A799840}
      Hotfix for Windows Media Format 11 SDK (KB929399)-->"C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
      Hotfix for Windows Media Format SDK (KB902344)-->"C:\WINDOWS\$NtUninstallKB902344$\spuninst\spuninst.exe"
      Intel(R) Graphics Media Accelerator Driver-->RUNDLL32.EXE C:\WINDOWS\system32\ialmrem.dll,UninstallW2KIGfx2ID PCI\VEN_8086&DEV_27A6 PCI\VEN_8086&DEV_27A2
      iTunes-->MsiExec.exe /I{4F5CE18C-D97D-48FF-A510-A0D90C918294}
      J2SE Development Kit 5.0 Update 9-->MsiExec.exe /I{32A3A4F4-B792-11D6-A78A-00B0D0150090}
      J2SE Runtime Environment 5.0 Update 9-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150090}
      Java(TM) 6 Update 13-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216013FF}
      Java(TM) 6 Update 5-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160050}
      Java(TM) 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
      LAN-Express AS IEEE 802.11 Wireless LAN-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FCCB0B43-7A6D-49A4-A5B3-B10F592F4EB6}\setup.exe" -l0x40c -removeonly
      Lecteur Windows Media 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
      LimeWire PRO 4.12.3-->"C:\Program Files\LimeWire\uninstall.exe"
      Logiciel Intel(R) PROSet/Wireless-->C:\WINDOWS\Installer\iProInst.exe
      LUMIX Simple Viewer-->C:\Program Files\InstallShield Installation Information\{2CDCCE7E-55D5-40CC-AEA0-ABA54713501F}\setup.exe -runfromtemp -l0x040c -removeonly
      Magic ISO Maker v5.4 (build 0239)-->C:\PROGRA~1\MagicISO\UNWISE.EXE C:\PROGRA~1\MagicISO\INSTALL.LOG
      Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
      mCore-->MsiExec.exe /I{E81667C6-2856-46D6-ABEA-6A2F42166779}
      mDriver-->MsiExec.exe /I{A0F925BF-5C55-44C2-A4E7-5A4C59791C29}
      Microsoft .NET Framework 1.1 French Language Pack-->MsiExec.exe /X{9A394342-4A68-4EBA-85A6-55B559F4E700}
      Microsoft .NET Framework 1.1 Hotfix (KB928366)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"
      Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
      Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
      Microsoft .NET Framework 2.0 Service Pack 1-->MsiExec.exe /I{B508B3F1-A24A-32C0-B310-85786919EF28}
      Microsoft .NET Framework 3.0 French Language Pack-->MsiExec.exe /X{E3C080B0-23F5-49AF-89F8-8E8DBC89E659}
      Microsoft .NET Framework 3.0 Service Pack 1-->MsiExec.exe /I{2BA00471-0328-3743-93BD-FA813353A783}
      Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
      Microsoft Data Access Components KB870669-->C:\WINDOWS\muninst.exe C:\WINDOWS\INF\KB870669.inf
      Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
      Microsoft Motocross Madness-->"C:\Program Files\Microsoft Games\Motocross Madness\UNINSTAL.EXE" /runtemp
      Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
      Microsoft Office Access MUI (English) 2007-->MsiExec.exe /X{90120000-0015-0409-0000-0000000FF1CE}
      Microsoft Office Access Setup Metadata MUI (English) 2007-->MsiExec.exe /X{90120000-0117-0409-0000-0000000FF1CE}
      Microsoft Office Enterprise 2007-->"C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall ENTERPRISE /dll OSETUP.DLL
      Microsoft Office Enterprise 2007-->MsiExec.exe /X{90120000-0030-0000-0000-0000000FF1CE}
      Microsoft Office Excel MUI (English) 2007-->MsiExec.exe /X{90120000-0016-0409-0000-0000000FF1CE}
      Microsoft Office Groove MUI (English) 2007-->MsiExec.exe /X{90120000-00BA-0409-0000-0000000FF1CE}
      Microsoft Office Groove Setup Metadata MUI (English) 2007-->MsiExec.exe /X{90120000-0114-0409-0000-0000000FF1CE}
      Microsoft Office InfoPath MUI (English) 2007-->MsiExec.exe /X{90120000-0044-0409-0000-0000000FF1CE}
      Microsoft Office OneNote MUI (English) 2007-->MsiExec.exe /X{90120000-00A1-0409-0000-0000000FF1CE}
      Microsoft Office Outlook MUI (English) 2007-->MsiExec.exe /X{90120000-001A-0409-0000-0000000FF1CE}
      Microsoft Office PowerPoint MUI (English) 2007-->MsiExec.exe /X{90120000-0018-0409-0000-0000000FF1CE}
      Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
      Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
      Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
      Microsoft Office Proofing (English) 2007-->MsiExec.exe /X{90120000-002C-0409-0000-0000000FF1CE}
      Microsoft Office Publisher MUI (English) 2007-->MsiExec.exe /X{90120000-0019-0409-0000-0000000FF1CE}
      Microsoft Office Shared MUI (English) 2007-->MsiExec.exe /X{90120000-006E-0409-0000-0000000FF1CE}
      Microsoft Office Shared Setup Metadata MUI (English) 2007-->MsiExec.exe /X{90120000-0115-0409-0000-0000000FF1CE}
      Microsoft Office Word MUI (English) 2007-->MsiExec.exe /X{90120000-001B-0409-0000-0000000FF1CE}
      Microsoft Save as PDF or XPS Add-in for 2007 Microsoft Office programs-->MsiExec.exe /X{90120000-00B2-0409-0000-0000000FF1CE}
      Microsoft Silverlight-->MsiExec.exe /I{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
      Microsoft User-Mode Driver Framework Feature Pack 1.0-->"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
      Mise à jour critique pour Lecteur Windows Media 11 (KB959772)-->"C:\WINDOWS\$NtUninstallKB959772_WM11$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Lecteur Windows Media (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Lecteur Windows Media 10 (KB917734)-->"C:\WINDOWS\$NtUninstallKB917734_WMP10$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Lecteur Windows Media 10 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP10$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Lecteur Windows Media 11 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Lecteur Windows Media 11 (KB954154)-->"C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB938127)-->"C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB944533)-->"C:\WINDOWS\ie7updates\KB944533-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB950759)-->"C:\WINDOWS\ie7updates\KB950759-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB953838)-->"C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB956390)-->"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB958215)-->"C:\WINDOWS\ie7updates\KB958215-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB960714)-->"C:\WINDOWS\ie7updates\KB960714-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB961260)-->"C:\WINDOWS\ie7updates\KB961260-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB963027)-->"C:\WINDOWS\ie7updates\KB963027-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB969897)-->"C:\WINDOWS\ie7updates\KB969897-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB904706)-->"C:\WINDOWS\$NtUninstallKB904706$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB923561)-->"C:\WINDOWS\$NtUninstallKB923561$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB923789)-->C:\WINDOWS\system32\MacroMed\Flash\genuinst.exe C:\WINDOWS\system32\MacroMed\Flash\KB923789.inf
      Mise à jour de sécurité pour Windows XP (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB950760)-->"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB951376)-->"C:\WINDOWS\$NtUninstallKB951376$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB952004)-->"C:\WINDOWS\$NtUninstallKB952004$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB953155)-->"C:\WINDOWS\$NtUninstallKB953155$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB953839)-->"C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB954211)-->"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB954459)-->"C:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB954600)-->"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB956391)-->"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB956572)-->"C:\WINDOWS\$NtUninstallKB956572$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB956841)-->"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB957095)-->"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB958687)-->"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB958690)-->"C:\WINDOWS\$NtUninstallKB958690$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB959426)-->"C:\WINDOWS\$NtUninstallKB959426$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB960225)-->"C:\WINDOWS\$NtUninstallKB960225$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB960715)-->"C:\WINDOWS\$NtUninstallKB960715$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB960803)-->"C:\WINDOWS\$NtUninstallKB960803$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB961373)-->"C:\WINDOWS\$NtUninstallKB961373$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB961501)-->"C:\WINDOWS\$NtUninstallKB961501$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB968537)-->"C:\WINDOWS\$NtUninstallKB968537$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB969898)-->"C:\WINDOWS\$NtUninstallKB969898$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB970238)-->"C:\WINDOWS\$NtUninstallKB970238$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB970483)-->"C:\WINDOWS\$NtUninstallKB970483$\spuninst\spuninst.exe"
      Mise à jour pour Windows XP (KB942763)-->"C:\WINDOWS\$NtUninstallKB942763$\spuninst\spuninst.exe"
      Mise à jour pour Windows XP (KB951072-v2)-->"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
      Mise à jour pour Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
      Mise à jour pour Windows XP (KB955839)-->"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
      Mise à jour pour Windows XP (KB967715)-->"C:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe"
      mMHouse-->MsiExec.exe /I{F0BFC7EF-9CF8-44EE-91B0-158884CD87C5}
      Module de prise en charge linguistique de Microsoft .NET Framework 2.0 - FRA-->C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0 Language Pack - FRA\install.exe
      Module de prise en charge linguistique du français de Microsoft .NET Framework 3.0-->c:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0 French Language Pack\setup.exe
      Mozilla Firefox (3.0.11)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
      mPfMgr-->MsiExec.exe /I{8B928BA1-EDEC-4227-A2DA-DD83026C36F5}
      mProSafe-->MsiExec.exe /I{23FB368F-1399-4EAC-817C-4B83ECBE3D83}
      MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
      MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
      MSXML 6.0 Parser (KB933579)-->MsiExec.exe /I{0A869A65-8C94-4F7C-A5C7-972D3C8CED9E}
      mWlsSafe-->MsiExec.exe /I{FCA651F3-5BDA-4DDA-9E4A-5D87D6914CC4}
      mXML-->MsiExec.exe /I{9CC89556-3578-48DD-8408-04E66EBEF401}
      Nero 7 Ultra Edition-->MsiExec.exe /I{F14B8ECC-BDA0-4987-9201-D7B7DBE11036}
      NOD32 v3.x FiX 1.1 by TemDono (Free Updates - Expire in 2050)-->"C:\Program Files\ESET\ESET NOD32 Antivirus\unins000.exe"
      OpenOffice.org 3.1-->MsiExec.exe /I{E6B87DC4-2B3D-4483-ADFF-E483BF718991}
      Outil de mise à jour Google-->"C:\Program Files\Google\Google Updater\GoogleUpdater.exe" -uninstall
      Package de base Microsoft de service de chiffrement pour cartes à puce-->"C:\WINDOWS\$NtUninstallbasecsp$\spuninst\spuninst.exe"
      PHOTOfunSTUDIO -viewer--->C:\Program Files\InstallShield Installation Information\{9A9DBEBC-C800-4776-A970-D76D6AA405B1}\Setup.exe -runfromtemp -l0x040cPackage -removeonly
      PowerArchiver-->C:\Program Files\PowerArchiver\UNINST.EXE
      Pro Evolution Soccer 6 DEMO-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe /M{AC63F331-8D46-46BC-A0DA-9B3DF927FD3A} /l1036
      Pro Evolution Soccer 6-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe /M{EBB794ED-D282-4334-92FB-254481EFF514} /l1036
      QuickTime-->MsiExec.exe /I{9763E36A-08E9-4228-BBCE-12989A4EB1A8}
      Real Alternative 1.9.0-->"C:\Program Files\Real Alternative\unins000.exe"
      Realtek High Definition Audio Driver-->RtlUpd.exe -r -m
      Security Update for 2007 Microsoft Office System (KB951550)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {B243E9A5-ED77-4F1B-B338-2486FD82DC85}
      Security Update for 2007 Microsoft Office System (KB951944)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {797AE457-BA17-4BBC-B501-25FB3A0103C7}
      Security Update for 2007 Microsoft Office System (KB969559)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {69F52148-9BF6-4CDC-BF76-103DEAF3DD08}
      Security Update for 2007 Microsoft Office System (KB969679)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {C66E4A6C-6E07-4C63-8CCD-2493B5087C73}
      Security Update for Microsoft Office Excel 2007 (KB969682)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {C03803BD-745A-46F8-8557-817DED578780}
      Security Update for Microsoft Office OneNote 2007 (KB950130)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {F1B2401C-B610-4BF2-AA1C-52C55827A8F4}
      Security Update for Microsoft Office PowerPoint 2007 (KB957789)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {7559E742-FF9F-4FAE-B279-008ED296CB4D}
      Security Update for Microsoft Office Publisher 2007 (KB950114)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {F9C3CDBA-1F00-4D4D-959D-75C9D3ACDD85}
      Security Update for Microsoft Office system 2007 (KB954326)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {5F7F6FFF-395D-480E-8450-64F385D82C5F}
      Security Update for Microsoft Office system 2007 (KB969613)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {5ECEB317-CBE9-4E08-AB10-756CB6F0FB6C}
      Security Update for Microsoft Office Word 2007 (KB969604)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {CF3D6499-709C-43D0-8908-BC5652656050}
      Setting Utility Series-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{59452470-A902-477F-9338-9B88101681BD}\setup.exe" -l0x40c UNINSTALL -removeonly
      Skype™ 3.8-->MsiExec.exe /X{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}
      SLD Codec Pack-->C:\Program Files\SLD Codec Pack\uninstall.exe
      Soft Data Fax Modem with SmartCP-->C:\Program Files\CONEXANT\CNXT_MODEM_PCI_VEN_14F1&DEV_2C06&SUBSYS_104D1700\HXFSETUP.EXE -U -ISnZ17005.inf
      Sony MP4 Shared Library-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{01FDC9FC-4D4F-4DB0-ACD1-D3E8E1D52902}\setup.exe" -l0x40c -removeonly
      Sony USB Mouse-->Pmuninst.exe MouseSuite98
      Sony Utilities DLL-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{EF3D45BB-2260-4008-88EA-492E7744A9DF}\setup.exe" -l0x9 -removeonly
      Sony Video Shared Library-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BE56FEF0-1A0F-4719-B3AD-34B5087AFA6D}\setup.exe" -l0x40c -removeonly
      SubEdit-Player-->"C:\Program Files\SubEdit-Player\unins000.exe"
      Update for 2007 Microsoft Office System (KB967642)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {C444285D-5E4F-48A4-91DD-47AAAA68E92D}
      Update for Microsoft Office Outlook 2007 (KB969907)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {74F98B24-AFBD-4800-9BD6-87D349B5C462}
      Update for Outlook 2007 Junk Email Filter (kb970012)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {DC4A962B-9EC2-469C-BC9C-87312ADAEE81}
      VAIO Control Center-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FC37C108-821D-4EDE-8F40-D5B497586805}\Setup.exe" -l0x40c
      VAIO Event Service-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F0D85ADD-DD61-4B43-87A0-6DA52A211A8B}\setup.exe" -l0x40c -removeonly
      VAIO Power Management-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9E319E96-ED8E-4B01-9775-C521A1869A25}\setup.exe" -l0x40c UNINSTALL -removeonly
      VeohTV BETA-->C:\Program Files\InstallShield Installation Information\{0405E51E-9582-4207-8F38-AC44201D3808}\setup.exe -runfromtemp -l0x0409
      VLC media player 0.9.2-->C:\Program Files\VideoLAN\VLC\uninstall.exe
      Winamp-->"C:\Program Files\Winamp\UninstWA.exe"
      Windows Imaging Component-->"C:\WINDOWS\$NtUninstallWIC$\spuninst\spuninst.exe"
      Windows Live installer-->MsiExec.exe /X{FD44E544-E7D0-4DBA-9FA0-8AE1A1300390}
      Windows Live Messenger-->MsiExec.exe /X{BADF6744-3787-48F6-B8C9-4C4995401D65}
      Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
      Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
      Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
      Windows Presentation Foundation Language Pack (FRA)-->MsiExec.exe /X{6901DD22-527A-41EF-9059-E81FEDE9E494}
      Windows Presentation Foundation-->MsiExec.exe /X{BAF78226-3200-4DB4-BE33-4D922A799840}
      Windows Workflow Foundation FR Language Pack-->MsiExec.exe /I{B84C141C-9A13-44BE-9A69-301D7B11D836}
      Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
      WinZip 11.2-->MsiExec.exe /X{CD95F661-A5C4-44F5-A6AA-ECDD91C240B6}
      WinZip Self-Extractor-->"C:\Program Files\WinZip Self-Extractor\setup.exe" /uninstall
      Wireless LAN Starter-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{61D6E4FB-1A62-4EB1-BE56-929B00C155CF}\setup.exe" -l0x40c -removeonly
      Wireless Switch Setting Utility-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2A0F3EF9-68EE-49E9-A05B-ED5B82DF63E5}\Setup.exe" -l0x40c
      XML Paper Specification Shared Components Language Pack 1.0-->"C:\WINDOWS\$NtUninstallXPSEPSCLP$\spuninst\spuninst.exe"

      ======Security center information======

      AV: ESET NOD32 Antivirus 3.0

      ======System event log======

      Computer Name: LAPTOP
      Event Code: 51
      Message: Une erreur a été détectée sur le périphérique \Device\Harddisk3\D au cours d'une opération de pagination.

      Record Number: 30165
      Source Name: Disk
      Time Written: 20090630111700.000000+120
      Event Type: warning
      User:

      Computer Name: LAPTOP
      Event Code: 51
      Message: Une erreur a été détectée sur le périphérique \Device\Harddisk3\D au cours d'une opération de pagination.

      Record Number: 30164
      Source Name: Disk
      Time Written: 20090630111657.000000+120
      Event Type: warning
      User:

      Computer Name: LAPTOP
      Event Code: 1007
      Message: Votre ordinateur a automatiquement configuré l'adresse IP pour la
      carte avec l'adresse réseau 0016CFA024A8. L'adresse IP utilisée est 169.254.252.128.

      Record Number: 30128
      Source Name: Dhcp
      Time Written: 20090629232511.000000+120
      Event Type: warning
      User:

      Computer Name: LAPTOP
      Event Code: 4226
      Message: TCP/IP a atteint la limite de sécurité imposée sur le nombre de tentatives de connexion TCP simultanées.

      Record Number: 30060
      Source Name: Tcpip
      Time Written: 20090628235204.000000+120
      Event Type: warning
      User:

      Computer Name: LAPTOP
      Event Code: 36
      Message: Le service de temps n'a pas pu synchroniser l'heure système de 49152
      secondes car aucun fournisseur de temps n'a pu fournir de datage
      utilisable. L'horloge système n'est pas synchronisée.

      Record Number: 29993
      Source Name: W32Time
      Time Written: 20090628005545.000000+120
      Event Type: warning
      User:

      =====Application event log=====

      Computer Name: LAPTOP
      Event Code: 1002
      Message: Application bloquée firefox.exe, version 1.9.0.3188, module bloqué hungapp, version 0.0.0.0, adresse de blocage 0x00000000.

      Record Number: 1904
      Source Name: Application Hang
      Time Written: 20081006182343.000000+120
      Event Type: error
      User:

      Computer Name: LAPTOP
      Event Code: 1015
      Message: Le paramètre TraceLevel ne se trouve pas dans le Registre.
      La niveau de suivi utilisé par défaut est 32.

      Record Number: 1901
      Source Name: EvntAgnt
      Time Written: 20081006110338.000000+120
      Event Type: warning
      User:

      Computer Name: LAPTOP
      Event Code: 1003
      Message: Le paramètre TraceFileName ne se trouve pas dans le Registre.
      Le fichier de suivi utilisé par défaut est .

      Record Number: 1900
      Source Name: EvntAgnt
      Time Written: 20081006110338.000000+120
      Event Type: warning
      User:

      Computer Name: LAPTOP
      Event Code: 1015
      Message: Le paramètre TraceLevel ne se trouve pas dans le Registre.
      La niveau de suivi utilisé par défaut est 32.

      Record Number: 1894
      Source Name: EvntAgnt
      Time Written: 20081005095840.000000+120
      Event Type: warning
      User:

      Computer Name: LAPTOP
      Event Code: 1003
      Message: Le paramètre TraceFileName ne se trouve pas dans le Registre.
      Le fichier de suivi utilisé par défaut est .

      Record Number: 1893
      Source Name: EvntAgnt
      Time Written: 20081005095840.000000+120
      Event Type: warning
      User:

      ======Environment variables======

      "ComSpec"=%SystemRoot%\system32\cmd.exe
      "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\QuickTime\QTSystem;C:\Program Files\Intel\Wireless\Bin;C:\Program Files\ESTsoft\ALZip
      "windir"=%SystemRoot%
      "OS"=Windows_NT
      "PROCESSOR_ARCHITECTURE"=x86
      "PROCESSOR_LEVEL"=6
      "PROCESSOR_IDENTIFIER"=x86 Family 6 Model 14 Stepping 8, GenuineIntel
      "PROCESSOR_REVISION"=0e08
      "NUMBER_OF_PROCESSORS"=2
      "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
      "TEMP"=%SystemRoot%\TEMP
      "TMP"=%SystemRoot%\TEMP
      "CLASSPATH"=.;C:\Program Files\QuickTime\QTSystem\QTJava.zip
      "QTJAVA"=C:\Program Files\QuickTime\QTSystem\QTJava.zip
      "FP_NO_HOST_CHECK"=NO

      -----------------EOF-----------------
      et le deuxième:

      Logfile of random's system information tool 1.06 (written by random/random)
      Run by Jé at 2009-07-01 18:35:53
      Microsoft Windows XP Professionnel Service Pack 3
      System drive C: has 9 GB (29%) free of 31 GB
      Total RAM: 502 MB (21% free)

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 18:36:11, on 1/07/2009
      Platform: Windows XP SP3 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.16850)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
      C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
      C:\WINDOWS\System32\inetsrv\inetinfo.exe
      C:\Program Files\Java\jre6\bin\jqs.exe
      C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
      C:\WINDOWS\System32\tcpsvcs.exe
      C:\WINDOWS\System32\snmp.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
      C:\Program Files\iTunes\iTunesHelper.exe
      C:\Program Files\Java\jre6\bin\jusched.exe
      C:\Program Files\Sony\ISB Utility\ISBMgr.exe
      C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
      C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
      C:\WINDOWS\system32\hkcmd.exe
      C:\WINDOWS\system32\igfxpers.exe
      C:\WINDOWS\BBSTORE\DSS\DSSAGENT.EXE
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe
      C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      C:\Program Files\DNA\btdna.exe
      C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexStoreSvr.exe
      C:\Program Files\Panasonic\LUMIXSimpleViewer\PhLeAutoRun.exe
      C:\Program Files\OpenOffice.org 3\program\soffice.exe
      C:\Program Files\OpenOffice.org 3\program\soffice.bin
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\iPod\bin\iPodService.exe
      C:\WINDOWS\System32\wbem\wmiapsrv.exe
      C:\Program Files\Skype\Phone\Skype.exe
      C:\Program Files\Skype\Plugin Manager\skypePM.exe
      C:\WINDOWS\system32\taskmgr.exe
      C:\Program Files\Mozilla Firefox\firefox.exe
      C:\WINDOWS\explorer.exe
      C:\Documents and Settings\Jé\Bureau\RSIT.exe
      C:\Program Files\trend micro\Jé.exe

      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
      O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
      O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
      O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
      O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll (file missing)
      O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
      O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
      O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE
      O4 - HKLM\..\Run: [ISBMgr.exe] C:\Program Files\Sony\ISB Utility\ISBMgr.exe
      O4 - HKLM\..\Run: [SonyPowerCfg] "C:\Program Files\Sony\VAIO Power Management\SPMgr.exe"
      O4 - HKLM\..\Run: [Switcher.exe] C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
      O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
      O4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
      O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
      O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
      O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
      O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
      O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
      O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
      O4 - HKLM\..\Run: [DSS] C:\WINDOWS\BBSTORE\DSS\DSSAGENT.EXE
      O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_1_0 -reboot 1
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      O4 - HKCU\..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
      O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
      O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
      O4 - Startup: OpenOffice.org 3.1.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
      O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
      O4 - Global Startup: LUMIX Simple Viewer.lnk = ?
      O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
      O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
      O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
      O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
      O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/...
      O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
      O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
      O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
      O20 - AppInit_DLLs: mhiwuk.dll
      O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
      O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
      O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
      O23 - Service: Service Google Update (gupdate1c9afc42926bc28) (gupdate1c9afc42926bc28) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
      O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
      O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
      O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
      O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
      O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
      0
      1. • Télécharge :https://www.superantispyware.com/
        • Choisis "enregistrer" et enregistre-le sur ton bureau.
        • Double-clique sur l'icône d'installation qui vient de se créer et suis les instructions.
        • Créé une icône sur le bureau.
        • Double-clique sur l'icône de SAS (une tête dans un cercle rouge barré) pour le lancer.
        • Si l'outil te demande de mettre à jour le programme ("update the program definitions", clique sur yes.
        • Sous Configuration and Preferences, clique sur le bouton "Preferences"
        • Clique sur l'onglet "Scanning Control "
        • Dans "Scanner Options ", assure toi que la case devant lles lignes suivantes est cochée :
        • Close browsers before scanning
        • Scan for tracking cookies
        • Terminate memory threats before quarantining
        • Laisse les autres lignes décochées.
        • Clique sur le bouton "Close" pour quitter l'écran du centre de contrôle.
        • Dans la fenêtre principale, clique, dans "Scan for Harmful Software", sur "Scan your computer".
        • Dans la colonne de gauche, coche C:\Fixed Drive.
        • Dans la colonne de droite, sous "Complete scan", clique sur "Perform Complete Scan"
        • Clique sur "next" pour lancer le scan. Patiente pendant la durée du scan.
        • A la fin du scan, une fenêtre de résultats s'ouvre . Clique sur OK.
        • Assure toi que toutes les lignes de la fenêtre blanche sont cochées et clique sur "Next".
        • Tout ce qui a été trouvé sera mis en quarantaine. S'il t'es demandé de redémarrer l'ordi ("reboot"), clique sur Yes.
        • Pour recopier les informations sur le forum, fais ceci :
        • après le redémarrage de l'ordi, double-clique sur l'icône pour lancer SAS.
        • Clique sur "Preferences" puis sur l'onglet "Statistics/Logs ".
        • Dans "scanners logs", double-clique sur SUPERAntiSpyware Scan Log.
        • Le rapport va s'ouvrir dans ton éditeur de texte par défaut.
        • Copie son contenu dans ta réponse.
        • Regarde bien le tuto SUPERAntiSpyware il est très bien expliqué.
        • https://www.malekal.com/?s=SUPERAntiSpyware

        0
        1. bonjour,

          voila le rapport apres le scan:

          SUPERAntiSpyware Scan Log
          https://www.superantispyware.com/

          Generated 07/01/2009 at 08:45 PM

          Application Version : 4.26.1006

          Core Rules Database Version : 3965
          Trace Rules Database Version: 1905

          Scan type : Custom Scan
          Total Scan Time : 01:36:40

          Memory items scanned : 692
          Memory threats detected : 1
          Registry items scanned : 6943
          Registry threats detected : 6
          File items scanned : 72755
          File threats detected : 50

          Background Agent Application by Broderbund Software
          C:\WINDOWS\BBSTORE\DSS\DSSAGENT.EXE
          C:\WINDOWS\BBSTORE\DSS\DSSAGENT.EXE
          [DSS] C:\WINDOWS\BBSTORE\DSS\DSSAGENT.EXE

          Adware.Tracking Cookie
          C:\Documents and Settings\Jé\Cookies\jé@pcprivacycleaner[1].txt
          C:\Documents and Settings\Jé\Cookies\jé@virusremover2008[2].txt
          C:\Documents and Settings\Jé\Cookies\jé@msnportal.112.2o7[1].txt
          C:\Documents and Settings\Jé\Cookies\jé@wmvmedialease[1].txt
          C:\Documents and Settings\Jé\Cookies\jé@rotator.adjuggler[2].txt
          C:\Documents and Settings\Jé\Cookies\jé@fastclick[2].txt
          C:\Documents and Settings\Jé\Cookies\jé@bs.serving-sys[2].txt
          C:\Documents and Settings\Jé\Cookies\jé@serving-sys[2].txt
          C:\Documents and Settings\Jé\Cookies\jé@ad.dragonstar.dmoglobal[2].txt
          C:\Documents and Settings\Jé\Cookies\jé@www.system-defender[1].txt
          C:\Documents and Settings\Jé\Cookies\jé@adbrite[1].txt
          C:\Documents and Settings\Jé\Cookies\jé@ads.heias[1].txt
          C:\Documents and Settings\Jé\Cookies\jé@de.sitestat[1].txt
          C:\Documents and Settings\Jé\Cookies\jé@atwola[2].txt
          C:\Documents and Settings\Jé\Cookies\jé@webmasterplan[1].txt
          C:\Documents and Settings\Jé\Cookies\jé@scanner.vav-x-scanner[2].txt
          C:\Documents and Settings\Jé\Cookies\jé@windowsmedia[1].txt
          C:\Documents and Settings\Jé\Cookies\jé@adopt.euroclick[1].txt
          C:\Documents and Settings\Jé\Cookies\jé@a2.adserver01[2].txt
          C:\Documents and Settings\Jé\Cookies\jé@statcounter[1].txt
          C:\Documents and Settings\Jé\Cookies\jé@protect.trustedantivirus[3].txt
          C:\Documents and Settings\Jé\Cookies\jé@atdmt[1].txt
          C:\Documents and Settings\Jé\Cookies\jé@doubleclick[2].txt
          C:\Documents and Settings\Jé\Cookies\jé@adtech[2].txt
          C:\Documents and Settings\Jé\Cookies\jé@tacoda[1].txt
          C:\Documents and Settings\Jé\Cookies\jé@content.yieldmanager.edgesuite[1].txt
          C:\Documents and Settings\Jé\Cookies\jé@advertising[2].txt
          C:\Documents and Settings\Jé\Cookies\jé@ad.yieldmanager[2].txt
          C:\Documents and Settings\Jé\Cookies\jé@fr.sitestat[1].txt
          C:\Documents and Settings\Jé\Cookies\jé@tracking.mlsat02[1].txt
          C:\Documents and Settings\Jé\Cookies\jé@content.yieldmanager[3].txt
          C:\Documents and Settings\Jé\Cookies\jé@adfarm1.adition[1].txt
          C:\Documents and Settings\Jé\Cookies\jé@fl01.ct2.comclick[1].txt
          C:\Documents and Settings\Jé\Cookies\jé@www.etracker[2].txt
          C:\Documents and Settings\Jé\Cookies\jé@himedia.individuad[2].txt
          C:\Documents and Settings\Jé\Cookies\jé@smartadserver[1].txt
          C:\Documents and Settings\Jé\Cookies\jé@content.yieldmanager[2].txt
          C:\Documents and Settings\Jé\Cookies\jé@protect.trustedantivirus[2].txt
          C:\Documents and Settings\Jé\Cookies\jé@2o7[2].txt
          C:\Documents and Settings\Jé\Cookies\jé@bluestreak[1].txt
          C:\Documents and Settings\Jé\Cookies\jé@tradedoubler[2].txt
          C:\Documents and Settings\Jé\Cookies\jé@adsrv.admediate[2].txt
          C:\Documents and Settings\Jé\Cookies\jé@mediaplex[1].txt
          C:\Documents and Settings\Jé\Cookies\jé@statse.webtrendslive[2].txt
          C:\Documents and Settings\Jé\Cookies\jé@apmebf[2].txt
          C:\Documents and Settings\Jé\Cookies\jé@www.safewebnavigate2008[1].txt

          Rogue.Component/Trace
          HKLM\Software\Microsoft\4C1AA2D3
          HKLM\Software\Microsoft\4C1AA2D3#4c1aa2d3
          HKLM\Software\Microsoft\4C1AA2D3#Version
          HKLM\Software\Microsoft\4C1AA2D3#4c1a0f53
          HKLM\Software\Microsoft\4C1AA2D3#4c1a66b6

          Adware.WhenU
          C:\PROGRAM FILES\DAEMON TOOLS\SETUPDTSB.EXE

          Trojan.Unknown Origin
          C:\WINDOWS\SYSTEM32\1.ICO
          C:\WINDOWS\SYSTEM32\2.ICO

          merci beaucoup
          0
          1. hello,

            voila j'ai recopié les deux rappors.

            Quelqu'un peut- il m'aider.

            Merci d'avance
            0
            1. hello,

              Personne ne sait m'aider pour déchiffrer ces deux rapports et regler une fois pour toute ces problèmes.

              merci d'avance
              0
              1. Bonjour

                Problème de connexion je ne pouvais pas être présent .A faire dans l'ordre.
                1=>Supprime tout ce que superanti spywares a trouvé.Redémarre ton pc.
                2=> Télécharge CCleaner : https://www.01net.com/telecharger/windows/Utilitaire/nettoyeurs_et_installeurs/fiches/32599.html

                • ou https://www.pcastuces.com/logitheque/ccleaner.htm
                • Ce logiciel va permettre de supprimer tous les fichiers temporaires et de corriger ton registre .
                • Lors de l'installation choisis bien "français" en langue .
                • avant de cliquer sur le bouton "installer", décoche toutes les "options supplémentaires" sauf les 2 premières.
                • (attention à l'installation penser à DECOCHER l'installation de Yahoo toolbar discrètement proposé en plus de CCleaner).
                • Un tuto ( aide ): http://perso.orange.fr/jesses/Docs/Logiciels/CCleaner.htm
                • Utilisation:
                • ! déconnecte toi et ferme toutes applications en cours !
                • va dans "nettoyeur" : fais -analyse- puis -nettoyage
                • va dans "registre": fais -chercher les erreurs- et -réparer toutes les erreurs-
                ( plusieurs fois jusqu'à ce qu'il n'y est plus d'erreur ) .
                • ( CCleaner : soft à garder sur son PC , super utile pour de bons nettoyages ...)
                ---------------------------------------------------------------------------
                3=>Post un nouveau rapport rsit.
                0
                1. Bonjour,

                  voila mon nouveau rapport rsit après nettoyage:

                  Logfile of random's system information tool 1.06 (written by random/random)
                  Run by Jé at 2009-07-02 18:32:20
                  Microsoft Windows XP Professionnel Service Pack 3
                  System drive C: has 9 GB (29%) free of 31 GB
                  Total RAM: 502 MB (46% free)

                  Logfile of Trend Micro HijackThis v2.0.2
                  Scan saved at 18:32:29, on 2/07/2009
                  Platform: Windows XP SP3 (WinNT 5.01.2600)
                  MSIE: Internet Explorer v7.00 (7.00.6000.16850)
                  Boot mode: Normal

                  Running processes:
                  C:\WINDOWS\System32\smss.exe
                  C:\WINDOWS\system32\winlogon.exe
                  C:\WINDOWS\system32\services.exe
                  C:\WINDOWS\system32\lsass.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
                  C:\WINDOWS\Explorer.EXE
                  C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
                  C:\WINDOWS\system32\spoolsv.exe
                  C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
                  C:\WINDOWS\System32\inetsrv\inetinfo.exe
                  C:\Program Files\Java\jre6\bin\jqs.exe
                  C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
                  C:\WINDOWS\System32\tcpsvcs.exe
                  C:\WINDOWS\System32\snmp.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
                  C:\Program Files\iTunes\iTunesHelper.exe
                  C:\Program Files\Java\jre6\bin\jusched.exe
                  C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
                  C:\Program Files\Sony\ISB Utility\ISBMgr.exe
                  C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
                  C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
                  C:\WINDOWS\system32\hkcmd.exe
                  C:\WINDOWS\system32\igfxpers.exe
                  C:\WINDOWS\system32\ctfmon.exe
                  C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe
                  C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                  C:\Program Files\DNA\btdna.exe
                  C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexStoreSvr.exe
                  C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
                  C:\Program Files\Panasonic\LUMIXSimpleViewer\PhLeAutoRun.exe
                  C:\Program Files\OpenOffice.org 3\program\soffice.exe
                  C:\Program Files\OpenOffice.org 3\program\soffice.bin
                  C:\WINDOWS\System32\svchost.exe
                  C:\Program Files\iPod\bin\iPodService.exe
                  C:\WINDOWS\System32\wbem\wmiapsrv.exe
                  C:\WINDOWS\system32\NOTEPAD.EXE
                  C:\WINDOWS\system32\NOTEPAD.EXE
                  C:\Program Files\Mozilla Firefox\firefox.exe
                  C:\Documents and Settings\Jé\Bureau\RSIT.exe
                  C:\Program Files\trend micro\Jé.exe

                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                  O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                  O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
                  O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
                  O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
                  O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                  O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
                  O3 - Toolbar: (no name) - {D0943516-5076-4020-A3B5-AEFAF26AB263} - (no file)
                  O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
                  O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                  O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                  O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                  O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
                  O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE
                  O4 - HKLM\..\Run: [ISBMgr.exe] C:\Program Files\Sony\ISB Utility\ISBMgr.exe
                  O4 - HKLM\..\Run: [SonyPowerCfg] "C:\Program Files\Sony\VAIO Power Management\SPMgr.exe"
                  O4 - HKLM\..\Run: [Switcher.exe] C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
                  O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
                  O4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
                  O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
                  O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
                  O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
                  O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
                  O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
                  O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
                  O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
                  O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_1_0 -reboot 1
                  O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                  O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
                  O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                  O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
                  O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
                  O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
                  O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                  O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
                  O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
                  O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
                  O4 - Startup: OpenOffice.org 3.1.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
                  O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                  O4 - Global Startup: LUMIX Simple Viewer.lnk = ?
                  O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
                  O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
                  O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
                  O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
                  O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
                  O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                  O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                  O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
                  O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/...
                  O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
                  O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
                  O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
                  O20 - AppInit_DLLs: mhiwuk.dll
                  O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
                  O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
                  O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
                  O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
                  O23 - Service: Service Google Update (gupdate1c9afc42926bc28) (gupdate1c9afc42926bc28) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
                  O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                  O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                  O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
                  O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
                  O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
                  O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
                  O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
                  0
                  1. • Télécharge et installe Malwarebytes' Anti-Malware
                    • (NB : S'il te manque"COMCTL32.OCX" lors de l'installe, alors télécharge le ici : https://www.malekal.com/tutorial-aboutbuster/
                    • A la fin de l'installation, veille à ce que l'option « mettre a jour Malwarebyte's Anti-Malware » soit cochée
                    • Lance MBAM et laisse les Mises à jour se télécharger (sinon fais les manuellement au lancement du programme)
                    • Puis va dans l'onglet "Recherche", coche "Exécuter un examen complet" puis "Rechercher"
                    • Sélectionne tes disques durs" puis clique sur "Lancer l’examen"
                    • A la fin du scan, clique sur Afficher les résultats
                    • Coche tous les éléments détectés puis clique sur Supprimer la sélection
                    • Enregistre le rapport
                    • S'il t'est demandé de redémarrer, clique sur Yes
                    • Poste le rapport de scan après la suppression ici
                    • Si tu as besoin d’aide regarde ce tutorial
                    https://www.malekal.com/tutoriel-malwarebyte-anti-malware/
                    0
                    1. lorsque je veux scanner mos disque dur externe (H) Il plante après 2min 3 sec sur:

                      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CurrentVersion\install­er\UserData\S-1-5-18\Components\[41565f5t

                      et après il me dit que le programme ne répond plus.

                      Que faire?
                      0
                      1. Fait superantispyware.
                        • Télécharge :https://www.superantispyware.com/
                        • Choisis "enregistrer" et enregistre-le sur ton bureau.
                        • Double-clique sur l'icône d'installation qui vient de se créer et suis les instructions.
                        • Créé une icône sur le bureau.
                        • Double-clique sur l'icône de SAS (une tête dans un cercle rouge barré) pour le lancer.
                        • Si l'outil te demande de mettre à jour le programme ("update the program definitions", clique sur yes.
                        • Sous Configuration and Preferences, clique sur le bouton "Preferences"
                        • Clique sur l'onglet "Scanning Control "
                        • Dans "Scanner Options ", assure toi que la case devant lles lignes suivantes est cochée :
                        • Close browsers before scanning
                        • Scan for tracking cookies
                        • Terminate memory threats before quarantining
                        • Laisse les autres lignes décochées.
                        • Clique sur le bouton "Close" pour quitter l'écran du centre de contrôle.
                        • Dans la fenêtre principale, clique, dans "Scan for Harmful Software", sur "Scan your computer".
                        • Dans la colonne de gauche, coche C:\Fixed Drive.
                        • Dans la colonne de droite, sous "Complete scan", clique sur "Perform Complete Scan"
                        • Clique sur "next" pour lancer le scan. Patiente pendant la durée du scan.
                        • A la fin du scan, une fenêtre de résultats s'ouvre . Clique sur OK.
                        • Assure toi que toutes les lignes de la fenêtre blanche sont cochées et clique sur "Next".
                        • Tout ce qui a été trouvé sera mis en quarantaine. S'il t'es demandé de redémarrer l'ordi ("reboot"), clique sur Yes.
                        • Pour recopier les informations sur le forum, fais ceci :
                        • après le redémarrage de l'ordi, double-clique sur l'icône pour lancer SAS.
                        • Clique sur "Preferences" puis sur l'onglet "Statistics/Logs ".
                        • Dans "scanners logs", double-clique sur SUPERAntiSpyware Scan Log.
                        • Le rapport va s'ouvrir dans ton éditeur de texte par défaut.
                        • Copie son contenu dans ta réponse.
                        • Regarde bien le tuto SUPERAntiSpyware il est très bien expliqué.
                        • https://www.malekal.com/?s=SUPERAntiSpyware

                        0
                        1. désolé du retard voila la réponse

                          SUPERAntiSpyware Scan Log
                          https://www.superantispyware.com/

                          Generated 07/03/2009 at 05:31 PM

                          Application Version : 4.26.1006

                          Core Rules Database Version : 3969
                          Trace Rules Database Version: 1909

                          Scan type : Complete Scan
                          Total Scan Time : 01:39:36

                          Memory items scanned : 692
                          Memory threats detected : 0
                          Registry items scanned : 6917
                          Registry threats detected : 0
                          File items scanned : 103462
                          File threats detected : 1

                          Trojan.Agent/Gen-Dropper[Temp]
                          C:\WINDOWS\SYSTEM32\SET21C.TMP
                          0
                          1. • Télécharges :
                            • http://sd-1.archive-host.com/membres/up/127028005715545653/FindyKill.exe
                            • \ !/Utilisateurs de Vista, il est nécessaire de désactiver l'UAC (contrôle des comptes utilisateurs) comme expliqué : ici
                            • Lance l’ installation avec les paramètres par defaut

                            • Double clic sur le raccourci FindyKill sur ton bureau
                            • Au menu principal, choisi option 1 (Recherche)
                            • Post le rapport FindyKill.txt

                            • Note : le rapport FindyKill.txt est sauvegardé a la racine du disque

                            0
                            1. hello,

                              voila le rapport findyskill:

                              ############################## | FindyKill V6.002 |

                              # User : Jé (Administrateurs) # LAPTOP
                              # Update on 03/07/09 by Chiquitine29 & C_XX
                              # Start at: 3:39:50 | 5/07/2009
                              # Website : http://pagesperso-orange.fr/NosTools/index.html

                              # Genuine Intel(R) CPU T2050 @ 1.60GHz
                              # Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 3
                              # Internet Explorer 7.0.5730.13
                              # Windows Firewall Status : Enabled
                              # AV : ESET NOD32 Antivirus 3.0 3.0 [ Enabled | Updated ]

                              # C:\ # Disque fixe local # 30 Go (8,69 Go free) [Windows] # NTFS
                              # D:\ # Disque fixe local # 44,52 Go (43,34 Go free) [Data] # NTFS
                              # E:\ # Disque CD-ROM # 5,91 Go (0 Mo free) [EURO_TRIP] # UDF
                              # F:\ # Disque amovible
                              # G:\ # Disque amovible
                              # H:\ # Disque fixe local # 596,02 Go (174,36 Go free) [Elements] # FAT32
                              # I:\ # Disque CD-ROM

                              ############################## | Processus actifs |

                              C:\WINDOWS\System32\smss.exe
                              C:\WINDOWS\system32\csrss.exe
                              C:\WINDOWS\system32\winlogon.exe
                              C:\WINDOWS\system32\services.exe
                              C:\WINDOWS\system32\lsass.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\System32\svchost.exe
                              C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
                              C:\WINDOWS\Explorer.EXE
                              C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
                              C:\WINDOWS\System32\svchost.exe
                              C:\WINDOWS\System32\svchost.exe
                              C:\WINDOWS\system32\spoolsv.exe
                              C:\WINDOWS\System32\svchost.exe
                              C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
                              C:\WINDOWS\System32\inetsrv\inetinfo.exe
                              C:\Program Files\Java\jre6\bin\jqs.exe
                              C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
                              C:\WINDOWS\System32\tcpsvcs.exe
                              C:\WINDOWS\System32\snmp.exe
                              C:\WINDOWS\System32\svchost.exe
                              C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
                              C:\WINDOWS\System32\alg.exe
                              C:\Program Files\iTunes\iTunesHelper.exe
                              C:\Program Files\Java\jre6\bin\jusched.exe
                              C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
                              C:\Program Files\Sony\ISB Utility\ISBMgr.exe
                              C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
                              C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
                              C:\WINDOWS\system32\igfxpers.exe
                              C:\WINDOWS\system32\ctfmon.exe
                              C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe
                              C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                              C:\Program Files\DNA\btdna.exe
                              C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexStoreSvr.exe
                              C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
                              C:\Program Files\Panasonic\LUMIXSimpleViewer\PhLeAutoRun.exe
                              C:\WINDOWS\System32\svchost.exe
                              C:\Program Files\iPod\bin\iPodService.exe
                              C:\WINDOWS\System32\wbem\wmiapsrv.exe
                              C:\Program Files\OpenOffice.org 3\program\soffice.exe
                              C:\Program Files\OpenOffice.org 3\program\soffice.bin
                              C:\Program Files\Mozilla Firefox\firefox.exe
                              C:\Program Files\Winamp\winamp.exe
                              C:\WINDOWS\system32\wbem\wmiprvse.exe

                              ################## | Registre Startup |

                              HKCU_Main: "Local Page"="C:\\WINDOWS\\system32\\blank.htm"
                              HKCU_Main: "Search Page"="https://www.google.com/?gws_rd=ssl"
                              HKCU_Main: "Start Page"="https://www.google.com/?gws_rd=ssl"
                              HKLM_logon: "Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
                              HKLM_logon: "DefaultUserName"="J‚"
                              HKLM_logon: "AltDefaultUserName"="J‚"
                              HKLM_logon: "LegalNoticeCaption"=""
                              HKLM_logon: "LegalNoticeText"=""
                              HKLM_Run: QuickTime Task="C:\Program Files\QuickTime\QTTask.exe" -atboottime
                              HKLM_Run: iTunesHelper="C:\Program Files\iTunes\iTunesHelper.exe"
                              HKLM_Run: SunJavaUpdateSched="C:\Program Files\Java\jre6\bin\jusched.exe"
                              HKLM_Run: egui="C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
                              HKLM_Run: Mouse Suite 98 Daemon=ICO.EXE
                              HKLM_Run: ISBMgr.exe=C:\Program Files\Sony\ISB Utility\ISBMgr.exe
                              HKLM_Run: SonyPowerCfg="C:\Program Files\Sony\VAIO Power Management\SPMgr.exe"
                              HKLM_Run: Switcher.exe=C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
                              HKLM_Run: GrooveMonitor="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
                              HKLM_Run: AzMixerSel=C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
                              HKLM_Run: SkyTel=SkyTel.EXE
                              HKLM_Run: Alcmtr=ALCMTR.EXE
                              HKLM_Run: NeroFilterCheck=C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
                              HKLM_Run: igfxtray=C:\WINDOWS\system32\igfxtray.exe
                              HKLM_Run: igfxhkcmd=C:\WINDOWS\system32\hkcmd.exe
                              HKLM_Run: igfxpers=C:\WINDOWS\system32\igfxpers.exe
                              HKCU_Run: updateMgr="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_1_0 -reboot 1
                              HKCU_Run: ctfmon.exe=C:\WINDOWS\system32\ctfmon.exe
                              HKCU_Run: BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}="C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
                              HKCU_Run: swg=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                              HKCU_Run: BitTorrent DNA="C:\Program Files\DNA\btdna.exe"
                              HKCU_Run: SUPERAntiSpyware=C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe

                              ################## | Fichiers # Dossiers infectieux |

                              ################## | C:\Documents and Settings\J‚\Temporary Internet Files |

                              ################## | All Drives ... |

                              Présent ! H:\autorun.inf

                              ################## | Registre # Clés Run infectieuses |

                              Présent ! HKCU\Software\Local AppWizard-Generated Applications\PhLeAutoRun
                              Présent ! HKU\S-1-5-21-1123561945-1482476501-725345543-1003\Software\Local AppWizard-Generated Applications\PhLeAutoRun

                              ################## | Registre # Mountpoints2 |

                              HKCU\...\Explorer\MountPoints2\H\Shell\AutoRun\Command
                              HKCU\...\Explorer\MountPoints2\{45f22104-423f-11de-ae7f-0016cfa024a8}\Shell\AutoRun\Command
                              HKCU\...\Explorer\MountPoints2\{c6730a48-fc4c-11dd-ae06-0016cfa024a8}\Shell\AutoRun\Command

                              ################## | Etat / Services / Informations |

                              # Affichage des fichiers cachés : OK

                              # Mode sans echec : OK

                              # Ndisuio -> Start = 3 ( Good = 3 | Bad = 4 )
                              # EapHost -> Start = 3 ( Good = 2 | Bad = 4 )
                              # Ip6Fw -> Start = 3 ( Good = 2 | Bad = 4 )
                              # SharedAccess -> Start = 2 ( Good = 2 | Bad = 4 )
                              # wuauserv -> Start = 2 ( Good = 2 | Bad = 4 )
                              # wscsvc -> Start = 2 ( Good = 2 | Bad = 4 )

                              ################## | Cracks / Keygens / Serials |

                              ################## | ! Fin du rapport # FindyKill V6.002 ! |
                              0
                              1. Bonjour

                                • Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) suceptible d avoir été infectés sans les ouvrir
                                • Double clic sur le raccourci FindyKill sur ton bureau
                                • Au menu principal,choisi l option 2 (Suppression)

                                /!\ il y aura 2 redémarrage, laisse travailler l outils jusqu a l apparition du message "nettoyage effectué"

                                /!\ Ne te sert pas du pc durant la suppression , ton bureau ne sera pas accessible c est normal !
                                • ensuite post le rapport FindyKill.txt
                                • Note : le rapport FindyKill.txt est sauvegardé a la racine du disque
                                • Note : Si le Bureau ne réapparait pas presse Ctrl + Alt + Suppr , Onglet "Fichier" , "Nouvelle tâche" , tapes explorer.exe et valides
                                0
                                1. hello,

                                  voici le rapport:

                                  ############################## | FindyKill V6.002 |

                                  # User : Jé (Administrateurs) # LAPTOP
                                  # Update on 03/07/09 by Chiquitine29 & C_XX
                                  # Start at: 21:01:33 | 5/07/2009
                                  # Website : http://pagesperso-orange.fr/NosTools/index.html

                                  # Genuine Intel(R) CPU T2050 @ 1.60GHz
                                  # Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 3
                                  # Internet Explorer 7.0.5730.13
                                  # Windows Firewall Status : Enabled
                                  # AV : ESET NOD32 Antivirus 3.0 3.0 [ Enabled | Updated ]

                                  # C:\ # Disque fixe local # 30 Go (10,26 Go free) [Windows] # NTFS
                                  # D:\ # Disque fixe local # 44,52 Go (43,34 Go free) [Data] # NTFS
                                  # E:\ # Disque CD-ROM # 5,91 Go (0 Mo free) [EURO_TRIP] # UDF
                                  # F:\ # Disque amovible
                                  # G:\ # Disque amovible
                                  # I:\ # Disque CD-ROM

                                  ############################## | Processus actifs |

                                  C:\WINDOWS\System32\smss.exe
                                  C:\WINDOWS\system32\csrss.exe
                                  C:\WINDOWS\system32\winlogon.exe
                                  C:\WINDOWS\system32\services.exe
                                  C:\WINDOWS\system32\lsass.exe
                                  C:\WINDOWS\system32\svchost.exe
                                  C:\WINDOWS\system32\svchost.exe
                                  C:\WINDOWS\System32\svchost.exe
                                  C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
                                  C:\WINDOWS\system32\logonui.exe
                                  C:\WINDOWS\system32\WgaTray.exe
                                  C:\WINDOWS\Explorer.EXE
                                  C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
                                  C:\WINDOWS\System32\svchost.exe
                                  C:\WINDOWS\System32\svchost.exe
                                  C:\WINDOWS\system32\spoolsv.exe
                                  C:\Program Files\Google\Update\GoogleUpdate.exe
                                  C:\WINDOWS\System32\svchost.exe
                                  C:\WINDOWS\System32\svchost.exe
                                  C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
                                  C:\Program Files\Google\Update\GoogleUpdate.exe
                                  C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                  C:\WINDOWS\System32\inetsrv\inetinfo.exe
                                  C:\Program Files\Java\jre6\bin\jqs.exe
                                  C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
                                  C:\Program Files\Google\Update\GoogleUpdate.exe
                                  C:\WINDOWS\System32\tcpsvcs.exe
                                  C:\WINDOWS\System32\snmp.exe
                                  C:\WINDOWS\System32\svchost.exe
                                  C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
                                  C:\WINDOWS\system32\wbem\wmiprvse.exe
                                  C:\WINDOWS\System32\alg.exe
                                  C:\WINDOWS\System32\wbem\wmiapsrv.exe

                                  ################## | Fichiers # Dossiers infectieux |

                                  ################## | C:\Documents and Settings\J‚\Temporary Internet Files |

                                  ################## | All Drives ... |

                                  ################## | Autres ... |

                                  ################## | Registre # Clés Run infectieuses |

                                  Supprimé ! HKCU\Software\Local AppWizard-Generated Applications\PhLeAutoRun

                                  ################## | Registre # Mountpoints2 |

                                  ################## | Listing des fichiers présent |

                                  [22/02/2009 22:27|--a------|0] - C:\ALZ55FE.tmp
                                  [06/06/2008 18:55|--a------|0] - C:\AUTOEXEC.BAT
                                  [07/06/2008 18:02|-rahs----|211] - C:\boot.ini
                                  [28/08/2001 14:00|-rahs----|4952] - C:\Bootfont.bin
                                  [06/06/2008 18:55|--a------|0] - C:\CONFIG.SYS
                                  [05/07/2009 21:20|--a------|2815] - C:\FindyKill.txt
                                  [06/09/2008 22:24|--a------|2380] - C:\fixnavi.txt
                                  [06/06/2008 18:55|-rahs----|0] - C:\IO.SYS
                                  [17/11/2008 19:28|--a------|0] - C:\log_lobby.txt
                                  [17/11/2008 19:28|--a------|0] - C:\log_lobby_dumper.txt
                                  [06/06/2008 18:55|-rahs----|0] - C:\MSDOS.SYS
                                  [07/06/2008 17:53|-rahs----|47564] - C:\NTDETECT.COM
                                  [08/06/2008 12:22|-rahs----|252240] - C:\ntldr
                                  [||] - C:\pagefile.sys
                                  [06/09/2008 23:14|--a------|2855] - C:\rapport.txt
                                  [08/06/2008 03:07|--ah-----|268] - C:\sqmdata00.sqm
                                  [08/06/2008 03:09|--ah-----|268] - C:\sqmdata01.sqm
                                  [08/06/2008 04:46|--ah-----|268] - C:\sqmdata02.sqm
                                  [12/06/2008 15:44|--ah-----|232] - C:\sqmdata03.sqm
                                  [12/06/2008 15:46|--ah-----|232] - C:\sqmdata04.sqm
                                  [12/06/2008 15:46|--ah-----|232] - C:\sqmdata05.sqm
                                  [12/06/2008 15:46|--ah-----|232] - C:\sqmdata06.sqm
                                  [12/06/2008 15:46|--ah-----|232] - C:\sqmdata07.sqm
                                  [12/06/2008 15:47|--ah-----|232] - C:\sqmdata08.sqm
                                  [12/06/2008 15:47|--ah-----|232] - C:\sqmdata09.sqm
                                  [12/06/2008 19:00|--ah-----|232] - C:\sqmdata10.sqm
                                  [12/06/2008 19:00|--ah-----|232] - C:\sqmdata11.sqm
                                  [12/06/2008 19:00|--ah-----|232] - C:\sqmdata12.sqm
                                  [12/06/2008 19:01|--ah-----|232] - C:\sqmdata13.sqm
                                  [26/07/2008 20:39|--ah-----|232] - C:\sqmdata14.sqm
                                  [10/01/2009 21:38|--ah-----|232] - C:\sqmdata15.sqm
                                  [05/03/2009 18:16|--ah-----|232] - C:\sqmdata16.sqm
                                  [12/04/2009 13:32|--ah-----|232] - C:\sqmdata17.sqm
                                  [12/04/2009 13:33|--ah-----|232] - C:\sqmdata18.sqm
                                  [06/06/2009 10:06|--ah-----|232] - C:\sqmdata19.sqm
                                  [08/06/2008 03:07|--ah-----|244] - C:\sqmnoopt00.sqm
                                  [08/06/2008 03:09|--ah-----|244] - C:\sqmnoopt01.sqm
                                  [08/06/2008 04:46|--ah-----|244] - C:\sqmnoopt02.sqm
                                  [12/06/2008 15:44|--ah-----|244] - C:\sqmnoopt03.sqm
                                  [12/06/2008 15:46|--ah-----|244] - C:\sqmnoopt04.sqm
                                  [12/06/2008 15:46|--ah-----|244] - C:\sqmnoopt05.sqm
                                  [12/06/2008 15:46|--ah-----|244] - C:\sqmnoopt06.sqm
                                  [12/06/2008 15:46|--ah-----|244] - C:\sqmnoopt07.sqm
                                  [12/06/2008 15:47|--ah-----|244] - C:\sqmnoopt08.sqm
                                  [12/06/2008 15:47|--ah-----|244] - C:\sqmnoopt09.sqm
                                  [12/06/2008 19:00|--ah-----|244] - C:\sqmnoopt10.sqm
                                  [12/06/2008 19:00|--ah-----|244] - C:\sqmnoopt11.sqm
                                  [12/06/2008 19:00|--ah-----|244] - C:\sqmnoopt12.sqm
                                  [12/06/2008 19:01|--ah-----|244] - C:\sqmnoopt13.sqm
                                  [26/07/2008 20:39|--ah-----|244] - C:\sqmnoopt14.sqm
                                  [10/01/2009 21:38|--ah-----|244] - C:\sqmnoopt15.sqm
                                  [05/03/2009 18:16|--ah-----|244] - C:\sqmnoopt16.sqm
                                  [12/04/2009 13:32|--ah-----|244] - C:\sqmnoopt17.sqm
                                  [12/04/2009 13:33|--ah-----|244] - C:\sqmnoopt18.sqm
                                  [06/06/2009 10:06|--ah-----|244] - C:\sqmnoopt19.sqm
                                  [05/07/2009 13:20|--a------|5917] - C:\UsbFix.txt

                                  ################## | Vaccination |

                                  # C:\autorun.inf ( # Not infected ) -> Folder created by FindyKill.
                                  # D:\autorun.inf ( # Not infected ) -> Folder created by FindyKill.

                                  ################## | Etat / Services / Informations |

                                  # Mode sans echec : OK

                                  # Affichage des fichiers cachés : OK

                                  # Ndisuio -> Start = 3 ( Good = 3 | Bad = 4 )
                                  # EapHost -> Start = 2 ( Good = 2 | Bad = 4 )
                                  # Ip6Fw -> Start = 2 ( Good = 2 | Bad = 4 )
                                  # SharedAccess -> Start = 2 ( Good = 2 | Bad = 4 )
                                  # wuauserv -> Start = 2 ( Good = 2 | Bad = 4 )
                                  # wscsvc -> Start = 2 ( Good = 2 | Bad = 4 )

                                  ################## | PEH ... |

                                  ################## | Cracks / Keygens / Serials |

                                  ################## | ! Fin du rapport # FindyKill V6.002 ! |
                                  0
                                  1. Pour la désinfection tu n'as pas branché H:\ # Disque fixe local # 596,02 Go (174,36 Go free) [Elements] # FAT32
                                    Refait le en connectant H: et post le rapport.
                                    0
                                    1. Ah ok,

                                      jel'avais déjà fais mais il mettait tellement de temps que je ne trouvais pas cela normal. Mon ordi s'est éteint et quand il a redémarré il m'a mis un fond bleu disant que windows analyserait le disque H FAT 32. cette analyse n'avance pas pour un sou.

                                      Donc c'est tout a fait normal qu'il mette des plombes pour le nettoyer???

                                      je posterai le rapport demain ou dans la nuit (je dois attendre 3h avant que mon DD externe s'installe)

                                      encore merci
                                      0
                                      1. Donc c'est tout a fait normal qu'il mette des plombes pour le nettoyer??? NON
                                        Laisse tomber findykill.Pour cette nuit fait un scan avec dr web .
                                        Le scan peut être très long.Scan toos tes dd externes.
                                        • Télécharge: ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe sur ton bureau.
                                        • Double-clique sur drweb-cureit.exe et clique sur Commencer le scan.
                                        • Si il trouve des processus infectés, clique sur le bouton Oui pour Tout à l'invite.
                                        • Lorsque le scan rapide est terminé, clique sur Options > Changer la configuration.
                                        • Choisis l'onglet Scanner, et décoche Analyse heuristique.
                                        • De retour à la fenêtre principale : choisis Analyse complète.
                                        • Clique la flèche verte sur la droite et le scan débutera. Une publicité apparaît quelquefois, ferme-la.
                                        • Clique Oui pour Tout si un fichier est détecté.
                                        • A la fin du scan, si des infections sont trouvées, clique sur Tout sélectionner, puis surDésinfecter.
                                        • Si la désinfection est impossible, clique sur Quarantaine.
                                        • Au menu principal de l'outil, en haut à gauche, clique sur le menu Fichier et choisis Enregistrer le rapport.
                                        • Sauvegarde le rapport sur ton Bureau. Ce dernier se nommera DrWeb.csv.
                                        • Ferme Dr.Web CureIt!
                                        • /!\ Important /!\ Redémarre ton ordinateur car certains fichiers peuvent être déplacés/réparés au redémarrage.
                                        • Après le redémarrage, fais un copié/collé du rapport dans ta prochaine réponse
                                        0
                                        1. bon, des que mon DD externe sera installé je ferai le scan avec dr web.

                                          Si je suis oblige de le redémarrer (mon ordi) dois- je à chaque fois attendre de réinstaller mon DD externe, car si je le laisse brancher à mon ordi celui-ci redémarre en balancant un programme (sur fond bleu) qui l'analyse.

                                          c'est quand je le redémarre moi je débranche mon DD externe!!! sinon je suis parti pour des heures

                                          je fais comment sinon??

                                          merci
                                          0
                                          • 1
                                          • 2