Impossible d'accéder au poste de travail

Bonjour tout le monde,

Récemment, j'ai eu beaucoup de problème avec mon ordinateur est-ce que vous pourriez m'aider à les résoudre. ( je ne m'y connais pas trop en informatique alors ,s'il vous plaît, soyez concis)


• L'ordinateur redémarre seul après avoir afficher un écran bleu. (Principalement quand je démarre une vidéo)

• Je n'arrive plus a ouvrir Photoshop (il bug après avoir vérifier les modules externes)

• Certain programme (comme Ad-aware) sont impossibles à installer. (il y a une fenêtre "Windows instal" avec une jauge qui ne se remplit jamais)

• L'ordinateur ne reconnait plus ma PSP mais ma clée USB oui

• Il est impossible d'accéder au Poste de Travail ( Il y a une lampe torche éclairant un dossier puis ça bug. Je
suis obligée de retirer la fenêtre via le gestionnaire de tâches )

• Certain jeu et émulateur ne se lance pas.

Il me semble que tout ces problèmes soient l'œuvre d'un virus. Il y a-t-il une solution ? Ou suis-je obligé de tout formater ?

Cordialement =)
Configuration: Windows XP
Firefox 3.0.11

38 réponses

Résumé de la discussion

Plusieurs symptômes surviennent sur Windows XP, indiquant une potentielle infection ou un dysfonctionnement: redémarrages après un écran bleu, impossibilité d’ouvrir Photoshop et des problèmes de reconnaissance des périphériques. Des mesures préconisées incluent le démarrage en mode sans échec et l’usage d’outils de nettoyage comme RSIT, et l’analyse via des journaux de diagnostic (OTL/OTM) pour repérer les éléments malveillants. Les extraits montrent des modifications système importantes: processus et services supprimés, fichiers et clés de registre altérés, et un fichier hosts modifié, Avast signalant une protection active sur la machine.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    ok jte laisse faire avec ta baguette magic :)
    1
    1. Contributeur sécurité
      salut

      • Télécharge Random's System Information Tool (RSIT) de Random/Random, et enregistre le sur ton Bureau.
      http://images.malwareremoval.com/random/RSIT.exe
      • Double clique sur RSIT.exe pour lancer l'outil.
      • Clique sur "Continue" à l'écran Disclaimer.
      • Si l'outil HijackThis n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu s'il te le demande) et tu devras accepter la licence.
      • Une fois le scan terminé, deux rapports vont apparaître : poste les dans deux messages séparés stp

      Tutoriel illustré pour t'aider : https://www.androidworld.fr/
      0
      1. bon, surtout avan de telecharger je ne sais quoi, tu va faire une petite reparation

        demarer
        executer (tu tape cmd)
        de la une fenetre noir souvre;

        tu tape dedans chkdsk/f

        tu redemar ton pc et la tada! une page bleu saffiche avec un scan qui va reparer toute les erreur de windows.

        ces pas bo quand meme sa????
        0
        1. Contributeur sécurité
          @ greg14000 : salut

          et donc d'après toi sa vient d'un probleme de windows, comment as tu pu dire que sa vient de la et pas d'autre choses sans avoir vu quoique ce soit ??

          est ce que tu sais a quoi sert RSIT ?
          0
          1. je sais par exeperiance que une simple reparation de windows suffi. jai vu des informaticien me dire quun disque dure est hs a cause dun ecran bleu qui saffiche au debus par exemple... alors que le chkdsk c comme magic!!!
            0
            1. en gros sa fai la meme chose que toi. sauf que la c un logiciel inclu dans windows
              0
              1. Merci pour vos solutions mais le programme RSIT n'arrive pas à se lancer, et pour l'autre solution, je ne l'ai pas encore tester. Je le ferai plus tard car pour le moment j'ai besoin de mon ordinateur.
                0
                1. oki mais tien nous au courent tout de meme
                  0
                  1. Contributeur sécurité
                    bonjour,

                    essaye en mode sans echec RSIT
                    0
                    1. Bonjour,

                      Le scan de Windows n'a donné aucun résultat ^^' J'ai donc lancé RSIT :


                      ________________________________________

                      Logfile of random's system information tool 1.06 (written by random/random)
                      Run by Moi at 2009-07-21 18:42:16
                      Microsoft Windows XP Professionnel Service Pack 2
                      System drive C: has 17 GB (13%) free of 131 GB
                      Total RAM: 1535 MB (83% free)

                      HijackThis download failed

                      ======Scheduled tasks folder======

                      C:\WINDOWS\tasks\AppleSoftwareUpdate.job
                      C:\WINDOWS\tasks\HPpromotions journeysoftware.job

                      ======Registry dump======

                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
                      Aide pour le lien d'Adobe PDF Reader - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]

                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{39F7E362-828A-4B5A-BCAF-5B79BFDFEA60}]
                      BitComet Helper - C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll [2008-02-29 468280]

                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
                      Spybot-S&D IE Protection - C:\PROGRA~1\SPYBOT~1\SDHelper.dll []

                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]

                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
                      Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-05-01 35840]

                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
                      {8E718888-423F-11D2-876E-00A0C9082467} - &Radio - C:\WINDOWS\System32\msdxm.ocx [2004-08-20 848922]
                      {32099AAC-C132-4136-9E9A-4E364A424E17} - DAEMON Tools Toolbar - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll [2009-04-23 937416]

                      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
                      "XpDis0Conf"=C:\PROGRA~1\Belkin\BELKIN~1\Tool\WinXPDisableZeroConfigation.exe VEN_14E4&DEV_4320&SUBSYS_70011799 /d []
                      "avast!"=C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe [2009-02-05 81000]
                      "Athan"=C:\Program Files\Athan\Athan.exe [2008-08-18 1069056]
                      "NvCplDaemon"=C:\WINDOWS\System32\NvCpl.dll [2007-06-28 8466432]
                      "SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-05-01 148888]
                      "KernelFaultCheck"=C:\WINDOWS\system32\dumprep 0 -k []
                      "QuickTime Task"=C:\Program Files\MpcStar\Codecs\QuickTime\QTTask.exe -atboottime []
                      "iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2009-06-05 292136]

                      [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
                      "SpybotSD TeaTimer"=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2009-01-26 2144088]
                      "DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\daemon.exe [2009-04-23 691656]

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
                      C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-01-11 39792]

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcoholAutomount]
                      C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe /automount []

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AnyDVD]
                      C:\Program Files\SlySoft\AnyDVD\AnyDVDtray.exe []

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUSGamerOSD]
                      C:\Program Files\ASUS\GamerOSD\GamerOSD.exe [2007-07-12 380928]

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
                      C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe []

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CloneCDTray]
                      C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe [2006-09-28 57344]

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
                      C:\WINDOWS\System32\ctfmon.exe [2004-08-20 15360]

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Pro Agent]
                      C:\Program Files\DAEMON Tools Pro\DTProAgent.exe []

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools-1033]
                      C:\Program Files\D-Tools\daemon.exe -lang 1033 []

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
                      C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2005-05-11 49152]

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IDMan]
                      C:\Program Files\Internet Download Manager\IDMan.exe /onboot []

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMJPMIG8.1]
                      C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE [2004-08-04 208952]

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KON]
                      C:\PROGRA~1\KON\KON\KON.exe []

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
                      C:\Program Files\MSN Messenger\msnmsgr.exe [2007-01-19 5674352]

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSPY2002]
                      C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe [2004-08-04 59392]

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
                      C:\WINDOWS\system32\NeroCheck.exe [2001-07-09 155648]

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
                      C:\WINDOWS\System32\NvCpl.dll [2007-06-28 8466432]

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
                      C:\WINDOWS\System32\NvMcTray.dll [2007-06-28 81920]

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
                      nwiz.exe /install []

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002A]
                      C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE [2004-08-04 455168]

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002ASync]
                      C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE [2004-08-04 455168]

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PVR Agent]
                      C:\Program Files\CONCEPTRONIC Multimedia\PVR Plus\TVR\Scheduled.exe [2005-04-13 751104]

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
                      C:\Program Files\MpcStar\Codecs\QuickTime\QTSystem\qttask.exe -atboottime []

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
                      C:\WINDOWS\SOUNDMAN.EXE [2005-04-15 77824]

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
                      C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe []

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TomTomHOME.exe]
                      C:\Program Files\TomTom HOME 2\HOMERunner.exe [2008-05-06 202088]

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WengoPhoneNG]
                      C:\Program Files\WengoPhone\qtwengophone.exe -b []

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Win2DS]
                      C:\Documents and Settings\Moi\Bureau\ds\Win2DS.exe []

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
                      C:\Program Files\Winamp\winampa.exe []

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^HP Digital Imaging Monitor.lnk]
                      C:\PROGRA~1\HP\DIGITA~1\bin\hpqtra08.exe [2005-05-11 282624]

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Microsoft Office.lnk]
                      C:\PROGRA~1\MICROS~2\Office\OSA9.EXE [1999-02-17 65588]

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Remote Control.lnk]
                      C:\PROGRA~1\CONCEP~1\CTVFMI~1\P3XRCtl.exe []

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Moi^Menu Démarrer^Programmes^Démarrage^Adobe Gamma.lnk]
                      C:\PROGRA~1\FICHIE~1\Adobe\CALIBR~1\ADOBEG~1.EXE []

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Moi^Menu Démarrer^Programmes^Démarrage^OpenOffice.org 3.0.lnk]
                      C:\PROGRA~1\OPENOF~1.ORG\program\QUICKS~1.EXE [2008-09-12 384000]

                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Antiwpa]
                      C:\WINDOWS\system32\antiwpa.dll [2005-09-18 5376]

                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
                      C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 190464]

                      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]

                      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}]

                      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
                      "dontdisplaylastusername"=0
                      "legalnoticecaption"=
                      "legalnoticetext"=
                      "shutdownwithoutlogon"=1
                      "undockwithoutlogon"=1

                      [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
                      "NoDriveTypeAutoRun"=145

                      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
                      "HonorAutoRunSetting"=

                      [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
                      "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
                      "C:\Program Files\MSN Messenger\msnmsgr.exe"="C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
                      "C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
                      "C:\Program Files\BitComet\BitComet.exe"="C:\Program Files\BitComet\BitComet.exe:*:Enabled:BitComet - a BitTorrent Client"
                      "C:\Program Files\Shareaza\Shareaza.exe"="C:\Program Files\Shareaza\Shareaza.exe:*:Enabled:Shareaza"
                      "C:\Program Files\LimeWire\LimeWire.exe"="C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire"
                      "C:\Program Files\Fichiers communs\mfteghfd\pulos397.exe"="C:\Program Files\Fichiers communs\mfteghfd\pulos397.exe:*:Enabled:applostwe56"
                      "C:\DOCUME~1\Moi\LOCALS~1\Temp\setup9845.exe"="C:\DOCUME~1\Moi\LOCALS~1\Temp\setup9845.exe:*:Enabled:applostwe56"
                      "C:\Program Files\Fichiers communs\yrujg2wn\ginder86.exe"="C:\Program Files\Fichiers communs\yrujg2wn\ginder86.exe:*:Enabled:b0tgh7678"
                      "C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
                      "C:\Program Files\iTunes\iTunes.exe"="C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes"
                      "C:\Program Files\Fichiers communs\Systems\WINSERV.exe"="C:\Program Files\Fichiers communs\Systems\WINSERV.exe:*:Enabled:WINSERV"
                      "C:\WINDOWS\System\winlogon.exe"="C:\WINDOWS\System\winlogon.exe:*:Enabled:ServicesA"
                      "C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\dytnbv.exe"="C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\dytnbv.exe:*:Enabled:ServicesA"

                      [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
                      "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
                      "C:\Program Files\MSN Messenger\msnmsgr.exe"="C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
                      "C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"

                      [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0e0c20ad-6f65-11dd-827b-0013d483fcd8}]
                      shell\AutoRun\command - F:\InstallTomTomHOME.exe

                      [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6fa9c0e4-4e92-11de-84b3-0013d483fcd8}]
                      shell\AutoRun\command - E:\SETUP.EXE
                      0
                      1. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
                        Aide pour le lien d'Adobe PDF Reader - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]

                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{39F7E362-828A-4B5A-BCAF-5B79BFDFEA60}]
                        BitComet Helper - C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll [2008-02-29 468280]

                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
                        Spybot-S&D IE Protection - C:\PROGRA~1\SPYBOT~1\SDHelper.dll []

                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]

                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
                        Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-05-01 35840]

                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
                        {8E718888-423F-11D2-876E-00A0C9082467} - &Radio - C:\WINDOWS\System32\msdxm.ocx [2004-08-20 848922]
                        {32099AAC-C132-4136-9E9A-4E364A424E17} - DAEMON Tools Toolbar - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll [2009-04-23 937416]

                        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
                        "XpDis0Conf"=C:\PROGRA~1\Belkin\BELKIN~1\Tool\WinXPDisableZeroConfigation.exe VEN_14E4&DEV_4320&SUBSYS_70011799 /d []
                        "avast!"=C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe [2009-02-05 81000]
                        "Athan"=C:\Program Files\Athan\Athan.exe [2008-08-18 1069056]
                        "NvCplDaemon"=C:\WINDOWS\System32\NvCpl.dll [2007-06-28 8466432]
                        "SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-05-01 148888]
                        "KernelFaultCheck"=C:\WINDOWS\system32\dumprep 0 -k []
                        "QuickTime Task"=C:\Program Files\MpcStar\Codecs\QuickTime\QTTask.exe -atboottime []
                        "iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2009-06-05 292136]

                        [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
                        "SpybotSD TeaTimer"=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2009-01-26 2144088]
                        "DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\daemon.exe [2009-04-23 691656]

                        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
                        C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-01-11 39792]

                        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcoholAutomount]
                        C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe /automount []

                        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AnyDVD]
                        C:\Program Files\SlySoft\AnyDVD\AnyDVDtray.exe []

                        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUSGamerOSD]
                        C:\Program Files\ASUS\GamerOSD\GamerOSD.exe [2007-07-12 380928]

                        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
                        C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe []

                        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CloneCDTray]
                        C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe [2006-09-28 57344]

                        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
                        C:\WINDOWS\System32\ctfmon.exe [2004-08-20 15360]

                        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Pro Agent]
                        C:\Program Files\DAEMON Tools Pro\DTProAgent.exe []

                        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools-1033]
                        C:\Program Files\D-Tools\daemon.exe -lang 1033 []

                        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
                        C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2005-05-11 49152]

                        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IDMan]
                        C:\Program Files\Internet Download Manager\IDMan.exe /onboot []

                        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMJPMIG8.1]
                        C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE [2004-08-04 208952]

                        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KON]
                        C:\PROGRA~1\KON\KON\KON.exe []

                        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
                        C:\Program Files\MSN Messenger\msnmsgr.exe [2007-01-19 5674352]

                        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSPY2002]
                        C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe [2004-08-04 59392]

                        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
                        C:\WINDOWS\system32\NeroCheck.exe [2001-07-09 155648]

                        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
                        C:\WINDOWS\System32\NvCpl.dll [2007-06-28 8466432]

                        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
                        C:\WINDOWS\System32\NvMcTray.dll [2007-06-28 81920]

                        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
                        nwiz.exe /install []

                        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002A]
                        C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE [2004-08-04 455168]

                        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002ASync]
                        C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE [2004-08-04 455168]

                        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PVR Agent]
                        C:\Program Files\CONCEPTRONIC Multimedia\PVR Plus\TVR\Scheduled.exe [2005-04-13 751104]

                        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
                        C:\Program Files\MpcStar\Codecs\QuickTime\QTSystem\qttask.exe -atboottime []

                        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
                        C:\WINDOWS\SOUNDMAN.EXE [2005-04-15 77824]

                        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
                        C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe []

                        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TomTomHOME.exe]
                        C:\Program Files\TomTom HOME 2\HOMERunner.exe [2008-05-06 202088]

                        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WengoPhoneNG]
                        C:\Program Files\WengoPhone\qtwengophone.exe -b []

                        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Win2DS]
                        C:\Documents and Settings\Moi\Bureau\ds\Win2DS.exe []

                        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
                        C:\Program Files\Winamp\winampa.exe []

                        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^HP Digital Imaging Monitor.lnk]
                        C:\PROGRA~1\HP\DIGITA~1\bin\hpqtra08.exe [2005-05-11 282624]

                        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Microsoft Office.lnk]
                        C:\PROGRA~1\MICROS~2\Office\OSA9.EXE [1999-02-17 65588]

                        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Remote Control.lnk]
                        C:\PROGRA~1\CONCEP~1\CTVFMI~1\P3XRCtl.exe []

                        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Moi^Menu Démarrer^Programmes^Démarrage^Adobe Gamma.lnk]
                        C:\PROGRA~1\FICHIE~1\Adobe\CALIBR~1\ADOBEG~1.EXE []

                        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Moi^Menu Démarrer^Programmes^Démarrage^OpenOffice.org 3.0.lnk]
                        C:\PROGRA~1\OPENOF~1.ORG\program\QUICKS~1.EXE [2008-09-12 384000]

                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Antiwpa]
                        C:\WINDOWS\system32\antiwpa.dll [2005-09-18 5376]

                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
                        C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 190464]

                        [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]

                        [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}]

                        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
                        "dontdisplaylastusername"=0
                        "legalnoticecaption"=
                        "legalnoticetext"=
                        "shutdownwithoutlogon"=1
                        "undockwithoutlogon"=1

                        [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
                        "NoDriveTypeAutoRun"=145

                        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
                        "HonorAutoRunSetting"=

                        [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
                        "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
                        "C:\Program Files\MSN Messenger\msnmsgr.exe"="C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
                        "C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
                        "C:\Program Files\BitComet\BitComet.exe"="C:\Program Files\BitComet\BitComet.exe:*:Enabled:BitComet - a BitTorrent Client"
                        "C:\Program Files\Shareaza\Shareaza.exe"="C:\Program Files\Shareaza\Shareaza.exe:*:Enabled:Shareaza"
                        "C:\Program Files\LimeWire\LimeWire.exe"="C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire"
                        "C:\Program Files\Fichiers communs\mfteghfd\pulos397.exe"="C:\Program Files\Fichiers communs\mfteghfd\pulos397.exe:*:Enabled:applostwe56"
                        "C:\DOCUME~1\Moi\LOCALS~1\Temp\setup9845.exe"="C:\DOCUME~1\Moi\LOCALS~1\Temp\setup9845.exe:*:Enabled:applostwe56"
                        "C:\Program Files\Fichiers communs\yrujg2wn\ginder86.exe"="C:\Program Files\Fichiers communs\yrujg2wn\ginder86.exe:*:Enabled:b0tgh7678"
                        "C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
                        "C:\Program Files\iTunes\iTunes.exe"="C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes"
                        "C:\Program Files\Fichiers communs\Systems\WINSERV.exe"="C:\Program Files\Fichiers communs\Systems\WINSERV.exe:*:Enabled:WINSERV"
                        "C:\WINDOWS\System\winlogon.exe"="C:\WINDOWS\System\winlogon.exe:*:Enabled:ServicesA"
                        "C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\dytnbv.exe"="C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\dytnbv.exe:*:Enabled:ServicesA"

                        [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
                        "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
                        "C:\Program Files\MSN Messenger\msnmsgr.exe"="C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
                        "C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"

                        [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0e0c20ad-6f65-11dd-827b-0013d483fcd8}]
                        shell\AutoRun\command - F:\InstallTomTomHOME.exe

                        [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6fa9c0e4-4e92-11de-84b3-0013d483fcd8}]
                        shell\AutoRun\command - E:\SETUP.EXE
                        0
                        1. Veuillez ne pas prendre en considération le post N°11. J'ai fait une erreur de manipulation.

                          ======List of files/folders created in the last 1 months======

                          2009-07-21 18:41:48 ----D---- C:\Program Files\trend micro
                          2009-07-17 15:04:29 ----D---- C:\rsit
                          2009-07-12 15:45:24 ----D---- C:\Documents and Settings\All Users\Application Data\BigFishGamesCache
                          2009-07-06 22:20:33 ----D---- C:\Program Files\TomTom DesktopSuite
                          2009-07-05 16:53:31 ----D---- C:\Documents and Settings\Moi\Application Data\Xfire
                          2009-07-05 16:53:23 ----D---- C:\Program Files\Xfire
                          2009-07-05 16:47:45 ----D---- C:\AeriaGames
                          2009-07-05 15:34:18 ----D---- C:\Program Files\DNA
                          2009-07-05 15:34:18 ----D---- C:\Documents and Settings\Moi\Application Data\DNA
                          2009-06-27 18:34:01 ----D---- C:\Program Files\Fichiers communs\Wise Installation Wizard

                          ======List of files/folders modified in the last 1 months======

                          2009-07-21 18:41:48 ----AD---- C:\Program Files
                          2009-07-21 18:41:35 ----AC---- C:\WINDOWS\ntbtlog.txt
                          2009-07-21 18:38:29 ----D---- C:\WINDOWS\system32\CatRoot2
                          2009-07-21 18:36:02 ----D---- C:\WINDOWS\Temp
                          2009-07-21 18:34:11 ----A---- C:\WINDOWS\NeroDigital.ini
                          2009-07-21 18:32:34 ----D---- C:\Program Files\Mozilla Firefox
                          2009-07-21 18:30:32 ----AD---- C:\WINDOWS
                          2009-07-21 18:29:29 ----D---- C:\Documents and Settings
                          2009-07-21 16:50:31 ----D---- C:\WINDOWS\Prefetch
                          2009-07-14 23:53:55 ----D---- C:\WINDOWS\system32\drivers
                          2009-07-14 14:33:43 ----D---- C:\WINDOWS\Minidump
                          2009-07-13 00:00:00 ----A---- C:\WINDOWS\SchedLgU.Txt
                          2009-07-10 14:32:21 ----D---- C:\WINDOWS\system32
                          2009-07-07 13:31:14 ----A---- C:\WINDOWS\win.ini
                          2009-07-06 22:21:13 ----D---- C:\Program Files\TomTom HOME 2
                          2009-07-06 15:54:12 ----D---- C:\Documents and Settings\Moi\Application Data\LimeWire
                          2009-07-05 16:47:44 ----HD---- C:\Program Files\InstallShield Installation Information
                          2009-07-02 14:55:13 ----D---- C:\Downloads
                          2009-06-27 18:34:01 ----D---- C:\Program Files\Fichiers communs
                          2009-06-26 14:54:59 ----D---- C:\Program Files\iPod
                          2009-06-26 14:54:47 ----D---- C:\Program Files\Bonjour
                          2009-06-23 15:50:11 ----D---- C:\Program Files\Adobe
                          2009-06-23 15:43:47 ----D---- C:\Program Files\Java
                          2009-06-23 15:43:17 ----D---- C:\Program Files\MpcStar
                          2009-06-23 13:30:44 ----D---- C:\Documents and Settings\Moi\Application Data\DAEMON Tools Pro

                          ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

                          R1 kbdhid;Pilote HID de clavier; C:\WINDOWS\System32\DRIVERS\kbdhid.sys [2004-08-20 14848]
                          R3 ElbyCDFL;ElbyCDFL; C:\WINDOWS\System32\Drivers\ElbyCDFL.sys [2007-02-16 34760]
                          R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys [2009-03-19 23400]
                          R3 hidusb;Pilote de classe HID Microsoft; C:\WINDOWS\System32\DRIVERS\hidusb.sys [2001-09-28 9600]
                          R3 mouhid;Pilote HID de souris; C:\WINDOWS\System32\DRIVERS\mouhid.sys [2001-09-28 12288]
                          R3 MTsensor;ATK0110 ACPI UTILITY; C:\WINDOWS\System32\DRIVERS\ASACPI.sys [2004-08-13 5810]
                          R3 usbccgp;Pilote parent générique USB Microsoft; C:\WINDOWS\System32\DRIVERS\usbccgp.sys [2004-08-04 31616]
                          R3 usbhub;Concentrateur USB2; C:\WINDOWS\System32\DRIVERS\usbhub.sys [2004-08-04 57600]
                          R3 usbohci;Pilote miniport de contrôleur hôte ouvert USB Microsoft; C:\WINDOWS\System32\DRIVERS\usbohci.sys [2004-08-04 17024]
                          S1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2009-02-05 26944]
                          S1 asuskbnt;Enhanced Display Driver Helper Service; C:\WINDOWS\system32\drivers\atkkbnt.sys [2007-07-12 11136]
                          S1 aswSP;avast! Self Protection; C:\WINDOWS\system32\drivers\aswSP.sys [2009-02-05 114768]
                          S1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2009-02-05 51376]
                          S1 EIO;EIO; \??\C:\WINDOWS\system32\drivers\EIO.sys []
                          S1 ElbyCDIO;ElbyCDIO Driver; C:\WINDOWS\System32\Drivers\ElbyCDIO.sys [2007-08-07 25160]
                          S1 StarOpen;StarOpen; C:\WINDOWS\system32\drivers\StarOpen.sys [2006-07-24 5632]
                          S2 aswMon2;avast! Standard Shield Support; C:\WINDOWS\system32\drivers\aswMon2.sys [2009-02-05 94032]
                          S3 a2kas9un;a2kas9un; C:\WINDOWS\system32\drivers\a2kas9un.sys []
                          S3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2005-04-19 2317504]
                          S3 asusgsb;ASUS Virtual Video Capture Device Driver; C:\WINDOWS\system32\drivers\asusgsb.sys [2007-07-12 12416]
                          S3 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2009-02-05 23152]
                          S3 BCM43XX;Pilote pour carte réseau BCM 802.11b; C:\WINDOWS\System32\DRIVERS\bcmwl5.sys []
                          S3 Cap713x;Philips Cap713x Video Capture; C:\WINDOWS\System32\DRIVERS\Cap713x.sys [2005-10-04 686080]
                          S3 CCDECODE;Décodeur sous-titre fermé; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [2004-08-04 17024]
                          S3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\System32\DRIVERS\HPZid412.sys [2005-03-08 51120]
                          S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\System32\DRIVERS\HPZipr12.sys [2005-03-08 16496]
                          S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\System32\DRIVERS\HPZius12.sys [2005-03-08 21744]
                          S3 ms_mpu401;Pilote UART MIDI MPU-401 Microsoft; C:\WINDOWS\system32\drivers\msmpu401.sys [2001-08-17 2944]
                          S3 MSTEE;Convertisseur en T/site-à-site de répartition Microsoft; C:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-04 5504]
                          S3 NABTSFEC;Codec NABTS/FEC VBI; C:\WINDOWS\System32\DRIVERS\NABTSFEC.sys [2004-08-04 85376]
                          S3 NdisIP;Connection TV/vidéo Microsoft; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [2004-08-04 10880]
                          S3 nv;nv; C:\WINDOWS\System32\DRIVERS\nv4_mini.sys [2007-06-28 6807328]
                          S3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\WINDOWS\System32\DRIVERS\NVENETFD.sys [2005-04-05 33536]
                          S3 nvnetbus;NVIDIA Network Bus Enumerator; C:\WINDOWS\System32\DRIVERS\nvnetbus.sys [2005-04-05 12928]
                          S3 pcouffin;VSO Software pcouffin; C:\WINDOWS\System32\Drivers\pcouffin.sys [2009-02-17 47360]
                          S3 SLIP;Détrameur décalage BDA; C:\WINDOWS\System32\DRIVERS\SLIP.sys [2004-08-04 11136]
                          S3 ss_bus;SAMSUNG Mobile USB Device 1.0 driver (WDM); C:\WINDOWS\System32\DRIVERS\ss_bus.sys [2005-08-30 58320]
                          S3 ss_mdfl;SAMSUNG Mobile USB Modem 1.0 Filter; C:\WINDOWS\System32\DRIVERS\ss_mdfl.sys [2005-08-30 8304]
                          S3 ss_mdm;SAMSUNG Mobile USB Modem 1.0 Drivers; C:\WINDOWS\System32\DRIVERS\ss_mdm.sys [2005-08-30 94000]
                          S3 streamip;BDA IPSink; C:\WINDOWS\System32\DRIVERS\StreamIP.sys [2004-08-04 15360]
                          S3 TotRec7;Total Recorder WDM audio driver; C:\WINDOWS\system32\drivers\TotRec7.sys [2009-03-02 127496]
                          S3 USBAAPL;Apple Mobile USB Driver; C:\WINDOWS\System32\Drivers\usbaapl.sys [2009-06-05 39424]
                          S3 usbprint;Classe d'imprimantes USB Microsoft; C:\WINDOWS\System32\DRIVERS\usbprint.sys [2004-08-04 25856]
                          S3 usbscan;Pilote de scanneur USB; C:\WINDOWS\System32\DRIVERS\usbscan.sys [2004-08-04 15104]
                          S3 USBSTOR;Pilote de stockage de masse USB; C:\WINDOWS\System32\DRIVERS\USBSTOR.SYS [2004-08-04 26496]
                          S3 Video3D;ASUS Video3D Service; C:\WINDOWS\System32\Drivers\Video3D32.sys [2007-07-12 10752]
                          S3 WSTCODEC;Codec Teletext standard; C:\WINDOWS\System32\DRIVERS\WSTCODEC.SYS [2004-08-04 19328]
                          S3 XDva092;XDva092; \??\C:\WINDOWS\System32\XDva092.sys []
                          S3 XDva221;XDva221; \??\C:\WINDOWS\system32\XDva221.sys []
                          S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []

                          ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

                          S2 7truityui;8hut56u; C:\Program Files\Fichiers communs\yrujg2wn\ginder86.exe [2009-06-13 215066]
                          S2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2009-06-05 144712]
                          S2 aswUpdSv;avast! iAVS4 Control Service; C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe [2009-02-05 18752]
                          S2 ATKKeyboardService;ATK Keyboard Service; C:\WINDOWS\ATKKBService.exe [2007-07-12 257024]
                          S2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast4\ashServ.exe [2009-02-05 138680]
                          S2 Bonjour Service;Service Bonjour; C:\Program Files\Bonjour\mDNSResponder.exe [2008-12-12 238888]
                          S2 ForcewareWebInterface;Forceware Web Interface; C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe [2004-11-30 20543]
                          S2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-05-01 152984]
                          S2 nSvcLog;ForceWare user log service; C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe [2005-04-29 57412]
                          S2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\System32\nvsvc32.exe [2007-06-28 155716]
                          S2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\System32\HPZipm12.exe [2004-09-29 69632]
                          S2 ServicesZ;ServicesZ; C:\WINDOWS\System\winlogon.exe [2009-06-22 57856]
                          S2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\System32\wdfmgr.exe [2004-08-11 38912]
                          S3 Adobe LM Service;Adobe LM Service; C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe [2009-01-06 72704]
                          S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2005-09-23 29896]
                          S3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe [2009-02-05 254040]
                          S3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast4\ashWebSv.exe [2009-02-05 352920]
                          S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2005-09-23 66240]
                          S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2009-04-25 654848]
                          S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe [2005-11-14 69632]
                          S3 iPod Service;Service de l’iPod; C:\Program Files\iPod\bin\iPodService.exe [2009-06-05 541992]
                          S3 NMIndexingService;NMIndexingService; C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe []
                          S3 usnjsvc;Service Messenger Sharing Folders USN Journal Reader; C:\Program Files\MSN Messenger\usnsvc.exe [2007-01-19 97136]
                          S3 usprserv;User Privilege Service; C:\WINDOWS\System32\svchost.exe [2004-08-20 14336]

                          -----------------EOF-----------------
                          0
                          1. Voici le deuxième rapport ;)

                            info.txt logfile of random's system information tool 1.06 2009-07-21 18:41:51

                            ======Uninstall list======

                            -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
                            Adobe Acrobat and Reader 8.1.2 Security Update 1 (KB403742)-->MsiExec.exe /X{6846389C-BAC0-4374-808E-B120F86AF5D7}
                            Adobe Anchor Service CS3-->MsiExec.exe /I{90176341-0A8B-4CCC-A78D-F862228A6B95}
                            Adobe Asset Services CS3-->MsiExec.exe /I{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}
                            Adobe Bridge CS3-->MsiExec.exe /I{9C9824D9-9000-4373-A6A5-D0E5D4831394}
                            Adobe Bridge Start Meeting-->MsiExec.exe /I{08B32819-6EEF-4057-AEDA-5AB681A36A23}
                            Adobe Camera Raw 4.0-->MsiExec.exe /I{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}
                            Adobe CMaps-->MsiExec.exe /I{A2B242BD-FF8D-4840-9DAA-9170EABEC59C}
                            Adobe Color - Photoshop Specific-->MsiExec.exe /I{A2D81E70-2A98-4A08-A628-94388B063C5E}
                            Adobe Color Common Settings-->MsiExec.exe /I{DADD7B8A-BCB0-44F5-967A-ECB6B4F2ECD9}
                            Adobe Color EU Recommended Settings-->MsiExec.exe /I{73B5D990-04EA-4751-B10F-5534770B91F2}
                            Adobe Color JA Extra Settings-->MsiExec.exe /I{DD7DB3C5-6FA3-4FA3-8A71-C2F2940EB029}
                            Adobe Color NA Extra Settings-->MsiExec.exe /I{FF29A7E2-FF40-4D07-B7E4-2093DE59E10A}
                            Adobe Default Language CS3-->MsiExec.exe /I{B9B35331-B7E4-4E5C-BF4C-7BC87856124D}
                            Adobe Device Central CS3-->MsiExec.exe /I{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}
                            Adobe ExtendScript Toolkit 2-->MsiExec.exe /I{C2D69781-F392-4118-A5A7-C7E9C38DBFC2}
                            Adobe Flash Player 10 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
                            Adobe Flash Player 10 Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
                            Adobe Fonts All-->MsiExec.exe /I{6ABE0BEE-D572-4FE8-B434-9E72A289431B}
                            Adobe Help Viewer CS3-->MsiExec.exe /I{04AF207D-9A77-465A-8B76-991F6AB66245}
                            Adobe Linguistics CS3-->MsiExec.exe /I{54793AA1-5001-42F4-ABB6-C364617C6078}
                            Adobe PDF Library Files-->MsiExec.exe /I{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}
                            Adobe Photoshop CS3-->C:\Program Files\Fichiers communs\Adobe\Installers\32e9033392a51340b32fdc6ad893ab7\Setup.exe
                            Adobe Photoshop CS3-->MsiExec.exe /I{BF794769-8875-4E01-B7BE-E00104604F4A}
                            Adobe Reader 8.1.2 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A81200000003}
                            Adobe Setup-->MsiExec.exe /I{926DEB4E-2B0A-4C5C-AE4A-BF6C06949702}
                            Adobe Shockwave Player 11.5-->C:\WINDOWS\system32\Adobe\uninstaller.exe
                            Adobe Stock Photos CS3-->MsiExec.exe /I{29E5EA97-5F74-4A57-B8B2-D4F169117183}
                            Adobe Type Support-->MsiExec.exe /I{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}
                            Adobe Update Manager CS3-->MsiExec.exe /I{E69AE897-9E0B-485C-8552-7841F48D42D8}
                            Adobe Version Cue CS3 Client-->MsiExec.exe /I{D0DFF92A-492E-4C40-B862-A74A173C25C5}
                            Adobe WinSoft Linguistics Plugin-->MsiExec.exe /I{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}
                            Adobe XMP Panels CS3-->MsiExec.exe /I{802771A9-A856-4A41-ACF7-1450E523C923}
                            AnglaisFacile.com - Barre Verbes Irréguliers-->"C:\Program Files\AnglaisFacile.com\Barre Verbes Irréguliers\uninstall.exe"
                            Apple Mobile Device Support-->MsiExec.exe /I{8355F970-601D-442D-A79B-1D7DB4F24CAD}
                            Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
                            Archiveur WinRAR-->C:\Program Files\WinRAR\uninstall.exe
                            ASUS Gamer OSD-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{315ACD04-BCEB-478B-9B1D-5431D0E6CB11}\setup.exe" -l0x40c -removeonly
                            Athan Basic 3.4-->C:\WINDOWS\iun6002.exe "C:\Program Files\Athan\irunin.ini"
                            avast! Antivirus-->C:\Program Files\Alwil Software\Avast4\aswRunDll.exe "C:\Program Files\Alwil Software\Avast4\Setup\setiface.dll",RunSetup
                            BitComet 1.02-->C:\Program Files\BitComet\uninst.exe
                            Bonjour-->MsiExec.exe /I{07287123-B8AC-41CE-8346-3D777245C35B}
                            City Racing-->"C:\Program Files\GameTop.com\City Racing\unins000.exe"
                            CloneCD-->"C:\Program Files\SlySoft\CloneCD\ccd-uninst.exe" /D="C:\Program Files\SlySoft\CloneCD"
                            Codeur Windows Media Série 9-->msiexec.exe /I {E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}
                            Codeur Windows Media Série 9-->MsiExec.exe /I{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}
                            CONCEPTRONIC CTVFMi2 WDM Drivers-->C:\WINDOWS\p3xunist.exe
                            Correctif pour Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
                            DAEMON Tools Toolbar-->C:\Program Files\DAEMON Tools Toolbar\uninst.exe
                            Easy CD-DA Extractor 11-->"C:\WINDOWS\Easy CD-DA Extractor 11.5.3\uninstall.exe" "/U:C:\Program Files\Easy CD-DA Extractor 11\irunin.xml"
                            eXperience112-->C:\Program Files\InstallShield Installation Information\{3CF44BDE-BDDC-4510-A5CF-EBE97D1B8F73}\SETUP.EXE -runfromtemp -l0x040c -removeonly
                            HP Image Zone Express-->MsiExec.exe /X{FE64AE29-0883-4C70-8388-DC026019C900}
                            HP Imaging Device Functions 5.3-->C:\Program Files\HP\Digital Imaging\DigitalImagingMonitor\hpzscr01.exe -datfile hpqbud01.dat
                            HP PSC & OfficeJet 5.3.A-->"C:\Program Files\HP\Digital Imaging\{3E386744-10FA-44b2-98C9-DF7A270DECB3}\setup\hpzscr01.exe" -datfile hposcr06.dat
                            HP Software Update-->MsiExec.exe /X{15EE79F4-4ED1-4267-9B0F-351009325D7D}
                            HP Solution Center & Imaging Support Tools 5.3-->C:\Program Files\HP\Digital Imaging\eSupport\hpzscr01.exe -datfile hpqbud05.dat
                            iPhone/iTouch/iPod to Computer Transfer 3.9.2-->"C:\Program Files\Cucusoft\iPod to Computer\unins000.exe"
                            iTunes-->MsiExec.exe /I{5D601655-6D54-4384-B52C-17EC5385FBBD}
                            Java 2 Runtime Environment, SE v1.4.2_03-->MsiExec.exe /I{7148F0A8-6813-11D6-A77B-00B0D0142030}
                            Java(TM) 6 Update 13-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216013FF}
                            LimeWire 4.18.2-->"C:\Program Files\LimeWire\uninstall.exe"
                            Messenger Plus! Live-->"C:\Program Files\Messenger Plus! Live\Uninstall.exe"
                            Microsoft .NET Framework 2.0-->C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.exe
                            Microsoft Office 2000 Premium-->MsiExec.exe /I{0000040C-78E1-11D2-B60F-006097C998E7}
                            Mise à jour de sécurité pour le Codeur Windows Media (KB954156)-->"C:\WINDOWS\$NtUninstallKB954156_WM9L$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Lecteur Windows Media (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB901190)-->"C:\WINDOWS\$NtUninstallKB901190$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB923561)-->"C:\WINDOWS\$NtUninstallKB923561$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB923689)-->"C:\WINDOWS\$NtUninstallKB923689$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB938464-v2)-->"C:\WINDOWS\$NtUninstallKB938464-v2$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB944338-v2)-->"C:\WINDOWS\$NtUninstallKB944338-v2$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB950760)-->"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB952004)-->"C:\WINDOWS\$NtUninstallKB952004$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB954600)-->"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB956572)-->"C:\WINDOWS\$NtUninstallKB956572$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB956841)-->"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB958215)-->"C:\WINDOWS\$NtUninstallKB958215$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB958687)-->"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB958690)-->"C:\WINDOWS\$NtUninstallKB958690$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB959426)-->"C:\WINDOWS\$NtUninstallKB959426$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB960225)-->"C:\WINDOWS\$NtUninstallKB960225$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB960714)-->"C:\WINDOWS\$NtUninstallKB960714$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB960715)-->"C:\WINDOWS\$NtUninstallKB960715$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB960803)-->"C:\WINDOWS\$NtUninstallKB960803$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB961373)-->"C:\WINDOWS\$NtUninstallKB961373$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB961501)-->"C:\WINDOWS\$NtUninstallKB961501$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB963027)-->"C:\WINDOWS\$NtUninstallKB963027$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB968537)-->"C:\WINDOWS\$NtUninstallKB968537$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB969897)-->"C:\WINDOWS\$NtUninstallKB969897$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB969898)-->"C:\WINDOWS\$NtUninstallKB969898$\spuninst\spuninst.exe"
                            Mise à jour de sécurité pour Windows XP (KB970238)-->"C:\WINDOWS\$NtUninstallKB970238$\spuninst\spuninst.exe"
                            Mise à jour pour Windows XP (KB898461)-->"C:\WINDOWS\$NtUninstallKB898461$\spuninst\spuninst.exe"
                            Mise à jour pour Windows XP (KB955839)-->"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
                            Mise à jour pour Windows XP (KB967715)-->"C:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe"
                            Mozilla Firefox (3.0.11)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
                            MpcStar 3.8-->C:\Program Files\MpcStar\uninst.exe
                            MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
                            Nero 6 Ultra Edition-->C:\Program Files\Ahead\nero\uninstall\UNNERO.exe /UNINSTALL
                            neroxml-->MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B}
                            NVIDIA Drivers-->C:\WINDOWS\System32\NVUNINST.EXE UninstallGUI
                            NVIDIA ForceWare Network Access Manager-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe /M{1F6423DE-7959-4178-80E0-023C7EAA5347} /l1036
                            OpenOffice.org 3.0-->MsiExec.exe /I{6860B340-530D-46B3-91F8-1AE1F70F7C33}
                            PDF Settings-->MsiExec.exe /I{AC5B0C19-D851-42F4-BDA0-410ECF7F70A5}
                            PrintParade Studio-->C:\PROGRA~1\PRINTP~1\UNWISE.EXE C:\PROGRA~1\PRINTP~1\INSTALL.LOG
                            PVR Plus-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5B893587-00A8-4A4E-83F0-8AFA7BFC7C1A}\Setup.exe" -l0x40c
                            QuickTime-->MsiExec.exe /I{C78EAC6F-7A73-452E-8134-DBB2165C5A68}
                            Ragnarok-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{679DC0E1-E1F1-426A-9571-3B2720850787}\setup.exe" -l0x40c -removeonly
                            Realtek AC'97 Audio-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FB08F381-6533-4108-B7DD-039E11FBC27E}\setup.exe" REMOVE
                            Robin Hood-->"C:\WINDOWS\lsb_un20.exe" /C=UC /N=Robin Hood
                            SAMSUNG CDMA Modem Driver Set-->C:\WINDOWS\System32\Samsung_USB_Drivers\3\SSCDUninstall.exe
                            SAMSUNG Mobile Composite Device Software-->C:\WINDOWS\System32\Samsung_USB_Drivers\6\SSBCUninstall.exe
                            Samsung Mobile phone USB driver Software-->C:\WINDOWS\System32\Samsung_USB_Drivers\5\SSSDUninstall.exe
                            SAMSUNG Mobile USB Modem 1.0 Software-->C:\WINDOWS\System32\Samsung_USB_Drivers\1\SS_Uninstall.exe
                            SAMSUNG Mobile USB Modem Software-->C:\WINDOWS\System32\Samsung_USB_Drivers\2\SSM_Uninstall.exe
                            Samsung PC Studio 3-->"C:\Program Files\InstallShield Installation Information\{C4A4722E-79F9-417C-BD72-8D359A090C97}\setup.exe" -runfromtemp -l0x040c -removeonly
                            Shareaza 2.4.0.0-->"C:\Program Files\Shareaza\Uninstall\unins000.exe"
                            Spybot - Search & Destroy-->"C:\Program Files\Spybot - Search & Destroy\unins000.exe"
                            TeLL me More-->"C:\TELL ME MORE NV\BIN\unsetup.exe" -file "C:\TELL ME MORE NV\unsetup.aui"
                            Theme Hospital-->C:\WINDOWS\unin040c.exe -f"C:\Program Files\Bullfrog\Hospital\DeIsL1.isu"
                            TomTom HOME-->C:\Program Files\TomTom HOME 2\Uninstall TomTom HOME.exe
                            Total Recorder 7.1-->"C:\Program Files\HighCriteria\TotalRecorder\setup.exe" U
                            VC 9.0 Runtime-->MsiExec.exe /I{02E89EFC-7B07-4D5A-AA03-9EC0902914EE}
                            VC_MergeModuleToMSI-->MsiExec.exe /I{900A92BA-19EF-4A34-86CF-7B6C85BDD971}
                            VDownloader 0.82-->"C:\Program Files\VDOWNLOADER\unins000.exe"
                            Windows Installer 3.1 (KB893803)-->"C:\WINDOWS\$MSI31Uninstall_KB893803v2$\spuninst\spuninst.exe"
                            Windows Live Messenger-->MsiExec.exe /I{F6326B60-1B1D-4ABF-BFCD-7B7404F44411}
                            Windows Media Format Runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
                            Windows XP Service Pack 2-->C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe
                            Zylom Games Player Plugin-->"C:\Program Files\Zylom Games\UninstallPlugin.exe" --uninstall

                            ======Hosts File======

                            127.0.0.1 www.007guard.com
                            127.0.0.1 007guard.com
                            127.0.0.1 008i.com
                            127.0.0.1 www.008k.com
                            127.0.0.1 008k.com
                            127.0.0.1 www.00hq.com
                            127.0.0.1 00hq.com
                            127.0.0.1 010402.com
                            127.0.0.1 www.032439.com
                            127.0.0.1 032439.com

                            ======Security center information======

                            AV: avast! antivirus 4.8.1335 [VPS 090621-0]

                            ======System event log======

                            Computer Name: J-AD1BUO9JGE
                            Event Code: 6009
                            Message: Microsoft (R) Windows (R) 5.01. 2600 Service Pack 2 Uniprocessor Free.

                            Record Number: 5
                            Source Name: EventLog
                            Time Written: 20090710154642.000000+120
                            Event Type: Informations
                            User:

                            Computer Name: J-AD1BUO9JGE
                            Event Code: 2
                            Message: Device identified.

                            Record Number: 4
                            Source Name: nvata
                            Time Written: 20090710121821.000000+120
                            Event Type: Informations
                            User:

                            Computer Name: J-AD1BUO9JGE
                            Event Code: 2
                            Message: Device identified.

                            Record Number: 3
                            Source Name: nvata
                            Time Written: 20090710121821.000000+120
                            Event Type: Informations
                            User:

                            Computer Name: J-AD1BUO9JGE
                            Event Code: 6005
                            Message: Le service d'Enregistrement d'événement a démarré.

                            Record Number: 2
                            Source Name: EventLog
                            Time Written: 20090710121813.000000+120
                            Event Type: Informations
                            User:

                            Computer Name: J-AD1BUO9JGE
                            Event Code: 6009
                            Message: Microsoft (R) Windows (R) 5.01. 2600 Service Pack 2 Uniprocessor Free.

                            Record Number: 1
                            Source Name: EventLog
                            Time Written: 20090710121813.000000+120
                            Event Type: Informations
                            User:

                            =====Application event log=====

                            Computer Name: J-AD1BUO9JGE
                            Event Code: 101
                            Message: msnmsgr (944) Le moteur de base de données est arrêté.

                            Record Number: 1546
                            Source Name: ESENT
                            Time Written: 20090317183644.000000+060
                            Event Type: Informations
                            User:

                            Computer Name: J-AD1BUO9JGE
                            Event Code: 103
                            Message: msnmsgr (944) \\.\C:\Documents and Settings\Moi\Local Settings\Application Data\Microsoft\Messenger\petite_alimaj@hotmail.com\SharingMetadata\Working\database_474_23AB_7423_9E84\dfsr.db: Le moteur de base de données a arrêté une instance (0).

                            Record Number: 1545
                            Source Name: ESENT
                            Time Written: 20090317183644.000000+060
                            Event Type: Informations
                            User:

                            Computer Name: J-AD1BUO9JGE
                            Event Code: 102
                            Message: msnmsgr (944) \\.\C:\Documents and Settings\Moi\Local Settings\Application Data\Microsoft\Messenger\petite_alimaj@hotmail.com\SharingMetadata\Working\database_474_23AB_7423_9E84\dfsr.db: Le moteur de base de données a démarré une nouvelle instance (0).

                            Record Number: 1544
                            Source Name: ESENT
                            Time Written: 20090317183638.000000+060
                            Event Type: Informations
                            User:

                            Computer Name: J-AD1BUO9JGE
                            Event Code: 100
                            Message: msnmsgr (944) Le moteur de base de données 5.01.2600.2180 est démarré.

                            Record Number: 1543
                            Source Name: ESENT
                            Time Written: 20090317183638.000000+060
                            Event Type: Informations
                            User:

                            Computer Name: J-AD1BUO9JGE
                            Event Code: 101
                            Message: msnmsgr (3876) Le moteur de base de données est arrêté.

                            Record Number: 1542
                            Source Name: ESENT
                            Time Written: 20090317183637.000000+060
                            Event Type: Informations
                            User:

                            ======Environment variables======

                            "ComSpec"=%SystemRoot%\system32\cmd.exe
                            "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\Samsung\Samsung PC Studio 3\;C:\Program Files\Fichiers communs\Ulead Systems\MPEG;C:\Program Files\MpcStar\Codecs\QuickTime\QTSystem\
                            "windir"=%SystemRoot%
                            "OS"=Windows_NT
                            "PROCESSOR_ARCHITECTURE"=x86
                            "PROCESSOR_LEVEL"=15
                            "PROCESSOR_IDENTIFIER"=x86 Family 15 Model 47 Stepping 2, AuthenticAMD
                            "PROCESSOR_REVISION"=2f02
                            "NUMBER_OF_PROCESSORS"=1
                            "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
                            "TEMP"=%SystemRoot%\TEMP
                            "TMP"=%SystemRoot%\TEMP
                            "FP_NO_HOST_CHECK"=NO
                            "CLASSPATH"=.;C:\Program Files\Java\jre6\lib\ext\QTJava.zip
                            "QTJAVA"=C:\Program Files\Java\jre6\lib\ext\QTJava.zip
                            "SAFEBOOT_OPTION"=MINIMAL

                            -----------------EOF-----------------
                            0
                            1. Contributeur sécurité
                              bonjour

                              je comprends bien que le scan windows n'ai rien donné vu les trojans...

                              clic ici http://www.cijoint.fr/cj200907/cijUhATfHD.txt et suit les instructions qui sont dit,

                              je pense qu'parès cela tu devrais retrouver l'accés a ton poste de travail mais ce n'est pas fini.

                              telecharge hijackthis sur ton bureau https://www.01net.com/telecharger/windows/Securite/anti-spyware/fiches/29061.html

                              lance choisit do scan and save the log et poste le rapport

                              + un nouveau RSIT
                              0
                              1. J'ai lancé OTM, la première fois, avast à signaler un virus et puis il y a eu l'"écran bleu" et ça a redémarré mais je n'ai pas abandonner =P .J'ai relancé une 2 ème fois le programme et la ça a fonctionné mais j'ai vu pas mal de " Delete Failed " Soit, voici le rapport pour HiJackThis :


                                ________________________________________________________________________________________

                                Logfile of Trend Micro HijackThis v2.0.2
                                Scan saved at 23:43:48, on 21/07/2009
                                Platform: Windows XP SP2 (WinNT 5.01.2600)
                                MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                                Boot mode: Safe mode

                                Running processes:
                                C:\WINDOWS\System32\smss.exe
                                C:\WINDOWS\system32\winlogon.exe
                                C:\WINDOWS\system32\services.exe
                                C:\WINDOWS\system32\lsass.exe
                                C:\WINDOWS\system32\svchost.exe
                                C:\WINDOWS\system32\svchost.exe
                                C:\WINDOWS\system32\userinit.exe
                                C:\WINDOWS\Explorer.EXE
                                C:\Documents and Settings\Moi\Bureau\HiJackThis.exe

                                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.be/?gws_rd=ssl
                                R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                                R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                                R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                                O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                                O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll
                                O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll (file missing)
                                O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                                O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                                O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
                                O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll (file missing)
                                O4 - HKLM\..\Run: [XpDis0Conf] C:\PROGRA~1\Belkin\BELKIN~1\Tool\WinXPDisableZeroConfigation.exe VEN_14E4&DEV_4320&SUBSYS_70011799 /d
                                O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                                O4 - HKLM\..\Run: [Athan] C:\Program Files\Athan\Athan.exe
                                O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
                                O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe
                                O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
                                O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\MpcStar\Codecs\QuickTime\QTTask.exe" -atboottime
                                O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                                O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                                O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
                                O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                                O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
                                O4 - HKUS\S-1-5-18\..\Run: [mconfig] C:\Windows\security\Database\mconfig.exe (User 'SYSTEM')
                                O4 - HKUS\S-1-5-18\..\Run: [ja.exe] C:\Users\\AppData\Local\Microsoft\Windows\Explorer\ja.exe (User 'SYSTEM')
                                O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
                                O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
                                O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
                                O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
                                O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                                O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                                O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll/206 (file missing)
                                O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll (file missing)
                                O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll (file missing)
                                O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
                                O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
                                O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
                                O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
                                O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
                                O16 - DPF: {CAC677B6-4963-4305-9066-0BD135CD9233} (IPSUploader4 Control) - https://asp.photoprintit.de/microsite/12188/defaults/activex/ips/IPSUploader4.cab
                                O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://jeuxmultijoueurs.orange.fr/Gameshell/GameHost/1.0/OberonGameHost.cab
                                O18 - Filter hijack: text/html - {C6F62B7A-5450-4A2F-8687-6CEEC3AEB055} - C:\WINDOWS\System32\controlkids2.dll
                                O20 - Winlogon Notify: Antiwpa - antiwpa.dll (file missing)
                                O23 - Service: 8hut56u (7truityui) - - C:\Program Files\Fichiers communs\yrujg2wn\ginder86.exe
                                O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
                                O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
                                O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                                O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                                O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                                O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
                                O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
                                O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
                                O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                                O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
                                O23 - Service: NMIndexingService - Unknown owner - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe (file missing)
                                O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
                                O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
                                O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
                                O23 - Service: ServicesZ - Unknown owner - C:\WINDOWS\System\winlogon.exe (file missing)
                                0
                                1. Alléluia j'arrive à accéder à mon Poste de Travail ! x') Merci beaucoup

                                  Premier rapport RSIT :


                                  __________________________________________________________________________________________

                                  Logfile of random's system information tool 1.06 (written by random/random)
                                  Run by Moi at 2009-07-22 00:09:00
                                  Microsoft Windows XP Professionnel Service Pack 2
                                  System drive C: has 24 GB (19%) free of 131 GB
                                  Total RAM: 1535 MB (82% free)

                                  Logfile of Trend Micro HijackThis v2.0.2
                                  Scan saved at 0:09:08, on 22/07/2009
                                  Platform: Windows XP SP2 (WinNT 5.01.2600)
                                  MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                                  Boot mode: Safe mode

                                  Running processes:
                                  C:\WINDOWS\System32\smss.exe
                                  C:\WINDOWS\system32\winlogon.exe
                                  C:\WINDOWS\system32\services.exe
                                  C:\WINDOWS\system32\lsass.exe
                                  C:\WINDOWS\system32\svchost.exe
                                  C:\WINDOWS\system32\svchost.exe
                                  C:\WINDOWS\Explorer.EXE
                                  C:\Documents and Settings\Moi\Bureau\Téléchargement\RSIT.exe
                                  C:\Documents and Settings\Moi\Bureau\Moi.exe

                                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.be/?gws_rd=ssl
                                  R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                                  R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                                  O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                                  O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll
                                  O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll (file missing)
                                  O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                                  O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                                  O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
                                  O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll (file missing)
                                  O4 - HKLM\..\Run: [XpDis0Conf] C:\PROGRA~1\Belkin\BELKIN~1\Tool\WinXPDisableZeroConfigation.exe VEN_14E4&DEV_4320&SUBSYS_70011799 /d
                                  O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                                  O4 - HKLM\..\Run: [Athan] C:\Program Files\Athan\Athan.exe
                                  O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
                                  O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe
                                  O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
                                  O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\MpcStar\Codecs\QuickTime\QTTask.exe" -atboottime
                                  O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                                  O4 - HKLM\..\RunOnce: [OTM] "C:\Documents and Settings\Moi\Bureau\OTM.exe"
                                  O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                                  O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
                                  O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                                  O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
                                  O4 - HKUS\S-1-5-18\..\Run: [mconfig] C:\Windows\security\Database\mconfig.exe (User 'SYSTEM')
                                  O4 - HKUS\S-1-5-18\..\Run: [ja.exe] C:\Users\\AppData\Local\Microsoft\Windows\Explorer\ja.exe (User 'SYSTEM')
                                  O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
                                  O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
                                  O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
                                  O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
                                  O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                                  O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                                  O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll/206 (file missing)
                                  O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll (file missing)
                                  O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll (file missing)
                                  O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                  O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                  O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
                                  O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
                                  O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
                                  O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
                                  O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
                                  O16 - DPF: {CAC677B6-4963-4305-9066-0BD135CD9233} (IPSUploader4 Control) - https://asp.photoprintit.de/microsite/12188/defaults/activex/ips/IPSUploader4.cab
                                  O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://jeuxmultijoueurs.orange.fr/Gameshell/GameHost/1.0/OberonGameHost.cab
                                  O18 - Filter hijack: text/html - {C6F62B7A-5450-4A2F-8687-6CEEC3AEB055} - C:\WINDOWS\System32\controlkids2.dll
                                  O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
                                  O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                  O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                  O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
                                  O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                  O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                                  O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                                  O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                                  O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
                                  O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
                                  O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
                                  O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                                  O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
                                  O23 - Service: NMIndexingService - Unknown owner - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe (file missing)
                                  O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
                                  O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
                                  O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
                                  0
                                  1. Mmh... Pour ne pas rester bête ; Comment vous faites pour voir les trojans qui se trouve sur mon ordinateur ?

                                    Deuxième post...


                                    info.txt logfile of random's system information tool 1.06 2009-07-21 18:41:51

                                    ======Uninstall list======

                                    -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
                                    Adobe Acrobat and Reader 8.1.2 Security Update 1 (KB403742)-->MsiExec.exe /X{6846389C-BAC0-4374-808E-B120F86AF5D7}
                                    Adobe Anchor Service CS3-->MsiExec.exe /I{90176341-0A8B-4CCC-A78D-F862228A6B95}
                                    Adobe Asset Services CS3-->MsiExec.exe /I{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}
                                    Adobe Bridge CS3-->MsiExec.exe /I{9C9824D9-9000-4373-A6A5-D0E5D4831394}
                                    Adobe Bridge Start Meeting-->MsiExec.exe /I{08B32819-6EEF-4057-AEDA-5AB681A36A23}
                                    Adobe Camera Raw 4.0-->MsiExec.exe /I{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}
                                    Adobe CMaps-->MsiExec.exe /I{A2B242BD-FF8D-4840-9DAA-9170EABEC59C}
                                    Adobe Color - Photoshop Specific-->MsiExec.exe /I{A2D81E70-2A98-4A08-A628-94388B063C5E}
                                    Adobe Color Common Settings-->MsiExec.exe /I{DADD7B8A-BCB0-44F5-967A-ECB6B4F2ECD9}
                                    Adobe Color EU Recommended Settings-->MsiExec.exe /I{73B5D990-04EA-4751-B10F-5534770B91F2}
                                    Adobe Color JA Extra Settings-->MsiExec.exe /I{DD7DB3C5-6FA3-4FA3-8A71-C2F2940EB029}
                                    Adobe Color NA Extra Settings-->MsiExec.exe /I{FF29A7E2-FF40-4D07-B7E4-2093DE59E10A}
                                    Adobe Default Language CS3-->MsiExec.exe /I{B9B35331-B7E4-4E5C-BF4C-7BC87856124D}
                                    Adobe Device Central CS3-->MsiExec.exe /I{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}
                                    Adobe ExtendScript Toolkit 2-->MsiExec.exe /I{C2D69781-F392-4118-A5A7-C7E9C38DBFC2}
                                    Adobe Flash Player 10 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
                                    Adobe Flash Player 10 Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
                                    Adobe Fonts All-->MsiExec.exe /I{6ABE0BEE-D572-4FE8-B434-9E72A289431B}
                                    Adobe Help Viewer CS3-->MsiExec.exe /I{04AF207D-9A77-465A-8B76-991F6AB66245}
                                    Adobe Linguistics CS3-->MsiExec.exe /I{54793AA1-5001-42F4-ABB6-C364617C6078}
                                    Adobe PDF Library Files-->MsiExec.exe /I{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}
                                    Adobe Photoshop CS3-->C:\Program Files\Fichiers communs\Adobe\Installers\32e9033392a51340b32fdc6ad893ab7\Setup.exe
                                    Adobe Photoshop CS3-->MsiExec.exe /I{BF794769-8875-4E01-B7BE-E00104604F4A}
                                    Adobe Reader 8.1.2 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A81200000003}
                                    Adobe Setup-->MsiExec.exe /I{926DEB4E-2B0A-4C5C-AE4A-BF6C06949702}
                                    Adobe Shockwave Player 11.5-->C:\WINDOWS\system32\Adobe\uninstaller.exe
                                    Adobe Stock Photos CS3-->MsiExec.exe /I{29E5EA97-5F74-4A57-B8B2-D4F169117183}
                                    Adobe Type Support-->MsiExec.exe /I{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}
                                    Adobe Update Manager CS3-->MsiExec.exe /I{E69AE897-9E0B-485C-8552-7841F48D42D8}
                                    Adobe Version Cue CS3 Client-->MsiExec.exe /I{D0DFF92A-492E-4C40-B862-A74A173C25C5}
                                    Adobe WinSoft Linguistics Plugin-->MsiExec.exe /I{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}
                                    Adobe XMP Panels CS3-->MsiExec.exe /I{802771A9-A856-4A41-ACF7-1450E523C923}
                                    AnglaisFacile.com - Barre Verbes Irréguliers-->"C:\Program Files\AnglaisFacile.com\Barre Verbes Irréguliers\uninstall.exe"
                                    Apple Mobile Device Support-->MsiExec.exe /I{8355F970-601D-442D-A79B-1D7DB4F24CAD}
                                    Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
                                    Archiveur WinRAR-->C:\Program Files\WinRAR\uninstall.exe
                                    ASUS Gamer OSD-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{315ACD04-BCEB-478B-9B1D-5431D0E6CB11}\setup.exe" -l0x40c -removeonly
                                    Athan Basic 3.4-->C:\WINDOWS\iun6002.exe "C:\Program Files\Athan\irunin.ini"
                                    avast! Antivirus-->C:\Program Files\Alwil Software\Avast4\aswRunDll.exe "C:\Program Files\Alwil Software\Avast4\Setup\setiface.dll",RunSetup
                                    BitComet 1.02-->C:\Program Files\BitComet\uninst.exe
                                    Bonjour-->MsiExec.exe /I{07287123-B8AC-41CE-8346-3D777245C35B}
                                    City Racing-->"C:\Program Files\GameTop.com\City Racing\unins000.exe"
                                    CloneCD-->"C:\Program Files\SlySoft\CloneCD\ccd-uninst.exe" /D="C:\Program Files\SlySoft\CloneCD"
                                    Codeur Windows Media Série 9-->msiexec.exe /I {E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}
                                    Codeur Windows Media Série 9-->MsiExec.exe /I{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}
                                    CONCEPTRONIC CTVFMi2 WDM Drivers-->C:\WINDOWS\p3xunist.exe
                                    Correctif pour Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
                                    DAEMON Tools Toolbar-->C:\Program Files\DAEMON Tools Toolbar\uninst.exe
                                    Easy CD-DA Extractor 11-->"C:\WINDOWS\Easy CD-DA Extractor 11.5.3\uninstall.exe" "/U:C:\Program Files\Easy CD-DA Extractor 11\irunin.xml"
                                    eXperience112-->C:\Program Files\InstallShield Installation Information\{3CF44BDE-BDDC-4510-A5CF-EBE97D1B8F73}\SETUP.EXE -runfromtemp -l0x040c -removeonly
                                    HP Image Zone Express-->MsiExec.exe /X{FE64AE29-0883-4C70-8388-DC026019C900}
                                    HP Imaging Device Functions 5.3-->C:\Program Files\HP\Digital Imaging\DigitalImagingMonitor\hpzscr01.exe -datfile hpqbud01.dat
                                    HP PSC & OfficeJet 5.3.A-->"C:\Program Files\HP\Digital Imaging\{3E386744-10FA-44b2-98C9-DF7A270DECB3}\setup\hpzscr01.exe" -datfile hposcr06.dat
                                    HP Software Update-->MsiExec.exe /X{15EE79F4-4ED1-4267-9B0F-351009325D7D}
                                    HP Solution Center & Imaging Support Tools 5.3-->C:\Program Files\HP\Digital Imaging\eSupport\hpzscr01.exe -datfile hpqbud05.dat
                                    iPhone/iTouch/iPod to Computer Transfer 3.9.2-->"C:\Program Files\Cucusoft\iPod to Computer\unins000.exe"
                                    iTunes-->MsiExec.exe /I{5D601655-6D54-4384-B52C-17EC5385FBBD}
                                    Java 2 Runtime Environment, SE v1.4.2_03-->MsiExec.exe /I{7148F0A8-6813-11D6-A77B-00B0D0142030}
                                    Java(TM) 6 Update 13-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216013FF}
                                    LimeWire 4.18.2-->"C:\Program Files\LimeWire\uninstall.exe"
                                    Messenger Plus! Live-->"C:\Program Files\Messenger Plus! Live\Uninstall.exe"
                                    Microsoft .NET Framework 2.0-->C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.exe
                                    Microsoft Office 2000 Premium-->MsiExec.exe /I{0000040C-78E1-11D2-B60F-006097C998E7}
                                    Mise à jour de sécurité pour le Codeur Windows Media (KB954156)-->"C:\WINDOWS\$NtUninstallKB954156_WM9L$\spuninst\spuninst.exe"
                                    Mise à jour de sécurité pour Lecteur Windows Media (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
                                    Mise à jour de sécurité pour Windows XP (KB901190)-->"C:\WINDOWS\$NtUninstallKB901190$\spuninst\spuninst.exe"
                                    Mise à jour de sécurité pour Windows XP (KB923561)-->"C:\WINDOWS\$NtUninstallKB923561$\spuninst\spuninst.exe"
                                    Mise à jour de sécurité pour Windows XP (KB923689)-->"C:\WINDOWS\$NtUninstallKB923689$\spuninst\spuninst.exe"
                                    Mise à jour de sécurité pour Windows XP (KB938464-v2)-->"C:\WINDOWS\$NtUninstallKB938464-v2$\spuninst\spuninst.exe"
                                    Mise à jour de sécurité pour Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
                                    Mise à jour de sécurité pour Windows XP (KB944338-v2)-->"C:\WINDOWS\$NtUninstallKB944338-v2$\spuninst\spuninst.exe"
                                    Mise à jour de sécurité pour Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
                                    Mise à jour de sécurité pour Windows XP (KB950760)-->"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
                                    Mise à jour de sécurité pour Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
                                    Mise à jour de sécurité pour Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
                                    Mise à jour de sécurité pour Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
                                    Mise à jour de sécurité pour Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
                                    Mise à jour de sécurité pour Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
                                    Mise à jour de sécurité pour Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
                                    Mise à jour de sécurité pour Windows XP (KB952004)-->"C:\WINDOWS\$NtUninstallKB952004$\spuninst\spuninst.exe"
                                    Mise à jour de sécurité pour Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
                                    Mise à jour de sécurité pour Windows XP (KB954600)-->"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
                                    Mise à jour de sécurité pour Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
                                    Mise à jour de sécurité pour Windows XP (KB956572)-->"C:\WINDOWS\$NtUninstallKB956572$\spuninst\spuninst.exe"
                                    Mise à jour de sécurité pour Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
                                    Mise à jour de sécurité pour Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
                                    Mise à jour de sécurité pour Windows XP (KB956841)-->"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
                                    Mise à jour de sécurité pour Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
                                    Mise à jour de sécurité pour Windows XP (KB958215)-->"C:\WINDOWS\$NtUninstallKB958215$\spuninst\spuninst.exe"
                                    Mise à jour de sécurité pour Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
                                    Mise à jour de sécurité pour Windows XP (KB958687)-->"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
                                    Mise à jour de sécurité pour Windows XP (KB958690)-->"C:\WINDOWS\$NtUninstallKB958690$\spuninst\spuninst.exe"
                                    Mise à jour de sécurité pour Windows XP (KB959426)-->"C:\WINDOWS\$NtUninstallKB959426$\spuninst\spuninst.exe"
                                    Mise à jour de sécurité pour Windows XP (KB960225)-->"C:\WINDOWS\$NtUninstallKB960225$\spuninst\spuninst.exe"
                                    Mise à jour de sécurité pour Windows XP (KB960714)-->"C:\WINDOWS\$NtUninstallKB960714$\spuninst\spuninst.exe"
                                    Mise à jour de sécurité pour Windows XP (KB960715)-->"C:\WINDOWS\$NtUninstallKB960715$\spuninst\spuninst.exe"
                                    Mise à jour de sécurité pour Windows XP (KB960803)-->"C:\WINDOWS\$NtUninstallKB960803$\spuninst\spuninst.exe"
                                    Mise à jour de sécurité pour Windows XP (KB961373)-->"C:\WINDOWS\$NtUninstallKB961373$\spuninst\spuninst.exe"
                                    Mise à jour de sécurité pour Windows XP (KB961501)-->"C:\WINDOWS\$NtUninstallKB961501$\spuninst\spuninst.exe"
                                    Mise à jour de sécurité pour Windows XP (KB963027)-->"C:\WINDOWS\$NtUninstallKB963027$\spuninst\spuninst.exe"
                                    Mise à jour de sécurité pour Windows XP (KB968537)-->"C:\WINDOWS\$NtUninstallKB968537$\spuninst\spuninst.exe"
                                    Mise à jour de sécurité pour Windows XP (KB969897)-->"C:\WINDOWS\$NtUninstallKB969897$\spuninst\spuninst.exe"
                                    Mise à jour de sécurité pour Windows XP (KB969898)-->"C:\WINDOWS\$NtUninstallKB969898$\spuninst\spuninst.exe"
                                    Mise à jour de sécurité pour Windows XP (KB970238)-->"C:\WINDOWS\$NtUninstallKB970238$\spuninst\spuninst.exe"
                                    Mise à jour pour Windows XP (KB898461)-->"C:\WINDOWS\$NtUninstallKB898461$\spuninst\spuninst.exe"
                                    Mise à jour pour Windows XP (KB955839)-->"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
                                    Mise à jour pour Windows XP (KB967715)-->"C:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe"
                                    Mozilla Firefox (3.0.11)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
                                    MpcStar 3.8-->C:\Program Files\MpcStar\uninst.exe
                                    MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
                                    Nero 6 Ultra Edition-->C:\Program Files\Ahead\nero\uninstall\UNNERO.exe /UNINSTALL
                                    neroxml-->MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B}
                                    NVIDIA Drivers-->C:\WINDOWS\System32\NVUNINST.EXE UninstallGUI
                                    NVIDIA ForceWare Network Access Manager-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe /M{1F6423DE-7959-4178-80E0-023C7EAA5347} /l1036
                                    OpenOffice.org 3.0-->MsiExec.exe /I{6860B340-530D-46B3-91F8-1AE1F70F7C33}
                                    PDF Settings-->MsiExec.exe /I{AC5B0C19-D851-42F4-BDA0-410ECF7F70A5}
                                    PrintParade Studio-->C:\PROGRA~1\PRINTP~1\UNWISE.EXE C:\PROGRA~1\PRINTP~1\INSTALL.LOG
                                    PVR Plus-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5B893587-00A8-4A4E-83F0-8AFA7BFC7C1A}\Setup.exe" -l0x40c
                                    QuickTime-->MsiExec.exe /I{C78EAC6F-7A73-452E-8134-DBB2165C5A68}
                                    Ragnarok-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{679DC0E1-E1F1-426A-9571-3B2720850787}\setup.exe" -l0x40c -removeonly
                                    Realtek AC'97 Audio-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FB08F381-6533-4108-B7DD-039E11FBC27E}\setup.exe" REMOVE
                                    Robin Hood-->"C:\WINDOWS\lsb_un20.exe" /C=UC /N=Robin Hood
                                    SAMSUNG CDMA Modem Driver Set-->C:\WINDOWS\System32\Samsung_USB_Drivers\3\SSCDUninstall.exe
                                    SAMSUNG Mobile Composite Device Software-->C:\WINDOWS\System32\Samsung_USB_Drivers\6\SSBCUninstall.exe
                                    Samsung Mobile phone USB driver Software-->C:\WINDOWS\System32\Samsung_USB_Drivers\5\SSSDUninstall.exe
                                    SAMSUNG Mobile USB Modem 1.0 Software-->C:\WINDOWS\System32\Samsung_USB_Drivers\1\SS_Uninstall.exe
                                    SAMSUNG Mobile USB Modem Software-->C:\WINDOWS\System32\Samsung_USB_Drivers\2\SSM_Uninstall.exe
                                    Samsung PC Studio 3-->"C:\Program Files\InstallShield Installation Information\{C4A4722E-79F9-417C-BD72-8D359A090C97}\setup.exe" -runfromtemp -l0x040c -removeonly
                                    Shareaza 2.4.0.0-->"C:\Program Files\Shareaza\Uninstall\unins000.exe"
                                    Spybot - Search & Destroy-->"C:\Program Files\Spybot - Search & Destroy\unins000.exe"
                                    TeLL me More-->"C:\TELL ME MORE NV\BIN\unsetup.exe" -file "C:\TELL ME MORE NV\unsetup.aui"
                                    Theme Hospital-->C:\WINDOWS\unin040c.exe -f"C:\Program Files\Bullfrog\Hospital\DeIsL1.isu"
                                    TomTom HOME-->C:\Program Files\TomTom HOME 2\Uninstall TomTom HOME.exe
                                    Total Recorder 7.1-->"C:\Program Files\HighCriteria\TotalRecorder\setup.exe" U
                                    VC 9.0 Runtime-->MsiExec.exe /I{02E89EFC-7B07-4D5A-AA03-9EC0902914EE}
                                    VC_MergeModuleToMSI-->MsiExec.exe /I{900A92BA-19EF-4A34-86CF-7B6C85BDD971}
                                    VDownloader 0.82-->"C:\Program Files\VDOWNLOADER\unins000.exe"
                                    Windows Installer 3.1 (KB893803)-->"C:\WINDOWS\$MSI31Uninstall_KB893803v2$\spuninst\spuninst.exe"
                                    Windows Live Messenger-->MsiExec.exe /I{F6326B60-1B1D-4ABF-BFCD-7B7404F44411}
                                    Windows Media Format Runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
                                    Windows XP Service Pack 2-->C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe
                                    Zylom Games Player Plugin-->"C:\Program Files\Zylom Games\UninstallPlugin.exe" --uninstall

                                    ======Hosts File======

                                    127.0.0.1 www.007guard.com
                                    127.0.0.1 007guard.com
                                    127.0.0.1 008i.com
                                    127.0.0.1 www.008k.com
                                    127.0.0.1 008k.com
                                    127.0.0.1 www.00hq.com
                                    127.0.0.1 00hq.com
                                    127.0.0.1 010402.com
                                    127.0.0.1 www.032439.com
                                    127.0.0.1 032439.com

                                    ======Security center information======

                                    AV: avast! antivirus 4.8.1335 [VPS 090621-0]

                                    ======System event log======

                                    Computer Name: J-AD1BUO9JGE
                                    Event Code: 6009
                                    Message: Microsoft (R) Windows (R) 5.01. 2600 Service Pack 2 Uniprocessor Free.

                                    Record Number: 5
                                    Source Name: EventLog
                                    Time Written: 20090710154642.000000+120
                                    Event Type: Informations
                                    User:

                                    Computer Name: J-AD1BUO9JGE
                                    Event Code: 2
                                    Message: Device identified.

                                    Record Number: 4
                                    Source Name: nvata
                                    Time Written: 20090710121821.000000+120
                                    Event Type: Informations
                                    User:

                                    Computer Name: J-AD1BUO9JGE
                                    Event Code: 2
                                    Message: Device identified.

                                    Record Number: 3
                                    Source Name: nvata
                                    Time Written: 20090710121821.000000+120
                                    Event Type: Informations
                                    User:

                                    Computer Name: J-AD1BUO9JGE
                                    Event Code: 6005
                                    Message: Le service d'Enregistrement d'événement a démarré.

                                    Record Number: 2
                                    Source Name: EventLog
                                    Time Written: 20090710121813.000000+120
                                    Event Type: Informations
                                    User:

                                    Computer Name: J-AD1BUO9JGE
                                    Event Code: 6009
                                    Message: Microsoft (R) Windows (R) 5.01. 2600 Service Pack 2 Uniprocessor Free.

                                    Record Number: 1
                                    Source Name: EventLog
                                    Time Written: 20090710121813.000000+120
                                    Event Type: Informations
                                    User:

                                    =====Application event log=====

                                    Computer Name: J-AD1BUO9JGE
                                    Event Code: 101
                                    Message: msnmsgr (944) Le moteur de base de données est arrêté.

                                    Record Number: 1546
                                    Source Name: ESENT
                                    Time Written: 20090317183644.000000+060
                                    Event Type: Informations
                                    User:

                                    Computer Name: J-AD1BUO9JGE
                                    Event Code: 103
                                    Message: msnmsgr (944) \\.\C:\Documents and Settings\Moi\Local Settings\Application Data\Microsoft\Messenger\petite_alimaj@hotmail.com\SharingMetadata\Working\database_474_23AB_7423_9E84\dfsr.db: Le moteur de base de données a arrêté une instance (0).

                                    Record Number: 1545
                                    Source Name: ESENT
                                    Time Written: 20090317183644.000000+060
                                    Event Type: Informations
                                    User:

                                    Computer Name: J-AD1BUO9JGE
                                    Event Code: 102
                                    Message: msnmsgr (944) \\.\C:\Documents and Settings\Moi\Local Settings\Application Data\Microsoft\Messenger\adresse-email@hotmail.com\SharingMetadata\Working\database_474_23AB_7423_9E84\dfsr.db: Le moteur de base de données a démarré une nouvelle instance (0).

                                    Record Number: 1544
                                    Source Name: ESENT
                                    Time Written: 20090317183638.000000+060
                                    Event Type: Informations
                                    User:

                                    Computer Name: J-AD1BUO9JGE
                                    Event Code: 100
                                    Message: msnmsgr (944) Le moteur de base de données 5.01.2600.2180 est démarré.

                                    Record Number: 1543
                                    Source Name: ESENT
                                    Time Written: 20090317183638.000000+060
                                    Event Type: Informations
                                    User:

                                    Computer Name: J-AD1BUO9JGE
                                    Event Code: 101
                                    Message: msnmsgr (3876) Le moteur de base de données est arrêté.

                                    Record Number: 1542
                                    Source Name: ESENT
                                    Time Written: 20090317183637.000000+060
                                    Event Type: Informations
                                    User:

                                    ======Environment variables======

                                    "ComSpec"=%SystemRoot%\system32\cmd.exe
                                    "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\Samsung\Samsung PC Studio 3\;C:\Program Files\Fichiers communs\Ulead Systems\MPEG;C:\Program Files\MpcStar\Codecs\QuickTime\QTSystem\
                                    "windir"=%SystemRoot%
                                    "OS"=Windows_NT
                                    "PROCESSOR_ARCHITECTURE"=x86
                                    "PROCESSOR_LEVEL"=15
                                    "PROCESSOR_IDENTIFIER"=x86 Family 15 Model 47 Stepping 2, AuthenticAMD
                                    "PROCESSOR_REVISION"=2f02
                                    "NUMBER_OF_PROCESSORS"=1
                                    "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
                                    "TEMP"=%SystemRoot%\TEMP
                                    "TMP"=%SystemRoot%\TEMP
                                    "FP_NO_HOST_CHECK"=NO
                                    "CLASSPATH"=.;C:\Program Files\Java\jre6\lib\ext\QTJava.zip
                                    "QTJAVA"=C:\Program Files\Java\jre6\lib\ext\QTJava.zip
                                    "SAFEBOOT_OPTION"=MINIMAL

                                    -----------------EOF-----------------
                                    0
                                    1. Contributeur sécurité
                                      salut

                                      Poste le rapport situé dans C:\_OTMoveIt\MovedFiles.
                                      0
                                      1. Contributeur sécurité
                                        re

                                        il en reste, par contre tu as pas redemarré ton PC après OTM c'est trés important c'est pour finir la suppression, on voit bien dans ton rapport que tu as fait RSIt juste après OTM SANS AVOIR REDEMARRE comem l'outils te l'as demandé...

                                        bref Poste le rapport situé dans C:\_OTMoveIt\MovedFiles.

                                        puis

                                        # Télécharge ToolbarSD (de Team IDN) sur ton Bureau

                                        https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/ToolBarSD.exe?attachauth=ANoY7cqJWPphpudyTqv7TRo5RQ3nm_Sx8JluVMO59X5E9cyE3j3LqKlmStIqiDqJdIgMJLi7MXn2nKVajQfoWuVvZZ2wIx_vkqO4k4P0K9jh-ra9jaKPXdZcoaVF2UqJZNH8ubL_42uIwh6f35xJ2GJMuzddVj2Qth1DgZ839lxEIFGkgWz3TdfvNMy-YtxfA3gqBUrj4U4LFeAPiWr3ClmjIP0t_Xs5PQ%3D%3D&attredirects=2

                                        # Lance l'installation du programme en exécutant le fichier téléchargé.

                                        # Double-clique maintenant sur le raccourci de Toolbar-S&D.

                                        # Sélectionne la langue souhaitée en tapant la lettre de ton choix puis en validant avec la touche Entrée.

                                        # Choisis maintenant l'option 1 (Recherche). Patiente jusqu'à la fin de la recherche.

                                        # Poste le rapport généré. (C:\TB.txt)

                                        puis

                                        * Telecharge UsbFix de C_XX & Chiquitine29

                                        http://sd-1.archive-host.com/membres/up/127028005715545653/UsbFix.exe

                                        * Lance l installation avec les parametres par default

                                        * Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) suceptible d'avoir été infectés sans les ouvrir

                                        * Double clic sur le raccourci UsbFix sur ton bureau
                                        * Choisi l'option 2 (suppression)
                                        * Laisse travailler l'outil
                                        * Ensuite post le rapport UsbFix.txt qui apparaîtra
                                        * Note : le rapport UsbFix.txt est sauvegardé a la racine du disque

                                        * Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
                                        Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
                                        Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus
                                        0
                                        1. All processes killed
                                          ========== PROCESSES ==========
                                          No active process named explorer.exe was found!
                                          ========== SERVICES/DRIVERS ==========

                                          Service\Driver ServicesZ deleted successfully.

                                          Service\Driver 7truityui deleted successfully.
                                          ========== FILES ==========
                                          File/Folder c:\program files\daemon tools toolbar not found.
                                          File/Folder c:\windows\system32\antiwpa.dll not found.
                                          File/Folder c:\windows\system\winlogon.exe not found.
                                          File move failed. C:\Program Files\Fichiers communs\yrujg2wn\ginder86.exe scheduled to be moved on reboot.
                                          ========== REGISTRY ==========
                                          Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Antiwpa\ deleted successfully.
                                          Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}\\C:\WINDOWS\System\winlogon.exe not found.
                                          Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersio­n\Explorer\Browser Helper Objects\{39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} not found.
                                          ========== COMMANDS ==========

                                          [EMPTYTEMP]

                                          User: Administrateur
                                          ->Temp folder emptied: 0 bytes
                                          ->Temporary Internet Files folder emptied: 33170 bytes

                                          User: All Users

                                          User: Invité
                                          ->Temp folder emptied: -1001657227 bytes
                                          ->Temporary Internet Files folder emptied: 12827879 bytes
                                          ->Java cache emptied: 2397944 bytes
                                          ->FireFox cache emptied: 128274730 bytes

                                          User: LocalService
                                          File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
                                          File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Historique\History.IE5\index.dat scheduled to be deleted on reboot.
                                          File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat scheduled to be deleted on reboot.
                                          ->Temp folder emptied: 65716 bytes
                                          File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
                                          ->Temporary Internet Files folder emptied: 67350 bytes

                                          User: Moi
                                          ->Temp folder emptied: 1013757578 bytes
                                          ->Temporary Internet Files folder emptied: 1899046 bytes
                                          ->Java cache emptied: 98872601 bytes
                                          ->FireFox cache emptied: 3490134 bytes

                                          User: NetworkService
                                          ->Temp folder emptied: 0 bytes
                                          ->Temporary Internet Files folder emptied: 33170 bytes

                                          %systemdrive% .tmp files removed: 0 bytes
                                          C:\WINDOWS\msdownld.tmp folder deleted successfully.
                                          File delete failed. C:\WINDOWS\SFED2C542.tmp scheduled to be deleted on reboot.
                                          %systemroot% .tmp files removed: 1119437 bytes
                                          %systemroot%\System32 .tmp files removed: 554496 bytes
                                          File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_5fc.dat scheduled to be deleted on reboot.
                                          Windows Temp folder emptied: 361582 bytes
                                          RecycleBin emptied: 3000232494 bytes

                                          Total Files Cleaned = -984,80 mb

                                          OTM by OldTimer - Version 3.0.0.5 log created on 07212009_231543
                                          0
                                          • 1
                                          • 2