Pc s eteind tout seul .infecté??

Résolu
Bonjour,
depuis hier mon pc s eteind tout seul ou bug quand je regarde un film et je suis obligé de l eteindre et de le rallumer
il ne faisait pas sa avant c est depuis hier seulement

pouvez vous m aider car peut etre je suis infecté?

merci
Configuration: Windows XP
Firefox 3.5.3

44 réponses

Résumé de la discussion

Problème rencontré: un PC équipé de Windows XP s’éteint ou plante systématiquement en regardant un film, apparition soudaine depuis hier et susceptible d’être lié à une infection ou à un conflit logiciel. Pour les solutions, les réponses privilégient l’analyse système et le nettoyage, avec des conseils pour supprimer des programmes potentiellement source d’instabilité et pour vérifier les mises à jour critiques. Parmi les recommandations, HijackThis et Malwarebytes sont proposés comme outils de diagnostic et de suppression, accompagnés d’un relevé des programmes installés et désinstallés afin d'aider à cibler les causes. D’autres éléments signalent que la liste extensive d’installations et de désinstallations peut refléter des restes d’installations et suggère de vérifier les pilotes graphiques et les codecs utilisés par le lecteur vidéo.

Bobot (l’IA à votre service)
  1. bonjour,
    on va regarder voir si ceci est un problème d'infection ou materiel :
    •Télécharge random's system information tool (RSIT) et enregistre le sur ton bureau.
    http://images.malwareremoval.com/random/RSIT.exe

    Tuto : https://forum.pcastuces.com/randoms_system_information_tool_rsit-f31s31.htm
    Double clique sur RSIT.exe pour lancer l'outil.
    Clique sur ' continue ' à l'écran Disclaimer.
    Si l'outil HIjackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera et tu devras accepter la licence.
    Une fois le scan fini, 2 rapports vont apparaître. Poste le contenu des 2 rapports séparément. Ils se trouvent sur c :
    (log.txt & info.txt)
    (CTRL+A Pour tout sélectionner, CTRL+C pour copier et CTRL+V pour coller)
    0
    1. Logfile of random's system information tool 1.06 (written by random/random)
      Run by mikavirg at 2009-10-25 16:35:11
      Microsoft Windows XP Édition familiale Service Pack 3
      System drive C: has 142 GB (60%) free of 238 GB
      Total RAM: 3053 MB (77% free)

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 16:35:22, on 25/10/2009
      Platform: Windows XP SP3 (WinNT 5.01.2600)
      MSIE: Internet Explorer v8.00 (8.00.6001.18702)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\Ati2evxx.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\Ati2evxx.exe
      C:\WINDOWS\System32\brsvc01a.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\WINDOWS\System32\brss01a.exe
      C:\Program Files\Avira\AntiVir Desktop\sched.exe
      C:\Program Files\Google\Update\1.2.183.7\GoogleCrashHandler.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\SimpleCenter\bin\win\sclauncher.exe
      C:\WINDOWS\Mixer.exe
      C:\Program Files\Multimedia Keyboard & Mouse Driver\V5\StartAutorun.exe
      C:\Program Files\Multimedia Keyboard & Mouse Driver\V5\KMConfig.exe
      C:\WINDOWS\system32\rundll32.exe
      C:\Program Files\Java\jre6\bin\jusched.exe
      C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe
      C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe
      C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
      C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
      C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
      C:\Program Files\lg_fwupdate\fwupdate.exe
      C:\Program Files\Microsoft ActiveSync\Wcescomm.exe
      C:\Program Files\Multimedia Keyboard & Mouse Driver\V5\KMProcess.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
      C:\Program Files\Logitech\GamePanel Software\Applets\LCDMedia.exe
      C:\Program Files\Logitech\GamePanel Software\Applets\LCDCountdown.exe
      C:\Program Files\Logitech\GamePanel Software\LCD Manager\Applets\LCDClock.exe
      C:\Program Files\Logitech\GamePanel Software\Applets\ColorOnly\LCDMovieViewer.exe
      C:\PROGRA~1\MICROS~3\rapimgr.exe
      C:\Program Files\Innovative Solutions\DriverMax\devices.exe
      C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe
      C:\PROGRA~1\Wanadoo\GestionnaireInternet.exe
      C:\PROGRA~1\Wanadoo\ComComp.exe
      C:\PROGRA~1\Wanadoo\Toaster.exe
      C:\PROGRA~1\Wanadoo\Inactivity.exe
      C:\PROGRA~1\Wanadoo\PollingModule.exe
      C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
      C:\Program Files\a-squared Free\a2service.exe
      C:\Program Files\Avira\AntiVir Desktop\avguard.exe
      C:\WINDOWS\System32\FTRTSVC.exe
      C:\Program Files\Java\jre6\bin\jqs.exe
      C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
      C:\WINDOWS\system32\IoctlSvc.exe
      C:\Program Files\CyberLink\Shared Files\RichVideo.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\wuauclt.exe
      C:\Documents and Settings\mikavirg\Bureau\RSIT.exe
      C:\Program Files\trend micro\mikavirg.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer fourni par Orange
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
      R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
      O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
      O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
      O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
      O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
      O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
      O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
      O4 - HKLM\..\Run: [sclauncher] C:\Program Files\SimpleCenter\bin\win\sclauncher.exe
      O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
      O4 - HKLM\..\Run: [KMConfig] "C:\Program Files\Multimedia Keyboard & Mouse Driver\V5\StartAutorun.exe" KMConfig.exe
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
      O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
      O4 - HKLM\..\Run: [CmPCIaudio] RunDll32 CMICNFG3.cpl,CMICtrlWnd
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
      O4 - HKLM\..\Run: [Launch LgDevAgt] "C:\Program Files\Logitech\GamePanel Software\LgDevAgt.exe"
      O4 - HKLM\..\Run: [Launch LCDMon] "C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe"
      O4 - HKLM\..\Run: [Launch LGDCore] "C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe" /SHOWHIDE
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
      O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe"
      O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
      O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
      O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
      O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\YouCam" UpdateWithCreateOnce "Software\CyberLink\YouCam\1.0"
      O4 - HKLM\..\Run: [LGODDFU] "C:\Program Files\lg_fwupdate\fwupdate.exe" blrun
      O4 - HKLM\..\Run: [UpdatePSTShortCut] "C:\Program Files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\DVD Suite" UpdateWithCreateOnce "Software\CyberLink\PowerStarter"
      O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\Wcescomm.exe"
      O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
      O4 - HKCU\..\Run: [DriverMax] "C:\Program Files\Innovative Solutions\DriverMax\devices.exe" -agent
      O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
      O4 - HKCU\..\Run: [DriverMax_RESTART] "C:\Program Files\Innovative Solutions\DriverMax\devices.exe" -RESTART
      O4 - Startup: RocketDock.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe
      O4 - Startup: TransBar.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\TransBar\TransBar.exe
      O8 - Extra context menu item: eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
      O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
      O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
      O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
      O9 - Extra button: Barre de recherche Encarta - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Fichiers communs\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
      O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O15 - Trusted Zone: http://asia.msi.com.tw
      O15 - Trusted Zone: http://global.msi.com.tw
      O15 - Trusted Zone: http://www.msi.com.tw
      O15 - Trusted Zone: https://applications-et-logiciels.orange.fr/
      O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
      O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
      O16 - DPF: {8167C273-DF59-4416-B647-C8BB2C7EE83E} (WebSDev Control) - http://liveupdate.msi.com.tw/autobios/LOnline/install.cab
      O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
      O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
      O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
      O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
      O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
      O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\System32\brsvc01a.exe
      O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
      O23 - Service: Service Google Update (gupdate1c9c66a5888689c) (gupdate1c9c66a5888689c) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
      O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
      O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
      O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
      O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe
      O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
      O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
      O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
      O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
      O23 - Service: Audio Service (STacSV) - Unknown owner - c:\docume~1\mikavirg\locals~1\temp\cdm\{4d309b13-24ad-4675-b823-bc8f7f389b43}\STacSV.exe (file missing)
      0
      1. info.txt logfile of random's system information tool 1.06 2009-10-25 16:35:30

        ======Uninstall list======

        -->C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
        -->C:\Program Files\Nero\Nero8\\nero\uninstall\UNNERO.exe /UNINSTALL
        -->C:\WINDOWS\UNNeroBackItUp.exe /UNINSTALL
        -->C:\WINDOWS\UNNeroMediaHome.exe /UNINSTALL
        -->C:\WINDOWS\UNNeroShowTime.exe /UNINSTALL
        -->C:\WINDOWS\UNNeroVision.exe /UNINSTALL
        -->C:\WINDOWS\UNRecode.exe /UNINSTALL
        -->MsiExec.exe /I{403EF592-953B-4794-BCEF-ECAB835C2095}
        -->MsiExec.exe /I{8A42F680-2DD6-11D4-9A8C-0040F6982C20}
        -->MsiExec.exe /I{A2529672-574A-4A99-86A5-C1770A0E31FE}
        -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
        Adobe Flash Player 10 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
        Adobe Flash Player 10 Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
        Adobe Reader 9.2 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A92000000001}
        adsl TV-->C:\Program Files\adslTV\Uninstal.exe
        Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
        Archiveur WinRAR-->C:\Program Files\WinRAR\uninstall.exe
        a-squared Free 4.5-->"C:\Program Files\a-squared Free\unins000.exe"
        Assistant de connexion Windows Live-->MsiExec.exe /I{D3116CC7-24DC-4CA3-9CE1-23FED836E9F2}
        ATI Display Driver-->rundll32 C:\WINDOWS\system32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
        AusLogics Disk Defrag-->"C:\Program Files\Auslogics\AusLogics Disk Defrag\unins000.exe"
        Avira AntiVir Personal - Free Antivirus-->C:\Program Files\Avira\AntiVir Desktop\setup.exe /REMOVE
        Berlin 1943 (v1.1)-->"C:\Program Files\Micro Application\Berlin 1943\unins000.exe"
        Brother MFL-Pro Suite-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BB9AC6BF-71B6-42A4-9689-C17D9F44E79A}\Setup.exe" -l0x40c Brunin03.dllBrunin03.dll
        CamfrogWEB Advanced ActiveX Plugin (remove only)-->"C:\Program Files\CFWebAdvancedU\Uninstall.exe"
        CAM-IN SUITE III-->C:\PROGRA~1\CAM-IN~1\UNWISE.EXE C:\PROGRA~1\CAM-IN~1\INSTALL.LOG
        Casse Briques Chinois-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{391334EE-AE29-4C80-A4EF-31648AE9FF85}\Setup.exe" -l0x40c
        CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
        CDex extraction audio-->"C:\Program Files\CDex_150\uninstall.exe"
        C-Media PCI Audio Device-->C:\WINDOWS\CmiPCIUninstall.exe C:\Program Files\C-Media PCI Audio Device#C-Media PCI Audio Device#C-Media PCI Audio Device#
        Codecs.fr v1.0-->C:\Program Files\Fr Codec\uninst.exe
        Correctif pour Lecteur Windows Media 11 (KB939683)-->"C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
        Correctif pour Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
        Correctif pour Windows XP (KB961118)-->"C:\WINDOWS\$NtUninstallKB961118$\spuninst\spuninst.exe"
        Correctif pour Windows XP (KB970653-v3)-->"C:\WINDOWS\$NtUninstallKB970653-v3$\spuninst\spuninst.exe"
        dBpoweramp Music Converter-->"C:\WINDOWS\system32\SpoonUninstall.exe" <uninstall>C:\WINDOWS\system32\SpoonUninstall-dBpoweramp Music Converter.dat
        DigitalCam Pro-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7E6E2EF6-AACA-431A-B824-049C394EA5F8}\Setup.exe"
        DivX Codec-->C:\Program Files\DivX\DivXCodecUninstall.exe /CODEC
        DivX Converter-->C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
        DivX Player-->C:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYER
        DivX Web Player-->C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
        DivxToDVD 0.5.2-->"C:\Program Files\vso\DivxToDVD\unins000.exe"
        Driver Detective-->MsiExec.exe /X{5721A8EA-A30F-4F66-9046-3F40C43AE1DC}
        DriverMax 5-->"C:\Program Files\Innovative Solutions\DriverMax\unins000.exe"
        eMule-->"C:\Program Files\eMule\Uninstall.exe"
        ENJOY Plus!-->"C:\Program Files\ENJOY Plus!\UnInstall.exe"
        Error Repair Professional 3.8.5-->"C:\Program Files\Error Repair Professional\unins000.exe"
        EVEREST Ultimate Edition v4.60-->"C:\Program Files\Lavalys\EVEREST Ultimate Edition\unins000.exe"
        Foxit Reader-->C:\Program Files\Foxit Software\Foxit Reader\Uninstall.exe
        Free Mp3 Wma Converter V 1.8.0-->"C:\Program Files\Free Audio Pack\unins000.exe"
        Gestionnaire Internet-->C:\PROGRA~1\Wanadoo\uninstall.exe
        Google Chrome-->"C:\Program Files\Google\Chrome\Application\3.0.195.27\Installer\setup.exe" --uninstall --system-level
        Google Update Helper-->MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
        High Definition Audio Driver Package - KB888111-->"C:\WINDOWS\$NtUninstallKB888111WXPSP2$\spuninst\spuninst.exe"
        HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
        Home Media Server 4.1.4.0067-->C:\Program Files\SimpleCenter\uninstall.exe
        Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
        Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
        Hotfix for Windows Media Format 11 SDK (KB929399)-->"C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
        Intel(R) Management Engine Interface-->C:\WINDOWS\system32\heciudlg.exe -uninstall
        Intel(R) Network Connections 14.6.7.0-->MsiExec.exe /i{CCC68887-6E07-4438-A035-7C22EFBDC15E} ARPREMOVE=1
        Java(TM) 6 Update 15-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216013FF}
        Java(TM) 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
        Kaspersky Online Scanner-->C:\WINDOWS\system32\KASPER~1\KASPER~1\kavuninstall.exe
        K-Lite Codec Pack 4.0.0 (Full)-->"C:\Program Files\K-Lite Codec Pack\unins000.exe"
        Le Maillon Faible-->C:\PROGRA~1\ACTIVI~1\LEMAIL~1\UNINST~1\UNINST~1.EXE C:\Program Files\Activision\Le Maillon Faible\uninstall\Le Maillon Faible.log
        Lecteur Windows Media 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
        LG CyberLink PowerBackup-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{ADD5DB49-72CF-11D8-9D75-000129760D75}\Setup.exe" -uninstall
        LG CyberLink PowerDVD 7.0-->"C:\Program Files\InstallShield Installation Information\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}\Setup.exe" -uninstall
        LG CyberLink PowerProducer-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B7A0CE06-068E-11D6-97FD-0050BACBF861}\Setup.exe" -uninstall
        LG CyberLink YouCam-->"C:\Program Files\InstallShield Installation Information\{01FB4998-33C4-4431-85ED-079E3EEFE75D}\Setup.exe" /z-uninstall
        LG CyberLink YouCam-->"C:\Program Files\InstallShield Installation Information\{01FB4998-33C4-4431-85ED-079E3EEFE75D}\Setup.exe" /z-uninstall
        LG MC USB Modem driver-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6059C682-4C5F-4106-8487-943E98225D3B}\setup.exe" -l0x40c -removeonly
        LG PC Suite II-->C:\Program Files\InstallShield Installation Information\{14DCD95A-EBA3-4BF0-B7EF-533852E99BE6}\setup.exe -runfromtemp -l0x040c -removeonly
        LG Power Tools-->"C:\Program Files\InstallShield Installation Information\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}\Setup.exe" /z-uninstall
        LG Power Tools-->"C:\Program Files\InstallShield Installation Information\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}\Setup.exe" /z-uninstall
        livebox-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{17342E3B-0818-4A6F-BFF8-99476605ADD6}\Setup.exe" -l0x40c
        Logitech GamePanel Software 3.01-->MsiExec.exe /X{9B5B156B-9A4B-48FB-AA59-47B221495A7B}
        Ma-Config.com-->MsiExec.exe /X{425FFD94-36BD-4933-881B-FE0B9DADF2B7}
        Magic Spheres v1.0-->"C:\Program Files\GameYard.com\Magic Spheres\unins000.exe"
        Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
        Messenger Plus! 3-->"C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /Remove
        Messenger Plus! Live-->"C:\Program Files\Messenger Plus! Live\Uninstall.exe"
        Microsoft .NET Framework 2.0 Service Pack 2-->MsiExec.exe /I{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}
        Microsoft .NET Framework 3.0 Service Pack 2-->MsiExec.exe /I{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}
        Microsoft .NET Framework 3.5 SP1-->C:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
        Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
        Microsoft ActiveSync-->MsiExec.exe /I{99052DB7-9592-4522-A558-5417BBAD48EE}
        Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
        Microsoft Encarta 2009 - Collection-->MsiExec.exe /I{09180081-2C94-4A67-8E55-8483C019C7D2}
        Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
        Microsoft Kernel-Mode Driver Framework Feature Pack 1.5-->"C:\WINDOWS\$NtUninstallWdf01005$\spuninst\spuninst.exe"
        Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
        Microsoft Office 97 Professional-->C:\Program Files\Microsoft Office\Office\Install\Acme.exe /w Off97Pro.STF
        Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
        Microsoft User-Mode Driver Framework Feature Pack 1.5-->"C:\WINDOWS\$NtUninstallWudf01005$\spuninst\spuninst.exe"
        Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053-->MsiExec.exe /X{770657D0-A123-3C07-8E44-1C83EC895118}
        Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
        Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148-->MsiExec.exe /X{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}
        Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17-->MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475}
        Microsoft Windows Media Video 9 VCM-->RunDll32 advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmv9vcm.inf, Uninstall
        Mise à jour automatique du Firmware pour ODD LG-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6179550A-3E7C-499E-BCC9-9E8113E0A285}\Setup.exe"
        Mise à jour critique pour Lecteur Windows Media 11 (KB959772)-->"C:\WINDOWS\$NtUninstallKB959772_WM11$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Lecteur Windows Media (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Lecteur Windows Media (KB954155)-->"C:\WINDOWS\$NtUninstallKB954155_WM9$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Lecteur Windows Media (KB968816)-->"C:\WINDOWS\$NtUninstallKB968816_WM9$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Lecteur Windows Media (KB973540)-->"C:\WINDOWS\$NtUninstallKB973540_WM9$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Lecteur Windows Media 11 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Lecteur Windows Media 11 (KB954154)-->"C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Lecteur Windows Media 8 (KB917734)-->"C:\WINDOWS\$NtUninstallKB917734_WMP8$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Lecteur Windows Media 9 (KB911565)-->"C:\WINDOWS\$NtUninstallKB911565$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB938127)-->"C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB950759)-->"C:\WINDOWS\ie7updates\KB950759-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB953838)-->"C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB956390)-->"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB958215)-->"C:\WINDOWS\ie7updates\KB958215-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB960714)-->"C:\WINDOWS\ie7updates\KB960714-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB961260)-->"C:\WINDOWS\ie7updates\KB961260-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB963027)-->"C:\WINDOWS\ie7updates\KB963027-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB969897)-->"C:\WINDOWS\ie7updates\KB969897-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB972260)-->"C:\WINDOWS\ie7updates\KB972260-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB974455)-->"C:\WINDOWS\ie7updates\KB974455-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 8 (KB971961)-->"C:\WINDOWS\ie8updates\KB971961-IE8\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 8 (KB974455)-->"C:\WINDOWS\ie8updates\KB974455-IE8\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB923561)-->"C:\WINDOWS\$NtUninstallKB923561$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB950759)-->"C:\WINDOWS\$NtUninstallKB950759$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB950760)-->"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB952004)-->"C:\WINDOWS\$NtUninstallKB952004$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB953839)-->"C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB954211)-->"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB954459)-->"C:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB954600)-->"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB956391)-->"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB956572)-->"C:\WINDOWS\$NtUninstallKB956572$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB956744)-->"C:\WINDOWS\$NtUninstallKB956744$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB956841)-->"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB956844)-->"C:\WINDOWS\$NtUninstallKB956844$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB957095)-->"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB958687)-->"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB958690)-->"C:\WINDOWS\$NtUninstallKB958690$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB958869)-->"C:\WINDOWS\$NtUninstallKB958869$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB959426)-->"C:\WINDOWS\$NtUninstallKB959426$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB960225)-->"C:\WINDOWS\$NtUninstallKB960225$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB960715)-->"C:\WINDOWS\$NtUninstallKB960715$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB960803)-->"C:\WINDOWS\$NtUninstallKB960803$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB960859)-->"C:\WINDOWS\$NtUninstallKB960859$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB961371)-->"C:\WINDOWS\$NtUninstallKB961371$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB961373)-->"C:\WINDOWS\$NtUninstallKB961373$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB961501)-->"C:\WINDOWS\$NtUninstallKB961501$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB968537)-->"C:\WINDOWS\$NtUninstallKB968537$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB969059)-->"C:\WINDOWS\$NtUninstallKB969059$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB969898)-->"C:\WINDOWS\$NtUninstallKB969898$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB970238)-->"C:\WINDOWS\$NtUninstallKB970238$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB971486)-->"C:\WINDOWS\$NtUninstallKB971486$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB971557)-->"C:\WINDOWS\$NtUninstallKB971557$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB971633)-->"C:\WINDOWS\$NtUninstallKB971633$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB971657)-->"C:\WINDOWS\$NtUninstallKB971657$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB971961)-->"C:\WINDOWS\$NtUninstallKB971961$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB973346)-->"C:\WINDOWS\$NtUninstallKB973346$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB973354)-->"C:\WINDOWS\$NtUninstallKB973354$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB973507)-->"C:\WINDOWS\$NtUninstallKB973507$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB973525)-->"C:\WINDOWS\$NtUninstallKB973525$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB973869)-->"C:\WINDOWS\$NtUninstallKB973869$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB974112)-->"C:\WINDOWS\$NtUninstallKB974112$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB974571)-->"C:\WINDOWS\$NtUninstallKB974571$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB975025)-->"C:\WINDOWS\$NtUninstallKB975025$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB975467)-->"C:\WINDOWS\$NtUninstallKB975467$\spuninst\spuninst.exe"
        Mise à jour pour Windows Internet Explorer 8 (KB973874)-->"C:\WINDOWS\ie8updates\KB973874-IE8\spuninst\spuninst.exe"
        Mise à jour pour Windows XP (KB942763)-->"C:\WINDOWS\$NtUninstallKB942763$\spuninst\spuninst.exe"
        Mise à jour pour Windows XP (KB951072-v2)-->"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
        Mise à jour pour Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
        Mise à jour pour Windows XP (KB955839)-->"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
        Mise à jour pour Windows XP (KB967715)-->"C:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe"
        Mise à jour pour Windows XP (KB968389)-->"C:\WINDOWS\$NtUninstallKB968389$\spuninst\spuninst.exe"
        Mise à jour pour Windows XP (KB973815)-->"C:\WINDOWS\$NtUninstallKB973815$\spuninst\spuninst.exe"
        Module de prise en charge linguistique de Microsoft .NET Framework 2.0 - FRA-->C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0 Language Pack - FRA\install.exe
        Mozilla Firefox (3.5.3)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
        MP3 Player Utilities 3.68-->MsiExec.exe /I{D98BFAD2-0C90-47F4-9D69-2EFF21631884}
        MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
        MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
        MSXML 6.0 Parser (KB933579)-->MsiExec.exe /I{0A869A65-8C94-4F7C-A5C7-972D3C8CED9E}
        Multimedia Keyboard & Mouse Driver-->C:\Program Files\InstallShield Installation Information\{055A9D81-5E0A-4088-94B3-BAC849EC3C20}\setup.exe -runfromtemp -l0x040c
        Navigateur Orange-->C:\PROGRA~1\Wanadoo\Shell.exe inst\uninst_FTBrowser.shl
        Nero - Burning Rom-->MsiExec.exe /X{A4D7B764-4140-11D4-88EB-0050DA3579C0}
        Nero 8-->MsiExec.exe /X{BE282C23-5484-47FF-B2C1-EBEA5C891036}
        neroxml-->MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B}
        Nokia Connectivity Cable Driver-->MsiExec.exe /X{C3F19A5F-35A8-4FDB-A6ED-0F4CE398DA48}
        Nokia Flashing Cable Driver-->MsiExec.exe /X{2A0A6470-FD0F-4F45-9B11-85F3167DB943}
        Nokia Lifeblog 2.5-->MsiExec.exe /I{E94603CA-2996-4154-8EE2-A5FCD4BFB500}
        Nokia NSeries Application Installer-->MsiExec.exe /I{FD349381-D79C-4E5C-8980-015DFFB962D5}
        Nokia NSeries Content Copier-->MsiExec.exe /X{F779EC8D-6703-4C4A-817C-37B07898E647}
        Nokia NSeries Multimedia Player-->MsiExec.exe /I{FA25FAF6-3097-43C9-BBB2-A77CE8AF1881}
        Nokia NSeries Music Manager-->MsiExec.exe /I{F89E5AD8-AE47-49B5-B9F9-C498791E6255}
        Nokia NSeries One Touch Access-->MsiExec.exe /I{F4EE8763-EAA8-4BC1-8594-8501F5F00414}
        Nokia NSeries System Utilities-->MsiExec.exe /X{96E94E18-54D6-42C1-8FC4-24DACEDC3395}
        Nokia Nseries Video Manager-->MsiExec.exe /X{2D21ECE3-8EC1-4315-AE4E-1970FB3AF17A}
        Nokia Software Launcher-->MsiExec.exe /I{A8C856AD-63CD-4613-AA29-E6C85607EA06}
        Nokia Software Updater-->MsiExec.exe /X{48110A46-A3A4-481E-8230-7873B7F4C696}
        NVIDIA Drivers-->C:\WINDOWS\system32\nvuninst.exe UninstallGUI
        OpenCV 3x-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{073D5DDE-B535-4859-A794-B2B4D933D983} /l1036
        OrangeInstaller version 1.0.0.0-->RunDll32 C:\WINDOWS\system32\advpack.dll,LaunchINFSection C:\WINDOWS\INF\OrangeInstaller_1.0.0.0.inf,DefaultUninstall
        Orban/Coding Technologies AAC/aacPlus Player Plugin™ 1.0-->"C:\Program Files\Orban\AAC-aacPlus Plugin\unins000.exe"
        Outil de mise à jour Google-->"C:\Program Files\Google\Google Updater\GoogleUpdater.exe" -uninstall
        Pack Vista Inspirat 2 1.0-->C:\WINDOWS\BricoPacks\Vista Inspirat 2\Remove.exe
        PaperPort-->MsiExec.exe /I{A17EABB6-D0C6-44E5-820C-72DC7F495064}
        PC Connectivity Solution-->MsiExec.exe /I{6094AB91-4CC8-498E-9DFF-134CC0B159DE}
        PCI Audio Driver-->cmuninst.exe
        PhotoFiltre-->"C:\Program Files\PhotoFiltre\Uninst.exe"
        QuickTime-->MsiExec.exe /I{C78EAC6F-7A73-452E-8134-DBB2165C5A68}
        REALTEK GbE & FE Ethernet PCI NIC Driver-->C:\Program Files\InstallShield Installation Information\{ACCA20B0-C4D1-4BF5-BF21-0A0EB5EF9730}\setup.exe -runfromtemp -l0x040c -removeonly
        Realtek High Definition Audio Driver-->RtlUpd.exe -r -m -nrg2709
        SigmaTel Audio-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A462213D-EED4-42C2-9A60-7BDD4D4B0B17}\setup.exe" -l0x40c -remove -removeonly
        Sony Ericsson Device Data-->MsiExec.exe /I{C92E7DF1-624A-4D95-A4C4-18CB491B44A4}
        Sony Ericsson Drivers-->MsiExec.exe /I{C60BA916-9E44-4DA4-B11A-9E27B7624EF5}
        Sony Ericsson PC Suite-->C:\WINDOWS\Installer\{D6BF6477-8369-489F-8DE6-3731F4B88560}\Setup.exe /uninstall
        Sony Ericsson PC Suite-->MsiExec.exe /I{25BEC3AB-5CD4-481D-9143-215C1BBB189E}
        SpeedFan (remove only)-->"C:\Program Files\SpeedFan\uninstall.exe"
        Spybot - Search & Destroy-->"C:\Program Files\Spybot - Search & Destroy\unins000.exe"
        SUPER © Version 2009.bld.36 (June 10, 2009)-->C:\PROGRA~1\ERIGHT~1\SUPER\Setup.exe /remove /q0
        Update for Microsoft .NET Framework 3.5 SP1 (KB963707)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {B2AE9C82-DC7B-3641-BFC8-87275C4F3607} /qb+ REBOOTPROMPT=""
        VCRedistSetup-->MsiExec.exe /I{3921A67A-5AB1-4E48-9444-C71814CF3027}
        Video Converter 3-->C:\Program Files\Xilisoft\Video Converter 3\Uninstall.exe
        VirginMega.Fr Premium-->MsiExec.exe /I{EE467474-04A8-48D5-8DDF-0F8D3A3CCBE5}
        Virtual Magnifying Glass-->"C:\Program Files\Virtual Magnifying Glass\uninstall.exe"
        Visionneuse Journal Windows Microsoft-->MsiExec.exe /X{43DCF766-6838-4F9A-8C91-D92DA586DFA8}
        VLC media player 0.9.8a-->C:\Program Files\adslTV\uninstall.exe
        VSO CopyToDVD 4-->"C:\Program Files\VSO\unins000.exe"
        Windows Driver Package - Nokia (WUDFRd) WPD (03/19/2007 6.83.31.1)-->C:\PROGRA~1\DIFX\D6ACC4BE676423A2B130B78A4B627FC457D98997\dpinst.exe /u C:\WINDOWS\system32\DRVSTORE\pccswpddri_039E7E24575DBAE6A389611AF28F4EB97729D33E\pccswpddriver.inf
        Windows Driver Package - Realtek Semiconductor Corp. HD Audio Driver (03/26/2007 5.10.0.5391)-->C:\PROGRA~1\DIFX\D6ACC4BE676423A2B130B78A4B627FC457D98997\DPInst.exe /u C:\WINDOWS\system32\DRVSTORE\hdart_C71723100C9B1362CA9E28BC0C6DB02E6CB8385E\hdart.inf
        Windows Internet Explorer 8-->"C:\WINDOWS\ie8\spuninst\spuninst.exe"
        Windows Live installer-->MsiExec.exe /X{FD44E544-E7D0-4DBA-9FA0-8AE1A1300390}
        Windows Live Messenger-->MsiExec.exe /X{BADF6744-3787-48F6-B8C9-4C4995401D65}
        Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
        Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
        Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
        Windows Media Player 9 Series TweakMP PowerToy-->RunDll32 advpack.dll,LaunchINFSection C:\WINDOWS\INF\tweakmp.inf,DefaultUninstall
        Windows Media Player Firefox Plugin-->MsiExec.exe /I{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}
        Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
        WinZip 12.1-->MsiExec.exe /X{CD95F661-A5C4-44F5-A6AA-ECDD91C240B8}
        XnView 1.96.2-->"C:\Program Files\XnView\unins000.exe"
        Yahoo! Install Manager-->C:\WINDOWS\System32\regsvr32 /u C:\PROGRA~1\Yahoo!\Common\YINSTH~1.DLL
        Yahoo! Toolbar avec bloqueur de fenêtres pop-up-->C:\PROGRA~1\Yahoo!\Common\unyt.exe

        ======Hosts File======

        127.0.0.1 www.007guard.com
        127.0.0.1 007guard.com
        127.0.0.1 008i.com
        127.0.0.1 www.008k.com
        127.0.0.1 008k.com
        127.0.0.1 www.00hq.com
        127.0.0.1 00hq.com
        127.0.0.1 010402.com
        127.0.0.1 www.032439.com
        127.0.0.1 032439.com

        ======Security center information======

        AV: AntiVir Desktop

        ======System event log======

        Computer Name: MIKAVIRG-AHB1UF
        Event Code: 7023
        Message: Le service Gestion d'applications s'est arrêté avec l'erreur :
        Le module spécifié est introuvable.

        Record Number: 35864
        Source Name: Service Control Manager
        Time Written: 20091014101526.000000+120
        Event Type: erreur
        User:

        Computer Name: MIKAVIRG-AHB1UF
        Event Code: 7036
        Message: Le service Gestion d'applications est entré dans l'état : arrêté.

        Record Number: 35863
        Source Name: Service Control Manager
        Time Written: 20091014101526.000000+120
        Event Type: Informations
        User:

        Computer Name: MIKAVIRG-AHB1UF
        Event Code: 7035
        Message: Un contrôle Démarrer a correctement été envoyé au service Gestion d'applications.

        Record Number: 35862
        Source Name: Service Control Manager
        Time Written: 20091014101525.000000+120
        Event Type: Informations
        User: MIKAVIRG-AHB1UF\mikavirg

        Computer Name: MIKAVIRG-AHB1UF
        Event Code: 7023
        Message: Le service Gestion d'applications s'est arrêté avec l'erreur :
        Le module spécifié est introuvable.

        Record Number: 35861
        Source Name: Service Control Manager
        Time Written: 20091014101525.000000+120
        Event Type: erreur
        User:

        Computer Name: MIKAVIRG-AHB1UF
        Event Code: 7036
        Message: Le service Gestion d'applications est entré dans l'état : arrêté.

        Record Number: 35860
        Source Name: Service Control Manager
        Time Written: 20091014101525.000000+120
        Event Type: Informations
        User:

        =====Application event log=====

        Computer Name: MIKAVIRG-AHB1UF
        Event Code: 0
        Message:
        Record Number: 2974
        Source Name: ServiceLayer
        Time Written: 20090710165449.000000+120
        Event Type: Informations
        User:

        Computer Name: MIKAVIRG-AHB1UF
        Event Code: 4096
        Message: Le service AntiVir a bien démarré!

        Record Number: 2973
        Source Name: Avira AntiVir
        Time Written: 20090710165436.000000+120
        Event Type: Informations
        User: AUTORITE NT\SYSTEM

        Computer Name: MIKAVIRG-AHB1UF
        Event Code: 1800
        Message: Le service Centre de sécurité Windows a démarré.

        Record Number: 2972
        Source Name: SecurityCenter
        Time Written: 20090710165436.000000+120
        Event Type: Informations
        User:

        Computer Name: MIKAVIRG-AHB1UF
        Event Code: 105
        Message: The service was started.

        Record Number: 2971
        Source Name: PLFlash DeviceIoControl Service
        Time Written: 20090710165435.000000+120
        Event Type: Informations
        User:

        Computer Name: MIKAVIRG-AHB1UF
        Event Code: 0
        Message:
        Record Number: 2970
        Source Name: Nero BackItUp Scheduler 3
        Time Written: 20090710165435.000000+120
        Event Type: Informations
        User:

        ======Environment variables======

        "ComSpec"=%SystemRoot%\system32\cmd.exe
        "Path"=%systemroot%\system32;%systemroot%;%systemroot%\system32\wbem;C:\Program Files\PC Connectivity Solution;C:\Program Files\QuickTime\QTSystem;C:\Program Files\Fichiers communs\Teleca Shared;C:\PROGRA~1\DISKEE~1\DISKEE~1;C:\Program Files\QuickTime\QTSystem\;C:\Program Files\Intel\DMIX
        "windir"=%SystemRoot%
        "OS"=Windows_NT
        "PROCESSOR_ARCHITECTURE"=x86
        "PROCESSOR_LEVEL"=6
        "PROCESSOR_IDENTIFIER"=x86 Family 6 Model 23 Stepping 10, GenuineIntel
        "PROCESSOR_REVISION"=170a
        "NUMBER_OF_PROCESSORS"=2
        "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
        "TEMP"=%SystemRoot%\TEMP
        "TMP"=%SystemRoot%\TEMP
        "FP_NO_HOST_CHECK"=NO
        "CLASSPATH"=.;C:\Program Files\Java\jre1.6.0_07\lib\ext\QTJava.zip
        "QTJAVA"=C:\Program Files\Java\jre1.6.0_07\lib\ext\QTJava.zip

        -----------------EOF-----------------
        0
        1. /!\ Utilisateur de Vista : Ne pas oublier de désactiver l’UAC juste le temps de désinfection de ton pc, il sera à réactiver plus tard :
          Tuto : https://www.commentcamarche.net/faq/8343-vista-desactiver-l-uac

          Télécharge Smitfraudfix : (merci a S!RI pour ce petit programme).
          http://siri.urz.free.fr/Fix/SmitfraudFix.exe

          /!\Utilisateur de Vista : Clique droit sur le logo de smithfarudfix, « exécuter en tant qu’Administrateur »

          Exécute le, Double click sur Smitfraudfix.exe choisit l’option 1,
          voila a quoi cela ressemble : http://siri.urz.free.fr/Fix/SmitfraudFix.php
          il va générer un rapport : copie/colle le sur le poste stp.

          Tuto:http://pagesperso-orange.fr/rginformatique/section%20virus/smitfraudfix.htm

          Note :
          process.exe est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool. Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus. Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus
          0
          1. SmitFraudFix v2.424

            Rapport fait à 8:32:28,39, 26/10/2009
            Executé à partir de C:\Documents and Settings\mikavirg\Bureau\SmitfraudFix
            OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
            Le type du système de fichiers est NTFS
            Fix executé en mode normal

            »»»»»»»»»»»»»»»»»»»»»»»» Process

            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\Ati2evxx.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\Ati2evxx.exe
            C:\WINDOWS\System32\brsvc01a.exe
            C:\WINDOWS\System32\brss01a.exe
            C:\WINDOWS\system32\spoolsv.exe
            C:\Program Files\Avira\AntiVir Desktop\sched.exe
            C:\WINDOWS\Explorer.EXE
            C:\Program Files\Google\Update\1.2.183.7\GoogleCrashHandler.exe
            C:\Program Files\SimpleCenter\bin\win\sclauncher.exe
            C:\WINDOWS\Mixer.exe
            C:\Program Files\Multimedia Keyboard & Mouse Driver\V5\StartAutorun.exe
            C:\Program Files\Multimedia Keyboard & Mouse Driver\V5\KMConfig.exe
            C:\WINDOWS\system32\rundll32.exe
            C:\Program Files\Java\jre6\bin\jusched.exe
            C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe
            C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe
            C:\Program Files\Multimedia Keyboard & Mouse Driver\V5\KMProcess.exe
            C:\Program Files\Logitech\GamePanel Software\Applets\LCDMedia.exe
            C:\Program Files\Logitech\GamePanel Software\Applets\LCDCountdown.exe
            C:\Program Files\Logitech\GamePanel Software\LCD Manager\Applets\LCDClock.exe
            C:\Program Files\Logitech\GamePanel Software\Applets\ColorOnly\LCDMovieViewer.exe
            C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
            C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
            C:\Program Files\lg_fwupdate\fwupdate.exe
            C:\Program Files\Microsoft ActiveSync\Wcescomm.exe
            C:\PROGRA~1\MICROS~3\rapimgr.exe
            C:\WINDOWS\system32\ctfmon.exe
            C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
            C:\Program Files\a-squared Free\a2service.exe
            C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe
            C:\PROGRA~1\Wanadoo\GestionnaireInternet.exe
            C:\Program Files\Avira\AntiVir Desktop\avguard.exe
            C:\WINDOWS\System32\FTRTSVC.exe
            C:\PROGRA~1\Wanadoo\ComComp.exe
            C:\Program Files\Java\jre6\bin\jqs.exe
            C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
            C:\PROGRA~1\Wanadoo\Toaster.exe
            C:\PROGRA~1\Wanadoo\Inactivity.exe
            C:\PROGRA~1\Wanadoo\PollingModule.exe
            C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
            C:\WINDOWS\system32\IoctlSvc.exe
            C:\Program Files\CyberLink\Shared Files\RichVideo.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\Program Files\Mozilla Firefox\firefox.exe
            C:\Documents and Settings\mikavirg\Bureau\SmitfraudFix\Policies.exe
            C:\WINDOWS\system32\cmd.exe

            »»»»»»»»»»»»»»»»»»»»»»»» hosts

            »»»»»»»»»»»»»»»»»»»»»»»» C:\

            »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

            »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

            »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

            »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

            »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles

            »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\mikavirg

            »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\mikavirg\LOCALS~1\Temp

            »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\mikavirg\Application Data

            »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

            »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\mikavirg\Favoris

            »»»»»»»»»»»»»»»»»»»»»»»» Bureau

            »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

            »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

            »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

            »»»»»»»»»»»»»»»»»»»»»»»» o4Patch
            !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

            o4Patch
            Credits: Malware Analysis & Diagnostic
            Code: S!Ri

            »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
            !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

            IEDFix
            Credits: Malware Analysis & Diagnostic
            Code: S!Ri

            »»»»»»»»»»»»»»»»»»»»»»»» Agent.OMZ.Fix
            !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

            Agent.OMZ.Fix
            Credits: Malware Analysis & Diagnostic
            Code: S!Ri

            »»»»»»»»»»»»»»»»»»»»»»»» VACFix
            !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

            VACFix
            Credits: Malware Analysis & Diagnostic
            Code: S!Ri

            »»»»»»»»»»»»»»»»»»»»»»»» 404Fix
            !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

            404Fix
            Credits: Malware Analysis & Diagnostic
            Code: S!Ri

            »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
            !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

            SrchSTS.exe by S!Ri
            Search SharedTaskScheduler's .dll

            »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
            !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

            »»»»»»»»»»»»»»»»»»»»»»»» Winlogon
            !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
            "Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"

            »»»»»»»»»»»»»»»»»»»»»»»» RK

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
            "System"=""

            »»»»»»»»»»»»»»»»»»»»»»»» DNS

            Description: Intel(R) 82566DC-2 Gigabit Network Connection - Miniport d'ordonnancement de paquets
            DNS Server Search Order: 192.168.1.1

            Description: Intel(R) 82566DC-2 Gigabit Network Connection - Miniport d'ordonnancement de paquets
            DNS Server Search Order: 192.168.1.1

            HKLM\SYSTEM\CCS\Services\Tcpip\..\{AFE5B887-D1D4-4145-B6D6-1DDF35DDD62F}: DhcpNameServer=192.168.1.1
            HKLM\SYSTEM\CCS\Services\Tcpip\..\{D144121B-C836-488E-86E5-8685F3C3C1BF}: DhcpNameServer=192.168.1.1
            HKLM\SYSTEM\CS2\Services\Tcpip\..\{AFE5B887-D1D4-4145-B6D6-1DDF35DDD62F}: DhcpNameServer=192.168.1.1
            HKLM\SYSTEM\CS2\Services\Tcpip\..\{D144121B-C836-488E-86E5-8685F3C3C1BF}: DhcpNameServer=192.168.1.1
            HKLM\SYSTEM\CS3\Services\Tcpip\..\{AFE5B887-D1D4-4145-B6D6-1DDF35DDD62F}: DhcpNameServer=192.168.1.1
            HKLM\SYSTEM\CS3\Services\Tcpip\..\{D144121B-C836-488E-86E5-8685F3C3C1BF}: DhcpNameServer=192.168.1.1
            HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
            HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
            HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1

            »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

            »»»»»»»»»»»»»»»»»»»»»»»» Fin
            0
            1. Bonjour,
              désinstalle ce programme :
              C:\Program Files\Real

              refait un essai, et repasse un autre rsit
              poste son rapport sur ton prochain message
              merci
              0
              1. Logfile of random's system information tool 1.06 (written by random/random)
                Run by mikavirg at 2009-10-26 17:06:53
                Microsoft Windows XP Édition familiale Service Pack 3
                System drive C: has 140 GB (59%) free of 238 GB
                Total RAM: 2029 MB (49% free)

                Logfile of Trend Micro HijackThis v2.0.2
                Scan saved at 17:06:57, on 26/10/2009
                Platform: Windows XP SP3 (WinNT 5.01.2600)
                MSIE: Internet Explorer v8.00 (8.00.6001.18702)
                Boot mode: Normal

                Running processes:
                C:\WINDOWS\System32\smss.exe
                C:\WINDOWS\system32\winlogon.exe
                C:\WINDOWS\system32\services.exe
                C:\WINDOWS\system32\lsass.exe
                C:\WINDOWS\system32\Ati2evxx.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\System32\svchost.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\system32\Ati2evxx.exe
                C:\WINDOWS\System32\brss01a.exe
                C:\WINDOWS\system32\spoolsv.exe
                C:\Program Files\Avira\AntiVir Desktop\sched.exe
                C:\WINDOWS\Explorer.EXE
                C:\Program Files\Google\Update\1.2.183.7\GoogleCrashHandler.exe
                C:\Program Files\SimpleCenter\bin\win\sclauncher.exe
                C:\WINDOWS\Mixer.exe
                C:\Program Files\Multimedia Keyboard & Mouse Driver\V5\StartAutorun.exe
                C:\Program Files\Multimedia Keyboard & Mouse Driver\V5\KMConfig.exe
                C:\WINDOWS\system32\rundll32.exe
                C:\Program Files\Java\jre6\bin\jusched.exe
                C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe
                C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe
                C:\Program Files\Multimedia Keyboard & Mouse Driver\V5\KMProcess.exe
                C:\Program Files\Logitech\GamePanel Software\Applets\LCDMedia.exe
                C:\Program Files\Logitech\GamePanel Software\Applets\LCDCountdown.exe
                C:\Program Files\Logitech\GamePanel Software\LCD Manager\Applets\LCDClock.exe
                C:\Program Files\Logitech\GamePanel Software\Applets\ColorOnly\LCDMovieViewer.exe
                C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
                C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
                C:\Program Files\lg_fwupdate\fwupdate.exe
                C:\Program Files\Microsoft ActiveSync\Wcescomm.exe
                C:\PROGRA~1\MICROS~3\rapimgr.exe
                C:\WINDOWS\system32\ctfmon.exe
                C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                C:\Program Files\a-squared Free\a2service.exe
                C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe
                C:\PROGRA~1\Wanadoo\GestionnaireInternet.exe
                C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                C:\WINDOWS\System32\FTRTSVC.exe
                C:\PROGRA~1\Wanadoo\ComComp.exe
                C:\Program Files\Java\jre6\bin\jqs.exe
                C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
                C:\PROGRA~1\Wanadoo\Toaster.exe
                C:\PROGRA~1\Wanadoo\Inactivity.exe
                C:\PROGRA~1\Wanadoo\PollingModule.exe
                C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
                C:\WINDOWS\system32\IoctlSvc.exe
                C:\Program Files\CyberLink\Shared Files\RichVideo.exe
                C:\WINDOWS\System32\svchost.exe
                C:\WINDOWS\System32\svchost.exe
                C:\Program Files\eMule\emule.exe
                C:\Program Files\Mozilla Firefox\firefox.exe
                C:\Documents and Settings\mikavirg\Bureau\RSIT.exe
                C:\Program Files\trend micro\mikavirg.exe

                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer fourni par Orange
                R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
                R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
                O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
                O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
                O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                O4 - HKLM\..\Run: [sclauncher] C:\Program Files\SimpleCenter\bin\win\sclauncher.exe
                O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
                O4 - HKLM\..\Run: [KMConfig] "C:\Program Files\Multimedia Keyboard & Mouse Driver\V5\StartAutorun.exe" KMConfig.exe
                O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
                O4 - HKLM\..\Run: [CmPCIaudio] RunDll32 CMICNFG3.cpl,CMICtrlWnd
                O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
                O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                O4 - HKLM\..\Run: [Launch LgDevAgt] "C:\Program Files\Logitech\GamePanel Software\LgDevAgt.exe"
                O4 - HKLM\..\Run: [Launch LCDMon] "C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe"
                O4 - HKLM\..\Run: [Launch LGDCore] "C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe" /SHOWHIDE
                O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
                O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe"
                O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
                O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
                O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
                O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\YouCam" UpdateWithCreateOnce "Software\CyberLink\YouCam\1.0"
                O4 - HKLM\..\Run: [LGODDFU] "C:\Program Files\lg_fwupdate\fwupdate.exe" blrun
                O4 - HKLM\..\Run: [UpdatePSTShortCut] "C:\Program Files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\DVD Suite" UpdateWithCreateOnce "Software\CyberLink\PowerStarter"
                O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\Wcescomm.exe"
                O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
                O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                O4 - HKCU\..\Run: [DriverMax] "C:\Program Files\Innovative Solutions\DriverMax\devices.exe" -agent
                O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                O4 - HKCU\..\Run: [DriverMax_RESTART] "C:\Program Files\Innovative Solutions\DriverMax\devices.exe" -RESTART
                O4 - Startup: RocketDock.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe
                O4 - Startup: TransBar.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\TransBar\TransBar.exe
                O8 - Extra context menu item: eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
                O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
                O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
                O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
                O9 - Extra button: Barre de recherche Encarta - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Fichiers communs\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
                O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                O15 - Trusted Zone: http://asia.msi.com.tw
                O15 - Trusted Zone: http://global.msi.com.tw
                O15 - Trusted Zone: http://www.msi.com.tw
                O15 - Trusted Zone: https://applications-et-logiciels.orange.fr/
                O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
                O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
                O16 - DPF: {8167C273-DF59-4416-B647-C8BB2C7EE83E} (WebSDev Control) - http://liveupdate.msi.com.tw/autobios/LOnline/install.cab
                O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
                O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
                O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\System32\brsvc01a.exe
                O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
                O23 - Service: Service Google Update (gupdate1c9c66a5888689c) (gupdate1c9c66a5888689c) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
                O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
                O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
                O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
                O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe
                O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
                O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
                O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
                O23 - Service: Audio Service (STacSV) - Unknown owner - c:\docume~1\mikavirg\locals~1\temp\cdm\{4d309b13-24ad-4675-b823-bc8f7f389b43}\STacSV.exe (file missing)
                0
                1. bonjour,
                  Telecharge ToolsCleaner2--> http://pc-system.fr/
                  -Une fois téléchargé, installe-le et lance-le
                  -Clique sur Recherche et laisse le scan se terminer
                  -Clique sur SUPPRESSION
                  -Clique sur Quitter pour que le rapport puisse se créer
                  -Poste moi le rapport se trouvant ici--> C:\TCleaner.txt

                  refait un autre rsit s'il te plait et poste moi son rapport,

                  merci
                  0
                  1. [ Rapport ToolsCleaner version 2.3.1 (par A.Rothstein & dj QUIOU) ]

                    -->- Recherche:

                    C:\Rsit: trouvé !
                    C:\Documents and Settings\mikavirg\Bureau\SmitFraudFix.exe: trouvé !
                    C:\Documents and Settings\mikavirg\Bureau\Rsit.exe: trouvé !
                    C:\Documents and Settings\mikavirg\Bureau\SmitFraudfix: trouvé !
                    C:\Program Files\Trend Micro\HijackThis.exe: trouvé !
                    C:\Program Files\Trend Micro\hijackthis.log: trouvé !

                    ---------------------------------
                    -->- Suppression:

                    C:\Documents and Settings\mikavirg\Bureau\SmitFraudFix.exe: supprimé !
                    C:\Program Files\Trend Micro\HijackThis.exe: supprimé !
                    C:\Documents and Settings\mikavirg\Bureau\Rsit.exe: supprimé !
                    C:\Program Files\Trend Micro\hijackthis.log: supprimé !
                    C:\Rsit: supprimé !
                    C:\Documents and Settings\mikavirg\Bureau\SmitFraudfix: supprimé !
                    0
                    1. Logfile of random's system information tool 1.06 (written by random/random)
                      Run by mikavirg at 2009-10-26 19:24:32
                      Microsoft Windows XP Édition familiale Service Pack 3
                      System drive C: has 140 GB (59%) free of 238 GB
                      Total RAM: 2029 MB (62% free)

                      Logfile of Trend Micro HijackThis v2.0.2
                      Scan saved at 19:24:48, on 26/10/2009
                      Platform: Windows XP SP3 (WinNT 5.01.2600)
                      MSIE: Internet Explorer v8.00 (8.00.6001.18702)
                      Boot mode: Normal

                      Running processes:
                      C:\WINDOWS\System32\smss.exe
                      C:\WINDOWS\system32\winlogon.exe
                      C:\WINDOWS\system32\services.exe
                      C:\WINDOWS\system32\lsass.exe
                      C:\WINDOWS\system32\Ati2evxx.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\system32\Ati2evxx.exe
                      C:\WINDOWS\System32\brss01a.exe
                      C:\WINDOWS\system32\spoolsv.exe
                      C:\Program Files\Avira\AntiVir Desktop\sched.exe
                      C:\WINDOWS\Explorer.EXE
                      C:\Program Files\Google\Update\1.2.183.7\GoogleCrashHandler.exe
                      C:\Program Files\SimpleCenter\bin\win\sclauncher.exe
                      C:\WINDOWS\Mixer.exe
                      C:\Program Files\Multimedia Keyboard & Mouse Driver\V5\StartAutorun.exe
                      C:\Program Files\Multimedia Keyboard & Mouse Driver\V5\KMConfig.exe
                      C:\WINDOWS\system32\rundll32.exe
                      C:\Program Files\Java\jre6\bin\jusched.exe
                      C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe
                      C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe
                      C:\Program Files\Multimedia Keyboard & Mouse Driver\V5\KMProcess.exe
                      C:\Program Files\Logitech\GamePanel Software\Applets\LCDMedia.exe
                      C:\Program Files\Logitech\GamePanel Software\Applets\LCDCountdown.exe
                      C:\Program Files\Logitech\GamePanel Software\LCD Manager\Applets\LCDClock.exe
                      C:\Program Files\Logitech\GamePanel Software\Applets\ColorOnly\LCDMovieViewer.exe
                      C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
                      C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
                      C:\Program Files\lg_fwupdate\fwupdate.exe
                      C:\Program Files\Microsoft ActiveSync\Wcescomm.exe
                      C:\PROGRA~1\MICROS~3\rapimgr.exe
                      C:\WINDOWS\system32\ctfmon.exe
                      C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                      C:\Program Files\a-squared Free\a2service.exe
                      C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe
                      C:\PROGRA~1\Wanadoo\GestionnaireInternet.exe
                      C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                      C:\WINDOWS\System32\FTRTSVC.exe
                      C:\PROGRA~1\Wanadoo\ComComp.exe
                      C:\Program Files\Java\jre6\bin\jqs.exe
                      C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
                      C:\PROGRA~1\Wanadoo\Toaster.exe
                      C:\PROGRA~1\Wanadoo\Inactivity.exe
                      C:\PROGRA~1\Wanadoo\PollingModule.exe
                      C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
                      C:\WINDOWS\system32\IoctlSvc.exe
                      C:\Program Files\CyberLink\Shared Files\RichVideo.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\Program Files\Mozilla Firefox\firefox.exe
                      C:\Documents and Settings\mikavirg\Bureau\RSIT.exe
                      C:\Program Files\trend micro\mikavirg.exe

                      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer fourni par Orange
                      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                      R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
                      R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                      O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                      O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
                      O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
                      O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                      O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
                      O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                      O4 - HKLM\..\Run: [sclauncher] C:\Program Files\SimpleCenter\bin\win\sclauncher.exe
                      O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
                      O4 - HKLM\..\Run: [KMConfig] "C:\Program Files\Multimedia Keyboard & Mouse Driver\V5\StartAutorun.exe" KMConfig.exe
                      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                      O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                      O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
                      O4 - HKLM\..\Run: [CmPCIaudio] RunDll32 CMICNFG3.cpl,CMICtrlWnd
                      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                      O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
                      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                      O4 - HKLM\..\Run: [Launch LgDevAgt] "C:\Program Files\Logitech\GamePanel Software\LgDevAgt.exe"
                      O4 - HKLM\..\Run: [Launch LCDMon] "C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe"
                      O4 - HKLM\..\Run: [Launch LGDCore] "C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe" /SHOWHIDE
                      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
                      O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe"
                      O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
                      O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
                      O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
                      O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\YouCam" UpdateWithCreateOnce "Software\CyberLink\YouCam\1.0"
                      O4 - HKLM\..\Run: [LGODDFU] "C:\Program Files\lg_fwupdate\fwupdate.exe" blrun
                      O4 - HKLM\..\Run: [UpdatePSTShortCut] "C:\Program Files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\DVD Suite" UpdateWithCreateOnce "Software\CyberLink\PowerStarter"
                      O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\Wcescomm.exe"
                      O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
                      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                      O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                      O4 - HKCU\..\Run: [DriverMax] "C:\Program Files\Innovative Solutions\DriverMax\devices.exe" -agent
                      O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                      O4 - HKCU\..\Run: [DriverMax_RESTART] "C:\Program Files\Innovative Solutions\DriverMax\devices.exe" -RESTART
                      O4 - Startup: RocketDock.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe
                      O4 - Startup: TransBar.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\TransBar\TransBar.exe
                      O8 - Extra context menu item: eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
                      O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
                      O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
                      O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
                      O9 - Extra button: Barre de recherche Encarta - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Fichiers communs\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
                      O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                      O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                      O15 - Trusted Zone: http://asia.msi.com.tw
                      O15 - Trusted Zone: http://global.msi.com.tw
                      O15 - Trusted Zone: http://www.msi.com.tw
                      O15 - Trusted Zone: https://applications-et-logiciels.orange.fr/
                      O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
                      O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
                      O16 - DPF: {8167C273-DF59-4416-B647-C8BB2C7EE83E} (WebSDev Control) - http://liveupdate.msi.com.tw/autobios/LOnline/install.cab
                      O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                      O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
                      O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
                      O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                      O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                      O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\System32\brsvc01a.exe
                      O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
                      O23 - Service: Service Google Update (gupdate1c9c66a5888689c) (gupdate1c9c66a5888689c) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
                      O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                      O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
                      O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
                      O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
                      O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe
                      O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                      O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
                      O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
                      O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
                      O23 - Service: Audio Service (STacSV) - Unknown owner - c:\docume~1\mikavirg\locals~1\temp\cdm\{4d309b13-24ad-4675-b823-bc8f7f389b43}\STacSV.exe (file missing)
                      0
                      1. •/!\ Utilisateur de vista et windows 7 : ne pas oublier de désactiver Le contrôle des comptes utilisateurs
                        https://www.commentcamarche.net/faq/8343-vista-desactiver-l-uac

                        Télécharge USBFIX de Chiquitine29, C_xx et Chimay8

                        http://pagesperso-orange.fr/NosTools/Chiquitine29/UsbFix.exe

                        /!\ Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptible d'avoir été infectées sans les ouvrir

                        • Double clic sur le raccourci UsbFix présent sur ton bureau .
                        /!\Utilisateur de Vista : Clique droit sur le logo de USBFIX, « exécuter en tant qu’Administrateur »

                        • Choisis l'option 1 (Recherche)

                        • Laisse travailler l'outil.

                        • Ensuite post le rapport UsbFix.txt qui apparaîtra.

                        • Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque. ( C:\UsbFix.txt )

                        ( CTRL+A Pour tout sélectionner , CTRL+C pour copier et CTRL+V pour coller )

                        • Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
                        Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
                        Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.

                        • Tuto : http://pagesperso-orange.fr/NosTools/usbfix.html
                        0
                        1. ############################## | UsbFix V6.045 |

                          User : mikavirg (Administrateurs) # MIKAVIRG-AHB1UF
                          Update on 24/10/2009 by Chiquitine29, C_XX & Chimay8
                          Start at: 20:29:37 | 26/10/2009
                          Website : http://pagesperso-orange.fr/NosTools/index.html
                          Contact : FindyKill.Contact@gmail.com

                          Processeur Intel Pentium III Xeon
                          Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
                          Internet Explorer 8.0.6001.18702
                          Windows Firewall Status : Enabled
                          AV : AntiVir Desktop 9.0.1.32 [ Enabled | Updated ]

                          C:\ -> Disque fixe local # 232,88 Go (136,92 Go free) # NTFS
                          D:\ -> Disque CD-ROM
                          E:\ -> Disque CD-ROM # 0,38 Mo (0 Mo free) [Bluebirds] # CDFS

                          ############################## | Processus actifs |

                          C:\WINDOWS\System32\smss.exe
                          C:\WINDOWS\system32\csrss.exe
                          C:\WINDOWS\system32\winlogon.exe
                          C:\WINDOWS\system32\services.exe
                          C:\WINDOWS\system32\lsass.exe
                          C:\WINDOWS\system32\Ati2evxx.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\system32\Ati2evxx.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\System32\brss01a.exe
                          C:\WINDOWS\system32\spoolsv.exe
                          C:\Program Files\Avira\AntiVir Desktop\sched.exe
                          C:\WINDOWS\Explorer.EXE
                          C:\Program Files\Google\Update\1.2.183.7\GoogleCrashHandler.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\Program Files\SimpleCenter\bin\win\sclauncher.exe
                          C:\WINDOWS\Mixer.exe
                          C:\Program Files\Multimedia Keyboard & Mouse Driver\V5\StartAutorun.exe
                          C:\Program Files\Multimedia Keyboard & Mouse Driver\V5\KMConfig.exe
                          C:\WINDOWS\system32\rundll32.exe
                          C:\Program Files\Java\jre6\bin\jusched.exe
                          C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe
                          C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe
                          C:\Program Files\Multimedia Keyboard & Mouse Driver\V5\KMProcess.exe
                          C:\Program Files\Logitech\GamePanel Software\Applets\LCDMedia.exe
                          C:\Program Files\Logitech\GamePanel Software\Applets\LCDCountdown.exe
                          C:\Program Files\Logitech\GamePanel Software\LCD Manager\Applets\LCDClock.exe
                          C:\Program Files\Logitech\GamePanel Software\Applets\ColorOnly\LCDMovieViewer.exe
                          C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
                          C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
                          C:\Program Files\lg_fwupdate\fwupdate.exe
                          C:\Program Files\Microsoft ActiveSync\Wcescomm.exe
                          C:\PROGRA~1\MICROS~3\rapimgr.exe
                          C:\WINDOWS\system32\ctfmon.exe
                          C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                          C:\Program Files\a-squared Free\a2service.exe
                          C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe
                          C:\PROGRA~1\Wanadoo\GestionnaireInternet.exe
                          C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\System32\FTRTSVC.exe
                          C:\PROGRA~1\Wanadoo\ComComp.exe
                          C:\Program Files\Java\jre6\bin\jqs.exe
                          C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
                          C:\PROGRA~1\Wanadoo\Toaster.exe
                          C:\PROGRA~1\Wanadoo\Inactivity.exe
                          C:\PROGRA~1\Wanadoo\PollingModule.exe
                          C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
                          C:\WINDOWS\system32\IoctlSvc.exe
                          C:\Program Files\CyberLink\Shared Files\RichVideo.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\WINDOWS\System32\alg.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\WINDOWS\system32\wbem\wmiprvse.exe

                          ################## | Fichiers # Dossiers infectieux |

                          E:\autorun.inf
                          E:\BlueBirds.exe
                          E:\Drag&Burn.exe
                          E:\S e t u p.exe

                          ################## | Registre # Clés Run infectieuses |

                          [HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NoDrives"

                          ################## | Registre # Mountpoints2 |

                          HKCU\..\..\Explorer\MountPoints2\F
                          Shell\AutoRun\command =F:\MediaManager.exe

                          HKCU\..\..\Explorer\MountPoints2\{9ead3cbb-a34d-11de-8326-001cc092ff1b}
                          Shell\AutoRun\command =F:\MediaManager.exe

                          HKCU\..\..\Explorer\MountPoints2\{ca4a0ab9-bcae-11de-9307-806d6172696f}
                          Shell\AutoRun\command =E:\BlueBirds.exe

                          ################## | Suspect | https://www.virustotal.com/gui/ |

                          ################## | Cracks / Keygens / Serials |

                          "C:\Documents and Settings\mikavirg\Mes documents\Michael KIS\nero\Nero.8.Ultra.Edition.v8.3.2.1.FR.Incl-Serial\Nero-8.3.2.1_fra_trial.exe"
                          12/03/2008 16:02 |Size 197415200 |Crc32 a7f8577f |Md5 38725f65769dbfcb9151dd4969f39bd7

                          "C:\Documents and Settings\mikavirg\Mes documents\Michael KIS\Xilisoft.Video.Converter.v3.1.7.0630b.Multilangages.Incl.Keygen\x-video-converter.exe"
                          08/07/2006 02:05 |Size 14425167 |Crc32 6f03da1d |Md5 aa353001d1a3d773d7e68b82e9fb06eb

                          ################## | ! Fin du rapport # UsbFix V6.045 ! |
                          0
                          1. E:\ -> Disque CD-ROM

                            enlève le cd de ton lecteur :-)

                            relance l'outil usbfix en option 2 cette fois ci
                            puis poste son rapport
                            merci
                            0
                            1. il n y a aucun cd dans mes lecteurs!
                              0
                              1. ############################## | UsbFix V6.045 |

                                User : mikavirg (Administrateurs) # MIKAVIRG-AHB1UF
                                Update on 24/10/2009 by Chiquitine29, C_XX & Chimay8
                                Start at: 07:18:36 | 27/10/2009
                                Website : http://pagesperso-orange.fr/NosTools/index.html
                                Contact : FindyKill.Contact@gmail.com

                                Processeur Intel Pentium III Xeon
                                Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
                                Internet Explorer 8.0.6001.18702
                                Windows Firewall Status : Enabled
                                AV : AntiVir Desktop 9.0.1.32 [ Enabled | Updated ]

                                C:\ -> Disque fixe local # 232,88 Go (136,92 Go free) # NTFS
                                D:\ -> Disque CD-ROM
                                E:\ -> Disque CD-ROM # 0,38 Mo (0 Mo free) [Bluebirds] # CDFS

                                ############################## | Processus actifs |

                                C:\WINDOWS\System32\smss.exe
                                C:\WINDOWS\system32\csrss.exe
                                C:\WINDOWS\system32\winlogon.exe
                                C:\WINDOWS\system32\services.exe
                                C:\WINDOWS\system32\lsass.exe
                                C:\WINDOWS\system32\Ati2evxx.exe
                                C:\WINDOWS\system32\svchost.exe
                                C:\WINDOWS\system32\svchost.exe
                                C:\WINDOWS\System32\svchost.exe
                                C:\WINDOWS\system32\svchost.exe
                                C:\WINDOWS\System32\svchost.exe
                                C:\WINDOWS\system32\LogonUI.EXE
                                C:\WINDOWS\system32\Ati2evxx.exe
                                C:\WINDOWS\system32\svchost.exe
                                C:\WINDOWS\System32\brsvc01a.exe
                                C:\WINDOWS\system32\spoolsv.exe
                                C:\WINDOWS\System32\brss01a.exe
                                C:\Program Files\Avira\AntiVir Desktop\sched.exe
                                C:\WINDOWS\System32\svchost.exe
                                C:\Program Files\Google\Update\1.2.183.7\GoogleCrashHandler.exe
                                C:\WINDOWS\Explorer.EXE
                                C:\Program Files\a-squared Free\a2service.exe
                                C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                                C:\WINDOWS\system32\svchost.exe
                                C:\WINDOWS\System32\FTRTSVC.exe
                                C:\Program Files\Google\Update\GoogleUpdate.exe
                                C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                C:\Program Files\Java\jre6\bin\jqs.exe
                                C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
                                C:\Program Files\Google\Update\GoogleUpdate.exe
                                C:\WINDOWS\system32\IoctlSvc.exe
                                C:\Program Files\CyberLink\Shared Files\RichVideo.exe
                                C:\WINDOWS\System32\svchost.exe
                                C:\WINDOWS\System32\alg.exe
                                C:\WINDOWS\system32\wbem\wmiprvse.exe

                                ################## | Fichiers # Dossiers infectieux |

                                Non supprimé ! E:\autorun.inf
                                Non supprimé ! E:\BlueBirds.exe
                                Non supprimé ! E:\S e t u p.exe

                                ################## | Registre # Clés Run infectieuses |

                                Supprimé ! [HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NoDrives"

                                ################## | Registre # Mountpoints2 |

                                Supprimé ! HKCU\...\Explorer\MountPoints2\F\Shell\AutoRun\Command
                                Supprimé ! HKCU\...\Explorer\MountPoints2\{9ead3cbb-a34d-11de-8326-001cc092ff1b}\Shell\AutoRun\Command

                                ################## | Listing des fichiers présent |

                                [24/10/2009 05:27|--a------|16572] C:\aaw7boot.log
                                [03/07/2008 18:56|--a------|0] C:\AUTOEXEC.BAT
                                [09/09/2008 05:16|--a------|216] C:\Boot.bak
                                [13/10/2009 19:50|--ahs----|286] C:\boot.ini
                                [30/08/2002 13:00|-rahs----|4952] C:\Bootfont.bin
                                [03/08/2004 23:00|--a------|263488] C:\cmldr
                                [03/07/2008 18:56|--a------|0] C:\CONFIG.SYS
                                [15/05/2009 15:52|--ah-----|5381] C:\ffastun.ffa
                                [15/05/2009 15:52|--ah-----|294912] C:\ffastun.ffl
                                [15/05/2009 15:52|--ah-----|122880] C:\ffastun.ffo
                                [15/05/2009 15:52|--ah-----|1961984] C:\ffastun0.ffx
                                [03/07/2008 18:56|-rahs----|0] C:\IO.SYS
                                [03/07/2008 18:56|-rahs----|0] C:\MSDOS.SYS
                                [05/07/2008 06:59|-rahs----|47564] C:\NTDETECT.COM
                                [09/09/2008 18:31|-rahs----|252240] C:\ntldr
                                [?|?|?] C:\pagefile.sys
                                [26/10/2009 08:33|--a------|6370] C:\rapport.txt
                                [22/10/2009 15:37|--ah-----|268] C:\sqmdata00.sqm
                                [23/10/2009 05:58|--ah-----|268] C:\sqmdata01.sqm
                                [23/10/2009 09:25|--ah-----|268] C:\sqmdata02.sqm
                                [23/10/2009 13:33|--ah-----|268] C:\sqmdata03.sqm
                                [24/10/2009 05:29|--ah-----|268] C:\sqmdata04.sqm
                                [24/10/2009 07:03|--ah-----|268] C:\sqmdata05.sqm
                                [24/10/2009 17:34|--ah-----|268] C:\sqmdata06.sqm
                                [25/10/2009 05:56|--ah-----|268] C:\sqmdata07.sqm
                                [25/10/2009 12:05|--ah-----|268] C:\sqmdata08.sqm
                                [25/10/2009 12:55|--ah-----|268] C:\sqmdata09.sqm
                                [25/10/2009 13:30|--ah-----|268] C:\sqmdata10.sqm
                                [25/10/2009 13:43|--ah-----|268] C:\sqmdata11.sqm
                                [25/10/2009 16:18|--ah-----|268] C:\sqmdata12.sqm
                                [25/10/2009 16:35|--ah-----|268] C:\sqmdata13.sqm
                                [25/10/2009 17:38|--ah-----|268] C:\sqmdata14.sqm
                                [26/10/2009 05:29|--ah-----|268] C:\sqmdata15.sqm
                                [27/10/2009 06:19|--ah-----|268] C:\sqmdata16.sqm
                                [27/10/2009 07:13|--ah-----|268] C:\sqmdata17.sqm
                                [21/10/2009 06:18|--ah-----|268] C:\sqmdata18.sqm
                                [22/10/2009 07:21|--ah-----|268] C:\sqmdata19.sqm
                                [22/10/2009 15:37|--ah-----|244] C:\sqmnoopt00.sqm
                                [23/10/2009 05:58|--ah-----|244] C:\sqmnoopt01.sqm
                                [23/10/2009 09:25|--ah-----|244] C:\sqmnoopt02.sqm
                                [23/10/2009 13:33|--ah-----|244] C:\sqmnoopt03.sqm
                                [24/10/2009 05:29|--ah-----|244] C:\sqmnoopt04.sqm
                                [24/10/2009 07:03|--ah-----|244] C:\sqmnoopt05.sqm
                                [24/10/2009 17:34|--ah-----|244] C:\sqmnoopt06.sqm
                                [25/10/2009 05:56|--ah-----|244] C:\sqmnoopt07.sqm
                                [25/10/2009 12:05|--ah-----|244] C:\sqmnoopt08.sqm
                                [25/10/2009 12:55|--ah-----|244] C:\sqmnoopt09.sqm
                                [25/10/2009 13:30|--ah-----|244] C:\sqmnoopt10.sqm
                                [25/10/2009 13:43|--ah-----|244] C:\sqmnoopt11.sqm
                                [25/10/2009 16:18|--ah-----|244] C:\sqmnoopt12.sqm
                                [25/10/2009 16:35|--ah-----|244] C:\sqmnoopt13.sqm
                                [25/10/2009 17:38|--ah-----|244] C:\sqmnoopt14.sqm
                                [26/10/2009 05:29|--ah-----|244] C:\sqmnoopt15.sqm
                                [27/10/2009 06:19|--ah-----|244] C:\sqmnoopt16.sqm
                                [27/10/2009 07:13|--ah-----|244] C:\sqmnoopt17.sqm
                                [21/10/2009 06:18|--ah-----|244] C:\sqmnoopt18.sqm
                                [22/10/2009 07:21|--ah-----|244] C:\sqmnoopt19.sqm
                                [26/10/2009 19:22|--a------|816] C:\TCleaner.txt
                                [02/09/2009 13:09|--a------|22383416] C:\upload_moi_MIKAVIRG-AHB1UF.tar.gz
                                [27/10/2009 07:20|--a------|5729] C:\UsbFix.txt
                                [27/09/2009 15:52|--a------|89] C:\wl.err
                                [29/04/2009 10:02|-r-------|55] E:\autorun.inf
                                [29/04/2009 10:02|-r-------|270336] E:\BlueBirds.exe
                                [29/04/2009 10:02|-r-------|270336] E:\S e t u p.exe
                                [29/04/2009 10:02|-r-------|81920] E:\Drag&Burn.exe

                                ################## | Vaccination |

                                # C:\autorun.inf -> Folder created by UsbFix.

                                ################## | Suspect | https://www.virustotal.com/gui/ |

                                ################## | Cracks / Keygens / Serials |

                                "C:\Documents and Settings\mikavirg\Mes documents\Michael KIS\nero\Nero.8.Ultra.Edition.v8.3.2.1.FR.Incl-Serial\Nero-8.3.2.1_fra_trial.exe"
                                12/03/2008 16:02 |Size 197415200 |Crc32 a7f8577f |Md5 38725f65769dbfcb9151dd4969f39bd7

                                "C:\Documents and Settings\mikavirg\Mes documents\Michael KIS\Xilisoft.Video.Converter.v3.1.7.0630b.Multilangages.Incl.Keygen\x-video-converter.exe"
                                08/07/2006 02:05 |Size 14425167 |Crc32 6f03da1d |Md5 aa353001d1a3d773d7e68b82e9fb06eb

                                ################## | Upload |

                                Veuillez envoyer le fichier : C:\DOCUME~1\mikavirg\Bureau\UsbFix_Upload_Me_MIKAVIRG-AHB1UF.zip : https://www.androidworld.fr/
                                Merci pour votre contribution .

                                ################## | ! Fin du rapport # UsbFix V6.045 ! |
                                0
                                1. bonjour,
                                  j'attire ton attention sur ces fichiers :
                                  [22/10/2009 15:37|--ah-----|268] C:\sqmdata00.sqm
                                  [23/10/2009 05:58|--ah-----|268] C:\sqmdata01.sqm
                                  [23/10/2009 09:25|--ah-----|268] C:\sqmdata02.sqm
                                  [23/10/2009 13:33|--ah-----|268] C:\sqmdata03.sqm
                                  [24/10/2009 05:29|--ah-----|268] C:\sqmdata04.sqm
                                  [24/10/2009 07:03|--ah-----|268] C:\sqmdata05.sqm
                                  [24/10/2009 17:34|--ah-----|268] C:\sqmdata06.sqm
                                  [25/10/2009 05:56|--ah-----|268] C:\sqmdata07.sqm
                                  [25/10/2009 12:05|--ah-----|268] C:\sqmdata08.sqm
                                  [25/10/2009 12:55|--ah-----|268] C:\sqmdata09.sqm
                                  [25/10/2009 13:30|--ah-----|268] C:\sqmdata10.sqm
                                  [25/10/2009 13:43|--ah-----|268] C:\sqmdata11.sqm
                                  [25/10/2009 16:18|--ah-----|268] C:\sqmdata12.sqm
                                  [25/10/2009 16:35|--ah-----|268] C:\sqmdata13.sqm
                                  [25/10/2009 17:38|--ah-----|268] C:\sqmdata14.sqm
                                  [26/10/2009 05:29|--ah-----|268] C:\sqmdata15.sqm
                                  [27/10/2009 06:19|--ah-----|268] C:\sqmdata16.sqm
                                  [27/10/2009 07:13|--ah-----|268] C:\sqmdata17.sqm
                                  [21/10/2009 06:18|--ah-----|268] C:\sqmdata18.sqm
                                  [22/10/2009 07:21|--ah-----|268] C:\sqmdata19.sqm
                                  [22/10/2009 15:37|--ah-----|244] C:\sqmnoopt00.sqm
                                  [23/10/2009 05:58|--ah-----|244] C:\sqmnoopt01.sqm
                                  [23/10/2009 09:25|--ah-----|244] C:\sqmnoopt02.sqm
                                  [23/10/2009 13:33|--ah-----|244] C:\sqmnoopt03.sqm
                                  [24/10/2009 05:29|--ah-----|244] C:\sqmnoopt04.sqm
                                  [24/10/2009 07:03|--ah-----|244] C:\sqmnoopt05.sqm
                                  [24/10/2009 17:34|--ah-----|244] C:\sqmnoopt06.sqm
                                  [25/10/2009 05:56|--ah-----|244] C:\sqmnoopt07.sqm
                                  [25/10/2009 12:05|--ah-----|244] C:\sqmnoopt08.sqm
                                  [25/10/2009 12:55|--ah-----|244] C:\sqmnoopt09.sqm
                                  [25/10/2009 13:30|--ah-----|244] C:\sqmnoopt10.sqm
                                  [25/10/2009 13:43|--ah-----|244] C:\sqmnoopt11.sqm
                                  [25/10/2009 16:18|--ah-----|244] C:\sqmnoopt12.sqm
                                  [25/10/2009 16:35|--ah-----|244] C:\sqmnoopt13.sqm
                                  [25/10/2009 17:38|--ah-----|244] C:\sqmnoopt14.sqm
                                  [26/10/2009 05:29|--ah-----|244] C:\sqmnoopt15.sqm
                                  [27/10/2009 06:19|--ah-----|244] C:\sqmnoopt16.sqm
                                  [27/10/2009 07:13|--ah-----|244] C:\sqmnoopt17.sqm
                                  [21/10/2009 06:18|--ah-----|244] C:\sqmnoopt18.sqm
                                  [22/10/2009 07:21|--ah-----|244] C:\sqmnoopt19.sqm

                                  ces fichiers ne sont pas des virus, mais des fichiers crées par Windows live messenger, non dangeureux, de taille minis alors ne te casse pas la tête avec ceci ;-)

                                  Pour info :

                                  les fichiers sqm sont des fichiers SERVICE QUALITY MONITORING, ce sont des fichiers espions pour aider a l'amélioration des programmes. Pour les desactiver, il faut lancer MSN,:
                                  Aller dans l'aide, choisir 'Programme d'amélioration des services' et dire 'Je ne veux pas participer' ! Il n'y aura plus de nouveaus fichiers sqm. Et effaces ceux présents.
                                  0
                                  1. ba deja fait des anlyses anti-virus ci ca donne rien parle moi en
                                    0
                                    1. E:\ -> Disque CD-ROM # 0,38 Mo (0 Mo free) [Bluebirds] # CDFS

                                      Non supprimé ! E:\autorun.inf
                                      Non supprimé ! E:\BlueBirds.exe
                                      Non supprimé ! E:\S e t u p.exe
                                      0
                                      1. autorun , blue bird et setup exe impossible de les supprimer j ai un message qui me dit

                                        impossible de les supprimer car ils sont en lecture seule
                                        0
                                        1. Bonjour,
                                          ils se trouvent ou ces repertoirs?

                                          sur un CD rom?

                                          dans ce cas, tu ne peux pas les virer !!!
                                          0
                                          • 1
                                          • 2
                                          • 3