PC de plus en plus lent, mémoire vive réduite

Frech -  
 Utilisateur anonyme -
Bonjour,
j'ai des petits problèmes en ce moment avec mon ordi. Entre autres, mon ordi tourne à 800mo de mémoire vive de plus en plus souvent, avec quelques pics à 950 ! Et des services comme cftmon.exe, svchost.exe, winlogon.exe, ati2evxx.exe,ANIWZCsds.exe sont très gourmands !

J'ai également une infection de clé USB puisque je ne peux plus rien supprimer dessus ! j'avais trouvé la solution en supprimant l'autorun mais du coup tous mes programmes ne se lançaient plus ! Probleme résolu mais pas pour la clé qui reste infectée...

J'ai installé Avira AntiVir qui m'aide un peu mais pas pour la mémoire vive... Argh !

Help s'il vous plait !

Merci d'avance !

Frech.
Configuration: Windows XP
Firefox 3.5.3

12 réponses

  1. Frech
     
    A quoi servent ces logiciels ?

    J'avais essayé malwarebytes sans trop de résultats.

    Sinon j'ai smitfraudfix et hijackthis mais je ne sais pas trop comment m'en servir !

    Merci de ta réponse je vais essayer tout de même !
    0
  2. Frech
     
    Voilà un rapport SmitFraudFix, si pouviez m'aider à le déchiffer, j'y comprends pas tout ! ^^

    SmitFraudFix v2.424

    Rapport fait à 17:44:47,78, 26/10/2009
    Executé à partir de C:\Program Files\Free Download Manager\SmitfraudFix
    OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
    Le type du système de fichiers est NTFS
    Fix executé en mode normal

    »»»»»»»»»»»»»»»»»»»»»»»» Process

    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Avira\AntiVir Desktop\sched.exe
    C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
    C:\Program Files\Avira\AntiVir Desktop\avguard.exe
    C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Google\Update\GoogleUpdate.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\WINDOWS\system32\taskmgr.exe
    c:\program files\avira\antivir desktop\avcenter.exe
    C:\Program Files\Avira\AntiVir Desktop\avscan.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\PROGRA~1\FREEDO~1\FDM.exe
    C:\WINDOWS\system32\cmd.exe

    »»»»»»»»»»»»»»»»»»»»»»»» hosts

    »»»»»»»»»»»»»»»»»»»»»»»» C:\

    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

    »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Administrateur

    »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp

    »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Administrateur\Application Data

    »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

    »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\ADMINI~1\Favoris

    »»»»»»»»»»»»»»»»»»»»»»»» Bureau

    »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

    »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

    »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
    "Source"="About:Home"
    "SubscribedURL"="About:Home"
    "FriendlyName"="Ma page d'accueil"

    »»»»»»»»»»»»»»»»»»»»»»»» o4Patch
    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

    o4Patch
    Credits: Malware Analysis & Diagnostic
    Code: S!Ri

    »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

    IEDFix
    Credits: Malware Analysis & Diagnostic
    Code: S!Ri

    »»»»»»»»»»»»»»»»»»»»»»»» Agent.OMZ.Fix
    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

    Agent.OMZ.Fix
    Credits: Malware Analysis & Diagnostic
    Code: S!Ri

    »»»»»»»»»»»»»»»»»»»»»»»» VACFix
    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

    VACFix
    Credits: Malware Analysis & Diagnostic
    Code: S!Ri

    »»»»»»»»»»»»»»»»»»»»»»»» 404Fix
    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

    404Fix
    Credits: Malware Analysis & Diagnostic
    Code: S!Ri

    »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

    SrchSTS.exe by S!Ri
    Search SharedTaskScheduler's .dll

    »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
    "AppInit_DLLs"=""

    »»»»»»»»»»»»»»»»»»»»»»»» Winlogon
    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
    "Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"

    »»»»»»»»»»»»»»»»»»»»»»»» RK

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
    "System"=""

    »»»»»»»»»»»»»»»»»»»»»»»» DNS

    Description: D-Link Wireless G DWA-110 USB Adapter - Miniport d'ordonnancement de paquets
    DNS Server Search Order: 192.168.1.1

    Description: D-Link Wireless G DWA-110 USB Adapter - Miniport d'ordonnancement de paquets
    DNS Server Search Order: 192.168.1.1
    DNS Server Search Order: 192.168.1.1

    HKLM\SYSTEM\CCS\Services\Tcpip\..\{9E308DD6-1EC4-49F1-BB11-FCD4D8207843}: DhcpNameServer=192.168.1.1 192.168.1.1
    HKLM\SYSTEM\CCS\Services\Tcpip\..\{A99703C0-6F76-4EAE-B395-CF6C382974AA}: NameServer=192.168.1.1
    HKLM\SYSTEM\CCS\Services\Tcpip\..\{CA5B42D7-E8E6-4F8F-93E0-9A8BC78209F4}: NameServer=192.168.1.1
    HKLM\SYSTEM\CS1\Services\Tcpip\..\{9E308DD6-1EC4-49F1-BB11-FCD4D8207843}: DhcpNameServer=192.168.1.1 192.168.1.1
    HKLM\SYSTEM\CS1\Services\Tcpip\..\{A99703C0-6F76-4EAE-B395-CF6C382974AA}: NameServer=192.168.1.1
    HKLM\SYSTEM\CS1\Services\Tcpip\..\{CA5B42D7-E8E6-4F8F-93E0-9A8BC78209F4}: NameServer=192.168.1.1
    HKLM\SYSTEM\CS3\Services\Tcpip\..\{9E308DD6-1EC4-49F1-BB11-FCD4D8207843}: DhcpNameServer=192.168.1.1 192.168.1.1
    HKLM\SYSTEM\CS3\Services\Tcpip\..\{A99703C0-6F76-4EAE-B395-CF6C382974AA}: NameServer=192.168.1.1
    HKLM\SYSTEM\CS3\Services\Tcpip\..\{CA5B42D7-E8E6-4F8F-93E0-9A8BC78209F4}: NameServer=192.168.1.1

    »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

    »»»»»»»»»»»»»»»»»»»»»»»» Fin
    0
    1. Utilisateur anonyme
       
      Bonsoir Frech

      Fait ceci stp merci:
      1- Télécharge et installe le logiciel HijackThis :

      https://www.commentcamarche.net/telecharger/securite/11747-hijackthis/
      ou ici http://www.trendsecure.com/portal/en-US/_download/HJTInstall.exe
      ou ici https://www.clubic.com/telecharger-fiche17891-hijackthis.html

      -->Clique sur le setup pour lancer l'installation : laisse toi guider et ne modifie pas les paramètres d'installation .
      A la fin de l’installation, le programme se lance automatiquement : ferme le en cliquant sur la croix rouge.
      Au final, tu dois avoir un raccourci sur ton bureau et aussi un cheminement comme :
      "C:\ program files\Trend Micro\HijackThis\HijackThis.exe " .

      (Ne lance pas ce prg pour l'instant et fais la suite ... )


      2- Télécharge Random's System Information Tool (RSIT) de random/random et enregistre l'exécutable sur ton Bureau.

      -> http://images.malwareremoval.com/random/RSIT.exe

      ! Déconnecte toi et ferme toutes tes applications en cours !

      Double-clique sur " RSIT.exe " pour le lancer.

      Clic droit sous VISTA (exécuter en tant que…)

      -> Une première fenêtre s'ouvre avec en titre : " Disclaimer of warranty " .

      * Devant l'option "List files/folders created ..." , tu choisis : 2 months

      * clique ensuite sur " Continue " pour lancer l'analyse ...


      -> laisse faire le scan et ne touche pas au PC ...


      Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront (probablement avec le bloc-notes).

      Poste le contenu de " log.txt " (c'est celui qui apparaît à l'écran), ainsi que de " info.txt " (que tu verras dans la barre des tâches), pour analyse et attends la suite ...

      Important : poste un rapport, puis l'autre dans la réponse suivante ...
      Si tu essaies de poster les deux en même temps, cela risque d'être trop long pour le forum ...
      ( Et si "log.txt" seul, ne passe pas non plus , fais le en 2 fois ... merci ... )

      ( Note : les rapports seront en outre sauvegardés dans ce dossier -> C:\rsit )

      Merci

      0
  3. Frech
     
    OK je m'en occupe !

    Par contre je suis sous XP et non Vista !

    Merci de ta réponse !
    0
  4. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  5. Frech
     
    Alors voilà le premier rapport dit LOG :

    Logfile of random's system information tool 1.06 (written by random/random)
    Run by Administrateur at 2009-10-26 19:18:05
    Microsoft Windows XP Professionnel Service Pack 3
    System drive C: has 27 GB (53%) free of 50 GB
    Total RAM: 510 MB (57% free)

    HijackThis download failed

    ======Scheduled tasks folder======

    C:\WINDOWS\tasks\Google Software Updater.job
    C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
    C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
    C:\WINDOWS\tasks\WGASetup.job

    ======Registry dump======

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
    Adobe PDF Link Helper - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
    Programme d'aide de l'Assistant de connexion Windows Live - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CC59E0F9-7E43-44FA-9FAA-8377850BF205}]
    FDMIECookiesBHO Class - C:\Program Files\Free Download Manager\iefdm2.dll [2009-03-02 98304]

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    "Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-02-27 35696]
    "QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2008-11-04 413696]
    "avgnt"=C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [2009-03-02 209153]
    "Malwarebytes Anti-Malware (reboot)"=D:\Program Files\Malwarebytes' Anti-Malware\mbam.exe [2009-09-10 1312080]

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
    "Malwarebytes' Anti-Malware"=D:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe [2009-09-10 420176]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-13 15360]
    "DAEMON Tools Pro Agent"=C:\Program Files\DAEMON Tools Pro\DTProAgent.exe [2009-08-05 224712]

    C:\Documents and Settings\Administrateur\Menu Démarrer\Programmes\Démarrage
    OpenOffice.org 3.0.lnk - C:\Program Files\OpenOffice.org 3\program\quickstart.exe

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
    C:\WINDOWS\system32\Ati2evxx.dll [2006-05-03 61440]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
    C:\WINDOWS\system32\WgaLogon.dll [2008-09-05 267304]

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
    "dontdisplaylastusername"=0
    "legalnoticecaption"=
    "legalnoticetext"=
    "shutdownwithoutlogon"=1
    "undockwithoutlogon"=1

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
    "NoDriveTypeAutoRun"=145

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
    "HonorAutoRunSetting"=

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
    "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
    "C:\Program Files\ma-config.com\maconfservice.exe"="C:\Program Files\ma-config.com\maconfservice.exe:LocalSubNet:Enabled:maconfservice"
    "%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
    "C:\Documents and Settings\Administrateur\cftmon.exe"="C:\Documents and Settings\Administrateur\cftmon.exe:*:Enabled:cftmon"
    "C:\WINDOWS\system32\drivers\spools.exe"="C:\WINDOWS\system32\drivers\spools.exe:*:Enabled:spools"
    "C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
    "D:\Program Files\EMPIRES2.ICD"="D:\Program Files\EMPIRES2.ICD:*:Enabled:Age of Empires II"
    "D:\Program Files\Spotify\spotify.exe"="D:\Program Files\Spotify\spotify.exe:*:Enabled:Spotify"
    "D:\Program Files\Sports Interactive\Football Manager 2009\fm.exe"="D:\Program Files\Sports Interactive\Football Manager 2009\fm.exe:*:Enabled:Football Manager 2009"
    "C:\Program Files\BitTorrent\bittorrent.exe"="C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent"
    "C:\Program Files\Free Download Manager\fdm.exe"="C:\Program Files\Free Download Manager\fdm.exe:*:Disabled:Free Download Manager"
    "C:\Program Files\Windows Live\Messenger\wlcsdk.exe"="C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call"
    "C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
    "C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe"="C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live FolderShare"
    "D:\Program Files\TVAnts\Tvants.exe"="D:\Program Files\TVAnts\Tvants.exe:*:Enabled:TVAnts"
    "D:\Program Files\StreamTorrent 1.0\StreamTorrent.exe"="D:\Program Files\StreamTorrent 1.0\StreamTorrent.exe:*:Enabled:StreamTorrent Peer-to-Peer Streaming Program"
    "C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
    "D:\Program Files\PPMate\ppmate.exe"="D:\Program Files\PPMate\ppmate.exe:*:Enabled:PPMate"
    "D:\Program Files\PPMate\ppamnet.exe"="D:\Program Files\PPMate\ppamnet.exe:*:Enabled:PPMate"
    "D:\Program Files\SopCast\adv\SopAdver.exe"="D:\Program Files\SopCast\adv\SopAdver.exe:*:Enabled:SopCast Adver"
    "D:\Program Files\SopCast\SopCast.exe"="D:\Program Files\SopCast\SopCast.exe:*:Enabled:SopCast Main Application"
    "D:\Program Files\eMule\emule.exe"="D:\Program Files\eMule\emule.exe:*:Enabled:eMule"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
    "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
    "%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
    "C:\Program Files\Windows Live\Messenger\wlcsdk.exe"="C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call"
    "C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
    "C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe"="C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live FolderShare"

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4b85f96e-9321-11de-81f7-0022b00d04c6}]
    shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL autorun.exe

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5120ebe1-9312-11de-81f6-0022b00d04c6}]
    shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL autorun.exe

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6adf94c7-abce-11de-8224-0022b00d04c6}]
    shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL autorun.exe

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{90242ffc-a2bf-11de-8217-0022b00d04c6}]
    shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL autorun.exe

    ======List of files/folders created in the last 2 months======

    2009-10-26 19:18:15 ----D---- C:\Program Files\trend micro
    2009-10-26 19:18:05 ----D---- C:\rsit
    2009-10-26 18:18:55 ----D---- C:\Documents and Settings\Administrateur\Application Data\Malwarebytes
    2009-10-26 18:18:12 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
    2009-10-26 17:45:41 ----A---- C:\WINDOWS\system32\tmp.txt
    2009-10-26 17:44:47 ----A---- C:\rapport.txt
    2009-10-26 17:41:05 ----A---- C:\WINDOWS\system32\o4Patch.exe
    2009-10-26 17:41:05 ----A---- C:\WINDOWS\system32\IEDFix.C.exe
    2009-10-26 17:41:05 ----A---- C:\WINDOWS\system32\Agent.OMZ.Fix.exe
    2009-10-26 17:41:04 ----A---- C:\WINDOWS\system32\WS2Fix.exe
    2009-10-26 17:41:04 ----A---- C:\WINDOWS\system32\VCCLSID.exe
    2009-10-26 17:41:04 ----A---- C:\WINDOWS\system32\VACFix.exe
    2009-10-26 17:41:04 ----A---- C:\WINDOWS\system32\swxcacls.exe
    2009-10-26 17:41:04 ----A---- C:\WINDOWS\system32\swsc.exe
    2009-10-26 17:41:04 ----A---- C:\WINDOWS\system32\swreg.exe
    2009-10-26 17:41:04 ----A---- C:\WINDOWS\system32\SrchSTS.exe
    2009-10-26 17:41:04 ----A---- C:\WINDOWS\system32\Process.exe
    2009-10-26 17:41:04 ----A---- C:\WINDOWS\system32\IEDFix.exe
    2009-10-26 17:41:04 ----A---- C:\WINDOWS\system32\dumphive.exe
    2009-10-26 17:41:04 ----A---- C:\WINDOWS\system32\404Fix.exe
    2009-10-19 17:08:13 ----D---- C:\Program Files\Avira
    2009-10-19 17:08:13 ----D---- C:\Documents and Settings\All Users\Application Data\Avira
    2009-10-16 00:37:03 ----SHD---- C:\Config.Msi
    2009-10-16 00:35:46 ----HDC---- C:\WINDOWS\$NtUninstallKB958869$
    2009-10-16 00:33:40 ----HDC---- C:\WINDOWS\$NtUninstallKB969059$
    2009-10-16 00:33:33 ----HDC---- C:\WINDOWS\$NtUninstallKB954155_WM9$
    2009-10-16 00:33:09 ----HDC---- C:\WINDOWS\$NtUninstallKB974112$
    2009-10-16 00:33:01 ----HDC---- C:\WINDOWS\$NtUninstallKB975025$
    2009-10-16 00:32:31 ----HDC---- C:\WINDOWS\$NtUninstallKB974571$
    2009-10-16 00:32:01 ----HDC---- C:\WINDOWS\$NtUninstallKB971486$
    2009-10-16 00:31:53 ----HDC---- C:\WINDOWS\$NtUninstallKB973525$
    2009-10-16 00:31:43 ----HDC---- C:\WINDOWS\$NtUninstallKB975467$
    2009-10-11 23:11:16 ----D---- C:\Documents and Settings\All Users\Application Data\CA
    2009-10-11 22:47:55 ----D---- C:\Program Files\Windows Live Safety Center
    2009-10-11 22:33:05 ----D---- C:\Documents and Settings\Administrateur\Application Data\HouseCall 6.6
    2009-10-04 23:55:19 ----D---- C:\Documents and Settings\Administrateur\Application Data\dvdcss
    2009-10-04 17:28:09 ----A---- C:\WINDOWS\msgtn.ini
    2009-10-04 17:28:08 ----A---- C:\WINDOWS\psnetwork.ini
    2009-10-04 17:28:08 ----A---- C:\WINDOWS\powerplayer.ini
    2009-10-04 17:28:05 ----D---- C:\Documents and Settings\Administrateur\Application Data\SopCast
    2009-10-04 17:27:31 ----D---- C:\ppmaterecord
    2009-10-04 17:26:31 ----D---- C:\Documents and Settings\Administrateur\Application Data\PPMate
    2009-10-04 17:26:19 ----D---- C:\Program Files\Fichiers communs\Synacast
    2009-10-04 01:41:31 ----D---- C:\Program Files\Bonjour
    2009-10-04 01:40:43 ----D---- C:\Program Files\QuickTime
    2009-10-04 01:40:40 ----D---- C:\Documents and Settings\All Users\Application Data\Apple Computer
    2009-10-04 01:40:12 ----D---- C:\Program Files\Apple Software Update
    2009-10-04 01:39:47 ----D---- C:\Program Files\Fichiers communs\Apple
    2009-10-04 01:39:46 ----D---- C:\Documents and Settings\All Users\Application Data\Apple
    2009-10-03 14:07:34 ----D---- C:\Games
    2009-10-03 14:07:13 ----A---- C:\WINDOWS\unin040c.exe
    2009-09-26 21:09:44 ----D---- C:\Documents and Settings\Administrateur\Application Data\live-player
    2009-09-26 21:08:06 ----D---- C:\Program Files\Live-Player
    2009-09-20 20:38:33 ----A---- C:\WINDOWS\ntbtlog.txt
    2009-09-20 02:06:05 ----HDC---- C:\WINDOWS\$NtUninstallKB961503$
    2009-09-19 20:21:10 ----A---- C:\WINDOWS\system32\muweb.dll
    2009-09-19 20:21:10 ----A---- C:\WINDOWS\system32\mucltui.dll.mui
    2009-09-19 20:21:10 ----A---- C:\WINDOWS\system32\mucltui.dll
    2009-09-18 18:47:52 ----D---- C:\Program Files\Microsoft Silverlight
    2009-09-18 18:46:15 ----D---- C:\Program Files\Microsoft SQL Server Compact Edition
    2009-09-18 18:45:28 ----D---- C:\Program Files\Microsoft
    2009-09-18 18:45:12 ----D---- C:\Program Files\Windows Live SkyDrive
    2009-09-18 18:44:50 ----D---- C:\Program Files\Windows Live
    2009-09-18 18:26:31 ----D---- C:\Program Files\Fichiers communs\Windows Live
    2009-09-15 18:13:57 ----AT---- C:\WINDOWS\system32\SIntfNT.dll
    2009-09-15 18:13:57 ----AT---- C:\WINDOWS\system32\SIntf32.dll
    2009-09-15 18:13:57 ----AT---- C:\WINDOWS\system32\SIntf16.dll
    2009-09-15 18:11:59 ----A---- C:\WINDOWS\system32\wiaaut.dll
    2009-09-15 18:05:31 ----A---- C:\WINDOWS\DIIUnin.exe
    2009-09-15 17:02:20 ----D---- C:\Documents and Settings\Administrateur\Application Data\InstallShield Installation Information
    2009-09-09 16:32:31 ----HDC---- C:\WINDOWS\$NtUninstallKB968816_WM9$
    2009-09-09 16:32:28 ----HDC---- C:\WINDOWS\$NtUninstallKB956844$
    2009-09-09 16:32:19 ----HDC---- C:\WINDOWS\$NtUninstallKB971961$
    2009-09-08 18:23:37 ----D---- C:\Program Files\Microsoft Games
    2009-09-08 15:00:08 ----D---- C:\Program Files\DAEMON Tools Pro
    2009-09-08 15:00:08 ----D---- C:\Documents and Settings\All Users\Application Data\DAEMON Tools Pro
    2009-09-08 14:57:50 ----D---- C:\Documents and Settings\Administrateur\Application Data\DAEMON Tools Pro
    2009-09-08 14:03:16 ----D---- C:\Unreal
    2009-09-08 13:40:45 ----D---- C:\Program Files\directx
    2009-09-08 13:35:44 ----D---- C:\UnrealTournament
    2009-09-08 13:22:54 ----D---- C:\Program Files\Max Payne
    2009-09-08 12:04:08 ----D---- C:\Program Files\Eidos Interactive
    2009-09-08 11:52:13 ----D---- C:\Documents and Settings\All Users\Application Data\DAEMON Tools Lite
    2009-09-08 11:49:50 ----D---- C:\Documents and Settings\Administrateur\Application Data\DAEMON Tools Lite
    2009-09-05 16:07:38 ----D---- C:\Program Files\VDMSound
    2009-09-04 13:42:38 ----D---- C:\Documents and Settings\Administrateur\Application Data\BitTorrent
    2009-09-04 12:46:46 ----D---- C:\Program Files\BitTorrent
    2009-09-03 08:55:15 ----D---- C:\Documents and Settings\Administrateur\Application Data\Sports Interactive
    2009-09-03 08:28:58 ----D---- C:\WINDOWS\system32\appmgmt
    2009-09-02 23:33:10 ----D---- C:\Documents and Settings\All Users\Application Data\Sports Interactive
    2009-09-02 23:31:04 ----A---- C:\WINDOWS\system32\XAudio2_1.dll
    2009-09-02 23:31:04 ----A---- C:\WINDOWS\system32\XAPOFX1_0.dll
    2009-09-02 23:31:04 ----A---- C:\WINDOWS\system32\xactengine3_1.dll
    2009-09-02 23:31:03 ----A---- C:\WINDOWS\system32\X3DAudio1_4.dll
    2009-09-02 23:31:03 ----A---- C:\WINDOWS\system32\d3dx10_38.dll
    2009-09-02 23:31:03 ----A---- C:\WINDOWS\system32\D3DCompiler_38.dll
    2009-09-02 23:31:02 ----A---- C:\WINDOWS\system32\XAudio2_0.dll
    2009-09-02 23:31:02 ----A---- C:\WINDOWS\system32\D3DX9_38.dll
    2009-09-02 23:31:01 ----A---- C:\WINDOWS\system32\xactengine3_0.dll
    2009-09-02 23:31:01 ----A---- C:\WINDOWS\system32\X3DAudio1_3.dll
    2009-09-02 23:31:00 ----A---- C:\WINDOWS\system32\D3DX9_37.dll
    2009-09-02 23:31:00 ----A---- C:\WINDOWS\system32\d3dx10_37.dll
    2009-09-02 23:31:00 ----A---- C:\WINDOWS\system32\D3DCompiler_37.dll
    2009-09-02 23:30:59 ----A---- C:\WINDOWS\system32\xactengine2_10.dll
    2009-09-02 23:30:58 ----A---- C:\WINDOWS\system32\d3dx10_36.dll
    2009-09-02 23:30:58 ----A---- C:\WINDOWS\system32\D3DCompiler_36.dll
    2009-09-02 23:30:57 ----A---- C:\WINDOWS\system32\xactengine2_9.dll
    2009-09-02 23:30:57 ----A---- C:\WINDOWS\system32\d3dx9_36.dll
    2009-09-02 23:30:56 ----A---- C:\WINDOWS\system32\d3dx9_35.dll
    2009-09-02 23:30:56 ----A---- C:\WINDOWS\system32\d3dx10_35.dll
    2009-09-02 23:30:56 ----A---- C:\WINDOWS\system32\D3DCompiler_35.dll
    2009-09-02 23:30:55 ----A---- C:\WINDOWS\system32\xactengine2_8.dll
    2009-09-02 23:30:55 ----A---- C:\WINDOWS\system32\X3DAudio1_2.dll
    2009-09-02 23:30:55 ----A---- C:\WINDOWS\system32\d3dx10_34.dll
    2009-09-02 23:30:55 ----A---- C:\WINDOWS\system32\D3DCompiler_34.dll
    2009-09-02 23:30:50 ----A---- C:\WINDOWS\system32\d3dx9_34.dll
    2009-09-02 23:30:35 ----A---- C:\WINDOWS\system32\xactengine2_7.dll
    2009-09-02 23:30:29 ----A---- C:\WINDOWS\system32\d3dx10_33.dll
    2009-09-02 23:30:29 ----A---- C:\WINDOWS\system32\D3DCompiler_33.dll
    2009-09-02 23:30:18 ----A---- C:\WINDOWS\system32\d3dx9_33.dll
    2009-09-02 23:30:17 ----A---- C:\WINDOWS\system32\xactengine2_6.dll
    2009-09-02 23:30:17 ----A---- C:\WINDOWS\system32\xactengine2_5.dll
    2009-09-02 23:30:16 ----A---- C:\WINDOWS\system32\xactengine2_4.dll
    2009-09-02 23:30:16 ----A---- C:\WINDOWS\system32\x3daudio1_1.dll
    2009-09-02 23:30:16 ----A---- C:\WINDOWS\system32\d3dx9_32.dll
    2009-09-02 23:30:16 ----A---- C:\WINDOWS\system32\d3dx9_31.dll
    2009-09-02 23:30:15 ----A---- C:\WINDOWS\system32\xinput1_2.dll
    2009-09-02 23:30:15 ----A---- C:\WINDOWS\system32\xactengine2_3.dll
    2009-09-02 23:30:15 ----A---- C:\WINDOWS\system32\xactengine2_2.dll
    2009-09-02 23:30:14 ----A---- C:\WINDOWS\system32\xinput1_1.dll
    2009-09-02 23:30:14 ----A---- C:\WINDOWS\system32\xactengine2_1.dll
    2009-09-02 23:30:03 ----A---- C:\WINDOWS\system32\d3dx9_30.dll
    2009-09-02 23:30:02 ----A---- C:\WINDOWS\system32\xactengine2_0.dll
    2009-09-02 23:30:02 ----A---- C:\WINDOWS\system32\x3daudio1_0.dll
    2009-09-02 23:30:02 ----A---- C:\WINDOWS\system32\d3dx9_29.dll
    2009-09-02 23:30:02 ----A---- C:\WINDOWS\system32\d3dx9_28.dll
    2009-09-02 23:30:01 ----A---- C:\WINDOWS\system32\xinput9_1_0.dll
    2009-09-02 23:29:59 ----A---- C:\WINDOWS\system32\d3dx9_26.dll
    2009-09-02 23:29:58 ----A---- C:\WINDOWS\system32\d3dx9_25.dll
    2009-09-02 23:29:56 ----A---- C:\WINDOWS\system32\d3dx9_24.dll
    2009-09-02 23:29:24 ----D---- C:\WINDOWS\Logs
    2009-09-02 22:18:29 ----HD---- C:\Program Files\Zero G Registry
    2009-09-02 22:18:29 ----D---- C:\Program Files\Sports Interactive
    2009-09-02 11:49:37 ----D---- C:\Documents and Settings\Administrateur\Application Data\Spotify
    2009-09-01 21:26:24 ----D---- C:\Documents and Settings\All Users\Application Data\Adobe
    2009-09-01 21:25:28 ----D---- C:\Program Files\Fichiers communs\Adobe
    2009-09-01 21:25:28 ----D---- C:\Program Files\Adobe
    2009-09-01 21:06:38 ----D---- C:\Downloads
    2009-09-01 21:00:14 ----D---- C:\Program Files\NOS
    2009-09-01 21:00:14 ----D---- C:\Documents and Settings\All Users\Application Data\NOS
    2009-08-30 21:13:30 ----D---- C:\WINDOWS\Sun
    2009-08-30 16:59:58 ----D---- C:\Program Files\Microsoft Works
    2009-08-30 16:59:10 ----D---- C:\Program Files\Microsoft Visual Studio
    2009-08-30 16:59:09 ----D---- C:\Program Files\Fichiers communs\DESIGNER
    2009-08-30 16:58:02 ----D---- C:\Program Files\Microsoft.NET
    2009-08-30 16:41:43 ----D---- C:\Program Files\Microsoft Visual Studio 8
    2009-08-30 16:41:03 ----D---- C:\WINDOWS\SHELLNEW
    2009-08-30 16:40:06 ----D---- C:\Program Files\Microsoft Office
    2009-08-30 16:40:01 ----D---- C:\Documents and Settings\All Users\Application Data\Microsoft Help
    2009-08-30 16:38:27 ----RHD---- C:\MSOCache
    2009-08-29 01:21:55 ----A---- C:\WINDOWS\system32\d3dx9_27.dll
    2009-08-29 00:12:00 ----A---- C:\WINDOWS\ScUnin.exe
    2009-08-29 00:10:05 ----D---- C:\Program Files\Starcraft
    2009-08-28 21:27:34 ----A---- C:\AILog.txt
    2009-08-28 02:05:02 ----D---- C:\Documents and Settings\Administrateur\Application Data\Free Download Manager
    2009-08-28 02:04:57 ----D---- C:\Program Files\Free Download Manager
    2009-08-28 02:00:48 ----HDC---- C:\WINDOWS\$NtUninstallKB968389$
    2009-08-28 01:33:28 ----D---- C:\Program Files\Core Design
    2009-08-28 01:33:28 ----A---- C:\WINDOWS\system32\Winstr.dll
    2009-08-28 01:33:28 ----A---- C:\WINDOWS\system32\Winsdec.dll
    2009-08-28 01:33:28 ----A---- C:\WINDOWS\system32\Winplay.dll
    2009-08-28 01:33:28 ----A---- C:\WINDOWS\system32\Edec.dll
    2009-08-28 01:33:28 ----A---- C:\WINDOWS\system32\Dec130.dll
    2009-08-28 01:32:32 ----A---- C:\WINDOWS\IsUninst.exe
    2009-08-27 18:25:41 ----HDC---- C:\WINDOWS\$NtUninstallWdf01001$
    2009-08-27 18:15:24 ----DC---- C:\WINDOWS\system32\DRVSTORE
    2009-08-27 18:15:24 ----A---- C:\WINDOWS\system32\WdfCoInstaller01001.dll
    2009-08-27 18:15:22 ----D---- C:\Program Files\Microsoft Xbox 360 Accessories
    2009-08-27 18:15:15 ----A---- C:\WINDOWS\system32\xinput1_3.dll
    2009-08-27 18:13:00 ----D---- C:\Documents and Settings\Administrateur\Application Data\WinRAR
    2009-08-27 18:12:29 ----D---- C:\Program Files\WinRAR
    2009-08-27 17:04:37 ----D---- C:\Documents and Settings\Administrateur\Application Data\vlc
    2009-08-27 15:02:35 ----D---- C:\Documents and Settings\Administrateur\Application Data\OpenOffice.org
    2009-08-27 02:02:28 ----HDC---- C:\WINDOWS\$NtUninstallKB961371-v2$
    2009-08-27 02:00:42 ----HDC---- C:\WINDOWS\$NtUninstallKB961118$
    2009-08-27 02:00:18 ----HDC---- C:\WINDOWS\$NtUninstallKB970653-v3$

    ======List of files/folders modified in the last 2 months======

    2009-10-26 19:18:15 ----RD---- C:\Program Files
    2009-10-26 18:18:20 ----D---- C:\WINDOWS\system32\drivers
    2009-10-26 17:45:43 ----D---- C:\WINDOWS\system32
    2009-10-26 15:12:07 ----D---- C:\Program Files\Mozilla Firefox
    2009-10-26 15:03:58 ----D---- C:\WINDOWS\system32\CatRoot2
    2009-10-26 15:03:23 ----SD---- C:\WINDOWS\Tasks
    2009-10-25 20:36:26 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
    2009-10-22 03:25:05 ----D---- C:\WINDOWS\system32\wbem
    2009-10-19 19:11:24 ----HD---- C:\WINDOWS\inf
    2009-10-19 17:23:16 ----D---- C:\WINDOWS
    2009-10-19 17:06:14 ----D---- C:\WINDOWS\WinSxS
    2009-10-19 17:06:12 ----D---- C:\Program Files\Fichiers communs\Microsoft Shared
    2009-10-19 17:06:11 ----SHD---- C:\WINDOWS\Installer
    2009-10-16 01:44:31 ----D---- C:\WINDOWS\Microsoft.NET
    2009-10-16 01:44:24 ----RSD---- C:\WINDOWS\assembly
    2009-10-16 00:33:42 ----A---- C:\WINDOWS\imsins.BAK
    2009-10-16 00:33:41 ----D---- C:\WINDOWS\system32\dllcache
    2009-10-16 00:32:50 ----D---- C:\WINDOWS\system32\fr-fr
    2009-10-16 00:32:50 ----D---- C:\Program Files\Internet Explorer
    2009-10-16 00:32:00 ----HD---- C:\WINDOWS\$hf_mig$
    2009-10-14 16:39:07 ----D---- C:\WINDOWS\Help
    2009-10-11 23:11:16 ----SD---- C:\WINDOWS\Downloaded Program Files
    2009-10-04 01:39:47 ----D---- C:\Program Files\Fichiers communs
    2009-10-03 14:08:20 ----D---- C:\WINDOWS\system
    2009-10-03 14:08:19 ----RSD---- C:\WINDOWS\Fonts
    2009-10-02 19:01:57 ----A---- C:\WINDOWS\system32\MRT.exe
    2009-09-20 20:12:46 ----A---- C:\WINDOWS\setuplog.txt
    2009-09-20 20:12:35 ----A---- C:\WINDOWS\system32\wpa.bak
    2009-09-18 18:51:18 ----D---- C:\Documents and Settings\Administrateur\Application Data\Microsoft
    2009-09-18 18:46:32 ----D---- C:\WINDOWS\Temp
    2009-09-18 18:46:32 ----D---- C:\WINDOWS\system32\DirectX
    2009-09-18 18:26:17 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft
    2009-09-15 18:12:01 ----A---- C:\WINDOWS\system32\comcat.dll
    2009-09-11 15:18:20 ----A---- C:\WINDOWS\system32\msv1_0.dll
    2009-09-08 13:22:53 ----HD---- C:\Program Files\InstallShield Installation Information
    2009-09-04 22:04:39 ----A---- C:\WINDOWS\system32\msasn1.dll
    2009-09-01 21:29:12 ----D---- C:\Documents and Settings\Administrateur\Application Data\Adobe
    2009-08-30 17:01:16 ----D---- C:\WINDOWS\system32\config
    2009-08-30 16:59:37 ----D---- C:\Program Files\MSBuild
    2009-08-30 16:41:17 ----A---- C:\WINDOWS\win.ini
    2009-08-30 16:41:13 ----D---- C:\Program Files\Fichiers communs\System
    2009-08-30 00:54:24 ----A---- C:\WINDOWS\SchedLgU.Txt
    2009-08-29 23:44:21 ----D---- C:\WINDOWS\Prefetch
    2009-08-29 08:28:35 ----A---- C:\WINDOWS\system32\wininet.dll
    2009-08-29 08:28:35 ----A---- C:\WINDOWS\system32\webcheck.dll
    2009-08-29 08:28:35 ----A---- C:\WINDOWS\system32\urlmon.dll
    2009-08-29 08:28:35 ----A---- C:\WINDOWS\system32\url.dll
    2009-08-29 08:28:34 ----N---- C:\WINDOWS\system32\pngfilt.dll
    2009-08-29 08:28:34 ----N---- C:\WINDOWS\system32\occache.dll
    2009-08-29 08:28:34 ----N---- C:\WINDOWS\system32\mstime.dll
    2009-08-29 08:28:34 ----N---- C:\WINDOWS\system32\msrating.dll
    2009-08-29 08:28:34 ----N---- C:\WINDOWS\system32\mshtmled.dll
    2009-08-29 08:28:29 ----A---- C:\WINDOWS\system32\mshtml.dll
    2009-08-29 08:28:27 ----A---- C:\WINDOWS\system32\msfeedsbs.dll
    2009-08-29 08:28:27 ----A---- C:\WINDOWS\system32\msfeeds.dll
    2009-08-29 08:28:26 ----N---- C:\WINDOWS\system32\jsproxy.dll
    2009-08-29 08:28:26 ----N---- C:\WINDOWS\system32\iernonce.dll
    2009-08-29 08:28:26 ----A---- C:\WINDOWS\system32\iertutil.dll
    2009-08-29 08:28:26 ----A---- C:\WINDOWS\system32\ieframe.dll
    2009-08-29 08:28:23 ----N---- C:\WINDOWS\system32\iedkcs32.dll
    2009-08-29 08:28:23 ----N---- C:\WINDOWS\system32\ieaksie.dll
    2009-08-29 08:28:23 ----A---- C:\WINDOWS\system32\ieencode.dll
    2009-08-29 08:28:23 ----A---- C:\WINDOWS\system32\ieapfltr.dll
    2009-08-29 08:28:22 ----N---- C:\WINDOWS\system32\ieakeng.dll
    2009-08-29 08:28:22 ----N---- C:\WINDOWS\system32\extmgr.dll
    2009-08-29 08:28:22 ----N---- C:\WINDOWS\system32\dxtrans.dll
    2009-08-29 08:28:22 ----N---- C:\WINDOWS\system32\dxtmsft.dll
    2009-08-29 08:28:22 ----A---- C:\WINDOWS\system32\icardie.dll
    2009-08-29 08:28:22 ----A---- C:\WINDOWS\system32\corpol.dll
    2009-08-29 08:28:22 ----A---- C:\WINDOWS\system32\advpack.dll
    2009-08-28 11:30:11 ----N---- C:\WINDOWS\system32\ie4uinit.exe
    2009-08-28 11:30:11 ----A---- C:\WINDOWS\system32\ieudinit.exe
    2009-08-27 06:18:41 ----N---- C:\WINDOWS\system32\ieakui.dll
    2009-08-27 02:01:41 ----D---- C:\WINDOWS\system32\CatRoot

    ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

    R1 avgio;avgio; \??\C:\Program Files\Avira\AntiVir Desktop\avgio.sys []
    R1 avipbb;avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [2009-03-30 96104]
    R1 intelppm;Pilote de processeur Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-13 40576]
    R1 ssmdrv;ssmdrv; C:\WINDOWS\system32\DRIVERS\ssmdrv.sys [2009-05-11 28520]
    R2 ANIO;ANIO Service; \??\C:\WINDOWS\system32\ANIO.SYS []
    R2 avgntflt;avgntflt; C:\WINDOWS\system32\DRIVERS\avgntflt.sys [2009-07-28 55656]
    R2 tmcomm;tmcomm; \??\C:\WINDOWS\system32\drivers\tmcomm.sys []
    R2 ubumapi;Unibrain 1394 FireAPI Driver; C:\WINDOWS\system32\DRIVERS\ubumapi.sys [2004-12-21 29824]
    R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2008-09-24 4122368]
    R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2006-05-03 1540608]
    R3 HidUsb;Pilote de classe HID Microsoft; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
    R3 mouhid;Pilote HID de souris; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-23 12288]
    R3 ubohci;Unibrain 1394 OHCI Driver; C:\WINDOWS\system32\DRIVERS\ubohci.sys [2004-12-21 72320]
    R3 ubsbp2;Unibrain SBP2 Bus Driver; C:\WINDOWS\system32\DRIVERS\ubsbp2.sys [2004-12-21 32768]
    R3 usbehci;Pilote miniport de contrôleur d'hôte amélioré Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
    R3 usbhub;Pilote de concentrateur standard USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
    R3 usbohci;Pilote miniport de contrôleur hôte ouvert USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbohci.sys [2008-04-13 17152]
    S3 abk5nj1k;abk5nj1k; C:\WINDOWS\system32\drivers\abk5nj1k.sys []
    S3 Arp1394;Protocole client ARP 1394; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-13 60800]
    S3 driverhardwarev2;driverhardwarev2; \??\C:\Program Files\ma-config.com\Drivers\driverhardwarev2.sys []
    S3 NIC1394;Pilote réseau 1394; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-13 61824]
    S3 RT73;D-Link USB Wireless LAN Card Driver; C:\WINDOWS\system32\DRIVERS\Dr71WU.sys [2006-12-21 429440]
    S3 RTL8023xp;Realtek 10/100/1000 PCI NIC Family NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtnicxp.sys [2009-01-29 118656]
    S3 rtl8139;Pilote NT de carte Realtek PCI Fast Ethernet à base RTL8139(A/B/C); C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2004-08-03 20992]
    S3 USBAAPL;Apple Mobile USB Driver; C:\WINDOWS\System32\Drivers\usbaapl.sys [2008-11-07 32000]
    S3 usbaudio;Pilote USB audio (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2008-04-13 60032]
    S3 USBSTOR;Pilote de stockage de masse USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
    S3 Wdf01000;Wdf01000; C:\WINDOWS\system32\DRIVERS\Wdf01000.sys [2006-04-19 479200]
    S3 xusb20;Xbox 360 Wireless Receiver for Windows Driver Service; C:\WINDOWS\system32\DRIVERS\xusb20.sys [2006-10-13 50048]
    S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []

    ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

    R2 ANIWZCSdService;ANIWZCSd Service; C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe [2007-01-19 49152]
    R2 AntiVirSchedulerService;Avira AntiVir Planificateur; C:\Program Files\Avira\AntiVir Desktop\sched.exe [2009-05-13 108289]
    R2 AntiVirService;Avira AntiVir Guard; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [2009-07-21 185089]
    R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2008-11-07 132424]
    R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2006-05-03 413696]
    R2 Bonjour Service;Service Bonjour; C:\Program Files\Bonjour\mDNSResponder.exe [2008-08-29 238888]
    R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-02-01 152984]
    S2 ATI Smart;ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [2006-05-03 520192]
    S2 gupdate1ca24aee8c590e;Service Google Update (gupdate1ca24aee8c590e); C:\Program Files\Google\Update\GoogleUpdate.exe [2009-08-24 133104]
    S2 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-08-24 194032]
    S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
    S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
    S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
    S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
    S3 maconfservice;Ma-Config Service; C:\Program Files\ma-config.com\maconfservice.exe [2009-01-24 216232]
    S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
    S3 ose;Office Source Engine; C:\Program Files\Fichiers communs\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
    S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

    -----------------EOF-----------------

    CA FAIT LONG TOuT CA ! Merci beaucoup de ton aide en tout cas !
    0
    1. Utilisateur anonyme
       
      Re

      1)
      # Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
      Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
      Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.

      Télécharge et install UsbFix de C_XX
      Ici : http://pagesperso-orange.fr/NosTools/Chiquitine29/UsbFix.exe

      Tutorial de Malekal_Morte si besoin, merci à lui : https://www.malekal.com/usbfix-supprimer-virus-usb/

      Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) suceptible d avoir été infectés sans les ouvrir

      # Double clic sur le raccourci UsbFix présent sur ton bureau.

      # Choisi l option 1 (Recherche)

      # Laisse travailler l outil.

      # Ensuite post le rapport UsbFix.txt qui apparaîtra.

      # Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque. ( C:\UsbFix.txt )

      ( CTRL+A Pour tout sélectionner , CTRL+C pour copier et CTRL+V pour coller )

      @+
      0
  6. Frech
     
    Et voilà le second, dit INFO :

    info.txt logfile of random's system information tool 1.06 2009-10-26 19:18:31

    ======Uninstall list======

    -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
    Adobe Download Manager-->"C:\WINDOWS\system32\rundll32.exe" "C:\Program Files\NOS\bin\getPlus_Helper.dll",Uninstall /Get1
    Adobe Flash Player 10 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
    Adobe Flash Player 10 Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
    Adobe Reader 9.1 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A91000000001}
    Age of Mythology-->"C:\Program Files\Microsoft Games\Age of Mythology\UNINSTAL.EXE" /runtemp /addremove
    ANIO Service-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7B5CE976-C7A9-4E38-A7F3-6C8EF025DD8E}\Setup.exe"
    ANIWZCS2 Service-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{4C590030-7469-453E-8589-D15DA9D03F52}\Setup.exe"
    Apple Mobile Device Support-->MsiExec.exe /I{EC4455AB-F155-4CC1-A4C5-88F3777F9886}
    Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
    Archiveur WinRAR-->C:\Program Files\WinRAR\uninstall.exe
    Assistant de connexion Windows Live-->MsiExec.exe /I{DCE8CD14-FBF5-4464-B9A4-E18E473546C7}
    ATI - Software Uninstall Utility-->C:\Program Files\ATI Technologies\UninstallAll\AtiCimUn.exe
    ATI Display Driver-->rundll32 C:\WINDOWS\system32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
    Avira AntiVir Personal - Free Antivirus-->C:\Program Files\Avira\AntiVir Desktop\setup.exe /REMOVE
    Bonjour-->MsiExec.exe /I{8A25392D-C5D2-4E79-A2BD-C15DDC5B0959}
    Correctif pour Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
    Correctif pour Windows XP (KB961118)-->"C:\WINDOWS\$NtUninstallKB961118$\spuninst\spuninst.exe"
    Correctif pour Windows XP (KB970653-v3)-->"C:\WINDOWS\$NtUninstallKB970653-v3$\spuninst\spuninst.exe"
    Diablo II-->C:\WINDOWS\DIIUnin.exe C:\WINDOWS\DIIUnin.dat
    D-Link Wireless G DWA-110-->C:\Program Files\InstallShield Installation Information\{5F753314-628E-4C13-B8AE-BFA7FD514CBE}\setup.exe -runfromtemp -l0x040c -removeonly
    Dreamfall-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D751B34C-058F-42EF-BE95-14EBB0D2C585}\setup.exe" -l0x40c -removeonly
    eMule-->"D:\Program Files\eMule\Uninstall.exe"
    Football Manager 2009-->"D:\Program Files\Sports Interactive\Football Manager 2009\Uninstall_Football Manager 2009\Désinstaller Football Manager 2009.exe"
    Free Easy Burner V 3.8-->"C:\Program Files\Free Easy Burner\unins000.exe"
    Galerie de photos Windows Live-->MsiExec.exe /X{B131E59D-202C-43C6-84C9-68F0C37541F1}
    Google Chrome-->"C:\Program Files\Google\Chrome\Application\3.0.195.27\Installer\setup.exe" --uninstall --system-level
    Google Update Helper-->MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
    Google Earth-->MsiExec.exe /X{CC016F21-3970-11DE-B878-005056806466}
    Gruntz-->C:\WINDOWS\unin040c.exe -fC:\Games\Gruntz\DeIsL1.isu
    HijackThis 2.0.2-->"D:\HijackThis.exe" /uninstall
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
    Installation Windows Live-->C:\Program Files\Windows Live\Installer\wlarp.exe
    Installation Windows Live-->MsiExec.exe /I{46ABBC54-1872-4AA3-95E2-F2C063A63F31}
    Java(TM) 6 Update 11-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216011FF}
    Java(TM) 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
    Legacy of Kain: Soul Reaver-->C:\WINDOWS\IsUninst.exe -f"C:\Program Files\Eidos Interactive\Soul Reaver\UninstSR.isu"
    Ma-Config.com-->MsiExec.exe /X{8AFB8FC4-3EBA-4C67-943F-CF43DB2180F1}
    Malwarebytes' Anti-Malware-->"D:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
    Max Payne-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{39930321-4C58-4B8B-BCBF-342698C9801D}\setup.exe" uninstall uninstall
    Microsoft .NET Framework 2.0 Service Pack 2-->MsiExec.exe /I{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}
    Microsoft .NET Framework 3.0 Service Pack 2-->MsiExec.exe /I{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}
    Microsoft .NET Framework 3.5 SP1-->C:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
    Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
    Microsoft Age of Empires II : The Conquerors Expansion-->"D:\Program Files\UNINSTALX.EXE" /runtemp /addremove
    Microsoft Age of Empires II-->"D:\Program Files\UNINSTAL.EXE" /runtemp /uninstall
    Microsoft Choice Guard-->MsiExec.exe /X{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}
    Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
    Microsoft Kernel-Mode Driver Framework Feature Pack 1.1-->"C:\WINDOWS\$NtUninstallWdf01001$\spuninst\spuninst.exe"
    Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
    Microsoft Office Access MUI (French) 2007-->MsiExec.exe /X{90120000-0015-040C-0000-0000000FF1CE}
    Microsoft Office Excel MUI (French) 2007-->MsiExec.exe /X{90120000-0016-040C-0000-0000000FF1CE}
    Microsoft Office InfoPath MUI (French) 2007-->MsiExec.exe /X{90120000-0044-040C-0000-0000000FF1CE}
    Microsoft Office Live Add-in 1.3-->MsiExec.exe /I{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}
    Microsoft Office Outlook MUI (French) 2007-->MsiExec.exe /X{90120000-001A-040C-0000-0000000FF1CE}
    Microsoft Office PowerPoint MUI (French) 2007-->MsiExec.exe /X{90120000-0018-040C-0000-0000000FF1CE}
    Microsoft Office Professional Plus 2007-->"C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall PROPLUS /dll OSETUP.DLL
    Microsoft Office Professional Plus 2007-->MsiExec.exe /X{90120000-0011-0000-0000-0000000FF1CE}
    Microsoft Office Proof (Arabic) 2007-->MsiExec.exe /X{90120000-001F-0401-0000-0000000FF1CE}
    Microsoft Office Proof (Dutch) 2007-->MsiExec.exe /X{90120000-001F-0413-0000-0000000FF1CE}
    Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
    Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
    Microsoft Office Proof (German) 2007-->MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}
    Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
    Microsoft Office Proofing (French) 2007-->MsiExec.exe /X{90120000-002C-040C-0000-0000000FF1CE}
    Microsoft Office Publisher MUI (French) 2007-->MsiExec.exe /X{90120000-0019-040C-0000-0000000FF1CE}
    Microsoft Office Shared MUI (French) 2007-->MsiExec.exe /X{90120000-006E-040C-0000-0000000FF1CE}
    Microsoft Office Word MUI (French) 2007-->MsiExec.exe /X{90120000-001B-040C-0000-0000000FF1CE}
    Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
    Microsoft SQL Server 2005 Compact Edition [ENU]-->MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
    Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148-->MsiExec.exe /X{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17-->MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475}
    Microsoft Xbox 360 Accessories 1.1-->MsiExec.exe /X{7ACDE995-61E8-41C6-86AD-86579F26A200}
    Mise à jour de sécurité pour Lecteur Windows Media (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Lecteur Windows Media (KB954155)-->"C:\WINDOWS\$NtUninstallKB954155_WM9$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Lecteur Windows Media (KB968816)-->"C:\WINDOWS\$NtUninstallKB968816_WM9$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Lecteur Windows Media (KB973540)-->"C:\WINDOWS\$NtUninstallKB973540_WM9$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows Internet Explorer 7 (KB938127-v2)-->"C:\WINDOWS\ie7updates\KB938127-v2-IE7\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows Internet Explorer 7 (KB956390)-->"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows Internet Explorer 7 (KB958215)-->"C:\WINDOWS\ie7updates\KB958215-IE7\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows Internet Explorer 7 (KB972260)-->"C:\WINDOWS\ie7updates\KB972260-IE7\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows Internet Explorer 7 (KB974455)-->"C:\WINDOWS\ie7updates\KB974455-IE7\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB923561)-->"C:\WINDOWS\$NtUninstallKB923561$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB923789)-->C:\WINDOWS\system32\MacroMed\Flash\genuinst.exe C:\WINDOWS\system32\MacroMed\Flash\KB923789.inf
    Mise à jour de sécurité pour Windows XP (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB952004)-->"C:\WINDOWS\$NtUninstallKB952004$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB954211)-->"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB954459)-->"C:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB954600)-->"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB956391)-->"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB956572)-->"C:\WINDOWS\$NtUninstallKB956572$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB956744)-->"C:\WINDOWS\$NtUninstallKB956744$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB956841)-->"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB956844)-->"C:\WINDOWS\$NtUninstallKB956844$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB958215)-->"C:\WINDOWS\$NtUninstallKB958215$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB958687)-->"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB958869)-->"C:\WINDOWS\$NtUninstallKB958869$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB959426)-->"C:\WINDOWS\$NtUninstallKB959426$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB960225)-->"C:\WINDOWS\$NtUninstallKB960225$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB960714)-->"C:\WINDOWS\$NtUninstallKB960714$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB960803)-->"C:\WINDOWS\$NtUninstallKB960803$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB960859)-->"C:\WINDOWS\$NtUninstallKB960859$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB961371-v2)-->"C:\WINDOWS\$NtUninstallKB961371-v2$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB961501)-->"C:\WINDOWS\$NtUninstallKB961501$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB968537)-->"C:\WINDOWS\$NtUninstallKB968537$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB969059)-->"C:\WINDOWS\$NtUninstallKB969059$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB970238)-->"C:\WINDOWS\$NtUninstallKB970238$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB971486)-->"C:\WINDOWS\$NtUninstallKB971486$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB971557)-->"C:\WINDOWS\$NtUninstallKB971557$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB971633)-->"C:\WINDOWS\$NtUninstallKB971633$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB971657)-->"C:\WINDOWS\$NtUninstallKB971657$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB971961)-->"C:\WINDOWS\$NtUninstallKB971961$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB973346)-->"C:\WINDOWS\$NtUninstallKB973346$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB973354)-->"C:\WINDOWS\$NtUninstallKB973354$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB973507)-->"C:\WINDOWS\$NtUninstallKB973507$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB973525)-->"C:\WINDOWS\$NtUninstallKB973525$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB973869)-->"C:\WINDOWS\$NtUninstallKB973869$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB974112)-->"C:\WINDOWS\$NtUninstallKB974112$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB974571)-->"C:\WINDOWS\$NtUninstallKB974571$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB975025)-->"C:\WINDOWS\$NtUninstallKB975025$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB975467)-->"C:\WINDOWS\$NtUninstallKB975467$\spuninst\spuninst.exe"
    Mise à jour pour Windows XP (KB898461)-->"C:\WINDOWS\$NtUninstallKB898461$\spuninst\spuninst.exe"
    Mise à jour pour Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
    Mise à jour pour Windows XP (KB955839)-->"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
    Mise à jour pour Windows XP (KB961503)-->"C:\WINDOWS\$NtUninstallKB961503$\spuninst\spuninst.exe"
    Mise à jour pour Windows XP (KB967715)-->"C:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe"
    Mise à jour pour Windows XP (KB968389)-->"C:\WINDOWS\$NtUninstallKB968389$\spuninst\spuninst.exe"
    Mise à jour pour Windows XP (KB973815)-->"C:\WINDOWS\$NtUninstallKB973815$\spuninst\spuninst.exe"
    Mozilla Firefox (3.5.3)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
    MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
    MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
    MSXML4 Parser-->MsiExec.exe /I{01501EBA-EC35-4F9F-8889-3BE346E5DA13}
    OpenOffice.org 3.0-->MsiExec.exe /I{6860B340-530D-46B3-91F8-1AE1F70F7C33}
    Outil de mise à jour Google-->"C:\Program Files\Google\Google Updater\GoogleUpdater.exe" -uninstall
    Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
    PPMate Network TV 2.3.3.6-->D:\Program Files\PPMate\uninst.exe
    QuickTime-->MsiExec.exe /I{F958CA02-BB40-4007-894B-258729456EE4}
    Realtek AC'97 Audio-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FB08F381-6533-4108-B7DD-039E11FBC27E}\setup.exe" -l0x40c -removeonly
    REALTEK GbE & FE Ethernet PCI NIC Driver-->C:\Program Files\InstallShield Installation Information\{ACCA20B0-C4D1-4BF5-BF21-0A0EB5EF9730}\setup.exe -runfromtemp -removeonly
    Security Update for 2007 Microsoft Office System (KB951944)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {797AE457-BA17-4BBC-B501-25FB3A0103C7}
    Segoe UI-->MsiExec.exe /I{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}
    SiSRaidPackage-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{13D41D72-0284-4931-A261-F86F6565D4B4}\setup.exe" -l0x40c
    SopCast 3.2.4-->D:\Program Files\SopCast\uninst.exe
    Spotify-->"D:\Program Files\Spotify\uninstall.exe"
    Starcraft-->C:\WINDOWS\scunin.exe C:\WINDOWS\scunin.dat
    Stream Torrent 1.0-->"D:\Program Files\StreamTorrent 1.0\uninstall.exe"
    Tomb Raider II-->C:\WINDOWS\IsUninst.exe -f"C:\Program Files\Core Design\Tomb Raider II\Uninst.isu"
    TubeMaster++ 1.5-->"D:\Program Files\TubeMaster++\unins000.exe"
    TVAnts 1.0-->D:\PROGRA~1\TVAnts\UNWISE.EXE D:\PROGRA~1\TVAnts\INSTALL.LOG
    ubCore-->C:\Program Files\Fichiers communs\InstallShield\Driver\8\Intel 32\IDriver.exe /M{4321CFD4-27B9-4955-BCD9-A4920090CFFF}
    Unreal Tournament G.O.T.Y. Edition-->C:\UnrealTournament\System\Setup.exe uninstall "UnrealTournament"
    Unreal-->C:\WINDOWS\IsUn040c.exe -fC:\Unreal\System\Uninst.isu
    Update for 2007 Microsoft Office System (KB967642)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {C444285D-5E4F-48A4-91DD-47AAAA68E92D}
    Update for Microsoft .NET Framework 3.5 SP1 (KB963707)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {B2AE9C82-DC7B-3641-BFC8-87275C4F3607} /qb+ REBOOTPROMPT=""
    Update for Outlook 2007 Junk Email Filter (KB974810)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {C05FBAD5-A211-4E86-BB51-7E07B80C9233}
    VDMSound-->C:\Program Files\VDMSound\uninst.exe
    VLC media player 0.9.8a-->C:\Program Files\VideoLAN\VLC\uninstall.exe
    Windows Internet Explorer 7-->"C:\WINDOWS\ie7\spuninst\spuninst.exe"
    Windows Live Call-->MsiExec.exe /I{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}
    Windows Live Communications Platform-->MsiExec.exe /I{3B4E636E-9D65-4D67-BA61-189800823F52}
    Windows Live FolderShare-->MsiExec.exe /X{2075CB0A-D26F-4DAA-B424-5079296B43BA}
    Windows Live Messenger-->MsiExec.exe /X{770F1BEC-2871-4E70-B837-FB8525FFA3B1}
    Windows Live OneCare safety scanner-->RunDll32.exe "C:\Program Files\Windows Live Safety Center\wlscCore.dll",UninstallFunction WLSC_SCANNER_PRODUCT
    Windows Live Writer-->MsiExec.exe /X{4634B21A-CC07-4396-890C-2B8168661FEA}
    Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"

    ======Security center information======

    AV: AntiVir Desktop

    ======System event log======

    Computer Name: PERSO
    Event Code: 7036
    Message: Le service Google Software Updater est entré dans l'état : arrêté.

    Record Number: 4669
    Source Name: Service Control Manager
    Time Written: 20091011212642.000000+120
    Event Type: Informations
    User:

    Computer Name: PERSO
    Event Code: 4201
    Message: Le système a détecté que la carte réseau \DEVICE\TCPIP_{A99703C0-6F76-4EAE-B395-CF6C382974AA} était connectée au réseau,
    et a lancé une opération normale sur la carte réseau.

    Record Number: 4668
    Source Name: Tcpip
    Time Written: 20091011212638.000000+120
    Event Type: Informations
    User:

    Computer Name: PERSO
    Event Code: 7036
    Message: Le service Service Google Update (gupdate1ca24aee8c590e) est entré dans l'état : arrêté.

    Record Number: 4667
    Source Name: Service Control Manager
    Time Written: 20091011212557.000000+120
    Event Type: Informations
    User:

    Computer Name: PERSO
    Event Code: 35
    Message: Le service de temps synchronise maintenant l'heure système avec la
    source de temps time.windows.com (ntp.m|0x1|192.168.1.5:123->207.46.232.182:123).

    Record Number: 4666
    Source Name: W32Time
    Time Written: 20091011212540.000000+120
    Event Type: Informations
    User:

    Computer Name: PERSO
    Event Code: 7036
    Message: Le service Service COM de gravage de CD IMAPI est entré dans l'état : arrêté.

    Record Number: 4665
    Source Name: Service Control Manager
    Time Written: 20091011212545.000000+120
    Event Type: Informations
    User:

    =====Application event log=====

    Computer Name: PERSO
    Event Code: 1000
    Message: Application défaillante vlc.exe, version 0.9.8.1, module défaillant libvlccore.dll, version 0.9.8.1, adresse de défaillance 0x000702bc.

    Record Number: 374
    Source Name: Application Error
    Time Written: 20090827180257.000000+120
    Event Type: erreur
    User:

    Computer Name: PERSO
    Event Code: 1000
    Message: Application défaillante vlc.exe, version 0.9.8.1, module défaillant libvlccore.dll, version 0.9.8.1, adresse de défaillance 0x000702bc.

    Record Number: 373
    Source Name: Application Error
    Time Written: 20090827180257.000000+120
    Event Type: erreur
    User:

    Computer Name: PERSO
    Event Code: 1000
    Message: Application défaillante vlc.exe, version 0.9.8.1, module défaillant libvlccore.dll, version 0.9.8.1, adresse de défaillance 0x0006ffe4.

    Record Number: 372
    Source Name: Application Error
    Time Written: 20090827180257.000000+120
    Event Type: erreur
    User:

    Computer Name: PERSO
    Event Code: 1000
    Message: Application défaillante vlc.exe, version 0.9.8.1, module défaillant libvlccore.dll, version 0.9.8.1, adresse de défaillance 0x000702bc.

    Record Number: 371
    Source Name: Application Error
    Time Written: 20090827180257.000000+120
    Event Type: erreur
    User:

    Computer Name: PERSO
    Event Code: 1000
    Message: Application défaillante vlc.exe, version 0.9.8.1, module défaillant libvlccore.dll, version 0.9.8.1, adresse de défaillance 0x000702bc.

    Record Number: 370
    Source Name: Application Error
    Time Written: 20090827180257.000000+120
    Event Type: erreur
    User:

    ======Environment variables======

    "ComSpec"=%SystemRoot%\system32\cmd.exe
    "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\VDMSound;C:\Program Files\VDMSound;C:\Program Files\QuickTime\QTSystem\
    "windir"=%SystemRoot%
    "FP_NO_HOST_CHECK"=NO
    "OS"=Windows_NT
    "PROCESSOR_ARCHITECTURE"=x86
    "PROCESSOR_LEVEL"=15
    "PROCESSOR_IDENTIFIER"=x86 Family 15 Model 4 Stepping 1, GenuineIntel
    "PROCESSOR_REVISION"=0401
    "NUMBER_OF_PROCESSORS"=1
    "TEMP"=%USERPROFILE%\Local Settings\Temp
    "TMP"=%USERPROFILE%\Local Settings\Temp
    "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
    "KTD"=C:\WINDOWS\DriverPacks
    "VDMSPath"=C:\Program Files\VDMSound
    "CLASSPATH"=.;C:\Program Files\Java\jre6\lib\ext\QTJava.zip
    "QTJAVA"=C:\Program Files\Java\jre6\lib\ext\QTJava.zip

    -----------------EOF-----------------
    0
  7. Frech
     
    Ok USBFix c'est en train de tourner ! Donc RSIT n'a rien détecté d'anormal sur le PC ? Ni de grave ou d'important ?

    Pour le scan de RSIT je n'ai pas pu déconnecter Avira Anti Vir, ce n'est pas important ?

    Merci !
    0
  8. Frech
     
    Et HOP voilà le rapport USB Fix !

    ############################## | UsbFix V6.045 |

    User : Administrateur (Administrateurs) # PERSO
    Update on 24/10/2009 by Chiquitine29, C_XX & Chimay8
    Start at: 19:34:21 | 26/10/2009
    Website : http://pagesperso-orange.fr/NosTools/index.html
    Contact : FindyKill.Contact@gmail.com

    Intel(R) Celeron(R) CPU 2.80GHz
    Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 3
    Internet Explorer 7.0.5730.13
    Windows Firewall Status : Enabled
    AV : AntiVir Desktop 9.0.1.32 [ Enabled | Updated ]

    C:\ -> Disque fixe local # 48,83 Go (25,96 Go free) # NTFS
    D:\ -> Disque fixe local # 65,66 Go (22,38 Go free) # NTFS
    E:\ -> Disque CD-ROM
    F:\ -> Disque CD-ROM
    G:\ -> Disque amovible # 941,73 Mo (98,41 Mo free) [UDISK 2.0] # FAT
    H:\ -> Disque CD-ROM
    I:\ -> Disque CD-ROM

    ############################## | Processus actifs |

    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Avira\AntiVir Desktop\sched.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
    C:\Program Files\Avira\AntiVir Desktop\avguard.exe
    C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Google\Update\GoogleUpdate.exe
    C:\WINDOWS\System32\alg.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\WINDOWS\system32\NOTEPAD.EXE
    C:\WINDOWS\system32\NOTEPAD.EXE
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Windows NT\Pinball\PINBALL.EXE
    C:\WINDOWS\system32\taskmgr.exe
    C:\PROGRA~1\FREEDO~1\FDM.exe
    C:\WINDOWS\system32\wbem\wmiprvse.exe

    ################## | Fichiers # Dossiers infectieux |

    C:\DOCUME~1\ADMINI~1\Bureau\u95.exe
    G:\autorun.inf

    ################## | Registre # Clés Run infectieuses |

    ################## | Registre # Mountpoints2 |

    HKCU\..\..\Explorer\MountPoints2\{4b85f96e-9321-11de-81f7-0022b00d04c6}
    Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL autorun.exe

    HKCU\..\..\Explorer\MountPoints2\{5120ebe1-9312-11de-81f6-0022b00d04c6}
    Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL autorun.exe

    HKCU\..\..\Explorer\MountPoints2\{6adf94c7-abce-11de-8224-0022b00d04c6}
    Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL autorun.exe

    HKCU\..\..\Explorer\MountPoints2\{90242ffc-a2bf-11de-8217-0022b00d04c6}
    Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL autorun.exe

    ################## | Suspect | https://www.virustotal.com/gui/ |

    ################## | Cracks / Keygens / Serials |

    ################## | ! Fin du rapport # UsbFix V6.045 ! |
    0
    1. Utilisateur anonyme
       
      Re

      Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptible d avoir été infectés sans les ouvrir

      # Double clic sur le raccourci UsbFix présent sur ton bureau

      # choisi l option 2 (Suppression)

      # Ton bureau disparaîtra et le pc redémarrera.

      # Au redémarrage, UsbFix scannera ton pc, laisse travailler l outil.

      # Ensuite post le rapport UsbFix.txt qui apparaîtra avec le bureau.

      # Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque.( C:\UsbFix.txt )

      ( CTRL+A Pour tout sélectionner , CTRL+C pour copier et CTRL+V pour coller )


      @+
      0
  9. Frech
     
    Et voilà le rapport final :

    ############################# | UsbFix V6.045 |

    User : Administrateur (Administrateurs) # PERSO
    Update on 24/10/2009 by Chiquitine29, C_XX & Chimay8
    Start at: 20:33:54 | 26/10/2009
    Website : http://pagesperso-orange.fr/NosTools/index.html
    Contact : FindyKill.Contact@gmail.com

    Intel(R) Celeron(R) CPU 2.80GHz
    Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 3
    Internet Explorer 7.0.5730.13
    Windows Firewall Status : Enabled
    AV : AntiVir Desktop 9.0.1.32 [ Enabled | Updated ]

    C:\ -> Disque fixe local # 48,83 Go (26,23 Go free) # NTFS
    D:\ -> Disque fixe local # 65,66 Go (22,31 Go free) # NTFS
    E:\ -> Disque CD-ROM
    F:\ -> Disque CD-ROM
    G:\ -> Disque amovible # 941,73 Mo (98,41 Mo free) [UDISK 2.0] # FAT
    H:\ -> Disque CD-ROM
    I:\ -> Disque CD-ROM

    ############################## | Processus actifs |

    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\logonui.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Avira\AntiVir Desktop\sched.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
    C:\Program Files\Avira\AntiVir Desktop\avguard.exe
    C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Google\Update\GoogleUpdate.exe
    C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\Google\Update\GoogleUpdate.exe
    C:\WINDOWS\system32\wbem\wmiprvse.exe
    C:\WINDOWS\System32\alg.exe
    C:\WINDOWS\system32\wbem\wmiprvse.exe

    ################## | Fichiers # Dossiers infectieux |

    Supprimé ! C:\DOCUME~1\ADMINI~1\Bureau\u95.exe
    Supprimé ! G:\autorun.inf

    ################## | Registre # Clés Run infectieuses |

    ################## | Registre # Mountpoints2 |

    Supprimé ! HKCU\...\Explorer\MountPoints2\{4b85f96e-9321-11de-81f7-0022b00d04c6}\Shell\AutoRun\Command
    Supprimé ! HKCU\...\Explorer\MountPoints2\{6adf94c7-abce-11de-8224-0022b00d04c6}\Shell\AutoRun\Command
    Supprimé ! HKCU\...\Explorer\MountPoints2\{90242ffc-a2bf-11de-8217-0022b00d04c6}\Shell\AutoRun\Command

    ################## | Listing des fichiers présent |

    [05/10/2009 16:10|--a------|2485] C:\a.jpg
    [05/09/2009 15:34|--a------|0] C:\AILog.txt
    [28/01/2009 23:21|--a------|0] C:\AUTOEXEC.BAT
    [28/01/2009 23:16|---hs----|212] C:\boot.ini
    [05/08/2004 14:00|-rahs----|4952] C:\Bootfont.bin
    [28/01/2009 23:21|--a------|0] C:\CONFIG.SYS
    [28/01/2009 23:27|--a------|14426] C:\DPsFnshr.log
    [?|?|?] C:\hiberfil.sys
    [28/01/2009 23:21|-rahs----|0] C:\IO.SYS
    [28/01/2009 23:21|-rahs----|0] C:\MSDOS.SYS
    [05/08/2004 14:00|-rahs----|47564] C:\NTDETECT.COM
    [29/01/2009 00:40|-rahs----|252240] C:\ntldr
    [29/02/2004 16:44|--a------|52576] C:\orange.bmp
    [?|?|?] C:\pagefile.sys
    [26/10/2009 17:49|--a------|5282] C:\rapport.txt
    [26/10/2009 20:37|--a------|3295] C:\UsbFix.txt
    [21/10/2009 08:21|--a------|3342809] D:\eMule0.49c-Installer.exe
    [30/08/2009 18:55|--ah-----|2286977024] D:\fm2009-tl-DiABLO.is
    [30/08/2009 18:49|--ah-----|1040000000] D:\FM9.part1.rar
    [26/10/2009 20:31|--ah-----|732772352] D:\H2G2 - Le Guide du Voyageur Galactique.avi
    [26/10/2009 19:09|--a------|732772352] D:\H2G2.avi
    [01/09/2009 21:27|--a------|570027] D:\INT18071364.pdf
    [25/10/2009 20:45|--a------|3976784] D:\RegistryEasy.exe
    [20/10/2009 20:45|--a------|328378274] D:\Serie - CSI - Saison 02E01 - Une Mort EtouffǸe.avi
    [20/10/2009 21:47|--a------|368098272] D:\Serie - CSI - Saison 02E02 - Victime Sans Coupable.avi
    [20/10/2009 16:36|--a------|7040498] D:\setup_tm++.exe
    [04/10/2009 21:03|--ah-----|5419576] D:\SopCast.zip
    [14/10/2009 16:30|--a------|2869440] D:\spotify.exe
    [20/10/2009 16:32|--a------|165379] D:\Spotify_ripper.rar
    [20/10/2009 16:30|--a------|20824127] D:\Streamy_4.0_beta_M4.win32.win32.x86.zip
    [16/10/2009 15:25|--ah-----|734009344] D:\The.Chaser.FRENCH.DVDRIP.2009.avi
    [26/10/2009 19:33|--a------|806644] D:\UsbFix.exe
    [18/09/2009 18:26|--a------|1164624] D:\wlsetup-custom.exe
    [25/03/2009 02:31|--a------|17292183] G:\Guide Resident Evil 5.pdf
    [05/04/2008 12:21|--a------|59782440] G:\itunes_itunes_7.6.2_francais_11140.exe
    [17/12/2008 03:15|--a------|68756776] G:\iTunesSetup.exe
    [17/03/2009 05:10|--a------|1108330] G:\SharePod.zip
    [10/03/2009 12:41|--a------|2958336] G:\SharePod.exe
    [20/09/2009 17:26|--ah-----|4096] G:\._.Trashes
    [02/09/2009 00:36|--a------|25282] G:\FrechouMaximephoto.jpeg
    [02/09/2009 01:38|--a------|12811] G:\Curriculum Vitae.docx
    [03/09/2009 01:59|--a------|260418] G:\Curriculum Vitae.pdf
    [22/09/2009 16:14|--ah-----|4096] G:\._Laruns 2009
    [20/09/2009 18:18|--ah-----|4096] G:\._.TemporaryItems
    [07/10/2009 06:13|--a------|730093568] G:\Antarctic.Journal.2007.FRENCH.DVDRIP.XVID-BN.DIV.avi

    ################## | Vaccination |

    # C:\autorun.inf -> Folder created by UsbFix.
    # D:\autorun.inf -> Folder created by UsbFix.
    # G:\autorun.inf -> Folder created by UsbFix.

    ################## | Suspect | https://www.virustotal.com/gui/ |

    ################## | Cracks / Keygens / Serials |

    ################## | Upload |

    Veuillez envoyer le fichier : C:\DOCUME~1\ADMINI~1\Bureau\UsbFix_Upload_Me_PERSO.zip : https://www.androidworld.fr/
    Merci pour votre contribution .

    ################## | ! Fin du rapport # UsbFix V6.045 ! |
    0
  10. Frech
     
    Au passage, tu sais si on peut trouver des tutoriels pour apprendre à se débrouiller pour déchiffrer ces messages, rapports ? Ces logiciels ont l'air bien, et savoir s'en servir seul peut être important !
    0
  11. Frech
     
    Merci beaucoup de ton aide, mais USB Fix n'a pas résolu mon problème... Ma clé USB, et toutes celles que je connecte à mon PC, ont des fichiers dessus que je peux pas effacer...
    0
    1. Utilisateur anonyme
       
      Bonsoir

      Que veux tu dire par ne pas pouvoir effacer?
      Si tu formates ;est ce cela fonctionne?

      @+
      0
  12. Frech
     
    Eh bien j'ai toujours un fichier que je peux pas effacer sur ma clé USB, et sur les autres que je connecte à mon PC !

    Et impossible de fomater ! La clé est formatée en FAT, (FAt tout court, pas de 32 après), et lorsque je fais propriétés, pas de bouton "formater"... Etrange...
    0
    1. Utilisateur anonyme
       
      Bonsoir

      Quel est la marque et la capacité de tes clés Usb ?
      Quel est le nom du ou des fichiers que tu ne peux pas effacer?

      @+
      0