PC lourd !

Bonsoir,

Mon pc devient super lent et je pense qu'il est temps de faire un peu de ménage là-dedans. Merci infiniment de m'aider dans ma démarche.
antivirus : Avast familial
pare-feu : ashampoo
Configuration: Windows XP Internet Explorer 6.0

25 réponses

Résumé de la discussion

Problème de lenteur du PC nécessitant un nettoyage en profondeur, avec diagnostic des performances, suppression des infections et optimisation des paramètres système pour retrouver une expérience utilisateur fluide. Des mesures clés incluent la désinstallation des composants indésirables tels que Norton, la mise à jour de Windows XP vers SP3 et le recours à Malwarebytes' Anti-Malware pour un balayage complet du système. Des outils additionnels comme Ad-Remover et CCleaner aident à repérer et supprimer les barres d’outils et les entrées de registre indésirables, tout en corrigeant les paramètres du navigateur. À l’issue du balayage, les rapports générés (logs et quarantaine) offrent des éléments concrets à examiner et peuvent nécessiter un redémarrage pour finaliser la suppression des menaces.

Bobot (l’IA à votre service)
  1. supprime le restant de norton sur ton pc :

    • Pour désinstaller Norton
    http://service1.symantec.com/SUPPORT/INTER/tsgeninfointl.nsf/fr_docid/20050414110429924

    Un complément
    https://www.01net.com/telecharger/windows/Utilitaire/manipulation_de_fichier/fiches/32585.html

    fais une mise à jour de xp, passe à sp3.

    puis Télécharge Malwarebytes' Anti-Malware et enregistre le sur ton bureau:
    https://www.malekal.com/tutoriel-malwarebyte-anti-malware/

    ou ici : http://www.malwarebytes.org/mbam/program/mbam-setup.exe
    . Double cliques sur le fichier téléchargé pour lancer le processus d'installation.
    . Dans l'onglet "mise à jour", cliques sur le bouton Recherche de mise à jour
    . si le pare-feu demande l'autorisation de se connecter pour malwarebytes, acceptes
    . Une fois la mise à jour terminé
    . rend-toi dans l'onglet, Recherche
    . Sélectionnes Exécuter un examen complet
    . Cliques sur Rechercher
    . Le scan démarre.
    . A la fin de l'analyse, un message s'affiche : L'examen s'est terminé normalement. Cliquez sur 'Afficher les résultats' pour afficher tous les objets trouvés.
    . Cliques sur Ok pour poursuivre.
    . Si des malwares ont été détectés, cliques sur Afficher les résultats
    . Sélectionnes tout (ou laisses cochés) et cliques sur Supprimer la sélection Malwarebytes va détruire les fichiers et clés de registre et en mettre une copie dans la quarantaine
    .
    . Malwarebytes va ouvrir le bloc-notes et y copier le rapport d'analyse.
    . rends toi dans l'onglet rapport/log
    . tu cliques dessus pour l'afficher une fois affiché
    . tu cliques sur edition en haut du boc notes,et puis sur sélectionner tous
    . tu recliques sur edition et puis sur copier et tu reviens sur le forum et dans ta réponse
    . Tu cliques droit dans le cadre de la réponse et coller
    . À la fin du scan, il se peut que MBAM ait besoin de redémarrer le pc pour finaliser la suppression, donc pas de panique, redémarre ton pc !!!
    Si tu as besoin d'aide regarde ce tutoriel :
    https://www.malekal.com/tutoriel-malwarebyte-anti-malware/

    donne moi des nouvelles du fonctionnement de ton pc

    @++
    1. bonsoir,
      •Télécharge random's system information tool (RSIT) et enregistre le sur ton bureau.
      http://images.malwareremoval.com/random/RSIT.exe

      Tuto : https://forum.pcastuces.com/randoms_system_information_tool_rsit-f31s31.htm
      Double clique sur RSIT.exe pour lancer l'outil.
      Clique sur ' continue ' à l'écran Disclaimer.
      Si l'outil HIjackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera et tu devras accepter la licence.
      Une fois le scan fini, 2 rapports vont apparaître. Poste le contenu des 2 rapports séparément. Ils se trouvent sur c :
      (log.txt & info.txt)
      (CTRL+A Pour tout sélectionner, CTRL+C pour copier et CTRL+V pour coller)
      1. si le pc est vraiment trop lent fait un bon nettoyage de printemps donc formatage mais avant cela fait une copie sur une disque dur externe de tous les truc important que tu veux garder

        a par sa je ne connait rien pour redonner vitalité a sont pc

        évite de trop le charger une fois le formatage effectué
        ps il doit toujours resté 1/3 de place sur un disque dur pour pas perdre en vitesse
        1. justement, je vais faire le menage là dedans en commençant par rsit :-)
        2. @Utilisateur anonymeBonjour,
          Bon voilà les rapports RSIT (avec un peu de retard !) :

          1er rapport

          Logfile of random's system information tool 1.06 (written by random/random)
          Run by HP_Propriétaire at 2010-02-26 19:13:48
          Microsoft Windows XP Édition familiale Service Pack 2
          System drive C: has 104 GB (57%) free of 184 GB
          Total RAM: 1022 MB (37% free)

          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 19:14:04, on 26/02/2010
          Platform: Windows XP SP2 (WinNT 5.01.2600)
          MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
          Boot mode: Normal

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\Ati2evxx.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
          C:\WINDOWS\system32\spoolsv.exe
          C:\Program Files\Avira\AntiVir Desktop\sched.exe
          C:\Program Files\Avira\AntiVir Desktop\avguard.exe
          C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
          C:\Program Files\Bonjour\mDNSResponder.exe
          C:\Program Files\Google\Update\GoogleUpdate.exe
          C:\Program Files\Java\jre6\bin\jqs.exe
          c:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
          C:\Program Files\Fichiers communs\Microsoft Shared\Media Manager\airsvcu.exe
          C:\Program Files\Fichiers communs\Nero\Nero BackItUp 4\NBService.exe
          C:\WINDOWS\system32\Ati2evxx.exe
          C:\WINDOWS\Explorer.EXE
          C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
          C:\PROGRA~1\TEXTBR~1.0\Bin\INSTAN~1.EXE
          C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe
          C:\Program Files\Hercules\Hercules DualPix HD Webcam\CamService.exe
          C:\Program Files\Java\jre6\bin\jusched.exe
          C:\Program Files\QuickTime\QTTask.exe
          C:\Program Files\iTunes\iTunesHelper.exe
          C:\Program Files\HiYo\bin\HiYo.exe
          C:\Program Files\TomTom HOME\TomTomHOME.exe
          C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
          C:\Program Files\Nero\Nero BackItUp 4\IoctlSvc.exe
          C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
          C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
          C:\Program Files\Packard Bell\Software Suite\PowerSave\PSPBSSS.exe
          C:\WINDOWS\system32\ctfmon.exe
          C:\Program Files\SFR\Media Center\MediaCenter.exe
          C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
          C:\Program Files\Packard Bell\Software Suite\PBSoftSuite.exe
          C:\Program Files\Fichiers communs\LightScribe\LightScribeControlPanel.exe
          C:\WINDOWS\system32\svchost.exe
          C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
          C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
          C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkCalRem.exe
          C:\Program Files\Packard Bell\Software Suite\pbDevDetect.exe
          C:\WINDOWS\system32\wbem\wmiapsrv.exe
          C:\Program Files\iPod\bin\iPodService.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\wuauclt.exe
          C:\Program Files\SFR\Media Center\httpd\httpd.exe
          C:\Program Files\SFR\Media Center\httpd\httpd.exe
          C:\Program Files\Windows Live\Contacts\wlcomm.exe
          C:\Documents and Settings\HP_Propriétaire\Bureau\RSIT.exe
          C:\Program Files\trend micro\HP_Propriétaire.exe

          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?redirfallthru=http%3a%2f%2fwww.msn.fr%2fdajo%3f
          R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
          O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
          O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
          O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
          O2 - BHO: Videoraptor_WebRipPlugin Class - {3C0372C2-04C3-4100-BAB1-1D42C552BC48} - C:\Program Files\RapidSolution\AudialsOne\Mediaraptor\plugins\IE\MR_WebRipIePlugin.dll
          O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
          O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
          O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
          O2 - BHO: Tunebite_WebRipPlugin Class - {AA102584-3B97-47e7-B9BC-75D54C110A7D} - C:\Program Files\RapidSolution\AudialsOne\Tunebite\plugins\IE\TB_WebRipIePlugin.dll
          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
          O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll
          O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
          O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
          O2 - BHO: Pando Toolbar BHO - {E3EA4FD1-CADE-4ae5-84F7-086EEE888BE4} - C:\Program Files\PandoBar\bar\1.bin\PANDOBAR.DLL
          O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
          O2 - BHO: Ask Toolbar BHO - {FE063DB1-4EC0-403e-8DD8-394C54984B2C} - C:\Program Files\AskTBar\bar\2.bin\ASKTBAR.DLL
          O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
          O3 - Toolbar: Pando Toolbar - {E3EA4FD9-CADE-4ae5-84F7-086EEE888BE4} - C:\Program Files\PandoBar\bar\1.bin\PANDOBAR.DLL
          O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
          O3 - Toolbar: Foxit Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
          O3 - Toolbar: Ask Toolbar - {FE063DB9-4EC0-403e-8DD8-394C54984B2C} - C:\Program Files\AskTBar\bar\2.bin\ASKTBAR.DLL
          O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
          O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
          O4 - HKLM\..\Run: [Ashampoo FireWall] "C:\Program Files\Ashampoo\Ashampoo FireWall\FireWall.exe" -TRAY
          O4 - HKLM\..\Run: [InstantAccess] C:\PROGRA~1\TEXTBR~1.0\Bin\INSTAN~1.EXE /h
          O4 - HKLM\..\Run: [RegisterDropHandler] C:\PROGRA~1\TEXTBR~1.0\Bin\REGIST~1.EXE
          O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe"
          O4 - HKLM\..\Run: [HerculesCamService] C:\Program Files\Hercules\Hercules DualPix HD Webcam\CamService.exe
          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
          O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
          O4 - HKLM\..\Run: [Hiyo] C:\Program Files\HiYo\bin\HiYo.exe /RunFromStartup
          O4 - HKLM\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME\TomTomHOME.exe" -s
          O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
          O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero BackItUp 4\NBKeyScan.exe"
          O4 - HKLM\..\Run: [Nero MediaHome 4] "C:\Program Files\Nero\Nero MediaHome 4\NeroMediaHome.exe" /AUTORUN
          O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
          O4 - HKLM\..\RunServices: [RegisterDropHandler] C:\PROGRA~1\TEXTBR~1.0\Bin\REGIST~1.EXE
          O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
          O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
          O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
          O4 - HKCU\..\Run: [Neuf Media Center] "C:\Program Files\SFR\Media Center\MediaCenter.exe"
          O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\HP_Propriétaire\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
          O4 - HKCU\..\Run: [Packard Bell Software Suite] "C:\Program Files\Packard Bell\Software Suite\PBSoftSuite.exe" /run
          O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Fichiers communs\LightScribe\LightScribeControlPanel.exe -hidden
          O4 - S-1-5-21-4096709876-1069044103-4087124974-1010 Startup: AutoTBar.exe (User 'NeroMediaHomeUser.4')
          O4 - S-1-5-21-4096709876-1069044103-4087124974-1010 User Startup: AutoTBar.exe (User 'NeroMediaHomeUser.4')
          O4 - .DEFAULT User Startup: AutoTBar.exe (User 'Default user')
          O4 - Startup: Présentation de Media Manager.lnk = C:\Program Files\Fichiers communs\Microsoft Shared\Media Manager\SPLASHA.EXE
          O4 - Startup: wkcalrem.LNK = C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkCalRem.exe
          O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
          O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
          O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
          O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
          O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
          O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
          O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Fichiers communs\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
          O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
          O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w3/resources/MSNPUpld.cab
          O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
          O16 - DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} (HpProductDetection Class) - http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
          O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
          O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} (Windows Live Hotmail Photo Upload Tool) - http://gfx1.hotmail.com/mail/w4/pr01/photouploadcontrol/MSNPUpld.cab
          O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
          O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
          O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
          O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
          O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
          O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
          O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
          O23 - Service: Service Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
          O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
          O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
          O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
          O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
          O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Fichiers communs\Nero\Nero BackItUp 4\NBService.exe
          O23 - Service: Nero MediaHome 4 Service (NeroMediaHomeService.4) - Nero AG - C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe
          O23 - Service: NMIndexingService - Unknown owner - C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe (file missing)
          O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\Program Files\Nero\Nero BackItUp 4\IoctlSvc.exe
          O23 - Service: PowerSave Service (PowerSave) - Packard Bell Services - C:\Program Files\Packard Bell\Software Suite\PowerSave\PSPBSSS.exe
      2. bonjour,

        Télécharge Toolbar-S&D (Team IDN) sur ton Bureau.
        https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/ToolBarSD.exe?attachauth=ANoY7cpVobGk5bHnxrhQ4yaoEUDJvOYNnEGyYjgqHZz5GqZLfutR3fMFPlsC3-CGIilfupPAguYATNyua3csodN_frdMK8sSzUpit10Yac-QJCOkMqJKkbdKcP6ySs8trWPgoNVIq4TGGWCe6o0txXQv-ZueJF9vZzw3RXsGwFYIqN2lvF2LPdQzS8mE1d5kWOVOz6EMzQuE5-lClSJM869uq3oc7-t7yg%3D%3D&attredirects=3
        ou ici : https://sites.google.com/site/toolbarsd/

        * Lance l'installation du programme en exécutant le fichier téléchargé.
        * Double-clique maintenant sur le raccourci de Toolbar-S&D.
        * Sélectionne la langue souhaitée en tapant la lettre de ton choix puis en validant avec la touche Entrée.
        * Choisis maintenant l'option 2

        . Patiente jusqu'à la fin de la recherche.
        * Poste le rapport généré. (C:\TB.txt)

        Tuto :
        https://www.malekal.com/adwcleaner-supprimer-virus-adwares-pup/

        Télécharge de AD-Remover sur ton Bureau. (Merci à Cyrildu17 / C_XX)
        http://pagesperso-orange.fr/NosTools/C_XX/AD-R.exe

        Miroir:

        https://www.androidworld.fr/

        /!\ Déconnecte-toi d’internet et ferme toutes applications en cours /!\

        - Double-clique sur le programme d'installation, installe-le dans son emplacement par défaut (C:\Program files).
        - Double-clique sur l'icône Ad-remover située sur ton Bureau.
        - Au menu principal, choisis l'option « L ».
        - Laisse travailler l’outil.

        - Poste le rapport qui apparaît à la fin.

        (Le rapport est sauvegardé aussi sous C:\Ad-report(date).log)

        (CTRL+A pour tout sélectionner, CTRL+C pour copier et CTRL+V pour coller)

        Note :
        "Process.exe", une composante de l'outil, est détectée par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
        Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.

        Tuto : http://pagesperso-orange.fr/NosTools/tuto_adr_3.html

        Télécharge USBFIX sur ton bureauhttp://pagesperso-orange.fr/NosTools/Chiquitine29/UsbFix.exe
        ou ici :
        https://www.ionos.fr/?affiliate_id=77097

        /!\ Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptible d'avoir été infectées sans les ouvrir • Double clic sur le raccourci UsbFix présent sur ton bureau .
        • Choisis l'option 2

        • Laisse travailler l'outil.

        • Ensuite post le rapport UsbFix.txt qui apparaîtra.

        • Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque. ( C:\UsbFix.txt )

        ( CTRL+A Pour tout sélectionner , CTRL+C pour copier et CTRL+V pour coller )

        • Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
        Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
        1. bonjour,

          voici le rapport toolbar :

          -----------\\ ToolBar S&D 1.2.9 XP/Vista

          Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 2
          X86-based PC ( Uniprocessor Free : AMD Athlon(tm) 64 Processor 3000+ )
          BIOS : Phoenix - Award BIOS v6.00PG
          USER : HP_Propriétaire ( Not Administrator ! )
          BOOT : Normal boot
          Antivirus : AntiVir Desktop 9.0.1.32 (Activated)
          C:\ (Local Disk) - NTFS - Total:179 Go (Free:101 Go)
          D:\ (Local Disk) - FAT32 - Total:6 Go (Free:3 Go)
          E:\ (CD or DVD)
          F:\ (CD or DVD)
          G:\ (USB)
          H:\ (USB)
          I:\ (USB)
          J:\ (USB)
          K:\ (Local Disk) - FAT32 - Total:931 Go (Free:902 Go)
          L:\ (USB)

          "C:\ToolBar SD" ( MAJ : 22-08-2009|18:42 )
          Option : [1] ( 27/02/2010|20:45 )

          -----------\\ Recherche de Fichiers / Dossiers ...

          C:\Program Files\AskBarDis
          C:\Program Files\AskBarDis\bar
          C:\Program Files\AskBarDis\unins000.dat
          C:\Program Files\AskBarDis\unins000.exe
          C:\Program Files\AskBarDis\bar\bin
          C:\Program Files\AskBarDis\bar\Cache
          C:\Program Files\AskBarDis\bar\History
          C:\Program Files\AskBarDis\bar\Settings
          C:\Program Files\AskBarDis\bar\bin\askBar.dll
          C:\Program Files\AskBarDis\bar\bin\askPopStp.dll
          C:\Program Files\AskBarDis\bar\bin\psvince.dll
          C:\Program Files\AskBarDis\bar\Cache\00562855.bin
          C:\Program Files\AskBarDis\bar\Cache\005631BC.bin
          C:\Program Files\AskBarDis\bar\Cache\005634B9.bin
          C:\Program Files\AskBarDis\bar\Cache\005635D3.bin
          C:\Program Files\AskBarDis\bar\Cache\005636EC.bin
          C:\Program Files\AskBarDis\bar\Cache\005637F5.bin
          C:\Program Files\AskBarDis\bar\Cache\0056390F.bin
          C:\Program Files\AskBarDis\bar\Cache\00563A28.bin
          C:\Program Files\AskBarDis\bar\Cache\00563B41.bin
          C:\Program Files\AskBarDis\bar\Cache\00563C5A.bin
          C:\Program Files\AskBarDis\bar\Cache\00B083FD
          C:\Program Files\AskBarDis\bar\Cache\files.ini
          C:\Program Files\AskBarDis\bar\History\search
          C:\Program Files\AskBarDis\bar\Settings\config.dat
          C:\Program Files\AskBarDis\bar\Settings\config.dat.bak
          C:\Program Files\AskBarDis\bar\Settings\prevcfg.htm
          C:\Program Files\AskTBar
          C:\Program Files\AskTBar\bar
          C:\Program Files\AskTBar\PopSwatr
          C:\Program Files\AskTBar\bar\2.bin
          C:\Program Files\AskTBar\bar\Cache
          C:\Program Files\AskTBar\bar\History
          C:\Program Files\AskTBar\bar\Settings
          C:\Program Files\AskTBar\bar\2.bin\A5POPSWT.DLL
          C:\Program Files\AskTBar\bar\2.bin\ASKTBAR.DLL
          C:\Program Files\AskTBar\bar\Cache\005708E2
          C:\Program Files\AskTBar\bar\Cache\00571C0C
          C:\Program Files\AskTBar\bar\Cache\00571D54.bin
          C:\Program Files\AskTBar\bar\Cache\00571F0A.bin
          C:\Program Files\AskTBar\bar\Cache\005720FE.bin
          C:\Program Files\AskTBar\bar\Cache\00572236.bin
          C:\Program Files\AskTBar\bar\Cache\files.ini
          C:\Program Files\AskTBar\bar\History\search2
          C:\Program Files\AskTBar\bar\Settings\prevcfg2.htm
          C:\Program Files\AskTBar\PopSwatr\History
          C:\Program Files\AskTBar\PopSwatr\History\allowed
          C:\Program Files\AskTBar\PopSwatr\History\notallow
          C:\DOCUME~1\HP_PRO~1\APPLIC~1\Dealio
          C:\DOCUME~1\HP_PRO~1\APPLIC~1\Dealio\res
          C:\DOCUME~1\HP_PRO~1\APPLIC~1\Dealio\temp
          C:\DOCUME~1\HP_PRO~1\APPLIC~1\Dealio\res\widgets.xml
          C:\DOCUME~1\HP_PRO~1\APPLIC~1\Dealio\temp\http___www_dealio_com_rss_coupons-deals_dotd_.xml
          C:\DOCUME~1\HP_PRO~1\Cookies\hp_propriétaire@mysearch[2].txt
          C:\DOCUME~1\HP_PRO~1\APPLIC~1\Search Settings
          C:\DOCUME~1\HP_PRO~1\APPLIC~1\Search Settings\kb128
          C:\DOCUME~1\HP_PRO~1\APPLIC~1\Search Settings\kb128\temp
          C:\DOCUME~1\HP_PRO~1\APPLIC~1\Search Settings\kb128\temp\ws-14561.log

          -----------\\ Extensions

          (HP_Propri‚taire) - {E9A1DEE0-C623-4439-8932-001E7D17607D} => ajtoolbar

          -----------\\ [..\Internet Explorer\Main]

          [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
          "Local Page"="C:\\WINDOWS\\system32\\blank.htm"
          "Start Page"="https://www.msn.com/fr-fr/?redirfallthru=http%3a%2f%2fwww.msn.fr%2fdajo%3f"
          "Search Page"="https://www.google.com/?gws_rd=ssl"
          "Default_Page_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
          "Default_Search_URL"="http://www.google.com/toolbar/ie8/sidebar.html"
          "Search Bar"="http://www.google.com/toolbar/ie8/sidebar.html"
          "SearchAssistant"="https://www.bing.com/?toHttps=1&redig=8F3F334EA60E4B1CB4D040DCFE393A89{SUB_RFC1766}/srchasst/srchasst.htm"
          "CustomizeSearch"="https://www.bing.com/?toHttps=1&redig=8F3F334EA60E4B1CB4D040DCFE393A89{SUB_RFC1766}/srchasst/srchcust.htm"
          "First Home Page"="http://www.microsoft.com/isapi/redir.dll?Prd=ie&Pver=5.0&Ar=ie5update&O1=b1"

          [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
          "Default_Page_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
          "Default_Search_URL"="http://www.google.com/toolbar/ie8/sidebar.html"
          "Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
          "Start Page"="https://www.google.com/?gws_rd=ssl"
          "Search Bar"="http://www.bing.com/spresults.aspx"
          "SearchAssistant"="https://www.bing.com/?toHttps=1&redig=8F3F334EA60E4B1CB4D040DCFE393A89{SUB_RFC1766}/srchasst/srchasst.htm"
          "CustomizeSearch"="https://www.bing.com/?toHttps=1&redig=8F3F334EA60E4B1CB4D040DCFE393A89{SUB_RFC1766}/srchasst/srchcust.htm"

          --------------------\\ Recherche d'autres infections

          Aucune autre infection trouvée !

          1 - "C:\ToolBar SD\TB_1.txt" - 27/02/2010|20:46 - Option : [1]

          -----------\\ Fin du rapport a 20:46:18,25
          1. et voici le rapport Ad-report :

            .
            ======= RAPPORT D'AD-REMOVER 1.1.4.6_J | UNIQUEMENT XP/VISTA/7 =======
            .
            Mis à jour par C_XX le 05.02.2010 à 17:34
            Contact: AdRemover.contact@gmail.com
            Site web: http://pagesperso-orange.fr/NosTools/ad_remover.html
            .
            Lancé à: 20:52:28, 27/02/2010 | Mode Normal | Option: SCAN
            Exécuté de: C:\Ad-Remover\
            Système d'exploitation: Microsoft® Windows XP™ Service Pack 2 v5.1.2600
            Nom du PC: NOM-EB85C523610 | Utilisateur actuel: HP_Propri‚taire
            .
            ============== ÉLÉMENT(S) TROUVÉ(S) ==============
            .

            C:\DOCUME~1\HP_PRO~1\APPLIC~1\Mozilla\FireFox\Profiles\xhmmgckg.default\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}
            C:\Program Files\AskBarDis
            C:\Program Files\AskTBar
            C:\Program Files\Dealio Toolbar
            C:\Program Files\eoRezo
            C:\Program Files\PandoBar
            C:\DOCUME~1\HP_PRO~1\APPLIC~1\Dealio
            C:\DOCUME~1\HP_PRO~1\APPLIC~1\EoRezo
            C:\DOCUME~1\HP_PRO~1\APPLIC~1\ItsLabel
            C:\DOCUME~1\HP_PRO~1\APPLIC~1\Search Settings
            .
            HKCU\software\appdatalow\AskBarDis
            HKCU\software\EoRezo
            HKCU\software\ItsLabel
            HKCU\software\microsoft\internet explorer\searchscopes\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}
            HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{0E5CBF21-D15F-11D0-8301-00AA005B4383}
            HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{3041d03e-fd4b-44e0-b742-2d9b88305f98}
            HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{3041D03E-FD4B-44E0-B742-2D9B88305F98}
            HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{4B3803EA-5230-4DC3-A7FC-33638F3D3542}
            HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{E3EA4FD9-CADE-4AE5-84F7-086EEE888BE4}
            HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{E3EA4FD9-CADE-4ae5-84F7-086EEE888BE4}
            HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{FE063DB9-4EC0-403E-8DD8-394C54984B2C}
            HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{FE063DB9-4EC0-403e-8DD8-394C54984B2C}
            HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00A6FAF1-072E-44CF-8957-5838F569A31D}
            HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EA1-A523-4961-B6BB-170DE4475CCA}
            HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EAB-A523-4961-B6BB-170DE4475CCA}
            HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB}
            HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{25560540-9571-4D7B-9389-0F166788785A}
            HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3DC201FB-E9C9-499C-A11F-23C360D7C3F8}
            HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{64F56FC1-1272-44CD-BA6E-39723696E350}
            HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9FF05104-B030-46FC-94B8-81276E4E27DF}
            HKLM\software\AskBarDis
            HKLM\software\classes\AskIBar.PopSwatterBarButton
            HKLM\software\classes\AskIBar.PopSwatterBarButton.1
            HKLM\software\classes\AskIBar.PopSwatterSettingsControl
            HKLM\software\classes\AskIBar.PopSwatterSettingsControl.1
            HKLM\software\classes\AskToolBar.SettingsPlugin
            HKLM\software\classes\AskToolBar.SettingsPlugin.1
            HKLM\Software\Classes\CLSID\{0702a2b6-13aa-4090-9e01-bcdc85dd933f}
            HKLM\Software\Classes\CLSID\{08993A7C-E764-4172-9627-BFB5EA6897B2}
            HKLM\Software\Classes\CLSID\{128A6C66-AC6A-4617-8268-AB7F47B7215E}
            HKLM\Software\Classes\CLSID\{201f27d4-3704-41d6-89c1-aa35e39143ed}
            HKLM\Software\Classes\CLSID\{3041d03e-fd4b-44e0-b742-2d9b88305f98}
            HKLM\Software\Classes\CLSID\{3B8B90F0-A76C-4a02-B44A-BB338D8D00F0}
            HKLM\Software\Classes\CLSID\{571715D7-3395-4DF0-B43C-784836209E60}
            HKLM\Software\Classes\CLSID\{622fd888-4e91-4d68-84d4-7262fd0811bf}
            HKLM\Software\Classes\CLSID\{b0de3308-5d5a-470d-81b9-634fc078393b}
            HKLM\Software\Classes\CLSID\{E3EA4FD1-CADE-4ae5-84F7-086EEE888BE4}
            HKLM\Software\Classes\CLSID\{E3EA4FD9-CADE-4ae5-84F7-086EEE888BE4}
            HKLM\Software\Classes\CLSID\{E3EA4FDB-CADE-4ae5-84F7-086EEE888BE4}
            HKLM\Software\Classes\CLSID\{FE063DB1-4EC0-403e-8DD8-394C54984B2C}
            HKLM\Software\Classes\CLSID\{FE063DB9-4EC0-403e-8DD8-394C54984B2C}
            HKLM\Software\Classes\CLSID\{FE063DBB-4EC0-403e-8DD8-394C54984B2C}
            HKLM\Software\Classes\Interface\{4634804A-F0B0-4A74-A550-FC0EEF8A4362}
            HKLM\Software\Classes\Interface\{4C07EA4F-5F52-4222-B170-4CD9ED33BAEA}
            HKLM\Software\Classes\Interface\{B0D071A1-36B3-4757-A126-14C89C56013A}
            HKLM\Software\Classes\Interface\{C44FEFF4-EF0C-4CF7-83D0-92B4266A32B9}
            HKLM\Software\Classes\Interface\{E3EA4FDA-CADE-4AE5-84F7-086EEE888BE4}
            HKLM\Software\Classes\Interface\{E3EA4FDC-CADE-4AE5-84F7-086EEE888BE4}
            HKLM\Software\Classes\Interface\{F131923C-381D-4E4C-A472-4A17118FD742}
            HKLM\software\classes\PandoBar.SettingsPlugin
            HKLM\software\classes\PandoBar.SettingsPlugin.1
            HKLM\software\classes\PandoBar.ToolbarPlugin
            HKLM\software\classes\PandoBar.ToolbarPlugin.1
            HKLM\Software\Classes\TypeLib\{4B1C1E16-6B34-430E-B074-5928ECA4C150}
            HKLM\Software\Classes\TypeLib\{B4C656C9-F2E9-4E77-B3F4-443DF2BD778F}
            HKLM\Software\Classes\TypeLib\{D2E5FA06-DCC7-46F9-BEFF-BFD06F69B9B2}
            HKLM\Software\Classes\TypeLib\{E3EA4FD0-CADE-4AE5-84F7-086EEE888BE4}
            HKLM\software\EoRezo
            HKLM\Software\Microsoft\Internet Explorer\Toolbar\\{3041D03E-FD4B-44E0-B742-2D9B88305F98}
            HKLM\Software\Microsoft\Internet Explorer\Toolbar\\{3041d03e-fd4b-44e0-b742-2d9b88305f98}
            HKLM\Software\Microsoft\Internet Explorer\Toolbar\\{E3EA4FD9-CADE-4AE5-84F7-086EEE888BE4}
            HKLM\Software\Microsoft\Internet Explorer\Toolbar\\{E3EA4FD9-CADE-4ae5-84F7-086EEE888BE4}
            HKLM\Software\Microsoft\Internet Explorer\Toolbar\\{FE063DB9-4EC0-403e-8DD8-394C54984B2C}
            HKLM\Software\Microsoft\Internet Explorer\Toolbar\\{FE063DB9-4EC0-403E-8DD8-394C54984B2C}
            HKLM\Software\Microsoft\Multimedia\WMPlayer\Schemes\f3pss
            HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}
            HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E3EA4FD1-CADE-4ae5-84F7-086EEE888BE4}
            HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FE063DB1-4EC0-403e-8DD8-394C54984B2C}
            HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\EoEngine
            HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\InstantAccess
            HKLM\software\microsoft\windows\currentversion\uninstall\Ask Toolbar_is1
            HKLM\software\microsoft\windows\currentversion\uninstall\PandoBar Uninstall
            HKLM\software\PandoBar
            HKU\s-1-5-21-4096709876-1069044103-4087124974-1007\software\appdatalow\AskBarDis
            HKU\s-1-5-21-4096709876-1069044103-4087124974-1007\software\EoRezo
            HKU\s-1-5-21-4096709876-1069044103-4087124974-1007\software\ItsLabel
            .
            ============== Scan additionnel ==============
            .
            .
            * Mozilla FireFox Version [Impossible d'obtenir la version] *
            .
            Nom du profil: xhmmgckg.default (HP_Propri‚taire)
            .
            (HP_PRO~1, prefs.js) Browser.startup.homepage, hxxp://www.vlcsearch.com/?cfg=1-1-1-115i
            (HP_PRO~1, prefs.js) Browser.search.selectedEngine, Ask
            .
            .
            * Internet Explorer Version 6.0.2900.2180 *
            .
            [HKEY_CURRENT_USER\..\Internet Explorer\Main]
            .
            Do404Search: 01000000
            Local Page: C:\WINDOWS\system32\blank.htm
            Show_ToolBar: yes
            Start Page: hxxp://www.msn.fr/
            Search Page: hxxp://www.google.com
            Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
            Default_Search_URL: hxxp://www.google.com/ie
            Search Bar: hxxp://www.google.com/ie
            Use Custom Search URL: 1 (0x1)
            Use Search Asst: no
            Enable Browser Extensions: yes
            SearchAssistant: hxxp://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
            First Home Page: hxxp://www.microsoft.com/isapi/redir.dll?Prd=ie&Pver=5.0&Ar=ie5update&O1=b1
            .
            [HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]
            .
            Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
            Default_Search_URL: hxxp://www.google.com/ie
            Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
            Delete_Temp_Files_On_Exit: yes
            Local Page: %SystemRoot%\system32\blank.htm
            Start Page: hxxp://www.google.com
            Search Bar: hxxp://search.msn.com/spbasic.htm
            SearchAssistant: hxxp://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
            Use Custom Search URL: 0 (0x0)
            Use search Asst: no
            .
            [HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]
            .
            Error: Value: "Tabs" does not exist!
            .
            ============== Suspect (Cracks, Serials, ...) ==============
            .
            C:\Documents and Settings\All Users\Documents\Pinnacle\Content\HollywoodFX\HfxSerial.exe
            C:\Documents and Settings\HP_Propri‚taire\Mes documents\Mises … jour de programme t‚l‚charg‚es\HomeTheater 2 HP CPC\HomeTheater 2 HP Update 2.6.1.133 (French)\IHT2.6.1.133HP(CPC)_logid32206patch.exe
            .
            ===================================
            .
            8625 Octet(s) - C:\Ad-Report-SCAN[1].log
            .
            100 Fichier(s) - C:\DOCUME~1\HP_PRO~1\LOCALS~1\Temp
            15 Fichier(s) - C:\WINDOWS\Temp
            58 Fichier(s) - C:\WINDOWS\Prefetch
            .
            2 Fichier(s) - C:\Ad-Remover\BACKUP
            0 Fichier(s) - C:\Ad-Remover\QUARANTINE
            .
            Fin à: 21:00:41 | 27/02/2010 - SCAN[1]
            .
            ============== E.O.F ==============
            .
            1. Et voici le rapport UsbFix :

              ############################## | UsbFix V6.097 |

              User : HP_Propriétaire (Administrateurs) # NOM-EB85C523610
              Update on 20/02/2010 by El Desaparecido , C_XX & Chimay8
              Start at: 11:21:58 | 27/02/2010
              Website : http://pagesperso-orange.fr/NosTools/index.html
              Contact : FindyKill.Contact@gmail.com

              AMD Athlon(tm) 64 Processor 3000+
              Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 2
              Internet Explorer 6.0.2900.2180
              Windows Firewall Status : Disabled
              AV : AntiVir Desktop 9.0.1.32 [ Enabled | Updated ]

              C:\ -> Disque fixe local # 179,33 Go (101,82 Go free) [HP_PAVILION] # NTFS
              D:\ -> Disque fixe local # 6,96 Go (3,11 Go free) [HP_RECOVERY] # FAT32
              E:\ -> Disque CD-ROM
              F:\ -> Disque CD-ROM
              G:\ -> Disque amovible
              H:\ -> Disque amovible
              I:\ -> Disque amovible
              J:\ -> Disque amovible
              K:\ -> Disque fixe local # 931,28 Go (902,09 Go free) [PACKARDBELL] # FAT32
              L:\ -> Disque amovible
              M:\ -> Disque amovible # 968,25 Mo (792,33 Mo free) # FAT

              ############################## | Processus actifs |

              C:\WINDOWS\System32\smss.exe
              C:\WINDOWS\system32\csrss.exe
              C:\WINDOWS\system32\winlogon.exe
              C:\WINDOWS\system32\services.exe
              C:\WINDOWS\system32\lsass.exe
              C:\WINDOWS\system32\Ati2evxx.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\system32\svchost.exe
              C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
              C:\WINDOWS\system32\spoolsv.exe
              C:\Program Files\Avira\AntiVir Desktop\sched.exe
              C:\WINDOWS\system32\svchost.exe
              C:\Program Files\Avira\AntiVir Desktop\avguard.exe
              C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
              C:\Program Files\Bonjour\mDNSResponder.exe
              C:\Program Files\Google\Update\GoogleUpdate.exe
              C:\Program Files\Java\jre6\bin\jqs.exe
              c:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
              C:\Program Files\Fichiers communs\Microsoft Shared\Media Manager\airsvcu.exe
              C:\Program Files\Fichiers communs\Nero\Nero BackItUp 4\NBService.exe
              C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe
              C:\Program Files\Nero\Nero BackItUp 4\IoctlSvc.exe
              C:\Program Files\Packard Bell\Software Suite\PowerSave\PSPBSSS.exe
              C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\system32\wbem\wmiapsrv.exe
              C:\WINDOWS\System32\alg.exe
              C:\WINDOWS\system32\Ati2evxx.exe
              C:\WINDOWS\Explorer.EXE
              C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
              C:\Program Files\Ashampoo\Ashampoo FireWall\FireWall.exe
              C:\PROGRA~1\TEXTBR~1.0\Bin\INSTAN~1.EXE
              C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe
              C:\WINDOWS\System32\svchost.exe
              C:\Program Files\Hercules\Hercules DualPix HD Webcam\CamService.exe
              C:\Program Files\Java\jre6\bin\jusched.exe
              C:\Program Files\QuickTime\QTTask.exe
              C:\Program Files\iTunes\iTunesHelper.exe
              C:\Program Files\HiYo\bin\HiYo.exe
              C:\Program Files\TomTom HOME\TomTomHOME.exe
              C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
              C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
              C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
              C:\WINDOWS\system32\ctfmon.exe
              C:\Program Files\SFR\Media Center\MediaCenter.exe
              C:\Program Files\Packard Bell\Software Suite\PBSoftSuite.exe
              C:\Program Files\Fichiers communs\LightScribe\LightScribeControlPanel.exe
              C:\WINDOWS\system32\wuauclt.exe
              C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
              C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkCalRem.exe
              C:\Program Files\iPod\bin\iPodService.exe
              C:\Program Files\Packard Bell\Software Suite\pbDevDetect.exe
              C:\Program Files\SFR\Media Center\httpd\httpd.exe
              C:\Program Files\SFR\Media Center\httpd\httpd.exe
              C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
              C:\Program Files\Windows Live\Contacts\wlcomm.exe
              C:\WINDOWS\system32\wbem\wmiprvse.exe

              ################## | Elements infectieux |

              C:\Documents and Settings\HP_Propri‚taire\new.txt
              D:\autorun.inf
              K:\autorun.inf
              M:\host.exe
              M:\msvcr71.dll

              ################## | Registre |

              ################## | Mountpoints2 |

              HKCU\..\..\Explorer\MountPoints2\{69a05904-d466-11de-9a48-001109f56ec5}
              Shell\AutoRun\command =K:\ClickMe.exe

              HKCU\..\..\Explorer\MountPoints2\{bcc14cbe-5c61-11da-9661-806d6172696f}
              Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480

              HKCU\..\..\Explorer\MountPoints2\{e85e7262-1473-11dd-98d4-001109f56ec5}
              Shell\AutoRun\command =L:\SSVICHOSST.exe
              Shell\Open\command =L:\SSVICHOSST.exe

              ################## | Vaccin |

              ################## | ! Fin du rapport # UsbFix V6.097 ! |
              1. bonjour,
                tu n'as pas suivi ce que j'ai noté !
                relance toolbar s&d en option 2

                relance AD remover en option L

                puis usbfix en option 2

                poste les rapports


                merci
                1. bonjour,
                  excuses-moi, j'avais peur des mots "nettoyage" et "suppression" ! mais j'ai refait les manip et voici les rapports :

                  Rapport ToolbarSD :

                  -----------\\ ToolBar S&D 1.2.9 XP/Vista

                  Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 2
                  X86-based PC ( Uniprocessor Free : AMD Athlon(tm) 64 Processor 3000+ )
                  BIOS : Phoenix - Award BIOS v6.00PG
                  USER : HP_Propriétaire ( Not Administrator ! )
                  BOOT : Normal boot
                  Antivirus : AntiVir Desktop 9.0.1.32 (Activated)
                  C:\ (Local Disk) - NTFS - Total:179 Go (Free:101 Go)
                  D:\ (Local Disk) - FAT32 - Total:6 Go (Free:3 Go)
                  E:\ (CD or DVD)
                  F:\ (CD or DVD)
                  G:\ (USB)
                  H:\ (USB)
                  I:\ (USB)
                  J:\ (USB)
                  K:\ (Local Disk) - FAT32 - Total:931 Go (Free:902 Go)

                  "C:\ToolBar SD" ( MAJ : 22-08-2009|18:42 )
                  Option : [2] ( 28/02/2010|14:51 )

                  -----------\\ SUPPRESSION

                  Supprime! - C:\Program Files\AskBarDis\bar
                  Supprime! - C:\Program Files\AskBarDis\unins000.dat
                  Supprime! - C:\Program Files\AskBarDis\unins000.exe
                  Supprime! - C:\Program Files\AskTBar\bar
                  Supprime! - C:\Program Files\AskTBar\PopSwatr
                  Supprime! - C:\DOCUME~1\HP_PRO~1\APPLIC~1\Dealio\res
                  Supprime! - C:\DOCUME~1\HP_PRO~1\APPLIC~1\Dealio\temp
                  Supprime! - C:\DOCUME~1\HP_PRO~1\Cookies\hp_propriétaire@mysearch[2].txt
                  Supprime! - C:\DOCUME~1\HP_PRO~1\APPLIC~1\Search Settings\kb128
                  Supprime! - C:\Program Files\AskBarDis
                  Supprime! - C:\Program Files\AskTBar
                  Supprime! - C:\DOCUME~1\HP_PRO~1\APPLIC~1\Dealio
                  Supprime! - C:\DOCUME~1\HP_PRO~1\APPLIC~1\Search Settings

                  -----------\\ Recherche de Fichiers / Dossiers ...

                  -----------\\ Extensions

                  (HP_Propri‚taire) - {E9A1DEE0-C623-4439-8932-001E7D17607D} => ajtoolbar

                  -----------\\ [..\Internet Explorer\Main]

                  [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                  "Local Page"="C:\\WINDOWS\\system32\\blank.htm"
                  "Start Page"="https://www.msn.com/fr-fr/?redirfallthru=http%3a%2f%2fwww.msn.fr%2fdajo%3f"
                  "Search Page"="https://www.google.com/?gws_rd=ssl"
                  "Default_Page_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
                  "Default_Search_URL"="http://www.google.com/toolbar/ie8/sidebar.html"
                  "Search Bar"="http://www.google.com/toolbar/ie8/sidebar.html"
                  "SearchAssistant"="https://www.bing.com/?toHttps=1&redig=8F3F334EA60E4B1CB4D040DCFE393A89{SUB_RFC1766}/srchasst/srchasst.htm"
                  "CustomizeSearch"="https://www.bing.com/?toHttps=1&redig=8F3F334EA60E4B1CB4D040DCFE393A89{SUB_RFC1766}/srchasst/srchcust.htm"
                  "First Home Page"="http://www.microsoft.com/isapi/redir.dll?Prd=ie&Pver=5.0&Ar=ie5update&O1=b1"

                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
                  "Default_Page_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
                  "Default_Search_URL"="http://www.google.com/toolbar/ie8/sidebar.html"
                  "Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
                  "Start Page"="https://www.msn.com/fr-fr/"
                  "Search Bar"="http://www.bing.com/spresults.aspx"
                  "SearchAssistant"="https://www.bing.com/?toHttps=1&redig=8F3F334EA60E4B1CB4D040DCFE393A89{SUB_RFC1766}/srchasst/srchasst.htm"
                  "CustomizeSearch"="https://www.bing.com/?toHttps=1&redig=8F3F334EA60E4B1CB4D040DCFE393A89{SUB_RFC1766}/srchasst/srchcust.htm"

                  --------------------\\ Recherche d'autres infections

                  Aucune autre infection trouvée !

                  1 - "C:\ToolBar SD\TB_1.txt" - 27/02/2010|20:46 - Option : [1]
                  2 - "C:\ToolBar SD\TB_2.txt" - 28/02/2010|14:51 - Option : [2]

                  -----------\\ Fin du rapport a 14:51:56,78
                  1. Le 2ème rapport Ad-Report :

                    .
                    ======= RAPPORT D'AD-REMOVER 1.1.4.6_J | UNIQUEMENT XP/VISTA/7 =======
                    .
                    Mis à jour par C_XX le 05.02.2010 à 17:34
                    Contact: AdRemover.contact@gmail.com
                    Site web: http://pagesperso-orange.fr/NosTools/ad_remover.html
                    .
                    Lancé à: 14:56:34, 28/02/2010 | Mode Normal | Option: CLEAN
                    Exécuté de: C:\Ad-Remover\
                    Système d'exploitation: Microsoft® Windows XP™ Service Pack 2 v5.1.2600
                    Nom du PC: NOM-EB85C523610 | Utilisateur actuel: HP_Propri‚taire
                    .
                    ============== ÉLÉMENT(S) NEUTRALISÉ(S) ==============
                    .

                    C:\DOCUME~1\HP_PRO~1\APPLIC~1\Mozilla\FireFox\Profiles\xhmmgckg.default\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}
                    C:\Program Files\Dealio Toolbar
                    C:\Program Files\eoRezo
                    C:\Program Files\PandoBar
                    C:\DOCUME~1\HP_PRO~1\APPLIC~1\EoRezo
                    C:\DOCUME~1\HP_PRO~1\APPLIC~1\ItsLabel

                    (!) -- Fichiers temporaires supprimés.

                    .
                    HKCU\software\appdatalow\AskBarDis
                    HKCU\software\EoRezo
                    HKCU\software\ItsLabel
                    HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{0E5CBF21-D15F-11D0-8301-00AA005B4383}
                    HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{3041D03E-FD4B-44E0-B742-2D9B88305F98}
                    HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{4B3803EA-5230-4DC3-A7FC-33638F3D3542}
                    HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{E3EA4FD9-CADE-4ae5-84F7-086EEE888BE4}
                    HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{FE063DB9-4EC0-403E-8DD8-394C54984B2C}
                    HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB}
                    HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{25560540-9571-4D7B-9389-0F166788785A}
                    HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3DC201FB-E9C9-499C-A11F-23C360D7C3F8}
                    HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{64F56FC1-1272-44CD-BA6E-39723696E350}
                    HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9FF05104-B030-46FC-94B8-81276E4E27DF}
                    HKLM\software\AskBarDis
                    HKLM\software\classes\AskIBar.PopSwatterBarButton
                    HKLM\software\classes\AskIBar.PopSwatterBarButton.1
                    HKLM\software\classes\AskIBar.PopSwatterSettingsControl
                    HKLM\software\classes\AskIBar.PopSwatterSettingsControl.1
                    HKLM\software\classes\AskToolBar.SettingsPlugin
                    HKLM\software\classes\AskToolBar.SettingsPlugin.1
                    HKLM\Software\Classes\CLSID\{0702a2b6-13aa-4090-9e01-bcdc85dd933f}
                    HKLM\Software\Classes\CLSID\{08993A7C-E764-4172-9627-BFB5EA6897B2}
                    HKLM\Software\Classes\CLSID\{128A6C66-AC6A-4617-8268-AB7F47B7215E}
                    HKLM\Software\Classes\CLSID\{3B8B90F0-A76C-4a02-B44A-BB338D8D00F0}
                    HKLM\Software\Classes\CLSID\{571715D7-3395-4DF0-B43C-784836209E60}
                    HKLM\Software\Classes\CLSID\{622fd888-4e91-4d68-84d4-7262fd0811bf}
                    HKLM\Software\Classes\CLSID\{b0de3308-5d5a-470d-81b9-634fc078393b}
                    HKLM\Software\Classes\CLSID\{E3EA4FD1-CADE-4ae5-84F7-086EEE888BE4}
                    HKLM\Software\Classes\CLSID\{E3EA4FD9-CADE-4ae5-84F7-086EEE888BE4}
                    HKLM\Software\Classes\CLSID\{E3EA4FDB-CADE-4ae5-84F7-086EEE888BE4}
                    HKLM\Software\Classes\CLSID\{FE063DB1-4EC0-403e-8DD8-394C54984B2C}
                    HKLM\Software\Classes\CLSID\{FE063DB9-4EC0-403e-8DD8-394C54984B2C}
                    HKLM\Software\Classes\CLSID\{FE063DBB-4EC0-403e-8DD8-394C54984B2C}
                    HKLM\Software\Classes\Interface\{4634804A-F0B0-4A74-A550-FC0EEF8A4362}
                    HKLM\Software\Classes\Interface\{4C07EA4F-5F52-4222-B170-4CD9ED33BAEA}
                    HKLM\Software\Classes\Interface\{B0D071A1-36B3-4757-A126-14C89C56013A}
                    HKLM\Software\Classes\Interface\{C44FEFF4-EF0C-4CF7-83D0-92B4266A32B9}
                    HKLM\Software\Classes\Interface\{E3EA4FDA-CADE-4AE5-84F7-086EEE888BE4}
                    HKLM\Software\Classes\Interface\{E3EA4FDC-CADE-4AE5-84F7-086EEE888BE4}
                    HKLM\Software\Classes\Interface\{F131923C-381D-4E4C-A472-4A17118FD742}
                    HKLM\software\classes\PandoBar.SettingsPlugin
                    HKLM\software\classes\PandoBar.SettingsPlugin.1
                    HKLM\software\classes\PandoBar.ToolbarPlugin
                    HKLM\software\classes\PandoBar.ToolbarPlugin.1
                    HKLM\Software\Classes\TypeLib\{4B1C1E16-6B34-430E-B074-5928ECA4C150}
                    HKLM\Software\Classes\TypeLib\{B4C656C9-F2E9-4E77-B3F4-443DF2BD778F}
                    HKLM\Software\Classes\TypeLib\{D2E5FA06-DCC7-46F9-BEFF-BFD06F69B9B2}
                    HKLM\Software\Classes\TypeLib\{E3EA4FD0-CADE-4AE5-84F7-086EEE888BE4}
                    HKLM\software\EoRezo
                    HKLM\Software\Microsoft\Internet Explorer\Toolbar\\{E3EA4FD9-CADE-4ae5-84F7-086EEE888BE4}
                    HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E3EA4FD1-CADE-4ae5-84F7-086EEE888BE4}
                    HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\EoEngine
                    HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\InstantAccess
                    HKLM\software\microsoft\windows\currentversion\uninstall\Ask Toolbar_is1
                    HKLM\software\microsoft\windows\currentversion\uninstall\PandoBar Uninstall
                    HKLM\software\PandoBar
                    .
                    ============== Scan additionnel ==============
                    .
                    .
                    * Mozilla FireFox Version [Impossible d'obtenir la version] *
                    .
                    Nom du profil: xhmmgckg.default (HP_Propri‚taire)
                    .
                    (HP_PRO~1, prefs.js) Browser.startup.homepage, hxxp://www.vlcsearch.com/?cfg=1-1-1-115i
                    (HP_PRO~1, prefs.js) Browser.search.selectedEngine, Ask
                    .
                    .
                    * Internet Explorer Version 6.0.2900.2180 *
                    .
                    [HKEY_CURRENT_USER\..\Internet Explorer\Main]
                    .
                    Do404Search: 01000000
                    Local Page: C:\WINDOWS\system32\blank.htm
                    Show_ToolBar: yes
                    Start Page: hxxp://fr.msn.com/
                    Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
                    Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                    Search Bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
                    Use Custom Search URL: 1 (0x1)
                    Use Search Asst: no
                    Enable Browser Extensions: yes
                    SearchAssistant: hxxp://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
                    .
                    [HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]
                    .
                    Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
                    Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                    Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                    Delete_Temp_Files_On_Exit: yes
                    Local Page: %SystemRoot%\system32\blank.htm
                    Start Page: hxxp://fr.msn.com/
                    Search Bar: hxxp://search.msn.com/spbasic.htm
                    Use Custom Search URL: 0 (0x0)
                    Use search Asst: no
                    .
                    [HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]
                    .
                    Tabs: res://ieframe.dll/tabswelcome.htm
                    .
                    ============== Suspect (Cracks, Serials, ...) ==============
                    .
                    C:\Documents and Settings\All Users\Documents\Pinnacle\Content\HollywoodFX\HfxSerial.exe
                    C:\Documents and Settings\HP_Propri‚taire\Mes documents\Mises … jour de programme t‚l‚charg‚es\HomeTheater 2 HP CPC\HomeTheater 2 HP Update 2.6.1.133 (French)\IHT2.6.1.133HP(CPC)_logid32206patch.exe
                    .
                    ===================================
                    .
                    6621 Octet(s) - C:\Ad-Report-CLEAN[1].log
                    8964 Octet(s) - C:\Ad-Report-SCAN[1].log
                    .
                    96 Fichier(s) - C:\DOCUME~1\HP_PRO~1\LOCALS~1\Temp
                    15 Fichier(s) - C:\WINDOWS\Temp
                    10 Fichier(s) - C:\WINDOWS\Prefetch
                    .
                    19 Fichier(s) - C:\Ad-Remover\BACKUP
                    70 Fichier(s) - C:\Ad-Remover\QUARANTINE
                    .
                    Fin à: 15:06:23 | 28/02/2010 - CLEAN[1]
                    .
                    ============== E.O.F ==============
                    .
                    1. Le 3ème Rapport UsbFix (après lequel j'ai eu vraiment chaud parce que mon pc ne se connectait plus à ma box, mais après un redémarrage tout est rentré dans l'ordre !) :

                      ############################## | UsbFix V6.097 |

                      User : HP_Propriétaire (Administrateurs) # NOM-EB85C523610
                      Update on 20/02/2010 by El Desaparecido , C_XX & Chimay8
                      Start at: 18:03:31 | 28/02/2010
                      Website : http://pagesperso-orange.fr/NosTools/index.html
                      Contact : FindyKill.Contact@gmail.com

                      AMD Athlon(tm) 64 Processor 3000+
                      Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 2
                      Internet Explorer 6.0.2900.2180
                      Windows Firewall Status : Enabled
                      AV : AntiVir Desktop 9.0.1.32 [ Enabled | Updated ]

                      C:\ -> Disque fixe local # 179,33 Go (103,63 Go free) [HP_PAVILION] # NTFS
                      D:\ -> Disque fixe local # 6,96 Go (3,11 Go free) [HP_RECOVERY] # FAT32
                      E:\ -> Disque CD-ROM
                      F:\ -> Disque CD-ROM
                      G:\ -> Disque amovible
                      H:\ -> Disque amovible
                      I:\ -> Disque amovible
                      J:\ -> Disque amovible
                      K:\ -> Disque fixe local # 931,28 Go (902,38 Go free) [PACKARDBELL] # FAT32
                      L:\ -> Disque amovible
                      N:\ -> Disque amovible # 7,42 Go (6,93 Go free) [IPOD (PATRI] # FAT32

                      ############################## | Processus actifs |

                      C:\WINDOWS\System32\smss.exe
                      C:\WINDOWS\system32\csrss.exe
                      C:\WINDOWS\system32\winlogon.exe
                      C:\WINDOWS\system32\services.exe
                      C:\WINDOWS\system32\lsass.exe
                      C:\WINDOWS\system32\Ati2evxx.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
                      C:\WINDOWS\system32\spoolsv.exe
                      C:\Program Files\Avira\AntiVir Desktop\sched.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\system32\Ati2evxx.exe
                      C:\Program Files\Google\Update\GoogleUpdate.exe
                      C:\WINDOWS\Explorer.EXE
                      C:\Program Files\Google\Update\GoogleUpdate.exe
                      C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                      C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                      C:\Program Files\Bonjour\mDNSResponder.exe
                      C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                      C:\Program Files\Google\Update\GoogleUpdate.exe
                      C:\Program Files\Java\jre6\bin\jqs.exe
                      c:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
                      C:\Program Files\Fichiers communs\Microsoft Shared\Media Manager\airsvcu.exe
                      C:\Program Files\Fichiers communs\Nero\Nero BackItUp 4\NBService.exe
                      C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe
                      C:\Program Files\Nero\Nero BackItUp 4\IoctlSvc.exe
                      C:\Program Files\Packard Bell\Software Suite\PowerSave\PSPBSSS.exe
                      C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\system32\wuauclt.exe
                      C:\WINDOWS\system32\wbem\wmiapsrv.exe
                      C:\WINDOWS\System32\alg.exe
                      C:\WINDOWS\system32\wbem\wmiprvse.exe
                      C:\WINDOWS\system32\wbem\wmiprvse.exe

                      ################## | Elements infectieux |

                      Supprimé ! C:\Documents and Settings\HP_Propri‚taire\new.txt
                      Supprimé ! C:\Recycler\S-1-5-21-4096709876-1069044103-4087124974-1007
                      Supprimé ! D:\autorun.inf
                      Supprimé ! K:\autorun.inf

                      ################## | Registre |

                      ################## | Mountpoints2 |

                      Supprimé ! HKCU\...\Explorer\MountPoints2\{e85e7262-1473-11dd-98d4-001109f56ec5}\Shell\AutoRun\Command

                      ################## | Listing des fichiers présent |

                      [28/02/2010 15:06|--a------|7006] C:\Ad-Report-CLEAN[1].log
                      [27/02/2010 21:00|--a------|8964] C:\Ad-Report-SCAN[1].log
                      [25/01/2009 16:41|--a------|40] C:\Auth.prof
                      [23/11/2004 22:21|--a------|0] C:\AUTOEXEC.BAT
                      [23/11/2005 21:48|-rahs----|218] C:\BOOT.BAK
                      [16/04/2008 19:35|-rahs----|296] C:\boot.ini
                      [05/08/2004 13:00|-rahs----|4952] C:\Bootfont.bin
                      [05/08/2004 13:00|-r-hs----|263488] C:\cmldr
                      [28/02/2010 18:07|--ah-----|12] C:\cmsstorage.lst
                      [23/11/2004 22:21|--a------|0] C:\CONFIG.SYS
                      [28/04/2007 19:33|--a------|91171328] C:\file000001.avi
                      [28/04/2007 19:35|--a------|22300160] C:\file000002.avi
                      [28/04/2007 19:38|--a------|103877120] C:\file000003.avi
                      [13/01/2008 19:16|--a------|1948] C:\fixnavi.txt
                      [05/09/2001 22:00|--a------|1700352] C:\gdiplus.dll
                      [?|?|?] C:\hiberfil.sys
                      [01/01/2005 07:26|--ah-----|2] C:\hpbi.log
                      [22/01/2007 16:35|--a------|2295] C:\INSTALL.LOG
                      [23/11/2004 22:21|-rahs----|0] C:\IO.SYS
                      [23/11/2004 22:21|-rahs----|0] C:\MSDOS.SYS
                      [05/08/2004 13:00|-rahs----|47564] C:\NTDETECT.COM
                      [20/09/2008 19:35|-rahs----|252240] C:\ntldr
                      [?|?|?] C:\pagefile.sys
                      [28/02/2010 14:51|--a------|3191] C:\TB.txt
                      [20/01/2008 13:56|--a------|79] C:\TCleaner.txt
                      [24/05/2001 12:59|--a------|162304] C:\UNWISE.EXE
                      [28/02/2010 18:07|--a------|4517] C:\UsbFix.txt
                      [11/12/2005 20:33|--a------|23] C:\wxp.ini
                      [28/07/2001 07:07|---hs----|0] D:\AUTOEXEC.BAT
                      [16/09/2004 16:27|---hs----|6] D:\BLOCK.RIN
                      [09/01/2002 20:52|---hs----|244] D:\BOOT.INI
                      [17/08/2001 10:26|---hs----|237728] D:\CMLDR
                      [28/07/2001 07:07|---hs----|0] D:\CONFIG.SYS
                      [10/09/2002 00:14|---hs----|100] D:\Desktop.ini
                      [10/09/2002 18:21|---hs----|7850] D:\Folder.htt
                      [30/04/2001 21:16|---hs----|14] D:\Graph
                      [25/01/2002 19:21|---hs----|0] D:\GRAPH16
                      [30/11/2004 13:01|---hs----|73728] D:\Info.exe
                      [28/07/2001 07:07|---hs----|0] D:\IO.SYS
                      [05/05/2005 14:01|---hs----|904] D:\MASTER.LOG
                      [28/07/2001 07:07|---hs----|0] D:\MSDOS.SYS
                      [25/07/2001 23:00|---hs----|45124] D:\NTDETECT.COM
                      [17/08/2001 16:32|---hs----|0] D:\NTFS
                      [25/07/2001 23:00|---hs----|222880] D:\NTLDR
                      [10/09/2002 15:58|---hs----|181616] D:\protect.ed
                      [23/11/2004 17:39|---hs----|36] D:\SaveFile.Dir
                      [30/04/2001 21:16|---hs----|14] D:\SVGA
                      [01/01/2005 00:58|--ahs----|900] D:\USER
                      [09/02/2002 00:44|---hs----|88038] D:\Warning.bmp
                      [18/08/2001 16:00|---hs----|10] D:\WIN51
                      [22/01/2001 16:00|---hs----|11] D:\WIN51.B2
                      [25/07/2001 16:00|---hs----|11] D:\WIN51.RC1
                      [25/07/2001 21:47|---hs----|11] D:\WIN51.RC2
                      [18/08/2001 16:00|---hs----|10] D:\WIN51IC
                      [20/03/2001 16:00|---hs----|11] D:\WIN51IC.B2
                      [25/07/2001 16:00|---hs----|11] D:\WIN51IC.RC1
                      [25/07/2001 16:00|---hs----|11] D:\WIN51IC.RC2
                      [17/08/2001 16:00|---hs----|10] D:\WIN51IP
                      [22/01/2001 16:00|---hs----|11] D:\WIN51IP.B2
                      [25/07/2001 21:47|---hs----|11] D:\WIN51IP.RC2
                      [17/08/2001 14:17|---hs----|184] D:\WINBOM.INI
                      [24/02/2004 17:38|--a------|498] D:\BATCH.OLD
                      [01/01/2005 00:59|--ahs----|1552] D:\BATCH.LOG
                      [01/02/2005 15:49|---hs----|535] D:\install.bat
                      [01/03/2005 17:39|---hs----|7] D:\Softthinks_MLSP_ALL_BLU_WW-01.block
                      [01/03/2005 17:39|---hs----|2213] D:\Softthinks_MLSP_ALL_BLU_WW.txt
                      [05/05/2005 14:01|-r-hs----|26] D:\RCBoot.sys
                      [05/05/2005 15:06|--ahs----|22] D:\HPCD.sys
                      [28/02/2010 18:07|--ah-----|0] D:\cmsstorage.lst
                      [15/12/2006 12:14|--a------|32256] D:\sans.wcp
                      [29/04/2009 01:33|--a------|3026] K:\ClickMe MAC.htm
                      [19/05/2009 01:31|--a------|151664] K:\ClickMe.exe
                      [19/05/2009 18:24|--a------|215248] K:\Store20090518.dat
                      [23/11/2004 23:25|--a------|693] K:\chantillons d'images.lnk
                      [22/05/2007 22:51|--a------|818993868] K:\T-818993868-Cours de Danse - Danse orientale bon niveau.mpeg
                      [24/05/2007 18:37|--a------|726439102] K:\Bruce Lee - Big Boss DVD Rip Fr DivX 5.2 Par Sthepirat.avi
                      [25/05/2007 22:29|--a------|734021632] K:\Bruce Lee - Operation Dragon - DVDRip Fr.avi
                      [28/05/2007 15:56|--a------|664877056] K:\Gad Elmaleh La Vie Normale Divx Francais.avi
                      [02/06/2007 23:41|--a------|733933568] K:\CO Florence.Foresti.Fait.Des.Sketches.A.La.Cigale.avi
                      [04/06/2007 13:25|--a------|372807680] K:\Florence Foresti - Best Of on a tout ‚ssay‚ (Bonus DVD).avi
                      [04/06/2007 17:05|--a------|733433856] K:\Florence.Foresti.A.Tout.Essaye.FRENCH.DVDRip.XviD-OTHERS-David91.avi
                      [12/05/2008 01:28|--a------|735604736] K:\Bienvenue.Chez.Les.Chtis.FRENCH.DVDSCR.XViD-Get24.avi
                      [07/11/2008 23:38|--a------|734083072] K:\Gad_Elmaleh_Papa_est_en_haut_Spectacle_2008_(trŠs_bonne_qualit‚).avi
                      [20/12/2008 14:27|--a------|734083072] K:\Papa est en haut.avi
                      [25/01/2009 16:15|--a------|808750132] K:\La vie est belle.avi
                      [25/02/2009 13:33|--a------|12705989] K:\TV-LG.pdf
                      [18/03/2009 13:21|--a------|1363848] K:\PersonnalisezVotrePC.exe
                      [23/07/2009 02:57|--a------|684077] K:\100_0047.JPG
                      [10/08/2009 15:03|--a------|903512] K:\100_0050.JPG
                      [10/08/2009 15:07|--a------|860318] K:\100_0051.JPG
                      [10/08/2009 15:07|--a------|908951] K:\100_0053.JPG
                      [13/08/2009 21:11|--a------|527049] K:\100_0087.JPG
                      [13/08/2009 21:12|--a------|543310] K:\100_0088.JPG
                      [24/01/2010 12:47|--ahs----|61952] K:\Thumbs.db
                      [24/11/2009 21:08|--a------|941769] K:\AMALE.jpg
                      [24/01/2010 00:58|--a------|3906224640] K:\Vid-20100124-001.avi
                      [07/02/2010 19:38|--a------|19968] K:\MDPS.doc
                      [18/10/2063 06:30|---------|0] N:\.metadata_never_index

                      ################## | Vaccination |

                      # C:\autorun.inf -> Dossier créé par UsbFix (El Desaparecido).
                      # D:\autorun.inf -> Dossier créé par UsbFix (El Desaparecido).
                      # K:\autorun.inf -> Dossier créé par UsbFix (El Desaparecido).
                      # N:\autorun.inf -> Dossier créé par UsbFix (El Desaparecido).

                      ################## | Upload |

                      Veuillez envoyer le fichier : C:\UsbFix_Upload_Me_NOM-EB85C523610.zip : https://www.ionos.fr/?affiliate_id=77097
                      Merci pour votre contribution .

                      ################## | ! Fin du rapport # UsbFix V6.097 ! |
                      1. bonjour,
                        repasse un autre rsit et poste son rapport
                        note : tu n'auras qu'un seul rapport (log.txt)
                        1. bonjour,

                          Le rapport je te l'envoie en plusieurs parties pour qu'il n'arrive pas incomplet :

                          Logfile of random's system information tool 1.06 (written by random/random)
                          Run by HP_Propriétaire at 2010-03-01 17:22:03
                          Microsoft Windows XP Édition familiale Service Pack 2
                          System drive C: has 106 GB (58%) free of 184 GB
                          Total RAM: 1022 MB (47% free)

                          Logfile of Trend Micro HijackThis v2.0.2
                          Scan saved at 17:22:11, on 01/03/2010
                          Platform: Windows XP SP2 (WinNT 5.01.2600)
                          MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                          Boot mode: Normal

                          Running processes:
                          C:\WINDOWS\System32\smss.exe
                          C:\WINDOWS\system32\winlogon.exe
                          C:\WINDOWS\system32\services.exe
                          C:\WINDOWS\system32\lsass.exe
                          C:\WINDOWS\system32\Ati2evxx.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
                          C:\WINDOWS\system32\spoolsv.exe
                          C:\Program Files\Avira\AntiVir Desktop\sched.exe
                          C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                          C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                          C:\Program Files\Bonjour\mDNSResponder.exe
                          C:\Program Files\Java\jre6\bin\jqs.exe
                          c:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
                          C:\Program Files\Google\Update\GoogleUpdate.exe
                          C:\Program Files\Fichiers communs\Microsoft Shared\Media Manager\airsvcu.exe
                          C:\Program Files\Fichiers communs\Nero\Nero BackItUp 4\NBService.exe
                          C:\Program Files\Nero\Nero BackItUp 4\IoctlSvc.exe
                          C:\Program Files\Packard Bell\Software Suite\PowerSave\PSPBSSS.exe
                          C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\system32\wbem\wmiapsrv.exe
                          C:\WINDOWS\system32\Ati2evxx.exe
                          C:\WINDOWS\Explorer.EXE
                          C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
                          C:\Program Files\Ashampoo\Ashampoo FireWall\FireWall.exe
                          C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe
                          C:\Program Files\Hercules\Hercules DualPix HD Webcam\CamService.exe
                          C:\Program Files\Java\jre6\bin\jusched.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\Program Files\QuickTime\QTTask.exe
                          C:\Program Files\iTunes\iTunesHelper.exe
                          C:\Program Files\HiYo\bin\HiYo.exe
                          C:\WINDOWS\system32\wuauclt.exe
                          C:\Program Files\TomTom HOME\TomTomHOME.exe
                          C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                          C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
                          C:\WINDOWS\system32\ctfmon.exe
                          C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
                          C:\Program Files\SFR\Media Center\MediaCenter.exe
                          C:\Program Files\Packard Bell\Software Suite\PBSoftSuite.exe
                          C:\Program Files\Fichiers communs\LightScribe\LightScribeControlPanel.exe
                          C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                          C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkCalRem.exe
                          C:\Program Files\SFR\Media Center\httpd\httpd.exe
                          C:\Program Files\iPod\bin\iPodService.exe
                          C:\Program Files\SFR\Media Center\httpd\httpd.exe
                          C:\Program Files\Packard Bell\Software Suite\pbDevDetect.exe
                          C:\Program Files\Windows Live\Contacts\wlcomm.exe
                          C:\Documents and Settings\HP_Propriétaire\Bureau\RSIT.exe
                          C:\Program Files\trend micro\HP_Propriétaire.exe

                          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://actus.sfr.fr
                          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://actus.sfr.fr
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://actus.sfr.fr
                          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
                          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = https://actus.sfr.fr
                          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer
                          R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                          R3 - Default URLSearchHook is missing
                          O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
                          O2 - BHO: Videoraptor_WebRipPlugin Class - {3C0372C2-04C3-4100-BAB1-1D42C552BC48} - C:\Program Files\RapidSolution\AudialsOne\Mediaraptor\plugins\IE\MR_WebRipIePlugin.dll
                          O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
                          O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                          O2 - BHO: Tunebite_WebRipPlugin Class - {AA102584-3B97-47e7-B9BC-75D54C110A7D} - C:\Program Files\RapidSolution\AudialsOne\Tunebite\plugins\IE\TB_WebRipIePlugin.dll
                          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                          O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll
                          O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                          O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                          O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
                          O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                          O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
                          O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
                          O4 - HKLM\..\Run: [Ashampoo FireWall] "C:\Program Files\Ashampoo\Ashampoo FireWall\FireWall.exe" -TRAY
                          O4 - HKLM\..\Run: [RegisterDropHandler] C:\PROGRA~1\TEXTBR~1.0\Bin\REGIST~1.EXE
                          O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe"
                          O4 - HKLM\..\Run: [HerculesCamService] C:\Program Files\Hercules\Hercules DualPix HD Webcam\CamService.exe
                          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                          O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                          O4 - HKLM\..\Run: [Hiyo] C:\Program Files\HiYo\bin\HiYo.exe /RunFromStartup
                          O4 - HKLM\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME\TomTomHOME.exe" -s
                          O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                          O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero BackItUp 4\NBKeyScan.exe"
                          O4 - HKLM\..\Run: [Nero MediaHome 4] "C:\Program Files\Nero\Nero MediaHome 4\NeroMediaHome.exe" /AUTORUN
                          O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
                          O4 - HKLM\..\RunServices: [RegisterDropHandler] C:\PROGRA~1\TEXTBR~1.0\Bin\REGIST~1.EXE
                          O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                          O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                          O4 - HKCU\..\Run: [Neuf Media Center] "C:\Program Files\SFR\Media Center\MediaCenter.exe"
                          O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\HP_Propriétaire\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
                          O4 - HKCU\..\Run: [Packard Bell Software Suite] "C:\Program Files\Packard Bell\Software Suite\PBSoftSuite.exe" /run
                          O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Fichiers communs\LightScribe\LightScribeControlPanel.exe -hidden
                          O4 - S-1-5-21-4096709876-1069044103-4087124974-1010 Startup: AutoTBar.exe (User 'NeroMediaHomeUser.4')
                          O4 - S-1-5-21-4096709876-1069044103-4087124974-1010 User Startup: AutoTBar.exe (User 'NeroMediaHomeUser.4')
                          O4 - .DEFAULT User Startup: AutoTBar.exe (User 'Default user')
                          O4 - Startup: Présentation de Media Manager.lnk = C:\Program Files\Fichiers communs\Microsoft Shared\Media Manager\SPLASHA.EXE
                          O4 - Startup: wkcalrem.LNK = C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkCalRem.exe
                          O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                          O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
                          O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                          O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                          O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                          O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                          O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Fichiers communs\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
                          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                          O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
                          O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
                          O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w3/resources/MSNPUpld.cab
                          O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
                          O16 - DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} (HpProductDetection Class) - http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
                          O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
                          O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} (Windows Live Hotmail Photo Upload Tool) - http://gfx1.hotmail.com/mail/w4/pr01/photouploadcontrol/MSNPUpld.cab
                          O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
                          O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
                          O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
                          O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                          O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                          O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                          O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                          O23 - Service: Service Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
                          O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
                          O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                          O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
                          O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
                          O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Fichiers communs\Nero\Nero BackItUp 4\NBService.exe
                          O23 - Service: Nero MediaHome 4 Service (NeroMediaHomeService.4) - Nero AG - C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe
                          O23 - Service: NMIndexingService - Unknown owner - C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe (file missing)
                          O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\Program Files\Nero\Nero BackItUp 4\IoctlSvc.exe
                          O23 - Service: PowerSave Service (PowerSave) - Packard Bell Services - C:\Program Files\Packard Bell\Software Suite\PowerSave\PSPBSSS.exe
                        2. bonjour,
                          je recommence à envoyer le rapport par parties :

                          1° partie :

                          Logfile of random's system information tool 1.06 (written by random/random)
                          Run by HP_Propriétaire at 2010-03-01 17:22:03
                          Microsoft Windows XP Édition familiale Service Pack 2
                          System drive C: has 106 GB (58%) free of 184 GB
                          Total RAM: 1022 MB (47% free)

                          Logfile of Trend Micro HijackThis v2.0.2
                          Scan saved at 17:22:11, on 01/03/2010
                          Platform: Windows XP SP2 (WinNT 5.01.2600)
                          MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                          Boot mode: Normal

                          Running processes:
                          C:\WINDOWS\System32\smss.exe
                          C:\WINDOWS\system32\winlogon.exe
                          C:\WINDOWS\system32\services.exe
                          C:\WINDOWS\system32\lsass.exe
                          C:\WINDOWS\system32\Ati2evxx.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
                          C:\WINDOWS\system32\spoolsv.exe
                          C:\Program Files\Avira\AntiVir Desktop\sched.exe
                          C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                          C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                          C:\Program Files\Bonjour\mDNSResponder.exe
                          C:\Program Files\Java\jre6\bin\jqs.exe
                          c:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
                          C:\Program Files\Google\Update\GoogleUpdate.exe
                          C:\Program Files\Fichiers communs\Microsoft Shared\Media Manager\airsvcu.exe
                          C:\Program Files\Fichiers communs\Nero\Nero BackItUp 4\NBService.exe
                          C:\Program Files\Nero\Nero BackItUp 4\IoctlSvc.exe
                          C:\Program Files\Packard Bell\Software Suite\PowerSave\PSPBSSS.exe
                          C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\system32\wbem\wmiapsrv.exe
                          C:\WINDOWS\system32\Ati2evxx.exe
                          C:\WINDOWS\Explorer.EXE
                          C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
                          C:\Program Files\Ashampoo\Ashampoo FireWall\FireWall.exe
                          C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe
                          C:\Program Files\Hercules\Hercules DualPix HD Webcam\CamService.exe
                          C:\Program Files\Java\jre6\bin\jusched.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\Program Files\QuickTime\QTTask.exe
                          C:\Program Files\iTunes\iTunesHelper.exe
                          C:\Program Files\HiYo\bin\HiYo.exe
                          C:\WINDOWS\system32\wuauclt.exe
                          C:\Program Files\TomTom HOME\TomTomHOME.exe
                          C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                          C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
                          C:\WINDOWS\system32\ctfmon.exe
                          C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
                          C:\Program Files\SFR\Media Center\MediaCenter.exe
                          C:\Program Files\Packard Bell\Software Suite\PBSoftSuite.exe
                          C:\Program Files\Fichiers communs\LightScribe\LightScribeControlPanel.exe
                          C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                          C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkCalRem.exe
                          C:\Program Files\SFR\Media Center\httpd\httpd.exe
                          C:\Program Files\iPod\bin\iPodService.exe
                          C:\Program Files\SFR\Media Center\httpd\httpd.exe
                          C:\Program Files\Packard Bell\Software Suite\pbDevDetect.exe
                          C:\Program Files\Windows Live\Contacts\wlcomm.exe
                          C:\Documents and Settings\HP_Propriétaire\Bureau\RSIT.exe
                          C:\Program Files\trend micro\HP_Propriétaire.exe

                          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://recherche.neuf.fr/ie/default.html
                          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://recherche.neuf.fr/
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://recherche.neuf.fr/
                          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
                          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://recherche.neuf.fr/ie/default.html
                          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer
                          R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                          R3 - Default URLSearchHook is missing
                          O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
                          O2 - BHO: Videoraptor_WebRipPlugin Class - {3C0372C2-04C3-4100-BAB1-1D42C552BC48} - C:\Program Files\RapidSolution\AudialsOne\Mediaraptor\plugins\IE\MR_WebRipIePlugin.dll
                          O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
                          O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                          O2 - BHO: Tunebite_WebRipPlugin Class - {AA102584-3B97-47e7-B9BC-75D54C110A7D} - C:\Program Files\RapidSolution\AudialsOne\Tunebite\plugins\IE\TB_WebRipIePlugin.dll
                          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                          O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll
                          O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                          O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                          O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
                          O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                          O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
                          O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
                          O4 - HKLM\..\Run: [Ashampoo FireWall] "C:\Program Files\Ashampoo\Ashampoo FireWall\FireWall.exe" -TRAY
                          O4 - HKLM\..\Run: [RegisterDropHandler] C:\PROGRA~1\TEXTBR~1.0\Bin\REGIST~1.EXE
                          O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe"
                          O4 - HKLM\..\Run: [HerculesCamService] C:\Program Files\Hercules\Hercules DualPix HD Webcam\CamService.exe
                          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                          O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                          O4 - HKLM\..\Run: [Hiyo] C:\Program Files\HiYo\bin\HiYo.exe /RunFromStartup
                          O4 - HKLM\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME\TomTomHOME.exe" -s
                          O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                          O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero BackItUp 4\NBKeyScan.exe"
                          O4 - HKLM\..\Run: [Nero MediaHome 4] "C:\Program Files\Nero\Nero MediaHome 4\NeroMediaHome.exe" /AUTORUN
                          O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
                          O4 - HKLM\..\RunServices: [RegisterDropHandler] C:\PROGRA~1\TEXTBR~1.0\Bin\REGIST~1.EXE
                          O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                          O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                          O4 - HKCU\..\Run: [Neuf Media Center] "C:\Program Files\SFR\Media Center\MediaCenter.exe"
                          O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\HP_Propriétaire\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
                          O4 - HKCU\..\Run: [Packard Bell Software Suite] "C:\Program Files\Packard Bell\Software Suite\PBSoftSuite.exe" /run
                          O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Fichiers communs\LightScribe\LightScribeControlPanel.exe -hidden
                          O4 - S-1-5-21-4096709876-1069044103-4087124974-1010 Startup: AutoTBar.exe (User 'NeroMediaHomeUser.4')
                          O4 - S-1-5-21-4096709876-1069044103-4087124974-1010 User Startup: AutoTBar.exe (User 'NeroMediaHomeUser.4')
                          O4 - .DEFAULT User Startup: AutoTBar.exe (User 'Default user')
                          O4 - Startup: Présentation de Media Manager.lnk = C:\Program Files\Fichiers communs\Microsoft Shared\Media Manager\SPLASHA.EXE
                          O4 - Startup: wkcalrem.LNK = C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkCalRem.exe
                          O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                          O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
                          O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                          O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                          O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                          O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                          O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Fichiers communs\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
                          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                          O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
                          O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
                          O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w3/resources/MSNPUpld.cab
                          O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
                          O16 - DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} (HpProductDetection Class) - http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
                          O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
                          O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} (Windows Live Hotmail Photo Upload Tool) - http://gfx1.hotmail.com/mail/w4/pr01/photouploadcontrol/MSNPUpld.cab
                          O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
                          O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
                          O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
                          O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                          O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                          O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                          O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                          O23 - Service: Service Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
                          O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
                          O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                          O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
                          O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
                          O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Fichiers communs\Nero\Nero BackItUp 4\NBService.exe
                          O23 - Service: Nero MediaHome 4 Service (NeroMediaHomeService.4) - Nero AG - C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe
                          O23 - Service: NMIndexingService - Unknown owner - C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe (file missing)
                          O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\Program Files\Nero\Nero BackItUp 4\IoctlSvc.exe
                          O23 - Service: PowerSave Service (PowerSave) - Packard Bell Services - C:\Program Files\Packard Bell\Software Suite\PowerSave\PSPBSSS.exe
                      2. 2° partie :

                        ======Scheduled tasks folder======

                        C:\WINDOWS\tasks\AppleSoftwareUpdate.job
                        C:\WINDOWS\tasks\Google Software Updater.job
                        C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
                        C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
                        C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-4096709876-1069044103-4087124974-1007Core.job
                        C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-4096709876-1069044103-4087124974-1007UA.job
                        C:\WINDOWS\tasks\Symantec NetDetect.job

                        ======Registry dump======

                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
                        RealPlayer Download and Record Plugin for Internet Explorer - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll [2010-02-13 329312]

                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3C0372C2-04C3-4100-BAB1-1D42C552BC48}]
                        Videoraptor_WebRipPlugin Class - C:\Program Files\RapidSolution\AudialsOne\Mediaraptor\plugins\IE\MR_WebRipIePlugin.dll [2009-09-11 173456]

                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
                        Search Helper - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll [2009-05-19 137600]

                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
                        Programme d'aide de l'Assistant de connexion Windows Live - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]

                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA102584-3B97-47e7-B9BC-75D54C110A7D}]
                        Tunebite_WebRipPlugin Class - C:\Program Files\RapidSolution\AudialsOne\Tunebite\plugins\IE\TB_WebRipIePlugin.dll [2009-09-11 173360]

                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
                        Google Toolbar Helper - c:\program files\google\googletoolbar1.dll [2007-03-14 2436160]

                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
                        Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll [2009-12-05 764912]

                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
                        Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-10-11 41760]

                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10}]
                        Windows Live Toolbar Helper - C:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-02-06 1068904]

                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
                        JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-10-11 73728]

                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]

                        {21FA44EF-376D-4D53-9B0F-8A89D3229068} - &Windows Live Toolbar - C:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-02-06 1068904]

                        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
                        "ISUSScheduler"=C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe [2005-02-16 81920]
                        "ISUSPM Startup"=C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\isuspm.exe [2005-02-16 221184]
                        "Ashampoo FireWall"=C:\Program Files\Ashampoo\Ashampoo FireWall\FireWall.exe [2007-04-05 3251800]
                        "RegisterDropHandler"=C:\PROGRA~1\TEXTBR~1.0\Bin\REGIST~1.EXE [1998-07-07 22528]
                        "Adobe Photo Downloader"=C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe [2005-06-23 57344]
                        "HerculesCamService"=C:\Program Files\Hercules\Hercules DualPix HD Webcam\CamService.exe [2006-10-13 106496]
                        "SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-10-11 149280]
                        "QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2009-11-10 417792]
                        "iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2009-11-12 141600]
                        "Hiyo"=C:\Program Files\HiYo\bin\HiYo.exe [2009-12-12 210288]
                        "TomTomHOME.exe"=C:\Program Files\TomTom HOME\TomTomHOME.exe [2006-12-12 3577512]
                        "TkBellExe"=C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe [2010-02-13 198160]
                        "NBKeyScan"=C:\Program Files\Nero\Nero BackItUp 4\NBKeyScan.exe [2008-12-05 2254120]
                        "Nero MediaHome 4"=C:\Program Files\Nero\Nero MediaHome 4\NeroMediaHome.exe [2009-04-20 4859176]
                        "avgnt"=C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [2009-03-02 209153]

                        [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
                        "ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2004-08-05 15360]
                        "msnmsgr"=C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe [2009-07-26 3883856]
                        "Neuf Media Center"=C:\Program Files\SFR\Media Center\MediaCenter.exe [2008-10-10 726336]
                        "Google Update"=C:\Documents and Settings\HP_Propriétaire\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-04-21 133104]
                        "Packard Bell Software Suite"=C:\Program Files\Packard Bell\Software Suite\PBSoftSuite.exe [2009-04-10 2901024]
                        "LightScribe Control Panel"=C:\Program Files\Fichiers communs\LightScribe\LightScribeControlPanel.exe [2009-08-20 2363392]

                        C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage
                        HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

                        C:\Documents and Settings\HP_Propriétaire\Menu Démarrer\Programmes\Démarrage
                        Présentation de Media Manager.lnk - C:\Program Files\Fichiers communs\Microsoft Shared\Media Manager\SPLASHA.EXE
                        wkcalrem.LNK - C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkCalRem.exe

                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
                        C:\WINDOWS\system32\Ati2evxx.dll [2004-11-04 90112]

                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
                        C:\WINDOWS\system32\WgaLogon.dll [2007-02-15 236928]

                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
                        WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

                        [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]

                        [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\aawservice]

                        [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
                        "NoFind"=0
                        "NoRun"=0
                        "NoDesktop"=0
                        "NoClose"=0
                        "StartMenuLogOff"=0
                        "HideClock"=0

                        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
                        "dontdisplaylastusername"=0
                        "legalnoticecaption"=
                        "legalnoticetext"=
                        "shutdownwithoutlogon"=1
                        "undockwithoutlogon"=1

                        [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
                        "NoDriveTypeAutoRun"=255
                        "NoDriveAutoRun"=255
                        "HonorAutoRunSetting"=0

                        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
                        "HonorAutoRunSetting"=
                        "BackupNoCDBurning"=
                        "NoDriveAutoRun"=
                        "NoDriveTypeAutoRun"=

                        [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
                        "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
                        "C:\Program Files\AOL 9.0\waol.exe"="C:\Program Files\AOL 9.0\waol.exe:*:Enabled:AOL France"
                        "C:\Program Files\IncrediMail\bin\ImApp.exe"="C:\Program Files\IncrediMail\bin\ImApp.exe:*:Enabled:IncrediMail"
                        "C:\Program Files\IncrediMail\bin\IncMail.exe"="C:\Program Files\IncrediMail\bin\IncMail.exe:*:Enabled:IncrediMail"
                        "C:\Program Files\IncrediMail\bin\ImpCnt.exe"="C:\Program Files\IncrediMail\bin\ImpCnt.exe:*:Enabled:IncrediMail"
                        "C:\Program Files\Pando Networks\Pando\pando.exe"="C:\Program Files\Pando Networks\Pando\pando.exe:*:Enabled:pando"
                        "C:\Program Files\Hercules\Hercules DualPix HD Webcam\Station2.exe"="C:\Program Files\Hercules\Hercules DualPix HD Webcam\Station2.exe:*:Enabled:Hercules Webcam Station Evolution"
                        "C:\Program Files\LimeWire\LimeWire.exe"="C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire"
                        "C:\Program Files\eMule\emule.exe"="C:\Program Files\eMule\emule.exe:*:Enabled:eMule"
                        "C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
                        "C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe"="C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live FolderShare"
                        "C:\Program Files\Pinnacle\Studio 12\Programs\RM.exe"="C:\Program Files\Pinnacle\Studio 12\Programs\RM.exe:*:Enabled:Render Manager"
                        "C:\Program Files\Pinnacle\Studio 12\Programs\Studio.exe"="C:\Program Files\Pinnacle\Studio 12\Programs\Studio.exe:*:Enabled:Studio"
                        "C:\Program Files\Pinnacle\Studio 12\Programs\umi.exe"="C:\Program Files\Pinnacle\Studio 12\Programs\umi.exe:*:Enabled:umi"
                        "C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
                        "C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe"="C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe:*:Enabled:Nero MediaHome 4"
                        "C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype. Take a deep breath "
                        "C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
                        "C:\Program Files\iTunes\iTunes.exe"="C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes"
                        "C:\Program Files\SFR\Media Center\httpd\httpd.exe"="C:\Program Files\SFR\Media Center\httpd\httpd.exe:172.16.255.0/255.255.255.0,192.168.1.0/255.255.255.0:Enabled:Serveur de partage Media Center (Player SFR)"

                        [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
                        "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
                        "%ProgramFiles%\iTunes\iTunes.exe"="%ProgramFiles%\iTunes\iTunes.exe:*:enabled:iTunes"
                        "C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
                        "C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe"="C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live FolderShare"
                        1. Et 3° et dernière partie :

                          ======List of files/folders created in the last 1 months======

                          2010-02-28 18:07:47 ----RASHD---- C:\autorun.inf
                          2010-02-28 18:02:48 ----A---- C:\UsbFix.txt
                          2010-02-28 17:49:43 ----A---- C:\WINDOWS\system32\ptpusb.dll
                          2010-02-28 17:49:42 ----A---- C:\WINDOWS\system32\ptpusd.dll
                          2010-02-27 20:45:46 ----A---- C:\TB.txt
                          2010-02-27 20:45:13 ----D---- C:\ToolBar SD
                          2010-02-27 11:18:44 ----D---- C:\UsbFix
                          2010-02-26 21:00:37 ----HDC---- C:\WINDOWS\$NtUninstallKB979306$
                          2010-02-26 00:11:12 ----D---- C:\Ad-Remover
                          2010-02-25 23:58:50 ----D---- C:\Program Files\Avira
                          2010-02-25 23:58:50 ----D---- C:\Documents and Settings\All Users\Application Data\Avira
                          2010-02-24 21:09:56 ----A---- C:\WINDOWS\NeroDigital.ini
                          2010-02-24 19:26:19 ----HDC---- C:\WINDOWS\$NtUninstallKB952011$
                          2010-02-21 23:13:36 ----D---- C:\Program Files\iTunes
                          2010-02-21 23:13:36 ----D---- C:\Program Files\iPod
                          2010-02-21 22:35:36 ----D---- C:\Program Files\iPod(4)
                          2010-02-21 22:35:22 ----D---- C:\Program Files\iTunes(4)
                          2010-02-16 21:53:50 ----D---- C:\Documents and Settings\HP_Propriétaire\Application Data\Nero
                          2010-02-16 20:42:52 ----D---- C:\Program Files\Nero
                          2010-02-16 20:42:10 ----D---- C:\Program Files\Fichiers communs\Nero
                          2010-02-14 18:47:26 ----D---- C:\Documents and Settings\HP_Propriétaire\Application Data\RapidSolution
                          2010-02-14 18:38:25 ----D---- C:\Program Files\PixiePack Codec Pack
                          2010-02-14 18:37:00 ----D---- C:\Documents and Settings\All Users\Application Data\Rapidsolution
                          2010-02-14 18:36:02 ----D---- C:\Program Files\RapidSolution
                          2010-02-14 17:54:17 ----D---- C:\Program Files\Windows Sidebar
                          2010-02-14 17:53:24 ----A---- C:\WINDOWS\Irremote.ini
                          2010-02-14 17:23:28 ----D---- C:\Documents and Settings\All Users\Application Data\LightScribe
                          2010-02-14 17:13:43 ----A---- C:\WINDOWS\system32\regsvr32.exe.log
                          2010-02-13 20:30:47 ----D---- C:\Program Files\Fichiers communs\Skype
                          2010-02-13 20:30:44 ----RD---- C:\Program Files\Skype
                          2010-02-13 20:28:18 ----D---- C:\Program Files\Fichiers communs\xing shared
                          2010-02-11 20:46:31 ----D---- C:\Program Files\Foxit Software
                          2010-02-11 20:46:31 ----D---- C:\Documents and Settings\HP_Propriétaire\Application Data\Foxit
                          2010-02-10 19:32:48 ----HDC---- C:\WINDOWS\$NtUninstallKB978262$
                          2010-02-10 19:32:38 ----HDC---- C:\WINDOWS\$NtUninstallKB971468$
                          2010-02-10 19:29:51 ----HDC---- C:\WINDOWS\$NtUninstallKB978037$
                          2010-02-10 19:29:41 ----HDC---- C:\WINDOWS\$NtUninstallKB978251$
                          2010-02-10 19:29:31 ----HDC---- C:\WINDOWS\$NtUninstallKB975560$
                          2010-02-10 19:28:50 ----HDC---- C:\WINDOWS\$NtUninstallKB977914$
                          2010-02-10 19:28:35 ----HDC---- C:\WINDOWS\$NtUninstallKB978706$
                          2010-02-10 19:28:13 ----HDC---- C:\WINDOWS\$NtUninstallKB977165$
                          2010-02-10 19:01:43 ----A---- C:\WINDOWS\system32\imagXpr7.dll
                          2010-02-10 19:01:43 ----A---- C:\WINDOWS\system32\imagX7.dll
                          2010-02-04 19:50:22 ----D---- C:\Program Files\iPod(3)
                          2010-02-04 19:50:02 ----D---- C:\Program Files\iTunes(3)
                          2010-02-03 19:41:50 ----D---- C:\SAVOIR

                          ======List of files/folders modified in the last 1 months======

                          2010-03-01 17:22:07 ----D---- C:\WINDOWS\Prefetch
                          2010-03-01 17:22:04 ----D---- C:\Program Files\Trend Micro
                          2010-03-01 17:12:00 ----A---- C:\WINDOWS\SchedLgU.Txt
                          2010-03-01 16:49:40 ----D---- C:\WINDOWS\Temp
                          2010-03-01 15:56:03 ----D---- C:\Program Files
                          2010-03-01 14:50:11 ----D---- C:\WINDOWS\Tasks
                          2010-03-01 10:47:54 ----D---- C:\WINDOWS\system32\CatRoot2
                          2010-02-28 19:16:08 ----SHD---- C:\Documents and Settings\HP_Propriétaire\Application Data\.#
                          2010-02-28 18:36:58 ----D---- C:\WINDOWS
                          2010-02-28 18:31:52 ----HD---- C:\WINDOWS\inf
                          2010-02-28 18:07:42 ----SHD---- C:\RECYCLER
                          2010-02-28 17:49:48 ----D---- C:\WINDOWS\system32
                          2010-02-26 21:01:02 ----SHD---- C:\WINDOWS\Installer
                          2010-02-26 21:01:02 ----HD---- C:\Config.Msi
                          2010-02-26 21:01:01 ----D---- C:\WINDOWS\WinSxS
                          2010-02-26 19:14:06 ----D---- C:\rsit
                          2010-02-25 23:59:08 ----D---- C:\WINDOWS\system32\drivers
                          2010-02-24 19:26:38 ----D---- C:\WINDOWS\system32\dllcache
                          2010-02-21 23:15:09 ----D---- C:\WINDOWS\system32\config
                          2010-02-21 23:14:37 ----D---- C:\WINDOWS\system32\wbem
                          2010-02-21 23:14:36 ----D---- C:\WINDOWS\Registration
                          2010-02-19 21:12:57 ----D---- C:\WINDOWS\Debug
                          2010-02-18 19:49:47 ----D---- C:\Documents and Settings\All Users\Application Data\Apple
                          2010-02-17 21:53:41 ----D---- C:\Documents and Settings\HP_Propriétaire\Application Data\Skype
                          2010-02-17 21:49:51 ----D---- C:\Documents and Settings\HP_Propriétaire\Application Data\skypePM
                          2010-02-16 22:10:15 ----D---- C:\Documents and Settings
                          2010-02-16 20:47:08 ----D---- C:\Documents and Settings\All Users\Application Data\Nero
                          2010-02-16 20:42:10 ----D---- C:\Program Files\Fichiers communs
                          2010-02-16 20:42:01 ----D---- C:\Program Files\Fichiers communs\Microsoft Shared
                          2010-02-14 21:26:36 ----D---- C:\WINDOWS\SxsCaPendDel
                          2010-02-14 19:49:01 ----AD---- C:\Program Files\Fichiers communs\LightScribe
                          2010-02-14 16:38:32 ----D---- C:\Documents and Settings\HP_Propriétaire\Application Data\dvdcss
                          2010-02-13 20:30:43 ----D---- C:\Documents and Settings\All Users\Application Data\Skype
                          2010-02-13 20:28:49 ----D---- C:\Program Files\Fichiers communs\Real
                          2010-02-13 20:28:42 ----A---- C:\WINDOWS\system32\rmoc3260.dll
                          2010-02-13 20:28:26 ----A---- C:\WINDOWS\system32\pndx5032.dll
                          2010-02-13 20:28:26 ----A---- C:\WINDOWS\system32\pndx5016.dll
                          2010-02-13 20:27:51 ----A---- C:\WINDOWS\system32\pncrt.dll
                          2010-02-11 19:48:50 ----D---- C:\Program Files\Fichiers communs\Adobe
                          2010-02-11 19:48:48 ----D---- C:\Documents and Settings\All Users\Application Data\Adobe
                          2010-02-10 22:48:08 ----D---- C:\WINDOWS\system32\CatRoot
                          2010-02-10 19:32:47 ----HD---- C:\WINDOWS\$hf_mig$
                          2010-02-10 19:19:51 ----D---- C:\WINDOWS\Minidump
                          2010-02-10 18:58:17 ----A---- C:\WINDOWS\system32\MsiExec.exe.log
                          2010-02-03 19:41:53 ----D---- C:\WINDOWS\system
                          2010-02-03 19:41:53 ----A---- C:\WINDOWS\win.ini
                          2010-02-03 19:41:53 ----A---- C:\WINDOWS\system.ini

                          ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

                          R1 AmdK8;Pilote de processeur AMD Athlon64; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2004-05-08 38912]
                          R1 AvgArCln;Avg Anti-Rootkit Clean Driver; C:\WINDOWS\System32\DRIVERS\AvgArCln.sys [2007-01-18 3968]
                          R1 avgio;avgio; \??\C:\Program Files\Avira\AntiVir Desktop\avgio.sys []
                          R1 avipbb;avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [2009-03-30 96104]
                          R1 ssmdrv;ssmdrv; C:\WINDOWS\system32\DRIVERS\ssmdrv.sys [2009-05-11 28520]
                          R1 SYMTDI;SYMTDI; C:\WINDOWS\System32\Drivers\SYMTDI.SYS [2007-02-07 269616]
                          R1 WS2IFSL;Environnement de prise en charge de Fournisseur de services non-IFS Windows Sockets 2.0; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2004-08-05 12032]
                          R2 avgntflt;avgntflt; C:\WINDOWS\system32\DRIVERS\avgntflt.sys [2009-11-25 56816]
                          R3 AgereSoftModem;Agere Systems Soft Modem; C:\WINDOWS\system32\DRIVERS\AGRSM.sys [2004-06-29 1268204]
                          R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2004-10-01 2279424]
                          R3 APL531;Hercules Dualpix HD Webcam; C:\WINDOWS\System32\Drivers\HDvid.sys [2006-09-27 274816]
                          R3 Arp1394;Protocole client ARP 1394; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2004-08-05 60800]
                          R3 ASFWHide;ASFWHide; \??\C:\DOCUME~1\HP_PRO~1\LOCALS~1\Temp\ASFWHide []
                          R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2004-11-04 821248]
                          R3 camfilt;camfilt; C:\WINDOWS\System32\Drivers\camfilt.sys [2006-10-03 22656]
                          R3 Cap7134;ASUS TV7134 WDM Video Capture; C:\WINDOWS\system32\DRIVERS\Cap7134.sys [2004-10-27 335360]
                          R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\SYSTEM32\DRIVERS\GEARAspiWDM.sys [2009-05-18 26600]
                          R3 Iviaspi;IVI ASPI Shell; C:\WINDOWS\system32\drivers\iviaspi.sys [2003-09-11 21060]
                          R3 MarvinBus;Pinnacle Marvin Bus; C:\WINDOWS\system32\DRIVERS\MarvinBus.sys [2005-09-23 171520]
                          R3 NIC1394;Pilote réseau 1394; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2004-08-05 61824]
                          R3 Pfc;Padus ASPI Shell; C:\WINDOWS\system32\drivers\pfc.sys [2003-09-19 10368]
                          R3 PhTVTune;ASUS WDM TV Tuner; C:\WINDOWS\system32\DRIVERS\PhTVTune.sys [2004-10-24 24544]
                          R3 Ps2;PS2; C:\WINDOWS\system32\DRIVERS\PS2.sys [2001-06-04 14112]
                          R3 rtl8139;Realtek RTL8139/810x Family Fast Ethernet NIC NT Driver; C:\WINDOWS\system32\DRIVERS\R8139n51.SYS [2002-10-04 46976]
                          R3 SymEvent;SymEvent; \??\C:\Program Files\Symantec\SYMEVENT.SYS []
                          R3 tbhsd;Tunebite High-Speed Dubbing; C:\WINDOWS\system32\drivers\tbhsd.sys [2009-09-11 37664]
                          R3 usbaudio;Pilote USB audio (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2004-08-03 59264]
                          R3 usbccgp;Pilote parent générique USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-03 31616]
                          R3 usbehci;Pilote miniport de contrôleur d'hôte amélioré Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2004-08-05 26624]
                          R3 usbhub;Concentrateur USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2004-08-05 57600]
                          R3 usbohci;Pilote miniport de contrôleur hôte ouvert USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbohci.sys [2004-08-04 17024]
                          R3 USBSTOR;Pilote de stockage de masse USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
                          S1 intelppm;Pilote de processeur Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys []
                          S1 kbdhid;Pilote HID de clavier; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2004-08-03 14848]
                          S3 61883;Pilote d'unité 61883; C:\WINDOWS\system32\DRIVERS\61883.sys [2004-08-03 48128]
                          S3 Avc;Périphérique AVC; C:\WINDOWS\system32\DRIVERS\avc.sys [2004-08-03 38912]
                          S3 catchme;catchme; \??\C:\DOCUME~1\HP_PRO~1\LOCALS~1\Temp\catchme.sys []
                          S3 CCDECODE;Décodeur sous-titre fermé; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2004-08-04 17024]
                          S3 HidUsb;Pilote de classe HID Microsoft; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-08-17 9600]
                          S3 ltmodem5;LT Modem Driver; C:\WINDOWS\system32\DRIVERS\ltmdmnt.sys [2004-08-04 607452]
                          S3 mouhid;Pilote HID de souris; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-23 12288]
                          S3 MSDV;Microsoft DV Camera and VCR; C:\WINDOWS\system32\DRIVERS\msdv.sys [2004-08-03 51328]
                          S3 MSTEE;Convertisseur en T/site-à-site de répartition Microsoft; C:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-04 5504]
                          S3 NABTSFEC;Codec NABTS/FEC VBI; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-08-04 85376]
                          S3 NdisIP;Connection TV/vidéo Microsoft; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2004-08-04 10880]
                          S3 pcouffin;VSO Software pcouffin; C:\WINDOWS\System32\Drivers\pcouffin.sys [2007-04-21 47360]
                          S3 SLIP;Détrameur décalage BDA; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2004-08-04 11136]
                          S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2004-08-04 15360]
                          S3 SYMDNS;SYMDNS; C:\WINDOWS\System32\Drivers\SYMDNS.SYS [2007-02-07 11536]
                          S3 SYMFW;SYMFW; C:\WINDOWS\System32\Drivers\SYMFW.SYS [2007-02-07 173392]
                          S3 SYMIDS;SYMIDS; C:\WINDOWS\System32\Drivers\SYMIDS.SYS [2007-02-07 36976]
                          S3 SYMNDIS;SYMNDIS; C:\WINDOWS\System32\Drivers\SYMNDIS.SYS [2007-02-07 47184]
                          S3 SYMREDRV;SYMREDRV; C:\WINDOWS\System32\Drivers\SYMREDRV.SYS [2007-02-07 17968]
                          S3 USBAAPL;Apple Mobile USB Driver; C:\WINDOWS\System32\Drivers\usbaapl.sys [2009-08-28 40448]
                          S3 usbprint;Classe d'imprimantes USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-03 25856]
                          S3 usbscan;Pilote de scanneur USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 15104]
                          S3 usbuhci;Pilote miniport de contrôleur hôte universel USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2004-08-05 20480]
                          S3 usbvideo;Périphérique vidéo USB (WDM); C:\WINDOWS\System32\Drivers\usbvideo.sys [2004-08-03 78464]
                          S3 WSTCODEC;Codec Teletext standard; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-08-04 19328]
                          S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
                          S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
                          S4 IntelIde;IntelIde; C:\WINDOWS\system32\DRIVERS\intelide.sys [2004-08-04 5504]

                          ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

                          R2 aawservice;Lavasoft Ad-Aware Service; C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe [2008-07-07 611664]
                          R2 AntiVirSchedulerService;Avira AntiVir Planificateur; C:\Program Files\Avira\AntiVir Desktop\sched.exe [2009-05-13 108289]
                          R2 AntiVirService;Avira AntiVir Guard; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [2009-07-21 185089]
                          R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2009-08-28 144672]
                          R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2004-11-04 413696]
                          R2 Bonjour Service;Service Bonjour; C:\Program Files\Bonjour\mDNSResponder.exe [2008-12-12 238888]
                          R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-10-11 153376]
                          R2 LightScribeService;LightScribeService Direct Disc Labeling Service; c:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe [2009-08-20 73728]
                          R2 MMIndexer;Indexer de Media Manager; C:\Program Files\Fichiers communs\Microsoft Shared\Media Manager\airsvcu.exe [1997-07-30 137216]
                          R2 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0; C:\Program Files\Fichiers communs\Nero\Nero BackItUp 4\NBService.exe [2009-04-17 935208]
                          R2 NeroMediaHomeService.4;Nero MediaHome 4 Service; C:\Program Files\Nero\Nero MediaHome 4\NMMediaServerService.exe [2009-04-20 259368]
                          R2 PLFlash DeviceIoControl Service;PLFlash DeviceIoControl Service; C:\Program Files\Nero\Nero BackItUp 4\IoctlSvc.exe [2008-12-05 81920]
                          R2 PowerSave;PowerSave Service; C:\Program Files\Packard Bell\Software Suite\PowerSave\PSPBSSS.exe [2009-04-06 1002016]
                          R2 SeaPort;SeaPort; C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-05-19 240512]
                          R3 iPod Service;Service de l’iPod; C:\Program Files\iPod\bin\iPodService.exe [2009-11-12 545568]
                          S2 gupdate;Service Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-01-06 135664]
                          S2 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2010-01-30 194032]
                          S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
                          S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
                          S3 Fax;Fax; C:\WINDOWS\system32\fxssvc.exe [2004-08-05 268800]
                          S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
                          S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-03 69632]
                          S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
                          S3 NMIndexingService;NMIndexingService; C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe []
                          S3 WMPNetworkSvc;Service Partage réseau du Lecteur Windows Media; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-11-03 918016]
                          S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2004-08-05 14336]
                          S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
                          S4 SNDSrvc;Symantec Network Drivers Service; c:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe [2007-02-07 206544]

                          -----------------EOF-----------------
                          1. Bonjour,
                            je vais te raconter l'histoire toute l'histoire !
                            j'ai fait la suppression de Norton comme indiqué, puis juste après j'ai fait la mise à jour SP3 et j'ai arrêté mon ordinateur parce qu'il était tard. Le lendemain, j'ai voulu démarrer mon pc, il s'allume et arrivé à la page de démarrage : là où j'ai le choix entre démarrer windows normalement ou avec la dernière configuration, il ne finissait pas le démarrage : il se remet en veille et redémarre 1, 2...10 fois sans démarrer vraiment ! j'ai essayé de le démarrer avec la dernière config sans résultat ! Alors j'étais obligée de choisir le mode sans échec et faire une restauration à une heure antérieure aux dernières manip effectuée (mise à jour sp3 + suppression Norton) !
                            J'ai eu vraiment chaud et là j'appréhende toute manip et j'ose pas reprendre tes instructions (c'est pas parce que j'ai pas confiance mais parce que je suis nulle !) ! Alors si tu as une explication à tout ça, c'est du à quoi..? et si je dois refaire les manips.. ? je te remercie.
                            1. bonsoir,
                              pas mal comme histoire, mais je vais te raconter la mienne :
                              il y a quelques années, au moment des fêtes, j'ai commandé au père noël, une boule de christal afin de pouvoir résoudre tous les problèmes, voir donner des explications aux personnes qui m'intérpèlent, mais hélas, à ce jour, toujours pas de réponde de sa part !

                              pour en revenir à notre sujet, ne fais pas de mise à jour et passe directement à MBAM, poste 18 et suis bien ce que j'ai noté :-)

                              @++
                              1. j'attands le rapport de MBAM
                                en attendant, bonne nuit et à demain :)
                                1. bonjour,
                                  ..et voici l'histoire après l'exécution de MBAM :

                                  Malwarebytes' Anti-Malware 1.44
                                  Version de la base de données: 3825
                                  Windows 5.1.2600 Service Pack 2
                                  Internet Explorer 6.0.2900.2180

                                  05/03/2010 17:02:39
                                  mbam-log-2010-03-05 (17-02-39).txt

                                  Type de recherche: Examen complet (C:\|D:\|K:\|)
                                  Eléments examinés: 334953
                                  Temps écoulé: 2 hour(s), 32 minute(s), 17 second(s)

                                  Processus mémoire infecté(s): 0
                                  Module(s) mémoire infecté(s): 0
                                  Clé(s) du Registre infectée(s): 6
                                  Valeur(s) du Registre infectée(s): 0
                                  Elément(s) de données du Registre infecté(s): 2
                                  Dossier(s) infecté(s): 0
                                  Fichier(s) infecté(s): 0

                                  Processus mémoire infecté(s):
                                  (Aucun élément nuisible détecté)

                                  Module(s) mémoire infecté(s):
                                  (Aucun élément nuisible détecté)

                                  Clé(s) du Registre infectée(s):
                                  HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{4b18dd50-c996-44fc-ac52-0fecff82ed58} (Adware.Hotbar) -> Quarantined and deleted successfully.
                                  HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{90b5a95a-afd5-4d11-b9bd-a69d53d22226} (Adware.Hotbar) -> Quarantined and deleted successfully.
                                  HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{09f1adac-76d8-4d0f-99a5-5c907dadb988} (Rogue.Multiple) -> Quarantined and deleted successfully.
                                  HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{b64f4a7c-97c9-11da-8bde-f66bad1e3f3a} (Rogue.WinAntiVirus) -> Quarantined and deleted successfully.
                                  HKEY_LOCAL_MACHINE\SOFTWARE\Error Safe Free (Rogue.Errorsafe) -> Quarantined and deleted successfully.
                                  HKEY_LOCAL_MACHINE\SOFTWARE\winantivirus pro 2006 (Rogue.WinAntiVirus) -> Quarantined and deleted successfully.

                                  Valeur(s) du Registre infectée(s):
                                  (Aucun élément nuisible détecté)

                                  Elément(s) de données du Registre infecté(s):
                                  HKEY_CURRENT_USER\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
                                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

                                  Dossier(s) infecté(s):
                                  (Aucun élément nuisible détecté)

                                  Fichier(s) infecté(s):
                                  (Aucun élément nuisible détecté)
                                  1. bonsoir,
                                    . télécharges Ccleaner à partir de cette adresse et enregistres le sur le bureau

                                    https://www.commentcamarche.net/telecharger/utilitaires/5647-ccleaner/

                                    .double-cliques sur le fichier pour lancer l'installation
                                    .sur la fenêtre de l'installation langage bien choisir français et OK
                                    .cliques sur suivant
                                    .lis la licence et j'accepte
                                    .cliques sur suivant
                                    .la tu ne gardes de coché que mettre un raccourci sur le bureau et puis contrôler automatiquement les mises à jour de Ccleaner
                                    .cliques sur intaller
                                    .cliques sur fermer
                                    .double-cliques sur l'icône de Ccleaner pour l'ouvrir
                                    .une fois ouvert tu cliques sur option et puis avancé
                                    .tu décoches effacer uniquement les fichiers, du dossier temp de windows plus vieux que 48 heures
                                    .cliques sur nettoyeur
                                    .cliques sur windows et dans la colonne avancé
                                    .cochesla première case vieilles données du perfetch que celle-la ce qui te donnes la case vielles données du perfetch et la case avancé qui c'est coché automatiquement mais que celle-la
                                    .cliques sur analyse une fois l'analyse terminé
                                    .cliques sur lancer le nettoyage et sur la demande de confirmation OK il vas falloir que tu le refasses une autre fois une fois fini vériffis en appuiant de nouveau sur analyse pour être sur qu'il n'y est plus rien
                                    .cliques maintenant sur registre et puis sur rechercher les erreurs
                                    .laisses tout cochées et cliques sur réparrer les erreurs sélectionnées
                                    .il te demande de sauvegarder OUI
                                    .tu lui donnes un nom pour pouvoir la retrouver et enregistre
                                    .cliques sur corriger toutes les erreurs sélectionnées et sur la demande de confirmation OK
                                    .il supprime et fermer tu vériffis en relancant rechercher les erreurs
                                    .tu retournes dans option et tu recoches la case effacer uniquement les fichiers, du dossier temp de windows plus vieux que 48 heures et sur nettoyeur, windows sous avancé tu décoches la première case vieilles données du perfetch
                                    .tu peux fermer Ccleaner
                                    • 1
                                    • 2