Analyse log Hijackthis

Bonjour et merci d'avance aux âmes charitables qui pourrront me donner 1 coup de pouce.

J'ai des petits soucis avec mon PC depuis 2 jours. Je soupçonne une infection dans la base de registre.

Ma config: Windows XP pro SP3
Dual core AMD opteron 175
2,00 G. RAM
antivirus: NOD32 3.0

log Hijack:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:03:04, on 20/12/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18372)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
D:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
D:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\qtplugin.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SuperCopier2\SuperCopier2.exe
D:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\StkASv2K.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\rundll32.exe
D:\Software\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - D:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O4 - HKLM\..\Run: [egui] "D:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nView\nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [RegistryMonitor1] C:\WINDOWS\system32\qtplugin.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SuperCopier2.exe] C:\Program Files\SuperCopier2\SuperCopier2.exe
O4 - HKCU\..\Run: [RegistryMonitor1] "C:\WINDOWS\system32\qtplugin.exe"
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [RegistryMonitor1] "C:\WINDOWS\TEMP\lvnh.tmp\svchost.exe" (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://D:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O14 - IERESET.INF: START_PAGE_URL=https://www.google.fr/?gws_rd=ssl
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} (System Requirements Lab) - https://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - http://www.zebulon.fr/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/...
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} - https://www.trendmicro.com/en_us/forHome/products/housecall.html
O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} (NVIDIA Smart Scan) - https://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} - http://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab
O23 - Service: a-squared Anti-Malware Service (a2AntiMalware) - Unknown owner - C:\Program Files\a-squared Anti-Malware\a2service.exe (file missing)
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - D:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - D:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: LogMeIn Hamachi 2.0 Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
O23 - Service: Java Quick Starter (javaquickstarterservice) - Sun Microsystems, Inc. - D:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Syntek STK1160 Service (StkASSrv) - Syntek America Inc. - C:\WINDOWS\System32\StkASv2K.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe

--
End of file - 7146 bytes
Configuration: Windows XP Internet Explorer 7.0

8 réponses

  1. Contributeur
    Salut,

    - Télécharge Malwarebytes' Anti-Malware :
    http://www.malwarebytes.org/mbam/program/mbam-setup.exe

    - Installe le > double-clic sur Mbam-setup.exe, à la fin de l'installation, il se mettra automatiquement à jour
    - Une fois installé, fermes toutes les applications en cours et lances Malwarebytes
    - Exécutes un examen rapide du pc ( tu n'auras pas accés à internet pendant l'analyse)
    - A la fin du scan clic sur " Afficher les résultats ", si Malwarebytes a trouvé des infections >> clic sur " Supprimer la sélection "
    - Si il a besoin de redémarrer le pc pour finir la désinfection, acceptes
    - Un rapport s'établira, postes son contenu.
    ...
    0
    1. Merci pour la réponse rapide Ced_king.

      10 infections ont été éliminés par malwarebytes, voici le rapport:

      Malwarebytes' Anti-Malware 1.42
      Version de la base de données: 3396
      Windows 5.1.2600 Service Pack 3
      Internet Explorer 8.0.6001.18372

      20/12/2009 13:20:17
      mbam-log-2009-12-20 (13-20-17).txt

      Type de recherche: Examen rapide
      Eléments examinés: 112347
      Temps écoulé: 4 minute(s), 10 second(s)

      Processus mémoire infecté(s): 1
      Module(s) mémoire infecté(s): 0
      Clé(s) du Registre infectée(s): 0
      Valeur(s) du Registre infectée(s): 2
      Elément(s) de données du Registre infecté(s): 0
      Dossier(s) infecté(s): 0
      Fichier(s) infecté(s): 7

      Processus mémoire infecté(s):
      C:\WINDOWS\system32\qtplugin.exe (Rootkit.Agent) -> Unloaded process successfully.

      Module(s) mémoire infecté(s):
      (Aucun élément nuisible détecté)

      Clé(s) du Registre infectée(s):
      (Aucun élément nuisible détecté)

      Valeur(s) du Registre infectée(s):
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\registrymonitor1 (Rootkit.Agent) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\registrymonitor1 (Rootkit.Agent) -> Quarantined and deleted successfully.

      Elément(s) de données du Registre infecté(s):
      (Aucun élément nuisible détecté)

      Dossier(s) infecté(s):
      (Aucun élément nuisible détecté)

      Fichier(s) infecté(s):
      C:\Documents and Settings\King\Local Settings\temp\Setup.tmp (Adware.Agent) -> Quarantined and deleted successfully.
      C:\Documents and Settings\King\Application Data\SystemProc\lsass.exe (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\Tasks\{66BA574B-1E11-49b8-909C-8CC9E0E8E015}.job (Trojan.Downloader) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\qtplugin.exe (Rootkit.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job (Trojan.Downloader) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\sshnas.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully.
      C:\WINDOWS\Temp\sshnas.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully
      0
      1. Contributeur
        Ok, vide la quarantaine de Malwarebytes --> onglet "Quarantaine" et supprime tout.

        Puis redémarre ton pc (important)

        Télécharge et installe ccleaner : https://filehippo.com/download_ccleaner/
        - Durant l'installation, décoche la case proposant la barre d'outils yahoo et décoche la case " ajouter l'option des mises à jour"

        - Une fois installé, ferme toutes les applications en cours et lance ccleaner
        - clic >> option >> avancé et décoche " effacer les fichiers etc... plus vieux que 24h
        - Sélectionne " nettoyeur " >> clic sur Analyse et nettoyage, puis referme le programme...

        ---------------------------------

        Ensuite,

        Télécharge RSIT " Random's System Information Tool " sur ton bureau : http://images.malwareremoval.com/random/RSIT.exe

        - Ferme toutes les applications en cours et double clic sur RSIT.exe
        - Selectionne " Continue " à l'ecran >> RSIT va analyser le pc et verifier si l'outil hijackthis ( version à jour) est présent sur le pc, si ce n'est pas le cas, RSIT le téléchargera >> acceptes la license
        - Une fois l'analyse terminée, 2 rapports.txt s'ouvrent,
        -->log.txt à l'écran
        -->info.txt dans la barre des tâches
        - Postes le contenu des 2 rapports
        ...
        0
        1. Voici le 1° rapport RSIT:

          Logfile of random's system information tool 1.06 (written by random/random)
          Run by King at 2009-12-20 13:40:59
          Microsoft Windows XP Professionnel Service Pack 3
          System drive C: has 2 GB (25%) free of 10 GB
          Total RAM: 2047 MB (79% free)

          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 13:42:06, on 20/12/2009
          Platform: Windows XP SP3 (WinNT 5.01.2600)
          MSIE: Internet Explorer v8.00 (8.00.6001.18372)
          Boot mode: Normal

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\nvsvc32.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\spoolsv.exe
          C:\WINDOWS\Explorer.EXE
          D:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
          C:\WINDOWS\system32\RUNDLL32.EXE
          C:\WINDOWS\system32\ctfmon.exe
          C:\Program Files\SuperCopier2\SuperCopier2.exe
          D:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
          C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
          C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
          D:\Program Files\Java\jre6\bin\jqs.exe
          C:\WINDOWS\system32\PnkBstrA.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\System32\StkASv2K.exe
          C:\WINDOWS\system32\wscntfy.exe
          C:\Documents and Settings\King\Bureau\RSIT.exe
          C:\Program Files\Internet Explorer\iexplore.exe
          C:\Program Files\Internet Explorer\iexplore.exe
          D:\Software\King.exe

          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
          R3 - URLSearchHook: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - (no file)
          O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
          O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
          O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
          O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Program Files\Java\jre6\bin\jp2ssv.dll
          O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - D:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
          O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
          O4 - HKLM\..\Run: [egui] "D:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
          O4 - HKLM\..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nView\nwiz.exe /install
          O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
          O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\QuickTime\qttask.exe" -atboottime
          O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
          O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
          O4 - HKCU\..\Run: [SuperCopier2.exe] C:\Program Files\SuperCopier2\SuperCopier2.exe
          O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
          O4 - HKUS\S-1-5-18\..\Run: [RegistryMonitor1] "C:\WINDOWS\TEMP\lvnh.tmp\svchost.exe" (User 'SYSTEM')
          O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
          O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://D:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000
          O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
          O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
          O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
          O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
          O14 - IERESET.INF: START_PAGE_URL=http://www.google.fr
          O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab
          O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - http://www.zebulon.fr/scan8/oscan8.cab
          O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
          O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/...
          O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} - http://a840.g.akamai.net/...
          O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} (NVIDIA Smart Scan) - http://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab
          O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} - http://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab
          O23 - Service: a-squared Anti-Malware Service (a2AntiMalware) - Unknown owner - C:\Program Files\a-squared Anti-Malware\a2service.exe (file missing)
          O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - D:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
          O23 - Service: Eset Service (ekrn) - ESET - D:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
          O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
          O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
          O23 - Service: LogMeIn Hamachi 2.0 Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
          O23 - Service: Java Quick Starter (javaquickstarterservice) - Sun Microsystems, Inc. - D:\Program Files\Java\jre6\bin\jqs.exe
          O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
          O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
          O23 - Service: Syntek STK1160 Service (StkASSrv) - Syntek America Inc. - C:\WINDOWS\System32\StkASv2K.exe
          O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe
          0
          1. Second rapport RSIT :

            info.txt logfile of random's system information tool 1.06 2009-12-20 13:42:08

            ======Uninstall list======

            -->D:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
            -->MsiExec /X{C5C1C0F0-D62F-4DBF-81D4-D7EF397C228B}
            -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
            7-Zip 4.65-->"D:\Program Files\7-Zip\Uninstall.exe"
            ABC (remove only)-->d:\Program Files\ABC\Uninstall.exe
            Adobe Reader 9.2 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A92000000001}
            Adobe Shockwave Player 11-->C:\WINDOWS\system32\adobe\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Adobe\SHOCKW~1\Install.log
            Archiveur WinRAR-->D:\Program Files\WinRAR\uninstall.exe
            Assistant de connexion Windows Live-->MsiExec.exe /I{DCE8CD14-FBF5-4464-B9A4-E18E473546C7}
            Battlefield 1942 Mod Launcher v1.4-->D:\Program Files\Battlefield 1942 Mod Launcher\Uninstal.exe
            Battlefield 1942-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{698D7E61-E4BF-4CA6-8A09-CF6BDBFDEF65}\setup.exe" -l0x40c
            Battlefield 2(TM)-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{04858915-9F49-4B2A-AED4-DC49A7DE6A7B}\setup.exe" -l0x40c -removeonly
            Battlegroup Frontlines Mod v1.05 Beta-->"D:\Program Files\EA GAMES\Battlefield 2\mods\bgf105\unins000.exe"
            BayGenie eBay Auction Sniper Pro Edition 3.2.2.0-->"D:\Program Files\BayGenie\ProEdition\unins000.exe"
            Call of Duty(R) - World at War(TM) 1.2 Patch-->C:\Program Files\InstallShield Installation Information\{2BF0AE92-C3BC-4112-9066-1546342B1FAE}\setup.exe -runfromtemp -l0x0409
            Call of Duty(R) - World at War(TM) 1.4 Patch-->C:\Program Files\InstallShield Installation Information\{9F01A67B-7D67-482F-9D4F-D5980A440FD4}\setup.exe -runfromtemp -l0x0409
            Call of Duty(R) - World at War(TM)-->C:\Program Files\InstallShield Installation Information\{D80A6A73-E58A-4673-AFF5-F12D7110661F}\setup.exe -runfromtemp -l0x0409
            CCleaner (remove only)-->"d:\Program Files\CCleaner\uninst.exe"
            Codeur Windows Media Série 9-->msiexec.exe /I {E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}
            Codeur Windows Media Série 9-->MsiExec.exe /I{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}
            Combined Community Codec Pack 2008-09-21 16:18-->"d:\Program Files\Combined Community Codec Pack\unins000.exe"
            Compatibility Pack for the 2007 Office system-->MsiExec.exe /X{90120000-0020-040C-0000-0000000FF1CE}
            Corel Paint Shop Pro X-->MsiExec.exe /I{1A15507A-8551-4626-915D-3D5FA095CC1B}
            DesertCombat 0.7-->C:\WINDOWS\iun6002.exe "D:\Program Files\EA GAMES\Battlefield 1942\DesertCombat.ini"
            DivX Converter-->D:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
            DivX Player-->D:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYER
            DivX Web Player-->D:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
            EPSON Logiciel imprimante-->C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\EPUPDATE.EXE /R
            EPSON Scan Tool-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9F57DB08-26D6-11D6-8AA5-0000E22DA3A0}\Setup.exe" -l0x9
            ESET NOD32 Antivirus-->MsiExec.exe /I{D63BE135-E5A0-41D3-889A-6F28A3C4C531}
            FH Historical Textures and Sounds for FH 0.7 Version 1.0-->D:\Program Files\EA GAMES\Battlefield 1942\uninst_textures_sounds.exe
            FileZilla Client 3.1.3-->D:\Program Files\FileZilla FTP Client\uninstall.exe
            Free Mp3 Wma Converter V 1.7.2-->"d:\Program Files\Free Audio Pack\unins000.exe"
            getPlus(R) for Adobe-->"C:\Program Files\NOS\bin\getPlus_HelperSvc.exe" /UninstallGet1
            Grand Theft Auto IV-->"C:\Program Files\InstallShield Installation Information\{579BA58C-F33D-4970-9953-B94B43768AC3}\setup.exe" -runfromtemp -l0x040c -removeonly
            Haali Media Splitter-->"d:\Program Files\Haali\MatroskaSplitter\uninstall.exe"
            HijackThis 2.0.2-->"D:\Software\HijackThis.exe" /uninstall
            Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
            Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
            Installation Windows Live-->C:\Program Files\Windows Live\Installer\wlarp.exe
            Installation Windows Live-->MsiExec.exe /I{46ABBC54-1872-4AA3-95E2-F2C063A63F31}
            Java(TM) 6 Update 13-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216013FF}
            La Bataille pour la Terre du Milieu™ II-->d:\Program Files\Electronic Arts\La Bataille pour la Terre du Milieu II\EAUninstall.exe
            Lame ACM MP3 Codec-->C:\WINDOWS\system32\rundll32.exe setupapi,InstallHinfSection Remove_LameMP3 132 C:\WINDOWS\INF\LameACM.inf
            L'Avènement du Roi-sorcier™-->D:\Program Files\Electronic Arts\L'Avènement du Roi-sorcier\EAUninstall.exe
            Lecteur Windows Media 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
            LogMeIn Hamachi-->C:\WINDOWS\system32\\msiexec.exe /i {067EC517-9731-43FD-B4D5-296EE0027BBB} REMOVE=ALL
            LogMeIn Hamachi-->MsiExec.exe /I{067EC517-9731-43FD-B4D5-296EE0027BBB}
            Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
            Microsoft .NET Framework 1.1 French Language Pack-->MsiExec.exe /X{9A394342-4A68-4EBA-85A6-55B559F4E700}
            Microsoft .NET Framework 1.1 Hotfix (KB928366)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"
            Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
            Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
            Microsoft .NET Framework 2.0 Language Pack - DEU-->C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0 Language Pack - DEU\install.exe
            Microsoft .NET Framework 2.0 Service Pack 2 Language Pack - FRA-->MsiExec.exe /I{72AD53CC-CCC0-3757-8480-9EE176866A7C}
            Microsoft .NET Framework 2.0 Service Pack 2-->MsiExec.exe /I{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}
            Microsoft .NET Framework 3.0 Service Pack 2 Language Pack - FRA-->MsiExec.exe /I{0BD83598-C2EF-3343-847B-7D2E84599128}
            Microsoft .NET Framework 3.0 Service Pack 2-->MsiExec.exe /I{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}
            Microsoft .NET Framework 3.5 Language Pack SP1 - fra-->MsiExec.exe /I{3E31821C-7917-367E-938E-E65FC413EA31}
            Microsoft .NET Framework 3.5 SP1-->C:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
            Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
            Microsoft Choice Guard-->MsiExec.exe /X{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}
            Microsoft Games for Windows - LIVE -->MsiExec.exe /X{4AA3D64E-9EC3-4B0F-AB91-5885AC55641F}
            Microsoft Games for Windows - LIVE Redistributable-->MsiExec.exe /X{FD052FB9-FE90-4438-B355-15EDC89D8FB1}
            Microsoft Office XP Professional avec FrontPage-->MsiExec.exe /I{9028040C-6000-11D3-8CFE-0050048383C9}
            Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
            Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17-->MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475}
            Mise à jour pour Windows Internet Explorer 8 (KB961813)-->"C:\WINDOWS\ie8updates\KB961813-IE8\spuninst\spuninst.exe"
            Module linguistique Microsoft .NET Framework 3.5 SP1- fra-->C:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 Language Pack SP1 - fra\setup.exe
            Mortal Kombat 4-->C:\WINDOWS\IsUninst.exe -f"d:\Program Files\Acclaim\Mortal Kombat 4\Uninst.isu"
            MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
            MSXML 6.0 Parser (KB925673)-->MsiExec.exe /I{FE9126DB-5F84-495A-BB46-3C724F1C2D08}
            Nero Media Player-->C:\WINDOWS\UNNMP.exe /UNINSTALL
            Nero OEM-->d:\Program Files\Ahead\nero\uninstall\UNNERO.exe /UNINSTALL
            NeroVision Express 2-->C:\WINDOWS\UNNeroVision.exe /UNINSTALL
            Norwegian Resistance Hotfix 0.86-->D:\Program Files\EA GAMES\Battlefield 1942\Uninstal_NorwegianRes.exe
            Norwegian Resistance v0.85-->D:\Program Files\EA GAMES\Battlefield 1942\Uninstal_NorwegianRes.exe
            Norwegian Resistance v0.86b Hotfixhotfix-->D:\Program Files\EA GAMES\Battlefield 1942\Uninstal_NorwegianRes.exe
            NVIDIA Drivers-->C:\WINDOWS\system32\nvuninst.exe UninstallGUI
            NVIDIA nView Desktop Manager-->C:\Program Files\NVIDIA Corporation\nView\nViewSetup.exe -uninstall
            NVIDIA PhysX-->MsiExec.exe /X{C5C1C0F0-D62F-4DBF-81D4-D7EF397C228B}
            Ogg Codecs 0.80.15039-->D:\Program Files\Xiph.Org\Ogg Codecs\uninst.exe
            On2 VP7 Personal Edition-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{DD0DDC9E-2ED4-44DD-B461-0EFC126813A0}\Setup.exe" -l0x9
            OpenAL-->"C:\Program Files\OpenAL\oalinst.exe" /U
            OpenOffice.org 3.0-->MsiExec.exe /I{6860B340-530D-46B3-91F8-1AE1F70F7C33}
            Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
            PDF Password Cracker Pro v2.0-->"d:\Program Files\PDF Password Cracker Pro v2.0\unins000.exe"
            PunkBuster Services-->C:\WINDOWS\system32\pbsvc.exe -u
            QuickTime-->MsiExec.exe /I{08CA9554-B5FE-4313-938F-D4A417B81175}
            REALTEK GbE & FE Ethernet PCI NIC Driver-->C:\Program Files\InstallShield Installation Information\{ACCA20B0-C4D1-4BF5-BF21-0A0EB5EF9730}\setup.exe -runfromtemp -removeonly
            Realtek High Definition Audio Driver-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\Setup.exe" -l0x40c -removeonly
            Ri4m v5.0.1d-->D:\Program Files\Ripp-it_AM\Ri4m_Uninstal.exe
            Ripp-It Codec Pack v 4.2.6-->D:\Program Files\Ripp-It Codec Pack\uninst.exe
            Rockstar Games Social Club-->"C:\Program Files\InstallShield Installation Information\{08B3869E-D282-424C-9AFC-870E04A4BA14}\setup.exe" -runfromtemp -l0x040c -removeonly
            Search Settings 1.2-->MsiExec.exe /X{D0C73318-7B4A-4D16-A0C4-3B83F075EA88}
            Segoe UI-->MsiExec.exe /I{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}
            Silent Hunter 4 Wolves of the Pacific-->C:\Program Files\InstallShield Installation Information\{0D005F09-A5F4-473B-A901-5735C6AF5628}\setup.exe -runfromtemp -l0x040c -removeonly
            'Steel Fury - Kharkov 1942'-->"D:\Program Files\Lighthouse Interactive\Steel Fury - Kharkov 1942\unins000.exe"
            SuperCopier2-->"C:\Program Files\SuperCopier2\SC2Uninst.exe"
            System Requirements Lab-->C:\Program Files\SystemRequirementsLab\Uninstall.exe
            TeamSpeak 2 RC2-->"d:\Program Files\Teamspeak2_RC2\unins000.exe"
            TuneUp Utilities 2008-->MsiExec.exe /I{5888428E-699C-4E71-BF71-94EE06B497DA}
            Universal Share Downloader-->"D:\Program Files\Universal Share Downloader\unins000.exe"
            VC80CRTRedist - 8.0.50727.762-->MsiExec.exe /I{767CC44C-9BBC-438D-BAD3-FD4595DD148B}
            VideoLAN VLC media player 0.7.2-->D:\Program Files\VideoLAN\VLC\uninstall.exe
            Visionneuse Journal Windows Microsoft-->MsiExec.exe /X{43DCF766-6838-4F9A-8C91-D92DA586DFA8}
            Windows Live Call-->MsiExec.exe /I{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}
            Windows Live Communications Platform-->MsiExec.exe /I{3B4E636E-9D65-4D67-BA61-189800823F52}
            Windows Live Messenger-->MsiExec.exe /X{770F1BEC-2871-4E70-B837-FB8525FFA3B1}
            Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
            Windows Presentation Foundation-->MsiExec.exe /X{BAF78226-3200-4DB4-BE33-4D922A799840}
            x264 Revision 573 x264.nl (remove only)-->"d:\Program Files\x264\x264-uninstall.exe"
            Xvid 1.1.2 final uninstall-->"D:\Program Files\Xvid\unins000.exe"

            ======Security center information======

            AV: ESET NOD32 Antivirus 3.0

            ======System event log======

            Computer Name: KING
            Event Code: 8
            Message: L'imprimante EPSON Stylus C42 Series a été vidée.

            Record Number: 24078
            Source Name: Print
            Time Written: 20091104200443.000000+060
            Event Type: warning
            User: KING\King

            Computer Name: KING
            Event Code: 36
            Message: Le service de temps n'a pas pu synchroniser l'heure système de 49152
            secondes car aucun fournisseur de temps n'a pu fournir de datage
            utilisable. L'horloge système n'est pas synchronisée.

            Record Number: 23919
            Source Name: W32Time
            Time Written: 20091101225011.000000+060
            Event Type: warning
            User:

            Computer Name: KING
            Event Code: 10005
            Message: DCOM a reçu l'erreur "%1058" lors de la mise en route du service upnphost avec les arguments ""
            pour démarrer le serveur :
            {204810B9-73B2-11D4-BF42-00B0D0118B56}

            Record Number: 23905
            Source Name: DCOM
            Time Written: 20091101100540.000000+060
            Event Type: error
            User: KING\King

            Computer Name: KING
            Event Code: 10005
            Message: DCOM a reçu l'erreur "%1058" lors de la mise en route du service upnphost avec les arguments ""
            pour démarrer le serveur :
            {204810B9-73B2-11D4-BF42-00B0D0118B56}

            Record Number: 23887
            Source Name: DCOM
            Time Written: 20091031233219.000000+060
            Event Type: error
            User: KING\King

            Computer Name: KING
            Event Code: 10005
            Message: DCOM a reçu l'erreur "%1058" lors de la mise en route du service upnphost avec les arguments ""
            pour démarrer le serveur :
            {204810B9-73B2-11D4-BF42-00B0D0118B56}

            Record Number: 23886
            Source Name: DCOM
            Time Written: 20091031221346.000000+060
            Event Type: error
            User: KING\King

            =====Application event log=====

            Computer Name: KING
            Event Code: 12001
            Message:
            Record Number: 83
            Source Name: usnjsvc
            Time Written: 20090808125819.000000+120
            Event Type:
            User:

            Computer Name: KING
            Event Code: 12001
            Message:
            Record Number: 36
            Source Name: usnjsvc
            Time Written: 20090807181900.000000+120
            Event Type:
            User:

            Computer Name: KING
            Event Code: 12001
            Message:
            Record Number: 29
            Source Name: usnjsvc
            Time Written: 20090806085917.000000+120
            Event Type:
            User:

            Computer Name: KING
            Event Code: 12001
            Message:
            Record Number: 15
            Source Name: usnjsvc
            Time Written: 20090805180052.000000+120
            Event Type:
            User:

            Computer Name: KING
            Event Code: 12001
            Message:
            Record Number: 3
            Source Name: usnjsvc
            Time Written: 20090804125456.000000+120
            Event Type:
            User:

            ======Environment variables======

            "ComSpec"=%SystemRoot%\system32\cmd.exe
            "Path"=%systemroot%\system32;%systemroot%;%systemroot%\system32\wbem;D:\Program Files\QuickTime\QTSystem;C:\Program Files\Fichiers communs\Ulead Systems\MPEG
            "windir"=%SystemRoot%
            "OS"=Windows_NT
            "PROCESSOR_ARCHITECTURE"=x86
            "PROCESSOR_LEVEL"=15
            "PROCESSOR_IDENTIFIER"=x86 Family 15 Model 35 Stepping 2, AuthenticAMD
            "PROCESSOR_REVISION"=2302
            "NUMBER_OF_PROCESSORS"=2
            "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
            "TEMP"=%SystemRoot%\TEMP
            "TMP"=%SystemRoot%\TEMP
            "FP_NO_HOST_CHECK"=NO
            "CLASSPATH"=.;C:\Program Files\Java\jre1.6.0_06\lib\ext\QTJava.zip
            "QTJAVA"=C:\Program Files\Java\jre1.6.0_06\lib\ext\QTJava.zip
            "RGSCLauncher"=d:\Program Files\Rockstar Games\Rockstar Games Social Club
            "RGSC"=d:\Program Files\Rockstar Games\Rockstar Games Social Club\1_0_0_0

            -----------------EOF-----------------
            0
            1. Contributeur
              télécharge UsbFix sur ton bureau
              Double clique sur UsbFix.exe présent sur ton bureau.
              Tape F pour français , et presse enter pour valider .
              Le second menu apparait , choisis l'option 1 ( Recherche ) .
              Un avertissement apparait , branche tes supports amovibles (clé Usb, DD externe, etc.) et clique sur OK .
              Laisse l'outil travailler, un rapport est généré à la fin de la recherche, poste son contenu

              Note : le rapport est également à C:\USBFix.txt
              ...
              0
              1. Voici donc le rapport d'USBfix :

                ############################## | UsbFix V6.066 |

                User : King (Utilisateurs) # KING
                Update on 20/12/2009 by Chiquitine29, C_XX & Chimay8
                Start at: 14:59:55 | 20/12/2009
                Website : http://pagesperso-orange.fr/NosTools/index.html
                Contact : FindyKill.Contact@gmail.com

                Dual Core AMD Opteron(tm) Processor 175
                Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 3
                Internet Explorer 8.0.6001.18372
                Windows Firewall Status : Disabled
                AV : ESET NOD32 Antivirus 3.0 3.0 [ Enabled | Updated ]

                A:\ -> Lecteur de disquettes 3 ½ pouces
                C:\ -> Disque fixe local # 9,29 Go (2,34 Go free) # NTFS
                D:\ -> Disque fixe local # 172,78 Go (14,17 Go free) # NTFS
                F:\ -> Disque amovible
                G:\ -> Disque amovible
                H:\ -> Disque fixe local # 4,24 Go (861,53 Mo free) [PRESARIO_RP] # FAT32
                I:\ -> Disque CD-ROM
                J:\ -> Disque CD-ROM
                K:\ -> Disque amovible
                L:\ -> Disque amovible

                ############################## | Processus actifs |

                C:\WINDOWS\System32\smss.exe 556
                C:\WINDOWS\system32\csrss.exe 604
                C:\WINDOWS\system32\winlogon.exe 628
                C:\WINDOWS\system32\services.exe 676
                C:\WINDOWS\system32\lsass.exe 688
                C:\WINDOWS\system32\nvsvc32.exe 868
                C:\WINDOWS\system32\svchost.exe 900
                C:\WINDOWS\system32\svchost.exe 964
                C:\WINDOWS\System32\svchost.exe 1112
                C:\WINDOWS\System32\svchost.exe 1196
                C:\WINDOWS\system32\svchost.exe 1408
                C:\WINDOWS\system32\spoolsv.exe 1448
                C:\WINDOWS\Explorer.EXE 1728
                D:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe 1972
                C:\WINDOWS\system32\RUNDLL32.EXE 1988
                C:\WINDOWS\system32\ctfmon.exe 2012
                C:\Program Files\SuperCopier2\SuperCopier2.exe 2024
                D:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe 1224
                C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe 1292
                C:\Program Files\LogMeIn Hamachi\hamachi-2.exe 1532
                D:\Program Files\Java\jre6\bin\jqs.exe 1564
                C:\WINDOWS\system32\PnkBstrA.exe 1824
                C:\WINDOWS\System32\svchost.exe 436
                C:\WINDOWS\System32\StkASv2K.exe 524
                C:\WINDOWS\system32\wuauclt.exe 1424
                C:\WINDOWS\system32\wscntfy.exe 2488
                C:\WINDOWS\System32\alg.exe 2516
                C:\WINDOWS\System32\wbem\wmiprvse.exe 3684

                ################## | Fichiers # Dossiers infectieux |

                ################## | Registre # Clés infectieuses |

                [HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System] "DisableRegistryTools"
                [HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NoDrives"
                [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NoDrives"

                ################## | Registre # Mountpoints2 |

                HKCU\..\..\Explorer\MountPoints2\{48a32178-1884-11de-9406-000854368c4f}
                Shell\AutoRun\command =E:\Autorun.exe

                ################## | Cracks / Keygens / Serials |

                "D:\Program Files\PDF Password Cracker Pro v2.0\crackpdf.exe"
                08/07/2006 15:30 |Size 610304 |Crc32 0a3127a7 |Md5 7456159797d3ccfed187d3c6f1d701e6

                "D:\Program Files\PDF Password Cracker Pro v2.0\unins000.exe"
                27/07/2009 20:50 |Size 668938 |Crc32 819bc97f |Md5 85332a17a12da3d0bf3dc08fea36f803

                "D:\Software\PDF_cracker_pro\pdfcrackerpro.exe"
                27/07/2009 20:50 |Size 1789299 |Crc32 0bdac678 |Md5 af95fd8cd2f41d6a251f0acec6a56a20

                ################## | ! Fin du rapport # UsbFix V6.066 ! |
                0
                1. Hello ced_king, je ne sais pas si tu es toujours par ici... je vois dans le rapport des clés infectieuses. Serai tu comment s'en débarraser ? un tuto ou une petite explication...?

                  Un gros merci à toi pour l'aide que tu m'as apporter jusqu'ici .

                  Bonne soirée
                  0