Virus detecte par AVAST impossible à eliminer

Bonjour,

Avast me trouve un virusdans:" C:\WINDOWS\System32\Drivers\vymmswss.sys".
J'ai demandé à Avast de le supprimer mais il revient tjrs.
Qd je vais le chercher dans son emplacement dans drivers,j'ai le message
"Impossible de supprimer Vymmswss.sys. Impoossible de lire à partir du fichier ou de la disquette source."
Que puis-je faire????? Merci de votre aide!!!!!!!!!
Bonne soirée.
Configuration: Windows XP
Firefox 3.5.5

15 réponses

Résumé de la discussion

Le sujet concerne une détection par Avast d'un virus dans C:\WINDOWS\System32\Drivers\vymmswss.sys sur Windows XP, avec impossibilité de supprimer le fichier et message d'erreur lors de lecture. Des éléments de diagnostic affluent dans la discussion, notamment des extraits de RSIT et HijackThis et des détails sur les pilotes, les tâches planifiées et les entrées du registre. Plusieurs messages notent l'incomplétude possible des premiers rapports et mentionnent des emplacements comme C:\rsit\log.txt ou les listes de services et de pilotes visibles dans les journaux pour évaluer la menace. En dernier, la discussion ne tranche pas sur une solution immédiate et met en avant la nécessité d'évaluer l'intégrité des fichiers système et d'autres indicateurs techniques pour confirmer une infection.

Bobot (l’IA à votre service)
  1. Tu pourais essayer de télécharger et installer Antivir ? (logiciel anti-cheval de trois ect... gratuit ! ;) en plus c'est mieux que Avast! ) et faire une analyse antivirus pour trouver le virsu concerné et le supprimer?
    0
    1. Méthode parano de désinfection
      0
      1. Contributeur sécurité
        bonjour

        • Télécharge Random's System Information Tool (RSIT) de Random/Random.

        http://images.malwareremoval.com/random/RSIT.exe

        • Enregistre le sur ton Bureau.

        • Double clique sur RSIT.exe pour lancer l'outil.

        • Clique sur "Continue" à l'écran Disclaimer.

        • Si l'outil HijackThis n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu s'il te le demande)

        et tu devras accepter la licence.

        • Une fois le scan terminé, deux rapports vont apparaître : poste les dans deux messages séparés stp

        Les rapports se trouvent à cet endroit:
        C:\rsit\info.txt
        C:\rsit\log.txt
        0
        1. Ci joint le rapport Log

          [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b91d2600-16e5-11dd-aca0-003005b259b6}]
          shell\AutoRun\command - J:\fsaht.cmd
          shell\open\command - J:\fsaht.cmd

          ======List of files/folders created in the last 1 months======

          2010-01-06 08:05:03 ----D---- C:\rsit
          2009-12-29 14:54:58 ----D---- C:\Program Files\Sophos
          2009-12-28 23:12:25 ----D---- C:\Program Files\Spybot - Search & Destroy
          2009-12-28 23:12:25 ----D---- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
          2009-12-28 11:16:20 ----A---- C:\WINDOWS\system32\aswBoot.exe
          2009-12-28 11:15:42 ----A---- C:\setupfre.exe
          2009-12-28 11:09:48 ----D---- C:\fichiers installations
          2009-12-28 10:44:15 ----D---- C:\THIERRY
          2009-12-28 10:23:30 ----D---- C:\Program Files\Fichiers communs\Wise Installation Wizard
          2009-12-27 14:31:53 ----D---- C:\Program Files\WinPcap
          2009-12-08 22:34:40 ----HDC---- C:\WINDOWS\$NtUninstallKB970430$
          2009-12-08 22:34:30 ----HDC---- C:\WINDOWS\$NtUninstallKB974318$
          2009-12-08 22:34:19 ----HDC---- C:\WINDOWS\$NtUninstallKB973904$
          2009-12-08 22:33:39 ----HDC---- C:\WINDOWS\$NtUninstallKB974392$
          2009-12-08 22:33:28 ----HDC---- C:\WINDOWS\$NtUninstallKB971737$

          ======List of files/folders modified in the last 1 months======

          2010-01-06 08:09:15 ----D---- C:\Program Files\Trend Micro
          2010-01-06 08:08:40 ----D---- C:\WINDOWS\Prefetch
          2010-01-06 08:06:28 ----D---- C:\Documents and Settings\Thierry\Application Data\skypePM
          2010-01-06 08:05:55 ----D---- C:\Documents and Settings\Thierry\Application Data\Skype
          2010-01-06 07:59:04 ----D---- C:\Program Files\Mozilla Firefox
          2010-01-06 07:13:24 ----D---- C:\WINDOWS\Temp
          2010-01-06 07:13:23 ----D---- C:\WINDOWS\system32\CatRoot2
          2010-01-06 07:05:52 ----SD---- C:\WINDOWS\Tasks
          2010-01-06 07:05:34 ----D---- C:\WINDOWS\system32\Lang
          2010-01-06 07:05:29 ----D---- C:\WINDOWS
          2010-01-05 22:13:18 ----A---- C:\WINDOWS\SchedLgU.Txt
          2010-01-05 19:19:15 ----D---- C:\Documents and Settings\All Users\Application Data\Google Updater
          2010-01-04 21:25:20 ----A---- C:\WINDOWS\ntbtlog.txt
          2010-01-01 10:04:28 ----RD---- C:\Program Files
          2009-12-31 22:57:24 ----D---- C:\Documents and Settings\Thierry\Application Data\vlc
          2009-12-31 22:44:29 ----D---- C:\Documents and Settings\Thierry\Application Data\dvdcss
          2009-12-30 18:23:58 ----HDC---- C:\WINDOWS\ie7
          2009-12-30 18:23:57 ----HD---- C:\WINDOWS\inf
          2009-12-30 18:21:15 ----D---- C:\WINDOWS\system32
          2009-12-28 11:55:37 ----HD---- C:\Config.Msi
          2009-12-28 11:55:37 ----D---- C:\Documents and Settings\All Users\Application Data\Avira
          2009-12-28 11:16:45 ----D---- C:\WINDOWS\system32\drivers
          2009-12-28 11:03:04 ----D---- C:\soso
          2009-12-28 10:57:43 ----SHD---- C:\WINDOWS\Installer
          2009-12-28 10:57:36 ----D---- C:\WINDOWS\WinSxS
          2009-12-28 10:56:04 ----D---- C:\Program Files\BitDefender
          2009-12-28 10:54:48 ----A---- C:\WINDOWS\bdagent.INI
          2009-12-28 10:32:37 ----SHD---- C:\RECYCLER
          2009-12-28 10:26:09 ----D---- C:\Documents and Settings
          2009-12-27 14:31:21 ----RSHDC---- C:\WINDOWS\system32\dllcache
          2009-12-12 17:54:40 ----A---- C:\WINDOWS\NeroDigital.ini
          2009-12-11 21:46:58 ----D---- C:\WINDOWS\Help
          2009-12-09 22:07:20 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
          2009-12-08 22:34:44 ----A---- C:\WINDOWS\imsins.BAK
          2009-12-08 22:34:16 ----HD---- C:\WINDOWS\$hf_mig$
          2009-12-08 22:34:05 ----D---- C:\WINDOWS\system32\fr-fr
          2009-12-08 22:34:05 ----D---- C:\Program Files\Internet Explorer
          2009-12-08 22:33:55 ----D---- C:\WINDOWS\ie7updates

          ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

          R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2009-11-25 27408]
          R1 aswSP;avast! Self Protection; C:\WINDOWS\system32\drivers\aswSP.sys [2009-11-25 114768]
          R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2009-11-25 48560]
          R1 intelppm;Pilote de processeur Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2004-08-05 40320]
          R1 kbdhid;Pilote HID de clavier; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2004-08-05 14848]
          R1 SAVRKBootTasks;Boot Tasks Driver; \??\C:\WINDOWS\system32\SAVRKBootTasks.sys []
          R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2009-11-25 20560]
          R2 aswMon2;avast! Standard Shield Support; C:\WINDOWS\system32\drivers\aswMon2.sys [2009-11-25 94160]
          R2 fssfltr;FssFltr; C:\WINDOWS\system32\DRIVERS\fssfltr_tdi.sys [2009-08-05 54752]
          R2 npf;NetGroup Packet Filter Driver; C:\WINDOWS\system32\drivers\npf.sys [2007-11-15 34064]
          R2 nvcap;nVidia WDM Video Capture (universal); C:\WINDOWS\system32\DRIVERS\nvcap.sys [2005-04-14 141582]
          R2 NVXBAR;nVidia WDM A/V Crossbar; C:\WINDOWS\system32\DRIVERS\NVxbar.sys [2005-04-14 16496]
          R3 3xHybrid;3xHybrid service; C:\WINDOWS\system32\DRIVERS\3xHybrid.sys [2005-06-23 799744]
          R3 APL531;Hercules Blog Webcam; C:\WINDOWS\System32\Drivers\BLvid.sys [2006-09-29 274816]
          R3 Arp1394;Protocole client ARP 1394; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2004-08-05 60800]
          R3 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2009-11-25 23120]
          R3 camfilt;camfilt; C:\WINDOWS\System32\Drivers\camfilt.sys [2006-10-03 22656]
          R3 E100B;Intel(R) PRO Network Connection Driver; C:\WINDOWS\system32\DRIVERS\e100b325.sys [2005-06-13 162816]
          R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2004-10-27 138240]
          R3 hidusb;Pilote de classe HID Microsoft; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2004-08-05 9600]
          R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2005-10-18 4034048]
          R3 mouhid;Pilote HID de souris; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2004-08-05 12288]
          R3 NIC1394;Pilote réseau 1394; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2004-08-05 61824]
          R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2005-08-02 3198560]
          R3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\WINDOWS\System32\Drivers\RootMdm.sys [2004-08-05 5888]
          R3 SIS163u;SiS163 usb Wireless LAN Adapter Driver; C:\WINDOWS\system32\DRIVERS\sis163u.sys [2005-06-20 215040]
          R3 usbaudio;Pilote USB audio (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2004-08-03 59264]
          R3 usbccgp;Pilote parent générique USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-05 31616]
          R3 usbehci;Pilote miniport de contrôleur d'hôte amélioré Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2004-08-03 26624]
          R3 usbhub;Concentrateur USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2004-08-03 57600]
          R3 usbstor;Pilote de stockage de masse USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-05 26496]
          R3 usbuhci;Pilote miniport de contrôleur hôte universel USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2004-08-03 20480]
          S3 catchme;catchme; \??\C:\DOCUME~1\Thierry\LOCALS~1\Temp\catchme.sys []
          S3 CCDECODE;Décodeur sous-titre fermé; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2004-08-03 17024]
          S3 HdAudAddService;Microsoft UAA Function Driver for High Definition Audio Service; C:\WINDOWS\system32\drivers\HdAudio.sys [2004-10-27 145920]
          S3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\system32\DRIVERS\HPZid412.sys [2004-06-21 51088]
          S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2004-06-21 16496]
          S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2004-06-21 21744]
          S3 MEMSWEEP2;MEMSWEEP2; \??\C:\WINDOWS\system32\3A.tmp []
          S3 MPE;Filtre BDA MPE; C:\WINDOWS\system32\DRIVERS\MPE.sys [2004-08-03 15360]
          S3 MSTEE;Convertisseur en T/site-à-site de répartition Microsoft; C:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-03 5504]
          S3 NABTSFEC;Codec NABTS/FEC VBI; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-08-03 85376]
          S3 NdisIP;Connection TV/vidéo Microsoft; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2004-08-03 10880]
          S3 nmwcd;Nokia USB Phone Parent; C:\WINDOWS\system32\drivers\nmwcd.sys [2007-02-22 137216]
          S3 nmwcdc;Nokia USB Generic; C:\WINDOWS\system32\drivers\nmwcdc.sys [2007-02-22 8320]
          S3 nmwcdcj;Nokia USB Port; C:\WINDOWS\system32\drivers\nmwcdcj.sys [2007-02-22 12288]
          S3 nmwcdcm;Nokia USB Modem; C:\WINDOWS\system32\drivers\nmwcdcm.sys [2007-02-22 12288]
          S3 PCANDIS5;PCANDIS5 NDIS Protocol Driver; \??\C:\WINDOWS\system32\PCANDIS5.SYS []
          S3 PCASp50;PCASp50 NDIS Protocol Driver; C:\WINDOWS\System32\Drivers\PCASp50.sys [2005-11-19 20096]
          S3 Profos;Profos; \??\C:\Program Files\Fichiers communs\BitDefender\BitDefender Threat Scanner\profos.sys []
          S3 SLIP;Détrameur décalage BDA; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2004-08-03 11136]
          S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2004-08-03 15360]
          S3 Trufos;Trufos; \??\C:\Program Files\Fichiers communs\BitDefender\BitDefender Threat Scanner\trufos.sys []
          S3 USB_RNDIS;Inventel Gateway; C:\WINDOWS\system32\DRIVERS\usb8023.sys [2004-08-05 12672]
          S3 usbprint;Classe d'imprimantes USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-03 25856]
          S3 usbscan;Pilote de scanneur USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 15104]
          S3 WSTCODEC;Codec Teletext standard; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-08-03 19328]
          S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-15 82688]

          ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

          R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2007-10-31 110592]
          R2 aswUpdSv;avast! iAVS4 Control Service; C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe [2009-11-25 18752]
          R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast4\ashServ.exe [2009-11-25 138680]
          R2 CLCapSvc;CyberLink Background Capture Service (CBCS); C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe [2005-09-30 249954]
          R2 CLSched;CyberLink Task Scheduler (CTS); C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe [2005-09-30 114784]
          R2 CyberLink Media Library Service;CyberLink Media Library Service; C:\Program Files\CyberLink\PowerCinema\Kernel\CLML_NTService\CLMLServer.exe [2005-09-30 61440]
          R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2005-08-02 127043]
          R2 SeaPort;SeaPort; C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-05-19 240512]
          R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2004-08-05 14336]
          R3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe [2009-11-25 254040]
          R3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast4\ashWebSv.exe [2009-11-25 352920]
          R3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2007-06-15 300544]
          S2 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-05-07 182768]
          S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
          S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
          S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
          S3 fsssvc;Service Windows Live Contrôle parental; C:\Program Files\Windows Live\Family Safety\fsssvc.exe [2009-08-05 704864]
          S3 GoogleDesktopManager-093009-130223;Google Desktop Manager 5.9.909.30391; C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [2009-10-24 30192]
          S3 idsvc;Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
          S3 NBService;NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2007-03-22 779824]
          S3 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\system32\HPZipm12.exe [2004-03-18 65536]
          S3 WMPNetworkSvc;Service Partage réseau du Lecteur Windows Media; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-11-03 918016]
          S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
          S4 NMIndexingService;NMIndexingService; C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe [2007-03-22 271920]

          -----------------EOF-----------------
          0
        2. info.txt logfile of random's system information tool 1.06 2010-01-06 08:22:47

          ======Uninstall list======

          -->C:\Program Files\Nero\Nero 7\nero\uninstall\UNNERO.exe /UNINSTALL
          -->C:\WINDOWS\UNNeroBackItUp.exe /UNINSTALL
          -->C:\WINDOWS\UNNeroMediaHome.exe /UNINSTALL
          -->C:\WINDOWS\UNNeroShowTime.exe /UNINSTALL
          -->C:\WINDOWS\UNNeroVision.exe /UNINSTALL
          -->C:\WINDOWS\UNRecode.exe /UNINSTALL
          -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
          Adobe Flash Player 10 Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
          Adobe Flash Player 9 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\FlashUtil9b.exe -uninstallDelete
          Adobe Flash Player ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
          Adobe Reader 9.1 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A91000000001}
          Adobe Shockwave Player-->C:\WINDOWS\system32\Macromed\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Macromed\SHOCKW~1\Install.log
          Apple Mobile Device Support-->MsiExec.exe /I{B5C209B1-8DDB-4642-A573-375B951514CB}
          Assistant de connexion Windows Live-->MsiExec.exe /I{D3116CC7-24DC-4CA3-9CE1-23FED836E9F2}
          avast! Antivirus-->C:\Program Files\Alwil Software\Avast4\aswRunDll.exe "C:\Program Files\Alwil Software\Avast4\Setup\setiface.dll",RunSetup
          Correctif pour Lecteur Windows Media 11 (KB939683)-->"C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
          Correctif pour Windows Internet Explorer 7 (KB947864)-->"C:\WINDOWS\ie7updates\KB947864-IE7\spuninst\spuninst.exe"
          Correctif pour Windows XP (KB914440)-->"C:\WINDOWS\$NtUninstallKB914440$\spuninst\spuninst.exe"
          Correctif pour Windows XP (KB935448)-->"C:\WINDOWS\$NtUninstallKB935448$\spuninst\spuninst.exe"
          Correctif pour Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
          Correctif pour Windows XP (KB961118)-->"C:\WINDOWS\$NtUninstallKB961118$\spuninst\spuninst.exe"
          Correctif pour Windows XP (KB970653-v3)-->"C:\WINDOWS\$NtUninstallKB970653-v3$\spuninst\spuninst.exe"
          Correctif pour Windows XP (KB976098-v2)-->"C:\WINDOWS\$NtUninstallKB976098-v2$\spuninst\spuninst.exe"
          Correctif Windows XP - KB885884-->C:\WINDOWS\$NtUninstallKB885884$\spuninst\spuninst.exe
          Correctif Windows XP - KB887472-->C:\WINDOWS\$NtUninstallKB887472$\spuninst\spuninst.exe
          Correctif Windows XP - KB888302-->C:\WINDOWS\$NtUninstallKB888302$\spuninst\spuninst.exe
          Correctif Windows XP - KB890859-->"C:\WINDOWS\$NtUninstallKB890859$\spuninst\spuninst.exe"
          Correctif Windows XP - KB891781-->C:\WINDOWS\$NtUninstallKB891781$\spuninst\spuninst.exe
          e-Carte Bleue La Banque Postale-->"C:\Program Files\InstallShield Installation Information\{11B0F8D4-FD80-4800-ABA8-50D28FF769AF}\setup.exe" -runfromtemp -l0x040c -removeonly
          eMule Plus 1.2d-->"C:\Program Files\eMule\unins000.exe"
          Fujitsu Siemens Computers WLAN 802.11b/g D1705/D1706-->C:\WINDOWS\system32\unwlsdrv.exe SiS163u
          Galerie de photos Windows Live-->MsiExec.exe /X{B131E59D-202C-43C6-84C9-68F0C37541F1}
          Google Desktop-->C:\Program Files\Google\Google Desktop Search\GoogleDesktopSetup.exe -uninstall
          Google Earth-->MsiExec.exe /I{1E04F83B-2AB9-4301-9EF7-E86307F79C72}
          Google Toolbar for Internet Explorer-->"C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_0E996B068B56FCA2.exe" /uninstall
          Google Toolbar for Internet Explorer-->MsiExec.exe /I{18455581-E099-4BA8-BC6B-F34B2F06600C}
          Hercules Blog Webcam-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{8B6490BA-FAEA-486C-BAB5-561251D5F2B1}\setup.exe" -l0x40c -removeonly
          Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
          Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
          Hotfix for Windows Media Format 11 SDK (KB929399)-->"C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
          Hotfix for Windows XP (KB915865)-->"C:\WINDOWS\$NtUninstallKB915865$\spuninst\spuninst.exe"
          Hotfix for Windows XP (KB926239)-->"C:\WINDOWS\$NtUninstallKB926239$\spuninst\spuninst.exe"
          HP Image Zone 4.2-->C:\Program Files\HP\Digital Imaging\uninstall\hpzscr01.exe -datfile hpqscr01.dat
          HP PSC & OfficeJet 4.2-->"C:\Program Files\HP\Digital Imaging\{A1062847-0846-427A-92A1-BB8251A91E91}\setup\hpzscr01.exe" -datfile hposcr04.dat
          HP Software Update-->MsiExec.exe /X{457791C5-D702-4143-A7B2-2744BE9573F2}
          Installation Windows Live-->C:\Program Files\Windows Live\Installer\wlarp.exe
          Installation Windows Live-->MsiExec.exe /I{46ABBC54-1872-4AA3-95E2-F2C063A63F31}
          Intel(R) PRO Network Connections Drivers-->Prounstl.exe
          InterVideo WinDVD-->"C:\Program Files\InstallShield Installation Information\{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}\setup.exe" REMOVEALL
          J2SE Runtime Environment 5.0-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150000}
          Java(TM) 6 Update 5-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160050}
          Java(TM) 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
          Java(TM) SE Runtime Environment 6 Update 1-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160010}
          Junk Mail filter update-->MsiExec.exe /I{E2DFE069-083E-4631-9B6C-43C48E991DE5}
          Lecteur Windows Media 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
          Macromedia Flash Player 8-->MsiExec.exe /X{6815FCDD-401D-481E-BA88-31B4754C2B46}
          Microsoft .NET Framework 1.1 French Language Pack-->MsiExec.exe /X{9A394342-4A68-4EBA-85A6-55B559F4E700}
          Microsoft .NET Framework 1.1 Security Update (KB953297)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M953297\M953297Uninstall.msp"
          Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
          Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
          Microsoft .NET Framework 2.0 Service Pack 2-->MsiExec.exe /I{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}
          Microsoft .NET Framework 3.0 Service Pack 2-->MsiExec.exe /I{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}
          Microsoft .NET Framework 3.5 SP1-->C:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
          Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
          Microsoft Choice Guard-->MsiExec.exe /X{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}
          Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
          Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
          Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
          Microsoft Office Live Add-in 1.3-->MsiExec.exe /I{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}
          Microsoft Office XP Professional avec FrontPage-->MsiExec.exe /I{9028040C-6000-11D3-8CFE-0050048383C9}
          Microsoft Search Enhancement Pack-->MsiExec.exe /X{4CBA3D4C-8F51-4D60-B27E-F6B641C571E7}
          Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
          Microsoft SQL Server 2005 Compact Edition [ENU]-->MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
          Microsoft Sync Framework Runtime Native v1.0 (x86)-->MsiExec.exe /I{8A74E887-8F0F-4017-AF53-CBA42211AAA5}
          Microsoft Sync Framework Services Native v1.0 (x86)-->MsiExec.exe /I{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}
          Microsoft User-Mode Driver Framework Feature Pack 1.5-->"C:\WINDOWS\$NtUninstallWudf01005$\spuninst\spuninst.exe"
          MioMore Desktop 2008-->C:\Program Files\InstallShield Installation Information\{7617FC2E-EA1B-4F07-A0F5-5D5F437CB32D}\Setup.exe -runfromtemp -l0x040c -removeonly
          Mise à jour critique pour Lecteur Windows Media 11 (KB959772)-->"C:\WINDOWS\$NtUninstallKB959772_WM11$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Lecteur Windows Media (KB911564)-->"C:\WINDOWS\$NtUninstallKB911564$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Lecteur Windows Media (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Lecteur Windows Media (KB954155)-->"C:\WINDOWS\$NtUninstallKB954155_WM9$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Lecteur Windows Media (KB968816)-->"C:\WINDOWS\$NtUninstallKB968816_WM9$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Lecteur Windows Media (KB973540)-->"C:\WINDOWS\$NtUninstallKB973540_WM9L$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Lecteur Windows Media 11 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Lecteur Windows Media 11 (KB954154)-->"C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Lecteur Windows Media 6.4 (KB925398)-->"C:\WINDOWS\$NtUninstallKB925398_WMP64$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Lecteur Windows Media 9 (KB917734)-->"C:\WINDOWS\$NtUninstallKB917734_WMP9$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Lecteur Windows Media 9 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP9$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows Internet Explorer 7 (KB937143)-->"C:\WINDOWS\ie7updates\KB937143-IE7\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows Internet Explorer 7 (KB938127)-->"C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows Internet Explorer 7 (KB939653)-->"C:\WINDOWS\ie7updates\KB939653-IE7\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows Internet Explorer 7 (KB942615)-->"C:\WINDOWS\ie7updates\KB942615-IE7\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows Internet Explorer 7 (KB944533)-->"C:\WINDOWS\ie7updates\KB944533-IE7\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows Internet Explorer 7 (KB950759)-->"C:\WINDOWS\ie7updates\KB950759-IE7\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows Internet Explorer 7 (KB953838)-->"C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows Internet Explorer 7 (KB956390)-->"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows Internet Explorer 7 (KB958215)-->"C:\WINDOWS\ie7updates\KB958215-IE7\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows Internet Explorer 7 (KB960714)-->"C:\WINDOWS\ie7updates\KB960714-IE7\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows Internet Explorer 7 (KB961260)-->"C:\WINDOWS\ie7updates\KB961260-IE7\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows Internet Explorer 7 (KB963027)-->"C:\WINDOWS\ie7updates\KB963027-IE7\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows Internet Explorer 7 (KB969897)-->"C:\WINDOWS\ie7updates\KB969897-IE7\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows Internet Explorer 7 (KB972260)-->"C:\WINDOWS\ie7updates\KB972260-IE7\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows Internet Explorer 7 (KB974455)-->"C:\WINDOWS\ie7updates\KB974455-IE7\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows Internet Explorer 7 (KB976325)-->"C:\WINDOWS\ie7updates\KB976325-IE7\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB893756)-->"C:\WINDOWS\$NtUninstallKB893756$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB896358)-->"C:\WINDOWS\$NtUninstallKB896358$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB896423)-->"C:\WINDOWS\$NtUninstallKB896423$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB896428)-->"C:\WINDOWS\$NtUninstallKB896428$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB899587)-->"C:\WINDOWS\$NtUninstallKB899587$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB899591)-->"C:\WINDOWS\$NtUninstallKB899591$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB900725)-->"C:\WINDOWS\$NtUninstallKB900725$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB901017)-->"C:\WINDOWS\$NtUninstallKB901017$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB901214)-->"C:\WINDOWS\$NtUninstallKB901214$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB902400)-->"C:\WINDOWS\$NtUninstallKB902400$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB904706)-->"C:\WINDOWS\$NtUninstallKB904706$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB905414)-->"C:\WINDOWS\$NtUninstallKB905414$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB905749)-->"C:\WINDOWS\$NtUninstallKB905749$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB908519)-->"C:\WINDOWS\$NtUninstallKB908519$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB911562)-->"C:\WINDOWS\$NtUninstallKB911562$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB911927)-->"C:\WINDOWS\$NtUninstallKB911927$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB913580)-->"C:\WINDOWS\$NtUninstallKB913580$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB914388)-->"C:\WINDOWS\$NtUninstallKB914388$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB914389)-->"C:\WINDOWS\$NtUninstallKB914389$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB917344)-->"C:\WINDOWS\$NtUninstallKB917344$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB917422)-->"C:\WINDOWS\$NtUninstallKB917422$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB917953)-->"C:\WINDOWS\$NtUninstallKB917953$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB918118)-->"C:\WINDOWS\$NtUninstallKB918118$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB918439)-->"C:\WINDOWS\$NtUninstallKB918439$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB919007)-->"C:\WINDOWS\$NtUninstallKB919007$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB920213)-->"C:\WINDOWS\$NtUninstallKB920213$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB920670)-->"C:\WINDOWS\$NtUninstallKB920670$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB920683)-->"C:\WINDOWS\$NtUninstallKB920683$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB920685)-->"C:\WINDOWS\$NtUninstallKB920685$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB921503)-->"C:\WINDOWS\$NtUninstallKB921503$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB922819)-->"C:\WINDOWS\$NtUninstallKB922819$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB923191)-->"C:\WINDOWS\$NtUninstallKB923191$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB923414)-->"C:\WINDOWS\$NtUninstallKB923414$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB923561)-->"C:\WINDOWS\$NtUninstallKB923561$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB923689)-->"C:\WINDOWS\$NtUninstallKB923689$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB923694)-->"C:\WINDOWS\$NtUninstallKB923694$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB923980)-->"C:\WINDOWS\$NtUninstallKB923980$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB924191)-->"C:\WINDOWS\$NtUninstallKB924191$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB924270)-->"C:\WINDOWS\$NtUninstallKB924270$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB924496)-->"C:\WINDOWS\$NtUninstallKB924496$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB924667)-->"C:\WINDOWS\$NtUninstallKB924667$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB925902)-->"C:\WINDOWS\$NtUninstallKB925902$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB926255)-->"C:\WINDOWS\$NtUninstallKB926255$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB926436)-->"C:\WINDOWS\$NtUninstallKB926436$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB927779)-->"C:\WINDOWS\$NtUninstallKB927779$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB927802)-->"C:\WINDOWS\$NtUninstallKB927802$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB928090)-->"C:\WINDOWS\$NtUninstallKB928090$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB928255)-->"C:\WINDOWS\$NtUninstallKB928255$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB928843)-->"C:\WINDOWS\$NtUninstallKB928843$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB929123)-->"C:\WINDOWS\$NtUninstallKB929123$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB929969)-->"C:\WINDOWS\$NtUninstallKB929969$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB930178)-->"C:\WINDOWS\$NtUninstallKB930178$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB931261)-->"C:\WINDOWS\$NtUninstallKB931261$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB931768)-->"C:\WINDOWS\$NtUninstallKB931768$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB931784)-->"C:\WINDOWS\$NtUninstallKB931784$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB932168)-->"C:\WINDOWS\$NtUninstallKB932168$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB933566)-->"C:\WINDOWS\$NtUninstallKB933566$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB933729)-->"C:\WINDOWS\$NtUninstallKB933729$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB935839)-->"C:\WINDOWS\$NtUninstallKB935839$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB935840)-->"C:\WINDOWS\$NtUninstallKB935840$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB936021)-->"C:\WINDOWS\$NtUninstallKB936021$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB937143)-->"C:\WINDOWS\$NtUninstallKB937143$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB938127)-->"C:\WINDOWS\$NtUninstallKB938127$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB938829)-->"C:\WINDOWS\$NtUninstallKB938829$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB941202)-->"C:\WINDOWS\$NtUninstallKB941202$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB941568)-->"C:\WINDOWS\$NtUninstallKB941568$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB941644)-->"C:\WINDOWS\$NtUninstallKB941644$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB941693)-->"C:\WINDOWS\$NtUninstallKB941693$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB943055)-->"C:\WINDOWS\$NtUninstallKB943055$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB943460)-->"C:\WINDOWS\$NtUninstallKB943460$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB943485)-->"C:\WINDOWS\$NtUninstallKB943485$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB944653)-->"C:\WINDOWS\$NtUninstallKB944653$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB945553)-->"C:\WINDOWS\$NtUninstallKB945553$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB946026)-->"C:\WINDOWS\$NtUninstallKB946026$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB948590)-->"C:\WINDOWS\$NtUninstallKB948590$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB948881)-->"C:\WINDOWS\$NtUninstallKB948881$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB950749)-->"C:\WINDOWS\$NtUninstallKB950749$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB950760)-->"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB951376)-->"C:\WINDOWS\$NtUninstallKB951376$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB952004)-->"C:\WINDOWS\$NtUninstallKB952004$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB953839)-->"C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB954211)-->"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB954600)-->"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB956391)-->"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB956572)-->"C:\WINDOWS\$NtUninstallKB956572$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB956841)-->"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB956844)-->"C:\WINDOWS\$NtUninstallKB956844$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB957095)-->"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB958470)-->"C:\WINDOWS\$NtUninstallKB958470$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB958687)-->"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB958690)-->"C:\WINDOWS\$NtUninstallKB958690$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB958869)-->"C:\WINDOWS\$NtUninstallKB958869$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB959426)-->"C:\WINDOWS\$NtUninstallKB959426$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB960225)-->"C:\WINDOWS\$NtUninstallKB960225$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB960715)-->"C:\WINDOWS\$NtUninstallKB960715$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB960803)-->"C:\WINDOWS\$NtUninstallKB960803$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB960859)-->"C:\WINDOWS\$NtUninstallKB960859$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB961371)-->"C:\WINDOWS\$NtUninstallKB961371$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB961373)-->"C:\WINDOWS\$NtUninstallKB961373$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB961501)-->"C:\WINDOWS\$NtUninstallKB961501$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB968537)-->"C:\WINDOWS\$NtUninstallKB968537$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB969059)-->"C:\WINDOWS\$NtUninstallKB969059$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB969898)-->"C:\WINDOWS\$NtUninstallKB969898$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB969947)-->"C:\WINDOWS\$NtUninstallKB969947$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB970238)-->"C:\WINDOWS\$NtUninstallKB970238$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB970430)-->"C:\WINDOWS\$NtUninstallKB970430$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB971486)-->"C:\WINDOWS\$NtUninstallKB971486$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB971557)-->"C:\WINDOWS\$NtUninstallKB971557$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB971633)-->"C:\WINDOWS\$NtUninstallKB971633$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB971657)-->"C:\WINDOWS\$NtUninstallKB971657$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB971961)-->"C:\WINDOWS\$NtUninstallKB971961$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB973346)-->"C:\WINDOWS\$NtUninstallKB973346$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB973354)-->"C:\WINDOWS\$NtUninstallKB973354$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB973507)-->"C:\WINDOWS\$NtUninstallKB973507$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB973525)-->"C:\WINDOWS\$NtUninstallKB973525$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB973869)-->"C:\WINDOWS\$NtUninstallKB973869$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB973904)-->"C:\WINDOWS\$NtUninstallKB973904$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB974112)-->"C:\WINDOWS\$NtUninstallKB974112$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB974318)-->"C:\WINDOWS\$NtUninstallKB974318$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB974392)-->"C:\WINDOWS\$NtUninstallKB974392$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB974571)-->"C:\WINDOWS\$NtUninstallKB974571$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB975025)-->"C:\WINDOWS\$NtUninstallKB975025$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB975467)-->"C:\WINDOWS\$NtUninstallKB975467$\spuninst\spuninst.exe"
          Mise à jour pour Windows Internet Explorer 7 (KB976749)-->"C:\WINDOWS\ie7updates\KB976749-IE7\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB894391)-->"C:\WINDOWS\$NtUninstallKB894391$\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB898461)-->"C:\WINDOWS\$NtUninstallKB898461$\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB900485)-->"C:\WINDOWS\$NtUninstallKB900485$\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB904942)-->"C:\WINDOWS\$NtUninstallKB904942$\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB908531)-->"C:\WINDOWS\$NtUninstallKB908531$\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB910437)-->"C:\WINDOWS\$NtUninstallKB910437$\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB911280)-->"C:\WINDOWS\$NtUninstallKB911280$\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB916595)-->"C:\WINDOWS\$NtUninstallKB916595$\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB920872)-->"C:\WINDOWS\$NtUninstallKB920872$\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB922582)-->"C:\WINDOWS\$NtUninstallKB922582$\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB925720)-->"C:\WINDOWS\$NtUninstallKB925720$\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB927891)-->"C:\WINDOWS\$NtUninstallKB927891$\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB929338)-->"C:\WINDOWS\$NtUninstallKB929338$\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB930916)-->"C:\WINDOWS\$NtUninstallKB930916$\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB931836)-->"C:\WINDOWS\$NtUninstallKB931836$\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB932823-v3)-->"C:\WINDOWS\$NtUninstallKB932823-v3$\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB933360)-->"C:\WINDOWS\$NtUninstallKB933360$\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB936357)-->"C:\WINDOWS\$NtUninstallKB936357$\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB938828)-->"C:\WINDOWS\$NtUninstallKB938828$\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB942763)-->"C:\WINDOWS\$NtUninstallKB942763$\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB951072-v2)-->"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB955839)-->"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB961503)-->"C:\WINDOWS\$NtUninstallKB961503$\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB967715)-->"C:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB968389)-->"C:\WINDOWS\$NtUninstallKB968389$\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB971737)-->"C:\WINDOWS\$NtUninstallKB971737$\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB973687)-->"C:\WINDOWS\$NtUninstallKB973687$\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB973815)-->"C:\WINDOWS\$NtUninstallKB973815$\spuninst\spuninst.exe"
          Mozilla Firefox (3.5.6)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
          MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
          MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
          MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
          MSXML 4.0 SP2 (KB973688)-->MsiExec.exe /I{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
          MSXML 6 Service Pack 2 (KB973686)-->MsiExec.exe /I{56EA8BC0-3751-4B93-BC9D-6651CC36E5AA}
          Navilog1 3.6.5-->"C:\Program Files\Navilog1\unins000.exe"
          Nero 7 Essentials-->MsiExec.exe /X{282E3F81-CC37-44AF-8156-C35104D21036}
          neroxml-->MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B}
          Nokia Connectivity Cable Driver-->MsiExec.exe /X{11964613-805F-432D-A12B-169554B793E7}
          Nokia PC Suite-->C:\Documents and Settings\All Users\Application Data\Installations\{A982E6CC-9F0D-4948-9B18-BDFD55DE4A72}\Nokia_PC_Suite_6_84_10_3_EA.exe
          Nokia PC Suite-->MsiExec.exe /I{A982E6CC-9F0D-4948-9B18-BDFD55DE4A72}
          NVIDIA Drivers-->C:\WINDOWS\system32\nvudisp.exe UninstallGUI
          OpenOffice.org Installer 1.0-->MsiExec.exe /X{3A2AF807-9F9F-43C9-A24A-17B617238B74}
          Outil de mise à jour Google-->"C:\Program Files\Google\Google Updater\GoogleUpdater.exe" -uninstall
          Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
          Package de pilotes Windows - Nokia (WUDFRd) WPD (06/01/2007 6.84.33.0)-->C:\PROGRA~1\DIFX\270581355A767BF1\dpinst.exe /u C:\WINDOWS\system32\DRVSTORE\pccswpddri_044C8712DB44F83D9DE6C376991EE9254E0A69E4\pccswpddriver.inf
          Package de pilotes Windows - Nokia Modem (02/15/2007 3.1)-->C:\PROGRA~1\DIFX\270581355A767BF1\dpinst.exe /u C:\WINDOWS\system32\DRVSTORE\pccs_bluet_F12A08B6F776984A95553486F64C541356F86E38\pccs_bluetooth.inf
          Package de pilotes Windows - Nokia Modem (05/24/2007 6.84.0.1)-->C:\PROGRA~1\DIFX\270581355A767BF1\dpinst.exe /u C:\WINDOWS\system32\DRVSTORE\nokbtmdm_5E1541AFF1E1EA3554CE566743CCAD323ED1C108\nokbtmdm.inf
          PC Connectivity Solution-->MsiExec.exe /I{99A40651-0BC2-4095-8F9A-A40FAB224FEF}
          Power IEv3-->MsiExec.exe /I{AF7C627C-F354-4FF1-8450-398C806B436E}
          PowerCinema-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2637C347-9DAD-11D6-9EA2-00055D0CA761}\Setup.exe" -uninstall
          PowerDVD-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}\Setup.exe" -uninstall
          QuickTime-->MsiExec.exe /I{9763E36A-08E9-4228-BBCE-12989A4EB1A8}
          Realtek High Definition Audio Driver-->RtlUpd.exe -r
          Security Update for CAPICOM (KB931906)-->MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
          Security Update for CAPICOM (KB931906)-->MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
          Segoe UI-->MsiExec.exe /I{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}
          SFR - Kit de connexion-->C:\Program Files\SFR\Kit\uninstall.exe
          Skype web features-->MsiExec.exe /I{541DEAC0-5F3D-45E6-B7CB-94ECF3B96748}
          Skype™ 4.1-->MsiExec.exe /X{D103C4BA-F905-437A-8049-DB24763BBE36}
          Sophos Anti-Rootkit 1.3.1-->C:\Program Files\Sophos\Sophos Anti-Rootkit\helper.exe remove
          Spybot - Search & Destroy-->"C:\Program Files\Spybot - Search & Destroy\unins000.exe"
          Update for Microsoft .NET Framework 3.5 SP1 (KB963707)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {B2AE9C82-DC7B-3641-BFC8-87275C4F3607} /qb+ REBOOTPROMPT=""
          VLC media player 1.0.3-->C:\Program Files\VideoLAN\VLC\uninstall.exe
          Windows Imaging Component-->"C:\WINDOWS\$NtUninstallWIC$\spuninst\spuninst.exe"
          Windows Installer 3.1 (KB893803)-->"C:\WINDOWS\$MSI31Uninstall_KB893803v2$\spuninst\spuninst.exe"
          Windows Internet Explorer 7-->"C:\WINDOWS\ie7\spuninst\spuninst.exe"
          Windows Live Call-->MsiExec.exe /I{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}
          Windows Live Communications Platform-->MsiExec.exe /I{ED00D08A-3C5F-488D-93A0-A04F21F23956}
          Windows Live Contrôle parental-->MsiExec.exe /X{D5D81435-B8DE-4CAF-867F-7998F2B92CFC}
          Windows Live FolderShare-->MsiExec.exe /X{2075CB0A-D26F-4DAA-B424-5079296B43BA}
          Windows Live Mail-->MsiExec.exe /I{5DD76286-9BE7-4894-A990-E905E91AC818}
          Windows Live Messenger-->MsiExec.exe /X{770F1BEC-2871-4E70-B837-FB8525FFA3B1}
          Windows Live Toolbar-->MsiExec.exe /X{F7D27C70-90F5-49B9-B188-0A133C0CE353}
          Windows Live Writer-->MsiExec.exe /X{4634B21A-CC07-4396-890C-2B8168661FEA}
          Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
          Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
          Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"

          ======Hosts File======

          127.0.0.1 www.007guard.com
          127.0.0.1 007guard.com
          127.0.0.1 008i.com
          127.0.0.1 www.008k.com
          127.0.0.1 008k.com
          127.0.0.1 www.00hq.com
          127.0.0.1 00hq.com
          127.0.0.1 010402.com
          127.0.0.1 www.032439.com
          127.0.0.1 032439.com

          ======Security center information======

          AV: avast! antivirus 4.8.1368 [VPS 100105-0]

          ======System event log======

          Computer Name: LUCALULU
          Event Code: 7035
          Message: Un contrôle Démarrer a correctement été envoyé au service NLA (Network Location Awareness).

          Record Number: 76081
          Source Name: Service Control Manager
          Time Written: 20091221181037.000000+060
          Event Type: Informations
          User: AUTORITE NT\SYSTEM

          Computer Name: LUCALULU
          Event Code: 7035
          Message: Un contrôle Démarrer a correctement été envoyé au service Service de découvertes SSDP.

          Record Number: 76080
          Source Name: Service Control Manager
          Time Written: 20091221181037.000000+060
          Event Type: Informations
          User: AUTORITE NT\SYSTEM

          Computer Name: LUCALULU
          Event Code: 7035
          Message: Un contrôle Démarrer a correctement été envoyé au service Pml Driver HPZ12.

          Record Number: 76079
          Source Name: Service Control Manager
          Time Written: 20091221181037.000000+060
          Event Type: Informations
          User: LUCALULU\Thierry

          Computer Name: LUCALULU
          Event Code: 7036
          Message: Le service Pml Driver HPZ12 est entré dans l'état : en cours d'exécution.

          Record Number: 76078
          Source Name: Service Control Manager
          Time Written: 20091221181037.000000+060
          Event Type: Informations
          User:

          Computer Name: LUCALULU
          Event Code: 7036
          Message: Le service Service COM de gravage de CD IMAPI est entré dans l'état : en cours d'exécution.

          Record Number: 76077
          Source Name: Service Control Manager
          Time Written: 20091221181037.000000+060
          Event Type: Informations
          User:

          =====Application event log=====

          Computer Name: LUCALULU
          Event Code: 103
          Message: MsnMsgr (1948) \\.\C:\Documents and Settings\Thierry\Local Settings\Application Data\Microsoft\Messenger\sosolabelette69@hotmail.com\SharingMetadata\Working\database_30EC_7C5_EC07_83F6\dfsr.db: Le moteur de base de données a arrêté une instance (0).

          Record Number: 22093
          Source Name: ESENT
          Time Written: 20090929203712.000000+120
          Event Type: Informations
          User:

          Computer Name: LUCALULU
          Event Code: 0
          Message:
          Record Number: 22092
          Source Name: gusvc
          Time Written: 20090929202912.000000+120
          Event Type: Informations
          User:

          Computer Name: LUCALULU
          Event Code: 0
          Message:
          Record Number: 22091
          Source Name: gusvc
          Time Written: 20090929202800.000000+120
          Event Type: Informations
          User:

          Computer Name: LUCALULU
          Event Code: 0
          Message:
          Record Number: 22090
          Source Name: gusvc
          Time Written: 20090929200712.000000+120
          Event Type: Informations
          User:

          Computer Name: LUCALULU
          Event Code: 0
          Message:
          Record Number: 22089
          Source Name: gusvc
          Time Written: 20090929200611.000000+120
          Event Type: Informations
          User:

          ======Environment variables======

          "ComSpec"=%SystemRoot%\system32\cmd.exe
          "Path"=C:\Program Files\PC Connectivity Solution\;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\QuickTime\QTSystem\
          "windir"=%SystemRoot%
          "FP_NO_HOST_CHECK"=NO
          "OS"=Windows_NT
          "PROCESSOR_ARCHITECTURE"=x86
          "PROCESSOR_LEVEL"=15
          "PROCESSOR_IDENTIFIER"=x86 Family 15 Model 4 Stepping 4, GenuineIntel
          "PROCESSOR_REVISION"=0404
          "NUMBER_OF_PROCESSORS"=2
          "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
          "TEMP"=%SystemRoot%\TEMP
          "TMP"=%SystemRoot%\TEMP
          "CLASSPATH"=.;C:\Program Files\Java\jre1.6.0_01\lib\ext\QTJava.zip
          "QTJAVA"=C:\Program Files\Java\jre1.6.0_01\lib\ext\QTJava.zip

          -----------------EOF-----------------
          0
      2. Contributeur sécurité
        le premier rapport n'est pas complet

        il se trouve ici C:\rsit\log.txt
        0
        1. Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 11:55:45, on 06/01/2010
          Platform: Windows XP SP2 (WinNT 5.01.2600)
          MSIE: Internet Explorer v7.00 (7.00.6000.16945)
          Boot mode: Normal

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\Explorer.EXE
          C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
          C:\Program Files\Alwil Software\Avast4\ashServ.exe
          C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
          C:\WINDOWS\RTHDCPL.EXE
          C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
          C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
          C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
          C:\Program Files\CyberLink\PowerCinema\PCMService.exe
          C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
          C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
          C:\Program Files\Hercules\Hercules Blog Webcam\CamService.exe
          C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
          C:\WINDOWS\system32\ctfmon.exe
          C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
          C:\Program Files\Messenger\msmsgs.exe
          C:\WINDOWS\system32\spoolsv.exe
          C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
          C:\Program Files\Skype\Phone\Skype.exe
          C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
          C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
          C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
          C:\WINDOWS\system32\VirtualExpander\VirtualExpander.exe
          C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
          C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe
          C:\Program Files\CyberLink\PowerCinema\Kernel\CLML_NTService\CLMLServer.exe
          C:\Program Files\CyberLink\PowerCinema\Kernel\CLML_NTService\CLMLService.exe
          C:\WINDOWS\system32\nvsvc32.exe
          C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
          C:\WINDOWS\system32\svchost.exe
          C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe
          C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
          C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
          C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
          C:\WINDOWS\System32\svchost.exe
          C:\Program Files\Skype\Plugin Manager\skypePM.exe
          C:\WINDOWS\system32\wbem\wmiapsrv.exe
          C:\WINDOWS\system32\wuauclt.exe
          C:\Program Files\Fichiers communs\Adobe\Updater6\Adobe_Updater.exe
          C:\Program Files\Mozilla Firefox\firefox.exe
          C:\Program Files\Trend Micro\hijackthis.exe

          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.tattoodle.com?tid={FCEE73E3-0B60-4a05-AA7F-19575C620FF7}
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
          O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
          O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
          O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
          O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
          O2 - BHO: BrowserHelper Class - {8A9D74F9-560B-4FE7-ABEB-3B2E638E5CD6} - C:\Program Files\SGPSA\SearchAssistant.dll (file missing)
          O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
          O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll
          O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
          O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
          O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
          O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
          O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
          O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
          O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
          O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
          O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
          O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
          O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
          O4 - HKLM\..\Run: [PCMService] "C:\Program Files\CyberLink\PowerCinema\PCMService.exe"
          O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
          O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
          O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
          O4 - HKLM\..\Run: [HerculesCamService] C:\Program Files\Hercules\Hercules Blog Webcam\CamService.exe
          O4 - HKLM\..\Run: [Real Popup-Killer] c:\TuePub\TuePub.exe
          O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
          O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
          O4 - HKLM\..\Run: [sysgif32] C:\WINDOWS\TEMP\~TM145.tmp
          O4 - HKLM\..\Run: [67220724] C:\DOCUME~1\ALLUSE~1\APPLIC~1\67220724\67220724.exe
          O4 - HKLM\..\Run: [CTFMON] C:\WINDOWS\Temp\_ex-08.exe
          O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
          O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
          O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|DEFAULT=cnx|PARAM=
          O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
          O4 - HKCU\..\Run: [Rainlendar2] C:\Program Files\Rainlendar2\Rainlendar2.exe
          O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
          O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
          O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
          O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Thierry\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
          O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\\Phone\Skype.exe" /nosplash /minimized
          O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
          O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
          O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
          O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
          O4 - Startup: MaxTV.lnk = C:\Program Files\DMV\MaxTV4\maxtv.exe
          O4 - Startup: VirtualExpander.lnk = C:\WINDOWS\system32\VirtualExpander\VirtualExpander.exe
          O4 - Global Startup: Démarrage rapide du logiciel HP Image Zone.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
          O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
          O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
          O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
          O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
          O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
          O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
          O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
          O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
          O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
          O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
          O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
          O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O16 - DPF: {1FF43AD5-2262-4C2F-81D4-26D710C3F305} (VB2S Mannequin Virtuel Control) - http://mannequin.redoute.fr/activex/Mannequin.cab
          O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab
          O16 - DPF: {54823A9D-6BAE-11D5-B519-0050BA2413EB} (ChkDVDCtl Class) - http://www.cyberlink.com/winxp/CheckDVD.cab
          O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.zebulon.fr/scan8/oscan8.cab
          O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
          O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
          O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
          O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
          O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
          O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
          O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
          O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
          O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
          O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe
          O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe
          O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\PowerCinema\Kernel\CLML_NTService\CLMLServer.exe
          O23 - Service: Google Desktop Manager 5.9.909.30391 (GoogleDesktopManager-093009-130223) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
          O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
          O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
          O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
          O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
          0
        2. Logfile of random's system information tool 1.06 (written by random/random)
          Run by Thierry at 2010-01-06 08:09:11
          Microsoft Windows XP Édition familiale Service Pack 2
          System drive C: has 162 GB (68%) free of 238 GB
          Total RAM: 1023 MB (21% free)

          ======Scheduled tasks folder======

          C:\WINDOWS\tasks\Google Software Updater.job
          C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-606747145-1715567821-839522115-1005Core.job
          C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-606747145-1715567821-839522115-1005UA.job
          C:\WINDOWS\tasks\WebReg 20070611225932.job

          ======Registry dump======

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
          Adobe PDF Link Helper - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
          Spybot-S&D IE Protection - C:\PROGRA~1\SPYBOT~1\SDHelper.dll [2009-01-26 1879896]

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
          Search Helper - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll [2009-05-19 137600]

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
          SSVHelper Class - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll [2008-06-10 509328]

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8A9D74F9-560B-4FE7-ABEB-3B2E638E5CD6}]
          BrowserHelper Class - C:\Program Files\SGPSA\SearchAssistant.dll []

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
          Programme d'aide de l'Assistant de connexion Windows Live - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-02-17 408440]

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
          Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2009-12-06 263280]

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
          Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll [2009-11-20 764912]

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10}]
          Windows Live Toolbar Helper - C:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-02-06 1068904]

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
          {21FA44EF-376D-4D53-9B0F-8A89D3229068} - &Windows Live Toolbar - C:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-02-06 1068904]
          {2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2009-12-06 263280]

          [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
          "High Definition Audio Property Page Shortcut"=C:\WINDOWS\system32\HDAShCut.exe [2004-10-27 61952]
          "SunJavaUpdateSched"=C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe [2008-06-10 144784]
          "RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2005-10-14 14864384]
          "Alcmtr"=ALCMTR.EXE []
          "NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2005-08-02 7110656]
          "nwiz"=nwiz.exe /install []
          "Google Desktop Search"=C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [2009-10-24 30192]
          "HP Software Update"=C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2004-02-12 49152]
          "HP Component Manager"=C:\Program Files\HP\hpcoretech\hpcmpmgr.exe [2004-05-12 241664]
          "PCMService"=C:\Program Files\CyberLink\PowerCinema\PCMService.exe [2005-09-30 139264]
          "RemoteControl"=C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe [2005-04-15 45056]
          "QuickTime Task"=C:\Program Files\QuickTime\qttask.exe [2007-11-14 286720]
          "NeroFilterCheck"=C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe [2007-03-15 153136]
          "PCSuiteTrayApplication"=C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe [2007-06-18 271360]
          "HerculesCamService"=C:\Program Files\Hercules\Hercules Blog Webcam\CamService.exe [2006-10-13 122880]
          "Real Popup-Killer"=c:\TuePub\TuePub.exe []
          "KernelFaultCheck"=C:\WINDOWS\system32\dumprep 0 -k []
          "Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-02-27 35696]
          "sysgif32"=C:\WINDOWS\TEMP\~TM145.tmp [2009-12-27 15360]
          "67220724"=C:\DOCUME~1\ALLUSE~1\APPLIC~1\67220724\67220724.exe []
          "CTFMON"=C:\WINDOWS\Temp\_ex-08.exe []
          "avast!"=C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe [2009-11-25 81000]

          [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
          "CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2004-08-05 15360]
          "WOOKIT"=C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|DEFAULT=cnx|PARAM= []
          "MsnMsgr"=C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe [2009-07-26 3883856]
          "Rainlendar2"=C:\Program Files\Rainlendar2\Rainlendar2.exe []
          "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe [2007-03-22 149040]
          "MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2004-10-13 1694208]
          "swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2007-04-05 68856]
          "Google Update"=C:\Documents and Settings\Thierry\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-04 133104]
          "Skype"=C:\Program Files\Skype\\Phone\Skype.exe [2009-10-09 25623336]
          "SpybotSD TeaTimer"=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2009-03-05 2260480]

          C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage
          Démarrage rapide du logiciel HP Image Zone.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
          HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
          Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE

          C:\Documents and Settings\Thierry\Menu Démarrer\Programmes\Démarrage
          MaxTV.lnk - C:\Program Files\DMV\MaxTV4\maxtv.exe
          VirtualExpander.lnk - C:\WINDOWS\system32\VirtualExpander\VirtualExpander.exe

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
          "AppInit_DLLS"="C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL"

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
          C:\WINDOWS\system32\WgaLogon.dll [2007-03-15 236928]

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
          WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

          [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
          "dontdisplaylastusername"=0
          "legalnoticecaption"=
          "legalnoticetext"=
          "shutdownwithoutlogon"=1
          "undockwithoutlogon"=1

          [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
          "NoDriveTypeAutoRun"=95000000

          [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
          "HonorAutoRunSetting"=

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
          "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
          "C:\Program Files\CyberLink\PowerCinema\PowerCinema.exe"="C:\Program Files\CyberLink\PowerCinema\PowerCinema.exe:*:Enabled:CyberLink PowerCinema"
          "C:\Program Files\CyberLink\PowerCinema\PCMService.exe"="C:\Program Files\CyberLink\PowerCinema\PCMService.exe:*:Enabled:CyberLink PowerCinema Resident Program"
          "%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
          "C:\Program Files\Mozilla Firefox\firefox.exe"="C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox"
          "C:\WINDOWS\system32\ZoneLabs\avsys\ScanningProcess.exe"="C:\WINDOWS\system32\ZoneLabs\avsys\ScanningProcess.exe:*:Enabled:Kaspersky AV Scanner"
          "C:\Program Files\Messenger\msmsgs.exe"="C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger"
          "C:\Program Files\Hercules\Hercules Blog Webcam\Station2.exe"="C:\Program Files\Hercules\Hercules Blog Webcam\Station2.exe:*:Enabled:Hercules Webcam Station Evolution"
          "C:\Program Files\Hercules\Hercules Blog Webcam\ControlUI.exe"="C:\Program Files\Hercules\Hercules Blog Webcam\ControlUI.exe:*:Enabled:Hercules Zoom Controller Main Application"
          "C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
          "C:\Program Files\Windows Live\Messenger\wlcsdk.exe"="C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call"
          "C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
          "C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe"="C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live FolderShare"
          "C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
          "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
          "%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
          "C:\Program Files\Windows Live\Messenger\wlcsdk.exe"="C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call"
          "C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
          "C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe"="C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live FolderShare"

          [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b91d2600-16e5-11dd-aca0-003005b259b6}]
          shell\AutoRun\command - J:\fsaht.cmd
          shell\open\command - J:\fsaht.cmd

          ======List of files/folders created in the last 1 months======

          2010-01-06 08:05:03 ----D---- C:\rsit
          2009-12-29 14:54:58 ----D---- C:\Program Files\Sophos
          2009-12-28 23:12:25 ----D---- C:\Program Files\Spybot - Search & Destroy
          2009-12-28 23:12:25 ----D---- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
          2009-12-28 11:16:20 ----A---- C:\WINDOWS\system32\aswBoot.exe
          2009-12-28 11:15:42 ----A---- C:\setupfre.exe
          2009-12-28 11:09:48 ----D---- C:\fichiers installations
          2009-12-28 10:44:15 ----D---- C:\THIERRY
          2009-12-28 10:23:30 ----D---- C:\Program Files\Fichiers communs\Wise Installation Wizard
          2009-12-27 14:31:53 ----D---- C:\Program Files\WinPcap
          2009-12-08 22:34:40 ----HDC---- C:\WINDOWS\$NtUninstallKB970430$
          2009-12-08 22:34:30 ----HDC---- C:\WINDOWS\$NtUninstallKB974318$
          2009-12-08 22:34:19 ----HDC---- C:\WINDOWS\$NtUninstallKB973904$
          2009-12-08 22:33:39 ----HDC---- C:\WINDOWS\$NtUninstallKB974392$
          2009-12-08 22:33:28 ----HDC---- C:\WINDOWS\$NtUninstallKB971737$

          ======List of files/folders modified in the last 1 months======

          2010-01-06 08:09:15 ----D---- C:\Program Files\Trend Micro
          2010-01-06 08:08:40 ----D---- C:\WINDOWS\Prefetch
          2010-01-06 08:06:28 ----D---- C:\Documents and Settings\Thierry\Application Data\skypePM
          2010-01-06 08:05:55 ----D---- C:\Documents and Settings\Thierry\Application Data\Skype
          2010-01-06 07:59:04 ----D---- C:\Program Files\Mozilla Firefox
          2010-01-06 07:13:24 ----D---- C:\WINDOWS\Temp
          2010-01-06 07:13:23 ----D---- C:\WINDOWS\system32\CatRoot2
          2010-01-06 07:05:52 ----SD---- C:\WINDOWS\Tasks
          2010-01-06 07:05:34 ----D---- C:\WINDOWS\system32\Lang
          2010-01-06 07:05:29 ----D---- C:\WINDOWS
          2010-01-05 22:13:18 ----A---- C:\WINDOWS\SchedLgU.Txt
          2010-01-05 19:19:15 ----D---- C:\Documents and Settings\All Users\Application Data\Google Updater
          2010-01-04 21:25:20 ----A---- C:\WINDOWS\ntbtlog.txt
          2010-01-01 10:04:28 ----RD---- C:\Program Files
          2009-12-31 22:57:24 ----D---- C:\Documents and Settings\Thierry\Application Data\vlc
          2009-12-31 22:44:29 ----D---- C:\Documents and Settings\Thierry\Application Data\dvdcss
          2009-12-30 18:23:58 ----HDC---- C:\WINDOWS\ie7
          2009-12-30 18:23:57 ----HD---- C:\WINDOWS\inf
          2009-12-30 18:21:15 ----D---- C:\WINDOWS\system32
          2009-12-28 11:55:37 ----HD---- C:\Config.Msi
          2009-12-28 11:55:37 ----D---- C:\Documents and Settings\All Users\Application Data\Avira
          2009-12-28 11:16:45 ----D---- C:\WINDOWS\system32\drivers
          2009-12-28 11:03:04 ----D---- C:\soso
          2009-12-28 10:57:43 ----SHD---- C:\WINDOWS\Installer
          2009-12-28 10:57:36 ----D---- C:\WINDOWS\WinSxS
          2009-12-28 10:56:04 ----D---- C:\Program Files\BitDefender
          2009-12-28 10:54:48 ----A---- C:\WINDOWS\bdagent.INI
          2009-12-28 10:32:37 ----SHD---- C:\RECYCLER
          2009-12-28 10:26:09 ----D---- C:\Documents and Settings
          2009-12-27 14:31:21 ----RSHDC---- C:\WINDOWS\system32\dllcache
          2009-12-12 17:54:40 ----A---- C:\WINDOWS\NeroDigital.ini
          2009-12-11 21:46:58 ----D---- C:\WINDOWS\Help
          2009-12-09 22:07:20 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
          2009-12-08 22:34:44 ----A---- C:\WINDOWS\imsins.BAK
          2009-12-08 22:34:16 ----HD---- C:\WINDOWS\$hf_mig$
          2009-12-08 22:34:05 ----D---- C:\WINDOWS\system32\fr-fr
          2009-12-08 22:34:05 ----D---- C:\Program Files\Internet Explorer
          2009-12-08 22:33:55 ----D---- C:\WINDOWS\ie7updates

          ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

          R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2009-11-25 27408]
          R1 aswSP;avast! Self Protection; C:\WINDOWS\system32\drivers\aswSP.sys [2009-11-25 114768]
          R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2009-11-25 48560]
          R1 intelppm;Pilote de processeur Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2004-08-05 40320]
          R1 kbdhid;Pilote HID de clavier; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2004-08-05 14848]
          R1 SAVRKBootTasks;Boot Tasks Driver; \??\C:\WINDOWS\system32\SAVRKBootTasks.sys []
          R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2009-11-25 20560]
          R2 aswMon2;avast! Standard Shield Support; C:\WINDOWS\system32\drivers\aswMon2.sys [2009-11-25 94160]
          R2 fssfltr;FssFltr; C:\WINDOWS\system32\DRIVERS\fssfltr_tdi.sys [2009-08-05 54752]
          R2 npf;NetGroup Packet Filter Driver; C:\WINDOWS\system32\drivers\npf.sys [2007-11-15 34064]
          R2 nvcap;nVidia WDM Video Capture (universal); C:\WINDOWS\system32\DRIVERS\nvcap.sys [2005-04-14 141582]
          R2 NVXBAR;nVidia WDM A/V Crossbar; C:\WINDOWS\system32\DRIVERS\NVxbar.sys [2005-04-14 16496]
          R3 3xHybrid;3xHybrid service; C:\WINDOWS\system32\DRIVERS\3xHybrid.sys [2005-06-23 799744]
          R3 APL531;Hercules Blog Webcam; C:\WINDOWS\System32\Drivers\BLvid.sys [2006-09-29 274816]
          R3 Arp1394;Protocole client ARP 1394; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2004-08-05 60800]
          R3 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2009-11-25 23120]
          R3 camfilt;camfilt; C:\WINDOWS\System32\Drivers\camfilt.sys [2006-10-03 22656]
          R3 E100B;Intel(R) PRO Network Connection Driver; C:\WINDOWS\system32\DRIVERS\e100b325.sys [2005-06-13 162816]
          R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2004-10-27 138240]
          R3 hidusb;Pilote de classe HID Microsoft; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2004-08-05 9600]
          R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2005-10-18 4034048]
          R3 mouhid;Pilote HID de souris; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2004-08-05 12288]
          R3 NIC1394;Pilote réseau 1394; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2004-08-05 61824]
          R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2005-08-02 3198560]
          R3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\WINDOWS\System32\Drivers\RootMdm.sys [2004-08-05 5888]
          R3 SIS163u;SiS163 usb Wireless LAN Adapter Driver; C:\WINDOWS\system32\DRIVERS\sis163u.sys [2005-06-20 215040]
          R3 usbaudio;Pilote USB audio (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2004-08-03 59264]
          R3 usbccgp;Pilote parent générique USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-05 31616]
          R3 usbehci;Pilote miniport de contrôleur d'hôte amélioré Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2004-08-03 26624]
          R3 usbhub;Concentrateur USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2004-08-03 57600]
          R3 usbstor;Pilote de stockage de masse USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-05 26496]
          R3 usbuhci;Pilote miniport de contrôleur hôte universel USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2004-08-03 20480]
          S3 catchme;catchme; \??\C:\DOCUME~1\Thierry\LOCALS~1\Temp\catchme.sys []
          S3 CCDECODE;Décodeur sous-titre fermé; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2004-08-03 17024]
          S3 HdAudAddService;Microsoft UAA Function Driver for High Definition Audio Service; C:\WINDOWS\system32\drivers\HdAudio.sys [2004-10-27 145920]
          S3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\system32\DRIVERS\HPZid412.sys [2004-06-21 51088]
          S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2004-06-21 16496]
          S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2004-06-21 21744]
          S3 MEMSWEEP2;MEMSWEEP2; \??\C:\WINDOWS\system32\3A.tmp []
          S3 MPE;Filtre BDA MPE; C:\WINDOWS\system32\DRIVERS\MPE.sys [2004-08-03 15360]
          S3 MSTEE;Convertisseur en T/site-à-site de répartition Microsoft; C:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-03 5504]
          S3 NABTSFEC;Codec NABTS/FEC VBI; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-08-03 85376]
          S3 NdisIP;Connection TV/vidéo Microsoft; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2004-08-03 10880]
          S3 nmwcd;Nokia USB Phone Parent; C:\WINDOWS\system32\drivers\nmwcd.sys [2007-02-22 137216]
          S3 nmwcdc;Nokia USB Generic; C:\WINDOWS\system32\drivers\nmwcdc.sys [2007-02-22 8320]
          S3 nmwcdcj;Nokia USB Port; C:\WINDOWS\system32\drivers\nmwcdcj.sys [2007-02-22 12288]
          S3 nmwcdcm;Nokia USB Modem; C:\WINDOWS\system32\drivers\nmwcdcm.sys [2007-02-22 12288]
          S3 PCANDIS5;PCANDIS5 NDIS Protocol Driver; \??\C:\WINDOWS\system32\PCANDIS5.SYS []
          S3 PCASp50;PCASp50 NDIS Protocol Driver; C:\WINDOWS\System32\Drivers\PCASp50.sys [2005-11-19 20096]
          S3 Profos;Profos; \??\C:\Program Files\Fichiers communs\BitDefender\BitDefender Threat Scanner\profos.sys []
          S3 SLIP;Détrameur décalage BDA; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2004-08-03 11136]
          S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2004-08-03 15360]
          S3 Trufos;Trufos; \??\C:\Program Files\Fichiers communs\BitDefender\BitDefender Threat Scanner\trufos.sys []
          S3 USB_RNDIS;Inventel Gateway; C:\WINDOWS\system32\DRIVERS\usb8023.sys [2004-08-05 12672]
          S3 usbprint;Classe d'imprimantes USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-03 25856]
          S3 usbscan;Pilote de scanneur USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 15104]
          S3 WSTCODEC;Codec Teletext standard; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-08-03 19328]
          S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-15 82688]

          ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

          R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2007-10-31 110592]
          R2 aswUpdSv;avast! iAVS4 Control Service; C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe [2009-11-25 18752]
          R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast4\ashServ.exe [2009-11-25 138680]
          R2 CLCapSvc;CyberLink Background Capture Service (CBCS); C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe [2005-09-30 249954]
          R2 CLSched;CyberLink Task Scheduler (CTS); C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe [2005-09-30 114784]
          R2 CyberLink Media Library Service;CyberLink Media Library Service; C:\Program Files\CyberLink\PowerCinema\Kernel\CLML_NTService\CLMLServer.exe [2005-09-30 61440]
          R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2005-08-02 127043]
          R2 SeaPort;SeaPort; C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-05-19 240512]
          R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2004-08-05 14336]
          R3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe [2009-11-25 254040]
          R3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast4\ashWebSv.exe [2009-11-25 352920]
          R3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2007-06-15 300544]
          S2 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-05-07 182768]
          S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
          S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
          S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
          S3 fsssvc;Service Windows Live Contrôle parental; C:\Program Files\Windows Live\Family Safety\fsssvc.exe [2009-08-05 704864]
          S3 GoogleDesktopManager-093009-130223;Google Desktop Manager 5.9.909.30391; C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [2009-10-24 30192]
          S3 idsvc;Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
          S3 NBService;NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2007-03-22 779824]
          S3 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\system32\HPZipm12.exe [2004-03-18 65536]
          S3 WMPNetworkSvc;Service Partage réseau du Lecteur Windows Media; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-11-03 918016]
          S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
          S4 NMIndexingService;NMIndexingService; C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe [2007-03-22 271920]

          -----------------EOF-----------------
          0
        3. Voilqm

          Normalement, il y a tout
          0
        4. Bonjour,

          La neige, la neige et encore la neige........J'ai pas ue le temps de me replonger dans mes soucis de virus.....
          Je viens de tout refaire et voila le rapport. J'ai tout essayé mais ces deux virus ne peuvent pas se supprimer, si tu as une derniere idée........merci d'avance.

          Malwarebytes' Anti-Malware 1.43
          Version de la base de données: 3502
          Windows 5.1.2600 Service Pack 2
          Internet Explorer 7.0.5730.11

          10/01/2010 09:21:44
          mbam-log-2010-01-10 (09-21-44).txt

          Type de recherche: Examen complet (C:\|D:\|E:\|F:\|G:\|H:\|I:\|)
          Eléments examinés: 201279
          Temps écoulé: 26 hour(s), 9 minute(s), 51 second(s)

          Processus mémoire infecté(s): 0
          Module(s) mémoire infecté(s): 0
          Clé(s) du Registre infectée(s): 0
          Valeur(s) du Registre infectée(s): 0
          Elément(s) de données du Registre infecté(s): 0
          Dossier(s) infecté(s): 0
          Fichier(s) infecté(s): 2

          Processus mémoire infecté(s):
          (Aucun élément nuisible détecté)

          Module(s) mémoire infecté(s):
          (Aucun élément nuisible détecté)

          Clé(s) du Registre infectée(s):
          (Aucun élément nuisible détecté)

          Valeur(s) du Registre infectée(s):
          (Aucun élément nuisible détecté)

          Elément(s) de données du Registre infecté(s):
          (Aucun élément nuisible détecté)

          Dossier(s) infecté(s):
          (Aucun élément nuisible détecté)

          Fichier(s) infecté(s):
          C:\UsbFix\Quarantine\J\fsaht.cmd.UsbFix (Spyware.OnlineGames) -> Quarantined and deleted successfully.
          C:\WINDOWS\system32\drivers\vymmswss.sys (Rootkit.Agent) -> Delete on reboot.
          0
      3. Contributeur sécurité
        ok

        plusieurs infections

        Rends toi sur ce site :

        https://www.virustotal.com/gui/

        Clique sur parcourir et cherche ce fichier :

        C:\DOCUME~1\ALLUSE~1\APPLIC~1\67220724\67220724.exe

        Clique sur Send File.

        Un rapport va s'élaborer ligne à ligne.

        Attends la fin. Il doit comprendre la taille du fichier envoyé.

        Sauvegarde le rapport avec le bloc-note.

        Copie le dans ta réponse.

        Si tu ne trouves pas le fichier alors

        Affiche tous les fichiers et dossiers :

        Pour cela :
        Clique sur démarrer/panneau de configuration/option des dossiers/affichage

        Cocher afficher les dossiers cachés

        Décoche la case "Masquer les fichiers protégés du système d'exploitation (recommandé)"

        Décocher masquer les extensions dont le type est connu

        Puis fais «appliquer» pour valider les changements.

        Et OK
        0
        1. je suppose que "applic-1" est application data? Si c'est le cas je ne trouve pas le dossier 67220724?
          0
        2. Je suppose que "applic-1" est application data? Si c'est le cas je ne trouve pas le dossier 67220724?
          0
      4. Contributeur sécurité
        ok

        dans cet ordre (tu peux poster les rapports en suivant)

        1)

        Téléchargez USBFIX de Chiquitine29, C_xx

        http://pagesperso-orange.fr/NosTools/Chiquitine29/UsbFix.exe
        ou
        https://www.ionos.fr/?affiliate_id=77097

        /!\ Utilisateur de vista et windows 7 :
        ne pas oublier de désactiver Le contrôle des comptes utilisateurs
        https://www.commentcamarche.net/faq/8343-vista-desactiver-l-uac

        /!\ Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptible d'avoir été infectées sans les ouvrir

        • Double clic sur le raccourci UsbFix présent sur le bureau .

        Choisir l'option2
        (d’autres options disponibles, voir le tutoriel).
        • Laissez travailler l'outil.
        Le menu démarrer et les icônes vont disparaître.. c'est normal.

        Si un message te demande de redémarrer l'ordinateur fais le ...

        ● Au redémarrage, le fix se relance... laisses l'opération s'effectuer.

        ● Le bloc note s'ouvre avec un rapport, envoies le dans la prochaine réponse

        • Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque. ( C:\UsbFix.txt )

        ( CTRL+A Pour tout sélectionner , CTRL+C pour copier et CTRL+V pour coller )

        • Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
        Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
        Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.

        • Tuto : http://pagesperso-orange.fr/NosTools/usbfix.html

        UsbFix peut te demander d'uploader un dossier compressé à cette adresse : https://www.ionos.fr/?affiliate_id=77097

        Il est enregistré sur ton bureau.

        Merci de l'envoyer à l'adresse indiquée afin d'aider l'auteur de UsbFix dans ses recherches.

        Merci

        .............................

        2)

        Téléchargez MalwareByte's Anti-Malware

        http://www.malwarebytes.org/mbam/program/mbam-setup.exe

        . Enregistres le sur le bureau
        . Double cliques sur le fichier téléchargé pour lancer le processus d'installation.
        . Dans l'onglet "mise à jour", cliques sur le bouton Recherche de mise à jour
        . Si le pare-feu demande l'autorisation de se connecter pour malwarebytes, accepte
        . Une fois la mise à jour terminé
        . Rend-toi dans l'onglet, Recherche
        . Sélectionnes Exécuter un examen complet
        . Cliques sur Rechercher
        . Le scan démarre.
        . A la fin de l'analyse, un message s'affiche : L'examen s'est terminé normalement. Cliquez sur 'Afficher les résultats' pour afficher tous les objets trouvés.
        . Cliques sur Ok pour poursuivre.
        . Si des malwares ont été détectés, clique sur Afficher les résultats
        . Sélectionnes tout (ou laisses cochés) et cliques sur Supprimer la sélection Malwarebytes va détruire les fichiers et clés de registre et en mettre une copie dans la quarantaine.
        . Malwarebytes va ouvrir le bloc-notes et y copier le rapport d'analyse.
        . Rends toi dans l'onglet rapport/log
        . Tu cliques dessus pour l'afficher, une fois affiché
        . Tu cliques sur edition en haut du boc notes, et puis sur sélectionner tous
        . Tu recliques sur edition et puis sur copier et tu reviens sur le forum et dans ta réponse
        . tu cliques droit dans le cadre de la reponse et coller

        Si tu as besoin d'aide regarde ces tutoriels :
        Aide: https://www.malekal.com/tutoriel-malwarebyte-anti-malware/
        http://www.infos-du-net.com/forum/278396-11-tuto-malwarebytes-anti-malware-mbam

        ........................

        3)

        relancer RSIT et poster juste le rapport log

        0
        1. ############################## | UsbFix V6.070 |

          User : Thierry (Administrateurs) # LUCALULU
          Update on 03/01/2010 by El Desaparecido , C_XX & Chimay8
          Start at: 13:23:43 | 06/01/2010
          Website : http://pagesperso-orange.fr/NosTools/index.html
          Contact : FindyKill.Contact@gmail.com

          Intel(R) Pentium(R) D CPU 2.80GHz
          Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 2
          Internet Explorer 7.0.5730.11
          Windows Firewall Status : Enabled
          AV : avast! antivirus 4.8.1368 [VPS 100105-0] 4.8.1368 [ Enabled | Updated ]

          C:\ -> Disque fixe local # 232,88 Go (157,98 Go free) # NTFS
          D:\ -> Disque CD-ROM # 0 Mo (0 Mo free) [Audio CD] # CDFS
          E:\ -> Disque amovible
          F:\ -> Disque amovible
          G:\ -> Disque amovible
          H:\ -> Disque amovible
          I:\ -> Disque amovible

          ############################## | Processus actifs |

          C:\WINDOWS\System32\smss.exe 600
          C:\WINDOWS\system32\csrss.exe 828
          C:\WINDOWS\system32\winlogon.exe 852
          C:\WINDOWS\system32\services.exe 900
          C:\WINDOWS\system32\lsass.exe 912
          C:\WINDOWS\system32\svchost.exe 1088
          C:\WINDOWS\system32\svchost.exe 1144
          C:\WINDOWS\System32\svchost.exe 1292
          C:\WINDOWS\system32\svchost.exe 1336
          C:\WINDOWS\system32\svchost.exe 1420
          C:\WINDOWS\system32\logonui.exe 1440
          C:\WINDOWS\system32\svchost.exe 1664
          C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe 2000
          C:\Program Files\Alwil Software\Avast4\ashServ.exe 148
          C:\WINDOWS\Explorer.EXE 256
          C:\WINDOWS\system32\spoolsv.exe 784
          C:\Program Files\Alwil Software\Avast4\setup\avast.setup 1492
          C:\WINDOWS\system32\svchost.exe 1544
          C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe 1596
          C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe 1616
          C:\Program Files\CyberLink\PowerCinema\Kernel\CLML_NTService\CLMLServer.exe 1636
          C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe 1680
          C:\Program Files\CyberLink\PowerCinema\Kernel\CLML_NTService\CLMLService.exe 1692
          C:\WINDOWS\system32\nvsvc32.exe 1776
          C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe 1816
          C:\WINDOWS\system32\svchost.exe 424
          C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe 712
          C:\WINDOWS\system32\wuauclt.exe 1348
          C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe 1748
          C:\Program Files\Alwil Software\Avast4\ashWebSv.exe 2052
          C:\WINDOWS\system32\wbem\wmiprvse.exe 2284
          C:\WINDOWS\System32\alg.exe 2296

          ################## | Elements infectieux |

          Supprimé ! C:\DOCUME~1\Thierry\LOCALS~1\Temp\Setup.exe
          Supprimé ! C:\DOCUME~1\Thierry\LOCALS~1\Temp\un.bat
          Supprimé ! C:\Recycler\S-1-5-21-606747145-1715567821-839522115-1005
          Supprimé ! C:\Recycler\S-1-5-21-606747145-1715567821-839522115-500

          ################## | Registre |

          Supprimé ! [HKLM\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON"

          ################## | Mountpoints2 |

          Supprimé ! HKCU\...\Explorer\MountPoints2\{b91d2600-16e5-11dd-aca0-003005b259b6}\Shell\AutoRun\Command

          ################## | Listing des fichiers présent |

          [09/08/2009 14:37|--a------|268583] C:\Accueil - Site Officiel de la Ville de Lyon.mht
          [18/09/2007 11:54|--a------|24536608] C:\AdbeRdr810_fr_FR.exe
          [23/03/2009 20:37|--a------|626] C:\autoAlbum.log
          [04/04/2007 06:15|--a------|0] C:\AUTOEXEC.BAT
          [04/04/2007 06:10|---hs----|216] C:\boot.ini
          [05/08/2004 13:00|-rahs----|4952] C:\Bootfont.bin
          [20/10/2008 21:01|--a------|2389] C:\cleannavi.txt
          [16/12/2009 07:22|--a------|27136] C:\COMPTES MAISON.xls
          [06/01/2010 07:24|--a------|133632] C:\Comptes Sonia.xls
          [04/04/2007 06:15|--a------|0] C:\CONFIG.SYS
          [26/01/2008 22:46|--a------|58880] C:\CV Soso.doc
          [20/11/2009 22:56|--a------|123392] C:\d-compte LAFFITE.doc
          [23/09/2008 20:11|--a------|2303] C:\fixnavi.txt
          [19/08/2008 20:31|--a------|376] C:\HighLogging.log
          [06/02/2004 16:19|-ra------|16384] C:\hpqimgrc.resources.dll
          [04/04/2007 06:15|-rahs----|0] C:\IO.SYS
          [04/04/2007 06:15|-rahs----|0] C:\MSDOS.SYS
          [05/08/2004 13:00|-rahs----|47564] C:\NTDETECT.COM
          [05/08/2004 13:00|-rahs----|251712] C:\ntldr
          [29/02/2004 16:44|--a------|52576] C:\orange.bmp
          [?|?|?] C:\pagefile.sys
          [28/12/2009 11:05|--a------|104] C:\Raccourci vers SFR.lnk
          [03/09/2008 15:26|--a------|2753] C:\rapportantispyware.txt
          [08/07/2008 06:13|--a------|2698] C:\rollback.ini
          [12/07/2008 08:55|--a------|512] C:\ScanSectorLog.dat
          [28/12/2009 11:15|--a------|41958336] C:\setupfre.exe
          [06/01/2010 13:27|--a------|4464] C:\UsbFix.txt
          [06/05/2008 21:24|--a------|27102562] C:\xscan.txt
          [05/04/2007 18:46|--a------|1167] C:\_Sid.txt
          [01/01/1995 01:00|-r-------|44] D:\Track01.cda
          [01/01/1995 01:04|-r-------|44] D:\Track02.cda
          [01/01/1995 01:08|-r-------|44] D:\Track03.cda
          [01/01/1995 01:11|-r-------|44] D:\Track04.cda
          [01/01/1995 01:15|-r-------|44] D:\Track05.cda
          [01/01/1995 01:21|-r-------|44] D:\Track06.cda
          [01/01/1995 01:23|-r-------|44] D:\Track07.cda
          [01/01/1995 01:26|-r-------|44] D:\Track08.cda
          [01/01/1995 01:29|-r-------|44] D:\Track09.cda
          [01/01/1995 01:33|-r-------|44] D:\Track10.cda
          [01/01/1995 01:38|-r-------|44] D:\Track11.cda
          [01/01/1995 01:42|-r-------|44] D:\Track12.cda
          [01/01/1995 01:46|-r-------|44] D:\Track13.cda
          [01/01/1995 01:52|-r-------|44] D:\Track14.cda

          ################## | Vaccination |

          # C:\autorun.inf -> Dossier créé par UsbFix.

          ################## | Crack > Keygen > Serial |

          ################## | Upload |

          Veuillez envoyer le fichier : C:\DOCUME~1\Thierry\Bureau\UsbFix_Upload_Me_LUCALULU.zip : https://www.ionos.fr/?affiliate_id=77097
          Merci pour votre contribution .

          ################## | ! Fin du rapport # UsbFix V6.070 ! |
          0
        2. Malwarebytes' Anti-Malware 1.43
          Version de la base de données: 3502
          Windows 5.1.2600 Service Pack 2
          Internet Explorer 7.0.5730.11

          06/01/2010 20:24:48
          mbam-log-2010-01-06 (20-24-48).txt

          Type de recherche: Examen complet (C:\|D:\|E:\|F:\|G:\|H:\|I:\|)
          Eléments examinés: 196502
          Temps écoulé: 49 minute(s), 50 second(s)

          Processus mémoire infecté(s): 0
          Module(s) mémoire infecté(s): 0
          Clé(s) du Registre infectée(s): 9
          Valeur(s) du Registre infectée(s): 2
          Elément(s) de données du Registre infecté(s): 0
          Dossier(s) infecté(s): 0
          Fichier(s) infecté(s): 9

          Processus mémoire infecté(s):
          (Aucun élément nuisible détecté)

          Module(s) mémoire infecté(s):
          (Aucun élément nuisible détecté)

          Clé(s) du Registre infectée(s):
          HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{6fd31ed6-7c94-4bbc-8e95-f927f4d3a949} (Adware.180Solutions) -> Quarantined and deleted successfully.
          HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1f158a1e-a687-4a11-9679-b3ac64b86a1c} (Adware.Seekmo) -> Quarantined and deleted successfully.
          HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{100eb1fd-d03e-47fd-81f3-ee91287f9465} (Adware.ShopperReports) -> Quarantined and deleted successfully.
          HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{c5428486-50a0-4a02-9d20-520b59a9f9b2} (Adware.ShopperReports) -> Quarantined and deleted successfully.
          HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{c5428486-50a0-4a02-9d20-520b59a9f9b3} (Adware.ShopperReports) -> Quarantined and deleted successfully.
          HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{90b8b761-df2b-48ac-bbe0-bcc03a819b3b} (Adware.Zango) -> Quarantined and deleted successfully.
          HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{bfc08cff-c737-4433-bd5a-0ee7efcfee54} (Adware.Zango) -> Quarantined and deleted successfully.
          HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{09f1adac-76d8-4d0f-99a5-5c907dadb988} (Rogue.Multiple) -> Quarantined and deleted successfully.
          HKEY_CURRENT_USER\SOFTWARE\fcn (Rogue.Residue) -> Quarantined and deleted successfully.

          Valeur(s) du Registre infectée(s):
          HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\sysgif32 (Trojan.Agent) -> Quarantined and deleted successfully.
          HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\67220724 (Rogue.Multiple) -> Quarantined and deleted successfully.

          Elément(s) de données du Registre infecté(s):
          (Aucun élément nuisible détecté)

          Dossier(s) infecté(s):
          (Aucun élément nuisible détecté)

          Fichier(s) infecté(s):
          C:\Documents and Settings\Thierry\Local Settings\Temp\nsy924.tmp\NSISdl.dll (Trojan.Banker) -> Quarantined and deleted successfully.
          C:\Program Files\Navilog1\gnc.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
          C:\UsbFix\Quarantine\C\RECYCLER\S-1-5-21-606747145-1715567821-839522115-500.UsbFix\Dc1\67220724.exe (Rogue.Installer) -> Delete on reboot.
          C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\3ZVP15OW\wcap[1].exe (Trojan.Dropper) -> Quarantined and deleted successfully.
          C:\WINDOWS\system32\drivers\vymmswss.sys (Rootkit.Agent) -> Delete on reboot.
          C:\WINDOWS\Temp\TMP149.tmp (Trojan.Dropper) -> Quarantined and deleted successfully.
          C:\WINDOWS\Temp\~TM147.tmp (Trojan.Dropper) -> Delete on reboot.
          C:\Documents and Settings\Thierry\Application Data\avdrn.dat (Malware.Trace) -> Quarantined and deleted successfully.
          C:\Documents and Settings\Thierry\Application Data\fvgqad.dat (Malware.Trace) -> Quarantined and deleted successfully.
          0
      5. Contributeur sécurité
        à quoi correspondent ces périphériques ?

        il ne sont pas vaccinés et donc absents du scan

        E:\ -> Disque amovible
        F:\ -> Disque amovible
        G:\ -> Disque amovible
        H:\ -> Disque amovible
        I:\ -> Disque amovible

        0
        1. Ceux st mes srtis usb, carts Sd, lecteur DVD etc, mais je me sens sert quasimment jamais
          0
      6. Contributeur sécurité
        ils peuvent être infectés et de plus, seront vaccinés pour ne pas l'être

        refais l'option 2 avec eux

        et tu pourras enchainer avec MalwareByte's Anti-Malware

        0
        1. Contributeur sécurité
          redemarrer le pc pour que les suppressions soient effectives

          puis

          refaire un nouveau RSIT stp
          0
          1. Logfile of random's system information tool 1.06 (written by random/random)
            Run by Thierry at 2010-01-06 21:17:11
            Microsoft Windows XP Édition familiale Service Pack 2
            System drive C: has 162 GB (68%) free of 238 GB
            Total RAM: 1023 MB (51% free)

            Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 21:17:24, on 06/01/2010
            Platform: Windows XP SP2 (WinNT 5.01.2600)
            MSIE: Internet Explorer v7.00 (7.00.6000.16945)
            Boot mode: Normal

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\system32\svchost.exe
            C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
            C:\Program Files\Alwil Software\Avast4\ashServ.exe
            C:\WINDOWS\system32\spoolsv.exe
            C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
            C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe
            C:\Program Files\CyberLink\PowerCinema\Kernel\CLML_NTService\CLMLServer.exe
            C:\Program Files\CyberLink\PowerCinema\Kernel\CLML_NTService\CLMLService.exe
            C:\WINDOWS\system32\nvsvc32.exe
            C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
            C:\WINDOWS\system32\svchost.exe
            C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe
            C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
            C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
            C:\WINDOWS\explorer.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\system32\wuauclt.exe
            C:\WINDOWS\system32\ctfmon.exe
            C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
            C:\Program Files\Mozilla Firefox\firefox.exe
            C:\Documents and Settings\Thierry\Mes documents\Téléchargements\RSIT.exe
            C:\Program Files\Trend Micro\Thierry.exe

            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
            R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer
            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
            O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
            O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
            O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
            O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
            O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
            O2 - BHO: BrowserHelper Class - {8A9D74F9-560B-4FE7-ABEB-3B2E638E5CD6} - C:\Program Files\SGPSA\SearchAssistant.dll (file missing)
            O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
            O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
            O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll
            O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
            O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
            O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
            O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
            O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
            O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
            O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
            O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
            O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
            O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
            O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
            O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
            O4 - HKLM\..\Run: [PCMService] "C:\Program Files\CyberLink\PowerCinema\PCMService.exe"
            O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
            O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
            O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
            O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
            O4 - HKLM\..\Run: [HerculesCamService] C:\Program Files\Hercules\Hercules Blog Webcam\CamService.exe
            O4 - HKLM\..\Run: [Real Popup-Killer] c:\TuePub\TuePub.exe
            O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
            O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
            O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
            O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
            O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
            O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|DEFAULT=cnx|PARAM=
            O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
            O4 - HKCU\..\Run: [Rainlendar2] C:\Program Files\Rainlendar2\Rainlendar2.exe
            O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
            O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
            O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
            O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Thierry\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
            O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\\Phone\Skype.exe" /nosplash /minimized
            O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
            O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
            O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
            O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
            O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
            O4 - Startup: MaxTV.lnk = C:\Program Files\DMV\MaxTV4\maxtv.exe
            O4 - Startup: VirtualExpander.lnk = C:\WINDOWS\system32\VirtualExpander\VirtualExpander.exe
            O4 - Global Startup: Démarrage rapide du logiciel HP Image Zone.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
            O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
            O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
            O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
            O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
            O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
            O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
            O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
            O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
            O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
            O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
            O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
            O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
            O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
            O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O16 - DPF: {1FF43AD5-2262-4C2F-81D4-26D710C3F305} (VB2S Mannequin Virtuel Control) - http://mannequin.redoute.fr/activex/Mannequin.cab
            O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab
            O16 - DPF: {54823A9D-6BAE-11D5-B519-0050BA2413EB} (ChkDVDCtl Class) - http://www.cyberlink.com/winxp/CheckDVD.cab
            O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.zebulon.fr/scan8/oscan8.cab
            O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
            O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
            O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
            O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
            O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
            O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
            O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
            O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
            O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
            O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe
            O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe
            O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\PowerCinema\Kernel\CLML_NTService\CLMLServer.exe
            O23 - Service: Google Desktop Manager 5.9.909.30391 (GoogleDesktopManager-093009-130223) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
            O23 - Service: Service Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
            O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
            O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
            O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
            O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
            O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
            0
          2. malwarebytes trouve le probleme mais n'arrive pas à le supprimer, que faire?

            Malwarebytes' Anti-Malware 1.43
            Version de la base de données: 3502
            Windows 5.1.2600 Service Pack 2
            Internet Explorer 7.0.5730.11

            06/01/2010 21:19:09
            mbam-log-2010-01-06 (21-19-09).txt

            Type de recherche: Examen rapide
            Eléments examinés: 1
            Temps écoulé: 6 second(s)

            Processus mémoire infecté(s): 0
            Module(s) mémoire infecté(s): 0
            Clé(s) du Registre infectée(s): 0
            Valeur(s) du Registre infectée(s): 0
            Elément(s) de données du Registre infecté(s): 0
            Dossier(s) infecté(s): 0
            Fichier(s) infecté(s): 1

            Processus mémoire infecté(s):
            (Aucun élément nuisible détecté)

            Module(s) mémoire infecté(s):
            (Aucun élément nuisible détecté)

            Clé(s) du Registre infectée(s):
            (Aucun élément nuisible détecté)

            Valeur(s) du Registre infectée(s):
            (Aucun élément nuisible détecté)

            Elément(s) de données du Registre infecté(s):
            (Aucun élément nuisible détecté)

            Dossier(s) infecté(s):
            (Aucun élément nuisible détecté)

            Fichier(s) infecté(s):
            c:\WINDOWS\system32\drivers\vymmswss.sys (Rootkit.Agent) -> Delete on reboot.
            0
        2. Contributeur sécurité
          Delete on reboot.= redemarrer le pc

          Examen rapide ...à refaire dons mais en examen complet, puis supprimer ce qu'il trouve et poster le rapport....

          0
          1. Contributeur sécurité
            redemarres le pc

            relances RSIT et postes le rapport log
            0
            1. Logfile of random's system information tool 1.06 (written by random/random)
              Run by Thierry at 2010-01-10 11:20:32
              Microsoft Windows XP Édition familiale Service Pack 2
              System drive C: has 162 GB (68%) free of 238 GB
              Total RAM: 1023 MB (31% free)

              Logfile of Trend Micro HijackThis v2.0.2
              Scan saved at 11:20:54, on 10/01/2010
              Platform: Windows XP SP2 (WinNT 5.01.2600)
              MSIE: Internet Explorer v7.00 (7.00.6000.16945)
              Boot mode: Normal

              Running processes:
              C:\WINDOWS\System32\smss.exe
              C:\WINDOWS\system32\winlogon.exe
              C:\WINDOWS\system32\services.exe
              C:\WINDOWS\system32\lsass.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\system32\svchost.exe
              C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
              C:\Program Files\Alwil Software\Avast4\ashServ.exe
              C:\WINDOWS\Explorer.EXE
              C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
              C:\WINDOWS\RTHDCPL.EXE
              C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
              C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
              C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
              C:\Program Files\CyberLink\PowerCinema\PCMService.exe
              C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
              C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
              C:\Program Files\Hercules\Hercules Blog Webcam\CamService.exe
              C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
              C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
              C:\WINDOWS\system32\ctfmon.exe
              C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
              C:\Program Files\Messenger\msmsgs.exe
              C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
              C:\WINDOWS\system32\spoolsv.exe
              C:\Program Files\Skype\Phone\Skype.exe
              C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
              C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
              C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
              C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe
              C:\Program Files\CyberLink\PowerCinema\Kernel\CLML_NTService\CLMLServer.exe
              C:\Program Files\CyberLink\PowerCinema\Kernel\CLML_NTService\CLMLService.exe
              C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
              C:\WINDOWS\system32\VirtualExpander\VirtualExpander.exe
              C:\WINDOWS\system32\nvsvc32.exe
              C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
              C:\WINDOWS\system32\svchost.exe
              C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe
              C:\WINDOWS\system32\wuauclt.exe
              C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
              C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
              C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
              C:\WINDOWS\System32\svchost.exe
              C:\Program Files\Skype\Plugin Manager\skypePM.exe
              C:\WINDOWS\system32\wbem\wmiapsrv.exe
              C:\WINDOWS\system32\wuauclt.exe
              C:\Documents and Settings\Thierry\Mes documents\Téléchargements\RSIT.exe
              C:\Program Files\Trend Micro\Thierry.exe

              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer
              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
              O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
              O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
              O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
              O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
              O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
              O2 - BHO: BrowserHelper Class - {8A9D74F9-560B-4FE7-ABEB-3B2E638E5CD6} - C:\Program Files\SGPSA\SearchAssistant.dll (file missing)
              O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
              O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
              O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll
              O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
              O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
              O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
              O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
              O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
              O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
              O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
              O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
              O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
              O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
              O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
              O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
              O4 - HKLM\..\Run: [PCMService] "C:\Program Files\CyberLink\PowerCinema\PCMService.exe"
              O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
              O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
              O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
              O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
              O4 - HKLM\..\Run: [HerculesCamService] C:\Program Files\Hercules\Hercules Blog Webcam\CamService.exe
              O4 - HKLM\..\Run: [Real Popup-Killer] c:\TuePub\TuePub.exe
              O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
              O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
              O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
              O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
              O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|DEFAULT=cnx|PARAM=
              O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
              O4 - HKCU\..\Run: [Rainlendar2] C:\Program Files\Rainlendar2\Rainlendar2.exe
              O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
              O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
              O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
              O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Thierry\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
              O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\\Phone\Skype.exe" /nosplash /minimized
              O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
              O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
              O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
              O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
              O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
              O4 - Startup: MaxTV.lnk = C:\Program Files\DMV\MaxTV4\maxtv.exe
              O4 - Startup: VirtualExpander.lnk = C:\WINDOWS\system32\VirtualExpander\VirtualExpander.exe
              O4 - Global Startup: Démarrage rapide du logiciel HP Image Zone.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
              O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
              O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
              O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
              O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
              O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
              O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
              O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
              O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
              O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
              O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
              O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
              O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
              O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
              O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
              O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
              O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O16 - DPF: {1FF43AD5-2262-4C2F-81D4-26D710C3F305} (VB2S Mannequin Virtuel Control) - http://mannequin.redoute.fr/activex/Mannequin.cab
              O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab
              O16 - DPF: {54823A9D-6BAE-11D5-B519-0050BA2413EB} (ChkDVDCtl Class) - http://www.cyberlink.com/winxp/CheckDVD.cab
              O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.zebulon.fr/scan8/oscan8.cab
              O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/...
              O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
              O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
              O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
              O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
              O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
              O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
              O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
              O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
              O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe
              O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe
              O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\PowerCinema\Kernel\CLML_NTService\CLMLServer.exe
              O23 - Service: Google Desktop Manager 5.9.909.30391 (GoogleDesktopManager-093009-130223) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
              O23 - Service: Service Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
              O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
              O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
              O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
              O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
              O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
              0
          2. Contributeur sécurité
            as tu bien redemarré le pc pour rendre effective la suppression par MBAM

            si oui refais un examen rapide

            s'il est encore là, on passera quelque chose de plus fort
            0
            1. j'ai bien redemarre le PC, et il est tjrs là!!!!!!!!!! je commence à desesperer!!!!!!!!
              0
          3. Contributeur sécurité
            Attention, avant de commencer, lit attentivement la procédure, et imprime la

            Télécharge ComboFix de sUBs sur ton Bureau :

            http://download.bleepingcomputer.com/sUBs/ComboFix.exe

            /!\ Déconnecte-toi du net et DESACTIVES TOUTES LES DEFENSES, antivirus et antispyware y compris /!\

            ---> Double-clique sur ComboFix.exe
            Un "pop-up" va apparaître qui dit que ComboFix est utilisé à vos risques et avec aucune garantie... Clique sur oui pour accepter

            SURTOUT INSTALLES LA CONSOLE DE RECUPERATION
            (si il te le propose remets provisoirement internet)

            ---> Mets-le en langue française F
            Tape sur la touche 1 (Yes) pour démarrer le scan.

            Ne touche à rien(souris, clavier) tant que le scan n'est pas terminé, car tu risques de planter ton PC

            En fin de scan, il est possible que ComboFix ait besoin de redémarrer le PC pour finaliser la désinfection, laisse-le faire.

            Une fois le scan achevé, un rapport va s'afficher : Poste son contenu

            /!\ Réactive la protection en temps réel de ton antivirus et de ton antispyware avant de te reconnecter à Internet. /!\

            Note : Le rapport se trouve également là : C:\ComboFix.txt
            0
            1. ComboFix 10-01-04.01 - Thierry 10/01/2010 20:49:15.1.2 - x86
              Microsoft Windows XP Édition familiale 5.1.2600.2.1252.33.1036.18.1023.490 [GMT 1:00]
              Lancé depuis: c:\documents and settings\Thierry\Mes documents\Téléchargements\ComboFix.exe
              .

              (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
              .

              c:\program files\WinPCap
              c:\program files\WinPCap\rpcapd.exe
              c:\windows\patch.exe
              c:\windows\system32\drivers\npf.sys
              c:\windows\system32\Packet.dll
              c:\windows\system32\pthreadVC.dll
              c:\windows\system32\WanPacket.dll
              c:\windows\system32\wpcap.dll

              .
              ((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
              .

              -------\Legacy_NPF
              -------\Service_npf

              ((((((((((((((((((((((((((((( Fichiers créés du 2009-12-10 au 2010-01-10 ))))))))))))))))))))))))))))))))))))
              .

              2010-01-06 19:26 . 2010-01-06 19:26 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Google
              2010-01-06 19:21 . 2010-01-06 19:21 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Google
              2010-01-06 17:30 . 2010-01-10 19:42 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
              2010-01-06 12:20 . 2010-01-06 19:42 -------- d-----w- C:\UsbFix
              2010-01-06 07:05 . 2010-01-06 07:22 -------- d-----w- C:\rsit
              2009-12-30 18:03 . 2009-12-30 18:03 -------- d-----w- c:\documents and settings\Administrateur\Local Settings\Application Data\Mozilla
              2009-12-29 13:54 . 2009-12-29 13:54 -------- d-----w- c:\program files\Sophos
              2009-12-28 22:12 . 2010-01-10 19:42 -------- d-----w- c:\program files\Spybot - Search & Destroy
              2009-12-28 22:12 . 2010-01-10 19:26 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
              2009-12-28 10:15 . 2009-12-28 10:15 41958336 ----a-w- C:\setupfre.exe
              2009-12-28 10:09 . 2009-12-28 10:12 -------- d-----w- C:\fichiers installations
              2009-12-28 09:44 . 2009-12-28 10:03 -------- d-----w- C:\THIERRY
              2009-12-28 09:23 . 2009-12-28 09:23 -------- d-----w- c:\program files\Fichiers communs\Wise Installation Wizard
              2009-12-27 13:31 . 2010-01-10 19:57 763904 ----a-w- c:\windows\system32\drivers\vymmswss.sys

              .
              (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
              .
              2010-01-10 19:45 . 2009-06-09 19:39 -------- d-----w- c:\documents and settings\Thierry\Application Data\Skype
              2010-01-10 19:42 . 2009-06-09 19:41 -------- d-----w- c:\documents and settings\Thierry\Application Data\skypePM
              2010-01-10 10:20 . 2008-10-20 20:08 -------- d-----w- c:\program files\Trend Micro
              2010-01-09 22:25 . 2007-04-05 16:16 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater
              2010-01-06 19:24 . 2008-09-03 14:07 -------- d-----w- c:\program files\Navilog1
              2010-01-06 19:21 . 2007-04-05 16:16 -------- d-----w- c:\program files\Google
              2009-12-31 21:57 . 2009-11-29 19:48 -------- d-----w- c:\documents and settings\Thierry\Application Data\vlc
              2009-12-31 21:44 . 2009-11-29 19:48 -------- d-----w- c:\documents and settings\Thierry\Application Data\dvdcss
              2009-12-28 10:55 . 2008-06-02 14:49 -------- d-----w- c:\documents and settings\All Users\Application Data\Avira
              2009-12-28 09:56 . 2008-08-18 14:22 -------- d-----w- c:\program files\BitDefender
              2009-12-28 09:54 . 2008-08-18 14:26 81984 ----a-w- c:\windows\system32\bdod.bin
              2009-12-09 21:07 . 2004-08-05 12:00 84874 ----a-w- c:\windows\system32\perfc00C.dat
              2009-12-09 21:07 . 2004-08-05 12:00 510656 ----a-w- c:\windows\system32\perfh00C.dat
              2009-11-29 19:46 . 2009-11-29 19:46 -------- d-----w- c:\program files\VideoLAN
              2009-11-27 17:50 . 2009-11-27 17:50 -------- d-----w- c:\program files\Skyline
              2009-11-22 17:35 . 2009-11-22 17:35 -------- d-----w- c:\documents and settings\Thierry\Application Data\Anuman Interactive
              2009-11-19 10:48 . 2009-12-01 06:30 872960 ----a-w- c:\documents and settings\Thierry\Application Data\Mozilla\Firefox\Profiles\ie2qzp4i.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
              2009-11-19 10:48 . 2009-12-01 06:30 43008 ----a-w- c:\documents and settings\Thierry\Application Data\Mozilla\Firefox\Profiles\ie2qzp4i.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbarloader.dll
              2009-11-19 10:48 . 2009-12-01 06:30 340480 ----a-w- c:\documents and settings\Thierry\Application Data\Mozilla\Firefox\Profiles\ie2qzp4i.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff2.dll
              2009-11-19 10:48 . 2009-12-01 06:30 346624 ----a-w- c:\documents and settings\Thierry\Application Data\Mozilla\Firefox\Profiles\ie2qzp4i.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff3.dll
              2009-11-18 14:29 . 2009-11-17 17:32 -------- d-----w- c:\program files\Microsoft Silverlight
              2009-11-17 17:34 . 2007-04-04 10:47 40872 ----a-w- c:\documents and settings\Thierry\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
              2009-11-17 17:32 . 2009-11-17 17:28 -------- d-----w- c:\program files\Microsoft
              2009-11-17 17:32 . 2008-05-05 11:14 -------- d-----w- c:\program files\Windows Live
              2009-11-17 17:31 . 2009-11-17 17:31 -------- d-----w- c:\program files\Microsoft Sync Framework
              2009-11-17 17:30 . 2009-11-17 17:30 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
              2009-11-17 17:28 . 2009-11-17 17:28 -------- d-----w- c:\program files\Windows Live SkyDrive
              2009-11-17 16:51 . 2009-11-17 16:51 -------- d-----w- c:\program files\Fichiers communs\Windows Live
              2009-10-29 07:44 . 2004-09-29 18:49 832512 ----a-w- c:\windows\system32\wininet.dll
              2009-10-29 07:44 . 2004-08-05 12:00 78336 ----a-w- c:\windows\system32\ieencode.dll
              2009-10-29 07:44 . 2004-08-05 12:00 17408 ----a-w- c:\windows\system32\corpol.dll
              2009-10-21 06:03 . 2004-08-05 12:00 75776 ----a-w- c:\windows\system32\strmfilt.dll
              2009-10-21 06:03 . 2004-08-05 12:00 25088 ----a-w- c:\windows\system32\httpapi.dll
              2009-10-20 14:58 . 2004-08-05 12:00 263552 ----a-w- c:\windows\system32\drivers\http.sys
              2009-10-13 10:52 . 2004-08-05 12:00 267776 ----a-w- c:\windows\system32\oakley.dll
              2007-04-04 11:26 . 2007-04-04 05:37 278528 ----a-w- c:\program files\Fichiers communs\FDEUnInstaller.exe
              2009-10-24 16:26 . 2007-08-12 21:31 119808 ----a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
              .

              ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
              .
              .
              *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
              REGEDIT4

              [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\VirtualExpanderFile.1]
              @="{E4000AC4-5E5F-4956-807A-C5854405D64F}"
              [HKEY_CLASSES_ROOT\CLSID\{E4000AC4-5E5F-4956-807A-C5854405D64F}]
              2008-10-20 14:17 73728 ----a-w- c:\windows\system32\VirtualExpander\VEShellExt.dll

              [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
              "MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2009-07-26 3883856]
              "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe" [2007-03-22 149040]
              "MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
              "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-04-05 68856]
              "Google Update"="c:\documents and settings\Thierry\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-09-04 133104]
              "Skype"="c:\program files\Skype\\Phone\Skype.exe" [2009-10-09 25623336]

              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
              "High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2004-10-27 61952]
              "SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
              "RTHDCPL"="RTHDCPL.EXE" [2005-10-14 14864384]
              "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-08-02 7110656]
              "nwiz"="nwiz.exe" [2005-08-02 1519616]
              "Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2009-10-24 30192]
              "HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2004-02-12 49152]
              "HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2004-05-12 241664]
              "PCMService"="c:\program files\CyberLink\PowerCinema\PCMService.exe" [2005-09-30 139264]
              "RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2005-04-15 45056]
              "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-11-14 286720]
              "NeroFilterCheck"="c:\program files\Fichiers communs\Ahead\Lib\NeroCheck.exe" [2007-03-15 153136]
              "PCSuiteTrayApplication"="c:\program files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2007-06-18 271360]
              "HerculesCamService"="c:\program files\Hercules\Hercules Blog Webcam\CamService.exe" [2006-10-13 122880]
              "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]

              [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
              "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-05 15360]
              "Nokia.PCSync"="c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-06-19 1241088]

              c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
              D‚marrage rapide du logiciel HP Image Zone.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2004-5-28 53248]
              HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2004-5-28 241664]
              Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]

              [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
              "HonorAutoRunSetting"= 0 (0x0)

              [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
              "HonorAutoRunSetting"= 0 (0x0)

              [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
              "%windir%\\system32\\sessmgr.exe"=
              "c:\\Program Files\\CyberLink\\PowerCinema\\PowerCinema.exe"=
              "c:\\Program Files\\CyberLink\\PowerCinema\\PCMService.exe"=
              "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
              "c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
              "c:\\Program Files\\Messenger\\msmsgs.exe"=
              "c:\\Program Files\\Hercules\\Hercules Blog Webcam\\Station2.exe"=
              "c:\\Program Files\\Hercules\\Hercules Blog Webcam\\ControlUI.exe"=
              "c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
              "c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
              "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
              "c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
              "c:\\Program Files\\Skype\\Phone\\Skype.exe"=

              R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [17/11/2009 18:32 54752]
              R3 3xHybrid;3xHybrid service;c:\windows\system32\drivers\3xHybrid.sys [04/04/2007 12:21 799744]
              R3 APL531;Hercules Blog Webcam;c:\windows\system32\drivers\BLvid.sys [15/07/2008 20:58 274816]
              R3 camfilt;camfilt;c:\windows\system32\drivers\camfilt.sys [15/07/2008 20:58 22656]
              R3 SIS163u;SiS163 usb Wireless LAN Adapter Driver;c:\windows\system32\drivers\sis163u.sys [04/04/2007 12:20 215040]
              S2 gupdate;Service Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [06/01/2010 20:21 135664]
              S3 fsssvc;Service Windows Live Contrôle parental;c:\program files\Windows Live\Family Safety\fsssvc.exe [05/08/2009 22:48 704864]
              S3 GoogleDesktopManager-093009-130223;Google Desktop Manager 5.9.909.30391;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [05/04/2007 17:17 30192]
              S3 MEMSWEEP2;MEMSWEEP2;\??\c:\windows\system32\3A.tmp --> c:\windows\system32\3A.tmp [?]

              --- Autres Services/Pilotes en mémoire ---

              *Deregistered* - vymmswss
              .
              Contenu du dossier 'Tâches planifiées'

              2010-01-10 c:\windows\Tasks\Google Software Updater.job
              - c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-04-05 18:50]

              2010-01-10 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
              - c:\program files\Google\Update\GoogleUpdate.exe [2010-01-06 19:21]

              2010-01-10 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
              - c:\program files\Google\Update\GoogleUpdate.exe [2010-01-06 19:21]

              2010-01-09 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-606747145-1715567821-839522115-1005Core.job
              - c:\documents and settings\Thierry\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-04 20:30]

              2010-01-10 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-606747145-1715567821-839522115-1005UA.job
              - c:\documents and settings\Thierry\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-04 20:30]

              2010-01-09 c:\windows\Tasks\WebReg 20070611225932.job
              - c:\program files\HP\Digital Imaging\bin\hpqwrg.exe [2004-05-28 20:47]
              .
              .
              ------- Examen supplémentaire -------
              .
              uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
              uSearchAssistant = hxxp://www.google.com/ie
              uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
              IE: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
              IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~3\Office10\EXCEL.EXE/3000
              IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
              DPF: {1FF43AD5-2262-4C2F-81D4-26D710C3F305} - hxxp://mannequin.redoute.fr/activex/Mannequin.cab
              DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - hxxp://www.zebulon.fr/scan8/oscan8.cab
              FF - ProfilePath - c:\documents and settings\Thierry\Application Data\Mozilla\Firefox\Profiles\ie2qzp4i.default\
              FF - prefs.js: browser.search.selectedEngine - Fast Browser Search
              FF - prefs.js: browser.startup.homepage - hxxp://www.construiresamaison.com/
              FF - component: c:\documents and settings\Thierry\Application Data\Mozilla\Firefox\Profiles\ie2qzp4i.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
              FF - component: c:\program files\Mozilla Firefox\components\GoogleDesktopMozilla.dll
              FF - plugin: c:\documents and settings\Thierry\Local Settings\Application Data\Google\Update\1.2.183.13\npGoogleOneClick8.dll
              FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
              FF - plugin: c:\program files\Google\Google Updater\2.4.1368.5602\npCIDetect13.dll
              FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
              FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
              FF - plugin: c:\program files\Mozilla Firefox\plugins\npMdm.dll
              FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
              FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
              .
              - - - - ORPHELINS SUPPRIMES - - - -

              HKCU-Run-WOOKIT - c:\progra~1\Wanadoo\Shell.exe
              HKCU-Run-Rainlendar2 - c:\program files\Rainlendar2\Rainlendar2.exe
              HKLM-Run-Real Popup-Killer - c:\tuepub\TuePub.exe
              AddRemove-ShockwaveFlash - c:\windows\system32\Macromed\Flash\FlashUtil9b.exe

              **************************************************************************

              catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
              Rootkit scan 2010-01-10 20:56
              Windows 5.1.2600 Service Pack 2 NTFS

              Recherche de processus cachés ...

              Recherche d'éléments en démarrage automatique cachés ...

              Recherche de fichiers cachés ...

              Scan terminé avec succès
              Fichiers cachés: 0

              **************************************************************************

              [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MEMSWEEP2]
              "ImagePath"="\??\c:\windows\system32\3A.tmp"

              [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\vymmswss]

              .
              --------------------- DLLs chargées dans les processus actifs ---------------------

              - - - - - - - > 'explorer.exe'(3916)
              c:\windows\system32\VirtualExpander\VEShellExt.dll
              c:\program files\Fichiers communs\Ahead\Lib\NeroSearchBar.dll
              c:\program files\Fichiers communs\Ahead\Lib\MFC71U.DLL
              c:\program files\Fichiers communs\Ahead\Lib\BCGCBPRO800u.dll
              c:\windows\system32\WPDShServiceObj.dll
              c:\program files\Nokia\Nokia PC Suite 6\PhoneBrowser.dll
              c:\program files\Nokia\Nokia PC Suite 6\PCSCM.dll
              c:\program files\Nokia\Nokia PC Suite 6\Lang\PhoneBrowser_fre.nlr
              c:\program files\Nokia\Nokia PC Suite 6\Resource\PhoneBrowser_Nokia.ngr
              c:\windows\system32\PortableDeviceTypes.dll
              c:\windows\system32\PortableDeviceApi.dll
              .
              ------------------------ Autres processus actifs ------------------------
              .
              c:\program files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
              c:\program files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe
              c:\program files\CyberLink\PowerCinema\Kernel\CLML_NTService\CLMLServer.exe
              c:\program files\CyberLink\PowerCinema\Kernel\CLML_NTService\CLMLService.exe
              c:\windows\system32\nvsvc32.exe
              c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
              c:\program files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe
              c:\windows\system32\wscntfy.exe
              c:\windows\RTHDCPL.EXE
              c:\program files\Skype\Phone\Skype.exe
              c:\program files\PC Connectivity Solution\ServiceLayer.exe
              c:\program files\HP\Digital Imaging\bin\hpqgalry.exe
              c:\windows\system32\VirtualExpander\VirtualExpander.exe
              c:\program files\Skype\Plugin Manager\skypePM.exe
              c:\windows\system32\wbem\wmiapsrv.exe
              .
              **************************************************************************
              .
              Heure de fin: 2010-01-10 21:02:23 - La machine a redémarré
              ComboFix-quarantined-files.txt 2010-01-10 20:02

              Avant-CF: 169 551 568 896 octets libres
              Après-CF: 170 606 854 144 octets libres

              WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe
              [boot loader]
              timeout=2
              default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
              [operating systems]
              c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
              multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP dition familiale" /noexecute=optin /fastdetect

              - - End Of File - - D60416934B4C2B4A3AE56E84835ED0D3
              0
          4. Contributeur sécurité
            ok refais un MBAM rapdide stp
            0
            1. Malwarebytes' Anti-Malware 1.44
              Version de la base de données: 3539
              Windows 5.1.2600 Service Pack 2
              Internet Explorer 7.0.5730.11

              11/01/2010 19:43:22
              mbam-log-2010-01-11 (19-43-22).txt

              Type de recherche: Examen rapide
              Eléments examinés: 118449
              Temps écoulé: 6 minute(s), 56 second(s)

              Processus mémoire infecté(s): 0
              Module(s) mémoire infecté(s): 0
              Clé(s) du Registre infectée(s): 0
              Valeur(s) du Registre infectée(s): 0
              Elément(s) de données du Registre infecté(s): 0
              Dossier(s) infecté(s): 0
              Fichier(s) infecté(s): 1

              Processus mémoire infecté(s):
              (Aucun élément nuisible détecté)

              Module(s) mémoire infecté(s):
              (Aucun élément nuisible détecté)

              Clé(s) du Registre infectée(s):
              (Aucun élément nuisible détecté)

              Valeur(s) du Registre infectée(s):
              (Aucun élément nuisible détecté)

              Elément(s) de données du Registre infecté(s):
              (Aucun élément nuisible détecté)

              Dossier(s) infecté(s):
              (Aucun élément nuisible détecté)

              Fichier(s) infecté(s):
              C:\WINDOWS\system32\drivers\vymmswss.sys (Rootkit.Agent) -> Delete on reboot.
              0
          5. Contributeur sécurité
            il est fatiguant ce rookit

            désinstalles combofix et supprimes

            puis

            retélécharges le en le renommant LUCA.exe avant de l'enregistrer sur ton bureau

            ensuite, même procédure qu'au post 28

            0