Gibidl.dll est introuvable

Bonjour,
dès que je démarre mon ordinateur ce message s'affiche:
Cette application n'a pas pu démarrer car gibidl.dll est introuvable.
La réinstallation de cette application peut corriger ce problème.

j'aimerais savoir comment faire pour qu'il ne s'affiche plus, j'ai lu dans le forum qu'il fallait ouvrir son propre topic pour résoudre le problème. j'attends votre aide merci
Configuration: Windows XP  firefox 3.6

23 réponses

  1. Bonjour,
    Très simple, il te suffit de télécharger ce pauvre petit DLL qui s'es perdu dans ton ordinateur ou qui à été supprimée par erreur.
    Tu peut le télécharger gratuitement ici :
    https://www.fichier-dll.fr/
    0
    1. je suis allé sur le site et il n'y est pas donc que dois je faire
      0
      1. Contributeur sécurité
        bonjour

        • Télécharge Random's System Information Tool (RSIT) de Random/Random.

        (outil de diagnostic)

        http://images.malwareremoval.com/random/RSIT.exe

        • Enregistre le sur ton Bureau.

        • Double clique sur RSIT.exe pour lancer l'outil.

        • Clique sur "Continue" à l'écran Disclaimer.

        • Si l'outil HijackThis n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu s'il te le demande)

        et tu devras accepter la licence.

        • Une fois le scan terminé, deux rapports vont apparaître : poste les dans deux messages séparés stp

        Les rapports se trouvent à cet endroit:
        C:\rsit\info.txt
        C:\rsit\log.txt

        0
        1. voici le rapport log:

          Logfile of random's system information tool 1.06 (written by random/random)
          Run by Abbassi at 2010-02-01 14:44:00
          Microsoft Windows XP Édition familiale Service Pack 3
          System drive C: has 42 GB (28%) free of 149 GB
          Total RAM: 1023 MB (14% free)

          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 14:44:39, on 01/02/2010
          Platform: Windows XP SP3 (WinNT 5.01.2600)
          MSIE: Internet Explorer v8.00 (8.00.6001.18702)
          Boot mode: Normal

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\Ati2evxx.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\Ati2evxx.exe
          C:\WINDOWS\Explorer.EXE
          C:\WINDOWS\system32\ZoneLabs\vsmon.exe
          C:\WINDOWS\system32\spoolsv.exe
          C:\Program Files\Avira\AntiVir Desktop\sched.exe
          C:\Program Files\Avira\AntiVir Desktop\avguard.exe
          C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
          C:\Program Files\Bonjour\mDNSResponder.exe
          C:\Program Files\Java\jre6\bin\jqs.exe
          C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
          C:\WINDOWS\SOUNDMAN.EXE
          C:\apps\ABoard\ABoard.exe
          C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
          C:\apps\ABoard\AOSD.exe
          C:\WINDOWS\System32\svchost.exe
          C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
          C:\WINDOWS\wanmpsvc.exe
          C:\Program Files\Winsudate\gibsvc.exe
          C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
          C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
          C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
          C:\Program Files\QuickTime\QTTask.exe
          C:\Program Files\iTunes\iTunesHelper.exe
          C:\WINDOWS\system32\ctfmon.exe
          C:\Program Files\Microsoft ActiveSync\wcescomm.exe
          C:\Program Files\Messenger\msmsgs.exe
          C:\PROGRA~1\MICROS~4\rapimgr.exe
          C:\Program Files\SAGEM WiFi manager\WLANUTL.exe
          C:\WINDOWS\System32\wbem\wmiapsrv.exe
          C:\Program Files\iPod\bin\iPodService.exe
          C:\WINDOWS\system32\wuauclt.exe
          C:\Program Files\Mozilla Firefox\firefox.exe
          C:\Program Files\Windows Live\Messenger\msnmsgr.exe
          C:\Program Files\Windows Live\Contacts\wlcomm.exe
          C:\WINDOWS\System32\svchost.exe
          C:\Program Files\Internet Explorer\IEXPLORE.EXE
          C:\Program Files\Windows Live\Toolbar\wltuser.exe
          C:\Program Files\Internet Explorer\IEXPLORE.EXE
          C:\Program Files\Windows Media Player\wmplayer.exe
          C:\Documents and Settings\Abbassi\Bureau\RSIT.exe
          C:\Program Files\trend micro\Abbassi.exe

          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.hugedomains.com/domain_profile.cfm?d=wibeez&e=com
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
          R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
          O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
          O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
          O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
          O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
          O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
          O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
          O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
          O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
          O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
          O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
          O3 - Toolbar: (no name) - {66886C4D-B307-4ECA-A228-52CA9B9851A4} - (no file)
          O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
          O4 - HKLM\..\Run: [ACTIVBOARD] c:\apps\ABoard\ABoard.exe
          O4 - HKLM\..\Run: [ATIPTA] C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
          O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
          O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
          O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
          O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
          O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
          O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
          O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
          O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|DEFAULT=cnx|PARAM=
          O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
          O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
          O4 - HKCU\..\Run: [WinUsr] C:\Program Files\Winsudate\gibusr.exe
          O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
          O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
          O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
          O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
          O4 - Global Startup: Utilitaire réseau pour SAGEM Wi-Fi 11g USB adapter.lnk = ?
          O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
          O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
          O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
          O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
          O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
          O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
          O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
          O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\fr.htm
          O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
          O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
          O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
          O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
          O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://download.divx.com/webplayer/stage6/windows/AutoDLDivXWebPlayerInstaller.cab
          O16 - DPF: {80B626D6-BC34-4BCF-B5A1-7149E4FD9CFA} (UnoCtrl Class) - http://zone.msn.com/bingame/zpagames/GAME_UNO1.cab60096.cab
          O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
          O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZPAFramework.cab102118.cab
          O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
          O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
          O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab
          O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
          O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
          O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
          O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
          O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
          O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
          O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
          O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
          O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
          O23 - Service: Virtual CD v4 Security service (SDK - Version) (VCSSecS) - H+H Software GmbH - C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
          O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
          O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
          O23 - Service: Gestionnaire de mise à jour Winsudate (WinSvc) - Unknown owner - C:\Program Files\Winsudate\gibsvc.exe
          0
          1. voici le rapport info:

            info.txt logfile of random's system information tool 1.06 2010-02-01 11:24:12

            ======Uninstall list======

            -->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{09B44E78-A988-4BC0-962F-63ECD3333708} /l1036
            -->C:\Program Files\Fichiers communs\aolshare\Aolunins_fr.exe
            -->C:\Program Files\Fichiers communs\Real\Update_OB\rnuninst.exe RealNetworks|RealPlayer|6.0
            -->C:\Program Files\Fichiers communs\Real\Update_OB\rnuninst.exe RealNetworks|RealPlayer|6.0
            -->C:\WINDOWS\IsUn040c.exe -fC:\WINDOWS\orun32.isu
            -->C:\WINDOWS\Modio\SLAMR2KO\Setup.exe /Remove
            -->C:\WINDOWS\System32\\MSIEXEC.EXE /x {9541FED0-327F-4df0-8B96-EF57EF622F19}
            -->C:\WINDOWS\unvise32qt.exe C:\WINDOWS\System32\QuickTime\Uninstall.log
            -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{0BEDBD4E-2D34-47B5-9973-57E62B29307C}\setup.exe"
            -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2637C347-9DAD-11D6-9EA2-00055D0CA761}\Setup.EXE" -uninstall
            -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B7A0CE06-068E-11D6-97FD-0050BACBF861}\SETUP.EXE" -uninstall
            -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
            Adobe Flash Player 10 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
            Adobe Flash Player 10 Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
            Adobe Reader 9.1.3 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A91000000001}
            Apple Application Support-->MsiExec.exe /I{3FA365DF-2D68-45ED-8F83-8C8A33E65143}
            Apple Mobile Device Support-->MsiExec.exe /I{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}
            Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
            Archiveur WinRAR-->C:\Program Files\WinRAR\uninstall.exe
            Ask Toolbar-->"C:\Program Files\AskBarDis\unins000.exe"
            Assistant de connexion Windows Live-->MsiExec.exe /I{D3116CC7-24DC-4CA3-9CE1-23FED836E9F2}
            ATI - Software Uninstall Utility-->C:\Program Files\ATI Technologies\UninstallAll\AtiCimUn.exe
            ATI Display Driver-->rundll32 C:\WINDOWS\system32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
            Avira AntiVir Personal - Free Antivirus-->C:\Program Files\Avira\AntiVir Desktop\setup.exe /REMOVE
            AviSynth 2.5-->"C:\Program Files\AviSynth 2.5\Uninstall.exe"
            Bonjour-->MsiExec.exe /I{07287123-B8AC-41CE-8346-3D777245C35B}
            CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
            Correctif pour Lecteur Windows Media 11 (KB939683)-->"C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
            Correctif pour Windows Internet Explorer 7 (KB947864)-->"C:\WINDOWS\ie7updates\KB947864-IE7\spuninst\spuninst.exe"
            Correctif pour Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
            Correctif pour Windows XP (KB961118)-->"C:\WINDOWS\$NtUninstallKB961118$\spuninst\spuninst.exe"
            Correctif pour Windows XP (KB970653-v3)-->"C:\WINDOWS\$NtUninstallKB970653-v3$\spuninst\spuninst.exe"
            Correctif pour Windows XP (KB976098-v2)-->"C:\WINDOWS\$NtUninstallKB976098-v2$\spuninst\spuninst.exe"
            DivX Content Uploader-->C:\Program Files\DivX\DivXContentUploaderUninstall.exe /CUPLOADER
            Full Tilt Poker-->"C:\Program Files\InstallShield Installation Information\{D4C9692E-4EFA-4DA0-8B7F-9439466D9E31}\setup.exe" -runfromtemp -l0x040c -removeonly
            Galerie de photos Windows Live-->MsiExec.exe /X{B131E59D-202C-43C6-84C9-68F0C37541F1}
            HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
            Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
            Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
            Hotfix for Windows Media Format 11 SDK (KB929399)-->"C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
            Installation Windows Live-->C:\Program Files\Windows Live\Installer\wlarp.exe
            Installation Windows Live-->MsiExec.exe /I{46ABBC54-1872-4AA3-95E2-F2C063A63F31}
            iTunes-->MsiExec.exe /I{A6FDF86A-F541-4E7B-AEA0-8849A2A700D5}
            Java(TM) 6 Update 11-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216011FF}
            Junk Mail filter update-->MsiExec.exe /I{E2DFE069-083E-4631-9B6C-43C48E991DE5}
            Lecteur Windows Media 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
            Livebox-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FC7DDAAE-7F2B-4270-9BFD-5A130B667E9E}\Setup.exe" -l0x40c
            Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
            Manuel de l'appareil Windows Mobile®-->C:\Program Files\Windows Mobile Device Handbook\Windows Mobile Device Handbook\Bin\DHUninstall.exe
            Microsoft .NET Framework 1.1 Security Update (KB953297)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M953297\M953297Uninstall.msp"
            Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
            Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
            Microsoft .NET Framework 2.0 Service Pack 2-->MsiExec.exe /I{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}
            Microsoft .NET Framework 3.0 Service Pack 2-->MsiExec.exe /I{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}
            Microsoft .NET Framework 3.5 SP1-->C:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
            Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
            Microsoft ActiveSync-->MsiExec.exe /I{99052DB7-9592-4522-A558-5417BBAD48EE}
            Microsoft Choice Guard-->MsiExec.exe /X{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}
            Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
            Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
            Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
            Microsoft Office Live Add-in 1.3-->MsiExec.exe /I{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}
            Microsoft Office PowerPoint Viewer 2003-->MsiExec.exe /X{90AF040C-6000-11D3-8CFE-0150048383C9}
            Microsoft Search Enhancement Pack-->MsiExec.exe /X{4CBA3D4C-8F51-4D60-B27E-F6B641C571E7}
            Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
            Microsoft SQL Server 2005 Compact Edition [ENU]-->MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
            Microsoft Sync Framework Runtime Native v1.0 (x86)-->MsiExec.exe /I{8A74E887-8F0F-4017-AF53-CBA42211AAA5}
            Microsoft Sync Framework Services Native v1.0 (x86)-->MsiExec.exe /I{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}
            Microsoft User-Mode Driver Framework Feature Pack 1.0-->"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
            Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148-->MsiExec.exe /X{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}
            Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17-->MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475}
            Microsoft Word 2002-->MsiExec.exe /I{911B040C-6000-11D3-8CFE-0050048383C9}
            Mise à jour critique pour Lecteur Windows Media 11 (KB959772)-->"C:\WINDOWS\$NtUninstallKB959772_WM11$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Lecteur Windows Media (KB954155)-->"C:\WINDOWS\$NtUninstallKB954155_WM9$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Lecteur Windows Media (KB968816)-->"C:\WINDOWS\$NtUninstallKB968816_WM9$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Lecteur Windows Media (KB973540)-->"C:\WINDOWS\$NtUninstallKB973540_WM9$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Lecteur Windows Media 10 (KB917734)-->"C:\WINDOWS\$NtUninstallKB917734_WMP10$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Lecteur Windows Media 11 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Lecteur Windows Media 11 (KB954154)-->"C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Step by Step Interactive Training (KB898458)-->"C:\WINDOWS\$NtUninstallKB898458$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Step by Step Interactive Training (KB923723)-->"C:\WINDOWS\$NtUninstallKB923723$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows Internet Explorer 7 (KB928090)-->"C:\WINDOWS\ie7updates\KB928090-IE7\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows Internet Explorer 7 (KB929969)-->"C:\WINDOWS\ie7updates\KB929969\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows Internet Explorer 7 (KB931768)-->"C:\WINDOWS\ie7updates\KB931768-IE7\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows Internet Explorer 7 (KB933566)-->"C:\WINDOWS\ie7updates\KB933566-IE7\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows Internet Explorer 7 (KB937143)-->"C:\WINDOWS\ie7updates\KB937143-IE7\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows Internet Explorer 7 (KB938127)-->"C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows Internet Explorer 7 (KB939653)-->"C:\WINDOWS\ie7updates\KB939653-IE7\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows Internet Explorer 7 (KB942615)-->"C:\WINDOWS\ie7updates\KB942615-IE7\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows Internet Explorer 7 (KB944533)-->"C:\WINDOWS\ie7updates\KB944533-IE7\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows Internet Explorer 7 (KB950759)-->"C:\WINDOWS\ie7updates\KB950759-IE7\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows Internet Explorer 7 (KB953838)-->"C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows Internet Explorer 7 (KB956390)-->"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows Internet Explorer 7 (KB961260)-->"C:\WINDOWS\ie7updates\KB961260-IE7\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows Internet Explorer 7 (KB963027)-->"C:\WINDOWS\ie7updates\KB963027-IE7\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows Internet Explorer 7 (KB969897)-->"C:\WINDOWS\ie7updates\KB969897-IE7\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows Internet Explorer 8 (KB969897)-->"C:\WINDOWS\ie8updates\KB969897-IE8\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows Internet Explorer 8 (KB971961)-->"C:\WINDOWS\ie8updates\KB971961-IE8\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows Internet Explorer 8 (KB972260)-->"C:\WINDOWS\ie8updates\KB972260-IE8\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows Internet Explorer 8 (KB974455)-->"C:\WINDOWS\ie8updates\KB974455-IE8\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows Internet Explorer 8 (KB976325)-->"C:\WINDOWS\ie8updates\KB976325-IE8\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows Internet Explorer 8 (KB978207)-->"C:\WINDOWS\ie8updates\KB978207-IE8\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB913433)-->C:\WINDOWS\system32\MacroMed\Flash\genuinst.exe C:\WINDOWS\system32\MacroMed\Flash\KB913433.inf
            Mise à jour de sécurité pour Windows XP (KB923561)-->"C:\WINDOWS\$NtUninstallKB923561$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB938464-v2)-->"C:\WINDOWS\$NtUninstallKB938464-v2$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB950760)-->"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB951376)-->"C:\WINDOWS\$NtUninstallKB951376$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB952004)-->"C:\WINDOWS\$NtUninstallKB952004$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB953839)-->"C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB954211)-->"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB954459)-->"C:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB954600)-->"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB956391)-->"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB956572)-->"C:\WINDOWS\$NtUninstallKB956572$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB956744)-->"C:\WINDOWS\$NtUninstallKB956744$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB956841)-->"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB956844)-->"C:\WINDOWS\$NtUninstallKB956844$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB957095)-->"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB958687)-->"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB958690)-->"C:\WINDOWS\$NtUninstallKB958690$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB958869)-->"C:\WINDOWS\$NtUninstallKB958869$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB959426)-->"C:\WINDOWS\$NtUninstallKB959426$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB960225)-->"C:\WINDOWS\$NtUninstallKB960225$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB960715)-->"C:\WINDOWS\$NtUninstallKB960715$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB960803)-->"C:\WINDOWS\$NtUninstallKB960803$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB960859)-->"C:\WINDOWS\$NtUninstallKB960859$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB961371)-->"C:\WINDOWS\$NtUninstallKB961371$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB961373)-->"C:\WINDOWS\$NtUninstallKB961373$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB961501)-->"C:\WINDOWS\$NtUninstallKB961501$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB968537)-->"C:\WINDOWS\$NtUninstallKB968537$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB969059)-->"C:\WINDOWS\$NtUninstallKB969059$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB969898)-->"C:\WINDOWS\$NtUninstallKB969898$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB969947)-->"C:\WINDOWS\$NtUninstallKB969947$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB970238)-->"C:\WINDOWS\$NtUninstallKB970238$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB970430)-->"C:\WINDOWS\$NtUninstallKB970430$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB971486)-->"C:\WINDOWS\$NtUninstallKB971486$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB971557)-->"C:\WINDOWS\$NtUninstallKB971557$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB971633)-->"C:\WINDOWS\$NtUninstallKB971633$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB971657)-->"C:\WINDOWS\$NtUninstallKB971657$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB972270)-->"C:\WINDOWS\$NtUninstallKB972270$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB973346)-->"C:\WINDOWS\$NtUninstallKB973346$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB973507)-->"C:\WINDOWS\$NtUninstallKB973507$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB973525)-->"C:\WINDOWS\$NtUninstallKB973525$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB973869)-->"C:\WINDOWS\$NtUninstallKB973869$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB973904)-->"C:\WINDOWS\$NtUninstallKB973904$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB974112)-->"C:\WINDOWS\$NtUninstallKB974112$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB974318)-->"C:\WINDOWS\$NtUninstallKB974318$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB974392)-->"C:\WINDOWS\$NtUninstallKB974392$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB974571)-->"C:\WINDOWS\$NtUninstallKB974571$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB975025)-->"C:\WINDOWS\$NtUninstallKB975025$\spuninst\spuninst.exe"
            Mise à jour de sécurité pour Windows XP (KB975467)-->"C:\WINDOWS\$NtUninstallKB975467$\spuninst\spuninst.exe"
            Mise à jour pour Windows Internet Explorer 8 (KB971180)-->"C:\WINDOWS\ie8updates\KB971180-IE8\spuninst\spuninst.exe"
            Mise à jour pour Windows Internet Explorer 8 (KB976749)-->"C:\WINDOWS\ie8updates\KB976749-IE8\spuninst\spuninst.exe"
            Mise à jour pour Windows XP (KB951072-v2)-->"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
            Mise à jour pour Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
            Mise à jour pour Windows XP (KB955759)-->"C:\WINDOWS\$NtUninstallKB955759$\spuninst\spuninst.exe"
            Mise à jour pour Windows XP (KB961503)-->"C:\WINDOWS\$NtUninstallKB961503$\spuninst\spuninst.exe"
            Mise à jour pour Windows XP (KB967715)-->"C:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe"
            Mise à jour pour Windows XP (KB968389)-->"C:\WINDOWS\$NtUninstallKB968389$\spuninst\spuninst.exe"
            Mise à jour pour Windows XP (KB971737)-->"C:\WINDOWS\$NtUninstallKB971737$\spuninst\spuninst.exe"
            Mise à jour pour Windows XP (KB973687)-->"C:\WINDOWS\$NtUninstallKB973687$\spuninst\spuninst.exe"
            Mise à jour pour Windows XP (KB973815)-->"C:\WINDOWS\$NtUninstallKB973815$\spuninst\spuninst.exe"
            Mozilla Firefox (3.5.7)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
            MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
            MSXML 4.0 SP2 (KB927978)-->MsiExec.exe /I{37477865-A3F1-4772-AD43-AAFC6BCFF99F}
            MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
            MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
            MSXML 4.0 SP2 (KB973688)-->MsiExec.exe /I{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
            Neuf - Kit de connexion-->C:\Program Files\Neuf\Kit\uninstall.exe
            Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
            PhotoFiltre-->"C:\Program Files\PhotoFiltre\Uninst.exe"
            QuickTime-->MsiExec.exe /I{1451DE6B-ABE1-4F62-BE9A-B363A17588A2}
            S3 S3Display-->vtuninst.exe -reg 5 'HKLM\Software\S3\VT\S3Uninst\S3Display'
            S3 S3Gamma2-->vtuninst.exe -reg 5 'HKLM\Software\S3\VT\S3Uninst\S3Gamma2'
            S3 S3Info2-->vtuninst.exe -reg 5 'HKLM\Software\S3\VT\S3Uninst\S3Info2'
            S3 S3Overlay-->vtuninst.exe -reg 5 'HKLM\Software\S3\VT\S3Uninst\S3Overlay'
            Sagem Wi-Fi 11g USB adapter (driver)-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2ED60C17-4568-4CD5-830A-03C4688B09A1}\setup.exe" -l0x40c
            Sagem Wi-Fi 11g USB adapter (utility)-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{AAFD22B6-A6C7-4134-AF4E-080BCBCD3493}\setup.exe" -l0x40c
            Segoe UI-->MsiExec.exe /I{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}
            Skype 2.5-->"C:\Program Files\Skype\Phone\unins000.exe"
            Sonic RecordNow!-->MsiExec.exe /I{9541FED0-327F-4DF0-8B96-EF57EF622F19}
            Spelling Dictionaries Support For Adobe Reader 9-->MsiExec.exe /I{AC76BA86-7AD7-5464-3428-900000000004}
            Spybot - Search & Destroy 1.4-->"C:\Program Files\Spybot - Search & Destroy\unins000.exe"
            Spybot - Search & Destroy-->"C:\Program Files\Spybot - Search & Destroy\unins001.exe"
            TeamSpeak 2 RC2-->"C:\Program Files\Teamspeak2_RC2\unins000.exe"
            Uninstall 1.0.0.1-->"C:\Program Files\Fichiers communs\DVDVideoSoft\unins000.exe"
            Update for Microsoft .NET Framework 3.5 SP1 (KB963707)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {B2AE9C82-DC7B-3641-BFC8-87275C4F3607} /qb+ REBOOTPROMPT=""
            VC 9.0 Runtime-->MsiExec.exe /I{02E89EFC-7B07-4D5A-AA03-9EC0902914EE}
            VideoLAN VLC media player 0.8.6c-->C:\Program Files\VideoLAN\VLC\uninstall.exe
            Viewpoint Media Player-->C:\Program Files\Viewpoint\Viewpoint Experience Technology\mtsAxInstaller.exe /u
            Windows Internet Explorer 8-->"C:\WINDOWS\ie8\spuninst\spuninst.exe"
            Windows Live Call-->MsiExec.exe /I{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}
            Windows Live Communications Platform-->MsiExec.exe /I{3B4E636E-9D65-4D67-BA61-189800823F52}
            Windows Live Contrôle parental-->MsiExec.exe /X{D5D81435-B8DE-4CAF-867F-7998F2B92CFC}
            Windows Live FolderShare-->MsiExec.exe /X{2075CB0A-D26F-4DAA-B424-5079296B43BA}
            Windows Live Mail-->MsiExec.exe /I{5DD76286-9BE7-4894-A990-E905E91AC818}
            Windows Live Messenger-->MsiExec.exe /X{770F1BEC-2871-4E70-B837-FB8525FFA3B1}
            Windows Live Toolbar-->MsiExec.exe /X{F7D27C70-90F5-49B9-B188-0A133C0CE353}
            Windows Live Writer-->MsiExec.exe /X{4634B21A-CC07-4396-890C-2B8168661FEA}
            Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
            Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
            Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
            Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
            ZoneAlarm-->C:\Program Files\Zone Labs\ZoneAlarm\zauninst.exe

            ======Hosts File======

            127.0.0.1 www.007guard.com
            127.0.0.1 007guard.com
            127.0.0.1 008i.com
            127.0.0.1 www.008k.com
            127.0.0.1 008k.com
            127.0.0.1 www.00hq.com
            127.0.0.1 00hq.com
            127.0.0.1 010402.com
            127.0.0.1 www.032439.com
            127.0.0.1 032439.com

            ======Security center information======

            AV: AntiVir Desktop
            FW: ZoneAlarm Firewall

            ======System event log======

            Computer Name: SN401381390009
            Event Code: 26
            Message: Application popup :  : Machine Check:

            Record Number: 2035
            Source Name: Application Popup
            Time Written: 20100125144736.000000+060
            Event Type: Informations
            User:

            Computer Name: SN401381390009
            Event Code: 10
            Message: Ce lecteur ne semble pas prendre en charge la lecture audio numérique.

            Record Number: 2034
            Source Name: redbook
            Time Written: 20100125144736.000000+060
            Event Type: Informations
            User:

            Computer Name: SN401381390009
            Event Code: 10
            Message: Ce lecteur ne semble pas prendre en charge la lecture audio numérique.

            Record Number: 2033
            Source Name: redbook
            Time Written: 20100125144736.000000+060
            Event Type: Informations
            User:

            Computer Name: SN401381390009
            Event Code: 10
            Message: Ce lecteur ne semble pas prendre en charge la lecture audio numérique.

            Record Number: 2032
            Source Name: redbook
            Time Written: 20100125144736.000000+060
            Event Type: Informations
            User:

            Computer Name: SN401381390009
            Event Code: 6005
            Message: Le service d'Enregistrement d'événement a démarré.

            Record Number: 2031
            Source Name: EventLog
            Time Written: 20100125144727.000000+060
            Event Type: Informations
            User:

            =====Application event log=====

            Computer Name: SN401381390009
            Event Code: 0
            Message: Service started

            Record Number: 23415
            Source Name: SeaPort
            Time Written: 20091110154602.000000+060
            Event Type: Informations
            User:

            Computer Name: SN401381390009
            Event Code: 8
            Message: Échec de la récupération de la mise à jour automatique du numéro de séquence de la liste racine tierce partie à partir de : <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt> avec l'erreur : Cette opération s'est terminée car le délai d'attente a expiré.

            Record Number: 23414
            Source Name: crypt32
            Time Written: 20091110154602.000000+060
            Event Type: erreur
            User:

            Computer Name: SN401381390009
            Event Code: 105
            Message: The service was started.

            Record Number: 23413
            Source Name: ATI Smart
            Time Written: 20091110154551.000000+060
            Event Type: Informations
            User:

            Computer Name: SN401381390009
            Event Code: 0
            Message:
            Record Number: 23412
            Source Name: NOSSO(R)
            Time Written: 20091109193734.000000+060
            Event Type: erreur
            User:

            Computer Name: SN401381390009
            Event Code: 2002
            Message: Le service EAPOL a été arrêté correctement.

            Record Number: 23411
            Source Name: EAPOL
            Time Written: 20091109133610.000000+060
            Event Type: Informations
            User:

            ======Environment variables======

            "ComSpec"=%SystemRoot%\system32\cmd.exe
            "Path"=%systemroot%\system32;%systemroot%;%systemroot%\system32\wbem;C:\ATI Technologies\ATI Control Panel;C:\PROGRA~1\FICHIE~1\TVNAVI~1;C:\Program Files\Fichiers communs\Teleca Shared;C:\Program Files\QuickTime\QTSystem\
            "windir"=%SystemRoot%
            "OS"=Windows_NT
            "PROCESSOR_ARCHITECTURE"=x86
            "PROCESSOR_LEVEL"=6
            "PROCESSOR_IDENTIFIER"=x86 Family 6 Model 8 Stepping 1, AuthenticAMD
            "PROCESSOR_REVISION"=0801
            "NUMBER_OF_PROCESSORS"=1
            "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
            "TEMP"=%SystemRoot%\TEMP
            "TMP"=%SystemRoot%\TEMP
            "CLASSPATH"=.;"i\QTJava.zip";C:\Program Files\Java\jre6\lib\ext\QTJava.zip
            "QTJAVA"=C:\Program Files\Java\jre6\lib\ext\QTJava.zip
            "FP_NO_HOST_CHECK"=NO
            "tvdumpflags"=8

            -----------------EOF-----------------
            0
            1. Contributeur sécurité
              ok

              plusieurs infections

              à faire dans cet ordre et poster les rapports au fur et à mesure

              1)
              Téléchargez USBFIX de El Desaparecido, C_xx

              http://pagesperso-orange.fr/NosTools/Chiquitine29/UsbFix.exe
              ou
              https://www.ionos.fr/?affiliate_id=77097

              /!\ Utilisateur de vista et windows 7 :
              ne pas oublier de désactiver Le contrôle des comptes utilisateurs
              https://www.commentcamarche.net/faq/8343-vista-desactiver-l-uac

              /!\ Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptible d'avoir été infectées sans les ouvrir

              • Double clic sur le raccourci UsbFix présent sur le bureau .

              • Choisir l'option2 suppression
              (d’autres options disponibles, voir le tutoriel).
              • Laissez travailler l'outil.
              Le menu démarrer et les icônes vont disparaître.. c'est normal.

              Si un message te demande de redémarrer l'ordinateur fais le ...

              ● Au redémarrage, le fix se relance... laisses l'opération s'effectuer.

              ● Le bloc note s'ouvre avec un rapport, envoies le dans la prochaine réponse

              • Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque. ( C:\UsbFix.txt )

              ( CTRL+A Pour tout sélectionner , CTRL+C pour copier et CTRL+V pour coller )

              • Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
              Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
              Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.

              • Tuto : http://pagesperso-orange.fr/NosTools/usbfix.html

              UsbFix peut te demander d'uploader un dossier compressé à cette adresse : https://www.ionos.fr/?affiliate_id=77097

              Il est enregistré sur ton bureau.

              Merci de l'envoyer à l'adresse indiquée afin d'aider l'auteur de UsbFix dans ses recherches.

              .....................

              2)
              Téléchargez Toolbar-S&D ( Merci à Eric_71, Angel Dark, Sham_Rock et XmichouX ) sur le Bureau

              https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/ToolBarSD.exe?attachauth=ANoY7cpVobGk5bHnxrhQ4yaoEUDJvOYNnEGyYjgqHZz5GqZLfutR3fMFPlsC3-CGIilfupPAguYATNyua3csodN_frdMK8sSzUpit10Yac-QJCOkMqJKkbdKcP6ySs8trWPgoNVIq4TGGWCe6o0txXQv-ZueJF9vZzw3RXsGwFYIqN2lvF2LPdQzS8mE1d5kWOVOz6EMzQuE5-lClSJM869uq3oc7-t7yg%3D%3D&attredirects=3

              Lancez l'installation du programme en exécutant le fichier téléchargé.
              Double-cliquez maintenant sur le raccourci de Toolbar-S&D.
              Sélectionnez la langue souhaitée en tapant la lettre de ton choix puis en validant avec la touche Entrée.
              Choisir maintenant l'option 2 suppression
              Patientez jusqu'à la fin de la recherche.
              Postez le rapport généré. (C:\TB.txt)

              Tuto: https://sites.google.com/site/toolbarsd/aideenimages

              ........................

              3)

              Téléchargez MalwareByte's Anti-Malware

              http://www.malwarebytes.org/mbam/program/mbam-setup.exe

              . Enregistres le sur le bureau
              . Double cliques sur le fichier téléchargé pour lancer le processus d'installation.
              . Dans l'onglet "mise à jour", cliques sur le bouton Recherche de mise à jour
              . Si le pare-feu demande l'autorisation de se connecter pour malwarebytes, accepte
              . Une fois la mise à jour terminé
              . Rend-toi dans l'onglet, Recherche
              . Sélectionnes Exécuter un examen complet (examen assez long)
              . Cliques sur Rechercher
              . Le scan démarre.
              . A la fin de l'analyse, un message s'affiche : L'examen s'est terminé normalement. Cliquez sur 'Afficher les résultats' pour afficher tous les objets trouvés.
              . Cliques sur Ok pour poursuivre.
              . Si des malwares ont été détectés, clique sur Afficher les résultats
              . Sélectionnes tout (ou laisses cochés) et cliques sur Supprimer la sélection Malwarebytes va détruire les fichiers et clés de registre et en mettre une copie dans la quarantaine.
              . Malwarebytes va ouvrir le bloc-notes et y copier le rapport d'analyse.
              . Rends toi dans l'onglet rapport/log
              . Tu cliques dessus pour l'afficher, une fois affiché
              . Tu cliques sur edition en haut du boc notes, et puis sur sélectionner tous
              . Tu recliques sur edition et puis sur copier et tu reviens sur le forum et dans ta réponse
              . tu cliques droit dans le cadre de la reponse et coller

              Si tu as besoin d'aide regarde ces tutoriels :
              Aide: https://www.malekal.com/tutoriel-malwarebyte-anti-malware/
              http://www.infos-du-net.com/forum/278396-11-tuto-malwarebytes-anti-malware-mbam

              0
              1. voici le rapport usbfix.txt

                ############################## | UsbFix V6.084 |

                User : Abbassi (Administrateurs) # SN401381390009
                Update on 01/02/2010 by El Desaparecido , C_XX & Chimay8
                Start at: 15:21:07 | 01/02/2010
                Website : http://pagesperso-orange.fr/NosTools/index.html
                Contact : FindyKill.Contact@gmail.com

                AMD Athlon(tm) XP 2700+
                Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
                Internet Explorer 8.0.6001.18702
                Windows Firewall Status : Enabled
                AV : AntiVir Desktop 9.0.1.32 [ Enabled | Updated ]
                FW : ZoneAlarm Firewall[ Enabled ]8.0.298.000

                A:\ -> Lecteur de disquettes 3 ½ pouces
                C:\ -> Disque fixe local # 145,04 Go (40,66 Go free) [HDD] # NTFS
                D:\ -> Disque CD-ROM
                E:\ -> Disque CD-ROM
                I:\ -> Disque amovible
                J:\ -> Disque amovible

                ############################## | Processus actifs |

                C:\WINDOWS\System32\smss.exe
                C:\WINDOWS\system32\csrss.exe
                C:\WINDOWS\system32\winlogon.exe
                C:\WINDOWS\system32\services.exe
                C:\WINDOWS\system32\lsass.exe
                C:\WINDOWS\system32\Ati2evxx.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\System32\svchost.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\System32\svchost.exe
                C:\WINDOWS\system32\Ati2evxx.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\Explorer.EXE
                C:\WINDOWS\system32\ZoneLabs\vsmon.exe
                C:\WINDOWS\system32\spoolsv.exe
                C:\Program Files\Avira\AntiVir Desktop\sched.exe
                C:\WINDOWS\System32\svchost.exe
                C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                C:\Program Files\Bonjour\mDNSResponder.exe
                C:\Program Files\Java\jre6\bin\jqs.exe
                C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
                C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                C:\WINDOWS\system32\slserv.exe
                C:\WINDOWS\System32\svchost.exe
                C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
                C:\WINDOWS\wanmpsvc.exe
                C:\Program Files\Winsudate\gibsvc.exe
                C:\WINDOWS\system32\wuauclt.exe
                C:\WINDOWS\system32\wbem\wmiprvse.exe
                C:\WINDOWS\system32\wbem\wmiprvse.exe
                C:\WINDOWS\System32\alg.exe

                ################## | Elements infectieux |

                Supprimé ! C:\GETBOOTD.BAT
                Supprimé ! C:\Recycler\S-1-5-21-3046840070-1875883765-231225164-8348\rundll32.exe
                Supprimé ! C:\Recycler\S-1-5-21-3046840070-1875883765-231225164-8348\Desktop.ini
                Supprimé ! C:\Recycler\S-1-5-21-3046840070-1875883765-231225164-8348
                Supprimé ! C:\Recycler\S-1-5-18
                Supprimé ! C:\Recycler\S-1-5-21-482117970-2289595660-1097813078-1007

                ################## | Registre |

                Supprimé ! [HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NoDrives"
                Supprimé ! [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NoDrives"

                ################## | Mountpoints2 |

                Supprimé ! HKCU\...\Explorer\MountPoints2\{211a69ec-3343-11dd-954a-00038a000015}\Shell\AutoRun\Command
                Supprimé ! HKCU\...\Explorer\MountPoints2\{319ce751-60f6-11de-97ad-00038a000015}\Shell\AutoRun\Command
                Supprimé ! HKCU\...\Explorer\MountPoints2\{b53bdca2-9c10-11dc-9454-00038a000015}\Shell\AutoRun\Command
                Supprimé ! HKCU\...\Explorer\MountPoints2\{d1bf4046-94a0-11de-9820-00038a000015}\Shell\AutoRun\Command
                Supprimé ! HKCU\...\Explorer\MountPoints2\{e3c06d06-3bfb-11de-9758-00038a000015}\Shell\AutoRun\Command

                ################## | Listing des fichiers présent |

                [05/01/2010 00:46|--a------|33958] C:\ASLog.txt
                [11/11/2003 02:06|-rahs----|193] C:\BOOT.BAK
                [23/07/2006 13:34|-rahs----|291] C:\BOOT.INI
                [30/08/2002 13:00|-rahs----|4952] C:\Bootfont.bin
                [30/08/2002 13:00|-rahs----|249136] C:\cmldr
                [09/12/2008 18:14|--a------|2669858] C:\DSCF1024.JPG
                [11/11/2003 02:55|--a------|6238] C:\DWNLOG.TXT
                [15/02/2007 21:22|--a------|446067] C:\ExtractLog.txt
                [09/03/2000 09:06|--a------|28680] C:\FLIPART.MSNFix
                [29/08/2002 15:03|--a------|6384] C:\GETDRIVE.MSNFix
                [12/08/2008 11:04|--a------|752] C:\HighLogging.log
                [04/07/2006 19:02|-rahs----|0] C:\IO.SYS
                [11/11/2003 02:12|--ah-----|456] C:\IPH.PH
                [30/12/2008 02:38|--a------|6018] C:\JavaRa.log
                [29/12/2008 19:35|--a------|15244] C:\lxdj.log
                [04/07/2006 19:02|-rahs----|0] C:\MSDOS.SYS
                [04/07/2006 18:45|-rahs----|47564] C:\NTDETECT.COM
                [31/12/2008 00:40|-rahs----|252240] C:\ntldr
                [?|?|?] C:\pagefile.sys
                [11/11/2003 02:02|--a------|20] C:\realquas.TAG
                [29/09/2006 14:05|--a------|90] C:\Setup.log
                [30/12/2008 23:04|--a------|1782] C:\TCleaner.txt
                [01/02/2010 15:26|--a------|4472] C:\UsbFix.txt

                ################## | Vaccination |

                # C:\autorun.inf -> Dossier créé par UsbFix.
                0
                1. voici le rapport TB.txt

                  -----------\\ ToolBar S&D 1.2.9 XP/Vista

                  Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 3
                  X86-based PC ( Uniprocessor Free : AMD Athlon(tm) XP 2700+ )
                  BIOS : Phoenix - AwardBIOS v6.00PG
                  USER : Abbassi ( Administrator )
                  BOOT : Normal boot
                  Antivirus : AntiVir Desktop 9.0.1.32 (Activated)
                  Firewall : ZoneAlarm Firewall 8.0.298.000 (Activated)
                  A:\ (USB)
                  C:\ (Local Disk) - NTFS - Total:145 Go (Free:40 Go)
                  D:\ (CD or DVD)
                  E:\ (CD or DVD)
                  I:\ (USB)
                  J:\ (USB)

                  "C:\ToolBar SD" ( MAJ : 22-08-2009|18:42 )
                  Option : [2] ( 01/02/2010|15:40 )

                  -----------\\ SUPPRESSION

                  Supprime! - C:\Program Files\AskBarDis\bar
                  Supprime! - C:\Program Files\AskBarDis\unins00.exe
                  Supprime! - C:\Program Files\AskBarDis\unins000.dat
                  Supprime! - C:\Program Files\AskBarDis\unins000.exe
                  Supprime! - C:\Program Files\AskBarDis\zonealarm.ico
                  Supprime! - C:\Program Files\Multi_Media_France\INSTALL.LOG
                  Supprime! - C:\Program Files\AskBarDis
                  Supprime! - C:\Program Files\Multi_Media_France

                  -----------\\ Recherche de Fichiers / Dossiers ...

                  -----------\\ Extensions

                  (Abbassi) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar
                  (Abbassi) - {635abd67-4fe9-1b23-4f01-e679fa7484c1} => ytoolbar
                  (Abbassi) - {b9db16a4-6edc-47ec-a1f4-b86292ed211d} => dwhelper
                  (Abbassi) - {b9db16a4-6edc-47ec-a1f4-b86292ed211d} => dwhelper
                  (Abbassi) - {C2DCA7EB-22D2-4FD2-86A9-F99FCC8122BB} => fbstoolbar
                  (Abbassi) - {E9A1DEE0-C623-4439-8932-001E7D17607D} => ajtoolbar

                  -----------\\ [..\Internet Explorer\Main]

                  [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                  "Local Page"="C:\\WINDOWS\\system32\\blank.htm"
                  "Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
                  "Start Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
                  "Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"

                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
                  "Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
                  "Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
                  "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
                  "Local Page"="C:\\WINDOWS\\system32\\blank.htm"
                  "Start Page"="https://www.msn.com/fr-fr/"

                  --------------------\\ Recherche d'autres infections

                  C:\DOCUME~1\Abbassi\LOCALS~1\APPLIC~1\aifzg_nav.dat
                  C:\DOCUME~1\Abbassi\LOCALS~1\APPLIC~1\aifzg_navps.dat
                  C:\WINDOWS\System32\ygqeq.dat.bd.ren
                  C:\WINDOWS\System32\ygqeq_nav.dat.bd.ren
                  C:\WINDOWS\System32\ygqeq_navps.dat.bd.ren
                  C:\WINDOWS\System32\ygqeq_navup.dat.bd.ren
                  [b]==> EGDACCESS <==/b

                  --------------------\\ Cracks & Keygens ..

                  C:\DOCUME~1\Abbassi\Bureau\iphone\club\Eminem - Crack A Bottle [Feat Dr Dre & 50 Cent]lyrics.mp3
                  C:\DOCUME~1\Abbassi\Mes documents\divers\4757\Eminem - Crack A Bottle [Feat Dr Dre & 50 Cent]lyrics.mp3
                  C:\DOCUME~1\Abbassi\Mes documents\divers\cd clio\Eminem - Crack A Bottle [Feat Dr Dre & 50 Cent]lyrics.mp3
                  C:\DOCUME~1\Abbassi\Mes documents\divers\Cl‚ USB HaGeR\son de la mort\Eminem - Crack A Bottle [Feat Dr Dre & 50 Cent]lyrics.mp3
                  C:\DOCUME~1\Abbassi\Mes documents\DVDVideoSoft\FreeYouTubeToMP3Converter\Eminem - Crack A Bottle [Feat Dr Dre & 50 Cent]lyrics.mp3

                  1 - "C:\ToolBar SD\TB_1.txt" - 01/02/2010|15:42 - Option : [2]

                  -----------\\ Fin du rapport a 15:42:24,92
                  0
                  1. Contributeur sécurité
                    vu

                    attends avant de lancer MBAM

                    fais ceci avant

                    Infection Navipromo….Pour info :

                    Il s'installe via certains programmes, dont ceux-ci qu'il faut éviter à tout prix:
                    * Funky Emoticons
                    * go-astro
                    * Games Attack
                    * GoRecord
                    * HotTVPlayer / HotTVPlayer & Paris Hilton
                    * Live-Player
                    * MailSkinner
                    * Messenger Skinner
                    * Instant Access
                    * InternetGameBox
                    * Officiale Emule (Version d'Emule modifiée)
                    * Original Solitaire
                    * SuperSexPlayer
                    * Speed Downloading
                    * Sudoplanet
                    * Webmediaplayer

                    il faudrait télécharge navilog1 sur le bureau :
                    http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe

                    Certaines infections bloquent les téléchargements d' outils de désinfection utilisez ce lien alternatif:
                    http://ww38.toofiles.com/fr/oip/documents/exe/yop3.html

                    1°Double-clique sur navilog1.exe présent sur ton bureau
                    2°Sélectionnez la langue désirée dans le menu puis valide le choix par la touche « entrer »
                    3°Petit message d’avertissement, appuyez sur une touche pour passe à la suite
                    4°un nouveau avertissement, appuie sur une touche pour suivre
                    5°Vérification de l’installation de Navilog1 : si tout est bon, appuyez sur une touche pour continuer
                    6°Choisir option 1 : recherche/désinfection automatique
                    7°La recherche va se lancer automatiquement et peut durée quelques minutes, patientez
                    8°Une fois l’analyse terminé, fermez et enregistrez votre travail en cours, puis appuiez sur une touche pour que votre pc puisse démarrer
                    9°Au redémarrage du pc, Navilog va supprimer ce qu’il a trouvé, patientez quelques instants.

                    Un rapport est gèneré par l'outil. Il se trouve à cette emplacement :
                    XP : demarrer/poste de travail/c:/cleannavi.txt
                    0
                    1. voici le rapport cleannavi.txt

                      Fix Navipromo version 4.0.6 commencé le 01/02/2010 15:50:19,43

                      !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
                      !!! Postez ce rapport sur le forum pour le faire analyser !!!

                      Outil exécuté depuis C:\Program Files\navilog1

                      Mise à jour le 03.01.2010 à 11h00 par IL-MAFIOSO

                      Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 3
                      X86-based PC ( Uniprocessor Free : AMD Athlon(tm) XP 2700+ )
                      BIOS : Phoenix - AwardBIOS v6.00PG
                      USER : Abbassi ( Administrator )
                      BOOT : Normal boot

                      Antivirus : AntiVir Desktop 9.0.1.32 (Activated)
                      Firewall : ZoneAlarm Firewall 8.0.298.000 (Activated)

                      A:\ (USB)
                      C:\ (Local Disk) - NTFS - Total:145 Go (Free:40 Go)
                      D:\ (CD or DVD)
                      E:\ (CD or DVD)
                      I:\ (USB)
                      J:\ (USB)

                      Recherche executée en mode normal

                      Nettoyage exécuté au redémarrage de l'ordinateur

                      C:\WINDOWS\system32\jyqzcmm.dat supprimé !
                      C:\WINDOWS\system32\ygqeq.dat.bd.ren supprimé !
                      C:\WINDOWS\system32\ygqeq_nav.dat.bd.ren supprimé !
                      C:\WINDOWS\system32\ygqeq_navps.dat.bd.ren supprimé !
                      C:\WINDOWS\system32\ygqeq_navup.dat.bd.ren supprimé !
                      c:\docume~1\abbassi\locals~1\applic~1\aifzg_nav.dat supprimé !
                      c:\docume~1\abbassi\locals~1\applic~1\aifzg_navps.dat supprimé !

                      Nettoyage contenu C:\WINDOWS\Temp effectué !
                      Nettoyage contenu C:\Documents and Settings\Abbassi\locals~1\Temp effectué !

                      *** Sauvegarde du Registre vers dossier Safebackup ***

                      sauvegarde du Registre réalisée avec succès !

                      *** Nettoyage Registre ***

                      Nettoyage Registre Ok

                      Certificat OOO-Favorit supprimé !

                      *** Scan terminé 01/02/2010 15:54:35,06 ***
                      0
                      1. Contributeur sécurité
                        bien

                        ==> MBAM donc, c'est un peu plus long..
                        0
                        1. voici le dernier rapport

                          Malwarebytes' Anti-Malware 1.44
                          Version de la base de données: 3672
                          Windows 5.1.2600 Service Pack 3
                          Internet Explorer 8.0.6001.18702

                          01/02/2010 18:26:12
                          mbam-log-2010-02-01 (18-26-12).txt

                          Type de recherche: Examen complet (A:\|C:\|D:\|E:\|I:\|J:\|)
                          Eléments examinés: 214675
                          Temps écoulé: 2 hour(s), 5 minute(s), 51 second(s)

                          Processus mémoire infecté(s): 0
                          Module(s) mémoire infecté(s): 0
                          Clé(s) du Registre infectée(s): 0
                          Valeur(s) du Registre infectée(s): 1
                          Elément(s) de données du Registre infecté(s): 0
                          Dossier(s) infecté(s): 1
                          Fichier(s) infecté(s): 2

                          Processus mémoire infecté(s):
                          (Aucun élément nuisible détecté)

                          Module(s) mémoire infecté(s):
                          (Aucun élément nuisible détecté)

                          Clé(s) du Registre infectée(s):
                          (Aucun élément nuisible détecté)

                          Valeur(s) du Registre infectée(s):
                          HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\winusr (Adware.Gibmedia) -> Quarantined and deleted successfully.

                          Elément(s) de données du Registre infecté(s):
                          (Aucun élément nuisible détecté)

                          Dossier(s) infecté(s):
                          C:\Program Files\Winsudate (Adware.Gibmedia) -> Quarantined and deleted successfully.

                          Fichier(s) infecté(s):
                          C:\Program Files\Winsudate\gibupt.exe (Adware.Gibmedia) -> Quarantined and deleted successfully.
                          C:\UsbFix\Quarantine\C\RECYCLER\S-1-5-21-3046840070-1875883765-231225164-8348\rundll32.exe.UsbFix (Worm.Autorun.B) -> Quarantined and deleted successfully.
                          0
                          1. Contributeur sécurité
                            ok

                            comment va le pc ?

                            relances RSIT et poste le rapport log stp
                            0
                            1. voila le rapport

                              Logfile of random's system information tool 1.06 (written by random/random)
                              Run by Abbassi at 2010-02-01 19:38:21
                              Microsoft Windows XP Édition familiale Service Pack 3
                              System drive C: has 41 GB (28%) free of 149 GB
                              Total RAM: 1023 MB (46% free)

                              Logfile of Trend Micro HijackThis v2.0.2
                              Scan saved at 19:38:47, on 01/02/2010
                              Platform: Windows XP SP3 (WinNT 5.01.2600)
                              MSIE: Internet Explorer v8.00 (8.00.6001.18702)
                              Boot mode: Normal

                              Running processes:
                              C:\WINDOWS\System32\smss.exe
                              C:\WINDOWS\system32\winlogon.exe
                              C:\WINDOWS\system32\services.exe
                              C:\WINDOWS\system32\lsass.exe
                              C:\WINDOWS\system32\Ati2evxx.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\System32\svchost.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\system32\Ati2evxx.exe
                              C:\WINDOWS\Explorer.EXE
                              C:\WINDOWS\system32\ZoneLabs\vsmon.exe
                              C:\WINDOWS\system32\spoolsv.exe
                              C:\Program Files\Avira\AntiVir Desktop\sched.exe
                              C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                              C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                              C:\Program Files\Bonjour\mDNSResponder.exe
                              C:\Program Files\Java\jre6\bin\jqs.exe
                              C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
                              C:\WINDOWS\SOUNDMAN.EXE
                              C:\apps\ABoard\ABoard.exe
                              C:\apps\ABoard\AOSD.exe
                              C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                              C:\WINDOWS\system32\slserv.exe
                              C:\WINDOWS\System32\svchost.exe
                              C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
                              C:\WINDOWS\wanmpsvc.exe
                              C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                              C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
                              C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
                              C:\Program Files\QuickTime\QTTask.exe
                              C:\Program Files\iTunes\iTunesHelper.exe
                              C:\WINDOWS\system32\ctfmon.exe
                              C:\Program Files\Microsoft ActiveSync\wcescomm.exe
                              C:\Program Files\Messenger\msmsgs.exe
                              C:\Program Files\SAGEM WiFi manager\WLANUTL.exe
                              C:\PROGRA~1\MICROS~4\rapimgr.exe
                              C:\WINDOWS\System32\wbem\wmiapsrv.exe
                              C:\Program Files\iPod\bin\iPodService.exe
                              C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                              C:\WINDOWS\system32\wuauclt.exe
                              C:\Program Files\Windows Live\Contacts\wlcomm.exe
                              C:\WINDOWS\System32\svchost.exe
                              C:\Program Files\Mozilla Firefox\firefox.exe
                              C:\Documents and Settings\Abbassi\Bureau\RSIT.exe
                              C:\Program Files\trend micro\Abbassi.exe

                              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer
                              R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                              R3 - Default URLSearchHook is missing
                              O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
                              O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                              O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
                              O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
                              O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
                              O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                              O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                              O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                              O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                              O3 - Toolbar: (no name) - {66886C4D-B307-4ECA-A228-52CA9B9851A4} - (no file)
                              O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
                              O4 - HKLM\..\Run: [ACTIVBOARD] c:\apps\ABoard\ABoard.exe
                              O4 - HKLM\..\Run: [ATIPTA] C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
                              O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
                              O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
                              O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                              O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
                              O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
                              O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                              O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                              O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
                              O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|DEFAULT=cnx|PARAM=
                              O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                              O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
                              O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                              O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
                              O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
                              O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
                              O4 - Global Startup: Utilitaire réseau pour SAGEM Wi-Fi 11g USB adapter.lnk = ?
                              O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                              O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                              O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
                              O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
                              O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
                              O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
                              O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                              O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                              O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                              O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                              O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                              O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                              O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\fr.htm
                              O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
                              O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
                              O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
                              O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
                              O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://download.divx.com/webplayer/stage6/windows/AutoDLDivXWebPlayerInstaller.cab
                              O16 - DPF: {80B626D6-BC34-4BCF-B5A1-7149E4FD9CFA} (UnoCtrl Class) - http://zone.msn.com/bingame/zpagames/GAME_UNO1.cab60096.cab
                              O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
                              O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZPAFramework.cab102118.cab
                              O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
                              O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                              O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab
                              O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
                              O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                              O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                              O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                              O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
                              O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                              O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
                              O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                              O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
                              O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
                              O23 - Service: Virtual CD v4 Security service (SDK - Version) (VCSSecS) - H+H Software GmbH - C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
                              O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
                              O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
                              O23 - Service: Gestionnaire de mise à jour Winsudate (WinSvc) - Unknown owner - C:\Program Files\Winsudate\gibsvc.exe (file missing)
                              0
                              1. Contributeur sécurité
                                tu ne m'as dit si tu avais toujours des problèmes...
                                0
                                1. jai un truc que menerve c un message sur zone alarm qui met met generic host process for win32. si je met deny jai pas internet avant javais pas ce message mais a part ca tout va bien
                                  0
                                  1. Contributeur sécurité
                                    ok

                                    Desactive ton antivirus le temps de la manip ainsi que ton parefeu si présent(car il est detecté a tort comme infection)

                                    ▶ Télécharge et installe List&Kill'em et enregistre le sur ton bureau
                                    http://sd-1.archive-host.com/membres/up/829108531491024/List_Killem_Install.exe

                                    double clique ( clic droit "executer en tant qu'administrateur" pour Vista/7 ) sur le raccourci sur ton bureau pour lancer l'installation

                                    coche la case "creer une icone sur le bureau"

                                    une fois terminée , clic sur "terminer" et le programme se lancer seul

                                    choisis la langue puis choisis l'option 1 = Mode Recherche

                                    ▶ laisse travailler l'outil

                                    à l'apparition de la fenetre blanche , c'est un peu long , c'est normal , le programme n'est pas bloqué.

                                    un rapport du nom de catchme apparait sur ton bureau , ignore-le,ne le poste pas , mais ne le supprime pas pour l instant, le scan n'est pas fini.

                                    ▶ Poste le contenu du rapport qui s'ouvre aux 100 % du scan à l'ecran "COMPLETED"

                                    tu peux supprimer le rapport catchme.log de ton bureau maintenant.
                                    0
                                    1. voici le rapport demander

                                      List'em by g3n-h@ckm@n 1.2.1.3
                                      User : Abbassi (Administrateurs)
                                      Update on 01/02/2010 by g3n-h@ckm@n ::::: 20.20
                                      Start at: 15:58:01 | 02/02/2010
                                      Contact : g3n-h@ckm@n sur CCM

                                      AMD Athlon(tm) XP 2700+
                                      Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
                                      Internet Explorer 8.0.6001.18702
                                      Windows Firewall Status : Disabled
                                      AV : AntiVir Desktop 9.0.1.32 [ Enabled | Updated ]
                                      FW : ZoneAlarm Firewall[ Enabled ]8.0.298.000

                                      A:\ -> Lecteur de disquettes 3 ½ pouces
                                      C:\ -> Disque fixe local | 145,04 Go (40,68 Go free) [HDD] | NTFS
                                      D:\ -> Disque CD-ROM
                                      E:\ -> Disque CD-ROM
                                      I:\ -> Disque amovible
                                      J:\ -> Disque amovible

                                      ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running

                                      C:\WINDOWS\System32\smss.exe
                                      C:\WINDOWS\system32\csrss.exe
                                      C:\WINDOWS\system32\winlogon.exe
                                      C:\WINDOWS\system32\services.exe
                                      C:\WINDOWS\system32\lsass.exe
                                      C:\WINDOWS\system32\Ati2evxx.exe
                                      C:\WINDOWS\system32\svchost.exe
                                      C:\WINDOWS\system32\svchost.exe
                                      C:\WINDOWS\System32\svchost.exe
                                      C:\WINDOWS\system32\svchost.exe
                                      C:\WINDOWS\System32\svchost.exe
                                      C:\WINDOWS\system32\Ati2evxx.exe
                                      C:\WINDOWS\Explorer.EXE
                                      C:\WINDOWS\system32\svchost.exe
                                      C:\WINDOWS\system32\ZoneLabs\vsmon.exe
                                      C:\WINDOWS\system32\spoolsv.exe
                                      C:\Program Files\Avira\AntiVir Desktop\sched.exe
                                      C:\WINDOWS\System32\svchost.exe
                                      C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                                      C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                      C:\Program Files\Bonjour\mDNSResponder.exe
                                      C:\Program Files\Java\jre6\bin\jqs.exe
                                      C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
                                      C:\WINDOWS\SOUNDMAN.EXE
                                      C:\apps\ABoard\ABoard.exe
                                      C:\apps\ABoard\AOSD.exe
                                      C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                                      C:\WINDOWS\system32\slserv.exe
                                      C:\WINDOWS\System32\svchost.exe
                                      C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
                                      C:\WINDOWS\wanmpsvc.exe
                                      C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                                      C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
                                      C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
                                      C:\Program Files\QuickTime\QTTask.exe
                                      C:\Program Files\iTunes\iTunesHelper.exe
                                      C:\WINDOWS\system32\ctfmon.exe
                                      C:\Program Files\Microsoft ActiveSync\wcescomm.exe
                                      C:\Program Files\Messenger\msmsgs.exe
                                      C:\Program Files\SAGEM WiFi manager\WLANUTL.exe
                                      C:\PROGRA~1\MICROS~4\rapimgr.exe
                                      C:\WINDOWS\System32\alg.exe
                                      C:\Program Files\iPod\bin\iPodService.exe
                                      C:\WINDOWS\System32\wbem\wmiapsrv.exe
                                      C:\Program Files\Mozilla Firefox\firefox.exe
                                      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                                      C:\Program Files\Windows Live\Contacts\wlcomm.exe
                                      C:\Program Files\Internet Explorer\IEXPLORE.EXE
                                      C:\Program Files\Internet Explorer\IEXPLORE.EXE
                                      C:\Program Files\Windows Live\Toolbar\wltuser.exe
                                      C:\Program Files\Internet Explorer\IEXPLORE.EXE
                                      C:\Program Files\List_Kill'em\List_Kill'em.scr
                                      C:\WINDOWS\system32\cmd.exe
                                      C:\WINDOWS\system32\wbem\wmiprvse.exe
                                      C:\Documents and Settings\Abbassi\Local Settings\temp\19.tmp\pv.exe

                                      ======================
                                      Keys "Run"
                                      ======================
                                      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                      WOOKIT REG_SZ C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|DEFAULT=cnx|PARAM=
                                      ctfmon.exe REG_SZ C:\WINDOWS\system32\ctfmon.exe
                                      H/PC Connection Agent REG_SZ "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
                                      MSMSGS REG_SZ "C:\Program Files\Messenger\msmsgs.exe" /background

                                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                      SoundMan REG_SZ SOUNDMAN.EXE
                                      ACTIVBOARD REG_SZ c:\apps\ABoard\ABoard.exe
                                      ATIPTA REG_SZ C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
                                      Adobe Reader Speed Launcher REG_SZ "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
                                      KernelFaultCheck REG_EXPAND_SZ %systemroot%\system32\dumprep 0 -k
                                      TkBellExe REG_SZ "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                                      avgnt REG_SZ "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
                                      ZoneAlarm Client REG_SZ "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
                                      QuickTime Task REG_SZ "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                                      iTunesHelper REG_SZ "C:\Program Files\iTunes\iTunesHelper.exe"
                                      VTTimer REG_SZ VTTimer.exe

                                      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]

                                      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]

                                      =====================
                                      Other Keys
                                      =====================
                                      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
                                      dontdisplaylastusername REG_DWORD 0 (0x0)
                                      legalnoticecaption REG_SZ
                                      legalnoticetext REG_SZ
                                      shutdownwithoutlogon REG_DWORD 1 (0x1)
                                      undockwithoutlogon REG_DWORD 1 (0x1)

                                      ===============
                                      [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
                                      NoDriveAutoRun REG_DWORD 128 (0x80)
                                      NoDriveTypeAutoRun REG_DWORD 128 (0x80)
                                      HonorAutoRunSetting REG_DWORD 0 (0x0)

                                      ===============
                                      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
                                      NoDriveAutoRun REG_DWORD 128 (0x80)
                                      NoCDBurning REG_DWORD 0 (0x0)
                                      NoDriveTypeAutoRun REG_DWORD 128 (0x80)
                                      HonorAutoRunSetting REG_DWORD 0 (0x0)

                                      ===============
                                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]

                                      ===============
                                      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
                                      AutoRestartShell REG_DWORD 1 (0x1)
                                      DefaultDomainName REG_SZ SN401381390009
                                      DefaultUserName REG_SZ Abbassi
                                      LegalNoticeCaption REG_SZ
                                      LegalNoticeText REG_SZ
                                      PowerdownAfterShutdown REG_SZ 0
                                      ReportBootOk REG_SZ 1
                                      Shell REG_SZ explorer.exe
                                      ShutdownWithoutLogon REG_SZ 0
                                      System REG_SZ
                                      Userinit REG_SZ C:\WINDOWS\system32\userinit.exe,
                                      VmApplet REG_SZ rundll32 shell32,Control_RunDLL "sysdm.cpl"
                                      SfcQuota REG_DWORD -1 (0xffffffff)
                                      allocatecdroms REG_SZ 0
                                      allocatedasd REG_SZ 0
                                      allocatefloppies REG_SZ 0
                                      cachedlogonscount REG_SZ 10
                                      forceunlocklogon REG_DWORD 0 (0x0)
                                      passwordexpirywarning REG_DWORD 14 (0xe)
                                      scremoveoption REG_SZ 0
                                      AllowMultipleTSSessions REG_DWORD 1 (0x1)
                                      UIHost REG_EXPAND_SZ logonui.exe
                                      LogonType REG_DWORD 1 (0x1)
                                      Background REG_SZ 0 0 0
                                      DebugServerCommand REG_SZ no
                                      SFCDisable REG_DWORD 0 (0x0)
                                      WinStationsDisabled REG_SZ 0
                                      HibernationPreviouslyEnabled REG_DWORD 1 (0x1)
                                      ShowLogonOptions REG_DWORD 0 (0x0)
                                      AltDefaultUserName REG_SZ Abbassi
                                      AltDefaultDomainName REG_SZ SN401381390009
                                      ChangePasswordUseKerberos REG_DWORD 1 (0x1)

                                      ===============
                                      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\AtiExtEvent]
                                      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\crypt32chain]
                                      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cryptnet]
                                      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cscdll]
                                      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\dimsntfy]
                                      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ScCertProp]
                                      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Schedule]
                                      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\sclgntfy]
                                      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\SensLogn]
                                      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\termsrv]
                                      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WgaLogon]
                                      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wlballoon]

                                      ===============
                                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
                                      {AEB6717E-7E19-11d0-97EE-00C04FD91972} REG_SZ

                                      ===============
                                      [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
                                      %windir%\system32\sessmgr.exe REG_SZ %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
                                      C:\WINDOWS\system32\rtcshare.exe REG_SZ C:\WINDOWS\system32\rtcshare.exe:*:Disabled:Partage de l'application RTC
                                      %windir%\Network Diagnostic\xpnetdiag.exe REG_SZ %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
                                      C:\Program Files\Messenger\msmsgs.exe REG_SZ C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger
                                      C:\WINDOWS\SOUNDMAN.EXE REG_SZ C:\WINDOWS\SOUNDMAN.EXE:*:Enabled:SOUNDMAN
                                      C:\Program Files\Windows Live\Messenger\usnsvc.exe REG_SZ C:\Program Files\Windows Live\Messenger\usnsvc.exe:*:Enabled:usnsvc
                                      C:\Program Files\SAGEM WiFi manager\WLANUTL.EXE REG_SZ C:\Program Files\SAGEM WiFi manager\WLANUTL.EXE:*:Enabled:WLANUTL
                                      C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe REG_SZ C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe:*:Enabled:realsched
                                      C:\Program Files\QuickTime\qttask.exe REG_SZ C:\Program Files\QuickTime\qttask.exe:*:Enabled:qttask
                                      C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe REG_SZ C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe:*:Enabled:avgnt
                                      C:\WINDOWS\system32\ati2evxx.exe REG_SZ C:\WINDOWS\system32\ati2evxx.exe:*:Enabled:Ati2evxx
                                      C:\APPS\ABoard\AOSD.EXE REG_SZ C:\APPS\ABoard\AOSD.EXE:*:Enabled:AOSD
                                      C:\Program Files\Avira\AntiVir PersonalEdition Classic\guardgui.exe REG_SZ C:\Program Files\Avira\AntiVir PersonalEdition Classic\guardgui.exe:*:Enabled:GUARDGUI
                                      C:\Program Files\Skype\Phone\Skype.exe REG_SZ C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype
                                      C:\Program Files\Kyodai Mahjongg 2006\kmj.exe REG_SZ C:\Program Files\Kyodai Mahjongg 2006\kmj.exe:*:Disabled:Kyodai Mahjongg
                                      C:\Program Files\Microsoft ActiveSync\rapimgr.exe REG_SZ C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
                                      C:\Program Files\Microsoft ActiveSync\wcescomm.exe REG_SZ C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
                                      C:\Program Files\Microsoft ActiveSync\WCESMgr.exe REG_SZ C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
                                      C:\Documents and Settings\Abbassi\Mes documents\WM_Abbassi Mes documents\FM2008\fm.exe REG_SZ C:\Documents and Settings\Abbassi\Mes documents\WM_Abbassi Mes documents\FM2008\fm.exe:*:Enabled:Football Manager 2008
                                      C:\Program Files\Windows Live\Messenger\wlcsdk.exe REG_SZ C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call
                                      C:\Program Files\Sports Interactive\Football Manager 2008\fm.exe REG_SZ C:\Program Files\Sports Interactive\Football Manager 2008\fm.exe:*:Disabled:Football Manager 2008
                                      C:\Program Files\Sports Interactive\Football Manager 2009\fm.exe REG_SZ C:\Program Files\Sports Interactive\Football Manager 2009\fm.exe:*:Disabled:Football Manager 2009
                                      C:\Program Files\Windows Live\Messenger\msnmsgr.exe REG_SZ C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger
                                      C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe REG_SZ C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live FolderShare
                                      C:\Program Files\Bonjour\mDNSResponder.exe REG_SZ C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour
                                      C:\Program Files\iTunes\iTunes.exe REG_SZ C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes

                                      [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
                                      %windir%\system32\sessmgr.exe REG_SZ %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
                                      %windir%\Network Diagnostic\xpnetdiag.exe REG_SZ %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
                                      C:\Program Files\Lexmark 1400 Series\app4r.exe REG_SZ C:\Program Files\Lexmark 1400 Series\App4R.exe:*:Enabled:Lexmark Imaging Studio
                                      C:\Program Files\Microsoft ActiveSync\rapimgr.exe REG_SZ C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
                                      C:\Program Files\Microsoft ActiveSync\wcescomm.exe REG_SZ C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
                                      C:\Program Files\Microsoft ActiveSync\WCESMgr.exe REG_SZ C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
                                      C:\Program Files\Windows Live\Messenger\wlcsdk.exe REG_SZ C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call
                                      C:\Program Files\Windows Live\Messenger\msnmsgr.exe REG_SZ C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger
                                      C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe REG_SZ C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live FolderShare

                                      ===============
                                      ActivX controls
                                      ===============
                                      HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\DirectAnimation Java Classes
                                      HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\Microsoft XML Parser for Java
                                      HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{00B71CFB-6864-4346-A978-C0A14556272C}
                                      HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{20A60F0D-9AFA-4515-A0FD-83BD84642501}
                                      HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{2917297F-F02B-4B9D-81DF-494B6333150B}
                                      HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{5D6F45B3-9043-443D-A792-115447494D24}
                                      HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{67DABFBF-D0AB-41FA-9C46-CC0F21721616}
                                      HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{80B626D6-BC34-4BCF-B5A1-7149E4FD9CFA}
                                      HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{8AD9C840-044E-11D1-B3E9-00805F499D93}
                                      HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{8E0D4DE5-3180-4024-A327-4DFAD1796A8D}
                                      HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
                                      HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{B8BE5E93-A60C-4D26-A2DC-220313175592}
                                      HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{C3F79A2B-B9B4-4A66-B012-3EE46475B072}
                                      HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
                                      HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
                                      HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{D27CDB6E-AE6D-11CF-96B8-444553540000}
                                      HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{F6BF0D00-0B2A-4A75-BF7B-F385591623AF}

                                      ===============
                                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\<{12d0ed0d-0ee0-4f90-8827-78cefb8f4988}
                                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}
                                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{26923b43-4d38-484f-9b9e-de460746276c}
                                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}
                                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{CB58DED6-4AF3-4080-9DF1-DEE72075169F}
                                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{03F998B2-0E00-11D3-A498-00104B6EB52E}
                                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{08B0E5C0-4FCB-11CF-AAA5-00401C608500}
                                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{08B0E5C0-4FCB-11CF-AAA5-00401C608555}
                                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10072CEC-8CC1-11D1-986E-00A0C955B42F}
                                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{1325db73-d9f1-48f8-8895-6d814ec58889}
                                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{166B1BCA-3F9C-11CF-8075-444553540000}
                                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{1B00725B-C455-4DE6-BFB6-AD540AD427CD}
                                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2179C5D3-EBFF-11CF-B6FD-00AA00B4E220}
                                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}
                                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{283807B5-2C60-11D0-A31D-00AA00B92C03}
                                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2A202491-F00D-11cf-87CC-0020AFEECF20}
                                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}
                                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{36f8ec70-c29a-11d1-b5c7-0000f8051515}
                                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{3af36230-a269-11d1-b5bf-0000f8051515}
                                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{3bf42070-b3b1-11d1-b5c5-0000f8051515}
                                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{411EDCF7-755D-414E-A74B-3DCD6583F589}
                                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4278c270-a269-11d1-b5bf-0000f8051515}
                                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}
                                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}
                                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA848-CC51-11CF-AAFA-00AA00B6015C}
                                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}
                                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA855-CC51-11CF-AAFA-00AA00B6015F}
                                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{45ea75a0-a269-11d1-b5bf-0000f8051515}
                                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4f216970-c90c-11d1-b5c7-0000f8051515}
                                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4f645220-306d-11d2-995d-00c04f98bbc9}
                                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5945c046-1e7d-11d1-bc44-00c04fd912be}
                                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5A8D6EE0-3E18-11D0-821E-444553540000}
                                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5fd399c0-a70a-11d1-9948-00c04f98bbc9}
                                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{630b1da0-b465-11d1-9948-00c04f98bbc9}
                                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}
                                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6fab99d0-bab8-11d1-994a-00c04f98bbc9}
                                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}
                                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{73FA19D0-2D75-11D2-995D-00C04F98BBC9}
                                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7790769C-0471-11d2-AF11-00C04FA35D02}
                                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4340}
                                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4383}
                                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}
                                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9381D8F2-0288-11D0-9501-00AA00B911A5}
                                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{B508B3F1-A24A-32C0-B310-85786919EF28}
                                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}
                                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C9E9A340-D1F1-11D0-821E-444553540600}
                                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
                                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CC2A9BA0-3BDD-11D0-821E-444553540000}
                                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CDD7975E-60F8-41d5-8149-19E51D6F71D0}
                                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{D27CDB6E-AE6D-11cf-96B8-444553540000}
                                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{DAA94A2A-2A8D-4D3B-9DB8-56FBECED082D}
                                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{de5aed00-a4bf-11d1-9948-00c04f98bbc9}
                                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{E92B03AB-B707-11d2-9CBD-0000F87A369E}
                                      HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{F5776D81-AE53-4935-8E84-B0B283D8BCEF}

                                      ==============
                                      BHO :
                                      ======
                                      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
                                      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{53707962-6F74-2D53-2644-206D7942484F}]
                                      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]
                                      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
                                      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
                                      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
                                      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
                                      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10}]

                                      ================
                                      Internet Explorer :
                                      ================
                                      [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
                                      Start Page REG_SZ https://www.msn.com/fr-fr/

                                      [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                                      Start Page REG_SZ http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome

                                      ========
                                      Services
                                      ========
                                      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services]

                                      Ndisuio : 0x3
                                      EapHost : 0x3
                                      SharedAccess : 0x2
                                      wuauserv : 0x2

                                      =========
                                      Atapi.sys
                                      =========

                                      %%%% HASHDEEP-1.0
                                      %%%% size,md5,sha256,filename
                                      ## Invoked from: C:\Documents and Settings\Abbassi\Local Settings\temp\19.tmp
                                      ## C:\> hashdeep C:\WINDOWS\System32\Drivers\atapi.sys
                                      ##
                                      95360,cdfe4411a69c224bd1d11b2da92dac51,0e6b23a80f171550575bebc56f7500cd87a5cf03b2b9fdc49bc3de96282cd69d,C:\WINDOWS\System32\Drivers\atapi.sys

                                      Sources
                                      =======

                                      C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
                                      C:\WINDOWS\$NtUninstallQ331060$\atapi.sys
                                      C:\WINDOWS\ServicePackFiles\i386\atapi.sys
                                      C:\WINDOWS\system32\drivers\atapi.sys

                                      Référence :
                                      ==========

                                      Win XP_32b : a64013e98426e1877cb653685c5c0009
                                      Win XP_SP2_32b : CDFE4411A69C224BD1D11B2DA92DAC51
                                      Win XP_SP3_32b : 9F3A2F5AA6875C72BF062C712CFA2674
                                      Vista_32b : e03e8c99d15d0381e02743c36afc7c6f
                                      Vista_SP1_32b : 2d9c903dc76a66813d350a562de40ed9
                                      Vista_SP2_32b : 1F05B78AB91C9075565A9D8A4B880BC4
                                      Vista_SP2_64b : 1898FAE8E07D97F2F6C2D5326C633FAC
                                      Windows 7_32b : 80C40F7FDFC376E4C5FEEC28B41C119E
                                      Windows 7_64b : 02062C0B390B7729EDC9E69C680A6F3C

                                      =======
                                      Drive :
                                      =======

                                      D‚fragmenteur de disque Windows
                                      Copyright (c) 2001 Microsoft Corp. et Executive Software International Inc.

                                      Rapport d'analyse
                                      145 Go total, 40,69 Go libre (28%), 20% fragment‚ (fragmentation du fichier 39%)

                                      Vous devriez d‚fragmenter ce volume.

                                      ¤¤¤¤¤¤¤¤¤¤ Files/folders :

                                      Present !! : C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
                                      Present !! : C:\Program Files\AskBarDis
                                      Present !! : C:\Program Files\Fast Browser Search
                                      Present !! : C:\Program Files\Mozilla FireFox\Components\AskHPRFF.js
                                      Present !! : C:\WINDOWS\002156_.tmp
                                      Present !! : C:\WINDOWS\005299_.tmp
                                      Present !! : C:\WINDOWS\DUMP666a.tmp
                                      Present !! : C:\WINDOWS\system32\x3daudio1_0.dll
                                      Present !! : C:\WINDOWS\system32\x3daudio1_1.dll
                                      Present !! : C:\WINDOWS\system32\X3DAudio1_2.dll
                                      Present !! : C:\WINDOWS\system32\X3DAudio1_3.dll
                                      Present !! : C:\WINDOWS\system32\X3DAudio1_4.dll
                                      Present !! : C:\WINDOWS\system32\xinput9_1_0.dll
                                      Present !! : C:\WINDOWS\System32\drivers\etc\hosts.msn
                                      Present !! : C:\WINDOWS\System32\netwbix32.dll
                                      Present !! : C:\WINDOWS\System32\SET1A.tmp
                                      Present !! : C:\WINDOWS\System32\SET23.tmp
                                      Present !! : C:\WINDOWS\System32\SET2B.tmp
                                      Present !! : C:\WINDOWS\System32\SETB4.tmp
                                      Present !! : C:\WINDOWS\System32\SETBB.tmp
                                      Present !! : C:\WINDOWS\System32\SETC7.tmp
                                      Present !! : C:\Documents and Settings\Abbassi\Application Data\GDIPFONTCACHEV1.DAT
                                      Present !! : C:\Documents and Settings\Abbassi\Application Data\GDIPFONTCACHEV1.DAT

                                      ¤¤¤¤¤¤¤¤¤¤ Keys :

                                      Present !! : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{66886C4D-B307-4ECA-A228-52CA9B9851A4}
                                      Present !! : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{0E5CBF21-D15F-11D0-8301-00AA005B4383}
                                      Present !! : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{3041d03e-fd4b-44e0-b742-2d9b88305f98}
                                      Present !! : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Install.exe"
                                      Present !! : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Setup.exe"
                                      Present !! : HKCR\CLSID\{0702a2b6-13aa-4090-9e01-bcdc85dd933f}
                                      Present !! : HKCR\CLSID\{b0de3308-5d5a-470d-81b9-634fc078393b}
                                      Present !! : HKCU\Software\AppDataLow\AskBarDis
                                      Present !! : HKLM\Software\Classes\CLSID\{0702a2b6-13aa-4090-9e01-bcdc85dd933f}
                                      Present !! : HKLM\Software\Classes\CLSID\{622fd888-4e91-4d68-84d4-7262fd0811bf}
                                      Present !! : HKLM\Software\Classes\CLSID\{b0de3308-5d5a-470d-81b9-634fc078393b}
                                      Present !! : HKLM\Software\Classes\TypeLib\{4B1C1E16-6B34-430E-B074-5928ECA4C150}
                                      Present !! : "HKLM\software\Poker 770"
                                      Present !! : HKLM\SYSTEM\ControlSet001\Services\winsvc
                                      Present !! : HKLM\SYSTEM\ControlSet003\Services\winsvc
                                      Present !! : HKLM\SYSTEM\CurrentControlSet\Services\winsvc

                                      ============

                                      catchme 0.3.1398.3 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                                      Rootkit scan 2010-02-02 16:18:09
                                      Windows 5.1.2600 Service Pack 3 NTFS

                                      scanning hidden processes ...

                                      scanning hidden services & system hive ...

                                      scanning hidden registry entries ...

                                      scanning hidden files ...

                                      scan completed successfully
                                      hidden processes: 0
                                      hidden services: 0
                                      hidden files: 0

                                      Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

                                      device: opened successfully
                                      user: MBR read successfully
                                      kernel: MBR read successfully
                                      user & kernel MBR OK

                                      ==========
                                      Programs
                                      ==========

                                      Adobe
                                      AOL 8.0
                                      AOL Compagnon
                                      Apple Software Update
                                      Ask & Record Toolbar
                                      AskBardis
                                      ATI Technologies
                                      Avira
                                      AviSynth 2.5
                                      BitComet
                                      BitDefender
                                      Bonjour
                                      CCleaner
                                      ComPlus Applications
                                      DivX
                                      DVDVideoSoft
                                      eMule
                                      Fast Browser Search
                                      Fichiers communs
                                      Full Tilt Poker
                                      Futuremark
                                      Hewlett-Packard
                                      InstallShield Installation Information
                                      Internet Explorer
                                      iPod
                                      iTunes
                                      IVCsoft
                                      Java
                                      Kyodai Mahjongg 2006
                                      List_Kill'em
                                      lx_cats
                                      Malwarebytes' Anti-Malware
                                      Messenger
                                      Microsoft
                                      Microsoft ActiveSync
                                      microsoft frontpage
                                      Microsoft Office
                                      Microsoft Silverlight
                                      Microsoft SQL Server Compact Edition
                                      Microsoft Sync Framework
                                      Microsoft Visual Studio
                                      Movie Maker
                                      Mozilla Firefox
                                      MSBuild
                                      MSN
                                      MSN Gaming Zone
                                      MSXML 4.0
                                      Navilog1
                                      NetMeeting
                                      Neuf
                                      Nullsoft
                                      OpenOffice.org 2.1
                                      Orange HSS
                                      OrangeHSS
                                      outlook express
                                      PhotoFiltre
                                      PokerStars
                                      QuickTime
                                      Real
                                      Red Kawa
                                      Reference Assemblies
                                      SAGEM WiFi manager
                                      Saxo
                                      Services en ligne
                                      Skype
                                      Softwin
                                      Sonic
                                      Sports Interactive
                                      Spybot - Search & Destroy
                                      Teamspeak2_RC2
                                      Trend Micro
                                      Uninstall Information
                                      VideoLAN
                                      Viewpoint
                                      Virtual CD v4 SDK
                                      Wanadoo
                                      Webteh
                                      Windows Live
                                      Windows Live SkyDrive
                                      Windows Media Connect 2
                                      Windows Media Player
                                      Windows Mobile Device Handbook
                                      Windows NT
                                      WindowsUpdate
                                      WinRAR
                                      xerox
                                      Zero G Registry
                                      Zone Labs
                                      Zylom Games

                                      ============
                                      Drive C:
                                      ============

                                      7c5a66d565c941291cdd5b706c
                                      ACTIVDOC
                                      adfa85de6e96f8079cbb80ffc3c8
                                      APPS
                                      ASLog.txt
                                      ATI
                                      ATI Technologies
                                      autorun.inf
                                      b3226cfb5c6da86c8837fc4b
                                      bazooka
                                      BOOT.BAK
                                      BOOT.INI
                                      Bootfont.bin
                                      cleannavi.txt
                                      cmdcons
                                      cmldr
                                      Config.Msi
                                      DIVTOOLS
                                      Documents and Settings
                                      Downloads
                                      DRIVERS
                                      DSCF1024.JPG
                                      DWNLOG.TXT
                                      e9c087ecd9dad8bba69f
                                      ExtractLog.txt
                                      FLIPART.MSNFix
                                      GETDRIVE.MSNFix
                                      HighLogging.log
                                      IO.SYS
                                      IPH.PH
                                      JavaRa.log
                                      Kill'em
                                      List'em.txt
                                      logs
                                      lxdj.log
                                      MicroGaming
                                      MSDOS.SYS
                                      My Music
                                      NTDETECT.COM
                                      ntldr
                                      OEMCUST
                                      pagefile.sys
                                      PNP
                                      Poker
                                      Program Files
                                      realquas.TAG
                                      RECYCLER
                                      rsit
                                      SAUVE
                                      Setup.log
                                      System Volume Information
                                      TB.txt
                                      TCleaner.txt
                                      ToolBar SD
                                      UsbFix
                                      UsbFix.txt
                                      UsbFix_Upload_Me
                                      UsbFix_Upload_Me_SN401381390009.zip
                                      VProRecovery
                                      WINDOWS

                                      ¤¤¤¤¤¤¤¤¤¤ Cracks | Keygens | Serials

                                      C:\Documents and Settings\Abbassi\Mes documents\divers\Cl‚ USB HaGeR\Microsoft Office 2007\Serial.txt
                                      C:\Documents and Settings\Abbassi\Mes documents\divers\Nouveau dossier (8)\DoSSieR HaGeR\Microsoft Office 2007\Serial.txt
                                      C:\Documents and Settings\Abbassi\Mes documents\divers\Nouveau dossier (8)\musik\Microsoft Office 2007\Serial.txt
                                      C:\Documents and Settings\Abbassi\Mes documents\divers\Nouveau dossier (8)\Nouveau dossier (7)\Microsoft Office 2007\Serial.txt
                                      C:\Program Files\AOL 8.0\Patchw32.dll
                                      C:\WINDOWS\system32\Macromed\Download\Install.exe

                                      ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
                                      0
                                      1. Contributeur sécurité
                                        ▶ Relance List&Kill'em avec le raccourci sur ton bureau ,

                                        mais cette fois-ci :

                                        ▶ choisis l'option 2 = Mode Suppression

                                        laisse travailler l'outil.

                                        en fin de scan un rapport s'ouvre

                                        ▶ colle le contenu dans ta reponse

                                        Tu peux le désinstaller ensuite

                                        ................................

                                        Cherches et cliques sur C:\Program Files\trend micro\Abbassi.exe
                                        Au menu principal, choisir do a scan only, puis cocher la case devant les lignes suivantes à corriger et cliquer en bas sur Fix Checked (s’il manque des lignes…pas grave)

                                        C:\WINDOWS\SOUNDMAN.EXE
                                        R3 - Default URLSearchHook is missing
                                        O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
                                        O3 - Toolbar: (no name) - {66886C4D-B307-4ECA-A228-52CA9B9851A4} - (no file)
                                        O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
                                        O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
                                        O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                                        O4 - Global Startup: Utilitaire réseau pour SAGEM Wi-Fi 11g USB adapter.lnk =
                                        O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
                                        O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                                        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                                        O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                                        O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
                                        O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
                                        O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe



                                        0
                                        1. voici le rapport

                                          Kill'em by g3n-h@ckm@n 1.2.1.3

                                          User : Abbassi (Administrateurs)
                                          Update on 01/02/2010 by g3n-h@ckm@n ::::: 20.20
                                          Start at: 17:35:47 | 02/02/2010
                                          Contact : g3n-h@ckm@n sur CCM

                                          AMD Athlon(tm) XP 2700+
                                          Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
                                          Internet Explorer 8.0.6001.18702
                                          Windows Firewall Status : Disabled
                                          AV : AntiVir Desktop 9.0.1.32 [ Enabled | Updated ]
                                          FW : ZoneAlarm Firewall[ Enabled ]8.0.298.000

                                          A:\ -> Lecteur de disquettes 3 ½ pouces
                                          C:\ -> Disque fixe local | 145,04 Go (40,69 Go free) [HDD] | NTFS
                                          D:\ -> Disque CD-ROM
                                          E:\ -> Disque CD-ROM
                                          I:\ -> Disque amovible
                                          J:\ -> Disque amovible

                                          ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running

                                          C:\WINDOWS\System32\smss.exe
                                          C:\WINDOWS\system32\csrss.exe
                                          C:\WINDOWS\system32\winlogon.exe
                                          C:\WINDOWS\system32\services.exe
                                          C:\WINDOWS\system32\lsass.exe
                                          C:\WINDOWS\system32\Ati2evxx.exe
                                          C:\WINDOWS\system32\svchost.exe
                                          C:\WINDOWS\system32\svchost.exe
                                          C:\WINDOWS\System32\svchost.exe
                                          C:\WINDOWS\system32\svchost.exe
                                          C:\WINDOWS\System32\svchost.exe
                                          C:\WINDOWS\system32\Ati2evxx.exe
                                          C:\WINDOWS\Explorer.EXE
                                          C:\WINDOWS\system32\svchost.exe
                                          C:\WINDOWS\system32\ZoneLabs\vsmon.exe
                                          C:\WINDOWS\system32\spoolsv.exe
                                          C:\Program Files\Avira\AntiVir Desktop\sched.exe
                                          C:\WINDOWS\System32\svchost.exe
                                          C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                                          C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                          C:\Program Files\Bonjour\mDNSResponder.exe
                                          C:\Program Files\Java\jre6\bin\jqs.exe
                                          C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
                                          C:\WINDOWS\SOUNDMAN.EXE
                                          C:\apps\ABoard\ABoard.exe
                                          C:\apps\ABoard\AOSD.exe
                                          C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                                          C:\WINDOWS\system32\slserv.exe
                                          C:\WINDOWS\System32\svchost.exe
                                          C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
                                          C:\WINDOWS\wanmpsvc.exe
                                          C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                                          C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
                                          C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
                                          C:\Program Files\QuickTime\QTTask.exe
                                          C:\Program Files\iTunes\iTunesHelper.exe
                                          C:\WINDOWS\system32\ctfmon.exe
                                          C:\Program Files\Microsoft ActiveSync\wcescomm.exe
                                          C:\Program Files\Messenger\msmsgs.exe
                                          C:\Program Files\SAGEM WiFi manager\WLANUTL.exe
                                          C:\PROGRA~1\MICROS~4\rapimgr.exe
                                          C:\WINDOWS\System32\alg.exe
                                          C:\Program Files\iPod\bin\iPodService.exe
                                          C:\WINDOWS\System32\wbem\wmiapsrv.exe
                                          C:\Program Files\Mozilla Firefox\firefox.exe
                                          C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                                          C:\Program Files\Windows Live\Contacts\wlcomm.exe
                                          C:\Program Files\Internet Explorer\IEXPLORE.EXE
                                          C:\Program Files\Internet Explorer\IEXPLORE.EXE
                                          C:\Program Files\Windows Live\Toolbar\wltuser.exe
                                          C:\WINDOWS\System32\svchost.exe
                                          C:\Program Files\Internet Explorer\IEXPLORE.EXE
                                          C:\Program Files\List_Kill'em\List_Kill'em.scr
                                          C:\WINDOWS\system32\cmd.exe
                                          C:\WINDOWS\system32\wbem\wmiprvse.exe
                                          C:\Documents and Settings\Abbassi\Local Settings\temp\E0.tmp\pv.exe

                                          Detections :
                                          ==========

                                          ¤¤¤¤¤¤¤¤¤¤ Files/folders :

                                          Quarantined & Deleted !! : C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
                                          Quarantined & Deleted !! : C:\Program Files\AskBarDis
                                          Quarantined & Deleted !! : C:\Program Files\Fast Browser Search
                                          Quarantined & Deleted !! : C:\Program Files\Mozilla FireFox\Components\AskHPRFF.js
                                          Quarantined & Deleted !! : C:\WINDOWS\002156_.tmp
                                          Quarantined & Deleted !! : C:\WINDOWS\005299_.tmp
                                          Quarantined & Deleted !! : C:\WINDOWS\DUMP666a.tmp

                                          Quarantined & Deleted !! : C:\WINDOWS\system32\x3daudio1_0.dll
                                          Quarantined & Deleted !! : C:\WINDOWS\system32\x3daudio1_1.dll
                                          Quarantined & Deleted !! : C:\WINDOWS\system32\X3DAudio1_2.dll
                                          Quarantined & Deleted !! : C:\WINDOWS\system32\X3DAudio1_3.dll
                                          Quarantined & Deleted !! : C:\WINDOWS\system32\X3DAudio1_4.dll
                                          Quarantined & Deleted !! : C:\WINDOWS\system32\xinput9_1_0.dll
                                          Quarantined & Deleted !! : C:\WINDOWS\System32\drivers\etc\hosts.msn
                                          Quarantined & Deleted !! : C:\WINDOWS\System32\netwbix32.dll
                                          Quarantined & Deleted !! : C:\WINDOWS\System32\SET1A.tmp
                                          Quarantined & Deleted !! : C:\WINDOWS\System32\SET23.tmp
                                          Quarantined & Deleted !! : C:\WINDOWS\System32\SET2B.tmp
                                          Quarantined & Deleted !! : C:\WINDOWS\System32\SETB4.tmp
                                          Quarantined & Deleted !! : C:\WINDOWS\System32\SETBB.tmp
                                          Quarantined & Deleted !! : C:\WINDOWS\System32\SETC7.tmp
                                          Quarantined & Deleted !! : C:\Documents and Settings\Abbassi\Application Data\GDIPFONTCACHEV1.DAT

                                          ==============
                                          host file OK !
                                          ==============

                                          ========
                                          Registry
                                          ========
                                          Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{66886C4D-B307-4ECA-A228-52CA9B9851A4}
                                          Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{0E5CBF21-D15F-11D0-8301-00AA005B4383}
                                          Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{3041d03e-fd4b-44e0-b742-2d9b88305f98}
                                          Deleted : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Install.exe"
                                          Deleted : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Setup.exe"
                                          Deleted : HKCR\CLSID\{0702a2b6-13aa-4090-9e01-bcdc85dd933f}
                                          Deleted : HKCR\CLSID\{b0de3308-5d5a-470d-81b9-634fc078393b}
                                          Deleted : HKCU\Software\AppDataLow\AskBarDis
                                          Deleted : HKLM\Software\Classes\CLSID\{622fd888-4e91-4d68-84d4-7262fd0811bf}
                                          Deleted : HKLM\Software\Classes\TypeLib\{4B1C1E16-6B34-430E-B074-5928ECA4C150}
                                          Deleted : "HKLM\software\Poker 770"
                                          Deleted : HKLM\SYSTEM\ControlSet001\Services\winsvc
                                          Deleted : HKLM\SYSTEM\ControlSet003\Services\winsvc

                                          ============
                                          Disk Cleaned
                                          ============

                                          ================
                                          Prefetch cleaned
                                          ================

                                          ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
                                          0
                                          • 1
                                          • 2